[Tue Aug 18 12:53:06.355869 2026] [lsapi:notice] [pid 119994:tid 119994] mod_lsapi: version 1.1-92 [Tue Aug 18 12:53:06.363935 2026] [:notice] [pid 66590:tid 66590] [host root@srv254.prodns.com.br] mod_lsapi: Selfstarter 66590 started [Tue Aug 18 12:53:06.399358 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ledline.net.br.ledline.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.450563 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: nardyefeitozaadvogados.adv.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.457583 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp36-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.459176 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: tenaxengenharia.com.br.solutiengenharia.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.480222 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: avalleimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.495174 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp37-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.505641 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ciaobus.com.br.imgm.giordaniturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.506562 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: taniimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.516405 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: tenazprotecaoveicular.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.562833 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: osorioimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.567196 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cariaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.569073 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: belmais.com.br.construbelmais.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.577766 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lucenaassessoria.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.588707 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dominiocontroledepragas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.689639 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: smcasanova.silplan.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.692142 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: smconstrutoraeengenharia.com.br.silplan.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.702768 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: loja.portalsatfiscal.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.711132 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: limapolimentos.com.br.riopolimento.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.720312 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: r3telhas.r3metais.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.732200 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aagroup.com.br.pontadaareiaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.739347 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pisogranitina.com.br.pisodegranitina.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.807885 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: msinspecoes.com.br.msengnr13.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.826866 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lagenzia.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.830368 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: skyorionn.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.834751 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: skyorion.tec.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.849595 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: centroassistencialpaz.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.851344 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mconteccontabil.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.852119 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gramadoboutiqueeventos.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.852848 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: seuferrazzabarbearia.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.853984 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ktcproducoeseeventos.com.br.testedemesa.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.854691 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lojasmemo.memo.ind.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.858483 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cervejeirasmemo.memo.ind.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.898184 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: shopping.impactodivisoria.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.899036 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: impactodivisorias.com.br.impactodivisoria.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.937090 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: holldyperfuracoes.grupoaquifero.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.937855 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: americapocosartesianos.grupoaquifero.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.972180 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: maosaobramt.com.br.ferrazegomes.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.974616 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: website.fbenevides.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:06.988207 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cargaedescargatiofe.com.br.expressotiofe.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.000830 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: drthiagocollares.drthiagocollares.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.001642 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: azelarcontroledepragas.com.br.dominiocontroledepragas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.019146 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: construtoradetoni.detoniconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.051161 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: capecodcleaningsvc.com.capecodcleaningservice.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.061777 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: seaconsultoriaambiental.bigcat.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.068520 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: belmaisbomfim.belmaisold.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.072715 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: requintelimp.com.br.automasantos.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.130133 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rodolfoveras.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.130936 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: portobeloimoveismg.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.131614 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: novosares.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.134612 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lacazaconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.136204 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: soimoveistatuape.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.136931 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: zavaloni.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.137675 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sulhaus.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.138397 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: inlarimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.139123 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imparavelimob.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.139872 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: perescoelho.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.140589 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: voxconsultoriaimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.141385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: comercialimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.143781 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: localimoveisaraguari.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.144506 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: 3xpay.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.145228 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: santosimoveis.imb.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.145960 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: angelaflats.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.147432 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariaparanhos.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.148204 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: priorimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.170228 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: wrsteel.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.173803 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: oniimoveis.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.174541 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: igarataimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.178280 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rlcorretores.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.179112 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vprimesolucoes.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.179905 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vp3.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.198321 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lplnegocios.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.213935 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rilleyerick.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.214663 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: finanimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.215428 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: regentnegociosimobiliarios.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.219949 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: uniquemultimarcas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.223523 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: underr.co:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.226615 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brunocunhaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.227323 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: domusimoveisaracaju.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.228193 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: intuitoimobiliario.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.229729 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: quadradoimob.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.231177 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fhcorretores.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.245728 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ccrimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.263588 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alessandrawagner.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.264342 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beachhouseimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.265088 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: privatebroker.online:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.267413 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vanessasantosimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.275690 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: equipeaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.282101 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sportvel.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.282932 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lusoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.310403 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sfcacessorios.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.338914 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: meimoveisnapraia.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.339580 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: analustosaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.348800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: noventaempreendimentos.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.354896 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: grservicos.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.373952 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: reidasbateriasbarra.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.386943 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: hdpinturas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.388427 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: roselifroesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.391638 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: jeosafaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.395408 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gfsnegociosimobiliarios.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.396124 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arteembambu.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.396940 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobi1.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.412111 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bahiabrokers.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.426048 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: wmtransporterj.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.436887 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: slobimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.437604 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pandaimoveispraia.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.442172 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pasys.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.442897 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: passopreto.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.452292 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: sdtechelevadores.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.453052 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ivofilhoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.470671 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: octoaipro.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.472243 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rayssamoutranconsultora.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.473542 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariaborille.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.474280 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: duarteemouraoadvogados.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.474961 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vicentegomesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.477913 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: minattoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.478639 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vidamoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.486798 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: andrehkarrimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.491739 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bcostim.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.492400 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: abensimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.497553 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: iconeimoveisrs.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.498303 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fabioporfiro.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.499621 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: inovalleimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.509911 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mogipallets.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.513438 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mmachado.imb.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.524369 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: receptivaimoveis.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.559275 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: maracanaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.571195 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: pusch.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.572661 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: deucertoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.576608 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: luxsociety.club:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.578326 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: luvdesign.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.584188 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dealencastroconyvidal.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.591030 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lojainspirada.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.593248 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alconstrutora.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.599184 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fserranodosreisimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.600252 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: desimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.606850 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: planetimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.607633 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brazriosimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.608385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: azevedofernandes.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.696631 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariacenterville.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.697413 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: yurilisboaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.698256 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: homego.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.699010 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bolzonelloimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.700603 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ofimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.704153 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: mendesestrutura.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.704982 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imob.adm.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.705839 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: detalhesimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.706853 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: positivoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.707980 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: casaverdeeamarelamogi.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.712320 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretorafaroldabarra.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.713007 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: singularimovel.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.719455 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: moralesemenezesadvocacia.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.759932 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imperiodosquadros.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.776418 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: investincorporacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.778631 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: marciacristiane.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.784615 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aragoniimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.794715 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: casafacilprudente.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.812553 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rmi.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.820066 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: gavino.imb.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.820831 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretoresdeimoveis.cim.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.828479 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: amaadvocacia.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.829210 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ponto4imoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.834670 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: palaceteimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.835373 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: novolarlimeira.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.836087 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beneville.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.853609 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: beckcentral.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.855946 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ferrazegomes.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.859956 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: feitech.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.868166 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: braunaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.871833 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: re9nove.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.886924 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rmautomoveisitajai.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.896801 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dayaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.905800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: reiximoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.906483 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: diegorobertoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.910458 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: dryulocesare.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.915657 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: fernandooliveiracorretor.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.924487 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: diveramkt.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.933600 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: destaquemultimarcas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.941254 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: vigaimoveistc.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.944171 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ingalar.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.955212 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: credprimevc.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.957417 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp39-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.958208 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: cp38-imobibrasil.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.959547 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: corretorjoaofilho.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.967645 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: conquistamaquinas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.990385 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: claraconecta.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:07.991160 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: openhouses.net.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.032800 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: alocaimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.033520 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: imobiliariasafra.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.039737 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: brsplit.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.049417 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: bondtintas.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.052605 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: a2ai.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.063950 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: raposoimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.082193 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: lopesreis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.095986 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: atendeprime.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.102613 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arsegfire.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.105885 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: arautosveiculos.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.106712 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: rastroimoveis.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.107479 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: advfreire.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.110069 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: eliaquimimoveis.com:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.113185 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: ipimoveisjatai.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.164554 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: acertdecor.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.165340 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: aceleradigital.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.167587 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: n5negocios.com.br:443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.171467 2026] [ssl:warn] [pid 119994:tid 119994] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name [Tue Aug 18 12:53:08.194906 2026] [qos:notice] [pid 119994:tid 119994] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients) [Tue Aug 18 12:53:08.565879 2026] [http2:info] [pid 119994:tid 119994] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing... [Tue Aug 18 12:53:08.572849 2026] [mpm_event:notice] [pid 119994:tid 119994] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations [Tue Aug 18 12:53:08.572863 2026] [core:notice] [pid 119994:tid 119994] AH00094: Command line: '/usr/sbin/httpd' [Tue Aug 18 12:53:09.651444 2026] [http2:info] [pid 66623:tid 66623] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 12:53:09.680852 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.154.236:65211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_5dO5rbWdOArH04J1owAAASM"] [Tue Aug 18 12:53:09.681678 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.100.201:56859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1pQAAASc"] [Tue Aug 18 12:53:09.682589 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/qfvqu.php"] [unique_id "aoR_5dO5rbWdOArH04J1pwAAASs"] [Tue Aug 18 12:53:09.682759 2026] [security2:error] [pid 66623:tid 66801] [client 20.48.236.86:10801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/av.php"] [unique_id "aoR_5dO5rbWdOArH04J1qAAAAS0"] [Tue Aug 18 12:53:09.683632 2026] [security2:error] [pid 66623:tid 66805] [client 20.151.109.219:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ut.php"] [unique_id "aoR_5dO5rbWdOArH04J1qgAAATE"] [Tue Aug 18 12:53:09.684253 2026] [security2:error] [pid 66623:tid 66807] [client 172.202.39.151:11074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/k.php"] [unique_id "aoR_5dO5rbWdOArH04J1qwAAATM"] [Tue Aug 18 12:53:09.685521 2026] [security2:error] [pid 66623:tid 66813] [client 172.202.39.151:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content.php.php"] [unique_id "aoR_5dO5rbWdOArH04J1rgAAATk"] [Tue Aug 18 12:53:09.685937 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.100.201:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-asudo.php"] [unique_id "aoR_5dO5rbWdOArH04J1mwAAARU"] [Tue Aug 18 12:53:09.685966 2026] [security2:error] [pid 66623:tid 66787] [client 104.209.144.33:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoR_5dO5rbWdOArH04J1ogAAAR8"] [Tue Aug 18 12:53:09.686001 2026] [security2:error] [pid 66623:tid 66785] [client 20.171.51.14:16762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ij.php"] [unique_id "aoR_5dO5rbWdOArH04J1ngAAAR0"] [Tue Aug 18 12:53:09.686032 2026] [security2:error] [pid 66623:tid 66773] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wap.php"] [unique_id "aoR_5dO5rbWdOArH04J1mQAAARE"] [Tue Aug 18 12:53:09.686051 2026] [security2:error] [pid 66623:tid 66779] [client 20.250.27.191:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/kir.php"] [unique_id "aoR_5dO5rbWdOArH04J1nQAAARc"] [Tue Aug 18 12:53:09.686095 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/47.php"] [unique_id "aoR_5dO5rbWdOArH04J1lgAAAQw"] [Tue Aug 18 12:53:09.686145 2026] [security2:error] [pid 66623:tid 66766] [client 68.221.73.131:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/xiugai.php"] [unique_id "aoR_5dO5rbWdOArH04J1lQAAAQo"] [Tue Aug 18 12:53:09.686180 2026] [security2:error] [pid 66623:tid 66772] [client 132.196.61.152:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/xiugai.php"] [unique_id "aoR_5dO5rbWdOArH04J1mgAAARA"] [Tue Aug 18 12:53:09.686204 2026] [security2:error] [pid 66623:tid 66767] [client 20.42.19.40:2227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/chosen.php"] [unique_id "aoR_5dO5rbWdOArH04J1lwAAAQs"] [Tue Aug 18 12:53:09.686261 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR_5dO5rbWdOArH04J1oAAAARk"] [Tue Aug 18 12:53:09.686288 2026] [security2:error] [pid 66623:tid 66783] [client 20.171.51.14:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pu.php"] [unique_id "aoR_5dO5rbWdOArH04J1nwAAARs"] [Tue Aug 18 12:53:09.686331 2026] [security2:error] [pid 66623:tid 66815] [client 52.238.210.254:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J1rwAAATs"] [Tue Aug 18 12:53:09.686361 2026] [security2:error] [pid 66623:tid 66789] [client 4.223.164.152:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1oQAAASE"] [Tue Aug 18 12:53:09.688032 2026] [security2:error] [pid 66623:tid 66823] [client 74.249.206.207:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J1sQAAAUM"] [Tue Aug 18 12:53:09.688347 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.136.165:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xqq.php"] [unique_id "aoR_5dO5rbWdOArH04J1sgAAAUU"] [Tue Aug 18 12:53:09.690324 2026] [security2:error] [pid 66623:tid 66833] [client 52.238.210.254:42081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/goods.php"] [unique_id "aoR_5dO5rbWdOArH04J1tgAAAU0"] [Tue Aug 18 12:53:09.690868 2026] [security2:error] [pid 66623:tid 66835] [client 104.209.144.33:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1twAAAU8"] [Tue Aug 18 12:53:09.703261 2026] [autoindex:error] [pid 66623:tid 66811] [client 52.139.47.57:0] AH01276: Cannot serve directory /home4/spilwf01/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:09.741038 2026] [security2:error] [pid 66623:tid 66825] [client 192.141.172.134:49714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5dO5rbWdOArH04J1uQAAAUU"] [Tue Aug 18 12:53:09.741186 2026] [security2:error] [pid 66623:tid 66825] [client 192.141.172.134:49714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5dO5rbWdOArH04J1uQAAAUU"] [Tue Aug 18 12:53:09.747352 2026] [autoindex:error] [pid 66623:tid 66793] [client 4.223.164.152:46149] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:09.804764 2026] [security2:error] [pid 66623:tid 66810] [client 20.119.58.187:15357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/admin-post.php"] [unique_id "aoR_5dO5rbWdOArH04J1vQAAATY"] [Tue Aug 18 12:53:09.811965 2026] [security2:error] [pid 66623:tid 66641] [remote 57.141.22.92:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J1wAABhgQ"] [Tue Aug 18 12:53:09.818782 2026] [authz_core:error] [pid 66623:tid 66843] [client 192.178.4.133:64201] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:09.819032 2026] [authz_core:error] [pid 66623:tid 66843] [client 192.178.4.133:64201] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:09.856107 2026] [security2:error] [pid 66623:tid 66649] [remote 57.141.22.18:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J10AABHww"] [Tue Aug 18 12:53:09.856527 2026] [security2:error] [pid 66623:tid 66663] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J11gABFho"] [Tue Aug 18 12:53:09.866978 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:09.867513 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:09.871467 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:09.871980 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:18307] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:09.895835 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoR_5dO5rbWdOArH04J15wAAASw"] [Tue Aug 18 12:53:09.903755 2026] [security2:error] [pid 66623:tid 66677] [remote 57.141.22.7:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5dO5rbWdOArH04J16QABaSg"] [Tue Aug 18 12:53:09.955785 2026] [autoindex:error] [pid 66623:tid 66869] [client 20.91.215.254:12614] AH01276: Cannot serve directory /home3/aceunai/public_html/abraceocomerciodeunai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:09.973232 2026] [security2:error] [pid 66623:tid 66679] [remote 159.69.192.98:33246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.192.69.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoR_5dO5rbWdOArH04J18AABbSo"] [Tue Aug 18 12:53:09.984271 2026] [security2:error] [pid 66623:tid 66779] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5dO5rbWdOArH04J18wAAARc"] [Tue Aug 18 12:53:10.021323 2026] [security2:error] [pid 66623:tid 66690] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5tO5rbWdOArH04J1-wABWTU"] [Tue Aug 18 12:53:10.028561 2026] [security2:error] [pid 66623:tid 66841] [client 213.35.127.232:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_5tO5rbWdOArH04J1_wAAAVU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:10.033780 2026] [security2:error] [pid 66623:tid 66838] [client 20.42.19.40:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/simple.php"] [unique_id "aoR_5tO5rbWdOArH04J2AgAAAVI"] [Tue Aug 18 12:53:10.035857 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoR_5tO5rbWdOArH04J2AwAAAVk"] [Tue Aug 18 12:53:10.043016 2026] [security2:error] [pid 66623:tid 66830] [client 52.139.47.57:39517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/pwnd/as.php"] [unique_id "aoR_5tO5rbWdOArH04J2BAAAAUo"] [Tue Aug 18 12:53:10.069551 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/adminner.php"] [unique_id "aoR_5tO5rbWdOArH04J2CQAAAVk"] [Tue Aug 18 12:53:10.108596 2026] [security2:error] [pid 66623:tid 66830] [client 192.141.172.134:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2DgAAAUo"] [Tue Aug 18 12:53:10.108902 2026] [security2:error] [pid 66623:tid 66830] [client 192.141.172.134:50021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2DgAAAUo"] [Tue Aug 18 12:53:10.117368 2026] [security2:error] [pid 66623:tid 66787] [client 68.221.73.131:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/adminner.php"] [unique_id "aoR_5tO5rbWdOArH04J2DwAAAR8"] [Tue Aug 18 12:53:10.127756 2026] [security2:error] [pid 66623:tid 66702] [remote 66.102.134.13:49070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2EAABdkE"] [Tue Aug 18 12:53:10.130507 2026] [security2:error] [pid 66623:tid 66790] [client 20.250.27.191:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/nofile.php"] [unique_id "aoR_5tO5rbWdOArH04J2EQAAASI"] [Tue Aug 18 12:53:10.152511 2026] [security2:error] [pid 66623:tid 66703] [remote 72.167.40.62:53450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2EgABH0I"] [Tue Aug 18 12:53:10.156510 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoR_5tO5rbWdOArH04J2FAAAARI"] [Tue Aug 18 12:53:10.160502 2026] [security2:error] [pid 66623:tid 66890] [client 20.65.69.59:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/payout.php"] [unique_id "aoR_5tO5rbWdOArH04J2FQAAAYY"] [Tue Aug 18 12:53:10.182887 2026] [security2:error] [pid 66623:tid 66709] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/media.php"] [unique_id "aoR_5tO5rbWdOArH04J2GgABdkg"] [Tue Aug 18 12:53:10.188660 2026] [security2:error] [pid 66623:tid 66710] [remote 74.220.219.216:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2GwABfEk"] [Tue Aug 18 12:53:10.189507 2026] [security2:error] [pid 66623:tid 66844] [client 20.91.215.254:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/mah/function.php"] [unique_id "aoR_5tO5rbWdOArH04J2HgAAAVg"] [Tue Aug 18 12:53:10.192673 2026] [security2:error] [pid 66623:tid 66712] [remote 46.62.208.238:53350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2HQABg0s"] [Tue Aug 18 12:53:10.212391 2026] [security2:error] [pid 66623:tid 66852] [client 4.223.164.152:6893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-blog.php"] [unique_id "aoR_5tO5rbWdOArH04J2JAAAAWA"] [Tue Aug 18 12:53:10.219913 2026] [security2:error] [pid 66623:tid 66788] [client 74.7.244.15:45094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jx2.com.br.jx2sitesprofissionais.com"] [uri "/index.php"] [unique_id "aoR_5dO5rbWdOArH04J14AABIB8"] [Tue Aug 18 12:53:10.221510 2026] [authz_core:error] [pid 66623:tid 66715] [remote 57.141.22.51:27560] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:10.221932 2026] [authz_core:error] [pid 66623:tid 66715] [remote 57.141.22.51:27560] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:10.223800 2026] [security2:error] [pid 66623:tid 66875] [client 149.34.210.141:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2KAAAAXc"] [Tue Aug 18 12:53:10.232474 2026] [security2:error] [pid 66623:tid 66877] [client 45.92.229.104:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2JwAAAXk"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:53:10.252772 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:27708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/fone1.php"] [unique_id "aoR_5tO5rbWdOArH04J2LAAAAX4"] [Tue Aug 18 12:53:10.340155 2026] [security2:error] [pid 66623:tid 66799] [client 20.119.58.187:15315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "aoR_5tO5rbWdOArH04J2RAAAASs"] [Tue Aug 18 12:53:10.347687 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/admin.php"] [unique_id "aoR_5tO5rbWdOArH04J2RwABemw"] [Tue Aug 18 12:53:10.362540 2026] [security2:error] [pid 66623:tid 66790] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5tO5rbWdOArH04J2TgAAASI"] [Tue Aug 18 12:53:10.373451 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bgymj.php"] [unique_id "aoR_5tO5rbWdOArH04J2XgAAAQ4"] [Tue Aug 18 12:53:10.376971 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.200.96:14200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/oivcl.php"] [unique_id "aoR_5tO5rbWdOArH04J2XwAAASI"] [Tue Aug 18 12:53:10.386018 2026] [security2:error] [pid 66623:tid 66781] [client 213.232.122.14:64853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J1_QAAARk"] [Tue Aug 18 12:53:10.403090 2026] [security2:error] [pid 66623:tid 66798] [client 4.223.164.152:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/pucci.php"] [unique_id "aoR_5tO5rbWdOArH04J2YQAAASo"] [Tue Aug 18 12:53:10.406765 2026] [lsapi:error] [pid 66623:tid 66823] [client 192.178.4.5:61914] [host csleducacional.com.br] Backend fatal error: PHP Fatal error: Uncaught TypeError: implode(): Argument #2 ($array) must be of type ?array, string given in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php:528\nStack trace:\n#0 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(528): implode(Array, '|')\n#1 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(314): MatthiasMullie\\Minify\\CSS->shortenColors('.elementor-kit-...')\n#2 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/Minify.php(111): MatthiasMullie\\Minify\\CSS->execute(NULL)\n#3 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(175): MatthiasMullie\\Minify\\Minify->minify()\n#4 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(128): WP_Rocket\\Optimization\\CSS\\Minify->minify('/home3/csleduca...', '/home3/csleduca...')\n#5 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(66): WP_Rocket\\Optimization\\CSS\\Minify->replace_url('https://csleduc...')\n#6 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-abstract-minify-subscriber.php(85): WP_Rocket\\Optimization\\CSS\\Minify->optimize('...')\n#7 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-minify-css-subscriber.php(44): WP_Rocket\\Subscriber\\Optimization\\Minify_Subscriber->optimize('...')\n#8 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): WP_Rocket\\Subscriber\\Optimization\\Minify_CSS_Subscriber->process('...')\n#9 /home3/csleduca/public_html/wp-includes/plugin.php(205): WP_Hook->apply_filters('...', Array)\n#10 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/Buffer/class-optimization.php(104): apply_filters('rocket_buffer', '...')\n#11 [internal function]: WP_Rocket\\Buffer\\Optimization->maybe_process_buffer('...', 9)\n#12 /home3/csleduca/public_html/wp-includes/functions.php(5493): ob_end_flush()\n#13 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): wp_ob_end_flush_all('')\n#14 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(365): WP_Hook->apply_filters(NULL, Array)\n#15 /home3/csleduca/public_html/wp-includes/plugin.php(522): WP_Hook->do_action(Array)\n#16 /home3/csleduca/public_html/wp-includes/load.php(1308): do_action('shutdown')\n#17 [internal function]: shutdown_action_hook()\n#18 {main}\n thrown in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php on line 528\n [Tue Aug 18 12:53:10.425524 2026] [security2:error] [pid 66623:tid 66883] [client 160.120.140.123:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2YgAAAX8"] [Tue Aug 18 12:53:10.425744 2026] [security2:error] [pid 66623:tid 66883] [client 160.120.140.123:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2YgAAAX8"] [Tue Aug 18 12:53:10.461444 2026] [security2:error] [pid 66623:tid 66879] [client 178.153.171.161:64444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZAAAAXs"] [Tue Aug 18 12:53:10.461632 2026] [security2:error] [pid 66623:tid 66879] [client 178.153.171.161:64444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZAAAAXs"] [Tue Aug 18 12:53:10.478546 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:29246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ry.php"] [unique_id "aoR_5tO5rbWdOArH04J2ZgAAAWA"] [Tue Aug 18 12:53:10.491126 2026] [security2:error] [pid 66623:tid 66800] [client 20.65.69.59:60126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/bh.php"] [unique_id "aoR_5tO5rbWdOArH04J2aAAAASw"] [Tue Aug 18 12:53:10.491426 2026] [security2:error] [pid 66623:tid 66875] [client 149.34.210.141:56234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2KAAAAXc"] [Tue Aug 18 12:53:10.518786 2026] [security2:error] [pid 66623:tid 66799] [client 20.104.100.201:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/az.php"] [unique_id "aoR_5tO5rbWdOArH04J2agAAASs"] [Tue Aug 18 12:53:10.519307 2026] [security2:error] [pid 66623:tid 66674] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/mac.php"] [unique_id "aoR_5tO5rbWdOArH04J2aQABIyU"] [Tue Aug 18 12:53:10.543190 2026] [security2:error] [pid 66623:tid 66838] [client 132.196.61.152:54746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file1221.php"] [unique_id "aoR_5tO5rbWdOArH04J2awAAAVI"] [Tue Aug 18 12:53:10.556727 2026] [security2:error] [pid 66623:tid 66883] [client 68.221.73.131:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/file1221.php"] [unique_id "aoR_5tO5rbWdOArH04J2bAAAAX8"] [Tue Aug 18 12:53:10.585175 2026] [security2:error] [pid 66623:tid 66869] [client 158.158.74.177:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoR_5tO5rbWdOArH04J2cgAAAXE"] [Tue Aug 18 12:53:10.609200 2026] [security2:error] [pid 66623:tid 66794] [client 20.250.27.191:7889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/fling.php"] [unique_id "aoR_5tO5rbWdOArH04J2dQAAASY"] [Tue Aug 18 12:53:10.635149 2026] [security2:error] [pid 66623:tid 66788] [client 52.173.121.69:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR_5tO5rbWdOArH04J2dwAAASA"] [Tue Aug 18 12:53:10.692652 2026] [http2:info] [pid 67073:tid 67073] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 12:53:10.695349 2026] [security2:error] [pid 66623:tid 66885] [client 74.248.18.37:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp.php"] [unique_id "aoR_5tO5rbWdOArH04J2fgAAAYE"] [Tue Aug 18 12:53:10.701140 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/dropdown.php"] [unique_id "aoR_5tO5rbWdOArH04J2gAAAASg"] [Tue Aug 18 12:53:10.704198 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.154.236:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_5tO5rbWdOArH04J2gQAAASM"] [Tue Aug 18 12:53:10.708493 2026] [security2:error] [pid 66623:tid 66792] [client 47.128.54.59:51252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aesexaustores.com.br"] [uri "/robots.txt"] [unique_id "aoR_5tO5rbWdOArH04J2ggAAASQ"] [Tue Aug 18 12:53:10.717259 2026] [security2:error] [pid 66623:tid 66694] [remote 20.250.27.191:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "paypix.co"] [uri "/1.php"] [unique_id "aoR_5tO5rbWdOArH04J2gwABeTk"] [Tue Aug 18 12:53:10.717405 2026] [security2:error] [pid 66623:tid 66694] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1.php"] [unique_id "aoR_5tO5rbWdOArH04J2gwABeTk"] [Tue Aug 18 12:53:10.718251 2026] [security2:error] [pid 66623:tid 66694] [remote 72.167.40.62:42624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoR_5tO5rbWdOArH04J2hAABEjk"] [Tue Aug 18 12:53:10.720572 2026] [security2:error] [pid 66623:tid 66779] [client 85.154.68.202:56134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2hQAAARc"] [Tue Aug 18 12:53:10.720846 2026] [security2:error] [pid 66623:tid 66779] [client 85.154.68.202:56134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2hQAAARc"] [Tue Aug 18 12:53:10.728253 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_5tO5rbWdOArH04J2hwAAARs"] [Tue Aug 18 12:53:10.828807 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/lock360.php"] [unique_id "aoR_5tO5rbWdOArH04J2lAAAATo"] [Tue Aug 18 12:53:10.831340 2026] [security2:error] [pid 66623:tid 66889] [client 34.178.149.167:45784] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/database.sql"] [unique_id "aoR_5tO5rbWdOArH04J2lgAAAYU"] [Tue Aug 18 12:53:10.832330 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2lQAAAVo"] [Tue Aug 18 12:53:10.832463 2026] [security2:error] [pid 67073:tid 67208] [client 132.196.61.152:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/inx.php"] [unique_id "aoR_5vcmepr5_nHgLbMpXAAAAhc"] [Tue Aug 18 12:53:10.832481 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2lQAAAVo"] [Tue Aug 18 12:53:10.836580 2026] [security2:error] [pid 67073:tid 67206] [client 20.42.19.40:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoR_5vcmepr5_nHgLbMpXQAAAhU"] [Tue Aug 18 12:53:10.848162 2026] [security2:error] [pid 66623:tid 66860] [client 34.178.149.167:45782] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoR_5tO5rbWdOArH04J2mQAAAWg"] [Tue Aug 18 12:53:10.850319 2026] [security2:error] [pid 66623:tid 66772] [client 34.178.149.167:45778] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/telescope/requests"] [unique_id "aoR_5tO5rbWdOArH04J2nAAAARA"] [Tue Aug 18 12:53:10.852348 2026] [security2:error] [pid 66623:tid 66837] [client 168.62.48.100:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_5tO5rbWdOArH04J2ngAAAVE"] [Tue Aug 18 12:53:10.854752 2026] [security2:error] [pid 66623:tid 66785] [client 34.178.149.167:45748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/dump.sql"] [unique_id "aoR_5tO5rbWdOArH04J2mgAAAR0"] [Tue Aug 18 12:53:10.857779 2026] [security2:error] [pid 66623:tid 66789] [client 34.178.149.167:45722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/backup.sql"] [unique_id "aoR_5tO5rbWdOArH04J2oAAAASE"] [Tue Aug 18 12:53:10.877489 2026] [security2:error] [pid 66623:tid 66848] [client 34.178.149.167:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.149.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blueorbit.com.br"] [uri "/info.php"] [unique_id "aoR_5tO5rbWdOArH04J2pgAAAVw"] [Tue Aug 18 12:53:10.878806 2026] [security2:error] [pid 66623:tid 66704] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/coffee.php"] [unique_id "aoR_5tO5rbWdOArH04J2pwABcUM"] [Tue Aug 18 12:53:10.887874 2026] [security2:error] [pid 66623:tid 66787] [client 20.65.69.59:36362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/ct.php"] [unique_id "aoR_5tO5rbWdOArH04J2qAAAAR8"] [Tue Aug 18 12:53:10.894717 2026] [autoindex:error] [pid 66623:tid 66847] [client 4.223.164.152:37301] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:10.899902 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2qgAAAXU"] [Tue Aug 18 12:53:10.900056 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_5tO5rbWdOArH04J2qgAAAXU"] [Tue Aug 18 12:53:10.959603 2026] [security2:error] [pid 66623:tid 66770] [client 34.178.149.167:45846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoR_5tO5rbWdOArH04J2rwAAAQ4"] [Tue Aug 18 12:53:10.980620 2026] [security2:error] [pid 66623:tid 66852] [client 68.221.73.131:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/inx.php"] [unique_id "aoR_5tO5rbWdOArH04J2sQAAAWA"] [Tue Aug 18 12:53:11.004383 2026] [security2:error] [pid 67073:tid 67218] [client 20.48.236.86:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/media.php"] [unique_id "aoR_5_cmepr5_nHgLbMpYQAAAiE"] [Tue Aug 18 12:53:11.018086 2026] [security2:error] [pid 66623:tid 66836] [client 74.248.18.37:41349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/ncx.php"] [unique_id "aoR_59O5rbWdOArH04J2vAAAAVA"] [Tue Aug 18 12:53:11.049048 2026] [security2:error] [pid 66623:tid 66676] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/classwithtostring.php"] [unique_id "aoR_59O5rbWdOArH04J2wAABKyc"] [Tue Aug 18 12:53:11.068461 2026] [security2:error] [pid 66623:tid 66866] [client 20.250.27.191:7934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/zoo1.php"] [unique_id "aoR_59O5rbWdOArH04J21gAAAW4"] [Tue Aug 18 12:53:11.072039 2026] [security2:error] [pid 67073:tid 67205] [client 213.35.127.232:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_5_cmepr5_nHgLbMpYwAAAhQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:11.076736 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:15323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/index.php"] [unique_id "aoR_59O5rbWdOArH04J25QAAARY"] [Tue Aug 18 12:53:11.089553 2026] [security2:error] [pid 67073:tid 67220] [client 168.62.48.100:16318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZAAAAiM"] [Tue Aug 18 12:53:11.130040 2026] [security2:error] [pid 67073:tid 67221] [client 4.223.164.152:6613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/adminfuns.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZQAAAiQ"] [Tue Aug 18 12:53:11.172731 2026] [security2:error] [pid 66623:tid 66808] [client 132.196.61.152:23817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/reviall.php"] [unique_id "aoR_59O5rbWdOArH04J2-wAAATQ"] [Tue Aug 18 12:53:11.223516 2026] [security2:error] [pid 66623:tid 66692] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-ws68.php"] [unique_id "aoR_59O5rbWdOArH04J3BQABXzc"] [Tue Aug 18 12:53:11.238679 2026] [security2:error] [pid 66623:tid 66819] [client 20.171.51.14:29193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pm.php"] [unique_id "aoR_59O5rbWdOArH04J3BwAAAT8"] [Tue Aug 18 12:53:11.240284 2026] [security2:error] [pid 67073:tid 67227] [client 20.65.69.59:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/gy.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZgAAAio"] [Tue Aug 18 12:53:11.264672 2026] [security2:error] [pid 66623:tid 66885] [client 158.158.74.177:14258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/lite.php"] [unique_id "aoR_59O5rbWdOArH04J3CQAAAYE"] [Tue Aug 18 12:53:11.277928 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/rk2.php"] [unique_id "aoR_5_cmepr5_nHgLbMpZwAAAho"] [Tue Aug 18 12:53:11.282064 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_5_cmepr5_nHgLbMpaAAAAis"] [Tue Aug 18 12:53:11.318530 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:20716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/eh.php"] [unique_id "aoR_5_cmepr5_nHgLbMpaQAAAi0"] [Tue Aug 18 12:53:11.325691 2026] [security2:error] [pid 67073:tid 67229] [client 168.62.48.100:14828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/weozh.php"] [unique_id "aoR_5_cmepr5_nHgLbMpagAAAiw"] [Tue Aug 18 12:53:11.328590 2026] [security2:error] [pid 66623:tid 66767] [client 20.91.215.254:20262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/filter.php"] [unique_id "aoR_59O5rbWdOArH04J3GQAAAQs"] [Tue Aug 18 12:53:11.332738 2026] [autoindex:error] [pid 66623:tid 66882] [client 4.223.164.152:37301] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:11.340513 2026] [security2:error] [pid 66623:tid 66704] [remote 115.146.125.52:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoR_59O5rbWdOArH04J3GgABcEM"] [Tue Aug 18 12:53:11.341762 2026] [security2:error] [pid 66623:tid 66873] [client 52.238.210.254:10113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_59O5rbWdOArH04J3GwAAAXU"] [Tue Aug 18 12:53:11.397084 2026] [security2:error] [pid 67073:tid 67209] [client 34.178.149.167:45876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/trace.axd"] [unique_id "aoR_5_cmepr5_nHgLbMpawAAAhg"] [Tue Aug 18 12:53:11.404687 2026] [security2:error] [pid 66623:tid 66668] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/yj09.php"] [unique_id "aoR_59O5rbWdOArH04J3JAABDh8"] [Tue Aug 18 12:53:11.422794 2026] [security2:error] [pid 66623:tid 66852] [client 68.221.73.131:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/reviall.php"] [unique_id "aoR_59O5rbWdOArH04J3KAAAAWA"] [Tue Aug 18 12:53:11.423463 2026] [security2:error] [pid 66623:tid 66705] [remote 162.43.94.44:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.94.43.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoR_59O5rbWdOArH04J3JwABNUQ"] [Tue Aug 18 12:53:11.426626 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:40261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/thoms.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbAAAAjI"] [Tue Aug 18 12:53:11.432497 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/about.php7"] [unique_id "aoR_59O5rbWdOArH04J3KQAAAQ0"] [Tue Aug 18 12:53:11.458500 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:62382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/log.php"] [unique_id "aoR_59O5rbWdOArH04J3LAAAAUA"] [Tue Aug 18 12:53:11.458681 2026] [security2:error] [pid 67073:tid 67233] [client 20.42.19.40:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/av.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbgAAAjA"] [Tue Aug 18 12:53:11.464847 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR_5_cmepr5_nHgLbMpbwAAAjc"] [Tue Aug 18 12:53:11.489805 2026] [security2:error] [pid 66623:tid 66840] [client 74.7.175.149:42912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "caiosousamendes.adv.br"] [uri "/index.php"] [unique_id "aoR_5dO5rbWdOArH04J1zwABVBU"] [Tue Aug 18 12:53:11.517246 2026] [security2:error] [pid 67073:tid 67244] [client 20.250.27.191:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/zoo2.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcAAAAjs"] [Tue Aug 18 12:53:11.522841 2026] [security2:error] [pid 67073:tid 67246] [client 172.182.200.96:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/zugvi.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcQAAAj0"] [Tue Aug 18 12:53:11.527243 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.61.152:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/11.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcgAAAj4"] [Tue Aug 18 12:53:11.533911 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.100.201:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/z43agz.php"] [unique_id "aoR_59O5rbWdOArH04J3QQAAAWQ"] [Tue Aug 18 12:53:11.542198 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:37301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-temp.php"] [unique_id "aoR_59O5rbWdOArH04J3QgAAATA"] [Tue Aug 18 12:53:11.563639 2026] [security2:error] [pid 67073:tid 67248] [client 158.23.17.4:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/vd.php"] [unique_id "aoR_5_cmepr5_nHgLbMpcwAAAj8"] [Tue Aug 18 12:53:11.564112 2026] [deflate:error] [pid 66623:tid 66821] (104)Connection reset by peer: [client 213.232.122.14:64419] AH10298: failed reading from PIPE bucket [Tue Aug 18 12:53:11.582092 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/scxy.php"] [unique_id "aoR_59O5rbWdOArH04J3RwABKlw"] [Tue Aug 18 12:53:11.609008 2026] [security2:error] [pid 67073:tid 67252] [client 168.62.48.100:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/rymmm.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdAAAAkM"] [Tue Aug 18 12:53:11.613879 2026] [security2:error] [pid 67073:tid 67255] [client 20.171.51.14:29210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ud.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdQAAAkY"] [Tue Aug 18 12:53:11.625057 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/xx.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdgAAAkc"] [Tue Aug 18 12:53:11.664706 2026] [security2:error] [pid 67073:tid 67257] [client 20.65.69.59:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/tt.php"] [unique_id "aoR_5_cmepr5_nHgLbMpdwAAAkg"] [Tue Aug 18 12:53:11.676186 2026] [security2:error] [pid 67073:tid 67203] [remote 57.141.22.86:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_5_cmepr5_nHgLbMpeAACQX8"] [Tue Aug 18 12:53:11.738770 2026] [security2:error] [pid 66623:tid 66753] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoR_59O5rbWdOArH04J3VQABg3Q"] [Tue Aug 18 12:53:11.743661 2026] [security2:error] [pid 67073:tid 67268] [client 111.225.149.166:42678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2018/04/Bianca-Pereira-e-Marcos-Nascimento-400x284.jpg"] [unique_id "aoR_5_cmepr5_nHgLbMpegAAAlM"] [Tue Aug 18 12:53:11.745439 2026] [security2:error] [pid 67073:tid 67269] [client 4.223.164.152:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/ms-edit.php"] [unique_id "aoR_5_cmepr5_nHgLbMpewAAAlQ"] [Tue Aug 18 12:53:11.768001 2026] [security2:error] [pid 67073:tid 67077] [remote 108.167.161.133:41210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoR_5_cmepr5_nHgLbMpfQACVgE"] [Tue Aug 18 12:53:11.789330 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:15339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/adminfuns.php7"] [unique_id "aoR_59O5rbWdOArH04J3WwAAAUU"] [Tue Aug 18 12:53:11.825117 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.61.152:25677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/File.php"] [unique_id "aoR_5_cmepr5_nHgLbMpfwAAAl0"] [Tue Aug 18 12:53:11.837584 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.154.236:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_59O5rbWdOArH04J3YQAAAV8"] [Tue Aug 18 12:53:11.842132 2026] [security2:error] [pid 67073:tid 67280] [client 68.221.73.131:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/11.php"] [unique_id "aoR_5_cmepr5_nHgLbMpgAAAAl8"] [Tue Aug 18 12:53:11.845766 2026] [security2:error] [pid 67073:tid 67281] [client 168.62.48.100:14784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/lddxs.php"] [unique_id "aoR_5_cmepr5_nHgLbMpgQAAAmA"] [Tue Aug 18 12:53:11.894875 2026] [security2:error] [pid 66623:tid 66854] [client 34.178.149.167:45860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/.bash_history"] [unique_id "aoR_59O5rbWdOArH04J3ZAAAAWI"] [Tue Aug 18 12:53:11.921312 2026] [security2:error] [pid 66623:tid 66682] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_59O5rbWdOArH04J3aAABIS0"] [Tue Aug 18 12:53:11.925582 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.74.177:13823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoR_5_cmepr5_nHgLbMphAAAAkw"] [Tue Aug 18 12:53:11.928017 2026] [security2:error] [pid 66623:tid 66787] [client 20.48.236.86:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/images.php"] [unique_id "aoR_59O5rbWdOArH04J3aQAAAR8"] [Tue Aug 18 12:53:11.967556 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/av.php"] [unique_id "aoR_59O5rbWdOArH04J3cQAAAVs"] [Tue Aug 18 12:53:11.982493 2026] [security2:error] [pid 66623:tid 66882] [client 172.182.200.96:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wsrer.php"] [unique_id "aoR_59O5rbWdOArH04J3cwAAAX4"] [Tue Aug 18 12:53:11.983290 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_59O5rbWdOArH04J3dAAAAXA"] [Tue Aug 18 12:53:11.993562 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.27.191:7401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/org.php"] [unique_id "aoR_5_cmepr5_nHgLbMphQAAAmk"] [Tue Aug 18 12:53:11.997147 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:33319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/mq.php"] [unique_id "aoR_59O5rbWdOArH04J3dQAAAUQ"] [Tue Aug 18 12:53:12.020731 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:27654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ethosconsult.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_6NO5rbWdOArH04J3eQAAARk"] [Tue Aug 18 12:53:12.032015 2026] [security2:error] [pid 66623:tid 66672] [remote 57.141.22.115:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6NO5rbWdOArH04J3egABcSM"] [Tue Aug 18 12:53:12.035055 2026] [security2:error] [pid 67073:tid 67080] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMphwACUQQ"] [Tue Aug 18 12:53:12.035311 2026] [security2:error] [pid 67073:tid 67266] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMphwACUQQ"] [Tue Aug 18 12:53:12.082899 2026] [security2:error] [pid 66623:tid 66679] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/blurbs.php"] [unique_id "aoR_6NO5rbWdOArH04J3ewABDio"] [Tue Aug 18 12:53:12.091212 2026] [security2:error] [pid 67073:tid 67298] [client 168.62.48.100:14786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zjggu.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpiwAAAnE"] [Tue Aug 18 12:53:12.091711 2026] [security2:error] [pid 67073:tid 67270] [client 213.35.127.232:64631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjAAAAlU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:12.097221 2026] [security2:error] [pid 66623:tid 66802] [client 74.248.18.37:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/lv.php"] [unique_id "aoR_6NO5rbWdOArH04J3fgAAAS4"] [Tue Aug 18 12:53:12.099125 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:12.099574 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:12.099591 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:12.100046 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:12.144345 2026] [security2:error] [pid 66623:tid 66788] [client 132.196.61.152:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/fi22.php"] [unique_id "aoR_6NO5rbWdOArH04J3gAAAASA"] [Tue Aug 18 12:53:12.154703 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ebs.php7"] [unique_id "aoR_6Pcmepr5_nHgLbMpjQAAAms"] [Tue Aug 18 12:53:12.196916 2026] [security2:error] [pid 66623:tid 66873] [client 20.91.215.254:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/input.php"] [unique_id "aoR_6NO5rbWdOArH04J3gwAAAXU"] [Tue Aug 18 12:53:12.235381 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:15100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/atex1.php"] [unique_id "aoR_6NO5rbWdOArH04J3hQAAARg"] [Tue Aug 18 12:53:12.243017 2026] [security2:error] [pid 67073:tid 67309] [client 4.223.164.152:6604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/222.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjgAAAnw"] [Tue Aug 18 12:53:12.264667 2026] [security2:error] [pid 66623:tid 66815] [client 4.232.151.198:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/666.php"] [unique_id "aoR_6NO5rbWdOArH04J3hwAAATs"] [Tue Aug 18 12:53:12.272448 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/01.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpjwAAAn4"] [Tue Aug 18 12:53:12.275524 2026] [security2:error] [pid 66623:tid 66714] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/bajah.php"] [unique_id "aoR_6NO5rbWdOArH04J3iAABck0"] [Tue Aug 18 12:53:12.291388 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:12.291831 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:54798] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:12.295676 2026] [security2:error] [pid 66623:tid 66799] [client 68.221.73.131:4843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/File.php"] [unique_id "aoR_6NO5rbWdOArH04J3jQAAASs"] [Tue Aug 18 12:53:12.300285 2026] [security2:error] [pid 66623:tid 66796] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/media.php"] [unique_id "aoR_6NO5rbWdOArH04J3jgAAASg"] [Tue Aug 18 12:53:12.324850 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:14787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/dlvqo.php"] [unique_id "aoR_6NO5rbWdOArH04J3kAAAAYc"] [Tue Aug 18 12:53:12.402007 2026] [security2:error] [pid 66623:tid 66774] [client 20.250.27.191:7928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/imageskir.php"] [unique_id "aoR_6NO5rbWdOArH04J3lgAAARI"] [Tue Aug 18 12:53:12.411049 2026] [security2:error] [pid 66623:tid 66877] [client 20.65.69.59:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/13.php"] [unique_id "aoR_6NO5rbWdOArH04J3mAAAAXk"] [Tue Aug 18 12:53:12.422055 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/simple.php"] [unique_id "aoR_6Pcmepr5_nHgLbMplQAAAjE"] [Tue Aug 18 12:53:12.458057 2026] [security2:error] [pid 66623:tid 66861] [client 149.34.210.157:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3pAAAAWk"] [Tue Aug 18 12:53:12.478006 2026] [security2:error] [pid 66623:tid 66709] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/domvf.php"] [unique_id "aoR_6NO5rbWdOArH04J3rAABhEg"] [Tue Aug 18 12:53:12.508746 2026] [security2:error] [pid 67073:tid 67318] [client 20.119.58.187:15358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ws.php7"] [unique_id "aoR_6Pcmepr5_nHgLbMplgAAAoU"] [Tue Aug 18 12:53:12.512743 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:53863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/3.php"] [unique_id "aoR_6Pcmepr5_nHgLbMplwAAAow"] [Tue Aug 18 12:53:12.545402 2026] [security2:error] [pid 66623:tid 66833] [client 20.171.51.14:58839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ip.php"] [unique_id "aoR_6NO5rbWdOArH04J3swAAAU0"] [Tue Aug 18 12:53:12.549771 2026] [security2:error] [pid 66623:tid 66812] [client 34.178.149.167:45924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoR_6NO5rbWdOArH04J3tAAAATg"] [Tue Aug 18 12:53:12.561620 2026] [security2:error] [pid 66623:tid 66801] [client 74.248.136.165:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/06.php"] [unique_id "aoR_6NO5rbWdOArH04J3uAAAAS0"] [Tue Aug 18 12:53:12.564474 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:37263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/puc.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpmAAAAo0"] [Tue Aug 18 12:53:12.565931 2026] [security2:error] [pid 67073:tid 67327] [client 168.62.48.100:14799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/pkmoj.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpmQAAAo4"] [Tue Aug 18 12:53:12.579670 2026] [security2:error] [pid 66623:tid 66803] [client 74.7.175.149:42924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.caiosousamendes.adv.br"] [uri "/index.php"] [unique_id "aoR_6NO5rbWdOArH04J3rQABLxI"], referer: https://caiosousamendes.adv.br/robots.txt [Tue Aug 18 12:53:12.580215 2026] [security2:error] [pid 66623:tid 66854] [client 132.196.61.152:7868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_6NO5rbWdOArH04J3vAAAAWI"] [Tue Aug 18 12:53:12.624434 2026] [security2:error] [pid 67073:tid 67315] [client 158.158.74.177:13771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnAAAAoI"] [Tue Aug 18 12:53:12.636682 2026] [security2:error] [pid 66623:tid 66658] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fpwch.php"] [unique_id "aoR_6NO5rbWdOArH04J3vwABWxU"] [Tue Aug 18 12:53:12.644375 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/images.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnQAAApM"] [Tue Aug 18 12:53:12.659576 2026] [security2:error] [pid 67073:tid 67300] [client 74.249.206.207:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpngAAAnM"] [Tue Aug 18 12:53:12.665636 2026] [security2:error] [pid 66623:tid 66845] [client 213.232.122.14:39897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3wwAAAVk"] [Tue Aug 18 12:53:12.668533 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpnwAAAnQ"] [Tue Aug 18 12:53:12.670482 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.200.96:14163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/ucpfr.php"] [unique_id "aoR_6NO5rbWdOArH04J3xQAAAUQ"] [Tue Aug 18 12:53:12.687146 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cgi-bin/index.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpoAAAAhs"] [Tue Aug 18 12:53:12.720341 2026] [security2:error] [pid 66623:tid 66841] [client 20.151.109.219:33502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ad.php"] [unique_id "aoR_6NO5rbWdOArH04J3yAAAAVU"] [Tue Aug 18 12:53:12.725349 2026] [security2:error] [pid 66623:tid 66861] [client 149.34.210.157:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6NO5rbWdOArH04J3pAAAAWk"] [Tue Aug 18 12:53:12.728830 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.18.37:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mah/function.php"] [unique_id "aoR_6NO5rbWdOArH04J3ygAAARQ"] [Tue Aug 18 12:53:12.763341 2026] [security2:error] [pid 66623:tid 66793] [client 68.221.73.131:4379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/fi22.php"] [unique_id "aoR_6NO5rbWdOArH04J3zAAAASU"] [Tue Aug 18 12:53:12.804043 2026] [security2:error] [pid 67073:tid 67207] [client 168.62.48.100:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/kopyw.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpoQAAAhY"] [Tue Aug 18 12:53:12.831891 2026] [security2:error] [pid 67073:tid 67222] [client 20.250.27.191:58979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/indexo.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpogAAAiU"] [Tue Aug 18 12:53:12.840200 2026] [security2:error] [pid 67073:tid 67223] [client 52.238.210.254:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/php8.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpowAAAiY"] [Tue Aug 18 12:53:12.871124 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/alfanew2.php7"] [unique_id "aoR_6NO5rbWdOArH04J30gAAAXo"] [Tue Aug 18 12:53:12.884841 2026] [security2:error] [pid 66623:tid 66755] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/adminner.php"] [unique_id "aoR_6NO5rbWdOArH04J30wABgnY"] [Tue Aug 18 12:53:12.912285 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppAAAAis"] [Tue Aug 18 12:53:12.943303 2026] [security2:error] [pid 66623:tid 66873] [client 132.196.61.152:38353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR_6NO5rbWdOArH04J31QAAAXU"] [Tue Aug 18 12:53:12.974634 2026] [security2:error] [pid 67073:tid 67209] [client 20.171.51.14:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dr.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppgAAAhg"] [Tue Aug 18 12:53:12.983931 2026] [security2:error] [pid 67073:tid 67231] [client 20.48.236.86:65130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/admin.php"] [unique_id "aoR_6Pcmepr5_nHgLbMppwAAAi4"] [Tue Aug 18 12:53:12.984871 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/mac.php"] [unique_id "aoR_6Pcmepr5_nHgLbMpqAAAAi8"] [Tue Aug 18 12:53:13.016920 2026] [security2:error] [pid 66623:tid 66809] [client 5.253.205.188:60996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/error_reportinstallmysql.sql"] [unique_id "aoR_6dO5rbWdOArH04J31wAAATU"], referer: https://medihub.com.br/error_reportinstallmysql.sql [Tue Aug 18 12:53:13.038595 2026] [security2:error] [pid 67073:tid 67233] [client 168.62.48.100:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zznmg.php"] [unique_id "aoR_6fcmepr5_nHgLbMpqgAAAjA"] [Tue Aug 18 12:53:13.054660 2026] [autoindex:error] [pid 67073:tid 67240] [client 4.223.164.152:37271] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:13.060016 2026] [security2:error] [pid 66623:tid 66749] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/abcd.php"] [unique_id "aoR_6dO5rbWdOArH04J32QABMHA"] [Tue Aug 18 12:53:13.087496 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:32675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoR_6fcmepr5_nHgLbMprgAAAj0"] [Tue Aug 18 12:53:13.104156 2026] [security2:error] [pid 66623:tid 66798] [client 20.171.51.14:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/99.php"] [unique_id "aoR_6dO5rbWdOArH04J32gAAASo"] [Tue Aug 18 12:53:13.109984 2026] [security2:error] [pid 66623:tid 66802] [client 213.35.127.232:64854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_6dO5rbWdOArH04J32wAAAS4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:13.141808 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR_6fcmepr5_nHgLbMprwAAAkU"] [Tue Aug 18 12:53:13.177916 2026] [security2:error] [pid 66623:tid 66836] [client 20.91.215.254:16676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/jquery.php"] [unique_id "aoR_6dO5rbWdOArH04J33gAAAVA"] [Tue Aug 18 12:53:13.224380 2026] [security2:error] [pid 67073:tid 67262] [client 68.221.73.131:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_6fcmepr5_nHgLbMpswAAAk0"] [Tue Aug 18 12:53:13.226418 2026] [security2:error] [pid 67073:tid 67247] [client 20.119.58.187:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/alfa-rex2.php7"] [unique_id "aoR_6fcmepr5_nHgLbMptAAAAj4"] [Tue Aug 18 12:53:13.239489 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:30180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/403.php"] [unique_id "aoR_6fcmepr5_nHgLbMpugAAAlI"] [Tue Aug 18 12:53:13.239985 2026] [security2:error] [pid 67073:tid 67265] [client 132.196.61.152:38385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_6fcmepr5_nHgLbMpuwAAAlA"] [Tue Aug 18 12:53:13.241499 2026] [security2:error] [pid 67073:tid 67268] [client 20.250.27.191:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvAAAAlM"] [Tue Aug 18 12:53:13.241730 2026] [security2:error] [pid 67073:tid 67239] [client 158.158.74.177:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvQAAAjY"] [Tue Aug 18 12:53:13.242127 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/simple.php"] [unique_id "aoR_6dO5rbWdOArH04J34AABblw"] [Tue Aug 18 12:53:13.246772 2026] [security2:error] [pid 66623:tid 66805] [client 68.155.154.236:65196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_6dO5rbWdOArH04J34QAAATE"] [Tue Aug 18 12:53:13.260958 2026] [security2:error] [pid 66623:tid 66774] [client 172.182.200.96:7642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/yxijx.php"] [unique_id "aoR_6dO5rbWdOArH04J34gAAARI"] [Tue Aug 18 12:53:13.276096 2026] [security2:error] [pid 66623:tid 66814] [client 168.62.48.100:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/bhfnd.php"] [unique_id "aoR_6dO5rbWdOArH04J34wAAATo"] [Tue Aug 18 12:53:13.299250 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.69.59:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/so.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvgAAAlY"] [Tue Aug 18 12:53:13.322547 2026] [security2:error] [pid 66623:tid 66834] [client 34.178.149.167:45968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/debug/default/view"] [unique_id "aoR_6dO5rbWdOArH04J36gAAAU4"] [Tue Aug 18 12:53:13.330663 2026] [security2:error] [pid 66623:tid 66781] [client 196.12.128.158:52379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6dO5rbWdOArH04J37AAAARk"] [Tue Aug 18 12:53:13.330810 2026] [security2:error] [pid 66623:tid 66781] [client 196.12.128.158:52379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_6dO5rbWdOArH04J37AAAARk"] [Tue Aug 18 12:53:13.330968 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/ops.php"] [unique_id "aoR_6fcmepr5_nHgLbMpvwAAAlk"] [Tue Aug 18 12:53:13.342971 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwAAAAlo"] [Tue Aug 18 12:53:13.392154 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:62387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/makeasmtp.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwQAAAkc"] [Tue Aug 18 12:53:13.398900 2026] [security2:error] [pid 66623:tid 66764] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-manager.php"] [unique_id "aoR_6dO5rbWdOArH04J37wABG38"] [Tue Aug 18 12:53:13.441539 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/log.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwgAAAl4"] [Tue Aug 18 12:53:13.489567 2026] [authz_core:error] [pid 66623:tid 66842] [client 34.178.149.167:45952] AH01630: client denied by server configuration: /home1/blueorbit/public_html/error_log [Tue Aug 18 12:53:13.515161 2026] [security2:error] [pid 66623:tid 66888] [client 168.62.48.100:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/qfvqu.php"] [unique_id "aoR_6dO5rbWdOArH04J38wAAAYQ"] [Tue Aug 18 12:53:13.516419 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:37271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/8.php"] [unique_id "aoR_6fcmepr5_nHgLbMpwwAAAmw"] [Tue Aug 18 12:53:13.534996 2026] [security2:error] [pid 66623:tid 66851] [client 104.209.144.33:25289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoR_6dO5rbWdOArH04J39wAAAV8"] [Tue Aug 18 12:53:13.558326 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:23808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxAAAAlU"] [Tue Aug 18 12:53:13.581170 2026] [security2:error] [pid 67073:tid 67285] [client 20.119.58.187:15147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxQAAAmQ"] [Tue Aug 18 12:53:13.604873 2026] [security2:error] [pid 66623:tid 66739] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/xiugai.php"] [unique_id "aoR_6dO5rbWdOArH04J3-QABNGY"] [Tue Aug 18 12:53:13.631128 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/er.php"] [unique_id "aoR_6fcmepr5_nHgLbMpxwAAAms"] [Tue Aug 18 12:53:13.662076 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/coffexium.php"] [unique_id "aoR_6dO5rbWdOArH04J3-wAAAYE"] [Tue Aug 18 12:53:13.663671 2026] [security2:error] [pid 67073:tid 67305] [client 68.221.73.131:4387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR_6fcmepr5_nHgLbMpyQAAAng"] [Tue Aug 18 12:53:13.674806 2026] [security2:error] [pid 67073:tid 67307] [client 172.182.200.96:14172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/zwlsv.php"] [unique_id "aoR_6fcmepr5_nHgLbMpywAAAno"] [Tue Aug 18 12:53:13.678870 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/8pyceeo.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzAAAAnw"] [Tue Aug 18 12:53:13.680637 2026] [security2:error] [pid 67073:tid 67295] [client 104.209.144.33:25297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzQAAAm4"] [Tue Aug 18 12:53:13.760704 2026] [security2:error] [pid 66623:tid 66639] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-load.php"] [unique_id "aoR_6dO5rbWdOArH04J3_wABLwI"] [Tue Aug 18 12:53:13.767896 2026] [deflate:error] [pid 66623:tid 66859] (104)Connection reset by peer: [client 213.232.122.14:15047] AH10298: failed reading from PIPE bucket [Tue Aug 18 12:53:13.767907 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:54607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/10.php"] [unique_id "aoR_6dO5rbWdOArH04J4AAAAAWI"] [Tue Aug 18 12:53:13.768832 2026] [security2:error] [pid 66623:tid 66815] [client 20.100.169.31:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoR_6dO5rbWdOArH04J4AQAAATs"] [Tue Aug 18 12:53:13.776192 2026] [security2:error] [pid 67073:tid 67312] [client 168.62.48.100:16344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/oivcl.php"] [unique_id "aoR_6fcmepr5_nHgLbMpzwAAAn8"] [Tue Aug 18 12:53:13.856992 2026] [security2:error] [pid 67073:tid 67316] [client 20.104.100.201:17386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ohct.php"] [unique_id "aoR_6fcmepr5_nHgLbMp0QAAAoM"] [Tue Aug 18 12:53:13.858691 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:23681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/media-new.php"] [unique_id "aoR_6fcmepr5_nHgLbMp0gAAAnc"] [Tue Aug 18 12:53:13.937754 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/xmrlpc.php"] [unique_id "aoR_6fcmepr5_nHgLbMp1QAAAnk"] [Tue Aug 18 12:53:13.943641 2026] [security2:error] [pid 67073:tid 67100] [remote 57.141.22.94:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6fcmepr5_nHgLbMp1gACgRg"] [Tue Aug 18 12:53:13.944183 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:15135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "aoR_6dO5rbWdOArH04J4CgAAASE"] [Tue Aug 18 12:53:13.952599 2026] [security2:error] [pid 66623:tid 66737] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/155.php"] [unique_id "aoR_6dO5rbWdOArH04J4CwABW2Q"] [Tue Aug 18 12:53:14.006658 2026] [security2:error] [pid 67073:tid 67331] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_6vcmepr5_nHgLbMp1wAAApI"] [Tue Aug 18 12:53:14.007994 2026] [security2:error] [pid 67073:tid 67332] [client 20.48.236.86:10797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/222.php"] [unique_id "aoR_6vcmepr5_nHgLbMp2QAAApM"] [Tue Aug 18 12:53:14.022906 2026] [security2:error] [pid 67073:tid 67216] [client 168.62.48.100:16308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zugvi.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3AAAAh8"] [Tue Aug 18 12:53:14.024307 2026] [security2:error] [pid 67073:tid 67300] [client 4.223.164.152:37281] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "veloxxprodutos.com.br"] [uri "/1.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3QAAAnM"] [Tue Aug 18 12:53:14.024981 2026] [security2:error] [pid 67073:tid 67300] [client 4.223.164.152:37281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/1.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3QAAAnM"] [Tue Aug 18 12:53:14.039709 2026] [security2:error] [pid 66623:tid 66786] [client 34.178.149.167:45824] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "www.blueorbit.com.br"] [uri "/server-info"] [unique_id "aoR_6tO5rbWdOArH04J4EAAAAR4"] [Tue Aug 18 12:53:14.043087 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.18.37:62376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mass.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3gAAAoA"] [Tue Aug 18 12:53:14.062050 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:28736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/ws54.php"] [unique_id "aoR_6vcmepr5_nHgLbMp3wAAAhU"] [Tue Aug 18 12:53:14.083799 2026] [security2:error] [pid 66623:tid 66827] [client 20.171.51.14:29211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/qk.php"] [unique_id "aoR_6tO5rbWdOArH04J4FAAAAUc"] [Tue Aug 18 12:53:14.094174 2026] [security2:error] [pid 66623:tid 66795] [client 20.250.27.191:8037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/.admin.php"] [unique_id "aoR_6tO5rbWdOArH04J4FQAAASc"] [Tue Aug 18 12:53:14.103612 2026] [security2:error] [pid 66623:tid 66881] [client 34.178.149.167:45976] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.blueorbit.com.br"] [uri "/secrets.yml"] [unique_id "aoR_6tO5rbWdOArH04J4FgAAAX0"] [Tue Aug 18 12:53:14.111187 2026] [security2:error] [pid 67073:tid 67214] [client 4.223.164.152:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4AAAAh0"] [Tue Aug 18 12:53:14.112696 2026] [security2:error] [pid 67073:tid 67217] [client 54.39.89.227:19642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoR_6vcmepr5_nHgLbMp4QAAAiA"] [Tue Aug 18 12:53:14.112794 2026] [security2:error] [pid 67073:tid 67217] [client 54.39.89.227:19642] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoR_6vcmepr5_nHgLbMp4QAAAiA"] [Tue Aug 18 12:53:14.118971 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4gAAAhw"] [Tue Aug 18 12:53:14.119497 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:25286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4GAAAASU"] [Tue Aug 18 12:53:14.127478 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_6tO5rbWdOArH04J4GQAAAUM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:14.128756 2026] [security2:error] [pid 66623:tid 66770] [client 68.221.73.131:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_6tO5rbWdOArH04J4GgAAAQ4"] [Tue Aug 18 12:53:14.130934 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/vd.php"] [unique_id "aoR_6vcmepr5_nHgLbMp4wAAAiE"] [Tue Aug 18 12:53:14.137580 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_6tO5rbWdOArH04J4GwAAAUo"] [Tue Aug 18 12:53:14.155522 2026] [security2:error] [pid 66623:tid 66682] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4HQABhS0"] [Tue Aug 18 12:53:14.178370 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/155.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5QAAAko"] [Tue Aug 18 12:53:14.194154 2026] [security2:error] [pid 67073:tid 67211] [client 104.209.144.33:31276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5gAAAho"] [Tue Aug 18 12:53:14.199088 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ot.php"] [unique_id "aoR_6vcmepr5_nHgLbMp5wAAAis"] [Tue Aug 18 12:53:14.204916 2026] [security2:error] [pid 67073:tid 67328] [client 85.208.96.208:39408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1751683201/1753920000/"] [unique_id "aoR_6vcmepr5_nHgLbMp6AAAAo8"] [Tue Aug 18 12:53:14.205098 2026] [security2:error] [pid 67073:tid 67328] [client 85.208.96.208:39408] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1751683201/1753920000/"] [unique_id "aoR_6vcmepr5_nHgLbMp6AAAAo8"] [Tue Aug 18 12:53:14.211362 2026] [security2:error] [pid 67073:tid 67223] [client 192.141.172.134:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6QAAAiY"] [Tue Aug 18 12:53:14.211476 2026] [security2:error] [pid 67073:tid 67223] [client 192.141.172.134:50276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6QAAAiY"] [Tue Aug 18 12:53:14.233807 2026] [security2:error] [pid 67073:tid 67297] [client 197.184.64.235:41353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6gAAAnA"] [Tue Aug 18 12:53:14.233935 2026] [security2:error] [pid 67073:tid 67297] [client 197.184.64.235:41353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6gAAAnA"] [Tue Aug 18 12:53:14.259626 2026] [security2:error] [pid 67073:tid 67237] [client 168.62.48.100:16309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wsrer.php"] [unique_id "aoR_6vcmepr5_nHgLbMp6wAAAjQ"] [Tue Aug 18 12:53:14.270935 2026] [security2:error] [pid 67073:tid 67236] [client 172.202.39.151:44479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/404.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7AAAAjM"] [Tue Aug 18 12:53:14.305223 2026] [security2:error] [pid 67073:tid 67225] [client 20.119.58.187:14644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7QAAAig"] [Tue Aug 18 12:53:14.321302 2026] [security2:error] [pid 66623:tid 66674] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/aaa.php"] [unique_id "aoR_6tO5rbWdOArH04J4IAABHSU"] [Tue Aug 18 12:53:14.322073 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/aa.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7gAAAjg"] [Tue Aug 18 12:53:14.339389 2026] [security2:error] [pid 66623:tid 66840] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/sf.php"] [unique_id "aoR_6tO5rbWdOArH04J4IQAAAVQ"] [Tue Aug 18 12:53:14.345563 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/jrpga.php"] [unique_id "aoR_6vcmepr5_nHgLbMp7wAAAkA"] [Tue Aug 18 12:53:14.348991 2026] [security2:error] [pid 66623:tid 66819] [client 20.100.169.31:28458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/class-t.api.php"] [unique_id "aoR_6tO5rbWdOArH04J4IgAAAT8"] [Tue Aug 18 12:53:14.406759 2026] [security2:error] [pid 66623:tid 66798] [client 52.238.210.254:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoR_6tO5rbWdOArH04J4JAAAASo"] [Tue Aug 18 12:53:14.419291 2026] [security2:error] [pid 67073:tid 67255] [client 132.196.61.152:38378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8AAAAkY"] [Tue Aug 18 12:53:14.453682 2026] [security2:error] [pid 67073:tid 67258] [client 4.223.164.152:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/about.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8QAAAkk"] [Tue Aug 18 12:53:14.457809 2026] [security2:error] [pid 66623:tid 66791] [client 52.238.210.254:15921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/info.php"] [unique_id "aoR_6tO5rbWdOArH04J4JgAAASM"] [Tue Aug 18 12:53:14.477635 2026] [security2:error] [pid 66623:tid 66654] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/FWAZ.php"] [unique_id "aoR_6tO5rbWdOArH04J4KAABNxE"] [Tue Aug 18 12:53:14.500716 2026] [security2:error] [pid 66623:tid 66893] [client 52.139.47.57:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/storage/rip.php"] [unique_id "aoR_6tO5rbWdOArH04J4LQAAAYk"] [Tue Aug 18 12:53:14.501631 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/ucpfr.php"] [unique_id "aoR_6tO5rbWdOArH04J4LgAAATE"] [Tue Aug 18 12:53:14.504104 2026] [security2:error] [pid 66623:tid 66792] [client 20.250.27.191:7386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/wsomini.php"] [unique_id "aoR_6tO5rbWdOArH04J4LwAAASQ"] [Tue Aug 18 12:53:14.556362 2026] [security2:error] [pid 66623:tid 66884] [client 114.5.214.109:49791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6tO5rbWdOArH04J4MwAAAYA"] [Tue Aug 18 12:53:14.556482 2026] [security2:error] [pid 66623:tid 66884] [client 114.5.214.109:49791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6tO5rbWdOArH04J4MwAAAYA"] [Tue Aug 18 12:53:14.581797 2026] [security2:error] [pid 67073:tid 67239] [client 68.221.73.131:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8gAAAjY"] [Tue Aug 18 12:53:14.585398 2026] [security2:error] [pid 67073:tid 67251] [client 158.158.74.177:13793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoR_6vcmepr5_nHgLbMp8wAAAkI"] [Tue Aug 18 12:53:14.623625 2026] [security2:error] [pid 67073:tid 67222] [client 86.120.159.145:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9AAAAiU"] [Tue Aug 18 12:53:14.623807 2026] [security2:error] [pid 67073:tid 67222] [client 86.120.159.145:61122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9AAAAiU"] [Tue Aug 18 12:53:14.631361 2026] [access_compat:error] [pid 66623:tid 66883] [client 34.178.149.167:46052] AH01797: client denied by server configuration: /home1/blueorbit/public_html/server-status [Tue Aug 18 12:53:14.659647 2026] [security2:error] [pid 66623:tid 66678] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/site.php"] [unique_id "aoR_6tO5rbWdOArH04J4NQABgSk"] [Tue Aug 18 12:53:14.660839 2026] [security2:error] [pid 66623:tid 66826] [client 20.119.58.187:15352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoR_6tO5rbWdOArH04J4NgAAAUY"] [Tue Aug 18 12:53:14.672841 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/k.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9QAAAkc"] [Tue Aug 18 12:53:14.687574 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.100.201:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/root.php"] [unique_id "aoR_6vcmepr5_nHgLbMp9gAAAlw"] [Tue Aug 18 12:53:14.695485 2026] [security2:error] [pid 66623:tid 66836] [client 74.248.18.37:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/memberfuns.php"] [unique_id "aoR_6tO5rbWdOArH04J4OAAAAVA"] [Tue Aug 18 12:53:14.719260 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fraie1p4.php"] [unique_id "aoR_6vcmepr5_nHgLbMp-QAAAmc"] [Tue Aug 18 12:53:14.720826 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/v5.php"] [unique_id "aoR_6vcmepr5_nHgLbMp-gAAAmw"] [Tue Aug 18 12:53:14.743337 2026] [security2:error] [pid 66623:tid 66815] [client 104.209.144.33:31291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_6tO5rbWdOArH04J4OQAAATs"] [Tue Aug 18 12:53:14.743988 2026] [security2:error] [pid 66623:tid 66800] [client 104.209.144.33:32684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoR_6tO5rbWdOArH04J4OgAAASw"] [Tue Aug 18 12:53:14.747801 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:14749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/yxijx.php"] [unique_id "aoR_6tO5rbWdOArH04J4OwAAAR8"] [Tue Aug 18 12:53:14.792180 2026] [security2:error] [pid 66623:tid 66849] [client 4.223.164.152:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/i.php"] [unique_id "aoR_6tO5rbWdOArH04J4PgAAAV0"] [Tue Aug 18 12:53:14.802686 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.61.152:38375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/media.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_AAAAnU"] [Tue Aug 18 12:53:14.836247 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.154.236:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_6tO5rbWdOArH04J4QAAAAVE"] [Tue Aug 18 12:53:14.843010 2026] [security2:error] [pid 66623:tid 66708] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/ccc.php"] [unique_id "aoR_6tO5rbWdOArH04J4QQABR0c"] [Tue Aug 18 12:53:14.875065 2026] [security2:error] [pid 66623:tid 66861] [client 20.42.19.40:2198] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin"] [unique_id "aoR_6tO5rbWdOArH04J4RAAAAWk"] [Tue Aug 18 12:53:14.877966 2026] [security2:error] [pid 67073:tid 67276] [client 20.91.215.254:16652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_gAAAls"] [Tue Aug 18 12:53:14.887305 2026] [security2:error] [pid 67073:tid 67267] [client 213.232.122.14:39363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "acpecasebaterias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMp_wAAAlI"] [Tue Aug 18 12:53:14.903731 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAAAAAhg"] [Tue Aug 18 12:53:14.912368 2026] [security2:error] [pid 66623:tid 66793] [client 20.250.27.191:58973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nolancollection.com.br"] [uri "/vr.php"] [unique_id "aoR_6tO5rbWdOArH04J4RQAAASU"] [Tue Aug 18 12:53:14.916567 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAAAAAhg"] [Tue Aug 18 12:53:14.918741 2026] [security2:error] [pid 67073:tid 67278] [client 20.100.169.31:28477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAgAAAl0"] [Tue Aug 18 12:53:14.942856 2026] [security2:error] [pid 67073:tid 67283] [client 4.223.164.152:37265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/admin.php"] [unique_id "aoR_6vcmepr5_nHgLbMqAwAAAmI"] [Tue Aug 18 12:53:14.943170 2026] [security2:error] [pid 67073:tid 67294] [client 52.173.121.69:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/first.php"] [unique_id "aoR_6vcmepr5_nHgLbMqBAAAAm0"] [Tue Aug 18 12:53:14.984234 2026] [security2:error] [pid 67073:tid 67289] [client 168.62.48.100:14734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/zwlsv.php"] [unique_id "aoR_6vcmepr5_nHgLbMqBgAAAmg"] [Tue Aug 18 12:53:15.011879 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/82.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCAAAAog"] [Tue Aug 18 12:53:15.014059 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:14611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aoR_69O5rbWdOArH04J4SQAAAX0"] [Tue Aug 18 12:53:15.022033 2026] [security2:error] [pid 67073:tid 67322] [client 20.48.236.86:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mac.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCQAAAok"] [Tue Aug 18 12:53:15.082305 2026] [security2:error] [pid 66623:tid 66809] [client 68.221.73.131:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR_69O5rbWdOArH04J4TAAAATU"] [Tue Aug 18 12:53:15.087304 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoR_6_cmepr5_nHgLbMqCgAAAow"] [Tue Aug 18 12:53:15.115912 2026] [security2:error] [pid 66623:tid 66656] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/admin.php"] [unique_id "aoR_69O5rbWdOArH04J4TQABKxM"] [Tue Aug 18 12:53:15.117047 2026] [security2:error] [pid 66623:tid 66852] [client 138.36.100.162:42749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4TgAAAWA"] [Tue Aug 18 12:53:15.117185 2026] [security2:error] [pid 66623:tid 66852] [client 138.36.100.162:42749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4TgAAAWA"] [Tue Aug 18 12:53:15.145585 2026] [security2:error] [pid 67073:tid 67292] [client 213.35.127.232:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDAAAAms"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:15.195435 2026] [security2:error] [pid 66623:tid 66794] [client 20.42.19.40:2207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp.php"] [unique_id "aoR_69O5rbWdOArH04J4VQAAASY"] [Tue Aug 18 12:53:15.218825 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/deepseek_d.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDgAAAmA"] [Tue Aug 18 12:53:15.222233 2026] [security2:error] [pid 67073:tid 67300] [client 168.62.48.100:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/jrpga.php"] [unique_id "aoR_6_cmepr5_nHgLbMqDwAAAnM"] [Tue Aug 18 12:53:15.248055 2026] [security2:error] [pid 66623:tid 66844] [client 135.136.0.233:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.0.136.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4WAAAAVg"] [Tue Aug 18 12:53:15.248255 2026] [security2:error] [pid 66623:tid 66844] [client 135.136.0.233:62982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_69O5rbWdOArH04J4WAAAAVg"] [Tue Aug 18 12:53:15.300843 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.61.152:38379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/inso.php"] [unique_id "aoR_6_cmepr5_nHgLbMqEAAAAhU"] [Tue Aug 18 12:53:15.318253 2026] [autoindex:error] [pid 67073:tid 67331] [client 205.210.31.41:57612] AH01276: Cannot serve directory /home4/ejsserralheriasp/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:15.320201 2026] [security2:error] [pid 66623:tid 66649] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/reviall.php"] [unique_id "aoR_69O5rbWdOArH04J4XQABVgw"] [Tue Aug 18 12:53:15.328102 2026] [security2:error] [pid 67073:tid 67314] [client 74.248.18.37:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/meta.php"] [unique_id "aoR_6_cmepr5_nHgLbMqEgAAAoE"] [Tue Aug 18 12:53:15.350076 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/dex.php"] [unique_id "aoR_69O5rbWdOArH04J4XgAAAXw"] [Tue Aug 18 12:53:15.358827 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.154.236:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/rezor.php"] [unique_id "aoR_69O5rbWdOArH04J4XwAAAYY"] [Tue Aug 18 12:53:15.369544 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:15303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "aoR_69O5rbWdOArH04J4YAAAAXo"] [Tue Aug 18 12:53:15.425082 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/edit.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFAAAAiE"] [Tue Aug 18 12:53:15.442207 2026] [security2:error] [pid 66623:tid 66812] [client 74.249.206.207:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_69O5rbWdOArH04J4YgAAATg"] [Tue Aug 18 12:53:15.454125 2026] [security2:error] [pid 66623:tid 66801] [client 20.104.100.201:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoR_69O5rbWdOArH04J4YwAAAS0"] [Tue Aug 18 12:53:15.456890 2026] [security2:error] [pid 67073:tid 67226] [client 168.62.48.100:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/museu/yhweq.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFQAAAik"] [Tue Aug 18 12:53:15.471021 2026] [security2:error] [pid 66623:tid 66846] [client 20.171.51.14:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ts.php"] [unique_id "aoR_69O5rbWdOArH04J4ZAAAAVo"] [Tue Aug 18 12:53:15.478666 2026] [security2:error] [pid 66623:tid 66719] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/nope.php"] [unique_id "aoR_69O5rbWdOArH04J4ZQABblI"] [Tue Aug 18 12:53:15.513305 2026] [security2:error] [pid 66623:tid 66854] [client 68.221.73.131:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoR_69O5rbWdOArH04J4aAAAAWI"] [Tue Aug 18 12:53:15.520231 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/ku.php"] [unique_id "aoR_69O5rbWdOArH04J4aQAAASw"] [Tue Aug 18 12:53:15.559371 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoR_6_cmepr5_nHgLbMqFwAAAiA"] [Tue Aug 18 12:53:15.573430 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:47496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/96i.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGAAAAh8"] [Tue Aug 18 12:53:15.575877 2026] [security2:error] [pid 67073:tid 67230] [client 20.104.100.201:56889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/fpwch.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGQAAAi0"] [Tue Aug 18 12:53:15.587138 2026] [security2:error] [pid 67073:tid 67297] [client 51.222.168.251:61932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "eccellenzaconsultoria.com.br"] [uri "/"] [unique_id "aoR_6_cmepr5_nHgLbMqGgAAAnA"] [Tue Aug 18 12:53:15.587258 2026] [security2:error] [pid 67073:tid 67297] [client 51.222.168.251:61932] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eccellenzaconsultoria.com.br"] [uri "/"] [unique_id "aoR_6_cmepr5_nHgLbMqGgAAAnA"] [Tue Aug 18 12:53:15.588812 2026] [security2:error] [pid 66623:tid 66849] [client 40.85.222.29:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/Cachex.php"] [unique_id "aoR_69O5rbWdOArH04J4bgAAAV0"] [Tue Aug 18 12:53:15.595947 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/abcd.php"] [unique_id "aoR_6_cmepr5_nHgLbMqGwAAAnY"] [Tue Aug 18 12:53:15.640937 2026] [security2:error] [pid 66623:tid 66660] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/nope.php"] [unique_id "aoR_69O5rbWdOArH04J4cQABJxc"] [Tue Aug 18 12:53:15.661279 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.61.152:25679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/shiny.php"] [unique_id "aoR_69O5rbWdOArH04J4cgAAAWk"] [Tue Aug 18 12:53:15.692424 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:14839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/nwwha.php"] [unique_id "aoR_69O5rbWdOArH04J4dAAAAUM"] [Tue Aug 18 12:53:15.717266 2026] [security2:error] [pid 66623:tid 66830] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/puc.php"] [unique_id "aoR_69O5rbWdOArH04J4dQAAAUo"] [Tue Aug 18 12:53:15.725828 2026] [security2:error] [pid 66623:tid 66786] [client 20.119.58.187:15298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoR_69O5rbWdOArH04J4dgAAAR4"] [Tue Aug 18 12:53:15.764052 2026] [security2:error] [pid 67073:tid 67238] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoR_6_cmepr5_nHgLbMqHAAAAjU"] [Tue Aug 18 12:53:15.771157 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:28837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fs.php"] [unique_id "aoR_6_cmepr5_nHgLbMqHQAAAjA"] [Tue Aug 18 12:53:15.780982 2026] [authz_core:error] [pid 66623:tid 66684] [remote 57.141.22.30:36034] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:15.781440 2026] [authz_core:error] [pid 66623:tid 66684] [remote 57.141.22.30:36034] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:15.808552 2026] [security2:error] [pid 66623:tid 66667] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/new.php"] [unique_id "aoR_69O5rbWdOArH04J4eQABHR4"] [Tue Aug 18 12:53:15.886050 2026] [security2:error] [pid 67073:tid 67112] [remote 57.141.22.21:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_6_cmepr5_nHgLbMqHwACMyQ"] [Tue Aug 18 12:53:15.910564 2026] [security2:error] [pid 67073:tid 67244] [client 20.48.236.86:10662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ops.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIAAAAjs"] [Tue Aug 18 12:53:15.944043 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:37252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIQAAAkg"] [Tue Aug 18 12:53:15.948911 2026] [security2:error] [pid 66623:tid 66852] [client 168.62.48.100:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/opsqt.php"] [unique_id "aoR_69O5rbWdOArH04J4fQAAAWA"] [Tue Aug 18 12:53:15.961290 2026] [security2:error] [pid 66623:tid 66821] [client 20.171.51.14:58856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/53.php"] [unique_id "aoR_69O5rbWdOArH04J4fgAAAUE"] [Tue Aug 18 12:53:15.964409 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mini.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIgAAAic"] [Tue Aug 18 12:53:15.969160 2026] [security2:error] [pid 67073:tid 67258] [client 20.42.19.40:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/file2.php"] [unique_id "aoR_6_cmepr5_nHgLbMqIwAAAkk"] [Tue Aug 18 12:53:15.983482 2026] [security2:error] [pid 66623:tid 66734] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/new.php"] [unique_id "aoR_69O5rbWdOArH04J4gQABh2E"] [Tue Aug 18 12:53:15.989691 2026] [security2:error] [pid 66623:tid 66856] [client 132.196.61.152:44447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/403dd.php"] [unique_id "aoR_69O5rbWdOArH04J4ggAAAWQ"] [Tue Aug 18 12:53:16.014692 2026] [security2:error] [pid 67073:tid 67247] [client 68.221.73.131:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/media.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqJQAAAj4"] [Tue Aug 18 12:53:16.021730 2026] [security2:error] [pid 66623:tid 66790] [client 103.184.169.37:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7NO5rbWdOArH04J4gwAAASI"] [Tue Aug 18 12:53:16.021891 2026] [security2:error] [pid 66623:tid 66790] [client 103.184.169.37:40949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7NO5rbWdOArH04J4gwAAASI"] [Tue Aug 18 12:53:16.023684 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.154.236:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoR_7NO5rbWdOArH04J4hAAAAQs"] [Tue Aug 18 12:53:16.042864 2026] [security2:error] [pid 67073:tid 67265] [client 104.209.144.33:25307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqJwAAAlA"] [Tue Aug 18 12:53:16.048328 2026] [deflate:error] [pid 66623:tid 66841] (104)Connection reset by peer: [client 213.232.122.14:19397] AH10298: failed reading from PIPE bucket [Tue Aug 18 12:53:16.058584 2026] [security2:error] [pid 66623:tid 66773] [client 104.209.144.33:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoR_7NO5rbWdOArH04J4hwAAARE"] [Tue Aug 18 12:53:16.060631 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/inso.php"] [unique_id "aoR_7NO5rbWdOArH04J4iAAAASY"] [Tue Aug 18 12:53:16.090499 2026] [security2:error] [pid 67073:tid 67250] [client 20.119.58.187:15356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKAAAAkE"] [Tue Aug 18 12:53:16.136681 2026] [security2:error] [pid 66623:tid 66877] [client 52.238.210.254:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/edit.php"] [unique_id "aoR_7NO5rbWdOArH04J4iwAAAXk"] [Tue Aug 18 12:53:16.140068 2026] [security2:error] [pid 66623:tid 66814] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bolt.php"] [unique_id "aoR_7NO5rbWdOArH04J4jAAAATo"] [Tue Aug 18 12:53:16.142439 2026] [security2:error] [pid 66623:tid 66754] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/apreset.php"] [unique_id "aoR_7NO5rbWdOArH04J4jQABGXU"] [Tue Aug 18 12:53:16.154059 2026] [security2:error] [pid 67073:tid 67242] [client 20.104.100.201:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/mg.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKQAAAjk"] [Tue Aug 18 12:53:16.159672 2026] [security2:error] [pid 67073:tid 67249] [client 213.35.127.232:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKgAAAkA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:16.186375 2026] [security2:error] [pid 67073:tid 67275] [client 168.62.48.100:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/jvcpa.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqKwAAAlo"] [Tue Aug 18 12:53:16.186702 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.100.201:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/dk.php"] [unique_id "aoR_7NO5rbWdOArH04J4jwAAAUk"] [Tue Aug 18 12:53:16.196139 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.169.31:28447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/w.php"] [unique_id "aoR_7NO5rbWdOArH04J4kQAAAYQ"] [Tue Aug 18 12:53:16.244658 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-manager.php"] [unique_id "aoR_7NO5rbWdOArH04J4kwAAARw"] [Tue Aug 18 12:53:16.250637 2026] [security2:error] [pid 67073:tid 67110] [remote 47.86.33.52:10068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLQACjyI"] [Tue Aug 18 12:53:16.266511 2026] [security2:error] [pid 66623:tid 66839] [client 74.248.136.165:1908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/166.php"] [unique_id "aoR_7NO5rbWdOArH04J4lgAAAVM"] [Tue Aug 18 12:53:16.273979 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:7343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/baba.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLgAAAlM"] [Tue Aug 18 12:53:16.299956 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1mage.php"] [unique_id "aoR_7NO5rbWdOArH04J4lwABd2w"] [Tue Aug 18 12:53:16.346465 2026] [security2:error] [pid 66623:tid 66778] [client 20.91.215.254:23683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoR_7NO5rbWdOArH04J4nQAAARY"] [Tue Aug 18 12:53:16.364974 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:37300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inputs.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqLwAAAlY"] [Tue Aug 18 12:53:16.407560 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/aa.php"] [unique_id "aoR_7NO5rbWdOArH04J4nwAAAVo"] [Tue Aug 18 12:53:16.412188 2026] [security2:error] [pid 67073:tid 67309] [client 158.158.74.177:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMAAAAnw"] [Tue Aug 18 12:53:16.419955 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rb.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMQAAAlI"] [Tue Aug 18 12:53:16.432926 2026] [security2:error] [pid 67073:tid 67209] [client 168.62.48.100:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMgAAAhg"] [Tue Aug 18 12:53:16.440221 2026] [security2:error] [pid 67073:tid 67111] [remote 46.62.208.238:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqMwACWSM"] [Tue Aug 18 12:53:16.443064 2026] [security2:error] [pid 67073:tid 67278] [client 68.221.73.131:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/inso.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNAAAAl0"] [Tue Aug 18 12:53:16.449541 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNgAAAk8"] [Tue Aug 18 12:53:16.476863 2026] [security2:error] [pid 66623:tid 66677] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/imsc.php"] [unique_id "aoR_7NO5rbWdOArH04J4oQABLyg"] [Tue Aug 18 12:53:16.512582 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lq.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOAAAAn8"] [Tue Aug 18 12:53:16.527960 2026] [security2:error] [pid 66623:tid 66865] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bthil.php"] [unique_id "aoR_7NO5rbWdOArH04J4owAAAW0"] [Tue Aug 18 12:53:16.561276 2026] [security2:error] [pid 67073:tid 67234] [client 132.196.61.152:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/site.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOgAAAjE"] [Tue Aug 18 12:53:16.565075 2026] [security2:error] [pid 66623:tid 66847] [client 172.202.39.151:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/gecko.php"] [unique_id "aoR_7NO5rbWdOArH04J4pAAAAVs"] [Tue Aug 18 12:53:16.569174 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/as.php"] [unique_id "aoR_7NO5rbWdOArH04J4pQAAARs"] [Tue Aug 18 12:53:16.629786 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/mm.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqOwAAAls"] [Tue Aug 18 12:53:16.636638 2026] [security2:error] [pid 67073:tid 67292] [client 74.249.206.207:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPAAAAms"] [Tue Aug 18 12:53:16.657366 2026] [security2:error] [pid 67073:tid 67254] [client 216.73.160.114:50713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqNwAAAkU"] [Tue Aug 18 12:53:16.667808 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPQAAApE"] [Tue Aug 18 12:53:16.772636 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.177.66:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.danielimoveispva.com.br"] [uri "/1.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPwAAAnM"] [Tue Aug 18 12:53:16.772760 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/1.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqPwAAAnM"] [Tue Aug 18 12:53:16.777808 2026] [security2:error] [pid 66623:tid 66815] [client 4.232.151.198:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/function/function.php"] [unique_id "aoR_7NO5rbWdOArH04J4qgAAATs"] [Tue Aug 18 12:53:16.825552 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/imscjpg.php"] [unique_id "aoR_7NO5rbWdOArH04J4qwABJVw"] [Tue Aug 18 12:53:16.826062 2026] [security2:error] [pid 67073:tid 67206] [client 52.238.210.254:27632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/chosen.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQQAAAhU"] [Tue Aug 18 12:53:16.843554 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/museu/yhweq.php"] [unique_id "aoR_7NO5rbWdOArH04J4rAAAAXE"] [Tue Aug 18 12:53:16.850368 2026] [security2:error] [pid 67073:tid 67272] [client 20.119.58.187:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/xmrlpc.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQgAAAlc"] [Tue Aug 18 12:53:16.871660 2026] [security2:error] [pid 66623:tid 66769] [client 132.196.61.152:23848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wp-admin/maint/index.php"] [unique_id "aoR_7NO5rbWdOArH04J4swAAAQ0"] [Tue Aug 18 12:53:16.885727 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:6905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqQwAAAoE"] [Tue Aug 18 12:53:16.895049 2026] [security2:error] [pid 67073:tid 67212] [client 104.209.144.33:32692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRAAAAhs"] [Tue Aug 18 12:53:16.897776 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/av.php"] [unique_id "aoR_7NO5rbWdOArH04J4vgAAAXA"] [Tue Aug 18 12:53:16.900505 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoR_7NO5rbWdOArH04J4vwAAAR0"] [Tue Aug 18 12:53:16.920972 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:43580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_7NO5rbWdOArH04J4wAAAAXU"] [Tue Aug 18 12:53:16.927864 2026] [security2:error] [pid 67073:tid 67214] [client 68.221.73.131:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/shiny.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRQAAAh0"] [Tue Aug 18 12:53:16.953507 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRgAAAhw"] [Tue Aug 18 12:53:16.956523 2026] [security2:error] [pid 67073:tid 67207] [client 68.155.154.236:63393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqRwAAAhY"] [Tue Aug 18 12:53:16.961004 2026] [security2:error] [pid 66623:tid 66768] [client 20.104.100.201:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/bal.php"] [unique_id "aoR_7NO5rbWdOArH04J4wgAAAQw"] [Tue Aug 18 12:53:16.977117 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/37.php"] [unique_id "aoR_7Pcmepr5_nHgLbMqSAAAAiA"] [Tue Aug 18 12:53:16.982068 2026] [security2:error] [pid 66623:tid 66763] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/qlex1.php"] [unique_id "aoR_7NO5rbWdOArH04J4xQABCn4"] [Tue Aug 18 12:53:17.062596 2026] [security2:error] [pid 67073:tid 67238] [client 52.238.210.254:10200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/w.php"] [unique_id "aoR_7fcmepr5_nHgLbMqTQAAAjU"] [Tue Aug 18 12:53:17.085899 2026] [security2:error] [pid 67073:tid 67118] [remote 157.230.98.178:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoR_7fcmepr5_nHgLbMqTgACiyo"] [Tue Aug 18 12:53:17.127792 2026] [security2:error] [pid 67073:tid 67248] [client 20.104.100.201:65127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/reop3.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUAAAAj8"] [Tue Aug 18 12:53:17.139793 2026] [security2:error] [pid 66623:tid 66707] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/mariju.php"] [unique_id "aoR_7dO5rbWdOArH04J4zAABZEY"] [Tue Aug 18 12:53:17.144559 2026] [security2:error] [pid 67073:tid 67308] [client 168.62.48.100:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUQAAAns"] [Tue Aug 18 12:53:17.171402 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:49335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_7dO5rbWdOArH04J4zQAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:17.173406 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/te.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUgAAAmU"] [Tue Aug 18 12:53:17.173406 2026] [security2:error] [pid 66623:tid 66840] [client 20.91.215.254:20258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoR_7dO5rbWdOArH04J4zgAAAVQ"] [Tue Aug 18 12:53:17.178443 2026] [security2:error] [pid 67073:tid 67257] [client 132.196.61.152:44442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/cabs.php"] [unique_id "aoR_7fcmepr5_nHgLbMqUwAAAkg"] [Tue Aug 18 12:53:17.212775 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.85.180:18847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVAAAAks"] [Tue Aug 18 12:53:17.217652 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.74.177:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/asd.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVQAAAh8"] [Tue Aug 18 12:53:17.217988 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:14798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVgAAAjw"] [Tue Aug 18 12:53:17.275280 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.18.37:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/modules/mod_footer.php"] [unique_id "aoR_7fcmepr5_nHgLbMqVwAAAjQ"] [Tue Aug 18 12:53:17.288245 2026] [security2:error] [pid 67073:tid 67323] [client 20.42.19.40:2716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/images/class-config.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWAAAAoo"] [Tue Aug 18 12:53:17.298931 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/img.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWQAAAkE"] [Tue Aug 18 12:53:17.308044 2026] [security2:error] [pid 66623:tid 66756] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/cofbgxlk.php"] [unique_id "aoR_7dO5rbWdOArH04J42gABfnc"] [Tue Aug 18 12:53:17.325619 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_7fcmepr5_nHgLbMqWwAAAjY"] [Tue Aug 18 12:53:17.345350 2026] [security2:error] [pid 67073:tid 67275] [client 68.221.73.131:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/403dd.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXAAAAlo"] [Tue Aug 18 12:53:17.367234 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXQAAAh4"] [Tue Aug 18 12:53:17.382084 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:14725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoR_7dO5rbWdOArH04J43AAAATE"] [Tue Aug 18 12:53:17.416523 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXgAAAog"] [Tue Aug 18 12:53:17.431423 2026] [security2:error] [pid 67073:tid 67268] [client 104.209.144.33:31253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_7fcmepr5_nHgLbMqXwAAAlM"] [Tue Aug 18 12:53:17.474083 2026] [security2:error] [pid 67073:tid 67307] [client 104.209.144.33:32645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoR_7fcmepr5_nHgLbMqZwAAAno"] [Tue Aug 18 12:53:17.487896 2026] [security2:error] [pid 66623:tid 66726] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/contacto.php"] [unique_id "aoR_7dO5rbWdOArH04J43gABJFk"] [Tue Aug 18 12:53:17.491530 2026] [security2:error] [pid 67073:tid 67311] [client 4.223.164.152:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoR_7fcmepr5_nHgLbMqaQAAAn4"] [Tue Aug 18 12:53:17.493574 2026] [security2:error] [pid 67073:tid 67274] [client 132.196.61.152:45174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/insc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqagAAAlk"] [Tue Aug 18 12:53:17.521403 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/kc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqawAAAmE"] [Tue Aug 18 12:53:17.530370 2026] [security2:error] [pid 67073:tid 67283] [client 68.155.154.236:64529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/index/function.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbAAAAmI"] [Tue Aug 18 12:53:17.568642 2026] [security2:error] [pid 66623:tid 66838] [client 20.104.85.180:18846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/admin.php"] [unique_id "aoR_7dO5rbWdOArH04J44QAAAVI"] [Tue Aug 18 12:53:17.574137 2026] [security2:error] [pid 66623:tid 66782] [client 52.173.121.69:17978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR_7dO5rbWdOArH04J44gAAARo"] [Tue Aug 18 12:53:17.574137 2026] [security2:error] [pid 67073:tid 67270] [client 20.119.58.187:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbQAAAlU"] [Tue Aug 18 12:53:17.619452 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:16311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoR_7dO5rbWdOArH04J45QAAAU8"] [Tue Aug 18 12:53:17.634977 2026] [security2:error] [pid 67073:tid 67292] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/222.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbwAAAms"] [Tue Aug 18 12:53:17.689915 2026] [security2:error] [pid 66623:tid 66784] [client 52.238.210.254:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file.php"] [unique_id "aoR_7dO5rbWdOArH04J46gAAARw"] [Tue Aug 18 12:53:17.708622 2026] [security2:error] [pid 66623:tid 66839] [client 20.42.19.40:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/alfa.php"] [unique_id "aoR_7dO5rbWdOArH04J46wAAAVM"] [Tue Aug 18 12:53:17.760012 2026] [security2:error] [pid 66623:tid 66808] [client 68.221.73.131:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/baba.php"] [unique_id "aoR_7dO5rbWdOArH04J47gAAATQ"] [Tue Aug 18 12:53:17.769518 2026] [security2:error] [pid 67073:tid 67128] [remote 2a02:c207:2345:2647::1:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paneladechocolate.com.br"] [uri "/.env"] [unique_id "aoR_7fcmepr5_nHgLbMqcQACkjQ"] [Tue Aug 18 12:53:17.787356 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:25723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file.php"] [unique_id "aoR_7dO5rbWdOArH04J48AAAAWY"] [Tue Aug 18 12:53:17.792782 2026] [security2:error] [pid 66623:tid 66736] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/image2.php"] [unique_id "aoR_7dO5rbWdOArH04J48gABFmM"] [Tue Aug 18 12:53:17.808005 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_7fcmepr5_nHgLbMqcgAAAoE"] [Tue Aug 18 12:53:17.808747 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbgAAAhc"] [Tue Aug 18 12:53:17.808926 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:49874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqbgAAAhc"] [Tue Aug 18 12:53:17.815739 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:20230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/ebs.php7"] [unique_id "aoR_7fcmepr5_nHgLbMqcwAAAok"] [Tue Aug 18 12:53:17.854011 2026] [security2:error] [pid 66623:tid 66866] [client 168.62.48.100:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoR_7dO5rbWdOArH04J49gAAAW4"] [Tue Aug 18 12:53:17.854449 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.85.180:43567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/public/css.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdQAAAhY"] [Tue Aug 18 12:53:17.903023 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/jn.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdgAAAhQ"] [Tue Aug 18 12:53:17.907959 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.18.37:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/moon.php"] [unique_id "aoR_7fcmepr5_nHgLbMqdwAAApA"] [Tue Aug 18 12:53:17.925795 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:25308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoR_7fcmepr5_nHgLbMqeQAAAhk"] [Tue Aug 18 12:53:17.930068 2026] [security2:error] [pid 67073:tid 67217] [client 104.209.144.33:24842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_7fcmepr5_nHgLbMqegAAAiA"] [Tue Aug 18 12:53:17.938446 2026] [security2:error] [pid 67073:tid 67131] [remote 57.141.22.94:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_7fcmepr5_nHgLbMqfAACKTc"] [Tue Aug 18 12:53:17.948456 2026] [security2:error] [pid 67073:tid 67306] [client 20.119.58.187:15340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/img/xmrlpc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfQAAAnk"] [Tue Aug 18 12:53:17.952356 2026] [security2:error] [pid 66623:tid 66693] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fb.php"] [unique_id "aoR_7dO5rbWdOArH04J4-QABFzg"] [Tue Aug 18 12:53:17.960402 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/you.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfgAAAmc"] [Tue Aug 18 12:53:17.968621 2026] [security2:error] [pid 67073:tid 67132] [remote 190.6.176.90:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7fcmepr5_nHgLbMqfwACLDg"] [Tue Aug 18 12:53:17.970751 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/md.php"] [unique_id "aoR_7fcmepr5_nHgLbMqgAAAAiY"] [Tue Aug 18 12:53:17.977090 2026] [security2:error] [pid 67073:tid 67327] [client 158.158.74.177:13792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/akc.php"] [unique_id "aoR_7fcmepr5_nHgLbMqgQAAAo4"] [Tue Aug 18 12:53:17.995284 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.100.201:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yawa.php"] [unique_id "aoR_7fcmepr5_nHgLbMqggAAAnA"] [Tue Aug 18 12:53:18.005776 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/key.php"] [unique_id "aoR_7tO5rbWdOArH04J4_AAAAVE"] [Tue Aug 18 12:53:18.094592 2026] [security2:error] [pid 67073:tid 67258] [client 74.249.206.207:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/xx.php"] [unique_id "aoR_7vcmepr5_nHgLbMqjgAAAkk"] [Tue Aug 18 12:53:18.098132 2026] [security2:error] [pid 67073:tid 67260] [client 168.62.48.100:14829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoR_7vcmepr5_nHgLbMqjwAAAks"] [Tue Aug 18 12:53:18.112990 2026] [security2:error] [pid 66623:tid 66685] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/gi.php"] [unique_id "aoR_7tO5rbWdOArH04J4_gABJzA"] [Tue Aug 18 12:53:18.131711 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/classwithtostring.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkAAAAj4"] [Tue Aug 18 12:53:18.147403 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:44281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/min.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkQAAAkY"] [Tue Aug 18 12:53:18.165777 2026] [security2:error] [pid 67073:tid 67265] [client 132.196.61.152:23837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dex.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkgAAAlA"] [Tue Aug 18 12:53:18.184524 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:2217] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/1.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkwAAAk0"] [Tue Aug 18 12:53:18.184615 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/1.php"] [unique_id "aoR_7vcmepr5_nHgLbMqkwAAAk0"] [Tue Aug 18 12:53:18.189136 2026] [security2:error] [pid 67073:tid 67213] [client 213.35.127.232:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlAAAAhw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:18.208689 2026] [security2:error] [pid 67073:tid 67146] [remote 57.141.22.18:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_7vcmepr5_nHgLbMqlQACH0Y"] [Tue Aug 18 12:53:18.228667 2026] [security2:error] [pid 67073:tid 67275] [client 68.221.73.131:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/site.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlgAAAlo"] [Tue Aug 18 12:53:18.229136 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:37282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-blog.php"] [unique_id "aoR_7vcmepr5_nHgLbMqlwAAAh4"] [Tue Aug 18 12:53:18.238637 2026] [security2:error] [pid 66623:tid 66890] [client 149.34.210.141:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5GQAAAYY"] [Tue Aug 18 12:53:18.247745 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.154.236:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_7tO5rbWdOArH04J5GgAAAQ0"] [Tue Aug 18 12:53:18.267984 2026] [security2:error] [pid 66623:tid 66745] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/video.php"] [unique_id "aoR_7tO5rbWdOArH04J5HAABgmw"] [Tue Aug 18 12:53:18.269268 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:20983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/56.php"] [unique_id "aoR_7vcmepr5_nHgLbMqmgAAAl8"] [Tue Aug 18 12:53:18.301754 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "aoR_7vcmepr5_nHgLbMqmwAAAiU"] [Tue Aug 18 12:53:18.334798 2026] [security2:error] [pid 67073:tid 67305] [client 168.62.48.100:14755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoR_7vcmepr5_nHgLbMqnQAAAng"] [Tue Aug 18 12:53:18.338503 2026] [security2:error] [pid 67073:tid 67271] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/chosen.php"] [unique_id "aoR_7vcmepr5_nHgLbMqngAAAlY"] [Tue Aug 18 12:53:18.341428 2026] [security2:error] [pid 67073:tid 67307] [client 52.238.210.254:10167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoR_7vcmepr5_nHgLbMqnwAAAno"] [Tue Aug 18 12:53:18.343586 2026] [security2:error] [pid 67073:tid 67295] [client 4.223.164.152:6907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/simple.php"] [unique_id "aoR_7vcmepr5_nHgLbMqoAAAAm4"] [Tue Aug 18 12:53:18.345638 2026] [security2:error] [pid 66623:tid 66873] [client 20.48.236.86:65093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/8.php"] [unique_id "aoR_7tO5rbWdOArH04J5IAAAAXU"] [Tue Aug 18 12:53:18.423677 2026] [security2:error] [pid 66623:tid 66662] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/hel.php"] [unique_id "aoR_7tO5rbWdOArH04J5JQABNRk"] [Tue Aug 18 12:53:18.428118 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/iy.php"] [unique_id "aoR_7vcmepr5_nHgLbMqogAAAn8"] [Tue Aug 18 12:53:18.473249 2026] [security2:error] [pid 66623:tid 66799] [client 132.196.61.152:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/key.php"] [unique_id "aoR_7tO5rbWdOArH04J5JwAAASs"] [Tue Aug 18 12:53:18.496784 2026] [security2:error] [pid 66623:tid 66800] [client 172.202.39.151:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/lv.php"] [unique_id "aoR_7tO5rbWdOArH04J5KAAAASw"] [Tue Aug 18 12:53:18.516988 2026] [security2:error] [pid 66623:tid 66890] [client 149.34.210.141:56936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5GQAAAYY"] [Tue Aug 18 12:53:18.527258 2026] [security2:error] [pid 67073:tid 67292] [client 20.104.100.201:57311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/php5.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpAAAAms"] [Tue Aug 18 12:53:18.554684 2026] [security2:error] [pid 67073:tid 67302] [client 74.248.18.37:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/n.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpgAAAnU"] [Tue Aug 18 12:53:18.566483 2026] [security2:error] [pid 67073:tid 67309] [client 168.62.48.100:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoR_7vcmepr5_nHgLbMqpwAAAnw"] [Tue Aug 18 12:53:18.572093 2026] [security2:error] [pid 66623:tid 66830] [client 104.209.144.33:31236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoR_7tO5rbWdOArH04J5MAAAAUo"] [Tue Aug 18 12:53:18.573394 2026] [security2:error] [pid 66623:tid 66840] [client 104.209.144.33:25309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_7tO5rbWdOArH04J5MQAAAVQ"] [Tue Aug 18 12:53:18.589328 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqAAAAlQ"] [Tue Aug 18 12:53:18.590605 2026] [security2:error] [pid 67073:tid 67281] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/x.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqQAAAmA"] [Tue Aug 18 12:53:18.592674 2026] [security2:error] [pid 66623:tid 66827] [client 185.168.31.100:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.31.168.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acpecasebaterias.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7tO5rbWdOArH04J5JAAAAUc"] [Tue Aug 18 12:53:18.607004 2026] [security2:error] [pid 66623:tid 66768] [client 158.158.74.177:13712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/maintenance.php"] [unique_id "aoR_7tO5rbWdOArH04J5MwAAAQw"] [Tue Aug 18 12:53:18.613671 2026] [security2:error] [pid 66623:tid 66712] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/grok.php"] [unique_id "aoR_7tO5rbWdOArH04J5NQABfks"] [Tue Aug 18 12:53:18.629618 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/snq.php"] [unique_id "aoR_7tO5rbWdOArH04J5OAAAASY"] [Tue Aug 18 12:53:18.666630 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:15337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "aoR_7tO5rbWdOArH04J5OgAAASM"] [Tue Aug 18 12:53:18.680319 2026] [security2:error] [pid 67073:tid 67206] [client 68.221.73.131:4840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqgAAAhU"] [Tue Aug 18 12:53:18.685662 2026] [autoindex:error] [pid 66623:tid 66855] [client 4.223.164.152:54224] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:18.690995 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/thoms.php"] [unique_id "aoR_7tO5rbWdOArH04J5OwAAAUA"] [Tue Aug 18 12:53:18.698749 2026] [security2:error] [pid 67073:tid 67221] [client 20.100.169.31:15088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/h.php"] [unique_id "aoR_7vcmepr5_nHgLbMqqwAAAiQ"] [Tue Aug 18 12:53:18.720945 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:20256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrQAAAkw"] [Tue Aug 18 12:53:18.745299 2026] [security2:error] [pid 67073:tid 67322] [client 52.238.210.254:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aa.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrgAAAok"] [Tue Aug 18 12:53:18.769534 2026] [security2:error] [pid 66623:tid 66751] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/indes.php"] [unique_id "aoR_7tO5rbWdOArH04J5QAABM3I"] [Tue Aug 18 12:53:18.792281 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_7vcmepr5_nHgLbMqrwAAAmM"] [Tue Aug 18 12:53:18.805417 2026] [security2:error] [pid 67073:tid 67287] [client 168.62.48.100:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoR_7vcmepr5_nHgLbMqsAAAAmY"] [Tue Aug 18 12:53:18.820494 2026] [security2:error] [pid 66623:tid 66842] [client 132.196.61.152:38365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/kir.php"] [unique_id "aoR_7tO5rbWdOArH04J5RQAAAVY"] [Tue Aug 18 12:53:18.841280 2026] [security2:error] [pid 66623:tid 66784] [client 20.104.100.201:54045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoR_7tO5rbWdOArH04J5RgAAARw"] [Tue Aug 18 12:53:18.877678 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:25019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR_7vcmepr5_nHgLbMqsQAAAmk"] [Tue Aug 18 12:53:18.926171 2026] [security2:error] [pid 66623:tid 66732] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/tTPcH.php"] [unique_id "aoR_7tO5rbWdOArH04J5SwABiF8"] [Tue Aug 18 12:53:18.942990 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoR_7tO5rbWdOArH04J5TAAAAWY"] [Tue Aug 18 12:53:19.006403 2026] [security2:error] [pid 67073:tid 67306] [client 74.249.206.207:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/av.php"] [unique_id "aoR_7_cmepr5_nHgLbMqsgAAAnk"] [Tue Aug 18 12:53:19.007187 2026] [security2:error] [pid 66623:tid 66767] [client 5.253.205.188:35728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/export.bak"] [unique_id "aoR_79O5rbWdOArH04J5TwAAAQs"], referer: https://medihub.com.br/export.bak [Tue Aug 18 12:53:19.026319 2026] [security2:error] [pid 67073:tid 67259] [client 20.119.58.187:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/images/xmrlpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqswAAAko"] [Tue Aug 18 12:53:19.041778 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/wpxml.php"] [unique_id "aoR_79O5rbWdOArH04J5UAAAATg"] [Tue Aug 18 12:53:19.055114 2026] [security2:error] [pid 66623:tid 66887] [client 52.238.210.254:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/classwithtostring.php"] [unique_id "aoR_79O5rbWdOArH04J5UQAAAYM"] [Tue Aug 18 12:53:19.072916 2026] [security2:error] [pid 66623:tid 66866] [client 168.62.48.100:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoR_79O5rbWdOArH04J5UgAAAW4"] [Tue Aug 18 12:53:19.088090 2026] [security2:error] [pid 66623:tid 66757] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/bs1.php"] [unique_id "aoR_79O5rbWdOArH04J5VAABRng"] [Tue Aug 18 12:53:19.100750 2026] [security2:error] [pid 66623:tid 66885] [client 4.223.164.152:54224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/adminfuns.php"] [unique_id "aoR_79O5rbWdOArH04J5VQAAAYE"] [Tue Aug 18 12:53:19.101765 2026] [security2:error] [pid 66623:tid 66833] [client 20.171.51.14:57407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/og.php"] [unique_id "aoR_79O5rbWdOArH04J5VgAAAU0"] [Tue Aug 18 12:53:19.124268 2026] [security2:error] [pid 66623:tid 66860] [client 68.221.73.131:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/cabs.php"] [unique_id "aoR_79O5rbWdOArH04J5WAAAAWg"] [Tue Aug 18 12:53:19.140716 2026] [security2:error] [pid 66623:tid 66834] [client 132.196.61.152:45135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/nofile.php"] [unique_id "aoR_79O5rbWdOArH04J5WQAAAU4"] [Tue Aug 18 12:53:19.168653 2026] [security2:error] [pid 66623:tid 66785] [client 157.51.166.53:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_79O5rbWdOArH04J5WwAAAR0"] [Tue Aug 18 12:53:19.168775 2026] [security2:error] [pid 66623:tid 66785] [client 157.51.166.53:50082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_79O5rbWdOArH04J5WwAAAR0"] [Tue Aug 18 12:53:19.187386 2026] [security2:error] [pid 66623:tid 66813] [client 74.248.18.37:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/nc4.php"] [unique_id "aoR_79O5rbWdOArH04J5XAAAATk"] [Tue Aug 18 12:53:19.197378 2026] [security2:error] [pid 67073:tid 67304] [client 68.155.154.236:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/Cachex.php"] [unique_id "aoR_7_cmepr5_nHgLbMqtgAAAnc"] [Tue Aug 18 12:53:19.202759 2026] [security2:error] [pid 66623:tid 66851] [client 213.35.127.232:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_79O5rbWdOArH04J5XQAAAV8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:19.222573 2026] [security2:error] [pid 66623:tid 66783] [client 40.85.222.29:27743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_79O5rbWdOArH04J5XwAAARs"] [Tue Aug 18 12:53:19.235824 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:36375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns254.prodns.com.br"] [uri "/bf.php"] [unique_id "aoR_7_cmepr5_nHgLbMqtwAAAns"] [Tue Aug 18 12:53:19.241376 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.74.177:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/options-writing.php"] [unique_id "aoR_7_cmepr5_nHgLbMquAAAAiY"] [Tue Aug 18 12:53:19.262401 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMquQAAAoA"] [Tue Aug 18 12:53:19.262526 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:51624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMquQAAAoA"] [Tue Aug 18 12:53:19.272663 2026] [security2:error] [pid 66623:tid 66683] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/hp2.php"] [unique_id "aoR_79O5rbWdOArH04J5YgABOy4"] [Tue Aug 18 12:53:19.314037 2026] [security2:error] [pid 66623:tid 66879] [client 168.62.48.100:14733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoR_79O5rbWdOArH04J5ZAAAAXs"] [Tue Aug 18 12:53:19.342400 2026] [security2:error] [pid 67073:tid 67314] [client 178.153.171.161:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqugAAAoE"] [Tue Aug 18 12:53:19.342547 2026] [security2:error] [pid 67073:tid 67314] [client 178.153.171.161:5603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_7_cmepr5_nHgLbMqugAAAoE"] [Tue Aug 18 12:53:19.343914 2026] [security2:error] [pid 66623:tid 66775] [client 20.171.51.14:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ez.php"] [unique_id "aoR_79O5rbWdOArH04J5ZQAAARM"] [Tue Aug 18 12:53:19.378941 2026] [security2:error] [pid 67073:tid 67301] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/file1221.php"] [unique_id "aoR_7_cmepr5_nHgLbMquwAAAnQ"] [Tue Aug 18 12:53:19.385014 2026] [security2:error] [pid 66623:tid 66824] [client 20.119.58.187:15106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoR_79O5rbWdOArH04J5ZwAAAUQ"] [Tue Aug 18 12:53:19.390065 2026] [security2:error] [pid 67073:tid 67245] [client 52.238.210.254:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about.php"] [unique_id "aoR_7_cmepr5_nHgLbMqvQAAAjw"] [Tue Aug 18 12:53:19.428706 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/fling.php"] [unique_id "aoR_79O5rbWdOArH04J5aAAAAVk"] [Tue Aug 18 12:53:19.464585 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/new.php"] [unique_id "aoR_79O5rbWdOArH04J5agAAATU"] [Tue Aug 18 12:53:19.473744 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/chosen.php"] [unique_id "aoR_79O5rbWdOArH04J5awAAAXY"] [Tue Aug 18 12:53:19.485269 2026] [security2:error] [pid 66623:tid 66707] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/yb.php"] [unique_id "aoR_79O5rbWdOArH04J5bAABMEY"] [Tue Aug 18 12:53:19.548556 2026] [security2:error] [pid 67073:tid 67249] [client 168.62.48.100:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwAAAAkA"] [Tue Aug 18 12:53:19.552843 2026] [security2:error] [pid 66623:tid 66800] [client 68.221.73.131:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/insc.php"] [unique_id "aoR_79O5rbWdOArH04J5bgAAASw"] [Tue Aug 18 12:53:19.553824 2026] [security2:error] [pid 66623:tid 66859] [client 4.223.164.152:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_79O5rbWdOArH04J5bwAAAWc"] [Tue Aug 18 12:53:19.568055 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.169.31:28435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/archive.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwgAAAoY"] [Tue Aug 18 12:53:19.588680 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoR_7_cmepr5_nHgLbMqwwAAAjs"] [Tue Aug 18 12:53:19.590160 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.100.201:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/7.php"] [unique_id "aoR_79O5rbWdOArH04J5cAAAAXA"] [Tue Aug 18 12:53:19.611026 2026] [security2:error] [pid 66623:tid 66827] [client 104.209.144.33:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoR_79O5rbWdOArH04J5cQAAAUc"] [Tue Aug 18 12:53:19.619099 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:28954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxAAAAh0"] [Tue Aug 18 12:53:19.622101 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:47429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/tool.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxQAAAjM"] [Tue Aug 18 12:53:19.639026 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:44453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-login.php"] [unique_id "aoR_7_cmepr5_nHgLbMqxgAAAl4"] [Tue Aug 18 12:53:19.655638 2026] [security2:error] [pid 66623:tid 66741] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/vc.php"] [unique_id "aoR_79O5rbWdOArH04J5dQABVWg"] [Tue Aug 18 12:53:19.663388 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.32:31860] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:19.663661 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.32:31860] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:19.723899 2026] [security2:error] [pid 66623:tid 66674] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoR_79O5rbWdOArH04J5fQABEiU"] [Tue Aug 18 12:53:19.734811 2026] [autoindex:error] [pid 66623:tid 66772] [client 198.235.24.147:60110] AH01276: Cannot serve directory /home4/filial35/public_html/spotrestaurante/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:19.742151 2026] [security2:error] [pid 66623:tid 66798] [client 20.119.58.187:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "aoR_79O5rbWdOArH04J5gAAAASo"] [Tue Aug 18 12:53:19.754652 2026] [security2:error] [pid 67073:tid 67280] [client 104.209.144.33:32698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoR_7_cmepr5_nHgLbMqyQAAAl8"] [Tue Aug 18 12:53:19.766570 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.169.31:31247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_79O5rbWdOArH04J5ggAAAVE"] [Tue Aug 18 12:53:19.770016 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/zoo1.php"] [unique_id "aoR_7_cmepr5_nHgLbMqywAAAlM"] [Tue Aug 18 12:53:19.786234 2026] [security2:error] [pid 67073:tid 67293] [client 168.62.48.100:14744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzAAAAmw"] [Tue Aug 18 12:53:19.850597 2026] [security2:error] [pid 66623:tid 66679] [remote 190.6.176.90:44538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoR_79O5rbWdOArH04J5hwABDSo"] [Tue Aug 18 12:53:19.852256 2026] [security2:error] [pid 66623:tid 66708] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/pema.php"] [unique_id "aoR_79O5rbWdOArH04J5iAABHEc"] [Tue Aug 18 12:53:19.857738 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:12514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/new.php"] [unique_id "aoR_79O5rbWdOArH04J5iQAAAX4"] [Tue Aug 18 12:53:19.864930 2026] [security2:error] [pid 66623:tid 66852] [client 158.158.74.177:13802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoR_79O5rbWdOArH04J5igAAAWA"] [Tue Aug 18 12:53:19.914401 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:64532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_79O5rbWdOArH04J5jAAAAYA"] [Tue Aug 18 12:53:19.950266 2026] [security2:error] [pid 67073:tid 67238] [client 20.171.51.14:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lp.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzQAAAjU"] [Tue Aug 18 12:53:19.955069 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/nox.php"] [unique_id "aoR_79O5rbWdOArH04J5jQAAATQ"] [Tue Aug 18 12:53:19.970849 2026] [security2:error] [pid 67073:tid 67283] [client 68.221.73.131:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/file.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzgAAAmI"] [Tue Aug 18 12:53:19.981583 2026] [security2:error] [pid 67073:tid 67312] [client 4.223.164.152:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/222.php"] [unique_id "aoR_7_cmepr5_nHgLbMqzwAAAn8"] [Tue Aug 18 12:53:20.020715 2026] [security2:error] [pid 66623:tid 66680] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/sh.php"] [unique_id "aoR_8NO5rbWdOArH04J5jwABCys"] [Tue Aug 18 12:53:20.023690 2026] [security2:error] [pid 66623:tid 66883] [client 168.62.48.100:14801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoR_8NO5rbWdOArH04J5kAAAAX8"] [Tue Aug 18 12:53:20.028224 2026] [security2:error] [pid 67073:tid 67156] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0AACUlA"] [Tue Aug 18 12:53:20.028388 2026] [security2:error] [pid 67073:tid 67267] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0AACUlA"] [Tue Aug 18 12:53:20.044183 2026] [security2:error] [pid 66623:tid 66812] [client 104.209.144.33:25329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5kgAAATg"] [Tue Aug 18 12:53:20.046862 2026] [security2:error] [pid 66623:tid 66887] [client 74.248.136.165:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-access.php"] [unique_id "aoR_8NO5rbWdOArH04J5kwAAAYM"] [Tue Aug 18 12:53:20.055877 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:45732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_8NO5rbWdOArH04J5lQAAAYE"] [Tue Aug 18 12:53:20.057649 2026] [security2:error] [pid 66623:tid 66833] [client 132.196.61.152:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/zoo2.php"] [unique_id "aoR_8NO5rbWdOArH04J5lgAAAU0"] [Tue Aug 18 12:53:20.097766 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:14612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq0gAAAk8"] [Tue Aug 18 12:53:20.114755 2026] [security2:error] [pid 67073:tid 67298] [client 74.249.206.207:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/media.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1AAAAnE"] [Tue Aug 18 12:53:20.114768 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:10778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/biufile.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1QAAAls"] [Tue Aug 18 12:53:20.132166 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/wp-config.php.old"] [unique_id "aoR_8NO5rbWdOArH04J5mAABd1U"] [Tue Aug 18 12:53:20.135160 2026] [security2:error] [pid 66623:tid 66813] [client 52.238.210.254:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/goods.php"] [unique_id "aoR_8NO5rbWdOArH04J5mQAAATk"] [Tue Aug 18 12:53:20.179938 2026] [security2:error] [pid 66623:tid 66728] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/button.php"] [unique_id "aoR_8NO5rbWdOArH04J5nwABPFs"] [Tue Aug 18 12:53:20.185572 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.23:28168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:20.186024 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.23:28168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:20.201191 2026] [security2:error] [pid 66623:tid 66685] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/config/.env.php"] [unique_id "aoR_8NO5rbWdOArH04J5pAABGzA"] [Tue Aug 18 12:53:20.202489 2026] [security2:error] [pid 66623:tid 66649] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/.env.php.bak"] [unique_id "aoR_8NO5rbWdOArH04J5pQABegw"] [Tue Aug 18 12:53:20.221827 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:50007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_8NO5rbWdOArH04J5pwAAAVM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:20.258355 2026] [security2:error] [pid 66623:tid 66866] [client 20.91.215.254:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/lite.php"] [unique_id "aoR_8NO5rbWdOArH04J5qgAAAW4"] [Tue Aug 18 12:53:20.261508 2026] [security2:error] [pid 66623:tid 66823] [client 4.223.164.152:7090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/als.php"] [unique_id "aoR_8NO5rbWdOArH04J5qwAAAUM"] [Tue Aug 18 12:53:20.262941 2026] [security2:error] [pid 66623:tid 66789] [client 168.62.48.100:16299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoR_8NO5rbWdOArH04J5rAAAASE"] [Tue Aug 18 12:53:20.286468 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/akismet.php"] [unique_id "aoR_8NO5rbWdOArH04J5rwAAAR4"] [Tue Aug 18 12:53:20.306556 2026] [security2:error] [pid 67073:tid 67291] [client 135.136.0.233:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.0.136.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1wAAAmo"] [Tue Aug 18 12:53:20.306791 2026] [security2:error] [pid 67073:tid 67291] [client 135.136.0.233:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq1wAAAmo"] [Tue Aug 18 12:53:20.317168 2026] [security2:error] [pid 66623:tid 66801] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoR_8NO5rbWdOArH04J5sAAAAS0"] [Tue Aug 18 12:53:20.321151 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.100.201:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ws77.php"] [unique_id "aoR_8NO5rbWdOArH04J5sQAAAUQ"] [Tue Aug 18 12:53:20.334582 2026] [security2:error] [pid 66623:tid 66645] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wlc.php"] [unique_id "aoR_8NO5rbWdOArH04J5sgABeQg"] [Tue Aug 18 12:53:20.352944 2026] [security2:error] [pid 66623:tid 66845] [client 132.196.61.152:7786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/org.php"] [unique_id "aoR_8NO5rbWdOArH04J5swAAAVk"] [Tue Aug 18 12:53:20.382591 2026] [security2:error] [pid 66623:tid 66804] [client 68.221.73.131:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/dex.php"] [unique_id "aoR_8NO5rbWdOArH04J5tQAAATA"] [Tue Aug 18 12:53:20.415067 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.100.201:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/acp.php"] [unique_id "aoR_8NO5rbWdOArH04J5tgAAAUE"] [Tue Aug 18 12:53:20.437586 2026] [security2:error] [pid 67073:tid 67241] [client 104.209.144.33:31284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2AAAAjg"] [Tue Aug 18 12:53:20.455790 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:14809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoR_8NO5rbWdOArH04J5uAAAAYI"] [Tue Aug 18 12:53:20.457904 2026] [security2:error] [pid 66623:tid 66819] [client 4.223.164.152:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5ugAAAT8"] [Tue Aug 18 12:53:20.491005 2026] [security2:error] [pid 66623:tid 66702] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/fi.php"] [unique_id "aoR_8NO5rbWdOArH04J5vAABcEE"] [Tue Aug 18 12:53:20.495581 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/packed.php"] [unique_id "aoR_8NO5rbWdOArH04J5vQAAAXE"] [Tue Aug 18 12:53:20.500105 2026] [security2:error] [pid 66623:tid 66830] [client 168.62.48.100:14817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoR_8NO5rbWdOArH04J5vgAAAUo"] [Tue Aug 18 12:53:20.522326 2026] [security2:error] [pid 67073:tid 67305] [client 85.154.68.202:7533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2gAAAng"] [Tue Aug 18 12:53:20.522463 2026] [security2:error] [pid 67073:tid 67305] [client 85.154.68.202:7533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2gAAAng"] [Tue Aug 18 12:53:20.545364 2026] [security2:error] [pid 66623:tid 66827] [client 20.171.51.14:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ey.php"] [unique_id "aoR_8NO5rbWdOArH04J5wAAAAUc"] [Tue Aug 18 12:53:20.575781 2026] [security2:error] [pid 66623:tid 66873] [client 158.158.74.177:13805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/maint.php"] [unique_id "aoR_8NO5rbWdOArH04J5wwAAAXU"] [Tue Aug 18 12:53:20.636344 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/admin.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq2wAAAhs"] [Tue Aug 18 12:53:20.639904 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:41951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/nw.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq3AAAAmA"] [Tue Aug 18 12:53:20.642911 2026] [security2:error] [pid 67073:tid 67284] [client 52.238.210.254:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/php8.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq3QAAAmM"] [Tue Aug 18 12:53:20.655027 2026] [security2:error] [pid 66623:tid 66667] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/chris.php"] [unique_id "aoR_8NO5rbWdOArH04J5xgABMx4"] [Tue Aug 18 12:53:20.664179 2026] [security2:error] [pid 66623:tid 66792] [client 132.196.61.152:38380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/imageskir.php"] [unique_id "aoR_8NO5rbWdOArH04J5xwAAASQ"] [Tue Aug 18 12:53:20.664445 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:17976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR_8NO5rbWdOArH04J5yAAAASo"] [Tue Aug 18 12:53:20.666948 2026] [security2:error] [pid 66623:tid 66888] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoR_8NO5rbWdOArH04J5yQAAAYQ"] [Tue Aug 18 12:53:20.683385 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.18.37:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/php8.php"] [unique_id "aoR_8NO5rbWdOArH04J5ygAAAU8"] [Tue Aug 18 12:53:20.744713 2026] [security2:error] [pid 67073:tid 67218] [client 168.62.48.100:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4AAAAiE"] [Tue Aug 18 12:53:20.811900 2026] [security2:error] [pid 67073:tid 67282] [client 20.119.58.187:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4QAAAmE"] [Tue Aug 18 12:53:20.821082 2026] [security2:error] [pid 66623:tid 66770] [client 68.221.73.131:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/key.php"] [unique_id "aoR_8NO5rbWdOArH04J50AAAAQ4"] [Tue Aug 18 12:53:20.848630 2026] [security2:error] [pid 66623:tid 66655] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/doc.php"] [unique_id "aoR_8NO5rbWdOArH04J50QABNBI"] [Tue Aug 18 12:53:20.851662 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/asus.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4gAAAhk"] [Tue Aug 18 12:53:20.902109 2026] [security2:error] [pid 67073:tid 67327] [client 4.223.164.152:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq4wAAAo4"] [Tue Aug 18 12:53:20.907634 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:7061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/nox.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq5AAAAoc"] [Tue Aug 18 12:53:20.912159 2026] [security2:error] [pid 67073:tid 67230] [client 104.209.144.33:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/update/wpupex.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq5QAAAi0"] [Tue Aug 18 12:53:20.912250 2026] [security2:error] [pid 66623:tid 66892] [client 104.209.144.33:31265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoR_8NO5rbWdOArH04J50wAAAYg"] [Tue Aug 18 12:53:20.959750 2026] [security2:error] [pid 66623:tid 66767] [client 132.196.61.152:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/indexo.php"] [unique_id "aoR_8NO5rbWdOArH04J51AAAAQs"] [Tue Aug 18 12:53:20.965300 2026] [security2:error] [pid 66623:tid 66883] [client 52.238.210.254:10219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/info.php"] [unique_id "aoR_8NO5rbWdOArH04J51QAAAX8"] [Tue Aug 18 12:53:20.980968 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:14735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoR_8Pcmepr5_nHgLbMq6AAAApE"] [Tue Aug 18 12:53:20.982048 2026] [security2:error] [pid 66623:tid 66826] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/bajah.php"] [unique_id "aoR_8NO5rbWdOArH04J51gAAAUY"] [Tue Aug 18 12:53:20.989817 2026] [security2:error] [pid 67073:tid 67162] [remote 57.141.22.106:57970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_8Pcmepr5_nHgLbMq6QACIFY"] [Tue Aug 18 12:53:21.006711 2026] [security2:error] [pid 66623:tid 66834] [client 20.104.100.201:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/read.php"] [unique_id "aoR_8dO5rbWdOArH04J52AAAAU4"] [Tue Aug 18 12:53:21.012343 2026] [security2:error] [pid 66623:tid 66822] [client 20.91.215.254:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoR_8dO5rbWdOArH04J52QAAAUI"] [Tue Aug 18 12:53:21.033694 2026] [security2:error] [pid 67073:tid 67255] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoR_7_cmepr5_nHgLbMqvgACRk4"], referer: https://1ba.com.br/ [Tue Aug 18 12:53:21.034402 2026] [security2:error] [pid 67073:tid 67211] [client 68.155.154.236:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_8fcmepr5_nHgLbMq6wAAAho"] [Tue Aug 18 12:53:21.037520 2026] [security2:error] [pid 66623:tid 66705] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/1337.php"] [unique_id "aoR_8dO5rbWdOArH04J52gABHUQ"] [Tue Aug 18 12:53:21.095399 2026] [security2:error] [pid 66623:tid 66782] [client 34.198.201.66:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoR_79O5rbWdOArH04J5fwABGnc"], referer: https://alsconsultoria.com.br/ [Tue Aug 18 12:53:21.109738 2026] [security2:error] [pid 66623:tid 66650] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/config.php.bak"] [unique_id "aoR_8dO5rbWdOArH04J53wABXw0"] [Tue Aug 18 12:53:21.124476 2026] [security2:error] [pid 66623:tid 66723] [remote 136.110.27.48:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lencoisflat.com.br"] [uri "/configuration.php.bak"] [unique_id "aoR_8dO5rbWdOArH04J54AABX1Y"] [Tue Aug 18 12:53:21.171349 2026] [security2:error] [pid 67073:tid 67235] [client 20.119.58.187:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/mail.php"] [unique_id "aoR_8fcmepr5_nHgLbMq7QAAAjI"] [Tue Aug 18 12:53:21.204212 2026] [security2:error] [pid 66623:tid 66854] [client 158.158.74.177:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/phpMailer.php"] [unique_id "aoR_8dO5rbWdOArH04J55wAAAWI"] [Tue Aug 18 12:53:21.219926 2026] [security2:error] [pid 67073:tid 67314] [client 168.62.48.100:14825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoR_8fcmepr5_nHgLbMq7wAAAoE"] [Tue Aug 18 12:53:21.238975 2026] [security2:error] [pid 67073:tid 67229] [client 213.35.127.232:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8AAAAiw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:21.239261 2026] [security2:error] [pid 66623:tid 66724] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/Njima.php"] [unique_id "aoR_8dO5rbWdOArH04J56AABQ1c"] [Tue Aug 18 12:53:21.249407 2026] [security2:error] [pid 67073:tid 67209] [client 132.196.61.152:23819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8QAAAhg"] [Tue Aug 18 12:53:21.257854 2026] [security2:error] [pid 67073:tid 67263] [client 68.221.73.131:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/kir.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8gAAAk4"] [Tue Aug 18 12:53:21.280154 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lv.php"] [unique_id "aoR_8fcmepr5_nHgLbMq8wAAAks"] [Tue Aug 18 12:53:21.334507 2026] [security2:error] [pid 66623:tid 66789] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/ajax.php"] [unique_id "aoR_8dO5rbWdOArH04J56wAAASE"] [Tue Aug 18 12:53:21.354932 2026] [autoindex:error] [pid 67073:tid 67323] [client 4.223.164.152:37256] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:21.356370 2026] [security2:error] [pid 66623:tid 66786] [client 4.223.164.152:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file59.php"] [unique_id "aoR_8dO5rbWdOArH04J57AAAAR4"] [Tue Aug 18 12:53:21.366108 2026] [security2:error] [pid 67073:tid 67299] [client 52.238.210.254:10179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/chosen.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9QAAAnI"] [Tue Aug 18 12:53:21.393212 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:62345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/plugin.php"] [unique_id "aoR_8dO5rbWdOArH04J57gAAARM"] [Tue Aug 18 12:53:21.423269 2026] [security2:error] [pid 66623:tid 66729] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/BIBIL.php"] [unique_id "aoR_8dO5rbWdOArH04J57wABeVw"] [Tue Aug 18 12:53:21.455175 2026] [security2:error] [pid 66623:tid 66766] [client 168.62.48.100:14830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoR_8dO5rbWdOArH04J58AAAAQo"] [Tue Aug 18 12:53:21.474909 2026] [security2:error] [pid 66623:tid 66809] [client 52.238.210.254:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/simple.php"] [unique_id "aoR_8dO5rbWdOArH04J58gAAATU"] [Tue Aug 18 12:53:21.487201 2026] [security2:error] [pid 67073:tid 67319] [client 74.248.136.165:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/nw.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9gAAAoY"] [Tue Aug 18 12:53:21.531507 2026] [security2:error] [pid 67073:tid 67236] [client 74.249.206.207:13369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/images.php"] [unique_id "aoR_8fcmepr5_nHgLbMq9wAAAjM"] [Tue Aug 18 12:53:21.549583 2026] [security2:error] [pid 66623:tid 66804] [client 132.196.61.152:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/8pyceeo.php"] [unique_id "aoR_8dO5rbWdOArH04J58wAAATA"] [Tue Aug 18 12:53:21.560294 2026] [security2:error] [pid 66623:tid 66801] [client 20.119.58.187:15139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/upfile.php"] [unique_id "aoR_8dO5rbWdOArH04J59QAAAS0"] [Tue Aug 18 12:53:21.562146 2026] [security2:error] [pid 66623:tid 66821] [client 40.85.222.29:45737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_8dO5rbWdOArH04J59gAAAUE"] [Tue Aug 18 12:53:21.610616 2026] [security2:error] [pid 66623:tid 66712] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/too.php"] [unique_id "aoR_8dO5rbWdOArH04J59wABZks"] [Tue Aug 18 12:53:21.618435 2026] [security2:error] [pid 67073:tid 67256] [client 104.209.144.33:31235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-QAAAkc"] [Tue Aug 18 12:53:21.621848 2026] [security2:error] [pid 66623:tid 66859] [client 104.209.144.33:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoR_8dO5rbWdOArH04J5-AAAAWc"] [Tue Aug 18 12:53:21.651848 2026] [security2:error] [pid 66623:tid 66845] [client 20.100.169.31:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/a7.php"] [unique_id "aoR_8dO5rbWdOArH04J5-QAAAVk"] [Tue Aug 18 12:53:21.670675 2026] [security2:error] [pid 67073:tid 67277] [client 20.171.51.14:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/51.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-gAAAlw"] [Tue Aug 18 12:53:21.672446 2026] [security2:error] [pid 67073:tid 67321] [client 68.221.73.131:4356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/nofile.php"] [unique_id "aoR_8fcmepr5_nHgLbMq-wAAAog"] [Tue Aug 18 12:53:21.673922 2026] [security2:error] [pid 66623:tid 66677] [remote 203.99.146.53:54174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villanobreeventos.com.br"] [uri "/wp-login.php"] [unique_id "aoR_8dO5rbWdOArH04J5-wABOyg"] [Tue Aug 18 12:53:21.675151 2026] [security2:error] [pid 66623:tid 66830] [client 20.100.177.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.177.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.danielimoveispva.com.br"] [uri "/adminfuns.php"] [unique_id "aoR_8dO5rbWdOArH04J5_AAAAUo"] [Tue Aug 18 12:53:21.675883 2026] [security2:error] [pid 67073:tid 67280] [client 20.42.19.40:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/222.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_AAAAl8"] [Tue Aug 18 12:53:21.684375 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.169.31:33167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/bless.php"] [unique_id "aoR_8dO5rbWdOArH04J5_QAAATg"] [Tue Aug 18 12:53:21.691752 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:14780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoR_8dO5rbWdOArH04J5_gAAARc"] [Tue Aug 18 12:53:21.692651 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/simple.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_gAAAiU"] [Tue Aug 18 12:53:21.718851 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_8fcmepr5_nHgLbMq_wAAAo8"] [Tue Aug 18 12:53:21.732540 2026] [security2:error] [pid 66623:tid 66841] [client 20.104.100.201:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/albin.php"] [unique_id "aoR_8dO5rbWdOArH04J5_wAAAVU"] [Tue Aug 18 12:53:21.790051 2026] [security2:error] [pid 66623:tid 66805] [client 20.48.236.86:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/coffexium.php"] [unique_id "aoR_8dO5rbWdOArH04J6AQAAATE"] [Tue Aug 18 12:53:21.797292 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAQAAAmw"] [Tue Aug 18 12:53:21.798234 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.100.201:57313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/yas.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAgAAAlY"] [Tue Aug 18 12:53:21.821068 2026] [security2:error] [pid 66623:tid 66819] [client 20.91.215.254:20264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoR_8dO5rbWdOArH04J6BAAAAT8"] [Tue Aug 18 12:53:21.841742 2026] [security2:error] [pid 66623:tid 66710] [remote 20.250.27.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/g3.php"] [unique_id "aoR_8dO5rbWdOArH04J6BgABKEk"] [Tue Aug 18 12:53:21.850715 2026] [security2:error] [pid 67073:tid 67257] [client 172.202.39.151:43619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/aa.php"] [unique_id "aoR_8fcmepr5_nHgLbMrAwAAAkg"] [Tue Aug 18 12:53:21.868901 2026] [security2:error] [pid 66623:tid 66733] [remote 57.141.22.5:29270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_8dO5rbWdOArH04J6CgABImA"] [Tue Aug 18 12:53:21.893634 2026] [security2:error] [pid 66623:tid 66869] [client 158.158.74.177:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoR_8dO5rbWdOArH04J6DAAAAXE"] [Tue Aug 18 12:53:21.914048 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-conflg.php"] [unique_id "aoR_8dO5rbWdOArH04J6DQAAASM"] [Tue Aug 18 12:53:21.925209 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoR_8dO5rbWdOArH04J6DwAAAVY"] [Tue Aug 18 12:53:21.927004 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:43348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/22.php"] [unique_id "aoR_8fcmepr5_nHgLbMrBQAAAn8"] [Tue Aug 18 12:53:21.930652 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:45143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/.admin.php"] [unique_id "aoR_8fcmepr5_nHgLbMrBwAAAlU"] [Tue Aug 18 12:53:21.937675 2026] [authz_core:error] [pid 66623:tid 66855] [client 192.178.4.133:64761] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:21.937986 2026] [authz_core:error] [pid 66623:tid 66855] [client 192.178.4.133:64761] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:22.015909 2026] [security2:error] [pid 66623:tid 66784] [client 40.85.222.29:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6EwAAARw"] [Tue Aug 18 12:53:22.018137 2026] [security2:error] [pid 66623:tid 66811] [client 104.209.144.33:31294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6FAAAATc"] [Tue Aug 18 12:53:22.020287 2026] [security2:error] [pid 67073:tid 67298] [client 104.209.144.33:32682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_8vcmepr5_nHgLbMrCAAAAnE"] [Tue Aug 18 12:53:22.058375 2026] [security2:error] [pid 66623:tid 66861] [client 52.238.210.254:10223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoR_8tO5rbWdOArH04J6FwAAAWk"] [Tue Aug 18 12:53:22.087368 2026] [security2:error] [pid 67073:tid 67254] [client 68.221.73.131:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/fling.php"] [unique_id "aoR_8vcmepr5_nHgLbMrCgAAAkU"] [Tue Aug 18 12:53:22.128378 2026] [security2:error] [pid 66623:tid 66880] [client 4.223.164.152:7049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/admin.php"] [unique_id "aoR_8tO5rbWdOArH04J6GQAAAXw"] [Tue Aug 18 12:53:22.162299 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoR_8tO5rbWdOArH04J6GgAAARY"] [Tue Aug 18 12:53:22.172121 2026] [security2:error] [pid 66623:tid 66882] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoR_8tO5rbWdOArH04J6GwABfgc"], referer: https://graices.com.br/ [Tue Aug 18 12:53:22.177115 2026] [security2:error] [pid 67073:tid 67274] [client 52.173.121.69:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/blog/byp.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDAAAAlk"] [Tue Aug 18 12:53:22.247831 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/i.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDgAAAmo"] [Tue Aug 18 12:53:22.252448 2026] [security2:error] [pid 66623:tid 66798] [client 213.35.127.232:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6HQAAASo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:22.261899 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/public/moon.php"] [unique_id "aoR_8vcmepr5_nHgLbMrDwAAAn4"] [Tue Aug 18 12:53:22.267172 2026] [security2:error] [pid 67073:tid 67315] [client 52.173.121.69:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEAAAAoI"] [Tue Aug 18 12:53:22.273240 2026] [security2:error] [pid 67073:tid 67294] [client 132.196.61.152:25673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wsomini.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEQAAAm0"] [Tue Aug 18 12:53:22.283192 2026] [security2:error] [pid 67073:tid 67310] [client 20.119.58.187:15353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/xmrlpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEgAAAn0"] [Tue Aug 18 12:53:22.340362 2026] [security2:error] [pid 66623:tid 66787] [client 68.155.154.236:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_8tO5rbWdOArH04J6IAAAAR8"] [Tue Aug 18 12:53:22.383341 2026] [security2:error] [pid 66623:tid 66875] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoR_8tO5rbWdOArH04J6HwABd34"], referer: https://graices.com.br/ [Tue Aug 18 12:53:22.409716 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoR_8vcmepr5_nHgLbMrEwAAAmg"] [Tue Aug 18 12:53:22.418564 2026] [security2:error] [pid 67073:tid 67212] [client 40.85.222.29:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFQAAAhs"] [Tue Aug 18 12:53:22.419670 2026] [security2:error] [pid 67073:tid 67281] [client 168.62.48.100:14822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFgAAAmA"] [Tue Aug 18 12:53:22.433513 2026] [security2:error] [pid 66623:tid 66887] [client 20.42.19.40:2699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/asasx.php"] [unique_id "aoR_8tO5rbWdOArH04J6JAAAAYM"] [Tue Aug 18 12:53:22.441844 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fw/34.php"] [unique_id "aoR_8vcmepr5_nHgLbMrFwAAAmk"] [Tue Aug 18 12:53:22.471184 2026] [security2:error] [pid 67073:tid 67329] [client 20.171.51.14:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ew.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGAAAApA"] [Tue Aug 18 12:53:22.479787 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGQAAAjg"] [Tue Aug 18 12:53:22.501782 2026] [security2:error] [pid 66623:tid 66854] [client 20.171.51.14:15789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zs.php"] [unique_id "aoR_8tO5rbWdOArH04J6JgAAAWI"] [Tue Aug 18 12:53:22.524431 2026] [security2:error] [pid 66623:tid 66785] [client 158.158.74.177:13780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/al.php"] [unique_id "aoR_8tO5rbWdOArH04J6JwAAAR0"] [Tue Aug 18 12:53:22.526626 2026] [security2:error] [pid 67073:tid 67228] [client 68.221.73.131:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/zoo1.php"] [unique_id "aoR_8vcmepr5_nHgLbMrGgAAAis"] [Tue Aug 18 12:53:22.535358 2026] [security2:error] [pid 66623:tid 66866] [client 104.209.144.33:24852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoR_8tO5rbWdOArH04J6KAAAAW4"] [Tue Aug 18 12:53:22.558525 2026] [security2:error] [pid 67073:tid 67327] [client 104.209.144.33:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHAAAAo4"] [Tue Aug 18 12:53:22.580198 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ws62.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHQAAAi0"] [Tue Aug 18 12:53:22.630001 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:45149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/vr.php"] [unique_id "aoR_8tO5rbWdOArH04J6KgAAAUQ"] [Tue Aug 18 12:53:22.647322 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ae.php"] [unique_id "aoR_8tO5rbWdOArH04J6LAAAASk"] [Tue Aug 18 12:53:22.664163 2026] [security2:error] [pid 67073:tid 67322] [client 168.62.48.100:14845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHgAAAok"] [Tue Aug 18 12:53:22.668669 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:6618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/aa2.php"] [unique_id "aoR_8vcmepr5_nHgLbMrHwAAAko"] [Tue Aug 18 12:53:22.670362 2026] [security2:error] [pid 67073:tid 67232] [client 4.223.164.152:64697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/abcd.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIAAAAi8"] [Tue Aug 18 12:53:22.714654 2026] [security2:error] [pid 67073:tid 67276] [client 37.40.227.74:56769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIQAAAls"] [Tue Aug 18 12:53:22.714843 2026] [security2:error] [pid 67073:tid 67276] [client 37.40.227.74:56769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIQAAAls"] [Tue Aug 18 12:53:22.758860 2026] [security2:error] [pid 67073:tid 67252] [client 172.182.200.96:14194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/nwwha.php"] [unique_id "aoR_8vcmepr5_nHgLbMrIgAAAkM"] [Tue Aug 18 12:53:22.771753 2026] [security2:error] [pid 66623:tid 66801] [client 172.202.39.151:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/222.php"] [unique_id "aoR_8tO5rbWdOArH04J6LwAAAS0"] [Tue Aug 18 12:53:22.804491 2026] [security2:error] [pid 67073:tid 67205] [client 5.253.205.188:35774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/export.sql"] [unique_id "aoR_8vcmepr5_nHgLbMrIwAAAhQ"], referer: https://medihub.com.br/export.sql [Tue Aug 18 12:53:22.819899 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.98.162:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJAAAAjI"] [Tue Aug 18 12:53:22.824285 2026] [security2:error] [pid 67073:tid 67314] [client 52.238.210.254:10231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/av.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJQAAAoE"] [Tue Aug 18 12:53:22.884892 2026] [security2:error] [pid 67073:tid 67245] [client 20.171.51.14:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/pqr.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJgAAAjw"] [Tue Aug 18 12:53:22.889528 2026] [security2:error] [pid 67073:tid 67263] [client 104.209.144.33:31295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoR_8vcmepr5_nHgLbMrJwAAAk4"] [Tue Aug 18 12:53:22.890202 2026] [security2:error] [pid 66623:tid 66799] [client 104.209.144.33:25324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_8tO5rbWdOArH04J6NAAAASs"] [Tue Aug 18 12:53:22.891209 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.18.37:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/public/storage.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKAAAAnY"] [Tue Aug 18 12:53:22.896421 2026] [security2:error] [pid 67073:tid 67247] [client 168.62.48.100:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKQAAAj4"] [Tue Aug 18 12:53:22.912340 2026] [security2:error] [pid 66623:tid 66886] [client 20.151.109.219:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/rx.php"] [unique_id "aoR_8tO5rbWdOArH04J6NQAAAYI"] [Tue Aug 18 12:53:22.993920 2026] [security2:error] [pid 67073:tid 67216] [client 68.221.73.131:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/zoo2.php"] [unique_id "aoR_8vcmepr5_nHgLbMrKgAAAh8"] [Tue Aug 18 12:53:23.009259 2026] [security2:error] [pid 67073:tid 67260] [client 20.119.58.187:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/moon.php"] [unique_id "aoR_8_cmepr5_nHgLbMrKwAAAks"] [Tue Aug 18 12:53:23.049152 2026] [security2:error] [pid 66623:tid 66789] [client 149.34.210.157:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_89O5rbWdOArH04J6OAAAASE"] [Tue Aug 18 12:53:23.058819 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:23.059087 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:23.079631 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoR_8_cmepr5_nHgLbMrLgAAAkQ"] [Tue Aug 18 12:53:23.113270 2026] [security2:error] [pid 67073:tid 67328] [client 172.202.39.151:24943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/0x.php"] [unique_id "aoR_8_cmepr5_nHgLbMrLwAAAo8"] [Tue Aug 18 12:53:23.116754 2026] [security2:error] [pid 67073:tid 67208] [client 52.139.47.57:11552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMAAAAhc"] [Tue Aug 18 12:53:23.127585 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-manager.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMgAAAmw"] [Tue Aug 18 12:53:23.129641 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:23.129922 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:23.131052 2026] [security2:error] [pid 67073:tid 67271] [client 168.62.48.100:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoR_8_cmepr5_nHgLbMrMwAAAlY"] [Tue Aug 18 12:53:23.138115 2026] [security2:error] [pid 67073:tid 67295] [client 20.48.236.86:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/dex.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNAAAAm4"] [Tue Aug 18 12:53:23.154656 2026] [security2:error] [pid 67073:tid 67273] [client 74.249.206.207:21032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/mac.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNgAAAlg"] [Tue Aug 18 12:53:23.154680 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:30502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_8_cmepr5_nHgLbMrNQAAAkg"] [Tue Aug 18 12:53:23.179785 2026] [security2:error] [pid 67073:tid 67249] [client 20.91.215.254:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/xmrlpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOAAAAkA"] [Tue Aug 18 12:53:23.189747 2026] [security2:error] [pid 67073:tid 67265] [client 158.158.74.177:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOQAAAlA"] [Tue Aug 18 12:53:23.196327 2026] [security2:error] [pid 67073:tid 67238] [client 4.223.164.152:6629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/xamp.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOgAAAjU"] [Tue Aug 18 12:53:23.261551 2026] [security2:error] [pid 67073:tid 67264] [client 104.209.144.33:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_8_cmepr5_nHgLbMrOwAAAk8"] [Tue Aug 18 12:53:23.263074 2026] [security2:error] [pid 66623:tid 66773] [client 213.35.127.232:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_89O5rbWdOArH04J6PAAAARE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:23.263074 2026] [security2:error] [pid 67073:tid 67251] [client 104.209.144.33:25331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/well-known/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPAAAAkI"] [Tue Aug 18 12:53:23.264830 2026] [security2:error] [pid 67073:tid 67298] [client 20.104.100.201:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp9.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPQAAAnE"] [Tue Aug 18 12:53:23.319309 2026] [security2:error] [pid 66623:tid 66789] [client 149.34.210.157:64406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_89O5rbWdOArH04J6OAAAASE"] [Tue Aug 18 12:53:23.369887 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:14608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ini.php"] [unique_id "aoR_8_cmepr5_nHgLbMrPwAAAn8"] [Tue Aug 18 12:53:23.403686 2026] [security2:error] [pid 67073:tid 67310] [client 168.62.48.100:14728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQAAAAn0"] [Tue Aug 18 12:53:23.409507 2026] [security2:error] [pid 67073:tid 67331] [client 52.173.121.69:54437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQQAAApI"] [Tue Aug 18 12:53:23.431472 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:23.431756 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:23.441739 2026] [security2:error] [pid 67073:tid 67272] [client 68.221.73.131:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/org.php"] [unique_id "aoR_8_cmepr5_nHgLbMrQwAAAlc"] [Tue Aug 18 12:53:23.443107 2026] [security2:error] [pid 67073:tid 67289] [client 20.104.100.201:57329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/ah25.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRAAAAmg"] [Tue Aug 18 12:53:23.490177 2026] [security2:error] [pid 67073:tid 67212] [client 74.249.206.207:21005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/ops.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRgAAAhs"] [Tue Aug 18 12:53:23.543400 2026] [security2:error] [pid 67073:tid 67282] [client 52.238.210.254:31474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoR_8_cmepr5_nHgLbMrRwAAAmE"] [Tue Aug 18 12:53:23.547135 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:32673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSAAAAhk"] [Tue Aug 18 12:53:23.552397 2026] [security2:error] [pid 67073:tid 67286] [client 196.12.128.158:53110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSQAAAmU"] [Tue Aug 18 12:53:23.552563 2026] [security2:error] [pid 67073:tid 67286] [client 196.12.128.158:53110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSQAAAmU"] [Tue Aug 18 12:53:23.570504 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/radio.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSgAAAlk"] [Tue Aug 18 12:53:23.571859 2026] [security2:error] [pid 66623:tid 66812] [client 104.209.144.33:24844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_89O5rbWdOArH04J6RwAAATg"] [Tue Aug 18 12:53:23.586658 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoR_8_cmepr5_nHgLbMrSwAAAjg"] [Tue Aug 18 12:53:23.606704 2026] [security2:error] [pid 67073:tid 67313] [client 4.232.151.198:30468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/xleet.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTAAAAoA"] [Tue Aug 18 12:53:23.637937 2026] [security2:error] [pid 67073:tid 67230] [client 168.62.48.100:14803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTQAAAi0"] [Tue Aug 18 12:53:23.641262 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:29203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/an.php"] [unique_id "aoR_8_cmepr5_nHgLbMrTgAAAnA"] [Tue Aug 18 12:53:23.647192 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:10139] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin"] [unique_id "aoR_8_cmepr5_nHgLbMrTwAAAiA"] [Tue Aug 18 12:53:23.689445 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:17937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUAAAAi8"] [Tue Aug 18 12:53:23.727611 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:15141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/shell.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUQAAAmc"] [Tue Aug 18 12:53:23.797006 2026] [security2:error] [pid 66623:tid 66891] [client 4.223.164.152:6622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/bless.php"] [unique_id "aoR_89O5rbWdOArH04J6UAAAAYc"] [Tue Aug 18 12:53:23.815434 2026] [security2:error] [pid 66623:tid 66841] [client 158.158.74.177:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-activat.php"] [unique_id "aoR_89O5rbWdOArH04J6UQAAAVU"] [Tue Aug 18 12:53:23.836640 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_89O5rbWdOArH04J6UgAAASI"] [Tue Aug 18 12:53:23.868117 2026] [security2:error] [pid 66623:tid 66814] [client 68.221.73.131:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/imageskir.php"] [unique_id "aoR_89O5rbWdOArH04J6VAAAATo"] [Tue Aug 18 12:53:23.873710 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:14660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoR_89O5rbWdOArH04J6VQAAASQ"] [Tue Aug 18 12:53:23.915432 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.136.165:23367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/public/vx.php"] [unique_id "aoR_89O5rbWdOArH04J6WAAAASM"] [Tue Aug 18 12:53:23.917968 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:29230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUgAAAnQ"] [Tue Aug 18 12:53:23.918929 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_8_cmepr5_nHgLbMrUwAAAk0"] [Tue Aug 18 12:53:23.936112 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoR_8_cmepr5_nHgLbMrVAAAAho"] [Tue Aug 18 12:53:23.949914 2026] [security2:error] [pid 66623:tid 66888] [client 104.209.144.33:25315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_89O5rbWdOArH04J6WgAAAYQ"] [Tue Aug 18 12:53:23.981089 2026] [security2:error] [pid 66623:tid 66820] [client 104.209.144.33:32659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_89O5rbWdOArH04J6XgAAAUA"] [Tue Aug 18 12:53:23.995472 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.100.201:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/save.php"] [unique_id "aoR_8_cmepr5_nHgLbMrVQAAAjw"] [Tue Aug 18 12:53:24.036442 2026] [security2:error] [pid 66623:tid 66663] [remote 57.141.22.17:58500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoR_9NO5rbWdOArH04J6XwABVho"] [Tue Aug 18 12:53:24.079207 2026] [security2:error] [pid 67073:tid 67263] [client 20.151.109.219:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/mandrill.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrVgAAAk4"] [Tue Aug 18 12:53:24.094102 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrVwAAAnY"] [Tue Aug 18 12:53:24.096268 2026] [security2:error] [pid 66623:tid 66835] [client 20.119.58.187:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/makeasmtp.php"] [unique_id "aoR_9NO5rbWdOArH04J6YQAAAU8"] [Tue Aug 18 12:53:24.106319 2026] [security2:error] [pid 67073:tid 67323] [client 168.62.48.100:14720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWAAAAoo"] [Tue Aug 18 12:53:24.168299 2026] [security2:error] [pid 67073:tid 67214] [client 74.249.206.207:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/coffexium.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWQAAAh0"] [Tue Aug 18 12:53:24.185852 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sy.php"] [unique_id "aoR_9NO5rbWdOArH04J6ZQAAAYE"] [Tue Aug 18 12:53:24.189763 2026] [security2:error] [pid 67073:tid 67236] [client 20.171.51.14:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iz.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWgAAAjM"] [Tue Aug 18 12:53:24.212223 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.18.37:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/root.php"] [unique_id "aoR_9NO5rbWdOArH04J6ZgAAATc"] [Tue Aug 18 12:53:24.270640 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:18360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrWwAAAic"] [Tue Aug 18 12:53:24.274230 2026] [security2:error] [pid 67073:tid 67229] [client 213.35.127.232:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXAAAAiw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:24.300944 2026] [security2:error] [pid 66623:tid 66844] [client 68.221.73.131:4856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/indexo.php"] [unique_id "aoR_9NO5rbWdOArH04J6aAAAAVg"] [Tue Aug 18 12:53:24.317334 2026] [security2:error] [pid 66623:tid 66813] [client 4.223.164.152:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file25.php"] [unique_id "aoR_9NO5rbWdOArH04J6agAAATk"] [Tue Aug 18 12:53:24.342843 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoR_9NO5rbWdOArH04J6awAAAR8"] [Tue Aug 18 12:53:24.366005 2026] [security2:error] [pid 66623:tid 66702] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6bAABJUE"] [Tue Aug 18 12:53:24.366194 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6bAABJUE"] [Tue Aug 18 12:53:24.372055 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.154.236:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6bQAAAXo"] [Tue Aug 18 12:53:24.376705 2026] [security2:error] [pid 66623:tid 66783] [client 52.238.210.254:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp.php"] [unique_id "aoR_9NO5rbWdOArH04J6bgAAARs"] [Tue Aug 18 12:53:24.449009 2026] [security2:error] [pid 66623:tid 66807] [client 197.184.64.235:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6cAAAATM"] [Tue Aug 18 12:53:24.449115 2026] [security2:error] [pid 66623:tid 66807] [client 197.184.64.235:41354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6cAAAATM"] [Tue Aug 18 12:53:24.460444 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.74.177:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXgAAAi4"] [Tue Aug 18 12:53:24.463913 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:14646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-sigunq.php"] [unique_id "aoR_9NO5rbWdOArH04J6cQAAATw"] [Tue Aug 18 12:53:24.565813 2026] [security2:error] [pid 67073:tid 67299] [client 20.100.169.31:12625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/sagax1.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrXwAAAnI"] [Tue Aug 18 12:53:24.572322 2026] [security2:error] [pid 66623:tid 66775] [client 104.209.144.33:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_9NO5rbWdOArH04J6cwAAARM"] [Tue Aug 18 12:53:24.578831 2026] [security2:error] [pid 66623:tid 66824] [client 168.62.48.100:14837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoR_9NO5rbWdOArH04J6dAAAAUQ"] [Tue Aug 18 12:53:24.599210 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:10678] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "m2mit.info"] [uri "/1.php"] [unique_id "aoR_9NO5rbWdOArH04J6dwAAATU"] [Tue Aug 18 12:53:24.599308 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:10678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/1.php"] [unique_id "aoR_9NO5rbWdOArH04J6dwAAATU"] [Tue Aug 18 12:53:24.629181 2026] [autoindex:error] [pid 66623:tid 66851] [client 20.91.215.254:16651] AH01276: Cannot serve directory /home2/reservamatadapra/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:24.636416 2026] [security2:error] [pid 66623:tid 66782] [client 20.100.169.31:16591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/manager.php"] [unique_id "aoR_9NO5rbWdOArH04J6eAAAARo"] [Tue Aug 18 12:53:24.654866 2026] [security2:error] [pid 66623:tid 66795] [client 20.42.19.40:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/filemanager.php"] [unique_id "aoR_9NO5rbWdOArH04J6fAAAASc"] [Tue Aug 18 12:53:24.660351 2026] [security2:error] [pid 66623:tid 66800] [client 40.85.222.29:27770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6fQAAASw"] [Tue Aug 18 12:53:24.686215 2026] [security2:error] [pid 67073:tid 67173] [remote 203.99.146.53:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guinchomarquette.com.br"] [uri "/wp-login.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYAACUmE"] [Tue Aug 18 12:53:24.688168 2026] [security2:error] [pid 66623:tid 66773] [client 20.171.51.14:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/57.php"] [unique_id "aoR_9NO5rbWdOArH04J6fgAAARE"] [Tue Aug 18 12:53:24.720352 2026] [security2:error] [pid 66623:tid 66890] [client 20.171.51.14:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/se.php"] [unique_id "aoR_9NO5rbWdOArH04J6gAAAAYY"] [Tue Aug 18 12:53:24.720647 2026] [security2:error] [pid 66623:tid 66845] [client 68.221.73.131:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoR_9NO5rbWdOArH04J6gQAAAVk"] [Tue Aug 18 12:53:24.738373 2026] [security2:error] [pid 66623:tid 66830] [client 104.209.144.33:25342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoR_9NO5rbWdOArH04J6ggAAAUo"] [Tue Aug 18 12:53:24.756353 2026] [security2:error] [pid 66623:tid 66801] [client 74.7.241.147:37954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.halleyhotel.natbrweb.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoR_9NO5rbWdOArH04J6gwABLTY"] [Tue Aug 18 12:53:24.759492 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:40402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/ano.php"] [unique_id "aoR_9NO5rbWdOArH04J6hAAAATg"] [Tue Aug 18 12:53:24.760946 2026] [security2:error] [pid 66623:tid 66827] [client 4.223.164.152:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/simple.php"] [unique_id "aoR_9NO5rbWdOArH04J6hQAAAUc"] [Tue Aug 18 12:53:24.797924 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6hgAAARc"] [Tue Aug 18 12:53:24.798067 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:50835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9NO5rbWdOArH04J6hgAAARc"] [Tue Aug 18 12:53:24.806535 2026] [security2:error] [pid 67073:tid 67271] [client 52.238.210.254:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file2.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYgAAAlY"] [Tue Aug 18 12:53:24.813107 2026] [security2:error] [pid 67073:tid 67257] [client 168.62.48.100:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrYwAAAkg"] [Tue Aug 18 12:53:24.815944 2026] [security2:error] [pid 66623:tid 66859] [client 20.119.58.187:14595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wso112233.php"] [unique_id "aoR_9NO5rbWdOArH04J6iAAAAWc"] [Tue Aug 18 12:53:24.824955 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.61.152:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrZAAAAkA"] [Tue Aug 18 12:53:24.835670 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.100.201:54036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoR_9NO5rbWdOArH04J6igAAARA"] [Tue Aug 18 12:53:24.838606 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/ku.php"] [unique_id "aoR_9NO5rbWdOArH04J6iwAAAYc"] [Tue Aug 18 12:53:24.854382 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.18.37:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/server.php"] [unique_id "aoR_9NO5rbWdOArH04J6jAAAAXY"] [Tue Aug 18 12:53:24.883773 2026] [security2:error] [pid 66623:tid 66792] [client 68.155.154.236:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_9NO5rbWdOArH04J6jQAAASQ"] [Tue Aug 18 12:53:24.896060 2026] [security2:error] [pid 67073:tid 67240] [client 4.223.164.152:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file15.php"] [unique_id "aoR_9Pcmepr5_nHgLbMrZwAAAjc"] [Tue Aug 18 12:53:24.956860 2026] [security2:error] [pid 66623:tid 66770] [client 74.249.206.207:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoR_9NO5rbWdOArH04J6jwAAAQ4"] [Tue Aug 18 12:53:25.003789 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.98.162:17799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMraQAAAkE"] [Tue Aug 18 12:53:25.052237 2026] [security2:error] [pid 66623:tid 66880] [client 168.62.48.100:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoR_9dO5rbWdOArH04J6kAAAAXw"] [Tue Aug 18 12:53:25.078952 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/simple.php"] [unique_id "aoR_9fcmepr5_nHgLbMrawAAAnU"] [Tue Aug 18 12:53:25.090162 2026] [security2:error] [pid 66623:tid 66790] [client 158.158.74.177:14214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/past1.php"] [unique_id "aoR_9dO5rbWdOArH04J6kQAAASI"] [Tue Aug 18 12:53:25.095287 2026] [security2:error] [pid 67073:tid 67254] [client 104.209.144.33:25328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/mt/byp.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbAAAAkU"] [Tue Aug 18 12:53:25.141939 2026] [security2:error] [pid 67073:tid 67285] [client 68.221.73.131:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/8pyceeo.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbQAAAmQ"] [Tue Aug 18 12:53:25.143856 2026] [security2:error] [pid 67073:tid 67225] [client 52.173.121.69:16489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR_9fcmepr5_nHgLbMrbgAAAig"] [Tue Aug 18 12:53:25.166705 2026] [security2:error] [pid 66623:tid 66826] [client 104.209.144.33:31280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/rezor.php"] [unique_id "aoR_9dO5rbWdOArH04J6kgAAAUY"] [Tue Aug 18 12:53:25.170528 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/fw.php"] [unique_id "aoR_9dO5rbWdOArH04J6kwAAAWQ"] [Tue Aug 18 12:53:25.181906 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6lAAAAX4"] [Tue Aug 18 12:53:25.181988 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:42757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6lAAAAX4"] [Tue Aug 18 12:53:25.242776 2026] [security2:error] [pid 67073:tid 67268] [client 86.120.159.145:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcQAAAlM"] [Tue Aug 18 12:53:25.242930 2026] [security2:error] [pid 67073:tid 67268] [client 86.120.159.145:61679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcQAAAlM"] [Tue Aug 18 12:53:25.278386 2026] [security2:error] [pid 66623:tid 66834] [client 20.42.19.40:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/themes.php"] [unique_id "aoR_9dO5rbWdOArH04J6lgAAAU4"] [Tue Aug 18 12:53:25.285685 2026] [security2:error] [pid 67073:tid 67215] [client 213.35.127.232:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcgAAAh4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:25.286953 2026] [security2:error] [pid 66623:tid 66808] [client 168.62.48.100:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoR_9dO5rbWdOArH04J6lwAAATQ"] [Tue Aug 18 12:53:25.357171 2026] [security2:error] [pid 66623:tid 66706] [remote 103.56.163.133:44822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoR_9dO5rbWdOArH04J6mAABVEU"] [Tue Aug 18 12:53:25.409407 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ah.php"] [unique_id "aoR_9dO5rbWdOArH04J6mQAAAVM"] [Tue Aug 18 12:53:25.417585 2026] [security2:error] [pid 66623:tid 66816] [client 20.171.51.14:36441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vp.php"] [unique_id "aoR_9dO5rbWdOArH04J6mgAAATw"] [Tue Aug 18 12:53:25.423915 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/f35.php"] [unique_id "aoR_9dO5rbWdOArH04J6mwAAAW8"] [Tue Aug 18 12:53:25.430571 2026] [security2:error] [pid 66623:tid 66785] [client 20.48.236.86:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/coffee.php"] [unique_id "aoR_9dO5rbWdOArH04J6nQAAAR0"] [Tue Aug 18 12:53:25.440190 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:65142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/nwflm.php"] [unique_id "aoR_9dO5rbWdOArH04J6ngAAAV0"] [Tue Aug 18 12:53:25.440860 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoR_9fcmepr5_nHgLbMrcwAAAoQ"] [Tue Aug 18 12:53:25.444939 2026] [security2:error] [pid 66623:tid 66768] [client 5.31.227.224:29912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6nwAAAQw"] [Tue Aug 18 12:53:25.445024 2026] [security2:error] [pid 66623:tid 66768] [client 5.31.227.224:29912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9dO5rbWdOArH04J6nwAAAQw"] [Tue Aug 18 12:53:25.477190 2026] [security2:error] [pid 66623:tid 66824] [client 52.238.210.254:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/av.php"] [unique_id "aoR_9dO5rbWdOArH04J6oAAAAUQ"] [Tue Aug 18 12:53:25.482255 2026] [autoindex:error] [pid 66623:tid 66854] [client 4.223.164.152:64654] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:25.502385 2026] [security2:error] [pid 66623:tid 66797] [client 40.85.222.29:45706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_9dO5rbWdOArH04J6oQAAASk"] [Tue Aug 18 12:53:25.503445 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdQAAAlc"] [Tue Aug 18 12:53:25.516611 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:21154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ho.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdgAAAhs"] [Tue Aug 18 12:53:25.527054 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp.php"] [unique_id "aoR_9fcmepr5_nHgLbMrdwAAAhU"] [Tue Aug 18 12:53:25.528167 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "aoR_9dO5rbWdOArH04J6ogAAAYM"] [Tue Aug 18 12:53:25.532411 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/zxz.php"] [unique_id "aoR_9dO5rbWdOArH04J6owAAATU"] [Tue Aug 18 12:53:25.546440 2026] [security2:error] [pid 67073:tid 67218] [client 20.104.100.201:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/gecko-new.php"] [unique_id "aoR_9fcmepr5_nHgLbMreAAAAiE"] [Tue Aug 18 12:53:25.553081 2026] [security2:error] [pid 66623:tid 66851] [client 168.62.48.100:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/rezor.php"] [unique_id "aoR_9dO5rbWdOArH04J6pQAAAV8"] [Tue Aug 18 12:53:25.556337 2026] [security2:error] [pid 67073:tid 67294] [client 52.139.47.57:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoR_9fcmepr5_nHgLbMreQAAAm0"] [Tue Aug 18 12:53:25.559195 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.18.37:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoR_9dO5rbWdOArH04J6pgAAAVg"] [Tue Aug 18 12:53:25.601272 2026] [autoindex:error] [pid 66623:tid 66793] [client 20.91.215.254:23721] AH01276: Cannot serve directory /home2/reservamatadapra/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:25.621669 2026] [security2:error] [pid 67073:tid 67210] [client 68.221.73.131:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/.admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMregAAAhk"] [Tue Aug 18 12:53:25.696652 2026] [security2:error] [pid 67073:tid 67313] [client 52.238.210.254:10153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/images/class-config.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfAAAAoA"] [Tue Aug 18 12:53:25.722995 2026] [security2:error] [pid 67073:tid 67289] [client 158.158.74.177:13707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/file61.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfQAAAmg"] [Tue Aug 18 12:53:25.731906 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.136.165:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/loxi-o.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfgAAAnk"] [Tue Aug 18 12:53:25.746411 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/admin.php"] [unique_id "aoR_9fcmepr5_nHgLbMrfwAAAo4"] [Tue Aug 18 12:53:25.792430 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/uploads/bypass.php"] [unique_id "aoR_9dO5rbWdOArH04J6rwAAARc"] [Tue Aug 18 12:53:25.811381 2026] [security2:error] [pid 66623:tid 66781] [client 20.91.215.254:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/chosen.php"] [unique_id "aoR_9dO5rbWdOArH04J6sAAAARk"] [Tue Aug 18 12:53:25.848586 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vw.php"] [unique_id "aoR_9dO5rbWdOArH04J6sQAAAX0"] [Tue Aug 18 12:53:25.869674 2026] [security2:error] [pid 66623:tid 66891] [client 104.209.144.33:25282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoR_9dO5rbWdOArH04J6sgAAAYc"] [Tue Aug 18 12:53:25.894806 2026] [security2:error] [pid 67073:tid 67330] [client 20.119.58.187:14609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/classsmtps.php"] [unique_id "aoR_9fcmepr5_nHgLbMrgQAAApE"] [Tue Aug 18 12:53:25.896873 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/chosen.php"] [unique_id "aoR_9dO5rbWdOArH04J6swAAAXY"] [Tue Aug 18 12:53:25.909062 2026] [security2:error] [pid 66623:tid 66792] [client 4.223.164.152:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-load.php"] [unique_id "aoR_9dO5rbWdOArH04J6tAAAASQ"] [Tue Aug 18 12:53:25.957451 2026] [security2:error] [pid 66623:tid 66847] [client 132.196.61.152:56084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_9dO5rbWdOArH04J6uAAAAVs"] [Tue Aug 18 12:53:25.965634 2026] [security2:error] [pid 67073:tid 67252] [client 20.104.100.201:53867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/df.php"] [unique_id "aoR_9fcmepr5_nHgLbMrggAAAkM"] [Tue Aug 18 12:53:25.979965 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_9fcmepr5_nHgLbMrgwAAAnc"] [Tue Aug 18 12:53:25.989564 2026] [security2:error] [pid 67073:tid 67223] [client 52.173.121.69:25000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/security.php"] [unique_id "aoR_9fcmepr5_nHgLbMrhQAAAiY"] [Tue Aug 18 12:53:26.027893 2026] [security2:error] [pid 66623:tid 66805] [client 168.62.48.100:14756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_9tO5rbWdOArH04J6uwAAATE"] [Tue Aug 18 12:53:26.033567 2026] [security2:error] [pid 66623:tid 66780] [client 68.221.73.131:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/wsomini.php"] [unique_id "aoR_9tO5rbWdOArH04J6vAAAARg"] [Tue Aug 18 12:53:26.057611 2026] [autoindex:error] [pid 66623:tid 66880] [client 169.58.72.249:50192] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:26.144070 2026] [security2:error] [pid 66623:tid 66811] [client 104.209.144.33:32650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR_9tO5rbWdOArH04J6xwAAATc"] [Tue Aug 18 12:53:26.171667 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.56.190:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/97.php"] [unique_id "aoR_9vcmepr5_nHgLbMrhwAAAh8"] [Tue Aug 18 12:53:26.174024 2026] [security2:error] [pid 67073:tid 67319] [client 20.104.100.201:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-load.php"] [unique_id "aoR_9vcmepr5_nHgLbMriAAAAoY"] [Tue Aug 18 12:53:26.178535 2026] [security2:error] [pid 66623:tid 66803] [client 74.249.206.207:63338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/sf.php"] [unique_id "aoR_9tO5rbWdOArH04J6yAAAAS8"] [Tue Aug 18 12:53:26.192835 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/shell.php"] [unique_id "aoR_9tO5rbWdOArH04J6yQAAAUA"] [Tue Aug 18 12:53:26.224110 2026] [security2:error] [pid 66623:tid 66863] [client 20.42.19.40:2215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/buy.php"] [unique_id "aoR_9tO5rbWdOArH04J6ygAAAWs"] [Tue Aug 18 12:53:26.262259 2026] [security2:error] [pid 66623:tid 66839] [client 168.62.48.100:14797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/index/function.php"] [unique_id "aoR_9tO5rbWdOArH04J6ywAAAVM"] [Tue Aug 18 12:53:26.262640 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.18.37:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/222.php"] [unique_id "aoR_9tO5rbWdOArH04J6zAAAASA"] [Tue Aug 18 12:53:26.264317 2026] [security2:error] [pid 66623:tid 66885] [client 20.119.58.187:15328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-blog-header.php"] [unique_id "aoR_9tO5rbWdOArH04J6zQAAAYE"] [Tue Aug 18 12:53:26.265585 2026] [security2:error] [pid 67073:tid 67213] [client 104.209.144.33:31271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoR_9vcmepr5_nHgLbMrigAAAhw"] [Tue Aug 18 12:53:26.299424 2026] [security2:error] [pid 67073:tid 67248] [client 213.35.127.232:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_9vcmepr5_nHgLbMriwAAAj8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:26.302950 2026] [security2:error] [pid 67073:tid 67256] [client 68.155.154.236:64569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjAAAAkc"] [Tue Aug 18 12:53:26.368572 2026] [autoindex:error] [pid 66623:tid 66866] [client 4.223.164.152:64644] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:26.397814 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:53835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjQAAAiw"] [Tue Aug 18 12:53:26.412554 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.30:63744] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:26.412813 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.30:63744] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:26.451138 2026] [security2:error] [pid 67073:tid 67297] [client 103.184.169.37:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjgAAAnA"] [Tue Aug 18 12:53:26.451268 2026] [security2:error] [pid 67073:tid 67297] [client 103.184.169.37:41051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjgAAAnA"] [Tue Aug 18 12:53:26.453998 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.61.152:55313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/img.php"] [unique_id "aoR_9vcmepr5_nHgLbMrjwAAAj0"] [Tue Aug 18 12:53:26.482508 2026] [security2:error] [pid 67073:tid 67231] [client 104.209.144.33:24890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/index/function.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkAAAAi4"] [Tue Aug 18 12:53:26.497642 2026] [security2:error] [pid 67073:tid 67328] [client 168.62.48.100:14804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkgAAAo8"] [Tue Aug 18 12:53:26.509534 2026] [security2:error] [pid 67073:tid 67267] [client 68.221.73.131:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.rotta101.com.br"] [uri "/vr.php"] [unique_id "aoR_9vcmepr5_nHgLbMrkwAAAlI"] [Tue Aug 18 12:53:26.550842 2026] [security2:error] [pid 66623:tid 66793] [client 158.158.74.177:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anmultimarcas.com.br"] [uri "/license.php"] [unique_id "aoR_9tO5rbWdOArH04J60gAAASU"] [Tue Aug 18 12:53:26.561329 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_9vcmepr5_nHgLbMrlAAAAjQ"] [Tue Aug 18 12:53:26.564776 2026] [security2:error] [pid 66623:tid 66838] [client 114.119.132.227:42607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rkazuoveiculos.com.br"] [uri "/veiculo/162200/zafira-eleg-2-0-mpfi-flexpower-8v-5p-aut"] [unique_id "aoR_9tO5rbWdOArH04J60wAAAVI"], referer: https://rkazuoveiculos.com.br/veiculo/162200/zafira-eleg-2-0-mpfi-flexpower-8v-5p-aut [Tue Aug 18 12:53:26.596320 2026] [security2:error] [pid 67073:tid 67240] [client 104.209.144.33:25284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoR_9vcmepr5_nHgLbMrlQAAAjc"] [Tue Aug 18 12:53:26.597515 2026] [security2:error] [pid 66623:tid 66822] [client 20.91.215.254:20278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/asd.php"] [unique_id "aoR_9tO5rbWdOArH04J61AAAAUI"] [Tue Aug 18 12:53:26.619556 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.98.162:32352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/biufile.php"] [unique_id "aoR_9vcmepr5_nHgLbMrmAAAAk8"] [Tue Aug 18 12:53:26.624942 2026] [security2:error] [pid 66623:tid 66745] [remote 84.205.178.135:26133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoR_9tO5rbWdOArH04J61QABEGw"] [Tue Aug 18 12:53:26.626230 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lj.php"] [unique_id "aoR_9vcmepr5_nHgLbMrmgAAAkI"] [Tue Aug 18 12:53:26.688917 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:15343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-comments-post.php"] [unique_id "aoR_9vcmepr5_nHgLbMrnwAAAjU"] [Tue Aug 18 12:53:26.737290 2026] [security2:error] [pid 66623:tid 66773] [client 168.62.48.100:14844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/Cachex.php"] [unique_id "aoR_9tO5rbWdOArH04J61wAAARE"] [Tue Aug 18 12:53:26.740938 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.100.201:53834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/usr.php"] [unique_id "aoR_9tO5rbWdOArH04J62AAAAXA"] [Tue Aug 18 12:53:26.742363 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.136.165:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sdsa.php"] [unique_id "aoR_9tO5rbWdOArH04J62QAAASE"] [Tue Aug 18 12:53:26.793557 2026] [security2:error] [pid 66623:tid 66817] [client 4.223.164.152:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/als.php"] [unique_id "aoR_9tO5rbWdOArH04J62gAAAT0"] [Tue Aug 18 12:53:26.803734 2026] [security2:error] [pid 67073:tid 67215] [client 74.249.206.207:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/k.php"] [unique_id "aoR_9vcmepr5_nHgLbMrowAAAh4"] [Tue Aug 18 12:53:26.826878 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:10701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/classwithtostring.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpAAAAng"] [Tue Aug 18 12:53:26.836210 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ph.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpgAAAms"] [Tue Aug 18 12:53:26.837660 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.18.37:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/sim.php"] [unique_id "aoR_9vcmepr5_nHgLbMrpwAAAkE"] [Tue Aug 18 12:53:26.842231 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/jj.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqAAAAoQ"] [Tue Aug 18 12:53:26.857462 2026] [security2:error] [pid 67073:tid 67221] [client 104.209.144.33:32702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqgAAAiQ"] [Tue Aug 18 12:53:26.859864 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:10147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/alfa.php"] [unique_id "aoR_9vcmepr5_nHgLbMrqwAAAlc"] [Tue Aug 18 12:53:26.928735 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:39403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR_9vcmepr5_nHgLbMrrQAAAhs"] [Tue Aug 18 12:53:26.942915 2026] [security2:error] [pid 66623:tid 66825] [client 104.209.144.33:32664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoR_9tO5rbWdOArH04J62wAAAUU"] [Tue Aug 18 12:53:26.974556 2026] [security2:error] [pid 67073:tid 67316] [client 168.62.48.100:14727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_9vcmepr5_nHgLbMrsAAAAoM"] [Tue Aug 18 12:53:27.020946 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kh.php"] [unique_id "aoR_99O5rbWdOArH04J63AAAAX0"] [Tue Aug 18 12:53:27.049607 2026] [security2:error] [pid 66623:tid 66804] [client 20.119.58.187:15325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-cron.php"] [unique_id "aoR_99O5rbWdOArH04J63QAAATA"] [Tue Aug 18 12:53:27.052040 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoR_9_cmepr5_nHgLbMrswAAAko"] [Tue Aug 18 12:53:27.128634 2026] [security2:error] [pid 67073:tid 67230] [client 20.104.100.201:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoR_9_cmepr5_nHgLbMrtgAAAi0"] [Tue Aug 18 12:53:27.131194 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:12655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMruAAAAmo"] [Tue Aug 18 12:53:27.210635 2026] [security2:error] [pid 67073:tid 67243] [client 168.62.48.100:14766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-2019.php"] [unique_id "aoR_9_cmepr5_nHgLbMruQAAAjo"] [Tue Aug 18 12:53:27.241633 2026] [security2:error] [pid 66623:tid 66888] [client 4.223.164.152:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/nox.php"] [unique_id "aoR_99O5rbWdOArH04J64AAAAYQ"] [Tue Aug 18 12:53:27.281915 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:36435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/s.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvAAAAns"] [Tue Aug 18 12:53:27.290286 2026] [security2:error] [pid 67073:tid 67284] [client 132.196.61.152:27276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/aa.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvQAAAmM"] [Tue Aug 18 12:53:27.292054 2026] [security2:error] [pid 67073:tid 67205] [client 172.202.39.151:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/www.php"] [unique_id "aoR_9_cmepr5_nHgLbMrvgAAAhQ"] [Tue Aug 18 12:53:27.315279 2026] [security2:error] [pid 67073:tid 67286] [client 213.35.127.232:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwAAAAmU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:27.319940 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwQAAAhc"] [Tue Aug 18 12:53:27.320076 2026] [security2:error] [pid 67073:tid 67208] [client 157.20.138.62:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_9_cmepr5_nHgLbMrwQAAAhc"] [Tue Aug 18 12:53:27.409744 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:15332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-load.php"] [unique_id "aoR_99O5rbWdOArH04J64QAAAQ0"] [Tue Aug 18 12:53:27.445640 2026] [security2:error] [pid 67073:tid 67323] [client 168.62.48.100:14740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMrxgAAAoo"] [Tue Aug 18 12:53:27.448678 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jb.php"] [unique_id "aoR_99O5rbWdOArH04J64gAAAWA"] [Tue Aug 18 12:53:27.470301 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.18.37:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/simple.php"] [unique_id "aoR_9_cmepr5_nHgLbMrxwAAAnc"] [Tue Aug 18 12:53:27.483934 2026] [security2:error] [pid 67073:tid 67252] [client 20.91.215.254:20267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/akc.php"] [unique_id "aoR_9_cmepr5_nHgLbMryAAAAkM"] [Tue Aug 18 12:53:27.518482 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.100.201:17360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/css/database.php"] [unique_id "aoR_99O5rbWdOArH04J65AAAATE"] [Tue Aug 18 12:53:27.518492 2026] [security2:error] [pid 66623:tid 66842] [client 104.209.144.33:24851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/Cachex.php"] [unique_id "aoR_99O5rbWdOArH04J64wAAAVY"] [Tue Aug 18 12:53:27.525876 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR_99O5rbWdOArH04J65QAAARg"] [Tue Aug 18 12:53:27.551022 2026] [security2:error] [pid 66623:tid 66873] [client 74.248.18.37:25929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoR_99O5rbWdOArH04J65gAAAXU"] [Tue Aug 18 12:53:27.551888 2026] [security2:error] [pid 66623:tid 66778] [client 52.238.210.254:10130] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.savvy.ind.br"] [uri "/1.php"] [unique_id "aoR_99O5rbWdOArH04J65wAAARY"] [Tue Aug 18 12:53:27.552035 2026] [security2:error] [pid 66623:tid 66778] [client 52.238.210.254:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/1.php"] [unique_id "aoR_99O5rbWdOArH04J65wAAARY"] [Tue Aug 18 12:53:27.566064 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.100.201:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/img.php"] [unique_id "aoR_99O5rbWdOArH04J66AAAASI"] [Tue Aug 18 12:53:27.629453 2026] [security2:error] [pid 67073:tid 67262] [client 4.232.151.198:46528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/155.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzAAAAk0"] [Tue Aug 18 12:53:27.642503 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_99O5rbWdOArH04J66wAAAWQ"] [Tue Aug 18 12:53:27.657889 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.169.31:15092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/w1.php"] [unique_id "aoR_99O5rbWdOArH04J67AAAASY"] [Tue Aug 18 12:53:27.672808 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.56.190:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rh.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzQAAAkc"] [Tue Aug 18 12:53:27.694436 2026] [security2:error] [pid 66623:tid 66837] [client 74.249.206.207:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/82.php"] [unique_id "aoR_99O5rbWdOArH04J67QAAAVE"] [Tue Aug 18 12:53:27.696705 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/aaa.php"] [unique_id "aoR_9_cmepr5_nHgLbMrzwAAAl8"] [Tue Aug 18 12:53:27.700221 2026] [security2:error] [pid 67073:tid 67239] [client 168.62.48.100:14824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/.cache/x.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0AAAAjY"] [Tue Aug 18 12:53:27.714318 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.61.152:56087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/av.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0QAAAik"] [Tue Aug 18 12:53:27.770637 2026] [security2:error] [pid 67073:tid 67222] [client 135.225.75.187:9434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0gAAAiU"] [Tue Aug 18 12:53:27.771896 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-activate.php"] [unique_id "aoR_9_cmepr5_nHgLbMr0wAAAhw"] [Tue Aug 18 12:53:27.787007 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.136.165:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr1AAAAnA"] [Tue Aug 18 12:53:27.807102 2026] [security2:error] [pid 67073:tid 67246] [client 4.223.164.152:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file59.php"] [unique_id "aoR_9_cmepr5_nHgLbMr1QAAAj0"] [Tue Aug 18 12:53:27.889428 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/u.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2AAAAlo"] [Tue Aug 18 12:53:27.919401 2026] [security2:error] [pid 66623:tid 66783] [client 52.238.210.254:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/222.php"] [unique_id "aoR_99O5rbWdOArH04J68AAAARs"] [Tue Aug 18 12:53:27.933601 2026] [security2:error] [pid 67073:tid 67318] [client 168.62.48.100:16307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2gAAAoU"] [Tue Aug 18 12:53:27.970404 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_9_cmepr5_nHgLbMr2wAAAkU"] [Tue Aug 18 12:53:28.005904 2026] [security2:error] [pid 67073:tid 67269] [client 104.209.144.33:15686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4QAAAlQ"] [Tue Aug 18 12:53:28.006081 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4gAAAn8"] [Tue Aug 18 12:53:28.013113 2026] [security2:error] [pid 67073:tid 67225] [client 20.151.109.219:58342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/main.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr4wAAAig"] [Tue Aug 18 12:53:28.017922 2026] [security2:error] [pid 67073:tid 67278] [client 20.171.51.14:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uo.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr5AAAAl0"] [Tue Aug 18 12:53:28.086135 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/privdayz.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6AAAAmw"] [Tue Aug 18 12:53:28.117181 2026] [security2:error] [pid 67073:tid 67326] [client 74.248.18.37:13205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/st.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6gAAAo0"] [Tue Aug 18 12:53:28.117582 2026] [security2:error] [pid 67073:tid 67272] [client 20.171.51.14:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/do.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr6wAAAlc"] [Tue Aug 18 12:53:28.124765 2026] [security2:error] [pid 67073:tid 67302] [client 20.119.58.187:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/berlin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7AAAAnU"] [Tue Aug 18 12:53:28.155117 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:61839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7QAAAhs"] [Tue Aug 18 12:53:28.166046 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/we.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7gAAAmk"] [Tue Aug 18 12:53:28.171122 2026] [security2:error] [pid 67073:tid 67207] [client 168.62.48.100:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr7wAAAhY"] [Tue Aug 18 12:53:28.187935 2026] [security2:error] [pid 66623:tid 66677] [remote 47.128.31.19:15618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoR_-NO5rbWdOArH04J69QABNyg"] [Tue Aug 18 12:53:28.189380 2026] [security2:error] [pid 67073:tid 67261] [client 4.223.164.152:6858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/gecko.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr8QAAAkw"] [Tue Aug 18 12:53:28.204657 2026] [security2:error] [pid 66623:tid 66885] [client 52.139.47.57:29399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoR_-NO5rbWdOArH04J69gAAAYE"] [Tue Aug 18 12:53:28.207923 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.136.165:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr9AAAAoA"] [Tue Aug 18 12:53:28.270176 2026] [security2:error] [pid 67073:tid 67306] [client 52.238.210.254:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/asasx.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-AAAAnk"] [Tue Aug 18 12:53:28.290050 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:64682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/admin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-QAAAko"] [Tue Aug 18 12:53:28.293524 2026] [security2:error] [pid 67073:tid 67232] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr-gAAAi8"] [Tue Aug 18 12:53:28.330296 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR_-Pcmepr5_nHgLbMr_gAAAjU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:28.374156 2026] [security2:error] [pid 67073:tid 67243] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsAgAAAjo"] [Tue Aug 18 12:53:28.380366 2026] [security2:error] [pid 66623:tid 66768] [client 132.196.61.152:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/media.php"] [unique_id "aoR_-NO5rbWdOArH04J6-AAAAQw"] [Tue Aug 18 12:53:28.395019 2026] [security2:error] [pid 67073:tid 67244] [client 104.209.144.33:31251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsAwAAAjs"] [Tue Aug 18 12:53:28.407852 2026] [security2:error] [pid 67073:tid 67223] [client 168.62.48.100:14841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBAAAAiY"] [Tue Aug 18 12:53:28.414453 2026] [security2:error] [pid 67073:tid 67250] [client 20.91.215.254:23738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/maintenance.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBQAAAkE"] [Tue Aug 18 12:53:28.415072 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.136.165:20315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-freya.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBgAAAns"] [Tue Aug 18 12:53:28.445400 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.100.201:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wg459o.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsBwAAAhc"] [Tue Aug 18 12:53:28.464491 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:25325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-2019.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsCQAAAnQ"] [Tue Aug 18 12:53:28.479778 2026] [security2:error] [pid 67073:tid 67324] [client 20.119.58.187:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/not/includes/php8.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsCgAAAos"] [Tue Aug 18 12:53:28.570609 2026] [security2:error] [pid 67073:tid 67252] [client 52.238.210.254:10136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/filemanager.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDAAAAkM"] [Tue Aug 18 12:53:28.592181 2026] [security2:error] [pid 67073:tid 67216] [client 74.249.206.207:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/dex.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDQAAAh8"] [Tue Aug 18 12:53:28.602230 2026] [security2:error] [pid 66623:tid 66866] [client 20.48.236.86:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/wp-ws68.php"] [unique_id "aoR_-NO5rbWdOArH04J6-QAAAW4"] [Tue Aug 18 12:53:28.626220 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws61.php"] [unique_id "aoR_-NO5rbWdOArH04J6-gAAAWI"] [Tue Aug 18 12:53:28.641502 2026] [security2:error] [pid 66623:tid 66797] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/h.php"] [unique_id "aoR_-NO5rbWdOArH04J6-wAAASk"] [Tue Aug 18 12:53:28.645477 2026] [security2:error] [pid 67073:tid 67209] [client 168.62.48.100:14743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsDgAAAhg"] [Tue Aug 18 12:53:28.688201 2026] [security2:error] [pid 66623:tid 66867] [client 149.34.210.141:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-NO5rbWdOArH04J6_AAAAW8"] [Tue Aug 18 12:53:28.694830 2026] [security2:error] [pid 67073:tid 67298] [client 114.119.128.132:55759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.medraeng.com"] [uri "/robots.txt"] [unique_id "aoR_-Pcmepr5_nHgLbMsEAAAAnE"], referer: https://www.medraeng.com/robots.txt [Tue Aug 18 12:53:28.700840 2026] [security2:error] [pid 67073:tid 67224] [client 4.223.164.152:6633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/xiugai.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsEQAAAic"] [Tue Aug 18 12:53:28.708708 2026] [security2:error] [pid 67073:tid 67322] [client 5.253.205.188:48154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/file.bak"] [unique_id "aoR_-Pcmepr5_nHgLbMsEwAAAok"], referer: https://medihub.com.br/file.bak [Tue Aug 18 12:53:28.708847 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/weozh.php"] [unique_id "aoR_-NO5rbWdOArH04J6_QAAAYM"] [Tue Aug 18 12:53:28.708911 2026] [security2:error] [pid 67073:tid 67205] [client 109.122.18.177:52915] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "edgeresidences.com.br"] [uri "/.env"] [unique_id "aoR_-Pcmepr5_nHgLbMsEgAAAhQ"] [Tue Aug 18 12:53:28.716276 2026] [security2:error] [pid 67073:tid 67235] [client 4.223.164.152:37293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/aa2.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsFAAAAjI"] [Tue Aug 18 12:53:28.751857 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsFwAAAoo"] [Tue Aug 18 12:53:28.766303 2026] [security2:error] [pid 67073:tid 67226] [client 68.155.154.236:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsGAAAAik"] [Tue Aug 18 12:53:28.767442 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yw.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsGQAAAiU"] [Tue Aug 18 12:53:28.819824 2026] [authz_core:error] [pid 67073:tid 67236] [client 192.178.4.133:61705] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:28.820258 2026] [authz_core:error] [pid 67073:tid 67236] [client 192.178.4.133:61705] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:28.839417 2026] [security2:error] [pid 67073:tid 67274] [client 20.119.58.187:14649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/wp-theme-editor/php8.php/wp-content/themes/aahana/json.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHAAAAlk"] [Tue Aug 18 12:53:28.883653 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.61.152:56110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/images.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHQAAAnI"] [Tue Aug 18 12:53:28.889985 2026] [security2:error] [pid 67073:tid 67328] [client 168.62.48.100:14809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHgAAAo8"] [Tue Aug 18 12:53:28.890299 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.100.201:53854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/mifta.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsHwAAAlI"] [Tue Aug 18 12:53:28.946082 2026] [security2:error] [pid 66623:tid 66867] [client 149.34.210.141:57638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-NO5rbWdOArH04J6_AAAAW8"] [Tue Aug 18 12:53:28.948614 2026] [security2:error] [pid 67073:tid 67270] [client 20.42.19.40:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/dropdown.php"] [unique_id "aoR_-Pcmepr5_nHgLbMsIgAAAlU"] [Tue Aug 18 12:53:29.011490 2026] [security2:error] [pid 67073:tid 67300] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/rymmm.php"] [unique_id "aoR_-fcmepr5_nHgLbMsJgAAAnM"] [Tue Aug 18 12:53:29.044660 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.136.165:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rum.php"] [unique_id "aoR_-fcmepr5_nHgLbMsKAAAAn0"] [Tue Aug 18 12:53:29.048492 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.98.162:16620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/coffexium.php"] [unique_id "aoR_-fcmepr5_nHgLbMsKQAAAng"] [Tue Aug 18 12:53:29.067402 2026] [security2:error] [pid 67073:tid 67253] [client 52.238.210.254:10201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/themes.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLAAAAkQ"] [Tue Aug 18 12:53:29.076870 2026] [security2:error] [pid 67073:tid 67317] [client 104.209.144.33:32649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/first.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLQAAAoQ"] [Tue Aug 18 12:53:29.080182 2026] [security2:error] [pid 66623:tid 66819] [client 104.209.144.33:31285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoR_-dO5rbWdOArH04J7AgAAAT8"] [Tue Aug 18 12:53:29.083472 2026] [security2:error] [pid 67073:tid 67327] [client 4.232.151.198:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/96i.php"] [unique_id "aoR_-fcmepr5_nHgLbMsLgAAAo4"] [Tue Aug 18 12:53:29.140190 2026] [security2:error] [pid 66623:tid 66859] [client 168.62.48.100:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-dO5rbWdOArH04J7AwAAAWc"] [Tue Aug 18 12:53:29.162248 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:46169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/xamp.php"] [unique_id "aoR_-fcmepr5_nHgLbMsMQAAAiE"] [Tue Aug 18 12:53:29.182861 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/adminner.php"] [unique_id "aoR_-fcmepr5_nHgLbMsMgAAAoM"] [Tue Aug 18 12:53:29.194101 2026] [security2:error] [pid 66623:tid 66845] [client 20.119.58.187:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/Requests/php8.php"] [unique_id "aoR_-dO5rbWdOArH04J7BAAAAVk"] [Tue Aug 18 12:53:29.238996 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-fcmepr5_nHgLbMsNAAAAmE"] [Tue Aug 18 12:53:29.253836 2026] [security2:error] [pid 66623:tid 66804] [client 20.171.51.14:33724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/qh.php"] [unique_id "aoR_-dO5rbWdOArH04J7BQAAATA"] [Tue Aug 18 12:53:29.271859 2026] [autoindex:error] [pid 66623:tid 66893] [client 172.232.22.88:43722] AH01276: Cannot serve directory /home3/sortistecnologia/weishaupt.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:29.352750 2026] [security2:error] [pid 67073:tid 67285] [client 213.35.127.232:51965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR_-fcmepr5_nHgLbMsOAAAAmQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:29.374944 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:23722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/options-writing.php"] [unique_id "aoR_-fcmepr5_nHgLbMsOwAAAo0"] [Tue Aug 18 12:53:29.380289 2026] [security2:error] [pid 67073:tid 67217] [client 168.62.48.100:14664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPAAAAiA"] [Tue Aug 18 12:53:29.387196 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:21915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/system.php"] [unique_id "aoR_-dO5rbWdOArH04J7CAAAAX0"] [Tue Aug 18 12:53:29.465633 2026] [security2:error] [pid 67073:tid 67255] [client 20.48.236.86:10802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mgrr.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPgAAAkY"] [Tue Aug 18 12:53:29.466550 2026] [security2:error] [pid 67073:tid 67291] [client 52.139.47.57:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-mail.php"] [unique_id "aoR_-fcmepr5_nHgLbMsPwAAAmo"] [Tue Aug 18 12:53:29.466578 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ze.php"] [unique_id "aoR_-fcmepr5_nHgLbMsQAAAAjU"] [Tue Aug 18 12:53:29.469450 2026] [security2:error] [pid 67073:tid 67276] [client 52.173.121.69:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsQgAAAls"] [Tue Aug 18 12:53:29.482001 2026] [security2:error] [pid 66623:tid 66805] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/lddxs.php"] [unique_id "aoR_-dO5rbWdOArH04J7CwAAATE"] [Tue Aug 18 12:53:29.525778 2026] [security2:error] [pid 67073:tid 67284] [client 52.238.210.254:10174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/admin.php"] [unique_id "aoR_-fcmepr5_nHgLbMsRQAAAmM"] [Tue Aug 18 12:53:29.538777 2026] [autoindex:error] [pid 67073:tid 67232] [client 172.236.112.76:56750] AH01276: Cannot serve directory /home3/sortistecnologia/weishaupt.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:29.547266 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ga.php"] [unique_id "aoR_-fcmepr5_nHgLbMsRwAAAns"] [Tue Aug 18 12:53:29.592490 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/.cache/x.php"] [unique_id "aoR_-dO5rbWdOArH04J7DQAAARg"] [Tue Aug 18 12:53:29.604762 2026] [security2:error] [pid 67073:tid 67307] [client 20.119.58.187:15351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/SimplePie/php8.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSQAAAno"] [Tue Aug 18 12:53:29.607676 2026] [security2:error] [pid 67073:tid 67324] [client 4.223.164.152:37290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/bless.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSgAAAos"] [Tue Aug 18 12:53:29.614778 2026] [security2:error] [pid 67073:tid 67245] [client 168.62.48.100:14706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsSwAAAjw"] [Tue Aug 18 12:53:29.618842 2026] [security2:error] [pid 67073:tid 67263] [client 40.85.222.29:30473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTAAAAk4"] [Tue Aug 18 12:53:29.619315 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.61.152:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/admin.php"] [unique_id "aoR_-dO5rbWdOArH04J7DgAAAXw"] [Tue Aug 18 12:53:29.720029 2026] [security2:error] [pid 67073:tid 67249] [client 157.51.166.53:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTgAAAkA"] [Tue Aug 18 12:53:29.720150 2026] [security2:error] [pid 67073:tid 67249] [client 157.51.166.53:50694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTgAAAkA"] [Tue Aug 18 12:53:29.721089 2026] [security2:error] [pid 66623:tid 66856] [client 74.249.206.207:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/puc.php"] [unique_id "aoR_-dO5rbWdOArH04J7EAAAAWQ"] [Tue Aug 18 12:53:29.725640 2026] [security2:error] [pid 67073:tid 67216] [client 4.223.164.152:6641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file1221.php"] [unique_id "aoR_-fcmepr5_nHgLbMsTwAAAh8"] [Tue Aug 18 12:53:29.727932 2026] [security2:error] [pid 67073:tid 67319] [client 104.209.144.33:31258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR_-fcmepr5_nHgLbMsUAAAAoY"] [Tue Aug 18 12:53:29.761424 2026] [security2:error] [pid 67073:tid 67262] [client 20.171.51.14:45389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kx.php"] [unique_id "aoR_-fcmepr5_nHgLbMsUwAAAk0"] [Tue Aug 18 12:53:29.775227 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zjggu.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVAAAAm4"] [Tue Aug 18 12:53:29.791382 2026] [security2:error] [pid 67073:tid 67224] [client 20.171.51.14:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/r.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVQAAAic"] [Tue Aug 18 12:53:29.806083 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:53869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVgAAAjI"] [Tue Aug 18 12:53:29.830752 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVwAAAoA"] [Tue Aug 18 12:53:29.830861 2026] [security2:error] [pid 67073:tid 67313] [client 160.120.140.123:52188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-fcmepr5_nHgLbMsVwAAAoA"] [Tue Aug 18 12:53:29.838943 2026] [security2:error] [pid 67073:tid 67248] [client 20.100.169.31:15081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/fone1.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWQAAAj8"] [Tue Aug 18 12:53:29.854895 2026] [security2:error] [pid 67073:tid 67297] [client 20.51.153.15:13318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWgAAAnA"] [Tue Aug 18 12:53:29.888148 2026] [security2:error] [pid 66623:tid 66799] [client 168.62.48.100:14721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR_-dO5rbWdOArH04J7EwAAASs"] [Tue Aug 18 12:53:29.894367 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.136.165:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gjm.php"] [unique_id "aoR_-fcmepr5_nHgLbMsWwAAAnI"] [Tue Aug 18 12:53:29.918408 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:28986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-dO5rbWdOArH04J7FAAAASM"] [Tue Aug 18 12:53:29.918494 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:28986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR_-dO5rbWdOArH04J7FAAAASM"] [Tue Aug 18 12:53:29.972595 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/banners/php8.php"] [unique_id "aoR_-fcmepr5_nHgLbMsYAAAAhw"] [Tue Aug 18 12:53:29.993035 2026] [autoindex:error] [pid 66623:tid 66794] [client 20.250.13.23:12040] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:30.031399 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/system_log.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZQAAAoo"] [Tue Aug 18 12:53:30.046562 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.18.37:14583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/info.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZgAAAmU"] [Tue Aug 18 12:53:30.067222 2026] [security2:error] [pid 67073:tid 67233] [client 20.91.215.254:20282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoR_-vcmepr5_nHgLbMsZwAAAjA"] [Tue Aug 18 12:53:30.090542 2026] [security2:error] [pid 66623:tid 66788] [client 4.223.164.152:64674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file25.php"] [unique_id "aoR_-tO5rbWdOArH04J7GAAAASA"] [Tue Aug 18 12:53:30.090954 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/dlvqo.php"] [unique_id "aoR_-vcmepr5_nHgLbMsaAAAAlQ"] [Tue Aug 18 12:53:30.139024 2026] [security2:error] [pid 67073:tid 67215] [client 168.62.48.100:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/update/wpupex.php"] [unique_id "aoR_-vcmepr5_nHgLbMsawAAAh4"] [Tue Aug 18 12:53:30.148198 2026] [security2:error] [pid 67073:tid 67305] [client 104.209.144.33:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbAAAAng"] [Tue Aug 18 12:53:30.150605 2026] [security2:error] [pid 67073:tid 67292] [client 172.202.39.151:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbQAAAms"] [Tue Aug 18 12:53:30.151370 2026] [security2:error] [pid 66623:tid 66840] [client 52.238.210.254:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/buy.php"] [unique_id "aoR_-tO5rbWdOArH04J7GQAAAVQ"] [Tue Aug 18 12:53:30.204906 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.136.165:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fleen.php"] [unique_id "aoR_-vcmepr5_nHgLbMsbgAAAiQ"] [Tue Aug 18 12:53:30.208727 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:6722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/inx.php"] [unique_id "aoR_-vcmepr5_nHgLbMscAAAAoQ"] [Tue Aug 18 12:53:30.264635 2026] [security2:error] [pid 66623:tid 66885] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoR_-tO5rbWdOArH04J7GgAAAYE"] [Tue Aug 18 12:53:30.272971 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.169.31:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoR_-tO5rbWdOArH04J7GwAAAVA"] [Tue Aug 18 12:53:30.311454 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.136.165:46511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/new4.php"] [unique_id "aoR_-tO5rbWdOArH04J7HAAAAW4"] [Tue Aug 18 12:53:30.321527 2026] [security2:error] [pid 66623:tid 66854] [client 20.171.51.14:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/17.php"] [unique_id "aoR_-tO5rbWdOArH04J7HQAAAWI"] [Tue Aug 18 12:53:30.368684 2026] [security2:error] [pid 67073:tid 67280] [client 213.35.127.232:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdQAAAl8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:30.378942 2026] [security2:error] [pid 67073:tid 67218] [client 20.119.58.187:15132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/php8.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdgAAAiE"] [Tue Aug 18 12:53:30.379237 2026] [security2:error] [pid 67073:tid 67315] [client 168.62.48.100:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/install.php"] [unique_id "aoR_-vcmepr5_nHgLbMsdwAAAoI"] [Tue Aug 18 12:53:30.380835 2026] [security2:error] [pid 66623:tid 66797] [client 74.249.206.207:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/inso.php"] [unique_id "aoR_-tO5rbWdOArH04J7HgAAASk"] [Tue Aug 18 12:53:30.394551 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/va.php"] [unique_id "aoR_-vcmepr5_nHgLbMseAAAAjg"] [Tue Aug 18 12:53:30.419860 2026] [security2:error] [pid 67073:tid 67228] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/pkmoj.php"] [unique_id "aoR_-vcmepr5_nHgLbMsegAAAis"] [Tue Aug 18 12:53:30.428597 2026] [security2:error] [pid 67073:tid 67265] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR_-vcmepr5_nHgLbMsewAAAlA"] [Tue Aug 18 12:53:30.442055 2026] [security2:error] [pid 67073:tid 67285] [client 20.51.153.15:13427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-vcmepr5_nHgLbMsfAAAAmQ"] [Tue Aug 18 12:53:30.491555 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:10141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/dropdown.php"] [unique_id "aoR_-vcmepr5_nHgLbMsfgAAAiA"] [Tue Aug 18 12:53:30.517096 2026] [security2:error] [pid 66623:tid 66876] [client 20.104.100.201:17384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/index2.php"] [unique_id "aoR_-tO5rbWdOArH04J7IAAAAXg"] [Tue Aug 18 12:53:30.524061 2026] [security2:error] [pid 66623:tid 66853] [client 4.223.164.152:37261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file15.php"] [unique_id "aoR_-tO5rbWdOArH04J7IgAAAWE"] [Tue Aug 18 12:53:30.605795 2026] [autoindex:error] [pid 66623:tid 66793] [client 172.202.39.151:44358] AH01276: Cannot serve directory /home4/lecarveiculos/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:30.614039 2026] [security2:error] [pid 67073:tid 67284] [client 168.62.48.100:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsggAAAmM"] [Tue Aug 18 12:53:30.622047 2026] [security2:error] [pid 66623:tid 66772] [client 172.202.39.151:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wicked.php"] [unique_id "aoR_-tO5rbWdOArH04J7KgAAARA"] [Tue Aug 18 12:53:30.634069 2026] [security2:error] [pid 67073:tid 67250] [client 132.196.61.152:56077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/222.php"] [unique_id "aoR_-vcmepr5_nHgLbMsgwAAAkE"] [Tue Aug 18 12:53:30.687053 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-tO5rbWdOArH04J7LQAAAVw"] [Tue Aug 18 12:53:30.728381 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:10007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-act.php"] [unique_id "aoR_-vcmepr5_nHgLbMshgAAAjQ"] [Tue Aug 18 12:53:30.733636 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/kopyw.php"] [unique_id "aoR_-vcmepr5_nHgLbMshwAAAnQ"] [Tue Aug 18 12:53:30.740302 2026] [security2:error] [pid 66623:tid 66858] [client 20.119.58.187:14641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/php8.php"] [unique_id "aoR_-tO5rbWdOArH04J7LgAAAWY"] [Tue Aug 18 12:53:30.744119 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:10423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/55.php"] [unique_id "aoR_-tO5rbWdOArH04J7LwAAATY"] [Tue Aug 18 12:53:30.751374 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wso.php"] [unique_id "aoR_-vcmepr5_nHgLbMsiAAAAno"] [Tue Aug 18 12:53:30.780403 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsiwAAAjw"] [Tue Aug 18 12:53:30.792569 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:16729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ev.php"] [unique_id "aoR_-vcmepr5_nHgLbMsjAAAAkM"] [Tue Aug 18 12:53:30.808306 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.18.37:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/templates/beez3/error.php"] [unique_id "aoR_-tO5rbWdOArH04J7MAAAAVI"] [Tue Aug 18 12:53:30.815691 2026] [security2:error] [pid 66623:tid 66867] [client 20.51.153.15:13405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/dirs.php"] [unique_id "aoR_-tO5rbWdOArH04J7MQAAAW8"] [Tue Aug 18 12:53:30.829629 2026] [security2:error] [pid 66623:tid 66890] [client 135.225.75.187:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws61.php"] [unique_id "aoR_-tO5rbWdOArH04J7MgAAAYY"] [Tue Aug 18 12:53:30.851975 2026] [security2:error] [pid 67073:tid 67234] [client 168.62.48.100:14747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoR_-vcmepr5_nHgLbMsjgAAAjE"] [Tue Aug 18 12:53:30.913158 2026] [security2:error] [pid 67073:tid 67224] [client 4.223.164.152:6881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/reviall.php"] [unique_id "aoR_-vcmepr5_nHgLbMslAAAAic"] [Tue Aug 18 12:53:30.947883 2026] [security2:error] [pid 67073:tid 67313] [client 52.28.162.93:46232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/"] [unique_id "aoR_-vcmepr5_nHgLbMslQAAAoA"], referer: http://www.agrimotor.com.br/ [Tue Aug 18 12:53:30.948640 2026] [security2:error] [pid 67073:tid 67248] [client 4.223.164.152:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/f35.php"] [unique_id "aoR_-vcmepr5_nHgLbMslgAAAj8"] [Tue Aug 18 12:53:30.957912 2026] [security2:error] [pid 67073:tid 67226] [client 20.65.98.162:23913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/dex.php"] [unique_id "aoR_-vcmepr5_nHgLbMslwAAAik"] [Tue Aug 18 12:53:30.971089 2026] [security2:error] [pid 66623:tid 66775] [client 85.154.68.202:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-tO5rbWdOArH04J7MwAAARM"] [Tue Aug 18 12:53:30.971192 2026] [security2:error] [pid 66623:tid 66775] [client 85.154.68.202:57277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoR_-tO5rbWdOArH04J7MwAAARM"] [Tue Aug 18 12:53:30.988036 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:40155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/yg.php"] [unique_id "aoR_-vcmepr5_nHgLbMsmwAAAlI"] [Tue Aug 18 12:53:31.002577 2026] [security2:error] [pid 67073:tid 67231] [client 20.171.51.14:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fo.php"] [unique_id "aoR_-_cmepr5_nHgLbMsnQAAAi4"] [Tue Aug 18 12:53:31.068596 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zznmg.php"] [unique_id "aoR_-9O5rbWdOArH04J7NAAAAUc"] [Tue Aug 18 12:53:31.093052 2026] [security2:error] [pid 67073:tid 67205] [client 52.238.210.254:10206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/inputs.php"] [unique_id "aoR_-_cmepr5_nHgLbMspQAAAhQ"] [Tue Aug 18 12:53:31.097517 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:14643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/Text/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMspgAAAnI"] [Tue Aug 18 12:53:31.098091 2026] [security2:error] [pid 66623:tid 66859] [client 168.62.48.100:14741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoR_-9O5rbWdOArH04J7NQAAAWc"] [Tue Aug 18 12:53:31.100988 2026] [security2:error] [pid 67073:tid 67303] [client 20.51.153.15:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fresh.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqAAAAnY"] [Tue Aug 18 12:53:31.103839 2026] [security2:error] [pid 66623:tid 66877] [client 20.91.215.254:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/maint.php"] [unique_id "aoR_-9O5rbWdOArH04J7NwAAAXk"] [Tue Aug 18 12:53:31.113438 2026] [security2:error] [pid 67073:tid 67270] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqgAAAlU"] [Tue Aug 18 12:53:31.148779 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:19500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/grsiuk.php"] [unique_id "aoR_-_cmepr5_nHgLbMsqwAAAjA"] [Tue Aug 18 12:53:31.150233 2026] [security2:error] [pid 66623:tid 66822] [client 52.139.47.57:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-the.php"] [unique_id "aoR_-9O5rbWdOArH04J7OAAAAUI"] [Tue Aug 18 12:53:31.258311 2026] [security2:error] [pid 67073:tid 67288] [client 20.250.13.23:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/inputs.php"] [unique_id "aoR_-_cmepr5_nHgLbMsrgAAAmc"] [Tue Aug 18 12:53:31.278087 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:40511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/et.php"] [unique_id "aoR_-_cmepr5_nHgLbMssQAAAng"] [Tue Aug 18 12:53:31.286839 2026] [security2:error] [pid 66623:tid 66869] [client 104.209.144.33:32663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR_-9O5rbWdOArH04J7OgAAAXE"] [Tue Aug 18 12:53:31.289852 2026] [security2:error] [pid 67073:tid 67328] [client 4.232.151.198:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/as.php"] [unique_id "aoR_-_cmepr5_nHgLbMssgAAAo8"] [Tue Aug 18 12:53:31.339687 2026] [security2:error] [pid 67073:tid 67327] [client 168.62.48.100:14757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/well-known/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMstAAAAo4"] [Tue Aug 18 12:53:31.340271 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:13333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/admin404.php"] [unique_id "aoR_-_cmepr5_nHgLbMstQAAAlc"] [Tue Aug 18 12:53:31.381591 2026] [security2:error] [pid 67073:tid 67315] [client 52.238.210.254:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/100.php"] [unique_id "aoR_-_cmepr5_nHgLbMstwAAAoI"] [Tue Aug 18 12:53:31.388354 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoR_-_cmepr5_nHgLbMsuQAAAjc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:31.388657 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:54235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-load.php"] [unique_id "aoR_-_cmepr5_nHgLbMsuAAAAkg"] [Tue Aug 18 12:53:31.390151 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/HLA-dd.php"] [unique_id "aoR_-_cmepr5_nHgLbMsugAAAl4"] [Tue Aug 18 12:53:31.392746 2026] [security2:error] [pid 66623:tid 66769] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/bhfnd.php"] [unique_id "aoR_-9O5rbWdOArH04J7PAAAAQ0"] [Tue Aug 18 12:53:31.410090 2026] [autoindex:error] [pid 66623:tid 66829] [client 169.58.72.249:50192] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:31.429974 2026] [security2:error] [pid 67073:tid 67236] [client 52.238.210.254:9017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/about.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvQAAAjM"] [Tue Aug 18 12:53:31.435150 2026] [security2:error] [pid 67073:tid 67321] [client 20.104.100.201:53849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/8.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvgAAAog"] [Tue Aug 18 12:53:31.447691 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/test.php"] [unique_id "aoR_-_cmepr5_nHgLbMsvwAAAkc"] [Tue Aug 18 12:53:31.457794 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/ID3/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMswAAAAoQ"] [Tue Aug 18 12:53:31.465522 2026] [security2:error] [pid 67073:tid 67325] [client 4.223.164.152:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/11.php"] [unique_id "aoR_-_cmepr5_nHgLbMswQAAAow"] [Tue Aug 18 12:53:31.475254 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/loading.php"] [unique_id "aoR_-_cmepr5_nHgLbMswgAAAiA"] [Tue Aug 18 12:53:31.565753 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:39507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/h.php"] [unique_id "aoR_-_cmepr5_nHgLbMsxwAAAjU"] [Tue Aug 18 12:53:31.573941 2026] [security2:error] [pid 67073:tid 67276] [client 168.62.48.100:14840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoR_-_cmepr5_nHgLbMszQAAAls"] [Tue Aug 18 12:53:31.582372 2026] [security2:error] [pid 67073:tid 67225] [client 132.196.61.152:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mac.php"] [unique_id "aoR_-_cmepr5_nHgLbMszgAAAig"] [Tue Aug 18 12:53:31.598143 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:13343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/loading.php"] [unique_id "aoR_-_cmepr5_nHgLbMs0AAAAlg"] [Tue Aug 18 12:53:31.603534 2026] [security2:error] [pid 67073:tid 67232] [client 74.249.206.207:13335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/aa.php"] [unique_id "aoR_-_cmepr5_nHgLbMs0QAAAi8"] [Tue Aug 18 12:53:31.633925 2026] [security2:error] [pid 67073:tid 67314] [client 20.151.109.219:28754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wb.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1AAAAoE"] [Tue Aug 18 12:53:31.679511 2026] [security2:error] [pid 67073:tid 67324] [client 20.171.51.14:21078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xs.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1QAAAos"] [Tue Aug 18 12:53:31.682179 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.56.190:9961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/of.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1gAAAk4"] [Tue Aug 18 12:53:31.682250 2026] [security2:error] [pid 67073:tid 67247] [client 172.202.39.151:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/sf.php"] [unique_id "aoR_-_cmepr5_nHgLbMs1wAAAj4"] [Tue Aug 18 12:53:31.707435 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/qfvqu.php"] [unique_id "aoR_-_cmepr5_nHgLbMs2QAAAnc"] [Tue Aug 18 12:53:31.746775 2026] [security2:error] [pid 67073:tid 67221] [client 52.28.162.93:29174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMsxQAAAiQ"], referer: http://www.agrimotor.com.br/ [Tue Aug 18 12:53:31.763769 2026] [security2:error] [pid 67073:tid 67260] [client 52.238.210.254:8937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/akc.php"] [unique_id "aoR_-_cmepr5_nHgLbMs2wAAAks"] [Tue Aug 18 12:53:31.771000 2026] [security2:error] [pid 67073:tid 67295] [client 68.155.154.236:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMs3AAAAm4"] [Tue Aug 18 12:53:31.780294 2026] [security2:error] [pid 67073:tid 67296] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR_-_cmepr5_nHgLbMs3gAAAm8"] [Tue Aug 18 12:53:31.812100 2026] [security2:error] [pid 67073:tid 67227] [client 20.119.58.187:14637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/img/php8.php"] [unique_id "aoR_-_cmepr5_nHgLbMs4wAAAio"] [Tue Aug 18 12:53:31.812582 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:31.812850 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:31.814423 2026] [security2:error] [pid 67073:tid 67222] [client 168.62.48.100:14723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5AAAAiU"] [Tue Aug 18 12:53:31.817419 2026] [security2:error] [pid 67073:tid 67259] [client 20.100.169.31:25099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/default.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5QAAAko"] [Tue Aug 18 12:53:31.824657 2026] [autoindex:error] [pid 67073:tid 67226] [client 4.223.164.152:64676] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:31.846945 2026] [security2:error] [pid 66623:tid 66770] [client 20.51.153.15:13330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/conn-test.php"] [unique_id "aoR_-9O5rbWdOArH04J7PgAAAQ4"] [Tue Aug 18 12:53:31.867210 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.136.165:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/e.php"] [unique_id "aoR_-_cmepr5_nHgLbMs5gAAAiY"] [Tue Aug 18 12:53:31.921345 2026] [security2:error] [pid 67073:tid 67237] [client 20.91.215.254:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/phpMailer.php"] [unique_id "aoR_-_cmepr5_nHgLbMs6AAAAjQ"] [Tue Aug 18 12:53:31.964113 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/File.php"] [unique_id "aoR_-_cmepr5_nHgLbMs6gAAAk8"] [Tue Aug 18 12:53:31.966354 2026] [security2:error] [pid 66623:tid 66780] [client 20.48.236.86:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ajax.php"] [unique_id "aoR_-9O5rbWdOArH04J7PwAAARg"] [Tue Aug 18 12:53:31.984433 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:58259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/koiy.php"] [unique_id "aoR_-9O5rbWdOArH04J7QAAAAWk"] [Tue Aug 18 12:53:32.018770 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:48021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7QAAAoU"] [Tue Aug 18 12:53:32.040973 2026] [security2:error] [pid 67073:tid 67233] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/oivcl.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7gAAAjA"] [Tue Aug 18 12:53:32.051141 2026] [security2:error] [pid 67073:tid 67229] [client 168.62.48.100:14768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoR__Pcmepr5_nHgLbMs7wAAAiw"] [Tue Aug 18 12:53:32.080161 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:21946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/test1.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8QAAAlY"] [Tue Aug 18 12:53:32.099020 2026] [security2:error] [pid 66623:tid 66790] [client 20.51.153.15:13426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/evil.php"] [unique_id "aoR__NO5rbWdOArH04J7RwAAASI"] [Tue Aug 18 12:53:32.113407 2026] [security2:error] [pid 67073:tid 67283] [client 20.171.51.14:15771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/lmfi2.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8gAAAmI"] [Tue Aug 18 12:53:32.126578 2026] [security2:error] [pid 66623:tid 66826] [client 20.226.56.190:21141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bu.php"] [unique_id "aoR__NO5rbWdOArH04J7SAAAAUY"] [Tue Aug 18 12:53:32.148960 2026] [security2:error] [pid 67073:tid 67288] [client 20.104.100.201:53839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/images.php"] [unique_id "aoR__Pcmepr5_nHgLbMs8wAAAmc"] [Tue Aug 18 12:53:32.152617 2026] [security2:error] [pid 67073:tid 67305] [client 20.171.51.14:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ke.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9AAAAng"] [Tue Aug 18 12:53:32.156632 2026] [security2:error] [pid 66623:tid 66856] [client 172.202.39.151:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/index/function.php"] [unique_id "aoR__NO5rbWdOArH04J7SQAAAWQ"] [Tue Aug 18 12:53:32.163511 2026] [security2:error] [pid 67073:tid 67218] [client 20.100.169.31:28439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/ncx.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9QAAAiE"] [Tue Aug 18 12:53:32.173939 2026] [security2:error] [pid 66623:tid 66880] [client 20.119.58.187:14642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/languages/php8.php"] [unique_id "aoR__NO5rbWdOArH04J7SgAAAXw"] [Tue Aug 18 12:53:32.222525 2026] [security2:error] [pid 67073:tid 67173] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR__Pcmepr5_nHgLbMs9wACf2E"] [Tue Aug 18 12:53:32.267080 2026] [authz_core:error] [pid 67073:tid 67174] [remote 57.141.22.120:28652] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:32.267556 2026] [authz_core:error] [pid 67073:tid 67174] [remote 57.141.22.120:28652] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:32.290175 2026] [security2:error] [pid 66623:tid 66791] [client 168.62.48.100:14824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/mt/byp.php"] [unique_id "aoR__NO5rbWdOArH04J7TAAAASM"] [Tue Aug 18 12:53:32.295984 2026] [autoindex:error] [pid 67073:tid 67207] [client 4.223.164.152:64676] AH01276: Cannot serve directory /home2/veloxx/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:32.316374 2026] [security2:error] [pid 67073:tid 67268] [client 5.253.205.188:48208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/file.sql"] [unique_id "aoR__Pcmepr5_nHgLbMs-wAAAlM"], referer: https://medihub.com.br/file.sql [Tue Aug 18 12:53:32.318028 2026] [security2:error] [pid 67073:tid 67286] [client 4.232.151.198:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/min.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_AAAAmU"] [Tue Aug 18 12:53:32.342058 2026] [security2:error] [pid 67073:tid 67261] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zugvi.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_QAAAkw"] [Tue Aug 18 12:53:32.379661 2026] [security2:error] [pid 67073:tid 67240] [client 52.238.210.254:10207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoR__Pcmepr5_nHgLbMs_wAAAjc"] [Tue Aug 18 12:53:32.379850 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:31936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/inputs.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAAAAAh0"] [Tue Aug 18 12:53:32.402629 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:46519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fff.php"] [unique_id "aoR__NO5rbWdOArH04J7TwAAASY"] [Tue Aug 18 12:53:32.406024 2026] [security2:error] [pid 66623:tid 66808] [client 20.51.153.15:13332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-key.php"] [unique_id "aoR__NO5rbWdOArH04J7UAAAATQ"] [Tue Aug 18 12:53:32.414253 2026] [security2:error] [pid 67073:tid 67294] [client 213.35.127.232:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAQAAAm0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:32.442110 2026] [security2:error] [pid 67073:tid 67280] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR__Pcmepr5_nHgLbMtAgAAAl8"] [Tue Aug 18 12:53:32.474985 2026] [security2:error] [pid 67073:tid 67239] [client 37.40.227.74:57121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBQAAAjY"] [Tue Aug 18 12:53:32.475127 2026] [security2:error] [pid 67073:tid 67239] [client 37.40.227.74:57121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBQAAAjY"] [Tue Aug 18 12:53:32.478107 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fd.php"] [unique_id "aoR__Pcmepr5_nHgLbMtBgAAAog"] [Tue Aug 18 12:53:32.507024 2026] [security2:error] [pid 67073:tid 67266] [client 4.223.164.152:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCAAAAlE"] [Tue Aug 18 12:53:32.524789 2026] [security2:error] [pid 66623:tid 66882] [client 52.28.162.93:29186] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoR__NO5rbWdOArH04J7TgAAAX4"], referer: http://www.agrimotor.com.br/ [Tue Aug 18 12:53:32.527260 2026] [security2:error] [pid 67073:tid 67317] [client 168.62.48.100:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/MTOS/byp.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCQAAAoQ"] [Tue Aug 18 12:53:32.537637 2026] [security2:error] [pid 66623:tid 66863] [client 20.119.58.187:15338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/customize/php8.php"] [unique_id "aoR__NO5rbWdOArH04J7UwAAAWs"] [Tue Aug 18 12:53:32.541217 2026] [security2:error] [pid 67073:tid 67325] [client 4.223.164.152:6901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/fi22.php"] [unique_id "aoR__Pcmepr5_nHgLbMtCgAAAow"] [Tue Aug 18 12:53:32.560914 2026] [security2:error] [pid 66623:tid 66811] [client 135.225.75.187:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rum.php"] [unique_id "aoR__NO5rbWdOArH04J7VAAAATc"] [Tue Aug 18 12:53:32.604054 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:49748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/a.php"] [unique_id "aoR__NO5rbWdOArH04J7WAAAAVY"] [Tue Aug 18 12:53:32.616204 2026] [security2:error] [pid 67073:tid 67238] [client 172.202.39.151:60999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cah.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDAAAAjU"] [Tue Aug 18 12:53:32.622458 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:20247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDQAAAlo"] [Tue Aug 18 12:53:32.634386 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDgAAAlU"] [Tue Aug 18 12:53:32.645232 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.61.152:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ops.php"] [unique_id "aoR__Pcmepr5_nHgLbMtDwAAAjs"] [Tue Aug 18 12:53:32.654058 2026] [security2:error] [pid 66623:tid 66885] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wsrer.php"] [unique_id "aoR__NO5rbWdOArH04J7WQAAAYE"] [Tue Aug 18 12:53:32.666808 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/a7.php"] [unique_id "aoR__Pcmepr5_nHgLbMtEQAAApI"] [Tue Aug 18 12:53:32.742972 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/text.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFQAAAkc"] [Tue Aug 18 12:53:32.748107 2026] [authz_core:error] [pid 67073:tid 67186] [remote 57.141.22.15:31022] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:32.748386 2026] [authz_core:error] [pid 67073:tid 67186] [remote 57.141.22.15:31022] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:32.760215 2026] [security2:error] [pid 67073:tid 67187] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFgACFW8"] [Tue Aug 18 12:53:32.764764 2026] [security2:error] [pid 67073:tid 67330] [client 168.62.48.100:14776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoR__Pcmepr5_nHgLbMtFwAAApE"] [Tue Aug 18 12:53:32.779057 2026] [security2:error] [pid 67073:tid 67301] [client 20.51.153.15:13406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpcheck.php"] [unique_id "aoR__Pcmepr5_nHgLbMtGQAAAnQ"] [Tue Aug 18 12:53:32.805635 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:6392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rn.php"] [unique_id "aoR__Pcmepr5_nHgLbMtGgAAAjw"] [Tue Aug 18 12:53:32.820412 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.136.165:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pouhg.php"] [unique_id "aoR__NO5rbWdOArH04J7XQAAAWM"] [Tue Aug 18 12:53:32.849673 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nh.php"] [unique_id "aoR__NO5rbWdOArH04J7XgAAAVM"] [Tue Aug 18 12:53:32.902033 2026] [security2:error] [pid 67073:tid 67290] [client 20.119.58.187:15312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes.bak/html-api/php8.php"] [unique_id "aoR__Pcmepr5_nHgLbMtHAAAAmk"] [Tue Aug 18 12:53:32.945186 2026] [security2:error] [pid 67073:tid 67313] [client 4.223.164.152:54255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/aaa.php"] [unique_id "aoR__Pcmepr5_nHgLbMtHgAAAoA"] [Tue Aug 18 12:53:32.961912 2026] [security2:error] [pid 66623:tid 66777] [client 20.48.236.86:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/yj09.php"] [unique_id "aoR__NO5rbWdOArH04J7YgAAARU"] [Tue Aug 18 12:53:32.977668 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/ucpfr.php"] [unique_id "aoR__NO5rbWdOArH04J7YwAAAUg"] [Tue Aug 18 12:53:32.980223 2026] [security2:error] [pid 66623:tid 66809] [client 20.171.51.14:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/info2.php"] [unique_id "aoR__NO5rbWdOArH04J7ZAAAATU"] [Tue Aug 18 12:53:32.999355 2026] [security2:error] [pid 66623:tid 66851] [client 52.238.210.254:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/php.php"] [unique_id "aoR__NO5rbWdOArH04J7ZQAAAV8"] [Tue Aug 18 12:53:33.003674 2026] [security2:error] [pid 66623:tid 66782] [client 168.62.48.100:14843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoR__dO5rbWdOArH04J7ZgAAARo"] [Tue Aug 18 12:53:33.022792 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.100.201:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/a.php"] [unique_id "aoR__fcmepr5_nHgLbMtIAAAAnA"] [Tue Aug 18 12:53:33.104979 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:13341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/mimes.php"] [unique_id "aoR__fcmepr5_nHgLbMtIgAAAiY"] [Tue Aug 18 12:53:33.109760 2026] [security2:error] [pid 66623:tid 66850] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/xx.php"] [unique_id "aoR__dO5rbWdOArH04J7aAAAAV4"] [Tue Aug 18 12:53:33.194453 2026] [security2:error] [pid 67073:tid 67215] [client 114.119.153.172:45941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "v8multimarcasrs.com.br"] [uri "/veiculos"] [unique_id "aoR__fcmepr5_nHgLbMtJAAAAh4"], referer: https://v8multimarcasrs.com.br/veiculos?marca_id=HONDA&page=2 [Tue Aug 18 12:53:33.213706 2026] [security2:error] [pid 67073:tid 67237] [client 20.151.109.219:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/xn.php"] [unique_id "aoR__fcmepr5_nHgLbMtJQAAAjQ"] [Tue Aug 18 12:53:33.232516 2026] [security2:error] [pid 66623:tid 66810] [client 20.118.172.148:33784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wk/index.php"] [unique_id "aoR__dO5rbWdOArH04J7agAAATY"] [Tue Aug 18 12:53:33.237294 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.136.165:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/moon3.php"] [unique_id "aoR__dO5rbWdOArH04J7awAAARE"] [Tue Aug 18 12:53:33.247655 2026] [security2:error] [pid 66623:tid 66868] [client 168.62.48.100:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoR__dO5rbWdOArH04J7bAAAAXA"] [Tue Aug 18 12:53:33.256925 2026] [security2:error] [pid 67073:tid 67303] [client 4.223.164.152:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoR__fcmepr5_nHgLbMtJwAAAnY"] [Tue Aug 18 12:53:33.258477 2026] [security2:error] [pid 66623:tid 66806] [client 20.119.58.187:14607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/widgets/php8.php"] [unique_id "aoR__dO5rbWdOArH04J7bQAAATI"] [Tue Aug 18 12:53:33.267498 2026] [security2:error] [pid 67073:tid 67197] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws61.php"] [unique_id "aoR__fcmepr5_nHgLbMtKAACink"] [Tue Aug 18 12:53:33.282064 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/yxijx.php"] [unique_id "aoR__dO5rbWdOArH04J7bgAAASE"] [Tue Aug 18 12:53:33.324384 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/edit.php"] [unique_id "aoR__fcmepr5_nHgLbMtKwAAAoU"] [Tue Aug 18 12:53:33.338232 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:16581] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jotaautos.com.br"] [uri "/1.php"] [unique_id "aoR__dO5rbWdOArH04J7bwAAAT0"] [Tue Aug 18 12:53:33.338304 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:16581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/1.php"] [unique_id "aoR__dO5rbWdOArH04J7bwAAAT0"] [Tue Aug 18 12:53:33.341154 2026] [security2:error] [pid 67073:tid 67254] [client 52.238.210.254:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/t.php"] [unique_id "aoR__fcmepr5_nHgLbMtLQAAAkU"] [Tue Aug 18 12:53:33.366143 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/al.php"] [unique_id "aoR__fcmepr5_nHgLbMtLgAAAlI"] [Tue Aug 18 12:53:33.366908 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/gecko.php"] [unique_id "aoR__dO5rbWdOArH04J7cAAAAW8"] [Tue Aug 18 12:53:33.377771 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.18.37:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoR__fcmepr5_nHgLbMtMAAAAi4"] [Tue Aug 18 12:53:33.383701 2026] [security2:error] [pid 67073:tid 67229] [client 20.51.153.15:13331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fraie1p4.php"] [unique_id "aoR__fcmepr5_nHgLbMtMQAAAiw"] [Tue Aug 18 12:53:33.395884 2026] [security2:error] [pid 66623:tid 66798] [client 4.232.151.198:35493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/php8.php"] [unique_id "aoR__dO5rbWdOArH04J7cQAAASo"] [Tue Aug 18 12:53:33.417831 2026] [security2:error] [pid 67073:tid 67288] [client 20.171.51.14:15013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/oo.php"] [unique_id "aoR__fcmepr5_nHgLbMtMwAAAmc"] [Tue Aug 18 12:53:33.418196 2026] [security2:error] [pid 67073:tid 67305] [client 172.202.39.151:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/system_log.php"] [unique_id "aoR__fcmepr5_nHgLbMtNAAAAng"] [Tue Aug 18 12:53:33.427104 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoR__fcmepr5_nHgLbMtNgAAAjk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:33.451619 2026] [security2:error] [pid 67073:tid 67200] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rum.php"] [unique_id "aoR__fcmepr5_nHgLbMtOgACRHw"] [Tue Aug 18 12:53:33.464657 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:32661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/blog/byp.php"] [unique_id "aoR__fcmepr5_nHgLbMtPAAAAj0"] [Tue Aug 18 12:53:33.491151 2026] [security2:error] [pid 67073:tid 67272] [client 74.249.206.207:52137] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/1.php"] [unique_id "aoR__fcmepr5_nHgLbMtPgAAAlc"] [Tue Aug 18 12:53:33.491278 2026] [security2:error] [pid 67073:tid 67272] [client 74.249.206.207:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/1.php"] [unique_id "aoR__fcmepr5_nHgLbMtPgAAAlc"] [Tue Aug 18 12:53:33.491533 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.56.190:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ut.php"] [unique_id "aoR__fcmepr5_nHgLbMtPwAAAoM"] [Tue Aug 18 12:53:33.492609 2026] [security2:error] [pid 67073:tid 67212] [client 168.62.48.100:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoR__fcmepr5_nHgLbMtQAAAAhs"] [Tue Aug 18 12:53:33.512329 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:18831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR__fcmepr5_nHgLbMtQwAAAkw"] [Tue Aug 18 12:53:33.569735 2026] [security2:error] [pid 67073:tid 67294] [client 20.171.51.14:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sx.php"] [unique_id "aoR__fcmepr5_nHgLbMtSQAAAm0"] [Tue Aug 18 12:53:33.593582 2026] [security2:error] [pid 67073:tid 67241] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/zwlsv.php"] [unique_id "aoR__fcmepr5_nHgLbMtSwAAAjg"] [Tue Aug 18 12:53:33.595618 2026] [authz_core:error] [pid 67073:tid 67086] [remote 57.141.22.24:43678] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:33.595936 2026] [authz_core:error] [pid 67073:tid 67086] [remote 57.141.22.24:43678] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:33.623028 2026] [security2:error] [pid 67073:tid 67286] [client 20.119.58.187:15145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/IXR/php8.php"] [unique_id "aoR__fcmepr5_nHgLbMtTAAAAmU"] [Tue Aug 18 12:53:33.629326 2026] [security2:error] [pid 66623:tid 66858] [client 149.34.210.157:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR__dO5rbWdOArH04J7cgAAAWY"] [Tue Aug 18 12:53:33.645383 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ze.php"] [unique_id "aoR__dO5rbWdOArH04J7cwAAAUU"] [Tue Aug 18 12:53:33.646406 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:55599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/info.php"] [unique_id "aoR__fcmepr5_nHgLbMtTgAAAi0"] [Tue Aug 18 12:53:33.651938 2026] [security2:error] [pid 67073:tid 67255] [client 20.51.153.15:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/pqr.php"] [unique_id "aoR__fcmepr5_nHgLbMtTwAAAkY"] [Tue Aug 18 12:53:33.652852 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:17248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/opts.php"] [unique_id "aoR__fcmepr5_nHgLbMtUAAAAjU"] [Tue Aug 18 12:53:33.685540 2026] [security2:error] [pid 67073:tid 67088] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ze.php"] [unique_id "aoR__fcmepr5_nHgLbMtUgACKAw"] [Tue Aug 18 12:53:33.731062 2026] [security2:error] [pid 67073:tid 67326] [client 168.62.48.100:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoR__fcmepr5_nHgLbMtVwAAAo0"] [Tue Aug 18 12:53:33.757781 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.61.152:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/8.php"] [unique_id "aoR__fcmepr5_nHgLbMtWAAAAkc"] [Tue Aug 18 12:53:33.763651 2026] [security2:error] [pid 67073:tid 67232] [client 20.104.100.201:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoR__fcmepr5_nHgLbMtWgAAAi8"] [Tue Aug 18 12:53:33.773117 2026] [security2:error] [pid 66623:tid 66774] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/av.php"] [unique_id "aoR__dO5rbWdOArH04J7dgAAARI"] [Tue Aug 18 12:53:33.786821 2026] [security2:error] [pid 66623:tid 66877] [client 4.223.164.152:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/xiugai.php"] [unique_id "aoR__dO5rbWdOArH04J7dwAAAXk"] [Tue Aug 18 12:53:33.822233 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.85.180:7013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gelay.php"] [unique_id "aoR__fcmepr5_nHgLbMtWwAAAnw"] [Tue Aug 18 12:53:33.896270 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:13314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/lmfi2.php"] [unique_id "aoR__fcmepr5_nHgLbMtXgAAAj4"] [Tue Aug 18 12:53:33.904946 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gjm.php"] [unique_id "aoR__fcmepr5_nHgLbMtXwACeRI"] [Tue Aug 18 12:53:33.905333 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/jrpga.php"] [unique_id "aoR__fcmepr5_nHgLbMtYAAAAkM"] [Tue Aug 18 12:53:33.906259 2026] [security2:error] [pid 66623:tid 66858] [client 149.34.210.157:65044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoR__dO5rbWdOArH04J7cgAAAWY"] [Tue Aug 18 12:53:33.930859 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:28418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoR__dO5rbWdOArH04J7eQAAAWg"] [Tue Aug 18 12:53:33.933967 2026] [security2:error] [pid 66623:tid 66804] [client 52.238.210.254:8876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/index/function.php"] [unique_id "aoR__dO5rbWdOArH04J7egAAATA"] [Tue Aug 18 12:53:33.968432 2026] [security2:error] [pid 67073:tid 67262] [client 168.62.48.100:14779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoR__fcmepr5_nHgLbMtZAAAAk0"] [Tue Aug 18 12:53:33.977460 2026] [security2:error] [pid 67073:tid 67324] [client 20.119.58.187:15157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/js/php8.php"] [unique_id "aoR__fcmepr5_nHgLbMtZgAAAos"] [Tue Aug 18 12:53:33.978499 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.56.190:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/eh.php"] [unique_id "aoR__dO5rbWdOArH04J7ewAAATg"] [Tue Aug 18 12:53:33.979150 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/inputs.php"] [unique_id "aoR__fcmepr5_nHgLbMtZwAAAiQ"] [Tue Aug 18 12:53:34.020250 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.18.37:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/u.php"] [unique_id "aoR__vcmepr5_nHgLbMtagAAApE"] [Tue Aug 18 12:53:34.037982 2026] [security2:error] [pid 67073:tid 67278] [client 196.12.128.158:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtawAAAl0"] [Tue Aug 18 12:53:34.038152 2026] [security2:error] [pid 67073:tid 67278] [client 196.12.128.158:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtawAAAl0"] [Tue Aug 18 12:53:34.070475 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.136.165:58247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zwq13.php"] [unique_id "aoR__vcmepr5_nHgLbMtbQAAAm8"] [Tue Aug 18 12:53:34.079234 2026] [security2:error] [pid 67073:tid 67222] [client 213.202.253.4:60149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/schallfuns.php"] [unique_id "aoR__vcmepr5_nHgLbMtbgAAAiU"], referer: www.google.com [Tue Aug 18 12:53:34.120579 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoR__tO5rbWdOArH04J7fAAAARw"] [Tue Aug 18 12:53:34.204572 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:13342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/info2.php"] [unique_id "aoR__tO5rbWdOArH04J7fQAAARk"] [Tue Aug 18 12:53:34.206952 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:43559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoR__tO5rbWdOArH04J7fgAAATE"] [Tue Aug 18 12:53:34.210458 2026] [security2:error] [pid 67073:tid 67223] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoR__vcmepr5_nHgLbMtdQAAAiY"] [Tue Aug 18 12:53:34.217599 2026] [security2:error] [pid 66623:tid 66770] [client 168.62.48.100:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/first.php"] [unique_id "aoR__tO5rbWdOArH04J7fwAAAQ4"] [Tue Aug 18 12:53:34.226107 2026] [security2:error] [pid 67073:tid 67220] [client 4.223.164.152:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/adminner.php"] [unique_id "aoR__vcmepr5_nHgLbMtdgAAAiM"] [Tue Aug 18 12:53:34.228758 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/new4.php"] [unique_id "aoR__vcmepr5_nHgLbMtdwACbBY"] [Tue Aug 18 12:53:34.288433 2026] [security2:error] [pid 67073:tid 67105] [remote 115.146.125.52:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoR__vcmepr5_nHgLbMtegACOh0"] [Tue Aug 18 12:53:34.301210 2026] [security2:error] [pid 67073:tid 67299] [client 20.171.51.14:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/nu.php"] [unique_id "aoR__vcmepr5_nHgLbMtewAAAnI"] [Tue Aug 18 12:53:34.367142 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:14613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/pki-validation/php8.php"] [unique_id "aoR__tO5rbWdOArH04J7gAAAAWk"] [Tue Aug 18 12:53:34.376565 2026] [security2:error] [pid 66623:tid 66665] [remote 203.99.146.53:52288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoR__tO5rbWdOArH04J7ggABWRw"] [Tue Aug 18 12:53:34.376762 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp.php"] [unique_id "aoR__tO5rbWdOArH04J7gQAAAYc"] [Tue Aug 18 12:53:34.409372 2026] [security2:error] [pid 67073:tid 67320] [client 20.171.51.14:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ja.php"] [unique_id "aoR__vcmepr5_nHgLbMtfQAAAoc"] [Tue Aug 18 12:53:34.417662 2026] [security2:error] [pid 67073:tid 67318] [client 52.238.210.254:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wk/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtfgAAAoU"] [Tue Aug 18 12:53:34.418470 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.56.190:10608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ad.php"] [unique_id "aoR__vcmepr5_nHgLbMtfwAAAlQ"] [Tue Aug 18 12:53:34.423552 2026] [security2:error] [pid 67073:tid 67109] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-act.php"] [unique_id "aoR__vcmepr5_nHgLbMtgAACRSE"] [Tue Aug 18 12:53:34.445602 2026] [security2:error] [pid 66623:tid 66766] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/media.php"] [unique_id "aoR__tO5rbWdOArH04J7hQAAAQo"] [Tue Aug 18 12:53:34.445975 2026] [security2:error] [pid 66623:tid 66870] [client 213.35.127.232:53012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoR__tO5rbWdOArH04J7hgAAAXI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:34.453096 2026] [security2:error] [pid 66623:tid 66837] [client 168.62.48.100:14750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoR__tO5rbWdOArH04J7iAAAAVE"] [Tue Aug 18 12:53:34.487030 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.136.165:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/Okxob.php"] [unique_id "aoR__vcmepr5_nHgLbMtggAAAnM"] [Tue Aug 18 12:53:34.496072 2026] [security2:error] [pid 67073:tid 67288] [client 20.104.85.180:18836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/adminfuns.php"] [unique_id "aoR__vcmepr5_nHgLbMtgwAAAmc"] [Tue Aug 18 12:53:34.500201 2026] [security2:error] [pid 66623:tid 66886] [client 20.51.153.15:13386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/test_info.php"] [unique_id "aoR__tO5rbWdOArH04J7igAAAYI"] [Tue Aug 18 12:53:34.546541 2026] [authz_core:error] [pid 67073:tid 67112] [remote 57.141.22.26:50700] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:34.546851 2026] [authz_core:error] [pid 67073:tid 67112] [remote 57.141.22.26:50700] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:34.580041 2026] [security2:error] [pid 66623:tid 66767] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/nwwha.php"] [unique_id "aoR__tO5rbWdOArH04J7iwAAAQs"] [Tue Aug 18 12:53:34.625635 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/grsiuk.php"] [unique_id "aoR__vcmepr5_nHgLbMthgACfRw"] [Tue Aug 18 12:53:34.638169 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:48227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoR__tO5rbWdOArH04J7jQAAAUk"] [Tue Aug 18 12:53:34.644695 2026] [security2:error] [pid 67073:tid 67272] [client 172.202.39.151:44456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoR__vcmepr5_nHgLbMtiAAAAlc"] [Tue Aug 18 12:53:34.651551 2026] [security2:error] [pid 66623:tid 66788] [client 135.225.75.187:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gjm.php"] [unique_id "aoR__tO5rbWdOArH04J7jgAAASA"] [Tue Aug 18 12:53:34.651773 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/updates.php"] [unique_id "aoR__vcmepr5_nHgLbMtiQAAAlY"] [Tue Aug 18 12:53:34.670177 2026] [security2:error] [pid 67073:tid 67237] [client 20.250.13.23:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/admin.php"] [unique_id "aoR__vcmepr5_nHgLbMtiwAAAjQ"] [Tue Aug 18 12:53:34.671457 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file1221.php"] [unique_id "aoR__vcmepr5_nHgLbMtjAAAAhs"] [Tue Aug 18 12:53:34.672957 2026] [security2:error] [pid 66623:tid 66821] [client 20.171.51.14:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ko.php"] [unique_id "aoR__tO5rbWdOArH04J7jwAAAUE"] [Tue Aug 18 12:53:34.690534 2026] [security2:error] [pid 67073:tid 67205] [client 20.104.100.201:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/99.php"] [unique_id "aoR__vcmepr5_nHgLbMtjQAAAhQ"] [Tue Aug 18 12:53:34.691235 2026] [security2:error] [pid 67073:tid 67268] [client 168.62.48.100:14669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtjgAAAlM"] [Tue Aug 18 12:53:34.699806 2026] [security2:error] [pid 67073:tid 67261] [client 104.209.144.33:25317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtjwAAAkw"] [Tue Aug 18 12:53:34.710175 2026] [security2:error] [pid 67073:tid 67210] [client 20.48.236.86:65126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/scxy.php"] [unique_id "aoR__vcmepr5_nHgLbMtkAAAAhk"] [Tue Aug 18 12:53:34.721320 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:14617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/pomo/php8.php"] [unique_id "aoR__tO5rbWdOArH04J7kAAAASY"] [Tue Aug 18 12:53:34.748574 2026] [security2:error] [pid 66623:tid 66842] [client 20.51.153.15:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/xynz1.php"] [unique_id "aoR__tO5rbWdOArH04J7kQAAAVY"] [Tue Aug 18 12:53:34.768027 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoR__vcmepr5_nHgLbMtkwAAAl8"] [Tue Aug 18 12:53:34.795919 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.18.37:32261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoR__vcmepr5_nHgLbMtlAAAAmo"] [Tue Aug 18 12:53:34.844607 2026] [security2:error] [pid 67073:tid 67321] [client 132.196.61.152:55297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/biufile.php"] [unique_id "aoR__vcmepr5_nHgLbMtmAAAAog"] [Tue Aug 18 12:53:34.864190 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:6609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoR__vcmepr5_nHgLbMtmgAAAis"] [Tue Aug 18 12:53:34.874641 2026] [security2:error] [pid 67073:tid 67120] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/h.php"] [unique_id "aoR__vcmepr5_nHgLbMtmwACZSw"] [Tue Aug 18 12:53:34.888254 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/opsqt.php"] [unique_id "aoR__vcmepr5_nHgLbMtnQAAAi0"] [Tue Aug 18 12:53:34.912636 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.136.165:39515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/file59.php"] [unique_id "aoR__tO5rbWdOArH04J7lAAAAU8"] [Tue Aug 18 12:53:34.926104 2026] [security2:error] [pid 67073:tid 67315] [client 168.62.48.100:14752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoR__vcmepr5_nHgLbMtnwAAAoI"] [Tue Aug 18 12:53:34.964193 2026] [security2:error] [pid 66623:tid 66839] [client 74.248.136.165:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/hello.php"] [unique_id "aoR__tO5rbWdOArH04J7mAAAAVM"] [Tue Aug 18 12:53:34.978881 2026] [security2:error] [pid 67073:tid 67251] [client 197.184.64.235:41355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtogAAAkI"] [Tue Aug 18 12:53:34.979003 2026] [security2:error] [pid 67073:tid 67251] [client 197.184.64.235:41355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__vcmepr5_nHgLbMtogAAAkI"] [Tue Aug 18 12:53:34.995273 2026] [security2:error] [pid 67073:tid 67302] [client 20.51.153.15:13385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/album.php"] [unique_id "aoR__vcmepr5_nHgLbMtowAAAnU"] [Tue Aug 18 12:53:35.052883 2026] [security2:error] [pid 67073:tid 67255] [client 52.139.47.57:39405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wso.php"] [unique_id "aoR___cmepr5_nHgLbMtpgAAAkY"] [Tue Aug 18 12:53:35.075667 2026] [security2:error] [pid 67073:tid 67331] [client 20.119.58.187:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/block-patterns/php8.php"] [unique_id "aoR___cmepr5_nHgLbMtpwAAApI"] [Tue Aug 18 12:53:35.088763 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.56.190:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/vd.php"] [unique_id "aoR__9O5rbWdOArH04J7mQAAAYM"] [Tue Aug 18 12:53:35.088766 2026] [security2:error] [pid 66623:tid 66853] [client 52.238.210.254:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-blink.php"] [unique_id "aoR__9O5rbWdOArH04J7mgAAAWE"] [Tue Aug 18 12:53:35.090716 2026] [security2:error] [pid 66623:tid 66777] [client 20.171.51.14:33697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xx.php"] [unique_id "aoR__9O5rbWdOArH04J7mwAAARU"] [Tue Aug 18 12:53:35.092502 2026] [security2:error] [pid 66623:tid 66828] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/manager.php"] [unique_id "aoR__9O5rbWdOArH04J7nAAAAUg"] [Tue Aug 18 12:53:35.103353 2026] [security2:error] [pid 67073:tid 67309] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/images.php"] [unique_id "aoR___cmepr5_nHgLbMtqgAAAnw"] [Tue Aug 18 12:53:35.126002 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/pl.php"] [unique_id "aoR___cmepr5_nHgLbMtrAAAAk4"] [Tue Aug 18 12:53:35.143024 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:54254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inx.php"] [unique_id "aoR___cmepr5_nHgLbMtrQAAAjw"] [Tue Aug 18 12:53:35.159091 2026] [security2:error] [pid 67073:tid 67304] [client 172.202.39.151:44361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-good.php"] [unique_id "aoR___cmepr5_nHgLbMtrwAAAnc"] [Tue Aug 18 12:53:35.162352 2026] [security2:error] [pid 67073:tid 67306] [client 168.62.48.100:14673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/blog/byp.php"] [unique_id "aoR___cmepr5_nHgLbMtsAAAAnk"] [Tue Aug 18 12:53:35.213996 2026] [security2:error] [pid 66623:tid 66879] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/jvcpa.php"] [unique_id "aoR__9O5rbWdOArH04J7nwAAAXs"] [Tue Aug 18 12:53:35.260494 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/creds.php"] [unique_id "aoR___cmepr5_nHgLbMttAAAAks"] [Tue Aug 18 12:53:35.284146 2026] [security2:error] [pid 67073:tid 67317] [client 74.248.18.37:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoR___cmepr5_nHgLbMttgAAAoQ"] [Tue Aug 18 12:53:35.295582 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.100.201:17387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yup.php"] [unique_id "aoR___cmepr5_nHgLbMttwAAAic"] [Tue Aug 18 12:53:35.303235 2026] [security2:error] [pid 67073:tid 67126] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/koiy.php"] [unique_id "aoR___cmepr5_nHgLbMtuQACGDI"] [Tue Aug 18 12:53:35.308424 2026] [security2:error] [pid 67073:tid 67296] [client 4.223.164.152:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoR___cmepr5_nHgLbMtugAAAm8"] [Tue Aug 18 12:53:35.330507 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.136.165:39523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/eauu.php"] [unique_id "aoR___cmepr5_nHgLbMtuwAAAiU"] [Tue Aug 18 12:53:35.398738 2026] [security2:error] [pid 67073:tid 67311] [client 20.163.43.14:3162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoR___cmepr5_nHgLbMtvgAAAn4"] [Tue Aug 18 12:53:35.402340 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:14760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoR__9O5rbWdOArH04J7oQAAAUM"] [Tue Aug 18 12:53:35.405360 2026] [security2:error] [pid 67073:tid 67282] [client 52.238.210.254:10212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/xfun.php"] [unique_id "aoR___cmepr5_nHgLbMtvwAAAmE"] [Tue Aug 18 12:53:35.425589 2026] [security2:error] [pid 66623:tid 66864] [client 192.141.172.134:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__9O5rbWdOArH04J7ogAAAWw"] [Tue Aug 18 12:53:35.425713 2026] [security2:error] [pid 66623:tid 66864] [client 192.141.172.134:51397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR__9O5rbWdOArH04J7ogAAAWw"] [Tue Aug 18 12:53:35.459150 2026] [security2:error] [pid 66623:tid 66800] [client 213.35.127.232:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoR__9O5rbWdOArH04J7owAAASw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:35.462607 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:15320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/updraft/php8.php"] [unique_id "aoR___cmepr5_nHgLbMtwwAAAik"] [Tue Aug 18 12:53:35.463536 2026] [security2:error] [pid 67073:tid 67213] [client 104.209.144.33:32669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR___cmepr5_nHgLbMtxAAAAhw"] [Tue Aug 18 12:53:35.466959 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.200.96:14102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/opsqt.php"] [unique_id "aoR___cmepr5_nHgLbMtxgAAAl4"] [Tue Aug 18 12:53:35.476270 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/w1.php"] [unique_id "aoR___cmepr5_nHgLbMtxwAAAnI"] [Tue Aug 18 12:53:35.482106 2026] [security2:error] [pid 67073:tid 67324] [client 4.232.151.198:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoR___cmepr5_nHgLbMtyAAAAos"] [Tue Aug 18 12:53:35.507109 2026] [security2:error] [pid 67073:tid 67131] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fff.php"] [unique_id "aoR___cmepr5_nHgLbMtywACRTc"] [Tue Aug 18 12:53:35.525617 2026] [security2:error] [pid 66623:tid 66809] [client 20.91.215.254:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-activat.php"] [unique_id "aoR__9O5rbWdOArH04J7pAAAATU"] [Tue Aug 18 12:53:35.539355 2026] [security2:error] [pid 67073:tid 67233] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoR___cmepr5_nHgLbMtzAAAAjA"] [Tue Aug 18 12:53:35.586844 2026] [security2:error] [pid 67073:tid 67218] [client 74.249.206.207:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/img.php"] [unique_id "aoR___cmepr5_nHgLbMtzwAAAiE"] [Tue Aug 18 12:53:35.590811 2026] [security2:error] [pid 67073:tid 67310] [client 20.51.153.15:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/mandrill.php"] [unique_id "aoR___cmepr5_nHgLbMt0AAAAn0"] [Tue Aug 18 12:53:35.600459 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/reviall.php"] [unique_id "aoR___cmepr5_nHgLbMt0gAAAo8"] [Tue Aug 18 12:53:35.606961 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-act.php"] [unique_id "aoR___cmepr5_nHgLbMt1AAAAlc"] [Tue Aug 18 12:53:35.641689 2026] [security2:error] [pid 67073:tid 67237] [client 168.62.48.100:14767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoR___cmepr5_nHgLbMt1QAAAjQ"] [Tue Aug 18 12:53:35.716014 2026] [security2:error] [pid 67073:tid 67210] [client 20.65.98.162:29483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/coffee.php"] [unique_id "aoR___cmepr5_nHgLbMt2QAAAhk"] [Tue Aug 18 12:53:35.723759 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/222.php"] [unique_id "aoR___cmepr5_nHgLbMt2gAAAjc"] [Tue Aug 18 12:53:35.730862 2026] [security2:error] [pid 67073:tid 67143] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pouhg.php"] [unique_id "aoR___cmepr5_nHgLbMt2wACHUM"] [Tue Aug 18 12:53:35.739059 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:29199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/conn-test.php"] [unique_id "aoR___cmepr5_nHgLbMt3AAAAmo"] [Tue Aug 18 12:53:35.748754 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.136.165:65109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/dsd.php"] [unique_id "aoR__9O5rbWdOArH04J7pgAAAVU"] [Tue Aug 18 12:53:35.773732 2026] [security2:error] [pid 66623:tid 66775] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/mac.php"] [unique_id "aoR__9O5rbWdOArH04J7qAAAARM"] [Tue Aug 18 12:53:35.788558 2026] [security2:error] [pid 67073:tid 67227] [client 86.120.159.145:62230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR___cmepr5_nHgLbMt3wAAAio"] [Tue Aug 18 12:53:35.788640 2026] [security2:error] [pid 67073:tid 67227] [client 86.120.159.145:62230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoR___cmepr5_nHgLbMt3wAAAio"] [Tue Aug 18 12:53:35.799512 2026] [security2:error] [pid 66623:tid 66824] [client 20.163.43.14:3172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoR__9O5rbWdOArH04J7qQAAAUQ"] [Tue Aug 18 12:53:35.801576 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.56.190:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/56.php"] [unique_id "aoR__9O5rbWdOArH04J7qgAAAS0"] [Tue Aug 18 12:53:35.813167 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/env.php"] [unique_id "aoR___cmepr5_nHgLbMt4AAAAlA"] [Tue Aug 18 12:53:35.824170 2026] [security2:error] [pid 67073:tid 67207] [client 20.119.58.187:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/upgrade-temp-backup/php8.php"] [unique_id "aoR___cmepr5_nHgLbMt4QAAAhY"] [Tue Aug 18 12:53:35.825854 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoR___cmepr5_nHgLbMt4gAAAi0"] [Tue Aug 18 12:53:35.847524 2026] [security2:error] [pid 67073:tid 67238] [client 20.51.153.15:13423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/main.php"] [unique_id "aoR___cmepr5_nHgLbMt5AAAAjU"] [Tue Aug 18 12:53:35.851751 2026] [security2:error] [pid 66623:tid 66827] [client 135.225.75.187:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/new4.php"] [unique_id "aoR__9O5rbWdOArH04J7qwAAAUc"] [Tue Aug 18 12:53:35.859430 2026] [security2:error] [pid 67073:tid 67315] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoR___cmepr5_nHgLbMt5gAAAoI"] [Tue Aug 18 12:53:35.875165 2026] [security2:error] [pid 66623:tid 66819] [client 168.62.48.100:16316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "journeyxperience.com"] [uri "/images/security.php"] [unique_id "aoR__9O5rbWdOArH04J7rAAAAT8"] [Tue Aug 18 12:53:35.901308 2026] [security2:error] [pid 67073:tid 67284] [client 132.196.61.152:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/coffexium.php"] [unique_id "aoR___cmepr5_nHgLbMt6QAAAmM"] [Tue Aug 18 12:53:35.917053 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atinslencoisadventure.tur.br"] [uri "/uploads/admin.php"] [unique_id "aoR__9O5rbWdOArH04J7rQAAATs"] [Tue Aug 18 12:53:35.934531 2026] [security2:error] [pid 67073:tid 67142] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/moon3.php"] [unique_id "aoR___cmepr5_nHgLbMt6gACdUI"] [Tue Aug 18 12:53:36.041366 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/11.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7AAAAjw"] [Tue Aug 18 12:53:36.048652 2026] [security2:error] [pid 67073:tid 67306] [client 20.151.109.219:58334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/47.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7QAAAnk"] [Tue Aug 18 12:53:36.065081 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wso.php"] [unique_id "aoSAAPcmepr5_nHgLbMt7gAAAmI"] [Tue Aug 18 12:53:36.112277 2026] [security2:error] [pid 66623:tid 66792] [client 20.51.153.15:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/payout.php"] [unique_id "aoSAANO5rbWdOArH04J7sAAAASQ"] [Tue Aug 18 12:53:36.123933 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:3154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/admin.php"] [unique_id "aoSAANO5rbWdOArH04J7sQAAAXE"] [Tue Aug 18 12:53:36.157916 2026] [security2:error] [pid 67073:tid 67152] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/opts.php"] [unique_id "aoSAAPcmepr5_nHgLbMt8wACaUw"] [Tue Aug 18 12:53:36.174205 2026] [security2:error] [pid 66623:tid 66847] [client 104.209.144.33:24870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/security.php"] [unique_id "aoSAANO5rbWdOArH04J7tAAAAVs"] [Tue Aug 18 12:53:36.178757 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.136.165:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/c4.php"] [unique_id "aoSAANO5rbWdOArH04J7tQAAAQ0"] [Tue Aug 18 12:53:36.179293 2026] [security2:error] [pid 67073:tid 67252] [client 20.119.58.187:15269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/php8.php"] [unique_id "aoSAAPcmepr5_nHgLbMt9QAAAkM"] [Tue Aug 18 12:53:36.207802 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAAPcmepr5_nHgLbMt9wAAAiI"] [Tue Aug 18 12:53:36.212575 2026] [security2:error] [pid 67073:tid 67274] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAAPcmepr5_nHgLbMt-AAAAlk"] [Tue Aug 18 12:53:36.223617 2026] [security2:error] [pid 66623:tid 66868] [client 5.31.227.224:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7tgAAAXA"] [Tue Aug 18 12:53:36.234229 2026] [security2:error] [pid 66623:tid 66868] [client 5.31.227.224:7854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7tgAAAXA"] [Tue Aug 18 12:53:36.254565 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:8309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/rx.php"] [unique_id "aoSAAPcmepr5_nHgLbMt-gAAAoQ"] [Tue Aug 18 12:53:36.299882 2026] [security2:error] [pid 66623:tid 66892] [client 4.223.164.152:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAANO5rbWdOArH04J7twAAAYg"] [Tue Aug 18 12:53:36.301303 2026] [security2:error] [pid 66623:tid 66825] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7swABRSs"] [Tue Aug 18 12:53:36.314571 2026] [security2:error] [pid 67073:tid 67314] [client 52.87.72.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSAAPcmepr5_nHgLbMt8gACgUY"], referer: https://1td.com.br [Tue Aug 18 12:53:36.322901 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAPcmepr5_nHgLbMt_QAAAkE"] [Tue Aug 18 12:53:36.348120 2026] [security2:error] [pid 66623:tid 66852] [client 20.171.51.14:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mz.php"] [unique_id "aoSAANO5rbWdOArH04J7ugAAAWA"] [Tue Aug 18 12:53:36.350580 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zwq13.php"] [unique_id "aoSAAPcmepr5_nHgLbMt_gACMk8"] [Tue Aug 18 12:53:36.407074 2026] [security2:error] [pid 66623:tid 66870] [client 20.51.153.15:13336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAANO5rbWdOArH04J7uwAAAXI"] [Tue Aug 18 12:53:36.410958 2026] [security2:error] [pid 67073:tid 67226] [client 52.238.210.254:9055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/goods.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBAAAAik"] [Tue Aug 18 12:53:36.430638 2026] [security2:error] [pid 67073:tid 67243] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/ops.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBQAAAjo"] [Tue Aug 18 12:53:36.439156 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:41058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAANO5rbWdOArH04J7vQAAAYQ"] [Tue Aug 18 12:53:36.460971 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/File.php"] [unique_id "aoSAAPcmepr5_nHgLbMuBgAAAok"] [Tue Aug 18 12:53:36.466484 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:3182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/public/css.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCAAAAnI"] [Tue Aug 18 12:53:36.479187 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAANO5rbWdOArH04J7vgAAAR4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:36.518977 2026] [security2:error] [pid 67073:tid 67292] [client 74.249.206.207:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/222.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCQAAAms"] [Tue Aug 18 12:53:36.533715 2026] [security2:error] [pid 67073:tid 67162] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/Okxob.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCgACbFY"] [Tue Aug 18 12:53:36.535457 2026] [security2:error] [pid 66623:tid 66770] [client 20.100.169.31:28382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/i.php"] [unique_id "aoSAANO5rbWdOArH04J7vwAAAQ4"] [Tue Aug 18 12:53:36.537961 2026] [security2:error] [pid 67073:tid 67303] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAAPcmepr5_nHgLbMuCwAAAnY"] [Tue Aug 18 12:53:36.541610 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/php8.php"] [unique_id "aoSAAPcmepr5_nHgLbMuDAAAAh4"] [Tue Aug 18 12:53:36.551820 2026] [security2:error] [pid 67073:tid 67323] [client 20.186.30.159:14240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAAPcmepr5_nHgLbMuDQAAAoo"] [Tue Aug 18 12:53:36.566843 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:32644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAANO5rbWdOArH04J7wAAAAXc"] [Tue Aug 18 12:53:36.574799 2026] [security2:error] [pid 67073:tid 67324] [client 52.238.210.254:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/p.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEAAAAos"] [Tue Aug 18 12:53:36.575123 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/mandrill.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEQAAAiA"] [Tue Aug 18 12:53:36.580505 2026] [security2:error] [pid 67073:tid 67269] [client 172.202.39.151:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/tes.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEgAAAlQ"] [Tue Aug 18 12:53:36.596355 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.136.165:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/an7.php"] [unique_id "aoSAAPcmepr5_nHgLbMuEwAAAoU"] [Tue Aug 18 12:53:36.694693 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:13411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/oauth.php"] [unique_id "aoSAAPcmepr5_nHgLbMuFgAAAiE"] [Tue Aug 18 12:53:36.754482 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.61.152:56093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/dex.php"] [unique_id "aoSAANO5rbWdOArH04J7wwAAAUE"] [Tue Aug 18 12:53:36.788513 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/file59.php"] [unique_id "aoSAAPcmepr5_nHgLbMuGgACkFo"] [Tue Aug 18 12:53:36.794780 2026] [security2:error] [pid 66623:tid 66816] [client 20.163.43.14:3164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAANO5rbWdOArH04J7xQAAATw"] [Tue Aug 18 12:53:36.795837 2026] [security2:error] [pid 67073:tid 67267] [client 45.131.195.188:29631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-login.php"] [unique_id "aoSAAPcmepr5_nHgLbMuFAAAAlI"] [Tue Aug 18 12:53:36.801397 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ft.php"] [unique_id "aoSAANO5rbWdOArH04J7xgAAAUY"] [Tue Aug 18 12:53:36.815399 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAAPcmepr5_nHgLbMuGwAAAlM"] [Tue Aug 18 12:53:36.861178 2026] [security2:error] [pid 67073:tid 67210] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAAPcmepr5_nHgLbMuHwAAAhk"] [Tue Aug 18 12:53:36.875053 2026] [security2:error] [pid 66623:tid 66840] [client 4.223.164.152:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/media.php"] [unique_id "aoSAANO5rbWdOArH04J7xwAAAVQ"] [Tue Aug 18 12:53:36.886319 2026] [security2:error] [pid 66623:tid 66849] [client 104.209.144.33:25326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAANO5rbWdOArH04J7yAAAAV0"] [Tue Aug 18 12:53:36.904883 2026] [security2:error] [pid 66623:tid 66878] [client 20.48.236.86:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ws13.php"] [unique_id "aoSAANO5rbWdOArH04J7yQAAAXo"] [Tue Aug 18 12:53:36.914160 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/fi22.php"] [unique_id "aoSAAPcmepr5_nHgLbMuIAAAAl8"] [Tue Aug 18 12:53:36.919506 2026] [security2:error] [pid 66623:tid 66811] [client 20.119.58.187:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/images/php8.php"] [unique_id "aoSAANO5rbWdOArH04J7ygAAATc"] [Tue Aug 18 12:53:36.966095 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/timeclock.php"] [unique_id "aoSAAPcmepr5_nHgLbMuJgAAAio"] [Tue Aug 18 12:53:36.966605 2026] [security2:error] [pid 66623:tid 66780] [client 103.184.169.37:41112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7ywAAARg"] [Tue Aug 18 12:53:36.966705 2026] [security2:error] [pid 66623:tid 66780] [client 103.184.169.37:41112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAANO5rbWdOArH04J7ywAAARg"] [Tue Aug 18 12:53:36.970099 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAAPcmepr5_nHgLbMuJwAAAis"] [Tue Aug 18 12:53:36.972941 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.75.187:33017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-act.php"] [unique_id "aoSAAPcmepr5_nHgLbMuKAAAAlE"] [Tue Aug 18 12:53:36.994173 2026] [security2:error] [pid 67073:tid 67265] [client 20.151.109.219:28737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/payout.php"] [unique_id "aoSAAPcmepr5_nHgLbMuKQAAAlA"] [Tue Aug 18 12:53:37.014486 2026] [security2:error] [pid 67073:tid 67275] [client 74.248.136.165:40845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAAfcmepr5_nHgLbMuKwAAAlo"] [Tue Aug 18 12:53:37.054606 2026] [security2:error] [pid 66623:tid 66776] [client 52.173.121.69:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAAdO5rbWdOArH04J7zgAAARQ"] [Tue Aug 18 12:53:37.057875 2026] [security2:error] [pid 66623:tid 66855] [client 20.91.215.254:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAAdO5rbWdOArH04J7zwAAAWM"] [Tue Aug 18 12:53:37.061529 2026] [security2:error] [pid 67073:tid 67270] [client 20.186.30.159:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/media.php"] [unique_id "aoSAAfcmepr5_nHgLbMuLgAAAlU"] [Tue Aug 18 12:53:37.091499 2026] [security2:error] [pid 67073:tid 67315] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/coffexium.php"] [unique_id "aoSAAfcmepr5_nHgLbMuLwAAAoI"] [Tue Aug 18 12:53:37.118672 2026] [security2:error] [pid 66623:tid 66839] [client 74.249.206.207:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/key.php"] [unique_id "aoSAAdO5rbWdOArH04J70AAAAVM"] [Tue Aug 18 12:53:37.164779 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAAfcmepr5_nHgLbMuMgAAAns"] [Tue Aug 18 12:53:37.194726 2026] [security2:error] [pid 67073:tid 67304] [client 104.209.144.33:24856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAAfcmepr5_nHgLbMuNgAAAnc"] [Tue Aug 18 12:53:37.199373 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.172.148:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAAfcmepr5_nHgLbMuNwAAAmI"] [Tue Aug 18 12:53:37.214155 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/email.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOAAAAjE"] [Tue Aug 18 12:53:37.219389 2026] [security2:error] [pid 67073:tid 67238] [client 138.36.100.162:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOQAAAjU"] [Tue Aug 18 12:53:37.219471 2026] [security2:error] [pid 67073:tid 67238] [client 138.36.100.162:41929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOQAAAjU"] [Tue Aug 18 12:53:37.235673 2026] [security2:error] [pid 67073:tid 67192] [remote 162.214.205.212:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSAAfcmepr5_nHgLbMuOwACO3Q"] [Tue Aug 18 12:53:37.236277 2026] [security2:error] [pid 66623:tid 66795] [client 20.42.19.40:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/100.php"] [unique_id "aoSAAdO5rbWdOArH04J70QAAASc"] [Tue Aug 18 12:53:37.251332 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.56.190:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/main.php"] [unique_id "aoSAAdO5rbWdOArH04J70gAAAVc"] [Tue Aug 18 12:53:37.274785 2026] [security2:error] [pid 66623:tid 66829] [client 45.8.19.134:24591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baccovaledosvinhedos.com.br"] [uri "/wp-login.php"] [unique_id "aoSAAdO5rbWdOArH04J71AAAAUk"] [Tue Aug 18 12:53:37.281835 2026] [security2:error] [pid 67073:tid 67290] [client 52.238.210.254:12544] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp-admin"] [unique_id "aoSAAfcmepr5_nHgLbMuPQAAAmk"] [Tue Aug 18 12:53:37.283701 2026] [security2:error] [pid 66623:tid 66777] [client 20.171.51.14:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fg.php"] [unique_id "aoSAAdO5rbWdOArH04J71QAAARU"] [Tue Aug 18 12:53:37.292842 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/h.php"] [unique_id "aoSAAfcmepr5_nHgLbMuPgAAAkM"] [Tue Aug 18 12:53:37.295500 2026] [security2:error] [pid 67073:tid 67309] [client 20.119.58.187:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/blogs.dir/php8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuQAAAAnw"] [Tue Aug 18 12:53:37.296058 2026] [security2:error] [pid 67073:tid 67219] [client 52.238.210.254:8901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuQQAAAiI"] [Tue Aug 18 12:53:37.325708 2026] [security2:error] [pid 67073:tid 67317] [client 20.186.30.159:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRAAAAoQ"] [Tue Aug 18 12:53:37.337846 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.18.37:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/vx.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRQAAAn0"] [Tue Aug 18 12:53:37.358491 2026] [security2:error] [pid 67073:tid 67296] [client 4.223.164.152:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRgAAAm8"] [Tue Aug 18 12:53:37.363321 2026] [security2:error] [pid 67073:tid 67222] [client 172.202.39.151:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/files/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuRwAAAiU"] [Tue Aug 18 12:53:37.432687 2026] [security2:error] [pid 67073:tid 67312] [client 4.223.164.152:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/inso.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSQAAAn8"] [Tue Aug 18 12:53:37.433133 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.136.165:49506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/byp8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSgAAAkE"] [Tue Aug 18 12:53:37.446235 2026] [security2:error] [pid 67073:tid 67291] [client 4.232.151.198:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSAAfcmepr5_nHgLbMuSwAAAmo"] [Tue Aug 18 12:53:37.452137 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/profile.php"] [unique_id "aoSAAfcmepr5_nHgLbMuTAAAAiY"] [Tue Aug 18 12:53:37.456808 2026] [security2:error] [pid 67073:tid 67298] [client 20.163.43.14:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAAfcmepr5_nHgLbMuTQAAAnE"] [Tue Aug 18 12:53:37.462847 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:56121] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.riosafe.com.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUAAAAhw"] [Tue Aug 18 12:53:37.462928 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.61.152:56121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUAAAAhw"] [Tue Aug 18 12:53:37.482707 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUQAAAiM"] [Tue Aug 18 12:53:37.489369 2026] [security2:error] [pid 67073:tid 67211] [client 213.35.127.232:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuUgAAAho"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:37.561360 2026] [security2:error] [pid 67073:tid 67323] [client 20.151.109.219:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/bh.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVAAAAoo"] [Tue Aug 18 12:53:37.570774 2026] [security2:error] [pid 67073:tid 67217] [client 20.186.30.159:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/mac.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVQAAAiA"] [Tue Aug 18 12:53:37.651455 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:15257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/images/php8.php"] [unique_id "aoSAAfcmepr5_nHgLbMuVwAAAh4"] [Tue Aug 18 12:53:37.695474 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWAAAAok"] [Tue Aug 18 12:53:37.702379 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/eauu.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWgACVwQ"] [Tue Aug 18 12:53:37.708172 2026] [security2:error] [pid 67073:tid 67271] [client 158.23.17.4:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/rx.php"] [unique_id "aoSAAfcmepr5_nHgLbMuWwAAAlY"] [Tue Aug 18 12:53:37.753737 2026] [security2:error] [pid 67073:tid 67329] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAAfcmepr5_nHgLbMuXQAAApA"] [Tue Aug 18 12:53:37.757784 2026] [security2:error] [pid 67073:tid 67267] [client 104.209.144.33:25338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAAfcmepr5_nHgLbMuXgAAAlI"] [Tue Aug 18 12:53:37.774471 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.100.201:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/spadex.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYAAAAk8"] [Tue Aug 18 12:53:37.778897 2026] [security2:error] [pid 67073:tid 67240] [client 20.51.153.15:13362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/summary.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYQAAAjc"] [Tue Aug 18 12:53:37.786041 2026] [security2:error] [pid 67073:tid 67214] [client 52.238.210.254:10199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aaa.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYgAAAh0"] [Tue Aug 18 12:53:37.786099 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:64656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAAfcmepr5_nHgLbMuYwAAAmA"] [Tue Aug 18 12:53:37.791067 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ve.php"] [unique_id "aoSAAfcmepr5_nHgLbMuZQAAAog"] [Tue Aug 18 12:53:37.804419 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:27775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAfcmepr5_nHgLbMuZwAAAlE"] [Tue Aug 18 12:53:37.814708 2026] [security2:error] [pid 67073:tid 67285] [client 20.171.51.14:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/40.php"] [unique_id "aoSAAfcmepr5_nHgLbMuaQAAAmQ"] [Tue Aug 18 12:53:37.820774 2026] [security2:error] [pid 67073:tid 67313] [client 114.119.153.50:51549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mhost.com.br"] [uri "/teste-vimeo"] [unique_id "aoSAAfcmepr5_nHgLbMuagAAAoA"], referer: https://mhost.com.br/3457-dpt99476-aplicativos-de-paquera-gratuito.html [Tue Aug 18 12:53:37.837999 2026] [security2:error] [pid 67073:tid 67265] [client 20.186.30.159:14330] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "residencial.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMubAAAAlA"] [Tue Aug 18 12:53:37.838109 2026] [security2:error] [pid 67073:tid 67265] [client 20.186.30.159:14330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAAfcmepr5_nHgLbMubAAAAlA"] [Tue Aug 18 12:53:37.838451 2026] [security2:error] [pid 67073:tid 67325] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAAfcmepr5_nHgLbMubQAAAow"] [Tue Aug 18 12:53:37.850155 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/plugins.php"] [unique_id "aoSAAfcmepr5_nHgLbMubgAAAi0"] [Tue Aug 18 12:53:37.858131 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:40455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ga.php"] [unique_id "aoSAAfcmepr5_nHgLbMubwAAAm0"] [Tue Aug 18 12:53:37.864920 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gelay.php"] [unique_id "aoSAAdO5rbWdOArH04J72AAAARE"] [Tue Aug 18 12:53:37.901133 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:37.901510 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:37.922906 2026] [security2:error] [pid 67073:tid 67273] [client 157.20.138.62:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMucgAAAlg"] [Tue Aug 18 12:53:37.923044 2026] [security2:error] [pid 67073:tid 67273] [client 157.20.138.62:51204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAAfcmepr5_nHgLbMucgAAAlg"] [Tue Aug 18 12:53:37.942269 2026] [security2:error] [pid 67073:tid 67076] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/dsd.php"] [unique_id "aoSAAfcmepr5_nHgLbMucwACRwA"] [Tue Aug 18 12:53:38.007904 2026] [security2:error] [pid 67073:tid 67315] [client 20.119.58.187:15359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMudgAAAoI"] [Tue Aug 18 12:53:38.030364 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.56.190:10591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/wb.php"] [unique_id "aoSAAvcmepr5_nHgLbMudwAAAkA"] [Tue Aug 18 12:53:38.037504 2026] [security2:error] [pid 67073:tid 67262] [client 74.249.206.207:58563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/chosen.php"] [unique_id "aoSAAvcmepr5_nHgLbMueAAAAk0"] [Tue Aug 18 12:53:38.047367 2026] [security2:error] [pid 67073:tid 67307] [client 4.223.164.152:6637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/shiny.php"] [unique_id "aoSAAvcmepr5_nHgLbMueQAAAno"] [Tue Aug 18 12:53:38.052897 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/conf.php"] [unique_id "aoSAAvcmepr5_nHgLbMuewAAAmk"] [Tue Aug 18 12:53:38.070169 2026] [security2:error] [pid 67073:tid 67089] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMufgACIg0"] [Tue Aug 18 12:53:38.071377 2026] [security2:error] [pid 67073:tid 67195] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/config/.env.php"] [unique_id "aoSAAvcmepr5_nHgLbMufQACInc"] [Tue Aug 18 12:53:38.083651 2026] [security2:error] [pid 67073:tid 67295] [client 20.186.30.159:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/coffee.php"] [unique_id "aoSAAvcmepr5_nHgLbMugQAAAm4"] [Tue Aug 18 12:53:38.155979 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/c4.php"] [unique_id "aoSAAvcmepr5_nHgLbMuhgACSRA"] [Tue Aug 18 12:53:38.161460 2026] [security2:error] [pid 67073:tid 67259] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAAvcmepr5_nHgLbMuhwAAAko"] [Tue Aug 18 12:53:38.199358 2026] [security2:error] [pid 67073:tid 67291] [client 20.163.43.14:3196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAAvcmepr5_nHgLbMujQAAAmo"] [Tue Aug 18 12:53:38.203439 2026] [security2:error] [pid 67073:tid 67226] [client 4.223.164.152:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAAvcmepr5_nHgLbMujwAAAik"] [Tue Aug 18 12:53:38.206488 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAAvcmepr5_nHgLbMukAAAAhw"] [Tue Aug 18 12:53:38.221181 2026] [security2:error] [pid 67073:tid 67234] [client 5.253.205.188:46740] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/files.bak"] [unique_id "aoSAAvcmepr5_nHgLbMukQAAAjE"], referer: https://medihub.com.br/files.bak [Tue Aug 18 12:53:38.273182 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.136.165:19256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/100.kb.php"] [unique_id "aoSAAvcmepr5_nHgLbMukgAAAho"] [Tue Aug 18 12:53:38.280611 2026] [security2:error] [pid 67073:tid 67292] [client 104.209.144.33:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMukwAAAms"] [Tue Aug 18 12:53:38.302936 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:43366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ee.php"] [unique_id "aoSAAvcmepr5_nHgLbMulQAAAnY"] [Tue Aug 18 12:53:38.305125 2026] [security2:error] [pid 66623:tid 66841] [client 135.225.75.187:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/grsiuk.php"] [unique_id "aoSAAtO5rbWdOArH04J73AAAAVU"] [Tue Aug 18 12:53:38.325637 2026] [security2:error] [pid 67073:tid 67320] [client 20.186.30.159:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/classwithtostring.php"] [unique_id "aoSAAvcmepr5_nHgLbMulgAAAoc"] [Tue Aug 18 12:53:38.335716 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/xn.php"] [unique_id "aoSAAvcmepr5_nHgLbMulwAAAiA"] [Tue Aug 18 12:53:38.335894 2026] [security2:error] [pid 67073:tid 67324] [client 20.51.153.15:13348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/bala.php"] [unique_id "aoSAAvcmepr5_nHgLbMumAAAAos"] [Tue Aug 18 12:53:38.361319 2026] [security2:error] [pid 66623:tid 66775] [client 172.202.39.151:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAAtO5rbWdOArH04J73QAAARM"] [Tue Aug 18 12:53:38.370830 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.98.162:16631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAAvcmepr5_nHgLbMumQAAAoU"] [Tue Aug 18 12:53:38.372091 2026] [security2:error] [pid 67073:tid 67220] [client 20.119.58.187:14428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cgi-bin/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMumgAAAiM"] [Tue Aug 18 12:53:38.374803 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.100.201:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMumwAAAkU"] [Tue Aug 18 12:53:38.375738 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/www.php"] [unique_id "aoSAAvcmepr5_nHgLbMunAAAAjM"] [Tue Aug 18 12:53:38.387926 2026] [security2:error] [pid 67073:tid 67086] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/an7.php"] [unique_id "aoSAAvcmepr5_nHgLbMunQACLAo"] [Tue Aug 18 12:53:38.393380 2026] [security2:error] [pid 66623:tid 66857] [client 20.100.169.31:12667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/zup.php73"] [unique_id "aoSAAtO5rbWdOArH04J73gAAAWU"] [Tue Aug 18 12:53:38.398488 2026] [security2:error] [pid 67073:tid 67167] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/config.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMunwACXFs"] [Tue Aug 18 12:53:38.422308 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/brc.php"] [unique_id "aoSAAvcmepr5_nHgLbMuoAAAAkQ"] [Tue Aug 18 12:53:38.434761 2026] [security2:error] [pid 67073:tid 67322] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/sf.php"] [unique_id "aoSAAvcmepr5_nHgLbMuoQAAAok"] [Tue Aug 18 12:53:38.439342 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.56.190:2512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAAvcmepr5_nHgLbMuogAAAoM"] [Tue Aug 18 12:53:38.466223 2026] [security2:error] [pid 67073:tid 67267] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAAvcmepr5_nHgLbMuowAAAlI"] [Tue Aug 18 12:53:38.478211 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/47.php"] [unique_id "aoSAAvcmepr5_nHgLbMupgAAAhs"] [Tue Aug 18 12:53:38.490731 2026] [security2:error] [pid 67073:tid 67240] [client 52.238.210.254:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/term.php"] [unique_id "aoSAAvcmepr5_nHgLbMupwAAAjc"] [Tue Aug 18 12:53:38.501378 2026] [security2:error] [pid 67073:tid 67091] [remote 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.atekrefrigeracao.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAAvcmepr5_nHgLbMuqAACNA8"] [Tue Aug 18 12:53:38.505108 2026] [security2:error] [pid 67073:tid 67280] [client 132.196.61.152:55349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/coffee.php"] [unique_id "aoSAAvcmepr5_nHgLbMuqgAAAl8"] [Tue Aug 18 12:53:38.506843 2026] [security2:error] [pid 67073:tid 67314] [client 213.35.127.232:53823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAAvcmepr5_nHgLbMuqwAAAoE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:38.519655 2026] [security2:error] [pid 66623:tid 66824] [client 40.85.222.29:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAAtO5rbWdOArH04J73wAAAUQ"] [Tue Aug 18 12:53:38.526390 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAAvcmepr5_nHgLbMurQAAAmQ"] [Tue Aug 18 12:53:38.551390 2026] [security2:error] [pid 67073:tid 67224] [client 20.91.215.254:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAAvcmepr5_nHgLbMurgAAAic"] [Tue Aug 18 12:53:38.563506 2026] [security2:error] [pid 66623:tid 66832] [client 104.209.144.33:15681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAAtO5rbWdOArH04J74AAAAUw"] [Tue Aug 18 12:53:38.573596 2026] [security2:error] [pid 67073:tid 67325] [client 20.186.30.159:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/wp-ws68.php"] [unique_id "aoSAAvcmepr5_nHgLbMusAAAAow"] [Tue Aug 18 12:53:38.587405 2026] [security2:error] [pid 67073:tid 67326] [client 20.51.153.15:13391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/222.php"] [unique_id "aoSAAvcmepr5_nHgLbMusgAAAo0"] [Tue Aug 18 12:53:38.599233 2026] [security2:error] [pid 67073:tid 67176] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAAvcmepr5_nHgLbMuswACKGQ"] [Tue Aug 18 12:53:38.605158 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:10807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/btx25.php"] [unique_id "aoSAAtO5rbWdOArH04J74QAAAT8"] [Tue Aug 18 12:53:38.621982 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAAvcmepr5_nHgLbMutAAAAmg"] [Tue Aug 18 12:53:38.630501 2026] [security2:error] [pid 67073:tid 67305] [client 4.223.164.152:37303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSAAvcmepr5_nHgLbMutQAAAng"] [Tue Aug 18 12:53:38.695078 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.136.165:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mamzi.php"] [unique_id "aoSAAvcmepr5_nHgLbMuuAAAAns"] [Tue Aug 18 12:53:38.726047 2026] [security2:error] [pid 67073:tid 67207] [client 20.119.58.187:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/gallery/php8.php"] [unique_id "aoSAAvcmepr5_nHgLbMuuQAAAhY"] [Tue Aug 18 12:53:38.727842 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.18.37:14656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wap.php"] [unique_id "aoSAAvcmepr5_nHgLbMuugAAAjU"] [Tue Aug 18 12:53:38.777091 2026] [security2:error] [pid 67073:tid 67309] [client 20.171.51.14:29227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ak.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwAAAAnw"] [Tue Aug 18 12:53:38.784928 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/byp8.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwQACWxw"] [Tue Aug 18 12:53:38.823221 2026] [authz_core:error] [pid 67073:tid 67306] [client 192.178.4.133:35836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:38.823499 2026] [authz_core:error] [pid 67073:tid 67306] [client 192.178.4.133:35836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:38.825999 2026] [security2:error] [pid 67073:tid 67260] [client 20.186.30.159:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/yj09.php"] [unique_id "aoSAAvcmepr5_nHgLbMuwwAAAks"] [Tue Aug 18 12:53:38.860340 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:54459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAAtO5rbWdOArH04J74gAAAXM"] [Tue Aug 18 12:53:38.887741 2026] [security2:error] [pid 66623:tid 66858] [client 4.223.164.152:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/403dd.php"] [unique_id "aoSAAtO5rbWdOArH04J74wAAAWY"] [Tue Aug 18 12:53:38.908281 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:13399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/routes.php"] [unique_id "aoSAAvcmepr5_nHgLbMuyAAAAis"] [Tue Aug 18 12:53:38.938686 2026] [security2:error] [pid 67073:tid 67235] [client 172.202.39.151:44457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAAvcmepr5_nHgLbMuywAAAjI"] [Tue Aug 18 12:53:38.947930 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/srontol.php"] [unique_id "aoSAAvcmepr5_nHgLbMuzAAAAl4"] [Tue Aug 18 12:53:38.988537 2026] [security2:error] [pid 67073:tid 67108] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/plugins.php"] [unique_id "aoSAAvcmepr5_nHgLbMuzgACJCA"] [Tue Aug 18 12:53:39.010797 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAA9O5rbWdOArH04J75AAAAXQ"] [Tue Aug 18 12:53:39.059182 2026] [security2:error] [pid 67073:tid 67257] [client 104.209.144.33:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAA_cmepr5_nHgLbMu0gAAAkg"] [Tue Aug 18 12:53:39.060101 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSAA9O5rbWdOArH04J75QAAATA"] [Tue Aug 18 12:53:39.066849 2026] [security2:error] [pid 67073:tid 67323] [client 20.186.30.159:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/scxy.php"] [unique_id "aoSAA_cmepr5_nHgLbMu0wAAAoo"] [Tue Aug 18 12:53:39.072995 2026] [security2:error] [pid 67073:tid 67311] [client 74.249.206.207:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/thoms.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1AAAAn4"] [Tue Aug 18 12:53:39.082910 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:14648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/blocks/php8.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1QAAAik"] [Tue Aug 18 12:53:39.084758 2026] [security2:error] [pid 67073:tid 67320] [client 52.238.210.254:10237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/7.php"] [unique_id "aoSAA_cmepr5_nHgLbMu1gAAAoc"] [Tue Aug 18 12:53:39.101697 2026] [security2:error] [pid 67073:tid 67232] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/k.php"] [unique_id "aoSAA_cmepr5_nHgLbMu2AAAAi8"] [Tue Aug 18 12:53:39.103465 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:39.103747 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:39.106380 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:23760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAA_cmepr5_nHgLbMu2QAAAkU"] [Tue Aug 18 12:53:39.112444 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.136.165:52053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms.php"] [unique_id "aoSAA9O5rbWdOArH04J75gAAATo"] [Tue Aug 18 12:53:39.170944 2026] [security2:error] [pid 67073:tid 67229] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3AAAAiw"] [Tue Aug 18 12:53:39.173187 2026] [security2:error] [pid 67073:tid 67110] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/100.kb.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3QACXCI"] [Tue Aug 18 12:53:39.179925 2026] [security2:error] [pid 67073:tid 67315] [client 149.34.210.141:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3gAAAoI"] [Tue Aug 18 12:53:39.181972 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3wAAAh4"] [Tue Aug 18 12:53:39.203510 2026] [security2:error] [pid 67073:tid 67243] [client 20.91.215.254:20214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/st.php"] [unique_id "aoSAA_cmepr5_nHgLbMu4AAAAjo"] [Tue Aug 18 12:53:39.261399 2026] [security2:error] [pid 66623:tid 66860] [client 20.250.13.23:31436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/goods.php"] [unique_id "aoSAA9O5rbWdOArH04J75wAAAWg"] [Tue Aug 18 12:53:39.279138 2026] [security2:error] [pid 67073:tid 67329] [client 20.51.153.15:13424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/php5.php"] [unique_id "aoSAA_cmepr5_nHgLbMu4wAAApA"] [Tue Aug 18 12:53:39.310138 2026] [security2:error] [pid 67073:tid 67267] [client 158.23.17.4:11789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/mandrill.php"] [unique_id "aoSAA_cmepr5_nHgLbMu5AAAAlI"] [Tue Aug 18 12:53:39.318372 2026] [security2:error] [pid 67073:tid 67261] [client 20.151.109.219:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/ct.php"] [unique_id "aoSAA_cmepr5_nHgLbMu5gAAAkw"] [Tue Aug 18 12:53:39.319927 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ia.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6AAAAk8"] [Tue Aug 18 12:53:39.331473 2026] [security2:error] [pid 67073:tid 67212] [client 20.186.30.159:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6QAAAhs"] [Tue Aug 18 12:53:39.341215 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:16749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/test_info.php"] [unique_id "aoSAA_cmepr5_nHgLbMu6wAAAhk"] [Tue Aug 18 12:53:39.390490 2026] [security2:error] [pid 67073:tid 67178] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mamzi.php"] [unique_id "aoSAA_cmepr5_nHgLbMu7QACX2Y"] [Tue Aug 18 12:53:39.392159 2026] [security2:error] [pid 67073:tid 67314] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAA_cmepr5_nHgLbMu7gAAAoE"] [Tue Aug 18 12:53:39.398168 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.56.190:31653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/st.php"] [unique_id "aoSAA_cmepr5_nHgLbMu8AAAAlE"] [Tue Aug 18 12:53:39.445793 2026] [security2:error] [pid 67073:tid 67315] [client 149.34.210.141:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAA_cmepr5_nHgLbMu3gAAAoI"] [Tue Aug 18 12:53:39.460567 2026] [security2:error] [pid 66623:tid 66873] [client 20.91.215.254:16686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAA9O5rbWdOArH04J76QAAAXU"] [Tue Aug 18 12:53:39.466026 2026] [authz_core:error] [pid 67073:tid 67119] [remote 57.141.22.100:38094] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:39.466320 2026] [authz_core:error] [pid 67073:tid 67119] [remote 57.141.22.100:38094] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:39.482714 2026] [security2:error] [pid 66623:tid 66868] [client 172.202.39.151:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAA9O5rbWdOArH04J76gAAAXA"] [Tue Aug 18 12:53:39.489328 2026] [security2:error] [pid 67073:tid 67270] [client 4.223.164.152:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAA_cmepr5_nHgLbMu9wAAAlU"] [Tue Aug 18 12:53:39.499457 2026] [security2:error] [pid 67073:tid 67252] [client 4.232.151.198:39365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/a.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-AAAAkM"] [Tue Aug 18 12:53:39.515897 2026] [security2:error] [pid 67073:tid 67326] [client 20.163.43.14:3160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/about.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-gAAAo0"] [Tue Aug 18 12:53:39.521501 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:54040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAA_cmepr5_nHgLbMu-wAAAiE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:39.531377 2026] [security2:error] [pid 67073:tid 67302] [client 74.248.136.165:17242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gfile.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_AAAAnU"] [Tue Aug 18 12:53:39.539932 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:13416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/Black.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_QAAAlg"] [Tue Aug 18 12:53:39.564384 2026] [security2:error] [pid 66623:tid 66778] [client 4.223.164.152:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/baba.php"] [unique_id "aoSAA9O5rbWdOArH04J76wAAARY"] [Tue Aug 18 12:53:39.565793 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:37736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_gAAAkc"] [Tue Aug 18 12:53:39.572029 2026] [security2:error] [pid 67073:tid 67241] [client 20.186.30.159:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAA_cmepr5_nHgLbMu_wAAAjg"] [Tue Aug 18 12:53:39.581262 2026] [security2:error] [pid 66623:tid 66790] [client 135.225.75.187:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/h.php"] [unique_id "aoSAA9O5rbWdOArH04J77AAAASI"] [Tue Aug 18 12:53:39.586158 2026] [security2:error] [pid 66623:tid 66892] [client 52.238.210.254:10175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file5.php"] [unique_id "aoSAA9O5rbWdOArH04J77QAAAYg"] [Tue Aug 18 12:53:39.615808 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:21143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/payout.php"] [unique_id "aoSAA_cmepr5_nHgLbMvAgAAAjs"] [Tue Aug 18 12:53:39.664463 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.6.191:6539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAA_cmepr5_nHgLbMvBAAAAhU"] [Tue Aug 18 12:53:39.708236 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.61.152:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAA_cmepr5_nHgLbMvBgAAAkA"] [Tue Aug 18 12:53:39.739935 2026] [security2:error] [pid 66623:tid 66852] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAA9O5rbWdOArH04J77wAAAWA"] [Tue Aug 18 12:53:39.763422 2026] [security2:error] [pid 66623:tid 66861] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/82.php"] [unique_id "aoSAA9O5rbWdOArH04J78AAAAWk"] [Tue Aug 18 12:53:39.834396 2026] [security2:error] [pid 67073:tid 67219] [client 20.186.30.159:14319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/blurbs.php"] [unique_id "aoSAA_cmepr5_nHgLbMvCgAAAiI"] [Tue Aug 18 12:53:39.838972 2026] [security2:error] [pid 66623:tid 66781] [client 20.100.169.31:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAA9O5rbWdOArH04J78QAAARk"] [Tue Aug 18 12:53:39.840231 2026] [security2:error] [pid 67073:tid 67248] [client 20.171.51.14:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kn.php"] [unique_id "aoSAA_cmepr5_nHgLbMvCwAAAj8"] [Tue Aug 18 12:53:39.843801 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAA9O5rbWdOArH04J78gAAAUU"] [Tue Aug 18 12:53:39.859825 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDAAAAm4"] [Tue Aug 18 12:53:39.862108 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:13371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/filesystems.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDQAAApE"] [Tue Aug 18 12:53:39.878303 2026] [security2:error] [pid 67073:tid 67310] [client 20.171.51.14:45409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/14.php"] [unique_id "aoSAA_cmepr5_nHgLbMvDgAAAn0"] [Tue Aug 18 12:53:39.919740 2026] [security2:error] [pid 67073:tid 67319] [client 4.223.164.152:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/media.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEAAAAoY"] [Tue Aug 18 12:53:39.937872 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/file5.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEQAAAjI"] [Tue Aug 18 12:53:39.957645 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.136.165:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEgAAAmo"] [Tue Aug 18 12:53:39.959358 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAA_cmepr5_nHgLbMvEwAAAl4"] [Tue Aug 18 12:53:40.016555 2026] [security2:error] [pid 66623:tid 66799] [client 52.238.210.254:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/makeasmtp.php"] [unique_id "aoSABNO5rbWdOArH04J78wAAASs"] [Tue Aug 18 12:53:40.085326 2026] [security2:error] [pid 67073:tid 67293] [client 20.186.30.159:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/bajah.php"] [unique_id "aoSABPcmepr5_nHgLbMvGgAAAmw"] [Tue Aug 18 12:53:40.086785 2026] [security2:error] [pid 66623:tid 66791] [client 74.249.206.207:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/wpxml.php"] [unique_id "aoSABNO5rbWdOArH04J79AAAASM"] [Tue Aug 18 12:53:40.146442 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.56.190:23753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/le.php"] [unique_id "aoSABPcmepr5_nHgLbMvHAAAAik"] [Tue Aug 18 12:53:40.148369 2026] [security2:error] [pid 66623:tid 66870] [client 20.91.215.254:20225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/past1.php"] [unique_id "aoSABNO5rbWdOArH04J79QAAAXI"] [Tue Aug 18 12:53:40.165254 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.56.190:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bh.php"] [unique_id "aoSABNO5rbWdOArH04J79gAAAS8"] [Tue Aug 18 12:53:40.180058 2026] [security2:error] [pid 67073:tid 67269] [client 20.51.153.15:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSABPcmepr5_nHgLbMvHwAAAlQ"] [Tue Aug 18 12:53:40.206949 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.13.23:53033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/file.php"] [unique_id "aoSABPcmepr5_nHgLbMvIAAAAmk"] [Tue Aug 18 12:53:40.231800 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:3140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/f35.php"] [unique_id "aoSABPcmepr5_nHgLbMvIQAAAjM"] [Tue Aug 18 12:53:40.235374 2026] [security2:error] [pid 66623:tid 66821] [client 172.202.39.151:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/rip.php"] [unique_id "aoSABNO5rbWdOArH04J79wAAAUE"] [Tue Aug 18 12:53:40.249033 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:2720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/akc.php"] [unique_id "aoSABPcmepr5_nHgLbMvIgAAAmU"] [Tue Aug 18 12:53:40.261312 2026] [security2:error] [pid 67073:tid 67277] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSABPcmepr5_nHgLbMvJAAAAlw"] [Tue Aug 18 12:53:40.303568 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:40.303839 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:40.324631 2026] [security2:error] [pid 67073:tid 67300] [client 20.171.51.14:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tk.php"] [unique_id "aoSABPcmepr5_nHgLbMvJgAAAnM"] [Tue Aug 18 12:53:40.326652 2026] [security2:error] [pid 67073:tid 67243] [client 20.186.30.159:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/domvf.php"] [unique_id "aoSABPcmepr5_nHgLbMvJwAAAjo"] [Tue Aug 18 12:53:40.342157 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.56.190:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/ct.php"] [unique_id "aoSABPcmepr5_nHgLbMvKAAAAhg"] [Tue Aug 18 12:53:40.375311 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.136.165:19208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/cu.php"] [unique_id "aoSABNO5rbWdOArH04J7-QAAAVo"] [Tue Aug 18 12:53:40.386393 2026] [security2:error] [pid 66623:tid 66812] [client 4.223.164.152:46197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/inso.php"] [unique_id "aoSABNO5rbWdOArH04J7-gAAATg"] [Tue Aug 18 12:53:40.400480 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.136.165:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/file52.php"] [unique_id "aoSABPcmepr5_nHgLbMvLgAAAk8"] [Tue Aug 18 12:53:40.417882 2026] [security2:error] [pid 66623:tid 66849] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/dex.php"] [unique_id "aoSABNO5rbWdOArH04J7-wAAAV0"] [Tue Aug 18 12:53:40.429091 2026] [security2:error] [pid 67073:tid 67263] [client 160.120.140.123:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvLwAAAk4"] [Tue Aug 18 12:53:40.429205 2026] [security2:error] [pid 67073:tid 67263] [client 160.120.140.123:52776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvLwAAAk4"] [Tue Aug 18 12:53:40.435126 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSABNO5rbWdOArH04J7_AAAAXo"] [Tue Aug 18 12:53:40.437399 2026] [security2:error] [pid 66623:tid 66856] [client 178.153.171.161:11196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABNO5rbWdOArH04J7_QAAAWQ"] [Tue Aug 18 12:53:40.437476 2026] [security2:error] [pid 66623:tid 66856] [client 178.153.171.161:11196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABNO5rbWdOArH04J7_QAAAWQ"] [Tue Aug 18 12:53:40.478161 2026] [security2:error] [pid 66623:tid 66794] [client 20.91.215.254:9136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-configs.php"] [unique_id "aoSABNO5rbWdOArH04J7_gAAASY"] [Tue Aug 18 12:53:40.483961 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wm.php"] [unique_id "aoSABPcmepr5_nHgLbMvMQAAAog"] [Tue Aug 18 12:53:40.485231 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.6.191:6536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSABNO5rbWdOArH04J7_wAAAX4"] [Tue Aug 18 12:53:40.507744 2026] [security2:error] [pid 66623:tid 66780] [client 20.51.153.15:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpstatus.php"] [unique_id "aoSABNO5rbWdOArH04J8AAAAARg"] [Tue Aug 18 12:53:40.523189 2026] [security2:error] [pid 67073:tid 67238] [client 157.51.166.53:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvMwAAAjU"] [Tue Aug 18 12:53:40.523328 2026] [security2:error] [pid 67073:tid 67238] [client 157.51.166.53:5504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABPcmepr5_nHgLbMvMwAAAjU"] [Tue Aug 18 12:53:40.529666 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/x.php"] [unique_id "aoSABPcmepr5_nHgLbMvNAAAAno"] [Tue Aug 18 12:53:40.532674 2026] [security2:error] [pid 67073:tid 67281] [client 158.23.17.4:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/main.php"] [unique_id "aoSABPcmepr5_nHgLbMvNQAAAmA"] [Tue Aug 18 12:53:40.532700 2026] [security2:error] [pid 66623:tid 66807] [client 213.35.127.232:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSABNO5rbWdOArH04J8AgAAATM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:40.567468 2026] [security2:error] [pid 67073:tid 67285] [client 20.186.30.159:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/fpwch.php"] [unique_id "aoSABPcmepr5_nHgLbMvNwAAAmQ"] [Tue Aug 18 12:53:40.587256 2026] [security2:error] [pid 67073:tid 67224] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSABPcmepr5_nHgLbMvOQAAAic"] [Tue Aug 18 12:53:40.629284 2026] [security2:error] [pid 66623:tid 66797] [client 132.196.61.152:27270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSABNO5rbWdOArH04J8AwAAASk"] [Tue Aug 18 12:53:40.642854 2026] [security2:error] [pid 66623:tid 66839] [client 104.209.144.33:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSABNO5rbWdOArH04J8BAAAAVM"] [Tue Aug 18 12:53:40.680467 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/default.php"] [unique_id "aoSABPcmepr5_nHgLbMvPQAAAlU"] [Tue Aug 18 12:53:40.696300 2026] [security2:error] [pid 66623:tid 66785] [client 4.223.164.152:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/site.php"] [unique_id "aoSABNO5rbWdOArH04J8BQAAAR0"] [Tue Aug 18 12:53:40.699751 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.18.37:38925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSABPcmepr5_nHgLbMvPgAAAhQ"] [Tue Aug 18 12:53:40.710840 2026] [security2:error] [pid 67073:tid 67326] [client 20.48.236.86:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/SDsadqwrf.php"] [unique_id "aoSABPcmepr5_nHgLbMvPwAAAo0"] [Tue Aug 18 12:53:40.713700 2026] [security2:error] [pid 67073:tid 67267] [client 143.244.161.13:63737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "stampi.ind.br"] [uri "/"] [unique_id "aoSABPcmepr5_nHgLbMvQAAAAlI"] [Tue Aug 18 12:53:40.719449 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/koiy.php"] [unique_id "aoSABNO5rbWdOArH04J8BgAAASc"] [Tue Aug 18 12:53:40.738846 2026] [security2:error] [pid 67073:tid 67305] [client 20.163.43.14:3170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/inputs.php"] [unique_id "aoSABPcmepr5_nHgLbMvQQAAAng"] [Tue Aug 18 12:53:40.752882 2026] [security2:error] [pid 67073:tid 67256] [client 74.249.206.207:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/file1221.php"] [unique_id "aoSABPcmepr5_nHgLbMvRAAAAkc"] [Tue Aug 18 12:53:40.755594 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:21162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/gy.php"] [unique_id "aoSABPcmepr5_nHgLbMvRQAAAjs"] [Tue Aug 18 12:53:40.764916 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:28383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSABPcmepr5_nHgLbMvRgAAAlM"] [Tue Aug 18 12:53:40.766017 2026] [security2:error] [pid 67073:tid 67228] [client 213.202.253.4:57951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/schallfuns.php"] [unique_id "aoSABPcmepr5_nHgLbMvRwAAAis"], referer: www.google.com [Tue Aug 18 12:53:40.787229 2026] [security2:error] [pid 66623:tid 66813] [client 4.232.151.198:36220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSABNO5rbWdOArH04J8BwAAATk"] [Tue Aug 18 12:53:40.792112 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.136.165:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/X57.php"] [unique_id "aoSABPcmepr5_nHgLbMvSQAAAj4"] [Tue Aug 18 12:53:40.824040 2026] [security2:error] [pid 67073:tid 67308] [client 4.223.164.152:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/shiny.php"] [unique_id "aoSABPcmepr5_nHgLbMvSgAAAns"] [Tue Aug 18 12:53:40.827494 2026] [security2:error] [pid 67073:tid 67239] [client 20.51.153.15:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/del.php"] [unique_id "aoSABPcmepr5_nHgLbMvSwAAAjY"] [Tue Aug 18 12:53:40.840217 2026] [security2:error] [pid 67073:tid 67245] [client 20.171.51.14:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/hp.php"] [unique_id "aoSABPcmepr5_nHgLbMvTQAAAjw"] [Tue Aug 18 12:53:40.858085 2026] [security2:error] [pid 67073:tid 67309] [client 52.238.210.254:57873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp.php"] [unique_id "aoSABPcmepr5_nHgLbMvTgAAAnw"] [Tue Aug 18 12:53:40.872767 2026] [security2:error] [pid 67073:tid 67276] [client 20.186.30.159:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/adminner.php"] [unique_id "aoSABPcmepr5_nHgLbMvUAAAAls"] [Tue Aug 18 12:53:40.886077 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSABNO5rbWdOArH04J8CAAAAUg"] [Tue Aug 18 12:53:40.910418 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/gy.php"] [unique_id "aoSABPcmepr5_nHgLbMvUgAAAn0"] [Tue Aug 18 12:53:40.911196 2026] [autoindex:error] [pid 67073:tid 67301] [client 172.202.39.151:33107] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:40.920980 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.56.190:52049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hr.php"] [unique_id "aoSABPcmepr5_nHgLbMvUwAAAko"] [Tue Aug 18 12:53:40.958820 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:33687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ac.php"] [unique_id "aoSABPcmepr5_nHgLbMvWQAAAmo"] [Tue Aug 18 12:53:41.042594 2026] [security2:error] [pid 67073:tid 67147] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms.php"] [unique_id "aoSABfcmepr5_nHgLbMvXAACH0c"] [Tue Aug 18 12:53:41.083076 2026] [security2:error] [pid 67073:tid 67320] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/puc.php"] [unique_id "aoSABfcmepr5_nHgLbMvYAAAAoc"] [Tue Aug 18 12:53:41.117197 2026] [security2:error] [pid 67073:tid 67318] [client 20.186.30.159:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "residencial.multiveicular.org.br"] [uri "/abcd.php"] [unique_id "aoSABfcmepr5_nHgLbMvYQAAAoU"] [Tue Aug 18 12:53:41.117573 2026] [security2:error] [pid 67073:tid 67330] [client 20.91.215.254:9102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-post.php"] [unique_id "aoSABfcmepr5_nHgLbMvYgAAApE"] [Tue Aug 18 12:53:41.123085 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.56.190:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kt.php"] [unique_id "aoSABfcmepr5_nHgLbMvZQAAAmk"] [Tue Aug 18 12:53:41.131472 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.6.191:6649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/admin.php"] [unique_id "aoSABfcmepr5_nHgLbMvZgAAAjM"] [Tue Aug 18 12:53:41.181385 2026] [security2:error] [pid 66623:tid 66793] [client 20.104.100.201:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yup.php"] [unique_id "aoSABdO5rbWdOArH04J8CQAAASU"] [Tue Aug 18 12:53:41.182518 2026] [security2:error] [pid 67073:tid 67250] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSABfcmepr5_nHgLbMvaAAAAkE"] [Tue Aug 18 12:53:41.191770 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:40169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/tt.php"] [unique_id "aoSABfcmepr5_nHgLbMvagAAAkQ"] [Tue Aug 18 12:53:41.206813 2026] [security2:error] [pid 67073:tid 67233] [client 192.141.172.134:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvbQAAAjA"] [Tue Aug 18 12:53:41.206925 2026] [security2:error] [pid 67073:tid 67233] [client 192.141.172.134:51701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvbQAAAjA"] [Tue Aug 18 12:53:41.210313 2026] [security2:error] [pid 66623:tid 66808] [client 74.248.136.165:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/forbidals.php"] [unique_id "aoSABdO5rbWdOArH04J8CgAAATQ"] [Tue Aug 18 12:53:41.214600 2026] [security2:error] [pid 67073:tid 67243] [client 52.238.210.254:10211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvbwAAAjo"] [Tue Aug 18 12:53:41.219169 2026] [security2:error] [pid 67073:tid 67272] [client 172.202.39.151:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvcQAAAlc"] [Tue Aug 18 12:53:41.221494 2026] [security2:error] [pid 67073:tid 67328] [client 20.51.153.15:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/moderator.php"] [unique_id "aoSABfcmepr5_nHgLbMvcgAAAo8"] [Tue Aug 18 12:53:41.229889 2026] [security2:error] [pid 67073:tid 67185] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gfile.php"] [unique_id "aoSABfcmepr5_nHgLbMvdAACPW0"] [Tue Aug 18 12:53:41.245203 2026] [security2:error] [pid 67073:tid 67261] [client 158.23.17.4:58710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/ga.php"] [unique_id "aoSABfcmepr5_nHgLbMvdgAAAkw"] [Tue Aug 18 12:53:41.261008 2026] [security2:error] [pid 67073:tid 67210] [client 74.249.206.207:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/nox.php"] [unique_id "aoSABfcmepr5_nHgLbMvdwAAAhk"] [Tue Aug 18 12:53:41.276905 2026] [security2:error] [pid 67073:tid 67263] [client 4.223.164.152:37307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/403dd.php"] [unique_id "aoSABfcmepr5_nHgLbMveAAAAk4"] [Tue Aug 18 12:53:41.281757 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wx.php"] [unique_id "aoSABfcmepr5_nHgLbMveQAAAoo"] [Tue Aug 18 12:53:41.403361 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/alfa.php"] [unique_id "aoSABfcmepr5_nHgLbMvfAAAAmQ"] [Tue Aug 18 12:53:41.451083 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:16658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/file61.php"] [unique_id "aoSABfcmepr5_nHgLbMvfQAAAnc"] [Tue Aug 18 12:53:41.470281 2026] [security2:error] [pid 67073:tid 67230] [client 132.196.61.152:55345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mgrr.php"] [unique_id "aoSABfcmepr5_nHgLbMvfgAAAi0"] [Tue Aug 18 12:53:41.484083 2026] [security2:error] [pid 67073:tid 67294] [client 172.202.39.151:44431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABfcmepr5_nHgLbMvfwAAAm0"] [Tue Aug 18 12:53:41.507265 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSABfcmepr5_nHgLbMvgQAAAkM"] [Tue Aug 18 12:53:41.511554 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.98.162:23922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSABfcmepr5_nHgLbMvggAAAig"] [Tue Aug 18 12:53:41.512448 2026] [security2:error] [pid 67073:tid 67205] [client 20.171.51.14:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yz.php"] [unique_id "aoSABfcmepr5_nHgLbMvgwAAAhQ"] [Tue Aug 18 12:53:41.546583 2026] [security2:error] [pid 67073:tid 67300] [client 213.35.127.232:54464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSABfcmepr5_nHgLbMvhAAAAnM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:41.563232 2026] [security2:error] [pid 67073:tid 67284] [client 20.51.153.15:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/infoinfo.php"] [unique_id "aoSABfcmepr5_nHgLbMvhgAAAmM"] [Tue Aug 18 12:53:41.626316 2026] [security2:error] [pid 67073:tid 67244] [client 74.248.136.165:40837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/edit.php"] [unique_id "aoSABfcmepr5_nHgLbMviAAAAjs"] [Tue Aug 18 12:53:41.662832 2026] [security2:error] [pid 67073:tid 67247] [client 20.171.51.14:14982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/dj.php"] [unique_id "aoSABfcmepr5_nHgLbMviQAAAj4"] [Tue Aug 18 12:53:41.713424 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:41.713697 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:41.719748 2026] [security2:error] [pid 67073:tid 67207] [client 52.173.121.69:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvjAAAAhY"] [Tue Aug 18 12:53:41.732131 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/lock360.php"] [unique_id "aoSABfcmepr5_nHgLbMvjQAAAnw"] [Tue Aug 18 12:53:41.746166 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:20193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSABfcmepr5_nHgLbMvjgAAAlI"] [Tue Aug 18 12:53:41.748259 2026] [security2:error] [pid 67073:tid 67276] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/inso.php"] [unique_id "aoSABfcmepr5_nHgLbMvjwAAAls"] [Tue Aug 18 12:53:41.764638 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.56.190:28245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ww.php"] [unique_id "aoSABdO5rbWdOArH04J8DAAAAVI"] [Tue Aug 18 12:53:41.772429 2026] [security2:error] [pid 66623:tid 66867] [client 4.223.164.152:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/baba.php"] [unique_id "aoSABdO5rbWdOArH04J8DQAAAW8"] [Tue Aug 18 12:53:41.773376 2026] [security2:error] [pid 67073:tid 67260] [client 4.223.164.152:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvkgAAAks"] [Tue Aug 18 12:53:41.797281 2026] [security2:error] [pid 67073:tid 67242] [client 47.128.22.219:57886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gabrielabrandao.adv.br"] [uri "/robots.txt"] [unique_id "aoSABfcmepr5_nHgLbMvkwAAAjk"] [Tue Aug 18 12:53:41.802051 2026] [security2:error] [pid 67073:tid 67295] [client 20.51.153.15:13326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/c99shell.php"] [unique_id "aoSABfcmepr5_nHgLbMvlAAAAm4"] [Tue Aug 18 12:53:41.818166 2026] [security2:error] [pid 67073:tid 67220] [client 5.253.205.188:46794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/files.sql"] [unique_id "aoSABfcmepr5_nHgLbMvlQAAAiM"], referer: https://medihub.com.br/files.sql [Tue Aug 18 12:53:41.820186 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSABfcmepr5_nHgLbMvlgAAAos"] [Tue Aug 18 12:53:41.840644 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:25319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSABfcmepr5_nHgLbMvmAAAAnQ"] [Tue Aug 18 12:53:41.886080 2026] [security2:error] [pid 67073:tid 67219] [client 54.87.112.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSABfcmepr5_nHgLbMvkAAAAiI"], referer: https://bn2s.com.br/ [Tue Aug 18 12:53:41.927688 2026] [security2:error] [pid 67073:tid 67234] [client 20.48.236.86:10761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSABfcmepr5_nHgLbMvnAAAAjE"] [Tue Aug 18 12:53:41.977317 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:55338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/55.php"] [unique_id "aoSABfcmepr5_nHgLbMvngAAAlo"] [Tue Aug 18 12:53:41.990480 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kj.php"] [unique_id "aoSABfcmepr5_nHgLbMvnwAAAms"] [Tue Aug 18 12:53:42.001962 2026] [security2:error] [pid 67073:tid 67186] [remote 34.26.95.176:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "atekrefrigeracao.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSABvcmepr5_nHgLbMvoAACRm4"] [Tue Aug 18 12:53:42.009975 2026] [security2:error] [pid 66623:tid 66857] [client 135.225.75.187:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fff.php"] [unique_id "aoSABtO5rbWdOArH04J8DgAAAWU"] [Tue Aug 18 12:53:42.025764 2026] [security2:error] [pid 67073:tid 67303] [client 158.23.17.4:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/wb.php"] [unique_id "aoSABvcmepr5_nHgLbMvoQAAAnY"] [Tue Aug 18 12:53:42.035849 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.18.37:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bgymj.php"] [unique_id "aoSABvcmepr5_nHgLbMvowAAAk8"] [Tue Aug 18 12:53:42.044766 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:19222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/kj.php"] [unique_id "aoSABvcmepr5_nHgLbMvpAAAAh4"] [Tue Aug 18 12:53:42.046303 2026] [security2:error] [pid 67073:tid 67184] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSABvcmepr5_nHgLbMvpQACKWw"] [Tue Aug 18 12:53:42.051127 2026] [security2:error] [pid 67073:tid 67320] [client 20.51.153.15:13433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/profiler.php"] [unique_id "aoSABvcmepr5_nHgLbMvpgAAAoc"] [Tue Aug 18 12:53:42.061886 2026] [security2:error] [pid 67073:tid 67238] [client 85.154.68.202:8221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvqAAAAjU"] [Tue Aug 18 12:53:42.062016 2026] [security2:error] [pid 67073:tid 67238] [client 85.154.68.202:8221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvqAAAAjU"] [Tue Aug 18 12:53:42.067098 2026] [security2:error] [pid 67073:tid 67269] [client 20.163.43.14:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/flower.php"] [unique_id "aoSABvcmepr5_nHgLbMvqQAAAlQ"] [Tue Aug 18 12:53:42.084860 2026] [security2:error] [pid 67073:tid 67330] [client 20.42.19.40:2689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/php.php"] [unique_id "aoSABvcmepr5_nHgLbMvqgAAApE"] [Tue Aug 18 12:53:42.159612 2026] [security2:error] [pid 67073:tid 67277] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSABvcmepr5_nHgLbMvrQAAAlw"] [Tue Aug 18 12:53:42.168998 2026] [security2:error] [pid 67073:tid 67288] [client 172.202.39.151:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/abc.php"] [unique_id "aoSABvcmepr5_nHgLbMvsAAAAmc"] [Tue Aug 18 12:53:42.190922 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/site.php"] [unique_id "aoSABvcmepr5_nHgLbMvsgAAAok"] [Tue Aug 18 12:53:42.235291 2026] [security2:error] [pid 67073:tid 67188] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/cu.php"] [unique_id "aoSABvcmepr5_nHgLbMvswACGHA"] [Tue Aug 18 12:53:42.240941 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.144.65:53003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tivinalili.com.br"] [uri "/mestre-derivan-lanca-o-livro-ultimate-bartender-book-2018"] [unique_id "aoSABvcmepr5_nHgLbMvtQAAAm8"], referer: https://tivinalili.com.br/mestre-derivan-lanca-o-livro-ultimate-bartender-book-2018 [Tue Aug 18 12:53:42.252391 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.56.190:3049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mo.php"] [unique_id "aoSABvcmepr5_nHgLbMvtgAAAn4"] [Tue Aug 18 12:53:42.305206 2026] [autoindex:error] [pid 67073:tid 67197] [remote 172.182.217.32:0] AH01276: Cannot serve directory /home3/pcjnl23s/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:42.320884 2026] [security2:error] [pid 66623:tid 66774] [client 20.51.153.15:13439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/findes.php"] [unique_id "aoSABtO5rbWdOArH04J8EQAAARI"] [Tue Aug 18 12:53:42.359797 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.100.201:53886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSABvcmepr5_nHgLbMvuQAAAk4"] [Tue Aug 18 12:53:42.365203 2026] [security2:error] [pid 67073:tid 67231] [client 4.223.164.152:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/cabs.php"] [unique_id "aoSABvcmepr5_nHgLbMvugAAAi4"] [Tue Aug 18 12:53:42.368577 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.169.31:28458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/k.php"] [unique_id "aoSABtO5rbWdOArH04J8EgAAAVs"] [Tue Aug 18 12:53:42.383673 2026] [security2:error] [pid 67073:tid 67323] [client 104.209.144.33:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvuwAAAoo"] [Tue Aug 18 12:53:42.386026 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:31989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/admin.php"] [unique_id "aoSABvcmepr5_nHgLbMvvAAAAo0"] [Tue Aug 18 12:53:42.386033 2026] [security2:error] [pid 67073:tid 67280] [client 74.249.206.207:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/akismet.php"] [unique_id "aoSABvcmepr5_nHgLbMvvQAAAl8"] [Tue Aug 18 12:53:42.404385 2026] [security2:error] [pid 67073:tid 67233] [client 20.91.215.254:9113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSABvcmepr5_nHgLbMvvgAAAjA"] [Tue Aug 18 12:53:42.404929 2026] [security2:error] [pid 67073:tid 67316] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/aa.php"] [unique_id "aoSABvcmepr5_nHgLbMvvwAAAoM"] [Tue Aug 18 12:53:42.423948 2026] [security2:error] [pid 66623:tid 66806] [client 172.202.39.151:44375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/moon.php"] [unique_id "aoSABtO5rbWdOArH04J8FQAAATI"] [Tue Aug 18 12:53:42.434483 2026] [security2:error] [pid 67073:tid 67241] [client 20.250.13.23:30518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/adminfuns.php"] [unique_id "aoSABvcmepr5_nHgLbMvwQAAAjg"] [Tue Aug 18 12:53:42.448343 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:3187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/13.php"] [unique_id "aoSABtO5rbWdOArH04J8FwAAAXk"] [Tue Aug 18 12:53:42.455106 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/X57.php"] [unique_id "aoSABvcmepr5_nHgLbMvwgACUQQ"] [Tue Aug 18 12:53:42.462203 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bes.php"] [unique_id "aoSABvcmepr5_nHgLbMvwwAAAn8"] [Tue Aug 18 12:53:42.481323 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSABtO5rbWdOArH04J8GQAAAXM"] [Tue Aug 18 12:53:42.491775 2026] [security2:error] [pid 66623:tid 66890] [client 40.85.222.29:2860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSABtO5rbWdOArH04J8GgAAAYY"] [Tue Aug 18 12:53:42.492892 2026] [security2:error] [pid 67073:tid 67164] [remote 34.26.95.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.95.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSABvcmepr5_nHgLbMvrwACTVg"] [Tue Aug 18 12:53:42.508678 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:33824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSABvcmepr5_nHgLbMvxQAAAjI"] [Tue Aug 18 12:53:42.575584 2026] [security2:error] [pid 67073:tid 67306] [client 213.35.127.232:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvyQAAAnk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:42.609789 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.56.190:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qr.php"] [unique_id "aoSABvcmepr5_nHgLbMvywAAAig"] [Tue Aug 18 12:53:42.654255 2026] [security2:error] [pid 66623:tid 66860] [client 20.171.51.14:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fa.php"] [unique_id "aoSABtO5rbWdOArH04J8GwAAAWg"] [Tue Aug 18 12:53:42.655377 2026] [security2:error] [pid 67073:tid 67268] [client 4.223.164.152:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSABvcmepr5_nHgLbMvzgAAAlM"] [Tue Aug 18 12:53:42.680138 2026] [security2:error] [pid 66623:tid 66869] [client 132.196.61.152:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ajax.php"] [unique_id "aoSABtO5rbWdOArH04J8HAAAAXE"] [Tue Aug 18 12:53:42.780075 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cc.php"] [unique_id "aoSABvcmepr5_nHgLbMv0wAAAnw"] [Tue Aug 18 12:53:42.783538 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/BDKR28WP.php"] [unique_id "aoSABvcmepr5_nHgLbMv1QAAAls"] [Tue Aug 18 12:53:42.797152 2026] [security2:error] [pid 67073:tid 67260] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSABvcmepr5_nHgLbMv1gAAAks"] [Tue Aug 18 12:53:42.819299 2026] [security2:error] [pid 67073:tid 67248] [client 172.202.39.151:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/akcc.php"] [unique_id "aoSABvcmepr5_nHgLbMv2AAAAj8"] [Tue Aug 18 12:53:42.820635 2026] [security2:error] [pid 67073:tid 67242] [client 52.238.210.254:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/file2.php"] [unique_id "aoSABvcmepr5_nHgLbMv2QAAAjk"] [Tue Aug 18 12:53:42.880138 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.136.165:19254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws60.php"] [unique_id "aoSABvcmepr5_nHgLbMv2gAAAos"] [Tue Aug 18 12:53:42.905569 2026] [security2:error] [pid 67073:tid 67278] [client 158.158.74.177:25866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSABvcmepr5_nHgLbMv3AAAAl0"] [Tue Aug 18 12:53:42.911613 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:42.911891 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:42.921201 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:3067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dirs.php"] [unique_id "aoSABvcmepr5_nHgLbMv3gAAAnA"] [Tue Aug 18 12:53:42.928924 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:6599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/insc.php"] [unique_id "aoSABvcmepr5_nHgLbMv3wAAAiI"] [Tue Aug 18 12:53:42.957862 2026] [security2:error] [pid 67073:tid 67289] [client 20.65.98.162:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/mgrr.php"] [unique_id "aoSABvcmepr5_nHgLbMv4AAAAmg"] [Tue Aug 18 12:53:43.000824 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.56.190:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/mq.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5AAAAiQ"] [Tue Aug 18 12:53:43.006348 2026] [security2:error] [pid 67073:tid 67255] [client 20.51.153.15:13317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/fedora.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5QAAAkY"] [Tue Aug 18 12:53:43.007729 2026] [security2:error] [pid 67073:tid 67195] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/forbidals.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5gACbHc"] [Tue Aug 18 12:53:43.038715 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAB_cmepr5_nHgLbMv5wAAAm4"] [Tue Aug 18 12:53:43.066443 2026] [security2:error] [pid 66623:tid 66892] [client 20.171.51.14:45434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fb.php"] [unique_id "aoSAB9O5rbWdOArH04J8HwAAAYg"] [Tue Aug 18 12:53:43.067805 2026] [security2:error] [pid 67073:tid 67264] [client 20.24.67.246:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/1.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6AAAAk8"] [Tue Aug 18 12:53:43.067882 2026] [security2:error] [pid 67073:tid 67264] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/1.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6AAAAk8"] [Tue Aug 18 12:53:43.094535 2026] [security2:error] [pid 67073:tid 67238] [client 4.223.164.152:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/cabs.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6gAAAjU"] [Tue Aug 18 12:53:43.102713 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAB_cmepr5_nHgLbMv6wAAAlQ"] [Tue Aug 18 12:53:43.114413 2026] [security2:error] [pid 66623:tid 66778] [client 158.158.74.177:25858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAB9O5rbWdOArH04J8IAAAARY"] [Tue Aug 18 12:53:43.144103 2026] [security2:error] [pid 67073:tid 67286] [client 20.163.43.14:3108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAB_cmepr5_nHgLbMv7AAAAmU"] [Tue Aug 18 12:53:43.152469 2026] [security2:error] [pid 67073:tid 67277] [client 135.225.75.187:9987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pouhg.php"] [unique_id "aoSAB_cmepr5_nHgLbMv7QAAAlw"] [Tue Aug 18 12:53:43.168388 2026] [security2:error] [pid 66623:tid 66698] [remote 57.141.22.113:33344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAB9O5rbWdOArH04J8IQABIj0"] [Tue Aug 18 12:53:43.178138 2026] [security2:error] [pid 66623:tid 66868] [client 74.248.18.37:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSAB9O5rbWdOArH04J8IgAAAXA"] [Tue Aug 18 12:53:43.253300 2026] [security2:error] [pid 67073:tid 67240] [client 20.250.13.23:31479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/404.php"] [unique_id "aoSAB_cmepr5_nHgLbMv8gAAAjc"] [Tue Aug 18 12:53:43.257591 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/edit.php"] [unique_id "aoSAB_cmepr5_nHgLbMv8wACGBA"] [Tue Aug 18 12:53:43.276318 2026] [security2:error] [pid 66623:tid 66891] [client 20.91.215.254:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reservamatadapraia.com.br"] [uri "/license.php"] [unique_id "aoSAB9O5rbWdOArH04J8IwAAAYc"] [Tue Aug 18 12:53:43.298495 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.136.165:41175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/olfclass.php"] [unique_id "aoSAB_cmepr5_nHgLbMv9QAAAj0"] [Tue Aug 18 12:53:43.315119 2026] [security2:error] [pid 66623:tid 66881] [client 52.139.47.57:13510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAB9O5rbWdOArH04J8JAAAAX0"] [Tue Aug 18 12:53:43.315828 2026] [security2:error] [pid 66623:tid 66781] [client 20.48.236.86:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAB9O5rbWdOArH04J8JQAAARk"] [Tue Aug 18 12:53:43.326011 2026] [security2:error] [pid 66623:tid 66805] [client 20.51.153.15:13389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/path.php"] [unique_id "aoSAB9O5rbWdOArH04J8JwAAATE"] [Tue Aug 18 12:53:43.357665 2026] [security2:error] [pid 67073:tid 67303] [client 114.119.145.125:62393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lecarveiculospira.com.br"] [uri "/estoque/veiculos/marca-volkswagen_modelo-fox_ordem-year-desc"] [unique_id "aoSAB_cmepr5_nHgLbMv9gAAAnY"], referer: https://www.lecarveiculospira.com.br/estoque/veiculos/marca-volkswagen_modelo-fox_ordem-price-desc [Tue Aug 18 12:53:43.363157 2026] [security2:error] [pid 67073:tid 67290] [client 20.118.172.148:44279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAB_cmepr5_nHgLbMv9wAAAmk"] [Tue Aug 18 12:53:43.406538 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:28378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAB_cmepr5_nHgLbMv-QAAAlo"] [Tue Aug 18 12:53:43.441210 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAB9O5rbWdOArH04J8KAAAAUA"] [Tue Aug 18 12:53:43.443091 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.56.190:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sn.php"] [unique_id "aoSAB9O5rbWdOArH04J8KQAAAYQ"] [Tue Aug 18 12:53:43.452045 2026] [security2:error] [pid 66623:tid 66886] [client 20.42.19.40:2705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/t.php"] [unique_id "aoSAB9O5rbWdOArH04J8KgAAAYI"] [Tue Aug 18 12:53:43.469418 2026] [security2:error] [pid 66623:tid 66865] [client 158.23.17.4:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/xn.php"] [unique_id "aoSAB9O5rbWdOArH04J8KwAAAW0"] [Tue Aug 18 12:53:43.481343 2026] [security2:error] [pid 67073:tid 67083] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/kj.php"] [unique_id "aoSAB_cmepr5_nHgLbMv-wACTgc"] [Tue Aug 18 12:53:43.533010 2026] [security2:error] [pid 66623:tid 66875] [client 20.163.43.14:3188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAB9O5rbWdOArH04J8LQAAAXc"] [Tue Aug 18 12:53:43.533057 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAB9O5rbWdOArH04J8LAAAAXI"] [Tue Aug 18 12:53:43.544296 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/insc.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_AAAAo0"] [Tue Aug 18 12:53:43.548881 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/file.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_QAAAoE"] [Tue Aug 18 12:53:43.557574 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gw.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_gAAAjA"] [Tue Aug 18 12:53:43.563751 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/yj09.php"] [unique_id "aoSAB_cmepr5_nHgLbMv_wAAAoM"] [Tue Aug 18 12:53:43.602016 2026] [security2:error] [pid 67073:tid 67307] [client 20.104.100.201:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-the.php"] [unique_id "aoSAB_cmepr5_nHgLbMwAgAAAno"] [Tue Aug 18 12:53:43.602070 2026] [security2:error] [pid 67073:tid 67328] [client 213.35.127.232:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAB_cmepr5_nHgLbMwAwAAAo8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:43.611111 2026] [security2:error] [pid 67073:tid 67281] [client 172.202.39.151:44359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/cache.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBQAAAmA"] [Tue Aug 18 12:53:43.611139 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.6.191:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/public/css.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBAAAAn8"] [Tue Aug 18 12:53:43.628436 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:29645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAB_cmepr5_nHgLbMwBgAAAiw"] [Tue Aug 18 12:53:43.637861 2026] [security2:error] [pid 66623:tid 66884] [client 52.238.210.254:30059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAB9O5rbWdOArH04J8MAAAAYA"] [Tue Aug 18 12:53:43.638386 2026] [security2:error] [pid 66623:tid 66821] [client 20.226.56.190:7311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/13.php"] [unique_id "aoSAB9O5rbWdOArH04J8MQAAAUE"] [Tue Aug 18 12:53:43.641447 2026] [security2:error] [pid 66623:tid 66863] [client 20.51.153.15:13436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/456.php"] [unique_id "aoSAB9O5rbWdOArH04J8MgAAAWs"] [Tue Aug 18 12:53:43.670844 2026] [security2:error] [pid 67073:tid 67078] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bes.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCAACjgI"] [Tue Aug 18 12:53:43.677905 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/cjfuns.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCQAAAhk"] [Tue Aug 18 12:53:43.682098 2026] [security2:error] [pid 67073:tid 67224] [client 20.48.236.86:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCgAAAic"] [Tue Aug 18 12:53:43.724129 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.136.165:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wpver.php"] [unique_id "aoSAB_cmepr5_nHgLbMwCwAAAow"] [Tue Aug 18 12:53:43.725910 2026] [security2:error] [pid 67073:tid 67230] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/img.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDAAAAi0"] [Tue Aug 18 12:53:43.739324 2026] [security2:error] [pid 67073:tid 67317] [client 40.85.222.29:37753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDQAAAoQ"] [Tue Aug 18 12:53:43.747492 2026] [security2:error] [pid 66623:tid 66878] [client 172.182.200.96:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/jvcpa.php"] [unique_id "aoSAB9O5rbWdOArH04J8NAAAAXo"] [Tue Aug 18 12:53:43.763484 2026] [security2:error] [pid 67073:tid 67205] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAB_cmepr5_nHgLbMwDgAAAhQ"] [Tue Aug 18 12:53:43.812280 2026] [security2:error] [pid 67073:tid 67258] [client 158.158.74.177:25880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAB_cmepr5_nHgLbMwEgAAAkk"] [Tue Aug 18 12:53:43.840504 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/43.php"] [unique_id "aoSAB_cmepr5_nHgLbMwEwAAAjs"] [Tue Aug 18 12:53:43.878207 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/SMTP.php"] [unique_id "aoSAB_cmepr5_nHgLbMwFgAAAj4"] [Tue Aug 18 12:53:43.878378 2026] [security2:error] [pid 67073:tid 67308] [client 20.163.43.14:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/01.php"] [unique_id "aoSAB_cmepr5_nHgLbMwFwAAAns"] [Tue Aug 18 12:53:43.883471 2026] [security2:error] [pid 66623:tid 66811] [client 20.48.236.86:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/sky.php"] [unique_id "aoSAB9O5rbWdOArH04J8NQAAATc"] [Tue Aug 18 12:53:43.908028 2026] [security2:error] [pid 66623:tid 66779] [client 74.249.206.207:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/admin.php"] [unique_id "aoSAB9O5rbWdOArH04J8NgAAARc"] [Tue Aug 18 12:53:43.916098 2026] [security2:error] [pid 66623:tid 66854] [client 52.238.210.254:10160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAB9O5rbWdOArH04J8NwAAAWI"] [Tue Aug 18 12:53:43.961067 2026] [security2:error] [pid 67073:tid 67171] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws60.php"] [unique_id "aoSAB_cmepr5_nHgLbMwGgACP18"] [Tue Aug 18 12:53:43.967621 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:45385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sw.php"] [unique_id "aoSAB_cmepr5_nHgLbMwGwAAAjk"] [Tue Aug 18 12:53:43.975590 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:37259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/file.php"] [unique_id "aoSAB_cmepr5_nHgLbMwHAAAAis"] [Tue Aug 18 12:53:43.987574 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:31997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/goods.php"] [unique_id "aoSAB9O5rbWdOArH04J8OQAAAX4"] [Tue Aug 18 12:53:44.059901 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.136.165:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSACPcmepr5_nHgLbMwHwAAAmo"] [Tue Aug 18 12:53:44.073049 2026] [security2:error] [pid 66623:tid 66839] [client 20.171.51.14:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vg.php"] [unique_id "aoSACNO5rbWdOArH04J8OgAAAVM"] [Tue Aug 18 12:53:44.075618 2026] [security2:error] [pid 66623:tid 66835] [client 20.48.236.86:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSACNO5rbWdOArH04J8OwAAAU8"] [Tue Aug 18 12:53:44.081957 2026] [security2:error] [pid 67073:tid 67279] [client 4.223.164.152:6917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/dex.php"] [unique_id "aoSACPcmepr5_nHgLbMwIAAAAl4"] [Tue Aug 18 12:53:44.105207 2026] [security2:error] [pid 67073:tid 67304] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSACPcmepr5_nHgLbMwIQAAAnc"] [Tue Aug 18 12:53:44.113497 2026] [security2:error] [pid 67073:tid 67289] [client 20.51.153.15:13328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/vbseo.php"] [unique_id "aoSACPcmepr5_nHgLbMwIgAAAmg"] [Tue Aug 18 12:53:44.133490 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:44.133760 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:44.140493 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.136.165:58367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/thui.php"] [unique_id "aoSACPcmepr5_nHgLbMwJgAAAiQ"] [Tue Aug 18 12:53:44.158859 2026] [security2:error] [pid 67073:tid 67293] [client 158.23.17.4:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/47.php"] [unique_id "aoSACPcmepr5_nHgLbMwKAAAAmw"] [Tue Aug 18 12:53:44.158917 2026] [security2:error] [pid 67073:tid 67093] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/olfclass.php"] [unique_id "aoSACPcmepr5_nHgLbMwJwACRhE"] [Tue Aug 18 12:53:44.206912 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.100.201:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSACNO5rbWdOArH04J8PAAAAW4"] [Tue Aug 18 12:53:44.214968 2026] [security2:error] [pid 66623:tid 66795] [client 20.163.43.14:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/lv.php"] [unique_id "aoSACNO5rbWdOArH04J8PQAAASc"] [Tue Aug 18 12:53:44.239514 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:18100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/55.php"] [unique_id "aoSACNO5rbWdOArH04J8PwAAATk"] [Tue Aug 18 12:53:44.252731 2026] [security2:error] [pid 67073:tid 67264] [client 135.225.75.187:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/moon3.php"] [unique_id "aoSACPcmepr5_nHgLbMwKgAAAk8"] [Tue Aug 18 12:53:44.268968 2026] [security2:error] [pid 67073:tid 67302] [client 149.34.210.157:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwKwAAAnU"] [Tue Aug 18 12:53:44.309340 2026] [security2:error] [pid 66623:tid 66785] [client 20.91.215.254:20174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSACNO5rbWdOArH04J8QAAAAR0"] [Tue Aug 18 12:53:44.320254 2026] [security2:error] [pid 67073:tid 67320] [client 132.196.61.152:56121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/scxy.php"] [unique_id "aoSACPcmepr5_nHgLbMwLwAAAoc"] [Tue Aug 18 12:53:44.383444 2026] [security2:error] [pid 67073:tid 67108] [remote 34.26.95.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.95.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwMAACkSA"] [Tue Aug 18 12:53:44.383641 2026] [security2:error] [pid 67073:tid 67330] [client 34.26.95.176:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atekrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwMAACkSA"] [Tue Aug 18 12:53:44.398674 2026] [security2:error] [pid 66623:tid 66793] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/222.php"] [unique_id "aoSACNO5rbWdOArH04J8QQAAASU"] [Tue Aug 18 12:53:44.399873 2026] [security2:error] [pid 67073:tid 67249] [client 4.223.164.152:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/dex.php"] [unique_id "aoSACPcmepr5_nHgLbMwMQAAAkA"] [Tue Aug 18 12:53:44.399942 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.56.190:47105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fresh.php"] [unique_id "aoSACPcmepr5_nHgLbMwMgAAAiA"] [Tue Aug 18 12:53:44.405419 2026] [security2:error] [pid 67073:tid 67236] [client 20.51.153.15:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sysinfo.php"] [unique_id "aoSACPcmepr5_nHgLbMwMwAAAjM"] [Tue Aug 18 12:53:44.407845 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:6381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/so.php"] [unique_id "aoSACNO5rbWdOArH04J8QgAAARA"] [Tue Aug 18 12:53:44.420697 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSACPcmepr5_nHgLbMwNQAAAmU"] [Tue Aug 18 12:53:44.423027 2026] [security2:error] [pid 67073:tid 67214] [client 52.139.47.57:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/aaa.php"] [unique_id "aoSACPcmepr5_nHgLbMwNwAAAh0"] [Tue Aug 18 12:53:44.440597 2026] [security2:error] [pid 66623:tid 66818] [client 158.158.74.177:25875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/st.php"] [unique_id "aoSACNO5rbWdOArH04J8QwAAAT4"] [Tue Aug 18 12:53:44.498328 2026] [security2:error] [pid 66623:tid 66848] [client 74.249.206.207:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/bajah.php"] [unique_id "aoSACNO5rbWdOArH04J8RQAAAVw"] [Tue Aug 18 12:53:44.547771 2026] [security2:error] [pid 67073:tid 67302] [client 149.34.210.157:49294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSACPcmepr5_nHgLbMwKwAAAnU"] [Tue Aug 18 12:53:44.556289 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:35942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoSACPcmepr5_nHgLbMwOgAAAng"] [Tue Aug 18 12:53:44.558583 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tmpls.php"] [unique_id "aoSACPcmepr5_nHgLbMwOwAAAhg"] [Tue Aug 18 12:53:44.563797 2026] [security2:error] [pid 67073:tid 67246] [client 104.209.144.33:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSACPcmepr5_nHgLbMwPQAAAj0"] [Tue Aug 18 12:53:44.565731 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:44.566004 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:44.596105 2026] [security2:error] [pid 66623:tid 66889] [client 196.12.128.158:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSACNO5rbWdOArH04J8RwAAAYU"] [Tue Aug 18 12:53:44.596220 2026] [security2:error] [pid 66623:tid 66889] [client 196.12.128.158:54578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSACNO5rbWdOArH04J8RwAAAYU"] [Tue Aug 18 12:53:44.610427 2026] [security2:error] [pid 66623:tid 66810] [client 20.163.43.14:3136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/new.php"] [unique_id "aoSACNO5rbWdOArH04J8SAAAATY"] [Tue Aug 18 12:53:44.617436 2026] [security2:error] [pid 67073:tid 67215] [client 213.35.127.232:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSACPcmepr5_nHgLbMwPwAAAh4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:44.648502 2026] [security2:error] [pid 66623:tid 66800] [client 20.51.153.15:13316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ppinfo.php"] [unique_id "aoSACNO5rbWdOArH04J8SQAAASw"] [Tue Aug 18 12:53:44.662306 2026] [security2:error] [pid 66623:tid 66789] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/i.php"] [unique_id "aoSACNO5rbWdOArH04J8SgAAASE"] [Tue Aug 18 12:53:44.686167 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:36431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gc.php"] [unique_id "aoSACNO5rbWdOArH04J8SwAAAX8"] [Tue Aug 18 12:53:44.709949 2026] [security2:error] [pid 67073:tid 67290] [client 40.85.222.29:37709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/well-known/index.php"] [unique_id "aoSACPcmepr5_nHgLbMwQwAAAmk"] [Tue Aug 18 12:53:44.748326 2026] [security2:error] [pid 66623:tid 66867] [client 20.48.236.86:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSACNO5rbWdOArH04J8TAAAAW8"] [Tue Aug 18 12:53:44.763634 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSACPcmepr5_nHgLbMwRAAAAlo"] [Tue Aug 18 12:53:44.766647 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:25228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wk/index.php"] [unique_id "aoSACNO5rbWdOArH04J8TQAAAV8"] [Tue Aug 18 12:53:44.769161 2026] [security2:error] [pid 66623:tid 66830] [client 52.238.210.254:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/alfa.php"] [unique_id "aoSACNO5rbWdOArH04J8TgAAAUo"] [Tue Aug 18 12:53:44.789913 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.56.190:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gj.php"] [unique_id "aoSACPcmepr5_nHgLbMwSAAAAi4"] [Tue Aug 18 12:53:44.836110 2026] [security2:error] [pid 66623:tid 66841] [client 20.104.100.201:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/xwpg.php"] [unique_id "aoSACNO5rbWdOArH04J8UAAAAVU"] [Tue Aug 18 12:53:44.858991 2026] [security2:error] [pid 67073:tid 67314] [client 20.48.236.86:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file5.php"] [unique_id "aoSACPcmepr5_nHgLbMwSQAAAoE"] [Tue Aug 18 12:53:44.861111 2026] [security2:error] [pid 66623:tid 66857] [client 4.223.164.152:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/key.php"] [unique_id "aoSACNO5rbWdOArH04J8UQAAAWU"] [Tue Aug 18 12:53:44.896593 2026] [security2:error] [pid 66623:tid 66827] [client 20.51.153.15:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/globals.php"] [unique_id "aoSACNO5rbWdOArH04J8UgAAAUc"] [Tue Aug 18 12:53:44.928948 2026] [security2:error] [pid 66623:tid 66847] [client 132.196.61.152:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ws13.php"] [unique_id "aoSACNO5rbWdOArH04J8UwAAAVs"] [Tue Aug 18 12:53:44.952136 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:20221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSACPcmepr5_nHgLbMwTAAAAkw"] [Tue Aug 18 12:53:44.975827 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.136.165:40877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nzv.php"] [unique_id "aoSACPcmepr5_nHgLbMwTwAAAkU"] [Tue Aug 18 12:53:44.980871 2026] [security2:error] [pid 67073:tid 67266] [client 20.163.43.14:3137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/222.php"] [unique_id "aoSACPcmepr5_nHgLbMwUAAAAlE"] [Tue Aug 18 12:53:44.995087 2026] [security2:error] [pid 67073:tid 67114] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wpver.php"] [unique_id "aoSACPcmepr5_nHgLbMwUQACjyY"] [Tue Aug 18 12:53:45.018150 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:45.018421 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:45.034928 2026] [security2:error] [pid 66623:tid 66871] [client 74.249.206.207:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/ajax.php"] [unique_id "aoSACdO5rbWdOArH04J8VQAAAXM"] [Tue Aug 18 12:53:45.066325 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.56.190:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pd.php"] [unique_id "aoSACdO5rbWdOArH04J8VwAAAUQ"] [Tue Aug 18 12:53:45.069523 2026] [security2:error] [pid 66623:tid 66872] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/key.php"] [unique_id "aoSACdO5rbWdOArH04J8WAAAAXQ"] [Tue Aug 18 12:53:45.075590 2026] [security2:error] [pid 66623:tid 66833] [client 20.48.236.86:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/xx.php"] [unique_id "aoSACdO5rbWdOArH04J8WQAAAU0"] [Tue Aug 18 12:53:45.093462 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:54451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSACdO5rbWdOArH04J8WgAAATo"] [Tue Aug 18 12:53:45.106499 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:20634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSACfcmepr5_nHgLbMwVAAAAio"] [Tue Aug 18 12:53:45.109898 2026] [security2:error] [pid 66623:tid 66832] [client 158.158.74.177:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSACdO5rbWdOArH04J8WwAAAUw"] [Tue Aug 18 12:53:45.115003 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:43051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wk/index.php"] [unique_id "aoSACfcmepr5_nHgLbMwVQAAApI"] [Tue Aug 18 12:53:45.120960 2026] [security2:error] [pid 66623:tid 66860] [client 20.171.51.14:43375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/uq.php"] [unique_id "aoSACdO5rbWdOArH04J8XAAAAWg"] [Tue Aug 18 12:53:45.121004 2026] [security2:error] [pid 67073:tid 67229] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwVgAAAiw"] [Tue Aug 18 12:53:45.131995 2026] [security2:error] [pid 66623:tid 66869] [client 20.51.153.15:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/yindu.php"] [unique_id "aoSACdO5rbWdOArH04J8XQAAAXE"] [Tue Aug 18 12:53:45.167648 2026] [security2:error] [pid 67073:tid 67211] [client 4.223.164.152:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/key.php"] [unique_id "aoSACfcmepr5_nHgLbMwWAAAAho"] [Tue Aug 18 12:53:45.185920 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/thui.php"] [unique_id "aoSACfcmepr5_nHgLbMwWQACGS4"] [Tue Aug 18 12:53:45.198922 2026] [security2:error] [pid 67073:tid 67224] [client 52.238.210.254:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/atomlib.php"] [unique_id "aoSACfcmepr5_nHgLbMwWgAAAic"] [Tue Aug 18 12:53:45.213667 2026] [security2:error] [pid 66623:tid 66721] [remote 103.56.163.133:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSACdO5rbWdOArH04J8XgABC1Q"] [Tue Aug 18 12:53:45.227913 2026] [security2:error] [pid 67073:tid 67325] [client 172.202.39.151:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwXAAAAow"] [Tue Aug 18 12:53:45.250849 2026] [security2:error] [pid 67073:tid 67238] [client 47.128.17.52:44372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rodriguesesoutoadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSACfcmepr5_nHgLbMwXgAAAjU"] [Tue Aug 18 12:53:45.290607 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:29663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSACdO5rbWdOArH04J8XwAAAS0"] [Tue Aug 18 12:53:45.298841 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSACdO5rbWdOArH04J8YAAAASI"] [Tue Aug 18 12:53:45.308272 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:3177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/chosen.php"] [unique_id "aoSACfcmepr5_nHgLbMwYAAAAhQ"] [Tue Aug 18 12:53:45.385773 2026] [security2:error] [pid 67073:tid 67172] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tmpls.php"] [unique_id "aoSACfcmepr5_nHgLbMwYwACFWA"] [Tue Aug 18 12:53:45.392039 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/error1.php"] [unique_id "aoSACdO5rbWdOArH04J8YQAAAWk"] [Tue Aug 18 12:53:45.392702 2026] [security2:error] [pid 66623:tid 66845] [client 4.223.164.152:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/kir.php"] [unique_id "aoSACdO5rbWdOArH04J8YgAAAVk"] [Tue Aug 18 12:53:45.408509 2026] [security2:error] [pid 67073:tid 67283] [client 20.48.236.86:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/av.php"] [unique_id "aoSACfcmepr5_nHgLbMwZAAAAmI"] [Tue Aug 18 12:53:45.410585 2026] [security2:error] [pid 67073:tid 67207] [client 114.119.144.41:42043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.capitalcaminhonetes.com.br"] [uri "/veiculo/993911/ranger-xlt-3-2-20v-4x4-cd-diesel-aut"] [unique_id "aoSACfcmepr5_nHgLbMwZQAAAhY"], referer: http://www.capitalcaminhonetes.com.br/veiculo/90162/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut [Tue Aug 18 12:53:45.415823 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/index/function.php"] [unique_id "aoSACfcmepr5_nHgLbMwZwAAAlI"] [Tue Aug 18 12:53:45.416939 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:33708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sm.php"] [unique_id "aoSACfcmepr5_nHgLbMwaAAAAks"] [Tue Aug 18 12:53:45.428573 2026] [security2:error] [pid 66623:tid 66881] [client 20.104.100.201:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/dex.php"] [unique_id "aoSACdO5rbWdOArH04J8YwAAAX0"] [Tue Aug 18 12:53:45.437546 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.56.190:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/th.php"] [unique_id "aoSACfcmepr5_nHgLbMwawAAAjk"] [Tue Aug 18 12:53:45.441669 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSACdO5rbWdOArH04J8ZAAAARk"] [Tue Aug 18 12:53:45.504870 2026] [security2:error] [pid 66623:tid 66886] [client 132.196.61.152:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/btx25.php"] [unique_id "aoSACdO5rbWdOArH04J8ZQAAAYI"] [Tue Aug 18 12:53:45.506307 2026] [security2:error] [pid 66623:tid 66819] [client 197.184.64.235:41914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACdO5rbWdOArH04J8ZgAAAT8"] [Tue Aug 18 12:53:45.510993 2026] [security2:error] [pid 66623:tid 66819] [client 197.184.64.235:41914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACdO5rbWdOArH04J8ZgAAAT8"] [Tue Aug 18 12:53:45.542378 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.6.191:6639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSACfcmepr5_nHgLbMwbwAAAl4"] [Tue Aug 18 12:53:45.590351 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/import.php"] [unique_id "aoSACfcmepr5_nHgLbMwcAAAAjs"] [Tue Aug 18 12:53:45.604315 2026] [security2:error] [pid 67073:tid 67257] [client 158.23.17.4:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/payout.php"] [unique_id "aoSACfcmepr5_nHgLbMwcgAAAkg"] [Tue Aug 18 12:53:45.630708 2026] [security2:error] [pid 66623:tid 66859] [client 213.35.127.232:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSACdO5rbWdOArH04J8aQAAAWc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:45.640322 2026] [security2:error] [pid 67073:tid 67320] [client 20.171.51.14:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/32.php"] [unique_id "aoSACfcmepr5_nHgLbMwdAAAAoc"] [Tue Aug 18 12:53:45.649519 2026] [security2:error] [pid 67073:tid 67270] [client 20.51.153.15:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sxx.php"] [unique_id "aoSACfcmepr5_nHgLbMwdQAAAlU"] [Tue Aug 18 12:53:45.654117 2026] [security2:error] [pid 67073:tid 67318] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSACfcmepr5_nHgLbMwdgAAAoU"] [Tue Aug 18 12:53:45.667123 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:14877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bolt.php"] [unique_id "aoSACdO5rbWdOArH04J8agAAASQ"] [Tue Aug 18 12:53:45.667685 2026] [security2:error] [pid 67073:tid 67249] [client 74.249.206.207:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rmlmaquinas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSACfcmepr5_nHgLbMweAAAAkA"] [Tue Aug 18 12:53:45.668444 2026] [security2:error] [pid 67073:tid 67102] [remote 157.55.39.52:60102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2026/08/15/study-report-on-pirots-5s-compatibility-across-different-devices/"] [unique_id "aoSACfcmepr5_nHgLbMwdwACYxo"] [Tue Aug 18 12:53:45.700398 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:16512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ajax.php"] [unique_id "aoSACdO5rbWdOArH04J8awAAAXI"] [Tue Aug 18 12:53:45.720382 2026] [security2:error] [pid 67073:tid 67230] [client 20.250.13.23:31465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/about.php"] [unique_id "aoSACfcmepr5_nHgLbMwegAAAi0"] [Tue Aug 18 12:53:45.726915 2026] [security2:error] [pid 66623:tid 66884] [client 20.163.43.14:3181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/info.php"] [unique_id "aoSACdO5rbWdOArH04J8bAAAAYA"] [Tue Aug 18 12:53:45.731386 2026] [security2:error] [pid 67073:tid 67236] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSACfcmepr5_nHgLbMwewAAAjM"] [Tue Aug 18 12:53:45.748058 2026] [security2:error] [pid 67073:tid 67214] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSACfcmepr5_nHgLbMwfQAAAh0"] [Tue Aug 18 12:53:45.759592 2026] [security2:error] [pid 66623:tid 66863] [client 135.225.75.187:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/opts.php"] [unique_id "aoSACdO5rbWdOArH04J8bQAAAWs"] [Tue Aug 18 12:53:45.781707 2026] [security2:error] [pid 67073:tid 67288] [client 20.226.56.190:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/admin404.php"] [unique_id "aoSACfcmepr5_nHgLbMwfgAAAmc"] [Tue Aug 18 12:53:45.797128 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.169.31:7385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/file.php"] [unique_id "aoSACfcmepr5_nHgLbMwfwAAAis"] [Tue Aug 18 12:53:45.810541 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.136.165:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/155.php"] [unique_id "aoSACfcmepr5_nHgLbMwgQAAAjc"] [Tue Aug 18 12:53:45.840659 2026] [security2:error] [pid 66623:tid 66688] [remote 47.86.33.52:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/wp-login.php"] [unique_id "aoSACdO5rbWdOArH04J8bwABZjM"] [Tue Aug 18 12:53:45.851976 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/nofile.php"] [unique_id "aoSACfcmepr5_nHgLbMwggAAAh4"] [Tue Aug 18 12:53:45.858714 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-configs.php"] [unique_id "aoSACfcmepr5_nHgLbMwgwAAAik"] [Tue Aug 18 12:53:45.895663 2026] [security2:error] [pid 66623:tid 66880] [client 20.48.236.86:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/media.php"] [unique_id "aoSACdO5rbWdOArH04J8cAAAAXw"] [Tue Aug 18 12:53:45.900084 2026] [security2:error] [pid 66623:tid 66812] [client 20.171.51.14:51819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/28.php"] [unique_id "aoSACdO5rbWdOArH04J8cQAAATg"] [Tue Aug 18 12:53:45.912936 2026] [security2:error] [pid 66623:tid 66849] [client 20.51.153.15:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/settings.php"] [unique_id "aoSACdO5rbWdOArH04J8cgAAAV0"] [Tue Aug 18 12:53:45.947852 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACfcmepr5_nHgLbMwhwAAAlY"] [Tue Aug 18 12:53:45.947955 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACfcmepr5_nHgLbMwhwAAAlY"] [Tue Aug 18 12:53:45.953729 2026] [security2:error] [pid 67073:tid 67140] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nzv.php"] [unique_id "aoSACfcmepr5_nHgLbMwiAACikA"] [Tue Aug 18 12:53:45.987389 2026] [security2:error] [pid 67073:tid 67233] [client 20.104.100.201:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/xyn.php"] [unique_id "aoSACfcmepr5_nHgLbMwigAAAjA"] [Tue Aug 18 12:53:46.016080 2026] [security2:error] [pid 67073:tid 67254] [client 4.223.164.152:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/kir.php"] [unique_id "aoSACvcmepr5_nHgLbMwjgAAAkU"] [Tue Aug 18 12:53:46.016347 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:31617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/73.php"] [unique_id "aoSACvcmepr5_nHgLbMwjwAAAlE"] [Tue Aug 18 12:53:46.040821 2026] [security2:error] [pid 67073:tid 67281] [client 20.226.56.190:45055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qo.php"] [unique_id "aoSACvcmepr5_nHgLbMwkAAAAmA"] [Tue Aug 18 12:53:46.047264 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/fpwch.php"] [unique_id "aoSACvcmepr5_nHgLbMwkQAAAlQ"] [Tue Aug 18 12:53:46.069966 2026] [security2:error] [pid 67073:tid 67268] [client 37.40.227.74:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwkgAAAlM"] [Tue Aug 18 12:53:46.072589 2026] [security2:error] [pid 67073:tid 67208] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSACvcmepr5_nHgLbMwkwAAAhc"] [Tue Aug 18 12:53:46.073716 2026] [security2:error] [pid 67073:tid 67268] [client 37.40.227.74:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwkgAAAlM"] [Tue Aug 18 12:53:46.110862 2026] [security2:error] [pid 66623:tid 66783] [client 20.48.236.86:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/xyn.php"] [unique_id "aoSACtO5rbWdOArH04J8dQAAARs"] [Tue Aug 18 12:53:46.140141 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/error1.php"] [unique_id "aoSACvcmepr5_nHgLbMwlgACGSk"] [Tue Aug 18 12:53:46.168145 2026] [security2:error] [pid 67073:tid 67218] [client 40.85.222.29:29247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSACvcmepr5_nHgLbMwlwAAAiE"] [Tue Aug 18 12:53:46.171921 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.56.190:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sd.php"] [unique_id "aoSACvcmepr5_nHgLbMwmAAAAjU"] [Tue Aug 18 12:53:46.212882 2026] [security2:error] [pid 67073:tid 67306] [client 158.23.17.4:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/bh.php"] [unique_id "aoSACvcmepr5_nHgLbMwmwAAAnk"] [Tue Aug 18 12:53:46.224740 2026] [security2:error] [pid 66623:tid 66807] [client 20.91.215.254:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/cropper.php"] [unique_id "aoSACtO5rbWdOArH04J8dwAAATM"] [Tue Aug 18 12:53:46.229604 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fasx.php"] [unique_id "aoSACvcmepr5_nHgLbMwnAAAAig"] [Tue Aug 18 12:53:46.253051 2026] [security2:error] [pid 66623:tid 66835] [client 20.51.153.15:13407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/spip.php"] [unique_id "aoSACtO5rbWdOArH04J8eAAAAU8"] [Tue Aug 18 12:53:46.274907 2026] [security2:error] [pid 66623:tid 66866] [client 4.223.164.152:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/fling.php"] [unique_id "aoSACtO5rbWdOArH04J8eQAAAW4"] [Tue Aug 18 12:53:46.300260 2026] [security2:error] [pid 67073:tid 67303] [client 86.120.159.145:1399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwoQAAAnY"] [Tue Aug 18 12:53:46.300357 2026] [security2:error] [pid 67073:tid 67303] [client 86.120.159.145:1399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACvcmepr5_nHgLbMwoQAAAnY"] [Tue Aug 18 12:53:46.315477 2026] [security2:error] [pid 67073:tid 67223] [client 20.48.236.86:16261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/images.php"] [unique_id "aoSACvcmepr5_nHgLbMwpAAAAiY"] [Tue Aug 18 12:53:46.317194 2026] [security2:error] [pid 67073:tid 67242] [client 52.238.210.254:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/min.php"] [unique_id "aoSACvcmepr5_nHgLbMwpQAAAjk"] [Tue Aug 18 12:53:46.332698 2026] [security2:error] [pid 66623:tid 66853] [client 20.171.51.14:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/m.php"] [unique_id "aoSACtO5rbWdOArH04J8egAAAWE"] [Tue Aug 18 12:53:46.344827 2026] [security2:error] [pid 67073:tid 67231] [client 20.100.169.31:28365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwpwAAAi4"] [Tue Aug 18 12:53:46.373393 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:46.373800 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:46.377635 2026] [security2:error] [pid 67073:tid 67145] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/155.php"] [unique_id "aoSACvcmepr5_nHgLbMwqgACaEU"] [Tue Aug 18 12:53:46.380214 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wk/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwqwAAAiQ"] [Tue Aug 18 12:53:46.390811 2026] [security2:error] [pid 67073:tid 67292] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/thoms.php"] [unique_id "aoSACvcmepr5_nHgLbMwrAAAAms"] [Tue Aug 18 12:53:46.391391 2026] [security2:error] [pid 67073:tid 67293] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSACvcmepr5_nHgLbMwrQAAAmw"] [Tue Aug 18 12:53:46.406507 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:3174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwrgAAAls"] [Tue Aug 18 12:53:46.459326 2026] [security2:error] [pid 66623:tid 66813] [client 104.209.144.33:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSACtO5rbWdOArH04J8fQAAATk"] [Tue Aug 18 12:53:46.475747 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:44437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-mail.php"] [unique_id "aoSACvcmepr5_nHgLbMwsAAAAnw"] [Tue Aug 18 12:53:46.495757 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:20612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSACvcmepr5_nHgLbMwsQAAAkg"] [Tue Aug 18 12:53:46.513701 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-post.php"] [unique_id "aoSACvcmepr5_nHgLbMwsgAAAlI"] [Tue Aug 18 12:53:46.533118 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.61.152:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSACvcmepr5_nHgLbMwswAAAlU"] [Tue Aug 18 12:53:46.562912 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fasx.php"] [unique_id "aoSACvcmepr5_nHgLbMwtQACkU8"] [Tue Aug 18 12:53:46.582091 2026] [security2:error] [pid 67073:tid 67308] [client 74.248.18.37:14896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bthil.php"] [unique_id "aoSACvcmepr5_nHgLbMwtgAAAns"] [Tue Aug 18 12:53:46.638425 2026] [security2:error] [pid 67073:tid 67230] [client 20.48.236.86:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/mac.php"] [unique_id "aoSACvcmepr5_nHgLbMwtwAAAi0"] [Tue Aug 18 12:53:46.644359 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.100.201:17365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwuQAAAjM"] [Tue Aug 18 12:53:46.649430 2026] [security2:error] [pid 66623:tid 66772] [client 74.248.136.165:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-good.php"] [unique_id "aoSACtO5rbWdOArH04J8fgAAARA"] [Tue Aug 18 12:53:46.654318 2026] [security2:error] [pid 67073:tid 67220] [client 213.35.127.232:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSACvcmepr5_nHgLbMwugAAAiM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:46.665732 2026] [security2:error] [pid 66623:tid 66818] [client 20.171.51.14:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ib.php"] [unique_id "aoSACtO5rbWdOArH04J8fwAAAT4"] [Tue Aug 18 12:53:46.667118 2026] [security2:error] [pid 66623:tid 66808] [client 114.119.129.110:62439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onlineveiculoscachoeira.com.br"] [uri "/robots.txt"] [unique_id "aoSACtO5rbWdOArH04J8gAAAATQ"], referer: http://onlineveiculoscachoeira.com.br/robots.txt [Tue Aug 18 12:53:46.697502 2026] [security2:error] [pid 67073:tid 67214] [client 4.223.164.152:54257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/zoo1.php"] [unique_id "aoSACvcmepr5_nHgLbMwvAAAAh0"] [Tue Aug 18 12:53:46.712331 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:13435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/search.php"] [unique_id "aoSACvcmepr5_nHgLbMwvgAAAjE"] [Tue Aug 18 12:53:46.728737 2026] [security2:error] [pid 66623:tid 66823] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSACtO5rbWdOArH04J8gQAAAUM"] [Tue Aug 18 12:53:46.745995 2026] [security2:error] [pid 67073:tid 67243] [client 20.163.43.14:3081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSACvcmepr5_nHgLbMwwAAAAjo"] [Tue Aug 18 12:53:46.771697 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-good.php"] [unique_id "aoSACvcmepr5_nHgLbMwwgACb04"] [Tue Aug 18 12:53:46.788175 2026] [security2:error] [pid 66623:tid 66855] [client 5.31.227.224:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8ggAAAWM"] [Tue Aug 18 12:53:46.792283 2026] [security2:error] [pid 66623:tid 66855] [client 5.31.227.224:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8ggAAAWM"] [Tue Aug 18 12:53:46.861099 2026] [security2:error] [pid 66623:tid 66793] [client 20.91.215.254:20188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSACtO5rbWdOArH04J8gwAAASU"] [Tue Aug 18 12:53:46.897642 2026] [security2:error] [pid 66623:tid 66800] [client 192.141.172.134:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8hQAAASw"] [Tue Aug 18 12:53:46.897768 2026] [security2:error] [pid 66623:tid 66800] [client 192.141.172.134:51952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSACtO5rbWdOArH04J8hQAAASw"] [Tue Aug 18 12:53:46.969130 2026] [security2:error] [pid 67073:tid 67250] [client 20.171.51.14:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nl.php"] [unique_id "aoSACvcmepr5_nHgLbMwxQAAAkE"] [Tue Aug 18 12:53:46.970663 2026] [security2:error] [pid 67073:tid 67157] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zxin.php"] [unique_id "aoSACvcmepr5_nHgLbMwxgACaVE"] [Tue Aug 18 12:53:46.976619 2026] [security2:error] [pid 67073:tid 67275] [client 20.51.153.15:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/build.php"] [unique_id "aoSACvcmepr5_nHgLbMwyAAAAlo"] [Tue Aug 18 12:53:46.983540 2026] [security2:error] [pid 67073:tid 67329] [client 158.23.17.4:15151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/ct.php"] [unique_id "aoSACvcmepr5_nHgLbMwyQAAApA"] [Tue Aug 18 12:53:46.988598 2026] [security2:error] [pid 67073:tid 67327] [client 213.202.253.4:58567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSACvcmepr5_nHgLbMwygAAAo4"], referer: www.google.com [Tue Aug 18 12:53:47.014882 2026] [security2:error] [pid 66623:tid 66851] [client 20.104.100.201:54051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-good.php"] [unique_id "aoSAC9O5rbWdOArH04J8iAAAAV8"] [Tue Aug 18 12:53:47.016560 2026] [security2:error] [pid 67073:tid 67258] [client 20.48.236.86:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/ops.php"] [unique_id "aoSAC_cmepr5_nHgLbMwzAAAAkk"] [Tue Aug 18 12:53:47.035593 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/nofile.php"] [unique_id "aoSAC_cmepr5_nHgLbMw1wAAAlY"] [Tue Aug 18 12:53:47.048137 2026] [security2:error] [pid 67073:tid 67323] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/wpxml.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2AAAAoo"] [Tue Aug 18 12:53:47.053694 2026] [security2:error] [pid 67073:tid 67237] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2QAAAjQ"] [Tue Aug 18 12:53:47.065935 2026] [security2:error] [pid 67073:tid 67314] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2gAAAoE"] [Tue Aug 18 12:53:47.066515 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zxin.php"] [unique_id "aoSAC_cmepr5_nHgLbMw2wAAAjA"] [Tue Aug 18 12:53:47.097291 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:3178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/k.php"] [unique_id "aoSAC_cmepr5_nHgLbMw3QAAAoM"] [Tue Aug 18 12:53:47.120708 2026] [security2:error] [pid 66623:tid 66809] [client 4.223.164.152:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/zoo2.php"] [unique_id "aoSAC9O5rbWdOArH04J8iQAAATU"] [Tue Aug 18 12:53:47.124242 2026] [security2:error] [pid 66623:tid 66857] [client 172.202.39.151:44421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/o.php"] [unique_id "aoSAC9O5rbWdOArH04J8igAAAWU"] [Tue Aug 18 12:53:47.150415 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:58407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xm.php"] [unique_id "aoSAC9O5rbWdOArH04J8iwAAAVg"] [Tue Aug 18 12:53:47.155265 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:9361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSAC_cmepr5_nHgLbMw4QAAAik"] [Tue Aug 18 12:53:47.191263 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pass4.php"] [unique_id "aoSAC_cmepr5_nHgLbMw5wACKm4"] [Tue Aug 18 12:53:47.219030 2026] [security2:error] [pid 66623:tid 66847] [client 20.51.153.15:13358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/defaul.php"] [unique_id "aoSAC9O5rbWdOArH04J8jAAAAVs"] [Tue Aug 18 12:53:47.243771 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:6530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAC9O5rbWdOArH04J8jgAAATI"] [Tue Aug 18 12:53:47.272989 2026] [security2:error] [pid 66623:tid 66822] [client 52.238.210.254:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/mac.php"] [unique_id "aoSAC9O5rbWdOArH04J8jwAAAUI"] [Tue Aug 18 12:53:47.274102 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:47.274377 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:47.281786 2026] [security2:error] [pid 67073:tid 67235] [client 135.225.75.187:57835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zwq13.php"] [unique_id "aoSAC_cmepr5_nHgLbMxAQAAAjI"] [Tue Aug 18 12:53:47.291343 2026] [security2:error] [pid 67073:tid 67215] [client 114.119.166.95:45207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jcveiculosutilitarios.com.br"] [uri "/ficha-cadastral"] [unique_id "aoSAC_cmepr5_nHgLbMxAgAAAh4"], referer: https://www.jcveiculosutilitarios.com.br/estoque [Tue Aug 18 12:53:47.366478 2026] [security2:error] [pid 67073:tid 67306] [client 20.48.236.86:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/coffexium.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDAAAAnk"] [Tue Aug 18 12:53:47.373970 2026] [security2:error] [pid 67073:tid 67077] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDgACQwE"] [Tue Aug 18 12:53:47.382986 2026] [security2:error] [pid 66623:tid 66893] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAC9O5rbWdOArH04J8kQAAAYk"] [Tue Aug 18 12:53:47.397502 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.56.190:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/km.php"] [unique_id "aoSAC9O5rbWdOArH04J8kgAAAUw"] [Tue Aug 18 12:53:47.399026 2026] [security2:error] [pid 66623:tid 66860] [client 20.65.98.162:16611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/yj09.php"] [unique_id "aoSAC9O5rbWdOArH04J8kwAAAWg"] [Tue Aug 18 12:53:47.408816 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.61.152:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAC9O5rbWdOArH04J8lAAAASo"] [Tue Aug 18 12:53:47.446809 2026] [security2:error] [pid 66623:tid 66864] [client 103.184.169.37:41166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8lgAAAWw"] [Tue Aug 18 12:53:47.446941 2026] [security2:error] [pid 66623:tid 66864] [client 103.184.169.37:41166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8lgAAAWw"] [Tue Aug 18 12:53:47.452485 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAC9O5rbWdOArH04J8lwAAASg"] [Tue Aug 18 12:53:47.458229 2026] [security2:error] [pid 67073:tid 67225] [client 20.171.51.14:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/68.php"] [unique_id "aoSAC_cmepr5_nHgLbMxDwAAAig"] [Tue Aug 18 12:53:47.484265 2026] [security2:error] [pid 67073:tid 67206] [client 74.248.136.165:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pass4.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEQAAAhU"] [Tue Aug 18 12:53:47.484542 2026] [security2:error] [pid 67073:tid 67247] [client 20.51.153.15:13434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/twin.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEgAAAj4"] [Tue Aug 18 12:53:47.511328 2026] [security2:error] [pid 66623:tid 66876] [client 68.155.154.236:65208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAC9O5rbWdOArH04J8mAAAAXg"] [Tue Aug 18 12:53:47.530186 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAC_cmepr5_nHgLbMxEwAAAiE"] [Tue Aug 18 12:53:47.545682 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/org.php"] [unique_id "aoSAC9O5rbWdOArH04J8mQAAAXA"] [Tue Aug 18 12:53:47.553477 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.56.190:2559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mf.php"] [unique_id "aoSAC9O5rbWdOArH04J8mwAAAWA"] [Tue Aug 18 12:53:47.586632 2026] [security2:error] [pid 66623:tid 66845] [client 20.163.43.14:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/403.php"] [unique_id "aoSAC9O5rbWdOArH04J8nAAAAVk"] [Tue Aug 18 12:53:47.633189 2026] [security2:error] [pid 66623:tid 66781] [client 104.209.144.33:25327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAC9O5rbWdOArH04J8nQAAARk"] [Tue Aug 18 12:53:47.649820 2026] [security2:error] [pid 66623:tid 66767] [client 5.253.205.188:35534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/forumacplibinserts.bak"] [unique_id "aoSAC9O5rbWdOArH04J8ngAAAQs"], referer: https://medihub.com.br/forumacplibinserts.bak [Tue Aug 18 12:53:47.657748 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/10.php"] [unique_id "aoSAC_cmepr5_nHgLbMxGgAAAoI"] [Tue Aug 18 12:53:47.664040 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAC_cmepr5_nHgLbMxGwAAAjU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:47.695596 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.100.201:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wmore1.php"] [unique_id "aoSAC_cmepr5_nHgLbMxHAAAAl4"] [Tue Aug 18 12:53:47.709767 2026] [security2:error] [pid 66623:tid 66825] [client 138.36.100.162:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8nwAAAUU"] [Tue Aug 18 12:53:47.712828 2026] [security2:error] [pid 67073:tid 67304] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/file1221.php"] [unique_id "aoSAC_cmepr5_nHgLbMxHQAAAnc"] [Tue Aug 18 12:53:47.726076 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:47.726340 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:47.728011 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAC9O5rbWdOArH04J8oAAAAR4"] [Tue Aug 18 12:53:47.793756 2026] [security2:error] [pid 67073:tid 67264] [client 20.48.236.86:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIAAAAk8"] [Tue Aug 18 12:53:47.797560 2026] [security2:error] [pid 67073:tid 67309] [client 4.223.164.152:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/fling.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIQAAAnw"] [Tue Aug 18 12:53:47.812627 2026] [security2:error] [pid 67073:tid 67257] [client 20.171.51.14:43386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/zy.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIgAAAkg"] [Tue Aug 18 12:53:47.819769 2026] [security2:error] [pid 66623:tid 66891] [client 158.158.74.177:25859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSAC9O5rbWdOArH04J8oQAAAYc"] [Tue Aug 18 12:53:47.831378 2026] [security2:error] [pid 66623:tid 66803] [client 20.51.153.15:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/new2.php"] [unique_id "aoSAC9O5rbWdOArH04J8ogAAAS8"] [Tue Aug 18 12:53:47.831578 2026] [security2:error] [pid 66623:tid 66884] [client 20.118.172.148:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAC9O5rbWdOArH04J8owAAAYA"] [Tue Aug 18 12:53:47.845702 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.18.37:35912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/x.php"] [unique_id "aoSAC_cmepr5_nHgLbMxIwAAAlI"] [Tue Aug 18 12:53:47.902438 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.136.165:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAC9O5rbWdOArH04J8pAAAAVY"] [Tue Aug 18 12:53:47.946688 2026] [security2:error] [pid 67073:tid 67259] [client 158.23.17.4:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/gy.php"] [unique_id "aoSAC_cmepr5_nHgLbMxJwAAAko"] [Tue Aug 18 12:53:47.981258 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:17958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/te.php"] [unique_id "aoSAC_cmepr5_nHgLbMxKwAAAnA"] [Tue Aug 18 12:53:47.981820 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/imageskir.php"] [unique_id "aoSAC_cmepr5_nHgLbMxLAAAAi0"] [Tue Aug 18 12:53:48.013178 2026] [security2:error] [pid 67073:tid 67277] [client 172.202.39.151:21824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSADPcmepr5_nHgLbMxLQAAAlw"] [Tue Aug 18 12:53:48.052796 2026] [security2:error] [pid 67073:tid 67296] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSADPcmepr5_nHgLbMxLwAAAm8"] [Tue Aug 18 12:53:48.066588 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:13419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/rex.php"] [unique_id "aoSADPcmepr5_nHgLbMxMAAAAis"] [Tue Aug 18 12:53:48.086382 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:23866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/term.php"] [unique_id "aoSADNO5rbWdOArH04J8pwAAARY"] [Tue Aug 18 12:53:48.104408 2026] [security2:error] [pid 66623:tid 66825] [client 138.36.100.162:42976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAC9O5rbWdOArH04J8nwAAAUU"] [Tue Aug 18 12:53:48.138656 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:21873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.formedesign.com.br"] [uri "/1.php"] [unique_id "aoSADPcmepr5_nHgLbMxNgAAAok"] [Tue Aug 18 12:53:48.138774 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/1.php"] [unique_id "aoSADPcmepr5_nHgLbMxNgAAAok"] [Tue Aug 18 12:53:48.144047 2026] [security2:error] [pid 67073:tid 67258] [client 20.48.236.86:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/sf.php"] [unique_id "aoSADPcmepr5_nHgLbMxOAAAAkk"] [Tue Aug 18 12:53:48.152373 2026] [security2:error] [pid 67073:tid 67237] [client 132.196.61.152:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSADPcmepr5_nHgLbMxOgAAAjQ"] [Tue Aug 18 12:53:48.181908 2026] [security2:error] [pid 67073:tid 67308] [client 20.91.215.254:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/goat.php"] [unique_id "aoSADPcmepr5_nHgLbMxOwAAAns"] [Tue Aug 18 12:53:48.186462 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/nc4.php"] [unique_id "aoSADPcmepr5_nHgLbMxPAAAAoM"] [Tue Aug 18 12:53:48.246880 2026] [security2:error] [pid 67073:tid 67269] [client 20.48.236.86:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSADPcmepr5_nHgLbMxPgAAAlQ"] [Tue Aug 18 12:53:48.261138 2026] [security2:error] [pid 67073:tid 67266] [client 20.104.100.201:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/special.php"] [unique_id "aoSADPcmepr5_nHgLbMxPwAAAlE"] [Tue Aug 18 12:53:48.320796 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.136.165:53467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/z.php"] [unique_id "aoSADPcmepr5_nHgLbMxRAAAAlk"] [Tue Aug 18 12:53:48.326554 2026] [security2:error] [pid 67073:tid 67211] [client 20.51.153.15:13361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/verification.php"] [unique_id "aoSADPcmepr5_nHgLbMxRQAAAho"] [Tue Aug 18 12:53:48.344887 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:43897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/well-known/index.php"] [unique_id "aoSADNO5rbWdOArH04J8qQAAARg"] [Tue Aug 18 12:53:48.373492 2026] [security2:error] [pid 67073:tid 67215] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/nox.php"] [unique_id "aoSADPcmepr5_nHgLbMxRwAAAh4"] [Tue Aug 18 12:53:48.416629 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.136.165:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/path.php"] [unique_id "aoSADPcmepr5_nHgLbMxSgAAAmI"] [Tue Aug 18 12:53:48.424622 2026] [security2:error] [pid 67073:tid 67206] [client 20.171.51.14:31635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jl.php"] [unique_id "aoSADPcmepr5_nHgLbMxTAAAAhU"] [Tue Aug 18 12:53:48.433316 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/indexo.php"] [unique_id "aoSADPcmepr5_nHgLbMxTQAAAl8"] [Tue Aug 18 12:53:48.456704 2026] [security2:error] [pid 67073:tid 67325] [client 20.163.43.14:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/gecko.php"] [unique_id "aoSADPcmepr5_nHgLbMxTgAAAow"] [Tue Aug 18 12:53:48.478411 2026] [security2:error] [pid 66623:tid 66799] [client 157.20.138.62:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADNO5rbWdOArH04J8qwAAASs"] [Tue Aug 18 12:53:48.478513 2026] [security2:error] [pid 66623:tid 66799] [client 157.20.138.62:51812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADNO5rbWdOArH04J8qwAAASs"] [Tue Aug 18 12:53:48.498739 2026] [security2:error] [pid 67073:tid 67218] [client 20.48.236.86:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/k.php"] [unique_id "aoSADPcmepr5_nHgLbMxUQAAAiE"] [Tue Aug 18 12:53:48.508074 2026] [security2:error] [pid 67073:tid 67124] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/z.php"] [unique_id "aoSADPcmepr5_nHgLbMxUgACJjA"] [Tue Aug 18 12:53:48.531701 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.56.190:17886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ie.php"] [unique_id "aoSADPcmepr5_nHgLbMxVAAAAjk"] [Tue Aug 18 12:53:48.542655 2026] [security2:error] [pid 67073:tid 67317] [client 20.171.51.14:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/q.php"] [unique_id "aoSADPcmepr5_nHgLbMxVQAAAoQ"] [Tue Aug 18 12:53:48.551603 2026] [security2:error] [pid 66623:tid 66779] [client 158.158.74.177:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-2019.php"] [unique_id "aoSADNO5rbWdOArH04J8rAAAARc"] [Tue Aug 18 12:53:48.570624 2026] [security2:error] [pid 66623:tid 66839] [client 135.225.75.187:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/Okxob.php"] [unique_id "aoSADNO5rbWdOArH04J8rQAAAVM"] [Tue Aug 18 12:53:48.592924 2026] [security2:error] [pid 66623:tid 66837] [client 20.51.153.15:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/smtp.php"] [unique_id "aoSADNO5rbWdOArH04J8rgAAAVE"] [Tue Aug 18 12:53:48.605945 2026] [security2:error] [pid 67073:tid 67315] [client 172.202.39.151:44465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/bb.php"] [unique_id "aoSADPcmepr5_nHgLbMxWAAAAoI"] [Tue Aug 18 12:53:48.610477 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.56.190:45194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/kc.php"] [unique_id "aoSADNO5rbWdOArH04J8rwAAAW4"] [Tue Aug 18 12:53:48.625657 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:48.625939 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:48.658012 2026] [security2:error] [pid 67073:tid 67261] [client 158.23.17.4:15135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/tt.php"] [unique_id "aoSADPcmepr5_nHgLbMxXgAAAkw"] [Tue Aug 18 12:53:48.667919 2026] [security2:error] [pid 66623:tid 66811] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/rezor.php"] [unique_id "aoSADNO5rbWdOArH04J8sAAAATc"] [Tue Aug 18 12:53:48.671012 2026] [security2:error] [pid 67073:tid 67229] [client 4.223.164.152:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/zoo1.php"] [unique_id "aoSADPcmepr5_nHgLbMxXwAAAiw"] [Tue Aug 18 12:53:48.679204 2026] [security2:error] [pid 67073:tid 67235] [client 213.35.127.232:55879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSADPcmepr5_nHgLbMxYwAAAjI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:48.680097 2026] [security2:error] [pid 67073:tid 67126] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env"] [unique_id "aoSADPcmepr5_nHgLbMxYgACczI"] [Tue Aug 18 12:53:48.690805 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/222.php"] [unique_id "aoSADPcmepr5_nHgLbMxaAACOz4"] [Tue Aug 18 12:53:48.738738 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.136.165:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/222.php"] [unique_id "aoSADNO5rbWdOArH04J8sQAAARU"] [Tue Aug 18 12:53:48.741173 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.61.152:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/sky.php"] [unique_id "aoSADPcmepr5_nHgLbMxawAAAk8"] [Tue Aug 18 12:53:48.827930 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-blink.php"] [unique_id "aoSADNO5rbWdOArH04J8sgAAAVA"] [Tue Aug 18 12:53:48.839808 2026] [security2:error] [pid 66623:tid 66879] [client 52.238.210.254:10205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/as.php"] [unique_id "aoSADNO5rbWdOArH04J8swAAAXs"] [Tue Aug 18 12:53:48.853678 2026] [security2:error] [pid 66623:tid 66853] [client 20.91.215.254:20192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/Session.php"] [unique_id "aoSADNO5rbWdOArH04J8tAAAAWE"] [Tue Aug 18 12:53:48.854426 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSADPcmepr5_nHgLbMxcAAAAmE"] [Tue Aug 18 12:53:48.904146 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:13340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/teste.php"] [unique_id "aoSADPcmepr5_nHgLbMxcwAAApE"] [Tue Aug 18 12:53:48.928398 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:48.928663 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:48.977320 2026] [security2:error] [pid 66623:tid 66808] [client 40.85.222.29:37705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSADNO5rbWdOArH04J8tQAAATQ"] [Tue Aug 18 12:53:48.978750 2026] [security2:error] [pid 67073:tid 67243] [client 20.226.56.190:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nw.php"] [unique_id "aoSADPcmepr5_nHgLbMxfAAAAjo"] [Tue Aug 18 12:53:48.992558 2026] [security2:error] [pid 67073:tid 67253] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSADPcmepr5_nHgLbMxfQAAAkQ"] [Tue Aug 18 12:53:48.993100 2026] [security2:error] [pid 66623:tid 66889] [client 20.65.98.162:23910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/scxy.php"] [unique_id "aoSADNO5rbWdOArH04J8tgAAAYU"] [Tue Aug 18 12:53:49.018713 2026] [security2:error] [pid 67073:tid 67212] [client 20.104.100.201:53871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSADfcmepr5_nHgLbMxgQAAAhs"] [Tue Aug 18 12:53:49.046631 2026] [security2:error] [pid 67073:tid 67322] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/akismet.php"] [unique_id "aoSADfcmepr5_nHgLbMxhQAAAok"] [Tue Aug 18 12:53:49.050918 2026] [security2:error] [pid 66623:tid 66855] [client 20.48.236.86:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/82.php"] [unique_id "aoSADdO5rbWdOArH04J8uAAAAWM"] [Tue Aug 18 12:53:49.072996 2026] [security2:error] [pid 67073:tid 67260] [client 74.248.18.37:38465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSADfcmepr5_nHgLbMxhgAAAks"] [Tue Aug 18 12:53:49.102703 2026] [security2:error] [pid 67073:tid 67237] [client 20.171.51.14:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xf.php"] [unique_id "aoSADfcmepr5_nHgLbMxigAAAjQ"] [Tue Aug 18 12:53:49.103747 2026] [security2:error] [pid 67073:tid 67233] [client 20.171.51.14:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tq.php"] [unique_id "aoSADfcmepr5_nHgLbMxiwAAAjA"] [Tue Aug 18 12:53:49.158234 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.136.165:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/G-in.php"] [unique_id "aoSADfcmepr5_nHgLbMxkwAAAjg"] [Tue Aug 18 12:53:49.158418 2026] [security2:error] [pid 67073:tid 67158] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxlAACTlI"], referer: https://transevang.com.br/login [Tue Aug 18 12:53:49.179921 2026] [security2:error] [pid 67073:tid 67310] [client 20.51.153.15:13413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/local.php"] [unique_id "aoSADfcmepr5_nHgLbMxlQAAAn0"] [Tue Aug 18 12:53:49.186702 2026] [security2:error] [pid 67073:tid 67288] [client 158.158.74.177:25893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/cjfuns.php"] [unique_id "aoSADfcmepr5_nHgLbMxmAAAAmc"] [Tue Aug 18 12:53:49.195228 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:3143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/aa.php"] [unique_id "aoSADfcmepr5_nHgLbMxmgAAAmA"] [Tue Aug 18 12:53:49.221934 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file5.php"] [unique_id "aoSADfcmepr5_nHgLbMxoAAAAiU"] [Tue Aug 18 12:53:49.223350 2026] [security2:error] [pid 67073:tid 67286] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxjQACZTY"] [Tue Aug 18 12:53:49.228296 2026] [security2:error] [pid 67073:tid 67266] [client 20.42.19.40:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/xfun.php"] [unique_id "aoSADfcmepr5_nHgLbMxogAAAlE"] [Tue Aug 18 12:53:49.228346 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:49.228631 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:49.273111 2026] [security2:error] [pid 66623:tid 66867] [client 20.226.56.190:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/jn.php"] [unique_id "aoSADdO5rbWdOArH04J8uQAAAW8"] [Tue Aug 18 12:53:49.275080 2026] [security2:error] [pid 67073:tid 67227] [client 4.223.164.152:28486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSADfcmepr5_nHgLbMxowAAAio"] [Tue Aug 18 12:53:49.296480 2026] [security2:error] [pid 67073:tid 67208] [client 52.238.210.254:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/k.php"] [unique_id "aoSADfcmepr5_nHgLbMxpAAAAhc"] [Tue Aug 18 12:53:49.302997 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSADdO5rbWdOArH04J8ugAAAV4"] [Tue Aug 18 12:53:49.326958 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.56.190:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sb.php"] [unique_id "aoSADdO5rbWdOArH04J8uwAAASc"] [Tue Aug 18 12:53:49.352536 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/zoo2.php"] [unique_id "aoSADfcmepr5_nHgLbMxpgAAAmQ"] [Tue Aug 18 12:53:49.358986 2026] [security2:error] [pid 67073:tid 67294] [client 104.209.144.33:34129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSADfcmepr5_nHgLbMxpwAAAm0"] [Tue Aug 18 12:53:49.387088 2026] [security2:error] [pid 67073:tid 67273] [client 158.23.17.4:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/mq.php"] [unique_id "aoSADfcmepr5_nHgLbMxqAAAAlg"] [Tue Aug 18 12:53:49.427550 2026] [security2:error] [pid 66623:tid 66831] [client 20.51.153.15:13403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSADdO5rbWdOArH04J8vAAAAUs"] [Tue Aug 18 12:53:49.494586 2026] [security2:error] [pid 66623:tid 66838] [client 20.91.215.254:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSADdO5rbWdOArH04J8vQAAAVI"] [Tue Aug 18 12:53:49.516813 2026] [security2:error] [pid 67073:tid 67210] [client 143.244.161.13:50956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "stampi.ind.br"] [uri "/.env"] [unique_id "aoSADfcmepr5_nHgLbMxrQAAAhk"] [Tue Aug 18 12:53:49.528318 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:49.528582 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:49.546037 2026] [security2:error] [pid 67073:tid 67315] [client 135.225.75.187:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/file59.php"] [unique_id "aoSADfcmepr5_nHgLbMxrwAAAoI"] [Tue Aug 18 12:53:49.547600 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:3157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/0x.php"] [unique_id "aoSADfcmepr5_nHgLbMxsAAAAkU"] [Tue Aug 18 12:53:49.562975 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/cv.php"] [unique_id "aoSADfcmepr5_nHgLbMxsQAAAlA"] [Tue Aug 18 12:53:49.575820 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xxx.php"] [unique_id "aoSADfcmepr5_nHgLbMxswAAAi4"] [Tue Aug 18 12:53:49.587983 2026] [security2:error] [pid 66623:tid 66827] [client 20.226.56.190:52083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xj.php"] [unique_id "aoSADdO5rbWdOArH04J8vgAAAUc"] [Tue Aug 18 12:53:49.604830 2026] [security2:error] [pid 67073:tid 67199] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/G-in.php"] [unique_id "aoSADfcmepr5_nHgLbMxtQACans"] [Tue Aug 18 12:53:49.676202 2026] [security2:error] [pid 67073:tid 67279] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSADfcmepr5_nHgLbMxtwAAAl4"] [Tue Aug 18 12:53:49.685400 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.56.190:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anuariodoaco.siderurgiabrasil.com.br"] [uri "/bf.php"] [unique_id "aoSADfcmepr5_nHgLbMxuQAAAmg"] [Tue Aug 18 12:53:49.690193 2026] [security2:error] [pid 67073:tid 67221] [client 172.202.39.151:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxugAAAiQ"] [Tue Aug 18 12:53:49.694469 2026] [security2:error] [pid 67073:tid 67292] [client 20.51.153.15:13370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ninja.php"] [unique_id "aoSADfcmepr5_nHgLbMxuwAAAms"] [Tue Aug 18 12:53:49.694494 2026] [security2:error] [pid 66623:tid 66802] [client 213.35.127.232:56091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSADdO5rbWdOArH04J8vwAAAS4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:53:49.720002 2026] [security2:error] [pid 67073:tid 67235] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxwgAAAjI"] [Tue Aug 18 12:53:49.722497 2026] [security2:error] [pid 67073:tid 67269] [client 149.34.210.141:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxwwAAAlQ"] [Tue Aug 18 12:53:49.728840 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:54271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/.admin.php"] [unique_id "aoSADfcmepr5_nHgLbMxxQAAAjs"] [Tue Aug 18 12:53:49.737770 2026] [security2:error] [pid 67073:tid 67213] [client 52.238.210.254:10191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSADfcmepr5_nHgLbMxxgAAAhw"] [Tue Aug 18 12:53:49.741074 2026] [security2:error] [pid 66623:tid 66815] [client 20.171.51.14:15799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gb.php"] [unique_id "aoSADdO5rbWdOArH04J8wAAAATs"] [Tue Aug 18 12:53:49.746610 2026] [security2:error] [pid 67073:tid 67198] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.bak"] [unique_id "aoSADfcmepr5_nHgLbMxyAACbHo"] [Tue Aug 18 12:53:49.746620 2026] [security2:error] [pid 67073:tid 67080] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.backup"] [unique_id "aoSADfcmepr5_nHgLbMxxwACbAQ"] [Tue Aug 18 12:53:49.746816 2026] [security2:error] [pid 67073:tid 67191] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.old"] [unique_id "aoSADfcmepr5_nHgLbMxyQACbHM"] [Tue Aug 18 12:53:49.782565 2026] [security2:error] [pid 66623:tid 66877] [client 132.196.61.152:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/xyn.php"] [unique_id "aoSADdO5rbWdOArH04J8wgAAAXk"] [Tue Aug 18 12:53:49.789831 2026] [security2:error] [pid 67073:tid 67190] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxygACbHI"], referer: https://transevang.com.br/wp-admin/ [Tue Aug 18 12:53:49.790053 2026] [security2:error] [pid 67073:tid 67177] [remote 34.62.54.143:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSADfcmepr5_nHgLbMxywACbGU"], referer: https://transevang.com.br/wp-admin/ [Tue Aug 18 12:53:49.812445 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:43524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSADfcmepr5_nHgLbMxzAAAAk8"] [Tue Aug 18 12:53:49.822330 2026] [security2:error] [pid 67073:tid 67200] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xxx.php"] [unique_id "aoSADfcmepr5_nHgLbMxzQACfHw"] [Tue Aug 18 12:53:49.893064 2026] [security2:error] [pid 66623:tid 66822] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSADdO5rbWdOArH04J8wwAAAUI"] [Tue Aug 18 12:53:49.902997 2026] [security2:error] [pid 67073:tid 67276] [client 158.158.74.177:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSADfcmepr5_nHgLbMxzwAAAls"] [Tue Aug 18 12:53:49.992638 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.136.165:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/un.php"] [unique_id "aoSADdO5rbWdOArH04J8xAAAAYY"] [Tue Aug 18 12:53:50.022466 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gelay.php"] [unique_id "aoSADtO5rbWdOArH04J8xQAAAUQ"] [Tue Aug 18 12:53:50.026637 2026] [security2:error] [pid 67073:tid 67269] [client 149.34.210.141:59032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSADfcmepr5_nHgLbMxwwAAAlQ"] [Tue Aug 18 12:53:50.071083 2026] [security2:error] [pid 66623:tid 66833] [client 20.51.153.15:13344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/phpprobe.php"] [unique_id "aoSADtO5rbWdOArH04J8xgAAAU0"] [Tue Aug 18 12:53:50.083799 2026] [security2:error] [pid 66623:tid 66814] [client 20.48.236.86:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/inso.php"] [unique_id "aoSADtO5rbWdOArH04J8xwAAATo"] [Tue Aug 18 12:53:50.086497 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.56.190:28267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ns.php"] [unique_id "aoSADvcmepr5_nHgLbMx0wAAAjM"] [Tue Aug 18 12:53:50.130991 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:18838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/about.php"] [unique_id "aoSADvcmepr5_nHgLbMx1AAAAiM"] [Tue Aug 18 12:53:50.339879 2026] [security2:error] [pid 67073:tid 67228] [client 20.171.51.14:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jp.php"] [unique_id "aoSADvcmepr5_nHgLbMx1QAAAis"] [Tue Aug 18 12:53:50.421421 2026] [security2:error] [pid 67073:tid 67313] [client 4.232.151.198:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSADvcmepr5_nHgLbMx1gAAAoA"] [Tue Aug 18 12:53:50.476950 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.100.201:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/thoms.php"] [unique_id "aoSADvcmepr5_nHgLbMx1wAAAkI"] [Tue Aug 18 12:53:50.560583 2026] [security2:error] [pid 67073:tid 67311] [client 20.48.236.86:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/dex.php"] [unique_id "aoSADvcmepr5_nHgLbMx2AAAAn4"] [Tue Aug 18 12:53:50.588862 2026] [security2:error] [pid 67073:tid 67272] [client 20.163.43.14:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/zxz.php"] [unique_id "aoSADvcmepr5_nHgLbMx2QAAAlc"] [Tue Aug 18 12:53:50.631626 2026] [security2:error] [pid 67073:tid 67327] [client 158.23.17.4:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/13.php"] [unique_id "aoSADvcmepr5_nHgLbMx2gAAAo4"] [Tue Aug 18 12:53:50.670987 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/system_log.php"] [unique_id "aoSADvcmepr5_nHgLbMx2wAAAkk"] [Tue Aug 18 12:53:50.726861 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:50.727129 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:50.770021 2026] [security2:error] [pid 67073:tid 67316] [client 20.171.51.14:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/un.php"] [unique_id "aoSADvcmepr5_nHgLbMx3QAAAoM"] [Tue Aug 18 12:53:50.772777 2026] [security2:error] [pid 67073:tid 67290] [client 135.225.75.187:9462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/eauu.php"] [unique_id "aoSADvcmepr5_nHgLbMx3gAAAmk"] [Tue Aug 18 12:53:50.807680 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSADvcmepr5_nHgLbMx3wAAAik"] [Tue Aug 18 12:53:50.829105 2026] [security2:error] [pid 67073:tid 67207] [client 20.65.98.162:18926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ws13.php"] [unique_id "aoSADvcmepr5_nHgLbMx4AAAAhY"] [Tue Aug 18 12:53:50.878438 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:50.878717 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:50.946311 2026] [security2:error] [pid 66623:tid 66800] [client 20.100.169.31:47511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.julioalvez.com.br"] [uri "/adminfuns.php"] [unique_id "aoSADtO5rbWdOArH04J8yQAAASw"] [Tue Aug 18 12:53:51.015213 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eq.php"] [unique_id "aoSAD_cmepr5_nHgLbMx4gAAAlE"] [Tue Aug 18 12:53:51.043286 2026] [security2:error] [pid 67073:tid 67248] [client 20.48.236.86:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/puc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx4wAAAj8"] [Tue Aug 18 12:53:51.052888 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:51.053139 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:51.059061 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAD9O5rbWdOArH04J8ygAAASo"] [Tue Aug 18 12:53:51.159496 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.74.177:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAD_cmepr5_nHgLbMx5gAAAmA"] [Tue Aug 18 12:53:51.160874 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAD_cmepr5_nHgLbMx5wAAAlM"] [Tue Aug 18 12:53:51.188664 2026] [security2:error] [pid 66623:tid 66769] [client 52.238.210.254:30369] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSAD9O5rbWdOArH04J8ywAAAQ0"] [Tue Aug 18 12:53:51.188758 2026] [security2:error] [pid 66623:tid 66769] [client 52.238.210.254:30369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSAD9O5rbWdOArH04J8ywAAAQ0"] [Tue Aug 18 12:53:51.255829 2026] [security2:error] [pid 67073:tid 67245] [client 157.51.166.53:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx6AAAAjw"] [Tue Aug 18 12:53:51.255945 2026] [security2:error] [pid 67073:tid 67245] [client 157.51.166.53:51940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAD_cmepr5_nHgLbMx6AAAAjw"] [Tue Aug 18 12:53:51.265692 2026] [security2:error] [pid 66623:tid 66876] [client 20.51.153.15:13347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/wp-title.php"] [unique_id "aoSAD9O5rbWdOArH04J8zAAAAXg"] [Tue Aug 18 12:53:51.474441 2026] [security2:error] [pid 66623:tid 66774] [client 74.248.136.165:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/autogooey.php"] [unique_id "aoSAD9O5rbWdOArH04J8zQAAARI"] [Tue Aug 18 12:53:51.480879 2026] [security2:error] [pid 66623:tid 66845] [client 20.104.85.180:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAD9O5rbWdOArH04J8zgAAAVk"] [Tue Aug 18 12:53:51.527208 2026] [security2:error] [pid 66623:tid 66781] [client 4.223.164.152:64687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/wsomini.php"] [unique_id "aoSAD9O5rbWdOArH04J8zwAAARk"] [Tue Aug 18 12:53:51.605922 2026] [security2:error] [pid 67073:tid 67175] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/un.php"] [unique_id "aoSAD_cmepr5_nHgLbMx8wACQ2M"] [Tue Aug 18 12:53:51.620431 2026] [security2:error] [pid 67073:tid 67263] [client 20.48.236.86:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/inso.php"] [unique_id "aoSAD_cmepr5_nHgLbMx9QAAAk4"] [Tue Aug 18 12:53:51.648214 2026] [security2:error] [pid 67073:tid 67249] [client 20.91.215.254:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/abcd.php"] [unique_id "aoSAD_cmepr5_nHgLbMx9gAAAkA"] [Tue Aug 18 12:53:51.659662 2026] [security2:error] [pid 66623:tid 66796] [client 4.232.151.198:27770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/vx.php"] [unique_id "aoSAD9O5rbWdOArH04J80AAAASg"] [Tue Aug 18 12:53:51.829811 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/so.php"] [unique_id "aoSAD9O5rbWdOArH04J80wAAASM"] [Tue Aug 18 12:53:52.031754 2026] [security2:error] [pid 66623:tid 66891] [client 104.209.144.33:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAENO5rbWdOArH04J81gAAAYc"] [Tue Aug 18 12:53:52.118034 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/aa.php"] [unique_id "aoSAEPcmepr5_nHgLbMx-gAAAl8"] [Tue Aug 18 12:53:52.162234 2026] [security2:error] [pid 67073:tid 67303] [client 52.238.210.254:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/x.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_AAAAnY"] [Tue Aug 18 12:53:52.362812 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_QAAApI"] [Tue Aug 18 12:53:52.417537 2026] [security2:error] [pid 67073:tid 67324] [client 172.202.39.151:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/k.php"] [unique_id "aoSAEPcmepr5_nHgLbMx_wAAAos"] [Tue Aug 18 12:53:52.489203 2026] [security2:error] [pid 67073:tid 67254] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/bajah.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAAAAAkU"] [Tue Aug 18 12:53:52.489423 2026] [security2:error] [pid 67073:tid 67265] [client 20.171.51.14:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ep.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAgAAAlA"] [Tue Aug 18 12:53:52.489661 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gk.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAQAAAoQ"] [Tue Aug 18 12:53:52.512232 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/styles.php"] [unique_id "aoSAEPcmepr5_nHgLbMyAwAAAmo"] [Tue Aug 18 12:53:52.515566 2026] [security2:error] [pid 67073:tid 67217] [client 74.248.136.165:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sty.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBAAAAiA"] [Tue Aug 18 12:53:52.568209 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBQAAAl4"] [Tue Aug 18 12:53:52.635886 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.56.190:47155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wn.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBgAAAms"] [Tue Aug 18 12:53:52.736324 2026] [security2:error] [pid 67073:tid 67273] [client 158.158.74.177:9486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/import.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCAAAAlg"] [Tue Aug 18 12:53:52.805660 2026] [security2:error] [pid 66623:tid 66881] [client 160.120.140.123:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAENO5rbWdOArH04J84QAAAX0"] [Tue Aug 18 12:53:52.805791 2026] [security2:error] [pid 66623:tid 66881] [client 160.120.140.123:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAENO5rbWdOArH04J84QAAAX0"] [Tue Aug 18 12:53:52.824571 2026] [security2:error] [pid 67073:tid 67264] [client 20.51.153.15:13367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/server.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCQAAAk8"] [Tue Aug 18 12:53:52.842941 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.85.180:18843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/f35.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCgAAAnw"] [Tue Aug 18 12:53:52.933425 2026] [security2:error] [pid 67073:tid 67205] [client 52.238.210.254:10203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAEPcmepr5_nHgLbMyCwAAAhQ"] [Tue Aug 18 12:53:52.988981 2026] [security2:error] [pid 67073:tid 67089] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/autogooey.php"] [unique_id "aoSAEPcmepr5_nHgLbMyDAACWw0"] [Tue Aug 18 12:53:53.056895 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.6.191:6543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAEfcmepr5_nHgLbMyDQAAAko"] [Tue Aug 18 12:53:53.152995 2026] [security2:error] [pid 66623:tid 66885] [client 20.42.19.40:2199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/p.php"] [unique_id "aoSAEdO5rbWdOArH04J84gAAAYE"] [Tue Aug 18 12:53:53.180677 2026] [security2:error] [pid 66623:tid 66780] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/ajax.php"] [unique_id "aoSAEdO5rbWdOArH04J84wAAARg"] [Tue Aug 18 12:53:53.210949 2026] [security2:error] [pid 66623:tid 66768] [client 20.51.153.15:13409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/xinfo.php"] [unique_id "aoSAEdO5rbWdOArH04J85AAAAQw"] [Tue Aug 18 12:53:53.211699 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/kj.php"] [unique_id "aoSAEfcmepr5_nHgLbMyFwAAAiE"] [Tue Aug 18 12:53:53.289677 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.100.201:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAEdO5rbWdOArH04J85QAAARs"] [Tue Aug 18 12:53:53.377344 2026] [security2:error] [pid 67073:tid 67284] [client 4.223.164.152:37284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "veloxxprodutos.com.br"] [uri "/vr.php"] [unique_id "aoSAEfcmepr5_nHgLbMyGQAAAmM"] [Tue Aug 18 12:53:53.410599 2026] [security2:error] [pid 66623:tid 66835] [client 20.65.98.162:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/btx25.php"] [unique_id "aoSAEdO5rbWdOArH04J85gAAAU8"] [Tue Aug 18 12:53:53.573553 2026] [security2:error] [pid 66623:tid 66779] [client 74.248.133.44:15359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/f5.php"] [unique_id "aoSAEdO5rbWdOArH04J86gAAARc"] [Tue Aug 18 12:53:53.582274 2026] [security2:error] [pid 67073:tid 67194] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sty.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHAACgHY"] [Tue Aug 18 12:53:53.620849 2026] [security2:error] [pid 67073:tid 67238] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/Cachex.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHQAAAjU"] [Tue Aug 18 12:53:53.689982 2026] [security2:error] [pid 67073:tid 67297] [client 20.42.19.40:2732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAEfcmepr5_nHgLbMyHwAAAnA"] [Tue Aug 18 12:53:53.692657 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/0x.php"] [unique_id "aoSAEfcmepr5_nHgLbMyIAAAAlc"] [Tue Aug 18 12:53:53.760823 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:53.761083 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:53.828934 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEfcmepr5_nHgLbMyJQAAAi0"] [Tue Aug 18 12:53:53.829026 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEfcmepr5_nHgLbMyJQAAAi0"] [Tue Aug 18 12:53:53.940203 2026] [security2:error] [pid 66623:tid 66828] [client 104.209.144.33:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/weozh.php"] [unique_id "aoSAEdO5rbWdOArH04J87AAAAUg"] [Tue Aug 18 12:53:54.020951 2026] [security2:error] [pid 67073:tid 67260] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAEvcmepr5_nHgLbMyJgAAAks"] [Tue Aug 18 12:53:54.025518 2026] [security2:error] [pid 66623:tid 66813] [client 158.158.74.177:9534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/cropper.php"] [unique_id "aoSAEtO5rbWdOArH04J87wAAATk"] [Tue Aug 18 12:53:54.060322 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wio.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKAACkBw"] [Tue Aug 18 12:53:54.064657 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rf.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKQAAAns"] [Tue Aug 18 12:53:54.084652 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.100.201:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/root.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKgAAAmk"] [Tue Aug 18 12:53:54.152121 2026] [security2:error] [pid 66623:tid 66818] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAEtO5rbWdOArH04J88AAAAT4"] [Tue Aug 18 12:53:54.174043 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:20199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/languages.php"] [unique_id "aoSAEvcmepr5_nHgLbMyKwAAAj0"] [Tue Aug 18 12:53:54.229198 2026] [security2:error] [pid 67073:tid 67207] [client 45.131.195.116:54925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/"] [unique_id "aoSAEvcmepr5_nHgLbMyLwAAAhY"] [Tue Aug 18 12:53:54.316321 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:58327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wio.php"] [unique_id "aoSAEvcmepr5_nHgLbMyMAAAAmU"] [Tue Aug 18 12:53:54.400359 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/evil.php"] [unique_id "aoSAEvcmepr5_nHgLbMyMwAAAmA"] [Tue Aug 18 12:53:54.455262 2026] [security2:error] [pid 66623:tid 66809] [client 114.5.214.109:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEtO5rbWdOArH04J88wAAATU"] [Tue Aug 18 12:53:54.523912 2026] [security2:error] [pid 66623:tid 66789] [client 104.209.144.33:33710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/rymmm.php"] [unique_id "aoSAEtO5rbWdOArH04J89AAAASE"] [Tue Aug 18 12:53:54.681425 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xynz1.php"] [unique_id "aoSAEtO5rbWdOArH04J89QAAAX8"] [Tue Aug 18 12:53:54.696458 2026] [security2:error] [pid 66623:tid 66867] [client 52.238.210.254:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/hosty.php"] [unique_id "aoSAEtO5rbWdOArH04J89gAAAW8"] [Tue Aug 18 12:53:54.703265 2026] [security2:error] [pid 67073:tid 67240] [client 178.153.171.161:27589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBwAAAjc"] [Tue Aug 18 12:53:54.703366 2026] [security2:error] [pid 67073:tid 67240] [client 178.153.171.161:27589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEPcmepr5_nHgLbMyBwAAAjc"] [Tue Aug 18 12:53:54.752869 2026] [security2:error] [pid 67073:tid 67113] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/1061.php"] [unique_id "aoSAEvcmepr5_nHgLbMyNwACTiU"] [Tue Aug 18 12:53:54.757991 2026] [security2:error] [pid 66623:tid 66795] [client 172.202.39.151:31570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAEtO5rbWdOArH04J8-AAAASc"] [Tue Aug 18 12:53:54.829186 2026] [security2:error] [pid 66623:tid 66848] [client 20.51.153.15:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/sym.php"] [unique_id "aoSAEtO5rbWdOArH04J8-QAAAVw"] [Tue Aug 18 12:53:54.949515 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:54.949799 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:55.061510 2026] [security2:error] [pid 67073:tid 67300] [client 213.202.253.4:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affaripericiacontabil.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSAE_cmepr5_nHgLbMyOQAAAnM"], referer: www.google.com [Tue Aug 18 12:53:55.094553 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAE_cmepr5_nHgLbMyOgAAAhU"] [Tue Aug 18 12:53:55.099753 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pw.php"] [unique_id "aoSAE9O5rbWdOArH04J8_AAAAVg"] [Tue Aug 18 12:53:55.138384 2026] [security2:error] [pid 66623:tid 66874] [client 20.51.153.15:13422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gruposchopan.com.br"] [uri "/ye.php"] [unique_id "aoSAE9O5rbWdOArH04J8_QAAAXY"] [Tue Aug 18 12:53:55.194441 2026] [security2:error] [pid 67073:tid 67331] [client 20.48.236.86:10758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/puc.php"] [unique_id "aoSAE_cmepr5_nHgLbMyPQAAApI"] [Tue Aug 18 12:53:55.345758 2026] [security2:error] [pid 66623:tid 66871] [client 45.131.195.129:34015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "aoSAE9O5rbWdOArH04J8_wAAAXM"] [Tue Aug 18 12:53:55.359533 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.136.165:36391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/1061.php"] [unique_id "aoSAE9O5rbWdOArH04J9AAAAAYY"] [Tue Aug 18 12:53:55.396298 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.133.44:32424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/al.php"] [unique_id "aoSAE9O5rbWdOArH04J9AQAAAWo"] [Tue Aug 18 12:53:55.468292 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:50707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAE_cmepr5_nHgLbMyQQAAAl0"] [Tue Aug 18 12:53:55.480763 2026] [security2:error] [pid 66623:tid 66872] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSAE9O5rbWdOArH04J9AgAAAXQ"] [Tue Aug 18 12:53:55.511748 2026] [security2:error] [pid 66623:tid 66892] [client 20.250.13.23:21481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAE9O5rbWdOArH04J9AwAAAYg"] [Tue Aug 18 12:53:55.511888 2026] [security2:error] [pid 67073:tid 67131] [remote 84.205.178.135:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSAE_cmepr5_nHgLbMyQwACXjc"] [Tue Aug 18 12:53:55.552329 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:55.552584 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:55.625311 2026] [security2:error] [pid 66623:tid 66832] [client 52.238.210.254:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/test1.php"] [unique_id "aoSAE9O5rbWdOArH04J9BAAAAUw"] [Tue Aug 18 12:53:55.742824 2026] [security2:error] [pid 67073:tid 67314] [client 4.223.164.152:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/org.php"] [unique_id "aoSAE_cmepr5_nHgLbMySAAAAoE"] [Tue Aug 18 12:53:55.829926 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.136.165:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/gec.php"] [unique_id "aoSAE_cmepr5_nHgLbMySgAAAlg"] [Tue Aug 18 12:53:55.835011 2026] [security2:error] [pid 66623:tid 66869] [client 20.104.100.201:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/fpwch.php"] [unique_id "aoSAE9O5rbWdOArH04J9BgAAAXE"] [Tue Aug 18 12:53:55.890383 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:9112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/nw.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTAAAAm4"] [Tue Aug 18 12:53:55.902440 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTQAAAiw"] [Tue Aug 18 12:53:55.936135 2026] [security2:error] [pid 66623:tid 66809] [client 114.5.214.109:49794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAEtO5rbWdOArH04J88wAAATU"] [Tue Aug 18 12:53:55.985480 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gec.php"] [unique_id "aoSAE_cmepr5_nHgLbMyTgACFBo"] [Tue Aug 18 12:53:56.023894 2026] [security2:error] [pid 66623:tid 66798] [client 172.182.200.96:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAFNO5rbWdOArH04J9BwAAASo"] [Tue Aug 18 12:53:56.046679 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:10788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/19.php"] [unique_id "aoSAFPcmepr5_nHgLbMyTwAAAoc"] [Tue Aug 18 12:53:56.107625 2026] [security2:error] [pid 66623:tid 66876] [client 20.42.19.40:2694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/aaa.php"] [unique_id "aoSAFNO5rbWdOArH04J9CQAAAXg"] [Tue Aug 18 12:53:56.205758 2026] [security2:error] [pid 66623:tid 66861] [client 52.238.210.254:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/zwso.php"] [unique_id "aoSAFNO5rbWdOArH04J9CgAAAWk"] [Tue Aug 18 12:53:56.324291 2026] [security2:error] [pid 67073:tid 67228] [client 4.223.164.152:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/imageskir.php"] [unique_id "aoSAFPcmepr5_nHgLbMyVgAAAis"] [Tue Aug 18 12:53:56.376970 2026] [security2:error] [pid 66623:tid 66852] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAFNO5rbWdOArH04J9CwAAAWA"] [Tue Aug 18 12:53:56.464041 2026] [security2:error] [pid 67073:tid 67212] [client 45.131.195.166:58049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.foxalpha.com.br"] [uri "/media/system/js/core.js"] [unique_id "aoSAFPcmepr5_nHgLbMyWAAAAhs"] [Tue Aug 18 12:53:56.595800 2026] [security2:error] [pid 67073:tid 67141] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/scx.php7"] [unique_id "aoSAFPcmepr5_nHgLbMyYgACjkE"] [Tue Aug 18 12:53:56.655769 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:10181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/Geforce.php"] [unique_id "aoSAFPcmepr5_nHgLbMyYwAAAkk"] [Tue Aug 18 12:53:56.705410 2026] [security2:error] [pid 66623:tid 66769] [client 20.250.13.23:23850] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/1.php"] [unique_id "aoSAFNO5rbWdOArH04J9DwAAAQ0"] [Tue Aug 18 12:53:56.705508 2026] [security2:error] [pid 66623:tid 66769] [client 20.250.13.23:23850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/1.php"] [unique_id "aoSAFNO5rbWdOArH04J9DwAAAQ0"] [Tue Aug 18 12:53:56.741651 2026] [security2:error] [pid 67073:tid 67298] [client 158.158.74.177:9390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyawAAAnE"] [Tue Aug 18 12:53:56.748586 2026] [security2:error] [pid 67073:tid 67254] [client 196.12.128.158:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyaQAAAkU"] [Tue Aug 18 12:53:56.748704 2026] [security2:error] [pid 67073:tid 67254] [client 196.12.128.158:55309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAFPcmepr5_nHgLbMyaQAAAkU"] [Tue Aug 18 12:53:56.749538 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/w.php"] [unique_id "aoSAFNO5rbWdOArH04J9EAAAAQ4"] [Tue Aug 18 12:53:56.766154 2026] [security2:error] [pid 66623:tid 66792] [client 172.202.39.151:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/as.php"] [unique_id "aoSAFNO5rbWdOArH04J9EQAAASQ"] [Tue Aug 18 12:53:56.808749 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAFPcmepr5_nHgLbMybAACSD0"] [Tue Aug 18 12:53:56.814278 2026] [security2:error] [pid 67073:tid 67304] [client 20.171.51.14:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vo.php"] [unique_id "aoSAFPcmepr5_nHgLbMybQAAAnc"] [Tue Aug 18 12:53:56.906490 2026] [security2:error] [pid 66623:tid 66891] [client 20.171.51.14:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fn.php"] [unique_id "aoSAFNO5rbWdOArH04J9FAAAAYc"] [Tue Aug 18 12:53:56.971257 2026] [security2:error] [pid 66623:tid 66875] [client 20.24.67.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.67.24.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jgbdominiosolucoes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAFNO5rbWdOArH04J9FQAAAXc"] [Tue Aug 18 12:53:57.057088 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:57.057370 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:57.140593 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.133.44:11456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/inc.php"] [unique_id "aoSAFfcmepr5_nHgLbMycgAAAi0"] [Tue Aug 18 12:53:57.143202 2026] [authz_core:error] [pid 66623:tid 66671] [remote 57.141.8.5:30556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:57.143464 2026] [authz_core:error] [pid 66623:tid 66671] [remote 57.141.8.5:30556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:57.159536 2026] [security2:error] [pid 66623:tid 66880] [client 20.42.19.40:2710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/term.php"] [unique_id "aoSAFdO5rbWdOArH04J9FwAAAXw"] [Tue Aug 18 12:53:57.212273 2026] [security2:error] [pid 66623:tid 66778] [client 4.223.164.152:6883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/indexo.php"] [unique_id "aoSAFdO5rbWdOArH04J9GAAAARY"] [Tue Aug 18 12:53:57.316341 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.136.165:53314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/scx.php7"] [unique_id "aoSAFdO5rbWdOArH04J9GQAAAX0"] [Tue Aug 18 12:53:57.357215 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:57.357471 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:57.393114 2026] [security2:error] [pid 66623:tid 66806] [client 20.100.169.31:32761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAFdO5rbWdOArH04J9GwAAATI"] [Tue Aug 18 12:53:57.399313 2026] [security2:error] [pid 67073:tid 67158] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp5.php"] [unique_id "aoSAFfcmepr5_nHgLbMydQACWVI"] [Tue Aug 18 12:53:57.426709 2026] [security2:error] [pid 66623:tid 66859] [client 192.141.172.134:52511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAFdO5rbWdOArH04J9HAAAAWc"] [Tue Aug 18 12:53:57.426834 2026] [security2:error] [pid 66623:tid 66859] [client 192.141.172.134:52511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAFdO5rbWdOArH04J9HAAAAWc"] [Tue Aug 18 12:53:57.435941 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.98.162:22687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAFfcmepr5_nHgLbMydgAAAh4"] [Tue Aug 18 12:53:57.451514 2026] [security2:error] [pid 67073:tid 67319] [client 132.196.61.152:55348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAFfcmepr5_nHgLbMydwAAAoY"] [Tue Aug 18 12:53:57.501733 2026] [security2:error] [pid 66623:tid 66768] [client 172.202.39.151:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAFdO5rbWdOArH04J9JAAAAQw"] [Tue Aug 18 12:53:57.514133 2026] [security2:error] [pid 67073:tid 67253] [client 20.91.215.254:20197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webeb.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSAFfcmepr5_nHgLbMyeAAAAkQ"] [Tue Aug 18 12:53:57.521805 2026] [autoindex:error] [pid 66623:tid 66780] [client 172.202.39.151:12981] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:57.574291 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.6.191:6626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAFfcmepr5_nHgLbMyeQAAAk4"] [Tue Aug 18 12:53:57.577371 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/mg.php"] [unique_id "aoSAFfcmepr5_nHgLbMyegAAAkA"] [Tue Aug 18 12:53:57.781632 2026] [security2:error] [pid 66623:tid 66807] [client 158.23.17.4:54760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/10.php"] [unique_id "aoSAFdO5rbWdOArH04J9JQAAATM"] [Tue Aug 18 12:53:57.815591 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.136.165:36369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAFfcmepr5_nHgLbMyfgAAAiY"] [Tue Aug 18 12:53:57.851695 2026] [security2:error] [pid 67073:tid 67245] [client 85.208.96.202:32418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cainelli.com.br"] [uri "/blog/page/3/"] [unique_id "aoSAFfcmepr5_nHgLbMyfwAAAjw"] [Tue Aug 18 12:53:57.851807 2026] [security2:error] [pid 67073:tid 67245] [client 85.208.96.202:32418] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cainelli.com.br"] [uri "/blog/page/3/"] [unique_id "aoSAFfcmepr5_nHgLbMyfwAAAjw"] [Tue Aug 18 12:53:57.856935 2026] [security2:error] [pid 66623:tid 66790] [client 172.202.39.151:12981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/403.php"] [unique_id "aoSAFdO5rbWdOArH04J9JwAAASI"] [Tue Aug 18 12:53:57.898479 2026] [security2:error] [pid 66623:tid 66811] [client 4.223.164.152:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAFdO5rbWdOArH04J9KAAAATc"] [Tue Aug 18 12:53:57.974882 2026] [security2:error] [pid 67073:tid 67231] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAFfcmepr5_nHgLbMygAAAAi4"] [Tue Aug 18 12:53:58.095905 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/a2.php"] [unique_id "aoSAFvcmepr5_nHgLbMygQACXk4"] [Tue Aug 18 12:53:58.296349 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/archive.php"] [unique_id "aoSAFtO5rbWdOArH04J9KQAAARo"] [Tue Aug 18 12:53:58.339706 2026] [security2:error] [pid 66623:tid 66812] [client 20.100.169.31:15049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/ww5.php"] [unique_id "aoSAFtO5rbWdOArH04J9KgAAATg"] [Tue Aug 18 12:53:58.346974 2026] [security2:error] [pid 66623:tid 66813] [client 20.171.51.14:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kf.php"] [unique_id "aoSAFtO5rbWdOArH04J9KwAAATk"] [Tue Aug 18 12:53:58.376919 2026] [security2:error] [pid 67073:tid 67132] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/app.php"] [unique_id "aoSAFvcmepr5_nHgLbMyjwACOzg"] [Tue Aug 18 12:53:58.419332 2026] [security2:error] [pid 67073:tid 67213] [client 4.232.151.198:28398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.leguizaimoveis.com.br"] [uri "/wap.php"] [unique_id "aoSAFvcmepr5_nHgLbMynQAAAhw"] [Tue Aug 18 12:53:58.484587 2026] [security2:error] [pid 67073:tid 67251] [client 5.253.205.188:35582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/forumacplibinserts.sql"] [unique_id "aoSAFvcmepr5_nHgLbMyngAAAkI"], referer: https://medihub.com.br/forumacplibinserts.sql [Tue Aug 18 12:53:58.525776 2026] [security2:error] [pid 67073:tid 67264] [client 40.85.222.29:36668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAFvcmepr5_nHgLbMynwAAAk8"] [Tue Aug 18 12:53:58.630404 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wu.php"] [unique_id "aoSAFvcmepr5_nHgLbMypwAAAlI"] [Tue Aug 18 12:53:58.675833 2026] [security2:error] [pid 67073:tid 67330] [client 104.209.144.33:25340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAFvcmepr5_nHgLbMyqQAAApE"] [Tue Aug 18 12:53:58.678653 2026] [security2:error] [pid 67073:tid 67221] [client 172.182.200.96:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAFvcmepr5_nHgLbMyqwAAAiQ"] [Tue Aug 18 12:53:58.763769 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:18007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAFvcmepr5_nHgLbMyvgAAAog"] [Tue Aug 18 12:53:58.849928 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.136.165:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp5.php"] [unique_id "aoSAFvcmepr5_nHgLbMyywAAAng"] [Tue Aug 18 12:53:58.854324 2026] [autoindex:error] [pid 67073:tid 67099] [remote 135.225.75.187:0] AH01276: Cannot serve directory /home3/savanasolucoes/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:53:58.885870 2026] [security2:error] [pid 67073:tid 67311] [client 20.42.19.40:2884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/7.php"] [unique_id "aoSAFvcmepr5_nHgLbMyzwAAAn4"] [Tue Aug 18 12:53:58.954144 2026] [security2:error] [pid 67073:tid 67322] [client 158.23.17.4:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/te.php"] [unique_id "aoSAFvcmepr5_nHgLbMy0AAAAok"] [Tue Aug 18 12:53:59.008135 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.100.201:53868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/reop3.php"] [unique_id "aoSAF_cmepr5_nHgLbMy0QAAAkk"] [Tue Aug 18 12:53:59.132376 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:41188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSAF9O5rbWdOArH04J9PgAAASk"] [Tue Aug 18 12:53:59.162116 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:59.162417 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:59.206871 2026] [security2:error] [pid 67073:tid 67327] [client 158.158.74.177:9395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAF_cmepr5_nHgLbMy1QAAAo4"] [Tue Aug 18 12:53:59.239138 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:28384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/2.php"] [unique_id "aoSAF_cmepr5_nHgLbMy1gAAAig"] [Tue Aug 18 12:53:59.292144 2026] [security2:error] [pid 66623:tid 66846] [client 20.118.172.148:47282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/222.php"] [unique_id "aoSAF9O5rbWdOArH04J9RQAAAVo"] [Tue Aug 18 12:53:59.292186 2026] [security2:error] [pid 66623:tid 66673] [remote 34.62.54.143:45372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.github/.env"] [unique_id "aoSAF9O5rbWdOArH04J9RAABXyQ"] [Tue Aug 18 12:53:59.362021 2026] [security2:error] [pid 66623:tid 66848] [client 172.202.39.151:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAF9O5rbWdOArH04J9RgAAAVw"] [Tue Aug 18 12:53:59.375181 2026] [security2:error] [pid 66623:tid 66830] [client 20.171.51.14:51811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/de.php"] [unique_id "aoSAF9O5rbWdOArH04J9RwAAAUo"] [Tue Aug 18 12:53:59.465173 2026] [security2:error] [pid 67073:tid 67294] [client 132.196.61.152:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/inso.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3gAAAm0"] [Tue Aug 18 12:53:59.465340 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:53:59.465737 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:53:59.469645 2026] [security2:error] [pid 67073:tid 67301] [client 197.184.64.235:41915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3wAAAnQ"] [Tue Aug 18 12:53:59.469767 2026] [security2:error] [pid 67073:tid 67301] [client 197.184.64.235:41915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy3wAAAnQ"] [Tue Aug 18 12:53:59.538414 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.75.187:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/dsd.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4AAAAjY"] [Tue Aug 18 12:53:59.541131 2026] [security2:error] [pid 67073:tid 67268] [client 52.238.210.254:9013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/info.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4QAAAlM"] [Tue Aug 18 12:53:59.568626 2026] [security2:error] [pid 67073:tid 67274] [client 20.48.236.86:16345] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.onemotos.com.br"] [uri "/1.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4gAAAlk"] [Tue Aug 18 12:53:59.568732 2026] [security2:error] [pid 67073:tid 67274] [client 20.48.236.86:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/1.php"] [unique_id "aoSAF_cmepr5_nHgLbMy4gAAAlk"] [Tue Aug 18 12:53:59.821736 2026] [security2:error] [pid 67073:tid 67295] [client 149.34.210.157:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6AAAAm4"] [Tue Aug 18 12:53:59.821868 2026] [security2:error] [pid 67073:tid 67295] [client 149.34.210.157:49932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6AAAAm4"] [Tue Aug 18 12:53:59.834655 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/8pyceeo.php"] [unique_id "aoSAF9O5rbWdOArH04J9SQAAAXY"] [Tue Aug 18 12:53:59.842644 2026] [security2:error] [pid 66623:tid 66810] [client 103.184.169.37:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF9O5rbWdOArH04J9SAAAATY"] [Tue Aug 18 12:53:59.842756 2026] [security2:error] [pid 66623:tid 66810] [client 103.184.169.37:41244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF9O5rbWdOArH04J9SAAAATY"] [Tue Aug 18 12:53:59.944596 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:21502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/alfa.php"] [unique_id "aoSAF_cmepr5_nHgLbMy7QAAAj8"] [Tue Aug 18 12:53:59.963449 2026] [security2:error] [pid 67073:tid 67300] [client 158.23.17.4:54755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/kc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy7wAAAnM"] [Tue Aug 18 12:53:59.966101 2026] [security2:error] [pid 66623:tid 66847] [client 20.171.51.14:28814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/album.php"] [unique_id "aoSAF9O5rbWdOArH04J9TAAAAVs"] [Tue Aug 18 12:54:00.066230 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAGPcmepr5_nHgLbMy8wACJg8"] [Tue Aug 18 12:54:00.066804 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:00.067069 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:00.085157 2026] [security2:error] [pid 66623:tid 66877] [client 172.202.39.151:44376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAGNO5rbWdOArH04J9TQAAAXk"] [Tue Aug 18 12:54:00.282763 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/cxc.php"] [unique_id "aoSAGPcmepr5_nHgLbMy9gACdT4"] [Tue Aug 18 12:54:00.286865 2026] [authz_core:error] [pid 66623:tid 66759] [remote 57.141.22.118:40900] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:00.287118 2026] [authz_core:error] [pid 66623:tid 66759] [remote 57.141.22.118:40900] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:00.311821 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.97:48036] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:00.312108 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.97:48036] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:00.339385 2026] [security2:error] [pid 67073:tid 67217] [client 74.248.136.165:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/a2.php"] [unique_id "aoSAGPcmepr5_nHgLbMy9wAAAiA"] [Tue Aug 18 12:54:00.342892 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSAGPcmepr5_nHgLbMy-AAAAjs"] [Tue Aug 18 12:54:00.500334 2026] [security2:error] [pid 67073:tid 67273] [client 172.182.200.96:14233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAGPcmepr5_nHgLbMy-QAAAlg"] [Tue Aug 18 12:54:00.509492 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAGPcmepr5_nHgLbMy-gACQi4"] [Tue Aug 18 12:54:00.599461 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:28262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/app.php"] [unique_id "aoSAGPcmepr5_nHgLbMy_QAAAlI"] [Tue Aug 18 12:54:00.680356 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:00.680610 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:00.753976 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/0.php"] [unique_id "aoSAGPcmepr5_nHgLbMzAwACHT0"] [Tue Aug 18 12:54:00.964192 2026] [security2:error] [pid 67073:tid 67313] [client 52.238.210.254:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/fpwch.php"] [unique_id "aoSAGPcmepr5_nHgLbMzDAAAAoA"] [Tue Aug 18 12:54:00.966526 2026] [security2:error] [pid 67073:tid 67107] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/dom.php"] [unique_id "aoSAGPcmepr5_nHgLbMzDQACfh8"] [Tue Aug 18 12:54:00.970717 2026] [authz_core:error] [pid 67073:tid 67155] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:00.970992 2026] [authz_core:error] [pid 67073:tid 67155] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:01.014663 2026] [security2:error] [pid 66623:tid 66774] [client 158.23.17.4:60337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/jn.php"] [unique_id "aoSAGdO5rbWdOArH04J9VAAAARI"] [Tue Aug 18 12:54:01.068133 2026] [security2:error] [pid 66623:tid 66845] [client 172.202.39.151:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAGdO5rbWdOArH04J9VQAAAVk"] [Tue Aug 18 12:54:01.083011 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.100.201:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/php5.php"] [unique_id "aoSAGfcmepr5_nHgLbMzDwAAAkk"] [Tue Aug 18 12:54:01.111308 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.6.191:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAGfcmepr5_nHgLbMzEAAAAkU"] [Tue Aug 18 12:54:01.183048 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/bb.php"] [unique_id "aoSAGfcmepr5_nHgLbMzEwACMTE"] [Tue Aug 18 12:54:01.248168 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.56.190:44999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/87.php"] [unique_id "aoSAGdO5rbWdOArH04J9VwAAASQ"] [Tue Aug 18 12:54:01.265141 2026] [security2:error] [pid 66623:tid 66891] [client 20.48.236.86:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/img.php"] [unique_id "aoSAGdO5rbWdOArH04J9WgAAAYc"] [Tue Aug 18 12:54:01.275785 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:01.276223 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:01.340692 2026] [security2:error] [pid 67073:tid 67207] [client 135.225.75.187:55139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/c4.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGAAAAhY"] [Tue Aug 18 12:54:01.354124 2026] [security2:error] [pid 67073:tid 67263] [client 158.158.74.177:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/goat.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGQAAAk4"] [Tue Aug 18 12:54:01.431485 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGgAAAoo"] [Tue Aug 18 12:54:01.432973 2026] [security2:error] [pid 67073:tid 67298] [client 138.36.100.162:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy2wAAAnE"] [Tue Aug 18 12:54:01.433146 2026] [security2:error] [pid 67073:tid 67298] [client 138.36.100.162:42487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAF_cmepr5_nHgLbMy2wAAAnE"] [Tue Aug 18 12:54:01.437824 2026] [security2:error] [pid 67073:tid 67316] [client 172.182.200.96:14168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAGfcmepr5_nHgLbMzGwAAAoM"] [Tue Aug 18 12:54:01.447406 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.200.96:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/weozh.php"] [unique_id "aoSAGfcmepr5_nHgLbMzHQAAAm0"] [Tue Aug 18 12:54:01.475528 2026] [security2:error] [pid 67073:tid 67154] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ok.php"] [unique_id "aoSAGfcmepr5_nHgLbMzHgACdE4"] [Tue Aug 18 12:54:01.492859 2026] [security2:error] [pid 66623:tid 66798] [client 178.153.171.161:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAGdO5rbWdOArH04J9XgAAASo"] [Tue Aug 18 12:54:01.536958 2026] [security2:error] [pid 67073:tid 67274] [client 51.89.129.229:17220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.julioalvez.com.br"] [uri "/robots.txt"] [unique_id "aoSAGfcmepr5_nHgLbMzIQAAAlk"] [Tue Aug 18 12:54:01.537126 2026] [security2:error] [pid 67073:tid 67274] [client 51.89.129.229:17220] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.julioalvez.com.br"] [uri "/robots.txt"] [unique_id "aoSAGfcmepr5_nHgLbMzIQAAAlk"] [Tue Aug 18 12:54:01.581164 2026] [security2:error] [pid 67073:tid 67262] [client 20.250.13.23:52999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/edit.php"] [unique_id "aoSAGfcmepr5_nHgLbMzIgAAAk0"] [Tue Aug 18 12:54:01.588856 2026] [autoindex:error] [pid 66623:tid 66880] [client 172.202.39.151:49203] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:01.602179 2026] [security2:error] [pid 66623:tid 66778] [client 132.196.61.152:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/puc.php"] [unique_id "aoSAGdO5rbWdOArH04J9YQAAARY"] [Tue Aug 18 12:54:01.614401 2026] [security2:error] [pid 66623:tid 66886] [client 20.42.19.40:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/file5.php"] [unique_id "aoSAGdO5rbWdOArH04J9YgAAAYI"] [Tue Aug 18 12:54:01.683976 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/acp.php"] [unique_id "aoSAGfcmepr5_nHgLbMzIwAAAkA"] [Tue Aug 18 12:54:01.690976 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp9.php"] [unique_id "aoSAGfcmepr5_nHgLbMzJAACYFo"] [Tue Aug 18 12:54:01.698433 2026] [security2:error] [pid 67073:tid 67215] [client 20.226.6.191:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/about.php"] [unique_id "aoSAGfcmepr5_nHgLbMzJQAAAh4"] [Tue Aug 18 12:54:01.719899 2026] [security2:error] [pid 66623:tid 66770] [client 114.119.140.137:58833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mairabordignon.com.br"] [uri "/2022/11/30/technics-brand-discontinued"] [unique_id "aoSAGdO5rbWdOArH04J9ZAAAAQ4"], referer: https://evga-nvidiageforce.com/2022/11/30/wedding-card-gift-amount [Tue Aug 18 12:54:01.724498 2026] [security2:error] [pid 67073:tid 67326] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSAF_cmepr5_nHgLbMy6wACjR4"], referer: https://jgbdominiosolucoes.com.br/ [Tue Aug 18 12:54:01.906148 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.200.96:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/rymmm.php"] [unique_id "aoSAGdO5rbWdOArH04J9ZQAAAWQ"] [Tue Aug 18 12:54:01.917401 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:2213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/makeasmtp.php"] [unique_id "aoSAGfcmepr5_nHgLbMzKgAAAl0"] [Tue Aug 18 12:54:01.943358 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.133.44:11751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAGdO5rbWdOArH04J9ZgAAAXo"] [Tue Aug 18 12:54:01.959570 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws59.php"] [unique_id "aoSAGfcmepr5_nHgLbMzLAACam4"] [Tue Aug 18 12:54:01.983098 2026] [security2:error] [pid 66623:tid 66796] [client 52.238.210.254:10218] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/mini"] [unique_id "aoSAGdO5rbWdOArH04J9ZwAAASg"] [Tue Aug 18 12:54:02.139290 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.6.191:6638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAGtO5rbWdOArH04J9aQAAAXA"] [Tue Aug 18 12:54:02.168578 2026] [security2:error] [pid 66623:tid 66776] [client 158.23.17.4:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmveiculosrp.com.br"] [uri "/bf.php"] [unique_id "aoSAGtO5rbWdOArH04J9agAAARQ"] [Tue Aug 18 12:54:02.236671 2026] [security2:error] [pid 66623:tid 66864] [client 213.202.253.4:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/txets.php"] [unique_id "aoSAGtO5rbWdOArH04J9awAAAWw"], referer: www.google.com [Tue Aug 18 12:54:02.309209 2026] [security2:error] [pid 66623:tid 66839] [client 172.182.200.96:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/lddxs.php"] [unique_id "aoSAGtO5rbWdOArH04J9bAAAAVM"] [Tue Aug 18 12:54:02.335051 2026] [security2:error] [pid 66623:tid 66790] [client 20.171.51.14:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/su.php"] [unique_id "aoSAGtO5rbWdOArH04J9bQAAASI"] [Tue Aug 18 12:54:02.364072 2026] [security2:error] [pid 66623:tid 66784] [client 20.104.100.201:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/yas.php"] [unique_id "aoSAGtO5rbWdOArH04J9bgAAARw"] [Tue Aug 18 12:54:02.461400 2026] [security2:error] [pid 66623:tid 66798] [client 178.153.171.161:62877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAGdO5rbWdOArH04J9XgAAASo"] [Tue Aug 18 12:54:02.535121 2026] [authz_core:error] [pid 66623:tid 66747] [remote 57.141.22.101:46704] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:02.535404 2026] [authz_core:error] [pid 66623:tid 66747] [remote 57.141.22.101:46704] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:02.550827 2026] [security2:error] [pid 67073:tid 67199] [remote 74.220.219.216:37372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-login.php"] [unique_id "aoSAGvcmepr5_nHgLbMzOQACgns"] [Tue Aug 18 12:54:02.642529 2026] [security2:error] [pid 67073:tid 67276] [client 20.42.19.40:2690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/index.php"] [unique_id "aoSAGvcmepr5_nHgLbMzOgAAAls"] [Tue Aug 18 12:54:02.681909 2026] [security2:error] [pid 66623:tid 66843] [client 132.196.61.152:55346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/19.php"] [unique_id "aoSAGtO5rbWdOArH04J9cgAAAVc"] [Tue Aug 18 12:54:02.729908 2026] [security2:error] [pid 66623:tid 66853] [client 4.223.164.152:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/.admin.php"] [unique_id "aoSAGtO5rbWdOArH04J9dAAAAWE"] [Tue Aug 18 12:54:02.931351 2026] [security2:error] [pid 66623:tid 66820] [client 20.104.100.201:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAGtO5rbWdOArH04J9eAAAAUA"] [Tue Aug 18 12:54:02.946356 2026] [security2:error] [pid 67073:tid 67216] [client 20.42.19.40:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAGvcmepr5_nHgLbMzQwAAAh8"] [Tue Aug 18 12:54:03.026867 2026] [autoindex:error] [pid 66623:tid 66883] [client 172.202.39.151:49203] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:03.103507 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.100.201:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ah25.php"] [unique_id "aoSAG9O5rbWdOArH04J9fAAAASc"] [Tue Aug 18 12:54:03.210710 2026] [fcgid:warn] [pid 67073:tid 67265] (70014)End of file found: [client 66.132.195.55:53860] mod_fcgid: can't get data from http client [Tue Aug 18 12:54:03.273689 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.100.201:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAG_cmepr5_nHgLbMzSwAAAkg"] [Tue Aug 18 12:54:03.298728 2026] [security2:error] [pid 66623:tid 66742] [remote 188.164.197.230:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-login.php"] [unique_id "aoSAG9O5rbWdOArH04J9gQABWGk"] [Tue Aug 18 12:54:03.416654 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTAAAAj0"] [Tue Aug 18 12:54:03.457916 2026] [security2:error] [pid 67073:tid 67221] [client 160.120.140.123:53939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTgAAAiQ"] [Tue Aug 18 12:54:03.458050 2026] [security2:error] [pid 67073:tid 67221] [client 160.120.140.123:53939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTgAAAiQ"] [Tue Aug 18 12:54:03.556437 2026] [security2:error] [pid 67073:tid 67220] [client 20.65.98.162:18068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAG_cmepr5_nHgLbMzTwAAAiM"] [Tue Aug 18 12:54:03.580111 2026] [security2:error] [pid 67073:tid 67309] [client 213.35.127.232:58276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAG_cmepr5_nHgLbMzUQAAAnw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:03.634306 2026] [security2:error] [pid 67073:tid 67234] [client 20.250.13.23:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/elp.php"] [unique_id "aoSAG_cmepr5_nHgLbMzUwAAAjE"] [Tue Aug 18 12:54:03.645007 2026] [security2:error] [pid 67073:tid 67228] [client 104.209.144.33:35893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/lddxs.php"] [unique_id "aoSAG_cmepr5_nHgLbMzVAAAAis"] [Tue Aug 18 12:54:03.678485 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:03.678748 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:03.696823 2026] [security2:error] [pid 66623:tid 66799] [client 135.225.75.187:19237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/an7.php"] [unique_id "aoSAG9O5rbWdOArH04J9ggAAASs"] [Tue Aug 18 12:54:03.734616 2026] [security2:error] [pid 66623:tid 66874] [client 172.202.39.151:49203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/gecko.php"] [unique_id "aoSAG9O5rbWdOArH04J9gwAAAXY"] [Tue Aug 18 12:54:03.780205 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.133.44:32390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/x.php"] [unique_id "aoSAG9O5rbWdOArH04J9hAAAAUg"] [Tue Aug 18 12:54:03.828467 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:36383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/app.php"] [unique_id "aoSAG_cmepr5_nHgLbMzXQAAAi0"] [Tue Aug 18 12:54:03.873076 2026] [security2:error] [pid 66623:tid 66866] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAG9O5rbWdOArH04J9hQAAAW4"] [Tue Aug 18 12:54:03.879295 2026] [security2:error] [pid 66623:tid 66847] [client 172.182.200.96:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zjggu.php"] [unique_id "aoSAG9O5rbWdOArH04J9hgAAAVs"] [Tue Aug 18 12:54:03.900972 2026] [security2:error] [pid 67073:tid 67169] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAG_cmepr5_nHgLbMzXwACTV0"] [Tue Aug 18 12:54:03.976052 2026] [security2:error] [pid 66623:tid 66833] [client 172.202.39.151:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/file.php"] [unique_id "aoSAG9O5rbWdOArH04J9iAAAAU0"] [Tue Aug 18 12:54:03.981328 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:03.981601 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:03.999785 2026] [security2:error] [pid 67073:tid 67252] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAG_cmepr5_nHgLbMzYQAAAkM"] [Tue Aug 18 12:54:04.019000 2026] [security2:error] [pid 66623:tid 66832] [client 20.171.51.14:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wp-key.php"] [unique_id "aoSAHNO5rbWdOArH04J9iQAAAUw"] [Tue Aug 18 12:54:04.076832 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:6603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/f35.php"] [unique_id "aoSAHPcmepr5_nHgLbMzYwAAAkw"] [Tue Aug 18 12:54:04.135620 2026] [security2:error] [pid 67073:tid 67090] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAHPcmepr5_nHgLbMzZQACYA4"] [Tue Aug 18 12:54:04.209112 2026] [security2:error] [pid 67073:tid 67193] [remote 47.128.60.119:56950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.galeriadoengenho.com"] [uri "/robots.txt"] [unique_id "aoSAHPcmepr5_nHgLbMzZgACInU"] [Tue Aug 18 12:54:04.253241 2026] [security2:error] [pid 66623:tid 66876] [client 20.42.19.40:2237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/atomlib.php"] [unique_id "aoSAHNO5rbWdOArH04J9iwAAAXg"] [Tue Aug 18 12:54:04.255957 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kv.php"] [unique_id "aoSAHPcmepr5_nHgLbMzZwAAAo0"] [Tue Aug 18 12:54:04.291439 2026] [security2:error] [pid 66623:tid 66774] [client 172.182.200.96:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAHNO5rbWdOArH04J9jAAAARI"] [Tue Aug 18 12:54:04.370364 2026] [security2:error] [pid 66623:tid 66791] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAHNO5rbWdOArH04J9jgAAASM"] [Tue Aug 18 12:54:04.461732 2026] [security2:error] [pid 67073:tid 67275] [client 157.51.166.53:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzawAAAlo"] [Tue Aug 18 12:54:04.461871 2026] [security2:error] [pid 67073:tid 67275] [client 157.51.166.53:52558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzawAAAlo"] [Tue Aug 18 12:54:04.503517 2026] [authz_core:error] [pid 67073:tid 67188] [remote 57.141.22.87:32008] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:04.503789 2026] [authz_core:error] [pid 67073:tid 67188] [remote 57.141.22.87:32008] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:04.505660 2026] [security2:error] [pid 67073:tid 67299] [client 37.40.227.74:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzbgAAAnI"] [Tue Aug 18 12:54:04.575458 2026] [autoindex:error] [pid 67073:tid 67245] [client 172.202.39.151:33734] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:04.615941 2026] [authz_core:error] [pid 67073:tid 67284] [client 192.178.4.135:42426] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:04.616197 2026] [authz_core:error] [pid 67073:tid 67284] [client 192.178.4.135:42426] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:04.722289 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:19638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zjggu.php"] [unique_id "aoSAHPcmepr5_nHgLbMzcgAAAlU"] [Tue Aug 18 12:54:04.729109 2026] [security2:error] [pid 67073:tid 67227] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAHPcmepr5_nHgLbMzcwAAAio"] [Tue Aug 18 12:54:04.760968 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHNO5rbWdOArH04J9kwAAAUI"] [Tue Aug 18 12:54:04.761149 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:59260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHNO5rbWdOArH04J9kwAAAUI"] [Tue Aug 18 12:54:04.776453 2026] [security2:error] [pid 67073:tid 67241] [client 172.182.200.96:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAHPcmepr5_nHgLbMzdAAAAjg"] [Tue Aug 18 12:54:04.869141 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/ano.php"] [unique_id "aoSAHPcmepr5_nHgLbMzdgAAAoc"] [Tue Aug 18 12:54:05.013226 2026] [security2:error] [pid 67073:tid 67330] [client 4.232.151.198:6182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/lock360.php"] [unique_id "aoSAHfcmepr5_nHgLbMzeAAAApE"] [Tue Aug 18 12:54:05.036225 2026] [security2:error] [pid 67073:tid 67250] [client 4.223.164.152:7057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/wsomini.php"] [unique_id "aoSAHfcmepr5_nHgLbMzeQAAAkE"] [Tue Aug 18 12:54:05.071886 2026] [security2:error] [pid 67073:tid 67321] [client 20.48.236.86:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/222.php"] [unique_id "aoSAHfcmepr5_nHgLbMzegAAAog"] [Tue Aug 18 12:54:05.103938 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.85.180:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzewAAAiw"] [Tue Aug 18 12:54:05.136072 2026] [security2:error] [pid 66623:tid 66794] [client 20.42.19.40:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/min.php"] [unique_id "aoSAHdO5rbWdOArH04J9lAAAASY"] [Tue Aug 18 12:54:05.142991 2026] [security2:error] [pid 67073:tid 67243] [client 114.119.152.77:24539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adepol.com.br"] [uri "/vsncga/your-friend-the-rat.html"] [unique_id "aoSAHfcmepr5_nHgLbMzfAAAAjo"], referer: https://www.ballthai.com/%e0%b9%80%e0%b8%95%e0%b9%87%e0%b8%a1%e0%b8%97%e0%b8%b5%e0%b9%88%e0%b9%81%e0%b8%99%e0%b9%88%e0%b8%99%e0%b8%ad%e0%b8%99-%e0%b9%82%e0%b8%84%e0%b9%89%e0%b8%8a%e0%b8%ab%e0%b8%99%e0%b8%b6%e0%b9%88 [Tue Aug 18 12:54:05.147853 2026] [security2:error] [pid 67073:tid 67313] [client 172.202.39.151:50223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzfQAAAoA"] [Tue Aug 18 12:54:05.179241 2026] [security2:error] [pid 67073:tid 67314] [client 40.85.222.29:32466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAHfcmepr5_nHgLbMzfgAAAoE"] [Tue Aug 18 12:54:05.255809 2026] [security2:error] [pid 66623:tid 66818] [client 114.119.139.42:24919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.luzpatchwork.com.br"] [uri "/tecidos-pre-cortados"] [unique_id "aoSAHdO5rbWdOArH04J9lQAAAT4"], referer: https://www.luzpatchwork.com.br/tecidos-pre-cortados [Tue Aug 18 12:54:05.264285 2026] [security2:error] [pid 67073:tid 67258] [client 172.182.200.96:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/kopyw.php"] [unique_id "aoSAHfcmepr5_nHgLbMzgAAAAkk"] [Tue Aug 18 12:54:05.347334 2026] [security2:error] [pid 67073:tid 67286] [client 20.100.169.31:33154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAHfcmepr5_nHgLbMzgQAAAmU"] [Tue Aug 18 12:54:05.433825 2026] [security2:error] [pid 67073:tid 67214] [client 114.119.132.101:56219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.economycarsmultimarcas.com.br"] [uri "/veiculo/87035/cruze-ltz-1-8-16v-flexpower-4p-aut"] [unique_id "aoSAHfcmepr5_nHgLbMzhAAAAh0"], referer: https://www.economycarsmultimarcas.com.br/estoque?page=2 [Tue Aug 18 12:54:05.439148 2026] [security2:error] [pid 67073:tid 67232] [client 172.202.39.151:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/aa.php"] [unique_id "aoSAHfcmepr5_nHgLbMzhQAAAi8"] [Tue Aug 18 12:54:05.456241 2026] [security2:error] [pid 67073:tid 67329] [client 20.48.236.86:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/key.php"] [unique_id "aoSAHfcmepr5_nHgLbMzhgAAApA"] [Tue Aug 18 12:54:05.485034 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:05.485310 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:05.512162 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjAAAAh8"] [Tue Aug 18 12:54:05.515543 2026] [security2:error] [pid 67073:tid 67217] [client 149.34.210.157:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjQAAAiA"] [Tue Aug 18 12:54:05.520808 2026] [security2:error] [pid 67073:tid 67307] [client 20.65.98.162:29465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/sky.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjgAAAno"] [Tue Aug 18 12:54:05.528163 2026] [security2:error] [pid 67073:tid 67206] [client 158.158.74.177:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/Session.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjwAAAhU"] [Tue Aug 18 12:54:05.530394 2026] [security2:error] [pid 67073:tid 67109] [remote 162.55.89.48:61900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSAHfcmepr5_nHgLbMziwACSiE"] [Tue Aug 18 12:54:05.617512 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:21121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAHdO5rbWdOArH04J9mQAAAWI"] [Tue Aug 18 12:54:05.672882 2026] [security2:error] [pid 67073:tid 67299] [client 37.40.227.74:56956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHPcmepr5_nHgLbMzbgAAAnI"] [Tue Aug 18 12:54:05.698713 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.100.201:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/nwflm.php"] [unique_id "aoSAHfcmepr5_nHgLbMzkQAAAis"] [Tue Aug 18 12:54:05.730532 2026] [security2:error] [pid 67073:tid 67312] [client 20.250.13.23:31484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAHfcmepr5_nHgLbMzkgAAAn8"] [Tue Aug 18 12:54:05.787811 2026] [authz_core:error] [pid 67073:tid 67083] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:05.788068 2026] [authz_core:error] [pid 67073:tid 67083] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:05.793860 2026] [security2:error] [pid 67073:tid 67274] [client 20.51.153.15:9104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAHfcmepr5_nHgLbMzlAAAAlk"] [Tue Aug 18 12:54:05.814701 2026] [security2:error] [pid 67073:tid 67217] [client 149.34.210.157:50568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAHfcmepr5_nHgLbMzjQAAAiA"] [Tue Aug 18 12:54:05.827968 2026] [security2:error] [pid 66623:tid 66786] [client 20.48.236.86:16272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/chosen.php"] [unique_id "aoSAHdO5rbWdOArH04J9mgAAAR4"] [Tue Aug 18 12:54:05.855114 2026] [security2:error] [pid 67073:tid 67322] [client 114.119.133.194:29757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marthaimenes.com"] [uri "/lander"] [unique_id "aoSAHfcmepr5_nHgLbMzlgAAAok"], referer: https://www.marthaimenes.com/lander?oref=https%3A%2F%2Fwww.marthaimenes.com%2Foi-tv-abre-canais-hbo-e-max-para-todos-clientes [Tue Aug 18 12:54:05.875944 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.136.165:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/a1vx.php"] [unique_id "aoSAHfcmepr5_nHgLbMzmAAAAlY"] [Tue Aug 18 12:54:05.892370 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:40507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/mq.php"] [unique_id "aoSAHfcmepr5_nHgLbMzmgAAAjc"] [Tue Aug 18 12:54:05.969331 2026] [security2:error] [pid 67073:tid 67310] [client 52.238.210.254:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAHfcmepr5_nHgLbMznAAAAn0"] [Tue Aug 18 12:54:06.018674 2026] [security2:error] [pid 66623:tid 66784] [client 20.163.43.14:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wicked.php"] [unique_id "aoSAHtO5rbWdOArH04J9nwAAARw"] [Tue Aug 18 12:54:06.068423 2026] [security2:error] [pid 66623:tid 66885] [client 4.232.151.198:48153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/log.php"] [unique_id "aoSAHtO5rbWdOArH04J9oAAAAYE"] [Tue Aug 18 12:54:06.149483 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.172.148:7674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/aa.php"] [unique_id "aoSAHvcmepr5_nHgLbMzrQAAAiY"] [Tue Aug 18 12:54:06.257014 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAHvcmepr5_nHgLbMzsAAAAjw"] [Tue Aug 18 12:54:06.412787 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAHvcmepr5_nHgLbMzsgAAAoc"] [Tue Aug 18 12:54:06.447197 2026] [security2:error] [pid 67073:tid 67296] [client 104.209.144.33:24874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAHvcmepr5_nHgLbMzswAAAm8"] [Tue Aug 18 12:54:06.552173 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/inputs.php"] [unique_id "aoSAHvcmepr5_nHgLbMztQAAAiE"] [Tue Aug 18 12:54:06.569459 2026] [security2:error] [pid 67073:tid 67330] [client 132.196.61.152:56091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/133.php"] [unique_id "aoSAHvcmepr5_nHgLbMztgAAApE"] [Tue Aug 18 12:54:06.661765 2026] [security2:error] [pid 66623:tid 66821] [client 74.248.136.165:21164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/cxc.php"] [unique_id "aoSAHtO5rbWdOArH04J9qwAAAUE"] [Tue Aug 18 12:54:06.690129 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:06.690382 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:06.747503 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAHtO5rbWdOArH04J9rgAAASE"] [Tue Aug 18 12:54:06.980037 2026] [security2:error] [pid 66623:tid 66797] [client 52.238.210.254:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about/function.php"] [unique_id "aoSAHtO5rbWdOArH04J9rwAAASk"] [Tue Aug 18 12:54:06.982485 2026] [security2:error] [pid 66623:tid 66782] [client 114.119.132.10:41681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zanoniautomoveis.com.br"] [uri "/multipla/modelo-marca/ONIX"] [unique_id "aoSAHtO5rbWdOArH04J9sAAAARo"], referer: https://zanoniautomoveis.com.br/financiamento?veiculo=66199 [Tue Aug 18 12:54:07.005585 2026] [security2:error] [pid 67073:tid 67264] [client 172.182.200.96:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zznmg.php"] [unique_id "aoSAH_cmepr5_nHgLbMzyAAAAk8"] [Tue Aug 18 12:54:07.010482 2026] [security2:error] [pid 67073:tid 67210] [client 197.184.64.235:41916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHvcmepr5_nHgLbMzxwAAAhk"] [Tue Aug 18 12:54:07.010737 2026] [security2:error] [pid 67073:tid 67210] [client 197.184.64.235:41916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAHvcmepr5_nHgLbMzxwAAAhk"] [Tue Aug 18 12:54:07.136444 2026] [security2:error] [pid 66623:tid 66777] [client 114.119.145.123:40005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rsmoto.com.br"] [uri "/veiculo/108061/ybr-125-factor-ed-factor-edition"] [unique_id "aoSAH9O5rbWdOArH04J9sgAAARU"], referer: https://www.rsmoto.com.br/veiculo/108061/ybr-125-factor-ed-factor-edition [Tue Aug 18 12:54:07.137878 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.136.165:32990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAH_cmepr5_nHgLbMz0wAAApA"] [Tue Aug 18 12:54:07.149911 2026] [security2:error] [pid 67073:tid 67289] [client 51.161.65.180:62790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.julioalvez.com.br"] [uri "/"] [unique_id "aoSAH_cmepr5_nHgLbMz1AAAAmg"] [Tue Aug 18 12:54:07.149999 2026] [security2:error] [pid 67073:tid 67289] [client 51.161.65.180:62790] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.julioalvez.com.br"] [uri "/"] [unique_id "aoSAH_cmepr5_nHgLbMz1AAAAmg"] [Tue Aug 18 12:54:07.179179 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file5.php"] [unique_id "aoSAH9O5rbWdOArH04J9swAAAVw"] [Tue Aug 18 12:54:07.180942 2026] [security2:error] [pid 67073:tid 67251] [client 114.119.144.163:47583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.avenidaveiculossc.com.br"] [uri "/veiculo/55771/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut"] [unique_id "aoSAH_cmepr5_nHgLbMz1QAAAkI"], referer: https://www.avenidaveiculossc.com.br/veiculo/55771/hilux-sw4-srv-d4-d-4x4-3-0-tdi-dies-aut [Tue Aug 18 12:54:07.316875 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:6166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/lv.php"] [unique_id "aoSAH9O5rbWdOArH04J9tAAAAVo"] [Tue Aug 18 12:54:07.329401 2026] [security2:error] [pid 67073:tid 67255] [client 20.48.236.86:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/thoms.php"] [unique_id "aoSAH_cmepr5_nHgLbMz2QAAAkY"] [Tue Aug 18 12:54:07.534333 2026] [security2:error] [pid 67073:tid 67234] [client 172.202.39.151:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/0x.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3gAAAjE"] [Tue Aug 18 12:54:07.541541 2026] [security2:error] [pid 67073:tid 67326] [client 196.12.128.158:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3wAAAo0"] [Tue Aug 18 12:54:07.541661 2026] [security2:error] [pid 67073:tid 67326] [client 196.12.128.158:56038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz3wAAAo0"] [Tue Aug 18 12:54:07.550443 2026] [security2:error] [pid 67073:tid 67257] [client 192.141.172.134:53075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4AAAAkg"] [Tue Aug 18 12:54:07.550549 2026] [security2:error] [pid 67073:tid 67257] [client 192.141.172.134:53075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4AAAAkg"] [Tue Aug 18 12:54:07.557315 2026] [security2:error] [pid 66623:tid 66645] [remote 64.225.17.112:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.17.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samarapraseres.com.br"] [uri "/wp-login.php"] [unique_id "aoSAH9O5rbWdOArH04J9tgABJwg"] [Tue Aug 18 12:54:07.607471 2026] [security2:error] [pid 66623:tid 66830] [client 158.158.74.177:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSAH9O5rbWdOArH04J9uAAAAUo"] [Tue Aug 18 12:54:07.618112 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/0.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4gAAAn8"] [Tue Aug 18 12:54:07.684115 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gg.php"] [unique_id "aoSAH_cmepr5_nHgLbMz4wAAAik"] [Tue Aug 18 12:54:07.698024 2026] [security2:error] [pid 67073:tid 67268] [client 135.225.75.187:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSAH_cmepr5_nHgLbMz5AAAAlM"] [Tue Aug 18 12:54:07.722598 2026] [security2:error] [pid 66623:tid 66831] [client 20.250.13.23:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/666.php"] [unique_id "aoSAH9O5rbWdOArH04J9ugAAAUs"] [Tue Aug 18 12:54:07.863619 2026] [security2:error] [pid 67073:tid 67212] [client 20.48.236.86:16292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/wpxml.php"] [unique_id "aoSAH_cmepr5_nHgLbMz6wAAAhs"] [Tue Aug 18 12:54:08.179208 2026] [security2:error] [pid 67073:tid 67302] [client 20.163.43.14:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAIPcmepr5_nHgLbMz8gAAAnU"] [Tue Aug 18 12:54:08.201688 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:08.202154 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:08.269985 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.85.180:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/inputs.php"] [unique_id "aoSAIPcmepr5_nHgLbMz9gAAAl4"] [Tue Aug 18 12:54:08.461922 2026] [security2:error] [pid 67073:tid 67219] [client 138.36.100.162:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HAAAAiI"] [Tue Aug 18 12:54:08.462011 2026] [security2:error] [pid 67073:tid 67219] [client 138.36.100.162:42317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HAAAAiI"] [Tue Aug 18 12:54:08.478375 2026] [security2:error] [pid 67073:tid 67327] [client 20.226.56.190:47108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zi.php"] [unique_id "aoSAIPcmepr5_nHgLbM0HQAAAo4"] [Tue Aug 18 12:54:08.517596 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:59040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAINO5rbWdOArH04J9vQAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:08.556629 2026] [security2:error] [pid 66623:tid 66828] [client 103.184.169.37:41279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAINO5rbWdOArH04J9vgAAAUg"] [Tue Aug 18 12:54:08.556807 2026] [security2:error] [pid 66623:tid 66828] [client 103.184.169.37:41279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAINO5rbWdOArH04J9vgAAAUg"] [Tue Aug 18 12:54:08.698159 2026] [security2:error] [pid 67073:tid 67252] [client 104.209.144.33:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAIPcmepr5_nHgLbM0IgAAAkM"] [Tue Aug 18 12:54:08.706095 2026] [security2:error] [pid 67073:tid 67284] [client 20.118.172.148:47277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/abcd.php"] [unique_id "aoSAIPcmepr5_nHgLbM0IwAAAmM"] [Tue Aug 18 12:54:08.789764 2026] [security2:error] [pid 66623:tid 66845] [client 20.171.51.14:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gi.php"] [unique_id "aoSAINO5rbWdOArH04J9wQAAAVk"] [Tue Aug 18 12:54:08.901507 2026] [security2:error] [pid 66623:tid 66641] [remote 47.86.33.52:46226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSAINO5rbWdOArH04J9wwABHwQ"] [Tue Aug 18 12:54:09.032947 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leve.etc.br"] [uri "/vr.php"] [unique_id "aoSAIfcmepr5_nHgLbM0KQAAAh4"] [Tue Aug 18 12:54:09.081856 2026] [security2:error] [pid 67073:tid 67292] [client 135.225.75.187:19210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/byp8.php"] [unique_id "aoSAIfcmepr5_nHgLbM0KgAAAms"] [Tue Aug 18 12:54:09.099198 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:09.099466 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:09.115598 2026] [security2:error] [pid 67073:tid 67301] [client 172.202.39.151:25685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/zxz.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LAAAAnQ"] [Tue Aug 18 12:54:09.133350 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.56.190:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/92.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LQAAAhk"] [Tue Aug 18 12:54:09.162358 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAIfcmepr5_nHgLbM0LwAAAlo"] [Tue Aug 18 12:54:09.199159 2026] [autoindex:error] [pid 66623:tid 66659] [remote 40.74.68.220:0] AH01276: Cannot serve directory /home3/cp38imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:09.203210 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:65267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAIfcmepr5_nHgLbM0MAAAAkI"] [Tue Aug 18 12:54:09.248363 2026] [security2:error] [pid 67073:tid 67235] [client 20.48.236.86:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/file1221.php"] [unique_id "aoSAIfcmepr5_nHgLbM0MgAAAjI"] [Tue Aug 18 12:54:09.402781 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:09.403050 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:09.426675 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.136.165:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/dom.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OAAAAh0"] [Tue Aug 18 12:54:09.456274 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pz.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OQAAAo0"] [Tue Aug 18 12:54:09.491045 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAIfcmepr5_nHgLbM0OwAAAkg"] [Tue Aug 18 12:54:09.508387 2026] [security2:error] [pid 67073:tid 67311] [client 20.250.13.23:31452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ws54.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PAAAAn4"] [Tue Aug 18 12:54:09.547733 2026] [security2:error] [pid 67073:tid 67268] [client 20.65.98.162:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/xyn.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PgAAAlM"] [Tue Aug 18 12:54:09.615614 2026] [security2:error] [pid 67073:tid 67276] [client 5.31.227.224:30438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIfcmepr5_nHgLbM0QAAAAls"] [Tue Aug 18 12:54:09.664570 2026] [security2:error] [pid 67073:tid 67076] [remote 57.141.22.88:40286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAIfcmepr5_nHgLbM0QgACKQA"] [Tue Aug 18 12:54:09.673523 2026] [security2:error] [pid 67073:tid 67230] [client 49.13.164.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSAIfcmepr5_nHgLbM0PwAAAi0"], referer: http://blog.tinna.com.br [Tue Aug 18 12:54:09.792166 2026] [security2:error] [pid 67073:tid 67099] [remote 203.99.146.53:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSAIPcmepr5_nHgLbM0JgACOxc"] [Tue Aug 18 12:54:09.884508 2026] [security2:error] [pid 66623:tid 66819] [client 104.209.144.33:31245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAIdO5rbWdOArH04J9xwAAAT8"] [Tue Aug 18 12:54:09.900499 2026] [security2:error] [pid 66623:tid 66767] [client 20.104.85.180:8051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/admin.php"] [unique_id "aoSAIdO5rbWdOArH04J9yAAAAQs"] [Tue Aug 18 12:54:09.905560 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/bb.php"] [unique_id "aoSAIdO5rbWdOArH04J9yQAAASY"] [Tue Aug 18 12:54:09.972040 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jm.php"] [unique_id "aoSAIfcmepr5_nHgLbM0RgAAAhs"] [Tue Aug 18 12:54:09.986751 2026] [security2:error] [pid 67073:tid 67271] [client 52.238.210.254:10228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/function/function.php"] [unique_id "aoSAIfcmepr5_nHgLbM0RwAAAlY"] [Tue Aug 18 12:54:10.000285 2026] [security2:error] [pid 66623:tid 66880] [client 5.253.205.188:47636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullbackup.bak"] [unique_id "aoSAIdO5rbWdOArH04J9ygAAAXw"], referer: https://medihub.com.br/fullbackup.bak [Tue Aug 18 12:54:10.002216 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:10.002478 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:10.069072 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/vx.php"] [unique_id "aoSAIvcmepr5_nHgLbM0SgACfRo"] [Tue Aug 18 12:54:10.122698 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAIvcmepr5_nHgLbM0TAAAAl8"] [Tue Aug 18 12:54:10.150362 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:23773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/abcd.php"] [unique_id "aoSAIvcmepr5_nHgLbM0TQAAApM"] [Tue Aug 18 12:54:10.194496 2026] [security2:error] [pid 66623:tid 66872] [client 20.51.153.15:9214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAItO5rbWdOArH04J9zAAAAXQ"] [Tue Aug 18 12:54:10.228071 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.56.190:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wj.php"] [unique_id "aoSAIvcmepr5_nHgLbM0UQAAAnU"] [Tue Aug 18 12:54:10.271298 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.6.191:6643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/alfa.php"] [unique_id "aoSAIvcmepr5_nHgLbM0UwAAAmo"] [Tue Aug 18 12:54:10.357538 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ah25.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VQACbz4"] [Tue Aug 18 12:54:10.426207 2026] [security2:error] [pid 67073:tid 67261] [client 86.120.159.145:2383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VgAAAkw"] [Tue Aug 18 12:54:10.426333 2026] [security2:error] [pid 67073:tid 67261] [client 86.120.159.145:2383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VgAAAkw"] [Tue Aug 18 12:54:10.483566 2026] [security2:error] [pid 67073:tid 67315] [client 40.85.222.29:2853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAIvcmepr5_nHgLbM0XQAAAoI"] [Tue Aug 18 12:54:10.550652 2026] [security2:error] [pid 67073:tid 67228] [client 114.119.128.181:56763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brazilcoa.com.br"] [uri "/quem-somos/"] [unique_id "aoSAIvcmepr5_nHgLbM0XgAAAis"], referer: https://brazilcoa.com.br/cacau-como-aproveitar-esta-fruta-tao-especial/ [Tue Aug 18 12:54:10.599727 2026] [security2:error] [pid 67073:tid 67282] [client 20.100.169.31:25972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/atomlib.php"] [unique_id "aoSAIvcmepr5_nHgLbM0YAAAAmE"] [Tue Aug 18 12:54:10.633361 2026] [security2:error] [pid 66623:tid 66783] [client 104.209.144.33:15692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAItO5rbWdOArH04J90gAAARs"] [Tue Aug 18 12:54:10.638221 2026] [security2:error] [pid 66623:tid 66801] [client 104.209.144.33:29834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/dlvqo.php"] [unique_id "aoSAItO5rbWdOArH04J90wAAAS0"] [Tue Aug 18 12:54:10.639378 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.56.190:31672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/74.php"] [unique_id "aoSAItO5rbWdOArH04J91AAAARQ"] [Tue Aug 18 12:54:10.645518 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown [Tue Aug 18 12:54:10.645535 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache [Tue Aug 18 12:54:10.645541 2026] [lsapi:error] [pid 67073:tid 67131] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] [host adobank.com.br] Client error on sending request(POST /xmlrpc.php HTTP/2.0); uri(/xmlrpc.php) content-length(714): user_get_body(tmpstackbuf, 16384): read from client failed [Tue Aug 18 12:54:10.674631 2026] [security2:error] [pid 67073:tid 67208] [client 114.119.158.189:30845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "espacosvilaolimpia.com.br"] [uri "/wp-content/themes/wilcity/assets/vendors"] [unique_id "aoSAIvcmepr5_nHgLbM0YgAAAhc"], referer: https://espacosvilaolimpia.com.br/wp-content/themes/wilcity/assets/vendors?C=M%3BO%3DA [Tue Aug 18 12:54:10.762704 2026] [security2:error] [pid 67073:tid 67254] [client 172.182.200.96:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAIvcmepr5_nHgLbM0ZwAAAkU"] [Tue Aug 18 12:54:10.763638 2026] [security2:error] [pid 67073:tid 67276] [client 5.31.227.224:30438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAIfcmepr5_nHgLbM0QAAAAls"] [Tue Aug 18 12:54:10.908735 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:10.908980 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:10.948455 2026] [security2:error] [pid 67073:tid 67289] [client 74.248.136.165:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ok.php"] [unique_id "aoSAIvcmepr5_nHgLbM0hwAAAmg"] [Tue Aug 18 12:54:11.134103 2026] [security2:error] [pid 67073:tid 67255] [client 132.196.61.152:27274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAI_cmepr5_nHgLbM0jwAAAkY"] [Tue Aug 18 12:54:11.174554 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/kj.php"] [unique_id "aoSAI9O5rbWdOArH04J93QAAASA"] [Tue Aug 18 12:54:11.207248 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:11.207543 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:11.275577 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.85.180:7943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/public/css.php"] [unique_id "aoSAI9O5rbWdOArH04J93gAAATg"] [Tue Aug 18 12:54:11.410935 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.136.165:30165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp9.php"] [unique_id "aoSAI_cmepr5_nHgLbM0kwAAAnk"] [Tue Aug 18 12:54:11.478616 2026] [security2:error] [pid 66623:tid 66829] [client 135.225.75.187:31421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/plugins.php"] [unique_id "aoSAI9O5rbWdOArH04J93wAAAUk"] [Tue Aug 18 12:54:11.480373 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:25069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSAI_cmepr5_nHgLbM0lAAAAh0"] [Tue Aug 18 12:54:11.508359 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:11.508846 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:30377] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:11.543120 2026] [security2:error] [pid 67073:tid 67270] [client 149.34.210.141:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mQAAAlU"] [Tue Aug 18 12:54:11.548403 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tt.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mgACNn0"] [Tue Aug 18 12:54:11.602073 2026] [security2:error] [pid 66623:tid 66789] [client 20.163.43.14:3184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cah.php"] [unique_id "aoSAI9O5rbWdOArH04J94QAAASE"] [Tue Aug 18 12:54:11.628802 2026] [security2:error] [pid 66623:tid 66766] [client 20.104.85.180:8023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAI9O5rbWdOArH04J94wAAAQo"] [Tue Aug 18 12:54:11.694707 2026] [security2:error] [pid 66623:tid 66820] [client 52.238.210.254:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-signin.php"] [unique_id "aoSAI9O5rbWdOArH04J95QAAAUA"] [Tue Aug 18 12:54:11.695568 2026] [security2:error] [pid 66623:tid 66836] [client 20.51.153.15:9142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/st.php"] [unique_id "aoSAI9O5rbWdOArH04J95gAAAVA"] [Tue Aug 18 12:54:11.830958 2026] [security2:error] [pid 67073:tid 67270] [client 149.34.210.141:60440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAI_cmepr5_nHgLbM0mQAAAlU"] [Tue Aug 18 12:54:11.879713 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.136.165:48164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ty.php"] [unique_id "aoSAI9O5rbWdOArH04J96AAAARo"] [Tue Aug 18 12:54:11.882831 2026] [security2:error] [pid 66623:tid 66777] [client 20.48.236.86:10769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/1xmomo.php"] [unique_id "aoSAI9O5rbWdOArH04J96QAAARU"] [Tue Aug 18 12:54:11.898950 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/www.php"] [unique_id "aoSAI9O5rbWdOArH04J96gAAAVg"] [Tue Aug 18 12:54:11.993557 2026] [security2:error] [pid 67073:tid 67205] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSAI_cmepr5_nHgLbM0qQAAAhQ"] [Tue Aug 18 12:54:12.023113 2026] [security2:error] [pid 67073:tid 67311] [client 178.153.171.161:18869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJPcmepr5_nHgLbM0qgAAAn4"] [Tue Aug 18 12:54:12.138651 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kk.php"] [unique_id "aoSAJPcmepr5_nHgLbM0rQAAAk4"] [Tue Aug 18 12:54:12.141309 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.98.162:29443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/inso.php"] [unique_id "aoSAJNO5rbWdOArH04J96wAAAVU"] [Tue Aug 18 12:54:12.204550 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAJPcmepr5_nHgLbM0rwAAAhw"] [Tue Aug 18 12:54:12.241070 2026] [security2:error] [pid 66623:tid 66846] [client 52.238.210.254:9016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/chosen.php"] [unique_id "aoSAJNO5rbWdOArH04J97AAAAVo"] [Tue Aug 18 12:54:12.340092 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAJPcmepr5_nHgLbM0sAAAAl4"] [Tue Aug 18 12:54:12.361646 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:15218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J97QAAAUs"] [Tue Aug 18 12:54:12.387591 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/lock360.php"] [unique_id "aoSAJPcmepr5_nHgLbM0sQAAAow"] [Tue Aug 18 12:54:12.439772 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:12.439797 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:12.440042 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:12.440046 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:12.451963 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dirs.php"] [unique_id "aoSAJPcmepr5_nHgLbM0tAAAAiY"] [Tue Aug 18 12:54:12.453636 2026] [security2:error] [pid 66623:tid 66775] [client 20.42.19.40:2711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/mac.php"] [unique_id "aoSAJNO5rbWdOArH04J98AAAARM"] [Tue Aug 18 12:54:12.458147 2026] [autoindex:error] [pid 66623:tid 66813] [client 20.104.85.180:8018] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:12.475346 2026] [security2:error] [pid 67073:tid 67132] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xqq.php"] [unique_id "aoSAJPcmepr5_nHgLbM0twACIjg"] [Tue Aug 18 12:54:12.492338 2026] [security2:error] [pid 67073:tid 67147] [remote 162.214.205.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSAJPcmepr5_nHgLbM0tQACgkc"] [Tue Aug 18 12:54:12.539797 2026] [security2:error] [pid 67073:tid 67282] [client 20.48.236.86:11068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/mosty.php"] [unique_id "aoSAJPcmepr5_nHgLbM0ugAAAmE"] [Tue Aug 18 12:54:12.543984 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:20018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/lock360.php"] [unique_id "aoSAJNO5rbWdOArH04J98QAAAUc"] [Tue Aug 18 12:54:12.546585 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.200.96:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAJNO5rbWdOArH04J98gAAAYU"] [Tue Aug 18 12:54:12.576864 2026] [security2:error] [pid 67073:tid 67317] [client 213.202.253.4:57307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/txets.php"] [unique_id "aoSAJPcmepr5_nHgLbM0vAAAAoQ"], referer: www.google.com [Tue Aug 18 12:54:12.616373 2026] [authz_core:error] [pid 67073:tid 67175] [remote 57.141.22.7:36512] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:12.616742 2026] [authz_core:error] [pid 67073:tid 67175] [remote 57.141.22.7:36512] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:12.633081 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:25396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAJNO5rbWdOArH04J98wAAAX4"] [Tue Aug 18 12:54:12.640903 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:9366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/languages.php"] [unique_id "aoSAJPcmepr5_nHgLbM0wQAAAok"] [Tue Aug 18 12:54:12.644816 2026] [security2:error] [pid 67073:tid 67252] [client 104.209.144.33:35857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/pkmoj.php"] [unique_id "aoSAJPcmepr5_nHgLbM0wgAAAkM"] [Tue Aug 18 12:54:12.688220 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:16265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/nox.php"] [unique_id "aoSAJPcmepr5_nHgLbM0xAAAAng"] [Tue Aug 18 12:54:12.690036 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:12.690347 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:12.788876 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.85.180:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J99AAAAUg"] [Tue Aug 18 12:54:12.882111 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/system_log.php"] [unique_id "aoSAJPcmepr5_nHgLbM0yAAAAh4"] [Tue Aug 18 12:54:12.895169 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:30199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws59.php"] [unique_id "aoSAJPcmepr5_nHgLbM0yQAAAjA"] [Tue Aug 18 12:54:12.968070 2026] [security2:error] [pid 66623:tid 66826] [client 172.202.39.151:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/admin.php"] [unique_id "aoSAJNO5rbWdOArH04J99QAAAUY"] [Tue Aug 18 12:54:12.994120 2026] [security2:error] [pid 67073:tid 67231] [client 172.182.200.96:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/oivcl.php"] [unique_id "aoSAJPcmepr5_nHgLbM0ywAAAi4"] [Tue Aug 18 12:54:13.029781 2026] [security2:error] [pid 67073:tid 67235] [client 20.91.215.254:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAJfcmepr5_nHgLbM0zAAAAjI"] [Tue Aug 18 12:54:13.096300 2026] [security2:error] [pid 67073:tid 67304] [client 20.250.13.23:40586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAJfcmepr5_nHgLbM00AAAAnc"] [Tue Aug 18 12:54:13.164103 2026] [security2:error] [pid 67073:tid 67130] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/06.php"] [unique_id "aoSAJfcmepr5_nHgLbM00QACJDY"] [Tue Aug 18 12:54:13.180746 2026] [security2:error] [pid 67073:tid 67295] [client 20.48.236.86:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/blurbs.php"] [unique_id "aoSAJfcmepr5_nHgLbM00wAAAm4"] [Tue Aug 18 12:54:13.212082 2026] [security2:error] [pid 67073:tid 67308] [client 172.202.39.151:44400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/epinyins.php"] [unique_id "aoSAJfcmepr5_nHgLbM01AAAAns"] [Tue Aug 18 12:54:13.352396 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:19969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/log.php"] [unique_id "aoSAJfcmepr5_nHgLbM02AAAAlk"] [Tue Aug 18 12:54:13.384856 2026] [security2:error] [pid 67073:tid 67109] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/166.php"] [unique_id "aoSAJfcmepr5_nHgLbM02gACRCE"] [Tue Aug 18 12:54:13.635199 2026] [security2:error] [pid 67073:tid 67300] [client 52.238.210.254:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/f35.php"] [unique_id "aoSAJfcmepr5_nHgLbM03AAAAnM"] [Tue Aug 18 12:54:13.660835 2026] [security2:error] [pid 67073:tid 67248] [client 54.167.223.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSAIvcmepr5_nHgLbM0VAACPwg"], referer: https://markettohome.com.br/ [Tue Aug 18 12:54:13.672768 2026] [security2:error] [pid 66623:tid 66878] [client 20.104.100.201:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/wp-load.php"] [unique_id "aoSAJdO5rbWdOArH04J9-QAAAXo"] [Tue Aug 18 12:54:13.713638 2026] [security2:error] [pid 66623:tid 66865] [client 135.225.75.187:31373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/100.kb.php"] [unique_id "aoSAJdO5rbWdOArH04J9-wAAAW0"] [Tue Aug 18 12:54:13.769521 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:25922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/rip.php"] [unique_id "aoSAJfcmepr5_nHgLbM03QAAAmo"] [Tue Aug 18 12:54:13.890079 2026] [security2:error] [pid 66623:tid 66819] [client 52.173.121.69:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAJdO5rbWdOArH04J9_QAAAT8"] [Tue Aug 18 12:54:13.918643 2026] [security2:error] [pid 66623:tid 66794] [client 20.151.109.219:36315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/13.php"] [unique_id "aoSAJdO5rbWdOArH04J9_gAAASY"] [Tue Aug 18 12:54:13.922756 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.155.217:64053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autofacilchapeco.com.br"] [uri "/veiculo/1029964/fit-lx-1-4-1-4-flex-8v-16v-5p-aut"] [unique_id "aoSAJfcmepr5_nHgLbM05QAAAm8"], referer: https://www.autofacilchapeco.com.br/index.php?pg=detran [Tue Aug 18 12:54:13.933066 2026] [security2:error] [pid 67073:tid 67331] [client 74.248.136.165:43682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAJfcmepr5_nHgLbM05wAAApI"] [Tue Aug 18 12:54:13.952270 2026] [security2:error] [pid 67073:tid 67170] [remote 47.128.58.0:46020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.padariaeconfeitariabrasil.com.br"] [uri "/site/servicos/confeitaria/"] [unique_id "aoSAJfcmepr5_nHgLbM06QACjV4"] [Tue Aug 18 12:54:13.953305 2026] [security2:error] [pid 67073:tid 67126] [remote 193.104.157.85:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.157.104.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSAJfcmepr5_nHgLbM04gACXjI"] [Tue Aug 18 12:54:14.000132 2026] [security2:error] [pid 67073:tid 67102] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/snq.php"] [unique_id "aoSAJfcmepr5_nHgLbM06wACjBo"] [Tue Aug 18 12:54:14.071928 2026] [security2:error] [pid 66623:tid 66881] [client 20.42.19.40:2190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/nc4.php"] [unique_id "aoSAJtO5rbWdOArH04J-AAAAAX0"] [Tue Aug 18 12:54:14.118753 2026] [security2:error] [pid 66623:tid 66796] [client 104.209.144.33:24835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAJtO5rbWdOArH04J-AQAAASg"] [Tue Aug 18 12:54:14.140964 2026] [security2:error] [pid 67073:tid 67261] [client 78.138.24.128:52109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zanseg.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSAJvcmepr5_nHgLbM08AAAAkw"] [Tue Aug 18 12:54:14.145420 2026] [security2:error] [pid 67073:tid 67223] [client 20.104.85.180:8017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gelay.php"] [unique_id "aoSAJvcmepr5_nHgLbM08QAAAiY"] [Tue Aug 18 12:54:14.200654 2026] [security2:error] [pid 66623:tid 66806] [client 20.65.98.162:23847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/puc.php"] [unique_id "aoSAJtO5rbWdOArH04J-AgAAATI"] [Tue Aug 18 12:54:14.208403 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-access.php"] [unique_id "aoSAJvcmepr5_nHgLbM08wACghw"] [Tue Aug 18 12:54:14.295999 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAJvcmepr5_nHgLbM09gAAAoQ"] [Tue Aug 18 12:54:14.322176 2026] [security2:error] [pid 67073:tid 67227] [client 20.171.51.14:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAJvcmepr5_nHgLbM0-AAAAio"] [Tue Aug 18 12:54:14.406182 2026] [security2:error] [pid 67073:tid 67284] [client 74.248.136.165:43707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAJvcmepr5_nHgLbM0-wAAAmM"] [Tue Aug 18 12:54:14.413291 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zugvi.php"] [unique_id "aoSAJtO5rbWdOArH04J-AwAAAXA"] [Tue Aug 18 12:54:14.447208 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nw.php"] [unique_id "aoSAJvcmepr5_nHgLbM0_wACIQ8"] [Tue Aug 18 12:54:14.476680 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:7589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAJvcmepr5_nHgLbM1AAAAAh8"] [Tue Aug 18 12:54:14.499504 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:14.499773 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:14.500283 2026] [security2:error] [pid 66623:tid 66786] [client 40.85.222.29:18830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAJtO5rbWdOArH04J-BAAAAR4"] [Tue Aug 18 12:54:14.506659 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.85.180:8030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAJvcmepr5_nHgLbM1AgAAAhc"] [Tue Aug 18 12:54:14.649106 2026] [security2:error] [pid 67073:tid 67211] [client 52.238.210.254:8392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/simple.php"] [unique_id "aoSAJvcmepr5_nHgLbM1BgAAAho"] [Tue Aug 18 12:54:14.657971 2026] [security2:error] [pid 67073:tid 67085] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws62.php"] [unique_id "aoSAJvcmepr5_nHgLbM1BwACLgk"] [Tue Aug 18 12:54:14.661130 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/lv.php"] [unique_id "aoSAJvcmepr5_nHgLbM1CAAAAng"] [Tue Aug 18 12:54:14.671612 2026] [security2:error] [pid 67073:tid 67289] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAJvcmepr5_nHgLbM1CQAAAmg"] [Tue Aug 18 12:54:14.794036 2026] [autoindex:error] [pid 66623:tid 66876] [client 158.158.74.177:9344] AH01276: Cannot serve directory /home3/evandrobene/public_html/wp-content/uploads/2022/07/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:14.850931 2026] [security2:error] [pid 67073:tid 67233] [client 85.208.96.195:20048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752870780/1753920000/"] [unique_id "aoSAJvcmepr5_nHgLbM1CwAAAjA"] [Tue Aug 18 12:54:14.851056 2026] [security2:error] [pid 67073:tid 67233] [client 85.208.96.195:20048] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752870780/1753920000/"] [unique_id "aoSAJvcmepr5_nHgLbM1CwAAAjA"] [Tue Aug 18 12:54:15.003973 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.42:52118] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:15.004236 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.42:52118] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:15.061977 2026] [security2:error] [pid 67073:tid 67304] [client 4.232.151.198:48145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mah/function.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1DwAAAnc"] [Tue Aug 18 12:54:15.094369 2026] [security2:error] [pid 66623:tid 66821] [client 104.209.144.33:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAJ9O5rbWdOArH04J-DgAAAUE"] [Tue Aug 18 12:54:15.103147 2026] [security2:error] [pid 67073:tid 67226] [client 157.51.166.53:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1EQAAAik"] [Tue Aug 18 12:54:15.103305 2026] [security2:error] [pid 67073:tid 67226] [client 157.51.166.53:53187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1EQAAAik"] [Tue Aug 18 12:54:15.110215 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:15.110481 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:15.323387 2026] [security2:error] [pid 67073:tid 67239] [client 20.104.85.180:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FAAAAjY"] [Tue Aug 18 12:54:15.332653 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.6.191:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/flower.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FQAAAn8"] [Tue Aug 18 12:54:15.364100 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.200.96:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wsrer.php"] [unique_id "aoSAJ9O5rbWdOArH04J-PAAAAQo"] [Tue Aug 18 12:54:15.401527 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:15.401845 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:15.453880 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/vx.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1FwAAAhs"] [Tue Aug 18 12:54:15.491142 2026] [security2:error] [pid 67073:tid 67271] [client 172.202.39.151:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1GAAAAlY"] [Tue Aug 18 12:54:15.520201 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/so.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1GQAAAj4"] [Tue Aug 18 12:54:15.527473 2026] [security2:error] [pid 66623:tid 66886] [client 104.209.144.33:31272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAJ9O5rbWdOArH04J-PgAAAYI"] [Tue Aug 18 12:54:15.577300 2026] [autoindex:error] [pid 66623:tid 66817] [client 52.73.140.57:45938] AH01276: Cannot serve directory /home2/atlasi11/About.atlas-ia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:15.602625 2026] [security2:error] [pid 66623:tid 66867] [client 20.118.172.148:48713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/akc.php"] [unique_id "aoSAJ9O5rbWdOArH04J-QAAAAW8"] [Tue Aug 18 12:54:15.697611 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/vx.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1KgACczE"] [Tue Aug 18 12:54:15.739912 2026] [security2:error] [pid 66623:tid 66790] [client 103.120.71.157:1299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJtO5rbWdOArH04J-BgAAASI"] [Tue Aug 18 12:54:15.740073 2026] [security2:error] [pid 66623:tid 66790] [client 103.120.71.157:1299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJtO5rbWdOArH04J-BgAAASI"] [Tue Aug 18 12:54:15.918917 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/as.php"] [unique_id "aoSAJ9O5rbWdOArH04J-YgAAAVo"] [Tue Aug 18 12:54:15.927201 2026] [security2:error] [pid 67073:tid 67308] [client 20.250.13.23:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/function/function.php"] [unique_id "aoSAJ_cmepr5_nHgLbM1LAAAAns"] [Tue Aug 18 12:54:15.931515 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.136.165:30178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ah25.php"] [unique_id "aoSAJ9O5rbWdOArH04J-YwAAASs"] [Tue Aug 18 12:54:16.029323 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:58819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dg.php"] [unique_id "aoSAKPcmepr5_nHgLbM1LQAAAjg"] [Tue Aug 18 12:54:16.063039 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/k.php"] [unique_id "aoSAKPcmepr5_nHgLbM1LgAAAiY"] [Tue Aug 18 12:54:16.139991 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/akismet.php"] [unique_id "aoSAKPcmepr5_nHgLbM1MQAAAoc"] [Tue Aug 18 12:54:16.233002 2026] [security2:error] [pid 66623:tid 66866] [client 158.158.74.177:9344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/nw.php"] [unique_id "aoSAKNO5rbWdOArH04J-ZgAAAW4"] [Tue Aug 18 12:54:16.343824 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PAACaX0"] [Tue Aug 18 12:54:16.344853 2026] [security2:error] [pid 67073:tid 67284] [client 68.155.154.236:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PQAAAmM"] [Tue Aug 18 12:54:16.362582 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAKPcmepr5_nHgLbM1PwAAAiM"] [Tue Aug 18 12:54:16.410170 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.136.165:30144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tt.php"] [unique_id "aoSAKPcmepr5_nHgLbM1QQAAAlE"] [Tue Aug 18 12:54:16.429778 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAKNO5rbWdOArH04J-aAAAARM"] [Tue Aug 18 12:54:16.527127 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wicked.php"] [unique_id "aoSAKPcmepr5_nHgLbM1RQAAAoU"] [Tue Aug 18 12:54:16.537463 2026] [security2:error] [pid 67073:tid 67127] [remote 157.55.39.52:60134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2026/08/15/study-report-on-pirots-5s-compatibility-across-different-devices/"] [unique_id "aoSAKPcmepr5_nHgLbM1RgACTDM"] [Tue Aug 18 12:54:16.556892 2026] [security2:error] [pid 67073:tid 67264] [client 20.48.236.86:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/admin.php"] [unique_id "aoSAKPcmepr5_nHgLbM1RwAAAk8"] [Tue Aug 18 12:54:16.599382 2026] [security2:error] [pid 67073:tid 67189] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sdsa.php"] [unique_id "aoSAKPcmepr5_nHgLbM1SQACgXE"] [Tue Aug 18 12:54:16.810916 2026] [security2:error] [pid 66623:tid 66772] [client 20.91.215.254:12716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAKNO5rbWdOArH04J-awAAARA"] [Tue Aug 18 12:54:16.829494 2026] [security2:error] [pid 67073:tid 67080] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAKPcmepr5_nHgLbM1SwACSwQ"] [Tue Aug 18 12:54:16.905329 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:16.905590 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:17.025066 2026] [security2:error] [pid 67073:tid 67323] [client 104.209.144.33:29867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/kopyw.php"] [unique_id "aoSAKfcmepr5_nHgLbM1TgAAAoo"] [Tue Aug 18 12:54:17.151453 2026] [security2:error] [pid 67073:tid 67254] [client 40.85.222.29:16560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAKfcmepr5_nHgLbM1UwAAAkU"] [Tue Aug 18 12:54:17.197881 2026] [security2:error] [pid 66623:tid 66862] [client 43.155.129.131:45818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.129.155.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campingatoba.com.br"] [uri "/wp-login.php"] [unique_id "aoSAI9O5rbWdOArH04J95wAAAWo"] [Tue Aug 18 12:54:17.273168 2026] [security2:error] [pid 67073:tid 67222] [client 160.120.140.123:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1VwAAAiU"] [Tue Aug 18 12:54:17.273314 2026] [security2:error] [pid 67073:tid 67222] [client 160.120.140.123:54500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1VwAAAiU"] [Tue Aug 18 12:54:17.281834 2026] [security2:error] [pid 67073:tid 67330] [client 85.154.68.202:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WAAAApE"] [Tue Aug 18 12:54:17.281957 2026] [security2:error] [pid 67073:tid 67330] [client 85.154.68.202:9217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WAAAApE"] [Tue Aug 18 12:54:17.404394 2026] [security2:error] [pid 66623:tid 66879] [client 135.225.75.187:33039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mamzi.php"] [unique_id "aoSAKdO5rbWdOArH04J-bQAAAXs"] [Tue Aug 18 12:54:17.436903 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:17961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/weozh.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WgAAAl0"] [Tue Aug 18 12:54:17.439996 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.136.165:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/vgtyu.php"] [unique_id "aoSAKdO5rbWdOArH04J-bwAAATs"] [Tue Aug 18 12:54:17.442187 2026] [security2:error] [pid 66623:tid 66814] [client 20.51.153.15:9199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sn.php"] [unique_id "aoSAKdO5rbWdOArH04J-cAAAATo"] [Tue Aug 18 12:54:17.452525 2026] [security2:error] [pid 67073:tid 67142] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fleen.php"] [unique_id "aoSAKfcmepr5_nHgLbM1WwACHUI"] [Tue Aug 18 12:54:17.507438 2026] [security2:error] [pid 67073:tid 67311] [client 178.153.171.161:18869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "400"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAJPcmepr5_nHgLbM0qgAAAn4"] [Tue Aug 18 12:54:17.515004 2026] [security2:error] [pid 67073:tid 67239] [client 20.118.172.148:39701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/buy.php"] [unique_id "aoSAKfcmepr5_nHgLbM1XgAAAjY"] [Tue Aug 18 12:54:17.639853 2026] [security2:error] [pid 67073:tid 67306] [client 20.91.215.254:12718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAKfcmepr5_nHgLbM1YAAAAnk"] [Tue Aug 18 12:54:17.715806 2026] [security2:error] [pid 66623:tid 66884] [client 172.182.200.96:14178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAKdO5rbWdOArH04J-cgAAAYA"] [Tue Aug 18 12:54:17.736449 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.154.236:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAKdO5rbWdOArH04J-cwAAAXo"] [Tue Aug 18 12:54:17.767148 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.100.201:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/jj.php"] [unique_id "aoSAKdO5rbWdOArH04J-dAAAAW0"] [Tue Aug 18 12:54:17.790914 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:17.791191 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:17.795779 2026] [security2:error] [pid 67073:tid 67237] [client 196.12.128.158:56784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1ZAAAAjQ"] [Tue Aug 18 12:54:17.795881 2026] [security2:error] [pid 67073:tid 67237] [client 196.12.128.158:56784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1ZAAAAjQ"] [Tue Aug 18 12:54:17.812922 2026] [security2:error] [pid 66623:tid 66856] [client 114.119.158.58:41047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lojaodovidraceiro.com"] [uri "/categoria-produto/vidros/"] [unique_id "aoSAKdO5rbWdOArH04J-dQAAAWQ"], referer: https://lojaodovidraceiro.com/categoria-produto/acessorios [Tue Aug 18 12:54:17.881777 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.98.162:18087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/19.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bAAAAms"] [Tue Aug 18 12:54:17.934592 2026] [security2:error] [pid 67073:tid 67248] [client 20.48.236.86:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/bajah.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bgAAAj8"] [Tue Aug 18 12:54:17.964689 2026] [security2:error] [pid 67073:tid 67291] [client 52.173.121.69:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/rymmm.php"] [unique_id "aoSAKfcmepr5_nHgLbM1cAAAAmo"] [Tue Aug 18 12:54:18.091264 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:18.091519 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:18.111479 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.133.44:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/filemanager.php"] [unique_id "aoSAKvcmepr5_nHgLbM1dgAAAlg"] [Tue Aug 18 12:54:18.279307 2026] [security2:error] [pid 67073:tid 67182] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/e.php"] [unique_id "aoSAKvcmepr5_nHgLbM1egACgmo"] [Tue Aug 18 12:54:18.315040 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKtO5rbWdOArH04J-egAAASw"] [Tue Aug 18 12:54:18.315136 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:56729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKtO5rbWdOArH04J-egAAASw"] [Tue Aug 18 12:54:18.320268 2026] [security2:error] [pid 67073:tid 67327] [client 20.48.236.86:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/ajax.php"] [unique_id "aoSAKvcmepr5_nHgLbM1fAAAAo4"] [Tue Aug 18 12:54:18.359599 2026] [security2:error] [pid 67073:tid 67256] [client 114.119.155.69:63481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mahokosveiculos.com.br"] [uri "/Anuncio/Details/551182"] [unique_id "aoSAKvcmepr5_nHgLbM1fQAAAkc"], referer: http://www.mahokosveiculos.com.br/Anuncio/Details/487903 [Tue Aug 18 12:54:18.433201 2026] [security2:error] [pid 66623:tid 66888] [client 172.202.39.151:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAKtO5rbWdOArH04J-fAAAAYQ"] [Tue Aug 18 12:54:18.512434 2026] [security2:error] [pid 67073:tid 67188] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/hello.php"] [unique_id "aoSAKvcmepr5_nHgLbM1fwACI3A"] [Tue Aug 18 12:54:18.528570 2026] [security2:error] [pid 66623:tid 66854] [client 52.238.210.254:10149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/gg.php"] [unique_id "aoSAKtO5rbWdOArH04J-fQAAAWI"] [Tue Aug 18 12:54:18.534245 2026] [security2:error] [pid 67073:tid 67218] [client 52.173.121.69:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/lddxs.php"] [unique_id "aoSAKvcmepr5_nHgLbM1gAAAAiE"] [Tue Aug 18 12:54:18.651797 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.100.201:58913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/cok.php"] [unique_id "aoSAKvcmepr5_nHgLbM1gwAAAk8"] [Tue Aug 18 12:54:18.691822 2026] [security2:error] [pid 66623:tid 66794] [client 20.91.215.254:20546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/st.php"] [unique_id "aoSAKtO5rbWdOArH04J-fwAAASY"] [Tue Aug 18 12:54:18.702743 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hQAAAjU"] [Tue Aug 18 12:54:18.726119 2026] [security2:error] [pid 67073:tid 67086] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/brc.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hgACdAo"] [Tue Aug 18 12:54:18.799007 2026] [security2:error] [pid 67073:tid 67316] [client 4.232.151.198:6146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hwAAAoM"] [Tue Aug 18 12:54:18.802929 2026] [security2:error] [pid 67073:tid 67283] [client 172.182.200.96:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAKvcmepr5_nHgLbM1iQAAAmI"] [Tue Aug 18 12:54:18.844296 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/43.php"] [unique_id "aoSAKvcmepr5_nHgLbM1jAAAAks"] [Tue Aug 18 12:54:18.985125 2026] [security2:error] [pid 67073:tid 67281] [client 104.209.144.33:19615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zznmg.php"] [unique_id "aoSAKvcmepr5_nHgLbM1kgAAAmA"] [Tue Aug 18 12:54:18.989944 2026] [security2:error] [pid 67073:tid 67222] [client 20.104.100.201:58891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/accesson.php"] [unique_id "aoSAKvcmepr5_nHgLbM1kwAAAiU"] [Tue Aug 18 12:54:19.026660 2026] [security2:error] [pid 67073:tid 67302] [client 103.184.169.37:41315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lAAAAnU"] [Tue Aug 18 12:54:19.026819 2026] [security2:error] [pid 67073:tid 67302] [client 103.184.169.37:41315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lAAAAnU"] [Tue Aug 18 12:54:19.066153 2026] [security2:error] [pid 66623:tid 66835] [client 52.173.121.69:17969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zjggu.php"] [unique_id "aoSAK9O5rbWdOArH04J-lgAAAU8"] [Tue Aug 18 12:54:19.088443 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lQAAAic"] [Tue Aug 18 12:54:19.088855 2026] [security2:error] [pid 67073:tid 67278] [client 104.209.144.33:24845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAK_cmepr5_nHgLbM1lgAAAl0"] [Tue Aug 18 12:54:19.136446 2026] [authz_core:error] [pid 67073:tid 67180] [remote 57.141.22.114:49336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:19.136922 2026] [authz_core:error] [pid 67073:tid 67180] [remote 57.141.22.114:49336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:19.159866 2026] [security2:error] [pid 67073:tid 67244] [client 20.51.153.15:9133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fresh.php"] [unique_id "aoSAK_cmepr5_nHgLbM1mQAAAjs"] [Tue Aug 18 12:54:19.191949 2026] [security2:error] [pid 66623:tid 66890] [client 74.7.230.22:46944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.memorialpax.com.br"] [uri "/index.php"] [unique_id "aoSAK9O5rbWdOArH04J-lwABhjo"] [Tue Aug 18 12:54:19.205549 2026] [security2:error] [pid 66623:tid 66766] [client 20.42.19.40:2730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/k.php"] [unique_id "aoSAK9O5rbWdOArH04J-mQAAAQo"] [Tue Aug 18 12:54:19.234863 2026] [security2:error] [pid 67073:tid 67211] [client 197.184.64.235:41917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1nQAAAho"] [Tue Aug 18 12:54:19.244344 2026] [security2:error] [pid 67073:tid 67329] [client 172.182.200.96:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/yxijx.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ngAAApA"] [Tue Aug 18 12:54:19.344133 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.100.201:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/av.php"] [unique_id "aoSAK_cmepr5_nHgLbM1oAAAAjQ"] [Tue Aug 18 12:54:19.369913 2026] [security2:error] [pid 67073:tid 67298] [client 132.196.61.152:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/mosty.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ogAAAnE"] [Tue Aug 18 12:54:19.393122 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:20592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAK_cmepr5_nHgLbM1owAAAmw"] [Tue Aug 18 12:54:19.404158 2026] [security2:error] [pid 67073:tid 67174] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/file52.php"] [unique_id "aoSAK_cmepr5_nHgLbM1pQACP2I"] [Tue Aug 18 12:54:19.466206 2026] [autoindex:error] [pid 67073:tid 67289] [client 74.248.133.44:45712] AH01276: Cannot serve directory /home3/hyundai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:19.480343 2026] [security2:error] [pid 67073:tid 67124] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qAACTjA"] [Tue Aug 18 12:54:19.480568 2026] [security2:error] [pid 67073:tid 67263] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qAACTjA"] [Tue Aug 18 12:54:19.488509 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAK_cmepr5_nHgLbM1qQAAAl4"] [Tue Aug 18 12:54:19.568546 2026] [security2:error] [pid 66623:tid 66651] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAK9O5rbWdOArH04J-ogABPQ4"] [Tue Aug 18 12:54:19.584126 2026] [security2:error] [pid 66623:tid 66704] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAK9O5rbWdOArH04J-owABEUM"] [Tue Aug 18 12:54:19.597877 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:19.598156 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:19.638173 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:61442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bm.php"] [unique_id "aoSAK_cmepr5_nHgLbM1rQAAAlI"] [Tue Aug 18 12:54:19.672664 2026] [security2:error] [pid 67073:tid 67249] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAK_cmepr5_nHgLbM1rgAAAkA"] [Tue Aug 18 12:54:19.675950 2026] [security2:error] [pid 66623:tid 66660] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/weozh.php"] [unique_id "aoSAK9O5rbWdOArH04J-pQABUxc"] [Tue Aug 18 12:54:19.686911 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.100.201:58443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/kj.php"] [unique_id "aoSAK9O5rbWdOArH04J-pgAAATM"] [Tue Aug 18 12:54:19.748975 2026] [security2:error] [pid 67073:tid 67209] [client 104.234.53.26:31911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samavelveiculos.com.br"] [uri "/wp-login.php"] [unique_id "aoSAKvcmepr5_nHgLbM1hAAAAhg"] [Tue Aug 18 12:54:19.757117 2026] [security2:error] [pid 66623:tid 66681] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/rymmm.php"] [unique_id "aoSAK9O5rbWdOArH04J-pwABVSw"] [Tue Aug 18 12:54:19.764775 2026] [security2:error] [pid 66623:tid 66793] [client 138.36.100.162:42602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK9O5rbWdOArH04J-qAAAASU"] [Tue Aug 18 12:54:19.764886 2026] [security2:error] [pid 66623:tid 66793] [client 138.36.100.162:42602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK9O5rbWdOArH04J-qAAAASU"] [Tue Aug 18 12:54:19.772829 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.133.44:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sAAAAos"] [Tue Aug 18 12:54:19.774267 2026] [security2:error] [pid 66623:tid 66661] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/lddxs.php"] [unique_id "aoSAK9O5rbWdOArH04J-qQABZRg"] [Tue Aug 18 12:54:19.776263 2026] [security2:error] [pid 67073:tid 67253] [client 4.232.151.198:6161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mass.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sQAAAkQ"] [Tue Aug 18 12:54:19.778157 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.100.201:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/img.php"] [unique_id "aoSAK_cmepr5_nHgLbM1sgAAAo4"] [Tue Aug 18 12:54:19.786654 2026] [security2:error] [pid 67073:tid 67282] [client 20.163.43.14:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAK_cmepr5_nHgLbM1tAAAAmE"] [Tue Aug 18 12:54:19.794074 2026] [security2:error] [pid 67073:tid 67256] [client 52.173.121.69:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAK_cmepr5_nHgLbM1tQAAAkc"] [Tue Aug 18 12:54:19.819577 2026] [security2:error] [pid 67073:tid 67214] [client 5.31.227.224:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ugAAAh0"] [Tue Aug 18 12:54:19.819687 2026] [security2:error] [pid 67073:tid 67214] [client 5.31.227.224:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1ugAAAh0"] [Tue Aug 18 12:54:19.827870 2026] [security2:error] [pid 67073:tid 67239] [client 114.119.132.171:62037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.confiancaveiculostj.com.br"] [uri "/veiculo/176235/c3-excl-1-6-vti-flex-start-16v-5p-mec"] [unique_id "aoSAK_cmepr5_nHgLbM1uwAAAjY"], referer: https://www.confiancaveiculostj.com.br/veiculo/176235/c3-excl-1-6-vti-flex-start-16v-5p-mec [Tue Aug 18 12:54:19.848159 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.136.165:65315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xqq.php"] [unique_id "aoSAK9O5rbWdOArH04J-qgAAASk"] [Tue Aug 18 12:54:19.884645 2026] [security2:error] [pid 66623:tid 66727] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zjggu.php"] [unique_id "aoSAK9O5rbWdOArH04J-qwABZ1o"] [Tue Aug 18 12:54:19.963425 2026] [security2:error] [pid 67073:tid 67216] [client 78.138.24.128:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.24.138.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAKfcmepr5_nHgLbM1bQAAAh8"] [Tue Aug 18 12:54:19.969005 2026] [security2:error] [pid 67073:tid 67314] [client 20.51.153.15:9138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gj.php"] [unique_id "aoSAK_cmepr5_nHgLbM1vQAAAoE"] [Tue Aug 18 12:54:19.970070 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSAK_cmepr5_nHgLbM1vgAAAjc"] [Tue Aug 18 12:54:20.006854 2026] [security2:error] [pid 67073:tid 67185] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSALPcmepr5_nHgLbM1wAACYm0"] [Tue Aug 18 12:54:20.021698 2026] [security2:error] [pid 67073:tid 67317] [client 158.158.74.177:15844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSALPcmepr5_nHgLbM1wQAAAoQ"] [Tue Aug 18 12:54:20.045234 2026] [security2:error] [pid 67073:tid 67210] [client 20.151.109.219:22929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/10.php"] [unique_id "aoSALPcmepr5_nHgLbM1xAAAAhk"] [Tue Aug 18 12:54:20.058957 2026] [security2:error] [pid 67073:tid 67235] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/2.php"] [unique_id "aoSALPcmepr5_nHgLbM1xQAAAjI"] [Tue Aug 18 12:54:20.067517 2026] [security2:error] [pid 66623:tid 66696] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/dlvqo.php"] [unique_id "aoSALNO5rbWdOArH04J-rQABbjs"] [Tue Aug 18 12:54:20.083202 2026] [security2:error] [pid 66623:tid 66749] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/pkmoj.php"] [unique_id "aoSALNO5rbWdOArH04J-rgABW3A"] [Tue Aug 18 12:54:20.105510 2026] [authz_core:error] [pid 67073:tid 67087] [remote 57.141.22.6:53752] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:20.105781 2026] [authz_core:error] [pid 67073:tid 67087] [remote 57.141.22.6:53752] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:20.107018 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:20555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-configs.php"] [unique_id "aoSALPcmepr5_nHgLbM1yQAAAo0"] [Tue Aug 18 12:54:20.127365 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:3191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/abc.php"] [unique_id "aoSALPcmepr5_nHgLbM1zAAAAiU"] [Tue Aug 18 12:54:20.137546 2026] [security2:error] [pid 66623:tid 66648] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/kopyw.php"] [unique_id "aoSALNO5rbWdOArH04J-tQABRws"] [Tue Aug 18 12:54:20.152238 2026] [security2:error] [pid 66623:tid 66637] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zznmg.php"] [unique_id "aoSALNO5rbWdOArH04J-tgABTQA"] [Tue Aug 18 12:54:20.155002 2026] [security2:error] [pid 67073:tid 67224] [client 20.171.51.14:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vu.php"] [unique_id "aoSALPcmepr5_nHgLbM1zgAAAic"] [Tue Aug 18 12:54:20.168641 2026] [security2:error] [pid 67073:tid 67244] [client 40.85.222.29:31688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSALPcmepr5_nHgLbM1zwAAAjs"] [Tue Aug 18 12:54:20.210367 2026] [security2:error] [pid 67073:tid 67158] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/path.php"] [unique_id "aoSALPcmepr5_nHgLbM10QACVlI"] [Tue Aug 18 12:54:20.232800 2026] [security2:error] [pid 66623:tid 66716] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/bhfnd.php"] [unique_id "aoSALNO5rbWdOArH04J-ugABak8"] [Tue Aug 18 12:54:20.249249 2026] [security2:error] [pid 67073:tid 67313] [client 20.104.100.201:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/png.php"] [unique_id "aoSALPcmepr5_nHgLbM10wAAAoA"] [Tue Aug 18 12:54:20.268086 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.136.165:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/06.php"] [unique_id "aoSALNO5rbWdOArH04J-uwAAAVI"] [Tue Aug 18 12:54:20.276271 2026] [security2:error] [pid 67073:tid 67293] [client 20.65.98.162:21021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/133.php"] [unique_id "aoSALPcmepr5_nHgLbM11AAAAmw"] [Tue Aug 18 12:54:20.277138 2026] [security2:error] [pid 66623:tid 66751] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/qfvqu.php"] [unique_id "aoSALNO5rbWdOArH04J-vQABOnI"] [Tue Aug 18 12:54:20.315501 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.18.37:28391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/edit-tags.php"] [unique_id "aoSALPcmepr5_nHgLbM12QAAAjk"] [Tue Aug 18 12:54:20.335891 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSALPcmepr5_nHgLbM12wAAAkA"] [Tue Aug 18 12:54:20.336920 2026] [security2:error] [pid 67073:tid 67100] [remote 47.89.174.181:64940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "agenda.automasantos.com.br"] [uri "/.env"] [unique_id "aoSALPcmepr5_nHgLbM12gACkBg"] [Tue Aug 18 12:54:20.394030 2026] [security2:error] [pid 66623:tid 66733] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/oivcl.php"] [unique_id "aoSALNO5rbWdOArH04J-vgABI2A"] [Tue Aug 18 12:54:20.400024 2026] [security2:error] [pid 67073:tid 67122] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wpo.php"] [unique_id "aoSALPcmepr5_nHgLbM13QACTC4"] [Tue Aug 18 12:54:20.400388 2026] [security2:error] [pid 66623:tid 66882] [client 4.232.151.198:6156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/memberfuns.php"] [unique_id "aoSALNO5rbWdOArH04J-vwAAAX4"] [Tue Aug 18 12:54:20.403132 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.18.37:21438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mah/function.php"] [unique_id "aoSALNO5rbWdOArH04J-wAAAARU"] [Tue Aug 18 12:54:20.448589 2026] [security2:error] [pid 67073:tid 67211] [client 197.184.64.235:41917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAK_cmepr5_nHgLbM1nQAAAho"] [Tue Aug 18 12:54:20.458810 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:3169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/akcc.php"] [unique_id "aoSALPcmepr5_nHgLbM13wAAAkc"] [Tue Aug 18 12:54:20.465462 2026] [security2:error] [pid 66623:tid 66832] [client 52.238.210.254:8929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/class.php"] [unique_id "aoSALNO5rbWdOArH04J-wgAAAUw"] [Tue Aug 18 12:54:20.469958 2026] [security2:error] [pid 66623:tid 66643] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zugvi.php"] [unique_id "aoSALNO5rbWdOArH04J-wwABegY"] [Tue Aug 18 12:54:20.481563 2026] [security2:error] [pid 67073:tid 67206] [client 20.51.153.15:9114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pd.php"] [unique_id "aoSALPcmepr5_nHgLbM14QAAAhU"] [Tue Aug 18 12:54:20.497767 2026] [security2:error] [pid 67073:tid 67219] [client 20.104.100.201:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "contabileconomy.com.br"] [uri "/we.php"] [unique_id "aoSALPcmepr5_nHgLbM14wAAAiI"] [Tue Aug 18 12:54:20.501139 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:20.501507 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:20.515388 2026] [security2:error] [pid 67073:tid 67284] [client 68.155.154.236:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSALPcmepr5_nHgLbM15AAAAmM"] [Tue Aug 18 12:54:20.520094 2026] [security2:error] [pid 66623:tid 66870] [client 104.209.144.33:24882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSALNO5rbWdOArH04J-xQAAAXI"] [Tue Aug 18 12:54:20.524365 2026] [security2:error] [pid 67073:tid 67218] [client 20.104.100.201:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ab.php"] [unique_id "aoSALPcmepr5_nHgLbM15QAAAiE"] [Tue Aug 18 12:54:20.528461 2026] [security2:error] [pid 66623:tid 66822] [client 52.238.210.254:8993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSALNO5rbWdOArH04J-xgAAAUI"] [Tue Aug 18 12:54:20.532515 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:16457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/pkmoj.php"] [unique_id "aoSALNO5rbWdOArH04J-xwAAAR8"] [Tue Aug 18 12:54:20.541023 2026] [security2:error] [pid 66623:tid 66844] [client 213.202.253.4:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSALNO5rbWdOArH04J-yAAAAVg"], referer: www.google.com [Tue Aug 18 12:54:20.544506 2026] [security2:error] [pid 66623:tid 66739] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wsrer.php"] [unique_id "aoSALNO5rbWdOArH04J-yQABWWY"] [Tue Aug 18 12:54:20.577513 2026] [security2:error] [pid 66623:tid 66666] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/ucpfr.php"] [unique_id "aoSALNO5rbWdOArH04J-ywABUR0"] [Tue Aug 18 12:54:20.592232 2026] [security2:error] [pid 66623:tid 66646] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/yxijx.php"] [unique_id "aoSALNO5rbWdOArH04J-zAABRQk"] [Tue Aug 18 12:54:20.606228 2026] [security2:error] [pid 66623:tid 66642] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/zwlsv.php"] [unique_id "aoSALNO5rbWdOArH04J-zQABJAU"] [Tue Aug 18 12:54:20.624522 2026] [security2:error] [pid 66623:tid 66723] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/jrpga.php"] [unique_id "aoSALNO5rbWdOArH04J-zgABfVY"] [Tue Aug 18 12:54:20.655180 2026] [autoindex:error] [pid 67073:tid 67253] [client 158.158.74.177:15856] AH01276: Cannot serve directory /home3/evandrobene/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:20.668858 2026] [security2:error] [pid 67073:tid 67305] [client 172.182.200.96:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/zwlsv.php"] [unique_id "aoSALPcmepr5_nHgLbM17AAAAng"] [Tue Aug 18 12:54:20.678204 2026] [security2:error] [pid 66623:tid 66710] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSALNO5rbWdOArH04J-zwABhEk"] [Tue Aug 18 12:54:20.685913 2026] [security2:error] [pid 67073:tid 67232] [client 20.250.13.23:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/nw.php"] [unique_id "aoSALPcmepr5_nHgLbM17QAAAi8"] [Tue Aug 18 12:54:20.687452 2026] [security2:error] [pid 67073:tid 67317] [client 74.248.136.165:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/166.php"] [unique_id "aoSALPcmepr5_nHgLbM17gAAAoQ"] [Tue Aug 18 12:54:20.749861 2026] [security2:error] [pid 67073:tid 67266] [client 20.91.215.254:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-post.php"] [unique_id "aoSALPcmepr5_nHgLbM18QAAAlE"] [Tue Aug 18 12:54:20.754850 2026] [security2:error] [pid 66623:tid 66768] [client 20.171.51.14:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ic.php"] [unique_id "aoSALNO5rbWdOArH04J-0QAAAQw"] [Tue Aug 18 12:54:20.792668 2026] [security2:error] [pid 67073:tid 67312] [client 20.51.153.15:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/th.php"] [unique_id "aoSALPcmepr5_nHgLbM18gAAAn8"] [Tue Aug 18 12:54:20.794811 2026] [security2:error] [pid 67073:tid 67260] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM17wACS2A"] [Tue Aug 18 12:54:20.796016 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/12.php"] [unique_id "aoSALPcmepr5_nHgLbM18wAAAo0"] [Tue Aug 18 12:54:20.801826 2026] [security2:error] [pid 66623:tid 66697] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/nwwha.php"] [unique_id "aoSALNO5rbWdOArH04J-0gABJjw"] [Tue Aug 18 12:54:20.807589 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.6.191:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/13.php"] [unique_id "aoSALPcmepr5_nHgLbM19AAAAiQ"] [Tue Aug 18 12:54:20.807612 2026] [security2:error] [pid 67073:tid 67254] [client 20.48.236.86:10404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bajah.php"] [unique_id "aoSALPcmepr5_nHgLbM19QAAAkU"] [Tue Aug 18 12:54:20.844640 2026] [security2:error] [pid 66623:tid 66732] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/opsqt.php"] [unique_id "aoSALNO5rbWdOArH04J-0wABX18"] [Tue Aug 18 12:54:20.860374 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.74.177:15856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSALPcmepr5_nHgLbM1-AAAApE"] [Tue Aug 18 12:54:20.860375 2026] [security2:error] [pid 66623:tid 66672] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/jvcpa.php"] [unique_id "aoSALNO5rbWdOArH04J-1AABGyM"] [Tue Aug 18 12:54:20.877406 2026] [security2:error] [pid 66623:tid 66730] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSALNO5rbWdOArH04J-1QABFF0"] [Tue Aug 18 12:54:20.884883 2026] [security2:error] [pid 66623:tid 66885] [client 20.163.43.14:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wk/index.php"] [unique_id "aoSALNO5rbWdOArH04J-1gAAAYE"] [Tue Aug 18 12:54:20.893467 2026] [security2:error] [pid 66623:tid 66699] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSALNO5rbWdOArH04J-1wABGD4"] [Tue Aug 18 12:54:20.907535 2026] [security2:error] [pid 66623:tid 66713] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSALNO5rbWdOArH04J-2AABg0w"] [Tue Aug 18 12:54:20.935394 2026] [security2:error] [pid 67073:tid 67309] [client 132.196.61.152:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/blurbs.php"] [unique_id "aoSALPcmepr5_nHgLbM1-gAAAnw"] [Tue Aug 18 12:54:20.951434 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM1-wAAAh0"] [Tue Aug 18 12:54:20.951552 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:2904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALPcmepr5_nHgLbM1-wAAAh0"] [Tue Aug 18 12:54:20.958807 2026] [security2:error] [pid 67073:tid 67213] [client 111.225.148.160:20386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/gloria-kalil-lanca-novo-livro-em-campinas/"] [unique_id "aoSALPcmepr5_nHgLbM1_AAAAhw"] [Tue Aug 18 12:54:20.959963 2026] [security2:error] [pid 67073:tid 67299] [client 104.209.144.33:24892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSALPcmepr5_nHgLbM1_QAAAnI"] [Tue Aug 18 12:54:20.963302 2026] [security2:error] [pid 67073:tid 67311] [client 68.155.154.236:64544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSALPcmepr5_nHgLbM1_gAAAn4"] [Tue Aug 18 12:54:20.965058 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.136.165:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mans.php"] [unique_id "aoSALPcmepr5_nHgLbM1_wAAApM"] [Tue Aug 18 12:54:20.990838 2026] [security2:error] [pid 66623:tid 66754] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSALNO5rbWdOArH04J-2QABF3U"] [Tue Aug 18 12:54:21.011482 2026] [security2:error] [pid 67073:tid 67313] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSALfcmepr5_nHgLbM2AQAAAoA"] [Tue Aug 18 12:54:21.014847 2026] [security2:error] [pid 67073:tid 67225] [client 172.182.200.96:14235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/jrpga.php"] [unique_id "aoSALfcmepr5_nHgLbM2AgAAAig"] [Tue Aug 18 12:54:21.018296 2026] [security2:error] [pid 67073:tid 67293] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSALfcmepr5_nHgLbM2AwAAAmw"] [Tue Aug 18 12:54:21.022928 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:48165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/meta.php"] [unique_id "aoSALdO5rbWdOArH04J-2gAAAXA"] [Tue Aug 18 12:54:21.023009 2026] [security2:error] [pid 67073:tid 67233] [client 20.118.172.148:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/cong.php"] [unique_id "aoSALfcmepr5_nHgLbM2BAAAAjA"] [Tue Aug 18 12:54:21.031101 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:19970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSALdO5rbWdOArH04J-2wAAAR4"] [Tue Aug 18 12:54:21.052243 2026] [security2:error] [pid 66623:tid 66821] [client 20.51.153.15:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/admin404.php"] [unique_id "aoSALdO5rbWdOArH04J-3AAAAUE"] [Tue Aug 18 12:54:21.075730 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/x1da.php"] [unique_id "aoSALdO5rbWdOArH04J-3QAAAU8"] [Tue Aug 18 12:54:21.101063 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:21.101359 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:21.105272 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.136.165:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/snq.php"] [unique_id "aoSALfcmepr5_nHgLbM2CgAAAk4"] [Tue Aug 18 12:54:21.182509 2026] [security2:error] [pid 66623:tid 66766] [client 52.173.121.69:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/kopyw.php"] [unique_id "aoSALdO5rbWdOArH04J-3wAAAQo"] [Tue Aug 18 12:54:21.193832 2026] [security2:error] [pid 66623:tid 66673] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSALdO5rbWdOArH04J-4AABSSQ"] [Tue Aug 18 12:54:21.229972 2026] [security2:error] [pid 66623:tid 66798] [client 20.163.43.14:3145] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ns2.noise2.com.br"] [uri "/1.php"] [unique_id "aoSALdO5rbWdOArH04J-4QAAASo"] [Tue Aug 18 12:54:21.230078 2026] [security2:error] [pid 66623:tid 66798] [client 20.163.43.14:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/1.php"] [unique_id "aoSALdO5rbWdOArH04J-4QAAASo"] [Tue Aug 18 12:54:21.236286 2026] [security2:error] [pid 67073:tid 67320] [client 149.34.210.141:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2DAAAAoc"] [Tue Aug 18 12:54:21.253650 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ue.php"] [unique_id "aoSALfcmepr5_nHgLbM2DQAAAiY"] [Tue Aug 18 12:54:21.270905 2026] [security2:error] [pid 66623:tid 66684] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSALdO5rbWdOArH04J-4gABby8"] [Tue Aug 18 12:54:21.300427 2026] [security2:error] [pid 66623:tid 66839] [client 20.151.109.219:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/te.php"] [unique_id "aoSALdO5rbWdOArH04J-4wAAAVM"] [Tue Aug 18 12:54:21.308710 2026] [security2:error] [pid 67073:tid 67230] [client 132.196.61.152:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bajah.php"] [unique_id "aoSALfcmepr5_nHgLbM2EAAAAi0"] [Tue Aug 18 12:54:21.312681 2026] [security2:error] [pid 67073:tid 67290] [client 157.20.138.62:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2EQAAAmk"] [Tue Aug 18 12:54:21.312852 2026] [security2:error] [pid 67073:tid 67290] [client 157.20.138.62:53651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2EQAAAmk"] [Tue Aug 18 12:54:21.353668 2026] [security2:error] [pid 66623:tid 66793] [client 20.51.153.15:9122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/qo.php"] [unique_id "aoSALdO5rbWdOArH04J-5QAAASU"] [Tue Aug 18 12:54:21.366999 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSALdO5rbWdOArH04J-6AAAAVw"] [Tue Aug 18 12:54:21.369665 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSALdO5rbWdOArH04J-6QAAAVo"] [Tue Aug 18 12:54:21.373809 2026] [security2:error] [pid 67073:tid 67282] [client 20.104.100.201:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mcs.php"] [unique_id "aoSALfcmepr5_nHgLbM2FAAAAmE"] [Tue Aug 18 12:54:21.385262 2026] [security2:error] [pid 66623:tid 66863] [client 104.209.144.33:25295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/first.php"] [unique_id "aoSALdO5rbWdOArH04J-6wAAAWs"] [Tue Aug 18 12:54:21.424921 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSALfcmepr5_nHgLbM2FwAAAkc"] [Tue Aug 18 12:54:21.429911 2026] [security2:error] [pid 66623:tid 66831] [client 104.209.144.33:33707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/bhfnd.php"] [unique_id "aoSALdO5rbWdOArH04J-7gAAAUs"] [Tue Aug 18 12:54:21.430511 2026] [security2:error] [pid 66623:tid 66690] [remote 20.75.217.69:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSALdO5rbWdOArH04J-7QABDjU"] [Tue Aug 18 12:54:21.442950 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.132.72:24689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "financeiro.fabioweb.com.br"] [uri "/pwreset.php"] [unique_id "aoSALfcmepr5_nHgLbM2GAAAAm8"], referer: https://financeiro.fabioweb.com.br/pwreset.php?language=norwegian [Tue Aug 18 12:54:21.444402 2026] [security2:error] [pid 66623:tid 66859] [client 172.182.200.96:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSALdO5rbWdOArH04J-7wAAAWc"] [Tue Aug 18 12:54:21.481859 2026] [security2:error] [pid 66623:tid 66817] [client 20.91.215.254:24332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSALdO5rbWdOArH04J-8gAAAT0"] [Tue Aug 18 12:54:21.492889 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.74.177:17162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSALfcmepr5_nHgLbM2GgAAAkw"] [Tue Aug 18 12:54:21.492909 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/a1vx.php"] [unique_id "aoSALfcmepr5_nHgLbM2GwACYyk"] [Tue Aug 18 12:54:21.502945 2026] [security2:error] [pid 67073:tid 67320] [client 149.34.210.141:61148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSALfcmepr5_nHgLbM2DAAAAoc"] [Tue Aug 18 12:54:21.523165 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.136.165:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-access.php"] [unique_id "aoSALdO5rbWdOArH04J-8wAAAVs"] [Tue Aug 18 12:54:21.545771 2026] [security2:error] [pid 66623:tid 66841] [client 5.253.205.188:34796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullbackup.sql"] [unique_id "aoSALdO5rbWdOArH04J-9AAAAVU"], referer: https://medihub.com.br/fullbackup.sql [Tue Aug 18 12:54:21.558236 2026] [security2:error] [pid 66623:tid 66833] [client 68.155.154.236:65192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSALdO5rbWdOArH04J-9QAAAU0"] [Tue Aug 18 12:54:21.567631 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:3132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSALdO5rbWdOArH04J-9gAAAXk"] [Tue Aug 18 12:54:21.616539 2026] [security2:error] [pid 66623:tid 66772] [client 20.51.153.15:9215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sd.php"] [unique_id "aoSALdO5rbWdOArH04J--AAAARA"] [Tue Aug 18 12:54:21.635502 2026] [security2:error] [pid 66623:tid 66725] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSALdO5rbWdOArH04J--QABYFg"] [Tue Aug 18 12:54:21.643545 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.100.201:58456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/adminner.php"] [unique_id "aoSALdO5rbWdOArH04J--gAAAUg"] [Tue Aug 18 12:54:21.652131 2026] [security2:error] [pid 66623:tid 66795] [client 4.232.151.198:6150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mini.php"] [unique_id "aoSALdO5rbWdOArH04J--wAAASc"] [Tue Aug 18 12:54:21.661766 2026] [security2:error] [pid 67073:tid 67307] [client 74.248.18.37:20014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mass.php"] [unique_id "aoSALfcmepr5_nHgLbM2HwAAAno"] [Tue Aug 18 12:54:21.670103 2026] [security2:error] [pid 66623:tid 66711] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSALdO5rbWdOArH04J-_AABcUo"] [Tue Aug 18 12:54:21.672575 2026] [security2:error] [pid 67073:tid 67191] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ty.php"] [unique_id "aoSALfcmepr5_nHgLbM2IAACFnM"] [Tue Aug 18 12:54:21.685591 2026] [security2:error] [pid 66623:tid 66729] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSALdO5rbWdOArH04J-_QABe1w"] [Tue Aug 18 12:54:21.692715 2026] [security2:error] [pid 66623:tid 66815] [client 20.48.236.86:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.onemotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSALdO5rbWdOArH04J-_gAAATs"] [Tue Aug 18 12:54:21.706090 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:21.706357 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:21.713397 2026] [security2:error] [pid 66623:tid 66814] [client 135.225.75.187:19222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms.php"] [unique_id "aoSALdO5rbWdOArH04J-_wAAATo"] [Tue Aug 18 12:54:21.731795 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSALdO5rbWdOArH04J_AAAAARI"] [Tue Aug 18 12:54:21.733088 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.61.152:56082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/h.php"] [unique_id "aoSALdO5rbWdOArH04J_AQAAAX4"] [Tue Aug 18 12:54:21.753537 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSALdO5rbWdOArH04J_AgAAAQ0"] [Tue Aug 18 12:54:21.758045 2026] [security2:error] [pid 66623:tid 66755] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSALdO5rbWdOArH04J_AwABTHY"] [Tue Aug 18 12:54:21.762577 2026] [security2:error] [pid 66623:tid 66884] [client 52.173.121.69:17983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zznmg.php"] [unique_id "aoSALdO5rbWdOArH04J_BAAAAYA"] [Tue Aug 18 12:54:21.774284 2026] [security2:error] [pid 66623:tid 66655] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSALdO5rbWdOArH04J_BgABehI"] [Tue Aug 18 12:54:21.791936 2026] [security2:error] [pid 66623:tid 66731] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSALdO5rbWdOArH04J_BwABP14"] [Tue Aug 18 12:54:21.807241 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.200.96:14303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/nwwha.php"] [unique_id "aoSALdO5rbWdOArH04J_CAAAAYg"] [Tue Aug 18 12:54:21.807822 2026] [security2:error] [pid 66623:tid 66718] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSALdO5rbWdOArH04J_CQABC1E"] [Tue Aug 18 12:54:21.822348 2026] [security2:error] [pid 66623:tid 66753] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSALdO5rbWdOArH04J_CgABUXQ"] [Tue Aug 18 12:54:21.837133 2026] [security2:error] [pid 66623:tid 66759] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSALdO5rbWdOArH04J_CwABRXo"] [Tue Aug 18 12:54:21.895247 2026] [security2:error] [pid 66623:tid 66762] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSALdO5rbWdOArH04J_DQABMn0"] [Tue Aug 18 12:54:21.918596 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.100.201:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dragonshell.php"] [unique_id "aoSALdO5rbWdOArH04J_DgAAAXU"] [Tue Aug 18 12:54:21.925318 2026] [security2:error] [pid 67073:tid 67268] [client 20.51.153.15:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/km.php"] [unique_id "aoSALfcmepr5_nHgLbM2JgAAAlM"] [Tue Aug 18 12:54:21.941355 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.136.165:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nw.php"] [unique_id "aoSALdO5rbWdOArH04J_EAAAASY"] [Tue Aug 18 12:54:21.957361 2026] [security2:error] [pid 66623:tid 66750] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSALdO5rbWdOArH04J_EQABeHE"] [Tue Aug 18 12:54:21.958588 2026] [security2:error] [pid 66623:tid 66776] [client 20.163.43.14:3180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSALdO5rbWdOArH04J_EgAAARQ"] [Tue Aug 18 12:54:22.028679 2026] [security2:error] [pid 66623:tid 66748] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSALtO5rbWdOArH04J_FQABc28"] [Tue Aug 18 12:54:22.034127 2026] [security2:error] [pid 67073:tid 67210] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSALvcmepr5_nHgLbM2KgAAAhk"] [Tue Aug 18 12:54:22.073555 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.98.162:22676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/1xmomo.php"] [unique_id "aoSALtO5rbWdOArH04J_FwAAAXA"] [Tue Aug 18 12:54:22.119617 2026] [security2:error] [pid 66623:tid 66875] [client 20.91.215.254:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSALtO5rbWdOArH04J_GAAAAXc"] [Tue Aug 18 12:54:22.144426 2026] [security2:error] [pid 66623:tid 66834] [client 158.158.74.177:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/f7.php"] [unique_id "aoSALtO5rbWdOArH04J_GQAAAU4"] [Tue Aug 18 12:54:22.153567 2026] [security2:error] [pid 66623:tid 66640] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSALtO5rbWdOArH04J_GgABQQM"] [Tue Aug 18 12:54:22.161135 2026] [security2:error] [pid 66623:tid 66803] [client 172.182.200.96:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/opsqt.php"] [unique_id "aoSALtO5rbWdOArH04J_GwAAAS8"] [Tue Aug 18 12:54:22.170327 2026] [security2:error] [pid 66623:tid 66703] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSALtO5rbWdOArH04J_HAABT0I"] [Tue Aug 18 12:54:22.179237 2026] [security2:error] [pid 67073:tid 67312] [client 20.171.51.14:16756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lr.php"] [unique_id "aoSALvcmepr5_nHgLbM2LAAAAn8"] [Tue Aug 18 12:54:22.186242 2026] [security2:error] [pid 66623:tid 66726] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSALtO5rbWdOArH04J_HQABhlk"] [Tue Aug 18 12:54:22.187302 2026] [security2:error] [pid 66623:tid 66808] [client 172.202.39.151:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSALtO5rbWdOArH04J_HgAAATQ"] [Tue Aug 18 12:54:22.187832 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mf.php"] [unique_id "aoSALvcmepr5_nHgLbM2LQAAAks"] [Tue Aug 18 12:54:22.194376 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/bhfnd.php"] [unique_id "aoSALvcmepr5_nHgLbM2MAAAAo0"] [Tue Aug 18 12:54:22.195309 2026] [security2:error] [pid 67073:tid 67212] [client 20.104.100.201:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/setup-config.php"] [unique_id "aoSALvcmepr5_nHgLbM2MQAAAhs"] [Tue Aug 18 12:54:22.229273 2026] [security2:error] [pid 66623:tid 66752] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSALtO5rbWdOArH04J_IAABSXM"] [Tue Aug 18 12:54:22.246702 2026] [security2:error] [pid 66623:tid 66738] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSALtO5rbWdOArH04J_IQABOGU"] [Tue Aug 18 12:54:22.253557 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:25982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSALtO5rbWdOArH04J_IgAAAS0"] [Tue Aug 18 12:54:22.272491 2026] [security2:error] [pid 67073:tid 67239] [client 20.250.13.23:44667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/xleet.php"] [unique_id "aoSALvcmepr5_nHgLbM2MgAAAjY"] [Tue Aug 18 12:54:22.273168 2026] [security2:error] [pid 67073:tid 67254] [client 104.209.144.33:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2MwAAAkU"] [Tue Aug 18 12:54:22.275749 2026] [security2:error] [pid 67073:tid 67235] [client 4.232.151.198:6173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/mm.php"] [unique_id "aoSALvcmepr5_nHgLbM2NAAAAjI"] [Tue Aug 18 12:54:22.284816 2026] [security2:error] [pid 67073:tid 67251] [client 213.35.127.232:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSALvcmepr5_nHgLbM2NgAAAkI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:22.306914 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/h.php"] [unique_id "aoSALvcmepr5_nHgLbM2NwAAAiU"] [Tue Aug 18 12:54:22.307127 2026] [security2:error] [pid 67073:tid 67281] [client 68.155.154.236:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/mt/byp.php"] [unique_id "aoSALvcmepr5_nHgLbM2OAAAAmA"] [Tue Aug 18 12:54:22.321250 2026] [security2:error] [pid 67073:tid 67257] [client 172.182.200.96:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSALvcmepr5_nHgLbM2OQAAAkg"] [Tue Aug 18 12:54:22.328354 2026] [security2:error] [pid 67073:tid 67234] [client 20.163.43.14:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/as.php"] [unique_id "aoSALvcmepr5_nHgLbM2OwAAAjE"] [Tue Aug 18 12:54:22.336752 2026] [security2:error] [pid 66623:tid 66665] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSALtO5rbWdOArH04J_IwABHBw"] [Tue Aug 18 12:54:22.349245 2026] [security2:error] [pid 67073:tid 67278] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSALvcmepr5_nHgLbM2PAAAAl0"] [Tue Aug 18 12:54:22.360182 2026] [security2:error] [pid 67073:tid 67258] [client 74.248.136.165:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws62.php"] [unique_id "aoSALvcmepr5_nHgLbM2PQAAAkk"] [Tue Aug 18 12:54:22.408950 2026] [security2:error] [pid 67073:tid 67208] [client 74.248.18.37:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/memberfuns.php"] [unique_id "aoSALvcmepr5_nHgLbM2QAAAAhc"] [Tue Aug 18 12:54:22.462112 2026] [security2:error] [pid 67073:tid 67078] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/vgtyu.php"] [unique_id "aoSALvcmepr5_nHgLbM2RwACfgI"] [Tue Aug 18 12:54:22.475912 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.100.201:58912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/f35.update.php"] [unique_id "aoSALvcmepr5_nHgLbM2SQAAApM"] [Tue Aug 18 12:54:22.480512 2026] [security2:error] [pid 66623:tid 66707] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSALtO5rbWdOArH04J_JQABb0Y"] [Tue Aug 18 12:54:22.484573 2026] [security2:error] [pid 67073:tid 67225] [client 20.51.153.15:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ie.php"] [unique_id "aoSALvcmepr5_nHgLbM2SgAAAig"] [Tue Aug 18 12:54:22.498664 2026] [security2:error] [pid 66623:tid 66792] [client 178.153.171.161:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALtO5rbWdOArH04J_JgAAASQ"] [Tue Aug 18 12:54:22.498789 2026] [security2:error] [pid 66623:tid 66792] [client 178.153.171.161:39177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSALtO5rbWdOArH04J_JgAAASQ"] [Tue Aug 18 12:54:22.528559 2026] [security2:error] [pid 66623:tid 66741] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSALtO5rbWdOArH04J_JwABEWg"] [Tue Aug 18 12:54:22.542984 2026] [security2:error] [pid 66623:tid 66679] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSALtO5rbWdOArH04J_KAABGio"] [Tue Aug 18 12:54:22.559586 2026] [security2:error] [pid 66623:tid 66743] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSALtO5rbWdOArH04J_KQABJWo"] [Tue Aug 18 12:54:22.559605 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.200.96:14253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/jvcpa.php"] [unique_id "aoSALvcmepr5_nHgLbM2TgAAAlk"] [Tue Aug 18 12:54:22.575166 2026] [security2:error] [pid 66623:tid 66764] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSALtO5rbWdOArH04J_KgABWn8"] [Tue Aug 18 12:54:22.656396 2026] [security2:error] [pid 67073:tid 67223] [client 20.163.43.14:3082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSALvcmepr5_nHgLbM2VAAAAiY"] [Tue Aug 18 12:54:22.682282 2026] [security2:error] [pid 67073:tid 67205] [client 172.202.39.151:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/public/css.php"] [unique_id "aoSALvcmepr5_nHgLbM2VwAAAhQ"] [Tue Aug 18 12:54:22.684151 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.18.37:24326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/u.php"] [unique_id "aoSALvcmepr5_nHgLbM2WAAAAjg"] [Tue Aug 18 12:54:22.690893 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSALtO5rbWdOArH04J_LAAAAUo"] [Tue Aug 18 12:54:22.691679 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSALvcmepr5_nHgLbM2WwAAAi0"] [Tue Aug 18 12:54:22.708205 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.169.31:33841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/p.php"] [unique_id "aoSALvcmepr5_nHgLbM2XAAAAoY"] [Tue Aug 18 12:54:22.731980 2026] [security2:error] [pid 66623:tid 66700] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSALtO5rbWdOArH04J_LQABSz8"] [Tue Aug 18 12:54:22.732225 2026] [autoindex:error] [pid 67073:tid 67300] [client 20.104.85.180:8019] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:22.750822 2026] [security2:error] [pid 66623:tid 66742] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSALtO5rbWdOArH04J_LgABZ2k"] [Tue Aug 18 12:54:22.751192 2026] [security2:error] [pid 67073:tid 67256] [client 20.104.100.201:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/bdroot.php"] [unique_id "aoSALvcmepr5_nHgLbM2YAAAAkc"] [Tue Aug 18 12:54:22.763742 2026] [security2:error] [pid 66623:tid 66849] [client 158.158.74.177:15841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/photo.php"] [unique_id "aoSALtO5rbWdOArH04J_LwAAAV0"] [Tue Aug 18 12:54:22.777526 2026] [security2:error] [pid 66623:tid 66823] [client 20.151.109.219:28793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/kc.php"] [unique_id "aoSALtO5rbWdOArH04J_MAAAAUM"] [Tue Aug 18 12:54:22.778498 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.136.165:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/vx.php"] [unique_id "aoSALvcmepr5_nHgLbM2YQAAAm8"] [Tue Aug 18 12:54:22.778639 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:31624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ka.php"] [unique_id "aoSALvcmepr5_nHgLbM2YgAAAns"] [Tue Aug 18 12:54:22.791629 2026] [security2:error] [pid 66623:tid 66683] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSALtO5rbWdOArH04J_MQABdi4"] [Tue Aug 18 12:54:22.800555 2026] [security2:error] [pid 66623:tid 66866] [client 20.51.153.15:8712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nw.php"] [unique_id "aoSALtO5rbWdOArH04J_MgAAAW4"] [Tue Aug 18 12:54:22.813524 2026] [security2:error] [pid 66623:tid 66763] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSALtO5rbWdOArH04J_MwABW34"] [Tue Aug 18 12:54:22.831242 2026] [security2:error] [pid 66623:tid 66757] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSALtO5rbWdOArH04J_NAABNng"] [Tue Aug 18 12:54:22.851969 2026] [security2:error] [pid 67073:tid 67297] [client 52.173.121.69:17948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/qfvqu.php"] [unique_id "aoSALvcmepr5_nHgLbM2agAAAnA"] [Tue Aug 18 12:54:22.874516 2026] [security2:error] [pid 66623:tid 66877] [client 104.209.144.33:36494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/qfvqu.php"] [unique_id "aoSALtO5rbWdOArH04J_NgAAAXk"] [Tue Aug 18 12:54:22.901830 2026] [security2:error] [pid 66623:tid 66887] [client 47.128.26.38:19740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.affaripericiacontabil.com.br"] [uri "/robots.txt"] [unique_id "aoSALtO5rbWdOArH04J_NwAAAYM"] [Tue Aug 18 12:54:22.904464 2026] [security2:error] [pid 66623:tid 66693] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSALtO5rbWdOArH04J_OAABMDg"] [Tue Aug 18 12:54:22.908459 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:22.908743 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:22.917623 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSALvcmepr5_nHgLbM2cAAAAoE"] [Tue Aug 18 12:54:22.919682 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSALvcmepr5_nHgLbM2cQAAAmk"] [Tue Aug 18 12:54:22.925535 2026] [security2:error] [pid 66623:tid 66802] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSALtO5rbWdOArH04J_OgAAAS4"] [Tue Aug 18 12:54:22.944429 2026] [security2:error] [pid 66623:tid 66656] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSALtO5rbWdOArH04J_TwABYBM"] [Tue Aug 18 12:54:22.946173 2026] [security2:error] [pid 67073:tid 67236] [client 20.91.215.254:24376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-2019.php"] [unique_id "aoSALvcmepr5_nHgLbM2dAAAAjM"] [Tue Aug 18 12:54:22.962967 2026] [security2:error] [pid 67073:tid 67220] [client 68.155.154.236:64562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSALvcmepr5_nHgLbM2dwAAAiM"] [Tue Aug 18 12:54:22.982881 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:45205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2eAAAAi4"] [Tue Aug 18 12:54:22.986292 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.75.187:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gfile.php"] [unique_id "aoSALvcmepr5_nHgLbM2eQAAAog"] [Tue Aug 18 12:54:23.002758 2026] [security2:error] [pid 67073:tid 67232] [client 20.104.85.180:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAL_cmepr5_nHgLbM2egAAAi8"] [Tue Aug 18 12:54:23.022552 2026] [security2:error] [pid 66623:tid 66826] [client 20.104.100.201:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAL9O5rbWdOArH04J_eAAAAUY"] [Tue Aug 18 12:54:23.036393 2026] [security2:error] [pid 66623:tid 66637] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAL9O5rbWdOArH04J_eQABewA"] [Tue Aug 18 12:54:23.040126 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:20010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/meta.php"] [unique_id "aoSAL_cmepr5_nHgLbM2fgAAAms"] [Tue Aug 18 12:54:23.054897 2026] [security2:error] [pid 66623:tid 66676] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAL9O5rbWdOArH04J_ewABOic"] [Tue Aug 18 12:54:23.071702 2026] [security2:error] [pid 66623:tid 66667] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/rezor.php"] [unique_id "aoSAL9O5rbWdOArH04J_fQABIx4"] [Tue Aug 18 12:54:23.085620 2026] [security2:error] [pid 67073:tid 67235] [client 20.51.153.15:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sb.php"] [unique_id "aoSAL_cmepr5_nHgLbM2gAAAAjI"] [Tue Aug 18 12:54:23.086614 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAL_cmepr5_nHgLbM2gQAAAo4"] [Tue Aug 18 12:54:23.089755 2026] [security2:error] [pid 66623:tid 66733] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAL9O5rbWdOArH04J_fwABfmA"] [Tue Aug 18 12:54:23.149974 2026] [security2:error] [pid 66623:tid 66669] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAL9O5rbWdOArH04J_ggABTCA"] [Tue Aug 18 12:54:23.195449 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:62752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAL_cmepr5_nHgLbM2hgAAAhw"] [Tue Aug 18 12:54:23.203087 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_hwAAAXo"] [Tue Aug 18 12:54:23.213928 2026] [security2:error] [pid 67073:tid 67303] [client 157.51.166.53:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2igAAAnY"] [Tue Aug 18 12:54:23.214058 2026] [security2:error] [pid 67073:tid 67303] [client 157.51.166.53:53838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2igAAAnY"] [Tue Aug 18 12:54:23.222163 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:10372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ano.php"] [unique_id "aoSAL9O5rbWdOArH04J_iAAAASk"] [Tue Aug 18 12:54:23.231992 2026] [security2:error] [pid 66623:tid 66863] [client 160.120.140.123:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL9O5rbWdOArH04J_iQAAAWs"] [Tue Aug 18 12:54:23.232334 2026] [security2:error] [pid 66623:tid 66863] [client 160.120.140.123:55069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAL9O5rbWdOArH04J_iQAAAWs"] [Tue Aug 18 12:54:23.245688 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.118:21656] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:23.246116 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.118:21656] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:23.253467 2026] [security2:error] [pid 67073:tid 67293] [client 172.182.200.96:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jAAAAmw"] [Tue Aug 18 12:54:23.254584 2026] [security2:error] [pid 67073:tid 67225] [client 20.118.172.148:7648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jQAAAig"] [Tue Aug 18 12:54:23.298397 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.100.201:58941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-css.php"] [unique_id "aoSAL9O5rbWdOArH04J_iwAAAR8"] [Tue Aug 18 12:54:23.300290 2026] [security2:error] [pid 67073:tid 67315] [client 213.35.127.232:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAL_cmepr5_nHgLbM2jwAAAoI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:23.303144 2026] [security2:error] [pid 66623:tid 66678] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/index/function.php"] [unique_id "aoSAL9O5rbWdOArH04J_jAABWCk"] [Tue Aug 18 12:54:23.309817 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.85.180:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/about.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kQAAAk0"] [Tue Aug 18 12:54:23.312176 2026] [security2:error] [pid 67073:tid 67316] [client 52.173.121.69:16484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/oivcl.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kgAAAoM"] [Tue Aug 18 12:54:23.314064 2026] [security2:error] [pid 67073:tid 67229] [client 20.171.51.14:14989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ot.php"] [unique_id "aoSAL_cmepr5_nHgLbM2kwAAAiw"] [Tue Aug 18 12:54:23.346968 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/jn.php"] [unique_id "aoSAL_cmepr5_nHgLbM2lQAAAl4"] [Tue Aug 18 12:54:23.379347 2026] [security2:error] [pid 66623:tid 66827] [client 20.51.153.15:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xj.php"] [unique_id "aoSAL9O5rbWdOArH04J_jgAAAUc"] [Tue Aug 18 12:54:23.390102 2026] [security2:error] [pid 66623:tid 66697] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAL9O5rbWdOArH04J_jwABRDw"] [Tue Aug 18 12:54:23.393278 2026] [security2:error] [pid 67073:tid 67243] [client 158.158.74.177:20501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-aa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mAAAAjo"] [Tue Aug 18 12:54:23.394055 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:31897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/co.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mQAAAmU"] [Tue Aug 18 12:54:23.416427 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_kAAAAXw"] [Tue Aug 18 12:54:23.428341 2026] [security2:error] [pid 67073:tid 67273] [client 192.141.172.134:53931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mwAAAlg"] [Tue Aug 18 12:54:23.428462 2026] [security2:error] [pid 67073:tid 67273] [client 192.141.172.134:53931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2mwAAAlg"] [Tue Aug 18 12:54:23.446380 2026] [security2:error] [pid 67073:tid 67259] [client 78.46.190.63:28362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSALvcmepr5_nHgLbM2LgAAAko"], referer: https://www.connectformaturas.com.br [Tue Aug 18 12:54:23.470883 2026] [security2:error] [pid 66623:tid 66732] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/Cachex.php"] [unique_id "aoSAL9O5rbWdOArH04J_kQABKF8"] [Tue Aug 18 12:54:23.483208 2026] [security2:error] [pid 67073:tid 67246] [client 213.35.127.232:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ngAAAj0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:23.496424 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mans.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ogACLRw"] [Tue Aug 18 12:54:23.506511 2026] [security2:error] [pid 67073:tid 67319] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pAAAAoY"] [Tue Aug 18 12:54:23.511557 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:23.511818 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:23.518195 2026] [security2:error] [pid 66623:tid 66672] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAL9O5rbWdOArH04J_kgABYiM"] [Tue Aug 18 12:54:23.536489 2026] [security2:error] [pid 66623:tid 66730] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAL9O5rbWdOArH04J_kwABDF0"] [Tue Aug 18 12:54:23.537894 2026] [security2:error] [pid 67073:tid 67274] [client 4.232.151.198:6169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/moon.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pQAAAlk"] [Tue Aug 18 12:54:23.552099 2026] [security2:error] [pid 66623:tid 66699] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_lAABJj4"] [Tue Aug 18 12:54:23.562014 2026] [security2:error] [pid 66623:tid 66851] [client 132.196.61.152:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ano.php"] [unique_id "aoSAL9O5rbWdOArH04J_lQAAAV8"] [Tue Aug 18 12:54:23.570084 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.154.236:65195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAL_cmepr5_nHgLbM2pgAAAos"] [Tue Aug 18 12:54:23.573112 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.100.201:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/flox.php"] [unique_id "aoSAL9O5rbWdOArH04J_lgAAARs"] [Tue Aug 18 12:54:23.580028 2026] [security2:error] [pid 66623:tid 66713] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAL9O5rbWdOArH04J_lwABFEw"] [Tue Aug 18 12:54:23.589903 2026] [security2:error] [pid 66623:tid 66780] [client 52.238.210.254:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/av.php"] [unique_id "aoSAL9O5rbWdOArH04J_mAAAARg"] [Tue Aug 18 12:54:23.612798 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.136.165:37942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sdsa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qAAAAkc"] [Tue Aug 18 12:54:23.619047 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cc.php"] [unique_id "aoSAL9O5rbWdOArH04J_mQAAAXM"] [Tue Aug 18 12:54:23.622020 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.85.180:43526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/alfa.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qQAAAkY"] [Tue Aug 18 12:54:23.625304 2026] [security2:error] [pid 67073:tid 67250] [client 20.91.215.254:24380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/cjfuns.php"] [unique_id "aoSAL_cmepr5_nHgLbM2qgAAAkE"] [Tue Aug 18 12:54:23.644543 2026] [security2:error] [pid 66623:tid 66671] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_mgABPiI"] [Tue Aug 18 12:54:23.677095 2026] [security2:error] [pid 67073:tid 67091] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/co.php"] [unique_id "aoSAL_cmepr5_nHgLbM2uAACIg8"] [Tue Aug 18 12:54:23.679647 2026] [security2:error] [pid 67073:tid 67284] [client 172.182.200.96:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAL_cmepr5_nHgLbM2uQAAAmM"] [Tue Aug 18 12:54:23.683767 2026] [security2:error] [pid 66623:tid 66806] [client 74.248.18.37:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mini.php"] [unique_id "aoSAL9O5rbWdOArH04J_mwAAATI"] [Tue Aug 18 12:54:23.695065 2026] [security2:error] [pid 66623:tid 66754] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_nAABf3U"] [Tue Aug 18 12:54:23.739410 2026] [security2:error] [pid 66623:tid 66821] [client 20.51.153.15:9108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ns.php"] [unique_id "aoSAL9O5rbWdOArH04J_nwAAAUE"] [Tue Aug 18 12:54:23.756247 2026] [security2:error] [pid 67073:tid 67210] [client 85.154.68.202:60398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ugAAAhk"] [Tue Aug 18 12:54:23.756404 2026] [security2:error] [pid 67073:tid 67210] [client 85.154.68.202:60398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAL_cmepr5_nHgLbM2ugAAAhk"] [Tue Aug 18 12:54:23.758436 2026] [security2:error] [pid 67073:tid 67307] [client 20.65.98.162:18095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/mosty.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vAAAAno"] [Tue Aug 18 12:54:23.763306 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:13529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vQAAAlU"] [Tue Aug 18 12:54:23.764187 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.85.180:7936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vgAAAnQ"] [Tue Aug 18 12:54:23.781106 2026] [security2:error] [pid 67073:tid 67264] [client 104.209.144.33:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2vwAAAk8"] [Tue Aug 18 12:54:23.785932 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:3092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAL_cmepr5_nHgLbM2wAAAAjU"] [Tue Aug 18 12:54:23.808118 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAL9O5rbWdOArH04J_oAAAATQ"] [Tue Aug 18 12:54:23.813558 2026] [security2:error] [pid 66623:tid 66673] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_oQABSSQ"] [Tue Aug 18 12:54:23.818109 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:23.818567 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:23.839328 2026] [security2:error] [pid 67073:tid 67314] [client 20.171.51.14:58849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ih.php"] [unique_id "aoSAL_cmepr5_nHgLbM2wgAAAoE"] [Tue Aug 18 12:54:23.850049 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAL9O5rbWdOArH04J_ogAAAW0"] [Tue Aug 18 12:54:23.852512 2026] [security2:error] [pid 67073:tid 67295] [client 20.104.100.201:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/op.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xAAAAm4"] [Tue Aug 18 12:54:23.856047 2026] [security2:error] [pid 67073:tid 67108] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/btx25.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xQACdSA"] [Tue Aug 18 12:54:23.857372 2026] [security2:error] [pid 67073:tid 67326] [client 20.250.13.23:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp.php"] [unique_id "aoSAL_cmepr5_nHgLbM2xgAAAo0"] [Tue Aug 18 12:54:23.893798 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:43552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/lock360.php"] [unique_id "aoSAL9O5rbWdOArH04J_owAAATc"] [Tue Aug 18 12:54:23.926416 2026] [security2:error] [pid 66623:tid 66872] [client 68.155.154.236:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAL9O5rbWdOArH04J_pAAAAXQ"] [Tue Aug 18 12:54:23.941696 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zugvi.php"] [unique_id "aoSAL9O5rbWdOArH04J_pQAAASo"] [Tue Aug 18 12:54:23.960659 2026] [security2:error] [pid 67073:tid 67321] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/p.php"] [unique_id "aoSAL_cmepr5_nHgLbM2yAAAAog"] [Tue Aug 18 12:54:23.991423 2026] [security2:error] [pid 66623:tid 66892] [client 20.100.169.31:20240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/php.php"] [unique_id "aoSAL9O5rbWdOArH04J_pwAAAYg"] [Tue Aug 18 12:54:23.999548 2026] [security2:error] [pid 66623:tid 66684] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAL9O5rbWdOArH04J_qAABUC8"] [Tue Aug 18 12:54:24.015230 2026] [security2:error] [pid 66623:tid 66766] [client 158.158.74.177:15849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/d.php"] [unique_id "aoSAMNO5rbWdOArH04J_qQAAAQo"] [Tue Aug 18 12:54:24.030934 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAMPcmepr5_nHgLbM2ywAAAhs"] [Tue Aug 18 12:54:24.064260 2026] [security2:error] [pid 67073:tid 67122] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zAACji4"] [Tue Aug 18 12:54:24.064402 2026] [security2:error] [pid 67073:tid 67327] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zAACji4"] [Tue Aug 18 12:54:24.067039 2026] [security2:error] [pid 67073:tid 67178] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/avim.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zQACQmY"] [Tue Aug 18 12:54:24.078157 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAMPcmepr5_nHgLbM2zwAAAoo"] [Tue Aug 18 12:54:24.117234 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.61.152:56104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ai.php"] [unique_id "aoSAMPcmepr5_nHgLbM20wAAAl0"] [Tue Aug 18 12:54:24.130017 2026] [security2:error] [pid 66623:tid 66793] [client 20.104.100.201:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAMNO5rbWdOArH04J_rQAAASU"] [Tue Aug 18 12:54:24.144190 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSAMPcmepr5_nHgLbM21QAAAlY"] [Tue Aug 18 12:54:24.145795 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:8049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/f35.php"] [unique_id "aoSAMNO5rbWdOArH04J_rgAAAVw"] [Tue Aug 18 12:54:24.151960 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_rwAAAVo"] [Tue Aug 18 12:54:24.178036 2026] [security2:error] [pid 66623:tid 66725] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAMNO5rbWdOArH04J_sAABXlg"] [Tue Aug 18 12:54:24.188569 2026] [security2:error] [pid 67073:tid 67283] [client 4.232.151.198:6193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/n.php"] [unique_id "aoSAMPcmepr5_nHgLbM21wAAAmI"] [Tue Aug 18 12:54:24.215416 2026] [security2:error] [pid 66623:tid 66711] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_sQABSko"] [Tue Aug 18 12:54:24.234523 2026] [security2:error] [pid 66623:tid 66770] [client 20.171.51.14:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/k.php"] [unique_id "aoSAMNO5rbWdOArH04J_sgAAAQ4"] [Tue Aug 18 12:54:24.238580 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:18879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/flower.php"] [unique_id "aoSAMNO5rbWdOArH04J_swAAAWc"] [Tue Aug 18 12:54:24.246941 2026] [security2:error] [pid 67073:tid 67087] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/myfile.php"] [unique_id "aoSAMPcmepr5_nHgLbM22QACcgs"] [Tue Aug 18 12:54:24.260130 2026] [security2:error] [pid 67073:tid 67254] [client 20.91.215.254:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSAMPcmepr5_nHgLbM22gAAAkU"] [Tue Aug 18 12:54:24.264005 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.6.191:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMPcmepr5_nHgLbM22wAAAng"] [Tue Aug 18 12:54:24.294521 2026] [security2:error] [pid 66623:tid 66761] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_tQABPXw"] [Tue Aug 18 12:54:24.309863 2026] [security2:error] [pid 67073:tid 67293] [client 74.248.136.165:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/btx25.php"] [unique_id "aoSAMPcmepr5_nHgLbM23QAAAmw"] [Tue Aug 18 12:54:24.325078 2026] [security2:error] [pid 67073:tid 67232] [client 213.35.127.232:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAMPcmepr5_nHgLbM23wAAAi8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:24.348934 2026] [security2:error] [pid 67073:tid 67215] [client 52.139.47.57:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/hosty.php"] [unique_id "aoSAMPcmepr5_nHgLbM24AAAAh4"] [Tue Aug 18 12:54:24.389167 2026] [security2:error] [pid 67073:tid 67315] [client 20.151.109.219:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/bf.php"] [unique_id "aoSAMPcmepr5_nHgLbM24QAAAoI"] [Tue Aug 18 12:54:24.393419 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:29604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/mm.php"] [unique_id "aoSAMNO5rbWdOArH04J_tgAAARE"] [Tue Aug 18 12:54:24.411692 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/txets.php"] [unique_id "aoSAMPcmepr5_nHgLbM25gAAAiw"] [Tue Aug 18 12:54:24.417740 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:64464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMPcmepr5_nHgLbM25wAAAl4"] [Tue Aug 18 12:54:24.418002 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:24.418278 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:24.421067 2026] [security2:error] [pid 66623:tid 66841] [client 20.163.43.14:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_twAAAVU"] [Tue Aug 18 12:54:24.422059 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAMNO5rbWdOArH04J_uAAAATM"] [Tue Aug 18 12:54:24.449465 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fleen.php"] [unique_id "aoSAMPcmepr5_nHgLbM26AAAAjo"] [Tue Aug 18 12:54:24.454925 2026] [security2:error] [pid 67073:tid 67286] [client 20.48.236.86:11054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ai.php"] [unique_id "aoSAMPcmepr5_nHgLbM26QAAAmU"] [Tue Aug 18 12:54:24.455424 2026] [security2:error] [pid 67073:tid 67151] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xmy.php"] [unique_id "aoSAMPcmepr5_nHgLbM26gACiUs"] [Tue Aug 18 12:54:24.478347 2026] [autoindex:error] [pid 66623:tid 66887] [client 20.104.85.180:8006] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:24.498517 2026] [security2:error] [pid 67073:tid 67273] [client 20.51.153.15:9119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gk.php"] [unique_id "aoSAMPcmepr5_nHgLbM27QAAAlg"] [Tue Aug 18 12:54:24.503234 2026] [security2:error] [pid 67073:tid 67259] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAMPcmepr5_nHgLbM27gAAAko"] [Tue Aug 18 12:54:24.518186 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.85.180:43523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/13.php"] [unique_id "aoSAMPcmepr5_nHgLbM27wAAAkA"] [Tue Aug 18 12:54:24.542702 2026] [security2:error] [pid 66623:tid 66729] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_ugABLlw"] [Tue Aug 18 12:54:24.561483 2026] [security2:error] [pid 66623:tid 66755] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAMNO5rbWdOArH04J_uwABOXY"] [Tue Aug 18 12:54:24.577158 2026] [security2:error] [pid 66623:tid 66712] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAMNO5rbWdOArH04J_vAABaks"] [Tue Aug 18 12:54:24.587127 2026] [security2:error] [pid 67073:tid 67240] [client 20.100.169.31:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAMPcmepr5_nHgLbM2-gAAAjc"] [Tue Aug 18 12:54:24.607121 2026] [security2:error] [pid 66623:tid 66655] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAMNO5rbWdOArH04J_vQABJxI"] [Tue Aug 18 12:54:24.623648 2026] [security2:error] [pid 66623:tid 66731] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_vgABEF4"] [Tue Aug 18 12:54:24.649657 2026] [security2:error] [pid 67073:tid 67263] [client 158.158.74.177:20536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAMPcmepr5_nHgLbM3AwAAAk4"] [Tue Aug 18 12:54:24.680162 2026] [security2:error] [pid 66623:tid 66718] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_vwABIlE"] [Tue Aug 18 12:54:24.683727 2026] [security2:error] [pid 67073:tid 67304] [client 20.104.100.201:58445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAMPcmepr5_nHgLbM3CAAAAnc"] [Tue Aug 18 12:54:24.693317 2026] [security2:error] [pid 67073:tid 67191] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xda.php"] [unique_id "aoSAMPcmepr5_nHgLbM3CQACIHM"] [Tue Aug 18 12:54:24.719124 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:24.719573 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:24.763036 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:3151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/an.php"] [unique_id "aoSAMPcmepr5_nHgLbM3FwAAApA"] [Tue Aug 18 12:54:24.771040 2026] [security2:error] [pid 67073:tid 67298] [client 135.225.75.187:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/cu.php"] [unique_id "aoSAMPcmepr5_nHgLbM3GQAAAnE"] [Tue Aug 18 12:54:24.775152 2026] [security2:error] [pid 66623:tid 66879] [client 20.104.85.180:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/inputs.php"] [unique_id "aoSAMNO5rbWdOArH04J_wAAAAXs"] [Tue Aug 18 12:54:24.780536 2026] [security2:error] [pid 67073:tid 67297] [client 172.182.200.96:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HAAAAnA"] [Tue Aug 18 12:54:24.803886 2026] [security2:error] [pid 66623:tid 66753] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAMNO5rbWdOArH04J_wQABOnQ"] [Tue Aug 18 12:54:24.811444 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:43520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cc.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HgAAAkg"] [Tue Aug 18 12:54:24.815688 2026] [security2:error] [pid 67073:tid 67268] [client 4.232.151.198:48151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/nc4.php"] [unique_id "aoSAMPcmepr5_nHgLbM3HwAAAlM"] [Tue Aug 18 12:54:24.819472 2026] [security2:error] [pid 66623:tid 66759] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_wgABI3o"] [Tue Aug 18 12:54:24.821644 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IQAAAnQ"] [Tue Aug 18 12:54:24.831804 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IgAAAk8"] [Tue Aug 18 12:54:24.834978 2026] [security2:error] [pid 66623:tid 66762] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAMNO5rbWdOArH04J_wwABEn0"] [Tue Aug 18 12:54:24.837279 2026] [security2:error] [pid 66623:tid 66882] [client 104.209.144.33:29865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/oivcl.php"] [unique_id "aoSAMNO5rbWdOArH04J_xAAAAX4"] [Tue Aug 18 12:54:24.843903 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iu.php"] [unique_id "aoSAMPcmepr5_nHgLbM3IwAAAl8"] [Tue Aug 18 12:54:24.863199 2026] [security2:error] [pid 67073:tid 67314] [client 172.202.39.151:37162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JQAAAoE"] [Tue Aug 18 12:54:24.867826 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.136.165:16976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/e.php"] [unique_id "aoSAMNO5rbWdOArH04J_xQAAARU"] [Tue Aug 18 12:54:24.882082 2026] [security2:error] [pid 66623:tid 66750] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAMNO5rbWdOArH04J_xgABV3E"] [Tue Aug 18 12:54:24.913946 2026] [security2:error] [pid 67073:tid 67206] [client 20.91.215.254:24328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JgAAAhU"] [Tue Aug 18 12:54:24.919405 2026] [security2:error] [pid 67073:tid 67155] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zz.php"] [unique_id "aoSAMPcmepr5_nHgLbM3JwACdU8"] [Tue Aug 18 12:54:24.922485 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wsrer.php"] [unique_id "aoSAMPcmepr5_nHgLbM3KAAAAo0"] [Tue Aug 18 12:54:24.959952 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.100.201:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAMNO5rbWdOArH04J_xwAAAUw"] [Tue Aug 18 12:54:24.971898 2026] [security2:error] [pid 66623:tid 66748] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAMNO5rbWdOArH04J_yAABh28"] [Tue Aug 18 12:54:24.983291 2026] [security2:error] [pid 67073:tid 67227] [client 52.139.47.57:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/t.php"] [unique_id "aoSAMPcmepr5_nHgLbM3KwAAAio"] [Tue Aug 18 12:54:25.001046 2026] [security2:error] [pid 67073:tid 67312] [client 20.51.153.15:9139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wn.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LAAAAn8"] [Tue Aug 18 12:54:25.004127 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.18.37:29232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/h.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LQAAAjA"] [Tue Aug 18 12:54:25.015004 2026] [security2:error] [pid 67073:tid 67266] [client 20.65.98.162:18939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/blurbs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3LgAAAlE"] [Tue Aug 18 12:54:25.027200 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSAMdO5rbWdOArH04J_yQAAAWg"] [Tue Aug 18 12:54:25.043403 2026] [security2:error] [pid 66623:tid 66639] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_ygABGQI"] [Tue Aug 18 12:54:25.050831 2026] [security2:error] [pid 66623:tid 66878] [client 40.85.222.29:2400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_ywAAAXo"] [Tue Aug 18 12:54:25.058746 2026] [security2:error] [pid 66623:tid 66640] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_zAABZAM"] [Tue Aug 18 12:54:25.085402 2026] [security2:error] [pid 66623:tid 66819] [client 132.196.61.152:56097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/w1px.php"] [unique_id "aoSAMdO5rbWdOArH04J_zQAAAT8"] [Tue Aug 18 12:54:25.097604 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.85.180:43565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMfcmepr5_nHgLbM3NQAAAkI"] [Tue Aug 18 12:54:25.107580 2026] [security2:error] [pid 67073:tid 67160] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xa.php"] [unique_id "aoSAMfcmepr5_nHgLbM3NwACilQ"] [Tue Aug 18 12:54:25.141067 2026] [autoindex:error] [pid 67073:tid 67327] [client 20.104.85.180:8063] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:25.148820 2026] [security2:error] [pid 66623:tid 66726] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAMdO5rbWdOArH04J_zwABUVk"] [Tue Aug 18 12:54:25.164746 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAMdO5rbWdOArH04J_0AAAAUU"] [Tue Aug 18 12:54:25.216444 2026] [security2:error] [pid 67073:tid 67271] [client 172.182.200.96:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAMfcmepr5_nHgLbM3OwAAAlY"] [Tue Aug 18 12:54:25.237913 2026] [security2:error] [pid 67073:tid 67214] [client 20.104.100.201:58898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PAAAAh0"] [Tue Aug 18 12:54:25.241474 2026] [security2:error] [pid 66623:tid 66752] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_0gABO3M"] [Tue Aug 18 12:54:25.247117 2026] [security2:error] [pid 66623:tid 66845] [client 74.248.133.44:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAMdO5rbWdOArH04J_0wAAAVk"] [Tue Aug 18 12:54:25.256888 2026] [security2:error] [pid 66623:tid 66738] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMdO5rbWdOArH04J_1AABVGU"] [Tue Aug 18 12:54:25.269714 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.74.177:17201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAMdO5rbWdOArH04J_1QAAASk"] [Tue Aug 18 12:54:25.273780 2026] [security2:error] [pid 66623:tid 66665] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAMdO5rbWdOArH04J_1gABYhw"] [Tue Aug 18 12:54:25.277295 2026] [security2:error] [pid 67073:tid 67305] [client 20.163.43.14:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/404.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PgAAAng"] [Tue Aug 18 12:54:25.285592 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:37893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/hello.php"] [unique_id "aoSAMfcmepr5_nHgLbM3PwAAAjQ"] [Tue Aug 18 12:54:25.294246 2026] [security2:error] [pid 67073:tid 67184] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/f6.php"] [unique_id "aoSAMfcmepr5_nHgLbM3QAACTGw"] [Tue Aug 18 12:54:25.305046 2026] [security2:error] [pid 66623:tid 66838] [client 103.120.71.157:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_2QAAAVI"] [Tue Aug 18 12:54:25.305138 2026] [security2:error] [pid 66623:tid 66838] [client 103.120.71.157:61410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_2QAAAVI"] [Tue Aug 18 12:54:25.313442 2026] [security2:error] [pid 66623:tid 66851] [client 20.51.153.15:8813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/app.php"] [unique_id "aoSAMdO5rbWdOArH04J_2wAAAV8"] [Tue Aug 18 12:54:25.321943 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:25.322194 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:25.339975 2026] [security2:error] [pid 66623:tid 66884] [client 213.35.127.232:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_3AAAAYA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:25.363462 2026] [security2:error] [pid 67073:tid 67232] [client 20.48.236.86:10794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/w1px.php"] [unique_id "aoSAMfcmepr5_nHgLbM3QwAAAi8"] [Tue Aug 18 12:54:25.376535 2026] [security2:error] [pid 66623:tid 66780] [client 20.104.85.180:43522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAMdO5rbWdOArH04J_3QAAARg"] [Tue Aug 18 12:54:25.389020 2026] [security2:error] [pid 66623:tid 66741] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_3gABc2g"] [Tue Aug 18 12:54:25.416765 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.85.180:8063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/alfa.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RAAAAk0"] [Tue Aug 18 12:54:25.457834 2026] [security2:error] [pid 67073:tid 67243] [client 20.251.48.93:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RQAAAjo"] [Tue Aug 18 12:54:25.462522 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.136.165:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/avim.php"] [unique_id "aoSAMdO5rbWdOArH04J_3wAAAS8"] [Tue Aug 18 12:54:25.464816 2026] [security2:error] [pid 67073:tid 67286] [client 20.171.51.14:45439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pk.php"] [unique_id "aoSAMfcmepr5_nHgLbM3RgAAAmU"] [Tue Aug 18 12:54:25.483873 2026] [security2:error] [pid 67073:tid 67317] [client 52.238.210.254:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/flower.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SAAAAoQ"] [Tue Aug 18 12:54:25.493414 2026] [security2:error] [pid 67073:tid 67242] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SQAAAjk"] [Tue Aug 18 12:54:25.497602 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mcs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3SgACShA"] [Tue Aug 18 12:54:25.515147 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.154.236:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_4AAAAYY"] [Tue Aug 18 12:54:25.515398 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSAMfcmepr5_nHgLbM3TQAAAkA"] [Tue Aug 18 12:54:25.521303 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:48184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/new.php"] [unique_id "aoSAMdO5rbWdOArH04J_4QAAARs"] [Tue Aug 18 12:54:25.557818 2026] [security2:error] [pid 66623:tid 66800] [client 20.91.215.254:24371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/import.php"] [unique_id "aoSAMdO5rbWdOArH04J_4gAAASw"] [Tue Aug 18 12:54:25.563817 2026] [security2:error] [pid 66623:tid 66679] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_5AABSSo"] [Tue Aug 18 12:54:25.571002 2026] [security2:error] [pid 67073:tid 67241] [client 172.182.200.96:14216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAMfcmepr5_nHgLbM3TwAAAjg"] [Tue Aug 18 12:54:25.576167 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:56125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/zi-936.php"] [unique_id "aoSAMfcmepr5_nHgLbM3UAAAAoM"] [Tue Aug 18 12:54:25.588559 2026] [security2:error] [pid 67073:tid 67240] [client 20.51.153.15:9191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/87.php"] [unique_id "aoSAMfcmepr5_nHgLbM3UQAAAjc"] [Tue Aug 18 12:54:25.661517 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.18.37:12993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/moon.php"] [unique_id "aoSAMfcmepr5_nHgLbM3VwAAAiQ"] [Tue Aug 18 12:54:25.664490 2026] [security2:error] [pid 67073:tid 67300] [client 20.104.85.180:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/01.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WAAAAnM"] [Tue Aug 18 12:54:25.677982 2026] [security2:error] [pid 67073:tid 67263] [client 135.225.75.187:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/X57.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WQAAAk4"] [Tue Aug 18 12:54:25.688959 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/xleet.php"] [unique_id "aoSAMfcmepr5_nHgLbM3WwACkSQ"] [Tue Aug 18 12:54:25.700276 2026] [security2:error] [pid 67073:tid 67256] [client 78.138.24.128:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.24.138.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XAAAAkc"] [Tue Aug 18 12:54:25.700408 2026] [security2:error] [pid 67073:tid 67256] [client 78.138.24.128:50593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zanseg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XAAAAkc"] [Tue Aug 18 12:54:25.704716 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.136.165:29413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/brc.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XQAAAkY"] [Tue Aug 18 12:54:25.743663 2026] [security2:error] [pid 67073:tid 67304] [client 20.104.85.180:8046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/lock360.php"] [unique_id "aoSAMfcmepr5_nHgLbM3XgAAAnc"] [Tue Aug 18 12:54:25.743931 2026] [security2:error] [pid 66623:tid 66836] [client 52.139.47.57:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_5wAAAVA"] [Tue Aug 18 12:54:25.776947 2026] [security2:error] [pid 66623:tid 66865] [client 20.163.43.14:3189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-login.php"] [unique_id "aoSAMdO5rbWdOArH04J_5QAAAW0"] [Tue Aug 18 12:54:25.792247 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.100.201:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAMdO5rbWdOArH04J_6AAAAVM"] [Tue Aug 18 12:54:25.800674 2026] [security2:error] [pid 66623:tid 66834] [client 172.202.39.151:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAMdO5rbWdOArH04J_6QAAAU4"] [Tue Aug 18 12:54:25.830817 2026] [security2:error] [pid 67073:tid 67213] [client 20.51.153.15:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/zi.php"] [unique_id "aoSAMfcmepr5_nHgLbM3YAAAAhw"] [Tue Aug 18 12:54:25.840715 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_6gAAAVw"] [Tue Aug 18 12:54:25.876357 2026] [security2:error] [pid 66623:tid 66743] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/first.php"] [unique_id "aoSAMdO5rbWdOArH04J_6wABbGo"] [Tue Aug 18 12:54:25.899612 2026] [security2:error] [pid 66623:tid 66764] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_7AABWn8"] [Tue Aug 18 12:54:25.912029 2026] [security2:error] [pid 66623:tid 66886] [client 158.158.74.177:20523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7QAAAYI"] [Tue Aug 18 12:54:25.915799 2026] [security2:error] [pid 67073:tid 67084] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAMfcmepr5_nHgLbM3YgACGgg"] [Tue Aug 18 12:54:25.918518 2026] [security2:error] [pid 66623:tid 66700] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_7gABSj8"] [Tue Aug 18 12:54:25.921313 2026] [security2:error] [pid 66623:tid 66824] [client 37.40.227.74:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7wAAAUQ"] [Tue Aug 18 12:54:25.924017 2026] [security2:error] [pid 66623:tid 66824] [client 37.40.227.74:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAMdO5rbWdOArH04J_7wAAAUQ"] [Tue Aug 18 12:54:25.924529 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:25.924780 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:25.965023 2026] [security2:error] [pid 67073:tid 67280] [client 172.182.200.96:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAMfcmepr5_nHgLbM3ZgAAAl8"] [Tue Aug 18 12:54:25.967868 2026] [security2:error] [pid 66623:tid 66742] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAMdO5rbWdOArH04J_8AABXWk"] [Tue Aug 18 12:54:25.983282 2026] [security2:error] [pid 66623:tid 66644] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAMdO5rbWdOArH04J_8QABPQc"] [Tue Aug 18 12:54:26.005037 2026] [security2:error] [pid 66623:tid 66866] [client 20.171.51.14:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ge.php"] [unique_id "aoSAMtO5rbWdOArH04J_8gAAAW4"] [Tue Aug 18 12:54:26.019160 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ZwAAAm4"] [Tue Aug 18 12:54:26.022930 2026] [security2:error] [pid 66623:tid 66683] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_8wABWy4"] [Tue Aug 18 12:54:26.034813 2026] [security2:error] [pid 67073:tid 67302] [client 20.104.85.180:7945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/flower.php"] [unique_id "aoSAMvcmepr5_nHgLbM3agAAAnU"] [Tue Aug 18 12:54:26.043099 2026] [security2:error] [pid 66623:tid 66763] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_9AABE34"] [Tue Aug 18 12:54:26.058468 2026] [security2:error] [pid 66623:tid 66757] [remote 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plannerempreendedor.com.br"] [uri "/images/security.php"] [unique_id "aoSAMtO5rbWdOArH04J_9QABEXg"] [Tue Aug 18 12:54:26.071562 2026] [security2:error] [pid 66623:tid 66858] [client 20.104.100.201:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/term.php"] [unique_id "aoSAMtO5rbWdOArH04J_9gAAAWY"] [Tue Aug 18 12:54:26.087565 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:18845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/lv.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bQAAAiM"] [Tue Aug 18 12:54:26.094854 2026] [security2:error] [pid 67073:tid 67318] [client 132.196.61.152:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bgAAAoU"] [Tue Aug 18 12:54:26.117965 2026] [security2:error] [pid 67073:tid 67218] [client 20.163.43.14:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAMvcmepr5_nHgLbM3bwAAAiE"] [Tue Aug 18 12:54:26.123737 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.136.165:29405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/file52.php"] [unique_id "aoSAMvcmepr5_nHgLbM3cQAAAio"] [Tue Aug 18 12:54:26.134301 2026] [security2:error] [pid 67073:tid 67183] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/gool.php"] [unique_id "aoSAMvcmepr5_nHgLbM3cwACS2s"] [Tue Aug 18 12:54:26.143966 2026] [security2:error] [pid 67073:tid 67292] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAMvcmepr5_nHgLbM3dAAAAms"] [Tue Aug 18 12:54:26.143986 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/92.php"] [unique_id "aoSAMvcmepr5_nHgLbM3dQAAAmE"] [Tue Aug 18 12:54:26.146495 2026] [security2:error] [pid 66623:tid 66859] [client 4.232.151.198:48155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/packed.php"] [unique_id "aoSAMtO5rbWdOArH04J_9wAAAWc"] [Tue Aug 18 12:54:26.207523 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:38039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/w.php"] [unique_id "aoSAMvcmepr5_nHgLbM3eAAAApM"] [Tue Aug 18 12:54:26.222179 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:26.222443 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:26.230426 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAMvcmepr5_nHgLbM3egAAAoo"] [Tue Aug 18 12:54:26.236973 2026] [security2:error] [pid 67073:tid 67314] [client 20.91.215.254:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/cropper.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ewAAAoE"] [Tue Aug 18 12:54:26.241279 2026] [security2:error] [pid 67073:tid 67267] [client 20.251.48.93:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fAAAAlI"] [Tue Aug 18 12:54:26.277388 2026] [security2:error] [pid 67073:tid 67294] [client 20.48.236.86:10775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/zi-936.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fgAAAm0"] [Tue Aug 18 12:54:26.294304 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.18.37:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/n.php"] [unique_id "aoSAMvcmepr5_nHgLbM3fwAAAkQ"] [Tue Aug 18 12:54:26.315417 2026] [security2:error] [pid 67073:tid 67283] [client 172.182.200.96:14215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAMvcmepr5_nHgLbM3gQAAAmI"] [Tue Aug 18 12:54:26.321914 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:16551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bajah.php"] [unique_id "aoSAMtO5rbWdOArH04J_-AAAATk"] [Tue Aug 18 12:54:26.329359 2026] [security2:error] [pid 67073:tid 67134] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/maxro.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ggACdjo"] [Tue Aug 18 12:54:26.339580 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:7991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/13.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hAAAAkU"] [Tue Aug 18 12:54:26.350568 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.100.201:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/black.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hQAAAjQ"] [Tue Aug 18 12:54:26.360385 2026] [security2:error] [pid 67073:tid 67290] [client 213.35.127.232:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAMvcmepr5_nHgLbM3hgAAAmk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:26.362484 2026] [security2:error] [pid 66623:tid 66852] [client 20.104.85.180:43533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/new.php"] [unique_id "aoSAMtO5rbWdOArH04J_-QAAAWA"] [Tue Aug 18 12:54:26.425808 2026] [security2:error] [pid 67073:tid 67265] [client 40.85.222.29:45238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/first.php"] [unique_id "aoSAMvcmepr5_nHgLbM3igAAAlA"] [Tue Aug 18 12:54:26.436544 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAMvcmepr5_nHgLbM3iwAAAj8"] [Tue Aug 18 12:54:26.457420 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAMtO5rbWdOArH04J_-gAAAR0"] [Tue Aug 18 12:54:26.458930 2026] [security2:error] [pid 67073:tid 67278] [client 52.139.47.57:3279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/xx.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jAAAAl0"] [Tue Aug 18 12:54:26.482546 2026] [security2:error] [pid 67073:tid 67317] [client 20.51.153.15:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/jm.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jgAAAoQ"] [Tue Aug 18 12:54:26.506541 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wdf.php"] [unique_id "aoSAMvcmepr5_nHgLbM3jwACSj4"] [Tue Aug 18 12:54:26.522503 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:26.522780 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:26.541509 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.136.165:23460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSAMvcmepr5_nHgLbM3kwAAAn4"] [Tue Aug 18 12:54:26.541638 2026] [security2:error] [pid 67073:tid 67310] [client 158.158.74.177:17187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lAAAAn0"] [Tue Aug 18 12:54:26.550924 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/system_log.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lQAAAoM"] [Tue Aug 18 12:54:26.554214 2026] [security2:error] [pid 67073:tid 67236] [client 149.34.210.157:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lgAAAjM"] [Tue Aug 18 12:54:26.559811 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ag.php"] [unique_id "aoSAMtO5rbWdOArH04J__AAAARA"] [Tue Aug 18 12:54:26.586750 2026] [security2:error] [pid 67073:tid 67244] [client 74.248.133.44:45737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/.__info.php"] [unique_id "aoSAMvcmepr5_nHgLbM3mAAAAjs"] [Tue Aug 18 12:54:26.625756 2026] [security2:error] [pid 66623:tid 66791] [client 20.104.85.180:7947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cc.php"] [unique_id "aoSAMtO5rbWdOArH04J__gAAASM"] [Tue Aug 18 12:54:26.626287 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.100.201:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/as.php"] [unique_id "aoSAMtO5rbWdOArH04J__wAAAYU"] [Tue Aug 18 12:54:26.669868 2026] [security2:error] [pid 67073:tid 67330] [client 172.182.200.96:14234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAMvcmepr5_nHgLbM3nQAAApE"] [Tue Aug 18 12:54:26.682370 2026] [security2:error] [pid 67073:tid 67256] [client 132.196.61.152:27265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/php.php"] [unique_id "aoSAMvcmepr5_nHgLbM3ngAAAkc"] [Tue Aug 18 12:54:26.693443 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.154.236:65106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAMvcmepr5_nHgLbM3nwAAAkY"] [Tue Aug 18 12:54:26.702966 2026] [security2:error] [pid 67073:tid 67313] [client 20.104.85.180:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/222.php"] [unique_id "aoSAMvcmepr5_nHgLbM3oQAAAoA"] [Tue Aug 18 12:54:26.762691 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.6.191:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/01.php"] [unique_id "aoSAMtO5rbWdOArH04KAAQAAAYc"] [Tue Aug 18 12:54:26.768128 2026] [security2:error] [pid 66623:tid 66810] [client 196.12.128.158:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMtO5rbWdOArH04KAAgAAATY"] [Tue Aug 18 12:54:26.768230 2026] [security2:error] [pid 66623:tid 66810] [client 196.12.128.158:57523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMtO5rbWdOArH04KAAgAAATY"] [Tue Aug 18 12:54:26.795324 2026] [security2:error] [pid 66623:tid 66857] [client 20.51.153.15:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wj.php"] [unique_id "aoSAMtO5rbWdOArH04KABAAAAWU"] [Tue Aug 18 12:54:26.798579 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAMtO5rbWdOArH04KABQAAAXI"] [Tue Aug 18 12:54:26.802903 2026] [security2:error] [pid 67073:tid 67207] [client 20.171.51.14:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kl.php"] [unique_id "aoSAMvcmepr5_nHgLbM3pQAAAhY"] [Tue Aug 18 12:54:26.803080 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.163.43.14:3142] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:26.827854 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:26.828263 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:26.832310 2026] [security2:error] [pid 67073:tid 67236] [client 149.34.210.157:51830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAMvcmepr5_nHgLbM3lgAAAjM"] [Tue Aug 18 12:54:26.865390 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.136.165:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/myfile.php"] [unique_id "aoSAMvcmepr5_nHgLbM3pwAAAho"] [Tue Aug 18 12:54:26.875459 2026] [security2:error] [pid 66623:tid 66843] [client 20.91.215.254:24344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSAMtO5rbWdOArH04KABwAAAVc"] [Tue Aug 18 12:54:26.898623 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:10165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/motu.php"] [unique_id "aoSAMvcmepr5_nHgLbM3qgAAAlc"] [Tue Aug 18 12:54:26.906122 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.100.201:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/pucci.php"] [unique_id "aoSAMtO5rbWdOArH04KACAAAAR8"] [Tue Aug 18 12:54:26.924631 2026] [security2:error] [pid 66623:tid 66832] [client 52.139.47.57:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/zwso.php"] [unique_id "aoSAMtO5rbWdOArH04KACQAAAUw"] [Tue Aug 18 12:54:26.949242 2026] [security2:error] [pid 66623:tid 66767] [client 52.173.121.69:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/yxijx.php"] [unique_id "aoSAMtO5rbWdOArH04KACgAAAQs"] [Tue Aug 18 12:54:26.960029 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.136.165:39576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/path.php"] [unique_id "aoSAMvcmepr5_nHgLbM3rAAAAh8"] [Tue Aug 18 12:54:26.965904 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wso.php"] [unique_id "aoSAMvcmepr5_nHgLbM3rQAAAm4"] [Tue Aug 18 12:54:26.982979 2026] [security2:error] [pid 67073:tid 67263] [client 114.119.159.62:40687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bioarquitetar.com"] [uri "/portfolio/casacor-minas-gerais/"] [unique_id "aoSAMvcmepr5_nHgLbM3rwAAAk4"], referer: https://mobillegends.net/24a-casacor-minas-gerais-apresenta-o-tema-a-casa-viva-blog-do [Tue Aug 18 12:54:26.988684 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:6174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/plugin.php"] [unique_id "aoSAMtO5rbWdOArH04KACwAAAYQ"] [Tue Aug 18 12:54:26.988894 2026] [security2:error] [pid 66623:tid 66881] [client 20.104.85.180:8005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAMtO5rbWdOArH04KADAAAAX0"] [Tue Aug 18 12:54:26.992452 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/chosen.php"] [unique_id "aoSAMvcmepr5_nHgLbM3sAAAAhU"] [Tue Aug 18 12:54:27.018404 2026] [security2:error] [pid 67073:tid 67318] [client 135.225.75.187:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/forbidals.php"] [unique_id "aoSAM_cmepr5_nHgLbM3sQAAAoU"] [Tue Aug 18 12:54:27.025215 2026] [security2:error] [pid 67073:tid 67252] [client 74.248.18.37:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/nc4.php"] [unique_id "aoSAM_cmepr5_nHgLbM3sgAAAkM"] [Tue Aug 18 12:54:27.027538 2026] [security2:error] [pid 67073:tid 67175] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ff1.php"] [unique_id "aoSAM_cmepr5_nHgLbM3swACIWM"] [Tue Aug 18 12:54:27.034715 2026] [security2:error] [pid 67073:tid 67329] [client 213.202.253.4:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSAM_cmepr5_nHgLbM3tAAAApA"], referer: www.google.com [Tue Aug 18 12:54:27.057376 2026] [security2:error] [pid 66623:tid 66796] [client 172.182.200.96:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAM9O5rbWdOArH04KADQAAASg"] [Tue Aug 18 12:54:27.071408 2026] [security2:error] [pid 66623:tid 66873] [client 20.51.153.15:9145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/av.php"] [unique_id "aoSAM9O5rbWdOArH04KADgAAAXU"] [Tue Aug 18 12:54:27.124925 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:27.125223 2026] [authz_core:error] [pid 67073:tid 67123] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:27.147525 2026] [security2:error] [pid 67073:tid 67322] [client 20.250.13.23:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/155.php"] [unique_id "aoSAM_cmepr5_nHgLbM3uQAAAok"] [Tue Aug 18 12:54:27.153692 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAM9O5rbWdOArH04KADwAAAUc"] [Tue Aug 18 12:54:27.164607 2026] [security2:error] [pid 66623:tid 66825] [client 158.158.74.177:15828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAM9O5rbWdOArH04KAEAAAAUU"] [Tue Aug 18 12:54:27.187098 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.100.201:58897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wicked.php"] [unique_id "aoSAM_cmepr5_nHgLbM3uwAAApM"] [Tue Aug 18 12:54:27.205891 2026] [security2:error] [pid 67073:tid 67136] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/guk.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vAACajw"] [Tue Aug 18 12:54:27.231321 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/HLA-dd.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vQAAAlI"] [Tue Aug 18 12:54:27.266465 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:8024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAM_cmepr5_nHgLbM3vwAAAm0"] [Tue Aug 18 12:54:27.271083 2026] [security2:error] [pid 67073:tid 67208] [client 132.196.61.152:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/sf.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wAAAAhc"] [Tue Aug 18 12:54:27.277179 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.85.180:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/info.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wQAAAo4"] [Tue Aug 18 12:54:27.321657 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/sf.php"] [unique_id "aoSAM9O5rbWdOArH04KAEQAAARg"] [Tue Aug 18 12:54:27.336788 2026] [security2:error] [pid 66623:tid 66871] [client 20.171.51.14:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gs.php"] [unique_id "aoSAM9O5rbWdOArH04KAEgAAAXM"] [Tue Aug 18 12:54:27.367112 2026] [security2:error] [pid 67073:tid 67299] [client 52.173.121.69:24964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAM_cmepr5_nHgLbM3wwAAAnI"] [Tue Aug 18 12:54:27.377987 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.136.165:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wpo.php"] [unique_id "aoSAM_cmepr5_nHgLbM3xAAAAkE"] [Tue Aug 18 12:54:27.392645 2026] [security2:error] [pid 66623:tid 66845] [client 213.35.127.232:63708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAM9O5rbWdOArH04KAEwAAAVk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:27.407754 2026] [security2:error] [pid 67073:tid 67225] [client 172.182.200.96:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAM_cmepr5_nHgLbM3xgAAAig"] [Tue Aug 18 12:54:27.416610 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:6605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/lv.php"] [unique_id "aoSAM9O5rbWdOArH04KAFAAAATI"] [Tue Aug 18 12:54:27.425591 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:27.425856 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:27.428180 2026] [security2:error] [pid 67073:tid 67179] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-the.php"] [unique_id "aoSAM_cmepr5_nHgLbM3yAACaWc"] [Tue Aug 18 12:54:27.440445 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:24836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAM9O5rbWdOArH04KAFQAAAXc"] [Tue Aug 18 12:54:27.463142 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/water.php"] [unique_id "aoSAM_cmepr5_nHgLbM3yQAAAmM"] [Tue Aug 18 12:54:27.494230 2026] [security2:error] [pid 67073:tid 67232] [client 20.51.153.15:9162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ag.php"] [unique_id "aoSAM_cmepr5_nHgLbM3ywAAAi8"] [Tue Aug 18 12:54:27.502524 2026] [security2:error] [pid 67073:tid 67215] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zAAAAh4"] [Tue Aug 18 12:54:27.514968 2026] [security2:error] [pid 67073:tid 67253] [client 5.253.205.188:40682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullwebsite.bak"] [unique_id "aoSAM_cmepr5_nHgLbM3zQAAAkQ"], referer: https://medihub.com.br/fullwebsite.bak [Tue Aug 18 12:54:27.522968 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zgAAAnw"] [Tue Aug 18 12:54:27.527699 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:28276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ig.php"] [unique_id "aoSAM_cmepr5_nHgLbM3zwAAAoI"] [Tue Aug 18 12:54:27.544831 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.30.78:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nsimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAM9O5rbWdOArH04KAFgAAAUE"] [Tue Aug 18 12:54:27.545189 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/01.php"] [unique_id "aoSAM9O5rbWdOArH04KAFwAAAU8"] [Tue Aug 18 12:54:27.558014 2026] [security2:error] [pid 67073:tid 67278] [client 52.139.47.57:48951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/x.php"] [unique_id "aoSAM_cmepr5_nHgLbM30AAAAl0"] [Tue Aug 18 12:54:27.618964 2026] [security2:error] [pid 67073:tid 67124] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sbhu.php"] [unique_id "aoSAM_cmepr5_nHgLbM30wAChDA"] [Tue Aug 18 12:54:27.640936 2026] [security2:error] [pid 67073:tid 67273] [client 20.48.236.86:10756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/dcsgumnm.php"] [unique_id "aoSAM_cmepr5_nHgLbM31AAAAlg"] [Tue Aug 18 12:54:27.682817 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/index/function.php"] [unique_id "aoSAM_cmepr5_nHgLbM31gAAAkA"] [Tue Aug 18 12:54:27.716692 2026] [security2:error] [pid 66623:tid 66808] [client 132.196.61.152:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/xx.php"] [unique_id "aoSAM9O5rbWdOArH04KAGQAAATQ"] [Tue Aug 18 12:54:27.716692 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.18.37:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/new.php"] [unique_id "aoSAM_cmepr5_nHgLbM31wAAAlA"] [Tue Aug 18 12:54:27.717892 2026] [security2:error] [pid 66623:tid 66708] [remote 103.56.163.133:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAM9O5rbWdOArH04KAGgABK0c"] [Tue Aug 18 12:54:27.740707 2026] [security2:error] [pid 67073:tid 67240] [client 20.104.100.201:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fine.php"] [unique_id "aoSAM_cmepr5_nHgLbM32AAAAjc"] [Tue Aug 18 12:54:27.752437 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.154.236:65102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/first.php"] [unique_id "aoSAM9O5rbWdOArH04KAGwAAAT4"] [Tue Aug 18 12:54:27.758401 2026] [security2:error] [pid 66623:tid 66880] [client 172.182.200.96:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAM9O5rbWdOArH04KAHAAAAXw"] [Tue Aug 18 12:54:27.797462 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.136.165:16999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/a1vx.php"] [unique_id "aoSAM9O5rbWdOArH04KAHQAAATc"] [Tue Aug 18 12:54:27.801880 2026] [security2:error] [pid 66623:tid 66805] [client 20.251.48.93:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/media.php"] [unique_id "aoSAM9O5rbWdOArH04KAHgAAATE"] [Tue Aug 18 12:54:27.808152 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.74.177:15832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/abc.php"] [unique_id "aoSAM_cmepr5_nHgLbM32wAAAik"] [Tue Aug 18 12:54:27.823926 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33AAAAjA"] [Tue Aug 18 12:54:27.824047 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33AAAAjA"] [Tue Aug 18 12:54:27.826561 2026] [security2:error] [pid 67073:tid 67209] [client 4.232.151.198:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/public/moon.php"] [unique_id "aoSAM_cmepr5_nHgLbM33QAAAhg"] [Tue Aug 18 12:54:27.829486 2026] [security2:error] [pid 67073:tid 67319] [client 114.5.214.109:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33gAAAoY"] [Tue Aug 18 12:54:27.832396 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAM9O5rbWdOArH04KAIAAAASo"] [Tue Aug 18 12:54:27.838541 2026] [security2:error] [pid 67073:tid 67319] [client 114.5.214.109:49797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAM_cmepr5_nHgLbM33gAAAoY"] [Tue Aug 18 12:54:27.867251 2026] [security2:error] [pid 66623:tid 66836] [client 4.223.164.152:46161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAM9O5rbWdOArH04KAIQAAAVA"] [Tue Aug 18 12:54:27.867693 2026] [security2:error] [pid 66623:tid 66766] [client 20.104.85.180:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/lv.php"] [unique_id "aoSAM9O5rbWdOArH04KAIgAAAQo"] [Tue Aug 18 12:54:27.887556 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/jrpga.php"] [unique_id "aoSAM9O5rbWdOArH04KAIwAAAW8"] [Tue Aug 18 12:54:27.960063 2026] [security2:error] [pid 66623:tid 66865] [client 20.226.6.191:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/new.php"] [unique_id "aoSAM9O5rbWdOArH04KAJAAAAW0"] [Tue Aug 18 12:54:27.995003 2026] [security2:error] [pid 66623:tid 66820] [client 52.139.47.57:3273] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.plenitude.com.br"] [uri "/1.php"] [unique_id "aoSAM9O5rbWdOArH04KAJgAAAUA"] [Tue Aug 18 12:54:27.995104 2026] [security2:error] [pid 66623:tid 66820] [client 52.139.47.57:3273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/1.php"] [unique_id "aoSAM9O5rbWdOArH04KAJgAAAUA"] [Tue Aug 18 12:54:28.025608 2026] [security2:error] [pid 66623:tid 66831] [client 20.163.43.14:3109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/edit.php"] [unique_id "aoSANNO5rbWdOArH04KAJwAAAUs"] [Tue Aug 18 12:54:28.027043 2026] [security2:error] [pid 66623:tid 66770] [client 20.104.100.201:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/loader.php"] [unique_id "aoSANNO5rbWdOArH04KAKAAAAQ4"] [Tue Aug 18 12:54:28.029732 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:28.029999 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:28.040273 2026] [security2:error] [pid 67073:tid 67178] [remote 185.118.190.176:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carnescapellari.top"] [uri "/wp-login.php"] [unique_id "aoSANPcmepr5_nHgLbM34wACLWY"] [Tue Aug 18 12:54:28.049502 2026] [security2:error] [pid 67073:tid 67241] [client 20.171.51.14:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lw.php"] [unique_id "aoSANPcmepr5_nHgLbM35AAAAjg"] [Tue Aug 18 12:54:28.115191 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.133.44:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/access.php"] [unique_id "aoSANNO5rbWdOArH04KAKwAAAXQ"] [Tue Aug 18 12:54:28.140603 2026] [security2:error] [pid 67073:tid 67298] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/first.php"] [unique_id "aoSANPcmepr5_nHgLbM35gAAAnE"] [Tue Aug 18 12:54:28.163563 2026] [security2:error] [pid 66623:tid 66775] [client 172.182.200.96:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSANNO5rbWdOArH04KALAAAARM"] [Tue Aug 18 12:54:28.196480 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSANPcmepr5_nHgLbM36QAAAno"] [Tue Aug 18 12:54:28.201247 2026] [security2:error] [pid 66623:tid 66848] [client 20.91.215.254:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/goat.php"] [unique_id "aoSANNO5rbWdOArH04KALgAAAVw"] [Tue Aug 18 12:54:28.214651 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.136.165:37889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ty.php"] [unique_id "aoSANNO5rbWdOArH04KALwAAAVU"] [Tue Aug 18 12:54:28.241125 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:8057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/new.php"] [unique_id "aoSANNO5rbWdOArH04KAMAAAAWc"] [Tue Aug 18 12:54:28.273278 2026] [security2:error] [pid 66623:tid 66804] [client 20.116.17.175:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSANNO5rbWdOArH04KAMQAAATA"] [Tue Aug 18 12:54:28.285635 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSANPcmepr5_nHgLbM36wAAAk8"] [Tue Aug 18 12:54:28.288779 2026] [security2:error] [pid 66623:tid 66784] [client 52.173.121.69:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSANNO5rbWdOArH04KAMgAAARw"] [Tue Aug 18 12:54:28.317994 2026] [security2:error] [pid 67073:tid 67216] [client 20.104.100.201:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/zero.php"] [unique_id "aoSANPcmepr5_nHgLbM37gAAAh8"] [Tue Aug 18 12:54:28.326243 2026] [security2:error] [pid 67073:tid 67121] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/zc-318.php"] [unique_id "aoSANPcmepr5_nHgLbM38AACFC0"] [Tue Aug 18 12:54:28.328547 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:28.328816 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:28.342822 2026] [security2:error] [pid 66623:tid 66862] [client 192.141.172.134:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAMwAAAWo"] [Tue Aug 18 12:54:28.342919 2026] [security2:error] [pid 66623:tid 66862] [client 192.141.172.134:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAMwAAAWo"] [Tue Aug 18 12:54:28.364673 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:19224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/edit.php"] [unique_id "aoSANNO5rbWdOArH04KANAAAASc"] [Tue Aug 18 12:54:28.385954 2026] [security2:error] [pid 66623:tid 66814] [client 132.196.61.152:56096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/uwu.php"] [unique_id "aoSANNO5rbWdOArH04KANQAAATo"] [Tue Aug 18 12:54:28.411964 2026] [security2:error] [pid 67073:tid 67320] [client 213.35.127.232:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSANPcmepr5_nHgLbM38gAAAoc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:28.420181 2026] [security2:error] [pid 67073:tid 67270] [client 52.139.47.57:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/z.php"] [unique_id "aoSANPcmepr5_nHgLbM38wAAAlU"] [Tue Aug 18 12:54:28.432378 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/packed.php"] [unique_id "aoSANPcmepr5_nHgLbM39AAAAkg"] [Tue Aug 18 12:54:28.444093 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.74.177:17206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/sf.php"] [unique_id "aoSANNO5rbWdOArH04KAOAAAATM"] [Tue Aug 18 12:54:28.456209 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.6.191:6540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/222.php"] [unique_id "aoSANNO5rbWdOArH04KAOQAAAYc"] [Tue Aug 18 12:54:28.457305 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANNO5rbWdOArH04KAOgAAARk"] [Tue Aug 18 12:54:28.461420 2026] [security2:error] [pid 67073:tid 67211] [client 4.232.151.198:6151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/public/storage.php"] [unique_id "aoSANPcmepr5_nHgLbM39gAAAho"] [Tue Aug 18 12:54:28.468521 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.98.162:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/h.php"] [unique_id "aoSANPcmepr5_nHgLbM39wAAAhU"] [Tue Aug 18 12:54:28.477542 2026] [security2:error] [pid 66623:tid 66861] [client 86.120.159.145:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAPAAAAWk"] [Tue Aug 18 12:54:28.477619 2026] [security2:error] [pid 66623:tid 66861] [client 86.120.159.145:64974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANNO5rbWdOArH04KAPAAAAWk"] [Tue Aug 18 12:54:28.477634 2026] [security2:error] [pid 67073:tid 67321] [client 114.119.148.64:29859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bomcarmultimarcas.com.br"] [uri "/veiculo/270316/brasilia"] [unique_id "aoSANPcmepr5_nHgLbM3-QAAAog"], referer: https://bomcarmultimarcas.com.br/veiculo/270316/brasilia [Tue Aug 18 12:54:28.497494 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:15768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vj.php"] [unique_id "aoSANNO5rbWdOArH04KAPwAAAUY"] [Tue Aug 18 12:54:28.500865 2026] [security2:error] [pid 66623:tid 66856] [client 52.238.210.254:8904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/404.php"] [unique_id "aoSANNO5rbWdOArH04KAQAAAAWQ"] [Tue Aug 18 12:54:28.507301 2026] [security2:error] [pid 67073:tid 67148] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ccou.php"] [unique_id "aoSANPcmepr5_nHgLbM3-wACjUg"] [Tue Aug 18 12:54:28.528672 2026] [security2:error] [pid 67073:tid 67318] [client 172.182.200.96:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSANPcmepr5_nHgLbM3_AAAAoU"] [Tue Aug 18 12:54:28.533224 2026] [security2:error] [pid 66623:tid 66870] [client 104.209.144.33:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zugvi.php"] [unique_id "aoSANNO5rbWdOArH04KAQQAAAXI"] [Tue Aug 18 12:54:28.534046 2026] [security2:error] [pid 66623:tid 66819] [client 20.104.85.180:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/222.php"] [unique_id "aoSANNO5rbWdOArH04KAQgAAAT8"] [Tue Aug 18 12:54:28.542336 2026] [security2:error] [pid 67073:tid 67213] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANPcmepr5_nHgLbM39QACHBk"] [Tue Aug 18 12:54:28.605879 2026] [security2:error] [pid 66623:tid 66788] [client 20.104.100.201:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/002.php"] [unique_id "aoSANNO5rbWdOArH04KARQAAASA"] [Tue Aug 18 12:54:28.611706 2026] [security2:error] [pid 67073:tid 67296] [client 20.48.236.86:10752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/php.php"] [unique_id "aoSANPcmepr5_nHgLbM3_wAAAm8"] [Tue Aug 18 12:54:28.630040 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:28.630319 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:28.632098 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.136.165:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/vgtyu.php"] [unique_id "aoSANNO5rbWdOArH04KARgAAAYQ"] [Tue Aug 18 12:54:28.648500 2026] [security2:error] [pid 66623:tid 66654] [remote 192.250.229.214:59490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSANNO5rbWdOArH04KARwABIxE"] [Tue Aug 18 12:54:28.689349 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/txets.php"] [unique_id "aoSANPcmepr5_nHgLbM4AgACa24"] [Tue Aug 18 12:54:28.695476 2026] [security2:error] [pid 67073:tid 67328] [client 20.116.17.175:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSANPcmepr5_nHgLbM4AwAAAo8"] [Tue Aug 18 12:54:28.746821 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:16475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/nwwha.php"] [unique_id "aoSANPcmepr5_nHgLbM4BAAAAkI"] [Tue Aug 18 12:54:28.752984 2026] [security2:error] [pid 67073:tid 67267] [client 40.85.222.29:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANPcmepr5_nHgLbM4BQAAAlI"] [Tue Aug 18 12:54:28.757642 2026] [security2:error] [pid 66623:tid 66833] [client 20.163.43.14:3163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSANNO5rbWdOArH04KASAAAAU0"] [Tue Aug 18 12:54:28.788054 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSANNO5rbWdOArH04KASQAAAUc"] [Tue Aug 18 12:54:28.792198 2026] [security2:error] [pid 67073:tid 67271] [client 4.223.164.152:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/domvf.php"] [unique_id "aoSANPcmepr5_nHgLbM4CAAAAlY"] [Tue Aug 18 12:54:28.851286 2026] [security2:error] [pid 66623:tid 66837] [client 20.91.215.254:20545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/Session.php"] [unique_id "aoSANNO5rbWdOArH04KASgAAAVE"] [Tue Aug 18 12:54:28.856086 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSANPcmepr5_nHgLbM4CgAAAh0"] [Tue Aug 18 12:54:28.890628 2026] [security2:error] [pid 66623:tid 66884] [client 20.104.85.180:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/chosen.php"] [unique_id "aoSANNO5rbWdOArH04KASwAAAYA"] [Tue Aug 18 12:54:28.891608 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.100.201:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/zxz.php"] [unique_id "aoSANPcmepr5_nHgLbM4CwAAAnI"] [Tue Aug 18 12:54:28.898966 2026] [security2:error] [pid 66623:tid 66779] [client 74.248.136.165:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xmy.php"] [unique_id "aoSANNO5rbWdOArH04KATQAAARc"] [Tue Aug 18 12:54:28.906584 2026] [authz_core:error] [pid 67073:tid 67190] [remote 57.141.22.21:45994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:28.907003 2026] [authz_core:error] [pid 67073:tid 67190] [remote 57.141.22.21:45994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:28.913160 2026] [autoindex:error] [pid 66623:tid 66780] [client 172.202.39.151:65245] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:28.932275 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:28.932536 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:28.949637 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:6644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/chosen.php"] [unique_id "aoSANPcmepr5_nHgLbM4EAAAAkw"] [Tue Aug 18 12:54:28.951288 2026] [security2:error] [pid 67073:tid 67284] [client 20.51.153.15:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ig.php"] [unique_id "aoSANPcmepr5_nHgLbM4EQAAAmM"] [Tue Aug 18 12:54:28.959629 2026] [security2:error] [pid 66623:tid 66838] [client 52.139.47.57:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ee.php"] [unique_id "aoSANNO5rbWdOArH04KATwAAAVI"] [Tue Aug 18 12:54:29.011054 2026] [security2:error] [pid 67073:tid 67232] [client 20.171.51.14:45423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mimes.php"] [unique_id "aoSANfcmepr5_nHgLbM4EgAAAi8"] [Tue Aug 18 12:54:29.049798 2026] [security2:error] [pid 67073:tid 67315] [client 74.248.136.165:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mans.php"] [unique_id "aoSANfcmepr5_nHgLbM4FAAAAoI"] [Tue Aug 18 12:54:29.061946 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:20510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/chosen.php"] [unique_id "aoSANfcmepr5_nHgLbM4FQAAAnY"] [Tue Aug 18 12:54:29.090092 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.133.44:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/02.php"] [unique_id "aoSANfcmepr5_nHgLbM4GAAAApM"] [Tue Aug 18 12:54:29.094515 2026] [security2:error] [pid 66623:tid 66794] [client 135.225.75.187:9403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/kj.php"] [unique_id "aoSANdO5rbWdOArH04KAUQAAASY"] [Tue Aug 18 12:54:29.103226 2026] [security2:error] [pid 67073:tid 67279] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSANfcmepr5_nHgLbM4GQAAAl4"] [Tue Aug 18 12:54:29.113838 2026] [security2:error] [pid 66623:tid 66800] [client 20.163.43.14:3120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-good.php"] [unique_id "aoSANdO5rbWdOArH04KAUgAAASw"] [Tue Aug 18 12:54:29.143315 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:26844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/signon.php"] [unique_id "aoSANfcmepr5_nHgLbM4GwAAAiU"] [Tue Aug 18 12:54:29.144586 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:48186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/radio.php"] [unique_id "aoSANdO5rbWdOArH04KAUwAAAVk"] [Tue Aug 18 12:54:29.165210 2026] [security2:error] [pid 66623:tid 66818] [client 20.104.100.201:21489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/memberfuns.php"] [unique_id "aoSANdO5rbWdOArH04KAVAAAAT4"] [Tue Aug 18 12:54:29.174516 2026] [security2:error] [pid 67073:tid 67117] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fun.php"] [unique_id "aoSANfcmepr5_nHgLbM4HAAChCk"] [Tue Aug 18 12:54:29.187801 2026] [fcgid:warn] [pid 66623:tid 66880] (70014)End of file found: [client 199.45.155.71:43980] mod_fcgid: can't get data from http client [Tue Aug 18 12:54:29.201855 2026] [security2:error] [pid 66623:tid 66812] [client 172.202.39.151:65245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSANdO5rbWdOArH04KAVgAAATg"] [Tue Aug 18 12:54:29.203777 2026] [security2:error] [pid 67073:tid 67259] [client 104.209.144.33:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wsrer.php"] [unique_id "aoSANfcmepr5_nHgLbM4HgAAAko"] [Tue Aug 18 12:54:29.206384 2026] [security2:error] [pid 66623:tid 66776] [client 114.119.136.12:52413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.novapack.com.br"] [uri "/produto/np-70tb"] [unique_id "aoSANdO5rbWdOArH04KAVwAAARQ"], referer: https://www.novapack.com.br/produto/np-30t [Tue Aug 18 12:54:29.209475 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:39851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/archive.php"] [unique_id "aoSANfcmepr5_nHgLbM4HwAAAiA"] [Tue Aug 18 12:54:29.210669 2026] [security2:error] [pid 67073:tid 67310] [client 20.104.85.180:8022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/info.php"] [unique_id "aoSANfcmepr5_nHgLbM4IAAAAn0"] [Tue Aug 18 12:54:29.224229 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSANfcmepr5_nHgLbM4IgAAAjs"] [Tue Aug 18 12:54:29.230023 2026] [security2:error] [pid 67073:tid 67324] [client 20.51.153.15:9170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ta.php"] [unique_id "aoSANfcmepr5_nHgLbM4JAAAAos"] [Tue Aug 18 12:54:29.232312 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:29.232638 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:29.239457 2026] [security2:error] [pid 67073:tid 67252] [client 5.31.227.224:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANfcmepr5_nHgLbM4JQAAAkM"] [Tue Aug 18 12:54:29.248325 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.200.96:14239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSANfcmepr5_nHgLbM4JgAAAlk"] [Tue Aug 18 12:54:29.250298 2026] [security2:error] [pid 67073:tid 67252] [client 5.31.227.224:30425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANfcmepr5_nHgLbM4JQAAAkM"] [Tue Aug 18 12:54:29.301590 2026] [security2:error] [pid 66623:tid 66836] [client 52.173.121.69:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/opsqt.php"] [unique_id "aoSANdO5rbWdOArH04KAWAAAAVA"] [Tue Aug 18 12:54:29.375507 2026] [security2:error] [pid 66623:tid 66834] [client 20.116.17.175:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSANdO5rbWdOArH04KAWQAAAU4"] [Tue Aug 18 12:54:29.383242 2026] [security2:error] [pid 67073:tid 67125] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/jq.php"] [unique_id "aoSANfcmepr5_nHgLbM4KQACLTE"] [Tue Aug 18 12:54:29.385274 2026] [security2:error] [pid 66623:tid 66796] [client 103.184.169.37:41353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANdO5rbWdOArH04KAWgAAASg"] [Tue Aug 18 12:54:29.385568 2026] [security2:error] [pid 66623:tid 66796] [client 103.184.169.37:41353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSANdO5rbWdOArH04KAWgAAASg"] [Tue Aug 18 12:54:29.419986 2026] [security2:error] [pid 67073:tid 67298] [client 20.171.51.14:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ni.php"] [unique_id "aoSANfcmepr5_nHgLbM4KwAAAnE"] [Tue Aug 18 12:54:29.430450 2026] [security2:error] [pid 66623:tid 66853] [client 213.35.127.232:64108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSANdO5rbWdOArH04KAXAAAAWE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:29.433567 2026] [security2:error] [pid 66623:tid 66641] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/img/class-wp-http-client.php"] [unique_id "aoSANdO5rbWdOArH04KAXQABSQQ"] [Tue Aug 18 12:54:29.439630 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.100.201:58480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/aa.php"] [unique_id "aoSANfcmepr5_nHgLbM4LQAAAhY"] [Tue Aug 18 12:54:29.452062 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSANdO5rbWdOArH04KAXgAAAVo"] [Tue Aug 18 12:54:29.466809 2026] [security2:error] [pid 66623:tid 66830] [client 74.248.136.165:16966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/co.php"] [unique_id "aoSANdO5rbWdOArH04KAXwAAAUo"] [Tue Aug 18 12:54:29.509508 2026] [security2:error] [pid 66623:tid 66849] [client 52.238.210.254:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lite.php"] [unique_id "aoSANdO5rbWdOArH04KAYQAAAV0"] [Tue Aug 18 12:54:29.511359 2026] [autoindex:error] [pid 66623:tid 66831] [client 20.104.85.180:8009] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:29.521348 2026] [security2:error] [pid 66623:tid 66823] [client 20.51.153.15:9208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/34.php"] [unique_id "aoSANdO5rbWdOArH04KAYgAAAUM"] [Tue Aug 18 12:54:29.533230 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:29.533499 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:29.562474 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sys.php"] [unique_id "aoSANfcmepr5_nHgLbM4MAACNRI"] [Tue Aug 18 12:54:29.575490 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.98.162:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ano.php"] [unique_id "aoSANdO5rbWdOArH04KAZAAAARE"] [Tue Aug 18 12:54:29.589857 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSANfcmepr5_nHgLbM4MgAAAlc"] [Tue Aug 18 12:54:29.636922 2026] [security2:error] [pid 66623:tid 66859] [client 52.173.121.69:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/mt/byp.php"] [unique_id "aoSANdO5rbWdOArH04KAZQAAAWc"] [Tue Aug 18 12:54:29.655110 2026] [security2:error] [pid 67073:tid 67295] [client 52.173.121.69:24987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/jvcpa.php"] [unique_id "aoSANfcmepr5_nHgLbM4NAAAAm4"] [Tue Aug 18 12:54:29.690951 2026] [security2:error] [pid 66623:tid 66804] [client 20.48.236.86:65112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/sf.php"] [unique_id "aoSANdO5rbWdOArH04KAZwAAATA"] [Tue Aug 18 12:54:29.690979 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.56.190:31035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ta.php"] [unique_id "aoSANdO5rbWdOArH04KAZgAAAVM"] [Tue Aug 18 12:54:29.719016 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/echkm.php"] [unique_id "aoSANfcmepr5_nHgLbM4OAAAAoc"] [Tue Aug 18 12:54:29.738114 2026] [security2:error] [pid 67073:tid 67270] [client 20.118.172.148:8258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/db.php"] [unique_id "aoSANfcmepr5_nHgLbM4OQAAAlU"] [Tue Aug 18 12:54:29.740966 2026] [security2:error] [pid 66623:tid 66828] [client 4.223.164.152:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gec.php"] [unique_id "aoSANdO5rbWdOArH04KAaQAAAUg"] [Tue Aug 18 12:54:29.743691 2026] [security2:error] [pid 67073:tid 67128] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/pp.php"] [unique_id "aoSANfcmepr5_nHgLbM4OgACSDQ"] [Tue Aug 18 12:54:29.773923 2026] [security2:error] [pid 66623:tid 66775] [client 4.232.151.198:48157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/root.php"] [unique_id "aoSANdO5rbWdOArH04KAagAAARM"] [Tue Aug 18 12:54:29.802851 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSANfcmepr5_nHgLbM4PAAAAog"] [Tue Aug 18 12:54:29.834447 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:29.834755 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:29.853974 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.6.191:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/info.php"] [unique_id "aoSANfcmepr5_nHgLbM4PgAAAjw"] [Tue Aug 18 12:54:29.868052 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.18.37:13038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/plugin.php"] [unique_id "aoSANdO5rbWdOArH04KAbAAAAWo"] [Tue Aug 18 12:54:29.893370 2026] [security2:error] [pid 67073:tid 67326] [client 20.51.153.15:9200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/he.php"] [unique_id "aoSANfcmepr5_nHgLbM4QAAAAo0"] [Tue Aug 18 12:54:29.900177 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.56.190:47106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/34.php"] [unique_id "aoSANfcmepr5_nHgLbM4QQAAAoU"] [Tue Aug 18 12:54:29.932864 2026] [security2:error] [pid 67073:tid 67218] [client 20.251.48.93:2128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/admin.php"] [unique_id "aoSANfcmepr5_nHgLbM4QgAAAiE"] [Tue Aug 18 12:54:29.938125 2026] [security2:error] [pid 67073:tid 67296] [client 172.182.200.96:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSANfcmepr5_nHgLbM4QwAAAm8"] [Tue Aug 18 12:54:29.967874 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:15776] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jcarvalhoimport.com.br"] [uri "/1.php"] [unique_id "aoSANfcmepr5_nHgLbM4RAAAAl8"] [Tue Aug 18 12:54:29.967968 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:15776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/1.php"] [unique_id "aoSANfcmepr5_nHgLbM4RAAAAl8"] [Tue Aug 18 12:54:29.983886 2026] [security2:error] [pid 66623:tid 66814] [client 172.182.200.96:7625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSANdO5rbWdOArH04KAbQAAATo"] [Tue Aug 18 12:54:29.987556 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file61.php"] [unique_id "aoSANfcmepr5_nHgLbM4RgAAAlo"] [Tue Aug 18 12:54:29.989819 2026] [security2:error] [pid 66623:tid 66824] [client 158.158.74.177:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/u.php"] [unique_id "aoSANdO5rbWdOArH04KAbgAAAUQ"] [Tue Aug 18 12:54:30.026326 2026] [security2:error] [pid 66623:tid 66811] [client 52.139.47.57:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/we.php"] [unique_id "aoSANtO5rbWdOArH04KAbwAAATc"] [Tue Aug 18 12:54:30.050643 2026] [security2:error] [pid 67073:tid 67223] [client 20.100.169.31:12379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/bless.php"] [unique_id "aoSANvcmepr5_nHgLbM4SQAAAiY"] [Tue Aug 18 12:54:30.167664 2026] [security2:error] [pid 67073:tid 67231] [client 172.202.39.151:44459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp.php"] [unique_id "aoSANvcmepr5_nHgLbM4TAAAAi4"] [Tue Aug 18 12:54:30.174296 2026] [security2:error] [pid 66623:tid 66891] [client 20.104.85.180:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANtO5rbWdOArH04KAcQAAAYc"] [Tue Aug 18 12:54:30.179622 2026] [security2:error] [pid 67073:tid 67323] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4TQAAAoo"] [Tue Aug 18 12:54:30.250378 2026] [security2:error] [pid 66623:tid 66850] [client 20.163.43.14:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/tes.php"] [unique_id "aoSANtO5rbWdOArH04KAcgAAAV4"] [Tue Aug 18 12:54:30.323302 2026] [security2:error] [pid 67073:tid 67289] [client 20.91.215.254:26426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSANvcmepr5_nHgLbM4UAAAAmg"] [Tue Aug 18 12:54:30.328204 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.200.96:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSANtO5rbWdOArH04KAcwAAAWQ"] [Tue Aug 18 12:54:30.350303 2026] [security2:error] [pid 66623:tid 66656] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/in.php"] [unique_id "aoSANtO5rbWdOArH04KAdAABFRM"] [Tue Aug 18 12:54:30.355498 2026] [security2:error] [pid 67073:tid 67214] [client 135.225.75.187:9351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bes.php"] [unique_id "aoSANvcmepr5_nHgLbM4UQAAAh0"] [Tue Aug 18 12:54:30.358278 2026] [security2:error] [pid 67073:tid 67234] [client 52.238.210.254:8898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lock360.php"] [unique_id "aoSANvcmepr5_nHgLbM4UgAAAjE"] [Tue Aug 18 12:54:30.425061 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:30.425316 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:30.491689 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:30.492001 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:30.537382 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.85.180:8059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4VwAAAhc"] [Tue Aug 18 12:54:30.561284 2026] [security2:error] [pid 66623:tid 66767] [client 104.209.144.33:25322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/blog/byp.php"] [unique_id "aoSANtO5rbWdOArH04KAdgAAAQs"] [Tue Aug 18 12:54:30.603708 2026] [security2:error] [pid 67073:tid 67284] [client 20.171.51.14:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/88.php"] [unique_id "aoSANvcmepr5_nHgLbM4WQAAAmM"] [Tue Aug 18 12:54:30.623318 2026] [security2:error] [pid 67073:tid 67293] [client 68.155.154.236:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSANvcmepr5_nHgLbM4WgAAAmw"] [Tue Aug 18 12:54:30.633525 2026] [security2:error] [pid 67073:tid 67161] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wqqs.php"] [unique_id "aoSANvcmepr5_nHgLbM4WwACL1U"] [Tue Aug 18 12:54:30.677413 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.61.152:55327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/copypaths.php"] [unique_id "aoSANvcmepr5_nHgLbM4XAAAAkQ"] [Tue Aug 18 12:54:30.712427 2026] [security2:error] [pid 67073:tid 67248] [client 172.182.200.96:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSANvcmepr5_nHgLbM4XQAAAj8"] [Tue Aug 18 12:54:30.713599 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSANtO5rbWdOArH04KAdwAAAS4"] [Tue Aug 18 12:54:30.718242 2026] [security2:error] [pid 66623:tid 66885] [client 4.223.164.152:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/sky.php"] [unique_id "aoSANtO5rbWdOArH04KAeAAAAYE"] [Tue Aug 18 12:54:30.736412 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:30.736663 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:30.790148 2026] [security2:error] [pid 66623:tid 66797] [client 172.202.39.151:61319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSANtO5rbWdOArH04KAeQAAASk"] [Tue Aug 18 12:54:30.798858 2026] [autoindex:error] [pid 66623:tid 66844] [client 147.185.132.60:59878] AH01276: Cannot serve directory /home1/deliciacom/public_html/: No matching DirectoryIndex (public/index.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:30.828656 2026] [security2:error] [pid 67073:tid 67171] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/clasa99.php"] [unique_id "aoSANvcmepr5_nHgLbM4YQACLF8"] [Tue Aug 18 12:54:30.853153 2026] [security2:error] [pid 67073:tid 67332] [client 20.116.17.175:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/cok.php"] [unique_id "aoSANvcmepr5_nHgLbM4YgAAApM"] [Tue Aug 18 12:54:31.042270 2026] [security2:error] [pid 67073:tid 67160] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/666.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ZgACeFQ"] [Tue Aug 18 12:54:31.052203 2026] [security2:error] [pid 67073:tid 67273] [client 20.104.100.201:58482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/domvf.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ZwAAAlg"] [Tue Aug 18 12:54:31.100929 2026] [security2:error] [pid 67073:tid 67290] [client 74.248.133.44:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/menu.php"] [unique_id "aoSAN_cmepr5_nHgLbM4aQAAAmk"] [Tue Aug 18 12:54:31.110579 2026] [security2:error] [pid 67073:tid 67249] [client 74.248.136.165:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/btx25.php"] [unique_id "aoSAN_cmepr5_nHgLbM4agAAAkA"] [Tue Aug 18 12:54:31.118947 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAN9O5rbWdOArH04KAfgAAAVE"] [Tue Aug 18 12:54:31.121730 2026] [security2:error] [pid 67073:tid 67311] [client 52.173.121.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.romarizimoveis.com.br"] [uri "/images/security.php"] [unique_id "aoSAN_cmepr5_nHgLbM4awAAAn4"] [Tue Aug 18 12:54:31.184902 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:26820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bless6.php"] [unique_id "aoSAN_cmepr5_nHgLbM4bgAAAoM"] [Tue Aug 18 12:54:31.234422 2026] [autoindex:error] [pid 67073:tid 67274] [client 52.73.140.57:52382] AH01276: Cannot serve directory /home3/aceunai/public_html/abraceocomerciodeunai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:31.352253 2026] [security2:error] [pid 66623:tid 66736] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/inc.php"] [unique_id "aoSAN9O5rbWdOArH04KAfwABF2M"] [Tue Aug 18 12:54:31.352867 2026] [security2:error] [pid 67073:tid 67209] [client 40.85.222.29:2250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAN_cmepr5_nHgLbM4cgAAAhg"] [Tue Aug 18 12:54:31.375304 2026] [security2:error] [pid 67073:tid 67300] [client 20.104.100.201:58880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/red.php"] [unique_id "aoSAN_cmepr5_nHgLbM4dAAAAnM"] [Tue Aug 18 12:54:31.547595 2026] [security2:error] [pid 67073:tid 67241] [client 172.202.39.151:29701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/an.php"] [unique_id "aoSAN_cmepr5_nHgLbM4dwAAAjg"] [Tue Aug 18 12:54:31.576876 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAN9O5rbWdOArH04KAggAAAVI"] [Tue Aug 18 12:54:31.631366 2026] [security2:error] [pid 66623:tid 66875] [client 172.202.39.151:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gelay.php"] [unique_id "aoSAN9O5rbWdOArH04KAhAAAAXc"] [Tue Aug 18 12:54:31.657231 2026] [security2:error] [pid 67073:tid 67092] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/thui.php"] [unique_id "aoSAN_cmepr5_nHgLbM4eQACcBA"] [Tue Aug 18 12:54:31.672883 2026] [security2:error] [pid 66623:tid 66668] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSAN9O5rbWdOArH04KAhQABGh8"] [Tue Aug 18 12:54:31.765302 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.136.165:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xda.php"] [unique_id "aoSAN_cmepr5_nHgLbM4ewAAAjM"] [Tue Aug 18 12:54:31.769873 2026] [security2:error] [pid 67073:tid 67222] [client 157.20.138.62:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fAAAAiU"] [Tue Aug 18 12:54:31.769963 2026] [security2:error] [pid 67073:tid 67222] [client 157.20.138.62:54266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fAAAAiU"] [Tue Aug 18 12:54:31.830136 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:29196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAN9O5rbWdOArH04KAhgAAAVY"] [Tue Aug 18 12:54:31.844043 2026] [security2:error] [pid 66623:tid 66794] [client 20.51.153.15:9091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gz.php"] [unique_id "aoSAN9O5rbWdOArH04KAhwAAASY"] [Tue Aug 18 12:54:31.850239 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:21413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/ucpfr.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fQAAAlc"] [Tue Aug 18 12:54:31.913109 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/server.php"] [unique_id "aoSAN9O5rbWdOArH04KAiAAAAXA"] [Tue Aug 18 12:54:31.925556 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/k.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fgAAAk8"] [Tue Aug 18 12:54:31.931036 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:57623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/accesson.php"] [unique_id "aoSAN9O5rbWdOArH04KAiQAAAUI"] [Tue Aug 18 12:54:31.942733 2026] [security2:error] [pid 67073:tid 67268] [client 172.202.39.151:44417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/function/function.php"] [unique_id "aoSAN_cmepr5_nHgLbM4fwAAAlM"] [Tue Aug 18 12:54:31.983639 2026] [security2:error] [pid 66623:tid 66890] [client 132.196.61.152:56109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/special.php"] [unique_id "aoSAN9O5rbWdOArH04KAjAAAAYY"] [Tue Aug 18 12:54:31.984241 2026] [autoindex:error] [pid 66623:tid 66863] [client 158.158.74.177:20492] AH01276: Cannot serve directory /home3/evandrobene/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:31.993390 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:14238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAN9O5rbWdOArH04KAjQAAASs"] [Tue Aug 18 12:54:32.008983 2026] [security2:error] [pid 67073:tid 67295] [client 172.182.200.96:14159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gAAAAm4"] [Tue Aug 18 12:54:32.107649 2026] [security2:error] [pid 66623:tid 66818] [client 52.238.210.254:10116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAONO5rbWdOArH04KAjgAAAT4"] [Tue Aug 18 12:54:32.145739 2026] [security2:error] [pid 67073:tid 67301] [client 52.173.121.69:48403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gQAAAnQ"] [Tue Aug 18 12:54:32.170471 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.100.201:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSAOPcmepr5_nHgLbM4ggAAAhk"] [Tue Aug 18 12:54:32.219246 2026] [security2:error] [pid 66623:tid 66812] [client 158.158.74.177:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/customize.php"] [unique_id "aoSAONO5rbWdOArH04KAjwAAATg"] [Tue Aug 18 12:54:32.225132 2026] [security2:error] [pid 66623:tid 66776] [client 20.171.51.14:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/hj.php"] [unique_id "aoSAONO5rbWdOArH04KAkAAAARQ"] [Tue Aug 18 12:54:32.233674 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.6.191:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAOPcmepr5_nHgLbM4gwAAAjw"] [Tue Aug 18 12:54:32.237012 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.56.190:45039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/he.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hAAAAnU"] [Tue Aug 18 12:54:32.245641 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:32.245897 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:32.247284 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/agg.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hgACjSQ"] [Tue Aug 18 12:54:32.251317 2026] [security2:error] [pid 66623:tid 66816] [client 213.35.127.232:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAONO5rbWdOArH04KAkQAAATw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:32.264547 2026] [security2:error] [pid 67073:tid 67206] [client 138.36.100.162:41464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hwAAAhU"] [Tue Aug 18 12:54:32.264644 2026] [security2:error] [pid 67073:tid 67206] [client 138.36.100.162:41464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAOPcmepr5_nHgLbM4hwAAAhU"] [Tue Aug 18 12:54:32.412349 2026] [autoindex:error] [pid 67073:tid 67275] [client 199.45.155.71:43984] AH01276: Cannot serve directory /home4/filial35/public_html/kazanovapapeldeparede/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:32.451493 2026] [security2:error] [pid 67073:tid 67266] [client 172.182.200.96:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAOPcmepr5_nHgLbM4iQAAAlE"] [Tue Aug 18 12:54:32.484659 2026] [security2:error] [pid 66623:tid 66836] [client 20.65.98.162:23869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ai.php"] [unique_id "aoSAONO5rbWdOArH04KAkwAAAVA"] [Tue Aug 18 12:54:32.520801 2026] [security2:error] [pid 67073:tid 67205] [client 52.139.47.57:13533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/to.php"] [unique_id "aoSAOPcmepr5_nHgLbM4iwAAAhQ"] [Tue Aug 18 12:54:32.533992 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.18.37:12315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/public/moon.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jAAAAjI"] [Tue Aug 18 12:54:32.552924 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:32.553177 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:32.622011 2026] [security2:error] [pid 67073:tid 67260] [client 4.232.151.198:6491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jgAAAks"] [Tue Aug 18 12:54:32.649108 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:9147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nf.php"] [unique_id "aoSAOPcmepr5_nHgLbM4jwAAAmo"] [Tue Aug 18 12:54:32.705797 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAOPcmepr5_nHgLbM4kQAAAlw"] [Tue Aug 18 12:54:32.731142 2026] [security2:error] [pid 66623:tid 66662] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index/function.php"] [unique_id "aoSAONO5rbWdOArH04KAlAABSRk"] [Tue Aug 18 12:54:32.761559 2026] [security2:error] [pid 67073:tid 67289] [client 20.171.51.14:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ij.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lAAAAmg"] [Tue Aug 18 12:54:32.768902 2026] [security2:error] [pid 67073:tid 67283] [client 20.116.17.175:57611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/av.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lQAAAmI"] [Tue Aug 18 12:54:32.786155 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAOPcmepr5_nHgLbM4lgAAAh0"] [Tue Aug 18 12:54:32.845278 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:32.845545 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:32.847089 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.56.190:2554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gz.php"] [unique_id "aoSAOPcmepr5_nHgLbM4mQAAAkw"] [Tue Aug 18 12:54:32.955406 2026] [security2:error] [pid 66623:tid 66770] [client 172.202.39.151:30472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cah.php"] [unique_id "aoSAONO5rbWdOArH04KAlgAAAQ4"] [Tue Aug 18 12:54:32.964963 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSAONO5rbWdOArH04KAlwAAAV0"] [Tue Aug 18 12:54:33.009812 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:37941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/96i.php"] [unique_id "aoSAOdO5rbWdOArH04KAmAAAAXw"] [Tue Aug 18 12:54:33.035785 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/files/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4nAAAAl4"] [Tue Aug 18 12:54:33.054946 2026] [security2:error] [pid 66623:tid 66653] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/index4.php"] [unique_id "aoSAOdO5rbWdOArH04KAmQABQxA"] [Tue Aug 18 12:54:33.058818 2026] [security2:error] [pid 67073:tid 67135] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/erty.php"] [unique_id "aoSAOfcmepr5_nHgLbM4ngACfzs"] [Tue Aug 18 12:54:33.061172 2026] [authz_core:error] [pid 67073:tid 67182] [remote 57.141.22.35:45836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:33.061436 2026] [authz_core:error] [pid 67073:tid 67182] [remote 57.141.22.35:45836] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:33.082423 2026] [security2:error] [pid 67073:tid 67269] [client 20.251.48.93:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/mac.php"] [unique_id "aoSAOfcmepr5_nHgLbM4oAAAAlQ"] [Tue Aug 18 12:54:33.157877 2026] [security2:error] [pid 67073:tid 67290] [client 104.209.144.33:17257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/yxijx.php"] [unique_id "aoSAOfcmepr5_nHgLbM4oQAAAmk"] [Tue Aug 18 12:54:33.282059 2026] [security2:error] [pid 67073:tid 67119] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mini.php"] [unique_id "aoSAOfcmepr5_nHgLbM4qQACOys"] [Tue Aug 18 12:54:33.293216 2026] [autoindex:error] [pid 67073:tid 67310] [client 20.104.85.180:7966] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:33.342818 2026] [autoindex:error] [pid 66623:tid 66859] [client 194.36.25.35:56723] AH01276: Cannot serve directory /home1/hawaiedu/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:33.368846 2026] [security2:error] [pid 66623:tid 66658] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/info.php"] [unique_id "aoSAOdO5rbWdOArH04KAnAABgxU"] [Tue Aug 18 12:54:33.372118 2026] [security2:error] [pid 66623:tid 66804] [client 52.173.121.69:16479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAOdO5rbWdOArH04KAnQAAATA"] [Tue Aug 18 12:54:33.378741 2026] [security2:error] [pid 67073:tid 67233] [client 20.51.153.15:8785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xv.php"] [unique_id "aoSAOfcmepr5_nHgLbM4rQAAAjA"] [Tue Aug 18 12:54:33.532327 2026] [security2:error] [pid 67073:tid 67138] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sid3.php"] [unique_id "aoSAOfcmepr5_nHgLbM4sAACZD4"] [Tue Aug 18 12:54:33.595639 2026] [security2:error] [pid 67073:tid 67258] [client 20.104.85.180:7966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/403.php"] [unique_id "aoSAOfcmepr5_nHgLbM4swAAAkk"] [Tue Aug 18 12:54:33.691355 2026] [security2:error] [pid 66623:tid 66704] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/init.php"] [unique_id "aoSAOdO5rbWdOArH04KAoAABHUM"] [Tue Aug 18 12:54:33.701699 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.61.152:26825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/fz.php"] [unique_id "aoSAOdO5rbWdOArH04KAoQAAARM"] [Tue Aug 18 12:54:33.753165 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:33.753641 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:33.859492 2026] [security2:error] [pid 66623:tid 66793] [client 52.238.210.254:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAOdO5rbWdOArH04KAogAAASU"] [Tue Aug 18 12:54:33.866318 2026] [security2:error] [pid 66623:tid 66772] [client 20.171.51.14:29190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ud.php"] [unique_id "aoSAOdO5rbWdOArH04KAowAAARA"] [Tue Aug 18 12:54:33.902486 2026] [security2:error] [pid 67073:tid 67238] [client 172.182.200.96:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAOfcmepr5_nHgLbM4uAAAAjU"] [Tue Aug 18 12:54:33.932608 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:50233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAOdO5rbWdOArH04KApgAAATc"] [Tue Aug 18 12:54:33.969955 2026] [autoindex:error] [pid 67073:tid 67268] [client 20.104.85.180:7993] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:33.981857 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:3100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4uwAAAm4"] [Tue Aug 18 12:54:33.986030 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.133.44:48297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/spip.php"] [unique_id "aoSAOfcmepr5_nHgLbM4vAAAAiM"] [Tue Aug 18 12:54:33.992309 2026] [security2:error] [pid 67073:tid 67278] [client 78.47.173.76:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSAOfcmepr5_nHgLbM4mwACXRs"], referer: https://www.doroincorporacoes.com.br/ [Tue Aug 18 12:54:34.046426 2026] [security2:error] [pid 67073:tid 67267] [client 20.51.153.15:8831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mx.php"] [unique_id "aoSAOvcmepr5_nHgLbM4vgAAAlI"] [Tue Aug 18 12:54:34.049743 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:34.050008 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:34.066657 2026] [security2:error] [pid 67073:tid 67307] [client 20.250.13.23:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/as.php"] [unique_id "aoSAOvcmepr5_nHgLbM4vwAAAno"] [Tue Aug 18 12:54:34.077053 2026] [security2:error] [pid 67073:tid 67097] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/moon.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wAACSBU"] [Tue Aug 18 12:54:34.122838 2026] [security2:error] [pid 66623:tid 66824] [client 5.253.205.188:40734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/fullwebsite.sql"] [unique_id "aoSAOtO5rbWdOArH04KAqAAAAUQ"], referer: https://medihub.com.br/fullwebsite.sql [Tue Aug 18 12:54:34.195127 2026] [security2:error] [pid 66623:tid 66810] [client 20.226.56.190:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nf.php"] [unique_id "aoSAOtO5rbWdOArH04KAqQAAATY"] [Tue Aug 18 12:54:34.223861 2026] [security2:error] [pid 66623:tid 66877] [client 52.139.47.57:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ty.php"] [unique_id "aoSAOtO5rbWdOArH04KAqgAAAXk"] [Tue Aug 18 12:54:34.228416 2026] [security2:error] [pid 66623:tid 66856] [client 4.223.164.152:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/sixxis.php"] [unique_id "aoSAOtO5rbWdOArH04KAqwAAAWQ"] [Tue Aug 18 12:54:34.297164 2026] [security2:error] [pid 67073:tid 67174] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wgACdWI"] [Tue Aug 18 12:54:34.316916 2026] [security2:error] [pid 67073:tid 67202] [remote 203.99.146.53:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "macambio.com"] [uri "/wp-login.php"] [unique_id "aoSAOvcmepr5_nHgLbM4wwACVn4"] [Tue Aug 18 12:54:34.329003 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAOtO5rbWdOArH04KArQAAAWg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:34.340471 2026] [autoindex:error] [pid 67073:tid 67318] [client 20.104.85.180:7993] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:34.340905 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/45.php"] [unique_id "aoSAOvcmepr5_nHgLbM4xQAAAio"] [Tue Aug 18 12:54:34.351306 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:34.351568 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:34.384343 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.169.31:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAOtO5rbWdOArH04KArgAAAVs"] [Tue Aug 18 12:54:34.432563 2026] [security2:error] [pid 67073:tid 67280] [client 135.225.75.187:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws60.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zAAAAl8"] [Tue Aug 18 12:54:34.444145 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/dropdown.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zQAAAlo"] [Tue Aug 18 12:54:34.492930 2026] [security2:error] [pid 67073:tid 67167] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wsws.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zgACPls"] [Tue Aug 18 12:54:34.500511 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAOvcmepr5_nHgLbM4zwAAAhQ"] [Tue Aug 18 12:54:34.515810 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.85.180:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/gecko.php"] [unique_id "aoSAOvcmepr5_nHgLbM40AAAAjI"] [Tue Aug 18 12:54:34.545758 2026] [autoindex:error] [pid 67073:tid 67260] [client 172.202.39.151:42789] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:34.600799 2026] [security2:error] [pid 66623:tid 66660] [remote 46.62.208.238:48548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSAOtO5rbWdOArH04KAsgABPRc"] [Tue Aug 18 12:54:34.602951 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAOvcmepr5_nHgLbM40wAAAkI"] [Tue Aug 18 12:54:34.685519 2026] [authz_core:error] [pid 67073:tid 67118] [remote 57.141.22.48:29922] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:34.685782 2026] [authz_core:error] [pid 67073:tid 67118] [remote 57.141.22.48:29922] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:34.688284 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.56.190:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xv.php"] [unique_id "aoSAOtO5rbWdOArH04KAuAAAAYE"] [Tue Aug 18 12:54:34.688400 2026] [autoindex:error] [pid 66623:tid 66802] [client 194.36.25.35:56723] AH01276: Cannot serve directory /home1/hawaiedu/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:34.730062 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:12301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/public/storage.php"] [unique_id "aoSAOtO5rbWdOArH04KAugAAASE"] [Tue Aug 18 12:54:34.835200 2026] [security2:error] [pid 67073:tid 67261] [client 4.223.164.152:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/yj09.php"] [unique_id "aoSAOvcmepr5_nHgLbM42QAAAkw"] [Tue Aug 18 12:54:34.976945 2026] [security2:error] [pid 67073:tid 67289] [client 4.232.151.198:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/shell.php"] [unique_id "aoSAOvcmepr5_nHgLbM43AAAAmg"] [Tue Aug 18 12:54:35.149449 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.98.162:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAO_cmepr5_nHgLbM43gAAAlQ"] [Tue Aug 18 12:54:35.161344 2026] [security2:error] [pid 67073:tid 67203] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/motu.php"] [unique_id "aoSAO_cmepr5_nHgLbM43wAChH8"] [Tue Aug 18 12:54:35.196606 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:2510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mx.php"] [unique_id "aoSAO_cmepr5_nHgLbM44AAAAlg"] [Tue Aug 18 12:54:35.198614 2026] [security2:error] [pid 66623:tid 66773] [client 160.120.140.123:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAwAAAARE"] [Tue Aug 18 12:54:35.198731 2026] [security2:error] [pid 66623:tid 66773] [client 160.120.140.123:55637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAwAAAARE"] [Tue Aug 18 12:54:35.205105 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.6.191:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/k.php"] [unique_id "aoSAO_cmepr5_nHgLbM44gAAAkA"] [Tue Aug 18 12:54:35.206176 2026] [security2:error] [pid 66623:tid 66837] [client 20.171.51.14:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xg.php"] [unique_id "aoSAO9O5rbWdOArH04KAwQAAAVE"] [Tue Aug 18 12:54:35.268914 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:35.269181 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:35.279026 2026] [security2:error] [pid 67073:tid 67284] [client 172.202.39.151:44464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAO_cmepr5_nHgLbM45QAAAmM"] [Tue Aug 18 12:54:35.285196 2026] [security2:error] [pid 67073:tid 67277] [client 52.139.47.57:19626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ak.php"] [unique_id "aoSAO_cmepr5_nHgLbM45wAAAlw"] [Tue Aug 18 12:54:35.331497 2026] [security2:error] [pid 66623:tid 66825] [client 20.100.169.31:24506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAO9O5rbWdOArH04KAxAAAAUU"] [Tue Aug 18 12:54:35.352929 2026] [autoindex:error] [pid 67073:tid 67233] [client 20.104.85.180:7234] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:35.379442 2026] [security2:error] [pid 67073:tid 67120] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fff.php"] [unique_id "aoSAO_cmepr5_nHgLbM46gACjCw"] [Tue Aug 18 12:54:35.416281 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:3149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAO_cmepr5_nHgLbM46wAAAkY"] [Tue Aug 18 12:54:35.459481 2026] [security2:error] [pid 67073:tid 67252] [client 74.248.18.37:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/radio.php"] [unique_id "aoSAO_cmepr5_nHgLbM47QAAAkM"] [Tue Aug 18 12:54:35.460181 2026] [security2:error] [pid 67073:tid 67217] [client 20.151.109.219:12884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAO_cmepr5_nHgLbM47gAAAiA"] [Tue Aug 18 12:54:35.559764 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:35.560179 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:35.600746 2026] [security2:error] [pid 67073:tid 67095] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/66.php"] [unique_id "aoSAO_cmepr5_nHgLbM48wACdxM"] [Tue Aug 18 12:54:35.603164 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.155.199:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAOvcmepr5_nHgLbM40gAAAiY"] [Tue Aug 18 12:54:35.634838 2026] [security2:error] [pid 67073:tid 67207] [client 172.182.200.96:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAO_cmepr5_nHgLbM49gAAAhY"] [Tue Aug 18 12:54:35.680812 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/sim.php"] [unique_id "aoSAO_cmepr5_nHgLbM49wAAAjQ"] [Tue Aug 18 12:54:35.737144 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:47235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/file.php"] [unique_id "aoSAO9O5rbWdOArH04KAyAAAAS8"] [Tue Aug 18 12:54:35.797846 2026] [security2:error] [pid 67073:tid 67238] [client 20.151.109.219:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAO_cmepr5_nHgLbM4-gAAAjU"] [Tue Aug 18 12:54:35.804136 2026] [security2:error] [pid 66623:tid 66794] [client 20.163.43.14:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/rip.php"] [unique_id "aoSAO9O5rbWdOArH04KAyQAAASY"] [Tue Aug 18 12:54:35.813413 2026] [security2:error] [pid 67073:tid 67121] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/g.php"] [unique_id "aoSAO_cmepr5_nHgLbM4-wACVy0"] [Tue Aug 18 12:54:35.865969 2026] [security2:error] [pid 66623:tid 66868] [client 20.251.48.93:35083] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.activevalue.com.br"] [uri "/1.php"] [unique_id "aoSAO9O5rbWdOArH04KAygAAAXA"] [Tue Aug 18 12:54:35.866058 2026] [security2:error] [pid 66623:tid 66868] [client 20.251.48.93:35083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/1.php"] [unique_id "aoSAO9O5rbWdOArH04KAygAAAXA"] [Tue Aug 18 12:54:35.892847 2026] [security2:error] [pid 67073:tid 67278] [client 52.238.210.254:10138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.alf.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JAAAAl0"] [Tue Aug 18 12:54:35.942989 2026] [security2:error] [pid 67073:tid 67301] [client 20.51.153.15:9189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wy.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JQAAAnQ"] [Tue Aug 18 12:54:35.956878 2026] [security2:error] [pid 67073:tid 67210] [client 172.202.39.151:36880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/404.php"] [unique_id "aoSAO_cmepr5_nHgLbM5JgAAAhk"] [Tue Aug 18 12:54:36.050127 2026] [security2:error] [pid 67073:tid 67321] [client 20.171.51.14:43362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ip.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KAAAAog"] [Tue Aug 18 12:54:36.185546 2026] [security2:error] [pid 67073:tid 67227] [client 20.226.56.190:3039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/45.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KgAAAio"] [Tue Aug 18 12:54:36.264901 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:9106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/f.php"] [unique_id "aoSAPPcmepr5_nHgLbM5KwAAAiE"] [Tue Aug 18 12:54:36.268207 2026] [security2:error] [pid 67073:tid 67296] [client 172.202.39.151:55425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LAAAAm8"] [Tue Aug 18 12:54:36.310050 2026] [security2:error] [pid 66623:tid 66705] [remote 162.241.153.188:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAO9O5rbWdOArH04KAwwABiUQ"] [Tue Aug 18 12:54:36.311319 2026] [security2:error] [pid 67073:tid 67266] [client 4.223.164.152:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/k.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LQAAAlE"] [Tue Aug 18 12:54:36.320838 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSAPPcmepr5_nHgLbM5LgAAAjI"] [Tue Aug 18 12:54:36.369481 2026] [security2:error] [pid 67073:tid 67291] [client 52.238.210.254:10143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.trash7206/index.php"] [unique_id "aoSAPPcmepr5_nHgLbM5MAAAAmo"] [Tue Aug 18 12:54:36.490321 2026] [security2:error] [pid 67073:tid 67276] [client 213.202.253.4:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/filefuns.php"] [unique_id "aoSAPPcmepr5_nHgLbM5MgAAAls"], referer: www.google.com [Tue Aug 18 12:54:36.556370 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/zz.php"] [unique_id "aoSAPPcmepr5_nHgLbM5NQAAAh4"] [Tue Aug 18 12:54:36.582028 2026] [security2:error] [pid 66623:tid 66744] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/inputs.php"] [unique_id "aoSAPNO5rbWdOArH04KA2wABLWs"] [Tue Aug 18 12:54:36.597970 2026] [security2:error] [pid 67073:tid 67312] [client 20.151.109.219:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/st.php"] [unique_id "aoSAPPcmepr5_nHgLbM5NgAAAn8"] [Tue Aug 18 12:54:36.713870 2026] [security2:error] [pid 67073:tid 67265] [client 20.104.85.180:7234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/aa.php"] [unique_id "aoSAPPcmepr5_nHgLbM5RAAAAlA"] [Tue Aug 18 12:54:36.719776 2026] [autoindex:error] [pid 67073:tid 67311] [client 209.38.140.160:57374] AH01276: Cannot serve directory /home1/numem/console.numem.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:36.738736 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:7442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/fm.php"] [unique_id "aoSAPPcmepr5_nHgLbM5RQAAAnk"] [Tue Aug 18 12:54:36.790935 2026] [security2:error] [pid 66623:tid 66822] [client 37.40.227.74:56715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPNO5rbWdOArH04KA3wAAAUI"] [Tue Aug 18 12:54:36.791549 2026] [security2:error] [pid 66623:tid 66822] [client 37.40.227.74:56715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPNO5rbWdOArH04KA3wAAAUI"] [Tue Aug 18 12:54:36.871925 2026] [security2:error] [pid 66623:tid 66798] [client 52.238.210.254:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp-login.php"] [unique_id "aoSAPNO5rbWdOArH04KA3gAAASo"] [Tue Aug 18 12:54:36.909466 2026] [security2:error] [pid 67073:tid 67173] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/x7.php"] [unique_id "aoSAPPcmepr5_nHgLbM5SwACRmE"] [Tue Aug 18 12:54:36.922845 2026] [security2:error] [pid 67073:tid 67258] [client 20.226.6.191:6651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/403.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TAAAAkk"] [Tue Aug 18 12:54:36.972910 2026] [security2:error] [pid 67073:tid 67217] [client 52.173.121.69:25017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TgAAAiA"] [Tue Aug 18 12:54:36.984896 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/root.php"] [unique_id "aoSAPPcmepr5_nHgLbM5TwAAAkg"] [Tue Aug 18 12:54:37.076086 2026] [security2:error] [pid 66623:tid 66875] [client 85.154.68.202:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAPdO5rbWdOArH04KA4gAAAXc"] [Tue Aug 18 12:54:37.076232 2026] [security2:error] [pid 66623:tid 66875] [client 85.154.68.202:9861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAPdO5rbWdOArH04KA4gAAAXc"] [Tue Aug 18 12:54:37.078216 2026] [security2:error] [pid 66623:tid 66834] [client 52.238.210.254:10235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAPdO5rbWdOArH04KA4wAAAU4"] [Tue Aug 18 12:54:37.107859 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/god.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UQACdxY"] [Tue Aug 18 12:54:37.179315 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:42789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/system_log.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UgAAAmI"] [Tue Aug 18 12:54:37.224690 2026] [security2:error] [pid 67073:tid 67237] [client 104.209.144.33:32677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAPfcmepr5_nHgLbM5UwAAAjQ"] [Tue Aug 18 12:54:37.275234 2026] [security2:error] [pid 66623:tid 66853] [client 135.225.75.187:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/olfclass.php"] [unique_id "aoSAPdO5rbWdOArH04KA5QAAAWE"] [Tue Aug 18 12:54:37.291129 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:39682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/goods.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VAAAAiU"] [Tue Aug 18 12:54:37.295503 2026] [security2:error] [pid 66623:tid 66829] [client 20.171.51.14:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/nd.php"] [unique_id "aoSAPdO5rbWdOArH04KA5gAAAUk"] [Tue Aug 18 12:54:37.304962 2026] [security2:error] [pid 67073:tid 67112] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VQACNSQ"] [Tue Aug 18 12:54:37.355008 2026] [security2:error] [pid 67073:tid 67223] [client 52.139.47.57:63070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp.php"] [unique_id "aoSAPfcmepr5_nHgLbM5VwAAAiY"] [Tue Aug 18 12:54:37.437016 2026] [security2:error] [pid 67073:tid 67307] [client 20.151.109.219:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/le.php"] [unique_id "aoSAPfcmepr5_nHgLbM5XgAAAno"] [Tue Aug 18 12:54:37.454191 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:46199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/w.php"] [unique_id "aoSAPfcmepr5_nHgLbM5XwAAAhk"] [Tue Aug 18 12:54:37.460940 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YAAAAmw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:37.489056 2026] [security2:error] [pid 66623:tid 66881] [client 20.51.153.15:9164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/30.php"] [unique_id "aoSAPdO5rbWdOArH04KA5wAAAX0"] [Tue Aug 18 12:54:37.502296 2026] [security2:error] [pid 67073:tid 67297] [client 20.251.48.93:29306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/coffee.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YQAAAnA"] [Tue Aug 18 12:54:37.502333 2026] [security2:error] [pid 67073:tid 67192] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/8.php"] [unique_id "aoSAPfcmepr5_nHgLbM5YgACiHQ"] [Tue Aug 18 12:54:37.509312 2026] [security2:error] [pid 67073:tid 67324] [client 20.250.13.23:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/min.php"] [unique_id "aoSAPfcmepr5_nHgLbM5ZAAAAos"] [Tue Aug 18 12:54:37.580734 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:3171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5agAAAlY"] [Tue Aug 18 12:54:37.595045 2026] [security2:error] [pid 67073:tid 67206] [client 52.173.121.69:9916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bAAAAhU"] [Tue Aug 18 12:54:37.697794 2026] [security2:error] [pid 67073:tid 67153] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/koiy.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bQACWk0"] [Tue Aug 18 12:54:37.698401 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.155.199:7320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAPfcmepr5_nHgLbM5bgAAAns"] [Tue Aug 18 12:54:37.718821 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.133.44:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSAPfcmepr5_nHgLbM5cQAAAho"] [Tue Aug 18 12:54:37.791419 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:24889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hr.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dAAAAh0"] [Tue Aug 18 12:54:37.855694 2026] [security2:error] [pid 67073:tid 67317] [client 157.51.166.53:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dQAAAoQ"] [Tue Aug 18 12:54:37.855841 2026] [security2:error] [pid 67073:tid 67317] [client 157.51.166.53:54488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dQAAAoQ"] [Tue Aug 18 12:54:37.891380 2026] [security2:error] [pid 67073:tid 67181] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/iko.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dgACFGk"] [Tue Aug 18 12:54:37.934023 2026] [security2:error] [pid 67073:tid 67232] [client 20.65.98.162:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/admin.php"] [unique_id "aoSAPfcmepr5_nHgLbM5dwAAAi8"] [Tue Aug 18 12:54:37.936181 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:28499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fpwch.php"] [unique_id "aoSAPfcmepr5_nHgLbM5eAAAAmE"] [Tue Aug 18 12:54:38.046366 2026] [security2:error] [pid 67073:tid 67247] [client 52.139.47.57:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/33.php"] [unique_id "aoSAPvcmepr5_nHgLbM5fQAAAj4"] [Tue Aug 18 12:54:38.055854 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/moon.php"] [unique_id "aoSAPvcmepr5_nHgLbM5fgAAAo4"] [Tue Aug 18 12:54:38.131906 2026] [security2:error] [pid 67073:tid 67284] [client 158.158.74.177:20527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/mah/function.php"] [unique_id "aoSAPvcmepr5_nHgLbM5gQAAAmM"] [Tue Aug 18 12:54:38.133522 2026] [security2:error] [pid 67073:tid 67277] [client 20.151.109.219:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kt.php"] [unique_id "aoSAPvcmepr5_nHgLbM5ggAAAlw"] [Tue Aug 18 12:54:38.172957 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:61025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAPtO5rbWdOArH04KA6gAAAWY"] [Tue Aug 18 12:54:38.180886 2026] [security2:error] [pid 67073:tid 67286] [client 20.48.236.86:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/xx.php"] [unique_id "aoSAPvcmepr5_nHgLbM5gwAAAmU"] [Tue Aug 18 12:54:38.268908 2026] [security2:error] [pid 66623:tid 66839] [client 52.238.210.254:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAPtO5rbWdOArH04KA6wAAAVM"] [Tue Aug 18 12:54:38.270607 2026] [security2:error] [pid 67073:tid 67250] [client 20.104.100.201:21463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSAPvcmepr5_nHgLbM5hAAAAkE"] [Tue Aug 18 12:54:38.285825 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:38.286284 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:38.373493 2026] [security2:error] [pid 67073:tid 67097] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/raw.php"] [unique_id "aoSAPvcmepr5_nHgLbM5igACjBU"] [Tue Aug 18 12:54:38.440383 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAPvcmepr5_nHgLbM5iwAAAkg"] [Tue Aug 18 12:54:38.496453 2026] [security2:error] [pid 67073:tid 67298] [client 74.248.136.165:1149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xa.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jAAAAnE"] [Tue Aug 18 12:54:38.515148 2026] [security2:error] [pid 67073:tid 67236] [client 68.155.154.236:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jQAAAjM"] [Tue Aug 18 12:54:38.517543 2026] [security2:error] [pid 67073:tid 67256] [client 135.225.75.187:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wpver.php"] [unique_id "aoSAPvcmepr5_nHgLbM5jwAAAkc"] [Tue Aug 18 12:54:38.556591 2026] [security2:error] [pid 66623:tid 66785] [client 20.163.43.14:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/cache.php"] [unique_id "aoSAPtO5rbWdOArH04KA7AAAAR0"] [Tue Aug 18 12:54:38.561538 2026] [security2:error] [pid 67073:tid 67081] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/05.php"] [unique_id "aoSAPvcmepr5_nHgLbM5kAACVwU"] [Tue Aug 18 12:54:38.565232 2026] [autoindex:error] [pid 67073:tid 67237] [client 172.202.39.151:50206] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:38.664234 2026] [security2:error] [pid 67073:tid 67283] [client 52.139.47.57:16813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/az.php"] [unique_id "aoSAPvcmepr5_nHgLbM5kwAAAmI"] [Tue Aug 18 12:54:38.672840 2026] [security2:error] [pid 66623:tid 66772] [client 20.118.172.148:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAPtO5rbWdOArH04KA7wAAARA"] [Tue Aug 18 12:54:38.675814 2026] [security2:error] [pid 67073:tid 67223] [client 20.104.85.180:7245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/0x.php"] [unique_id "aoSAPvcmepr5_nHgLbM5lAAAAiY"] [Tue Aug 18 12:54:38.715918 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:24370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/abcd.php"] [unique_id "aoSAPvcmepr5_nHgLbM5lQAAAj0"] [Tue Aug 18 12:54:38.843364 2026] [ssl:error] [pid 67073:tid 67212] [client 3.233.59.216:41770] AH02032: Hostname srv254.prodns.com.br (default host as no SNI was provided) and hostname www.renatawelinski.com.br provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 12:54:38.847510 2026] [security2:error] [pid 66623:tid 66878] [client 20.171.51.14:45429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ri.php"] [unique_id "aoSAPtO5rbWdOArH04KA8gAAAXo"] [Tue Aug 18 12:54:38.848364 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/gecko.php"] [unique_id "aoSAPtO5rbWdOArH04KA8wAAAUQ"] [Tue Aug 18 12:54:38.902889 2026] [security2:error] [pid 67073:tid 67309] [client 172.182.200.96:14184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAPvcmepr5_nHgLbM5nAAAAnw"] [Tue Aug 18 12:54:38.907434 2026] [security2:error] [pid 67073:tid 67305] [client 20.205.121.237:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tmp/index.php"] [unique_id "aoSAPvcmepr5_nHgLbM5nQAAAng"] [Tue Aug 18 12:54:39.017787 2026] [security2:error] [pid 67073:tid 67326] [client 20.251.48.93:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAP_cmepr5_nHgLbM5oAAAAo0"] [Tue Aug 18 12:54:39.042877 2026] [security2:error] [pid 67073:tid 67206] [client 172.182.200.96:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAP_cmepr5_nHgLbM5ogAAAhU"] [Tue Aug 18 12:54:39.055539 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:54198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/server.php"] [unique_id "aoSAP9O5rbWdOArH04KA9QAAARk"] [Tue Aug 18 12:54:39.075847 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.100.201:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/output.php"] [unique_id "aoSAP_cmepr5_nHgLbM5pAAAAks"] [Tue Aug 18 12:54:39.103495 2026] [autoindex:error] [pid 67073:tid 67332] [client 172.202.39.151:41871] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:39.116344 2026] [security2:error] [pid 67073:tid 67152] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/public/hi.php"] [unique_id "aoSAP_cmepr5_nHgLbM5pgAChUw"] [Tue Aug 18 12:54:39.141856 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.169.31:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAP_cmepr5_nHgLbM5qAAAAkw"] [Tue Aug 18 12:54:39.184859 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:39.185119 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:39.230792 2026] [security2:error] [pid 66623:tid 66860] [client 52.173.121.69:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAP9O5rbWdOArH04KA-AAAAWg"] [Tue Aug 18 12:54:39.320440 2026] [security2:error] [pid 67073:tid 67136] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/get.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rAACHTw"] [Tue Aug 18 12:54:39.353163 2026] [security2:error] [pid 66623:tid 66845] [client 192.141.172.134:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAP9O5rbWdOArH04KA-gAAAVk"] [Tue Aug 18 12:54:39.353305 2026] [security2:error] [pid 66623:tid 66845] [client 192.141.172.134:54486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAP9O5rbWdOArH04KA-gAAAVk"] [Tue Aug 18 12:54:39.357950 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:63901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rQAAAjE"] [Tue Aug 18 12:54:39.402269 2026] [security2:error] [pid 66623:tid 66682] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/install.php"] [unique_id "aoSAP9O5rbWdOArH04KA_QABSy0"] [Tue Aug 18 12:54:39.406830 2026] [security2:error] [pid 67073:tid 67281] [client 20.104.100.201:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/tiny2.php"] [unique_id "aoSAP_cmepr5_nHgLbM5rgAAAmA"] [Tue Aug 18 12:54:39.407761 2026] [security2:error] [pid 66623:tid 66815] [client 20.51.153.15:9175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pu.php"] [unique_id "aoSAP9O5rbWdOArH04KA_gAAATs"] [Tue Aug 18 12:54:39.461750 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.200.96:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAP9O5rbWdOArH04KA_wAAASM"] [Tue Aug 18 12:54:39.486480 2026] [security2:error] [pid 67073:tid 67215] [client 20.118.172.148:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/htaccess.php"] [unique_id "aoSAP_cmepr5_nHgLbM5sQAAAh4"] [Tue Aug 18 12:54:39.500645 2026] [security2:error] [pid 67073:tid 67315] [client 20.151.109.219:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ww.php"] [unique_id "aoSAP_cmepr5_nHgLbM5sgAAAoI"] [Tue Aug 18 12:54:39.509214 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:50206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAP_cmepr5_nHgLbM5swAAAn8"] [Tue Aug 18 12:54:39.522887 2026] [security2:error] [pid 67073:tid 67104] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rpk.php"] [unique_id "aoSAP_cmepr5_nHgLbM5tAACgRw"] [Tue Aug 18 12:54:39.585436 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:41871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAP_cmepr5_nHgLbM5tQAAAlA"] [Tue Aug 18 12:54:39.658154 2026] [security2:error] [pid 66623:tid 66854] [client 40.85.222.29:26146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAP9O5rbWdOArH04KBAgAAAWI"] [Tue Aug 18 12:54:39.663702 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAP9O5rbWdOArH04KBAwAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:39.694773 2026] [security2:error] [pid 67073:tid 67276] [client 114.119.155.69:43983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.viacentroveiculos.com.br"] [uri "/photo-resize/2026/970771/gb-ab3e66a.jpeg/0"] [unique_id "aoSAP_cmepr5_nHgLbM5uAAAAls"], referer: https://www.viacentroveiculos.com.br/veiculo/970771/i30-2-0-16v-145cv-5p-aut [Tue Aug 18 12:54:39.713829 2026] [security2:error] [pid 67073:tid 67085] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAP_cmepr5_nHgLbM5uQACKgk"] [Tue Aug 18 12:54:39.714307 2026] [security2:error] [pid 66623:tid 66773] [client 20.51.153.15:9156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ry.php"] [unique_id "aoSAP9O5rbWdOArH04KBBAAAARE"] [Tue Aug 18 12:54:39.731997 2026] [security2:error] [pid 66623:tid 66646] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAP9O5rbWdOArH04KBBQABUQk"] [Tue Aug 18 12:54:39.757080 2026] [security2:error] [pid 66623:tid 66779] [client 68.155.155.199:7340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSAP9O5rbWdOArH04KBBgAAARc"] [Tue Aug 18 12:54:39.780004 2026] [security2:error] [pid 67073:tid 67235] [client 194.36.25.35:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.25.36.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hawaieducacional.com.br"] [uri "/wp-login.php"] [unique_id "aoSAPfcmepr5_nHgLbM5cAAAAjI"] [Tue Aug 18 12:54:39.886115 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.154.236:64517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAP9O5rbWdOArH04KBCAAAAVY"] [Tue Aug 18 12:54:39.902629 2026] [security2:error] [pid 67073:tid 67290] [client 52.139.47.57:19601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/sx.php"] [unique_id "aoSAP_cmepr5_nHgLbM5vgAAAmk"] [Tue Aug 18 12:54:39.920315 2026] [security2:error] [pid 66623:tid 66794] [client 20.171.51.14:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/99.php"] [unique_id "aoSAP9O5rbWdOArH04KBCQAAASY"] [Tue Aug 18 12:54:39.934022 2026] [security2:error] [pid 67073:tid 67094] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/mga.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wAACZBI"] [Tue Aug 18 12:54:39.988284 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wwAAAic"] [Tue Aug 18 12:54:39.988387 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:2899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAP_cmepr5_nHgLbM5wwAAAic"] [Tue Aug 18 12:54:40.011510 2026] [security2:error] [pid 66623:tid 66843] [client 5.31.227.224:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBCwAAAVc"] [Tue Aug 18 12:54:40.011599 2026] [security2:error] [pid 66623:tid 66843] [client 5.31.227.224:59043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBCwAAAVc"] [Tue Aug 18 12:54:40.015630 2026] [security2:error] [pid 67073:tid 67328] [client 52.173.121.69:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAQPcmepr5_nHgLbM5xQAAAo8"] [Tue Aug 18 12:54:40.036458 2026] [security2:error] [pid 66623:tid 66847] [client 103.184.169.37:41391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBDAAAAVs"] [Tue Aug 18 12:54:40.036540 2026] [security2:error] [pid 66623:tid 66847] [client 103.184.169.37:41391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBDAAAAVs"] [Tue Aug 18 12:54:40.063016 2026] [security2:error] [pid 66623:tid 66678] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/iqps3ldefault.php"] [unique_id "aoSAQNO5rbWdOArH04KBDQABKyk"] [Tue Aug 18 12:54:40.098049 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.136.165:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/avim.php"] [unique_id "aoSAQNO5rbWdOArH04KBDgAAAW0"] [Tue Aug 18 12:54:40.109821 2026] [security2:error] [pid 66623:tid 66800] [client 20.104.85.180:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/zxz.php"] [unique_id "aoSAQNO5rbWdOArH04KBDwAAASw"] [Tue Aug 18 12:54:40.123832 2026] [security2:error] [pid 67073:tid 67166] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/fs.php"] [unique_id "aoSAQPcmepr5_nHgLbM5ywACKFo"] [Tue Aug 18 12:54:40.219127 2026] [security2:error] [pid 66623:tid 66790] [client 158.158.74.177:9898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/filter.php"] [unique_id "aoSAQNO5rbWdOArH04KBEQAAASI"] [Tue Aug 18 12:54:40.235149 2026] [security2:error] [pid 67073:tid 67106] [remote 179.64.21.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.21.64.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM50AACJR4"] [Tue Aug 18 12:54:40.235293 2026] [security2:error] [pid 67073:tid 67222] [client 179.64.21.92:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM50AACJR4"] [Tue Aug 18 12:54:40.258922 2026] [security2:error] [pid 66623:tid 66862] [client 86.120.159.145:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBEgAAAWo"] [Tue Aug 18 12:54:40.259016 2026] [security2:error] [pid 66623:tid 66862] [client 86.120.159.145:3977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBEgAAAWo"] [Tue Aug 18 12:54:40.314464 2026] [security2:error] [pid 66623:tid 66876] [client 4.223.164.152:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/blurbs.php"] [unique_id "aoSAQNO5rbWdOArH04KBEwAAAXg"] [Tue Aug 18 12:54:40.318411 2026] [security2:error] [pid 67073:tid 67151] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAQPcmepr5_nHgLbM50gACdEs"] [Tue Aug 18 12:54:40.328889 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mo.php"] [unique_id "aoSAQPcmepr5_nHgLbM50wAAAmI"] [Tue Aug 18 12:54:40.350086 2026] [security2:error] [pid 67073:tid 67223] [client 3.79.134.69:19554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSAQPcmepr5_nHgLbM51AAAAiY"], referer: http://www.webeb.com.br [Tue Aug 18 12:54:40.389233 2026] [security2:error] [pid 66623:tid 66697] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/item.php"] [unique_id "aoSAQNO5rbWdOArH04KBFQABczw"] [Tue Aug 18 12:54:40.472984 2026] [security2:error] [pid 66623:tid 66861] [client 52.139.47.57:16789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/tfm.php"] [unique_id "aoSAQNO5rbWdOArH04KBFgAAAWk"] [Tue Aug 18 12:54:40.478217 2026] [security2:error] [pid 67073:tid 67272] [client 20.91.215.254:20551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/kj.php"] [unique_id "aoSAQPcmepr5_nHgLbM51gAAAlc"] [Tue Aug 18 12:54:40.479189 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:9698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAQPcmepr5_nHgLbM51wAAAiM"] [Tue Aug 18 12:54:40.505015 2026] [security2:error] [pid 67073:tid 67126] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/sadd.php"] [unique_id "aoSAQPcmepr5_nHgLbM52QACkDI"] [Tue Aug 18 12:54:40.519335 2026] [security2:error] [pid 66623:tid 66891] [client 4.232.151.198:6486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/simple.php"] [unique_id "aoSAQNO5rbWdOArH04KBFwAAAYc"] [Tue Aug 18 12:54:40.571726 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.18.37:33333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/a7.php"] [unique_id "aoSAQPcmepr5_nHgLbM53AAAAo4"] [Tue Aug 18 12:54:40.574617 2026] [security2:error] [pid 67073:tid 67207] [client 20.171.51.14:43365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tp.php"] [unique_id "aoSAQPcmepr5_nHgLbM53gAAAhY"] [Tue Aug 18 12:54:40.591323 2026] [security2:error] [pid 67073:tid 67212] [client 20.116.17.175:57608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/kj.php"] [unique_id "aoSAQPcmepr5_nHgLbM54AAAAhs"] [Tue Aug 18 12:54:40.596434 2026] [security2:error] [pid 67073:tid 67293] [client 20.51.153.15:9197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pm.php"] [unique_id "aoSAQPcmepr5_nHgLbM54QAAAmw"] [Tue Aug 18 12:54:40.609935 2026] [security2:error] [pid 67073:tid 67213] [client 20.48.236.86:11010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/uwu.php"] [unique_id "aoSAQPcmepr5_nHgLbM54gAAAhw"] [Tue Aug 18 12:54:40.668338 2026] [authz_core:error] [pid 67073:tid 67125] [remote 57.141.22.106:27906] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:40.668595 2026] [authz_core:error] [pid 67073:tid 67125] [remote 57.141.22.106:27906] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:40.694851 2026] [security2:error] [pid 66623:tid 66803] [client 114.5.214.109:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBGQAAAS8"] [Tue Aug 18 12:54:40.694981 2026] [security2:error] [pid 66623:tid 66803] [client 114.5.214.109:49798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQNO5rbWdOArH04KBGQAAAS8"] [Tue Aug 18 12:54:40.696865 2026] [security2:error] [pid 67073:tid 67186] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ex.php"] [unique_id "aoSAQPcmepr5_nHgLbM55AACGG4"] [Tue Aug 18 12:54:40.704691 2026] [security2:error] [pid 67073:tid 67326] [client 104.209.144.33:25625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/zwlsv.php"] [unique_id "aoSAQPcmepr5_nHgLbM55wAAAo0"] [Tue Aug 18 12:54:40.707668 2026] [authz_core:error] [pid 67073:tid 67157] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:40.707962 2026] [authz_core:error] [pid 67073:tid 67157] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:40.723234 2026] [security2:error] [pid 66623:tid 66732] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/jga.php"] [unique_id "aoSAQNO5rbWdOArH04KBGgABTl8"] [Tue Aug 18 12:54:40.737801 2026] [security2:error] [pid 67073:tid 67148] [remote 52.167.144.194:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memo.ind.br"] [uri "/index.php/produtos/acessorios/mangueira-de-chope"] [unique_id "aoSAQPcmepr5_nHgLbM55gACGUg"] [Tue Aug 18 12:54:40.769805 2026] [security2:error] [pid 67073:tid 67218] [client 20.118.172.148:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/images/wso.php"] [unique_id "aoSAQPcmepr5_nHgLbM56wAAAiE"] [Tue Aug 18 12:54:40.829915 2026] [security2:error] [pid 67073:tid 67280] [client 172.202.39.151:45214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ioxi-o.php"] [unique_id "aoSAQPcmepr5_nHgLbM57AAAAl8"] [Tue Aug 18 12:54:40.851111 2026] [security2:error] [pid 67073:tid 67246] [client 138.36.100.162:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM57gAAAj0"] [Tue Aug 18 12:54:40.851212 2026] [security2:error] [pid 67073:tid 67246] [client 138.36.100.162:42154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQPcmepr5_nHgLbM57gAAAj0"] [Tue Aug 18 12:54:40.860447 2026] [security2:error] [pid 67073:tid 67308] [client 20.251.48.93:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAQPcmepr5_nHgLbM57wAAAns"] [Tue Aug 18 12:54:40.886635 2026] [security2:error] [pid 67073:tid 67211] [client 20.171.51.14:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/er.php"] [unique_id "aoSAQPcmepr5_nHgLbM58QAAAho"] [Tue Aug 18 12:54:40.893304 2026] [security2:error] [pid 67073:tid 67143] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/tax.php"] [unique_id "aoSAQPcmepr5_nHgLbM58gACakM"] [Tue Aug 18 12:54:40.961321 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/100.php"] [unique_id "aoSAQPcmepr5_nHgLbM59AAAAh4"] [Tue Aug 18 12:54:41.006860 2026] [security2:error] [pid 67073:tid 67320] [client 20.42.19.40:2898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/autoload_classmap.php"] [unique_id "aoSAQfcmepr5_nHgLbM59QAAAoc"] [Tue Aug 18 12:54:41.048856 2026] [security2:error] [pid 66623:tid 66699] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/jquery.php"] [unique_id "aoSAQdO5rbWdOArH04KBHQABDj4"] [Tue Aug 18 12:54:41.079575 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/f6.php"] [unique_id "aoSAQfcmepr5_nHgLbM59wAAAjo"] [Tue Aug 18 12:54:41.136101 2026] [security2:error] [pid 66623:tid 66782] [client 20.151.109.219:17539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qr.php"] [unique_id "aoSAQdO5rbWdOArH04KBIAAAARo"] [Tue Aug 18 12:54:41.153474 2026] [security2:error] [pid 67073:tid 67149] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/X7x.php"] [unique_id "aoSAQfcmepr5_nHgLbM5-QACXEk"] [Tue Aug 18 12:54:41.205434 2026] [security2:error] [pid 66623:tid 66822] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQdO5rbWdOArH04KBHwABQkw"] [Tue Aug 18 12:54:41.216754 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:17955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAQfcmepr5_nHgLbM5-wAAAlM"] [Tue Aug 18 12:54:41.269063 2026] [security2:error] [pid 67073:tid 67311] [client 172.182.200.96:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAQfcmepr5_nHgLbM5_gAAAn4"] [Tue Aug 18 12:54:41.301564 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSAQfcmepr5_nHgLbM5_wAAAkE"] [Tue Aug 18 12:54:41.375374 2026] [security2:error] [pid 66623:tid 66671] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/k.php"] [unique_id "aoSAQdO5rbWdOArH04KBIQABdiI"] [Tue Aug 18 12:54:41.387758 2026] [security2:error] [pid 67073:tid 67168] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ocxla.php"] [unique_id "aoSAQfcmepr5_nHgLbM6AgACjFw"] [Tue Aug 18 12:54:41.442711 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.18.37:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSAQfcmepr5_nHgLbM6AwAAAjE"] [Tue Aug 18 12:54:41.508912 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/www.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BAAAAkU"] [Tue Aug 18 12:54:41.511665 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.75.187:58985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/thui.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BQAAAi8"] [Tue Aug 18 12:54:41.515515 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.154.236:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAQdO5rbWdOArH04KBIgAAARQ"] [Tue Aug 18 12:54:41.518695 2026] [security2:error] [pid 67073:tid 67239] [client 20.151.109.219:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dirs.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BgAAAjY"] [Tue Aug 18 12:54:41.524986 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:9083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp.php"] [unique_id "aoSAQfcmepr5_nHgLbM6BwAAAnc"] [Tue Aug 18 12:54:41.545557 2026] [security2:error] [pid 67073:tid 67225] [client 132.196.61.152:26816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/clque.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CAAAAig"] [Tue Aug 18 12:54:41.564978 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CgAAAkc"] [Tue Aug 18 12:54:41.570924 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:18933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/sf.php"] [unique_id "aoSAQfcmepr5_nHgLbM6CwAAApI"] [Tue Aug 18 12:54:41.576319 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/index/function.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DAAAAiU"] [Tue Aug 18 12:54:41.580132 2026] [security2:error] [pid 66623:tid 66872] [client 20.171.51.14:29228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/qk.php"] [unique_id "aoSAQdO5rbWdOArH04KBIwAAAXQ"] [Tue Aug 18 12:54:41.589139 2026] [security2:error] [pid 67073:tid 67137] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/post.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DQACdD0"] [Tue Aug 18 12:54:41.604563 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAQfcmepr5_nHgLbM6DwAAAmI"] [Tue Aug 18 12:54:41.607179 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:41.607440 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:41.696411 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAQfcmepr5_nHgLbM6EQAAAlc"] [Tue Aug 18 12:54:41.707164 2026] [security2:error] [pid 66623:tid 66853] [client 52.139.47.57:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/asd.php"] [unique_id "aoSAQdO5rbWdOArH04KBJAAAAWE"] [Tue Aug 18 12:54:41.790698 2026] [security2:error] [pid 67073:tid 67212] [client 172.182.200.96:14192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAQfcmepr5_nHgLbM6EgAAAhs"] [Tue Aug 18 12:54:41.802784 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:9623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAQdO5rbWdOArH04KBJwAAARw"] [Tue Aug 18 12:54:41.885779 2026] [security2:error] [pid 66623:tid 66772] [client 74.248.136.165:29417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/myfile.php"] [unique_id "aoSAQdO5rbWdOArH04KBKAAAARA"] [Tue Aug 18 12:54:41.911383 2026] [security2:error] [pid 67073:tid 67180] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/nhr.php"] [unique_id "aoSAQfcmepr5_nHgLbM6FgACHGg"] [Tue Aug 18 12:54:42.075022 2026] [security2:error] [pid 67073:tid 67287] [client 52.238.210.254:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HAAAAmY"] [Tue Aug 18 12:54:42.097818 2026] [security2:error] [pid 67073:tid 67201] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HgACcH0"] [Tue Aug 18 12:54:42.114273 2026] [security2:error] [pid 67073:tid 67275] [client 52.173.121.69:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAQvcmepr5_nHgLbM6HwAAAlo"] [Tue Aug 18 12:54:42.132636 2026] [security2:error] [pid 67073:tid 67246] [client 132.196.61.152:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IAAAAj0"] [Tue Aug 18 12:54:42.156875 2026] [security2:error] [pid 67073:tid 67308] [client 20.48.236.86:10421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/signon.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IQAAAns"] [Tue Aug 18 12:54:42.164125 2026] [security2:error] [pid 67073:tid 67321] [client 74.248.18.37:54196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/shell.php"] [unique_id "aoSAQvcmepr5_nHgLbM6IgAAAog"] [Tue Aug 18 12:54:42.192750 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAQvcmepr5_nHgLbM6JgAAAh0"] [Tue Aug 18 12:54:42.214546 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:42.214992 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:42.227648 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:29226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAQvcmepr5_nHgLbM6KQAAAlE"] [Tue Aug 18 12:54:42.248314 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.155.199:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/edit.php"] [unique_id "aoSAQvcmepr5_nHgLbM6KwAAApE"] [Tue Aug 18 12:54:42.257055 2026] [security2:error] [pid 67073:tid 67221] [client 114.119.137.28:40123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "monroviaexport.com.br"] [uri "/2022/12/30/trend-single-wirklich-kostenlos-musik"] [unique_id "aoSAQvcmepr5_nHgLbM6LAAAAiQ"], referer: https://www.sikuraservizi.it/2022/12/29/singles-rheinland-pfalz-gruppenticket [Tue Aug 18 12:54:42.269469 2026] [security2:error] [pid 67073:tid 67245] [client 197.184.64.235:41919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LQAAAjw"] [Tue Aug 18 12:54:42.269571 2026] [security2:error] [pid 67073:tid 67245] [client 197.184.64.235:41919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LQAAAjw"] [Tue Aug 18 12:54:42.276470 2026] [security2:error] [pid 66623:tid 66725] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/k2.php"] [unique_id "aoSAQtO5rbWdOArH04KBKgABJ1g"] [Tue Aug 18 12:54:42.316408 2026] [security2:error] [pid 67073:tid 67131] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ws79.php"] [unique_id "aoSAQvcmepr5_nHgLbM6LwACRjc"] [Tue Aug 18 12:54:42.318452 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.6.191:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/aa.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MAAAAoI"] [Tue Aug 18 12:54:42.332757 2026] [security2:error] [pid 66623:tid 66807] [client 20.65.98.162:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/biufile.php"] [unique_id "aoSAQtO5rbWdOArH04KBKwAAATM"] [Tue Aug 18 12:54:42.364218 2026] [security2:error] [pid 66623:tid 66824] [client 74.248.136.165:41200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xmy.php"] [unique_id "aoSAQtO5rbWdOArH04KBLQAAAUQ"] [Tue Aug 18 12:54:42.385453 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MQAAAk0"] [Tue Aug 18 12:54:42.445338 2026] [security2:error] [pid 67073:tid 67284] [client 20.118.172.148:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/info.php"] [unique_id "aoSAQvcmepr5_nHgLbM6MwAAAmM"] [Tue Aug 18 12:54:42.481571 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:24678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/input.php"] [unique_id "aoSAQvcmepr5_nHgLbM6NAAAAok"] [Tue Aug 18 12:54:42.535282 2026] [security2:error] [pid 67073:tid 67090] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/rtx.php"] [unique_id "aoSAQvcmepr5_nHgLbM6NQACUw4"] [Tue Aug 18 12:54:42.551469 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAQtO5rbWdOArH04KBMAAAAUY"] [Tue Aug 18 12:54:42.647121 2026] [security2:error] [pid 66623:tid 66809] [client 149.34.210.157:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAQtO5rbWdOArH04KBMQAAATU"] [Tue Aug 18 12:54:42.668347 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.133.44:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/aksinet.php"] [unique_id "aoSAQvcmepr5_nHgLbM6OQAAAh8"] [Tue Aug 18 12:54:42.707886 2026] [security2:error] [pid 66623:tid 66810] [client 20.42.19.40:2750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/hosty.php"] [unique_id "aoSAQtO5rbWdOArH04KBMgAAATY"] [Tue Aug 18 12:54:42.753702 2026] [security2:error] [pid 67073:tid 67298] [client 20.91.215.254:20559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/languages.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PAAAAnE"] [Tue Aug 18 12:54:42.767085 2026] [security2:error] [pid 67073:tid 67325] [client 20.104.100.201:58489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wpxml.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PQAAAow"] [Tue Aug 18 12:54:42.797413 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/o.php"] [unique_id "aoSAQvcmepr5_nHgLbM6PgAAAjA"] [Tue Aug 18 12:54:42.804624 2026] [security2:error] [pid 67073:tid 67224] [client 114.119.159.210:47623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.grupofoco.com.br"] [uri "/focotalentos"] [unique_id "aoSAQvcmepr5_nHgLbM6PwAAAic"], referer: http://www.grupofoco.com.br/focotalentos?C=D%3BO%3DA [Tue Aug 18 12:54:42.897207 2026] [security2:error] [pid 67073:tid 67254] [client 20.116.17.175:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/png.php"] [unique_id "aoSAQvcmepr5_nHgLbM6QQAAAkU"] [Tue Aug 18 12:54:42.900202 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:42894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAQtO5rbWdOArH04KBNwAAARU"] [Tue Aug 18 12:54:42.937621 2026] [security2:error] [pid 66623:tid 66880] [client 213.35.127.232:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAQtO5rbWdOArH04KBOAAAAXw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:42.940924 2026] [security2:error] [pid 66623:tid 66809] [client 149.34.210.157:52463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAQtO5rbWdOArH04KBMQAAATU"] [Tue Aug 18 12:54:43.005775 2026] [security2:error] [pid 67073:tid 67228] [client 20.171.51.14:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fs.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6RgAAAis"] [Tue Aug 18 12:54:43.120420 2026] [security2:error] [pid 67073:tid 67098] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/end.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SAACIxY"] [Tue Aug 18 12:54:43.121177 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:43.121444 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:43.130445 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.155.199:5735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/w.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SQAAAlc"] [Tue Aug 18 12:54:43.136864 2026] [security2:error] [pid 66623:tid 66864] [client 114.119.158.167:62867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.paranavans.com.br"] [uri "/veiculo/205997/8-150-e-delivery-2p-bau-2009"] [unique_id "aoSAQ9O5rbWdOArH04KBOQAAAWw"], referer: https://www.paranavans.com.br [Tue Aug 18 12:54:43.145854 2026] [security2:error] [pid 66623:tid 66852] [client 20.250.13.23:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/php8.php"] [unique_id "aoSAQ9O5rbWdOArH04KBOgAAAWA"] [Tue Aug 18 12:54:43.150256 2026] [security2:error] [pid 66623:tid 66860] [client 172.202.39.151:30465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/abc.php"] [unique_id "aoSAQ9O5rbWdOArH04KBOwAAAWg"] [Tue Aug 18 12:54:43.174850 2026] [security2:error] [pid 66623:tid 66755] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/license.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPAABUnY"] [Tue Aug 18 12:54:43.185369 2026] [security2:error] [pid 67073:tid 67263] [client 20.163.43.14:3194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/bb.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6SgAAAk4"] [Tue Aug 18 12:54:43.248840 2026] [security2:error] [pid 67073:tid 67327] [client 20.251.48.93:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/yj09.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6TgAAAo4"] [Tue Aug 18 12:54:43.311614 2026] [security2:error] [pid 67073:tid 67127] [remote 135.225.75.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savanasolucoesfinanceiras.com.br"] [uri "/ae.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UQACfDM"] [Tue Aug 18 12:54:43.334524 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.74.177:9863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/jquery.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UgAAAiY"] [Tue Aug 18 12:54:43.422092 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:43.422361 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:43.435390 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6VQAAAhQ"] [Tue Aug 18 12:54:43.477851 2026] [security2:error] [pid 67073:tid 67192] [remote 69.165.68.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.68.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metodomsd.sttudio.com.br"] [uri "/index.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6UAAChHQ"], referer: https://metodomsd.sttudio.com.br [Tue Aug 18 12:54:43.500420 2026] [security2:error] [pid 66623:tid 66802] [client 20.51.153.15:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dr.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPQAAAS4"] [Tue Aug 18 12:54:43.501776 2026] [security2:error] [pid 66623:tid 66712] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/link.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPgABVEs"] [Tue Aug 18 12:54:43.572850 2026] [security2:error] [pid 67073:tid 67287] [client 20.163.43.14:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WAAAAmY"] [Tue Aug 18 12:54:43.634392 2026] [security2:error] [pid 67073:tid 67285] [client 4.232.151.198:25814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/st.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WQAAAmQ"] [Tue Aug 18 12:54:43.639798 2026] [security2:error] [pid 67073:tid 67318] [client 172.182.200.96:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6WgAAAoU"] [Tue Aug 18 12:54:43.828647 2026] [security2:error] [pid 66623:tid 66655] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/lite.php"] [unique_id "aoSAQ9O5rbWdOArH04KBPwABgxI"] [Tue Aug 18 12:54:43.869241 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ts.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6bgAAAmE"] [Tue Aug 18 12:54:43.888149 2026] [security2:error] [pid 67073:tid 67330] [client 20.116.17.175:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ab.php"] [unique_id "aoSAQ_cmepr5_nHgLbM6bwAAApE"] [Tue Aug 18 12:54:44.025052 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:44.025315 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:44.025322 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.75.187:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tmpls.php"] [unique_id "aoSARPcmepr5_nHgLbM6cQAAAj4"] [Tue Aug 18 12:54:44.041274 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSARPcmepr5_nHgLbM6cgAAAkA"] [Tue Aug 18 12:54:44.072671 2026] [security2:error] [pid 67073:tid 67276] [client 172.182.200.96:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSARPcmepr5_nHgLbM6dAAAAls"] [Tue Aug 18 12:54:44.079385 2026] [security2:error] [pid 67073:tid 67277] [client 20.171.51.14:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rb.php"] [unique_id "aoSARPcmepr5_nHgLbM6dQAAAlw"] [Tue Aug 18 12:54:44.109584 2026] [security2:error] [pid 67073:tid 67280] [client 20.104.100.201:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSARPcmepr5_nHgLbM6dwAAAl8"] [Tue Aug 18 12:54:44.161656 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.136.165:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xda.php"] [unique_id "aoSARPcmepr5_nHgLbM6eAAAAmU"] [Tue Aug 18 12:54:44.220068 2026] [security2:error] [pid 67073:tid 67295] [client 157.20.138.62:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6egAAAm4"] [Tue Aug 18 12:54:44.220209 2026] [security2:error] [pid 67073:tid 67295] [client 157.20.138.62:54881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6egAAAm4"] [Tue Aug 18 12:54:44.285421 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.56.190:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wy.php"] [unique_id "aoSARPcmepr5_nHgLbM6ewAAAi4"] [Tue Aug 18 12:54:44.297820 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/12.php"] [unique_id "aoSARPcmepr5_nHgLbM6fAAAAh8"] [Tue Aug 18 12:54:44.324817 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:44.325075 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:44.372407 2026] [security2:error] [pid 66623:tid 66873] [client 20.42.19.40:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/test1.php"] [unique_id "aoSARNO5rbWdOArH04KBQQAAAXU"] [Tue Aug 18 12:54:44.407837 2026] [security2:error] [pid 67073:tid 67233] [client 132.196.61.152:60999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/img.php"] [unique_id "aoSARPcmepr5_nHgLbM6gQAAAjA"] [Tue Aug 18 12:54:44.550118 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:7553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/profile.php"] [unique_id "aoSARPcmepr5_nHgLbM6iAAAAkg"] [Tue Aug 18 12:54:44.566932 2026] [security2:error] [pid 66623:tid 66863] [client 196.12.128.158:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSARNO5rbWdOArH04KBQwAAAWs"] [Tue Aug 18 12:54:44.567039 2026] [security2:error] [pid 66623:tid 66863] [client 196.12.128.158:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSARNO5rbWdOArH04KBQwAAAWs"] [Tue Aug 18 12:54:44.627182 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:44.627447 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:44.640000 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.136.165:34623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zz.php"] [unique_id "aoSARPcmepr5_nHgLbM6iwAAAis"] [Tue Aug 18 12:54:44.678374 2026] [security2:error] [pid 67073:tid 67290] [client 20.250.13.23:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSARPcmepr5_nHgLbM6jQAAAmk"] [Tue Aug 18 12:54:44.707802 2026] [security2:error] [pid 66623:tid 66731] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/load.php"] [unique_id "aoSARNO5rbWdOArH04KBRQABLF4"] [Tue Aug 18 12:54:44.745959 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.155.199:19044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file.php"] [unique_id "aoSARPcmepr5_nHgLbM6mwAAAl0"] [Tue Aug 18 12:54:44.767071 2026] [security2:error] [pid 67073:tid 67222] [client 20.100.169.31:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSARPcmepr5_nHgLbM6nAAAAiU"] [Tue Aug 18 12:54:44.809421 2026] [security2:error] [pid 67073:tid 67328] [client 157.51.166.53:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6nQAAAo8"] [Tue Aug 18 12:54:44.813017 2026] [security2:error] [pid 67073:tid 67217] [client 40.85.222.29:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSARPcmepr5_nHgLbM6ngAAAiA"] [Tue Aug 18 12:54:44.813168 2026] [security2:error] [pid 67073:tid 67328] [client 157.51.166.53:55141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARPcmepr5_nHgLbM6nQAAAo8"] [Tue Aug 18 12:54:44.829965 2026] [security2:error] [pid 67073:tid 67327] [client 52.173.121.69:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSARPcmepr5_nHgLbM6nwAAAo4"] [Tue Aug 18 12:54:44.914339 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.85.180:8070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wicked.php"] [unique_id "aoSARPcmepr5_nHgLbM6oAAAAlI"] [Tue Aug 18 12:54:44.917747 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:25799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSARPcmepr5_nHgLbM6oQAAAjQ"] [Tue Aug 18 12:54:45.034290 2026] [security2:error] [pid 66623:tid 66718] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/log.php"] [unique_id "aoSARdO5rbWdOArH04KBRgABGFE"] [Tue Aug 18 12:54:45.034760 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:8260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/sx.php"] [unique_id "aoSARdO5rbWdOArH04KBRwAAAXM"] [Tue Aug 18 12:54:45.037588 2026] [security2:error] [pid 67073:tid 67297] [client 178.153.171.161:37026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARfcmepr5_nHgLbM6vgAAAnA"] [Tue Aug 18 12:54:45.037701 2026] [security2:error] [pid 67073:tid 67297] [client 178.153.171.161:37026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARfcmepr5_nHgLbM6vgAAAnA"] [Tue Aug 18 12:54:45.050453 2026] [security2:error] [pid 67073:tid 67320] [client 213.202.253.4:52385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/filefuns.php"] [unique_id "aoSARfcmepr5_nHgLbM6vwAAAoc"], referer: www.google.com [Tue Aug 18 12:54:45.056661 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nzv.php"] [unique_id "aoSARdO5rbWdOArH04KBSAAAASE"] [Tue Aug 18 12:54:45.069001 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSARdO5rbWdOArH04KBSQAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:45.104111 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:2731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/zwso.php"] [unique_id "aoSARfcmepr5_nHgLbM6wAAAAhY"] [Tue Aug 18 12:54:45.178345 2026] [security2:error] [pid 66623:tid 66891] [client 20.226.56.190:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/f.php"] [unique_id "aoSARdO5rbWdOArH04KBSgAAAYc"] [Tue Aug 18 12:54:45.211972 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.6.191:6640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/0x.php"] [unique_id "aoSARdO5rbWdOArH04KBSwAAAVA"] [Tue Aug 18 12:54:45.252468 2026] [security2:error] [pid 66623:tid 66867] [client 20.104.85.180:8056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSARdO5rbWdOArH04KBTQAAAW8"] [Tue Aug 18 12:54:45.306250 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:21964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/akcc.php"] [unique_id "aoSARdO5rbWdOArH04KBUAAAAUk"] [Tue Aug 18 12:54:45.360345 2026] [security2:error] [pid 66623:tid 66759] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/lufix.php"] [unique_id "aoSARdO5rbWdOArH04KBUQABQHo"] [Tue Aug 18 12:54:45.369525 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:61003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/aa.php"] [unique_id "aoSARfcmepr5_nHgLbM6xAAAAmQ"] [Tue Aug 18 12:54:45.430995 2026] [authz_core:error] [pid 67073:tid 67165] [remote 57.141.22.123:64170] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:45.431290 2026] [authz_core:error] [pid 67073:tid 67165] [remote 57.141.22.123:64170] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:45.442127 2026] [security2:error] [pid 67073:tid 67246] [client 20.251.48.93:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/scxy.php"] [unique_id "aoSARfcmepr5_nHgLbM6yQAAAj0"] [Tue Aug 18 12:54:45.451397 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/Geforce.php"] [unique_id "aoSARfcmepr5_nHgLbM6ygAAAog"] [Tue Aug 18 12:54:45.455731 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.100.201:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ccou.php"] [unique_id "aoSARfcmepr5_nHgLbM6ywAAAlY"] [Tue Aug 18 12:54:45.545396 2026] [security2:error] [pid 67073:tid 67266] [client 172.182.200.96:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSARfcmepr5_nHgLbM60wAAAlE"] [Tue Aug 18 12:54:45.575836 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.6.191:6572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/zxz.php"] [unique_id "aoSARfcmepr5_nHgLbM61gAAAiQ"] [Tue Aug 18 12:54:45.605542 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/jrpga.php"] [unique_id "aoSARfcmepr5_nHgLbM62QAAAn8"] [Tue Aug 18 12:54:45.642799 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.85.180:8055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSARfcmepr5_nHgLbM62gAAAkA"] [Tue Aug 18 12:54:45.676071 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.136.165:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xa.php"] [unique_id "aoSARdO5rbWdOArH04KBUwAAAYA"] [Tue Aug 18 12:54:45.685111 2026] [security2:error] [pid 66623:tid 66762] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ly.php"] [unique_id "aoSARdO5rbWdOArH04KBVAABGn0"] [Tue Aug 18 12:54:45.714271 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:43542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSARdO5rbWdOArH04KBVQAAARs"] [Tue Aug 18 12:54:45.785668 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.100.201:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/crgio.php"] [unique_id "aoSARfcmepr5_nHgLbM63AAAAlw"] [Tue Aug 18 12:54:45.799332 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:3063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/30.php"] [unique_id "aoSARfcmepr5_nHgLbM63QAAAl8"] [Tue Aug 18 12:54:45.835327 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:45.835782 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:45.955561 2026] [security2:error] [pid 67073:tid 67311] [client 172.182.200.96:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSARfcmepr5_nHgLbM66gAAAn4"] [Tue Aug 18 12:54:45.975836 2026] [security2:error] [pid 67073:tid 67316] [client 20.250.27.191:1872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSARfcmepr5_nHgLbM66wAAAoM"] [Tue Aug 18 12:54:45.995441 2026] [security2:error] [pid 67073:tid 67264] [client 20.116.17.175:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/x1da.php"] [unique_id "aoSARfcmepr5_nHgLbM67QAAAk8"] [Tue Aug 18 12:54:46.011993 2026] [security2:error] [pid 67073:tid 67250] [client 20.104.85.180:7948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cah.php"] [unique_id "aoSARvcmepr5_nHgLbM67gAAAkE"] [Tue Aug 18 12:54:46.066387 2026] [security2:error] [pid 67073:tid 67240] [client 172.202.39.151:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-login.php"] [unique_id "aoSAQvcmepr5_nHgLbM6RQAAAjc"] [Tue Aug 18 12:54:46.104700 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSARvcmepr5_nHgLbM68wAAAoY"] [Tue Aug 18 12:54:46.131759 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:46.132018 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:46.184808 2026] [security2:error] [pid 67073:tid 67248] [client 52.238.210.254:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSARvcmepr5_nHgLbM69QAAAj8"] [Tue Aug 18 12:54:46.316955 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:25817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSARvcmepr5_nHgLbM69wAAAkc"] [Tue Aug 18 12:54:46.342670 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/coffexium.php"] [unique_id "aoSARvcmepr5_nHgLbM6-AAAApI"] [Tue Aug 18 12:54:46.351767 2026] [security2:error] [pid 67073:tid 67228] [client 132.196.61.152:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/nano.php"] [unique_id "aoSARvcmepr5_nHgLbM6-QAAAis"] [Tue Aug 18 12:54:46.564901 2026] [security2:error] [pid 66623:tid 66640] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/m.php"] [unique_id "aoSARtO5rbWdOArH04KBWwABMwM"] [Tue Aug 18 12:54:46.638381 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:50214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/about.php"] [unique_id "aoSARvcmepr5_nHgLbM6_wAAAnw"] [Tue Aug 18 12:54:46.662795 2026] [security2:error] [pid 67073:tid 67239] [client 52.173.121.69:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSARvcmepr5_nHgLbM7AAAAAjY"] [Tue Aug 18 12:54:46.670385 2026] [security2:error] [pid 66623:tid 66792] [client 160.120.140.123:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARtO5rbWdOArH04KBXgAAASQ"] [Tue Aug 18 12:54:46.670479 2026] [security2:error] [pid 66623:tid 66792] [client 160.120.140.123:56207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSARtO5rbWdOArH04KBXgAAASQ"] [Tue Aug 18 12:54:46.766049 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/fpwch.php"] [unique_id "aoSARvcmepr5_nHgLbM7BAAAAhs"] [Tue Aug 18 12:54:46.824712 2026] [security2:error] [pid 67073:tid 67320] [client 172.182.200.96:14268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSARvcmepr5_nHgLbM7JQAAAoc"] [Tue Aug 18 12:54:46.850548 2026] [security2:error] [pid 67073:tid 67317] [client 20.116.17.175:57605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mcs.php"] [unique_id "aoSARvcmepr5_nHgLbM7JgAAAoQ"] [Tue Aug 18 12:54:46.922030 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/museu/yhweq.php"] [unique_id "aoSARvcmepr5_nHgLbM7KQAAAhk"] [Tue Aug 18 12:54:46.959682 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.75.187:23923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/error1.php"] [unique_id "aoSARvcmepr5_nHgLbM7KgAAAi8"] [Tue Aug 18 12:54:46.966475 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.133.44:31783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/simple.php"] [unique_id "aoSARvcmepr5_nHgLbM7KwAAAhQ"] [Tue Aug 18 12:54:46.969863 2026] [security2:error] [pid 67073:tid 67218] [client 20.91.215.254:20579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/nw.php"] [unique_id "aoSARvcmepr5_nHgLbM7LAAAAiE"] [Tue Aug 18 12:54:47.012729 2026] [security2:error] [pid 67073:tid 67308] [client 114.119.158.251:20191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arruelasdobrasil.com.br"] [uri "/pt/galeria-de-fotos"] [unique_id "aoSAR_cmepr5_nHgLbM7LwAAAns"], referer: http://www.arruelasdobrasil.com.br/pt/galeria-de-fotos?func=detail&id=6 [Tue Aug 18 12:54:47.032758 2026] [security2:error] [pid 67073:tid 67246] [client 172.202.39.151:39997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wk/index.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MQAAAj0"] [Tue Aug 18 12:54:47.057072 2026] [security2:error] [pid 67073:tid 67304] [client 20.42.19.40:9690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MgAAAnc"] [Tue Aug 18 12:54:47.070277 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:17963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAR_cmepr5_nHgLbM7MwAAAog"] [Tue Aug 18 12:54:47.073100 2026] [security2:error] [pid 67073:tid 67271] [client 20.42.19.40:2714] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/mini"] [unique_id "aoSAR_cmepr5_nHgLbM7NAAAAlY"] [Tue Aug 18 12:54:47.079268 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAR_cmepr5_nHgLbM7NQAAAkw"] [Tue Aug 18 12:54:47.127651 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.100.201:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSAR9O5rbWdOArH04KBZgAAAVw"] [Tue Aug 18 12:54:47.176389 2026] [security2:error] [pid 67073:tid 67299] [client 40.85.222.29:25446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cubangovidros.com.br"] [uri "/images/security.php"] [unique_id "aoSAR_cmepr5_nHgLbM7NwAAAnI"] [Tue Aug 18 12:54:47.334314 2026] [security2:error] [pid 67073:tid 67276] [client 172.202.39.151:29741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PAAAAls"] [Tue Aug 18 12:54:47.334856 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:47.335124 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:47.408780 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PQAAAkI"] [Tue Aug 18 12:54:47.434644 2026] [security2:error] [pid 66623:tid 66852] [client 20.42.19.40:2737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-blog-header.php"] [unique_id "aoSAR9O5rbWdOArH04KBaQAAAWA"] [Tue Aug 18 12:54:47.464734 2026] [security2:error] [pid 66623:tid 66764] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/m57.php"] [unique_id "aoSAR9O5rbWdOArH04KBawABaH8"] [Tue Aug 18 12:54:47.476962 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:9025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/nij.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PgAAAnQ"] [Tue Aug 18 12:54:47.581887 2026] [security2:error] [pid 66623:tid 66838] [client 132.196.61.152:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/av.php"] [unique_id "aoSAR9O5rbWdOArH04KBbAAAAVI"] [Tue Aug 18 12:54:47.587360 2026] [security2:error] [pid 67073:tid 67220] [client 4.232.151.198:25829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/system.php"] [unique_id "aoSAR_cmepr5_nHgLbM7PwAAAiM"] [Tue Aug 18 12:54:47.689251 2026] [security2:error] [pid 67073:tid 67231] [client 172.182.200.96:14096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QQAAAi4"] [Tue Aug 18 12:54:47.766251 2026] [security2:error] [pid 67073:tid 67298] [client 20.42.19.40:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/about/function.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QgAAAnE"] [Tue Aug 18 12:54:47.779843 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSAR_cmepr5_nHgLbM7QwAAAjA"] [Tue Aug 18 12:54:47.790625 2026] [security2:error] [pid 66623:tid 66644] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mac.php"] [unique_id "aoSAR9O5rbWdOArH04KBbwABIwc"] [Tue Aug 18 12:54:47.820349 2026] [security2:error] [pid 67073:tid 67226] [client 74.248.18.37:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/manager.php"] [unique_id "aoSAR_cmepr5_nHgLbM7RQAAAik"] [Tue Aug 18 12:54:47.991438 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:42966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/404.php"] [unique_id "aoSAR_cmepr5_nHgLbM7SQAAAic"] [Tue Aug 18 12:54:48.012944 2026] [security2:error] [pid 66623:tid 66775] [client 20.100.169.31:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSASNO5rbWdOArH04KBeAAAARM"] [Tue Aug 18 12:54:48.035432 2026] [security2:error] [pid 67073:tid 67227] [client 20.250.13.23:14179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/222.php"] [unique_id "aoSASPcmepr5_nHgLbM7SgAAAio"] [Tue Aug 18 12:54:48.105941 2026] [security2:error] [pid 67073:tid 67263] [client 135.225.75.187:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/155.php"] [unique_id "aoSASPcmepr5_nHgLbM7SwAAAk4"] [Tue Aug 18 12:54:48.154616 2026] [security2:error] [pid 66623:tid 66821] [client 20.251.48.93:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSASNO5rbWdOArH04KBeQAAAUE"] [Tue Aug 18 12:54:48.171455 2026] [security2:error] [pid 67073:tid 67217] [client 20.42.19.40:2887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/function/function.php"] [unique_id "aoSASPcmepr5_nHgLbM7TQAAAiA"] [Tue Aug 18 12:54:48.237575 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:48.237842 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:48.371657 2026] [security2:error] [pid 66623:tid 66833] [client 20.42.19.40:9727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/edit.php"] [unique_id "aoSASNO5rbWdOArH04KBewAAAU0"] [Tue Aug 18 12:54:48.431271 2026] [security2:error] [pid 67073:tid 67237] [client 20.205.121.237:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tmpls.php"] [unique_id "aoSASPcmepr5_nHgLbM7UgAAAjQ"] [Tue Aug 18 12:54:48.450271 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.104.85.180:8026] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:48.473461 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.100.201:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/css.php"] [unique_id "aoSASPcmepr5_nHgLbM7VAAAAhU"] [Tue Aug 18 12:54:48.507332 2026] [security2:error] [pid 66623:tid 66785] [client 103.120.71.157:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASNO5rbWdOArH04KBfAAAAR0"] [Tue Aug 18 12:54:48.507444 2026] [security2:error] [pid 66623:tid 66785] [client 103.120.71.157:62594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASNO5rbWdOArH04KBfAAAAR0"] [Tue Aug 18 12:54:48.507618 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:24333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSASPcmepr5_nHgLbM7VQAAAmw"] [Tue Aug 18 12:54:48.507643 2026] [security2:error] [pid 66623:tid 66768] [client 20.42.19.40:2695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-signin.php"] [unique_id "aoSASNO5rbWdOArH04KBfQAAAQw"] [Tue Aug 18 12:54:48.590959 2026] [security2:error] [pid 67073:tid 67285] [client 52.173.121.69:47384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSASPcmepr5_nHgLbM7VwAAAmQ"] [Tue Aug 18 12:54:48.677570 2026] [security2:error] [pid 66623:tid 66656] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mah.php"] [unique_id "aoSASNO5rbWdOArH04KBgwABFhM"] [Tue Aug 18 12:54:48.794594 2026] [security2:error] [pid 67073:tid 67260] [client 20.104.85.180:8026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/system_log.php"] [unique_id "aoSASPcmepr5_nHgLbM7WwAAAks"] [Tue Aug 18 12:54:48.813043 2026] [security2:error] [pid 67073:tid 67246] [client 20.104.100.201:58475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSASPcmepr5_nHgLbM7XAAAAj0"] [Tue Aug 18 12:54:48.852023 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:6597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/www.php"] [unique_id "aoSASNO5rbWdOArH04KBhgAAASY"] [Tue Aug 18 12:54:48.906655 2026] [security2:error] [pid 66623:tid 66843] [client 20.151.109.219:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sn.php"] [unique_id "aoSASNO5rbWdOArH04KBhwAAAVc"] [Tue Aug 18 12:54:48.914737 2026] [security2:error] [pid 66623:tid 66847] [client 20.171.51.14:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/zj.php"] [unique_id "aoSASNO5rbWdOArH04KBiAAAAVs"] [Tue Aug 18 12:54:49.004828 2026] [security2:error] [pid 66623:tid 66736] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSASdO5rbWdOArH04KBiQABhmM"] [Tue Aug 18 12:54:49.007649 2026] [security2:error] [pid 66623:tid 66781] [client 20.116.17.175:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/adminner.php"] [unique_id "aoSASdO5rbWdOArH04KBigAAARk"] [Tue Aug 18 12:54:49.049165 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.56.190:23769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pu.php"] [unique_id "aoSASfcmepr5_nHgLbM7XgAAAkY"] [Tue Aug 18 12:54:49.094335 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/w.php"] [unique_id "aoSASfcmepr5_nHgLbM7XwAAAk0"] [Tue Aug 18 12:54:49.155352 2026] [security2:error] [pid 67073:tid 67289] [client 20.104.100.201:21487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/epinyins.php"] [unique_id "aoSASfcmepr5_nHgLbM7YQAAAmg"] [Tue Aug 18 12:54:49.307562 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.75.187:58042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fasx.php"] [unique_id "aoSASfcmepr5_nHgLbM7YwAAAkI"] [Tue Aug 18 12:54:49.319792 2026] [security2:error] [pid 66623:tid 66776] [client 213.35.127.232:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSASdO5rbWdOArH04KBjAAAARQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:49.334956 2026] [security2:error] [pid 66623:tid 66662] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/manager.php"] [unique_id "aoSASdO5rbWdOArH04KBjQABPBk"] [Tue Aug 18 12:54:49.426674 2026] [security2:error] [pid 66623:tid 66871] [client 20.42.19.40:9723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSASdO5rbWdOArH04KBjwAAAXM"] [Tue Aug 18 12:54:49.496083 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.61.152:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/media.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZQAAAk8"] [Tue Aug 18 12:54:49.497100 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.136.165:41202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/f6.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZgAAAos"] [Tue Aug 18 12:54:49.583244 2026] [security2:error] [pid 66623:tid 66797] [client 20.91.215.254:20563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSASdO5rbWdOArH04KBkQAAASk"] [Tue Aug 18 12:54:49.595003 2026] [security2:error] [pid 67073:tid 67240] [client 20.171.51.14:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/x.php"] [unique_id "aoSASfcmepr5_nHgLbM7ZwAAAjc"] [Tue Aug 18 12:54:49.637682 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:63076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/mah.php"] [unique_id "aoSASfcmepr5_nHgLbM7aAAAAn0"] [Tue Aug 18 12:54:49.672911 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.teodorojunior.com.br"] [uri "/images/security.php"] [unique_id "aoSASfcmepr5_nHgLbM7bgAAAjE"] [Tue Aug 18 12:54:49.711650 2026] [security2:error] [pid 67073:tid 67222] [client 197.184.64.235:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASfcmepr5_nHgLbM7cAAAAiU"] [Tue Aug 18 12:54:49.711763 2026] [security2:error] [pid 67073:tid 67222] [client 197.184.64.235:41920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASfcmepr5_nHgLbM7cAAAAiU"] [Tue Aug 18 12:54:49.745253 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSASfcmepr5_nHgLbM7cwAAAnY"] [Tue Aug 18 12:54:49.767107 2026] [security2:error] [pid 67073:tid 67250] [client 4.223.164.152:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ccc.php"] [unique_id "aoSASfcmepr5_nHgLbM7dAAAAkE"] [Tue Aug 18 12:54:49.851828 2026] [security2:error] [pid 67073:tid 67261] [client 116.179.37.120:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSASfcmepr5_nHgLbM7dgAAAkw"], referer: https://plenitude.com.br/como-conquistar-felicidade-em-sua-vida/ [Tue Aug 18 12:54:49.885926 2026] [security2:error] [pid 67073:tid 67146] [remote 192.250.235.185:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSARvcmepr5_nHgLbM7KAACXkY"] [Tue Aug 18 12:54:49.923780 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.136.165:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mcs.php"] [unique_id "aoSASfcmepr5_nHgLbM7dwAAAis"] [Tue Aug 18 12:54:49.936781 2026] [security2:error] [pid 67073:tid 67300] [client 20.251.48.93:35110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSASfcmepr5_nHgLbM7eAAAAnM"] [Tue Aug 18 12:54:49.998987 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.116:54256] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:49.999239 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.116:54256] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:50.047122 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSASvcmepr5_nHgLbM7fQAAAl0"] [Tue Aug 18 12:54:50.109642 2026] [security2:error] [pid 66623:tid 66780] [client 192.141.172.134:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBlAAAARg"] [Tue Aug 18 12:54:50.109812 2026] [security2:error] [pid 66623:tid 66780] [client 192.141.172.134:55322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBlAAAARg"] [Tue Aug 18 12:54:50.183536 2026] [autoindex:error] [pid 67073:tid 67272] [client 20.104.85.180:8010] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:50.214390 2026] [security2:error] [pid 66623:tid 66689] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mar.php"] [unique_id "aoSAStO5rbWdOArH04KBlgABdjQ"] [Tue Aug 18 12:54:50.278755 2026] [security2:error] [pid 67073:tid 67257] [client 52.173.121.69:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSASvcmepr5_nHgLbM7mQAAAkg"] [Tue Aug 18 12:54:50.310428 2026] [security2:error] [pid 66623:tid 66862] [client 4.232.151.198:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/system_log.php"] [unique_id "aoSAStO5rbWdOArH04KBmAAAAWo"] [Tue Aug 18 12:54:50.345363 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:17964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSASvcmepr5_nHgLbM7mgAAAmk"] [Tue Aug 18 12:54:50.376011 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:9610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/classwithtostring.php"] [unique_id "aoSAStO5rbWdOArH04KBmQAAAUo"] [Tue Aug 18 12:54:50.401574 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ry.php"] [unique_id "aoSAStO5rbWdOArH04KBmgAAAWY"] [Tue Aug 18 12:54:50.407864 2026] [security2:error] [pid 67073:tid 67227] [client 138.36.100.162:41861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASvcmepr5_nHgLbM7mwAAAio"] [Tue Aug 18 12:54:50.408015 2026] [security2:error] [pid 67073:tid 67227] [client 138.36.100.162:41861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSASvcmepr5_nHgLbM7mwAAAio"] [Tue Aug 18 12:54:50.452731 2026] [security2:error] [pid 67073:tid 67292] [client 20.104.85.180:43579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/k.php"] [unique_id "aoSASvcmepr5_nHgLbM7nAAAAms"] [Tue Aug 18 12:54:50.491122 2026] [authz_core:error] [pid 67073:tid 67198] [remote 57.141.22.34:38912] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:50.491557 2026] [authz_core:error] [pid 67073:tid 67198] [remote 57.141.22.34:38912] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:50.513355 2026] [security2:error] [pid 66623:tid 66798] [client 103.184.169.37:41431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBmwAAASo"] [Tue Aug 18 12:54:50.513478 2026] [security2:error] [pid 66623:tid 66798] [client 103.184.169.37:41431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBmwAAASo"] [Tue Aug 18 12:54:50.540523 2026] [security2:error] [pid 66623:tid 66658] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/maxro.php"] [unique_id "aoSAStO5rbWdOArH04KBnAABORU"] [Tue Aug 18 12:54:50.554500 2026] [security2:error] [pid 67073:tid 67293] [client 20.163.43.14:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSASvcmepr5_nHgLbM7oAAAAmw"] [Tue Aug 18 12:54:50.557280 2026] [security2:error] [pid 66623:tid 66783] [client 20.205.121.237:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/tool.php"] [unique_id "aoSAStO5rbWdOArH04KBnQAAARs"] [Tue Aug 18 12:54:50.596688 2026] [security2:error] [pid 66623:tid 66882] [client 52.238.210.254:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/xmr.php"] [unique_id "aoSAStO5rbWdOArH04KBngAAAX4"] [Tue Aug 18 12:54:50.724176 2026] [security2:error] [pid 67073:tid 67277] [client 172.182.200.96:13949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/rezor.php"] [unique_id "aoSASvcmepr5_nHgLbM7qAAAAlw"] [Tue Aug 18 12:54:50.748494 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.6.191:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wicked.php"] [unique_id "aoSASvcmepr5_nHgLbM7qQAAAmE"] [Tue Aug 18 12:54:50.785606 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.56.190:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pm.php"] [unique_id "aoSAStO5rbWdOArH04KBoQAAASc"] [Tue Aug 18 12:54:50.787445 2026] [security2:error] [pid 66623:tid 66825] [client 52.139.47.57:27942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ws.php7"] [unique_id "aoSAStO5rbWdOArH04KBogAAAUU"] [Tue Aug 18 12:54:50.797202 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.133.44:35822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/berax.php"] [unique_id "aoSASvcmepr5_nHgLbM7qgAAAhs"] [Tue Aug 18 12:54:50.803548 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.100.201:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/load.php"] [unique_id "aoSAStO5rbWdOArH04KBowAAATM"] [Tue Aug 18 12:54:50.806695 2026] [security2:error] [pid 66623:tid 66824] [client 20.171.51.14:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yn.php"] [unique_id "aoSAStO5rbWdOArH04KBpQAAAUQ"] [Tue Aug 18 12:54:50.866387 2026] [security2:error] [pid 66623:tid 66681] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mds.php"] [unique_id "aoSAStO5rbWdOArH04KBpwABOiw"] [Tue Aug 18 12:54:50.888895 2026] [security2:error] [pid 66623:tid 66859] [client 20.151.109.219:12872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/43.php"] [unique_id "aoSAStO5rbWdOArH04KBqAAAAWc"] [Tue Aug 18 12:54:50.893515 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:24341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSASvcmepr5_nHgLbM7rAAAAlo"] [Tue Aug 18 12:54:50.923315 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.18.37:48252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/w1.php"] [unique_id "aoSASvcmepr5_nHgLbM7rQAAAoU"] [Tue Aug 18 12:54:50.951397 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:50.951671 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:50.986540 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:9418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mcs.php"] [unique_id "aoSASvcmepr5_nHgLbM7uwAAAn8"] [Tue Aug 18 12:54:51.006541 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vAAAAj4"] [Tue Aug 18 12:54:51.009785 2026] [security2:error] [pid 67073:tid 67289] [client 20.163.43.14:3152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vQAAAmg"] [Tue Aug 18 12:54:51.078732 2026] [security2:error] [pid 67073:tid 67283] [client 104.209.144.33:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/nwwha.php"] [unique_id "aoSAS_cmepr5_nHgLbM7vwAAAmI"] [Tue Aug 18 12:54:51.111646 2026] [security2:error] [pid 67073:tid 67280] [client 172.182.200.96:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAS_cmepr5_nHgLbM7wQAAAl8"] [Tue Aug 18 12:54:51.139996 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.100.201:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSAS_cmepr5_nHgLbM7wgAAAnQ"] [Tue Aug 18 12:54:51.198209 2026] [security2:error] [pid 66623:tid 66691] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/media.php"] [unique_id "aoSAS9O5rbWdOArH04KBqwABezY"] [Tue Aug 18 12:54:51.230133 2026] [security2:error] [pid 67073:tid 67316] [client 20.51.153.15:9121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/you.php"] [unique_id "aoSAS_cmepr5_nHgLbM7xAAAAoM"] [Tue Aug 18 12:54:51.241676 2026] [security2:error] [pid 66623:tid 66848] [client 20.151.109.219:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fresh.php"] [unique_id "aoSAS9O5rbWdOArH04KBrAAAAVw"] [Tue Aug 18 12:54:51.294382 2026] [security2:error] [pid 66623:tid 66880] [client 4.223.164.152:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/get.php"] [unique_id "aoSAS9O5rbWdOArH04KBrgAAAXw"] [Tue Aug 18 12:54:51.294396 2026] [security2:error] [pid 66623:tid 66724] [remote 103.56.163.133:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSAS9O5rbWdOArH04KBrQABTlc"] [Tue Aug 18 12:54:51.358945 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wso.php"] [unique_id "aoSAS9O5rbWdOArH04KBrwAAATU"] [Tue Aug 18 12:54:51.417563 2026] [security2:error] [pid 66623:tid 66852] [client 52.139.47.57:27934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/as.php"] [unique_id "aoSAS9O5rbWdOArH04KBsAAAAWA"] [Tue Aug 18 12:54:51.460912 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.136.165:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/xleet.php"] [unique_id "aoSAS9O5rbWdOArH04KBsQAAAQs"] [Tue Aug 18 12:54:51.470095 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:38033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/dex.php"] [unique_id "aoSAS9O5rbWdOArH04KBsgAAAXE"] [Tue Aug 18 12:54:51.492438 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:8957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/about.php"] [unique_id "aoSAS_cmepr5_nHgLbM72wAAAiU"] [Tue Aug 18 12:54:51.502618 2026] [security2:error] [pid 67073:tid 67319] [client 116.179.37.220:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSASvcmepr5_nHgLbM7nQAAAoY"], referer: https://plenitude.com.br/como-conquistar-felicidade-em-sua-vida/ [Tue Aug 18 12:54:51.519311 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.56.190:30992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dr.php"] [unique_id "aoSAS_cmepr5_nHgLbM73QAAAhc"] [Tue Aug 18 12:54:51.616048 2026] [security2:error] [pid 66623:tid 66878] [client 132.196.61.152:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/images.php"] [unique_id "aoSAS9O5rbWdOArH04KBtAAAAXo"] [Tue Aug 18 12:54:51.623328 2026] [security2:error] [pid 66623:tid 66864] [client 20.91.215.254:20544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/f7.php"] [unique_id "aoSAS9O5rbWdOArH04KBtQAAAWw"] [Tue Aug 18 12:54:51.741094 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAS9O5rbWdOArH04KBtgAAAUI"] [Tue Aug 18 12:54:51.815614 2026] [security2:error] [pid 67073:tid 67278] [client 20.104.85.180:7973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAS_cmepr5_nHgLbM74QAAAl0"] [Tue Aug 18 12:54:51.815614 2026] [security2:error] [pid 66623:tid 66883] [client 213.202.253.4:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSAS9O5rbWdOArH04KBtwAAAX8"], referer: www.google.com [Tue Aug 18 12:54:51.870761 2026] [security2:error] [pid 67073:tid 67230] [client 20.251.48.93:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/blurbs.php"] [unique_id "aoSAS_cmepr5_nHgLbM74wAAAi0"] [Tue Aug 18 12:54:51.949376 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAS_cmepr5_nHgLbM75QAAAh4"] [Tue Aug 18 12:54:51.990540 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:42979] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "loja1.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSAS_cmepr5_nHgLbM76AAAAnw"] [Tue Aug 18 12:54:51.990645 2026] [security2:error] [pid 67073:tid 67309] [client 172.202.39.151:42979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSAS_cmepr5_nHgLbM76AAAAnw"] [Tue Aug 18 12:54:52.023015 2026] [security2:error] [pid 67073:tid 67239] [client 172.182.200.96:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSATPcmepr5_nHgLbM76QAAAjY"] [Tue Aug 18 12:54:52.051474 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ts.php"] [unique_id "aoSATPcmepr5_nHgLbM76gAAAlI"] [Tue Aug 18 12:54:52.160513 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:52.160782 2026] [authz_core:error] [pid 67073:tid 67156] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:52.161496 2026] [security2:error] [pid 67073:tid 67243] [client 172.202.39.151:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/sf.php"] [unique_id "aoSATPcmepr5_nHgLbM78AAAAjo"] [Tue Aug 18 12:54:52.282254 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.56.190:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/53.php"] [unique_id "aoSATNO5rbWdOArH04KBvQAAATI"] [Tue Aug 18 12:54:52.350237 2026] [security2:error] [pid 67073:tid 67297] [client 20.91.215.254:20560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/photo.php"] [unique_id "aoSATPcmepr5_nHgLbM79QAAAnA"] [Tue Aug 18 12:54:52.443531 2026] [security2:error] [pid 67073:tid 67285] [client 20.163.43.14:3113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/file.php"] [unique_id "aoSATPcmepr5_nHgLbM79gAAAmQ"] [Tue Aug 18 12:54:52.498148 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:24793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSATPcmepr5_nHgLbM79wAAAog"] [Tue Aug 18 12:54:52.535154 2026] [security2:error] [pid 67073:tid 67205] [client 20.163.43.14:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/admin.php"] [unique_id "aoSATPcmepr5_nHgLbM7-AAAAhQ"] [Tue Aug 18 12:54:52.698123 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/11.php"] [unique_id "aoSATPcmepr5_nHgLbM8AAAAAoo"] [Tue Aug 18 12:54:52.704579 2026] [security2:error] [pid 66623:tid 66876] [client 5.31.227.224:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBoAAAAXg"] [Tue Aug 18 12:54:52.704744 2026] [security2:error] [pid 66623:tid 66876] [client 5.31.227.224:7823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAStO5rbWdOArH04KBoAAAAXg"] [Tue Aug 18 12:54:52.706113 2026] [security2:error] [pid 67073:tid 67275] [client 52.238.210.254:9008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/file2.php"] [unique_id "aoSATPcmepr5_nHgLbM8AQAAAlo"] [Tue Aug 18 12:54:52.755035 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:52.755304 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:52.818937 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSATNO5rbWdOArH04KBwAAAASY"] [Tue Aug 18 12:54:52.847686 2026] [security2:error] [pid 66623:tid 66851] [client 20.51.153.15:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ez.php"] [unique_id "aoSATNO5rbWdOArH04KBwQAAAV8"] [Tue Aug 18 12:54:52.853082 2026] [security2:error] [pid 67073:tid 67247] [client 68.155.155.199:14013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSATPcmepr5_nHgLbM8BAAAAj4"] [Tue Aug 18 12:54:52.859381 2026] [security2:error] [pid 66623:tid 66837] [client 20.163.43.14:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/epinyins.php"] [unique_id "aoSATNO5rbWdOArH04KBwgAAAVE"] [Tue Aug 18 12:54:52.866036 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:44472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/ok.php"] [unique_id "aoSATNO5rbWdOArH04KBwwAAAVc"] [Tue Aug 18 12:54:52.961858 2026] [security2:error] [pid 67073:tid 67324] [client 157.20.138.62:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATPcmepr5_nHgLbM8BwAAAos"] [Tue Aug 18 12:54:52.961962 2026] [security2:error] [pid 67073:tid 67324] [client 157.20.138.62:55499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATPcmepr5_nHgLbM8BwAAAos"] [Tue Aug 18 12:54:52.964801 2026] [security2:error] [pid 67073:tid 67295] [client 20.251.48.93:2969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/bajah.php"] [unique_id "aoSATPcmepr5_nHgLbM8CAAAAm4"] [Tue Aug 18 12:54:53.014075 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:8920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoSATfcmepr5_nHgLbM8EgAAAoM"] [Tue Aug 18 12:54:53.024815 2026] [security2:error] [pid 67073:tid 67284] [client 4.232.151.198:6817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSATfcmepr5_nHgLbM8GwAAAmM"] [Tue Aug 18 12:54:53.110419 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ty.php"] [unique_id "aoSATdO5rbWdOArH04KBxAAAATg"] [Tue Aug 18 12:54:53.157649 2026] [security2:error] [pid 67073:tid 67252] [client 20.104.85.180:7946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/abc.php"] [unique_id "aoSATfcmepr5_nHgLbM8JgAAAkM"] [Tue Aug 18 12:54:53.229645 2026] [security2:error] [pid 67073:tid 67273] [client 4.223.164.152:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/images.php"] [unique_id "aoSATfcmepr5_nHgLbM8LQAAAlg"] [Tue Aug 18 12:54:53.247989 2026] [security2:error] [pid 67073:tid 67208] [client 20.163.43.14:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8LwAAAhc"] [Tue Aug 18 12:54:53.288047 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.133.44:23395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/fi2.php"] [unique_id "aoSATfcmepr5_nHgLbM8NwAAAjk"] [Tue Aug 18 12:54:53.342476 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/sim.php"] [unique_id "aoSATfcmepr5_nHgLbM8OQAAAko"] [Tue Aug 18 12:54:53.399021 2026] [security2:error] [pid 67073:tid 67226] [client 20.163.43.14:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/public/css.php"] [unique_id "aoSATfcmepr5_nHgLbM8OwAAAik"] [Tue Aug 18 12:54:53.448440 2026] [security2:error] [pid 66623:tid 66891] [client 20.104.100.201:58901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSATdO5rbWdOArH04KByAAAAYc"] [Tue Aug 18 12:54:53.487170 2026] [security2:error] [pid 67073:tid 67302] [client 20.118.172.148:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8PAAAAnU"] [Tue Aug 18 12:54:53.499763 2026] [security2:error] [pid 67073:tid 67278] [client 20.104.85.180:7955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/akcc.php"] [unique_id "aoSATfcmepr5_nHgLbM8PQAAAl0"] [Tue Aug 18 12:54:53.501585 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lq.php"] [unique_id "aoSATdO5rbWdOArH04KByQAAARA"] [Tue Aug 18 12:54:53.534338 2026] [security2:error] [pid 67073:tid 67236] [client 49.13.167.123:52216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSATPcmepr5_nHgLbM7-QAAAjM"], referer: https://www.institutoferiani.com.br [Tue Aug 18 12:54:53.579183 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.27.191:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSATdO5rbWdOArH04KBzQAAAQ4"] [Tue Aug 18 12:54:53.583805 2026] [security2:error] [pid 66623:tid 66830] [client 20.116.17.175:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dragonshell.php"] [unique_id "aoSATdO5rbWdOArH04KBzgAAAUo"] [Tue Aug 18 12:54:53.694662 2026] [security2:error] [pid 67073:tid 67328] [client 213.35.127.232:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSATfcmepr5_nHgLbM8PgAAAo8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:53.710367 2026] [security2:error] [pid 67073:tid 67215] [client 4.223.164.152:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/alls.php"] [unique_id "aoSATfcmepr5_nHgLbM8QQAAAh4"] [Tue Aug 18 12:54:53.733076 2026] [security2:error] [pid 66623:tid 66717] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mini.php"] [unique_id "aoSATdO5rbWdOArH04KB0gABK1A"] [Tue Aug 18 12:54:53.789324 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.100.201:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dot.php"] [unique_id "aoSATfcmepr5_nHgLbM8RAAAAnw"] [Tue Aug 18 12:54:53.829154 2026] [security2:error] [pid 67073:tid 67287] [client 20.205.121.237:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/txets.php"] [unique_id "aoSATfcmepr5_nHgLbM8RQAAAmY"] [Tue Aug 18 12:54:53.846445 2026] [security2:error] [pid 67073:tid 67332] [client 20.104.85.180:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wk/index.php"] [unique_id "aoSATfcmepr5_nHgLbM8TAAAApM"] [Tue Aug 18 12:54:53.854214 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:16691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/atex1.php"] [unique_id "aoSATfcmepr5_nHgLbM8TQAAAnQ"] [Tue Aug 18 12:54:53.873675 2026] [security2:error] [pid 67073:tid 67113] [remote 47.86.33.52:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSATfcmepr5_nHgLbM8TgACeiU"] [Tue Aug 18 12:54:54.034758 2026] [security2:error] [pid 67073:tid 67210] [client 20.42.19.40:9704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about.php"] [unique_id "aoSATvcmepr5_nHgLbM8UQAAAhk"] [Tue Aug 18 12:54:54.038129 2026] [security2:error] [pid 67073:tid 67265] [client 20.250.27.191:1906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/media.php"] [unique_id "aoSATvcmepr5_nHgLbM8UgAAAlA"] [Tue Aug 18 12:54:54.050375 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.136.165:34381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/xleet.php"] [unique_id "aoSATvcmepr5_nHgLbM8UwAAAjI"] [Tue Aug 18 12:54:54.058330 2026] [security2:error] [pid 66623:tid 66675] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/miru1.php"] [unique_id "aoSATtO5rbWdOArH04KB1wABKCY"] [Tue Aug 18 12:54:54.095668 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/asus.php"] [unique_id "aoSATvcmepr5_nHgLbM8VAAAAks"] [Tue Aug 18 12:54:54.113494 2026] [security2:error] [pid 66623:tid 66857] [client 20.42.19.40:2218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/f35.php"] [unique_id "aoSATtO5rbWdOArH04KB2AAAAWU"] [Tue Aug 18 12:54:54.167213 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.155.199:13992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about.php"] [unique_id "aoSATvcmepr5_nHgLbM8VQAAAiY"] [Tue Aug 18 12:54:54.189951 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:64645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/coffexium.php"] [unique_id "aoSATtO5rbWdOArH04KB2QAAARw"] [Tue Aug 18 12:54:54.216804 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:8048] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rodrigolocadora.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB2gAAARU"] [Tue Aug 18 12:54:54.216929 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:8048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB2gAAARU"] [Tue Aug 18 12:54:54.222682 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.133.44:18998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/feeds.php"] [unique_id "aoSATtO5rbWdOArH04KB2wAAAWc"] [Tue Aug 18 12:54:54.225385 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:52892] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gruposchopan.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB3AAAAVw"] [Tue Aug 18 12:54:54.225472 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.98.162:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/1.php"] [unique_id "aoSATtO5rbWdOArH04KB3AAAAVw"] [Tue Aug 18 12:54:54.248882 2026] [security2:error] [pid 67073:tid 67093] [remote 188.164.197.230:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSATvcmepr5_nHgLbM8VgACbxE"] [Tue Aug 18 12:54:54.314339 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.16:34878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:54.314594 2026] [authz_core:error] [pid 66623:tid 66705] [remote 57.141.22.16:34878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:54.377292 2026] [security2:error] [pid 66623:tid 66709] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/mjq.php"] [unique_id "aoSATtO5rbWdOArH04KB3gABfEg"] [Tue Aug 18 12:54:54.444389 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/22.php"] [unique_id "aoSATvcmepr5_nHgLbM8WgAAAmE"] [Tue Aug 18 12:54:54.503299 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.27.191:1885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSATtO5rbWdOArH04KB3wAAAQs"] [Tue Aug 18 12:54:54.540119 2026] [security2:error] [pid 66623:tid 66847] [client 20.91.215.254:20569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-aa.php"] [unique_id "aoSATtO5rbWdOArH04KB4AAAAVs"] [Tue Aug 18 12:54:54.575729 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.100.201:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/005.php"] [unique_id "aoSATvcmepr5_nHgLbM8WwAAAjw"] [Tue Aug 18 12:54:54.625479 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:12394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/simple.php"] [unique_id "aoSATtO5rbWdOArH04KB4QAAATM"] [Tue Aug 18 12:54:54.627134 2026] [security2:error] [pid 66623:tid 66889] [client 52.139.47.57:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/jga.php"] [unique_id "aoSATtO5rbWdOArH04KB4gAAAYU"] [Tue Aug 18 12:54:54.698613 2026] [security2:error] [pid 66623:tid 66664] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/modules/mod_footer/tmpl/index.php"] [unique_id "aoSATtO5rbWdOArH04KB4wABHxs"] [Tue Aug 18 12:54:54.710068 2026] [security2:error] [pid 66623:tid 66828] [client 20.48.236.86:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file61.php"] [unique_id "aoSATtO5rbWdOArH04KB5QAAAUg"] [Tue Aug 18 12:54:54.830563 2026] [security2:error] [pid 66623:tid 66885] [client 132.196.61.152:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/admin.php"] [unique_id "aoSATtO5rbWdOArH04KB5gAAAYE"] [Tue Aug 18 12:54:54.846034 2026] [security2:error] [pid 66623:tid 66888] [client 178.153.171.161:32932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATtO5rbWdOArH04KB5wAAAYQ"] [Tue Aug 18 12:54:54.846160 2026] [security2:error] [pid 66623:tid 66888] [client 178.153.171.161:32932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSATtO5rbWdOArH04KB5wAAAYQ"] [Tue Aug 18 12:54:54.908711 2026] [security2:error] [pid 67073:tid 67268] [client 20.104.100.201:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/v2.php"] [unique_id "aoSATvcmepr5_nHgLbM8XwAAAlM"] [Tue Aug 18 12:54:54.909333 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:44970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/first.php"] [unique_id "aoSATvcmepr5_nHgLbM8YAAAAos"] [Tue Aug 18 12:54:54.964920 2026] [security2:error] [pid 66623:tid 66808] [client 20.250.27.191:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/mac.php"] [unique_id "aoSATtO5rbWdOArH04KB6AAAATQ"] [Tue Aug 18 12:54:54.974639 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSATvcmepr5_nHgLbM8YQAAAhY"] [Tue Aug 18 12:54:55.061403 2026] [security2:error] [pid 67073:tid 67216] [client 132.196.61.152:27268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "webmail.riosafe.com.br"] [uri "/.mopj.php"] [unique_id "aoSAT_cmepr5_nHgLbM8YgAAAh8"] [Tue Aug 18 12:54:55.068438 2026] [security2:error] [pid 67073:tid 67224] [client 20.251.48.93:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/domvf.php"] [unique_id "aoSAT_cmepr5_nHgLbM8YwAAAic"] [Tue Aug 18 12:54:55.170307 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vm.php"] [unique_id "aoSAT_cmepr5_nHgLbM8ZgAAAiU"] [Tue Aug 18 12:54:55.234624 2026] [security2:error] [pid 67073:tid 67242] [client 20.104.100.201:58916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wkl.php"] [unique_id "aoSAT_cmepr5_nHgLbM8agAAAjk"] [Tue Aug 18 12:54:55.325853 2026] [security2:error] [pid 66623:tid 66785] [client 20.42.19.40:1373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAT9O5rbWdOArH04KB6wAAAR0"] [Tue Aug 18 12:54:55.416755 2026] [security2:error] [pid 67073:tid 67319] [client 74.248.18.37:47614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSAT_cmepr5_nHgLbM8ZwAAAoY"] [Tue Aug 18 12:54:55.438110 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.27.191:1875] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAT9O5rbWdOArH04KB7QAAAQw"] [Tue Aug 18 12:54:55.438235 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.27.191:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAT9O5rbWdOArH04KB7QAAAQw"] [Tue Aug 18 12:54:55.469089 2026] [security2:error] [pid 67073:tid 67217] [client 85.154.68.202:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAT_cmepr5_nHgLbM8awAAAiA"] [Tue Aug 18 12:54:55.469206 2026] [security2:error] [pid 67073:tid 67217] [client 85.154.68.202:10535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAT_cmepr5_nHgLbM8awAAAiA"] [Tue Aug 18 12:54:55.490638 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:8508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hoteisecovip.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAT9O5rbWdOArH04KB7gAAATc"] [Tue Aug 18 12:54:55.571557 2026] [security2:error] [pid 67073:tid 67286] [client 132.196.61.152:55318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/bengi.php"] [unique_id "aoSAT_cmepr5_nHgLbM8bQAAAmU"] [Tue Aug 18 12:54:55.599035 2026] [security2:error] [pid 67073:tid 67267] [client 135.225.75.187:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-good.php"] [unique_id "aoSAT_cmepr5_nHgLbM8bgAAAlI"] [Tue Aug 18 12:54:55.605887 2026] [security2:error] [pid 66623:tid 66851] [client 20.163.43.14:3147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAT9O5rbWdOArH04KB8gAAAV8"] [Tue Aug 18 12:54:55.642974 2026] [security2:error] [pid 66623:tid 66837] [client 20.251.48.93:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/fpwch.php"] [unique_id "aoSAT9O5rbWdOArH04KB8wAAAVE"] [Tue Aug 18 12:54:55.648318 2026] [security2:error] [pid 67073:tid 67228] [client 5.253.205.188:51058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/home.bak"] [unique_id "aoSAT_cmepr5_nHgLbM8bwAAAis"], referer: https://medihub.com.br/home.bak [Tue Aug 18 12:54:55.658574 2026] [security2:error] [pid 67073:tid 67269] [client 52.173.121.69:16468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAT_cmepr5_nHgLbM8cQAAAlQ"] [Tue Aug 18 12:54:55.769342 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/166.php"] [unique_id "aoSAT_cmepr5_nHgLbM8cwAAAiM"] [Tue Aug 18 12:54:55.806277 2026] [security2:error] [pid 66623:tid 66890] [client 172.202.39.151:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lecarveiculospira.com.br"] [uri "/item.php"] [unique_id "aoSAT9O5rbWdOArH04KB9AAAAYY"] [Tue Aug 18 12:54:55.903987 2026] [security2:error] [pid 66623:tid 66843] [client 74.248.18.37:12706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/st.php"] [unique_id "aoSAT9O5rbWdOArH04KB-AAAAVc"] [Tue Aug 18 12:54:55.905297 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:1888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/coffee.php"] [unique_id "aoSAT_cmepr5_nHgLbM8dAAAAnw"] [Tue Aug 18 12:54:55.992067 2026] [security2:error] [pid 66623:tid 66790] [client 20.163.43.14:3186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAT9O5rbWdOArH04KB-QAAASI"] [Tue Aug 18 12:54:56.066351 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:56.066611 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:56.157066 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.133.44:42067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/curl.php"] [unique_id "aoSAUPcmepr5_nHgLbM8egAAAoA"] [Tue Aug 18 12:54:56.213223 2026] [security2:error] [pid 66623:tid 66891] [client 74.248.136.165:62389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAUNO5rbWdOArH04KB_AAAAYc"] [Tue Aug 18 12:54:56.263839 2026] [security2:error] [pid 67073:tid 67317] [client 52.238.210.254:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAUPcmepr5_nHgLbM8ewAAAoQ"] [Tue Aug 18 12:54:56.284515 2026] [security2:error] [pid 67073:tid 67237] [client 20.65.98.162:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/coffee.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fQAAAjQ"] [Tue Aug 18 12:54:56.292138 2026] [security2:error] [pid 67073:tid 67272] [client 132.196.61.152:27296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/file2.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fgAAAlc"] [Tue Aug 18 12:54:56.309644 2026] [security2:error] [pid 67073:tid 67227] [client 20.251.48.93:35082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/adminner.php"] [unique_id "aoSAUPcmepr5_nHgLbM8fwAAAio"] [Tue Aug 18 12:54:56.391373 2026] [security2:error] [pid 67073:tid 67325] [client 20.163.43.14:3168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gAAAAow"] [Tue Aug 18 12:54:56.441324 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.56.190:20377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/you.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gQAAAlA"] [Tue Aug 18 12:54:56.562739 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/php8.php"] [unique_id "aoSAUPcmepr5_nHgLbM8ggAAAog"] [Tue Aug 18 12:54:56.564733 2026] [security2:error] [pid 67073:tid 67253] [client 52.139.47.57:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/log.php"] [unique_id "aoSAUPcmepr5_nHgLbM8gwAAAkQ"] [Tue Aug 18 12:54:56.595701 2026] [security2:error] [pid 67073:tid 67205] [client 20.104.100.201:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSAUPcmepr5_nHgLbM8hgAAAhQ"] [Tue Aug 18 12:54:56.683188 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.113.47:55191] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lubarbosaassessoria.com.br"] [uri "/"] [unique_id "aoSAT9O5rbWdOArH04KB8QAAAVg"] [Tue Aug 18 12:54:56.745643 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:25808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/test.php"] [unique_id "aoSAUNO5rbWdOArH04KCAQAAAVA"] [Tue Aug 18 12:54:56.822892 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eg.php"] [unique_id "aoSAUPcmepr5_nHgLbM8iQAAAoo"] [Tue Aug 18 12:54:56.838934 2026] [security2:error] [pid 67073:tid 67318] [client 20.48.236.86:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/copypaths.php"] [unique_id "aoSAUPcmepr5_nHgLbM8igAAAoU"] [Tue Aug 18 12:54:56.864235 2026] [security2:error] [pid 67073:tid 67300] [client 213.35.127.232:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jAAAAnM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:54:56.904661 2026] [security2:error] [pid 67073:tid 67245] [client 20.250.27.191:1891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jgAAAjw"] [Tue Aug 18 12:54:56.928581 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAUPcmepr5_nHgLbM8jwAAAl8"] [Tue Aug 18 12:54:56.941704 2026] [security2:error] [pid 66623:tid 66687] [remote 216.194.122.158:47092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSAUNO5rbWdOArH04KCAgABWTI"] [Tue Aug 18 12:54:56.948802 2026] [security2:error] [pid 66623:tid 66766] [client 52.238.210.254:8883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoSAUNO5rbWdOArH04KCAwAAAQo"] [Tue Aug 18 12:54:56.949217 2026] [security2:error] [pid 66623:tid 66882] [client 135.225.75.187:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zxin.php"] [unique_id "aoSAUNO5rbWdOArH04KCBAAAAX4"] [Tue Aug 18 12:54:56.969932 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:56.970182 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:57.016990 2026] [security2:error] [pid 66623:tid 66855] [client 132.196.61.152:55309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/gm.php"] [unique_id "aoSAUdO5rbWdOArH04KCBQAAAWM"] [Tue Aug 18 12:54:57.077672 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAUfcmepr5_nHgLbM8kQAAAls"] [Tue Aug 18 12:54:57.147416 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.18.37:12705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSAUfcmepr5_nHgLbM8kwAAAj4"] [Tue Aug 18 12:54:57.183974 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/d.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lAAAAho"] [Tue Aug 18 12:54:57.220124 2026] [security2:error] [pid 67073:tid 67278] [client 157.51.166.53:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lgAAAl0"] [Tue Aug 18 12:54:57.220248 2026] [security2:error] [pid 67073:tid 67278] [client 157.51.166.53:55787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8lgAAAl0"] [Tue Aug 18 12:54:57.269604 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:57.269902 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:57.287145 2026] [security2:error] [pid 67073:tid 67208] [client 20.42.19.40:9618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mQAAAhc"] [Tue Aug 18 12:54:57.362380 2026] [security2:error] [pid 67073:tid 67259] [client 20.171.51.14:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/37.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mgAAAko"] [Tue Aug 18 12:54:57.370875 2026] [security2:error] [pid 67073:tid 67279] [client 20.250.27.191:1890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAUfcmepr5_nHgLbM8mwAAAl4"] [Tue Aug 18 12:54:57.536359 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.6.191:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAUfcmepr5_nHgLbM8nwAAAiA"] [Tue Aug 18 12:54:57.556358 2026] [security2:error] [pid 67073:tid 67235] [client 149.34.210.141:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8ngAAAjI"] [Tue Aug 18 12:54:57.649007 2026] [security2:error] [pid 66623:tid 66839] [client 20.163.43.14:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gelay.php"] [unique_id "aoSAUdO5rbWdOArH04KCCQAAAVM"] [Tue Aug 18 12:54:57.673000 2026] [security2:error] [pid 66623:tid 66796] [client 20.251.48.93:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.activevalue.com.br"] [uri "/abcd.php"] [unique_id "aoSAUdO5rbWdOArH04KCCgAAASg"] [Tue Aug 18 12:54:57.677822 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.130.103:15412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAUdO5rbWdOArH04KCCwAAAUw"] [Tue Aug 18 12:54:57.706228 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/setup-config.php"] [unique_id "aoSAUfcmepr5_nHgLbM8sAAAAkE"] [Tue Aug 18 12:54:57.707087 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:3142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/file.php"] [unique_id "aoSAUfcmepr5_nHgLbM8sQAAAiw"] [Tue Aug 18 12:54:57.753107 2026] [security2:error] [pid 66623:tid 66784] [client 4.223.164.152:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/red.php"] [unique_id "aoSAUdO5rbWdOArH04KCDAAAARw"] [Tue Aug 18 12:54:57.873613 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:57.873903 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:57.919536 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/az.php"] [unique_id "aoSAUdO5rbWdOArH04KCDwAAAU8"] [Tue Aug 18 12:54:57.965182 2026] [security2:error] [pid 67073:tid 67317] [client 20.65.98.162:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAUfcmepr5_nHgLbM8tgAAAoQ"] [Tue Aug 18 12:54:58.029849 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:24504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAUtO5rbWdOArH04KCEQAAARI"] [Tue Aug 18 12:54:58.045239 2026] [security2:error] [pid 67073:tid 67222] [client 37.40.227.74:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM8twAAAiU"] [Tue Aug 18 12:54:58.045364 2026] [security2:error] [pid 67073:tid 67222] [client 37.40.227.74:57161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM8twAAAiU"] [Tue Aug 18 12:54:58.093348 2026] [security2:error] [pid 66623:tid 66767] [client 216.244.66.243:58110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/tensei+shitara+slime+datta+ken+3+temporada+dublado-2/"] [unique_id "aoSAUtO5rbWdOArH04KCEwAAAQs"] [Tue Aug 18 12:54:58.093484 2026] [security2:error] [pid 66623:tid 66767] [client 216.244.66.243:58110] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/tensei+shitara+slime+datta+ken+3+temporada+dublado-2/"] [unique_id "aoSAUtO5rbWdOArH04KCEwAAAQs"] [Tue Aug 18 12:54:58.096855 2026] [security2:error] [pid 67073:tid 67209] [client 185.198.240.219:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "celleiromoveis.com"] [uri "/wp-login.php"] [unique_id "aoSAUfcmepr5_nHgLbM8tAAAAhg"] [Tue Aug 18 12:54:58.335299 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.130.103:15417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAUtO5rbWdOArH04KCPQAAAXk"] [Tue Aug 18 12:54:58.348529 2026] [security2:error] [pid 67073:tid 67293] [client 52.173.121.69:17953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAUvcmepr5_nHgLbM8uQAAAmw"] [Tue Aug 18 12:54:58.372998 2026] [security2:error] [pid 66623:tid 66888] [client 52.238.210.254:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/alfa.php"] [unique_id "aoSAUtO5rbWdOArH04KCPgAAAYQ"] [Tue Aug 18 12:54:58.374268 2026] [security2:error] [pid 66623:tid 66857] [client 196.12.128.158:59734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUtO5rbWdOArH04KCPwAAAWU"] [Tue Aug 18 12:54:58.374374 2026] [security2:error] [pid 66623:tid 66857] [client 196.12.128.158:59734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUtO5rbWdOArH04KCPwAAAWU"] [Tue Aug 18 12:54:58.400382 2026] [security2:error] [pid 67073:tid 67308] [client 114.119.130.97:26083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "leguizaimoveis.com.br"] [uri "/imoveis/property/51/resid%C3%AAncia-de-alto-luxo-num-dos-melhores-condom%C3%ADnios-de-itaipu.html"] [unique_id "aoSAUvcmepr5_nHgLbM8ugAAAns"], referer: https://leguizaimoveis.com.br/imoveis/property/51/resid%C3%AAncia-de-alto-luxo-num-dos-melhores-condom%C3%ADnios-de-itaipu.html [Tue Aug 18 12:54:58.432229 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.136.165:59475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/gool.php"] [unique_id "aoSAUtO5rbWdOArH04KCQAAAAVQ"] [Tue Aug 18 12:54:58.461473 2026] [security2:error] [pid 67073:tid 67326] [client 20.48.236.86:11013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bless6.php"] [unique_id "aoSAUvcmepr5_nHgLbM8uwAAAo0"] [Tue Aug 18 12:54:58.477748 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:58.478011 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:58.540220 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.56.190:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ez.php"] [unique_id "aoSAUvcmepr5_nHgLbM8vQAAAiY"] [Tue Aug 18 12:54:58.545076 2026] [security2:error] [pid 66623:tid 66778] [client 4.232.151.198:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/inputs.php"] [unique_id "aoSAUtO5rbWdOArH04KCQQAAARY"] [Tue Aug 18 12:54:58.611166 2026] [security2:error] [pid 67073:tid 67235] [client 149.34.210.141:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAUfcmepr5_nHgLbM8ngAAAjI"] [Tue Aug 18 12:54:58.681619 2026] [security2:error] [pid 66623:tid 66846] [client 132.196.61.152:61036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/222.php"] [unique_id "aoSAUtO5rbWdOArH04KCQwAAAVo"] [Tue Aug 18 12:54:58.699648 2026] [security2:error] [pid 67073:tid 67296] [client 132.196.61.152:27319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/ws55.php"] [unique_id "aoSAUvcmepr5_nHgLbM82wAAAm8"] [Tue Aug 18 12:54:58.720860 2026] [security2:error] [pid 66623:tid 66870] [client 20.151.109.219:17580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gj.php"] [unique_id "aoSAUtO5rbWdOArH04KCRAAAAXI"] [Tue Aug 18 12:54:58.721289 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.100.201:21468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/z43agz.php"] [unique_id "aoSAUvcmepr5_nHgLbM83AAAAoo"] [Tue Aug 18 12:54:58.775640 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:58.775898 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:58.885305 2026] [security2:error] [pid 67073:tid 67312] [client 20.116.17.175:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/f35.update.php"] [unique_id "aoSAUvcmepr5_nHgLbM85QAAAn8"] [Tue Aug 18 12:54:58.897785 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/chosen.php"] [unique_id "aoSAUvcmepr5_nHgLbM85gAAAk0"] [Tue Aug 18 12:54:58.945180 2026] [security2:error] [pid 67073:tid 67171] [remote 57.141.22.54:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAUvcmepr5_nHgLbM85wACWV8"] [Tue Aug 18 12:54:58.955125 2026] [security2:error] [pid 67073:tid 67330] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAUvcmepr5_nHgLbM85AACkVs"] [Tue Aug 18 12:54:58.982093 2026] [security2:error] [pid 67073:tid 67316] [client 20.171.51.14:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/uk.php"] [unique_id "aoSAUvcmepr5_nHgLbM86AAAAoM"] [Tue Aug 18 12:54:59.020545 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.130.103:14410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/domvf.php"] [unique_id "aoSAU9O5rbWdOArH04KCRwAAATc"] [Tue Aug 18 12:54:59.023527 2026] [autoindex:error] [pid 66623:tid 66703] [remote 52.167.144.17:32059] AH01276: Cannot serve directory /home2/natbrw01/uhequeimado.com.br/web/wp-content/themes/vamtam-landscaping/vamtam/assets/css/dist/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:54:59.075679 2026] [security2:error] [pid 67073:tid 67224] [client 20.100.169.31:31436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAU_cmepr5_nHgLbM86gAAAic"] [Tue Aug 18 12:54:59.106199 2026] [security2:error] [pid 67073:tid 67246] [client 103.120.71.157:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM86wAAAj0"] [Tue Aug 18 12:54:59.106328 2026] [security2:error] [pid 67073:tid 67246] [client 103.120.71.157:4101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM86wAAAj0"] [Tue Aug 18 12:54:59.146319 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:6843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/test1.php"] [unique_id "aoSAU_cmepr5_nHgLbM87AAAAmk"] [Tue Aug 18 12:54:59.159938 2026] [security2:error] [pid 66623:tid 66868] [client 20.163.43.14:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAU9O5rbWdOArH04KCSQAAAXA"] [Tue Aug 18 12:54:59.204238 2026] [security2:error] [pid 67073:tid 67206] [client 20.91.215.254:24343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAU_cmepr5_nHgLbM88gAAAhU"] [Tue Aug 18 12:54:59.270676 2026] [security2:error] [pid 67073:tid 67304] [client 20.29.77.16:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAU_cmepr5_nHgLbM88wAAAnc"] [Tue Aug 18 12:54:59.300821 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/index/function.php"] [unique_id "aoSAU_cmepr5_nHgLbM89AAAApI"] [Tue Aug 18 12:54:59.377527 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:54:59.377793 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:54:59.432046 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.18.37:12682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/system.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-QAAAhs"] [Tue Aug 18 12:54:59.484025 2026] [security2:error] [pid 67073:tid 67277] [client 114.5.214.109:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-gAAAlw"] [Tue Aug 18 12:54:59.484204 2026] [security2:error] [pid 67073:tid 67277] [client 114.5.214.109:49799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU_cmepr5_nHgLbM8-gAAAlw"] [Tue Aug 18 12:54:59.569444 2026] [security2:error] [pid 66623:tid 66843] [client 20.151.109.219:12914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pd.php"] [unique_id "aoSAU9O5rbWdOArH04KCTAAAAVc"] [Tue Aug 18 12:54:59.581430 2026] [security2:error] [pid 67073:tid 67328] [client 135.225.75.187:9502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pass4.php"] [unique_id "aoSAU_cmepr5_nHgLbM8_QAAAo8"] [Tue Aug 18 12:54:59.584392 2026] [security2:error] [pid 66623:tid 66779] [client 4.223.164.152:54265] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/sodium_compat/"] [unique_id "aoSAU9O5rbWdOArH04KCTQAAARc"] [Tue Aug 18 12:54:59.634863 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:24857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.capitalcaminhonetes.com.br"] [uri "/images/security.php"] [unique_id "aoSAU9O5rbWdOArH04KCTgAAASU"] [Tue Aug 18 12:54:59.640607 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAU_cmepr5_nHgLbM8_gAAAi8"] [Tue Aug 18 12:54:59.657641 2026] [security2:error] [pid 67073:tid 67250] [client 104.209.144.33:39356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/opsqt.php"] [unique_id "aoSAU_cmepr5_nHgLbM9AAAAAkE"] [Tue Aug 18 12:54:59.684635 2026] [security2:error] [pid 67073:tid 67239] [client 20.163.43.14:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAU_cmepr5_nHgLbM9AwAAAjY"] [Tue Aug 18 12:54:59.689402 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:2556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/asus.php"] [unique_id "aoSAU_cmepr5_nHgLbM9BAAAAmY"] [Tue Aug 18 12:54:59.741828 2026] [security2:error] [pid 66623:tid 66856] [client 160.120.140.123:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU9O5rbWdOArH04KCTwAAAWQ"] [Tue Aug 18 12:54:59.741965 2026] [security2:error] [pid 66623:tid 66856] [client 160.120.140.123:56772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAU9O5rbWdOArH04KCTwAAAWQ"] [Tue Aug 18 12:54:59.750452 2026] [security2:error] [pid 67073:tid 67218] [client 132.196.61.152:61013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mac.php"] [unique_id "aoSAU_cmepr5_nHgLbM9BwAAAiE"] [Tue Aug 18 12:54:59.953111 2026] [security2:error] [pid 67073:tid 67210] [client 20.151.109.219:21660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/th.php"] [unique_id "aoSAU_cmepr5_nHgLbM9DAAAAhk"] [Tue Aug 18 12:54:59.983568 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:32439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSAU_cmepr5_nHgLbM9DQAAAlA"] [Tue Aug 18 12:55:00.029136 2026] [security2:error] [pid 67073:tid 67243] [client 192.141.172.134:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9DwAAAjo"] [Tue Aug 18 12:55:00.029276 2026] [security2:error] [pid 67073:tid 67243] [client 192.141.172.134:56046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9DwAAAjo"] [Tue Aug 18 12:55:00.043847 2026] [security2:error] [pid 67073:tid 67306] [client 20.42.19.40:2751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/gg.php"] [unique_id "aoSAVPcmepr5_nHgLbM9EQAAAnk"] [Tue Aug 18 12:55:00.077192 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:64675] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Text/"] [unique_id "aoSAVPcmepr5_nHgLbM9EgAAAmQ"] [Tue Aug 18 12:55:00.082942 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/3.php"] [unique_id "aoSAVPcmepr5_nHgLbM9EwAAAmM"] [Tue Aug 18 12:55:00.161438 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.18.37:12694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/system_log.php"] [unique_id "aoSAVPcmepr5_nHgLbM9FQAAAio"] [Tue Aug 18 12:55:00.196733 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/simple.php"] [unique_id "aoSAVPcmepr5_nHgLbM9FwAAAnY"] [Tue Aug 18 12:55:00.236643 2026] [security2:error] [pid 67073:tid 67257] [client 86.120.159.145:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GQAAAkg"] [Tue Aug 18 12:55:00.237004 2026] [security2:error] [pid 67073:tid 67257] [client 86.120.159.145:50260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GQAAAkg"] [Tue Aug 18 12:55:00.251564 2026] [security2:error] [pid 67073:tid 67301] [client 20.91.215.254:24251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9GgAAAnQ"] [Tue Aug 18 12:55:00.309379 2026] [security2:error] [pid 67073:tid 67323] [client 132.196.61.152:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/m.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HAAAAoo"] [Tue Aug 18 12:55:00.313850 2026] [security2:error] [pid 67073:tid 67302] [client 20.151.109.219:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/admin404.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HQAAAnU"] [Tue Aug 18 12:55:00.341907 2026] [security2:error] [pid 67073:tid 67254] [client 52.173.121.69:24797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HgAAAkU"] [Tue Aug 18 12:55:00.376100 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.200.96:14221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAVPcmepr5_nHgLbM9HwAAAlM"] [Tue Aug 18 12:55:00.401986 2026] [security2:error] [pid 67073:tid 67329] [client 4.232.151.198:41312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/admin.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IAAAApA"] [Tue Aug 18 12:55:00.475807 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/special.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IgAAAl8"] [Tue Aug 18 12:55:00.489341 2026] [security2:error] [pid 67073:tid 67225] [client 197.184.64.235:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IwAAAig"] [Tue Aug 18 12:55:00.489507 2026] [security2:error] [pid 67073:tid 67225] [client 197.184.64.235:41921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVPcmepr5_nHgLbM9IwAAAig"] [Tue Aug 18 12:55:00.523789 2026] [security2:error] [pid 66623:tid 66891] [client 20.116.17.175:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/bdroot.php"] [unique_id "aoSAVNO5rbWdOArH04KCUwAAAYc"] [Tue Aug 18 12:55:00.593878 2026] [security2:error] [pid 67073:tid 67220] [client 20.100.169.31:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/0x.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JAAAAiM"] [Tue Aug 18 12:55:00.605855 2026] [security2:error] [pid 67073:tid 67260] [client 213.35.127.232:53686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JQAAAks"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:00.616237 2026] [security2:error] [pid 67073:tid 67240] [client 20.91.215.254:27427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/backup.php"] [unique_id "aoSAVPcmepr5_nHgLbM9JgAAAjc"] [Tue Aug 18 12:55:00.684292 2026] [security2:error] [pid 66623:tid 66806] [client 213.202.253.4:53414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSAVNO5rbWdOArH04KCVQAAATI"], referer: www.google.com [Tue Aug 18 12:55:00.696077 2026] [security2:error] [pid 66623:tid 66818] [client 20.100.169.31:24496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAVNO5rbWdOArH04KCVgAAAT4"] [Tue Aug 18 12:55:00.745495 2026] [security2:error] [pid 67073:tid 67331] [client 74.248.130.103:14458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAVPcmepr5_nHgLbM9KAAAApI"] [Tue Aug 18 12:55:00.784745 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:36473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/creds.php"] [unique_id "aoSAVPcmepr5_nHgLbM9KgAAAik"] [Tue Aug 18 12:55:00.806335 2026] [security2:error] [pid 67073:tid 67212] [client 74.248.136.165:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/maxro.php"] [unique_id "aoSAVPcmepr5_nHgLbM9LAAAAhs"] [Tue Aug 18 12:55:00.854385 2026] [security2:error] [pid 67073:tid 67217] [client 20.250.27.191:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/yj09.php"] [unique_id "aoSAVPcmepr5_nHgLbM9LgAAAiA"] [Tue Aug 18 12:55:00.887134 2026] [security2:error] [pid 67073:tid 67267] [client 20.104.100.201:21469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/log.php"] [unique_id "aoSAVPcmepr5_nHgLbM9MAAAAlI"] [Tue Aug 18 12:55:00.942225 2026] [security2:error] [pid 66623:tid 66797] [client 172.202.39.151:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAVNO5rbWdOArH04KCWQAAASk"] [Tue Aug 18 12:55:00.948809 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.18.37:12719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSAVPcmepr5_nHgLbM9NgAAAlg"] [Tue Aug 18 12:55:00.975705 2026] [security2:error] [pid 67073:tid 67140] [remote 84.205.178.135:32681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSAVPcmepr5_nHgLbM9NQACJEA"] [Tue Aug 18 12:55:01.012798 2026] [security2:error] [pid 67073:tid 67232] [client 20.163.43.14:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAVfcmepr5_nHgLbM9NwAAAi8"] [Tue Aug 18 12:55:01.063169 2026] [security2:error] [pid 67073:tid 67250] [client 104.209.144.33:29871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/jvcpa.php"] [unique_id "aoSAVfcmepr5_nHgLbM9OQAAAkE"] [Tue Aug 18 12:55:01.188844 2026] [security2:error] [pid 67073:tid 67244] [client 34.177.98.83:48128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "pisogranitina.com.br"] [uri "/"] [unique_id "aoSAVfcmepr5_nHgLbM9PAAAAjs"] [Tue Aug 18 12:55:01.227056 2026] [security2:error] [pid 67073:tid 67251] [client 20.104.100.201:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ohct.php"] [unique_id "aoSAVfcmepr5_nHgLbM9PgAAAkI"] [Tue Aug 18 12:55:01.229570 2026] [security2:error] [pid 67073:tid 67235] [client 4.232.151.198:6809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/text.php"] [unique_id "aoSAVfcmepr5_nHgLbM9PwAAAjI"] [Tue Aug 18 12:55:01.267034 2026] [security2:error] [pid 67073:tid 67265] [client 66.249.77.98:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/robots.txt"] [unique_id "aoSAVfcmepr5_nHgLbM9QAAAAlA"] [Tue Aug 18 12:55:01.290961 2026] [security2:error] [pid 67073:tid 67261] [client 52.139.47.57:2054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/bolt.php"] [unique_id "aoSAVfcmepr5_nHgLbM9QQAAAkw"] [Tue Aug 18 12:55:01.317775 2026] [security2:error] [pid 67073:tid 67293] [client 20.250.27.191:1913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/scxy.php"] [unique_id "aoSAVfcmepr5_nHgLbM9QgAAAmw"] [Tue Aug 18 12:55:01.357299 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ho.php"] [unique_id "aoSAVfcmepr5_nHgLbM9RAAAAnA"] [Tue Aug 18 12:55:01.408631 2026] [security2:error] [pid 67073:tid 67253] [client 20.29.77.16:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAVfcmepr5_nHgLbM9RgAAAkQ"] [Tue Aug 18 12:55:01.548172 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:61030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ops.php"] [unique_id "aoSAVdO5rbWdOArH04KCZgAAARk"] [Tue Aug 18 12:55:01.562264 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.100.201:58933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ot.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SAAAAnQ"] [Tue Aug 18 12:55:01.612964 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/default.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SgAAAkY"] [Tue Aug 18 12:55:01.621995 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:9021] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mirenax.com.br"] [uri "/1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SwAAAhY"] [Tue Aug 18 12:55:01.622095 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:9021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9SwAAAhY"] [Tue Aug 18 12:55:01.626749 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:7996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAVdO5rbWdOArH04KCaQAAAUM"] [Tue Aug 18 12:55:01.639618 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:14650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/index/function.php"] [unique_id "aoSAVdO5rbWdOArH04KCagAAARg"] [Tue Aug 18 12:55:01.669786 2026] [security2:error] [pid 67073:tid 67318] [client 138.36.100.162:42282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9TAAAAoU"] [Tue Aug 18 12:55:01.678202 2026] [security2:error] [pid 66623:tid 66829] [client 20.151.109.219:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qo.php"] [unique_id "aoSAVdO5rbWdOArH04KCawAAAUk"] [Tue Aug 18 12:55:01.761614 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAVdO5rbWdOArH04KCbgAAARU"] [Tue Aug 18 12:55:01.795185 2026] [security2:error] [pid 67073:tid 67279] [client 20.91.215.254:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UAAAAl4"] [Tue Aug 18 12:55:01.818935 2026] [security2:error] [pid 67073:tid 67215] [client 20.100.169.31:31054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UQAAAh4"] [Tue Aug 18 12:55:01.834988 2026] [security2:error] [pid 67073:tid 67280] [client 20.48.236.86:10650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/fz.php"] [unique_id "aoSAVfcmepr5_nHgLbM9UwAAAl8"] [Tue Aug 18 12:55:01.838142 2026] [security2:error] [pid 67073:tid 67219] [client 158.158.74.177:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evandrobene.com.br"] [uri "/media-new.php"] [unique_id "aoSAVfcmepr5_nHgLbM9VAAAAiI"] [Tue Aug 18 12:55:01.857098 2026] [security2:error] [pid 67073:tid 67258] [client 20.51.153.15:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/zs.php"] [unique_id "aoSAVfcmepr5_nHgLbM9VQAAAkk"] [Tue Aug 18 12:55:01.893287 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.100.201:21462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/v5.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WAAAAic"] [Tue Aug 18 12:55:01.924318 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/about.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WQAAAkM"] [Tue Aug 18 12:55:01.941021 2026] [security2:error] [pid 67073:tid 67254] [client 4.232.151.198:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSAVfcmepr5_nHgLbM9WgAAAkU"] [Tue Aug 18 12:55:01.963778 2026] [security2:error] [pid 67073:tid 67160] [remote 156.59.198.135:48720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tribunadolitoral.com"] [uri "/wp-content/uploads/2024/11/edital_PSS-Educacao-PR.pdf"] [unique_id "aoSAVfcmepr5_nHgLbM9WwACGVQ"] [Tue Aug 18 12:55:02.011645 2026] [security2:error] [pid 67073:tid 67237] [client 20.91.215.254:11744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XQAAAjQ"] [Tue Aug 18 12:55:02.028475 2026] [security2:error] [pid 67073:tid 67240] [client 104.209.144.33:20468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XgAAAjc"] [Tue Aug 18 12:55:02.064634 2026] [security2:error] [pid 67073:tid 67238] [client 20.171.51.14:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/97.php"] [unique_id "aoSAVvcmepr5_nHgLbM9XwAAAjU"] [Tue Aug 18 12:55:02.084651 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.133.44:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/Njima.php"] [unique_id "aoSAVvcmepr5_nHgLbM9YAAAAng"] [Tue Aug 18 12:55:02.188372 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.6.191:6599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cah.php"] [unique_id "aoSAVvcmepr5_nHgLbM9YwAAAik"] [Tue Aug 18 12:55:02.189006 2026] [security2:error] [pid 66623:tid 66893] [client 135.225.75.187:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAVtO5rbWdOArH04KCeAAAAYk"] [Tue Aug 18 12:55:02.305916 2026] [security2:error] [pid 67073:tid 67323] [client 5.31.227.224:7810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9ZwAAAoo"] [Tue Aug 18 12:55:02.310735 2026] [security2:error] [pid 67073:tid 67323] [client 5.31.227.224:7810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVvcmepr5_nHgLbM9ZwAAAoo"] [Tue Aug 18 12:55:02.388450 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:02.388701 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:02.405057 2026] [security2:error] [pid 66623:tid 66857] [client 20.29.77.16:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/dirs.php"] [unique_id "aoSAVtO5rbWdOArH04KCfAAAAWU"] [Tue Aug 18 12:55:02.418428 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/as.php"] [unique_id "aoSAVvcmepr5_nHgLbM9agAAAj0"] [Tue Aug 18 12:55:02.454948 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.136.165:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wdf.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bAAAAnw"] [Tue Aug 18 12:55:02.519422 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/system_log.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bgAAAnM"] [Tue Aug 18 12:55:02.555460 2026] [security2:error] [pid 67073:tid 67296] [client 20.100.169.31:39044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/k.php"] [unique_id "aoSAVvcmepr5_nHgLbM9bwAAAm8"] [Tue Aug 18 12:55:02.574604 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAVvcmepr5_nHgLbM9cAAAAiU"] [Tue Aug 18 12:55:02.587523 2026] [security2:error] [pid 67073:tid 67320] [client 52.139.47.57:27925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/atomlib.php"] [unique_id "aoSAVvcmepr5_nHgLbM9cQAAAoc"] [Tue Aug 18 12:55:02.659778 2026] [security2:error] [pid 67073:tid 67232] [client 4.232.151.198:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/u.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dAAAAi8"] [Tue Aug 18 12:55:02.662993 2026] [security2:error] [pid 67073:tid 67269] [client 20.104.100.201:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dQAAAlQ"] [Tue Aug 18 12:55:02.706941 2026] [security2:error] [pid 67073:tid 67099] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/i8hqok6nr.php"] [unique_id "aoSAVvcmepr5_nHgLbM9dgACjxc"] [Tue Aug 18 12:55:02.749042 2026] [security2:error] [pid 66623:tid 66776] [client 132.196.61.152:61039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/8.php"] [unique_id "aoSAVtO5rbWdOArH04KCgQAAARQ"] [Tue Aug 18 12:55:02.865140 2026] [security2:error] [pid 66623:tid 66794] [client 20.171.51.14:28816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rh.php"] [unique_id "aoSAVtO5rbWdOArH04KCgwAAASY"] [Tue Aug 18 12:55:02.869139 2026] [security2:error] [pid 67073:tid 67321] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/sp/limeira/jardim-colinas-de-sao-joao/img/avenida-luiz-berto-jardim-colinas-de-sao-joao-limeira-sp.webp"] [unique_id "aoSAVvcmepr5_nHgLbM9ewAAAog"] [Tue Aug 18 12:55:02.933473 2026] [security2:error] [pid 67073:tid 67227] [client 20.48.236.86:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/clque.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fQAAAio"] [Tue Aug 18 12:55:02.948466 2026] [security2:error] [pid 67073:tid 67318] [client 138.36.100.162:42282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAVfcmepr5_nHgLbM9TAAAAoU"] [Tue Aug 18 12:55:02.977436 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/item.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fgAAAhs"] [Tue Aug 18 12:55:02.994844 2026] [security2:error] [pid 67073:tid 67242] [client 20.116.17.175:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAVvcmepr5_nHgLbM9fwAAAjk"] [Tue Aug 18 12:55:03.016513 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.130.103:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gec.php"] [unique_id "aoSAV_cmepr5_nHgLbM9gAAAAnY"] [Tue Aug 18 12:55:03.019462 2026] [security2:error] [pid 67073:tid 67097] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/moon.php"] [unique_id "aoSAV_cmepr5_nHgLbM9gQACchU"] [Tue Aug 18 12:55:03.035058 2026] [security2:error] [pid 67073:tid 67266] [client 20.163.43.14:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/f35.php"] [unique_id "aoSAV_cmepr5_nHgLbM9ggAAAlE"] [Tue Aug 18 12:55:03.064330 2026] [security2:error] [pid 67073:tid 67308] [client 20.100.169.31:31430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSAV_cmepr5_nHgLbM9hAAAAns"] [Tue Aug 18 12:55:03.076330 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/edit.php"] [unique_id "aoSAV9O5rbWdOArH04KCiAAAAXQ"] [Tue Aug 18 12:55:03.323988 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAV9O5rbWdOArH04KCjwAAAVc"] [Tue Aug 18 12:55:03.326927 2026] [security2:error] [pid 66623:tid 66779] [client 20.151.109.219:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sd.php"] [unique_id "aoSAV9O5rbWdOArH04KCkAAAARc"] [Tue Aug 18 12:55:03.359175 2026] [security2:error] [pid 67073:tid 67325] [client 52.173.121.69:25012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAV_cmepr5_nHgLbM9igAAAow"] [Tue Aug 18 12:55:03.453498 2026] [security2:error] [pid 67073:tid 67312] [client 4.232.151.198:25820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/updates.php"] [unique_id "aoSAV_cmepr5_nHgLbM9jgAAAn8"] [Tue Aug 18 12:55:03.473217 2026] [security2:error] [pid 66623:tid 66789] [client 20.51.153.15:9167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/iz.php"] [unique_id "aoSAV9O5rbWdOArH04KClAAAASE"] [Tue Aug 18 12:55:03.496637 2026] [security2:error] [pid 66623:tid 66883] [client 149.34.210.141:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAV9O5rbWdOArH04KClgAAAX8"] [Tue Aug 18 12:55:03.505620 2026] [security2:error] [pid 66623:tid 66833] [client 20.250.27.191:1874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAV9O5rbWdOArH04KClwAAAU0"] [Tue Aug 18 12:55:03.515553 2026] [security2:error] [pid 67073:tid 67203] [remote 50.6.108.183:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.108.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSAV_cmepr5_nHgLbM9jAAChH8"] [Tue Aug 18 12:55:03.591763 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:03.592024 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:03.601446 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/sx.php"] [unique_id "aoSAV_cmepr5_nHgLbM9kgAAAlw"] [Tue Aug 18 12:55:03.633076 2026] [security2:error] [pid 67073:tid 67252] [client 135.225.75.187:23889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/z.php"] [unique_id "aoSAV_cmepr5_nHgLbM9lgAAAkM"] [Tue Aug 18 12:55:03.658197 2026] [security2:error] [pid 67073:tid 67290] [client 4.223.164.152:37289] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/uploads/"] [unique_id "aoSAV_cmepr5_nHgLbM9lwAAAmk"] [Tue Aug 18 12:55:03.659402 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.6.191:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mAAAAk8"] [Tue Aug 18 12:55:03.731849 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/km.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mQAAAjc"] [Tue Aug 18 12:55:03.736414 2026] [security2:error] [pid 66623:tid 66817] [client 4.232.151.198:37277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/goods.php"] [unique_id "aoSAV9O5rbWdOArH04KCmQAAAT0"] [Tue Aug 18 12:55:03.785380 2026] [security2:error] [pid 67073:tid 67310] [client 172.182.200.96:13824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/Cachex.php"] [unique_id "aoSAV_cmepr5_nHgLbM9mwAAAn0"] [Tue Aug 18 12:55:03.791568 2026] [security2:error] [pid 66623:tid 66883] [client 149.34.210.141:63963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAV9O5rbWdOArH04KClgAAAX8"] [Tue Aug 18 12:55:03.793377 2026] [security2:error] [pid 66623:tid 66818] [client 132.196.61.152:61020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/biufile.php"] [unique_id "aoSAV9O5rbWdOArH04KCmwAAAT4"] [Tue Aug 18 12:55:03.839984 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:3050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/22.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nQAAAng"] [Tue Aug 18 12:55:03.943160 2026] [security2:error] [pid 67073:tid 67306] [client 103.184.169.37:41488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nwAAAnk"] [Tue Aug 18 12:55:03.943294 2026] [security2:error] [pid 67073:tid 67306] [client 103.184.169.37:41488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAV_cmepr5_nHgLbM9nwAAAnk"] [Tue Aug 18 12:55:03.960786 2026] [security2:error] [pid 67073:tid 67258] [client 74.248.18.37:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/i.php"] [unique_id "aoSAV_cmepr5_nHgLbM9oQAAAkk"] [Tue Aug 18 12:55:03.964699 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.133.44:17534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/colors.php"] [unique_id "aoSAV_cmepr5_nHgLbM9ogAAAiM"] [Tue Aug 18 12:55:03.972830 2026] [security2:error] [pid 67073:tid 67228] [client 20.250.27.191:1900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAV_cmepr5_nHgLbM9owAAAis"] [Tue Aug 18 12:55:03.981229 2026] [security2:error] [pid 67073:tid 67324] [client 20.48.236.86:11028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/nano.php"] [unique_id "aoSAV_cmepr5_nHgLbM9pAAAAos"] [Tue Aug 18 12:55:03.998021 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.100.201:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSAV_cmepr5_nHgLbM9pgAAAoo"] [Tue Aug 18 12:55:04.027854 2026] [autoindex:error] [pid 67073:tid 67311] [client 3.86.142.91:56386] AH01276: Cannot serve directory /home4/vaicercom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:04.095225 2026] [security2:error] [pid 67073:tid 67130] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/motu.php"] [unique_id "aoSAWPcmepr5_nHgLbM9qQACZTY"] [Tue Aug 18 12:55:04.138845 2026] [security2:error] [pid 66623:tid 66792] [client 20.163.43.14:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/function/function.php"] [unique_id "aoSAWNO5rbWdOArH04KCqwAAASQ"] [Tue Aug 18 12:55:04.158498 2026] [security2:error] [pid 67073:tid 67221] [client 20.116.17.175:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-css.php"] [unique_id "aoSAWPcmepr5_nHgLbM9sQAAAiQ"] [Tue Aug 18 12:55:04.168732 2026] [security2:error] [pid 67073:tid 67259] [client 4.232.151.198:25800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSAWPcmepr5_nHgLbM9sgAAAko"] [Tue Aug 18 12:55:04.175100 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAWNO5rbWdOArH04KCrAAAAWE"] [Tue Aug 18 12:55:04.220641 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAWPcmepr5_nHgLbM9tAAAAhk"] [Tue Aug 18 12:55:04.287790 2026] [security2:error] [pid 66623:tid 66766] [client 104.209.144.33:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAWNO5rbWdOArH04KCrQAAAQo"] [Tue Aug 18 12:55:04.322698 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAWNO5rbWdOArH04KCrgAAATo"] [Tue Aug 18 12:55:04.338057 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.136.165:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ff1.php"] [unique_id "aoSAWNO5rbWdOArH04KCsQAAASs"] [Tue Aug 18 12:55:04.405700 2026] [security2:error] [pid 67073:tid 67171] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAWPcmepr5_nHgLbM9zwACb18"] [Tue Aug 18 12:55:04.444524 2026] [security2:error] [pid 67073:tid 67298] [client 74.248.18.37:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/test.php"] [unique_id "aoSAWPcmepr5_nHgLbM90AAAAnE"] [Tue Aug 18 12:55:04.566561 2026] [security2:error] [pid 66623:tid 66780] [client 20.29.77.16:49251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fresh.php"] [unique_id "aoSAWNO5rbWdOArH04KCtAAAARg"] [Tue Aug 18 12:55:04.691622 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:42542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/info.php"] [unique_id "aoSAWNO5rbWdOArH04KCuAAAARA"] [Tue Aug 18 12:55:04.792085 2026] [security2:error] [pid 67073:tid 67307] [client 20.104.100.201:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dk.php"] [unique_id "aoSAWPcmepr5_nHgLbM91wAAAno"] [Tue Aug 18 12:55:04.916840 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:58843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/yg.php"] [unique_id "aoSAWPcmepr5_nHgLbM93AAAAjk"] [Tue Aug 18 12:55:04.945525 2026] [security2:error] [pid 66623:tid 66805] [client 52.139.47.57:19934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/sid3.php"] [unique_id "aoSAWNO5rbWdOArH04KCvgAAATE"] [Tue Aug 18 12:55:05.097712 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:05.097990 2026] [authz_core:error] [pid 67073:tid 67125] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:05.176454 2026] [security2:error] [pid 67073:tid 67245] [client 172.202.39.151:33515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/index.php"] [unique_id "aoSAWfcmepr5_nHgLbM97gAAAjw"] [Tue Aug 18 12:55:05.322185 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/f35.php"] [unique_id "aoSAWfcmepr5_nHgLbM98AAAAn8"] [Tue Aug 18 12:55:05.325101 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAWdO5rbWdOArH04KCwAAAAXE"] [Tue Aug 18 12:55:05.399076 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:05.399344 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:05.408586 2026] [security2:error] [pid 66623:tid 66815] [client 52.238.210.254:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/bolt.php"] [unique_id "aoSAWdO5rbWdOArH04KCwgAAATs"] [Tue Aug 18 12:55:05.431979 2026] [security2:error] [pid 67073:tid 67219] [client 20.151.109.219:53224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mf.php"] [unique_id "aoSAWfcmepr5_nHgLbM98wAAAiI"] [Tue Aug 18 12:55:05.474814 2026] [security2:error] [pid 67073:tid 67277] [client 172.202.39.151:14692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAWfcmepr5_nHgLbM99AAAAlw"] [Tue Aug 18 12:55:05.494614 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:9041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/size.php"] [unique_id "aoSAWfcmepr5_nHgLbM99QAAAl4"] [Tue Aug 18 12:55:05.496498 2026] [security2:error] [pid 66623:tid 66831] [client 4.223.164.152:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAWdO5rbWdOArH04KCwwAAAUs"] [Tue Aug 18 12:55:05.516840 2026] [security2:error] [pid 67073:tid 67327] [client 20.91.215.254:27407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/st.php"] [unique_id "aoSAWfcmepr5_nHgLbM99gAAAo4"] [Tue Aug 18 12:55:05.699476 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:05.699746 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:05.733376 2026] [security2:error] [pid 67073:tid 67316] [client 52.238.210.254:8333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/222.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-AAAAoM"] [Tue Aug 18 12:55:05.740994 2026] [security2:error] [pid 67073:tid 67290] [client 192.141.172.134:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-QAAAmk"] [Tue Aug 18 12:55:05.741181 2026] [security2:error] [pid 67073:tid 67290] [client 192.141.172.134:56422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-QAAAmk"] [Tue Aug 18 12:55:05.769006 2026] [security2:error] [pid 67073:tid 67310] [client 20.250.27.191:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/blurbs.php"] [unique_id "aoSAWfcmepr5_nHgLbM9-gAAAn0"] [Tue Aug 18 12:55:05.805367 2026] [security2:error] [pid 66623:tid 66781] [client 213.35.127.232:54547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAWdO5rbWdOArH04KCxgAAARk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:05.820979 2026] [security2:error] [pid 66623:tid 66808] [client 135.225.75.187:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/222.php"] [unique_id "aoSAWdO5rbWdOArH04KCxwAAATQ"] [Tue Aug 18 12:55:05.840936 2026] [security2:error] [pid 67073:tid 67331] [client 20.163.43.14:3199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAWfcmepr5_nHgLbM9_gAAApI"] [Tue Aug 18 12:55:05.858460 2026] [security2:error] [pid 67073:tid 67275] [client 104.209.144.33:19589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAWfcmepr5_nHgLbM9_wAAAlo"] [Tue Aug 18 12:55:05.889453 2026] [security2:error] [pid 67073:tid 67217] [client 20.151.109.219:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ie.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AAAAAiA"] [Tue Aug 18 12:55:05.892206 2026] [security2:error] [pid 67073:tid 67301] [client 52.139.47.57:63050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/black.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AQAAAnQ"] [Tue Aug 18 12:55:05.944701 2026] [security2:error] [pid 67073:tid 67303] [client 74.248.18.37:12672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/test1.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AgAAAnY"] [Tue Aug 18 12:55:05.961483 2026] [security2:error] [pid 67073:tid 67278] [client 20.91.215.254:20402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAWfcmepr5_nHgLbM-AwAAAl0"] [Tue Aug 18 12:55:06.128946 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.100.201:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/bal.php"] [unique_id "aoSAWvcmepr5_nHgLbM-BQAAAjM"] [Tue Aug 18 12:55:06.152580 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.136.165:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/guk.php"] [unique_id "aoSAWvcmepr5_nHgLbM-BgAAAlI"] [Tue Aug 18 12:55:06.165393 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.133.44:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSAWtO5rbWdOArH04KCyAAAAWs"] [Tue Aug 18 12:55:06.169963 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/flox.php"] [unique_id "aoSAWtO5rbWdOArH04KCyQAAAW4"] [Tue Aug 18 12:55:06.216608 2026] [security2:error] [pid 66623:tid 66857] [client 4.232.151.198:6804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSAWtO5rbWdOArH04KCygAAAWU"] [Tue Aug 18 12:55:06.235855 2026] [security2:error] [pid 67073:tid 67309] [client 20.250.27.191:1901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/bajah.php"] [unique_id "aoSAWvcmepr5_nHgLbM-CQAAAnw"] [Tue Aug 18 12:55:06.355829 2026] [security2:error] [pid 67073:tid 67296] [client 20.104.85.180:18854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/403.php"] [unique_id "aoSAWvcmepr5_nHgLbM-DAAAAm8"] [Tue Aug 18 12:55:06.379507 2026] [security2:error] [pid 66623:tid 66794] [client 20.48.236.86:10781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "m2mit.info"] [uri "/.mopj.php"] [unique_id "aoSAWtO5rbWdOArH04KCywAAASY"] [Tue Aug 18 12:55:06.385646 2026] [security2:error] [pid 66623:tid 66851] [client 20.29.77.16:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/admin404.php"] [unique_id "aoSAWtO5rbWdOArH04KCzAAAAV8"] [Tue Aug 18 12:55:06.425272 2026] [security2:error] [pid 67073:tid 67273] [client 178.153.171.161:41304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM98QAAAlg"] [Tue Aug 18 12:55:06.425449 2026] [security2:error] [pid 67073:tid 67273] [client 178.153.171.161:41304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWfcmepr5_nHgLbM98QAAAlg"] [Tue Aug 18 12:55:06.440144 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:2511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zs.php"] [unique_id "aoSAWvcmepr5_nHgLbM-DQAAAiU"] [Tue Aug 18 12:55:06.600709 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:06.600989 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:06.683751 2026] [security2:error] [pid 67073:tid 67252] [client 114.5.214.109:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FAAAAkM"] [Tue Aug 18 12:55:06.683906 2026] [security2:error] [pid 67073:tid 67252] [client 114.5.214.109:49800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FAAAAkM"] [Tue Aug 18 12:55:06.700422 2026] [security2:error] [pid 67073:tid 67244] [client 20.250.27.191:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/domvf.php"] [unique_id "aoSAWvcmepr5_nHgLbM-FQAAAjs"] [Tue Aug 18 12:55:06.729148 2026] [security2:error] [pid 66623:tid 66812] [client 4.223.164.152:28518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAWtO5rbWdOArH04KC0QAAATg"] [Tue Aug 18 12:55:06.797347 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAWtO5rbWdOArH04KC0gAAAYM"] [Tue Aug 18 12:55:06.825146 2026] [security2:error] [pid 67073:tid 67208] [client 20.51.153.15:9172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/se.php"] [unique_id "aoSAWvcmepr5_nHgLbM-GwAAAhc"] [Tue Aug 18 12:55:06.942778 2026] [security2:error] [pid 67073:tid 67313] [client 20.100.169.31:31459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAWvcmepr5_nHgLbM-IQAAAoA"] [Tue Aug 18 12:55:06.959760 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/bengi.php"] [unique_id "aoSAWvcmepr5_nHgLbM-IgAAAjo"] [Tue Aug 18 12:55:07.088796 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/tgrs.php"] [unique_id "aoSAW_cmepr5_nHgLbM-IwAAAno"] [Tue Aug 18 12:55:07.160437 2026] [security2:error] [pid 67073:tid 67255] [client 20.250.27.191:1889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/fpwch.php"] [unique_id "aoSAW_cmepr5_nHgLbM-KwAAAkY"] [Tue Aug 18 12:55:07.308741 2026] [security2:error] [pid 67073:tid 67212] [client 20.91.215.254:27401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAW_cmepr5_nHgLbM-LQAAAhs"] [Tue Aug 18 12:55:07.337955 2026] [autoindex:error] [pid 66623:tid 66779] [client 172.202.39.151:65216] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:07.422869 2026] [security2:error] [pid 67073:tid 67183] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/ncx.php"] [unique_id "aoSAW_cmepr5_nHgLbM-MgACKGs"] [Tue Aug 18 12:55:07.520947 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAW_cmepr5_nHgLbM-NQAAAk8"] [Tue Aug 18 12:55:07.534557 2026] [security2:error] [pid 67073:tid 67228] [client 158.158.34.183:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/f5.php"] [unique_id "aoSAWvcmepr5_nHgLbM-EAAAAis"] [Tue Aug 18 12:55:07.626228 2026] [security2:error] [pid 67073:tid 67290] [client 20.65.98.162:38042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/mgrr.php"] [unique_id "aoSAW_cmepr5_nHgLbM-OwAAAmk"] [Tue Aug 18 12:55:07.653049 2026] [security2:error] [pid 67073:tid 67240] [client 20.48.236.86:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/file2.php"] [unique_id "aoSAW_cmepr5_nHgLbM-PAAAAjc"] [Tue Aug 18 12:55:07.703572 2026] [security2:error] [pid 67073:tid 67272] [client 104.209.144.33:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAW_cmepr5_nHgLbM-PwAAAlc"] [Tue Aug 18 12:55:07.812817 2026] [security2:error] [pid 67073:tid 67301] [client 20.42.19.40:9696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/av.php"] [unique_id "aoSAW_cmepr5_nHgLbM-QwAAAnQ"] [Tue Aug 18 12:55:07.820781 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:42975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/ws83.php"] [unique_id "aoSAW_cmepr5_nHgLbM-RAAAAl4"] [Tue Aug 18 12:55:07.939636 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form [Tue Aug 18 12:55:07.939654 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form [Tue Aug 18 12:55:07.939659 2026] [lsapi:error] [pid 67073:tid 67103] [remote 168.181.166.128:1505] [host riobrancoconsultorios.com.br] Client error on sending request(POST /agenda/painel/paginas/agendamentos/listar-horarios.php HTTP/2.0); uri(/agenda/painel/paginas/agendamentos/listar-horarios.php) content-length(59): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form [Tue Aug 18 12:55:08.049014 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:27432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-configs.php"] [unique_id "aoSAXPcmepr5_nHgLbM-TwAAAiA"] [Tue Aug 18 12:55:08.131323 2026] [security2:error] [pid 67073:tid 67275] [client 20.205.121.237:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/ty.php"] [unique_id "aoSAXPcmepr5_nHgLbM-UgAAAlo"] [Tue Aug 18 12:55:08.155321 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vp.php"] [unique_id "aoSAXPcmepr5_nHgLbM-UwAAAhk"] [Tue Aug 18 12:55:08.179036 2026] [security2:error] [pid 67073:tid 67311] [client 20.100.169.31:3019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAXPcmepr5_nHgLbM-VAAAAn4"] [Tue Aug 18 12:55:08.202606 2026] [security2:error] [pid 67073:tid 67300] [client 52.238.210.254:8908] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/cgi-bin/"] [unique_id "aoSAXPcmepr5_nHgLbM-VQAAAnM"] [Tue Aug 18 12:55:08.208507 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAXPcmepr5_nHgLbM-VgAAAlg"] [Tue Aug 18 12:55:08.349354 2026] [security2:error] [pid 67073:tid 67251] [client 74.248.18.37:17551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAXPcmepr5_nHgLbM-WAAAAkI"] [Tue Aug 18 12:55:08.354568 2026] [security2:error] [pid 67073:tid 67282] [client 20.29.77.16:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/loading.php"] [unique_id "aoSAXPcmepr5_nHgLbM-WQAAAmE"] [Tue Aug 18 12:55:08.493438 2026] [security2:error] [pid 67073:tid 67205] [client 20.48.236.86:10385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/gm.php"] [unique_id "aoSAXPcmepr5_nHgLbM-XQAAAhQ"] [Tue Aug 18 12:55:08.649867 2026] [security2:error] [pid 67073:tid 67121] [remote 14.194.153.54:39392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.153.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YAACiC0"] [Tue Aug 18 12:55:08.676120 2026] [security2:error] [pid 67073:tid 67243] [client 20.42.19.40:9719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YQAAAjo"] [Tue Aug 18 12:55:08.801794 2026] [security2:error] [pid 67073:tid 67242] [client 4.223.164.152:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file52.php"] [unique_id "aoSAXPcmepr5_nHgLbM-YwAAAjk"] [Tue Aug 18 12:55:08.938747 2026] [security2:error] [pid 67073:tid 67266] [client 20.250.27.191:1857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/adminner.php"] [unique_id "aoSAXPcmepr5_nHgLbM-ZwAAAlE"] [Tue Aug 18 12:55:09.028122 2026] [security2:error] [pid 66623:tid 66817] [client 132.196.61.152:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/coffexium.php"] [unique_id "aoSAXdO5rbWdOArH04KC2AAAAT0"] [Tue Aug 18 12:55:09.159289 2026] [security2:error] [pid 67073:tid 67312] [client 104.209.144.33:33718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bAAAAn8"] [Tue Aug 18 12:55:09.312226 2026] [authz_core:error] [pid 67073:tid 67177] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:09.312497 2026] [authz_core:error] [pid 67073:tid 67177] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:09.334024 2026] [security2:error] [pid 66623:tid 66872] [client 5.253.205.188:56868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/home.sql"] [unique_id "aoSAXdO5rbWdOArH04KC2wAAAXQ"], referer: https://medihub.com.br/home.sql [Tue Aug 18 12:55:09.406015 2026] [security2:error] [pid 67073:tid 67277] [client 20.250.27.191:1911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rafaelmachadocorretor.com.br"] [uri "/abcd.php"] [unique_id "aoSAXfcmepr5_nHgLbM-dAAAAlw"] [Tue Aug 18 12:55:09.429302 2026] [security2:error] [pid 67073:tid 67264] [client 52.173.121.69:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fAAAAk8"] [Tue Aug 18 12:55:09.477569 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yawa.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fgAAAk0"] [Tue Aug 18 12:55:09.520215 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.133.44:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/radio.php"] [unique_id "aoSAXfcmepr5_nHgLbM-fwAAAmQ"] [Tue Aug 18 12:55:09.546780 2026] [security2:error] [pid 67073:tid 67248] [client 20.29.77.16:20810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/conn-test.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gAAAAj8"] [Tue Aug 18 12:55:09.563524 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/abc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gQAAAnc"] [Tue Aug 18 12:55:09.584213 2026] [security2:error] [pid 67073:tid 67224] [client 20.163.43.14:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAXfcmepr5_nHgLbM-gwAAAic"] [Tue Aug 18 12:55:09.595328 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:12140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-post.php"] [unique_id "aoSAXfcmepr5_nHgLbM-hAAAAhc"] [Tue Aug 18 12:55:09.625643 2026] [security2:error] [pid 67073:tid 67272] [client 52.238.210.254:9039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/asasx.php"] [unique_id "aoSAXfcmepr5_nHgLbM-hQAAAlc"] [Tue Aug 18 12:55:09.629910 2026] [security2:error] [pid 66623:tid 66672] [remote 89.185.225.24:32892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boscoagriturismo.com"] [uri "/wp-login.php"] [unique_id "aoSAWtO5rbWdOArH04KCzgABeCM"] [Tue Aug 18 12:55:09.787746 2026] [security2:error] [pid 66623:tid 66836] [client 20.116.17.175:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/op.php"] [unique_id "aoSAXdO5rbWdOArH04KC3AAAAVA"] [Tue Aug 18 12:55:09.857929 2026] [security2:error] [pid 66623:tid 66892] [client 20.51.153.15:9204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/s.php"] [unique_id "aoSAXdO5rbWdOArH04KC3QAAAYg"] [Tue Aug 18 12:55:09.953221 2026] [security2:error] [pid 66623:tid 66801] [client 135.225.75.187:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/G-in.php"] [unique_id "aoSAXdO5rbWdOArH04KC3gAAAS0"] [Tue Aug 18 12:55:09.957926 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:16692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/style.php"] [unique_id "aoSAXfcmepr5_nHgLbM-jwAAAnA"] [Tue Aug 18 12:55:09.994680 2026] [security2:error] [pid 67073:tid 67230] [client 52.238.210.254:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/class-t.api.php"] [unique_id "aoSAXfcmepr5_nHgLbM-kAAAAi0"] [Tue Aug 18 12:55:10.036334 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.61.152:55311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/33.php"] [unique_id "aoSAXtO5rbWdOArH04KC3wAAAWk"] [Tue Aug 18 12:55:10.043877 2026] [security2:error] [pid 67073:tid 67267] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-jgACUn4"] [Tue Aug 18 12:55:10.214865 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:10.215134 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:10.268699 2026] [security2:error] [pid 66623:tid 66879] [client 158.158.34.183:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/al.php"] [unique_id "aoSAXtO5rbWdOArH04KC4AAAAXs"] [Tue Aug 18 12:55:10.300239 2026] [security2:error] [pid 66623:tid 66820] [client 20.250.13.23:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/a.php"] [unique_id "aoSAXtO5rbWdOArH04KC4QAAAUA"] [Tue Aug 18 12:55:10.310052 2026] [security2:error] [pid 67073:tid 67320] [client 20.42.19.40:9611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file2.php"] [unique_id "aoSAXvcmepr5_nHgLbM-mAAAAoc"] [Tue Aug 18 12:55:10.369714 2026] [security2:error] [pid 66623:tid 66730] [remote 162.240.105.3:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.105.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSAXtO5rbWdOArH04KC4gABOl0"] [Tue Aug 18 12:55:10.386254 2026] [security2:error] [pid 66623:tid 66795] [client 20.116.17.175:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAXtO5rbWdOArH04KC4wAAASc"] [Tue Aug 18 12:55:10.461799 2026] [security2:error] [pid 67073:tid 67282] [client 52.173.121.69:24969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAXvcmepr5_nHgLbM-nAAAAmE"] [Tue Aug 18 12:55:10.468822 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/ok.php"] [unique_id "aoSAXvcmepr5_nHgLbM-nQAAAkM"] [Tue Aug 18 12:55:10.506250 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ngAAAjI"] [Tue Aug 18 12:55:10.603324 2026] [security2:error] [pid 66623:tid 66849] [client 20.42.19.40:9686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/images/class-config.php"] [unique_id "aoSAXtO5rbWdOArH04KC5AAAAV0"] [Tue Aug 18 12:55:10.632164 2026] [security2:error] [pid 67073:tid 67250] [client 153.67.129.223:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.129.67.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bwAAAkE"] [Tue Aug 18 12:55:10.632299 2026] [security2:error] [pid 67073:tid 67250] [client 153.67.129.223:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "i-databi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXfcmepr5_nHgLbM-bwAAAkE"] [Tue Aug 18 12:55:10.659988 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ogAAAjA"] [Tue Aug 18 12:55:10.660078 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-ogAAAjA"] [Tue Aug 18 12:55:10.688574 2026] [security2:error] [pid 67073:tid 67247] [client 20.104.85.180:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/as.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pAAAAj4"] [Tue Aug 18 12:55:10.798075 2026] [security2:error] [pid 67073:tid 67249] [client 52.238.210.254:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/edit.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qAAAAkA"] [Tue Aug 18 12:55:10.819745 2026] [security2:error] [pid 67073:tid 67216] [client 20.104.100.201:58883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qQAAAh8"] [Tue Aug 18 12:55:10.852185 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.noise2.com.br"] [uri "/item.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qgAAAkY"] [Tue Aug 18 12:55:10.874290 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qwAAAmA"] [Tue Aug 18 12:55:10.970082 2026] [security2:error] [pid 66623:tid 66884] [client 135.225.75.187:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xxx.php"] [unique_id "aoSAXtO5rbWdOArH04KC5wAAAYA"] [Tue Aug 18 12:55:10.983907 2026] [security2:error] [pid 67073:tid 67276] [client 167.235.143.113:12324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAXvcmepr5_nHgLbM-rAAAAls"], referer: https://www.saojudas.com.br/ [Tue Aug 18 12:55:11.027708 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAX_cmepr5_nHgLbM-rQAAAjc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:11.110382 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.8:29896] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:11.110642 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.8:29896] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:11.118378 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:11.118627 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:11.167915 2026] [security2:error] [pid 67073:tid 67290] [client 172.182.200.96:14199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAX_cmepr5_nHgLbM-tAAAAmk"] [Tue Aug 18 12:55:11.182422 2026] [security2:error] [pid 67073:tid 67248] [client 104.209.144.33:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAX_cmepr5_nHgLbM-tQAAAj8"] [Tue Aug 18 12:55:11.205405 2026] [security2:error] [pid 66623:tid 66839] [client 20.100.169.31:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6AAAAVM"] [Tue Aug 18 12:55:11.245940 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:56718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-qwAAAmA"] [Tue Aug 18 12:55:11.272142 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:3658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2QAAAh4"] [Tue Aug 18 12:55:11.301275 2026] [security2:error] [pid 67073:tid 67302] [client 20.205.121.237:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/u.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2gAAAnU"] [Tue Aug 18 12:55:11.322156 2026] [security2:error] [pid 67073:tid 67265] [client 20.42.19.40:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/alfa.php"] [unique_id "aoSAX_cmepr5_nHgLbM-2wAAAlA"] [Tue Aug 18 12:55:11.424387 2026] [security2:error] [pid 67073:tid 67301] [client 213.202.253.4:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/postnews.php"] [unique_id "aoSAX_cmepr5_nHgLbM-3wAAAnQ"], referer: www.google.com [Tue Aug 18 12:55:11.457079 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:43183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6QAAAX4"] [Tue Aug 18 12:55:11.457214 2026] [security2:error] [pid 66623:tid 66882] [client 138.36.100.162:43183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX9O5rbWdOArH04KC6QAAAX4"] [Tue Aug 18 12:55:11.629640 2026] [security2:error] [pid 67073:tid 67306] [client 52.173.121.69:16507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4wAAAnk"] [Tue Aug 18 12:55:11.754126 2026] [security2:error] [pid 67073:tid 67254] [client 4.232.151.198:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/file.php"] [unique_id "aoSAX_cmepr5_nHgLbM-5gAAAkU"] [Tue Aug 18 12:55:11.773005 2026] [security2:error] [pid 67073:tid 67320] [client 52.238.210.254:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ff1.php"] [unique_id "aoSAX_cmepr5_nHgLbM-5wAAAoc"] [Tue Aug 18 12:55:11.849306 2026] [security2:error] [pid 67073:tid 67258] [client 20.250.13.23:51508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/chosen.php"] [unique_id "aoSAX_cmepr5_nHgLbM-6QAAAkk"] [Tue Aug 18 12:55:11.885654 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.56.190:45013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iz.php"] [unique_id "aoSAX9O5rbWdOArH04KC7AAAATM"] [Tue Aug 18 12:55:11.982657 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.61.152:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/dex.php"] [unique_id "aoSAX_cmepr5_nHgLbM-7gAAAmY"] [Tue Aug 18 12:55:12.007298 2026] [security2:error] [pid 67073:tid 67266] [client 3.79.134.69:4264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAX_cmepr5_nHgLbM-7AAAAlE"], referer: https://www.saojudas.com.br [Tue Aug 18 12:55:12.026454 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:8020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAYNO5rbWdOArH04KC7QAAATE"] [Tue Aug 18 12:55:12.040328 2026] [security2:error] [pid 67073:tid 67261] [client 52.139.47.57:42950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/bs1.php"] [unique_id "aoSAYPcmepr5_nHgLbM-8AAAAkw"] [Tue Aug 18 12:55:12.053202 2026] [security2:error] [pid 66623:tid 66834] [client 104.209.144.33:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAYNO5rbWdOArH04KC7gAAAU4"] [Tue Aug 18 12:55:12.063397 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9726] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "plantaodasbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAYNO5rbWdOArH04KC7wAAAQ4"] [Tue Aug 18 12:55:12.063470 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAYNO5rbWdOArH04KC7wAAAQ4"] [Tue Aug 18 12:55:12.088135 2026] [security2:error] [pid 66623:tid 66838] [client 4.223.164.152:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/geck.php"] [unique_id "aoSAYNO5rbWdOArH04KC8AAAAVI"] [Tue Aug 18 12:55:12.134578 2026] [security2:error] [pid 66623:tid 66893] [client 172.202.39.151:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/as.php"] [unique_id "aoSAYNO5rbWdOArH04KC8QAAAYk"] [Tue Aug 18 12:55:12.235037 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:12.235310 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:12.299254 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/sf.php"] [unique_id "aoSAYPcmepr5_nHgLbM-9wAAAlw"] [Tue Aug 18 12:55:12.306583 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/55.php"] [unique_id "aoSAYPcmepr5_nHgLbM--AAAApI"] [Tue Aug 18 12:55:12.373078 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAYNO5rbWdOArH04KC8gAAARU"] [Tue Aug 18 12:55:12.388327 2026] [security2:error] [pid 66623:tid 66885] [client 20.42.19.40:9681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAYNO5rbWdOArH04KC8wAAAYE"] [Tue Aug 18 12:55:12.400671 2026] [security2:error] [pid 67073:tid 67323] [client 158.158.34.183:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/inc.php"] [unique_id "aoSAYPcmepr5_nHgLbM--wAAAoo"] [Tue Aug 18 12:55:12.408915 2026] [security2:error] [pid 67073:tid 67310] [client 103.120.71.157:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_AAAAn0"] [Tue Aug 18 12:55:12.408995 2026] [security2:error] [pid 67073:tid 67310] [client 103.120.71.157:4697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_AAAAn0"] [Tue Aug 18 12:55:12.484640 2026] [security2:error] [pid 66623:tid 66712] [remote 20.237.251.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSAYNO5rbWdOArH04KC9gABDUs"] [Tue Aug 18 12:55:12.508023 2026] [security2:error] [pid 67073:tid 67222] [client 5.31.227.224:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_wAAAiU"] [Tue Aug 18 12:55:12.510798 2026] [security2:error] [pid 67073:tid 67222] [client 5.31.227.224:59022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYPcmepr5_nHgLbM-_wAAAiU"] [Tue Aug 18 12:55:12.548576 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:57033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAYNO5rbWdOArH04KC9wAAAWI"] [Tue Aug 18 12:55:12.558730 2026] [security2:error] [pid 67073:tid 67223] [client 172.182.200.96:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAYPcmepr5_nHgLbM_AgAAAiY"] [Tue Aug 18 12:55:12.570665 2026] [security2:error] [pid 67073:tid 67216] [client 20.171.51.14:28813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/md.php"] [unique_id "aoSAYPcmepr5_nHgLbM_AwAAAh8"] [Tue Aug 18 12:55:12.577834 2026] [security2:error] [pid 67073:tid 67273] [client 213.35.127.232:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BAAAAlg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:12.585681 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.133.44:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BQAAAmQ"] [Tue Aug 18 12:55:12.669885 2026] [security2:error] [pid 66623:tid 66794] [client 4.223.164.152:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/biufile.php"] [unique_id "aoSAYNO5rbWdOArH04KC-AAAASY"] [Tue Aug 18 12:55:12.688057 2026] [security2:error] [pid 66623:tid 66637] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/network.php"] [unique_id "aoSAYNO5rbWdOArH04KC-QABXAA"] [Tue Aug 18 12:55:12.724353 2026] [security2:error] [pid 67073:tid 67305] [client 20.100.169.31:25928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAYPcmepr5_nHgLbM_BwAAAng"] [Tue Aug 18 12:55:12.741907 2026] [security2:error] [pid 67073:tid 67275] [client 20.91.215.254:24811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp/images/my.php"] [unique_id "aoSAYPcmepr5_nHgLbM_CAAAAlo"] [Tue Aug 18 12:55:12.774712 2026] [security2:error] [pid 67073:tid 67314] [client 196.12.128.158:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pQAAAoE"] [Tue Aug 18 12:55:12.774859 2026] [security2:error] [pid 67073:tid 67314] [client 196.12.128.158:60475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAXvcmepr5_nHgLbM-pQAAAoE"] [Tue Aug 18 12:55:12.794117 2026] [security2:error] [pid 66623:tid 66847] [client 135.225.75.187:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/un.php"] [unique_id "aoSAYNO5rbWdOArH04KC_AAAAVs"] [Tue Aug 18 12:55:12.857494 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:1678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-the.php"] [unique_id "aoSAYPcmepr5_nHgLbM_CgAAAn8"] [Tue Aug 18 12:55:12.996704 2026] [security2:error] [pid 66623:tid 66723] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/new.php"] [unique_id "aoSAYNO5rbWdOArH04KC_wABdVY"] [Tue Aug 18 12:55:13.008699 2026] [security2:error] [pid 67073:tid 67262] [client 172.202.39.151:42996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-good.php"] [unique_id "aoSAYfcmepr5_nHgLbM_DgAAAk0"] [Tue Aug 18 12:55:13.009536 2026] [security2:error] [pid 66623:tid 66781] [client 4.232.151.198:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAYdO5rbWdOArH04KDAQAAARk"] [Tue Aug 18 12:55:13.014513 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.169.31:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAYfcmepr5_nHgLbM_DwAAAhs"] [Tue Aug 18 12:55:13.078530 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/asasx.php"] [unique_id "aoSAYfcmepr5_nHgLbM_EAAAAk8"] [Tue Aug 18 12:55:13.144183 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.6.191:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/abc.php"] [unique_id "aoSAYfcmepr5_nHgLbM_EQAAAhc"] [Tue Aug 18 12:55:13.211642 2026] [security2:error] [pid 66623:tid 66779] [client 20.48.236.86:10368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/ws55.php"] [unique_id "aoSAYdO5rbWdOArH04KDAgAAARc"] [Tue Aug 18 12:55:13.213914 2026] [security2:error] [pid 66623:tid 66773] [client 52.238.210.254:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/fff.php"] [unique_id "aoSAYdO5rbWdOArH04KDAwAAARE"] [Tue Aug 18 12:55:13.217479 2026] [security2:error] [pid 67073:tid 67316] [client 20.65.69.59:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/dirs.php"] [unique_id "aoSAYfcmepr5_nHgLbM_FAAAAoM"] [Tue Aug 18 12:55:13.253611 2026] [security2:error] [pid 66623:tid 66819] [client 20.205.121.237:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/ultra.php"] [unique_id "aoSAYdO5rbWdOArH04KDBAAAAT8"] [Tue Aug 18 12:55:13.431546 2026] [security2:error] [pid 66623:tid 66821] [client 20.42.19.40:9702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/filemanager.php"] [unique_id "aoSAYdO5rbWdOArH04KDBQAAAUE"] [Tue Aug 18 12:55:13.443600 2026] [security2:error] [pid 66623:tid 66790] [client 74.248.136.165:9756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/maxro.php"] [unique_id "aoSAYdO5rbWdOArH04KDBgAAASI"] [Tue Aug 18 12:55:13.674399 2026] [security2:error] [pid 67073:tid 67286] [client 213.35.127.232:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAYfcmepr5_nHgLbM_HQAAAmU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:13.702350 2026] [security2:error] [pid 66623:tid 66810] [client 74.248.18.37:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/text.php"] [unique_id "aoSAYdO5rbWdOArH04KDBwAAATY"] [Tue Aug 18 12:55:13.715632 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.98.162:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ajax.php"] [unique_id "aoSAYfcmepr5_nHgLbM_HwAAAi4"] [Tue Aug 18 12:55:13.725029 2026] [security2:error] [pid 66623:tid 66872] [client 20.42.19.40:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/themes.php"] [unique_id "aoSAYdO5rbWdOArH04KDCAAAAXQ"] [Tue Aug 18 12:55:13.737805 2026] [authz_core:error] [pid 67073:tid 67090] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:13.738070 2026] [authz_core:error] [pid 67073:tid 67090] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:13.810140 2026] [security2:error] [pid 67073:tid 67284] [client 172.202.39.151:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAYfcmepr5_nHgLbM_IQAAAmM"] [Tue Aug 18 12:55:13.912695 2026] [security2:error] [pid 67073:tid 67228] [client 20.51.153.15:9130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uo.php"] [unique_id "aoSAYfcmepr5_nHgLbM_IwAAAis"] [Tue Aug 18 12:55:13.944712 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/txets.php"] [unique_id "aoSAYdO5rbWdOArH04KDDQAAAYg"] [Tue Aug 18 12:55:13.974478 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:56123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.riosafe.com.br"] [uri "/packed.php"] [unique_id "aoSAYdO5rbWdOArH04KDDwAAAUQ"] [Tue Aug 18 12:55:14.138165 2026] [security2:error] [pid 67073:tid 67209] [client 157.20.138.62:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_JwAAAhg"] [Tue Aug 18 12:55:14.138299 2026] [security2:error] [pid 67073:tid 67209] [client 157.20.138.62:56740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_JwAAAhg"] [Tue Aug 18 12:55:14.166737 2026] [security2:error] [pid 67073:tid 67252] [client 20.251.48.93:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAYvcmepr5_nHgLbM_KQAAAkM"] [Tue Aug 18 12:55:14.170209 2026] [security2:error] [pid 66623:tid 66853] [client 20.104.100.201:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/7.php"] [unique_id "aoSAYtO5rbWdOArH04KDGgAAAWE"] [Tue Aug 18 12:55:14.200368 2026] [security2:error] [pid 66623:tid 66813] [client 104.209.144.33:29887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAYtO5rbWdOArH04KDIQAAATk"] [Tue Aug 18 12:55:14.261002 2026] [security2:error] [pid 66623:tid 66798] [client 52.139.47.57:16644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp-the.php"] [unique_id "aoSAYtO5rbWdOArH04KDIgAAASo"] [Tue Aug 18 12:55:14.272943 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.169.31:31444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/cong.php"] [unique_id "aoSAYtO5rbWdOArH04KDIwAAAS0"] [Tue Aug 18 12:55:14.379441 2026] [security2:error] [pid 66623:tid 66830] [client 20.205.121.237:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/up.php"] [unique_id "aoSAYtO5rbWdOArH04KDJAAAAUo"] [Tue Aug 18 12:55:14.449358 2026] [security2:error] [pid 67073:tid 67239] [client 20.48.236.86:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/m.php"] [unique_id "aoSAYvcmepr5_nHgLbM_MgAAAjY"] [Tue Aug 18 12:55:14.482566 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.136.165:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wdf.php"] [unique_id "aoSAYvcmepr5_nHgLbM_MwAAAjE"] [Tue Aug 18 12:55:14.542901 2026] [security2:error] [pid 67073:tid 67328] [client 103.184.169.37:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4AAAAo8"] [Tue Aug 18 12:55:14.543009 2026] [security2:error] [pid 67073:tid 67328] [client 103.184.169.37:41580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAX_cmepr5_nHgLbM-4AAAAo8"] [Tue Aug 18 12:55:14.620683 2026] [security2:error] [pid 67073:tid 67323] [client 20.171.51.14:16734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/iy.php"] [unique_id "aoSAYvcmepr5_nHgLbM_NAAAAoo"] [Tue Aug 18 12:55:14.629575 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.6.191:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/akcc.php"] [unique_id "aoSAYvcmepr5_nHgLbM_NQAAAj4"] [Tue Aug 18 12:55:14.678861 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:24967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAYtO5rbWdOArH04KDNgAAAVY"] [Tue Aug 18 12:55:14.741455 2026] [security2:error] [pid 67073:tid 67235] [client 20.29.77.16:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/evil.php"] [unique_id "aoSAYvcmepr5_nHgLbM_OQAAAjI"] [Tue Aug 18 12:55:14.756513 2026] [authz_core:error] [pid 67073:tid 67100] [remote 57.141.22.89:54638] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:14.756783 2026] [authz_core:error] [pid 67073:tid 67100] [remote 57.141.22.89:54638] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:14.824841 2026] [security2:error] [pid 67073:tid 67313] [client 52.139.47.57:42955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/plugin.php"] [unique_id "aoSAYvcmepr5_nHgLbM_OwAAAoA"] [Tue Aug 18 12:55:14.833955 2026] [security2:error] [pid 67073:tid 67254] [client 20.91.215.254:27437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/function.php"] [unique_id "aoSAYvcmepr5_nHgLbM_PAAAAkU"] [Tue Aug 18 12:55:14.847874 2026] [security2:error] [pid 66623:tid 66692] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/new4.php"] [unique_id "aoSAYtO5rbWdOArH04KDOgABHjc"] [Tue Aug 18 12:55:14.987884 2026] [security2:error] [pid 66623:tid 66882] [client 20.51.153.15:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kx.php"] [unique_id "aoSAYtO5rbWdOArH04KDOwAAAX4"] [Tue Aug 18 12:55:15.017125 2026] [security2:error] [pid 67073:tid 67321] [client 20.42.19.40:9721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAY_cmepr5_nHgLbM_PwAAAog"] [Tue Aug 18 12:55:15.076975 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.130.103:14447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/sky.php"] [unique_id "aoSAY9O5rbWdOArH04KDPAAAAYI"] [Tue Aug 18 12:55:15.257294 2026] [security2:error] [pid 66623:tid 66880] [client 20.251.48.93:9755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAY9O5rbWdOArH04KDPgAAAXw"] [Tue Aug 18 12:55:15.263432 2026] [security2:error] [pid 66623:tid 66797] [client 20.250.13.23:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAY9O5rbWdOArH04KDPwAAASk"] [Tue Aug 18 12:55:15.296956 2026] [security2:error] [pid 67073:tid 67310] [client 178.153.171.161:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_QwAAAn0"] [Tue Aug 18 12:55:15.297085 2026] [security2:error] [pid 67073:tid 67310] [client 178.153.171.161:48142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_QwAAAn0"] [Tue Aug 18 12:55:15.308750 2026] [security2:error] [pid 67073:tid 67257] [client 20.42.19.40:9628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAY_cmepr5_nHgLbM_RAAAAkg"] [Tue Aug 18 12:55:15.342050 2026] [security2:error] [pid 66623:tid 66893] [client 20.116.17.175:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/img.php"] [unique_id "aoSAY9O5rbWdOArH04KDQgAAAYk"] [Tue Aug 18 12:55:15.371056 2026] [security2:error] [pid 66623:tid 66774] [client 158.158.34.183:47533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAY9O5rbWdOArH04KDRAAAARI"] [Tue Aug 18 12:55:15.474666 2026] [security2:error] [pid 67073:tid 67330] [client 86.120.159.145:4805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_SAAAApE"] [Tue Aug 18 12:55:15.474783 2026] [security2:error] [pid 67073:tid 67330] [client 86.120.159.145:4805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAY_cmepr5_nHgLbM_SAAAApE"] [Tue Aug 18 12:55:15.545223 2026] [security2:error] [pid 67073:tid 67269] [client 4.232.151.198:30635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/404.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TQAAAlQ"] [Tue Aug 18 12:55:15.545244 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.69.59:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fresh.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TAAAAms"] [Tue Aug 18 12:55:15.548864 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.155.199:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/goods.php"] [unique_id "aoSAY_cmepr5_nHgLbM_TgAAAkE"] [Tue Aug 18 12:55:15.567464 2026] [security2:error] [pid 66623:tid 66807] [client 52.139.47.57:18479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/readme.php"] [unique_id "aoSAY9O5rbWdOArH04KDRQAAATM"] [Tue Aug 18 12:55:15.616628 2026] [security2:error] [pid 67073:tid 67279] [client 20.42.19.40:9711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UQAAAl4"] [Tue Aug 18 12:55:15.728342 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/va.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UgAAAiQ"] [Tue Aug 18 12:55:15.733863 2026] [security2:error] [pid 66623:tid 66775] [client 52.238.210.254:10225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/inputs.php"] [unique_id "aoSAY9O5rbWdOArH04KDRgAAARM"] [Tue Aug 18 12:55:15.813713 2026] [security2:error] [pid 67073:tid 67215] [client 20.91.215.254:27421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-2019.php"] [unique_id "aoSAY_cmepr5_nHgLbM_UwAAAh4"] [Tue Aug 18 12:55:15.820370 2026] [security2:error] [pid 67073:tid 67253] [client 20.104.100.201:21442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ws77.php"] [unique_id "aoSAY_cmepr5_nHgLbM_VQAAAkQ"] [Tue Aug 18 12:55:15.833970 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAY_cmepr5_nHgLbM_VgACjTc"] [Tue Aug 18 12:55:15.846125 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:15.846387 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:15.849634 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:2468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAY_cmepr5_nHgLbM_WAAAAig"] [Tue Aug 18 12:55:15.853014 2026] [security2:error] [pid 67073:tid 67311] [client 20.29.77.16:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-key.php"] [unique_id "aoSAY_cmepr5_nHgLbM_WQAAAn4"] [Tue Aug 18 12:55:15.869607 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:16491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAY9O5rbWdOArH04KDSAAAAUc"] [Tue Aug 18 12:55:15.871494 2026] [security2:error] [pid 66623:tid 66785] [client 20.171.51.14:33710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/og.php"] [unique_id "aoSAY9O5rbWdOArH04KDSQAAAR0"] [Tue Aug 18 12:55:15.959871 2026] [security2:error] [pid 67073:tid 67281] [client 185.191.171.1:55304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750938813/1751241600/"] [unique_id "aoSAY_cmepr5_nHgLbM_XQAAAmA"] [Tue Aug 18 12:55:15.959990 2026] [security2:error] [pid 67073:tid 67281] [client 185.191.171.1:55304] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750938813/1751241600/"] [unique_id "aoSAY_cmepr5_nHgLbM_XQAAAmA"] [Tue Aug 18 12:55:15.964086 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.98.162:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/uwu.php"] [unique_id "aoSAY_cmepr5_nHgLbM_XwAAAmI"] [Tue Aug 18 12:55:16.007368 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.emisetfilms.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDSgAAARY"] [Tue Aug 18 12:55:16.053020 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSAZNO5rbWdOArH04KDSwAAAXk"] [Tue Aug 18 12:55:16.102937 2026] [security2:error] [pid 66623:tid 66854] [client 52.139.47.57:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/chosen.php"] [unique_id "aoSAZNO5rbWdOArH04KDTgAAAWI"] [Tue Aug 18 12:55:16.147090 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.130.103:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/sixxis.php"] [unique_id "aoSAZNO5rbWdOArH04KDTwAAARQ"] [Tue Aug 18 12:55:16.157652 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.6.191:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wk/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDUAAAAUs"] [Tue Aug 18 12:55:16.293969 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:9946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ff1.php"] [unique_id "aoSAZPcmepr5_nHgLbM_aQAAAiM"] [Tue Aug 18 12:55:16.313158 2026] [security2:error] [pid 67073:tid 67266] [client 172.202.39.151:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-config-sample.php"] [unique_id "aoSAZPcmepr5_nHgLbM_awAAAlE"] [Tue Aug 18 12:55:16.327685 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.6.191:6641] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDUgAAAYY"] [Tue Aug 18 12:55:16.327797 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.6.191:6641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDUgAAAYY"] [Tue Aug 18 12:55:16.368434 2026] [security2:error] [pid 66623:tid 66856] [client 52.238.210.254:8949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoSAZNO5rbWdOArH04KDUwAAAWQ"] [Tue Aug 18 12:55:16.447016 2026] [security2:error] [pid 66623:tid 66819] [client 172.202.39.151:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/tes.php"] [unique_id "aoSAZNO5rbWdOArH04KDVAAAAT8"] [Tue Aug 18 12:55:16.575701 2026] [security2:error] [pid 66623:tid 66654] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/newfile.php"] [unique_id "aoSAZNO5rbWdOArH04KDVwABQRE"] [Tue Aug 18 12:55:16.590756 2026] [security2:error] [pid 66623:tid 66840] [client 157.51.166.53:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZNO5rbWdOArH04KDWQAAAVQ"] [Tue Aug 18 12:55:16.590883 2026] [security2:error] [pid 66623:tid 66840] [client 157.51.166.53:57081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZNO5rbWdOArH04KDWQAAAVQ"] [Tue Aug 18 12:55:16.605575 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dejavu.php"] [unique_id "aoSAZPcmepr5_nHgLbM_cgAAAiI"] [Tue Aug 18 12:55:16.659999 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.6.191:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDXAAAARw"] [Tue Aug 18 12:55:16.668358 2026] [security2:error] [pid 66623:tid 66817] [client 135.225.75.187:9302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/autogooey.php"] [unique_id "aoSAZNO5rbWdOArH04KDXQAAAT0"] [Tue Aug 18 12:55:16.681163 2026] [security2:error] [pid 66623:tid 66891] [client 20.116.17.175:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAZNO5rbWdOArH04KDXgAAAYc"] [Tue Aug 18 12:55:16.738083 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:12354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andaimetal.com.br"] [uri "/u.php"] [unique_id "aoSAZNO5rbWdOArH04KDYQAAATA"] [Tue Aug 18 12:55:16.759764 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.69.59:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/admin404.php"] [unique_id "aoSAZNO5rbWdOArH04KDYgAAAVU"] [Tue Aug 18 12:55:16.772082 2026] [security2:error] [pid 66623:tid 66663] [remote 178.156.200.16:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSAZNO5rbWdOArH04KDYAABOBo"] [Tue Aug 18 12:55:16.775746 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.61.152:60325] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDYwAAAXc"] [Tue Aug 18 12:55:16.775819 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.61.152:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1.php"] [unique_id "aoSAZNO5rbWdOArH04KDYwAAAXc"] [Tue Aug 18 12:55:16.825617 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dQACVjU"] [Tue Aug 18 12:55:16.854169 2026] [security2:error] [pid 66623:tid 66883] [client 20.226.6.191:6608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAZNO5rbWdOArH04KDZQAAAX8"] [Tue Aug 18 12:55:16.882316 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.98.162:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/yj09.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dgAAAjs"] [Tue Aug 18 12:55:16.885799 2026] [security2:error] [pid 66623:tid 66645] [remote 40.74.68.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.68.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1ba.com.br"] [uri "/nf.php"] [unique_id "aoSAZNO5rbWdOArH04KDZgABHwg"] [Tue Aug 18 12:55:16.897225 2026] [security2:error] [pid 67073:tid 67302] [client 160.120.140.123:57898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dwAAAnU"] [Tue Aug 18 12:55:16.897343 2026] [security2:error] [pid 67073:tid 67302] [client 160.120.140.123:57898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZPcmepr5_nHgLbM_dwAAAnU"] [Tue Aug 18 12:55:16.973692 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.7.189:9778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/666.php"] [unique_id "aoSAZPcmepr5_nHgLbM_eAAAAj4"] [Tue Aug 18 12:55:17.040549 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.130.103:14450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/yj09.php"] [unique_id "aoSAZfcmepr5_nHgLbM_egAAAiU"] [Tue Aug 18 12:55:17.069422 2026] [security2:error] [pid 67073:tid 67101] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/st.php"] [unique_id "aoSAZfcmepr5_nHgLbM_ewACJhk"] [Tue Aug 18 12:55:17.099066 2026] [security2:error] [pid 67073:tid 67277] [client 20.91.215.254:27442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/cjfuns.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fAAAAlw"] [Tue Aug 18 12:55:17.113675 2026] [security2:error] [pid 66623:tid 66872] [client 20.250.13.23:30401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/vx.php"] [unique_id "aoSAZdO5rbWdOArH04KDagAAAXQ"] [Tue Aug 18 12:55:17.136553 2026] [security2:error] [pid 66623:tid 66766] [client 4.223.164.152:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aaf.php"] [unique_id "aoSAZdO5rbWdOArH04KDbAAAAQo"] [Tue Aug 18 12:55:17.146994 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.7.189:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bgymj.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fQAAAjI"] [Tue Aug 18 12:55:17.231191 2026] [security2:error] [pid 67073:tid 67285] [client 20.226.6.191:6652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/as.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fgAAAmQ"] [Tue Aug 18 12:55:17.270712 2026] [security2:error] [pid 66623:tid 66799] [client 20.226.7.189:9015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bthil.php"] [unique_id "aoSAZdO5rbWdOArH04KDbQAAASs"] [Tue Aug 18 12:55:17.298940 2026] [security2:error] [pid 67073:tid 67327] [client 52.173.121.69:24978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAZfcmepr5_nHgLbM_fwAAAo4"] [Tue Aug 18 12:55:17.319304 2026] [security2:error] [pid 66623:tid 66853] [client 52.139.47.57:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/system.php"] [unique_id "aoSAZdO5rbWdOArH04KDbwAAAWE"] [Tue Aug 18 12:55:17.358516 2026] [security2:error] [pid 66623:tid 66842] [client 20.51.153.15:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fo.php"] [unique_id "aoSAZdO5rbWdOArH04KDcAAAAVY"] [Tue Aug 18 12:55:17.479078 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDcgAAAUI"] [Tue Aug 18 12:55:17.479208 2026] [security2:error] [pid 66623:tid 66822] [client 85.154.68.202:11203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDcgAAAUI"] [Tue Aug 18 12:55:17.491848 2026] [security2:error] [pid 66623:tid 66809] [client 158.158.34.183:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/x.php"] [unique_id "aoSAZdO5rbWdOArH04KDcwAAATU"] [Tue Aug 18 12:55:17.521420 2026] [security2:error] [pid 67073:tid 67246] [client 114.5.214.109:49801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oAAAAj0"] [Tue Aug 18 12:55:17.521501 2026] [security2:error] [pid 67073:tid 67246] [client 114.5.214.109:49801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oAAAAj0"] [Tue Aug 18 12:55:17.564683 2026] [security2:error] [pid 67073:tid 67224] [client 172.182.200.96:14167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAZfcmepr5_nHgLbM_oQAAAic"] [Tue Aug 18 12:55:17.646909 2026] [security2:error] [pid 67073:tid 67208] [client 20.251.48.93:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAZfcmepr5_nHgLbM_ogAAAhc"] [Tue Aug 18 12:55:17.695092 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:17.695349 2026] [authz_core:error] [pid 67073:tid 67093] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:17.696094 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.130.103:15385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/k.php"] [unique_id "aoSAZdO5rbWdOArH04KDdAAAASA"] [Tue Aug 18 12:55:17.726121 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:8818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ve.php"] [unique_id "aoSAZfcmepr5_nHgLbM_pQAAAiQ"] [Tue Aug 18 12:55:17.736189 2026] [security2:error] [pid 67073:tid 67297] [client 20.171.51.14:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lp.php"] [unique_id "aoSAZfcmepr5_nHgLbM_pgAAAnA"] [Tue Aug 18 12:55:17.756299 2026] [security2:error] [pid 67073:tid 67215] [client 172.202.39.151:28073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/files/index.php"] [unique_id "aoSAZfcmepr5_nHgLbM_qAAAAh4"] [Tue Aug 18 12:55:17.818203 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:35863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAZfcmepr5_nHgLbM_qwAAAnw"] [Tue Aug 18 12:55:17.835393 2026] [security2:error] [pid 66623:tid 66814] [client 192.141.172.134:57011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDdwAAATo"] [Tue Aug 18 12:55:17.835485 2026] [security2:error] [pid 66623:tid 66814] [client 192.141.172.134:57011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZdO5rbWdOArH04KDdwAAATo"] [Tue Aug 18 12:55:17.931552 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/lite.php"] [unique_id "aoSAZfcmepr5_nHgLbM_rwAAAnc"] [Tue Aug 18 12:55:18.018662 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.7.189:19164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xp.php"] [unique_id "aoSAZvcmepr5_nHgLbM_sAAAAkY"] [Tue Aug 18 12:55:18.032891 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAZtO5rbWdOArH04KDeAAAAXw"] [Tue Aug 18 12:55:18.049619 2026] [security2:error] [pid 67073:tid 67228] [client 20.116.17.175:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAZvcmepr5_nHgLbM_sQAAAis"] [Tue Aug 18 12:55:18.137026 2026] [security2:error] [pid 66623:tid 66806] [client 4.232.151.198:16024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wk/index.php"] [unique_id "aoSAZtO5rbWdOArH04KDeQAAATI"] [Tue Aug 18 12:55:18.220331 2026] [security2:error] [pid 66623:tid 66886] [client 20.100.169.31:31452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/db.php"] [unique_id "aoSAZtO5rbWdOArH04KDegAAAYI"] [Tue Aug 18 12:55:18.303002 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.7.189:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/reze.php"] [unique_id "aoSAZvcmepr5_nHgLbM_ugAAAmE"] [Tue Aug 18 12:55:18.392088 2026] [security2:error] [pid 67073:tid 67300] [client 20.29.77.16:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAZvcmepr5_nHgLbM_wQAAAnM"] [Tue Aug 18 12:55:18.422300 2026] [security2:error] [pid 66623:tid 66882] [client 52.139.47.57:44670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/wp-load.php"] [unique_id "aoSAZtO5rbWdOArH04KDewAAAX4"] [Tue Aug 18 12:55:18.453859 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.136.165:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/guk.php"] [unique_id "aoSAZtO5rbWdOArH04KDfAAAAXE"] [Tue Aug 18 12:55:18.528064 2026] [security2:error] [pid 67073:tid 67266] [client 20.205.121.237:5116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/upload.php"] [unique_id "aoSAZvcmepr5_nHgLbM_zgAAAlE"] [Tue Aug 18 12:55:18.531542 2026] [security2:error] [pid 67073:tid 67111] [remote 103.56.163.133:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faganelli.com.br.bergoninf.com"] [uri "/wp-login.php"] [unique_id "aoSAZvcmepr5_nHgLbM_zwACHyM"] [Tue Aug 18 12:55:18.540854 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:3753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/loading.php"] [unique_id "aoSAZvcmepr5_nHgLbM_0AAAAjI"] [Tue Aug 18 12:55:18.554235 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:18.554492 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:18.748524 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.133.44:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAZvcmepr5_nHgLbM_5gAAAmY"] [Tue Aug 18 12:55:18.756029 2026] [security2:error] [pid 67073:tid 67268] [client 132.196.61.152:61008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/coffee.php"] [unique_id "aoSAZvcmepr5_nHgLbM_5wAAAlM"] [Tue Aug 18 12:55:18.822363 2026] [security2:error] [pid 66623:tid 66777] [client 135.225.75.187:9337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sty.php"] [unique_id "aoSAZtO5rbWdOArH04KDfQAAARU"] [Tue Aug 18 12:55:18.862045 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:8864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ms-edit.php"] [unique_id "aoSAZvcmepr5_nHgLbM_8QAAAj0"] [Tue Aug 18 12:55:18.876377 2026] [security2:error] [pid 66623:tid 66815] [client 20.42.19.40:2205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/flower.php"] [unique_id "aoSAZtO5rbWdOArH04KDfwAAATs"] [Tue Aug 18 12:55:18.939467 2026] [security2:error] [pid 67073:tid 67297] [client 20.42.19.40:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/inputs.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9AAAAnA"] [Tue Aug 18 12:55:18.953482 2026] [security2:error] [pid 67073:tid 67215] [client 172.202.39.151:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9QAAAh4"] [Tue Aug 18 12:55:18.957543 2026] [security2:error] [pid 67073:tid 67296] [client 213.35.127.232:57303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAZvcmepr5_nHgLbM_9gAAAm8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:18.985788 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/le.php"] [unique_id "aoSAZvcmepr5_nHgLbM_-AACLHM"] [Tue Aug 18 12:55:18.992298 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.169.31:31451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAZvcmepr5_nHgLbM_-QAAApA"] [Tue Aug 18 12:55:19.010989 2026] [security2:error] [pid 67073:tid 67218] [client 20.163.43.14:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAZ_cmepr5_nHgLbM_-gAAAiE"] [Tue Aug 18 12:55:19.026271 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/inputs.php"] [unique_id "aoSAZ_cmepr5_nHgLbM_-wAAAhk"] [Tue Aug 18 12:55:19.035792 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.plenitude.com.br"] [uri "/files/8.php"] [unique_id "aoSAZ_cmepr5_nHgLbM__AAAAms"] [Tue Aug 18 12:55:19.108113 2026] [authz_core:error] [pid 67073:tid 67156] [remote 57.141.22.100:50894] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:19.108420 2026] [authz_core:error] [pid 67073:tid 67156] [remote 57.141.22.100:50894] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:19.153796 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.6.191:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAAAAAmU"] [Tue Aug 18 12:55:19.216387 2026] [security2:error] [pid 67073:tid 67272] [client 20.91.215.254:20677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAgAAAlc"] [Tue Aug 18 12:55:19.226623 2026] [security2:error] [pid 67073:tid 67140] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hr.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAAwACh0A"] [Tue Aug 18 12:55:19.228246 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/rip.php"] [unique_id "aoSAZ_cmepr5_nHgLbNABAAAAnc"] [Tue Aug 18 12:55:19.292399 2026] [security2:error] [pid 66623:tid 66827] [client 52.238.210.254:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/filemanager.php"] [unique_id "aoSAZ9O5rbWdOArH04KDgAAAAUc"] [Tue Aug 18 12:55:19.311100 2026] [security2:error] [pid 67073:tid 67261] [client 158.158.34.183:11420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/filemanager.php"] [unique_id "aoSAZ_cmepr5_nHgLbNABwAAAkw"] [Tue Aug 18 12:55:19.378167 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.130.103:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/w.php"] [unique_id "aoSAZ_cmepr5_nHgLbNACAAAAnk"] [Tue Aug 18 12:55:19.443370 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.98.162:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/signon.php"] [unique_id "aoSAZ_cmepr5_nHgLbNACgAAAis"] [Tue Aug 18 12:55:19.460953 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:19.461213 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:19.489930 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/inputs.php"] [unique_id "aoSAZ9O5rbWdOArH04KDggAAAWc"] [Tue Aug 18 12:55:19.531066 2026] [security2:error] [pid 67073:tid 67310] [client 196.12.128.158:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADAAAAn0"] [Tue Aug 18 12:55:19.531175 2026] [security2:error] [pid 67073:tid 67310] [client 196.12.128.158:61383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADAAAAn0"] [Tue Aug 18 12:55:19.672973 2026] [security2:error] [pid 66623:tid 66776] [client 20.42.19.40:9600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/100.php"] [unique_id "aoSAZ9O5rbWdOArH04KDgwAAARQ"] [Tue Aug 18 12:55:19.761611 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADwAAAkM"] [Tue Aug 18 12:55:19.765159 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:19.765530 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:19.821032 2026] [security2:error] [pid 67073:tid 67314] [client 178.156.185.231:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSAZ_cmepr5_nHgLbNADQACgU0"], referer: https://thatianysantana.com.br/ [Tue Aug 18 12:55:19.914120 2026] [security2:error] [pid 67073:tid 67302] [client 20.91.215.254:12660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/chosen.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAEgAAAnU"] [Tue Aug 18 12:55:19.933013 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kt.php"] [unique_id "aoSAZ_cmepr5_nHgLbNAEwACHx8"] [Tue Aug 18 12:55:19.979656 2026] [security2:error] [pid 66623:tid 66873] [client 172.182.200.96:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAZ9O5rbWdOArH04KDhAAAAXU"] [Tue Aug 18 12:55:20.016009 2026] [security2:error] [pid 67073:tid 67313] [client 20.42.19.40:9613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAFgAAAoA"] [Tue Aug 18 12:55:20.058545 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:20.058812 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:20.161497 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"] [Tue Aug 18 12:55:20.171910 2026] [security2:error] [pid 67073:tid 67307] [client 20.42.19.40:2719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/motu.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGgAAAno"] [Tue Aug 18 12:55:20.181067 2026] [security2:error] [pid 67073:tid 67187] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ww.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGwACKW8"] [Tue Aug 18 12:55:20.191758 2026] [fcgid:warn] [pid 66623:tid 66819] (70014)End of file found: [client 66.132.172.184:27208] mod_fcgid: can't get data from http client [Tue Aug 18 12:55:20.208789 2026] [security2:error] [pid 67073:tid 67322] [client 74.248.130.103:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHQAAAok"] [Tue Aug 18 12:55:20.255978 2026] [security2:error] [pid 67073:tid 67273] [client 78.47.98.55:37500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHAAAAlg"], referer: https://www.saojudas.com.br [Tue Aug 18 12:55:20.299259 2026] [security2:error] [pid 67073:tid 67239] [client 20.42.19.40:9725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSAaPcmepr5_nHgLbNAHwAAAjY"] [Tue Aug 18 12:55:20.306744 2026] [security2:error] [pid 67073:tid 67285] [client 52.139.47.57:16664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/colors/blue/about.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIAAAAmQ"] [Tue Aug 18 12:55:20.356913 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.61.152:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIQAAAic"] [Tue Aug 18 12:55:20.387950 2026] [security2:error] [pid 67073:tid 67207] [client 4.232.151.198:16053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/about.php"] [unique_id "aoSAaPcmepr5_nHgLbNAIwAAAhY"] [Tue Aug 18 12:55:20.490296 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/conn-test.php"] [unique_id "aoSAaPcmepr5_nHgLbNAKgAAAiw"] [Tue Aug 18 12:55:20.545531 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.136.165:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sbhu.php"] [unique_id "aoSAaPcmepr5_nHgLbNALAAAAms"] [Tue Aug 18 12:55:20.629854 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-the.php"] [unique_id "aoSAaPcmepr5_nHgLbNALwAAApE"] [Tue Aug 18 12:55:20.640480 2026] [security2:error] [pid 66623:tid 66860] [client 135.225.75.187:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wio.php"] [unique_id "aoSAaNO5rbWdOArH04KDiAAAAWg"] [Tue Aug 18 12:55:20.651081 2026] [security2:error] [pid 67073:tid 67286] [client 196.251.121.142:39420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/web/"] [unique_id "aoSAaPcmepr5_nHgLbNAMAAAAmU"] [Tue Aug 18 12:55:20.663881 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:20.664139 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:20.725688 2026] [security2:error] [pid 66623:tid 66841] [client 52.238.210.254:8926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/update/da222.php"] [unique_id "aoSAaNO5rbWdOArH04KDiQAAAVU"] [Tue Aug 18 12:55:20.744135 2026] [security2:error] [pid 67073:tid 67231] [client 20.29.77.16:20811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/mimes.php"] [unique_id "aoSAaPcmepr5_nHgLbNANAAAAi4"] [Tue Aug 18 12:55:20.779236 2026] [security2:error] [pid 67073:tid 67308] [client 213.35.127.232:58409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNANgAAAns"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:20.794115 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/alfa.php"] [unique_id "aoSAaPcmepr5_nHgLbNANwAAAjA"] [Tue Aug 18 12:55:20.844872 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.98.162:39993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/scxy.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOAAAAmI"] [Tue Aug 18 12:55:20.874563 2026] [security2:error] [pid 67073:tid 67260] [client 20.171.51.14:16759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/of.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOQAAAks"] [Tue Aug 18 12:55:20.942071 2026] [security2:error] [pid 67073:tid 67318] [client 197.184.64.235:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOgAAAoU"] [Tue Aug 18 12:55:20.942194 2026] [security2:error] [pid 67073:tid 67318] [client 197.184.64.235:41924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAOgAAAoU"] [Tue Aug 18 12:55:20.965944 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:20.966198 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:20.980733 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.18.37:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAaPcmepr5_nHgLbNAPAAAAnQ"] [Tue Aug 18 12:55:20.987749 2026] [security2:error] [pid 67073:tid 67261] [client 74.248.130.103:14462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/FWAZ.php"] [unique_id "aoSAaPcmepr5_nHgLbNAPQAAAkw"] [Tue Aug 18 12:55:21.022941 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSAafcmepr5_nHgLbNAPgAAAjg"] [Tue Aug 18 12:55:21.029696 2026] [security2:error] [pid 66623:tid 66883] [client 20.51.153.15:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ia.php"] [unique_id "aoSAadO5rbWdOArH04KDjAAAAX8"] [Tue Aug 18 12:55:21.085028 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSAafcmepr5_nHgLbNAQgAAAm4"] [Tue Aug 18 12:55:21.207981 2026] [security2:error] [pid 67073:tid 67220] [client 52.238.210.254:10193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/upload.php"] [unique_id "aoSAafcmepr5_nHgLbNAQwAAAiM"] [Tue Aug 18 12:55:21.265538 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:21.265817 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:21.369198 2026] [security2:error] [pid 67073:tid 67263] [client 132.196.61.152:60294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAafcmepr5_nHgLbNASQAAAk4"] [Tue Aug 18 12:55:21.388497 2026] [security2:error] [pid 67073:tid 67252] [client 20.51.153.15:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kn.php"] [unique_id "aoSAafcmepr5_nHgLbNASgAAAkM"] [Tue Aug 18 12:55:21.456741 2026] [autoindex:error] [pid 67073:tid 67302] [client 3.210.118.109:65379] AH01276: Cannot serve directory /home1/xsolutions/aceauto.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:21.535605 2026] [security2:error] [pid 67073:tid 67243] [client 213.202.253.4:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/postnews.php"] [unique_id "aoSAafcmepr5_nHgLbNAUQAAAjo"], referer: www.google.com [Tue Aug 18 12:55:21.544634 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.7.189:19190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/2026w.php"] [unique_id "aoSAadO5rbWdOArH04KDjgAAARw"] [Tue Aug 18 12:55:21.545748 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ey.php"] [unique_id "aoSAafcmepr5_nHgLbNAUgAAAjI"] [Tue Aug 18 12:55:21.566650 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:21.566918 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:21.605112 2026] [security2:error] [pid 67073:tid 67331] [client 20.42.19.40:9612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/php.php"] [unique_id "aoSAafcmepr5_nHgLbNAXwAAApI"] [Tue Aug 18 12:55:21.614690 2026] [security2:error] [pid 67073:tid 67289] [client 135.225.75.187:29107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/1061.php"] [unique_id "aoSAafcmepr5_nHgLbNAYQAAAmg"] [Tue Aug 18 12:55:21.671253 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.136.165:28664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sbhu.php"] [unique_id "aoSAafcmepr5_nHgLbNAZAAAAo4"] [Tue Aug 18 12:55:21.811623 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mo.php"] [unique_id "aoSAafcmepr5_nHgLbNAZQACWlk"] [Tue Aug 18 12:55:21.913947 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:38631] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "valeriana.com.br"] [uri "/1.php"] [unique_id "aoSAafcmepr5_nHgLbNAaAAAAk0"] [Tue Aug 18 12:55:21.914057 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:38631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/1.php"] [unique_id "aoSAafcmepr5_nHgLbNAaAAAAk0"] [Tue Aug 18 12:55:21.914962 2026] [security2:error] [pid 67073:tid 67279] [client 86.120.159.145:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAafcmepr5_nHgLbNAagAAAl4"] [Tue Aug 18 12:55:21.915057 2026] [security2:error] [pid 67073:tid 67279] [client 86.120.159.145:5067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAafcmepr5_nHgLbNAagAAAl4"] [Tue Aug 18 12:55:21.919671 2026] [security2:error] [pid 67073:tid 67268] [client 20.205.121.237:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/v5.php"] [unique_id "aoSAafcmepr5_nHgLbNAawAAAlM"] [Tue Aug 18 12:55:22.008484 2026] [security2:error] [pid 67073:tid 67303] [client 196.251.121.142:38934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/wfs"] [unique_id "aoSAavcmepr5_nHgLbNAbgAAAnY"] [Tue Aug 18 12:55:22.015166 2026] [security2:error] [pid 67073:tid 67219] [client 103.184.169.37:41633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAbwAAAiI"] [Tue Aug 18 12:55:22.015515 2026] [security2:error] [pid 67073:tid 67219] [client 103.184.169.37:41633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAbwAAAiI"] [Tue Aug 18 12:55:22.025463 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.7.189:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/2.php"] [unique_id "aoSAavcmepr5_nHgLbNAcAAAAo0"] [Tue Aug 18 12:55:22.033617 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qr.php"] [unique_id "aoSAavcmepr5_nHgLbNAcQACLFo"] [Tue Aug 18 12:55:22.118980 2026] [security2:error] [pid 67073:tid 67286] [client 20.171.51.14:29217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bu.php"] [unique_id "aoSAavcmepr5_nHgLbNAcwAAAmU"] [Tue Aug 18 12:55:22.237967 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.7.189:19174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/7.php"] [unique_id "aoSAavcmepr5_nHgLbNAdgAAAlQ"] [Tue Aug 18 12:55:22.271073 2026] [security2:error] [pid 67073:tid 67115] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dirs.php"] [unique_id "aoSAavcmepr5_nHgLbNAeQACLSc"] [Tue Aug 18 12:55:22.291551 2026] [security2:error] [pid 67073:tid 67294] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSAavcmepr5_nHgLbNAeAAAAm0"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 12:55:22.300893 2026] [security2:error] [pid 67073:tid 67296] [client 74.248.130.103:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/blurbs.php"] [unique_id "aoSAavcmepr5_nHgLbNAegAAAm8"] [Tue Aug 18 12:55:22.301434 2026] [security2:error] [pid 67073:tid 67281] [client 20.116.17.175:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSAavcmepr5_nHgLbNAewAAAmA"] [Tue Aug 18 12:55:22.332227 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAavcmepr5_nHgLbNAfAAAAlc"] [Tue Aug 18 12:55:22.342600 2026] [security2:error] [pid 66623:tid 66853] [client 20.42.19.40:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/t.php"] [unique_id "aoSAatO5rbWdOArH04KDkgAAAWE"] [Tue Aug 18 12:55:22.410890 2026] [security2:error] [pid 67073:tid 67309] [client 192.141.172.134:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAfwAAAnw"] [Tue Aug 18 12:55:22.410990 2026] [security2:error] [pid 67073:tid 67309] [client 192.141.172.134:57281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAavcmepr5_nHgLbNAfwAAAnw"] [Tue Aug 18 12:55:22.470318 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:22.470583 2026] [authz_core:error] [pid 67073:tid 67130] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:22.477307 2026] [security2:error] [pid 66623:tid 66861] [client 20.91.215.254:12751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/u.php"] [unique_id "aoSAatO5rbWdOArH04KDkwAAAWk"] [Tue Aug 18 12:55:22.483636 2026] [security2:error] [pid 67073:tid 67190] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sn.php"] [unique_id "aoSAavcmepr5_nHgLbNAggAChXI"] [Tue Aug 18 12:55:22.550784 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/lock360.php"] [unique_id "aoSAatO5rbWdOArH04KDlAAAAV0"] [Tue Aug 18 12:55:22.604740 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.7.189:10071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/10.php"] [unique_id "aoSAavcmepr5_nHgLbNAhQAAAmM"] [Tue Aug 18 12:55:22.613376 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.133.44:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/u.php"] [unique_id "aoSAavcmepr5_nHgLbNAhwAAAkc"] [Tue Aug 18 12:55:22.637362 2026] [autoindex:error] [pid 67073:tid 67295] [client 172.202.39.151:50212] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:22.639714 2026] [security2:error] [pid 67073:tid 67290] [client 20.42.19.40:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAavcmepr5_nHgLbNAiAAAAmk"] [Tue Aug 18 12:55:22.749141 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.6.191:7105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAavcmepr5_nHgLbNAiwAAAi8"] [Tue Aug 18 12:55:22.772073 2026] [security2:error] [pid 66623:tid 66772] [client 20.171.51.14:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rn.php"] [unique_id "aoSAatO5rbWdOArH04KDlwAAARA"] [Tue Aug 18 12:55:22.809402 2026] [security2:error] [pid 67073:tid 67276] [client 157.90.155.240:12502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSAavcmepr5_nHgLbNAjAAAAls"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 12:55:22.976219 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/flower.php"] [unique_id "aoSAatO5rbWdOArH04KDmQAAARg"] [Tue Aug 18 12:55:22.979742 2026] [security2:error] [pid 67073:tid 67253] [client 172.202.39.151:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/alfa.php"] [unique_id "aoSAavcmepr5_nHgLbNAqAAAAkQ"] [Tue Aug 18 12:55:22.980591 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.98.162:17054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file61.php"] [unique_id "aoSAavcmepr5_nHgLbNAqQAAAlw"] [Tue Aug 18 12:55:23.147747 2026] [security2:error] [pid 66623:tid 66835] [client 20.29.77.16:47765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAa9O5rbWdOArH04KDmgAAAU8"] [Tue Aug 18 12:55:23.192030 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.130.103:15378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/100.php"] [unique_id "aoSAa_cmepr5_nHgLbNArgAAAoA"] [Tue Aug 18 12:55:23.286196 2026] [security2:error] [pid 66623:tid 66806] [client 132.196.61.152:34753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mgrr.php"] [unique_id "aoSAa9O5rbWdOArH04KDmwAAATI"] [Tue Aug 18 12:55:23.305603 2026] [security2:error] [pid 67073:tid 67289] [client 20.163.43.14:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/public/css.php"] [unique_id "aoSAa_cmepr5_nHgLbNAwgAAAmg"] [Tue Aug 18 12:55:23.332602 2026] [authz_core:error] [pid 67073:tid 67172] [remote 57.141.22.37:44302] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:23.332868 2026] [authz_core:error] [pid 67073:tid 67172] [remote 57.141.22.37:44302] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:23.353111 2026] [security2:error] [pid 67073:tid 67218] [client 196.251.121.142:34138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/web/"] [unique_id "aoSAa_cmepr5_nHgLbNAxAAAAiE"] [Tue Aug 18 12:55:23.365299 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:2916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/404.php"] [unique_id "aoSAa_cmepr5_nHgLbNAxQAAAig"] [Tue Aug 18 12:55:23.393321 2026] [security2:error] [pid 66623:tid 66886] [client 52.238.210.254:35203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/themes.php"] [unique_id "aoSAa9O5rbWdOArH04KDngAAAYI"] [Tue Aug 18 12:55:23.422433 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lv.php"] [unique_id "aoSAa_cmepr5_nHgLbNAxwAAAo4"] [Tue Aug 18 12:55:23.484994 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.100.201:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/read.php"] [unique_id "aoSAa_cmepr5_nHgLbNAyAAAAok"] [Tue Aug 18 12:55:23.501029 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:50806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wap.php"] [unique_id "aoSAa_cmepr5_nHgLbNAyQAAAj8"] [Tue Aug 18 12:55:23.519744 2026] [security2:error] [pid 66623:tid 66893] [client 20.65.98.162:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ws13.php"] [unique_id "aoSAa9O5rbWdOArH04KDoAAAAYk"] [Tue Aug 18 12:55:23.597450 2026] [security2:error] [pid 66623:tid 66774] [client 20.51.153.15:8806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wm.php"] [unique_id "aoSAa9O5rbWdOArH04KDoQAAARI"] [Tue Aug 18 12:55:23.869000 2026] [security2:error] [pid 67073:tid 67242] [client 20.171.51.14:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ut.php"] [unique_id "aoSAa_cmepr5_nHgLbNA3gAAAjk"] [Tue Aug 18 12:55:23.957275 2026] [security2:error] [pid 67073:tid 67318] [client 20.42.19.40:9682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wk/index.php"] [unique_id "aoSAa_cmepr5_nHgLbNA5AAAAoU"] [Tue Aug 18 12:55:24.025011 2026] [security2:error] [pid 66623:tid 66815] [client 172.202.39.151:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/lock360.php"] [unique_id "aoSAbNO5rbWdOArH04KDpAAAATs"] [Tue Aug 18 12:55:24.159978 2026] [security2:error] [pid 67073:tid 67207] [client 52.139.47.57:13509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/con7.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8AAAAhY"] [Tue Aug 18 12:55:24.220967 2026] [security2:error] [pid 67073:tid 67311] [client 20.42.19.40:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lite.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8QAAAn4"] [Tue Aug 18 12:55:24.251049 2026] [security2:error] [pid 67073:tid 67319] [client 20.42.19.40:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-blink.php"] [unique_id "aoSAbPcmepr5_nHgLbNA8gAAAoY"] [Tue Aug 18 12:55:24.300251 2026] [security2:error] [pid 67073:tid 67212] [client 52.238.210.254:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wk/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNA9QAAAhs"] [Tue Aug 18 12:55:24.404825 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/155.php"] [unique_id "aoSAbPcmepr5_nHgLbNA-AAAAjM"] [Tue Aug 18 12:55:24.424727 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/13.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_QAAAoE"] [Tue Aug 18 12:55:24.441450 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/43.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_gACMn8"] [Tue Aug 18 12:55:24.465871 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAbPcmepr5_nHgLbNA_wAAAmg"] [Tue Aug 18 12:55:24.492044 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbNO5rbWdOArH04KDpwAAAUo"] [Tue Aug 18 12:55:24.492142 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:42724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbNO5rbWdOArH04KDpwAAAUo"] [Tue Aug 18 12:55:24.497507 2026] [security2:error] [pid 66623:tid 66775] [client 196.251.121.142:34140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "fbenevides.com"] [uri "/geoserver/wfs"] [unique_id "aoSAbNO5rbWdOArH04KDqQAAARM"] [Tue Aug 18 12:55:24.502161 2026] [security2:error] [pid 67073:tid 67293] [client 20.42.19.40:9629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/xfun.php"] [unique_id "aoSAbPcmepr5_nHgLbNBAAAAAmw"] [Tue Aug 18 12:55:24.514017 2026] [security2:error] [pid 66623:tid 66851] [client 20.251.48.93:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAbNO5rbWdOArH04KDqgAAAV8"] [Tue Aug 18 12:55:24.588242 2026] [security2:error] [pid 67073:tid 67284] [client 149.34.210.141:65378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCgAAAmM"] [Tue Aug 18 12:55:24.589861 2026] [security2:error] [pid 67073:tid 67275] [client 68.155.154.236:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCwAAAlo"] [Tue Aug 18 12:55:24.610019 2026] [security2:error] [pid 67073:tid 67224] [client 172.202.39.151:32402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNBDwAAAic"] [Tue Aug 18 12:55:24.611684 2026] [security2:error] [pid 66623:tid 66802] [client 172.182.200.96:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAbNO5rbWdOArH04KDzwAAAS4"] [Tue Aug 18 12:55:24.637949 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:2725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lock360.php"] [unique_id "aoSAbPcmepr5_nHgLbNBEwAAAnY"] [Tue Aug 18 12:55:24.667751 2026] [security2:error] [pid 67073:tid 67273] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCAACWCk"] [Tue Aug 18 12:55:24.672047 2026] [security2:error] [pid 67073:tid 67279] [client 4.232.151.198:18583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/inputs.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFQAAAl4"] [Tue Aug 18 12:55:24.678091 2026] [security2:error] [pid 67073:tid 67302] [client 157.20.138.62:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFgAAAnU"] [Tue Aug 18 12:55:24.678177 2026] [security2:error] [pid 67073:tid 67302] [client 157.20.138.62:57362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFgAAAnU"] [Tue Aug 18 12:55:24.703231 2026] [security2:error] [pid 67073:tid 67193] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fresh.php"] [unique_id "aoSAbPcmepr5_nHgLbNBFwACNHU"] [Tue Aug 18 12:55:24.747212 2026] [security2:error] [pid 66623:tid 66872] [client 4.232.151.198:41299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/term.php"] [unique_id "aoSAbNO5rbWdOArH04KD0QAAAXQ"] [Tue Aug 18 12:55:24.773343 2026] [security2:error] [pid 66623:tid 66831] [client 20.91.215.254:19535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/customize.php"] [unique_id "aoSAbNO5rbWdOArH04KD0gAAAUs"] [Tue Aug 18 12:55:24.773745 2026] [security2:error] [pid 66623:tid 66887] [client 20.104.100.201:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/albin.php"] [unique_id "aoSAbNO5rbWdOArH04KD0wAAAYM"] [Tue Aug 18 12:55:24.786799 2026] [security2:error] [pid 67073:tid 67269] [client 20.163.43.14:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGAAAAlQ"] [Tue Aug 18 12:55:24.791977 2026] [security2:error] [pid 67073:tid 67230] [client 20.42.19.40:9631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/p.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGQAAAi0"] [Tue Aug 18 12:55:24.813850 2026] [security2:error] [pid 66623:tid 66890] [client 20.163.43.14:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cc.php"] [unique_id "aoSAbNO5rbWdOArH04KD1AAAAYY"] [Tue Aug 18 12:55:24.835271 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.7.189:19178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/13.php"] [unique_id "aoSAbNO5rbWdOArH04KD1QAAAVM"] [Tue Aug 18 12:55:24.856037 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.7.189:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/100.php"] [unique_id "aoSAbNO5rbWdOArH04KD1gAAAQ0"] [Tue Aug 18 12:55:24.869258 2026] [security2:error] [pid 67073:tid 67284] [client 149.34.210.141:65378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBCgAAAmM"] [Tue Aug 18 12:55:24.884248 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ops.php"] [unique_id "aoSAbPcmepr5_nHgLbNBHQAAAoQ"] [Tue Aug 18 12:55:24.890965 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ac.php"] [unique_id "aoSAbPcmepr5_nHgLbNBHwAAAhk"] [Tue Aug 18 12:55:24.949456 2026] [security2:error] [pid 67073:tid 67250] [client 52.173.121.69:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIQAAAkE"] [Tue Aug 18 12:55:24.976629 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.7.189:18021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/222.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIgAAAos"] [Tue Aug 18 12:55:25.037524 2026] [security2:error] [pid 67073:tid 67205] [client 20.42.19.40:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAbfcmepr5_nHgLbNBJwAAAhQ"] [Tue Aug 18 12:55:25.069569 2026] [security2:error] [pid 66623:tid 66776] [client 52.139.47.57:18196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSAbdO5rbWdOArH04KD2gAAARQ"] [Tue Aug 18 12:55:25.087503 2026] [security2:error] [pid 67073:tid 67244] [client 20.104.100.201:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fw/34.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKQAAAjs"] [Tue Aug 18 12:55:25.093512 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/zc-318.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKgAAAkQ"] [Tue Aug 18 12:55:25.127849 2026] [security2:error] [pid 67073:tid 67328] [client 20.51.153.15:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yz.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLAAAAo8"] [Tue Aug 18 12:55:25.159161 2026] [security2:error] [pid 67073:tid 67310] [client 68.155.154.236:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLgAAAn0"] [Tue Aug 18 12:55:25.192953 2026] [security2:error] [pid 67073:tid 67148] [remote 129.121.103.155:33692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodosorrisosobral.com.br"] [uri "/wp-login.php"] [unique_id "aoSAbfcmepr5_nHgLbNBLwACQ0g"] [Tue Aug 18 12:55:25.217148 2026] [security2:error] [pid 67073:tid 67292] [client 20.251.48.93:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/xx.php"] [unique_id "aoSAbfcmepr5_nHgLbNBMAAAAms"] [Tue Aug 18 12:55:25.218332 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:21101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/eh.php"] [unique_id "aoSAbfcmepr5_nHgLbNBMQAAAo4"] [Tue Aug 18 12:55:25.280537 2026] [security2:error] [pid 67073:tid 67224] [client 20.42.19.40:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aaa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBNAAAAic"] [Tue Aug 18 12:55:25.285394 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.7.189:9759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAbdO5rbWdOArH04KD3QAAAVU"] [Tue Aug 18 12:55:25.304306 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.7.189:18632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/abcd.php"] [unique_id "aoSAbdO5rbWdOArH04KD3gAAAV4"] [Tue Aug 18 12:55:25.305220 2026] [security2:error] [pid 66623:tid 66824] [client 52.238.210.254:10184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-act.php"] [unique_id "aoSAbdO5rbWdOArH04KD3wAAAUQ"] [Tue Aug 18 12:55:25.308383 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbfcmepr5_nHgLbNBNgAAAk0"] [Tue Aug 18 12:55:25.318193 2026] [security2:error] [pid 66623:tid 66795] [client 20.48.236.86:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbdO5rbWdOArH04KD4AAAASc"] [Tue Aug 18 12:55:25.320595 2026] [security2:error] [pid 67073:tid 67248] [client 20.171.51.14:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/51.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOAAAAj8"] [Tue Aug 18 12:55:25.332010 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.7.189:38644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/al.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOgAAAnY"] [Tue Aug 18 12:55:25.332635 2026] [security2:error] [pid 67073:tid 67249] [client 4.223.164.152:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/mac.php"] [unique_id "aoSAbfcmepr5_nHgLbNBOwAAAkA"] [Tue Aug 18 12:55:25.351774 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.7.189:10741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/alfa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBPwAAAl4"] [Tue Aug 18 12:55:25.352567 2026] [security2:error] [pid 67073:tid 67102] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gj.php"] [unique_id "aoSAbfcmepr5_nHgLbNBQAACNBo"] [Tue Aug 18 12:55:25.371963 2026] [security2:error] [pid 67073:tid 67241] [client 20.100.169.31:31464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSAbfcmepr5_nHgLbNBQwAAAjg"] [Tue Aug 18 12:55:25.373105 2026] [security2:error] [pid 67073:tid 67330] [client 20.29.77.16:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/pqr.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRAAAApE"] [Tue Aug 18 12:55:25.374306 2026] [security2:error] [pid 66623:tid 66784] [client 20.226.7.189:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/as.php"] [unique_id "aoSAbdO5rbWdOArH04KD4QAAARw"] [Tue Aug 18 12:55:25.378728 2026] [security2:error] [pid 66623:tid 66791] [client 20.226.6.191:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAbdO5rbWdOArH04KD4gAAASM"] [Tue Aug 18 12:55:25.393451 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.7.189:19149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/aa.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRQAAAmU"] [Tue Aug 18 12:55:25.397134 2026] [security2:error] [pid 67073:tid 67315] [client 20.104.100.201:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp9.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRgAAAoI"] [Tue Aug 18 12:55:25.401397 2026] [security2:error] [pid 67073:tid 67233] [client 20.51.153.15:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kj.php"] [unique_id "aoSAbfcmepr5_nHgLbNBRwAAAjA"] [Tue Aug 18 12:55:25.411485 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.7.189:19141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/abc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSAAAAm8"] [Tue Aug 18 12:55:25.425455 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.61.152:61042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/55.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSgAAAoQ"] [Tue Aug 18 12:55:25.434955 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.7.189:9770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/av.php"] [unique_id "aoSAbfcmepr5_nHgLbNBSwAAAlc"] [Tue Aug 18 12:55:25.449641 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.34.183:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAbfcmepr5_nHgLbNBTQAAAh8"] [Tue Aug 18 12:55:25.470337 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.7.189:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAbfcmepr5_nHgLbNBTwAAAiw"] [Tue Aug 18 12:55:25.484526 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:25.484916 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:25.499910 2026] [security2:error] [pid 67073:tid 67256] [client 172.182.200.96:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAbfcmepr5_nHgLbNBUQAAAkc"] [Tue Aug 18 12:55:25.501109 2026] [security2:error] [pid 66623:tid 66858] [client 52.238.210.254:11579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAbdO5rbWdOArH04KD5AAAAWY"] [Tue Aug 18 12:55:25.513959 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.136.165:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ccou.php"] [unique_id "aoSAbfcmepr5_nHgLbNBUgAAAlI"] [Tue Aug 18 12:55:25.518610 2026] [security2:error] [pid 67073:tid 67331] [client 78.47.173.76:38174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNA5wAAApI"], referer: https://www.parquefazendadasflores.com.br [Tue Aug 18 12:55:25.521167 2026] [security2:error] [pid 66623:tid 66833] [client 20.226.7.189:10052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/asus.php"] [unique_id "aoSAbdO5rbWdOArH04KD5gAAAU0"] [Tue Aug 18 12:55:25.526461 2026] [autoindex:error] [pid 66623:tid 66876] [client 198.235.24.29:60974] AH01276: Cannot serve directory /home3/lidero37/novidades.lidero.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:25.537955 2026] [security2:error] [pid 67073:tid 67223] [client 135.225.75.187:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gec.php"] [unique_id "aoSAbfcmepr5_nHgLbNBVwAAAiY"] [Tue Aug 18 12:55:25.540749 2026] [security2:error] [pid 67073:tid 67255] [client 20.163.43.14:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAbfcmepr5_nHgLbNBWAAAAkY"] [Tue Aug 18 12:55:25.565081 2026] [security2:error] [pid 66623:tid 66823] [client 74.248.133.44:24761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/k.php"] [unique_id "aoSAbdO5rbWdOArH04KD5wAAAUM"] [Tue Aug 18 12:55:25.571501 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/about.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXAAAAhQ"] [Tue Aug 18 12:55:25.598764 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.7.189:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/atomlib.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXgAAAls"] [Tue Aug 18 12:55:25.599325 2026] [security2:error] [pid 67073:tid 67244] [client 20.42.19.40:1384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/term.php"] [unique_id "aoSAbfcmepr5_nHgLbNBXwAAAjs"] [Tue Aug 18 12:55:25.604804 2026] [security2:error] [pid 67073:tid 67083] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pd.php"] [unique_id "aoSAbfcmepr5_nHgLbNBYAACMwc"] [Tue Aug 18 12:55:25.608053 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAbdO5rbWdOArH04KD6AAAAWE"] [Tue Aug 18 12:55:25.615192 2026] [security2:error] [pid 66623:tid 66861] [client 20.48.236.86:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAbdO5rbWdOArH04KD6QAAAWk"] [Tue Aug 18 12:55:25.620319 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.7.189:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAbdO5rbWdOArH04KD6gAAAVk"] [Tue Aug 18 12:55:25.625797 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:14683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAbdO5rbWdOArH04KD6wAAAR4"] [Tue Aug 18 12:55:25.637826 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.7.189:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/b.php"] [unique_id "aoSAbdO5rbWdOArH04KD7QAAAVA"] [Tue Aug 18 12:55:25.639666 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAbdO5rbWdOArH04KD7gAAASg"] [Tue Aug 18 12:55:25.651642 2026] [security2:error] [pid 66623:tid 66772] [client 20.51.153.15:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vg.php"] [unique_id "aoSAbdO5rbWdOArH04KD7wAAARA"] [Tue Aug 18 12:55:25.659393 2026] [security2:error] [pid 66623:tid 66780] [client 20.226.7.189:18674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/buy.php"] [unique_id "aoSAbdO5rbWdOArH04KD8AAAARg"] [Tue Aug 18 12:55:25.669783 2026] [security2:error] [pid 67073:tid 67310] [client 20.91.215.254:12521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/mah/function.php"] [unique_id "aoSAbfcmepr5_nHgLbNBYgAAAn0"] [Tue Aug 18 12:55:25.682030 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.7.189:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bless.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZAAAAkM"] [Tue Aug 18 12:55:25.683482 2026] [security2:error] [pid 67073:tid 67215] [client 178.153.171.161:32465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZQAAAh4"] [Tue Aug 18 12:55:25.683581 2026] [security2:error] [pid 67073:tid 67215] [client 178.153.171.161:32465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbfcmepr5_nHgLbNBZQAAAh4"] [Tue Aug 18 12:55:25.702579 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.7.189:9772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAbdO5rbWdOArH04KD9gAAASk"] [Tue Aug 18 12:55:25.721954 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.7.189:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/cache.php"] [unique_id "aoSAbdO5rbWdOArH04KD9wAAAVI"] [Tue Aug 18 12:55:25.743002 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:38597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/content.php"] [unique_id "aoSAbfcmepr5_nHgLbNBaAAAAic"] [Tue Aug 18 12:55:25.750601 2026] [security2:error] [pid 67073:tid 67299] [client 20.116.17.175:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAbfcmepr5_nHgLbNBaQAAAnI"] [Tue Aug 18 12:55:25.762960 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.7.189:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAbfcmepr5_nHgLbNBagAAAjY"] [Tue Aug 18 12:55:25.782483 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:25.782757 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:25.785425 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.7.189:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/css.php"] [unique_id "aoSAbdO5rbWdOArH04KD-QAAATM"] [Tue Aug 18 12:55:25.802550 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.7.189:38601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/chosen.php"] [unique_id "aoSAbdO5rbWdOArH04KD-gAAATo"] [Tue Aug 18 12:55:25.826023 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/th.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbQACbgg"] [Tue Aug 18 12:55:25.828102 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.7.189:18019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/doc.php"] [unique_id "aoSAbdO5rbWdOArH04KD_gAAAR0"] [Tue Aug 18 12:55:25.830940 2026] [security2:error] [pid 67073:tid 67241] [client 20.104.100.201:58885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/save.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbgAAAjg"] [Tue Aug 18 12:55:25.849346 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:19156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/elp.php"] [unique_id "aoSAbfcmepr5_nHgLbNBbwAAApE"] [Tue Aug 18 12:55:25.852241 2026] [security2:error] [pid 67073:tid 67211] [client 20.42.19.40:9691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/7.php"] [unique_id "aoSAbfcmepr5_nHgLbNBcAAAAho"] [Tue Aug 18 12:55:25.862477 2026] [security2:error] [pid 66623:tid 66851] [client 4.223.164.152:64660] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "aoSAbdO5rbWdOArH04KD_wAAAV8"] [Tue Aug 18 12:55:25.867355 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.7.189:19185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/Exception-class.php"] [unique_id "aoSAbdO5rbWdOArH04KEAAAAAWs"] [Tue Aug 18 12:55:25.876019 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:13940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAbdO5rbWdOArH04KEAQAAAXA"] [Tue Aug 18 12:55:25.888666 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.7.189:19194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ee.php"] [unique_id "aoSAbfcmepr5_nHgLbNBdAAAAm0"] [Tue Aug 18 12:55:25.908383 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.7.189:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/edit.php"] [unique_id "aoSAbfcmepr5_nHgLbNBdQAAAoM"] [Tue Aug 18 12:55:25.927292 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.7.189:18667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/f35.php"] [unique_id "aoSAbdO5rbWdOArH04KEAwAAAS4"] [Tue Aug 18 12:55:25.931392 2026] [security2:error] [pid 66623:tid 66837] [client 74.248.136.165:27946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/txets.php"] [unique_id "aoSAbdO5rbWdOArH04KEBAAAAVE"] [Tue Aug 18 12:55:25.948610 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.7.189:18660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/fff.php"] [unique_id "aoSAbdO5rbWdOArH04KEBgAAAWU"] [Tue Aug 18 12:55:25.967518 2026] [security2:error] [pid 67073:tid 67317] [client 20.171.51.14:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ew.php"] [unique_id "aoSAbfcmepr5_nHgLbNBeQAAAoQ"] [Tue Aug 18 12:55:25.967555 2026] [security2:error] [pid 67073:tid 67266] [client 20.51.153.15:9137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sm.php"] [unique_id "aoSAbfcmepr5_nHgLbNBegAAAlE"] [Tue Aug 18 12:55:25.969680 2026] [security2:error] [pid 66623:tid 66872] [client 20.226.7.189:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ff1.php"] [unique_id "aoSAbdO5rbWdOArH04KECAAAAXQ"] [Tue Aug 18 12:55:25.978482 2026] [security2:error] [pid 66623:tid 66783] [client 20.205.121.237:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/w.php"] [unique_id "aoSAbdO5rbWdOArH04KECQAAARs"] [Tue Aug 18 12:55:25.988668 2026] [security2:error] [pid 67073:tid 67322] [client 20.163.43.14:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gelay.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfQAAAok"] [Tue Aug 18 12:55:25.991470 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.7.189:19151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/flower.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfgAAAig"] [Tue Aug 18 12:55:25.994945 2026] [security2:error] [pid 67073:tid 67274] [client 52.238.210.254:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAbfcmepr5_nHgLbNBfwAAAlk"] [Tue Aug 18 12:55:26.000620 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.169.31:2432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAbdO5rbWdOArH04KECgAAATE"] [Tue Aug 18 12:55:26.012559 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.7.189:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/file.php"] [unique_id "aoSAbvcmepr5_nHgLbNBgAAAAiw"] [Tue Aug 18 12:55:26.029315 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:9024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/dist/alfa-rex.php"] [unique_id "aoSAbvcmepr5_nHgLbNBgQAAAl4"] [Tue Aug 18 12:55:26.034032 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.7.189:11286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/goods.php"] [unique_id "aoSAbvcmepr5_nHgLbNBggAAAoA"] [Tue Aug 18 12:55:26.059319 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.7.189:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/g.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhQAAAnk"] [Tue Aug 18 12:55:26.063050 2026] [security2:error] [pid 67073:tid 67093] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/admin404.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhgACFhE"] [Tue Aug 18 12:55:26.063343 2026] [security2:error] [pid 67073:tid 67210] [client 4.232.151.198:42247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAbvcmepr5_nHgLbNBhwAAAhk"] [Tue Aug 18 12:55:26.080613 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.7.189:9226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNBiQAAAn4"] [Tue Aug 18 12:55:26.084144 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:26.084416 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:26.099271 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.98.162:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/copypaths.php"] [unique_id "aoSAbvcmepr5_nHgLbNBiwAAAls"] [Tue Aug 18 12:55:26.100972 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.7.189:19173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjAAAAoo"] [Tue Aug 18 12:55:26.107119 2026] [security2:error] [pid 67073:tid 67244] [client 132.196.61.152:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ajax.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjQAAAjs"] [Tue Aug 18 12:55:26.119969 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.7.189:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/in.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjgAAAlw"] [Tue Aug 18 12:55:26.122870 2026] [security2:error] [pid 66623:tid 66821] [client 20.42.19.40:9605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file5.php"] [unique_id "aoSAbtO5rbWdOArH04KEDAAAAUE"] [Tue Aug 18 12:55:26.125788 2026] [security2:error] [pid 66623:tid 66870] [client 20.163.43.14:4274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/01.php"] [unique_id "aoSAbtO5rbWdOArH04KEDQAAAXI"] [Tue Aug 18 12:55:26.139904 2026] [security2:error] [pid 66623:tid 66866] [client 20.65.98.162:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/btx25.php"] [unique_id "aoSAbtO5rbWdOArH04KEDgAAAW4"] [Tue Aug 18 12:55:26.142442 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.7.189:18639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/info.php"] [unique_id "aoSAbtO5rbWdOArH04KEDwAAAVQ"] [Tue Aug 18 12:55:26.150456 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.100.201:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSAbtO5rbWdOArH04KEEAAAAT0"] [Tue Aug 18 12:55:26.166367 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.7.189:11278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/inputs.php"] [unique_id "aoSAbtO5rbWdOArH04KEEwAAAWg"] [Tue Aug 18 12:55:26.168586 2026] [security2:error] [pid 66623:tid 66808] [client 114.119.137.70:46851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nacur.com.br"] [uri "/sitemap_index_13.xml"] [unique_id "aoSAbtO5rbWdOArH04KEFAAAATQ"] [Tue Aug 18 12:55:26.192652 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.7.189:19199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/item.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkAAAAl8"] [Tue Aug 18 12:55:26.213478 2026] [security2:error] [pid 67073:tid 67327] [client 20.226.7.189:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/k.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkgAAAo4"] [Tue Aug 18 12:55:26.223489 2026] [security2:error] [pid 67073:tid 67227] [client 20.251.48.93:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/av.php"] [unique_id "aoSAbvcmepr5_nHgLbNBkwAAAio"] [Tue Aug 18 12:55:26.232355 2026] [security2:error] [pid 67073:tid 67332] [client 20.226.7.189:10697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/license.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlAAAApM"] [Tue Aug 18 12:55:26.255027 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:9742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/load.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlgAAAic"] [Tue Aug 18 12:55:26.255961 2026] [security2:error] [pid 67073:tid 67248] [client 20.42.19.40:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAbvcmepr5_nHgLbNBlwAAAj8"] [Tue Aug 18 12:55:26.268301 2026] [security2:error] [pid 67073:tid 67303] [client 172.182.200.96:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmAAAAnY"] [Tue Aug 18 12:55:26.275096 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/manager.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmQAAAmM"] [Tue Aug 18 12:55:26.285940 2026] [security2:error] [pid 67073:tid 67208] [client 4.223.164.152:64667] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSAbvcmepr5_nHgLbNBmgAAAhc"] [Tue Aug 18 12:55:26.294047 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.7.189:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/media.php"] [unique_id "aoSAbtO5rbWdOArH04KEFQAAAV4"] [Tue Aug 18 12:55:26.307130 2026] [security2:error] [pid 67073:tid 67282] [client 20.51.153.15:9135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/28.php"] [unique_id "aoSAbvcmepr5_nHgLbNBmwAAAmE"] [Tue Aug 18 12:55:26.307651 2026] [security2:error] [pid 67073:tid 67295] [client 20.116.17.175:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/term.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnAAAAm4"] [Tue Aug 18 12:55:26.312115 2026] [security2:error] [pid 67073:tid 67241] [client 20.48.236.86:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnQAAAjg"] [Tue Aug 18 12:55:26.322734 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:38609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mar.php"] [unique_id "aoSAbvcmepr5_nHgLbNBnwAAApE"] [Tue Aug 18 12:55:26.337326 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAbtO5rbWdOArH04KEFwAAAUI"] [Tue Aug 18 12:55:26.342291 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.7.189:9250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/my1.php"] [unique_id "aoSAbvcmepr5_nHgLbNBoAAAAmU"] [Tue Aug 18 12:55:26.349443 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.136.165:9964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fun.php"] [unique_id "aoSAbvcmepr5_nHgLbNBoQAAAi0"] [Tue Aug 18 12:55:26.354050 2026] [security2:error] [pid 66623:tid 66816] [client 20.91.215.254:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/filter.php"] [unique_id "aoSAbtO5rbWdOArH04KEGAAAATw"] [Tue Aug 18 12:55:26.360842 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.7.189:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mm.php"] [unique_id "aoSAbvcmepr5_nHgLbNBpQAAAh0"] [Tue Aug 18 12:55:26.364111 2026] [security2:error] [pid 67073:tid 67123] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qo.php"] [unique_id "aoSAbvcmepr5_nHgLbNBpgACiC8"] [Tue Aug 18 12:55:26.381891 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:26.382179 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:26.382749 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.7.189:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/network.php"] [unique_id "aoSAbvcmepr5_nHgLbNBqgAAAjE"] [Tue Aug 18 12:55:26.385049 2026] [security2:error] [pid 67073:tid 67257] [client 20.42.19.40:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/makeasmtp.php"] [unique_id "aoSAbvcmepr5_nHgLbNBqwAAAkg"] [Tue Aug 18 12:55:26.390373 2026] [security2:error] [pid 67073:tid 67318] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSAbPcmepr5_nHgLbNBIAAChUQ"], referer: https://tecpolorefrigeracaosp.com.br/ [Tue Aug 18 12:55:26.402450 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.7.189:19156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/new.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrAAAAlc"] [Tue Aug 18 12:55:26.411239 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrQAAAoc"] [Tue Aug 18 12:55:26.422023 2026] [security2:error] [pid 67073:tid 67301] [client 20.226.7.189:19194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/0x.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrgAAAnQ"] [Tue Aug 18 12:55:26.429625 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.100.201:21470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbvcmepr5_nHgLbNBrwAAAok"] [Tue Aug 18 12:55:26.444183 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.7.189:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/0.php"] [unique_id "aoSAbvcmepr5_nHgLbNBsAAAAik"] [Tue Aug 18 12:55:26.463969 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.7.189:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/oxshell.php"] [unique_id "aoSAbvcmepr5_nHgLbNBsgAAAjk"] [Tue Aug 18 12:55:26.471675 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:36289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAbvcmepr5_nHgLbNBswAAAlo"] [Tue Aug 18 12:55:26.481432 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.7.189:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/php8.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtAAAAlI"] [Tue Aug 18 12:55:26.499319 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.7.189:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/p.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtQAAAmk"] [Tue Aug 18 12:55:26.517073 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:38604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/php.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtgAAAhQ"] [Tue Aug 18 12:55:26.534871 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.7.189:19143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/past.php"] [unique_id "aoSAbtO5rbWdOArH04KEGQAAAQw"] [Tue Aug 18 12:55:26.535556 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/weozh.php"] [unique_id "aoSAbvcmepr5_nHgLbNBtwAAAk8"] [Tue Aug 18 12:55:26.549251 2026] [security2:error] [pid 66623:tid 66858] [client 135.225.75.187:29079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/scx.php7"] [unique_id "aoSAbtO5rbWdOArH04KEGgAAAWY"] [Tue Aug 18 12:55:26.553912 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.7.189:19137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/root.php"] [unique_id "aoSAbvcmepr5_nHgLbNBuAAAAoo"] [Tue Aug 18 12:55:26.562518 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/lv.php"] [unique_id "aoSAbvcmepr5_nHgLbNBuQAAAjs"] [Tue Aug 18 12:55:26.595451 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.7.189:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/r.php"] [unique_id "aoSAbvcmepr5_nHgLbNBvAAAAlw"] [Tue Aug 18 12:55:26.598062 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sb.php"] [unique_id "aoSAbvcmepr5_nHgLbNBvgAAAj4"] [Tue Aug 18 12:55:26.620359 2026] [security2:error] [pid 66623:tid 66800] [client 172.182.200.96:14271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEGwAAASw"] [Tue Aug 18 12:55:26.623568 2026] [security2:error] [pid 66623:tid 66801] [client 52.238.210.254:8283] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/js/"] [unique_id "aoSAbtO5rbWdOArH04KEHAAAAS0"] [Tue Aug 18 12:55:26.628666 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:2444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/hplfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNBwQAAAlQ"] [Tue Aug 18 12:55:26.632211 2026] [security2:error] [pid 66623:tid 66823] [client 20.51.153.15:9100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/m.php"] [unique_id "aoSAbtO5rbWdOArH04KEHgAAAUM"] [Tue Aug 18 12:55:26.647236 2026] [security2:error] [pid 67073:tid 67108] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sd.php"] [unique_id "aoSAbvcmepr5_nHgLbNBywACISA"] [Tue Aug 18 12:55:26.649935 2026] [security2:error] [pid 67073:tid 67281] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbPcmepr5_nHgLbNBGgACYDI"] [Tue Aug 18 12:55:26.669022 2026] [security2:error] [pid 67073:tid 67319] [client 160.120.140.123:58461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNBzgAAAoY"] [Tue Aug 18 12:55:26.669179 2026] [security2:error] [pid 67073:tid 67319] [client 160.120.140.123:58461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNBzgAAAoY"] [Tue Aug 18 12:55:26.674388 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:65259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/flower.php"] [unique_id "aoSAbtO5rbWdOArH04KEIgAAAVg"] [Tue Aug 18 12:55:26.682098 2026] [security2:error] [pid 67073:tid 67287] [client 192.141.172.134:57571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0AAAAmY"] [Tue Aug 18 12:55:26.682231 2026] [security2:error] [pid 67073:tid 67287] [client 192.141.172.134:57571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0AAAAmY"] [Tue Aug 18 12:55:26.685182 2026] [security2:error] [pid 66623:tid 66849] [client 20.42.19.40:9676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEJAAAAV0"] [Tue Aug 18 12:55:26.687537 2026] [security2:error] [pid 66623:tid 66786] [client 20.171.51.14:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ad.php"] [unique_id "aoSAbtO5rbWdOArH04KEJQAAAR4"] [Tue Aug 18 12:55:26.697848 2026] [security2:error] [pid 66623:tid 66836] [client 20.48.236.86:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/av.php"] [unique_id "aoSAbtO5rbWdOArH04KEJgAAAVA"] [Tue Aug 18 12:55:26.721631 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:19180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sid3.php"] [unique_id "aoSAbvcmepr5_nHgLbNB0wAAAic"] [Tue Aug 18 12:55:26.735705 2026] [security2:error] [pid 67073:tid 67313] [client 74.248.18.37:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1AAAAoA"] [Tue Aug 18 12:55:26.739825 2026] [security2:error] [pid 67073:tid 67331] [client 85.154.68.202:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1QAAApI"] [Tue Aug 18 12:55:26.739950 2026] [security2:error] [pid 67073:tid 67331] [client 85.154.68.202:11529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAbvcmepr5_nHgLbNB1QAAApI"] [Tue Aug 18 12:55:26.748217 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.7.189:10698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ss.php"] [unique_id "aoSAbtO5rbWdOArH04KEJwAAATU"] [Tue Aug 18 12:55:26.768061 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.136.165:30925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/jq.php"] [unique_id "aoSAbvcmepr5_nHgLbNB2AAAAm4"] [Tue Aug 18 12:55:26.769608 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sts.php"] [unique_id "aoSAbtO5rbWdOArH04KEKgAAAUA"] [Tue Aug 18 12:55:26.787958 2026] [security2:error] [pid 66623:tid 66806] [client 20.171.51.14:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pqr.php"] [unique_id "aoSAbtO5rbWdOArH04KEKwAAATI"] [Tue Aug 18 12:55:26.791188 2026] [security2:error] [pid 67073:tid 67211] [client 20.226.7.189:38609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/shell.php"] [unique_id "aoSAbvcmepr5_nHgLbNB2wAAAho"] [Tue Aug 18 12:55:26.794893 2026] [security2:error] [pid 66623:tid 66797] [client 4.223.164.152:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAbtO5rbWdOArH04KELAAAASk"] [Tue Aug 18 12:55:26.813173 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.7.189:38654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/setup-config.php"] [unique_id "aoSAbtO5rbWdOArH04KELQAAAXs"] [Tue Aug 18 12:55:26.816886 2026] [security2:error] [pid 67073:tid 67230] [client 52.173.121.69:17940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3AAAAi0"] [Tue Aug 18 12:55:26.821190 2026] [security2:error] [pid 66623:tid 66826] [client 172.182.200.96:14129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAbtO5rbWdOArH04KELgAAAUY"] [Tue Aug 18 12:55:26.834288 2026] [security2:error] [pid 66623:tid 66869] [client 20.226.7.189:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/t.php"] [unique_id "aoSAbtO5rbWdOArH04KELwAAAXE"] [Tue Aug 18 12:55:26.835317 2026] [security2:error] [pid 66623:tid 66782] [client 157.90.155.240:28410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSAbtO5rbWdOArH04KEHQAAARo"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 12:55:26.839885 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3QAAAh0"] [Tue Aug 18 12:55:26.850952 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.100.201:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/df.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3gAAAjE"] [Tue Aug 18 12:55:26.856601 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.7.189:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/up.php"] [unique_id "aoSAbvcmepr5_nHgLbNB3wAAAhs"] [Tue Aug 18 12:55:26.865143 2026] [security2:error] [pid 66623:tid 66799] [client 5.253.205.188:48236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/install.bak"] [unique_id "aoSAbtO5rbWdOArH04KEMAAAASs"], referer: https://medihub.com.br/install.bak [Tue Aug 18 12:55:26.871497 2026] [security2:error] [pid 67073:tid 67169] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/km.php"] [unique_id "aoSAbvcmepr5_nHgLbNB4AACZF0"] [Tue Aug 18 12:55:26.875115 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.7.189:9781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ultra.php"] [unique_id "aoSAbtO5rbWdOArH04KEMwAAAXo"] [Tue Aug 18 12:55:26.924142 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:9168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nl.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5AAAAlc"] [Tue Aug 18 12:55:26.925181 2026] [security2:error] [pid 66623:tid 66871] [client 20.42.19.40:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAbtO5rbWdOArH04KENQAAAXM"] [Tue Aug 18 12:55:26.942331 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:21676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xj.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5QAAAoQ"] [Tue Aug 18 12:55:26.971517 2026] [security2:error] [pid 67073:tid 67307] [client 4.232.151.198:42284] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "uniaoac.com.br"] [uri "/1.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6AAAAno"] [Tue Aug 18 12:55:26.971634 2026] [security2:error] [pid 67073:tid 67307] [client 4.232.151.198:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/1.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6AAAAno"] [Tue Aug 18 12:55:26.980956 2026] [security2:error] [pid 67073:tid 67226] [client 20.163.43.14:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/new.php"] [unique_id "aoSAbvcmepr5_nHgLbNB6wAAAik"] [Tue Aug 18 12:55:26.989972 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.130.103:15415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ccc.php"] [unique_id "aoSAbtO5rbWdOArH04KENgAAAR0"] [Tue Aug 18 12:55:26.989973 2026] [security2:error] [pid 67073:tid 67330] [client 20.91.215.254:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/input.php"] [unique_id "aoSAbvcmepr5_nHgLbNB7AAAApE"] [Tue Aug 18 12:55:27.015941 2026] [security2:error] [pid 67073:tid 67327] [client 20.205.121.237:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/we.php"] [unique_id "aoSAb_cmepr5_nHgLbNB7QAAAo4"] [Tue Aug 18 12:55:27.021697 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.6.191:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAb9O5rbWdOArH04KENwAAAV8"] [Tue Aug 18 12:55:27.064732 2026] [security2:error] [pid 66623:tid 66877] [client 172.182.200.96:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAb9O5rbWdOArH04KEOAAAAXk"] [Tue Aug 18 12:55:27.097628 2026] [security2:error] [pid 66623:tid 66773] [client 4.232.151.198:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/admin.php"] [unique_id "aoSAb9O5rbWdOArH04KEOQAAARE"] [Tue Aug 18 12:55:27.098491 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.69.59:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/evil.php"] [unique_id "aoSAb9O5rbWdOArH04KEOgAAASI"] [Tue Aug 18 12:55:27.121155 2026] [security2:error] [pid 67073:tid 67216] [client 78.46.190.63:1296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNB5wAAAh8"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 12:55:27.135743 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.100.201:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSAb_cmepr5_nHgLbNB7wAAAhY"] [Tue Aug 18 12:55:27.137210 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/vd.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8AAAAhk"] [Tue Aug 18 12:55:27.145328 2026] [security2:error] [pid 67073:tid 67254] [client 20.48.236.86:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/images.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8QAAAkU"] [Tue Aug 18 12:55:27.151145 2026] [security2:error] [pid 67073:tid 67258] [client 132.196.61.152:61054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/yj09.php"] [unique_id "aoSAb_cmepr5_nHgLbNB8wAAAkk"] [Tue Aug 18 12:55:27.158958 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.154.236:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/rymmm.php"] [unique_id "aoSAb_cmepr5_nHgLbNB9gAAAkY"] [Tue Aug 18 12:55:27.159589 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/atomlib.php"] [unique_id "aoSAb_cmepr5_nHgLbNB9wAAAk8"] [Tue Aug 18 12:55:27.168500 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.34.183:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-AAAAi4"] [Tue Aug 18 12:55:27.168956 2026] [security2:error] [pid 67073:tid 67276] [client 20.251.48.93:31792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/media.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-QAAAls"] [Tue Aug 18 12:55:27.176192 2026] [security2:error] [pid 67073:tid 67323] [client 20.116.17.175:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/black.php"] [unique_id "aoSAb_cmepr5_nHgLbNB-wAAAoo"] [Tue Aug 18 12:55:27.179425 2026] [security2:error] [pid 67073:tid 67253] [client 135.225.75.187:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_AAAAkQ"] [Tue Aug 18 12:55:27.180254 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mf.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_QACOyI"] [Tue Aug 18 12:55:27.185022 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.136.165:9516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sys.php"] [unique_id "aoSAb_cmepr5_nHgLbNB_gAAAjo"] [Tue Aug 18 12:55:27.193211 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:10176] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSAb_cmepr5_nHgLbNB_wAAAnc"] [Tue Aug 18 12:55:27.198085 2026] [security2:error] [pid 67073:tid 67329] [client 20.51.153.15:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/68.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAAAAApA"] [Tue Aug 18 12:55:27.224797 2026] [security2:error] [pid 66623:tid 66846] [client 4.223.164.152:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAb9O5rbWdOArH04KEPAAAAVo"] [Tue Aug 18 12:55:27.243227 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAgAAAhg"] [Tue Aug 18 12:55:27.248137 2026] [security2:error] [pid 67073:tid 67209] [client 5.31.227.224:7851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCAgAAAhg"] [Tue Aug 18 12:55:27.259993 2026] [security2:error] [pid 66623:tid 66802] [client 20.100.169.31:31450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/htaccess.php"] [unique_id "aoSAb9O5rbWdOArH04KEPQAAAS4"] [Tue Aug 18 12:55:27.262935 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.169.31:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/inputs.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBAAAAi8"] [Tue Aug 18 12:55:27.283514 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.98.162:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBgAAAh4"] [Tue Aug 18 12:55:27.327726 2026] [security2:error] [pid 67073:tid 67326] [client 20.151.109.219:59727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ns.php"] [unique_id "aoSAb_cmepr5_nHgLbNCBwAAAo0"] [Tue Aug 18 12:55:27.345254 2026] [security2:error] [pid 67073:tid 67246] [client 157.51.166.53:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCCgAAAj0"] [Tue Aug 18 12:55:27.345459 2026] [security2:error] [pid 67073:tid 67246] [client 157.51.166.53:57722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAb_cmepr5_nHgLbNCCgAAAj0"] [Tue Aug 18 12:55:27.368465 2026] [security2:error] [pid 67073:tid 67250] [client 47.128.22.69:32722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "terrassis.com.br"] [uri "/robots.txt"] [unique_id "aoSAb_cmepr5_nHgLbNCDQAAAkE"] [Tue Aug 18 12:55:27.397853 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:9649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/min.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEQAAAmU"] [Tue Aug 18 12:55:27.399911 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:13537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/elementor/wp-login.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEgAAAns"] [Tue Aug 18 12:55:27.418063 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ie.php"] [unique_id "aoSAb_cmepr5_nHgLbNCEwACHWg"] [Tue Aug 18 12:55:27.435751 2026] [security2:error] [pid 67073:tid 67233] [client 172.182.200.96:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFQAAAjA"] [Tue Aug 18 12:55:27.440498 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.100.201:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/usr.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFgAAAjE"] [Tue Aug 18 12:55:27.442984 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.169.31:12291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/2.php"] [unique_id "aoSAb_cmepr5_nHgLbNCFwAAAkc"] [Tue Aug 18 12:55:27.473602 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/222.php"] [unique_id "aoSAb9O5rbWdOArH04KEPwAAAX0"] [Tue Aug 18 12:55:27.479340 2026] [security2:error] [pid 66623:tid 66819] [client 20.42.19.40:2723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-links-opml.php"] [unique_id "aoSAb9O5rbWdOArH04KEQAAAAT8"] [Tue Aug 18 12:55:27.481400 2026] [security2:error] [pid 66623:tid 66867] [client 20.51.153.15:9111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/jl.php"] [unique_id "aoSAb9O5rbWdOArH04KEQQAAAW8"] [Tue Aug 18 12:55:27.515342 2026] [security2:error] [pid 67073:tid 67223] [client 20.48.236.86:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ops.php"] [unique_id "aoSAb_cmepr5_nHgLbNCGQAAAiY"] [Tue Aug 18 12:55:27.531274 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAb_cmepr5_nHgLbNCHAAAAoc"] [Tue Aug 18 12:55:27.602990 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.136.165:17066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/pp.php"] [unique_id "aoSAb9O5rbWdOArH04KEQwAAAVQ"] [Tue Aug 18 12:55:27.615946 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.130.103:15371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/get.php"] [unique_id "aoSAb_cmepr5_nHgLbNCIAAAAl4"] [Tue Aug 18 12:55:27.630396 2026] [security2:error] [pid 67073:tid 67263] [client 74.7.241.149:60512] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "brooklynmodamasculina.com.br"] [uri "/index.php"] [unique_id "aoSAbfcmepr5_nHgLbNBKAACTm0"] [Tue Aug 18 12:55:27.650506 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nw.php"] [unique_id "aoSAb_cmepr5_nHgLbNCIgACUgA"] [Tue Aug 18 12:55:27.678150 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.85.180:8040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAb9O5rbWdOArH04KERQAAAUw"] [Tue Aug 18 12:55:27.698450 2026] [security2:error] [pid 66623:tid 66777] [client 20.42.19.40:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/mac.php"] [unique_id "aoSAb9O5rbWdOArH04KERwAAARU"] [Tue Aug 18 12:55:27.700492 2026] [security2:error] [pid 67073:tid 67328] [client 78.46.190.63:1290] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSAbvcmepr5_nHgLbNBjwAAAo8"], referer: http://ancavisi.com.br/ [Tue Aug 18 12:55:27.716417 2026] [security2:error] [pid 67073:tid 67205] [client 20.51.153.15:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tq.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJQAAAhQ"] [Tue Aug 18 12:55:27.721847 2026] [security2:error] [pid 67073:tid 67318] [client 78.46.190.63:57566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJAAAAoU"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 12:55:27.741514 2026] [security2:error] [pid 67073:tid 67317] [client 20.91.215.254:12416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/jquery.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJgAAAoQ"] [Tue Aug 18 12:55:27.765103 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.100.201:58490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSAb9O5rbWdOArH04KESAAAAWc"] [Tue Aug 18 12:55:27.766732 2026] [security2:error] [pid 67073:tid 67255] [client 20.29.77.16:33001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAb_cmepr5_nHgLbNCJwAAAkY"] [Tue Aug 18 12:55:27.776744 2026] [security2:error] [pid 67073:tid 67231] [client 52.238.210.254:8832] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/maint/"] [unique_id "aoSAb_cmepr5_nHgLbNCKQAAAi4"] [Tue Aug 18 12:55:27.783978 2026] [security2:error] [pid 66623:tid 66841] [client 172.182.200.96:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAb9O5rbWdOArH04KESQAAAVU"] [Tue Aug 18 12:55:27.843242 2026] [security2:error] [pid 66623:tid 66811] [client 4.223.164.152:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/system_log.php"] [unique_id "aoSAb9O5rbWdOArH04KESgAAATc"] [Tue Aug 18 12:55:27.855420 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sb.php"] [unique_id "aoSAb_cmepr5_nHgLbNCLAACkHc"] [Tue Aug 18 12:55:27.883960 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:3016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/images/wso.php"] [unique_id "aoSAb9O5rbWdOArH04KEUQAAAWg"] [Tue Aug 18 12:55:27.888437 2026] [security2:error] [pid 67073:tid 67209] [client 20.163.43.14:4225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/chosen.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMQAAAhg"] [Tue Aug 18 12:55:27.888620 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:27.888805 2026] [security2:error] [pid 66623:tid 66865] [client 20.151.109.219:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gk.php"] [unique_id "aoSAb9O5rbWdOArH04KEUgAAAW0"] [Tue Aug 18 12:55:27.888881 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:27.914933 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.7.189:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/vv.php"] [unique_id "aoSAb9O5rbWdOArH04KEVAAAASc"] [Tue Aug 18 12:55:27.933804 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/about.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMgAAAmA"] [Tue Aug 18 12:55:27.934438 2026] [security2:error] [pid 67073:tid 67292] [client 20.116.17.175:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/as.php"] [unique_id "aoSAb_cmepr5_nHgLbNCMwAAAms"] [Tue Aug 18 12:55:27.943085 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:9604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/nc4.php"] [unique_id "aoSAb9O5rbWdOArH04KEVQAAARw"] [Tue Aug 18 12:55:27.944546 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.7.189:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/V5.php"] [unique_id "aoSAb_cmepr5_nHgLbNCNQAAAiE"] [Tue Aug 18 12:55:27.949700 2026] [authz_core:error] [pid 67073:tid 67201] [remote 57.141.22.35:43122] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:27.950058 2026] [authz_core:error] [pid 67073:tid 67201] [remote 57.141.22.35:43122] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:27.967860 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.7.189:22756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-user.php"] [unique_id "aoSAb9O5rbWdOArH04KEVgAAATk"] [Tue Aug 18 12:55:27.983790 2026] [security2:error] [pid 67073:tid 67248] [client 20.51.153.15:9089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/cv.php"] [unique_id "aoSAb_cmepr5_nHgLbNCOAAAAj8"] [Tue Aug 18 12:55:27.988050 2026] [security2:error] [pid 66623:tid 66893] [client 20.48.236.86:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/coffexium.php"] [unique_id "aoSAb9O5rbWdOArH04KEVwAAAYk"] [Tue Aug 18 12:55:27.989478 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.7.189:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAb_cmepr5_nHgLbNCOQAAAk0"] [Tue Aug 18 12:55:27.996057 2026] [autoindex:error] [pid 67073:tid 67332] [client 20.104.85.180:7983] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:28.014411 2026] [security2:error] [pid 66623:tid 66804] [client 20.226.7.189:22773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp.php"] [unique_id "aoSAcNO5rbWdOArH04KEWAAAATA"] [Tue Aug 18 12:55:28.019929 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.136.165:29064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wqqs.php"] [unique_id "aoSAcNO5rbWdOArH04KEWQAAAQw"] [Tue Aug 18 12:55:28.036561 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.7.189:19158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/worksec.php"] [unique_id "aoSAcPcmepr5_nHgLbNCOwAAAj0"] [Tue Aug 18 12:55:28.040386 2026] [security2:error] [pid 66623:tid 66833] [client 20.104.100.201:58910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/css/database.php"] [unique_id "aoSAcNO5rbWdOArH04KEWgAAAU0"] [Tue Aug 18 12:55:28.051578 2026] [security2:error] [pid 67073:tid 67258] [client 20.205.121.237:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wk/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPAAAAkk"] [Tue Aug 18 12:55:28.058376 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.7.189:22780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAcNO5rbWdOArH04KEWwAAAXg"] [Tue Aug 18 12:55:28.062133 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.69.59:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-key.php"] [unique_id "aoSAcNO5rbWdOArH04KEXAAAAUM"] [Tue Aug 18 12:55:28.064462 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:39384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/admin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPgAAAmw"] [Tue Aug 18 12:55:28.071353 2026] [security2:error] [pid 67073:tid 67155] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xj.php"] [unique_id "aoSAcPcmepr5_nHgLbNCPwACQU8"] [Tue Aug 18 12:55:28.075882 2026] [security2:error] [pid 66623:tid 66861] [client 20.251.48.93:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/images.php"] [unique_id "aoSAcNO5rbWdOArH04KEXQAAAWk"] [Tue Aug 18 12:55:28.077101 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.7.189:9740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-signin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQAAAAj4"] [Tue Aug 18 12:55:28.081187 2026] [security2:error] [pid 66623:tid 66845] [client 68.155.154.236:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/lddxs.php"] [unique_id "aoSAcNO5rbWdOArH04KEXgAAAVk"] [Tue Aug 18 12:55:28.094587 2026] [security2:error] [pid 67073:tid 67295] [client 132.196.61.152:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/scxy.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQQAAAm4"] [Tue Aug 18 12:55:28.100365 2026] [security2:error] [pid 67073:tid 67228] [client 20.226.7.189:38627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAcPcmepr5_nHgLbNCQgAAAis"] [Tue Aug 18 12:55:28.138965 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:16474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAcNO5rbWdOArH04KEXwAAARA"] [Tue Aug 18 12:55:28.149448 2026] [security2:error] [pid 66623:tid 66809] [client 172.182.200.96:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEYAAAATU"] [Tue Aug 18 12:55:28.154106 2026] [security2:error] [pid 66623:tid 66810] [client 135.225.75.187:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp5.php"] [unique_id "aoSAcNO5rbWdOArH04KEYQAAATY"] [Tue Aug 18 12:55:28.167659 2026] [security2:error] [pid 66623:tid 66780] [client 20.171.51.14:43343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/56.php"] [unique_id "aoSAcNO5rbWdOArH04KEYgAAARg"] [Tue Aug 18 12:55:28.178051 2026] [security2:error] [pid 67073:tid 67241] [client 20.42.19.40:9630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/as.php"] [unique_id "aoSAcPcmepr5_nHgLbNCRgAAAjg"] [Tue Aug 18 12:55:28.195688 2026] [security2:error] [pid 66623:tid 66835] [client 20.171.51.14:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/an.php"] [unique_id "aoSAcNO5rbWdOArH04KEYwAAAU8"] [Tue Aug 18 12:55:28.276007 2026] [security2:error] [pid 67073:tid 67233] [client 20.104.85.180:7983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCSQAAAjA"] [Tue Aug 18 12:55:28.291082 2026] [security2:error] [pid 67073:tid 67106] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ns.php"] [unique_id "aoSAcPcmepr5_nHgLbNCSgACMR4"] [Tue Aug 18 12:55:28.292166 2026] [security2:error] [pid 67073:tid 67256] [client 4.223.164.152:64702] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/"] [unique_id "aoSAcPcmepr5_nHgLbNCSwAAAkc"] [Tue Aug 18 12:55:28.305401 2026] [security2:error] [pid 67073:tid 67316] [client 74.248.130.103:36810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/images.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTAAAAoM"] [Tue Aug 18 12:55:28.310092 2026] [security2:error] [pid 67073:tid 67257] [client 20.48.236.86:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTQAAAkg"] [Tue Aug 18 12:55:28.312259 2026] [security2:error] [pid 67073:tid 67285] [client 20.104.100.201:21496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/privdayz.php"] [unique_id "aoSAcPcmepr5_nHgLbNCTgAAAmQ"] [Tue Aug 18 12:55:28.319403 2026] [security2:error] [pid 66623:tid 66869] [client 20.151.109.219:24846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wn.php"] [unique_id "aoSAcNO5rbWdOArH04KEagAAAXE"] [Tue Aug 18 12:55:28.326645 2026] [security2:error] [pid 66623:tid 66889] [client 20.163.43.14:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEawAAAYU"] [Tue Aug 18 12:55:28.331631 2026] [security2:error] [pid 66623:tid 66782] [client 20.163.43.14:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/info.php"] [unique_id "aoSAcNO5rbWdOArH04KEbAAAARo"] [Tue Aug 18 12:55:28.346820 2026] [security2:error] [pid 67073:tid 67302] [client 172.202.39.151:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/13.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUAAAAnU"] [Tue Aug 18 12:55:28.365727 2026] [security2:error] [pid 66623:tid 66882] [client 20.51.153.15:8774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/un.php"] [unique_id "aoSAcNO5rbWdOArH04KEdAAAAX4"] [Tue Aug 18 12:55:28.374913 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.7.189:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ws.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUQAAAiY"] [Tue Aug 18 12:55:28.394310 2026] [security2:error] [pid 66623:tid 66891] [client 20.100.169.31:39458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAcNO5rbWdOArH04KEdQAAAYc"] [Tue Aug 18 12:55:28.399002 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.7.189:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wsa.php"] [unique_id "aoSAcNO5rbWdOArH04KEdgAAATs"] [Tue Aug 18 12:55:28.400211 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.18.37:40040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/NewFile.php"] [unique_id "aoSAcPcmepr5_nHgLbNCUgAAAnI"] [Tue Aug 18 12:55:28.416273 2026] [security2:error] [pid 66623:tid 66827] [client 20.42.19.40:9650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/k.php"] [unique_id "aoSAcNO5rbWdOArH04KEdwAAAUc"] [Tue Aug 18 12:55:28.417857 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.7.189:19179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/w.php"] [unique_id "aoSAcNO5rbWdOArH04KEeAAAATo"] [Tue Aug 18 12:55:28.422591 2026] [security2:error] [pid 66623:tid 66844] [client 78.46.190.63:57568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEZgAAAVg"], referer: http://ancavisi.com.br/ [Tue Aug 18 12:55:28.437992 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.7.189:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/x.php"] [unique_id "aoSAcNO5rbWdOArH04KEegAAAXM"] [Tue Aug 18 12:55:28.438006 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.136.165:43659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/clasa99.php"] [unique_id "aoSAcNO5rbWdOArH04KEewAAARY"] [Tue Aug 18 12:55:28.465398 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.7.189:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xx.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVgAAApE"] [Tue Aug 18 12:55:28.468424 2026] [security2:error] [pid 66623:tid 66806] [client 20.91.215.254:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/media-new.php"] [unique_id "aoSAcNO5rbWdOArH04KEfAAAATI"] [Tue Aug 18 12:55:28.477057 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVwAAAlY"] [Tue Aug 18 12:55:28.477166 2026] [security2:error] [pid 67073:tid 67271] [client 114.5.214.109:49803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCVwAAAlY"] [Tue Aug 18 12:55:28.490040 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.7.189:10707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWAAAAl8"] [Tue Aug 18 12:55:28.511728 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.7.189:11284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/y.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWgAAAlI"] [Tue Aug 18 12:55:28.514106 2026] [security2:error] [pid 67073:tid 67306] [client 213.202.253.4:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/userfuns.php"] [unique_id "aoSAcPcmepr5_nHgLbNCWwAAAnk"], referer: www.google.com [Tue Aug 18 12:55:28.516986 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gk.php"] [unique_id "aoSAcPcmepr5_nHgLbNCXAACHyo"] [Tue Aug 18 12:55:28.522048 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.169.31:31469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAcNO5rbWdOArH04KEfQAAAQs"] [Tue Aug 18 12:55:28.530799 2026] [security2:error] [pid 67073:tid 67207] [client 52.238.210.254:8913] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/"] [unique_id "aoSAcPcmepr5_nHgLbNCXQAAAhY"] [Tue Aug 18 12:55:28.569896 2026] [security2:error] [pid 66623:tid 66837] [client 52.139.47.57:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/goat1.php"] [unique_id "aoSAcNO5rbWdOArH04KEfgAAAVE"] [Tue Aug 18 12:55:28.575130 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.34.183:47507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/.__info.php"] [unique_id "aoSAcNO5rbWdOArH04KEfwAAAYQ"] [Tue Aug 18 12:55:28.577991 2026] [security2:error] [pid 67073:tid 67290] [client 20.104.85.180:7979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/an.php"] [unique_id "aoSAcPcmepr5_nHgLbNCXwAAAmk"] [Tue Aug 18 12:55:28.585918 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYAAAAjI"] [Tue Aug 18 12:55:28.588537 2026] [security2:error] [pid 67073:tid 67328] [client 20.104.100.201:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wg459o.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYQAAAo8"] [Tue Aug 18 12:55:28.598618 2026] [security2:error] [pid 67073:tid 67259] [client 20.51.153.15:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/evil.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYwAAAko"] [Tue Aug 18 12:55:28.630380 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAcNO5rbWdOArH04KEgAAAASQ"] [Tue Aug 18 12:55:28.640522 2026] [security2:error] [pid 67073:tid 67232] [client 20.100.169.31:28134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/admin.php"] [unique_id "aoSAcPcmepr5_nHgLbNCZQAAAi8"] [Tue Aug 18 12:55:28.653815 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEgQAAAVo"] [Tue Aug 18 12:55:28.668932 2026] [security2:error] [pid 67073:tid 67255] [client 20.151.109.219:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/app.php"] [unique_id "aoSAcPcmepr5_nHgLbNCZgAAAkY"] [Tue Aug 18 12:55:28.724500 2026] [security2:error] [pid 67073:tid 67236] [client 20.48.236.86:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/sf.php"] [unique_id "aoSAcPcmepr5_nHgLbNCaQAAAjM"] [Tue Aug 18 12:55:28.728729 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/alfa.php"] [unique_id "aoSAcNO5rbWdOArH04KEgwAAAVA"] [Tue Aug 18 12:55:28.736437 2026] [security2:error] [pid 67073:tid 67251] [client 4.223.164.152:28536] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aoSAcPcmepr5_nHgLbNCawAAAkI"] [Tue Aug 18 12:55:28.749397 2026] [security2:error] [pid 66623:tid 66890] [client 20.29.77.16:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/info2.php"] [unique_id "aoSAcNO5rbWdOArH04KEhAAAAYY"] [Tue Aug 18 12:55:28.749536 2026] [security2:error] [pid 67073:tid 67270] [client 52.173.121.69:24815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAcPcmepr5_nHgLbNCbQAAAlU"] [Tue Aug 18 12:55:28.750556 2026] [security2:error] [pid 67073:tid 67210] [client 20.91.215.254:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/import.php"] [unique_id "aoSAcPcmepr5_nHgLbNCbgAAAhk"] [Tue Aug 18 12:55:28.773903 2026] [security2:error] [pid 67073:tid 67189] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wn.php"] [unique_id "aoSAcPcmepr5_nHgLbNCcAACHnE"] [Tue Aug 18 12:55:28.794109 2026] [security2:error] [pid 67073:tid 67292] [client 20.42.19.40:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.alf.php"] [unique_id "aoSAcPcmepr5_nHgLbNCcgAAAms"] [Tue Aug 18 12:55:28.834197 2026] [security2:error] [pid 67073:tid 67287] [client 135.225.75.187:21838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/a2.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdAAAAmY"] [Tue Aug 18 12:55:28.855617 2026] [security2:error] [pid 67073:tid 67237] [client 74.248.136.165:43655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/666.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdQAAAjQ"] [Tue Aug 18 12:55:28.866073 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mifta.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdgAAAk0"] [Tue Aug 18 12:55:28.867842 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAcNO5rbWdOArH04KEhQAAAX0"] [Tue Aug 18 12:55:28.882550 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zjggu.php"] [unique_id "aoSAcPcmepr5_nHgLbNCegAAApM"] [Tue Aug 18 12:55:28.888419 2026] [security2:error] [pid 67073:tid 67266] [client 20.116.17.175:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/pucci.php"] [unique_id "aoSAcPcmepr5_nHgLbNCewAAAlE"] [Tue Aug 18 12:55:28.890726 2026] [security2:error] [pid 66623:tid 66794] [client 4.232.151.198:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/goods.php"] [unique_id "aoSAcNO5rbWdOArH04KEhgAAASY"] [Tue Aug 18 12:55:28.906324 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/f35.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfAAAAkk"] [Tue Aug 18 12:55:28.906957 2026] [security2:error] [pid 67073:tid 67293] [client 20.42.19.40:9621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/system_log.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfQAAAmw"] [Tue Aug 18 12:55:28.910318 2026] [security2:error] [pid 67073:tid 67250] [client 20.51.153.15:9144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pw.php"] [unique_id "aoSAcPcmepr5_nHgLbNCfwAAAkE"] [Tue Aug 18 12:55:28.923557 2026] [autoindex:error] [pid 67073:tid 67303] [client 20.104.85.180:8002] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:28.973731 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAcPcmepr5_nHgLbNCgAAAApI"] [Tue Aug 18 12:55:28.974407 2026] [security2:error] [pid 67073:tid 67193] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/app.php"] [unique_id "aoSAcPcmepr5_nHgLbNCgQACGnU"] [Tue Aug 18 12:55:28.995747 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.130.103:15384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/alls.php"] [unique_id "aoSAcPcmepr5_nHgLbNCggAAAi0"] [Tue Aug 18 12:55:29.011918 2026] [security2:error] [pid 67073:tid 67308] [client 20.171.51.14:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/rx.php"] [unique_id "aoSAcfcmepr5_nHgLbNChAAAAns"] [Tue Aug 18 12:55:29.038174 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/87.php"] [unique_id "aoSAcfcmepr5_nHgLbNChgAAAh0"] [Tue Aug 18 12:55:29.140599 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAcfcmepr5_nHgLbNCiwAAAjk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:29.142173 2026] [security2:error] [pid 67073:tid 67285] [client 20.104.100.201:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjAAAAmQ"] [Tue Aug 18 12:55:29.144569 2026] [security2:error] [pid 67073:tid 67213] [client 20.42.19.40:9637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/x.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjQAAAhw"] [Tue Aug 18 12:55:29.148106 2026] [security2:error] [pid 67073:tid 67247] [client 20.100.169.31:31440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAcfcmepr5_nHgLbNCjwAAAj4"] [Tue Aug 18 12:55:29.166037 2026] [security2:error] [pid 66623:tid 66817] [client 20.51.153.15:9126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fn.php"] [unique_id "aoSAcdO5rbWdOArH04KEiQAAAT0"] [Tue Aug 18 12:55:29.175317 2026] [security2:error] [pid 67073:tid 67314] [client 74.248.133.44:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/elp.php"] [unique_id "aoSAcfcmepr5_nHgLbNCkAAAAoE"] [Tue Aug 18 12:55:29.198340 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.85.180:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/404.php"] [unique_id "aoSAcfcmepr5_nHgLbNCkgAAAnI"] [Tue Aug 18 12:55:29.234728 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAcfcmepr5_nHgLbNClQAAAoI"] [Tue Aug 18 12:55:29.244096 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/k.php"] [unique_id "aoSAcfcmepr5_nHgLbNClgAAAiU"] [Tue Aug 18 12:55:29.265451 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/pucci.php"] [unique_id "aoSAcfcmepr5_nHgLbNClwAAAlo"] [Tue Aug 18 12:55:29.274414 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.136.165:9527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/thui.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmAAAAk4"] [Tue Aug 18 12:55:29.275056 2026] [security2:error] [pid 67073:tid 67151] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/87.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmQACfEs"] [Tue Aug 18 12:55:29.278227 2026] [security2:error] [pid 67073:tid 67234] [client 20.91.215.254:13199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAcfcmepr5_nHgLbNCmgAAAjE"] [Tue Aug 18 12:55:29.362085 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAcfcmepr5_nHgLbNCnQAAAjI"] [Tue Aug 18 12:55:29.383138 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/autoload_classmap.php"] [unique_id "aoSAcfcmepr5_nHgLbNCnwAAAng"] [Tue Aug 18 12:55:29.403027 2026] [security2:error] [pid 67073:tid 67244] [client 20.151.109.219:59712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zi.php"] [unique_id "aoSAcfcmepr5_nHgLbNCogAAAjs"] [Tue Aug 18 12:55:29.414035 2026] [security2:error] [pid 67073:tid 67279] [client 52.139.47.57:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/google-seo-rank/module.php"] [unique_id "aoSAcfcmepr5_nHgLbNCowAAAl4"] [Tue Aug 18 12:55:29.422964 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.100.201:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/index2.php"] [unique_id "aoSAcdO5rbWdOArH04KEiwAAARU"] [Tue Aug 18 12:55:29.434057 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:15024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sy.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpAAAAkI"] [Tue Aug 18 12:55:29.435754 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.6.191:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/public/css.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpgAAAlU"] [Tue Aug 18 12:55:29.437315 2026] [security2:error] [pid 67073:tid 67210] [client 20.205.121.237:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/worksec.php"] [unique_id "aoSAcfcmepr5_nHgLbNCpwAAAhk"] [Tue Aug 18 12:55:29.442848 2026] [security2:error] [pid 67073:tid 67209] [client 52.238.210.254:10163] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/"] [unique_id "aoSAcfcmepr5_nHgLbNCqQAAAhg"] [Tue Aug 18 12:55:29.442863 2026] [security2:error] [pid 67073:tid 67322] [client 20.91.215.254:27415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/cropper.php"] [unique_id "aoSAcfcmepr5_nHgLbNCqAAAAok"] [Tue Aug 18 12:55:29.449017 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.98.162:15512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bless6.php"] [unique_id "aoSAcfcmepr5_nHgLbNCqwAAAi4"] [Tue Aug 18 12:55:29.460466 2026] [security2:error] [pid 67073:tid 67215] [client 20.251.48.93:9771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/mac.php"] [unique_id "aoSAcfcmepr5_nHgLbNCrAAAAh4"] [Tue Aug 18 12:55:29.461633 2026] [security2:error] [pid 66623:tid 66859] [client 20.51.153.15:8753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kf.php"] [unique_id "aoSAcdO5rbWdOArH04KEjAAAAWc"] [Tue Aug 18 12:55:29.507163 2026] [security2:error] [pid 67073:tid 67224] [client 20.104.85.180:7974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-login.php"] [unique_id "aoSAcfcmepr5_nHgLbNCrgAAAic"] [Tue Aug 18 12:55:29.544460 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.154.236:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAcfcmepr5_nHgLbNCsQAAAhc"] [Tue Aug 18 12:55:29.545787 2026] [security2:error] [pid 67073:tid 67102] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zi.php"] [unique_id "aoSAcfcmepr5_nHgLbNCsgACSRo"] [Tue Aug 18 12:55:29.561175 2026] [security2:error] [pid 67073:tid 67239] [client 20.163.43.14:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/k.php"] [unique_id "aoSAcfcmepr5_nHgLbNCswAAAjY"] [Tue Aug 18 12:55:29.566628 2026] [security2:error] [pid 67073:tid 67313] [client 20.48.236.86:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/82.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtAAAAoA"] [Tue Aug 18 12:55:29.592359 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.6.191:6569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtgAAAm4"] [Tue Aug 18 12:55:29.610473 2026] [security2:error] [pid 67073:tid 67211] [client 20.163.43.14:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/inputs.php"] [unique_id "aoSAcfcmepr5_nHgLbNCtwAAAho"] [Tue Aug 18 12:55:29.621009 2026] [security2:error] [pid 67073:tid 67228] [client 20.42.19.40:9602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/hosty.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuAAAAis"] [Tue Aug 18 12:55:29.622911 2026] [security2:error] [pid 67073:tid 67230] [client 20.29.77.16:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/test_info.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuQAAAi0"] [Tue Aug 18 12:55:29.679701 2026] [security2:error] [pid 67073:tid 67321] [client 52.173.121.69:17942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAcfcmepr5_nHgLbNCuwAAAog"] [Tue Aug 18 12:55:29.692621 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.136.165:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/agg.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvQAAAn0"] [Tue Aug 18 12:55:29.697040 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:29.697300 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:29.697696 2026] [security2:error] [pid 67073:tid 67256] [client 20.104.100.201:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/8.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvgAAAkc"] [Tue Aug 18 12:55:29.698707 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.200.96:13838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAcdO5rbWdOArH04KEjgAAATc"] [Tue Aug 18 12:55:29.709325 2026] [security2:error] [pid 66623:tid 66789] [client 20.51.153.15:9213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/su.php"] [unique_id "aoSAcdO5rbWdOArH04KEjwAAASE"] [Tue Aug 18 12:55:29.714784 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.130.103:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/coffexium.php"] [unique_id "aoSAcfcmepr5_nHgLbNCvwAAApA"] [Tue Aug 18 12:55:29.717504 2026] [security2:error] [pid 67073:tid 67282] [client 103.120.71.157:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNCwAAAAmE"] [Tue Aug 18 12:55:29.717605 2026] [security2:error] [pid 67073:tid 67282] [client 103.120.71.157:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNCwAAAAmE"] [Tue Aug 18 12:55:29.722164 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:64681] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "aoSAcfcmepr5_nHgLbNCwQAAAkg"] [Tue Aug 18 12:55:29.722855 2026] [security2:error] [pid 67073:tid 67300] [client 52.87.72.16:39912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.autocred360.com.br"] [uri "/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCdwAAAnM"], referer: https://www.autocred360.com.br [Tue Aug 18 12:55:29.771874 2026] [security2:error] [pid 67073:tid 67278] [client 20.100.169.31:31457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/profile.php"] [unique_id "aoSAcfcmepr5_nHgLbNCxQAAAl0"] [Tue Aug 18 12:55:29.792469 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/92.php"] [unique_id "aoSAcfcmepr5_nHgLbNCyAACekk"] [Tue Aug 18 12:55:29.833418 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/92.php"] [unique_id "aoSAcfcmepr5_nHgLbNCzgAAAl4"] [Tue Aug 18 12:55:29.856354 2026] [security2:error] [pid 66623:tid 66791] [client 20.104.85.180:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAcdO5rbWdOArH04KEkQAAASM"] [Tue Aug 18 12:55:29.883982 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1QAAAn4"] [Tue Aug 18 12:55:29.884112 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:62172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1QAAAn4"] [Tue Aug 18 12:55:29.889120 2026] [security2:error] [pid 67073:tid 67227] [client 20.42.19.40:9671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/test1.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1gAAAio"] [Tue Aug 18 12:55:29.901487 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mandrill.php"] [unique_id "aoSAcfcmepr5_nHgLbNC1wAAAo4"] [Tue Aug 18 12:55:29.966183 2026] [security2:error] [pid 67073:tid 67213] [client 20.91.215.254:12600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAcfcmepr5_nHgLbNC3gAAAhw"] [Tue Aug 18 12:55:29.969132 2026] [security2:error] [pid 67073:tid 67293] [client 20.104.100.201:21381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/images.php"] [unique_id "aoSAcfcmepr5_nHgLbNC3wAAAmw"] [Tue Aug 18 12:55:29.981685 2026] [security2:error] [pid 67073:tid 67167] [remote 111.225.148.38:20390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gustavofrison.com.br"] [uri "/wp-content/uploads/2016/10/instagram.png"] [unique_id "aoSAcfcmepr5_nHgLbNC4QACdls"] [Tue Aug 18 12:55:29.986511 2026] [security2:error] [pid 67073:tid 67259] [client 4.232.151.198:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/file.php"] [unique_id "aoSAcfcmepr5_nHgLbNC4gAAAko"] [Tue Aug 18 12:55:29.989788 2026] [security2:error] [pid 67073:tid 67080] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jm.php"] [unique_id "aoSAcfcmepr5_nHgLbNC4wACgAQ"] [Tue Aug 18 12:55:30.000709 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:30.001156 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:30.008235 2026] [security2:error] [pid 67073:tid 67211] [client 20.116.17.175:57470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wicked.php"] [unique_id "aoSAcvcmepr5_nHgLbNC5gAAAho"] [Tue Aug 18 12:55:30.022269 2026] [security2:error] [pid 67073:tid 67230] [client 20.51.153.15:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wp-key.php"] [unique_id "aoSAcvcmepr5_nHgLbNC6AAAAi0"] [Tue Aug 18 12:55:30.043654 2026] [security2:error] [pid 67073:tid 67321] [client 172.182.200.96:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7QAAAog"] [Tue Aug 18 12:55:30.048474 2026] [security2:error] [pid 67073:tid 67214] [client 20.48.236.86:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dex.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7gAAAh0"] [Tue Aug 18 12:55:30.052082 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.18.37:43483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSAcvcmepr5_nHgLbNC7wAAAlY"] [Tue Aug 18 12:55:30.053337 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSActO5rbWdOArH04KElgAAAWE"] [Tue Aug 18 12:55:30.062316 2026] [security2:error] [pid 66623:tid 66861] [client 135.225.75.187:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/app.php"] [unique_id "aoSActO5rbWdOArH04KElwAAAWk"] [Tue Aug 18 12:55:30.064091 2026] [security2:error] [pid 66623:tid 66769] [client 52.139.47.57:19951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/h.php"] [unique_id "aoSActO5rbWdOArH04KEmAAAAQ0"] [Tue Aug 18 12:55:30.109970 2026] [security2:error] [pid 66623:tid 66845] [client 74.248.136.165:29063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/erty.php"] [unique_id "aoSActO5rbWdOArH04KEmQAAAVk"] [Tue Aug 18 12:55:30.112061 2026] [security2:error] [pid 66623:tid 66822] [client 20.171.51.14:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/57.php"] [unique_id "aoSActO5rbWdOArH04KEmgAAAUI"] [Tue Aug 18 12:55:30.124079 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:20706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bgymj.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9AAAAj8"] [Tue Aug 18 12:55:30.125796 2026] [security2:error] [pid 67073:tid 67205] [client 78.46.190.63:1302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSAcPcmepr5_nHgLbNCYgAAAhQ"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 12:55:30.141149 2026] [security2:error] [pid 67073:tid 67242] [client 20.42.19.40:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/zwso.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9QAAAjk"] [Tue Aug 18 12:55:30.154906 2026] [security2:error] [pid 66623:tid 66850] [client 213.35.127.232:60632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSActO5rbWdOArH04KEnAAAAV4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:30.155181 2026] [autoindex:error] [pid 66623:tid 66786] [client 20.104.85.180:8064] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:30.156056 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/403.php"] [unique_id "aoSActO5rbWdOArH04KEnQAAASg"] [Tue Aug 18 12:55:30.166565 2026] [security2:error] [pid 66623:tid 66772] [client 4.223.164.152:46182] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "aoSActO5rbWdOArH04KEngAAARA"] [Tue Aug 18 12:55:30.197412 2026] [security2:error] [pid 66623:tid 66809] [client 20.251.48.93:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/ops.php"] [unique_id "aoSActO5rbWdOArH04KEnwAAATU"] [Tue Aug 18 12:55:30.213633 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/alfa.php"] [unique_id "aoSAcvcmepr5_nHgLbNC9wAAAiU"] [Tue Aug 18 12:55:30.214041 2026] [security2:error] [pid 67073:tid 67252] [client 20.151.109.219:17537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jm.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-AAAAkM"] [Tue Aug 18 12:55:30.229894 2026] [security2:error] [pid 66623:tid 66875] [client 37.40.227.74:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSActO5rbWdOArH04KEoAAAAXc"] [Tue Aug 18 12:55:30.232108 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wj.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-QACemE"] [Tue Aug 18 12:55:30.233777 2026] [security2:error] [pid 66623:tid 66875] [client 37.40.227.74:57266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSActO5rbWdOArH04KEoAAAAXc"] [Tue Aug 18 12:55:30.236115 2026] [security2:error] [pid 67073:tid 67295] [client 20.91.215.254:20676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/images/xmrlpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-gAAAm4"] [Tue Aug 18 12:55:30.244605 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.100.201:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/a.php"] [unique_id "aoSAcvcmepr5_nHgLbNC-wAAAk4"] [Tue Aug 18 12:55:30.262287 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gg.php"] [unique_id "aoSAcvcmepr5_nHgLbNC_AAAAjE"] [Tue Aug 18 12:55:30.274777 2026] [autoindex:error] [pid 67073:tid 67324] [client 52.73.140.57:25391] AH01276: Cannot serve directory /home4/acessoso/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:30.294372 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.107:46916] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:30.294803 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.107:46916] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:30.297509 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.133.44:24712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSActO5rbWdOArH04KEoQAAATA"] [Tue Aug 18 12:55:30.300607 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:30.301023 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:30.340068 2026] [security2:error] [pid 66623:tid 66766] [client 20.29.77.16:52790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/xynz1.php"] [unique_id "aoSActO5rbWdOArH04KEowAAAQo"] [Tue Aug 18 12:55:30.348291 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.130.103:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/red.php"] [unique_id "aoSAcvcmepr5_nHgLbNDCwAAAl4"] [Tue Aug 18 12:55:30.377752 2026] [security2:error] [pid 67073:tid 67209] [client 20.42.19.40:1385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/Geforce.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDAAAAhg"] [Tue Aug 18 12:55:30.392183 2026] [security2:error] [pid 67073:tid 67281] [client 172.182.200.96:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDgAAAmA"] [Tue Aug 18 12:55:30.393051 2026] [security2:error] [pid 67073:tid 67299] [client 20.100.169.31:31446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/sx.php"] [unique_id "aoSAcvcmepr5_nHgLbNDDwAAAnI"] [Tue Aug 18 12:55:30.395932 2026] [security2:error] [pid 67073:tid 67292] [client 20.48.236.86:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/puc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDEAAAAms"] [Tue Aug 18 12:55:30.458446 2026] [autoindex:error] [pid 66623:tid 66826] [client 20.104.85.180:8064] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:30.465774 2026] [security2:error] [pid 66623:tid 66885] [client 216.73.161.209:23695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSActO5rbWdOArH04KEogAAAYE"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:55:30.491865 2026] [autoindex:error] [pid 67073:tid 67327] [client 20.226.6.191:55772] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:30.497320 2026] [security2:error] [pid 67073:tid 67096] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/74.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFAACURQ"] [Tue Aug 18 12:55:30.526969 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.100.201:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFQAAAmM"] [Tue Aug 18 12:55:30.532311 2026] [security2:error] [pid 67073:tid 67317] [client 52.139.47.57:19944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/import/csv1.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFgAAAoQ"] [Tue Aug 18 12:55:30.533377 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.136.165:49621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mini.php"] [unique_id "aoSActO5rbWdOArH04KEqAAAAXY"] [Tue Aug 18 12:55:30.565862 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:53217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wj.php"] [unique_id "aoSAcvcmepr5_nHgLbNDFwAAAhw"] [Tue Aug 18 12:55:30.592636 2026] [security2:error] [pid 66623:tid 66878] [client 20.51.153.15:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gi.php"] [unique_id "aoSActO5rbWdOArH04KEqQAAAXo"] [Tue Aug 18 12:55:30.595320 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:8064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wso.php"] [unique_id "aoSActO5rbWdOArH04KEqgAAAR8"] [Tue Aug 18 12:55:30.603664 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAcvcmepr5_nHgLbNDGgAAAmw"] [Tue Aug 18 12:55:30.614095 2026] [security2:error] [pid 67073:tid 67275] [client 20.42.19.40:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/fpwch.php"] [unique_id "aoSAcvcmepr5_nHgLbNDGwAAAlo"] [Tue Aug 18 12:55:30.636136 2026] [security2:error] [pid 67073:tid 67258] [client 52.238.210.254:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHQAAAkk"] [Tue Aug 18 12:55:30.638135 2026] [security2:error] [pid 67073:tid 67318] [client 20.163.43.14:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/lock360.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHgAAAoU"] [Tue Aug 18 12:55:30.639199 2026] [security2:error] [pid 67073:tid 67259] [client 4.223.164.152:37277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAcvcmepr5_nHgLbNDHwAAAko"] [Tue Aug 18 12:55:30.656762 2026] [security2:error] [pid 66623:tid 66827] [client 20.48.236.86:10755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.info"] [uri "/packed.php"] [unique_id "aoSActO5rbWdOArH04KErAAAAUc"] [Tue Aug 18 12:55:30.688760 2026] [security2:error] [pid 67073:tid 67212] [client 197.184.64.235:41925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIgAAAhs"] [Tue Aug 18 12:55:30.688872 2026] [security2:error] [pid 67073:tid 67212] [client 197.184.64.235:41925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIgAAAhs"] [Tue Aug 18 12:55:30.698587 2026] [security2:error] [pid 67073:tid 67169] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/av.php"] [unique_id "aoSAcvcmepr5_nHgLbNDIwACGl0"] [Tue Aug 18 12:55:30.701958 2026] [security2:error] [pid 67073:tid 67287] [client 4.232.151.198:25671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/edit.php"] [unique_id "aoSAcvcmepr5_nHgLbNDJQAAAmY"] [Tue Aug 18 12:55:30.702859 2026] [security2:error] [pid 67073:tid 67328] [client 5.253.205.188:48278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/install.sql"] [unique_id "aoSAcvcmepr5_nHgLbNDJAAAAo8"], referer: https://medihub.com.br/install.sql [Tue Aug 18 12:55:30.758890 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:24977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSActO5rbWdOArH04KErQAAAR0"] [Tue Aug 18 12:55:30.760540 2026] [security2:error] [pid 66623:tid 66889] [client 20.91.215.254:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSActO5rbWdOArH04KErgAAAYU"] [Tue Aug 18 12:55:30.774982 2026] [security2:error] [pid 67073:tid 67272] [client 20.100.169.31:33547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/goods.php"] [unique_id "aoSAcvcmepr5_nHgLbNDJwAAAlc"] [Tue Aug 18 12:55:30.780777 2026] [security2:error] [pid 67073:tid 67321] [client 20.48.236.86:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/inso.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKAAAAog"] [Tue Aug 18 12:55:30.790337 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKgAAAh0"] [Tue Aug 18 12:55:30.806298 2026] [security2:error] [pid 67073:tid 67310] [client 20.104.100.201:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/99.php"] [unique_id "aoSAcvcmepr5_nHgLbNDKwAAAn0"] [Tue Aug 18 12:55:30.821097 2026] [security2:error] [pid 66623:tid 66830] [client 20.205.121.237:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-access.php"] [unique_id "aoSActO5rbWdOArH04KErwAAAUo"] [Tue Aug 18 12:55:30.871754 2026] [security2:error] [pid 67073:tid 67257] [client 20.104.85.180:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/sf.php"] [unique_id "aoSAcvcmepr5_nHgLbNDLwAAAkg"] [Tue Aug 18 12:55:30.910355 2026] [security2:error] [pid 67073:tid 67280] [client 20.51.153.15:8791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ic.php"] [unique_id "aoSAcvcmepr5_nHgLbNDNQAAAl8"] [Tue Aug 18 12:55:30.920043 2026] [security2:error] [pid 67073:tid 67125] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ag.php"] [unique_id "aoSAcvcmepr5_nHgLbNDNwACKTE"] [Tue Aug 18 12:55:30.924506 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:13909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOAAAAjg"] [Tue Aug 18 12:55:30.924608 2026] [security2:error] [pid 67073:tid 67330] [client 20.151.109.219:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/74.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOQAAApE"] [Tue Aug 18 12:55:30.925752 2026] [security2:error] [pid 67073:tid 67261] [client 20.171.51.14:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/main.php"] [unique_id "aoSAcvcmepr5_nHgLbNDOgAAAkw"] [Tue Aug 18 12:55:30.951295 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.136.165:28627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sid3.php"] [unique_id "aoSAcvcmepr5_nHgLbNDPQAAAiI"] [Tue Aug 18 12:55:30.966355 2026] [security2:error] [pid 67073:tid 67234] [client 20.42.19.40:9616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-blog-header.php"] [unique_id "aoSAcvcmepr5_nHgLbNDPgAAAjE"] [Tue Aug 18 12:55:30.979904 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.6.191:32107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gelay.php"] [unique_id "aoSAcvcmepr5_nHgLbNDQAAAAnk"] [Tue Aug 18 12:55:30.980630 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.69.59:3760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpcheck.php"] [unique_id "aoSActO5rbWdOArH04KEsAAAAV8"] [Tue Aug 18 12:55:31.005815 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/gecko.php"] [unique_id "aoSAc_cmepr5_nHgLbNDQQAAAhY"] [Tue Aug 18 12:55:31.015909 2026] [security2:error] [pid 67073:tid 67223] [client 20.100.169.31:2967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDQwAAAiY"] [Tue Aug 18 12:55:31.040029 2026] [security2:error] [pid 67073:tid 67276] [client 20.163.43.14:4369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/flower.php"] [unique_id "aoSAc_cmepr5_nHgLbNDRgAAAls"] [Tue Aug 18 12:55:31.085434 2026] [security2:error] [pid 67073:tid 67235] [client 20.104.100.201:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yup.php"] [unique_id "aoSAc_cmepr5_nHgLbNDRwAAAjI"] [Tue Aug 18 12:55:31.114106 2026] [security2:error] [pid 67073:tid 67252] [client 52.139.47.57:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/index.bak.php"] [unique_id "aoSAc_cmepr5_nHgLbNDSQAAAkM"] [Tue Aug 18 12:55:31.122062 2026] [security2:error] [pid 66623:tid 66868] [client 4.223.164.152:28502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAc9O5rbWdOArH04KEsQAAAXA"] [Tue Aug 18 12:55:31.149449 2026] [security2:error] [pid 67073:tid 67299] [client 135.225.75.187:32714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTAAAAnI"] [Tue Aug 18 12:55:31.150580 2026] [security2:error] [pid 67073:tid 67292] [client 20.51.153.15:8790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lr.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTQAAAms"] [Tue Aug 18 12:55:31.155431 2026] [security2:error] [pid 67073:tid 67296] [client 172.182.200.96:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDTgAAAm8"] [Tue Aug 18 12:55:31.166342 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.6.191:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAc9O5rbWdOArH04KEsgAAAWQ"] [Tue Aug 18 12:55:31.168147 2026] [security2:error] [pid 67073:tid 67274] [client 213.35.127.232:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUAAAAlk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:31.174683 2026] [security2:error] [pid 67073:tid 67124] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ig.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUQACJzA"] [Tue Aug 18 12:55:31.185430 2026] [security2:error] [pid 67073:tid 67266] [client 20.48.236.86:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/aa.php"] [unique_id "aoSAc_cmepr5_nHgLbNDUgAAAlE"] [Tue Aug 18 12:55:31.200646 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:31.200942 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:31.212777 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDVQAAAmM"] [Tue Aug 18 12:55:31.215645 2026] [security2:error] [pid 66623:tid 66888] [client 132.196.61.152:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ws13.php"] [unique_id "aoSAc9O5rbWdOArH04KEswAAAYQ"] [Tue Aug 18 12:55:31.225715 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:9677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about/function.php"] [unique_id "aoSAc_cmepr5_nHgLbNDVgAAAiM"] [Tue Aug 18 12:55:31.236118 2026] [security2:error] [pid 67073:tid 67315] [client 78.46.190.63:64714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDSgAAAoI"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 12:55:31.247522 2026] [security2:error] [pid 66623:tid 66757] [remote 50.6.169.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSAc9O5rbWdOArH04KEtAABC3g"] [Tue Aug 18 12:55:31.257894 2026] [security2:error] [pid 67073:tid 67323] [client 20.104.85.180:7985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/index/function.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWAAAAoo"] [Tue Aug 18 12:55:31.276379 2026] [security2:error] [pid 67073:tid 67275] [client 20.251.48.93:31797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/coffexium.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWQAAAlo"] [Tue Aug 18 12:55:31.276951 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.6.191:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAc_cmepr5_nHgLbNDWgAAAjY"] [Tue Aug 18 12:55:31.295552 2026] [security2:error] [pid 67073:tid 67318] [client 20.151.109.219:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/av.php"] [unique_id "aoSAc_cmepr5_nHgLbNDXAAAAoU"] [Tue Aug 18 12:55:31.360707 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.100.201:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/222.php"] [unique_id "aoSAc_cmepr5_nHgLbNDYwAAAlc"] [Tue Aug 18 12:55:31.370199 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.136.165:29072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/moon.php"] [unique_id "aoSAc9O5rbWdOArH04KEtQAAAWo"] [Tue Aug 18 12:55:31.385879 2026] [autoindex:error] [pid 67073:tid 67218] [client 20.226.6.191:36372] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:31.400975 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.18.37:29284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDZQAAAos"] [Tue Aug 18 12:55:31.404420 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.6.191:36372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAc_cmepr5_nHgLbNDZgAAAoM"] [Tue Aug 18 12:55:31.409385 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ta.php"] [unique_id "aoSAc_cmepr5_nHgLbNDaAACc2g"] [Tue Aug 18 12:55:31.423775 2026] [security2:error] [pid 66623:tid 66846] [client 52.238.210.254:10226] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/uploads/"] [unique_id "aoSAc9O5rbWdOArH04KEtwAAAVo"] [Tue Aug 18 12:55:31.425129 2026] [security2:error] [pid 67073:tid 67248] [client 20.29.77.16:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/album.php"] [unique_id "aoSAc_cmepr5_nHgLbNDawAAAj8"] [Tue Aug 18 12:55:31.434005 2026] [security2:error] [pid 67073:tid 67225] [client 20.163.43.14:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/13.php"] [unique_id "aoSAc_cmepr5_nHgLbNDbAAAAig"] [Tue Aug 18 12:55:31.435545 2026] [security2:error] [pid 66623:tid 66831] [client 20.171.51.14:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ah.php"] [unique_id "aoSAc9O5rbWdOArH04KEuAAAAUs"] [Tue Aug 18 12:55:31.482760 2026] [security2:error] [pid 66623:tid 66805] [client 20.42.19.40:9603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/function/function.php"] [unique_id "aoSAc9O5rbWdOArH04KEuQAAATE"] [Tue Aug 18 12:55:31.496465 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.6.191:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/about.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcAAAApE"] [Tue Aug 18 12:55:31.501477 2026] [security2:error] [pid 67073:tid 67216] [client 20.91.215.254:22595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcQAAAh8"] [Tue Aug 18 12:55:31.502888 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:31.503144 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:31.510460 2026] [security2:error] [pid 67073:tid 67219] [client 172.182.200.96:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcgAAAiI"] [Tue Aug 18 12:55:31.518742 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/iy.php"] [unique_id "aoSAc_cmepr5_nHgLbNDcwAAAjE"] [Tue Aug 18 12:55:31.530843 2026] [security2:error] [pid 67073:tid 67306] [client 20.48.236.86:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/img.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdAAAAnk"] [Tue Aug 18 12:55:31.564226 2026] [security2:error] [pid 67073:tid 67207] [client 20.104.85.180:8060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/edit.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdgAAAhY"] [Tue Aug 18 12:55:31.566575 2026] [security2:error] [pid 67073:tid 67223] [client 4.223.164.152:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/puc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDdwAAAiY"] [Tue Aug 18 12:55:31.582008 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/aa.php"] [unique_id "aoSAc_cmepr5_nHgLbNDeQAAAjs"] [Tue Aug 18 12:55:31.588480 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.6.191:38268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDegAAAjk"] [Tue Aug 18 12:55:31.591253 2026] [core:notice] [pid 67073:tid 67229] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 12:55:31.595201 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:12896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ag.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfAAAAjo"] [Tue Aug 18 12:55:31.613364 2026] [security2:error] [pid 67073:tid 67210] [client 132.196.61.152:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/btx25.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfgAAAhk"] [Tue Aug 18 12:55:31.616508 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.154.236:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAc_cmepr5_nHgLbNDfwAAAjI"] [Tue Aug 18 12:55:31.632448 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.100.201:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAc_cmepr5_nHgLbNDgQAAAhg"] [Tue Aug 18 12:55:31.644491 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/34.php"] [unique_id "aoSAc_cmepr5_nHgLbNDgwACHig"] [Tue Aug 18 12:55:31.646924 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.6.191:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/f35.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhAAAAms"] [Tue Aug 18 12:55:31.647436 2026] [security2:error] [pid 66623:tid 66887] [client 20.100.169.31:2447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAc9O5rbWdOArH04KEugAAAYM"] [Tue Aug 18 12:55:31.662201 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.130.103:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhQAAAlA"] [Tue Aug 18 12:55:31.712785 2026] [security2:error] [pid 67073:tid 67224] [client 52.173.121.69:16477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAc_cmepr5_nHgLbNDhwAAAic"] [Tue Aug 18 12:55:31.720548 2026] [security2:error] [pid 66623:tid 66770] [client 20.42.19.40:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-signin.php"] [unique_id "aoSAc9O5rbWdOArH04KEuwAAAQ4"] [Tue Aug 18 12:55:31.747953 2026] [autoindex:error] [pid 67073:tid 67266] [client 20.226.6.191:64020] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:31.748112 2026] [security2:error] [pid 67073:tid 67267] [client 20.91.215.254:27450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/goat.php"] [unique_id "aoSAc_cmepr5_nHgLbNDiQAAAlI"] [Tue Aug 18 12:55:31.759207 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.6.191:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/inputs.php"] [unique_id "aoSAc_cmepr5_nHgLbNDiwAAAoc"] [Tue Aug 18 12:55:31.759994 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lp.php"] [unique_id "aoSAc9O5rbWdOArH04KEvQAAARk"] [Tue Aug 18 12:55:31.780780 2026] [security2:error] [pid 67073:tid 67228] [client 86.120.159.145:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjAAAAis"] [Tue Aug 18 12:55:31.781048 2026] [security2:error] [pid 67073:tid 67228] [client 86.120.159.145:5335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjAAAAis"] [Tue Aug 18 12:55:31.787333 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.136.165:43702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms.php"] [unique_id "aoSAc_cmepr5_nHgLbNDjgAAAmE"] [Tue Aug 18 12:55:31.794623 2026] [security2:error] [pid 66623:tid 66881] [client 20.163.43.14:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cc.php"] [unique_id "aoSAc9O5rbWdOArH04KEvgAAAX0"] [Tue Aug 18 12:55:31.815918 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:15506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/special.php"] [unique_id "aoSAc9O5rbWdOArH04KEvwAAASY"] [Tue Aug 18 12:55:31.833051 2026] [security2:error] [pid 67073:tid 67323] [client 20.48.236.86:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/222.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkAAAAoo"] [Tue Aug 18 12:55:31.834414 2026] [security2:error] [pid 66623:tid 66867] [client 104.209.144.33:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAc9O5rbWdOArH04KEwAAAAW8"] [Tue Aug 18 12:55:31.853117 2026] [security2:error] [pid 67073:tid 67295] [client 20.205.121.237:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkgAAAm4"] [Tue Aug 18 12:55:31.862156 2026] [security2:error] [pid 67073:tid 67275] [client 20.171.51.14:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ga.php"] [unique_id "aoSAc_cmepr5_nHgLbNDkwAAAlo"] [Tue Aug 18 12:55:31.895576 2026] [security2:error] [pid 67073:tid 67168] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/he.php"] [unique_id "aoSAc_cmepr5_nHgLbNDlQACdlw"] [Tue Aug 18 12:55:31.905785 2026] [security2:error] [pid 66623:tid 66776] [client 20.104.100.201:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/spadex.php"] [unique_id "aoSAc9O5rbWdOArH04KEwQAAARQ"] [Tue Aug 18 12:55:31.910745 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:15489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSAc_cmepr5_nHgLbNDlgAAAo0"] [Tue Aug 18 12:55:31.914221 2026] [security2:error] [pid 66623:tid 66783] [client 135.225.75.187:31148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/cxc.php"] [unique_id "aoSAc9O5rbWdOArH04KEwgAAARs"] [Tue Aug 18 12:55:31.917605 2026] [security2:error] [pid 66623:tid 66857] [client 52.238.210.254:8940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAc9O5rbWdOArH04KEwwAAAWU"] [Tue Aug 18 12:55:31.961073 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:9717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/f35.php"] [unique_id "aoSAc_cmepr5_nHgLbNDmQAAAhs"] [Tue Aug 18 12:55:31.962178 2026] [autoindex:error] [pid 67073:tid 67287] [client 74.248.133.44:24736] AH01276: Cannot serve directory /home3/hyundai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:31.973569 2026] [security2:error] [pid 67073:tid 67273] [client 20.151.109.219:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ig.php"] [unique_id "aoSAc_cmepr5_nHgLbNDmgAAAlg"] [Tue Aug 18 12:55:31.978317 2026] [security2:error] [pid 66623:tid 66872] [client 20.100.169.31:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/file.php"] [unique_id "aoSAc9O5rbWdOArH04KExAAAAXQ"] [Tue Aug 18 12:55:31.988568 2026] [security2:error] [pid 67073:tid 67230] [client 172.182.200.96:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAc_cmepr5_nHgLbNDnAAAAi0"] [Tue Aug 18 12:55:31.991057 2026] [security2:error] [pid 67073:tid 67272] [client 4.223.164.152:64684] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Requests/"] [unique_id "aoSAc_cmepr5_nHgLbNDnQAAAlc"] [Tue Aug 18 12:55:31.993212 2026] [autoindex:error] [pid 67073:tid 67328] [client 20.104.85.180:8061] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:32.031765 2026] [security2:error] [pid 67073:tid 67310] [client 20.163.43.14:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/0x.php"] [unique_id "aoSAdPcmepr5_nHgLbNDoAAAAn0"] [Tue Aug 18 12:55:32.060155 2026] [security2:error] [pid 67073:tid 67237] [client 20.51.153.15:9202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ey.php"] [unique_id "aoSAdPcmepr5_nHgLbNDoQAAAjQ"] [Tue Aug 18 12:55:32.101169 2026] [security2:error] [pid 67073:tid 67155] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gz.php"] [unique_id "aoSAdPcmepr5_nHgLbNDqQACgU8"] [Tue Aug 18 12:55:32.109247 2026] [authz_core:error] [pid 67073:tid 67097] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:32.109685 2026] [authz_core:error] [pid 67073:tid 67097] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:32.160846 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/ebs.php7"] [unique_id "aoSAdPcmepr5_nHgLbNDrAAAAoU"] [Tue Aug 18 12:55:32.165807 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/key.php"] [unique_id "aoSAdNO5rbWdOArH04KExgAAATQ"] [Tue Aug 18 12:55:32.167317 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:24570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/elp.php"] [unique_id "aoSAdNO5rbWdOArH04KExwAAARU"] [Tue Aug 18 12:55:32.172378 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.133.44:24736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/o.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrQAAAiU"] [Tue Aug 18 12:55:32.182338 2026] [security2:error] [pid 66623:tid 66832] [client 20.171.51.14:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vw.php"] [unique_id "aoSAdNO5rbWdOArH04KEyAAAAUw"] [Tue Aug 18 12:55:32.185113 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrgAAAmw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:32.187858 2026] [security2:error] [pid 67073:tid 67234] [client 68.221.73.131:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdPcmepr5_nHgLbNDrwAAAjE"] [Tue Aug 18 12:55:32.194088 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.100.201:21398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNDsAAAAkU"] [Tue Aug 18 12:55:32.214061 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.136.165:9965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wsws.php"] [unique_id "aoSAdPcmepr5_nHgLbNDsgAAAkQ"] [Tue Aug 18 12:55:32.214296 2026] [security2:error] [pid 67073:tid 67244] [client 20.163.43.14:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAdPcmepr5_nHgLbNDswAAAjs"] [Tue Aug 18 12:55:32.226143 2026] [security2:error] [pid 67073:tid 67279] [client 20.116.17.175:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/water.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtAAAAl4"] [Tue Aug 18 12:55:32.259476 2026] [security2:error] [pid 67073:tid 67270] [client 20.151.109.219:24881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ta.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtQAAAlU"] [Tue Aug 18 12:55:32.277249 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.85.180:8061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAdPcmepr5_nHgLbNDtgAAAhk"] [Tue Aug 18 12:55:32.290715 2026] [security2:error] [pid 67073:tid 67305] [client 4.232.151.198:27348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAdPcmepr5_nHgLbNDuAAAAng"] [Tue Aug 18 12:55:32.305911 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.6.191:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNDuQAAAhg"] [Tue Aug 18 12:55:32.350435 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.34.183:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/access.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvgAAAoY"] [Tue Aug 18 12:55:32.367923 2026] [security2:error] [pid 67073:tid 67262] [client 103.184.169.37:41687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvwAAAk0"] [Tue Aug 18 12:55:32.368047 2026] [security2:error] [pid 67073:tid 67262] [client 103.184.169.37:41687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdPcmepr5_nHgLbNDvwAAAk0"] [Tue Aug 18 12:55:32.370353 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.130.103:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwAAAAio"] [Tue Aug 18 12:55:32.388044 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nf.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwQACU1Q"] [Tue Aug 18 12:55:32.391487 2026] [security2:error] [pid 67073:tid 67327] [client 20.215.241.237:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwgAAAo4"] [Tue Aug 18 12:55:32.394648 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:20693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/Session.php"] [unique_id "aoSAdPcmepr5_nHgLbNDwwAAAnw"] [Tue Aug 18 12:55:32.397208 2026] [security2:error] [pid 67073:tid 67330] [client 52.139.47.57:44641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/lite.php"] [unique_id "aoSAdPcmepr5_nHgLbNDxAAAApE"] [Tue Aug 18 12:55:32.416436 2026] [security2:error] [pid 67073:tid 67317] [client 52.173.121.69:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAdPcmepr5_nHgLbNDyAAAAoQ"] [Tue Aug 18 12:55:32.424333 2026] [security2:error] [pid 66623:tid 66892] [client 4.223.164.152:28530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/8.php"] [unique_id "aoSAdNO5rbWdOArH04KEyQAAAYg"] [Tue Aug 18 12:55:32.424837 2026] [security2:error] [pid 66623:tid 66795] [client 20.51.153.15:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/lv.php"] [unique_id "aoSAdNO5rbWdOArH04KEygAAASc"] [Tue Aug 18 12:55:32.431136 2026] [security2:error] [pid 66623:tid 66784] [client 52.238.210.254:8946] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/"] [unique_id "aoSAdNO5rbWdOArH04KEzAAAARw"] [Tue Aug 18 12:55:32.467351 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.100.201:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/srontol.php"] [unique_id "aoSAdPcmepr5_nHgLbND0wAAAkY"] [Tue Aug 18 12:55:32.481203 2026] [security2:error] [pid 67073:tid 67228] [client 172.202.39.151:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cc.php"] [unique_id "aoSAdPcmepr5_nHgLbND1AAAAis"] [Tue Aug 18 12:55:32.485935 2026] [security2:error] [pid 67073:tid 67282] [client 20.48.236.86:16303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/chosen.php"] [unique_id "aoSAdPcmepr5_nHgLbND1QAAAmE"] [Tue Aug 18 12:55:32.506510 2026] [autoindex:error] [pid 67073:tid 67312] [client 20.226.6.191:32276] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:32.518330 2026] [security2:error] [pid 67073:tid 67323] [client 20.163.43.14:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/zxz.php"] [unique_id "aoSAdPcmepr5_nHgLbND1wAAAoo"] [Tue Aug 18 12:55:32.535815 2026] [security2:error] [pid 67073:tid 67275] [client 172.182.200.96:14262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAdPcmepr5_nHgLbND2QAAAlo"] [Tue Aug 18 12:55:32.540581 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.6.191:32276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/alfa.php"] [unique_id "aoSAdPcmepr5_nHgLbND2gAAAls"] [Tue Aug 18 12:55:32.554443 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.31:59788] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:32.554702 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.31:59788] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:32.556805 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:31478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAdPcmepr5_nHgLbND2wAAAlQ"] [Tue Aug 18 12:55:32.573619 2026] [security2:error] [pid 67073:tid 67299] [client 20.104.85.180:8027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-good.php"] [unique_id "aoSAdPcmepr5_nHgLbND3AAAAnI"] [Tue Aug 18 12:55:32.575068 2026] [security2:error] [pid 67073:tid 67290] [client 20.251.48.93:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdPcmepr5_nHgLbND3QAAAmk"] [Tue Aug 18 12:55:32.626560 2026] [security2:error] [pid 67073:tid 67272] [client 20.151.109.219:53243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/34.php"] [unique_id "aoSAdPcmepr5_nHgLbND4AAAAlc"] [Tue Aug 18 12:55:32.637174 2026] [security2:error] [pid 67073:tid 67321] [client 74.248.136.165:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/motu.php"] [unique_id "aoSAdPcmepr5_nHgLbND4QAAAog"] [Tue Aug 18 12:55:32.644224 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.136.165:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/zc-318.php"] [unique_id "aoSAdPcmepr5_nHgLbND4gAAAmI"] [Tue Aug 18 12:55:32.652927 2026] [security2:error] [pid 67073:tid 67308] [client 68.221.73.131:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAdPcmepr5_nHgLbND4wAAAns"] [Tue Aug 18 12:55:32.674109 2026] [security2:error] [pid 67073:tid 67260] [client 20.51.153.15:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/51.php"] [unique_id "aoSAdPcmepr5_nHgLbND5AAAAks"] [Tue Aug 18 12:55:32.685454 2026] [security2:error] [pid 67073:tid 67186] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xv.php"] [unique_id "aoSAdPcmepr5_nHgLbND5wACkG4"] [Tue Aug 18 12:55:32.726606 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:32.726891 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:32.731617 2026] [security2:error] [pid 66623:tid 66772] [client 20.163.43.14:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAdNO5rbWdOArH04KE0AAAARA"] [Tue Aug 18 12:55:32.742309 2026] [security2:error] [pid 67073:tid 67331] [client 20.104.100.201:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/file5.php"] [unique_id "aoSAdPcmepr5_nHgLbND6QAAApI"] [Tue Aug 18 12:55:32.751418 2026] [security2:error] [pid 67073:tid 67278] [client 20.29.77.16:51373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/creds.php"] [unique_id "aoSAdPcmepr5_nHgLbND6gAAAl0"] [Tue Aug 18 12:55:32.753281 2026] [security2:error] [pid 66623:tid 66809] [client 52.238.210.254:29109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/buy.php"] [unique_id "aoSAdNO5rbWdOArH04KE0QAAATU"] [Tue Aug 18 12:55:32.755394 2026] [security2:error] [pid 66623:tid 66810] [client 20.171.51.14:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wb.php"] [unique_id "aoSAdNO5rbWdOArH04KE0gAAATY"] [Tue Aug 18 12:55:32.774607 2026] [security2:error] [pid 67073:tid 67216] [client 20.48.236.86:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpxml.php"] [unique_id "aoSAdPcmepr5_nHgLbND7QAAAh8"] [Tue Aug 18 12:55:32.798071 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.61.152:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSAdPcmepr5_nHgLbND7wAAAiU"] [Tue Aug 18 12:55:32.839361 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.6.191:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/an.php"] [unique_id "aoSAdNO5rbWdOArH04KE0wAAAXw"] [Tue Aug 18 12:55:32.851228 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46202] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1.php"] [unique_id "aoSAdNO5rbWdOArH04KE1AAAATA"] [Tue Aug 18 12:55:32.851348 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:46202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1.php"] [unique_id "aoSAdNO5rbWdOArH04KE1AAAATA"] [Tue Aug 18 12:55:32.874855 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:12455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSAdPcmepr5_nHgLbND8gAAAho"] [Tue Aug 18 12:55:32.915728 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/www.php"] [unique_id "aoSAdPcmepr5_nHgLbND9AAAAjk"] [Tue Aug 18 12:55:32.924524 2026] [security2:error] [pid 67073:tid 67279] [client 135.225.75.187:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSAdPcmepr5_nHgLbNEDQAAAl4"] [Tue Aug 18 12:55:32.931860 2026] [security2:error] [pid 67073:tid 67270] [client 20.42.19.40:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.trash7206/index.php"] [unique_id "aoSAdPcmepr5_nHgLbNEDwAAAlU"] [Tue Aug 18 12:55:32.941734 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.130.103:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file52.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEAAAAnM"] [Tue Aug 18 12:55:32.950710 2026] [autoindex:error] [pid 67073:tid 67325] [client 20.104.85.180:7938] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:32.953474 2026] [security2:error] [pid 67073:tid 67235] [client 172.182.200.96:13876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEQAAAjI"] [Tue Aug 18 12:55:32.954752 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mx.php"] [unique_id "aoSAdPcmepr5_nHgLbNEEgACGHo"] [Tue Aug 18 12:55:32.963832 2026] [security2:error] [pid 67073:tid 67322] [client 20.151.109.219:24849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/he.php"] [unique_id "aoSAdPcmepr5_nHgLbNEFAAAAok"] [Tue Aug 18 12:55:32.979745 2026] [security2:error] [pid 67073:tid 67219] [client 20.51.153.15:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ew.php"] [unique_id "aoSAdPcmepr5_nHgLbNEFQAAAiI"] [Tue Aug 18 12:55:33.009397 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:33.009670 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:33.018272 2026] [security2:error] [pid 67073:tid 67215] [client 20.104.100.201:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yup.php"] [unique_id "aoSAdfcmepr5_nHgLbNEGAAAAh4"] [Tue Aug 18 12:55:33.038843 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:49329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/mimes.php"] [unique_id "aoSAdfcmepr5_nHgLbNEGgAAAk0"] [Tue Aug 18 12:55:33.054560 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.136.165:10084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fff.php"] [unique_id "aoSAddO5rbWdOArH04KE1gAAAXE"] [Tue Aug 18 12:55:33.064349 2026] [security2:error] [pid 67073:tid 67292] [client 5.31.227.224:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHgAAAms"] [Tue Aug 18 12:55:33.064436 2026] [security2:error] [pid 67073:tid 67292] [client 5.31.227.224:59071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHgAAAms"] [Tue Aug 18 12:55:33.064582 2026] [security2:error] [pid 67073:tid 67293] [client 4.232.151.198:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHQAAAmw"] [Tue Aug 18 12:55:33.067881 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file1221.php"] [unique_id "aoSAddO5rbWdOArH04KE1wAAAWY"] [Tue Aug 18 12:55:33.073572 2026] [security2:error] [pid 66623:tid 66811] [client 47.128.19.54:43862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.galeriadoengenho.com"] [uri "/robots.txt"] [unique_id "aoSAddO5rbWdOArH04KE2AAAATc"] [Tue Aug 18 12:55:33.127707 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.98.162:56700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdfcmepr5_nHgLbNEHwAAApE"] [Tue Aug 18 12:55:33.154374 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/45.php"] [unique_id "aoSAdfcmepr5_nHgLbNEIQACQBY"] [Tue Aug 18 12:55:33.165459 2026] [security2:error] [pid 67073:tid 67324] [client 20.91.215.254:20682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/acme-challenge.php"] [unique_id "aoSAdfcmepr5_nHgLbNEIwAAAos"] [Tue Aug 18 12:55:33.188855 2026] [security2:error] [pid 67073:tid 67303] [client 20.100.169.31:15543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/rip.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJAAAAnY"] [Tue Aug 18 12:55:33.194997 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/01.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJQAAAoI"] [Tue Aug 18 12:55:33.204040 2026] [security2:error] [pid 66623:tid 66818] [client 213.35.127.232:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAddO5rbWdOArH04KE3AAAAT4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:33.217348 2026] [security2:error] [pid 67073:tid 67320] [client 138.36.100.162:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJwAAAoc"] [Tue Aug 18 12:55:33.218132 2026] [security2:error] [pid 67073:tid 67320] [client 138.36.100.162:42757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdfcmepr5_nHgLbNEJwAAAoc"] [Tue Aug 18 12:55:33.222448 2026] [autoindex:error] [pid 67073:tid 67194] [remote 40.77.167.70:60661] AH01276: Cannot serve directory /home1/verona/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:33.246920 2026] [security2:error] [pid 67073:tid 67295] [client 20.51.153.15:9131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pqr.php"] [unique_id "aoSAdfcmepr5_nHgLbNEKgAAAm4"] [Tue Aug 18 12:55:33.247975 2026] [security2:error] [pid 66623:tid 66799] [client 20.205.121.237:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/advanced1.php"] [unique_id "aoSAddO5rbWdOArH04KE3QAAASs"] [Tue Aug 18 12:55:33.268123 2026] [security2:error] [pid 67073:tid 67275] [client 20.163.43.14:4337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wicked.php"] [unique_id "aoSAdfcmepr5_nHgLbNELAAAAlo"] [Tue Aug 18 12:55:33.269884 2026] [security2:error] [pid 66623:tid 66891] [client 20.151.109.219:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gz.php"] [unique_id "aoSAddO5rbWdOArH04KE3wAAAYc"] [Tue Aug 18 12:55:33.278899 2026] [security2:error] [pid 66623:tid 66815] [client 4.223.164.152:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/about.php"] [unique_id "aoSAddO5rbWdOArH04KE4AAAATs"] [Tue Aug 18 12:55:33.290226 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.6.191:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/lock360.php"] [unique_id "aoSAddO5rbWdOArH04KE4QAAAXo"] [Tue Aug 18 12:55:33.297095 2026] [autoindex:error] [pid 67073:tid 67213] [client 20.104.85.180:7938] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:33.298071 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:21485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAdfcmepr5_nHgLbNELQAAAo0"] [Tue Aug 18 12:55:33.304717 2026] [security2:error] [pid 67073:tid 67299] [client 172.182.200.96:13929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAdfcmepr5_nHgLbNELwAAAnI"] [Tue Aug 18 12:55:33.309599 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:33.309867 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:33.325501 2026] [security2:error] [pid 67073:tid 67212] [client 68.221.73.131:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAdfcmepr5_nHgLbNEMQAAAhs"] [Tue Aug 18 12:55:33.356174 2026] [security2:error] [pid 66623:tid 66827] [client 68.155.154.236:16261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/kopyw.php"] [unique_id "aoSAddO5rbWdOArH04KE4wAAAUc"] [Tue Aug 18 12:55:33.366802 2026] [security2:error] [pid 66623:tid 66875] [client 4.232.151.198:19957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/404.php"] [unique_id "aoSAddO5rbWdOArH04KE5AAAAXc"] [Tue Aug 18 12:55:33.367315 2026] [security2:error] [pid 67073:tid 67272] [client 20.48.236.86:16281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/nox.php"] [unique_id "aoSAdfcmepr5_nHgLbNEMgAAAlc"] [Tue Aug 18 12:55:33.407382 2026] [security2:error] [pid 66623:tid 66797] [client 20.100.169.31:31442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/about.php"] [unique_id "aoSAddO5rbWdOArH04KE5QAAASk"] [Tue Aug 18 12:55:33.411838 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wy.php"] [unique_id "aoSAdfcmepr5_nHgLbNENgACMEE"] [Tue Aug 18 12:55:33.433398 2026] [security2:error] [pid 67073:tid 67236] [client 20.104.85.180:7938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/tes.php"] [unique_id "aoSAdfcmepr5_nHgLbNEOAAAAjM"] [Tue Aug 18 12:55:33.472275 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.136.165:10062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/66.php"] [unique_id "aoSAddO5rbWdOArH04KE5gAAAR0"] [Tue Aug 18 12:55:33.498708 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:19914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/live.php"] [unique_id "aoSAdfcmepr5_nHgLbNEPAAAAnU"] [Tue Aug 18 12:55:33.505464 2026] [security2:error] [pid 66623:tid 66806] [client 74.248.130.103:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/geck.php"] [unique_id "aoSAddO5rbWdOArH04KE5wAAATI"] [Tue Aug 18 12:55:33.537715 2026] [security2:error] [pid 66623:tid 66852] [client 20.116.17.175:57657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fine.php"] [unique_id "aoSAddO5rbWdOArH04KE6AAAAWA"] [Tue Aug 18 12:55:33.542588 2026] [security2:error] [pid 66623:tid 66879] [client 52.173.121.69:16501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAddO5rbWdOArH04KE6QAAAXs"] [Tue Aug 18 12:55:33.556188 2026] [security2:error] [pid 67073:tid 67229] [client 20.51.153.15:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/an.php"] [unique_id "aoSAdfcmepr5_nHgLbNEPwAAAiw"] [Tue Aug 18 12:55:33.567424 2026] [security2:error] [pid 66623:tid 66863] [client 20.104.100.201:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-the.php"] [unique_id "aoSAddO5rbWdOArH04KE6gAAAWs"] [Tue Aug 18 12:55:33.570387 2026] [security2:error] [pid 67073:tid 67230] [client 20.91.215.254:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAdfcmepr5_nHgLbNEQAAAAi0"] [Tue Aug 18 12:55:33.586662 2026] [security2:error] [pid 67073:tid 67216] [client 20.151.109.219:24876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nf.php"] [unique_id "aoSAdfcmepr5_nHgLbNEQQAAAh8"] [Tue Aug 18 12:55:33.592211 2026] [security2:error] [pid 66623:tid 66868] [client 20.171.51.14:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lj.php"] [unique_id "aoSAddO5rbWdOArH04KE6wAAAXA"] [Tue Aug 18 12:55:33.611213 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:33.611470 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:33.621858 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/f.php"] [unique_id "aoSAdfcmepr5_nHgLbNERgACJQg"] [Tue Aug 18 12:55:33.624876 2026] [security2:error] [pid 66623:tid 66888] [client 20.251.48.93:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/sf.php"] [unique_id "aoSAddO5rbWdOArH04KE7AAAAYQ"] [Tue Aug 18 12:55:33.637678 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAddO5rbWdOArH04KE7QAAARE"] [Tue Aug 18 12:55:33.662598 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:33539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/02.php"] [unique_id "aoSAdfcmepr5_nHgLbNERwAAAig"] [Tue Aug 18 12:55:33.672644 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/lv.php"] [unique_id "aoSAdfcmepr5_nHgLbNESAAAAkU"] [Tue Aug 18 12:55:33.675822 2026] [security2:error] [pid 67073:tid 67207] [client 20.48.236.86:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/akismet.php"] [unique_id "aoSAdfcmepr5_nHgLbNESQAAAhY"] [Tue Aug 18 12:55:33.691686 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.61.152:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAdfcmepr5_nHgLbNETwAAAiY"] [Tue Aug 18 12:55:33.696149 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:54263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUAAAAk8"] [Tue Aug 18 12:55:33.703741 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.112.14:32203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "monroviaexport.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUQAAAhU"] [Tue Aug 18 12:55:33.720321 2026] [security2:error] [pid 67073:tid 67286] [client 20.215.241.237:23280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAdfcmepr5_nHgLbNEUgAAAmU"] [Tue Aug 18 12:55:33.751877 2026] [security2:error] [pid 66623:tid 66805] [client 68.221.73.131:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAddO5rbWdOArH04KE7wAAATE"] [Tue Aug 18 12:55:33.755640 2026] [security2:error] [pid 66623:tid 66877] [client 172.182.200.96:14228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAddO5rbWdOArH04KE8AAAAXk"] [Tue Aug 18 12:55:33.756417 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/flower.php"] [unique_id "aoSAddO5rbWdOArH04KE8QAAAS4"] [Tue Aug 18 12:55:33.779440 2026] [security2:error] [pid 67073:tid 67210] [client 20.104.85.180:8041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/files/index.php"] [unique_id "aoSAdfcmepr5_nHgLbNEVgAAAhk"] [Tue Aug 18 12:55:33.781073 2026] [security2:error] [pid 67073:tid 67305] [client 52.238.210.254:8944] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-includes/js/crop/"] [unique_id "aoSAdfcmepr5_nHgLbNEVwAAAng"] [Tue Aug 18 12:55:33.826673 2026] [security2:error] [pid 67073:tid 67319] [client 135.225.75.187:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/0.php"] [unique_id "aoSAdfcmepr5_nHgLbNEWgAAAoY"] [Tue Aug 18 12:55:33.848919 2026] [security2:error] [pid 67073:tid 67296] [client 20.104.100.201:21481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAdfcmepr5_nHgLbNEWwAAAm8"] [Tue Aug 18 12:55:33.856784 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:9207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/57.php"] [unique_id "aoSAddO5rbWdOArH04KE8wAAARk"] [Tue Aug 18 12:55:33.863129 2026] [security2:error] [pid 66623:tid 66881] [client 20.171.51.14:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xn.php"] [unique_id "aoSAddO5rbWdOArH04KE9AAAAX0"] [Tue Aug 18 12:55:33.869021 2026] [security2:error] [pid 67073:tid 67263] [client 4.232.151.198:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/666.php"] [unique_id "aoSAdfcmepr5_nHgLbNEXQAAAk4"] [Tue Aug 18 12:55:33.896326 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.136.165:43667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/g.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYQAAAo4"] [Tue Aug 18 12:55:33.903465 2026] [security2:error] [pid 67073:tid 67271] [client 20.250.13.23:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/aa.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYgAAAlY"] [Tue Aug 18 12:55:33.908592 2026] [security2:error] [pid 66623:tid 66792] [client 20.91.215.254:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/abcd.php"] [unique_id "aoSAddO5rbWdOArH04KE9QAAASQ"] [Tue Aug 18 12:55:33.960791 2026] [security2:error] [pid 67073:tid 67099] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/30.php"] [unique_id "aoSAdfcmepr5_nHgLbNEYwACHRc"] [Tue Aug 18 12:55:33.980746 2026] [security2:error] [pid 67073:tid 67267] [client 20.151.109.219:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xv.php"] [unique_id "aoSAdfcmepr5_nHgLbNEZgAAAlI"] [Tue Aug 18 12:55:34.005785 2026] [security2:error] [pid 66623:tid 66776] [client 20.48.236.86:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/admin.php"] [unique_id "aoSAdtO5rbWdOArH04KE9gAAARQ"] [Tue Aug 18 12:55:34.010096 2026] [security2:error] [pid 67073:tid 67224] [client 20.100.169.31:45603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAdvcmepr5_nHgLbNEZwAAAic"] [Tue Aug 18 12:55:34.026915 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEaQAAAoc"] [Tue Aug 18 12:55:34.036713 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.169.31:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAdvcmepr5_nHgLbNEagAAAkw"] [Tue Aug 18 12:55:34.054243 2026] [security2:error] [pid 67073:tid 67323] [client 20.65.69.59:3707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fraie1p4.php"] [unique_id "aoSAdvcmepr5_nHgLbNEawAAAoo"] [Tue Aug 18 12:55:34.058607 2026] [security2:error] [pid 66623:tid 66857] [client 20.171.51.14:58827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kh.php"] [unique_id "aoSAdtO5rbWdOArH04KE9wAAAWU"] [Tue Aug 18 12:55:34.065188 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.6.191:6607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/404.php"] [unique_id "aoSAdvcmepr5_nHgLbNEbAAAAm4"] [Tue Aug 18 12:55:34.079841 2026] [security2:error] [pid 67073:tid 67276] [client 20.104.85.180:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEbgAAAls"] [Tue Aug 18 12:55:34.094400 2026] [security2:error] [pid 66623:tid 66819] [client 52.173.121.69:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAdtO5rbWdOArH04KE-AAAAT8"] [Tue Aug 18 12:55:34.124494 2026] [security2:error] [pid 66623:tid 66883] [client 4.223.164.152:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/edit.php"] [unique_id "aoSAdtO5rbWdOArH04KE-QAAAX8"] [Tue Aug 18 12:55:34.126771 2026] [security2:error] [pid 67073:tid 67326] [client 20.104.100.201:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/xwpg.php"] [unique_id "aoSAdvcmepr5_nHgLbNEcAAAAo0"] [Tue Aug 18 12:55:34.139414 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yw.php"] [unique_id "aoSAdvcmepr5_nHgLbNEcgAAAmk"] [Tue Aug 18 12:55:34.146810 2026] [security2:error] [pid 67073:tid 67313] [client 172.182.200.96:14245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdQAAAoA"] [Tue Aug 18 12:55:34.177376 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/new.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdgAAAj0"] [Tue Aug 18 12:55:34.192331 2026] [security2:error] [pid 67073:tid 67272] [client 20.226.6.191:56255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/13.php"] [unique_id "aoSAdvcmepr5_nHgLbNEdwAAAlc"] [Tue Aug 18 12:55:34.205369 2026] [security2:error] [pid 67073:tid 67142] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEeAACiEI"] [Tue Aug 18 12:55:34.212288 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:34.212550 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:34.215270 2026] [security2:error] [pid 67073:tid 67268] [client 213.35.127.232:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAdvcmepr5_nHgLbNEegAAAlM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:34.255609 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.130.103:14449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/biufile.php"] [unique_id "aoSAdtO5rbWdOArH04KE-gAAAUw"] [Tue Aug 18 12:55:34.296708 2026] [security2:error] [pid 67073:tid 67238] [client 20.42.19.40:2201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEfgAAAjU"] [Tue Aug 18 12:55:34.313485 2026] [security2:error] [pid 67073:tid 67241] [client 74.248.136.165:38219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/x7.php"] [unique_id "aoSAdvcmepr5_nHgLbNEfwAAAjg"] [Tue Aug 18 12:55:34.326594 2026] [security2:error] [pid 67073:tid 67255] [client 20.91.215.254:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/lite.php"] [unique_id "aoSAdvcmepr5_nHgLbNEgAAAAkY"] [Tue Aug 18 12:55:34.331357 2026] [security2:error] [pid 67073:tid 67229] [client 20.116.17.175:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/loader.php"] [unique_id "aoSAdvcmepr5_nHgLbNEggAAAiw"] [Tue Aug 18 12:55:34.334394 2026] [security2:error] [pid 67073:tid 67218] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEewACIVg"] [Tue Aug 18 12:55:34.343043 2026] [security2:error] [pid 66623:tid 66825] [client 20.151.109.219:59744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mx.php"] [unique_id "aoSAdtO5rbWdOArH04KE-wAAAUU"] [Tue Aug 18 12:55:34.358851 2026] [security2:error] [pid 67073:tid 67277] [client 20.48.236.86:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ajax.php"] [unique_id "aoSAdvcmepr5_nHgLbNEhAAAAlw"] [Tue Aug 18 12:55:34.365538 2026] [security2:error] [pid 67073:tid 67285] [client 68.221.73.131:61293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/xx.php"] [unique_id "aoSAdvcmepr5_nHgLbNEhwAAAmQ"] [Tue Aug 18 12:55:34.368197 2026] [security2:error] [pid 67073:tid 67234] [client 20.104.85.180:8050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAdvcmepr5_nHgLbNEiAAAAjE"] [Tue Aug 18 12:55:34.382893 2026] [security2:error] [pid 67073:tid 67306] [client 20.163.43.14:4323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cah.php"] [unique_id "aoSAdvcmepr5_nHgLbNEiQAAAnk"] [Tue Aug 18 12:55:34.400182 2026] [security2:error] [pid 66623:tid 66841] [client 52.139.47.57:16684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/bypass.php"] [unique_id "aoSAdtO5rbWdOArH04KE_AAAAVU"] [Tue Aug 18 12:55:34.412828 2026] [security2:error] [pid 66623:tid 66860] [client 20.104.100.201:21452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/dex.php"] [unique_id "aoSAdtO5rbWdOArH04KE_gAAAWg"] [Tue Aug 18 12:55:34.441156 2026] [security2:error] [pid 66623:tid 66767] [client 157.20.138.62:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KE_wAAAQs"] [Tue Aug 18 12:55:34.441303 2026] [security2:error] [pid 66623:tid 66767] [client 157.20.138.62:57984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KE_wAAAQs"] [Tue Aug 18 12:55:34.462736 2026] [security2:error] [pid 67073:tid 67223] [client 52.238.210.254:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjAAAAiY"] [Tue Aug 18 12:55:34.487293 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ry.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjQACFTs"] [Tue Aug 18 12:55:34.488353 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.61.152:60997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAdtO5rbWdOArH04KFAAAAARw"] [Tue Aug 18 12:55:34.491257 2026] [security2:error] [pid 67073:tid 67308] [client 172.182.200.96:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAdvcmepr5_nHgLbNEjwAAAns"] [Tue Aug 18 12:55:34.505450 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.6.191:38247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEkAAAAjs"] [Tue Aug 18 12:55:34.536439 2026] [security2:error] [pid 67073:tid 67283] [client 158.158.34.183:62215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/menu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEkwAAAmI"] [Tue Aug 18 12:55:34.537950 2026] [security2:error] [pid 66623:tid 66893] [client 20.51.153.15:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/qh.php"] [unique_id "aoSAdtO5rbWdOArH04KFAQAAAYk"] [Tue Aug 18 12:55:34.559673 2026] [security2:error] [pid 67073:tid 67273] [client 74.248.133.44:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/theme.php"] [unique_id "aoSAdvcmepr5_nHgLbNElAAAAlg"] [Tue Aug 18 12:55:34.560889 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/222.php"] [unique_id "aoSAdvcmepr5_nHgLbNElQAAAnQ"] [Tue Aug 18 12:55:34.564181 2026] [security2:error] [pid 67073:tid 67278] [client 4.223.164.152:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAdvcmepr5_nHgLbNElgAAAl0"] [Tue Aug 18 12:55:34.638960 2026] [security2:error] [pid 67073:tid 67262] [client 20.48.236.86:16302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/abe.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmgAAAk0"] [Tue Aug 18 12:55:34.652779 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.6.191:6586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-login.php"] [unique_id "aoSAdtO5rbWdOArH04KFAgAAAXg"] [Tue Aug 18 12:55:34.679788 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmwAAApM"] [Tue Aug 18 12:55:34.680093 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jb.php"] [unique_id "aoSAdvcmepr5_nHgLbNEnAAAAmw"] [Tue Aug 18 12:55:34.684055 2026] [security2:error] [pid 67073:tid 67134] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pm.php"] [unique_id "aoSAdvcmepr5_nHgLbNEnQACbzo"] [Tue Aug 18 12:55:34.685578 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.100.201:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/xyn.php"] [unique_id "aoSAdvcmepr5_nHgLbNEngAAAio"] [Tue Aug 18 12:55:34.701209 2026] [security2:error] [pid 67073:tid 67263] [client 68.155.154.236:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zznmg.php"] [unique_id "aoSAdvcmepr5_nHgLbNEoAAAAk4"] [Tue Aug 18 12:55:34.701236 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.75.187:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/dom.php"] [unique_id "aoSAdvcmepr5_nHgLbNEoQAAAlA"] [Tue Aug 18 12:55:34.709305 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:59767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/45.php"] [unique_id "aoSAdvcmepr5_nHgLbNEogAAAn0"] [Tue Aug 18 12:55:34.716109 2026] [security2:error] [pid 67073:tid 67327] [client 20.104.85.180:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAdvcmepr5_nHgLbNEowAAAo4"] [Tue Aug 18 12:55:34.734097 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:10074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/god.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpAAAApE"] [Tue Aug 18 12:55:34.734118 2026] [security2:error] [pid 67073:tid 67231] [client 20.116.17.175:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/zero.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpQAAAi4"] [Tue Aug 18 12:55:34.737041 2026] [security2:error] [pid 67073:tid 67249] [client 20.205.121.237:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpgAAAkA"] [Tue Aug 18 12:55:34.741662 2026] [security2:error] [pid 67073:tid 67205] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAdvcmepr5_nHgLbNEmQACFG8"] [Tue Aug 18 12:55:34.752800 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:29205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/47.php"] [unique_id "aoSAdvcmepr5_nHgLbNEpwAAAlE"] [Tue Aug 18 12:55:34.754530 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/sky.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqAAAAh0"] [Tue Aug 18 12:55:34.771597 2026] [security2:error] [pid 67073:tid 67220] [client 20.51.153.15:9194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/r.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqgAAAiM"] [Tue Aug 18 12:55:34.773319 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.6.191:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAdvcmepr5_nHgLbNEqwAAAoI"] [Tue Aug 18 12:55:34.803860 2026] [security2:error] [pid 67073:tid 67215] [client 20.91.215.254:27436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/kj.php"] [unique_id "aoSAdvcmepr5_nHgLbNErgAAAh4"] [Tue Aug 18 12:55:34.818125 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:34.818577 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:34.818594 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.130.103:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dejavu.php"] [unique_id "aoSAdvcmepr5_nHgLbNEsAAAAn8"] [Tue Aug 18 12:55:34.846702 2026] [security2:error] [pid 67073:tid 67295] [client 68.221.73.131:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/av.php"] [unique_id "aoSAdvcmepr5_nHgLbNEsQAAAm4"] [Tue Aug 18 12:55:34.899809 2026] [security2:error] [pid 67073:tid 67290] [client 20.29.77.16:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/mandrill.php"] [unique_id "aoSAdvcmepr5_nHgLbNEswAAAmk"] [Tue Aug 18 12:55:34.917065 2026] [security2:error] [pid 67073:tid 67259] [client 20.163.43.14:4379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/chosen.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtAAAAko"] [Tue Aug 18 12:55:34.928298 2026] [security2:error] [pid 67073:tid 67152] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dr.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtQACKUw"] [Tue Aug 18 12:55:34.932475 2026] [security2:error] [pid 67073:tid 67287] [client 20.163.43.14:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/system_log.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtgAAAmY"] [Tue Aug 18 12:55:34.934678 2026] [security2:error] [pid 67073:tid 67291] [client 172.182.200.96:14256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAdvcmepr5_nHgLbNEtwAAAmo"] [Tue Aug 18 12:55:34.942299 2026] [security2:error] [pid 67073:tid 67246] [client 20.48.236.86:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/bs1.php"] [unique_id "aoSAdvcmepr5_nHgLbNEuAAAAj0"] [Tue Aug 18 12:55:34.964612 2026] [security2:error] [pid 66623:tid 66850] [client 20.104.100.201:58899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAdtO5rbWdOArH04KFBQAAAV4"] [Tue Aug 18 12:55:34.987611 2026] [security2:error] [pid 66623:tid 66813] [client 149.34.210.141:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KFBgAAATk"] [Tue Aug 18 12:55:35.004743 2026] [security2:error] [pid 67073:tid 67282] [client 20.91.215.254:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAd_cmepr5_nHgLbNEvAAAAmE"] [Tue Aug 18 12:55:35.014623 2026] [security2:error] [pid 67073:tid 67280] [client 4.223.164.152:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inputs.php"] [unique_id "aoSAd_cmepr5_nHgLbNEvgAAAl8"] [Tue Aug 18 12:55:35.029176 2026] [security2:error] [pid 67073:tid 67257] [client 20.151.109.219:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wy.php"] [unique_id "aoSAd_cmepr5_nHgLbNEvwAAAkg"] [Tue Aug 18 12:55:35.055712 2026] [security2:error] [pid 67073:tid 67238] [client 20.42.19.40:2738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAd_cmepr5_nHgLbNEwQAAAjU"] [Tue Aug 18 12:55:35.115506 2026] [security2:error] [pid 67073:tid 67222] [client 20.116.17.175:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/002.php"] [unique_id "aoSAd_cmepr5_nHgLbNEwgAAAiU"] [Tue Aug 18 12:55:35.148518 2026] [security2:error] [pid 66623:tid 66880] [client 20.104.85.180:7995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/rip.php"] [unique_id "aoSAd9O5rbWdOArH04KFCAAAAXw"] [Tue Aug 18 12:55:35.152419 2026] [security2:error] [pid 67073:tid 67232] [client 20.251.48.93:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/k.php"] [unique_id "aoSAd_cmepr5_nHgLbNExgAAAi8"] [Tue Aug 18 12:55:35.154844 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:16641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/lock360.php"] [unique_id "aoSAd_cmepr5_nHgLbNExwAAAnk"] [Tue Aug 18 12:55:35.159185 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.136.165:30915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAd9O5rbWdOArH04KFCQAAATA"] [Tue Aug 18 12:55:35.166847 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ts.php"] [unique_id "aoSAd_cmepr5_nHgLbNEyQACRxw"] [Tue Aug 18 12:55:35.222892 2026] [security2:error] [pid 66623:tid 66817] [client 213.202.253.4:49463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/userfuns.php"] [unique_id "aoSAd9O5rbWdOArH04KFCgAAAT0"], referer: www.google.com [Tue Aug 18 12:55:35.226715 2026] [security2:error] [pid 67073:tid 67326] [client 213.35.127.232:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzAAAAo0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:35.241842 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.100.201:58904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-good.php"] [unique_id "aoSAd9O5rbWdOArH04KFCwAAAU8"] [Tue Aug 18 12:55:35.253199 2026] [security2:error] [pid 66623:tid 66813] [client 149.34.210.141:49712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAdtO5rbWdOArH04KFBgAAATk"] [Tue Aug 18 12:55:35.253338 2026] [security2:error] [pid 67073:tid 67308] [client 20.51.153.15:8807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ev.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzgAAAns"] [Tue Aug 18 12:55:35.312882 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Warning. String match "408" at RESPONSE_STATUS. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "35"] [id "343434"] [rev "1"] [msg "Atomicorp.com WAF Rules: Client Connection dropped by Apache due to slow connection, possible Slowaris attack"] [severity "WARNING"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"] [Tue Aug 18 12:55:35.312938 2026] [security2:error] [pid 67073:tid 67240] [client 103.120.71.157:5300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "408"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAaPcmepr5_nHgLbNAGQAAAjc"] [Tue Aug 18 12:55:35.314878 2026] [security2:error] [pid 67073:tid 67244] [client 172.182.200.96:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNEzwAAAjs"] [Tue Aug 18 12:55:35.321525 2026] [security2:error] [pid 67073:tid 67242] [client 20.48.236.86:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/yes.php"] [unique_id "aoSAd_cmepr5_nHgLbNE0AAAAjk"] [Tue Aug 18 12:55:35.325944 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/info.php"] [unique_id "aoSAd_cmepr5_nHgLbNE0gAAAhk"] [Tue Aug 18 12:55:35.348238 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:3022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/content.php"] [unique_id "aoSAd9O5rbWdOArH04KFDAAAARg"] [Tue Aug 18 12:55:35.359330 2026] [security2:error] [pid 66623:tid 66766] [client 74.248.130.103:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aaf.php"] [unique_id "aoSAd9O5rbWdOArH04KFDQAAAQo"] [Tue Aug 18 12:55:35.369544 2026] [security2:error] [pid 66623:tid 66834] [client 20.151.109.219:21646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/f.php"] [unique_id "aoSAd9O5rbWdOArH04KFDgAAAU4"] [Tue Aug 18 12:55:35.371457 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/do.php"] [unique_id "aoSAd_cmepr5_nHgLbNE1QAAAjI"] [Tue Aug 18 12:55:35.387473 2026] [security2:error] [pid 66623:tid 66884] [client 132.196.61.152:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/sky.php"] [unique_id "aoSAd9O5rbWdOArH04KFEAAAAYA"] [Tue Aug 18 12:55:35.400887 2026] [security2:error] [pid 67073:tid 67301] [client 68.221.73.131:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/media.php"] [unique_id "aoSAd_cmepr5_nHgLbNE1gAAAnQ"] [Tue Aug 18 12:55:35.426020 2026] [security2:error] [pid 67073:tid 67136] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/53.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2QAChjw"] [Tue Aug 18 12:55:35.432155 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/payout.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2gAAAkM"] [Tue Aug 18 12:55:35.446244 2026] [security2:error] [pid 67073:tid 67332] [client 4.223.164.152:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/av.php"] [unique_id "aoSAd_cmepr5_nHgLbNE2wAAApM"] [Tue Aug 18 12:55:35.461254 2026] [security2:error] [pid 67073:tid 67296] [client 20.215.241.237:24193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAd_cmepr5_nHgLbNE3AAAAm8"] [Tue Aug 18 12:55:35.509394 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNE3wAAAlY"] [Tue Aug 18 12:55:35.516783 2026] [security2:error] [pid 67073:tid 67330] [client 135.225.75.187:62051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/bb.php"] [unique_id "aoSAd_cmepr5_nHgLbNE4QAAApE"] [Tue Aug 18 12:55:35.520187 2026] [security2:error] [pid 67073:tid 67249] [client 20.104.100.201:58439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wmore1.php"] [unique_id "aoSAd_cmepr5_nHgLbNE4gAAAkA"] [Tue Aug 18 12:55:35.522980 2026] [security2:error] [pid 67073:tid 67325] [client 147.224.249.133:61068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSAd_cmepr5_nHgLbNE4wAAAow"] [Tue Aug 18 12:55:35.524691 2026] [autoindex:error] [pid 67073:tid 67231] [client 20.104.85.180:8003] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:35.566555 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:1363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/gg.php"] [unique_id "aoSAd_cmepr5_nHgLbNE5QAAAlI"] [Tue Aug 18 12:55:35.571325 2026] [security2:error] [pid 66623:tid 66801] [client 4.232.151.198:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/wk/index.php"] [unique_id "aoSAd9O5rbWdOArH04KFEQAAAS0"] [Tue Aug 18 12:55:35.576136 2026] [security2:error] [pid 67073:tid 67270] [client 20.91.215.254:27438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/languages.php"] [unique_id "aoSAd_cmepr5_nHgLbNE5wAAAlU"] [Tue Aug 18 12:55:35.576706 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:9940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/8.php"] [unique_id "aoSAd_cmepr5_nHgLbNE6AAAAiM"] [Tue Aug 18 12:55:35.579823 2026] [security2:error] [pid 67073:tid 67224] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/nine2code.php"] [unique_id "aoSAd_cmepr5_nHgLbNE6wAAAic"] [Tue Aug 18 12:55:35.599529 2026] [security2:error] [pid 67073:tid 67219] [client 52.238.210.254:8257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/ioxi-o.php"] [unique_id "aoSAd_cmepr5_nHgLbNE8AAAAiI"] [Tue Aug 18 12:55:35.646851 2026] [security2:error] [pid 67073:tid 67275] [client 20.48.236.86:16314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/go.php"] [unique_id "aoSAd_cmepr5_nHgLbNE9QAAAlo"] [Tue Aug 18 12:55:35.662000 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-AAAAmw"] [Tue Aug 18 12:55:35.664075 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-QAAAhc"] [Tue Aug 18 12:55:35.670577 2026] [security2:error] [pid 67073:tid 67269] [client 172.182.200.96:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNE-wAAAlQ"] [Tue Aug 18 12:55:35.712308 2026] [security2:error] [pid 67073:tid 67146] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lq.php"] [unique_id "aoSAd_cmepr5_nHgLbNE_wACZkY"] [Tue Aug 18 12:55:35.716499 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:35.716824 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:35.717713 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:52074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vp.php"] [unique_id "aoSAd_cmepr5_nHgLbNFAAAAAmo"] [Tue Aug 18 12:55:35.739957 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/30.php"] [unique_id "aoSAd_cmepr5_nHgLbNFAQAAAog"] [Tue Aug 18 12:55:35.784146 2026] [security2:error] [pid 66623:tid 66891] [client 52.173.121.69:24963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAd9O5rbWdOArH04KFFAAAAYc"] [Tue Aug 18 12:55:35.788176 2026] [security2:error] [pid 67073:tid 67292] [client 20.205.121.237:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/file-admin.php"] [unique_id "aoSAd_cmepr5_nHgLbNFBgAAAms"] [Tue Aug 18 12:55:35.796344 2026] [security2:error] [pid 67073:tid 67329] [client 20.104.100.201:21416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/special.php"] [unique_id "aoSAd_cmepr5_nHgLbNFBwAAApA"] [Tue Aug 18 12:55:35.798854 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.85.180:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAd_cmepr5_nHgLbNFCAAAAkw"] [Tue Aug 18 12:55:35.826635 2026] [security2:error] [pid 66623:tid 66815] [client 20.42.19.40:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/class.php"] [unique_id "aoSAd9O5rbWdOArH04KFFQAAATs"] [Tue Aug 18 12:55:35.908167 2026] [security2:error] [pid 67073:tid 67277] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/num.php"] [unique_id "aoSAd_cmepr5_nHgLbNFDgAAAlw"] [Tue Aug 18 12:55:35.913278 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:37287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAd_cmepr5_nHgLbNFDwAAAmQ"] [Tue Aug 18 12:55:35.919612 2026] [security2:error] [pid 67073:tid 67222] [client 20.42.19.40:2693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEAAAAiU"] [Tue Aug 18 12:55:35.930403 2026] [security2:error] [pid 66623:tid 66878] [client 20.163.43.14:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAd9O5rbWdOArH04KFFgAAAXo"] [Tue Aug 18 12:55:35.930962 2026] [security2:error] [pid 66623:tid 66829] [client 20.171.51.14:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yw.php"] [unique_id "aoSAd9O5rbWdOArH04KFFwAAAUk"] [Tue Aug 18 12:55:35.949318 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.133.44:24705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hyundai-steel.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEQAAAnk"] [Tue Aug 18 12:55:35.957696 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.6.191:6591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAd9O5rbWdOArH04KFGAAAATo"] [Tue Aug 18 12:55:35.974558 2026] [security2:error] [pid 67073:tid 67260] [client 20.100.169.31:31429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/index.php"] [unique_id "aoSAd_cmepr5_nHgLbNFEwAAAks"] [Tue Aug 18 12:55:35.996799 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.136.165:29118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/koiy.php"] [unique_id "aoSAd_cmepr5_nHgLbNFFgAAAkU"] [Tue Aug 18 12:55:36.011243 2026] [security2:error] [pid 67073:tid 67264] [client 20.163.43.14:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAePcmepr5_nHgLbNFGAAAAk8"] [Tue Aug 18 12:55:36.017757 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:36.018020 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:36.049132 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/you.php"] [unique_id "aoSAePcmepr5_nHgLbNFGQACFQU"] [Tue Aug 18 12:55:36.058930 2026] [security2:error] [pid 67073:tid 67297] [client 147.224.249.133:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.249.224.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSAePcmepr5_nHgLbNFGgAAAnA"] [Tue Aug 18 12:55:36.059589 2026] [security2:error] [pid 67073:tid 67308] [client 20.116.17.175:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/zxz.php"] [unique_id "aoSAePcmepr5_nHgLbNFHAAAAns"] [Tue Aug 18 12:55:36.067931 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/h02ugyh.php"] [unique_id "aoSAePcmepr5_nHgLbNFHQAAAkQ"] [Tue Aug 18 12:55:36.072918 2026] [security2:error] [pid 67073:tid 67286] [client 20.104.100.201:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFHgAAAmU"] [Tue Aug 18 12:55:36.090155 2026] [security2:error] [pid 66623:tid 66875] [client 20.104.85.180:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/moon.php"] [unique_id "aoSAeNO5rbWdOArH04KFGQAAAXc"] [Tue Aug 18 12:55:36.092067 2026] [security2:error] [pid 67073:tid 67244] [client 52.139.47.57:16696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFHwAAAjs"] [Tue Aug 18 12:55:36.092098 2026] [security2:error] [pid 67073:tid 67240] [client 20.42.19.40:9619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/flower.php"] [unique_id "aoSAePcmepr5_nHgLbNFIAAAAjc"] [Tue Aug 18 12:55:36.095240 2026] [security2:error] [pid 66623:tid 66797] [client 172.182.200.96:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/first.php"] [unique_id "aoSAeNO5rbWdOArH04KFGgAAASk"] [Tue Aug 18 12:55:36.110454 2026] [security2:error] [pid 67073:tid 67242] [client 20.226.6.191:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAePcmepr5_nHgLbNFIQAAAjk"] [Tue Aug 18 12:55:36.133826 2026] [security2:error] [pid 67073:tid 67214] [client 178.153.171.161:48961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAePcmepr5_nHgLbNFIgAAAh0"] [Tue Aug 18 12:55:36.133956 2026] [security2:error] [pid 67073:tid 67214] [client 178.153.171.161:48961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAePcmepr5_nHgLbNFIgAAAh0"] [Tue Aug 18 12:55:36.135766 2026] [security2:error] [pid 67073:tid 67305] [client 20.151.109.219:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pu.php"] [unique_id "aoSAePcmepr5_nHgLbNFIwAAAng"] [Tue Aug 18 12:55:36.155036 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:3689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/pqr.php"] [unique_id "aoSAePcmepr5_nHgLbNFJQAAAjI"] [Tue Aug 18 12:55:36.194893 2026] [security2:error] [pid 66623:tid 66785] [client 68.155.154.236:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAeNO5rbWdOArH04KFHAAAAR0"] [Tue Aug 18 12:55:36.204165 2026] [security2:error] [pid 66623:tid 66842] [client 68.221.73.131:61249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/images.php"] [unique_id "aoSAeNO5rbWdOArH04KFHQAAAVY"] [Tue Aug 18 12:55:36.232091 2026] [security2:error] [pid 67073:tid 67263] [client 20.42.19.40:2224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFKQAAAk4"] [Tue Aug 18 12:55:36.237676 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAePcmepr5_nHgLbNFKgAAAi0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:36.272808 2026] [security2:error] [pid 66623:tid 66775] [client 20.163.43.14:4400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAeNO5rbWdOArH04KFHgAAARM"] [Tue Aug 18 12:55:36.293306 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.98.162:15535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/fz.php"] [unique_id "aoSAePcmepr5_nHgLbNFLQAAAnU"] [Tue Aug 18 12:55:36.317766 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:36.318039 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:36.319218 2026] [security2:error] [pid 67073:tid 67330] [client 20.48.236.86:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/cof.php"] [unique_id "aoSAePcmepr5_nHgLbNFMQAAApE"] [Tue Aug 18 12:55:36.328560 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ez.php"] [unique_id "aoSAePcmepr5_nHgLbNFMwACjHo"] [Tue Aug 18 12:55:36.334876 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.6.191:36403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/01.php"] [unique_id "aoSAePcmepr5_nHgLbNFOAAAAlE"] [Tue Aug 18 12:55:36.336687 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:9640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/motu.php"] [unique_id "aoSAePcmepr5_nHgLbNFOQAAAlI"] [Tue Aug 18 12:55:36.343647 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:27201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/main.php"] [unique_id "aoSAePcmepr5_nHgLbNFOgAAAiM"] [Tue Aug 18 12:55:36.353451 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bh.php"] [unique_id "aoSAePcmepr5_nHgLbNFOwAAAmA"] [Tue Aug 18 12:55:36.353757 2026] [security2:error] [pid 67073:tid 67315] [client 20.104.100.201:21451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/thoms.php"] [unique_id "aoSAePcmepr5_nHgLbNFPAAAAoI"] [Tue Aug 18 12:55:36.365446 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.85.180:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/cache.php"] [unique_id "aoSAeNO5rbWdOArH04KFHwAAAUg"] [Tue Aug 18 12:55:36.368428 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:46175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAePcmepr5_nHgLbNFPQAAAoc"] [Tue Aug 18 12:55:36.380715 2026] [security2:error] [pid 66623:tid 66788] [client 20.163.43.14:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/abc.php"] [unique_id "aoSAeNO5rbWdOArH04KFIAAAASA"] [Tue Aug 18 12:55:36.408974 2026] [security2:error] [pid 67073:tid 67323] [client 147.224.249.133:61377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSAePcmepr5_nHgLbNFPgAAAoo"] [Tue Aug 18 12:55:36.412513 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.136.165:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/iko.php"] [unique_id "aoSAePcmepr5_nHgLbNFPwAAAm4"] [Tue Aug 18 12:55:36.418963 2026] [security2:error] [pid 66623:tid 66889] [client 20.91.215.254:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAeNO5rbWdOArH04KFIQAAAYU"] [Tue Aug 18 12:55:36.436000 2026] [security2:error] [pid 67073:tid 67289] [client 20.51.153.15:8827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xs.php"] [unique_id "aoSAePcmepr5_nHgLbNFQgAAAmg"] [Tue Aug 18 12:55:36.451126 2026] [security2:error] [pid 67073:tid 67208] [client 20.151.109.219:24851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ry.php"] [unique_id "aoSAePcmepr5_nHgLbNFQwAAAhc"] [Tue Aug 18 12:55:36.495878 2026] [security2:error] [pid 67073:tid 67303] [client 20.251.48.93:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/82.php"] [unique_id "aoSAePcmepr5_nHgLbNFRAAAAnY"] [Tue Aug 18 12:55:36.495878 2026] [security2:error] [pid 66623:tid 66888] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "aoSAeNO5rbWdOArH04KFIgAAAYQ"] [Tue Aug 18 12:55:36.504154 2026] [security2:error] [pid 67073:tid 67237] [client 52.238.210.254:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/0x.php"] [unique_id "aoSAePcmepr5_nHgLbNFRQAAAjQ"] [Tue Aug 18 12:55:36.542159 2026] [security2:error] [pid 67073:tid 67246] [client 20.116.17.175:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAePcmepr5_nHgLbNFRwAAAj0"] [Tue Aug 18 12:55:36.563187 2026] [security2:error] [pid 67073:tid 67268] [client 20.91.215.254:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/nw.php"] [unique_id "aoSAePcmepr5_nHgLbNFSQAAAlM"] [Tue Aug 18 12:55:36.563217 2026] [security2:error] [pid 67073:tid 67293] [client 66.249.70.4:43493] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.drogavilla.com.br"] [uri "/robots.txt"] [unique_id "aoSAePcmepr5_nHgLbNFSAAAAmw"] [Tue Aug 18 12:55:36.570627 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ok.php"] [unique_id "aoSAePcmepr5_nHgLbNFSgAAAmE"] [Tue Aug 18 12:55:36.586014 2026] [security2:error] [pid 67073:tid 67248] [client 74.248.130.103:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/155.php"] [unique_id "aoSAePcmepr5_nHgLbNFSwAAAj8"] [Tue Aug 18 12:55:36.588202 2026] [security2:error] [pid 66623:tid 66793] [client 172.182.200.96:13895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAeNO5rbWdOArH04KFJAAAASU"] [Tue Aug 18 12:55:36.599501 2026] [security2:error] [pid 66623:tid 66846] [client 20.42.19.40:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/404.php"] [unique_id "aoSAeNO5rbWdOArH04KFJgAAAVo"] [Tue Aug 18 12:55:36.601207 2026] [security2:error] [pid 67073:tid 67215] [client 20.100.169.31:52437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSAePcmepr5_nHgLbNFTQAAAh4"] [Tue Aug 18 12:55:36.615379 2026] [security2:error] [pid 66623:tid 66805] [client 20.163.43.14:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/k.php"] [unique_id "aoSAeNO5rbWdOArH04KFKAAAATE"] [Tue Aug 18 12:55:36.627270 2026] [security2:error] [pid 67073:tid 67255] [client 20.104.100.201:21456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAePcmepr5_nHgLbNFTwAAAkY"] [Tue Aug 18 12:55:36.630594 2026] [security2:error] [pid 67073:tid 67250] [client 5.253.205.188:38544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdatadata_en_us.bak"] [unique_id "aoSAePcmepr5_nHgLbNFUAAAAkE"], referer: https://medihub.com.br/installdatadata_en_us.bak [Tue Aug 18 12:55:36.634784 2026] [security2:error] [pid 67073:tid 67092] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/asus.php"] [unique_id "aoSAePcmepr5_nHgLbNFUQACIRA"] [Tue Aug 18 12:55:36.644882 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.85.180:43545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/gecko.php"] [unique_id "aoSAePcmepr5_nHgLbNFUgAAAlw"] [Tue Aug 18 12:55:36.692156 2026] [autoindex:error] [pid 66623:tid 66848] [client 20.104.85.180:8001] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:36.732918 2026] [security2:error] [pid 66623:tid 66770] [client 20.163.43.14:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/akcc.php"] [unique_id "aoSAeNO5rbWdOArH04KFLAAAAQ4"] [Tue Aug 18 12:55:36.742381 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wso.php"] [unique_id "aoSAeNO5rbWdOArH04KFLQAAARI"] [Tue Aug 18 12:55:36.748407 2026] [security2:error] [pid 67073:tid 67313] [client 147.224.249.133:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.249.224.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www2.lazzarevestimentos.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSAePcmepr5_nHgLbNFVwAAAoA"] [Tue Aug 18 12:55:36.782538 2026] [security2:error] [pid 67073:tid 67311] [client 68.221.73.131:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/mac.php"] [unique_id "aoSAePcmepr5_nHgLbNFWQAAAn4"] [Tue Aug 18 12:55:36.801702 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.61.152:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file5.php"] [unique_id "aoSAePcmepr5_nHgLbNFWwAAAkQ"] [Tue Aug 18 12:55:36.805015 2026] [security2:error] [pid 67073:tid 67286] [client 4.223.164.152:37311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAePcmepr5_nHgLbNFXAAAAmU"] [Tue Aug 18 12:55:36.806729 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pm.php"] [unique_id "aoSAePcmepr5_nHgLbNFXQAAAjc"] [Tue Aug 18 12:55:36.820155 2026] [security2:error] [pid 66623:tid 66867] [client 4.232.151.198:37352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/ws54.php"] [unique_id "aoSAeNO5rbWdOArH04KFLgAAAW8"] [Tue Aug 18 12:55:36.830066 2026] [security2:error] [pid 66623:tid 66870] [client 74.248.136.165:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/raw.php"] [unique_id "aoSAeNO5rbWdOArH04KFLwAAAXI"] [Tue Aug 18 12:55:36.851754 2026] [security2:error] [pid 67073:tid 67300] [client 20.42.19.40:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lite.php"] [unique_id "aoSAePcmepr5_nHgLbNFXwAAAnM"] [Tue Aug 18 12:55:36.865964 2026] [security2:error] [pid 67073:tid 67287] [client 20.205.121.237:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/file.php"] [unique_id "aoSAePcmepr5_nHgLbNFYQAAAmY"] [Tue Aug 18 12:55:36.898818 2026] [security2:error] [pid 66623:tid 66776] [client 20.104.100.201:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/root.php"] [unique_id "aoSAeNO5rbWdOArH04KFMAAAARQ"] [Tue Aug 18 12:55:36.904878 2026] [security2:error] [pid 67073:tid 67199] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/22.php"] [unique_id "aoSAePcmepr5_nHgLbNFYwACYns"] [Tue Aug 18 12:55:36.953217 2026] [security2:error] [pid 67073:tid 67252] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAePcmepr5_nHgLbNFZQAAAkM"] [Tue Aug 18 12:55:37.015497 2026] [security2:error] [pid 67073:tid 67326] [client 172.182.200.96:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFaAAAAo0"] [Tue Aug 18 12:55:37.049992 2026] [security2:error] [pid 67073:tid 67284] [client 20.100.169.31:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/p.php"] [unique_id "aoSAefcmepr5_nHgLbNFaQAAAmM"] [Tue Aug 18 12:55:37.073560 2026] [security2:error] [pid 67073:tid 67214] [client 20.91.215.254:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFawAAAh0"] [Tue Aug 18 12:55:37.074098 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAefcmepr5_nHgLbNFbAAAAnU"] [Tue Aug 18 12:55:37.085809 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/lv.php"] [unique_id "aoSAedO5rbWdOArH04KFNQAAAUQ"] [Tue Aug 18 12:55:37.092050 2026] [security2:error] [pid 66623:tid 66777] [client 20.116.17.175:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/aa.php"] [unique_id "aoSAedO5rbWdOArH04KFNgAAARU"] [Tue Aug 18 12:55:37.095986 2026] [security2:error] [pid 66623:tid 66832] [client 20.42.19.40:9642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lock360.php"] [unique_id "aoSAedO5rbWdOArH04KFNwAAAUw"] [Tue Aug 18 12:55:37.113855 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/sf.php"] [unique_id "aoSAefcmepr5_nHgLbNFbwAAAow"] [Tue Aug 18 12:55:37.119770 2026] [security2:error] [pid 66623:tid 66854] [client 20.163.43.14:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/403.php"] [unique_id "aoSAedO5rbWdOArH04KFOAAAAWI"] [Tue Aug 18 12:55:37.143981 2026] [security2:error] [pid 67073:tid 67084] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zs.php"] [unique_id "aoSAefcmepr5_nHgLbNFcQACFAg"] [Tue Aug 18 12:55:37.164987 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.130.103:15362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ops.php"] [unique_id "aoSAefcmepr5_nHgLbNFcwAAAlI"] [Tue Aug 18 12:55:37.167090 2026] [security2:error] [pid 67073:tid 67324] [client 20.151.109.219:45727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dr.php"] [unique_id "aoSAefcmepr5_nHgLbNFdAAAAos"] [Tue Aug 18 12:55:37.173830 2026] [security2:error] [pid 67073:tid 67270] [client 20.104.100.201:21493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/fpwch.php"] [unique_id "aoSAefcmepr5_nHgLbNFdQAAAlU"] [Tue Aug 18 12:55:37.175134 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:9053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/pwnd/as.php"] [unique_id "aoSAefcmepr5_nHgLbNFdgAAAnA"] [Tue Aug 18 12:55:37.198371 2026] [security2:error] [pid 67073:tid 67312] [client 20.163.43.14:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wk/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFewAAAn8"] [Tue Aug 18 12:55:37.211392 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfAAAApI"] [Tue Aug 18 12:55:37.211481 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:59025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfAAAApI"] [Tue Aug 18 12:55:37.216097 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfgAAAmA"] [Tue Aug 18 12:55:37.216185 2026] [security2:error] [pid 67073:tid 67281] [client 192.141.172.134:58132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfgAAAmA"] [Tue Aug 18 12:55:37.220496 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:37.220748 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:37.237548 2026] [security2:error] [pid 67073:tid 67292] [client 85.154.68.202:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfwAAAms"] [Tue Aug 18 12:55:37.237662 2026] [security2:error] [pid 67073:tid 67292] [client 85.154.68.202:64384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFfwAAAms"] [Tue Aug 18 12:55:37.246809 2026] [security2:error] [pid 67073:tid 67239] [client 52.238.210.254:8897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/222.php"] [unique_id "aoSAefcmepr5_nHgLbNFgAAAAjY"] [Tue Aug 18 12:55:37.247132 2026] [security2:error] [pid 67073:tid 67275] [client 74.248.136.165:30924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/05.php"] [unique_id "aoSAefcmepr5_nHgLbNFgQAAAlo"] [Tue Aug 18 12:55:37.248340 2026] [security2:error] [pid 67073:tid 67202] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env"] [unique_id "aoSAefcmepr5_nHgLbNFggACaH4"] [Tue Aug 18 12:55:37.253527 2026] [security2:error] [pid 67073:tid 67208] [client 4.223.164.152:28509] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/js/jquery/"] [unique_id "aoSAefcmepr5_nHgLbNFhAAAAhc"] [Tue Aug 18 12:55:37.257744 2026] [security2:error] [pid 67073:tid 67280] [client 213.35.127.232:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAefcmepr5_nHgLbNFgwAAAl8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:37.264481 2026] [security2:error] [pid 67073:tid 67230] [client 20.100.169.31:2464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSAefcmepr5_nHgLbNFhgAAAi0"] [Tue Aug 18 12:55:37.283877 2026] [security2:error] [pid 66623:tid 66795] [client 68.221.73.131:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/ops.php"] [unique_id "aoSAedO5rbWdOArH04KFOQAAASc"] [Tue Aug 18 12:55:37.287532 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.34.183:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/spip.php"] [unique_id "aoSAefcmepr5_nHgLbNFiAAAAiA"] [Tue Aug 18 12:55:37.326323 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:27413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/lofmebwd.php"] [unique_id "aoSAedO5rbWdOArH04KFOgAAAUU"] [Tue Aug 18 12:55:37.352249 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.75.187:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp9.php"] [unique_id "aoSAefcmepr5_nHgLbNFiwAAAog"] [Tue Aug 18 12:55:37.358922 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.169.31:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/404.php"] [unique_id "aoSAefcmepr5_nHgLbNFjAAAAlk"] [Tue Aug 18 12:55:37.366803 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iz.php"] [unique_id "aoSAefcmepr5_nHgLbNFjQACUyY"] [Tue Aug 18 12:55:37.375474 2026] [security2:error] [pid 66623:tid 66885] [client 20.48.236.86:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/Engine.php"] [unique_id "aoSAedO5rbWdOArH04KFPAAAAYE"] [Tue Aug 18 12:55:37.380414 2026] [security2:error] [pid 66623:tid 66893] [client 20.42.19.40:9700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSAedO5rbWdOArH04KFPQAAAYk"] [Tue Aug 18 12:55:37.388890 2026] [security2:error] [pid 66623:tid 66768] [client 20.171.51.14:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/qh.php"] [unique_id "aoSAedO5rbWdOArH04KFPwAAAQw"] [Tue Aug 18 12:55:37.454663 2026] [security2:error] [pid 67073:tid 67238] [client 20.104.100.201:21449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/mg.php"] [unique_id "aoSAefcmepr5_nHgLbNFkAAAAjU"] [Tue Aug 18 12:55:37.455901 2026] [security2:error] [pid 67073:tid 67209] [client 103.82.26.211:60053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "massagemrelax.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSAefcmepr5_nHgLbNFkQAAAhg"] [Tue Aug 18 12:55:37.493686 2026] [security2:error] [pid 66623:tid 66853] [client 20.116.17.175:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/echkm.php"] [unique_id "aoSAedO5rbWdOArH04KFQQAAAWE"] [Tue Aug 18 12:55:37.513211 2026] [security2:error] [pid 67073:tid 67234] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAefcmepr5_nHgLbNFkgAAAjE"] [Tue Aug 18 12:55:37.527784 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:37.528190 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:37.539881 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ts.php"] [unique_id "aoSAefcmepr5_nHgLbNFlQAAAiU"] [Tue Aug 18 12:55:37.542631 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.6.191:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/index/function.php"] [unique_id "aoSAefcmepr5_nHgLbNFlgAAAig"] [Tue Aug 18 12:55:37.548761 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4320] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSAedO5rbWdOArH04KFQgAAAUI"] [Tue Aug 18 12:55:37.548881 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSAedO5rbWdOArH04KFQgAAAUI"] [Tue Aug 18 12:55:37.565015 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/se.php"] [unique_id "aoSAefcmepr5_nHgLbNFmAACR1A"] [Tue Aug 18 12:55:37.577605 2026] [security2:error] [pid 67073:tid 67206] [client 172.182.200.96:13913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFmQAAAhU"] [Tue Aug 18 12:55:37.666328 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.136.165:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/public/hi.php"] [unique_id "aoSAedO5rbWdOArH04KFRAAAATU"] [Tue Aug 18 12:55:37.729395 2026] [security2:error] [pid 67073:tid 67233] [client 20.48.236.86:16223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/hehe.php"] [unique_id "aoSAefcmepr5_nHgLbNFngAAAjA"] [Tue Aug 18 12:55:37.731219 2026] [security2:error] [pid 67073:tid 67305] [client 20.104.100.201:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/reop3.php"] [unique_id "aoSAefcmepr5_nHgLbNFnwAAAng"] [Tue Aug 18 12:55:37.733080 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAefcmepr5_nHgLbNFoAAAAnw"] [Tue Aug 18 12:55:37.743041 2026] [security2:error] [pid 67073:tid 67235] [client 4.223.164.152:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAefcmepr5_nHgLbNFoQAAAjI"] [Tue Aug 18 12:55:37.765032 2026] [security2:error] [pid 66623:tid 66813] [client 20.42.19.40:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAedO5rbWdOArH04KFRgAAATk"] [Tue Aug 18 12:55:37.772894 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.130.103:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/mac.php"] [unique_id "aoSAefcmepr5_nHgLbNFogAAAjM"] [Tue Aug 18 12:55:37.809218 2026] [security2:error] [pid 67073:tid 67332] [client 20.171.51.14:33683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ct.php"] [unique_id "aoSAefcmepr5_nHgLbNFpAAAApM"] [Tue Aug 18 12:55:37.810287 2026] [security2:error] [pid 67073:tid 67228] [client 52.238.210.254:10239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/aa.php"] [unique_id "aoSAefcmepr5_nHgLbNFpQAAAis"] [Tue Aug 18 12:55:37.819251 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.6.191:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/new.php"] [unique_id "aoSAefcmepr5_nHgLbNFqAAAAiw"] [Tue Aug 18 12:55:37.844009 2026] [security2:error] [pid 67073:tid 67227] [client 202.46.68.84:10299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.68.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idealesquadriasivoti.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFqQAAAio"] [Tue Aug 18 12:55:37.844135 2026] [security2:error] [pid 67073:tid 67227] [client 202.46.68.84:10299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "idealesquadriasivoti.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAefcmepr5_nHgLbNFqQAAAio"] [Tue Aug 18 12:55:37.859205 2026] [security2:error] [pid 67073:tid 67144] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vp.php"] [unique_id "aoSAefcmepr5_nHgLbNFrAACTkQ"] [Tue Aug 18 12:55:37.866279 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.169.31:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAedO5rbWdOArH04KFRwAAAXw"] [Tue Aug 18 12:55:37.893851 2026] [security2:error] [pid 67073:tid 67279] [client 20.42.19.40:2179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/xmr.php"] [unique_id "aoSAefcmepr5_nHgLbNFrgAAAl4"] [Tue Aug 18 12:55:37.900875 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gecko.php"] [unique_id "aoSAefcmepr5_nHgLbNFsAAAAh0"] [Tue Aug 18 12:55:37.916534 2026] [security2:error] [pid 67073:tid 67271] [client 68.221.73.131:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/coffexium.php"] [unique_id "aoSAefcmepr5_nHgLbNFsgAAAlY"] [Tue Aug 18 12:55:37.918228 2026] [security2:error] [pid 67073:tid 67330] [client 20.163.43.14:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAefcmepr5_nHgLbNFswAAApE"] [Tue Aug 18 12:55:37.923316 2026] [security2:error] [pid 66623:tid 66866] [client 157.51.166.53:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAedO5rbWdOArH04KFSQAAAW4"] [Tue Aug 18 12:55:37.923429 2026] [security2:error] [pid 66623:tid 66866] [client 157.51.166.53:58476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAedO5rbWdOArH04KFSQAAAW4"] [Tue Aug 18 12:55:37.926373 2026] [security2:error] [pid 67073:tid 67231] [client 20.151.109.219:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/53.php"] [unique_id "aoSAefcmepr5_nHgLbNFtQAAAi4"] [Tue Aug 18 12:55:37.955971 2026] [security2:error] [pid 67073:tid 67270] [client 52.173.121.69:16485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAefcmepr5_nHgLbNFtgAAAlU"] [Tue Aug 18 12:55:37.956448 2026] [security2:error] [pid 67073:tid 67297] [client 172.182.200.96:13938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAefcmepr5_nHgLbNFtwAAAnA"] [Tue Aug 18 12:55:37.962036 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.61.152:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/xyn.php"] [unique_id "aoSAefcmepr5_nHgLbNFugAAAic"] [Tue Aug 18 12:55:37.962771 2026] [security2:error] [pid 67073:tid 67180] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.backup"] [unique_id "aoSAefcmepr5_nHgLbNFuQACI2g"] [Tue Aug 18 12:55:37.977209 2026] [security2:error] [pid 67073:tid 67315] [client 20.116.17.175:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/domvf.php"] [unique_id "aoSAefcmepr5_nHgLbNFuwAAAoI"] [Tue Aug 18 12:55:37.981539 2026] [security2:error] [pid 67073:tid 67112] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.bak"] [unique_id "aoSAefcmepr5_nHgLbNFvAACfyQ"] [Tue Aug 18 12:55:38.001647 2026] [security2:error] [pid 67073:tid 67323] [client 20.42.19.40:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.alf.php"] [unique_id "aoSAevcmepr5_nHgLbNFvwAAAoo"] [Tue Aug 18 12:55:38.008799 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.100.201:21483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/php5.php"] [unique_id "aoSAetO5rbWdOArH04KFSgAAATg"] [Tue Aug 18 12:55:38.076710 2026] [security2:error] [pid 67073:tid 67280] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/media.php"] [unique_id "aoSAevcmepr5_nHgLbNFwAAAAl8"] [Tue Aug 18 12:55:38.084321 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:9931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/get.php"] [unique_id "aoSAevcmepr5_nHgLbNFwgAAAhw"] [Tue Aug 18 12:55:38.122545 2026] [security2:error] [pid 67073:tid 67095] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ph.php"] [unique_id "aoSAevcmepr5_nHgLbNFxgACjxM"] [Tue Aug 18 12:55:38.123130 2026] [security2:error] [pid 67073:tid 67129] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.old"] [unique_id "aoSAevcmepr5_nHgLbNFxQACajU"] [Tue Aug 18 12:55:38.132448 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:38.132942 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:38.156419 2026] [security2:error] [pid 67073:tid 67293] [client 20.48.236.86:16220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dkSUq.php"] [unique_id "aoSAevcmepr5_nHgLbNFyAAAAmw"] [Tue Aug 18 12:55:38.189070 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:46179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAevcmepr5_nHgLbNFygAAAmE"] [Tue Aug 18 12:55:38.228416 2026] [security2:error] [pid 67073:tid 67261] [client 20.29.77.16:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/payout.php"] [unique_id "aoSAevcmepr5_nHgLbNFzAAAAkw"] [Tue Aug 18 12:55:38.241795 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lq.php"] [unique_id "aoSAevcmepr5_nHgLbNFzQAAAj8"] [Tue Aug 18 12:55:38.255345 2026] [security2:error] [pid 67073:tid 67290] [client 20.205.121.237:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAevcmepr5_nHgLbNFzgAAAmk"] [Tue Aug 18 12:55:38.256835 2026] [security2:error] [pid 67073:tid 67255] [client 20.42.19.40:9707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.trash7206/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF0AAAAkY"] [Tue Aug 18 12:55:38.279618 2026] [security2:error] [pid 67073:tid 67205] [client 213.35.127.232:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF0gAAAhQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:38.283450 2026] [security2:error] [pid 66623:tid 66849] [client 20.104.100.201:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/acp.php"] [unique_id "aoSAetO5rbWdOArH04KFSwAAAV0"] [Tue Aug 18 12:55:38.305595 2026] [security2:error] [pid 67073:tid 67218] [client 20.251.48.93:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/dex.php"] [unique_id "aoSAevcmepr5_nHgLbNF1gAAAiE"] [Tue Aug 18 12:55:38.349893 2026] [security2:error] [pid 66623:tid 66826] [client 20.226.6.191:7121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/edit.php"] [unique_id "aoSAetO5rbWdOArH04KFTAAAAUY"] [Tue Aug 18 12:55:38.360050 2026] [security2:error] [pid 67073:tid 67245] [client 74.248.18.37:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAevcmepr5_nHgLbNF2AAAAjw"] [Tue Aug 18 12:55:38.372200 2026] [security2:error] [pid 67073:tid 67152] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/s.php"] [unique_id "aoSAevcmepr5_nHgLbNF2QACZEw"] [Tue Aug 18 12:55:38.373868 2026] [security2:error] [pid 67073:tid 67268] [client 52.139.47.57:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/rk2.php"] [unique_id "aoSAevcmepr5_nHgLbNF2gAAAlM"] [Tue Aug 18 12:55:38.379437 2026] [security2:error] [pid 67073:tid 67225] [client 52.238.210.254:10173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/abcd.php"] [unique_id "aoSAevcmepr5_nHgLbNF2wAAAig"] [Tue Aug 18 12:55:38.386376 2026] [security2:error] [pid 67073:tid 67306] [client 20.215.241.237:32475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/xx.php"] [unique_id "aoSAevcmepr5_nHgLbNF3AAAAnk"] [Tue Aug 18 12:55:38.405968 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws59.php"] [unique_id "aoSAevcmepr5_nHgLbNF3gAAAoA"] [Tue Aug 18 12:55:38.416576 2026] [security2:error] [pid 67073:tid 67308] [client 20.163.43.14:4330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF3wAAAns"] [Tue Aug 18 12:55:38.427558 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:38.427826 2026] [authz_core:error] [pid 67073:tid 67109] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:38.431497 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/aa.php"] [unique_id "aoSAevcmepr5_nHgLbNF4QAAAkk"] [Tue Aug 18 12:55:38.434761 2026] [security2:error] [pid 67073:tid 67206] [client 68.221.73.131:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAevcmepr5_nHgLbNF4gAAAhU"] [Tue Aug 18 12:55:38.446888 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.56.190:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ph.php"] [unique_id "aoSAevcmepr5_nHgLbNF5QAAAjQ"] [Tue Aug 18 12:55:38.460803 2026] [security2:error] [pid 67073:tid 67242] [client 172.182.200.96:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF6AAAAjk"] [Tue Aug 18 12:55:38.482296 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/lmfi2.php"] [unique_id "aoSAevcmepr5_nHgLbNF6QAAAoE"] [Tue Aug 18 12:55:38.489710 2026] [security2:error] [pid 67073:tid 67195] [remote 162.241.153.188:36300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSAevcmepr5_nHgLbNF6gACkHc"] [Tue Aug 18 12:55:38.500365 2026] [security2:error] [pid 67073:tid 67241] [client 20.42.19.40:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSAevcmepr5_nHgLbNF6wAAAjg"] [Tue Aug 18 12:55:38.502457 2026] [security2:error] [pid 67073:tid 67305] [client 20.91.215.254:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSAevcmepr5_nHgLbNF7AAAAng"] [Tue Aug 18 12:55:38.503887 2026] [security2:error] [pid 66623:tid 66799] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/option.php"] [unique_id "aoSAetO5rbWdOArH04KFTQAAASs"] [Tue Aug 18 12:55:38.505536 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rpk.php"] [unique_id "aoSAevcmepr5_nHgLbNF7QAAAjA"] [Tue Aug 18 12:55:38.518662 2026] [security2:error] [pid 66623:tid 66811] [client 20.100.169.31:52421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAetO5rbWdOArH04KFTgAAATc"] [Tue Aug 18 12:55:38.533409 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:42264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAetO5rbWdOArH04KFTwAAAXg"] [Tue Aug 18 12:55:38.555835 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.100.201:21492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/yas.php"] [unique_id "aoSAevcmepr5_nHgLbNF8QAAAiw"] [Tue Aug 18 12:55:38.575051 2026] [security2:error] [pid 67073:tid 67227] [client 20.116.17.175:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/red.php"] [unique_id "aoSAevcmepr5_nHgLbNF8wAAAio"] [Tue Aug 18 12:55:38.593507 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:53234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/you.php"] [unique_id "aoSAevcmepr5_nHgLbNF9gAAAl4"] [Tue Aug 18 12:55:38.617459 2026] [security2:error] [pid 67073:tid 67211] [client 20.91.215.254:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/ku.php"] [unique_id "aoSAevcmepr5_nHgLbNF9wAAAho"] [Tue Aug 18 12:55:38.634614 2026] [security2:error] [pid 67073:tid 67136] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/api/.env"] [unique_id "aoSAevcmepr5_nHgLbNF-QACizw"] [Tue Aug 18 12:55:38.635668 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uo.php"] [unique_id "aoSAevcmepr5_nHgLbNF-gACVSw"] [Tue Aug 18 12:55:38.644094 2026] [security2:error] [pid 67073:tid 67159] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/config/.env"] [unique_id "aoSAevcmepr5_nHgLbNF-wACcFM"] [Tue Aug 18 12:55:38.644923 2026] [security2:error] [pid 67073:tid 67165] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/backend/.env"] [unique_id "aoSAevcmepr5_nHgLbNF_AACcFk"] [Tue Aug 18 12:55:38.651498 2026] [security2:error] [pid 67073:tid 67220] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/admin.php"] [unique_id "aoSAevcmepr5_nHgLbNF_gAAAiM"] [Tue Aug 18 12:55:38.671557 2026] [security2:error] [pid 67073:tid 67219] [client 4.223.164.152:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/222.php"] [unique_id "aoSAevcmepr5_nHgLbNF_wAAAiI"] [Tue Aug 18 12:55:38.690925 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.98.162:29530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/clque.php"] [unique_id "aoSAevcmepr5_nHgLbNGAQAAAlg"] [Tue Aug 18 12:55:38.694169 2026] [security2:error] [pid 67073:tid 67301] [client 20.100.169.31:38121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/php.php"] [unique_id "aoSAevcmepr5_nHgLbNGAwAAAnQ"] [Tue Aug 18 12:55:38.710587 2026] [security2:error] [pid 67073:tid 67317] [client 20.48.236.86:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/qwas.php"] [unique_id "aoSAevcmepr5_nHgLbNGBAAAAoQ"] [Tue Aug 18 12:55:38.733370 2026] [security2:error] [pid 66623:tid 66782] [client 20.226.6.191:32093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/222.php"] [unique_id "aoSAetO5rbWdOArH04KFUAAAARo"] [Tue Aug 18 12:55:38.742067 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/as.php"] [unique_id "aoSAevcmepr5_nHgLbNGCAAAAi0"] [Tue Aug 18 12:55:38.747897 2026] [security2:error] [pid 67073:tid 67213] [client 20.171.51.14:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/r.php"] [unique_id "aoSAevcmepr5_nHgLbNGCQAAAhw"] [Tue Aug 18 12:55:38.774211 2026] [security2:error] [pid 67073:tid 67299] [client 68.155.154.236:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAevcmepr5_nHgLbNGDAAAAnI"] [Tue Aug 18 12:55:38.778975 2026] [security2:error] [pid 67073:tid 67217] [client 20.163.43.14:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/0x.php"] [unique_id "aoSAevcmepr5_nHgLbNGDQAAAiA"] [Tue Aug 18 12:55:38.780682 2026] [security2:error] [pid 67073:tid 67254] [client 20.100.169.31:48066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wk/index.php"] [unique_id "aoSAevcmepr5_nHgLbNGDgAAAkU"] [Tue Aug 18 12:55:38.793413 2026] [security2:error] [pid 67073:tid 67328] [client 20.42.19.40:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAevcmepr5_nHgLbNGDwAAAo8"] [Tue Aug 18 12:55:38.799152 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.56.190:47115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/s.php"] [unique_id "aoSAetO5rbWdOArH04KFUQAAAWw"] [Tue Aug 18 12:55:38.806553 2026] [security2:error] [pid 66623:tid 66843] [client 20.42.19.40:9654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSAetO5rbWdOArH04KFUgAAAVc"] [Tue Aug 18 12:55:38.814833 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:13845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAevcmepr5_nHgLbNGEQAAAlc"] [Tue Aug 18 12:55:38.831052 2026] [security2:error] [pid 67073:tid 67261] [client 20.104.100.201:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ah25.php"] [unique_id "aoSAevcmepr5_nHgLbNGEgAAAkw"] [Tue Aug 18 12:55:38.851100 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kx.php"] [unique_id "aoSAevcmepr5_nHgLbNGEwACFCo"] [Tue Aug 18 12:55:38.861187 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSAevcmepr5_nHgLbNGFAAAAmA"] [Tue Aug 18 12:55:38.924428 2026] [security2:error] [pid 67073:tid 67234] [client 74.248.136.165:30935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAevcmepr5_nHgLbNGGQAAAjE"] [Tue Aug 18 12:55:38.934423 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:33020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAevcmepr5_nHgLbNGGgAAAlM"] [Tue Aug 18 12:55:38.939281 2026] [security2:error] [pid 67073:tid 67260] [client 68.221.73.131:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/sf.php"] [unique_id "aoSAevcmepr5_nHgLbNGGwAAAks"] [Tue Aug 18 12:55:38.974418 2026] [security2:error] [pid 67073:tid 67237] [client 20.151.109.219:53231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ez.php"] [unique_id "aoSAevcmepr5_nHgLbNGHgAAAjQ"] [Tue Aug 18 12:55:39.008153 2026] [security2:error] [pid 67073:tid 67291] [client 52.139.47.57:43561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAe_cmepr5_nHgLbNGIgAAAmo"] [Tue Aug 18 12:55:39.019847 2026] [security2:error] [pid 67073:tid 67314] [client 52.238.210.254:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGJAAAAoE"] [Tue Aug 18 12:55:39.044091 2026] [security2:error] [pid 67073:tid 67287] [client 20.42.19.40:9632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGJgAAAmY"] [Tue Aug 18 12:55:39.082542 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGKAAAApM"] [Tue Aug 18 12:55:39.099061 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAe9O5rbWdOArH04KFVQAAAR0"] [Tue Aug 18 12:55:39.103143 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.100.201:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/ano.php"] [unique_id "aoSAe_cmepr5_nHgLbNGKgAAAoc"] [Tue Aug 18 12:55:39.118454 2026] [security2:error] [pid 67073:tid 67227] [client 4.223.164.152:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLAAAAio"] [Tue Aug 18 12:55:39.127832 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.6.191:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAe9O5rbWdOArH04KFVwAAARM"] [Tue Aug 18 12:55:39.133646 2026] [security2:error] [pid 67073:tid 67265] [client 74.248.130.103:14428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/makeasmtp.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLQAAAlA"] [Tue Aug 18 12:55:39.136460 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/OK.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLgAAAjo"] [Tue Aug 18 12:55:39.141006 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.169.31:31471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAe_cmepr5_nHgLbNGLwAAAmQ"] [Tue Aug 18 12:55:39.149008 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/zxz.php"] [unique_id "aoSAe_cmepr5_nHgLbNGMAAAAl4"] [Tue Aug 18 12:55:39.159351 2026] [security2:error] [pid 67073:tid 67214] [client 20.42.19.40:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAe_cmepr5_nHgLbNGMgAAAh0"] [Tue Aug 18 12:55:39.185667 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gy.php"] [unique_id "aoSAe_cmepr5_nHgLbNGNQAAAlY"] [Tue Aug 18 12:55:39.201290 2026] [security2:error] [pid 67073:tid 67151] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/va.php"] [unique_id "aoSAe_cmepr5_nHgLbNGOAACGks"] [Tue Aug 18 12:55:39.216632 2026] [security2:error] [pid 67073:tid 67266] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/p.php"] [unique_id "aoSAe_cmepr5_nHgLbNGOwAAAlE"] [Tue Aug 18 12:55:39.225881 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/mac.php"] [unique_id "aoSAe_cmepr5_nHgLbNGPQAAAos"] [Tue Aug 18 12:55:39.251113 2026] [security2:error] [pid 66623:tid 66828] [client 20.65.69.59:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/info2.php"] [unique_id "aoSAe9O5rbWdOArH04KFWQAAAUg"] [Tue Aug 18 12:55:39.273865 2026] [security2:error] [pid 67073:tid 67323] [client 172.182.200.96:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavomoema.com.br"] [uri "/images/security.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQAAAAoo"] [Tue Aug 18 12:55:39.274224 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:21641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/asus.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQQAAAkA"] [Tue Aug 18 12:55:39.280572 2026] [security2:error] [pid 67073:tid 67273] [client 20.42.19.40:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGQgAAAlg"] [Tue Aug 18 12:55:39.291891 2026] [security2:error] [pid 66623:tid 66889] [client 20.42.19.40:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/about.php"] [unique_id "aoSAe9O5rbWdOArH04KFWgAAAYU"] [Tue Aug 18 12:55:39.295011 2026] [security2:error] [pid 67073:tid 67207] [client 20.205.121.237:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGRAAAAhY"] [Tue Aug 18 12:55:39.301894 2026] [security2:error] [pid 67073:tid 67264] [client 213.35.127.232:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAe_cmepr5_nHgLbNGRQAAAk8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:39.331598 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:39.331895 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:39.342687 2026] [security2:error] [pid 66623:tid 66816] [client 74.248.136.165:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/mga.php"] [unique_id "aoSAe9O5rbWdOArH04KFWwAAATw"] [Tue Aug 18 12:55:39.346666 2026] [security2:error] [pid 66623:tid 66827] [client 20.116.17.175:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSAe9O5rbWdOArH04KFXAAAAUc"] [Tue Aug 18 12:55:39.351015 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:42237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/function/function.php"] [unique_id "aoSAe9O5rbWdOArH04KFXQAAAVY"] [Tue Aug 18 12:55:39.379589 2026] [security2:error] [pid 67073:tid 67312] [client 20.104.100.201:21477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/nwflm.php"] [unique_id "aoSAe_cmepr5_nHgLbNGTAAAAn8"] [Tue Aug 18 12:55:39.400946 2026] [security2:error] [pid 67073:tid 67217] [client 20.171.51.14:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/17.php"] [unique_id "aoSAe_cmepr5_nHgLbNGTwAAAiA"] [Tue Aug 18 12:55:39.400983 2026] [autoindex:error] [pid 66623:tid 66888] [client 20.104.85.180:7233] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:39.411289 2026] [security2:error] [pid 67073:tid 67318] [client 68.221.73.131:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/k.php"] [unique_id "aoSAe_cmepr5_nHgLbNGUAAAAoU"] [Tue Aug 18 12:55:39.420558 2026] [security2:error] [pid 67073:tid 67090] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fo.php"] [unique_id "aoSAe_cmepr5_nHgLbNGUQACjw4"] [Tue Aug 18 12:55:39.449249 2026] [security2:error] [pid 67073:tid 67329] [client 20.91.215.254:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGVAAAApA"] [Tue Aug 18 12:55:39.465929 2026] [security2:error] [pid 67073:tid 67274] [client 52.238.210.254:8923] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.savvy.ind.br"] [uri "/admin/controller/extension/extension/"] [unique_id "aoSAe_cmepr5_nHgLbNGWAAAAlk"] [Tue Aug 18 12:55:39.475315 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/chosen.php"] [unique_id "aoSAe9O5rbWdOArH04KFYAAAAXM"] [Tue Aug 18 12:55:39.501984 2026] [security2:error] [pid 67073:tid 67290] [client 20.163.43.14:4360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/www.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXAAAAmk"] [Tue Aug 18 12:55:39.505957 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXQAAAh4"] [Tue Aug 18 12:55:39.533379 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.6.191:6589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-good.php"] [unique_id "aoSAe_cmepr5_nHgLbNGXwAAAjE"] [Tue Aug 18 12:55:39.541819 2026] [security2:error] [pid 67073:tid 67226] [client 20.42.19.40:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/xmr.php"] [unique_id "aoSAe_cmepr5_nHgLbNGYQAAAik"] [Tue Aug 18 12:55:39.569012 2026] [security2:error] [pid 67073:tid 67225] [client 4.223.164.152:28514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZAAAAig"] [Tue Aug 18 12:55:39.583499 2026] [security2:error] [pid 67073:tid 67260] [client 20.91.215.254:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/chosen.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZgAAAks"] [Tue Aug 18 12:55:39.602240 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/22.php"] [unique_id "aoSAe_cmepr5_nHgLbNGZwAAAns"] [Tue Aug 18 12:55:39.629612 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:39.629876 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:39.656222 2026] [security2:error] [pid 67073:tid 67123] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/loading.php"] [unique_id "aoSAe_cmepr5_nHgLbNGfgACMy8"] [Tue Aug 18 12:55:39.656405 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.100.201:21465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/wp-load.php"] [unique_id "aoSAe9O5rbWdOArH04KFYQAAAVw"] [Tue Aug 18 12:55:39.657197 2026] [security2:error] [pid 66623:tid 66806] [client 20.48.236.86:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/13.php"] [unique_id "aoSAe9O5rbWdOArH04KFYgAAATI"] [Tue Aug 18 12:55:39.676280 2026] [security2:error] [pid 66623:tid 66890] [client 20.104.85.180:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAe9O5rbWdOArH04KFYwAAAYY"] [Tue Aug 18 12:55:39.691873 2026] [security2:error] [pid 67073:tid 67227] [client 135.225.75.187:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGfwAAAio"] [Tue Aug 18 12:55:39.723208 2026] [security2:error] [pid 67073:tid 67243] [client 20.215.241.237:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/av.php"] [unique_id "aoSAe_cmepr5_nHgLbNGhAAAAjo"] [Tue Aug 18 12:55:39.733529 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/admin.php"] [unique_id "aoSAe_cmepr5_nHgLbNGhgAAAo4"] [Tue Aug 18 12:55:39.750069 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:23761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uo.php"] [unique_id "aoSAe_cmepr5_nHgLbNGigAAAjw"] [Tue Aug 18 12:55:39.761874 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.136.165:17047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/fs.php"] [unique_id "aoSAe_cmepr5_nHgLbNGiwAAAlY"] [Tue Aug 18 12:55:39.768897 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.130.103:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjAAAApE"] [Tue Aug 18 12:55:39.771770 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjQAAAlM"] [Tue Aug 18 12:55:39.800602 2026] [security2:error] [pid 67073:tid 67266] [client 20.42.19.40:9664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGjgAAAlE"] [Tue Aug 18 12:55:39.826583 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkQAAAi8"] [Tue Aug 18 12:55:39.826670 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/1.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkQAAAi8"] [Tue Aug 18 12:55:39.834617 2026] [security2:error] [pid 67073:tid 67309] [client 52.139.47.57:44649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/tool.php"] [unique_id "aoSAe_cmepr5_nHgLbNGkwAAAnw"] [Tue Aug 18 12:55:39.836372 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:61012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAe9O5rbWdOArH04KFZAAAARk"] [Tue Aug 18 12:55:39.846601 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:4324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlQAAAiM"] [Tue Aug 18 12:55:39.854329 2026] [security2:error] [pid 67073:tid 67201] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ke.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlgACin0"] [Tue Aug 18 12:55:39.878979 2026] [security2:error] [pid 66623:tid 66792] [client 20.171.51.14:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/tt.php"] [unique_id "aoSAe9O5rbWdOArH04KFZQAAASQ"] [Tue Aug 18 12:55:39.882314 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:4372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wicked.php"] [unique_id "aoSAe_cmepr5_nHgLbNGlwAAAm4"] [Tue Aug 18 12:55:39.893948 2026] [security2:error] [pid 67073:tid 67191] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.github/.env"] [unique_id "aoSAe_cmepr5_nHgLbNGoAACXHM"] [Tue Aug 18 12:55:39.915929 2026] [security2:error] [pid 67073:tid 67292] [client 158.23.17.4:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAe_cmepr5_nHgLbNGpwAAAms"] [Tue Aug 18 12:55:39.928807 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:21384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/jj.php"] [unique_id "aoSAe_cmepr5_nHgLbNGqgAAAoQ"] [Tue Aug 18 12:55:39.934012 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:39.934408 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:39.947412 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zs.php"] [unique_id "aoSAe_cmepr5_nHgLbNGqwAAAi0"] [Tue Aug 18 12:55:39.955023 2026] [security2:error] [pid 67073:tid 67272] [client 20.100.169.31:42639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/about.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrAAAAlc"] [Tue Aug 18 12:55:39.956475 2026] [security2:error] [pid 67073:tid 67319] [client 20.104.85.180:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/o.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrQAAAoY"] [Tue Aug 18 12:55:39.957881 2026] [security2:error] [pid 67073:tid 67213] [client 52.238.210.254:10120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/adminfuns.php"] [unique_id "aoSAe_cmepr5_nHgLbNGrgAAAhw"] [Tue Aug 18 12:55:39.978817 2026] [security2:error] [pid 67073:tid 67256] [client 68.221.73.131:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/82.php"] [unique_id "aoSAe_cmepr5_nHgLbNGtQAAAkc"] [Tue Aug 18 12:55:40.029252 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.18.37:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSAfPcmepr5_nHgLbNGvwAAAnc"] [Tue Aug 18 12:55:40.041100 2026] [security2:error] [pid 67073:tid 67255] [client 20.42.19.40:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNGwAAAAkY"] [Tue Aug 18 12:55:40.041504 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:54269] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/l10n/"] [unique_id "aoSAfPcmepr5_nHgLbNGwQAAAmA"] [Tue Aug 18 12:55:40.070050 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nh.php"] [unique_id "aoSAfPcmepr5_nHgLbNGwgACQSw"] [Tue Aug 18 12:55:40.091162 2026] [security2:error] [pid 67073:tid 67222] [client 20.48.236.86:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file.php"] [unique_id "aoSAfPcmepr5_nHgLbNGxQAAAiU"] [Tue Aug 18 12:55:40.112942 2026] [security2:error] [pid 67073:tid 67260] [client 20.65.69.59:3720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/test_info.php"] [unique_id "aoSAfPcmepr5_nHgLbNGxwAAAks"] [Tue Aug 18 12:55:40.178216 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.136.165:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAfPcmepr5_nHgLbNGygAAAng"] [Tue Aug 18 12:55:40.180758 2026] [security2:error] [pid 67073:tid 67269] [client 5.253.205.188:38596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdatadata_en_us.sql"] [unique_id "aoSAfPcmepr5_nHgLbNGzAAAAlQ"], referer: https://medihub.com.br/installdatadata_en_us.sql [Tue Aug 18 12:55:40.201359 2026] [security2:error] [pid 67073:tid 67262] [client 20.104.100.201:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzgAAAk0"] [Tue Aug 18 12:55:40.201375 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzQAAAkM"] [Tue Aug 18 12:55:40.203187 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.154.236:16210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/oivcl.php"] [unique_id "aoSAfPcmepr5_nHgLbNGzwAAAis"] [Tue Aug 18 12:55:40.235275 2026] [security2:error] [pid 67073:tid 67296] [client 20.251.48.93:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/puc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG0AAAAm8"] [Tue Aug 18 12:55:40.238785 2026] [security2:error] [pid 67073:tid 67290] [client 20.91.215.254:24647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/asd.php"] [unique_id "aoSAfPcmepr5_nHgLbNG0QAAAmk"] [Tue Aug 18 12:55:40.239962 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:8034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/bb.php"] [unique_id "aoSAfNO5rbWdOArH04KFZwAAAUE"] [Tue Aug 18 12:55:40.258551 2026] [security2:error] [pid 67073:tid 67326] [client 20.151.109.219:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iz.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1AAAAo0"] [Tue Aug 18 12:55:40.264576 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1QAAAjw"] [Tue Aug 18 12:55:40.289530 2026] [security2:error] [pid 67073:tid 67077] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/oo.php"] [unique_id "aoSAfPcmepr5_nHgLbNG1wACXgE"] [Tue Aug 18 12:55:40.301371 2026] [security2:error] [pid 66623:tid 66776] [client 20.42.19.40:9693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAfNO5rbWdOArH04KFaAAAARQ"] [Tue Aug 18 12:55:40.315295 2026] [security2:error] [pid 67073:tid 67318] [client 213.35.127.232:63051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAfPcmepr5_nHgLbNG2wAAAoU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:40.354230 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/oauth.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3AAAAlM"] [Tue Aug 18 12:55:40.355896 2026] [security2:error] [pid 67073:tid 67221] [client 20.250.13.23:48414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3QAAAiQ"] [Tue Aug 18 12:55:40.392445 2026] [security2:error] [pid 67073:tid 67232] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/coffee.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4AAAAi8"] [Tue Aug 18 12:55:40.392543 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.169.31:31426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNG3wAAAjA"] [Tue Aug 18 12:55:40.406870 2026] [security2:error] [pid 67073:tid 67257] [client 45.92.229.87:24087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4gAAAkg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:55:40.410565 2026] [security2:error] [pid 67073:tid 67224] [client 20.48.236.86:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/rezor.php"] [unique_id "aoSAfPcmepr5_nHgLbNG4wAAAic"] [Tue Aug 18 12:55:40.421911 2026] [security2:error] [pid 66623:tid 66839] [client 196.12.128.158:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAfNO5rbWdOArH04KFagAAAVM"] [Tue Aug 18 12:55:40.422022 2026] [security2:error] [pid 66623:tid 66839] [client 196.12.128.158:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAfNO5rbWdOArH04KFagAAAVM"] [Tue Aug 18 12:55:40.427865 2026] [security2:error] [pid 67073:tid 67295] [client 20.116.17.175:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSAfPcmepr5_nHgLbNG5gAAAm4"] [Tue Aug 18 12:55:40.437994 2026] [security2:error] [pid 66623:tid 66831] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/past.php"] [unique_id "aoSAfNO5rbWdOArH04KFawAAAUs"] [Tue Aug 18 12:55:40.445783 2026] [security2:error] [pid 67073:tid 67301] [client 135.225.75.187:25703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6AAAAnQ"] [Tue Aug 18 12:55:40.475113 2026] [security2:error] [pid 67073:tid 67317] [client 20.104.100.201:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dealermotors.com.br"] [uri "/we.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6gAAAoQ"] [Tue Aug 18 12:55:40.490524 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.6.191:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/tes.php"] [unique_id "aoSAfPcmepr5_nHgLbNG6wAAAl8"] [Tue Aug 18 12:55:40.499978 2026] [security2:error] [pid 67073:tid 67230] [client 52.238.210.254:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/akc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7AAAAi0"] [Tue Aug 18 12:55:40.500947 2026] [security2:error] [pid 66623:tid 66789] [client 4.223.164.152:17643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp.php"] [unique_id "aoSAfNO5rbWdOArH04KFbQAAASE"] [Tue Aug 18 12:55:40.518309 2026] [security2:error] [pid 67073:tid 67219] [client 103.120.71.157:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7gAAAiI"] [Tue Aug 18 12:55:40.518416 2026] [security2:error] [pid 67073:tid 67219] [client 103.120.71.157:49170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfPcmepr5_nHgLbNG7gAAAiI"] [Tue Aug 18 12:55:40.529089 2026] [authz_core:error] [pid 67073:tid 67139] [remote 34.62.54.143:52216] AH01630: client denied by server configuration: /home2/natbrw01/uhequeimado.com.br/.htpasswd [Tue Aug 18 12:55:40.535356 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:40.535604 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:40.535769 2026] [security2:error] [pid 67073:tid 67303] [client 20.104.85.180:7992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAfPcmepr5_nHgLbNG8QAAAnY"] [Tue Aug 18 12:55:40.538908 2026] [security2:error] [pid 67073:tid 67182] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ja.php"] [unique_id "aoSAfPcmepr5_nHgLbNG8gACIGo"] [Tue Aug 18 12:55:40.542714 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.6.191:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/info.php"] [unique_id "aoSAfPcmepr5_nHgLbNG9QAAAko"] [Tue Aug 18 12:55:40.545847 2026] [security2:error] [pid 67073:tid 67328] [client 20.42.19.40:9635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/as.php"] [unique_id "aoSAfPcmepr5_nHgLbNG9gAAAo8"] [Tue Aug 18 12:55:40.596652 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.136.165:43699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/sadd.php"] [unique_id "aoSAfNO5rbWdOArH04KFbwAAAQs"] [Tue Aug 18 12:55:40.616817 2026] [security2:error] [pid 66623:tid 66825] [client 20.163.43.14:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAfNO5rbWdOArH04KFcAAAAUU"] [Tue Aug 18 12:55:40.640080 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:32986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/se.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_AAAAh4"] [Tue Aug 18 12:55:40.689403 2026] [security2:error] [pid 66623:tid 66885] [client 20.205.121.237:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSAfNO5rbWdOArH04KFcQAAAYE"] [Tue Aug 18 12:55:40.693616 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/edit.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_gAAAig"] [Tue Aug 18 12:55:40.714575 2026] [security2:error] [pid 67073:tid 67313] [client 20.48.236.86:16369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/3p8jj8r.php"] [unique_id "aoSAfPcmepr5_nHgLbNG_wAAAoA"] [Tue Aug 18 12:55:40.723305 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:19963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAAAAAiM"] [Tue Aug 18 12:55:40.733566 2026] [security2:error] [pid 67073:tid 67260] [client 68.221.73.131:61211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/dex.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAgAAAks"] [Tue Aug 18 12:55:40.741922 2026] [security2:error] [pid 66623:tid 66893] [client 20.163.43.14:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAfNO5rbWdOArH04KFcgAAAYk"] [Tue Aug 18 12:55:40.742958 2026] [security2:error] [pid 67073:tid 67292] [client 20.91.215.254:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/f7.php"] [unique_id "aoSAfPcmepr5_nHgLbNHAwAAAms"] [Tue Aug 18 12:55:40.757362 2026] [security2:error] [pid 66623:tid 66641] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfNO5rbWdOArH04KFcwABJwQ"] [Tue Aug 18 12:55:40.801920 2026] [security2:error] [pid 67073:tid 67258] [client 20.42.19.40:1362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/bolt.php"] [unique_id "aoSAfPcmepr5_nHgLbNHBQAAAkk"] [Tue Aug 18 12:55:40.837102 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:40.837349 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:40.844446 2026] [security2:error] [pid 67073:tid 67242] [client 20.251.48.93:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/inso.php"] [unique_id "aoSAfPcmepr5_nHgLbNHCgAAAjk"] [Tue Aug 18 12:55:40.846032 2026] [security2:error] [pid 67073:tid 67113] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xx.php"] [unique_id "aoSAfPcmepr5_nHgLbNHCwACaiU"] [Tue Aug 18 12:55:40.850602 2026] [autoindex:error] [pid 67073:tid 67240] [client 20.226.6.191:45840] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:40.858191 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/term.php"] [unique_id "aoSAfNO5rbWdOArH04KFdQAAAWg"] [Tue Aug 18 12:55:40.858684 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDAAAAmM"] [Tue Aug 18 12:55:40.861988 2026] [security2:error] [pid 67073:tid 67252] [client 20.171.51.14:58840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/mq.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDQAAAkM"] [Tue Aug 18 12:55:40.863577 2026] [security2:error] [pid 67073:tid 67262] [client 20.171.51.14:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ev.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDgAAAk0"] [Tue Aug 18 12:55:40.882682 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/akc.php"] [unique_id "aoSAfPcmepr5_nHgLbNHDwAAAhc"] [Tue Aug 18 12:55:40.904976 2026] [security2:error] [pid 67073:tid 67210] [client 52.238.210.254:8296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/buy.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEAAAAhk"] [Tue Aug 18 12:55:40.925397 2026] [security2:error] [pid 67073:tid 67080] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/0x.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEgACbwQ"] [Tue Aug 18 12:55:40.931241 2026] [security2:error] [pid 67073:tid 67290] [client 20.151.109.219:21667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vp.php"] [unique_id "aoSAfPcmepr5_nHgLbNHEwAAAmk"] [Tue Aug 18 12:55:40.939414 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.130.103:14402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/system_log.php"] [unique_id "aoSAfPcmepr5_nHgLbNHFAAAAjo"] [Tue Aug 18 12:55:40.960593 2026] [security2:error] [pid 67073:tid 67326] [client 4.223.164.152:28542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/i.php"] [unique_id "aoSAfPcmepr5_nHgLbNHFQAAAo0"] [Tue Aug 18 12:55:40.986342 2026] [security2:error] [pid 67073:tid 67318] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAfPcmepr5_nHgLbNHGwAAAoU"] [Tue Aug 18 12:55:41.019480 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:30919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ex.php"] [unique_id "aoSAffcmepr5_nHgLbNHHgAAAi4"] [Tue Aug 18 12:55:41.020639 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.169.31:2437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHHwAAAjQ"] [Tue Aug 18 12:55:41.045477 2026] [cgid:error] [pid 67073:tid 67266] [client 20.42.19.40:9697] AH01265: stderr from /home4/plantaodasbateri/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 12:55:41.054779 2026] [security2:error] [pid 66623:tid 66783] [client 37.40.227.74:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfdO5rbWdOArH04KFdwAAARs"] [Tue Aug 18 12:55:41.054877 2026] [security2:error] [pid 66623:tid 66783] [client 37.40.227.74:56892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfdO5rbWdOArH04KFdwAAARs"] [Tue Aug 18 12:55:41.067864 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/an.php"] [unique_id "aoSAffcmepr5_nHgLbNHJAAAAnw"] [Tue Aug 18 12:55:41.082583 2026] [security2:error] [pid 67073:tid 67249] [client 20.48.236.86:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dapa.php"] [unique_id "aoSAffcmepr5_nHgLbNHJQAAAkA"] [Tue Aug 18 12:55:41.084110 2026] [security2:error] [pid 67073:tid 67316] [client 4.232.151.198:39145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/about.php"] [unique_id "aoSAffcmepr5_nHgLbNHJgAAAoM"] [Tue Aug 18 12:55:41.085579 2026] [security2:error] [pid 67073:tid 67295] [client 20.65.98.162:28543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/nano.php"] [unique_id "aoSAffcmepr5_nHgLbNHJwAAAm4"] [Tue Aug 18 12:55:41.086782 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/conn-test.php"] [unique_id "aoSAffcmepr5_nHgLbNHKAACFno"] [Tue Aug 18 12:55:41.091795 2026] [security2:error] [pid 66623:tid 66693] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/222.php"] [unique_id "aoSAfdO5rbWdOArH04KFeAABNTg"] [Tue Aug 18 12:55:41.129805 2026] [security2:error] [pid 67073:tid 67301] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAffcmepr5_nHgLbNHKwAAAnQ"] [Tue Aug 18 12:55:41.138801 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:41.139063 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:41.169581 2026] [security2:error] [pid 67073:tid 67235] [client 20.163.43.14:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cah.php"] [unique_id "aoSAffcmepr5_nHgLbNHLQAAAjI"] [Tue Aug 18 12:55:41.207272 2026] [security2:error] [pid 66623:tid 66817] [client 172.202.39.151:65220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAfdO5rbWdOArH04KFegAAAT0"] [Tue Aug 18 12:55:41.209081 2026] [security2:error] [pid 67073:tid 67083] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSAffcmepr5_nHgLbNHLwACNgc"] [Tue Aug 18 12:55:41.223252 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kx.php"] [unique_id "aoSAffcmepr5_nHgLbNHMAAAAoQ"] [Tue Aug 18 12:55:41.223783 2026] [security2:error] [pid 67073:tid 67238] [client 197.184.64.235:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHMQAAAjU"] [Tue Aug 18 12:55:41.223872 2026] [security2:error] [pid 67073:tid 67238] [client 197.184.64.235:41926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHMQAAAjU"] [Tue Aug 18 12:55:41.258008 2026] [security2:error] [pid 67073:tid 67160] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/aa.php"] [unique_id "aoSAffcmepr5_nHgLbNHMgACIlQ"] [Tue Aug 18 12:55:41.268015 2026] [security2:error] [pid 67073:tid 67303] [client 20.151.109.219:21673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ph.php"] [unique_id "aoSAffcmepr5_nHgLbNHMwAAAnY"] [Tue Aug 18 12:55:41.279203 2026] [security2:error] [pid 67073:tid 67289] [client 20.42.19.40:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/class-t.api.php"] [unique_id "aoSAffcmepr5_nHgLbNHNQAAAmg"] [Tue Aug 18 12:55:41.289588 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fg.php"] [unique_id "aoSAffcmepr5_nHgLbNHNwACSnA"] [Tue Aug 18 12:55:41.301944 2026] [security2:error] [pid 67073:tid 67293] [client 132.196.61.152:61015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/inso.php"] [unique_id "aoSAffcmepr5_nHgLbNHOAAAAmw"] [Tue Aug 18 12:55:41.327648 2026] [security2:error] [pid 67073:tid 67268] [client 213.35.127.232:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAffcmepr5_nHgLbNHOQAAAlM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:41.356624 2026] [security2:error] [pid 67073:tid 67329] [client 68.221.73.131:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/puc.php"] [unique_id "aoSAffcmepr5_nHgLbNHOgAAApA"] [Tue Aug 18 12:55:41.377750 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/files/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHPAAAAj8"] [Tue Aug 18 12:55:41.386131 2026] [security2:error] [pid 67073:tid 67255] [client 4.223.164.152:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/abcd.php"] [unique_id "aoSAffcmepr5_nHgLbNHPQAAAkY"] [Tue Aug 18 12:55:41.429313 2026] [security2:error] [pid 66623:tid 66658] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/abcd.php"] [unique_id "aoSAfdO5rbWdOArH04KFfAABLBU"] [Tue Aug 18 12:55:41.438930 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:41.439179 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:41.442988 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.136.165:49663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/tax.php"] [unique_id "aoSAfdO5rbWdOArH04KFfQAAAW4"] [Tue Aug 18 12:55:41.453548 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/w.php"] [unique_id "aoSAffcmepr5_nHgLbNHQQAAAiM"] [Tue Aug 18 12:55:41.468204 2026] [security2:error] [pid 66623:tid 66884] [client 20.171.51.14:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xs.php"] [unique_id "aoSAfdO5rbWdOArH04KFfgAAAYA"] [Tue Aug 18 12:55:41.488776 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:31205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/vx.php"] [unique_id "aoSAffcmepr5_nHgLbNHRQAAAkk"] [Tue Aug 18 12:55:41.505179 2026] [security2:error] [pid 67073:tid 67253] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/php8.php"] [unique_id "aoSAffcmepr5_nHgLbNHRgAAAkQ"] [Tue Aug 18 12:55:41.512391 2026] [security2:error] [pid 67073:tid 67305] [client 20.48.236.86:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/Ipv6.php"] [unique_id "aoSAffcmepr5_nHgLbNHRwAAAng"] [Tue Aug 18 12:55:41.519928 2026] [security2:error] [pid 67073:tid 67269] [client 20.42.19.40:1394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/edit.php"] [unique_id "aoSAffcmepr5_nHgLbNHSAAAAlQ"] [Tue Aug 18 12:55:41.540024 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ve.php"] [unique_id "aoSAffcmepr5_nHgLbNHSwACal4"] [Tue Aug 18 12:55:41.570290 2026] [security2:error] [pid 67073:tid 67261] [client 20.91.215.254:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/maintenance.php"] [unique_id "aoSAffcmepr5_nHgLbNHTgAAAkw"] [Tue Aug 18 12:55:41.574936 2026] [security2:error] [pid 67073:tid 67082] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSAffcmepr5_nHgLbNHUAACTQY"] [Tue Aug 18 12:55:41.575560 2026] [security2:error] [pid 67073:tid 67228] [client 20.163.43.14:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/404.php"] [unique_id "aoSAffcmepr5_nHgLbNHUwAAAis"] [Tue Aug 18 12:55:41.576766 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAffcmepr5_nHgLbNHVAAAAn0"] [Tue Aug 18 12:55:41.592441 2026] [security2:error] [pid 67073:tid 67216] [client 20.151.109.219:65019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/s.php"] [unique_id "aoSAffcmepr5_nHgLbNHVgAAAh8"] [Tue Aug 18 12:55:41.595296 2026] [security2:error] [pid 67073:tid 67108] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/admin.php"] [unique_id "aoSAffcmepr5_nHgLbNHVwACGSA"] [Tue Aug 18 12:55:41.605203 2026] [security2:error] [pid 66623:tid 66812] [client 20.251.48.93:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/aa.php"] [unique_id "aoSAfdO5rbWdOArH04KFgAAAATg"] [Tue Aug 18 12:55:41.646936 2026] [security2:error] [pid 67073:tid 67285] [client 20.116.17.175:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSAffcmepr5_nHgLbNHXAAAAmQ"] [Tue Aug 18 12:55:41.678393 2026] [security2:error] [pid 67073:tid 67245] [client 20.29.77.16:52747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/timeclock.php"] [unique_id "aoSAffcmepr5_nHgLbNHXwAAAjw"] [Tue Aug 18 12:55:41.683030 2026] [security2:error] [pid 67073:tid 67330] [client 52.238.210.254:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/cong.php"] [unique_id "aoSAffcmepr5_nHgLbNHYAAAApE"] [Tue Aug 18 12:55:41.722311 2026] [security2:error] [pid 66623:tid 66803] [client 20.205.121.237:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/colour.php"] [unique_id "aoSAfdO5rbWdOArH04KFggAAAS8"] [Tue Aug 18 12:55:41.734422 2026] [security2:error] [pid 67073:tid 67237] [client 20.104.85.180:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHYwAAAjQ"] [Tue Aug 18 12:55:41.773547 2026] [security2:error] [pid 67073:tid 67232] [client 158.23.17.4:38857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAffcmepr5_nHgLbNHZAAAAi8"] [Tue Aug 18 12:55:41.777917 2026] [security2:error] [pid 67073:tid 67292] [client 20.91.215.254:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/photo.php"] [unique_id "aoSAffcmepr5_nHgLbNHZgAAAms"] [Tue Aug 18 12:55:41.783490 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:9645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ff1.php"] [unique_id "aoSAffcmepr5_nHgLbNHZwAAAlI"] [Tue Aug 18 12:55:41.785928 2026] [security2:error] [pid 67073:tid 67309] [client 20.171.51.14:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/13.php"] [unique_id "aoSAffcmepr5_nHgLbNHaAAAAnw"] [Tue Aug 18 12:55:41.790337 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ia.php"] [unique_id "aoSAffcmepr5_nHgLbNHaQACJ2E"] [Tue Aug 18 12:55:41.800962 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/system_log.php"] [unique_id "aoSAfdO5rbWdOArH04KFhAAAAV0"] [Tue Aug 18 12:55:41.812295 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.6.191:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHawAAAkA"] [Tue Aug 18 12:55:41.844763 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:46157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-manager.php"] [unique_id "aoSAffcmepr5_nHgLbNHbQAAAjs"] [Tue Aug 18 12:55:41.860377 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.136.165:30945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/X7x.php"] [unique_id "aoSAffcmepr5_nHgLbNHbgAAAjI"] [Tue Aug 18 12:55:41.883956 2026] [security2:error] [pid 67073:tid 67280] [client 20.104.85.180:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHcAAAAl8"] [Tue Aug 18 12:55:41.896105 2026] [security2:error] [pid 67073:tid 67302] [client 114.5.214.109:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHcQAAAnU"] [Tue Aug 18 12:55:41.896221 2026] [security2:error] [pid 67073:tid 67302] [client 114.5.214.109:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAffcmepr5_nHgLbNHcQAAAnU"] [Tue Aug 18 12:55:41.949362 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.56.190:3062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/va.php"] [unique_id "aoSAffcmepr5_nHgLbNHdAAAAoY"] [Tue Aug 18 12:55:41.952420 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:12927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uo.php"] [unique_id "aoSAffcmepr5_nHgLbNHdgAAAhw"] [Tue Aug 18 12:55:41.953226 2026] [security2:error] [pid 67073:tid 67279] [client 172.202.39.151:13402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/rip.php"] [unique_id "aoSAffcmepr5_nHgLbNHdwAAAl4"] [Tue Aug 18 12:55:41.961512 2026] [security2:error] [pid 67073:tid 67303] [client 132.196.61.152:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/puc.php"] [unique_id "aoSAffcmepr5_nHgLbNHeAAAAnY"] [Tue Aug 18 12:55:41.962746 2026] [security2:error] [pid 67073:tid 67289] [client 20.48.236.86:16245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/first.php"] [unique_id "aoSAffcmepr5_nHgLbNHegAAAmg"] [Tue Aug 18 12:55:41.981943 2026] [security2:error] [pid 67073:tid 67111] [remote 129.121.74.194:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHfAACZSM"] [Tue Aug 18 12:55:41.996855 2026] [security2:error] [pid 67073:tid 67283] [client 74.248.18.37:28818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAffcmepr5_nHgLbNHfQAAAmI"] [Tue Aug 18 12:55:42.018583 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kn.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgAACkFI"] [Tue Aug 18 12:55:42.026558 2026] [security2:error] [pid 67073:tid 67304] [client 20.42.19.40:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/fff.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgQAAAnc"] [Tue Aug 18 12:55:42.043354 2026] [security2:error] [pid 67073:tid 67263] [client 192.141.172.134:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgwAAAk4"] [Tue Aug 18 12:55:42.043453 2026] [security2:error] [pid 67073:tid 67263] [client 192.141.172.134:58399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHgwAAAk4"] [Tue Aug 18 12:55:42.052334 2026] [security2:error] [pid 67073:tid 67277] [client 68.221.73.131:61228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/inso.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhAAAAlw"] [Tue Aug 18 12:55:42.053958 2026] [security2:error] [pid 67073:tid 67255] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhQAAAkY"] [Tue Aug 18 12:55:42.073281 2026] [security2:error] [pid 67073:tid 67297] [client 20.100.169.31:2440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNHhgAAAnA"] [Tue Aug 18 12:55:42.095566 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-login.php"] [unique_id "aoSAffcmepr5_nHgLbNHcwAAAi0"] [Tue Aug 18 12:55:42.105394 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.104:54644] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:42.105644 2026] [authz_core:error] [pid 67073:tid 67154] [remote 57.141.22.104:54644] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:42.111135 2026] [security2:error] [pid 67073:tid 67205] [client 20.215.241.237:52549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/media.php"] [unique_id "aoSAfvcmepr5_nHgLbNHiQAAAhQ"] [Tue Aug 18 12:55:42.116697 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:18216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNHigAAAho"] [Tue Aug 18 12:55:42.122180 2026] [security2:error] [pid 66623:tid 66819] [client 52.238.210.254:8853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAftO5rbWdOArH04KFhgAAAT8"] [Tue Aug 18 12:55:42.135450 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zugvi.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjAAAAkk"] [Tue Aug 18 12:55:42.139378 2026] [security2:error] [pid 67073:tid 67201] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_rsa"] [unique_id "aoSAfvcmepr5_nHgLbNHjQACRH0"] [Tue Aug 18 12:55:42.163852 2026] [security2:error] [pid 67073:tid 67269] [client 20.104.85.180:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjgAAAlQ"] [Tue Aug 18 12:55:42.174962 2026] [security2:error] [pid 67073:tid 67291] [client 20.42.19.40:3344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/file.php"] [unique_id "aoSAfvcmepr5_nHgLbNHjwAAAmo"] [Tue Aug 18 12:55:42.194997 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.6.191:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/k.php"] [unique_id "aoSAfvcmepr5_nHgLbNHkwAAAmM"] [Tue Aug 18 12:55:42.195165 2026] [security2:error] [pid 67073:tid 67169] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_dsa"] [unique_id "aoSAfvcmepr5_nHgLbNHkgACN10"] [Tue Aug 18 12:55:42.215633 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wm.php"] [unique_id "aoSAfvcmepr5_nHgLbNHlgACH2g"] [Tue Aug 18 12:55:42.220687 2026] [security2:error] [pid 67073:tid 67246] [client 20.91.215.254:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/options-writing.php"] [unique_id "aoSAfvcmepr5_nHgLbNHlwAAAj0"] [Tue Aug 18 12:55:42.228216 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.56.190:2552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fo.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmAAAAoc"] [Tue Aug 18 12:55:42.235528 2026] [security2:error] [pid 67073:tid 67210] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/yj09.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmQAAAhk"] [Tue Aug 18 12:55:42.245243 2026] [security2:error] [pid 67073:tid 67218] [client 213.202.253.4:49293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/gdftps.php"] [unique_id "aoSAfvcmepr5_nHgLbNHmgAAAiE"], referer: www.google.com [Tue Aug 18 12:55:42.250506 2026] [security2:error] [pid 67073:tid 67112] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAfvcmepr5_nHgLbNHnAACjyQ"] [Tue Aug 18 12:55:42.265254 2026] [security2:error] [pid 66623:tid 66891] [client 20.42.19.40:9667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/inputs.php"] [unique_id "aoSAftO5rbWdOArH04KFiAAAAYc"] [Tue Aug 18 12:55:42.266019 2026] [security2:error] [pid 66623:tid 66882] [client 20.151.109.219:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kx.php"] [unique_id "aoSAftO5rbWdOArH04KFiQAAAX4"] [Tue Aug 18 12:55:42.274303 2026] [security2:error] [pid 67073:tid 67273] [client 86.120.159.145:5685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHngAAAlg"] [Tue Aug 18 12:55:42.274425 2026] [security2:error] [pid 67073:tid 67273] [client 86.120.159.145:5685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNHngAAAlg"] [Tue Aug 18 12:55:42.278282 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:44260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ocxla.php"] [unique_id "aoSAfvcmepr5_nHgLbNHoAAAAig"] [Tue Aug 18 12:55:42.337112 2026] [security2:error] [pid 67073:tid 67237] [client 20.171.51.14:33713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/so.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpAAAAjQ"] [Tue Aug 18 12:55:42.346405 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:42.346854 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:42.349942 2026] [security2:error] [pid 67073:tid 67274] [client 213.35.127.232:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpQAAAlk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:42.360762 2026] [security2:error] [pid 67073:tid 67322] [client 20.163.43.14:4382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHpgAAAok"] [Tue Aug 18 12:55:42.364753 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:3673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/xynz1.php"] [unique_id "aoSAfvcmepr5_nHgLbNHqgAAAjg"] [Tue Aug 18 12:55:42.370077 2026] [security2:error] [pid 67073:tid 67314] [client 158.158.34.183:11282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/aksinet.php"] [unique_id "aoSAfvcmepr5_nHgLbNHqwAAAoE"] [Tue Aug 18 12:55:42.385710 2026] [security2:error] [pid 67073:tid 67232] [client 4.223.164.152:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAfvcmepr5_nHgLbNHrAAAAi8"] [Tue Aug 18 12:55:42.422493 2026] [security2:error] [pid 66623:tid 66704] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/akc.php"] [unique_id "aoSAftO5rbWdOArH04KFiwABbEM"] [Tue Aug 18 12:55:42.444260 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/file.php"] [unique_id "aoSAftO5rbWdOArH04KFjQAAAVc"] [Tue Aug 18 12:55:42.462310 2026] [security2:error] [pid 67073:tid 67323] [client 20.163.43.14:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAfvcmepr5_nHgLbNHsAAAAoo"] [Tue Aug 18 12:55:42.501961 2026] [security2:error] [pid 67073:tid 67239] [client 20.42.19.40:1398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfvcmepr5_nHgLbNHsgAAAjY"] [Tue Aug 18 12:55:42.516832 2026] [security2:error] [pid 67073:tid 67152] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/key.pem"] [unique_id "aoSAfvcmepr5_nHgLbNHswACeUw"] [Tue Aug 18 12:55:42.517199 2026] [security2:error] [pid 67073:tid 67275] [client 132.196.61.152:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/19.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtAAAAlo"] [Tue Aug 18 12:55:42.523750 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.6.191:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtQAAAo0"] [Tue Aug 18 12:55:42.546463 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ac.php"] [unique_id "aoSAfvcmepr5_nHgLbNHtwACV0U"] [Tue Aug 18 12:55:42.552651 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.98.162:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file5.php"] [unique_id "aoSAftO5rbWdOArH04KFkQAAASk"] [Tue Aug 18 12:55:42.573945 2026] [security2:error] [pid 67073:tid 67279] [client 68.221.73.131:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNHuAAAAl4"] [Tue Aug 18 12:55:42.589222 2026] [security2:error] [pid 66623:tid 66875] [client 52.238.210.254:8874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/db.php"] [unique_id "aoSAftO5rbWdOArH04KFkgAAAXc"] [Tue Aug 18 12:55:42.590177 2026] [security2:error] [pid 67073:tid 67089] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/buy.php"] [unique_id "aoSAfvcmepr5_nHgLbNHugACcg0"] [Tue Aug 18 12:55:42.596564 2026] [security2:error] [pid 67073:tid 67195] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/privatekey.key"] [unique_id "aoSAfvcmepr5_nHgLbNHuwACInc"] [Tue Aug 18 12:55:42.598684 2026] [security2:error] [pid 66623:tid 66852] [client 135.225.75.187:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ah25.php"] [unique_id "aoSAftO5rbWdOArH04KFkwAAAWA"] [Tue Aug 18 12:55:42.605908 2026] [security2:error] [pid 66623:tid 66775] [client 20.42.19.40:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAftO5rbWdOArH04KFlAAAARM"] [Tue Aug 18 12:55:42.632409 2026] [security2:error] [pid 67073:tid 67268] [client 20.48.236.86:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpupex.php"] [unique_id "aoSAfvcmepr5_nHgLbNHwQAAAlM"] [Tue Aug 18 12:55:42.642223 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:42.642486 2026] [authz_core:error] [pid 67073:tid 67136] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:42.656332 2026] [security2:error] [pid 67073:tid 67229] [client 4.232.151.198:15653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/nw.php"] [unique_id "aoSAfvcmepr5_nHgLbNHxgAAAiw"] [Tue Aug 18 12:55:42.674686 2026] [security2:error] [pid 67073:tid 67307] [client 20.91.215.254:11977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNHyQAAAno"] [Tue Aug 18 12:55:42.704324 2026] [security2:error] [pid 67073:tid 67226] [client 74.248.136.165:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/post.php"] [unique_id "aoSAfvcmepr5_nHgLbNHygAAAik"] [Tue Aug 18 12:55:42.727758 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAfvcmepr5_nHgLbNHzgAAAoA"] [Tue Aug 18 12:55:42.728039 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.85.180:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/epinyins.php"] [unique_id "aoSAfvcmepr5_nHgLbNHzwAAAiM"] [Tue Aug 18 12:55:42.750106 2026] [security2:error] [pid 67073:tid 67234] [client 20.151.109.219:24893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/va.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0AAAAjE"] [Tue Aug 18 12:55:42.752592 2026] [security2:error] [pid 67073:tid 67257] [client 20.205.121.237:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0QAAAkg"] [Tue Aug 18 12:55:42.754086 2026] [security2:error] [pid 67073:tid 67260] [client 20.42.19.40:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/lite.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0gAAAks"] [Tue Aug 18 12:55:42.757419 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.56.190:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/loading.php"] [unique_id "aoSAftO5rbWdOArH04KFlQAAAWQ"] [Tue Aug 18 12:55:42.762787 2026] [security2:error] [pid 67073:tid 67122] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/cong.php"] [unique_id "aoSAfvcmepr5_nHgLbNH0wACfi4"] [Tue Aug 18 12:55:42.818519 2026] [security2:error] [pid 66623:tid 66863] [client 20.100.169.31:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-fclass.php"] [unique_id "aoSAftO5rbWdOArH04KFlwAAAWs"] [Tue Aug 18 12:55:42.822656 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yz.php"] [unique_id "aoSAfvcmepr5_nHgLbNH1wACeCY"] [Tue Aug 18 12:55:42.830025 2026] [security2:error] [pid 67073:tid 67284] [client 4.223.164.152:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2AAAAmM"] [Tue Aug 18 12:55:42.850063 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/scxy.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2QAAAn0"] [Tue Aug 18 12:55:42.868986 2026] [security2:error] [pid 67073:tid 67242] [client 103.184.169.37:41727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2gAAAjk"] [Tue Aug 18 12:55:42.869437 2026] [security2:error] [pid 67073:tid 67242] [client 103.184.169.37:41727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2gAAAjk"] [Tue Aug 18 12:55:42.873445 2026] [security2:error] [pid 67073:tid 67304] [client 20.91.215.254:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAfvcmepr5_nHgLbNH2wAAAnc"] [Tue Aug 18 12:55:42.897232 2026] [security2:error] [pid 67073:tid 67213] [client 20.250.13.23:20674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bolt.php"] [unique_id "aoSAfvcmepr5_nHgLbNH3QAAAhw"] [Tue Aug 18 12:55:42.926884 2026] [security2:error] [pid 66623:tid 66691] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAftO5rbWdOArH04KFmAABXjY"] [Tue Aug 18 12:55:42.933947 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.130.103:14422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/pucci.php"] [unique_id "aoSAftO5rbWdOArH04KFmQAAAYQ"] [Tue Aug 18 12:55:42.944791 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:42.945128 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:42.949672 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.61.152:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/133.php"] [unique_id "aoSAfvcmepr5_nHgLbNH4wAAAjw"] [Tue Aug 18 12:55:42.998842 2026] [security2:error] [pid 67073:tid 67327] [client 20.42.19.40:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/aa.php"] [unique_id "aoSAfvcmepr5_nHgLbNH5wAAAo4"] [Tue Aug 18 12:55:43.006229 2026] [security2:error] [pid 67073:tid 67231] [client 20.42.19.40:1360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ms-edit.php"] [unique_id "aoSAf_cmepr5_nHgLbNH6gAAAi4"] [Tue Aug 18 12:55:43.020807 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kj.php"] [unique_id "aoSAf_cmepr5_nHgLbNH7QACWSE"] [Tue Aug 18 12:55:43.062920 2026] [security2:error] [pid 67073:tid 67297] [client 52.139.47.57:19904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSAf_cmepr5_nHgLbNH7wAAAnA"] [Tue Aug 18 12:55:43.076038 2026] [security2:error] [pid 67073:tid 67331] [client 20.151.109.219:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fo.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8QAAApI"] [Tue Aug 18 12:55:43.088363 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.56.190:23764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ke.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8gAAAnw"] [Tue Aug 18 12:55:43.092291 2026] [security2:error] [pid 67073:tid 67182] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/db.php"] [unique_id "aoSAf_cmepr5_nHgLbNH8wACQmo"] [Tue Aug 18 12:55:43.093227 2026] [security2:error] [pid 67073:tid 67224] [client 68.221.73.131:9749] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.maxhost.com.br"] [uri "/1.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9QAAAic"] [Tue Aug 18 12:55:43.093315 2026] [security2:error] [pid 67073:tid 67224] [client 68.221.73.131:9749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/1.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9QAAAic"] [Tue Aug 18 12:55:43.105791 2026] [security2:error] [pid 67073:tid 67227] [client 158.158.34.183:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/simple.php"] [unique_id "aoSAf_cmepr5_nHgLbNH9wAAAio"] [Tue Aug 18 12:55:43.110430 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/abc.php"] [unique_id "aoSAf_cmepr5_nHgLbNH-AAAAhY"] [Tue Aug 18 12:55:43.121839 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.136.165:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/nhr.php"] [unique_id "aoSAf_cmepr5_nHgLbNH-QAAAnQ"] [Tue Aug 18 12:55:43.143672 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAf9O5rbWdOArH04KFnAAAAXM"] [Tue Aug 18 12:55:43.144195 2026] [security2:error] [pid 66623:tid 66793] [client 20.171.51.14:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/10.php"] [unique_id "aoSAf9O5rbWdOArH04KFnQAAASU"] [Tue Aug 18 12:55:43.158138 2026] [security2:error] [pid 66623:tid 66868] [client 20.163.43.14:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wso.php"] [unique_id "aoSAf9O5rbWdOArH04KFngAAAXA"] [Tue Aug 18 12:55:43.173022 2026] [security2:error] [pid 66623:tid 66830] [client 20.251.48.93:9790] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "filmecompleto.com.br"] [uri "/1.php"] [unique_id "aoSAf9O5rbWdOArH04KFnwAAAUo"] [Tue Aug 18 12:55:43.173132 2026] [security2:error] [pid 66623:tid 66830] [client 20.251.48.93:9790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/1.php"] [unique_id "aoSAf9O5rbWdOArH04KFnwAAAUo"] [Tue Aug 18 12:55:43.176640 2026] [security2:error] [pid 66623:tid 66805] [client 52.238.210.254:8869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/dropdown.php"] [unique_id "aoSAf9O5rbWdOArH04KFoAAAATE"] [Tue Aug 18 12:55:43.203670 2026] [security2:error] [pid 67073:tid 67209] [client 20.100.169.31:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAf_cmepr5_nHgLbNH_gAAAhg"] [Tue Aug 18 12:55:43.253214 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/rip.php"] [unique_id "aoSAf9O5rbWdOArH04KFoQAAAVA"] [Tue Aug 18 12:55:43.258322 2026] [security2:error] [pid 67073:tid 67279] [client 158.23.17.4:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/dirs.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAQAAAl4"] [Tue Aug 18 12:55:43.262941 2026] [security2:error] [pid 67073:tid 67097] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/dropdown.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAgACbhU"] [Tue Aug 18 12:55:43.263524 2026] [security2:error] [pid 67073:tid 67299] [client 20.42.19.40:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAf_cmepr5_nHgLbNIAwAAAnI"] [Tue Aug 18 12:55:43.269420 2026] [autoindex:error] [pid 67073:tid 67317] [client 20.226.6.191:45867] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:43.293840 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.56.190:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nh.php"] [unique_id "aoSAf_cmepr5_nHgLbNIBQAAAiI"] [Tue Aug 18 12:55:43.303732 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.6.191:45867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/403.php"] [unique_id "aoSAf_cmepr5_nHgLbNIBgAAAiA"] [Tue Aug 18 12:55:43.333737 2026] [security2:error] [pid 67073:tid 67283] [client 4.223.164.152:54239] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-content/"] [unique_id "aoSAf_cmepr5_nHgLbNIBwAAAmI"] [Tue Aug 18 12:55:43.376578 2026] [security2:error] [pid 67073:tid 67241] [client 213.35.127.232:63699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNICgAAAjg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:43.383798 2026] [security2:error] [pid 67073:tid 67127] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vg.php"] [unique_id "aoSAf_cmepr5_nHgLbNICwACkDM"] [Tue Aug 18 12:55:43.388895 2026] [security2:error] [pid 67073:tid 67321] [client 20.91.215.254:20728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/d.php"] [unique_id "aoSAf_cmepr5_nHgLbNIDAAAAog"] [Tue Aug 18 12:55:43.407092 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:17024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "jotaautos.com.br"] [uri "/.mopj.php"] [unique_id "aoSAf9O5rbWdOArH04KFowAAAW8"] [Tue Aug 18 12:55:43.407697 2026] [security2:error] [pid 66623:tid 66870] [client 20.151.109.219:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/loading.php"] [unique_id "aoSAf9O5rbWdOArH04KFpAAAAXI"] [Tue Aug 18 12:55:43.417961 2026] [security2:error] [pid 67073:tid 67113] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSAf_cmepr5_nHgLbNIDQACLCU"] [Tue Aug 18 12:55:43.420960 2026] [security2:error] [pid 66623:tid 66821] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAf9O5rbWdOArH04KFpQAAAUE"] [Tue Aug 18 12:55:43.422826 2026] [security2:error] [pid 67073:tid 67263] [client 172.202.39.151:65251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/01.php"] [unique_id "aoSAf_cmepr5_nHgLbNIEAAAAk4"] [Tue Aug 18 12:55:43.432072 2026] [autoindex:error] [pid 67073:tid 67215] [client 20.104.85.180:8021] AH01276: Cannot serve directory /home2/rodrigolocadora/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:43.432462 2026] [security2:error] [pid 66623:tid 66696] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/file.php"] [unique_id "aoSAf9O5rbWdOArH04KFpgABFDs"] [Tue Aug 18 12:55:43.461539 2026] [security2:error] [pid 66623:tid 66872] [client 20.226.56.190:45049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/oo.php"] [unique_id "aoSAf9O5rbWdOArH04KFqAAAAXQ"] [Tue Aug 18 12:55:43.465864 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/akcc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFAAAAiU"] [Tue Aug 18 12:55:43.473127 2026] [security2:error] [pid 67073:tid 67247] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/post.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFQAAAj4"] [Tue Aug 18 12:55:43.487214 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.6.191:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAf9O5rbWdOArH04KFqQAAAWM"] [Tue Aug 18 12:55:43.503144 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/sf.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFgAAAi0"] [Tue Aug 18 12:55:43.504046 2026] [security2:error] [pid 67073:tid 67234] [client 20.42.19.40:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/update/da222.php"] [unique_id "aoSAf_cmepr5_nHgLbNIFwAAAjE"] [Tue Aug 18 12:55:43.534169 2026] [security2:error] [pid 67073:tid 67311] [client 52.238.210.254:40244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/dropdown.php"] [unique_id "aoSAf_cmepr5_nHgLbNIGAAAAn4"] [Tue Aug 18 12:55:43.540986 2026] [security2:error] [pid 67073:tid 67208] [client 74.248.136.165:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAf_cmepr5_nHgLbNIGgAAAhc"] [Tue Aug 18 12:55:43.546710 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:43.546973 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:43.560549 2026] [security2:error] [pid 66623:tid 66887] [client 20.91.215.254:13094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/maint.php"] [unique_id "aoSAf9O5rbWdOArH04KFqgAAAYM"] [Tue Aug 18 12:55:43.574902 2026] [security2:error] [pid 67073:tid 67332] [client 4.232.151.198:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/xleet.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIAAAApM"] [Tue Aug 18 12:55:43.585674 2026] [security2:error] [pid 66623:tid 66859] [client 74.7.241.168:54862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "veiculossaojose.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAf9O5rbWdOArH04KFrAABZzo"] [Tue Aug 18 12:55:43.598146 2026] [security2:error] [pid 67073:tid 67198] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/goods.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIQACM3o"] [Tue Aug 18 12:55:43.617127 2026] [security2:error] [pid 67073:tid 67211] [client 138.36.100.162:41935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIgAAAho"] [Tue Aug 18 12:55:43.617221 2026] [security2:error] [pid 67073:tid 67211] [client 138.36.100.162:41935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIgAAAho"] [Tue Aug 18 12:55:43.637232 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sm.php"] [unique_id "aoSAf_cmepr5_nHgLbNIIwACYQU"] [Tue Aug 18 12:55:43.648227 2026] [security2:error] [pid 67073:tid 67246] [client 52.238.210.254:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/file.php"] [unique_id "aoSAf_cmepr5_nHgLbNIJQAAAj0"] [Tue Aug 18 12:55:43.673000 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.56.190:31633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ja.php"] [unique_id "aoSAf_cmepr5_nHgLbNIJwAAAm8"] [Tue Aug 18 12:55:43.699565 2026] [security2:error] [pid 67073:tid 67285] [client 20.151.109.219:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ke.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKAAAAmQ"] [Tue Aug 18 12:55:43.702988 2026] [security2:error] [pid 67073:tid 67273] [client 20.104.85.180:8021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKQAAAlg"] [Tue Aug 18 12:55:43.706958 2026] [security2:error] [pid 66623:tid 66767] [client 20.42.19.40:3450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/about.php"] [unique_id "aoSAf9O5rbWdOArH04KFrgAAAQs"] [Tue Aug 18 12:55:43.707661 2026] [security2:error] [pid 67073:tid 67245] [client 132.196.61.152:60343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAf_cmepr5_nHgLbNIKgAAAjw"] [Tue Aug 18 12:55:43.718615 2026] [security2:error] [pid 67073:tid 67266] [client 20.48.236.86:16276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/bibil.php"] [unique_id "aoSAf_cmepr5_nHgLbNILAAAAlE"] [Tue Aug 18 12:55:43.720284 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:53074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf_cmepr5_nHgLbNILQAAAoU"] [Tue Aug 18 12:55:43.739206 2026] [security2:error] [pid 67073:tid 67231] [client 20.42.19.40:9651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/upload.php"] [unique_id "aoSAf_cmepr5_nHgLbNILwAAAi4"] [Tue Aug 18 12:55:43.751550 2026] [security2:error] [pid 66623:tid 66808] [client 172.182.200.96:14141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAf9O5rbWdOArH04KFsAAAATQ"] [Tue Aug 18 12:55:43.769128 2026] [security2:error] [pid 67073:tid 67181] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAf_cmepr5_nHgLbNIMAACh2k"] [Tue Aug 18 12:55:43.774822 2026] [security2:error] [pid 66623:tid 66893] [client 4.223.164.152:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/simple.php"] [unique_id "aoSAf9O5rbWdOArH04KFsgAAAYk"] [Tue Aug 18 12:55:43.785446 2026] [security2:error] [pid 66623:tid 66857] [client 20.205.121.237:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAf9O5rbWdOArH04KFswAAAWU"] [Tue Aug 18 12:55:43.795169 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wk/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIMgAAAoE"] [Tue Aug 18 12:55:43.803916 2026] [security2:error] [pid 67073:tid 67271] [client 178.156.189.249:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yycc.com.br"] [uri "/index.php"] [unique_id "aoSAfvcmepr5_nHgLbNHuQACVm8"], referer: https://yycc.com.br/ [Tue Aug 18 12:55:43.814372 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf9O5rbWdOArH04KFtQAAAWo"] [Tue Aug 18 12:55:43.814453 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAf9O5rbWdOArH04KFtQAAAWo"] [Tue Aug 18 12:55:43.829609 2026] [security2:error] [pid 66623:tid 66769] [client 68.221.73.131:61269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/img.php"] [unique_id "aoSAf9O5rbWdOArH04KFtgAAAQ0"] [Tue Aug 18 12:55:43.832981 2026] [security2:error] [pid 67073:tid 67297] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "aoSAf_cmepr5_nHgLbNINAAAAnA"] [Tue Aug 18 12:55:43.835026 2026] [security2:error] [pid 67073:tid 67232] [client 20.163.43.14:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/index/function.php"] [unique_id "aoSAf_cmepr5_nHgLbNINQAAAi8"] [Tue Aug 18 12:55:43.857703 2026] [security2:error] [pid 67073:tid 67207] [client 20.100.169.31:28577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOAAAAhY"] [Tue Aug 18 12:55:43.880390 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/28.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOgACW3A"] [Tue Aug 18 12:55:43.895392 2026] [security2:error] [pid 67073:tid 67206] [client 158.23.17.4:9283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fresh.php"] [unique_id "aoSAf_cmepr5_nHgLbNIOwAAAhU"] [Tue Aug 18 12:55:43.933083 2026] [security2:error] [pid 66623:tid 66720] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/htaccess.php"] [unique_id "aoSAf9O5rbWdOArH04KFtwABQ1M"] [Tue Aug 18 12:55:43.958698 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:10093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ws79.php"] [unique_id "aoSAf_cmepr5_nHgLbNIPgAAAhg"] [Tue Aug 18 12:55:43.982154 2026] [security2:error] [pid 67073:tid 67326] [client 20.42.19.40:9652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wk/index.php"] [unique_id "aoSAf_cmepr5_nHgLbNIPwAAAo0"] [Tue Aug 18 12:55:43.988260 2026] [security2:error] [pid 66623:tid 66783] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAf9O5rbWdOArH04KFuQAAARs"] [Tue Aug 18 12:55:43.996150 2026] [security2:error] [pid 66623:tid 66772] [client 20.151.109.219:24884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nh.php"] [unique_id "aoSAf9O5rbWdOArH04KFugAAARA"] [Tue Aug 18 12:55:44.005418 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:9063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAgPcmepr5_nHgLbNIQQAAAnU"] [Tue Aug 18 12:55:44.011784 2026] [security2:error] [pid 66623:tid 66809] [client 135.225.75.187:18714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tt.php"] [unique_id "aoSAgNO5rbWdOArH04KFuwAAATU"] [Tue Aug 18 12:55:44.022811 2026] [security2:error] [pid 66623:tid 66784] [client 20.171.51.14:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/te.php"] [unique_id "aoSAgNO5rbWdOArH04KFvQAAARw"] [Tue Aug 18 12:55:44.023137 2026] [security2:error] [pid 66623:tid 66835] [client 20.116.17.175:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSAgNO5rbWdOArH04KFvgAAAU8"] [Tue Aug 18 12:55:44.032317 2026] [security2:error] [pid 66623:tid 66786] [client 20.104.85.180:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAgNO5rbWdOArH04KFvwAAAR4"] [Tue Aug 18 12:55:44.094290 2026] [security2:error] [pid 67073:tid 67115] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/m.php"] [unique_id "aoSAgPcmepr5_nHgLbNIRQACbic"] [Tue Aug 18 12:55:44.098573 2026] [security2:error] [pid 67073:tid 67192] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/images/wso.php"] [unique_id "aoSAgPcmepr5_nHgLbNIRwACcnQ"] [Tue Aug 18 12:55:44.123066 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:2944] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KFyAAAAWk"] [Tue Aug 18 12:55:44.123100 2026] [security2:error] [pid 66623:tid 66812] [client 20.42.19.40:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/goods.php"] [unique_id "aoSAgNO5rbWdOArH04KFxwAAATg"] [Tue Aug 18 12:55:44.123157 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KFyAAAAWk"] [Tue Aug 18 12:55:44.136229 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.56.190:2525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xx.php"] [unique_id "aoSAgNO5rbWdOArH04KFyQAAAUA"] [Tue Aug 18 12:55:44.153101 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:44.153540 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:44.202523 2026] [security2:error] [pid 66623:tid 66877] [client 20.163.43.14:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/edit.php"] [unique_id "aoSAgNO5rbWdOArH04KFzgAAAXk"] [Tue Aug 18 12:55:44.203800 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.34.183:17485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/berax.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUAAAAnk"] [Tue Aug 18 12:55:44.210867 2026] [security2:error] [pid 67073:tid 67324] [client 20.91.215.254:20730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUQAAAos"] [Tue Aug 18 12:55:44.219446 2026] [security2:error] [pid 67073:tid 67303] [client 20.42.19.40:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-act.php"] [unique_id "aoSAgPcmepr5_nHgLbNIUgAAAnY"] [Tue Aug 18 12:55:44.226815 2026] [security2:error] [pid 67073:tid 67223] [client 4.223.164.152:46185] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aoSAgPcmepr5_nHgLbNIUwAAAiY"] [Tue Aug 18 12:55:44.256687 2026] [security2:error] [pid 67073:tid 67268] [client 20.251.48.93:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/img.php"] [unique_id "aoSAgPcmepr5_nHgLbNIVgAAAlM"] [Tue Aug 18 12:55:44.257628 2026] [security2:error] [pid 66623:tid 66882] [client 52.238.210.254:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/goods.php"] [unique_id "aoSAgNO5rbWdOArH04KFzwAAAX4"] [Tue Aug 18 12:55:44.267077 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.61.152:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/mosty.php"] [unique_id "aoSAgNO5rbWdOArH04KF0AAAARo"] [Tue Aug 18 12:55:44.269120 2026] [security2:error] [pid 67073:tid 67174] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/index/function.php"] [unique_id "aoSAgPcmepr5_nHgLbNIVwACbGI"] [Tue Aug 18 12:55:44.273831 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:49312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/album.php"] [unique_id "aoSAgNO5rbWdOArH04KF0QAAAUk"] [Tue Aug 18 12:55:44.278827 2026] [security2:error] [pid 66623:tid 66840] [client 20.91.215.254:19510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/phpMailer.php"] [unique_id "aoSAgNO5rbWdOArH04KF0gAAAVQ"] [Tue Aug 18 12:55:44.293158 2026] [security2:error] [pid 67073:tid 67184] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAgPcmepr5_nHgLbNIWQACXWw"] [Tue Aug 18 12:55:44.296685 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAgPcmepr5_nHgLbNIWgAAAkc"] [Tue Aug 18 12:55:44.317824 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:8028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp.php"] [unique_id "aoSAgNO5rbWdOArH04KF0wAAARM"] [Tue Aug 18 12:55:44.326069 2026] [security2:error] [pid 67073:tid 67307] [client 20.48.236.86:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/halo.php"] [unique_id "aoSAgPcmepr5_nHgLbNIXAAAAno"] [Tue Aug 18 12:55:44.340231 2026] [security2:error] [pid 67073:tid 67212] [client 20.151.109.219:17579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/oo.php"] [unique_id "aoSAgPcmepr5_nHgLbNIXQAAAhs"] [Tue Aug 18 12:55:44.378674 2026] [security2:error] [pid 66623:tid 66856] [client 74.248.136.165:29107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/rtx.php"] [unique_id "aoSAgNO5rbWdOArH04KF1QAAAWQ"] [Tue Aug 18 12:55:44.380849 2026] [security2:error] [pid 67073:tid 67313] [client 68.155.154.236:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wsrer.php"] [unique_id "aoSAgPcmepr5_nHgLbNIYgAAAoA"] [Tue Aug 18 12:55:44.388629 2026] [security2:error] [pid 67073:tid 67228] [client 213.35.127.232:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAgPcmepr5_nHgLbNIYwAAAis"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:44.410333 2026] [security2:error] [pid 66623:tid 66863] [client 68.221.73.131:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/222.php"] [unique_id "aoSAgNO5rbWdOArH04KF1gAAAWs"] [Tue Aug 18 12:55:44.413563 2026] [security2:error] [pid 67073:tid 67173] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nl.php"] [unique_id "aoSAgPcmepr5_nHgLbNIZAACMWE"] [Tue Aug 18 12:55:44.436457 2026] [security2:error] [pid 66623:tid 66705] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/info.php"] [unique_id "aoSAgNO5rbWdOArH04KF1wABXkQ"] [Tue Aug 18 12:55:44.472635 2026] [security2:error] [pid 67073:tid 67258] [client 20.163.43.14:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNIZwAAAkk"] [Tue Aug 18 12:55:44.476806 2026] [security2:error] [pid 67073:tid 67284] [client 20.42.19.40:9625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAgPcmepr5_nHgLbNIaAAAAmM"] [Tue Aug 18 12:55:44.480171 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.169.31:31480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSAgPcmepr5_nHgLbNIaQAAApA"] [Tue Aug 18 12:55:44.482669 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.56.190:47107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/conn-test.php"] [unique_id "aoSAgPcmepr5_nHgLbNIagAAAng"] [Tue Aug 18 12:55:44.501756 2026] [security2:error] [pid 67073:tid 67332] [client 20.42.19.40:3409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/php8.php"] [unique_id "aoSAgPcmepr5_nHgLbNIbAAAApM"] [Tue Aug 18 12:55:44.531861 2026] [security2:error] [pid 67073:tid 67310] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/public/css.php"] [unique_id "aoSAgPcmepr5_nHgLbNIbgAAAn0"] [Tue Aug 18 12:55:44.533203 2026] [security2:error] [pid 66623:tid 66790] [client 20.171.51.14:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/kc.php"] [unique_id "aoSAgNO5rbWdOArH04KF2QAAASI"] [Tue Aug 18 12:55:44.545145 2026] [security2:error] [pid 67073:tid 67242] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/blurbs.php"] [unique_id "aoSAgPcmepr5_nHgLbNIcAAAAjk"] [Tue Aug 18 12:55:44.582411 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.130.103:14451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-temp.php"] [unique_id "aoSAgNO5rbWdOArH04KF2gAAASU"] [Tue Aug 18 12:55:44.597884 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.85.180:8038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/function/function.php"] [unique_id "aoSAgNO5rbWdOArH04KF2wAAAXA"] [Tue Aug 18 12:55:44.602087 2026] [security2:error] [pid 67073:tid 67091] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/profile.php"] [unique_id "aoSAgPcmepr5_nHgLbNIcwACGQ8"] [Tue Aug 18 12:55:44.620331 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/68.php"] [unique_id "aoSAgPcmepr5_nHgLbNIdAACUHY"] [Tue Aug 18 12:55:44.623849 2026] [security2:error] [pid 66623:tid 66805] [client 52.238.210.254:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/hplfuns.php"] [unique_id "aoSAgNO5rbWdOArH04KF3AAAATE"] [Tue Aug 18 12:55:44.625299 2026] [security2:error] [pid 66623:tid 66787] [client 20.151.109.219:24860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ja.php"] [unique_id "aoSAgNO5rbWdOArH04KF3QAAAR8"] [Tue Aug 18 12:55:44.658778 2026] [security2:error] [pid 67073:tid 67225] [client 4.223.164.152:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/chosen.php"] [unique_id "aoSAgPcmepr5_nHgLbNIdwAAAig"] [Tue Aug 18 12:55:44.672632 2026] [security2:error] [pid 67073:tid 67233] [client 20.29.77.16:52765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/email.php"] [unique_id "aoSAgPcmepr5_nHgLbNIeAAAAjA"] [Tue Aug 18 12:55:44.705011 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.56.190:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fg.php"] [unique_id "aoSAgPcmepr5_nHgLbNIegAAAlE"] [Tue Aug 18 12:55:44.737960 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAgPcmepr5_nHgLbNIgQAAAlY"] [Tue Aug 18 12:55:44.752461 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:44.752776 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:44.773017 2026] [security2:error] [pid 67073:tid 67178] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/sx.php"] [unique_id "aoSAgPcmepr5_nHgLbNIgwACkWY"] [Tue Aug 18 12:55:44.774901 2026] [security2:error] [pid 67073:tid 67297] [client 158.23.17.4:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/admin404.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhAAAAnA"] [Tue Aug 18 12:55:44.784245 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.6.191:6621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/rip.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhgAAAms"] [Tue Aug 18 12:55:44.801993 2026] [security2:error] [pid 67073:tid 67316] [client 74.248.136.165:43695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/end.php"] [unique_id "aoSAgPcmepr5_nHgLbNIhwAAAoM"] [Tue Aug 18 12:55:44.814763 2026] [security2:error] [pid 67073:tid 67207] [client 20.163.43.14:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNIiAAAAhY"] [Tue Aug 18 12:55:44.837312 2026] [security2:error] [pid 67073:tid 67276] [client 20.116.17.175:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/output.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjAAAAls"] [Tue Aug 18 12:55:44.876949 2026] [security2:error] [pid 67073:tid 67201] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jl.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjgACGH0"] [Tue Aug 18 12:55:44.883590 2026] [security2:error] [pid 67073:tid 67326] [client 132.196.61.152:61026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/blurbs.php"] [unique_id "aoSAgPcmepr5_nHgLbNIjwAAAo0"] [Tue Aug 18 12:55:44.900479 2026] [security2:error] [pid 66623:tid 66794] [client 20.104.85.180:7283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAgNO5rbWdOArH04KF3wAAASY"] [Tue Aug 18 12:55:44.903983 2026] [security2:error] [pid 67073:tid 67238] [client 20.151.109.219:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xx.php"] [unique_id "aoSAgPcmepr5_nHgLbNIkQAAAjU"] [Tue Aug 18 12:55:44.923975 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAgPcmepr5_nHgLbNIkwAAAoU"] [Tue Aug 18 12:55:44.939128 2026] [fcgid:warn] [pid 66623:tid 66870] (70014)End of file found: [client 66.132.186.180:34584] mod_fcgid: can't get data from http client [Tue Aug 18 12:55:44.945128 2026] [security2:error] [pid 67073:tid 67096] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAgPcmepr5_nHgLbNImAACRRQ"] [Tue Aug 18 12:55:44.958551 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:45627] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KF4QAAARg"] [Tue Aug 18 12:55:44.958648 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:45627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/1.php"] [unique_id "aoSAgNO5rbWdOArH04KF4QAAARg"] [Tue Aug 18 12:55:44.978904 2026] [security2:error] [pid 67073:tid 67223] [client 52.139.47.57:47632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSAgPcmepr5_nHgLbNImwAAAiY"] [Tue Aug 18 12:55:44.979623 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgNO5rbWdOArH04KF4gAAATc"] [Tue Aug 18 12:55:44.979739 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:58604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgNO5rbWdOArH04KF4gAAATc"] [Tue Aug 18 12:55:44.979832 2026] [security2:error] [pid 66623:tid 66821] [client 172.202.39.151:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/lv.php"] [unique_id "aoSAgNO5rbWdOArH04KF4wAAAUE"] [Tue Aug 18 12:55:44.995836 2026] [security2:error] [pid 66623:tid 66776] [client 20.48.236.86:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ajq1s.php"] [unique_id "aoSAgNO5rbWdOArH04KF5AAAARQ"] [Tue Aug 18 12:55:45.047013 2026] [security2:error] [pid 67073:tid 67278] [client 20.42.19.40:3430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/info.php"] [unique_id "aoSAgfcmepr5_nHgLbNIogAAAl0"] [Tue Aug 18 12:55:45.053203 2026] [authz_core:error] [pid 67073:tid 67124] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:45.053443 2026] [authz_core:error] [pid 67073:tid 67124] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:45.057587 2026] [security2:error] [pid 67073:tid 67256] [client 20.65.69.59:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/creds.php"] [unique_id "aoSAgfcmepr5_nHgLbNIowAAAkc"] [Tue Aug 18 12:55:45.060454 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-good.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpAAAAmA"] [Tue Aug 18 12:55:45.075621 2026] [security2:error] [pid 67073:tid 67263] [client 68.221.73.131:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/key.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpQAAAk4"] [Tue Aug 18 12:55:45.077501 2026] [security2:error] [pid 67073:tid 67289] [client 4.223.164.152:46183] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSAgfcmepr5_nHgLbNIpgAAAmg"] [Tue Aug 18 12:55:45.087474 2026] [security2:error] [pid 67073:tid 67231] [client 20.91.215.254:20714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAgfcmepr5_nHgLbNIqAAAAi4"] [Tue Aug 18 12:55:45.107400 2026] [security2:error] [pid 67073:tid 67259] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/bajah.php"] [unique_id "aoSAgfcmepr5_nHgLbNIqwAAAko"] [Tue Aug 18 12:55:45.114985 2026] [security2:error] [pid 67073:tid 67152] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNIrAACNkw"] [Tue Aug 18 12:55:45.117843 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tq.php"] [unique_id "aoSAgfcmepr5_nHgLbNIrQACG0U"] [Tue Aug 18 12:55:45.180246 2026] [security2:error] [pid 67073:tid 67313] [client 20.205.121.237:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jic.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNIsAAAAoA"] [Tue Aug 18 12:55:45.189224 2026] [security2:error] [pid 67073:tid 67257] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/r.php"] [unique_id "aoSAgfcmepr5_nHgLbNIsgAAAkg"] [Tue Aug 18 12:55:45.189684 2026] [security2:error] [pid 66623:tid 66859] [client 135.225.75.187:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xqq.php"] [unique_id "aoSAgdO5rbWdOArH04KF5QAAAWc"] [Tue Aug 18 12:55:45.197780 2026] [security2:error] [pid 66623:tid 66831] [client 158.158.74.177:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/g.php"] [unique_id "aoSAgdO5rbWdOArH04KF5gAAAUs"] [Tue Aug 18 12:55:45.219205 2026] [security2:error] [pid 67073:tid 67208] [client 20.171.51.14:51797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIswAAAhc"] [Tue Aug 18 12:55:45.220494 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.136.165:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detoniconstrutora.com.br"] [uri "/ae.php"] [unique_id "aoSAgdO5rbWdOArH04KF6AAAAWI"] [Tue Aug 18 12:55:45.220943 2026] [security2:error] [pid 66623:tid 66841] [client 20.171.51.14:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/jn.php"] [unique_id "aoSAgdO5rbWdOArH04KF6QAAAVU"] [Tue Aug 18 12:55:45.224260 2026] [security2:error] [pid 67073:tid 67252] [client 20.163.43.14:4423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/as.php"] [unique_id "aoSAgfcmepr5_nHgLbNItAAAAkM"] [Tue Aug 18 12:55:45.229128 2026] [security2:error] [pid 67073:tid 67305] [client 20.104.85.180:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNItgAAAng"] [Tue Aug 18 12:55:45.260693 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:24972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAgfcmepr5_nHgLbNIuAAAAjc"] [Tue Aug 18 12:55:45.271160 2026] [security2:error] [pid 66623:tid 66802] [client 20.151.109.219:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/conn-test.php"] [unique_id "aoSAgdO5rbWdOArH04KF7QAAAS4"] [Tue Aug 18 12:55:45.276346 2026] [security2:error] [pid 67073:tid 67232] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIpwACL0I"] [Tue Aug 18 12:55:45.286710 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.34.183:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fi2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIuwAAAnk"] [Tue Aug 18 12:55:45.332339 2026] [autoindex:error] [pid 67073:tid 67141] [remote 74.248.18.37:0] AH01276: Cannot serve directory /home1/powerbelt/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:45.339371 2026] [security2:error] [pid 67073:tid 67210] [client 20.100.169.31:33136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSAgfcmepr5_nHgLbNIvQAAAhk"] [Tue Aug 18 12:55:45.342656 2026] [security2:error] [pid 67073:tid 67296] [client 20.116.17.175:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/tiny2.php"] [unique_id "aoSAgfcmepr5_nHgLbNIvgAAAm8"] [Tue Aug 18 12:55:45.348035 2026] [security2:error] [pid 67073:tid 67243] [client 20.42.19.40:9678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAgfcmepr5_nHgLbNIwAAAAjo"] [Tue Aug 18 12:55:45.353014 2026] [security2:error] [pid 67073:tid 67154] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/cv.php"] [unique_id "aoSAgfcmepr5_nHgLbNIwQACUE4"] [Tue Aug 18 12:55:45.387739 2026] [security2:error] [pid 67073:tid 67135] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "uhequeimado.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAgfcmepr5_nHgLbNIxAACZjs"] [Tue Aug 18 12:55:45.389467 2026] [security2:error] [pid 66623:tid 66826] [client 4.232.151.198:33876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wp.php"] [unique_id "aoSAgdO5rbWdOArH04KF7gAAAUY"] [Tue Aug 18 12:55:45.400425 2026] [security2:error] [pid 67073:tid 67255] [client 213.35.127.232:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAgfcmepr5_nHgLbNIxwAAAkY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:45.401911 2026] [security2:error] [pid 66623:tid 66824] [client 158.158.74.177:22730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gecko.php"] [unique_id "aoSAgdO5rbWdOArH04KF7wAAAUQ"] [Tue Aug 18 12:55:45.409203 2026] [security2:error] [pid 67073:tid 67274] [client 20.226.6.191:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIyAAAAlk"] [Tue Aug 18 12:55:45.504938 2026] [security2:error] [pid 67073:tid 67095] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNIzAACKhM"] [Tue Aug 18 12:55:45.506489 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.56.190:2547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ve.php"] [unique_id "aoSAgfcmepr5_nHgLbNIzQAAAhY"] [Tue Aug 18 12:55:45.530874 2026] [security2:error] [pid 66623:tid 66853] [client 20.104.85.180:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/ok.php"] [unique_id "aoSAgdO5rbWdOArH04KF8AAAAWE"] [Tue Aug 18 12:55:45.551635 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/als.php"] [unique_id "aoSAgfcmepr5_nHgLbNI0AAAAhU"] [Tue Aug 18 12:55:45.554966 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/un.php"] [unique_id "aoSAgfcmepr5_nHgLbNI0QACWh8"] [Tue Aug 18 12:55:45.558635 2026] [autoindex:error] [pid 66623:tid 66769] [client 20.226.6.191:56214] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:45.566186 2026] [security2:error] [pid 66623:tid 66825] [client 20.91.215.254:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/al.php"] [unique_id "aoSAgdO5rbWdOArH04KF8wAAAUU"] [Tue Aug 18 12:55:45.575438 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:53211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fg.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1AAAAl8"] [Tue Aug 18 12:55:45.593633 2026] [security2:error] [pid 66623:tid 66832] [client 20.163.43.14:4365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAgdO5rbWdOArH04KF9QAAAUw"] [Tue Aug 18 12:55:45.609237 2026] [security2:error] [pid 67073:tid 67286] [client 126.159.39.191:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.39.159.126.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innacorp.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIygAAAmU"] [Tue Aug 18 12:55:45.609345 2026] [security2:error] [pid 67073:tid 67286] [client 126.159.39.191:56562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innacorp.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNIygAAAmU"] [Tue Aug 18 12:55:45.623841 2026] [security2:error] [pid 67073:tid 67222] [client 149.34.210.141:50421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1gAAAiU"] [Tue Aug 18 12:55:45.636217 2026] [autoindex:error] [pid 67073:tid 67291] [client 52.73.140.57:14715] AH01276: Cannot serve directory /home1/xsolutions/advoguide.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:45.671439 2026] [security2:error] [pid 67073:tid 67279] [client 20.251.48.93:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/222.php"] [unique_id "aoSAgfcmepr5_nHgLbNI2wAAAl4"] [Tue Aug 18 12:55:45.682005 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.56.190:23748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ia.php"] [unique_id "aoSAgfcmepr5_nHgLbNI3QAAAnI"] [Tue Aug 18 12:55:45.684471 2026] [security2:error] [pid 66623:tid 66881] [client 35.240.145.190:33724] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ferreirafreitas.com.br"] [uri "/"] [unique_id "aoSAgdO5rbWdOArH04KF9gAAAX0"] [Tue Aug 18 12:55:45.687928 2026] [security2:error] [pid 67073:tid 67254] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/domvf.php"] [unique_id "aoSAgfcmepr5_nHgLbNI3wAAAkU"] [Tue Aug 18 12:55:45.711619 2026] [security2:error] [pid 66623:tid 66809] [client 20.42.19.40:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAgdO5rbWdOArH04KF9wAAATU"] [Tue Aug 18 12:55:45.717642 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.130.103:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAgfcmepr5_nHgLbNI4QAAAos"] [Tue Aug 18 12:55:45.724877 2026] [autoindex:error] [pid 67073:tid 67125] [remote 74.248.18.37:0] AH01276: Cannot serve directory /home1/powerbelt/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:45.740949 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/tes.php"] [unique_id "aoSAgfcmepr5_nHgLbNI4wAAAlM"] [Tue Aug 18 12:55:45.747990 2026] [security2:error] [pid 67073:tid 67320] [client 68.221.73.131:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/chosen.php"] [unique_id "aoSAgfcmepr5_nHgLbNI5AAAAoc"] [Tue Aug 18 12:55:45.773205 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bf.php"] [unique_id "aoSAgfcmepr5_nHgLbNI5gAAAjI"] [Tue Aug 18 12:55:45.789412 2026] [security2:error] [pid 67073:tid 67122] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "uhequeimado.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSAgfcmepr5_nHgLbNI5wACXS4"] [Tue Aug 18 12:55:45.791963 2026] [security2:error] [pid 67073:tid 67229] [client 52.238.210.254:10224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/htaccess.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6QAAAiw"] [Tue Aug 18 12:55:45.796304 2026] [security2:error] [pid 66623:tid 66786] [client 20.65.98.162:28513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/bengi.php"] [unique_id "aoSAgdO5rbWdOArH04KF-AAAAR4"] [Tue Aug 18 12:55:45.815087 2026] [security2:error] [pid 67073:tid 67103] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/config/.env.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6gACYBs"] [Tue Aug 18 12:55:45.816357 2026] [security2:error] [pid 67073:tid 67219] [client 20.104.85.180:7964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodrigolocadora.com.br"] [uri "/item.php"] [unique_id "aoSAgfcmepr5_nHgLbNI6wAAAiI"] [Tue Aug 18 12:55:45.851923 2026] [security2:error] [pid 67073:tid 67263] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/radio.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7QAAAk4"] [Tue Aug 18 12:55:45.885203 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/evil.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7gACNlk"] [Tue Aug 18 12:55:45.891336 2026] [security2:error] [pid 67073:tid 67222] [client 149.34.210.141:50421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAgfcmepr5_nHgLbNI1gAAAiU"] [Tue Aug 18 12:55:45.900003 2026] [security2:error] [pid 67073:tid 67114] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSAgfcmepr5_nHgLbNI7wACKSY"] [Tue Aug 18 12:55:45.924372 2026] [security2:error] [pid 67073:tid 67079] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/laravel/.env"] [unique_id "aoSAgfcmepr5_nHgLbNI8QACTwM"] [Tue Aug 18 12:55:45.948038 2026] [security2:error] [pid 66623:tid 66779] [client 20.65.69.59:40523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/mandrill.php"] [unique_id "aoSAgdO5rbWdOArH04KF-gAAARc"] [Tue Aug 18 12:55:45.956812 2026] [security2:error] [pid 67073:tid 67328] [client 74.248.18.37:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ws83.php"] [unique_id "aoSAgfcmepr5_nHgLbNI9QAAAo8"] [Tue Aug 18 12:55:45.960430 2026] [security2:error] [pid 67073:tid 67087] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAgfcmepr5_nHgLbNI9gACSws"] [Tue Aug 18 12:55:45.961585 2026] [security2:error] [pid 67073:tid 67311] [client 20.151.109.219:17544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ve.php"] [unique_id "aoSAgfcmepr5_nHgLbNI9wAAAn4"] [Tue Aug 18 12:55:45.981991 2026] [security2:error] [pid 67073:tid 67312] [client 20.163.43.14:4357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAgfcmepr5_nHgLbNI-QAAAn8"] [Tue Aug 18 12:55:45.991473 2026] [security2:error] [pid 67073:tid 67293] [client 5.253.205.188:50496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdemodemo.bak"] [unique_id "aoSAgfcmepr5_nHgLbNI-gAAAmw"], referer: https://medihub.com.br/installdemodemo.bak [Tue Aug 18 12:55:46.018826 2026] [security2:error] [pid 67073:tid 67252] [client 68.155.154.236:16276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAgvcmepr5_nHgLbNI_QAAAkM"] [Tue Aug 18 12:55:46.038747 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/nox.php"] [unique_id "aoSAgvcmepr5_nHgLbNI_wAAAjM"] [Tue Aug 18 12:55:46.047138 2026] [security2:error] [pid 67073:tid 67217] [client 20.91.215.254:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/abc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAAAAAiA"] [Tue Aug 18 12:55:46.069418 2026] [security2:error] [pid 67073:tid 67109] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAgACLyE"] [Tue Aug 18 12:55:46.069946 2026] [security2:error] [pid 67073:tid 67240] [client 20.163.43.14:4282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/files/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJAwAAAjc"] [Tue Aug 18 12:55:46.080554 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJBAAAAh8"] [Tue Aug 18 12:55:46.085958 2026] [security2:error] [pid 67073:tid 67171] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pw.php"] [unique_id "aoSAgvcmepr5_nHgLbNJBQACd18"] [Tue Aug 18 12:55:46.098659 2026] [security2:error] [pid 67073:tid 67139] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/core/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJBwACPT8"] [Tue Aug 18 12:55:46.112426 2026] [security2:error] [pid 67073:tid 67332] [client 20.48.236.86:16203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/spip.php"] [unique_id "aoSAgvcmepr5_nHgLbNJCQAAApM"] [Tue Aug 18 12:55:46.129155 2026] [security2:error] [pid 67073:tid 67321] [client 20.226.6.191:6625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/moon.php"] [unique_id "aoSAgvcmepr5_nHgLbNJCgAAAog"] [Tue Aug 18 12:55:46.187079 2026] [security2:error] [pid 67073:tid 67225] [client 20.42.19.40:1406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-links-opml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDAAAAig"] [Tue Aug 18 12:55:46.194006 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.169.31:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAgtO5rbWdOArH04KF_gAAAUA"] [Tue Aug 18 12:55:46.203862 2026] [security2:error] [pid 67073:tid 67208] [client 20.91.215.254:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDgAAAhc"] [Tue Aug 18 12:55:46.205411 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:22754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gettest.php"] [unique_id "aoSAgvcmepr5_nHgLbNJDwAAAjE"] [Tue Aug 18 12:55:46.206179 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:7622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAgtO5rbWdOArH04KF_wAAAV0"] [Tue Aug 18 12:55:46.226651 2026] [security2:error] [pid 67073:tid 67255] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSAgvcmepr5_nHgLbNJEQAAAkY"] [Tue Aug 18 12:55:46.241838 2026] [security2:error] [pid 67073:tid 67314] [client 172.202.39.151:50553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/moon.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFAAAAoE"] [Tue Aug 18 12:55:46.250737 2026] [security2:error] [pid 66623:tid 66818] [client 20.226.56.190:17907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kn.php"] [unique_id "aoSAgtO5rbWdOArH04KGBAAAAT4"] [Tue Aug 18 12:55:46.251392 2026] [security2:error] [pid 67073:tid 67186] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFgACcG4"] [Tue Aug 18 12:55:46.251537 2026] [security2:error] [pid 67073:tid 67330] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/fpwch.php"] [unique_id "aoSAgvcmepr5_nHgLbNJFwAAApE"] [Tue Aug 18 12:55:46.257232 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:46.257514 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:46.263195 2026] [security2:error] [pid 67073:tid 67305] [client 4.232.151.198:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/155.php"] [unique_id "aoSAgvcmepr5_nHgLbNJGAAAAng"] [Tue Aug 18 12:55:46.265277 2026] [security2:error] [pid 67073:tid 67249] [client 20.171.51.14:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fd.php"] [unique_id "aoSAgvcmepr5_nHgLbNJGQAAAkA"] [Tue Aug 18 12:55:46.320801 2026] [security2:error] [pid 67073:tid 67128] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fn.php"] [unique_id "aoSAgvcmepr5_nHgLbNJHQACRDQ"] [Tue Aug 18 12:55:46.332534 2026] [security2:error] [pid 67073:tid 67134] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/config.php.bak"] [unique_id "aoSAgvcmepr5_nHgLbNJHgACOzo"] [Tue Aug 18 12:55:46.334634 2026] [security2:error] [pid 66623:tid 66869] [client 68.221.73.131:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/thoms.php"] [unique_id "aoSAgtO5rbWdOArH04KGBQAAAXE"] [Tue Aug 18 12:55:46.362589 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.56.190:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wm.php"] [unique_id "aoSAgtO5rbWdOArH04KGBwAAAXk"] [Tue Aug 18 12:55:46.362591 2026] [security2:error] [pid 67073:tid 67206] [client 132.196.61.152:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bajah.php"] [unique_id "aoSAgvcmepr5_nHgLbNJIAAAAhU"] [Tue Aug 18 12:55:46.383643 2026] [security2:error] [pid 67073:tid 67272] [client 135.225.75.187:47206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/06.php"] [unique_id "aoSAgvcmepr5_nHgLbNJIgAAAlc"] [Tue Aug 18 12:55:46.390375 2026] [security2:error] [pid 67073:tid 67077] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uhequeimado.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAgvcmepr5_nHgLbNJIwACGAE"] [Tue Aug 18 12:55:46.399115 2026] [security2:error] [pid 67073:tid 67302] [client 52.139.47.57:9049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJAAAAnU"] [Tue Aug 18 12:55:46.413399 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJQAAAjk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:46.421223 2026] [security2:error] [pid 67073:tid 67118] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJgACcio"] [Tue Aug 18 12:55:46.424791 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJJwAAAkU"] [Tue Aug 18 12:55:46.425709 2026] [security2:error] [pid 67073:tid 67324] [client 20.163.43.14:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKAAAAos"] [Tue Aug 18 12:55:46.432900 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.130.103:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/puc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKQAAAm4"] [Tue Aug 18 12:55:46.464991 2026] [security2:error] [pid 67073:tid 67268] [client 158.23.17.4:29460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/loading.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKgAAAlM"] [Tue Aug 18 12:55:46.472481 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.34.183:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/feeds.php"] [unique_id "aoSAgvcmepr5_nHgLbNJKwAAAoY"] [Tue Aug 18 12:55:46.474967 2026] [security2:error] [pid 67073:tid 67320] [client 20.48.236.86:16202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/wpup.php"] [unique_id "aoSAgvcmepr5_nHgLbNJLAAAAoc"] [Tue Aug 18 12:55:46.481909 2026] [security2:error] [pid 66623:tid 66878] [client 4.223.164.152:17630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file59.php"] [unique_id "aoSAgtO5rbWdOArH04KGCAAAAXo"] [Tue Aug 18 12:55:46.487129 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.56.190:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ac.php"] [unique_id "aoSAgtO5rbWdOArH04KGCQAAAWw"] [Tue Aug 18 12:55:46.530174 2026] [security2:error] [pid 67073:tid 67281] [client 20.42.19.40:9617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/ioxi-o.php"] [unique_id "aoSAgvcmepr5_nHgLbNJLgAAAmA"] [Tue Aug 18 12:55:46.563167 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:46.563441 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:46.569247 2026] [security2:error] [pid 67073:tid 67097] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kf.php"] [unique_id "aoSAgvcmepr5_nHgLbNJMgACNhU"] [Tue Aug 18 12:55:46.593153 2026] [security2:error] [pid 67073:tid 67203] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJMwACLX8"] [Tue Aug 18 12:55:46.615154 2026] [security2:error] [pid 67073:tid 67313] [client 20.151.109.219:53199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ia.php"] [unique_id "aoSAgvcmepr5_nHgLbNJNAAAAoA"] [Tue Aug 18 12:55:46.617895 2026] [security2:error] [pid 67073:tid 67105] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.swp"] [unique_id "aoSAgvcmepr5_nHgLbNJNQACKx0"] [Tue Aug 18 12:55:46.640397 2026] [security2:error] [pid 66623:tid 66844] [client 20.116.17.175:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSAgtO5rbWdOArH04KGCgAAAVg"] [Tue Aug 18 12:55:46.640762 2026] [security2:error] [pid 67073:tid 67257] [client 52.238.210.254:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/images/wso.php"] [unique_id "aoSAgvcmepr5_nHgLbNJOQAAAkg"] [Tue Aug 18 12:55:46.691059 2026] [security2:error] [pid 67073:tid 67217] [client 20.215.241.237:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/images.php"] [unique_id "aoSAgvcmepr5_nHgLbNJPAAAAiA"] [Tue Aug 18 12:55:46.765428 2026] [security2:error] [pid 67073:tid 67136] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSAgvcmepr5_nHgLbNJPwACHzw"] [Tue Aug 18 12:55:46.769028 2026] [security2:error] [pid 67073:tid 67218] [client 178.153.171.161:37212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQAAAAiE"] [Tue Aug 18 12:55:46.769156 2026] [security2:error] [pid 67073:tid 67218] [client 178.153.171.161:37212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQAAAAiE"] [Tue Aug 18 12:55:46.774495 2026] [security2:error] [pid 67073:tid 67304] [client 20.48.236.86:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/myy.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQgAAAnc"] [Tue Aug 18 12:55:46.776668 2026] [security2:error] [pid 67073:tid 67282] [client 20.171.51.14:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/info2.php"] [unique_id "aoSAgvcmepr5_nHgLbNJQwAAAmE"] [Tue Aug 18 12:55:46.787511 2026] [security2:error] [pid 67073:tid 67332] [client 20.42.19.40:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/0x.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRAAAApM"] [Tue Aug 18 12:55:46.790787 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.6.191:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/cache.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRQAAAhw"] [Tue Aug 18 12:55:46.810352 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAgvcmepr5_nHgLbNJRgAAAj4"] [Tue Aug 18 12:55:46.817391 2026] [security2:error] [pid 66623:tid 66829] [client 20.100.169.31:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAgtO5rbWdOArH04KGDQAAAUk"] [Tue Aug 18 12:55:46.821775 2026] [security2:error] [pid 66623:tid 66785] [client 20.251.48.93:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/key.php"] [unique_id "aoSAgtO5rbWdOArH04KGDgAAAR0"] [Tue Aug 18 12:55:46.828564 2026] [security2:error] [pid 67073:tid 67210] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/adminner.php"] [unique_id "aoSAgvcmepr5_nHgLbNJSQAAAhk"] [Tue Aug 18 12:55:46.839091 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:29981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/alfa.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTAAAAiw"] [Tue Aug 18 12:55:46.839663 2026] [security2:error] [pid 67073:tid 67148] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/public/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJSwACGkg"] [Tue Aug 18 12:55:46.853750 2026] [security2:error] [pid 67073:tid 67248] [client 20.91.215.254:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTQAAAj8"] [Tue Aug 18 12:55:46.863087 2026] [security2:error] [pid 67073:tid 67265] [client 20.163.43.14:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAgvcmepr5_nHgLbNJTgAAAlA"] [Tue Aug 18 12:55:46.897788 2026] [security2:error] [pid 67073:tid 67234] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/readme.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUAAAAjE"] [Tue Aug 18 12:55:46.909587 2026] [security2:error] [pid 67073:tid 67287] [client 4.223.164.152:46148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/admin.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUQAAAmY"] [Tue Aug 18 12:55:46.917020 2026] [security2:error] [pid 67073:tid 67081] [remote 212.29.237.5:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-login.php"] [unique_id "aoSAgvcmepr5_nHgLbNJUwACHgU"] [Tue Aug 18 12:55:46.920371 2026] [security2:error] [pid 67073:tid 67329] [client 20.91.215.254:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-activat.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVAAAApA"] [Tue Aug 18 12:55:46.922588 2026] [security2:error] [pid 67073:tid 67252] [client 158.158.74.177:2631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/goods.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVQAAAkM"] [Tue Aug 18 12:55:46.936126 2026] [security2:error] [pid 67073:tid 67155] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVgACRk8"] [Tue Aug 18 12:55:46.943741 2026] [security2:error] [pid 67073:tid 67220] [client 68.221.73.131:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/wpxml.php"] [unique_id "aoSAgvcmepr5_nHgLbNJVwAAAiM"] [Tue Aug 18 12:55:46.945087 2026] [security2:error] [pid 67073:tid 67181] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/su.php"] [unique_id "aoSAgvcmepr5_nHgLbNJWAACZGk"] [Tue Aug 18 12:55:46.956934 2026] [security2:error] [pid 67073:tid 67160] [remote 34.62.54.143:52216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/web/.env"] [unique_id "aoSAgvcmepr5_nHgLbNJWQACgVQ"] [Tue Aug 18 12:55:46.985461 2026] [security2:error] [pid 66623:tid 66884] [client 20.151.109.219:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kn.php"] [unique_id "aoSAgtO5rbWdOArH04KGDwAAAYA"] [Tue Aug 18 12:55:46.994117 2026] [security2:error] [pid 67073:tid 67297] [client 132.196.61.152:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/h.php"] [unique_id "aoSAgvcmepr5_nHgLbNJXAAAAnA"] [Tue Aug 18 12:55:47.004610 2026] [security2:error] [pid 67073:tid 67251] [client 20.65.98.162:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file2.php"] [unique_id "aoSAg_cmepr5_nHgLbNJXwAAAkI"] [Tue Aug 18 12:55:47.043194 2026] [security2:error] [pid 67073:tid 67249] [client 20.42.19.40:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYAAAAkA"] [Tue Aug 18 12:55:47.050779 2026] [security2:error] [pid 67073:tid 67316] [client 20.116.17.175:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ccou.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYQAAAoM"] [Tue Aug 18 12:55:47.054430 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:9658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/222.php"] [unique_id "aoSAg_cmepr5_nHgLbNJYgAAAhY"] [Tue Aug 18 12:55:47.111080 2026] [security2:error] [pid 67073:tid 67143] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJZQACjUM"] [Tue Aug 18 12:55:47.140427 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-the.php"] [unique_id "aoSAg_cmepr5_nHgLbNJaAAAAms"] [Tue Aug 18 12:55:47.158916 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:47.159200 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:47.199157 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.130.103:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/8.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbAAAAiY"] [Tue Aug 18 12:55:47.212118 2026] [security2:error] [pid 67073:tid 67268] [client 20.48.236.86:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/geido.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbgAAAlM"] [Tue Aug 18 12:55:47.220170 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAg_cmepr5_nHgLbNJbwAAAoc"] [Tue Aug 18 12:55:47.236289 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.56.190:2499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yz.php"] [unique_id "aoSAg9O5rbWdOArH04KGEAAAAUg"] [Tue Aug 18 12:55:47.247329 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wp-key.php"] [unique_id "aoSAg_cmepr5_nHgLbNJcQACYHQ"] [Tue Aug 18 12:55:47.247660 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJcgAAAkc"] [Tue Aug 18 12:55:47.252678 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.6.191:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/gecko.php"] [unique_id "aoSAg9O5rbWdOArH04KGEQAAASQ"] [Tue Aug 18 12:55:47.271325 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.56.190:31018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kj.php"] [unique_id "aoSAg9O5rbWdOArH04KGFAAAAVE"] [Tue Aug 18 12:55:47.276134 2026] [security2:error] [pid 67073:tid 67237] [client 4.232.151.198:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/96i.php"] [unique_id "aoSAg_cmepr5_nHgLbNJdQAAAjQ"] [Tue Aug 18 12:55:47.278585 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wm.php"] [unique_id "aoSAg9O5rbWdOArH04KGFQAAAV4"] [Tue Aug 18 12:55:47.282813 2026] [security2:error] [pid 67073:tid 67174] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAg_cmepr5_nHgLbNJdwACG2I"] [Tue Aug 18 12:55:47.291562 2026] [security2:error] [pid 67073:tid 67313] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/reze.php"] [unique_id "aoSAg_cmepr5_nHgLbNJeAAAAoA"] [Tue Aug 18 12:55:47.306689 2026] [security2:error] [pid 66623:tid 66845] [client 20.42.19.40:9626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/aa.php"] [unique_id "aoSAg9O5rbWdOArH04KGFgAAAVk"] [Tue Aug 18 12:55:47.339236 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aa2.php"] [unique_id "aoSAg_cmepr5_nHgLbNJegAAAo8"] [Tue Aug 18 12:55:47.388755 2026] [security2:error] [pid 67073:tid 67217] [client 52.238.210.254:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/index/function.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfQAAAiA"] [Tue Aug 18 12:55:47.393019 2026] [security2:error] [pid 67073:tid 67279] [client 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.simetriaarquitetura.com.br"] [uri "/abcd.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfgAAAl4"] [Tue Aug 18 12:55:47.397116 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.56.190:47145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vg.php"] [unique_id "aoSAg_cmepr5_nHgLbNJfwAAAjc"] [Tue Aug 18 12:55:47.398591 2026] [security2:error] [pid 66623:tid 66773] [client 20.42.19.40:2194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/adminfuns.php"] [unique_id "aoSAg9O5rbWdOArH04KGFwAAARE"] [Tue Aug 18 12:55:47.399465 2026] [security2:error] [pid 67073:tid 67310] [client 172.202.39.151:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/new.php"] [unique_id "aoSAg_cmepr5_nHgLbNJgQAAAn0"] [Tue Aug 18 12:55:47.419673 2026] [security2:error] [pid 67073:tid 67304] [client 20.116.17.175:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/crgio.php"] [unique_id "aoSAg_cmepr5_nHgLbNJggAAAnc"] [Tue Aug 18 12:55:47.426734 2026] [security2:error] [pid 67073:tid 67227] [client 213.35.127.232:64582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAg_cmepr5_nHgLbNJgwAAAio"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:47.433227 2026] [security2:error] [pid 66623:tid 66816] [client 20.163.43.14:4375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAg9O5rbWdOArH04KGGAAAATw"] [Tue Aug 18 12:55:47.454000 2026] [security2:error] [pid 67073:tid 67235] [client 20.100.169.31:17869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJhAAAAjI"] [Tue Aug 18 12:55:47.463813 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gg.php"] [unique_id "aoSAg_cmepr5_nHgLbNJhwACk1E"] [Tue Aug 18 12:55:47.473024 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:47.473383 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:47.478972 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:31675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sm.php"] [unique_id "aoSAg_cmepr5_nHgLbNJiQAAAj4"] [Tue Aug 18 12:55:47.507379 2026] [security2:error] [pid 67073:tid 67170] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJiwACUl4"] [Tue Aug 18 12:55:47.537395 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/gelay.php"] [unique_id "aoSAg9O5rbWdOArH04KGGQAAAVo"] [Tue Aug 18 12:55:47.585029 2026] [security2:error] [pid 67073:tid 67215] [client 20.163.43.14:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/rip.php"] [unique_id "aoSAg_cmepr5_nHgLbNJjwAAAh4"] [Tue Aug 18 12:55:47.585746 2026] [security2:error] [pid 66623:tid 66830] [client 20.42.19.40:9692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAg9O5rbWdOArH04KGGgAAAUo"] [Tue Aug 18 12:55:47.624258 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.69.59:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/main.php"] [unique_id "aoSAg_cmepr5_nHgLbNJkQAAAig"] [Tue Aug 18 12:55:47.635518 2026] [security2:error] [pid 67073:tid 67255] [client 20.151.109.219:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ac.php"] [unique_id "aoSAg_cmepr5_nHgLbNJkgAAAkY"] [Tue Aug 18 12:55:47.641166 2026] [security2:error] [pid 67073:tid 67205] [client 20.91.215.254:24664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJlAAAAhQ"] [Tue Aug 18 12:55:47.643002 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.136.165:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ccou.php"] [unique_id "aoSAg_cmepr5_nHgLbNJlgAAAmQ"] [Tue Aug 18 12:55:47.653666 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:44613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmAAAAiw"] [Tue Aug 18 12:55:47.655097 2026] [security2:error] [pid 67073:tid 67232] [client 20.91.215.254:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmQAAAi8"] [Tue Aug 18 12:55:47.664591 2026] [security2:error] [pid 67073:tid 67274] [client 135.225.75.187:37309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/166.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmgAAAlk"] [Tue Aug 18 12:55:47.677042 2026] [security2:error] [pid 66623:tid 66836] [client 20.226.6.191:6537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAg9O5rbWdOArH04KGHAAAAVA"] [Tue Aug 18 12:55:47.678009 2026] [security2:error] [pid 67073:tid 67091] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAg_cmepr5_nHgLbNJmwACVg8"] [Tue Aug 18 12:55:47.709252 2026] [security2:error] [pid 67073:tid 67251] [client 20.226.56.190:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/28.php"] [unique_id "aoSAg_cmepr5_nHgLbNJnwAAAkI"] [Tue Aug 18 12:55:47.766458 2026] [security2:error] [pid 67073:tid 67253] [client 20.163.43.14:4389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/an.php"] [unique_id "aoSAg_cmepr5_nHgLbNJowAAAkQ"] [Tue Aug 18 12:55:47.773207 2026] [security2:error] [pid 67073:tid 67297] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJnAACcHY"] [Tue Aug 18 12:55:47.778396 2026] [security2:error] [pid 66623:tid 66847] [client 85.154.68.202:12173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg9O5rbWdOArH04KGHQAAAVs"] [Tue Aug 18 12:55:47.778495 2026] [security2:error] [pid 66623:tid 66847] [client 85.154.68.202:12173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg9O5rbWdOArH04KGHQAAAVs"] [Tue Aug 18 12:55:47.786388 2026] [security2:error] [pid 67073:tid 67111] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gi.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpQACjSM"] [Tue Aug 18 12:55:47.788904 2026] [security2:error] [pid 67073:tid 67295] [client 160.120.140.123:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpgAAAm4"] [Tue Aug 18 12:55:47.789079 2026] [security2:error] [pid 67073:tid 67295] [client 160.120.140.123:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpgAAAm4"] [Tue Aug 18 12:55:47.804778 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/xamp.php"] [unique_id "aoSAg_cmepr5_nHgLbNJpwAAAlo"] [Tue Aug 18 12:55:47.807074 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.6.191:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/o.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqAAAAnU"] [Tue Aug 18 12:55:47.850016 2026] [security2:error] [pid 67073:tid 67201] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqgAChX0"] [Tue Aug 18 12:55:47.861846 2026] [security2:error] [pid 67073:tid 67244] [client 192.141.172.134:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqwAAAjs"] [Tue Aug 18 12:55:47.861929 2026] [security2:error] [pid 67073:tid 67244] [client 192.141.172.134:58696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAg_cmepr5_nHgLbNJqwAAAjs"] [Tue Aug 18 12:55:47.867027 2026] [security2:error] [pid 67073:tid 67223] [client 20.226.56.190:2509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/m.php"] [unique_id "aoSAg_cmepr5_nHgLbNJrQAAAiY"] [Tue Aug 18 12:55:47.871805 2026] [security2:error] [pid 67073:tid 67309] [client 68.221.73.131:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/file1221.php"] [unique_id "aoSAg_cmepr5_nHgLbNJrgAAAnw"] [Tue Aug 18 12:55:47.873077 2026] [security2:error] [pid 66623:tid 66870] [client 20.42.19.40:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAg9O5rbWdOArH04KGIAAAAXI"] [Tue Aug 18 12:55:47.884303 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.56.190:31665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsAAAAoY"] [Tue Aug 18 12:55:47.896645 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:15360] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsQAAAiI"] [Tue Aug 18 12:55:47.896759 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:15360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsQAAAiI"] [Tue Aug 18 12:55:47.911681 2026] [security2:error] [pid 67073:tid 67276] [client 20.48.236.86:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/atomlib.php"] [unique_id "aoSAg_cmepr5_nHgLbNJsgAAAls"] [Tue Aug 18 12:55:47.943787 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:21692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yz.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtAAAAiU"] [Tue Aug 18 12:55:47.946355 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.56.190:28253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/68.php"] [unique_id "aoSAg9O5rbWdOArH04KGIwAAATc"] [Tue Aug 18 12:55:47.947586 2026] [security2:error] [pid 67073:tid 67224] [client 158.158.34.183:36155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/curl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtQAAAic"] [Tue Aug 18 12:55:47.991034 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.56.190:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jl.php"] [unique_id "aoSAg_cmepr5_nHgLbNJtwAAAk8"] [Tue Aug 18 12:55:48.010651 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.6.191:6585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/bb.php"] [unique_id "aoSAhPcmepr5_nHgLbNJuQAAAoA"] [Tue Aug 18 12:55:48.020846 2026] [security2:error] [pid 67073:tid 67117] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAhPcmepr5_nHgLbNJugACSCk"] [Tue Aug 18 12:55:48.029853 2026] [security2:error] [pid 67073:tid 67236] [client 20.251.48.93:9784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/chosen.php"] [unique_id "aoSAhPcmepr5_nHgLbNJuwAAAjM"] [Tue Aug 18 12:55:48.042618 2026] [security2:error] [pid 67073:tid 67112] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pz.php"] [unique_id "aoSAhPcmepr5_nHgLbNJvAACSSQ"] [Tue Aug 18 12:55:48.086040 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.56.190:2522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tq.php"] [unique_id "aoSAhNO5rbWdOArH04KGJAAAAUs"] [Tue Aug 18 12:55:48.092107 2026] [security2:error] [pid 66623:tid 66767] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/rh.php"] [unique_id "aoSAhNO5rbWdOArH04KGJQAAAQs"] [Tue Aug 18 12:55:48.103066 2026] [security2:error] [pid 66623:tid 66808] [client 20.116.17.175:57419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSAhNO5rbWdOArH04KGJgAAATQ"] [Tue Aug 18 12:55:48.117111 2026] [security2:error] [pid 66623:tid 66872] [client 52.139.47.57:19956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wso.php"] [unique_id "aoSAhNO5rbWdOArH04KGJwAAAXQ"] [Tue Aug 18 12:55:48.121569 2026] [security2:error] [pid 66623:tid 66826] [client 20.163.43.14:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGKAAAAUY"] [Tue Aug 18 12:55:48.138455 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.56.190:31028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/cv.php"] [unique_id "aoSAhPcmepr5_nHgLbNJwQAAAiE"] [Tue Aug 18 12:55:48.229304 2026] [security2:error] [pid 66623:tid 66862] [client 4.223.164.152:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/bless.php"] [unique_id "aoSAhNO5rbWdOArH04KGLgAAAWo"] [Tue Aug 18 12:55:48.238176 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kk.php"] [unique_id "aoSAhPcmepr5_nHgLbNJxQACkxY"] [Tue Aug 18 12:55:48.244713 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:6600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAhNO5rbWdOArH04KGMAAAAWE"] [Tue Aug 18 12:55:48.248786 2026] [security2:error] [pid 66623:tid 66777] [client 20.42.19.40:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/adminfuns.php"] [unique_id "aoSAhNO5rbWdOArH04KGMQAAARU"] [Tue Aug 18 12:55:48.270917 2026] [security2:error] [pid 66623:tid 66825] [client 20.48.236.86:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/ee.php"] [unique_id "aoSAhNO5rbWdOArH04KGMgAAAUU"] [Tue Aug 18 12:55:48.273562 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/un.php"] [unique_id "aoSAhPcmepr5_nHgLbNJxgAAAlI"] [Tue Aug 18 12:55:48.280421 2026] [security2:error] [pid 66623:tid 66887] [client 20.91.215.254:24672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/past1.php"] [unique_id "aoSAhNO5rbWdOArH04KGMwAAAYM"] [Tue Aug 18 12:55:48.286803 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:17570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kj.php"] [unique_id "aoSAhPcmepr5_nHgLbNJyAAAAh0"] [Tue Aug 18 12:55:48.310220 2026] [security2:error] [pid 66623:tid 66796] [client 20.163.43.14:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/404.php"] [unique_id "aoSAhNO5rbWdOArH04KGNAAAASg"] [Tue Aug 18 12:55:48.365889 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:48.366159 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:48.377552 2026] [security2:error] [pid 66623:tid 66793] [client 213.202.253.4:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/gdftps.php"] [unique_id "aoSAhNO5rbWdOArH04KGNgAAASU"], referer: www.google.com [Tue Aug 18 12:55:48.387889 2026] [security2:error] [pid 67073:tid 67233] [client 52.238.210.254:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/info.php"] [unique_id "aoSAhPcmepr5_nHgLbNJzAAAAjA"] [Tue Aug 18 12:55:48.436419 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAhPcmepr5_nHgLbNJzgACHkU"] [Tue Aug 18 12:55:48.438564 2026] [security2:error] [pid 66623:tid 66855] [client 213.35.127.232:64802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAhNO5rbWdOArH04KGNwAAAWM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:48.444042 2026] [security2:error] [pid 66623:tid 66798] [client 20.91.215.254:11277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/abc.php"] [unique_id "aoSAhNO5rbWdOArH04KGOAAAASo"] [Tue Aug 18 12:55:48.486559 2026] [security2:error] [pid 67073:tid 67252] [client 20.42.19.40:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/akc.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0AAAAkM"] [Tue Aug 18 12:55:48.494527 2026] [security2:error] [pid 66623:tid 66861] [client 20.163.43.14:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/moon.php"] [unique_id "aoSAhNO5rbWdOArH04KGOQAAAWk"] [Tue Aug 18 12:55:48.508090 2026] [security2:error] [pid 67073:tid 67254] [client 158.158.74.177:16524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/gulu.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0gAAAkU"] [Tue Aug 18 12:55:48.521893 2026] [security2:error] [pid 67073:tid 67255] [client 20.100.169.31:17878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ0wAAAkY"] [Tue Aug 18 12:55:48.530139 2026] [fcgid:warn] [pid 67073:tid 67245] (70014)End of file found: [client 66.132.195.88:7832] mod_fcgid: can't get data from http client [Tue Aug 18 12:55:48.555703 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/profile.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ1wAAAiM"] [Tue Aug 18 12:55:48.558229 2026] [security2:error] [pid 66623:tid 66867] [client 20.100.169.31:47419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/edit.php"] [unique_id "aoSAhNO5rbWdOArH04KGOgAAAW8"] [Tue Aug 18 12:55:48.558510 2026] [security2:error] [pid 67073:tid 67314] [client 20.116.17.175:57643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/css.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ2AAAAoE"] [Tue Aug 18 12:55:48.590828 2026] [security2:error] [pid 66623:tid 66803] [client 68.221.73.131:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/nox.php"] [unique_id "aoSAhNO5rbWdOArH04KGOwAAAS8"] [Tue Aug 18 12:55:48.619977 2026] [security2:error] [pid 66623:tid 66774] [client 157.51.166.53:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGPQAAARI"] [Tue Aug 18 12:55:48.620114 2026] [security2:error] [pid 66623:tid 66774] [client 157.51.166.53:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhNO5rbWdOArH04KGPQAAARI"] [Tue Aug 18 12:55:48.624111 2026] [security2:error] [pid 66623:tid 66849] [client 20.151.109.219:24895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vg.php"] [unique_id "aoSAhNO5rbWdOArH04KGPgAAAV0"] [Tue Aug 18 12:55:48.662124 2026] [security2:error] [pid 66623:tid 66833] [client 52.139.47.57:9028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/www.php"] [unique_id "aoSAhNO5rbWdOArH04KGQAAAAU0"] [Tue Aug 18 12:55:48.668460 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:48.668869 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:48.674144 2026] [security2:error] [pid 66623:tid 66874] [client 4.223.164.152:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file25.php"] [unique_id "aoSAhNO5rbWdOArH04KGQgAAAXY"] [Tue Aug 18 12:55:48.674889 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSAhNO5rbWdOArH04KGQwAAAXE"] [Tue Aug 18 12:55:48.685056 2026] [security2:error] [pid 67073:tid 67231] [client 132.196.61.152:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ano.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3AAAAi4"] [Tue Aug 18 12:55:48.689151 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.56.190:28232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/evil.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3QAAAlY"] [Tue Aug 18 12:55:48.703095 2026] [security2:error] [pid 67073:tid 67094] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dg.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3gACSxI"] [Tue Aug 18 12:55:48.708927 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/as.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ3wAAAoM"] [Tue Aug 18 12:55:48.725851 2026] [security2:error] [pid 66623:tid 66819] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSAhNO5rbWdOArH04KGRgAAAT8"] [Tue Aug 18 12:55:48.730463 2026] [security2:error] [pid 67073:tid 67323] [client 20.48.236.86:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/tfm.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ4QAAAoo"] [Tue Aug 18 12:55:48.740090 2026] [security2:error] [pid 67073:tid 67297] [client 135.225.75.187:18764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/snq.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ4gAAAnA"] [Tue Aug 18 12:55:48.770885 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pw.php"] [unique_id "aoSAhPcmepr5_nHgLbNJ7AAAAmU"] [Tue Aug 18 12:55:48.792238 2026] [security2:error] [pid 66623:tid 66878] [client 158.23.17.4:29440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/conn-test.php"] [unique_id "aoSAhNO5rbWdOArH04KGRwAAAXo"] [Tue Aug 18 12:55:48.800922 2026] [security2:error] [pid 67073:tid 67206] [client 20.42.19.40:9641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/buy.php"] [unique_id "aoSAhPcmepr5_nHgLbNKGQAAAhU"] [Tue Aug 18 12:55:48.836025 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/cache.php"] [unique_id "aoSAhPcmepr5_nHgLbNKGgAAAoQ"] [Tue Aug 18 12:55:48.843393 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:24985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAhNO5rbWdOArH04KGSQAAAVg"] [Tue Aug 18 12:55:48.874965 2026] [security2:error] [pid 66623:tid 66778] [client 20.251.48.93:65248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/thoms.php"] [unique_id "aoSAhNO5rbWdOArH04KGSgAAARY"] [Tue Aug 18 12:55:48.886534 2026] [security2:error] [pid 67073:tid 67146] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHAACOUY"] [Tue Aug 18 12:55:48.892595 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.56.190:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fn.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHQAAAlw"] [Tue Aug 18 12:55:48.895234 2026] [security2:error] [pid 67073:tid 67299] [client 68.155.154.236:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/yxijx.php"] [unique_id "aoSAhPcmepr5_nHgLbNKHgAAAnI"] [Tue Aug 18 12:55:48.927194 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bm.php"] [unique_id "aoSAhPcmepr5_nHgLbNKIAACYkg"] [Tue Aug 18 12:55:48.930659 2026] [security2:error] [pid 67073:tid 67223] [client 20.151.109.219:24843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sm.php"] [unique_id "aoSAhPcmepr5_nHgLbNKIQAAAiY"] [Tue Aug 18 12:55:48.959826 2026] [security2:error] [pid 66623:tid 66877] [client 20.91.215.254:14298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/file61.php"] [unique_id "aoSAhNO5rbWdOArH04KGTAAAAXk"] [Tue Aug 18 12:55:48.974924 2026] [security2:error] [pid 66623:tid 66865] [client 20.226.56.190:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kf.php"] [unique_id "aoSAhNO5rbWdOArH04KGTgAAAW0"] [Tue Aug 18 12:55:49.001858 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.130.103:15376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKLQAAAk4"] [Tue Aug 18 12:55:49.010442 2026] [security2:error] [pid 66623:tid 66838] [client 20.163.43.14:4373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAhdO5rbWdOArH04KGUAAAAVI"] [Tue Aug 18 12:55:49.040707 2026] [security2:error] [pid 66623:tid 66827] [client 20.42.19.40:9687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/cong.php"] [unique_id "aoSAhdO5rbWdOArH04KGUQAAAUc"] [Tue Aug 18 12:55:49.042986 2026] [security2:error] [pid 66623:tid 66850] [client 20.116.17.175:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAhdO5rbWdOArH04KGUgAAAV4"] [Tue Aug 18 12:55:49.057091 2026] [security2:error] [pid 67073:tid 67184] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSAhfcmepr5_nHgLbNKOgACNGw"] [Tue Aug 18 12:55:49.063194 2026] [security2:error] [pid 67073:tid 67222] [client 52.238.210.254:8867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/profile.php"] [unique_id "aoSAhfcmepr5_nHgLbNKOwAAAiU"] [Tue Aug 18 12:55:49.083665 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/222.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPAAAAk8"] [Tue Aug 18 12:55:49.084375 2026] [security2:error] [pid 66623:tid 66773] [client 20.48.236.86:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/tool.php"] [unique_id "aoSAhdO5rbWdOArH04KGUwAAARE"] [Tue Aug 18 12:55:49.088820 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/bolt.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPgAAAhs"] [Tue Aug 18 12:55:49.096993 2026] [security2:error] [pid 67073:tid 67221] [client 4.232.151.198:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/term.php"] [unique_id "aoSAhfcmepr5_nHgLbNKPwAAAiQ"] [Tue Aug 18 12:55:49.098496 2026] [security2:error] [pid 66623:tid 66871] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/root.php"] [unique_id "aoSAhdO5rbWdOArH04KGVAAAAXM"] [Tue Aug 18 12:55:49.106540 2026] [security2:error] [pid 67073:tid 67199] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAhfcmepr5_nHgLbNKQwACW3s"], referer: https://barsantajulia.com.br/ [Tue Aug 18 12:55:49.123141 2026] [security2:error] [pid 67073:tid 67226] [client 4.223.164.152:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file15.php"] [unique_id "aoSAhfcmepr5_nHgLbNKTgAAAik"] [Tue Aug 18 12:55:49.123432 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.56.190:2741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/su.php"] [unique_id "aoSAhdO5rbWdOArH04KGVQAAAWs"] [Tue Aug 18 12:55:49.186473 2026] [security2:error] [pid 67073:tid 67205] [client 20.250.13.23:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bthil.php"] [unique_id "aoSAhfcmepr5_nHgLbNKUAAAAhQ"] [Tue Aug 18 12:55:49.187841 2026] [security2:error] [pid 66623:tid 66884] [client 20.91.215.254:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/sf.php"] [unique_id "aoSAhdO5rbWdOArH04KGVwAAAYA"] [Tue Aug 18 12:55:49.201220 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sx.php"] [unique_id "aoSAhdO5rbWdOArH04KGWQAAAXI"] [Tue Aug 18 12:55:49.206053 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vu.php"] [unique_id "aoSAhfcmepr5_nHgLbNKUgACj3Y"] [Tue Aug 18 12:55:49.213919 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:6583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAhdO5rbWdOArH04KGWgAAATc"] [Tue Aug 18 12:55:49.258744 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:12911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/28.php"] [unique_id "aoSAhfcmepr5_nHgLbNKVQAAAns"] [Tue Aug 18 12:55:49.318751 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.69.59:40549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/payout.php"] [unique_id "aoSAhdO5rbWdOArH04KGXQAAAVU"] [Tue Aug 18 12:55:49.330367 2026] [security2:error] [pid 66623:tid 66872] [client 68.221.73.131:9775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/akismet.php"] [unique_id "aoSAhdO5rbWdOArH04KGXgAAAXQ"] [Tue Aug 18 12:55:49.352011 2026] [security2:error] [pid 67073:tid 67267] [client 20.42.19.40:1393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAhfcmepr5_nHgLbNKZAAAAlI"] [Tue Aug 18 12:55:49.363993 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:22731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/h.php"] [unique_id "aoSAhdO5rbWdOArH04KGXwAAAYQ"] [Tue Aug 18 12:55:49.367428 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.56.190:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wp-key.php"] [unique_id "aoSAhdO5rbWdOArH04KGYAAAAQw"] [Tue Aug 18 12:55:49.370083 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:17906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKZQAAAh0"] [Tue Aug 18 12:55:49.423920 2026] [security2:error] [pid 66623:tid 66862] [client 20.48.236.86:16128] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.sitemw.com.br"] [uri "/1.php"] [unique_id "aoSAhdO5rbWdOArH04KGYgAAAWo"] [Tue Aug 18 12:55:49.424035 2026] [security2:error] [pid 66623:tid 66862] [client 20.48.236.86:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/1.php"] [unique_id "aoSAhdO5rbWdOArH04KGYgAAAWo"] [Tue Aug 18 12:55:49.431178 2026] [security2:error] [pid 67073:tid 67236] [client 158.158.34.183:32230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/Njima.php"] [unique_id "aoSAhfcmepr5_nHgLbNKagAAAjM"] [Tue Aug 18 12:55:49.446494 2026] [autoindex:error] [pid 67073:tid 67329] [client 20.226.6.191:64099] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:49.455345 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.6.191:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/aa.php"] [unique_id "aoSAhfcmepr5_nHgLbNKbwAAAig"] [Tue Aug 18 12:55:49.458280 2026] [security2:error] [pid 67073:tid 67313] [client 213.35.127.232:65055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAhfcmepr5_nHgLbNKcAAAAoA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:49.463441 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ic.php"] [unique_id "aoSAhfcmepr5_nHgLbNKcQACRlA"] [Tue Aug 18 12:55:49.512512 2026] [security2:error] [pid 67073:tid 67229] [client 20.29.77.16:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/summary.php"] [unique_id "aoSAhfcmepr5_nHgLbNKdgAAAiw"] [Tue Aug 18 12:55:49.554039 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:44623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/x.php"] [unique_id "aoSAhfcmepr5_nHgLbNKdwAAAn0"] [Tue Aug 18 12:55:49.562242 2026] [security2:error] [pid 67073:tid 67232] [client 20.151.109.219:21672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/m.php"] [unique_id "aoSAhfcmepr5_nHgLbNKeAAAAi8"] [Tue Aug 18 12:55:49.569707 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:49.570012 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:49.586494 2026] [security2:error] [pid 67073:tid 67251] [client 20.42.19.40:1397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/db.php"] [unique_id "aoSAhfcmepr5_nHgLbNKfgAAAkI"] [Tue Aug 18 12:55:49.587135 2026] [security2:error] [pid 67073:tid 67260] [client 4.223.164.152:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/f35.php"] [unique_id "aoSAhfcmepr5_nHgLbNKfwAAAks"] [Tue Aug 18 12:55:49.588366 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:2706] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/cgi-bin/"] [unique_id "aoSAhfcmepr5_nHgLbNKgAAAAng"] [Tue Aug 18 12:55:49.595960 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.56.190:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gg.php"] [unique_id "aoSAhfcmepr5_nHgLbNKhAAAAkA"] [Tue Aug 18 12:55:49.647457 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:15374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAhfcmepr5_nHgLbNKjgAAAkQ"] [Tue Aug 18 12:55:49.648261 2026] [security2:error] [pid 67073:tid 67266] [client 5.253.205.188:50526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/installdemodemo.sql"] [unique_id "aoSAhfcmepr5_nHgLbNKjQAAAlE"], referer: https://medihub.com.br/installdemodemo.sql [Tue Aug 18 12:55:49.663358 2026] [security2:error] [pid 67073:tid 67286] [client 135.225.75.187:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-access.php"] [unique_id "aoSAhfcmepr5_nHgLbNKkQAAAmU"] [Tue Aug 18 12:55:49.679410 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ue.php"] [unique_id "aoSAhfcmepr5_nHgLbNKkwACalk"] [Tue Aug 18 12:55:49.687958 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.56.190:23786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gi.php"] [unique_id "aoSAhfcmepr5_nHgLbNKlAAAAlo"] [Tue Aug 18 12:55:49.715281 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/epinyins.php"] [unique_id "aoSAhdO5rbWdOArH04KGZgAAARA"] [Tue Aug 18 12:55:49.734422 2026] [security2:error] [pid 67073:tid 67299] [client 52.238.210.254:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/sx.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpAAAAnI"] [Tue Aug 18 12:55:49.734443 2026] [security2:error] [pid 67073:tid 67277] [client 20.48.236.86:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/dev1s.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpQAAAlw"] [Tue Aug 18 12:55:49.745326 2026] [security2:error] [pid 66623:tid 66809] [client 20.163.43.14:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAhdO5rbWdOArH04KGZwAAATU"] [Tue Aug 18 12:55:49.759030 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pz.php"] [unique_id "aoSAhfcmepr5_nHgLbNKpgAAAjs"] [Tue Aug 18 12:55:49.762404 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.6.191:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAhfcmepr5_nHgLbNKqAAAAmI"] [Tue Aug 18 12:55:49.767707 2026] [security2:error] [pid 67073:tid 67262] [client 20.163.43.14:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wso.php"] [unique_id "aoSAhfcmepr5_nHgLbNKqwAAAk0"] [Tue Aug 18 12:55:49.804545 2026] [security2:error] [pid 67073:tid 67241] [client 20.91.215.254:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.instrumedcalibracao.com.br"] [uri "/license.php"] [unique_id "aoSAhfcmepr5_nHgLbNKsgAAAjg"] [Tue Aug 18 12:55:49.850002 2026] [security2:error] [pid 67073:tid 67285] [client 4.232.151.198:19910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtAAAAmQ"] [Tue Aug 18 12:55:49.851214 2026] [security2:error] [pid 67073:tid 67219] [client 20.42.19.40:1352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/dropdown.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtQAAAiI"] [Tue Aug 18 12:55:49.861850 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nl.php"] [unique_id "aoSAhfcmepr5_nHgLbNKtwAAAjo"] [Tue Aug 18 12:55:49.870458 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:49.870716 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:49.881814 2026] [security2:error] [pid 66623:tid 66775] [client 47.128.60.142:39256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sunlux.com.br"] [uri "/robots.txt"] [unique_id "aoSAhdO5rbWdOArH04KGaAAAARM"] [Tue Aug 18 12:55:49.896764 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lr.php"] [unique_id "aoSAhfcmepr5_nHgLbNKuwACTyo"] [Tue Aug 18 12:55:49.907526 2026] [security2:error] [pid 67073:tid 67168] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAhfcmepr5_nHgLbNKvAACJFw"] [Tue Aug 18 12:55:49.914681 2026] [security2:error] [pid 66623:tid 66813] [client 20.171.51.14:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nu.php"] [unique_id "aoSAhdO5rbWdOArH04KGaQAAATk"] [Tue Aug 18 12:55:49.932550 2026] [security2:error] [pid 67073:tid 67278] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/s.php"] [unique_id "aoSAhfcmepr5_nHgLbNKvgAAAl0"] [Tue Aug 18 12:55:49.940181 2026] [security2:error] [pid 66623:tid 66796] [client 20.91.215.254:12011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/chosen.php"] [unique_id "aoSAhdO5rbWdOArH04KGawAAASg"] [Tue Aug 18 12:55:50.020310 2026] [security2:error] [pid 66623:tid 66881] [client 20.100.169.31:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAhtO5rbWdOArH04KGbAAAAX0"] [Tue Aug 18 12:55:50.031383 2026] [security2:error] [pid 67073:tid 67282] [client 4.223.164.152:37275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-load.php"] [unique_id "aoSAhvcmepr5_nHgLbNKyAAAAmE"] [Tue Aug 18 12:55:50.050475 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kk.php"] [unique_id "aoSAhvcmepr5_nHgLbNKywAAAj4"] [Tue Aug 18 12:55:50.073516 2026] [security2:error] [pid 67073:tid 67237] [client 158.158.74.177:16514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/hello.php"] [unique_id "aoSAhvcmepr5_nHgLbNKzQAAAjQ"] [Tue Aug 18 12:55:50.078149 2026] [security2:error] [pid 67073:tid 67142] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSAhvcmepr5_nHgLbNKzgACGUI"] [Tue Aug 18 12:55:50.090057 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:28137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSAhtO5rbWdOArH04KGbgAAARw"] [Tue Aug 18 12:55:50.092479 2026] [security2:error] [pid 67073:tid 67214] [client 20.42.19.40:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/file.php"] [unique_id "aoSAhvcmepr5_nHgLbNK0QAAAh0"] [Tue Aug 18 12:55:50.108269 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.12:35772] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:50.108527 2026] [authz_core:error] [pid 66623:tid 66672] [remote 57.141.22.12:35772] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:50.136922 2026] [security2:error] [pid 67073:tid 67246] [client 20.48.236.86:16312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/we.php"] [unique_id "aoSAhvcmepr5_nHgLbNK0wAAAj0"] [Tue Aug 18 12:55:50.156105 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ka.php"] [unique_id "aoSAhvcmepr5_nHgLbNK2AACGlQ"] [Tue Aug 18 12:55:50.188075 2026] [security2:error] [pid 67073:tid 67236] [client 20.151.109.219:51672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/68.php"] [unique_id "aoSAhvcmepr5_nHgLbNK2wAAAjM"] [Tue Aug 18 12:55:50.198624 2026] [security2:error] [pid 67073:tid 67215] [client 20.116.17.175:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/load.php"] [unique_id "aoSAhvcmepr5_nHgLbNK3AAAAh4"] [Tue Aug 18 12:55:50.204924 2026] [security2:error] [pid 67073:tid 67304] [client 20.226.56.190:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAhvcmepr5_nHgLbNK3QAAAnc"] [Tue Aug 18 12:55:50.265161 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4AAAAjw"] [Tue Aug 18 12:55:50.266887 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.130.103:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/edit.php"] [unique_id "aoSAhtO5rbWdOArH04KGcAAAAUA"] [Tue Aug 18 12:55:50.276801 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/gm.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4QAAAiw"] [Tue Aug 18 12:55:50.280817 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/sf.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4gAAAoE"] [Tue Aug 18 12:55:50.296732 2026] [security2:error] [pid 66623:tid 66782] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sang.php"] [unique_id "aoSAhtO5rbWdOArH04KGcgAAARo"] [Tue Aug 18 12:55:50.300273 2026] [security2:error] [pid 66623:tid 66866] [client 20.29.77.16:47753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/conf.php"] [unique_id "aoSAhtO5rbWdOArH04KGcwAAAW4"] [Tue Aug 18 12:55:50.304968 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:24609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/colors.php"] [unique_id "aoSAhvcmepr5_nHgLbNK4wAAAok"] [Tue Aug 18 12:55:50.319202 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.61.152:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ai.php"] [unique_id "aoSAhtO5rbWdOArH04KGdAAAAWY"] [Tue Aug 18 12:55:50.336879 2026] [security2:error] [pid 67073:tid 67228] [client 20.42.19.40:1365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/goods.php"] [unique_id "aoSAhvcmepr5_nHgLbNK5QAAAis"] [Tue Aug 18 12:55:50.339954 2026] [security2:error] [pid 66623:tid 66799] [client 20.251.48.93:14462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/wpxml.php"] [unique_id "aoSAhtO5rbWdOArH04KGdQAAASs"] [Tue Aug 18 12:55:50.343023 2026] [security2:error] [pid 66623:tid 66814] [client 52.238.210.254:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAhtO5rbWdOArH04KGdgAAATo"] [Tue Aug 18 12:55:50.391571 2026] [security2:error] [pid 66623:tid 66833] [client 52.139.47.57:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAhtO5rbWdOArH04KGeAAAAU0"] [Tue Aug 18 12:55:50.397914 2026] [security2:error] [pid 67073:tid 67205] [client 114.5.214.109:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7QAAAhQ"] [Tue Aug 18 12:55:50.398043 2026] [security2:error] [pid 67073:tid 67205] [client 114.5.214.109:49807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7QAAAhQ"] [Tue Aug 18 12:55:50.402293 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:40569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/Mailgun.php"] [unique_id "aoSAhvcmepr5_nHgLbNK7wAAAng"] [Tue Aug 18 12:55:50.421474 2026] [security2:error] [pid 67073:tid 67184] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ot.php"] [unique_id "aoSAhvcmepr5_nHgLbNK8AACF2w"] [Tue Aug 18 12:55:50.449984 2026] [security2:error] [pid 67073:tid 67253] [client 4.223.164.152:28481] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-includes/assets/"] [unique_id "aoSAhvcmepr5_nHgLbNK8gAAAkQ"] [Tue Aug 18 12:55:50.471528 2026] [security2:error] [pid 66623:tid 66801] [client 213.35.127.232:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAhtO5rbWdOArH04KGeQAAAS0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:50.475533 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:50.475786 2026] [authz_core:error] [pid 67073:tid 67170] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:50.511169 2026] [security2:error] [pid 67073:tid 67291] [client 68.221.73.131:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/admin.php"] [unique_id "aoSAhvcmepr5_nHgLbNK9gAAAmo"] [Tue Aug 18 12:55:50.512074 2026] [security2:error] [pid 67073:tid 67272] [client 20.48.236.86:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/gdn.php"] [unique_id "aoSAhvcmepr5_nHgLbNK9wAAAlc"] [Tue Aug 18 12:55:50.523774 2026] [security2:error] [pid 67073:tid 67302] [client 20.151.109.219:12919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jl.php"] [unique_id "aoSAhvcmepr5_nHgLbNK-AAAAnU"] [Tue Aug 18 12:55:50.577045 2026] [security2:error] [pid 66623:tid 66865] [client 20.42.19.40:9699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/hplfuns.php"] [unique_id "aoSAhtO5rbWdOArH04KGegAAAW0"] [Tue Aug 18 12:55:50.608275 2026] [security2:error] [pid 67073:tid 67173] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSAhvcmepr5_nHgLbNK-wACFWE"] [Tue Aug 18 12:55:50.609954 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/o.php"] [unique_id "aoSAhvcmepr5_nHgLbNK_AAAAjk"] [Tue Aug 18 12:55:50.650996 2026] [security2:error] [pid 67073:tid 67090] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ih.php"] [unique_id "aoSAhvcmepr5_nHgLbNK_gACkg4"] [Tue Aug 18 12:55:50.658203 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:17861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAhvcmepr5_nHgLbNLAAAAAjE"] [Tue Aug 18 12:55:50.689734 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:29457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/evil.php"] [unique_id "aoSAhtO5rbWdOArH04KGewAAAVE"] [Tue Aug 18 12:55:50.740353 2026] [security2:error] [pid 66623:tid 66790] [client 20.226.56.190:47113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dg.php"] [unique_id "aoSAhtO5rbWdOArH04KGfQAAASI"] [Tue Aug 18 12:55:50.758231 2026] [security2:error] [pid 67073:tid 67241] [client 20.163.43.14:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/index/function.php"] [unique_id "aoSAhvcmepr5_nHgLbNLCQAAAjg"] [Tue Aug 18 12:55:50.761529 2026] [security2:error] [pid 66623:tid 66875] [client 20.91.215.254:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/u.php"] [unique_id "aoSAhtO5rbWdOArH04KGfgAAAXc"] [Tue Aug 18 12:55:50.771252 2026] [security2:error] [pid 66623:tid 66773] [client 135.225.75.187:31581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nw.php"] [unique_id "aoSAhtO5rbWdOArH04KGfwAAARE"] [Tue Aug 18 12:55:50.775763 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:50.776024 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:50.816936 2026] [security2:error] [pid 67073:tid 67292] [client 158.158.74.177:2659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/images/index.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEgAAAms"] [Tue Aug 18 12:55:50.829599 2026] [security2:error] [pid 67073:tid 67326] [client 4.232.151.198:35335] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEwAAAo0"] [Tue Aug 18 12:55:50.829683 2026] [security2:error] [pid 67073:tid 67326] [client 4.232.151.198:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSAhvcmepr5_nHgLbNLEwAAAo0"] [Tue Aug 18 12:55:50.831692 2026] [security2:error] [pid 66623:tid 66805] [client 20.151.109.219:65018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tq.php"] [unique_id "aoSAhtO5rbWdOArH04KGgAAAATE"] [Tue Aug 18 12:55:50.860086 2026] [security2:error] [pid 67073:tid 67243] [client 20.250.13.23:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/x.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFQAAAjo"] [Tue Aug 18 12:55:50.862602 2026] [security2:error] [pid 67073:tid 67196] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/k.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFgACJXg"] [Tue Aug 18 12:55:50.870483 2026] [security2:error] [pid 67073:tid 67224] [client 20.42.19.40:9713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/htaccess.php"] [unique_id "aoSAhvcmepr5_nHgLbNLFwAAAic"] [Tue Aug 18 12:55:50.873284 2026] [security2:error] [pid 67073:tid 67300] [client 20.48.236.86:16310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/166.php"] [unique_id "aoSAhvcmepr5_nHgLbNLGAAAAnM"] [Tue Aug 18 12:55:50.881670 2026] [security2:error] [pid 66623:tid 66845] [client 52.139.47.57:18626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/aaa.php"] [unique_id "aoSAhtO5rbWdOArH04KGgQAAAVk"] [Tue Aug 18 12:55:50.890763 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:17620] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aoSAhvcmepr5_nHgLbNLGQAAAi0"] [Tue Aug 18 12:55:50.898967 2026] [security2:error] [pid 67073:tid 67212] [client 20.116.17.175:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSAhvcmepr5_nHgLbNLGwAAAhs"] [Tue Aug 18 12:55:50.901108 2026] [security2:error] [pid 66623:tid 66819] [client 196.12.128.158:63654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAhtO5rbWdOArH04KGggAAAT8"] [Tue Aug 18 12:55:50.901213 2026] [security2:error] [pid 66623:tid 66819] [client 196.12.128.158:63654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAhtO5rbWdOArH04KGggAAAT8"] [Tue Aug 18 12:55:50.939545 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/bb.php"] [unique_id "aoSAhvcmepr5_nHgLbNLHgAAAnw"] [Tue Aug 18 12:55:50.983753 2026] [security2:error] [pid 66623:tid 66870] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/scxy.php"] [unique_id "aoSAhtO5rbWdOArH04KGgwAAAXI"] [Tue Aug 18 12:55:51.007593 2026] [security2:error] [pid 67073:tid 67240] [client 47.128.96.224:40384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mrguaratoldos.com.br"] [uri "/robots.txt"] [unique_id "aoSAh_cmepr5_nHgLbNLIAAAAjc"] [Tue Aug 18 12:55:51.066104 2026] [security2:error] [pid 67073:tid 67227] [client 20.29.77.16:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/bala.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJAAAAio"] [Tue Aug 18 12:55:51.066691 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.34.183:24633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJQAAApE"] [Tue Aug 18 12:55:51.081310 2026] [security2:error] [pid 67073:tid 67247] [client 52.238.210.254:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savvy.ind.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAh_cmepr5_nHgLbNLJwAAAj4"] [Tue Aug 18 12:55:51.083522 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/edit.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKAAAAog"] [Tue Aug 18 12:55:51.095299 2026] [security2:error] [pid 67073:tid 67163] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iu.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKQACNFc"] [Tue Aug 18 12:55:51.104981 2026] [security2:error] [pid 67073:tid 67214] [client 20.215.241.237:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/mac.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKgAAAh0"] [Tue Aug 18 12:55:51.113390 2026] [security2:error] [pid 67073:tid 67265] [client 20.42.19.40:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/images/wso.php"] [unique_id "aoSAh_cmepr5_nHgLbNLKwAAAlA"] [Tue Aug 18 12:55:51.123785 2026] [security2:error] [pid 67073:tid 67156] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLLwACMFA"] [Tue Aug 18 12:55:51.160758 2026] [authz_core:error] [pid 67073:tid 67152] [remote 57.141.22.31:53966] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:51.161020 2026] [authz_core:error] [pid 67073:tid 67152] [remote 57.141.22.31:53966] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:51.166711 2026] [security2:error] [pid 66623:tid 66780] [client 20.151.109.219:53241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/cv.php"] [unique_id "aoSAh9O5rbWdOArH04KGhgAAARg"] [Tue Aug 18 12:55:51.194400 2026] [security2:error] [pid 66623:tid 66839] [client 68.221.73.131:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/bajah.php"] [unique_id "aoSAh9O5rbWdOArH04KGhwAAAVM"] [Tue Aug 18 12:55:51.244236 2026] [security2:error] [pid 67073:tid 67250] [client 20.48.236.86:16221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/file3.php"] [unique_id "aoSAh_cmepr5_nHgLbNLNwAAAkE"] [Tue Aug 18 12:55:51.258814 2026] [security2:error] [pid 67073:tid 67229] [client 52.173.121.69:16509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOAAAAiw"] [Tue Aug 18 12:55:51.274243 2026] [security2:error] [pid 67073:tid 67261] [client 74.248.130.103:15420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/admin.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOQAAAkw"] [Tue Aug 18 12:55:51.296388 2026] [security2:error] [pid 67073:tid 67201] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAh_cmepr5_nHgLbNLOgACL30"] [Tue Aug 18 12:55:51.317759 2026] [security2:error] [pid 67073:tid 67159] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pk.php"] [unique_id "aoSAh_cmepr5_nHgLbNLPQACjlM"] [Tue Aug 18 12:55:51.343613 2026] [security2:error] [pid 66623:tid 66893] [client 20.163.43.14:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAh9O5rbWdOArH04KGiAAAAYk"] [Tue Aug 18 12:55:51.346305 2026] [security2:error] [pid 66623:tid 66872] [client 4.223.164.152:28519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSAh9O5rbWdOArH04KGiQAAAXQ"] [Tue Aug 18 12:55:51.379302 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:51.379558 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:51.386186 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/index/function.php"] [unique_id "aoSAh_cmepr5_nHgLbNLQgAAAng"] [Tue Aug 18 12:55:51.412830 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/w1px.php"] [unique_id "aoSAh_cmepr5_nHgLbNLRQAAAoM"] [Tue Aug 18 12:55:51.438042 2026] [security2:error] [pid 67073:tid 67195] [remote 103.56.163.133:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSAh_cmepr5_nHgLbNLRwAChXc"] [Tue Aug 18 12:55:51.467675 2026] [security2:error] [pid 67073:tid 67085] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSAACVQk"] [Tue Aug 18 12:55:51.492370 2026] [security2:error] [pid 67073:tid 67280] [client 20.151.109.219:12912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/un.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSgAAAl8"] [Tue Aug 18 12:55:51.495588 2026] [security2:error] [pid 67073:tid 67287] [client 213.35.127.232:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAh_cmepr5_nHgLbNLSwAAAmY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:51.497122 2026] [security2:error] [pid 67073:tid 67286] [client 68.155.154.236:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTAAAAmU"] [Tue Aug 18 12:55:51.508402 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/wp-themes.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTQAAAlo"] [Tue Aug 18 12:55:51.546928 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ge.php"] [unique_id "aoSAh_cmepr5_nHgLbNLTgACFTc"] [Tue Aug 18 12:55:51.585544 2026] [security2:error] [pid 67073:tid 67324] [client 20.48.236.86:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/y.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUQAAAos"] [Tue Aug 18 12:55:51.587949 2026] [autoindex:error] [pid 67073:tid 67331] [client 44.215.89.156:48563] AH01276: Cannot serve directory /home1/activevaluecom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:51.609343 2026] [security2:error] [pid 67073:tid 67220] [client 20.163.43.14:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUgAAAiM"] [Tue Aug 18 12:55:51.615933 2026] [security2:error] [pid 67073:tid 67244] [client 20.91.215.254:20672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/customize.php"] [unique_id "aoSAh_cmepr5_nHgLbNLUwAAAjs"] [Tue Aug 18 12:55:51.630615 2026] [security2:error] [pid 67073:tid 67262] [client 20.42.19.40:9639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/info.php"] [unique_id "aoSAh_cmepr5_nHgLbNLVAAAAk0"] [Tue Aug 18 12:55:51.638250 2026] [security2:error] [pid 66623:tid 66848] [client 37.40.227.74:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh9O5rbWdOArH04KGjQAAAVw"] [Tue Aug 18 12:55:51.638410 2026] [security2:error] [pid 66623:tid 66848] [client 37.40.227.74:56582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh9O5rbWdOArH04KGjQAAAVw"] [Tue Aug 18 12:55:51.644400 2026] [security2:error] [pid 67073:tid 67319] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sd.php"] [unique_id "aoSAh_cmepr5_nHgLbNLVgAAAoY"] [Tue Aug 18 12:55:51.696079 2026] [security2:error] [pid 67073:tid 67256] [client 20.116.17.175:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ty.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWgAAAkc"] [Tue Aug 18 12:55:51.708951 2026] [security2:error] [pid 67073:tid 67243] [client 158.23.17.4:8738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-key.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWwAAAjo"] [Tue Aug 18 12:55:51.757494 2026] [security2:error] [pid 67073:tid 67268] [client 20.29.77.16:51365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/222.php"] [unique_id "aoSAh_cmepr5_nHgLbNLXQAAAlM"] [Tue Aug 18 12:55:51.767858 2026] [security2:error] [pid 67073:tid 67281] [client 88.99.80.227:10116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLWQAAAmA"], referer: https://www.meucrescer.com.br [Tue Aug 18 12:55:51.822487 2026] [security2:error] [pid 67073:tid 67328] [client 20.171.51.14:43360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ko.php"] [unique_id "aoSAh_cmepr5_nHgLbNLYAAAAo8"] [Tue Aug 18 12:55:51.843804 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.56.190:23774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bm.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZQAAAn8"] [Tue Aug 18 12:55:51.851022 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/index.bak.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZgAAAjE"] [Tue Aug 18 12:55:51.851155 2026] [security2:error] [pid 67073:tid 67161] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kl.php"] [unique_id "aoSAh_cmepr5_nHgLbNLZwACbFU"] [Tue Aug 18 12:55:51.854712 2026] [security2:error] [pid 67073:tid 67258] [client 20.151.109.219:21689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/evil.php"] [unique_id "aoSAh_cmepr5_nHgLbNLaAAAAkk"] [Tue Aug 18 12:55:51.864256 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:28531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/aaa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLagAAAiE"] [Tue Aug 18 12:55:51.869136 2026] [security2:error] [pid 67073:tid 67283] [client 158.158.34.183:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/radio.php"] [unique_id "aoSAh_cmepr5_nHgLbNLawAAAmI"] [Tue Aug 18 12:55:51.886635 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.copemsa.com.br"] [uri "/fpwch.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbAAAAms"] [Tue Aug 18 12:55:51.888702 2026] [security2:error] [pid 67073:tid 67216] [client 20.163.43.14:4285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbQAAAh8"] [Tue Aug 18 12:55:51.900943 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.130.103:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inputs.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbgAAApE"] [Tue Aug 18 12:55:51.922033 2026] [security2:error] [pid 67073:tid 67291] [client 4.232.151.198:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/alfa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLbwAAAmo"] [Tue Aug 18 12:55:51.930932 2026] [security2:error] [pid 67073:tid 67214] [client 20.104.85.180:43562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/aa.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcAAAAh0"] [Tue Aug 18 12:55:51.946465 2026] [security2:error] [pid 67073:tid 67233] [client 20.42.19.40:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/profile.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcgAAAjA"] [Tue Aug 18 12:55:51.968818 2026] [security2:error] [pid 67073:tid 67235] [client 197.184.64.235:41927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcwAAAjI"] [Tue Aug 18 12:55:51.968899 2026] [security2:error] [pid 67073:tid 67235] [client 197.184.64.235:41927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAh_cmepr5_nHgLbNLcwAAAjI"] [Tue Aug 18 12:55:51.977325 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:51.977563 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:51.986175 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:9830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws62.php"] [unique_id "aoSAh_cmepr5_nHgLbNLdQAAAoA"] [Tue Aug 18 12:55:51.991536 2026] [security2:error] [pid 66623:tid 66853] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sf.php"] [unique_id "aoSAh9O5rbWdOArH04KGjwAAAWE"] [Tue Aug 18 12:55:52.013057 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-good.php"] [unique_id "aoSAiPcmepr5_nHgLbNLdwAAAjU"] [Tue Aug 18 12:55:52.014568 2026] [security2:error] [pid 67073:tid 67314] [client 20.48.236.86:16237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modric8QWQCC.php"] [unique_id "aoSAiPcmepr5_nHgLbNLeAAAAoE"] [Tue Aug 18 12:55:52.055151 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gs.php"] [unique_id "aoSAiPcmepr5_nHgLbNLegACNig"] [Tue Aug 18 12:55:52.128150 2026] [security2:error] [pid 67073:tid 67267] [client 20.100.169.31:2443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lojaodasbaterias.aju.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfAAAAlI"] [Tue Aug 18 12:55:52.142519 2026] [security2:error] [pid 67073:tid 67253] [client 20.116.17.175:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfgAAAkQ"] [Tue Aug 18 12:55:52.153768 2026] [security2:error] [pid 67073:tid 67145] [remote 50.87.182.201:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.182.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSAiPcmepr5_nHgLbNLfwACX0U"] [Tue Aug 18 12:55:52.155454 2026] [security2:error] [pid 67073:tid 67286] [client 172.202.39.151:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/chosen.php"] [unique_id "aoSAiPcmepr5_nHgLbNLgAAAAmU"] [Tue Aug 18 12:55:52.171792 2026] [security2:error] [pid 66623:tid 66846] [client 20.65.98.162:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ws55.php"] [unique_id "aoSAiNO5rbWdOArH04KGkAAAAVo"] [Tue Aug 18 12:55:52.177161 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/oauth.php"] [unique_id "aoSAiPcmepr5_nHgLbNLgQAAAnU"] [Tue Aug 18 12:55:52.183209 2026] [security2:error] [pid 67073:tid 67317] [client 20.42.19.40:9643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/sx.php"] [unique_id "aoSAiPcmepr5_nHgLbNLggAAAoQ"] [Tue Aug 18 12:55:52.200127 2026] [security2:error] [pid 66623:tid 66860] [client 20.151.109.219:59738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pw.php"] [unique_id "aoSAiNO5rbWdOArH04KGkQAAAWg"] [Tue Aug 18 12:55:52.210969 2026] [security2:error] [pid 67073:tid 67306] [client 20.104.85.180:18828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/0x.php"] [unique_id "aoSAiPcmepr5_nHgLbNLhAAAAnk"] [Tue Aug 18 12:55:52.252629 2026] [security2:error] [pid 66623:tid 66825] [client 20.163.43.14:4290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGkgAAAUU"] [Tue Aug 18 12:55:52.266105 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.6.191:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/file.php"] [unique_id "aoSAiNO5rbWdOArH04KGkwAAAUw"] [Tue Aug 18 12:55:52.280555 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:52.280828 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:52.291946 2026] [security2:error] [pid 66623:tid 66791] [client 4.223.164.152:17617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gecko.php"] [unique_id "aoSAiNO5rbWdOArH04KGlAAAASM"] [Tue Aug 18 12:55:52.293294 2026] [security2:error] [pid 67073:tid 67324] [client 68.221.73.131:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/ajax.php"] [unique_id "aoSAiPcmepr5_nHgLbNLhwAAAos"] [Tue Aug 18 12:55:52.307968 2026] [security2:error] [pid 67073:tid 67139] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lw.php"] [unique_id "aoSAiPcmepr5_nHgLbNLiAACOz8"] [Tue Aug 18 12:55:52.327648 2026] [security2:error] [pid 67073:tid 67162] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAiPcmepr5_nHgLbNLigACilY"] [Tue Aug 18 12:55:52.378964 2026] [security2:error] [pid 67073:tid 67222] [client 20.171.51.14:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/pl.php"] [unique_id "aoSAiPcmepr5_nHgLbNLjgAAAiU"] [Tue Aug 18 12:55:52.384194 2026] [security2:error] [pid 67073:tid 67300] [client 52.173.121.69:16493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAiPcmepr5_nHgLbNLjwAAAnM"] [Tue Aug 18 12:55:52.425153 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkQAAAhs"] [Tue Aug 18 12:55:52.428366 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.56.190:32309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vu.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkgAAAiQ"] [Tue Aug 18 12:55:52.448827 2026] [security2:error] [pid 67073:tid 67281] [client 172.182.200.96:14160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAiPcmepr5_nHgLbNLkwAAAmA"] [Tue Aug 18 12:55:52.469736 2026] [security2:error] [pid 67073:tid 67278] [client 20.48.236.86:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modric7Z7J2X.php"] [unique_id "aoSAiPcmepr5_nHgLbNLlQAAAl0"] [Tue Aug 18 12:55:52.477991 2026] [security2:error] [pid 66623:tid 66817] [client 20.226.56.190:17882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ic.php"] [unique_id "aoSAiNO5rbWdOArH04KGlgAAAT0"] [Tue Aug 18 12:55:52.504913 2026] [security2:error] [pid 67073:tid 67328] [client 20.104.85.180:43529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/zxz.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmAAAAo8"] [Tue Aug 18 12:55:52.508786 2026] [security2:error] [pid 67073:tid 67297] [client 213.35.127.232:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmQAAAnA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:52.509384 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.130.103:14401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/av.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmgAAAkg"] [Tue Aug 18 12:55:52.518123 2026] [security2:error] [pid 67073:tid 67274] [client 20.29.77.16:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/routes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLmwAAAlk"] [Tue Aug 18 12:55:52.525235 2026] [security2:error] [pid 66623:tid 66789] [client 20.151.109.219:65020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fn.php"] [unique_id "aoSAiNO5rbWdOArH04KGmAAAASE"] [Tue Aug 18 12:55:52.552014 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAiPcmepr5_nHgLbNLnQAAAls"] [Tue Aug 18 12:55:52.560338 2026] [security2:error] [pid 67073:tid 67325] [client 20.226.6.191:48824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/0x.php"] [unique_id "aoSAiPcmepr5_nHgLbNLngAAAow"] [Tue Aug 18 12:55:52.576630 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vj.php"] [unique_id "aoSAiPcmepr5_nHgLbNLoQACkyo"] [Tue Aug 18 12:55:52.580562 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:52.580825 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:52.584251 2026] [security2:error] [pid 66623:tid 66813] [client 158.23.17.4:38879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAiNO5rbWdOArH04KGmQAAATk"] [Tue Aug 18 12:55:52.611560 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/file.php"] [unique_id "aoSAiPcmepr5_nHgLbNLowAAAog"] [Tue Aug 18 12:55:52.617102 2026] [security2:error] [pid 66623:tid 66834] [client 103.120.71.157:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGmgAAAU4"] [Tue Aug 18 12:55:52.617244 2026] [security2:error] [pid 66623:tid 66834] [client 103.120.71.157:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiNO5rbWdOArH04KGmgAAAU4"] [Tue Aug 18 12:55:52.629984 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:2516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ue.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpAAAAmo"] [Tue Aug 18 12:55:52.659397 2026] [security2:error] [pid 66623:tid 66798] [client 20.42.19.40:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plantaodasbaterias.aju.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAiNO5rbWdOArH04KGmwAAASo"] [Tue Aug 18 12:55:52.691330 2026] [security2:error] [pid 67073:tid 67269] [client 20.91.215.254:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/mah/function.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpgAAAlQ"] [Tue Aug 18 12:55:52.702831 2026] [security2:error] [pid 66623:tid 66835] [client 158.158.74.177:16534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/index/function.php"] [unique_id "aoSAiNO5rbWdOArH04KGnAAAAU8"] [Tue Aug 18 12:55:52.703228 2026] [security2:error] [pid 67073:tid 67215] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/shell.php"] [unique_id "aoSAiPcmepr5_nHgLbNLpwAAAh4"] [Tue Aug 18 12:55:52.711685 2026] [security2:error] [pid 66623:tid 66861] [client 4.223.164.152:37299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/xiugai.php"] [unique_id "aoSAiNO5rbWdOArH04KGnQAAAWk"] [Tue Aug 18 12:55:52.714424 2026] [security2:error] [pid 67073:tid 67304] [client 20.163.43.14:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/tes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLqAAAAnc"] [Tue Aug 18 12:55:52.721431 2026] [security2:error] [pid 67073:tid 67235] [client 20.116.17.175:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dot.php"] [unique_id "aoSAiPcmepr5_nHgLbNLqQAAAjI"] [Tue Aug 18 12:55:52.751119 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:28820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAiNO5rbWdOArH04KGngAAATU"] [Tue Aug 18 12:55:52.802233 2026] [security2:error] [pid 67073:tid 67314] [client 20.104.85.180:7019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/www.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrAAAAoE"] [Tue Aug 18 12:55:52.805588 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mimes.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrQACLH8"] [Tue Aug 18 12:55:52.807234 2026] [security2:error] [pid 67073:tid 67322] [client 20.171.51.14:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/env.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrgAAAok"] [Tue Aug 18 12:55:52.808864 2026] [security2:error] [pid 66623:tid 66774] [client 20.251.48.93:9760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/file1221.php"] [unique_id "aoSAiNO5rbWdOArH04KGnwAAARI"] [Tue Aug 18 12:55:52.816960 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAiPcmepr5_nHgLbNLrwAAAkw"] [Tue Aug 18 12:55:52.819360 2026] [security2:error] [pid 67073:tid 67259] [client 86.120.159.145:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsAAAAko"] [Tue Aug 18 12:55:52.819524 2026] [security2:error] [pid 67073:tid 67259] [client 86.120.159.145:5975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsAAAAko"] [Tue Aug 18 12:55:52.859577 2026] [security2:error] [pid 67073:tid 67151] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAiPcmepr5_nHgLbNLsgACL0s"] [Tue Aug 18 12:55:52.872989 2026] [security2:error] [pid 67073:tid 67216] [client 158.158.34.183:32212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAiPcmepr5_nHgLbNLswAAAh8"] [Tue Aug 18 12:55:52.879618 2026] [security2:error] [pid 67073:tid 67251] [client 20.151.109.219:21657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kf.php"] [unique_id "aoSAiPcmepr5_nHgLbNLtQAAAkI"] [Tue Aug 18 12:55:52.945549 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/epinyins.php"] [unique_id "aoSAiPcmepr5_nHgLbNLtwAAAoM"] [Tue Aug 18 12:55:52.947048 2026] [security2:error] [pid 67073:tid 67207] [client 20.42.19.40:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/class-t.api.php"] [unique_id "aoSAiPcmepr5_nHgLbNLuAAAAhY"] [Tue Aug 18 12:55:52.958410 2026] [security2:error] [pid 66623:tid 66890] [client 20.48.236.86:16306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/modricXP4D68.php"] [unique_id "aoSAiNO5rbWdOArH04KGoAAAAYY"] [Tue Aug 18 12:55:53.031340 2026] [security2:error] [pid 67073:tid 67158] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAifcmepr5_nHgLbNLugACZlI"] [Tue Aug 18 12:55:53.077980 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/st.php"] [unique_id "aoSAifcmepr5_nHgLbNLvAAAAnU"] [Tue Aug 18 12:55:53.088079 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:6983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wicked.php"] [unique_id "aoSAifcmepr5_nHgLbNLvgAAAhU"] [Tue Aug 18 12:55:53.131482 2026] [security2:error] [pid 67073:tid 67220] [client 4.223.164.152:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/adminner.php"] [unique_id "aoSAifcmepr5_nHgLbNLwQAAAiM"] [Tue Aug 18 12:55:53.138203 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.6.191:39377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/zxz.php"] [unique_id "aoSAifcmepr5_nHgLbNLwwAAAj8"] [Tue Aug 18 12:55:53.142743 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/jrpga.php"] [unique_id "aoSAifcmepr5_nHgLbNLxAAAAjs"] [Tue Aug 18 12:55:53.154645 2026] [security2:error] [pid 67073:tid 67323] [client 68.221.73.131:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxhost.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAifcmepr5_nHgLbNLxgAAAoo"] [Tue Aug 18 12:55:53.181681 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:53.181991 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:53.201987 2026] [security2:error] [pid 67073:tid 67176] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAifcmepr5_nHgLbNLywACGGQ"] [Tue Aug 18 12:55:53.218580 2026] [security2:error] [pid 67073:tid 67132] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ni.php"] [unique_id "aoSAifcmepr5_nHgLbNLzQACjTg"] [Tue Aug 18 12:55:53.219772 2026] [security2:error] [pid 67073:tid 67243] [client 20.29.77.16:49277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/php5.php"] [unique_id "aoSAifcmepr5_nHgLbNLzgAAAjo"] [Tue Aug 18 12:55:53.219879 2026] [security2:error] [pid 67073:tid 67222] [client 20.163.43.14:4402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/files/index.php"] [unique_id "aoSAifcmepr5_nHgLbNLzwAAAiU"] [Tue Aug 18 12:55:53.235772 2026] [security2:error] [pid 66623:tid 66866] [client 20.151.109.219:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/su.php"] [unique_id "aoSAidO5rbWdOArH04KGpAAAAW4"] [Tue Aug 18 12:55:53.245521 2026] [security2:error] [pid 66623:tid 66858] [client 20.116.17.175:57442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/005.php"] [unique_id "aoSAidO5rbWdOArH04KGpQAAAWY"] [Tue Aug 18 12:55:53.256873 2026] [security2:error] [pid 66623:tid 66814] [client 20.48.236.86:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sitemw.com.br"] [uri "/clara.php"] [unique_id "aoSAidO5rbWdOArH04KGpgAAATo"] [Tue Aug 18 12:55:53.280572 2026] [security2:error] [pid 66623:tid 66869] [client 20.163.43.14:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAidO5rbWdOArH04KGpwAAAXE"] [Tue Aug 18 12:55:53.316150 2026] [security2:error] [pid 67073:tid 67281] [client 135.225.78.186:12992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAifcmepr5_nHgLbNL0wAAAmA"] [Tue Aug 18 12:55:53.338842 2026] [security2:error] [pid 67073:tid 67210] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/le.php"] [unique_id "aoSAifcmepr5_nHgLbNL1gAAAhk"] [Tue Aug 18 12:55:53.354273 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.130.103:36835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/classwithtostring.php"] [unique_id "aoSAifcmepr5_nHgLbNL2QAAAnA"] [Tue Aug 18 12:55:53.361335 2026] [security2:error] [pid 67073:tid 67265] [client 103.184.169.37:41767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNL2gAAAlA"] [Tue Aug 18 12:55:53.361745 2026] [security2:error] [pid 67073:tid 67265] [client 103.184.169.37:41767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNL2gAAAlA"] [Tue Aug 18 12:55:53.365516 2026] [security2:error] [pid 67073:tid 67303] [client 20.91.215.254:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/filter.php"] [unique_id "aoSAifcmepr5_nHgLbNL3AAAAnY"] [Tue Aug 18 12:55:53.366946 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/timeclock.php"] [unique_id "aoSAifcmepr5_nHgLbNL3QAAAjc"] [Tue Aug 18 12:55:53.367440 2026] [security2:error] [pid 66623:tid 66886] [client 20.104.85.180:43547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAidO5rbWdOArH04KGqQAAAYI"] [Tue Aug 18 12:55:53.376000 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.75.187:18805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/vx.php"] [unique_id "aoSAifcmepr5_nHgLbNL3wAAAn8"] [Tue Aug 18 12:55:53.398540 2026] [security2:error] [pid 67073:tid 67211] [client 20.250.13.23:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/index/function.php"] [unique_id "aoSAifcmepr5_nHgLbNL4gAAAho"] [Tue Aug 18 12:55:53.410631 2026] [security2:error] [pid 67073:tid 67319] [client 158.158.74.177:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/info.php"] [unique_id "aoSAifcmepr5_nHgLbNL6gAAAoY"] [Tue Aug 18 12:55:53.464481 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSAifcmepr5_nHgLbNL6wACKkg"] [Tue Aug 18 12:55:53.464583 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSAifcmepr5_nHgLbNL6wACKkg"] [Tue Aug 18 12:55:53.482700 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:53.482971 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:53.497213 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.6.191:39418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/www.php"] [unique_id "aoSAidO5rbWdOArH04KGqwAAASk"] [Tue Aug 18 12:55:53.523304 2026] [security2:error] [pid 67073:tid 67289] [client 213.35.127.232:49550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL7gAAAmg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:53.573860 2026] [security2:error] [pid 67073:tid 67233] [client 4.223.164.152:46170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file1221.php"] [unique_id "aoSAifcmepr5_nHgLbNL8QAAAjA"] [Tue Aug 18 12:55:53.574819 2026] [security2:error] [pid 67073:tid 67249] [client 4.232.151.198:19953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/edit.php"] [unique_id "aoSAifcmepr5_nHgLbNL8gAAAkA"] [Tue Aug 18 12:55:53.607002 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wp-key.php"] [unique_id "aoSAifcmepr5_nHgLbNL9AAAAh4"] [Tue Aug 18 12:55:53.608464 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hr.php"] [unique_id "aoSAifcmepr5_nHgLbNL9QAAAnc"] [Tue Aug 18 12:55:53.621450 2026] [security2:error] [pid 67073:tid 67235] [client 158.23.17.4:33491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/mimes.php"] [unique_id "aoSAifcmepr5_nHgLbNL-AAAAjI"] [Tue Aug 18 12:55:53.632536 2026] [autoindex:error] [pid 67073:tid 67292] [client 172.202.39.151:12704] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:53.648286 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.85.180:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL-wAAAjw"] [Tue Aug 18 12:55:53.671638 2026] [security2:error] [pid 67073:tid 67314] [client 20.163.43.14:3041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL_AAAAoE"] [Tue Aug 18 12:55:53.683702 2026] [security2:error] [pid 66623:tid 66785] [client 132.196.61.152:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/zi-936.php"] [unique_id "aoSAidO5rbWdOArH04KGrQAAAR0"] [Tue Aug 18 12:55:53.695157 2026] [security2:error] [pid 66623:tid 66889] [client 20.226.6.191:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/epinyins.php"] [unique_id "aoSAidO5rbWdOArH04KGrgAAAYU"] [Tue Aug 18 12:55:53.695622 2026] [security2:error] [pid 67073:tid 67325] [client 157.90.155.240:13666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSAifcmepr5_nHgLbNL9gAAAow"], referer: https://www.meucrescer.com.br [Tue Aug 18 12:55:53.705355 2026] [security2:error] [pid 67073:tid 67322] [client 20.29.77.16:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/Black.php"] [unique_id "aoSAifcmepr5_nHgLbNL_wAAAok"] [Tue Aug 18 12:55:53.712250 2026] [security2:error] [pid 66623:tid 66865] [client 172.202.39.151:65231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/info.php"] [unique_id "aoSAidO5rbWdOArH04KGrwAAAW0"] [Tue Aug 18 12:55:53.716143 2026] [security2:error] [pid 67073:tid 67228] [client 20.100.169.31:45604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/elp.php"] [unique_id "aoSAifcmepr5_nHgLbNMAQAAAis"] [Tue Aug 18 12:55:53.718474 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/88.php"] [unique_id "aoSAifcmepr5_nHgLbNMAgACSkE"] [Tue Aug 18 12:55:53.734003 2026] [security2:error] [pid 67073:tid 67310] [client 135.225.78.186:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAifcmepr5_nHgLbNMAwAAAn0"] [Tue Aug 18 12:55:53.740259 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:3059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lr.php"] [unique_id "aoSAifcmepr5_nHgLbNMBAAAAi8"] [Tue Aug 18 12:55:53.741038 2026] [security2:error] [pid 67073:tid 67090] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAifcmepr5_nHgLbNMBQACHw4"] [Tue Aug 18 12:55:53.788055 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:53.788511 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:53.798063 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.34.183:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAifcmepr5_nHgLbNMDAAAApE"] [Tue Aug 18 12:55:53.800914 2026] [security2:error] [pid 67073:tid 67316] [client 20.163.43.14:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMDQAAAoM"] [Tue Aug 18 12:55:53.844793 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.130.103:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMDwAAAl8"] [Tue Aug 18 12:55:53.850760 2026] [security2:error] [pid 67073:tid 67286] [client 20.116.17.175:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/v2.php"] [unique_id "aoSAifcmepr5_nHgLbNMEAAAAmU"] [Tue Aug 18 12:55:53.862514 2026] [security2:error] [pid 67073:tid 67306] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kt.php"] [unique_id "aoSAifcmepr5_nHgLbNMEQAAAnk"] [Tue Aug 18 12:55:53.915458 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hj.php"] [unique_id "aoSAifcmepr5_nHgLbNMFAACclE"] [Tue Aug 18 12:55:53.919108 2026] [security2:error] [pid 67073:tid 67170] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.powerbelt.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAifcmepr5_nHgLbNMFQACXF4"] [Tue Aug 18 12:55:53.933703 2026] [security2:error] [pid 67073:tid 67244] [client 20.104.85.180:18840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cah.php"] [unique_id "aoSAifcmepr5_nHgLbNMFgAAAjs"] [Tue Aug 18 12:55:53.940420 2026] [security2:error] [pid 67073:tid 67323] [client 20.151.109.219:59751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gg.php"] [unique_id "aoSAifcmepr5_nHgLbNMFwAAAoo"] [Tue Aug 18 12:55:53.946688 2026] [security2:error] [pid 67073:tid 67262] [client 172.182.200.96:14101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAifcmepr5_nHgLbNMGAAAAk0"] [Tue Aug 18 12:55:53.960987 2026] [security2:error] [pid 67073:tid 67256] [client 20.215.241.237:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/ops.php"] [unique_id "aoSAifcmepr5_nHgLbNMGgAAAkc"] [Tue Aug 18 12:55:53.983903 2026] [security2:error] [pid 67073:tid 67326] [client 52.173.121.69:24997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAifcmepr5_nHgLbNMHQAAAo0"] [Tue Aug 18 12:55:53.989480 2026] [security2:error] [pid 67073:tid 67222] [client 172.202.39.151:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSAifcmepr5_nHgLbNMHgAAAiU"] [Tue Aug 18 12:55:54.001520 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.56.190:28281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ka.php"] [unique_id "aoSAivcmepr5_nHgLbNMHwAAAnM"] [Tue Aug 18 12:55:54.007276 2026] [security2:error] [pid 67073:tid 67318] [client 20.91.215.254:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/input.php"] [unique_id "aoSAivcmepr5_nHgLbNMIAAAAoU"] [Tue Aug 18 12:55:54.086396 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:54.086670 2026] [authz_core:error] [pid 67073:tid 67180] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:54.090114 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inx.php"] [unique_id "aoSAivcmepr5_nHgLbNMIwAAAmA"] [Tue Aug 18 12:55:54.121500 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:43351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mz.php"] [unique_id "aoSAivcmepr5_nHgLbNMJAAAAhk"] [Tue Aug 18 12:55:54.125133 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ww.php"] [unique_id "aoSAitO5rbWdOArH04KGsgAAAXA"] [Tue Aug 18 12:55:54.131247 2026] [security2:error] [pid 67073:tid 67324] [client 158.158.74.177:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/inputs.php"] [unique_id "aoSAivcmepr5_nHgLbNMJgAAAos"] [Tue Aug 18 12:55:54.132257 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ot.php"] [unique_id "aoSAivcmepr5_nHgLbNMJwAAAnA"] [Tue Aug 18 12:55:54.134974 2026] [security2:error] [pid 67073:tid 67303] [client 20.163.43.14:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAivcmepr5_nHgLbNMKAAAAnY"] [Tue Aug 18 12:55:54.156369 2026] [security2:error] [pid 67073:tid 67295] [client 135.225.78.186:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/media.php"] [unique_id "aoSAivcmepr5_nHgLbNMKgAAAm4"] [Tue Aug 18 12:55:54.163613 2026] [security2:error] [pid 67073:tid 67121] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ij.php"] [unique_id "aoSAivcmepr5_nHgLbNMKwACMS0"] [Tue Aug 18 12:55:54.194542 2026] [security2:error] [pid 67073:tid 67283] [client 20.65.69.59:3723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/email.php"] [unique_id "aoSAivcmepr5_nHgLbNMNQAAAmI"] [Tue Aug 18 12:55:54.227320 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAivcmepr5_nHgLbNMNwAAApM"] [Tue Aug 18 12:55:54.229820 2026] [security2:error] [pid 67073:tid 67275] [client 138.36.100.162:42989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMOAAAAlo"] [Tue Aug 18 12:55:54.229901 2026] [security2:error] [pid 67073:tid 67275] [client 138.36.100.162:42989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMOAAAAlo"] [Tue Aug 18 12:55:54.252935 2026] [security2:error] [pid 67073:tid 67219] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sid3.php"] [unique_id "aoSAivcmepr5_nHgLbNMOgAAAiI"] [Tue Aug 18 12:55:54.342166 2026] [security2:error] [pid 67073:tid 67249] [client 158.23.17.4:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAivcmepr5_nHgLbNMQQAAAkA"] [Tue Aug 18 12:55:54.367301 2026] [security2:error] [pid 67073:tid 67304] [client 20.116.17.175:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wkl.php"] [unique_id "aoSAivcmepr5_nHgLbNMQgAAAnc"] [Tue Aug 18 12:55:54.379469 2026] [security2:error] [pid 67073:tid 67108] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ud.php"] [unique_id "aoSAivcmepr5_nHgLbNMRAACMiA"] [Tue Aug 18 12:55:54.382573 2026] [security2:error] [pid 67073:tid 67292] [client 20.151.109.219:21664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gi.php"] [unique_id "aoSAivcmepr5_nHgLbNMRQAAAms"] [Tue Aug 18 12:55:54.388901 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mo.php"] [unique_id "aoSAivcmepr5_nHgLbNMRgAAApA"] [Tue Aug 18 12:55:54.390415 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:54.390833 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:54.454548 2026] [security2:error] [pid 67073:tid 67322] [client 20.251.48.93:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/nox.php"] [unique_id "aoSAivcmepr5_nHgLbNMSgAAAok"] [Tue Aug 18 12:55:54.463148 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.6.191:64074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wicked.php"] [unique_id "aoSAivcmepr5_nHgLbNMSwAAAkw"] [Tue Aug 18 12:55:54.480951 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:40226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/elp.php"] [unique_id "aoSAitO5rbWdOArH04KGtQAAAVk"] [Tue Aug 18 12:55:54.533291 2026] [security2:error] [pid 67073:tid 67302] [client 5.31.227.224:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMUgAAAnU"] [Tue Aug 18 12:55:54.536240 2026] [security2:error] [pid 67073:tid 67293] [client 213.35.127.232:49776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAivcmepr5_nHgLbNMUwAAAmw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:54.542974 2026] [security2:error] [pid 67073:tid 67302] [client 5.31.227.224:7854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAivcmepr5_nHgLbNMUgAAAnU"] [Tue Aug 18 12:55:54.543685 2026] [security2:error] [pid 66623:tid 66794] [client 4.223.164.152:28528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/reviall.php"] [unique_id "aoSAitO5rbWdOArH04KGtgAAASY"] [Tue Aug 18 12:55:54.553188 2026] [security2:error] [pid 67073:tid 67225] [client 213.202.253.4:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAivcmepr5_nHgLbNMVAAAAig"], referer: www.google.com [Tue Aug 18 12:55:54.565056 2026] [security2:error] [pid 66623:tid 66829] [client 20.163.43.14:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp.php"] [unique_id "aoSAitO5rbWdOArH04KGtwAAAUk"] [Tue Aug 18 12:55:54.574067 2026] [security2:error] [pid 67073:tid 67205] [client 135.225.78.186:12996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAivcmepr5_nHgLbNMVwAAAhQ"] [Tue Aug 18 12:55:54.592871 2026] [security2:error] [pid 67073:tid 67144] [remote 192.250.229.214:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gustavofrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSAivcmepr5_nHgLbNMWQACXUQ"] [Tue Aug 18 12:55:54.615123 2026] [security2:error] [pid 67073:tid 67236] [client 74.248.130.103:14415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-blog.php"] [unique_id "aoSAivcmepr5_nHgLbNMWwAAAjM"] [Tue Aug 18 12:55:54.646810 2026] [security2:error] [pid 67073:tid 67316] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qr.php"] [unique_id "aoSAivcmepr5_nHgLbNMXAAAAoM"] [Tue Aug 18 12:55:54.653119 2026] [security2:error] [pid 66623:tid 66776] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSAitO5rbWdOArH04KGuAAAARQ"] [Tue Aug 18 12:55:54.663032 2026] [security2:error] [pid 67073:tid 67231] [client 135.225.75.187:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/loxi-o.php"] [unique_id "aoSAivcmepr5_nHgLbNMXgAAAi4"] [Tue Aug 18 12:55:54.667439 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAivcmepr5_nHgLbNMXwAAAlI"] [Tue Aug 18 12:55:54.707899 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ip.php"] [unique_id "aoSAivcmepr5_nHgLbNMYQACZR8"] [Tue Aug 18 12:55:54.712324 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pz.php"] [unique_id "aoSAivcmepr5_nHgLbNMYgAAAoQ"] [Tue Aug 18 12:55:54.735789 2026] [security2:error] [pid 66623:tid 66816] [client 20.250.13.23:25692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/aaa.php"] [unique_id "aoSAitO5rbWdOArH04KGuwAAATw"] [Tue Aug 18 12:55:54.762680 2026] [security2:error] [pid 67073:tid 67327] [client 20.91.215.254:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/jquery.php"] [unique_id "aoSAivcmepr5_nHgLbNMZAAAAo4"] [Tue Aug 18 12:55:54.784468 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:55768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAitO5rbWdOArH04KGvAAAAS4"] [Tue Aug 18 12:55:54.794619 2026] [security2:error] [pid 66623:tid 66893] [client 20.65.69.59:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/profile.php"] [unique_id "aoSAitO5rbWdOArH04KGvQAAAYk"] [Tue Aug 18 12:55:54.810324 2026] [security2:error] [pid 67073:tid 67299] [client 20.171.51.14:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ft.php"] [unique_id "aoSAivcmepr5_nHgLbNMZgAAAnI"] [Tue Aug 18 12:55:54.894142 2026] [security2:error] [pid 67073:tid 67326] [client 20.163.43.14:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/function/function.php"] [unique_id "aoSAivcmepr5_nHgLbNMagAAAo0"] [Tue Aug 18 12:55:54.894361 2026] [security2:error] [pid 67073:tid 67243] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dirs.php"] [unique_id "aoSAivcmepr5_nHgLbNMawAAAjo"] [Tue Aug 18 12:55:54.924684 2026] [security2:error] [pid 66623:tid 66885] [client 158.23.17.4:33524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/pqr.php"] [unique_id "aoSAitO5rbWdOArH04KGvwAAAYE"] [Tue Aug 18 12:55:54.988752 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:54.989058 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:54.991010 2026] [security2:error] [pid 67073:tid 67300] [client 135.225.78.186:13006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/mac.php"] [unique_id "aoSAivcmepr5_nHgLbNMbgAAAnM"] [Tue Aug 18 12:55:54.992808 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/99.php"] [unique_id "aoSAivcmepr5_nHgLbNMbwACYSY"] [Tue Aug 18 12:55:55.006941 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcQAAAjY"] [Tue Aug 18 12:55:55.025860 2026] [security2:error] [pid 67073:tid 67268] [client 4.223.164.152:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/11.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcgAAAlM"] [Tue Aug 18 12:55:55.026393 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:21674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kk.php"] [unique_id "aoSAi_cmepr5_nHgLbNMcwAAAik"] [Tue Aug 18 12:55:55.036755 2026] [security2:error] [pid 66623:tid 66848] [client 20.42.19.40:2926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/edit.php"] [unique_id "aoSAi9O5rbWdOArH04KGwQAAAVw"] [Tue Aug 18 12:55:55.108193 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.154.236:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAi9O5rbWdOArH04KGwgAAAQw"] [Tue Aug 18 12:55:55.111073 2026] [security2:error] [pid 67073:tid 67296] [client 158.158.74.177:2677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/install.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdQAAAm8"] [Tue Aug 18 12:55:55.116374 2026] [security2:error] [pid 66623:tid 66830] [client 172.202.39.151:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/cache.php"] [unique_id "aoSAi9O5rbWdOArH04KGwwAAAUo"] [Tue Aug 18 12:55:55.136490 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:32311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAi9O5rbWdOArH04KGxAAAAWE"] [Tue Aug 18 12:55:55.142111 2026] [security2:error] [pid 66623:tid 66777] [client 20.226.56.190:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ih.php"] [unique_id "aoSAi9O5rbWdOArH04KGxgAAARU"] [Tue Aug 18 12:55:55.142946 2026] [security2:error] [pid 67073:tid 67257] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sn.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdgAAAkg"] [Tue Aug 18 12:55:55.143098 2026] [security2:error] [pid 67073:tid 67324] [client 20.163.43.14:4409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/rip.php"] [unique_id "aoSAi_cmepr5_nHgLbNMdwAAAos"] [Tue Aug 18 12:55:55.168914 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSAi_cmepr5_nHgLbNMeQAAAnY"] [Tue Aug 18 12:55:55.199686 2026] [security2:error] [pid 66623:tid 66860] [client 20.29.77.16:56379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/filesystems.php"] [unique_id "aoSAi9O5rbWdOArH04KGxwAAAWg"] [Tue Aug 18 12:55:55.230435 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:22552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/u.php"] [unique_id "aoSAi9O5rbWdOArH04KGyAAAASM"] [Tue Aug 18 12:55:55.233517 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAi_cmepr5_nHgLbNMewAAAkM"] [Tue Aug 18 12:55:55.247797 2026] [security2:error] [pid 66623:tid 66793] [client 20.65.98.162:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/m.php"] [unique_id "aoSAi9O5rbWdOArH04KGyQAAASU"] [Tue Aug 18 12:55:55.250784 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAi_cmepr5_nHgLbNMfgAAApM"] [Tue Aug 18 12:55:55.270638 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/er.php"] [unique_id "aoSAi_cmepr5_nHgLbNMfwACV1k"] [Tue Aug 18 12:55:55.289178 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:55.289493 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:55.297717 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/weozh.php"] [unique_id "aoSAi_cmepr5_nHgLbNMgQAAAj4"] [Tue Aug 18 12:55:55.317577 2026] [security2:error] [pid 67073:tid 67274] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/rymmm.php"] [unique_id "aoSAi_cmepr5_nHgLbNMggAAAlk"] [Tue Aug 18 12:55:55.325199 2026] [security2:error] [pid 67073:tid 67258] [client 20.151.109.219:53207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAi_cmepr5_nHgLbNMgwAAAkk"] [Tue Aug 18 12:55:55.358943 2026] [security2:error] [pid 67073:tid 67285] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sitemap.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhQAAAmQ"] [Tue Aug 18 12:55:55.391796 2026] [security2:error] [pid 66623:tid 66789] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/43.php"] [unique_id "aoSAi9O5rbWdOArH04KGygAAASE"] [Tue Aug 18 12:55:55.393360 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/lddxs.php"] [unique_id "aoSAi9O5rbWdOArH04KGywAAATk"] [Tue Aug 18 12:55:55.407528 2026] [security2:error] [pid 66623:tid 66834] [client 135.225.78.186:13256] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAi9O5rbWdOArH04KGzAAAAU4"] [Tue Aug 18 12:55:55.407629 2026] [security2:error] [pid 66623:tid 66834] [client 135.225.78.186:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1.php"] [unique_id "aoSAi9O5rbWdOArH04KGzAAAAU4"] [Tue Aug 18 12:55:55.412702 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zjggu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhgAAAkA"] [Tue Aug 18 12:55:55.415085 2026] [security2:error] [pid 67073:tid 67223] [client 20.171.51.14:45431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/h.php"] [unique_id "aoSAi_cmepr5_nHgLbNMhwAAAiY"] [Tue Aug 18 12:55:55.435444 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAi_cmepr5_nHgLbNMiwAAAoI"] [Tue Aug 18 12:55:55.438788 2026] [security2:error] [pid 67073:tid 67312] [client 5.253.205.188:50610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/lib.model.schema.bak"] [unique_id "aoSAi_cmepr5_nHgLbNMjAAAAn8"], referer: https://medihub.com.br/lib.model.schema.bak [Tue Aug 18 12:55:55.449772 2026] [security2:error] [pid 67073:tid 67292] [client 4.223.164.152:28489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/File.php"] [unique_id "aoSAi_cmepr5_nHgLbNMjQAAAms"] [Tue Aug 18 12:55:55.457920 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.18.37:29256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/w.php"] [unique_id "aoSAi9O5rbWdOArH04KGzQAAASs"] [Tue Aug 18 12:55:55.468827 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:39161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAi9O5rbWdOArH04KGzgAAARs"] [Tue Aug 18 12:55:55.479977 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.56.190:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/k.php"] [unique_id "aoSAi_cmepr5_nHgLbNMjgAAApA"] [Tue Aug 18 12:55:55.512092 2026] [security2:error] [pid 67073:tid 67164] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qk.php"] [unique_id "aoSAi_cmepr5_nHgLbNMkQACPFg"] [Tue Aug 18 12:55:55.580505 2026] [security2:error] [pid 66623:tid 66832] [client 213.35.127.232:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAi9O5rbWdOArH04KG0AAAAUw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:55.595541 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:55.595806 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:55.597023 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAi_cmepr5_nHgLbNMkwAAAko"] [Tue Aug 18 12:55:55.603031 2026] [security2:error] [pid 66623:tid 66881] [client 20.65.98.162:50119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/xyn.php"] [unique_id "aoSAi9O5rbWdOArH04KG0QAAAX0"] [Tue Aug 18 12:55:55.627059 2026] [security2:error] [pid 66623:tid 66779] [client 20.151.109.219:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dg.php"] [unique_id "aoSAi9O5rbWdOArH04KG0gAAARc"] [Tue Aug 18 12:55:55.631831 2026] [security2:error] [pid 67073:tid 67323] [client 157.20.138.62:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlQAAAoo"] [Tue Aug 18 12:55:55.631956 2026] [security2:error] [pid 67073:tid 67323] [client 157.20.138.62:59224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlQAAAoo"] [Tue Aug 18 12:55:55.649115 2026] [security2:error] [pid 66623:tid 66888] [client 20.163.43.14:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAi9O5rbWdOArH04KG1AAAAYQ"] [Tue Aug 18 12:55:55.649600 2026] [security2:error] [pid 67073:tid 67232] [client 74.248.130.103:14439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/adminfuns.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlgAAAi8"] [Tue Aug 18 12:55:55.653408 2026] [security2:error] [pid 66623:tid 66890] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fresh.php"] [unique_id "aoSAi9O5rbWdOArH04KG1QAAAYY"] [Tue Aug 18 12:55:55.659487 2026] [security2:error] [pid 67073:tid 67255] [client 20.91.215.254:20718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/media-new.php"] [unique_id "aoSAi_cmepr5_nHgLbNMlwAAAkY"] [Tue Aug 18 12:55:55.659959 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/kopyw.php"] [unique_id "aoSAi9O5rbWdOArH04KG1gAAAS8"] [Tue Aug 18 12:55:55.663486 2026] [security2:error] [pid 67073:tid 67251] [client 20.163.43.14:4380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmAAAAkI"] [Tue Aug 18 12:55:55.726544 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:38211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cah.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmgAAAmw"] [Tue Aug 18 12:55:55.736086 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zznmg.php"] [unique_id "aoSAi_cmepr5_nHgLbNMmwAAAnU"] [Tue Aug 18 12:55:55.752254 2026] [security2:error] [pid 67073:tid 67134] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAi_cmepr5_nHgLbNMnQACFDo"] [Tue Aug 18 12:55:55.777456 2026] [security2:error] [pid 66623:tid 66869] [client 20.116.17.175:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/az.php"] [unique_id "aoSAi9O5rbWdOArH04KG2wAAAXE"] [Tue Aug 18 12:55:55.783280 2026] [security2:error] [pid 67073:tid 67305] [client 20.42.19.40:2915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ff1.php"] [unique_id "aoSAi_cmepr5_nHgLbNMngAAAng"] [Tue Aug 18 12:55:55.790118 2026] [security2:error] [pid 66623:tid 66821] [client 135.225.75.187:58360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sdsa.php"] [unique_id "aoSAi9O5rbWdOArH04KG3AAAAUE"] [Tue Aug 18 12:55:55.792644 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.69.59:39211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/summary.php"] [unique_id "aoSAi9O5rbWdOArH04KG3QAAAVc"] [Tue Aug 18 12:55:55.829932 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.78.186:13016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/coffee.php"] [unique_id "aoSAi_cmepr5_nHgLbNMoAAAAlY"] [Tue Aug 18 12:55:55.832144 2026] [security2:error] [pid 67073:tid 67330] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAi_cmepr5_nHgLbNMoQAAApE"] [Tue Aug 18 12:55:55.874966 2026] [security2:error] [pid 66623:tid 66882] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAi9O5rbWdOArH04KG1wABfnY"] [Tue Aug 18 12:55:55.892239 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.56.190:2530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpAAAAkE"] [Tue Aug 18 12:55:55.903376 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fi22.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpQAAAk8"] [Tue Aug 18 12:55:55.907820 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gj.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpgAAAiA"] [Tue Aug 18 12:55:55.914060 2026] [security2:error] [pid 67073:tid 67211] [client 4.232.151.198:22555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/as.php"] [unique_id "aoSAi_cmepr5_nHgLbNMpwAAAho"] [Tue Aug 18 12:55:55.932749 2026] [security2:error] [pid 66623:tid 66810] [client 158.158.74.177:2683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAi9O5rbWdOArH04KG4AAAATY"] [Tue Aug 18 12:55:55.940431 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bm.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqAAAAo4"] [Tue Aug 18 12:55:55.941412 2026] [security2:error] [pid 67073:tid 67242] [client 158.23.17.4:9284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqQAAAjk"] [Tue Aug 18 12:55:55.964543 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAi_cmepr5_nHgLbNMqgAAAjc"] [Tue Aug 18 12:55:55.985560 2026] [security2:error] [pid 66623:tid 66889] [client 20.163.43.14:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/ok.php"] [unique_id "aoSAi9O5rbWdOArH04KG4QAAAYU"] [Tue Aug 18 12:55:55.994705 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.154.236:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/nwwha.php"] [unique_id "aoSAi_cmepr5_nHgLbNMrAAAAoY"] [Tue Aug 18 12:55:55.995142 2026] [security2:error] [pid 67073:tid 67136] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fs.php"] [unique_id "aoSAi_cmepr5_nHgLbNMrQACPzw"] [Tue Aug 18 12:55:56.012957 2026] [security2:error] [pid 66623:tid 66880] [client 20.163.43.14:3028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/moon.php"] [unique_id "aoSAjNO5rbWdOArH04KG4wAAAXw"] [Tue Aug 18 12:55:56.013335 2026] [security2:error] [pid 66623:tid 66828] [client 20.251.48.93:57259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/akismet.php"] [unique_id "aoSAjNO5rbWdOArH04KG5AAAAUg"] [Tue Aug 18 12:55:56.030559 2026] [autoindex:error] [pid 66623:tid 66857] [client 20.226.6.191:64121] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:56.036107 2026] [security2:error] [pid 66623:tid 66879] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/size.php"] [unique_id "aoSAjNO5rbWdOArH04KG5gAAAXs"] [Tue Aug 18 12:55:56.040612 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.6.191:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/system_log.php"] [unique_id "aoSAjNO5rbWdOArH04KG5wAAAVI"] [Tue Aug 18 12:55:56.110461 2026] [security2:error] [pid 67073:tid 67326] [client 20.171.51.14:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/40.php"] [unique_id "aoSAjPcmepr5_nHgLbNMsAAAAo0"] [Tue Aug 18 12:55:56.118037 2026] [security2:error] [pid 66623:tid 66833] [client 74.7.175.153:35792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.contabilidadecapimgrosso.com.br.foxalpha.com.br"] [uri "/robots.txt"] [unique_id "aoSAjNO5rbWdOArH04KG6AABTXc"] [Tue Aug 18 12:55:56.128164 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/oivcl.php"] [unique_id "aoSAjNO5rbWdOArH04KG6QAAAWQ"] [Tue Aug 18 12:55:56.163278 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pd.php"] [unique_id "aoSAjPcmepr5_nHgLbNMsgAAAjU"] [Tue Aug 18 12:55:56.167577 2026] [security2:error] [pid 67073:tid 67301] [client 149.34.210.141:51128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjPcmepr5_nHgLbNMswAAAnQ"] [Tue Aug 18 12:55:56.201257 2026] [security2:error] [pid 67073:tid 67282] [client 20.29.77.16:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSAjPcmepr5_nHgLbNMtgAAAmE"] [Tue Aug 18 12:55:56.210476 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:28983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/an.php"] [unique_id "aoSAjPcmepr5_nHgLbNMuQAAAi0"] [Tue Aug 18 12:55:56.224403 2026] [autoindex:error] [pid 67073:tid 67263] [client 172.202.39.151:50218] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:56.234290 2026] [security2:error] [pid 67073:tid 67221] [client 20.42.19.40:2894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/fff.php"] [unique_id "aoSAjPcmepr5_nHgLbNMuwAAAiQ"] [Tue Aug 18 12:55:56.245801 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:16483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/rezor.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvQAAAlM"] [Tue Aug 18 12:55:56.246542 2026] [security2:error] [pid 67073:tid 67226] [client 135.225.78.186:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/classwithtostring.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvgAAAik"] [Tue Aug 18 12:55:56.249138 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zugvi.php"] [unique_id "aoSAjPcmepr5_nHgLbNMvwAAAks"] [Tue Aug 18 12:55:56.301887 2026] [security2:error] [pid 67073:tid 67088] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rb.php"] [unique_id "aoSAjPcmepr5_nHgLbNMwAACbww"] [Tue Aug 18 12:55:56.312469 2026] [security2:error] [pid 67073:tid 67328] [client 74.248.130.103:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/ms-edit.php"] [unique_id "aoSAjPcmepr5_nHgLbNMwgAAAo8"] [Tue Aug 18 12:55:56.323546 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vu.php"] [unique_id "aoSAjNO5rbWdOArH04KG6wAAAXM"] [Tue Aug 18 12:55:56.325916 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wsrer.php"] [unique_id "aoSAjNO5rbWdOArH04KG7AAAAXA"] [Tue Aug 18 12:55:56.328906 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.56.190:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pk.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxAAAAkg"] [Tue Aug 18 12:55:56.341442 2026] [security2:error] [pid 67073:tid 67270] [client 4.232.151.198:19934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/666.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxgAAAlU"] [Tue Aug 18 12:55:56.355105 2026] [security2:error] [pid 67073:tid 67295] [client 4.223.164.152:37283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAjPcmepr5_nHgLbNMxwAAAm4"] [Tue Aug 18 12:55:56.372056 2026] [security2:error] [pid 66623:tid 66836] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sm.php"] [unique_id "aoSAjNO5rbWdOArH04KG7QAAAVA"] [Tue Aug 18 12:55:56.396614 2026] [security2:error] [pid 66623:tid 66788] [client 20.163.43.14:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cache.php"] [unique_id "aoSAjNO5rbWdOArH04KG7gAAASA"] [Tue Aug 18 12:55:56.411838 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/th.php"] [unique_id "aoSAjNO5rbWdOArH04KG7wAAAYA"] [Tue Aug 18 12:55:56.414218 2026] [security2:error] [pid 66623:tid 66766] [client 20.163.43.14:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mabelini.com.br"] [uri "/item.php"] [unique_id "aoSAjNO5rbWdOArH04KG8AAAAQo"] [Tue Aug 18 12:55:56.417914 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAjNO5rbWdOArH04KG8QAAAVk"] [Tue Aug 18 12:55:56.435100 2026] [security2:error] [pid 67073:tid 67301] [client 149.34.210.141:51128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjPcmepr5_nHgLbNMswAAAnQ"] [Tue Aug 18 12:55:56.442855 2026] [security2:error] [pid 67073:tid 67239] [client 20.91.215.254:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAjPcmepr5_nHgLbNMygAAAjY"] [Tue Aug 18 12:55:56.458260 2026] [security2:error] [pid 67073:tid 67275] [client 158.23.17.4:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/info2.php"] [unique_id "aoSAjPcmepr5_nHgLbNMywAAAlo"] [Tue Aug 18 12:55:56.467574 2026] [autoindex:error] [pid 66623:tid 66863] [client 20.226.6.191:59966] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:56.472641 2026] [security2:error] [pid 66623:tid 66847] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/yxijx.php"] [unique_id "aoSAjNO5rbWdOArH04KG9AAAAVs"] [Tue Aug 18 12:55:56.492774 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAjPcmepr5_nHgLbNMzgAAAj4"] [Tue Aug 18 12:55:56.495189 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:56.495460 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:56.503007 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAjNO5rbWdOArH04KG9QAAAS4"] [Tue Aug 18 12:55:56.521345 2026] [security2:error] [pid 67073:tid 67289] [client 172.202.39.151:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0AAAAmg"] [Tue Aug 18 12:55:56.551326 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/jrpga.php"] [unique_id "aoSAjNO5rbWdOArH04KG9wAAAUQ"] [Tue Aug 18 12:55:56.552586 2026] [security2:error] [pid 66623:tid 66859] [client 20.42.19.40:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/inputs.php"] [unique_id "aoSAjNO5rbWdOArH04KG-AAAAWc"] [Tue Aug 18 12:55:56.558894 2026] [security2:error] [pid 67073:tid 67126] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/37.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0QACNDI"] [Tue Aug 18 12:55:56.601194 2026] [security2:error] [pid 67073:tid 67266] [client 213.35.127.232:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAjPcmepr5_nHgLbNM0gAAAlE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:56.601710 2026] [security2:error] [pid 66623:tid 66830] [client 20.151.109.219:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ic.php"] [unique_id "aoSAjNO5rbWdOArH04KG-QAAAUo"] [Tue Aug 18 12:55:56.641855 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1AAAAkA"] [Tue Aug 18 12:55:56.662692 2026] [security2:error] [pid 66623:tid 66794] [client 158.158.74.177:22746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/item.php"] [unique_id "aoSAjNO5rbWdOArH04KG-wAAASY"] [Tue Aug 18 12:55:56.664024 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/nwwha.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1QAAAn8"] [Tue Aug 18 12:55:56.664112 2026] [security2:error] [pid 66623:tid 66862] [client 135.225.78.186:13033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-ws68.php"] [unique_id "aoSAjNO5rbWdOArH04KG_AAAAWo"] [Tue Aug 18 12:55:56.666425 2026] [security2:error] [pid 66623:tid 66853] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/admin404.php"] [unique_id "aoSAjNO5rbWdOArH04KG_QAAAWE"] [Tue Aug 18 12:55:56.684703 2026] [security2:error] [pid 67073:tid 67292] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/opsqt.php"] [unique_id "aoSAjPcmepr5_nHgLbNM1gAAAms"] [Tue Aug 18 12:55:56.705254 2026] [security2:error] [pid 66623:tid 66846] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAjNO5rbWdOArH04KG_wAAAVo"] [Tue Aug 18 12:55:56.727438 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAjNO5rbWdOArH04KHAQAAASc"] [Tue Aug 18 12:55:56.776414 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.154.236:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/opsqt.php"] [unique_id "aoSAjPcmepr5_nHgLbNM2wAAAis"] [Tue Aug 18 12:55:56.776415 2026] [security2:error] [pid 66623:tid 66873] [client 20.250.13.23:24819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/abcd.php"] [unique_id "aoSAjNO5rbWdOArH04KHBAAAAXU"] [Tue Aug 18 12:55:56.782942 2026] [security2:error] [pid 66623:tid 66817] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAjNO5rbWdOArH04KHBQAAAT0"] [Tue Aug 18 12:55:56.808226 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAjNO5rbWdOArH04KHBgAAASE"] [Tue Aug 18 12:55:56.817244 2026] [security2:error] [pid 67073:tid 67097] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/md.php"] [unique_id "aoSAjPcmepr5_nHgLbNM3gACShU"] [Tue Aug 18 12:55:56.830604 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.18.37:28098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/archive.php"] [unique_id "aoSAjPcmepr5_nHgLbNM3wAAAiU"] [Tue Aug 18 12:55:56.833580 2026] [security2:error] [pid 66623:tid 66822] [client 4.223.164.152:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAjNO5rbWdOArH04KHCAAAAUI"] [Tue Aug 18 12:55:56.838455 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.130.103:15404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/222.php"] [unique_id "aoSAjNO5rbWdOArH04KHCgAAASs"] [Tue Aug 18 12:55:56.841730 2026] [security2:error] [pid 67073:tid 67308] [client 52.238.210.254:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAjPcmepr5_nHgLbNM4AAAAns"] [Tue Aug 18 12:55:56.851657 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.6.191:59965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAjPcmepr5_nHgLbNM4QAAAoo"] [Tue Aug 18 12:55:56.853316 2026] [security2:error] [pid 66623:tid 66807] [client 4.232.151.198:37328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/min.php"] [unique_id "aoSAjNO5rbWdOArH04KHCwAAATM"] [Tue Aug 18 12:55:56.864362 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAjNO5rbWdOArH04KHDAAAARs"] [Tue Aug 18 12:55:56.871493 2026] [security2:error] [pid 66623:tid 66861] [client 158.158.34.183:32238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/k.php"] [unique_id "aoSAjNO5rbWdOArH04KHDQAAAWk"] [Tue Aug 18 12:55:56.910169 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5QAAAh8"] [Tue Aug 18 12:55:56.926959 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.75.187:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-freya.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5gAAAkI"] [Tue Aug 18 12:55:56.931125 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAjPcmepr5_nHgLbNM5wAAAhw"] [Tue Aug 18 12:55:56.936631 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qo.php"] [unique_id "aoSAjPcmepr5_nHgLbNM6AAAAnU"] [Tue Aug 18 12:55:56.949690 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAjPcmepr5_nHgLbNM6gAAAj0"] [Tue Aug 18 12:55:56.969472 2026] [security2:error] [pid 66623:tid 66867] [client 20.226.6.191:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/abc.php"] [unique_id "aoSAjNO5rbWdOArH04KHDgAAAW8"] [Tue Aug 18 12:55:57.012840 2026] [security2:error] [pid 66623:tid 66818] [client 20.251.48.93:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/admin.php"] [unique_id "aoSAjdO5rbWdOArH04KHEQAAAT4"] [Tue Aug 18 12:55:57.022989 2026] [security2:error] [pid 66623:tid 66874] [client 20.151.109.219:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ue.php"] [unique_id "aoSAjdO5rbWdOArH04KHEgAAAXY"] [Tue Aug 18 12:55:57.067611 2026] [security2:error] [pid 67073:tid 67138] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/iy.php"] [unique_id "aoSAjfcmepr5_nHgLbNM7gACkT4"] [Tue Aug 18 12:55:57.082841 2026] [security2:error] [pid 66623:tid 66772] [client 20.100.169.31:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAjdO5rbWdOArH04KHFAAAARA"] [Tue Aug 18 12:55:57.086074 2026] [security2:error] [pid 66623:tid 66784] [client 135.225.78.186:12998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/yj09.php"] [unique_id "aoSAjdO5rbWdOArH04KHFQAAARw"] [Tue Aug 18 12:55:57.097553 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:57.097883 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:57.103964 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ge.php"] [unique_id "aoSAjfcmepr5_nHgLbNM8gAAAkQ"] [Tue Aug 18 12:55:57.123981 2026] [security2:error] [pid 67073:tid 67250] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sql.php"] [unique_id "aoSAjfcmepr5_nHgLbNM9AAAAkE"] [Tue Aug 18 12:55:57.181901 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.6.191:6533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAjdO5rbWdOArH04KHFgAAAX4"] [Tue Aug 18 12:55:57.201181 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sd.php"] [unique_id "aoSAjdO5rbWdOArH04KHFwAAASk"] [Tue Aug 18 12:55:57.248778 2026] [security2:error] [pid 67073:tid 67217] [client 20.116.17.175:57443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/z43agz.php"] [unique_id "aoSAjfcmepr5_nHgLbNM9wAAAiA"] [Tue Aug 18 12:55:57.265116 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.6.191:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/akcc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGAAAAXk"] [Tue Aug 18 12:55:57.282764 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/og.php"] [unique_id "aoSAjfcmepr5_nHgLbNM-QACjnQ"] [Tue Aug 18 12:55:57.299809 2026] [security2:error] [pid 67073:tid 67242] [client 20.163.43.14:3025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAjfcmepr5_nHgLbNM-gAAAjk"] [Tue Aug 18 12:55:57.319687 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:21691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lr.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_QAAAj8"] [Tue Aug 18 12:55:57.319732 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_AAAAmY"] [Tue Aug 18 12:55:57.340388 2026] [security2:error] [pid 67073:tid 67244] [client 4.223.164.152:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAjfcmepr5_nHgLbNM_gAAAjs"] [Tue Aug 18 12:55:57.354951 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGgAAASM"] [Tue Aug 18 12:55:57.355076 2026] [security2:error] [pid 66623:tid 66791] [client 178.153.171.161:43832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjdO5rbWdOArH04KHGgAAASM"] [Tue Aug 18 12:55:57.425450 2026] [security2:error] [pid 67073:tid 67309] [client 172.182.200.96:7627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAjfcmepr5_nHgLbNNAQAAAnw"] [Tue Aug 18 12:55:57.445933 2026] [security2:error] [pid 67073:tid 67238] [client 20.215.241.237:24621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/coffexium.php"] [unique_id "aoSAjfcmepr5_nHgLbNNBwAAAjU"] [Tue Aug 18 12:55:57.456589 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/km.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCAAAAoU"] [Tue Aug 18 12:55:57.462773 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAjdO5rbWdOArH04KHHAAAAXs"] [Tue Aug 18 12:55:57.476501 2026] [security2:error] [pid 67073:tid 67243] [client 18.192.166.72:57044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSAjfcmepr5_nHgLbNNAgAAAjo"], referer: http://www.pinceisroma.com.br [Tue Aug 18 12:55:57.481131 2026] [security2:error] [pid 67073:tid 67268] [client 74.248.130.103:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCQAAAlM"] [Tue Aug 18 12:55:57.484836 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAjfcmepr5_nHgLbNNCgAAAik"] [Tue Aug 18 12:55:57.503460 2026] [security2:error] [pid 66623:tid 66812] [client 135.225.78.186:13023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/scxy.php"] [unique_id "aoSAjdO5rbWdOArH04KHHQAAATg"] [Tue Aug 18 12:55:57.505717 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAjdO5rbWdOArH04KHHgAAAW4"] [Tue Aug 18 12:55:57.525316 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.56.190:31669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kl.php"] [unique_id "aoSAjfcmepr5_nHgLbNNDAAAAm8"] [Tue Aug 18 12:55:57.537924 2026] [security2:error] [pid 67073:tid 67303] [client 52.173.121.69:16470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAjfcmepr5_nHgLbNNDwAAAnY"] [Tue Aug 18 12:55:57.549875 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lp.php"] [unique_id "aoSAjfcmepr5_nHgLbNNEAACbhg"] [Tue Aug 18 12:55:57.573601 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAjfcmepr5_nHgLbNNEgAAAmI"] [Tue Aug 18 12:55:57.576316 2026] [security2:error] [pid 66623:tid 66856] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/ss.php"] [unique_id "aoSAjdO5rbWdOArH04KHHwAAAWQ"] [Tue Aug 18 12:55:57.591799 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAjdO5rbWdOArH04KHIAAAAV4"] [Tue Aug 18 12:55:57.611636 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAjdO5rbWdOArH04KHIQAAAQs"] [Tue Aug 18 12:55:57.617025 2026] [security2:error] [pid 67073:tid 67265] [client 213.35.127.232:50495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFAAAAlA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:57.644511 2026] [security2:error] [pid 67073:tid 67314] [client 20.151.109.219:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ka.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFgAAAoE"] [Tue Aug 18 12:55:57.656460 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAjfcmepr5_nHgLbNNFwAAAiI"] [Tue Aug 18 12:55:57.676597 2026] [security2:error] [pid 66623:tid 66787] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAjdO5rbWdOArH04KHJQAAAR8"] [Tue Aug 18 12:55:57.703833 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:57.704085 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:57.705348 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mf.php"] [unique_id "aoSAjfcmepr5_nHgLbNNGQAAAlk"] [Tue Aug 18 12:55:57.723976 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:49011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSAjfcmepr5_nHgLbNNGwAAAk0"] [Tue Aug 18 12:55:57.742977 2026] [security2:error] [pid 67073:tid 67266] [client 158.23.17.4:10976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/test_info.php"] [unique_id "aoSAjfcmepr5_nHgLbNNHAAAAlE"] [Tue Aug 18 12:55:57.767786 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.154.236:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAjdO5rbWdOArH04KHJgAAASA"] [Tue Aug 18 12:55:57.773361 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAjdO5rbWdOArH04KHJwAAAYA"] [Tue Aug 18 12:55:57.778477 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:6538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNHwAAAlg"] [Tue Aug 18 12:55:57.784318 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ey.php"] [unique_id "aoSAjfcmepr5_nHgLbNNIAACf0k"] [Tue Aug 18 12:55:57.817746 2026] [security2:error] [pid 67073:tid 67292] [client 20.42.19.40:2907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoSAjfcmepr5_nHgLbNNIwAAAms"] [Tue Aug 18 12:55:57.824007 2026] [autoindex:error] [pid 67073:tid 67328] [client 4.232.151.198:37341] AH01276: Cannot serve directory /home4/uniaoaccom/public_html/.well-known/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:55:57.847966 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAjdO5rbWdOArH04KHKAAAARg"] [Tue Aug 18 12:55:57.869218 2026] [security2:error] [pid 67073:tid 67261] [client 20.171.51.14:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ee.php"] [unique_id "aoSAjfcmepr5_nHgLbNNJwAAAkw"] [Tue Aug 18 12:55:57.885768 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.6.191:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wk/index.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKQAAAmk"] [Tue Aug 18 12:55:57.891311 2026] [security2:error] [pid 67073:tid 67245] [client 4.223.164.152:46165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKgAAAjw"] [Tue Aug 18 12:55:57.891601 2026] [security2:error] [pid 67073:tid 67228] [client 18.192.166.72:57060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSAjfcmepr5_nHgLbNNJgAAAis"], referer: http://www.pinceisroma.com.br [Tue Aug 18 12:55:57.892158 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:2520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gs.php"] [unique_id "aoSAjfcmepr5_nHgLbNNKwAAAhs"] [Tue Aug 18 12:55:57.924461 2026] [security2:error] [pid 67073:tid 67323] [client 135.225.78.186:13009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAjfcmepr5_nHgLbNNLgAAAoo"] [Tue Aug 18 12:55:57.956512 2026] [security2:error] [pid 67073:tid 67213] [client 20.65.69.59:40574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/conf.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMAAAAhw"] [Tue Aug 18 12:55:57.968818 2026] [security2:error] [pid 67073:tid 67302] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ie.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMQAAAnU"] [Tue Aug 18 12:55:57.980447 2026] [security2:error] [pid 67073:tid 67305] [client 20.29.77.16:57056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpstatus.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMwAAAng"] [Tue Aug 18 12:55:57.986705 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lv.php"] [unique_id "aoSAjfcmepr5_nHgLbNNNAACF1E"] [Tue Aug 18 12:55:58.000824 2026] [security2:error] [pid 67073:tid 67271] [client 20.151.109.219:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ot.php"] [unique_id "aoSAjvcmepr5_nHgLbNNNwAAAlY"] [Tue Aug 18 12:55:58.000984 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:58.001277 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:58.005704 2026] [security2:error] [pid 66623:tid 66845] [client 20.91.215.254:11996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/import.php"] [unique_id "aoSAjtO5rbWdOArH04KHKwAAAVk"] [Tue Aug 18 12:55:58.015251 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAjtO5rbWdOArH04KHLAAAATc"] [Tue Aug 18 12:55:58.032881 2026] [security2:error] [pid 67073:tid 67324] [client 20.250.13.23:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-good.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOAAAAos"] [Tue Aug 18 12:55:58.051097 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOQAAAi4"] [Tue Aug 18 12:55:58.070423 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOgAAAkE"] [Tue Aug 18 12:55:58.071186 2026] [security2:error] [pid 67073:tid 67317] [client 4.232.151.198:37341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/php8.php"] [unique_id "aoSAjvcmepr5_nHgLbNNOwAAAoQ"] [Tue Aug 18 12:55:58.089986 2026] [security2:error] [pid 67073:tid 67286] [client 158.158.74.177:2674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/js.php"] [unique_id "aoSAjvcmepr5_nHgLbNNPwAAAmU"] [Tue Aug 18 12:55:58.105821 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.6.191:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQAAAAn0"] [Tue Aug 18 12:55:58.114810 2026] [security2:error] [pid 66623:tid 66859] [client 20.42.19.40:2939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/lite.php"] [unique_id "aoSAjtO5rbWdOArH04KHMAAAAWc"] [Tue Aug 18 12:55:58.125196 2026] [security2:error] [pid 67073:tid 67211] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQQAAAho"] [Tue Aug 18 12:55:58.154272 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.56.190:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lw.php"] [unique_id "aoSAjvcmepr5_nHgLbNNQwAAAnI"] [Tue Aug 18 12:55:58.172077 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRAAAAj8"] [Tue Aug 18 12:55:58.180309 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.61.152:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSAjtO5rbWdOArH04KHMQAAARk"] [Tue Aug 18 12:55:58.192344 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAjtO5rbWdOArH04KHMgAAAVw"] [Tue Aug 18 12:55:58.225086 2026] [security2:error] [pid 67073:tid 67209] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nw.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRgAAAhg"] [Tue Aug 18 12:55:58.229809 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAjtO5rbWdOArH04KHMwAAASY"] [Tue Aug 18 12:55:58.231056 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/51.php"] [unique_id "aoSAjvcmepr5_nHgLbNNRwACjBY"] [Tue Aug 18 12:55:58.248600 2026] [security2:error] [pid 67073:tid 67241] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAjvcmepr5_nHgLbNNSAAAAjg"] [Tue Aug 18 12:55:58.263862 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/o.php"] [unique_id "aoSAjvcmepr5_nHgLbNNSgAAAjU"] [Tue Aug 18 12:55:58.288199 2026] [security2:error] [pid 66623:tid 66860] [client 135.225.75.187:25647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fleen.php"] [unique_id "aoSAjtO5rbWdOArH04KHNgAAAWg"] [Tue Aug 18 12:55:58.297097 2026] [security2:error] [pid 66623:tid 66790] [client 85.154.68.202:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjtO5rbWdOArH04KHNwAAASI"] [Tue Aug 18 12:55:58.297244 2026] [security2:error] [pid 66623:tid 66790] [client 85.154.68.202:12511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAjtO5rbWdOArH04KHNwAAASI"] [Tue Aug 18 12:55:58.302650 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:58.302690 2026] [security2:error] [pid 67073:tid 67291] [client 160.120.140.123:60148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTAAAAmo"] [Tue Aug 18 12:55:58.302812 2026] [security2:error] [pid 67073:tid 67291] [client 160.120.140.123:60148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTAAAAmo"] [Tue Aug 18 12:55:58.302930 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:58.305219 2026] [security2:error] [pid 66623:tid 66795] [client 52.173.121.69:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAjtO5rbWdOArH04KHOAAAASc"] [Tue Aug 18 12:55:58.313380 2026] [security2:error] [pid 66623:tid 66823] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAjtO5rbWdOArH04KHOQAAAUM"] [Tue Aug 18 12:55:58.322258 2026] [security2:error] [pid 66623:tid 66831] [client 20.100.169.31:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/666.php"] [unique_id "aoSAjtO5rbWdOArH04KHOgAAAUs"] [Tue Aug 18 12:55:58.326405 2026] [security2:error] [pid 66623:tid 66855] [client 4.232.151.198:27353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/ws54.php"] [unique_id "aoSAjtO5rbWdOArH04KHOwAAAWM"] [Tue Aug 18 12:55:58.334736 2026] [security2:error] [pid 67073:tid 67243] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTgAAAjo"] [Tue Aug 18 12:55:58.342621 2026] [security2:error] [pid 66623:tid 66786] [client 135.225.78.186:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAjtO5rbWdOArH04KHPAAAAR4"] [Tue Aug 18 12:55:58.355942 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUAAAAiQ"] [Tue Aug 18 12:55:58.366383 2026] [security2:error] [pid 67073:tid 67303] [client 20.251.48.93:31770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/bajah.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUQAAAnY"] [Tue Aug 18 12:55:58.368054 2026] [security2:error] [pid 67073:tid 67295] [client 74.248.130.103:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/BDKR28WP.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUgAAAm4"] [Tue Aug 18 12:55:58.375308 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAjtO5rbWdOArH04KHPQAAASE"] [Tue Aug 18 12:55:58.382841 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.154.236:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAjtO5rbWdOArH04KHPgAAATQ"] [Tue Aug 18 12:55:58.384004 2026] [security2:error] [pid 67073:tid 67307] [client 20.151.109.219:64157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ih.php"] [unique_id "aoSAjvcmepr5_nHgLbNNUwAAAno"] [Tue Aug 18 12:55:58.385087 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:32995] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/1.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVAAAAiE"] [Tue Aug 18 12:55:58.385179 2026] [security2:error] [pid 67073:tid 67218] [client 20.226.6.191:32995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/1.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVAAAAiE"] [Tue Aug 18 12:55:58.393008 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVgAAAjE"] [Tue Aug 18 12:55:58.412411 2026] [security2:error] [pid 67073:tid 67301] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAjvcmepr5_nHgLbNNVwAAAnQ"] [Tue Aug 18 12:55:58.415774 2026] [security2:error] [pid 67073:tid 67239] [client 4.223.164.152:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWAAAAjY"] [Tue Aug 18 12:55:58.431444 2026] [security2:error] [pid 67073:tid 67275] [client 20.215.241.237:46700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWQAAAlo"] [Tue Aug 18 12:55:58.474966 2026] [security2:error] [pid 66623:tid 66799] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAjtO5rbWdOArH04KHQAAAASs"] [Tue Aug 18 12:55:58.483336 2026] [security2:error] [pid 67073:tid 67247] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sb.php"] [unique_id "aoSAjvcmepr5_nHgLbNNWwAAAj4"] [Tue Aug 18 12:55:58.491244 2026] [security2:error] [pid 67073:tid 67227] [client 20.226.6.191:6562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/function/function.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXAAAAio"] [Tue Aug 18 12:55:58.491516 2026] [security2:error] [pid 67073:tid 67078] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ew.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXQACVwI"] [Tue Aug 18 12:55:58.494607 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAjvcmepr5_nHgLbNNXgAAAmg"] [Tue Aug 18 12:55:58.515851 2026] [security2:error] [pid 67073:tid 67217] [client 142.132.180.39:45340] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSAjvcmepr5_nHgLbNNTQAAAiA"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 12:55:58.544145 2026] [security2:error] [pid 66623:tid 66832] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAjtO5rbWdOArH04KHQgAAAUw"] [Tue Aug 18 12:55:58.562529 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYAAAAlE"] [Tue Aug 18 12:55:58.629284 2026] [security2:error] [pid 67073:tid 67318] [client 213.35.127.232:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYQAAAoU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:58.642101 2026] [security2:error] [pid 66623:tid 66818] [client 20.215.241.237:45790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAjtO5rbWdOArH04KHRAAAAT4"] [Tue Aug 18 12:55:58.652086 2026] [security2:error] [pid 66623:tid 66874] [client 20.226.6.191:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAjtO5rbWdOArH04KHRgAAAXY"] [Tue Aug 18 12:55:58.695907 2026] [security2:error] [pid 67073:tid 67178] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pqr.php"] [unique_id "aoSAjvcmepr5_nHgLbNNYwACTGY"] [Tue Aug 18 12:55:58.702601 2026] [security2:error] [pid 66623:tid 66796] [client 20.91.215.254:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAjtO5rbWdOArH04KHSAAAASg"] [Tue Aug 18 12:55:58.720916 2026] [security2:error] [pid 67073:tid 67245] [client 20.163.43.14:4415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/bb.php"] [unique_id "aoSAjvcmepr5_nHgLbNNZQAAAjw"] [Tue Aug 18 12:55:58.734867 2026] [security2:error] [pid 67073:tid 67228] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/stats.php"] [unique_id "aoSAjvcmepr5_nHgLbNNZwAAAis"] [Tue Aug 18 12:55:58.743565 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.56.190:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vj.php"] [unique_id "aoSAjtO5rbWdOArH04KHSgAAATs"] [Tue Aug 18 12:55:58.744098 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xj.php"] [unique_id "aoSAjtO5rbWdOArH04KHSwAAARM"] [Tue Aug 18 12:55:58.751803 2026] [security2:error] [pid 67073:tid 67222] [client 20.151.109.219:45711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/k.php"] [unique_id "aoSAjvcmepr5_nHgLbNNaAAAAiU"] [Tue Aug 18 12:55:58.755380 2026] [security2:error] [pid 67073:tid 67233] [client 20.29.77.16:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/del.php"] [unique_id "aoSAjvcmepr5_nHgLbNNaQAAAjA"] [Tue Aug 18 12:55:58.757711 2026] [security2:error] [pid 67073:tid 67311] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAjfcmepr5_nHgLbNNMgACfgY"] [Tue Aug 18 12:55:58.759857 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.74.177:3000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/k.php"] [unique_id "aoSAjvcmepr5_nHgLbNNagAAAk0"] [Tue Aug 18 12:55:58.765445 2026] [security2:error] [pid 67073:tid 67323] [client 135.225.78.186:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/blurbs.php"] [unique_id "aoSAjvcmepr5_nHgLbNNawAAAoo"] [Tue Aug 18 12:55:58.836019 2026] [security2:error] [pid 66623:tid 66822] [client 74.248.18.37:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/sagax1.php"] [unique_id "aoSAjtO5rbWdOArH04KHTAAAAUI"] [Tue Aug 18 12:55:58.855335 2026] [security2:error] [pid 66623:tid 66814] [client 20.226.6.191:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAjtO5rbWdOArH04KHTQAAATo"] [Tue Aug 18 12:55:58.863431 2026] [security2:error] [pid 66623:tid 66886] [client 4.223.164.152:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSAjtO5rbWdOArH04KHTgAAAYI"] [Tue Aug 18 12:55:58.880761 2026] [security2:error] [pid 66623:tid 66821] [client 158.23.17.4:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/xynz1.php"] [unique_id "aoSAjtO5rbWdOArH04KHUAAAAUE"] [Tue Aug 18 12:55:58.904520 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:58.904834 2026] [authz_core:error] [pid 67073:tid 67096] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:58.941291 2026] [security2:error] [pid 66623:tid 66804] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAjtO5rbWdOArH04KHUQAAATA"] [Tue Aug 18 12:55:58.943489 2026] [security2:error] [pid 67073:tid 67305] [client 20.171.51.14:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ak.php"] [unique_id "aoSAjvcmepr5_nHgLbNNcwAAAng"] [Tue Aug 18 12:55:58.966364 2026] [security2:error] [pid 67073:tid 67177] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/an.php"] [unique_id "aoSAjvcmepr5_nHgLbNNdAACXmU"] [Tue Aug 18 12:55:58.985886 2026] [security2:error] [pid 66623:tid 66797] [client 20.42.19.40:2712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ms-edit.php"] [unique_id "aoSAjtO5rbWdOArH04KHUgAAASk"] [Tue Aug 18 12:55:58.996693 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.6.191:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/ok.php"] [unique_id "aoSAjtO5rbWdOArH04KHUwAAAS0"] [Tue Aug 18 12:55:59.004253 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAj9O5rbWdOArH04KHVAAAAR0"] [Tue Aug 18 12:55:59.008124 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ns.php"] [unique_id "aoSAj_cmepr5_nHgLbNNdwAAAkE"] [Tue Aug 18 12:55:59.041291 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNegAAAoQ"] [Tue Aug 18 12:55:59.042525 2026] [security2:error] [pid 66623:tid 66889] [client 20.151.109.219:21680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iu.php"] [unique_id "aoSAj9O5rbWdOArH04KHVQAAAYU"] [Tue Aug 18 12:55:59.048636 2026] [security2:error] [pid 67073:tid 67331] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAj_cmepr5_nHgLbNNewAAApI"] [Tue Aug 18 12:55:59.068787 2026] [security2:error] [pid 67073:tid 67267] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/sump1.php"] [unique_id "aoSAj_cmepr5_nHgLbNNggAAAlI"] [Tue Aug 18 12:55:59.103632 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhAAAAnI"] [Tue Aug 18 12:55:59.105357 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.6.191:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhQAAAoY"] [Tue Aug 18 12:55:59.111169 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:25696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/simple.php"] [unique_id "aoSAj9O5rbWdOArH04KHVgAAARA"] [Tue Aug 18 12:55:59.121366 2026] [security2:error] [pid 67073:tid 67322] [client 172.182.200.96:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAj_cmepr5_nHgLbNNhgAAAok"] [Tue Aug 18 12:55:59.122680 2026] [security2:error] [pid 67073:tid 67277] [client 74.248.130.103:15405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp.php"] [unique_id "aoSAj_cmepr5_nHgLbNNiAAAAlw"] [Tue Aug 18 12:55:59.123463 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAj_cmepr5_nHgLbNNiQAAAjs"] [Tue Aug 18 12:55:59.169300 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sy.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjAACNXM"] [Tue Aug 18 12:55:59.181997 2026] [security2:error] [pid 67073:tid 67315] [client 4.232.151.198:25664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjgAAAoI"] [Tue Aug 18 12:55:59.183537 2026] [security2:error] [pid 67073:tid 67269] [client 135.225.78.186:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/bajah.php"] [unique_id "aoSAj_cmepr5_nHgLbNNjwAAAlQ"] [Tue Aug 18 12:55:59.184900 2026] [security2:error] [pid 67073:tid 67175] [remote 47.128.123.68:36678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/passeio-de-lancha-pelo-rio-preguicas-ninhal-dos-guaras-novo-passeio"] [unique_id "aoSAj_cmepr5_nHgLbNNkAACFmM"] [Tue Aug 18 12:55:59.191556 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.156.252:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAj9O5rbWdOArH04KHVwAAAVI"] [Tue Aug 18 12:55:59.192933 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/rezor.php"] [unique_id "aoSAj9O5rbWdOArH04KHWAAAASQ"] [Tue Aug 18 12:55:59.198488 2026] [security2:error] [pid 66623:tid 66833] [client 20.163.43.14:4361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAj9O5rbWdOArH04KHWQAAAU0"] [Tue Aug 18 12:55:59.205004 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:59.205324 2026] [authz_core:error] [pid 67073:tid 67102] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:59.248986 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlQAAAlM"] [Tue Aug 18 12:55:59.253051 2026] [security2:error] [pid 67073:tid 67210] [client 157.51.166.53:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlgAAAhk"] [Tue Aug 18 12:55:59.253198 2026] [security2:error] [pid 67073:tid 67210] [client 157.51.166.53:59868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlgAAAhk"] [Tue Aug 18 12:55:59.255930 2026] [security2:error] [pid 67073:tid 67281] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gk.php"] [unique_id "aoSAj_cmepr5_nHgLbNNlwAAAmA"] [Tue Aug 18 12:55:59.283436 2026] [security2:error] [pid 67073:tid 67296] [client 20.29.77.16:56531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/moderator.php"] [unique_id "aoSAj_cmepr5_nHgLbNNmgAAAm8"] [Tue Aug 18 12:55:59.288577 2026] [security2:error] [pid 67073:tid 67270] [client 4.223.164.152:46195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/media.php"] [unique_id "aoSAj_cmepr5_nHgLbNNmwAAAlU"] [Tue Aug 18 12:55:59.307940 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAj9O5rbWdOArH04KHWgAAAYY"] [Tue Aug 18 12:55:59.311396 2026] [security2:error] [pid 67073:tid 67220] [client 20.42.19.40:2917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/rip.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnAAAAiM"] [Tue Aug 18 12:55:59.319709 2026] [security2:error] [pid 67073:tid 67307] [client 20.226.6.191:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luceanjo.com.br"] [uri "/item.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnQAAAno"] [Tue Aug 18 12:55:59.335055 2026] [security2:error] [pid 67073:tid 67276] [client 20.151.109.219:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pk.php"] [unique_id "aoSAj_cmepr5_nHgLbNNnwAAAls"] [Tue Aug 18 12:55:59.346604 2026] [authz_core:error] [pid 67073:tid 67199] [remote 57.141.22.108:36282] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:59.346887 2026] [authz_core:error] [pid 67073:tid 67199] [remote 57.141.22.108:36282] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:59.356694 2026] [security2:error] [pid 66623:tid 66876] [client 20.65.69.59:40512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/bala.php"] [unique_id "aoSAj9O5rbWdOArH04KHXAAAAXg"] [Tue Aug 18 12:55:59.388709 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/index/function.php"] [unique_id "aoSAj_cmepr5_nHgLbNNogAAAjY"] [Tue Aug 18 12:55:59.407379 2026] [security2:error] [pid 67073:tid 67309] [client 20.91.215.254:20696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/ebs.php7"] [unique_id "aoSAj_cmepr5_nHgLbNNowAAAnw"] [Tue Aug 18 12:55:59.407385 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAj_cmepr5_nHgLbNNpAAAAkg"] [Tue Aug 18 12:55:59.409304 2026] [security2:error] [pid 66623:tid 66837] [client 158.158.34.183:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/elp.php"] [unique_id "aoSAj9O5rbWdOArH04KHXQAAAVE"] [Tue Aug 18 12:55:59.409475 2026] [security2:error] [pid 67073:tid 67314] [client 158.23.17.4:8705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/album.php"] [unique_id "aoSAj_cmepr5_nHgLbNNpQAAAoE"] [Tue Aug 18 12:55:59.432893 2026] [security2:error] [pid 67073:tid 67103] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/57.php"] [unique_id "aoSAj_cmepr5_nHgLbNNqQACKhs"] [Tue Aug 18 12:55:59.455817 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:2532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mimes.php"] [unique_id "aoSAj_cmepr5_nHgLbNNqgAAAkU"] [Tue Aug 18 12:55:59.505356 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:55:59.505609 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:55:59.511380 2026] [security2:error] [pid 66623:tid 66875] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wn.php"] [unique_id "aoSAj9O5rbWdOArH04KHXgAAAXc"] [Tue Aug 18 12:55:59.517511 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:16205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAj_cmepr5_nHgLbNNrgAAAkk"] [Tue Aug 18 12:55:59.566863 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAj9O5rbWdOArH04KHXwAAAVY"] [Tue Aug 18 12:55:59.598074 2026] [security2:error] [pid 67073:tid 67265] [client 158.158.74.177:16567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/media/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsAAAAlA"] [Tue Aug 18 12:55:59.601378 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.78.186:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/domvf.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsQAAAn8"] [Tue Aug 18 12:55:59.611750 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.130.103:14448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/i.php"] [unique_id "aoSAj_cmepr5_nHgLbNNsgAAAoU"] [Tue Aug 18 12:55:59.626921 2026] [security2:error] [pid 66623:tid 66836] [client 20.42.19.40:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/update/da222.php"] [unique_id "aoSAj9O5rbWdOArH04KHYQAAAVA"] [Tue Aug 18 12:55:59.643691 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAj_cmepr5_nHgLbNNtAAAAm4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:55:59.649362 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ah.php"] [unique_id "aoSAj_cmepr5_nHgLbNNtQACQCE"] [Tue Aug 18 12:55:59.664673 2026] [security2:error] [pid 66623:tid 66809] [client 20.151.109.219:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ge.php"] [unique_id "aoSAj9O5rbWdOArH04KHYwAAATU"] [Tue Aug 18 12:55:59.666186 2026] [security2:error] [pid 66623:tid 66857] [client 20.215.241.237:10780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAj9O5rbWdOArH04KHZAAAAWU"] [Tue Aug 18 12:55:59.671388 2026] [security2:error] [pid 66623:tid 66788] [client 49.13.134.145:56462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSAj9O5rbWdOArH04KHZQAAASA"], referer: http://rakhomed.com.br [Tue Aug 18 12:55:59.729078 2026] [security2:error] [pid 67073:tid 67212] [client 4.223.164.152:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/inso.php"] [unique_id "aoSAj_cmepr5_nHgLbNNuAAAAhs"] [Tue Aug 18 12:55:59.774714 2026] [security2:error] [pid 67073:tid 67323] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/app.php"] [unique_id "aoSAj_cmepr5_nHgLbNNugAAAoo"] [Tue Aug 18 12:55:59.819086 2026] [security2:error] [pid 67073:tid 67320] [client 135.225.75.187:58335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/e.php"] [unique_id "aoSAj_cmepr5_nHgLbNNvQAAAoc"] [Tue Aug 18 12:55:59.824465 2026] [security2:error] [pid 66623:tid 66773] [client 20.163.43.14:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAj9O5rbWdOArH04KHaAAAARE"] [Tue Aug 18 12:55:59.826403 2026] [security2:error] [pid 67073:tid 67302] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/Cachex.php"] [unique_id "aoSAj_cmepr5_nHgLbNNvgAAAnU"] [Tue Aug 18 12:55:59.848113 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAj9O5rbWdOArH04KHaQAAATw"] [Tue Aug 18 12:55:59.853655 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vw.php"] [unique_id "aoSAj_cmepr5_nHgLbNNwAACFyw"] [Tue Aug 18 12:55:59.861567 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/test_info.php"] [unique_id "aoSAj9O5rbWdOArH04KHagAAAXI"] [Tue Aug 18 12:55:59.889256 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAj_cmepr5_nHgLbNNwwAAAkQ"] [Tue Aug 18 12:55:59.910303 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAj9O5rbWdOArH04KHbAAAATc"] [Tue Aug 18 12:55:59.911984 2026] [security2:error] [pid 66623:tid 66793] [client 20.29.77.16:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/infoinfo.php"] [unique_id "aoSAj9O5rbWdOArH04KHbQAAASU"] [Tue Aug 18 12:55:59.942809 2026] [security2:error] [pid 67073:tid 67206] [client 20.251.48.93:9768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/ajax.php"] [unique_id "aoSAj_cmepr5_nHgLbNNxQAAAhU"] [Tue Aug 18 12:55:59.946959 2026] [security2:error] [pid 66623:tid 66892] [client 128.140.106.114:51048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.portaltomazzi.com.br"] [uri "/index.php"] [unique_id "aoSAjtO5rbWdOArH04KHRwAAAYg"], referer: https://www.portaltomazzi.com.br/ [Tue Aug 18 12:55:59.972010 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAj_cmepr5_nHgLbNNxwAAAos"] [Tue Aug 18 12:55:59.991538 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAj_cmepr5_nHgLbNNyAAAAjM"] [Tue Aug 18 12:55:59.996994 2026] [security2:error] [pid 66623:tid 66844] [client 172.202.39.151:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/k.php"] [unique_id "aoSAj9O5rbWdOArH04KHbgAAAVg"] [Tue Aug 18 12:56:00.010631 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNNygAAAnI"] [Tue Aug 18 12:56:00.022136 2026] [security2:error] [pid 67073:tid 67287] [client 135.225.78.186:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fpwch.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzAAAAmY"] [Tue Aug 18 12:56:00.022420 2026] [security2:error] [pid 67073:tid 67322] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/87.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzQAAAok"] [Tue Aug 18 12:56:00.030800 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzgAAAjs"] [Tue Aug 18 12:56:00.044473 2026] [security2:error] [pid 66623:tid 66829] [client 20.250.13.23:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/edit-tags.php"] [unique_id "aoSAkNO5rbWdOArH04KHbwAAAUk"] [Tue Aug 18 12:56:00.049929 2026] [security2:error] [pid 67073:tid 67259] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAkPcmepr5_nHgLbNNzwAAAko"] [Tue Aug 18 12:56:00.052411 2026] [security2:error] [pid 66623:tid 66824] [client 20.151.109.219:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kl.php"] [unique_id "aoSAkNO5rbWdOArH04KHcAAAAUQ"] [Tue Aug 18 12:56:00.065503 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN0AAAAnM"] [Tue Aug 18 12:56:00.085003 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.98.162:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/33.php"] [unique_id "aoSAkPcmepr5_nHgLbNN0QAAAlQ"] [Tue Aug 18 12:56:00.109072 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:00.109374 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:00.116319 2026] [security2:error] [pid 67073:tid 67139] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lj.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1AACYT8"] [Tue Aug 18 12:56:00.119693 2026] [security2:error] [pid 67073:tid 67291] [client 20.42.19.40:2900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/upload.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1gAAAmo"] [Tue Aug 18 12:56:00.123119 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAkNO5rbWdOArH04KHcQAAAVw"] [Tue Aug 18 12:56:00.144917 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHcgAAASY"] [Tue Aug 18 12:56:00.145993 2026] [security2:error] [pid 67073:tid 67279] [client 20.91.215.254:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/include/Lurd.class.php"] [unique_id "aoSAkPcmepr5_nHgLbNN1wAAAl4"] [Tue Aug 18 12:56:00.162823 2026] [security2:error] [pid 66623:tid 66800] [client 4.223.164.152:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/shiny.php"] [unique_id "aoSAkNO5rbWdOArH04KHcwAAASw"] [Tue Aug 18 12:56:00.166623 2026] [security2:error] [pid 66623:tid 66777] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system.php"] [unique_id "aoSAkNO5rbWdOArH04KHdAAAARU"] [Tue Aug 18 12:56:00.167649 2026] [security2:error] [pid 66623:tid 66860] [client 68.155.156.252:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAkNO5rbWdOArH04KHdQAAAWg"] [Tue Aug 18 12:56:00.177345 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2AAAAlM"] [Tue Aug 18 12:56:00.192093 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2QAAAks"] [Tue Aug 18 12:56:00.217483 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN2wAAAik"] [Tue Aug 18 12:56:00.261999 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:22748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3QAAAnk"] [Tue Aug 18 12:56:00.273480 2026] [security2:error] [pid 67073:tid 67270] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zi.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3gAAAlU"] [Tue Aug 18 12:56:00.290769 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.56.190:30980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ni.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3wAAAj0"] [Tue Aug 18 12:56:00.302173 2026] [security2:error] [pid 66623:tid 66873] [client 20.65.69.59:40567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/222.php"] [unique_id "aoSAkNO5rbWdOArH04KHdgAAAXU"] [Tue Aug 18 12:56:00.327035 2026] [security2:error] [pid 67073:tid 67218] [client 20.116.17.175:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/3.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4QAAAiE"] [Tue Aug 18 12:56:00.328055 2026] [security2:error] [pid 67073:tid 67242] [client 74.248.18.37:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4gAAAjk"] [Tue Aug 18 12:56:00.328767 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.154.236:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAkNO5rbWdOArH04KHdwAAAR4"] [Tue Aug 18 12:56:00.336880 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAkNO5rbWdOArH04KHeQAAATQ"] [Tue Aug 18 12:56:00.359183 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAkNO5rbWdOArH04KHegAAAWA"] [Tue Aug 18 12:56:00.364896 2026] [security2:error] [pid 67073:tid 67301] [client 20.151.109.219:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gs.php"] [unique_id "aoSAkPcmepr5_nHgLbNN5AAAAnQ"] [Tue Aug 18 12:56:00.376237 2026] [security2:error] [pid 67073:tid 67264] [client 4.232.151.198:41973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uniaoac.com.br"] [uri "/222.php"] [unique_id "aoSAkPcmepr5_nHgLbNN5QAAAk8"] [Tue Aug 18 12:56:00.442876 2026] [security2:error] [pid 67073:tid 67329] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAkPcmepr5_nHgLbNN4wACkBw"] [Tue Aug 18 12:56:00.445118 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/adminner.php"] [unique_id "aoSAkPcmepr5_nHgLbNN6AAAAjY"] [Tue Aug 18 12:56:00.450805 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/as.php"] [unique_id "aoSAkNO5rbWdOArH04KHewAAAQ0"] [Tue Aug 18 12:56:00.454262 2026] [security2:error] [pid 67073:tid 67167] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kh.php"] [unique_id "aoSAkPcmepr5_nHgLbNN6QACg1s"] [Tue Aug 18 12:56:00.505828 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/14.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7AAAAnY"] [Tue Aug 18 12:56:00.508253 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.130.103:14425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/abcd.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7QAAAio"] [Tue Aug 18 12:56:00.526796 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7gAAAmg"] [Tue Aug 18 12:56:00.531136 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file.php"] [unique_id "aoSAkPcmepr5_nHgLbNN7wAAAj4"] [Tue Aug 18 12:56:00.534275 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/92.php"] [unique_id "aoSAkPcmepr5_nHgLbNN8AAAAiA"] [Tue Aug 18 12:56:00.548286 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.56.190:31011] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rakhomed.com.br"] [uri "/1.php"] [unique_id "aoSAkNO5rbWdOArH04KHfAAAAU4"] [Tue Aug 18 12:56:00.548395 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.56.190:31011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/1.php"] [unique_id "aoSAkNO5rbWdOArH04KHfAAAAU4"] [Tue Aug 18 12:56:00.576789 2026] [security2:error] [pid 67073:tid 67266] [client 20.100.169.31:39353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ws54.php"] [unique_id "aoSAkPcmepr5_nHgLbNN8gAAAlE"] [Tue Aug 18 12:56:00.606094 2026] [security2:error] [pid 67073:tid 67285] [client 4.223.164.152:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/403dd.php"] [unique_id "aoSAkPcmepr5_nHgLbNN9AAAAmQ"] [Tue Aug 18 12:56:00.656964 2026] [security2:error] [pid 66623:tid 66855] [client 213.35.127.232:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAkNO5rbWdOArH04KHfgAAAWM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:00.698365 2026] [security2:error] [pid 66623:tid 66820] [client 20.151.109.219:12888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lw.php"] [unique_id "aoSAkNO5rbWdOArH04KHfwAAAUA"] [Tue Aug 18 12:56:00.709290 2026] [security2:error] [pid 67073:tid 67126] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jb.php"] [unique_id "aoSAkPcmepr5_nHgLbNN9wACazI"] [Tue Aug 18 12:56:00.724429 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSAkPcmepr5_nHgLbNN-AAAAjw"] [Tue Aug 18 12:56:00.753781 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.6.191:39397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAkNO5rbWdOArH04KHgQAAATs"] [Tue Aug 18 12:56:00.757817 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHggAAARM"] [Tue Aug 18 12:56:00.757989 2026] [security2:error] [pid 67073:tid 67147] [remote 135.236.141.8:21379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkPcmepr5_nHgLbNN-QACWkc"] [Tue Aug 18 12:56:00.778877 2026] [security2:error] [pid 66623:tid 66854] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAkNO5rbWdOArH04KHhAAAAWI"] [Tue Aug 18 12:56:00.801715 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAkPcmepr5_nHgLbNN_AAAAhs"] [Tue Aug 18 12:56:00.802077 2026] [security2:error] [pid 66623:tid 66858] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jm.php"] [unique_id "aoSAkNO5rbWdOArH04KHhQAAAWY"] [Tue Aug 18 12:56:00.812832 2026] [security2:error] [pid 67073:tid 67238] [client 49.13.134.145:25302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSAkPcmepr5_nHgLbNN3AAAAjU"], referer: http://rakhomed.com.br [Tue Aug 18 12:56:00.833635 2026] [security2:error] [pid 67073:tid 67327] [client 158.23.17.4:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/creds.php"] [unique_id "aoSAkPcmepr5_nHgLbNN_QAAAo4"] [Tue Aug 18 12:56:00.854332 2026] [security2:error] [pid 67073:tid 67308] [client 135.225.75.187:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/hello.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAAAAAns"] [Tue Aug 18 12:56:00.867701 2026] [security2:error] [pid 67073:tid 67302] [client 68.155.154.236:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAQAAAnU"] [Tue Aug 18 12:56:00.868488 2026] [security2:error] [pid 67073:tid 67205] [client 135.225.78.186:13036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/abcd.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAgAAAhQ"] [Tue Aug 18 12:56:00.886082 2026] [security2:error] [pid 67073:tid 67273] [client 20.91.215.254:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAkPcmepr5_nHgLbNOAwAAAlg"] [Tue Aug 18 12:56:00.897983 2026] [security2:error] [pid 66623:tid 66796] [client 158.158.74.177:16560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mgrr.php"] [unique_id "aoSAkNO5rbWdOArH04KHhgAAASg"] [Tue Aug 18 12:56:00.904463 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/do.php"] [unique_id "aoSAkPcmepr5_nHgLbNOBAACkVI"] [Tue Aug 18 12:56:00.944805 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.6.191:41831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAkPcmepr5_nHgLbNOCAAAAkE"] [Tue Aug 18 12:56:00.945834 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/epinyins.php"] [unique_id "aoSAkPcmepr5_nHgLbNOCQAAAoQ"] [Tue Aug 18 12:56:00.951087 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.56.190:31673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/88.php"] [unique_id "aoSAkNO5rbWdOArH04KHhwAAAYI"] [Tue Aug 18 12:56:00.998358 2026] [autoindex:error] [pid 67073:tid 67324] [client 43.164.190.28:57344] AH01276: Cannot serve directory /home1/olhaoreplay/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:01.013639 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:01.014079 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:01.038555 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEAAAAnI"] [Tue Aug 18 12:56:01.045925 2026] [security2:error] [pid 67073:tid 67287] [client 20.151.109.219:53193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vj.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEQAAAmY"] [Tue Aug 18 12:56:01.058229 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAkdO5rbWdOArH04KHiAAAAVc"] [Tue Aug 18 12:56:01.070029 2026] [security2:error] [pid 66623:tid 66804] [client 4.223.164.152:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/baba.php"] [unique_id "aoSAkdO5rbWdOArH04KHiQAAATA"] [Tue Aug 18 12:56:01.075526 2026] [security2:error] [pid 66623:tid 66882] [client 20.251.48.93:61160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filmecompleto.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAkdO5rbWdOArH04KHigAAAX4"] [Tue Aug 18 12:56:01.078818 2026] [security2:error] [pid 66623:tid 66797] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wj.php"] [unique_id "aoSAkdO5rbWdOArH04KHiwAAASk"] [Tue Aug 18 12:56:01.091181 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOEwAAAkc"] [Tue Aug 18 12:56:01.110347 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFAAAAmo"] [Tue Aug 18 12:56:01.112449 2026] [security2:error] [pid 67073:tid 67207] [client 132.196.61.152:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/php.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFQAAAhY"] [Tue Aug 18 12:56:01.130250 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAkfcmepr5_nHgLbNOFwAAAo0"] [Tue Aug 18 12:56:01.149284 2026] [security2:error] [pid 67073:tid 67127] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yw.php"] [unique_id "aoSAkfcmepr5_nHgLbNOGAACTjM"] [Tue Aug 18 12:56:01.150183 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAkfcmepr5_nHgLbNOGQAAAn4"] [Tue Aug 18 12:56:01.171894 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAkdO5rbWdOArH04KHjQAAAR0"] [Tue Aug 18 12:56:01.183060 2026] [security2:error] [pid 66623:tid 66768] [client 4.223.164.152:4861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAkdO5rbWdOArH04KHjgAAAQw"] [Tue Aug 18 12:56:01.219989 2026] [security2:error] [pid 66623:tid 66881] [client 68.155.156.252:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAkdO5rbWdOArH04KHjwAAAX0"] [Tue Aug 18 12:56:01.234131 2026] [security2:error] [pid 67073:tid 67267] [client 74.248.18.37:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/fone1.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHAAAAlI"] [Tue Aug 18 12:56:01.238712 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHQAAAhk"] [Tue Aug 18 12:56:01.266748 2026] [security2:error] [pid 67073:tid 67226] [client 20.215.241.237:24637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/sf.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHgAAAik"] [Tue Aug 18 12:56:01.274230 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.130.103:14454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-manager.php"] [unique_id "aoSAkdO5rbWdOArH04KHkAAAAVQ"] [Tue Aug 18 12:56:01.276224 2026] [security2:error] [pid 67073:tid 67221] [client 20.163.43.14:4396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOHwAAAiQ"] [Tue Aug 18 12:56:01.288708 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAkfcmepr5_nHgLbNOIAAAAnk"] [Tue Aug 18 12:56:01.290818 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.78.186:40777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/simple.php"] [unique_id "aoSAkfcmepr5_nHgLbNOIQAAAlU"] [Tue Aug 18 12:56:01.321993 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/log.php"] [unique_id "aoSAkdO5rbWdOArH04KHkQAAAXs"] [Tue Aug 18 12:56:01.342438 2026] [security2:error] [pid 67073:tid 67234] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/74.php"] [unique_id "aoSAkfcmepr5_nHgLbNOJgAAAjE"] [Tue Aug 18 12:56:01.343730 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAkfcmepr5_nHgLbNOJwAAAls"] [Tue Aug 18 12:56:01.345137 2026] [security2:error] [pid 67073:tid 67301] [client 74.248.136.165:28099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/txets.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKAAAAnQ"] [Tue Aug 18 12:56:01.349084 2026] [security2:error] [pid 67073:tid 67264] [client 20.42.19.40:2637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wk/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKQAAAk8"] [Tue Aug 18 12:56:01.364226 2026] [security2:error] [pid 67073:tid 67332] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOKwAAApM"] [Tue Aug 18 12:56:01.379776 2026] [security2:error] [pid 67073:tid 67316] [client 20.151.109.219:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mimes.php"] [unique_id "aoSAkfcmepr5_nHgLbNOLAAAAoM"] [Tue Aug 18 12:56:01.381433 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/qh.php"] [unique_id "aoSAkfcmepr5_nHgLbNOLQACfCI"] [Tue Aug 18 12:56:01.408953 2026] [security2:error] [pid 67073:tid 67216] [client 2a02:c207:2265:4159::1:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.simetriaarquitetura.com.br"] [uri "/.git/config"] [unique_id "aoSAkfcmepr5_nHgLbNOLwAAAh8"] [Tue Aug 18 12:56:01.421201 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAkdO5rbWdOArH04KHlQAAAWQ"] [Tue Aug 18 12:56:01.421469 2026] [security2:error] [pid 67073:tid 67328] [client 196.12.128.158:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMAAAAo8"] [Tue Aug 18 12:56:01.421595 2026] [security2:error] [pid 67073:tid 67328] [client 196.12.128.158:64398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMAAAAo8"] [Tue Aug 18 12:56:01.424409 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMQAAAoE"] [Tue Aug 18 12:56:01.471352 2026] [security2:error] [pid 67073:tid 67217] [client 172.202.39.151:34218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAkfcmepr5_nHgLbNOMwAAAiA"] [Tue Aug 18 12:56:01.482491 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/first.php"] [unique_id "aoSAkfcmepr5_nHgLbNONAAAAjQ"] [Tue Aug 18 12:56:01.503042 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNONgAAAi8"] [Tue Aug 18 12:56:01.512005 2026] [security2:error] [pid 67073:tid 67265] [client 20.65.69.59:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/routes.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOAAAAlA"] [Tue Aug 18 12:56:01.514253 2026] [security2:error] [pid 67073:tid 67307] [client 93.152.221.213:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkfcmepr5_nHgLbNONwAAAno"], referer: https://wordpress.org/ [Tue Aug 18 12:56:01.515178 2026] [security2:error] [pid 67073:tid 67312] [client 52.173.121.69:24994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOQAAAn8"] [Tue Aug 18 12:56:01.519527 2026] [security2:error] [pid 67073:tid 67292] [client 20.215.241.237:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOgAAAms"] [Tue Aug 18 12:56:01.521341 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/mandrill.php"] [unique_id "aoSAkdO5rbWdOArH04KHlwAAAVE"] [Tue Aug 18 12:56:01.523488 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOOwAAAm4"] [Tue Aug 18 12:56:01.526401 2026] [security2:error] [pid 66623:tid 66827] [client 213.202.253.4:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAkdO5rbWdOArH04KHmAAAAUc"], referer: www.google.com [Tue Aug 18 12:56:01.529935 2026] [security2:error] [pid 67073:tid 67246] [client 20.100.169.31:48080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPAAAAj0"] [Tue Aug 18 12:56:01.545038 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPQAAAlo"] [Tue Aug 18 12:56:01.554750 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:28283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hj.php"] [unique_id "aoSAkfcmepr5_nHgLbNOPgAAAiU"] [Tue Aug 18 12:56:01.556849 2026] [security2:error] [pid 66623:tid 66875] [client 4.223.164.152:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/site.php"] [unique_id "aoSAkdO5rbWdOArH04KHmgAAAXc"] [Tue Aug 18 12:56:01.598517 2026] [security2:error] [pid 67073:tid 67257] [client 20.91.215.254:20709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/lite.php"] [unique_id "aoSAkfcmepr5_nHgLbNOQgAAAkg"] [Tue Aug 18 12:56:01.603872 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/av.php"] [unique_id "aoSAkfcmepr5_nHgLbNOQwAAAns"] [Tue Aug 18 12:56:01.605373 2026] [security2:error] [pid 67073:tid 67320] [client 4.223.164.152:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAkfcmepr5_nHgLbNORAAAAoc"] [Tue Aug 18 12:56:01.606904 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.6.191:39378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNORQAAAmw"] [Tue Aug 18 12:56:01.647428 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/r.php"] [unique_id "aoSAkfcmepr5_nHgLbNOSQACK0g"] [Tue Aug 18 12:56:01.671015 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAkdO5rbWdOArH04KHnQAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:01.691833 2026] [security2:error] [pid 66623:tid 66805] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAkdO5rbWdOArH04KHnwAAATE"] [Tue Aug 18 12:56:01.710477 2026] [security2:error] [pid 67073:tid 67253] [client 135.225.78.186:13015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-manager.php"] [unique_id "aoSAkfcmepr5_nHgLbNOUQAAAkQ"] [Tue Aug 18 12:56:01.715594 2026] [security2:error] [pid 67073:tid 67299] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOUwAAAnI"] [Tue Aug 18 12:56:01.721800 2026] [security2:error] [pid 67073:tid 67248] [client 20.151.109.219:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ni.php"] [unique_id "aoSAkfcmepr5_nHgLbNOVAAAAj8"] [Tue Aug 18 12:56:01.737489 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAkdO5rbWdOArH04KHoAAAARQ"] [Tue Aug 18 12:56:01.788286 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.156.252:4796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/av.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWAAAAnM"] [Tue Aug 18 12:56:01.800158 2026] [security2:error] [pid 67073:tid 67269] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.qtag.com.br"] [uri "/images/security.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWQAAAlQ"] [Tue Aug 18 12:56:01.802231 2026] [security2:error] [pid 67073:tid 67282] [client 20.163.43.14:3050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWgAAAmE"] [Tue Aug 18 12:56:01.811234 2026] [security2:error] [pid 66623:tid 66870] [client 78.46.190.63:1946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSAkdO5rbWdOArH04KHogAAAXI"], referer: http://rakhomed.com.br [Tue Aug 18 12:56:01.820821 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.56.190:2553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ij.php"] [unique_id "aoSAkfcmepr5_nHgLbNOWwAAAi0"] [Tue Aug 18 12:56:01.848877 2026] [security2:error] [pid 67073:tid 67290] [client 4.232.151.198:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/function/function.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXAAAAmk"] [Tue Aug 18 12:56:01.849346 2026] [security2:error] [pid 67073:tid 67119] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/17.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXQACTis"] [Tue Aug 18 12:56:01.860977 2026] [security2:error] [pid 67073:tid 67268] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ag.php"] [unique_id "aoSAkfcmepr5_nHgLbNOXwAAAlM"] [Tue Aug 18 12:56:01.862873 2026] [security2:error] [pid 67073:tid 67283] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "aoSAkfcmepr5_nHgLbNOYAAAAmI"] [Tue Aug 18 12:56:01.885468 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tk.php"] [unique_id "aoSAkfcmepr5_nHgLbNOYwAAAhk"] [Tue Aug 18 12:56:01.887674 2026] [security2:error] [pid 67073:tid 67281] [client 68.155.154.236:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAkfcmepr5_nHgLbNOZAAAAmA"] [Tue Aug 18 12:56:01.917179 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.6.191:32983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAkdO5rbWdOArH04KHpAAAAYE"] [Tue Aug 18 12:56:01.920767 2026] [security2:error] [pid 66623:tid 66892] [client 93.152.221.213:63658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAkdO5rbWdOArH04KHpQAAAYg"] [Tue Aug 18 12:56:01.953728 2026] [security2:error] [pid 67073:tid 67220] [client 158.23.17.4:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/main.php"] [unique_id "aoSAkfcmepr5_nHgLbNOaAAAAiM"] [Tue Aug 18 12:56:02.002678 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:59760] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "suportesignrj.com.br"] [uri "/1.php"] [unique_id "aoSAkvcmepr5_nHgLbNOagAAAow"] [Tue Aug 18 12:56:02.002811 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/1.php"] [unique_id "aoSAkvcmepr5_nHgLbNOagAAAow"] [Tue Aug 18 12:56:02.026717 2026] [security2:error] [pid 67073:tid 67264] [client 4.223.164.152:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/domvf.php"] [unique_id "aoSAkvcmepr5_nHgLbNOawAAAk8"] [Tue Aug 18 12:56:02.065323 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNObwAAAoM"] [Tue Aug 18 12:56:02.108958 2026] [security2:error] [pid 66623:tid 66781] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ig.php"] [unique_id "aoSAktO5rbWdOArH04KHpwAAARk"] [Tue Aug 18 12:56:02.119948 2026] [security2:error] [pid 67073:tid 67174] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ev.php"] [unique_id "aoSAkvcmepr5_nHgLbNOcwACGGI"] [Tue Aug 18 12:56:02.129235 2026] [security2:error] [pid 67073:tid 67314] [client 135.225.78.186:12997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/xiugai.php"] [unique_id "aoSAkvcmepr5_nHgLbNOdAAAAoE"] [Tue Aug 18 12:56:02.159609 2026] [security2:error] [pid 67073:tid 67237] [client 20.163.43.14:3035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNOeAAAAjQ"] [Tue Aug 18 12:56:02.166403 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.130.103:15410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAktO5rbWdOArH04KHqQAAAVs"] [Tue Aug 18 12:56:02.209297 2026] [security2:error] [pid 67073:tid 67225] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "aoSAkvcmepr5_nHgLbNOegAAAig"] [Tue Aug 18 12:56:02.222671 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:02.223094 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:02.269159 2026] [security2:error] [pid 66623:tid 66863] [client 197.184.64.235:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHrAAAAWs"] [Tue Aug 18 12:56:02.269306 2026] [security2:error] [pid 66623:tid 66863] [client 197.184.64.235:41928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHrAAAAWs"] [Tue Aug 18 12:56:02.280695 2026] [security2:error] [pid 67073:tid 67332] [client 20.91.215.254:12021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAkvcmepr5_nHgLbNOfQAAApM"] [Tue Aug 18 12:56:02.295971 2026] [security2:error] [pid 66623:tid 66887] [client 20.151.109.219:21671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/88.php"] [unique_id "aoSAktO5rbWdOArH04KHrQAAAYM"] [Tue Aug 18 12:56:02.324325 2026] [security2:error] [pid 66623:tid 66859] [client 20.100.169.31:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/function/function.php"] [unique_id "aoSAktO5rbWdOArH04KHtQAAAWc"] [Tue Aug 18 12:56:02.329652 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.56.190:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ud.php"] [unique_id "aoSAkvcmepr5_nHgLbNOfgAAAhs"] [Tue Aug 18 12:56:02.366377 2026] [security2:error] [pid 67073:tid 67200] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xs.php"] [unique_id "aoSAkvcmepr5_nHgLbNOgAACgHw"] [Tue Aug 18 12:56:02.375677 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ta.php"] [unique_id "aoSAkvcmepr5_nHgLbNOgQAAAiw"] [Tue Aug 18 12:56:02.401789 2026] [security2:error] [pid 66623:tid 66868] [client 37.40.227.74:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHuAAAAXA"] [Tue Aug 18 12:56:02.404093 2026] [security2:error] [pid 66623:tid 66868] [client 37.40.227.74:56726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAktO5rbWdOArH04KHuAAAAXA"] [Tue Aug 18 12:56:02.422832 2026] [security2:error] [pid 67073:tid 67232] [client 78.46.190.63:26894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSAkvcmepr5_nHgLbNOggAAAi8"], referer: http://rakhomed.com.br [Tue Aug 18 12:56:02.445641 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhAAAAmw"] [Tue Aug 18 12:56:02.470147 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.154.236:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhgAAAkw"] [Tue Aug 18 12:56:02.473418 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.56.190:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ip.php"] [unique_id "aoSAktO5rbWdOArH04KHuwAAAUs"] [Tue Aug 18 12:56:02.483966 2026] [autoindex:error] [pid 66623:tid 66795] [client 20.226.6.191:32286] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:02.489901 2026] [security2:error] [pid 66623:tid 66873] [client 135.225.75.187:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/brc.php"] [unique_id "aoSAktO5rbWdOArH04KHvAAAAXU"] [Tue Aug 18 12:56:02.499183 2026] [security2:error] [pid 66623:tid 66786] [client 20.226.6.191:32286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAktO5rbWdOArH04KHvQAAAR4"] [Tue Aug 18 12:56:02.504453 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.156.252:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/images.php"] [unique_id "aoSAkvcmepr5_nHgLbNOhwAAApI"] [Tue Aug 18 12:56:02.515148 2026] [security2:error] [pid 67073:tid 67317] [client 4.223.164.152:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/cabs.php"] [unique_id "aoSAkvcmepr5_nHgLbNOiQAAAoQ"] [Tue Aug 18 12:56:02.518779 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:02.519026 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:02.551810 2026] [security2:error] [pid 66623:tid 66861] [client 135.225.78.186:13043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wp-load.php"] [unique_id "aoSAktO5rbWdOArH04KHvgAAAWk"] [Tue Aug 18 12:56:02.553235 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:4374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp.php"] [unique_id "aoSAkvcmepr5_nHgLbNOiwAAAjM"] [Tue Aug 18 12:56:02.557202 2026] [security2:error] [pid 67073:tid 67253] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjQAAAkQ"] [Tue Aug 18 12:56:02.562809 2026] [authz_core:error] [pid 67073:tid 67173] [remote 57.141.22.100:27296] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:02.563072 2026] [authz_core:error] [pid 67073:tid 67173] [remote 57.141.22.100:27296] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:02.571631 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/payout.php"] [unique_id "aoSAktO5rbWdOArH04KHvwAAAQ0"] [Tue Aug 18 12:56:02.575542 2026] [security2:error] [pid 67073:tid 67163] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjgACP1c"] [Tue Aug 18 12:56:02.586307 2026] [security2:error] [pid 67073:tid 67278] [client 20.151.109.219:64595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hj.php"] [unique_id "aoSAkvcmepr5_nHgLbNOjwAAAl0"] [Tue Aug 18 12:56:02.629816 2026] [security2:error] [pid 67073:tid 67310] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/34.php"] [unique_id "aoSAkvcmepr5_nHgLbNOkQAAAn0"] [Tue Aug 18 12:56:02.685020 2026] [security2:error] [pid 67073:tid 67238] [client 213.35.127.232:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAkvcmepr5_nHgLbNOkwAAAjU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:02.759769 2026] [security2:error] [pid 67073:tid 67268] [client 52.173.121.69:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/Cachex.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlQAAAlM"] [Tue Aug 18 12:56:02.766980 2026] [security2:error] [pid 67073:tid 67283] [client 20.79.204.6:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlgAAAmI"] [Tue Aug 18 12:56:02.779608 2026] [security2:error] [pid 67073:tid 67082] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fd.php"] [unique_id "aoSAkvcmepr5_nHgLbNOlwACUgY"] [Tue Aug 18 12:56:02.785768 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.130.103:15389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAktO5rbWdOArH04KHwQAAAUA"] [Tue Aug 18 12:56:02.820715 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:02.821129 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:02.887747 2026] [security2:error] [pid 67073:tid 67308] [client 4.232.151.198:29550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/nw.php"] [unique_id "aoSAkvcmepr5_nHgLbNOnQAAAns"] [Tue Aug 18 12:56:02.891886 2026] [security2:error] [pid 67073:tid 67297] [client 20.104.49.167:3582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAkvcmepr5_nHgLbNOngAAAnA"] [Tue Aug 18 12:56:02.895454 2026] [security2:error] [pid 67073:tid 67306] [client 20.163.43.14:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/function/function.php"] [unique_id "aoSAkvcmepr5_nHgLbNOnwAAAnk"] [Tue Aug 18 12:56:02.905670 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/he.php"] [unique_id "aoSAktO5rbWdOArH04KHwwAAAUY"] [Tue Aug 18 12:56:02.918747 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:24883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ij.php"] [unique_id "aoSAkvcmepr5_nHgLbNOoAAAAiE"] [Tue Aug 18 12:56:02.932546 2026] [security2:error] [pid 67073:tid 67234] [client 4.223.164.152:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/gec.php"] [unique_id "aoSAkvcmepr5_nHgLbNOoQAAAjE"] [Tue Aug 18 12:56:02.935797 2026] [security2:error] [pid 67073:tid 67325] [client 20.42.19.40:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/simple.php"] [unique_id "aoSAkvcmepr5_nHgLbNOogAAAow"] [Tue Aug 18 12:56:02.966494 2026] [security2:error] [pid 66623:tid 66813] [client 20.79.204.6:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSAktO5rbWdOArH04KHxQAAATk"] [Tue Aug 18 12:56:02.969353 2026] [security2:error] [pid 67073:tid 67216] [client 135.225.78.186:13026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/155.php"] [unique_id "aoSAkvcmepr5_nHgLbNOpwAAAh8"] [Tue Aug 18 12:56:02.985250 2026] [security2:error] [pid 67073:tid 67328] [client 4.223.164.152:46205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/insc.php"] [unique_id "aoSAkvcmepr5_nHgLbNOqQAAAo8"] [Tue Aug 18 12:56:03.018647 2026] [security2:error] [pid 67073:tid 67106] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/info2.php"] [unique_id "aoSAk_cmepr5_nHgLbNOrgACWx4"] [Tue Aug 18 12:56:03.077315 2026] [security2:error] [pid 67073:tid 67247] [client 20.42.19.40:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-act.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsQAAAj4"] [Tue Aug 18 12:56:03.112716 2026] [security2:error] [pid 67073:tid 67323] [client 192.141.172.134:59521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsgAAAoo"] [Tue Aug 18 12:56:03.112983 2026] [security2:error] [pid 67073:tid 67323] [client 192.141.172.134:59521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk_cmepr5_nHgLbNOsgAAAoo"] [Tue Aug 18 12:56:03.136007 2026] [security2:error] [pid 67073:tid 67296] [client 20.91.215.254:20715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/alfa-rex1.php"] [unique_id "aoSAk_cmepr5_nHgLbNOswAAAm8"] [Tue Aug 18 12:56:03.139321 2026] [security2:error] [pid 67073:tid 67285] [client 20.29.77.16:20843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/c99shell.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtAAAAmQ"] [Tue Aug 18 12:56:03.149716 2026] [security2:error] [pid 67073:tid 67312] [client 20.65.98.162:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/packed.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtQAAAn8"] [Tue Aug 18 12:56:03.161633 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gz.php"] [unique_id "aoSAk_cmepr5_nHgLbNOtwAAAk0"] [Tue Aug 18 12:56:03.168079 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/99.php"] [unique_id "aoSAk_cmepr5_nHgLbNOuAAAAoI"] [Tue Aug 18 12:56:03.211867 2026] [security2:error] [pid 67073:tid 67246] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/t.php"] [unique_id "aoSAk_cmepr5_nHgLbNOuQAAAj0"] [Tue Aug 18 12:56:03.226634 2026] [security2:error] [pid 66623:tid 66782] [client 20.151.109.219:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ud.php"] [unique_id "aoSAk9O5rbWdOArH04KHxwAAARo"] [Tue Aug 18 12:56:03.227674 2026] [security2:error] [pid 67073:tid 67274] [client 20.215.241.237:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/av.php"] [unique_id "aoSAk_cmepr5_nHgLbNOugAAAlk"] [Tue Aug 18 12:56:03.268186 2026] [security2:error] [pid 67073:tid 67191] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sx.php"] [unique_id "aoSAk_cmepr5_nHgLbNOvQACG3M"] [Tue Aug 18 12:56:03.296618 2026] [security2:error] [pid 66623:tid 66882] [client 20.116.17.175:57628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ohct.php"] [unique_id "aoSAk9O5rbWdOArH04KHyAAAAX4"] [Tue Aug 18 12:56:03.303486 2026] [security2:error] [pid 67073:tid 67229] [client 20.163.43.14:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAk_cmepr5_nHgLbNOwAAAAiw"] [Tue Aug 18 12:56:03.312184 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAk_cmepr5_nHgLbNOwQAAAnQ"] [Tue Aug 18 12:56:03.322096 2026] [autoindex:error] [pid 67073:tid 67222] [client 172.202.39.151:50187] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:03.325322 2026] [security2:error] [pid 67073:tid 67259] [client 79.127.164.8:38656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/lib.model.schema.sql"] [unique_id "aoSAk_cmepr5_nHgLbNOwwAAAko"], referer: https://medihub.com.br/lib.model.schema.sql [Tue Aug 18 12:56:03.330313 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:47157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/er.php"] [unique_id "aoSAk_cmepr5_nHgLbNOxAAAAi8"] [Tue Aug 18 12:56:03.366148 2026] [security2:error] [pid 67073:tid 67205] [client 4.223.164.152:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/sky.php"] [unique_id "aoSAk_cmepr5_nHgLbNOxgAAAhQ"] [Tue Aug 18 12:56:03.375600 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.156.252:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/ops.php"] [unique_id "aoSAk_cmepr5_nHgLbNOyAAAAis"] [Tue Aug 18 12:56:03.380416 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qk.php"] [unique_id "aoSAk_cmepr5_nHgLbNOyQAAAlg"] [Tue Aug 18 12:56:03.384931 2026] [security2:error] [pid 66623:tid 66888] [client 86.120.159.145:6251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KHyQAAAYQ"] [Tue Aug 18 12:56:03.385066 2026] [security2:error] [pid 66623:tid 66888] [client 86.120.159.145:6251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KHyQAAAYQ"] [Tue Aug 18 12:56:03.387141 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.69.59:3749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/php5.php"] [unique_id "aoSAk_cmepr5_nHgLbNOygAAApI"] [Tue Aug 18 12:56:03.391523 2026] [security2:error] [pid 67073:tid 67317] [client 135.225.78.186:13025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNOywAAAoQ"] [Tue Aug 18 12:56:03.420550 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:03.420852 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:03.423561 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nf.php"] [unique_id "aoSAk9O5rbWdOArH04KHygAAAS0"] [Tue Aug 18 12:56:03.469377 2026] [security2:error] [pid 67073:tid 67213] [client 85.208.98.55:16384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "i-databi.com.br"] [uri "/robots.txt"] [unique_id "aoSAk_cmepr5_nHgLbNOzgAAAhw"] [Tue Aug 18 12:56:03.469509 2026] [security2:error] [pid 67073:tid 67213] [client 85.208.98.55:16384] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "i-databi.com.br"] [uri "/robots.txt"] [unique_id "aoSAk_cmepr5_nHgLbNOzgAAAhw"] [Tue Aug 18 12:56:03.475056 2026] [security2:error] [pid 67073:tid 67255] [client 158.158.74.177:16555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mini.php"] [unique_id "aoSAk_cmepr5_nHgLbNOzwAAAkY"] [Tue Aug 18 12:56:03.521509 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.56.190:52050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAk9O5rbWdOArH04KHywAAAQw"] [Tue Aug 18 12:56:03.542011 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.6.191:38267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/an.php"] [unique_id "aoSAk9O5rbWdOArH04KHzAAAAX0"] [Tue Aug 18 12:56:03.569687 2026] [security2:error] [pid 66623:tid 66880] [client 20.151.109.219:21681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ip.php"] [unique_id "aoSAk9O5rbWdOArH04KHzQAAAXw"] [Tue Aug 18 12:56:03.571154 2026] [security2:error] [pid 67073:tid 67252] [client 20.100.169.31:7850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/nw.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1QAAAkM"] [Tue Aug 18 12:56:03.571625 2026] [security2:error] [pid 67073:tid 67261] [client 20.79.204.6:2388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1gAAAkw"] [Tue Aug 18 12:56:03.608416 2026] [security2:error] [pid 67073:tid 67326] [client 172.202.39.151:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/403.php"] [unique_id "aoSAk_cmepr5_nHgLbNO1wAAAo0"] [Tue Aug 18 12:56:03.629539 2026] [security2:error] [pid 66623:tid 66817] [client 158.23.17.4:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/Mailgun.php"] [unique_id "aoSAk9O5rbWdOArH04KHzgAAAT0"] [Tue Aug 18 12:56:03.664075 2026] [security2:error] [pid 67073:tid 67156] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nu.php"] [unique_id "aoSAk_cmepr5_nHgLbNO2wACZVA"] [Tue Aug 18 12:56:03.680027 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:33699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/hp.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3QAAAlI"] [Tue Aug 18 12:56:03.684064 2026] [security2:error] [pid 67073:tid 67226] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xv.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3gAAAik"] [Tue Aug 18 12:56:03.690651 2026] [security2:error] [pid 67073:tid 67264] [client 20.100.169.31:12962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/inputs.php"] [unique_id "aoSAk_cmepr5_nHgLbNO3wAAAk8"] [Tue Aug 18 12:56:03.707798 2026] [security2:error] [pid 67073:tid 67302] [client 213.35.127.232:51905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNO4QAAAnU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:03.709037 2026] [security2:error] [pid 67073:tid 67306] [client 68.155.154.236:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAk_cmepr5_nHgLbNO4gAAAnk"] [Tue Aug 18 12:56:03.776298 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.130.103:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/simple.php"] [unique_id "aoSAk_cmepr5_nHgLbNO5QAAAow"] [Tue Aug 18 12:56:03.804826 2026] [security2:error] [pid 67073:tid 67240] [client 20.215.241.237:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/k.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6AAAAjc"] [Tue Aug 18 12:56:03.807865 2026] [security2:error] [pid 66623:tid 66778] [client 135.225.78.186:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/aaa.php"] [unique_id "aoSAk9O5rbWdOArH04KHzwAAARY"] [Tue Aug 18 12:56:03.814201 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/sixxis.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6QAAAoM"] [Tue Aug 18 12:56:03.815807 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAk_cmepr5_nHgLbNO6gAAAnw"] [Tue Aug 18 12:56:03.835091 2026] [security2:error] [pid 66623:tid 66856] [client 4.223.164.152:28515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/file.php"] [unique_id "aoSAk9O5rbWdOArH04KH0QAAAWQ"] [Tue Aug 18 12:56:03.870931 2026] [security2:error] [pid 66623:tid 66807] [client 103.184.169.37:41808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KH0gAAATM"] [Tue Aug 18 12:56:03.871052 2026] [security2:error] [pid 66623:tid 66807] [client 103.184.169.37:41808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAk9O5rbWdOArH04KH0gAAATM"] [Tue Aug 18 12:56:03.883867 2026] [security2:error] [pid 66623:tid 66767] [client 20.151.109.219:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/99.php"] [unique_id "aoSAk9O5rbWdOArH04KH0wAAAQs"] [Tue Aug 18 12:56:03.891573 2026] [security2:error] [pid 67073:tid 67114] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ko.php"] [unique_id "aoSAk_cmepr5_nHgLbNO7gACaiY"] [Tue Aug 18 12:56:03.897293 2026] [security2:error] [pid 67073:tid 67253] [client 158.158.34.183:11512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSAk_cmepr5_nHgLbNO7wAAAkQ"] [Tue Aug 18 12:56:03.934251 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.49.167:35261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAk_cmepr5_nHgLbNO8QAAAhg"] [Tue Aug 18 12:56:03.945951 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mx.php"] [unique_id "aoSAk_cmepr5_nHgLbNO8gAAAnc"] [Tue Aug 18 12:56:03.981163 2026] [security2:error] [pid 67073:tid 67266] [client 52.173.121.69:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAk_cmepr5_nHgLbNO9AAAAlE"] [Tue Aug 18 12:56:03.996817 2026] [security2:error] [pid 66623:tid 66810] [client 20.91.215.254:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAk9O5rbWdOArH04KH1gAAATY"] [Tue Aug 18 12:56:04.024496 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:04.024924 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:04.086319 2026] [security2:error] [pid 67073:tid 67249] [client 20.29.77.16:47802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/profiler.php"] [unique_id "aoSAlPcmepr5_nHgLbNO-QAAAkA"] [Tue Aug 18 12:56:04.091054 2026] [security2:error] [pid 67073:tid 67227] [client 93.152.221.213:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSAlPcmepr5_nHgLbNO-gAAAio"], referer: https://t.co/ [Tue Aug 18 12:56:04.107655 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:2656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/minishell.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_AAAAnY"] [Tue Aug 18 12:56:04.108615 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.156.252:19061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/coffexium.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_QAAAjw"] [Tue Aug 18 12:56:04.143805 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/pl.php"] [unique_id "aoSAlPcmepr5_nHgLbNO_wACeCw"] [Tue Aug 18 12:56:04.182279 2026] [security2:error] [pid 67073:tid 67257] [client 135.225.75.187:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/file52.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAAAAAkg"] [Tue Aug 18 12:56:04.192507 2026] [security2:error] [pid 67073:tid 67237] [client 20.79.204.6:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAgAAAjQ"] [Tue Aug 18 12:56:04.200559 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/45.php"] [unique_id "aoSAlPcmepr5_nHgLbNPAwAAAiw"] [Tue Aug 18 12:56:04.208291 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:3029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ok.php"] [unique_id "aoSAlPcmepr5_nHgLbNPBAAAAnQ"] [Tue Aug 18 12:56:04.210028 2026] [security2:error] [pid 66623:tid 66792] [client 103.120.71.157:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlNO5rbWdOArH04KH1wAAASQ"] [Tue Aug 18 12:56:04.210156 2026] [security2:error] [pid 66623:tid 66792] [client 103.120.71.157:7703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlNO5rbWdOArH04KH1wAAASQ"] [Tue Aug 18 12:56:04.225556 2026] [security2:error] [pid 67073:tid 67259] [client 135.225.78.186:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/FWAZ.php"] [unique_id "aoSAlPcmepr5_nHgLbNPBgAAAko"] [Tue Aug 18 12:56:04.239489 2026] [security2:error] [pid 66623:tid 66803] [client 4.223.164.152:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/yj09.php"] [unique_id "aoSAlNO5rbWdOArH04KH2AAAAS8"] [Tue Aug 18 12:56:04.251233 2026] [security2:error] [pid 67073:tid 67205] [client 20.151.109.219:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/er.php"] [unique_id "aoSAlPcmepr5_nHgLbNPCAAAAhQ"] [Tue Aug 18 12:56:04.269125 2026] [security2:error] [pid 67073:tid 67295] [client 85.208.98.55:16384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "i-databi.com.br"] [uri "/poka-yoke-exemplos-praticos-para-evitar-erros/"] [unique_id "aoSAlPcmepr5_nHgLbNPCgAAAm4"] [Tue Aug 18 12:56:04.269226 2026] [security2:error] [pid 67073:tid 67295] [client 85.208.98.55:16384] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "i-databi.com.br"] [uri "/poka-yoke-exemplos-praticos-para-evitar-erros/"] [unique_id "aoSAlPcmepr5_nHgLbNPCgAAAm4"] [Tue Aug 18 12:56:04.282245 2026] [security2:error] [pid 67073:tid 67230] [client 5.161.177.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atekrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSAk_cmepr5_nHgLbNO2QACLW0"], referer: https://atekrefrigeracao.com.br/ [Tue Aug 18 12:56:04.290305 2026] [autoindex:error] [pid 67073:tid 67243] [client 20.226.6.191:36354] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:04.325307 2026] [security2:error] [pid 67073:tid 67215] [client 20.226.6.191:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/404.php"] [unique_id "aoSAlPcmepr5_nHgLbNPDgAAAh4"] [Tue Aug 18 12:56:04.328875 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:04.329336 2026] [authz_core:error] [pid 67073:tid 67134] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:04.343086 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/dex.php"] [unique_id "aoSAlPcmepr5_nHgLbNPEAAAAjM"] [Tue Aug 18 12:56:04.391300 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/env.php"] [unique_id "aoSAlPcmepr5_nHgLbNPEgACXjs"] [Tue Aug 18 12:56:04.419004 2026] [security2:error] [pid 66623:tid 66806] [client 20.42.19.40:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSAlNO5rbWdOArH04KH2gAAATI"] [Tue Aug 18 12:56:04.470751 2026] [security2:error] [pid 67073:tid 67332] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wy.php"] [unique_id "aoSAlPcmepr5_nHgLbNPFAAAApM"] [Tue Aug 18 12:56:04.479119 2026] [security2:error] [pid 66623:tid 66875] [client 20.100.169.31:18810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/admin.php"] [unique_id "aoSAlNO5rbWdOArH04KH2wAAAXc"] [Tue Aug 18 12:56:04.560692 2026] [security2:error] [pid 67073:tid 67264] [client 20.151.109.219:24840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qk.php"] [unique_id "aoSAlPcmepr5_nHgLbNPFwAAAk8"] [Tue Aug 18 12:56:04.580828 2026] [security2:error] [pid 66623:tid 66772] [client 20.65.69.59:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/Black.php"] [unique_id "aoSAlNO5rbWdOArH04KH3gAAARA"] [Tue Aug 18 12:56:04.583441 2026] [security2:error] [pid 67073:tid 67281] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/term.php"] [unique_id "aoSAlPcmepr5_nHgLbNPGQAAAmA"] [Tue Aug 18 12:56:04.584847 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/xleet.php"] [unique_id "aoSAlPcmepr5_nHgLbNPGgAAAoc"] [Tue Aug 18 12:56:04.601191 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.130.103:14434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/chosen.php"] [unique_id "aoSAlNO5rbWdOArH04KH3wAAARQ"] [Tue Aug 18 12:56:04.602825 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mz.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHAACeRw"] [Tue Aug 18 12:56:04.616983 2026] [security2:error] [pid 66623:tid 66773] [client 20.226.6.191:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-login.php"] [unique_id "aoSAlNO5rbWdOArH04KH4AAAARE"] [Tue Aug 18 12:56:04.643083 2026] [security2:error] [pid 66623:tid 66836] [client 135.225.78.186:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/site.php"] [unique_id "aoSAlNO5rbWdOArH04KH4gAAAVA"] [Tue Aug 18 12:56:04.647577 2026] [security2:error] [pid 67073:tid 67256] [client 138.36.100.162:43228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHgAAAkc"] [Tue Aug 18 12:56:04.647666 2026] [security2:error] [pid 67073:tid 67256] [client 138.36.100.162:43228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPHgAAAkc"] [Tue Aug 18 12:56:04.661593 2026] [security2:error] [pid 67073:tid 67270] [client 20.163.43.14:4412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/item.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIAAAAlU"] [Tue Aug 18 12:56:04.666314 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/k.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIQAAAhU"] [Tue Aug 18 12:56:04.667626 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.56.190:3066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fs.php"] [unique_id "aoSAlNO5rbWdOArH04KH4wAAAXI"] [Tue Aug 18 12:56:04.712237 2026] [security2:error] [pid 67073:tid 67286] [client 20.91.215.254:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/xmrlpc.php"] [unique_id "aoSAlPcmepr5_nHgLbNPIgAAAmU"] [Tue Aug 18 12:56:04.724171 2026] [security2:error] [pid 67073:tid 67277] [client 213.35.127.232:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJAAAAlw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:04.725899 2026] [security2:error] [pid 66623:tid 66871] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/f.php"] [unique_id "aoSAlNO5rbWdOArH04KH5QAAAXM"] [Tue Aug 18 12:56:04.734109 2026] [security2:error] [pid 67073:tid 67325] [client 132.196.61.152:61000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/sf.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJQAAAow"] [Tue Aug 18 12:56:04.770492 2026] [security2:error] [pid 67073:tid 67241] [client 4.223.164.152:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/key.php"] [unique_id "aoSAlPcmepr5_nHgLbNPJwAAAjg"] [Tue Aug 18 12:56:04.782123 2026] [security2:error] [pid 67073:tid 67316] [client 20.42.19.40:2902] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/js/"] [unique_id "aoSAlPcmepr5_nHgLbNPKAAAAoM"] [Tue Aug 18 12:56:04.801454 2026] [security2:error] [pid 67073:tid 67297] [client 20.79.204.6:2225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSAlPcmepr5_nHgLbNPKQAAAnA"] [Tue Aug 18 12:56:04.812371 2026] [security2:error] [pid 67073:tid 67172] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ft.php"] [unique_id "aoSAlPcmepr5_nHgLbNPKgACH2A"] [Tue Aug 18 12:56:04.844398 2026] [security2:error] [pid 67073:tid 67291] [client 20.116.17.175:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ot.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLAAAAmo"] [Tue Aug 18 12:56:04.847085 2026] [security2:error] [pid 67073:tid 67302] [client 158.158.74.177:2644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/mm.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLQAAAnU"] [Tue Aug 18 12:56:04.847329 2026] [security2:error] [pid 66623:tid 66883] [client 20.151.109.219:24847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAlNO5rbWdOArH04KH5wAAAX8"] [Tue Aug 18 12:56:04.862048 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLgAAAiI"] [Tue Aug 18 12:56:04.899060 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:38899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/oauth.php"] [unique_id "aoSAlPcmepr5_nHgLbNPLwAAAhg"] [Tue Aug 18 12:56:04.997909 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/30.php"] [unique_id "aoSAlNO5rbWdOArH04KH6AAAAUQ"] [Tue Aug 18 12:56:05.044993 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNAAAAm8"] [Tue Aug 18 12:56:05.047668 2026] [security2:error] [pid 67073:tid 67089] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/h.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNQACZA0"] [Tue Aug 18 12:56:05.061554 2026] [security2:error] [pid 66623:tid 66781] [client 135.225.78.186:40819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/ccc.php"] [unique_id "aoSAldO5rbWdOArH04KH6QAAARk"] [Tue Aug 18 12:56:05.095172 2026] [security2:error] [pid 67073:tid 67318] [client 4.223.164.152:4857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/w.php"] [unique_id "aoSAlfcmepr5_nHgLbNPNgAAAoU"] [Tue Aug 18 12:56:05.162339 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:65006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fs.php"] [unique_id "aoSAlfcmepr5_nHgLbNPOAAAAmI"] [Tue Aug 18 12:56:05.174771 2026] [security2:error] [pid 66623:tid 66884] [client 5.31.227.224:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAldO5rbWdOArH04KH6gAAAYA"] [Tue Aug 18 12:56:05.178777 2026] [security2:error] [pid 66623:tid 66884] [client 5.31.227.224:30445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAldO5rbWdOArH04KH6gAAAYA"] [Tue Aug 18 12:56:05.222907 2026] [security2:error] [pid 66623:tid 66848] [client 4.223.164.152:39789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/kir.php"] [unique_id "aoSAldO5rbWdOArH04KH6wAAAVw"] [Tue Aug 18 12:56:05.227329 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:05.227610 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:05.232707 2026] [security2:error] [pid 67073:tid 67246] [client 20.51.153.15:9140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/nu.php"] [unique_id "aoSAlfcmepr5_nHgLbNPOwAAAj0"] [Tue Aug 18 12:56:05.245495 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pu.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPAAAAjw"] [Tue Aug 18 12:56:05.261931 2026] [security2:error] [pid 67073:tid 67158] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/40.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPQACWVI"] [Tue Aug 18 12:56:05.264808 2026] [security2:error] [pid 67073:tid 67305] [client 135.225.75.187:9804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPgAAAng"] [Tue Aug 18 12:56:05.267782 2026] [security2:error] [pid 67073:tid 67313] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/test.php"] [unique_id "aoSAlfcmepr5_nHgLbNPPwAAAoA"] [Tue Aug 18 12:56:05.296304 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.56.190:45035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rb.php"] [unique_id "aoSAldO5rbWdOArH04KH7AAAAYM"] [Tue Aug 18 12:56:05.314457 2026] [security2:error] [pid 67073:tid 67278] [client 74.248.18.37:28831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ncx.php"] [unique_id "aoSAlfcmepr5_nHgLbNPQgAAAl0"] [Tue Aug 18 12:56:05.342160 2026] [security2:error] [pid 67073:tid 67292] [client 20.100.169.31:47387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp.php"] [unique_id "aoSAlfcmepr5_nHgLbNPQwAAAms"] [Tue Aug 18 12:56:05.369200 2026] [security2:error] [pid 67073:tid 67095] [remote 115.146.125.52:43470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRAACMRM"] [Tue Aug 18 12:56:05.396002 2026] [security2:error] [pid 67073:tid 67295] [client 20.29.77.16:52799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/findes.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRwAAAm4"] [Tue Aug 18 12:56:05.396144 2026] [security2:error] [pid 67073:tid 67205] [client 20.171.51.14:62517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wx.php"] [unique_id "aoSAlfcmepr5_nHgLbNPRgAAAhQ"] [Tue Aug 18 12:56:05.420488 2026] [security2:error] [pid 67073:tid 67315] [client 20.91.215.254:12113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAlfcmepr5_nHgLbNPSQAAAoI"] [Tue Aug 18 12:56:05.442524 2026] [security2:error] [pid 67073:tid 67322] [client 20.215.241.237:45778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/82.php"] [unique_id "aoSAlfcmepr5_nHgLbNPSwAAAok"] [Tue Aug 18 12:56:05.443622 2026] [security2:error] [pid 67073:tid 67250] [client 20.151.109.219:12913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rb.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTAAAAkE"] [Tue Aug 18 12:56:05.451698 2026] [security2:error] [pid 67073:tid 67303] [client 20.79.204.6:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTQAAAnY"] [Tue Aug 18 12:56:05.483415 2026] [security2:error] [pid 67073:tid 67215] [client 135.225.78.186:40768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/admin.php"] [unique_id "aoSAlfcmepr5_nHgLbNPTwAAAh4"] [Tue Aug 18 12:56:05.495655 2026] [security2:error] [pid 67073:tid 67271] [client 20.104.49.167:36311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAlfcmepr5_nHgLbNPUgAAAlY"] [Tue Aug 18 12:56:05.502691 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.74.177:16556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAlfcmepr5_nHgLbNPUwAAAiA"] [Tue Aug 18 12:56:05.503774 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ry.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVAAAAho"] [Tue Aug 18 12:56:05.523686 2026] [security2:error] [pid 67073:tid 67321] [client 4.223.164.152:4818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/fpwch.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVgAAAog"] [Tue Aug 18 12:56:05.531320 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:05.531628 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:05.531852 2026] [security2:error] [pid 67073:tid 67105] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ee.php"] [unique_id "aoSAlfcmepr5_nHgLbNPVwACWh0"] [Tue Aug 18 12:56:05.531965 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.130.103:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/als.php"] [unique_id "aoSAlfcmepr5_nHgLbNPWAAAAnI"] [Tue Aug 18 12:56:05.543216 2026] [security2:error] [pid 67073:tid 67289] [client 68.155.156.252:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAlfcmepr5_nHgLbNPWQAAAmg"] [Tue Aug 18 12:56:05.589699 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:37305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/images.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXAAAAiU"] [Tue Aug 18 12:56:05.607907 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.56.190:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/37.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXQAAAhY"] [Tue Aug 18 12:56:05.617973 2026] [security2:error] [pid 67073:tid 67212] [client 4.232.151.198:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/xleet.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXgAAAhs"] [Tue Aug 18 12:56:05.630062 2026] [security2:error] [pid 67073:tid 67287] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/test1.php"] [unique_id "aoSAlfcmepr5_nHgLbNPXwAAAmY"] [Tue Aug 18 12:56:05.658418 2026] [security2:error] [pid 67073:tid 67281] [client 4.223.164.152:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/nofile.php"] [unique_id "aoSAlfcmepr5_nHgLbNPYAAAAmA"] [Tue Aug 18 12:56:05.739084 2026] [security2:error] [pid 67073:tid 67206] [client 52.173.121.69:16505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZAAAAhU"] [Tue Aug 18 12:56:05.741519 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZQAAAi0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:05.745650 2026] [security2:error] [pid 67073:tid 67220] [client 20.151.109.219:21649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/37.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZgAAAiM"] [Tue Aug 18 12:56:05.755899 2026] [security2:error] [pid 67073:tid 67218] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pm.php"] [unique_id "aoSAlfcmepr5_nHgLbNPZwAAAiE"] [Tue Aug 18 12:56:05.804872 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:16256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAlfcmepr5_nHgLbNPaQAAAlw"] [Tue Aug 18 12:56:05.813802 2026] [security2:error] [pid 67073:tid 67198] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ak.php"] [unique_id "aoSAlfcmepr5_nHgLbNPagACN3o"] [Tue Aug 18 12:56:05.858995 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/md.php"] [unique_id "aoSAlfcmepr5_nHgLbNPbQAAAnA"] [Tue Aug 18 12:56:05.901856 2026] [security2:error] [pid 67073:tid 67219] [client 135.225.78.186:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/reviall.php"] [unique_id "aoSAlfcmepr5_nHgLbNPbwAAAiI"] [Tue Aug 18 12:56:05.956647 2026] [security2:error] [pid 66623:tid 66873] [client 4.223.164.152:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAldO5rbWdOArH04KH8QAAAXU"] [Tue Aug 18 12:56:05.958616 2026] [security2:error] [pid 67073:tid 67214] [client 20.171.51.14:51797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/dj.php"] [unique_id "aoSAlfcmepr5_nHgLbNPcQAAAh0"] [Tue Aug 18 12:56:06.022127 2026] [authz_core:error] [pid 66623:tid 66700] [remote 57.141.22.34:61818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:06.022423 2026] [authz_core:error] [pid 66623:tid 66700] [remote 57.141.22.34:61818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:06.061225 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dr.php"] [unique_id "aoSAlvcmepr5_nHgLbNPdgAAAkA"] [Tue Aug 18 12:56:06.071323 2026] [security2:error] [pid 67073:tid 67227] [client 20.151.109.219:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/md.php"] [unique_id "aoSAlvcmepr5_nHgLbNPeAAAAio"] [Tue Aug 18 12:56:06.078661 2026] [autoindex:error] [pid 67073:tid 67282] [client 20.226.6.191:32292] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:06.087050 2026] [security2:error] [pid 67073:tid 67142] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/test_info.php"] [unique_id "aoSAlvcmepr5_nHgLbNPeQACPUI"] [Tue Aug 18 12:56:06.097487 2026] [security2:error] [pid 67073:tid 67245] [client 20.104.49.167:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/av.php"] [unique_id "aoSAlvcmepr5_nHgLbNPegAAAjw"] [Tue Aug 18 12:56:06.124324 2026] [security2:error] [pid 67073:tid 67237] [client 20.42.19.40:2216] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSAlvcmepr5_nHgLbNPfgAAAjQ"] [Tue Aug 18 12:56:06.146289 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/iy.php"] [unique_id "aoSAlvcmepr5_nHgLbNPgQAAAiw"] [Tue Aug 18 12:56:06.146950 2026] [autoindex:error] [pid 67073:tid 67301] [client 172.202.39.151:65226] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:06.150853 2026] [security2:error] [pid 67073:tid 67327] [client 157.20.138.62:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPggAAAo4"] [Tue Aug 18 12:56:06.150956 2026] [security2:error] [pid 67073:tid 67327] [client 157.20.138.62:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPggAAAo4"] [Tue Aug 18 12:56:06.185673 2026] [security2:error] [pid 67073:tid 67259] [client 104.209.144.33:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAlvcmepr5_nHgLbNPgwAAAko"] [Tue Aug 18 12:56:06.216601 2026] [autoindex:error] [pid 67073:tid 67329] [client 20.226.6.191:32292] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:06.223220 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.6.191:32292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wso.php"] [unique_id "aoSAlvcmepr5_nHgLbNPhgAAAhQ"] [Tue Aug 18 12:56:06.241204 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:2672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ms-themes.php"] [unique_id "aoSAlvcmepr5_nHgLbNPiAAAAno"] [Tue Aug 18 12:56:06.252259 2026] [autoindex:error] [pid 67073:tid 67234] [client 172.202.39.151:12687] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:06.289239 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:7657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/155.php"] [unique_id "aoSAlvcmepr5_nHgLbNPiwAAAjU"] [Tue Aug 18 12:56:06.290952 2026] [security2:error] [pid 67073:tid 67271] [client 20.116.17.175:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/v5.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjAAAAlY"] [Tue Aug 18 12:56:06.292110 2026] [security2:error] [pid 67073:tid 67217] [client 135.225.75.187:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/path.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjQAAAiA"] [Tue Aug 18 12:56:06.292560 2026] [security2:error] [pid 67073:tid 67211] [client 68.155.156.252:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/sf.php"] [unique_id "aoSAlvcmepr5_nHgLbNPjgAAAho"] [Tue Aug 18 12:56:06.324703 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:49243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/ops.php"] [unique_id "aoSAltO5rbWdOArH04KH8wAAAVo"] [Tue Aug 18 12:56:06.326998 2026] [security2:error] [pid 67073:tid 67275] [client 4.223.164.152:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/fling.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkAAAAlo"] [Tue Aug 18 12:56:06.327292 2026] [security2:error] [pid 67073:tid 67299] [client 135.225.78.186:13037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/nope.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkQAAAnI"] [Tue Aug 18 12:56:06.330711 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.130.103:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/nox.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkgAAAhw"] [Tue Aug 18 12:56:06.331197 2026] [security2:error] [pid 67073:tid 67289] [client 20.91.215.254:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/ku.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlAAAAmg"] [Tue Aug 18 12:56:06.331379 2026] [security2:error] [pid 67073:tid 67174] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/14.php"] [unique_id "aoSAlvcmepr5_nHgLbNPkwACP2I"] [Tue Aug 18 12:56:06.333949 2026] [security2:error] [pid 67073:tid 67255] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ts.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlQAAAkY"] [Tue Aug 18 12:56:06.357893 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAlvcmepr5_nHgLbNPlgAAAjs"] [Tue Aug 18 12:56:06.383713 2026] [security2:error] [pid 67073:tid 67293] [client 4.223.164.152:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/blurbs.php"] [unique_id "aoSAlvcmepr5_nHgLbNPmAAAAmw"] [Tue Aug 18 12:56:06.422993 2026] [security2:error] [pid 67073:tid 67292] [client 4.232.151.198:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.comatmotos.com.br"] [uri "/wp.php"] [unique_id "aoSAlvcmepr5_nHgLbNPmQAAAms"] [Tue Aug 18 12:56:06.446838 2026] [autoindex:error] [pid 67073:tid 67222] [client 172.202.39.151:65226] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:06.448609 2026] [security2:error] [pid 67073:tid 67224] [client 20.51.153.15:8727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/pl.php"] [unique_id "aoSAlvcmepr5_nHgLbNPnAAAAic"] [Tue Aug 18 12:56:06.460629 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/iy.php"] [unique_id "aoSAlvcmepr5_nHgLbNPnQAAAjo"] [Tue Aug 18 12:56:06.462538 2026] [security2:error] [pid 67073:tid 67251] [client 20.250.13.23:19518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/u.php"] [unique_id "aoSAlvcmepr5_nHgLbNPngAAAkI"] [Tue Aug 18 12:56:06.482482 2026] [security2:error] [pid 67073:tid 67208] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPigACFw4"] [Tue Aug 18 12:56:06.487497 2026] [security2:error] [pid 67073:tid 67247] [client 20.100.169.31:29619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/goods.php"] [unique_id "aoSAlvcmepr5_nHgLbNPoQAAAj4"] [Tue Aug 18 12:56:06.525019 2026] [security2:error] [pid 67073:tid 67226] [client 20.42.19.40:2704] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/maint/"] [unique_id "aoSAlvcmepr5_nHgLbNPowAAAik"] [Tue Aug 18 12:56:06.530702 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tk.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpAACT0k"] [Tue Aug 18 12:56:06.537062 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.61.152:61043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/xx.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpQAAAiY"] [Tue Aug 18 12:56:06.562182 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:12687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/404.php"] [unique_id "aoSAlvcmepr5_nHgLbNPpwAAAi0"] [Tue Aug 18 12:56:06.595105 2026] [security2:error] [pid 67073:tid 67210] [client 172.202.39.151:65226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/gecko.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqAAAAhk"] [Tue Aug 18 12:56:06.595818 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/53.php"] [unique_id "aoSAltO5rbWdOArH04KH9QAAAW8"] [Tue Aug 18 12:56:06.608633 2026] [security2:error] [pid 67073:tid 67240] [client 20.226.56.190:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/og.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqgAAAjc"] [Tue Aug 18 12:56:06.626116 2026] [security2:error] [pid 67073:tid 67280] [client 114.5.214.109:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqwAAAl8"] [Tue Aug 18 12:56:06.626238 2026] [security2:error] [pid 67073:tid 67280] [client 114.5.214.109:49808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAlvcmepr5_nHgLbNPqwAAAl8"] [Tue Aug 18 12:56:06.637755 2026] [security2:error] [pid 67073:tid 67276] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tfm.php"] [unique_id "aoSAlvcmepr5_nHgLbNPrAAAAls"] [Tue Aug 18 12:56:06.687060 2026] [security2:error] [pid 66623:tid 66874] [client 158.23.17.4:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/timeclock.php"] [unique_id "aoSAltO5rbWdOArH04KH9wAAAXY"] [Tue Aug 18 12:56:06.723074 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.56.190:23744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lp.php"] [unique_id "aoSAltO5rbWdOArH04KH-QAAAWg"] [Tue Aug 18 12:56:06.733663 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:06.734036 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:06.744392 2026] [security2:error] [pid 67073:tid 67214] [client 135.225.78.186:13020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/nope.php"] [unique_id "aoSAlvcmepr5_nHgLbNPrwAAAh0"] [Tue Aug 18 12:56:06.758479 2026] [security2:error] [pid 66623:tid 66783] [client 213.35.127.232:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAltO5rbWdOArH04KH-gAAARs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:06.762822 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/hp.php"] [unique_id "aoSAlvcmepr5_nHgLbNPsQACbzU"] [Tue Aug 18 12:56:06.776794 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.6.191:32301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/sf.php"] [unique_id "aoSAltO5rbWdOArH04KH-wAAAXo"] [Tue Aug 18 12:56:06.796889 2026] [security2:error] [pid 66623:tid 66808] [client 149.34.210.141:51839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAltO5rbWdOArH04KH_QAAATQ"] [Tue Aug 18 12:56:06.798138 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:21686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/og.php"] [unique_id "aoSAlvcmepr5_nHgLbNPswAAAmI"] [Tue Aug 18 12:56:06.816912 2026] [security2:error] [pid 66623:tid 66854] [client 4.223.164.152:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/100.php"] [unique_id "aoSAltO5rbWdOArH04KH_gAAAWI"] [Tue Aug 18 12:56:06.857914 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lq.php"] [unique_id "aoSAlvcmepr5_nHgLbNPtQAAAlk"] [Tue Aug 18 12:56:06.867978 2026] [security2:error] [pid 67073:tid 67257] [client 4.223.164.152:28529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/zoo1.php"] [unique_id "aoSAlvcmepr5_nHgLbNPtwAAAkg"] [Tue Aug 18 12:56:06.877034 2026] [security2:error] [pid 67073:tid 67278] [client 74.248.130.103:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file59.php"] [unique_id "aoSAlvcmepr5_nHgLbNPuQAAAl0"] [Tue Aug 18 12:56:06.919510 2026] [security2:error] [pid 66623:tid 66814] [client 52.238.210.254:9042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mirenax.com.br"] [uri "/buy.php"] [unique_id "aoSAltO5rbWdOArH04KH_wAAATo"] [Tue Aug 18 12:56:06.926464 2026] [security2:error] [pid 67073:tid 67229] [client 20.79.204.6:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAlvcmepr5_nHgLbNPugAAAiw"] [Tue Aug 18 12:56:06.928682 2026] [security2:error] [pid 66623:tid 66796] [client 104.209.144.33:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAltO5rbWdOArH04KIAQAAASg"] [Tue Aug 18 12:56:06.929227 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAltO5rbWdOArH04KIAgAAAXE"] [Tue Aug 18 12:56:06.931868 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.127:64090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:06.932134 2026] [authz_core:error] [pid 66623:tid 66644] [remote 57.141.22.127:64090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:06.935569 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSAltO5rbWdOArH04KIAwAAAYI"] [Tue Aug 18 12:56:06.942083 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.49.167:19384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/images.php"] [unique_id "aoSAlvcmepr5_nHgLbNPuwAAAnQ"] [Tue Aug 18 12:56:06.948453 2026] [security2:error] [pid 66623:tid 66784] [client 20.42.19.40:2724] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-admin/"] [unique_id "aoSAltO5rbWdOArH04KIBAAAARw"] [Tue Aug 18 12:56:06.977653 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wx.php"] [unique_id "aoSAlvcmepr5_nHgLbNPvQACKxY"] [Tue Aug 18 12:56:06.981988 2026] [security2:error] [pid 67073:tid 67329] [client 20.171.51.14:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fa.php"] [unique_id "aoSAlvcmepr5_nHgLbNPvgAAApA"] [Tue Aug 18 12:56:07.057023 2026] [security2:error] [pid 66623:tid 66843] [client 135.225.75.187:9801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wpo.php"] [unique_id "aoSAl9O5rbWdOArH04KIBQAAAVc"] [Tue Aug 18 12:56:07.063655 2026] [security2:error] [pid 67073:tid 67273] [client 68.155.156.252:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/k.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxAAAAlg"] [Tue Aug 18 12:56:07.072411 2026] [security2:error] [pid 66623:tid 66808] [client 149.34.210.141:51839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAltO5rbWdOArH04KH_QAAATQ"] [Tue Aug 18 12:56:07.077042 2026] [security2:error] [pid 66623:tid 66785] [client 20.226.56.190:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ey.php"] [unique_id "aoSAl9O5rbWdOArH04KIBgAAAR0"] [Tue Aug 18 12:56:07.089478 2026] [security2:error] [pid 67073:tid 67307] [client 20.51.153.15:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mz.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxgAAAno"] [Tue Aug 18 12:56:07.089926 2026] [security2:error] [pid 67073:tid 67282] [client 158.158.74.177:2660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/my1.php"] [unique_id "aoSAl_cmepr5_nHgLbNPxwAAAmE"] [Tue Aug 18 12:56:07.120218 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/you.php"] [unique_id "aoSAl_cmepr5_nHgLbNPyAAAAjU"] [Tue Aug 18 12:56:07.123230 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.6.191:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/index/function.php"] [unique_id "aoSAl_cmepr5_nHgLbNPyQAAAlY"] [Tue Aug 18 12:56:07.130207 2026] [security2:error] [pid 66623:tid 66881] [client 20.151.109.219:21632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lp.php"] [unique_id "aoSAl9O5rbWdOArH04KIBwAAAX0"] [Tue Aug 18 12:56:07.161574 2026] [security2:error] [pid 67073:tid 67321] [client 135.225.78.186:13000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/new.php"] [unique_id "aoSAl_cmepr5_nHgLbNPzAAAAog"] [Tue Aug 18 12:56:07.185813 2026] [security2:error] [pid 67073:tid 67275] [client 20.29.77.16:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/fedora.php"] [unique_id "aoSAl_cmepr5_nHgLbNPzQAAAlo"] [Tue Aug 18 12:56:07.238559 2026] [security2:error] [pid 67073:tid 67125] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/dj.php"] [unique_id "aoSAl_cmepr5_nHgLbNP3AACTjE"] [Tue Aug 18 12:56:07.247931 2026] [security2:error] [pid 67073:tid 67293] [client 20.91.215.254:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/chosen.php"] [unique_id "aoSAl_cmepr5_nHgLbNP3gAAAmw"] [Tue Aug 18 12:56:07.257780 2026] [security2:error] [pid 66623:tid 66817] [client 4.223.164.152:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/ccc.php"] [unique_id "aoSAl9O5rbWdOArH04KICQAAAT0"] [Tue Aug 18 12:56:07.267659 2026] [security2:error] [pid 66623:tid 66825] [client 20.226.56.190:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lv.php"] [unique_id "aoSAl9O5rbWdOArH04KICgAAAUU"] [Tue Aug 18 12:56:07.284044 2026] [authz_core:error] [pid 66623:tid 66753] [remote 57.141.22.42:54386] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.284487 2026] [authz_core:error] [pid 66623:tid 66753] [remote 57.141.22.42:54386] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.335565 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.335849 2026] [authz_core:error] [pid 67073:tid 67194] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.340965 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/coffexium.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5AAAAo0"] [Tue Aug 18 12:56:07.361187 2026] [security2:error] [pid 67073:tid 67251] [client 20.226.56.190:47149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/51.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5QAAAkI"] [Tue Aug 18 12:56:07.365217 2026] [security2:error] [pid 67073:tid 67287] [client 158.158.34.183:25681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/o.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5gAAAmY"] [Tue Aug 18 12:56:07.366764 2026] [security2:error] [pid 67073:tid 67231] [client 20.51.153.15:9159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ft.php"] [unique_id "aoSAl_cmepr5_nHgLbNP5wAAAi4"] [Tue Aug 18 12:56:07.373580 2026] [security2:error] [pid 66623:tid 66810] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ez.php"] [unique_id "aoSAl9O5rbWdOArH04KIGwAAATY"] [Tue Aug 18 12:56:07.373859 2026] [security2:error] [pid 66623:tid 66872] [client 20.215.241.237:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/dex.php"] [unique_id "aoSAl9O5rbWdOArH04KIHAAAAXQ"] [Tue Aug 18 12:56:07.382887 2026] [security2:error] [pid 67073:tid 67290] [client 213.202.253.4:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAl_cmepr5_nHgLbNP6QAAAmk"], referer: www.google.com [Tue Aug 18 12:56:07.384019 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.6.191:39423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/edit.php"] [unique_id "aoSAl9O5rbWdOArH04KIHQAAAVE"] [Tue Aug 18 12:56:07.449998 2026] [security2:error] [pid 66623:tid 66792] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/thebe.php"] [unique_id "aoSAl9O5rbWdOArH04KIHgAAASQ"] [Tue Aug 18 12:56:07.486574 2026] [authz_core:error] [pid 66623:tid 66742] [remote 57.141.22.92:60988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.486876 2026] [authz_core:error] [pid 66623:tid 66742] [remote 57.141.22.92:60988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.487539 2026] [security2:error] [pid 67073:tid 67196] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fa.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7AACT3g"] [Tue Aug 18 12:56:07.495410 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.156.252:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/82.php"] [unique_id "aoSAl9O5rbWdOArH04KIIAAAAT8"] [Tue Aug 18 12:56:07.499614 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ey.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7QAAAmA"] [Tue Aug 18 12:56:07.510951 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.100:46124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.511263 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.100:46124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.533848 2026] [security2:error] [pid 67073:tid 67212] [client 20.79.204.6:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/akc.php"] [unique_id "aoSAl_cmepr5_nHgLbNP7wAAAhs"] [Tue Aug 18 12:56:07.547338 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAl9O5rbWdOArH04KIIgAAAXc"] [Tue Aug 18 12:56:07.562068 2026] [security2:error] [pid 66623:tid 66805] [client 158.23.17.4:33474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/email.php"] [unique_id "aoSAl9O5rbWdOArH04KIIwAAATE"] [Tue Aug 18 12:56:07.582962 2026] [security2:error] [pid 66623:tid 66772] [client 135.225.78.186:13027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/new.php"] [unique_id "aoSAl9O5rbWdOArH04KIJAAAARA"] [Tue Aug 18 12:56:07.606753 2026] [security2:error] [pid 67073:tid 67206] [client 4.223.164.152:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/zoo2.php"] [unique_id "aoSAl_cmepr5_nHgLbNP8QAAAhU"] [Tue Aug 18 12:56:07.625052 2026] [security2:error] [pid 66623:tid 66865] [client 20.52.168.85:7814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/aged.php"] [unique_id "aoSAl9O5rbWdOArH04KIKQAAAW0"] [Tue Aug 18 12:56:07.639683 2026] [security2:error] [pid 67073:tid 67286] [client 20.42.19.40:2696] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/"] [unique_id "aoSAl_cmepr5_nHgLbNP9QAAAmU"] [Tue Aug 18 12:56:07.641012 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.641486 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.645769 2026] [security2:error] [pid 67073:tid 67218] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/asus.php"] [unique_id "aoSAl_cmepr5_nHgLbNP9gAAAiE"] [Tue Aug 18 12:56:07.651311 2026] [security2:error] [pid 67073:tid 67328] [client 20.116.17.175:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSAl_cmepr5_nHgLbNP9wAAAo8"] [Tue Aug 18 12:56:07.660026 2026] [security2:error] [pid 67073:tid 67277] [client 132.196.61.152:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/uwu.php"] [unique_id "aoSAl_cmepr5_nHgLbNP-AAAAlw"] [Tue Aug 18 12:56:07.680714 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/get.php"] [unique_id "aoSAl_cmepr5_nHgLbNP-QAAAhk"] [Tue Aug 18 12:56:07.685422 2026] [security2:error] [pid 66623:tid 66802] [client 20.51.153.15:8784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/h.php"] [unique_id "aoSAl9O5rbWdOArH04KIMAAAAS4"] [Tue Aug 18 12:56:07.751752 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/fb.php"] [unique_id "aoSAl_cmepr5_nHgLbNQBAACajc"] [Tue Aug 18 12:56:07.773418 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAl9O5rbWdOArH04KINQAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:07.786858 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.130.103:14441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/admin.php"] [unique_id "aoSAl_cmepr5_nHgLbNQBgAAAiI"] [Tue Aug 18 12:56:07.789314 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.49.167:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ops.php"] [unique_id "aoSAl9O5rbWdOArH04KINgAAAUk"] [Tue Aug 18 12:56:07.822923 2026] [security2:error] [pid 67073:tid 67209] [client 20.151.109.219:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lv.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCAAAAhg"] [Tue Aug 18 12:56:07.885785 2026] [security2:error] [pid 67073:tid 67325] [client 178.153.171.161:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCQAAAow"] [Tue Aug 18 12:56:07.885932 2026] [security2:error] [pid 67073:tid 67325] [client 178.153.171.161:62947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCQAAAow"] [Tue Aug 18 12:56:07.893602 2026] [security2:error] [pid 67073:tid 67279] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/22.php"] [unique_id "aoSAl_cmepr5_nHgLbNQCwAAAl4"] [Tue Aug 18 12:56:07.937500 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:07.937805 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:07.960613 2026] [security2:error] [pid 67073:tid 67268] [client 20.91.215.254:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/asd.php"] [unique_id "aoSAl_cmepr5_nHgLbNQDgAAAlM"] [Tue Aug 18 12:56:07.979566 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.156.252:24923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/dex.php"] [unique_id "aoSAl_cmepr5_nHgLbNQDwAAAig"] [Tue Aug 18 12:56:07.980696 2026] [security2:error] [pid 67073:tid 67096] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gw.php"] [unique_id "aoSAl_cmepr5_nHgLbNQEQACYhQ"] [Tue Aug 18 12:56:08.000451 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.78.186:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/apreset.php"] [unique_id "aoSAl_cmepr5_nHgLbNQEwAAAlE"] [Tue Aug 18 12:56:08.028621 2026] [security2:error] [pid 66623:tid 66893] [client 20.51.153.15:8805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/40.php"] [unique_id "aoSAmNO5rbWdOArH04KIOQAAAYk"] [Tue Aug 18 12:56:08.038556 2026] [security2:error] [pid 66623:tid 66809] [client 4.223.164.152:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/org.php"] [unique_id "aoSAmNO5rbWdOArH04KIOwAAATU"] [Tue Aug 18 12:56:08.039370 2026] [security2:error] [pid 66623:tid 66887] [client 135.225.75.187:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/a1vx.php"] [unique_id "aoSAmNO5rbWdOArH04KIPAAAAYM"] [Tue Aug 18 12:56:08.098304 2026] [security2:error] [pid 67073:tid 67301] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/themes.php"] [unique_id "aoSAmPcmepr5_nHgLbNQFwAAAnQ"] [Tue Aug 18 12:56:08.098854 2026] [security2:error] [pid 67073:tid 67327] [client 4.223.164.152:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/images.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGAAAAo4"] [Tue Aug 18 12:56:08.132884 2026] [security2:error] [pid 67073:tid 67228] [client 20.151.109.219:45743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/51.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGQAAAis"] [Tue Aug 18 12:56:08.143516 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zs.php"] [unique_id "aoSAmPcmepr5_nHgLbNQGgAAApA"] [Tue Aug 18 12:56:08.162462 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/file.php"] [unique_id "aoSAmNO5rbWdOArH04KIQQAAAX4"] [Tue Aug 18 12:56:08.181912 2026] [security2:error] [pid 67073:tid 67233] [client 216.73.161.205:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmPcmepr5_nHgLbNQFAAAAjA"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:56:08.193210 2026] [security2:error] [pid 67073:tid 67249] [client 20.79.204.6:2221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSAmPcmepr5_nHgLbNQHQAAAkA"] [Tue Aug 18 12:56:08.204437 2026] [security2:error] [pid 67073:tid 67323] [client 158.158.74.177:2649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/new.php"] [unique_id "aoSAmPcmepr5_nHgLbNQHwAAAoo"] [Tue Aug 18 12:56:08.210875 2026] [security2:error] [pid 67073:tid 67113] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/sw.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIAACeiU"] [Tue Aug 18 12:56:08.229286 2026] [security2:error] [pid 67073:tid 67245] [client 20.52.168.85:7858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/essexec.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIQAAAjw"] [Tue Aug 18 12:56:08.234021 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:30986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ew.php"] [unique_id "aoSAmPcmepr5_nHgLbNQIwAAAoQ"] [Tue Aug 18 12:56:08.264780 2026] [security2:error] [pid 67073:tid 67271] [client 20.51.153.15:9109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ee.php"] [unique_id "aoSAmPcmepr5_nHgLbNQJQAAAlY"] [Tue Aug 18 12:56:08.296506 2026] [security2:error] [pid 67073:tid 67213] [client 20.215.241.237:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAmPcmepr5_nHgLbNQJwAAAhw"] [Tue Aug 18 12:56:08.350717 2026] [security2:error] [pid 66623:tid 66852] [client 20.29.77.16:20817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/path.php"] [unique_id "aoSAmNO5rbWdOArH04KIRAAAAWA"] [Tue Aug 18 12:56:08.377004 2026] [security2:error] [pid 67073:tid 67299] [client 74.248.130.103:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aa2.php"] [unique_id "aoSAmPcmepr5_nHgLbNQKQAAAnI"] [Tue Aug 18 12:56:08.393856 2026] [security2:error] [pid 67073:tid 67207] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iz.php"] [unique_id "aoSAmPcmepr5_nHgLbNQKgAAAhY"] [Tue Aug 18 12:56:08.421820 2026] [security2:error] [pid 67073:tid 67232] [client 135.225.78.186:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1mage.php"] [unique_id "aoSAmPcmepr5_nHgLbNQNwAAAi8"] [Tue Aug 18 12:56:08.422426 2026] [security2:error] [pid 67073:tid 67290] [client 20.42.19.40:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAmPcmepr5_nHgLbNQOAAAAmk"] [Tue Aug 18 12:56:08.426142 2026] [security2:error] [pid 66623:tid 66779] [client 68.155.156.252:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/puc.php"] [unique_id "aoSAmNO5rbWdOArH04KIRQAAARc"] [Tue Aug 18 12:56:08.441539 2026] [security2:error] [pid 67073:tid 67264] [client 20.215.241.237:52581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/puc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQgQAAAk8"] [Tue Aug 18 12:56:08.481216 2026] [security2:error] [pid 67073:tid 67091] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQhwACJg8"] [Tue Aug 18 12:56:08.481831 2026] [autoindex:error] [pid 67073:tid 67308] [client 20.226.6.191:38228] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:08.506596 2026] [security2:error] [pid 67073:tid 67270] [client 20.51.153.15:8762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ak.php"] [unique_id "aoSAmPcmepr5_nHgLbNQiQAAAlU"] [Tue Aug 18 12:56:08.515174 2026] [security2:error] [pid 67073:tid 67316] [client 4.223.164.152:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/alls.php"] [unique_id "aoSAmPcmepr5_nHgLbNQigAAAoM"] [Tue Aug 18 12:56:08.521706 2026] [security2:error] [pid 66623:tid 66855] [client 20.151.109.219:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ew.php"] [unique_id "aoSAmNO5rbWdOArH04KIRgAAAWM"] [Tue Aug 18 12:56:08.527837 2026] [security2:error] [pid 66623:tid 66820] [client 20.116.17.175:57604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dk.php"] [unique_id "aoSAmNO5rbWdOArH04KIRwAAAUA"] [Tue Aug 18 12:56:08.529951 2026] [security2:error] [pid 67073:tid 67230] [client 4.223.164.152:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/imageskir.php"] [unique_id "aoSAmPcmepr5_nHgLbNQiwAAAi0"] [Tue Aug 18 12:56:08.608500 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/theme.php"] [unique_id "aoSAmNO5rbWdOArH04KISAAAASM"] [Tue Aug 18 12:56:08.617039 2026] [security2:error] [pid 67073:tid 67267] [client 20.171.51.14:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/fb.php"] [unique_id "aoSAmPcmepr5_nHgLbNQjwAAAlI"] [Tue Aug 18 12:56:08.622933 2026] [security2:error] [pid 67073:tid 67218] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQjgACIXg"] [Tue Aug 18 12:56:08.653939 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/se.php"] [unique_id "aoSAmNO5rbWdOArH04KISQAAARM"] [Tue Aug 18 12:56:08.678646 2026] [security2:error] [pid 67073:tid 67111] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uq.php"] [unique_id "aoSAmPcmepr5_nHgLbNQmAACOCM"] [Tue Aug 18 12:56:08.710840 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:31031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pqr.php"] [unique_id "aoSAmPcmepr5_nHgLbNQnQAAAkQ"] [Tue Aug 18 12:56:08.722857 2026] [security2:error] [pid 67073:tid 67205] [client 20.91.215.254:12000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/akc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQngAAAhQ"] [Tue Aug 18 12:56:08.725275 2026] [security2:error] [pid 66623:tid 66796] [client 20.104.49.167:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/coffexium.php"] [unique_id "aoSAmNO5rbWdOArH04KISwAAASg"] [Tue Aug 18 12:56:08.733534 2026] [security2:error] [pid 67073:tid 67254] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tiny.php"] [unique_id "aoSAmPcmepr5_nHgLbNQoQAAAkU"] [Tue Aug 18 12:56:08.735161 2026] [autoindex:error] [pid 67073:tid 67272] [client 172.202.39.151:65239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:08.795465 2026] [security2:error] [pid 66623:tid 66860] [client 20.79.204.6:2224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSAmNO5rbWdOArH04KITAAAAWg"] [Tue Aug 18 12:56:08.796185 2026] [security2:error] [pid 67073:tid 67281] [client 213.35.127.232:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAmPcmepr5_nHgLbNQpwAAAmA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:08.832318 2026] [security2:error] [pid 66623:tid 66783] [client 20.52.168.85:8005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/fw.php"] [unique_id "aoSAmNO5rbWdOArH04KITQAAARs"] [Tue Aug 18 12:56:08.836843 2026] [security2:error] [pid 66623:tid 66786] [client 160.120.140.123:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITgAAAR4"] [Tue Aug 18 12:56:08.836966 2026] [security2:error] [pid 66623:tid 66786] [client 160.120.140.123:60714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITgAAAR4"] [Tue Aug 18 12:56:08.841818 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:08.842101 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:08.844677 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/imsc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQswAAAjY"] [Tue Aug 18 12:56:08.857972 2026] [security2:error] [pid 67073:tid 67266] [client 20.151.109.219:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pqr.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtAAAAlE"] [Tue Aug 18 12:56:08.860331 2026] [security2:error] [pid 66623:tid 66784] [client 192.141.172.134:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITwAAARw"] [Tue Aug 18 12:56:08.860393 2026] [security2:error] [pid 66623:tid 66784] [client 192.141.172.134:59821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmNO5rbWdOArH04KITwAAARw"] [Tue Aug 18 12:56:08.861543 2026] [security2:error] [pid 66623:tid 66843] [client 68.155.156.252:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/inso.php"] [unique_id "aoSAmNO5rbWdOArH04KIUAAAAVc"] [Tue Aug 18 12:56:08.861569 2026] [security2:error] [pid 66623:tid 66804] [client 20.51.153.15:9181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/test_info.php"] [unique_id "aoSAmNO5rbWdOArH04KIUQAAATA"] [Tue Aug 18 12:56:08.899180 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vp.php"] [unique_id "aoSAmNO5rbWdOArH04KIUgAAAS0"] [Tue Aug 18 12:56:08.901688 2026] [security2:error] [pid 67073:tid 67319] [client 85.154.68.202:49731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtwAAAoY"] [Tue Aug 18 12:56:08.901805 2026] [security2:error] [pid 67073:tid 67319] [client 85.154.68.202:49731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAmPcmepr5_nHgLbNQtwAAAoY"] [Tue Aug 18 12:56:08.909212 2026] [security2:error] [pid 67073:tid 67101] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/32.php"] [unique_id "aoSAmPcmepr5_nHgLbNQuAACXRk"] [Tue Aug 18 12:56:08.924560 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.6.191:38228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAmPcmepr5_nHgLbNQuwAAAiw"] [Tue Aug 18 12:56:08.931586 2026] [security2:error] [pid 67073:tid 67153] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAmPcmepr5_nHgLbNQvAACdU0"], referer: https://barsantajulia.com.br/ [Tue Aug 18 12:56:08.936654 2026] [security2:error] [pid 67073:tid 67301] [client 4.223.164.152:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/coffexium.php"] [unique_id "aoSAmPcmepr5_nHgLbNQvgAAAnQ"] [Tue Aug 18 12:56:08.970938 2026] [security2:error] [pid 66623:tid 66814] [client 158.158.74.177:22750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/norn.php"] [unique_id "aoSAmNO5rbWdOArH04KIUwAAATo"] [Tue Aug 18 12:56:08.972602 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.130.103:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/xamp.php"] [unique_id "aoSAmNO5rbWdOArH04KIVAAAAQw"] [Tue Aug 18 12:56:08.981079 2026] [security2:error] [pid 67073:tid 67228] [client 132.196.61.152:60319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/signon.php"] [unique_id "aoSAmPcmepr5_nHgLbNQwAAAAis"] [Tue Aug 18 12:56:09.020191 2026] [security2:error] [pid 67073:tid 67233] [client 172.202.39.151:65239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/aa.php"] [unique_id "aoSAmfcmepr5_nHgLbNQxgAAAjA"] [Tue Aug 18 12:56:09.027943 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/bal.php"] [unique_id "aoSAmdO5rbWdOArH04KIVgAAAVQ"] [Tue Aug 18 12:56:09.043506 2026] [security2:error] [pid 67073:tid 67322] [client 4.223.164.152:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/indexo.php"] [unique_id "aoSAmfcmepr5_nHgLbNQxwAAAok"] [Tue Aug 18 12:56:09.044673 2026] [security2:error] [pid 67073:tid 67249] [client 135.225.75.187:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ty.php"] [unique_id "aoSAmfcmepr5_nHgLbNQyAAAAkA"] [Tue Aug 18 12:56:09.069077 2026] [security2:error] [pid 67073:tid 67323] [client 52.141.58.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontadaareiaimoveis.com.br"] [uri "/tmp/byp.php"] [unique_id "aoSAmfcmepr5_nHgLbNQyQAAAoo"] [Tue Aug 18 12:56:09.093060 2026] [security2:error] [pid 67073:tid 67317] [client 158.23.17.4:8741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/profile.php"] [unique_id "aoSAmfcmepr5_nHgLbNQywAAAoQ"] [Tue Aug 18 12:56:09.144008 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.18.37:14814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAmdO5rbWdOArH04KIZgAAAWk"] [Tue Aug 18 12:56:09.145405 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:09.145862 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:09.163830 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/an.php"] [unique_id "aoSAmdO5rbWdOArH04KIaAAAAV4"] [Tue Aug 18 12:56:09.164377 2026] [security2:error] [pid 66623:tid 66822] [client 20.163.43.14:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAmdO5rbWdOArH04KIaQAAAUI"] [Tue Aug 18 12:56:09.166712 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/73.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0AACHBg"] [Tue Aug 18 12:56:09.170094 2026] [security2:error] [pid 67073:tid 67255] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ph.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0QAAAkY"] [Tue Aug 18 12:56:09.171414 2026] [security2:error] [pid 67073:tid 67244] [client 20.42.19.40:2234] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/uploads/"] [unique_id "aoSAmfcmepr5_nHgLbNQ0gAAAjs"] [Tue Aug 18 12:56:09.186468 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/14.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ0wAAApE"] [Tue Aug 18 12:56:09.210709 2026] [security2:error] [pid 67073:tid 67263] [client 20.104.85.180:18816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/system_log.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ1QAAAk4"] [Tue Aug 18 12:56:09.210709 2026] [security2:error] [pid 66623:tid 66774] [client 79.127.164.8:37128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost_backup.bak"] [unique_id "aoSAmdO5rbWdOArH04KIagAAARI"], referer: https://medihub.com.br/localhost_backup.bak [Tue Aug 18 12:56:09.262007 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.78.186:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/imscjpg.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ2AAAAkI"] [Tue Aug 18 12:56:09.268929 2026] [security2:error] [pid 66623:tid 66877] [client 20.250.13.23:25705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAmdO5rbWdOArH04KIawAAAXk"] [Tue Aug 18 12:56:09.335609 2026] [security2:error] [pid 67073:tid 67320] [client 68.155.156.252:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/aa.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ2wAAAoc"] [Tue Aug 18 12:56:09.356485 2026] [security2:error] [pid 67073:tid 67174] [remote 191.39.149.110:7833] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ4gACe2I"], referer: https://barsantajulia.com.br/happyhour/ [Tue Aug 18 12:56:09.358663 2026] [security2:error] [pid 67073:tid 67311] [client 4.223.164.152:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/red.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5AAAAn4"] [Tue Aug 18 12:56:09.374332 2026] [security2:error] [pid 66623:tid 66780] [client 104.209.144.33:25608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAmdO5rbWdOArH04KIbQAAARg"] [Tue Aug 18 12:56:09.376764 2026] [security2:error] [pid 67073:tid 67206] [client 20.215.241.237:19887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/sf.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5QAAAhU"] [Tue Aug 18 12:56:09.401965 2026] [security2:error] [pid 66623:tid 66842] [client 20.79.204.6:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSAmdO5rbWdOArH04KIbgAAAVY"] [Tue Aug 18 12:56:09.408028 2026] [security2:error] [pid 67073:tid 67141] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ib.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ5wACLUE"] [Tue Aug 18 12:56:09.419904 2026] [security2:error] [pid 66623:tid 66864] [client 20.51.153.15:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tk.php"] [unique_id "aoSAmdO5rbWdOArH04KIbwAAAWw"] [Tue Aug 18 12:56:09.425428 2026] [security2:error] [pid 67073:tid 67220] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/s.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ6AAAAiM"] [Tue Aug 18 12:56:09.437889 2026] [security2:error] [pid 66623:tid 66806] [client 20.52.168.85:7828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/zwso.php"] [unique_id "aoSAmdO5rbWdOArH04KIcAAAATI"] [Tue Aug 18 12:56:09.445076 2026] [security2:error] [pid 66623:tid 66819] [client 20.91.215.254:12105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/maintenance.php"] [unique_id "aoSAmdO5rbWdOArH04KIcQAAAT8"] [Tue Aug 18 12:56:09.447564 2026] [security2:error] [pid 66623:tid 66841] [client 20.151.109.219:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sy.php"] [unique_id "aoSAmdO5rbWdOArH04KIcgAAAVU"] [Tue Aug 18 12:56:09.479945 2026] [security2:error] [pid 67073:tid 67081] [remote 103.56.163.133:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ7gACkwU"] [Tue Aug 18 12:56:09.485503 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.56.190:28282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/an.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8AAAAhk"] [Tue Aug 18 12:56:09.518157 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.6.191:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-good.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8gAAAh8"] [Tue Aug 18 12:56:09.528304 2026] [security2:error] [pid 67073:tid 67291] [client 20.163.43.14:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ8wAAAmo"] [Tue Aug 18 12:56:09.555595 2026] [security2:error] [pid 66623:tid 66838] [client 74.248.130.103:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/bless.php"] [unique_id "aoSAmdO5rbWdOArH04KIdAAAAVI"] [Tue Aug 18 12:56:09.605066 2026] [security2:error] [pid 66623:tid 66777] [client 20.215.241.237:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/inso.php"] [unique_id "aoSAmdO5rbWdOArH04KIdQAAARU"] [Tue Aug 18 12:56:09.661716 2026] [security2:error] [pid 67073:tid 67086] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xm.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ9wACRQo"] [Tue Aug 18 12:56:09.672561 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:57656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yawa.php"] [unique_id "aoSAmdO5rbWdOArH04KIdgAAATc"] [Tue Aug 18 12:56:09.679328 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uo.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ-QAAAkw"] [Tue Aug 18 12:56:09.680335 2026] [security2:error] [pid 66623:tid 66828] [client 135.225.78.186:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/qlex1.php"] [unique_id "aoSAmdO5rbWdOArH04KIdwAAAUg"] [Tue Aug 18 12:56:09.728456 2026] [security2:error] [pid 66623:tid 66812] [client 157.51.166.53:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmdO5rbWdOArH04KIfQAAATg"] [Tue Aug 18 12:56:09.728575 2026] [security2:error] [pid 66623:tid 66812] [client 157.51.166.53:60498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAmdO5rbWdOArH04KIfQAAATg"] [Tue Aug 18 12:56:09.731563 2026] [security2:error] [pid 67073:tid 67209] [client 20.51.153.15:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/hp.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ-wAAAhg"] [Tue Aug 18 12:56:09.781803 2026] [security2:error] [pid 66623:tid 66879] [client 4.223.164.152:17651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAmdO5rbWdOArH04KIggAAAXs"] [Tue Aug 18 12:56:09.791462 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.156.252:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/img.php"] [unique_id "aoSAmdO5rbWdOArH04KIgwAAAWc"] [Tue Aug 18 12:56:09.797752 2026] [security2:error] [pid 66623:tid 66862] [client 20.104.49.167:3531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/BDKR28WP.php"] [unique_id "aoSAmdO5rbWdOArH04KIhAAAAWo"] [Tue Aug 18 12:56:09.798849 2026] [security2:error] [pid 66623:tid 66800] [client 20.151.109.219:12917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/57.php"] [unique_id "aoSAmdO5rbWdOArH04KIhQAAASw"] [Tue Aug 18 12:56:09.814217 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAmfcmepr5_nHgLbNQ_wAAAiE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:09.867138 2026] [security2:error] [pid 67073:tid 67200] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zy.php"] [unique_id "aoSAmfcmepr5_nHgLbNRAgAChnw"] [Tue Aug 18 12:56:09.868930 2026] [security2:error] [pid 67073:tid 67278] [client 20.163.43.14:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/admin.php"] [unique_id "aoSAmfcmepr5_nHgLbNRAwAAAl0"] [Tue Aug 18 12:56:09.940713 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.61.152:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file61.php"] [unique_id "aoSAmdO5rbWdOArH04KIiQAAAX4"] [Tue Aug 18 12:56:09.942964 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kx.php"] [unique_id "aoSAmdO5rbWdOArH04KIigAAASI"] [Tue Aug 18 12:56:09.949319 2026] [security2:error] [pid 66623:tid 66863] [client 135.225.75.187:17668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/vgtyu.php"] [unique_id "aoSAmdO5rbWdOArH04KIiwAAAWs"] [Tue Aug 18 12:56:10.004705 2026] [security2:error] [pid 66623:tid 66799] [client 20.29.77.16:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/456.php"] [unique_id "aoSAmtO5rbWdOArH04KIjAAAASs"] [Tue Aug 18 12:56:10.013443 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/db.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCAAAAmA"] [Tue Aug 18 12:56:10.029103 2026] [security2:error] [pid 67073:tid 67325] [client 74.248.18.37:28805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCQAAAow"] [Tue Aug 18 12:56:10.044509 2026] [security2:error] [pid 67073:tid 67225] [client 20.52.168.85:7860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/term.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCgAAAig"] [Tue Aug 18 12:56:10.045083 2026] [security2:error] [pid 67073:tid 67214] [client 20.215.241.237:27234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/k.php"] [unique_id "aoSAmvcmepr5_nHgLbNRCwAAAh0"] [Tue Aug 18 12:56:10.054765 2026] [security2:error] [pid 67073:tid 67322] [client 20.51.153.15:8730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wx.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDQAAAok"] [Tue Aug 18 12:56:10.083419 2026] [security2:error] [pid 67073:tid 67323] [client 20.116.17.175:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDgAAAoo"] [Tue Aug 18 12:56:10.103705 2026] [security2:error] [pid 67073:tid 67314] [client 135.225.78.186:13052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/mariju.php"] [unique_id "aoSAmvcmepr5_nHgLbNRDwAAAoE"] [Tue Aug 18 12:56:10.132195 2026] [security2:error] [pid 67073:tid 67307] [client 20.171.51.14:28812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gw.php"] [unique_id "aoSAmvcmepr5_nHgLbNREQAAAno"] [Tue Aug 18 12:56:10.142607 2026] [security2:error] [pid 67073:tid 67309] [client 158.158.74.177:17973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/num.php"] [unique_id "aoSAmvcmepr5_nHgLbNREgAAAnw"] [Tue Aug 18 12:56:10.146732 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:15367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file25.php"] [unique_id "aoSAmvcmepr5_nHgLbNREwAAAmE"] [Tue Aug 18 12:56:10.149875 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.156.252:5626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/222.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFAAAAjw"] [Tue Aug 18 12:56:10.162540 2026] [security2:error] [pid 67073:tid 67157] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/q.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFQACdVE"] [Tue Aug 18 12:56:10.172564 2026] [security2:error] [pid 67073:tid 67312] [client 172.202.39.151:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/0x.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFgAAAn8"] [Tue Aug 18 12:56:10.184292 2026] [security2:error] [pid 67073:tid 67215] [client 20.151.109.219:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ah.php"] [unique_id "aoSAmvcmepr5_nHgLbNRFwAAAh4"] [Tue Aug 18 12:56:10.194971 2026] [security2:error] [pid 67073:tid 67238] [client 20.163.43.14:4276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/public/css.php"] [unique_id "aoSAmvcmepr5_nHgLbNRGAAAAjU"] [Tue Aug 18 12:56:10.211038 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/va.php"] [unique_id "aoSAmvcmepr5_nHgLbNRGQAAAlY"] [Tue Aug 18 12:56:10.256616 2026] [security2:error] [pid 67073:tid 67289] [client 4.223.164.152:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSAmvcmepr5_nHgLbNRHAAAAmg"] [Tue Aug 18 12:56:10.267772 2026] [security2:error] [pid 67073:tid 67227] [client 20.91.215.254:12100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/options-writing.php"] [unique_id "aoSAmvcmepr5_nHgLbNRHQAAAio"] [Tue Aug 18 12:56:10.289999 2026] [security2:error] [pid 66623:tid 66815] [client 20.51.153.15:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/dj.php"] [unique_id "aoSAmtO5rbWdOArH04KIkQAAATs"] [Tue Aug 18 12:56:10.348027 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:10.348289 2026] [authz_core:error] [pid 67073:tid 67138] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:10.381260 2026] [security2:error] [pid 67073:tid 67118] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xf.php"] [unique_id "aoSAmvcmepr5_nHgLbNRIAACQio"] [Tue Aug 18 12:56:10.391443 2026] [security2:error] [pid 66623:tid 66832] [client 20.250.13.23:24777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/h.php"] [unique_id "aoSAmtO5rbWdOArH04KIkgAAAUw"] [Tue Aug 18 12:56:10.442028 2026] [security2:error] [pid 67073:tid 67231] [client 20.104.49.167:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/sf.php"] [unique_id "aoSAmvcmepr5_nHgLbNRIgAAAi4"] [Tue Aug 18 12:56:10.470967 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fo.php"] [unique_id "aoSAmtO5rbWdOArH04KIlAAAARM"] [Tue Aug 18 12:56:10.483020 2026] [security2:error] [pid 66623:tid 66858] [client 4.223.164.152:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAmtO5rbWdOArH04KIlQAAAWY"] [Tue Aug 18 12:56:10.487512 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vw.php"] [unique_id "aoSAmvcmepr5_nHgLbNRJgAAAik"] [Tue Aug 18 12:56:10.521596 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.78.186:12994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/cofbgxlk.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKQAAAj4"] [Tue Aug 18 12:56:10.545631 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKgAAAoc"] [Tue Aug 18 12:56:10.560134 2026] [security2:error] [pid 67073:tid 67212] [client 20.42.19.40:2883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNRKwAAAhs"] [Tue Aug 18 12:56:10.562557 2026] [security2:error] [pid 67073:tid 67083] [remote 178.156.200.16:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLAACfQc"] [Tue Aug 18 12:56:10.578013 2026] [security2:error] [pid 67073:tid 67129] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gb.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLQACJjU"] [Tue Aug 18 12:56:10.595287 2026] [security2:error] [pid 67073:tid 67206] [client 20.116.17.175:57439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/7.php"] [unique_id "aoSAmvcmepr5_nHgLbNRLwAAAhU"] [Tue Aug 18 12:56:10.620762 2026] [security2:error] [pid 67073:tid 67287] [client 20.79.204.6:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSAmvcmepr5_nHgLbNRMQAAAmY"] [Tue Aug 18 12:56:10.648614 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:10.648934 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:10.649421 2026] [security2:error] [pid 67073:tid 67232] [client 20.52.168.85:7845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAmvcmepr5_nHgLbNRNgAAAi8"] [Tue Aug 18 12:56:10.716475 2026] [security2:error] [pid 66623:tid 66888] [client 20.51.153.15:9151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fa.php"] [unique_id "aoSAmtO5rbWdOArH04KImQAAAYQ"] [Tue Aug 18 12:56:10.732206 2026] [security2:error] [pid 67073:tid 67216] [client 68.155.156.252:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/key.php"] [unique_id "aoSAmvcmepr5_nHgLbNROAAAAh8"] [Tue Aug 18 12:56:10.735021 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/loading.php"] [unique_id "aoSAmvcmepr5_nHgLbNROQAAAjg"] [Tue Aug 18 12:56:10.742436 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:17625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/.admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNROwAAAmo"] [Tue Aug 18 12:56:10.751778 2026] [security2:error] [pid 66623:tid 66768] [client 158.23.17.4:9375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/summary.php"] [unique_id "aoSAmtO5rbWdOArH04KImgAAAQw"] [Tue Aug 18 12:56:10.759307 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.130.103:14429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file15.php"] [unique_id "aoSAmvcmepr5_nHgLbNRPAAAAkQ"] [Tue Aug 18 12:56:10.779348 2026] [security2:error] [pid 67073:tid 67192] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jp.php"] [unique_id "aoSAmvcmepr5_nHgLbNRPgACInQ"] [Tue Aug 18 12:56:10.832090 2026] [autoindex:error] [pid 67073:tid 67242] [client 20.226.6.191:64125] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:10.836060 2026] [security2:error] [pid 66623:tid 66834] [client 213.35.127.232:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAmtO5rbWdOArH04KInQAAAU4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:10.842101 2026] [security2:error] [pid 66623:tid 66880] [client 20.215.241.237:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/aa.php"] [unique_id "aoSAmtO5rbWdOArH04KIngAAAXw"] [Tue Aug 18 12:56:10.848711 2026] [security2:error] [pid 66623:tid 66840] [client 20.151.109.219:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lj.php"] [unique_id "aoSAmtO5rbWdOArH04KInwAAAVQ"] [Tue Aug 18 12:56:10.854027 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.56.190:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sy.php"] [unique_id "aoSAmvcmepr5_nHgLbNRQwAAAls"] [Tue Aug 18 12:56:10.884134 2026] [security2:error] [pid 67073:tid 67209] [client 20.104.49.167:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/k.php"] [unique_id "aoSAmvcmepr5_nHgLbNRRQAAAhg"] [Tue Aug 18 12:56:10.936368 2026] [security2:error] [pid 67073:tid 67218] [client 4.223.164.152:4850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/admin.php"] [unique_id "aoSAmvcmepr5_nHgLbNRSAAAAiE"] [Tue Aug 18 12:56:10.938238 2026] [security2:error] [pid 66623:tid 66866] [client 172.202.39.151:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/zxz.php"] [unique_id "aoSAmtO5rbWdOArH04KIoAAAAW4"] [Tue Aug 18 12:56:10.939213 2026] [security2:error] [pid 66623:tid 66778] [client 135.225.78.186:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/contacto.php"] [unique_id "aoSAmtO5rbWdOArH04KIoQAAARY"] [Tue Aug 18 12:56:10.952361 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:10.952616 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:10.964832 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.75.187:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mans.php"] [unique_id "aoSAmvcmepr5_nHgLbNRSgAAAjY"] [Tue Aug 18 12:56:10.971681 2026] [security2:error] [pid 67073:tid 67221] [client 20.91.215.254:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTAAAAiQ"] [Tue Aug 18 12:56:10.983104 2026] [security2:error] [pid 66623:tid 66814] [client 158.158.74.177:16564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/options-reading.php"] [unique_id "aoSAmtO5rbWdOArH04KIogAAATo"] [Tue Aug 18 12:56:10.983963 2026] [security2:error] [pid 67073:tid 67229] [client 158.158.34.183:18838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTQAAAiw"] [Tue Aug 18 12:56:10.984619 2026] [security2:error] [pid 67073:tid 67278] [client 20.51.153.15:8751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/fb.php"] [unique_id "aoSAmvcmepr5_nHgLbNRTgAAAl0"] [Tue Aug 18 12:56:10.987363 2026] [security2:error] [pid 66623:tid 66807] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ke.php"] [unique_id "aoSAmtO5rbWdOArH04KIowAAATM"] [Tue Aug 18 12:56:11.000247 2026] [security2:error] [pid 67073:tid 67130] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eq.php"] [unique_id "aoSAmvcmepr5_nHgLbNRUAACSjY"] [Tue Aug 18 12:56:11.022619 2026] [security2:error] [pid 66623:tid 66798] [client 20.29.77.16:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/SMTP.php"] [unique_id "aoSAm9O5rbWdOArH04KIpAAAASo"] [Tue Aug 18 12:56:11.065156 2026] [security2:error] [pid 67073:tid 67233] [client 20.163.43.14:4200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAm_cmepr5_nHgLbNRUQAAAjA"] [Tue Aug 18 12:56:11.137885 2026] [security2:error] [pid 66623:tid 66774] [client 20.151.109.219:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kh.php"] [unique_id "aoSAm9O5rbWdOArH04KIpgAAARI"] [Tue Aug 18 12:56:11.138496 2026] [security2:error] [pid 66623:tid 66785] [client 20.215.241.237:11005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/82.php"] [unique_id "aoSAm9O5rbWdOArH04KIpwAAAR0"] [Tue Aug 18 12:56:11.139828 2026] [security2:error] [pid 67073:tid 67250] [client 172.202.39.151:45171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAm_cmepr5_nHgLbNRUwAAAkE"] [Tue Aug 18 12:56:11.161498 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:30540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/zup.php73"] [unique_id "aoSAm_cmepr5_nHgLbNRVAAAAn4"] [Tue Aug 18 12:56:11.194629 2026] [security2:error] [pid 67073:tid 67245] [client 20.116.17.175:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ws77.php"] [unique_id "aoSAm_cmepr5_nHgLbNRVgAAAjw"] [Tue Aug 18 12:56:11.216757 2026] [autoindex:error] [pid 67073:tid 67307] [client 20.226.6.191:64125] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:11.218188 2026] [security2:error] [pid 66623:tid 66776] [client 20.51.153.15:9179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gw.php"] [unique_id "aoSAm9O5rbWdOArH04KIqAAAARQ"] [Tue Aug 18 12:56:11.220988 2026] [security2:error] [pid 67073:tid 67329] [client 20.79.204.6:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/file.php"] [unique_id "aoSAm_cmepr5_nHgLbNRVwAAApA"] [Tue Aug 18 12:56:11.230450 2026] [security2:error] [pid 67073:tid 67161] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ep.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWQACeFU"] [Tue Aug 18 12:56:11.237669 2026] [security2:error] [pid 67073:tid 67327] [client 74.248.130.103:14400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/f35.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWgAAAo4"] [Tue Aug 18 12:56:11.240800 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.6.191:64125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/tes.php"] [unique_id "aoSAm_cmepr5_nHgLbNRWwAAAjU"] [Tue Aug 18 12:56:11.241802 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nh.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXAAAAh4"] [Tue Aug 18 12:56:11.253130 2026] [security2:error] [pid 67073:tid 67325] [client 20.52.168.85:7847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-access.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXgAAAow"] [Tue Aug 18 12:56:11.283154 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:24979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAm9O5rbWdOArH04KIqgAAARE"] [Tue Aug 18 12:56:11.286641 2026] [security2:error] [pid 66623:tid 66816] [client 4.223.164.152:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/wsomini.php"] [unique_id "aoSAm9O5rbWdOArH04KIqwAAATw"] [Tue Aug 18 12:56:11.355924 2026] [security2:error] [pid 67073:tid 67236] [client 4.223.164.152:4839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/file52.php"] [unique_id "aoSAm_cmepr5_nHgLbNRXwAAAjM"] [Tue Aug 18 12:56:11.356300 2026] [security2:error] [pid 67073:tid 67252] [client 135.225.78.186:13039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/image2.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYAAAAkM"] [Tue Aug 18 12:56:11.387357 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAm9O5rbWdOArH04KIrQAAAVU"] [Tue Aug 18 12:56:11.391606 2026] [security2:error] [pid 67073:tid 67213] [client 20.163.43.14:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gelay.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYQAAAhw"] [Tue Aug 18 12:56:11.454482 2026] [security2:error] [pid 67073:tid 67330] [client 20.51.153.15:8761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/sw.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYgAAApE"] [Tue Aug 18 12:56:11.460242 2026] [security2:error] [pid 67073:tid 67088] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rf.php"] [unique_id "aoSAm_cmepr5_nHgLbNRYwACSAw"] [Tue Aug 18 12:56:11.470311 2026] [security2:error] [pid 67073:tid 67263] [client 20.151.109.219:65015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRZAAAAk4"] [Tue Aug 18 12:56:11.493493 2026] [security2:error] [pid 67073:tid 67248] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/oo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRZQAAAj8"] [Tue Aug 18 12:56:11.536401 2026] [security2:error] [pid 66623:tid 66777] [client 20.226.56.190:31645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/57.php"] [unique_id "aoSAm9O5rbWdOArH04KIrwAAARU"] [Tue Aug 18 12:56:11.552665 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:11.552965 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:11.585790 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.156.252:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/chosen.php"] [unique_id "aoSAm9O5rbWdOArH04KIsAAAAVA"] [Tue Aug 18 12:56:11.587365 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/copypaths.php"] [unique_id "aoSAm_cmepr5_nHgLbNRaAAAAmQ"] [Tue Aug 18 12:56:11.628764 2026] [security2:error] [pid 66623:tid 66824] [client 20.116.17.175:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/read.php"] [unique_id "aoSAm9O5rbWdOArH04KIsQAAAUQ"] [Tue Aug 18 12:56:11.643632 2026] [security2:error] [pid 67073:tid 67303] [client 20.104.49.167:30231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/82.php"] [unique_id "aoSAm_cmepr5_nHgLbNRagAAAnY"] [Tue Aug 18 12:56:11.655437 2026] [security2:error] [pid 66623:tid 66706] [remote 157.230.98.178:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSAm9O5rbWdOArH04KIsgABLkU"] [Tue Aug 18 12:56:11.662097 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:31003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ah.php"] [unique_id "aoSAm_cmepr5_nHgLbNRawAAAj4"] [Tue Aug 18 12:56:11.665086 2026] [security2:error] [pid 67073:tid 67104] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xynz1.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbAAChxw"] [Tue Aug 18 12:56:11.665755 2026] [security2:error] [pid 67073:tid 67212] [client 20.171.51.14:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/sw.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbQAAAhs"] [Tue Aug 18 12:56:11.668221 2026] [security2:error] [pid 67073:tid 67256] [client 135.225.75.187:17700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/co.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbgAAAkc"] [Tue Aug 18 12:56:11.681798 2026] [security2:error] [pid 67073:tid 67316] [client 45.92.229.84:38599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSAm_cmepr5_nHgLbNRbwAAAoM"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:56:11.723182 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.56.190:2730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vw.php"] [unique_id "aoSAm9O5rbWdOArH04KIswAAATc"] [Tue Aug 18 12:56:11.732413 2026] [security2:error] [pid 67073:tid 67328] [client 20.163.43.14:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcQAAAo8"] [Tue Aug 18 12:56:11.738900 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.130.103:14442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-load.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcgAAAho"] [Tue Aug 18 12:56:11.740985 2026] [security2:error] [pid 67073:tid 67267] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ja.php"] [unique_id "aoSAm_cmepr5_nHgLbNRcwAAAlI"] [Tue Aug 18 12:56:11.752512 2026] [security2:error] [pid 67073:tid 67332] [client 20.51.153.15:8385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/gc.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdAAAApM"] [Tue Aug 18 12:56:11.756253 2026] [security2:error] [pid 66623:tid 66781] [client 20.151.109.219:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/do.php"] [unique_id "aoSAm9O5rbWdOArH04KItAAAARk"] [Tue Aug 18 12:56:11.767151 2026] [security2:error] [pid 67073:tid 67326] [client 20.91.215.254:12130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/maint.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdQAAAo0"] [Tue Aug 18 12:56:11.768001 2026] [security2:error] [pid 66623:tid 66844] [client 20.226.56.190:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lj.php"] [unique_id "aoSAm9O5rbWdOArH04KItQAAAVg"] [Tue Aug 18 12:56:11.775664 2026] [security2:error] [pid 67073:tid 67208] [client 135.225.78.186:13042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdgAAAhc"] [Tue Aug 18 12:56:11.783292 2026] [security2:error] [pid 67073:tid 67210] [client 4.223.164.152:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/geck.php"] [unique_id "aoSAm_cmepr5_nHgLbNRdwAAAhk"] [Tue Aug 18 12:56:11.801062 2026] [security2:error] [pid 67073:tid 67231] [client 158.158.74.177:2645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ors32envu.php"] [unique_id "aoSAm_cmepr5_nHgLbNReAAAAi4"] [Tue Aug 18 12:56:11.803188 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kh.php"] [unique_id "aoSAm_cmepr5_nHgLbNReQAAAmU"] [Tue Aug 18 12:56:11.837208 2026] [security2:error] [pid 67073:tid 67297] [client 20.29.77.16:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/vbseo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfAAAAnA"] [Tue Aug 18 12:56:11.851391 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:11.851648 2026] [authz_core:error] [pid 67073:tid 67091] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:11.852286 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfgAAAm4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:11.854807 2026] [security2:error] [pid 67073:tid 67313] [client 20.79.204.6:2189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSAm_cmepr5_nHgLbNRfwAAAoA"] [Tue Aug 18 12:56:11.862181 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.56.190:32256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jb.php"] [unique_id "aoSAm_cmepr5_nHgLbNRgAAAAic"] [Tue Aug 18 12:56:11.864988 2026] [security2:error] [pid 67073:tid 67279] [client 20.52.168.85:7811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/bthil.php"] [unique_id "aoSAm_cmepr5_nHgLbNRgQAAAl4"] [Tue Aug 18 12:56:11.882322 2026] [security2:error] [pid 67073:tid 67235] [client 20.42.19.40:2717] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/"] [unique_id "aoSAm_cmepr5_nHgLbNRggAAAjI"] [Tue Aug 18 12:56:11.885738 2026] [security2:error] [pid 66623:tid 66893] [client 4.223.164.152:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gustavofrison.com.br"] [uri "/vr.php"] [unique_id "aoSAm9O5rbWdOArH04KItgAAAYk"] [Tue Aug 18 12:56:11.930229 2026] [security2:error] [pid 66623:tid 66849] [client 20.250.13.23:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAm9O5rbWdOArH04KItwAAAV0"] [Tue Aug 18 12:56:11.950948 2026] [security2:error] [pid 66623:tid 66833] [client 196.12.128.158:65139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAm9O5rbWdOArH04KIuAAAAU0"] [Tue Aug 18 12:56:11.951095 2026] [security2:error] [pid 66623:tid 66833] [client 196.12.128.158:65139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAm9O5rbWdOArH04KIuAAAAU0"] [Tue Aug 18 12:56:11.960796 2026] [security2:error] [pid 67073:tid 67278] [client 172.202.39.151:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/www.php"] [unique_id "aoSAm_cmepr5_nHgLbNRkQAAAl0"] [Tue Aug 18 12:56:11.961313 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vo.php"] [unique_id "aoSAm_cmepr5_nHgLbNRkgACKwA"] [Tue Aug 18 12:56:12.020982 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xx.php"] [unique_id "aoSAnPcmepr5_nHgLbNRmQAAAnw"] [Tue Aug 18 12:56:12.025406 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.56.190:17895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/do.php"] [unique_id "aoSAnPcmepr5_nHgLbNRmwAAAmE"] [Tue Aug 18 12:56:12.041786 2026] [security2:error] [pid 67073:tid 67312] [client 20.116.17.175:57651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/albin.php"] [unique_id "aoSAnPcmepr5_nHgLbNRngAAAn8"] [Tue Aug 18 12:56:12.057211 2026] [security2:error] [pid 67073:tid 67217] [client 20.163.43.14:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAnPcmepr5_nHgLbNRoQAAAiA"] [Tue Aug 18 12:56:12.059740 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:29356] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.dealermotors.com.br"] [uri "/1.php"] [unique_id "aoSAnPcmepr5_nHgLbNRogAAAl8"] [Tue Aug 18 12:56:12.059844 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:29356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/1.php"] [unique_id "aoSAnPcmepr5_nHgLbNRogAAAl8"] [Tue Aug 18 12:56:12.068396 2026] [security2:error] [pid 67073:tid 67275] [client 20.51.153.15:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uq.php"] [unique_id "aoSAnPcmepr5_nHgLbNRpQAAAlo"] [Tue Aug 18 12:56:12.078754 2026] [security2:error] [pid 67073:tid 67213] [client 20.151.109.219:21663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yw.php"] [unique_id "aoSAnPcmepr5_nHgLbNRqAAAAhw"] [Tue Aug 18 12:56:12.177331 2026] [security2:error] [pid 67073:tid 67165] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wu.php"] [unique_id "aoSAnPcmepr5_nHgLbNRuQACWFk"] [Tue Aug 18 12:56:12.197031 2026] [security2:error] [pid 67073:tid 67320] [client 135.225.78.186:13001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/gi.php"] [unique_id "aoSAnPcmepr5_nHgLbNRxAAAAoc"] [Tue Aug 18 12:56:12.223010 2026] [security2:error] [pid 66623:tid 66770] [client 4.223.164.152:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/biufile.php"] [unique_id "aoSAnNO5rbWdOArH04KIvQAAAQ4"] [Tue Aug 18 12:56:12.229034 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:31639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yw.php"] [unique_id "aoSAnPcmepr5_nHgLbNRyAAAAmY"] [Tue Aug 18 12:56:12.277377 2026] [security2:error] [pid 67073:tid 67208] [client 20.104.49.167:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dex.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzQAAAhc"] [Tue Aug 18 12:56:12.284964 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/conn-test.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzgAAAjg"] [Tue Aug 18 12:56:12.292690 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.136.165:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fun.php"] [unique_id "aoSAnPcmepr5_nHgLbNRzwAAAi4"] [Tue Aug 18 12:56:12.309019 2026] [security2:error] [pid 67073:tid 67272] [client 20.51.153.15:9176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/32.php"] [unique_id "aoSAnPcmepr5_nHgLbNR0AAAAlc"] [Tue Aug 18 12:56:12.350132 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.56.190:17894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/qh.php"] [unique_id "aoSAnNO5rbWdOArH04KIvgAAAVk"] [Tue Aug 18 12:56:12.369131 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:12.369391 2026] [authz_core:error] [pid 67073:tid 67141] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:12.383708 2026] [security2:error] [pid 67073:tid 67109] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/de.php"] [unique_id "aoSAnPcmepr5_nHgLbNR1AACgCE"] [Tue Aug 18 12:56:12.389627 2026] [security2:error] [pid 67073:tid 67224] [client 158.23.17.4:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/conf.php"] [unique_id "aoSAnPcmepr5_nHgLbNR1QAAAic"] [Tue Aug 18 12:56:12.401042 2026] [security2:error] [pid 67073:tid 67306] [client 104.209.144.33:29831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2AAAAnk"] [Tue Aug 18 12:56:12.410034 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.156.252:19013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2QAAAjI"] [Tue Aug 18 12:56:12.414392 2026] [security2:error] [pid 67073:tid 67218] [client 20.151.109.219:17584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/qh.php"] [unique_id "aoSAnPcmepr5_nHgLbNR2gAAAiE"] [Tue Aug 18 12:56:12.472747 2026] [security2:error] [pid 67073:tid 67326] [client 20.79.204.6:2190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSAnPcmepr5_nHgLbNR4gAAAo0"] [Tue Aug 18 12:56:12.473083 2026] [security2:error] [pid 66623:tid 66823] [client 20.52.168.85:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/packed.php"] [unique_id "aoSAnNO5rbWdOArH04KIwAAAAUM"] [Tue Aug 18 12:56:12.536911 2026] [security2:error] [pid 67073:tid 67292] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fg.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5QAAAms"] [Tue Aug 18 12:56:12.557457 2026] [security2:error] [pid 67073:tid 67233] [client 135.225.75.187:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/btx25.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5gAAAjA"] [Tue Aug 18 12:56:12.588836 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:2642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSAnPcmepr5_nHgLbNR5wAAAlI"] [Tue Aug 18 12:56:12.591243 2026] [security2:error] [pid 67073:tid 67311] [client 20.51.153.15:8721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/73.php"] [unique_id "aoSAnPcmepr5_nHgLbNR6AAAAn4"] [Tue Aug 18 12:56:12.595004 2026] [security2:error] [pid 66623:tid 66892] [client 158.158.34.183:18872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/bi.php"] [unique_id "aoSAnNO5rbWdOArH04KIwQAAAYg"] [Tue Aug 18 12:56:12.600946 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSAnPcmepr5_nHgLbNR6gAAAnw"] [Tue Aug 18 12:56:12.602574 2026] [security2:error] [pid 66623:tid 66795] [client 20.29.77.16:27254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sysinfo.php"] [unique_id "aoSAnNO5rbWdOArH04KIwgAAASc"] [Tue Aug 18 12:56:12.605656 2026] [security2:error] [pid 67073:tid 67230] [client 20.116.17.175:11221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fw/34.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7AAAAi0"] [Tue Aug 18 12:56:12.614234 2026] [security2:error] [pid 67073:tid 67304] [client 135.225.78.186:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/video.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7QAAAnc"] [Tue Aug 18 12:56:12.617498 2026] [security2:error] [pid 67073:tid 67307] [client 20.42.19.40:2739] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-includes/js/crop/"] [unique_id "aoSAnPcmepr5_nHgLbNR7gAAAno"] [Tue Aug 18 12:56:12.617753 2026] [security2:error] [pid 67073:tid 67160] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/album.php"] [unique_id "aoSAnPcmepr5_nHgLbNR7wACkFQ"] [Tue Aug 18 12:56:12.624623 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.18.37:24506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/k.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8AAAAig"] [Tue Aug 18 12:56:12.659393 2026] [security2:error] [pid 66623:tid 66769] [client 4.223.164.152:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/dejavu.php"] [unique_id "aoSAnNO5rbWdOArH04KIxAAAAQ0"] [Tue Aug 18 12:56:12.659616 2026] [security2:error] [pid 67073:tid 67250] [client 103.120.71.157:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8gAAAkE"] [Tue Aug 18 12:56:12.659742 2026] [security2:error] [pid 67073:tid 67250] [client 103.120.71.157:50962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR8gAAAkE"] [Tue Aug 18 12:56:12.667139 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:12.667414 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:12.669351 2026] [security2:error] [pid 66623:tid 66867] [client 172.202.39.151:65247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wicked.php"] [unique_id "aoSAnNO5rbWdOArH04KIxQAAAW8"] [Tue Aug 18 12:56:12.684657 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.130.103:14422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSAnPcmepr5_nHgLbNR9AAAAn8"] [Tue Aug 18 12:56:12.743833 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:21653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/r.php"] [unique_id "aoSAnPcmepr5_nHgLbNR9wAAAog"] [Tue Aug 18 12:56:12.748029 2026] [security2:error] [pid 67073:tid 67281] [client 79.127.164.8:37190] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost_backup.sql"] [unique_id "aoSAnPcmepr5_nHgLbNR-AAAAmA"], referer: https://medihub.com.br/localhost_backup.sql [Tue Aug 18 12:56:12.755551 2026] [security2:error] [pid 66623:tid 66839] [client 20.91.215.254:12120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/phpMailer.php"] [unique_id "aoSAnNO5rbWdOArH04KIxgAAAVM"] [Tue Aug 18 12:56:12.771520 2026] [security2:error] [pid 66623:tid 66820] [client 20.226.56.190:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/r.php"] [unique_id "aoSAnNO5rbWdOArH04KIxwAAAUA"] [Tue Aug 18 12:56:12.791938 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ve.php"] [unique_id "aoSAnPcmepr5_nHgLbNR-QAAAm8"] [Tue Aug 18 12:56:12.827425 2026] [security2:error] [pid 67073:tid 67255] [client 20.171.51.14:51788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR-wAAAkY"] [Tue Aug 18 12:56:12.832538 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.49.167:30256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/puc.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_AAAAio"] [Tue Aug 18 12:56:12.854047 2026] [security2:error] [pid 67073:tid 67143] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kv.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_QACJUM"] [Tue Aug 18 12:56:12.859364 2026] [security2:error] [pid 66623:tid 66775] [client 20.215.241.237:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAnNO5rbWdOArH04KIyAAAARM"] [Tue Aug 18 12:56:12.864568 2026] [security2:error] [pid 67073:tid 67228] [client 213.35.127.232:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAnPcmepr5_nHgLbNR_gAAAis"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:12.897116 2026] [security2:error] [pid 66623:tid 66886] [client 20.51.153.15:9150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ib.php"] [unique_id "aoSAnNO5rbWdOArH04KIyQAAAYI"] [Tue Aug 18 12:56:12.929022 2026] [security2:error] [pid 67073:tid 67248] [client 20.163.43.14:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/about.php"] [unique_id "aoSAnPcmepr5_nHgLbNSAAAAAj8"] [Tue Aug 18 12:56:12.967186 2026] [security2:error] [pid 66623:tid 66860] [client 20.42.19.40:2885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/wp-links-opml.php"] [unique_id "aoSAnNO5rbWdOArH04KIywAAAWg"] [Tue Aug 18 12:56:12.969067 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:12.969323 2026] [authz_core:error] [pid 67073:tid 67200] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:13.010636 2026] [security2:error] [pid 67073:tid 67245] [client 20.250.13.23:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/a7.php"] [unique_id "aoSAnfcmepr5_nHgLbNSAwAAAjw"] [Tue Aug 18 12:56:13.020253 2026] [security2:error] [pid 66623:tid 66818] [client 104.209.144.33:36516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAndO5rbWdOArH04KIzQAAAT4"] [Tue Aug 18 12:56:13.036481 2026] [security2:error] [pid 67073:tid 67251] [client 135.225.78.186:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/hel.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBAAAAkI"] [Tue Aug 18 12:56:13.051132 2026] [security2:error] [pid 67073:tid 67146] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/z.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBQACS0Y"] [Tue Aug 18 12:56:13.051715 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ia.php"] [unique_id "aoSAndO5rbWdOArH04KIzgAAAQw"] [Tue Aug 18 12:56:13.063933 2026] [security2:error] [pid 67073:tid 67277] [client 197.184.64.235:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBgAAAlw"] [Tue Aug 18 12:56:13.064031 2026] [security2:error] [pid 67073:tid 67277] [client 197.184.64.235:41929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSBgAAAlw"] [Tue Aug 18 12:56:13.079418 2026] [security2:error] [pid 66623:tid 66858] [client 20.52.168.85:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin/function.php"] [unique_id "aoSAndO5rbWdOArH04KIzwAAAWY"] [Tue Aug 18 12:56:13.093413 2026] [security2:error] [pid 67073:tid 67247] [client 20.151.109.219:61406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/17.php"] [unique_id "aoSAnfcmepr5_nHgLbNSCAAAAj4"] [Tue Aug 18 12:56:13.101658 2026] [security2:error] [pid 66623:tid 66834] [client 4.223.164.152:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/aaf.php"] [unique_id "aoSAndO5rbWdOArH04KI0AAAAU4"] [Tue Aug 18 12:56:13.134540 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp9.php"] [unique_id "aoSAndO5rbWdOArH04KI0gAAAVQ"] [Tue Aug 18 12:56:13.141481 2026] [security2:error] [pid 67073:tid 67212] [client 172.202.39.151:65219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAnfcmepr5_nHgLbNSCQAAAhs"] [Tue Aug 18 12:56:13.189866 2026] [security2:error] [pid 66623:tid 66786] [client 20.79.204.6:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/htaccess.php"] [unique_id "aoSAndO5rbWdOArH04KI0wAAAR4"] [Tue Aug 18 12:56:13.191239 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/o.php"] [unique_id "aoSAndO5rbWdOArH04KI1AAAAVc"] [Tue Aug 18 12:56:13.202857 2026] [security2:error] [pid 67073:tid 67206] [client 20.51.153.15:9201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xm.php"] [unique_id "aoSAnfcmepr5_nHgLbNSDAAAAhU"] [Tue Aug 18 12:56:13.210602 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.130.103:15418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/aaa.php"] [unique_id "aoSAndO5rbWdOArH04KI1QAAARY"] [Tue Aug 18 12:56:13.250309 2026] [security2:error] [pid 67073:tid 67144] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xg.php"] [unique_id "aoSAnfcmepr5_nHgLbNSDQACF0Q"] [Tue Aug 18 12:56:13.251097 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:16571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ova.php"] [unique_id "aoSAndO5rbWdOArH04KI1gAAAYQ"] [Tue Aug 18 12:56:13.279139 2026] [security2:error] [pid 66623:tid 66872] [client 20.163.43.14:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSAndO5rbWdOArH04KI1wAAAXQ"] [Tue Aug 18 12:56:13.333747 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kn.php"] [unique_id "aoSAndO5rbWdOArH04KI2AAAAUI"] [Tue Aug 18 12:56:13.344385 2026] [security2:error] [pid 67073:tid 67219] [client 52.173.121.69:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAnfcmepr5_nHgLbNSEQAAAiI"] [Tue Aug 18 12:56:13.346477 2026] [security2:error] [pid 67073:tid 67272] [client 20.29.77.16:32963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ppinfo.php"] [unique_id "aoSAnfcmepr5_nHgLbNSEgAAAlc"] [Tue Aug 18 12:56:13.356733 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.49.167:36351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/inso.php"] [unique_id "aoSAndO5rbWdOArH04KI2QAAASk"] [Tue Aug 18 12:56:13.367187 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.56.190:47144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/17.php"] [unique_id "aoSAnfcmepr5_nHgLbNSFQAAAm4"] [Tue Aug 18 12:56:13.418204 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ev.php"] [unique_id "aoSAnfcmepr5_nHgLbNSFwAAAl4"] [Tue Aug 18 12:56:13.425067 2026] [security2:error] [pid 66623:tid 66877] [client 20.215.241.237:9264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/img.php"] [unique_id "aoSAndO5rbWdOArH04KI2wAAAXk"] [Tue Aug 18 12:56:13.435086 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:12004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGAAAAmY"] [Tue Aug 18 12:56:13.441213 2026] [security2:error] [pid 66623:tid 66780] [client 20.171.51.14:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uq.php"] [unique_id "aoSAndO5rbWdOArH04KI3AAAARg"] [Tue Aug 18 12:56:13.448223 2026] [security2:error] [pid 67073:tid 67098] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/nd.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGQACFhY"] [Tue Aug 18 12:56:13.453256 2026] [security2:error] [pid 66623:tid 66773] [client 135.225.78.186:13007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/grok.php"] [unique_id "aoSAndO5rbWdOArH04KI3QAAARE"] [Tue Aug 18 12:56:13.455411 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.56.190:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ev.php"] [unique_id "aoSAnfcmepr5_nHgLbNSGgAAAnk"] [Tue Aug 18 12:56:13.483905 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.6.191:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/files/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHAAAAhQ"] [Tue Aug 18 12:56:13.501125 2026] [security2:error] [pid 67073:tid 67218] [client 68.155.156.252:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/file1221.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHQAAAiE"] [Tue Aug 18 12:56:13.521187 2026] [security2:error] [pid 67073:tid 67291] [client 4.223.164.152:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSAnfcmepr5_nHgLbNSHwAAAmo"] [Tue Aug 18 12:56:13.547485 2026] [security2:error] [pid 67073:tid 67221] [client 20.51.153.15:8715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/q.php"] [unique_id "aoSAnfcmepr5_nHgLbNSIgAAAiQ"] [Tue Aug 18 12:56:13.571578 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:13.571851 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:13.580411 2026] [security2:error] [pid 67073:tid 67263] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wm.php"] [unique_id "aoSAnfcmepr5_nHgLbNSJQAAAk4"] [Tue Aug 18 12:56:13.609342 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/f35.php"] [unique_id "aoSAnfcmepr5_nHgLbNSJgAAAlI"] [Tue Aug 18 12:56:13.637962 2026] [security2:error] [pid 67073:tid 67230] [client 20.116.17.175:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/save.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKAAAAi0"] [Tue Aug 18 12:56:13.647731 2026] [security2:error] [pid 67073:tid 67225] [client 20.226.56.190:23765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xs.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKQAAAig"] [Tue Aug 18 12:56:13.679608 2026] [security2:error] [pid 67073:tid 67209] [client 20.52.168.85:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/zoom1.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKgAAAhg"] [Tue Aug 18 12:56:13.701602 2026] [security2:error] [pid 66623:tid 66810] [client 74.248.130.103:14417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gecko.php"] [unique_id "aoSAndO5rbWdOArH04KI3gAAATY"] [Tue Aug 18 12:56:13.703583 2026] [security2:error] [pid 66623:tid 66819] [client 20.42.19.40:3455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.sortisinformatica.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAndO5rbWdOArH04KI3wAAAT8"] [Tue Aug 18 12:56:13.704356 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ri.php"] [unique_id "aoSAnfcmepr5_nHgLbNSKwACjHc"] [Tue Aug 18 12:56:13.713387 2026] [security2:error] [pid 66623:tid 66782] [client 132.196.61.152:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bless6.php"] [unique_id "aoSAndO5rbWdOArH04KI4AAAARo"] [Tue Aug 18 12:56:13.716844 2026] [security2:error] [pid 67073:tid 67231] [client 159.69.158.189:59266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chicodareia.com.br"] [uri "/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSIAAAAi4"], referer: https://www.chicodareia.com.br/ [Tue Aug 18 12:56:13.717019 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:20432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAndO5rbWdOArH04KI4QAAAVU"] [Tue Aug 18 12:56:13.757102 2026] [security2:error] [pid 67073:tid 67326] [client 49.13.130.29:28270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSLgAAAo0"], referer: https://dadicamotors.com.br/ [Tue Aug 18 12:56:13.778670 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xs.php"] [unique_id "aoSAnfcmepr5_nHgLbNSMQAAAmA"] [Tue Aug 18 12:56:13.824483 2026] [security2:error] [pid 66623:tid 66890] [client 20.51.153.15:9193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xf.php"] [unique_id "aoSAndO5rbWdOArH04KI4gAAAYY"] [Tue Aug 18 12:56:13.828577 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ac.php"] [unique_id "aoSAndO5rbWdOArH04KI4wAAAXI"] [Tue Aug 18 12:56:13.846464 2026] [security2:error] [pid 67073:tid 67304] [client 20.79.204.6:2228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/images/wso.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNAAAAnc"] [Tue Aug 18 12:56:13.869589 2026] [security2:error] [pid 66623:tid 66838] [client 172.202.39.151:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-login.php"] [unique_id "aoSAndO5rbWdOArH04KI5AAAAVI"] [Tue Aug 18 12:56:13.873128 2026] [security2:error] [pid 66623:tid 66885] [client 135.225.78.186:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/indes.php"] [unique_id "aoSAndO5rbWdOArH04KI5QAAAYE"] [Tue Aug 18 12:56:13.881494 2026] [security2:error] [pid 67073:tid 67285] [client 213.35.127.232:54581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNQAAAmQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:13.899035 2026] [security2:error] [pid 66623:tid 66883] [client 158.23.17.4:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/bala.php"] [unique_id "aoSAndO5rbWdOArH04KI5gAAAX8"] [Tue Aug 18 12:56:13.901050 2026] [security2:error] [pid 67073:tid 67079] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tp.php"] [unique_id "aoSAnfcmepr5_nHgLbNSNgACbwM"] [Tue Aug 18 12:56:13.927036 2026] [security2:error] [pid 66623:tid 66836] [client 135.225.75.187:58329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/avim.php"] [unique_id "aoSAndO5rbWdOArH04KI5wAAAVA"] [Tue Aug 18 12:56:13.970876 2026] [security2:error] [pid 66623:tid 66865] [client 4.223.164.152:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/155.php"] [unique_id "aoSAndO5rbWdOArH04KI6AAAAW0"] [Tue Aug 18 12:56:13.976253 2026] [security2:error] [pid 67073:tid 67253] [client 86.120.159.145:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSOwAAAkQ"] [Tue Aug 18 12:56:13.976373 2026] [security2:error] [pid 67073:tid 67253] [client 86.120.159.145:54216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnfcmepr5_nHgLbNSOwAAAkQ"] [Tue Aug 18 12:56:13.983693 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:16460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAndO5rbWdOArH04KI6QAAAUg"] [Tue Aug 18 12:56:14.021343 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.56.190:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAntO5rbWdOArH04KI6wAAAYA"] [Tue Aug 18 12:56:14.057517 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:21675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAntO5rbWdOArH04KI7gAAAXM"] [Tue Aug 18 12:56:14.060640 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.49.167:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/aa.php"] [unique_id "aoSAntO5rbWdOArH04KI7wAAAVw"] [Tue Aug 18 12:56:14.062011 2026] [security2:error] [pid 66623:tid 66809] [client 20.29.77.16:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/globals.php"] [unique_id "aoSAntO5rbWdOArH04KI8AAAATU"] [Tue Aug 18 12:56:14.084708 2026] [security2:error] [pid 67073:tid 67252] [client 158.158.74.177:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/p.php"] [unique_id "aoSAnvcmepr5_nHgLbNSPwAAAkM"] [Tue Aug 18 12:56:14.086122 2026] [security2:error] [pid 66623:tid 66849] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yz.php"] [unique_id "aoSAntO5rbWdOArH04KI8QAAAV0"] [Tue Aug 18 12:56:14.111063 2026] [security2:error] [pid 67073:tid 67283] [client 20.163.43.14:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/inputs.php"] [unique_id "aoSAnvcmepr5_nHgLbNSRgAAAmI"] [Tue Aug 18 12:56:14.116224 2026] [security2:error] [pid 66623:tid 66833] [client 20.51.153.15:8750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/eq.php"] [unique_id "aoSAntO5rbWdOArH04KI8gAAAU0"] [Tue Aug 18 12:56:14.127983 2026] [security2:error] [pid 67073:tid 67226] [client 20.116.17.175:57600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSAnvcmepr5_nHgLbNSSgAAAik"] [Tue Aug 18 12:56:14.175591 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:14.175870 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:14.184301 2026] [security2:error] [pid 67073:tid 67268] [client 20.100.169.31:23876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAnvcmepr5_nHgLbNSTwAAAlM"] [Tue Aug 18 12:56:14.196576 2026] [security2:error] [pid 67073:tid 67159] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/zj.php"] [unique_id "aoSAnvcmepr5_nHgLbNSUgACG1M"] [Tue Aug 18 12:56:14.217249 2026] [security2:error] [pid 67073:tid 67206] [client 68.155.156.252:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/nox.php"] [unique_id "aoSAnvcmepr5_nHgLbNSVgAAAhU"] [Tue Aug 18 12:56:14.232822 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:17871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fd.php"] [unique_id "aoSAnvcmepr5_nHgLbNSWAAAAiM"] [Tue Aug 18 12:56:14.282983 2026] [security2:error] [pid 66623:tid 66893] [client 20.52.168.85:7840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/about.php7"] [unique_id "aoSAntO5rbWdOArH04KI8wAAAYk"] [Tue Aug 18 12:56:14.296840 2026] [security2:error] [pid 67073:tid 67241] [client 135.225.78.186:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/tTPcH.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXAAAAjg"] [Tue Aug 18 12:56:14.297935 2026] [security2:error] [pid 67073:tid 67240] [client 213.202.253.4:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/memberfuns.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXQAAAjc"], referer: www.google.com [Tue Aug 18 12:56:14.310332 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.130.103:15403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/xiugai.php"] [unique_id "aoSAnvcmepr5_nHgLbNSXwAAAkU"] [Tue Aug 18 12:56:14.322796 2026] [security2:error] [pid 67073:tid 67311] [client 103.184.169.37:41851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYAAAAn4"] [Tue Aug 18 12:56:14.322903 2026] [security2:error] [pid 67073:tid 67311] [client 103.184.169.37:41851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYAAAAn4"] [Tue Aug 18 12:56:14.334815 2026] [security2:error] [pid 67073:tid 67272] [client 20.42.19.40:2928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.19.42.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadarecantofeliz.com"] [uri "/ioxi-o.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYQAAAlc"] [Tue Aug 18 12:56:14.340123 2026] [security2:error] [pid 66623:tid 66811] [client 20.91.215.254:12139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/al.php"] [unique_id "aoSAntO5rbWdOArH04KI9AAAATc"] [Tue Aug 18 12:56:14.341693 2026] [security2:error] [pid 67073:tid 67279] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kj.php"] [unique_id "aoSAnvcmepr5_nHgLbNSYwAAAl4"] [Tue Aug 18 12:56:14.352064 2026] [security2:error] [pid 66623:tid 66790] [client 20.51.153.15:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ep.php"] [unique_id "aoSAntO5rbWdOArH04KI9QAAASI"] [Tue Aug 18 12:56:14.393647 2026] [security2:error] [pid 66623:tid 66863] [client 4.223.164.152:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.164.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.formafit.com.br"] [uri "/ops.php"] [unique_id "aoSAntO5rbWdOArH04KI9gAAAWs"] [Tue Aug 18 12:56:14.430807 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fd.php"] [unique_id "aoSAnvcmepr5_nHgLbNSZgAAAn0"] [Tue Aug 18 12:56:14.437480 2026] [security2:error] [pid 67073:tid 67190] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/x.php"] [unique_id "aoSAnvcmepr5_nHgLbNSaAACFHI"] [Tue Aug 18 12:56:14.456606 2026] [security2:error] [pid 66623:tid 66845] [client 20.79.204.6:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSAntO5rbWdOArH04KI9wAAAVk"] [Tue Aug 18 12:56:14.530601 2026] [security2:error] [pid 67073:tid 67292] [client 52.173.121.69:17936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAnvcmepr5_nHgLbNSbAAAAms"] [Tue Aug 18 12:56:14.573572 2026] [security2:error] [pid 67073:tid 67278] [client 20.215.241.237:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/dex.php"] [unique_id "aoSAnvcmepr5_nHgLbNSbwAAAl0"] [Tue Aug 18 12:56:14.608409 2026] [security2:error] [pid 66623:tid 66789] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vg.php"] [unique_id "aoSAntO5rbWdOArH04KI-AAAASE"] [Tue Aug 18 12:56:14.615915 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/alfa.php"] [unique_id "aoSAnvcmepr5_nHgLbNScAAAAlI"] [Tue Aug 18 12:56:14.618386 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:60081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI-QAAARc"] [Tue Aug 18 12:56:14.618482 2026] [security2:error] [pid 66623:tid 66779] [client 192.141.172.134:60081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI-QAAARc"] [Tue Aug 18 12:56:14.630775 2026] [security2:error] [pid 67073:tid 67107] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yn.php"] [unique_id "aoSAnvcmepr5_nHgLbNScQAChh8"] [Tue Aug 18 12:56:14.717707 2026] [security2:error] [pid 67073:tid 67239] [client 135.225.78.186:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/bs1.php"] [unique_id "aoSAnvcmepr5_nHgLbNScwAAAjY"] [Tue Aug 18 12:56:14.718910 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:58353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/myfile.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdAAAAmE"] [Tue Aug 18 12:56:14.721151 2026] [security2:error] [pid 67073:tid 67307] [client 20.215.241.237:9238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/222.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdQAAAno"] [Tue Aug 18 12:56:14.738661 2026] [security2:error] [pid 67073:tid 67234] [client 20.51.153.15:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rf.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdgAAAjE"] [Tue Aug 18 12:56:14.741844 2026] [security2:error] [pid 67073:tid 67250] [client 20.151.109.219:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/info2.php"] [unique_id "aoSAnvcmepr5_nHgLbNSdwAAAkE"] [Tue Aug 18 12:56:14.763678 2026] [security2:error] [pid 66623:tid 66844] [client 114.5.214.109:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI_QAAAVg"] [Tue Aug 18 12:56:14.763799 2026] [security2:error] [pid 66623:tid 66844] [client 114.5.214.109:49809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KI_QAAAVg"] [Tue Aug 18 12:56:14.792772 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.56.190:30993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/info2.php"] [unique_id "aoSAnvcmepr5_nHgLbNSfAAAAk0"] [Tue Aug 18 12:56:14.792852 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:14.793283 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:14.801394 2026] [security2:error] [pid 67073:tid 67304] [client 52.238.210.254:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.210.238.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jomaconstrutora.com.br"] [uri "/100.php"] [unique_id "aoSAnvcmepr5_nHgLbNSfQAAAnc"] [Tue Aug 18 12:56:14.806883 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAntO5rbWdOArH04KI_wAAAYI"] [Tue Aug 18 12:56:14.824435 2026] [security2:error] [pid 66623:tid 66846] [client 20.29.77.16:52749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/yindu.php"] [unique_id "aoSAntO5rbWdOArH04KJAAAAAVo"] [Tue Aug 18 12:56:14.846286 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.6.191:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAnvcmepr5_nHgLbNSgQAAAoE"] [Tue Aug 18 12:56:14.851203 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.130.103:15413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/adminner.php"] [unique_id "aoSAntO5rbWdOArH04KJAQAAARs"] [Tue Aug 18 12:56:14.856888 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/11.php"] [unique_id "aoSAnvcmepr5_nHgLbNSgwACWjc"] [Tue Aug 18 12:56:14.864838 2026] [security2:error] [pid 66623:tid 66860] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sm.php"] [unique_id "aoSAntO5rbWdOArH04KJAgAAAWg"] [Tue Aug 18 12:56:14.883989 2026] [security2:error] [pid 66623:tid 66852] [client 20.52.168.85:7821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/cron.php"] [unique_id "aoSAntO5rbWdOArH04KJAwAAAWA"] [Tue Aug 18 12:56:14.896126 2026] [security2:error] [pid 66623:tid 66867] [client 213.35.127.232:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAntO5rbWdOArH04KJBAAAAW8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:14.930162 2026] [security2:error] [pid 67073:tid 67227] [client 20.104.49.167:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/img.php"] [unique_id "aoSAnvcmepr5_nHgLbNShQAAAio"] [Tue Aug 18 12:56:14.944158 2026] [security2:error] [pid 66623:tid 66835] [client 20.163.43.14:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/lock360.php"] [unique_id "aoSAntO5rbWdOArH04KJBQAAAU8"] [Tue Aug 18 12:56:14.980094 2026] [security2:error] [pid 66623:tid 66733] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KJBgABDGA"] [Tue Aug 18 12:56:14.980211 2026] [security2:error] [pid 66623:tid 66768] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAntO5rbWdOArH04KJBgABDGA"] [Tue Aug 18 12:56:14.987009 2026] [security2:error] [pid 66623:tid 66889] [client 104.209.144.33:34141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAntO5rbWdOArH04KJBwAAAYU"] [Tue Aug 18 12:56:15.039700 2026] [security2:error] [pid 66623:tid 66881] [client 172.202.39.151:15683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/bb.php"] [unique_id "aoSAn9O5rbWdOArH04KJCAAAAX0"] [Tue Aug 18 12:56:15.041964 2026] [security2:error] [pid 67073:tid 67290] [client 20.91.215.254:12114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp.php"] [unique_id "aoSAn_cmepr5_nHgLbNSiAAAAmk"] [Tue Aug 18 12:56:15.065531 2026] [security2:error] [pid 67073:tid 67285] [client 20.79.204.6:2377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSAn_cmepr5_nHgLbNSiQAAAmQ"] [Tue Aug 18 12:56:15.073022 2026] [security2:error] [pid 67073:tid 67180] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vm.php"] [unique_id "aoSAn_cmepr5_nHgLbNSigACWGg"] [Tue Aug 18 12:56:15.081244 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:15.081524 2026] [authz_core:error] [pid 67073:tid 67103] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:15.105446 2026] [security2:error] [pid 67073:tid 67252] [client 20.151.109.219:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sx.php"] [unique_id "aoSAn_cmepr5_nHgLbNSjAAAAkM"] [Tue Aug 18 12:56:15.125960 2026] [security2:error] [pid 66623:tid 66778] [client 172.202.39.151:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAn9O5rbWdOArH04KJCQAAARY"] [Tue Aug 18 12:56:15.138855 2026] [security2:error] [pid 66623:tid 66887] [client 135.225.78.186:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/hp2.php"] [unique_id "aoSAn9O5rbWdOArH04KJCgAAAYM"] [Tue Aug 18 12:56:15.140628 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/28.php"] [unique_id "aoSAn9O5rbWdOArH04KJCwAAAYQ"] [Tue Aug 18 12:56:15.174467 2026] [security2:error] [pid 66623:tid 66837] [client 20.51.153.15:8397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/album.php"] [unique_id "aoSAn9O5rbWdOArH04KJDAAAAVE"] [Tue Aug 18 12:56:15.218385 2026] [security2:error] [pid 66623:tid 66814] [client 138.36.100.162:41604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn9O5rbWdOArH04KJDQAAATo"] [Tue Aug 18 12:56:15.239285 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAn9O5rbWdOArH04KJDgAAATQ"] [Tue Aug 18 12:56:15.245648 2026] [security2:error] [pid 66623:tid 66788] [client 20.226.56.190:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sx.php"] [unique_id "aoSAn9O5rbWdOArH04KJDwAAASA"] [Tue Aug 18 12:56:15.253230 2026] [security2:error] [pid 66623:tid 66784] [client 20.29.77.16:47797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sxx.php"] [unique_id "aoSAn9O5rbWdOArH04KJEAAAARw"] [Tue Aug 18 12:56:15.277063 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAn9O5rbWdOArH04KJEQAAARE"] [Tue Aug 18 12:56:15.315973 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/flower.php"] [unique_id "aoSAn9O5rbWdOArH04KJEwAAATI"] [Tue Aug 18 12:56:15.343937 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eg.php"] [unique_id "aoSAn_cmepr5_nHgLbNSkwACXFo"] [Tue Aug 18 12:56:15.358762 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.130.103:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file1221.php"] [unique_id "aoSAn9O5rbWdOArH04KJFQAAARo"] [Tue Aug 18 12:56:15.380256 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:15.380527 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:15.394648 2026] [security2:error] [pid 66623:tid 66841] [client 20.116.17.175:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/df.php"] [unique_id "aoSAn9O5rbWdOArH04KJFgAAAVU"] [Tue Aug 18 12:56:15.395485 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/m.php"] [unique_id "aoSAn_cmepr5_nHgLbNSlgAAAnY"] [Tue Aug 18 12:56:15.407485 2026] [security2:error] [pid 67073:tid 67327] [client 20.171.51.14:30962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/32.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmAAAAo4"] [Tue Aug 18 12:56:15.414419 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.136.165:28142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/jq.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmQAAAkc"] [Tue Aug 18 12:56:15.435025 2026] [security2:error] [pid 67073:tid 67212] [client 20.151.109.219:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nu.php"] [unique_id "aoSAn_cmepr5_nHgLbNSmgAAAhs"] [Tue Aug 18 12:56:15.483334 2026] [security2:error] [pid 66623:tid 66816] [client 20.52.168.85:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-2019.php"] [unique_id "aoSAn9O5rbWdOArH04KJGAAAATw"] [Tue Aug 18 12:56:15.492419 2026] [security2:error] [pid 67073:tid 67232] [client 20.51.153.15:8755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tp.php"] [unique_id "aoSAn_cmepr5_nHgLbNSnQAAAi8"] [Tue Aug 18 12:56:15.556068 2026] [security2:error] [pid 67073:tid 67208] [client 135.225.78.186:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/yb.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpAAAAhc"] [Tue Aug 18 12:56:15.587761 2026] [security2:error] [pid 67073:tid 67171] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/uk.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpgACJV8"] [Tue Aug 18 12:56:15.631512 2026] [security2:error] [pid 66623:tid 66814] [client 138.36.100.162:41604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn9O5rbWdOArH04KJDQAAATo"] [Tue Aug 18 12:56:15.650139 2026] [security2:error] [pid 67073:tid 67311] [client 20.226.56.190:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nu.php"] [unique_id "aoSAn_cmepr5_nHgLbNSpwAAAn4"] [Tue Aug 18 12:56:15.654066 2026] [security2:error] [pid 67073:tid 67318] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nl.php"] [unique_id "aoSAn_cmepr5_nHgLbNSqAAAAoU"] [Tue Aug 18 12:56:15.679828 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:15.680094 2026] [authz_core:error] [pid 67073:tid 67153] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:15.685954 2026] [security2:error] [pid 67073:tid 67206] [client 20.79.204.6:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/profile.php"] [unique_id "aoSAn_cmepr5_nHgLbNSqwAAAhU"] [Tue Aug 18 12:56:15.687738 2026] [security2:error] [pid 66623:tid 66787] [client 20.163.43.14:4191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/13.php"] [unique_id "aoSAn9O5rbWdOArH04KJGgAAAR8"] [Tue Aug 18 12:56:15.704170 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.6.191:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAn_cmepr5_nHgLbNSrAAAAnM"] [Tue Aug 18 12:56:15.747440 2026] [security2:error] [pid 66623:tid 66856] [client 20.250.13.23:19456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/manager.php"] [unique_id "aoSAn9O5rbWdOArH04KJGwAAAWQ"] [Tue Aug 18 12:56:15.776240 2026] [security2:error] [pid 67073:tid 67306] [client 20.151.109.219:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ko.php"] [unique_id "aoSAn_cmepr5_nHgLbNSrwAAAnk"] [Tue Aug 18 12:56:15.784709 2026] [security2:error] [pid 67073:tid 67080] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/creds.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsAACMgQ"] [Tue Aug 18 12:56:15.803626 2026] [security2:error] [pid 67073:tid 67276] [client 20.51.153.15:8793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/eg.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsQAAAls"] [Tue Aug 18 12:56:15.819819 2026] [security2:error] [pid 67073:tid 67274] [client 20.91.215.254:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-activat.php"] [unique_id "aoSAn_cmepr5_nHgLbNSsgAAAlk"] [Tue Aug 18 12:56:15.822119 2026] [security2:error] [pid 66623:tid 66865] [client 52.173.121.69:24777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAn9O5rbWdOArH04KJHAAAAW0"] [Tue Aug 18 12:56:15.876157 2026] [security2:error] [pid 67073:tid 67278] [client 135.225.75.187:62335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xmy.php"] [unique_id "aoSAn_cmepr5_nHgLbNSuAAAAl0"] [Tue Aug 18 12:56:15.877544 2026] [security2:error] [pid 67073:tid 67305] [client 5.31.227.224:29905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn_cmepr5_nHgLbNStwAAAng"] [Tue Aug 18 12:56:15.877678 2026] [security2:error] [pid 67073:tid 67305] [client 5.31.227.224:29905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAn_cmepr5_nHgLbNStwAAAng"] [Tue Aug 18 12:56:15.901030 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/68.php"] [unique_id "aoSAn_cmepr5_nHgLbNSuwAAAmU"] [Tue Aug 18 12:56:15.912119 2026] [security2:error] [pid 66623:tid 66767] [client 74.248.130.103:25738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inx.php"] [unique_id "aoSAn9O5rbWdOArH04KJHQAAAQs"] [Tue Aug 18 12:56:15.913071 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwAAAAjc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:15.922333 2026] [security2:error] [pid 67073:tid 67309] [client 20.104.49.167:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/222.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwgAAAnw"] [Tue Aug 18 12:56:15.927133 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAn_cmepr5_nHgLbNSwwAAAjw"] [Tue Aug 18 12:56:15.949305 2026] [security2:error] [pid 66623:tid 66809] [client 20.171.51.14:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/73.php"] [unique_id "aoSAn9O5rbWdOArH04KJHgAAATU"] [Tue Aug 18 12:56:15.961140 2026] [security2:error] [pid 67073:tid 67307] [client 20.226.56.190:45029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ko.php"] [unique_id "aoSAn_cmepr5_nHgLbNSxwAAAno"] [Tue Aug 18 12:56:15.965864 2026] [security2:error] [pid 67073:tid 67224] [client 68.155.156.252:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/akismet.php"] [unique_id "aoSAn_cmepr5_nHgLbNSyAAAAic"] [Tue Aug 18 12:56:15.971634 2026] [security2:error] [pid 67073:tid 67234] [client 135.225.78.186:13004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/vc.php"] [unique_id "aoSAn_cmepr5_nHgLbNSyQAAAjE"] [Tue Aug 18 12:56:15.981179 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:15.981330 2026] [security2:error] [pid 67073:tid 67176] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ho.php"] [unique_id "aoSAn_cmepr5_nHgLbNSywACGGQ"] [Tue Aug 18 12:56:15.981453 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:16.019610 2026] [security2:error] [pid 67073:tid 67215] [client 158.23.17.4:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/222.php"] [unique_id "aoSAoPcmepr5_nHgLbNSzAAAAh4"] [Tue Aug 18 12:56:16.030336 2026] [security2:error] [pid 66623:tid 66849] [client 20.163.43.14:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cc.php"] [unique_id "aoSAoNO5rbWdOArH04KJHwAAAV0"] [Tue Aug 18 12:56:16.044045 2026] [security2:error] [pid 67073:tid 67326] [client 20.29.77.16:27223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/settings.php"] [unique_id "aoSAoPcmepr5_nHgLbNSzgAAAo0"] [Tue Aug 18 12:56:16.060702 2026] [security2:error] [pid 66623:tid 66876] [client 158.158.74.177:16545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/pages.php"] [unique_id "aoSAoNO5rbWdOArH04KJIAAAAXg"] [Tue Aug 18 12:56:16.070672 2026] [security2:error] [pid 67073:tid 67248] [client 20.100.169.31:30277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/404.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0AAAAj8"] [Tue Aug 18 12:56:16.089134 2026] [security2:error] [pid 67073:tid 67231] [client 20.151.109.219:12926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/pl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0QAAAi4"] [Tue Aug 18 12:56:16.090130 2026] [security2:error] [pid 67073:tid 67242] [client 20.52.168.85:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/gecko-new.php"] [unique_id "aoSAoPcmepr5_nHgLbNS0gAAAjk"] [Tue Aug 18 12:56:16.122597 2026] [security2:error] [pid 67073:tid 67275] [client 104.209.144.33:19624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1AAAAlo"] [Tue Aug 18 12:56:16.136099 2026] [security2:error] [pid 67073:tid 67302] [client 20.51.153.15:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/uk.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1gAAAnU"] [Tue Aug 18 12:56:16.148898 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS1wAAAm8"] [Tue Aug 18 12:56:16.164738 2026] [security2:error] [pid 67073:tid 67271] [client 37.40.227.74:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2AAAAlY"] [Tue Aug 18 12:56:16.164853 2026] [security2:error] [pid 67073:tid 67271] [client 37.40.227.74:56666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2AAAAlY"] [Tue Aug 18 12:56:16.180383 2026] [security2:error] [pid 67073:tid 67135] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/97.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2QACaDs"] [Tue Aug 18 12:56:16.191192 2026] [security2:error] [pid 67073:tid 67217] [client 172.182.200.96:14169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAoPcmepr5_nHgLbNS2gAAAiA"] [Tue Aug 18 12:56:16.211123 2026] [security2:error] [pid 67073:tid 67244] [client 20.226.56.190:3014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/pl.php"] [unique_id "aoSAoPcmepr5_nHgLbNS3AAAAjs"] [Tue Aug 18 12:56:16.290296 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSAoPcmepr5_nHgLbNS3wAAAmA"] [Tue Aug 18 12:56:16.313351 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.6.191:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/rip.php"] [unique_id "aoSAoPcmepr5_nHgLbNS4QAAApA"] [Tue Aug 18 12:56:16.367689 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gecko-new.php"] [unique_id "aoSAoPcmepr5_nHgLbNS4gAAAoA"] [Tue Aug 18 12:56:16.392575 2026] [security2:error] [pid 67073:tid 67303] [client 135.225.78.186:13014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/pema.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5AAAAnY"] [Tue Aug 18 12:56:16.405641 2026] [security2:error] [pid 67073:tid 67294] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tq.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5gAAAm0"] [Tue Aug 18 12:56:16.405781 2026] [security2:error] [pid 67073:tid 67091] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rh.php"] [unique_id "aoSAoPcmepr5_nHgLbNS5wACIQ8"] [Tue Aug 18 12:56:16.419512 2026] [security2:error] [pid 67073:tid 67212] [client 20.51.153.15:8792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/creds.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6QAAAhs"] [Tue Aug 18 12:56:16.443791 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/env.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6gAAAik"] [Tue Aug 18 12:56:16.467642 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.130.103:38679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/reviall.php"] [unique_id "aoSAoPcmepr5_nHgLbNS6wAAAiM"] [Tue Aug 18 12:56:16.503610 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/key.php"] [unique_id "aoSAoPcmepr5_nHgLbNS7QAAAiU"] [Tue Aug 18 12:56:16.532523 2026] [security2:error] [pid 67073:tid 67317] [client 85.208.96.198:27764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754206526/1756598400/"] [unique_id "aoSAoPcmepr5_nHgLbNS7gAAAoQ"] [Tue Aug 18 12:56:16.532649 2026] [security2:error] [pid 67073:tid 67317] [client 85.208.96.198:27764] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754206526/1756598400/"] [unique_id "aoSAoPcmepr5_nHgLbNS7gAAAoQ"] [Tue Aug 18 12:56:16.564749 2026] [authz_core:error] [pid 67073:tid 67147] [remote 57.141.22.106:64130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:16.565021 2026] [authz_core:error] [pid 67073:tid 67147] [remote 57.141.22.106:64130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:16.586774 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.136.165:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sys.php"] [unique_id "aoSAoPcmepr5_nHgLbNS8wAAAmY"] [Tue Aug 18 12:56:16.596373 2026] [security2:error] [pid 67073:tid 67251] [client 20.91.215.254:11922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNS9AAAAkI"] [Tue Aug 18 12:56:16.628148 2026] [security2:error] [pid 66623:tid 66831] [client 20.104.49.167:19328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/key.php"] [unique_id "aoSAoNO5rbWdOArH04KJIwAAAUs"] [Tue Aug 18 12:56:16.636661 2026] [security2:error] [pid 67073:tid 67081] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/yg.php"] [unique_id "aoSAoPcmepr5_nHgLbNS9QACeQU"] [Tue Aug 18 12:56:16.667377 2026] [security2:error] [pid 66623:tid 66882] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/cv.php"] [unique_id "aoSAoNO5rbWdOArH04KJJAAAAX4"] [Tue Aug 18 12:56:16.676124 2026] [security2:error] [pid 67073:tid 67276] [client 20.51.153.15:8744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ho.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-AAAAls"] [Tue Aug 18 12:56:16.689131 2026] [security2:error] [pid 67073:tid 67264] [client 20.52.168.85:7865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/add_actualites.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-QAAAk8"] [Tue Aug 18 12:56:16.704994 2026] [security2:error] [pid 67073:tid 67332] [client 20.163.43.14:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-gAAApM"] [Tue Aug 18 12:56:16.746943 2026] [security2:error] [pid 67073:tid 67305] [client 104.209.144.33:29833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAoPcmepr5_nHgLbNS-wAAAng"] [Tue Aug 18 12:56:16.749797 2026] [security2:error] [pid 66623:tid 66871] [client 157.20.138.62:60411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoNO5rbWdOArH04KJJQAAAXM"] [Tue Aug 18 12:56:16.749911 2026] [security2:error] [pid 66623:tid 66871] [client 157.20.138.62:60411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoNO5rbWdOArH04KJJQAAAXM"] [Tue Aug 18 12:56:16.769361 2026] [autoindex:error] [pid 67073:tid 67263] [client 20.226.6.191:55807] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:16.809605 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.78.186:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/sh.php"] [unique_id "aoSAoPcmepr5_nHgLbNS_wAAAlA"] [Tue Aug 18 12:56:16.814027 2026] [security2:error] [pid 66623:tid 66868] [client 20.226.56.190:23767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/env.php"] [unique_id "aoSAoNO5rbWdOArH04KJJgAAAXA"] [Tue Aug 18 12:56:16.815531 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.6.191:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAoPcmepr5_nHgLbNTBQAAAnw"] [Tue Aug 18 12:56:16.821651 2026] [security2:error] [pid 67073:tid 67310] [client 20.151.109.219:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mz.php"] [unique_id "aoSAoPcmepr5_nHgLbNTBwAAAn0"] [Tue Aug 18 12:56:16.834701 2026] [security2:error] [pid 67073:tid 67148] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/et.php"] [unique_id "aoSAoPcmepr5_nHgLbNTCQACJ0g"] [Tue Aug 18 12:56:16.879825 2026] [security2:error] [pid 66623:tid 66863] [client 172.202.39.151:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cah.php"] [unique_id "aoSAoNO5rbWdOArH04KJKAAAAWs"] [Tue Aug 18 12:56:16.893367 2026] [security2:error] [pid 67073:tid 67221] [client 20.79.204.6:2634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSAoPcmepr5_nHgLbNTDQAAAiQ"] [Tue Aug 18 12:56:16.901984 2026] [security2:error] [pid 66623:tid 66845] [client 52.173.121.69:17950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAoNO5rbWdOArH04KJKQAAAVk"] [Tue Aug 18 12:56:16.924837 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/un.php"] [unique_id "aoSAoPcmepr5_nHgLbNTDwAAAkw"] [Tue Aug 18 12:56:16.928311 2026] [security2:error] [pid 67073:tid 67207] [client 213.35.127.232:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEAAAAhY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:16.933116 2026] [security2:error] [pid 67073:tid 67326] [client 74.248.130.103:25761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/11.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEQAAAo0"] [Tue Aug 18 12:56:16.966790 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSAoNO5rbWdOArH04KJKgAAAYg"] [Tue Aug 18 12:56:16.967977 2026] [security2:error] [pid 67073:tid 67262] [client 20.226.56.190:28271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mz.php"] [unique_id "aoSAoPcmepr5_nHgLbNTEwAAAk0"] [Tue Aug 18 12:56:16.975732 2026] [security2:error] [pid 67073:tid 67321] [client 20.51.153.15:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/97.php"] [unique_id "aoSAoPcmepr5_nHgLbNTFAAAAog"] [Tue Aug 18 12:56:16.994448 2026] [security2:error] [pid 66623:tid 66799] [client 20.215.241.237:27245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/puc.php"] [unique_id "aoSAoNO5rbWdOArH04KJKwAAASs"] [Tue Aug 18 12:56:16.996967 2026] [security2:error] [pid 66623:tid 66795] [client 135.225.75.187:17716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xda.php"] [unique_id "aoSAoNO5rbWdOArH04KJLAAAASc"] [Tue Aug 18 12:56:17.030055 2026] [security2:error] [pid 67073:tid 67315] [client 20.250.13.23:13766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/w1.php"] [unique_id "aoSAofcmepr5_nHgLbNTFQAAAoI"] [Tue Aug 18 12:56:17.036746 2026] [security2:error] [pid 66623:tid 66874] [client 20.163.43.14:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/01.php"] [unique_id "aoSAodO5rbWdOArH04KJLQAAAXY"] [Tue Aug 18 12:56:17.088519 2026] [security2:error] [pid 67073:tid 67195] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/of.php"] [unique_id "aoSAofcmepr5_nHgLbNTFwACb3c"] [Tue Aug 18 12:56:17.179532 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.156.252:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/admin.php"] [unique_id "aoSAodO5rbWdOArH04KJLwAAAVM"] [Tue Aug 18 12:56:17.181991 2026] [security2:error] [pid 67073:tid 67331] [client 20.151.109.219:21662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ft.php"] [unique_id "aoSAofcmepr5_nHgLbNTHQAAApI"] [Tue Aug 18 12:56:17.183285 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:17.183515 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:17.186108 2026] [security2:error] [pid 67073:tid 67289] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/evil.php"] [unique_id "aoSAofcmepr5_nHgLbNTHgAAAmg"] [Tue Aug 18 12:56:17.230876 2026] [security2:error] [pid 67073:tid 67244] [client 135.225.78.186:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/button.php"] [unique_id "aoSAofcmepr5_nHgLbNTHwAAAjs"] [Tue Aug 18 12:56:17.266369 2026] [security2:error] [pid 67073:tid 67228] [client 20.215.241.237:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAofcmepr5_nHgLbNTIQAAAis"] [Tue Aug 18 12:56:17.271265 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:11484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSAofcmepr5_nHgLbNTIgAAAig"] [Tue Aug 18 12:56:17.283253 2026] [security2:error] [pid 66623:tid 66846] [client 20.29.77.16:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/spip.php"] [unique_id "aoSAodO5rbWdOArH04KJMQAAAVo"] [Tue Aug 18 12:56:17.284933 2026] [security2:error] [pid 66623:tid 66783] [client 20.51.153.15:8802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rh.php"] [unique_id "aoSAodO5rbWdOArH04KJMgAAARs"] [Tue Aug 18 12:56:17.292500 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bu.php"] [unique_id "aoSAofcmepr5_nHgLbNTIwACNF4"] [Tue Aug 18 12:56:17.292858 2026] [security2:error] [pid 66623:tid 66820] [client 20.52.168.85:8004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/browse.php"] [unique_id "aoSAodO5rbWdOArH04KJMwAAAUA"] [Tue Aug 18 12:56:17.304263 2026] [security2:error] [pid 67073:tid 67234] [client 149.34.210.141:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTJAAAAjE"] [Tue Aug 18 12:56:17.314197 2026] [security2:error] [pid 66623:tid 66789] [client 20.91.215.254:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/past1.php"] [unique_id "aoSAodO5rbWdOArH04KJNAAAASE"] [Tue Aug 18 12:56:17.352028 2026] [security2:error] [pid 67073:tid 67312] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTGgACfyo"] [Tue Aug 18 12:56:17.364358 2026] [security2:error] [pid 67073:tid 67281] [client 20.163.43.14:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/lv.php"] [unique_id "aoSAofcmepr5_nHgLbNTKAAAAmA"] [Tue Aug 18 12:56:17.384049 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.6.191:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/moon.php"] [unique_id "aoSAofcmepr5_nHgLbNTKQAAAos"] [Tue Aug 18 12:56:17.418739 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.130.103:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/File.php"] [unique_id "aoSAofcmepr5_nHgLbNTKwAAApA"] [Tue Aug 18 12:56:17.453409 2026] [security2:error] [pid 67073:tid 67313] [client 104.209.144.33:36489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAofcmepr5_nHgLbNTLAAAAoA"] [Tue Aug 18 12:56:17.453558 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pw.php"] [unique_id "aoSAofcmepr5_nHgLbNTLQAAAmE"] [Tue Aug 18 12:56:17.490776 2026] [security2:error] [pid 67073:tid 67128] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rn.php"] [unique_id "aoSAofcmepr5_nHgLbNTMAACdjQ"] [Tue Aug 18 12:56:17.511426 2026] [security2:error] [pid 66623:tid 66852] [client 20.79.204.6:2400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSAodO5rbWdOArH04KJNwAAAWA"] [Tue Aug 18 12:56:17.558463 2026] [security2:error] [pid 66623:tid 66834] [client 52.139.47.57:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/as.php"] [unique_id "aoSAodO5rbWdOArH04KJOAAAAU4"] [Tue Aug 18 12:56:17.566365 2026] [security2:error] [pid 67073:tid 67218] [client 20.51.153.15:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/yg.php"] [unique_id "aoSAofcmepr5_nHgLbNTMgAAAiE"] [Tue Aug 18 12:56:17.571117 2026] [security2:error] [pid 67073:tid 67234] [client 149.34.210.141:52656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAofcmepr5_nHgLbNTJAAAAjE"] [Tue Aug 18 12:56:17.641861 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.56.190:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ft.php"] [unique_id "aoSAodO5rbWdOArH04KJOgAAAXw"] [Tue Aug 18 12:56:17.648420 2026] [security2:error] [pid 66623:tid 66840] [client 135.225.78.186:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/wlc.php"] [unique_id "aoSAodO5rbWdOArH04KJOwAAAVQ"] [Tue Aug 18 12:56:17.675760 2026] [security2:error] [pid 66623:tid 66804] [client 20.104.49.167:3570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/chosen.php"] [unique_id "aoSAodO5rbWdOArH04KJPQAAATA"] [Tue Aug 18 12:56:17.685083 2026] [security2:error] [pid 67073:tid 67219] [client 20.151.109.219:17599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/h.php"] [unique_id "aoSAofcmepr5_nHgLbNTNgAAAiI"] [Tue Aug 18 12:56:17.709161 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fn.php"] [unique_id "aoSAofcmepr5_nHgLbNTOAAAAn4"] [Tue Aug 18 12:56:17.710072 2026] [security2:error] [pid 67073:tid 67145] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ut.php"] [unique_id "aoSAofcmepr5_nHgLbNTOQAChUU"] [Tue Aug 18 12:56:17.714978 2026] [security2:error] [pid 67073:tid 67317] [client 20.163.43.14:4107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/new.php"] [unique_id "aoSAofcmepr5_nHgLbNTOgAAAoQ"] [Tue Aug 18 12:56:17.740439 2026] [security2:error] [pid 67073:tid 67316] [client 132.196.61.152:60340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/special.php"] [unique_id "aoSAofcmepr5_nHgLbNTOwAAAoM"] [Tue Aug 18 12:56:17.786419 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:17.786691 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:17.796001 2026] [security2:error] [pid 66623:tid 66866] [client 20.215.241.237:20994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/domvf.php"] [unique_id "aoSAodO5rbWdOArH04KJPgAAAW4"] [Tue Aug 18 12:56:17.812658 2026] [security2:error] [pid 66623:tid 66887] [client 20.226.6.191:32268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/cache.php"] [unique_id "aoSAodO5rbWdOArH04KJPwAAAYM"] [Tue Aug 18 12:56:17.818843 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.136.165:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/pp.php"] [unique_id "aoSAodO5rbWdOArH04KJQAAAAYQ"] [Tue Aug 18 12:56:17.829147 2026] [security2:error] [pid 67073:tid 67211] [client 158.23.17.4:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/routes.php"] [unique_id "aoSAofcmepr5_nHgLbNTPwAAAho"] [Tue Aug 18 12:56:17.847119 2026] [security2:error] [pid 67073:tid 67251] [client 20.51.153.15:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/et.php"] [unique_id "aoSAofcmepr5_nHgLbNTQAAAAkI"] [Tue Aug 18 12:56:17.871081 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.130.103:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fi22.php"] [unique_id "aoSAodO5rbWdOArH04KJQQAAAWk"] [Tue Aug 18 12:56:17.902294 2026] [security2:error] [pid 67073:tid 67293] [client 20.52.168.85:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/contentloader1.php"] [unique_id "aoSAofcmepr5_nHgLbNTQgAAAmw"] [Tue Aug 18 12:56:17.920360 2026] [security2:error] [pid 67073:tid 67299] [client 20.116.17.175:57649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/usr.php"] [unique_id "aoSAofcmepr5_nHgLbNTQwAAAnI"] [Tue Aug 18 12:56:17.942110 2026] [security2:error] [pid 67073:tid 67230] [client 213.35.127.232:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAofcmepr5_nHgLbNTRAAAAi0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:17.945896 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.154.236:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAofcmepr5_nHgLbNTRQAAAjI"] [Tue Aug 18 12:56:17.952305 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.56.190:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/h.php"] [unique_id "aoSAofcmepr5_nHgLbNTRwAAAls"] [Tue Aug 18 12:56:17.956499 2026] [security2:error] [pid 67073:tid 67082] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/eh.php"] [unique_id "aoSAofcmepr5_nHgLbNTSAACTwY"] [Tue Aug 18 12:56:17.989566 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kf.php"] [unique_id "aoSAodO5rbWdOArH04KJRAAAAR0"] [Tue Aug 18 12:56:18.007765 2026] [security2:error] [pid 66623:tid 66877] [client 172.202.39.151:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAotO5rbWdOArH04KJRQAAAXk"] [Tue Aug 18 12:56:18.054397 2026] [security2:error] [pid 66623:tid 66875] [client 20.163.43.14:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/222.php"] [unique_id "aoSAotO5rbWdOArH04KJRgAAAXc"] [Tue Aug 18 12:56:18.062538 2026] [security2:error] [pid 67073:tid 67319] [client 20.29.77.16:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/search.php"] [unique_id "aoSAovcmepr5_nHgLbNTTQAAAoY"] [Tue Aug 18 12:56:18.071204 2026] [security2:error] [pid 67073:tid 67295] [client 135.225.78.186:13055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/fi.php"] [unique_id "aoSAovcmepr5_nHgLbNTTwAAAm4"] [Tue Aug 18 12:56:18.090591 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:18.091060 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:18.101576 2026] [security2:error] [pid 67073:tid 67287] [client 20.91.215.254:11905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/file61.php"] [unique_id "aoSAovcmepr5_nHgLbNTUgAAAmY"] [Tue Aug 18 12:56:18.107710 2026] [security2:error] [pid 67073:tid 67249] [client 20.215.241.237:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/chosen.php"] [unique_id "aoSAovcmepr5_nHgLbNTUwAAAkA"] [Tue Aug 18 12:56:18.118893 2026] [security2:error] [pid 66623:tid 66784] [client 104.209.144.33:35889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAotO5rbWdOArH04KJRwAAARw"] [Tue Aug 18 12:56:18.162433 2026] [autoindex:error] [pid 67073:tid 67306] [client 20.79.204.6:2423] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:18.177069 2026] [security2:error] [pid 67073:tid 67221] [client 135.225.75.187:29760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zz.php"] [unique_id "aoSAovcmepr5_nHgLbNTVgAAAiQ"] [Tue Aug 18 12:56:18.182293 2026] [security2:error] [pid 67073:tid 67261] [client 20.51.153.15:9127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/of.php"] [unique_id "aoSAovcmepr5_nHgLbNTVwAAAkw"] [Tue Aug 18 12:56:18.188199 2026] [security2:error] [pid 67073:tid 67175] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ad.php"] [unique_id "aoSAovcmepr5_nHgLbNTWAACFmM"] [Tue Aug 18 12:56:18.242766 2026] [security2:error] [pid 66623:tid 66810] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/su.php"] [unique_id "aoSAotO5rbWdOArH04KJSAAAATY"] [Tue Aug 18 12:56:18.253119 2026] [autoindex:error] [pid 67073:tid 67308] [client 172.202.39.151:50193] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:18.271923 2026] [security2:error] [pid 67073:tid 67315] [client 20.226.56.190:31637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/40.php"] [unique_id "aoSAovcmepr5_nHgLbNTXQAAAoI"] [Tue Aug 18 12:56:18.325403 2026] [security2:error] [pid 67073:tid 67240] [client 79.127.164.8:35640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost.bak"] [unique_id "aoSAovcmepr5_nHgLbNTYAAAAjc"], referer: https://medihub.com.br/localhost.bak [Tue Aug 18 12:56:18.331759 2026] [security2:error] [pid 67073:tid 67314] [client 20.215.241.237:44770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAovcmepr5_nHgLbNTYQAAAoE"] [Tue Aug 18 12:56:18.362112 2026] [security2:error] [pid 67073:tid 67301] [client 20.79.204.6:2423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAovcmepr5_nHgLbNTZQAAAnQ"] [Tue Aug 18 12:56:18.367748 2026] [security2:error] [pid 66623:tid 66850] [client 20.151.109.219:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/40.php"] [unique_id "aoSAotO5rbWdOArH04KJTQAAAV4"] [Tue Aug 18 12:56:18.381227 2026] [security2:error] [pid 67073:tid 67248] [client 20.163.43.14:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/chosen.php"] [unique_id "aoSAovcmepr5_nHgLbNTaQAAAj8"] [Tue Aug 18 12:56:18.393904 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:18.394156 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:18.397224 2026] [security2:error] [pid 67073:tid 67110] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/vd.php"] [unique_id "aoSAovcmepr5_nHgLbNTawACKCI"] [Tue Aug 18 12:56:18.431766 2026] [security2:error] [pid 66623:tid 66778] [client 178.153.171.161:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAotO5rbWdOArH04KJTgAAARY"] [Tue Aug 18 12:56:18.431931 2026] [security2:error] [pid 66623:tid 66778] [client 178.153.171.161:58888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAotO5rbWdOArH04KJTgAAARY"] [Tue Aug 18 12:56:18.453510 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/bu.php"] [unique_id "aoSAovcmepr5_nHgLbNTbQAAAmk"] [Tue Aug 18 12:56:18.482578 2026] [autoindex:error] [pid 67073:tid 67239] [client 20.226.6.191:36367] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:18.484100 2026] [security2:error] [pid 67073:tid 67198] [remote 162.241.153.188:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactads.com.br"] [uri "/wp-login.php"] [unique_id "aoSAovcmepr5_nHgLbNTbwACeHo"] [Tue Aug 18 12:56:18.484125 2026] [security2:error] [pid 67073:tid 67256] [client 158.158.34.183:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/24.php"] [unique_id "aoSAovcmepr5_nHgLbNTcAAAAkc"] [Tue Aug 18 12:56:18.489970 2026] [security2:error] [pid 67073:tid 67246] [client 135.225.78.186:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/chris.php"] [unique_id "aoSAovcmepr5_nHgLbNTcgAAAj0"] [Tue Aug 18 12:56:18.490824 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wp-key.php"] [unique_id "aoSAotO5rbWdOArH04KJUAAAAUI"] [Tue Aug 18 12:56:18.491292 2026] [security2:error] [pid 67073:tid 67253] [client 68.155.156.252:38864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.corpuspamassagem.com.br"] [uri "/ajax.php"] [unique_id "aoSAovcmepr5_nHgLbNTcwAAAkQ"] [Tue Aug 18 12:56:18.494564 2026] [security2:error] [pid 66623:tid 66885] [client 20.226.56.190:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ee.php"] [unique_id "aoSAotO5rbWdOArH04KJUQAAAYE"] [Tue Aug 18 12:56:18.503562 2026] [security2:error] [pid 66623:tid 66772] [client 20.52.168.85:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/upfile.php"] [unique_id "aoSAotO5rbWdOArH04KJUgAAARA"] [Tue Aug 18 12:56:18.515837 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.130.103:14403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSAovcmepr5_nHgLbNTdgAAAmQ"] [Tue Aug 18 12:56:18.545178 2026] [security2:error] [pid 67073:tid 67329] [client 172.202.39.151:50193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/system_log.php"] [unique_id "aoSAovcmepr5_nHgLbNTeAAAApA"] [Tue Aug 18 12:56:18.594238 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/56.php"] [unique_id "aoSAovcmepr5_nHgLbNTewACSQA"] [Tue Aug 18 12:56:18.627655 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.6.191:36367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAovcmepr5_nHgLbNTfwAAAh0"] [Tue Aug 18 12:56:18.660461 2026] [security2:error] [pid 66623:tid 66824] [client 20.29.77.16:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/build.php"] [unique_id "aoSAotO5rbWdOArH04KJVAAAAUQ"] [Tue Aug 18 12:56:18.716592 2026] [security2:error] [pid 67073:tid 67210] [client 20.51.153.15:8801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/vd.php"] [unique_id "aoSAovcmepr5_nHgLbNThQAAAhk"] [Tue Aug 18 12:56:18.717125 2026] [security2:error] [pid 66623:tid 66828] [client 20.104.49.167:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wpxml.php"] [unique_id "aoSAotO5rbWdOArH04KJVgAAAUg"] [Tue Aug 18 12:56:18.744154 2026] [security2:error] [pid 67073:tid 67247] [client 20.163.43.14:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/info.php"] [unique_id "aoSAovcmepr5_nHgLbNThgAAAj4"] [Tue Aug 18 12:56:18.749027 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gg.php"] [unique_id "aoSAovcmepr5_nHgLbNThwAAAn4"] [Tue Aug 18 12:56:18.754149 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.169.31:43004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/96i.php"] [unique_id "aoSAovcmepr5_nHgLbNTiAAAAjQ"] [Tue Aug 18 12:56:18.783066 2026] [security2:error] [pid 67073:tid 67211] [client 20.151.109.219:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ee.php"] [unique_id "aoSAovcmepr5_nHgLbNTiwAAAho"] [Tue Aug 18 12:56:18.791753 2026] [security2:error] [pid 67073:tid 67194] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/rx.php"] [unique_id "aoSAovcmepr5_nHgLbNTjAACQnY"] [Tue Aug 18 12:56:18.803034 2026] [security2:error] [pid 67073:tid 67294] [client 20.215.241.237:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gec.php"] [unique_id "aoSAovcmepr5_nHgLbNTjQAAAm0"] [Tue Aug 18 12:56:18.808279 2026] [security2:error] [pid 67073:tid 67297] [client 172.202.39.151:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAovcmepr5_nHgLbNTjgAAAnA"] [Tue Aug 18 12:56:18.851251 2026] [security2:error] [pid 66623:tid 66848] [client 20.226.56.190:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ak.php"] [unique_id "aoSAotO5rbWdOArH04KJWAAAAVw"] [Tue Aug 18 12:56:18.873703 2026] [security2:error] [pid 66623:tid 66849] [client 68.155.154.236:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAotO5rbWdOArH04KJWQAAAV0"] [Tue Aug 18 12:56:18.908122 2026] [security2:error] [pid 66623:tid 66862] [client 135.225.78.186:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/doc.php"] [unique_id "aoSAotO5rbWdOArH04KJaAAAAWo"] [Tue Aug 18 12:56:18.960698 2026] [security2:error] [pid 67073:tid 67277] [client 213.35.127.232:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAovcmepr5_nHgLbNTkwAAAlw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:18.990528 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:18.990802 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:18.991542 2026] [security2:error] [pid 67073:tid 67267] [client 104.209.144.33:19631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAovcmepr5_nHgLbNTlwAAAlI"] [Tue Aug 18 12:56:18.992093 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.130.103:15409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSAovcmepr5_nHgLbNTmAAAAmU"] [Tue Aug 18 12:56:18.997653 2026] [security2:error] [pid 67073:tid 67166] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mandrill.php"] [unique_id "aoSAovcmepr5_nHgLbNTmgACblo"] [Tue Aug 18 12:56:18.998546 2026] [security2:error] [pid 67073:tid 67265] [client 20.51.153.15:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/56.php"] [unique_id "aoSAovcmepr5_nHgLbNTmwAAAlA"] [Tue Aug 18 12:56:19.007851 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gi.php"] [unique_id "aoSAo_cmepr5_nHgLbNTnAAAAnw"] [Tue Aug 18 12:56:19.015684 2026] [security2:error] [pid 67073:tid 67245] [client 20.116.17.175:57431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSAo_cmepr5_nHgLbNTnQAAAjw"] [Tue Aug 18 12:56:19.017827 2026] [autoindex:error] [pid 67073:tid 67300] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:19.020918 2026] [security2:error] [pid 67073:tid 67249] [client 158.23.17.4:29453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/php5.php"] [unique_id "aoSAo_cmepr5_nHgLbNTngAAAkA"] [Tue Aug 18 12:56:19.021971 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:24831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJbAAAAUs"] [Tue Aug 18 12:56:19.060475 2026] [security2:error] [pid 67073:tid 67227] [client 52.139.47.57:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/atex1.php"] [unique_id "aoSAo_cmepr5_nHgLbNToAAAAio"] [Tue Aug 18 12:56:19.102904 2026] [security2:error] [pid 66623:tid 66871] [client 20.91.215.254:12137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eezy.site"] [uri "/license.php"] [unique_id "aoSAo9O5rbWdOArH04KJbwAAAXM"] [Tue Aug 18 12:56:19.109241 2026] [security2:error] [pid 67073:tid 67276] [client 20.52.168.85:7864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/form.php"] [unique_id "aoSAo_cmepr5_nHgLbNTowAAAls"] [Tue Aug 18 12:56:19.109561 2026] [security2:error] [pid 67073:tid 67261] [client 20.215.241.237:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/inso.php"] [unique_id "aoSAo_cmepr5_nHgLbNTpAAAAkw"] [Tue Aug 18 12:56:19.143883 2026] [security2:error] [pid 67073:tid 67308] [client 20.151.109.219:21679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ak.php"] [unique_id "aoSAo_cmepr5_nHgLbNTpgAAAns"] [Tue Aug 18 12:56:19.153760 2026] [security2:error] [pid 67073:tid 67291] [client 172.202.39.151:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqAAAAmo"] [Tue Aug 18 12:56:19.177470 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.56.190:20412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/test_info.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqQAAAi8"] [Tue Aug 18 12:56:19.216062 2026] [security2:error] [pid 67073:tid 67189] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/main.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqgACVnE"] [Tue Aug 18 12:56:19.218915 2026] [security2:error] [pid 67073:tid 67240] [client 20.79.204.6:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSAo_cmepr5_nHgLbNTqwAAAjc"] [Tue Aug 18 12:56:19.223166 2026] [security2:error] [pid 67073:tid 67229] [client 20.104.49.167:3372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/file1221.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrAAAAiw"] [Tue Aug 18 12:56:19.228316 2026] [security2:error] [pid 66623:tid 66823] [client 20.171.51.14:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ib.php"] [unique_id "aoSAo9O5rbWdOArH04KJcAAAAUM"] [Tue Aug 18 12:56:19.262175 2026] [security2:error] [pid 67073:tid 67301] [client 20.163.43.14:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrgAAAnQ"] [Tue Aug 18 12:56:19.262952 2026] [security2:error] [pid 67073:tid 67275] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pz.php"] [unique_id "aoSAo_cmepr5_nHgLbNTrwAAAlo"] [Tue Aug 18 12:56:19.286975 2026] [security2:error] [pid 67073:tid 67290] [client 20.51.153.15:8780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/rx.php"] [unique_id "aoSAo_cmepr5_nHgLbNTsQAAAmk"] [Tue Aug 18 12:56:19.291667 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:19.291921 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:19.307734 2026] [security2:error] [pid 67073:tid 67233] [client 158.158.74.177:22757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/past.php"] [unique_id "aoSAo_cmepr5_nHgLbNTswAAAjA"] [Tue Aug 18 12:56:19.328071 2026] [security2:error] [pid 67073:tid 67330] [client 135.225.78.186:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/1337.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtQAAApE"] [Tue Aug 18 12:56:19.346191 2026] [security2:error] [pid 67073:tid 67279] [client 160.120.140.123:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtgAAAl4"] [Tue Aug 18 12:56:19.346333 2026] [security2:error] [pid 67073:tid 67279] [client 160.120.140.123:61282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtgAAAl4"] [Tue Aug 18 12:56:19.356497 2026] [security2:error] [pid 67073:tid 67253] [client 192.141.172.134:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtwAAAkQ"] [Tue Aug 18 12:56:19.356610 2026] [security2:error] [pid 67073:tid 67253] [client 192.141.172.134:60380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTtwAAAkQ"] [Tue Aug 18 12:56:19.358072 2026] [security2:error] [pid 67073:tid 67217] [client 20.215.241.237:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/sky.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuAAAAiA"] [Tue Aug 18 12:56:19.362631 2026] [security2:error] [pid 67073:tid 67226] [client 85.154.68.202:50312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuQAAAik"] [Tue Aug 18 12:56:19.362728 2026] [security2:error] [pid 67073:tid 67226] [client 85.154.68.202:50312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAo_cmepr5_nHgLbNTuQAAAik"] [Tue Aug 18 12:56:19.366783 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.56.190:28238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/14.php"] [unique_id "aoSAo_cmepr5_nHgLbNTugAAApA"] [Tue Aug 18 12:56:19.387881 2026] [security2:error] [pid 66623:tid 66863] [client 20.116.17.175:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/css/database.php"] [unique_id "aoSAo9O5rbWdOArH04KJcwAAAWs"] [Tue Aug 18 12:56:19.390325 2026] [security2:error] [pid 66623:tid 66860] [client 45.92.229.97:34049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAo9O5rbWdOArH04KJdAAAAWg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:56:19.431946 2026] [security2:error] [pid 67073:tid 67223] [client 20.151.109.219:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/test_info.php"] [unique_id "aoSAo_cmepr5_nHgLbNTvgAAAiY"] [Tue Aug 18 12:56:19.460172 2026] [security2:error] [pid 67073:tid 67116] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ga.php"] [unique_id "aoSAo_cmepr5_nHgLbNTwAACISg"] [Tue Aug 18 12:56:19.469644 2026] [security2:error] [pid 67073:tid 67117] [remote 129.121.103.155:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSAo_cmepr5_nHgLbNTwQACGyk"] [Tue Aug 18 12:56:19.482832 2026] [security2:error] [pid 67073:tid 67256] [client 20.250.13.23:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAo_cmepr5_nHgLbNTsgAAAkc"] [Tue Aug 18 12:56:19.508488 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.154.236:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAo_cmepr5_nHgLbNTxQAAAhc"] [Tue Aug 18 12:56:19.529090 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kk.php"] [unique_id "aoSAo_cmepr5_nHgLbNTxwAAAiI"] [Tue Aug 18 12:56:19.538526 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.130.103:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAo_cmepr5_nHgLbNTygAAAlE"] [Tue Aug 18 12:56:19.540799 2026] [security2:error] [pid 66623:tid 66873] [client 20.51.153.15:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mandrill.php"] [unique_id "aoSAo9O5rbWdOArH04KJdgAAAXU"] [Tue Aug 18 12:56:19.556549 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.49.167:3558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/nox.php"] [unique_id "aoSAo_cmepr5_nHgLbNTzAAAAlc"] [Tue Aug 18 12:56:19.586919 2026] [security2:error] [pid 66623:tid 66839] [client 135.225.75.187:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xa.php"] [unique_id "aoSAo9O5rbWdOArH04KJeAAAAVM"] [Tue Aug 18 12:56:19.684921 2026] [security2:error] [pid 66623:tid 66869] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAo9O5rbWdOArH04KJeQABcQI"] [Tue Aug 18 12:56:19.692597 2026] [security2:error] [pid 66623:tid 66783] [client 20.163.43.14:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJegAAARs"] [Tue Aug 18 12:56:19.696978 2026] [security2:error] [pid 67073:tid 67203] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/wb.php"] [unique_id "aoSAo_cmepr5_nHgLbNT1wACPH8"] [Tue Aug 18 12:56:19.709451 2026] [security2:error] [pid 66623:tid 66820] [client 20.29.77.16:49264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/defaul.php"] [unique_id "aoSAo9O5rbWdOArH04KJewAAAUA"] [Tue Aug 18 12:56:19.714876 2026] [security2:error] [pid 67073:tid 67210] [client 20.52.168.85:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-sigunq.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2AAAAhk"] [Tue Aug 18 12:56:19.753113 2026] [security2:error] [pid 67073:tid 67325] [client 20.215.241.237:9302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/thoms.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2QAAAow"] [Tue Aug 18 12:56:19.757633 2026] [security2:error] [pid 67073:tid 67206] [client 135.225.78.186:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/Njima.php"] [unique_id "aoSAo_cmepr5_nHgLbNT2gAAAhU"] [Tue Aug 18 12:56:19.792633 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/phpcheck.php"] [unique_id "aoSAo_cmepr5_nHgLbNT3gAAAk0"] [Tue Aug 18 12:56:19.802900 2026] [security2:error] [pid 67073:tid 67242] [client 20.151.109.219:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/14.php"] [unique_id "aoSAo_cmepr5_nHgLbNT3wAAAjk"] [Tue Aug 18 12:56:19.822197 2026] [security2:error] [pid 66623:tid 66821] [client 20.79.204.6:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSAo9O5rbWdOArH04KJfgAAAUE"] [Tue Aug 18 12:56:19.852776 2026] [security2:error] [pid 66623:tid 66852] [client 20.215.241.237:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/sixxis.php"] [unique_id "aoSAo9O5rbWdOArH04KJfwAAAWA"] [Tue Aug 18 12:56:19.861926 2026] [security2:error] [pid 67073:tid 67291] [client 20.51.153.15:8775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/main.php"] [unique_id "aoSAo_cmepr5_nHgLbNT4gAAAmo"] [Tue Aug 18 12:56:19.869517 2026] [security2:error] [pid 67073:tid 67259] [client 20.116.17.175:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/privdayz.php"] [unique_id "aoSAo_cmepr5_nHgLbNT4wAAAko"] [Tue Aug 18 12:56:19.893814 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:19.894104 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:19.913314 2026] [security2:error] [pid 67073:tid 67188] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/xn.php"] [unique_id "aoSAo_cmepr5_nHgLbNT5gACb3A"] [Tue Aug 18 12:56:19.966029 2026] [security2:error] [pid 67073:tid 67275] [client 20.104.49.167:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/akismet.php"] [unique_id "aoSAo_cmepr5_nHgLbNT5wAAAlo"] [Tue Aug 18 12:56:19.974133 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAo9O5rbWdOArH04KJgAAAASU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:19.978045 2026] [security2:error] [pid 67073:tid 67248] [client 68.155.154.236:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAo_cmepr5_nHgLbNT6QAAAj8"] [Tue Aug 18 12:56:20.024973 2026] [security2:error] [pid 66623:tid 66817] [client 20.163.43.14:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/k.php"] [unique_id "aoSApNO5rbWdOArH04KJgQAAAT0"] [Tue Aug 18 12:56:20.046684 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dg.php"] [unique_id "aoSApPcmepr5_nHgLbNT6wAAAng"] [Tue Aug 18 12:56:20.071019 2026] [security2:error] [pid 67073:tid 67233] [client 20.226.56.190:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tk.php"] [unique_id "aoSApPcmepr5_nHgLbNT7QAAAjA"] [Tue Aug 18 12:56:20.072659 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.136.165:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wqqs.php"] [unique_id "aoSApPcmepr5_nHgLbNT7gAAApE"] [Tue Aug 18 12:56:20.117009 2026] [security2:error] [pid 67073:tid 67253] [client 104.209.144.33:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSApPcmepr5_nHgLbNT8gAAAkQ"] [Tue Aug 18 12:56:20.124101 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.130.103:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSApNO5rbWdOArH04KJhAAAAUU"] [Tue Aug 18 12:56:20.144181 2026] [security2:error] [pid 67073:tid 67167] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/47.php"] [unique_id "aoSApPcmepr5_nHgLbNT8wACKVs"] [Tue Aug 18 12:56:20.153862 2026] [security2:error] [pid 66623:tid 66887] [client 20.151.109.219:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tk.php"] [unique_id "aoSApNO5rbWdOArH04KJhgAAAYM"] [Tue Aug 18 12:56:20.182004 2026] [security2:error] [pid 66623:tid 66807] [client 20.51.153.15:8820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/ga.php"] [unique_id "aoSApNO5rbWdOArH04KJhwAAATM"] [Tue Aug 18 12:56:20.182797 2026] [security2:error] [pid 66623:tid 66888] [client 135.225.78.186:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/BIBIL.php"] [unique_id "aoSApNO5rbWdOArH04KJiAAAAYQ"] [Tue Aug 18 12:56:20.194757 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:20.195028 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:20.221905 2026] [security2:error] [pid 66623:tid 66797] [client 20.116.17.175:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wg459o.php"] [unique_id "aoSApNO5rbWdOArH04KJiQAAASk"] [Tue Aug 18 12:56:20.266373 2026] [security2:error] [pid 67073:tid 67224] [client 20.29.77.16:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/twin.php"] [unique_id "aoSApPcmepr5_nHgLbNT-AAAAic"] [Tue Aug 18 12:56:20.283913 2026] [security2:error] [pid 67073:tid 67273] [client 20.215.241.237:44075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/yj09.php"] [unique_id "aoSApPcmepr5_nHgLbNT-QAAAlg"] [Tue Aug 18 12:56:20.301012 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bm.php"] [unique_id "aoSApPcmepr5_nHgLbNT-gAAAh0"] [Tue Aug 18 12:56:20.314115 2026] [security2:error] [pid 67073:tid 67327] [client 20.186.30.159:13680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSApPcmepr5_nHgLbNT-wAAAo4"] [Tue Aug 18 12:56:20.318446 2026] [security2:error] [pid 67073:tid 67217] [client 20.52.168.85:7848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/07.php"] [unique_id "aoSApPcmepr5_nHgLbNT_AAAAiA"] [Tue Aug 18 12:56:20.320280 2026] [security2:error] [pid 67073:tid 67246] [client 158.158.74.177:22747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/php.php"] [unique_id "aoSApPcmepr5_nHgLbNT_QAAAj0"] [Tue Aug 18 12:56:20.348954 2026] [security2:error] [pid 66623:tid 66826] [client 20.171.51.14:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xm.php"] [unique_id "aoSApNO5rbWdOArH04KJjAAAAUY"] [Tue Aug 18 12:56:20.386784 2026] [security2:error] [pid 67073:tid 67149] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/payout.php"] [unique_id "aoSApPcmepr5_nHgLbNUAgACkkk"] [Tue Aug 18 12:56:20.396472 2026] [security2:error] [pid 67073:tid 67220] [client 20.104.49.167:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/admin.php"] [unique_id "aoSApPcmepr5_nHgLbNUBQAAAiM"] [Tue Aug 18 12:56:20.403970 2026] [autoindex:error] [pid 67073:tid 67256] [client 20.226.6.191:36426] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:20.428815 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:36426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-mail.php"] [unique_id "aoSApPcmepr5_nHgLbNUBgAAAiI"] [Tue Aug 18 12:56:20.429116 2026] [security2:error] [pid 66623:tid 66774] [client 20.79.204.6:2203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSApNO5rbWdOArH04KJjwAAARI"] [Tue Aug 18 12:56:20.450961 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:18822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-block.php"] [unique_id "aoSApPcmepr5_nHgLbNUCAAAAok"] [Tue Aug 18 12:56:20.474780 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.169.31:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wk/index.php"] [unique_id "aoSApNO5rbWdOArH04KJkAAAAUw"] [Tue Aug 18 12:56:20.481087 2026] [security2:error] [pid 67073:tid 67211] [client 20.151.109.219:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/hp.php"] [unique_id "aoSApPcmepr5_nHgLbNUCQAAAho"] [Tue Aug 18 12:56:20.496248 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:20.496512 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:20.509304 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.56.190:31619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/hp.php"] [unique_id "aoSApPcmepr5_nHgLbNUCwAAAo0"] [Tue Aug 18 12:56:20.529011 2026] [autoindex:error] [pid 67073:tid 67297] [client 172.202.39.151:65225] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:20.561031 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.154.236:16301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSApPcmepr5_nHgLbNUDwAAAl0"] [Tue Aug 18 12:56:20.561142 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vu.php"] [unique_id "aoSApPcmepr5_nHgLbNUEAAAAlw"] [Tue Aug 18 12:56:20.562762 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/403.php"] [unique_id "aoSApNO5rbWdOArH04KJkgAAATI"] [Tue Aug 18 12:56:20.572509 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.130.103:25774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSApPcmepr5_nHgLbNUEQAAAk4"] [Tue Aug 18 12:56:20.576915 2026] [security2:error] [pid 66623:tid 66803] [client 54.87.112.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSAo9O5rbWdOArH04KJbQABL1k"], referer: https://tecpolorefrigeracao.com.br/ [Tue Aug 18 12:56:20.600321 2026] [security2:error] [pid 67073:tid 67247] [client 135.225.78.186:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/too.php"] [unique_id "aoSApPcmepr5_nHgLbNUEwAAAj4"] [Tue Aug 18 12:56:20.606419 2026] [security2:error] [pid 67073:tid 67120] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bh.php"] [unique_id "aoSApPcmepr5_nHgLbNUFAACYiw"] [Tue Aug 18 12:56:20.606427 2026] [security2:error] [pid 66623:tid 66864] [client 20.51.153.15:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/wb.php"] [unique_id "aoSApNO5rbWdOArH04KJkwAAAWw"] [Tue Aug 18 12:56:20.615251 2026] [security2:error] [pid 66623:tid 66768] [client 157.51.166.53:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSApNO5rbWdOArH04KJlAAAAQw"] [Tue Aug 18 12:56:20.615403 2026] [security2:error] [pid 66623:tid 66768] [client 157.51.166.53:61145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSApNO5rbWdOArH04KJlAAAAQw"] [Tue Aug 18 12:56:20.737947 2026] [security2:error] [pid 66623:tid 66814] [client 20.29.77.16:52773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/new2.php"] [unique_id "aoSApNO5rbWdOArH04KJlQAAATo"] [Tue Aug 18 12:56:20.739381 2026] [security2:error] [pid 66623:tid 66782] [client 135.225.75.187:17710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/f6.php"] [unique_id "aoSApNO5rbWdOArH04KJlgAAARo"] [Tue Aug 18 12:56:20.802594 2026] [security2:error] [pid 67073:tid 67249] [client 172.182.200.96:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSApPcmepr5_nHgLbNUGgAAAkA"] [Tue Aug 18 12:56:20.816809 2026] [security2:error] [pid 67073:tid 67310] [client 172.202.39.151:65225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSApPcmepr5_nHgLbNUGwAAAn0"] [Tue Aug 18 12:56:20.817981 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:44093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/k.php"] [unique_id "aoSApPcmepr5_nHgLbNUHAAAAhk"] [Tue Aug 18 12:56:20.822037 2026] [security2:error] [pid 67073:tid 67227] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ic.php"] [unique_id "aoSApPcmepr5_nHgLbNUHQAAAio"] [Tue Aug 18 12:56:20.825587 2026] [security2:error] [pid 67073:tid 67281] [client 20.250.13.23:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/default.php"] [unique_id "aoSApPcmepr5_nHgLbNUHgAAAmA"] [Tue Aug 18 12:56:20.834883 2026] [security2:error] [pid 67073:tid 67100] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/ct.php"] [unique_id "aoSApPcmepr5_nHgLbNUHwACeRg"] [Tue Aug 18 12:56:20.864808 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mifta.php"] [unique_id "aoSApPcmepr5_nHgLbNUIAAAAnY"] [Tue Aug 18 12:56:20.880362 2026] [security2:error] [pid 67073:tid 67207] [client 20.151.109.219:12915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wx.php"] [unique_id "aoSApPcmepr5_nHgLbNUIQAAAhY"] [Tue Aug 18 12:56:20.890554 2026] [security2:error] [pid 66623:tid 66883] [client 20.51.153.15:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/xn.php"] [unique_id "aoSApNO5rbWdOArH04KJmQAAAX8"] [Tue Aug 18 12:56:20.921303 2026] [security2:error] [pid 67073:tid 67291] [client 20.186.30.159:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSApPcmepr5_nHgLbNUJAAAAmo"] [Tue Aug 18 12:56:20.923375 2026] [security2:error] [pid 66623:tid 66816] [client 20.52.168.85:7829] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSApNO5rbWdOArH04KJmgAAATw"] [Tue Aug 18 12:56:20.937614 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:34136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSApPcmepr5_nHgLbNUJQAAAi8"] [Tue Aug 18 12:56:20.986093 2026] [security2:error] [pid 67073:tid 67309] [client 213.35.127.232:56097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSApPcmepr5_nHgLbNUJwAAAnw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:21.017076 2026] [security2:error] [pid 67073:tid 67229] [client 135.225.78.186:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sosbaterias.aju.br"] [uri "/g3.php"] [unique_id "aoSApfcmepr5_nHgLbNUKAAAAiw"] [Tue Aug 18 12:56:21.032280 2026] [security2:error] [pid 67073:tid 67325] [client 20.79.204.6:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSApfcmepr5_nHgLbNUKQAAAow"] [Tue Aug 18 12:56:21.040141 2026] [security2:error] [pid 67073:tid 67225] [client 74.248.136.165:28141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/clasa99.php"] [unique_id "aoSApfcmepr5_nHgLbNUKgAAAig"] [Tue Aug 18 12:56:21.064750 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.49.167:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ajax.php"] [unique_id "aoSApdO5rbWdOArH04KJmwAAAUQ"] [Tue Aug 18 12:56:21.077466 2026] [security2:error] [pid 67073:tid 67271] [client 20.100.169.31:28157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/as.php"] [unique_id "aoSApfcmepr5_nHgLbNULwAAAlY"] [Tue Aug 18 12:56:21.082944 2026] [security2:error] [pid 67073:tid 67239] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ue.php"] [unique_id "aoSApfcmepr5_nHgLbNUMAAAAjY"] [Tue Aug 18 12:56:21.108657 2026] [security2:error] [pid 67073:tid 67086] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/gy.php"] [unique_id "aoSApfcmepr5_nHgLbNUMgACXwo"] [Tue Aug 18 12:56:21.142181 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.34.183:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wk/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUNAAAAk0"] [Tue Aug 18 12:56:21.182075 2026] [security2:error] [pid 67073:tid 67285] [client 20.215.241.237:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/wpxml.php"] [unique_id "aoSApfcmepr5_nHgLbNUNwAAAmQ"] [Tue Aug 18 12:56:21.198140 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.154.236:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSApdO5rbWdOArH04KJnQAAAVI"] [Tue Aug 18 12:56:21.202182 2026] [security2:error] [pid 67073:tid 67253] [client 20.171.51.14:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zy.php"] [unique_id "aoSApfcmepr5_nHgLbNUOAAAAkQ"] [Tue Aug 18 12:56:21.221667 2026] [security2:error] [pid 67073:tid 67209] [client 20.51.153.15:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/tt.php"] [unique_id "aoSApfcmepr5_nHgLbNUOgAAAhg"] [Tue Aug 18 12:56:21.249100 2026] [security2:error] [pid 67073:tid 67257] [client 20.163.43.14:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/gecko.php"] [unique_id "aoSApfcmepr5_nHgLbNUOwAAAkg"] [Tue Aug 18 12:56:21.292008 2026] [security2:error] [pid 67073:tid 67258] [client 20.215.241.237:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/w.php"] [unique_id "aoSApfcmepr5_nHgLbNUPQAAAkk"] [Tue Aug 18 12:56:21.301113 2026] [security2:error] [pid 67073:tid 67273] [client 20.151.109.219:21647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/dj.php"] [unique_id "aoSApfcmepr5_nHgLbNUPgAAAlg"] [Tue Aug 18 12:56:21.319258 2026] [security2:error] [pid 67073:tid 67223] [client 74.248.130.103:14452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSApfcmepr5_nHgLbNUPwAAAiY"] [Tue Aug 18 12:56:21.319535 2026] [security2:error] [pid 67073:tid 67094] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/tt.php"] [unique_id "aoSApfcmepr5_nHgLbNUQAACHhI"] [Tue Aug 18 12:56:21.320849 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.56.190:32300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wx.php"] [unique_id "aoSApfcmepr5_nHgLbNUQQAAAh0"] [Tue Aug 18 12:56:21.338031 2026] [security2:error] [pid 67073:tid 67246] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lr.php"] [unique_id "aoSApfcmepr5_nHgLbNUQgAAAj0"] [Tue Aug 18 12:56:21.401735 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:21.402013 2026] [authz_core:error] [pid 67073:tid 67087] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:21.408845 2026] [security2:error] [pid 67073:tid 67208] [client 68.155.156.252:16576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSApfcmepr5_nHgLbNURgAAAhc"] [Tue Aug 18 12:56:21.459204 2026] [security2:error] [pid 67073:tid 67316] [client 20.226.6.191:32961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/o.php"] [unique_id "aoSApfcmepr5_nHgLbNUSwAAAoM"] [Tue Aug 18 12:56:21.497393 2026] [security2:error] [pid 66623:tid 66781] [client 20.51.153.15:9105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/mq.php"] [unique_id "aoSApdO5rbWdOArH04KJnwAAARk"] [Tue Aug 18 12:56:21.508026 2026] [security2:error] [pid 67073:tid 67304] [client 158.158.74.177:2648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/php8.php"] [unique_id "aoSApfcmepr5_nHgLbNUTgAAAnc"] [Tue Aug 18 12:56:21.519937 2026] [security2:error] [pid 67073:tid 67170] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/mq.php"] [unique_id "aoSApfcmepr5_nHgLbNUTwACMl4"] [Tue Aug 18 12:56:21.523256 2026] [security2:error] [pid 67073:tid 67327] [client 20.52.168.85:7830] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSApfcmepr5_nHgLbNUUQAAAo4"] [Tue Aug 18 12:56:21.523334 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:65279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSApfcmepr5_nHgLbNUUAAAAk8"] [Tue Aug 18 12:56:21.557954 2026] [security2:error] [pid 67073:tid 67274] [client 20.186.30.159:13599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSApfcmepr5_nHgLbNUVQAAAlk"] [Tue Aug 18 12:56:21.575850 2026] [security2:error] [pid 67073:tid 67263] [client 52.173.121.69:17974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUVgAAAk4"] [Tue Aug 18 12:56:21.584641 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ka.php"] [unique_id "aoSApfcmepr5_nHgLbNUVwAAAlc"] [Tue Aug 18 12:56:21.597212 2026] [security2:error] [pid 67073:tid 67286] [client 213.202.253.4:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/delpaths.php"] [unique_id "aoSApfcmepr5_nHgLbNUWAAAAmU"], referer: www.google.com [Tue Aug 18 12:56:21.643071 2026] [security2:error] [pid 67073:tid 67205] [client 20.151.109.219:24866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fa.php"] [unique_id "aoSApfcmepr5_nHgLbNUXAAAAhQ"] [Tue Aug 18 12:56:21.647546 2026] [security2:error] [pid 67073:tid 67302] [client 135.225.75.187:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mcs.php"] [unique_id "aoSApfcmepr5_nHgLbNUXQAAAnU"] [Tue Aug 18 12:56:21.699226 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSApfcmepr5_nHgLbNUYAAAAjw"] [Tue Aug 18 12:56:21.701071 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:21.701336 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:21.732412 2026] [security2:error] [pid 67073:tid 67310] [client 20.215.241.237:48445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fpwch.php"] [unique_id "aoSApfcmepr5_nHgLbNUYgAAAn0"] [Tue Aug 18 12:56:21.740081 2026] [security2:error] [pid 67073:tid 67294] [client 20.250.13.23:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/i.php"] [unique_id "aoSApfcmepr5_nHgLbNUYwAAAm0"] [Tue Aug 18 12:56:21.746015 2026] [security2:error] [pid 66623:tid 66848] [client 20.163.43.14:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/aa.php"] [unique_id "aoSApdO5rbWdOArH04KJogAAAVw"] [Tue Aug 18 12:56:21.759294 2026] [security2:error] [pid 67073:tid 67227] [client 20.51.153.15:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/13.php"] [unique_id "aoSApfcmepr5_nHgLbNUZAAAAio"] [Tue Aug 18 12:56:21.763209 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.130.103:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/media.php"] [unique_id "aoSApdO5rbWdOArH04KJowAAAXs"] [Tue Aug 18 12:56:21.764392 2026] [security2:error] [pid 67073:tid 67230] [client 20.79.204.6:2201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSApfcmepr5_nHgLbNUZQAAAi0"] [Tue Aug 18 12:56:21.770166 2026] [security2:error] [pid 67073:tid 67181] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/13.php"] [unique_id "aoSApfcmepr5_nHgLbNUZgACYGk"] [Tue Aug 18 12:56:21.772129 2026] [security2:error] [pid 67073:tid 67277] [client 79.127.164.8:35678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/localhost.sql"] [unique_id "aoSApfcmepr5_nHgLbNUZwAAAlw"], referer: https://medihub.com.br/localhost.sql [Tue Aug 18 12:56:21.841402 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ot.php"] [unique_id "aoSApfcmepr5_nHgLbNUagAAAnY"] [Tue Aug 18 12:56:21.872536 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSApfcmepr5_nHgLbNUawAAAi8"] [Tue Aug 18 12:56:21.912534 2026] [security2:error] [pid 67073:tid 67238] [client 20.116.17.175:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSApfcmepr5_nHgLbNUbQAAAjU"] [Tue Aug 18 12:56:21.919501 2026] [security2:error] [pid 66623:tid 66800] [client 172.202.39.151:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSApdO5rbWdOArH04KJpQAAASw"] [Tue Aug 18 12:56:21.997945 2026] [security2:error] [pid 66623:tid 66767] [client 213.35.127.232:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSApdO5rbWdOArH04KJpgAAAQs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:22.001978 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:22.002245 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:22.002570 2026] [security2:error] [pid 67073:tid 67275] [client 20.151.109.219:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/fb.php"] [unique_id "aoSApvcmepr5_nHgLbNUcgAAAlo"] [Tue Aug 18 12:56:22.009262 2026] [security2:error] [pid 67073:tid 67182] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/so.php"] [unique_id "aoSApvcmepr5_nHgLbNUcwACjGo"] [Tue Aug 18 12:56:22.013402 2026] [security2:error] [pid 67073:tid 67228] [client 20.29.77.16:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/rex.php"] [unique_id "aoSApvcmepr5_nHgLbNUdAAAAis"] [Tue Aug 18 12:56:22.067683 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.154.236:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSApvcmepr5_nHgLbNUdQAAAig"] [Tue Aug 18 12:56:22.078892 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/0x.php"] [unique_id "aoSApvcmepr5_nHgLbNUdgAAAlY"] [Tue Aug 18 12:56:22.092969 2026] [security2:error] [pid 67073:tid 67280] [client 20.171.51.14:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/q.php"] [unique_id "aoSApvcmepr5_nHgLbNUeQAAAl8"] [Tue Aug 18 12:56:22.108578 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ih.php"] [unique_id "aoSApvcmepr5_nHgLbNUewAAApE"] [Tue Aug 18 12:56:22.132059 2026] [security2:error] [pid 66623:tid 66857] [client 20.52.168.85:7863] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.sortis.net"] [uri "/c99.php"] [unique_id "aoSAptO5rbWdOArH04KJqAAAAWU"] [Tue Aug 18 12:56:22.160761 2026] [security2:error] [pid 67073:tid 67308] [client 20.186.30.159:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSApvcmepr5_nHgLbNUfwAAAns"] [Tue Aug 18 12:56:22.187354 2026] [security2:error] [pid 66623:tid 66853] [client 20.215.241.237:40475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSAptO5rbWdOArH04KJqQAAAWE"] [Tue Aug 18 12:56:22.201067 2026] [security2:error] [pid 67073:tid 67324] [client 172.202.39.151:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/abc.php"] [unique_id "aoSApvcmepr5_nHgLbNUggAAAos"] [Tue Aug 18 12:56:22.212061 2026] [authz_core:error] [pid 67073:tid 67132] [remote 57.141.22.94:56768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:22.212511 2026] [authz_core:error] [pid 67073:tid 67132] [remote 57.141.22.94:56768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:22.228914 2026] [security2:error] [pid 67073:tid 67078] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/10.php"] [unique_id "aoSApvcmepr5_nHgLbNUgwACWAI"] [Tue Aug 18 12:56:22.231741 2026] [security2:error] [pid 67073:tid 67223] [client 20.51.153.15:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/so.php"] [unique_id "aoSApvcmepr5_nHgLbNUhAAAAiY"] [Tue Aug 18 12:56:22.260341 2026] [security2:error] [pid 67073:tid 67246] [client 20.226.56.190:23773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/dj.php"] [unique_id "aoSApvcmepr5_nHgLbNUhQAAAj0"] [Tue Aug 18 12:56:22.315875 2026] [security2:error] [pid 66623:tid 66871] [client 20.151.109.219:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gw.php"] [unique_id "aoSAptO5rbWdOArH04KJqgAAAXM"] [Tue Aug 18 12:56:22.330353 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.130.103:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/inso.php"] [unique_id "aoSApvcmepr5_nHgLbNUiAAAAn4"] [Tue Aug 18 12:56:22.365961 2026] [security2:error] [pid 66623:tid 66868] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/k.php"] [unique_id "aoSAptO5rbWdOArH04KJqwAAAXA"] [Tue Aug 18 12:56:22.372173 2026] [security2:error] [pid 67073:tid 67315] [client 20.79.204.6:2643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSApvcmepr5_nHgLbNUjAAAAoI"] [Tue Aug 18 12:56:22.394650 2026] [security2:error] [pid 67073:tid 67213] [client 132.196.30.78:18675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/inputs.php"] [unique_id "aoSApvcmepr5_nHgLbNUjgAAAhw"] [Tue Aug 18 12:56:22.423959 2026] [security2:error] [pid 67073:tid 67241] [client 20.163.43.14:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/zxz.php"] [unique_id "aoSApvcmepr5_nHgLbNUjwAAAjg"] [Tue Aug 18 12:56:22.434184 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.154.236:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSApvcmepr5_nHgLbNUkAAAAo0"] [Tue Aug 18 12:56:22.443865 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSApvcmepr5_nHgLbNUkQAAAkg"] [Tue Aug 18 12:56:22.475371 2026] [security2:error] [pid 67073:tid 67184] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/te.php"] [unique_id "aoSApvcmepr5_nHgLbNUlAACT2w"] [Tue Aug 18 12:56:22.492414 2026] [security2:error] [pid 67073:tid 67276] [client 196.12.128.158:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSApvcmepr5_nHgLbNUlgAAAls"] [Tue Aug 18 12:56:22.492546 2026] [security2:error] [pid 67073:tid 67276] [client 196.12.128.158:49500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSApvcmepr5_nHgLbNUlgAAAls"] [Tue Aug 18 12:56:22.499621 2026] [security2:error] [pid 66623:tid 66771] [client 20.51.153.15:9172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/kc.php"] [unique_id "aoSAptO5rbWdOArH04KJrQAAAQ8"] [Tue Aug 18 12:56:22.578998 2026] [security2:error] [pid 67073:tid 67286] [client 135.225.75.187:24662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/xleet.php"] [unique_id "aoSApvcmepr5_nHgLbNUmQAAAmU"] [Tue Aug 18 12:56:22.611011 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:49197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/blurbs.php"] [unique_id "aoSApvcmepr5_nHgLbNUmwAAAnU"] [Tue Aug 18 12:56:22.621800 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iu.php"] [unique_id "aoSApvcmepr5_nHgLbNUnQAAAjw"] [Tue Aug 18 12:56:22.623529 2026] [security2:error] [pid 67073:tid 67287] [client 20.151.109.219:24867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/sw.php"] [unique_id "aoSApvcmepr5_nHgLbNUnwAAAmY"] [Tue Aug 18 12:56:22.625784 2026] [security2:error] [pid 67073:tid 67290] [client 20.100.169.31:12676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/about.php"] [unique_id "aoSApvcmepr5_nHgLbNUoAAAAmk"] [Tue Aug 18 12:56:22.662159 2026] [security2:error] [pid 67073:tid 67260] [client 158.23.17.4:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/Black.php"] [unique_id "aoSApvcmepr5_nHgLbNUogAAAks"] [Tue Aug 18 12:56:22.705880 2026] [security2:error] [pid 67073:tid 67154] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/kc.php"] [unique_id "aoSApvcmepr5_nHgLbNUowACRU4"] [Tue Aug 18 12:56:22.706769 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:2667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/plugins.php"] [unique_id "aoSApvcmepr5_nHgLbNUpAAAAok"] [Tue Aug 18 12:56:22.738516 2026] [security2:error] [pid 67073:tid 67278] [client 20.52.168.85:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wander.php"] [unique_id "aoSApvcmepr5_nHgLbNUpwAAAl0"] [Tue Aug 18 12:56:22.740485 2026] [security2:error] [pid 66623:tid 66830] [client 20.116.17.175:57631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/index2.php"] [unique_id "aoSAptO5rbWdOArH04KJrwAAAUo"] [Tue Aug 18 12:56:22.772861 2026] [security2:error] [pid 67073:tid 67207] [client 20.51.153.15:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uninutri.ind.br"] [uri "/bf.php"] [unique_id "aoSApvcmepr5_nHgLbNUqAAAAhY"] [Tue Aug 18 12:56:22.832934 2026] [security2:error] [pid 66623:tid 66844] [client 20.163.43.14:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/www.php"] [unique_id "aoSAptO5rbWdOArH04KJsAAAAVg"] [Tue Aug 18 12:56:22.839592 2026] [security2:error] [pid 66623:tid 66874] [client 172.182.200.96:14170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAptO5rbWdOArH04KJsQAAAXY"] [Tue Aug 18 12:56:22.861526 2026] [security2:error] [pid 67073:tid 67211] [client 52.139.47.57:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/atomlib.php"] [unique_id "aoSApvcmepr5_nHgLbNUqgAAAho"] [Tue Aug 18 12:56:22.866474 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.130.103:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/shiny.php"] [unique_id "aoSAptO5rbWdOArH04KJsgAAAXo"] [Tue Aug 18 12:56:22.871037 2026] [security2:error] [pid 66623:tid 66846] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pk.php"] [unique_id "aoSAptO5rbWdOArH04KJswAAAVo"] [Tue Aug 18 12:56:22.877498 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.154.236:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAptO5rbWdOArH04KJtAAAARs"] [Tue Aug 18 12:56:22.904549 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.136.165:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/666.php"] [unique_id "aoSApvcmepr5_nHgLbNUrQAAAnw"] [Tue Aug 18 12:56:22.919037 2026] [security2:error] [pid 67073:tid 67131] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/jn.php"] [unique_id "aoSApvcmepr5_nHgLbNUrwACaDc"] [Tue Aug 18 12:56:22.919363 2026] [security2:error] [pid 67073:tid 67261] [client 132.196.30.78:18788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/admin.php"] [unique_id "aoSApvcmepr5_nHgLbNUsAAAAkw"] [Tue Aug 18 12:56:22.962347 2026] [security2:error] [pid 67073:tid 67325] [client 20.151.109.219:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gc.php"] [unique_id "aoSApvcmepr5_nHgLbNUsQAAAow"] [Tue Aug 18 12:56:22.978876 2026] [security2:error] [pid 67073:tid 67293] [client 20.79.204.6:2373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSApvcmepr5_nHgLbNUsgAAAmw"] [Tue Aug 18 12:56:23.009595 2026] [autoindex:error] [pid 66623:tid 66815] [client 172.202.39.151:15740] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:23.013918 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.56.190:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fa.php"] [unique_id "aoSAp9O5rbWdOArH04KJuQAAAWA"] [Tue Aug 18 12:56:23.017337 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtAAAAn0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:23.091925 2026] [security2:error] [pid 66623:tid 66793] [client 132.196.61.152:61035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/fz.php"] [unique_id "aoSAp9O5rbWdOArH04KJugAAASU"] [Tue Aug 18 12:56:23.099571 2026] [security2:error] [pid 67073:tid 67279] [client 20.29.77.16:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/verification.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtgAAAl4"] [Tue Aug 18 12:56:23.105417 2026] [security2:error] [pid 67073:tid 67308] [client 20.186.30.159:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/xx.php"] [unique_id "aoSAp_cmepr5_nHgLbNUtwAAAns"] [Tue Aug 18 12:56:23.118021 2026] [security2:error] [pid 66623:tid 66881] [client 20.215.241.237:54958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/100.php"] [unique_id "aoSAp9O5rbWdOArH04KJvAAAAX0"] [Tue Aug 18 12:56:23.126818 2026] [security2:error] [pid 66623:tid 66880] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ge.php"] [unique_id "aoSAp9O5rbWdOArH04KJvQAAAXw"] [Tue Aug 18 12:56:23.158748 2026] [security2:error] [pid 66623:tid 66804] [client 20.163.43.14:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wicked.php"] [unique_id "aoSAp9O5rbWdOArH04KJvgAAATA"] [Tue Aug 18 12:56:23.158748 2026] [security2:error] [pid 67073:tid 67076] [remote 20.171.51.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fonsecashop.com.br"] [uri "/bf.php"] [unique_id "aoSAp_cmepr5_nHgLbNUuAACkwA"] [Tue Aug 18 12:56:23.195893 2026] [security2:error] [pid 67073:tid 67258] [client 20.171.51.14:45405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xf.php"] [unique_id "aoSAp_cmepr5_nHgLbNUugAAAkk"] [Tue Aug 18 12:56:23.205737 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:23.206001 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:23.208182 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.6.191:36357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/bb.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvAAAAlg"] [Tue Aug 18 12:56:23.225426 2026] [security2:error] [pid 66623:tid 66840] [client 20.250.13.23:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJvwAAAVQ"] [Tue Aug 18 12:56:23.264039 2026] [security2:error] [pid 67073:tid 67217] [client 68.155.154.236:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvQAAAiA"] [Tue Aug 18 12:56:23.274116 2026] [security2:error] [pid 67073:tid 67262] [client 20.151.109.219:12902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uq.php"] [unique_id "aoSAp_cmepr5_nHgLbNUvgAAAk0"] [Tue Aug 18 12:56:23.322565 2026] [autoindex:error] [pid 66623:tid 66825] [client 172.202.39.151:15740] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:23.353612 2026] [security2:error] [pid 66623:tid 66817] [client 20.52.168.85:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/colour.php"] [unique_id "aoSAp9O5rbWdOArH04KJwgAAAT0"] [Tue Aug 18 12:56:23.386352 2026] [security2:error] [pid 66623:tid 66807] [client 172.202.39.151:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/akcc.php"] [unique_id "aoSAp9O5rbWdOArH04KJxAAAATM"] [Tue Aug 18 12:56:23.401599 2026] [security2:error] [pid 67073:tid 67329] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kl.php"] [unique_id "aoSAp_cmepr5_nHgLbNUygAAApA"] [Tue Aug 18 12:56:23.405743 2026] [security2:error] [pid 67073:tid 67230] [client 103.120.71.157:51558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNUywAAAi0"] [Tue Aug 18 12:56:23.405932 2026] [security2:error] [pid 67073:tid 67230] [client 103.120.71.157:51558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNUywAAAi0"] [Tue Aug 18 12:56:23.455395 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.130.103:14456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/403dd.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzAAAAkY"] [Tue Aug 18 12:56:23.466741 2026] [security2:error] [pid 66623:tid 66791] [client 172.202.39.151:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wso.php"] [unique_id "aoSAp9O5rbWdOArH04KJxQAAASM"] [Tue Aug 18 12:56:23.468727 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.6.191:55782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzQAAAkg"] [Tue Aug 18 12:56:23.469875 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/min.php"] [unique_id "aoSAp_cmepr5_nHgLbNUzwAAAjE"] [Tue Aug 18 12:56:23.482141 2026] [security2:error] [pid 66623:tid 66866] [client 20.163.43.14:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSAp9O5rbWdOArH04KJxgAAAW4"] [Tue Aug 18 12:56:23.505134 2026] [security2:error] [pid 67073:tid 67265] [client 74.7.230.22:45572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.massagemrelax.com"] [uri "/index.php"] [unique_id "aoSApvcmepr5_nHgLbNUfgACUC4"] [Tue Aug 18 12:56:23.534851 2026] [security2:error] [pid 67073:tid 67276] [client 135.225.75.187:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fr/ms.php"] [unique_id "aoSAp_cmepr5_nHgLbNU3AAAAls"] [Tue Aug 18 12:56:23.536359 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:16456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJxwAAAXc"] [Tue Aug 18 12:56:23.579162 2026] [security2:error] [pid 66623:tid 66839] [client 197.184.64.235:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp9O5rbWdOArH04KJyAAAAVM"] [Tue Aug 18 12:56:23.579282 2026] [security2:error] [pid 66623:tid 66839] [client 197.184.64.235:41930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp9O5rbWdOArH04KJyAAAAVM"] [Tue Aug 18 12:56:23.580128 2026] [security2:error] [pid 67073:tid 67314] [client 20.79.204.6:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAp_cmepr5_nHgLbNU3gAAAoE"] [Tue Aug 18 12:56:23.580231 2026] [security2:error] [pid 67073:tid 67307] [client 132.196.30.78:18756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/goods.php"] [unique_id "aoSAp_cmepr5_nHgLbNU4AAAAno"] [Tue Aug 18 12:56:23.589861 2026] [security2:error] [pid 67073:tid 67163] [remote 157.230.98.178:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/wp-login.php"] [unique_id "aoSAp_cmepr5_nHgLbNU4QACO1c"] [Tue Aug 18 12:56:23.646230 2026] [security2:error] [pid 66623:tid 66786] [client 20.151.109.219:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/32.php"] [unique_id "aoSAp9O5rbWdOArH04KJyQAAAR4"] [Tue Aug 18 12:56:23.658002 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gs.php"] [unique_id "aoSAp9O5rbWdOArH04KJygAAARE"] [Tue Aug 18 12:56:23.680372 2026] [security2:error] [pid 67073:tid 67316] [client 68.155.154.236:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-QAAAoM"] [Tue Aug 18 12:56:23.720665 2026] [security2:error] [pid 66623:tid 66810] [client 20.215.241.237:44036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ccc.php"] [unique_id "aoSAp9O5rbWdOArH04KJzAAAATY"] [Tue Aug 18 12:56:23.739765 2026] [security2:error] [pid 67073:tid 67319] [client 37.40.227.74:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-gAAAoY"] [Tue Aug 18 12:56:23.739866 2026] [security2:error] [pid 67073:tid 67319] [client 37.40.227.74:56882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAp_cmepr5_nHgLbNU-gAAAoY"] [Tue Aug 18 12:56:23.744366 2026] [security2:error] [pid 66623:tid 66861] [client 20.186.30.159:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/av.php"] [unique_id "aoSAp9O5rbWdOArH04KJzQAAAWk"] [Tue Aug 18 12:56:23.762165 2026] [security2:error] [pid 67073:tid 67269] [client 74.248.136.165:46801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/thui.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_AAAAlQ"] [Tue Aug 18 12:56:23.790920 2026] [security2:error] [pid 67073:tid 67290] [client 20.171.51.14:45438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gb.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_QAAAmk"] [Tue Aug 18 12:56:23.804531 2026] [security2:error] [pid 67073:tid 67226] [client 104.209.144.33:35875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAp_cmepr5_nHgLbNU_wAAAik"] [Tue Aug 18 12:56:23.820078 2026] [security2:error] [pid 66623:tid 66841] [client 20.163.43.14:4258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJzgAAAVU"] [Tue Aug 18 12:56:23.840600 2026] [security2:error] [pid 66623:tid 66854] [client 158.158.74.177:2628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/post.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0AAAAWI"] [Tue Aug 18 12:56:23.867793 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wk/index.php"] [unique_id "aoSAp_cmepr5_nHgLbNVBQAAAoQ"] [Tue Aug 18 12:56:23.903172 2026] [security2:error] [pid 67073:tid 67294] [client 20.116.17.175:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/8.php"] [unique_id "aoSAp_cmepr5_nHgLbNVBwAAAm0"] [Tue Aug 18 12:56:23.912134 2026] [security2:error] [pid 67073:tid 67254] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lw.php"] [unique_id "aoSAp_cmepr5_nHgLbNVCQAAAkU"] [Tue Aug 18 12:56:23.917139 2026] [security2:error] [pid 66623:tid 66850] [client 74.248.130.103:15365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/baba.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0gAAAV4"] [Tue Aug 18 12:56:23.925397 2026] [security2:error] [pid 66623:tid 66814] [client 20.29.77.16:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/smtp.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0wAAATo"] [Tue Aug 18 12:56:23.943980 2026] [security2:error] [pid 66623:tid 66864] [client 74.7.230.22:45574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "massagemrelax.com"] [uri "/index.php"] [unique_id "aoSAp9O5rbWdOArH04KJ0QABbD8"], referer: https://www.massagemrelax.com/robots.txt [Tue Aug 18 12:56:23.958683 2026] [security2:error] [pid 66623:tid 66768] [client 20.52.168.85:7838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/file4.php"] [unique_id "aoSAp9O5rbWdOArH04KJ1AAAAQw"] [Tue Aug 18 12:56:23.993818 2026] [security2:error] [pid 67073:tid 67277] [client 20.151.109.219:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/73.php"] [unique_id "aoSAp_cmepr5_nHgLbNVDgAAAlw"] [Tue Aug 18 12:56:24.029394 2026] [security2:error] [pid 67073:tid 67247] [client 213.35.127.232:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVEAAAAj4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:24.035904 2026] [security2:error] [pid 67073:tid 67221] [client 68.155.154.236:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAqPcmepr5_nHgLbNVEgAAAiQ"] [Tue Aug 18 12:56:24.150708 2026] [security2:error] [pid 67073:tid 67229] [client 20.163.43.14:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cah.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFQAAAiw"] [Tue Aug 18 12:56:24.158243 2026] [security2:error] [pid 67073:tid 67301] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vj.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFgAAAnQ"] [Tue Aug 18 12:56:24.203816 2026] [security2:error] [pid 67073:tid 67281] [client 20.79.204.6:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSAqPcmepr5_nHgLbNVFwAAAmA"] [Tue Aug 18 12:56:24.251298 2026] [security2:error] [pid 67073:tid 67332] [client 20.215.241.237:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/get.php"] [unique_id "aoSAqPcmepr5_nHgLbNVHQAAApM"] [Tue Aug 18 12:56:24.305870 2026] [authz_core:error] [pid 67073:tid 67225] [client 192.178.4.133:65481] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:24.306173 2026] [authz_core:error] [pid 67073:tid 67225] [client 192.178.4.133:65481] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:24.312244 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:12878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ib.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIAAAAkA"] [Tue Aug 18 12:56:24.344142 2026] [security2:error] [pid 67073:tid 67217] [client 20.186.30.159:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/media.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIQAAAiA"] [Tue Aug 18 12:56:24.351218 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:49338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/filesystems.php"] [unique_id "aoSAqPcmepr5_nHgLbNVIgAAAk0"] [Tue Aug 18 12:56:24.380379 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAqPcmepr5_nHgLbNVJwAAAlE"] [Tue Aug 18 12:56:24.405146 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/site.php"] [unique_id "aoSAqPcmepr5_nHgLbNVKwAAAmE"] [Tue Aug 18 12:56:24.410710 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:24.410993 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:24.433735 2026] [security2:error] [pid 67073:tid 67326] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mimes.php"] [unique_id "aoSAqPcmepr5_nHgLbNVLQAAAo0"] [Tue Aug 18 12:56:24.442000 2026] [security2:error] [pid 66623:tid 66865] [client 158.158.34.183:35132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/w.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2AAAAW0"] [Tue Aug 18 12:56:24.483262 2026] [security2:error] [pid 67073:tid 67312] [client 135.225.75.187:17670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/gool.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMAAAAn8"] [Tue Aug 18 12:56:24.486811 2026] [security2:error] [pid 67073:tid 67242] [client 86.120.159.145:6829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMwAAAjk"] [Tue Aug 18 12:56:24.486904 2026] [security2:error] [pid 67073:tid 67242] [client 86.120.159.145:6829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVMwAAAjk"] [Tue Aug 18 12:56:24.513370 2026] [security2:error] [pid 67073:tid 67264] [client 20.104.85.180:6977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNQAAAk8"] [Tue Aug 18 12:56:24.536395 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.30.78:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/file.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNgAAAh0"] [Tue Aug 18 12:56:24.562525 2026] [security2:error] [pid 67073:tid 67246] [client 20.52.168.85:7852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/assets/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVNwAAAj0"] [Tue Aug 18 12:56:24.575694 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqPcmepr5_nHgLbNVOQAAAoE"] [Tue Aug 18 12:56:24.581888 2026] [security2:error] [pid 67073:tid 67263] [client 20.171.51.14:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jp.php"] [unique_id "aoSAqPcmepr5_nHgLbNVOgAAAk4"] [Tue Aug 18 12:56:24.601669 2026] [security2:error] [pid 67073:tid 67226] [client 20.226.56.190:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/fb.php"] [unique_id "aoSAqPcmepr5_nHgLbNVPAAAAik"] [Tue Aug 18 12:56:24.645948 2026] [security2:error] [pid 67073:tid 67322] [client 20.151.109.219:65017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xm.php"] [unique_id "aoSAqPcmepr5_nHgLbNVPwAAAok"] [Tue Aug 18 12:56:24.654434 2026] [security2:error] [pid 67073:tid 67256] [client 20.163.43.14:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/system_log.php"] [unique_id "aoSAqPcmepr5_nHgLbNVQAAAAkc"] [Tue Aug 18 12:56:24.695949 2026] [security2:error] [pid 66623:tid 66879] [client 20.215.241.237:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/images.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2QAAAXs"] [Tue Aug 18 12:56:24.698055 2026] [security2:error] [pid 66623:tid 66833] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ni.php"] [unique_id "aoSAqNO5rbWdOArH04KJ2gAAAU0"] [Tue Aug 18 12:56:24.717046 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:24.717456 2026] [authz_core:error] [pid 67073:tid 67147] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:24.725782 2026] [security2:error] [pid 67073:tid 67309] [client 68.155.154.236:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAqPcmepr5_nHgLbNVRgAAAnw"] [Tue Aug 18 12:56:24.796063 2026] [security2:error] [pid 67073:tid 67228] [client 20.104.85.180:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAqPcmepr5_nHgLbNVSwAAAis"] [Tue Aug 18 12:56:24.799712 2026] [security2:error] [pid 67073:tid 67236] [client 103.184.169.37:41891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTAAAAjM"] [Tue Aug 18 12:56:24.799866 2026] [security2:error] [pid 67073:tid 67236] [client 103.184.169.37:41891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTAAAAjM"] [Tue Aug 18 12:56:24.821075 2026] [security2:error] [pid 67073:tid 67293] [client 20.186.30.159:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/images.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTQAAAmw"] [Tue Aug 18 12:56:24.826286 2026] [security2:error] [pid 66623:tid 66828] [client 20.79.204.6:2213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSAqNO5rbWdOArH04KJ3wAAAUg"] [Tue Aug 18 12:56:24.866760 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:22733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/r.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTgAAAng"] [Tue Aug 18 12:56:24.868609 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.130.103:14416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSAqPcmepr5_nHgLbNVTwAAAl8"] [Tue Aug 18 12:56:24.876037 2026] [security2:error] [pid 67073:tid 67222] [client 74.248.18.37:26813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/ww5.php"] [unique_id "aoSAqPcmepr5_nHgLbNVUQAAAiU"] [Tue Aug 18 12:56:24.945969 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4AAAAQs"] [Tue Aug 18 12:56:24.946055 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4AAAAQs"] [Tue Aug 18 12:56:24.956753 2026] [security2:error] [pid 66623:tid 66847] [client 158.23.17.4:38885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/filesystems.php"] [unique_id "aoSAqNO5rbWdOArH04KJ4QAAAVs"] [Tue Aug 18 12:56:24.971078 2026] [security2:error] [pid 67073:tid 67223] [client 172.202.39.151:28962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/file.php"] [unique_id "aoSAqPcmepr5_nHgLbNVVwAAAiY"] [Tue Aug 18 12:56:25.012145 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:25.012411 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:25.015016 2026] [security2:error] [pid 67073:tid 67232] [client 20.151.109.219:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zy.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXAAAAi8"] [Tue Aug 18 12:56:25.032580 2026] [security2:error] [pid 67073:tid 67220] [client 20.29.77.16:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/teste.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXgAAAiM"] [Tue Aug 18 12:56:25.041129 2026] [security2:error] [pid 67073:tid 67291] [client 213.35.127.232:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAqfcmepr5_nHgLbNVXwAAAmo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:25.066824 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAqfcmepr5_nHgLbNVYgAAAlE"] [Tue Aug 18 12:56:25.070128 2026] [autoindex:error] [pid 67073:tid 67221] [client 20.100.169.31:42683] AH01276: Cannot serve directory /home1/lubarbosa/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:25.077298 2026] [security2:error] [pid 67073:tid 67213] [client 20.104.85.180:18835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/abc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZAAAAhw"] [Tue Aug 18 12:56:25.126160 2026] [security2:error] [pid 67073:tid 67255] [client 20.215.241.237:61093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/alls.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZQAAAkY"] [Tue Aug 18 12:56:25.154143 2026] [security2:error] [pid 67073:tid 67304] [client 20.186.30.159:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/mac.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZwAAAnc"] [Tue Aug 18 12:56:25.162443 2026] [security2:error] [pid 66623:tid 66831] [client 20.52.168.85:8014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/t.php"] [unique_id "aoSAqdO5rbWdOArH04KJ4gAAAUs"] [Tue Aug 18 12:56:25.171378 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:65249] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVaQAAAlI"] [Tue Aug 18 12:56:25.171461 2026] [security2:error] [pid 67073:tid 67267] [client 172.202.39.151:65249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVaQAAAlI"] [Tue Aug 18 12:56:25.193547 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/88.php"] [unique_id "aoSAqfcmepr5_nHgLbNVagAAAk8"] [Tue Aug 18 12:56:25.216901 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVawAAAh0"] [Tue Aug 18 12:56:25.221731 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:48225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSAqdO5rbWdOArH04KJ4wAAATc"] [Tue Aug 18 12:56:25.256004 2026] [security2:error] [pid 67073:tid 67164] [remote 47.86.33.52:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVbQACFlg"] [Tue Aug 18 12:56:25.280102 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.169.31:42683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/php8.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeAAAAkE"] [Tue Aug 18 12:56:25.333451 2026] [security2:error] [pid 66623:tid 66868] [client 20.151.109.219:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/q.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5AAAAXA"] [Tue Aug 18 12:56:25.355366 2026] [security2:error] [pid 67073:tid 67254] [client 20.104.85.180:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/akcc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVfwAAAkU"] [Tue Aug 18 12:56:25.365817 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.130.103:15393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/cabs.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5QAAAWg"] [Tue Aug 18 12:56:25.381849 2026] [security2:error] [pid 67073:tid 67230] [client 158.158.34.183:34969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVgQAAAi0"] [Tue Aug 18 12:56:25.385784 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.136.165:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/agg.php"] [unique_id "aoSAqfcmepr5_nHgLbNVggAAAhQ"] [Tue Aug 18 12:56:25.404306 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.154.236:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqdO5rbWdOArH04KJ5wAAAWs"] [Tue Aug 18 12:56:25.434112 2026] [security2:error] [pid 67073:tid 67322] [client 20.226.6.191:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVhQAAAok"] [Tue Aug 18 12:56:25.439300 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.6.191:32295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVhgAAAkc"] [Tue Aug 18 12:56:25.448347 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hj.php"] [unique_id "aoSAqfcmepr5_nHgLbNViAAAAh4"] [Tue Aug 18 12:56:25.459563 2026] [security2:error] [pid 67073:tid 67257] [client 197.186.9.193:63821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.9.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeQAAAkg"] [Tue Aug 18 12:56:25.459703 2026] [security2:error] [pid 67073:tid 67257] [client 197.186.9.193:63821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVeQAAAkg"] [Tue Aug 18 12:56:25.523827 2026] [security2:error] [pid 67073:tid 67210] [client 20.79.204.6:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSAqfcmepr5_nHgLbNVigAAAhk"] [Tue Aug 18 12:56:25.543354 2026] [security2:error] [pid 66623:tid 66873] [client 20.163.43.14:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6AAAAXU"] [Tue Aug 18 12:56:25.551474 2026] [security2:error] [pid 67073:tid 67131] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env"] [unique_id "aoSAqfcmepr5_nHgLbNVjQACUzc"] [Tue Aug 18 12:56:25.577469 2026] [security2:error] [pid 67073:tid 67293] [client 20.29.77.16:52785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/local.php"] [unique_id "aoSAqfcmepr5_nHgLbNVjwAAAmw"] [Tue Aug 18 12:56:25.586003 2026] [security2:error] [pid 67073:tid 67248] [client 20.215.241.237:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/coffexium.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkAAAAj8"] [Tue Aug 18 12:56:25.614286 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:25.614541 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:25.615645 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkgAAAl8"] [Tue Aug 18 12:56:25.617631 2026] [security2:error] [pid 67073:tid 67222] [client 20.186.30.159:13609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/ops.php"] [unique_id "aoSAqfcmepr5_nHgLbNVkwAAAiU"] [Tue Aug 18 12:56:25.627749 2026] [security2:error] [pid 67073:tid 67285] [client 132.196.61.152:61052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/clque.php"] [unique_id "aoSAqfcmepr5_nHgLbNVlQAAAmQ"] [Tue Aug 18 12:56:25.640247 2026] [security2:error] [pid 67073:tid 67279] [client 20.104.85.180:18842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wk/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVlwAAAl4"] [Tue Aug 18 12:56:25.659079 2026] [security2:error] [pid 66623:tid 66846] [client 172.202.39.151:50209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6QAAAVo"] [Tue Aug 18 12:56:25.665763 2026] [security2:error] [pid 67073:tid 67281] [client 20.151.109.219:17545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xf.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmAAAAmA"] [Tue Aug 18 12:56:25.682784 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.75.187:25659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/maxro.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmQAAAlU"] [Tue Aug 18 12:56:25.701467 2026] [security2:error] [pid 67073:tid 67241] [client 52.139.47.57:25725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/black.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmgAAAjg"] [Tue Aug 18 12:56:25.709322 2026] [security2:error] [pid 67073:tid 67233] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ij.php"] [unique_id "aoSAqfcmepr5_nHgLbNVmwAAAjA"] [Tue Aug 18 12:56:25.715394 2026] [security2:error] [pid 66623:tid 66790] [client 20.65.98.162:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/puc.php"] [unique_id "aoSAqdO5rbWdOArH04KJ6wAAASI"] [Tue Aug 18 12:56:25.751229 2026] [security2:error] [pid 67073:tid 67206] [client 158.158.74.177:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/radio.php"] [unique_id "aoSAqfcmepr5_nHgLbNVnQAAAhU"] [Tue Aug 18 12:56:25.767540 2026] [security2:error] [pid 67073:tid 67228] [client 20.52.168.85:7853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "aoSAqfcmepr5_nHgLbNVoAAAAis"] [Tue Aug 18 12:56:25.852997 2026] [security2:error] [pid 67073:tid 67077] [remote 185.118.190.176:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latung.com.br"] [uri "/wp-login.php"] [unique_id "aoSAqfcmepr5_nHgLbNVogACIQE"] [Tue Aug 18 12:56:25.861843 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.130.103:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/insc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVowAAAhw"] [Tue Aug 18 12:56:25.896191 2026] [security2:error] [pid 67073:tid 67214] [client 20.163.43.14:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/abc.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpQAAAh0"] [Tue Aug 18 12:56:25.924101 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.85.180:18830] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "certificado.numem.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpwAAAlc"] [Tue Aug 18 12:56:25.924243 2026] [security2:error] [pid 67073:tid 67272] [client 20.104.85.180:18830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/1.php"] [unique_id "aoSAqfcmepr5_nHgLbNVpwAAAlc"] [Tue Aug 18 12:56:25.973914 2026] [security2:error] [pid 67073:tid 67245] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ud.php"] [unique_id "aoSAqfcmepr5_nHgLbNVqAAAAjw"] [Tue Aug 18 12:56:26.003457 2026] [autoindex:error] [pid 67073:tid 67207] [client 189.5.11.234:56651] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:26.034837 2026] [security2:error] [pid 67073:tid 67259] [client 172.202.39.151:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrAAAAko"] [Tue Aug 18 12:56:26.037263 2026] [security2:error] [pid 67073:tid 67317] [client 20.151.109.219:21684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gb.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrQAAAoQ"] [Tue Aug 18 12:56:26.052954 2026] [security2:error] [pid 66623:tid 66889] [client 20.215.241.237:40477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/red.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7AAAAYU"] [Tue Aug 18 12:56:26.057133 2026] [security2:error] [pid 67073:tid 67332] [client 213.35.127.232:57177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrgAAApM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:26.070894 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:2508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gw.php"] [unique_id "aoSAqvcmepr5_nHgLbNVrwAAAm0"] [Tue Aug 18 12:56:26.079249 2026] [security2:error] [pid 67073:tid 67205] [client 20.215.241.237:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/file1221.php"] [unique_id "aoSAqvcmepr5_nHgLbNVsAAAAhQ"] [Tue Aug 18 12:56:26.092715 2026] [security2:error] [pid 67073:tid 67212] [client 20.29.77.16:32967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSAqvcmepr5_nHgLbNVsgAAAhs"] [Tue Aug 18 12:56:26.122878 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAqvcmepr5_nHgLbNVswAAAh4"] [Tue Aug 18 12:56:26.126395 2026] [security2:error] [pid 67073:tid 67257] [client 104.209.144.33:25656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAqvcmepr5_nHgLbNVtQAAAkg"] [Tue Aug 18 12:56:26.134133 2026] [security2:error] [pid 67073:tid 67316] [client 20.79.204.6:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAqvcmepr5_nHgLbNVtgAAAoM"] [Tue Aug 18 12:56:26.164335 2026] [autoindex:error] [pid 67073:tid 67247] [client 189.5.11.234:34669] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:26.165605 2026] [security2:error] [pid 67073:tid 67284] [client 20.186.30.159:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/coffexium.php"] [unique_id "aoSAqvcmepr5_nHgLbNVuQAAAmM"] [Tue Aug 18 12:56:26.218674 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:26.219047 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:26.227163 2026] [security2:error] [pid 67073:tid 67231] [client 20.163.43.14:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/akcc.php"] [unique_id "aoSAqvcmepr5_nHgLbNVwAAAAi4"] [Tue Aug 18 12:56:26.228701 2026] [security2:error] [pid 66623:tid 66834] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ip.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7QAAAU4"] [Tue Aug 18 12:56:26.242219 2026] [security2:error] [pid 67073:tid 67102] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.backup"] [unique_id "aoSAqvcmepr5_nHgLbNVwgACgBo"] [Tue Aug 18 12:56:26.260490 2026] [security2:error] [pid 67073:tid 67103] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.bak"] [unique_id "aoSAqvcmepr5_nHgLbNVxAACgBs"] [Tue Aug 18 12:56:26.274732 2026] [security2:error] [pid 67073:tid 67301] [client 20.104.85.180:18834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNVxwAAAnQ"] [Tue Aug 18 12:56:26.276810 2026] [security2:error] [pid 67073:tid 67327] [client 20.116.17.175:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/images.php"] [unique_id "aoSAqvcmepr5_nHgLbNVyAAAAo4"] [Tue Aug 18 12:56:26.287221 2026] [security2:error] [pid 67073:tid 67190] [remote 47.86.33.52:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSAqvcmepr5_nHgLbNVygACGHI"] [Tue Aug 18 12:56:26.305770 2026] [autoindex:error] [pid 67073:tid 67229] [client 189.5.11.234:59663] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:26.315259 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.130.103:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/file.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7gAAAX0"] [Tue Aug 18 12:56:26.353459 2026] [security2:error] [pid 66623:tid 66789] [client 20.151.109.219:65010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jp.php"] [unique_id "aoSAqtO5rbWdOArH04KJ7wAAASE"] [Tue Aug 18 12:56:26.355995 2026] [security2:error] [pid 66623:tid 66840] [client 20.171.51.14:29229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eq.php"] [unique_id "aoSAqtO5rbWdOArH04KJ8AAAAVQ"] [Tue Aug 18 12:56:26.368266 2026] [security2:error] [pid 67073:tid 67296] [client 20.52.168.85:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/bgymj.php"] [unique_id "aoSAqvcmepr5_nHgLbNVzAAAAm8"] [Tue Aug 18 12:56:26.383148 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.6.191:32208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ8gAAAU8"] [Tue Aug 18 12:56:26.396048 2026] [autoindex:error] [pid 67073:tid 67287] [client 189.5.11.234:40473] AH01276: Cannot serve directory /home4/maxtelec/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:26.411897 2026] [security2:error] [pid 67073:tid 67268] [client 172.202.39.151:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/as.php"] [unique_id "aoSAqvcmepr5_nHgLbNVzwAAAlM"] [Tue Aug 18 12:56:26.428279 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.18.37:46683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/2.php"] [unique_id "aoSAqvcmepr5_nHgLbNV0AAAAho"] [Tue Aug 18 12:56:26.443454 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9AAAAUE"] [Tue Aug 18 12:56:26.443564 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9AAAAUE"] [Tue Aug 18 12:56:26.480357 2026] [security2:error] [pid 67073:tid 67114] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.old"] [unique_id "aoSAqvcmepr5_nHgLbNV0QACJiY"] [Tue Aug 18 12:56:26.487363 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/99.php"] [unique_id "aoSAqvcmepr5_nHgLbNV0gAAAiA"] [Tue Aug 18 12:56:26.522110 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:26.522561 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:26.552275 2026] [security2:error] [pid 67073:tid 67321] [client 20.163.43.14:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wk/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV1QAAAog"] [Tue Aug 18 12:56:26.556147 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:43573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9QAAAT0"] [Tue Aug 18 12:56:26.564329 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:18653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAqtO5rbWdOArH04KJ9gAAAXw"] [Tue Aug 18 12:56:26.566779 2026] [security2:error] [pid 67073:tid 67248] [client 158.158.74.177:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSAqvcmepr5_nHgLbNV1wAAAj8"] [Tue Aug 18 12:56:26.579860 2026] [security2:error] [pid 67073:tid 67085] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/api/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV2AACUQk"] [Tue Aug 18 12:56:26.609756 2026] [security2:error] [pid 67073:tid 67196] [remote 110.249.201.114:10208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tivinalili.com.br"] [uri "/starsue%20ever%20after%20high.pdf"] [unique_id "aoSAqvcmepr5_nHgLbNV2wACHHg"] [Tue Aug 18 12:56:26.624390 2026] [security2:error] [pid 67073:tid 67275] [client 20.186.30.159:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAqvcmepr5_nHgLbNV3AAAAlo"] [Tue Aug 18 12:56:26.636458 2026] [security2:error] [pid 66623:tid 66796] [client 158.23.17.4:63645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSAqtO5rbWdOArH04KJ-wAAASg"] [Tue Aug 18 12:56:26.677032 2026] [security2:error] [pid 67073:tid 67194] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/backend/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV3gACT3Y"] [Tue Aug 18 12:56:26.738110 2026] [security2:error] [pid 66623:tid 66776] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/er.php"] [unique_id "aoSAqtO5rbWdOArH04KJ_QAAARQ"] [Tue Aug 18 12:56:26.746372 2026] [security2:error] [pid 67073:tid 67297] [client 20.151.109.219:21656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eq.php"] [unique_id "aoSAqvcmepr5_nHgLbNV4wAAAnA"] [Tue Aug 18 12:56:26.754752 2026] [security2:error] [pid 66623:tid 66839] [client 172.202.39.151:65273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAqtO5rbWdOArH04KJ_gAAAVM"] [Tue Aug 18 12:56:26.764543 2026] [security2:error] [pid 67073:tid 67331] [client 5.161.73.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlypiscinas.com.br"] [uri "/index.php"] [unique_id "aoSAqfcmepr5_nHgLbNVZgACkj4"], referer: https://jlypiscinas.com.br/ [Tue Aug 18 12:56:26.786915 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV5gAAAmA"] [Tue Aug 18 12:56:26.791080 2026] [security2:error] [pid 67073:tid 67245] [client 135.225.75.187:29775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wdf.php"] [unique_id "aoSAqvcmepr5_nHgLbNV5wAAAjw"] [Tue Aug 18 12:56:26.819654 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:26.819967 2026] [authz_core:error] [pid 67073:tid 67165] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:26.839673 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:56753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/file.php"] [unique_id "aoSAqtO5rbWdOArH04KKBgAAAVY"] [Tue Aug 18 12:56:26.839985 2026] [security2:error] [pid 67073:tid 67095] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/config/.env"] [unique_id "aoSAqvcmepr5_nHgLbNV6QACPRM"] [Tue Aug 18 12:56:26.840474 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:43546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/as.php"] [unique_id "aoSAqtO5rbWdOArH04KKBwAAAS8"] [Tue Aug 18 12:56:26.859869 2026] [security2:error] [pid 67073:tid 67259] [client 68.155.154.236:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAqvcmepr5_nHgLbNV7AAAAko"] [Tue Aug 18 12:56:26.861786 2026] [security2:error] [pid 67073:tid 67261] [client 20.79.204.6:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSAqvcmepr5_nHgLbNV7QAAAkw"] [Tue Aug 18 12:56:26.912181 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:4111] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.fmplast.com.br"] [uri "/1.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8AAAAnI"] [Tue Aug 18 12:56:26.912301 2026] [security2:error] [pid 67073:tid 67299] [client 20.163.43.14:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/1.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8AAAAnI"] [Tue Aug 18 12:56:26.936324 2026] [security2:error] [pid 66623:tid 66645] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSAqtO5rbWdOArH04KKCAABYwg"] [Tue Aug 18 12:56:26.969066 2026] [security2:error] [pid 67073:tid 67227] [client 20.29.77.16:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ninja.php"] [unique_id "aoSAqvcmepr5_nHgLbNV8wAAAio"] [Tue Aug 18 12:56:26.992116 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qk.php"] [unique_id "aoSAqvcmepr5_nHgLbNV9AAAAhQ"] [Tue Aug 18 12:56:27.037490 2026] [security2:error] [pid 67073:tid 67309] [client 20.151.109.219:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ep.php"] [unique_id "aoSAq_cmepr5_nHgLbNV9gAAAnw"] [Tue Aug 18 12:56:27.070946 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.130.103:14424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/dex.php"] [unique_id "aoSAq_cmepr5_nHgLbNV9wAAAmE"] [Tue Aug 18 12:56:27.081849 2026] [security2:error] [pid 66623:tid 66808] [client 114.5.214.109:49810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKCwAAATQ"] [Tue Aug 18 12:56:27.081898 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAq_cmepr5_nHgLbNV-wAAAn0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:27.087903 2026] [security2:error] [pid 67073:tid 67308] [client 172.202.39.151:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAq_cmepr5_nHgLbNV_QAAAns"] [Tue Aug 18 12:56:27.088572 2026] [security2:error] [pid 66623:tid 66808] [client 114.5.214.109:49810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKCwAAATQ"] [Tue Aug 18 12:56:27.133665 2026] [security2:error] [pid 66623:tid 66778] [client 20.104.85.180:18870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAq9O5rbWdOArH04KKDAAAARY"] [Tue Aug 18 12:56:27.137258 2026] [security2:error] [pid 66623:tid 66708] [remote 57.141.22.51:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSAq9O5rbWdOArH04KKDQABOkc"] [Tue Aug 18 12:56:27.138367 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/sw.php"] [unique_id "aoSAq_cmepr5_nHgLbNWAQAAAiw"] [Tue Aug 18 12:56:27.175834 2026] [security2:error] [pid 67073:tid 67280] [client 20.52.168.85:7813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-blog.php"] [unique_id "aoSAq_cmepr5_nHgLbNWAgAAAl8"] [Tue Aug 18 12:56:27.201746 2026] [security2:error] [pid 67073:tid 67127] [remote 162.214.205.212:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSAq_cmepr5_nHgLbNWCgACNjM"] [Tue Aug 18 12:56:27.208978 2026] [security2:error] [pid 66623:tid 66864] [client 172.182.200.96:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAq9O5rbWdOArH04KKDgAAAWw"] [Tue Aug 18 12:56:27.222706 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.136.165:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/erty.php"] [unique_id "aoSAq_cmepr5_nHgLbNWDQAAAlU"] [Tue Aug 18 12:56:27.244755 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSAq9O5rbWdOArH04KKDwAAAQw"] [Tue Aug 18 12:56:27.246038 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.154.236:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEAAAAjA"] [Tue Aug 18 12:56:27.252460 2026] [security2:error] [pid 67073:tid 67208] [client 20.250.13.23:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEQAAAhc"] [Tue Aug 18 12:56:27.264593 2026] [security2:error] [pid 66623:tid 66890] [client 20.215.241.237:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAq9O5rbWdOArH04KKEAAAAYY"] [Tue Aug 18 12:56:27.284776 2026] [security2:error] [pid 67073:tid 67224] [client 158.23.17.4:29458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpstatus.php"] [unique_id "aoSAq_cmepr5_nHgLbNWEgAAAic"] [Tue Aug 18 12:56:27.294594 2026] [security2:error] [pid 67073:tid 67273] [client 20.171.51.14:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ep.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFAAAAlg"] [Tue Aug 18 12:56:27.295689 2026] [security2:error] [pid 67073:tid 67313] [client 20.163.43.14:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFQAAAoA"] [Tue Aug 18 12:56:27.318710 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.61.152:60300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/nano.php"] [unique_id "aoSAq9O5rbWdOArH04KKEQAAAUQ"] [Tue Aug 18 12:56:27.322762 2026] [security2:error] [pid 66623:tid 66816] [client 20.151.109.219:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rf.php"] [unique_id "aoSAq9O5rbWdOArH04KKEgAAATw"] [Tue Aug 18 12:56:27.325964 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.18.37:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSAq_cmepr5_nHgLbNWFgAAAj4"] [Tue Aug 18 12:56:27.333628 2026] [security2:error] [pid 67073:tid 67291] [client 157.20.138.62:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGAAAAmo"] [Tue Aug 18 12:56:27.333707 2026] [security2:error] [pid 67073:tid 67291] [client 157.20.138.62:61004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGAAAAmo"] [Tue Aug 18 12:56:27.362991 2026] [security2:error] [pid 67073:tid 67271] [client 158.158.74.177:16540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/red.php"] [unique_id "aoSAq_cmepr5_nHgLbNWGgAAAlY"] [Tue Aug 18 12:56:27.417362 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.85.180:18858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSAq9O5rbWdOArH04KKFQAAAW0"] [Tue Aug 18 12:56:27.421052 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:27.421507 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:27.427104 2026] [security2:error] [pid 67073:tid 67241] [client 79.127.164.8:46156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mails.bak"] [unique_id "aoSAq_cmepr5_nHgLbNWHQAAAjg"], referer: https://medihub.com.br/mails.bak [Tue Aug 18 12:56:27.441194 2026] [security2:error] [pid 67073:tid 67232] [client 20.226.6.191:54905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/epinyins.php"] [unique_id "aoSAq_cmepr5_nHgLbNWHgAAAi8"] [Tue Aug 18 12:56:27.441194 2026] [security2:error] [pid 66623:tid 66644] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSAq9O5rbWdOArH04KKFgABcgc"] [Tue Aug 18 12:56:27.469827 2026] [security2:error] [pid 67073:tid 67266] [client 172.202.39.151:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIAAAAlE"] [Tue Aug 18 12:56:27.479952 2026] [autoindex:error] [pid 66623:tid 66885] [client 20.79.204.6:2223] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:27.494899 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/404.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIQAAAl4"] [Tue Aug 18 12:56:27.530223 2026] [security2:error] [pid 66623:tid 66848] [client 74.248.130.103:25779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/key.php"] [unique_id "aoSAq9O5rbWdOArH04KKGAAAAVw"] [Tue Aug 18 12:56:27.560388 2026] [security2:error] [pid 67073:tid 67276] [client 172.202.39.151:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/index/function.php"] [unique_id "aoSAq_cmepr5_nHgLbNWIwAAAls"] [Tue Aug 18 12:56:27.614708 2026] [security2:error] [pid 66623:tid 66747] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSAq9O5rbWdOArH04KKGQABeG4"] [Tue Aug 18 12:56:27.621427 2026] [security2:error] [pid 66623:tid 66862] [client 20.151.109.219:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xynz1.php"] [unique_id "aoSAq9O5rbWdOArH04KKGgAAAWo"] [Tue Aug 18 12:56:27.625904 2026] [security2:error] [pid 67073:tid 67274] [client 20.163.43.14:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWKAAAAlk"] [Tue Aug 18 12:56:27.659011 2026] [security2:error] [pid 67073:tid 67307] [client 20.186.30.159:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/sf.php"] [unique_id "aoSAq_cmepr5_nHgLbNWLAAAAno"] [Tue Aug 18 12:56:27.678063 2026] [security2:error] [pid 67073:tid 67258] [client 213.202.253.4:57505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/delpaths.php"] [unique_id "aoSAq_cmepr5_nHgLbNWLwAAAkk"], referer: www.google.com [Tue Aug 18 12:56:27.684621 2026] [security2:error] [pid 67073:tid 67297] [client 20.116.17.175:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/a.php"] [unique_id "aoSAq_cmepr5_nHgLbNWMAAAAnA"] [Tue Aug 18 12:56:27.686342 2026] [security2:error] [pid 66623:tid 66843] [client 158.158.34.183:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/file5.php"] [unique_id "aoSAq9O5rbWdOArH04KKHAAAAVc"] [Tue Aug 18 12:56:27.694987 2026] [autoindex:error] [pid 66623:tid 66800] [client 20.79.204.6:2223] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:27.701122 2026] [security2:error] [pid 66623:tid 66836] [client 20.104.85.180:6976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSAq9O5rbWdOArH04KKHgAAAVA"] [Tue Aug 18 12:56:27.729262 2026] [security2:error] [pid 67073:tid 67186] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.github/.env"] [unique_id "aoSAq_cmepr5_nHgLbNWMgACP24"] [Tue Aug 18 12:56:27.736230 2026] [security2:error] [pid 67073:tid 67263] [client 68.155.154.236:16295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAq_cmepr5_nHgLbNWNAAAAk4"] [Tue Aug 18 12:56:27.741126 2026] [security2:error] [pid 67073:tid 67281] [client 20.215.241.237:43618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAq_cmepr5_nHgLbNWNQAAAmA"] [Tue Aug 18 12:56:27.779673 2026] [security2:error] [pid 67073:tid 67267] [client 20.52.168.85:7750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/tool.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOQAAAlI"] [Tue Aug 18 12:56:27.779778 2026] [security2:error] [pid 67073:tid 67260] [client 172.202.39.151:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOAAAAks"] [Tue Aug 18 12:56:27.784853 2026] [security2:error] [pid 66623:tid 66641] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/st.php"] [unique_id "aoSAq9O5rbWdOArH04KKHwABfgQ"] [Tue Aug 18 12:56:27.804503 2026] [security2:error] [pid 67073:tid 67211] [client 149.34.210.141:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOwAAAho"] [Tue Aug 18 12:56:27.849340 2026] [security2:error] [pid 67073:tid 67299] [client 20.29.77.16:27260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/phpprobe.php"] [unique_id "aoSAq_cmepr5_nHgLbNWPAAAAnI"] [Tue Aug 18 12:56:27.898320 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:2223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSAq9O5rbWdOArH04KKIAAAAUs"] [Tue Aug 18 12:56:27.955827 2026] [security2:error] [pid 67073:tid 67311] [client 20.163.43.14:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/as.php"] [unique_id "aoSAq_cmepr5_nHgLbNWPwAAAn4"] [Tue Aug 18 12:56:27.955966 2026] [security2:error] [pid 67073:tid 67212] [client 135.225.75.187:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ff1.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQAAAAhs"] [Tue Aug 18 12:56:27.960999 2026] [security2:error] [pid 66623:tid 66698] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSAq9O5rbWdOArH04KKIQABcz0"] [Tue Aug 18 12:56:27.983557 2026] [security2:error] [pid 67073:tid 67284] [client 20.104.85.180:43537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQgAAAmM"] [Tue Aug 18 12:56:27.986597 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.6.191:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAq_cmepr5_nHgLbNWQwAAAoU"] [Tue Aug 18 12:56:27.989697 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.130.103:14421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/kir.php"] [unique_id "aoSAq_cmepr5_nHgLbNWRAAAAnw"] [Tue Aug 18 12:56:28.016176 2026] [security2:error] [pid 66623:tid 66811] [client 20.151.109.219:17572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vo.php"] [unique_id "aoSArNO5rbWdOArH04KKIwAAATc"] [Tue Aug 18 12:56:28.022516 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:28.022838 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:28.057190 2026] [security2:error] [pid 67073:tid 67084] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWRwACMwg"] [Tue Aug 18 12:56:28.057380 2026] [security2:error] [pid 67073:tid 67236] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWRwACMwg"] [Tue Aug 18 12:56:28.066021 2026] [security2:error] [pid 67073:tid 67253] [client 132.196.30.78:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wk/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWSAAAAkQ"] [Tue Aug 18 12:56:28.072561 2026] [security2:error] [pid 67073:tid 67229] [client 20.226.56.190:2505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gc.php"] [unique_id "aoSArPcmepr5_nHgLbNWSwAAAiw"] [Tue Aug 18 12:56:28.082015 2026] [security2:error] [pid 67073:tid 67211] [client 149.34.210.141:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAq_cmepr5_nHgLbNWOwAAAho"] [Tue Aug 18 12:56:28.095396 2026] [security2:error] [pid 66623:tid 66872] [client 213.35.127.232:57668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSArNO5rbWdOArH04KKJQAAAXQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:28.118699 2026] [security2:error] [pid 66623:tid 66860] [client 158.23.17.4:11004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/del.php"] [unique_id "aoSArNO5rbWdOArH04KKJgAAAWg"] [Tue Aug 18 12:56:28.136088 2026] [security2:error] [pid 66623:tid 66693] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-configs.php"] [unique_id "aoSArNO5rbWdOArH04KKJwABDzg"] [Tue Aug 18 12:56:28.147012 2026] [security2:error] [pid 66623:tid 66863] [client 172.182.200.96:14197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSArNO5rbWdOArH04KKKAAAAWs"] [Tue Aug 18 12:56:28.163577 2026] [security2:error] [pid 66623:tid 66845] [client 20.171.51.14:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rf.php"] [unique_id "aoSArNO5rbWdOArH04KKKQAAAVk"] [Tue Aug 18 12:56:28.190697 2026] [security2:error] [pid 67073:tid 67233] [client 104.209.144.33:29838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSArPcmepr5_nHgLbNWTwAAAjA"] [Tue Aug 18 12:56:28.227660 2026] [security2:error] [pid 67073:tid 67287] [client 20.215.241.237:40495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file52.php"] [unique_id "aoSArPcmepr5_nHgLbNWUwAAAmY"] [Tue Aug 18 12:56:28.259130 2026] [security2:error] [pid 67073:tid 67224] [client 20.186.30.159:13637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/k.php"] [unique_id "aoSArPcmepr5_nHgLbNWVAAAAic"] [Tue Aug 18 12:56:28.286318 2026] [security2:error] [pid 66623:tid 66849] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKJAABXRU"] [Tue Aug 18 12:56:28.292520 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:2663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/release.php"] [unique_id "aoSArPcmepr5_nHgLbNWWQAAAng"] [Tue Aug 18 12:56:28.294055 2026] [autoindex:error] [pid 66623:tid 66830] [client 172.202.39.151:65248] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:28.302829 2026] [security2:error] [pid 66623:tid 66844] [client 20.163.43.14:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSArNO5rbWdOArH04KKLQAAAVg"] [Tue Aug 18 12:56:28.311155 2026] [security2:error] [pid 66623:tid 66656] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-post.php"] [unique_id "aoSArNO5rbWdOArH04KKLgABWhM"] [Tue Aug 18 12:56:28.372685 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.18.37:28107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSArPcmepr5_nHgLbNWWwAAAn8"] [Tue Aug 18 12:56:28.379616 2026] [security2:error] [pid 66623:tid 66873] [client 20.52.168.85:7862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ws.php"] [unique_id "aoSArNO5rbWdOArH04KKLwAAAXU"] [Tue Aug 18 12:56:28.379667 2026] [authz_core:error] [pid 67073:tid 67168] [remote 35.197.144.252:50706] AH01630: client denied by server configuration: /home3/adobankcom/public_html/.htpasswd [Tue Aug 18 12:56:28.387438 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:28.387707 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:28.417688 2026] [security2:error] [pid 67073:tid 67320] [client 20.151.109.219:24879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wu.php"] [unique_id "aoSArPcmepr5_nHgLbNWYQAAAoc"] [Tue Aug 18 12:56:28.437040 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/bs1.php"] [unique_id "aoSArPcmepr5_nHgLbNWYgAAAn0"] [Tue Aug 18 12:56:28.458444 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.130.103:15411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/nofile.php"] [unique_id "aoSArPcmepr5_nHgLbNWZQAAAk0"] [Tue Aug 18 12:56:28.481816 2026] [security2:error] [pid 67073:tid 67145] [remote 129.121.123.168:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoSArPcmepr5_nHgLbNWZwACI0U"] [Tue Aug 18 12:56:28.484038 2026] [security2:error] [pid 66623:tid 66653] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSArNO5rbWdOArH04KKMAABOxA"] [Tue Aug 18 12:56:28.506161 2026] [security2:error] [pid 67073:tid 67313] [client 20.79.204.6:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSArPcmepr5_nHgLbNWaAAAAoA"] [Tue Aug 18 12:56:28.576107 2026] [security2:error] [pid 67073:tid 67293] [client 20.100.169.31:7753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSArPcmepr5_nHgLbNWawAAAmw"] [Tue Aug 18 12:56:28.584528 2026] [security2:error] [pid 67073:tid 67276] [client 68.155.154.236:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSArPcmepr5_nHgLbNWbAAAAls"] [Tue Aug 18 12:56:28.598210 2026] [security2:error] [pid 66623:tid 66789] [client 172.202.39.151:65248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSArNO5rbWdOArH04KKMQAAASE"] [Tue Aug 18 12:56:28.604491 2026] [autoindex:error] [pid 67073:tid 67285] [client 20.226.6.191:48377] AH01276: Cannot serve directory /home2/pixmid70/sengerclimatizacao.com.br/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:28.613827 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.6.191:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWbgAAAlA"] [Tue Aug 18 12:56:28.625924 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:28.626185 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:28.630766 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:4209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSArPcmepr5_nHgLbNWcAAAApA"] [Tue Aug 18 12:56:28.633035 2026] [security2:error] [pid 67073:tid 67214] [client 20.186.30.159:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/82.php"] [unique_id "aoSArPcmepr5_nHgLbNWcQAAAh0"] [Tue Aug 18 12:56:28.639459 2026] [security2:error] [pid 67073:tid 67307] [client 20.116.17.175:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSArPcmepr5_nHgLbNWcgAAAno"] [Tue Aug 18 12:56:28.656769 2026] [security2:error] [pid 66623:tid 66650] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSArNO5rbWdOArH04KKMwABDg0"] [Tue Aug 18 12:56:28.661338 2026] [authz_core:error] [pid 67073:tid 67184] [remote 57.141.22.1:21702] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:28.661600 2026] [authz_core:error] [pid 67073:tid 67184] [remote 57.141.22.1:21702] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:28.671336 2026] [security2:error] [pid 67073:tid 67244] [client 20.215.241.237:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/geck.php"] [unique_id "aoSArPcmepr5_nHgLbNWdgAAAjs"] [Tue Aug 18 12:56:28.699714 2026] [security2:error] [pid 66623:tid 66840] [client 20.171.51.14:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xynz1.php"] [unique_id "aoSArNO5rbWdOArH04KKNAAAAVQ"] [Tue Aug 18 12:56:28.724747 2026] [security2:error] [pid 67073:tid 67297] [client 20.151.109.219:21682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/de.php"] [unique_id "aoSArPcmepr5_nHgLbNWeAAAAnA"] [Tue Aug 18 12:56:28.733136 2026] [security2:error] [pid 67073:tid 67097] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSArPcmepr5_nHgLbNWewACHxU"] [Tue Aug 18 12:56:28.749966 2026] [security2:error] [pid 67073:tid 67250] [client 40.85.222.29:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSArPcmepr5_nHgLbNWfQAAAkE"] [Tue Aug 18 12:56:28.804322 2026] [security2:error] [pid 67073:tid 67237] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fs.php"] [unique_id "aoSArPcmepr5_nHgLbNWggAAAjQ"] [Tue Aug 18 12:56:28.828562 2026] [security2:error] [pid 66623:tid 66750] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-2019.php"] [unique_id "aoSArNO5rbWdOArH04KKNQABJ3E"] [Tue Aug 18 12:56:28.886801 2026] [security2:error] [pid 67073:tid 67132] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSArPcmepr5_nHgLbNWhwACHzg"] [Tue Aug 18 12:56:28.908424 2026] [security2:error] [pid 66623:tid 66775] [client 178.153.171.161:40632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKNgAAARM"] [Tue Aug 18 12:56:28.908550 2026] [security2:error] [pid 66623:tid 66775] [client 178.153.171.161:40632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArNO5rbWdOArH04KKNgAAARM"] [Tue Aug 18 12:56:28.924358 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:61433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mini.php"] [unique_id "aoSArPcmepr5_nHgLbNWigAAAh4"] [Tue Aug 18 12:56:28.926026 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:28.926425 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:28.941441 2026] [security2:error] [pid 67073:tid 67228] [client 138.36.100.162:41830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWiwAAAis"] [Tue Aug 18 12:56:28.941576 2026] [security2:error] [pid 67073:tid 67228] [client 138.36.100.162:41830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArPcmepr5_nHgLbNWiwAAAis"] [Tue Aug 18 12:56:28.982951 2026] [security2:error] [pid 67073:tid 67219] [client 20.186.30.159:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/dex.php"] [unique_id "aoSArPcmepr5_nHgLbNWjAAAAiI"] [Tue Aug 18 12:56:28.985463 2026] [security2:error] [pid 67073:tid 67317] [client 20.52.168.85:8047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSArPcmepr5_nHgLbNWjQAAAoQ"] [Tue Aug 18 12:56:28.997797 2026] [security2:error] [pid 67073:tid 67130] [remote 162.214.96.231:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSArPcmepr5_nHgLbNWjgACkjY"] [Tue Aug 18 12:56:29.000370 2026] [security2:error] [pid 66623:tid 66704] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/cjfuns.php"] [unique_id "aoSArNO5rbWdOArH04KKOAABg0M"] [Tue Aug 18 12:56:29.002438 2026] [security2:error] [pid 67073:tid 67316] [client 20.151.109.219:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/album.php"] [unique_id "aoSArfcmepr5_nHgLbNWjwAAAoM"] [Tue Aug 18 12:56:29.019430 2026] [security2:error] [pid 67073:tid 67295] [client 20.163.43.14:4210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWkQAAAm4"] [Tue Aug 18 12:56:29.023839 2026] [security2:error] [pid 66623:tid 66880] [client 74.248.130.103:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/fling.php"] [unique_id "aoSArdO5rbWdOArH04KKOgAAAXw"] [Tue Aug 18 12:56:29.074711 2026] [security2:error] [pid 66623:tid 66794] [client 158.158.74.177:16542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/reop3.php"] [unique_id "aoSArdO5rbWdOArH04KKOwAAASY"] [Tue Aug 18 12:56:29.085578 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rb.php"] [unique_id "aoSArdO5rbWdOArH04KKPAAAATk"] [Tue Aug 18 12:56:29.114885 2026] [security2:error] [pid 67073:tid 67267] [client 213.35.127.232:57930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWlgAAAlI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:29.118737 2026] [security2:error] [pid 66623:tid 66837] [client 40.85.222.29:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSArdO5rbWdOArH04KKPQAAAVE"] [Tue Aug 18 12:56:29.129920 2026] [autoindex:error] [pid 67073:tid 67212] [client 20.79.204.6:2379] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:29.132518 2026] [security2:error] [pid 66623:tid 66796] [client 172.202.39.151:50232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/an.php"] [unique_id "aoSArdO5rbWdOArH04KKPgAAASg"] [Tue Aug 18 12:56:29.155644 2026] [security2:error] [pid 67073:tid 67229] [client 20.215.241.237:57789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/biufile.php"] [unique_id "aoSArfcmepr5_nHgLbNWlwAAAiw"] [Tue Aug 18 12:56:29.173655 2026] [security2:error] [pid 66623:tid 66689] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSArdO5rbWdOArH04KKPwABQDQ"] [Tue Aug 18 12:56:29.180768 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uq.php"] [unique_id "aoSArfcmepr5_nHgLbNWmAAAAiU"] [Tue Aug 18 12:56:29.206907 2026] [security2:error] [pid 67073:tid 67324] [client 132.196.61.152:60292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/.mopj.php"] [unique_id "aoSArfcmepr5_nHgLbNWmgAAAos"] [Tue Aug 18 12:56:29.226401 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:17269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSArfcmepr5_nHgLbNWnAAAAlU"] [Tue Aug 18 12:56:29.238028 2026] [security2:error] [pid 67073:tid 67287] [client 158.23.17.4:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/moderator.php"] [unique_id "aoSArfcmepr5_nHgLbNWngAAAmY"] [Tue Aug 18 12:56:29.259045 2026] [security2:error] [pid 67073:tid 67207] [client 132.196.30.78:19407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/about.php"] [unique_id "aoSArfcmepr5_nHgLbNWoAAAAhY"] [Tue Aug 18 12:56:29.264228 2026] [security2:error] [pid 66623:tid 66888] [client 167.235.143.113:31918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSArdO5rbWdOArH04KKQAAAAYQ"], referer: https://dadicamotors.com.br/ [Tue Aug 18 12:56:29.273227 2026] [security2:error] [pid 66623:tid 66776] [client 20.29.77.16:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/wp-title.php"] [unique_id "aoSArdO5rbWdOArH04KKQQAAARQ"] [Tue Aug 18 12:56:29.303897 2026] [security2:error] [pid 67073:tid 67112] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/id_rsa"] [unique_id "aoSArfcmepr5_nHgLbNWowACPiQ"] [Tue Aug 18 12:56:29.322028 2026] [security2:error] [pid 67073:tid 67291] [client 20.151.109.219:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kv.php"] [unique_id "aoSArfcmepr5_nHgLbNWpAAAAmo"] [Tue Aug 18 12:56:29.326582 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vo.php"] [unique_id "aoSArfcmepr5_nHgLbNWpQAAAlY"] [Tue Aug 18 12:56:29.341127 2026] [security2:error] [pid 67073:tid 67308] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/37.php"] [unique_id "aoSArfcmepr5_nHgLbNWqwAAAns"] [Tue Aug 18 12:56:29.341368 2026] [security2:error] [pid 67073:tid 67140] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/id_dsa"] [unique_id "aoSArfcmepr5_nHgLbNWqgACPkA"] [Tue Aug 18 12:56:29.344240 2026] [security2:error] [pid 66623:tid 66753] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSArdO5rbWdOArH04KKQgABTHQ"] [Tue Aug 18 12:56:29.346173 2026] [autoindex:error] [pid 67073:tid 67251] [client 20.79.204.6:2379] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:29.352715 2026] [security2:error] [pid 67073:tid 67320] [client 20.163.43.14:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWrAAAAoc"] [Tue Aug 18 12:56:29.420111 2026] [security2:error] [pid 66623:tid 66780] [client 20.116.17.175:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/99.php"] [unique_id "aoSArdO5rbWdOArH04KKQwAAARg"] [Tue Aug 18 12:56:29.432202 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.200.96:14137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSArdO5rbWdOArH04KKRAAAAR0"] [Tue Aug 18 12:56:29.454599 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.6.191:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWsQAAAlo"] [Tue Aug 18 12:56:29.460236 2026] [security2:error] [pid 67073:tid 67279] [client 20.186.30.159:8423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/puc.php"] [unique_id "aoSArfcmepr5_nHgLbNWsgAAAl4"] [Tue Aug 18 12:56:29.465976 2026] [security2:error] [pid 67073:tid 67264] [client 172.202.39.151:28977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/edit.php"] [unique_id "aoSArfcmepr5_nHgLbNWswAAAk8"] [Tue Aug 18 12:56:29.475183 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.130.103:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/zoo1.php"] [unique_id "aoSArfcmepr5_nHgLbNWtQAAAjI"] [Tue Aug 18 12:56:29.479776 2026] [security2:error] [pid 67073:tid 67274] [client 40.85.222.29:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/weozh.php"] [unique_id "aoSArfcmepr5_nHgLbNWtgAAAlk"] [Tue Aug 18 12:56:29.515368 2026] [security2:error] [pid 66623:tid 66742] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/import.php"] [unique_id "aoSArdO5rbWdOArH04KKRQABL2k"] [Tue Aug 18 12:56:29.528400 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:29.528653 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:29.551653 2026] [security2:error] [pid 67073:tid 67304] [client 20.79.204.6:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSArfcmepr5_nHgLbNWugAAAnc"] [Tue Aug 18 12:56:29.589964 2026] [security2:error] [pid 67073:tid 67321] [client 20.52.168.85:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWvAAAAog"] [Tue Aug 18 12:56:29.597887 2026] [security2:error] [pid 67073:tid 67250] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/md.php"] [unique_id "aoSArfcmepr5_nHgLbNWvQAAAkE"] [Tue Aug 18 12:56:29.604882 2026] [security2:error] [pid 67073:tid 67319] [client 20.215.241.237:40506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dejavu.php"] [unique_id "aoSArfcmepr5_nHgLbNWvgAAAoY"] [Tue Aug 18 12:56:29.621505 2026] [security2:error] [pid 67073:tid 67226] [client 20.151.109.219:21666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/z.php"] [unique_id "aoSArfcmepr5_nHgLbNWvwAAAik"] [Tue Aug 18 12:56:29.668334 2026] [security2:error] [pid 67073:tid 67162] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/key.pem"] [unique_id "aoSArfcmepr5_nHgLbNWwQACVFY"] [Tue Aug 18 12:56:29.677048 2026] [security2:error] [pid 67073:tid 67281] [client 20.171.51.14:65143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wu.php"] [unique_id "aoSArfcmepr5_nHgLbNWxQAAAmA"] [Tue Aug 18 12:56:29.682657 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:35026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/rip.php"] [unique_id "aoSArdO5rbWdOArH04KKRgAAAWY"] [Tue Aug 18 12:56:29.688737 2026] [security2:error] [pid 66623:tid 66662] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/cropper.php"] [unique_id "aoSArdO5rbWdOArH04KKRwABPxk"] [Tue Aug 18 12:56:29.708389 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.169.31:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/term.php"] [unique_id "aoSArfcmepr5_nHgLbNWxgAAAjA"] [Tue Aug 18 12:56:29.711895 2026] [security2:error] [pid 66623:tid 66774] [client 20.100.169.31:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/222.php"] [unique_id "aoSArdO5rbWdOArH04KKSAAAARI"] [Tue Aug 18 12:56:29.750991 2026] [security2:error] [pid 67073:tid 67311] [client 104.209.144.33:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSArfcmepr5_nHgLbNWyAAAAn4"] [Tue Aug 18 12:56:29.768264 2026] [autoindex:error] [pid 67073:tid 67289] [client 172.202.39.151:55443] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:29.775828 2026] [security2:error] [pid 67073:tid 67228] [client 52.173.121.69:24966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSArfcmepr5_nHgLbNWywAAAis"] [Tue Aug 18 12:56:29.813796 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/rymmm.php"] [unique_id "aoSArfcmepr5_nHgLbNWzAAAAmM"] [Tue Aug 18 12:56:29.826711 2026] [security2:error] [pid 67073:tid 67108] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/privatekey.key"] [unique_id "aoSArfcmepr5_nHgLbNWzQACVCA"] [Tue Aug 18 12:56:29.850303 2026] [security2:error] [pid 67073:tid 67315] [client 20.163.43.14:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSArfcmepr5_nHgLbNWzgAAAoI"] [Tue Aug 18 12:56:29.855626 2026] [security2:error] [pid 67073:tid 67260] [client 132.196.30.78:22465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/term.php"] [unique_id "aoSArfcmepr5_nHgLbNWzwAAAks"] [Tue Aug 18 12:56:29.859162 2026] [security2:error] [pid 66623:tid 66721] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSArdO5rbWdOArH04KKSQABY1Q"] [Tue Aug 18 12:56:29.861136 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/iy.php"] [unique_id "aoSArfcmepr5_nHgLbNW0AAAAoE"] [Tue Aug 18 12:56:29.903535 2026] [security2:error] [pid 67073:tid 67240] [client 20.151.109.219:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xg.php"] [unique_id "aoSArfcmepr5_nHgLbNW0gAAAjc"] [Tue Aug 18 12:56:29.941565 2026] [security2:error] [pid 67073:tid 67280] [client 135.225.75.187:29707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/guk.php"] [unique_id "aoSArfcmepr5_nHgLbNW1gAAAl8"] [Tue Aug 18 12:56:29.950242 2026] [security2:error] [pid 67073:tid 67232] [client 160.120.140.123:61855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW1wAAAi8"] [Tue Aug 18 12:56:29.950381 2026] [security2:error] [pid 67073:tid 67232] [client 160.120.140.123:61855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW1wAAAi8"] [Tue Aug 18 12:56:29.957697 2026] [security2:error] [pid 67073:tid 67296] [client 158.23.17.4:38903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/infoinfo.php"] [unique_id "aoSArfcmepr5_nHgLbNW2QAAAm8"] [Tue Aug 18 12:56:29.959501 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW2AAAAkU"] [Tue Aug 18 12:56:29.959639 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:50898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSArfcmepr5_nHgLbNW2AAAAkU"] [Tue Aug 18 12:56:29.976808 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.34.183:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/new.php"] [unique_id "aoSArfcmepr5_nHgLbNW2wAAAok"] [Tue Aug 18 12:56:29.988567 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.130.103:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/zoo2.php"] [unique_id "aoSArfcmepr5_nHgLbNW3AAAAj0"] [Tue Aug 18 12:56:29.997630 2026] [security2:error] [pid 66623:tid 66854] [client 20.186.30.159:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/inso.php"] [unique_id "aoSArdO5rbWdOArH04KKSgAAAWI"] [Tue Aug 18 12:56:30.030432 2026] [security2:error] [pid 66623:tid 66691] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSArtO5rbWdOArH04KKSwABbjY"] [Tue Aug 18 12:56:30.031929 2026] [security2:error] [pid 67073:tid 67210] [client 52.139.47.57:25710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/colors/blue/about.php"] [unique_id "aoSArvcmepr5_nHgLbNW3QAAAhk"] [Tue Aug 18 12:56:30.054616 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/404.php"] [unique_id "aoSArvcmepr5_nHgLbNW4gAAAhc"] [Tue Aug 18 12:56:30.062895 2026] [security2:error] [pid 67073:tid 67258] [client 20.215.241.237:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aaf.php"] [unique_id "aoSArvcmepr5_nHgLbNW4wAAAkk"] [Tue Aug 18 12:56:30.121961 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp.php"] [unique_id "aoSArtO5rbWdOArH04KKTAAAATQ"] [Tue Aug 18 12:56:30.130709 2026] [security2:error] [pid 67073:tid 67295] [client 213.35.127.232:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSArvcmepr5_nHgLbNW5QAAAm4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:30.139686 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:30.139955 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:30.140123 2026] [security2:error] [pid 66623:tid 66778] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/og.php"] [unique_id "aoSArtO5rbWdOArH04KKTQAAARY"] [Tue Aug 18 12:56:30.141255 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/lddxs.php"] [unique_id "aoSArvcmepr5_nHgLbNW5wAAAl0"] [Tue Aug 18 12:56:30.160687 2026] [security2:error] [pid 67073:tid 67218] [client 20.79.204.6:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSArvcmepr5_nHgLbNW6QAAAiE"] [Tue Aug 18 12:56:30.167138 2026] [security2:error] [pid 67073:tid 67273] [client 156.59.198.136:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/sp/sao-paulo/jardim-novo-santo-amaro/img/rua-caminho-particular-jardim-novo-santo-amaro-sao-paulo-sp.webp"] [unique_id "aoSArvcmepr5_nHgLbNW6wAAAlg"], referer: https://www.icep.com.br/livrocep/sp/sao-paulo/jardim-novo-santo-amaro/rua-caminho-particular-cep-05820232/ [Tue Aug 18 12:56:30.172171 2026] [security2:error] [pid 67073:tid 67291] [client 20.171.51.14:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/de.php"] [unique_id "aoSArvcmepr5_nHgLbNW7QAAAmo"] [Tue Aug 18 12:56:30.181517 2026] [security2:error] [pid 67073:tid 67277] [client 20.163.43.14:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/an.php"] [unique_id "aoSArvcmepr5_nHgLbNW7gAAAlw"] [Tue Aug 18 12:56:30.197317 2026] [security2:error] [pid 67073:tid 67299] [client 20.250.13.23:19686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/gecko-new.php"] [unique_id "aoSArvcmepr5_nHgLbNW8AAAAnI"] [Tue Aug 18 12:56:30.199367 2026] [security2:error] [pid 66623:tid 66766] [client 20.52.168.85:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/file.php"] [unique_id "aoSArtO5rbWdOArH04KKTgAAAQo"] [Tue Aug 18 12:56:30.199890 2026] [security2:error] [pid 67073:tid 67320] [client 20.151.109.219:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/nd.php"] [unique_id "aoSArvcmepr5_nHgLbNW8QAAAoc"] [Tue Aug 18 12:56:30.201554 2026] [security2:error] [pid 66623:tid 66695] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/goat.php"] [unique_id "aoSArtO5rbWdOArH04KKTwABOjo"] [Tue Aug 18 12:56:30.279329 2026] [security2:error] [pid 67073:tid 67207] [client 158.158.74.177:16575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/robots.php"] [unique_id "aoSArvcmepr5_nHgLbNW9QAAAhY"] [Tue Aug 18 12:56:30.377764 2026] [security2:error] [pid 66623:tid 66798] [client 20.186.30.159:13590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/aa.php"] [unique_id "aoSArtO5rbWdOArH04KKUQAAASo"] [Tue Aug 18 12:56:30.395760 2026] [security2:error] [pid 67073:tid 67235] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lp.php"] [unique_id "aoSArvcmepr5_nHgLbNW-QAAAjI"] [Tue Aug 18 12:56:30.415943 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.136.165:46790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sid3.php"] [unique_id "aoSArvcmepr5_nHgLbNW-gAAAlk"] [Tue Aug 18 12:56:30.424000 2026] [security2:error] [pid 67073:tid 67329] [client 172.202.39.151:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/epinyins.php"] [unique_id "aoSArvcmepr5_nHgLbNW-wAAApA"] [Tue Aug 18 12:56:30.430820 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.130.103:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/org.php"] [unique_id "aoSArvcmepr5_nHgLbNW_QAAAh0"] [Tue Aug 18 12:56:30.433641 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:30.433913 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:30.440186 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:19397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSArvcmepr5_nHgLbNW_gAAAjg"] [Tue Aug 18 12:56:30.455668 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zjggu.php"] [unique_id "aoSArvcmepr5_nHgLbNXAAAAAjk"] [Tue Aug 18 12:56:30.471981 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSArtO5rbWdOArH04KKUgAAAQw"] [Tue Aug 18 12:56:30.500018 2026] [security2:error] [pid 67073:tid 67139] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSArvcmepr5_nHgLbNXAgACQT8"] [Tue Aug 18 12:56:30.511775 2026] [security2:error] [pid 67073:tid 67234] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSArvcmepr5_nHgLbNXAQACMTo"] [Tue Aug 18 12:56:30.526856 2026] [security2:error] [pid 67073:tid 67259] [client 20.151.109.219:59743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ri.php"] [unique_id "aoSArvcmepr5_nHgLbNXBQAAAko"] [Tue Aug 18 12:56:30.534750 2026] [security2:error] [pid 66623:tid 66772] [client 20.215.241.237:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSArtO5rbWdOArH04KKUwAAARA"] [Tue Aug 18 12:56:30.587117 2026] [security2:error] [pid 66623:tid 66696] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/Session.php"] [unique_id "aoSArtO5rbWdOArH04KKVAABJDs"] [Tue Aug 18 12:56:30.605603 2026] [security2:error] [pid 66623:tid 66870] [client 20.171.51.14:58860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/album.php"] [unique_id "aoSArtO5rbWdOArH04KKVQAAAXI"] [Tue Aug 18 12:56:30.687286 2026] [security2:error] [pid 66623:tid 66885] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ey.php"] [unique_id "aoSArtO5rbWdOArH04KKVwAAAYE"] [Tue Aug 18 12:56:30.693297 2026] [security2:error] [pid 67073:tid 67233] [client 201.32.74.208:56356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSArvcmepr5_nHgLbNXCAAAAjA"] [Tue Aug 18 12:56:30.695252 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/404.php"] [unique_id "aoSArvcmepr5_nHgLbNXCQAAAi0"] [Tue Aug 18 12:56:30.736448 2026] [security2:error] [pid 67073:tid 67253] [client 172.202.39.151:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-login.php"] [unique_id "aoSArvcmepr5_nHgLbNXDAAAAkQ"] [Tue Aug 18 12:56:30.738871 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:30.739323 2026] [authz_core:error] [pid 67073:tid 67099] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:30.748434 2026] [security2:error] [pid 67073:tid 67205] [client 20.116.17.175:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yup.php"] [unique_id "aoSArvcmepr5_nHgLbNXDgAAAhQ"] [Tue Aug 18 12:56:30.758521 2026] [security2:error] [pid 66623:tid 66649] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSArtO5rbWdOArH04KKWAABRgw"] [Tue Aug 18 12:56:30.759577 2026] [security2:error] [pid 66623:tid 66809] [client 20.215.241.237:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/nox.php"] [unique_id "aoSArtO5rbWdOArH04KKWQAAATU"] [Tue Aug 18 12:56:30.783588 2026] [autoindex:error] [pid 66623:tid 66865] [client 20.79.204.6:2389] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:30.799692 2026] [security2:error] [pid 66623:tid 66777] [client 20.52.168.85:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSArtO5rbWdOArH04KKWwAAARU"] [Tue Aug 18 12:56:30.823048 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/p.php"] [unique_id "aoSArvcmepr5_nHgLbNXEAAAAls"] [Tue Aug 18 12:56:30.826163 2026] [security2:error] [pid 67073:tid 67257] [client 20.151.109.219:21642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tp.php"] [unique_id "aoSArvcmepr5_nHgLbNXEQAAAkg"] [Tue Aug 18 12:56:30.847638 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.6.191:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/function/function.php"] [unique_id "aoSArvcmepr5_nHgLbNXEwAAAiI"] [Tue Aug 18 12:56:30.851736 2026] [security2:error] [pid 66623:tid 66720] [remote 46.62.208.238:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/wp-login.php"] [unique_id "aoSArtO5rbWdOArH04KKXQABUlM"] [Tue Aug 18 12:56:30.869809 2026] [security2:error] [pid 67073:tid 67284] [client 40.85.222.29:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/dlvqo.php"] [unique_id "aoSArvcmepr5_nHgLbNXFAAAAmM"] [Tue Aug 18 12:56:30.872544 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.130.103:14460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/imageskir.php"] [unique_id "aoSArvcmepr5_nHgLbNXFQAAAoU"] [Tue Aug 18 12:56:30.920367 2026] [security2:error] [pid 67073:tid 67240] [client 20.186.30.159:13676] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/1.php"] [unique_id "aoSArvcmepr5_nHgLbNXIAAAAjc"] [Tue Aug 18 12:56:30.920455 2026] [security2:error] [pid 67073:tid 67240] [client 20.186.30.159:13676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/1.php"] [unique_id "aoSArvcmepr5_nHgLbNXIAAAAjc"] [Tue Aug 18 12:56:30.929154 2026] [security2:error] [pid 66623:tid 66667] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/abcd.php"] [unique_id "aoSArtO5rbWdOArH04KKYAABfh4"] [Tue Aug 18 12:56:30.934160 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lv.php"] [unique_id "aoSArtO5rbWdOArH04KKYQAAAWQ"] [Tue Aug 18 12:56:30.957282 2026] [security2:error] [pid 66623:tid 66848] [client 79.127.164.8:46210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mails.sql"] [unique_id "aoSArtO5rbWdOArH04KKYgAAAVw"], referer: https://medihub.com.br/mails.sql [Tue Aug 18 12:56:30.983880 2026] [security2:error] [pid 66623:tid 66871] [client 20.79.204.6:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSArtO5rbWdOArH04KKZAAAAXM"] [Tue Aug 18 12:56:31.026943 2026] [security2:error] [pid 66623:tid 66811] [client 20.163.43.14:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-login.php"] [unique_id "aoSAr9O5rbWdOArH04KKZQAAATc"] [Tue Aug 18 12:56:31.044915 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.56.190:47133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/32.php"] [unique_id "aoSAr_cmepr5_nHgLbNXIwAAAjY"] [Tue Aug 18 12:56:31.073728 2026] [security2:error] [pid 67073:tid 67212] [client 74.7.241.135:59038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gram.goptur.app.br"] [uri "/robots.txt"] [unique_id "aoSAr_cmepr5_nHgLbNXJQACGyU"] [Tue Aug 18 12:56:31.094453 2026] [security2:error] [pid 67073:tid 67278] [client 68.155.154.236:16229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAr_cmepr5_nHgLbNXJgAAAl0"] [Tue Aug 18 12:56:31.106394 2026] [security2:error] [pid 67073:tid 67268] [client 20.151.109.219:32985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/zj.php"] [unique_id "aoSAr_cmepr5_nHgLbNXJwAAAlM"] [Tue Aug 18 12:56:31.108984 2026] [security2:error] [pid 66623:tid 66716] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/kj.php"] [unique_id "aoSAr9O5rbWdOArH04KKZgABQ08"] [Tue Aug 18 12:56:31.147173 2026] [security2:error] [pid 67073:tid 67271] [client 40.85.222.29:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAr_cmepr5_nHgLbNXKgAAAlY"] [Tue Aug 18 12:56:31.155399 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAr9O5rbWdOArH04KKaAAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:31.170808 2026] [security2:error] [pid 67073:tid 67277] [client 20.215.241.237:44043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/155.php"] [unique_id "aoSAr_cmepr5_nHgLbNXKwAAAlw"] [Tue Aug 18 12:56:31.170823 2026] [security2:error] [pid 67073:tid 67328] [client 20.65.98.162:8456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/19.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLAAAAo8"] [Tue Aug 18 12:56:31.181279 2026] [security2:error] [pid 67073:tid 67299] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/51.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLgAAAnI"] [Tue Aug 18 12:56:31.212100 2026] [security2:error] [pid 67073:tid 67313] [client 20.186.30.159:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/img.php"] [unique_id "aoSAr_cmepr5_nHgLbNXLwAAAoA"] [Tue Aug 18 12:56:31.214109 2026] [security2:error] [pid 67073:tid 67290] [client 158.158.74.177:16515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/root.php"] [unique_id "aoSAr_cmepr5_nHgLbNXMAAAAmk"] [Tue Aug 18 12:56:31.228909 2026] [security2:error] [pid 67073:tid 67165] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAr_cmepr5_nHgLbNXNAACjVk"] [Tue Aug 18 12:56:31.233026 2026] [security2:error] [pid 67073:tid 67275] [client 158.23.17.4:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/c99shell.php"] [unique_id "aoSAr_cmepr5_nHgLbNXNQAAAlo"] [Tue Aug 18 12:56:31.239868 2026] [security2:error] [pid 67073:tid 67292] [client 20.171.51.14:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kv.php"] [unique_id "aoSAr_cmepr5_nHgLbNXNgAAAms"] [Tue Aug 18 12:56:31.281799 2026] [security2:error] [pid 67073:tid 67186] [remote 135.236.141.8:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoSAr_cmepr5_nHgLbNXOgACeW4"] [Tue Aug 18 12:56:31.282892 2026] [security2:error] [pid 66623:tid 66648] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/languages.php"] [unique_id "aoSAr9O5rbWdOArH04KKaQABWQs"] [Tue Aug 18 12:56:31.310287 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.61.152:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/bengi.php"] [unique_id "aoSAr_cmepr5_nHgLbNXOwAAAh0"] [Tue Aug 18 12:56:31.311927 2026] [security2:error] [pid 66623:tid 66890] [client 157.51.166.53:61788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAr9O5rbWdOArH04KKagAAAYY"] [Tue Aug 18 12:56:31.315660 2026] [security2:error] [pid 67073:tid 67241] [client 20.226.56.190:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/73.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPAAAAjg"] [Tue Aug 18 12:56:31.316205 2026] [security2:error] [pid 66623:tid 66890] [client 157.51.166.53:61788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAr9O5rbWdOArH04KKagAAAYY"] [Tue Aug 18 12:56:31.322614 2026] [security2:error] [pid 67073:tid 67242] [client 20.215.241.237:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPgAAAjk"] [Tue Aug 18 12:56:31.322613 2026] [authz_core:error] [pid 67073:tid 67153] [remote 57.141.22.101:47246] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:31.322942 2026] [authz_core:error] [pid 67073:tid 67153] [remote 57.141.22.101:47246] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:31.326884 2026] [security2:error] [pid 67073:tid 67304] [client 74.248.130.103:25780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/indexo.php"] [unique_id "aoSAr_cmepr5_nHgLbNXPwAAAnc"] [Tue Aug 18 12:56:31.328057 2026] [security2:error] [pid 67073:tid 67225] [client 158.158.34.183:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fm.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQAAAAig"] [Tue Aug 18 12:56:31.337398 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:19410] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/1.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQwAAApI"] [Tue Aug 18 12:56:31.337502 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/1.php"] [unique_id "aoSAr_cmepr5_nHgLbNXQwAAApI"] [Tue Aug 18 12:56:31.345826 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:31.346263 2026] [authz_core:error] [pid 67073:tid 67120] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:31.362478 2026] [security2:error] [pid 67073:tid 67327] [client 20.163.43.14:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRAAAAo4"] [Tue Aug 18 12:56:31.387430 2026] [security2:error] [pid 67073:tid 67325] [client 172.202.39.151:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRQAAAow"] [Tue Aug 18 12:56:31.403328 2026] [security2:error] [pid 67073:tid 67312] [client 20.52.168.85:7808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/news.php"] [unique_id "aoSAr_cmepr5_nHgLbNXRwAAAn8"] [Tue Aug 18 12:56:31.419046 2026] [security2:error] [pid 67073:tid 67243] [client 20.151.109.219:64626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/x.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSQAAAjo"] [Tue Aug 18 12:56:31.422578 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/kopyw.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSgAAAjQ"] [Tue Aug 18 12:56:31.445792 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ew.php"] [unique_id "aoSAr_cmepr5_nHgLbNXSwAAAkA"] [Tue Aug 18 12:56:31.458306 2026] [security2:error] [pid 67073:tid 67262] [client 172.202.39.151:12697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTAAAAk0"] [Tue Aug 18 12:56:31.540953 2026] [security2:error] [pid 67073:tid 67316] [client 135.225.75.187:25605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-the.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTgAAAoM"] [Tue Aug 18 12:56:31.556357 2026] [security2:error] [pid 67073:tid 67229] [client 52.139.47.57:47639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/con7.php"] [unique_id "aoSAr_cmepr5_nHgLbNXTwAAAiw"] [Tue Aug 18 12:56:31.616045 2026] [security2:error] [pid 67073:tid 67232] [client 20.186.30.159:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/222.php"] [unique_id "aoSAr_cmepr5_nHgLbNXUgAAAi8"] [Tue Aug 18 12:56:31.665736 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:29213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/z.php"] [unique_id "aoSAr9O5rbWdOArH04KKdAAAAVg"] [Tue Aug 18 12:56:31.685537 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ops.php"] [unique_id "aoSAr9O5rbWdOArH04KKdgAAAVo"] [Tue Aug 18 12:56:31.699466 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pqr.php"] [unique_id "aoSAr9O5rbWdOArH04KKeAAAAXE"] [Tue Aug 18 12:56:31.700453 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zznmg.php"] [unique_id "aoSAr_cmepr5_nHgLbNXVgAAAjY"] [Tue Aug 18 12:56:31.716390 2026] [security2:error] [pid 67073:tid 67246] [client 20.215.241.237:19006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/akismet.php"] [unique_id "aoSAr_cmepr5_nHgLbNXVwAAAj0"] [Tue Aug 18 12:56:31.720187 2026] [autoindex:error] [pid 67073:tid 67253] [client 20.79.204.6:2382] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:31.746999 2026] [security2:error] [pid 66623:tid 66867] [client 20.151.109.219:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yn.php"] [unique_id "aoSAr9O5rbWdOArH04KKeQAAAW8"] [Tue Aug 18 12:56:31.758816 2026] [security2:error] [pid 66623:tid 66801] [client 104.209.144.33:35852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAr9O5rbWdOArH04KKegAAAS0"] [Tue Aug 18 12:56:31.806185 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.56.190:2550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ib.php"] [unique_id "aoSAr_cmepr5_nHgLbNXXgAAAlM"] [Tue Aug 18 12:56:31.857506 2026] [security2:error] [pid 67073:tid 67151] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adopagamentos.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAr_cmepr5_nHgLbNXXwACYUs"] [Tue Aug 18 12:56:31.882317 2026] [autoindex:error] [pid 67073:tid 67291] [client 172.202.39.151:48201] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:31.882411 2026] [security2:error] [pid 67073:tid 67271] [client 74.248.130.103:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSAr_cmepr5_nHgLbNXYgAAAlY"] [Tue Aug 18 12:56:31.920593 2026] [security2:error] [pid 67073:tid 67299] [client 20.79.204.6:2382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSAr_cmepr5_nHgLbNXaAAAAnI"] [Tue Aug 18 12:56:31.936224 2026] [security2:error] [pid 66623:tid 66697] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/nw.php"] [unique_id "aoSAr9O5rbWdOArH04KKgAABEzw"] [Tue Aug 18 12:56:31.942916 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:31.943175 2026] [authz_core:error] [pid 67073:tid 67094] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:31.945169 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:34196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/moon.php"] [unique_id "aoSAr_cmepr5_nHgLbNXawAAAhg"] [Tue Aug 18 12:56:31.957237 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/alfa.php"] [unique_id "aoSAr9O5rbWdOArH04KKgwAAASI"] [Tue Aug 18 12:56:31.960786 2026] [security2:error] [pid 67073:tid 67275] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/an.php"] [unique_id "aoSAr_cmepr5_nHgLbNXbAAAAlo"] [Tue Aug 18 12:56:31.988421 2026] [security2:error] [pid 67073:tid 67273] [client 68.155.154.236:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAr_cmepr5_nHgLbNXbQAAAlg"] [Tue Aug 18 12:56:32.046527 2026] [security2:error] [pid 66623:tid 66887] [client 20.116.17.175:57621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/222.php"] [unique_id "aoSAsNO5rbWdOArH04KKhgAAAYM"] [Tue Aug 18 12:56:32.046544 2026] [security2:error] [pid 66623:tid 66807] [client 20.163.43.14:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wso.php"] [unique_id "aoSAsNO5rbWdOArH04KKhwAAATM"] [Tue Aug 18 12:56:32.048993 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAsNO5rbWdOArH04KKiAAAAT0"] [Tue Aug 18 12:56:32.061696 2026] [security2:error] [pid 66623:tid 66880] [client 172.202.39.151:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAsNO5rbWdOArH04KKiQAAAXw"] [Tue Aug 18 12:56:32.063894 2026] [security2:error] [pid 67073:tid 67264] [client 20.186.30.159:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/key.php"] [unique_id "aoSAsPcmepr5_nHgLbNXbwAAAk8"] [Tue Aug 18 12:56:32.068541 2026] [security2:error] [pid 67073:tid 67306] [client 20.226.6.191:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAsPcmepr5_nHgLbNXcAAAAnk"] [Tue Aug 18 12:56:32.083629 2026] [security2:error] [pid 67073:tid 67274] [client 20.151.109.219:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/11.php"] [unique_id "aoSAsPcmepr5_nHgLbNXcgAAAlk"] [Tue Aug 18 12:56:32.087367 2026] [autoindex:error] [pid 67073:tid 67265] [client 172.202.39.151:55439] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:32.108136 2026] [security2:error] [pid 66623:tid 66728] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSAsNO5rbWdOArH04KKigABKVs"] [Tue Aug 18 12:56:32.125258 2026] [security2:error] [pid 67073:tid 67170] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adopagamentos.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSAsPcmepr5_nHgLbNXcwACKF4"] [Tue Aug 18 12:56:32.140885 2026] [security2:error] [pid 67073:tid 67321] [client 158.23.17.4:38911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/profiler.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdQAAAog"] [Tue Aug 18 12:56:32.169902 2026] [security2:error] [pid 67073:tid 67234] [client 172.202.39.151:48201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdgAAAjE"] [Tue Aug 18 12:56:32.170280 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:58625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAsPcmepr5_nHgLbNXdwAAAiE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:32.207281 2026] [security2:error] [pid 67073:tid 67261] [client 201.32.74.208:56358] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSAsPcmepr5_nHgLbNXeAAAAkw"] [Tue Aug 18 12:56:32.211810 2026] [security2:error] [pid 66623:tid 66820] [client 20.52.168.85:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/yanz.php"] [unique_id "aoSAsNO5rbWdOArH04KKjAAAAUA"] [Tue Aug 18 12:56:32.223315 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:29844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.melocorretordeimoveis.com.br"] [uri "/php.php"] [unique_id "aoSAsPcmepr5_nHgLbNXeQAAAjc"] [Tue Aug 18 12:56:32.242738 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:32.243055 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:32.247505 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sy.php"] [unique_id "aoSAsPcmepr5_nHgLbNXewAAAhU"] [Tue Aug 18 12:56:32.249120 2026] [security2:error] [pid 67073:tid 67259] [client 20.215.241.237:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/mac.php"] [unique_id "aoSAsPcmepr5_nHgLbNXfAAAAko"] [Tue Aug 18 12:56:32.275861 2026] [security2:error] [pid 67073:tid 67212] [client 20.100.169.31:29986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAsPcmepr5_nHgLbNXfgAAAhs"] [Tue Aug 18 12:56:32.289466 2026] [security2:error] [pid 67073:tid 67141] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/core/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXgQACMEE"] [Tue Aug 18 12:56:32.290122 2026] [autoindex:error] [pid 66623:tid 66715] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:32.290360 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.5:35396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:32.290599 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.5:35396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:32.329026 2026] [security2:error] [pid 67073:tid 67303] [client 158.158.74.177:17949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/rrr.php"] [unique_id "aoSAsPcmepr5_nHgLbNXggAAAnY"] [Tue Aug 18 12:56:32.378606 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAsPcmepr5_nHgLbNXhgAAAlQ"] [Tue Aug 18 12:56:32.383707 2026] [autoindex:error] [pid 67073:tid 67229] [client 172.202.39.151:55439] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:32.407439 2026] [security2:error] [pid 66623:tid 66888] [client 20.163.43.14:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/sf.php"] [unique_id "aoSAsNO5rbWdOArH04KKkQAAAYQ"] [Tue Aug 18 12:56:32.439786 2026] [security2:error] [pid 67073:tid 67232] [client 74.248.130.103:36844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/8pyceeo.php"] [unique_id "aoSAsPcmepr5_nHgLbNXiQAAAi8"] [Tue Aug 18 12:56:32.440473 2026] [security2:error] [pid 67073:tid 67181] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/.env.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXfwACMGk"] [Tue Aug 18 12:56:32.450441 2026] [security2:error] [pid 67073:tid 67244] [client 20.151.109.219:21693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vm.php"] [unique_id "aoSAsPcmepr5_nHgLbNXigAAAjs"] [Tue Aug 18 12:56:32.463333 2026] [security2:error] [pid 66623:tid 66664] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSAsNO5rbWdOArH04KKkgABUxs"] [Tue Aug 18 12:56:32.473864 2026] [security2:error] [pid 67073:tid 67124] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/config/.env.php"] [unique_id "aoSAsPcmepr5_nHgLbNXiwACizA"] [Tue Aug 18 12:56:32.477560 2026] [security2:error] [pid 67073:tid 67157] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/laravel/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXjAACHlE"] [Tue Aug 18 12:56:32.511340 2026] [security2:error] [pid 67073:tid 67118] [remote 129.121.103.155:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSAsPcmepr5_nHgLbNXjwACLSo"] [Tue Aug 18 12:56:32.513276 2026] [security2:error] [pid 66623:tid 66832] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/57.php"] [unique_id "aoSAsNO5rbWdOArH04KKlAAAAUw"] [Tue Aug 18 12:56:32.521939 2026] [security2:error] [pid 67073:tid 67289] [client 20.79.204.6:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSAsPcmepr5_nHgLbNXkwAAAmg"] [Tue Aug 18 12:56:32.530506 2026] [security2:error] [pid 67073:tid 67227] [client 172.202.39.151:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wso.php"] [unique_id "aoSAsPcmepr5_nHgLbNXlAAAAio"] [Tue Aug 18 12:56:32.581943 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.6.191:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAsPcmepr5_nHgLbNXmAAAAng"] [Tue Aug 18 12:56:32.617203 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.6.191:48323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/ok.php"] [unique_id "aoSAsPcmepr5_nHgLbNXoAAAAoA"] [Tue Aug 18 12:56:32.633526 2026] [security2:error] [pid 66623:tid 66734] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSAsNO5rbWdOArH04KKlwABL2E"] [Tue Aug 18 12:56:32.640253 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.6.191:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/item.php"] [unique_id "aoSAsPcmepr5_nHgLbNXoQAAAhY"] [Tue Aug 18 12:56:32.646088 2026] [security2:error] [pid 67073:tid 67209] [client 132.196.61.152:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/file2.php"] [unique_id "aoSAsPcmepr5_nHgLbNXogAAAhg"] [Tue Aug 18 12:56:32.657810 2026] [security2:error] [pid 67073:tid 67216] [client 52.139.47.57:47653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpAAAAh8"] [Tue Aug 18 12:56:32.671733 2026] [security2:error] [pid 67073:tid 67079] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/config.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXpQACIAM"] [Tue Aug 18 12:56:32.674366 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAsNO5rbWdOArH04KKmQAAATY"] [Tue Aug 18 12:56:32.675022 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xg.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpgAAAk8"] [Tue Aug 18 12:56:32.696484 2026] [security2:error] [pid 67073:tid 67211] [client 40.85.222.29:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/oivcl.php"] [unique_id "aoSAsPcmepr5_nHgLbNXpwAAAho"] [Tue Aug 18 12:56:32.733147 2026] [security2:error] [pid 66623:tid 66685] [remote 191.39.149.110:7834] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSAsNO5rbWdOArH04KKmgABgjA"], referer: https://barsantajulia.com.br/happyhour/ [Tue Aug 18 12:56:32.735535 2026] [security2:error] [pid 66623:tid 66806] [client 20.163.43.14:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/index/function.php"] [unique_id "aoSAsNO5rbWdOArH04KKmwAAATI"] [Tue Aug 18 12:56:32.751616 2026] [security2:error] [pid 67073:tid 67214] [client 20.151.109.219:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eg.php"] [unique_id "aoSAsPcmepr5_nHgLbNXqwAAAh0"] [Tue Aug 18 12:56:32.763903 2026] [security2:error] [pid 67073:tid 67247] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ah.php"] [unique_id "aoSAsPcmepr5_nHgLbNXrgAAAj4"] [Tue Aug 18 12:56:32.789217 2026] [security2:error] [pid 67073:tid 67331] [client 20.186.30.159:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/chosen.php"] [unique_id "aoSAsPcmepr5_nHgLbNXsAAAApI"] [Tue Aug 18 12:56:32.804209 2026] [security2:error] [pid 66623:tid 66651] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/f7.php"] [unique_id "aoSAsNO5rbWdOArH04KKnQABPw4"] [Tue Aug 18 12:56:32.817095 2026] [security2:error] [pid 67073:tid 67299] [client 20.52.168.85:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/files/index.php"] [unique_id "aoSAsPcmepr5_nHgLbNXsgAAAnI"] [Tue Aug 18 12:56:32.836236 2026] [security2:error] [pid 67073:tid 67184] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/public/.env"] [unique_id "aoSAsPcmepr5_nHgLbNXswACIWw"] [Tue Aug 18 12:56:32.839293 2026] [security2:error] [pid 67073:tid 67088] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/.env.swp"] [unique_id "aoSAsPcmepr5_nHgLbNXtAACIQw"] [Tue Aug 18 12:56:32.841386 2026] [security2:error] [pid 67073:tid 67226] [client 172.182.200.96:14201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAsPcmepr5_nHgLbNXtgAAAik"] [Tue Aug 18 12:56:32.846360 2026] [security2:error] [pid 67073:tid 67128] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.197.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adopagamentos.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSAsPcmepr5_nHgLbNXtwACNzQ"] [Tue Aug 18 12:56:32.952356 2026] [security2:error] [pid 67073:tid 67302] [client 192.141.172.134:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsPcmepr5_nHgLbNXugAAAnU"] [Tue Aug 18 12:56:32.952493 2026] [security2:error] [pid 67073:tid 67302] [client 192.141.172.134:60950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsPcmepr5_nHgLbNXugAAAnU"] [Tue Aug 18 12:56:32.975210 2026] [security2:error] [pid 66623:tid 66669] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/photo.php"] [unique_id "aoSAsNO5rbWdOArH04KKoAABVSA"] [Tue Aug 18 12:56:32.996734 2026] [security2:error] [pid 66623:tid 66854] [client 40.85.222.29:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zugvi.php"] [unique_id "aoSAsNO5rbWdOArH04KKoQAAAWI"] [Tue Aug 18 12:56:32.998458 2026] [security2:error] [pid 67073:tid 67316] [client 135.225.75.187:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sbhu.php"] [unique_id "aoSAsPcmepr5_nHgLbNXuwAAAoM"] [Tue Aug 18 12:56:32.999091 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.130.103:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/.admin.php"] [unique_id "aoSAsPcmepr5_nHgLbNXvAAAAmU"] [Tue Aug 18 12:56:33.008102 2026] [security2:error] [pid 67073:tid 67221] [client 196.12.128.158:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvQAAAiQ"] [Tue Aug 18 12:56:33.008210 2026] [security2:error] [pid 67073:tid 67221] [client 196.12.128.158:50254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvQAAAiQ"] [Tue Aug 18 12:56:33.014085 2026] [security2:error] [pid 67073:tid 67249] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vw.php"] [unique_id "aoSAsfcmepr5_nHgLbNXvwAAAkA"] [Tue Aug 18 12:56:33.061139 2026] [security2:error] [pid 66623:tid 66866] [client 20.163.43.14:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/edit.php"] [unique_id "aoSAsdO5rbWdOArH04KKpAAAAW4"] [Tue Aug 18 12:56:33.073395 2026] [security2:error] [pid 67073:tid 67237] [client 132.196.30.78:21834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/edit.php"] [unique_id "aoSAsfcmepr5_nHgLbNXwgAAAjQ"] [Tue Aug 18 12:56:33.088140 2026] [security2:error] [pid 67073:tid 67220] [client 74.248.136.165:28110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ms.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxAAAAiM"] [Tue Aug 18 12:56:33.096460 2026] [security2:error] [pid 67073:tid 67104] [remote 35.197.144.252:50706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adopagamentos.com.br"] [uri "/web/.env"] [unique_id "aoSAsfcmepr5_nHgLbNXxQACXxw"] [Tue Aug 18 12:56:33.113872 2026] [security2:error] [pid 66623:tid 66793] [client 20.151.109.219:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/uk.php"] [unique_id "aoSAsdO5rbWdOArH04KKpgAAASU"] [Tue Aug 18 12:56:33.128849 2026] [security2:error] [pid 67073:tid 67311] [client 20.79.204.6:2227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxgAAAn4"] [Tue Aug 18 12:56:33.150038 2026] [security2:error] [pid 66623:tid 66778] [client 172.202.39.151:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/sf.php"] [unique_id "aoSAsdO5rbWdOArH04KKqAAAARY"] [Tue Aug 18 12:56:33.150909 2026] [security2:error] [pid 67073:tid 67213] [client 20.100.169.31:19909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAsfcmepr5_nHgLbNXxwAAAhw"] [Tue Aug 18 12:56:33.151223 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:19365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xm.php"] [unique_id "aoSAsfcmepr5_nHgLbNXyAAAAoQ"] [Tue Aug 18 12:56:33.151548 2026] [security2:error] [pid 66623:tid 66730] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-aa.php"] [unique_id "aoSAsdO5rbWdOArH04KKqQABCl0"] [Tue Aug 18 12:56:33.173686 2026] [security2:error] [pid 67073:tid 67296] [client 20.171.51.14:29186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/nd.php"] [unique_id "aoSAsfcmepr5_nHgLbNXyQAAAm8"] [Tue Aug 18 12:56:33.183133 2026] [security2:error] [pid 67073:tid 67261] [client 213.35.127.232:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAsfcmepr5_nHgLbNXywAAAkw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:33.190181 2026] [security2:error] [pid 67073:tid 67232] [client 158.23.17.4:9392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/findes.php"] [unique_id "aoSAsfcmepr5_nHgLbNXzAAAAi8"] [Tue Aug 18 12:56:33.275401 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/spadex.php"] [unique_id "aoSAsdO5rbWdOArH04KKrQAAARA"] [Tue Aug 18 12:56:33.280168 2026] [security2:error] [pid 66623:tid 66870] [client 40.85.222.29:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wsrer.php"] [unique_id "aoSAsdO5rbWdOArH04KKrgAAAXI"] [Tue Aug 18 12:56:33.308375 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lj.php"] [unique_id "aoSAsfcmepr5_nHgLbNX0AAAAhc"] [Tue Aug 18 12:56:33.371787 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:33594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/info.php"] [unique_id "aoSAsdO5rbWdOArH04KKsQAAATQ"] [Tue Aug 18 12:56:33.403589 2026] [security2:error] [pid 66623:tid 66712] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/d.php"] [unique_id "aoSAsdO5rbWdOArH04KKsgABgUs"] [Tue Aug 18 12:56:33.417756 2026] [security2:error] [pid 66623:tid 66864] [client 20.52.168.85:7817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/css/about.php"] [unique_id "aoSAsdO5rbWdOArH04KKtAAAAWw"] [Tue Aug 18 12:56:33.418495 2026] [security2:error] [pid 66623:tid 66809] [client 20.151.109.219:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/creds.php"] [unique_id "aoSAsdO5rbWdOArH04KKtQAAATU"] [Tue Aug 18 12:56:33.444805 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:33.445238 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:33.456627 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAsfcmepr5_nHgLbNX1AAAAlY"] [Tue Aug 18 12:56:33.473444 2026] [security2:error] [pid 67073:tid 67290] [client 74.248.130.103:38715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/wsomini.php"] [unique_id "aoSAsfcmepr5_nHgLbNX1QAAAmk"] [Tue Aug 18 12:56:33.559280 2026] [security2:error] [pid 66623:tid 66768] [client 52.139.47.57:44629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSAsdO5rbWdOArH04KKuAAAAQw"] [Tue Aug 18 12:56:33.568996 2026] [security2:error] [pid 66623:tid 66787] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kh.php"] [unique_id "aoSAsdO5rbWdOArH04KKuQAAAR8"] [Tue Aug 18 12:56:33.573901 2026] [security2:error] [pid 67073:tid 67292] [client 20.163.43.14:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2QAAAms"] [Tue Aug 18 12:56:33.576196 2026] [security2:error] [pid 66623:tid 66756] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSAsdO5rbWdOArH04KKugABUnc"] [Tue Aug 18 12:56:33.605063 2026] [security2:error] [pid 67073:tid 67216] [client 20.186.30.159:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/thoms.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2gAAAh8"] [Tue Aug 18 12:56:33.610293 2026] [security2:error] [pid 67073:tid 67285] [client 40.85.222.29:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAsfcmepr5_nHgLbNX2wAAAmQ"] [Tue Aug 18 12:56:33.641171 2026] [security2:error] [pid 67073:tid 67264] [client 20.171.51.14:28862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ri.php"] [unique_id "aoSAsfcmepr5_nHgLbNX3QAAAk8"] [Tue Aug 18 12:56:33.682997 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/showphpinfo.php"] [unique_id "aoSAsfcmepr5_nHgLbNX3gAAAiU"] [Tue Aug 18 12:56:33.710614 2026] [security2:error] [pid 67073:tid 67321] [client 20.151.109.219:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ho.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4AAAAog"] [Tue Aug 18 12:56:33.729908 2026] [security2:error] [pid 67073:tid 67325] [client 172.182.200.96:14155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4gAAAow"] [Tue Aug 18 12:56:33.730557 2026] [security2:error] [pid 67073:tid 67250] [client 172.202.39.151:48196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-good.php"] [unique_id "aoSAsfcmepr5_nHgLbNX4wAAAkE"] [Tue Aug 18 12:56:33.734543 2026] [security2:error] [pid 67073:tid 67330] [client 20.215.241.237:18960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/admin.php"] [unique_id "aoSAsfcmepr5_nHgLbNX5QAAApE"] [Tue Aug 18 12:56:33.743451 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:33.743736 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:33.746451 2026] [security2:error] [pid 66623:tid 66739] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSAsdO5rbWdOArH04KKvQABV2Y"] [Tue Aug 18 12:56:33.754568 2026] [autoindex:error] [pid 67073:tid 67293] [client 20.79.204.6:2381] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:33.795060 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:65258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/index/function.php"] [unique_id "aoSAsdO5rbWdOArH04KKvwAAAWc"] [Tue Aug 18 12:56:33.805829 2026] [security2:error] [pid 67073:tid 67082] [remote 47.128.57.62:54528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "igsautomoveis.com.br"] [uri "/veiculo/1019039/vw-volkswagen-polo-track-1-0-flex-12v-5p-2024"] [unique_id "aoSAsfcmepr5_nHgLbNX6gACXgY"] [Tue Aug 18 12:56:33.829072 2026] [security2:error] [pid 67073:tid 67243] [client 158.158.34.183:59413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/bolt.php"] [unique_id "aoSAsfcmepr5_nHgLbNX6wAAAjo"] [Tue Aug 18 12:56:33.829835 2026] [security2:error] [pid 67073:tid 67312] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jb.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7AAAAn8"] [Tue Aug 18 12:56:33.831317 2026] [security2:error] [pid 67073:tid 67301] [client 104.209.144.33:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7QAAAnQ"] [Tue Aug 18 12:56:33.832305 2026] [security2:error] [pid 67073:tid 67322] [client 172.202.39.151:38629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAsfcmepr5_nHgLbNX7gAAAok"] [Tue Aug 18 12:56:33.896852 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:2978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/s.php"] [unique_id "aoSAsdO5rbWdOArH04KKwQAAAS4"] [Tue Aug 18 12:56:33.906373 2026] [security2:error] [pid 66623:tid 66868] [client 132.196.61.152:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/gm.php"] [unique_id "aoSAsdO5rbWdOArH04KKwgAAAXA"] [Tue Aug 18 12:56:33.908149 2026] [security2:error] [pid 67073:tid 67235] [client 74.248.130.103:16142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formularios.filialweb.com"] [uri "/vr.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8AAAAjI"] [Tue Aug 18 12:56:33.908836 2026] [security2:error] [pid 67073:tid 67310] [client 20.163.43.14:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-good.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8QAAAn0"] [Tue Aug 18 12:56:33.908885 2026] [security2:error] [pid 66623:tid 66823] [client 20.116.17.175:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSAsdO5rbWdOArH04KKwwAAAUM"] [Tue Aug 18 12:56:33.913379 2026] [security2:error] [pid 67073:tid 67302] [client 40.85.222.29:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/yxijx.php"] [unique_id "aoSAsfcmepr5_nHgLbNX8gAAAnU"] [Tue Aug 18 12:56:33.918790 2026] [security2:error] [pid 66623:tid 66723] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSAsdO5rbWdOArH04KKxAABalY"] [Tue Aug 18 12:56:33.971815 2026] [security2:error] [pid 67073:tid 67328] [client 158.23.17.4:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/fedora.php"] [unique_id "aoSAsfcmepr5_nHgLbNX9AAAAo8"] [Tue Aug 18 12:56:34.006216 2026] [security2:error] [pid 67073:tid 67221] [client 20.151.109.219:64993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/97.php"] [unique_id "aoSAsvcmepr5_nHgLbNX9QAAAiQ"] [Tue Aug 18 12:56:34.024643 2026] [security2:error] [pid 66623:tid 66829] [client 20.52.168.85:7832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAstO5rbWdOArH04KKyAAAAUk"] [Tue Aug 18 12:56:34.073298 2026] [security2:error] [pid 66623:tid 66826] [client 103.120.71.157:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAstO5rbWdOArH04KKygAAAUY"] [Tue Aug 18 12:56:34.073412 2026] [security2:error] [pid 66623:tid 66826] [client 103.120.71.157:52156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAstO5rbWdOArH04KKygAAAUY"] [Tue Aug 18 12:56:34.074112 2026] [security2:error] [pid 67073:tid 67276] [client 197.184.64.235:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-AAAAls"] [Tue Aug 18 12:56:34.074233 2026] [security2:error] [pid 67073:tid 67276] [client 197.184.64.235:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-AAAAls"] [Tue Aug 18 12:56:34.087094 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/do.php"] [unique_id "aoSAsvcmepr5_nHgLbNX-QAAAnw"] [Tue Aug 18 12:56:34.090264 2026] [security2:error] [pid 66623:tid 66655] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAstO5rbWdOArH04KKzQABFxI"] [Tue Aug 18 12:56:34.115350 2026] [security2:error] [pid 67073:tid 67267] [client 20.226.56.190:31004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zy.php"] [unique_id "aoSAsvcmepr5_nHgLbNX_AAAAlI"] [Tue Aug 18 12:56:34.121704 2026] [security2:error] [pid 67073:tid 67213] [client 20.186.30.159:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/wpxml.php"] [unique_id "aoSAsvcmepr5_nHgLbNX_QAAAhw"] [Tue Aug 18 12:56:34.191090 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:9067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSAsvcmepr5_nHgLbNYDgAAAns"] [Tue Aug 18 12:56:34.191088 2026] [security2:error] [pid 67073:tid 67287] [client 20.79.204.6:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSAsvcmepr5_nHgLbNYDwAAAmY"] [Tue Aug 18 12:56:34.203503 2026] [security2:error] [pid 67073:tid 67259] [client 213.35.127.232:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAsvcmepr5_nHgLbNYGgAAAko"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:34.228436 2026] [security2:error] [pid 66623:tid 66801] [client 20.215.241.237:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSAstO5rbWdOArH04KK0AAAAS0"] [Tue Aug 18 12:56:34.236672 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/zc-318.php"] [unique_id "aoSAsvcmepr5_nHgLbNYGwAAAkk"] [Tue Aug 18 12:56:34.237536 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/zwlsv.php"] [unique_id "aoSAsvcmepr5_nHgLbNYHAAAAmg"] [Tue Aug 18 12:56:34.260091 2026] [security2:error] [pid 66623:tid 66670] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAstO5rbWdOArH04KK0QABPiE"] [Tue Aug 18 12:56:34.332254 2026] [security2:error] [pid 67073:tid 67305] [client 20.151.109.219:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rh.php"] [unique_id "aoSAsvcmepr5_nHgLbNYJgAAAng"] [Tue Aug 18 12:56:34.345929 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:34.346184 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:34.364358 2026] [security2:error] [pid 67073:tid 67271] [client 20.171.51.14:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tp.php"] [unique_id "aoSAsvcmepr5_nHgLbNYKAAAAlY"] [Tue Aug 18 12:56:34.382553 2026] [security2:error] [pid 67073:tid 67231] [client 20.116.17.175:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/srontol.php"] [unique_id "aoSAsvcmepr5_nHgLbNYKwAAAi4"] [Tue Aug 18 12:56:34.432966 2026] [security2:error] [pid 66623:tid 66713] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/abc.php"] [unique_id "aoSAstO5rbWdOArH04KK1QABIUw"] [Tue Aug 18 12:56:34.458865 2026] [security2:error] [pid 66623:tid 66770] [client 20.65.98.162:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/133.php"] [unique_id "aoSAstO5rbWdOArH04KK1gAAAQ4"] [Tue Aug 18 12:56:34.465665 2026] [security2:error] [pid 66623:tid 66830] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yw.php"] [unique_id "aoSAstO5rbWdOArH04KK1wAAAUo"] [Tue Aug 18 12:56:34.513628 2026] [security2:error] [pid 66623:tid 66821] [client 40.85.222.29:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/jrpga.php"] [unique_id "aoSAstO5rbWdOArH04KK2gAAAUE"] [Tue Aug 18 12:56:34.525422 2026] [security2:error] [pid 66623:tid 66790] [client 158.23.17.4:38871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/path.php"] [unique_id "aoSAstO5rbWdOArH04KK2wAAASI"] [Tue Aug 18 12:56:34.606317 2026] [security2:error] [pid 66623:tid 66690] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/sf.php"] [unique_id "aoSAstO5rbWdOArH04KK3QABdjU"] [Tue Aug 18 12:56:34.630576 2026] [security2:error] [pid 66623:tid 66834] [client 20.52.168.85:8026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/num.php"] [unique_id "aoSAstO5rbWdOArH04KK3gAAAU4"] [Tue Aug 18 12:56:34.643786 2026] [security2:error] [pid 67073:tid 67228] [client 20.250.13.23:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/NewFile.php"] [unique_id "aoSAsvcmepr5_nHgLbNYMQAAAis"] [Tue Aug 18 12:56:34.648227 2026] [security2:error] [pid 67073:tid 67250] [client 20.163.43.14:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/tes.php"] [unique_id "aoSAsvcmepr5_nHgLbNYMgAAAkE"] [Tue Aug 18 12:56:34.655516 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:34.656153 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:34.658414 2026] [security2:error] [pid 67073:tid 67330] [client 20.151.109.219:21640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/yg.php"] [unique_id "aoSAsvcmepr5_nHgLbNYNAAAApE"] [Tue Aug 18 12:56:34.659691 2026] [security2:error] [pid 67073:tid 67234] [client 20.186.30.159:13624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/file1221.php"] [unique_id "aoSAsvcmepr5_nHgLbNYNQAAAjE"] [Tue Aug 18 12:56:34.708513 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.61.152:60348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/ws55.php"] [unique_id "aoSAstO5rbWdOArH04KK4AAAASg"] [Tue Aug 18 12:56:34.730992 2026] [security2:error] [pid 66623:tid 66876] [client 132.196.30.78:19415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/elp.php"] [unique_id "aoSAstO5rbWdOArH04KK4QAAAXg"] [Tue Aug 18 12:56:34.730991 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/qh.php"] [unique_id "aoSAsvcmepr5_nHgLbNYOAAAAjc"] [Tue Aug 18 12:56:34.778303 2026] [security2:error] [pid 66623:tid 66754] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSAstO5rbWdOArH04KK4wABQHU"] [Tue Aug 18 12:56:34.805758 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSAsvcmepr5_nHgLbNYOQAAAjo"] [Tue Aug 18 12:56:34.811950 2026] [security2:error] [pid 66623:tid 66815] [client 20.100.169.31:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/a.php"] [unique_id "aoSAstO5rbWdOArH04KK5AAAATs"] [Tue Aug 18 12:56:34.836449 2026] [autoindex:error] [pid 67073:tid 67265] [client 20.79.204.6:2401] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:34.840935 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.69.59:49315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpstatus.php"] [unique_id "aoSAstO5rbWdOArH04KK5QAAATE"] [Tue Aug 18 12:56:34.888536 2026] [security2:error] [pid 66623:tid 66889] [client 74.248.136.165:18041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wsws.php"] [unique_id "aoSAstO5rbWdOArH04KK5wAAAYU"] [Tue Aug 18 12:56:34.917015 2026] [security2:error] [pid 67073:tid 67257] [client 20.215.241.237:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/system_log.php"] [unique_id "aoSAsvcmepr5_nHgLbNYPgAAAkg"] [Tue Aug 18 12:56:34.917574 2026] [security2:error] [pid 66623:tid 66776] [client 20.171.51.14:15745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/zj.php"] [unique_id "aoSAstO5rbWdOArH04KK6AAAARQ"] [Tue Aug 18 12:56:34.960012 2026] [security2:error] [pid 66623:tid 66726] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/u.php"] [unique_id "aoSAstO5rbWdOArH04KK6gABTFk"] [Tue Aug 18 12:56:34.960954 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:34.961429 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:34.973604 2026] [security2:error] [pid 66623:tid 66780] [client 20.163.43.14:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/files/index.php"] [unique_id "aoSAstO5rbWdOArH04KK6wAAARg"] [Tue Aug 18 12:56:34.989319 2026] [security2:error] [pid 66623:tid 66842] [client 104.209.144.33:29826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAstO5rbWdOArH04KK7AAAAVY"] [Tue Aug 18 12:56:34.991215 2026] [security2:error] [pid 67073:tid 67245] [client 20.151.109.219:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/et.php"] [unique_id "aoSAsvcmepr5_nHgLbNYQwAAAjw"] [Tue Aug 18 12:56:34.991911 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/r.php"] [unique_id "aoSAsvcmepr5_nHgLbNYRAAAAiI"] [Tue Aug 18 12:56:34.998612 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:57653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/file5.php"] [unique_id "aoSAstO5rbWdOArH04KK7QAAATY"] [Tue Aug 18 12:56:35.032160 2026] [security2:error] [pid 66623:tid 66774] [client 20.215.241.237:61843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/img.php"] [unique_id "aoSAs9O5rbWdOArH04KK7gAAARI"] [Tue Aug 18 12:56:35.038702 2026] [security2:error] [pid 67073:tid 67306] [client 20.79.204.6:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRQAAAnk"] [Tue Aug 18 12:56:35.043870 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRgAAAh0"] [Tue Aug 18 12:56:35.044026 2026] [security2:error] [pid 67073:tid 67214] [client 86.120.159.145:55489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRgAAAh0"] [Tue Aug 18 12:56:35.082677 2026] [security2:error] [pid 67073:tid 67316] [client 52.139.47.57:9069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/goat1.php"] [unique_id "aoSAs_cmepr5_nHgLbNYRwAAAoM"] [Tue Aug 18 12:56:35.112916 2026] [security2:error] [pid 67073:tid 67286] [client 172.182.200.96:14120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAs_cmepr5_nHgLbNYSQAAAmU"] [Tue Aug 18 12:56:35.114905 2026] [security2:error] [pid 67073:tid 67328] [client 40.85.222.29:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/nwwha.php"] [unique_id "aoSAs_cmepr5_nHgLbNYSgAAAo8"] [Tue Aug 18 12:56:35.188110 2026] [autoindex:error] [pid 66623:tid 66737] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:35.211451 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.69.59:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/del.php"] [unique_id "aoSAs_cmepr5_nHgLbNYTwAAAls"] [Tue Aug 18 12:56:35.215349 2026] [security2:error] [pid 66623:tid 66788] [client 213.35.127.232:59242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAs9O5rbWdOArH04KK9wAAASA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:35.231625 2026] [security2:error] [pid 66623:tid 66819] [client 20.52.168.85:7794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAs9O5rbWdOArH04KK-QAAAT8"] [Tue Aug 18 12:56:35.265431 2026] [security2:error] [pid 66623:tid 66772] [client 172.202.39.151:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp.php"] [unique_id "aoSAs9O5rbWdOArH04KK-wAAARA"] [Tue Aug 18 12:56:35.277477 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.156.252:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAs_cmepr5_nHgLbNYUgAAApM"] [Tue Aug 18 12:56:35.278106 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/17.php"] [unique_id "aoSAs_cmepr5_nHgLbNYUwAAAjs"] [Tue Aug 18 12:56:35.291621 2026] [security2:error] [pid 66623:tid 66870] [client 172.202.39.151:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/edit.php"] [unique_id "aoSAs9O5rbWdOArH04KK_AAAAXI"] [Tue Aug 18 12:56:35.296080 2026] [security2:error] [pid 67073:tid 67247] [client 103.184.169.37:41931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVAAAAj4"] [Tue Aug 18 12:56:35.296203 2026] [security2:error] [pid 67073:tid 67247] [client 103.184.169.37:41931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVAAAAj4"] [Tue Aug 18 12:56:35.316699 2026] [security2:error] [pid 67073:tid 67324] [client 158.23.17.4:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/456.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVQAAAos"] [Tue Aug 18 12:56:35.320654 2026] [security2:error] [pid 66623:tid 66803] [client 158.158.74.177:26169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/s93.php"] [unique_id "aoSAs9O5rbWdOArH04KK_QAAAS8"] [Tue Aug 18 12:56:35.330745 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVgAAAj0"] [Tue Aug 18 12:56:35.346140 2026] [security2:error] [pid 67073:tid 67283] [client 20.151.109.219:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/of.php"] [unique_id "aoSAs_cmepr5_nHgLbNYVwAAAmI"] [Tue Aug 18 12:56:35.357208 2026] [security2:error] [pid 66623:tid 66692] [remote 185.118.190.176:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guinchomarquette.com.br"] [uri "/wp-login.php"] [unique_id "aoSAs9O5rbWdOArH04KK_wABVTc"] [Tue Aug 18 12:56:35.365964 2026] [security2:error] [pid 66623:tid 66707] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/customize.php"] [unique_id "aoSAs9O5rbWdOArH04KLAAABX0Y"] [Tue Aug 18 12:56:35.408386 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/opsqt.php"] [unique_id "aoSAs_cmepr5_nHgLbNYWgAAAmg"] [Tue Aug 18 12:56:35.417422 2026] [security2:error] [pid 67073:tid 67221] [client 132.196.30.78:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAs_cmepr5_nHgLbNYWwAAAiQ"] [Tue Aug 18 12:56:35.447642 2026] [security2:error] [pid 67073:tid 67232] [client 20.171.51.14:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/x.php"] [unique_id "aoSAs_cmepr5_nHgLbNYXAAAAi8"] [Tue Aug 18 12:56:35.550658 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ev.php"] [unique_id "aoSAs_cmepr5_nHgLbNYYgAAAoE"] [Tue Aug 18 12:56:35.561870 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:35.562294 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:35.617756 2026] [security2:error] [pid 67073:tid 67230] [client 135.225.75.187:27258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ccou.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZQAAAi0"] [Tue Aug 18 12:56:35.631787 2026] [security2:error] [pid 67073:tid 67231] [client 52.139.47.57:18368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZgAAAi4"] [Tue Aug 18 12:56:35.638666 2026] [security2:error] [pid 67073:tid 67281] [client 20.116.17.175:57421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yup.php"] [unique_id "aoSAs_cmepr5_nHgLbNYZwAAAmA"] [Tue Aug 18 12:56:35.646255 2026] [security2:error] [pid 67073:tid 67280] [client 20.79.204.6:2658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSAs_cmepr5_nHgLbNYaAAAAl8"] [Tue Aug 18 12:56:35.672027 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:19943] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.noise2.com.br"] [uri "/1.php"] [unique_id "aoSAs9O5rbWdOArH04KLBgAAASs"] [Tue Aug 18 12:56:35.672150 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:19943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/1.php"] [unique_id "aoSAs9O5rbWdOArH04KLBgAAASs"] [Tue Aug 18 12:56:35.672552 2026] [security2:error] [pid 66623:tid 66828] [client 20.163.43.14:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAs9O5rbWdOArH04KLBwAAAUg"] [Tue Aug 18 12:56:35.673575 2026] [security2:error] [pid 66623:tid 66768] [client 52.173.121.69:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAs9O5rbWdOArH04KLCAAAAQw"] [Tue Aug 18 12:56:35.689913 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bu.php"] [unique_id "aoSAs_cmepr5_nHgLbNYagAAAo4"] [Tue Aug 18 12:56:35.723544 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/jvcpa.php"] [unique_id "aoSAs_cmepr5_nHgLbNYawAAAjk"] [Tue Aug 18 12:56:35.790611 2026] [autoindex:error] [pid 67073:tid 67234] [client 172.202.39.151:65254] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:35.807533 2026] [security2:error] [pid 67073:tid 67240] [client 132.196.61.152:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/m.php"] [unique_id "aoSAs_cmepr5_nHgLbNYbgAAAjc"] [Tue Aug 18 12:56:35.820017 2026] [security2:error] [pid 66623:tid 66800] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xs.php"] [unique_id "aoSAs9O5rbWdOArH04KLDQAAASw"] [Tue Aug 18 12:56:35.836399 2026] [security2:error] [pid 67073:tid 67241] [client 20.52.168.85:7856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/css/index.php"] [unique_id "aoSAs_cmepr5_nHgLbNYbwAAAjg"] [Tue Aug 18 12:56:35.836760 2026] [security2:error] [pid 66623:tid 66659] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/mah/function.php"] [unique_id "aoSAs9O5rbWdOArH04KLDwABWxY"] [Tue Aug 18 12:56:35.858522 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:35.858792 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:35.870063 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/nox.php"] [unique_id "aoSAs_cmepr5_nHgLbNYdQAAAj8"] [Tue Aug 18 12:56:35.956568 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.69.59:3725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/moderator.php"] [unique_id "aoSAs_cmepr5_nHgLbNYeQAAAlg"] [Tue Aug 18 12:56:35.971376 2026] [security2:error] [pid 67073:tid 67331] [client 158.23.17.4:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/SMTP.php"] [unique_id "aoSAs_cmepr5_nHgLbNYegAAApI"] [Tue Aug 18 12:56:35.979763 2026] [security2:error] [pid 67073:tid 67268] [client 20.171.51.14:43355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yn.php"] [unique_id "aoSAs_cmepr5_nHgLbNYewAAAlM"] [Tue Aug 18 12:56:35.999231 2026] [security2:error] [pid 66623:tid 66798] [client 40.85.222.29:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSAs9O5rbWdOArH04KLEgAAASo"] [Tue Aug 18 12:56:36.001629 2026] [security2:error] [pid 66623:tid 66868] [client 20.151.109.219:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rn.php"] [unique_id "aoSAtNO5rbWdOArH04KLEwAAAXA"] [Tue Aug 18 12:56:36.002838 2026] [security2:error] [pid 67073:tid 67245] [client 172.182.200.96:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAtPcmepr5_nHgLbNYfAAAAjw"] [Tue Aug 18 12:56:36.007964 2026] [security2:error] [pid 67073:tid 67329] [client 20.163.43.14:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAtPcmepr5_nHgLbNYfQAAApA"] [Tue Aug 18 12:56:36.008187 2026] [security2:error] [pid 66623:tid 66688] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/filter.php"] [unique_id "aoSAtNO5rbWdOArH04KLFAABQzM"] [Tue Aug 18 12:56:36.096411 2026] [security2:error] [pid 66623:tid 66771] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/lmfi2.php"] [unique_id "aoSAtNO5rbWdOArH04KLGAAAAQ8"] [Tue Aug 18 12:56:36.173260 2026] [security2:error] [pid 67073:tid 67225] [client 20.116.17.175:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAtPcmepr5_nHgLbNYhwAAAig"] [Tue Aug 18 12:56:36.179316 2026] [security2:error] [pid 66623:tid 66747] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/input.php"] [unique_id "aoSAtNO5rbWdOArH04KLGgABa24"] [Tue Aug 18 12:56:36.220586 2026] [security2:error] [pid 67073:tid 67229] [client 172.202.39.151:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSAtPcmepr5_nHgLbNYiQAAAiw"] [Tue Aug 18 12:56:36.231505 2026] [security2:error] [pid 66623:tid 66859] [client 213.35.127.232:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAtNO5rbWdOArH04KLGwAAAWc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:36.252293 2026] [autoindex:error] [pid 67073:tid 67296] [client 172.202.39.151:42152] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:36.254073 2026] [security2:error] [pid 66623:tid 66857] [client 20.79.204.6:2638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSAtNO5rbWdOArH04KLHQAAAWU"] [Tue Aug 18 12:56:36.258539 2026] [security2:error] [pid 66623:tid 66893] [client 52.139.47.57:16703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/h.php"] [unique_id "aoSAtNO5rbWdOArH04KLHgAAAYk"] [Tue Aug 18 12:56:36.278959 2026] [security2:error] [pid 67073:tid 67300] [client 20.151.109.219:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ut.php"] [unique_id "aoSAtPcmepr5_nHgLbNYigAAAnM"] [Tue Aug 18 12:56:36.294531 2026] [security2:error] [pid 67073:tid 67311] [client 40.85.222.29:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSAtPcmepr5_nHgLbNYiwAAAn4"] [Tue Aug 18 12:56:36.345503 2026] [security2:error] [pid 66623:tid 66769] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fd.php"] [unique_id "aoSAtNO5rbWdOArH04KLIQAAAQ0"] [Tue Aug 18 12:56:36.370497 2026] [security2:error] [pid 67073:tid 67246] [client 20.163.43.14:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/rip.php"] [unique_id "aoSAtPcmepr5_nHgLbNYjgAAAj0"] [Tue Aug 18 12:56:36.392791 2026] [security2:error] [pid 67073:tid 67294] [client 74.248.136.165:28114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/motu.php"] [unique_id "aoSAtPcmepr5_nHgLbNYjwAAAm0"] [Tue Aug 18 12:56:36.460108 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:36.460382 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:36.465713 2026] [security2:error] [pid 66623:tid 66783] [client 20.171.51.14:29197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/11.php"] [unique_id "aoSAtNO5rbWdOArH04KLJQAAARs"] [Tue Aug 18 12:56:36.466767 2026] [authz_core:error] [pid 67073:tid 67170] [remote 57.141.22.27:43316] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:36.467024 2026] [authz_core:error] [pid 67073:tid 67170] [remote 57.141.22.27:43316] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:36.504910 2026] [security2:error] [pid 66623:tid 66873] [client 20.215.241.237:46439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/pucci.php"] [unique_id "aoSAtNO5rbWdOArH04KLJgAAAXU"] [Tue Aug 18 12:56:36.550476 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/vbseo.php"] [unique_id "aoSAtPcmepr5_nHgLbNYmQAAAhg"] [Tue Aug 18 12:56:36.576187 2026] [autoindex:error] [pid 67073:tid 67259] [client 172.202.39.151:42152] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:36.588377 2026] [security2:error] [pid 67073:tid 67295] [client 40.85.222.29:12608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSAtPcmepr5_nHgLbNYmwAAAm4"] [Tue Aug 18 12:56:36.605329 2026] [security2:error] [pid 67073:tid 67251] [client 20.151.109.219:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/eh.php"] [unique_id "aoSAtPcmepr5_nHgLbNYnAAAAkI"] [Tue Aug 18 12:56:36.617458 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/info2.php"] [unique_id "aoSAtPcmepr5_nHgLbNYnQAAAng"] [Tue Aug 18 12:56:36.641884 2026] [security2:error] [pid 67073:tid 67216] [client 135.225.75.187:24670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/txets.php"] [unique_id "aoSAtPcmepr5_nHgLbNYngAAAh8"] [Tue Aug 18 12:56:36.645586 2026] [security2:error] [pid 66623:tid 66789] [client 20.52.168.85:7857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/mini.php"] [unique_id "aoSAtNO5rbWdOArH04KLKQAAASE"] [Tue Aug 18 12:56:36.674563 2026] [security2:error] [pid 67073:tid 67221] [client 74.7.244.23:52166] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "batlub.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAtPcmepr5_nHgLbNYoQACJEU"] [Tue Aug 18 12:56:36.686259 2026] [security2:error] [pid 67073:tid 67174] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/jquery.php"] [unique_id "aoSAtPcmepr5_nHgLbNYogACZmI"] [Tue Aug 18 12:56:36.696543 2026] [security2:error] [pid 67073:tid 67232] [client 52.139.47.57:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/import/csv1.php"] [unique_id "aoSAtPcmepr5_nHgLbNYowAAAi8"] [Tue Aug 18 12:56:36.715532 2026] [security2:error] [pid 67073:tid 67207] [client 172.202.39.151:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/tes.php"] [unique_id "aoSAtPcmepr5_nHgLbNYpAAAAhY"] [Tue Aug 18 12:56:36.825618 2026] [security2:error] [pid 67073:tid 67290] [client 79.127.164.8:33036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/main.bak"] [unique_id "aoSAtPcmepr5_nHgLbNYpwAAAmk"], referer: https://medihub.com.br/main.bak [Tue Aug 18 12:56:36.858357 2026] [security2:error] [pid 67073:tid 67228] [client 20.116.17.175:11259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-the.php"] [unique_id "aoSAtPcmepr5_nHgLbNYqQAAAis"] [Tue Aug 18 12:56:36.864759 2026] [security2:error] [pid 67073:tid 67330] [client 20.65.69.59:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/infoinfo.php"] [unique_id "aoSAtPcmepr5_nHgLbNYqgAAApE"] [Tue Aug 18 12:56:36.888147 2026] [security2:error] [pid 66623:tid 66790] [client 40.85.222.29:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSAtNO5rbWdOArH04KLLwAAASI"] [Tue Aug 18 12:56:36.888284 2026] [security2:error] [pid 67073:tid 67195] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/media-new.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrQACKXc"] [Tue Aug 18 12:56:36.901120 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:16547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/server.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrgAAApM"] [Tue Aug 18 12:56:36.901179 2026] [autoindex:error] [pid 67073:tid 67264] [client 20.79.204.6:2404] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:36.902508 2026] [security2:error] [pid 67073:tid 67279] [client 20.163.43.14:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtPcmepr5_nHgLbNYrwAAAl4"] [Tue Aug 18 12:56:36.903135 2026] [security2:error] [pid 67073:tid 67240] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sx.php"] [unique_id "aoSAtPcmepr5_nHgLbNYsAAAAjc"] [Tue Aug 18 12:56:36.971070 2026] [authz_core:error] [pid 67073:tid 67094] [remote 57.141.22.96:55994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:36.971351 2026] [authz_core:error] [pid 67073:tid 67094] [remote 57.141.22.96:55994] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:36.977280 2026] [security2:error] [pid 66623:tid 66817] [client 20.151.109.219:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ad.php"] [unique_id "aoSAtNO5rbWdOArH04KLMQAAAT0"] [Tue Aug 18 12:56:36.981260 2026] [security2:error] [pid 66623:tid 66874] [client 20.171.51.14:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vm.php"] [unique_id "aoSAtNO5rbWdOArH04KLMgAAAXY"] [Tue Aug 18 12:56:36.993563 2026] [security2:error] [pid 67073:tid 67322] [client 68.155.156.252:2275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/media.php"] [unique_id "aoSAtPcmepr5_nHgLbNYswAAAok"] [Tue Aug 18 12:56:36.994522 2026] [security2:error] [pid 66623:tid 66794] [client 172.202.39.151:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/function/function.php"] [unique_id "aoSAtNO5rbWdOArH04KLMwAAASY"] [Tue Aug 18 12:56:37.052998 2026] [security2:error] [pid 67073:tid 67212] [client 49.13.134.145:63768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alcorseguros.com.br"] [uri "/index.php"] [unique_id "aoSAtPcmepr5_nHgLbNYhQAAAhs"], referer: https://www.alcorseguros.com.br [Tue Aug 18 12:56:37.062954 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:37.063215 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:37.063844 2026] [security2:error] [pid 67073:tid 67087] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvAACfQs"] [Tue Aug 18 12:56:37.101491 2026] [security2:error] [pid 67073:tid 67331] [client 20.79.204.6:2404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-themes.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvQAAApI"] [Tue Aug 18 12:56:37.106487 2026] [security2:error] [pid 66623:tid 66812] [client 132.196.30.78:18631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/666.php"] [unique_id "aoSAtdO5rbWdOArH04KLNQAAATg"] [Tue Aug 18 12:56:37.158263 2026] [security2:error] [pid 67073:tid 67208] [client 20.100.169.31:38879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/chosen.php"] [unique_id "aoSAtfcmepr5_nHgLbNYvwAAAhc"] [Tue Aug 18 12:56:37.159600 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nu.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwAAAAmU"] [Tue Aug 18 12:56:37.168581 2026] [security2:error] [pid 67073:tid 67308] [client 5.31.227.224:30431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwQAAAns"] [Tue Aug 18 12:56:37.168664 2026] [security2:error] [pid 67073:tid 67308] [client 5.31.227.224:30431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwQAAAns"] [Tue Aug 18 12:56:37.172809 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwgAAAl0"] [Tue Aug 18 12:56:37.193614 2026] [security2:error] [pid 67073:tid 67222] [client 20.215.241.237:38843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/bajah.php"] [unique_id "aoSAtfcmepr5_nHgLbNYwwAAAiU"] [Tue Aug 18 12:56:37.198917 2026] [security2:error] [pid 67073:tid 67328] [client 172.182.200.96:14173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/rezor.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxAAAAo8"] [Tue Aug 18 12:56:37.239129 2026] [security2:error] [pid 67073:tid 67078] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxgACKAI"] [Tue Aug 18 12:56:37.239162 2026] [security2:error] [pid 67073:tid 67309] [client 20.163.43.14:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/moon.php"] [unique_id "aoSAtfcmepr5_nHgLbNYxwAAAnw"] [Tue Aug 18 12:56:37.246143 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAtdO5rbWdOArH04KLOQAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:37.255554 2026] [security2:error] [pid 67073:tid 67272] [client 20.52.168.85:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAtfcmepr5_nHgLbNYyAAAAlc"] [Tue Aug 18 12:56:37.256453 2026] [security2:error] [pid 67073:tid 67265] [client 172.202.39.151:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-good.php"] [unique_id "aoSAtfcmepr5_nHgLbNYyQAAAlA"] [Tue Aug 18 12:56:37.282019 2026] [security2:error] [pid 67073:tid 67306] [client 52.139.47.57:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/index.bak.php"] [unique_id "aoSAtfcmepr5_nHgLbNYygAAAnk"] [Tue Aug 18 12:56:37.320023 2026] [security2:error] [pid 67073:tid 67318] [client 20.151.109.219:12897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/vd.php"] [unique_id "aoSAtfcmepr5_nHgLbNYywAAAoU"] [Tue Aug 18 12:56:37.361079 2026] [authz_core:error] [pid 67073:tid 67161] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:37.361340 2026] [authz_core:error] [pid 67073:tid 67161] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:37.372159 2026] [security2:error] [pid 67073:tid 67283] [client 132.196.61.152:34771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/33.php"] [unique_id "aoSAtfcmepr5_nHgLbNYzwAAAmI"] [Tue Aug 18 12:56:37.415885 2026] [security2:error] [pid 67073:tid 67083] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0QACVQc"] [Tue Aug 18 12:56:37.424302 2026] [security2:error] [pid 67073:tid 67210] [client 37.40.227.74:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0gAAAhk"] [Tue Aug 18 12:56:37.428637 2026] [security2:error] [pid 67073:tid 67210] [client 37.40.227.74:56818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0gAAAhk"] [Tue Aug 18 12:56:37.439114 2026] [security2:error] [pid 67073:tid 67295] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ko.php"] [unique_id "aoSAtfcmepr5_nHgLbNY0wAAAm4"] [Tue Aug 18 12:56:37.450103 2026] [security2:error] [pid 66623:tid 66876] [client 40.85.222.29:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSAtdO5rbWdOArH04KLPQAAAXg"] [Tue Aug 18 12:56:37.455303 2026] [security2:error] [pid 66623:tid 66820] [client 20.65.98.162:42893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/1xmomo.php"] [unique_id "aoSAtdO5rbWdOArH04KLPgAAAUA"] [Tue Aug 18 12:56:37.554420 2026] [security2:error] [pid 67073:tid 67207] [client 52.173.121.69:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2QAAAhY"] [Tue Aug 18 12:56:37.574252 2026] [security2:error] [pid 67073:tid 67230] [client 20.215.241.237:7275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-temp.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2gAAAi0"] [Tue Aug 18 12:56:37.590951 2026] [security2:error] [pid 67073:tid 67184] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSAtfcmepr5_nHgLbNY2wACLmw"] [Tue Aug 18 12:56:37.595353 2026] [security2:error] [pid 67073:tid 67281] [client 135.225.75.187:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fun.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3AAAAmA"] [Tue Aug 18 12:56:37.598286 2026] [security2:error] [pid 66623:tid 66889] [client 20.171.51.14:45435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eg.php"] [unique_id "aoSAtdO5rbWdOArH04KLQAAAAYU"] [Tue Aug 18 12:56:37.628168 2026] [security2:error] [pid 67073:tid 67280] [client 20.163.43.14:4218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/cache.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3QAAAl8"] [Tue Aug 18 12:56:37.638485 2026] [security2:error] [pid 67073:tid 67290] [client 158.23.17.4:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sysinfo.php"] [unique_id "aoSAtfcmepr5_nHgLbNY3gAAAmk"] [Tue Aug 18 12:56:37.684384 2026] [security2:error] [pid 67073:tid 67327] [client 20.151.109.219:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/56.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4AAAAo4"] [Tue Aug 18 12:56:37.695521 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/pl.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4QAAAis"] [Tue Aug 18 12:56:37.735200 2026] [security2:error] [pid 66623:tid 66780] [client 40.85.222.29:12621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSAtdO5rbWdOArH04KLRAAAARg"] [Tue Aug 18 12:56:37.745647 2026] [security2:error] [pid 67073:tid 67130] [remote 110.249.202.88:44466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/"] [unique_id "aoSAtfcmepr5_nHgLbNY4gACKjY"] [Tue Aug 18 12:56:37.758700 2026] [security2:error] [pid 67073:tid 67274] [client 20.79.204.6:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY4wAAAlk"] [Tue Aug 18 12:56:37.765042 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.136.165:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fff.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5QAAAjc"] [Tue Aug 18 12:56:37.765236 2026] [security2:error] [pid 67073:tid 67313] [client 192.141.172.134:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5gAAAoA"] [Tue Aug 18 12:56:37.765351 2026] [security2:error] [pid 67073:tid 67313] [client 192.141.172.134:61213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY5gAAAoA"] [Tue Aug 18 12:56:37.766327 2026] [security2:error] [pid 67073:tid 67128] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/ebs.php7"] [unique_id "aoSAtfcmepr5_nHgLbNY5wACUTQ"] [Tue Aug 18 12:56:37.787690 2026] [security2:error] [pid 67073:tid 67307] [client 20.206.73.37:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAtfcmepr5_nHgLbNY6AAAAno"] [Tue Aug 18 12:56:37.812071 2026] [autoindex:error] [pid 67073:tid 67279] [client 172.202.39.151:50239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:37.842235 2026] [security2:error] [pid 67073:tid 67330] [client 52.139.47.57:11772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/lite.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7QAAApE"] [Tue Aug 18 12:56:37.857852 2026] [security2:error] [pid 67073:tid 67321] [client 20.52.168.85:7759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/classwithtostring.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7gAAAog"] [Tue Aug 18 12:56:37.899907 2026] [security2:error] [pid 67073:tid 67268] [client 157.20.138.62:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7wAAAlM"] [Tue Aug 18 12:56:37.900059 2026] [security2:error] [pid 67073:tid 67268] [client 157.20.138.62:61650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtfcmepr5_nHgLbNY7wAAAlM"] [Tue Aug 18 12:56:37.924825 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSAtdO5rbWdOArH04KLSQAAAW4"] [Tue Aug 18 12:56:37.940695 2026] [security2:error] [pid 67073:tid 67168] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSAtfcmepr5_nHgLbNY8QACkFw"] [Tue Aug 18 12:56:37.949737 2026] [security2:error] [pid 67073:tid 67282] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/env.php"] [unique_id "aoSAtfcmepr5_nHgLbNY8gAAAmE"] [Tue Aug 18 12:56:37.969118 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:37.969577 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:38.000237 2026] [security2:error] [pid 66623:tid 66766] [client 132.196.30.78:21850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ws54.php"] [unique_id "aoSAtdO5rbWdOArH04KLTAAAAQo"] [Tue Aug 18 12:56:38.023984 2026] [security2:error] [pid 67073:tid 67249] [client 20.151.109.219:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/rx.php"] [unique_id "aoSAtvcmepr5_nHgLbNY-QAAAkA"] [Tue Aug 18 12:56:38.043071 2026] [security2:error] [pid 67073:tid 67222] [client 40.85.222.29:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_QAAAiU"] [Tue Aug 18 12:56:38.078583 2026] [security2:error] [pid 67073:tid 67309] [client 20.186.30.159:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/akismet.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_gAAAnw"] [Tue Aug 18 12:56:38.099804 2026] [security2:error] [pid 66623:tid 66822] [client 20.215.241.237:54509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAttO5rbWdOArH04KLTgAAAUI"] [Tue Aug 18 12:56:38.104666 2026] [security2:error] [pid 66623:tid 66773] [client 20.171.51.14:30913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/uk.php"] [unique_id "aoSAttO5rbWdOArH04KLTwAAARE"] [Tue Aug 18 12:56:38.115117 2026] [security2:error] [pid 67073:tid 67076] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSAtvcmepr5_nHgLbNY_wACIwA"] [Tue Aug 18 12:56:38.148978 2026] [security2:error] [pid 67073:tid 67229] [client 104.209.144.33:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAtvcmepr5_nHgLbNZAgAAAiw"] [Tue Aug 18 12:56:38.172015 2026] [security2:error] [pid 67073:tid 67296] [client 20.65.69.59:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/c99shell.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBAAAAm8"] [Tue Aug 18 12:56:38.211766 2026] [autoindex:error] [pid 67073:tid 67265] [client 172.202.39.151:50239] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:38.212021 2026] [security2:error] [pid 67073:tid 67311] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mz.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBgAAAn4"] [Tue Aug 18 12:56:38.239121 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.34.183:35103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSAtvcmepr5_nHgLbNZBwAAAmQ"] [Tue Aug 18 12:56:38.242714 2026] [security2:error] [pid 67073:tid 67246] [client 68.155.154.236:16241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCAAAAj0"] [Tue Aug 18 12:56:38.251183 2026] [security2:error] [pid 66623:tid 66819] [client 135.225.75.187:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/jq.php"] [unique_id "aoSAttO5rbWdOArH04KLVAAAAT8"] [Tue Aug 18 12:56:38.261367 2026] [security2:error] [pid 67073:tid 67299] [client 213.35.127.232:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCgAAAnI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:38.290246 2026] [security2:error] [pid 67073:tid 67096] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/lite.php"] [unique_id "aoSAtvcmepr5_nHgLbNZCwACbRQ"] [Tue Aug 18 12:56:38.321628 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDAAAAjQ"] [Tue Aug 18 12:56:38.335489 2026] [security2:error] [pid 66623:tid 66806] [client 20.151.109.219:53185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mandrill.php"] [unique_id "aoSAttO5rbWdOArH04KLVgAAATI"] [Tue Aug 18 12:56:38.335939 2026] [security2:error] [pid 66623:tid 66782] [client 52.139.47.57:18392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/live.php"] [unique_id "aoSAttO5rbWdOArH04KLVwAAARo"] [Tue Aug 18 12:56:38.350814 2026] [security2:error] [pid 67073:tid 67310] [client 149.34.210.141:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDQAAAn0"] [Tue Aug 18 12:56:38.414166 2026] [security2:error] [pid 67073:tid 67319] [client 158.23.17.4:38860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ppinfo.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDwAAAoY"] [Tue Aug 18 12:56:38.421125 2026] [security2:error] [pid 67073:tid 67209] [client 172.202.39.151:50239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/tes.php"] [unique_id "aoSAtvcmepr5_nHgLbNZEAAAAhg"] [Tue Aug 18 12:56:38.459943 2026] [security2:error] [pid 66623:tid 66772] [client 20.52.168.85:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/404.php"] [unique_id "aoSAttO5rbWdOArH04KLXAAAARA"] [Tue Aug 18 12:56:38.464071 2026] [security2:error] [pid 67073:tid 67107] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSAtvcmepr5_nHgLbNZEQACVB8"] [Tue Aug 18 12:56:38.470457 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/settings.php"] [unique_id "aoSAttO5rbWdOArH04KLXQAAASA"] [Tue Aug 18 12:56:38.519043 2026] [security2:error] [pid 66623:tid 66885] [client 20.163.43.14:4286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAttO5rbWdOArH04KLXwAAAYE"] [Tue Aug 18 12:56:38.570588 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:38.570847 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:38.577865 2026] [security2:error] [pid 67073:tid 67292] [client 20.116.17.175:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/xwpg.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFAAAAms"] [Tue Aug 18 12:56:38.602856 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFQAAAmg"] [Tue Aug 18 12:56:38.620781 2026] [security2:error] [pid 67073:tid 67221] [client 132.196.61.152:60306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.61.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cattaniportoes.com.br"] [uri "/packed.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFgAAAiQ"] [Tue Aug 18 12:56:38.622706 2026] [security2:error] [pid 67073:tid 67310] [client 149.34.210.141:54231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZDQAAAn0"] [Tue Aug 18 12:56:38.637739 2026] [security2:error] [pid 67073:tid 67117] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSAtvcmepr5_nHgLbNZFwACZik"] [Tue Aug 18 12:56:38.656994 2026] [security2:error] [pid 66623:tid 66784] [client 20.151.109.219:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/main.php"] [unique_id "aoSAttO5rbWdOArH04KLZAAAARw"] [Tue Aug 18 12:56:38.664162 2026] [security2:error] [pid 66623:tid 66855] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ft.php"] [unique_id "aoSAttO5rbWdOArH04KLZQAAAWM"] [Tue Aug 18 12:56:38.676502 2026] [security2:error] [pid 67073:tid 67244] [client 20.171.51.14:29234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/creds.php"] [unique_id "aoSAtvcmepr5_nHgLbNZGQAAAjs"] [Tue Aug 18 12:56:38.685543 2026] [security2:error] [pid 66623:tid 66799] [client 20.215.241.237:40503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/puc.php"] [unique_id "aoSAttO5rbWdOArH04KLZgAAASs"] [Tue Aug 18 12:56:38.813972 2026] [security2:error] [pid 67073:tid 67180] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSAtvcmepr5_nHgLbNZGwACgmg"] [Tue Aug 18 12:56:38.847540 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:48608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/alfa.php"] [unique_id "aoSAttO5rbWdOArH04KLagAAATQ"] [Tue Aug 18 12:56:38.870984 2026] [authz_core:error] [pid 66623:tid 66758] [remote 57.141.22.2:60410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:38.871438 2026] [authz_core:error] [pid 66623:tid 66758] [remote 57.141.22.2:60410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:38.900133 2026] [security2:error] [pid 66623:tid 66843] [client 172.202.39.151:65230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/files/index.php"] [unique_id "aoSAttO5rbWdOArH04KLbgAAAVc"] [Tue Aug 18 12:56:38.912527 2026] [security2:error] [pid 67073:tid 67254] [client 40.85.222.29:12632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSAtvcmepr5_nHgLbNZIgAAAkU"] [Tue Aug 18 12:56:38.921924 2026] [security2:error] [pid 67073:tid 67327] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/h.php"] [unique_id "aoSAtvcmepr5_nHgLbNZIwAAAo4"] [Tue Aug 18 12:56:38.974841 2026] [security2:error] [pid 67073:tid 67291] [client 132.196.30.78:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAtvcmepr5_nHgLbNZJQAAAmo"] [Tue Aug 18 12:56:38.990053 2026] [security2:error] [pid 67073:tid 67101] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZJwACKRk"] [Tue Aug 18 12:56:39.026537 2026] [security2:error] [pid 67073:tid 67332] [client 20.151.109.219:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ga.php"] [unique_id "aoSAt_cmepr5_nHgLbNZKAAAApM"] [Tue Aug 18 12:56:39.046689 2026] [security2:error] [pid 66623:tid 66770] [client 74.7.175.183:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSAtNO5rbWdOArH04KLKwABDhM"] [Tue Aug 18 12:56:39.065208 2026] [security2:error] [pid 66623:tid 66856] [client 20.52.168.85:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/shell.php"] [unique_id "aoSAt9O5rbWdOArH04KLcwAAAWQ"] [Tue Aug 18 12:56:39.068326 2026] [security2:error] [pid 67073:tid 67325] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAtvcmepr5_nHgLbNZHgACjAk"] [Tue Aug 18 12:56:39.075443 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.136.165:22494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/66.php"] [unique_id "aoSAt_cmepr5_nHgLbNZMAAAAic"] [Tue Aug 18 12:56:39.085408 2026] [security2:error] [pid 66623:tid 66872] [client 20.163.43.14:4223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAt9O5rbWdOArH04KLdQAAAXQ"] [Tue Aug 18 12:56:39.103619 2026] [security2:error] [pid 67073:tid 67301] [client 158.23.17.4:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/globals.php"] [unique_id "aoSAt_cmepr5_nHgLbNZMwAAAnQ"] [Tue Aug 18 12:56:39.106257 2026] [security2:error] [pid 67073:tid 67218] [client 68.155.156.252:35701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/admin.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNAAAAiE"] [Tue Aug 18 12:56:39.161913 2026] [security2:error] [pid 67073:tid 67250] [client 52.139.47.57:25683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/bypass.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNQAAAkE"] [Tue Aug 18 12:56:39.165985 2026] [security2:error] [pid 67073:tid 67188] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSAt_cmepr5_nHgLbNZNwACTXA"] [Tue Aug 18 12:56:39.172517 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:39.172971 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:39.185135 2026] [security2:error] [pid 66623:tid 66826] [client 20.116.17.175:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/dex.php"] [unique_id "aoSAt9O5rbWdOArH04KLeAAAAUY"] [Tue Aug 18 12:56:39.186220 2026] [security2:error] [pid 66623:tid 66859] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/40.php"] [unique_id "aoSAt9O5rbWdOArH04KLeQAAAWc"] [Tue Aug 18 12:56:39.199566 2026] [security2:error] [pid 66623:tid 66893] [client 40.85.222.29:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSAt9O5rbWdOArH04KLegAAAYk"] [Tue Aug 18 12:56:39.271921 2026] [security2:error] [pid 67073:tid 67242] [client 213.35.127.232:60099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAt_cmepr5_nHgLbNZOQAAAjk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:39.336175 2026] [security2:error] [pid 66623:tid 66760] [remote 47.89.174.181:63882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dealencastroconyvidal.com.br"] [uri "/.env"] [unique_id "aoSAt9O5rbWdOArH04KLfQABF3s"] [Tue Aug 18 12:56:39.365160 2026] [security2:error] [pid 66623:tid 66783] [client 20.151.109.219:24848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/wb.php"] [unique_id "aoSAt9O5rbWdOArH04KLfwAAARs"] [Tue Aug 18 12:56:39.382328 2026] [security2:error] [pid 66623:tid 66873] [client 172.202.39.151:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAt9O5rbWdOArH04KLgAAAAXU"] [Tue Aug 18 12:56:39.392697 2026] [autoindex:error] [pid 67073:tid 67139] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:39.397053 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:25010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPAAAAmU"] [Tue Aug 18 12:56:39.416936 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:3667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/profiler.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPgAAAiU"] [Tue Aug 18 12:56:39.422515 2026] [security2:error] [pid 67073:tid 67219] [client 20.215.241.237:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/8.php"] [unique_id "aoSAt_cmepr5_nHgLbNZPwAAAiI"] [Tue Aug 18 12:56:39.443739 2026] [security2:error] [pid 67073:tid 67303] [client 20.171.51.14:29235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ho.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQAAAAnY"] [Tue Aug 18 12:56:39.446919 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ee.php"] [unique_id "aoSAt9O5rbWdOArH04KLggAAAS0"] [Tue Aug 18 12:56:39.449399 2026] [security2:error] [pid 67073:tid 67328] [client 20.163.43.14:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/o.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQQAAAo8"] [Tue Aug 18 12:56:39.450293 2026] [security2:error] [pid 66623:tid 66818] [client 20.215.241.237:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSAt9O5rbWdOArH04KLgwAAAT4"] [Tue Aug 18 12:56:39.452925 2026] [security2:error] [pid 66623:tid 66767] [client 178.153.171.161:11914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAt9O5rbWdOArH04KLhAAAAQs"] [Tue Aug 18 12:56:39.453015 2026] [security2:error] [pid 66623:tid 66767] [client 178.153.171.161:11914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAt9O5rbWdOArH04KLhAAAAQs"] [Tue Aug 18 12:56:39.471642 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:39.471916 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:39.477356 2026] [security2:error] [pid 66623:tid 66789] [client 40.85.222.29:13288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSAt9O5rbWdOArH04KLhQAAASE"] [Tue Aug 18 12:56:39.561992 2026] [security2:error] [pid 67073:tid 67211] [client 132.196.30.78:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/function/function.php"] [unique_id "aoSAt_cmepr5_nHgLbNZQwAAAho"] [Tue Aug 18 12:56:39.563632 2026] [security2:error] [pid 67073:tid 67272] [client 135.225.75.187:19089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sys.php"] [unique_id "aoSAt_cmepr5_nHgLbNZRAAAAlc"] [Tue Aug 18 12:56:39.571920 2026] [security2:error] [pid 67073:tid 67163] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/ku.php"] [unique_id "aoSAt_cmepr5_nHgLbNZRQACeVc"] [Tue Aug 18 12:56:39.720705 2026] [security2:error] [pid 66623:tid 66785] [client 20.151.109.219:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/xn.php"] [unique_id "aoSAt9O5rbWdOArH04KLiwAAAR0"] [Tue Aug 18 12:56:39.724512 2026] [security2:error] [pid 66623:tid 66892] [client 158.158.74.177:16539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sf.php"] [unique_id "aoSAt9O5rbWdOArH04KLjAAAAYg"] [Tue Aug 18 12:56:39.724850 2026] [security2:error] [pid 66623:tid 66812] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ak.php"] [unique_id "aoSAt9O5rbWdOArH04KLjQAAATg"] [Tue Aug 18 12:56:39.755391 2026] [security2:error] [pid 66623:tid 66807] [client 20.116.17.175:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/xyn.php"] [unique_id "aoSAt9O5rbWdOArH04KLjgAAATM"] [Tue Aug 18 12:56:39.774414 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:39.774884 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:39.793030 2026] [security2:error] [pid 67073:tid 67210] [client 20.163.43.14:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/bb.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUQAAAhk"] [Tue Aug 18 12:56:39.801710 2026] [autoindex:error] [pid 67073:tid 67176] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/jgbdominio/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:39.818660 2026] [security2:error] [pid 67073:tid 67261] [client 40.85.222.29:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUgAAAkw"] [Tue Aug 18 12:56:39.819201 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/php.php"] [unique_id "aoSAt_cmepr5_nHgLbNZUwAAAmA"] [Tue Aug 18 12:56:39.856339 2026] [security2:error] [pid 67073:tid 67209] [client 158.23.17.4:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/yindu.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVQAAAhg"] [Tue Aug 18 12:56:39.887048 2026] [security2:error] [pid 67073:tid 67260] [client 20.215.241.237:44765] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.borestebombordo.com.br"] [uri "/1.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVwAAAks"] [Tue Aug 18 12:56:39.887150 2026] [security2:error] [pid 67073:tid 67260] [client 20.215.241.237:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/1.php"] [unique_id "aoSAt_cmepr5_nHgLbNZVwAAAks"] [Tue Aug 18 12:56:39.887975 2026] [security2:error] [pid 66623:tid 66876] [client 20.52.168.85:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/file.php"] [unique_id "aoSAt9O5rbWdOArH04KLkgAAAXg"] [Tue Aug 18 12:56:39.917293 2026] [security2:error] [pid 67073:tid 67295] [client 52.139.47.57:16687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/lock360.php"] [unique_id "aoSAt_cmepr5_nHgLbNZWAAAAm4"] [Tue Aug 18 12:56:39.978482 2026] [security2:error] [pid 67073:tid 67090] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/chosen.php"] [unique_id "aoSAt_cmepr5_nHgLbNZXAACaw4"] [Tue Aug 18 12:56:40.004794 2026] [security2:error] [pid 66623:tid 66805] [client 172.202.39.151:28973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/files/index.php"] [unique_id "aoSAuNO5rbWdOArH04KLlQAAATE"] [Tue Aug 18 12:56:40.025801 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:20716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAuPcmepr5_nHgLbNZXwAAAiQ"] [Tue Aug 18 12:56:40.027236 2026] [security2:error] [pid 66623:tid 66875] [client 20.171.51.14:36419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/97.php"] [unique_id "aoSAuNO5rbWdOArH04KLlgAAAXc"] [Tue Aug 18 12:56:40.036953 2026] [security2:error] [pid 66623:tid 66888] [client 20.151.109.219:12918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/47.php"] [unique_id "aoSAuNO5rbWdOArH04KLlwAAAYQ"] [Tue Aug 18 12:56:40.051168 2026] [security2:error] [pid 67073:tid 67287] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/test_info.php"] [unique_id "aoSAuPcmepr5_nHgLbNZYQAAAmY"] [Tue Aug 18 12:56:40.065800 2026] [security2:error] [pid 67073:tid 67244] [client 172.202.39.151:50194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/images/images/about.php"] [unique_id "aoSAuPcmepr5_nHgLbNZYgAAAjs"] [Tue Aug 18 12:56:40.143861 2026] [security2:error] [pid 67073:tid 67278] [client 132.196.30.78:19399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/nw.php"] [unique_id "aoSAuPcmepr5_nHgLbNZZgAAAl0"] [Tue Aug 18 12:56:40.153285 2026] [security2:error] [pid 67073:tid 67119] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/asd.php"] [unique_id "aoSAuPcmepr5_nHgLbNZZwACaSs"] [Tue Aug 18 12:56:40.159503 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSAuPcmepr5_nHgLbNZaAAAAlY"] [Tue Aug 18 12:56:40.160166 2026] [security2:error] [pid 67073:tid 67238] [client 40.85.222.29:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSAuPcmepr5_nHgLbNZaQAAAjU"] [Tue Aug 18 12:56:40.185702 2026] [security2:error] [pid 66623:tid 66842] [client 20.65.69.59:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/findes.php"] [unique_id "aoSAuNO5rbWdOArH04KLmgAAAVY"] [Tue Aug 18 12:56:40.198079 2026] [security2:error] [pid 67073:tid 67239] [client 20.116.17.175:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAuPcmepr5_nHgLbNZawAAAjY"] [Tue Aug 18 12:56:40.262766 2026] [security2:error] [pid 67073:tid 67311] [client 114.5.214.109:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZbQAAAn4"] [Tue Aug 18 12:56:40.275295 2026] [security2:error] [pid 67073:tid 67311] [client 114.5.214.109:49811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZbQAAAn4"] [Tue Aug 18 12:56:40.290998 2026] [security2:error] [pid 66623:tid 66877] [client 213.35.127.232:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAuNO5rbWdOArH04KLnAAAAXk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:40.311001 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/14.php"] [unique_id "aoSAuNO5rbWdOArH04KLnQAAAWI"] [Tue Aug 18 12:56:40.327518 2026] [security2:error] [pid 67073:tid 67152] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/akc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZegACWUw"] [Tue Aug 18 12:56:40.375263 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:40.375532 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:40.380324 2026] [security2:error] [pid 67073:tid 67224] [client 20.151.109.219:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/payout.php"] [unique_id "aoSAuPcmepr5_nHgLbNZgQAAAic"] [Tue Aug 18 12:56:40.396490 2026] [security2:error] [pid 67073:tid 67301] [client 158.23.17.4:38892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sxx.php"] [unique_id "aoSAuPcmepr5_nHgLbNZggAAAnQ"] [Tue Aug 18 12:56:40.400619 2026] [security2:error] [pid 66623:tid 66766] [client 20.215.241.237:21508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/key.php"] [unique_id "aoSAuNO5rbWdOArH04KLoQAAAQo"] [Tue Aug 18 12:56:40.400935 2026] [security2:error] [pid 67073:tid 67218] [client 135.225.75.187:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/pp.php"] [unique_id "aoSAuPcmepr5_nHgLbNZgwAAAiE"] [Tue Aug 18 12:56:40.418841 2026] [security2:error] [pid 66623:tid 66813] [client 85.154.68.202:51474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAuNO5rbWdOArH04KLogAAATk"] [Tue Aug 18 12:56:40.418968 2026] [security2:error] [pid 66623:tid 66813] [client 85.154.68.202:51474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAuNO5rbWdOArH04KLogAAATk"] [Tue Aug 18 12:56:40.456907 2026] [security2:error] [pid 67073:tid 67279] [client 40.85.222.29:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSAuPcmepr5_nHgLbNZhQAAAl4"] [Tue Aug 18 12:56:40.469356 2026] [security2:error] [pid 66623:tid 66819] [client 20.215.241.237:20003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/ajax.php"] [unique_id "aoSAuNO5rbWdOArH04KLpQAAAT8"] [Tue Aug 18 12:56:40.491082 2026] [security2:error] [pid 67073:tid 67291] [client 20.52.168.85:7833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/222.php"] [unique_id "aoSAuPcmepr5_nHgLbNZhgAAAmo"] [Tue Aug 18 12:56:40.501738 2026] [security2:error] [pid 67073:tid 67120] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/maintenance.php"] [unique_id "aoSAuPcmepr5_nHgLbNZiQACFSw"] [Tue Aug 18 12:56:40.503852 2026] [security2:error] [pid 67073:tid 67277] [client 160.120.140.123:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZigAAAlw"] [Tue Aug 18 12:56:40.503933 2026] [security2:error] [pid 67073:tid 67277] [client 160.120.140.123:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAuPcmepr5_nHgLbNZigAAAlw"] [Tue Aug 18 12:56:40.527631 2026] [security2:error] [pid 67073:tid 67332] [client 79.127.164.8:33070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/main.sql"] [unique_id "aoSAuPcmepr5_nHgLbNZjAAAApM"], referer: https://medihub.com.br/main.sql [Tue Aug 18 12:56:40.573171 2026] [security2:error] [pid 66623:tid 66852] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tk.php"] [unique_id "aoSAuNO5rbWdOArH04KLqAAAAWA"] [Tue Aug 18 12:56:40.576013 2026] [security2:error] [pid 66623:tid 66788] [client 20.215.241.237:40489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/about.php"] [unique_id "aoSAuNO5rbWdOArH04KLqgAAASA"] [Tue Aug 18 12:56:40.604232 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:26175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/shell.php"] [unique_id "aoSAuPcmepr5_nHgLbNZkAAAAno"] [Tue Aug 18 12:56:40.620571 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:51795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rh.php"] [unique_id "aoSAuNO5rbWdOArH04KLrAAAAYE"] [Tue Aug 18 12:56:40.675709 2026] [security2:error] [pid 67073:tid 67149] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/options-writing.php"] [unique_id "aoSAuPcmepr5_nHgLbNZkwACZUk"] [Tue Aug 18 12:56:40.676398 2026] [authz_core:error] [pid 67073:tid 67098] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:40.676665 2026] [authz_core:error] [pid 67073:tid 67098] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:40.681569 2026] [security2:error] [pid 67073:tid 67249] [client 20.163.43.14:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlAAAAkA"] [Tue Aug 18 12:56:40.694645 2026] [security2:error] [pid 67073:tid 67303] [client 20.151.109.219:46527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bh.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlQAAAnY"] [Tue Aug 18 12:56:40.733448 2026] [security2:error] [pid 67073:tid 67316] [client 40.85.222.29:13233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSAuPcmepr5_nHgLbNZlgAAAoM"] [Tue Aug 18 12:56:40.760153 2026] [security2:error] [pid 66623:tid 66865] [client 20.116.17.175:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-good.php"] [unique_id "aoSAuNO5rbWdOArH04KLsgAAAW0"] [Tue Aug 18 12:56:40.834632 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/hp.php"] [unique_id "aoSAuPcmepr5_nHgLbNZmQAAAlc"] [Tue Aug 18 12:56:40.850685 2026] [security2:error] [pid 67073:tid 67100] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSAuPcmepr5_nHgLbNZmwACJhg"] [Tue Aug 18 12:56:40.887179 2026] [security2:error] [pid 67073:tid 67282] [client 158.23.17.4:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/settings.php"] [unique_id "aoSAuPcmepr5_nHgLbNZnQAAAmE"] [Tue Aug 18 12:56:40.892848 2026] [security2:error] [pid 67073:tid 67317] [client 20.102.65.165:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAuPcmepr5_nHgLbNZnwAAAoQ"] [Tue Aug 18 12:56:40.961592 2026] [security2:error] [pid 67073:tid 67265] [client 135.225.75.187:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wqqs.php"] [unique_id "aoSAuPcmepr5_nHgLbNZswAAAlA"] [Tue Aug 18 12:56:40.975896 2026] [security2:error] [pid 67073:tid 67295] [client 20.151.109.219:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/ct.php"] [unique_id "aoSAuPcmepr5_nHgLbNZuQAAAm4"] [Tue Aug 18 12:56:40.979560 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:40.979989 2026] [authz_core:error] [pid 67073:tid 67178] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:40.998779 2026] [ssl:error] [pid 67073:tid 67126] [remote 46.34.225.192:10695] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 12:56:41.002605 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.136.165:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/g.php"] [unique_id "aoSAufcmepr5_nHgLbNZvwAAAmY"] [Tue Aug 18 12:56:41.020552 2026] [security2:error] [pid 67073:tid 67230] [client 20.163.43.14:4208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZwAAAAi0"] [Tue Aug 18 12:56:41.025333 2026] [security2:error] [pid 67073:tid 67079] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/maint.php"] [unique_id "aoSAufcmepr5_nHgLbNZwQACLgM"] [Tue Aug 18 12:56:41.033264 2026] [security2:error] [pid 66623:tid 66800] [client 40.85.222.29:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSAudO5rbWdOArH04KLuAAAASw"] [Tue Aug 18 12:56:41.060455 2026] [security2:error] [pid 66623:tid 66808] [client 52.139.47.57:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSAudO5rbWdOArH04KLuQAAATQ"] [Tue Aug 18 12:56:41.062305 2026] [security2:error] [pid 67073:tid 67271] [client 158.158.34.183:23142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSAufcmepr5_nHgLbNZxAAAAlY"] [Tue Aug 18 12:56:41.098477 2026] [security2:error] [pid 67073:tid 67276] [client 20.52.168.85:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZxwAAAls"] [Tue Aug 18 12:56:41.101535 2026] [security2:error] [pid 66623:tid 66882] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wx.php"] [unique_id "aoSAudO5rbWdOArH04KLuwAAAX4"] [Tue Aug 18 12:56:41.104688 2026] [security2:error] [pid 67073:tid 67254] [client 20.65.69.59:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/fedora.php"] [unique_id "aoSAufcmepr5_nHgLbNZyAAAAkU"] [Tue Aug 18 12:56:41.130620 2026] [security2:error] [pid 67073:tid 67258] [client 20.102.65.165:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAufcmepr5_nHgLbNZygAAAkk"] [Tue Aug 18 12:56:41.168119 2026] [security2:error] [pid 67073:tid 67232] [client 20.186.30.159:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZzAAAAi8"] [Tue Aug 18 12:56:41.179425 2026] [security2:error] [pid 66623:tid 66843] [client 52.139.47.57:9062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/hplfuns.php"] [unique_id "aoSAudO5rbWdOArH04KLvQAAAVc"] [Tue Aug 18 12:56:41.200755 2026] [security2:error] [pid 67073:tid 67161] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/phpMailer.php"] [unique_id "aoSAufcmepr5_nHgLbNZzgACJ1U"] [Tue Aug 18 12:56:41.248081 2026] [security2:error] [pid 66623:tid 66868] [client 20.215.241.237:54952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAudO5rbWdOArH04KLvgAAAXA"] [Tue Aug 18 12:56:41.271789 2026] [security2:error] [pid 67073:tid 67243] [client 172.202.39.151:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ0wAAAjo"] [Tue Aug 18 12:56:41.278600 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:41.278888 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:41.302356 2026] [security2:error] [pid 67073:tid 67279] [client 20.151.109.219:12908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/gy.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1AAAAl4"] [Tue Aug 18 12:56:41.316726 2026] [security2:error] [pid 67073:tid 67284] [client 213.35.127.232:60540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1QAAAmM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:41.328537 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1gAAAkc"] [Tue Aug 18 12:56:41.329769 2026] [security2:error] [pid 67073:tid 67131] [remote 162.214.96.231:49218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSAufcmepr5_nHgLbNZ1wACMjc"] [Tue Aug 18 12:56:41.349814 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/dj.php"] [unique_id "aoSAufcmepr5_nHgLbNZ2gAAAhU"] [Tue Aug 18 12:56:41.352684 2026] [security2:error] [pid 66623:tid 66871] [client 20.116.17.175:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wmore1.php"] [unique_id "aoSAudO5rbWdOArH04KLwAAAAXM"] [Tue Aug 18 12:56:41.354775 2026] [security2:error] [pid 67073:tid 67330] [client 20.29.77.16:52742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/styles.php"] [unique_id "aoSAufcmepr5_nHgLbNZ2wAAApE"] [Tue Aug 18 12:56:41.355920 2026] [security2:error] [pid 67073:tid 67277] [client 20.163.43.14:4283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/file.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3AAAAlw"] [Tue Aug 18 12:56:41.374986 2026] [security2:error] [pid 67073:tid 67110] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3QACcCI"] [Tue Aug 18 12:56:41.391267 2026] [security2:error] [pid 67073:tid 67312] [client 20.102.65.165:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/media.php"] [unique_id "aoSAufcmepr5_nHgLbNZ3gAAAn8"] [Tue Aug 18 12:56:41.441091 2026] [security2:error] [pid 67073:tid 67242] [client 158.23.17.4:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/spip.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4AAAAjk"] [Tue Aug 18 12:56:41.454228 2026] [security2:error] [pid 67073:tid 67097] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4gACMRU"] [Tue Aug 18 12:56:41.454424 2026] [security2:error] [pid 67073:tid 67234] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ4gACMRU"] [Tue Aug 18 12:56:41.519695 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.154.236:16211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/rezor.php"] [unique_id "aoSAufcmepr5_nHgLbNZ5QAAAns"] [Tue Aug 18 12:56:41.549899 2026] [security2:error] [pid 67073:tid 67140] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/al.php"] [unique_id "aoSAufcmepr5_nHgLbNZ6AACQUA"] [Tue Aug 18 12:56:41.582885 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:41.583149 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:41.603737 2026] [security2:error] [pid 66623:tid 66771] [client 135.225.75.187:24688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/clasa99.php"] [unique_id "aoSAudO5rbWdOArH04KLxQAAAQ8"] [Tue Aug 18 12:56:41.605423 2026] [security2:error] [pid 66623:tid 66829] [client 40.85.222.29:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSAudO5rbWdOArH04KLxgAAAUk"] [Tue Aug 18 12:56:41.613908 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fa.php"] [unique_id "aoSAudO5rbWdOArH04KLxwAAAYA"] [Tue Aug 18 12:56:41.615998 2026] [security2:error] [pid 66623:tid 66826] [client 20.151.109.219:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/tt.php"] [unique_id "aoSAudO5rbWdOArH04KLyAAAAUY"] [Tue Aug 18 12:56:41.628911 2026] [security2:error] [pid 67073:tid 67272] [client 20.102.65.165:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/admin.php"] [unique_id "aoSAufcmepr5_nHgLbNZ6wAAAlc"] [Tue Aug 18 12:56:41.685149 2026] [security2:error] [pid 67073:tid 67296] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAufcmepr5_nHgLbNZ7AACbwE"] [Tue Aug 18 12:56:41.704785 2026] [security2:error] [pid 67073:tid 67307] [client 52.139.47.57:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/hosty.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8AAAAno"] [Tue Aug 18 12:56:41.704790 2026] [security2:error] [pid 67073:tid 67222] [client 20.52.168.85:7859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/a.php"] [unique_id "aoSAufcmepr5_nHgLbNZ7wAAAiU"] [Tue Aug 18 12:56:41.714232 2026] [security2:error] [pid 67073:tid 67267] [client 20.163.43.14:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/epinyins.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8QAAAlI"] [Tue Aug 18 12:56:41.726616 2026] [security2:error] [pid 67073:tid 67096] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8gACIxQ"] [Tue Aug 18 12:56:41.734105 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:16494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAufcmepr5_nHgLbNZ8wAAAos"] [Tue Aug 18 12:56:41.794468 2026] [security2:error] [pid 66623:tid 66844] [client 20.171.51.14:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/yg.php"] [unique_id "aoSAudO5rbWdOArH04KLzQAAAVg"] [Tue Aug 18 12:56:41.819919 2026] [security2:error] [pid 66623:tid 66869] [client 20.206.73.37:59856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/img.php"] [unique_id "aoSAudO5rbWdOArH04KLzgAAAXE"] [Tue Aug 18 12:56:41.870696 2026] [security2:error] [pid 67073:tid 67310] [client 158.23.17.4:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/search.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9QAAAn0"] [Tue Aug 18 12:56:41.888316 2026] [security2:error] [pid 67073:tid 67244] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/fb.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9gAAAjs"] [Tue Aug 18 12:56:41.903312 2026] [security2:error] [pid 67073:tid 67107] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-activat.php"] [unique_id "aoSAufcmepr5_nHgLbNZ9wACdx8"] [Tue Aug 18 12:56:41.905730 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSAufcmepr5_nHgLbNZ-AAAAi4"] [Tue Aug 18 12:56:41.929016 2026] [security2:error] [pid 67073:tid 67278] [client 20.215.241.237:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/edit.php"] [unique_id "aoSAufcmepr5_nHgLbNZ-gAAAl0"] [Tue Aug 18 12:56:41.934002 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.30.78:21853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/xleet.php"] [unique_id "aoSAudO5rbWdOArH04KL0wAAAUQ"] [Tue Aug 18 12:56:41.946255 2026] [security2:error] [pid 67073:tid 67290] [client 20.102.65.165:8306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/mac.php"] [unique_id "aoSAufcmepr5_nHgLbNZ_AAAAmk"] [Tue Aug 18 12:56:41.960676 2026] [security2:error] [pid 67073:tid 67265] [client 52.139.47.57:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/pwnd/as.php"] [unique_id "aoSAufcmepr5_nHgLbNZ_QAAAlA"] [Tue Aug 18 12:56:42.002395 2026] [security2:error] [pid 66623:tid 66838] [client 20.151.109.219:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/mq.php"] [unique_id "aoSAutO5rbWdOArH04KL1AAAAVI"] [Tue Aug 18 12:56:42.018649 2026] [security2:error] [pid 66623:tid 66873] [client 20.65.69.59:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/path.php"] [unique_id "aoSAutO5rbWdOArH04KL1gAAAXU"] [Tue Aug 18 12:56:42.023584 2026] [security2:error] [pid 66623:tid 66851] [client 157.51.166.53:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAutO5rbWdOArH04KL1wAAAV8"] [Tue Aug 18 12:56:42.023763 2026] [security2:error] [pid 66623:tid 66851] [client 157.51.166.53:62430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAutO5rbWdOArH04KL1wAAAV8"] [Tue Aug 18 12:56:42.044224 2026] [security2:error] [pid 67073:tid 67254] [client 20.163.43.14:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNZ_gAAAkU"] [Tue Aug 18 12:56:42.067097 2026] [security2:error] [pid 67073:tid 67311] [client 20.215.241.237:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAAAAAn4"] [Tue Aug 18 12:56:42.079834 2026] [security2:error] [pid 67073:tid 67180] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAQACSWg"] [Tue Aug 18 12:56:42.090423 2026] [security2:error] [pid 67073:tid 67320] [client 158.158.74.177:16541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/shiny.php"] [unique_id "aoSAuvcmepr5_nHgLbNaAgAAAoc"] [Tue Aug 18 12:56:42.131016 2026] [security2:error] [pid 67073:tid 67232] [client 104.209.144.33:34125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAuvcmepr5_nHgLbNaBAAAAi8"] [Tue Aug 18 12:56:42.139120 2026] [security2:error] [pid 67073:tid 67212] [client 74.7.230.53:41242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "novosite.rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSAufcmepr5_nHgLbNZ5wACG3w"] [Tue Aug 18 12:56:42.154219 2026] [security2:error] [pid 66623:tid 66795] [client 20.29.77.16:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/server.php"] [unique_id "aoSAutO5rbWdOArH04KL2wAAASc"] [Tue Aug 18 12:56:42.161519 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.136.165:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/x7.php"] [unique_id "aoSAutO5rbWdOArH04KL3AAAAT0"] [Tue Aug 18 12:56:42.189970 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gw.php"] [unique_id "aoSAuvcmepr5_nHgLbNaBwAAAlk"] [Tue Aug 18 12:56:42.192171 2026] [security2:error] [pid 66623:tid 66794] [client 40.85.222.29:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSAutO5rbWdOArH04KL3gAAASY"] [Tue Aug 18 12:56:42.201874 2026] [security2:error] [pid 67073:tid 67240] [client 20.102.65.165:8196] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCAAAAjc"] [Tue Aug 18 12:56:42.201998 2026] [security2:error] [pid 67073:tid 67240] [client 20.102.65.165:8196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCAAAAjc"] [Tue Aug 18 12:56:42.257531 2026] [security2:error] [pid 67073:tid 67116] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/past1.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCQACPig"] [Tue Aug 18 12:56:42.284822 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:47627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/t.php"] [unique_id "aoSAuvcmepr5_nHgLbNaCwAAAlQ"] [Tue Aug 18 12:56:42.313778 2026] [security2:error] [pid 67073:tid 67229] [client 20.52.168.85:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin.php"] [unique_id "aoSAuvcmepr5_nHgLbNaDAAAAiw"] [Tue Aug 18 12:56:42.342317 2026] [security2:error] [pid 66623:tid 66783] [client 213.35.127.232:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAutO5rbWdOArH04KL4QAAARs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:42.342421 2026] [security2:error] [pid 67073:tid 67284] [client 158.23.17.4:29495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/build.php"] [unique_id "aoSAuvcmepr5_nHgLbNaDQAAAmM"] [Tue Aug 18 12:56:42.352046 2026] [security2:error] [pid 66623:tid 66807] [client 20.151.109.219:59722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/13.php"] [unique_id "aoSAutO5rbWdOArH04KL4gAAATM"] [Tue Aug 18 12:56:42.388457 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:42.388706 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:42.432487 2026] [security2:error] [pid 67073:tid 67101] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/file61.php"] [unique_id "aoSAuvcmepr5_nHgLbNaEgACFRk"] [Tue Aug 18 12:56:42.443607 2026] [security2:error] [pid 67073:tid 67330] [client 20.102.65.165:8314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/coffee.php"] [unique_id "aoSAuvcmepr5_nHgLbNaEwAAApE"] [Tue Aug 18 12:56:42.459116 2026] [security2:error] [pid 67073:tid 67277] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/sw.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFAAAAlw"] [Tue Aug 18 12:56:42.465113 2026] [security2:error] [pid 66623:tid 66837] [client 20.171.51.14:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/et.php"] [unique_id "aoSAutO5rbWdOArH04KL5gAAAVE"] [Tue Aug 18 12:56:42.465548 2026] [security2:error] [pid 67073:tid 67262] [client 40.85.222.29:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFQAAAk0"] [Tue Aug 18 12:56:42.470047 2026] [security2:error] [pid 67073:tid 67241] [client 135.225.75.187:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/666.php"] [unique_id "aoSAuvcmepr5_nHgLbNaFgAAAjg"] [Tue Aug 18 12:56:42.517886 2026] [security2:error] [pid 67073:tid 67213] [client 172.202.39.151:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGAAAAhw"] [Tue Aug 18 12:56:42.534631 2026] [security2:error] [pid 67073:tid 67239] [client 132.196.30.78:18797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGgAAAjY"] [Tue Aug 18 12:56:42.561425 2026] [security2:error] [pid 67073:tid 67268] [client 20.163.43.14:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNaGwAAAlM"] [Tue Aug 18 12:56:42.613646 2026] [security2:error] [pid 67073:tid 67208] [client 20.215.241.237:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHQAAAhc"] [Tue Aug 18 12:56:42.625516 2026] [security2:error] [pid 67073:tid 67286] [client 104.209.144.33:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/rezor.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHgAAAmU"] [Tue Aug 18 12:56:42.642550 2026] [security2:error] [pid 66623:tid 66796] [client 20.151.109.219:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/so.php"] [unique_id "aoSAutO5rbWdOArH04KL6AAAASg"] [Tue Aug 18 12:56:42.682578 2026] [security2:error] [pid 67073:tid 67205] [client 20.102.65.165:8201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAuvcmepr5_nHgLbNaHwAAAhQ"] [Tue Aug 18 12:56:42.686121 2026] [security2:error] [pid 67073:tid 67329] [client 20.116.17.175:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/special.php"] [unique_id "aoSAuvcmepr5_nHgLbNaIQAAApA"] [Tue Aug 18 12:56:42.721440 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gc.php"] [unique_id "aoSAuvcmepr5_nHgLbNaIwAAAlc"] [Tue Aug 18 12:56:42.722250 2026] [security2:error] [pid 67073:tid 67300] [client 158.23.17.4:29501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/defaul.php"] [unique_id "aoSAuvcmepr5_nHgLbNaJAAAAnM"] [Tue Aug 18 12:56:42.743402 2026] [security2:error] [pid 67073:tid 67223] [client 40.85.222.29:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSAuvcmepr5_nHgLbNaJQAAAiY"] [Tue Aug 18 12:56:42.937032 2026] [security2:error] [pid 67073:tid 67292] [client 20.163.43.14:4155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAuvcmepr5_nHgLbNaMwAAAms"] [Tue Aug 18 12:56:42.938841 2026] [security2:error] [pid 67073:tid 67233] [client 74.248.136.165:28155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/god.php"] [unique_id "aoSAuvcmepr5_nHgLbNaNAAAAjA"] [Tue Aug 18 12:56:42.948908 2026] [security2:error] [pid 66623:tid 66805] [client 20.102.65.165:8301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSAutO5rbWdOArH04KL_QAAATE"] [Tue Aug 18 12:56:42.990321 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:42.990614 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:43.020775 2026] [security2:error] [pid 67073:tid 67230] [client 20.151.109.219:64138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/10.php"] [unique_id "aoSAu_cmepr5_nHgLbNaNgAAAi0"] [Tue Aug 18 12:56:43.021529 2026] [security2:error] [pid 66623:tid 66889] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uq.php"] [unique_id "aoSAu9O5rbWdOArH04KL_wAAAYU"] [Tue Aug 18 12:56:43.046300 2026] [security2:error] [pid 67073:tid 67315] [client 20.171.51.14:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/of.php"] [unique_id "aoSAu_cmepr5_nHgLbNaNwAAAoI"] [Tue Aug 18 12:56:43.051541 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAu9O5rbWdOArH04KMAQAAARg"] [Tue Aug 18 12:56:43.057484 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSAu_cmepr5_nHgLbNaOQAAAi4"] [Tue Aug 18 12:56:43.076815 2026] [security2:error] [pid 67073:tid 67134] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jgbdominiosolucoes.com.br"] [uri "/license.php"] [unique_id "aoSAu_cmepr5_nHgLbNaOgACgTo"] [Tue Aug 18 12:56:43.085609 2026] [security2:error] [pid 67073:tid 67308] [client 52.139.47.57:44622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/rk2.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPAAAAns"] [Tue Aug 18 12:56:43.095789 2026] [security2:error] [pid 67073:tid 67211] [client 20.52.168.85:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "aoSAuvcmepr5_nHgLbNaMQAAAho"] [Tue Aug 18 12:56:43.096037 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.34.183:64572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPQAAApM"] [Tue Aug 18 12:56:43.130307 2026] [security2:error] [pid 67073:tid 67237] [client 52.139.47.57:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPgAAAjQ"] [Tue Aug 18 12:56:43.136677 2026] [security2:error] [pid 67073:tid 67302] [client 20.186.30.159:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/bajah.php"] [unique_id "aoSAu_cmepr5_nHgLbNaPwAAAnU"] [Tue Aug 18 12:56:43.163838 2026] [security2:error] [pid 67073:tid 67254] [client 20.215.241.237:49203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inputs.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQAAAAkU"] [Tue Aug 18 12:56:43.211454 2026] [security2:error] [pid 67073:tid 67324] [client 132.196.30.78:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/155.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQwAAAos"] [Tue Aug 18 12:56:43.211518 2026] [security2:error] [pid 67073:tid 67320] [client 20.102.65.165:8285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/yj09.php"] [unique_id "aoSAu_cmepr5_nHgLbNaQgAAAoc"] [Tue Aug 18 12:56:43.214420 2026] [security2:error] [pid 67073:tid 67260] [client 20.65.69.59:3662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/456.php"] [unique_id "aoSAu_cmepr5_nHgLbNaRAAAAks"] [Tue Aug 18 12:56:43.263648 2026] [security2:error] [pid 67073:tid 67221] [client 20.163.43.14:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp.php"] [unique_id "aoSAu_cmepr5_nHgLbNaSQAAAiQ"] [Tue Aug 18 12:56:43.269651 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:43558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNaSgAAAm0"] [Tue Aug 18 12:56:43.291234 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:43.291519 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:43.331218 2026] [security2:error] [pid 67073:tid 67325] [client 40.85.222.29:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTQAAAow"] [Tue Aug 18 12:56:43.356529 2026] [security2:error] [pid 67073:tid 67243] [client 135.225.75.187:29716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/thui.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTgAAAjo"] [Tue Aug 18 12:56:43.359699 2026] [security2:error] [pid 67073:tid 67304] [client 213.35.127.232:61030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAu_cmepr5_nHgLbNaTwAAAnc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:43.369044 2026] [security2:error] [pid 67073:tid 67269] [client 20.29.77.16:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/xinfo.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUQAAAlQ"] [Tue Aug 18 12:56:43.410448 2026] [security2:error] [pid 66623:tid 66813] [client 20.151.109.219:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/te.php"] [unique_id "aoSAu9O5rbWdOArH04KMCQAAATk"] [Tue Aug 18 12:56:43.422310 2026] [security2:error] [pid 66623:tid 66793] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/32.php"] [unique_id "aoSAu9O5rbWdOArH04KMCgAAASU"] [Tue Aug 18 12:56:43.432542 2026] [security2:error] [pid 67073:tid 67279] [client 104.209.144.33:35878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/uploads/bypass.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUgAAAl4"] [Tue Aug 18 12:56:43.446679 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.74.177:16559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sid3.php"] [unique_id "aoSAu_cmepr5_nHgLbNaUwAAAng"] [Tue Aug 18 12:56:43.455966 2026] [security2:error] [pid 66623:tid 66773] [client 20.102.65.165:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/scxy.php"] [unique_id "aoSAu9O5rbWdOArH04KMCwAAARE"] [Tue Aug 18 12:56:43.497249 2026] [security2:error] [pid 67073:tid 67166] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/web.config"] [unique_id "aoSAu_cmepr5_nHgLbNaVgACblo"] [Tue Aug 18 12:56:43.530038 2026] [security2:error] [pid 67073:tid 67262] [client 158.23.17.4:9380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/twin.php"] [unique_id "aoSAu_cmepr5_nHgLbNaXAAAAk0"] [Tue Aug 18 12:56:43.547926 2026] [security2:error] [pid 67073:tid 67318] [client 20.104.85.180:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/an.php"] [unique_id "aoSAu_cmepr5_nHgLbNaYAAAAoU"] [Tue Aug 18 12:56:43.582110 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:61513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu9O5rbWdOArH04KMDwAAAX8"] [Tue Aug 18 12:56:43.582217 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:61513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu9O5rbWdOArH04KMDwAAAX8"] [Tue Aug 18 12:56:43.587438 2026] [security2:error] [pid 67073:tid 67270] [client 196.12.128.158:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZAAAAlU"] [Tue Aug 18 12:56:43.587538 2026] [security2:error] [pid 67073:tid 67270] [client 196.12.128.158:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZAAAAlU"] [Tue Aug 18 12:56:43.591236 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:43.591493 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:43.591858 2026] [security2:error] [pid 67073:tid 67236] [client 20.163.43.14:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/function/function.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZQAAAjM"] [Tue Aug 18 12:56:43.597390 2026] [security2:error] [pid 66623:tid 66822] [client 52.139.47.57:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/xx.php"] [unique_id "aoSAu9O5rbWdOArH04KMEAAAAUI"] [Tue Aug 18 12:56:43.611505 2026] [security2:error] [pid 67073:tid 67245] [client 40.85.222.29:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSAu_cmepr5_nHgLbNaZgAAAjw"] [Tue Aug 18 12:56:43.687051 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/73.php"] [unique_id "aoSAu_cmepr5_nHgLbNabAAAAnY"] [Tue Aug 18 12:56:43.696940 2026] [security2:error] [pid 67073:tid 67330] [client 20.52.168.85:8054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/plugins.php"] [unique_id "aoSAu_cmepr5_nHgLbNacQAAApE"] [Tue Aug 18 12:56:43.718153 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:45395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bu.php"] [unique_id "aoSAu_cmepr5_nHgLbNacgAAAmw"] [Tue Aug 18 12:56:43.735056 2026] [security2:error] [pid 67073:tid 67272] [client 20.102.65.165:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSAu_cmepr5_nHgLbNadQAAAlc"] [Tue Aug 18 12:56:43.772548 2026] [security2:error] [pid 67073:tid 67264] [client 132.196.30.78:22519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/96i.php"] [unique_id "aoSAu_cmepr5_nHgLbNaeAAAAk8"] [Tue Aug 18 12:56:43.802038 2026] [security2:error] [pid 67073:tid 67266] [client 20.151.109.219:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/kc.php"] [unique_id "aoSAu_cmepr5_nHgLbNaeQAAAlE"] [Tue Aug 18 12:56:43.815817 2026] [security2:error] [pid 67073:tid 67307] [client 20.116.17.175:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAu_cmepr5_nHgLbNafAAAAno"] [Tue Aug 18 12:56:43.885796 2026] [security2:error] [pid 67073:tid 67261] [client 20.215.241.237:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/av.php"] [unique_id "aoSAu_cmepr5_nHgLbNafgAAAkw"] [Tue Aug 18 12:56:43.891139 2026] [security2:error] [pid 66623:tid 66803] [client 40.85.222.29:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSAu9O5rbWdOArH04KMOwAAAS8"] [Tue Aug 18 12:56:43.917182 2026] [security2:error] [pid 67073:tid 67216] [client 20.163.43.14:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSAu_cmepr5_nHgLbNagAAAAh8"] [Tue Aug 18 12:56:43.947892 2026] [security2:error] [pid 66623:tid 66799] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ib.php"] [unique_id "aoSAu9O5rbWdOArH04KMRAAAASs"] [Tue Aug 18 12:56:43.993157 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.136.165:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAu_cmepr5_nHgLbNaggAAApM"] [Tue Aug 18 12:56:44.017108 2026] [security2:error] [pid 67073:tid 67265] [client 20.102.65.165:8274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSAvPcmepr5_nHgLbNahAAAAlA"] [Tue Aug 18 12:56:44.035620 2026] [security2:error] [pid 67073:tid 67220] [client 52.139.47.57:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/storage/rip.php"] [unique_id "aoSAvPcmepr5_nHgLbNahQAAAiM"] [Tue Aug 18 12:56:44.072623 2026] [security2:error] [pid 67073:tid 67260] [client 20.29.77.16:33023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/sym.php"] [unique_id "aoSAvPcmepr5_nHgLbNajAAAAks"] [Tue Aug 18 12:56:44.111636 2026] [security2:error] [pid 67073:tid 67273] [client 20.100.169.31:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNajgAAAlg"] [Tue Aug 18 12:56:44.113319 2026] [security2:error] [pid 67073:tid 67271] [client 20.151.109.219:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/jn.php"] [unique_id "aoSAvPcmepr5_nHgLbNajwAAAlY"] [Tue Aug 18 12:56:44.114251 2026] [security2:error] [pid 66623:tid 66781] [client 20.215.241.237:49599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dealermotors.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvNO5rbWdOArH04KMRgAAARk"] [Tue Aug 18 12:56:44.167610 2026] [security2:error] [pid 67073:tid 67226] [client 40.85.222.29:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSAvPcmepr5_nHgLbNakgAAAik"] [Tue Aug 18 12:56:44.238054 2026] [security2:error] [pid 67073:tid 67321] [client 52.139.47.57:42965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/zwso.php"] [unique_id "aoSAvPcmepr5_nHgLbNalgAAAog"] [Tue Aug 18 12:56:44.246212 2026] [security2:error] [pid 66623:tid 66847] [client 20.163.43.14:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAvNO5rbWdOArH04KMSgAAAVs"] [Tue Aug 18 12:56:44.253122 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xm.php"] [unique_id "aoSAvPcmepr5_nHgLbNalwAAAlQ"] [Tue Aug 18 12:56:44.263277 2026] [security2:error] [pid 66623:tid 66867] [client 20.100.169.31:22808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/edit.php"] [unique_id "aoSAvNO5rbWdOArH04KMSwAAAW8"] [Tue Aug 18 12:56:44.294650 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:13647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/ajax.php"] [unique_id "aoSAvPcmepr5_nHgLbNanAAAAj8"] [Tue Aug 18 12:56:44.310537 2026] [security2:error] [pid 67073:tid 67305] [client 20.102.65.165:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "aoSAvPcmepr5_nHgLbNaoAAAAng"] [Tue Aug 18 12:56:44.356201 2026] [security2:error] [pid 67073:tid 67218] [client 135.225.75.187:19100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/agg.php"] [unique_id "aoSAvPcmepr5_nHgLbNapgAAAiE"] [Tue Aug 18 12:56:44.365870 2026] [ssl:error] [pid 67073:tid 67158] [remote 46.34.225.192:10695] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 12:56:44.369181 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqAAAAm4"] [Tue Aug 18 12:56:44.374523 2026] [security2:error] [pid 66623:tid 66768] [client 213.35.127.232:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAvNO5rbWdOArH04KMTQAAAQw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:44.453072 2026] [security2:error] [pid 67073:tid 67242] [client 40.85.222.29:13230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqgAAAjk"] [Tue Aug 18 12:56:44.459351 2026] [security2:error] [pid 67073:tid 67300] [client 158.158.34.183:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/go.php"] [unique_id "aoSAvPcmepr5_nHgLbNaqwAAAnM"] [Tue Aug 18 12:56:44.461365 2026] [security2:error] [pid 67073:tid 67225] [client 68.155.154.236:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAvPcmepr5_nHgLbNarAAAAig"] [Tue Aug 18 12:56:44.472241 2026] [security2:error] [pid 66623:tid 66853] [client 20.151.109.219:21633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suportesignrj.com.br"] [uri "/bf.php"] [unique_id "aoSAvNO5rbWdOArH04KMTwAAAWE"] [Tue Aug 18 12:56:44.488179 2026] [security2:error] [pid 66623:tid 66816] [client 132.196.30.78:19394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/as.php"] [unique_id "aoSAvNO5rbWdOArH04KMUAAAATw"] [Tue Aug 18 12:56:44.501113 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:44.501425 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:44.503949 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-includes/customize/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNargAAAjM"] [Tue Aug 18 12:56:44.509519 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zy.php"] [unique_id "aoSAvPcmepr5_nHgLbNarwAAAhc"] [Tue Aug 18 12:56:44.556911 2026] [security2:error] [pid 67073:tid 67303] [client 20.116.17.175:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/thoms.php"] [unique_id "aoSAvPcmepr5_nHgLbNasgAAAnY"] [Tue Aug 18 12:56:44.557984 2026] [security2:error] [pid 67073:tid 67329] [client 20.102.65.165:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/bajah.php"] [unique_id "aoSAvPcmepr5_nHgLbNaswAAApA"] [Tue Aug 18 12:56:44.559088 2026] [security2:error] [pid 67073:tid 67210] [client 20.171.51.14:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rn.php"] [unique_id "aoSAvPcmepr5_nHgLbNatAAAAhk"] [Tue Aug 18 12:56:44.619257 2026] [security2:error] [pid 67073:tid 67264] [client 20.163.43.14:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/ok.php"] [unique_id "aoSAvPcmepr5_nHgLbNavQAAAk8"] [Tue Aug 18 12:56:44.628991 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvPcmepr5_nHgLbNavgAAAjA"] [Tue Aug 18 12:56:44.629092 2026] [security2:error] [pid 67073:tid 67233] [client 197.184.64.235:41932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvPcmepr5_nHgLbNavgAAAjA"] [Tue Aug 18 12:56:44.673211 2026] [security2:error] [pid 67073:tid 67243] [client 84.247.146.84:47384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/"] [unique_id "aoSAvPcmepr5_nHgLbNawAAAAjo"] [Tue Aug 18 12:56:44.701496 2026] [security2:error] [pid 67073:tid 67262] [client 158.158.74.177:26112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sid4.php"] [unique_id "aoSAvPcmepr5_nHgLbNawQAAAk0"] [Tue Aug 18 12:56:44.720072 2026] [security2:error] [pid 67073:tid 67286] [client 20.250.13.23:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSAvPcmepr5_nHgLbNawgAAAmU"] [Tue Aug 18 12:56:44.735317 2026] [security2:error] [pid 67073:tid 67312] [client 74.248.136.165:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/8.php"] [unique_id "aoSAvPcmepr5_nHgLbNaxAAAAn8"] [Tue Aug 18 12:56:44.747434 2026] [security2:error] [pid 66623:tid 66862] [client 40.85.222.29:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSAvNO5rbWdOArH04KMXgAAAWo"] [Tue Aug 18 12:56:44.753167 2026] [security2:error] [pid 66623:tid 66871] [client 104.209.144.33:21435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAvNO5rbWdOArH04KMYAAAAXM"] [Tue Aug 18 12:56:44.770519 2026] [security2:error] [pid 67073:tid 67261] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/q.php"] [unique_id "aoSAvPcmepr5_nHgLbNaxgAAAkw"] [Tue Aug 18 12:56:44.796039 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:44.796318 2026] [authz_core:error] [pid 67073:tid 67181] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:44.806924 2026] [security2:error] [pid 67073:tid 67244] [client 20.102.65.165:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/domvf.php"] [unique_id "aoSAvPcmepr5_nHgLbNayQAAAjs"] [Tue Aug 18 12:56:44.809704 2026] [security2:error] [pid 67073:tid 67126] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/frontend/.env"] [unique_id "aoSAvPcmepr5_nHgLbNaygACLTI"] [Tue Aug 18 12:56:44.809829 2026] [security2:error] [pid 67073:tid 67079] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/src/.env"] [unique_id "aoSAvPcmepr5_nHgLbNaywACLQM"] [Tue Aug 18 12:56:44.834280 2026] [security2:error] [pid 67073:tid 67159] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/app/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazgACgVM"] [Tue Aug 18 12:56:44.834357 2026] [security2:error] [pid 67073:tid 67094] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/dev/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazQACgRI"] [Tue Aug 18 12:56:44.834357 2026] [security2:error] [pid 67073:tid 67083] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/production/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazAACgQc"] [Tue Aug 18 12:56:44.834631 2026] [security2:error] [pid 67073:tid 67078] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/server/.env"] [unique_id "aoSAvPcmepr5_nHgLbNazwACgQI"] [Tue Aug 18 12:56:44.849705 2026] [security2:error] [pid 67073:tid 67308] [client 158.23.17.4:29447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/new2.php"] [unique_id "aoSAvPcmepr5_nHgLbNa0AAAAns"] [Tue Aug 18 12:56:44.852402 2026] [security2:error] [pid 67073:tid 67235] [client 52.139.47.57:18413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/tool.php"] [unique_id "aoSAvPcmepr5_nHgLbNa0QAAAjI"] [Tue Aug 18 12:56:44.861624 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.69.59:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/SMTP.php"] [unique_id "aoSAvNO5rbWdOArH04KMYwAAAYA"] [Tue Aug 18 12:56:44.883945 2026] [security2:error] [pid 66623:tid 66811] [client 20.29.77.16:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jthaautomoveis.com.br"] [uri "/ye.php"] [unique_id "aoSAvNO5rbWdOArH04KMZQAAATc"] [Tue Aug 18 12:56:44.898757 2026] [security2:error] [pid 67073:tid 67302] [client 20.215.241.237:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAvPcmepr5_nHgLbNa1QAAAnU"] [Tue Aug 18 12:56:44.957787 2026] [security2:error] [pid 67073:tid 67324] [client 52.139.47.57:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/x.php"] [unique_id "aoSAvPcmepr5_nHgLbNa1gAAAos"] [Tue Aug 18 12:56:45.025849 2026] [security2:error] [pid 67073:tid 67273] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xf.php"] [unique_id "aoSAvfcmepr5_nHgLbNa1wAAAlg"] [Tue Aug 18 12:56:45.042363 2026] [security2:error] [pid 67073:tid 67271] [client 20.163.43.14:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fmplast.com.br"] [uri "/item.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2AAAAlY"] [Tue Aug 18 12:56:45.075000 2026] [security2:error] [pid 67073:tid 67226] [client 40.85.222.29:12668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2QAAAik"] [Tue Aug 18 12:56:45.079595 2026] [security2:error] [pid 67073:tid 67274] [client 20.102.65.165:8226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "aoSAvfcmepr5_nHgLbNa2gAAAlk"] [Tue Aug 18 12:56:45.100624 2026] [security2:error] [pid 67073:tid 67088] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/@fs/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3AACgAw"] [Tue Aug 18 12:56:45.105556 2026] [security2:error] [pid 67073:tid 67130] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/staging/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3gACgDY"] [Tue Aug 18 12:56:45.112952 2026] [security2:error] [pid 67073:tid 67193] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/docker/.env"] [unique_id "aoSAvfcmepr5_nHgLbNa3wACjHU"] [Tue Aug 18 12:56:45.114191 2026] [security2:error] [pid 67073:tid 67147] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.production.bak"] [unique_id "aoSAvfcmepr5_nHgLbNa4AACjEc"] [Tue Aug 18 12:56:45.128009 2026] [security2:error] [pid 67073:tid 67131] [remote 34.158.8.33:32976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSAvfcmepr5_nHgLbNa4gACPjc"] [Tue Aug 18 12:56:45.144917 2026] [security2:error] [pid 66623:tid 66873] [client 135.225.75.187:18783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/erty.php"] [unique_id "aoSAvdO5rbWdOArH04KMbQAAAXU"] [Tue Aug 18 12:56:45.157211 2026] [security2:error] [pid 66623:tid 66851] [client 20.171.51.14:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ut.php"] [unique_id "aoSAvdO5rbWdOArH04KMbgAAAV8"] [Tue Aug 18 12:56:45.227186 2026] [security2:error] [pid 67073:tid 67263] [client 172.202.39.151:65262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/rip.php"] [unique_id "aoSAvfcmepr5_nHgLbNa5AAAAk4"] [Tue Aug 18 12:56:45.274373 2026] [security2:error] [pid 66623:tid 66801] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gb.php"] [unique_id "aoSAvdO5rbWdOArH04KMcQAAAS0"] [Tue Aug 18 12:56:45.309010 2026] [security2:error] [pid 67073:tid 67277] [client 20.206.73.37:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/aa.php"] [unique_id "aoSAvfcmepr5_nHgLbNa6QAAAlw"] [Tue Aug 18 12:56:45.325425 2026] [security2:error] [pid 67073:tid 67198] [remote 34.158.8.33:32976] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "alyauto.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSAvfcmepr5_nHgLbNa7gACaXo"] [Tue Aug 18 12:56:45.334915 2026] [security2:error] [pid 66623:tid 66830] [client 20.102.65.165:8279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/adminner.php"] [unique_id "aoSAvdO5rbWdOArH04KMcwAAAUo"] [Tue Aug 18 12:56:45.348949 2026] [security2:error] [pid 67073:tid 67213] [client 40.85.222.29:12631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8AAAAhw"] [Tue Aug 18 12:56:45.351759 2026] [security2:error] [pid 66623:tid 66821] [client 20.186.30.159:13678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.osecs.com.br.fokuss.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvdO5rbWdOArH04KMdgAAAUE"] [Tue Aug 18 12:56:45.362245 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:52786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8QAAAic"] [Tue Aug 18 12:56:45.362340 2026] [security2:error] [pid 67073:tid 67224] [client 103.120.71.157:52786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8QAAAic"] [Tue Aug 18 12:56:45.373257 2026] [security2:error] [pid 67073:tid 67251] [client 52.139.47.57:38991] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "whm.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8wAAAkI"] [Tue Aug 18 12:56:45.373343 2026] [security2:error] [pid 67073:tid 67251] [client 52.139.47.57:38991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa8wAAAkI"] [Tue Aug 18 12:56:45.393241 2026] [security2:error] [pid 67073:tid 67234] [client 20.215.241.237:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAvfcmepr5_nHgLbNa9QAAAjE"] [Tue Aug 18 12:56:45.395121 2026] [security2:error] [pid 66623:tid 66713] [remote 162.55.89.48:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSAvdO5rbWdOArH04KMdwABUkw"] [Tue Aug 18 12:56:45.401747 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:45.402125 2026] [authz_core:error] [pid 67073:tid 67154] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:45.408833 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAvfcmepr5_nHgLbNa9wAAAiQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:45.490179 2026] [security2:error] [pid 67073:tid 67305] [client 52.139.47.57:44621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-QAAAng"] [Tue Aug 18 12:56:45.528240 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8033] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.sortis.net"] [uri "/wp-content/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-wAAAjM"] [Tue Aug 18 12:56:45.528371 2026] [security2:error] [pid 67073:tid 67236] [client 20.52.168.85:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/1.php"] [unique_id "aoSAvfcmepr5_nHgLbNa-wAAAjM"] [Tue Aug 18 12:56:45.528776 2026] [security2:error] [pid 67073:tid 67208] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jp.php"] [unique_id "aoSAvfcmepr5_nHgLbNa_AAAAhc"] [Tue Aug 18 12:56:45.582057 2026] [security2:error] [pid 66623:tid 66892] [client 20.102.65.165:8197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/abcd.php"] [unique_id "aoSAvdO5rbWdOArH04KMewAAAYg"] [Tue Aug 18 12:56:45.609345 2026] [security2:error] [pid 66623:tid 66812] [client 20.215.241.237:17839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/wpxml.php"] [unique_id "aoSAvdO5rbWdOArH04KMfgAAATg"] [Tue Aug 18 12:56:45.620105 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAvdO5rbWdOArH04KMfwAAARs"] [Tue Aug 18 12:56:45.631303 2026] [security2:error] [pid 67073:tid 67328] [client 40.85.222.29:13291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSAvfcmepr5_nHgLbNbAgAAAo8"] [Tue Aug 18 12:56:45.653379 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.154.236:16312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAvfcmepr5_nHgLbNbBAAAApE"] [Tue Aug 18 12:56:45.701487 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:45.701808 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:45.709541 2026] [security2:error] [pid 66623:tid 66893] [client 20.100.169.31:25885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/elp.php"] [unique_id "aoSAvdO5rbWdOArH04KMgQAAAYk"] [Tue Aug 18 12:56:45.789946 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eq.php"] [unique_id "aoSAvdO5rbWdOArH04KMgwAAASg"] [Tue Aug 18 12:56:45.802545 2026] [security2:error] [pid 66623:tid 66880] [client 52.139.47.57:19945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/z.php"] [unique_id "aoSAvdO5rbWdOArH04KMhAAAAXw"] [Tue Aug 18 12:56:45.814837 2026] [security2:error] [pid 66623:tid 66775] [client 52.173.121.69:17930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAvdO5rbWdOArH04KMhQAAARM"] [Tue Aug 18 12:56:45.821755 2026] [security2:error] [pid 66623:tid 66785] [client 104.209.144.33:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/index/function.php"] [unique_id "aoSAvdO5rbWdOArH04KMhgAAAR0"] [Tue Aug 18 12:56:45.833618 2026] [security2:error] [pid 67073:tid 67249] [client 158.158.34.183:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/atomlib.php"] [unique_id "aoSAvfcmepr5_nHgLbNbCgAAAkA"] [Tue Aug 18 12:56:45.910651 2026] [security2:error] [pid 67073:tid 67209] [client 40.85.222.29:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSAvfcmepr5_nHgLbNbDgAAAhg"] [Tue Aug 18 12:56:45.912790 2026] [security2:error] [pid 67073:tid 67315] [client 132.196.30.78:21703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/min.php"] [unique_id "aoSAvfcmepr5_nHgLbNbDwAAAoI"] [Tue Aug 18 12:56:45.929960 2026] [security2:error] [pid 67073:tid 67246] [client 20.171.51.14:43340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/eh.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEAAAAj0"] [Tue Aug 18 12:56:45.953056 2026] [security2:error] [pid 67073:tid 67228] [client 103.184.169.37:41978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEQAAAis"] [Tue Aug 18 12:56:45.953149 2026] [security2:error] [pid 67073:tid 67228] [client 103.184.169.37:41978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEQAAAis"] [Tue Aug 18 12:56:45.958918 2026] [security2:error] [pid 67073:tid 67257] [client 158.158.74.177:2647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/size.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEgAAAkg"] [Tue Aug 18 12:56:45.961954 2026] [security2:error] [pid 67073:tid 67292] [client 172.202.39.151:42979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/images/images/about.php"] [unique_id "aoSAvfcmepr5_nHgLbNbEwAAAms"] [Tue Aug 18 12:56:45.962074 2026] [security2:error] [pid 67073:tid 67267] [client 52.139.47.57:39039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-admin.php"] [unique_id "aoSAvfcmepr5_nHgLbNbFAAAAlI"] [Tue Aug 18 12:56:45.993056 2026] [security2:error] [pid 67073:tid 67219] [client 135.225.75.187:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mini.php"] [unique_id "aoSAvfcmepr5_nHgLbNbHAAAAiI"] [Tue Aug 18 12:56:46.023279 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:7911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAvvcmepr5_nHgLbNbJwAAAjs"] [Tue Aug 18 12:56:46.051453 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ep.php"] [unique_id "aoSAvvcmepr5_nHgLbNbKAAAAi4"] [Tue Aug 18 12:56:46.149494 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:28252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/q.php"] [unique_id "aoSAvvcmepr5_nHgLbNbSQAAAlg"] [Tue Aug 18 12:56:46.210189 2026] [security2:error] [pid 66623:tid 66842] [client 40.85.222.29:13232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSAvtO5rbWdOArH04KMjQAAAVY"] [Tue Aug 18 12:56:46.226766 2026] [security2:error] [pid 67073:tid 67287] [client 79.127.164.8:54408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/messageinstallmysql.bak"] [unique_id "aoSAvvcmepr5_nHgLbNbUQAAAmY"], referer: https://medihub.com.br/messageinstallmysql.bak [Tue Aug 18 12:56:46.231347 2026] [security2:error] [pid 67073:tid 67293] [client 52.139.47.57:44657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ee.php"] [unique_id "aoSAvvcmepr5_nHgLbNbUgAAAmw"] [Tue Aug 18 12:56:46.314795 2026] [security2:error] [pid 67073:tid 67122] [remote 47.86.33.52:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSAvvcmepr5_nHgLbNbVQACci4"] [Tue Aug 18 12:56:46.336777 2026] [security2:error] [pid 66623:tid 66854] [client 20.52.168.85:8050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/user/index.php"] [unique_id "aoSAvtO5rbWdOArH04KMkAAAAWI"] [Tue Aug 18 12:56:46.351843 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rf.php"] [unique_id "aoSAvtO5rbWdOArH04KMkQAAATk"] [Tue Aug 18 12:56:46.363298 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.169.31:7954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/vx.php"] [unique_id "aoSAvtO5rbWdOArH04KMkwAAAUw"] [Tue Aug 18 12:56:46.368586 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.136.165:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/koiy.php"] [unique_id "aoSAvtO5rbWdOArH04KMlAAAAWk"] [Tue Aug 18 12:56:46.423656 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAvtO5rbWdOArH04KMlgAAAVM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:46.488008 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSAvtO5rbWdOArH04KMlwAAAWA"] [Tue Aug 18 12:56:46.531653 2026] [security2:error] [pid 66623:tid 66788] [client 20.65.69.59:3242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/vbseo.php"] [unique_id "aoSAvtO5rbWdOArH04KMmgAAASA"] [Tue Aug 18 12:56:46.572033 2026] [security2:error] [pid 67073:tid 67224] [client 52.139.47.57:44645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSAvvcmepr5_nHgLbNbjwAAAic"] [Tue Aug 18 12:56:46.599169 2026] [security2:error] [pid 66623:tid 66786] [client 20.215.241.237:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAvtO5rbWdOArH04KMngAAAR4"] [Tue Aug 18 12:56:46.606935 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:46.607336 2026] [authz_core:error] [pid 67073:tid 67077] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:46.614538 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xynz1.php"] [unique_id "aoSAvtO5rbWdOArH04KMnwAAAYI"] [Tue Aug 18 12:56:46.622531 2026] [security2:error] [pid 67073:tid 67310] [client 158.23.17.4:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/rex.php"] [unique_id "aoSAvvcmepr5_nHgLbNbkwAAAn0"] [Tue Aug 18 12:56:46.685059 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:16289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/index/function.php"] [unique_id "aoSAvvcmepr5_nHgLbNblwAAAo8"] [Tue Aug 18 12:56:46.691946 2026] [security2:error] [pid 67073:tid 67253] [client 52.139.47.57:16698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/we.php"] [unique_id "aoSAvvcmepr5_nHgLbNbmAAAAkQ"] [Tue Aug 18 12:56:46.699716 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAvvcmepr5_nHgLbNbmgAAAh4"] [Tue Aug 18 12:56:46.724546 2026] [security2:error] [pid 66623:tid 66879] [client 132.196.30.78:21902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/php8.php"] [unique_id "aoSAvtO5rbWdOArH04KMowAAAXs"] [Tue Aug 18 12:56:46.747605 2026] [security2:error] [pid 67073:tid 67300] [client 74.7.175.162:43292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scaclinic.com.br"] [uri "/index.php"] [unique_id "aoSAvfcmepr5_nHgLbNa_gACcx8"] [Tue Aug 18 12:56:46.767766 2026] [security2:error] [pid 66623:tid 66809] [client 40.85.222.29:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSAvtO5rbWdOArH04KMpAAAATU"] [Tue Aug 18 12:56:46.840648 2026] [security2:error] [pid 66623:tid 66867] [client 135.225.75.187:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sid3.php"] [unique_id "aoSAvtO5rbWdOArH04KMpwAAAW8"] [Tue Aug 18 12:56:46.845469 2026] [security2:error] [pid 66623:tid 66877] [client 114.119.144.200:20913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designstonego.com.br"] [uri "/arquitetura-sacra/"] [unique_id "aoSAvtO5rbWdOArH04KMqAAAAXk"], referer: https://designstonego.com.br/produtos/ [Tue Aug 18 12:56:46.876427 2026] [security2:error] [pid 66623:tid 66840] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vo.php"] [unique_id "aoSAvtO5rbWdOArH04KMqwAAAVQ"] [Tue Aug 18 12:56:46.907829 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:46.908269 2026] [authz_core:error] [pid 67073:tid 67168] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:46.979023 2026] [security2:error] [pid 67073:tid 67216] [client 20.116.17.175:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/root.php"] [unique_id "aoSAvvcmepr5_nHgLbNbqgAAAh8"] [Tue Aug 18 12:56:46.981595 2026] [security2:error] [pid 67073:tid 67244] [client 20.215.241.237:37669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/file1221.php"] [unique_id "aoSAvvcmepr5_nHgLbNbqwAAAjs"] [Tue Aug 18 12:56:47.062697 2026] [security2:error] [pid 66623:tid 66868] [client 40.85.222.29:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/rezor.php"] [unique_id "aoSAv9O5rbWdOArH04KMsAAAAXA"] [Tue Aug 18 12:56:47.109510 2026] [security2:error] [pid 67073:tid 67219] [client 52.139.47.57:47647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/to.php"] [unique_id "aoSAv_cmepr5_nHgLbNb0wAAAiI"] [Tue Aug 18 12:56:47.132369 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.98.162:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/mosty.php"] [unique_id "aoSAv_cmepr5_nHgLbNb1QAAAko"] [Tue Aug 18 12:56:47.133971 2026] [security2:error] [pid 67073:tid 67294] [client 172.202.39.151:38647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb1gAAAm0"] [Tue Aug 18 12:56:47.137527 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wu.php"] [unique_id "aoSAv9O5rbWdOArH04KMswAAARU"] [Tue Aug 18 12:56:47.158020 2026] [security2:error] [pid 67073:tid 67327] [client 20.52.168.85:7773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/adminer.php"] [unique_id "aoSAv_cmepr5_nHgLbNb2AAAAo4"] [Tue Aug 18 12:56:47.185403 2026] [security2:error] [pid 66623:tid 66836] [client 172.202.39.151:28681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ms-edit.php"] [unique_id "aoSAv9O5rbWdOArH04KMtAAAAVA"] [Tue Aug 18 12:56:47.207122 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:47.207387 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:47.211537 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.56.190:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xf.php"] [unique_id "aoSAv_cmepr5_nHgLbNb3QAAAmY"] [Tue Aug 18 12:56:47.220864 2026] [security2:error] [pid 67073:tid 67293] [client 20.171.51.14:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ad.php"] [unique_id "aoSAv_cmepr5_nHgLbNb3wAAAmw"] [Tue Aug 18 12:56:47.263087 2026] [security2:error] [pid 67073:tid 67273] [client 132.196.30.78:18654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb4gAAAlg"] [Tue Aug 18 12:56:47.265101 2026] [security2:error] [pid 66623:tid 66826] [client 20.206.73.37:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/av.php"] [unique_id "aoSAv9O5rbWdOArH04KMtgAAAUY"] [Tue Aug 18 12:56:47.269758 2026] [security2:error] [pid 67073:tid 67212] [client 158.158.34.183:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAv_cmepr5_nHgLbNb4wAAAhs"] [Tue Aug 18 12:56:47.302189 2026] [security2:error] [pid 67073:tid 67275] [client 20.100.169.31:25449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAv_cmepr5_nHgLbNb5AAAAlo"] [Tue Aug 18 12:56:47.353784 2026] [security2:error] [pid 66623:tid 66869] [client 40.85.222.29:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSAv9O5rbWdOArH04KMuQAAAXE"] [Tue Aug 18 12:56:47.354914 2026] [security2:error] [pid 67073:tid 67289] [client 104.209.144.33:19610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAv_cmepr5_nHgLbNb5gAAAmg"] [Tue Aug 18 12:56:47.393715 2026] [security2:error] [pid 66623:tid 66824] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/de.php"] [unique_id "aoSAv9O5rbWdOArH04KMuwAAAUQ"] [Tue Aug 18 12:56:47.415219 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:3728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sysinfo.php"] [unique_id "aoSAv9O5rbWdOArH04KMvwAAAQs"] [Tue Aug 18 12:56:47.430022 2026] [security2:error] [pid 66623:tid 66798] [client 158.158.74.177:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/special.php"] [unique_id "aoSAv9O5rbWdOArH04KMwQAAASo"] [Tue Aug 18 12:56:47.440188 2026] [security2:error] [pid 66623:tid 66848] [client 213.35.127.232:61865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAv9O5rbWdOArH04KMwgAAAVw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:47.461581 2026] [security2:error] [pid 67073:tid 67245] [client 52.173.121.69:17956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAv_cmepr5_nHgLbNb9QAAAjw"] [Tue Aug 18 12:56:47.491436 2026] [security2:error] [pid 66623:tid 66830] [client 20.215.241.237:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSAv9O5rbWdOArH04KMxAAAAUo"] [Tue Aug 18 12:56:47.510159 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:47.510451 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:47.512464 2026] [security2:error] [pid 67073:tid 67205] [client 52.139.47.57:18391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAv_cmepr5_nHgLbNb_gAAAhQ"] [Tue Aug 18 12:56:47.533968 2026] [security2:error] [pid 66623:tid 66802] [client 52.139.47.57:44648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ty.php"] [unique_id "aoSAv9O5rbWdOArH04KMxwAAAS4"] [Tue Aug 18 12:56:47.608647 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.136.165:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/iko.php"] [unique_id "aoSAv_cmepr5_nHgLbNcCAAAAmE"] [Tue Aug 18 12:56:47.644972 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAv_cmepr5_nHgLbNcEAAAAis"] [Tue Aug 18 12:56:47.649498 2026] [security2:error] [pid 67073:tid 67267] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/album.php"] [unique_id "aoSAv_cmepr5_nHgLbNcEgAAAlI"] [Tue Aug 18 12:56:47.675481 2026] [security2:error] [pid 66623:tid 66837] [client 135.225.75.187:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/moon.php"] [unique_id "aoSAv9O5rbWdOArH04KMywAAAVE"] [Tue Aug 18 12:56:47.713179 2026] [security2:error] [pid 67073:tid 67227] [client 68.155.154.236:39641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/weozh.php"] [unique_id "aoSAv_cmepr5_nHgLbNcIgAAAio"] [Tue Aug 18 12:56:47.735543 2026] [security2:error] [pid 67073:tid 67214] [client 172.182.200.96:7645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/uploads/bypass.php"] [unique_id "aoSAv_cmepr5_nHgLbNcJQAAAh0"] [Tue Aug 18 12:56:47.769449 2026] [security2:error] [pid 67073:tid 67301] [client 20.52.168.85:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "aoSAv_cmepr5_nHgLbNcKgAAAnQ"] [Tue Aug 18 12:56:47.874192 2026] [security2:error] [pid 66623:tid 66796] [client 68.155.154.236:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAv9O5rbWdOArH04KM0QAAASg"] [Tue Aug 18 12:56:47.874930 2026] [security2:error] [pid 67073:tid 67327] [client 132.196.30.78:18790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/222.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMAAAAo4"] [Tue Aug 18 12:56:47.878375 2026] [security2:error] [pid 67073:tid 67325] [client 5.31.227.224:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMgAAAow"] [Tue Aug 18 12:56:47.878481 2026] [security2:error] [pid 67073:tid 67325] [client 5.31.227.224:59012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAv_cmepr5_nHgLbNcMgAAAow"] [Tue Aug 18 12:56:47.904141 2026] [security2:error] [pid 66623:tid 66775] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kv.php"] [unique_id "aoSAv9O5rbWdOArH04KM0gAAARM"] [Tue Aug 18 12:56:47.953673 2026] [security2:error] [pid 67073:tid 67241] [client 145.239.69.153:38036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siderurgiabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSAv_cmepr5_nHgLbNcPwAAAjg"] [Tue Aug 18 12:56:47.953783 2026] [security2:error] [pid 67073:tid 67241] [client 145.239.69.153:38036] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "siderurgiabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSAv_cmepr5_nHgLbNcPwAAAjg"] [Tue Aug 18 12:56:47.967018 2026] [security2:error] [pid 67073:tid 67280] [client 45.92.229.112:39913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSAv_cmepr5_nHgLbNcLAAAAl8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:56:47.968154 2026] [security2:error] [pid 67073:tid 67258] [client 40.85.222.29:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/index/function.php"] [unique_id "aoSAv_cmepr5_nHgLbNcQQAAAkk"] [Tue Aug 18 12:56:47.972806 2026] [security2:error] [pid 67073:tid 67212] [client 52.139.47.57:38978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ak.php"] [unique_id "aoSAv_cmepr5_nHgLbNcQwAAAhs"] [Tue Aug 18 12:56:47.979430 2026] [security2:error] [pid 67073:tid 67268] [client 20.171.51.14:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/vd.php"] [unique_id "aoSAv_cmepr5_nHgLbNcRAAAAlM"] [Tue Aug 18 12:56:47.984942 2026] [autoindex:error] [pid 67073:tid 67213] [client 172.202.39.151:50190] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:48.001355 2026] [security2:error] [pid 66623:tid 66875] [client 20.215.241.237:57751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/222.php"] [unique_id "aoSAwNO5rbWdOArH04KM1QAAAXc"] [Tue Aug 18 12:56:48.079655 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwNO5rbWdOArH04KM1wAAAXU"] [Tue Aug 18 12:56:48.079766 2026] [security2:error] [pid 66623:tid 66873] [client 37.40.227.74:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwNO5rbWdOArH04KM1wAAAXU"] [Tue Aug 18 12:56:48.098341 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.169.31:48609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/666.php"] [unique_id "aoSAwNO5rbWdOArH04KM2QAAAXw"] [Tue Aug 18 12:56:48.143500 2026] [security2:error] [pid 67073:tid 67310] [client 20.116.17.175:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/fpwch.php"] [unique_id "aoSAwPcmepr5_nHgLbNcSgAAAn0"] [Tue Aug 18 12:56:48.152201 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/z.php"] [unique_id "aoSAwPcmepr5_nHgLbNcTAAAAhQ"] [Tue Aug 18 12:56:48.224862 2026] [security2:error] [pid 66623:tid 66776] [client 20.100.169.31:48129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wap.php"] [unique_id "aoSAwNO5rbWdOArH04KM3gAAARQ"] [Tue Aug 18 12:56:48.238038 2026] [security2:error] [pid 67073:tid 67207] [client 74.7.228.4:39670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fokuss.com.br"] [uri "/index.php"] [unique_id "aoSAvfcmepr5_nHgLbNa4wACFkQ"] [Tue Aug 18 12:56:48.245576 2026] [security2:error] [pid 67073:tid 67223] [client 168.119.96.239:26608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.stampi.ind.br"] [uri "/index.html"] [unique_id "aoSAwPcmepr5_nHgLbNcWQAAAiY"], referer: http://www.stampi.ind.br/ [Tue Aug 18 12:56:48.254979 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAwNO5rbWdOArH04KM4gAAAWk"] [Tue Aug 18 12:56:48.278987 2026] [security2:error] [pid 67073:tid 67315] [client 172.202.39.151:50190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcYQAAAoI"] [Tue Aug 18 12:56:48.405475 2026] [security2:error] [pid 67073:tid 67264] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xg.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbAAAAk8"] [Tue Aug 18 12:56:48.414368 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:48.414795 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:48.418106 2026] [security2:error] [pid 67073:tid 67262] [client 20.65.69.59:3407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ppinfo.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbQAAAk0"] [Tue Aug 18 12:56:48.436022 2026] [security2:error] [pid 67073:tid 67243] [client 157.20.138.62:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbwAAAjo"] [Tue Aug 18 12:56:48.436111 2026] [security2:error] [pid 67073:tid 67243] [client 157.20.138.62:62282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNcbwAAAjo"] [Tue Aug 18 12:56:48.449240 2026] [security2:error] [pid 67073:tid 67249] [client 132.196.30.78:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSAwPcmepr5_nHgLbNccAAAAkA"] [Tue Aug 18 12:56:48.452308 2026] [security2:error] [pid 66623:tid 66842] [client 213.35.127.232:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAwNO5rbWdOArH04KM6AAAAVY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:48.473902 2026] [security2:error] [pid 66623:tid 66793] [client 20.206.73.37:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/media.php"] [unique_id "aoSAwNO5rbWdOArH04KM6QAAASU"] [Tue Aug 18 12:56:48.488871 2026] [security2:error] [pid 66623:tid 66786] [client 135.225.75.187:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms.php"] [unique_id "aoSAwNO5rbWdOArH04KM6gAAAR4"] [Tue Aug 18 12:56:48.503529 2026] [security2:error] [pid 66623:tid 66806] [client 52.139.47.57:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/fm.php"] [unique_id "aoSAwNO5rbWdOArH04KM7AAAATI"] [Tue Aug 18 12:56:48.540120 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/Cachex.php"] [unique_id "aoSAwPcmepr5_nHgLbNcfAAAAoc"] [Tue Aug 18 12:56:48.549662 2026] [security2:error] [pid 67073:tid 67220] [client 172.202.39.151:38640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/rip.php"] [unique_id "aoSAwPcmepr5_nHgLbNcfgAAAiM"] [Tue Aug 18 12:56:48.558124 2026] [security2:error] [pid 67073:tid 67302] [client 68.155.154.236:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/rymmm.php"] [unique_id "aoSAwPcmepr5_nHgLbNcgAAAAnU"] [Tue Aug 18 12:56:48.585738 2026] [security2:error] [pid 67073:tid 67227] [client 20.52.168.85:8042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wso.php"] [unique_id "aoSAwPcmepr5_nHgLbNcgwAAAio"] [Tue Aug 18 12:56:48.637465 2026] [security2:error] [pid 67073:tid 67254] [client 68.155.156.252:19385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/mac.php"] [unique_id "aoSAwPcmepr5_nHgLbNchgAAAkU"] [Tue Aug 18 12:56:48.651495 2026] [security2:error] [pid 66623:tid 66841] [client 52.139.47.57:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSAwNO5rbWdOArH04KM9QAAAVU"] [Tue Aug 18 12:56:48.657957 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/nd.php"] [unique_id "aoSAwNO5rbWdOArH04KM9wAAAW0"] [Tue Aug 18 12:56:48.684738 2026] [security2:error] [pid 66623:tid 66781] [client 52.173.121.69:16472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAwNO5rbWdOArH04KM-QAAARk"] [Tue Aug 18 12:56:48.709889 2026] [security2:error] [pid 67073:tid 67321] [client 20.215.241.237:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSAwPcmepr5_nHgLbNciQAAAog"] [Tue Aug 18 12:56:48.716190 2026] [security2:error] [pid 67073:tid 67285] [client 20.215.241.237:36271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/nox.php"] [unique_id "aoSAwPcmepr5_nHgLbNciwAAAmQ"] [Tue Aug 18 12:56:48.787933 2026] [security2:error] [pid 66623:tid 66808] [client 20.171.51.14:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/56.php"] [unique_id "aoSAwNO5rbWdOArH04KM-wAAATQ"] [Tue Aug 18 12:56:48.790220 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:16278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/Cachex.php"] [unique_id "aoSAwPcmepr5_nHgLbNcjQAAAkE"] [Tue Aug 18 12:56:48.810872 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.136.165:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/raw.php"] [unique_id "aoSAwPcmepr5_nHgLbNcjgAAAl4"] [Tue Aug 18 12:56:48.829817 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwPcmepr5_nHgLbNckAAAAo0"] [Tue Aug 18 12:56:48.866910 2026] [security2:error] [pid 67073:tid 67256] [client 149.34.210.141:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNckgAAAkc"] [Tue Aug 18 12:56:48.913390 2026] [security2:error] [pid 67073:tid 67212] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ri.php"] [unique_id "aoSAwPcmepr5_nHgLbNclAAAAhs"] [Tue Aug 18 12:56:49.016989 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:49.017420 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:49.047857 2026] [security2:error] [pid 67073:tid 67258] [client 52.139.47.57:19923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp.php"] [unique_id "aoSAwfcmepr5_nHgLbNcqgAAAkk"] [Tue Aug 18 12:56:49.048606 2026] [security2:error] [pid 67073:tid 67299] [client 132.196.30.78:21906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/info.php"] [unique_id "aoSAwfcmepr5_nHgLbNcqwAAAnI"] [Tue Aug 18 12:56:49.057361 2026] [security2:error] [pid 67073:tid 67205] [client 20.65.69.59:3758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/globals.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrAAAAhQ"] [Tue Aug 18 12:56:49.069345 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/Cachex.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrQAAAjk"] [Tue Aug 18 12:56:49.105075 2026] [security2:error] [pid 66623:tid 66888] [client 158.158.74.177:16573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSAwdO5rbWdOArH04KNBwAAAYQ"] [Tue Aug 18 12:56:49.114729 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAwfcmepr5_nHgLbNcrgAAAlQ"] [Tue Aug 18 12:56:49.140296 2026] [security2:error] [pid 67073:tid 67256] [client 149.34.210.141:54938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwPcmepr5_nHgLbNckgAAAkc"] [Tue Aug 18 12:56:49.176622 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tp.php"] [unique_id "aoSAwfcmepr5_nHgLbNcsQAAAh4"] [Tue Aug 18 12:56:49.193072 2026] [security2:error] [pid 67073:tid 67272] [client 20.52.168.85:8058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-admin/css/index.php"] [unique_id "aoSAwfcmepr5_nHgLbNcsgAAAlc"] [Tue Aug 18 12:56:49.257613 2026] [security2:error] [pid 67073:tid 67281] [client 20.100.169.31:25861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ws54.php"] [unique_id "aoSAwfcmepr5_nHgLbNcuQAAAmA"] [Tue Aug 18 12:56:49.275682 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.154.236:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/lddxs.php"] [unique_id "aoSAwdO5rbWdOArH04KNDAAAAWc"] [Tue Aug 18 12:56:49.280351 2026] [security2:error] [pid 67073:tid 67255] [client 20.116.17.175:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/mg.php"] [unique_id "aoSAwfcmepr5_nHgLbNcugAAAkY"] [Tue Aug 18 12:56:49.339829 2026] [security2:error] [pid 67073:tid 67228] [client 135.225.75.187:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wsws.php"] [unique_id "aoSAwfcmepr5_nHgLbNcuwAAAis"] [Tue Aug 18 12:56:49.395972 2026] [security2:error] [pid 67073:tid 67331] [client 172.202.39.151:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/moon.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvAAAApI"] [Tue Aug 18 12:56:49.397343 2026] [security2:error] [pid 66623:tid 66846] [client 40.85.222.29:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAwdO5rbWdOArH04KNDQAAAVo"] [Tue Aug 18 12:56:49.412568 2026] [security2:error] [pid 66623:tid 66869] [client 52.173.121.69:17927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAwdO5rbWdOArH04KNDgAAAXE"] [Tue Aug 18 12:56:49.431981 2026] [security2:error] [pid 67073:tid 67222] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/zj.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvQAAAiU"] [Tue Aug 18 12:56:49.463302 2026] [security2:error] [pid 67073:tid 67330] [client 213.35.127.232:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAwfcmepr5_nHgLbNcvwAAApE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:49.464226 2026] [security2:error] [pid 67073:tid 67296] [client 52.139.47.57:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/33.php"] [unique_id "aoSAwfcmepr5_nHgLbNcwQAAAm8"] [Tue Aug 18 12:56:49.512602 2026] [security2:error] [pid 66623:tid 66767] [client 20.171.51.14:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/rx.php"] [unique_id "aoSAwdO5rbWdOArH04KNEgAAAQs"] [Tue Aug 18 12:56:49.600187 2026] [autoindex:error] [pid 67073:tid 67286] [client 172.202.39.151:44886] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:49.612739 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:49.612997 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:49.626285 2026] [security2:error] [pid 66623:tid 66847] [client 47.128.53.184:38906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.icemaq.com.br"] [uri "/robots.txt"] [unique_id "aoSAwdO5rbWdOArH04KNFQAAAVs"] [Tue Aug 18 12:56:49.660532 2026] [security2:error] [pid 67073:tid 67264] [client 79.127.164.8:54454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/messageinstallmysql.sql"] [unique_id "aoSAwfcmepr5_nHgLbNcywAAAk8"], referer: https://medihub.com.br/messageinstallmysql.sql [Tue Aug 18 12:56:49.694393 2026] [security2:error] [pid 67073:tid 67227] [client 40.85.222.29:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAwfcmepr5_nHgLbNczgAAAio"] [Tue Aug 18 12:56:49.717978 2026] [security2:error] [pid 67073:tid 67306] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/x.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0AAAAnk"] [Tue Aug 18 12:56:49.727455 2026] [security2:error] [pid 66623:tid 66826] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNFAABRg8"] [Tue Aug 18 12:56:49.738585 2026] [security2:error] [pid 67073:tid 67254] [client 20.215.241.237:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0QAAAkU"] [Tue Aug 18 12:56:49.792691 2026] [security2:error] [pid 67073:tid 67220] [client 20.52.168.85:8060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/mah.php"] [unique_id "aoSAwfcmepr5_nHgLbNc0gAAAiM"] [Tue Aug 18 12:56:49.881901 2026] [security2:error] [pid 67073:tid 67170] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/phpinfo.php"] [unique_id "aoSAwfcmepr5_nHgLbNc1gACIV4"] [Tue Aug 18 12:56:49.913868 2026] [security2:error] [pid 67073:tid 67241] [client 20.116.17.175:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/reop3.php"] [unique_id "aoSAwfcmepr5_nHgLbNc2gAAAjg"] [Tue Aug 18 12:56:49.936244 2026] [security2:error] [pid 67073:tid 67159] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/info.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3AACZlM"] [Tue Aug 18 12:56:49.943737 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zjggu.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3gAAAl8"] [Tue Aug 18 12:56:49.946159 2026] [security2:error] [pid 67073:tid 67290] [client 172.202.39.151:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/xmlrpc.php"] [unique_id "aoSAwfcmepr5_nHgLbNc3wAAAmk"] [Tue Aug 18 12:56:49.974951 2026] [security2:error] [pid 67073:tid 67212] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yn.php"] [unique_id "aoSAwfcmepr5_nHgLbNc4QAAAhs"] [Tue Aug 18 12:56:49.982996 2026] [security2:error] [pid 66623:tid 66892] [client 40.85.222.29:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAwdO5rbWdOArH04KNIQAAAYg"] [Tue Aug 18 12:56:49.995840 2026] [security2:error] [pid 66623:tid 66769] [client 178.153.171.161:47143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNIgAAAQ0"] [Tue Aug 18 12:56:49.995995 2026] [security2:error] [pid 66623:tid 66769] [client 178.153.171.161:47143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwdO5rbWdOArH04KNIgAAAQ0"] [Tue Aug 18 12:56:50.061084 2026] [security2:error] [pid 67073:tid 67297] [client 74.248.136.165:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/05.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5AAAAnA"] [Tue Aug 18 12:56:50.080192 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mandrill.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5gAAAjI"] [Tue Aug 18 12:56:50.087563 2026] [security2:error] [pid 67073:tid 67284] [client 52.139.47.57:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/az.php"] [unique_id "aoSAwvcmepr5_nHgLbNc5wAAAmM"] [Tue Aug 18 12:56:50.116491 2026] [security2:error] [pid 67073:tid 67319] [client 138.36.100.162:42886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6AAAAoY"] [Tue Aug 18 12:56:50.177967 2026] [security2:error] [pid 67073:tid 67078] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/pi.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6gACNAI"] [Tue Aug 18 12:56:50.179410 2026] [security2:error] [pid 67073:tid 67157] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/i.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6wACLFE"] [Tue Aug 18 12:56:50.197255 2026] [security2:error] [pid 67073:tid 67214] [client 20.250.13.23:21847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAwvcmepr5_nHgLbNc7gAAAh0"] [Tue Aug 18 12:56:50.200456 2026] [security2:error] [pid 67073:tid 67161] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/test.php"] [unique_id "aoSAwvcmepr5_nHgLbNc7wACOVU"] [Tue Aug 18 12:56:50.237215 2026] [security2:error] [pid 66623:tid 66876] [client 135.225.75.187:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/motu.php"] [unique_id "aoSAwtO5rbWdOArH04KNJwAAAXg"] [Tue Aug 18 12:56:50.269558 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAwvcmepr5_nHgLbNc8AAAAkc"] [Tue Aug 18 12:56:50.302488 2026] [security2:error] [pid 67073:tid 67184] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/app_dev.php"] [unique_id "aoSAwvcmepr5_nHgLbNc8wACVWw"] [Tue Aug 18 12:56:50.306868 2026] [security2:error] [pid 67073:tid 67215] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/11.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9AAAAh4"] [Tue Aug 18 12:56:50.347153 2026] [security2:error] [pid 66623:tid 66875] [client 20.65.98.162:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/blurbs.php"] [unique_id "aoSAwtO5rbWdOArH04KNLgAAAXc"] [Tue Aug 18 12:56:50.376754 2026] [security2:error] [pid 67073:tid 67283] [client 114.5.214.109:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9wAAAmI"] [Tue Aug 18 12:56:50.376923 2026] [security2:error] [pid 67073:tid 67283] [client 114.5.214.109:49812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc9wAAAmI"] [Tue Aug 18 12:56:50.384100 2026] [security2:error] [pid 67073:tid 67198] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alyauto.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSAwvcmepr5_nHgLbNc-AACdno"] [Tue Aug 18 12:56:50.397436 2026] [security2:error] [pid 67073:tid 67307] [client 20.52.168.85:7819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/about.php"] [unique_id "aoSAwvcmepr5_nHgLbNc-QAAAno"] [Tue Aug 18 12:56:50.423171 2026] [security2:error] [pid 66623:tid 66880] [client 104.209.144.33:29839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwtO5rbWdOArH04KNNAAAAXw"] [Tue Aug 18 12:56:50.478189 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAwvcmepr5_nHgLbNc_gAAAn0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:50.493974 2026] [security2:error] [pid 67073:tid 67319] [client 138.36.100.162:42886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAwvcmepr5_nHgLbNc6AAAAoY"] [Tue Aug 18 12:56:50.513311 2026] [security2:error] [pid 66623:tid 66890] [client 20.116.17.175:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/php5.php"] [unique_id "aoSAwtO5rbWdOArH04KNOwAAAYY"] [Tue Aug 18 12:56:50.519301 2026] [security2:error] [pid 67073:tid 67228] [client 20.65.69.59:3761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/yindu.php"] [unique_id "aoSAwvcmepr5_nHgLbNdAgAAAis"] [Tue Aug 18 12:56:50.520317 2026] [authz_core:error] [pid 67073:tid 67088] [remote 57.141.22.56:29018] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:50.520701 2026] [authz_core:error] [pid 67073:tid 67088] [remote 57.141.22.56:29018] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:50.556752 2026] [security2:error] [pid 66623:tid 66839] [client 40.85.222.29:12626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAwtO5rbWdOArH04KNPgAAAVM"] [Tue Aug 18 12:56:50.562578 2026] [security2:error] [pid 67073:tid 67267] [client 68.155.154.236:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSAwvcmepr5_nHgLbNdBwAAAlI"] [Tue Aug 18 12:56:50.573328 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vm.php"] [unique_id "aoSAwtO5rbWdOArH04KNQQAAATE"] [Tue Aug 18 12:56:50.578442 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.154.236:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/dlvqo.php"] [unique_id "aoSAwtO5rbWdOArH04KNQwAAAT8"] [Tue Aug 18 12:56:50.631994 2026] [security2:error] [pid 66623:tid 66889] [client 132.196.30.78:21947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/a.php"] [unique_id "aoSAwtO5rbWdOArH04KNRAAAAYU"] [Tue Aug 18 12:56:50.726750 2026] [security2:error] [pid 67073:tid 67292] [client 52.139.47.57:9048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/sx.php"] [unique_id "aoSAwvcmepr5_nHgLbNdDwAAAms"] [Tue Aug 18 12:56:50.736662 2026] [security2:error] [pid 66623:tid 66786] [client 40.74.65.169:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAwtO5rbWdOArH04KNSgAAAR4"] [Tue Aug 18 12:56:50.817798 2026] [security2:error] [pid 67073:tid 67231] [client 52.139.47.57:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-mail.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEAAAAi4"] [Tue Aug 18 12:56:50.820196 2026] [security2:error] [pid 66623:tid 66845] [client 84.247.146.84:53430] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSAwtO5rbWdOArH04KNUAAAAVk"] [Tue Aug 18 12:56:50.832629 2026] [security2:error] [pid 67073:tid 67314] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eg.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEgAAAoE"] [Tue Aug 18 12:56:50.842069 2026] [security2:error] [pid 67073:tid 67112] [remote 103.56.163.133:38562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSAwvcmepr5_nHgLbNdEwACdSQ"] [Tue Aug 18 12:56:50.845436 2026] [security2:error] [pid 67073:tid 67318] [client 40.85.222.29:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAwvcmepr5_nHgLbNdFAAAAoU"] [Tue Aug 18 12:56:50.849676 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:48595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSAwvcmepr5_nHgLbNdFQAAAog"] [Tue Aug 18 12:56:50.866475 2026] [security2:error] [pid 67073:tid 67227] [client 158.23.17.4:63656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/verification.php"] [unique_id "aoSAwvcmepr5_nHgLbNdGAAAAio"] [Tue Aug 18 12:56:50.912830 2026] [security2:error] [pid 67073:tid 67199] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/api/.env"] [unique_id "aoSAwvcmepr5_nHgLbNdGQACRXs"] [Tue Aug 18 12:56:50.925868 2026] [access_compat:error] [pid 67073:tid 67106] [remote 34.158.8.33:32992] AH01797: client denied by server configuration: /home3/alyautocom/public_html/server-status [Tue Aug 18 12:56:50.931558 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/cache.php"] [unique_id "aoSAwtO5rbWdOArH04KNVwAAATU"] [Tue Aug 18 12:56:50.935301 2026] [security2:error] [pid 66623:tid 66883] [client 20.171.51.14:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/main.php"] [unique_id "aoSAwtO5rbWdOArH04KNWAAAAX8"] [Tue Aug 18 12:56:51.006679 2026] [security2:error] [pid 67073:tid 67277] [client 85.154.68.202:52046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHAAAAlw"] [Tue Aug 18 12:56:51.006847 2026] [security2:error] [pid 67073:tid 67277] [client 85.154.68.202:52046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHAAAAlw"] [Tue Aug 18 12:56:51.013214 2026] [security2:error] [pid 66623:tid 66855] [client 20.52.168.85:7827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/sid3.php"] [unique_id "aoSAw9O5rbWdOArH04KNXAAAAWM"] [Tue Aug 18 12:56:51.042756 2026] [security2:error] [pid 67073:tid 67250] [client 192.141.172.134:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHgAAAkE"] [Tue Aug 18 12:56:51.042869 2026] [security2:error] [pid 67073:tid 67250] [client 192.141.172.134:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHgAAAkE"] [Tue Aug 18 12:56:51.049678 2026] [security2:error] [pid 67073:tid 67241] [client 20.116.17.175:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/acp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdHwAAAjg"] [Tue Aug 18 12:56:51.053878 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:31591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/akismet.php"] [unique_id "aoSAw_cmepr5_nHgLbNdIAAAAo0"] [Tue Aug 18 12:56:51.069792 2026] [security2:error] [pid 66623:tid 66832] [client 160.120.140.123:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAw9O5rbWdOArH04KNZQAAAUw"] [Tue Aug 18 12:56:51.069883 2026] [security2:error] [pid 66623:tid 66832] [client 160.120.140.123:62982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAw9O5rbWdOArH04KNZQAAAUw"] [Tue Aug 18 12:56:51.137407 2026] [security2:error] [pid 66623:tid 66823] [client 40.85.222.29:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAw9O5rbWdOArH04KNaAAAAUM"] [Tue Aug 18 12:56:51.143122 2026] [security2:error] [pid 67073:tid 67101] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/backend/.env"] [unique_id "aoSAw_cmepr5_nHgLbNdKwAChxk"] [Tue Aug 18 12:56:51.150372 2026] [security2:error] [pid 67073:tid 67102] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/config/.env"] [unique_id "aoSAw_cmepr5_nHgLbNdLgAChxo"] [Tue Aug 18 12:56:51.161016 2026] [security2:error] [pid 67073:tid 67325] [client 52.139.47.57:44627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/tfm.php"] [unique_id "aoSAw_cmepr5_nHgLbNdLwAAAow"] [Tue Aug 18 12:56:51.210551 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:19398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/chosen.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMQAAAl4"] [Tue Aug 18 12:56:51.250369 2026] [security2:error] [pid 67073:tid 67234] [client 20.65.69.59:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sxx.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMgAAAjE"] [Tue Aug 18 12:56:51.251942 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.56.190:30990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gb.php"] [unique_id "aoSAw_cmepr5_nHgLbNdMwAAAjI"] [Tue Aug 18 12:56:51.310097 2026] [security2:error] [pid 66623:tid 66824] [client 20.206.73.37:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/images.php"] [unique_id "aoSAw9O5rbWdOArH04KNcgAAAUQ"] [Tue Aug 18 12:56:51.419078 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:51.419347 2026] [authz_core:error] [pid 67073:tid 67150] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:51.421411 2026] [security2:error] [pid 66623:tid 66847] [client 74.248.136.165:22509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/public/hi.php"] [unique_id "aoSAw9O5rbWdOArH04KNdgAAAVs"] [Tue Aug 18 12:56:51.426246 2026] [security2:error] [pid 67073:tid 67329] [client 158.23.17.4:9298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/smtp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPQAAApA"] [Tue Aug 18 12:56:51.430320 2026] [security2:error] [pid 67073:tid 67246] [client 40.85.222.29:12609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPgAAAj0"] [Tue Aug 18 12:56:51.435545 2026] [security2:error] [pid 67073:tid 67208] [client 40.74.65.169:28202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAw_cmepr5_nHgLbNdPwAAAhc"] [Tue Aug 18 12:56:51.459560 2026] [security2:error] [pid 67073:tid 67266] [client 135.225.75.187:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fff.php"] [unique_id "aoSAw_cmepr5_nHgLbNdQQAAAlE"] [Tue Aug 18 12:56:51.498978 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAw9O5rbWdOArH04KNgAAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:51.532782 2026] [security2:error] [pid 67073:tid 67300] [client 52.139.47.57:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-the.php"] [unique_id "aoSAw_cmepr5_nHgLbNdQwAAAnM"] [Tue Aug 18 12:56:51.564147 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.56.190:45049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jp.php"] [unique_id "aoSAw9O5rbWdOArH04KNgwAAASY"] [Tue Aug 18 12:56:51.576911 2026] [security2:error] [pid 67073:tid 67294] [client 20.250.13.23:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/themes.php"] [unique_id "aoSAw_cmepr5_nHgLbNdRwAAAm0"] [Tue Aug 18 12:56:51.604306 2026] [authz_core:error] [pid 67073:tid 67187] [remote 57.141.0.37:48816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:51.604594 2026] [authz_core:error] [pid 67073:tid 67187] [remote 57.141.0.37:48816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:51.611876 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/uk.php"] [unique_id "aoSAw9O5rbWdOArH04KNhQAAAYg"] [Tue Aug 18 12:56:51.614084 2026] [security2:error] [pid 66623:tid 66798] [client 20.52.168.85:7766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/blog.php7"] [unique_id "aoSAw9O5rbWdOArH04KNhgAAASo"] [Tue Aug 18 12:56:51.655081 2026] [security2:error] [pid 67073:tid 67216] [client 52.139.47.57:38987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/asd.php"] [unique_id "aoSAw_cmepr5_nHgLbNdUQAAAh8"] [Tue Aug 18 12:56:51.666000 2026] [security2:error] [pid 66623:tid 66640] [remote 97.74.87.194:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSAw9O5rbWdOArH04KNiQABewM"] [Tue Aug 18 12:56:51.701060 2026] [security2:error] [pid 67073:tid 67225] [client 20.65.69.59:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/settings.php"] [unique_id "aoSAw_cmepr5_nHgLbNdVAAAAig"] [Tue Aug 18 12:56:51.708611 2026] [security2:error] [pid 66623:tid 66802] [client 132.196.30.78:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAw9O5rbWdOArH04KNigAAAS4"] [Tue Aug 18 12:56:51.713934 2026] [security2:error] [pid 67073:tid 67230] [client 40.85.222.29:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSAw_cmepr5_nHgLbNdVgAAAi0"] [Tue Aug 18 12:56:51.715815 2026] [security2:error] [pid 67073:tid 67275] [client 20.215.241.237:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp.php"] [unique_id "aoSAw_cmepr5_nHgLbNdWAAAAlo"] [Tue Aug 18 12:56:51.725646 2026] [authz_core:error] [pid 67073:tid 67202] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:51.725935 2026] [authz_core:error] [pid 67073:tid 67202] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:51.743263 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.154.236:7914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/pkmoj.php"] [unique_id "aoSAw9O5rbWdOArH04KNkAAAAUs"] [Tue Aug 18 12:56:51.794538 2026] [fcgid:warn] [pid 67073:tid 67286] (70014)End of file found: [client 66.132.186.168:16060] mod_fcgid: can't get data from http client [Tue Aug 18 12:56:51.859859 2026] [security2:error] [pid 66623:tid 66857] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/creds.php"] [unique_id "aoSAw9O5rbWdOArH04KNlAAAAWU"] [Tue Aug 18 12:56:51.902416 2026] [security2:error] [pid 67073:tid 67227] [client 20.171.51.14:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ga.php"] [unique_id "aoSAw_cmepr5_nHgLbNdYAAAAio"] [Tue Aug 18 12:56:52.009303 2026] [security2:error] [pid 67073:tid 67263] [client 40.85.222.29:13207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSAxPcmepr5_nHgLbNdZgAAAk4"] [Tue Aug 18 12:56:52.051924 2026] [security2:error] [pid 67073:tid 67304] [client 172.182.200.96:14198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSAxPcmepr5_nHgLbNdaAAAAnc"] [Tue Aug 18 12:56:52.054410 2026] [security2:error] [pid 67073:tid 67250] [client 20.116.17.175:57633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/yas.php"] [unique_id "aoSAxPcmepr5_nHgLbNdaQAAAkE"] [Tue Aug 18 12:56:52.082328 2026] [security2:error] [pid 67073:tid 67125] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env"] [unique_id "aoSAxPcmepr5_nHgLbNdawACODE"] [Tue Aug 18 12:56:52.118220 2026] [security2:error] [pid 67073:tid 67280] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ho.php"] [unique_id "aoSAxPcmepr5_nHgLbNdbAAAAl8"] [Tue Aug 18 12:56:52.133852 2026] [security2:error] [pid 67073:tid 67268] [client 40.74.65.169:27772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/domvf.php"] [unique_id "aoSAxPcmepr5_nHgLbNdbwAAAlM"] [Tue Aug 18 12:56:52.147173 2026] [security2:error] [pid 67073:tid 67243] [client 20.100.169.31:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAxPcmepr5_nHgLbNdcAAAAjo"] [Tue Aug 18 12:56:52.218867 2026] [security2:error] [pid 66623:tid 66780] [client 20.52.168.85:8020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/GOD.php"] [unique_id "aoSAxNO5rbWdOArH04KNmwAAARg"] [Tue Aug 18 12:56:52.240358 2026] [security2:error] [pid 67073:tid 67218] [client 52.139.47.57:16677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp.php"] [unique_id "aoSAxPcmepr5_nHgLbNddAAAAiE"] [Tue Aug 18 12:56:52.251053 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/vx.php"] [unique_id "aoSAxPcmepr5_nHgLbNddgAAAmY"] [Tue Aug 18 12:56:52.272946 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.69.59:49295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/spip.php"] [unique_id "aoSAxPcmepr5_nHgLbNddwAAAiw"] [Tue Aug 18 12:56:52.320465 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:52.320735 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:52.335535 2026] [security2:error] [pid 67073:tid 67200] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.github/.env"] [unique_id "aoSAxPcmepr5_nHgLbNdegACFnw"] [Tue Aug 18 12:56:52.338347 2026] [security2:error] [pid 67073:tid 67309] [client 40.85.222.29:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfAAAAnw"] [Tue Aug 18 12:56:52.340112 2026] [security2:error] [pid 67073:tid 67283] [client 172.202.39.151:43249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/ok.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfQAAAmI"] [Tue Aug 18 12:56:52.345767 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.34.183:55823] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aesexaustores.com.br"] [uri "/1.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfgAAAik"] [Tue Aug 18 12:56:52.345877 2026] [security2:error] [pid 67073:tid 67226] [client 158.158.34.183:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/1.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfgAAAik"] [Tue Aug 18 12:56:52.386410 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/97.php"] [unique_id "aoSAxPcmepr5_nHgLbNdfwAAAko"] [Tue Aug 18 12:56:52.388996 2026] [security2:error] [pid 67073:tid 67209] [client 74.248.136.165:28126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/get.php"] [unique_id "aoSAxPcmepr5_nHgLbNdgAAAAhg"] [Tue Aug 18 12:56:52.408307 2026] [security2:error] [pid 67073:tid 67203] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.backup"] [unique_id "aoSAxPcmepr5_nHgLbNdggACfX8"] [Tue Aug 18 12:56:52.427991 2026] [autoindex:error] [pid 67073:tid 67251] [client 172.202.39.151:55448] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:52.429153 2026] [security2:error] [pid 67073:tid 67319] [client 135.225.75.187:47220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/66.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhQAAAoY"] [Tue Aug 18 12:56:52.432615 2026] [security2:error] [pid 67073:tid 67332] [client 158.158.74.177:2653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/storage/index.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhgAAApM"] [Tue Aug 18 12:56:52.456022 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:30105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/moon.php"] [unique_id "aoSAxPcmepr5_nHgLbNdhwAAAhc"] [Tue Aug 18 12:56:52.481269 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSAxPcmepr5_nHgLbNdiAAAAhk"] [Tue Aug 18 12:56:52.500263 2026] [security2:error] [pid 67073:tid 67253] [client 104.209.144.33:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-2019.php"] [unique_id "aoSAxPcmepr5_nHgLbNdiQAAAkQ"] [Tue Aug 18 12:56:52.513957 2026] [security2:error] [pid 67073:tid 67325] [client 213.35.127.232:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAxPcmepr5_nHgLbNdigAAAow"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:52.541761 2026] [security2:error] [pid 66623:tid 66889] [client 20.206.73.37:20705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/admin.php"] [unique_id "aoSAxNO5rbWdOArH04KNpAAAAYU"] [Tue Aug 18 12:56:52.602378 2026] [security2:error] [pid 67073:tid 67222] [client 158.23.17.4:38907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/teste.php"] [unique_id "aoSAxPcmepr5_nHgLbNdjwAAAiU"] [Tue Aug 18 12:56:52.610766 2026] [security2:error] [pid 66623:tid 66785] [client 52.139.47.57:18200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/nij.php"] [unique_id "aoSAxNO5rbWdOArH04KNpgAAAR0"] [Tue Aug 18 12:56:52.615622 2026] [security2:error] [pid 67073:tid 67282] [client 20.215.241.237:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/i.php"] [unique_id "aoSAxPcmepr5_nHgLbNdkAAAAmE"] [Tue Aug 18 12:56:52.622937 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:52.623193 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:52.624394 2026] [security2:error] [pid 67073:tid 67248] [client 40.85.222.29:12634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSAxPcmepr5_nHgLbNdkgAAAj8"] [Tue Aug 18 12:56:52.644751 2026] [security2:error] [pid 67073:tid 67153] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.bak"] [unique_id "aoSAxPcmepr5_nHgLbNdlAACLU0"] [Tue Aug 18 12:56:52.644752 2026] [security2:error] [pid 67073:tid 67155] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.env.old"] [unique_id "aoSAxPcmepr5_nHgLbNdlQACLU8"] [Tue Aug 18 12:56:52.698915 2026] [security2:error] [pid 66623:tid 66796] [client 157.51.166.53:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxNO5rbWdOArH04KNqgAAASg"] [Tue Aug 18 12:56:52.699058 2026] [security2:error] [pid 66623:tid 66796] [client 157.51.166.53:63083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxNO5rbWdOArH04KNqgAAASg"] [Tue Aug 18 12:56:52.699979 2026] [security2:error] [pid 66623:tid 66858] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rh.php"] [unique_id "aoSAxNO5rbWdOArH04KNqwAAAWY"] [Tue Aug 18 12:56:52.709837 2026] [security2:error] [pid 67073:tid 67249] [client 20.100.169.31:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/function/function.php"] [unique_id "aoSAxPcmepr5_nHgLbNdnQAAAkA"] [Tue Aug 18 12:56:52.786153 2026] [security2:error] [pid 67073:tid 67291] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAxPcmepr5_nHgLbNdoAACaj8"] [Tue Aug 18 12:56:52.817244 2026] [security2:error] [pid 67073:tid 67296] [client 20.52.168.85:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/alumni_reg.php"] [unique_id "aoSAxPcmepr5_nHgLbNdogAAAm8"] [Tue Aug 18 12:56:52.837586 2026] [security2:error] [pid 66623:tid 66814] [client 40.74.65.169:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSAxNO5rbWdOArH04KNrgAAATo"] [Tue Aug 18 12:56:52.837710 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:58894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/kopyw.php"] [unique_id "aoSAxNO5rbWdOArH04KNrwAAASs"] [Tue Aug 18 12:56:52.893933 2026] [security2:error] [pid 67073:tid 67317] [client 20.116.17.175:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ah25.php"] [unique_id "aoSAxPcmepr5_nHgLbNdpQAAAoQ"] [Tue Aug 18 12:56:52.920499 2026] [security2:error] [pid 67073:tid 67232] [client 40.85.222.29:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqAAAAi8"] [Tue Aug 18 12:56:52.927067 2026] [security2:error] [pid 67073:tid 67263] [client 20.65.69.59:49309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/search.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqQAAAk4"] [Tue Aug 18 12:56:52.929679 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:52.930114 2026] [authz_core:error] [pid 67073:tid 67183] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:52.965846 2026] [security2:error] [pid 67073:tid 67304] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/yg.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqgAAAnc"] [Tue Aug 18 12:56:52.978025 2026] [security2:error] [pid 67073:tid 67225] [client 20.100.169.31:7714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bgymj.php"] [unique_id "aoSAxPcmepr5_nHgLbNdqwAAAig"] [Tue Aug 18 12:56:52.987801 2026] [authz_core:error] [pid 67073:tid 67194] [remote 34.158.8.33:32992] AH01630: client denied by server configuration: /home3/alyautocom/public_html/.htpasswd [Tue Aug 18 12:56:52.987893 2026] [security2:error] [pid 67073:tid 67276] [client 52.139.47.57:44647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wso.php"] [unique_id "aoSAxPcmepr5_nHgLbNdrwAAAls"] [Tue Aug 18 12:56:53.010264 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.156.252:40229] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "email.domcoworking.com.br"] [uri "/1.php"] [unique_id "aoSAxdO5rbWdOArH04KNtAAAAW8"] [Tue Aug 18 12:56:53.010378 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.156.252:40229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/1.php"] [unique_id "aoSAxdO5rbWdOArH04KNtAAAAW8"] [Tue Aug 18 12:56:53.027741 2026] [security2:error] [pid 67073:tid 67212] [client 172.202.39.151:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAxfcmepr5_nHgLbNdsQAAAhs"] [Tue Aug 18 12:56:53.035788 2026] [security2:error] [pid 67073:tid 67100] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSAxfcmepr5_nHgLbNdswACUxg"] [Tue Aug 18 12:56:53.118882 2026] [security2:error] [pid 66623:tid 66832] [client 158.23.17.4:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/local.php"] [unique_id "aoSAxdO5rbWdOArH04KNuAAAAUw"] [Tue Aug 18 12:56:53.179777 2026] [security2:error] [pid 67073:tid 67305] [client 49.13.134.145:6936] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/"] [unique_id "aoSAxfcmepr5_nHgLbNdtwAAAng"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 12:56:53.201432 2026] [security2:error] [pid 66623:tid 66793] [client 40.85.222.29:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSAxdO5rbWdOArH04KNugAAASU"] [Tue Aug 18 12:56:53.212188 2026] [security2:error] [pid 67073:tid 67320] [client 52.139.47.57:63055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/404.php"] [unique_id "aoSAxfcmepr5_nHgLbNduQAAAoc"] [Tue Aug 18 12:56:53.215041 2026] [security2:error] [pid 66623:tid 66816] [client 132.196.30.78:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wap.php"] [unique_id "aoSAxdO5rbWdOArH04KNvAAAATw"] [Tue Aug 18 12:56:53.243389 2026] [security2:error] [pid 67073:tid 67226] [client 20.171.51.14:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/wb.php"] [unique_id "aoSAxfcmepr5_nHgLbNduwAAAik"] [Tue Aug 18 12:56:53.293695 2026] [security2:error] [pid 67073:tid 67281] [client 20.215.241.237:59481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/abcd.php"] [unique_id "aoSAxfcmepr5_nHgLbNdvwAAAmA"] [Tue Aug 18 12:56:53.299486 2026] [security2:error] [pid 67073:tid 67209] [client 52.173.121.69:16467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAxfcmepr5_nHgLbNdwAAAAhg"] [Tue Aug 18 12:56:53.405765 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:36509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNdxQAAAjk"] [Tue Aug 18 12:56:53.424583 2026] [security2:error] [pid 67073:tid 67287] [client 20.52.168.85:7824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/depotcv.php"] [unique_id "aoSAxfcmepr5_nHgLbNdxgAAAmY"] [Tue Aug 18 12:56:53.428508 2026] [security2:error] [pid 67073:tid 67315] [client 20.250.13.23:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/cv.php"] [unique_id "aoSAxfcmepr5_nHgLbNdyAAAAoI"] [Tue Aug 18 12:56:53.505039 2026] [security2:error] [pid 67073:tid 67098] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSAxfcmepr5_nHgLbNdywACjxY"] [Tue Aug 18 12:56:53.526944 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:53.527212 2026] [authz_core:error] [pid 67073:tid 67159] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:53.535312 2026] [security2:error] [pid 67073:tid 67236] [client 213.35.127.232:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAxfcmepr5_nHgLbNdzQAAAjM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:53.537547 2026] [security2:error] [pid 67073:tid 67221] [client 40.74.65.169:27038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gec.php"] [unique_id "aoSAxfcmepr5_nHgLbNdzgAAAiQ"] [Tue Aug 18 12:56:53.548064 2026] [security2:error] [pid 67073:tid 67330] [client 40.85.222.29:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNd0AAAApE"] [Tue Aug 18 12:56:53.574999 2026] [security2:error] [pid 67073:tid 67294] [client 20.65.69.59:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/build.php"] [unique_id "aoSAxfcmepr5_nHgLbNd0QAAAm0"] [Tue Aug 18 12:56:53.586682 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zznmg.php"] [unique_id "aoSAxdO5rbWdOArH04KN0wAAAYA"] [Tue Aug 18 12:56:53.610573 2026] [security2:error] [pid 66623:tid 66803] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/et.php"] [unique_id "aoSAxdO5rbWdOArH04KN1AAAAS8"] [Tue Aug 18 12:56:53.619178 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.formedesign.com.br"] [uri "/item.php"] [unique_id "aoSAxdO5rbWdOArH04KN1QAAAUk"] [Tue Aug 18 12:56:53.633403 2026] [security2:error] [pid 67073:tid 67273] [client 52.139.47.57:1501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/mah.php"] [unique_id "aoSAxfcmepr5_nHgLbNd1AAAAlg"] [Tue Aug 18 12:56:53.682375 2026] [security2:error] [pid 67073:tid 67275] [client 20.116.17.175:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/ano.php"] [unique_id "aoSAxfcmepr5_nHgLbNd2AAAAlo"] [Tue Aug 18 12:56:53.682416 2026] [security2:error] [pid 66623:tid 66782] [client 47.128.36.158:65518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "reservamatadapraia.com.br"] [uri "/robots.txt"] [unique_id "aoSAxdO5rbWdOArH04KN2gAAARo"] [Tue Aug 18 12:56:53.721870 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.56.190:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eq.php"] [unique_id "aoSAxdO5rbWdOArH04KN2wAAAQs"] [Tue Aug 18 12:56:53.734819 2026] [security2:error] [pid 66623:tid 66888] [client 52.139.47.57:11762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/www.php"] [unique_id "aoSAxdO5rbWdOArH04KN3AAAAYQ"] [Tue Aug 18 12:56:53.752268 2026] [security2:error] [pid 67073:tid 67205] [client 158.158.74.177:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/storage/rip.php"] [unique_id "aoSAxfcmepr5_nHgLbNd2wAAAhQ"] [Tue Aug 18 12:56:53.768907 2026] [security2:error] [pid 67073:tid 67219] [client 172.202.39.151:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/cache.php"] [unique_id "aoSAxfcmepr5_nHgLbNd3gAAAiI"] [Tue Aug 18 12:56:53.825127 2026] [security2:error] [pid 67073:tid 67296] [client 20.171.51.14:29238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/xn.php"] [unique_id "aoSAxfcmepr5_nHgLbNd4wAAAm8"] [Tue Aug 18 12:56:53.830059 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:53.830320 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:53.853063 2026] [security2:error] [pid 67073:tid 67185] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSAxfcmepr5_nHgLbNd5QACZG0"] [Tue Aug 18 12:56:53.854882 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSAxfcmepr5_nHgLbNd5gAAAis"] [Tue Aug 18 12:56:53.887255 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/of.php"] [unique_id "aoSAxdO5rbWdOArH04KOFwAAAVc"] [Tue Aug 18 12:56:53.913079 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:18006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/rpk.php"] [unique_id "aoSAxfcmepr5_nHgLbNd5wAAAjU"] [Tue Aug 18 12:56:53.954775 2026] [security2:error] [pid 67073:tid 67304] [client 20.206.73.37:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/222.php"] [unique_id "aoSAxfcmepr5_nHgLbNd6AAAAnc"] [Tue Aug 18 12:56:53.988924 2026] [security2:error] [pid 66623:tid 66824] [client 132.196.30.78:21914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSAxdO5rbWdOArH04KOGQAAAUQ"] [Tue Aug 18 12:56:53.996542 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:29475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSAxdO5rbWdOArH04KOGwAAAQ0"] [Tue Aug 18 12:56:54.025917 2026] [security2:error] [pid 67073:tid 67254] [client 20.52.168.85:7804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin.php7"] [unique_id "aoSAxvcmepr5_nHgLbNd6gAAAkU"] [Tue Aug 18 12:56:54.084342 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAxvcmepr5_nHgLbNd7AAAAn4"] [Tue Aug 18 12:56:54.084441 2026] [security2:error] [pid 67073:tid 67311] [client 196.12.128.158:51736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSAxvcmepr5_nHgLbNd7AAAAn4"] [Tue Aug 18 12:56:54.087514 2026] [security2:error] [pid 67073:tid 67118] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/id_rsa"] [unique_id "aoSAxvcmepr5_nHgLbNd7QACICo"] [Tue Aug 18 12:56:54.129933 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:54.130198 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:54.131771 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8QAAAlY"] [Tue Aug 18 12:56:54.137886 2026] [security2:error] [pid 66623:tid 66848] [client 52.139.47.57:47643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ws.php7"] [unique_id "aoSAxtO5rbWdOArH04KOJwAAAVw"] [Tue Aug 18 12:56:54.142515 2026] [security2:error] [pid 67073:tid 67261] [client 40.85.222.29:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/well-known/index.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8gAAAkw"] [Tue Aug 18 12:56:54.171811 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bu.php"] [unique_id "aoSAxvcmepr5_nHgLbNd8wAAAho"] [Tue Aug 18 12:56:54.176189 2026] [security2:error] [pid 67073:tid 67239] [client 20.215.241.237:31607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dtbbrasil.com.br"] [uri "/ajax.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9AAAAjY"] [Tue Aug 18 12:56:54.179323 2026] [security2:error] [pid 67073:tid 67279] [client 20.116.17.175:57452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/nwflm.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9QAAAl4"] [Tue Aug 18 12:56:54.193742 2026] [security2:error] [pid 67073:tid 67227] [client 20.100.169.31:45609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/aa.php"] [unique_id "aoSAxvcmepr5_nHgLbNd9wAAAio"] [Tue Aug 18 12:56:54.221128 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.56.190:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ep.php"] [unique_id "aoSAxtO5rbWdOArH04KOPgAAAS4"] [Tue Aug 18 12:56:54.230429 2026] [security2:error] [pid 66623:tid 66887] [client 104.209.144.33:25648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/.cache/x.php"] [unique_id "aoSAxtO5rbWdOArH04KOPwAAAYM"] [Tue Aug 18 12:56:54.235394 2026] [security2:error] [pid 66623:tid 66825] [client 40.74.65.169:26747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/sky.php"] [unique_id "aoSAxtO5rbWdOArH04KOQAAAAUU"] [Tue Aug 18 12:56:54.434150 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:54.434599 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:54.445493 2026] [security2:error] [pid 67073:tid 67259] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rn.php"] [unique_id "aoSAxvcmepr5_nHgLbNd-wAAAko"] [Tue Aug 18 12:56:54.452871 2026] [security2:error] [pid 67073:tid 67281] [client 40.85.222.29:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSAxvcmepr5_nHgLbNd_AAAAmA"] [Tue Aug 18 12:56:54.484552 2026] [security2:error] [pid 67073:tid 67164] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/id_dsa"] [unique_id "aoSAxvcmepr5_nHgLbNd_wACXVg"] [Tue Aug 18 12:56:54.512357 2026] [security2:error] [pid 67073:tid 67237] [client 158.158.74.177:26122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/sts.php"] [unique_id "aoSAxvcmepr5_nHgLbNeAAAAAjQ"] [Tue Aug 18 12:56:54.548881 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:63398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAxtO5rbWdOArH04KOaAAAAVg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:54.567188 2026] [security2:error] [pid 66623:tid 66873] [client 52.139.47.57:47652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/jga.php"] [unique_id "aoSAxtO5rbWdOArH04KOaQAAAXU"] [Tue Aug 18 12:56:54.586518 2026] [security2:error] [pid 66623:tid 66890] [client 158.23.17.4:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ninja.php"] [unique_id "aoSAxtO5rbWdOArH04KOawAAAYY"] [Tue Aug 18 12:56:54.592610 2026] [security2:error] [pid 67073:tid 67283] [client 132.196.30.78:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bgymj.php"] [unique_id "aoSAxvcmepr5_nHgLbNeAQAAAmI"] [Tue Aug 18 12:56:54.644553 2026] [security2:error] [pid 66623:tid 66780] [client 20.52.168.85:8053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/f.php"] [unique_id "aoSAxtO5rbWdOArH04KObgAAARg"] [Tue Aug 18 12:56:54.721086 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:56771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/g.php"] [unique_id "aoSAxtO5rbWdOArH04KOcAAAASE"] [Tue Aug 18 12:56:54.729230 2026] [security2:error] [pid 67073:tid 67280] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ut.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBAAAAl8"] [Tue Aug 18 12:56:54.741679 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:40511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBQAAAhk"] [Tue Aug 18 12:56:54.744842 2026] [security2:error] [pid 67073:tid 67269] [client 20.65.69.59:49340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/defaul.php"] [unique_id "aoSAxvcmepr5_nHgLbNeBgAAAlQ"] [Tue Aug 18 12:56:54.770845 2026] [security2:error] [pid 67073:tid 67310] [client 52.139.47.57:47630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/x.php"] [unique_id "aoSAxvcmepr5_nHgLbNeCAAAAn0"] [Tue Aug 18 12:56:54.771363 2026] [security2:error] [pid 66623:tid 66822] [client 40.85.222.29:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSAxtO5rbWdOArH04KOcgAAAUI"] [Tue Aug 18 12:56:54.790400 2026] [security2:error] [pid 67073:tid 67256] [client 20.171.51.14:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/47.php"] [unique_id "aoSAxvcmepr5_nHgLbNeCgAAAkc"] [Tue Aug 18 12:56:54.858999 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:16264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-2019.php"] [unique_id "aoSAxvcmepr5_nHgLbNeEQAAAo8"] [Tue Aug 18 12:56:54.879763 2026] [security2:error] [pid 66623:tid 66858] [client 20.116.17.175:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-load.php"] [unique_id "aoSAxtO5rbWdOArH04KOegAAAWY"] [Tue Aug 18 12:56:54.929535 2026] [security2:error] [pid 67073:tid 67221] [client 40.74.65.169:30068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/sixxis.php"] [unique_id "aoSAxvcmepr5_nHgLbNeFAAAAiQ"] [Tue Aug 18 12:56:54.983894 2026] [security2:error] [pid 67073:tid 67213] [client 52.139.47.57:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/166.php"] [unique_id "aoSAxvcmepr5_nHgLbNeFgAAAhw"] [Tue Aug 18 12:56:55.002383 2026] [security2:error] [pid 67073:tid 67248] [client 20.250.13.23:21857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSAx_cmepr5_nHgLbNeFwAAAj8"] [Tue Aug 18 12:56:55.014081 2026] [security2:error] [pid 66623:tid 66814] [client 104.209.144.33:25642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAx9O5rbWdOArH04KOfgAAATo"] [Tue Aug 18 12:56:55.031150 2026] [security2:error] [pid 67073:tid 67230] [client 68.155.154.236:40326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/bhfnd.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHQAAAi0"] [Tue Aug 18 12:56:55.043706 2026] [security2:error] [pid 66623:tid 66804] [client 197.184.64.235:41933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOggAAATA"] [Tue Aug 18 12:56:55.043835 2026] [security2:error] [pid 66623:tid 66804] [client 197.184.64.235:41933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOggAAATA"] [Tue Aug 18 12:56:55.052507 2026] [security2:error] [pid 67073:tid 67222] [client 49.13.134.145:40024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/index.php"] [unique_id "aoSAxfcmepr5_nHgLbNd3wAAAiU"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 12:56:55.052548 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/eh.php"] [unique_id "aoSAx9O5rbWdOArH04KOgwAAAYI"] [Tue Aug 18 12:56:55.064454 2026] [security2:error] [pid 67073:tid 67231] [client 40.85.222.29:12652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHgAAAi4"] [Tue Aug 18 12:56:55.071349 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.169.31:48603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/nw.php"] [unique_id "aoSAx_cmepr5_nHgLbNeHwAAAjE"] [Tue Aug 18 12:56:55.090957 2026] [security2:error] [pid 67073:tid 67132] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/.hermes/.env"] [unique_id "aoSAx_cmepr5_nHgLbNeIgACgTg"] [Tue Aug 18 12:56:55.130674 2026] [security2:error] [pid 67073:tid 67286] [client 52.173.121.69:16487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAx_cmepr5_nHgLbNeJAAAAmU"] [Tue Aug 18 12:56:55.155666 2026] [security2:error] [pid 66623:tid 66784] [client 20.65.98.162:50884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bajah.php"] [unique_id "aoSAx9O5rbWdOArH04KOhQAAARw"] [Tue Aug 18 12:56:55.188908 2026] [security2:error] [pid 67073:tid 67182] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/key.pem"] [unique_id "aoSAx_cmepr5_nHgLbNeJwACTWo"] [Tue Aug 18 12:56:55.231491 2026] [security2:error] [pid 66623:tid 66787] [client 132.196.30.78:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/aa.php"] [unique_id "aoSAx9O5rbWdOArH04KOigAAAR8"] [Tue Aug 18 12:56:55.241032 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.56.190:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rf.php"] [unique_id "aoSAx_cmepr5_nHgLbNeKgAAAk4"] [Tue Aug 18 12:56:55.244763 2026] [security2:error] [pid 67073:tid 67275] [client 20.52.168.85:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/c.php"] [unique_id "aoSAx_cmepr5_nHgLbNeKwAAAlo"] [Tue Aug 18 12:56:55.270587 2026] [security2:error] [pid 66623:tid 66685] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOiwABJTA"] [Tue Aug 18 12:56:55.270762 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx9O5rbWdOArH04KOiwABJTA"] [Tue Aug 18 12:56:55.289435 2026] [security2:error] [pid 67073:tid 67327] [client 20.116.17.175:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/jj.php"] [unique_id "aoSAx_cmepr5_nHgLbNeLgAAAo4"] [Tue Aug 18 12:56:55.292931 2026] [security2:error] [pid 66623:tid 66838] [client 20.215.241.237:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSAx9O5rbWdOArH04KOjAAAAVI"] [Tue Aug 18 12:56:55.329562 2026] [security2:error] [pid 67073:tid 67241] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ad.php"] [unique_id "aoSAx_cmepr5_nHgLbNeMQAAAjg"] [Tue Aug 18 12:56:55.335561 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:55.335843 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:55.336992 2026] [security2:error] [pid 67073:tid 67158] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "alyauto.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSAx_cmepr5_nHgLbNeMgAChFI"] [Tue Aug 18 12:56:55.392790 2026] [security2:error] [pid 67073:tid 67217] [client 40.85.222.29:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/mt/byp.php"] [unique_id "aoSAx_cmepr5_nHgLbNeMwAAAiA"] [Tue Aug 18 12:56:55.401747 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.136.165:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-blog.php"] [unique_id "aoSAx9O5rbWdOArH04KOjwAAASw"] [Tue Aug 18 12:56:55.455975 2026] [security2:error] [pid 66623:tid 66778] [client 52.139.47.57:11773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/log.php"] [unique_id "aoSAx9O5rbWdOArH04KOkgAAARY"] [Tue Aug 18 12:56:55.465363 2026] [security2:error] [pid 66623:tid 66884] [client 135.225.75.187:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/x7.php"] [unique_id "aoSAx9O5rbWdOArH04KOkwAAAYA"] [Tue Aug 18 12:56:55.489543 2026] [security2:error] [pid 67073:tid 67107] [remote 34.158.8.33:32992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alyauto.com.br"] [uri "/privatekey.key"] [unique_id "aoSAx_cmepr5_nHgLbNeOQACeB8"] [Tue Aug 18 12:56:55.528095 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.69.59:40531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/twin.php"] [unique_id "aoSAx9O5rbWdOArH04KOlwAAAQs"] [Tue Aug 18 12:56:55.542375 2026] [security2:error] [pid 67073:tid 67254] [client 79.127.164.8:54518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/moduleinfoincludemysql/phpcms_info.bak"] [unique_id "aoSAx_cmepr5_nHgLbNeOgAAAkU"], referer: https://medihub.com.br/moduleinfoincludemysql/phpcms_info.bak [Tue Aug 18 12:56:55.560406 2026] [security2:error] [pid 67073:tid 67316] [client 213.35.127.232:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAx_cmepr5_nHgLbNeOwAAAoM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:55.585930 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/vd.php"] [unique_id "aoSAx9O5rbWdOArH04KOmQAAAV8"] [Tue Aug 18 12:56:55.618198 2026] [security2:error] [pid 66623:tid 66770] [client 20.171.51.14:21062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/payout.php"] [unique_id "aoSAx9O5rbWdOArH04KOmwAAAQ4"] [Tue Aug 18 12:56:55.622574 2026] [security2:error] [pid 66623:tid 66843] [client 40.74.65.169:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/yj09.php"] [unique_id "aoSAx9O5rbWdOArH04KOnQAAAVc"] [Tue Aug 18 12:56:55.628456 2026] [security2:error] [pid 67073:tid 67322] [client 158.158.74.177:16549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/system_log.php"] [unique_id "aoSAx_cmepr5_nHgLbNePQAAAok"] [Tue Aug 18 12:56:55.679767 2026] [security2:error] [pid 67073:tid 67282] [client 37.40.227.74:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx_cmepr5_nHgLbNePwAAAmE"] [Tue Aug 18 12:56:55.679898 2026] [security2:error] [pid 67073:tid 67282] [client 37.40.227.74:57006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAx_cmepr5_nHgLbNePwAAAmE"] [Tue Aug 18 12:56:55.706471 2026] [security2:error] [pid 66623:tid 66798] [client 40.85.222.29:12642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSAx9O5rbWdOArH04KOogAAASo"] [Tue Aug 18 12:56:55.815800 2026] [security2:error] [pid 67073:tid 67220] [client 158.158.34.183:42599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRAAAAiM"] [Tue Aug 18 12:56:55.821064 2026] [security2:error] [pid 67073:tid 67278] [client 20.116.17.175:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/img.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRQAAAl0"] [Tue Aug 18 12:56:55.833299 2026] [security2:error] [pid 66623:tid 66818] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/56.php"] [unique_id "aoSAx9O5rbWdOArH04KOpgAAAT4"] [Tue Aug 18 12:56:55.853701 2026] [security2:error] [pid 67073:tid 67249] [client 20.52.168.85:8024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ini.php"] [unique_id "aoSAx_cmepr5_nHgLbNeRwAAAkA"] [Tue Aug 18 12:56:55.892690 2026] [security2:error] [pid 67073:tid 67259] [client 52.139.47.57:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/file.php"] [unique_id "aoSAx_cmepr5_nHgLbNeSAAAAko"] [Tue Aug 18 12:56:55.922360 2026] [security2:error] [pid 66623:tid 66879] [client 158.23.17.4:10977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/phpprobe.php"] [unique_id "aoSAx9O5rbWdOArH04KOqQAAAXs"] [Tue Aug 18 12:56:56.001796 2026] [security2:error] [pid 66623:tid 66893] [client 40.85.222.29:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAyNO5rbWdOArH04KOqwAAAYk"] [Tue Aug 18 12:56:56.017952 2026] [authz_core:error] [pid 67073:tid 67206] [client 192.178.4.134:54606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:56.018214 2026] [authz_core:error] [pid 67073:tid 67206] [client 192.178.4.134:54606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:56.057373 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.154.236:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTAAAAoY"] [Tue Aug 18 12:56:56.057666 2026] [security2:error] [pid 67073:tid 67332] [client 132.196.30.78:26243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTQAAApM"] [Tue Aug 18 12:56:56.074216 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:56365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/god.php"] [unique_id "aoSAyNO5rbWdOArH04KOrQAAAUU"] [Tue Aug 18 12:56:56.086084 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/rx.php"] [unique_id "aoSAyPcmepr5_nHgLbNeTgAAApI"] [Tue Aug 18 12:56:56.189753 2026] [security2:error] [pid 67073:tid 67221] [client 20.171.51.14:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bh.php"] [unique_id "aoSAyPcmepr5_nHgLbNeUQAAAiQ"] [Tue Aug 18 12:56:56.297879 2026] [security2:error] [pid 66623:tid 66880] [client 40.85.222.29:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAyNO5rbWdOArH04KOtQAAAXw"] [Tue Aug 18 12:56:56.301262 2026] [security2:error] [pid 67073:tid 67222] [client 40.74.65.169:27794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/k.php"] [unique_id "aoSAyPcmepr5_nHgLbNeVgAAAiU"] [Tue Aug 18 12:56:56.341342 2026] [security2:error] [pid 66623:tid 66852] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mandrill.php"] [unique_id "aoSAyNO5rbWdOArH04KOtwAAAWA"] [Tue Aug 18 12:56:56.357681 2026] [security2:error] [pid 67073:tid 67236] [client 52.139.47.57:17905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/bolt.php"] [unique_id "aoSAyPcmepr5_nHgLbNeXAAAAjM"] [Tue Aug 18 12:56:56.364018 2026] [autoindex:error] [pid 67073:tid 67314] [client 172.202.39.151:65222] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:56.369145 2026] [security2:error] [pid 66623:tid 66856] [client 20.116.17.175:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/we.php"] [unique_id "aoSAyNO5rbWdOArH04KOuAAAAWQ"] [Tue Aug 18 12:56:56.446360 2026] [security2:error] [pid 67073:tid 67270] [client 20.215.241.237:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/simple.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYAAAAlU"] [Tue Aug 18 12:56:56.450142 2026] [security2:error] [pid 66623:tid 66827] [client 158.23.17.4:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/wp-title.php"] [unique_id "aoSAyNO5rbWdOArH04KOvgAAAUc"] [Tue Aug 18 12:56:56.459303 2026] [security2:error] [pid 67073:tid 67255] [client 20.52.168.85:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/nf.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYQAAAkY"] [Tue Aug 18 12:56:56.486048 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.74.177:16525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/t.php"] [unique_id "aoSAyNO5rbWdOArH04KOvwAAASk"] [Tue Aug 18 12:56:56.517618 2026] [security2:error] [pid 67073:tid 67251] [client 103.184.169.37:42029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYwAAAkI"] [Tue Aug 18 12:56:56.517711 2026] [security2:error] [pid 67073:tid 67251] [client 103.184.169.37:42029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNeYwAAAkI"] [Tue Aug 18 12:56:56.539454 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:56.539707 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:56.557667 2026] [security2:error] [pid 67073:tid 67285] [client 20.65.69.59:3676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/new2.php"] [unique_id "aoSAyPcmepr5_nHgLbNeZQAAAmQ"] [Tue Aug 18 12:56:56.571694 2026] [security2:error] [pid 67073:tid 67244] [client 213.35.127.232:63755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAyPcmepr5_nHgLbNeZgAAAjs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:56.578142 2026] [security2:error] [pid 67073:tid 67277] [client 68.155.154.236:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/.cache/x.php"] [unique_id "aoSAyPcmepr5_nHgLbNeaAAAAlw"] [Tue Aug 18 12:56:56.582259 2026] [security2:error] [pid 67073:tid 67229] [client 20.100.169.31:25914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/xleet.php"] [unique_id "aoSAyPcmepr5_nHgLbNeaQAAAiw"] [Tue Aug 18 12:56:56.587098 2026] [autoindex:error] [pid 67073:tid 67293] [client 172.202.39.151:44980] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:56.597034 2026] [security2:error] [pid 67073:tid 67238] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/main.php"] [unique_id "aoSAyPcmepr5_nHgLbNebAAAAjU"] [Tue Aug 18 12:56:56.653849 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:17931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSAyNO5rbWdOArH04KOwgAAAVY"] [Tue Aug 18 12:56:56.659885 2026] [security2:error] [pid 67073:tid 67225] [client 40.85.222.29:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAyPcmepr5_nHgLbNebgAAAig"] [Tue Aug 18 12:56:56.662320 2026] [security2:error] [pid 67073:tid 67327] [client 172.202.39.151:65222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyPcmepr5_nHgLbNebwAAAo4"] [Tue Aug 18 12:56:56.728002 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.156.252:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/coffee.php"] [unique_id "aoSAyPcmepr5_nHgLbNecAAAAhs"] [Tue Aug 18 12:56:56.770963 2026] [security2:error] [pid 67073:tid 67328] [client 103.120.71.157:10841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecQAAAo8"] [Tue Aug 18 12:56:56.771076 2026] [security2:error] [pid 67073:tid 67328] [client 103.120.71.157:10841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecQAAAo8"] [Tue Aug 18 12:56:56.812998 2026] [security2:error] [pid 67073:tid 67311] [client 192.141.172.134:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecgAAAn4"] [Tue Aug 18 12:56:56.813131 2026] [security2:error] [pid 67073:tid 67311] [client 192.141.172.134:62330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyPcmepr5_nHgLbNecgAAAn4"] [Tue Aug 18 12:56:56.834223 2026] [security2:error] [pid 67073:tid 67317] [client 52.139.47.57:11754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/item.php"] [unique_id "aoSAyPcmepr5_nHgLbNecwAAAoQ"] [Tue Aug 18 12:56:56.847190 2026] [security2:error] [pid 67073:tid 67211] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ga.php"] [unique_id "aoSAyPcmepr5_nHgLbNedAAAAho"] [Tue Aug 18 12:56:56.850404 2026] [security2:error] [pid 67073:tid 67239] [client 20.206.73.37:20699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mac.php"] [unique_id "aoSAyPcmepr5_nHgLbNedQAAAjY"] [Tue Aug 18 12:56:56.942305 2026] [security2:error] [pid 67073:tid 67299] [client 40.85.222.29:12638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAyPcmepr5_nHgLbNedgAAAnI"] [Tue Aug 18 12:56:56.954612 2026] [security2:error] [pid 66623:tid 66809] [client 68.155.154.236:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSAyNO5rbWdOArH04KOzgAAATU"] [Tue Aug 18 12:56:56.989091 2026] [security2:error] [pid 66623:tid 66883] [client 135.225.75.187:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSAyNO5rbWdOArH04KO0AAAAX8"] [Tue Aug 18 12:56:56.996063 2026] [security2:error] [pid 66623:tid 66875] [client 132.196.30.78:19395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bolt.php"] [unique_id "aoSAyNO5rbWdOArH04KO0QAAAXc"] [Tue Aug 18 12:56:57.003055 2026] [security2:error] [pid 67073:tid 67267] [client 40.74.65.169:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/w.php"] [unique_id "aoSAyfcmepr5_nHgLbNeegAAAlI"] [Tue Aug 18 12:56:57.065869 2026] [security2:error] [pid 67073:tid 67235] [client 20.52.168.85:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/room.php"] [unique_id "aoSAyfcmepr5_nHgLbNefAAAAjI"] [Tue Aug 18 12:56:57.100557 2026] [security2:error] [pid 66623:tid 66877] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/wb.php"] [unique_id "aoSAydO5rbWdOArH04KO1QAAAXk"] [Tue Aug 18 12:56:57.143637 2026] [security2:error] [pid 66623:tid 66788] [client 104.209.144.33:21432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/index.php"] [unique_id "aoSAydO5rbWdOArH04KO2AAAASA"] [Tue Aug 18 12:56:57.217977 2026] [security2:error] [pid 66623:tid 66793] [client 20.171.51.14:29212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/ct.php"] [unique_id "aoSAydO5rbWdOArH04KO2gAAASU"] [Tue Aug 18 12:56:57.218988 2026] [security2:error] [pid 67073:tid 67329] [client 40.85.222.29:12629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNefwAAApA"] [Tue Aug 18 12:56:57.245996 2026] [security2:error] [pid 66623:tid 66823] [client 74.248.136.165:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/mga.php"] [unique_id "aoSAydO5rbWdOArH04KO3AAAAUM"] [Tue Aug 18 12:56:57.250631 2026] [security2:error] [pid 67073:tid 67320] [client 20.215.241.237:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/chosen.php"] [unique_id "aoSAyfcmepr5_nHgLbNegAAAAoc"] [Tue Aug 18 12:56:57.261901 2026] [security2:error] [pid 66623:tid 66832] [client 52.139.47.57:39004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/sid3.php"] [unique_id "aoSAydO5rbWdOArH04KO3QAAAUw"] [Tue Aug 18 12:56:57.265753 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.200.96:14203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/index/function.php"] [unique_id "aoSAyfcmepr5_nHgLbNegQAAAlM"] [Tue Aug 18 12:56:57.356177 2026] [security2:error] [pid 67073:tid 67290] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/xn.php"] [unique_id "aoSAyfcmepr5_nHgLbNeggAAAmk"] [Tue Aug 18 12:56:57.396253 2026] [security2:error] [pid 67073:tid 67256] [client 68.155.154.236:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNegwAAAkc"] [Tue Aug 18 12:56:57.401382 2026] [security2:error] [pid 66623:tid 66784] [client 158.158.74.177:2634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/templates.php"] [unique_id "aoSAydO5rbWdOArH04KO4AAAARw"] [Tue Aug 18 12:56:57.433864 2026] [security2:error] [pid 67073:tid 67332] [client 158.23.17.4:9367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/styles.php"] [unique_id "aoSAyfcmepr5_nHgLbNehAAAApM"] [Tue Aug 18 12:56:57.435652 2026] [security2:error] [pid 67073:tid 67331] [client 20.65.98.162:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/h.php"] [unique_id "aoSAyfcmepr5_nHgLbNehgAAApI"] [Tue Aug 18 12:56:57.441644 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:57.441950 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:57.451965 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/qfvqu.php"] [unique_id "aoSAydO5rbWdOArH04KO4gAAAYA"] [Tue Aug 18 12:56:57.463118 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.69.59:3680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/rex.php"] [unique_id "aoSAydO5rbWdOArH04KO4wAAASQ"] [Tue Aug 18 12:56:57.477799 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-mail.php"] [unique_id "aoSAyfcmepr5_nHgLbNehwAAAmI"] [Tue Aug 18 12:56:57.486751 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:19470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bthil.php"] [unique_id "aoSAydO5rbWdOArH04KO5AAAAX4"] [Tue Aug 18 12:56:57.495144 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:12610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNeiAAAAlE"] [Tue Aug 18 12:56:57.584227 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAydO5rbWdOArH04KO6AAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:57.595691 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.56.190:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xynz1.php"] [unique_id "aoSAydO5rbWdOArH04KO6QAAAV8"] [Tue Aug 18 12:56:57.626201 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/47.php"] [unique_id "aoSAyfcmepr5_nHgLbNeiwAAAi4"] [Tue Aug 18 12:56:57.666897 2026] [security2:error] [pid 67073:tid 67233] [client 20.52.168.85:7870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-contentt.php"] [unique_id "aoSAyfcmepr5_nHgLbNejAAAAjA"] [Tue Aug 18 12:56:57.676559 2026] [security2:error] [pid 66623:tid 66864] [client 52.139.47.57:47664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/size.php"] [unique_id "aoSAydO5rbWdOArH04KO7AAAAWw"] [Tue Aug 18 12:56:57.707016 2026] [security2:error] [pid 67073:tid 67270] [client 135.225.75.187:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/8.php"] [unique_id "aoSAyfcmepr5_nHgLbNejwAAAlU"] [Tue Aug 18 12:56:57.710200 2026] [security2:error] [pid 67073:tid 67262] [client 40.74.65.169:42573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fpwch.php"] [unique_id "aoSAyfcmepr5_nHgLbNekAAAAk0"] [Tue Aug 18 12:56:57.719581 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAydO5rbWdOArH04KO7QAAAU8"] [Tue Aug 18 12:56:57.742222 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:57.742504 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:57.746554 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:16213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAyfcmepr5_nHgLbNekgAAAoo"] [Tue Aug 18 12:56:57.775061 2026] [security2:error] [pid 67073:tid 67274] [client 40.85.222.29:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/first.php"] [unique_id "aoSAyfcmepr5_nHgLbNekwAAAlk"] [Tue Aug 18 12:56:57.816660 2026] [security2:error] [pid 67073:tid 67209] [client 20.100.169.31:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp.php"] [unique_id "aoSAyfcmepr5_nHgLbNelQAAAhg"] [Tue Aug 18 12:56:57.826402 2026] [security2:error] [pid 67073:tid 67251] [client 20.171.51.14:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/gy.php"] [unique_id "aoSAyfcmepr5_nHgLbNelgAAAkI"] [Tue Aug 18 12:56:57.837616 2026] [security2:error] [pid 66623:tid 66766] [client 158.158.34.183:42615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSAydO5rbWdOArH04KO8gAAAQo"] [Tue Aug 18 12:56:57.891175 2026] [security2:error] [pid 66623:tid 66848] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/payout.php"] [unique_id "aoSAydO5rbWdOArH04KO9QAAAVw"] [Tue Aug 18 12:56:58.100537 2026] [security2:error] [pid 67073:tid 67241] [client 40.85.222.29:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNenAAAAjg"] [Tue Aug 18 12:56:58.144457 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bh.php"] [unique_id "aoSAytO5rbWdOArH04KO_QAAAYg"] [Tue Aug 18 12:56:58.181828 2026] [security2:error] [pid 66623:tid 66826] [client 52.139.47.57:18375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/tgrs.php"] [unique_id "aoSAytO5rbWdOArH04KO_gAAAUY"] [Tue Aug 18 12:56:58.188568 2026] [security2:error] [pid 67073:tid 67223] [client 132.196.30.78:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/x.php"] [unique_id "aoSAyvcmepr5_nHgLbNengAAAiY"] [Tue Aug 18 12:56:58.190090 2026] [security2:error] [pid 67073:tid 67330] [client 68.155.154.236:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAyvcmepr5_nHgLbNenwAAApE"] [Tue Aug 18 12:56:58.204887 2026] [security2:error] [pid 66623:tid 66779] [client 20.65.69.59:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/verification.php"] [unique_id "aoSAytO5rbWdOArH04KO_wAAARc"] [Tue Aug 18 12:56:58.226057 2026] [security2:error] [pid 67073:tid 67212] [client 20.118.172.148:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAyvcmepr5_nHgLbNeoQAAAhs"] [Tue Aug 18 12:56:58.236219 2026] [security2:error] [pid 66623:tid 66885] [client 52.139.47.57:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSAytO5rbWdOArH04KPAQAAAYE"] [Tue Aug 18 12:56:58.241750 2026] [security2:error] [pid 66623:tid 66782] [client 158.158.74.177:16552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/term.php"] [unique_id "aoSAytO5rbWdOArH04KPAgAAARo"] [Tue Aug 18 12:56:58.259754 2026] [security2:error] [pid 67073:tid 67245] [client 20.215.241.237:7548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/als.php"] [unique_id "aoSAyvcmepr5_nHgLbNeogAAAjw"] [Tue Aug 18 12:56:58.263545 2026] [security2:error] [pid 67073:tid 67217] [client 158.23.17.4:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/server.php"] [unique_id "aoSAyvcmepr5_nHgLbNeowAAAiA"] [Tue Aug 18 12:56:58.270188 2026] [security2:error] [pid 66623:tid 66830] [client 20.52.168.85:7850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/input.php"] [unique_id "aoSAytO5rbWdOArH04KPAwAAAUo"] [Tue Aug 18 12:56:58.300262 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.155.199:5029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/chosen.php"] [unique_id "aoSAyvcmepr5_nHgLbNepQAAAo0"] [Tue Aug 18 12:56:58.315094 2026] [security2:error] [pid 67073:tid 67211] [client 52.173.121.69:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNepgAAAho"] [Tue Aug 18 12:56:58.348131 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:58.348530 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:58.370151 2026] [security2:error] [pid 67073:tid 67286] [client 138.36.100.162:43044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqAAAAmU"] [Tue Aug 18 12:56:58.370246 2026] [security2:error] [pid 67073:tid 67286] [client 138.36.100.162:43044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqAAAAmU"] [Tue Aug 18 12:56:58.394297 2026] [security2:error] [pid 67073:tid 67305] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/ct.php"] [unique_id "aoSAyvcmepr5_nHgLbNeqQAAAng"] [Tue Aug 18 12:56:58.399222 2026] [security2:error] [pid 66623:tid 66817] [client 130.89.144.165:51409] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "culinariaemporio.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSAytO5rbWdOArH04KPCAAAAT0"] [Tue Aug 18 12:56:58.415472 2026] [security2:error] [pid 66623:tid 66880] [client 40.85.222.29:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSAytO5rbWdOArH04KPCgAAAXw"] [Tue Aug 18 12:56:58.439424 2026] [security2:error] [pid 66623:tid 66815] [client 20.171.51.14:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/tt.php"] [unique_id "aoSAytO5rbWdOArH04KPDAAAATs"] [Tue Aug 18 12:56:58.441644 2026] [security2:error] [pid 66623:tid 66852] [client 40.74.65.169:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/FWAZ.php"] [unique_id "aoSAytO5rbWdOArH04KPDQAAAWA"] [Tue Aug 18 12:56:58.525659 2026] [security2:error] [pid 66623:tid 66769] [client 5.31.227.224:30446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAytO5rbWdOArH04KPEAAAAQ0"] [Tue Aug 18 12:56:58.532566 2026] [security2:error] [pid 66623:tid 66769] [client 5.31.227.224:30446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAytO5rbWdOArH04KPEAAAAQ0"] [Tue Aug 18 12:56:58.599592 2026] [security2:error] [pid 66623:tid 66775] [client 213.35.127.232:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAytO5rbWdOArH04KPFAAAARM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:58.646220 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:58.646496 2026] [authz_core:error] [pid 67073:tid 67167] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:58.656018 2026] [security2:error] [pid 67073:tid 67289] [client 52.139.47.57:18382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/ws83.php"] [unique_id "aoSAyvcmepr5_nHgLbNerwAAAmg"] [Tue Aug 18 12:56:58.697568 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.69.59:49284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/smtp.php"] [unique_id "aoSAyvcmepr5_nHgLbNesAAAAlc"] [Tue Aug 18 12:56:58.701289 2026] [security2:error] [pid 66623:tid 66791] [client 135.225.75.187:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/koiy.php"] [unique_id "aoSAytO5rbWdOArH04KPFgAAASM"] [Tue Aug 18 12:56:58.704474 2026] [security2:error] [pid 67073:tid 67303] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/gy.php"] [unique_id "aoSAyvcmepr5_nHgLbNesQAAAnY"] [Tue Aug 18 12:56:58.712052 2026] [security2:error] [pid 67073:tid 67220] [client 40.85.222.29:12640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSAyvcmepr5_nHgLbNesgAAAiM"] [Tue Aug 18 12:56:58.734677 2026] [security2:error] [pid 67073:tid 67307] [client 172.202.39.151:44980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSAyvcmepr5_nHgLbNeswAAAno"] [Tue Aug 18 12:56:58.772908 2026] [autoindex:error] [pid 66623:tid 66861] [client 3.210.118.109:9003] AH01276: Cannot serve directory /home4/adf/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:56:58.781491 2026] [security2:error] [pid 66623:tid 66811] [client 158.158.34.183:39503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/aaa.php"] [unique_id "aoSAytO5rbWdOArH04KPGAAAATc"] [Tue Aug 18 12:56:58.804235 2026] [security2:error] [pid 66623:tid 66839] [client 130.89.144.165:35405] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "culinariaemporio.com.br"] [uri "/index.html"] [unique_id "aoSAytO5rbWdOArH04KPGgAAAVM"] [Tue Aug 18 12:56:58.841453 2026] [security2:error] [pid 67073:tid 67320] [client 20.104.85.180:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/404.php"] [unique_id "aoSAyvcmepr5_nHgLbNetAAAAoc"] [Tue Aug 18 12:56:58.874372 2026] [security2:error] [pid 67073:tid 67226] [client 20.52.168.85:7757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/disagreed.php"] [unique_id "aoSAyvcmepr5_nHgLbNetQAAAik"] [Tue Aug 18 12:56:58.879271 2026] [security2:error] [pid 66623:tid 66814] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSAytO5rbWdOArH04KPHAAAATo"] [Tue Aug 18 12:56:58.923227 2026] [security2:error] [pid 67073:tid 67235] [client 132.196.30.78:21919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/index/function.php"] [unique_id "aoSAyvcmepr5_nHgLbNetgAAAjI"] [Tue Aug 18 12:56:58.952104 2026] [security2:error] [pid 67073:tid 67315] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/tt.php"] [unique_id "aoSAyvcmepr5_nHgLbNeuQAAAoI"] [Tue Aug 18 12:56:58.965318 2026] [security2:error] [pid 66623:tid 66809] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSAytO5rbWdOArH04KPHgAAATU"] [Tue Aug 18 12:56:58.990558 2026] [security2:error] [pid 67073:tid 67310] [client 40.85.222.29:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/blog/byp.php"] [unique_id "aoSAyvcmepr5_nHgLbNeugAAAn0"] [Tue Aug 18 12:56:59.018386 2026] [security2:error] [pid 66623:tid 66807] [client 157.20.138.62:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAy9O5rbWdOArH04KPIAAAATM"] [Tue Aug 18 12:56:59.018501 2026] [security2:error] [pid 66623:tid 66807] [client 157.20.138.62:62917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAy9O5rbWdOArH04KPIAAAATM"] [Tue Aug 18 12:56:59.052058 2026] [security2:error] [pid 66623:tid 66805] [client 20.171.51.14:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/mq.php"] [unique_id "aoSAy9O5rbWdOArH04KPIgAAATE"] [Tue Aug 18 12:56:59.053583 2026] [security2:error] [pid 67073:tid 67290] [client 158.23.17.4:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/xinfo.php"] [unique_id "aoSAy_cmepr5_nHgLbNeuwAAAmk"] [Tue Aug 18 12:56:59.054055 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.74.177:26160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/test.php"] [unique_id "aoSAy9O5rbWdOArH04KPIwAAAR4"] [Tue Aug 18 12:56:59.072778 2026] [security2:error] [pid 67073:tid 67287] [client 52.139.47.57:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/style.php"] [unique_id "aoSAy_cmepr5_nHgLbNevAAAAmY"] [Tue Aug 18 12:56:59.086816 2026] [security2:error] [pid 67073:tid 67246] [client 79.127.164.8:60442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/moduleinfoincludemysql/phpcms_info.sql"] [unique_id "aoSAy_cmepr5_nHgLbNevQAAAj0"], referer: https://medihub.com.br/moduleinfoincludemysql/phpcms_info.sql [Tue Aug 18 12:56:59.118030 2026] [security2:error] [pid 66623:tid 66855] [client 20.215.241.237:43621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/nox.php"] [unique_id "aoSAy9O5rbWdOArH04KPJQAAAWM"] [Tue Aug 18 12:56:59.149320 2026] [security2:error] [pid 67073:tid 67266] [client 40.74.65.169:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/blurbs.php"] [unique_id "aoSAy_cmepr5_nHgLbNevwAAAlE"] [Tue Aug 18 12:56:59.157237 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSAy_cmepr5_nHgLbNewAAAAn8"] [Tue Aug 18 12:56:59.203615 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/mq.php"] [unique_id "aoSAy9O5rbWdOArH04KPKQAAAUk"] [Tue Aug 18 12:56:59.224878 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.136.165:18021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/fs.php"] [unique_id "aoSAy_cmepr5_nHgLbNewgAAAh8"] [Tue Aug 18 12:56:59.239750 2026] [security2:error] [pid 67073:tid 67231] [client 20.65.69.59:49342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/teste.php"] [unique_id "aoSAy_cmepr5_nHgLbNexAAAAi4"] [Tue Aug 18 12:56:59.272298 2026] [security2:error] [pid 67073:tid 67222] [client 20.226.56.190:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vo.php"] [unique_id "aoSAy_cmepr5_nHgLbNexQAAAiU"] [Tue Aug 18 12:56:59.279773 2026] [security2:error] [pid 67073:tid 67236] [client 40.85.222.29:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSAy_cmepr5_nHgLbNexgAAAjM"] [Tue Aug 18 12:56:59.298101 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:17962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSAy9O5rbWdOArH04KPLAAAAR8"] [Tue Aug 18 12:56:59.299354 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/edit.php"] [unique_id "aoSAy9O5rbWdOArH04KPLQAAARI"] [Tue Aug 18 12:56:59.314504 2026] [security2:error] [pid 66623:tid 66793] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/w.php"] [unique_id "aoSAy9O5rbWdOArH04KPLgAAASU"] [Tue Aug 18 12:56:59.328389 2026] [security2:error] [pid 66623:tid 66832] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file.php"] [unique_id "aoSAy9O5rbWdOArH04KPMAAAAUw"] [Tue Aug 18 12:56:59.346616 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:18855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-login.php"] [unique_id "aoSAy9O5rbWdOArH04KPJwAAARA"] [Tue Aug 18 12:56:59.369934 2026] [security2:error] [pid 66623:tid 66836] [client 84.247.146.84:53436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "i-databi.com.br"] [uri "/index.php"] [unique_id "aoSAy9O5rbWdOArH04KPKAAAAVA"] [Tue Aug 18 12:56:59.378971 2026] [security2:error] [pid 67073:tid 67242] [client 149.34.210.141:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAy_cmepr5_nHgLbNexwAAAjk"] [Tue Aug 18 12:56:59.384946 2026] [security2:error] [pid 67073:tid 67293] [client 20.100.169.31:43003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bolt.php"] [unique_id "aoSAy_cmepr5_nHgLbNeyAAAAmw"] [Tue Aug 18 12:56:59.393349 2026] [security2:error] [pid 66623:tid 66784] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAy9O5rbWdOArH04KPMQAAARw"] [Tue Aug 18 12:56:59.445461 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.154.236:40361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/oivcl.php"] [unique_id "aoSAy9O5rbWdOArH04KPMwAAAQs"] [Tue Aug 18 12:56:59.457794 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/13.php"] [unique_id "aoSAy9O5rbWdOArH04KPNAAAAYQ"] [Tue Aug 18 12:56:59.479018 2026] [security2:error] [pid 67073:tid 67313] [client 20.52.168.85:7760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/defaults.php"] [unique_id "aoSAy_cmepr5_nHgLbNeyQAAAoA"] [Tue Aug 18 12:56:59.514525 2026] [security2:error] [pid 66623:tid 66801] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aa.php"] [unique_id "aoSAy9O5rbWdOArH04KPNgAAAS0"] [Tue Aug 18 12:56:59.519387 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.154.236:16199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAy9O5rbWdOArH04KPNwAAAU8"] [Tue Aug 18 12:56:59.525441 2026] [authz_core:error] [pid 66623:tid 66778] [client 192.178.4.133:53183] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:59.525695 2026] [authz_core:error] [pid 66623:tid 66778] [client 192.178.4.133:53183] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:59.537618 2026] [security2:error] [pid 66623:tid 66872] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSAy9O5rbWdOArH04KPOQAAAXQ"] [Tue Aug 18 12:56:59.539823 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSAy_cmepr5_nHgLbNeygAAAoo"] [Tue Aug 18 12:56:59.547847 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:59.548115 2026] [authz_core:error] [pid 67073:tid 67144] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:59.576063 2026] [security2:error] [pid 67073:tid 67291] [client 40.85.222.29:13237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSAy_cmepr5_nHgLbNezQAAAmo"] [Tue Aug 18 12:56:59.587476 2026] [security2:error] [pid 66623:tid 66794] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about.php"] [unique_id "aoSAy9O5rbWdOArH04KPPAAAASY"] [Tue Aug 18 12:56:59.598156 2026] [security2:error] [pid 67073:tid 67250] [client 135.225.75.187:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/iko.php"] [unique_id "aoSAy_cmepr5_nHgLbNezgAAAkE"] [Tue Aug 18 12:56:59.613059 2026] [security2:error] [pid 66623:tid 66788] [client 213.35.127.232:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSAy9O5rbWdOArH04KPPgAAASA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:56:59.619047 2026] [security2:error] [pid 66623:tid 66851] [client 52.139.47.57:17903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp-the.php"] [unique_id "aoSAy9O5rbWdOArH04KPPwAAAV8"] [Tue Aug 18 12:56:59.645220 2026] [security2:error] [pid 67073:tid 67242] [client 149.34.210.141:55646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSAy_cmepr5_nHgLbNexwAAAjk"] [Tue Aug 18 12:56:59.647784 2026] [security2:error] [pid 67073:tid 67206] [client 20.104.85.180:43575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSAy_cmepr5_nHgLbNezwAAAhU"] [Tue Aug 18 12:56:59.652706 2026] [security2:error] [pid 66623:tid 66790] [client 132.196.30.78:21932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/aaa.php"] [unique_id "aoSAy9O5rbWdOArH04KPQAAAASI"] [Tue Aug 18 12:56:59.684297 2026] [security2:error] [pid 67073:tid 67257] [client 172.202.39.151:65252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/o.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0AAAAkg"] [Tue Aug 18 12:56:59.746401 2026] [security2:error] [pid 67073:tid 67230] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/so.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0QAAAi0"] [Tue Aug 18 12:56:59.774332 2026] [security2:error] [pid 66623:tid 66825] [client 158.23.17.4:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/sym.php"] [unique_id "aoSAy9O5rbWdOArH04KPSAAAAUU"] [Tue Aug 18 12:56:59.779790 2026] [security2:error] [pid 67073:tid 67208] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/goods.php"] [unique_id "aoSAy_cmepr5_nHgLbNe0wAAAhc"] [Tue Aug 18 12:56:59.818785 2026] [security2:error] [pid 66623:tid 66885] [client 20.171.51.14:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/13.php"] [unique_id "aoSAy9O5rbWdOArH04KPSQAAAYE"] [Tue Aug 18 12:56:59.848187 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:56:59.848447 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:56:59.871919 2026] [security2:error] [pid 66623:tid 66830] [client 40.74.65.169:30075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/100.php"] [unique_id "aoSAy9O5rbWdOArH04KPTQAAAUo"] [Tue Aug 18 12:56:59.882920 2026] [security2:error] [pid 66623:tid 66849] [client 40.85.222.29:12659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hotelvipunai.com.br"] [uri "/images/security.php"] [unique_id "aoSAy9O5rbWdOArH04KPTgAAAV0"] [Tue Aug 18 12:56:59.895644 2026] [security2:error] [pid 66623:tid 66892] [client 52.139.47.57:1483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/aaa.php"] [unique_id "aoSAy9O5rbWdOArH04KPTwAAAYg"] [Tue Aug 18 12:56:59.903761 2026] [security2:error] [pid 67073:tid 67245] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/php8.php"] [unique_id "aoSAy_cmepr5_nHgLbNe1wAAAjw"] [Tue Aug 18 12:56:59.936319 2026] [security2:error] [pid 67073:tid 67217] [client 20.65.69.59:3719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/local.php"] [unique_id "aoSAy_cmepr5_nHgLbNe2AAAAiA"] [Tue Aug 18 12:56:59.999988 2026] [security2:error] [pid 67073:tid 67286] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/10.php"] [unique_id "aoSAy_cmepr5_nHgLbNe2wAAAmU"] [Tue Aug 18 12:57:00.042263 2026] [security2:error] [pid 67073:tid 67276] [client 20.65.98.162:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ano.php"] [unique_id "aoSAzPcmepr5_nHgLbNe3QAAAls"] [Tue Aug 18 12:57:00.063261 2026] [security2:error] [pid 67073:tid 67224] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/info.php"] [unique_id "aoSAzPcmepr5_nHgLbNe3gAAAic"] [Tue Aug 18 12:57:00.087222 2026] [security2:error] [pid 66623:tid 66863] [client 20.52.168.85:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/kyami.php"] [unique_id "aoSAzNO5rbWdOArH04KPVAAAAWs"] [Tue Aug 18 12:57:00.090409 2026] [security2:error] [pid 66623:tid 66873] [client 52.139.47.57:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/plugin.php"] [unique_id "aoSAzNO5rbWdOArH04KPVQAAAXU"] [Tue Aug 18 12:57:00.201145 2026] [security2:error] [pid 67073:tid 67260] [client 158.158.74.177:2657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/test1.php"] [unique_id "aoSAzPcmepr5_nHgLbNe4gAAAks"] [Tue Aug 18 12:57:00.252691 2026] [security2:error] [pid 67073:tid 67309] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/te.php"] [unique_id "aoSAzPcmepr5_nHgLbNe4wAAAnw"] [Tue Aug 18 12:57:00.253959 2026] [security2:error] [pid 66623:tid 66861] [client 20.226.56.190:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wu.php"] [unique_id "aoSAzNO5rbWdOArH04KPWgAAAWk"] [Tue Aug 18 12:57:00.255601 2026] [security2:error] [pid 67073:tid 67254] [client 51.68.236.91:15707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autocompanymultimarcas.com.br"] [uri "/robots.txt"] [unique_id "aoSAzPcmepr5_nHgLbNe5AAAAkU"] [Tue Aug 18 12:57:00.255756 2026] [security2:error] [pid 67073:tid 67254] [client 51.68.236.91:15707] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autocompanymultimarcas.com.br"] [uri "/robots.txt"] [unique_id "aoSAzPcmepr5_nHgLbNe5AAAAkU"] [Tue Aug 18 12:57:00.271321 2026] [security2:error] [pid 66623:tid 66811] [client 135.225.75.187:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/raw.php"] [unique_id "aoSAzNO5rbWdOArH04KPWwAAATc"] [Tue Aug 18 12:57:00.288898 2026] [security2:error] [pid 66623:tid 66839] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/chosen.php"] [unique_id "aoSAzNO5rbWdOArH04KPXAAAAVM"] [Tue Aug 18 12:57:00.294401 2026] [security2:error] [pid 66623:tid 66828] [client 20.215.241.237:35248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file59.php"] [unique_id "aoSAzNO5rbWdOArH04KPXQAAAUg"] [Tue Aug 18 12:57:00.301788 2026] [security2:error] [pid 67073:tid 67282] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/simple.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5QAAAmE"] [Tue Aug 18 12:57:00.318102 2026] [security2:error] [pid 67073:tid 67214] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5gAAAh0"] [Tue Aug 18 12:57:00.381092 2026] [security2:error] [pid 67073:tid 67324] [client 20.171.51.14:36429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/so.php"] [unique_id "aoSAzPcmepr5_nHgLbNe6AAAAos"] [Tue Aug 18 12:57:00.386788 2026] [authz_core:error] [pid 66623:tid 66760] [remote 57.141.22.121:32396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:00.387051 2026] [authz_core:error] [pid 66623:tid 66760] [remote 57.141.22.121:32396] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:00.415404 2026] [security2:error] [pid 67073:tid 67207] [client 20.250.13.23:25708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ws83.php"] [unique_id "aoSAzPcmepr5_nHgLbNe6QAAAhY"] [Tue Aug 18 12:57:00.445188 2026] [authz_core:error] [pid 66623:tid 66709] [remote 57.141.22.12:24200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:00.445467 2026] [authz_core:error] [pid 66623:tid 66709] [remote 57.141.22.12:24200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:00.450627 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:00.450898 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:00.497551 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/alfa.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7QAAAng"] [Tue Aug 18 12:57:00.506769 2026] [security2:error] [pid 66623:tid 66829] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/kc.php"] [unique_id "aoSAzNO5rbWdOArH04KPaQAAAUk"] [Tue Aug 18 12:57:00.526417 2026] [security2:error] [pid 67073:tid 67328] [client 178.153.171.161:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7gAAAo8"] [Tue Aug 18 12:57:00.526551 2026] [security2:error] [pid 67073:tid 67328] [client 178.153.171.161:46480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe7gAAAo8"] [Tue Aug 18 12:57:00.543857 2026] [security2:error] [pid 67073:tid 67303] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzPcmepr5_nHgLbNe5wACdnI"] [Tue Aug 18 12:57:00.573667 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:27021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ccc.php"] [unique_id "aoSAzNO5rbWdOArH04KPbAAAAWE"] [Tue Aug 18 12:57:00.609664 2026] [security2:error] [pid 67073:tid 67315] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/av.php"] [unique_id "aoSAzPcmepr5_nHgLbNe8AAAAoI"] [Tue Aug 18 12:57:00.631498 2026] [security2:error] [pid 66623:tid 66833] [client 213.35.127.232:64541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSAzNO5rbWdOArH04KPbwAAAU0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:00.660390 2026] [security2:error] [pid 67073:tid 67319] [client 20.118.172.148:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/edit.php"] [unique_id "aoSAzPcmepr5_nHgLbNe8gAAAoY"] [Tue Aug 18 12:57:00.692644 2026] [security2:error] [pid 66623:tid 66855] [client 20.52.168.85:8059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/DxHhVcy2bmJ.php"] [unique_id "aoSAzNO5rbWdOArH04KPcgAAAWM"] [Tue Aug 18 12:57:00.746335 2026] [autoindex:error] [pid 67073:tid 67280] [client 20.119.58.187:7951] AH01276: Cannot serve directory /home1/gfrison965/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:00.751879 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:00.752126 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:00.753856 2026] [security2:error] [pid 67073:tid 67269] [client 52.139.47.57:18159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/readme.php"] [unique_id "aoSAzPcmepr5_nHgLbNe9wAAAlQ"] [Tue Aug 18 12:57:00.765934 2026] [security2:error] [pid 67073:tid 67216] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/jn.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-AAAAh8"] [Tue Aug 18 12:57:00.781641 2026] [security2:error] [pid 67073:tid 67213] [client 74.248.136.165:61359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/wp-tem.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-QAAAhw"] [Tue Aug 18 12:57:00.829555 2026] [security2:error] [pid 67073:tid 67236] [client 104.209.144.33:35867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSAzPcmepr5_nHgLbNe-wAAAjM"] [Tue Aug 18 12:57:00.835097 2026] [security2:error] [pid 67073:tid 67314] [client 20.215.241.237:7514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/admin.php"] [unique_id "aoSAzPcmepr5_nHgLbNe_AAAAoE"] [Tue Aug 18 12:57:00.973519 2026] [security2:error] [pid 66623:tid 66792] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp.php"] [unique_id "aoSAzNO5rbWdOArH04KPeAAAASQ"] [Tue Aug 18 12:57:00.980457 2026] [security2:error] [pid 66623:tid 66838] [client 20.171.51.14:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/10.php"] [unique_id "aoSAzNO5rbWdOArH04KPeQAAAVI"] [Tue Aug 18 12:57:01.036794 2026] [security2:error] [pid 67073:tid 67242] [client 68.155.154.236:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zugvi.php"] [unique_id "aoSAzfcmepr5_nHgLbNe_wAAAjk"] [Tue Aug 18 12:57:01.039450 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:3768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp_sitting.php"] [unique_id "aoSAzfcmepr5_nHgLbNfAAAAAhU"] [Tue Aug 18 12:57:01.042187 2026] [security2:error] [pid 66623:tid 66888] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioclimaarcondicionado.com.br"] [uri "/bf.php"] [unique_id "aoSAzdO5rbWdOArH04KPegAAAYQ"] [Tue Aug 18 12:57:01.054949 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:01.055211 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:54279] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:01.066325 2026] [security2:error] [pid 66623:tid 66872] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file2.php"] [unique_id "aoSAzdO5rbWdOArH04KPfAAAAXQ"] [Tue Aug 18 12:57:01.080450 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/images/class-config.php"] [unique_id "aoSAzfcmepr5_nHgLbNfAwAAAkg"] [Tue Aug 18 12:57:01.085898 2026] [autoindex:error] [pid 67073:tid 67219] [client 172.202.39.151:43206] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:01.094294 2026] [security2:error] [pid 67073:tid 67263] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/alfa.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBAAAAk4"] [Tue Aug 18 12:57:01.106798 2026] [security2:error] [pid 66623:tid 66859] [client 20.197.195.76:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAzdO5rbWdOArH04KPfQAAAWc"] [Tue Aug 18 12:57:01.106900 2026] [security2:error] [pid 66623:tid 66859] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/1.php"] [unique_id "aoSAzdO5rbWdOArH04KPfQAAAWc"] [Tue Aug 18 12:57:01.117229 2026] [security2:error] [pid 66623:tid 66794] [client 20.206.73.37:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ops.php"] [unique_id "aoSAzdO5rbWdOArH04KPfgAAASY"] [Tue Aug 18 12:57:01.127496 2026] [security2:error] [pid 67073:tid 67270] [client 158.158.74.177:16526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/thoms.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBQAAAlU"] [Tue Aug 18 12:57:01.221699 2026] [security2:error] [pid 67073:tid 67228] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/222.php"] [unique_id "aoSAzfcmepr5_nHgLbNfBwAAAis"] [Tue Aug 18 12:57:01.235641 2026] [security2:error] [pid 67073:tid 67253] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/asasx.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCAAAAkQ"] [Tue Aug 18 12:57:01.249357 2026] [security2:error] [pid 66623:tid 66869] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/filemanager.php"] [unique_id "aoSAzdO5rbWdOArH04KPgQAAAXE"] [Tue Aug 18 12:57:01.262245 2026] [security2:error] [pid 66623:tid 66795] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/themes.php"] [unique_id "aoSAzdO5rbWdOArH04KPgwAAASc"] [Tue Aug 18 12:57:01.268756 2026] [security2:error] [pid 66623:tid 66782] [client 40.74.65.169:27787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/get.php"] [unique_id "aoSAzdO5rbWdOArH04KPhQAAARo"] [Tue Aug 18 12:57:01.274828 2026] [security2:error] [pid 66623:tid 66881] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSAzdO5rbWdOArH04KPhgAAAX0"] [Tue Aug 18 12:57:01.296226 2026] [security2:error] [pid 66623:tid 66803] [client 20.52.168.85:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/amaxx.php"] [unique_id "aoSAzdO5rbWdOArH04KPhwAAAS8"] [Tue Aug 18 12:57:01.303995 2026] [security2:error] [pid 67073:tid 67262] [client 20.250.13.23:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/atex1.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCgAAAk0"] [Tue Aug 18 12:57:01.359319 2026] [security2:error] [pid 67073:tid 67223] [client 20.215.241.237:61100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aa2.php"] [unique_id "aoSAzfcmepr5_nHgLbNfCwAAAiY"] [Tue Aug 18 12:57:01.364081 2026] [security2:error] [pid 66623:tid 66892] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/buy.php"] [unique_id "aoSAzdO5rbWdOArH04KPigAAAYg"] [Tue Aug 18 12:57:01.373927 2026] [security2:error] [pid 67073:tid 67240] [client 172.202.39.151:43206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-mail.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDAAAAjc"] [Tue Aug 18 12:57:01.384048 2026] [security2:error] [pid 67073:tid 67245] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/dropdown.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDQAAAjw"] [Tue Aug 18 12:57:01.393680 2026] [security2:error] [pid 67073:tid 67296] [client 52.139.47.57:48722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/chosen.php"] [unique_id "aoSAzfcmepr5_nHgLbNfDgAAAm8"] [Tue Aug 18 12:57:01.481352 2026] [security2:error] [pid 67073:tid 67224] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/inputs.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEAAAAic"] [Tue Aug 18 12:57:01.482906 2026] [security2:error] [pid 67073:tid 67271] [client 52.173.121.69:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEQAAAlY"] [Tue Aug 18 12:57:01.489550 2026] [security2:error] [pid 67073:tid 67312] [client 85.154.68.202:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEgAAAn8"] [Tue Aug 18 12:57:01.489676 2026] [security2:error] [pid 67073:tid 67312] [client 85.154.68.202:52620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEgAAAn8"] [Tue Aug 18 12:57:01.514030 2026] [security2:error] [pid 67073:tid 67232] [client 172.182.200.96:14164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSAzfcmepr5_nHgLbNfEwAAAi8"] [Tue Aug 18 12:57:01.521097 2026] [security2:error] [pid 67073:tid 67267] [client 135.225.75.187:20254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/05.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFAAAAlI"] [Tue Aug 18 12:57:01.526927 2026] [security2:error] [pid 67073:tid 67209] [client 68.155.154.236:16280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFQAAAhg"] [Tue Aug 18 12:57:01.543363 2026] [security2:error] [pid 67073:tid 67317] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/100.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFgAAAoQ"] [Tue Aug 18 12:57:01.557432 2026] [security2:error] [pid 67073:tid 67261] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/akc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfFwAAAkw"] [Tue Aug 18 12:57:01.573354 2026] [security2:error] [pid 66623:tid 66890] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSAzdO5rbWdOArH04KPkQAAAYY"] [Tue Aug 18 12:57:01.583694 2026] [security2:error] [pid 67073:tid 67239] [client 20.100.169.31:7785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/bthil.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGAAAAjY"] [Tue Aug 18 12:57:01.598702 2026] [security2:error] [pid 67073:tid 67274] [client 160.120.140.123:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGQAAAlk"] [Tue Aug 18 12:57:01.598867 2026] [security2:error] [pid 67073:tid 67274] [client 160.120.140.123:63702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGQAAAlk"] [Tue Aug 18 12:57:01.635444 2026] [security2:error] [pid 66623:tid 66871] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/php.php"] [unique_id "aoSAzdO5rbWdOArH04KPlAAAAXM"] [Tue Aug 18 12:57:01.642750 2026] [security2:error] [pid 66623:tid 66778] [client 20.171.51.14:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/te.php"] [unique_id "aoSAzdO5rbWdOArH04KPlQAAARY"] [Tue Aug 18 12:57:01.645299 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:64754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSAzdO5rbWdOArH04KPlgAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:01.678021 2026] [security2:error] [pid 66623:tid 66798] [client 119.93.171.138:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.171.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imbeg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzdO5rbWdOArH04KPjAAAASo"] [Tue Aug 18 12:57:01.678216 2026] [security2:error] [pid 66623:tid 66798] [client 119.93.171.138:61139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imbeg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzdO5rbWdOArH04KPjAAAASo"] [Tue Aug 18 12:57:01.686506 2026] [security2:error] [pid 66623:tid 66887] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/t.php"] [unique_id "aoSAzdO5rbWdOArH04KPlwAAAYM"] [Tue Aug 18 12:57:01.753992 2026] [security2:error] [pid 67073:tid 67278] [client 158.158.34.183:64530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfGwAAAl0"] [Tue Aug 18 12:57:01.774354 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.155.199:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/simple.php"] [unique_id "aoSAzdO5rbWdOArH04KPmQAAAWQ"] [Tue Aug 18 12:57:01.781970 2026] [security2:error] [pid 66623:tid 66773] [client 132.196.30.78:18658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/abcd.php"] [unique_id "aoSAzdO5rbWdOArH04KPmwAAARE"] [Tue Aug 18 12:57:01.781953 2026] [security2:error] [pid 66623:tid 66873] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSAzdO5rbWdOArH04KPmgAAAXU"] [Tue Aug 18 12:57:01.836350 2026] [security2:error] [pid 67073:tid 67281] [client 158.23.17.4:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.apostolicoprofetico.com.br"] [uri "/ye.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHQAAAmA"] [Tue Aug 18 12:57:01.856189 2026] [security2:error] [pid 67073:tid 67217] [client 114.5.214.109:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHgAAAiA"] [Tue Aug 18 12:57:01.863191 2026] [security2:error] [pid 67073:tid 67303] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wk/index.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIAAAAnY"] [Tue Aug 18 12:57:01.871898 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/8.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIQAAAjI"] [Tue Aug 18 12:57:01.873370 2026] [security2:error] [pid 67073:tid 67217] [client 114.5.214.109:49813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAzfcmepr5_nHgLbNfHgAAAiA"] [Tue Aug 18 12:57:01.880389 2026] [security2:error] [pid 67073:tid 67290] [client 20.215.241.237:43169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/xamp.php"] [unique_id "aoSAzfcmepr5_nHgLbNfIwAAAmk"] [Tue Aug 18 12:57:01.897306 2026] [security2:error] [pid 67073:tid 67307] [client 20.52.168.85:7855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/BIBIL0DAY.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJAAAAno"] [Tue Aug 18 12:57:01.936144 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.154.236:8022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wsrer.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJQAAApI"] [Tue Aug 18 12:57:01.959054 2026] [security2:error] [pid 67073:tid 67283] [client 40.74.65.169:43139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/images.php"] [unique_id "aoSAzfcmepr5_nHgLbNfJgAAAmI"] [Tue Aug 18 12:57:02.002990 2026] [security2:error] [pid 67073:tid 67266] [client 20.171.51.14:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/kc.php"] [unique_id "aoSAzvcmepr5_nHgLbNfKAAAAlE"] [Tue Aug 18 12:57:02.031133 2026] [security2:error] [pid 67073:tid 67258] [client 158.158.74.177:26143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/tool.php"] [unique_id "aoSAzvcmepr5_nHgLbNfKwAAAkk"] [Tue Aug 18 12:57:02.090762 2026] [security2:error] [pid 67073:tid 67221] [client 52.139.47.57:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/system.php"] [unique_id "aoSAzvcmepr5_nHgLbNfLQAAAiQ"] [Tue Aug 18 12:57:02.120055 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.69.59:40539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ninja.php"] [unique_id "aoSAztO5rbWdOArH04KPpAAAAUI"] [Tue Aug 18 12:57:02.174951 2026] [security2:error] [pid 66623:tid 66849] [client 20.100.169.31:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/155.php"] [unique_id "aoSAztO5rbWdOArH04KPpgAAAV0"] [Tue Aug 18 12:57:02.184483 2026] [security2:error] [pid 67073:tid 67301] [client 172.202.39.151:54695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/o.php"] [unique_id "aoSAzvcmepr5_nHgLbNfLwAAAnQ"] [Tue Aug 18 12:57:02.246098 2026] [security2:error] [pid 66623:tid 66811] [client 52.173.121.69:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSAztO5rbWdOArH04KPqAAAATc"] [Tue Aug 18 12:57:02.294135 2026] [security2:error] [pid 66623:tid 66821] [client 114.119.131.235:55543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "site.paulocardosoimoveis.com"] [uri "/imoveis/venda/casa-itaipu"] [unique_id "aoSAztO5rbWdOArH04KPqQAAAUE"], referer: https://site.paulocardosoimoveis.com/imoveis/venda/casa-itaipu [Tue Aug 18 12:57:02.419955 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.30.78:21912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-good.php"] [unique_id "aoSAztO5rbWdOArH04KPrQAAAWk"] [Tue Aug 18 12:57:02.427150 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.136.165:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/sadd.php"] [unique_id "aoSAztO5rbWdOArH04KPrwAAAYI"] [Tue Aug 18 12:57:02.442518 2026] [security2:error] [pid 66623:tid 66805] [client 20.171.51.14:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/jn.php"] [unique_id "aoSAztO5rbWdOArH04KPsAAAATE"] [Tue Aug 18 12:57:02.497844 2026] [security2:error] [pid 67073:tid 67291] [client 20.52.168.85:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/functions.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNAAAAmo"] [Tue Aug 18 12:57:02.505838 2026] [security2:error] [pid 67073:tid 67270] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-blink.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNQAAAlU"] [Tue Aug 18 12:57:02.515514 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.56.190:23772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/de.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNgAAAi0"] [Tue Aug 18 12:57:02.525793 2026] [security2:error] [pid 66623:tid 66883] [client 52.139.47.57:18141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/wp-load.php"] [unique_id "aoSAztO5rbWdOArH04KPtAAAAX8"] [Tue Aug 18 12:57:02.549053 2026] [security2:error] [pid 67073:tid 67225] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/xfun.php"] [unique_id "aoSAzvcmepr5_nHgLbNfNwAAAig"] [Tue Aug 18 12:57:02.562067 2026] [security2:error] [pid 67073:tid 67284] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/p.php"] [unique_id "aoSAzvcmepr5_nHgLbNfOAAAAmM"] [Tue Aug 18 12:57:02.573086 2026] [security2:error] [pid 66623:tid 66844] [client 20.215.241.237:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/bless.php"] [unique_id "aoSAztO5rbWdOArH04KPtQAAAVg"] [Tue Aug 18 12:57:02.576111 2026] [security2:error] [pid 67073:tid 67212] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSAzvcmepr5_nHgLbNfOQAAAhs"] [Tue Aug 18 12:57:02.595547 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.27:46640] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:02.595836 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.27:46640] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:02.618170 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/biufile.php"] [unique_id "aoSAztO5rbWdOArH04KPuQAAAXI"] [Tue Aug 18 12:57:02.657198 2026] [security2:error] [pid 66623:tid 66776] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aaa.php"] [unique_id "aoSAztO5rbWdOArH04KPugAAARQ"] [Tue Aug 18 12:57:02.659885 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSAztO5rbWdOArH04KPuwAAAVM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:02.660285 2026] [security2:error] [pid 67073:tid 67296] [client 40.74.65.169:27818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/alls.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPAAAAm8"] [Tue Aug 18 12:57:02.674716 2026] [security2:error] [pid 67073:tid 67318] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/term.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPQAAAoU"] [Tue Aug 18 12:57:02.679695 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/w.php"] [unique_id "aoSAztO5rbWdOArH04KPvAAAATQ"] [Tue Aug 18 12:57:02.689302 2026] [security2:error] [pid 67073:tid 67211] [client 135.225.75.187:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/public/hi.php"] [unique_id "aoSAzvcmepr5_nHgLbNfPwAAAho"] [Tue Aug 18 12:57:02.725782 2026] [security2:error] [pid 67073:tid 67271] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/7.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQQAAAlY"] [Tue Aug 18 12:57:02.740187 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file5.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQgAAAn8"] [Tue Aug 18 12:57:02.742833 2026] [security2:error] [pid 67073:tid 67322] [client 20.65.98.162:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ai.php"] [unique_id "aoSAzvcmepr5_nHgLbNfQwAAAok"] [Tue Aug 18 12:57:02.752849 2026] [security2:error] [pid 67073:tid 67267] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSAzvcmepr5_nHgLbNfRwAAAlI"] [Tue Aug 18 12:57:02.757328 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.56.190:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/album.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSAAAAoQ"] [Tue Aug 18 12:57:02.759461 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:02.759736 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:02.762168 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:02.762353 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:02.762603 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:02.762809 2026] [authz_core:error] [pid 67073:tid 67188] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:02.763416 2026] [security2:error] [pid 67073:tid 67243] [client 52.173.121.69:16462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSQAAAjo"] [Tue Aug 18 12:57:02.765239 2026] [security2:error] [pid 67073:tid 67261] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSgAAAkw"] [Tue Aug 18 12:57:02.779359 2026] [security2:error] [pid 67073:tid 67260] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSAzvcmepr5_nHgLbNfSwAAAks"] [Tue Aug 18 12:57:02.779555 2026] [security2:error] [pid 67073:tid 67297] [client 104.209.144.33:21383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTAAAAnA"] [Tue Aug 18 12:57:02.791609 2026] [security2:error] [pid 66623:tid 66813] [client 68.155.154.236:48953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/ucpfr.php"] [unique_id "aoSAztO5rbWdOArH04KPvwAAATk"] [Tue Aug 18 12:57:02.847021 2026] [security2:error] [pid 66623:tid 66793] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/atomlib.php"] [unique_id "aoSAztO5rbWdOArH04KPwAAAASU"] [Tue Aug 18 12:57:02.852689 2026] [security2:error] [pid 67073:tid 67319] [client 20.250.13.23:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/class-t.api.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTgAAAoY"] [Tue Aug 18 12:57:02.875135 2026] [security2:error] [pid 67073:tid 67324] [client 20.65.69.59:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/phpprobe.php"] [unique_id "aoSAzvcmepr5_nHgLbNfTwAAAos"] [Tue Aug 18 12:57:02.878311 2026] [security2:error] [pid 67073:tid 67207] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/min.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUAAAAhY"] [Tue Aug 18 12:57:02.880245 2026] [security2:error] [pid 67073:tid 67117] [remote 192.250.229.214:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUQACXSk"] [Tue Aug 18 12:57:02.914048 2026] [security2:error] [pid 67073:tid 67305] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/mac.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUgAAAng"] [Tue Aug 18 12:57:02.928889 2026] [security2:error] [pid 66623:tid 66877] [client 52.139.47.57:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formularios.filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSAztO5rbWdOArH04KPwgAAAXk"] [Tue Aug 18 12:57:02.930741 2026] [security2:error] [pid 67073:tid 67259] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/nc4.php"] [unique_id "aoSAzvcmepr5_nHgLbNfUwAAAko"] [Tue Aug 18 12:57:02.944833 2026] [security2:error] [pid 66623:tid 66874] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/as.php"] [unique_id "aoSAztO5rbWdOArH04KPwwAAAXY"] [Tue Aug 18 12:57:02.949389 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.56.190:17904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kv.php"] [unique_id "aoSAztO5rbWdOArH04KPxAAAARA"] [Tue Aug 18 12:57:02.956644 2026] [security2:error] [pid 66623:tid 66889] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/k.php"] [unique_id "aoSAztO5rbWdOArH04KPxQAAAYU"] [Tue Aug 18 12:57:02.974130 2026] [security2:error] [pid 66623:tid 66857] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSAztO5rbWdOArH04KPyAAAAWU"] [Tue Aug 18 12:57:02.986295 2026] [security2:error] [pid 67073:tid 67235] [client 20.171.51.14:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jcarvalhoimport.com.br"] [uri "/bf.php"] [unique_id "aoSAzvcmepr5_nHgLbNfVAAAAjI"] [Tue Aug 18 12:57:03.013999 2026] [security2:error] [pid 67073:tid 67306] [client 132.196.30.78:18755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/simple.php"] [unique_id "aoSAz_cmepr5_nHgLbNfVQAAAnk"] [Tue Aug 18 12:57:03.060915 2026] [security2:error] [pid 66623:tid 66767] [client 68.155.155.199:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSAz9O5rbWdOArH04KPyQAAAQs"] [Tue Aug 18 12:57:03.062011 2026] [security2:error] [pid 67073:tid 67325] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/system_log.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWAAAAow"] [Tue Aug 18 12:57:03.100563 2026] [security2:error] [pid 66623:tid 66865] [client 52.139.47.57:17918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.multiveicular.org.br"] [uri "/files/8.php"] [unique_id "aoSAz9O5rbWdOArH04KPywAAAW0"] [Tue Aug 18 12:57:03.103788 2026] [security2:error] [pid 67073:tid 67220] [client 20.52.168.85:7868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/wp-comments-post.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWQAAAiM"] [Tue Aug 18 12:57:03.118970 2026] [security2:error] [pid 66623:tid 66855] [client 20.100.169.31:12570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/96i.php"] [unique_id "aoSAz9O5rbWdOArH04KPzQAAAWM"] [Tue Aug 18 12:57:03.205754 2026] [security2:error] [pid 67073:tid 67191] [remote 129.121.103.155:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfWgACZ3M"] [Tue Aug 18 12:57:03.282568 2026] [security2:error] [pid 67073:tid 67266] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/x.php"] [unique_id "aoSAz_cmepr5_nHgLbNfXAAAAlE"] [Tue Aug 18 12:57:03.337938 2026] [security2:error] [pid 66623:tid 66801] [client 20.226.56.190:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/z.php"] [unique_id "aoSAz9O5rbWdOArH04KP0QAAAS0"] [Tue Aug 18 12:57:03.353181 2026] [security2:error] [pid 67073:tid 67332] [client 40.74.65.169:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/coffexium.php"] [unique_id "aoSAz_cmepr5_nHgLbNfXgAAApM"] [Tue Aug 18 12:57:03.369053 2026] [security2:error] [pid 67073:tid 67221] [client 20.118.172.148:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file.php"] [unique_id "aoSAz_cmepr5_nHgLbNfYAAAAiQ"] [Tue Aug 18 12:57:03.398432 2026] [security2:error] [pid 66623:tid 66824] [client 104.209.144.33:34112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSAz9O5rbWdOArH04KP0gAAAUQ"] [Tue Aug 18 12:57:03.478100 2026] [security2:error] [pid 66623:tid 66829] [client 157.51.166.53:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP1gAAAUk"] [Tue Aug 18 12:57:03.478202 2026] [security2:error] [pid 66623:tid 66829] [client 157.51.166.53:63748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP1gAAAUk"] [Tue Aug 18 12:57:03.504561 2026] [security2:error] [pid 66623:tid 66825] [client 135.225.75.187:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/get.php"] [unique_id "aoSAz9O5rbWdOArH04KP2QAAAUU"] [Tue Aug 18 12:57:03.630292 2026] [security2:error] [pid 67073:tid 67222] [client 132.196.30.78:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/edit-tags.php"] [unique_id "aoSAz_cmepr5_nHgLbNfZgAAAiU"] [Tue Aug 18 12:57:03.649497 2026] [security2:error] [pid 67073:tid 67242] [client 20.215.241.237:35249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file25.php"] [unique_id "aoSAz_cmepr5_nHgLbNfZwAAAjk"] [Tue Aug 18 12:57:03.678357 2026] [security2:error] [pid 67073:tid 67210] [client 213.35.127.232:65233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfaAAAAhk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:03.707508 2026] [security2:error] [pid 66623:tid 66771] [client 20.52.168.85:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/conf_upload.php"] [unique_id "aoSAz9O5rbWdOArH04KP4QAAAQ8"] [Tue Aug 18 12:57:03.710686 2026] [security2:error] [pid 67073:tid 67219] [client 20.65.69.59:49281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-title.php"] [unique_id "aoSAz_cmepr5_nHgLbNfagAAAiI"] [Tue Aug 18 12:57:03.794194 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:03.794638 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:03.894031 2026] [security2:error] [pid 66623:tid 66677] [remote 34.176.82.226:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.82.176.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSAz9O5rbWdOArH04KP8QABdCg"] [Tue Aug 18 12:57:03.909829 2026] [security2:error] [pid 66623:tid 66848] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSAz9O5rbWdOArH04KP7wABXD4"] [Tue Aug 18 12:57:03.917743 2026] [security2:error] [pid 67073:tid 67286] [client 172.202.39.151:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/bb.php"] [unique_id "aoSAz_cmepr5_nHgLbNfcQAAAmU"] [Tue Aug 18 12:57:03.935339 2026] [security2:error] [pid 67073:tid 67099] [remote 162.214.96.231:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gvc.eng.br"] [uri "/wp-login.php"] [unique_id "aoSAz_cmepr5_nHgLbNfcwACKRc"] [Tue Aug 18 12:57:03.942447 2026] [security2:error] [pid 67073:tid 67253] [client 20.118.172.148:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSAz_cmepr5_nHgLbNfdAAAAkQ"] [Tue Aug 18 12:57:04.027535 2026] [security2:error] [pid 66623:tid 66782] [client 20.250.13.23:25687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/w.php"] [unique_id "aoSA0NO5rbWdOArH04KP9gAAARo"] [Tue Aug 18 12:57:04.053601 2026] [security2:error] [pid 66623:tid 66769] [client 40.74.65.169:27785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/red.php"] [unique_id "aoSA0NO5rbWdOArH04KP-QAAAQ0"] [Tue Aug 18 12:57:04.120439 2026] [security2:error] [pid 67073:tid 67276] [client 132.196.30.78:18752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/u.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfdQAAAls"] [Tue Aug 18 12:57:04.208200 2026] [security2:error] [pid 67073:tid 67267] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfeAAAAlI"] [Tue Aug 18 12:57:04.225429 2026] [security2:error] [pid 67073:tid 67209] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/hosty.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfeQAAAhg"] [Tue Aug 18 12:57:04.227670 2026] [security2:error] [pid 67073:tid 67317] [client 68.155.154.236:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/yxijx.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfegAAAoQ"] [Tue Aug 18 12:57:04.234433 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.136.165:22465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ex.php"] [unique_id "aoSA0NO5rbWdOArH04KQOAAAAUc"] [Tue Aug 18 12:57:04.239768 2026] [security2:error] [pid 66623:tid 66850] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/test1.php"] [unique_id "aoSA0NO5rbWdOArH04KQOQAAAV4"] [Tue Aug 18 12:57:04.276020 2026] [security2:error] [pid 67073:tid 67260] [client 104.209.144.33:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfewAAAks"] [Tue Aug 18 12:57:04.310069 2026] [security2:error] [pid 66623:tid 66785] [client 20.52.168.85:8057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/content.php888"] [unique_id "aoSA0NO5rbWdOArH04KQPQAAAR0"] [Tue Aug 18 12:57:04.331503 2026] [security2:error] [pid 67073:tid 67218] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/zwso.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffAAAAiE"] [Tue Aug 18 12:57:04.340637 2026] [security2:error] [pid 67073:tid 67254] [client 68.155.156.252:20767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffQAAAkU"] [Tue Aug 18 12:57:04.344179 2026] [security2:error] [pid 67073:tid 67282] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/Geforce.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffgAAAmE"] [Tue Aug 18 12:57:04.353021 2026] [security2:error] [pid 66623:tid 66807] [client 20.118.172.148:62113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aa.php"] [unique_id "aoSA0NO5rbWdOArH04KQQAAAATM"] [Tue Aug 18 12:57:04.358980 2026] [security2:error] [pid 67073:tid 67309] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/fpwch.php"] [unique_id "aoSA0Pcmepr5_nHgLbNffwAAAnw"] [Tue Aug 18 12:57:04.447178 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.155.199:2297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/av.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfhAAAAos"] [Tue Aug 18 12:57:04.492129 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.69.59:3767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/styles.php"] [unique_id "aoSA0NO5rbWdOArH04KQQwAAAXI"] [Tue Aug 18 12:57:04.630613 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfiAAAAm0"] [Tue Aug 18 12:57:04.630811 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:52482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfiAAAAm0"] [Tue Aug 18 12:57:04.634327 2026] [authz_core:error] [pid 67073:tid 67160] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:04.634588 2026] [authz_core:error] [pid 67073:tid 67160] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:04.694938 2026] [security2:error] [pid 67073:tid 67272] [client 213.35.127.232:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfigAAAlc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:04.698737 2026] [security2:error] [pid 66623:tid 66793] [client 135.225.75.187:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rpk.php"] [unique_id "aoSA0NO5rbWdOArH04KQUAAAASU"] [Tue Aug 18 12:57:04.702230 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA0NO5rbWdOArH04KQUQAAARI"] [Tue Aug 18 12:57:04.714677 2026] [cgid:error] [pid 67073:tid 67327] [client 20.100.169.31:43813] AH01265: stderr from /home1/lubarbosa/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 12:57:04.725815 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.56.190:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xg.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfjAAAAl4"] [Tue Aug 18 12:57:04.748920 2026] [security2:error] [pid 67073:tid 67329] [client 79.127.164.8:60518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/my.bak"] [unique_id "aoSA0Pcmepr5_nHgLbNfjQAAApA"], referer: https://medihub.com.br/my.bak [Tue Aug 18 12:57:04.850953 2026] [security2:error] [pid 67073:tid 67308] [client 20.118.172.148:62111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfjwAAAns"] [Tue Aug 18 12:57:04.855858 2026] [security2:error] [pid 67073:tid 67325] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about/function.php"] [unique_id "aoSA0Pcmepr5_nHgLbNfkAAAAow"] [Tue Aug 18 12:57:04.908564 2026] [security2:error] [pid 66623:tid 66776] [client 158.158.74.177:26172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/tools.php"] [unique_id "aoSA0NO5rbWdOArH04KQWgAAARQ"] [Tue Aug 18 12:57:04.921132 2026] [security2:error] [pid 67073:tid 67248] [client 20.52.168.85:8063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/gecko-new.php.1"] [unique_id "aoSA0Pcmepr5_nHgLbNfkwAAAj8"] [Tue Aug 18 12:57:04.922316 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/x.php"] [unique_id "aoSA0Pcmepr5_nHgLbNflAAAAmI"] [Tue Aug 18 12:57:04.933795 2026] [security2:error] [pid 66623:tid 66768] [client 132.196.30.78:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA0NO5rbWdOArH04KQXgAAAQw"] [Tue Aug 18 12:57:04.935041 2026] [security2:error] [pid 67073:tid 67288] [client 20.215.241.237:43149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file15.php"] [unique_id "aoSA0Pcmepr5_nHgLbNflQAAAmc"] [Tue Aug 18 12:57:05.068014 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.154.236:7621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA0fcmepr5_nHgLbNfnwAAAnQ"] [Tue Aug 18 12:57:05.111152 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:05.111444 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:05.196077 2026] [security2:error] [pid 67073:tid 67222] [client 20.118.172.148:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about.php"] [unique_id "aoSA0fcmepr5_nHgLbNfsgAAAiU"] [Tue Aug 18 12:57:05.208063 2026] [security2:error] [pid 67073:tid 67332] [client 20.100.169.31:16055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/as.php"] [unique_id "aoSA0fcmepr5_nHgLbNfswAAApM"] [Tue Aug 18 12:57:05.238774 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:05.239049 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:05.259604 2026] [security2:error] [pid 67073:tid 67206] [client 20.65.69.59:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/server.php"] [unique_id "aoSA0fcmepr5_nHgLbNftQAAAhU"] [Tue Aug 18 12:57:05.280170 2026] [security2:error] [pid 67073:tid 67210] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/function/function.php"] [unique_id "aoSA0fcmepr5_nHgLbNftgAAAhk"] [Tue Aug 18 12:57:05.299901 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA0fcmepr5_nHgLbNftwAAAkg"] [Tue Aug 18 12:57:05.305482 2026] [security2:error] [pid 67073:tid 67293] [client 20.250.13.23:41603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/archive.php"] [unique_id "aoSA0fcmepr5_nHgLbNfuAAAAmw"] [Tue Aug 18 12:57:05.339511 2026] [security2:error] [pid 67073:tid 67213] [client 172.202.39.151:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSA0fcmepr5_nHgLbNfuQAAAhw"] [Tue Aug 18 12:57:05.367207 2026] [security2:error] [pid 66623:tid 66812] [client 172.202.39.151:65264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/bb.php"] [unique_id "aoSA0dO5rbWdOArH04KQbgAAATg"] [Tue Aug 18 12:57:05.411242 2026] [security2:error] [pid 67073:tid 67291] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/f35.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvAAAAmo"] [Tue Aug 18 12:57:05.427759 2026] [security2:error] [pid 67073:tid 67238] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/gg.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvQAAAjU"] [Tue Aug 18 12:57:05.472297 2026] [security2:error] [pid 67073:tid 67223] [client 135.225.75.187:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-blog.php"] [unique_id "aoSA0fcmepr5_nHgLbNfvwAAAiY"] [Tue Aug 18 12:57:05.519263 2026] [security2:error] [pid 67073:tid 67296] [client 114.119.144.176:64321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoSA0fcmepr5_nHgLbNfwwAAAm8"], referer: http://eccellenzaconsultoria.com.br/robots.txt [Tue Aug 18 12:57:05.520563 2026] [security2:error] [pid 66623:tid 66840] [client 20.52.168.85:8045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/OthioNDwMEK.php"] [unique_id "aoSA0dO5rbWdOArH04KQdAAAAVQ"] [Tue Aug 18 12:57:05.539633 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:05.540029 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:05.544826 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:62143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/goods.php"] [unique_id "aoSA0dO5rbWdOArH04KQdgAAAWw"] [Tue Aug 18 12:57:05.550343 2026] [security2:error] [pid 66623:tid 66804] [client 132.196.30.78:18678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/h.php"] [unique_id "aoSA0dO5rbWdOArH04KQeAAAATA"] [Tue Aug 18 12:57:05.571328 2026] [security2:error] [pid 67073:tid 67211] [client 104.209.144.33:17253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA0fcmepr5_nHgLbNfxgAAAho"] [Tue Aug 18 12:57:05.571342 2026] [security2:error] [pid 67073:tid 67286] [client 20.226.56.190:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/nd.php"] [unique_id "aoSA0fcmepr5_nHgLbNfxQAAAmU"] [Tue Aug 18 12:57:05.598371 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/jrpga.php"] [unique_id "aoSA0dO5rbWdOArH04KQeQAAASI"] [Tue Aug 18 12:57:05.599243 2026] [security2:error] [pid 67073:tid 67220] [client 197.184.64.235:41934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0fcmepr5_nHgLbNfyAAAAiM"] [Tue Aug 18 12:57:05.599366 2026] [security2:error] [pid 67073:tid 67220] [client 197.184.64.235:41934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0fcmepr5_nHgLbNfyAAAAiM"] [Tue Aug 18 12:57:05.707239 2026] [security2:error] [pid 67073:tid 67264] [client 52.173.121.69:16458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/first.php"] [unique_id "aoSA0fcmepr5_nHgLbNfygAAAk8"] [Tue Aug 18 12:57:05.711103 2026] [security2:error] [pid 67073:tid 67244] [client 213.35.127.232:49269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA0fcmepr5_nHgLbNfywAAAjs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:05.774416 2026] [security2:error] [pid 67073:tid 67317] [client 20.65.69.59:40519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/xinfo.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzQAAAoQ"] [Tue Aug 18 12:57:05.780614 2026] [security2:error] [pid 67073:tid 67230] [client 158.158.34.183:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/sf.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzgAAAi0"] [Tue Aug 18 12:57:05.790153 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.155.199:13317] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin"] [unique_id "aoSA0dO5rbWdOArH04KQnwAAAU4"] [Tue Aug 18 12:57:05.821975 2026] [security2:error] [pid 67073:tid 67261] [client 40.74.65.169:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/index.php"] [unique_id "aoSA0fcmepr5_nHgLbNfzwAAAkw"] [Tue Aug 18 12:57:05.840591 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:05.841055 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:05.920132 2026] [security2:error] [pid 66623:tid 66885] [client 5.161.73.160:55124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSAz9O5rbWdOArH04KP3wAAAYE"], referer: https://ealoggroup.com.br/ [Tue Aug 18 12:57:05.960552 2026] [security2:error] [pid 67073:tid 67324] [client 172.182.200.96:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/Cachex.php"] [unique_id "aoSA0fcmepr5_nHgLbNf1gAAAos"] [Tue Aug 18 12:57:06.093789 2026] [security2:error] [pid 67073:tid 67259] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/class.php"] [unique_id "aoSA0vcmepr5_nHgLbNf3QAAAko"] [Tue Aug 18 12:57:06.105457 2026] [security2:error] [pid 67073:tid 67272] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/flower.php"] [unique_id "aoSA0vcmepr5_nHgLbNf3wAAAlc"] [Tue Aug 18 12:57:06.117466 2026] [security2:error] [pid 67073:tid 67235] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/motu.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4QAAAjI"] [Tue Aug 18 12:57:06.122514 2026] [security2:error] [pid 67073:tid 67237] [client 20.52.168.85:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/sim.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4gAAAjQ"] [Tue Aug 18 12:57:06.129520 2026] [security2:error] [pid 67073:tid 67329] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/404.php"] [unique_id "aoSA0vcmepr5_nHgLbNf4wAAApA"] [Tue Aug 18 12:57:06.140673 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:06.140947 2026] [authz_core:error] [pid 67073:tid 67121] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:06.141287 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.154.236:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA0vcmepr5_nHgLbNf5QAAAoI"] [Tue Aug 18 12:57:06.179495 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:21922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA0tO5rbWdOArH04KQuAAAAXw"] [Tue Aug 18 12:57:06.216901 2026] [security2:error] [pid 67073:tid 67248] [client 20.206.73.37:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/coffexium.php"] [unique_id "aoSA0vcmepr5_nHgLbNf5gAAAj8"] [Tue Aug 18 12:57:06.304264 2026] [security2:error] [pid 67073:tid 67280] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lite.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6AAAAl8"] [Tue Aug 18 12:57:06.316340 2026] [security2:error] [pid 67073:tid 67266] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lock360.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6QAAAlE"] [Tue Aug 18 12:57:06.328794 2026] [security2:error] [pid 67073:tid 67233] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA0vcmepr5_nHgLbNf6wAAAjA"] [Tue Aug 18 12:57:06.342748 2026] [security2:error] [pid 67073:tid 67330] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA0vcmepr5_nHgLbNf7AAAApE"] [Tue Aug 18 12:57:06.347971 2026] [security2:error] [pid 66623:tid 66893] [client 68.155.155.199:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp.php"] [unique_id "aoSA0tO5rbWdOArH04KQvAAAAYk"] [Tue Aug 18 12:57:06.354440 2026] [security2:error] [pid 66623:tid 66843] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.alf.php"] [unique_id "aoSA0tO5rbWdOArH04KQvwAAAVc"] [Tue Aug 18 12:57:06.366816 2026] [security2:error] [pid 67073:tid 67331] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf7wAAApI"] [Tue Aug 18 12:57:06.372529 2026] [security2:error] [pid 67073:tid 67216] [client 192.141.172.134:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8AAAAh8"] [Tue Aug 18 12:57:06.372649 2026] [security2:error] [pid 67073:tid 67216] [client 192.141.172.134:62891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8AAAAh8"] [Tue Aug 18 12:57:06.394554 2026] [security2:error] [pid 67073:tid 67332] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8gAAApM"] [Tue Aug 18 12:57:06.403675 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/min.php"] [unique_id "aoSA0vcmepr5_nHgLbNf8wAAAoc"] [Tue Aug 18 12:57:06.406744 2026] [security2:error] [pid 67073:tid 67206] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9AAAAhU"] [Tue Aug 18 12:57:06.419019 2026] [security2:error] [pid 67073:tid 67210] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9QAAAhk"] [Tue Aug 18 12:57:06.432881 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9gAAAkg"] [Tue Aug 18 12:57:06.444303 2026] [security2:error] [pid 67073:tid 67293] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/xmr.php"] [unique_id "aoSA0vcmepr5_nHgLbNf9wAAAmw"] [Tue Aug 18 12:57:06.456335 2026] [security2:error] [pid 67073:tid 67213] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/about.php"] [unique_id "aoSA0vcmepr5_nHgLbNf-AAAAhw"] [Tue Aug 18 12:57:06.467310 2026] [security2:error] [pid 66623:tid 66876] [client 20.65.69.59:39217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/sym.php"] [unique_id "aoSA0tO5rbWdOArH04KQwgAAAXg"] [Tue Aug 18 12:57:06.541922 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:26712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA0tO5rbWdOArH04KQyAAAAV4"] [Tue Aug 18 12:57:06.557965 2026] [security2:error] [pid 66623:tid 66797] [client 20.215.241.237:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/f35.php"] [unique_id "aoSA0tO5rbWdOArH04KQygAAASk"] [Tue Aug 18 12:57:06.632777 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.136.165:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/tax.php"] [unique_id "aoSA0tO5rbWdOArH04KQzgAAATM"] [Tue Aug 18 12:57:06.718416 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0QAAAR4"] [Tue Aug 18 12:57:06.721880 2026] [security2:error] [pid 66623:tid 66821] [client 20.52.168.85:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/y.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0gAAAUE"] [Tue Aug 18 12:57:06.730241 2026] [security2:error] [pid 67073:tid 67270] [client 132.196.30.78:21897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/a7.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_AAAAlU"] [Tue Aug 18 12:57:06.739627 2026] [security2:error] [pid 67073:tid 67286] [client 104.209.144.33:20458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_gAAAmU"] [Tue Aug 18 12:57:06.742921 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:06.743170 2026] [authz_core:error] [pid 67073:tid 67076] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:06.745645 2026] [security2:error] [pid 67073:tid 67231] [client 213.35.127.232:49473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA0vcmepr5_nHgLbNf_wAAAi4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:06.763297 2026] [security2:error] [pid 67073:tid 67226] [client 135.225.75.187:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/mga.php"] [unique_id "aoSA0vcmepr5_nHgLbNgAQAAAik"] [Tue Aug 18 12:57:06.789675 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/sf.php"] [unique_id "aoSA0tO5rbWdOArH04KQ0wAAAXI"] [Tue Aug 18 12:57:06.822348 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.154.236:48905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/nwwha.php"] [unique_id "aoSA0vcmepr5_nHgLbNgAwAAAjs"] [Tue Aug 18 12:57:06.925144 2026] [security2:error] [pid 67073:tid 67328] [client 158.158.74.177:16531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/txets.php"] [unique_id "aoSA0vcmepr5_nHgLbNgBQAAAo8"] [Tue Aug 18 12:57:07.048777 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:07.049040 2026] [authz_core:error] [pid 67073:tid 67088] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:07.221324 2026] [security2:error] [pid 67073:tid 67292] [client 103.184.169.37:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEAAAAms"] [Tue Aug 18 12:57:07.221440 2026] [security2:error] [pid 67073:tid 67292] [client 103.184.169.37:42074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEAAAAms"] [Tue Aug 18 12:57:07.253062 2026] [security2:error] [pid 67073:tid 67274] [client 40.74.65.169:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file52.php"] [unique_id "aoSA0_cmepr5_nHgLbNgEgAAAlk"] [Tue Aug 18 12:57:07.324868 2026] [security2:error] [pid 66623:tid 66774] [client 20.52.168.85:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/xleet.php"] [unique_id "aoSA09O5rbWdOArH04KQ3gAAARI"] [Tue Aug 18 12:57:07.350051 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:07.350481 2026] [authz_core:error] [pid 67073:tid 67163] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:07.366703 2026] [security2:error] [pid 67073:tid 67235] [client 20.226.56.190:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ri.php"] [unique_id "aoSA0_cmepr5_nHgLbNgIgAAAjI"] [Tue Aug 18 12:57:07.442231 2026] [security2:error] [pid 67073:tid 67237] [client 68.155.155.199:11344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file2.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJAAAAjQ"] [Tue Aug 18 12:57:07.467783 2026] [security2:error] [pid 67073:tid 67302] [client 103.120.71.157:11443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJQAAAnU"] [Tue Aug 18 12:57:07.467901 2026] [security2:error] [pid 67073:tid 67302] [client 103.120.71.157:11443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJQAAAnU"] [Tue Aug 18 12:57:07.487069 2026] [security2:error] [pid 67073:tid 67306] [client 20.215.241.237:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-load.php"] [unique_id "aoSA0_cmepr5_nHgLbNgJwAAAnk"] [Tue Aug 18 12:57:07.581938 2026] [security2:error] [pid 67073:tid 67167] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgKgACXls"] [Tue Aug 18 12:57:07.582075 2026] [security2:error] [pid 67073:tid 67279] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA0_cmepr5_nHgLbNgKgACXls"] [Tue Aug 18 12:57:07.597470 2026] [security2:error] [pid 67073:tid 67248] [client 104.209.144.33:29843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA0_cmepr5_nHgLbNgLAAAAj8"] [Tue Aug 18 12:57:07.639240 2026] [security2:error] [pid 66623:tid 66857] [client 135.225.75.187:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/fs.php"] [unique_id "aoSA09O5rbWdOArH04KQ6gAAAWU"] [Tue Aug 18 12:57:07.640884 2026] [security2:error] [pid 67073:tid 67263] [client 20.118.172.148:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/php8.php"] [unique_id "aoSA0_cmepr5_nHgLbNgLQAAAk4"] [Tue Aug 18 12:57:07.642433 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:39496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/file56.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMQAAAng"] [Tue Aug 18 12:57:07.648695 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:07.648974 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:07.691480 2026] [security2:error] [pid 67073:tid 67266] [client 68.155.154.236:40303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/opsqt.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMgAAAlE"] [Tue Aug 18 12:57:07.716146 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:8032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/g.php"] [unique_id "aoSA0_cmepr5_nHgLbNgMwAAAh0"] [Tue Aug 18 12:57:07.757623 2026] [security2:error] [pid 67073:tid 67224] [client 213.35.127.232:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA0_cmepr5_nHgLbNgNAAAAic"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:07.842630 2026] [security2:error] [pid 67073:tid 67216] [client 20.100.169.31:40535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/php8.php"] [unique_id "aoSA0_cmepr5_nHgLbNgNgAAAh8"] [Tue Aug 18 12:57:07.898481 2026] [security2:error] [pid 66623:tid 66832] [client 86.120.159.145:56482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA09O5rbWdOArH04KQ7AAAAUw"] [Tue Aug 18 12:57:07.898642 2026] [security2:error] [pid 66623:tid 66832] [client 86.120.159.145:56482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA09O5rbWdOArH04KQ7AAAAUw"] [Tue Aug 18 12:57:07.901945 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.69.59:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/ye.php"] [unique_id "aoSA09O5rbWdOArH04KQ8AAAAVI"] [Tue Aug 18 12:57:07.927261 2026] [security2:error] [pid 66623:tid 66868] [client 20.52.168.85:7755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/1index.php"] [unique_id "aoSA09O5rbWdOArH04KQ9AAAAXA"] [Tue Aug 18 12:57:08.009955 2026] [security2:error] [pid 66623:tid 66824] [client 40.74.65.169:43150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/geck.php"] [unique_id "aoSA1NO5rbWdOArH04KQ9wAAAUQ"] [Tue Aug 18 12:57:08.051688 2026] [security2:error] [pid 67073:tid 67257] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgOQAAAkg"] [Tue Aug 18 12:57:08.073508 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/info.php"] [unique_id "aoSA1NO5rbWdOArH04KQ-QAAASg"] [Tue Aug 18 12:57:08.135576 2026] [security2:error] [pid 67073:tid 67247] [client 20.250.13.23:47026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/bless.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgOwAAAj4"] [Tue Aug 18 12:57:08.190362 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.155.199:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/images/class-config.php"] [unique_id "aoSA1NO5rbWdOArH04KQ_QAAASc"] [Tue Aug 18 12:57:08.205965 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.74.177:26146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/u.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgPAAAAmQ"] [Tue Aug 18 12:57:08.222709 2026] [security2:error] [pid 67073:tid 67300] [client 79.127.164.8:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/my.sql"] [unique_id "aoSA1Pcmepr5_nHgLbNgPQAAAnM"], referer: https://medihub.com.br/my.sql [Tue Aug 18 12:57:08.250932 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:08.251232 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:08.354121 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:62118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gecko.php"] [unique_id "aoSA1NO5rbWdOArH04KRAAAAAUY"] [Tue Aug 18 12:57:08.408206 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/chosen.php"] [unique_id "aoSA1NO5rbWdOArH04KRAwAAAVs"] [Tue Aug 18 12:57:08.430594 2026] [security2:error] [pid 67073:tid 67319] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQAAAAoY"] [Tue Aug 18 12:57:08.447245 2026] [security2:error] [pid 67073:tid 67250] [client 138.36.100.162:42980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQQAAAkE"] [Tue Aug 18 12:57:08.451153 2026] [security2:error] [pid 67073:tid 67242] [client 104.209.144.33:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/update/wpupex.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQgAAAjk"] [Tue Aug 18 12:57:08.454954 2026] [fcgid:warn] [pid 66623:tid 66829] (70014)End of file found: [client 66.132.195.33:2782] mod_fcgid: can't get data from http client [Tue Aug 18 12:57:08.460462 2026] [security2:error] [pid 67073:tid 67238] [client 52.173.121.69:16476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQwAAAjU"] [Tue Aug 18 12:57:08.470971 2026] [security2:error] [pid 66623:tid 66882] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/as.php"] [unique_id "aoSA1NO5rbWdOArH04KRCgAAAX4"] [Tue Aug 18 12:57:08.484256 2026] [security2:error] [pid 67073:tid 67223] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/bolt.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgRgAAAiY"] [Tue Aug 18 12:57:08.505732 2026] [cgid:error] [pid 67073:tid 67258] [client 20.197.195.76:0] AH01265: stderr from /home3/cp36imobibrasil/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 12:57:08.517567 2026] [security2:error] [pid 67073:tid 67284] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTAAAAmM"] [Tue Aug 18 12:57:08.531369 2026] [security2:error] [pid 67073:tid 67256] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/edit.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTgAAAkc"] [Tue Aug 18 12:57:08.532927 2026] [security2:error] [pid 66623:tid 66834] [client 20.52.168.85:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/admin.php1"] [unique_id "aoSA1NO5rbWdOArH04KRDAAAAU4"] [Tue Aug 18 12:57:08.543656 2026] [security2:error] [pid 67073:tid 67286] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ff1.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgTwAAAmU"] [Tue Aug 18 12:57:08.545234 2026] [security2:error] [pid 66623:tid 66664] [remote 89.185.225.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1NO5rbWdOArH04KRDQABdBs"] [Tue Aug 18 12:57:08.552223 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:08.552524 2026] [authz_core:error] [pid 67073:tid 67133] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:08.579820 2026] [security2:error] [pid 66623:tid 66881] [client 158.158.34.183:45721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/2.php"] [unique_id "aoSA1NO5rbWdOArH04KRDwAAAX0"] [Tue Aug 18 12:57:08.656599 2026] [security2:error] [pid 66623:tid 66789] [client 135.225.75.187:58997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/wp-tem.php"] [unique_id "aoSA1NO5rbWdOArH04KREwAAASE"] [Tue Aug 18 12:57:08.704072 2026] [security2:error] [pid 67073:tid 67264] [client 40.74.65.169:27717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/biufile.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXQAAAk8"] [Tue Aug 18 12:57:08.730850 2026] [security2:error] [pid 67073:tid 67276] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/fff.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXgAAAls"] [Tue Aug 18 12:57:08.766690 2026] [security2:error] [pid 66623:tid 66769] [client 20.118.172.148:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/simple.php"] [unique_id "aoSA1NO5rbWdOArH04KRFgAAAQ0"] [Tue Aug 18 12:57:08.770841 2026] [security2:error] [pid 66623:tid 66876] [client 68.155.155.199:5043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/alfa.php"] [unique_id "aoSA1NO5rbWdOArH04KRFwAAAXg"] [Tue Aug 18 12:57:08.775775 2026] [security2:error] [pid 66623:tid 66825] [client 213.35.127.232:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA1NO5rbWdOArH04KRGAAAAUU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:08.804086 2026] [security2:error] [pid 67073:tid 67232] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/inputs.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgXwAAAi8"] [Tue Aug 18 12:57:08.822336 2026] [security2:error] [pid 67073:tid 67312] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgYAAAAn8"] [Tue Aug 18 12:57:08.825626 2026] [security2:error] [pid 67073:tid 67250] [client 138.36.100.162:42980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgQQAAAkE"] [Tue Aug 18 12:57:08.826143 2026] [security2:error] [pid 67073:tid 67209] [client 68.155.154.236:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgYQAAAhg"] [Tue Aug 18 12:57:08.851555 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:08.851842 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:08.852147 2026] [security2:error] [pid 67073:tid 67230] [client 172.202.39.151:52035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-login.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZQAAAi0"] [Tue Aug 18 12:57:08.893618 2026] [security2:error] [pid 67073:tid 67260] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/lite.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZgAAAks"] [Tue Aug 18 12:57:09.000240 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSA1Pcmepr5_nHgLbNgZwAAAkI"] [Tue Aug 18 12:57:09.038347 2026] [security2:error] [pid 66623:tid 66849] [client 74.248.18.37:26554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gettest.php"] [unique_id "aoSA1dO5rbWdOArH04KRIwAAAV0"] [Tue Aug 18 12:57:09.084839 2026] [security2:error] [pid 67073:tid 67322] [client 68.155.154.236:16250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgaQAAAok"] [Tue Aug 18 12:57:09.135497 2026] [security2:error] [pid 66623:tid 66821] [client 20.52.168.85:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/M1.php"] [unique_id "aoSA1dO5rbWdOArH04KRJgAAAUE"] [Tue Aug 18 12:57:09.135524 2026] [security2:error] [pid 67073:tid 67317] [client 20.118.172.148:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA1fcmepr5_nHgLbNgagAAAoQ"] [Tue Aug 18 12:57:09.151716 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:09.151982 2026] [authz_core:error] [pid 67073:tid 67142] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:09.153074 2026] [security2:error] [pid 66623:tid 66778] [client 5.31.227.224:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRKAAAARY"] [Tue Aug 18 12:57:09.153160 2026] [security2:error] [pid 66623:tid 66778] [client 5.31.227.224:30417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRKAAAARY"] [Tue Aug 18 12:57:09.210755 2026] [security2:error] [pid 66623:tid 66813] [client 20.215.241.237:25146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSA1dO5rbWdOArH04KRKwAAATk"] [Tue Aug 18 12:57:09.226095 2026] [security2:error] [pid 66623:tid 66866] [client 20.100.169.31:27744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA1dO5rbWdOArH04KRLAAAAW4"] [Tue Aug 18 12:57:09.228081 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.155.199:6598] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSA1dO5rbWdOArH04KRLQAAAW4"] [Tue Aug 18 12:57:09.228140 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.155.199:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSA1dO5rbWdOArH04KRLQAAAW4"] [Tue Aug 18 12:57:09.302614 2026] [security2:error] [pid 67073:tid 67229] [client 132.196.30.78:18773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/manager.php"] [unique_id "aoSA1fcmepr5_nHgLbNgcQAAAiw"] [Tue Aug 18 12:57:09.355699 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:24812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgdQAAAns"] [Tue Aug 18 12:57:09.419323 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:26718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dejavu.php"] [unique_id "aoSA1dO5rbWdOArH04KRMQAAAXY"] [Tue Aug 18 12:57:09.453980 2026] [authz_core:error] [pid 67073:tid 67191] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:09.454230 2026] [authz_core:error] [pid 67073:tid 67191] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:09.467907 2026] [security2:error] [pid 67073:tid 67290] [client 20.118.172.148:54855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/av.php"] [unique_id "aoSA1fcmepr5_nHgLbNgeQAAAmk"] [Tue Aug 18 12:57:09.569743 2026] [security2:error] [pid 67073:tid 67315] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA1fcmepr5_nHgLbNgewAAAoI"] [Tue Aug 18 12:57:09.586659 2026] [security2:error] [pid 67073:tid 67295] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/rip.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfQAAAm4"] [Tue Aug 18 12:57:09.598870 2026] [security2:error] [pid 67073:tid 67252] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/update/da222.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfgAAAkM"] [Tue Aug 18 12:57:09.608162 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNAAAATc"] [Tue Aug 18 12:57:09.608264 2026] [security2:error] [pid 66623:tid 66811] [client 157.20.138.62:63555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNAAAATc"] [Tue Aug 18 12:57:09.611781 2026] [security2:error] [pid 67073:tid 67214] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/upload.php"] [unique_id "aoSA1fcmepr5_nHgLbNgfwAAAh0"] [Tue Aug 18 12:57:09.658302 2026] [security2:error] [pid 67073:tid 67294] [client 158.158.74.177:2635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/ultra.php"] [unique_id "aoSA1fcmepr5_nHgLbNggQAAAm0"] [Tue Aug 18 12:57:09.690901 2026] [security2:error] [pid 67073:tid 67248] [client 74.248.18.37:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/goods.php"] [unique_id "aoSA1fcmepr5_nHgLbNgggAAAj8"] [Tue Aug 18 12:57:09.698775 2026] [security2:error] [pid 67073:tid 67241] [client 172.202.39.151:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.teste.advocaciacriminalgo.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1fcmepr5_nHgLbNggwAAAjg"] [Tue Aug 18 12:57:09.713548 2026] [security2:error] [pid 67073:tid 67207] [client 68.155.154.236:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA1fcmepr5_nHgLbNghAAAAhY"] [Tue Aug 18 12:57:09.733357 2026] [security2:error] [pid 66623:tid 66863] [client 37.40.227.74:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNgAAAWs"] [Tue Aug 18 12:57:09.733472 2026] [security2:error] [pid 66623:tid 66863] [client 37.40.227.74:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KRNgAAAWs"] [Tue Aug 18 12:57:09.740872 2026] [security2:error] [pid 66623:tid 66784] [client 20.52.168.85:7758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sortis.net"] [uri "/ds.php"] [unique_id "aoSA1dO5rbWdOArH04KRNwAAARw"] [Tue Aug 18 12:57:09.782495 2026] [security2:error] [pid 67073:tid 67288] [client 52.173.121.69:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNghwAAAmc"] [Tue Aug 18 12:57:09.788822 2026] [security2:error] [pid 67073:tid 67272] [client 213.35.127.232:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiAAAAlc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:09.790993 2026] [security2:error] [pid 67073:tid 67268] [client 135.225.75.187:19225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/sadd.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiQAAAlM"] [Tue Aug 18 12:57:09.820902 2026] [security2:error] [pid 67073:tid 67269] [client 68.155.156.252:6242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA1fcmepr5_nHgLbNgiwAAAlQ"] [Tue Aug 18 12:57:09.842002 2026] [security2:error] [pid 67073:tid 67326] [client 172.202.39.151:50180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSA1fcmepr5_nHgLbNgjAAAAo0"] [Tue Aug 18 12:57:09.854989 2026] [security2:error] [pid 67073:tid 67249] [client 74.248.136.165:61369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/X7x.php"] [unique_id "aoSA1fcmepr5_nHgLbNgkAAAAkA"] [Tue Aug 18 12:57:09.929895 2026] [security2:error] [pid 66623:tid 66823] [client 149.34.210.141:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KROAAAAUM"] [Tue Aug 18 12:57:10.017553 2026] [security2:error] [pid 67073:tid 67273] [client 20.118.172.148:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmAAAAlg"] [Tue Aug 18 12:57:10.037384 2026] [security2:error] [pid 66623:tid 66770] [client 104.209.144.33:20422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/install.php"] [unique_id "aoSA1tO5rbWdOArH04KROgAAAQ4"] [Tue Aug 18 12:57:10.046421 2026] [security2:error] [pid 67073:tid 67284] [client 20.226.56.190:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tp.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmQAAAmM"] [Tue Aug 18 12:57:10.055906 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:10.056151 2026] [authz_core:error] [pid 67073:tid 67149] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:10.070438 2026] [security2:error] [pid 67073:tid 67323] [client 20.215.241.237:43261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/aaa.php"] [unique_id "aoSA1vcmepr5_nHgLbNgmwAAAoo"] [Tue Aug 18 12:57:10.095313 2026] [security2:error] [pid 67073:tid 67080] [remote 162.241.152.27:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1vcmepr5_nHgLbNgnQACRgQ"] [Tue Aug 18 12:57:10.103597 2026] [security2:error] [pid 67073:tid 67286] [client 172.182.200.96:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA1vcmepr5_nHgLbNgngAAAmU"] [Tue Aug 18 12:57:10.105751 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:26703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aaf.php"] [unique_id "aoSA1tO5rbWdOArH04KROwAAAUA"] [Tue Aug 18 12:57:10.138675 2026] [security2:error] [pid 67073:tid 67228] [client 68.155.155.199:7384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSA1vcmepr5_nHgLbNgoAAAAis"] [Tue Aug 18 12:57:10.196890 2026] [security2:error] [pid 66623:tid 66823] [client 149.34.210.141:56357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA1dO5rbWdOArH04KROAAAAUM"] [Tue Aug 18 12:57:10.214614 2026] [security2:error] [pid 66623:tid 66864] [client 52.173.121.69:24992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA1tO5rbWdOArH04KRPQAAAWw"] [Tue Aug 18 12:57:10.239087 2026] [security2:error] [pid 66623:tid 66878] [client 172.202.39.151:50215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSA1tO5rbWdOArH04KRPgAAAXo"] [Tue Aug 18 12:57:10.357173 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:10.357450 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:10.370800 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/gulu.php"] [unique_id "aoSA1tO5rbWdOArH04KRQQAAASg"] [Tue Aug 18 12:57:10.475091 2026] [security2:error] [pid 67073:tid 67264] [client 158.158.74.177:2636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/un.php"] [unique_id "aoSA1vcmepr5_nHgLbNgsQAAAk8"] [Tue Aug 18 12:57:10.483456 2026] [security2:error] [pid 67073:tid 67215] [client 20.118.172.148:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file2.php"] [unique_id "aoSA1vcmepr5_nHgLbNgsgAAAh4"] [Tue Aug 18 12:57:10.548757 2026] [security2:error] [pid 66623:tid 66800] [client 20.250.13.23:21849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/sagax1.php"] [unique_id "aoSA1tO5rbWdOArH04KRQgAAASw"] [Tue Aug 18 12:57:10.566571 2026] [security2:error] [pid 67073:tid 67281] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wk/index.php"] [unique_id "aoSA1vcmepr5_nHgLbNgtQAAAmA"] [Tue Aug 18 12:57:10.579879 2026] [security2:error] [pid 67073:tid 67236] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-act.php"] [unique_id "aoSA1vcmepr5_nHgLbNgtgAAAjM"] [Tue Aug 18 12:57:10.658216 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:10.658482 2026] [authz_core:error] [pid 67073:tid 67092] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:10.811007 2026] [security2:error] [pid 67073:tid 67317] [client 213.35.127.232:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxQAAAoQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:10.816809 2026] [security2:error] [pid 67073:tid 67252] [client 40.74.65.169:27815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/h02ugyh.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxgAAAkM"] [Tue Aug 18 12:57:10.855321 2026] [security2:error] [pid 67073:tid 67321] [client 20.118.172.148:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/images/class-config.php"] [unique_id "aoSA1vcmepr5_nHgLbNgxwAAAog"] [Tue Aug 18 12:57:10.939955 2026] [security2:error] [pid 67073:tid 67248] [client 20.215.241.237:25091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gecko.php"] [unique_id "aoSA1vcmepr5_nHgLbNgyQAAAj8"] [Tue Aug 18 12:57:10.956876 2026] [security2:error] [pid 67073:tid 67282] [client 178.153.171.161:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1vcmepr5_nHgLbNgywAAAmE"] [Tue Aug 18 12:57:10.957059 2026] [security2:error] [pid 67073:tid 67282] [client 178.153.171.161:4196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1vcmepr5_nHgLbNgywAAAmE"] [Tue Aug 18 12:57:10.959267 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:10.959624 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:10.963809 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.155.199:8561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/asasx.php"] [unique_id "aoSA1tO5rbWdOArH04KRTwAAAUs"] [Tue Aug 18 12:57:11.012373 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA19O5rbWdOArH04KRUAAAASo"] [Tue Aug 18 12:57:11.016286 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.18.37:8034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/h.php"] [unique_id "aoSA1_cmepr5_nHgLbNgzQAAAlE"] [Tue Aug 18 12:57:11.064978 2026] [security2:error] [pid 66623:tid 66841] [client 104.209.144.33:17227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA19O5rbWdOArH04KRUwAAAVU"] [Tue Aug 18 12:57:11.086755 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.156.252:29031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/yj09.php"] [unique_id "aoSA19O5rbWdOArH04KRVQAAAQ0"] [Tue Aug 18 12:57:11.102911 2026] [security2:error] [pid 67073:tid 67207] [client 172.202.39.151:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/xmrlpc.php"] [unique_id "aoSA1_cmepr5_nHgLbNg0QAAAhY"] [Tue Aug 18 12:57:11.113096 2026] [security2:error] [pid 67073:tid 67216] [client 132.196.30.78:18628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/w1.php"] [unique_id "aoSA1_cmepr5_nHgLbNg0wAAAh8"] [Tue Aug 18 12:57:11.125265 2026] [security2:error] [pid 66623:tid 66847] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA1tO5rbWdOArH04KRTAABWyE"] [Tue Aug 18 12:57:11.180646 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.154.236:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA19O5rbWdOArH04KRWQAAAV4"] [Tue Aug 18 12:57:11.254542 2026] [security2:error] [pid 66623:tid 66871] [client 158.158.74.177:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/up.php"] [unique_id "aoSA19O5rbWdOArH04KRWgAAAXM"] [Tue Aug 18 12:57:11.262794 2026] [security2:error] [pid 67073:tid 67214] [client 20.100.169.31:27959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/index/function.php"] [unique_id "aoSA1_cmepr5_nHgLbNg1gAAAh0"] [Tue Aug 18 12:57:11.288160 2026] [security2:error] [pid 67073:tid 67250] [client 20.100.169.31:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/222.php"] [unique_id "aoSA1_cmepr5_nHgLbNg2AAAAkE"] [Tue Aug 18 12:57:11.364124 2026] [security2:error] [pid 66623:tid 66802] [client 20.119.58.187:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/666.php"] [unique_id "aoSA19O5rbWdOArH04KRWwAAAS4"] [Tue Aug 18 12:57:11.435140 2026] [security2:error] [pid 67073:tid 67265] [client 52.173.121.69:16465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA1_cmepr5_nHgLbNg3QAAAlA"] [Tue Aug 18 12:57:11.435597 2026] [security2:error] [pid 66623:tid 66734] [remote 194.163.162.96:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.162.163.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSA19O5rbWdOArH04KRXQABZmE"] [Tue Aug 18 12:57:11.453985 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.172.148:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/alfa.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4AAAAiY"] [Tue Aug 18 12:57:11.489424 2026] [security2:error] [pid 67073:tid 67283] [client 20.119.58.187:11316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bgymj.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4QAAAmI"] [Tue Aug 18 12:57:11.535227 2026] [security2:error] [pid 67073:tid 67258] [client 135.225.75.187:25667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ex.php"] [unique_id "aoSA1_cmepr5_nHgLbNg4wAAAkk"] [Tue Aug 18 12:57:11.564368 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:11.564630 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:11.571411 2026] [security2:error] [pid 67073:tid 67256] [client 40.74.65.169:30055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/155.php"] [unique_id "aoSA1_cmepr5_nHgLbNg5gAAAkc"] [Tue Aug 18 12:57:11.592192 2026] [security2:error] [pid 67073:tid 67270] [client 20.206.73.37:59853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/dex.php"] [unique_id "aoSA1_cmepr5_nHgLbNg5wAAAlU"] [Tue Aug 18 12:57:11.602199 2026] [security2:error] [pid 67073:tid 67286] [client 68.155.154.236:50371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA1_cmepr5_nHgLbNg6AAAAmU"] [Tue Aug 18 12:57:11.625863 2026] [security2:error] [pid 67073:tid 67297] [client 158.158.34.183:12106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSA1_cmepr5_nHgLbNg6QAAAnA"] [Tue Aug 18 12:57:11.661036 2026] [security2:error] [pid 66623:tid 66718] [remote 156.59.198.136:34156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "devota.com.br"] [uri "/img/about/sunset.svg"] [unique_id "aoSA19O5rbWdOArH04KRYAABFlE"], referer: https://devota.com.br/ [Tue Aug 18 12:57:11.669442 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/hello.php"] [unique_id "aoSA1_cmepr5_nHgLbNg7AAAAk0"] [Tue Aug 18 12:57:11.674607 2026] [security2:error] [pid 66623:tid 66867] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSA19O5rbWdOArH04KRYgAAAW8"] [Tue Aug 18 12:57:11.827207 2026] [security2:error] [pid 66623:tid 66849] [client 213.35.127.232:50601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA19O5rbWdOArH04KRZAAAAV0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:11.843534 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bthil.php"] [unique_id "aoSA1_cmepr5_nHgLbNg9wAAAi8"] [Tue Aug 18 12:57:11.846922 2026] [security2:error] [pid 66623:tid 66833] [client 20.215.241.237:25126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/xiugai.php"] [unique_id "aoSA19O5rbWdOArH04KRZQAAAU0"] [Tue Aug 18 12:57:11.862506 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:11.862797 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:11.865053 2026] [security2:error] [pid 67073:tid 67318] [client 20.250.13.23:39679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wpc.php"] [unique_id "aoSA1_cmepr5_nHgLbNg-QAAAoU"] [Tue Aug 18 12:57:11.881818 2026] [security2:error] [pid 67073:tid 67205] [client 132.196.30.78:26266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-login.php"] [unique_id "aoSA1_cmepr5_nHgLbNg-gAAAhQ"] [Tue Aug 18 12:57:11.926284 2026] [security2:error] [pid 67073:tid 67320] [client 95.108.213.173:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.213.108.95.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentaclehost.com.br"] [uri "/index.php"] [unique_id "aoSA1_cmepr5_nHgLbNg8AAAAoc"] [Tue Aug 18 12:57:11.932911 2026] [security2:error] [pid 66623:tid 66807] [client 85.154.68.202:53188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA19O5rbWdOArH04KRaQAAATM"] [Tue Aug 18 12:57:11.933036 2026] [security2:error] [pid 66623:tid 66807] [client 85.154.68.202:53188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA19O5rbWdOArH04KRaQAAATM"] [Tue Aug 18 12:57:11.977156 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.115:38394] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:11.977637 2026] [authz_core:error] [pid 66623:tid 66754] [remote 57.141.22.115:38394] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:12.007208 2026] [security2:error] [pid 67073:tid 67281] [client 20.65.98.162:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/xx.php"] [unique_id "aoSA2Pcmepr5_nHgLbNg_gAAAmA"] [Tue Aug 18 12:57:12.026265 2026] [security2:error] [pid 67073:tid 67217] [client 52.173.121.69:24810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.e543121cd56c.eduardocardosocorretor.com.br"] [uri "/images/security.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAAAAAiA"] [Tue Aug 18 12:57:12.127770 2026] [security2:error] [pid 67073:tid 67237] [client 20.118.172.148:62457] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.bluelord.com.br"] [uri "/1.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAwAAAjQ"] [Tue Aug 18 12:57:12.127880 2026] [security2:error] [pid 67073:tid 67237] [client 20.118.172.148:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/1.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhAwAAAjQ"] [Tue Aug 18 12:57:12.135404 2026] [security2:error] [pid 67073:tid 67293] [client 160.120.140.123:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhBAAAAmw"] [Tue Aug 18 12:57:12.135547 2026] [security2:error] [pid 67073:tid 67293] [client 160.120.140.123:64352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhBAAAAmw"] [Tue Aug 18 12:57:12.163308 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:12.163572 2026] [authz_core:error] [pid 67073:tid 67158] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:12.196397 2026] [security2:error] [pid 67073:tid 67254] [client 20.119.58.187:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xp.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCAAAAkU"] [Tue Aug 18 12:57:12.204559 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.155.199:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/filemanager.php"] [unique_id "aoSA2NO5rbWdOArH04KRawAAASU"] [Tue Aug 18 12:57:12.212284 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.200.96:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCQAAAo4"] [Tue Aug 18 12:57:12.241086 2026] [security2:error] [pid 67073:tid 67308] [client 68.155.154.236:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhCgAAAns"] [Tue Aug 18 12:57:12.248482 2026] [security2:error] [pid 66623:tid 66768] [client 172.202.39.151:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/file.php"] [unique_id "aoSA2NO5rbWdOArH04KRbAAAAQw"] [Tue Aug 18 12:57:12.262886 2026] [security2:error] [pid 67073:tid 67226] [client 40.74.65.169:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ops.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhDQAAAik"] [Tue Aug 18 12:57:12.320636 2026] [security2:error] [pid 66623:tid 66874] [client 74.248.18.37:8018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/images/index.php"] [unique_id "aoSA2NO5rbWdOArH04KRbgAAAXY"] [Tue Aug 18 12:57:12.406658 2026] [security2:error] [pid 67073:tid 67324] [client 20.100.169.31:16033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhEgAAAos"] [Tue Aug 18 12:57:12.463822 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:12.464076 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:12.485891 2026] [security2:error] [pid 67073:tid 67282] [client 135.225.75.187:31402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/tax.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhFQAAAmE"] [Tue Aug 18 12:57:12.533385 2026] [security2:error] [pid 67073:tid 67330] [client 158.158.74.177:16535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/users.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhFgAAApE"] [Tue Aug 18 12:57:12.539555 2026] [security2:error] [pid 67073:tid 67227] [client 104.209.144.33:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhGAAAAio"] [Tue Aug 18 12:57:12.548181 2026] [security2:error] [pid 67073:tid 67295] [client 20.119.58.187:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/reze.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhGQAAAm4"] [Tue Aug 18 12:57:12.656211 2026] [security2:error] [pid 66623:tid 66888] [client 20.215.241.237:48028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/adminner.php"] [unique_id "aoSA2NO5rbWdOArH04KRcwAAAYQ"] [Tue Aug 18 12:57:12.698267 2026] [security2:error] [pid 67073:tid 67269] [client 20.118.172.148:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/222.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhHQAAAlQ"] [Tue Aug 18 12:57:12.726141 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.156.252:19795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/scxy.php"] [unique_id "aoSA2NO5rbWdOArH04KRdgAAAUA"] [Tue Aug 18 12:57:12.748406 2026] [security2:error] [pid 67073:tid 67278] [client 172.202.39.151:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/file.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhIAAAAl0"] [Tue Aug 18 12:57:12.766017 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:12.766284 2026] [authz_core:error] [pid 67073:tid 67101] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:12.822817 2026] [security2:error] [pid 67073:tid 67266] [client 158.158.34.183:12124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhIwAAAlE"] [Tue Aug 18 12:57:12.832064 2026] [security2:error] [pid 67073:tid 67331] [client 132.196.30.78:21890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/default.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhJAAAApI"] [Tue Aug 18 12:57:12.843607 2026] [security2:error] [pid 67073:tid 67241] [client 213.35.127.232:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhJwAAAjg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:12.905342 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/2026w.php"] [unique_id "aoSA2NO5rbWdOArH04KReQAAASc"] [Tue Aug 18 12:57:12.950781 2026] [security2:error] [pid 66623:tid 66794] [client 40.74.65.169:27025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/mac.php"] [unique_id "aoSA2NO5rbWdOArH04KRewAAASY"] [Tue Aug 18 12:57:12.963530 2026] [security2:error] [pid 67073:tid 67275] [client 68.155.154.236:45593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA2Pcmepr5_nHgLbNhKQAAAlo"] [Tue Aug 18 12:57:13.021299 2026] [security2:error] [pid 67073:tid 67265] [client 20.226.56.190:2549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/zj.php"] [unique_id "aoSA2fcmepr5_nHgLbNhLAAAAlA"] [Tue Aug 18 12:57:13.065359 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:13.065625 2026] [authz_core:error] [pid 67073:tid 67162] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:13.097484 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:8016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/index.bak.php"] [unique_id "aoSA2fcmepr5_nHgLbNhLgAAAnM"] [Tue Aug 18 12:57:13.144653 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.155.199:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/themes.php"] [unique_id "aoSA2dO5rbWdOArH04KRgQAAARs"] [Tue Aug 18 12:57:13.191033 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.13.23:25718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/fone1.php"] [unique_id "aoSA2dO5rbWdOArH04KRggAAAQs"] [Tue Aug 18 12:57:13.258034 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11456] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.telesaopedro.com.br"] [uri "/1.php"] [unique_id "aoSA2dO5rbWdOArH04KRhgAAAYg"] [Tue Aug 18 12:57:13.258149 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/1.php"] [unique_id "aoSA2dO5rbWdOArH04KRhgAAAYg"] [Tue Aug 18 12:57:13.263252 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.154.236:16265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA2dO5rbWdOArH04KRhwAAAU4"] [Tue Aug 18 12:57:13.338127 2026] [security2:error] [pid 66623:tid 66818] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA2dO5rbWdOArH04KRiAAAAT4"] [Tue Aug 18 12:57:13.388916 2026] [security2:error] [pid 67073:tid 67208] [client 158.158.74.177:26164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/v.php"] [unique_id "aoSA2fcmepr5_nHgLbNhQwAAAhc"] [Tue Aug 18 12:57:13.413309 2026] [security2:error] [pid 67073:tid 67310] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSA2fcmepr5_nHgLbNhRQAAAn0"] [Tue Aug 18 12:57:13.583196 2026] [security2:error] [pid 67073:tid 67261] [client 172.202.39.151:54697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/epinyins.php"] [unique_id "aoSA2fcmepr5_nHgLbNhSgAAAkw"] [Tue Aug 18 12:57:13.610454 2026] [security2:error] [pid 67073:tid 67212] [client 20.119.58.187:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/2.php"] [unique_id "aoSA2fcmepr5_nHgLbNhTQAAAhs"] [Tue Aug 18 12:57:13.619215 2026] [security2:error] [pid 66623:tid 66788] [client 20.215.241.237:37908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file1221.php"] [unique_id "aoSA2dO5rbWdOArH04KRjAAAASA"] [Tue Aug 18 12:57:13.623701 2026] [security2:error] [pid 66623:tid 66825] [client 20.226.56.190:17868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/x.php"] [unique_id "aoSA2dO5rbWdOArH04KRjQAAAUU"] [Tue Aug 18 12:57:13.670508 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:13.670965 2026] [authz_core:error] [pid 67073:tid 67176] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:13.757074 2026] [security2:error] [pid 67073:tid 67230] [client 20.118.172.148:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/asasx.php"] [unique_id "aoSA2fcmepr5_nHgLbNhUgAAAi0"] [Tue Aug 18 12:57:13.757597 2026] [security2:error] [pid 66623:tid 66859] [client 20.65.98.162:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/uwu.php"] [unique_id "aoSA2dO5rbWdOArH04KRjwAAAWc"] [Tue Aug 18 12:57:13.768226 2026] [security2:error] [pid 67073:tid 67253] [client 79.127.164.8:39702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql_basic.bak"] [unique_id "aoSA2fcmepr5_nHgLbNhVAAAAkQ"], referer: https://medihub.com.br/mysql_basic.bak [Tue Aug 18 12:57:13.775253 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/i.php"] [unique_id "aoSA2dO5rbWdOArH04KRkAAAAX4"] [Tue Aug 18 12:57:13.781364 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:36506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA2fcmepr5_nHgLbNhVQAAAnw"] [Tue Aug 18 12:57:13.820273 2026] [security2:error] [pid 67073:tid 67313] [client 135.225.75.187:31370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/X7x.php"] [unique_id "aoSA2fcmepr5_nHgLbNhVgAAAoA"] [Tue Aug 18 12:57:13.855835 2026] [authz_core:error] [pid 67073:tid 67267] [client 192.178.4.133:57249] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:13.856105 2026] [authz_core:error] [pid 67073:tid 67267] [client 192.178.4.133:57249] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:13.860446 2026] [security2:error] [pid 67073:tid 67246] [client 74.248.18.37:31868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/index/function.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWQAAAj0"] [Tue Aug 18 12:57:13.861730 2026] [security2:error] [pid 66623:tid 66668] [remote 129.121.103.155:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "historiasparadormir.top"] [uri "/wp-login.php"] [unique_id "aoSA2dO5rbWdOArH04KRkQABiR8"] [Tue Aug 18 12:57:13.868189 2026] [security2:error] [pid 67073:tid 67312] [client 213.35.127.232:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWgAAAn8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:13.891187 2026] [security2:error] [pid 67073:tid 67243] [client 68.155.155.199:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA2fcmepr5_nHgLbNhWwAAAjo"] [Tue Aug 18 12:57:13.897580 2026] [security2:error] [pid 67073:tid 67238] [client 20.100.169.31:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/aaa.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXAAAAjU"] [Tue Aug 18 12:57:13.912517 2026] [security2:error] [pid 67073:tid 67262] [client 114.5.214.109:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXQAAAk0"] [Tue Aug 18 12:57:13.912660 2026] [security2:error] [pid 67073:tid 67262] [client 114.5.214.109:49814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2fcmepr5_nHgLbNhXQAAAk0"] [Tue Aug 18 12:57:13.969266 2026] [authz_core:error] [pid 67073:tid 67114] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:13.969569 2026] [authz_core:error] [pid 67073:tid 67114] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:13.973966 2026] [security2:error] [pid 67073:tid 67235] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA2fcmepr5_nHgLbNhYQAAAjI"] [Tue Aug 18 12:57:13.978067 2026] [security2:error] [pid 67073:tid 67304] [client 20.119.58.187:11216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/7.php"] [unique_id "aoSA2fcmepr5_nHgLbNhYgAAAnc"] [Tue Aug 18 12:57:13.986237 2026] [security2:error] [pid 67073:tid 67293] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA2fcmepr5_nHgLbNhZAAAAmw"] [Tue Aug 18 12:57:14.011436 2026] [security2:error] [pid 67073:tid 67234] [client 68.155.154.236:45575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA2vcmepr5_nHgLbNhZgAAAjE"] [Tue Aug 18 12:57:14.067149 2026] [security2:error] [pid 67073:tid 67287] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/0x.php"] [unique_id "aoSA2vcmepr5_nHgLbNhagAAAmY"] [Tue Aug 18 12:57:14.085376 2026] [security2:error] [pid 67073:tid 67255] [client 157.51.166.53:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbAAAAkY"] [Tue Aug 18 12:57:14.085480 2026] [security2:error] [pid 67073:tid 67255] [client 157.51.166.53:64392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbAAAAkY"] [Tue Aug 18 12:57:14.146582 2026] [security2:error] [pid 67073:tid 67274] [client 158.158.74.177:16530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/v5.php"] [unique_id "aoSA2vcmepr5_nHgLbNhbgAAAlk"] [Tue Aug 18 12:57:14.183948 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.26:43774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.184404 2026] [authz_core:error] [pid 67073:tid 67200] [remote 57.141.22.26:43774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.270793 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.271117 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.331308 2026] [security2:error] [pid 66623:tid 66827] [client 20.119.58.187:11306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/10.php"] [unique_id "aoSA2tO5rbWdOArH04KRlQAAAUc"] [Tue Aug 18 12:57:14.348061 2026] [authz_core:error] [pid 66623:tid 66819] [client 192.178.4.133:54432] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.348388 2026] [authz_core:error] [pid 66623:tid 66819] [client 192.178.4.133:54432] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.392052 2026] [security2:error] [pid 67073:tid 67251] [client 74.248.136.165:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ocxla.php"] [unique_id "aoSA2vcmepr5_nHgLbNhdAAAAkI"] [Tue Aug 18 12:57:14.402467 2026] [security2:error] [pid 67073:tid 67282] [client 40.74.65.169:28203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/makeasmtp.php"] [unique_id "aoSA2vcmepr5_nHgLbNhdwAAAmE"] [Tue Aug 18 12:57:14.458913 2026] [authz_core:error] [pid 66623:tid 66739] [remote 57.141.22.3:27164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.459176 2026] [authz_core:error] [pid 66623:tid 66739] [remote 57.141.22.3:27164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.462564 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/filemanager.php"] [unique_id "aoSA2vcmepr5_nHgLbNheAAAAio"] [Tue Aug 18 12:57:14.503060 2026] [security2:error] [pid 67073:tid 67221] [client 74.248.18.37:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/info.php"] [unique_id "aoSA2vcmepr5_nHgLbNhewAAAiQ"] [Tue Aug 18 12:57:14.573212 2026] [security2:error] [pid 66623:tid 66865] [client 5.161.113.195:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "amigosdoronron.com.br"] [uri "/index.php"] [unique_id "aoSA2dO5rbWdOArH04KRfwABbWg"], referer: https://amigosdoronron.com.br/ [Tue Aug 18 12:57:14.574272 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.574698 2026] [authz_core:error] [pid 67073:tid 67139] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.601642 2026] [security2:error] [pid 66623:tid 66866] [client 132.196.30.78:21827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSA2tO5rbWdOArH04KRmwAAAW4"] [Tue Aug 18 12:57:14.624790 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.154.236:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA2vcmepr5_nHgLbNhfwAAAlc"] [Tue Aug 18 12:57:14.625187 2026] [security2:error] [pid 67073:tid 67307] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/222.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgAAAAno"] [Tue Aug 18 12:57:14.636545 2026] [security2:error] [pid 67073:tid 67332] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/aa.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgQAAApM"] [Tue Aug 18 12:57:14.677634 2026] [security2:error] [pid 66623:tid 66775] [client 68.155.156.252:29051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSA2tO5rbWdOArH04KRnQAAARM"] [Tue Aug 18 12:57:14.686078 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/13.php"] [unique_id "aoSA2vcmepr5_nHgLbNhgwAAAmc"] [Tue Aug 18 12:57:14.735076 2026] [security2:error] [pid 67073:tid 67241] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/abcd.php"] [unique_id "aoSA2vcmepr5_nHgLbNhhAAAAjg"] [Tue Aug 18 12:57:14.771760 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:2257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/buy.php"] [unique_id "aoSA2vcmepr5_nHgLbNhhgAAAoY"] [Tue Aug 18 12:57:14.872798 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:14.873063 2026] [authz_core:error] [pid 67073:tid 67128] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:14.881889 2026] [security2:error] [pid 66623:tid 66862] [client 213.35.127.232:51335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA2tO5rbWdOArH04KRogAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:14.901224 2026] [security2:error] [pid 67073:tid 67258] [client 172.202.39.151:31525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA2vcmepr5_nHgLbNhkAAAAkk"] [Tue Aug 18 12:57:14.902843 2026] [security2:error] [pid 67073:tid 67257] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2vcmepr5_nHgLbNhjgACSEk"] [Tue Aug 18 12:57:14.952949 2026] [security2:error] [pid 66623:tid 66781] [client 20.100.169.31:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/info.php"] [unique_id "aoSA2tO5rbWdOArH04KRpQAAARk"] [Tue Aug 18 12:57:14.974620 2026] [security2:error] [pid 67073:tid 67210] [client 20.215.241.237:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inx.php"] [unique_id "aoSA2vcmepr5_nHgLbNhkwAAAhk"] [Tue Aug 18 12:57:14.983472 2026] [security2:error] [pid 67073:tid 67273] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlAAAAlg"] [Tue Aug 18 12:57:14.988301 2026] [security2:error] [pid 67073:tid 67279] [client 20.118.172.148:54875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/themes.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlQAAAl4"] [Tue Aug 18 12:57:14.993363 2026] [security2:error] [pid 67073:tid 67250] [client 158.158.74.177:22765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/we.php"] [unique_id "aoSA2vcmepr5_nHgLbNhlgAAAkE"] [Tue Aug 18 12:57:15.061020 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.154.236:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA29O5rbWdOArH04KRpgAAATQ"] [Tue Aug 18 12:57:15.067304 2026] [security2:error] [pid 66623:tid 66768] [client 20.119.58.187:11320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/100.php"] [unique_id "aoSA29O5rbWdOArH04KRpwAAAQw"] [Tue Aug 18 12:57:15.130925 2026] [security2:error] [pid 67073:tid 67314] [client 132.196.30.78:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnAAAAoE"] [Tue Aug 18 12:57:15.133240 2026] [security2:error] [pid 67073:tid 67309] [client 40.74.65.169:43147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnQAAAnw"] [Tue Aug 18 12:57:15.146120 2026] [security2:error] [pid 66623:tid 66857] [client 192.141.172.134:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA29O5rbWdOArH04KRqgAAAWU"] [Tue Aug 18 12:57:15.146292 2026] [security2:error] [pid 66623:tid 66857] [client 192.141.172.134:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA29O5rbWdOArH04KRqgAAAWU"] [Tue Aug 18 12:57:15.162501 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhngAAAm0"] [Tue Aug 18 12:57:15.162630 2026] [security2:error] [pid 67073:tid 67294] [client 196.12.128.158:53225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhngAAAm0"] [Tue Aug 18 12:57:15.168328 2026] [security2:error] [pid 67073:tid 67243] [client 135.225.75.187:24753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ocxla.php"] [unique_id "aoSA2_cmepr5_nHgLbNhnwAAAjo"] [Tue Aug 18 12:57:15.270700 2026] [security2:error] [pid 67073:tid 67286] [client 74.248.18.37:8017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/inputs.php"] [unique_id "aoSA2_cmepr5_nHgLbNhowAAAmU"] [Tue Aug 18 12:57:15.294203 2026] [security2:error] [pid 67073:tid 67237] [client 104.209.144.33:36515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/well-known/index.php"] [unique_id "aoSA2_cmepr5_nHgLbNhpAAAAjQ"] [Tue Aug 18 12:57:15.367555 2026] [security2:error] [pid 67073:tid 67229] [client 20.65.98.162:42483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/signon.php"] [unique_id "aoSA2_cmepr5_nHgLbNhpwAAAiw"] [Tue Aug 18 12:57:15.418499 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/222.php"] [unique_id "aoSA29O5rbWdOArH04KRsgAAAQ4"] [Tue Aug 18 12:57:15.418689 2026] [security2:error] [pid 67073:tid 67305] [client 172.182.200.96:14080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA2_cmepr5_nHgLbNhqwAAAng"] [Tue Aug 18 12:57:15.429404 2026] [authz_core:error] [pid 67073:tid 67183] [remote 57.141.22.98:32294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:15.429655 2026] [authz_core:error] [pid 67073:tid 67183] [remote 57.141.22.98:32294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:15.478151 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:15.478610 2026] [authz_core:error] [pid 67073:tid 67146] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:15.558263 2026] [security2:error] [pid 67073:tid 67267] [client 20.215.241.237:37928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/reviall.php"] [unique_id "aoSA2_cmepr5_nHgLbNhsQAAAlI"] [Tue Aug 18 12:57:15.560373 2026] [security2:error] [pid 67073:tid 67321] [client 68.155.154.236:16201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSA2_cmepr5_nHgLbNhsgAAAog"] [Tue Aug 18 12:57:15.665776 2026] [security2:error] [pid 67073:tid 67325] [client 20.118.172.148:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA2_cmepr5_nHgLbNhtAAAAow"] [Tue Aug 18 12:57:15.720593 2026] [security2:error] [pid 67073:tid 67317] [client 132.196.30.78:21945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA2_cmepr5_nHgLbNhtgAAAoQ"] [Tue Aug 18 12:57:15.770764 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA29O5rbWdOArH04KRtQAAASc"] [Tue Aug 18 12:57:15.775989 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:15.776261 2026] [authz_core:error] [pid 67073:tid 67195] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:15.808680 2026] [security2:error] [pid 66623:tid 66803] [client 158.158.74.177:16536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wkl.php"] [unique_id "aoSA29O5rbWdOArH04KRtgAAAS8"] [Tue Aug 18 12:57:15.841233 2026] [security2:error] [pid 66623:tid 66826] [client 40.74.65.169:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/system_log.php"] [unique_id "aoSA29O5rbWdOArH04KRtwAAAUY"] [Tue Aug 18 12:57:15.888918 2026] [security2:error] [pid 67073:tid 67302] [client 197.184.64.235:41935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvAAAAnU"] [Tue Aug 18 12:57:15.889040 2026] [security2:error] [pid 67073:tid 67302] [client 197.184.64.235:41935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvAAAAnU"] [Tue Aug 18 12:57:15.892025 2026] [security2:error] [pid 66623:tid 66783] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA29O5rbWdOArH04KRuAAAARs"] [Tue Aug 18 12:57:15.894189 2026] [security2:error] [pid 66623:tid 66836] [client 213.35.127.232:51603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA29O5rbWdOArH04KRuQAAAVA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:15.920773 2026] [security2:error] [pid 67073:tid 67330] [client 74.248.18.37:62084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/install.php"] [unique_id "aoSA2_cmepr5_nHgLbNhvQAAApE"] [Tue Aug 18 12:57:15.980467 2026] [security2:error] [pid 66623:tid 66815] [client 68.155.155.199:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/dropdown.php"] [unique_id "aoSA29O5rbWdOArH04KRvgAAATs"] [Tue Aug 18 12:57:16.010132 2026] [security2:error] [pid 66623:tid 66766] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/akc.php"] [unique_id "aoSA3NO5rbWdOArH04KRvwAAAQo"] [Tue Aug 18 12:57:16.025975 2026] [security2:error] [pid 66623:tid 66834] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/buy.php"] [unique_id "aoSA3NO5rbWdOArH04KRwAAAAU4"] [Tue Aug 18 12:57:16.044922 2026] [security2:error] [pid 66623:tid 66818] [client 20.118.133.132:27455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA3NO5rbWdOArH04KRwQAAAT4"] [Tue Aug 18 12:57:16.079241 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:16.079519 2026] [authz_core:error] [pid 67073:tid 67105] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:16.124383 2026] [security2:error] [pid 67073:tid 67249] [client 135.225.75.187:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/post.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhxQAAAkA"] [Tue Aug 18 12:57:16.165965 2026] [security2:error] [pid 66623:tid 66856] [client 20.215.241.237:20383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/11.php"] [unique_id "aoSA3NO5rbWdOArH04KRwgAAAWQ"] [Tue Aug 18 12:57:16.167202 2026] [security2:error] [pid 67073:tid 67272] [client 20.119.58.187:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/abcd.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhxwAAAlc"] [Tue Aug 18 12:57:16.216118 2026] [security2:error] [pid 67073:tid 67291] [client 158.158.34.183:57357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/dav.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhyQAAAmo"] [Tue Aug 18 12:57:16.350507 2026] [security2:error] [pid 67073:tid 67223] [client 172.182.200.96:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/weozh.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhzQAAAiY"] [Tue Aug 18 12:57:16.364897 2026] [security2:error] [pid 67073:tid 67241] [client 132.196.30.78:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/NewFile.php"] [unique_id "aoSA3Pcmepr5_nHgLbNhzgAAAjg"] [Tue Aug 18 12:57:16.378491 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:16.378755 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:16.411000 2026] [security2:error] [pid 67073:tid 67303] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/cong.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0QAAAnY"] [Tue Aug 18 12:57:16.411054 2026] [security2:error] [pid 67073:tid 67269] [client 20.100.169.31:40290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/abcd.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0AAAAlQ"] [Tue Aug 18 12:57:16.418238 2026] [security2:error] [pid 67073:tid 67300] [client 20.206.73.37:11919] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "villasgarage.com.br"] [uri "/1.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0gAAAnM"] [Tue Aug 18 12:57:16.418323 2026] [security2:error] [pid 67073:tid 67300] [client 20.206.73.37:11919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/1.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh0gAAAnM"] [Tue Aug 18 12:57:16.468983 2026] [security2:error] [pid 67073:tid 67257] [client 20.118.172.148:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/buy.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh1QAAAkg"] [Tue Aug 18 12:57:16.494391 2026] [security2:error] [pid 67073:tid 67311] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA3Pcmepr5_nHgLbNh2AAAAn4"] [Tue Aug 18 12:57:16.519678 2026] [security2:error] [pid 66623:tid 66882] [client 20.119.58.187:11323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/al.php"] [unique_id "aoSA3NO5rbWdOArH04KRxwAAAX4"] [Tue Aug 18 12:57:16.562034 2026] [security2:error] [pid 66623:tid 66843] [client 74.248.18.37:8019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA3NO5rbWdOArH04KRyQAAAVc"] [Tue Aug 18 12:57:16.677070 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:16.677397 2026] [authz_core:error] [pid 67073:tid 67108] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:16.680501 2026] [security2:error] [pid 67073:tid 67253] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/db.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiAgAAAkQ"] [Tue Aug 18 12:57:16.705175 2026] [security2:error] [pid 67073:tid 67309] [client 104.209.144.33:19588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiBAAAAnw"] [Tue Aug 18 12:57:16.758485 2026] [security2:error] [pid 66623:tid 66782] [client 68.155.154.236:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSA3NO5rbWdOArH04KRzAAAARo"] [Tue Aug 18 12:57:16.835463 2026] [security2:error] [pid 66623:tid 66850] [client 20.250.13.23:39662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ncx.php"] [unique_id "aoSA3NO5rbWdOArH04KRzQAAAV4"] [Tue Aug 18 12:57:16.872244 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/alfa.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiCAAAAn8"] [Tue Aug 18 12:57:16.876591 2026] [security2:error] [pid 67073:tid 67304] [client 135.225.75.187:24718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/nhr.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiCwAAAnc"] [Tue Aug 18 12:57:16.916380 2026] [security2:error] [pid 67073:tid 67218] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/dropdown.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDAAAAiE"] [Tue Aug 18 12:57:16.922650 2026] [security2:error] [pid 67073:tid 67240] [client 213.35.127.232:51868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDQAAAjc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:16.926656 2026] [security2:error] [pid 67073:tid 67286] [client 192.141.172.134:63465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDgAAAmU"] [Tue Aug 18 12:57:16.926755 2026] [security2:error] [pid 67073:tid 67286] [client 192.141.172.134:63465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDgAAAmU"] [Tue Aug 18 12:57:16.929007 2026] [security2:error] [pid 67073:tid 67255] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/file.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiDwAAAkY"] [Tue Aug 18 12:57:16.930152 2026] [security2:error] [pid 67073:tid 67290] [client 20.215.241.237:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/File.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEAAAAmk"] [Tue Aug 18 12:57:16.941559 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:50403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEQAAAng"] [Tue Aug 18 12:57:16.944013 2026] [security2:error] [pid 67073:tid 67299] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/goods.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiEgAAAnI"] [Tue Aug 18 12:57:16.956906 2026] [security2:error] [pid 66623:tid 66797] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA3NO5rbWdOArH04KRzwAAASk"] [Tue Aug 18 12:57:16.976222 2026] [security2:error] [pid 67073:tid 67280] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/htaccess.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiFwAAAl8"] [Tue Aug 18 12:57:16.996712 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:26123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/work.php"] [unique_id "aoSA3Pcmepr5_nHgLbNiGgAAAlI"] [Tue Aug 18 12:57:17.032606 2026] [security2:error] [pid 66623:tid 66809] [client 85.208.96.201:30028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/2025/06/14/hoot-loot-status-trial-in-the-high-5-game-neteller-casino-dragonz-5-deposit-95-rtp-2025-pt-sil/"] [unique_id "aoSA3dO5rbWdOArH04KR0QAAATU"] [Tue Aug 18 12:57:17.032734 2026] [security2:error] [pid 66623:tid 66809] [client 85.208.96.201:30028] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/2025/06/14/hoot-loot-status-trial-in-the-high-5-game-neteller-casino-dragonz-5-deposit-95-rtp-2025-pt-sil/"] [unique_id "aoSA3dO5rbWdOArH04KR0QAAATU"] [Tue Aug 18 12:57:17.040566 2026] [security2:error] [pid 67073:tid 67251] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/images/wso.php"] [unique_id "aoSA3fcmepr5_nHgLbNiHQAAAkI"] [Tue Aug 18 12:57:17.076472 2026] [autoindex:error] [pid 66623:tid 66807] [client 172.202.39.151:43213] AH01276: Cannot serve directory /home1/querofi1/loja1.queroficarnanet.com/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:17.078857 2026] [security2:error] [pid 66623:tid 66774] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSA3dO5rbWdOArH04KR0wAAARI"] [Tue Aug 18 12:57:17.085674 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.155.199:4361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/inputs.php"] [unique_id "aoSA3dO5rbWdOArH04KR1AAAAWE"] [Tue Aug 18 12:57:17.103445 2026] [security2:error] [pid 67073:tid 67227] [client 20.118.172.148:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/dropdown.php"] [unique_id "aoSA3fcmepr5_nHgLbNiIQAAAio"] [Tue Aug 18 12:57:17.194660 2026] [security2:error] [pid 66623:tid 66866] [client 49.13.164.148:17962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR0AAAAW4"], referer: https://agrimotor.com.br [Tue Aug 18 12:57:17.198930 2026] [security2:error] [pid 67073:tid 67324] [client 74.248.18.37:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/item.php"] [unique_id "aoSA3fcmepr5_nHgLbNiJQAAAos"] [Tue Aug 18 12:57:17.251025 2026] [security2:error] [pid 67073:tid 67313] [client 158.158.34.183:28885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/wp_wol.php"] [unique_id "aoSA3fcmepr5_nHgLbNiKAAAAoA"] [Tue Aug 18 12:57:17.272589 2026] [security2:error] [pid 67073:tid 67326] [client 172.182.200.96:14145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-2019.php"] [unique_id "aoSA3fcmepr5_nHgLbNiKgAAAo0"] [Tue Aug 18 12:57:17.283463 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:17.283928 2026] [authz_core:error] [pid 67073:tid 67082] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:17.284525 2026] [security2:error] [pid 66623:tid 66819] [client 20.119.58.187:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/as.php"] [unique_id "aoSA3dO5rbWdOArH04KR1wAAAT8"] [Tue Aug 18 12:57:17.335644 2026] [security2:error] [pid 66623:tid 66816] [client 74.7.228.11:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.adobank.com.br"] [uri "/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR1QABPHA"] [Tue Aug 18 12:57:17.345746 2026] [security2:error] [pid 67073:tid 67331] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/info.php"] [unique_id "aoSA3fcmepr5_nHgLbNiLAAAApI"] [Tue Aug 18 12:57:17.346485 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.169.31:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-good.php"] [unique_id "aoSA3dO5rbWdOArH04KR2AAAAYE"] [Tue Aug 18 12:57:17.349099 2026] [security2:error] [pid 67073:tid 67214] [client 40.74.65.169:27026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/pucci.php"] [unique_id "aoSA3fcmepr5_nHgLbNiLQAAAh0"] [Tue Aug 18 12:57:17.429468 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMgAAAi0"] [Tue Aug 18 12:57:17.429589 2026] [security2:error] [pid 67073:tid 67230] [client 37.40.227.74:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMgAAAi0"] [Tue Aug 18 12:57:17.444369 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR2gAAAXQ"] [Tue Aug 18 12:57:17.463089 2026] [security2:error] [pid 67073:tid 67269] [client 20.215.241.237:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fi22.php"] [unique_id "aoSA3fcmepr5_nHgLbNiMwAAAlQ"] [Tue Aug 18 12:57:17.578703 2026] [authz_core:error] [pid 67073:tid 67119] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:17.578968 2026] [authz_core:error] [pid 67073:tid 67119] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:17.579335 2026] [authz_core:error] [pid 67073:tid 67133] [remote 57.141.22.85:40878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:17.579713 2026] [authz_core:error] [pid 67073:tid 67133] [remote 57.141.22.85:40878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:17.618331 2026] [security2:error] [pid 66623:tid 66845] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/profile.php"] [unique_id "aoSA3dO5rbWdOArH04KR4AAAAVk"] [Tue Aug 18 12:57:17.625300 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:25709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPAAAAlY"] [Tue Aug 18 12:57:17.636480 2026] [security2:error] [pid 67073:tid 67323] [client 20.119.58.187:11298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/aa.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPQAAAoo"] [Tue Aug 18 12:57:17.645690 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.155.199:1917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/100.php"] [unique_id "aoSA3fcmepr5_nHgLbNiPwAAAkw"] [Tue Aug 18 12:57:17.763843 2026] [security2:error] [pid 67073:tid 67243] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/sx.php"] [unique_id "aoSA3fcmepr5_nHgLbNiRwAAAjo"] [Tue Aug 18 12:57:17.770609 2026] [security2:error] [pid 67073:tid 67296] [client 158.158.74.177:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/worksec.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSAAAAm8"] [Tue Aug 18 12:57:17.785429 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.136.165:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/post.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSQAAAjU"] [Tue Aug 18 12:57:17.786614 2026] [security2:error] [pid 66623:tid 66832] [client 68.155.154.236:16306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA3dO5rbWdOArH04KR4QAAAUw"] [Tue Aug 18 12:57:17.789751 2026] [security2:error] [pid 67073:tid 67260] [client 170.81.43.147:40146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.43.81.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.fbenevides.com.br"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "aoSA3fcmepr5_nHgLbNiSgAAAks"] [Tue Aug 18 12:57:17.838399 2026] [security2:error] [pid 67073:tid 67211] [client 103.184.169.37:42114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiTwAAAho"] [Tue Aug 18 12:57:17.838764 2026] [security2:error] [pid 67073:tid 67211] [client 103.184.169.37:42114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiTwAAAho"] [Tue Aug 18 12:57:17.840938 2026] [security2:error] [pid 67073:tid 67304] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA3fcmepr5_nHgLbNiUAAAAnc"] [Tue Aug 18 12:57:17.846426 2026] [security2:error] [pid 67073:tid 67217] [client 132.196.30.78:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSA3fcmepr5_nHgLbNiUQAAAiA"] [Tue Aug 18 12:57:17.870215 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.18.37:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/js.php"] [unique_id "aoSA3dO5rbWdOArH04KR4gAAAWs"] [Tue Aug 18 12:57:17.884965 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:17.885396 2026] [authz_core:error] [pid 67073:tid 67129] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:17.936392 2026] [security2:error] [pid 67073:tid 67310] [client 213.35.127.232:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA3fcmepr5_nHgLbNiWgAAAn0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:17.964770 2026] [security2:error] [pid 67073:tid 67306] [client 68.155.156.252:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXAAAAnk"] [Tue Aug 18 12:57:17.977943 2026] [security2:error] [pid 67073:tid 67263] [client 20.197.195.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduardocardosocorretor.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXgAAAk4"] [Tue Aug 18 12:57:17.993827 2026] [security2:error] [pid 67073:tid 67255] [client 20.119.58.187:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/abc.php"] [unique_id "aoSA3fcmepr5_nHgLbNiXwAAAkY"] [Tue Aug 18 12:57:18.049664 2026] [security2:error] [pid 66623:tid 66801] [client 20.215.241.237:37913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA3tO5rbWdOArH04KR5QAAAS0"] [Tue Aug 18 12:57:18.056182 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:45573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA3tO5rbWdOArH04KR5wAAAQ4"] [Tue Aug 18 12:57:18.068561 2026] [security2:error] [pid 66623:tid 66875] [client 20.118.172.148:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/inputs.php"] [unique_id "aoSA3tO5rbWdOArH04KR6QAAAXc"] [Tue Aug 18 12:57:18.181576 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:18.181890 2026] [authz_core:error] [pid 67073:tid 67081] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:18.213739 2026] [security2:error] [pid 66623:tid 66874] [client 103.120.71.157:54636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3tO5rbWdOArH04KR8gAAAXY"] [Tue Aug 18 12:57:18.213847 2026] [security2:error] [pid 66623:tid 66874] [client 103.120.71.157:54636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3tO5rbWdOArH04KR8gAAAXY"] [Tue Aug 18 12:57:18.255286 2026] [security2:error] [pid 66623:tid 66829] [client 68.155.155.199:7119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/akc.php"] [unique_id "aoSA3tO5rbWdOArH04KR9AAAAUk"] [Tue Aug 18 12:57:18.270936 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/coffee.php"] [unique_id "aoSA3vcmepr5_nHgLbNiZgAAAiQ"] [Tue Aug 18 12:57:18.281111 2026] [security2:error] [pid 67073:tid 67321] [client 20.100.169.31:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/simple.php"] [unique_id "aoSA3vcmepr5_nHgLbNiZwAAAog"] [Tue Aug 18 12:57:18.388792 2026] [security2:error] [pid 67073:tid 67320] [client 20.119.58.187:11307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/av.php"] [unique_id "aoSA3vcmepr5_nHgLbNibQAAAoc"] [Tue Aug 18 12:57:18.401498 2026] [security2:error] [pid 67073:tid 67227] [client 79.127.164.8:52192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql_basic.sql"] [unique_id "aoSA3vcmepr5_nHgLbNibgAAAio"], referer: https://medihub.com.br/mysql_basic.sql [Tue Aug 18 12:57:18.455388 2026] [security2:error] [pid 67073:tid 67272] [client 20.65.98.162:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file61.php"] [unique_id "aoSA3vcmepr5_nHgLbNicgAAAlc"] [Tue Aug 18 12:57:18.465767 2026] [security2:error] [pid 66623:tid 66892] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA3tO5rbWdOArH04KR_AAAAYg"] [Tue Aug 18 12:57:18.523670 2026] [security2:error] [pid 67073:tid 67207] [client 74.248.18.37:8007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/k.php"] [unique_id "aoSA3vcmepr5_nHgLbNidQAAAhY"] [Tue Aug 18 12:57:18.602959 2026] [security2:error] [pid 67073:tid 67247] [client 20.226.56.190:23752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yn.php"] [unique_id "aoSA3vcmepr5_nHgLbNidgAAAj4"] [Tue Aug 18 12:57:18.624392 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA3vcmepr5_nHgLbNieAAAAmI"] [Tue Aug 18 12:57:18.633102 2026] [security2:error] [pid 67073:tid 67277] [client 104.209.144.33:36497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA3vcmepr5_nHgLbNieQAAAlw"] [Tue Aug 18 12:57:18.646533 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/weozh.php"] [unique_id "aoSA3vcmepr5_nHgLbNiegAAAkg"] [Tue Aug 18 12:57:18.658178 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:57336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA3vcmepr5_nHgLbNiewAAAn4"] [Tue Aug 18 12:57:18.704772 2026] [security2:error] [pid 67073:tid 67268] [client 111.221.44.12:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.221.111.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA3vcmepr5_nHgLbNifQAAAlM"] [Tue Aug 18 12:57:18.757008 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA3vcmepr5_nHgLbNifwAAAjw"] [Tue Aug 18 12:57:18.781979 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:18.782237 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:18.793884 2026] [security2:error] [pid 67073:tid 67284] [client 135.225.75.187:36573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ws79.php"] [unique_id "aoSA3vcmepr5_nHgLbNigwAAAmM"] [Tue Aug 18 12:57:18.807119 2026] [security2:error] [pid 66623:tid 66890] [client 40.74.65.169:27831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-temp.php"] [unique_id "aoSA3tO5rbWdOArH04KSCgAAAYY"] [Tue Aug 18 12:57:18.853205 2026] [security2:error] [pid 67073:tid 67258] [client 20.118.172.148:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/100.php"] [unique_id "aoSA3vcmepr5_nHgLbNihAAAAkk"] [Tue Aug 18 12:57:18.861119 2026] [security2:error] [pid 67073:tid 67209] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/rymmm.php"] [unique_id "aoSA3vcmepr5_nHgLbNihQAAAhg"] [Tue Aug 18 12:57:18.931995 2026] [security2:error] [pid 67073:tid 67238] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/lddxs.php"] [unique_id "aoSA3vcmepr5_nHgLbNiiAAAAjU"] [Tue Aug 18 12:57:18.941111 2026] [security2:error] [pid 67073:tid 67260] [client 172.182.200.96:7621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/rymmm.php"] [unique_id "aoSA3vcmepr5_nHgLbNiiQAAAks"] [Tue Aug 18 12:57:18.941730 2026] [security2:error] [pid 67073:tid 67262] [client 20.118.133.132:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA3vcmepr5_nHgLbNiigAAAk0"] [Tue Aug 18 12:57:18.950193 2026] [security2:error] [pid 67073:tid 67269] [client 213.35.127.232:52329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA3vcmepr5_nHgLbNijAAAAlQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:19.084705 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:19.084978 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:19.108787 2026] [security2:error] [pid 67073:tid 67266] [client 20.119.58.187:11309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/asus.php"] [unique_id "aoSA3_cmepr5_nHgLbNikwAAAlE"] [Tue Aug 18 12:57:19.122617 2026] [security2:error] [pid 67073:tid 67273] [client 20.100.169.31:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/edit-tags.php"] [unique_id "aoSA3_cmepr5_nHgLbNilQAAAlg"] [Tue Aug 18 12:57:19.175661 2026] [security2:error] [pid 67073:tid 67288] [client 20.100.169.31:12561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/a.php"] [unique_id "aoSA3_cmepr5_nHgLbNimAAAAmc"] [Tue Aug 18 12:57:19.265344 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/media/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNinAAAAms"] [Tue Aug 18 12:57:19.294259 2026] [security2:error] [pid 67073:tid 67276] [client 20.118.172.148:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/akc.php"] [unique_id "aoSA3_cmepr5_nHgLbNingAAAls"] [Tue Aug 18 12:57:19.308848 2026] [security2:error] [pid 67073:tid 67252] [client 20.215.241.237:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSA3_cmepr5_nHgLbNinwAAAkM"] [Tue Aug 18 12:57:19.355057 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSA3_cmepr5_nHgLbNiogAAAjA"] [Tue Aug 18 12:57:19.356633 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zjggu.php"] [unique_id "aoSA3_cmepr5_nHgLbNiowAAAm4"] [Tue Aug 18 12:57:19.358425 2026] [fcgid:warn] [pid 67073:tid 67303] (70014)End of file found: [client 199.45.154.71:57014] mod_fcgid: can't get data from http client [Tue Aug 18 12:57:19.384919 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:19.385182 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:19.385761 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA39O5rbWdOArH04KSEAAAAWM"] [Tue Aug 18 12:57:19.412770 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.154.236:16218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNipgAAAoI"] [Tue Aug 18 12:57:19.486150 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA3_cmepr5_nHgLbNiqwAAAmE"] [Tue Aug 18 12:57:19.496692 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.136.165:17988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/nhr.php"] [unique_id "aoSA39O5rbWdOArH04KSEgAAAVg"] [Tue Aug 18 12:57:19.499244 2026] [security2:error] [pid 67073:tid 67294] [client 20.119.58.187:11301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/about.php"] [unique_id "aoSA3_cmepr5_nHgLbNirAAAAm0"] [Tue Aug 18 12:57:19.525088 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:40285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA3_cmepr5_nHgLbNirgAAApM"] [Tue Aug 18 12:57:19.546911 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:31656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/11.php"] [unique_id "aoSA39O5rbWdOArH04KSFAAAAWY"] [Tue Aug 18 12:57:19.574363 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA39O5rbWdOArH04KSFQAAATY"] [Tue Aug 18 12:57:19.608813 2026] [authz_core:error] [pid 66623:tid 66696] [remote 57.141.22.107:35194] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:19.609096 2026] [authz_core:error] [pid 66623:tid 66696] [remote 57.141.22.107:35194] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:19.639468 2026] [security2:error] [pid 67073:tid 67275] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/kopyw.php"] [unique_id "aoSA3_cmepr5_nHgLbNiswAAAlo"] [Tue Aug 18 12:57:19.682373 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:62086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSA39O5rbWdOArH04KSGQAAARM"] [Tue Aug 18 12:57:19.689098 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:19.689352 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:19.698989 2026] [security2:error] [pid 67073:tid 67239] [client 68.155.156.252:14997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/blurbs.php"] [unique_id "aoSA3_cmepr5_nHgLbNitQAAAjY"] [Tue Aug 18 12:57:19.730968 2026] [security2:error] [pid 67073:tid 67304] [client 5.31.227.224:7859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuAAAAnc"] [Tue Aug 18 12:57:19.738876 2026] [security2:error] [pid 67073:tid 67304] [client 5.31.227.224:7859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuAAAAnc"] [Tue Aug 18 12:57:19.764843 2026] [security2:error] [pid 67073:tid 67305] [client 158.158.34.183:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/fm2.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuQAAAng"] [Tue Aug 18 12:57:19.774272 2026] [security2:error] [pid 67073:tid 67277] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zznmg.php"] [unique_id "aoSA3_cmepr5_nHgLbNiuwAAAlw"] [Tue Aug 18 12:57:19.798567 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA3_cmepr5_nHgLbNivgAAAkA"] [Tue Aug 18 12:57:19.803680 2026] [security2:error] [pid 67073:tid 67271] [client 135.225.75.187:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/rtx.php"] [unique_id "aoSA3_cmepr5_nHgLbNivwAAAlY"] [Tue Aug 18 12:57:19.820835 2026] [security2:error] [pid 67073:tid 67208] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwAAAAhc"] [Tue Aug 18 12:57:19.822759 2026] [security2:error] [pid 67073:tid 67245] [client 172.202.39.151:31491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwQAAAjw"] [Tue Aug 18 12:57:19.834590 2026] [security2:error] [pid 67073:tid 67293] [client 111.221.44.12:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.221.111.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwgAAAmw"] [Tue Aug 18 12:57:19.842434 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/oivcl.php"] [unique_id "aoSA39O5rbWdOArH04KSHgAAATI"] [Tue Aug 18 12:57:19.853590 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/atomlib.php"] [unique_id "aoSA39O5rbWdOArH04KSHwAAARU"] [Tue Aug 18 12:57:19.858819 2026] [security2:error] [pid 67073:tid 67279] [client 68.155.154.236:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA3_cmepr5_nHgLbNiwwAAAl4"] [Tue Aug 18 12:57:19.877333 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zugvi.php"] [unique_id "aoSA3_cmepr5_nHgLbNixAAAAkQ"] [Tue Aug 18 12:57:19.900643 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/memberfuns.php"] [unique_id "aoSA39O5rbWdOArH04KSIAAAATU"] [Tue Aug 18 12:57:19.967562 2026] [security2:error] [pid 67073:tid 67287] [client 213.35.127.232:52549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA3_cmepr5_nHgLbNixwAAAmY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:19.986378 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:19.986651 2026] [authz_core:error] [pid 67073:tid 67151] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:20.042958 2026] [security2:error] [pid 66623:tid 66792] [client 20.206.73.37:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA4NO5rbWdOArH04KSIgAAASQ"] [Tue Aug 18 12:57:20.046435 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.56.190:2558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vm.php"] [unique_id "aoSA4NO5rbWdOArH04KSIwAAAVk"] [Tue Aug 18 12:57:20.125233 2026] [security2:error] [pid 66623:tid 66801] [client 68.155.155.199:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/php.php"] [unique_id "aoSA4NO5rbWdOArH04KSJgAAAS0"] [Tue Aug 18 12:57:20.131729 2026] [security2:error] [pid 67073:tid 67308] [client 132.196.30.78:21847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizAAAAns"] [Tue Aug 18 12:57:20.142569 2026] [security2:error] [pid 67073:tid 67205] [client 157.20.138.62:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizQAAAhQ"] [Tue Aug 18 12:57:20.142745 2026] [security2:error] [pid 67073:tid 67205] [client 157.20.138.62:64175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNizQAAAhQ"] [Tue Aug 18 12:57:20.148894 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:54873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/php.php"] [unique_id "aoSA4NO5rbWdOArH04KSJwAAAWw"] [Tue Aug 18 12:57:20.159862 2026] [security2:error] [pid 66623:tid 66878] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wsrer.php"] [unique_id "aoSA4NO5rbWdOArH04KSKQAAAXo"] [Tue Aug 18 12:57:20.208553 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSA4NO5rbWdOArH04KSKwAAARw"] [Tue Aug 18 12:57:20.227831 2026] [security2:error] [pid 66623:tid 66839] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA4NO5rbWdOArH04KSLQAAAVM"] [Tue Aug 18 12:57:20.246403 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.154.236:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/well-known/index.php"] [unique_id "aoSA4NO5rbWdOArH04KSLgAAASU"] [Tue Aug 18 12:57:20.269478 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:26694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/puc.php"] [unique_id "aoSA4NO5rbWdOArH04KSLwAAAXY"] [Tue Aug 18 12:57:20.371961 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.56.190:52085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eg.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi0wAAAn8"] [Tue Aug 18 12:57:20.406039 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/yxijx.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1QAAAn0"] [Tue Aug 18 12:57:20.417587 2026] [security2:error] [pid 67073:tid 67278] [client 149.34.210.141:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1gAAAl0"] [Tue Aug 18 12:57:20.459783 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA4NO5rbWdOArH04KSMQAAAVQ"] [Tue Aug 18 12:57:20.517201 2026] [security2:error] [pid 67073:tid 67263] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/jrpga.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi2QAAAk4"] [Tue Aug 18 12:57:20.546172 2026] [security2:error] [pid 66623:tid 66879] [client 158.158.34.183:19931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSA4NO5rbWdOArH04KSMwAAAXs"] [Tue Aug 18 12:57:20.555995 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.200.96:7619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA4NO5rbWdOArH04KSNAAAASY"] [Tue Aug 18 12:57:20.570957 2026] [security2:error] [pid 67073:tid 67299] [client 172.202.39.151:44977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/function/function.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi2wAAAnI"] [Tue Aug 18 12:57:20.590995 2026] [security2:error] [pid 66623:tid 66835] [client 74.248.18.37:31846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mgrr.php"] [unique_id "aoSA4NO5rbWdOArH04KSNQAAAU8"] [Tue Aug 18 12:57:20.598205 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/t.php"] [unique_id "aoSA4NO5rbWdOArH04KSNgAAAYM"] [Tue Aug 18 12:57:20.602415 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:11207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/b.php"] [unique_id "aoSA4NO5rbWdOArH04KSNwAAAYg"] [Tue Aug 18 12:57:20.646615 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.154.236:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi3QAAAhs"] [Tue Aug 18 12:57:20.672389 2026] [security2:error] [pid 66623:tid 66856] [client 20.215.241.237:44136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA4NO5rbWdOArH04KSOAAAAWQ"] [Tue Aug 18 12:57:20.686687 2026] [security2:error] [pid 67073:tid 67278] [client 149.34.210.141:57066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi1gAAAl0"] [Tue Aug 18 12:57:20.718284 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA4NO5rbWdOArH04KSOQAAAXw"] [Tue Aug 18 12:57:20.831192 2026] [security2:error] [pid 66623:tid 66881] [client 135.225.75.187:48262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/end.php"] [unique_id "aoSA4NO5rbWdOArH04KSOwAAAX0"] [Tue Aug 18 12:57:20.845962 2026] [security2:error] [pid 66623:tid 66859] [client 20.118.133.132:26814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/img.php"] [unique_id "aoSA4NO5rbWdOArH04KSPAAAAWc"] [Tue Aug 18 12:57:20.857143 2026] [security2:error] [pid 67073:tid 67317] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/nwwha.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi7QAAAoQ"] [Tue Aug 18 12:57:20.890802 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:20.891055 2026] [authz_core:error] [pid 67073:tid 67084] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:20.963286 2026] [security2:error] [pid 66623:tid 66780] [client 20.119.58.187:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/buy.php"] [unique_id "aoSA4NO5rbWdOArH04KSPQAAARg"] [Tue Aug 18 12:57:20.963539 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.56.190:31022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/uk.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi8AAAAoA"] [Tue Aug 18 12:57:20.986570 2026] [security2:error] [pid 67073:tid 67255] [client 213.35.127.232:52767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA4Pcmepr5_nHgLbNi8wAAAkY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:21.013978 2026] [security2:error] [pid 66623:tid 66814] [client 68.155.154.236:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA4dO5rbWdOArH04KSTQAAATo"] [Tue Aug 18 12:57:21.019301 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.154.236:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA4dO5rbWdOArH04KSTgAAAUI"] [Tue Aug 18 12:57:21.020106 2026] [security2:error] [pid 67073:tid 67252] [client 132.196.30.78:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/themes.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9QAAAkM"] [Tue Aug 18 12:57:21.028552 2026] [security2:error] [pid 67073:tid 67198] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9gACNHo"] [Tue Aug 18 12:57:21.028699 2026] [security2:error] [pid 67073:tid 67237] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9gACNHo"] [Tue Aug 18 12:57:21.050155 2026] [security2:error] [pid 67073:tid 67332] [client 20.118.172.148:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/index/function.php"] [unique_id "aoSA4fcmepr5_nHgLbNi9wAAApM"] [Tue Aug 18 12:57:21.101196 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/opsqt.php"] [unique_id "aoSA4dO5rbWdOArH04KSYAAAASE"] [Tue Aug 18 12:57:21.109586 2026] [security2:error] [pid 67073:tid 67220] [client 68.155.155.199:1861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/t.php"] [unique_id "aoSA4fcmepr5_nHgLbNi-QAAAiM"] [Tue Aug 18 12:57:21.131620 2026] [security2:error] [pid 67073:tid 67256] [client 20.100.169.31:14567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/chosen.php"] [unique_id "aoSA4fcmepr5_nHgLbNi-wAAAkc"] [Tue Aug 18 12:57:21.189959 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:21.190212 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:21.214008 2026] [security2:error] [pid 67073:tid 67302] [client 172.182.200.96:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/lddxs.php"] [unique_id "aoSA4fcmepr5_nHgLbNjAQAAAnU"] [Tue Aug 18 12:57:21.314821 2026] [security2:error] [pid 67073:tid 67226] [client 20.100.169.31:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/u.php"] [unique_id "aoSA4fcmepr5_nHgLbNjBgAAAik"] [Tue Aug 18 12:57:21.319201 2026] [security2:error] [pid 66623:tid 66883] [client 20.119.58.187:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/bless.php"] [unique_id "aoSA4dO5rbWdOArH04KSZAAAAX8"] [Tue Aug 18 12:57:21.336241 2026] [security2:error] [pid 66623:tid 66813] [client 40.74.65.169:27796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/8.php"] [unique_id "aoSA4dO5rbWdOArH04KSZQAAATk"] [Tue Aug 18 12:57:21.397833 2026] [security2:error] [pid 66623:tid 66833] [client 74.248.18.37:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/ioxi-o.php"] [unique_id "aoSA4dO5rbWdOArH04KSZwAAAU0"] [Tue Aug 18 12:57:21.421923 2026] [security2:error] [pid 66623:tid 66669] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4dO5rbWdOArH04KSaAABZiA"] [Tue Aug 18 12:57:21.422121 2026] [security2:error] [pid 66623:tid 66858] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4dO5rbWdOArH04KSaAABZiA"] [Tue Aug 18 12:57:21.435878 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA4fcmepr5_nHgLbNjCgAAAo0"] [Tue Aug 18 12:57:21.462367 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.18.37:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mini.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDAAAAmQ"] [Tue Aug 18 12:57:21.494680 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:21.494987 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:21.503041 2026] [security2:error] [pid 67073:tid 67221] [client 178.153.171.161:41402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDgAAAiQ"] [Tue Aug 18 12:57:21.503194 2026] [security2:error] [pid 67073:tid 67221] [client 178.153.171.161:41402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDgAAAiQ"] [Tue Aug 18 12:57:21.507303 2026] [security2:error] [pid 67073:tid 67283] [client 20.215.241.237:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSA4fcmepr5_nHgLbNjDwAAAmI"] [Tue Aug 18 12:57:21.531507 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA4fcmepr5_nHgLbNjEQAAAlM"] [Tue Aug 18 12:57:21.541026 2026] [security2:error] [pid 67073:tid 67271] [client 20.65.98.162:58053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/copypaths.php"] [unique_id "aoSA4fcmepr5_nHgLbNjEgAAAlY"] [Tue Aug 18 12:57:21.573292 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wk/index.php"] [unique_id "aoSA4fcmepr5_nHgLbNjFAAAAoo"] [Tue Aug 18 12:57:21.601644 2026] [security2:error] [pid 67073:tid 67261] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA4fcmepr5_nHgLbNjFQAAAkw"] [Tue Aug 18 12:57:21.629599 2026] [security2:error] [pid 67073:tid 67314] [client 68.155.154.236:46599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA4fcmepr5_nHgLbNjGAAAAoE"] [Tue Aug 18 12:57:21.630048 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA4dO5rbWdOArH04KSawAAAXI"] [Tue Aug 18 12:57:21.661344 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA4fcmepr5_nHgLbNjGQAAAhk"] [Tue Aug 18 12:57:21.721050 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:16248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA4dO5rbWdOArH04KSbQAAASs"] [Tue Aug 18 12:57:21.730054 2026] [security2:error] [pid 67073:tid 67284] [client 20.119.58.187:11292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA4fcmepr5_nHgLbNjHAAAAmM"] [Tue Aug 18 12:57:21.755094 2026] [autoindex:error] [pid 67073:tid 67253] [client 20.1.169.243:5774] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:21.766533 2026] [security2:error] [pid 66623:tid 66866] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA4dO5rbWdOArH04KSbgAAAW4"] [Tue Aug 18 12:57:21.772955 2026] [security2:error] [pid 66623:tid 66889] [client 104.209.144.33:36543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA4dO5rbWdOArH04KSbwAAAYU"] [Tue Aug 18 12:57:21.874378 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA4dO5rbWdOArH04KScAAAAYI"] [Tue Aug 18 12:57:21.918791 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.56.190:17909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/creds.php"] [unique_id "aoSA4fcmepr5_nHgLbNjIgAAAhQ"] [Tue Aug 18 12:57:21.958212 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.155.199:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/index/function.php"] [unique_id "aoSA4fcmepr5_nHgLbNjKwAAAjI"] [Tue Aug 18 12:57:21.962009 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLAAAAlg"] [Tue Aug 18 12:57:21.986729 2026] [security2:error] [pid 67073:tid 67206] [client 135.225.75.187:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariaalternativa.com.br"] [uri "/ae.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLgAAAhU"] [Tue Aug 18 12:57:22.000593 2026] [security2:error] [pid 67073:tid 67311] [client 213.35.127.232:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA4fcmepr5_nHgLbNjLwAAAn4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:22.029976 2026] [security2:error] [pid 67073:tid 67299] [client 20.118.172.148:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA4vcmepr5_nHgLbNjMQAAAnI"] [Tue Aug 18 12:57:22.072684 2026] [security2:error] [pid 67073:tid 67320] [client 132.196.30.78:18813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/cv.php"] [unique_id "aoSA4vcmepr5_nHgLbNjMgAAAoc"] [Tue Aug 18 12:57:22.079358 2026] [security2:error] [pid 66623:tid 66777] [client 40.74.65.169:27822] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1.php"] [unique_id "aoSA4tO5rbWdOArH04KScQAAARU"] [Tue Aug 18 12:57:22.079480 2026] [security2:error] [pid 66623:tid 66777] [client 40.74.65.169:27822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1.php"] [unique_id "aoSA4tO5rbWdOArH04KScQAAARU"] [Tue Aug 18 12:57:22.081465 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:11300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/cache.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNAAAAn8"] [Tue Aug 18 12:57:22.087159 2026] [security2:error] [pid 67073:tid 67309] [client 68.155.156.252:55664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/bajah.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNQAAAnw"] [Tue Aug 18 12:57:22.095514 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:22.095774 2026] [authz_core:error] [pid 67073:tid 67089] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:22.096081 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:27957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA4vcmepr5_nHgLbNjNwAAAiA"] [Tue Aug 18 12:57:22.127333 2026] [security2:error] [pid 66623:tid 66816] [client 158.158.74.177:22738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-activate.php"] [unique_id "aoSA4tO5rbWdOArH04KScwAAATw"] [Tue Aug 18 12:57:22.142857 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/minishell.php"] [unique_id "aoSA4vcmepr5_nHgLbNjOQAAAjc"] [Tue Aug 18 12:57:22.169855 2026] [security2:error] [pid 67073:tid 67251] [client 172.202.39.151:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPAAAAkI"] [Tue Aug 18 12:57:22.207467 2026] [security2:error] [pid 67073:tid 67327] [client 68.155.154.236:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/mt/byp.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPgAAAo4"] [Tue Aug 18 12:57:22.218341 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.18.37:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/0x.php"] [unique_id "aoSA4vcmepr5_nHgLbNjPwAAAnk"] [Tue Aug 18 12:57:22.218356 2026] [security2:error] [pid 67073:tid 67315] [client 20.215.241.237:28316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSA4vcmepr5_nHgLbNjQAAAAoI"] [Tue Aug 18 12:57:22.271494 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.56.190:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ho.php"] [unique_id "aoSA4vcmepr5_nHgLbNjQwAAAkY"] [Tue Aug 18 12:57:22.335199 2026] [security2:error] [pid 67073:tid 67209] [client 85.154.68.202:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRAAAAhg"] [Tue Aug 18 12:57:22.335328 2026] [security2:error] [pid 67073:tid 67209] [client 85.154.68.202:53779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRAAAAhg"] [Tue Aug 18 12:57:22.373289 2026] [security2:error] [pid 67073:tid 67332] [client 104.209.144.33:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/mt/byp.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRgAAApM"] [Tue Aug 18 12:57:22.375785 2026] [security2:error] [pid 67073:tid 67214] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA4vcmepr5_nHgLbNjRwAAAh0"] [Tue Aug 18 12:57:22.398239 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:22.398499 2026] [authz_core:error] [pid 67073:tid 67201] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:22.434932 2026] [security2:error] [pid 67073:tid 67252] [client 20.119.58.187:11286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/content.php"] [unique_id "aoSA4vcmepr5_nHgLbNjSQAAAkM"] [Tue Aug 18 12:57:22.474715 2026] [security2:error] [pid 67073:tid 67226] [client 20.118.172.148:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/xfun.php"] [unique_id "aoSA4vcmepr5_nHgLbNjSwAAAik"] [Tue Aug 18 12:57:22.512854 2026] [security2:error] [pid 67073:tid 67247] [client 74.248.136.165:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA4vcmepr5_nHgLbNjTAAAAj4"] [Tue Aug 18 12:57:22.530309 2026] [security2:error] [pid 66623:tid 66675] [remote 45.167.52.147:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.52.167.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imoveisbase.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4tO5rbWdOArH04KSdgABJCY"] [Tue Aug 18 12:57:22.530474 2026] [security2:error] [pid 66623:tid 66792] [client 45.167.52.147:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imoveisbase.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4tO5rbWdOArH04KSdgABJCY"] [Tue Aug 18 12:57:22.544794 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA4vcmepr5_nHgLbNjTwAAAo0"] [Tue Aug 18 12:57:22.568957 2026] [security2:error] [pid 67073:tid 67133] [remote 57.141.22.101:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSA4vcmepr5_nHgLbNjUAAChjk"] [Tue Aug 18 12:57:22.578620 2026] [security2:error] [pid 67073:tid 67270] [client 138.36.100.162:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUQAAAlU"] [Tue Aug 18 12:57:22.578716 2026] [security2:error] [pid 67073:tid 67270] [client 138.36.100.162:43238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUQAAAlU"] [Tue Aug 18 12:57:22.591867 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA4vcmepr5_nHgLbNjUgAAAiQ"] [Tue Aug 18 12:57:22.604683 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVgAAAoo"] [Tue Aug 18 12:57:22.609430 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVwAAApI"] [Tue Aug 18 12:57:22.609517 2026] [security2:error] [pid 67073:tid 67331] [client 160.120.140.123:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA4vcmepr5_nHgLbNjVwAAApI"] [Tue Aug 18 12:57:22.655321 2026] [security2:error] [pid 67073:tid 67293] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA4vcmepr5_nHgLbNjWQAAAmw"] [Tue Aug 18 12:57:22.722538 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA4vcmepr5_nHgLbNjXgAAAks"] [Tue Aug 18 12:57:22.748353 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA4tO5rbWdOArH04KSegAAAXc"] [Tue Aug 18 12:57:22.784172 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.154.236:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSA4tO5rbWdOArH04KSfAAAAXA"] [Tue Aug 18 12:57:22.795119 2026] [security2:error] [pid 67073:tid 67285] [client 74.248.18.37:8035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/mm.php"] [unique_id "aoSA4vcmepr5_nHgLbNjYwAAAmQ"] [Tue Aug 18 12:57:22.811219 2026] [security2:error] [pid 67073:tid 67219] [client 40.74.65.169:7413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/about.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZAAAAiI"] [Tue Aug 18 12:57:22.822445 2026] [security2:error] [pid 67073:tid 67284] [client 20.119.58.187:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZgAAAmM"] [Tue Aug 18 12:57:22.832617 2026] [security2:error] [pid 67073:tid 67308] [client 20.206.73.37:11958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA4vcmepr5_nHgLbNjZwAAAns"] [Tue Aug 18 12:57:22.858078 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/222.php"] [unique_id "aoSA4tO5rbWdOArH04KSfwAAAQ4"] [Tue Aug 18 12:57:22.866967 2026] [security2:error] [pid 66623:tid 66803] [client 132.196.30.78:21829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSA4tO5rbWdOArH04KSgAAAAS8"] [Tue Aug 18 12:57:22.877810 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.155.199:3568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wk/index.php"] [unique_id "aoSA4vcmepr5_nHgLbNjaAAAAnM"] [Tue Aug 18 12:57:22.894979 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA4vcmepr5_nHgLbNjawAAAhU"] [Tue Aug 18 12:57:22.962537 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:3009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/97.php"] [unique_id "aoSA4vcmepr5_nHgLbNjbgAAAl8"] [Tue Aug 18 12:57:22.981863 2026] [security2:error] [pid 66623:tid 66869] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA4tO5rbWdOArH04KShAAAAXE"] [Tue Aug 18 12:57:22.998007 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:22.998259 2026] [authz_core:error] [pid 67073:tid 67122] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:22.999407 2026] [security2:error] [pid 67073:tid 67320] [client 20.215.241.237:43393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSA4vcmepr5_nHgLbNjcgAAAoc"] [Tue Aug 18 12:57:23.014499 2026] [security2:error] [pid 67073:tid 67243] [client 213.35.127.232:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA4_cmepr5_nHgLbNjdAAAAjo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:23.024902 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.74.177:2629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjdQAAAko"] [Tue Aug 18 12:57:23.148476 2026] [security2:error] [pid 67073:tid 67216] [client 172.202.39.151:50191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/epinyins.php"] [unique_id "aoSA4_cmepr5_nHgLbNjeQAAAh8"] [Tue Aug 18 12:57:23.176432 2026] [security2:error] [pid 67073:tid 67240] [client 20.119.58.187:11270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/css.php"] [unique_id "aoSA4_cmepr5_nHgLbNjewAAAjc"] [Tue Aug 18 12:57:23.281604 2026] [security2:error] [pid 67073:tid 67211] [client 20.250.13.23:25678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA4_cmepr5_nHgLbNjggAAAho"] [Tue Aug 18 12:57:23.290320 2026] [security2:error] [pid 67073:tid 67276] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA4_cmepr5_nHgLbNjhAAAAls"] [Tue Aug 18 12:57:23.343305 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA49O5rbWdOArH04KSiwAAAU8"] [Tue Aug 18 12:57:23.422887 2026] [security2:error] [pid 67073:tid 67332] [client 20.118.172.148:54894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/p.php"] [unique_id "aoSA4_cmepr5_nHgLbNjiAAAApM"] [Tue Aug 18 12:57:23.429671 2026] [security2:error] [pid 67073:tid 67214] [client 20.65.98.162:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bless6.php"] [unique_id "aoSA4_cmepr5_nHgLbNjiwAAAh0"] [Tue Aug 18 12:57:23.429898 2026] [security2:error] [pid 67073:tid 67322] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA4_cmepr5_nHgLbNjjAAAAok"] [Tue Aug 18 12:57:23.491559 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.18.37:3085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/aa.php"] [unique_id "aoSA49O5rbWdOArH04KSjQAAAXs"] [Tue Aug 18 12:57:23.530892 2026] [security2:error] [pid 67073:tid 67252] [client 20.226.56.190:31010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rh.php"] [unique_id "aoSA4_cmepr5_nHgLbNjlAAAAkM"] [Tue Aug 18 12:57:23.531131 2026] [security2:error] [pid 66623:tid 66802] [client 20.119.58.187:11214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/chosen.php"] [unique_id "aoSA49O5rbWdOArH04KSjwAAAS4"] [Tue Aug 18 12:57:23.561022 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:8053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA4_cmepr5_nHgLbNjmAAAAic"] [Tue Aug 18 12:57:23.599391 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:23.599651 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:23.632264 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA49O5rbWdOArH04KSkQAAAQ0"] [Tue Aug 18 12:57:23.650113 2026] [security2:error] [pid 67073:tid 67326] [client 40.74.65.169:42566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjnAAAAo0"] [Tue Aug 18 12:57:23.660997 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA49O5rbWdOArH04KSlQAAAWA"] [Tue Aug 18 12:57:23.687414 2026] [security2:error] [pid 67073:tid 67328] [client 20.48.236.86:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA4_cmepr5_nHgLbNjnQAAAo8"] [Tue Aug 18 12:57:23.722600 2026] [security2:error] [pid 66623:tid 66776] [client 20.215.241.237:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/media.php"] [unique_id "aoSA49O5rbWdOArH04KSlwAAARQ"] [Tue Aug 18 12:57:23.799787 2026] [security2:error] [pid 67073:tid 67241] [client 68.155.154.236:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA4_cmepr5_nHgLbNjoAAAAjg"] [Tue Aug 18 12:57:23.808354 2026] [security2:error] [pid 67073:tid 67323] [client 68.155.154.236:16251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjogAAAoo"] [Tue Aug 18 12:57:23.815346 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.155.199:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA49O5rbWdOArH04KSmAAAAUI"] [Tue Aug 18 12:57:23.829140 2026] [security2:error] [pid 67073:tid 67319] [client 192.141.172.134:63781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjowAAAoY"] [Tue Aug 18 12:57:23.829292 2026] [security2:error] [pid 67073:tid 67319] [client 192.141.172.134:63781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjowAAAoY"] [Tue Aug 18 12:57:23.874661 2026] [security2:error] [pid 67073:tid 67314] [client 20.118.172.148:52255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA4_cmepr5_nHgLbNjpQAAAoE"] [Tue Aug 18 12:57:23.878334 2026] [security2:error] [pid 67073:tid 67207] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA4_cmepr5_nHgLbNjpgAAAhY"] [Tue Aug 18 12:57:23.900075 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:23.900479 2026] [authz_core:error] [pid 67073:tid 67199] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:23.941678 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.136.165:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ws79.php"] [unique_id "aoSA49O5rbWdOArH04KSmQAAAR0"] [Tue Aug 18 12:57:23.960544 2026] [security2:error] [pid 67073:tid 67261] [client 20.119.58.187:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/doc.php"] [unique_id "aoSA4_cmepr5_nHgLbNjrQAAAkw"] [Tue Aug 18 12:57:23.989991 2026] [security2:error] [pid 67073:tid 67221] [client 79.127.164.8:52274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql.bak"] [unique_id "aoSA4_cmepr5_nHgLbNjrgAAAiQ"], referer: https://medihub.com.br/mysql.bak [Tue Aug 18 12:57:23.990233 2026] [security2:error] [pid 67073:tid 67242] [client 20.100.169.31:16144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA4_cmepr5_nHgLbNjrwAAAjk"] [Tue Aug 18 12:57:24.029190 2026] [security2:error] [pid 67073:tid 67305] [client 213.35.127.232:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjsgAAAng"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:24.041461 2026] [security2:error] [pid 67073:tid 67235] [client 68.155.156.252:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/domvf.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjswAAAjI"] [Tue Aug 18 12:57:24.045001 2026] [security2:error] [pid 67073:tid 67258] [client 172.182.200.96:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zjggu.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjtAAAAkk"] [Tue Aug 18 12:57:24.137078 2026] [security2:error] [pid 67073:tid 67260] [client 132.196.30.78:22518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ws83.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjugAAAks"] [Tue Aug 18 12:57:24.144570 2026] [authz_core:error] [pid 67073:tid 67151] [remote 57.141.22.37:59990] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:24.144991 2026] [authz_core:error] [pid 67073:tid 67151] [remote 57.141.22.37:59990] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:24.186344 2026] [security2:error] [pid 67073:tid 67257] [client 74.248.18.37:27501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/abcd.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjvQAAAkg"] [Tue Aug 18 12:57:24.199706 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:24.199969 2026] [authz_core:error] [pid 67073:tid 67193] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:24.203519 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA5NO5rbWdOArH04KSnAAAASE"] [Tue Aug 18 12:57:24.230945 2026] [security2:error] [pid 67073:tid 67262] [client 74.248.18.37:31844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ms-themes.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjwgAAAk0"] [Tue Aug 18 12:57:24.292287 2026] [security2:error] [pid 67073:tid 67236] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjxAAAAjM"] [Tue Aug 18 12:57:24.314312 2026] [security2:error] [pid 67073:tid 67309] [client 20.119.58.187:11305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/elp.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjxgAAAnw"] [Tue Aug 18 12:57:24.368449 2026] [security2:error] [pid 67073:tid 67267] [client 20.206.73.37:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mgrr.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjyAAAAlI"] [Tue Aug 18 12:57:24.449953 2026] [security2:error] [pid 67073:tid 67282] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzQAAAmE"] [Tue Aug 18 12:57:24.463842 2026] [security2:error] [pid 67073:tid 67255] [client 68.155.155.199:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/xfun.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzgAAAkY"] [Tue Aug 18 12:57:24.466109 2026] [security2:error] [pid 67073:tid 67294] [client 20.215.241.237:28300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/inso.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjzwAAAm0"] [Tue Aug 18 12:57:24.502775 2026] [security2:error] [pid 67073:tid 67215] [client 68.155.154.236:40263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj0wAAAh4"] [Tue Aug 18 12:57:24.503553 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:24.503817 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:24.507568 2026] [security2:error] [pid 67073:tid 67286] [client 40.74.65.169:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/edit.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj1QAAAmU"] [Tue Aug 18 12:57:24.534853 2026] [security2:error] [pid 67073:tid 67248] [client 20.118.172.148:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aaa.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj1wAAAj8"] [Tue Aug 18 12:57:24.549868 2026] [security2:error] [pid 66623:tid 66858] [client 20.226.56.190:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/yg.php"] [unique_id "aoSA5NO5rbWdOArH04KSnwAAAWY"] [Tue Aug 18 12:57:24.571948 2026] [security2:error] [pid 66623:tid 66850] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA5NO5rbWdOArH04KSoAAAAV4"] [Tue Aug 18 12:57:24.588152 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:44790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5NO5rbWdOArH04KSowAAAT0"] [Tue Aug 18 12:57:24.591889 2026] [security2:error] [pid 67073:tid 67213] [client 202.63.210.218:56299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.210.63.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "icemaq.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjygAAAhw"] [Tue Aug 18 12:57:24.591989 2026] [security2:error] [pid 67073:tid 67213] [client 202.63.210.218:56299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "icemaq.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNjygAAAhw"] [Tue Aug 18 12:57:24.594123 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj2gAAAmk"] [Tue Aug 18 12:57:24.614846 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj3AAAAhs"] [Tue Aug 18 12:57:24.637996 2026] [security2:error] [pid 66623:tid 66786] [client 172.202.39.151:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSA5NO5rbWdOArH04KSpAAAAR4"] [Tue Aug 18 12:57:24.665473 2026] [security2:error] [pid 66623:tid 66833] [client 20.119.58.187:11261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/Exception-class.php"] [unique_id "aoSA5NO5rbWdOArH04KSpgAAAU0"] [Tue Aug 18 12:57:24.686315 2026] [security2:error] [pid 66623:tid 66799] [client 68.155.154.236:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA5NO5rbWdOArH04KSqQAAASs"] [Tue Aug 18 12:57:24.714577 2026] [security2:error] [pid 67073:tid 67223] [client 158.158.34.183:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/gebase.php69"] [unique_id "aoSA5Pcmepr5_nHgLbNj3wAAAiY"] [Tue Aug 18 12:57:24.717148 2026] [security2:error] [pid 67073:tid 67304] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj4AAAAnc"] [Tue Aug 18 12:57:24.743317 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj4wAAAlU"] [Tue Aug 18 12:57:24.754883 2026] [security2:error] [pid 67073:tid 67214] [client 132.196.30.78:21913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/atex1.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5AAAAh0"] [Tue Aug 18 12:57:24.763054 2026] [security2:error] [pid 67073:tid 67231] [client 157.51.166.53:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5wAAAi4"] [Tue Aug 18 12:57:24.772566 2026] [security2:error] [pid 67073:tid 67231] [client 157.51.166.53:65039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj5wAAAi4"] [Tue Aug 18 12:57:24.804872 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:24.805209 2026] [authz_core:error] [pid 67073:tid 67132] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:24.817905 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:3124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/admin.php"] [unique_id "aoSA5NO5rbWdOArH04KSqgAAAUc"] [Tue Aug 18 12:57:24.851408 2026] [security2:error] [pid 67073:tid 67293] [client 20.118.133.132:1236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/aa.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj6wAAAmw"] [Tue Aug 18 12:57:24.880146 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/my1.php"] [unique_id "aoSA5NO5rbWdOArH04KSqwAAATM"] [Tue Aug 18 12:57:24.882157 2026] [security2:error] [pid 66623:tid 66781] [client 20.118.172.148:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/term.php"] [unique_id "aoSA5NO5rbWdOArH04KSrAAAARk"] [Tue Aug 18 12:57:24.954471 2026] [security2:error] [pid 66623:tid 66816] [client 40.85.222.29:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA5NO5rbWdOArH04KSrwAAATw"] [Tue Aug 18 12:57:24.967118 2026] [security2:error] [pid 67073:tid 67261] [client 104.209.144.33:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/MTOS/byp.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj9gAAAkw"] [Tue Aug 18 12:57:24.999961 2026] [security2:error] [pid 67073:tid 67227] [client 213.202.253.4:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/schallfuns.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj9wAAAio"], referer: www.google.com [Tue Aug 18 12:57:25.000791 2026] [security2:error] [pid 67073:tid 67326] [client 20.100.169.31:39848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/vx.php"] [unique_id "aoSA5Pcmepr5_nHgLbNj-AAAAo0"] [Tue Aug 18 12:57:25.015373 2026] [security2:error] [pid 66623:tid 66811] [client 5.188.86.234:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maxxbox.ind.br"] [uri "/wp-login.php"] [unique_id "aoSA5dO5rbWdOArH04KSsAAAATc"] [Tue Aug 18 12:57:25.018596 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA5dO5rbWdOArH04KSsQAAAWU"] [Tue Aug 18 12:57:25.034608 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ee.php"] [unique_id "aoSA5dO5rbWdOArH04KSsgAAARU"] [Tue Aug 18 12:57:25.041702 2026] [security2:error] [pid 67073:tid 67239] [client 213.35.127.232:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA5fcmepr5_nHgLbNj_AAAAjY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:25.047024 2026] [security2:error] [pid 66623:tid 66845] [client 68.155.155.199:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/p.php"] [unique_id "aoSA5dO5rbWdOArH04KSswAAAVk"] [Tue Aug 18 12:57:25.156730 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA5fcmepr5_nHgLbNkCwAAAlg"] [Tue Aug 18 12:57:25.168986 2026] [security2:error] [pid 66623:tid 66801] [client 68.155.154.236:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA5dO5rbWdOArH04KStgAAAS0"] [Tue Aug 18 12:57:25.187010 2026] [security2:error] [pid 67073:tid 67206] [client 74.248.136.165:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/rtx.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDAAAAhU"] [Tue Aug 18 12:57:25.187030 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:7636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/.cache/x.php"] [unique_id "aoSA5dO5rbWdOArH04KStwAAAUw"] [Tue Aug 18 12:57:25.187894 2026] [security2:error] [pid 67073:tid 67289] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDQAAAmg"] [Tue Aug 18 12:57:25.189421 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.56.190:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/et.php"] [unique_id "aoSA5dO5rbWdOArH04KSuAAAAXc"] [Tue Aug 18 12:57:25.228560 2026] [security2:error] [pid 67073:tid 67244] [client 40.74.65.169:27744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA5fcmepr5_nHgLbNkDwAAAjs"] [Tue Aug 18 12:57:25.244019 2026] [security2:error] [pid 67073:tid 67260] [client 68.155.154.236:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA5fcmepr5_nHgLbNkEAAAAks"] [Tue Aug 18 12:57:25.254658 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/weozh.php"] [unique_id "aoSA5fcmepr5_nHgLbNkEQAAAnQ"] [Tue Aug 18 12:57:25.395414 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/edit.php"] [unique_id "aoSA5dO5rbWdOArH04KSuwAAARw"] [Tue Aug 18 12:57:25.432745 2026] [security2:error] [pid 67073:tid 67234] [client 20.215.241.237:8012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/shiny.php"] [unique_id "aoSA5fcmepr5_nHgLbNkHAAAAjE"] [Tue Aug 18 12:57:25.449251 2026] [security2:error] [pid 67073:tid 67230] [client 20.100.169.31:37653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/h.php"] [unique_id "aoSA5fcmepr5_nHgLbNkHgAAAi0"] [Tue Aug 18 12:57:25.516733 2026] [security2:error] [pid 66623:tid 66829] [client 20.118.172.148:62082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/7.php"] [unique_id "aoSA5dO5rbWdOArH04KSvwAAAUk"] [Tue Aug 18 12:57:25.524763 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:16538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIQAAAnk"] [Tue Aug 18 12:57:25.530484 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIgAAAos"] [Tue Aug 18 12:57:25.531178 2026] [security2:error] [pid 67073:tid 67211] [client 40.85.222.29:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/rymmm.php"] [unique_id "aoSA5fcmepr5_nHgLbNkIwAAAho"] [Tue Aug 18 12:57:25.541791 2026] [security2:error] [pid 67073:tid 67317] [client 172.202.39.151:44919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/ok.php"] [unique_id "aoSA5fcmepr5_nHgLbNkJAAAAoQ"] [Tue Aug 18 12:57:25.553709 2026] [security2:error] [pid 66623:tid 66767] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA5dO5rbWdOArH04KSwwAAAQs"] [Tue Aug 18 12:57:25.569106 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.154.236:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA5dO5rbWdOArH04KSxAAAAVQ"] [Tue Aug 18 12:57:25.576333 2026] [security2:error] [pid 67073:tid 67320] [client 74.248.18.37:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/new.php"] [unique_id "aoSA5fcmepr5_nHgLbNkJQAAAoc"] [Tue Aug 18 12:57:25.668941 2026] [security2:error] [pid 67073:tid 67256] [client 74.248.18.37:27476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/adminfuns.php"] [unique_id "aoSA5fcmepr5_nHgLbNkKAAAAkc"] [Tue Aug 18 12:57:25.680138 2026] [security2:error] [pid 66623:tid 66830] [client 20.206.73.37:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/55.php"] [unique_id "aoSA5dO5rbWdOArH04KSxgAAAUo"] [Tue Aug 18 12:57:25.693238 2026] [security2:error] [pid 67073:tid 67251] [client 132.196.30.78:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA5fcmepr5_nHgLbNkKgAAAkI"] [Tue Aug 18 12:57:25.706531 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:25.706804 2026] [authz_core:error] [pid 67073:tid 67187] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:25.741527 2026] [security2:error] [pid 66623:tid 66772] [client 196.12.128.158:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA5dO5rbWdOArH04KSyQAAARA"] [Tue Aug 18 12:57:25.741639 2026] [security2:error] [pid 66623:tid 66772] [client 196.12.128.158:53968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA5dO5rbWdOArH04KSyQAAARA"] [Tue Aug 18 12:57:25.748521 2026] [security2:error] [pid 67073:tid 67295] [client 20.119.58.187:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/f35.php"] [unique_id "aoSA5fcmepr5_nHgLbNkLAAAAm4"] [Tue Aug 18 12:57:25.823487 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA5dO5rbWdOArH04KSygAAAQ0"] [Tue Aug 18 12:57:25.851709 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA5dO5rbWdOArH04KSzAAAAVw"] [Tue Aug 18 12:57:25.914890 2026] [security2:error] [pid 67073:tid 67223] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5fcmepr5_nHgLbNkNQACJhI"] [Tue Aug 18 12:57:25.937544 2026] [security2:error] [pid 66623:tid 66852] [client 20.118.172.148:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file5.php"] [unique_id "aoSA5dO5rbWdOArH04KS0AAAAWA"] [Tue Aug 18 12:57:25.958926 2026] [security2:error] [pid 67073:tid 67307] [client 40.74.65.169:27022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inputs.php"] [unique_id "aoSA5fcmepr5_nHgLbNkPAAAAno"] [Tue Aug 18 12:57:26.008371 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:26.008637 2026] [authz_core:error] [pid 67073:tid 67203] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:26.055095 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA5tO5rbWdOArH04KS0gAAAWg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:26.061158 2026] [security2:error] [pid 66623:tid 66805] [client 20.226.56.190:19367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/of.php"] [unique_id "aoSA5tO5rbWdOArH04KS0wAAATE"] [Tue Aug 18 12:57:26.078342 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.155.199:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA5tO5rbWdOArH04KS1AAAAVE"] [Tue Aug 18 12:57:26.081439 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA5tO5rbWdOArH04KS1QAAAVU"] [Tue Aug 18 12:57:26.108270 2026] [security2:error] [pid 66623:tid 66882] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA5tO5rbWdOArH04KS1wAAAX4"] [Tue Aug 18 12:57:26.132863 2026] [security2:error] [pid 66623:tid 66855] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA5tO5rbWdOArH04KS2AAAAWM"] [Tue Aug 18 12:57:26.150918 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/fff.php"] [unique_id "aoSA5tO5rbWdOArH04KS2QAAARc"] [Tue Aug 18 12:57:26.157992 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.154.236:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA5vcmepr5_nHgLbNkQwAAAjw"] [Tue Aug 18 12:57:26.181048 2026] [security2:error] [pid 66623:tid 66844] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/rezor.php"] [unique_id "aoSA5tO5rbWdOArH04KS2gAAAVg"] [Tue Aug 18 12:57:26.185472 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ajax.php"] [unique_id "aoSA5vcmepr5_nHgLbNkRAAAAoY"] [Tue Aug 18 12:57:26.208030 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.92:28164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:26.208319 2026] [authz_core:error] [pid 67073:tid 67179] [remote 57.141.22.92:28164] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:26.241263 2026] [security2:error] [pid 67073:tid 67231] [client 74.248.18.37:8033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/norn.php"] [unique_id "aoSA5vcmepr5_nHgLbNkSQAAAi4"] [Tue Aug 18 12:57:26.258826 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA5vcmepr5_nHgLbNkSwAAAmY"] [Tue Aug 18 12:57:26.298140 2026] [security2:error] [pid 66623:tid 66873] [client 74.248.18.37:3106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/akc.php"] [unique_id "aoSA5tO5rbWdOArH04KS3AAAAXU"] [Tue Aug 18 12:57:26.399917 2026] [security2:error] [pid 66623:tid 66877] [client 158.158.74.177:22727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA5tO5rbWdOArH04KS4AAAAXk"] [Tue Aug 18 12:57:26.413998 2026] [security2:error] [pid 66623:tid 66810] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA5tO5rbWdOArH04KS4QAAATY"] [Tue Aug 18 12:57:26.426545 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:54892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSA5tO5rbWdOArH04KS4wAAARI"] [Tue Aug 18 12:57:26.428035 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5tO5rbWdOArH04KS5AAAASs"] [Tue Aug 18 12:57:26.440294 2026] [security2:error] [pid 67073:tid 67321] [client 158.158.34.183:42593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/akcc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkUQAAAog"] [Tue Aug 18 12:57:26.493314 2026] [security2:error] [pid 66623:tid 66819] [client 20.215.241.237:38231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/403dd.php"] [unique_id "aoSA5tO5rbWdOArH04KS5gAAAT8"] [Tue Aug 18 12:57:26.502112 2026] [security2:error] [pid 66623:tid 66889] [client 172.202.39.151:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "loja1.queroficarnanet.com"] [uri "/item.php"] [unique_id "aoSA5tO5rbWdOArH04KS5wAAAYU"] [Tue Aug 18 12:57:26.507109 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ff1.php"] [unique_id "aoSA5tO5rbWdOArH04KS6AAAAXg"] [Tue Aug 18 12:57:26.553886 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.56.190:31027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bu.php"] [unique_id "aoSA5tO5rbWdOArH04KS6QAAATI"] [Tue Aug 18 12:57:26.570964 2026] [security2:error] [pid 66623:tid 66807] [client 68.155.154.236:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA5tO5rbWdOArH04KS6gAAATM"] [Tue Aug 18 12:57:26.595405 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:7668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA5vcmepr5_nHgLbNkVAAAAng"] [Tue Aug 18 12:57:26.612393 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:26.612661 2026] [authz_core:error] [pid 67073:tid 67197] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:26.622351 2026] [security2:error] [pid 67073:tid 67081] [remote 5.188.86.234:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maxxbox.ind.br"] [uri "/wp-login.php"] [unique_id "aoSA5vcmepr5_nHgLbNkVwACJAU"] [Tue Aug 18 12:57:26.659105 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/av.php"] [unique_id "aoSA5vcmepr5_nHgLbNkWQAAAn4"] [Tue Aug 18 12:57:26.701502 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:11445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/yj09.php"] [unique_id "aoSA5vcmepr5_nHgLbNkWwAAAks"] [Tue Aug 18 12:57:26.708661 2026] [security2:error] [pid 67073:tid 67328] [client 197.184.64.235:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXQAAAo8"] [Tue Aug 18 12:57:26.708747 2026] [security2:error] [pid 67073:tid 67328] [client 197.184.64.235:41936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXQAAAo8"] [Tue Aug 18 12:57:26.721500 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/lddxs.php"] [unique_id "aoSA5vcmepr5_nHgLbNkXgAAAkg"] [Tue Aug 18 12:57:26.742265 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSA5vcmepr5_nHgLbNkYAAAAiA"] [Tue Aug 18 12:57:26.782002 2026] [security2:error] [pid 67073:tid 67309] [client 20.118.172.148:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA5vcmepr5_nHgLbNkYwAAAnw"] [Tue Aug 18 12:57:26.811208 2026] [security2:error] [pid 67073:tid 67234] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA5vcmepr5_nHgLbNkaAAAAjE"] [Tue Aug 18 12:57:26.820974 2026] [security2:error] [pid 67073:tid 67310] [client 132.196.30.78:21866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/w.php"] [unique_id "aoSA5vcmepr5_nHgLbNkaQAAAn0"] [Tue Aug 18 12:57:26.863038 2026] [security2:error] [pid 67073:tid 67259] [client 20.119.58.187:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/flower.php"] [unique_id "aoSA5vcmepr5_nHgLbNkagAAAko"] [Tue Aug 18 12:57:26.878126 2026] [security2:error] [pid 67073:tid 67228] [client 74.248.18.37:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/num.php"] [unique_id "aoSA5vcmepr5_nHgLbNkbAAAAis"] [Tue Aug 18 12:57:26.878638 2026] [security2:error] [pid 67073:tid 67250] [client 20.226.56.190:52092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rn.php"] [unique_id "aoSA5vcmepr5_nHgLbNkbQAAAkE"] [Tue Aug 18 12:57:26.967542 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.136.165:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/end.php"] [unique_id "aoSA5vcmepr5_nHgLbNkcwAAAh4"] [Tue Aug 18 12:57:26.974706 2026] [security2:error] [pid 67073:tid 67327] [client 114.119.142.14:56999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mudancassilvano.com.br"] [uri "/orcamento-m%C2%B3"] [unique_id "aoSA5vcmepr5_nHgLbNkdAAAAo4"], referer: https://mudancassilvano.com.br/orcamento-m%C2%B3?gclid=EAIaIQobChMI75mKzIb66gIVQweRCh28GwN-EAAYASACEgK8NfD_BwE&cf_pg=6 [Tue Aug 18 12:57:26.976027 2026] [security2:error] [pid 67073:tid 67264] [client 20.250.13.23:47032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wso.php"] [unique_id "aoSA5vcmepr5_nHgLbNkdQAAAk8"] [Tue Aug 18 12:57:27.001514 2026] [security2:error] [pid 67073:tid 67332] [client 40.85.222.29:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zjggu.php"] [unique_id "aoSA5_cmepr5_nHgLbNkdgAAApM"] [Tue Aug 18 12:57:27.027833 2026] [security2:error] [pid 67073:tid 67216] [client 68.155.154.236:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA5_cmepr5_nHgLbNkdwAAAh8"] [Tue Aug 18 12:57:27.056311 2026] [security2:error] [pid 66623:tid 66875] [client 20.100.169.31:16437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wap.php"] [unique_id "aoSA59O5rbWdOArH04KS8wAAAXc"] [Tue Aug 18 12:57:27.057354 2026] [security2:error] [pid 67073:tid 67296] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/Cachex.php"] [unique_id "aoSA5_cmepr5_nHgLbNkeQAAAm8"] [Tue Aug 18 12:57:27.069132 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:27.069416 2026] [authz_core:error] [pid 67073:tid 67143] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:27.072615 2026] [security2:error] [pid 67073:tid 67288] [client 213.35.127.232:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA5_cmepr5_nHgLbNkewAAAmc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:27.101650 2026] [security2:error] [pid 67073:tid 67306] [client 74.248.18.37:27494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/buy.php"] [unique_id "aoSA5_cmepr5_nHgLbNkfAAAAnk"] [Tue Aug 18 12:57:27.117815 2026] [security2:error] [pid 66623:tid 66771] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA59O5rbWdOArH04KS9AAAAQ8"] [Tue Aug 18 12:57:27.122625 2026] [security2:error] [pid 66623:tid 66868] [client 40.74.65.169:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA59O5rbWdOArH04KS9gAAAXA"] [Tue Aug 18 12:57:27.144196 2026] [security2:error] [pid 67073:tid 67263] [client 20.118.172.148:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSA5_cmepr5_nHgLbNkgAAAAk4"] [Tue Aug 18 12:57:27.231355 2026] [security2:error] [pid 67073:tid 67308] [client 168.119.123.75:22692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.petceu.com.br"] [uri "/index.php"] [unique_id "aoSA5vcmepr5_nHgLbNkZAAAAns"], referer: https://www.petceu.com.br [Tue Aug 18 12:57:27.247364 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:11271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/file.php"] [unique_id "aoSA59O5rbWdOArH04KS-AAAARw"] [Tue Aug 18 12:57:27.254552 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA59O5rbWdOArH04KS-QAAAV8"] [Tue Aug 18 12:57:27.354965 2026] [security2:error] [pid 67073:tid 67247] [client 40.85.222.29:44231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA5_cmepr5_nHgLbNkhgAAAj4"] [Tue Aug 18 12:57:27.378596 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkhwAAAmI"] [Tue Aug 18 12:57:27.409946 2026] [security2:error] [pid 67073:tid 67172] [remote 203.99.146.53:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiAACL2A"] [Tue Aug 18 12:57:27.410348 2026] [security2:error] [pid 67073:tid 67231] [client 40.74.65.169:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/classwithtostring.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiQAAAi4"] [Tue Aug 18 12:57:27.439692 2026] [security2:error] [pid 67073:tid 67238] [client 68.155.154.236:7627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA5_cmepr5_nHgLbNkiwAAAjU"] [Tue Aug 18 12:57:27.444875 2026] [security2:error] [pid 67073:tid 67224] [client 132.196.30.78:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/archive.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjAAAAic"] [Tue Aug 18 12:57:27.455030 2026] [security2:error] [pid 67073:tid 67318] [client 104.209.144.33:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjQAAAoU"] [Tue Aug 18 12:57:27.473154 2026] [security2:error] [pid 67073:tid 67240] [client 20.118.172.148:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/atomlib.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjgAAAjc"] [Tue Aug 18 12:57:27.483573 2026] [security2:error] [pid 67073:tid 67148] [remote 129.121.103.155:49258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSA5_cmepr5_nHgLbNkjwACV0g"] [Tue Aug 18 12:57:27.485284 2026] [security2:error] [pid 67073:tid 67253] [client 20.48.236.86:48725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA5_cmepr5_nHgLbNkkAAAAkQ"] [Tue Aug 18 12:57:27.515040 2026] [authz_core:error] [pid 67073:tid 67112] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:27.515309 2026] [authz_core:error] [pid 67073:tid 67112] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:27.526116 2026] [security2:error] [pid 67073:tid 67214] [client 74.248.18.37:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/options-reading.php"] [unique_id "aoSA5_cmepr5_nHgLbNkkwAAAh0"] [Tue Aug 18 12:57:27.527204 2026] [security2:error] [pid 67073:tid 67208] [client 79.127.164.8:47078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysql.sql"] [unique_id "aoSA5_cmepr5_nHgLbNklAAAAhc"], referer: https://medihub.com.br/mysql.sql [Tue Aug 18 12:57:27.571872 2026] [security2:error] [pid 66623:tid 66766] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA59O5rbWdOArH04KS_gAAAQo"] [Tue Aug 18 12:57:27.596589 2026] [security2:error] [pid 67073:tid 67254] [client 20.206.73.37:59890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/scxy.php"] [unique_id "aoSA5_cmepr5_nHgLbNklQAAAkU"] [Tue Aug 18 12:57:27.599392 2026] [security2:error] [pid 67073:tid 67261] [client 20.119.58.187:11294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/goods.php"] [unique_id "aoSA5_cmepr5_nHgLbNklwAAAkw"] [Tue Aug 18 12:57:27.604984 2026] [security2:error] [pid 67073:tid 67222] [client 192.141.172.134:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmAAAAiU"] [Tue Aug 18 12:57:27.605057 2026] [security2:error] [pid 67073:tid 67222] [client 192.141.172.134:64039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmAAAAiU"] [Tue Aug 18 12:57:27.609004 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmQAAAoE"] [Tue Aug 18 12:57:27.621883 2026] [security2:error] [pid 67073:tid 67311] [client 172.202.39.151:50231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkmgAAAn4"] [Tue Aug 18 12:57:27.638252 2026] [security2:error] [pid 67073:tid 67297] [client 20.215.241.237:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/baba.php"] [unique_id "aoSA5_cmepr5_nHgLbNknAAAAnA"] [Tue Aug 18 12:57:27.677738 2026] [security2:error] [pid 67073:tid 67323] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNknQAAAoo"] [Tue Aug 18 12:57:27.722024 2026] [security2:error] [pid 67073:tid 67270] [client 86.120.159.145:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkoAAAAlU"] [Tue Aug 18 12:57:27.722155 2026] [security2:error] [pid 67073:tid 67270] [client 86.120.159.145:7881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA5_cmepr5_nHgLbNkoAAAAlU"] [Tue Aug 18 12:57:27.735918 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:27486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/cong.php"] [unique_id "aoSA5_cmepr5_nHgLbNkogAAAiI"] [Tue Aug 18 12:57:27.759361 2026] [security2:error] [pid 66623:tid 66798] [client 68.155.154.236:16319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA59O5rbWdOArH04KS_wAAASo"] [Tue Aug 18 12:57:27.798746 2026] [security2:error] [pid 67073:tid 67234] [client 40.74.65.169:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/media.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpAAAAjE"] [Tue Aug 18 12:57:27.815411 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:27.815666 2026] [authz_core:error] [pid 67073:tid 67100] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:27.817162 2026] [security2:error] [pid 67073:tid 67307] [client 158.158.74.177:2662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpgAAAno"] [Tue Aug 18 12:57:27.821406 2026] [security2:error] [pid 67073:tid 67269] [client 40.85.222.29:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA5_cmepr5_nHgLbNkpwAAAlQ"] [Tue Aug 18 12:57:27.834299 2026] [security2:error] [pid 67073:tid 67310] [client 20.118.172.148:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/min.php"] [unique_id "aoSA5_cmepr5_nHgLbNkqAAAAn0"] [Tue Aug 18 12:57:27.871601 2026] [security2:error] [pid 67073:tid 67250] [client 68.155.154.236:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA5_cmepr5_nHgLbNkqgAAAkE"] [Tue Aug 18 12:57:27.937291 2026] [security2:error] [pid 67073:tid 67262] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrQAAAk0"] [Tue Aug 18 12:57:27.953077 2026] [security2:error] [pid 67073:tid 67274] [client 20.119.58.187:11315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/g.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrgAAAlk"] [Tue Aug 18 12:57:27.958753 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA5_cmepr5_nHgLbNkrwAAAoA"] [Tue Aug 18 12:57:28.017509 2026] [security2:error] [pid 67073:tid 67210] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNktAAAAhk"] [Tue Aug 18 12:57:28.033244 2026] [security2:error] [pid 67073:tid 67235] [client 20.250.13.23:47034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/zup.php73"] [unique_id "aoSA6Pcmepr5_nHgLbNktQAAAjI"] [Tue Aug 18 12:57:28.086087 2026] [security2:error] [pid 66623:tid 66887] [client 213.35.127.232:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA6NO5rbWdOArH04KTAQAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:28.103912 2026] [security2:error] [pid 67073:tid 67296] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkuAAAAm8"] [Tue Aug 18 12:57:28.119340 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:28.119615 2026] [authz_core:error] [pid 67073:tid 67164] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:28.120219 2026] [security2:error] [pid 67073:tid 67213] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/admin.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkugAAAhw"] [Tue Aug 18 12:57:28.134210 2026] [security2:error] [pid 67073:tid 67295] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/biufile.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkuwAAAm4"] [Tue Aug 18 12:57:28.137498 2026] [security2:error] [pid 67073:tid 67244] [client 40.74.65.169:28189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkvAAAAjs"] [Tue Aug 18 12:57:28.156667 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkvwAAAmo"] [Tue Aug 18 12:57:28.168903 2026] [security2:error] [pid 67073:tid 67304] [client 172.182.200.96:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwAAAAnc"] [Tue Aug 18 12:57:28.177026 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/mac.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwQAAAlo"] [Tue Aug 18 12:57:28.179576 2026] [security2:error] [pid 67073:tid 67308] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwgAAAns"] [Tue Aug 18 12:57:28.187788 2026] [security2:error] [pid 67073:tid 67259] [client 68.155.155.199:5982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aaa.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkwwAAAko"] [Tue Aug 18 12:57:28.221094 2026] [security2:error] [pid 67073:tid 67283] [client 68.155.154.236:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/first.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkxgAAAmI"] [Tue Aug 18 12:57:28.231517 2026] [security2:error] [pid 66623:tid 66847] [client 40.85.222.29:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/kopyw.php"] [unique_id "aoSA6NO5rbWdOArH04KTAwAAAVs"] [Tue Aug 18 12:57:28.244455 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkxwAAAjQ"] [Tue Aug 18 12:57:28.257689 2026] [security2:error] [pid 67073:tid 67232] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/coffexium.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkyAAAAi8"] [Tue Aug 18 12:57:28.258684 2026] [security2:error] [pid 67073:tid 67332] [client 74.248.18.37:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ors32envu.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkyQAAApM"] [Tue Aug 18 12:57:28.277217 2026] [security2:error] [pid 67073:tid 67277] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/dex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkygAAAlw"] [Tue Aug 18 12:57:28.290963 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkywAAAic"] [Tue Aug 18 12:57:28.291085 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkywAAAic"] [Tue Aug 18 12:57:28.307233 2026] [security2:error] [pid 67073:tid 67253] [client 20.119.58.187:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkzQAAAkQ"] [Tue Aug 18 12:57:28.307421 2026] [security2:error] [pid 67073:tid 67220] [client 20.119.58.187:11314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA6Pcmepr5_nHgLbNkzgAAAiM"] [Tue Aug 18 12:57:28.326287 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/coffee.php"] [unique_id "aoSA6NO5rbWdOArH04KTBQAAAWc"] [Tue Aug 18 12:57:28.339693 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA6NO5rbWdOArH04KTBgAAARg"] [Tue Aug 18 12:57:28.353568 2026] [security2:error] [pid 67073:tid 67214] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0QAAAh0"] [Tue Aug 18 12:57:28.368920 2026] [security2:error] [pid 67073:tid 67255] [client 74.248.18.37:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0wAAAkY"] [Tue Aug 18 12:57:28.373648 2026] [security2:error] [pid 67073:tid 67218] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/mgrr.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk1AAAAiE"] [Tue Aug 18 12:57:28.386523 2026] [security2:error] [pid 67073:tid 67305] [client 68.155.154.236:7890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk1QAAAng"] [Tue Aug 18 12:57:28.463643 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCAAAATs"] [Tue Aug 18 12:57:28.472431 2026] [security2:error] [pid 67073:tid 67289] [client 40.74.65.169:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/admin.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2AAAAmg"] [Tue Aug 18 12:57:28.513916 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/nc4.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2QAAAoo"] [Tue Aug 18 12:57:28.518818 2026] [security2:error] [pid 67073:tid 67246] [client 103.184.169.37:42151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2gAAAj0"] [Tue Aug 18 12:57:28.518909 2026] [security2:error] [pid 67073:tid 67246] [client 103.184.169.37:42151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2gAAAj0"] [Tue Aug 18 12:57:28.529413 2026] [security2:error] [pid 67073:tid 67312] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk2wAAAn8"] [Tue Aug 18 12:57:28.533462 2026] [security2:error] [pid 67073:tid 67270] [client 40.85.222.29:44249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zznmg.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3QAAAlU"] [Tue Aug 18 12:57:28.579609 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.200.96:7665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3gAAAl4"] [Tue Aug 18 12:57:28.660584 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk3wAAAnI"] [Tue Aug 18 12:57:28.660802 2026] [security2:error] [pid 66623:tid 66800] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSA6NO5rbWdOArH04KTCgAAASw"] [Tue Aug 18 12:57:28.664133 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCwAAAUI"] [Tue Aug 18 12:57:28.668242 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.200.96:14105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/kopyw.php"] [unique_id "aoSA6NO5rbWdOArH04KTDAAAARE"] [Tue Aug 18 12:57:28.672197 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/55.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk4AAAAks"] [Tue Aug 18 12:57:28.684128 2026] [security2:error] [pid 67073:tid 67321] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ajax.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk4gAAAog"] [Tue Aug 18 12:57:28.704953 2026] [security2:error] [pid 67073:tid 67097] [remote 47.128.31.157:14370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSA6Pcmepr5_nHgLbNk4wACNhU"] [Tue Aug 18 12:57:28.709920 2026] [security2:error] [pid 67073:tid 67233] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/yj09.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk5AAAAjA"] [Tue Aug 18 12:57:28.722171 2026] [security2:error] [pid 67073:tid 67313] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/scxy.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk5gAAAoA"] [Tue Aug 18 12:57:28.724842 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:28.725090 2026] [authz_core:error] [pid 67073:tid 67107] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:28.752555 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ws13.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6AAAAjI"] [Tue Aug 18 12:57:28.758532 2026] [autoindex:error] [pid 67073:tid 67209] [client 205.210.31.192:0] AH01276: Cannot serve directory /home2/le7f15nb/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:28.765192 2026] [security2:error] [pid 67073:tid 67271] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/btx25.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6gAAAlY"] [Tue Aug 18 12:57:28.774942 2026] [security2:error] [pid 67073:tid 67213] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk6wAAAhw"] [Tue Aug 18 12:57:28.781662 2026] [security2:error] [pid 67073:tid 67263] [client 103.120.71.157:12648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7AAAAk4"] [Tue Aug 18 12:57:28.781766 2026] [security2:error] [pid 67073:tid 67263] [client 103.120.71.157:12648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7AAAAk4"] [Tue Aug 18 12:57:28.791391 2026] [security2:error] [pid 67073:tid 67244] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk7wAAAjs"] [Tue Aug 18 12:57:28.804496 2026] [security2:error] [pid 66623:tid 66883] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA6NO5rbWdOArH04KTDQAAAX8"] [Tue Aug 18 12:57:28.817955 2026] [security2:error] [pid 67073:tid 67304] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk9gAAAnc"] [Tue Aug 18 12:57:28.831087 2026] [security2:error] [pid 67073:tid 67308] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/sky.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk9wAAAns"] [Tue Aug 18 12:57:28.841908 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-blog.php"] [unique_id "aoSA6NO5rbWdOArH04KTDgAAAWY"] [Tue Aug 18 12:57:28.843303 2026] [security2:error] [pid 66623:tid 66813] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file5.php"] [unique_id "aoSA6NO5rbWdOArH04KTDwAAATk"] [Tue Aug 18 12:57:28.857248 2026] [security2:error] [pid 66623:tid 66817] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/xyn.php"] [unique_id "aoSA6NO5rbWdOArH04KTEAAAAT0"] [Tue Aug 18 12:57:28.862336 2026] [security2:error] [pid 66623:tid 66810] [client 20.118.172.148:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/as.php"] [unique_id "aoSA6NO5rbWdOArH04KTEQAAATY"] [Tue Aug 18 12:57:28.870475 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/inso.php"] [unique_id "aoSA6NO5rbWdOArH04KTEgAAAXI"] [Tue Aug 18 12:57:28.879606 2026] [security2:error] [pid 67073:tid 67217] [client 20.100.169.31:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk-wAAAiA"] [Tue Aug 18 12:57:28.898183 2026] [security2:error] [pid 67073:tid 67245] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/puc.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_AAAAjw"] [Tue Aug 18 12:57:28.906162 2026] [security2:error] [pid 67073:tid 67276] [client 74.248.18.37:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_QAAAls"] [Tue Aug 18 12:57:28.925165 2026] [security2:error] [pid 66623:tid 66799] [client 40.85.222.29:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA6NO5rbWdOArH04KTEwAAASs"] [Tue Aug 18 12:57:28.926894 2026] [security2:error] [pid 67073:tid 67287] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/19.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk_gAAAmY"] [Tue Aug 18 12:57:28.943947 2026] [security2:error] [pid 66623:tid 66848] [client 49.13.167.123:61146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.capecodcleaningservice.com"] [uri "/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTBAAAAVw"], referer: https://www.capecodcleaningservice.com [Tue Aug 18 12:57:28.953189 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/133.php"] [unique_id "aoSA6NO5rbWdOArH04KTFAAAAT8"] [Tue Aug 18 12:57:28.959439 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSA6NO5rbWdOArH04KTFQAAAXg"] [Tue Aug 18 12:57:28.969225 2026] [security2:error] [pid 66623:tid 66807] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/1xmomo.php"] [unique_id "aoSA6NO5rbWdOArH04KTFwAAATM"] [Tue Aug 18 12:57:28.983686 2026] [security2:error] [pid 66623:tid 66853] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/mosty.php"] [unique_id "aoSA6NO5rbWdOArH04KTGAAAAWE"] [Tue Aug 18 12:57:28.997224 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/blurbs.php"] [unique_id "aoSA6NO5rbWdOArH04KTGQAAARQ"] [Tue Aug 18 12:57:29.003244 2026] [security2:error] [pid 67073:tid 67205] [client 74.248.18.37:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/db.php"] [unique_id "aoSA6fcmepr5_nHgLbNk_wAAAhQ"] [Tue Aug 18 12:57:29.014632 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAAAAAjg"] [Tue Aug 18 12:57:29.014751 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAAAAAjg"] [Tue Aug 18 12:57:29.016096 2026] [security2:error] [pid 67073:tid 67283] [client 20.119.58.187:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/in.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAQAAAmI"] [Tue Aug 18 12:57:29.017326 2026] [security2:error] [pid 67073:tid 67237] [client 20.119.58.187:12065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/user-new.php"] [unique_id "aoSA6fcmepr5_nHgLbNlAgAAAjQ"] [Tue Aug 18 12:57:29.032050 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:29.032504 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:29.054001 2026] [security2:error] [pid 67073:tid 67238] [client 20.203.183.135:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA6fcmepr5_nHgLbNlBQAAAjU"] [Tue Aug 18 12:57:29.068654 2026] [security2:error] [pid 66623:tid 66886] [client 68.155.154.236:16192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTGgAAAYI"] [Tue Aug 18 12:57:29.079762 2026] [security2:error] [pid 66623:tid 66862] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTGwAAAWo"] [Tue Aug 18 12:57:29.089149 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:7637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zznmg.php"] [unique_id "aoSA6dO5rbWdOArH04KTHAAAAUc"] [Tue Aug 18 12:57:29.099197 2026] [security2:error] [pid 67073:tid 67216] [client 213.35.127.232:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA6fcmepr5_nHgLbNlCgAAAh8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:29.106514 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ut.php"] [unique_id "aoSA6fcmepr5_nHgLbNlCwAAAiM"] [Tue Aug 18 12:57:29.109913 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTHQAAAYQ"] [Tue Aug 18 12:57:29.117718 2026] [security2:error] [pid 66623:tid 66845] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bajah.php"] [unique_id "aoSA6dO5rbWdOArH04KTHwAAAVk"] [Tue Aug 18 12:57:29.132124 2026] [security2:error] [pid 67073:tid 67227] [client 104.209.144.33:19616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDQAAAio"] [Tue Aug 18 12:57:29.132956 2026] [security2:error] [pid 67073:tid 67214] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/h.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDgAAAh0"] [Tue Aug 18 12:57:29.148568 2026] [security2:error] [pid 67073:tid 67248] [client 40.74.65.169:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/mac.php"] [unique_id "aoSA6fcmepr5_nHgLbNlDwAAAj8"] [Tue Aug 18 12:57:29.160323 2026] [security2:error] [pid 67073:tid 67315] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ano.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEAAAAoI"] [Tue Aug 18 12:57:29.175501 2026] [security2:error] [pid 67073:tid 67225] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ai.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEQAAAig"] [Tue Aug 18 12:57:29.200189 2026] [security2:error] [pid 67073:tid 67258] [client 68.155.154.236:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEgAAAkk"] [Tue Aug 18 12:57:29.207104 2026] [security2:error] [pid 67073:tid 67221] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/sf.php"] [unique_id "aoSA6fcmepr5_nHgLbNlEwAAAiQ"] [Tue Aug 18 12:57:29.222514 2026] [security2:error] [pid 67073:tid 67297] [client 20.118.172.148:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/k.php"] [unique_id "aoSA6fcmepr5_nHgLbNlFQAAAnA"] [Tue Aug 18 12:57:29.237990 2026] [security2:error] [pid 67073:tid 67301] [client 40.85.222.29:44792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA6fcmepr5_nHgLbNlFwAAAnQ"] [Tue Aug 18 12:57:29.238635 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/xx.php"] [unique_id "aoSA6dO5rbWdOArH04KTJAAAAQ8"] [Tue Aug 18 12:57:29.251940 2026] [security2:error] [pid 66623:tid 66795] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/uwu.php"] [unique_id "aoSA6dO5rbWdOArH04KTJQAAASc"] [Tue Aug 18 12:57:29.265841 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/signon.php"] [unique_id "aoSA6fcmepr5_nHgLbNlGQAAAoY"] [Tue Aug 18 12:57:29.279964 2026] [security2:error] [pid 67073:tid 67278] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file61.php"] [unique_id "aoSA6fcmepr5_nHgLbNlGwAAAl0"] [Tue Aug 18 12:57:29.293678 2026] [security2:error] [pid 67073:tid 67279] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/copypaths.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHAAAAl4"] [Tue Aug 18 12:57:29.321116 2026] [security2:error] [pid 67073:tid 67236] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bless6.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHQAAAjM"] [Tue Aug 18 12:57:29.321751 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSA6dO5rbWdOArH04KTJgAAAVI"] [Tue Aug 18 12:57:29.334244 2026] [security2:error] [pid 67073:tid 67226] [client 168.119.96.239:51582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rhsolucionar.com.br"] [uri "/index.php"] [unique_id "aoSA6Pcmepr5_nHgLbNk0AAAAik"], referer: https://www.rhsolucionar.com.br/ [Tue Aug 18 12:57:29.336238 2026] [security2:error] [pid 67073:tid 67260] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/special.php"] [unique_id "aoSA6fcmepr5_nHgLbNlHwAAAks"] [Tue Aug 18 12:57:29.351171 2026] [security2:error] [pid 67073:tid 67321] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/fz.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIQAAAog"] [Tue Aug 18 12:57:29.365220 2026] [security2:error] [pid 66623:tid 66864] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/clque.php"] [unique_id "aoSA6dO5rbWdOArH04KTKAAAAWw"] [Tue Aug 18 12:57:29.367311 2026] [security2:error] [pid 67073:tid 67233] [client 68.155.155.199:22800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/term.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIgAAAjA"] [Tue Aug 18 12:57:29.369123 2026] [security2:error] [pid 67073:tid 67246] [client 20.119.58.187:11313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/info.php"] [unique_id "aoSA6fcmepr5_nHgLbNlIwAAAj0"] [Tue Aug 18 12:57:29.372240 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.156.252:19809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/fpwch.php"] [unique_id "aoSA6dO5rbWdOArH04KTKQAAAV8"] [Tue Aug 18 12:57:29.378524 2026] [security2:error] [pid 67073:tid 67235] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/nano.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJAAAAjI"] [Tue Aug 18 12:57:29.391803 2026] [security2:error] [pid 67073:tid 67296] [client 20.206.73.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/.mopj.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJQAAAm8"] [Tue Aug 18 12:57:29.401981 2026] [security2:error] [pid 67073:tid 67213] [client 20.48.236.86:48708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/img.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJgAAAhw"] [Tue Aug 18 12:57:29.405261 2026] [security2:error] [pid 67073:tid 67251] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/bengi.php"] [unique_id "aoSA6fcmepr5_nHgLbNlJwAAAkI"] [Tue Aug 18 12:57:29.410371 2026] [security2:error] [pid 67073:tid 67212] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlKAAAAhs"] [Tue Aug 18 12:57:29.418903 2026] [security2:error] [pid 67073:tid 67281] [client 20.119.58.187:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/sodium_compat/src/about.php"] [unique_id "aoSA6fcmepr5_nHgLbNlKgAAAmA"] [Tue Aug 18 12:57:29.470796 2026] [security2:error] [pid 67073:tid 67329] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLQAAApA"] [Tue Aug 18 12:57:29.497555 2026] [security2:error] [pid 67073:tid 67295] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLgAAAm4"] [Tue Aug 18 12:57:29.500454 2026] [security2:error] [pid 67073:tid 67274] [client 20.65.98.162:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/special.php"] [unique_id "aoSA6fcmepr5_nHgLbNlLwAAAlk"] [Tue Aug 18 12:57:29.513984 2026] [security2:error] [pid 67073:tid 67207] [client 20.250.13.23:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/k.php"] [unique_id "aoSA6fcmepr5_nHgLbNlMAAAAhY"] [Tue Aug 18 12:57:29.536963 2026] [security2:error] [pid 67073:tid 67272] [client 172.182.200.96:14180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA6fcmepr5_nHgLbNlMQAAAlc"] [Tue Aug 18 12:57:29.565982 2026] [security2:error] [pid 66623:tid 66826] [client 20.118.172.148:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSA6dO5rbWdOArH04KTKgAAAUY"] [Tue Aug 18 12:57:29.588562 2026] [security2:error] [pid 66623:tid 66793] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSA6dO5rbWdOArH04KTKwAAASU"] [Tue Aug 18 12:57:29.603441 2026] [security2:error] [pid 66623:tid 66846] [client 20.215.241.237:48249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/site.php"] [unique_id "aoSA6dO5rbWdOArH04KTLAAAAVo"] [Tue Aug 18 12:57:29.607150 2026] [security2:error] [pid 67073:tid 67269] [client 74.248.18.37:20522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ova.php"] [unique_id "aoSA6fcmepr5_nHgLbNlNAAAAlQ"] [Tue Aug 18 12:57:29.616671 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.136.165:22489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.136.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sortisinformatica.com.br"] [uri "/ae.php"] [unique_id "aoSA6dO5rbWdOArH04KTLQAAAUA"] [Tue Aug 18 12:57:29.623271 2026] [security2:error] [pid 67073:tid 67249] [client 40.85.222.29:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/oivcl.php"] [unique_id "aoSA6fcmepr5_nHgLbNlNwAAAkA"] [Tue Aug 18 12:57:29.627094 2026] [security2:error] [pid 66623:tid 66841] [client 74.7.244.13:45790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesales.com.br"] [uri "/index.php"] [unique_id "aoSA6NO5rbWdOArH04KTCQABVXA"] [Tue Aug 18 12:57:29.634138 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.18.37:27489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/dropdown.php"] [unique_id "aoSA6fcmepr5_nHgLbNlOQAAAk4"] [Tue Aug 18 12:57:29.675244 2026] [security2:error] [pid 67073:tid 67231] [client 20.118.133.132:1260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/av.php"] [unique_id "aoSA6fcmepr5_nHgLbNlQwAAAi4"] [Tue Aug 18 12:57:29.712150 2026] [security2:error] [pid 67073:tid 67224] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/file2.php"] [unique_id "aoSA6fcmepr5_nHgLbNlSwAAAic"] [Tue Aug 18 12:57:29.721157 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/inputs.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTAAAAi8"] [Tue Aug 18 12:57:29.731918 2026] [security2:error] [pid 67073:tid 67220] [client 20.226.56.190:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/eh.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTgAAAiM"] [Tue Aug 18 12:57:29.741518 2026] [security2:error] [pid 67073:tid 67285] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/gm.php"] [unique_id "aoSA6fcmepr5_nHgLbNlTwAAAmQ"] [Tue Aug 18 12:57:29.760931 2026] [security2:error] [pid 67073:tid 67208] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/ws55.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUAAAAhc"] [Tue Aug 18 12:57:29.763740 2026] [security2:error] [pid 67073:tid 67214] [client 68.155.154.236:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUQAAAh0"] [Tue Aug 18 12:57:29.775770 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:12053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSA6dO5rbWdOArH04KTLwAAAVA"] [Tue Aug 18 12:57:29.782973 2026] [security2:error] [pid 67073:tid 67290] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUgAAAmk"] [Tue Aug 18 12:57:29.789783 2026] [security2:error] [pid 67073:tid 67248] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/m.php"] [unique_id "aoSA6fcmepr5_nHgLbNlUwAAAj8"] [Tue Aug 18 12:57:29.802396 2026] [security2:error] [pid 67073:tid 67280] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/33.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVAAAAl8"] [Tue Aug 18 12:57:29.813211 2026] [security2:error] [pid 67073:tid 67254] [client 20.206.73.37:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ws13.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVgAAAkU"] [Tue Aug 18 12:57:29.818193 2026] [security2:error] [pid 67073:tid 67261] [client 68.155.154.236:16308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlVwAAAkw"] [Tue Aug 18 12:57:29.827570 2026] [security2:error] [pid 67073:tid 67314] [client 20.206.73.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.sergiocamillo.com.br"] [uri "/packed.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWAAAAoE"] [Tue Aug 18 12:57:29.830297 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:4556] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/1.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWQAAAn4"] [Tue Aug 18 12:57:29.830365 2026] [security2:error] [pid 67073:tid 67311] [client 40.74.65.169:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/1.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWQAAAn4"] [Tue Aug 18 12:57:29.859176 2026] [security2:error] [pid 67073:tid 67312] [client 172.182.200.96:14195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/index.php"] [unique_id "aoSA6fcmepr5_nHgLbNlWgAAAn8"] [Tue Aug 18 12:57:29.892933 2026] [security2:error] [pid 66623:tid 66785] [client 20.100.169.31:34744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/ms-edit.php"] [unique_id "aoSA6dO5rbWdOArH04KTMAAAAR0"] [Tue Aug 18 12:57:29.897737 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSA6fcmepr5_nHgLbNlXgAAAkg"] [Tue Aug 18 12:57:29.914515 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.169.31:16422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bgymj.php"] [unique_id "aoSA6dO5rbWdOArH04KTMQAAAQs"] [Tue Aug 18 12:57:29.930139 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zugvi.php"] [unique_id "aoSA6fcmepr5_nHgLbNlYQAAAl0"] [Tue Aug 18 12:57:29.974751 2026] [security2:error] [pid 67073:tid 67227] [client 4.232.151.198:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSA6fcmepr5_nHgLbNlYgAAAio"] [Tue Aug 18 12:57:29.982121 2026] [security2:error] [pid 66623:tid 66834] [client 20.104.85.180:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wso.php"] [unique_id "aoSA6dO5rbWdOArH04KTMgAAAU4"] [Tue Aug 18 12:57:30.019380 2026] [security2:error] [pid 67073:tid 67330] [client 132.196.30.78:21852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/bless.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcgAAApE"] [Tue Aug 18 12:57:30.042164 2026] [security2:error] [pid 67073:tid 67302] [client 138.36.100.162:41662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcwAAAnU"] [Tue Aug 18 12:57:30.042268 2026] [security2:error] [pid 67073:tid 67302] [client 138.36.100.162:41662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlcwAAAnU"] [Tue Aug 18 12:57:30.057345 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/adminfuns.php"] [unique_id "aoSA6vcmepr5_nHgLbNldAAAAos"] [Tue Aug 18 12:57:30.099275 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/item.php"] [unique_id "aoSA6tO5rbWdOArH04KTNAAAAQ4"] [Tue Aug 18 12:57:30.101753 2026] [security2:error] [pid 67073:tid 67256] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA6vcmepr5_nHgLbNldwAAAkc"] [Tue Aug 18 12:57:30.110951 2026] [security2:error] [pid 66623:tid 66863] [client 213.35.127.232:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTNQAAAWs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:30.133970 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNleAAAAoQ"] [Tue Aug 18 12:57:30.181347 2026] [security2:error] [pid 67073:tid 67281] [client 4.232.151.198:4331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSA6vcmepr5_nHgLbNligAAAmA"] [Tue Aug 18 12:57:30.195624 2026] [security2:error] [pid 67073:tid 67291] [client 172.182.200.96:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA6vcmepr5_nHgLbNliwAAAmo"] [Tue Aug 18 12:57:30.228849 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:30.229103 2026] [authz_core:error] [pid 67073:tid 67179] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:30.236822 2026] [security2:error] [pid 67073:tid 67247] [client 40.85.222.29:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wsrer.php"] [unique_id "aoSA6vcmepr5_nHgLbNllgAAAj4"] [Tue Aug 18 12:57:30.249528 2026] [security2:error] [pid 67073:tid 67206] [client 20.118.172.148:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/system_log.php"] [unique_id "aoSA6vcmepr5_nHgLbNllwAAAhU"] [Tue Aug 18 12:57:30.272882 2026] [security2:error] [pid 67073:tid 67215] [client 74.248.18.37:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/p.php"] [unique_id "aoSA6vcmepr5_nHgLbNlmgAAAh4"] [Tue Aug 18 12:57:30.274837 2026] [security2:error] [pid 67073:tid 67264] [client 74.248.18.37:27475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/file.php"] [unique_id "aoSA6vcmepr5_nHgLbNlmwAAAk8"] [Tue Aug 18 12:57:30.278996 2026] [security2:error] [pid 67073:tid 67223] [client 68.155.154.236:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA6vcmepr5_nHgLbNlnAAAAiY"] [Tue Aug 18 12:57:30.304444 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTNgAAAS4"] [Tue Aug 18 12:57:30.307442 2026] [security2:error] [pid 67073:tid 67322] [client 20.104.85.180:7007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/sf.php"] [unique_id "aoSA6vcmepr5_nHgLbNlngAAAok"] [Tue Aug 18 12:57:30.340848 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:25273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNloQAAAm4"] [Tue Aug 18 12:57:30.367426 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA6vcmepr5_nHgLbNlowAAAiA"] [Tue Aug 18 12:57:30.393340 2026] [security2:error] [pid 66623:tid 66859] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA6tO5rbWdOArH04KTOgAAAWc"] [Tue Aug 18 12:57:30.410031 2026] [security2:error] [pid 67073:tid 67242] [client 5.31.227.224:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpAAAAjk"] [Tue Aug 18 12:57:30.410168 2026] [security2:error] [pid 67073:tid 67242] [client 5.31.227.224:1439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpAAAAjk"] [Tue Aug 18 12:57:30.452697 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/k.php"] [unique_id "aoSA6tO5rbWdOArH04KTPAAAAXs"] [Tue Aug 18 12:57:30.487530 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSA6tO5rbWdOArH04KTPgAAAVs"] [Tue Aug 18 12:57:30.523698 2026] [security2:error] [pid 67073:tid 67263] [client 40.74.65.169:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/coffee.php"] [unique_id "aoSA6vcmepr5_nHgLbNlpgAAAk4"] [Tue Aug 18 12:57:30.531520 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:30.531795 2026] [authz_core:error] [pid 67073:tid 67152] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:30.555303 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/7.php"] [unique_id "aoSA6tO5rbWdOArH04KTQwAAARE"] [Tue Aug 18 12:57:30.592436 2026] [security2:error] [pid 66623:tid 66789] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTRAAAASE"] [Tue Aug 18 12:57:30.593781 2026] [security2:error] [pid 67073:tid 67277] [client 20.104.85.180:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/index/function.php"] [unique_id "aoSA6vcmepr5_nHgLbNlqQAAAlw"] [Tue Aug 18 12:57:30.609535 2026] [security2:error] [pid 67073:tid 67237] [client 40.85.222.29:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA6vcmepr5_nHgLbNlqgAAAjQ"] [Tue Aug 18 12:57:30.646291 2026] [security2:error] [pid 67073:tid 67224] [client 20.118.172.148:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/x.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrAAAAic"] [Tue Aug 18 12:57:30.657014 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.74.177:26154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrQAAAko"] [Tue Aug 18 12:57:30.718333 2026] [security2:error] [pid 67073:tid 67253] [client 172.182.200.96:7632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/oivcl.php"] [unique_id "aoSA6vcmepr5_nHgLbNlrwAAAkQ"] [Tue Aug 18 12:57:30.741442 2026] [security2:error] [pid 67073:tid 67320] [client 104.209.144.33:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSA6vcmepr5_nHgLbNlsgAAAoc"] [Tue Aug 18 12:57:30.771449 2026] [security2:error] [pid 66623:tid 66867] [client 40.74.65.169:26727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/ms-edit.php"] [unique_id "aoSA6tO5rbWdOArH04KTRQAAAW8"] [Tue Aug 18 12:57:30.772232 2026] [security2:error] [pid 67073:tid 67299] [client 157.20.138.62:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlswAAAnI"] [Tue Aug 18 12:57:30.772323 2026] [security2:error] [pid 67073:tid 67299] [client 157.20.138.62:64811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6vcmepr5_nHgLbNlswAAAnI"] [Tue Aug 18 12:57:30.804225 2026] [security2:error] [pid 67073:tid 67255] [client 20.203.183.135:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA6vcmepr5_nHgLbNltAAAAkY"] [Tue Aug 18 12:57:30.806197 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/sagax1.php"] [unique_id "aoSA6vcmepr5_nHgLbNltQAAAmY"] [Tue Aug 18 12:57:30.810064 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/license.php"] [unique_id "aoSA6tO5rbWdOArH04KTRgAAAWQ"] [Tue Aug 18 12:57:30.816466 2026] [security2:error] [pid 67073:tid 67283] [client 20.100.169.31:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/aa.php"] [unique_id "aoSA6vcmepr5_nHgLbNltgAAAmI"] [Tue Aug 18 12:57:30.816711 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.154.236:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA6tO5rbWdOArH04KTRwAAAV4"] [Tue Aug 18 12:57:30.826294 2026] [security2:error] [pid 67073:tid 67238] [client 4.232.151.198:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/222.php"] [unique_id "aoSA6vcmepr5_nHgLbNluAAAAjU"] [Tue Aug 18 12:57:30.835392 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:30.835643 2026] [authz_core:error] [pid 67073:tid 67172] [remote 216.73.216.206:51833] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:30.874631 2026] [security2:error] [pid 66623:tid 66818] [client 20.119.58.187:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-widgets.php"] [unique_id "aoSA6tO5rbWdOArH04KTSAAAAT4"] [Tue Aug 18 12:57:30.875372 2026] [security2:error] [pid 67073:tid 67280] [client 68.155.154.236:16238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNluwAAAl8"] [Tue Aug 18 12:57:30.880188 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:43570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/edit.php"] [unique_id "aoSA6tO5rbWdOArH04KTSQAAAT0"] [Tue Aug 18 12:57:30.886212 2026] [security2:error] [pid 67073:tid 67221] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA6vcmepr5_nHgLbNlvwAAAiQ"] [Tue Aug 18 12:57:30.903994 2026] [security2:error] [pid 67073:tid 67216] [client 74.248.18.37:3105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/goods.php"] [unique_id "aoSA6vcmepr5_nHgLbNlwQAAAh8"] [Tue Aug 18 12:57:30.908367 2026] [security2:error] [pid 66623:tid 66883] [client 74.248.18.37:8042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/pages.php"] [unique_id "aoSA6tO5rbWdOArH04KTSgAAAX8"] [Tue Aug 18 12:57:30.924969 2026] [security2:error] [pid 67073:tid 67312] [client 20.100.185.105:25160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fxcexgle.php"] [unique_id "aoSA6vcmepr5_nHgLbNlwwAAAn8"] [Tue Aug 18 12:57:30.930927 2026] [security2:error] [pid 66623:tid 66824] [client 149.34.210.141:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA6tO5rbWdOArH04KTSwAAAUQ"] [Tue Aug 18 12:57:30.946461 2026] [security2:error] [pid 67073:tid 67270] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/first.php"] [unique_id "aoSA6vcmepr5_nHgLbNlxAAAAlU"] [Tue Aug 18 12:57:30.956639 2026] [security2:error] [pid 67073:tid 67266] [client 40.85.222.29:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/yxijx.php"] [unique_id "aoSA6vcmepr5_nHgLbNlxQAAAlE"] [Tue Aug 18 12:57:31.007004 2026] [security2:error] [pid 66623:tid 66848] [client 172.182.200.96:14095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA69O5rbWdOArH04KTTgAAAVw"] [Tue Aug 18 12:57:31.052789 2026] [security2:error] [pid 67073:tid 67268] [client 20.226.56.190:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ad.php"] [unique_id "aoSA6_cmepr5_nHgLbNlyQAAAlM"] [Tue Aug 18 12:57:31.060069 2026] [security2:error] [pid 67073:tid 67321] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzAAAAog"] [Tue Aug 18 12:57:31.085450 2026] [security2:error] [pid 67073:tid 67324] [client 20.118.172.148:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzgAAAos"] [Tue Aug 18 12:57:31.087886 2026] [security2:error] [pid 67073:tid 67184] [remote 216.194.122.158:56050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSA6_cmepr5_nHgLbNlzwACF2w"] [Tue Aug 18 12:57:31.115324 2026] [security2:error] [pid 66623:tid 66781] [client 172.182.200.96:14193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zugvi.php"] [unique_id "aoSA69O5rbWdOArH04KTUQAAARk"] [Tue Aug 18 12:57:31.125941 2026] [security2:error] [pid 66623:tid 66813] [client 213.35.127.232:54973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA69O5rbWdOArH04KTUgAAATk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:31.130990 2026] [security2:error] [pid 67073:tid 67213] [client 213.202.253.4:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/schallfuns.php"] [unique_id "aoSA6_cmepr5_nHgLbNl0QAAAhw"], referer: www.google.com [Tue Aug 18 12:57:31.165693 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:11268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/load.php"] [unique_id "aoSA69O5rbWdOArH04KTVAAAASk"] [Tue Aug 18 12:57:31.184424 2026] [security2:error] [pid 66623:tid 66674] [remote 95.111.251.70:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSA69O5rbWdOArH04KTVgABPCU"] [Tue Aug 18 12:57:31.194352 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA69O5rbWdOArH04KTVwAAAYI"] [Tue Aug 18 12:57:31.196847 2026] [security2:error] [pid 66623:tid 66824] [client 149.34.210.141:57778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA6tO5rbWdOArH04KTSwAAAUQ"] [Tue Aug 18 12:57:31.207525 2026] [security2:error] [pid 66623:tid 66811] [client 40.74.65.169:4824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/classwithtostring.php"] [unique_id "aoSA69O5rbWdOArH04KTWAAAATc"] [Tue Aug 18 12:57:31.228537 2026] [security2:error] [pid 67073:tid 67256] [client 20.119.58.187:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-signup.php"] [unique_id "aoSA6_cmepr5_nHgLbNl1gAAAkc"] [Tue Aug 18 12:57:31.256648 2026] [security2:error] [pid 66623:tid 66873] [client 20.100.169.31:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/a7.php"] [unique_id "aoSA69O5rbWdOArH04KTWgAAAXU"] [Tue Aug 18 12:57:31.260961 2026] [security2:error] [pid 67073:tid 67291] [client 20.226.56.190:32280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/vd.php"] [unique_id "aoSA6_cmepr5_nHgLbNl1wAAAmo"] [Tue Aug 18 12:57:31.269109 2026] [security2:error] [pid 66623:tid 66888] [client 40.85.222.29:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA69O5rbWdOArH04KTWwAAAYQ"] [Tue Aug 18 12:57:31.273791 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.154.236:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA6_cmepr5_nHgLbNl2gAAAk8"] [Tue Aug 18 12:57:31.330506 2026] [security2:error] [pid 67073:tid 67295] [client 20.206.73.37:11393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/btx25.php"] [unique_id "aoSA6_cmepr5_nHgLbNl2wAAAm4"] [Tue Aug 18 12:57:31.348672 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA69O5rbWdOArH04KTXQAAAXM"] [Tue Aug 18 12:57:31.418862 2026] [security2:error] [pid 66623:tid 66771] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA69O5rbWdOArH04KTXwAAAQ8"] [Tue Aug 18 12:57:31.466042 2026] [security2:error] [pid 66623:tid 66857] [client 4.232.151.198:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSA69O5rbWdOArH04KTYgAAAWU"] [Tue Aug 18 12:57:31.476528 2026] [security2:error] [pid 66623:tid 66842] [client 172.182.200.96:7662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wsrer.php"] [unique_id "aoSA69O5rbWdOArH04KTYwAAAVY"] [Tue Aug 18 12:57:31.525181 2026] [security2:error] [pid 67073:tid 67219] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5AAAAiI"] [Tue Aug 18 12:57:31.533019 2026] [security2:error] [pid 67073:tid 67253] [client 40.74.65.169:27800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/222.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5gAAAkQ"] [Tue Aug 18 12:57:31.536404 2026] [security2:error] [pid 67073:tid 67232] [client 68.155.155.199:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file5.php"] [unique_id "aoSA6_cmepr5_nHgLbNl6AAAAi8"] [Tue Aug 18 12:57:31.536432 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.18.37:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/hplfuns.php"] [unique_id "aoSA6_cmepr5_nHgLbNl5wAAAi0"] [Tue Aug 18 12:57:31.536944 2026] [security2:error] [pid 66623:tid 66875] [client 20.119.58.187:11283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/manager.php"] [unique_id "aoSA69O5rbWdOArH04KTZQAAAXc"] [Tue Aug 18 12:57:31.546067 2026] [security2:error] [pid 67073:tid 67274] [client 20.100.185.105:6200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/locale.php"] [unique_id "aoSA6_cmepr5_nHgLbNl6gAAAlk"] [Tue Aug 18 12:57:31.549963 2026] [security2:error] [pid 66623:tid 66812] [client 40.85.222.29:26882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/jrpga.php"] [unique_id "aoSA69O5rbWdOArH04KTZgAAATg"] [Tue Aug 18 12:57:31.587538 2026] [security2:error] [pid 67073:tid 67263] [client 20.119.58.187:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSA6_cmepr5_nHgLbNl7gAAAk4"] [Tue Aug 18 12:57:31.596358 2026] [autoindex:error] [pid 66623:tid 66809] [client 158.158.74.177:26147] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:31.599413 2026] [security2:error] [pid 67073:tid 67283] [client 20.226.56.190:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/56.php"] [unique_id "aoSA6_cmepr5_nHgLbNl7wAAAmI"] [Tue Aug 18 12:57:31.608091 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.172.148:62096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/hosty.php"] [unique_id "aoSA6_cmepr5_nHgLbNl8AAAAjU"] [Tue Aug 18 12:57:31.640320 2026] [security2:error] [pid 67073:tid 67280] [client 20.215.241.237:48200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/cabs.php"] [unique_id "aoSA6_cmepr5_nHgLbNl8gAAAl8"] [Tue Aug 18 12:57:31.696065 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA6_cmepr5_nHgLbNl9AAAAoE"] [Tue Aug 18 12:57:31.731821 2026] [security2:error] [pid 67073:tid 67216] [client 20.48.236.86:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/aa.php"] [unique_id "aoSA6_cmepr5_nHgLbNl9gAAAh8"] [Tue Aug 18 12:57:31.775004 2026] [security2:error] [pid 67073:tid 67331] [client 68.155.154.236:16298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/blog/byp.php"] [unique_id "aoSA6_cmepr5_nHgLbNl-QAAApI"] [Tue Aug 18 12:57:31.781731 2026] [security2:error] [pid 66623:tid 66835] [client 74.7.175.188:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSA6tO5rbWdOArH04KTOQAAAU8"] [Tue Aug 18 12:57:31.794247 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:31858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/past.php"] [unique_id "aoSA6_cmepr5_nHgLbNl-gAAAmY"] [Tue Aug 18 12:57:31.833196 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA6_cmepr5_nHgLbNl_wAAAo0"] [Tue Aug 18 12:57:31.834960 2026] [security2:error] [pid 66623:tid 66820] [client 158.158.74.177:26147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSA69O5rbWdOArH04KTaQAAAUA"] [Tue Aug 18 12:57:31.851484 2026] [security2:error] [pid 67073:tid 67310] [client 20.203.183.135:12402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/media.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAAAAAn0"] [Tue Aug 18 12:57:31.860996 2026] [security2:error] [pid 67073:tid 67268] [client 68.155.154.236:39647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAQAAAlM"] [Tue Aug 18 12:57:31.889585 2026] [security2:error] [pid 67073:tid 67211] [client 20.119.58.187:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/media.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAgAAAho"] [Tue Aug 18 12:57:31.901943 2026] [security2:error] [pid 67073:tid 67233] [client 172.182.200.96:7655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA6_cmepr5_nHgLbNmAwAAAjA"] [Tue Aug 18 12:57:31.905963 2026] [security2:error] [pid 67073:tid 67246] [client 40.74.65.169:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/wp-ws68.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBAAAAj0"] [Tue Aug 18 12:57:31.921100 2026] [security2:error] [pid 67073:tid 67324] [client 20.226.36.136:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.roselifroesimoveis.com.br"] [uri "/images/security.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBgAAAos"] [Tue Aug 18 12:57:31.946626 2026] [security2:error] [pid 67073:tid 67102] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBwACbBo"] [Tue Aug 18 12:57:31.946805 2026] [security2:error] [pid 67073:tid 67293] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmBwACbBo"] [Tue Aug 18 12:57:31.965994 2026] [security2:error] [pid 67073:tid 67317] [client 20.118.172.148:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/test1.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCAAAAoQ"] [Tue Aug 18 12:57:31.972212 2026] [security2:error] [pid 67073:tid 67217] [client 178.153.171.161:45638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCQAAAiA"] [Tue Aug 18 12:57:31.972321 2026] [security2:error] [pid 67073:tid 67217] [client 178.153.171.161:45638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA6_cmepr5_nHgLbNmCQAAAiA"] [Tue Aug 18 12:57:32.044681 2026] [security2:error] [pid 67073:tid 67236] [client 20.119.58.187:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ws.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmDQAAAjM"] [Tue Aug 18 12:57:32.076124 2026] [security2:error] [pid 67073:tid 67223] [client 20.118.133.132:14861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/media.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmDgAAAiY"] [Tue Aug 18 12:57:32.113333 2026] [security2:error] [pid 67073:tid 67260] [client 4.232.151.198:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEAAAAks"] [Tue Aug 18 12:57:32.121789 2026] [security2:error] [pid 67073:tid 67271] [client 20.226.56.190:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/rx.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEQAAAlY"] [Tue Aug 18 12:57:32.131054 2026] [security2:error] [pid 67073:tid 67239] [client 40.85.222.29:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/nwwha.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEgAAAjY"] [Tue Aug 18 12:57:32.138994 2026] [security2:error] [pid 67073:tid 67279] [client 213.35.127.232:55183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmEwAAAl4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:32.167507 2026] [security2:error] [pid 67073:tid 67240] [client 74.248.18.37:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/htaccess.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmFAAAAjc"] [Tue Aug 18 12:57:32.182469 2026] [security2:error] [pid 67073:tid 67251] [client 20.100.185.105:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cache-base.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmFgAAAkI"] [Tue Aug 18 12:57:32.184477 2026] [security2:error] [pid 67073:tid 67302] [client 132.196.30.78:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmGQAAAnU"] [Tue Aug 18 12:57:32.240468 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:11478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/mar.php"] [unique_id "aoSA7NO5rbWdOArH04KTbAAAAXo"] [Tue Aug 18 12:57:32.247015 2026] [autoindex:error] [pid 67073:tid 67247] [client 20.79.204.6:4807] AH01276: Cannot serve directory /home1/xsolutions/pagazul.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:32.273443 2026] [security2:error] [pid 66623:tid 66841] [client 20.100.169.31:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/manager.php"] [unique_id "aoSA7NO5rbWdOArH04KTbQAAAVU"] [Tue Aug 18 12:57:32.286648 2026] [security2:error] [pid 67073:tid 67219] [client 172.182.200.96:14091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/yxijx.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmIgAAAiI"] [Tue Aug 18 12:57:32.360321 2026] [security2:error] [pid 67073:tid 67285] [client 20.226.56.190:23790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mandrill.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmJAAAAmQ"] [Tue Aug 18 12:57:32.383800 2026] [security2:error] [pid 66623:tid 66834] [client 40.74.65.169:28160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSA7NO5rbWdOArH04KTbwAAAU4"] [Tue Aug 18 12:57:32.400493 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.172.148:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/zwso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmJwAAAjU"] [Tue Aug 18 12:57:32.421906 2026] [security2:error] [pid 67073:tid 67241] [client 20.119.58.187:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKAAAAjg"] [Tue Aug 18 12:57:32.466238 2026] [authz_core:error] [pid 67073:tid 67274] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:32.466516 2026] [authz_core:error] [pid 67073:tid 67274] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:32.478686 2026] [security2:error] [pid 67073:tid 67250] [client 40.85.222.29:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/opsqt.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLAAAAkE"] [Tue Aug 18 12:57:32.492819 2026] [security2:error] [pid 67073:tid 67314] [client 68.155.155.199:2258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLQAAAoE"] [Tue Aug 18 12:57:32.512901 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/php.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLgAAAnM"] [Tue Aug 18 12:57:32.541519 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:31030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/main.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmLwAAAlg"] [Tue Aug 18 12:57:32.541693 2026] [security2:error] [pid 67073:tid 67297] [client 20.215.241.237:25293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/insc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMAAAAnA"] [Tue Aug 18 12:57:32.577309 2026] [security2:error] [pid 66623:tid 66802] [client 68.155.156.252:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/adminner.php"] [unique_id "aoSA7NO5rbWdOArH04KTcgAAAS4"] [Tue Aug 18 12:57:32.585586 2026] [security2:error] [pid 67073:tid 67301] [client 40.74.65.169:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/yj09.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMgAAAnQ"] [Tue Aug 18 12:57:32.601951 2026] [security2:error] [pid 67073:tid 67254] [client 223.185.37.47:9065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKQAAAkU"] [Tue Aug 18 12:57:32.602116 2026] [security2:error] [pid 67073:tid 67254] [client 223.185.37.47:9065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmKQAAAkU"] [Tue Aug 18 12:57:32.603189 2026] [security2:error] [pid 67073:tid 67280] [client 20.119.58.187:11290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/my1.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmMwAAAl8"] [Tue Aug 18 12:57:32.612357 2026] [security2:error] [pid 66623:tid 66852] [client 172.182.200.96:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA7NO5rbWdOArH04KTcwAAAWA"] [Tue Aug 18 12:57:32.638293 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.154.236:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA7NO5rbWdOArH04KTdAAAARA"] [Tue Aug 18 12:57:32.739490 2026] [security2:error] [pid 66623:tid 66880] [client 4.232.151.198:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSA7NO5rbWdOArH04KTdgAAAXw"] [Tue Aug 18 12:57:32.784863 2026] [security2:error] [pid 67073:tid 67226] [client 20.119.58.187:12081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/meta.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmOwAAAik"] [Tue Aug 18 12:57:32.799588 2026] [security2:error] [pid 67073:tid 67323] [client 74.248.18.37:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/images/wso.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPAAAAoo"] [Tue Aug 18 12:57:32.799600 2026] [security2:error] [pid 67073:tid 67312] [client 20.100.185.105:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/lite.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPQAAAn8"] [Tue Aug 18 12:57:32.799983 2026] [security2:error] [pid 67073:tid 67208] [client 40.85.222.29:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmPgAAAhc"] [Tue Aug 18 12:57:32.860156 2026] [security2:error] [pid 67073:tid 67242] [client 20.100.169.31:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-mail.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmQgAAAjk"] [Tue Aug 18 12:57:32.872618 2026] [security2:error] [pid 67073:tid 67287] [client 132.196.30.78:21825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/fone1.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmQwAAAmY"] [Tue Aug 18 12:57:32.877474 2026] [autoindex:error] [pid 66623:tid 66855] [client 172.202.39.151:50182] AH01276: Cannot serve directory /home1/diogoem/teste.advocaciacriminalgo.com.br/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:32.957516 2026] [security2:error] [pid 67073:tid 67293] [client 20.119.58.187:11310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/mm.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmRgAAAmw"] [Tue Aug 18 12:57:32.973128 2026] [security2:error] [pid 67073:tid 67244] [client 172.182.200.96:14176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/jrpga.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmRwAAAjs"] [Tue Aug 18 12:57:32.994767 2026] [security2:error] [pid 67073:tid 67269] [client 85.154.68.202:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmSAAAAlQ"] [Tue Aug 18 12:57:32.994898 2026] [security2:error] [pid 67073:tid 67269] [client 85.154.68.202:54350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7Pcmepr5_nHgLbNmSAAAAlQ"] [Tue Aug 18 12:57:33.061506 2026] [security2:error] [pid 67073:tid 67260] [client 20.118.172.148:62108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/Geforce.php"] [unique_id "aoSA7fcmepr5_nHgLbNmTAAAAks"] [Tue Aug 18 12:57:33.077127 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA7fcmepr5_nHgLbNmTQAAAkg"] [Tue Aug 18 12:57:33.089871 2026] [security2:error] [pid 67073:tid 67259] [client 79.127.164.8:47150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysqldump.bak"] [unique_id "aoSA7fcmepr5_nHgLbNmTgAAAko"], referer: https://medihub.com.br/mysqldump.bak [Tue Aug 18 12:57:33.135482 2026] [security2:error] [pid 66623:tid 66874] [client 160.120.140.123:49182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KTegAAAXY"] [Tue Aug 18 12:57:33.135589 2026] [security2:error] [pid 66623:tid 66874] [client 160.120.140.123:49182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KTegAAAXY"] [Tue Aug 18 12:57:33.149205 2026] [security2:error] [pid 67073:tid 67209] [client 213.35.127.232:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUAAAAhg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:33.150270 2026] [security2:error] [pid 67073:tid 67264] [client 20.119.58.187:12092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hehe.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUQAAAk8"] [Tue Aug 18 12:57:33.159367 2026] [security2:error] [pid 67073:tid 67302] [client 40.74.65.169:27756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA7fcmepr5_nHgLbNmUgAAAnU"] [Tue Aug 18 12:57:33.174999 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.56.190:31678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ga.php"] [unique_id "aoSA7fcmepr5_nHgLbNmVAAAAjw"] [Tue Aug 18 12:57:33.194334 2026] [security2:error] [pid 66623:tid 66867] [client 172.202.39.151:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSA7dO5rbWdOArH04KTewAAAW8"] [Tue Aug 18 12:57:33.213988 2026] [autoindex:error] [pid 67073:tid 67325] [client 82.102.18.182:33894] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:33.217389 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:31851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/php8.php"] [unique_id "aoSA7dO5rbWdOArH04KTfAAAASM"] [Tue Aug 18 12:57:33.218018 2026] [security2:error] [pid 66623:tid 66850] [client 20.203.183.135:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/admin.php"] [unique_id "aoSA7dO5rbWdOArH04KTfQAAAV4"] [Tue Aug 18 12:57:33.230295 2026] [security2:error] [pid 67073:tid 67303] [client 68.155.154.236:45605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWAAAAnY"] [Tue Aug 18 12:57:33.232453 2026] [security2:error] [pid 67073:tid 67276] [client 68.155.154.236:16269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWQAAAls"] [Tue Aug 18 12:57:33.274006 2026] [security2:error] [pid 67073:tid 67309] [client 40.74.65.169:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/scxy.php"] [unique_id "aoSA7fcmepr5_nHgLbNmWgAAAnw"] [Tue Aug 18 12:57:33.279440 2026] [security2:error] [pid 67073:tid 67294] [client 104.209.144.33:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSA7fcmepr5_nHgLbNmXAAAAm0"] [Tue Aug 18 12:57:33.311072 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/network.php"] [unique_id "aoSA7dO5rbWdOArH04KTfwAAAUI"] [Tue Aug 18 12:57:33.314849 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:33.315115 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:33.315554 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:33.315817 2026] [authz_core:error] [pid 67073:tid 67110] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:33.315902 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:33.316192 2026] [authz_core:error] [pid 67073:tid 67174] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:33.318741 2026] [security2:error] [pid 67073:tid 67237] [client 20.215.241.237:38211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/file.php"] [unique_id "aoSA7fcmepr5_nHgLbNmYAAAAjQ"] [Tue Aug 18 12:57:33.396599 2026] [security2:error] [pid 66623:tid 66858] [client 20.100.185.105:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-good.php"] [unique_id "aoSA7dO5rbWdOArH04KTgAAAAWY"] [Tue Aug 18 12:57:33.428181 2026] [security2:error] [pid 66623:tid 66856] [client 158.158.74.177:16566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSA7dO5rbWdOArH04KTggAAAWQ"] [Tue Aug 18 12:57:33.441093 2026] [security2:error] [pid 66623:tid 66818] [client 74.248.18.37:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/index/function.php"] [unique_id "aoSA7dO5rbWdOArH04KTgwAAAT4"] [Tue Aug 18 12:57:33.448014 2026] [security2:error] [pid 66623:tid 66877] [client 192.141.172.134:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KThAAAAXk"] [Tue Aug 18 12:57:33.454729 2026] [security2:error] [pid 66623:tid 66877] [client 192.141.172.134:64362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA7dO5rbWdOArH04KThAAAAXk"] [Tue Aug 18 12:57:33.471751 2026] [security2:error] [pid 67073:tid 67238] [client 40.85.222.29:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA7fcmepr5_nHgLbNmZwAAAjU"] [Tue Aug 18 12:57:33.477338 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.30.78:21894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ncx.php"] [unique_id "aoSA7fcmepr5_nHgLbNmaAAAAj4"] [Tue Aug 18 12:57:33.507311 2026] [security2:error] [pid 67073:tid 67219] [client 20.119.58.187:12490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/yindu.php"] [unique_id "aoSA7fcmepr5_nHgLbNmaQAAAiI"] [Tue Aug 18 12:57:33.516843 2026] [security2:error] [pid 67073:tid 67315] [client 68.155.155.199:10403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmagAAAoI"] [Tue Aug 18 12:57:33.530291 2026] [autoindex:error] [pid 67073:tid 67320] [client 20.119.58.187:2643] AH01276: Cannot serve directory /home3/slwebn28/portopreguicasresort.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:33.551753 2026] [security2:error] [pid 67073:tid 67082] [remote 162.55.89.48:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbQACQAY"] [Tue Aug 18 12:57:33.585475 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.154.236:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbgAAAnM"] [Tue Aug 18 12:57:33.639101 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/fpwch.php"] [unique_id "aoSA7fcmepr5_nHgLbNmbwAAAh8"] [Tue Aug 18 12:57:33.664211 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:11516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/new.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcQAAAiU"] [Tue Aug 18 12:57:33.707339 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.169.31:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/w1.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcgAAAmQ"] [Tue Aug 18 12:57:33.710811 2026] [security2:error] [pid 67073:tid 67331] [client 172.182.200.96:14206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA7fcmepr5_nHgLbNmcwAAApI"] [Tue Aug 18 12:57:33.785290 2026] [security2:error] [pid 67073:tid 67229] [client 114.5.214.109:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7fcmepr5_nHgLbNmdgAAAiw"] [Tue Aug 18 12:57:33.791276 2026] [security2:error] [pid 67073:tid 67229] [client 114.5.214.109:49815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7fcmepr5_nHgLbNmdgAAAiw"] [Tue Aug 18 12:57:33.818967 2026] [security2:error] [pid 66623:tid 66806] [client 40.85.222.29:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA7dO5rbWdOArH04KThwAAATI"] [Tue Aug 18 12:57:33.838920 2026] [security2:error] [pid 66623:tid 66859] [client 74.7.228.16:41404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.coffeestationbrasil.com.br.culinariaemporio.com.br"] [uri "/index.php"] [unique_id "aoSA7NO5rbWdOArH04KTdQABZ0Q"] [Tue Aug 18 12:57:33.862576 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "aoSA7fcmepr5_nHgLbNmegAAAms"] [Tue Aug 18 12:57:33.868108 2026] [security2:error] [pid 67073:tid 67321] [client 20.215.241.237:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/dex.php"] [unique_id "aoSA7fcmepr5_nHgLbNmewAAAog"] [Tue Aug 18 12:57:33.943969 2026] [security2:error] [pid 66623:tid 66876] [client 74.248.18.37:20497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/plugins.php"] [unique_id "aoSA7dO5rbWdOArH04KTigAAAXg"] [Tue Aug 18 12:57:33.978634 2026] [security2:error] [pid 66623:tid 66886] [client 40.74.65.169:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSA7dO5rbWdOArH04KTiwAAAYI"] [Tue Aug 18 12:57:34.019791 2026] [security2:error] [pid 67073:tid 67319] [client 20.100.185.105:25194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/goods.php"] [unique_id "aoSA7vcmepr5_nHgLbNmgwAAAoY"] [Tue Aug 18 12:57:34.023046 2026] [security2:error] [pid 66623:tid 66776] [client 20.119.58.187:11285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/0x.php"] [unique_id "aoSA7tO5rbWdOArH04KTjQAAARQ"] [Tue Aug 18 12:57:34.074610 2026] [security2:error] [pid 66623:tid 66853] [client 74.248.18.37:3657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/info.php"] [unique_id "aoSA7tO5rbWdOArH04KTjgAAAWE"] [Tue Aug 18 12:57:34.099450 2026] [security2:error] [pid 67073:tid 67228] [client 40.85.222.29:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSA7vcmepr5_nHgLbNmhQAAAis"] [Tue Aug 18 12:57:34.144457 2026] [security2:error] [pid 67073:tid 67154] [remote 216.194.122.158:56066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carnescapellari.top"] [uri "/wp-login.php"] [unique_id "aoSA7vcmepr5_nHgLbNmiQACjU4"] [Tue Aug 18 12:57:34.144599 2026] [security2:error] [pid 67073:tid 67244] [client 104.209.144.33:19627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmiAAAAjs"] [Tue Aug 18 12:57:34.165412 2026] [security2:error] [pid 67073:tid 67231] [client 213.35.127.232:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA7vcmepr5_nHgLbNmigAAAi4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:34.215053 2026] [security2:error] [pid 67073:tid 67328] [client 68.155.154.236:40282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA7vcmepr5_nHgLbNmjQAAAo8"] [Tue Aug 18 12:57:34.225710 2026] [security2:error] [pid 67073:tid 67206] [client 4.232.151.198:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA7vcmepr5_nHgLbNmjwAAAhU"] [Tue Aug 18 12:57:34.242559 2026] [security2:error] [pid 67073:tid 67260] [client 40.74.65.169:43159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp.php"] [unique_id "aoSA7vcmepr5_nHgLbNmkAAAAks"] [Tue Aug 18 12:57:34.274265 2026] [authz_core:error] [pid 67073:tid 67168] [remote 57.141.22.1:49298] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:34.274537 2026] [authz_core:error] [pid 67073:tid 67168] [remote 57.141.22.1:49298] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:34.279419 2026] [security2:error] [pid 67073:tid 67257] [client 20.48.236.86:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/av.php"] [unique_id "aoSA7vcmepr5_nHgLbNmkgAAAkg"] [Tue Aug 18 12:57:34.326532 2026] [security2:error] [pid 67073:tid 67226] [client 132.196.30.78:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmlAAAAik"] [Tue Aug 18 12:57:34.343585 2026] [security2:error] [pid 67073:tid 67276] [client 20.119.58.187:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known//index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmlQAAAls"] [Tue Aug 18 12:57:34.376225 2026] [security2:error] [pid 67073:tid 67239] [client 20.119.58.187:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/0.php"] [unique_id "aoSA7vcmepr5_nHgLbNmmAAAAjY"] [Tue Aug 18 12:57:34.385060 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.200.96:14177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA7vcmepr5_nHgLbNmmQAAAm0"] [Tue Aug 18 12:57:34.402515 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSA7tO5rbWdOArH04KTkAAAARU"] [Tue Aug 18 12:57:34.413743 2026] [security2:error] [pid 66623:tid 66771] [client 20.118.172.148:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA7tO5rbWdOArH04KTkQAAAQ8"] [Tue Aug 18 12:57:34.428299 2026] [security2:error] [pid 67073:tid 67306] [client 158.158.74.177:26163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSA7vcmepr5_nHgLbNmnQAAAnk"] [Tue Aug 18 12:57:34.434300 2026] [security2:error] [pid 67073:tid 67265] [client 20.215.241.237:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/key.php"] [unique_id "aoSA7vcmepr5_nHgLbNmngAAAlA"] [Tue Aug 18 12:57:34.558372 2026] [security2:error] [pid 67073:tid 67329] [client 104.209.144.33:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmoAAAApA"] [Tue Aug 18 12:57:34.592065 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/post.php"] [unique_id "aoSA7vcmepr5_nHgLbNmogAAAnw"] [Tue Aug 18 12:57:34.623427 2026] [security2:error] [pid 67073:tid 67213] [client 20.100.169.31:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bolt.php"] [unique_id "aoSA7vcmepr5_nHgLbNmowAAAhw"] [Tue Aug 18 12:57:34.647981 2026] [security2:error] [pid 67073:tid 67205] [client 20.100.185.105:6369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqAAAAhQ"] [Tue Aug 18 12:57:34.657227 2026] [security2:error] [pid 67073:tid 67315] [client 40.74.65.169:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqQAAAoI"] [Tue Aug 18 12:57:34.697880 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.154.236:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alltimeadm.com.br"] [uri "/images/security.php"] [unique_id "aoSA7tO5rbWdOArH04KTlAAAAVY"] [Tue Aug 18 12:57:34.707391 2026] [security2:error] [pid 67073:tid 67263] [client 74.248.18.37:27504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/profile.php"] [unique_id "aoSA7vcmepr5_nHgLbNmqwAAAk4"] [Tue Aug 18 12:57:34.729336 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/phpmailer//index.php"] [unique_id "aoSA7vcmepr5_nHgLbNmrAAAAjU"] [Tue Aug 18 12:57:34.729341 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/oxshell.php"] [unique_id "aoSA7tO5rbWdOArH04KTlgAAASc"] [Tue Aug 18 12:57:34.775753 2026] [security2:error] [pid 67073:tid 67221] [client 40.85.222.29:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSA7vcmepr5_nHgLbNmsAAAAiQ"] [Tue Aug 18 12:57:34.817214 2026] [security2:error] [pid 67073:tid 67251] [client 68.155.154.236:8001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA7vcmepr5_nHgLbNmswAAAkI"] [Tue Aug 18 12:57:34.878102 2026] [authz_core:error] [pid 66623:tid 66648] [remote 57.141.22.37:61138] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:34.878378 2026] [authz_core:error] [pid 66623:tid 66648] [remote 57.141.22.37:61138] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:34.920580 2026] [security2:error] [pid 67073:tid 67322] [client 4.232.151.198:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/akc.php"] [unique_id "aoSA7vcmepr5_nHgLbNmtgAAAok"] [Tue Aug 18 12:57:34.942219 2026] [security2:error] [pid 67073:tid 67250] [client 132.196.30.78:18625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wso.php"] [unique_id "aoSA7vcmepr5_nHgLbNmuAAAAkE"] [Tue Aug 18 12:57:35.034546 2026] [security2:error] [pid 66623:tid 66787] [client 68.155.155.199:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSA79O5rbWdOArH04KTmgAAAR8"] [Tue Aug 18 12:57:35.060160 2026] [security2:error] [pid 67073:tid 67312] [client 40.74.65.169:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/i.php"] [unique_id "aoSA7_cmepr5_nHgLbNmwgAAAn8"] [Tue Aug 18 12:57:35.079939 2026] [security2:error] [pid 67073:tid 67313] [client 20.65.98.162:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/fz.php"] [unique_id "aoSA7_cmepr5_nHgLbNmxAAAAoA"] [Tue Aug 18 12:57:35.083594 2026] [authz_core:error] [pid 67073:tid 67139] [remote 57.141.22.25:57326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:35.083862 2026] [authz_core:error] [pid 67073:tid 67139] [remote 57.141.22.25:57326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:35.089256 2026] [security2:error] [pid 67073:tid 67268] [client 20.119.58.187:12485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "aoSA7_cmepr5_nHgLbNmxgAAAlM"] [Tue Aug 18 12:57:35.095408 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/php8.php"] [unique_id "aoSA7_cmepr5_nHgLbNmyQAAAmc"] [Tue Aug 18 12:57:35.135694 2026] [security2:error] [pid 67073:tid 67319] [client 40.85.222.29:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzAAAAoY"] [Tue Aug 18 12:57:35.144013 2026] [security2:error] [pid 67073:tid 67287] [client 20.206.73.37:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzQAAAmY"] [Tue Aug 18 12:57:35.149259 2026] [security2:error] [pid 66623:tid 66865] [client 20.250.13.23:39668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA79O5rbWdOArH04KTmwAAAW0"] [Tue Aug 18 12:57:35.168549 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about/function.php"] [unique_id "aoSA79O5rbWdOArH04KTnAAAAS8"] [Tue Aug 18 12:57:35.176769 2026] [security2:error] [pid 67073:tid 67284] [client 213.35.127.232:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA7_cmepr5_nHgLbNmzwAAAmM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:35.233228 2026] [security2:error] [pid 67073:tid 67266] [client 158.158.34.183:11377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSA7_cmepr5_nHgLbNm2AAAAlE"] [Tue Aug 18 12:57:35.253886 2026] [autoindex:error] [pid 67073:tid 67227] [client 158.158.74.177:26131] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:35.265704 2026] [security2:error] [pid 67073:tid 67208] [client 20.100.185.105:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cv.php"] [unique_id "aoSA7_cmepr5_nHgLbNm2QAAAhc"] [Tue Aug 18 12:57:35.293401 2026] [security2:error] [pid 66623:tid 66829] [client 74.248.18.37:7213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/r.php"] [unique_id "aoSA79O5rbWdOArH04KTngAAAUk"] [Tue Aug 18 12:57:35.346507 2026] [security2:error] [pid 66623:tid 66835] [client 40.74.65.169:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/blurbs.php"] [unique_id "aoSA79O5rbWdOArH04KTnwAAAU8"] [Tue Aug 18 12:57:35.347476 2026] [security2:error] [pid 67073:tid 67087] [remote 151.240.45.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.45.240.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-login.php"] [unique_id "aoSA7_cmepr5_nHgLbNm4QACVAs"] [Tue Aug 18 12:57:35.388110 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:27515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/sx.php"] [unique_id "aoSA79O5rbWdOArH04KToAAAASU"] [Tue Aug 18 12:57:35.440922 2026] [security2:error] [pid 67073:tid 67295] [client 20.215.241.237:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/kir.php"] [unique_id "aoSA7_cmepr5_nHgLbNm5gAAAm4"] [Tue Aug 18 12:57:35.449355 2026] [security2:error] [pid 67073:tid 67236] [client 20.119.58.187:11232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/p.php"] [unique_id "aoSA7_cmepr5_nHgLbNm5wAAAjM"] [Tue Aug 18 12:57:35.462192 2026] [security2:error] [pid 67073:tid 67264] [client 40.85.222.29:25036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSA7_cmepr5_nHgLbNm6AAAAk8"] [Tue Aug 18 12:57:35.465998 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12492] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSA79O5rbWdOArH04KToQAAAUA"] [Tue Aug 18 12:57:35.466085 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSA79O5rbWdOArH04KToQAAAUA"] [Tue Aug 18 12:57:35.468102 2026] [security2:error] [pid 67073:tid 67302] [client 158.158.74.177:26131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA7_cmepr5_nHgLbNm6QAAAnU"] [Tue Aug 18 12:57:35.529080 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:35.529541 2026] [authz_core:error] [pid 67073:tid 67079] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:35.563380 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSA79O5rbWdOArH04KTogAAAVQ"] [Tue Aug 18 12:57:35.607511 2026] [security2:error] [pid 67073:tid 67306] [client 104.209.144.33:19585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/first.php"] [unique_id "aoSA7_cmepr5_nHgLbNm7wAAAnk"] [Tue Aug 18 12:57:35.629416 2026] [security2:error] [pid 67073:tid 67265] [client 52.173.121.69:17928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA7_cmepr5_nHgLbNm8AAAAlA"] [Tue Aug 18 12:57:35.679893 2026] [security2:error] [pid 67073:tid 67222] [client 157.51.166.53:49311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9AAAAiU"] [Tue Aug 18 12:57:35.680010 2026] [security2:error] [pid 67073:tid 67222] [client 157.51.166.53:49311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9AAAAiU"] [Tue Aug 18 12:57:35.741119 2026] [security2:error] [pid 67073:tid 67283] [client 40.85.222.29:26913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSA7_cmepr5_nHgLbNm9wAAAmI"] [Tue Aug 18 12:57:35.788429 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/mac.php"] [unique_id "aoSA79O5rbWdOArH04KTowAAAWs"] [Tue Aug 18 12:57:35.801112 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/php.php"] [unique_id "aoSA7_cmepr5_nHgLbNm-QAAAi8"] [Tue Aug 18 12:57:35.804057 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/abcd.php"] [unique_id "aoSA79O5rbWdOArH04KTpAAAAS4"] [Tue Aug 18 12:57:35.821765 2026] [security2:error] [pid 67073:tid 67230] [client 20.119.58.187:12489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/BbUMY/flower.php"] [unique_id "aoSA7_cmepr5_nHgLbNm_AAAAi0"] [Tue Aug 18 12:57:35.828568 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:35.828841 2026] [authz_core:error] [pid 67073:tid 67126] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:35.853969 2026] [security2:error] [pid 66623:tid 66798] [client 172.202.39.151:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSA79O5rbWdOArH04KTpQAAASo"] [Tue Aug 18 12:57:35.866852 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/function/function.php"] [unique_id "aoSA79O5rbWdOArH04KTpgAAARg"] [Tue Aug 18 12:57:35.879339 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:48921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA79O5rbWdOArH04KTpwAAAUo"] [Tue Aug 18 12:57:35.883695 2026] [security2:error] [pid 67073:tid 67253] [client 20.100.185.105:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/core.php"] [unique_id "aoSA7_cmepr5_nHgLbNm_gAAAkQ"] [Tue Aug 18 12:57:35.920827 2026] [security2:error] [pid 66623:tid 66801] [client 132.196.30.78:21904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/zup.php73"] [unique_id "aoSA79O5rbWdOArH04KTqgAAAS0"] [Tue Aug 18 12:57:35.987635 2026] [authz_core:error] [pid 67073:tid 67263] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:35.987917 2026] [authz_core:error] [pid 67073:tid 67263] [client 192.178.4.133:46321] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:35.995074 2026] [security2:error] [pid 67073:tid 67329] [client 74.248.18.37:20534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/radio.php"] [unique_id "aoSA7_cmepr5_nHgLbNnAgAAApA"] [Tue Aug 18 12:57:36.020486 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBAAAAnw"] [Tue Aug 18 12:57:36.020823 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:26934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBQAAAoc"] [Tue Aug 18 12:57:36.047082 2026] [security2:error] [pid 67073:tid 67314] [client 40.74.65.169:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/bajah.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnBwAAAoE"] [Tue Aug 18 12:57:36.189745 2026] [security2:error] [pid 66623:tid 66772] [client 213.35.127.232:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA8NO5rbWdOArH04KTrgAAARA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:36.191406 2026] [security2:error] [pid 67073:tid 67221] [client 20.119.58.187:12493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ID3//file.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnCgAAAiQ"] [Tue Aug 18 12:57:36.211119 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:11322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/past.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnCwAAAkI"] [Tue Aug 18 12:57:36.227362 2026] [security2:error] [pid 66623:tid 66667] [remote 129.121.123.168:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sprintlimp.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8NO5rbWdOArH04KTrwABOB4"] [Tue Aug 18 12:57:36.234684 2026] [security2:error] [pid 67073:tid 67262] [client 196.12.128.158:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDQAAAk0"] [Tue Aug 18 12:57:36.234783 2026] [security2:error] [pid 67073:tid 67262] [client 196.12.128.158:54714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDQAAAk0"] [Tue Aug 18 12:57:36.239610 2026] [security2:error] [pid 67073:tid 67238] [client 4.232.151.198:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDgAAAjU"] [Tue Aug 18 12:57:36.259185 2026] [security2:error] [pid 67073:tid 67299] [client 158.158.74.177:16557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnDwAAAnI"] [Tue Aug 18 12:57:36.270181 2026] [security2:error] [pid 67073:tid 67285] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEAAAAmQ"] [Tue Aug 18 12:57:36.300920 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:26929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEQAAAl0"] [Tue Aug 18 12:57:36.318371 2026] [security2:error] [pid 67073:tid 67259] [client 158.158.34.183:19941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/updates.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnEwAAAko"] [Tue Aug 18 12:57:36.383563 2026] [security2:error] [pid 67073:tid 67330] [client 52.173.121.69:25015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnFQAAApE"] [Tue Aug 18 12:57:36.444038 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:36.444329 2026] [authz_core:error] [pid 67073:tid 67115] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:36.455335 2026] [security2:error] [pid 67073:tid 67242] [client 20.118.172.148:62127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnGQAAAjk"] [Tue Aug 18 12:57:36.503101 2026] [security2:error] [pid 67073:tid 67252] [client 20.100.185.105:29238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ahax.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHAAAAkM"] [Tue Aug 18 12:57:36.539884 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-manager.php"] [unique_id "aoSA8NO5rbWdOArH04KTsgAAAV4"] [Tue Aug 18 12:57:36.557351 2026] [security2:error] [pid 67073:tid 67313] [client 20.119.58.187:12089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine//about.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHQAAAoA"] [Tue Aug 18 12:57:36.562267 2026] [security2:error] [pid 67073:tid 67288] [client 20.119.58.187:11477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/root.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnHgAAAmc"] [Tue Aug 18 12:57:36.604875 2026] [security2:error] [pid 67073:tid 67326] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIAAAAo0"] [Tue Aug 18 12:57:36.606220 2026] [security2:error] [pid 67073:tid 67244] [client 68.155.155.199:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/atomlib.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIQAAAjs"] [Tue Aug 18 12:57:36.621717 2026] [security2:error] [pid 67073:tid 67256] [client 40.85.222.29:26896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIgAAAkc"] [Tue Aug 18 12:57:36.625958 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.7.189:17671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bthil.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnIwAAAlE"] [Tue Aug 18 12:57:36.645351 2026] [security2:error] [pid 66623:tid 66815] [client 20.226.7.189:17664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/index/function.php"] [unique_id "aoSA8NO5rbWdOArH04KTswAAATs"] [Tue Aug 18 12:57:36.671558 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:27517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJQAAAmY"] [Tue Aug 18 12:57:36.674272 2026] [security2:error] [pid 67073:tid 67331] [client 20.118.133.132:16807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/images.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJgAAApI"] [Tue Aug 18 12:57:36.675942 2026] [security2:error] [pid 67073:tid 67258] [client 20.226.7.189:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnJwAAAkk"] [Tue Aug 18 12:57:36.678413 2026] [security2:error] [pid 67073:tid 67090] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKQACjw4"] [Tue Aug 18 12:57:36.678516 2026] [security2:error] [pid 67073:tid 67328] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKQACjw4"] [Tue Aug 18 12:57:36.698979 2026] [security2:error] [pid 67073:tid 67310] [client 20.226.7.189:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/file5.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKgAAAn0"] [Tue Aug 18 12:57:36.718420 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.7.189:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnKwAAAkg"] [Tue Aug 18 12:57:36.720822 2026] [security2:error] [pid 67073:tid 67209] [client 40.74.65.169:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/domvf.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnLQAAAhg"] [Tue Aug 18 12:57:36.737385 2026] [security2:error] [pid 67073:tid 67245] [client 20.226.7.189:1739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-includes/blocks/search/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnLgAAAjw"] [Tue Aug 18 12:57:36.737387 2026] [security2:error] [pid 66623:tid 66779] [client 20.250.13.23:25719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/ww5.php"] [unique_id "aoSA8NO5rbWdOArH04KTtQAAARc"] [Tue Aug 18 12:57:36.745808 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:36.746099 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:36.753466 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.7.189:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/edit.php"] [unique_id "aoSA8NO5rbWdOArH04KTtwAAARM"] [Tue Aug 18 12:57:36.763884 2026] [security2:error] [pid 66623:tid 66822] [client 79.127.164.8:45388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/mysqldump.sql"] [unique_id "aoSA8NO5rbWdOArH04KTuAAAAUI"], referer: https://medihub.com.br/mysqldump.sql [Tue Aug 18 12:57:36.782780 2026] [security2:error] [pid 67073:tid 67224] [client 20.226.7.189:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/a.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnMgAAAic"] [Tue Aug 18 12:57:36.803394 2026] [security2:error] [pid 67073:tid 67318] [client 20.226.7.189:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/w.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnMwAAAoU"] [Tue Aug 18 12:57:36.818314 2026] [security2:error] [pid 67073:tid 67271] [client 20.215.241.237:25280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/nofile.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnNAAAAlY"] [Tue Aug 18 12:57:36.841956 2026] [security2:error] [pid 67073:tid 67230] [client 20.226.7.189:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnNgAAAi0"] [Tue Aug 18 12:57:36.842796 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:20500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSA8Pcmepr5_nHgLbNnNwAAAng"] [Tue Aug 18 12:57:36.848308 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:24983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/weozh.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnOAAAAiM"] [Tue Aug 18 12:57:36.880268 2026] [security2:error] [pid 67073:tid 67329] [client 20.48.236.86:23289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/media.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnPgAAApA"] [Tue Aug 18 12:57:36.882298 2026] [security2:error] [pid 67073:tid 67320] [client 20.226.7.189:17699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/0x.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnPwAAAoc"] [Tue Aug 18 12:57:36.902382 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.7.189:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/file.php"] [unique_id "aoSA8NO5rbWdOArH04KTuQAAAXk"] [Tue Aug 18 12:57:36.913306 2026] [security2:error] [pid 67073:tid 67261] [client 132.196.30.78:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/k.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQAAAAkw"] [Tue Aug 18 12:57:36.913426 2026] [security2:error] [pid 67073:tid 67222] [client 20.119.58.187:11480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/r.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQQAAAiU"] [Tue Aug 18 12:57:36.919813 2026] [security2:error] [pid 67073:tid 67300] [client 20.226.7.189:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQwAAAnM"] [Tue Aug 18 12:57:36.936004 2026] [security2:error] [pid 67073:tid 67235] [client 20.119.58.187:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine//index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnRAAAAjI"] [Tue Aug 18 12:57:36.944494 2026] [security2:error] [pid 67073:tid 67325] [client 4.232.151.198:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnRQAAAow"] [Tue Aug 18 12:57:36.946572 2026] [security2:error] [pid 67073:tid 67211] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnQgACGjo"] [Tue Aug 18 12:57:36.953474 2026] [security2:error] [pid 67073:tid 67221] [client 104.209.144.33:29862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSAAAAiQ"] [Tue Aug 18 12:57:36.965222 2026] [security2:error] [pid 67073:tid 67216] [client 20.226.7.189:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSQAAAh8"] [Tue Aug 18 12:57:36.984147 2026] [security2:error] [pid 67073:tid 67312] [client 197.184.64.235:41937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSwAAAn8"] [Tue Aug 18 12:57:36.986229 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.7.189:1783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnTAAAAkU"] [Tue Aug 18 12:57:36.988294 2026] [security2:error] [pid 67073:tid 67312] [client 197.184.64.235:41937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8Pcmepr5_nHgLbNnSwAAAn8"] [Tue Aug 18 12:57:37.005891 2026] [security2:error] [pid 66623:tid 66890] [client 20.226.7.189:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/3.php"] [unique_id "aoSA8dO5rbWdOArH04KTugAAAYY"] [Tue Aug 18 12:57:37.020428 2026] [security2:error] [pid 67073:tid 67259] [client 40.85.222.29:26890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSA8fcmepr5_nHgLbNnTwAAAko"] [Tue Aug 18 12:57:37.028868 2026] [security2:error] [pid 67073:tid 67231] [client 20.226.7.189:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/config.php"] [unique_id "aoSA8fcmepr5_nHgLbNnUAAAAi4"] [Tue Aug 18 12:57:37.047187 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:37.047444 2026] [authz_core:error] [pid 67073:tid 67198] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:37.049508 2026] [security2:error] [pid 67073:tid 67319] [client 20.226.7.189:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/simple.php"] [unique_id "aoSA8fcmepr5_nHgLbNnUwAAAoY"] [Tue Aug 18 12:57:37.057872 2026] [security2:error] [pid 67073:tid 67107] [remote 216.194.122.158:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVAACKR8"] [Tue Aug 18 12:57:37.076254 2026] [security2:error] [pid 67073:tid 67313] [client 20.226.7.189:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/storage/index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVQAAAoA"] [Tue Aug 18 12:57:37.097967 2026] [security2:error] [pid 67073:tid 67217] [client 20.226.7.189:17667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/themes.php"] [unique_id "aoSA8fcmepr5_nHgLbNnVgAAAiA"] [Tue Aug 18 12:57:37.136089 2026] [security2:error] [pid 67073:tid 67323] [client 20.118.172.148:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/f35.php"] [unique_id "aoSA8fcmepr5_nHgLbNnWwAAAoo"] [Tue Aug 18 12:57:37.146963 2026] [security2:error] [pid 67073:tid 67266] [client 20.226.7.189:17687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/packed.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXQAAAlE"] [Tue Aug 18 12:57:37.166843 2026] [security2:error] [pid 67073:tid 67287] [client 20.226.7.189:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXgAAAmY"] [Tue Aug 18 12:57:37.199132 2026] [security2:error] [pid 66623:tid 66813] [client 20.226.7.189:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-themes.php"] [unique_id "aoSA8dO5rbWdOArH04KTvQAAATk"] [Tue Aug 18 12:57:37.202222 2026] [security2:error] [pid 67073:tid 67219] [client 213.35.127.232:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA8fcmepr5_nHgLbNnXwAAAiI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:37.220833 2026] [security2:error] [pid 67073:tid 67206] [client 20.226.7.189:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/xda.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYAAAAhU"] [Tue Aug 18 12:57:37.240890 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.7.189:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSA8dO5rbWdOArH04KTvgAAATw"] [Tue Aug 18 12:57:37.245781 2026] [security2:error] [pid 67073:tid 67280] [client 158.158.74.177:22743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYgAAAl8"] [Tue Aug 18 12:57:37.248649 2026] [security2:error] [pid 66623:tid 66810] [client 142.111.55.8:16122] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSA8NO5rbWdOArH04KTtgAAATY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 12:57:37.270026 2026] [security2:error] [pid 67073:tid 67260] [client 20.226.7.189:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/15.php"] [unique_id "aoSA8fcmepr5_nHgLbNnYwAAAks"] [Tue Aug 18 12:57:37.292650 2026] [security2:error] [pid 67073:tid 67258] [client 20.119.58.187:12052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css//index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnZAAAAkk"] [Tue Aug 18 12:57:37.294566 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.7.189:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/403.php"] [unique_id "aoSA8dO5rbWdOArH04KTvwAAARQ"] [Tue Aug 18 12:57:37.316552 2026] [security2:error] [pid 67073:tid 67257] [client 20.226.7.189:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/404webshell.php"] [unique_id "aoSA8fcmepr5_nHgLbNnaAAAAkg"] [Tue Aug 18 12:57:37.323329 2026] [security2:error] [pid 67073:tid 67324] [client 40.74.65.169:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSA8fcmepr5_nHgLbNnaQAAAos"] [Tue Aug 18 12:57:37.332126 2026] [security2:error] [pid 67073:tid 67302] [client 20.100.185.105:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/contact_tpl.php"] [unique_id "aoSA8fcmepr5_nHgLbNnagAAAnU"] [Tue Aug 18 12:57:37.334965 2026] [security2:error] [pid 67073:tid 67269] [client 20.119.58.187:11317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/sid3.php"] [unique_id "aoSA8fcmepr5_nHgLbNnawAAAlQ"] [Tue Aug 18 12:57:37.336669 2026] [security2:error] [pid 67073:tid 67264] [client 20.226.7.189:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/666.php"] [unique_id "aoSA8fcmepr5_nHgLbNnbAAAAk8"] [Tue Aug 18 12:57:37.350147 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:37.350613 2026] [authz_core:error] [pid 67073:tid 67171] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:37.357125 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.7.189:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/7.php"] [unique_id "aoSA8fcmepr5_nHgLbNnbgAAAnY"] [Tue Aug 18 12:57:37.379296 2026] [security2:error] [pid 67073:tid 67237] [client 20.226.7.189:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/a7.php"] [unique_id "aoSA8fcmepr5_nHgLbNncAAAAjQ"] [Tue Aug 18 12:57:37.382872 2026] [security2:error] [pid 66623:tid 66811] [client 20.215.241.237:38254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/fling.php"] [unique_id "aoSA8dO5rbWdOArH04KTwQAAATc"] [Tue Aug 18 12:57:37.400860 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.7.189:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/alfadheat.php"] [unique_id "aoSA8fcmepr5_nHgLbNncQAAAlg"] [Tue Aug 18 12:57:37.411518 2026] [security2:error] [pid 67073:tid 67318] [client 40.74.65.169:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/fpwch.php"] [unique_id "aoSA8fcmepr5_nHgLbNncwAAAoU"] [Tue Aug 18 12:57:37.420176 2026] [security2:error] [pid 67073:tid 67255] [client 20.226.7.189:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/apikey/mar.php"] [unique_id "aoSA8fcmepr5_nHgLbNndAAAAkY"] [Tue Aug 18 12:57:37.431122 2026] [security2:error] [pid 67073:tid 67230] [client 68.155.155.199:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/min.php"] [unique_id "aoSA8fcmepr5_nHgLbNndQAAAi0"] [Tue Aug 18 12:57:37.439218 2026] [security2:error] [pid 67073:tid 67305] [client 20.226.7.189:17693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/assetsalfa.php"] [unique_id "aoSA8fcmepr5_nHgLbNndgAAAng"] [Tue Aug 18 12:57:37.463535 2026] [security2:error] [pid 67073:tid 67205] [client 20.226.7.189:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/init.php"] [unique_id "aoSA8fcmepr5_nHgLbNndwAAAhQ"] [Tue Aug 18 12:57:37.482551 2026] [security2:error] [pid 67073:tid 67309] [client 20.226.7.189:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bak.php"] [unique_id "aoSA8fcmepr5_nHgLbNneQAAAnw"] [Tue Aug 18 12:57:37.490922 2026] [security2:error] [pid 67073:tid 67279] [client 74.248.18.37:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/red.php"] [unique_id "aoSA8fcmepr5_nHgLbNnegAAAl4"] [Tue Aug 18 12:57:37.501599 2026] [security2:error] [pid 67073:tid 67249] [client 20.226.7.189:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/bgymj.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfAAAAkA"] [Tue Aug 18 12:57:37.521801 2026] [security2:error] [pid 67073:tid 67300] [client 74.248.18.37:27508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfQAAAnM"] [Tue Aug 18 12:57:37.529193 2026] [security2:error] [pid 67073:tid 67310] [client 132.196.30.78:18753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSA8fcmepr5_nHgLbNnfwAAAn0"] [Tue Aug 18 12:57:37.535141 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.7.189:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/class-t.api.php"] [unique_id "aoSA8fcmepr5_nHgLbNngAAAAj8"] [Tue Aug 18 12:57:37.555497 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.7.189:17680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.7.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/class.php"] [unique_id "aoSA8fcmepr5_nHgLbNngQAAAnA"] [Tue Aug 18 12:57:37.592879 2026] [security2:error] [pid 66623:tid 66884] [client 20.118.172.148:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/gg.php"] [unique_id "aoSA8dO5rbWdOArH04KTxQAAAYA"] [Tue Aug 18 12:57:37.643995 2026] [security2:error] [pid 67073:tid 67265] [client 4.232.151.198:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/db.php"] [unique_id "aoSA8fcmepr5_nHgLbNnhQAAAlA"] [Tue Aug 18 12:57:37.649554 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:37.649818 2026] [authz_core:error] [pid 67073:tid 67095] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:37.679688 2026] [security2:error] [pid 67073:tid 67290] [client 52.173.121.69:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/rymmm.php"] [unique_id "aoSA8fcmepr5_nHgLbNnhwAAAmk"] [Tue Aug 18 12:57:37.688011 2026] [security2:error] [pid 66623:tid 66849] [client 20.119.58.187:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ss.php"] [unique_id "aoSA8dO5rbWdOArH04KTxwAAAV0"] [Tue Aug 18 12:57:37.689828 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css//xc.php"] [unique_id "aoSA8fcmepr5_nHgLbNniQAAAkI"] [Tue Aug 18 12:57:37.882030 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:44257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSA8dO5rbWdOArH04KTzAAAAQ0"] [Tue Aug 18 12:57:37.943641 2026] [security2:error] [pid 66623:tid 66810] [client 142.111.55.8:16122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSA8NO5rbWdOArH04KTtgAAATY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 12:57:37.951997 2026] [security2:error] [pid 67073:tid 67234] [client 20.100.185.105:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSA8fcmepr5_nHgLbNnnwAAAjE"] [Tue Aug 18 12:57:37.960323 2026] [autoindex:error] [pid 66623:tid 66842] [client 158.158.74.177:22736] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:38.046399 2026] [security2:error] [pid 67073:tid 67256] [client 20.119.58.187:12054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images//about.php"] [unique_id "aoSA8vcmepr5_nHgLbNnowAAAkc"] [Tue Aug 18 12:57:38.059682 2026] [security2:error] [pid 67073:tid 67291] [client 20.119.58.187:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/sts.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpAAAAmo"] [Tue Aug 18 12:57:38.085105 2026] [security2:error] [pid 67073:tid 67212] [client 40.74.65.169:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/adminner.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpQAAAhs"] [Tue Aug 18 12:57:38.091057 2026] [security2:error] [pid 67073:tid 67328] [client 40.74.65.169:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSA8vcmepr5_nHgLbNnpwAAAo8"] [Tue Aug 18 12:57:38.091616 2026] [security2:error] [pid 67073:tid 67331] [client 192.141.172.134:64614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqAAAApI"] [Tue Aug 18 12:57:38.091703 2026] [security2:error] [pid 67073:tid 67331] [client 192.141.172.134:64614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqAAAApI"] [Tue Aug 18 12:57:38.109499 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:17968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/lddxs.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqgAAAl8"] [Tue Aug 18 12:57:38.111359 2026] [security2:error] [pid 67073:tid 67292] [client 172.182.200.96:14185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/nwwha.php"] [unique_id "aoSA8vcmepr5_nHgLbNnqwAAAms"] [Tue Aug 18 12:57:38.158654 2026] [security2:error] [pid 67073:tid 67266] [client 74.248.18.37:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/release.php"] [unique_id "aoSA8vcmepr5_nHgLbNnrgAAAlE"] [Tue Aug 18 12:57:38.161310 2026] [autoindex:error] [pid 67073:tid 67308] [client 20.100.169.31:42185] AH01276: Cannot serve directory /home1/lubarbosa/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:38.165355 2026] [security2:error] [pid 66623:tid 66839] [client 158.158.74.177:22736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSA8tO5rbWdOArH04KTzwAAAVM"] [Tue Aug 18 12:57:38.186388 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/class.php"] [unique_id "aoSA8tO5rbWdOArH04KT0AAAARs"] [Tue Aug 18 12:57:38.206798 2026] [security2:error] [pid 66623:tid 66820] [client 40.85.222.29:26889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSA8tO5rbWdOArH04KT0QAAAUA"] [Tue Aug 18 12:57:38.207649 2026] [security2:error] [pid 66623:tid 66892] [client 20.206.73.37:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA8tO5rbWdOArH04KT0gAAAYg"] [Tue Aug 18 12:57:38.217369 2026] [security2:error] [pid 67073:tid 67217] [client 213.35.127.232:56543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA8vcmepr5_nHgLbNnsAAAAiA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:38.242061 2026] [security2:error] [pid 66623:tid 66848] [client 213.202.253.4:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSA8tO5rbWdOArH04KT0wAAAVw"], referer: www.google.com [Tue Aug 18 12:57:38.284014 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSA8tO5rbWdOArH04KT1AAAAVo"] [Tue Aug 18 12:57:38.303786 2026] [security2:error] [pid 67073:tid 67245] [client 68.155.155.199:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/mac.php"] [unique_id "aoSA8vcmepr5_nHgLbNntQAAAjw"] [Tue Aug 18 12:57:38.357727 2026] [security2:error] [pid 67073:tid 67277] [client 20.215.241.237:25301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/zoo1.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuAAAAlw"] [Tue Aug 18 12:57:38.377769 2026] [security2:error] [pid 67073:tid 67224] [client 74.248.18.37:27496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/about.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuQAAAic"] [Tue Aug 18 12:57:38.410888 2026] [security2:error] [pid 66623:tid 66823] [client 20.119.58.187:12484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/crystal//index.php"] [unique_id "aoSA8tO5rbWdOArH04KT1gAAAUM"] [Tue Aug 18 12:57:38.426934 2026] [security2:error] [pid 67073:tid 67303] [client 20.119.58.187:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/shell.php"] [unique_id "aoSA8vcmepr5_nHgLbNnvAAAAnY"] [Tue Aug 18 12:57:38.466136 2026] [security2:error] [pid 66623:tid 66841] [client 20.65.98.162:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/clque.php"] [unique_id "aoSA8tO5rbWdOArH04KT2AAAAVU"] [Tue Aug 18 12:57:38.507911 2026] [security2:error] [pid 67073:tid 67230] [client 40.85.222.29:44241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSA8vcmepr5_nHgLbNnvwAAAi0"] [Tue Aug 18 12:57:38.527013 2026] [security2:error] [pid 67073:tid 67240] [client 52.173.121.69:24984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zjggu.php"] [unique_id "aoSA8vcmepr5_nHgLbNnygAAAjc"] [Tue Aug 18 12:57:38.553806 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:38.554081 2026] [authz_core:error] [pid 67073:tid 67166] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:38.576523 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:58262] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.amigosdoronron.com.br"] [uri "/1.php"] [unique_id "aoSA8tO5rbWdOArH04KT2QAAAWs"] [Tue Aug 18 12:57:38.576614 2026] [security2:error] [pid 66623:tid 66863] [client 20.203.183.135:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/1.php"] [unique_id "aoSA8tO5rbWdOArH04KT2QAAAWs"] [Tue Aug 18 12:57:38.586955 2026] [security2:error] [pid 67073:tid 67281] [client 20.100.169.31:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNnuwAAAmA"] [Tue Aug 18 12:57:38.652072 2026] [security2:error] [pid 67073:tid 67279] [client 132.196.30.78:21872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/ww5.php"] [unique_id "aoSA8vcmepr5_nHgLbNnzgAAAl4"] [Tue Aug 18 12:57:38.691443 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/flower.php"] [unique_id "aoSA8tO5rbWdOArH04KT2gAAAUs"] [Tue Aug 18 12:57:38.738123 2026] [security2:error] [pid 67073:tid 67237] [client 20.100.185.105:29232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNnzAAAAjQ"] [Tue Aug 18 12:57:38.766757 2026] [security2:error] [pid 67073:tid 67213] [client 20.119.58.187:12498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp//index.php"] [unique_id "aoSA8vcmepr5_nHgLbNn1QAAAhw"] [Tue Aug 18 12:57:38.767956 2026] [security2:error] [pid 67073:tid 67310] [client 40.74.65.169:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.barretoveiculos.com"] [uri "/abcd.php"] [unique_id "aoSA8vcmepr5_nHgLbNn1gAAAn0"] [Tue Aug 18 12:57:38.777071 2026] [security2:error] [pid 67073:tid 67320] [client 20.119.58.187:11273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/setup-config.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2AAAAoc"] [Tue Aug 18 12:57:38.789359 2026] [security2:error] [pid 67073:tid 67248] [client 40.85.222.29:26880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2QAAAj8"] [Tue Aug 18 12:57:38.859985 2026] [security2:error] [pid 67073:tid 67309] [client 74.248.18.37:31823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/reop3.php"] [unique_id "aoSA8vcmepr5_nHgLbNn3QAAAnw"] [Tue Aug 18 12:57:38.913671 2026] [security2:error] [pid 67073:tid 67299] [client 52.173.121.69:17944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/dlvqo.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4AAAAnI"] [Tue Aug 18 12:57:38.917755 2026] [security2:error] [pid 67073:tid 67290] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4QAAAmk"] [Tue Aug 18 12:57:38.918860 2026] [authz_core:error] [pid 67073:tid 67146] [remote 57.141.22.25:57342] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:38.919231 2026] [authz_core:error] [pid 67073:tid 67146] [remote 57.141.22.25:57342] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:38.923232 2026] [security2:error] [pid 67073:tid 67261] [client 4.232.151.198:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/file.php"] [unique_id "aoSA8vcmepr5_nHgLbNn4gAAAkw"] [Tue Aug 18 12:57:38.963326 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.156.252:18403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "email.domcoworking.com.br"] [uri "/abcd.php"] [unique_id "aoSA8vcmepr5_nHgLbNn6QAAAlc"] [Tue Aug 18 12:57:39.009221 2026] [security2:error] [pid 67073:tid 67330] [client 20.215.241.237:38235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/zoo2.php"] [unique_id "aoSA8_cmepr5_nHgLbNn9gAAApE"] [Tue Aug 18 12:57:39.023587 2026] [security2:error] [pid 67073:tid 67236] [client 158.158.74.177:26167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSA8vcmepr5_nHgLbNn2wAAAjM"] [Tue Aug 18 12:57:39.023593 2026] [security2:error] [pid 66623:tid 66830] [client 74.248.18.37:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSA89O5rbWdOArH04KT2wAAAUo"] [Tue Aug 18 12:57:39.066128 2026] [security2:error] [pid 67073:tid 67216] [client 20.250.13.23:47033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/2.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-AAAAh8"] [Tue Aug 18 12:57:39.095874 2026] [security2:error] [pid 67073:tid 67252] [client 40.85.222.29:44236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-QAAAkM"] [Tue Aug 18 12:57:39.124396 2026] [security2:error] [pid 67073:tid 67231] [client 20.119.58.187:12487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/user.php"] [unique_id "aoSA8_cmepr5_nHgLbNn-wAAAi4"] [Tue Aug 18 12:57:39.129434 2026] [security2:error] [pid 67073:tid 67233] [client 20.119.58.187:11284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/t.php"] [unique_id "aoSA8_cmepr5_nHgLbNn_AAAAjA"] [Tue Aug 18 12:57:39.195370 2026] [security2:error] [pid 67073:tid 67226] [client 40.74.65.169:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/simple.php"] [unique_id "aoSA8_cmepr5_nHgLbNoAAAAAik"] [Tue Aug 18 12:57:39.209609 2026] [security2:error] [pid 67073:tid 67246] [client 68.155.155.199:13332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/nc4.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBAAAAj0"] [Tue Aug 18 12:57:39.219337 2026] [security2:error] [pid 66623:tid 66774] [client 178.156.184.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlyclimatizacao.com.br"] [uri "/index.php"] [unique_id "aoSA8dO5rbWdOArH04KTxgABEgw"], referer: https://jlyclimatizacao.com.br/ [Tue Aug 18 12:57:39.232600 2026] [security2:error] [pid 67073:tid 67312] [client 213.35.127.232:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBgAAAn8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:39.264021 2026] [security2:error] [pid 67073:tid 67219] [client 20.118.172.148:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/motu.php"] [unique_id "aoSA8_cmepr5_nHgLbNoBwAAAiI"] [Tue Aug 18 12:57:39.308354 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:16471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/pkmoj.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCAAAAhs"] [Tue Aug 18 12:57:39.332863 2026] [security2:error] [pid 67073:tid 67315] [client 103.184.169.37:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCgAAAoI"] [Tue Aug 18 12:57:39.332997 2026] [security2:error] [pid 67073:tid 67315] [client 103.184.169.37:42195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoCgAAAoI"] [Tue Aug 18 12:57:39.363714 2026] [security2:error] [pid 67073:tid 67285] [client 20.100.185.105:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/Auth.php"] [unique_id "aoSA8_cmepr5_nHgLbNoDAAAAmQ"] [Tue Aug 18 12:57:39.411434 2026] [security2:error] [pid 67073:tid 67289] [client 40.85.222.29:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSA8_cmepr5_nHgLbNoDwAAAmg"] [Tue Aug 18 12:57:39.462276 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:25606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEAAAAhk"] [Tue Aug 18 12:57:39.482923 2026] [security2:error] [pid 67073:tid 67280] [client 20.119.58.187:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEQAAAl8"] [Tue Aug 18 12:57:39.518951 2026] [security2:error] [pid 67073:tid 67292] [client 20.119.58.187:11321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/up.php"] [unique_id "aoSA8_cmepr5_nHgLbNoEwAAAms"] [Tue Aug 18 12:57:39.525451 2026] [security2:error] [pid 67073:tid 67243] [client 103.120.71.157:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFAAAAjo"] [Tue Aug 18 12:57:39.525550 2026] [security2:error] [pid 67073:tid 67243] [client 103.120.71.157:13277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFAAAAjo"] [Tue Aug 18 12:57:39.563952 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:24950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSA8_cmepr5_nHgLbNoFQAAAlo"] [Tue Aug 18 12:57:39.597593 2026] [security2:error] [pid 67073:tid 67254] [client 20.100.169.31:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bthil.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGAAAAkU"] [Tue Aug 18 12:57:39.600388 2026] [security2:error] [pid 67073:tid 67291] [client 74.248.18.37:20516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/robots.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGQAAAmo"] [Tue Aug 18 12:57:39.623333 2026] [security2:error] [pid 67073:tid 67318] [client 172.202.39.151:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp.php"] [unique_id "aoSA8_cmepr5_nHgLbNoGwAAAoU"] [Tue Aug 18 12:57:39.651931 2026] [security2:error] [pid 67073:tid 67227] [client 74.248.18.37:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA8_cmepr5_nHgLbNoHAAAAio"] [Tue Aug 18 12:57:39.653793 2026] [security2:error] [pid 67073:tid 67232] [client 52.173.121.69:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/kopyw.php"] [unique_id "aoSA8_cmepr5_nHgLbNoHgAAAi8"] [Tue Aug 18 12:57:39.666927 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.183.135:60866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/coffee.php"] [unique_id "aoSA89O5rbWdOArH04KT3wAAAVg"] [Tue Aug 18 12:57:39.698001 2026] [security2:error] [pid 67073:tid 67217] [client 158.158.74.177:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSA8_cmepr5_nHgLbNoIAAAAiA"] [Tue Aug 18 12:57:39.702151 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSA89O5rbWdOArH04KT4AAAAWA"] [Tue Aug 18 12:57:39.741618 2026] [security2:error] [pid 67073:tid 67247] [client 20.215.241.237:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/org.php"] [unique_id "aoSA8_cmepr5_nHgLbNoIwAAAj4"] [Tue Aug 18 12:57:39.744378 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/404.php"] [unique_id "aoSA89O5rbWdOArH04KT4gAAAYk"] [Tue Aug 18 12:57:39.745312 2026] [security2:error] [pid 67073:tid 67253] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/av.php"] [unique_id "aoSA8_cmepr5_nHgLbNoJAAAAkQ"] [Tue Aug 18 12:57:39.759205 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:39.759468 2026] [authz_core:error] [pid 67073:tid 67189] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:39.819494 2026] [security2:error] [pid 67073:tid 67249] [client 68.155.154.236:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA8_cmepr5_nHgLbNoLgAAAkA"] [Tue Aug 18 12:57:39.847346 2026] [security2:error] [pid 66623:tid 66837] [client 20.119.58.187:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/functions.php"] [unique_id "aoSA89O5rbWdOArH04KT5AAAAVE"] [Tue Aug 18 12:57:39.871618 2026] [security2:error] [pid 67073:tid 67208] [client 20.119.58.187:11464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ultra.php"] [unique_id "aoSA8_cmepr5_nHgLbNoMAAAAhc"] [Tue Aug 18 12:57:39.989600 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.185.105:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/axx.php"] [unique_id "aoSA8_cmepr5_nHgLbNoNAAAApA"] [Tue Aug 18 12:57:40.013651 2026] [security2:error] [pid 67073:tid 67251] [client 52.173.121.69:16452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zznmg.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoNgAAAkI"] [Tue Aug 18 12:57:40.017610 2026] [security2:error] [pid 67073:tid 67259] [client 40.85.222.29:26895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoOQAAAko"] [Tue Aug 18 12:57:40.058270 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:40.058543 2026] [authz_core:error] [pid 67073:tid 67118] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:40.107788 2026] [security2:error] [pid 67073:tid 67313] [client 132.196.30.78:21878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/2.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoPAAAAoA"] [Tue Aug 18 12:57:40.115539 2026] [security2:error] [pid 67073:tid 67216] [client 20.118.172.148:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lite.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoPwAAAh8"] [Tue Aug 18 12:57:40.138158 2026] [security2:error] [pid 67073:tid 67319] [client 68.155.155.199:4409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/as.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoQQAAAoY"] [Tue Aug 18 12:57:40.173791 2026] [security2:error] [pid 66623:tid 66773] [client 20.100.169.31:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/default.php"] [unique_id "aoSA9NO5rbWdOArH04KT5wAAARE"] [Tue Aug 18 12:57:40.198270 2026] [security2:error] [pid 67073:tid 67330] [client 20.119.58.187:12528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cron.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoRAAAApE"] [Tue Aug 18 12:57:40.209759 2026] [security2:error] [pid 67073:tid 67309] [client 4.232.151.198:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSAAAAnw"] [Tue Aug 18 12:57:40.214386 2026] [security2:error] [pid 66623:tid 66772] [client 86.120.159.145:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9NO5rbWdOArH04KT6AAAARA"] [Tue Aug 18 12:57:40.214471 2026] [security2:error] [pid 66623:tid 66772] [client 86.120.159.145:57734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9NO5rbWdOArH04KT6AAAARA"] [Tue Aug 18 12:57:40.226362 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:11472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/vv.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSQAAAoQ"] [Tue Aug 18 12:57:40.238492 2026] [security2:error] [pid 67073:tid 67207] [client 40.74.65.169:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/chosen.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoSwAAAhY"] [Tue Aug 18 12:57:40.242916 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTAAAAiQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:40.257464 2026] [security2:error] [pid 66623:tid 66882] [client 20.215.241.237:25314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/imageskir.php"] [unique_id "aoSA9NO5rbWdOArH04KT6QAAAX4"] [Tue Aug 18 12:57:40.260991 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:20542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/root.php"] [unique_id "aoSA9NO5rbWdOArH04KT6gAAASM"] [Tue Aug 18 12:57:40.282005 2026] [security2:error] [pid 67073:tid 67238] [client 74.248.18.37:3653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/content.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTgAAAjU"] [Tue Aug 18 12:57:40.312119 2026] [security2:error] [pid 67073:tid 67326] [client 40.85.222.29:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoTwAAAo0"] [Tue Aug 18 12:57:40.362363 2026] [authz_core:error] [pid 67073:tid 67137] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:40.362734 2026] [authz_core:error] [pid 67073:tid 67137] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:40.387205 2026] [security2:error] [pid 67073:tid 67212] [client 52.173.121.69:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/bhfnd.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoVQAAAhs"] [Tue Aug 18 12:57:40.434712 2026] [security2:error] [pid 67073:tid 67267] [client 158.158.74.177:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoWgAAAlI"] [Tue Aug 18 12:57:40.456065 2026] [security2:error] [pid 67073:tid 67308] [client 20.118.172.148:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lock360.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoWwAAAns"] [Tue Aug 18 12:57:40.510539 2026] [security2:error] [pid 66623:tid 66870] [client 172.202.39.151:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/function/function.php"] [unique_id "aoSA9NO5rbWdOArH04KT6wAAAXI"] [Tue Aug 18 12:57:40.551796 2026] [security2:error] [pid 67073:tid 67266] [client 20.119.58.187:12095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoXwAAAlE"] [Tue Aug 18 12:57:40.616148 2026] [security2:error] [pid 67073:tid 67211] [client 20.100.185.105:43387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/disagraeed.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoYgAAAho"] [Tue Aug 18 12:57:40.650107 2026] [security2:error] [pid 67073:tid 67245] [client 20.119.58.187:11263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/V5.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoYwAAAjw"] [Tue Aug 18 12:57:40.655049 2026] [security2:error] [pid 67073:tid 67224] [client 40.85.222.29:44225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZAAAAic"] [Tue Aug 18 12:57:40.711142 2026] [security2:error] [pid 67073:tid 67303] [client 68.155.155.199:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/k.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZgAAAnY"] [Tue Aug 18 12:57:40.726199 2026] [security2:error] [pid 67073:tid 67324] [client 52.173.121.69:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/qfvqu.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoZwAAAos"] [Tue Aug 18 12:57:40.726689 2026] [security2:error] [pid 66623:tid 66869] [client 216.73.160.243:49363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hotelvipunai.com.br"] [uri "/wp-login.php"] [unique_id "aoSA9NO5rbWdOArH04KT8AAAAXE"] [Tue Aug 18 12:57:40.738863 2026] [autoindex:error] [pid 66623:tid 66776] [client 83.171.202.64:29800] AH01276: Cannot serve directory /home3/qs3e8j7ytlrlm8h9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:40.751129 2026] [security2:error] [pid 67073:tid 67220] [client 20.215.241.237:20649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/indexo.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoaQAAAiM"] [Tue Aug 18 12:57:40.802242 2026] [security2:error] [pid 67073:tid 67323] [client 132.196.30.78:21839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoawAAAoo"] [Tue Aug 18 12:57:40.838700 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/htaccess.php"] [unique_id "aoSA9NO5rbWdOArH04KT8gAAAXg"] [Tue Aug 18 12:57:40.918674 2026] [security2:error] [pid 67073:tid 67274] [client 74.248.18.37:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/index.php"] [unique_id "aoSA9Pcmepr5_nHgLbNobgAAAlk"] [Tue Aug 18 12:57:40.924433 2026] [security2:error] [pid 66623:tid 66853] [client 20.119.58.187:12497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cookie.php"] [unique_id "aoSA9NO5rbWdOArH04KT8wAAAWE"] [Tue Aug 18 12:57:40.924833 2026] [security2:error] [pid 67073:tid 67237] [client 20.206.73.37:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocAAAAjQ"] [Tue Aug 18 12:57:40.949136 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.169.31:41187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/x.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocQAAAnM"] [Tue Aug 18 12:57:40.949437 2026] [security2:error] [pid 67073:tid 67311] [client 20.48.236.86:32833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/images.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocgAAAn4"] [Tue Aug 18 12:57:40.950956 2026] [security2:error] [pid 67073:tid 67208] [client 40.85.222.29:44237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSA9Pcmepr5_nHgLbNocwAAAhc"] [Tue Aug 18 12:57:40.955714 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:20511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/rrr.php"] [unique_id "aoSA9NO5rbWdOArH04KT9AAAAYI"] [Tue Aug 18 12:57:40.963942 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:40.964194 2026] [authz_core:error] [pid 67073:tid 67111] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:41.000920 2026] [security2:error] [pid 67073:tid 67279] [client 20.119.58.187:11290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-user.php"] [unique_id "aoSA9Pcmepr5_nHgLbNoeQAAAl4"] [Tue Aug 18 12:57:41.030749 2026] [security2:error] [pid 67073:tid 67261] [client 20.118.133.132:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/admin.php"] [unique_id "aoSA9fcmepr5_nHgLbNofAAAAkw"] [Tue Aug 18 12:57:41.032581 2026] [security2:error] [pid 67073:tid 67248] [client 20.226.56.190:2506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/wb.php"] [unique_id "aoSA9fcmepr5_nHgLbNofgAAAj8"] [Tue Aug 18 12:57:41.058556 2026] [security2:error] [pid 67073:tid 67284] [client 5.31.227.224:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNogAAAAmM"] [Tue Aug 18 12:57:41.064921 2026] [security2:error] [pid 67073:tid 67284] [client 5.31.227.224:59013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNogAAAAmM"] [Tue Aug 18 12:57:41.095652 2026] [security2:error] [pid 67073:tid 67242] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/images.php"] [unique_id "aoSA9fcmepr5_nHgLbNoggAAAjk"] [Tue Aug 18 12:57:41.106762 2026] [security2:error] [pid 67073:tid 67222] [client 68.221.73.131:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.velasmagica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA9fcmepr5_nHgLbNogwAAAiU"] [Tue Aug 18 12:57:41.128346 2026] [security2:error] [pid 67073:tid 67317] [client 52.173.121.69:17976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/oivcl.php"] [unique_id "aoSA9fcmepr5_nHgLbNohAAAAoQ"] [Tue Aug 18 12:57:41.151686 2026] [security2:error] [pid 67073:tid 67239] [client 20.100.169.31:42184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/i.php"] [unique_id "aoSA9fcmepr5_nHgLbNohgAAAjY"] [Tue Aug 18 12:57:41.241120 2026] [security2:error] [pid 67073:tid 67205] [client 20.100.185.105:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/e69ovfsr.php"] [unique_id "aoSA9fcmepr5_nHgLbNoiQAAAhQ"] [Tue Aug 18 12:57:41.255109 2026] [security2:error] [pid 67073:tid 67249] [client 213.35.127.232:57179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA9fcmepr5_nHgLbNoigAAAkA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:41.287648 2026] [security2:error] [pid 67073:tid 67332] [client 40.85.222.29:44269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSA9fcmepr5_nHgLbNojQAAApM"] [Tue Aug 18 12:57:41.297392 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xleet.php"] [unique_id "aoSA9dO5rbWdOArH04KT-QAAATQ"] [Tue Aug 18 12:57:41.348264 2026] [security2:error] [pid 67073:tid 67326] [client 20.215.241.237:55367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSA9fcmepr5_nHgLbNojwAAAo0"] [Tue Aug 18 12:57:41.353588 2026] [security2:error] [pid 67073:tid 67228] [client 40.74.65.169:27791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/als.php"] [unique_id "aoSA9fcmepr5_nHgLbNokAAAAis"] [Tue Aug 18 12:57:41.354089 2026] [security2:error] [pid 67073:tid 67246] [client 20.119.58.187:11235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-blog.php"] [unique_id "aoSA9fcmepr5_nHgLbNokQAAAj0"] [Tue Aug 18 12:57:41.406183 2026] [autoindex:error] [pid 66623:tid 66797] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:41.486656 2026] [security2:error] [pid 66623:tid 66811] [client 149.34.210.141:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9dO5rbWdOArH04KT_AAAATc"] [Tue Aug 18 12:57:41.490144 2026] [security2:error] [pid 67073:tid 67236] [client 172.182.200.96:14153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/opsqt.php"] [unique_id "aoSA9fcmepr5_nHgLbNolgAAAjM"] [Tue Aug 18 12:57:41.506633 2026] [security2:error] [pid 67073:tid 67225] [client 52.173.121.69:17959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zugvi.php"] [unique_id "aoSA9fcmepr5_nHgLbNomQAAAig"] [Tue Aug 18 12:57:41.526753 2026] [security2:error] [pid 66623:tid 66868] [client 4.232.151.198:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/images/wso.php"] [unique_id "aoSA9dO5rbWdOArH04KT_QAAAXA"] [Tue Aug 18 12:57:41.567953 2026] [security2:error] [pid 67073:tid 67214] [client 157.20.138.62:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNomwAAAh0"] [Tue Aug 18 12:57:41.568062 2026] [security2:error] [pid 67073:tid 67214] [client 157.20.138.62:65455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNomwAAAh0"] [Tue Aug 18 12:57:41.569410 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:41.569657 2026] [authz_core:error] [pid 67073:tid 67117] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:41.572291 2026] [security2:error] [pid 67073:tid 67272] [client 20.118.172.148:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSA9fcmepr5_nHgLbNonAAAAlc"] [Tue Aug 18 12:57:41.602304 2026] [security2:error] [pid 67073:tid 67258] [client 40.85.222.29:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSA9fcmepr5_nHgLbNongAAAkk"] [Tue Aug 18 12:57:41.614449 2026] [security2:error] [pid 67073:tid 67287] [client 74.248.18.37:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/s.php"] [unique_id "aoSA9fcmepr5_nHgLbNonwAAAmY"] [Tue Aug 18 12:57:41.626600 2026] [security2:error] [pid 67073:tid 67210] [client 104.209.144.33:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSA9fcmepr5_nHgLbNooAAAAhk"] [Tue Aug 18 12:57:41.643580 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.18.37:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSA9fcmepr5_nHgLbNooQAAAlU"] [Tue Aug 18 12:57:41.656948 2026] [security2:error] [pid 67073:tid 67294] [client 20.226.56.190:19384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/xn.php"] [unique_id "aoSA9fcmepr5_nHgLbNoowAAAm0"] [Tue Aug 18 12:57:41.661574 2026] [security2:error] [pid 67073:tid 67267] [client 20.119.58.187:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/spip.php"] [unique_id "aoSA9fcmepr5_nHgLbNopAAAAlI"] [Tue Aug 18 12:57:41.699689 2026] [autoindex:error] [pid 66623:tid 66849] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:41.736454 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.56.190:17867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/47.php"] [unique_id "aoSA9dO5rbWdOArH04KT_wAAAXc"] [Tue Aug 18 12:57:41.743315 2026] [security2:error] [pid 67073:tid 67302] [client 20.250.13.23:38944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSA9fcmepr5_nHgLbNopgAAAnU"] [Tue Aug 18 12:57:41.754059 2026] [security2:error] [pid 66623:tid 66811] [client 149.34.210.141:58483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9dO5rbWdOArH04KT_AAAATc"] [Tue Aug 18 12:57:41.771643 2026] [security2:error] [pid 67073:tid 67209] [client 20.119.58.187:11325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp.php"] [unique_id "aoSA9fcmepr5_nHgLbNopwAAAhg"] [Tue Aug 18 12:57:41.789859 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqQAAAjg"] [Tue Aug 18 12:57:41.793705 2026] [security2:error] [pid 67073:tid 67241] [client 37.40.227.74:56749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqQAAAjg"] [Tue Aug 18 12:57:41.821746 2026] [security2:error] [pid 67073:tid 67273] [client 172.202.39.151:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqgAAAlg"] [Tue Aug 18 12:57:41.866550 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:41.866865 2026] [authz_core:error] [pid 67073:tid 67104] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:41.884573 2026] [security2:error] [pid 67073:tid 67220] [client 52.173.121.69:16463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wsrer.php"] [unique_id "aoSA9fcmepr5_nHgLbNorwAAAiM"] [Tue Aug 18 12:57:41.898513 2026] [security2:error] [pid 67073:tid 67324] [client 157.90.155.240:16348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9fcmepr5_nHgLbNoqwAAAos"], referer: http://www.idealquimica.com [Tue Aug 18 12:57:41.899534 2026] [security2:error] [pid 67073:tid 67266] [client 20.100.185.105:43346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSA9fcmepr5_nHgLbNosAAAAlE"] [Tue Aug 18 12:57:41.909922 2026] [autoindex:error] [pid 66623:tid 66865] [client 129.211.229.121:43178] AH01276: Cannot serve directory /home4/patiojardinsma/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:41.925812 2026] [security2:error] [pid 66623:tid 66769] [client 40.85.222.29:26919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA9dO5rbWdOArH04KUAwAAAQ0"] [Tue Aug 18 12:57:41.940623 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:7638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA9dO5rbWdOArH04KUBAAAAQw"] [Tue Aug 18 12:57:42.014453 2026] [security2:error] [pid 67073:tid 67274] [client 68.155.155.199:10396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoswAAAlk"] [Tue Aug 18 12:57:42.019701 2026] [security2:error] [pid 67073:tid 67232] [client 20.119.58.187:11841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/22.php"] [unique_id "aoSA9vcmepr5_nHgLbNotAAAAi8"] [Tue Aug 18 12:57:42.081303 2026] [security2:error] [pid 67073:tid 67293] [client 158.158.34.183:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSA9vcmepr5_nHgLbNotwAAAmw"] [Tue Aug 18 12:57:42.090217 2026] [autoindex:error] [pid 67073:tid 67211] [client 20.100.169.31:37680] AH01276: Cannot serve directory /home1/lubarbosa/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:42.094507 2026] [security2:error] [pid 67073:tid 67215] [client 45.92.229.99:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSA9vcmepr5_nHgLbNouAAAAh4"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:57:42.102801 2026] [security2:error] [pid 67073:tid 67230] [client 114.119.137.122:32443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.advocaciasc.com"] [uri "/wp-content/uploads/2021/04/cartao-de-credito-02.jpg"] [unique_id "aoSA9vcmepr5_nHgLbNouQAAAi0"], referer: https://www.advocaciasc.com/direito-bancario-cartao-de-credito/ [Tue Aug 18 12:57:42.119438 2026] [security2:error] [pid 67073:tid 67320] [client 40.74.65.169:26750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/nox.php"] [unique_id "aoSA9vcmepr5_nHgLbNougAAAoc"] [Tue Aug 18 12:57:42.123081 2026] [security2:error] [pid 67073:tid 67276] [client 20.119.58.187:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/worksec.php"] [unique_id "aoSA9vcmepr5_nHgLbNouwAAAls"] [Tue Aug 18 12:57:42.134030 2026] [security2:error] [pid 67073:tid 67265] [client 68.155.154.236:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA9vcmepr5_nHgLbNovQAAAlA"] [Tue Aug 18 12:57:42.187243 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/index/function.php"] [unique_id "aoSA9tO5rbWdOArH04KUBwAAAQ8"] [Tue Aug 18 12:57:42.195934 2026] [security2:error] [pid 66623:tid 66810] [client 4.232.151.198:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSA9tO5rbWdOArH04KUCAAAATY"] [Tue Aug 18 12:57:42.211383 2026] [security2:error] [pid 67073:tid 67154] [remote 84.205.178.135:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSA9vcmepr5_nHgLbNowAACRE4"] [Tue Aug 18 12:57:42.213132 2026] [security2:error] [pid 67073:tid 67257] [client 40.85.222.29:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSA9vcmepr5_nHgLbNowQAAAkg"] [Tue Aug 18 12:57:42.218261 2026] [security2:error] [pid 66623:tid 66792] [client 20.215.241.237:25298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSA9tO5rbWdOArH04KUCgAAASQ"] [Tue Aug 18 12:57:42.237150 2026] [security2:error] [pid 66623:tid 66840] [client 20.118.172.148:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSA9tO5rbWdOArH04KUDAAAAVQ"] [Tue Aug 18 12:57:42.268390 2026] [security2:error] [pid 66623:tid 66795] [client 213.35.127.232:57399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA9tO5rbWdOArH04KUDQAAASc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:42.271848 2026] [security2:error] [pid 67073:tid 67322] [client 52.173.121.69:25007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/ucpfr.php"] [unique_id "aoSA9vcmepr5_nHgLbNowwAAAok"] [Tue Aug 18 12:57:42.274901 2026] [security2:error] [pid 67073:tid 67311] [client 74.248.18.37:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxAAAAn4"] [Tue Aug 18 12:57:42.277310 2026] [autoindex:error] [pid 66623:tid 66846] [client 158.158.74.177:16558] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:42.296106 2026] [security2:error] [pid 67073:tid 67231] [client 20.100.169.31:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxQAAAi4"] [Tue Aug 18 12:57:42.299455 2026] [security2:error] [pid 66623:tid 66841] [client 20.48.236.86:36121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/admin.php"] [unique_id "aoSA9tO5rbWdOArH04KUDgAAAVU"] [Tue Aug 18 12:57:42.303437 2026] [security2:error] [pid 67073:tid 67310] [client 74.248.18.37:20526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/s93.php"] [unique_id "aoSA9vcmepr5_nHgLbNoxgAAAn0"] [Tue Aug 18 12:57:42.379070 2026] [security2:error] [pid 67073:tid 67319] [client 20.119.58.187:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/room.php"] [unique_id "aoSA9vcmepr5_nHgLbNoyAAAAoY"] [Tue Aug 18 12:57:42.393731 2026] [security2:error] [pid 66623:tid 66848] [client 132.196.30.78:21930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/atomlib.php"] [unique_id "aoSA9tO5rbWdOArH04KUEAAAAVw"] [Tue Aug 18 12:57:42.438820 2026] [security2:error] [pid 67073:tid 67318] [client 178.153.171.161:59476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9vcmepr5_nHgLbNoygAAAoU"] [Tue Aug 18 12:57:42.438926 2026] [security2:error] [pid 67073:tid 67318] [client 178.153.171.161:59476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9vcmepr5_nHgLbNoygAAAoU"] [Tue Aug 18 12:57:42.475111 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-themes.php"] [unique_id "aoSA9tO5rbWdOArH04KUEQAAAYM"] [Tue Aug 18 12:57:42.483075 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:16558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSA9tO5rbWdOArH04KUEgAAAS4"] [Tue Aug 18 12:57:42.511998 2026] [security2:error] [pid 66623:tid 66742] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9tO5rbWdOArH04KUFAABQGk"] [Tue Aug 18 12:57:42.512140 2026] [security2:error] [pid 66623:tid 66820] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9tO5rbWdOArH04KUFAABQGk"] [Tue Aug 18 12:57:42.533240 2026] [security2:error] [pid 66623:tid 66858] [client 40.85.222.29:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSA9tO5rbWdOArH04KUFQAAAWY"] [Tue Aug 18 12:57:42.558616 2026] [security2:error] [pid 67073:tid 67250] [client 79.127.164.8:45456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/old.bak"] [unique_id "aoSA9vcmepr5_nHgLbNo1AAAAkE"], referer: https://medihub.com.br/old.bak [Tue Aug 18 12:57:42.577027 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.185.105:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cd.php"] [unique_id "aoSA9vcmepr5_nHgLbNo1wAAAjA"] [Tue Aug 18 12:57:42.657613 2026] [security2:error] [pid 67073:tid 67272] [client 68.155.155.199:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/system_log.php"] [unique_id "aoSA9vcmepr5_nHgLbNo3AAAAlc"] [Tue Aug 18 12:57:42.686372 2026] [security2:error] [pid 67073:tid 67222] [client 157.90.155.240:1298] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNo0gAAAiU"], referer: http://www.idealquimica.com [Tue Aug 18 12:57:42.744785 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:12483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/disagreed.php"] [unique_id "aoSA9tO5rbWdOArH04KUGQAAAWA"] [Tue Aug 18 12:57:42.746912 2026] [security2:error] [pid 67073:tid 67303] [client 20.226.56.190:28226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/payout.php"] [unique_id "aoSA9vcmepr5_nHgLbNo5AAAAnY"] [Tue Aug 18 12:57:42.761487 2026] [security2:error] [pid 67073:tid 67252] [client 167.235.143.113:5590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSA9vcmepr5_nHgLbNoywAAAkM"], referer: https://www.idealquimica.com [Tue Aug 18 12:57:42.777226 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:42.777494 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:42.829343 2026] [security2:error] [pid 67073:tid 67315] [client 4.232.151.198:24955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/info.php"] [unique_id "aoSA9vcmepr5_nHgLbNo6QAAAoI"] [Tue Aug 18 12:57:42.835167 2026] [security2:error] [pid 66623:tid 66850] [client 40.85.222.29:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSA9tO5rbWdOArH04KUHAAAAV4"] [Tue Aug 18 12:57:42.836312 2026] [security2:error] [pid 67073:tid 67206] [client 20.119.58.187:11471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-signin.php"] [unique_id "aoSA9vcmepr5_nHgLbNo6wAAAhU"] [Tue Aug 18 12:57:42.870091 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.172.148:54899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.alf.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7AAAAmI"] [Tue Aug 18 12:57:42.896605 2026] [security2:error] [pid 66623:tid 66805] [client 20.215.241.237:54696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/.admin.php"] [unique_id "aoSA9tO5rbWdOArH04KUHQAAATE"] [Tue Aug 18 12:57:42.904499 2026] [security2:error] [pid 67073:tid 67305] [client 40.74.65.169:11229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file59.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7gAAAng"] [Tue Aug 18 12:57:42.919795 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA9vcmepr5_nHgLbNo7wAAAms"] [Tue Aug 18 12:57:42.943666 2026] [security2:error] [pid 67073:tid 67263] [client 52.173.121.69:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/yxijx.php"] [unique_id "aoSA9vcmepr5_nHgLbNo8AAAAk4"] [Tue Aug 18 12:57:42.953031 2026] [security2:error] [pid 67073:tid 67243] [client 74.248.18.37:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/server.php"] [unique_id "aoSA9vcmepr5_nHgLbNo8QAAAjo"] [Tue Aug 18 12:57:43.079753 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:43.080203 2026] [authz_core:error] [pid 67073:tid 67085] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:43.104441 2026] [security2:error] [pid 66623:tid 66775] [client 20.119.58.187:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSA99O5rbWdOArH04KUIAAAARM"] [Tue Aug 18 12:57:43.109823 2026] [security2:error] [pid 67073:tid 67322] [client 40.85.222.29:44767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_AAAAok"] [Tue Aug 18 12:57:43.189571 2026] [security2:error] [pid 67073:tid 67251] [client 20.119.58.187:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_gAAAkI"] [Tue Aug 18 12:57:43.199084 2026] [security2:error] [pid 67073:tid 67300] [client 20.100.185.105:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dropdown.php"] [unique_id "aoSA9_cmepr5_nHgLbNo_wAAAnM"] [Tue Aug 18 12:57:43.237396 2026] [security2:error] [pid 67073:tid 67310] [client 172.182.200.96:14196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA9_cmepr5_nHgLbNpAgAAAn0"] [Tue Aug 18 12:57:43.242027 2026] [security2:error] [pid 67073:tid 67314] [client 20.118.172.148:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBAAAAoE"] [Tue Aug 18 12:57:43.281861 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA99O5rbWdOArH04KUIgAAAX4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:43.301083 2026] [security2:error] [pid 66623:tid 66870] [client 20.48.236.86:2118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/222.php"] [unique_id "aoSA99O5rbWdOArH04KUIwAAAXI"] [Tue Aug 18 12:57:43.310813 2026] [security2:error] [pid 67073:tid 67247] [client 132.196.30.78:21757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/rip.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBQAAAj4"] [Tue Aug 18 12:57:43.361459 2026] [security2:error] [pid 67073:tid 67281] [client 158.158.34.183:31663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSA9_cmepr5_nHgLbNpBwAAAmA"] [Tue Aug 18 12:57:43.378095 2026] [security2:error] [pid 67073:tid 67240] [client 20.100.169.31:42200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpCQAAAjc"] [Tue Aug 18 12:57:43.378833 2026] [authz_core:error] [pid 67073:tid 67185] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:43.379096 2026] [authz_core:error] [pid 67073:tid 67185] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:43.385819 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:26906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSA99O5rbWdOArH04KUJAAAAT0"] [Tue Aug 18 12:57:43.472526 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDQAAAkU"] [Tue Aug 18 12:57:43.472695 2026] [security2:error] [pid 67073:tid 67254] [client 85.154.68.202:54921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDQAAAkU"] [Tue Aug 18 12:57:43.480256 2026] [security2:error] [pid 67073:tid 67239] [client 4.232.151.198:24934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/profile.php"] [unique_id "aoSA9_cmepr5_nHgLbNpDgAAAjY"] [Tue Aug 18 12:57:43.516757 2026] [security2:error] [pid 66623:tid 66889] [client 20.119.58.187:12509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSA99O5rbWdOArH04KUJgAAAYU"] [Tue Aug 18 12:57:43.532506 2026] [security2:error] [pid 67073:tid 67238] [client 20.118.133.132:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/222.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEAAAAjU"] [Tue Aug 18 12:57:43.537279 2026] [security2:error] [pid 67073:tid 67332] [client 68.155.154.236:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEQAAApM"] [Tue Aug 18 12:57:43.573973 2026] [security2:error] [pid 67073:tid 67312] [client 20.215.241.237:25320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/wsomini.php"] [unique_id "aoSA9_cmepr5_nHgLbNpEwAAAn8"] [Tue Aug 18 12:57:43.597813 2026] [security2:error] [pid 67073:tid 67268] [client 74.248.18.37:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/settings.php"] [unique_id "aoSA9_cmepr5_nHgLbNpFAAAAlM"] [Tue Aug 18 12:57:43.648643 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/admin.php"] [unique_id "aoSA99O5rbWdOArH04KUKAAAASs"] [Tue Aug 18 12:57:43.664740 2026] [security2:error] [pid 67073:tid 67285] [client 20.119.58.187:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/ws.php"] [unique_id "aoSA9_cmepr5_nHgLbNpFgAAAmQ"] [Tue Aug 18 12:57:43.720086 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:3102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSA99O5rbWdOArH04KUJwAAAXk"] [Tue Aug 18 12:57:43.726022 2026] [security2:error] [pid 66623:tid 66869] [client 40.85.222.29:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSA99O5rbWdOArH04KUKQAAAXE"] [Tue Aug 18 12:57:43.747602 2026] [security2:error] [pid 67073:tid 67330] [client 160.120.140.123:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpGgAAApE"] [Tue Aug 18 12:57:43.747735 2026] [security2:error] [pid 67073:tid 67330] [client 160.120.140.123:49752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA9_cmepr5_nHgLbNpGgAAApE"] [Tue Aug 18 12:57:43.816594 2026] [security2:error] [pid 67073:tid 67233] [client 20.100.185.105:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/22.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHQAAAjA"] [Tue Aug 18 12:57:43.825999 2026] [security2:error] [pid 67073:tid 67270] [client 104.209.144.33:36500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/blog/byp.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHgAAAlU"] [Tue Aug 18 12:57:43.863124 2026] [security2:error] [pid 67073:tid 67327] [client 20.118.172.148:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSA9_cmepr5_nHgLbNpHwAAAo4"] [Tue Aug 18 12:57:43.873102 2026] [security2:error] [pid 67073:tid 67280] [client 52.173.121.69:16455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/zwlsv.php"] [unique_id "aoSA9_cmepr5_nHgLbNpIAAAAl8"] [Tue Aug 18 12:57:43.884960 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/feeds.php"] [unique_id "aoSA99O5rbWdOArH04KUKwAAATw"] [Tue Aug 18 12:57:43.933147 2026] [security2:error] [pid 66623:tid 66827] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/ops.php"] [unique_id "aoSA99O5rbWdOArH04KULQAAAUc"] [Tue Aug 18 12:57:43.977962 2026] [authz_core:error] [pid 67073:tid 67148] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:43.978232 2026] [authz_core:error] [pid 67073:tid 67148] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:43.997624 2026] [security2:error] [pid 67073:tid 67269] [client 158.158.74.177:26120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSA9_cmepr5_nHgLbNpLwAAAlQ"] [Tue Aug 18 12:57:44.006589 2026] [security2:error] [pid 67073:tid 67241] [client 40.85.222.29:44770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMAAAAjg"] [Tue Aug 18 12:57:44.011855 2026] [security2:error] [pid 67073:tid 67277] [client 192.141.172.134:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMQAAAlw"] [Tue Aug 18 12:57:44.011961 2026] [security2:error] [pid 67073:tid 67277] [client 192.141.172.134:64928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMQAAAlw"] [Tue Aug 18 12:57:44.019244 2026] [security2:error] [pid 67073:tid 67267] [client 20.119.58.187:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/wsa.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpMgAAAlI"] [Tue Aug 18 12:57:44.091000 2026] [security2:error] [pid 67073:tid 67323] [client 20.215.241.237:36785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.borestebombordo.com.br"] [uri "/vr.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpOgAAAoo"] [Tue Aug 18 12:57:44.107626 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:24925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpPAAAAlo"] [Tue Aug 18 12:57:44.156257 2026] [security2:error] [pid 67073:tid 67274] [client 68.155.154.236:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpPwAAAlk"] [Tue Aug 18 12:57:44.241090 2026] [security2:error] [pid 67073:tid 67264] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/coffexium.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpQgAAAk8"] [Tue Aug 18 12:57:44.243601 2026] [security2:error] [pid 67073:tid 67205] [client 20.119.58.187:12535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/defaults.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpQwAAAhQ"] [Tue Aug 18 12:57:44.250528 2026] [security2:error] [pid 66623:tid 66833] [client 74.248.18.37:35369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sf.php"] [unique_id "aoSA-NO5rbWdOArH04KULgAAAU0"] [Tue Aug 18 12:57:44.275767 2026] [security2:error] [pid 67073:tid 67208] [client 172.202.39.151:65277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpRQAAAhc"] [Tue Aug 18 12:57:44.294237 2026] [security2:error] [pid 67073:tid 67306] [client 213.35.127.232:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpRgAAAnk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:44.309538 2026] [security2:error] [pid 66623:tid 66857] [client 40.85.222.29:25034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSA-NO5rbWdOArH04KULwAAAWU"] [Tue Aug 18 12:57:44.345997 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.155.199:5954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/x.php"] [unique_id "aoSA-NO5rbWdOArH04KUMAAAAXA"] [Tue Aug 18 12:57:44.350825 2026] [security2:error] [pid 67073:tid 67292] [client 74.248.18.37:3293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpSQAAAms"] [Tue Aug 18 12:57:44.353736 2026] [security2:error] [pid 66623:tid 66808] [client 74.7.228.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "leandroxavier1753363671494.0201157.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "aoSA-NO5rbWdOArH04KUMgABNCw"] [Tue Aug 18 12:57:44.370954 2026] [security2:error] [pid 67073:tid 67215] [client 20.119.58.187:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/w.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpSgAAAh4"] [Tue Aug 18 12:57:44.385470 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:44761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aa2.php"] [unique_id "aoSA-NO5rbWdOArH04KUNAAAAWw"] [Tue Aug 18 12:57:44.393454 2026] [security2:error] [pid 66623:tid 66861] [client 132.196.30.78:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/p.php"] [unique_id "aoSA-NO5rbWdOArH04KUNQAAAWk"] [Tue Aug 18 12:57:44.409119 2026] [security2:error] [pid 67073:tid 67237] [client 20.203.183.135:31320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpTAAAAjQ"] [Tue Aug 18 12:57:44.447737 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:42651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/hkvkjguw.php"] [unique_id "aoSA-NO5rbWdOArH04KUNwAAAS0"] [Tue Aug 18 12:57:44.511748 2026] [security2:error] [pid 67073:tid 67320] [client 20.100.169.31:43821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/gecko-new.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpTwAAAoc"] [Tue Aug 18 12:57:44.531186 2026] [security2:error] [pid 67073:tid 67310] [client 20.206.73.37:20712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/sky.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpUAAAAn0"] [Tue Aug 18 12:57:44.552739 2026] [security2:error] [pid 67073:tid 67314] [client 172.182.200.96:14129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpUwAAAoE"] [Tue Aug 18 12:57:44.584819 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:44.585088 2026] [authz_core:error] [pid 67073:tid 67106] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:44.594691 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:44263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSA-NO5rbWdOArH04KUPAAAAYE"] [Tue Aug 18 12:57:44.604879 2026] [security2:error] [pid 67073:tid 67311] [client 20.119.58.187:12086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/system.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpVgAAAn4"] [Tue Aug 18 12:57:44.722237 2026] [security2:error] [pid 67073:tid 67319] [client 20.119.58.187:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/x.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpXAAAAoY"] [Tue Aug 18 12:57:44.733625 2026] [security2:error] [pid 67073:tid 67300] [client 4.232.151.198:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpXQAAAnM"] [Tue Aug 18 12:57:44.792178 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:8052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/rezor.php"] [unique_id "aoSA-NO5rbWdOArH04KUTQAAAQ4"] [Tue Aug 18 12:57:44.861926 2026] [security2:error] [pid 67073:tid 67235] [client 52.173.121.69:24971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/jrpga.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpZAAAAjI"] [Tue Aug 18 12:57:44.869111 2026] [security2:error] [pid 66623:tid 66793] [client 104.209.144.33:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSA-NO5rbWdOArH04KUTgAAASU"] [Tue Aug 18 12:57:44.884370 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:44.884665 2026] [authz_core:error] [pid 67073:tid 67192] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:44.911200 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:44781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSA-NO5rbWdOArH04KUUAAAAYM"] [Tue Aug 18 12:57:44.919816 2026] [security2:error] [pid 67073:tid 67254] [client 74.248.18.37:20509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/shell.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpZwAAAkU"] [Tue Aug 18 12:57:44.921162 2026] [security2:error] [pid 66623:tid 66845] [client 158.158.34.183:43696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/Casper.php"] [unique_id "aoSA-NO5rbWdOArH04KUUQAAAVk"] [Tue Aug 18 12:57:44.986460 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.18.37:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSA-NO5rbWdOArH04KUUwAAASY"] [Tue Aug 18 12:57:44.997107 2026] [security2:error] [pid 67073:tid 67207] [client 158.158.74.177:16553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSA-Pcmepr5_nHgLbNpagAAAhY"] [Tue Aug 18 12:57:45.003953 2026] [security2:error] [pid 67073:tid 67328] [client 20.119.58.187:12491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-fcmepr5_nHgLbNpawAAAo8"] [Tue Aug 18 12:57:45.066478 2026] [security2:error] [pid 67073:tid 67284] [client 20.100.185.105:42687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cadastro-2.php"] [unique_id "aoSA-fcmepr5_nHgLbNpbQAAAmM"] [Tue Aug 18 12:57:45.080118 2026] [security2:error] [pid 66623:tid 66783] [client 20.119.58.187:11468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xx.php"] [unique_id "aoSA-dO5rbWdOArH04KUVQAAARs"] [Tue Aug 18 12:57:45.102778 2026] [security2:error] [pid 67073:tid 67295] [client 172.182.217.32:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/666.php"] [unique_id "aoSA-fcmepr5_nHgLbNpbwAAAm4"] [Tue Aug 18 12:57:45.108498 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSA-dO5rbWdOArH04KUVwAAARg"] [Tue Aug 18 12:57:45.132522 2026] [security2:error] [pid 67073:tid 67270] [client 40.74.65.169:27795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/xamp.php"] [unique_id "aoSA-fcmepr5_nHgLbNpcQAAAlU"] [Tue Aug 18 12:57:45.225535 2026] [security2:error] [pid 67073:tid 67280] [client 20.226.56.190:2077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bh.php"] [unique_id "aoSA-fcmepr5_nHgLbNpcwAAAl8"] [Tue Aug 18 12:57:45.243535 2026] [security2:error] [pid 66623:tid 66848] [client 132.196.30.78:18796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.centraldascaixas.com.br"] [uri "/php.php"] [unique_id "aoSA-dO5rbWdOArH04KUWQAAAVw"] [Tue Aug 18 12:57:45.254569 2026] [security2:error] [pid 67073:tid 67277] [client 40.85.222.29:44253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdQAAAlw"] [Tue Aug 18 12:57:45.265862 2026] [security2:error] [pid 67073:tid 67321] [client 172.182.217.32:15596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bgymj.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdgAAAog"] [Tue Aug 18 12:57:45.308431 2026] [security2:error] [pid 67073:tid 67289] [client 213.35.127.232:58075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpdwAAAmg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:45.359487 2026] [security2:error] [pid 67073:tid 67269] [client 20.119.58.187:11884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSA-fcmepr5_nHgLbNpeQAAAlQ"] [Tue Aug 18 12:57:45.369028 2026] [security2:error] [pid 67073:tid 67217] [client 68.155.155.199:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSA-fcmepr5_nHgLbNpegAAAiA"] [Tue Aug 18 12:57:45.406067 2026] [security2:error] [pid 67073:tid 67222] [client 4.232.151.198:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA-fcmepr5_nHgLbNpewAAAiU"] [Tue Aug 18 12:57:45.426966 2026] [security2:error] [pid 67073:tid 67209] [client 20.65.98.162:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/nano.php"] [unique_id "aoSA-fcmepr5_nHgLbNpfQAAAhg"] [Tue Aug 18 12:57:45.433396 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:11469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUXQAAAXs"] [Tue Aug 18 12:57:45.497777 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:45.498074 2026] [authz_core:error] [pid 67073:tid 67182] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:45.501834 2026] [security2:error] [pid 67073:tid 67266] [client 5.161.117.52:12650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpfwAAAlE"], referer: https://rota85motorshop.com.br/ [Tue Aug 18 12:57:45.528777 2026] [security2:error] [pid 67073:tid 67264] [client 172.182.200.96:7663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSA-fcmepr5_nHgLbNpggAAAk8"] [Tue Aug 18 12:57:45.562471 2026] [security2:error] [pid 67073:tid 67252] [client 40.85.222.29:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/rezor.php"] [unique_id "aoSA-fcmepr5_nHgLbNpgwAAAkM"] [Tue Aug 18 12:57:45.586974 2026] [security2:error] [pid 67073:tid 67248] [client 114.119.157.158:25355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vidracariafroesbox.com.br"] [uri "/servicos/fechamento-de-varandas-em-vidro"] [unique_id "aoSA-fcmepr5_nHgLbNphAAAAj8"], referer: https://vidracariafroesbox.com.br/servicos/fechamento-de-varandas-em-vidro [Tue Aug 18 12:57:45.607073 2026] [security2:error] [pid 67073:tid 67292] [client 20.206.73.37:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file5.php"] [unique_id "aoSA-fcmepr5_nHgLbNphwAAAms"] [Tue Aug 18 12:57:45.615258 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:41606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/atomlib.php"] [unique_id "aoSA-dO5rbWdOArH04KUXgAAARY"] [Tue Aug 18 12:57:45.639873 2026] [security2:error] [pid 67073:tid 67305] [client 74.248.18.37:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSA-fcmepr5_nHgLbNpiAAAAng"] [Tue Aug 18 12:57:45.677267 2026] [security2:error] [pid 66623:tid 66782] [client 20.118.133.132:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mac.php"] [unique_id "aoSA-dO5rbWdOArH04KUXwAAARo"] [Tue Aug 18 12:57:45.685331 2026] [security2:error] [pid 67073:tid 67244] [client 20.100.185.105:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/backup.php"] [unique_id "aoSA-fcmepr5_nHgLbNpigAAAjs"] [Tue Aug 18 12:57:45.713519 2026] [security2:error] [pid 67073:tid 67329] [client 20.119.58.187:12506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/colors.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjQAAApA"] [Tue Aug 18 12:57:45.716412 2026] [security2:error] [pid 67073:tid 67293] [client 74.248.18.37:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/shiny.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjgAAAmw"] [Tue Aug 18 12:57:45.754852 2026] [security2:error] [pid 67073:tid 67279] [client 172.182.217.32:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bthil.php"] [unique_id "aoSA-fcmepr5_nHgLbNpjwAAAl4"] [Tue Aug 18 12:57:45.767103 2026] [security2:error] [pid 67073:tid 67243] [client 20.48.236.86:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mac.php"] [unique_id "aoSA-fcmepr5_nHgLbNpkAAAAjo"] [Tue Aug 18 12:57:45.784487 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA-dO5rbWdOArH04KUYAAAAV4"] [Tue Aug 18 12:57:45.786966 2026] [security2:error] [pid 67073:tid 67242] [client 20.119.58.187:11101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.telesaopedro.com.br"] [uri "/y.php"] [unique_id "aoSA-fcmepr5_nHgLbNpkQAAAjk"] [Tue Aug 18 12:57:45.807630 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:45.807897 2026] [authz_core:error] [pid 67073:tid 67175] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:45.853653 2026] [security2:error] [pid 67073:tid 67309] [client 104.222.31.70:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.31.222.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fioplastic.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSA-fcmepr5_nHgLbNplQAAAnw"] [Tue Aug 18 12:57:45.861294 2026] [security2:error] [pid 66623:tid 66836] [client 223.185.37.47:3374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUYwAAAVA"] [Tue Aug 18 12:57:45.861431 2026] [security2:error] [pid 66623:tid 66836] [client 223.185.37.47:3374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSA-dO5rbWdOArH04KUYwAAAVA"] [Tue Aug 18 12:57:45.873817 2026] [security2:error] [pid 67073:tid 67205] [client 158.158.74.177:2632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSA-fcmepr5_nHgLbNplgAAAhQ"] [Tue Aug 18 12:57:45.874135 2026] [security2:error] [pid 66623:tid 66642] [remote 108.167.161.33:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guelraott.com"] [uri "/wp-login.php"] [unique_id "aoSA-dO5rbWdOArH04KUZAABRgU"] [Tue Aug 18 12:57:45.905670 2026] [security2:error] [pid 67073:tid 67213] [client 68.155.154.236:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA-fcmepr5_nHgLbNpmQAAAhw"] [Tue Aug 18 12:57:45.936552 2026] [security2:error] [pid 67073:tid 67256] [client 213.202.253.4:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSA-fcmepr5_nHgLbNpmwAAAkc"], referer: www.google.com [Tue Aug 18 12:57:45.987009 2026] [security2:error] [pid 66623:tid 66856] [client 40.74.65.169:28191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/bless.php"] [unique_id "aoSA-dO5rbWdOArH04KUZQAAAWQ"] [Tue Aug 18 12:57:46.034842 2026] [security2:error] [pid 67073:tid 67319] [client 104.209.144.33:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSA-vcmepr5_nHgLbNpngAAAoY"] [Tue Aug 18 12:57:46.053848 2026] [security2:error] [pid 66623:tid 66775] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSA-tO5rbWdOArH04KUZwAAARM"] [Tue Aug 18 12:57:46.058740 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSA-tO5rbWdOArH04KUaAAAAUw"] [Tue Aug 18 12:57:46.069821 2026] [security2:error] [pid 67073:tid 67332] [client 52.173.121.69:24961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSA-vcmepr5_nHgLbNpoAAAApM"] [Tue Aug 18 12:57:46.079534 2026] [autoindex:error] [pid 66623:tid 66815] [client 4.232.151.198:4342] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:46.090018 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:12071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/updates.php"] [unique_id "aoSA-tO5rbWdOArH04KUagAAARc"] [Tue Aug 18 12:57:46.105263 2026] [security2:error] [pid 67073:tid 67278] [client 40.85.222.29:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSA-vcmepr5_nHgLbNpoQAAAl0"] [Tue Aug 18 12:57:46.111426 2026] [security2:error] [pid 67073:tid 67213] [client 79.127.164.8:57786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/old.sql"] [unique_id "aoSA-vcmepr5_nHgLbNppwAAAhw"], referer: https://medihub.com.br/old.sql [Tue Aug 18 12:57:46.116124 2026] [security2:error] [pid 67073:tid 67297] [client 20.226.56.190:47139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/ct.php"] [unique_id "aoSA-vcmepr5_nHgLbNprQAAAnA"] [Tue Aug 18 12:57:46.117829 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:46.118262 2026] [authz_core:error] [pid 67073:tid 67131] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:46.234418 2026] [security2:error] [pid 66623:tid 66812] [client 20.118.172.148:33525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA-tO5rbWdOArH04KUbQAAATg"] [Tue Aug 18 12:57:46.246616 2026] [security2:error] [pid 66623:tid 66843] [client 20.104.85.180:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSA-tO5rbWdOArH04KUbgAAAVc"] [Tue Aug 18 12:57:46.255196 2026] [security2:error] [pid 67073:tid 67268] [client 172.182.217.32:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xp.php"] [unique_id "aoSA-vcmepr5_nHgLbNpswAAAlM"] [Tue Aug 18 12:57:46.273354 2026] [security2:error] [pid 66623:tid 66877] [client 68.155.155.199:13352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/hosty.php"] [unique_id "aoSA-tO5rbWdOArH04KUbwAAAXk"] [Tue Aug 18 12:57:46.309240 2026] [security2:error] [pid 66623:tid 66710] [remote 110.249.202.110:17212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2018/06/GF-com-Luiz-Schmidt-Caio-Almeida-e-Artur-da-Matta-400x284.jpg"] [unique_id "aoSA-tO5rbWdOArH04KUcAABUkk"] [Tue Aug 18 12:57:46.312924 2026] [security2:error] [pid 66623:tid 66886] [client 4.232.151.198:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSA-tO5rbWdOArH04KUcQAAAYI"] [Tue Aug 18 12:57:46.313333 2026] [security2:error] [pid 67073:tid 67219] [client 74.248.18.37:3270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSA-vcmepr5_nHgLbNpuwAAAiI"] [Tue Aug 18 12:57:46.320064 2026] [security2:error] [pid 67073:tid 67261] [client 20.100.185.105:43351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSA-vcmepr5_nHgLbNpvAAAAkw"] [Tue Aug 18 12:57:46.320463 2026] [security2:error] [pid 66623:tid 66772] [client 213.35.127.232:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA-tO5rbWdOArH04KUcgAAARA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:46.390905 2026] [security2:error] [pid 67073:tid 67230] [client 157.51.166.53:50240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwAAAAi0"] [Tue Aug 18 12:57:46.391097 2026] [security2:error] [pid 67073:tid 67230] [client 157.51.166.53:50240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwAAAAi0"] [Tue Aug 18 12:57:46.414447 2026] [security2:error] [pid 67073:tid 67318] [client 74.248.18.37:21513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sid3.php"] [unique_id "aoSA-vcmepr5_nHgLbNpwQAAAoU"] [Tue Aug 18 12:57:46.430781 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:46.431225 2026] [authz_core:error] [pid 67073:tid 67135] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:46.444921 2026] [security2:error] [pid 66623:tid 66816] [client 20.119.58.187:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSA-tO5rbWdOArH04KUcwAAATw"] [Tue Aug 18 12:57:46.451460 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.154.236:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA-tO5rbWdOArH04KUdAAAAYA"] [Tue Aug 18 12:57:46.465713 2026] [security2:error] [pid 66623:tid 66857] [client 40.85.222.29:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSA-tO5rbWdOArH04KUdQAAAWU"] [Tue Aug 18 12:57:46.612360 2026] [security2:error] [pid 66623:tid 66875] [client 104.209.144.33:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pagazulrecovery.3xsolutions.com"] [uri "/images/security.php"] [unique_id "aoSA-tO5rbWdOArH04KUdwAAAXc"] [Tue Aug 18 12:57:46.688795 2026] [security2:error] [pid 67073:tid 67206] [client 20.118.172.148:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSA-vcmepr5_nHgLbNpyAAAAhU"] [Tue Aug 18 12:57:46.689896 2026] [security2:error] [pid 67073:tid 67294] [client 20.104.85.180:43544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-good.php"] [unique_id "aoSA-vcmepr5_nHgLbNpyQAAAm0"] [Tue Aug 18 12:57:46.750237 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.217.32:15748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/reze.php"] [unique_id "aoSA-tO5rbWdOArH04KUewAAATA"] [Tue Aug 18 12:57:46.766882 2026] [security2:error] [pid 67073:tid 67285] [client 196.12.128.158:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpywAAAmQ"] [Tue Aug 18 12:57:46.766991 2026] [security2:error] [pid 67073:tid 67285] [client 196.12.128.158:55458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSA-vcmepr5_nHgLbNpywAAAmQ"] [Tue Aug 18 12:57:46.801987 2026] [security2:error] [pid 66623:tid 66865] [client 20.119.58.187:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-index.php"] [unique_id "aoSA-tO5rbWdOArH04KUfAAAAW0"] [Tue Aug 18 12:57:46.839299 2026] [security2:error] [pid 67073:tid 67262] [client 40.74.65.169:43193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file25.php"] [unique_id "aoSA-vcmepr5_nHgLbNpzgAAAk0"] [Tue Aug 18 12:57:46.868683 2026] [security2:error] [pid 66623:tid 66771] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/sf.php"] [unique_id "aoSA-tO5rbWdOArH04KUfQAAAQ8"] [Tue Aug 18 12:57:46.887492 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:46.887755 2026] [authz_core:error] [pid 67073:tid 67173] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:46.902273 2026] [authz_core:error] [pid 67073:tid 67142] [remote 57.141.22.29:54220] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:46.902532 2026] [authz_core:error] [pid 67073:tid 67142] [remote 57.141.22.29:54220] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:46.906551 2026] [security2:error] [pid 66623:tid 66841] [client 20.1.169.243:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/as.php"] [unique_id "aoSA-tO5rbWdOArH04KUgQAAAVU"] [Tue Aug 18 12:57:46.940514 2026] [security2:error] [pid 66623:tid 66846] [client 172.202.39.151:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/ok.php"] [unique_id "aoSA-tO5rbWdOArH04KUgwAAAVo"] [Tue Aug 18 12:57:46.958112 2026] [security2:error] [pid 66623:tid 66845] [client 40.85.222.29:44791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/index/function.php"] [unique_id "aoSA-tO5rbWdOArH04KUhgAAAVk"] [Tue Aug 18 12:57:46.958435 2026] [security2:error] [pid 66623:tid 66842] [client 20.100.185.105:29220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/item.php"] [unique_id "aoSA-tO5rbWdOArH04KUhwAAAVY"] [Tue Aug 18 12:57:47.026601 2026] [security2:error] [pid 66623:tid 66885] [client 20.1.169.243:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/atex1.php"] [unique_id "aoSA-9O5rbWdOArH04KUiQAAAYE"] [Tue Aug 18 12:57:47.048826 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/index/function.php"] [unique_id "aoSA-_cmepr5_nHgLbNp4wAAAm8"] [Tue Aug 18 12:57:47.082522 2026] [autoindex:error] [pid 67073:tid 67323] [client 158.158.74.177:26133] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:47.089403 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sid4.php"] [unique_id "aoSA-9O5rbWdOArH04KUiwAAAYg"] [Tue Aug 18 12:57:47.116489 2026] [security2:error] [pid 67073:tid 67243] [client 20.118.172.148:53104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/edit.php"] [unique_id "aoSA-_cmepr5_nHgLbNp5QAAAjo"] [Tue Aug 18 12:57:47.121158 2026] [autoindex:error] [pid 67073:tid 67264] [client 4.232.151.198:24913] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:47.150890 2026] [security2:error] [pid 66623:tid 66647] [remote 66.102.134.13:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSA-9O5rbWdOArH04KUjAABVAo"] [Tue Aug 18 12:57:47.172931 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew.php7"] [unique_id "aoSA-9O5rbWdOArH04KUjgAAASY"] [Tue Aug 18 12:57:47.184295 2026] [security2:error] [pid 67073:tid 67310] [client 52.173.121.69:16466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/nwwha.php"] [unique_id "aoSA-_cmepr5_nHgLbNp5wAAAn0"] [Tue Aug 18 12:57:47.197973 2026] [security2:error] [pid 67073:tid 67317] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/k.php"] [unique_id "aoSA-_cmepr5_nHgLbNp6AAAAoQ"] [Tue Aug 18 12:57:47.241426 2026] [security2:error] [pid 67073:tid 67293] [client 172.182.217.32:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/2026w.php"] [unique_id "aoSA-_cmepr5_nHgLbNp6gAAAmw"] [Tue Aug 18 12:57:47.287708 2026] [security2:error] [pid 67073:tid 67234] [client 158.158.74.177:26133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSA-_cmepr5_nHgLbNp7gAAAjE"] [Tue Aug 18 12:57:47.321217 2026] [security2:error] [pid 66623:tid 66813] [client 20.118.172.148:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSA-9O5rbWdOArH04KUlQAAATk"] [Tue Aug 18 12:57:47.327198 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:47.327468 2026] [authz_core:error] [pid 67073:tid 67190] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:47.330326 2026] [security2:error] [pid 67073:tid 67253] [client 213.35.127.232:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8QAAAkQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:47.330366 2026] [security2:error] [pid 67073:tid 67240] [client 4.232.151.198:24913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8AAAAjc"] [Tue Aug 18 12:57:47.371607 2026] [security2:error] [pid 67073:tid 67291] [client 20.100.169.31:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/aaa.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8gAAAmo"] [Tue Aug 18 12:57:47.372502 2026] [security2:error] [pid 66623:tid 66855] [client 40.85.222.29:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA-9O5rbWdOArH04KUlwAAAWM"] [Tue Aug 18 12:57:47.382847 2026] [security2:error] [pid 66623:tid 66782] [client 74.248.18.37:3661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSA-9O5rbWdOArH04KUmQAAARo"] [Tue Aug 18 12:57:47.387148 2026] [security2:error] [pid 67073:tid 67319] [client 20.206.73.37:59895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/xyn.php"] [unique_id "aoSA-_cmepr5_nHgLbNp8wAAAoY"] [Tue Aug 18 12:57:47.389537 2026] [security2:error] [pid 67073:tid 67247] [client 20.1.169.243:3656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/atomlib.php"] [unique_id "aoSA-_cmepr5_nHgLbNp9AAAAj4"] [Tue Aug 18 12:57:47.421083 2026] [core:error] [pid 67073:tid 67278] [client 52.167.144.146:33154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:57:47.421099 2026] [core:error] [pid 67073:tid 67278] [client 52.167.144.146:33154] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:57:47.465029 2026] [security2:error] [pid 67073:tid 67236] [client 68.155.155.199:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/test1.php"] [unique_id "aoSA-_cmepr5_nHgLbNp-AAAAjM"] [Tue Aug 18 12:57:47.524916 2026] [security2:error] [pid 67073:tid 67295] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/82.php"] [unique_id "aoSA-_cmepr5_nHgLbNp-wAAAm4"] [Tue Aug 18 12:57:47.529900 2026] [security2:error] [pid 67073:tid 67250] [client 20.119.58.187:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/locale.php"] [unique_id "aoSA-_cmepr5_nHgLbNp_AAAAkE"] [Tue Aug 18 12:57:47.552900 2026] [security2:error] [pid 67073:tid 67268] [client 68.155.154.236:7670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSA-_cmepr5_nHgLbNp_QAAAlM"] [Tue Aug 18 12:57:47.631292 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:47.631589 2026] [authz_core:error] [pid 67073:tid 67184] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:47.633041 2026] [security2:error] [pid 67073:tid 67261] [client 40.74.65.169:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file15.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBQAAAkw"] [Tue Aug 18 12:57:47.643974 2026] [security2:error] [pid 67073:tid 67245] [client 20.118.172.148:43503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/w.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBgAAAjw"] [Tue Aug 18 12:57:47.691614 2026] [security2:error] [pid 67073:tid 67177] [remote 72.167.40.62:35812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSA-_cmepr5_nHgLbNqBwACOGU"] [Tue Aug 18 12:57:47.749093 2026] [security2:error] [pid 67073:tid 67215] [client 197.184.64.235:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCgAAAh4"] [Tue Aug 18 12:57:47.749240 2026] [security2:error] [pid 67073:tid 67215] [client 197.184.64.235:41938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCgAAAh4"] [Tue Aug 18 12:57:47.751079 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.217.32:15600] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "invictambiental.com.br"] [uri "/1.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCwAAAo4"] [Tue Aug 18 12:57:47.751220 2026] [security2:error] [pid 67073:tid 67327] [client 172.182.217.32:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/1.php"] [unique_id "aoSA-_cmepr5_nHgLbNqCwAAAo4"] [Tue Aug 18 12:57:47.754754 2026] [security2:error] [pid 67073:tid 67306] [client 20.1.169.243:3392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/black.php"] [unique_id "aoSA-_cmepr5_nHgLbNqDAAAAnk"] [Tue Aug 18 12:57:47.804375 2026] [security2:error] [pid 67073:tid 67220] [client 20.100.185.105:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqDwAAAiM"] [Tue Aug 18 12:57:47.844452 2026] [security2:error] [pid 67073:tid 67269] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/dex.php"] [unique_id "aoSA-_cmepr5_nHgLbNqEAAAAlQ"] [Tue Aug 18 12:57:47.887342 2026] [security2:error] [pid 67073:tid 67217] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA-_cmepr5_nHgLbNqEgACIBY"] [Tue Aug 18 12:57:47.888182 2026] [security2:error] [pid 67073:tid 67273] [client 20.119.58.187:11875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wxo.php"] [unique_id "aoSA-_cmepr5_nHgLbNqHAAAAlg"] [Tue Aug 18 12:57:47.929432 2026] [security2:error] [pid 67073:tid 67152] [remote 165.227.132.137:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSA-_cmepr5_nHgLbNqHwACPUw"] [Tue Aug 18 12:57:47.930823 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:47.931092 2026] [authz_core:error] [pid 67073:tid 67086] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:47.995837 2026] [security2:error] [pid 67073:tid 67321] [client 4.232.151.198:4312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSA-_cmepr5_nHgLbNqIgAAAog"] [Tue Aug 18 12:57:47.998565 2026] [security2:error] [pid 67073:tid 67211] [client 74.248.18.37:21523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/size.php"] [unique_id "aoSA-_cmepr5_nHgLbNqIwAAAho"] [Tue Aug 18 12:57:48.013202 2026] [security2:error] [pid 67073:tid 67289] [client 74.248.18.37:3289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-fclass.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqJAAAAmg"] [Tue Aug 18 12:57:48.036619 2026] [security2:error] [pid 67073:tid 67218] [client 103.139.191.60:64585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqKgAAAiE"] [Tue Aug 18 12:57:48.036741 2026] [security2:error] [pid 67073:tid 67218] [client 103.139.191.60:64585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqKgAAAiE"] [Tue Aug 18 12:57:48.096464 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:44758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/Cachex.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqPwAAAjo"] [Tue Aug 18 12:57:48.101673 2026] [security2:error] [pid 67073:tid 67301] [client 20.118.172.148:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqVAAAAnQ"] [Tue Aug 18 12:57:48.114005 2026] [security2:error] [pid 66623:tid 66822] [client 20.250.13.23:47815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/rip.php"] [unique_id "aoSA_NO5rbWdOArH04KUpAAAAUI"] [Tue Aug 18 12:57:48.123439 2026] [security2:error] [pid 67073:tid 67208] [client 20.1.169.243:3704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/bs1.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqVgAAAhc"] [Tue Aug 18 12:57:48.124361 2026] [security2:error] [pid 66623:tid 66870] [client 68.155.154.236:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/Cachex.php"] [unique_id "aoSA_NO5rbWdOArH04KUpQAAAXI"] [Tue Aug 18 12:57:48.135265 2026] [autoindex:error] [pid 66623:tid 66703] [remote 40.77.167.224:43784] AH01276: Cannot serve directory /home1/sergiopontes/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:48.164349 2026] [security2:error] [pid 67073:tid 67212] [client 68.155.155.199:8146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/zwso.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqYAAAAhs"] [Tue Aug 18 12:57:48.165200 2026] [security2:error] [pid 67073:tid 67226] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/puc.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqYQAAAik"] [Tue Aug 18 12:57:48.180712 2026] [security2:error] [pid 66623:tid 66789] [client 158.158.34.183:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/beence.php"] [unique_id "aoSA_NO5rbWdOArH04KUpwAAASE"] [Tue Aug 18 12:57:48.243672 2026] [security2:error] [pid 67073:tid 67317] [client 20.119.58.187:12502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/colour.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqegAAAoQ"] [Tue Aug 18 12:57:48.249750 2026] [security2:error] [pid 67073:tid 67329] [client 172.182.217.32:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/2.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqewAAApA"] [Tue Aug 18 12:57:48.257304 2026] [security2:error] [pid 67073:tid 67322] [client 20.118.172.148:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/xmr.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqfwAAAok"] [Tue Aug 18 12:57:48.345350 2026] [security2:error] [pid 67073:tid 67331] [client 213.35.127.232:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqhwAAApI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:48.346941 2026] [security2:error] [pid 67073:tid 67279] [client 20.226.56.190:20376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/gy.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqiAAAAl4"] [Tue Aug 18 12:57:48.423994 2026] [security2:error] [pid 67073:tid 67253] [client 20.100.185.105:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-load.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqkgAAAkQ"] [Tue Aug 18 12:57:48.454986 2026] [security2:error] [pid 67073:tid 67318] [client 20.186.30.159:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqqAAAAoU"] [Tue Aug 18 12:57:48.510981 2026] [security2:error] [pid 66623:tid 66838] [client 20.1.169.243:3668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/colors/blue/about.php"] [unique_id "aoSA_NO5rbWdOArH04KUrAAAAVI"] [Tue Aug 18 12:57:48.516743 2026] [security2:error] [pid 67073:tid 67215] [client 20.203.183.135:24618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqrAAAAh4"] [Tue Aug 18 12:57:48.530777 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:48.531026 2026] [authz_core:error] [pid 67073:tid 67116] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:48.556932 2026] [core:error] [pid 66623:tid 66733] [remote 52.167.144.146:47566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:57:48.556946 2026] [core:error] [pid 66623:tid 66733] [remote 52.167.144.146:47566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:57:48.575893 2026] [security2:error] [pid 67073:tid 67308] [client 52.173.121.69:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/opsqt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqsAAAAns"] [Tue Aug 18 12:57:48.613761 2026] [security2:error] [pid 67073:tid 67217] [client 20.118.172.148:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqswAAAiA"] [Tue Aug 18 12:57:48.619491 2026] [security2:error] [pid 67073:tid 67273] [client 20.226.56.190:3057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/tt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqtQAAAlg"] [Tue Aug 18 12:57:48.639056 2026] [security2:error] [pid 67073:tid 67327] [client 20.119.58.187:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-contentt.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqugAAAo4"] [Tue Aug 18 12:57:48.655069 2026] [security2:error] [pid 67073:tid 67265] [client 4.232.151.198:24896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqvAAAAlA"] [Tue Aug 18 12:57:48.678981 2026] [security2:error] [pid 67073:tid 67230] [client 74.248.18.37:35373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/special.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqvQAAAi0"] [Tue Aug 18 12:57:48.723300 2026] [security2:error] [pid 67073:tid 67296] [client 68.155.154.236:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqyQAAAm8"] [Tue Aug 18 12:57:48.748420 2026] [security2:error] [pid 67073:tid 67294] [client 172.182.217.32:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/7.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqygAAAm0"] [Tue Aug 18 12:57:48.749200 2026] [security2:error] [pid 66623:tid 66857] [client 40.74.65.169:26723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/f35.php"] [unique_id "aoSA_NO5rbWdOArH04KUswAAAWU"] [Tue Aug 18 12:57:48.772150 2026] [security2:error] [pid 67073:tid 67243] [client 20.186.30.159:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqywAAAjo"] [Tue Aug 18 12:57:48.784559 2026] [security2:error] [pid 67073:tid 67301] [client 68.155.155.199:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/Geforce.php"] [unique_id "aoSA_Pcmepr5_nHgLbNqzAAAAnQ"] [Tue Aug 18 12:57:48.859676 2026] [security2:error] [pid 67073:tid 67219] [client 40.85.222.29:44266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq1gAAAiI"] [Tue Aug 18 12:57:48.877981 2026] [security2:error] [pid 66623:tid 66862] [client 20.1.169.243:3681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/con7.php"] [unique_id "aoSA_NO5rbWdOArH04KUtQAAAWo"] [Tue Aug 18 12:57:48.981986 2026] [security2:error] [pid 67073:tid 67326] [client 20.226.56.190:32307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/mq.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq4wAAAo0"] [Tue Aug 18 12:57:48.985938 2026] [security2:error] [pid 67073:tid 67306] [client 20.100.169.31:16428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/abcd.php"] [unique_id "aoSA_Pcmepr5_nHgLbNq5AAAAnk"] [Tue Aug 18 12:57:48.994356 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/config.php7"] [unique_id "aoSA_NO5rbWdOArH04KUtgAAATQ"] [Tue Aug 18 12:57:49.030700 2026] [security2:error] [pid 67073:tid 67285] [client 158.158.74.177:2665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSA_fcmepr5_nHgLbNq7AAAAmQ"] [Tue Aug 18 12:57:49.066161 2026] [security2:error] [pid 67073:tid 67311] [client 20.100.185.105:42637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/r.php"] [unique_id "aoSA_fcmepr5_nHgLbNq7QAAAn4"] [Tue Aug 18 12:57:49.088915 2026] [security2:error] [pid 66623:tid 66764] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUtwABd38"] [Tue Aug 18 12:57:49.089102 2026] [security2:error] [pid 66623:tid 66875] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUtwABd38"] [Tue Aug 18 12:57:49.133737 2026] [security2:error] [pid 67073:tid 67270] [client 74.248.18.37:3682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSA_fcmepr5_nHgLbNq8wAAAlU"] [Tue Aug 18 12:57:49.138443 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:43504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aa.php"] [unique_id "aoSA_dO5rbWdOArH04KUuAAAAR8"] [Tue Aug 18 12:57:49.142855 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:49.143113 2026] [authz_core:error] [pid 67073:tid 67186] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:49.155937 2026] [security2:error] [pid 67073:tid 67229] [client 20.186.30.159:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/media.php"] [unique_id "aoSA_fcmepr5_nHgLbNq-AAAAiw"] [Tue Aug 18 12:57:49.165873 2026] [security2:error] [pid 67073:tid 67244] [client 20.118.172.148:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/about.php"] [unique_id "aoSA_fcmepr5_nHgLbNq-gAAAjs"] [Tue Aug 18 12:57:49.179077 2026] [security2:error] [pid 67073:tid 67261] [client 20.118.133.132:1663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ops.php"] [unique_id "aoSA_fcmepr5_nHgLbNq_AAAAkw"] [Tue Aug 18 12:57:49.229213 2026] [security2:error] [pid 67073:tid 67318] [client 52.173.121.69:16480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/jvcpa.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAAAAAoU"] [Tue Aug 18 12:57:49.232036 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:7629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSA_dO5rbWdOArH04KUugAAAUc"] [Tue Aug 18 12:57:49.240203 2026] [security2:error] [pid 67073:tid 67330] [client 172.182.217.32:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/10.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAQAAApE"] [Tue Aug 18 12:57:49.243441 2026] [security2:error] [pid 67073:tid 67268] [client 20.1.169.243:3687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAgAAAlM"] [Tue Aug 18 12:57:49.244281 2026] [security2:error] [pid 67073:tid 67254] [client 20.226.56.190:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/13.php"] [unique_id "aoSA_fcmepr5_nHgLbNrAwAAAkU"] [Tue Aug 18 12:57:49.257464 2026] [security2:error] [pid 67073:tid 67281] [client 20.250.13.23:25707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/p.php"] [unique_id "aoSA_fcmepr5_nHgLbNrBAAAAmA"] [Tue Aug 18 12:57:49.303073 2026] [security2:error] [pid 67073:tid 67250] [client 4.232.151.198:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSA_fcmepr5_nHgLbNrBgAAAkE"] [Tue Aug 18 12:57:49.347943 2026] [security2:error] [pid 67073:tid 67312] [client 20.119.58.187:12524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/config.php"] [unique_id "aoSA_fcmepr5_nHgLbNrCQAAAn8"] [Tue Aug 18 12:57:49.362678 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:4353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/fpwch.php"] [unique_id "aoSA_dO5rbWdOArH04KUuwAAAV8"] [Tue Aug 18 12:57:49.363073 2026] [security2:error] [pid 67073:tid 67214] [client 213.35.127.232:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSA_fcmepr5_nHgLbNrDAAAAh0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:49.419708 2026] [security2:error] [pid 67073:tid 67253] [client 74.248.18.37:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSA_fcmepr5_nHgLbNrDQAAAkQ"] [Tue Aug 18 12:57:49.426145 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:32857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ops.php"] [unique_id "aoSA_dO5rbWdOArH04KUvQAAATY"] [Tue Aug 18 12:57:49.466498 2026] [security2:error] [pid 67073:tid 67255] [client 40.85.222.29:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA_fcmepr5_nHgLbNrEAAAAkY"] [Tue Aug 18 12:57:49.500270 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.154.236:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-2019.php"] [unique_id "aoSA_dO5rbWdOArH04KUvgAAAVM"] [Tue Aug 18 12:57:49.583955 2026] [security2:error] [pid 67073:tid 67252] [client 20.186.30.159:1670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/admin.php"] [unique_id "aoSA_fcmepr5_nHgLbNrGgAAAkM"] [Tue Aug 18 12:57:49.615541 2026] [security2:error] [pid 67073:tid 67274] [client 20.1.169.243:3654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSA_fcmepr5_nHgLbNrGwAAAlk"] [Tue Aug 18 12:57:49.632669 2026] [security2:error] [pid 66623:tid 66885] [client 20.118.172.148:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA_dO5rbWdOArH04KUwAAAAYE"] [Tue Aug 18 12:57:49.633494 2026] [security2:error] [pid 66623:tid 66860] [client 192.141.172.134:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwQAAAWg"] [Tue Aug 18 12:57:49.633635 2026] [security2:error] [pid 66623:tid 66860] [client 192.141.172.134:65184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwQAAAWg"] [Tue Aug 18 12:57:49.640815 2026] [security2:error] [pid 67073:tid 67216] [client 40.74.65.169:43190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-load.php"] [unique_id "aoSA_fcmepr5_nHgLbNrHQAAAh8"] [Tue Aug 18 12:57:49.679947 2026] [security2:error] [pid 66623:tid 66849] [client 37.40.227.74:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwgAAAV0"] [Tue Aug 18 12:57:49.680060 2026] [security2:error] [pid 66623:tid 66849] [client 37.40.227.74:56921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUwgAAAV0"] [Tue Aug 18 12:57:49.710638 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:11880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/theme.php"] [unique_id "aoSA_dO5rbWdOArH04KUwwAAAUU"] [Tue Aug 18 12:57:49.725863 2026] [security2:error] [pid 67073:tid 67314] [client 20.226.56.190:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/so.php"] [unique_id "aoSA_fcmepr5_nHgLbNrJgAAAoE"] [Tue Aug 18 12:57:49.729154 2026] [security2:error] [pid 67073:tid 67289] [client 172.182.217.32:15747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/13.php"] [unique_id "aoSA_fcmepr5_nHgLbNrJwAAAmg"] [Tue Aug 18 12:57:49.738435 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:49.738694 2026] [authz_core:error] [pid 67073:tid 67078] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:49.777848 2026] [security2:error] [pid 67073:tid 67259] [client 74.248.18.37:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSA_fcmepr5_nHgLbNrMAAAAko"] [Tue Aug 18 12:57:49.797933 2026] [security2:error] [pid 66623:tid 66793] [client 172.202.39.151:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.advocaciacriminalgo.com.br"] [uri "/item.php"] [unique_id "aoSA_dO5rbWdOArH04KUxgAAASU"] [Tue Aug 18 12:57:49.836059 2026] [security2:error] [pid 66623:tid 66809] [client 86.120.159.145:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUxwAAATU"] [Tue Aug 18 12:57:49.836194 2026] [security2:error] [pid 66623:tid 66809] [client 86.120.159.145:58124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_dO5rbWdOArH04KUxwAAATU"] [Tue Aug 18 12:57:49.892491 2026] [security2:error] [pid 67073:tid 67329] [client 20.100.185.105:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/root.php"] [unique_id "aoSA_fcmepr5_nHgLbNrMgAAApA"] [Tue Aug 18 12:57:49.908021 2026] [security2:error] [pid 67073:tid 67313] [client 40.85.222.29:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNAAAAoA"] [Tue Aug 18 12:57:49.931261 2026] [security2:error] [pid 67073:tid 67275] [client 4.232.151.198:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNgAAAlo"] [Tue Aug 18 12:57:49.978590 2026] [security2:error] [pid 66623:tid 66848] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/inso.php"] [unique_id "aoSA_dO5rbWdOArH04KUyQAAAVw"] [Tue Aug 18 12:57:50.040705 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:50.040977 2026] [authz_core:error] [pid 67073:tid 67196] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:50.041623 2026] [security2:error] [pid 67073:tid 67249] [client 20.186.30.159:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/mac.php"] [unique_id "aoSA_vcmepr5_nHgLbNrOwAAAkA"] [Tue Aug 18 12:57:50.054234 2026] [security2:error] [pid 66623:tid 66792] [client 158.158.34.183:27972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/configs.php"] [unique_id "aoSA_tO5rbWdOArH04KUzgAAASQ"] [Tue Aug 18 12:57:50.065350 2026] [security2:error] [pid 67073:tid 67238] [client 20.119.58.187:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/block-bindings.php"] [unique_id "aoSA_vcmepr5_nHgLbNrPAAAAjU"] [Tue Aug 18 12:57:50.068391 2026] [security2:error] [pid 67073:tid 67207] [client 172.182.200.96:7672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA_vcmepr5_nHgLbNrPgAAAhY"] [Tue Aug 18 12:57:50.082980 2026] [security2:error] [pid 67073:tid 67282] [client 74.248.18.37:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/storage/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQQAAAmE"] [Tue Aug 18 12:57:50.109147 2026] [security2:error] [pid 67073:tid 67233] [client 103.184.169.37:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQgAAAjA"] [Tue Aug 18 12:57:50.109255 2026] [security2:error] [pid 67073:tid 67233] [client 103.184.169.37:42234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrQgAAAjA"] [Tue Aug 18 12:57:50.117566 2026] [security2:error] [pid 67073:tid 67264] [client 68.155.155.199:13353] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/mini"] [unique_id "aoSA_vcmepr5_nHgLbNrQwAAAk8"] [Tue Aug 18 12:57:50.142349 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:62099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSA_tO5rbWdOArH04KU0AAAAVs"] [Tue Aug 18 12:57:50.146261 2026] [security2:error] [pid 66623:tid 66794] [client 20.1.169.243:3403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSA_dO5rbWdOArH04KUygAAASY"] [Tue Aug 18 12:57:50.224407 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.217.32:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/100.php"] [unique_id "aoSA_tO5rbWdOArH04KU0gAAAYk"] [Tue Aug 18 12:57:50.285403 2026] [security2:error] [pid 67073:tid 67300] [client 20.118.172.148:63082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about.php"] [unique_id "aoSA_vcmepr5_nHgLbNrSwAAAnM"] [Tue Aug 18 12:57:50.293378 2026] [security2:error] [pid 67073:tid 67319] [client 40.85.222.29:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTAAAAoY"] [Tue Aug 18 12:57:50.297606 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:1674] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTQAAAlM"] [Tue Aug 18 12:57:50.297739 2026] [security2:error] [pid 67073:tid 67268] [client 20.186.30.159:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTQAAAlM"] [Tue Aug 18 12:57:50.306595 2026] [security2:error] [pid 67073:tid 67281] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/aa.php"] [unique_id "aoSA_vcmepr5_nHgLbNrTwAAAmA"] [Tue Aug 18 12:57:50.320765 2026] [security2:error] [pid 67073:tid 67296] [client 103.120.71.157:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrUAAAAm8"] [Tue Aug 18 12:57:50.320919 2026] [security2:error] [pid 67073:tid 67296] [client 103.120.71.157:56448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrUAAAAm8"] [Tue Aug 18 12:57:50.340177 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:50.340507 2026] [authz_core:error] [pid 67073:tid 67127] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:50.355942 2026] [security2:error] [pid 67073:tid 67266] [client 114.119.135.217:37437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.trokarautomoveis.com.br"] [uri "/photo-resize/2026/975883/gb-b656418.jpg"] [unique_id "aoSA_vcmepr5_nHgLbNrVAAAAlE"], referer: https://www.trokarautomoveis.com.br/veiculo/975883/saveiro-cross-1-6-mi-total-flex-8v-ce [Tue Aug 18 12:57:50.360977 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.200.96:7624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSA_tO5rbWdOArH04KU1AAAASA"] [Tue Aug 18 12:57:50.377336 2026] [security2:error] [pid 67073:tid 67218] [client 213.35.127.232:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrVQAAAiE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:50.419492 2026] [security2:error] [pid 67073:tid 67325] [client 20.119.58.187:12522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/class_api.php"] [unique_id "aoSA_vcmepr5_nHgLbNrVwAAAow"] [Tue Aug 18 12:57:50.444626 2026] [authz_core:error] [pid 67073:tid 67138] [remote 57.141.22.25:35336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:50.445041 2026] [authz_core:error] [pid 67073:tid 67138] [remote 57.141.22.25:35336] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:50.462383 2026] [security2:error] [pid 67073:tid 67253] [client 20.226.56.190:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/10.php"] [unique_id "aoSA_vcmepr5_nHgLbNrWwAAAkQ"] [Tue Aug 18 12:57:50.474583 2026] [security2:error] [pid 67073:tid 67213] [client 52.173.121.69:17960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSA_vcmepr5_nHgLbNrXAAAAhw"] [Tue Aug 18 12:57:50.550716 2026] [security2:error] [pid 66623:tid 66887] [client 20.100.185.105:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/a1.php"] [unique_id "aoSA_tO5rbWdOArH04KU4gAAAYM"] [Tue Aug 18 12:57:50.603468 2026] [security2:error] [pid 67073:tid 67324] [client 68.155.154.236:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNraAAAAos"] [Tue Aug 18 12:57:50.606312 2026] [security2:error] [pid 66623:tid 66820] [client 4.232.151.198:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSA_tO5rbWdOArH04KU5AAAAUA"] [Tue Aug 18 12:57:50.635838 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.18.37:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSA_tO5rbWdOArH04KU5QAAAUg"] [Tue Aug 18 12:57:50.641175 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:50.641471 2026] [authz_core:error] [pid 67073:tid 67145] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:50.646527 2026] [security2:error] [pid 67073:tid 67243] [client 40.85.222.29:26887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrbQAAAjo"] [Tue Aug 18 12:57:50.679673 2026] [security2:error] [pid 66623:tid 66773] [client 158.158.74.177:16518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSA_tO5rbWdOArH04KU5wAAARE"] [Tue Aug 18 12:57:50.685845 2026] [security2:error] [pid 66623:tid 66870] [client 20.203.138.185:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSA_tO5rbWdOArH04KU6AAAAXI"] [Tue Aug 18 12:57:50.717515 2026] [security2:error] [pid 67073:tid 67274] [client 172.182.217.32:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/222.php"] [unique_id "aoSA_vcmepr5_nHgLbNrbwAAAlk"] [Tue Aug 18 12:57:50.742359 2026] [security2:error] [pid 67073:tid 67297] [client 20.100.169.31:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/NewFile.php"] [unique_id "aoSA_vcmepr5_nHgLbNrcgAAAnA"] [Tue Aug 18 12:57:50.759949 2026] [security2:error] [pid 67073:tid 67248] [client 20.186.30.159:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/coffee.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdAAAAj8"] [Tue Aug 18 12:57:50.770633 2026] [security2:error] [pid 67073:tid 67272] [client 74.248.18.37:35330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/storage/rip.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdQAAAlc"] [Tue Aug 18 12:57:50.774156 2026] [security2:error] [pid 67073:tid 67242] [client 20.119.58.187:12510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/root.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdgAAAjk"] [Tue Aug 18 12:57:50.804681 2026] [security2:error] [pid 67073:tid 67219] [client 68.155.155.199:5018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSA_vcmepr5_nHgLbNrdwAAAiI"] [Tue Aug 18 12:57:50.945257 2026] [security2:error] [pid 67073:tid 67275] [client 20.118.172.148:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_vcmepr5_nHgLbNrfQAAAlo"] [Tue Aug 18 12:57:50.948773 2026] [security2:error] [pid 67073:tid 67320] [client 40.85.222.29:25032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSA_vcmepr5_nHgLbNrfgAAAoc"] [Tue Aug 18 12:57:50.971994 2026] [security2:error] [pid 66623:tid 66886] [client 138.36.100.162:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_tO5rbWdOArH04KU6gAAAYI"] [Tue Aug 18 12:57:50.972122 2026] [security2:error] [pid 66623:tid 66886] [client 138.36.100.162:41368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_tO5rbWdOArH04KU6gAAAYI"] [Tue Aug 18 12:57:50.997216 2026] [security2:error] [pid 66623:tid 66863] [client 20.1.169.243:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/goat1.php"] [unique_id "aoSA_tO5rbWdOArH04KU6wAAAWs"] [Tue Aug 18 12:57:51.001375 2026] [security2:error] [pid 67073:tid 67222] [client 119.93.171.138:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.171.93.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imbe.eng.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrgQAAAiU"] [Tue Aug 18 12:57:51.001496 2026] [security2:error] [pid 67073:tid 67222] [client 119.93.171.138:62115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imbe.eng.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_vcmepr5_nHgLbNrgQAAAiU"] [Tue Aug 18 12:57:51.033433 2026] [security2:error] [pid 67073:tid 67236] [client 52.173.121.69:24980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSA__cmepr5_nHgLbNrigAAAjM"] [Tue Aug 18 12:57:51.117507 2026] [security2:error] [pid 67073:tid 67237] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/img.php"] [unique_id "aoSA__cmepr5_nHgLbNrjgAAAjQ"] [Tue Aug 18 12:57:51.122862 2026] [security2:error] [pid 66623:tid 66884] [client 20.186.30.159:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSA_9O5rbWdOArH04KU7AAAAYA"] [Tue Aug 18 12:57:51.130944 2026] [security2:error] [pid 67073:tid 67299] [client 20.119.58.187:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/menu.php"] [unique_id "aoSA__cmepr5_nHgLbNrjwAAAnI"] [Tue Aug 18 12:57:51.153882 2026] [security2:error] [pid 67073:tid 67239] [client 20.226.56.190:28244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/te.php"] [unique_id "aoSA__cmepr5_nHgLbNrkAAAAjY"] [Tue Aug 18 12:57:51.171498 2026] [security2:error] [pid 66623:tid 66772] [client 20.100.185.105:29231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/install.php"] [unique_id "aoSA_9O5rbWdOArH04KU7gAAARA"] [Tue Aug 18 12:57:51.203914 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.217.32:15555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/adminfuns.php"] [unique_id "aoSA_9O5rbWdOArH04KU7wAAAUQ"] [Tue Aug 18 12:57:51.235969 2026] [security2:error] [pid 67073:tid 67300] [client 68.155.154.236:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/.cache/x.php"] [unique_id "aoSA__cmepr5_nHgLbNrkwAAAnM"] [Tue Aug 18 12:57:51.246900 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:51.247165 2026] [authz_core:error] [pid 67073:tid 67140] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:51.261545 2026] [security2:error] [pid 67073:tid 67215] [client 20.206.73.37:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSA__cmepr5_nHgLbNrlQAAAh4"] [Tue Aug 18 12:57:51.265686 2026] [security2:error] [pid 67073:tid 67207] [client 4.232.151.198:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSA__cmepr5_nHgLbNrlwAAAhY"] [Tue Aug 18 12:57:51.275613 2026] [security2:error] [pid 67073:tid 67235] [client 40.74.65.169:43151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSA__cmepr5_nHgLbNrmQAAAjI"] [Tue Aug 18 12:57:51.321326 2026] [security2:error] [pid 66623:tid 66777] [client 40.85.222.29:44277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSA_9O5rbWdOArH04KU8AAAARU"] [Tue Aug 18 12:57:51.366731 2026] [security2:error] [pid 66623:tid 66786] [client 20.1.169.243:3404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSA_9O5rbWdOArH04KU8QAAAR4"] [Tue Aug 18 12:57:51.392634 2026] [security2:error] [pid 67073:tid 67221] [client 213.35.127.232:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSA__cmepr5_nHgLbNrmwAAAiQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:51.473245 2026] [security2:error] [pid 67073:tid 67326] [client 68.155.155.199:11863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about/function.php"] [unique_id "aoSA__cmepr5_nHgLbNroAAAAo0"] [Tue Aug 18 12:57:51.479581 2026] [security2:error] [pid 67073:tid 67280] [client 74.248.18.37:3327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSA__cmepr5_nHgLbNroQAAAl8"] [Tue Aug 18 12:57:51.484425 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:12532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/plugin.php"] [unique_id "aoSA_9O5rbWdOArH04KU9QAAAXA"] [Tue Aug 18 12:57:51.491608 2026] [security2:error] [pid 67073:tid 67283] [client 20.118.133.132:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/8.php"] [unique_id "aoSA__cmepr5_nHgLbNrpAAAAmI"] [Tue Aug 18 12:57:51.491817 2026] [security2:error] [pid 67073:tid 67250] [client 74.248.18.37:35339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/sts.php"] [unique_id "aoSA__cmepr5_nHgLbNrowAAAkE"] [Tue Aug 18 12:57:51.547301 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:51.547556 2026] [authz_core:error] [pid 67073:tid 67169] [remote 216.73.216.206:5480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:51.553807 2026] [security2:error] [pid 67073:tid 67295] [client 20.186.30.159:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSA__cmepr5_nHgLbNrqAAAAm4"] [Tue Aug 18 12:57:51.555470 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/goods.php"] [unique_id "aoSA_9O5rbWdOArH04KU9gAAAU8"] [Tue Aug 18 12:57:51.575268 2026] [security2:error] [pid 67073:tid 67234] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pousadadoreiarthur.com.br"] [uri "/index.php"] [unique_id "aoSA_fcmepr5_nHgLbNrNwACMXY"], referer: https://www.pousadadoreiarthur.com.br/ [Tue Aug 18 12:57:51.653495 2026] [security2:error] [pid 66623:tid 66804] [client 40.85.222.29:25035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSA_9O5rbWdOArH04KU-QAAATA"] [Tue Aug 18 12:57:51.693128 2026] [security2:error] [pid 67073:tid 67332] [client 172.182.217.32:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/abcd.php"] [unique_id "aoSA__cmepr5_nHgLbNrqQAAApM"] [Tue Aug 18 12:57:51.728486 2026] [security2:error] [pid 66623:tid 66841] [client 20.1.169.243:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/h.php"] [unique_id "aoSA_9O5rbWdOArH04KU_AAAAVU"] [Tue Aug 18 12:57:51.732268 2026] [security2:error] [pid 66623:tid 66823] [client 20.203.138.185:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSA_9O5rbWdOArH04KU_gAAAUM"] [Tue Aug 18 12:57:51.754235 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.56.190:28249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/kc.php"] [unique_id "aoSA_9O5rbWdOArH04KU_wAAAWg"] [Tue Aug 18 12:57:51.769298 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.172.148:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/as.php"] [unique_id "aoSA_9O5rbWdOArH04KVAQAAAV0"] [Tue Aug 18 12:57:51.779860 2026] [security2:error] [pid 66623:tid 66816] [client 5.31.227.224:30411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_9O5rbWdOArH04KVAgAAATw"] [Tue Aug 18 12:57:51.784238 2026] [security2:error] [pid 66623:tid 66816] [client 5.31.227.224:30411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSA_9O5rbWdOArH04KVAgAAATw"] [Tue Aug 18 12:57:51.849635 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:11872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cloud.php"] [unique_id "aoSA_9O5rbWdOArH04KVBAAAATE"] [Tue Aug 18 12:57:51.894828 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.151.198:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSA_9O5rbWdOArH04KVBwAAAVk"] [Tue Aug 18 12:57:51.933095 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.155.199:5004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/function/function.php"] [unique_id "aoSA_9O5rbWdOArH04KVCAAAAVw"] [Tue Aug 18 12:57:51.936495 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:17922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSA_9O5rbWdOArH04KVCQAAARI"] [Tue Aug 18 12:57:51.943399 2026] [security2:error] [pid 66623:tid 66885] [client 79.127.164.8:57864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpbb_db_backup_data.bak"] [unique_id "aoSA_9O5rbWdOArH04KVCgAAAYE"], referer: https://medihub.com.br/phpbb_db_backup_data.bak [Tue Aug 18 12:57:51.989422 2026] [security2:error] [pid 66623:tid 66878] [client 20.203.183.135:13092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/yj09.php"] [unique_id "aoSA_9O5rbWdOArH04KVDAAAAXo"] [Tue Aug 18 12:57:51.999950 2026] [security2:error] [pid 66623:tid 66782] [client 40.85.222.29:25073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSA_9O5rbWdOArH04KVDQAAARo"] [Tue Aug 18 12:57:52.017650 2026] [security2:error] [pid 67073:tid 67296] [client 223.185.37.47:17912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqgAAAm8"] [Tue Aug 18 12:57:52.017831 2026] [security2:error] [pid 67073:tid 67296] [client 223.185.37.47:17912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqgAAAm8"] [Tue Aug 18 12:57:52.056088 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.154.236:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBANO5rbWdOArH04KVEgAAAVA"] [Tue Aug 18 12:57:52.056087 2026] [security2:error] [pid 66623:tid 66865] [client 149.34.210.141:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVEwAAAW0"] [Tue Aug 18 12:57:52.072280 2026] [security2:error] [pid 66623:tid 66862] [client 157.20.138.62:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVFAAAAWo"] [Tue Aug 18 12:57:52.072422 2026] [security2:error] [pid 66623:tid 66862] [client 157.20.138.62:49730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVFAAAAWo"] [Tue Aug 18 12:57:52.080371 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.185.105:29226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/file2.php"] [unique_id "aoSBANO5rbWdOArH04KVFgAAAVE"] [Tue Aug 18 12:57:52.086866 2026] [security2:error] [pid 67073:tid 67321] [client 20.250.13.23:52380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.clebiogalvao.com.br"] [uri "/php.php"] [unique_id "aoSBAPcmepr5_nHgLbNrqwAAAog"] [Tue Aug 18 12:57:52.092364 2026] [security2:error] [pid 66623:tid 66844] [client 20.1.169.243:3664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/import/csv1.php"] [unique_id "aoSBANO5rbWdOArH04KVGAAAAVg"] [Tue Aug 18 12:57:52.104892 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.56.190:47136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/jn.php"] [unique_id "aoSBANO5rbWdOArH04KVGgAAAX0"] [Tue Aug 18 12:57:52.106238 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:26688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/aaa.php"] [unique_id "aoSBANO5rbWdOArH04KVGwAAASg"] [Tue Aug 18 12:57:52.114597 2026] [security2:error] [pid 66623:tid 66802] [client 74.248.18.37:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBANO5rbWdOArH04KVHAAAAS4"] [Tue Aug 18 12:57:52.137289 2026] [security2:error] [pid 66623:tid 66828] [client 20.186.30.159:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/yj09.php"] [unique_id "aoSBANO5rbWdOArH04KVHQAAAUg"] [Tue Aug 18 12:57:52.146859 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/system_log.php"] [unique_id "aoSBANO5rbWdOArH04KVHgAAAWY"] [Tue Aug 18 12:57:52.214208 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/al.php"] [unique_id "aoSBANO5rbWdOArH04KVIQAAASY"] [Tue Aug 18 12:57:52.215516 2026] [security2:error] [pid 66623:tid 66800] [client 20.119.58.187:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/configs.php"] [unique_id "aoSBANO5rbWdOArH04KVIgAAASw"] [Tue Aug 18 12:57:52.274564 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:52.274833 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:52.278784 2026] [security2:error] [pid 66623:tid 66886] [client 40.85.222.29:26914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBANO5rbWdOArH04KVJQAAAYI"] [Tue Aug 18 12:57:52.279421 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:52.279879 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:52.335898 2026] [security2:error] [pid 66623:tid 66865] [client 149.34.210.141:59186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBANO5rbWdOArH04KVEwAAAW0"] [Tue Aug 18 12:57:52.368822 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:2705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/php8.php"] [unique_id "aoSBANO5rbWdOArH04KVKAAAAXM"] [Tue Aug 18 12:57:52.407707 2026] [security2:error] [pid 66623:tid 66893] [client 213.35.127.232:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBANO5rbWdOArH04KVKwAAAYk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:52.410334 2026] [security2:error] [pid 66623:tid 66838] [client 20.118.172.148:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/bolt.php"] [unique_id "aoSBANO5rbWdOArH04KVLAAAAVI"] [Tue Aug 18 12:57:52.417995 2026] [security2:error] [pid 66623:tid 66793] [client 20.100.169.31:48424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lubarbosaassessoria.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBANO5rbWdOArH04KVLgAAASU"] [Tue Aug 18 12:57:52.422847 2026] [autoindex:error] [pid 66623:tid 66824] [client 82.102.18.182:58610] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:52.456772 2026] [security2:error] [pid 66623:tid 66790] [client 20.1.169.243:3679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/index.bak.php"] [unique_id "aoSBANO5rbWdOArH04KVLwAAASI"] [Tue Aug 18 12:57:52.473489 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:52.473743 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:52.537252 2026] [security2:error] [pid 66623:tid 66803] [client 68.155.155.199:6638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBANO5rbWdOArH04KVNQAAAS8"] [Tue Aug 18 12:57:52.567976 2026] [security2:error] [pid 66623:tid 66770] [client 20.226.56.190:2089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rakhomed.com.br"] [uri "/bf.php"] [unique_id "aoSBANO5rbWdOArH04KVOAAAAQ4"] [Tue Aug 18 12:57:52.568238 2026] [security2:error] [pid 66623:tid 66786] [client 20.119.58.187:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBANO5rbWdOArH04KVOQAAAR4"] [Tue Aug 18 12:57:52.568372 2026] [security2:error] [pid 66623:tid 66841] [client 40.85.222.29:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBANO5rbWdOArH04KVOgAAAVU"] [Tue Aug 18 12:57:52.663281 2026] [security2:error] [pid 66623:tid 66785] [client 20.48.236.86:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/8.php"] [unique_id "aoSBANO5rbWdOArH04KVSAAAAR0"] [Tue Aug 18 12:57:52.683855 2026] [security2:error] [pid 66623:tid 66889] [client 4.232.151.198:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBANO5rbWdOArH04KVMwAAAYU"] [Tue Aug 18 12:57:52.697868 2026] [security2:error] [pid 66623:tid 66795] [client 20.186.30.159:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/scxy.php"] [unique_id "aoSBANO5rbWdOArH04KVSQAAASc"] [Tue Aug 18 12:57:52.705144 2026] [security2:error] [pid 66623:tid 66787] [client 172.182.217.32:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/alfa.php"] [unique_id "aoSBANO5rbWdOArH04KVSgAAAR8"] [Tue Aug 18 12:57:52.710798 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.154.236:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBANO5rbWdOArH04KVSwAAAVw"] [Tue Aug 18 12:57:52.711480 2026] [security2:error] [pid 66623:tid 66784] [client 20.100.185.105:41015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBANO5rbWdOArH04KVTAAAARw"] [Tue Aug 18 12:57:52.718990 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBANO5rbWdOArH04KVUQAAAWE"] [Tue Aug 18 12:57:52.752623 2026] [security2:error] [pid 66623:tid 66813] [client 20.203.138.185:35049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws61.php"] [unique_id "aoSBANO5rbWdOArH04KVVAAAATk"] [Tue Aug 18 12:57:52.752831 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBANO5rbWdOArH04KVVQAAATA"] [Tue Aug 18 12:57:52.799824 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/info.php"] [unique_id "aoSBANO5rbWdOArH04KVVwAAAT8"] [Tue Aug 18 12:57:52.820370 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:21508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/t.php"] [unique_id "aoSBANO5rbWdOArH04KVWQAAASo"] [Tue Aug 18 12:57:52.821889 2026] [security2:error] [pid 66623:tid 66880] [client 20.1.169.243:3655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/lite.php"] [unique_id "aoSBANO5rbWdOArH04KVWgAAAXw"] [Tue Aug 18 12:57:52.875746 2026] [autoindex:error] [pid 66623:tid 66823] [client 158.158.74.177:2687] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:52.915668 2026] [security2:error] [pid 66623:tid 66852] [client 40.85.222.29:25046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBANO5rbWdOArH04KVYQAAAWA"] [Tue Aug 18 12:57:52.921949 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/update.php"] [unique_id "aoSBANO5rbWdOArH04KVYwAAAVA"] [Tue Aug 18 12:57:52.966538 2026] [security2:error] [pid 66623:tid 66828] [client 40.74.65.169:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gecko.php"] [unique_id "aoSBANO5rbWdOArH04KVaAAAAUg"] [Tue Aug 18 12:57:52.982432 2026] [security2:error] [pid 66623:tid 66825] [client 20.186.30.159:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBANO5rbWdOArH04KVaQAAAUU"] [Tue Aug 18 12:57:52.991901 2026] [security2:error] [pid 66623:tid 66834] [client 213.202.253.4:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/txets.php"] [unique_id "aoSBANO5rbWdOArH04KVagAAAU4"], referer: www.google.com [Tue Aug 18 12:57:53.026845 2026] [security2:error] [pid 66623:tid 66864] [client 178.153.171.161:47335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVbQAAAWw"] [Tue Aug 18 12:57:53.026987 2026] [security2:error] [pid 66623:tid 66864] [client 178.153.171.161:47335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVbQAAAWw"] [Tue Aug 18 12:57:53.107602 2026] [security2:error] [pid 66623:tid 66649] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVcQABGww"] [Tue Aug 18 12:57:53.107754 2026] [security2:error] [pid 66623:tid 66783] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAdO5rbWdOArH04KVcQABGww"] [Tue Aug 18 12:57:53.125166 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.155.199:7138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/f35.php"] [unique_id "aoSBAdO5rbWdOArH04KVdgAAAXY"] [Tue Aug 18 12:57:53.151425 2026] [security2:error] [pid 66623:tid 66871] [client 68.155.154.236:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBAdO5rbWdOArH04KVdwAAAXM"] [Tue Aug 18 12:57:53.183935 2026] [security2:error] [pid 66623:tid 66877] [client 20.1.169.243:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/live.php"] [unique_id "aoSBAdO5rbWdOArH04KVewAAAXk"] [Tue Aug 18 12:57:53.192899 2026] [security2:error] [pid 66623:tid 66838] [client 52.173.121.69:17925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBAdO5rbWdOArH04KVfQAAAVI"] [Tue Aug 18 12:57:53.196241 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/as.php"] [unique_id "aoSBAdO5rbWdOArH04KVfgAAASY"] [Tue Aug 18 12:57:53.242597 2026] [security2:error] [pid 66623:tid 66793] [client 40.85.222.29:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBAdO5rbWdOArH04KVfwAAASU"] [Tue Aug 18 12:57:53.269210 2026] [security2:error] [pid 66623:tid 66861] [client 92.222.108.115:56024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kuringacomunicacao.com.br"] [uri "/robots.txt"] [unique_id "aoSBAdO5rbWdOArH04KVggAAAWk"] [Tue Aug 18 12:57:53.269316 2026] [security2:error] [pid 66623:tid 66861] [client 92.222.108.115:56024] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kuringacomunicacao.com.br"] [uri "/robots.txt"] [unique_id "aoSBAdO5rbWdOArH04KVggAAAWk"] [Tue Aug 18 12:57:53.277982 2026] [security2:error] [pid 66623:tid 66773] [client 158.158.34.183:43663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/delpaths.php"] [unique_id "aoSBAdO5rbWdOArH04KVgwAAARE"] [Tue Aug 18 12:57:53.283982 2026] [security2:error] [pid 66623:tid 66790] [client 20.118.133.132:15397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/biufile.php"] [unique_id "aoSBAdO5rbWdOArH04KVhQAAASI"] [Tue Aug 18 12:57:53.292966 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBAdO5rbWdOArH04KVhgAAATc"] [Tue Aug 18 12:57:53.301492 2026] [security2:error] [pid 66623:tid 66810] [client 172.182.200.96:14182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/update/wpupex.php"] [unique_id "aoSBAdO5rbWdOArH04KViAAAATY"] [Tue Aug 18 12:57:53.304202 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBAdO5rbWdOArH04KViQAAAUk"] [Tue Aug 18 12:57:53.318971 2026] [security2:error] [pid 66623:tid 66797] [client 20.119.58.187:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/input.php"] [unique_id "aoSBAdO5rbWdOArH04KVigAAASk"] [Tue Aug 18 12:57:53.329408 2026] [security2:error] [pid 66623:tid 66850] [client 20.100.185.105:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KViwAAAV4"] [Tue Aug 18 12:57:53.350184 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBAdO5rbWdOArH04KVjgAAATM"] [Tue Aug 18 12:57:53.420603 2026] [security2:error] [pid 66623:tid 66869] [client 213.35.127.232:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBAdO5rbWdOArH04KVkgAAAXE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:53.446613 2026] [security2:error] [pid 66623:tid 66814] [client 20.118.172.148:43488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/chosen.php"] [unique_id "aoSBAdO5rbWdOArH04KVlAAAATo"] [Tue Aug 18 12:57:53.461648 2026] [security2:error] [pid 66623:tid 66804] [client 20.65.98.162:8372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "gruposchopan.com.br"] [uri "/.mopj.php"] [unique_id "aoSBAdO5rbWdOArH04KVlgAAATA"] [Tue Aug 18 12:57:53.527344 2026] [security2:error] [pid 66623:tid 66837] [client 40.85.222.29:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBAdO5rbWdOArH04KVmgAAAVE"] [Tue Aug 18 12:57:53.542163 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.18.37:20543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/templates.php"] [unique_id "aoSBAdO5rbWdOArH04KVmwAAAQ0"] [Tue Aug 18 12:57:53.551828 2026] [security2:error] [pid 66623:tid 66795] [client 20.1.169.243:3417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/bypass.php"] [unique_id "aoSBAdO5rbWdOArH04KVnQAAASc"] [Tue Aug 18 12:57:53.646891 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rum.php"] [unique_id "aoSBAdO5rbWdOArH04KVogAAASg"] [Tue Aug 18 12:57:53.671029 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/geju.php"] [unique_id "aoSBAdO5rbWdOArH04KVpAAAASM"] [Tue Aug 18 12:57:53.684817 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:53.685080 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:53.686078 2026] [security2:error] [pid 66623:tid 66867] [client 172.182.217.32:15612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/aa.php"] [unique_id "aoSBAdO5rbWdOArH04KVpgAAAW8"] [Tue Aug 18 12:57:53.723506 2026] [security2:error] [pid 66623:tid 66834] [client 158.158.74.177:2687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBAdO5rbWdOArH04KVqAAAAU4"] [Tue Aug 18 12:57:53.750748 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:43137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/xiugai.php"] [unique_id "aoSBAdO5rbWdOArH04KVrAAAAV8"] [Tue Aug 18 12:57:53.804388 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBAdO5rbWdOArH04KVtgAAAXM"] [Tue Aug 18 12:57:53.817044 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBAdO5rbWdOArH04KVvAAAAVI"] [Tue Aug 18 12:57:53.817147 2026] [security2:error] [pid 66623:tid 66794] [client 74.248.18.37:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBAdO5rbWdOArH04KVvQAAASY"] [Tue Aug 18 12:57:53.837267 2026] [security2:error] [pid 66623:tid 66862] [client 20.226.6.191:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBAdO5rbWdOArH04KVzQAAAWo"] [Tue Aug 18 12:57:53.853166 2026] [security2:error] [pid 66623:tid 66824] [client 20.226.6.191:4046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KVzgAAAUQ"] [Tue Aug 18 12:57:53.854966 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBAdO5rbWdOArH04KVzwAAAWk"] [Tue Aug 18 12:57:53.865203 2026] [security2:error] [pid 66623:tid 66811] [client 68.155.155.199:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/gg.php"] [unique_id "aoSBAdO5rbWdOArH04KV0AAAATc"] [Tue Aug 18 12:57:53.881242 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/inso.php"] [unique_id "aoSBAdO5rbWdOArH04KV0QAAAUc"] [Tue Aug 18 12:57:53.885131 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.6.191:4075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/public/css.php"] [unique_id "aoSBAdO5rbWdOArH04KV0wAAAS8"] [Tue Aug 18 12:57:53.895799 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:21514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/g.php"] [unique_id "aoSBAdO5rbWdOArH04KV1AAAAQ4"] [Tue Aug 18 12:57:53.906491 2026] [access_compat:error] [pid 66623:tid 66874] [client 192.178.4.34:61666] AH01797: client denied by server configuration: /home1/classea/public_html/robots.txt [Tue Aug 18 12:57:53.910415 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBAdO5rbWdOArH04KV1gAAAWg"] [Tue Aug 18 12:57:53.926168 2026] [security2:error] [pid 66623:tid 66781] [client 68.155.154.236:7895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBAdO5rbWdOArH04KV2gAAARk"] [Tue Aug 18 12:57:53.944243 2026] [security2:error] [pid 66623:tid 66768] [client 4.232.151.198:24956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBAdO5rbWdOArH04KV3AAAAQw"] [Tue Aug 18 12:57:53.954611 2026] [security2:error] [pid 66623:tid 66832] [client 20.100.185.105:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/123.php"] [unique_id "aoSBAdO5rbWdOArH04KV3gAAAUw"] [Tue Aug 18 12:57:53.968195 2026] [security2:error] [pid 66623:tid 66888] [client 170.81.43.147:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.43.81.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.fbenevides.com.br"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "aoSBAdO5rbWdOArH04KV4AAAAYQ"] [Tue Aug 18 12:57:53.999318 2026] [security2:error] [pid 66623:tid 66845] [client 20.226.6.191:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBAdO5rbWdOArH04KV4gAAAVk"] [Tue Aug 18 12:57:54.007933 2026] [security2:error] [pid 66623:tid 66808] [client 85.154.68.202:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV4wAAATQ"] [Tue Aug 18 12:57:54.008092 2026] [security2:error] [pid 66623:tid 66808] [client 85.154.68.202:55496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV4wAAATQ"] [Tue Aug 18 12:57:54.015532 2026] [security2:error] [pid 67073:tid 67301] [client 107.150.61.58:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.61.150.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.h6.com.br"] [uri "/wp-includes/admin.php"] [unique_id "aoSBAvcmepr5_nHgLbNrrAAAAnQ"], referer: https://mail.h6.com.br/wp-includes/admin.php [Tue Aug 18 12:57:54.035896 2026] [security2:error] [pid 66623:tid 66892] [client 20.119.58.187:12068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp.php"] [unique_id "aoSBAtO5rbWdOArH04KV5QAAAYg"] [Tue Aug 18 12:57:54.065619 2026] [security2:error] [pid 66623:tid 66876] [client 20.186.30.159:1942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/blurbs.php"] [unique_id "aoSBAtO5rbWdOArH04KV5gAAAXg"] [Tue Aug 18 12:57:54.079052 2026] [security2:error] [pid 66623:tid 66819] [client 20.226.6.191:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gelay.php"] [unique_id "aoSBAtO5rbWdOArH04KV6QAAAT8"] [Tue Aug 18 12:57:54.121353 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.18.37:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gecko.php"] [unique_id "aoSBAtO5rbWdOArH04KV6wAAAVU"] [Tue Aug 18 12:57:54.156868 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.172.148:63097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/simple.php"] [unique_id "aoSBAtO5rbWdOArH04KV7QAAAS0"] [Tue Aug 18 12:57:54.158308 2026] [security2:error] [pid 66623:tid 66779] [client 40.85.222.29:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBAtO5rbWdOArH04KV7gAAARc"] [Tue Aug 18 12:57:54.176254 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.217.32:15583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/abc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8AAAAU8"] [Tue Aug 18 12:57:54.176402 2026] [security2:error] [pid 66623:tid 66795] [client 20.226.6.191:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KV8QAAASc"] [Tue Aug 18 12:57:54.208126 2026] [security2:error] [pid 66623:tid 66774] [client 114.5.214.109:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8wAAARI"] [Tue Aug 18 12:57:54.212209 2026] [security2:error] [pid 66623:tid 66774] [client 114.5.214.109:49817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV8wAAARI"] [Tue Aug 18 12:57:54.215586 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:35341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/term.php"] [unique_id "aoSBAtO5rbWdOArH04KV9AAAATE"] [Tue Aug 18 12:57:54.283360 2026] [security2:error] [pid 66623:tid 66856] [client 20.226.6.191:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBAtO5rbWdOArH04KV-gAAAWQ"] [Tue Aug 18 12:57:54.284196 2026] [authz_core:error] [pid 66623:tid 66703] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:54.284479 2026] [authz_core:error] [pid 66623:tid 66703] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:54.325411 2026] [security2:error] [pid 66623:tid 66821] [client 160.120.140.123:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV-wAAAUE"] [Tue Aug 18 12:57:54.325547 2026] [security2:error] [pid 66623:tid 66821] [client 160.120.140.123:50314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KV-wAAAUE"] [Tue Aug 18 12:57:54.339953 2026] [security2:error] [pid 66623:tid 66764] [remote 135.236.141.8:6443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KV_wABIX8"] [Tue Aug 18 12:57:54.369592 2026] [security2:error] [pid 66623:tid 66886] [client 20.1.169.243:3684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/lock360.php"] [unique_id "aoSBAtO5rbWdOArH04KWBAAAAYI"] [Tue Aug 18 12:57:54.370835 2026] [security2:error] [pid 66623:tid 66863] [client 20.226.6.191:4005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBAtO5rbWdOArH04KWBQAAAWs"] [Tue Aug 18 12:57:54.390521 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hoot.php"] [unique_id "aoSBAtO5rbWdOArH04KWBwAAASg"] [Tue Aug 18 12:57:54.391112 2026] [security2:error] [pid 66623:tid 66893] [client 20.226.6.191:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/about.php"] [unique_id "aoSBAtO5rbWdOArH04KWCAAAAYk"] [Tue Aug 18 12:57:54.419727 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWCQAAASY"] [Tue Aug 18 12:57:54.421005 2026] [security2:error] [pid 66623:tid 66833] [client 20.118.172.148:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/edit.php"] [unique_id "aoSBAtO5rbWdOArH04KWCgAAAU0"] [Tue Aug 18 12:57:54.429104 2026] [security2:error] [pid 66623:tid 66862] [client 52.173.121.69:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBAtO5rbWdOArH04KWDAAAAWo"] [Tue Aug 18 12:57:54.437357 2026] [security2:error] [pid 66623:tid 66846] [client 213.35.127.232:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KWDgAAAVo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:54.438961 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.200.96:7616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/install.php"] [unique_id "aoSBAtO5rbWdOArH04KWDwAAARE"] [Tue Aug 18 12:57:54.450186 2026] [security2:error] [pid 66623:tid 66790] [client 68.155.154.236:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBAtO5rbWdOArH04KWEQAAASI"] [Tue Aug 18 12:57:54.480907 2026] [security2:error] [pid 66623:tid 66812] [client 40.85.222.29:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWFAAAATg"] [Tue Aug 18 12:57:54.539233 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/bajah.php"] [unique_id "aoSBAtO5rbWdOArH04KWGQAAATM"] [Tue Aug 18 12:57:54.548486 2026] [security2:error] [pid 66623:tid 66854] [client 40.74.65.169:27745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/adminner.php"] [unique_id "aoSBAtO5rbWdOArH04KWGwAAAWI"] [Tue Aug 18 12:57:54.572954 2026] [security2:error] [pid 66623:tid 66806] [client 20.100.185.105:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cc.php"] [unique_id "aoSBAtO5rbWdOArH04KWHQAAATI"] [Tue Aug 18 12:57:54.589365 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:54.589787 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:54.602237 2026] [security2:error] [pid 66623:tid 66785] [client 20.203.138.185:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ze.php"] [unique_id "aoSBAtO5rbWdOArH04KWIAAAAR0"] [Tue Aug 18 12:57:54.603153 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/f35.php"] [unique_id "aoSBAtO5rbWdOArH04KWIQAAATU"] [Tue Aug 18 12:57:54.624340 2026] [security2:error] [pid 66623:tid 66661] [remote 47.86.33.52:31798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBAtO5rbWdOArH04KWIwABFRg"] [Tue Aug 18 12:57:54.647379 2026] [security2:error] [pid 66623:tid 66853] [client 158.158.74.177:2630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWKwAAAWE"] [Tue Aug 18 12:57:54.654974 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:11875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/class.php"] [unique_id "aoSBAtO5rbWdOArH04KWLAAAAVg"] [Tue Aug 18 12:57:54.667380 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:3844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBAtO5rbWdOArH04KWLgAAAYY"] [Tue Aug 18 12:57:54.668969 2026] [security2:error] [pid 66623:tid 66811] [client 4.232.151.198:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KWLwAAATc"] [Tue Aug 18 12:57:54.671569 2026] [security2:error] [pid 66623:tid 66786] [client 172.182.217.32:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/av.php"] [unique_id "aoSBAtO5rbWdOArH04KWMAAAAR4"] [Tue Aug 18 12:57:54.683645 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KWMQAAAWM"] [Tue Aug 18 12:57:54.683777 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:65514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBAtO5rbWdOArH04KWMQAAAWM"] [Tue Aug 18 12:57:54.718826 2026] [security2:error] [pid 66623:tid 66837] [client 54.39.0.186:62924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "kuringacomunicacao.com.br"] [uri "/"] [unique_id "aoSBAtO5rbWdOArH04KWNQAAAVE"] [Tue Aug 18 12:57:54.718933 2026] [security2:error] [pid 66623:tid 66837] [client 54.39.0.186:62924] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kuringacomunicacao.com.br"] [uri "/"] [unique_id "aoSBAtO5rbWdOArH04KWNQAAAVE"] [Tue Aug 18 12:57:54.722740 2026] [security2:error] [pid 66623:tid 66797] [client 158.158.34.183:29805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/NewFile.php"] [unique_id "aoSBAtO5rbWdOArH04KWNgAAASk"] [Tue Aug 18 12:57:54.745592 2026] [security2:error] [pid 66623:tid 66848] [client 20.119.58.187:11843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBAtO5rbWdOArH04KWPQAAAVw"] [Tue Aug 18 12:57:54.753893 2026] [security2:error] [pid 66623:tid 66852] [client 20.118.172.148:53057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBAtO5rbWdOArH04KWQAAAAWA"] [Tue Aug 18 12:57:54.762294 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/inputs.php"] [unique_id "aoSBAtO5rbWdOArH04KWQgAAARI"] [Tue Aug 18 12:57:54.774442 2026] [security2:error] [pid 66623:tid 66798] [client 20.215.241.237:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBAtO5rbWdOArH04KWQwAAASo"] [Tue Aug 18 12:57:54.792619 2026] [security2:error] [pid 66623:tid 66827] [client 20.100.169.31:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-good.php"] [unique_id "aoSBAtO5rbWdOArH04KWRQAAAUc"] [Tue Aug 18 12:57:54.793580 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:21530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gettest.php"] [unique_id "aoSBAtO5rbWdOArH04KWRwAAARs"] [Tue Aug 18 12:57:54.805677 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:25048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBAtO5rbWdOArH04KWSAAAAYM"] [Tue Aug 18 12:57:54.836547 2026] [security2:error] [pid 66623:tid 66834] [client 68.155.154.236:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBAtO5rbWdOArH04KWTgAAAU4"] [Tue Aug 18 12:57:54.864570 2026] [security2:error] [pid 66623:tid 66851] [client 20.226.6.191:3983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/alfa.php"] [unique_id "aoSBAtO5rbWdOArH04KWTwAAAV8"] [Tue Aug 18 12:57:54.883004 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.6.191:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/lock360.php"] [unique_id "aoSBAtO5rbWdOArH04KWUAAAAYA"] [Tue Aug 18 12:57:54.901579 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:54964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/test.php"] [unique_id "aoSBAtO5rbWdOArH04KWUQAAAYg"] [Tue Aug 18 12:57:54.904093 2026] [security2:error] [pid 66623:tid 66893] [client 20.226.6.191:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/flower.php"] [unique_id "aoSBAtO5rbWdOArH04KWUgAAAYk"] [Tue Aug 18 12:57:54.928120 2026] [security2:error] [pid 66623:tid 66838] [client 20.226.6.191:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/13.php"] [unique_id "aoSBAtO5rbWdOArH04KWVAAAAVI"] [Tue Aug 18 12:57:54.941557 2026] [security2:error] [pid 66623:tid 66833] [client 20.226.6.191:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cc.php"] [unique_id "aoSBAtO5rbWdOArH04KWVgAAAU0"] [Tue Aug 18 12:57:54.969432 2026] [security2:error] [pid 66623:tid 66773] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/222.php"] [unique_id "aoSBAtO5rbWdOArH04KWVwAAARE"] [Tue Aug 18 12:57:55.012472 2026] [security2:error] [pid 66623:tid 66807] [client 20.226.6.191:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBA9O5rbWdOArH04KWWgAAATM"] [Tue Aug 18 12:57:55.036518 2026] [security2:error] [pid 66623:tid 66806] [client 20.226.6.191:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBA9O5rbWdOArH04KWWwAAATI"] [Tue Aug 18 12:57:55.061333 2026] [security2:error] [pid 66623:tid 66830] [client 20.226.6.191:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/01.php"] [unique_id "aoSBA9O5rbWdOArH04KWXAAAAUo"] [Tue Aug 18 12:57:55.080281 2026] [security2:error] [pid 66623:tid 66847] [client 20.226.6.191:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/lv.php"] [unique_id "aoSBA9O5rbWdOArH04KWXQAAAVs"] [Tue Aug 18 12:57:55.103230 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:12074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/db-cache.php"] [unique_id "aoSBA9O5rbWdOArH04KWXwAAAWk"] [Tue Aug 18 12:57:55.104465 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:26942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWYAAAASQ"] [Tue Aug 18 12:57:55.104620 2026] [security2:error] [pid 66623:tid 66879] [client 20.226.6.191:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/new.php"] [unique_id "aoSBA9O5rbWdOArH04KWYQAAAXs"] [Tue Aug 18 12:57:55.105896 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.200.96:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWYgAAAWE"] [Tue Aug 18 12:57:55.125168 2026] [security2:error] [pid 66623:tid 66811] [client 20.226.6.191:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/222.php"] [unique_id "aoSBA9O5rbWdOArH04KWZAAAATc"] [Tue Aug 18 12:57:55.148470 2026] [security2:error] [pid 66623:tid 66845] [client 20.1.169.243:3697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWZQAAAVk"] [Tue Aug 18 12:57:55.157901 2026] [security2:error] [pid 66623:tid 66819] [client 20.186.30.159:1935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/domvf.php"] [unique_id "aoSBA9O5rbWdOArH04KWawAAAT8"] [Tue Aug 18 12:57:55.159546 2026] [security2:error] [pid 66623:tid 66803] [client 172.182.217.32:15576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBA9O5rbWdOArH04KWbAAAAS8"] [Tue Aug 18 12:57:55.175679 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/chosen.php"] [unique_id "aoSBA9O5rbWdOArH04KWcQAAAVY"] [Tue Aug 18 12:57:55.187995 2026] [authz_core:error] [pid 66623:tid 66715] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:55.188266 2026] [authz_core:error] [pid 66623:tid 66715] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:55.190877 2026] [security2:error] [pid 66623:tid 66880] [client 20.226.6.191:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/info.php"] [unique_id "aoSBA9O5rbWdOArH04KWdAAAAXw"] [Tue Aug 18 12:57:55.196954 2026] [security2:error] [pid 66623:tid 66817] [client 20.118.172.148:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/av.php"] [unique_id "aoSBA9O5rbWdOArH04KWdgAAAT0"] [Tue Aug 18 12:57:55.211002 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/flower.php"] [unique_id "aoSBA9O5rbWdOArH04KWdwAAAUA"] [Tue Aug 18 12:57:55.211016 2026] [security2:error] [pid 66623:tid 66874] [client 20.100.185.105:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-logs.php"] [unique_id "aoSBA9O5rbWdOArH04KWeAAAAXY"] [Tue Aug 18 12:57:55.246884 2026] [security2:error] [pid 66623:tid 66775] [client 20.226.6.191:3987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWhAAAARM"] [Tue Aug 18 12:57:55.277759 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.6.191:3969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWhgAAARs"] [Tue Aug 18 12:57:55.286441 2026] [security2:error] [pid 66623:tid 66887] [client 172.182.200.96:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBA9O5rbWdOArH04KWiAAAAYM"] [Tue Aug 18 12:57:55.292989 2026] [security2:error] [pid 66623:tid 66839] [client 4.232.151.198:4334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWiQAAAVM"] [Tue Aug 18 12:57:55.304590 2026] [security2:error] [pid 66623:tid 66858] [client 68.155.154.236:7912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWigAAAWY"] [Tue Aug 18 12:57:55.310842 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/k.php"] [unique_id "aoSBA9O5rbWdOArH04KWiwAAAWg"] [Tue Aug 18 12:57:55.321487 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:55804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBA9O5rbWdOArH04KWjAAAARw"] [Tue Aug 18 12:57:55.327390 2026] [security2:error] [pid 66623:tid 66883] [client 20.203.138.185:10612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gjm.php"] [unique_id "aoSBA9O5rbWdOArH04KWjQAAAX8"] [Tue Aug 18 12:57:55.369448 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.133.132:15373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/coffexium.php"] [unique_id "aoSBA9O5rbWdOArH04KWkgAAAYk"] [Tue Aug 18 12:57:55.375396 2026] [security2:error] [pid 66623:tid 66843] [client 20.226.6.191:4087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/403.php"] [unique_id "aoSBA9O5rbWdOArH04KWkwAAAVc"] [Tue Aug 18 12:57:55.386440 2026] [security2:error] [pid 66623:tid 66837] [client 79.127.164.8:57896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpbb_db_backup_data.sql"] [unique_id "aoSBA9O5rbWdOArH04KWlQAAAVE"], referer: https://medihub.com.br/phpbb_db_backup_data.sql [Tue Aug 18 12:57:55.450889 2026] [security2:error] [pid 66623:tid 66890] [client 213.35.127.232:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWmgAAAYY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:55.458735 2026] [security2:error] [pid 66623:tid 66776] [client 20.119.58.187:12082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "aoSBA9O5rbWdOArH04KWnAAAARQ"] [Tue Aug 18 12:57:55.463887 2026] [security2:error] [pid 66623:tid 66773] [client 40.74.65.169:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file1221.php"] [unique_id "aoSBA9O5rbWdOArH04KWnQAAARE"] [Tue Aug 18 12:57:55.474522 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/goods.php"] [unique_id "aoSBA9O5rbWdOArH04KWogAAAQ8"] [Tue Aug 18 12:57:55.488378 2026] [security2:error] [pid 66623:tid 66829] [client 20.226.6.191:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/gecko.php"] [unique_id "aoSBA9O5rbWdOArH04KWqQAAAUk"] [Tue Aug 18 12:57:55.492922 2026] [authz_core:error] [pid 66623:tid 66649] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:55.493334 2026] [authz_core:error] [pid 66623:tid 66649] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:55.499823 2026] [security2:error] [pid 66623:tid 66866] [client 40.85.222.29:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBA9O5rbWdOArH04KWqgAAAW4"] [Tue Aug 18 12:57:55.515586 2026] [security2:error] [pid 66623:tid 66877] [client 20.1.169.243:3416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/pwnd/as.php"] [unique_id "aoSBA9O5rbWdOArH04KWrQAAAXk"] [Tue Aug 18 12:57:55.530093 2026] [security2:error] [pid 66623:tid 66830] [client 20.226.6.191:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/aa.php"] [unique_id "aoSBA9O5rbWdOArH04KWrgAAAUo"] [Tue Aug 18 12:57:55.551065 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/test1.php"] [unique_id "aoSBA9O5rbWdOArH04KWrwAAASE"] [Tue Aug 18 12:57:55.594194 2026] [security2:error] [pid 66623:tid 66808] [client 20.226.6.191:3972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/0x.php"] [unique_id "aoSBA9O5rbWdOArH04KWsQAAATQ"] [Tue Aug 18 12:57:55.597528 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ff1.php"] [unique_id "aoSBA9O5rbWdOArH04KWsgAAAWk"] [Tue Aug 18 12:57:55.632549 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.6.191:3981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/zxz.php"] [unique_id "aoSBA9O5rbWdOArH04KWtAAAAVQ"] [Tue Aug 18 12:57:55.647266 2026] [security2:error] [pid 66623:tid 66786] [client 20.226.6.191:4032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/www.php"] [unique_id "aoSBA9O5rbWdOArH04KWtQAAAR4"] [Tue Aug 18 12:57:55.648769 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.217.32:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/asus.php"] [unique_id "aoSBA9O5rbWdOArH04KWtgAAATg"] [Tue Aug 18 12:57:55.656423 2026] [security2:error] [pid 66623:tid 66855] [client 20.206.73.37:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/puc.php"] [unique_id "aoSBA9O5rbWdOArH04KWuQAAAWM"] [Tue Aug 18 12:57:55.670630 2026] [security2:error] [pid 66623:tid 66760] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.info.php"] [unique_id "aoSBA9O5rbWdOArH04KWugABWXs"] [Tue Aug 18 12:57:55.725836 2026] [security2:error] [pid 66623:tid 66797] [client 20.226.6.191:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wicked.php"] [unique_id "aoSBA9O5rbWdOArH04KWvwAAASk"] [Tue Aug 18 12:57:55.770356 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.6.191:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBA9O5rbWdOArH04KWwwAAAXI"] [Tue Aug 18 12:57:55.779925 2026] [security2:error] [pid 66623:tid 66848] [client 40.85.222.29:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWxAAAAVw"] [Tue Aug 18 12:57:55.790714 2026] [security2:error] [pid 66623:tid 66774] [client 20.226.6.191:4015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBA9O5rbWdOArH04KWxgAAARI"] [Tue Aug 18 12:57:55.794407 2026] [authz_core:error] [pid 66623:tid 66717] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:55.794843 2026] [authz_core:error] [pid 66623:tid 66717] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:55.795447 2026] [autoindex:error] [pid 66623:tid 66828] [client 158.158.74.177:26157] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:55.813839 2026] [security2:error] [pid 66623:tid 66841] [client 20.119.58.187:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "aoSBA9O5rbWdOArH04KWyAAAAVU"] [Tue Aug 18 12:57:55.843494 2026] [security2:error] [pid 66623:tid 66802] [client 20.226.6.191:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cah.php"] [unique_id "aoSBA9O5rbWdOArH04KWywAAAS4"] [Tue Aug 18 12:57:55.849873 2026] [security2:error] [pid 66623:tid 66720] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/about.php"] [unique_id "aoSBA9O5rbWdOArH04KWzQABG1M"] [Tue Aug 18 12:57:55.883034 2026] [security2:error] [pid 66623:tid 66874] [client 20.1.169.243:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/rk2.php"] [unique_id "aoSBA9O5rbWdOArH04KW0AAAAXY"] [Tue Aug 18 12:57:55.953954 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBA9O5rbWdOArH04KW1QAAAWc"] [Tue Aug 18 12:57:55.962047 2026] [autoindex:error] [pid 66623:tid 66817] [client 4.232.151.198:24957] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:55.971024 2026] [security2:error] [pid 66623:tid 66834] [client 172.182.200.96:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBA9O5rbWdOArH04KW1gAAAU4"] [Tue Aug 18 12:57:56.002447 2026] [security2:error] [pid 66623:tid 66825] [client 168.119.96.239:12218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pan.com.br"] [uri "/server.php"] [unique_id "aoSBA9O5rbWdOArH04KWswAAAUU"], referer: https://pan.com.br/?lang=pt-br [Tue Aug 18 12:57:56.010119 2026] [security2:error] [pid 66623:tid 66785] [client 158.158.74.177:26157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBBNO5rbWdOArH04KW2AAAAR0"] [Tue Aug 18 12:57:56.031342 2026] [security2:error] [pid 66623:tid 66864] [client 20.226.6.191:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/system_log.php"] [unique_id "aoSBBNO5rbWdOArH04KW3QAAAWw"] [Tue Aug 18 12:57:56.032819 2026] [security2:error] [pid 66623:tid 66892] [client 20.186.30.159:1699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fpwch.php"] [unique_id "aoSBBNO5rbWdOArH04KW3gAAAYg"] [Tue Aug 18 12:57:56.039348 2026] [autoindex:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:56.041699 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.154.236:48920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW3wAAAW8"] [Tue Aug 18 12:57:56.053758 2026] [security2:error] [pid 66623:tid 66794] [client 20.100.185.105:42685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW4AAAASY"] [Tue Aug 18 12:57:56.063854 2026] [security2:error] [pid 66623:tid 66862] [client 20.118.172.148:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp.php"] [unique_id "aoSBBNO5rbWdOArH04KW4QAAAWo"] [Tue Aug 18 12:57:56.071511 2026] [security2:error] [pid 66623:tid 66846] [client 40.85.222.29:26899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBBNO5rbWdOArH04KW4wAAAVo"] [Tue Aug 18 12:57:56.075643 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.200.96:7639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBBNO5rbWdOArH04KW5AAAARQ"] [Tue Aug 18 12:57:56.136744 2026] [security2:error] [pid 66623:tid 66791] [client 74.248.18.37:21527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gulu.php"] [unique_id "aoSBBNO5rbWdOArH04KW5wAAASM"] [Tue Aug 18 12:57:56.136974 2026] [security2:error] [pid 66623:tid 66883] [client 172.182.217.32:15753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/about.php"] [unique_id "aoSBBNO5rbWdOArH04KW6AAAAX8"] [Tue Aug 18 12:57:56.167416 2026] [security2:error] [pid 66623:tid 66873] [client 20.119.58.187:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KW6wAAAXU"] [Tue Aug 18 12:57:56.182804 2026] [autoindex:error] [pid 66623:tid 66854] [client 4.232.151.198:24957] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:56.197590 2026] [security2:error] [pid 66623:tid 66807] [client 20.203.183.135:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/scxy.php"] [unique_id "aoSBBNO5rbWdOArH04KW7gAAATM"] [Tue Aug 18 12:57:56.220667 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/thoms.php"] [unique_id "aoSBBNO5rbWdOArH04KW8QAAAV8"] [Tue Aug 18 12:57:56.229164 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSBBNO5rbWdOArH04KW8gABhEo"] [Tue Aug 18 12:57:56.237856 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:44755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inx.php"] [unique_id "aoSBBNO5rbWdOArH04KW9AAAAVs"] [Tue Aug 18 12:57:56.239493 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:25013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBBNO5rbWdOArH04KW9gAAARU"] [Tue Aug 18 12:57:56.251462 2026] [security2:error] [pid 66623:tid 66772] [client 20.1.169.243:3425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/storage/rip.php"] [unique_id "aoSBBNO5rbWdOArH04KW-gAAARA"] [Tue Aug 18 12:57:56.256755 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/bengi.php"] [unique_id "aoSBBNO5rbWdOArH04KW-wAAASQ"] [Tue Aug 18 12:57:56.256785 2026] [security2:error] [pid 66623:tid 66840] [client 20.226.6.191:4016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBBNO5rbWdOArH04KW_QAAAVQ"] [Tue Aug 18 12:57:56.355250 2026] [security2:error] [pid 66623:tid 66797] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/key.php"] [unique_id "aoSBBNO5rbWdOArH04KXEgAAASk"] [Tue Aug 18 12:57:56.357637 2026] [security2:error] [pid 66623:tid 66884] [client 20.226.6.191:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBBNO5rbWdOArH04KXEwAAAYA"] [Tue Aug 18 12:57:56.365681 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/motu.php"] [unique_id "aoSBBNO5rbWdOArH04KXFQAAAUA"] [Tue Aug 18 12:57:56.387973 2026] [security2:error] [pid 66623:tid 66774] [client 4.232.151.198:24957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBBNO5rbWdOArH04KXGAAAARI"] [Tue Aug 18 12:57:56.393559 2026] [security2:error] [pid 66623:tid 66828] [client 20.203.138.185:35008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/new4.php"] [unique_id "aoSBBNO5rbWdOArH04KXGQAAAUg"] [Tue Aug 18 12:57:56.393984 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:56.394237 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:56.421233 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file2.php"] [unique_id "aoSBBNO5rbWdOArH04KXGgAAAU8"] [Tue Aug 18 12:57:56.424219 2026] [security2:error] [pid 66623:tid 66841] [client 20.118.172.148:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/fff.php"] [unique_id "aoSBBNO5rbWdOArH04KXGwAAAVU"] [Tue Aug 18 12:57:56.440220 2026] [security2:error] [pid 66623:tid 66823] [client 40.85.222.29:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBBNO5rbWdOArH04KXHQAAAUM"] [Tue Aug 18 12:57:56.464073 2026] [security2:error] [pid 66623:tid 66871] [client 213.35.127.232:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBBNO5rbWdOArH04KXHgAAAXM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:56.521771 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:12517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXJgAAAWQ"] [Tue Aug 18 12:57:56.534646 2026] [security2:error] [pid 66623:tid 66778] [client 20.226.6.191:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/abc.php"] [unique_id "aoSBBNO5rbWdOArH04KXJwAAARY"] [Tue Aug 18 12:57:56.546385 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.200.96:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBBNO5rbWdOArH04KXKAAAAUU"] [Tue Aug 18 12:57:56.558301 2026] [security2:error] [pid 66623:tid 66865] [client 20.186.30.159:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/adminner.php"] [unique_id "aoSBBNO5rbWdOArH04KXKgAAAW0"] [Tue Aug 18 12:57:56.580677 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.169.31:15279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/simple.php"] [unique_id "aoSBBNO5rbWdOArH04KXLAAAATE"] [Tue Aug 18 12:57:56.593161 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:7555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBBNO5rbWdOArH04KXLQAAAVE"] [Tue Aug 18 12:57:56.618667 2026] [security2:error] [pid 66623:tid 66821] [client 20.1.169.243:3410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/tool.php"] [unique_id "aoSBBNO5rbWdOArH04KXLgAAAUE"] [Tue Aug 18 12:57:56.651282 2026] [security2:error] [pid 66623:tid 66783] [client 172.182.217.32:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/atomlib.php"] [unique_id "aoSBBNO5rbWdOArH04KXMAAAARs"] [Tue Aug 18 12:57:56.686005 2026] [security2:error] [pid 66623:tid 66854] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/chosen.php"] [unique_id "aoSBBNO5rbWdOArH04KXMgAAAWI"] [Tue Aug 18 12:57:56.687339 2026] [security2:error] [pid 66623:tid 66879] [client 20.100.185.105:42675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXMwAAAXs"] [Tue Aug 18 12:57:56.697384 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:56.697804 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:56.710089 2026] [security2:error] [pid 66623:tid 66679] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSBBNO5rbWdOArH04KXOgABbCo"] [Tue Aug 18 12:57:56.776511 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:37064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/biufile.php"] [unique_id "aoSBBNO5rbWdOArH04KXQQAAATU"] [Tue Aug 18 12:57:56.778516 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.154.236:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBBNO5rbWdOArH04KXQgAAAVs"] [Tue Aug 18 12:57:56.785830 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/h.php"] [unique_id "aoSBBNO5rbWdOArH04KXQwAAASg"] [Tue Aug 18 12:57:56.788749 2026] [security2:error] [pid 66623:tid 66861] [client 40.85.222.29:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBBNO5rbWdOArH04KXRAAAAWk"] [Tue Aug 18 12:57:56.849563 2026] [security2:error] [pid 66623:tid 66842] [client 20.226.6.191:3982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/akcc.php"] [unique_id "aoSBBNO5rbWdOArH04KXSQAAAVY"] [Tue Aug 18 12:57:56.866202 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.172.148:33494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBBNO5rbWdOArH04KXSwAAAUA"] [Tue Aug 18 12:57:56.876200 2026] [security2:error] [pid 66623:tid 66824] [client 20.119.58.187:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXTAAAAUQ"] [Tue Aug 18 12:57:56.886516 2026] [security2:error] [pid 66623:tid 66848] [client 52.173.121.69:25008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBBNO5rbWdOArH04KXTwAAAVw"] [Tue Aug 18 12:57:56.907491 2026] [security2:error] [pid 66623:tid 66773] [client 157.51.166.53:50880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBNO5rbWdOArH04KXUwAAARE"] [Tue Aug 18 12:57:56.907607 2026] [security2:error] [pid 66623:tid 66773] [client 157.51.166.53:50880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBNO5rbWdOArH04KXUwAAARE"] [Tue Aug 18 12:57:56.919453 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:20484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/tool.php"] [unique_id "aoSBBNO5rbWdOArH04KXVQAAATM"] [Tue Aug 18 12:57:56.943409 2026] [security2:error] [pid 66623:tid 66768] [client 20.226.6.191:3928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wk/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXWgAAAQw"] [Tue Aug 18 12:57:56.973181 2026] [security2:error] [pid 66623:tid 66834] [client 74.248.18.37:55795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/wp-themes.php"] [unique_id "aoSBBNO5rbWdOArH04KXXgAAAU4"] [Tue Aug 18 12:57:56.985360 2026] [security2:error] [pid 66623:tid 66880] [client 20.1.169.243:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSBBNO5rbWdOArH04KXYAAAAXw"] [Tue Aug 18 12:57:57.000403 2026] [security2:error] [pid 66623:tid 66772] [client 158.158.74.177:2641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBBNO5rbWdOArH04KXYwAAARA"] [Tue Aug 18 12:57:57.004603 2026] [security2:error] [pid 66623:tid 66886] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/wpxml.php"] [unique_id "aoSBBdO5rbWdOArH04KXZQAAAYI"] [Tue Aug 18 12:57:57.008358 2026] [authz_core:error] [pid 66623:tid 66707] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:57.008797 2026] [authz_core:error] [pid 66623:tid 66707] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:57.049202 2026] [security2:error] [pid 66623:tid 66876] [client 4.232.151.198:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBBdO5rbWdOArH04KXcQAAAXg"] [Tue Aug 18 12:57:57.068578 2026] [security2:error] [pid 66623:tid 66794] [client 20.186.30.159:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/abcd.php"] [unique_id "aoSBBdO5rbWdOArH04KXcwAAASY"] [Tue Aug 18 12:57:57.081520 2026] [security2:error] [pid 66623:tid 66789] [client 40.74.65.169:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/reviall.php"] [unique_id "aoSBBdO5rbWdOArH04KXdAAAASE"] [Tue Aug 18 12:57:57.088269 2026] [security2:error] [pid 66623:tid 66795] [client 158.158.34.183:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/system.php"] [unique_id "aoSBBdO5rbWdOArH04KXeAAAASc"] [Tue Aug 18 12:57:57.092591 2026] [security2:error] [pid 66623:tid 66791] [client 40.85.222.29:26928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXeQAAASM"] [Tue Aug 18 12:57:57.144780 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.217.32:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBBdO5rbWdOArH04KXfAAAAWQ"] [Tue Aug 18 12:57:57.177091 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSBBdO5rbWdOArH04KXfwABHTc"] [Tue Aug 18 12:57:57.232425 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:50068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/alfa.php"] [unique_id "aoSBBdO5rbWdOArH04KXgQAAAVs"] [Tue Aug 18 12:57:57.238853 2026] [security2:error] [pid 66623:tid 66822] [client 20.226.6.191:3921] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "riovacinas.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KXggAAAUI"] [Tue Aug 18 12:57:57.238979 2026] [security2:error] [pid 66623:tid 66822] [client 20.226.6.191:3921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KXggAAAUI"] [Tue Aug 18 12:57:57.251582 2026] [security2:error] [pid 66623:tid 66819] [client 20.119.58.187:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "aoSBBdO5rbWdOArH04KXhAAAAT8"] [Tue Aug 18 12:57:57.284992 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:20725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/19.php"] [unique_id "aoSBBdO5rbWdOArH04KXhQAAATY"] [Tue Aug 18 12:57:57.285609 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.154.236:40276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBBdO5rbWdOArH04KXhgAAAQ0"] [Tue Aug 18 12:57:57.298571 2026] [security2:error] [pid 66623:tid 66790] [client 196.12.128.158:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXiAAAASI"] [Tue Aug 18 12:57:57.298749 2026] [security2:error] [pid 66623:tid 66790] [client 196.12.128.158:56207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXiAAAASI"] [Tue Aug 18 12:57:57.311636 2026] [security2:error] [pid 66623:tid 66873] [client 20.100.185.105:29824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXiwAAAXU"] [Tue Aug 18 12:57:57.326069 2026] [security2:error] [pid 66623:tid 66803] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/file1221.php"] [unique_id "aoSBBdO5rbWdOArH04KXjAAAAS8"] [Tue Aug 18 12:57:57.353247 2026] [security2:error] [pid 66623:tid 66809] [client 20.1.169.243:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXlwAAATU"] [Tue Aug 18 12:57:57.371669 2026] [security2:error] [pid 66623:tid 66816] [client 40.85.222.29:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBBdO5rbWdOArH04KXmQAAATw"] [Tue Aug 18 12:57:57.372396 2026] [security2:error] [pid 66623:tid 66660] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KXmgABKRc"] [Tue Aug 18 12:57:57.401941 2026] [security2:error] [pid 66623:tid 66820] [client 68.155.155.199:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/404.php"] [unique_id "aoSBBdO5rbWdOArH04KXnQAAAUA"] [Tue Aug 18 12:57:57.423498 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/hello.php"] [unique_id "aoSBBdO5rbWdOArH04KXoQAAAXk"] [Tue Aug 18 12:57:57.431675 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/inputs.php"] [unique_id "aoSBBdO5rbWdOArH04KXowAAARM"] [Tue Aug 18 12:57:57.452989 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.200.96:14149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBBdO5rbWdOArH04KXpAAAAXA"] [Tue Aug 18 12:57:57.469641 2026] [security2:error] [pid 66623:tid 66823] [client 20.186.30.159:1678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/simple.php"] [unique_id "aoSBBdO5rbWdOArH04KXpQAAAUM"] [Tue Aug 18 12:57:57.476369 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:24976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBBdO5rbWdOArH04KXpgAAARE"] [Tue Aug 18 12:57:57.476861 2026] [security2:error] [pid 66623:tid 66864] [client 213.35.127.232:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBBdO5rbWdOArH04KXpwAAAWw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:57.554331 2026] [security2:error] [pid 66623:tid 66723] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/core.php"] [unique_id "aoSBBdO5rbWdOArH04KXwgABfVY"] [Tue Aug 18 12:57:57.568042 2026] [security2:error] [pid 66623:tid 66866] [client 74.248.18.37:21519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/tools.php"] [unique_id "aoSBBdO5rbWdOArH04KXxAAAAW4"] [Tue Aug 18 12:57:57.604996 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:57.605249 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:57.615584 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.18.37:3322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.leve.etc.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBdO5rbWdOArH04KXzQAAAYA"] [Tue Aug 18 12:57:57.622896 2026] [security2:error] [pid 66623:tid 66871] [client 20.119.58.187:12538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "aoSBBdO5rbWdOArH04KXzwAAAXM"] [Tue Aug 18 12:57:57.632195 2026] [security2:error] [pid 66623:tid 66800] [client 172.182.217.32:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/b.php"] [unique_id "aoSBBdO5rbWdOArH04KX0AAAASw"] [Tue Aug 18 12:57:57.672356 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:2691] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KX1gAAAYk"] [Tue Aug 18 12:57:57.672453 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSBBdO5rbWdOArH04KX1gAAAYk"] [Tue Aug 18 12:57:57.676056 2026] [security2:error] [pid 66623:tid 66837] [client 158.23.17.4:34150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBBdO5rbWdOArH04KX1wAAAVE"] [Tue Aug 18 12:57:57.678685 2026] [security2:error] [pid 66623:tid 66876] [client 20.203.138.185:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-act.php"] [unique_id "aoSBBdO5rbWdOArH04KX2AAAAXg"] [Tue Aug 18 12:57:57.679397 2026] [autoindex:error] [pid 66623:tid 66841] [client 4.232.151.198:51268] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:57.717688 2026] [security2:error] [pid 66623:tid 66882] [client 20.1.169.243:3394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBBdO5rbWdOArH04KX2gAAAX4"] [Tue Aug 18 12:57:57.734485 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBBdO5rbWdOArH04KX2wAAASY"] [Tue Aug 18 12:57:57.740608 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.200.96:7675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/well-known/index.php"] [unique_id "aoSBBdO5rbWdOArH04KX3AAAAU8"] [Tue Aug 18 12:57:57.750346 2026] [security2:error] [pid 66623:tid 66735] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/db-status.php"] [unique_id "aoSBBdO5rbWdOArH04KX3QABQWI"] [Tue Aug 18 12:57:57.771827 2026] [security2:error] [pid 66623:tid 66890] [client 40.85.222.29:26938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBBdO5rbWdOArH04KX4gAAAYY"] [Tue Aug 18 12:57:57.795604 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.133.132:15178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/dex.php"] [unique_id "aoSBBdO5rbWdOArH04KX5QAAAWI"] [Tue Aug 18 12:57:57.801059 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:43154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/11.php"] [unique_id "aoSBBdO5rbWdOArH04KX5gAAAV4"] [Tue Aug 18 12:57:57.909386 2026] [autoindex:error] [pid 66623:tid 66819] [client 4.232.151.198:51268] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:57.910717 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:57.911151 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:57.911877 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.154.236:8027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBBdO5rbWdOArH04KX7wAAAWE"] [Tue Aug 18 12:57:57.932122 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.185.105:40069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/fonts/admin.php"] [unique_id "aoSBBdO5rbWdOArH04KX8gAAAVI"] [Tue Aug 18 12:57:57.968334 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBBdO5rbWdOArH04KX9gABdRg"] [Tue Aug 18 12:57:57.971106 2026] [security2:error] [pid 66623:tid 66804] [client 20.118.172.148:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBBdO5rbWdOArH04KX9wAAATA"] [Tue Aug 18 12:57:57.982351 2026] [security2:error] [pid 66623:tid 66822] [client 20.119.58.187:12482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "aoSBBdO5rbWdOArH04KX-AAAAUI"] [Tue Aug 18 12:57:58.012864 2026] [security2:error] [pid 66623:tid 66774] [client 197.184.64.235:41939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KX-QAAARI"] [Tue Aug 18 12:57:58.012971 2026] [security2:error] [pid 66623:tid 66774] [client 197.184.64.235:41939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KX-QAAARI"] [Tue Aug 18 12:57:58.017199 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.169.31:29052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBBtO5rbWdOArH04KX-gAAARs"] [Tue Aug 18 12:57:58.018322 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBBtO5rbWdOArH04KX-wAAAS8"] [Tue Aug 18 12:57:58.054534 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:36124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/coffexium.php"] [unique_id "aoSBBtO5rbWdOArH04KX_QAAATQ"] [Tue Aug 18 12:57:58.061274 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBBtO5rbWdOArH04KX_gAAATU"] [Tue Aug 18 12:57:58.103972 2026] [security2:error] [pid 66623:tid 66812] [client 74.248.18.37:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/images/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYAwAAATg"] [Tue Aug 18 12:57:58.104606 2026] [authz_core:error] [pid 66623:tid 66686] [remote 57.141.22.23:40622] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:58.104874 2026] [authz_core:error] [pid 66623:tid 66686] [remote 57.141.22.23:40622] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:58.113090 2026] [security2:error] [pid 66623:tid 66801] [client 40.85.222.29:26931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBBtO5rbWdOArH04KYBAAAAS0"] [Tue Aug 18 12:57:58.114351 2026] [security2:error] [pid 66623:tid 66848] [client 4.232.151.198:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBBtO5rbWdOArH04KYDwAAAVw"] [Tue Aug 18 12:57:58.121207 2026] [security2:error] [pid 66623:tid 66781] [client 172.182.217.32:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/buy.php"] [unique_id "aoSBBtO5rbWdOArH04KYFgAAARk"] [Tue Aug 18 12:57:58.133379 2026] [security2:error] [pid 66623:tid 66793] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/nox.php"] [unique_id "aoSBBtO5rbWdOArH04KYGgAAASU"] [Tue Aug 18 12:57:58.148236 2026] [security2:error] [pid 66623:tid 66700] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYGwABET8"] [Tue Aug 18 12:57:58.152832 2026] [security2:error] [pid 66623:tid 66864] [client 20.186.30.159:1692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBBtO5rbWdOArH04KYHAAAAWw"] [Tue Aug 18 12:57:58.186472 2026] [security2:error] [pid 66623:tid 66814] [client 20.203.183.135:42445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBBtO5rbWdOArH04KYHgAAATo"] [Tue Aug 18 12:57:58.213228 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:58.213680 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:58.278877 2026] [security2:error] [pid 66623:tid 66825] [client 20.118.172.148:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/222.php"] [unique_id "aoSBBtO5rbWdOArH04KYKgAAAUU"] [Tue Aug 18 12:57:58.332157 2026] [security2:error] [pid 66623:tid 66841] [client 20.226.6.191:4025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/as.php"] [unique_id "aoSBBtO5rbWdOArH04KYLgAAAVU"] [Tue Aug 18 12:57:58.336632 2026] [security2:error] [pid 66623:tid 66829] [client 74.248.18.37:21561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/txets.php"] [unique_id "aoSBBtO5rbWdOArH04KYLwAAAUk"] [Tue Aug 18 12:57:58.350692 2026] [security2:error] [pid 66623:tid 66859] [client 20.119.58.187:12496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "aoSBBtO5rbWdOArH04KYMQAAAWc"] [Tue Aug 18 12:57:58.355539 2026] [security2:error] [pid 66623:tid 66691] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYMgABhjY"] [Tue Aug 18 12:57:58.436153 2026] [security2:error] [pid 66623:tid 66817] [client 40.85.222.29:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYNwAAAT0"] [Tue Aug 18 12:57:58.455704 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.138.185:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/grsiuk.php"] [unique_id "aoSBBtO5rbWdOArH04KYOgAAAVc"] [Tue Aug 18 12:57:58.468777 2026] [security2:error] [pid 66623:tid 66875] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/akismet.php"] [unique_id "aoSBBtO5rbWdOArH04KYPwAAAXc"] [Tue Aug 18 12:57:58.490377 2026] [security2:error] [pid 66623:tid 66839] [client 213.35.127.232:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBBtO5rbWdOArH04KYRwAAAVM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:58.528739 2026] [security2:error] [pid 66623:tid 66769] [client 20.186.30.159:1696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/xiugai.php"] [unique_id "aoSBBtO5rbWdOArH04KYSQAAAQ0"] [Tue Aug 18 12:57:58.539245 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:14135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBBtO5rbWdOArH04KYSgAAATA"] [Tue Aug 18 12:57:58.547802 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSBBtO5rbWdOArH04KYSwABEhU"] [Tue Aug 18 12:57:58.554213 2026] [security2:error] [pid 66623:tid 66805] [client 20.100.185.105:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/av.php"] [unique_id "aoSBBtO5rbWdOArH04KYTQAAATE"] [Tue Aug 18 12:57:58.554928 2026] [security2:error] [pid 66623:tid 66803] [client 20.226.6.191:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBBtO5rbWdOArH04KYTgAAAS8"] [Tue Aug 18 12:57:58.575016 2026] [security2:error] [pid 66623:tid 66808] [client 40.74.65.169:43197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/File.php"] [unique_id "aoSBBtO5rbWdOArH04KYUAAAATQ"] [Tue Aug 18 12:57:58.577396 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.155.199:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lite.php"] [unique_id "aoSBBtO5rbWdOArH04KYUgAAAVY"] [Tue Aug 18 12:57:58.615098 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.217.32:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/bless.php"] [unique_id "aoSBBtO5rbWdOArH04KYVQAAAR0"] [Tue Aug 18 12:57:58.623053 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.200.96:14089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBBtO5rbWdOArH04KYVgAAATg"] [Tue Aug 18 12:57:58.639185 2026] [security2:error] [pid 66623:tid 66848] [client 20.118.172.148:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/lite.php"] [unique_id "aoSBBtO5rbWdOArH04KYWAAAAVw"] [Tue Aug 18 12:57:58.679589 2026] [security2:error] [pid 66623:tid 66773] [client 20.118.133.132:15194] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "agrimotor.com.br"] [uri "/1.php"] [unique_id "aoSBBtO5rbWdOArH04KYXQAAARE"] [Tue Aug 18 12:57:58.679712 2026] [security2:error] [pid 66623:tid 66773] [client 20.118.133.132:15194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/1.php"] [unique_id "aoSBBtO5rbWdOArH04KYXQAAARE"] [Tue Aug 18 12:57:58.681539 2026] [security2:error] [pid 66623:tid 66864] [client 68.155.154.236:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYXgAAAWw"] [Tue Aug 18 12:57:58.710216 2026] [autoindex:error] [pid 66623:tid 66849] [client 158.158.74.177:16513] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:58.721592 2026] [security2:error] [pid 66623:tid 66784] [client 20.119.58.187:12073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "aoSBBtO5rbWdOArH04KYYQAAARw"] [Tue Aug 18 12:57:58.727812 2026] [security2:error] [pid 66623:tid 66855] [client 40.85.222.29:44227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBBtO5rbWdOArH04KYYgAAAWM"] [Tue Aug 18 12:57:58.735481 2026] [security2:error] [pid 66623:tid 66716] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/ms-files.php"] [unique_id "aoSBBtO5rbWdOArH04KYYwABYE8"] [Tue Aug 18 12:57:58.738026 2026] [security2:error] [pid 66623:tid 66838] [client 4.232.151.198:24898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBBtO5rbWdOArH04KYZAAAAVI"] [Tue Aug 18 12:57:58.750561 2026] [security2:error] [pid 66623:tid 66790] [client 74.248.18.37:54965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/index.bak.php"] [unique_id "aoSBBtO5rbWdOArH04KYZQAAASI"] [Tue Aug 18 12:57:58.785657 2026] [security2:error] [pid 66623:tid 66888] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBBtO5rbWdOArH04KYZgABhGo"] [Tue Aug 18 12:57:58.812178 2026] [security2:error] [pid 66623:tid 66886] [client 20.226.6.191:4091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBBtO5rbWdOArH04KYagAAAYI"] [Tue Aug 18 12:57:58.813430 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:58.813892 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:58.873736 2026] [security2:error] [pid 66623:tid 66859] [client 20.186.30.159:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wp-load.php"] [unique_id "aoSBBtO5rbWdOArH04KYbQAAAWc"] [Tue Aug 18 12:57:58.915059 2026] [security2:error] [pid 66623:tid 66846] [client 158.158.74.177:16513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBBtO5rbWdOArH04KYcQAAAVo"] [Tue Aug 18 12:57:58.924698 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/options.php"] [unique_id "aoSBBtO5rbWdOArH04KYcwABf3g"] [Tue Aug 18 12:57:58.978494 2026] [security2:error] [pid 66623:tid 66778] [client 74.248.18.37:20493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/u.php"] [unique_id "aoSBBtO5rbWdOArH04KYdwAAARY"] [Tue Aug 18 12:57:59.036159 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:26915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/first.php"] [unique_id "aoSBB9O5rbWdOArH04KYegAAASQ"] [Tue Aug 18 12:57:59.054313 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:48753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/dex.php"] [unique_id "aoSBB9O5rbWdOArH04KYewAAAT8"] [Tue Aug 18 12:57:59.076335 2026] [security2:error] [pid 66623:tid 66850] [client 20.119.58.187:12541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "aoSBB9O5rbWdOArH04KYfAAAAV4"] [Tue Aug 18 12:57:59.104184 2026] [security2:error] [pid 66623:tid 66862] [client 172.182.217.32:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBB9O5rbWdOArH04KYfgAAAWo"] [Tue Aug 18 12:57:59.109805 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/panel.php"] [unique_id "aoSBB9O5rbWdOArH04KYgAABF0o"] [Tue Aug 18 12:57:59.113459 2026] [security2:error] [pid 66623:tid 66813] [client 52.173.121.69:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBB9O5rbWdOArH04KYgQAAATk"] [Tue Aug 18 12:57:59.116306 2026] [security2:error] [pid 66623:tid 66791] [client 158.158.34.183:43742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSBB9O5rbWdOArH04KYggAAASM"] [Tue Aug 18 12:57:59.149891 2026] [security2:error] [pid 66623:tid 66770] [client 216.244.66.243:40156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/5522bet-2/"] [unique_id "aoSBB9O5rbWdOArH04KYhQAAAQ4"] [Tue Aug 18 12:57:59.149918 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.154.236:40267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYhAAAAT4"] [Tue Aug 18 12:57:59.150000 2026] [security2:error] [pid 66623:tid 66770] [client 216.244.66.243:40156] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/5522bet-2/"] [unique_id "aoSBB9O5rbWdOArH04KYhQAAAQ4"] [Tue Aug 18 12:57:59.155736 2026] [security2:error] [pid 66623:tid 66786] [client 158.23.17.4:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBB9O5rbWdOArH04KYiAAAAR4"] [Tue Aug 18 12:57:59.156787 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYiQAAAQ0"] [Tue Aug 18 12:57:59.172679 2026] [security2:error] [pid 66623:tid 66806] [client 68.155.155.199:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lock360.php"] [unique_id "aoSBB9O5rbWdOArH04KYigAAATI"] [Tue Aug 18 12:57:59.172791 2026] [security2:error] [pid 66623:tid 66885] [client 20.100.185.105:29845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KYiwAAAYE"] [Tue Aug 18 12:57:59.180219 2026] [security2:error] [pid 66623:tid 66643] [remote 185.118.190.176:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYjAABQgY"] [Tue Aug 18 12:57:59.225125 2026] [security2:error] [pid 66623:tid 66808] [client 20.1.169.243:3398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KYjgAAATQ"] [Tue Aug 18 12:57:59.227323 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:46772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/asasx.php"] [unique_id "aoSBB9O5rbWdOArH04KYjwAAATw"] [Tue Aug 18 12:57:59.229826 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBB9O5rbWdOArH04KYkAAAAWk"] [Tue Aug 18 12:57:59.261110 2026] [security2:error] [pid 66623:tid 66809] [client 192.141.172.134:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYkgAAATU"] [Tue Aug 18 12:57:59.261204 2026] [security2:error] [pid 66623:tid 66809] [client 192.141.172.134:49377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYkgAAATU"] [Tue Aug 18 12:57:59.279430 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:27778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fi22.php"] [unique_id "aoSBB9O5rbWdOArH04KYkwAAAV8"] [Tue Aug 18 12:57:59.306628 2026] [security2:error] [pid 66623:tid 66728] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSBB9O5rbWdOArH04KYlAABeVs"] [Tue Aug 18 12:57:59.355765 2026] [security2:error] [pid 66623:tid 66814] [client 40.85.222.29:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYmQAAATo"] [Tue Aug 18 12:57:59.372611 2026] [security2:error] [pid 66623:tid 66881] [client 20.226.6.191:4034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYmwAAAX0"] [Tue Aug 18 12:57:59.390639 2026] [security2:error] [pid 66623:tid 66879] [client 20.186.30.159:1691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/155.php"] [unique_id "aoSBB9O5rbWdOArH04KYnQAAAXs"] [Tue Aug 18 12:57:59.394430 2026] [autoindex:error] [pid 66623:tid 66777] [client 4.232.151.198:24919] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:59.412427 2026] [authz_core:error] [pid 66623:tid 66725] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:57:59.412672 2026] [authz_core:error] [pid 66623:tid 66725] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:57:59.431475 2026] [security2:error] [pid 66623:tid 66888] [client 20.226.6.191:3938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYpQAAAYQ"] [Tue Aug 18 12:57:59.438050 2026] [security2:error] [pid 66623:tid 66775] [client 20.119.58.187:11864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/rest-api/about.php"] [unique_id "aoSBB9O5rbWdOArH04KYpgAAARM"] [Tue Aug 18 12:57:59.480855 2026] [security2:error] [pid 66623:tid 66876] [client 172.182.200.96:14156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBB9O5rbWdOArH04KYrgAAAXg"] [Tue Aug 18 12:57:59.481986 2026] [security2:error] [pid 66623:tid 66785] [client 74.248.18.37:21543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/index/function.php"] [unique_id "aoSBB9O5rbWdOArH04KYrwAAAR0"] [Tue Aug 18 12:57:59.485411 2026] [security2:error] [pid 66623:tid 66867] [client 213.202.253.4:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/txets.php"] [unique_id "aoSBB9O5rbWdOArH04KYsAAAAW8"], referer: www.google.com [Tue Aug 18 12:57:59.495382 2026] [security2:error] [pid 66623:tid 66710] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSBB9O5rbWdOArH04KYswABfkk"] [Tue Aug 18 12:57:59.503234 2026] [security2:error] [pid 66623:tid 66873] [client 213.35.127.232:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYtQAAAXU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:57:59.505049 2026] [security2:error] [pid 66623:tid 66794] [client 20.226.6.191:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/an.php"] [unique_id "aoSBB9O5rbWdOArH04KYtgAAASY"] [Tue Aug 18 12:57:59.540934 2026] [security2:error] [pid 66623:tid 66776] [client 103.139.191.60:49328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYugAAARQ"] [Tue Aug 18 12:57:59.541058 2026] [security2:error] [pid 66623:tid 66776] [client 103.139.191.60:49328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBB9O5rbWdOArH04KYugAAARQ"] [Tue Aug 18 12:57:59.587344 2026] [security2:error] [pid 66623:tid 66766] [client 20.226.6.191:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/404.php"] [unique_id "aoSBB9O5rbWdOArH04KYwgAAAQo"] [Tue Aug 18 12:57:59.600903 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.217.32:15761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/cache.php"] [unique_id "aoSBB9O5rbWdOArH04KYxgAAAUg"] [Tue Aug 18 12:57:59.602276 2026] [security2:error] [pid 66623:tid 66836] [client 4.232.151.198:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBB9O5rbWdOArH04KYxwAAAVA"] [Tue Aug 18 12:57:59.631844 2026] [security2:error] [pid 66623:tid 66857] [client 20.226.6.191:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBB9O5rbWdOArH04KYyAAAAWU"] [Tue Aug 18 12:57:59.633847 2026] [security2:error] [pid 66623:tid 66875] [client 20.203.138.185:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/h.php"] [unique_id "aoSBB9O5rbWdOArH04KYygAAAXc"] [Tue Aug 18 12:57:59.657696 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:53115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/filemanager.php"] [unique_id "aoSBB9O5rbWdOArH04KYywAAAV4"] [Tue Aug 18 12:57:59.662092 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.154.236:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBB9O5rbWdOArH04KYzAAAAWE"] [Tue Aug 18 12:57:59.665915 2026] [security2:error] [pid 66623:tid 66860] [client 20.48.236.86:48724] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cabeceiragrandemg.com.br"] [uri "/1.php"] [unique_id "aoSBB9O5rbWdOArH04KYzQAAAWg"] [Tue Aug 18 12:57:59.666028 2026] [security2:error] [pid 66623:tid 66860] [client 20.48.236.86:48724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/1.php"] [unique_id "aoSBB9O5rbWdOArH04KYzQAAAWg"] [Tue Aug 18 12:57:59.674084 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:7226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/ultra.php"] [unique_id "aoSBB9O5rbWdOArH04KY0gAAAUU"] [Tue Aug 18 12:57:59.674090 2026] [security2:error] [pid 66623:tid 66818] [client 20.226.6.191:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBB9O5rbWdOArH04KY0QAAAT4"] [Tue Aug 18 12:57:59.681777 2026] [security2:error] [pid 66623:tid 66729] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSBB9O5rbWdOArH04KY0wABHlw"] [Tue Aug 18 12:57:59.727183 2026] [security2:error] [pid 66623:tid 66885] [client 40.85.222.29:26935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBB9O5rbWdOArH04KY1QAAAYE"] [Tue Aug 18 12:57:59.740242 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:56564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/rip.php"] [unique_id "aoSBB9O5rbWdOArH04KY2AAAARI"] [Tue Aug 18 12:57:59.756110 2026] [security2:error] [pid 66623:tid 66799] [client 52.173.121.69:16454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBB9O5rbWdOArH04KY2gAAASs"] [Tue Aug 18 12:57:59.760693 2026] [autoindex:error] [pid 66623:tid 66798] [client 20.226.6.191:4027] AH01276: Cannot serve directory /home1/agencialkx/riovacinas.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:57:59.766471 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.6.191:4027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wso.php"] [unique_id "aoSBB9O5rbWdOArH04KY3AAAATw"] [Tue Aug 18 12:57:59.772234 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBB9O5rbWdOArH04KY3gAAAUs"] [Tue Aug 18 12:57:59.775516 2026] [security2:error] [pid 66623:tid 66820] [client 20.186.30.159:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/index.php"] [unique_id "aoSBB9O5rbWdOArH04KY3wAAAUA"] [Tue Aug 18 12:57:59.783483 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.6.191:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/sf.php"] [unique_id "aoSBB9O5rbWdOArH04KY4AAAATg"] [Tue Aug 18 12:57:59.794660 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "aoSBB9O5rbWdOArH04KY5AAAAQ4"] [Tue Aug 18 12:57:59.804088 2026] [security2:error] [pid 66623:tid 66823] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/admin.php"] [unique_id "aoSBB9O5rbWdOArH04KY5QAAAUM"] [Tue Aug 18 12:57:59.824184 2026] [security2:error] [pid 66623:tid 66783] [client 20.226.6.191:3922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/index/function.php"] [unique_id "aoSBB9O5rbWdOArH04KY6QAAARs"] [Tue Aug 18 12:57:59.861278 2026] [security2:error] [pid 66623:tid 66764] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/test.php"] [unique_id "aoSBB9O5rbWdOArH04KY7wABhH8"] [Tue Aug 18 12:57:59.889253 2026] [security2:error] [pid 66623:tid 66865] [client 20.203.183.135:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBB9O5rbWdOArH04KY8QAAAW0"] [Tue Aug 18 12:57:59.915490 2026] [security2:error] [pid 66623:tid 66873] [client 68.155.155.199:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSBB9O5rbWdOArH04KY8wAAAXU"] [Tue Aug 18 12:57:59.927976 2026] [security2:error] [pid 66623:tid 66834] [client 20.226.6.191:4007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/edit.php"] [unique_id "aoSBB9O5rbWdOArH04KY9AAAAU4"] [Tue Aug 18 12:57:59.987550 2026] [security2:error] [pid 66623:tid 66772] [client 62.197.45.62:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exatarc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBB9O5rbWdOArH04KY6AAAARA"], referer: https://exatarc.com.br/ [Tue Aug 18 12:57:59.999183 2026] [security2:error] [pid 66623:tid 66835] [client 20.100.185.105:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-the.php"] [unique_id "aoSBB9O5rbWdOArH04KY-AAAAU8"] [Tue Aug 18 12:58:00.016325 2026] [security2:error] [pid 66623:tid 66840] [client 158.158.34.183:55388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSBCNO5rbWdOArH04KY-wAAAVQ"] [Tue Aug 18 12:58:00.017979 2026] [security2:error] [pid 66623:tid 66771] [client 20.118.172.148:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/themes.php"] [unique_id "aoSBCNO5rbWdOArH04KY_AAAAQ8"] [Tue Aug 18 12:58:00.042488 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSBCNO5rbWdOArH04KY_wABMyk"] [Tue Aug 18 12:58:00.045323 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.6.191:3907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBCNO5rbWdOArH04KZAAAAAUg"] [Tue Aug 18 12:58:00.064603 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.98.162:8629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/file2.php"] [unique_id "aoSBCNO5rbWdOArH04KZAQAAAVc"] [Tue Aug 18 12:58:00.081158 2026] [security2:error] [pid 66623:tid 66792] [client 40.85.222.29:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZAgAAASQ"] [Tue Aug 18 12:58:00.095610 2026] [security2:error] [pid 66623:tid 66875] [client 20.124.247.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialgi.com.br"] [uri "/ajax.php"] [unique_id "aoSBCNO5rbWdOArH04KZAwAAAXc"] [Tue Aug 18 12:58:00.097588 2026] [security2:error] [pid 66623:tid 66841] [client 172.182.217.32:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/content.php"] [unique_id "aoSBCNO5rbWdOArH04KZBAAAAVU"] [Tue Aug 18 12:58:00.119644 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:43184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBCNO5rbWdOArH04KZBQAAATY"] [Tue Aug 18 12:58:00.137000 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.18.37:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/info.php"] [unique_id "aoSBCNO5rbWdOArH04KZCAAAASw"] [Tue Aug 18 12:58:00.153796 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:11853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/banners/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZCQAAAT0"] [Tue Aug 18 12:58:00.178499 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-good.php"] [unique_id "aoSBCNO5rbWdOArH04KZCwAAAWg"] [Tue Aug 18 12:58:00.185291 2026] [security2:error] [pid 66623:tid 66791] [client 114.119.131.253:48291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "renatomultimarcas.com.br"] [uri "/veiculo/136148/idea-elx-1-4-mpi-fire-flex-8v-5p"] [unique_id "aoSBCNO5rbWdOArH04KZDAAAASM"], referer: http://renatomultimarcas.com.br/veiculo/136148/idea-elx-1-4-mpi-fire-flex-8v-5p [Tue Aug 18 12:58:00.225612 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSBCNO5rbWdOArH04KZDwABQiI"] [Tue Aug 18 12:58:00.243416 2026] [security2:error] [pid 66623:tid 66799] [client 20.186.30.159:1962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/aaa.php"] [unique_id "aoSBCNO5rbWdOArH04KZEgAAASs"] [Tue Aug 18 12:58:00.248266 2026] [autoindex:error] [pid 66623:tid 66811] [client 4.232.151.198:24905] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:00.254060 2026] [security2:error] [pid 66623:tid 66808] [client 20.1.169.243:3428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSBCNO5rbWdOArH04KZEwAAATQ"] [Tue Aug 18 12:58:00.264894 2026] [security2:error] [pid 66623:tid 66778] [client 37.40.227.74:56638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZFgAAARY"] [Tue Aug 18 12:58:00.269040 2026] [security2:error] [pid 66623:tid 66778] [client 37.40.227.74:56638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZFgAAARY"] [Tue Aug 18 12:58:00.273332 2026] [security2:error] [pid 66623:tid 66812] [client 68.155.154.236:7923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZGAAAATg"] [Tue Aug 18 12:58:00.312014 2026] [security2:error] [pid 66623:tid 66877] [client 20.226.6.191:4031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/tes.php"] [unique_id "aoSBCNO5rbWdOArH04KZHAAAAXk"] [Tue Aug 18 12:58:00.321055 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:00.321326 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:00.326873 2026] [security2:error] [pid 66623:tid 66770] [client 20.203.138.185:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/koiy.php"] [unique_id "aoSBCNO5rbWdOArH04KZHgAAAQ4"] [Tue Aug 18 12:58:00.364820 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/un.php"] [unique_id "aoSBCNO5rbWdOArH04KZHwAAAUc"] [Tue Aug 18 12:58:00.370333 2026] [security2:error] [pid 66623:tid 66881] [client 20.118.172.148:2704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBCNO5rbWdOArH04KZIAAAAX0"] [Tue Aug 18 12:58:00.377023 2026] [security2:error] [pid 66623:tid 66849] [client 20.226.6.191:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/files/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZIQAAAV0"] [Tue Aug 18 12:58:00.387875 2026] [security2:error] [pid 66623:tid 66825] [client 20.79.204.6:11659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/0x.php"] [unique_id "aoSBCNO5rbWdOArH04KZIgAAAUU"] [Tue Aug 18 12:58:00.406806 2026] [security2:error] [pid 66623:tid 66759] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSBCNO5rbWdOArH04KZJAABYHo"] [Tue Aug 18 12:58:00.413131 2026] [security2:error] [pid 66623:tid 66871] [client 20.226.6.191:4018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZJgAAAXM"] [Tue Aug 18 12:58:00.457051 2026] [security2:error] [pid 66623:tid 66865] [client 4.232.151.198:24905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZKQAAAW0"] [Tue Aug 18 12:58:00.462701 2026] [security2:error] [pid 66623:tid 66876] [client 20.226.6.191:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZKgAAAXg"] [Tue Aug 18 12:58:00.475521 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.172.148:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/update/da222.php"] [unique_id "aoSBCNO5rbWdOArH04KZLAAAAU4"] [Tue Aug 18 12:58:00.485076 2026] [security2:error] [pid 66623:tid 66878] [client 40.85.222.29:44763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBCNO5rbWdOArH04KZMgAAAXo"] [Tue Aug 18 12:58:00.487407 2026] [security2:error] [pid 66623:tid 66829] [client 20.226.6.191:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBCNO5rbWdOArH04KZMwAAAUk"] [Tue Aug 18 12:58:00.499799 2026] [security2:error] [pid 66623:tid 66772] [client 20.226.6.191:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/rip.php"] [unique_id "aoSBCNO5rbWdOArH04KZNQAAARA"] [Tue Aug 18 12:58:00.507007 2026] [security2:error] [pid 66623:tid 66783] [client 20.119.58.187:12488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZNwAAARs"] [Tue Aug 18 12:58:00.525767 2026] [security2:error] [pid 66623:tid 66766] [client 20.186.30.159:1948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBCNO5rbWdOArH04KZPgAAAQo"] [Tue Aug 18 12:58:00.530315 2026] [security2:error] [pid 66623:tid 66828] [client 20.226.6.191:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZPwAAAUg"] [Tue Aug 18 12:58:00.531981 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:61341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZQAAAAR4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:00.533796 2026] [security2:error] [pid 66623:tid 66870] [client 20.100.169.31:20231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/u.php"] [unique_id "aoSBCNO5rbWdOArH04KZQQAAAXI"] [Tue Aug 18 12:58:00.586340 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.217.32:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCNO5rbWdOArH04KZSQAAASI"] [Tue Aug 18 12:58:00.587485 2026] [security2:error] [pid 66623:tid 66792] [client 20.226.6.191:3851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/moon.php"] [unique_id "aoSBCNO5rbWdOArH04KZSwAAASQ"] [Tue Aug 18 12:58:00.602229 2026] [security2:error] [pid 66623:tid 66800] [client 20.226.6.191:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/cache.php"] [unique_id "aoSBCNO5rbWdOArH04KZTgAAASw"] [Tue Aug 18 12:58:00.625997 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.185.105:29874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZUgAAAVI"] [Tue Aug 18 12:58:00.629281 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.133.132:23183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/coffee.php"] [unique_id "aoSBCNO5rbWdOArH04KZUwAAASE"] [Tue Aug 18 12:58:00.636526 2026] [security2:error] [pid 66623:tid 66822] [client 68.155.155.199:20169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBCNO5rbWdOArH04KZVQAAAUI"] [Tue Aug 18 12:58:00.703597 2026] [security2:error] [pid 66623:tid 66812] [client 20.226.6.191:3905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZXwAAATg"] [Tue Aug 18 12:58:00.719198 2026] [security2:error] [pid 66623:tid 66856] [client 103.184.169.37:42271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZYgAAAWQ"] [Tue Aug 18 12:58:00.719466 2026] [security2:error] [pid 66623:tid 66856] [client 103.184.169.37:42271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZYgAAAWQ"] [Tue Aug 18 12:58:00.756093 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-login.php"] [unique_id "aoSBCNO5rbWdOArH04KZTAABP24"] [Tue Aug 18 12:58:00.780358 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.154.236:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBCNO5rbWdOArH04KZZgAAAUM"] [Tue Aug 18 12:58:00.809597 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.172.148:63055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/buy.php"] [unique_id "aoSBCNO5rbWdOArH04KZaAAAAUc"] [Tue Aug 18 12:58:00.824879 2026] [security2:error] [pid 66623:tid 66887] [client 40.85.222.29:26941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBCNO5rbWdOArH04KZagAAAYM"] [Tue Aug 18 12:58:00.851965 2026] [security2:error] [pid 66623:tid 66885] [client 74.248.18.37:7227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/inputs.php"] [unique_id "aoSBCNO5rbWdOArH04KZawAAAYE"] [Tue Aug 18 12:58:00.863950 2026] [security2:error] [pid 66623:tid 66888] [client 20.118.172.148:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/upload.php"] [unique_id "aoSBCNO5rbWdOArH04KZbgAAAYQ"] [Tue Aug 18 12:58:00.867949 2026] [security2:error] [pid 66623:tid 66877] [client 20.119.58.187:11860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/about.php"] [unique_id "aoSBCNO5rbWdOArH04KZbwAAAXk"] [Tue Aug 18 12:58:00.912385 2026] [security2:error] [pid 66623:tid 66873] [client 20.226.6.191:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBCNO5rbWdOArH04KZcgAAAXU"] [Tue Aug 18 12:58:00.951943 2026] [security2:error] [pid 66623:tid 66839] [client 20.203.138.185:22981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fff.php"] [unique_id "aoSBCNO5rbWdOArH04KZdgAAAVM"] [Tue Aug 18 12:58:00.953726 2026] [security2:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSBCNO5rbWdOArH04KZeAABH0A"] [Tue Aug 18 12:58:00.966348 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZeQAAAVg"] [Tue Aug 18 12:58:00.966470 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:57050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCNO5rbWdOArH04KZeQAAAVg"] [Tue Aug 18 12:58:00.986841 2026] [security2:error] [pid 66623:tid 66840] [client 20.1.169.243:1038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-mail.php"] [unique_id "aoSBCNO5rbWdOArH04KZfAAAAVQ"] [Tue Aug 18 12:58:00.988801 2026] [security2:error] [pid 66623:tid 66770] [client 20.79.204.6:11662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/222.php"] [unique_id "aoSBCNO5rbWdOArH04KZfQAAAQ4"] [Tue Aug 18 12:58:00.999815 2026] [security2:error] [pid 66623:tid 66773] [client 79.127.164.8:52338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpmyadmin.bak"] [unique_id "aoSBCNO5rbWdOArH04KZfgAAARE"], referer: https://medihub.com.br/phpmyadmin.bak [Tue Aug 18 12:58:01.048995 2026] [security2:error] [pid 66623:tid 66833] [client 20.48.236.86:37069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/coffee.php"] [unique_id "aoSBCdO5rbWdOArH04KZggAAAU0"] [Tue Aug 18 12:58:01.072767 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/up.php"] [unique_id "aoSBCdO5rbWdOArH04KZhAAAAUU"] [Tue Aug 18 12:58:01.075113 2026] [security2:error] [pid 66623:tid 66882] [client 172.182.217.32:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/css.php"] [unique_id "aoSBCdO5rbWdOArH04KZhQAAAX4"] [Tue Aug 18 12:58:01.081532 2026] [security2:error] [pid 66623:tid 66782] [client 4.232.151.198:24947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBCdO5rbWdOArH04KZhgAAARo"] [Tue Aug 18 12:58:01.108161 2026] [security2:error] [pid 66623:tid 66858] [client 20.186.30.159:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/site.php"] [unique_id "aoSBCdO5rbWdOArH04KZiQAAAWY"] [Tue Aug 18 12:58:01.111474 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:27773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBCdO5rbWdOArH04KZigAAARc"] [Tue Aug 18 12:58:01.124344 2026] [security2:error] [pid 66623:tid 66777] [client 52.173.121.69:17966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBCdO5rbWdOArH04KZiwAAARU"] [Tue Aug 18 12:58:01.146332 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSBCdO5rbWdOArH04KZjQABIzw"] [Tue Aug 18 12:58:01.147052 2026] [security2:error] [pid 66623:tid 66892] [client 20.118.172.148:43499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/dropdown.php"] [unique_id "aoSBCdO5rbWdOArH04KZjgAAAYg"] [Tue Aug 18 12:58:01.171746 2026] [security2:error] [pid 66623:tid 66860] [client 20.226.6.191:3960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/o.php"] [unique_id "aoSBCdO5rbWdOArH04KZjwAAAWg"] [Tue Aug 18 12:58:01.173442 2026] [security2:error] [pid 66623:tid 66866] [client 40.85.222.29:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZkAAAAW4"] [Tue Aug 18 12:58:01.198077 2026] [security2:error] [pid 66623:tid 66886] [client 68.155.154.236:7908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZkgAAAYI"] [Tue Aug 18 12:58:01.223592 2026] [security2:error] [pid 66623:tid 66809] [client 20.226.6.191:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/bb.php"] [unique_id "aoSBCdO5rbWdOArH04KZlAAAATU"] [Tue Aug 18 12:58:01.224830 2026] [security2:error] [pid 66623:tid 66848] [client 20.119.58.187:11870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZlQAAAVw"] [Tue Aug 18 12:58:01.249977 2026] [security2:error] [pid 66623:tid 66820] [client 20.219.2.203:7297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tmp/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZlgAAAUA"] [Tue Aug 18 12:58:01.265136 2026] [security2:error] [pid 66623:tid 66824] [client 20.100.185.105:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBCdO5rbWdOArH04KZlwAAAUQ"] [Tue Aug 18 12:58:01.274359 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wk/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZmAAAAWQ"] [Tue Aug 18 12:58:01.335506 2026] [security2:error] [pid 66623:tid 66716] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/002.php"] [unique_id "aoSBCdO5rbWdOArH04KZmwABOk8"] [Tue Aug 18 12:58:01.351453 2026] [security2:error] [pid 66623:tid 66797] [client 20.1.169.243:3411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-the.php"] [unique_id "aoSBCdO5rbWdOArH04KZnAAAASk"] [Tue Aug 18 12:58:01.367667 2026] [security2:error] [pid 66623:tid 66827] [client 20.226.6.191:3985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZnQAAAUc"] [Tue Aug 18 12:58:01.399990 2026] [security2:error] [pid 66623:tid 66877] [client 20.186.30.159:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/ccc.php"] [unique_id "aoSBCdO5rbWdOArH04KZngAAAXk"] [Tue Aug 18 12:58:01.443364 2026] [security2:error] [pid 66623:tid 66864] [client 158.158.74.177:16572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBCdO5rbWdOArH04KZoQAAAWw"] [Tue Aug 18 12:58:01.477970 2026] [security2:error] [pid 66623:tid 66829] [client 40.85.222.29:44281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sortis.com.br"] [uri "/images/security.php"] [unique_id "aoSBCdO5rbWdOArH04KZogAAAUk"] [Tue Aug 18 12:58:01.505974 2026] [security2:error] [pid 66623:tid 66835] [client 20.226.6.191:4029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZpwAAAU8"] [Tue Aug 18 12:58:01.507142 2026] [security2:error] [pid 66623:tid 66796] [client 74.248.18.37:7208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/install.php"] [unique_id "aoSBCdO5rbWdOArH04KZqAAAASg"] [Tue Aug 18 12:58:01.518773 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/0x.php"] [unique_id "aoSBCdO5rbWdOArH04KZqQABSng"] [Tue Aug 18 12:58:01.550752 2026] [security2:error] [pid 66623:tid 66816] [client 213.35.127.232:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBCdO5rbWdOArH04KZqwAAATw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:01.559834 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.217.32:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/chosen.php"] [unique_id "aoSBCdO5rbWdOArH04KZrAAAASA"] [Tue Aug 18 12:58:01.571254 2026] [security2:error] [pid 66623:tid 66770] [client 20.226.6.191:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBCdO5rbWdOArH04KZsAAAAQ4"] [Tue Aug 18 12:58:01.580394 2026] [security2:error] [pid 66623:tid 66893] [client 20.119.58.187:11977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZsQAAAYk"] [Tue Aug 18 12:58:01.580526 2026] [security2:error] [pid 66623:tid 66805] [client 20.219.2.203:7302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tmpls.php"] [unique_id "aoSBCdO5rbWdOArH04KZsgAAATE"] [Tue Aug 18 12:58:01.590616 2026] [security2:error] [pid 66623:tid 66852] [client 20.79.204.6:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/aa.php"] [unique_id "aoSBCdO5rbWdOArH04KZtAAAAWA"] [Tue Aug 18 12:58:01.617911 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.154.236:7646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBCdO5rbWdOArH04KZtwAAAR4"] [Tue Aug 18 12:58:01.618969 2026] [security2:error] [pid 66623:tid 66853] [client 20.118.172.148:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/inputs.php"] [unique_id "aoSBCdO5rbWdOArH04KZuQAAAWE"] [Tue Aug 18 12:58:01.624812 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:01.625066 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:01.631874 2026] [security2:error] [pid 66623:tid 66870] [client 20.226.6.191:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/file.php"] [unique_id "aoSBCdO5rbWdOArH04KZugAAAXI"] [Tue Aug 18 12:58:01.661669 2026] [security2:error] [pid 66623:tid 66875] [client 20.226.6.191:3868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/epinyins.php"] [unique_id "aoSBCdO5rbWdOArH04KZvgAAAXc"] [Tue Aug 18 12:58:01.681039 2026] [security2:error] [pid 66623:tid 66831] [client 20.226.6.191:3911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZwgAAAUs"] [Tue Aug 18 12:58:01.700557 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSBCdO5rbWdOArH04KZxQABFxw"] [Tue Aug 18 12:58:01.700644 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/1.php"] [unique_id "aoSBCdO5rbWdOArH04KZxQABFxw"] [Tue Aug 18 12:58:01.708795 2026] [security2:error] [pid 66623:tid 66802] [client 4.232.151.198:24938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZxwAAAS4"] [Tue Aug 18 12:58:01.715443 2026] [security2:error] [pid 66623:tid 66857] [client 20.1.169.243:3408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp.php"] [unique_id "aoSBCdO5rbWdOArH04KZywAAAWU"] [Tue Aug 18 12:58:01.719007 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.200.96:14158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBCdO5rbWdOArH04KZzAAAARQ"] [Tue Aug 18 12:58:01.721328 2026] [security2:error] [pid 66623:tid 66769] [client 20.226.6.191:3964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZzQAAAQ0"] [Tue Aug 18 12:58:01.722604 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/st.php"] [unique_id "aoSBCdO5rbWdOArH04KZzgAAAQ0"] [Tue Aug 18 12:58:01.763023 2026] [security2:error] [pid 66623:tid 66796] [client 20.226.6.191:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZ1QAAASg"] [Tue Aug 18 12:58:01.794997 2026] [security2:error] [pid 66623:tid 66816] [client 20.226.6.191:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp.php"] [unique_id "aoSBCdO5rbWdOArH04KZ1wAAATw"] [Tue Aug 18 12:58:01.800970 2026] [security2:error] [pid 66623:tid 66890] [client 172.182.200.96:7641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2AAAAYY"] [Tue Aug 18 12:58:01.830029 2026] [security2:error] [pid 66623:tid 66852] [client 20.226.6.191:3932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/function/function.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2gAAAWA"] [Tue Aug 18 12:58:01.841383 2026] [security2:error] [pid 66623:tid 66773] [client 20.186.30.159:1701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZ2wAAARE"] [Tue Aug 18 12:58:01.848142 2026] [security2:error] [pid 66623:tid 66853] [client 20.226.6.191:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3QAAAWE"] [Tue Aug 18 12:58:01.849954 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.34.183:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/akc.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3gAAATM"] [Tue Aug 18 12:58:01.854515 2026] [security2:error] [pid 66623:tid 66843] [client 68.155.155.199:11550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.alf.php"] [unique_id "aoSBCdO5rbWdOArH04KZ3wAAAVc"] [Tue Aug 18 12:58:01.861816 2026] [security2:error] [pid 66623:tid 66837] [client 20.226.6.191:3958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBCdO5rbWdOArH04KZ4QAAAVE"] [Tue Aug 18 12:58:01.876815 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:35731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBCdO5rbWdOArH04KZ4wAAAR0"] [Tue Aug 18 12:58:01.894059 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.133.132:23210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5QAAAUs"] [Tue Aug 18 12:58:01.896599 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/100.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5gABfnA"] [Tue Aug 18 12:58:01.901245 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:24803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBCdO5rbWdOArH04KZ5wAAASw"] [Tue Aug 18 12:58:01.921470 2026] [security2:error] [pid 66623:tid 66866] [client 34.86.30.230:41898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/proc/1/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ7QAAAW4"] [Tue Aug 18 12:58:01.921939 2026] [security2:error] [pid 66623:tid 66860] [client 34.86.30.230:41872] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ7gAAAWg"] [Tue Aug 18 12:58:01.926048 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:01.926308 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:01.926930 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:41844] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:01.926941 2026] [proxy:error] [pid 66623:tid 66774] [client 34.86.30.230:41844] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/graphql, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:01.934642 2026] [security2:error] [pid 66623:tid 66776] [client 20.226.6.191:3865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/ok.php"] [unique_id "aoSBCdO5rbWdOArH04KZ8QAAARQ"] [Tue Aug 18 12:58:01.935166 2026] [proxy_http:error] [pid 66623:tid 66860] (20014)Internal error (specific information not available): [client 34.86.30.230:41872] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:01.935182 2026] [proxy:error] [pid 66623:tid 66860] [client 34.86.30.230:41872] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html [Tue Aug 18 12:58:01.936394 2026] [security2:error] [pid 66623:tid 66770] [client 20.119.58.187:11888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/about.php"] [unique_id "aoSBCdO5rbWdOArH04KZ8wAAAQ4"] [Tue Aug 18 12:58:01.943644 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:41844] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:01.943662 2026] [proxy:error] [pid 66623:tid 66774] [client 34.86.30.230:41844] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:01.948757 2026] [security2:error] [pid 66623:tid 66892] [client 20.226.6.191:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/item.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9QAAAYg"] [Tue Aug 18 12:58:01.949205 2026] [security2:error] [pid 66623:tid 66789] [client 74.248.18.37:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/users.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9gAAASE"] [Tue Aug 18 12:58:01.950050 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:63077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/100.php"] [unique_id "aoSBCdO5rbWdOArH04KZ9wAAAVA"] [Tue Aug 18 12:58:01.950639 2026] [proxy_http:error] [pid 66623:tid 66878] (20014)Internal error (specific information not available): [client 34.86.30.230:42236] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:01.950652 2026] [proxy:error] [pid 66623:tid 66878] [client 34.86.30.230:42236] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/@fs/home/ec2-user/.aws/credentials [Tue Aug 18 12:58:01.958886 2026] [security2:error] [pid 66623:tid 66864] [client 34.86.30.230:41858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/media../.env"] [unique_id "aoSBCdO5rbWdOArH04KZ_QAAAWw"] [Tue Aug 18 12:58:01.958948 2026] [security2:error] [pid 66623:tid 66868] [client 34.86.30.230:41956] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/static../etc/passwd"] [unique_id "aoSBCdO5rbWdOArH04KZ-gAAAXA"] [Tue Aug 18 12:58:01.959209 2026] [security2:error] [pid 66623:tid 66842] [client 34.86.30.230:41884] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KZ-QAAAVY"] [Tue Aug 18 12:58:01.962683 2026] [security2:error] [pid 66623:tid 66848] [client 20.118.172.148:62121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-act.php"] [unique_id "aoSBCdO5rbWdOArH04KaAgAAAVw"] [Tue Aug 18 12:58:01.966461 2026] [security2:error] [pid 66623:tid 66821] [client 20.203.138.185:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pouhg.php"] [unique_id "aoSBCdO5rbWdOArH04KaAwAAAUE"] [Tue Aug 18 12:58:01.970563 2026] [security2:error] [pid 66623:tid 66797] [client 34.86.30.230:42038] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proc/self/environ"] [unique_id "aoSBCdO5rbWdOArH04KaBgAAASk"] [Tue Aug 18 12:58:01.970598 2026] [security2:error] [pid 66623:tid 66879] [client 34.86.30.230:42052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/config"] [unique_id "aoSBCdO5rbWdOArH04KaCQAAAXs"] [Tue Aug 18 12:58:01.972080 2026] [proxy_http:error] [pid 66623:tid 66874] (20014)Internal error (specific information not available): [client 34.86.30.230:42012] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:01.972097 2026] [proxy:error] [pid 66623:tid 66874] [client 34.86.30.230:42012] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/app/.env [Tue Aug 18 12:58:01.973313 2026] [security2:error] [pid 66623:tid 66850] [client 34.86.30.230:42178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBCdO5rbWdOArH04KaDAAAAV4"] [Tue Aug 18 12:58:01.973425 2026] [security2:error] [pid 66623:tid 66869] [client 34.86.30.230:42212] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/graphql"] [unique_id "aoSBCdO5rbWdOArH04KaDwAAAXE"], referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:01.974237 2026] [security2:error] [pid 66623:tid 66798] [client 34.86.30.230:42152] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/read"] [unique_id "aoSBCdO5rbWdOArH04KaFQAAASo"] [Tue Aug 18 12:58:01.974449 2026] [core:error] [pid 66623:tid 66856] [client 34.86.30.230:41982] AH10244: invalid URI path (/assets../../../etc/passwd) [Tue Aug 18 12:58:01.975895 2026] [security2:error] [pid 66623:tid 66827] [client 34.86.30.230:41984] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/files../etc/passwd"] [unique_id "aoSBCdO5rbWdOArH04KaHgAAAUc"] [Tue Aug 18 12:58:02.050698 2026] [security2:error] [pid 66623:tid 66638] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaJQABJQE"] [Tue Aug 18 12:58:02.050931 2026] [security2:error] [pid 66623:tid 66793] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaJQABJQE"] [Tue Aug 18 12:58:02.078363 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/2.php"] [unique_id "aoSBCtO5rbWdOArH04KaKAABETQ"] [Tue Aug 18 12:58:02.080198 2026] [security2:error] [pid 66623:tid 66838] [client 20.1.169.243:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wso.php"] [unique_id "aoSBCtO5rbWdOArH04KaKQAAAVI"] [Tue Aug 18 12:58:02.094258 2026] [security2:error] [pid 66623:tid 66863] [client 172.182.217.32:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/doc.php"] [unique_id "aoSBCtO5rbWdOArH04KaKwAAAWs"] [Tue Aug 18 12:58:02.098983 2026] [security2:error] [pid 66623:tid 66870] [client 20.100.185.105:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/3.php"] [unique_id "aoSBCtO5rbWdOArH04KaLAAAAXI"] [Tue Aug 18 12:58:02.108649 2026] [proxy_http:error] [pid 66623:tid 66814] (20014)Internal error (specific information not available): [client 34.86.30.230:42090] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.108672 2026] [proxy:error] [pid 66623:tid 66814] [client 34.86.30.230:42090] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.mcp.json [Tue Aug 18 12:58:02.114255 2026] [security2:error] [pid 66623:tid 66790] [client 20.186.30.159:1944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/reviall.php"] [unique_id "aoSBCtO5rbWdOArH04KaLQAAASI"] [Tue Aug 18 12:58:02.116833 2026] [proxy_http:error] [pid 66623:tid 66797] (20014)Internal error (specific information not available): [client 34.86.30.230:42038] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.116849 2026] [proxy:error] [pid 66623:tid 66797] [client 34.86.30.230:42038] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html [Tue Aug 18 12:58:02.124125 2026] [proxy_http:error] [pid 66623:tid 66851] (20014)Internal error (specific information not available): [client 34.86.30.230:42028] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.124139 2026] [proxy:error] [pid 66623:tid 66851] [client 34.86.30.230:42028] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/aws/credentials [Tue Aug 18 12:58:02.138849 2026] [proxy_http:error] [pid 66623:tid 66778] (20014)Internal error (specific information not available): [client 34.86.30.230:42064] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.138865 2026] [proxy:error] [pid 66623:tid 66778] [client 34.86.30.230:42064] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.git/HEAD [Tue Aug 18 12:58:02.144225 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.154.236:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBCtO5rbWdOArH04KaLwAAAVU"] [Tue Aug 18 12:58:02.146695 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:42022] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.147452 2026] [proxy:error] [pid 66623:tid 66824] [client 34.86.30.230:42022] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.aws/credentials [Tue Aug 18 12:58:02.151612 2026] [security2:error] [pid 66623:tid 66815] [client 158.23.17.4:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/le.php"] [unique_id "aoSBCtO5rbWdOArH04KaMAAAATs"] [Tue Aug 18 12:58:02.154997 2026] [proxy_http:error] [pid 66623:tid 66810] (20014)Internal error (specific information not available): [client 34.86.30.230:41922] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.155014 2026] [proxy:error] [pid 66623:tid 66810] [client 34.86.30.230:41922] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env [Tue Aug 18 12:58:02.163532 2026] [security2:error] [pid 66623:tid 66876] [client 138.36.100.162:42581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaMQAAAXg"] [Tue Aug 18 12:58:02.163666 2026] [security2:error] [pid 66623:tid 66876] [client 138.36.100.162:42581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaMQAAAXg"] [Tue Aug 18 12:58:02.209392 2026] [security2:error] [pid 66623:tid 66844] [client 20.79.204.6:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/abcd.php"] [unique_id "aoSBCtO5rbWdOArH04KaNwAAAVg"] [Tue Aug 18 12:58:02.228846 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:02.229109 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:02.261153 2026] [security2:error] [pid 66623:tid 66744] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/222.php"] [unique_id "aoSBCtO5rbWdOArH04KaPQABUGs"] [Tue Aug 18 12:58:02.269015 2026] [security2:error] [pid 66623:tid 66788] [client 74.248.18.37:21547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBCtO5rbWdOArH04KaPgAAASA"] [Tue Aug 18 12:58:02.270138 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:02.270158 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:42220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/v1/graphql, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:02.271334 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:59843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/133.php"] [unique_id "aoSBCtO5rbWdOArH04KaPwAAAR8"] [Tue Aug 18 12:58:02.276686 2026] [proxy_http:error] [pid 66623:tid 66889] (20014)Internal error (specific information not available): [client 34.86.30.230:42156] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.276707 2026] [proxy:error] [pid 66623:tid 66889] [client 34.86.30.230:42156] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch [Tue Aug 18 12:58:02.283437 2026] [proxy_http:error] [pid 66623:tid 66808] (20014)Internal error (specific information not available): [client 34.86.30.230:42040] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.283450 2026] [proxy:error] [pid 66623:tid 66808] [client 34.86.30.230:42040] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/actuator/env [Tue Aug 18 12:58:02.289467 2026] [security2:error] [pid 66623:tid 66845] [client 20.119.58.187:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/IXR/about.php"] [unique_id "aoSBCtO5rbWdOArH04KaQAAAAVk"] [Tue Aug 18 12:58:02.290380 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:42138] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.290391 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:42138] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/ [Tue Aug 18 12:58:02.297215 2026] [proxy_http:error] [pid 66623:tid 66826] (20014)Internal error (specific information not available): [client 34.86.30.230:41840] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.320414 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:02.320433 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:42220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br [Tue Aug 18 12:58:02.337806 2026] [security2:error] [pid 66623:tid 66879] [client 20.118.172.148:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/akc.php"] [unique_id "aoSBCtO5rbWdOArH04KaRQAAAXs"] [Tue Aug 18 12:58:02.351818 2026] [security2:error] [pid 66623:tid 66667] [remote 57.141.22.9:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSBCtO5rbWdOArH04KaRgABDh4"], referer: https://siderurgiabrasil.com.br/2023/02/27/cresceu-a-producao-de-aco-em-janeiro/ [Tue Aug 18 12:58:02.374037 2026] [autoindex:error] [pid 66623:tid 66875] [client 4.232.151.198:4449] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:02.384301 2026] [security2:error] [pid 66623:tid 66784] [client 20.186.30.159:1941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/nope.php"] [unique_id "aoSBCtO5rbWdOArH04KaSQAAARw"] [Tue Aug 18 12:58:02.386035 2026] [security2:error] [pid 66623:tid 66857] [client 5.31.227.224:7816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaSgAAAWU"] [Tue Aug 18 12:58:02.390642 2026] [security2:error] [pid 66623:tid 66857] [client 5.31.227.224:7816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaSgAAAWU"] [Tue Aug 18 12:58:02.427681 2026] [security2:error] [pid 66623:tid 66830] [client 52.173.121.69:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBCtO5rbWdOArH04KaUAAAAUo"] [Tue Aug 18 12:58:02.442169 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSBCtO5rbWdOArH04KaUQABPAc"] [Tue Aug 18 12:58:02.455309 2026] [security2:error] [pid 66623:tid 66821] [client 20.1.169.243:3673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/www.php"] [unique_id "aoSBCtO5rbWdOArH04KaVAAAAUE"] [Tue Aug 18 12:58:02.493446 2026] [security2:error] [pid 66623:tid 66853] [client 20.118.172.148:54883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBCtO5rbWdOArH04KaWAAAAWE"] [Tue Aug 18 12:58:02.500933 2026] [security2:error] [pid 66623:tid 66657] [remote 52.167.144.230:24617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/buy/kitte-letter/inshi/s_list.php"] [unique_id "aoSBCtO5rbWdOArH04KaWwABMxQ"] [Tue Aug 18 12:58:02.524146 2026] [security2:error] [pid 66623:tid 66802] [client 20.219.2.203:8594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/tool.php"] [unique_id "aoSBCtO5rbWdOArH04KaYQAAAS4"] [Tue Aug 18 12:58:02.539596 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.154.236:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBCtO5rbWdOArH04KaZQAAARA"] [Tue Aug 18 12:58:02.554919 2026] [security2:error] [pid 66623:tid 66849] [client 78.46.190.63:10168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.anzenblindados.com.br"] [uri "/index.php"] [unique_id "aoSBCdO5rbWdOArH04KZrwAAAV0"], referer: https://www.anzenblindados.com.br/ [Tue Aug 18 12:58:02.574577 2026] [security2:error] [pid 66623:tid 66822] [client 213.35.127.232:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBCtO5rbWdOArH04KaaQAAAUI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:02.584245 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.217.32:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/elp.php"] [unique_id "aoSBCtO5rbWdOArH04KaawAAATc"] [Tue Aug 18 12:58:02.584748 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:21555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/v.php"] [unique_id "aoSBCtO5rbWdOArH04KabAAAAXE"] [Tue Aug 18 12:58:02.586212 2026] [security2:error] [pid 66623:tid 66837] [client 149.34.210.141:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KabQAAAVE"] [Tue Aug 18 12:58:02.588952 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBCtO5rbWdOArH04KabwAAAR0"] [Tue Aug 18 12:58:02.606457 2026] [security2:error] [pid 66623:tid 66819] [client 34.86.30.230:41922] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.bak"] [unique_id "aoSBCtO5rbWdOArH04KacQAAAT8"] [Tue Aug 18 12:58:02.607017 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:41812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/server/.env"] [unique_id "aoSBCtO5rbWdOArH04KaeQAAAVg"] [Tue Aug 18 12:58:02.607565 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:41930] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/admin/.env"] [unique_id "aoSBCtO5rbWdOArH04KafwAAAVg"] [Tue Aug 18 12:58:02.609134 2026] [security2:error] [pid 66623:tid 66854] [client 34.86.30.230:42004] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.production"] [unique_id "aoSBCtO5rbWdOArH04KagAAAAWI"] [Tue Aug 18 12:58:02.617574 2026] [proxy_http:error] [pid 66623:tid 66876] (20014)Internal error (specific information not available): [client 34.86.30.230:42116] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.619711 2026] [security2:error] [pid 66623:tid 66805] [client 157.20.138.62:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaiAAAATE"] [Tue Aug 18 12:58:02.619835 2026] [security2:error] [pid 66623:tid 66805] [client 157.20.138.62:50593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaiAAAATE"] [Tue Aug 18 12:58:02.622770 2026] [security2:error] [pid 66623:tid 66681] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/403.php"] [unique_id "aoSBCtO5rbWdOArH04KaiQABKiw"] [Tue Aug 18 12:58:02.624411 2026] [proxy_http:error] [pid 66623:tid 66815] (20014)Internal error (specific information not available): [client 34.86.30.230:42064] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.631761 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:42124] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.637762 2026] [proxy_http:error] [pid 66623:tid 66792] (20014)Internal error (specific information not available): [client 34.86.30.230:41996] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.644847 2026] [proxy_http:error] [pid 66623:tid 66882] (20014)Internal error (specific information not available): [client 34.86.30.230:41824] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.651553 2026] [proxy_http:error] [pid 66623:tid 66858] (20014)Internal error (specific information not available): [client 34.86.30.230:41972] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.659118 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/about.php"] [unique_id "aoSBCtO5rbWdOArH04KaigAAAWk"] [Tue Aug 18 12:58:02.659170 2026] [proxy_http:error] [pid 66623:tid 66866] (20014)Internal error (specific information not available): [client 34.86.30.230:42236] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.665873 2026] [proxy_http:error] [pid 66623:tid 66832] (20014)Internal error (specific information not available): [client 34.86.30.230:42028] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.672075 2026] [security2:error] [pid 66623:tid 66787] [client 40.74.65.169:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBCtO5rbWdOArH04KaiwAAAR8"] [Tue Aug 18 12:58:02.672386 2026] [proxy_http:error] [pid 66623:tid 66892] (20014)Internal error (specific information not available): [client 34.86.30.230:41948] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.672464 2026] [security2:error] [pid 66623:tid 66864] [client 20.48.236.86:25981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBCtO5rbWdOArH04KajAAAAWw"] [Tue Aug 18 12:58:02.679565 2026] [proxy_http:error] [pid 66623:tid 66836] (20014)Internal error (specific information not available): [client 34.86.30.230:41942] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.687787 2026] [security2:error] [pid 66623:tid 66881] [client 34.86.30.230:41906] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/aws/credentials.json"] [unique_id "aoSBCtO5rbWdOArH04KajQAAAX0"] [Tue Aug 18 12:58:02.730605 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.172.148:19696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBCtO5rbWdOArH04KakQAAAUA"] [Tue Aug 18 12:58:02.751769 2026] [security2:error] [pid 66623:tid 66810] [client 20.203.138.185:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/moon3.php"] [unique_id "aoSBCtO5rbWdOArH04KalAAAATY"] [Tue Aug 18 12:58:02.765054 2026] [autoindex:error] [pid 66623:tid 66828] [client 158.158.74.177:26135] AH01276: Cannot serve directory /home2/ciclogcom/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:02.802735 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/404.php"] [unique_id "aoSBCtO5rbWdOArH04KalwABRx8"] [Tue Aug 18 12:58:02.812704 2026] [security2:error] [pid 66623:tid 66804] [client 20.79.204.6:11683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/admin.php"] [unique_id "aoSBCtO5rbWdOArH04KamAAAATA"] [Tue Aug 18 12:58:02.820981 2026] [security2:error] [pid 66623:tid 66795] [client 20.1.169.243:3397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/x.php"] [unique_id "aoSBCtO5rbWdOArH04KamQAAASc"] [Tue Aug 18 12:58:02.835204 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBCtO5rbWdOArH04KamwAAAV0"] [Tue Aug 18 12:58:02.835517 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:02.835772 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:02.858292 2026] [security2:error] [pid 66623:tid 66837] [client 149.34.210.141:59896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KabQAAAVE"] [Tue Aug 18 12:58:02.892632 2026] [security2:error] [pid 66623:tid 66808] [client 34.86.30.230:31158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/home/node/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KaoQAAATQ"] [Tue Aug 18 12:58:02.899791 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.899809 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31174] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/root/.aws/credentials [Tue Aug 18 12:58:02.906745 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:31144] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.906764 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:31144] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/@fs/home/ec2-user/.aws/credentials [Tue Aug 18 12:58:02.907007 2026] [core:error] [pid 66623:tid 66839] [client 34.86.30.230:31104] AH10244: invalid URI path (/assets../../../.env) [Tue Aug 18 12:58:02.907383 2026] [security2:error] [pid 66623:tid 66813] [client 20.100.185.105:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/index.php"] [unique_id "aoSBCtO5rbWdOArH04KapwAAATk"] [Tue Aug 18 12:58:02.907906 2026] [security2:error] [pid 66623:tid 66843] [client 223.185.37.47:21916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaqAAAAVc"] [Tue Aug 18 12:58:02.908107 2026] [security2:error] [pid 66623:tid 66843] [client 223.185.37.47:21916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBCtO5rbWdOArH04KaqAAAAVc"] [Tue Aug 18 12:58:02.909233 2026] [security2:error] [pid 66623:tid 66789] [client 34.86.30.230:31130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/root/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KaqQAAASE"] [Tue Aug 18 12:58:02.910106 2026] [security2:error] [pid 66623:tid 66840] [client 34.86.30.230:31054] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/backend/.aws/credentials"] [unique_id "aoSBCtO5rbWdOArH04KarQAAAVQ"] [Tue Aug 18 12:58:02.913525 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.913538 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31174] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:02.920710 2026] [proxy_http:error] [pid 66623:tid 66886] (20014)Internal error (specific information not available): [client 34.86.30.230:31144] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.920838 2026] [proxy:error] [pid 66623:tid 66886] [client 34.86.30.230:31144] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:02.921279 2026] [security2:error] [pid 66623:tid 66876] [client 20.186.30.159:1693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/nope.php"] [unique_id "aoSBCtO5rbWdOArH04KatAAAAXg"] [Tue Aug 18 12:58:02.928389 2026] [proxy_http:error] [pid 66623:tid 66893] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.928405 2026] [proxy:error] [pid 66623:tid 66893] [client 34.86.30.230:31066] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/home/ubuntu/.aws/credentials [Tue Aug 18 12:58:02.934544 2026] [proxy_http:error] [pid 66623:tid 66821] (20014)Internal error (specific information not available): [client 34.86.30.230:31102] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.934560 2026] [proxy:error] [pid 66623:tid 66821] [client 34.86.30.230:31102] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/_next/.env [Tue Aug 18 12:58:02.940630 2026] [proxy_http:error] [pid 66623:tid 66859] (20014)Internal error (specific information not available): [client 34.86.30.230:31080] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.940666 2026] [proxy:error] [pid 66623:tid 66859] [client 34.86.30.230:31080] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env [Tue Aug 18 12:58:02.947585 2026] [proxy_http:error] [pid 66623:tid 66781] (20014)Internal error (specific information not available): [client 34.86.30.230:31042] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.947608 2026] [proxy:error] [pid 66623:tid 66781] [client 34.86.30.230:31042] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/home/node/.aws/credentials [Tue Aug 18 12:58:02.952461 2026] [security2:error] [pid 66623:tid 66841] [client 34.86.30.230:42194] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBCtO5rbWdOArH04KauQAAAVU"] [Tue Aug 18 12:58:02.954322 2026] [proxy_http:error] [pid 66623:tid 66893] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.954336 2026] [proxy:error] [pid 66623:tid 66893] [client 34.86.30.230:31066] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:02.958402 2026] [security2:error] [pid 66623:tid 66882] [client 52.173.121.69:17932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBCtO5rbWdOArH04KaugAAAX4"] [Tue Aug 18 12:58:02.960236 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/item.php"] [unique_id "aoSBCtO5rbWdOArH04KavAAAATo"] [Tue Aug 18 12:58:02.973167 2026] [proxy_http:error] [pid 66623:tid 66858] (20014)Internal error (specific information not available): [client 34.86.30.230:42156] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:02.984636 2026] [security2:error] [pid 66623:tid 66675] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/4mosan.php"] [unique_id "aoSBCtO5rbWdOArH04KavgABFyY"] [Tue Aug 18 12:58:03.015420 2026] [security2:error] [pid 66623:tid 66785] [client 20.119.58.187:11852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updraft/about.php"] [unique_id "aoSBC9O5rbWdOArH04KawQAAAR0"] [Tue Aug 18 12:58:03.017405 2026] [security2:error] [pid 66623:tid 66872] [client 158.158.74.177:26135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBC9O5rbWdOArH04KawgAAAXQ"] [Tue Aug 18 12:58:03.025176 2026] [proxy_http:error] [pid 66623:tid 66881] (20014)Internal error (specific information not available): [client 34.86.30.230:42012] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.033461 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31088] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.033480 2026] [proxy:error] [pid 66623:tid 66833] [client 34.86.30.230:31088] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch [Tue Aug 18 12:58:03.040703 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31088] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.040732 2026] [proxy:error] [pid 66623:tid 66833] [client 34.86.30.230:31088] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:03.044855 2026] [security2:error] [pid 66623:tid 66770] [client 68.155.154.236:8006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBC9O5rbWdOArH04KaygAAAQ4"] [Tue Aug 18 12:58:03.047498 2026] [security2:error] [pid 66623:tid 66856] [client 3.77.67.4:52986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBCtO5rbWdOArH04KanQAAAWQ"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 12:58:03.048007 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:42210] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.055480 2026] [proxy_http:error] [pid 66623:tid 66887] (20014)Internal error (specific information not available): [client 34.86.30.230:42104] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.061936 2026] [proxy_http:error] [pid 66623:tid 66875] (20014)Internal error (specific information not available): [client 34.86.30.230:42220] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.068369 2026] [proxy_http:error] [pid 66623:tid 66852] (20014)Internal error (specific information not available): [client 34.86.30.230:42040] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.091997 2026] [security2:error] [pid 66623:tid 66829] [client 158.23.17.4:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hr.php"] [unique_id "aoSBC9O5rbWdOArH04Ka0gAAAUk"] [Tue Aug 18 12:58:03.094880 2026] [security2:error] [pid 66623:tid 66788] [client 172.182.217.32:15766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/Exception-class.php"] [unique_id "aoSBC9O5rbWdOArH04Ka0wAAASA"] [Tue Aug 18 12:58:03.100061 2026] [security2:error] [pid 66623:tid 66804] [client 68.155.155.199:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka1AAAATA"] [Tue Aug 18 12:58:03.140196 2026] [security2:error] [pid 66623:tid 66793] [client 34.86.30.230:31172] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/google-services.json"] [unique_id "aoSBC9O5rbWdOArH04Ka2AAAASU"] [Tue Aug 18 12:58:03.140483 2026] [security2:error] [pid 66623:tid 66786] [client 34.86.30.230:31120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04Ka2QAAAR4"] [Tue Aug 18 12:58:03.141061 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:03.141344 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:03.161734 2026] [security2:error] [pid 66623:tid 66682] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/504.php"] [unique_id "aoSBC9O5rbWdOArH04Ka4QABNy0"] [Tue Aug 18 12:58:03.163212 2026] [proxy_http:error] [pid 66623:tid 66799] (20014)Internal error (specific information not available): [client 34.86.30.230:31058] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.169879 2026] [proxy_http:error] [pid 66623:tid 66822] (20014)Internal error (specific information not available): [client 34.86.30.230:31174] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.171151 2026] [security2:error] [pid 66623:tid 66831] [client 34.86.30.230:31102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/__env.js"] [unique_id "aoSBC9O5rbWdOArH04Ka5AAAAUs"] [Tue Aug 18 12:58:03.177212 2026] [proxy_http:error] [pid 66623:tid 66869] (20014)Internal error (specific information not available): [client 34.86.30.230:31066] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.184233 2026] [proxy_http:error] [pid 66623:tid 66813] (20014)Internal error (specific information not available): [client 34.86.30.230:42170] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.186101 2026] [security2:error] [pid 66623:tid 66816] [client 20.1.169.243:3415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka5wAAATw"] [Tue Aug 18 12:58:03.190953 2026] [proxy_http:error] [pid 66623:tid 66789] (20014)Internal error (specific information not available): [client 34.86.30.230:42138] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.210311 2026] [security2:error] [pid 66623:tid 66839] [client 34.86.30.230:31088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/actuator/logfile"] [unique_id "aoSBC9O5rbWdOArH04Ka7AAAAVM"] [Tue Aug 18 12:58:03.212613 2026] [proxy_http:error] [pid 66623:tid 66889] (20014)Internal error (specific information not available): [client 34.86.30.230:42090] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.240045 2026] [security2:error] [pid 66623:tid 66893] [client 34.86.30.230:41844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04Ka7gAAAYk"] [Tue Aug 18 12:58:03.241995 2026] [security2:error] [pid 66623:tid 66825] [client 34.86.30.230:42224] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04Ka7wAAAUU"] [Tue Aug 18 12:58:03.271676 2026] [security2:error] [pid 66623:tid 66871] [client 20.65.98.162:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/gm.php"] [unique_id "aoSBC9O5rbWdOArH04Ka8wAAAXM"] [Tue Aug 18 12:58:03.277463 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:21550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/v5.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9AAAAXo"] [Tue Aug 18 12:58:03.287352 2026] [security2:error] [pid 66623:tid 66785] [client 20.118.172.148:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/php.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9wAAAR0"] [Tue Aug 18 12:58:03.338673 2026] [security2:error] [pid 66623:tid 66853] [client 35.219.242.23:42896] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBC9O5rbWdOArH04Ka9gAAAWE"] [Tue Aug 18 12:58:03.339469 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/7.php"] [unique_id "aoSBC9O5rbWdOArH04Ka-AABdTM"] [Tue Aug 18 12:58:03.345086 2026] [security2:error] [pid 66623:tid 66777] [client 34.86.30.230:31036] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/workflows/ci.yml"] [unique_id "aoSBC9O5rbWdOArH04Ka-gAAARU"] [Tue Aug 18 12:58:03.348044 2026] [security2:error] [pid 66623:tid 66850] [client 40.74.65.169:49049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBC9O5rbWdOArH04Ka-wAAAV4"] [Tue Aug 18 12:58:03.359227 2026] [proxy_http:error] [pid 66623:tid 66841] (20014)Internal error (specific information not available): [client 34.86.30.230:31168] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.367619 2026] [proxy_http:error] [pid 66623:tid 66772] (20014)Internal error (specific information not available): [client 34.86.30.230:31156] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.377862 2026] [proxy_http:error] [pid 66623:tid 66766] (20014)Internal error (specific information not available): [client 34.86.30.230:31080] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.388904 2026] [security2:error] [pid 66623:tid 66822] [client 34.86.30.230:31052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/file"] [unique_id "aoSBC9O5rbWdOArH04KbAwAAAUI"] [Tue Aug 18 12:58:03.412399 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:11842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbBgAAAQ0"] [Tue Aug 18 12:58:03.412526 2026] [proxy_http:error] [pid 66623:tid 66818] (20014)Internal error (specific information not available): [client 34.86.30.230:31190] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.412542 2026] [proxy:error] [pid 66623:tid 66818] [client 34.86.30.230:31190] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.env.old [Tue Aug 18 12:58:03.414613 2026] [security2:error] [pid 66623:tid 66789] [client 40.74.65.169:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBC9O5rbWdOArH04KbBwAAASE"] [Tue Aug 18 12:58:03.441989 2026] [authz_core:error] [pid 66623:tid 66738] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:03.442241 2026] [authz_core:error] [pid 66623:tid 66738] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:03.447865 2026] [security2:error] [pid 66623:tid 66779] [client 34.86.30.230:31208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04KbDgAAARc"] [Tue Aug 18 12:58:03.458053 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.133.132:14805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBC9O5rbWdOArH04KbEAAAAX8"] [Tue Aug 18 12:58:03.461727 2026] [security2:error] [pid 66623:tid 66790] [client 20.219.2.203:7307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/up.php"] [unique_id "aoSBC9O5rbWdOArH04KbEgAAASI"] [Tue Aug 18 12:58:03.468293 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:31220] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.468309 2026] [proxy:error] [pid 66623:tid 66775] [client 34.86.30.230:31220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/web/.env [Tue Aug 18 12:58:03.474134 2026] [security2:error] [pid 66623:tid 66882] [client 20.203.138.185:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/opts.php"] [unique_id "aoSBC9O5rbWdOArH04KbFgAAAX4"] [Tue Aug 18 12:58:03.475323 2026] [proxy_http:error] [pid 66623:tid 66775] (20014)Internal error (specific information not available): [client 34.86.30.230:31220] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.475336 2026] [proxy:error] [pid 66623:tid 66775] [client 34.86.30.230:31220] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:03.477194 2026] [security2:error] [pid 66623:tid 66781] [client 20.186.30.159:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/new.php"] [unique_id "aoSBC9O5rbWdOArH04KbFwAAARk"] [Tue Aug 18 12:58:03.481643 2026] [autoindex:error] [pid 66623:tid 66814] [client 4.232.151.198:24933] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:03.497497 2026] [security2:error] [pid 66623:tid 66872] [client 34.86.30.230:31272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBC9O5rbWdOArH04KbIgAAAXQ"] [Tue Aug 18 12:58:03.503938 2026] [security2:error] [pid 66623:tid 66810] [client 34.86.30.230:31340] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbIwAAATY"] [Tue Aug 18 12:58:03.520005 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.154.236:7637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBC9O5rbWdOArH04KbJAAAAT8"] [Tue Aug 18 12:58:03.520278 2026] [security2:error] [pid 66623:tid 66712] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/8.php"] [unique_id "aoSBC9O5rbWdOArH04KbJQABg0s"] [Tue Aug 18 12:58:03.520446 2026] [security2:error] [pid 66623:tid 66884] [client 178.153.171.161:23814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbJgAAAYA"] [Tue Aug 18 12:58:03.520572 2026] [security2:error] [pid 66623:tid 66884] [client 178.153.171.161:23814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbJgAAAYA"] [Tue Aug 18 12:58:03.551127 2026] [security2:error] [pid 66623:tid 66805] [client 20.1.169.243:3652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/aaa.php"] [unique_id "aoSBC9O5rbWdOArH04KbLgAAATE"] [Tue Aug 18 12:58:03.558177 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/Text/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbMAAAAYQ"] [Tue Aug 18 12:58:03.586566 2026] [security2:error] [pid 66623:tid 66830] [client 172.182.217.32:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ee.php"] [unique_id "aoSBC9O5rbWdOArH04KbNgAAAUo"] [Tue Aug 18 12:58:03.592691 2026] [security2:error] [pid 66623:tid 66821] [client 213.35.127.232:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBC9O5rbWdOArH04KbNwAAAUE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:03.595926 2026] [proxy_http:error] [pid 66623:tid 66881] (20014)Internal error (specific information not available): [client 34.86.30.230:31312] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.595941 2026] [proxy:error] [pid 66623:tid 66881] [client 34.86.30.230:31312] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch [Tue Aug 18 12:58:03.603322 2026] [proxy_http:error] [pid 66623:tid 66832] (20014)Internal error (specific information not available): [client 34.86.30.230:31298] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.603358 2026] [proxy:error] [pid 66623:tid 66832] [client 34.86.30.230:31298] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/debug/default/view [Tue Aug 18 12:58:03.604792 2026] [security2:error] [pid 66623:tid 66677] [remote 173.252.70.12:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hotelvipempresas.com.br"] [uri "/site/Warning:%20%20Undefined%20variable%20$onde%20in%20/home1/hotelvip/public_html/site/includes/menu.php%20on%20line%205conteudo/hoteis"] [unique_id "aoSBC9O5rbWdOArH04KbDQABcig"] [Tue Aug 18 12:58:03.607961 2026] [security2:error] [pid 66623:tid 66701] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbOgABQEA"] [Tue Aug 18 12:58:03.608120 2026] [security2:error] [pid 66623:tid 66820] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBC9O5rbWdOArH04KbOgABQEA"] [Tue Aug 18 12:58:03.608876 2026] [security2:error] [pid 66623:tid 66877] [client 158.158.34.183:34344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/flower.php"] [unique_id "aoSBC9O5rbWdOArH04KbOwAAAXk"] [Tue Aug 18 12:58:03.610541 2026] [proxy_http:error] [pid 66623:tid 66845] (20014)Internal error (specific information not available): [client 34.86.30.230:31242] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.610560 2026] [proxy:error] [pid 66623:tid 66845] [client 34.86.30.230:31242] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/runtime-config.js [Tue Aug 18 12:58:03.617043 2026] [proxy_http:error] [pid 66623:tid 66810] (20014)Internal error (specific information not available): [client 34.86.30.230:31340] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.617065 2026] [proxy:error] [pid 66623:tid 66810] [client 34.86.30.230:31340] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html [Tue Aug 18 12:58:03.618332 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.172.148:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/t.php"] [unique_id "aoSBC9O5rbWdOArH04KbPgAAASE"] [Tue Aug 18 12:58:03.624916 2026] [proxy_http:error] [pid 66623:tid 66849] (20014)Internal error (specific information not available): [client 34.86.30.230:31452] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.624933 2026] [proxy:error] [pid 66623:tid 66849] [client 34.86.30.230:31452] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/read [Tue Aug 18 12:58:03.633047 2026] [proxy_http:error] [pid 66623:tid 66862] (20014)Internal error (specific information not available): [client 34.86.30.230:31474] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.633072 2026] [proxy:error] [pid 66623:tid 66862] [client 34.86.30.230:31474] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch [Tue Aug 18 12:58:03.661422 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/js.php"] [unique_id "aoSBC9O5rbWdOArH04KbQQAAARE"] [Tue Aug 18 12:58:03.689843 2026] [security2:error] [pid 66623:tid 66783] [client 4.232.151.198:24933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbQwAAARs"] [Tue Aug 18 12:58:03.697956 2026] [security2:error] [pid 66623:tid 66779] [client 20.48.236.86:2362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBC9O5rbWdOArH04KbRAAAARc"] [Tue Aug 18 12:58:03.698687 2026] [security2:error] [pid 66623:tid 66687] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/82.php"] [unique_id "aoSBC9O5rbWdOArH04KbRQABhjI"] [Tue Aug 18 12:58:03.781864 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/about.php"] [unique_id "aoSBC9O5rbWdOArH04KbSwAAAYI"] [Tue Aug 18 12:58:03.788068 2026] [security2:error] [pid 66623:tid 66794] [client 34.86.30.230:31518] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbTAAAASY"] [Tue Aug 18 12:58:03.824184 2026] [proxy_http:error] [pid 66623:tid 66816] (20014)Internal error (specific information not available): [client 34.86.30.230:31478] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:03.824201 2026] [proxy:error] [pid 66623:tid 66816] [client 34.86.30.230:31478] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/proxy [Tue Aug 18 12:58:03.876052 2026] [security2:error] [pid 66623:tid 66719] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/a.php"] [unique_id "aoSBC9O5rbWdOArH04KbWAABI1I"] [Tue Aug 18 12:58:03.908939 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kt.php"] [unique_id "aoSBC9O5rbWdOArH04KbXwAAASE"] [Tue Aug 18 12:58:03.914840 2026] [security2:error] [pid 66623:tid 66825] [client 20.1.169.243:3705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ojmarbleandgranite.com"] [uri "/fpwch.php"] [unique_id "aoSBC9O5rbWdOArH04KbYAAAAUU"] [Tue Aug 18 12:58:03.916054 2026] [security2:error] [pid 66623:tid 66874] [client 20.203.183.135:42481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/blurbs.php"] [unique_id "aoSBC9O5rbWdOArH04KbYgAAAXY"] [Tue Aug 18 12:58:03.932322 2026] [security2:error] [pid 66623:tid 66885] [client 34.86.30.230:31678] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBC9O5rbWdOArH04KbZAAAAYE"] [Tue Aug 18 12:58:03.952317 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.172.148:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/index/function.php"] [unique_id "aoSBC9O5rbWdOArH04KbZgAAAV0"] [Tue Aug 18 12:58:03.956163 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:54924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/we.php"] [unique_id "aoSBC9O5rbWdOArH04KbaAAAARM"] [Tue Aug 18 12:58:04.026762 2026] [security2:error] [pid 66623:tid 66882] [client 34.86.30.230:31226] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/fetch"] [unique_id "aoSBDNO5rbWdOArH04KbcQAAAX4"] [Tue Aug 18 12:58:04.029042 2026] [security2:error] [pid 66623:tid 66873] [client 158.158.74.177:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBDNO5rbWdOArH04KbcgAAAXU"] [Tue Aug 18 12:58:04.039171 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:04.039439 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:04.048149 2026] [security2:error] [pid 66623:tid 66781] [client 40.74.65.169:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/media.php"] [unique_id "aoSBDNO5rbWdOArH04KbdQAAARk"] [Tue Aug 18 12:58:04.049179 2026] [security2:error] [pid 66623:tid 66814] [client 20.186.30.159:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/new.php"] [unique_id "aoSBDNO5rbWdOArH04KbdgAAATo"] [Tue Aug 18 12:58:04.049201 2026] [proxy_http:error] [pid 66623:tid 66802] (20014)Internal error (specific information not available): [client 34.86.30.230:31312] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:04.059434 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aa.php"] [unique_id "aoSBDNO5rbWdOArH04KbeAABHQY"] [Tue Aug 18 12:58:04.061766 2026] [security2:error] [pid 66623:tid 66720] [remote 138.68.158.60:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.158.68.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viniciushartl.com.br"] [uri "/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KbdwABc1M"] [Tue Aug 18 12:58:04.092480 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.217.32:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/edit.php"] [unique_id "aoSBDNO5rbWdOArH04KbfQAAATc"] [Tue Aug 18 12:58:04.117001 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:13345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBDNO5rbWdOArH04KbfwAAAYA"] [Tue Aug 18 12:58:04.118800 2026] [security2:error] [pid 66623:tid 66794] [client 68.155.154.236:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBDNO5rbWdOArH04KbgAAAASY"] [Tue Aug 18 12:58:04.140675 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "aoSBDNO5rbWdOArH04KbgQAAARc"] [Tue Aug 18 12:58:04.155331 2026] [security2:error] [pid 66623:tid 66862] [client 20.100.185.105:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/403.php"] [unique_id "aoSBDNO5rbWdOArH04KbggAAAWo"] [Tue Aug 18 12:58:04.218572 2026] [security2:error] [pid 66623:tid 66816] [client 34.86.30.230:31478] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/proxy"] [unique_id "aoSBDNO5rbWdOArH04KbiQAAATw"] [Tue Aug 18 12:58:04.238846 2026] [security2:error] [pid 66623:tid 66676] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aaa.php"] [unique_id "aoSBDNO5rbWdOArH04KbigABECc"] [Tue Aug 18 12:58:04.256705 2026] [security2:error] [pid 66623:tid 66791] [client 20.118.172.148:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBDNO5rbWdOArH04KbjQAAASM"] [Tue Aug 18 12:58:04.284355 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/config/.env.php"] [unique_id "aoSBDNO5rbWdOArH04KbjwABeVU"] [Tue Aug 18 12:58:04.284581 2026] [security2:error] [pid 66623:tid 66789] [client 34.86.30.230:31200] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbkQAAASE"] [Tue Aug 18 12:58:04.291388 2026] [security2:error] [pid 66623:tid 66833] [client 34.86.30.230:31438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/api/v1/fetch"] [unique_id "aoSBDNO5rbWdOArH04KbkgAAAU0"] [Tue Aug 18 12:58:04.307968 2026] [security2:error] [pid 66623:tid 66887] [client 4.232.151.198:24946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KblwAAAYM"] [Tue Aug 18 12:58:04.310879 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/k.php"] [unique_id "aoSBDNO5rbWdOArH04KbmAAAAYI"] [Tue Aug 18 12:58:04.340402 2026] [authz_core:error] [pid 66623:tid 66751] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:04.340665 2026] [authz_core:error] [pid 66623:tid 66751] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:04.344419 2026] [security2:error] [pid 66623:tid 66775] [client 40.74.65.169:35723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBDNO5rbWdOArH04KbnAAAARM"] [Tue Aug 18 12:58:04.375913 2026] [security2:error] [pid 66623:tid 66810] [client 20.186.30.159:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/apreset.php"] [unique_id "aoSBDNO5rbWdOArH04KboAAAATY"] [Tue Aug 18 12:58:04.381545 2026] [security2:error] [pid 66623:tid 66742] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KboQABUmk"] [Tue Aug 18 12:58:04.388710 2026] [security2:error] [pid 66623:tid 66858] [client 85.154.68.202:56068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04KbowAAAWY"] [Tue Aug 18 12:58:04.388830 2026] [security2:error] [pid 66623:tid 66858] [client 85.154.68.202:56068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04KbowAAAWY"] [Tue Aug 18 12:58:04.391920 2026] [security2:error] [pid 66623:tid 66771] [client 20.219.2.203:7309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/w.php"] [unique_id "aoSBDNO5rbWdOArH04KbpAAAAQ8"] [Tue Aug 18 12:58:04.400457 2026] [proxy_http:error] [pid 66623:tid 66800] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F [Tue Aug 18 12:58:04.400471 2026] [proxy:error] [pid 66623:tid 66800] [client 34.86.30.230:31598] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/proxy, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F [Tue Aug 18 12:58:04.406897 2026] [proxy_http:error] [pid 66623:tid 66796] (20014)Internal error (specific information not available): [client 34.86.30.230:31614] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:04.406914 2026] [proxy:error] [pid 66623:tid 66796] [client 34.86.30.230:31614] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/api/download [Tue Aug 18 12:58:04.413863 2026] [proxy_http:error] [pid 66623:tid 66800] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F [Tue Aug 18 12:58:04.413889 2026] [proxy:error] [pid 66623:tid 66800] [client 34.86.30.230:31598] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml, referer: https://webmail.nightblue.com.br/proxy?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F [Tue Aug 18 12:58:04.416830 2026] [security2:error] [pid 66623:tid 66745] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/aar.php"] [unique_id "aoSBDNO5rbWdOArH04KbpQABImw"] [Tue Aug 18 12:58:04.420096 2026] [security2:error] [pid 66623:tid 66861] [client 20.118.172.148:43500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wk/index.php"] [unique_id "aoSBDNO5rbWdOArH04KbpgAAAWk"] [Tue Aug 18 12:58:04.455695 2026] [security2:error] [pid 66623:tid 66788] [client 34.86.30.230:31600] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbqgAAASA"] [Tue Aug 18 12:58:04.498066 2026] [security2:error] [pid 66623:tid 66818] [client 20.119.58.187:12090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/about.php"] [unique_id "aoSBDNO5rbWdOArH04KbrwAAAT4"] [Tue Aug 18 12:58:04.540859 2026] [security2:error] [pid 66623:tid 66843] [client 79.127.164.8:52390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/phpmyadmin.sql"] [unique_id "aoSBDNO5rbWdOArH04KbtAAAAVc"], referer: https://medihub.com.br/phpmyadmin.sql [Tue Aug 18 12:58:04.555327 2026] [security2:error] [pid 66623:tid 66804] [client 34.86.30.230:31254] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/preview"] [unique_id "aoSBDNO5rbWdOArH04KbtQAAATA"] [Tue Aug 18 12:58:04.563841 2026] [proxy_http:error] [pid 66623:tid 66829] (20014)Internal error (specific information not available): [client 34.86.30.230:31474] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:04.582477 2026] [security2:error] [pid 66623:tid 66873] [client 172.182.217.32:15795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/f35.php"] [unique_id "aoSBDNO5rbWdOArH04KbuwAAAXU"] [Tue Aug 18 12:58:04.604216 2026] [security2:error] [pid 66623:tid 66766] [client 213.35.127.232:62178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBDNO5rbWdOArH04KbvQAAAQo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:04.609266 2026] [security2:error] [pid 66623:tid 66888] [client 20.203.138.185:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zwq13.php"] [unique_id "aoSBDNO5rbWdOArH04KbvgAAAYQ"] [Tue Aug 18 12:58:04.609768 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:7169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wkl.php"] [unique_id "aoSBDNO5rbWdOArH04KbwAAAATs"] [Tue Aug 18 12:58:04.609875 2026] [security2:error] [pid 66623:tid 66710] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KbvwABEEk"] [Tue Aug 18 12:58:04.628182 2026] [security2:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ab.php"] [unique_id "aoSBDNO5rbWdOArH04KbxQABZV8"] [Tue Aug 18 12:58:04.633088 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.154.236:8031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBDNO5rbWdOArH04KbxgAAAWQ"] [Tue Aug 18 12:58:04.636157 2026] [security2:error] [pid 66623:tid 66841] [client 34.86.30.230:31642] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDNO5rbWdOArH04KbxwAAAVU"] [Tue Aug 18 12:58:04.641587 2026] [security2:error] [pid 66623:tid 66826] [client 20.186.30.159:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1mage.php"] [unique_id "aoSBDNO5rbWdOArH04KbygAAAUY"] [Tue Aug 18 12:58:04.644316 2026] [security2:error] [pid 66623:tid 66764] [remote 136.110.27.48:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.martinmadeireira.com.br"] [uri "/config.php.bak"] [unique_id "aoSBDNO5rbWdOArH04KbzAABbX8"] [Tue Aug 18 12:58:04.647614 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:04.647895 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:04.652133 2026] [security2:error] [pid 66623:tid 66791] [client 34.86.30.230:31586] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/image"] [unique_id "aoSBDNO5rbWdOArH04KbzQAAASM"] [Tue Aug 18 12:58:04.681911 2026] [security2:error] [pid 66623:tid 66769] [client 158.158.34.183:31101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSBDNO5rbWdOArH04Kb0gAAAQ0"] [Tue Aug 18 12:58:04.722799 2026] [security2:error] [pid 66623:tid 66887] [client 40.74.65.169:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/admin.php"] [unique_id "aoSBDNO5rbWdOArH04Kb2QAAAYM"] [Tue Aug 18 12:58:04.731109 2026] [security2:error] [pid 66623:tid 66810] [client 158.23.17.4:34043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ww.php"] [unique_id "aoSBDNO5rbWdOArH04Kb3QAAATY"] [Tue Aug 18 12:58:04.753295 2026] [proxy_http:error] [pid 66623:tid 66774] (20014)Internal error (specific information not available): [client 34.86.30.230:31598] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:04.780478 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.185.105:18295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "aoSBDNO5rbWdOArH04Kb3gAAAVE"] [Tue Aug 18 12:58:04.811525 2026] [security2:error] [pid 66623:tid 66845] [client 20.118.172.148:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBDNO5rbWdOArH04Kb4wAAAVk"] [Tue Aug 18 12:58:04.811870 2026] [security2:error] [pid 66623:tid 66659] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/abc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5AABLhY"] [Tue Aug 18 12:58:04.846961 2026] [security2:error] [pid 66623:tid 66867] [client 160.120.140.123:50738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.140.120.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5QAAAW8"] [Tue Aug 18 12:58:04.847074 2026] [security2:error] [pid 66623:tid 66867] [client 160.120.140.123:50738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "circuitofechado.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDNO5rbWdOArH04Kb5QAAAW8"] [Tue Aug 18 12:58:04.865482 2026] [security2:error] [pid 66623:tid 66773] [client 20.119.58.187:12480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/about.php"] [unique_id "aoSBDNO5rbWdOArH04Kb8AAAARE"] [Tue Aug 18 12:58:04.886742 2026] [security2:error] [pid 66623:tid 66821] [client 158.158.74.177:26136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBDNO5rbWdOArH04Kb9wAAAUE"] [Tue Aug 18 12:58:04.935622 2026] [security2:error] [pid 66623:tid 66881] [client 4.232.151.198:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBDNO5rbWdOArH04Kb_QAAAX0"] [Tue Aug 18 12:58:04.948564 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:04.948829 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:04.964192 2026] [security2:error] [pid 66623:tid 66858] [client 74.248.18.37:54963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/media/index.php"] [unique_id "aoSBDNO5rbWdOArH04KcAAAAAWY"] [Tue Aug 18 12:58:04.965334 2026] [security2:error] [pid 66623:tid 66879] [client 20.186.30.159:1679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/imsc.php"] [unique_id "aoSBDNO5rbWdOArH04KcAQAAAXs"] [Tue Aug 18 12:58:04.995440 2026] [security2:error] [pid 66623:tid 66673] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/abcd.php"] [unique_id "aoSBDNO5rbWdOArH04KcBAABaCQ"] [Tue Aug 18 12:58:05.012613 2026] [security2:error] [pid 66623:tid 66786] [client 20.215.241.237:46255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBDdO5rbWdOArH04KcCQAAAR4"] [Tue Aug 18 12:58:05.016742 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.154.236:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcCgAAAUM"] [Tue Aug 18 12:58:05.058736 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:25005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBDdO5rbWdOArH04KcDQAAARA"] [Tue Aug 18 12:58:05.071764 2026] [security2:error] [pid 66623:tid 66819] [client 172.182.217.32:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/fff.php"] [unique_id "aoSBDdO5rbWdOArH04KcDgAAAT8"] [Tue Aug 18 12:58:05.072736 2026] [security2:error] [pid 66623:tid 66824] [client 20.48.236.86:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDdO5rbWdOArH04KcDwAAAUQ"] [Tue Aug 18 12:58:05.131851 2026] [security2:error] [pid 66623:tid 66883] [client 40.74.65.169:43188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/media.php"] [unique_id "aoSBDdO5rbWdOArH04KcEwAAAX8"] [Tue Aug 18 12:58:05.167539 2026] [security2:error] [pid 66623:tid 66830] [client 20.118.172.148:43461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/xfun.php"] [unique_id "aoSBDdO5rbWdOArH04KcFgAAAUo"] [Tue Aug 18 12:58:05.178171 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcFwABI3Q"] [Tue Aug 18 12:58:05.215404 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBDdO5rbWdOArH04KcHAAAATQ"] [Tue Aug 18 12:58:05.219152 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/gallery/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcHQAAAWQ"] [Tue Aug 18 12:58:05.247655 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:05.248096 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:05.267882 2026] [security2:error] [pid 66623:tid 66812] [client 158.23.17.4:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mo.php"] [unique_id "aoSBDdO5rbWdOArH04KcJQAAATg"] [Tue Aug 18 12:58:05.271184 2026] [security2:error] [pid 66623:tid 66774] [client 20.186.30.159:1673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBDdO5rbWdOArH04KcJgAAARI"] [Tue Aug 18 12:58:05.339279 2026] [security2:error] [pid 66623:tid 66864] [client 20.219.2.203:7308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcKwAAAWw"] [Tue Aug 18 12:58:05.371628 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/about/function.php"] [unique_id "aoSBDdO5rbWdOArH04KcLgABLjw"] [Tue Aug 18 12:58:05.375688 2026] [security2:error] [pid 66623:tid 66796] [client 34.86.30.230:31614] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcLwAAASg"] [Tue Aug 18 12:58:05.417740 2026] [security2:error] [pid 66623:tid 66821] [client 40.74.65.169:49043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/mac.php"] [unique_id "aoSBDdO5rbWdOArH04KcNAAAAUE"] [Tue Aug 18 12:58:05.419698 2026] [security2:error] [pid 66623:tid 66776] [client 20.100.185.105:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/test1.php"] [unique_id "aoSBDdO5rbWdOArH04KcNgAAARQ"] [Tue Aug 18 12:58:05.444122 2026] [security2:error] [pid 66623:tid 66832] [client 192.141.172.134:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcOQAAAUw"] [Tue Aug 18 12:58:05.444235 2026] [security2:error] [pid 66623:tid 66832] [client 192.141.172.134:49707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcOQAAAUw"] [Tue Aug 18 12:58:05.485809 2026] [security2:error] [pid 66623:tid 66798] [client 34.86.30.230:31696] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDdO5rbWdOArH04KcOwAAASo"] [Tue Aug 18 12:58:05.493073 2026] [proxy_http:error] [pid 66623:tid 66805] (20014)Internal error (specific information not available): [client 34.86.30.230:31680] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.493091 2026] [proxy:error] [pid 66623:tid 66805] [client 34.86.30.230:31680] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/fetch [Tue Aug 18 12:58:05.501241 2026] [proxy_http:error] [pid 66623:tid 66853] (20014)Internal error (specific information not available): [client 34.86.30.230:31424] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.510312 2026] [proxy_http:error] [pid 66623:tid 66798] (20014)Internal error (specific information not available): [client 34.86.30.230:31696] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.518890 2026] [security2:error] [pid 66623:tid 66779] [client 20.118.133.132:1605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDdO5rbWdOArH04KcPwAAARc"] [Tue Aug 18 12:58:05.519023 2026] [security2:error] [pid 66623:tid 66845] [client 34.86.30.230:31744] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcQAAAAVk"] [Tue Aug 18 12:58:05.531591 2026] [security2:error] [pid 66623:tid 66862] [client 74.248.18.37:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/work.php"] [unique_id "aoSBDdO5rbWdOArH04KcQQAAAWo"] [Tue Aug 18 12:58:05.548200 2026] [authz_core:error] [pid 66623:tid 66719] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:05.548495 2026] [authz_core:error] [pid 66623:tid 66719] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:05.555874 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/admin/admin.php"] [unique_id "aoSBDdO5rbWdOArH04KcRAABYCU"] [Tue Aug 18 12:58:05.558862 2026] [security2:error] [pid 66623:tid 66773] [client 172.182.217.32:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ff1.php"] [unique_id "aoSBDdO5rbWdOArH04KcRQAAARE"] [Tue Aug 18 12:58:05.583061 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBDdO5rbWdOArH04KcRgAAAXo"] [Tue Aug 18 12:58:05.599297 2026] [autoindex:error] [pid 66623:tid 66885] [client 4.232.151.198:24899] AH01276: Cannot serve directory /home4/leguizai/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:05.606823 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.154.236:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcSQAAAWI"] [Tue Aug 18 12:58:05.618570 2026] [security2:error] [pid 66623:tid 66778] [client 34.86.30.230:31714] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDdO5rbWdOArH04KcSgAAARY"] [Tue Aug 18 12:58:05.619329 2026] [security2:error] [pid 66623:tid 66806] [client 213.35.127.232:62381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBDdO5rbWdOArH04KcSwAAATI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:05.636417 2026] [security2:error] [pid 66623:tid 66888] [client 20.186.30.159:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/qlex1.php"] [unique_id "aoSBDdO5rbWdOArH04KcTwAAAYQ"] [Tue Aug 18 12:58:05.643235 2026] [security2:error] [pid 66623:tid 66783] [client 34.86.30.230:31770] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDdO5rbWdOArH04KcUQAAARs"] [Tue Aug 18 12:58:05.648779 2026] [security2:error] [pid 66623:tid 66861] [client 34.86.30.230:31742] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcUgAAAWk"] [Tue Aug 18 12:58:05.653734 2026] [security2:error] [pid 66623:tid 66770] [client 114.5.214.109:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcVAAAAQ4"] [Tue Aug 18 12:58:05.656280 2026] [security2:error] [pid 66623:tid 66772] [client 20.203.138.185:10580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/Okxob.php"] [unique_id "aoSBDdO5rbWdOArH04KcVQAAARA"] [Tue Aug 18 12:58:05.658412 2026] [security2:error] [pid 66623:tid 66770] [client 114.5.214.109:49818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDdO5rbWdOArH04KcVAAAAQ4"] [Tue Aug 18 12:58:05.682772 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KcVwAAAX0"] [Tue Aug 18 12:58:05.733972 2026] [proxy_http:error] [pid 66623:tid 66873] (20014)Internal error (specific information not available): [client 34.86.30.230:31702] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.740595 2026] [security2:error] [pid 66623:tid 66738] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/admin/function.php"] [unique_id "aoSBDdO5rbWdOArH04KcWgABHGU"] [Tue Aug 18 12:58:05.768923 2026] [security2:error] [pid 66623:tid 66844] [client 34.86.30.230:31726] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDdO5rbWdOArH04KcXQAAAVg"] [Tue Aug 18 12:58:05.802202 2026] [security2:error] [pid 66623:tid 66830] [client 20.118.172.148:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/p.php"] [unique_id "aoSBDdO5rbWdOArH04KcYQAAAUo"] [Tue Aug 18 12:58:05.807241 2026] [security2:error] [pid 66623:tid 66828] [client 4.232.151.198:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBDdO5rbWdOArH04KcYgAAAUg"] [Tue Aug 18 12:58:05.817322 2026] [security2:error] [pid 66623:tid 66871] [client 52.173.121.69:16482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBDdO5rbWdOArH04KcZAAAAXM"] [Tue Aug 18 12:58:05.848041 2026] [proxy_http:error] [pid 66623:tid 66861] (20014)Internal error (specific information not available): [client 34.86.30.230:31742] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.848058 2026] [proxy:error] [pid 66623:tid 66861] [client 34.86.30.230:31742] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html [Tue Aug 18 12:58:05.854619 2026] [proxy_http:error] [pid 66623:tid 66844] (20014)Internal error (specific information not available): [client 34.86.30.230:31726] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:05.854636 2026] [proxy:error] [pid 66623:tid 66844] [client 34.86.30.230:31726] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cgi-sys/403.html [Tue Aug 18 12:58:05.869455 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.74.177:16533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBDdO5rbWdOArH04KcZgAAAR4"] [Tue Aug 18 12:58:05.893511 2026] [security2:error] [pid 66623:tid 66849] [client 213.202.253.4:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSBDdO5rbWdOArH04KcZwAAAV0"], referer: www.google.com [Tue Aug 18 12:58:05.896169 2026] [security2:error] [pid 66623:tid 66850] [client 158.158.34.183:53283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/OK.php"] [unique_id "aoSBDdO5rbWdOArH04KcaAAAAV4"] [Tue Aug 18 12:58:05.913090 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KcawAAAUs"] [Tue Aug 18 12:58:05.924583 2026] [security2:error] [pid 66623:tid 66808] [client 20.48.236.86:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/55.php"] [unique_id "aoSBDdO5rbWdOArH04KcbQAAATQ"] [Tue Aug 18 12:58:05.927852 2026] [security2:error] [pid 66623:tid 66856] [client 158.23.17.4:31874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qr.php"] [unique_id "aoSBDdO5rbWdOArH04KcbgAAAWQ"] [Tue Aug 18 12:58:05.929383 2026] [security2:error] [pid 66623:tid 66877] [client 40.74.65.169:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/inso.php"] [unique_id "aoSBDdO5rbWdOArH04KcbwAAAXk"] [Tue Aug 18 12:58:05.935762 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBDdO5rbWdOArH04KccAABeAY"] [Tue Aug 18 12:58:05.945278 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:12515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "aoSBDdO5rbWdOArH04KccQAAASM"] [Tue Aug 18 12:58:05.950995 2026] [security2:error] [pid 66623:tid 66836] [client 68.155.155.199:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSBDdO5rbWdOArH04KccgAAAVA"] [Tue Aug 18 12:58:06.031048 2026] [security2:error] [pid 66623:tid 66882] [client 20.186.30.159:1960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/mariju.php"] [unique_id "aoSBDtO5rbWdOArH04KcdgAAAX4"] [Tue Aug 18 12:58:06.039794 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/asd.php"] [unique_id "aoSBDtO5rbWdOArH04KcdwAAAS0"] [Tue Aug 18 12:58:06.046203 2026] [security2:error] [pid 66623:tid 66813] [client 172.182.217.32:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/flower.php"] [unique_id "aoSBDtO5rbWdOArH04KceAAAATk"] [Tue Aug 18 12:58:06.096542 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.154.236:48957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/first.php"] [unique_id "aoSBDtO5rbWdOArH04KcfAAAAW4"] [Tue Aug 18 12:58:06.108326 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:49065] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.compratec.com.br"] [uri "/1.php"] [unique_id "aoSBDtO5rbWdOArH04KcfQAAASs"] [Tue Aug 18 12:58:06.108446 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/1.php"] [unique_id "aoSBDtO5rbWdOArH04KcfQAAASs"] [Tue Aug 18 12:58:06.118928 2026] [security2:error] [pid 66623:tid 66706] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSBDtO5rbWdOArH04KcfgABTEU"] [Tue Aug 18 12:58:06.137179 2026] [security2:error] [pid 66623:tid 66886] [client 34.86.30.230:31774] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDtO5rbWdOArH04KcfwAAAYI"] [Tue Aug 18 12:58:06.150441 2026] [authz_core:error] [pid 66623:tid 66743] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:06.150688 2026] [authz_core:error] [pid 66623:tid 66743] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:06.163798 2026] [security2:error] [pid 66623:tid 66777] [client 20.118.172.148:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBDtO5rbWdOArH04KchAAAARU"] [Tue Aug 18 12:58:06.187871 2026] [security2:error] [pid 66623:tid 66810] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KchQAAATY"] [Tue Aug 18 12:58:06.201087 2026] [security2:error] [pid 66623:tid 66845] [client 34.86.30.230:31754] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDtO5rbWdOArH04KchwAAAVk"] [Tue Aug 18 12:58:06.301580 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ahax.php"] [unique_id "aoSBDtO5rbWdOArH04KcjAABPHA"] [Tue Aug 18 12:58:06.304939 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:12518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "aoSBDtO5rbWdOArH04KcjQAAASE"] [Tue Aug 18 12:58:06.311818 2026] [security2:error] [pid 66623:tid 66867] [client 74.248.18.37:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/worksec.php"] [unique_id "aoSBDtO5rbWdOArH04KcjgAAAW8"] [Tue Aug 18 12:58:06.364869 2026] [security2:error] [pid 66623:tid 66864] [client 20.219.2.203:8616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBDtO5rbWdOArH04KckwAAAWw"] [Tue Aug 18 12:58:06.390878 2026] [security2:error] [pid 66623:tid 66858] [client 34.86.30.230:31792] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBDtO5rbWdOArH04KclAAAAWY"] [Tue Aug 18 12:58:06.413931 2026] [security2:error] [pid 66623:tid 66881] [client 20.186.30.159:1686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBDtO5rbWdOArH04KclQAAAX0"] [Tue Aug 18 12:58:06.418036 2026] [security2:error] [pid 66623:tid 66889] [client 74.248.18.37:35389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mgrr.php"] [unique_id "aoSBDtO5rbWdOArH04KclwAAAYU"] [Tue Aug 18 12:58:06.443908 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:62104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBDtO5rbWdOArH04KcmwAAARY"] [Tue Aug 18 12:58:06.446582 2026] [security2:error] [pid 66623:tid 66852] [client 4.232.151.198:24952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBDtO5rbWdOArH04KcnAAAAWA"] [Tue Aug 18 12:58:06.458971 2026] [security2:error] [pid 66623:tid 66824] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KclgAAAUQ"] [Tue Aug 18 12:58:06.468316 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.155.199:8497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSBDtO5rbWdOArH04KcoAAAAWs"] [Tue Aug 18 12:58:06.485062 2026] [security2:error] [pid 66623:tid 66646] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/alfa.php"] [unique_id "aoSBDtO5rbWdOArH04KcogABXwk"] [Tue Aug 18 12:58:06.497177 2026] [security2:error] [pid 66623:tid 66835] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "joanagaspar.com.br"] [uri "/"] [unique_id "aoSBDtO5rbWdOArH04KcpQABT3E"], referer: https://joanagaspar.com.br/ [Tue Aug 18 12:58:06.499227 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:46753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aaa.php"] [unique_id "aoSBDtO5rbWdOArH04KcpgAAAR8"] [Tue Aug 18 12:58:06.531171 2026] [security2:error] [pid 66623:tid 66823] [client 20.79.204.6:11709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/akc.php"] [unique_id "aoSBDtO5rbWdOArH04KcqgAAAUM"] [Tue Aug 18 12:58:06.570621 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.217.32:15571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/file.php"] [unique_id "aoSBDtO5rbWdOArH04KcrAAAAVo"] [Tue Aug 18 12:58:06.582758 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:48263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBDtO5rbWdOArH04KcrQAAAR4"] [Tue Aug 18 12:58:06.614937 2026] [security2:error] [pid 66623:tid 66850] [client 20.203.138.185:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/file59.php"] [unique_id "aoSBDtO5rbWdOArH04KcrwAAAV4"] [Tue Aug 18 12:58:06.628825 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.133.132:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/55.php"] [unique_id "aoSBDtO5rbWdOArH04KcsAAAATQ"] [Tue Aug 18 12:58:06.639117 2026] [security2:error] [pid 66623:tid 66860] [client 213.35.127.232:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBDtO5rbWdOArH04KcsQAAAWg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:06.658858 2026] [security2:error] [pid 66623:tid 66868] [client 20.186.30.159:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/contacto.php"] [unique_id "aoSBDtO5rbWdOArH04KcsgAAAXA"] [Tue Aug 18 12:58:06.660829 2026] [security2:error] [pid 66623:tid 66771] [client 34.86.30.230:31780] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/fetch"] [unique_id "aoSBDtO5rbWdOArH04KcswAAAQ8"] [Tue Aug 18 12:58:06.662762 2026] [security2:error] [pid 66623:tid 66704] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/alfax.php"] [unique_id "aoSBDtO5rbWdOArH04KctAABUEM"] [Tue Aug 18 12:58:06.669608 2026] [security2:error] [pid 66623:tid 66880] [client 20.119.58.187:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/cloud.php"] [unique_id "aoSBDtO5rbWdOArH04KctQAAAXw"] [Tue Aug 18 12:58:06.688514 2026] [security2:error] [pid 66623:tid 66774] [client 40.74.65.169:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/shiny.php"] [unique_id "aoSBDtO5rbWdOArH04KctgAAARI"] [Tue Aug 18 12:58:06.696691 2026] [autoindex:error] [pid 66623:tid 66838] [client 205.210.31.149:64762] AH01276: Cannot serve directory /home2/rj9727inseozcb1z/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:06.723166 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:24970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBDtO5rbWdOArH04KcugAAAS0"] [Tue Aug 18 12:58:06.742811 2026] [security2:error] [pid 66623:tid 66872] [client 20.206.73.37:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBDtO5rbWdOArH04KcuwAAAXQ"] [Tue Aug 18 12:58:06.757497 2026] [authz_core:error] [pid 66623:tid 66710] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:06.757946 2026] [authz_core:error] [pid 66623:tid 66710] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:06.784206 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:49076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/coffee.php"] [unique_id "aoSBDtO5rbWdOArH04KcwAAAASg"] [Tue Aug 18 12:58:06.839377 2026] [security2:error] [pid 66623:tid 66842] [client 34.86.30.230:31808] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/proxy"] [unique_id "aoSBDtO5rbWdOArH04KcxQAAAVY"] [Tue Aug 18 12:58:06.840993 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ant.php"] [unique_id "aoSBDtO5rbWdOArH04KcxgABah4"] [Tue Aug 18 12:58:06.866120 2026] [security2:error] [pid 66623:tid 66877] [client 35.219.242.23:42920] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBDtO5rbWdOArH04KcxwAAAXk"] [Tue Aug 18 12:58:06.882486 2026] [security2:error] [pid 66623:tid 66886] [client 172.182.200.96:14161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBDtO5rbWdOArH04KcyQAAAYI"] [Tue Aug 18 12:58:06.891999 2026] [security2:error] [pid 66623:tid 66885] [client 20.65.98.162:44177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/ws55.php"] [unique_id "aoSBDtO5rbWdOArH04KczQAAAYE"] [Tue Aug 18 12:58:06.906382 2026] [security2:error] [pid 66623:tid 66789] [client 20.48.236.86:32885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ajax.php"] [unique_id "aoSBDtO5rbWdOArH04Kc0gAAASE"] [Tue Aug 18 12:58:06.910009 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.154.236:48928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBDtO5rbWdOArH04Kc0wAAAW8"] [Tue Aug 18 12:58:06.924167 2026] [security2:error] [pid 66623:tid 66892] [client 20.118.172.148:43476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/term.php"] [unique_id "aoSBDtO5rbWdOArH04Kc1gAAAYg"] [Tue Aug 18 12:58:06.956363 2026] [security2:error] [pid 66623:tid 66814] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joanagaspar.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSBDtO5rbWdOArH04Kc0QABOhQ"], referer: https://joanagaspar.com.br/ [Tue Aug 18 12:58:06.972347 2026] [security2:error] [pid 66623:tid 66887] [client 158.158.34.183:31053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/config.php7"] [unique_id "aoSBDtO5rbWdOArH04Kc2QAAAYM"] [Tue Aug 18 12:58:06.986315 2026] [security2:error] [pid 66623:tid 66776] [client 74.248.18.37:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBDtO5rbWdOArH04Kc2gAAARQ"] [Tue Aug 18 12:58:07.027694 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/app.php"] [unique_id "aoSBD9O5rbWdOArH04Kc3AABiU4"] [Tue Aug 18 12:58:07.047486 2026] [security2:error] [pid 66623:tid 66834] [client 20.119.58.187:11859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSBD9O5rbWdOArH04Kc3gAAAU4"] [Tue Aug 18 12:58:07.054886 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:07.055151 2026] [authz_core:error] [pid 66623:tid 66735] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:07.060346 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.217.32:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/goods.php"] [unique_id "aoSBD9O5rbWdOArH04Kc4QAAATw"] [Tue Aug 18 12:58:07.091433 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dirs.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5AAAAV4"] [Tue Aug 18 12:58:07.092710 2026] [security2:error] [pid 66623:tid 66831] [client 20.100.185.105:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5QAAAUs"] [Tue Aug 18 12:58:07.103105 2026] [security2:error] [pid 66623:tid 66808] [client 20.118.172.148:56427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBD9O5rbWdOArH04Kc5gAAATQ"] [Tue Aug 18 12:58:07.108820 2026] [security2:error] [pid 66623:tid 66833] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc4gAAAU0"] [Tue Aug 18 12:58:07.118084 2026] [security2:error] [pid 66623:tid 66860] [client 20.186.30.159:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/image2.php"] [unique_id "aoSBD9O5rbWdOArH04Kc6wAAAWg"] [Tue Aug 18 12:58:07.136193 2026] [security2:error] [pid 66623:tid 66845] [client 20.79.204.6:11558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/buy.php"] [unique_id "aoSBD9O5rbWdOArH04Kc7AAAAVk"] [Tue Aug 18 12:58:07.184539 2026] [security2:error] [pid 66623:tid 66826] [client 34.86.30.230:31680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/azure-pipelines.yml"] [unique_id "aoSBD9O5rbWdOArH04Kc8AAAAUY"] [Tue Aug 18 12:58:07.191822 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.155.199:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSBD9O5rbWdOArH04Kc8gAAAYY"] [Tue Aug 18 12:58:07.248087 2026] [security2:error] [pid 66623:tid 66696] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/archive.php"] [unique_id "aoSBD9O5rbWdOArH04Kc9AABJTs"] [Tue Aug 18 12:58:07.259024 2026] [authz_core:error] [pid 66623:tid 66659] [remote 57.141.22.86:63388] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:07.259280 2026] [authz_core:error] [pid 66623:tid 66659] [remote 57.141.22.86:63388] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:07.277097 2026] [security2:error] [pid 66623:tid 66830] [client 34.86.30.230:31924] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.vercel/.env.production.local"] [unique_id "aoSBD9O5rbWdOArH04Kc_gAAAUo"] [Tue Aug 18 12:58:07.282239 2026] [proxy_http:error] [pid 66623:tid 66794] (20014)Internal error (specific information not available): [client 34.86.30.230:31946] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.282257 2026] [proxy:error] [pid 66623:tid 66794] [client 34.86.30.230:31946] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.vercel/.env.development.local [Tue Aug 18 12:58:07.290159 2026] [proxy_http:error] [pid 66623:tid 66870] (20014)Internal error (specific information not available): [client 34.86.30.230:31828] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.290182 2026] [proxy:error] [pid 66623:tid 66870] [client 34.86.30.230:31828] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/jenkins/Jenkinsfile [Tue Aug 18 12:58:07.290219 2026] [security2:error] [pid 66623:tid 66771] [client 20.203.138.185:38101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/eauu.php"] [unique_id "aoSBD9O5rbWdOArH04KdAgAAAQ8"] [Tue Aug 18 12:58:07.293127 2026] [security2:error] [pid 66623:tid 66832] [client 20.203.183.135:52383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/bajah.php"] [unique_id "aoSBD9O5rbWdOArH04KdCAAAAUw"] [Tue Aug 18 12:58:07.296517 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:2741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/7.php"] [unique_id "aoSBD9O5rbWdOArH04KdCQAAASg"] [Tue Aug 18 12:58:07.298557 2026] [proxy_http:error] [pid 66623:tid 66835] (20014)Internal error (specific information not available): [client 34.86.30.230:31890] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.298572 2026] [proxy:error] [pid 66623:tid 66835] [client 34.86.30.230:31890] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.travis.yml [Tue Aug 18 12:58:07.299654 2026] [security2:error] [pid 66623:tid 66783] [client 34.86.30.230:31852] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.ci"] [unique_id "aoSBD9O5rbWdOArH04KdCgAAARs"] [Tue Aug 18 12:58:07.305818 2026] [proxy_http:error] [pid 66623:tid 66787] (20014)Internal error (specific information not available): [client 34.86.30.230:31888] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.305838 2026] [proxy:error] [pid 66623:tid 66787] [client 34.86.30.230:31888] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.circleci/config.yml [Tue Aug 18 12:58:07.325180 2026] [proxy_http:error] [pid 66623:tid 66822] (20014)Internal error (specific information not available): [client 34.86.30.230:31904] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.325199 2026] [proxy:error] [pid 66623:tid 66822] [client 34.86.30.230:31904] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/.drone.yml [Tue Aug 18 12:58:07.332626 2026] [proxy_http:error] [pid 66623:tid 66824] (20014)Internal error (specific information not available): [client 34.86.30.230:31922] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.332643 2026] [proxy:error] [pid 66623:tid 66824] [client 34.86.30.230:31922] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/cloudbuild.yaml [Tue Aug 18 12:58:07.352119 2026] [proxy_http:error] [pid 66623:tid 66787] (20014)Internal error (specific information not available): [client 34.86.30.230:31888] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.352140 2026] [proxy:error] [pid 66623:tid 66787] [client 34.86.30.230:31888] AH00898: Error reading from remote server returned by /___proxy_subdomain_webmail/502.shtml [Tue Aug 18 12:58:07.358562 2026] [authz_core:error] [pid 66623:tid 66759] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:07.358959 2026] [authz_core:error] [pid 66623:tid 66759] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:07.372379 2026] [security2:error] [pid 66623:tid 66785] [client 35.219.242.23:42908] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdEgAAAR0"] [Tue Aug 18 12:58:07.373678 2026] [security2:error] [pid 66623:tid 66878] [client 20.186.30.159:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fb.php"] [unique_id "aoSBD9O5rbWdOArH04KdFgAAAXo"] [Tue Aug 18 12:58:07.382087 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.18.37:21562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mini.php"] [unique_id "aoSBD9O5rbWdOArH04KdGAAAAWM"] [Tue Aug 18 12:58:07.385050 2026] [security2:error] [pid 66623:tid 66853] [client 35.219.242.23:42920] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andradesalescarregamentos.com.br"] [uri "/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdEwAAAWE"] [Tue Aug 18 12:58:07.390560 2026] [security2:error] [pid 66623:tid 66854] [client 34.86.30.230:31826] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/workflows/test.yml"] [unique_id "aoSBD9O5rbWdOArH04KdGQAAAWI"] [Tue Aug 18 12:58:07.391320 2026] [autoindex:error] [pid 66623:tid 66778] [client 20.219.2.203:10410] AH01276: Cannot serve directory /home2/cropman/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:07.401299 2026] [security2:error] [pid 66623:tid 66815] [client 188.82.68.190:40376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSBDtO5rbWdOArH04KcvwABO00"], referer: https://bioarquitetar.com/xmlrpc.php [Tue Aug 18 12:58:07.405893 2026] [security2:error] [pid 66623:tid 66821] [client 20.119.58.187:11983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updates.php"] [unique_id "aoSBD9O5rbWdOArH04KdHQAAAUE"] [Tue Aug 18 12:58:07.428895 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/as.php"] [unique_id "aoSBD9O5rbWdOArH04KdHgABUxg"] [Tue Aug 18 12:58:07.438363 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:25952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/yj09.php"] [unique_id "aoSBD9O5rbWdOArH04KdHwAAASk"] [Tue Aug 18 12:58:07.465942 2026] [security2:error] [pid 66623:tid 66887] [client 34.86.30.230:31946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.github/secrets.env"] [unique_id "aoSBD9O5rbWdOArH04KdIgAAAYM"] [Tue Aug 18 12:58:07.482706 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBD9O5rbWdOArH04KdJAAAAWw"] [Tue Aug 18 12:58:07.489034 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:24285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBD9O5rbWdOArH04KdJQAAAX0"] [Tue Aug 18 12:58:07.490282 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:11916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/mosty.php"] [unique_id "aoSBD9O5rbWdOArH04KdJgAAAWc"] [Tue Aug 18 12:58:07.498443 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:12200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBD9O5rbWdOArH04KdJwAAASw"] [Tue Aug 18 12:58:07.533763 2026] [security2:error] [pid 66623:tid 66769] [client 158.158.74.177:22760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBD9O5rbWdOArH04KdLwAAAQ0"] [Tue Aug 18 12:58:07.540543 2026] [proxy_http:error] [pid 66623:tid 66786] (20014)Internal error (specific information not available): [client 34.86.30.230:31892] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.544202 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:25022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBD9O5rbWdOArH04KdNAAAAUs"] [Tue Aug 18 12:58:07.547914 2026] [security2:error] [pid 66623:tid 66885] [client 172.182.217.32:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/g.php"] [unique_id "aoSBD9O5rbWdOArH04KdNQAAAYE"] [Tue Aug 18 12:58:07.560874 2026] [security2:error] [pid 66623:tid 66856] [client 34.86.30.230:31922] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.env.production.bak"] [unique_id "aoSBD9O5rbWdOArH04KdNwAAAWQ"] [Tue Aug 18 12:58:07.563744 2026] [security2:error] [pid 66623:tid 66860] [client 34.86.30.230:31844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/var/www/html/.env"] [unique_id "aoSBD9O5rbWdOArH04KdOAAAAWg"] [Tue Aug 18 12:58:07.567825 2026] [proxy_http:error] [pid 66623:tid 66833] (20014)Internal error (specific information not available): [client 34.86.30.230:31904] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:07.570854 2026] [security2:error] [pid 66623:tid 66883] [client 157.51.166.53:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdOgAAAX8"] [Tue Aug 18 12:58:07.581203 2026] [security2:error] [pid 66623:tid 66883] [client 157.51.166.53:51525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdOgAAAX8"] [Tue Aug 18 12:58:07.588145 2026] [security2:error] [pid 66623:tid 66880] [client 20.118.172.148:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/0x.php"] [unique_id "aoSBD9O5rbWdOArH04KdPgAAAXw"] [Tue Aug 18 12:58:07.608700 2026] [security2:error] [pid 66623:tid 66838] [client 40.74.65.169:43187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/403dd.php"] [unique_id "aoSBD9O5rbWdOArH04KdRgAAAVI"] [Tue Aug 18 12:58:07.630234 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSBD9O5rbWdOArH04KdSQABRjM"] [Tue Aug 18 12:58:07.651283 2026] [authz_core:error] [pid 66623:tid 66748] [remote 57.141.22.20:20924] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:07.651548 2026] [authz_core:error] [pid 66623:tid 66748] [remote 57.141.22.20:20924] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:07.653947 2026] [security2:error] [pid 66623:tid 66775] [client 213.35.127.232:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBD9O5rbWdOArH04KdSwAAARM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:07.661485 2026] [security2:error] [pid 66623:tid 66814] [client 74.248.18.37:7179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBD9O5rbWdOArH04KdTQAAATo"] [Tue Aug 18 12:58:07.697786 2026] [security2:error] [pid 66623:tid 66866] [client 20.186.30.159:1698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/gi.php"] [unique_id "aoSBD9O5rbWdOArH04KdUAAAAW4"] [Tue Aug 18 12:58:07.708277 2026] [security2:error] [pid 66623:tid 66780] [client 20.219.2.203:10410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBD9O5rbWdOArH04KdUwAAARg"] [Tue Aug 18 12:58:07.720795 2026] [security2:error] [pid 66623:tid 66893] [client 20.100.185.105:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/gg.php"] [unique_id "aoSBD9O5rbWdOArH04KdVAAAAYk"] [Tue Aug 18 12:58:07.729834 2026] [security2:error] [pid 66623:tid 66851] [client 20.118.172.148:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file5.php"] [unique_id "aoSBD9O5rbWdOArH04KdVwAAAV8"] [Tue Aug 18 12:58:07.732509 2026] [security2:error] [pid 66623:tid 66781] [client 20.206.73.37:24270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBD9O5rbWdOArH04KdWAAAARk"] [Tue Aug 18 12:58:07.741830 2026] [security2:error] [pid 66623:tid 66849] [client 20.79.204.6:11682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/cong.php"] [unique_id "aoSBD9O5rbWdOArH04KdXAAAAV0"] [Tue Aug 18 12:58:07.749777 2026] [security2:error] [pid 66623:tid 66836] [client 34.86.30.230:31822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.30.86.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nightblue.com.br"] [uri "/.env.local.php"] [unique_id "aoSBD9O5rbWdOArH04KdPQAAAVA"] [Tue Aug 18 12:58:07.758615 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/css/cloud.php"] [unique_id "aoSBD9O5rbWdOArH04KdXgAAAYY"] [Tue Aug 18 12:58:07.819188 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/atomlib.php"] [unique_id "aoSBD9O5rbWdOArH04KdZQABVGc"] [Tue Aug 18 12:58:07.906673 2026] [security2:error] [pid 66623:tid 66884] [client 196.12.128.158:56957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdaAAAAYA"] [Tue Aug 18 12:58:07.906812 2026] [security2:error] [pid 66623:tid 66884] [client 196.12.128.158:56957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdaAAAAYA"] [Tue Aug 18 12:58:07.959064 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:07.959332 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:07.960963 2026] [security2:error] [pid 66623:tid 66872] [client 103.139.191.60:50084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdbAAAAXQ"] [Tue Aug 18 12:58:07.961085 2026] [security2:error] [pid 66623:tid 66872] [client 103.139.191.60:50084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ctrrefrigeracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBD9O5rbWdOArH04KdbAAAAXQ"] [Tue Aug 18 12:58:07.970132 2026] [security2:error] [pid 66623:tid 66846] [client 47.128.62.10:43782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acqualereformadepiscina.com.br"] [uri "/robots.txt"] [unique_id "aoSBD9O5rbWdOArH04KdbQAAAVo"] [Tue Aug 18 12:58:07.997426 2026] [security2:error] [pid 66623:tid 66662] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/b.php"] [unique_id "aoSBD9O5rbWdOArH04KdbwABbBk"] [Tue Aug 18 12:58:08.002133 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:50089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/domvf.php"] [unique_id "aoSBENO5rbWdOArH04KdcAAAAX0"] [Tue Aug 18 12:58:08.035919 2026] [security2:error] [pid 66623:tid 66824] [client 172.182.217.32:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBENO5rbWdOArH04KddAAAAUQ"] [Tue Aug 18 12:58:08.088775 2026] [security2:error] [pid 66623:tid 66861] [client 172.182.200.96:7631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/mt/byp.php"] [unique_id "aoSBENO5rbWdOArH04KddgAAAWk"] [Tue Aug 18 12:58:08.097235 2026] [security2:error] [pid 66623:tid 66855] [client 74.248.18.37:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/minishell.php"] [unique_id "aoSBENO5rbWdOArH04KddwAAAWM"] [Tue Aug 18 12:58:08.105145 2026] [security2:error] [pid 66623:tid 66737] [remote 103.82.26.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yycc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBENO5rbWdOArH04KdeQABd2Q"] [Tue Aug 18 12:58:08.112827 2026] [security2:error] [pid 66623:tid 66879] [client 20.119.58.187:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/cloud.php"] [unique_id "aoSBENO5rbWdOArH04KdegAAAXs"] [Tue Aug 18 12:58:08.113337 2026] [security2:error] [pid 66623:tid 66844] [client 20.186.30.159:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/video.php"] [unique_id "aoSBENO5rbWdOArH04KdewAAAVg"] [Tue Aug 18 12:58:08.123224 2026] [security2:error] [pid 66623:tid 66769] [client 68.155.155.199:19454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/xmr.php"] [unique_id "aoSBENO5rbWdOArH04KdfAAAAQ0"] [Tue Aug 18 12:58:08.138641 2026] [security2:error] [pid 66623:tid 66843] [client 20.48.236.86:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/scxy.php"] [unique_id "aoSBENO5rbWdOArH04KdfgAAAVc"] [Tue Aug 18 12:58:08.149074 2026] [security2:error] [pid 66623:tid 66850] [client 20.206.73.37:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBENO5rbWdOArH04KdgAAAAV4"] [Tue Aug 18 12:58:08.165369 2026] [security2:error] [pid 66623:tid 66856] [client 40.74.65.169:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBENO5rbWdOArH04KdggAAAWQ"] [Tue Aug 18 12:58:08.177917 2026] [security2:error] [pid 66623:tid 66709] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/backup.php"] [unique_id "aoSBENO5rbWdOArH04KdhgABTUg"] [Tue Aug 18 12:58:08.235471 2026] [security2:error] [pid 66623:tid 66775] [client 34.86.30.230:31828] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/www/.env"] [unique_id "aoSBENO5rbWdOArH04KdiwAAARM"] [Tue Aug 18 12:58:08.257020 2026] [authz_core:error] [pid 66623:tid 66724] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:08.257278 2026] [authz_core:error] [pid 66623:tid 66724] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:08.260476 2026] [security2:error] [pid 66623:tid 66793] [client 20.206.73.37:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gec.php"] [unique_id "aoSBENO5rbWdOArH04KdjQAAASU"] [Tue Aug 18 12:58:08.265349 2026] [security2:error] [pid 66623:tid 66827] [client 20.203.138.185:45321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/dsd.php"] [unique_id "aoSBENO5rbWdOArH04KdjgAAAUc"] [Tue Aug 18 12:58:08.277324 2026] [security2:error] [pid 66623:tid 66802] [client 20.118.172.148:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBENO5rbWdOArH04KdjwAAAS4"] [Tue Aug 18 12:58:08.288051 2026] [security2:error] [pid 66623:tid 66893] [client 20.206.73.37:52047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/sky.php"] [unique_id "aoSBENO5rbWdOArH04KdkQAAAYk"] [Tue Aug 18 12:58:08.312310 2026] [authz_core:error] [pid 66623:tid 66761] [remote 57.141.22.109:47760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:08.312663 2026] [authz_core:error] [pid 66623:tid 66761] [remote 57.141.22.109:47760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:08.316596 2026] [security2:error] [pid 66623:tid 66794] [client 34.86.30.230:31890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/.netlify/.env"] [unique_id "aoSBENO5rbWdOArH04KdlAAAASY"] [Tue Aug 18 12:58:08.321875 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:48297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/weozh.php"] [unique_id "aoSBENO5rbWdOArH04KdlQAAAXI"] [Tue Aug 18 12:58:08.322611 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/sixxis.php"] [unique_id "aoSBENO5rbWdOArH04KdlgAAAVw"] [Tue Aug 18 12:58:08.335105 2026] [security2:error] [pid 66623:tid 66852] [client 34.86.30.230:31740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/%2eenv"] [unique_id "aoSBENO5rbWdOArH04KdmQAAAWA"] [Tue Aug 18 12:58:08.337176 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:59813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/yj09.php"] [unique_id "aoSBENO5rbWdOArH04KdmwAAATY"] [Tue Aug 18 12:58:08.338401 2026] [security2:error] [pid 66623:tid 66840] [client 34.86.30.230:31888] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.nightblue.com.br"] [uri "/supabase/.env"] [unique_id "aoSBENO5rbWdOArH04KdnQAAAVQ"] [Tue Aug 18 12:58:08.338633 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.185.105:58359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/file.php"] [unique_id "aoSBENO5rbWdOArH04KdnAAAAR4"] [Tue Aug 18 12:58:08.348167 2026] [security2:error] [pid 66623:tid 66837] [client 40.74.65.169:28165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/baba.php"] [unique_id "aoSBENO5rbWdOArH04KdngAAAVE"] [Tue Aug 18 12:58:08.350001 2026] [security2:error] [pid 66623:tid 66885] [client 20.79.204.6:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBENO5rbWdOArH04KdnwAAAYE"] [Tue Aug 18 12:58:08.359684 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/k.php"] [unique_id "aoSBENO5rbWdOArH04KdoQAAAR8"] [Tue Aug 18 12:58:08.359734 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bak.php"] [unique_id "aoSBENO5rbWdOArH04KdoAABFSU"] [Tue Aug 18 12:58:08.396654 2026] [core:error] [pid 66623:tid 66806] [client 34.86.30.230:31908] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 12:58:08.406217 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.172.148:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/222.php"] [unique_id "aoSBENO5rbWdOArH04KdpgAAAWI"] [Tue Aug 18 12:58:08.417124 2026] [security2:error] [pid 66623:tid 66886] [client 34.86.30.230:31880] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webmail.nightblue.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSBENO5rbWdOArH04KdqAAAAYI"] [Tue Aug 18 12:58:08.429294 2026] [security2:error] [pid 66623:tid 66822] [client 158.158.34.183:31054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSBENO5rbWdOArH04KdqQAAAUI"] [Tue Aug 18 12:58:08.435897 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/w.php"] [unique_id "aoSBENO5rbWdOArH04KdqgAAATs"] [Tue Aug 18 12:58:08.471155 2026] [security2:error] [pid 66623:tid 66862] [client 20.119.58.187:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/cloud.php"] [unique_id "aoSBENO5rbWdOArH04KdrwAAAWo"] [Tue Aug 18 12:58:08.481948 2026] [core:error] [pid 66623:tid 66881] [client 34.86.30.230:31824] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 12:58:08.482115 2026] [security2:error] [pid 66623:tid 66859] [client 20.186.30.159:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/hel.php"] [unique_id "aoSBENO5rbWdOArH04KdsQAAAWc"] [Tue Aug 18 12:58:08.529060 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBENO5rbWdOArH04KdtQAAATE"] [Tue Aug 18 12:58:08.529154 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBENO5rbWdOArH04KdtQAAATE"] [Tue Aug 18 12:58:08.541147 2026] [security2:error] [pid 66623:tid 66878] [client 172.182.217.32:15767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBENO5rbWdOArH04KdtwAAAXo"] [Tue Aug 18 12:58:08.558480 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBENO5rbWdOArH04KdugAAAXE"] [Tue Aug 18 12:58:08.559807 2026] [security2:error] [pid 66623:tid 66703] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bgymj.php"] [unique_id "aoSBENO5rbWdOArH04KduwABaUI"] [Tue Aug 18 12:58:08.564596 2026] [authz_core:error] [pid 66623:tid 66656] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:08.565008 2026] [authz_core:error] [pid 66623:tid 66656] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:08.574160 2026] [core:error] [pid 66623:tid 66797] [client 34.86.30.230:31832] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 12:58:08.582614 2026] [proxy_http:error] [pid 66623:tid 66782] (20014)Internal error (specific information not available): [client 34.86.30.230:31866] AH01102: error reading status line from remote server 127.0.0.1:2095 [Tue Aug 18 12:58:08.585374 2026] [security2:error] [pid 66623:tid 66855] [client 20.206.73.37:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fpwch.php"] [unique_id "aoSBENO5rbWdOArH04KdvgAAAWM"] [Tue Aug 18 12:58:08.633901 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:8104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/about.php"] [unique_id "aoSBENO5rbWdOArH04KdvwAAAVg"] [Tue Aug 18 12:58:08.676630 2026] [security2:error] [pid 66623:tid 66835] [client 213.35.127.232:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBENO5rbWdOArH04KdwwAAAU8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:08.679010 2026] [security2:error] [pid 66623:tid 66801] [client 20.219.2.203:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBENO5rbWdOArH04KdxAAAAS0"] [Tue Aug 18 12:58:08.716383 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:24306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBENO5rbWdOArH04KdxgAAAXw"] [Tue Aug 18 12:58:08.728982 2026] [security2:error] [pid 66623:tid 66829] [client 20.48.236.86:25930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ws13.php"] [unique_id "aoSBENO5rbWdOArH04KdyAAAAUk"] [Tue Aug 18 12:58:08.740465 2026] [security2:error] [pid 66623:tid 66774] [client 158.23.17.4:38305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sn.php"] [unique_id "aoSBENO5rbWdOArH04KdyQAAARI"] [Tue Aug 18 12:58:08.745492 2026] [security2:error] [pid 66623:tid 66665] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bi.php"] [unique_id "aoSBENO5rbWdOArH04KdygABChw"] [Tue Aug 18 12:58:08.771557 2026] [security2:error] [pid 66623:tid 66868] [client 20.206.73.37:40647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/blurbs.php"] [unique_id "aoSBENO5rbWdOArH04KdzgAAAXA"] [Tue Aug 18 12:58:08.801488 2026] [security2:error] [pid 66623:tid 66781] [client 20.118.133.132:21726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ajax.php"] [unique_id "aoSBENO5rbWdOArH04Kd0AAAARk"] [Tue Aug 18 12:58:08.813956 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mm.php"] [unique_id "aoSBENO5rbWdOArH04Kd0QAAAVY"] [Tue Aug 18 12:58:08.815149 2026] [security2:error] [pid 66623:tid 66799] [client 172.182.200.96:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBENO5rbWdOArH04Kd0gAAASs"] [Tue Aug 18 12:58:08.820567 2026] [security2:error] [pid 66623:tid 66832] [client 20.186.30.159:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/grok.php"] [unique_id "aoSBENO5rbWdOArH04Kd0wAAAUw"] [Tue Aug 18 12:58:08.828769 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBENO5rbWdOArH04Kd1QAAAXg"] [Tue Aug 18 12:58:08.830406 2026] [security2:error] [pid 66623:tid 66875] [client 158.158.74.177:26127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBENO5rbWdOArH04Kd1gAAAXc"] [Tue Aug 18 12:58:08.835796 2026] [security2:error] [pid 66623:tid 66791] [client 20.206.73.37:52521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/100.php"] [unique_id "aoSBENO5rbWdOArH04Kd2QAAASM"] [Tue Aug 18 12:58:08.858167 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:08.858495 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:08.860320 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:64165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/yj09.php"] [unique_id "aoSBENO5rbWdOArH04Kd3AAAAWY"] [Tue Aug 18 12:58:08.889498 2026] [security2:error] [pid 66623:tid 66874] [client 216.73.160.245:59469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaquimlirio333.com.br"] [uri "/wp-login.php"] [unique_id "aoSBENO5rbWdOArH04Kd3gAAAXY"] [Tue Aug 18 12:58:08.926342 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/blog.php"] [unique_id "aoSBENO5rbWdOArH04Kd4QABNnA"] [Tue Aug 18 12:58:08.957051 2026] [security2:error] [pid 66623:tid 66775] [client 20.79.204.6:11700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/db.php"] [unique_id "aoSBENO5rbWdOArH04Kd5AAAARM"] [Tue Aug 18 12:58:08.969179 2026] [security2:error] [pid 66623:tid 66826] [client 20.100.185.105:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/index/function.php"] [unique_id "aoSBENO5rbWdOArH04Kd5QAAAUY"] [Tue Aug 18 12:58:08.976410 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.98.162:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/m.php"] [unique_id "aoSBENO5rbWdOArH04Kd5gAAARU"] [Tue Aug 18 12:58:08.984172 2026] [security2:error] [pid 66623:tid 66854] [client 20.206.73.37:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ccc.php"] [unique_id "aoSBENO5rbWdOArH04Kd5wAAAWI"] [Tue Aug 18 12:58:09.000435 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:19796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/c4.php"] [unique_id "aoSBENO5rbWdOArH04Kd6AAAARY"] [Tue Aug 18 12:58:09.048097 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:63049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBEdO5rbWdOArH04Kd6gAAAYM"] [Tue Aug 18 12:58:09.048162 2026] [security2:error] [pid 66623:tid 66792] [client 172.182.217.32:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/in.php"] [unique_id "aoSBEdO5rbWdOArH04Kd6wAAASQ"] [Tue Aug 18 12:58:09.080204 2026] [security2:error] [pid 66623:tid 66686] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBEdO5rbWdOArH04Kd7gABUzE"] [Tue Aug 18 12:58:09.101596 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:52083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/get.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8AAAAWc"] [Tue Aug 18 12:58:09.102241 2026] [security2:error] [pid 66623:tid 66857] [client 20.186.30.159:1967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/indes.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8QAAAWU"] [Tue Aug 18 12:58:09.102255 2026] [security2:error] [pid 66623:tid 66649] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/info.php"] [unique_id "aoSBEdO5rbWdOArH04Kd8gABMAw"] [Tue Aug 18 12:58:09.107658 2026] [security2:error] [pid 66623:tid 66723] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bs1.php"] [unique_id "aoSBEdO5rbWdOArH04Kd9AABLFY"] [Tue Aug 18 12:58:09.158916 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:09.159174 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:09.176761 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/site.php"] [unique_id "aoSBEdO5rbWdOArH04Kd_gAAAUM"] [Tue Aug 18 12:58:09.187748 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSBEdO5rbWdOArH04KeAgAAASg"] [Tue Aug 18 12:58:09.227750 2026] [security2:error] [pid 66623:tid 66834] [client 20.206.73.37:45799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/images.php"] [unique_id "aoSBEdO5rbWdOArH04KeBQAAAU4"] [Tue Aug 18 12:58:09.273492 2026] [security2:error] [pid 66623:tid 66745] [remote 136.110.27.48:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.nadianobre.com.br"] [uri "/i.php"] [unique_id "aoSBEdO5rbWdOArH04KeCAABQGw"] [Tue Aug 18 12:58:09.282615 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:40676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/alls.php"] [unique_id "aoSBEdO5rbWdOArH04KeCwAAAU8"] [Tue Aug 18 12:58:09.286728 2026] [security2:error] [pid 66623:tid 66638] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bthil.php"] [unique_id "aoSBEdO5rbWdOArH04KeDQABLQE"] [Tue Aug 18 12:58:09.313085 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:45813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/coffexium.php"] [unique_id "aoSBEdO5rbWdOArH04KeEwAAAXw"] [Tue Aug 18 12:58:09.316552 2026] [authz_core:error] [pid 66623:tid 66657] [remote 89.124.86.18:55130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:09.317018 2026] [authz_core:error] [pid 66623:tid 66657] [remote 89.124.86.18:55130] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:09.343387 2026] [security2:error] [pid 66623:tid 66774] [client 20.206.73.37:52051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/red.php"] [unique_id "aoSBEdO5rbWdOArH04KeFAAAARI"] [Tue Aug 18 12:58:09.356948 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:7210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBEdO5rbWdOArH04KeFgAAAXo"] [Tue Aug 18 12:58:09.394526 2026] [security2:error] [pid 66623:tid 66893] [client 20.186.30.159:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBEdO5rbWdOArH04KeGwAAAYk"] [Tue Aug 18 12:58:09.395943 2026] [security2:error] [pid 66623:tid 66798] [client 158.23.17.4:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/43.php"] [unique_id "aoSBEdO5rbWdOArH04KeHAAAASo"] [Tue Aug 18 12:58:09.425714 2026] [security2:error] [pid 66623:tid 66817] [client 20.118.172.148:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBEdO5rbWdOArH04KeHwAAAT0"] [Tue Aug 18 12:58:09.431803 2026] [security2:error] [pid 66623:tid 66876] [client 20.206.73.37:52489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeIAAAAXg"] [Tue Aug 18 12:58:09.452264 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/aa.php"] [unique_id "aoSBEdO5rbWdOArH04KeIwAAAS8"] [Tue Aug 18 12:58:09.476801 2026] [security2:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/bypass.php"] [unique_id "aoSBEdO5rbWdOArH04KeJwABJkc"] [Tue Aug 18 12:58:09.479040 2026] [security2:error] [pid 66623:tid 66890] [client 20.206.73.37:21705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBEdO5rbWdOArH04KeKQAAAYY"] [Tue Aug 18 12:58:09.488468 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.154.236:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeKgAAAXY"] [Tue Aug 18 12:58:09.507662 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file52.php"] [unique_id "aoSBEdO5rbWdOArH04KeKwAAATc"] [Tue Aug 18 12:58:09.510544 2026] [security2:error] [pid 66623:tid 66892] [client 68.155.155.199:13848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSBEdO5rbWdOArH04KeLAAAAYg"] [Tue Aug 18 12:58:09.533117 2026] [security2:error] [pid 66623:tid 66840] [client 40.74.65.169:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/scxy.php"] [unique_id "aoSBEdO5rbWdOArH04KeLQAAAVQ"] [Tue Aug 18 12:58:09.536082 2026] [security2:error] [pid 66623:tid 66818] [client 20.206.73.37:52035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/geck.php"] [unique_id "aoSBEdO5rbWdOArH04KeLgAAAT4"] [Tue Aug 18 12:58:09.538600 2026] [security2:error] [pid 66623:tid 66883] [client 74.248.18.37:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBEdO5rbWdOArH04KeLwAAAX8"] [Tue Aug 18 12:58:09.542011 2026] [security2:error] [pid 66623:tid 66868] [client 172.182.217.32:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/info.php"] [unique_id "aoSBEdO5rbWdOArH04KeMAAAAXA"] [Tue Aug 18 12:58:09.544847 2026] [security2:error] [pid 66623:tid 66841] [client 20.119.58.187:12516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/avaa.php"] [unique_id "aoSBEdO5rbWdOArH04KeMQAAAVU"] [Tue Aug 18 12:58:09.565099 2026] [security2:error] [pid 66623:tid 66814] [client 20.79.204.6:11704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/dropdown.php"] [unique_id "aoSBEdO5rbWdOArH04KeMgAAATo"] [Tue Aug 18 12:58:09.576284 2026] [security2:error] [pid 66623:tid 66786] [client 20.206.73.37:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/biufile.php"] [unique_id "aoSBEdO5rbWdOArH04KeNAAAAR4"] [Tue Aug 18 12:58:09.587103 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.185.105:6255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/getid3-core.php"] [unique_id "aoSBEdO5rbWdOArH04KeNQAAARg"] [Tue Aug 18 12:58:09.607790 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dejavu.php"] [unique_id "aoSBEdO5rbWdOArH04KeNwAAAR0"] [Tue Aug 18 12:58:09.627411 2026] [security2:error] [pid 66623:tid 66833] [client 20.219.2.203:8582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.2.219.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBEdO5rbWdOArH04KeOQAAAU0"] [Tue Aug 18 12:58:09.640327 2026] [security2:error] [pid 66623:tid 66777] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeOAABFWE"] [Tue Aug 18 12:58:09.665857 2026] [security2:error] [pid 66623:tid 66815] [client 20.186.30.159:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/bs1.php"] [unique_id "aoSBEdO5rbWdOArH04KePAAAATs"] [Tue Aug 18 12:58:09.698757 2026] [security2:error] [pid 66623:tid 66836] [client 158.158.74.177:26165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBEdO5rbWdOArH04KePgAAAVA"] [Tue Aug 18 12:58:09.698838 2026] [security2:error] [pid 66623:tid 66888] [client 213.35.127.232:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBEdO5rbWdOArH04KePQAAAYQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:09.700266 2026] [security2:error] [pid 66623:tid 66779] [client 20.203.138.185:38091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/an7.php"] [unique_id "aoSBEdO5rbWdOArH04KePwAAARc"] [Tue Aug 18 12:58:09.704803 2026] [security2:error] [pid 66623:tid 66714] [remote 103.82.26.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yycc.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBEdO5rbWdOArH04KeQAABS00"] [Tue Aug 18 12:58:09.710985 2026] [security2:error] [pid 66623:tid 66792] [client 20.206.73.37:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aaf.php"] [unique_id "aoSBEdO5rbWdOArH04KeQQAAASQ"] [Tue Aug 18 12:58:09.755117 2026] [security2:error] [pid 66623:tid 66839] [client 20.118.172.148:2751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/atomlib.php"] [unique_id "aoSBEdO5rbWdOArH04KeQwAAAVM"] [Tue Aug 18 12:58:09.779705 2026] [security2:error] [pid 66623:tid 66770] [client 20.48.236.86:32890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/btx25.php"] [unique_id "aoSBEdO5rbWdOArH04KeRgAAAQ4"] [Tue Aug 18 12:58:09.862509 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/33.php"] [unique_id "aoSBEdO5rbWdOArH04KeTAAAAXE"] [Tue Aug 18 12:58:09.888831 2026] [security2:error] [pid 66623:tid 66819] [client 192.141.172.134:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTgAAAT8"] [Tue Aug 18 12:58:09.891301 2026] [security2:error] [pid 66623:tid 66819] [client 192.141.172.134:49955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTgAAAT8"] [Tue Aug 18 12:58:09.895021 2026] [security2:error] [pid 66623:tid 66783] [client 86.120.159.145:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTwAAARs"] [Tue Aug 18 12:58:09.895146 2026] [security2:error] [pid 66623:tid 66783] [client 86.120.159.145:59156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBEdO5rbWdOArH04KeTwAAARs"] [Tue Aug 18 12:58:09.900834 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/cloud.php"] [unique_id "aoSBEdO5rbWdOArH04KeUAAAAUU"] [Tue Aug 18 12:58:09.911890 2026] [security2:error] [pid 66623:tid 66782] [client 20.186.30.159:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/hp2.php"] [unique_id "aoSBEdO5rbWdOArH04KeUQAAARo"] [Tue Aug 18 12:58:09.914634 2026] [security2:error] [pid 66623:tid 66877] [client 20.118.172.148:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/abcd.php"] [unique_id "aoSBEdO5rbWdOArH04KeUgAAAXk"] [Tue Aug 18 12:58:09.941697 2026] [security2:error] [pid 66623:tid 66754] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cc.php"] [unique_id "aoSBEdO5rbWdOArH04KeVQABWHU"] [Tue Aug 18 12:58:09.994137 2026] [security2:error] [pid 66623:tid 66847] [client 20.206.73.37:20680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/blurbs.php"] [unique_id "aoSBEdO5rbWdOArH04KeVwAAAVs"] [Tue Aug 18 12:58:09.994199 2026] [security2:error] [pid 66623:tid 66867] [client 20.206.73.37:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBEdO5rbWdOArH04KeWAAAAW8"] [Tue Aug 18 12:58:10.001545 2026] [security2:error] [pid 66623:tid 66812] [client 40.74.65.169:29626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBEtO5rbWdOArH04KeWQAAATg"] [Tue Aug 18 12:58:10.020619 2026] [security2:error] [pid 66623:tid 66838] [client 158.23.17.4:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fresh.php"] [unique_id "aoSBEtO5rbWdOArH04KeWwAAAVI"] [Tue Aug 18 12:58:10.030570 2026] [security2:error] [pid 66623:tid 66870] [client 172.182.217.32:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/inputs.php"] [unique_id "aoSBEtO5rbWdOArH04KeXQAAAXI"] [Tue Aug 18 12:58:10.044852 2026] [security2:error] [pid 66623:tid 66781] [client 34.86.30.230:31870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.30.86.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.nightblue.com.br"] [uri "/.env.php"] [unique_id "aoSBEtO5rbWdOArH04KeXgAAARk"] [Tue Aug 18 12:58:10.055912 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KeYAAAAV8"] [Tue Aug 18 12:58:10.062603 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:10.062878 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:10.121105 2026] [security2:error] [pid 66623:tid 66675] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KeYwABdyY"] [Tue Aug 18 12:58:10.153603 2026] [security2:error] [pid 66623:tid 66803] [client 20.186.30.159:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/yb.php"] [unique_id "aoSBEtO5rbWdOArH04KeZQAAAS8"] [Tue Aug 18 12:58:10.171696 2026] [security2:error] [pid 66623:tid 66801] [client 20.79.204.6:11675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/file.php"] [unique_id "aoSBEtO5rbWdOArH04KeZgAAAS0"] [Tue Aug 18 12:58:10.228647 2026] [security2:error] [pid 66623:tid 66840] [client 40.74.65.169:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBEtO5rbWdOArH04KebQAAAVQ"] [Tue Aug 18 12:58:10.256349 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "aoSBEtO5rbWdOArH04KebgAAASM"] [Tue Aug 18 12:58:10.325838 2026] [security2:error] [pid 66623:tid 66786] [client 20.118.172.148:53066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/min.php"] [unique_id "aoSBEtO5rbWdOArH04KecwAAAR4"] [Tue Aug 18 12:58:10.352409 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.18.37:7201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ms-themes.php"] [unique_id "aoSBEtO5rbWdOArH04KedAAAAXQ"] [Tue Aug 18 12:58:10.405541 2026] [security2:error] [pid 66623:tid 66853] [client 20.186.30.159:1665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/vc.php"] [unique_id "aoSBEtO5rbWdOArH04KedwAAAWE"] [Tue Aug 18 12:58:10.425197 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBEtO5rbWdOArH04KeeAAAAYA"] [Tue Aug 18 12:58:10.440654 2026] [security2:error] [pid 66623:tid 66871] [client 20.100.185.105:58320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/edit.php"] [unique_id "aoSBEtO5rbWdOArH04KeegAAAXM"] [Tue Aug 18 12:58:10.520812 2026] [security2:error] [pid 66623:tid 66785] [client 172.182.217.32:15604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/item.php"] [unique_id "aoSBEtO5rbWdOArH04KehAAAAR0"] [Tue Aug 18 12:58:10.520877 2026] [security2:error] [pid 66623:tid 66767] [client 158.158.34.183:31073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/randkeyword.php"] [unique_id "aoSBEtO5rbWdOArH04KehQAAAQs"] [Tue Aug 18 12:58:10.523425 2026] [security2:error] [pid 66623:tid 66857] [client 20.118.172.148:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KehgAAAWU"] [Tue Aug 18 12:58:10.532996 2026] [security2:error] [pid 66623:tid 66841] [client 79.127.164.8:40180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/pma.bak"] [unique_id "aoSBEtO5rbWdOArH04KehwAAAVU"], referer: https://medihub.com.br/pma.bak [Tue Aug 18 12:58:10.534712 2026] [security2:error] [pid 66623:tid 66886] [client 20.206.73.37:24265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/155.php"] [unique_id "aoSBEtO5rbWdOArH04KeiAAAAYI"] [Tue Aug 18 12:58:10.602530 2026] [security2:error] [pid 66623:tid 66819] [client 20.203.138.185:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSBEtO5rbWdOArH04KejAAAAT8"] [Tue Aug 18 12:58:10.621542 2026] [security2:error] [pid 66623:tid 66864] [client 20.119.58.187:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "aoSBEtO5rbWdOArH04KejwAAAWw"] [Tue Aug 18 12:58:10.665214 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:10.665486 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:10.670988 2026] [security2:error] [pid 66623:tid 66807] [client 20.186.30.159:1981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/pema.php"] [unique_id "aoSBEtO5rbWdOArH04KelQAAATM"] [Tue Aug 18 12:58:10.687015 2026] [security2:error] [pid 66623:tid 66834] [client 52.173.121.69:24771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBEtO5rbWdOArH04KelgAAAU4"] [Tue Aug 18 12:58:10.703414 2026] [security2:error] [pid 66623:tid 66850] [client 20.104.85.180:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBEtO5rbWdOArH04KelwAAAV4"] [Tue Aug 18 12:58:10.710971 2026] [security2:error] [pid 66623:tid 66843] [client 20.118.172.148:46771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/mac.php"] [unique_id "aoSBEtO5rbWdOArH04KemAAAAVc"] [Tue Aug 18 12:58:10.723871 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBEtO5rbWdOArH04KemQAAARU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:10.732864 2026] [security2:error] [pid 66623:tid 66820] [client 20.118.133.132:1916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/yj09.php"] [unique_id "aoSBEtO5rbWdOArH04KemgAAAUA"] [Tue Aug 18 12:58:10.736044 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:7405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/cabs.php"] [unique_id "aoSBEtO5rbWdOArH04KemwAAAUM"] [Tue Aug 18 12:58:10.739412 2026] [security2:error] [pid 66623:tid 66845] [client 158.23.17.4:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gj.php"] [unique_id "aoSBEtO5rbWdOArH04KenAAAAVk"] [Tue Aug 18 12:58:10.774973 2026] [security2:error] [pid 66623:tid 66805] [client 20.79.204.6:11698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/goods.php"] [unique_id "aoSBEtO5rbWdOArH04KengAAATE"] [Tue Aug 18 12:58:10.788892 2026] [security2:error] [pid 66623:tid 66880] [client 20.48.236.86:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBEtO5rbWdOArH04KeoQAAAXw"] [Tue Aug 18 12:58:10.863801 2026] [security2:error] [pid 66623:tid 66759] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSBEtO5rbWdOArH04KepAABeHo"] [Tue Aug 18 12:58:10.886421 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:54932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBEtO5rbWdOArH04KepQAAAXk"] [Tue Aug 18 12:58:10.900491 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.154.236:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBEtO5rbWdOArH04KepgAAAWc"] [Tue Aug 18 12:58:10.907459 2026] [security2:error] [pid 66623:tid 66801] [client 40.74.65.169:49078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBEtO5rbWdOArH04KepwAAAS0"] [Tue Aug 18 12:58:10.920165 2026] [security2:error] [pid 66623:tid 66794] [client 20.186.30.159:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/sh.php"] [unique_id "aoSBEtO5rbWdOArH04KeqAAAASY"] [Tue Aug 18 12:58:10.929916 2026] [security2:error] [pid 66623:tid 66881] [client 158.158.74.177:26149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBEtO5rbWdOArH04KeqQAAAX0"] [Tue Aug 18 12:58:10.965513 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:10.965804 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:10.974656 2026] [security2:error] [pid 66623:tid 66771] [client 20.119.58.187:11874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBEtO5rbWdOArH04KerQAAAQ8"] [Tue Aug 18 12:58:11.017259 2026] [security2:error] [pid 66623:tid 66829] [client 172.182.217.32:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/k.php"] [unique_id "aoSBE9O5rbWdOArH04KergAAAUk"] [Tue Aug 18 12:58:11.046004 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/my1.php"] [unique_id "aoSBE9O5rbWdOArH04KesAAAAUc"] [Tue Aug 18 12:58:11.089331 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:46741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/nc4.php"] [unique_id "aoSBE9O5rbWdOArH04KetAAAAX8"] [Tue Aug 18 12:58:11.200143 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:14151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/MTOS/byp.php"] [unique_id "aoSBE9O5rbWdOArH04KeuAAAAWI"] [Tue Aug 18 12:58:11.267530 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:11.267815 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:11.283850 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.185.105:59767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "aoSBE9O5rbWdOArH04KewAAAAVo"] [Tue Aug 18 12:58:11.302757 2026] [security2:error] [pid 66623:tid 66766] [client 158.23.17.4:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pd.php"] [unique_id "aoSBE9O5rbWdOArH04KewQAAAQo"] [Tue Aug 18 12:58:11.336452 2026] [security2:error] [pid 66623:tid 66853] [client 20.119.58.187:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/cloud.php"] [unique_id "aoSBE9O5rbWdOArH04KewwAAAWE"] [Tue Aug 18 12:58:11.337842 2026] [security2:error] [pid 66623:tid 66839] [client 20.206.73.37:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ops.php"] [unique_id "aoSBE9O5rbWdOArH04KexAAAAVM"] [Tue Aug 18 12:58:11.343784 2026] [security2:error] [pid 66623:tid 66813] [client 20.186.30.159:1847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/button.php"] [unique_id "aoSBE9O5rbWdOArH04KexQAAATk"] [Tue Aug 18 12:58:11.348552 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSBE9O5rbWdOArH04KexwABTXg"] [Tue Aug 18 12:58:11.350996 2026] [security2:error] [pid 66623:tid 66855] [client 103.184.169.37:42308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KeyAAAAWM"] [Tue Aug 18 12:58:11.351088 2026] [security2:error] [pid 66623:tid 66855] [client 103.184.169.37:42308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KeyAAAAWM"] [Tue Aug 18 12:58:11.370279 2026] [security2:error] [pid 66623:tid 66804] [client 20.104.85.180:26285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBE9O5rbWdOArH04KeyQAAATA"] [Tue Aug 18 12:58:11.376172 2026] [security2:error] [pid 66623:tid 66787] [client 20.79.204.6:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBE9O5rbWdOArH04KeywAAAR8"] [Tue Aug 18 12:58:11.385622 2026] [security2:error] [pid 66623:tid 66784] [client 68.155.154.236:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBE9O5rbWdOArH04KezAAAARw"] [Tue Aug 18 12:58:11.400135 2026] [security2:error] [pid 66623:tid 66800] [client 20.203.138.185:38136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/byp8.php"] [unique_id "aoSBE9O5rbWdOArH04KezgAAASw"] [Tue Aug 18 12:58:11.406637 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0AAAASg"] [Tue Aug 18 12:58:11.435686 2026] [security2:error] [pid 66623:tid 66797] [client 40.74.65.169:35774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/insc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0QAAASk"] [Tue Aug 18 12:58:11.441469 2026] [security2:error] [pid 66623:tid 66786] [client 158.158.34.183:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0gAAAR4"] [Tue Aug 18 12:58:11.451315 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:53067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/as.php"] [unique_id "aoSBE9O5rbWdOArH04Ke0wAAAT8"] [Tue Aug 18 12:58:11.479348 2026] [security2:error] [pid 66623:tid 66781] [client 188.82.68.190:35278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04KevQABGW4"], referer: https://bioarquitetar.com/xmlrpc.php [Tue Aug 18 12:58:11.500330 2026] [security2:error] [pid 66623:tid 66822] [client 172.182.217.32:15776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/license.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1QAAAUI"] [Tue Aug 18 12:58:11.522073 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:16489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1gAAAVc"] [Tue Aug 18 12:58:11.530041 2026] [security2:error] [pid 66623:tid 66693] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSBE9O5rbWdOArH04Ke1wABQDg"] [Tue Aug 18 12:58:11.550172 2026] [security2:error] [pid 66623:tid 66821] [client 20.100.169.31:32721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBE9O5rbWdOArH04Ke2QAAAUE"] [Tue Aug 18 12:58:11.590082 2026] [security2:error] [pid 66623:tid 66812] [client 40.74.65.169:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/blurbs.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3QAAATg"] [Tue Aug 18 12:58:11.591772 2026] [security2:error] [pid 66623:tid 66808] [client 68.155.155.199:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/as.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3gAAATQ"] [Tue Aug 18 12:58:11.600852 2026] [security2:error] [pid 66623:tid 66882] [client 20.186.30.159:1939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/wlc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke3wAAAX4"] [Tue Aug 18 12:58:11.615179 2026] [security2:error] [pid 66623:tid 66890] [client 103.120.71.157:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke4AAAAYY"] [Tue Aug 18 12:58:11.615313 2026] [security2:error] [pid 66623:tid 66890] [client 103.120.71.157:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke4AAAAYY"] [Tue Aug 18 12:58:11.692186 2026] [security2:error] [pid 66623:tid 66867] [client 20.119.58.187:12525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5AAAAW8"] [Tue Aug 18 12:58:11.711166 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/new.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5QAAAW0"] [Tue Aug 18 12:58:11.715275 2026] [security2:error] [pid 66623:tid 66724] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5gABfVc"] [Tue Aug 18 12:58:11.734421 2026] [security2:error] [pid 66623:tid 66790] [client 172.182.200.96:7668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBE9O5rbWdOArH04Ke5wAAASI"] [Tue Aug 18 12:58:11.741193 2026] [security2:error] [pid 66623:tid 66873] [client 213.35.127.232:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBE9O5rbWdOArH04Ke6AAAAXU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:11.813270 2026] [security2:error] [pid 66623:tid 66878] [client 20.118.172.148:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/k.php"] [unique_id "aoSBE9O5rbWdOArH04Ke7AAAAXo"] [Tue Aug 18 12:58:11.815545 2026] [security2:error] [pid 66623:tid 66802] [client 158.158.74.177:2625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBE9O5rbWdOArH04Ke7QAAAS4"] [Tue Aug 18 12:58:11.857543 2026] [security2:error] [pid 66623:tid 66818] [client 20.186.30.159:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/fi.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8AAAAT4"] [Tue Aug 18 12:58:11.879158 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/akc.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8gAAATw"] [Tue Aug 18 12:58:11.892077 2026] [security2:error] [pid 66623:tid 66761] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/config.php"] [unique_id "aoSBE9O5rbWdOArH04Ke8wABNnw"] [Tue Aug 18 12:58:11.894424 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9AAAAT0"] [Tue Aug 18 12:58:11.903682 2026] [security2:error] [pid 66623:tid 66803] [client 20.100.185.105:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9QAAAS8"] [Tue Aug 18 12:58:11.906100 2026] [security2:error] [pid 66623:tid 66780] [client 20.215.241.237:52676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9gAAARg"] [Tue Aug 18 12:58:11.929870 2026] [security2:error] [pid 66623:tid 66854] [client 20.48.236.86:48715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBE9O5rbWdOArH04Ke9wAAAWI"] [Tue Aug 18 12:58:11.977103 2026] [security2:error] [pid 66623:tid 66827] [client 20.79.204.6:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/htaccess.php"] [unique_id "aoSBE9O5rbWdOArH04Ke-QAAAUc"] [Tue Aug 18 12:58:11.993820 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.217.32:15755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/load.php"] [unique_id "aoSBE9O5rbWdOArH04Ke-gAAASM"] [Tue Aug 18 12:58:12.005151 2026] [security2:error] [pid 66623:tid 66792] [client 20.118.133.132:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/scxy.php"] [unique_id "aoSBFNO5rbWdOArH04Ke-wAAASQ"] [Tue Aug 18 12:58:12.044009 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:10599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/plugins.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_QAAAWE"] [Tue Aug 18 12:58:12.053587 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.154.236:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_gAAAVM"] [Tue Aug 18 12:58:12.054567 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:16502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBFNO5rbWdOArH04Ke_wAAAR0"] [Tue Aug 18 12:58:12.064638 2026] [security2:error] [pid 66623:tid 66789] [client 20.206.73.37:45811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/mac.php"] [unique_id "aoSBFNO5rbWdOArH04KfAAAAASE"] [Tue Aug 18 12:58:12.067016 2026] [security2:error] [pid 66623:tid 66683] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfAQABCy4"] [Tue Aug 18 12:58:12.073535 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.85.180:42261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/admin.php"] [unique_id "aoSBFNO5rbWdOArH04KfAwAAASc"] [Tue Aug 18 12:58:12.099701 2026] [security2:error] [pid 66623:tid 66779] [client 20.119.58.187:12521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/cloud.php"] [unique_id "aoSBFNO5rbWdOArH04KfBgAAARc"] [Tue Aug 18 12:58:12.106877 2026] [security2:error] [pid 66623:tid 66787] [client 20.186.30.159:1975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/chris.php"] [unique_id "aoSBFNO5rbWdOArH04KfBwAAAR8"] [Tue Aug 18 12:58:12.167643 2026] [security2:error] [pid 66623:tid 66834] [client 40.74.65.169:44771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/file.php"] [unique_id "aoSBFNO5rbWdOArH04KfCwAAAU4"] [Tue Aug 18 12:58:12.170491 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:12.171002 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:12.214439 2026] [security2:error] [pid 66623:tid 66769] [client 37.40.227.74:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFNO5rbWdOArH04KfDQAAAQ0"] [Tue Aug 18 12:58:12.214540 2026] [security2:error] [pid 66623:tid 66769] [client 37.40.227.74:56528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFNO5rbWdOArH04KfDQAAAQ0"] [Tue Aug 18 12:58:12.231244 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:53100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfDwAAAUw"] [Tue Aug 18 12:58:12.272191 2026] [security2:error] [pid 66623:tid 66778] [client 213.202.253.4:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSBFNO5rbWdOArH04KfEQAAARY"], referer: www.google.com [Tue Aug 18 12:58:12.273167 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/module.php"] [unique_id "aoSBFNO5rbWdOArH04KfEgABgjE"] [Tue Aug 18 12:58:12.274958 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/buy.php"] [unique_id "aoSBFNO5rbWdOArH04KfEwAAAVs"] [Tue Aug 18 12:58:12.289615 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/bajah.php"] [unique_id "aoSBFNO5rbWdOArH04KfFgAAAYE"] [Tue Aug 18 12:58:12.336861 2026] [security2:error] [pid 66623:tid 66893] [client 158.23.17.4:34002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/th.php"] [unique_id "aoSBFNO5rbWdOArH04KfGQAAAYk"] [Tue Aug 18 12:58:12.370254 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:21549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/norn.php"] [unique_id "aoSBFNO5rbWdOArH04KfGgAAAT8"] [Tue Aug 18 12:58:12.387233 2026] [security2:error] [pid 66623:tid 66857] [client 20.186.30.159:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/doc.php"] [unique_id "aoSBFNO5rbWdOArH04KfGwAAAWU"] [Tue Aug 18 12:58:12.411607 2026] [security2:error] [pid 66623:tid 66763] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFNO5rbWdOArH04KfHQABLX4"] [Tue Aug 18 12:58:12.426108 2026] [security2:error] [pid 66623:tid 66728] [remote 162.214.205.212:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFNO5rbWdOArH04KfHwABS1s"] [Tue Aug 18 12:58:12.430501 2026] [security2:error] [pid 66623:tid 66874] [client 68.155.155.199:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/bolt.php"] [unique_id "aoSBFNO5rbWdOArH04KfIAAAAXY"] [Tue Aug 18 12:58:12.451785 2026] [security2:error] [pid 66623:tid 66646] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/options.php"] [unique_id "aoSBFNO5rbWdOArH04KfIgABIgk"] [Tue Aug 18 12:58:12.458073 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/legacy/updates.php"] [unique_id "aoSBFNO5rbWdOArH04KfIwAAAYY"] [Tue Aug 18 12:58:12.471911 2026] [security2:error] [pid 66623:tid 66797] [client 20.100.169.31:32730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/h.php"] [unique_id "aoSBFNO5rbWdOArH04KfJQAAASk"] [Tue Aug 18 12:58:12.476251 2026] [authz_core:error] [pid 66623:tid 66698] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:12.476665 2026] [authz_core:error] [pid 66623:tid 66698] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:12.482496 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.217.32:15746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/manager.php"] [unique_id "aoSBFNO5rbWdOArH04KfJgAAAVI"] [Tue Aug 18 12:58:12.528792 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.154.236:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBFNO5rbWdOArH04KfKgAAAUo"] [Tue Aug 18 12:58:12.580038 2026] [security2:error] [pid 66623:tid 66859] [client 20.79.204.6:11708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/images/wso.php"] [unique_id "aoSBFNO5rbWdOArH04KfMAAAAWc"] [Tue Aug 18 12:58:12.603537 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBFNO5rbWdOArH04KfMgAAATY"] [Tue Aug 18 12:58:12.605509 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:21510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBFNO5rbWdOArH04KfMwAAAXc"] [Tue Aug 18 12:58:12.630057 2026] [security2:error] [pid 66623:tid 66694] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/panel.php"] [unique_id "aoSBFNO5rbWdOArH04KfNAABRDk"] [Tue Aug 18 12:58:12.639291 2026] [security2:error] [pid 66623:tid 66872] [client 20.118.172.148:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/cong.php"] [unique_id "aoSBFNO5rbWdOArH04KfNQAAAXQ"] [Tue Aug 18 12:58:12.666756 2026] [security2:error] [pid 66623:tid 66814] [client 20.186.30.159:1945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/1337.php"] [unique_id "aoSBFNO5rbWdOArH04KfOAAAATo"] [Tue Aug 18 12:58:12.705892 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:2728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/system_log.php"] [unique_id "aoSBFNO5rbWdOArH04KfOwAAAVA"] [Tue Aug 18 12:58:12.730499 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:6211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-file.php"] [unique_id "aoSBFNO5rbWdOArH04KfPAAAAYQ"] [Tue Aug 18 12:58:12.754075 2026] [security2:error] [pid 66623:tid 66792] [client 20.104.85.180:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/public/css.php"] [unique_id "aoSBFNO5rbWdOArH04KfPQAAASQ"] [Tue Aug 18 12:58:12.754270 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBFNO5rbWdOArH04KfPgAAAUM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:12.770487 2026] [authz_core:error] [pid 66623:tid 66745] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:12.770878 2026] [authz_core:error] [pid 66623:tid 66745] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:12.808210 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSBFNO5rbWdOArH04KfRAABCx4"] [Tue Aug 18 12:58:12.814020 2026] [security2:error] [pid 66623:tid 66871] [client 20.119.58.187:12505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/phpmailer/updates.php"] [unique_id "aoSBFNO5rbWdOArH04KfRQAAAXM"] [Tue Aug 18 12:58:12.831685 2026] [security2:error] [pid 66623:tid 66804] [client 158.23.17.4:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/admin404.php"] [unique_id "aoSBFNO5rbWdOArH04KfRgAAATA"] [Tue Aug 18 12:58:12.836809 2026] [security2:error] [pid 66623:tid 66779] [client 20.203.138.185:39035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/100.kb.php"] [unique_id "aoSBFNO5rbWdOArH04KfRwAAARc"] [Tue Aug 18 12:58:12.855758 2026] [security2:error] [pid 66623:tid 66787] [client 20.48.236.86:32849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBFNO5rbWdOArH04KfSAAAAR8"] [Tue Aug 18 12:58:12.925104 2026] [security2:error] [pid 66623:tid 66826] [client 40.74.65.169:31908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/dex.php"] [unique_id "aoSBFNO5rbWdOArH04KfSwAAAUY"] [Tue Aug 18 12:58:12.944233 2026] [security2:error] [pid 66623:tid 66776] [client 20.186.30.159:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/Njima.php"] [unique_id "aoSBFNO5rbWdOArH04KfTQAAARQ"] [Tue Aug 18 12:58:12.968455 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/media.php"] [unique_id "aoSBFNO5rbWdOArH04KfTwAAAU0"] [Tue Aug 18 12:58:12.976972 2026] [security2:error] [pid 66623:tid 66866] [client 158.158.74.177:16550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBFNO5rbWdOArH04KfUAAAAW4"] [Tue Aug 18 12:58:12.986914 2026] [security2:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSBFNO5rbWdOArH04KfUQABDV8"] [Tue Aug 18 12:58:12.987839 2026] [security2:error] [pid 66623:tid 66822] [client 40.74.65.169:49071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/domvf.php"] [unique_id "aoSBFNO5rbWdOArH04KfUgAAAUI"] [Tue Aug 18 12:58:12.992704 2026] [security2:error] [pid 66623:tid 66820] [client 20.206.73.37:21707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBFNO5rbWdOArH04KfUwAAAUA"] [Tue Aug 18 12:58:13.005658 2026] [security2:error] [pid 66623:tid 66764] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBFdO5rbWdOArH04KfVAABLH8"] [Tue Aug 18 12:58:13.016559 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.154.236:7665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaupromo.com.br"] [uri "/images/security.php"] [unique_id "aoSBFdO5rbWdOArH04KfVQAAAU8"] [Tue Aug 18 12:58:13.032772 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/x.php"] [unique_id "aoSBFdO5rbWdOArH04KfVwAAAWQ"] [Tue Aug 18 12:58:13.059084 2026] [authz_core:error] [pid 66623:tid 66864] [client 192.178.4.134:64604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:13.059358 2026] [authz_core:error] [pid 66623:tid 66864] [client 192.178.4.134:64604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:13.061629 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBFdO5rbWdOArH04KfWgAAAVs"] [Tue Aug 18 12:58:13.077428 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:13.077868 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:13.095144 2026] [security2:error] [pid 66623:tid 66803] [client 149.34.210.141:60605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXAAAAS8"] [Tue Aug 18 12:58:13.100060 2026] [security2:error] [pid 66623:tid 66865] [client 5.31.227.224:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXgAAAW0"] [Tue Aug 18 12:58:13.100154 2026] [security2:error] [pid 66623:tid 66865] [client 5.31.227.224:7846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXgAAAW0"] [Tue Aug 18 12:58:13.104278 2026] [security2:error] [pid 66623:tid 66808] [client 157.20.138.62:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXwAAATQ"] [Tue Aug 18 12:58:13.104385 2026] [security2:error] [pid 66623:tid 66808] [client 157.20.138.62:51307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXwAAATQ"] [Tue Aug 18 12:58:13.154537 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/num.php"] [unique_id "aoSBFdO5rbWdOArH04KfYwAAARw"] [Tue Aug 18 12:58:13.164936 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:11885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/libraries/vendor/updates.php"] [unique_id "aoSBFdO5rbWdOArH04KfZAAAARY"] [Tue Aug 18 12:58:13.169325 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfZQABEmo"] [Tue Aug 18 12:58:13.177946 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.155.199:3112] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/cgi-bin/"] [unique_id "aoSBFdO5rbWdOArH04KfZgAAAUs"] [Tue Aug 18 12:58:13.180686 2026] [security2:error] [pid 66623:tid 66874] [client 20.206.73.37:55643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSBFdO5rbWdOArH04KfZwAAAXY"] [Tue Aug 18 12:58:13.186302 2026] [security2:error] [pid 66623:tid 66850] [client 20.79.204.6:11653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/index/function.php"] [unique_id "aoSBFdO5rbWdOArH04KfaAAAAV4"] [Tue Aug 18 12:58:13.186801 2026] [security2:error] [pid 66623:tid 66793] [client 20.186.30.159:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBFdO5rbWdOArH04KfaQAAASU"] [Tue Aug 18 12:58:13.238245 2026] [security2:error] [pid 66623:tid 66680] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/st.php"] [unique_id "aoSBFdO5rbWdOArH04KfawABJis"] [Tue Aug 18 12:58:13.266745 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSBFdO5rbWdOArH04KfbQAAAYI"] [Tue Aug 18 12:58:13.345857 2026] [security2:error] [pid 66623:tid 66714] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/chosen.php"] [unique_id "aoSBFdO5rbWdOArH04KfdQABPU0"] [Tue Aug 18 12:58:13.352623 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/checkbox.php"] [unique_id "aoSBFdO5rbWdOArH04KfdwAAAS0"] [Tue Aug 18 12:58:13.353570 2026] [security2:error] [pid 66623:tid 66780] [client 172.202.39.151:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFdO5rbWdOArH04KfeAAAARg"] [Tue Aug 18 12:58:13.360683 2026] [security2:error] [pid 66623:tid 66803] [client 149.34.210.141:60605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfXAAAAS8"] [Tue Aug 18 12:58:13.392598 2026] [security2:error] [pid 66623:tid 66811] [client 20.118.172.148:46745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBFdO5rbWdOArH04KfewAAATc"] [Tue Aug 18 12:58:13.419865 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/le.php"] [unique_id "aoSBFdO5rbWdOArH04KffgABVg4"] [Tue Aug 18 12:58:13.428505 2026] [security2:error] [pid 66623:tid 66791] [client 20.206.73.37:46982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/pucci.php"] [unique_id "aoSBFdO5rbWdOArH04KffwAAASM"] [Tue Aug 18 12:58:13.435614 2026] [security2:error] [pid 66623:tid 66827] [client 223.185.37.47:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfhgAAAUc"] [Tue Aug 18 12:58:13.435771 2026] [security2:error] [pid 66623:tid 66827] [client 223.185.37.47:28000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfhgAAAUc"] [Tue Aug 18 12:58:13.437449 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBFdO5rbWdOArH04KfhwAAAUM"] [Tue Aug 18 12:58:13.445420 2026] [security2:error] [pid 66623:tid 66789] [client 20.186.30.159:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/too.php"] [unique_id "aoSBFdO5rbWdOArH04KfiQAAASE"] [Tue Aug 18 12:58:13.462072 2026] [security2:error] [pid 66623:tid 66830] [client 172.182.217.32:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/mar.php"] [unique_id "aoSBFdO5rbWdOArH04KfiwAAAUo"] [Tue Aug 18 12:58:13.521639 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew.php"] [unique_id "aoSBFdO5rbWdOArH04KfjgAAAYM"] [Tue Aug 18 12:58:13.554920 2026] [security2:error] [pid 66623:tid 66869] [client 20.203.138.185:38133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mamzi.php"] [unique_id "aoSBFdO5rbWdOArH04KfkgAAAXE"] [Tue Aug 18 12:58:13.599958 2026] [security2:error] [pid 66623:tid 66843] [client 20.206.73.37:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBFdO5rbWdOArH04KflgAAAVc"] [Tue Aug 18 12:58:13.624708 2026] [security2:error] [pid 66623:tid 66851] [client 20.215.241.237:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/av.php"] [unique_id "aoSBFdO5rbWdOArH04KfmAAAAV8"] [Tue Aug 18 12:58:13.650574 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:29603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/key.php"] [unique_id "aoSBFdO5rbWdOArH04KfmQAAAVs"] [Tue Aug 18 12:58:13.653613 2026] [security2:error] [pid 66623:tid 66840] [client 52.173.121.69:24800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBFdO5rbWdOArH04KfmgAAAVQ"] [Tue Aug 18 12:58:13.662902 2026] [security2:error] [pid 66623:tid 66812] [client 158.23.17.4:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qo.php"] [unique_id "aoSBFdO5rbWdOArH04KfmwAAATg"] [Tue Aug 18 12:58:13.674196 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:13.674457 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:13.683309 2026] [security2:error] [pid 66623:tid 66819] [client 40.74.65.169:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/fpwch.php"] [unique_id "aoSBFdO5rbWdOArH04KfoAAAAT8"] [Tue Aug 18 12:58:13.692585 2026] [security2:error] [pid 66623:tid 66642] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hr.php"] [unique_id "aoSBFdO5rbWdOArH04KfogABbwU"] [Tue Aug 18 12:58:13.711190 2026] [security2:error] [pid 66623:tid 66784] [client 40.74.65.169:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBFdO5rbWdOArH04KfowAAARw"] [Tue Aug 18 12:58:13.729350 2026] [security2:error] [pid 66623:tid 66778] [client 20.186.30.159:1811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.limapolimentos.com.br"] [uri "/g3.php"] [unique_id "aoSBFdO5rbWdOArH04KfpAAAARY"] [Tue Aug 18 12:58:13.745456 2026] [security2:error] [pid 66623:tid 66831] [client 20.206.73.37:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBFdO5rbWdOArH04KfpQAAAUs"] [Tue Aug 18 12:58:13.770179 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:50727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/sky.php"] [unique_id "aoSBFdO5rbWdOArH04KfqQAAASk"] [Tue Aug 18 12:58:13.775861 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/db.php"] [unique_id "aoSBFdO5rbWdOArH04KfqgAAAYk"] [Tue Aug 18 12:58:13.778796 2026] [security2:error] [pid 66623:tid 66805] [client 213.35.127.232:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBFdO5rbWdOArH04KfqwAAATE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:13.798507 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/class-protect-uploads.php"] [unique_id "aoSBFdO5rbWdOArH04KfrQABdSI"] [Tue Aug 18 12:58:13.807627 2026] [security2:error] [pid 66623:tid 66877] [client 138.36.100.162:41464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfrgAAAXk"] [Tue Aug 18 12:58:13.807752 2026] [security2:error] [pid 66623:tid 66877] [client 138.36.100.162:41464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFdO5rbWdOArH04KfrgAAAXk"] [Tue Aug 18 12:58:13.811440 2026] [security2:error] [pid 66623:tid 66809] [client 74.248.18.37:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/options-reading.php"] [unique_id "aoSBFdO5rbWdOArH04KfrwAAATU"] [Tue Aug 18 12:58:13.813003 2026] [security2:error] [pid 66623:tid 66800] [client 20.79.204.6:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/info.php"] [unique_id "aoSBFdO5rbWdOArH04KfsAAAASw"] [Tue Aug 18 12:58:13.847756 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:46775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/hosty.php"] [unique_id "aoSBFdO5rbWdOArH04KfsgAAAXA"] [Tue Aug 18 12:58:13.865412 2026] [security2:error] [pid 66623:tid 66644] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kt.php"] [unique_id "aoSBFdO5rbWdOArH04KfswABawc"] [Tue Aug 18 12:58:13.867331 2026] [security2:error] [pid 66623:tid 66804] [client 158.158.74.177:26139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBFdO5rbWdOArH04KftQAAATA"] [Tue Aug 18 12:58:13.883965 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSBFdO5rbWdOArH04KftwAAAYY"] [Tue Aug 18 12:58:13.929922 2026] [security2:error] [pid 66623:tid 66818] [client 20.206.73.37:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/puc.php"] [unique_id "aoSBFdO5rbWdOArH04KfuAAAAT4"] [Tue Aug 18 12:58:13.943956 2026] [security2:error] [pid 66623:tid 66859] [client 20.206.73.37:11954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bajah.php"] [unique_id "aoSBFdO5rbWdOArH04KfuQAAAWc"] [Tue Aug 18 12:58:13.950502 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/my1.php"] [unique_id "aoSBFdO5rbWdOArH04KfugAAASY"] [Tue Aug 18 12:58:13.976424 2026] [security2:error] [pid 66623:tid 66762] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSBFdO5rbWdOArH04KfvQABPX0"] [Tue Aug 18 12:58:14.012826 2026] [security2:error] [pid 66623:tid 66886] [client 79.127.164.8:40236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/pma.sql"] [unique_id "aoSBFtO5rbWdOArH04KfvwAAAYI"], referer: https://medihub.com.br/pma.sql [Tue Aug 18 12:58:14.021297 2026] [security2:error] [pid 66623:tid 66811] [client 172.182.200.96:7499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KfwQAAATc"] [Tue Aug 18 12:58:14.038856 2026] [security2:error] [pid 66623:tid 66836] [client 178.153.171.161:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KfxAAAAVA"] [Tue Aug 18 12:58:14.038999 2026] [security2:error] [pid 66623:tid 66836] [client 178.153.171.161:14979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KfxAAAAVA"] [Tue Aug 18 12:58:14.040777 2026] [security2:error] [pid 66623:tid 66844] [client 20.100.185.105:58343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wso112233.php"] [unique_id "aoSBFtO5rbWdOArH04KfxQAAAVg"] [Tue Aug 18 12:58:14.064326 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.155.199:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBFtO5rbWdOArH04KfxwAAAVY"] [Tue Aug 18 12:58:14.099941 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ww.php"] [unique_id "aoSBFtO5rbWdOArH04KfyAABR0A"] [Tue Aug 18 12:58:14.157808 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/content.php"] [unique_id "aoSBFtO5rbWdOArH04KfzQABc1A"] [Tue Aug 18 12:58:14.162370 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KfzgAAARc"] [Tue Aug 18 12:58:14.166495 2026] [security2:error] [pid 66623:tid 66864] [client 172.182.200.96:7670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1gAAAWw"] [Tue Aug 18 12:58:14.169437 2026] [security2:error] [pid 66623:tid 66737] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1wABHmQ"] [Tue Aug 18 12:58:14.169613 2026] [security2:error] [pid 66623:tid 66786] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04Kf1wABHmQ"] [Tue Aug 18 12:58:14.180338 2026] [security2:error] [pid 66623:tid 66782] [client 20.206.73.37:45776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/8.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4QAAARo"] [Tue Aug 18 12:58:14.185134 2026] [security2:error] [pid 66623:tid 66733] [remote 104.43.48.106:31860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.43.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4AABbmA"] [Tue Aug 18 12:58:14.190249 2026] [security2:error] [pid 66623:tid 66861] [client 20.203.138.185:38992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4gAAAWk"] [Tue Aug 18 12:58:14.207252 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:28018] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4wAAARQ"] [Tue Aug 18 12:58:14.207374 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:28018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf4wAAARQ"] [Tue Aug 18 12:58:14.224115 2026] [security2:error] [pid 66623:tid 66777] [client 74.248.18.37:7172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBFtO5rbWdOArH04Kf5gAAARU"] [Tue Aug 18 12:58:14.232205 2026] [security2:error] [pid 66623:tid 66856] [client 20.118.172.148:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/dropdown.php"] [unique_id "aoSBFtO5rbWdOArH04Kf6gAAAWQ"] [Tue Aug 18 12:58:14.241218 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:50095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/test1.php"] [unique_id "aoSBFtO5rbWdOArH04Kf6wAAARs"] [Tue Aug 18 12:58:14.275718 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:14.275985 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:14.291270 2026] [security2:error] [pid 66623:tid 66867] [client 158.23.17.4:34034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sd.php"] [unique_id "aoSBFtO5rbWdOArH04Kf9QAAAW8"] [Tue Aug 18 12:58:14.292638 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-p.php7"] [unique_id "aoSBFtO5rbWdOArH04Kf9wAAAUo"] [Tue Aug 18 12:58:14.293965 2026] [security2:error] [pid 66623:tid 66755] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mo.php"] [unique_id "aoSBFtO5rbWdOArH04Kf-AABHHY"] [Tue Aug 18 12:58:14.320320 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:39001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/about.php"] [unique_id "aoSBFtO5rbWdOArH04Kf-QAAATs"] [Tue Aug 18 12:58:14.335150 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/database.php"] [unique_id "aoSBFtO5rbWdOArH04Kf_QABIgY"] [Tue Aug 18 12:58:14.372202 2026] [security2:error] [pid 66623:tid 66873] [client 40.74.65.169:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/adminner.php"] [unique_id "aoSBFtO5rbWdOArH04KgAQAAAXU"] [Tue Aug 18 12:58:14.393811 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:40684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KgAwAAAQ8"] [Tue Aug 18 12:58:14.416870 2026] [security2:error] [pid 66623:tid 66858] [client 20.79.204.6:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/profile.php"] [unique_id "aoSBFtO5rbWdOArH04KgCgAAAWY"] [Tue Aug 18 12:58:14.426323 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/kir.php"] [unique_id "aoSBFtO5rbWdOArH04KgDAAAAS4"] [Tue Aug 18 12:58:14.437278 2026] [security2:error] [pid 66623:tid 66808] [client 172.182.217.32:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/mm.php"] [unique_id "aoSBFtO5rbWdOArH04KgDgAAATQ"] [Tue Aug 18 12:58:14.499426 2026] [security2:error] [pid 66623:tid 66692] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qr.php"] [unique_id "aoSBFtO5rbWdOArH04KgEgABiDc"] [Tue Aug 18 12:58:14.523539 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/db.php"] [unique_id "aoSBFtO5rbWdOArH04KgFgABL0w"] [Tue Aug 18 12:58:14.537386 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ors32envu.php"] [unique_id "aoSBFtO5rbWdOArH04KgGQAAAWg"] [Tue Aug 18 12:58:14.577334 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:14.577616 2026] [authz_core:error] [pid 66623:tid 66667] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:14.594810 2026] [security2:error] [pid 66623:tid 66885] [client 20.118.172.148:53099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/zwso.php"] [unique_id "aoSBFtO5rbWdOArH04KgIwAAAYE"] [Tue Aug 18 12:58:14.612430 2026] [security2:error] [pid 66623:tid 66844] [client 40.74.65.169:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBFtO5rbWdOArH04KgJQAAAVg"] [Tue Aug 18 12:58:14.630662 2026] [security2:error] [pid 66623:tid 66868] [client 158.158.74.177:16520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBFtO5rbWdOArH04KgJwAAAXA"] [Tue Aug 18 12:58:14.648507 2026] [security2:error] [pid 66623:tid 66839] [client 20.119.58.187:12530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/repeater.php"] [unique_id "aoSBFtO5rbWdOArH04KgKQAAAVM"] [Tue Aug 18 12:58:14.661585 2026] [security2:error] [pid 66623:tid 66817] [client 20.100.185.105:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBFtO5rbWdOArH04KgKgAAAT0"] [Tue Aug 18 12:58:14.677311 2026] [security2:error] [pid 66623:tid 66722] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dirs.php"] [unique_id "aoSBFtO5rbWdOArH04KgLQABXlU"] [Tue Aug 18 12:58:14.685579 2026] [security2:error] [pid 66623:tid 66715] [remote 72.167.40.62:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodosorrisosobral.com.br"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04KgLgABIE4"] [Tue Aug 18 12:58:14.702465 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/default.php"] [unique_id "aoSBFtO5rbWdOArH04KgMAABg2o"] [Tue Aug 18 12:58:14.712149 2026] [security2:error] [pid 66623:tid 66828] [client 20.118.172.148:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/file.php"] [unique_id "aoSBFtO5rbWdOArH04KgMQAAAUg"] [Tue Aug 18 12:58:14.769811 2026] [security2:error] [pid 66623:tid 66855] [client 68.155.155.199:7708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgMgAAAWM"] [Tue Aug 18 12:58:14.775281 2026] [security2:error] [pid 66623:tid 66833] [client 20.206.73.37:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgMwAAAU0"] [Tue Aug 18 12:58:14.776955 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.183.135:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/domvf.php"] [unique_id "aoSBFtO5rbWdOArH04KgNAAAAVc"] [Tue Aug 18 12:58:14.790224 2026] [security2:error] [pid 66623:tid 66875] [client 213.35.127.232:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBFtO5rbWdOArH04KgNwAAAXc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:14.853027 2026] [security2:error] [pid 66623:tid 66826] [client 85.154.68.202:16881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KgOgAAAUY"] [Tue Aug 18 12:58:14.853152 2026] [security2:error] [pid 66623:tid 66826] [client 85.154.68.202:16881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBFtO5rbWdOArH04KgOgAAAUY"] [Tue Aug 18 12:58:14.914662 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBFtO5rbWdOArH04KgPwAAAU8"] [Tue Aug 18 12:58:14.926872 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.217.32:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/network.php"] [unique_id "aoSBFtO5rbWdOArH04KgQAAAATM"] [Tue Aug 18 12:58:14.931982 2026] [security2:error] [pid 66623:tid 66730] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sn.php"] [unique_id "aoSBFtO5rbWdOArH04KgQQABEV0"] [Tue Aug 18 12:58:14.941503 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dex.php"] [unique_id "aoSBFtO5rbWdOArH04KgQgABSik"] [Tue Aug 18 12:58:14.963071 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:19166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gelay.php"] [unique_id "aoSBFtO5rbWdOArH04KgRQAAATs"] [Tue Aug 18 12:58:14.972785 2026] [security2:error] [pid 66623:tid 66837] [client 20.100.169.31:29094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBFtO5rbWdOArH04KgRgAAAVE"] [Tue Aug 18 12:58:14.988949 2026] [security2:error] [pid 66623:tid 66881] [client 20.65.98.162:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposchopan.com.br"] [uri "/packed.php"] [unique_id "aoSBFtO5rbWdOArH04KgRwAAAX0"] [Tue Aug 18 12:58:14.994310 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inputs.php"] [unique_id "aoSBFtO5rbWdOArH04KgSAAAAXI"] [Tue Aug 18 12:58:15.002011 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:11897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/repeater.php"] [unique_id "aoSBF9O5rbWdOArH04KgSQAAAVs"] [Tue Aug 18 12:58:15.023079 2026] [security2:error] [pid 66623:tid 66893] [client 20.206.73.37:52493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/av.php"] [unique_id "aoSBF9O5rbWdOArH04KgSwAAAYk"] [Tue Aug 18 12:58:15.023702 2026] [security2:error] [pid 66623:tid 66871] [client 20.250.13.23:7809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/inputs.php"] [unique_id "aoSBF9O5rbWdOArH04KgTAAAAXM"] [Tue Aug 18 12:58:15.068210 2026] [security2:error] [pid 66623:tid 66879] [client 40.74.65.169:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.compratec.com.br"] [uri "/abcd.php"] [unique_id "aoSBF9O5rbWdOArH04KgTwAAAXs"] [Tue Aug 18 12:58:15.084965 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:41007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBF9O5rbWdOArH04KgUAAAARs"] [Tue Aug 18 12:58:15.085762 2026] [security2:error] [pid 66623:tid 66863] [client 20.118.172.148:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/goods.php"] [unique_id "aoSBF9O5rbWdOArH04KgUQAAAWs"] [Tue Aug 18 12:58:15.092627 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgUgAAAWY"] [Tue Aug 18 12:58:15.094403 2026] [security2:error] [pid 66623:tid 66821] [client 20.79.204.6:11701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/sx.php"] [unique_id "aoSBF9O5rbWdOArH04KgUwAAAUE"] [Tue Aug 18 12:58:15.117395 2026] [security2:error] [pid 66623:tid 66664] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/df.php"] [unique_id "aoSBF9O5rbWdOArH04KgVQABLhs"] [Tue Aug 18 12:58:15.125295 2026] [security2:error] [pid 66623:tid 66889] [client 158.158.34.183:34340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSBF9O5rbWdOArH04KgVwAAAYU"] [Tue Aug 18 12:58:15.137357 2026] [security2:error] [pid 66623:tid 66780] [client 40.74.65.169:27720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/nofile.php"] [unique_id "aoSBF9O5rbWdOArH04KgWQAAARg"] [Tue Aug 18 12:58:15.139818 2026] [security2:error] [pid 66623:tid 66892] [client 20.206.73.37:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBF9O5rbWdOArH04KgWgAAAYg"] [Tue Aug 18 12:58:15.179607 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:15.179864 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSBF9O5rbWdOArH04KgXgAAARw"] [Tue Aug 18 12:58:15.179870 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:15.233259 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.172.148:43486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/Geforce.php"] [unique_id "aoSBF9O5rbWdOArH04KgYAAAARM"] [Tue Aug 18 12:58:15.241866 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:39994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gfile.php"] [unique_id "aoSBF9O5rbWdOArH04KgYQAAAVg"] [Tue Aug 18 12:58:15.245319 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/43.php"] [unique_id "aoSBF9O5rbWdOArH04KgYgABhEc"] [Tue Aug 18 12:58:15.265696 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgYwAAAUc"] [Tue Aug 18 12:58:15.283888 2026] [security2:error] [pid 66623:tid 66768] [client 20.100.185.105:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/gecko.php"] [unique_id "aoSBF9O5rbWdOArH04KgZQAAAQw"] [Tue Aug 18 12:58:15.298739 2026] [security2:error] [pid 66623:tid 66745] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/disagrsxr.php"] [unique_id "aoSBF9O5rbWdOArH04KgZgABHWw"] [Tue Aug 18 12:58:15.348630 2026] [security2:error] [pid 66623:tid 66862] [client 20.206.73.37:24272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBF9O5rbWdOArH04KgagAAAWo"] [Tue Aug 18 12:58:15.357380 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/repeater.php"] [unique_id "aoSBF9O5rbWdOArH04KgawAAAVA"] [Tue Aug 18 12:58:15.405762 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.85.180:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBF9O5rbWdOArH04KgbwAAAW4"] [Tue Aug 18 12:58:15.420514 2026] [security2:error] [pid 66623:tid 66791] [client 172.182.217.32:15770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/new.php"] [unique_id "aoSBF9O5rbWdOArH04KgcgAAASM"] [Tue Aug 18 12:58:15.481822 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:15.482093 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:15.483654 2026] [security2:error] [pid 66623:tid 66642] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/domvf.php"] [unique_id "aoSBF9O5rbWdOArH04KgdQABegU"] [Tue Aug 18 12:58:15.489771 2026] [security2:error] [pid 66623:tid 66868] [client 158.158.74.177:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBF9O5rbWdOArH04KgdgAAAXA"] [Tue Aug 18 12:58:15.523825 2026] [security2:error] [pid 66623:tid 66832] [client 20.206.73.37:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/h.php"] [unique_id "aoSBF9O5rbWdOArH04KgeQAAAUw"] [Tue Aug 18 12:58:15.552470 2026] [security2:error] [pid 66623:tid 66777] [client 158.23.17.4:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/km.php"] [unique_id "aoSBF9O5rbWdOArH04KgewAAARU"] [Tue Aug 18 12:58:15.560044 2026] [security2:error] [pid 66623:tid 66829] [client 40.74.65.169:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBF9O5rbWdOArH04KgfAAAAUk"] [Tue Aug 18 12:58:15.563549 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fresh.php"] [unique_id "aoSBF9O5rbWdOArH04KgfQABVHU"] [Tue Aug 18 12:58:15.643788 2026] [security2:error] [pid 66623:tid 66881] [client 51.68.111.203:24049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferreirafreitas.com.br"] [uri "/robots.txt"] [unique_id "aoSBF9O5rbWdOArH04KghAAAAX0"] [Tue Aug 18 12:58:15.643903 2026] [security2:error] [pid 66623:tid 66881] [client 51.68.111.203:24049] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ferreirafreitas.com.br"] [uri "/robots.txt"] [unique_id "aoSBF9O5rbWdOArH04KghAAAAX0"] [Tue Aug 18 12:58:15.663419 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dropdown.php"] [unique_id "aoSBF9O5rbWdOArH04KghQABcgc"] [Tue Aug 18 12:58:15.701107 2026] [security2:error] [pid 66623:tid 66787] [client 20.79.204.6:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgiAAAAR8"] [Tue Aug 18 12:58:15.709144 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wsoyanz.php"] [unique_id "aoSBF9O5rbWdOArH04KgiQAAAUo"] [Tue Aug 18 12:58:15.778647 2026] [security2:error] [pid 66623:tid 66879] [client 20.48.236.86:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file5.php"] [unique_id "aoSBF9O5rbWdOArH04KgjQAAAXs"] [Tue Aug 18 12:58:15.783008 2026] [security2:error] [pid 66623:tid 66783] [client 20.206.73.37:35164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgjgAAARs"] [Tue Aug 18 12:58:15.783572 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:15.783849 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:15.792989 2026] [security2:error] [pid 66623:tid 66890] [client 20.215.241.237:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/images.php"] [unique_id "aoSBF9O5rbWdOArH04KgkAAAAYY"] [Tue Aug 18 12:58:15.802235 2026] [security2:error] [pid 66623:tid 66833] [client 213.35.127.232:64469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBF9O5rbWdOArH04KgkQAAAU0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:15.803009 2026] [security2:error] [pid 66623:tid 66820] [client 20.100.169.31:40543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/a7.php"] [unique_id "aoSBF9O5rbWdOArH04KgkgAAAUA"] [Tue Aug 18 12:58:15.803497 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:40995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBF9O5rbWdOArH04KgkwAAAT8"] [Tue Aug 18 12:58:15.816236 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBF9O5rbWdOArH04KglAAAAWY"] [Tue Aug 18 12:58:15.837117 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.155.199:21583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ff1.php"] [unique_id "aoSBF9O5rbWdOArH04KglQAAAQ8"] [Tue Aug 18 12:58:15.841309 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSBF9O5rbWdOArH04KglgABgDM"] [Tue Aug 18 12:58:15.860164 2026] [security2:error] [pid 66623:tid 66802] [client 52.173.121.69:24965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBF9O5rbWdOArH04KglwAAAS4"] [Tue Aug 18 12:58:15.860180 2026] [security2:error] [pid 66623:tid 66682] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gj.php"] [unique_id "aoSBF9O5rbWdOArH04KgmAABZy0"] [Tue Aug 18 12:58:15.911456 2026] [security2:error] [pid 66623:tid 66793] [client 172.182.217.32:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/0x.php"] [unique_id "aoSBF9O5rbWdOArH04KgnQAAASU"] [Tue Aug 18 12:58:15.925674 2026] [security2:error] [pid 66623:tid 66845] [client 20.127.136.245:22128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBF9O5rbWdOArH04KgnwAAAVk"] [Tue Aug 18 12:58:15.938976 2026] [security2:error] [pid 66623:tid 66874] [client 20.100.185.105:6231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/catuploadcsv.php"] [unique_id "aoSBF9O5rbWdOArH04KgoQAAAXY"] [Tue Aug 18 12:58:15.940065 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:42301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgogAAAS8"] [Tue Aug 18 12:58:15.942059 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:56407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBF9O5rbWdOArH04KgowAAARw"] [Tue Aug 18 12:58:15.974427 2026] [security2:error] [pid 66623:tid 66770] [client 40.74.65.169:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/fling.php"] [unique_id "aoSBF9O5rbWdOArH04KgpwAAAQ4"] [Tue Aug 18 12:58:16.016402 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ova.php"] [unique_id "aoSBGNO5rbWdOArH04KgqAAAAUs"] [Tue Aug 18 12:58:16.017626 2026] [security2:error] [pid 66623:tid 66823] [client 20.203.138.185:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSBGNO5rbWdOArH04KgqQAAAUM"] [Tue Aug 18 12:58:16.021274 2026] [security2:error] [pid 66623:tid 66710] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/edit.php"] [unique_id "aoSBGNO5rbWdOArH04KgqgABXUk"] [Tue Aug 18 12:58:16.042886 2026] [security2:error] [pid 66623:tid 66817] [client 20.206.73.37:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBGNO5rbWdOArH04KgrAAAAT0"] [Tue Aug 18 12:58:16.065469 2026] [security2:error] [pid 66623:tid 66814] [client 20.119.58.187:11886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/yanz.php"] [unique_id "aoSBGNO5rbWdOArH04KgrgAAATo"] [Tue Aug 18 12:58:16.080123 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pd.php"] [unique_id "aoSBGNO5rbWdOArH04KgrwABIGQ"] [Tue Aug 18 12:58:16.080180 2026] [security2:error] [pid 66623:tid 66850] [client 20.118.172.148:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/fpwch.php"] [unique_id "aoSBGNO5rbWdOArH04KgsAAAAV4"] [Tue Aug 18 12:58:16.130714 2026] [security2:error] [pid 66623:tid 66805] [client 158.158.34.183:18898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/manager.php"] [unique_id "aoSBGNO5rbWdOArH04KgsgAAATE"] [Tue Aug 18 12:58:16.183082 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/222.php"] [unique_id "aoSBGNO5rbWdOArH04KgtQAAARQ"] [Tue Aug 18 12:58:16.197503 2026] [security2:error] [pid 66623:tid 66712] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/elp.php"] [unique_id "aoSBGNO5rbWdOArH04KgtwABY0s"] [Tue Aug 18 12:58:16.266971 2026] [security2:error] [pid 66623:tid 66799] [client 20.206.73.37:21750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBGNO5rbWdOArH04KguwAAASs"] [Tue Aug 18 12:58:16.277040 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/th.php"] [unique_id "aoSBGNO5rbWdOArH04KgvAABSSM"] [Tue Aug 18 12:58:16.285767 2026] [security2:error] [pid 66623:tid 66835] [client 20.206.73.37:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBGNO5rbWdOArH04KgvgAAAU8"] [Tue Aug 18 12:58:16.286822 2026] [security2:error] [pid 66623:tid 66812] [client 172.182.200.96:7579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBGNO5rbWdOArH04KgvwAAATg"] [Tue Aug 18 12:58:16.339645 2026] [security2:error] [pid 66623:tid 66836] [client 20.79.204.6:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBGNO5rbWdOArH04KgwwAAAVA"] [Tue Aug 18 12:58:16.345647 2026] [security2:error] [pid 66623:tid 66870] [client 20.206.73.37:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp.php"] [unique_id "aoSBGNO5rbWdOArH04KgxAAAAXI"] [Tue Aug 18 12:58:16.362756 2026] [security2:error] [pid 66623:tid 66880] [client 20.206.73.37:55675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/i.php"] [unique_id "aoSBGNO5rbWdOArH04KgxwAAAXw"] [Tue Aug 18 12:58:16.374166 2026] [security2:error] [pid 66623:tid 66674] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/email.php"] [unique_id "aoSBGNO5rbWdOArH04KgyAABSiU"] [Tue Aug 18 12:58:16.383739 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/htaccess.php"] [unique_id "aoSBGNO5rbWdOArH04KgygAAAYM"] [Tue Aug 18 12:58:16.384639 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:16.384938 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:16.387829 2026] [security2:error] [pid 66623:tid 66873] [client 20.206.73.37:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSBGNO5rbWdOArH04KgywAAAXU"] [Tue Aug 18 12:58:16.390843 2026] [security2:error] [pid 66623:tid 66662] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04KgzAABNRk"] [Tue Aug 18 12:58:16.390974 2026] [security2:error] [pid 66623:tid 66809] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04KgzAABNRk"] [Tue Aug 18 12:58:16.397820 2026] [security2:error] [pid 66623:tid 66856] [client 172.182.217.32:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/0.php"] [unique_id "aoSBGNO5rbWdOArH04KgzQAAAWQ"] [Tue Aug 18 12:58:16.418485 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0QAAAWA"] [Tue Aug 18 12:58:16.418616 2026] [security2:error] [pid 66623:tid 66804] [client 20.206.73.37:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0AAAATA"] [Tue Aug 18 12:58:16.428608 2026] [security2:error] [pid 66623:tid 66819] [client 20.127.136.245:10562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBGNO5rbWdOArH04Kg0wAAAT8"] [Tue Aug 18 12:58:16.430159 2026] [security2:error] [pid 66623:tid 66858] [client 20.206.73.37:40699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBGNO5rbWdOArH04Kg1AAAAWY"] [Tue Aug 18 12:58:16.447788 2026] [security2:error] [pid 66623:tid 66771] [client 20.206.73.37:52502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg1QAAAQ8"] [Tue Aug 18 12:58:16.473783 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/admin404.php"] [unique_id "aoSBGNO5rbWdOArH04Kg2AABbWs"] [Tue Aug 18 12:58:16.485392 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:52526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSBGNO5rbWdOArH04Kg2QAAARg"] [Tue Aug 18 12:58:16.515313 2026] [security2:error] [pid 66623:tid 66803] [client 20.206.73.37:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSBGNO5rbWdOArH04Kg3QAAAS8"] [Tue Aug 18 12:58:16.556654 2026] [security2:error] [pid 66623:tid 66703] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/error.php"] [unique_id "aoSBGNO5rbWdOArH04Kg3wABhEI"] [Tue Aug 18 12:58:16.557747 2026] [security2:error] [pid 66623:tid 66847] [client 20.100.185.105:6844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/info.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4AAAAVs"] [Tue Aug 18 12:58:16.559975 2026] [security2:error] [pid 66623:tid 66775] [client 20.250.13.23:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4QAAARM"] [Tue Aug 18 12:58:16.560175 2026] [security2:error] [pid 66623:tid 66827] [client 20.206.73.37:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/als.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4gAAAUc"] [Tue Aug 18 12:58:16.568777 2026] [security2:error] [pid 66623:tid 66663] [remote 129.121.48.235:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGNO5rbWdOArH04Kg4wABQho"] [Tue Aug 18 12:58:16.569957 2026] [security2:error] [pid 66623:tid 66807] [client 158.158.74.177:26115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5AAAATM"] [Tue Aug 18 12:58:16.609668 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:21708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/nox.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5gAAAVw"] [Tue Aug 18 12:58:16.629942 2026] [security2:error] [pid 66623:tid 66796] [client 114.5.214.109:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5wAAASg"] [Tue Aug 18 12:58:16.630444 2026] [security2:error] [pid 66623:tid 66796] [client 114.5.214.109:50408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGNO5rbWdOArH04Kg5wAAASg"] [Tue Aug 18 12:58:16.645641 2026] [security2:error] [pid 66623:tid 66801] [client 20.206.73.37:5500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file59.php"] [unique_id "aoSBGNO5rbWdOArH04Kg6QAAAS0"] [Tue Aug 18 12:58:16.657849 2026] [security2:error] [pid 66623:tid 66794] [client 20.206.73.37:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04Kg6wAAASY"] [Tue Aug 18 12:58:16.675564 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:35339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBGNO5rbWdOArH04Kg7QAAAR4"] [Tue Aug 18 12:58:16.675827 2026] [security2:error] [pid 66623:tid 66779] [client 20.206.73.37:21716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aa2.php"] [unique_id "aoSBGNO5rbWdOArH04Kg7gAAARc"] [Tue Aug 18 12:58:16.678305 2026] [security2:error] [pid 66623:tid 66866] [client 20.203.138.185:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/cu.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8AAAAW4"] [Tue Aug 18 12:58:16.683742 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:32575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mf.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8QAAASM"] [Tue Aug 18 12:58:16.684669 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:16.684943 2026] [authz_core:error] [pid 66623:tid 66695] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:16.694959 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/p.php"] [unique_id "aoSBGNO5rbWdOArH04Kg8wAAAWc"] [Tue Aug 18 12:58:16.715666 2026] [security2:error] [pid 66623:tid 66716] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qo.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9QABek8"] [Tue Aug 18 12:58:16.718607 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.133.132:1877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ws13.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9wAAAXA"] [Tue Aug 18 12:58:16.718626 2026] [security2:error] [pid 66623:tid 66792] [client 40.74.65.169:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/zoo1.php"] [unique_id "aoSBGNO5rbWdOArH04Kg9gAAASQ"] [Tue Aug 18 12:58:16.735504 2026] [security2:error] [pid 66623:tid 66683] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/f35.php"] [unique_id "aoSBGNO5rbWdOArH04Kg-AABTC4"] [Tue Aug 18 12:58:16.772271 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:12519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "aoSBGNO5rbWdOArH04Kg-wAAATQ"] [Tue Aug 18 12:58:16.780467 2026] [security2:error] [pid 66623:tid 66869] [client 172.182.200.96:7677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_AAAAXE"] [Tue Aug 18 12:58:16.781829 2026] [security2:error] [pid 66623:tid 66835] [client 20.118.172.148:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/images/wso.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_QAAAU8"] [Tue Aug 18 12:58:16.790349 2026] [security2:error] [pid 66623:tid 66812] [client 20.206.73.37:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/xamp.php"] [unique_id "aoSBGNO5rbWdOArH04Kg_wAAATg"] [Tue Aug 18 12:58:16.812137 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:64697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBGNO5rbWdOArH04KhAQAAASU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:16.819199 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:25933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/xyn.php"] [unique_id "aoSBGNO5rbWdOArH04KhAgAAAVo"] [Tue Aug 18 12:58:16.823351 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBGNO5rbWdOArH04KhAwAAATY"] [Tue Aug 18 12:58:16.834983 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.155.199:13162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/fff.php"] [unique_id "aoSBGNO5rbWdOArH04KhBAAAAVE"] [Tue Aug 18 12:58:16.839918 2026] [security2:error] [pid 66623:tid 66836] [client 20.104.85.180:31281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBGNO5rbWdOArH04KhBQAAAVA"] [Tue Aug 18 12:58:16.860017 2026] [security2:error] [pid 66623:tid 66839] [client 20.206.73.37:35152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSBGNO5rbWdOArH04KhCAAAAVM"] [Tue Aug 18 12:58:16.885855 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.217.32:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/oxshell.php"] [unique_id "aoSBGNO5rbWdOArH04KhCQAAAWI"] [Tue Aug 18 12:58:16.920417 2026] [security2:error] [pid 66623:tid 66640] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/f35.update.php"] [unique_id "aoSBGNO5rbWdOArH04KhCwABeQM"] [Tue Aug 18 12:58:16.936039 2026] [security2:error] [pid 66623:tid 66809] [client 20.206.73.37:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file25.php"] [unique_id "aoSBGNO5rbWdOArH04KhDAAAATU"] [Tue Aug 18 12:58:16.938052 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sd.php"] [unique_id "aoSBGNO5rbWdOArH04KhDQABe0U"] [Tue Aug 18 12:58:16.946851 2026] [security2:error] [pid 66623:tid 66863] [client 20.127.136.245:22117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/admin.php"] [unique_id "aoSBGNO5rbWdOArH04KhDgAAAWs"] [Tue Aug 18 12:58:16.974911 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file15.php"] [unique_id "aoSBGNO5rbWdOArH04KhEgAAAT8"] [Tue Aug 18 12:58:16.985368 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:16.985627 2026] [authz_core:error] [pid 66623:tid 66684] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:17.009584 2026] [security2:error] [pid 66623:tid 66884] [client 20.104.85.180:18826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/tes.php"] [unique_id "aoSBGdO5rbWdOArH04KhFAAAAYA"] [Tue Aug 18 12:58:17.022159 2026] [autoindex:error] [pid 66623:tid 66851] [client 20.79.204.6:12229] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:17.028690 2026] [security2:error] [pid 66623:tid 66802] [client 20.206.73.37:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/f35.php"] [unique_id "aoSBGdO5rbWdOArH04KhFgAAAS4"] [Tue Aug 18 12:58:17.106548 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/file.php"] [unique_id "aoSBGdO5rbWdOArH04KhGwABiDc"] [Tue Aug 18 12:58:17.114807 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/km.php"] [unique_id "aoSBGdO5rbWdOArH04KhHAABHG4"] [Tue Aug 18 12:58:17.129947 2026] [security2:error] [pid 66623:tid 66875] [client 20.119.58.187:11890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cache-compat.php"] [unique_id "aoSBGdO5rbWdOArH04KhHQAAAXc"] [Tue Aug 18 12:58:17.135481 2026] [security2:error] [pid 66623:tid 66649] [remote 46.62.208.238:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhHgABMgw"] [Tue Aug 18 12:58:17.144347 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:59789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-load.php"] [unique_id "aoSBGdO5rbWdOArH04KhHwAAATc"] [Tue Aug 18 12:58:17.163273 2026] [security2:error] [pid 66623:tid 66804] [client 20.100.185.105:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/jquery.php"] [unique_id "aoSBGdO5rbWdOArH04KhIAAAATA"] [Tue Aug 18 12:58:17.224476 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhIgAAAUs"] [Tue Aug 18 12:58:17.281815 2026] [security2:error] [pid 66623:tid 66838] [client 20.118.172.148:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/index/function.php"] [unique_id "aoSBGdO5rbWdOArH04KhJgAAAVI"] [Tue Aug 18 12:58:17.283866 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/file2.php"] [unique_id "aoSBGdO5rbWdOArH04KhJwABPXA"] [Tue Aug 18 12:58:17.285810 2026] [security2:error] [pid 66623:tid 66742] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mf.php"] [unique_id "aoSBGdO5rbWdOArH04KhKAABOmk"] [Tue Aug 18 12:58:17.295572 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:43525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/files/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhKQAAAR0"] [Tue Aug 18 12:58:17.316381 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/X57.php"] [unique_id "aoSBGdO5rbWdOArH04KhKgAAASg"] [Tue Aug 18 12:58:17.342185 2026] [security2:error] [pid 66623:tid 66699] [remote 103.56.163.133:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhKwABcz4"] [Tue Aug 18 12:58:17.344388 2026] [security2:error] [pid 66623:tid 66788] [client 20.104.85.180:23978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/about.php"] [unique_id "aoSBGdO5rbWdOArH04KhLAAAASA"] [Tue Aug 18 12:58:17.349088 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:7623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhLQAAAS0"] [Tue Aug 18 12:58:17.371012 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:24791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBGdO5rbWdOArH04KhMAAAASE"] [Tue Aug 18 12:58:17.398756 2026] [security2:error] [pid 66623:tid 66823] [client 172.182.217.32:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/php8.php"] [unique_id "aoSBGdO5rbWdOArH04KhMQAAAUM"] [Tue Aug 18 12:58:17.418495 2026] [security2:error] [pid 66623:tid 66866] [client 40.74.65.169:27782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/zoo2.php"] [unique_id "aoSBGdO5rbWdOArH04KhMwAAAW4"] [Tue Aug 18 12:58:17.483782 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:11865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ajax-actions.php"] [unique_id "aoSBGdO5rbWdOArH04KhOQAAASY"] [Tue Aug 18 12:58:17.490314 2026] [security2:error] [pid 66623:tid 66647] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/files.php"] [unique_id "aoSBGdO5rbWdOArH04KhOgABFAo"] [Tue Aug 18 12:58:17.496665 2026] [security2:error] [pid 66623:tid 66761] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ie.php"] [unique_id "aoSBGdO5rbWdOArH04KhOwABSXw"] [Tue Aug 18 12:58:17.529223 2026] [security2:error] [pid 66623:tid 66874] [client 144.86.18.243:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.18.86.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactads.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGdO5rbWdOArH04KhLwAAAXY"] [Tue Aug 18 12:58:17.529381 2026] [security2:error] [pid 66623:tid 66874] [client 144.86.18.243:62358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "impactads.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGdO5rbWdOArH04KhLwAAAXY"] [Tue Aug 18 12:58:17.529698 2026] [security2:error] [pid 66623:tid 66773] [client 158.23.17.4:34021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ie.php"] [unique_id "aoSBGdO5rbWdOArH04KhPQAAARE"] [Tue Aug 18 12:58:17.571932 2026] [security2:error] [pid 66623:tid 66837] [client 20.104.85.180:18874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhQQAAAVE"] [Tue Aug 18 12:58:17.588928 2026] [security2:error] [pid 66623:tid 66824] [client 39.194.1.247:9576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "usa.lifetreemarketing.com"] [uri "/"] [unique_id "aoSBGNO5rbWdOArH04KgtgAAAUQ"] [Tue Aug 18 12:58:17.590599 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:17.591033 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:17.592524 2026] [security2:error] [pid 66623:tid 66839] [client 20.127.136.245:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/edit.php"] [unique_id "aoSBGdO5rbWdOArH04KhRAAAAVM"] [Tue Aug 18 12:58:17.597280 2026] [security2:error] [pid 66623:tid 66825] [client 20.206.73.37:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBGdO5rbWdOArH04KhRQAAAUU"] [Tue Aug 18 12:58:17.613705 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:40965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pages.php"] [unique_id "aoSBGdO5rbWdOArH04KhRwAAAVY"] [Tue Aug 18 12:58:17.615785 2026] [security2:error] [pid 66623:tid 66786] [client 185.191.171.9:16866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754246636/1756598400/"] [unique_id "aoSBGdO5rbWdOArH04KhSQAAAR4"] [Tue Aug 18 12:58:17.615884 2026] [security2:error] [pid 66623:tid 66786] [client 185.191.171.9:16866] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754246636/1756598400/"] [unique_id "aoSBGdO5rbWdOArH04KhSQAAAR4"] [Tue Aug 18 12:58:17.672801 2026] [security2:error] [pid 66623:tid 66859] [client 74.248.18.37:40981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSBGdO5rbWdOArH04KhTAAAAWc"] [Tue Aug 18 12:58:17.679076 2026] [security2:error] [pid 66623:tid 66743] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fix.php"] [unique_id "aoSBGdO5rbWdOArH04KhTQABe2o"] [Tue Aug 18 12:58:17.690995 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nw.php"] [unique_id "aoSBGdO5rbWdOArH04KhTgABfxM"] [Tue Aug 18 12:58:17.721976 2026] [security2:error] [pid 66623:tid 66819] [client 20.206.73.37:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSBGdO5rbWdOArH04KhUAAAAT8"] [Tue Aug 18 12:58:17.757350 2026] [security2:error] [pid 66623:tid 66828] [client 158.158.74.177:16517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBGdO5rbWdOArH04KhUgAAAUg"] [Tue Aug 18 12:58:17.783200 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.185.105:18299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/5173e.php"] [unique_id "aoSBGdO5rbWdOArH04KhUwAAAVA"] [Tue Aug 18 12:58:17.793709 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.155.199:13014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/inputs.php"] [unique_id "aoSBGdO5rbWdOArH04KhVAAAASc"] [Tue Aug 18 12:58:17.825183 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBGdO5rbWdOArH04KhWAAAARU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:17.837503 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/ajax-actions.php"] [unique_id "aoSBGdO5rbWdOArH04KhWgAAAUA"] [Tue Aug 18 12:58:17.864919 2026] [security2:error] [pid 66623:tid 66698] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fm.php"] [unique_id "aoSBGdO5rbWdOArH04KhWwABgj0"] [Tue Aug 18 12:58:17.866299 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:62089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/info.php"] [unique_id "aoSBGdO5rbWdOArH04KhXAAAARw"] [Tue Aug 18 12:58:17.871012 2026] [security2:error] [pid 66623:tid 66875] [client 20.104.85.180:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBGdO5rbWdOArH04KhXQAAAXc"] [Tue Aug 18 12:58:17.872967 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sb.php"] [unique_id "aoSBGdO5rbWdOArH04KhXgABDl8"] [Tue Aug 18 12:58:17.878441 2026] [autoindex:error] [pid 66623:tid 66873] [client 20.79.204.6:11674] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:17.889096 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.217.32:15786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/p.php"] [unique_id "aoSBGdO5rbWdOArH04KhYAAAAWY"] [Tue Aug 18 12:58:17.917430 2026] [security2:error] [pid 66623:tid 66804] [client 20.206.73.37:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gecko.php"] [unique_id "aoSBGdO5rbWdOArH04KhYwAAATA"] [Tue Aug 18 12:58:17.956373 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:40645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/xiugai.php"] [unique_id "aoSBGdO5rbWdOArH04KhZAAAARM"] [Tue Aug 18 12:58:17.989947 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/first.php"] [unique_id "aoSBGdO5rbWdOArH04KhZgAAATM"] [Tue Aug 18 12:58:17.994579 2026] [security2:error] [pid 66623:tid 66817] [client 20.104.85.180:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBGdO5rbWdOArH04KhZwAAAT0"] [Tue Aug 18 12:58:18.008756 2026] [authz_core:error] [pid 66623:tid 66680] [remote 57.141.22.102:39006] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:18.009026 2026] [authz_core:error] [pid 66623:tid 66680] [remote 57.141.22.102:39006] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:18.013578 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:45771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/adminner.php"] [unique_id "aoSBGtO5rbWdOArH04KhawAAAR0"] [Tue Aug 18 12:58:18.047049 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/footer.php"] [unique_id "aoSBGtO5rbWdOArH04KhbAABLUo"] [Tue Aug 18 12:58:18.053506 2026] [security2:error] [pid 66623:tid 66864] [client 20.127.136.245:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/w.php"] [unique_id "aoSBGtO5rbWdOArH04KhbgAAAWw"] [Tue Aug 18 12:58:18.053512 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:57223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nw.php"] [unique_id "aoSBGtO5rbWdOArH04KhbQAAASE"] [Tue Aug 18 12:58:18.080269 2026] [security2:error] [pid 66623:tid 66791] [client 20.79.204.6:11674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBGtO5rbWdOArH04KhcQAAASM"] [Tue Aug 18 12:58:18.095353 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xj.php"] [unique_id "aoSBGtO5rbWdOArH04KhcwABVzA"] [Tue Aug 18 12:58:18.097859 2026] [security2:error] [pid 66623:tid 66868] [client 20.206.73.37:52061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file1221.php"] [unique_id "aoSBGtO5rbWdOArH04KhdQAAAXA"] [Tue Aug 18 12:58:18.117447 2026] [security2:error] [pid 66623:tid 66826] [client 20.206.73.37:11960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ano.php"] [unique_id "aoSBGtO5rbWdOArH04KhdgAAAUY"] [Tue Aug 18 12:58:18.133988 2026] [security2:error] [pid 66623:tid 66832] [client 40.74.65.169:35763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/org.php"] [unique_id "aoSBGtO5rbWdOArH04KhdwAAAUw"] [Tue Aug 18 12:58:18.139755 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inx.php"] [unique_id "aoSBGtO5rbWdOArH04KheAAAARQ"] [Tue Aug 18 12:58:18.157797 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBGtO5rbWdOArH04KhegAAARs"] [Tue Aug 18 12:58:18.190297 2026] [authz_core:error] [pid 66623:tid 66657] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:18.190567 2026] [authz_core:error] [pid 66623:tid 66657] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:18.191654 2026] [security2:error] [pid 66623:tid 66812] [client 20.206.73.37:42666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/reviall.php"] [unique_id "aoSBGtO5rbWdOArH04KhgAAAATg"] [Tue Aug 18 12:58:18.206944 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-consar.php"] [unique_id "aoSBGtO5rbWdOArH04KhggAAAXo"] [Tue Aug 18 12:58:18.233663 2026] [security2:error] [pid 66623:tid 66651] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/form.php"] [unique_id "aoSBGtO5rbWdOArH04KhgwABFg4"] [Tue Aug 18 12:58:18.278956 2026] [security2:error] [pid 66623:tid 66877] [client 20.206.73.37:55657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/11.php"] [unique_id "aoSBGtO5rbWdOArH04KhiQAAAXk"] [Tue Aug 18 12:58:18.289543 2026] [security2:error] [pid 66623:tid 66731] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ns.php"] [unique_id "aoSBGtO5rbWdOArH04KhigABe14"] [Tue Aug 18 12:58:18.363486 2026] [security2:error] [pid 66623:tid 66857] [client 20.206.73.37:5488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/File.php"] [unique_id "aoSBGtO5rbWdOArH04KhjgAAAWU"] [Tue Aug 18 12:58:18.371179 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/past.php"] [unique_id "aoSBGtO5rbWdOArH04KhkAAAAXE"] [Tue Aug 18 12:58:18.371686 2026] [security2:error] [pid 66623:tid 66800] [client 20.118.172.148:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/profile.php"] [unique_id "aoSBGtO5rbWdOArH04KhkQAAASw"] [Tue Aug 18 12:58:18.389379 2026] [security2:error] [pid 66623:tid 66880] [client 172.182.217.32:15803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/php.php"] [unique_id "aoSBGtO5rbWdOArH04KhkwAAAXw"] [Tue Aug 18 12:58:18.392808 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:41011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBGtO5rbWdOArH04KhlAAAASU"] [Tue Aug 18 12:58:18.404395 2026] [security2:error] [pid 66623:tid 66851] [client 20.206.73.37:52488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fi22.php"] [unique_id "aoSBGtO5rbWdOArH04KhlwAAAV8"] [Tue Aug 18 12:58:18.426283 2026] [security2:error] [pid 66623:tid 66798] [client 20.206.73.37:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04KhmAAAASo"] [Tue Aug 18 12:58:18.429807 2026] [security2:error] [pid 66623:tid 66669] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/fpwch.php"] [unique_id "aoSBGtO5rbWdOArH04KhmQABhSA"] [Tue Aug 18 12:58:18.433258 2026] [security2:error] [pid 66623:tid 66777] [client 20.104.85.180:18847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/rip.php"] [unique_id "aoSBGtO5rbWdOArH04KhmgAAARU"] [Tue Aug 18 12:58:18.433597 2026] [security2:error] [pid 66623:tid 66802] [client 196.12.128.158:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhmwAAAS4"] [Tue Aug 18 12:58:18.433696 2026] [security2:error] [pid 66623:tid 66802] [client 196.12.128.158:57694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhmwAAAS4"] [Tue Aug 18 12:58:18.448646 2026] [security2:error] [pid 66623:tid 66855] [client 20.100.185.105:34569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/class_api.php"] [unique_id "aoSBGtO5rbWdOArH04KhnQAAAWM"] [Tue Aug 18 12:58:18.464211 2026] [security2:error] [pid 66623:tid 66875] [client 40.74.65.169:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/xx.php"] [unique_id "aoSBGtO5rbWdOArH04KhoAAAAXc"] [Tue Aug 18 12:58:18.470433 2026] [security2:error] [pid 66623:tid 66770] [client 20.206.73.37:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhoQAAAQ4"] [Tue Aug 18 12:58:18.482974 2026] [security2:error] [pid 66623:tid 66750] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gk.php"] [unique_id "aoSBGtO5rbWdOArH04KhogABgXE"] [Tue Aug 18 12:58:18.492775 2026] [authz_core:error] [pid 66623:tid 66673] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:18.493074 2026] [authz_core:error] [pid 66623:tid 66673] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:18.522139 2026] [security2:error] [pid 66623:tid 66815] [client 157.51.166.53:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhpAAAATs"] [Tue Aug 18 12:58:18.522279 2026] [security2:error] [pid 66623:tid 66815] [client 157.51.166.53:52181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04KhpAAAATs"] [Tue Aug 18 12:58:18.559045 2026] [security2:error] [pid 66623:tid 66775] [client 172.182.200.96:7635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBGtO5rbWdOArH04KhpgAAARM"] [Tue Aug 18 12:58:18.561882 2026] [security2:error] [pid 66623:tid 66803] [client 20.119.58.187:11900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/repeater.php"] [unique_id "aoSBGtO5rbWdOArH04KhpwAAAS8"] [Tue Aug 18 12:58:18.584793 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.155.199:7551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBGtO5rbWdOArH04KhqQAAAQw"] [Tue Aug 18 12:58:18.594464 2026] [security2:error] [pid 66623:tid 66822] [client 20.206.73.37:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04KhqgAAAUI"] [Tue Aug 18 12:58:18.607388 2026] [security2:error] [pid 66623:tid 66814] [client 20.206.73.37:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhrAAAATo"] [Tue Aug 18 12:58:18.611174 2026] [security2:error] [pid 66623:tid 66739] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/function.php"] [unique_id "aoSBGtO5rbWdOArH04KhrQABKGY"] [Tue Aug 18 12:58:18.632041 2026] [security2:error] [pid 66623:tid 66788] [client 20.206.73.37:52536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhrgAAASA"] [Tue Aug 18 12:58:18.635600 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:24783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBGtO5rbWdOArH04KhsAAAAS0"] [Tue Aug 18 12:58:18.661912 2026] [security2:error] [pid 66623:tid 66843] [client 20.203.138.185:39031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/forbidals.php"] [unique_id "aoSBGtO5rbWdOArH04KhsgAAAVc"] [Tue Aug 18 12:58:18.663556 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wn.php"] [unique_id "aoSBGtO5rbWdOArH04KhswABcHc"] [Tue Aug 18 12:58:18.672949 2026] [security2:error] [pid 66623:tid 66769] [client 20.127.136.245:1794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file.php"] [unique_id "aoSBGtO5rbWdOArH04KhtAAAAQ0"] [Tue Aug 18 12:58:18.681217 2026] [security2:error] [pid 66623:tid 66867] [client 158.158.34.183:11718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/csv.php"] [unique_id "aoSBGtO5rbWdOArH04KhtQAAAW8"] [Tue Aug 18 12:58:18.685395 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBGtO5rbWdOArH04KhtgAAARQ"] [Tue Aug 18 12:58:18.687484 2026] [security2:error] [pid 66623:tid 66858] [client 20.79.204.6:11650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBGtO5rbWdOArH04KhtwAAAWY"] [Tue Aug 18 12:58:18.705544 2026] [security2:error] [pid 66623:tid 66773] [client 158.23.17.4:44805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sb.php"] [unique_id "aoSBGtO5rbWdOArH04KhuAAAARE"] [Tue Aug 18 12:58:18.714082 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/f35.php"] [unique_id "aoSBGtO5rbWdOArH04KhuQAAATw"] [Tue Aug 18 12:58:18.714748 2026] [security2:error] [pid 66623:tid 66810] [client 20.206.73.37:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/media.php"] [unique_id "aoSBGtO5rbWdOArH04KhugAAATY"] [Tue Aug 18 12:58:18.776780 2026] [security2:error] [pid 66623:tid 66767] [client 20.206.73.37:50066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/inso.php"] [unique_id "aoSBGtO5rbWdOArH04KhwQAAAQs"] [Tue Aug 18 12:58:18.780597 2026] [autoindex:error] [pid 66623:tid 66688] [remote 136.110.27.48:37542] AH01276: Cannot serve directory /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:18.793369 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/g.php"] [unique_id "aoSBGtO5rbWdOArH04KhwwABZ3Q"] [Tue Aug 18 12:58:18.803984 2026] [security2:error] [pid 66623:tid 66842] [client 20.206.73.37:45777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/shiny.php"] [unique_id "aoSBGtO5rbWdOArH04KhxAAAAVY"] [Tue Aug 18 12:58:18.824090 2026] [security2:error] [pid 66623:tid 66787] [client 20.206.73.37:45781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/403dd.php"] [unique_id "aoSBGtO5rbWdOArH04KhxgAAAR8"] [Tue Aug 18 12:58:18.835336 2026] [security2:error] [pid 66623:tid 66823] [client 40.74.65.169:26728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/imageskir.php"] [unique_id "aoSBGtO5rbWdOArH04KhxwAAAUM"] [Tue Aug 18 12:58:18.842144 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBGtO5rbWdOArH04KhzgAAAX4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:18.866425 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/app.php"] [unique_id "aoSBGtO5rbWdOArH04KhzwABbUk"] [Tue Aug 18 12:58:18.873271 2026] [security2:error] [pid 66623:tid 66798] [client 20.118.172.148:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/sx.php"] [unique_id "aoSBGtO5rbWdOArH04Kh0AAAASo"] [Tue Aug 18 12:58:18.880078 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.217.32:15789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/past.php"] [unique_id "aoSBGtO5rbWdOArH04Kh0QAAAVo"] [Tue Aug 18 12:58:18.911730 2026] [security2:error] [pid 66623:tid 66802] [client 20.206.73.37:52517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/baba.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1AAAAS4"] [Tue Aug 18 12:58:18.916204 2026] [security2:error] [pid 66623:tid 66861] [client 20.119.58.187:11993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin-post.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1QAAAWk"] [Tue Aug 18 12:58:18.938587 2026] [security2:error] [pid 66623:tid 66875] [client 20.48.236.86:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBGtO5rbWdOArH04Kh1wAAAXc"] [Tue Aug 18 12:58:18.969822 2026] [security2:error] [pid 66623:tid 66808] [client 20.206.73.37:40679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/site.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2AAAATQ"] [Tue Aug 18 12:58:18.970130 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2QAAAWM"] [Tue Aug 18 12:58:18.970235 2026] [security2:error] [pid 66623:tid 66855] [client 192.141.172.134:50278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2QAAAWM"] [Tue Aug 18 12:58:18.984637 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/goods.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2gABMFA"] [Tue Aug 18 12:58:18.985902 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBGtO5rbWdOArH04Kh2wAAATs"] [Tue Aug 18 12:58:19.017202 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.172.148:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBG9O5rbWdOArH04Kh3wAAAVs"] [Tue Aug 18 12:58:19.018297 2026] [security2:error] [pid 66623:tid 66884] [client 172.202.39.151:44550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4AAAAYA"] [Tue Aug 18 12:58:19.025431 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/cabs.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4QAAARM"] [Tue Aug 18 12:58:19.038487 2026] [security2:error] [pid 66623:tid 66844] [client 197.184.64.235:41943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4gAAAVg"] [Tue Aug 18 12:58:19.038557 2026] [security2:error] [pid 66623:tid 66844] [client 197.184.64.235:41943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4gAAAVg"] [Tue Aug 18 12:58:19.069099 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/insc.php"] [unique_id "aoSBG9O5rbWdOArH04Kh4wAAAV0"] [Tue Aug 18 12:58:19.071890 2026] [security2:error] [pid 66623:tid 66841] [client 74.248.18.37:7229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/php.php"] [unique_id "aoSBG9O5rbWdOArH04Kh5QAAAVU"] [Tue Aug 18 12:58:19.071912 2026] [security2:error] [pid 66623:tid 66807] [client 172.182.200.96:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBG9O5rbWdOArH04Kh5gAAATM"] [Tue Aug 18 12:58:19.086825 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/87.php"] [unique_id "aoSBG9O5rbWdOArH04Kh6AABK0g"] [Tue Aug 18 12:58:19.089235 2026] [security2:error] [pid 66623:tid 66889] [client 20.100.185.105:6228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/word.php"] [unique_id "aoSBG9O5rbWdOArH04Kh6QAAAYU"] [Tue Aug 18 12:58:19.093479 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:19.093753 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:19.099428 2026] [security2:error] [pid 66623:tid 66789] [client 20.206.73.37:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/file.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7QAAASE"] [Tue Aug 18 12:58:19.139016 2026] [security2:error] [pid 66623:tid 66791] [client 68.155.155.199:3846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/lite.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7gAAASM"] [Tue Aug 18 12:58:19.170566 2026] [security2:error] [pid 66623:tid 66758] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/gtt.php"] [unique_id "aoSBG9O5rbWdOArH04Kh7wABDXk"] [Tue Aug 18 12:58:19.209703 2026] [security2:error] [pid 66623:tid 66888] [client 74.248.18.37:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSBG9O5rbWdOArH04Kh8gAAAYQ"] [Tue Aug 18 12:58:19.224077 2026] [security2:error] [pid 66623:tid 66874] [client 20.206.73.37:11922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ai.php"] [unique_id "aoSBG9O5rbWdOArH04Kh8wAAAXY"] [Tue Aug 18 12:58:19.276818 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "aoSBG9O5rbWdOArH04Kh9gAAAXA"] [Tue Aug 18 12:58:19.304045 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zi.php"] [unique_id "aoSBG9O5rbWdOArH04Kh-QABFhk"] [Tue Aug 18 12:58:19.305852 2026] [security2:error] [pid 66623:tid 66788] [client 20.79.204.6:11668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBG9O5rbWdOArH04Kh-gAAASA"] [Tue Aug 18 12:58:19.312551 2026] [security2:error] [pid 66623:tid 66779] [client 20.118.172.148:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBG9O5rbWdOArH04Kh_QAAARc"] [Tue Aug 18 12:58:19.315568 2026] [security2:error] [pid 66623:tid 66825] [client 40.74.65.169:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/av.php"] [unique_id "aoSBG9O5rbWdOArH04Kh_wAAAUU"] [Tue Aug 18 12:58:19.341485 2026] [security2:error] [pid 66623:tid 66767] [client 20.206.73.37:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/dex.php"] [unique_id "aoSBG9O5rbWdOArH04KiBgAAAQs"] [Tue Aug 18 12:58:19.353832 2026] [security2:error] [pid 66623:tid 66762] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/gulu.php"] [unique_id "aoSBG9O5rbWdOArH04KiBwABf30"] [Tue Aug 18 12:58:19.369631 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:15439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/root.php"] [unique_id "aoSBG9O5rbWdOArH04KiCQAAARQ"] [Tue Aug 18 12:58:19.386496 2026] [security2:error] [pid 66623:tid 66859] [client 20.127.136.245:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBG9O5rbWdOArH04KiCgAAAWc"] [Tue Aug 18 12:58:19.393025 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:19.393305 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:19.463529 2026] [security2:error] [pid 66623:tid 66850] [client 4.232.151.198:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/uploads/backwpup-restore/uploads/users.php"] [unique_id "aoSBG9O5rbWdOArH04KiDQAAAV4"] [Tue Aug 18 12:58:19.480910 2026] [security2:error] [pid 66623:tid 66853] [client 20.250.13.23:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/goods.php"] [unique_id "aoSBG9O5rbWdOArH04KiDgAAAWE"] [Tue Aug 18 12:58:19.504968 2026] [security2:error] [pid 66623:tid 66780] [client 213.202.253.4:63644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/filefuns.php"] [unique_id "aoSBG9O5rbWdOArH04KiDwAAARg"], referer: www.google.com [Tue Aug 18 12:58:19.533080 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/hello.php"] [unique_id "aoSBG9O5rbWdOArH04KiFQABfDE"] [Tue Aug 18 12:58:19.534358 2026] [security2:error] [pid 66623:tid 66798] [client 40.74.65.169:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/indexo.php"] [unique_id "aoSBG9O5rbWdOArH04KiFgAAASo"] [Tue Aug 18 12:58:19.629092 2026] [security2:error] [pid 66623:tid 66882] [client 20.119.58.187:12542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBG9O5rbWdOArH04KiGgAAAX4"] [Tue Aug 18 12:58:19.702373 2026] [security2:error] [pid 66623:tid 66775] [client 20.206.73.37:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/key.php"] [unique_id "aoSBG9O5rbWdOArH04KiIAAAARM"] [Tue Aug 18 12:58:19.708633 2026] [security2:error] [pid 66623:tid 66869] [client 79.127.164.8:33078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/scriptsacplibinserts.bak"] [unique_id "aoSBG9O5rbWdOArH04KiIQAAAXE"], referer: https://medihub.com.br/scriptsacplibinserts.bak [Tue Aug 18 12:58:19.710103 2026] [security2:error] [pid 66623:tid 66783] [client 20.100.185.105:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-index.php"] [unique_id "aoSBG9O5rbWdOArH04KiIgAAARs"] [Tue Aug 18 12:58:19.723790 2026] [security2:error] [pid 66623:tid 66827] [client 172.182.200.96:14183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBG9O5rbWdOArH04KiJAAAAUc"] [Tue Aug 18 12:58:19.723862 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSBG9O5rbWdOArH04KiIwABS24"] [Tue Aug 18 12:58:19.757736 2026] [security2:error] [pid 66623:tid 66881] [client 20.118.172.148:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.bluelord.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBG9O5rbWdOArH04KiJwAAAX0"] [Tue Aug 18 12:58:19.774108 2026] [security2:error] [pid 66623:tid 66841] [client 52.173.121.69:24993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBG9O5rbWdOArH04KiKAAAAVU"] [Tue Aug 18 12:58:19.779415 2026] [security2:error] [pid 66623:tid 66695] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/92.php"] [unique_id "aoSBG9O5rbWdOArH04KiKgABajo"] [Tue Aug 18 12:58:19.780685 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/manager.php"] [unique_id "aoSBG9O5rbWdOArH04KiKwAAAXg"] [Tue Aug 18 12:58:19.792118 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/edit.php"] [unique_id "aoSBG9O5rbWdOArH04KiLQAAASg"] [Tue Aug 18 12:58:19.822065 2026] [security2:error] [pid 66623:tid 66878] [client 74.248.18.37:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/php8.php"] [unique_id "aoSBG9O5rbWdOArH04KiLwAAAXo"] [Tue Aug 18 12:58:19.853240 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBG9O5rbWdOArH04KiMQAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:19.857197 2026] [security2:error] [pid 66623:tid 66821] [client 172.182.217.32:15780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/r.php"] [unique_id "aoSBG9O5rbWdOArH04KiMgAAAUE"] [Tue Aug 18 12:58:19.898421 2026] [security2:error] [pid 66623:tid 66832] [client 20.215.241.237:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/ops.php"] [unique_id "aoSBG9O5rbWdOArH04KiNQAAAUw"] [Tue Aug 18 12:58:19.901494 2026] [security2:error] [pid 66623:tid 66749] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBG9O5rbWdOArH04KiNgABSXA"] [Tue Aug 18 12:58:19.910018 2026] [security2:error] [pid 66623:tid 66803] [client 20.79.204.6:11649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBG9O5rbWdOArH04KiNwAAAS8"] [Tue Aug 18 12:58:19.925599 2026] [security2:error] [pid 66623:tid 66816] [client 20.206.73.37:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/kir.php"] [unique_id "aoSBG9O5rbWdOArH04KiOQAAATw"] [Tue Aug 18 12:58:19.932967 2026] [security2:error] [pid 66623:tid 66852] [client 20.127.136.245:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/aa.php"] [unique_id "aoSBG9O5rbWdOArH04KiPAAAAWA"] [Tue Aug 18 12:58:19.961413 2026] [security2:error] [pid 66623:tid 66699] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jm.php"] [unique_id "aoSBG9O5rbWdOArH04KiPwABIj4"] [Tue Aug 18 12:58:19.983778 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBG9O5rbWdOArH04KiQQAAASE"] [Tue Aug 18 12:58:19.986912 2026] [security2:error] [pid 66623:tid 66825] [client 20.206.73.37:38993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/nofile.php"] [unique_id "aoSBG9O5rbWdOArH04KiQgAAAUU"] [Tue Aug 18 12:58:19.996707 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:19.996967 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:20.020151 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/fling.php"] [unique_id "aoSBHNO5rbWdOArH04KiSAAAARQ"] [Tue Aug 18 12:58:20.025530 2026] [security2:error] [pid 66623:tid 66859] [client 20.104.85.180:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/inputs.php"] [unique_id "aoSBHNO5rbWdOArH04KiTAAAAWc"] [Tue Aug 18 12:58:20.028355 2026] [security2:error] [pid 66623:tid 66648] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env"] [unique_id "aoSBHNO5rbWdOArH04KiTgABLQs"] [Tue Aug 18 12:58:20.037871 2026] [security2:error] [pid 66623:tid 66848] [client 158.23.17.4:44803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xj.php"] [unique_id "aoSBHNO5rbWdOArH04KiTwAAAVw"] [Tue Aug 18 12:58:20.065651 2026] [security2:error] [pid 66623:tid 66819] [client 68.155.155.199:1496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBHNO5rbWdOArH04KiUwAAAT8"] [Tue Aug 18 12:58:20.093462 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gxirhnercs.php"] [unique_id "aoSBHNO5rbWdOArH04KiVgAAAVc"] [Tue Aug 18 12:58:20.124130 2026] [security2:error] [pid 66623:tid 66795] [client 20.206.73.37:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/zoo1.php"] [unique_id "aoSBHNO5rbWdOArH04KiVwAAASc"] [Tue Aug 18 12:58:20.155495 2026] [security2:error] [pid 66623:tid 66846] [client 20.48.236.86:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/inso.php"] [unique_id "aoSBHNO5rbWdOArH04KiWQAAAVo"] [Tue Aug 18 12:58:20.183893 2026] [security2:error] [pid 66623:tid 66676] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wj.php"] [unique_id "aoSBHNO5rbWdOArH04KiWgABaSc"] [Tue Aug 18 12:58:20.205895 2026] [security2:error] [pid 66623:tid 66811] [client 20.206.73.37:50106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/zoo2.php"] [unique_id "aoSBHNO5rbWdOArH04KiXQAAATc"] [Tue Aug 18 12:58:20.219484 2026] [security2:error] [pid 66623:tid 66877] [client 20.206.73.37:40691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/org.php"] [unique_id "aoSBHNO5rbWdOArH04KiXgAAAXk"] [Tue Aug 18 12:58:20.221599 2026] [security2:error] [pid 66623:tid 66855] [client 40.74.65.169:27071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBHNO5rbWdOArH04KiXwAAAWM"] [Tue Aug 18 12:58:20.248402 2026] [security2:error] [pid 66623:tid 66869] [client 20.206.73.37:50090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/imageskir.php"] [unique_id "aoSBHNO5rbWdOArH04KiYQAAAXE"] [Tue Aug 18 12:58:20.296932 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/indexo.php"] [unique_id "aoSBHNO5rbWdOArH04KiZwAAAV0"] [Tue Aug 18 12:58:20.297088 2026] [authz_core:error] [pid 66623:tid 66720] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:20.297338 2026] [authz_core:error] [pid 66623:tid 66720] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:20.334323 2026] [security2:error] [pid 66623:tid 66836] [client 20.100.185.105:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/bypass.php"] [unique_id "aoSBHNO5rbWdOArH04KiagAAAVA"] [Tue Aug 18 12:58:20.343307 2026] [security2:error] [pid 66623:tid 66845] [client 172.182.217.32:15765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/sid3.php"] [unique_id "aoSBHNO5rbWdOArH04KiawAAAVk"] [Tue Aug 18 12:58:20.347936 2026] [security2:error] [pid 66623:tid 66785] [client 20.206.73.37:5487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBHNO5rbWdOArH04KibAAAAR0"] [Tue Aug 18 12:58:20.352484 2026] [security2:error] [pid 66623:tid 66808] [client 20.119.58.187:11980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/about.php7"] [unique_id "aoSBHNO5rbWdOArH04KibQAAATQ"] [Tue Aug 18 12:58:20.385758 2026] [security2:error] [pid 66623:tid 66805] [client 40.74.65.169:55811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/media.php"] [unique_id "aoSBHNO5rbWdOArH04KidAAAATE"] [Tue Aug 18 12:58:20.390383 2026] [security2:error] [pid 66623:tid 66729] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/images/index.php"] [unique_id "aoSBHNO5rbWdOArH04KidwABa1w"] [Tue Aug 18 12:58:20.401754 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/blog/byp.php"] [unique_id "aoSBHNO5rbWdOArH04KifAAAAQ0"] [Tue Aug 18 12:58:20.405468 2026] [security2:error] [pid 66623:tid 66812] [client 86.120.159.145:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiewAAATg"] [Tue Aug 18 12:58:20.405568 2026] [security2:error] [pid 66623:tid 66812] [client 86.120.159.145:59678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiewAAATg"] [Tue Aug 18 12:58:20.414262 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/74.php"] [unique_id "aoSBHNO5rbWdOArH04KifQABJg4"] [Tue Aug 18 12:58:20.425500 2026] [security2:error] [pid 66623:tid 66802] [client 216.73.160.240:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "twgestaoemarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBHNO5rbWdOArH04KiZAAAAS4"] [Tue Aug 18 12:58:20.514046 2026] [security2:error] [pid 66623:tid 66826] [client 158.158.74.177:2673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBHNO5rbWdOArH04KigwAAAUY"] [Tue Aug 18 12:58:20.515166 2026] [security2:error] [pid 66623:tid 66814] [client 20.79.204.6:11705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBHNO5rbWdOArH04KihAAAATo"] [Tue Aug 18 12:58:20.532947 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about/function.php"] [unique_id "aoSBHNO5rbWdOArH04KihwAAAXA"] [Tue Aug 18 12:58:20.568818 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/index/function.php"] [unique_id "aoSBHNO5rbWdOArH04KiiwABiR8"] [Tue Aug 18 12:58:20.585717 2026] [security2:error] [pid 66623:tid 66839] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHNO5rbWdOArH04KiigABUyA"] [Tue Aug 18 12:58:20.590800 2026] [security2:error] [pid 66623:tid 66714] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/av.php"] [unique_id "aoSBHNO5rbWdOArH04KijAABIU0"] [Tue Aug 18 12:58:20.598970 2026] [authz_core:error] [pid 66623:tid 66671] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:20.599250 2026] [authz_core:error] [pid 66623:tid 66671] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:20.611623 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/plugins.php"] [unique_id "aoSBHNO5rbWdOArH04KijgAAASk"] [Tue Aug 18 12:58:20.614687 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:24990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBHNO5rbWdOArH04KijwAAAUU"] [Tue Aug 18 12:58:20.635735 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBHNO5rbWdOArH04KikAAAARk"] [Tue Aug 18 12:58:20.683267 2026] [security2:error] [pid 66623:tid 66776] [client 20.206.73.37:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/w1px.php"] [unique_id "aoSBHNO5rbWdOArH04KilQAAARQ"] [Tue Aug 18 12:58:20.696673 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSBHNO5rbWdOArH04KilgAAAVw"] [Tue Aug 18 12:58:20.705549 2026] [security2:error] [pid 66623:tid 66788] [client 20.119.58.187:11901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/adminfuns.php7"] [unique_id "aoSBHNO5rbWdOArH04KilwAAASA"] [Tue Aug 18 12:58:20.710518 2026] [security2:error] [pid 66623:tid 66642] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.bak"] [unique_id "aoSBHNO5rbWdOArH04KimQABXgU"] [Tue Aug 18 12:58:20.712030 2026] [security2:error] [pid 66623:tid 66739] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.old"] [unique_id "aoSBHNO5rbWdOArH04KimgABXmY"] [Tue Aug 18 12:58:20.715425 2026] [security2:error] [pid 66623:tid 66864] [client 4.232.151.198:5261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/data.php"] [unique_id "aoSBHNO5rbWdOArH04KimwAAAWw"] [Tue Aug 18 12:58:20.725766 2026] [security2:error] [pid 66623:tid 66870] [client 158.158.34.183:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/404.php123123"] [unique_id "aoSBHNO5rbWdOArH04KinAAAAXI"] [Tue Aug 18 12:58:20.749368 2026] [security2:error] [pid 66623:tid 66866] [client 20.206.73.37:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/.admin.php"] [unique_id "aoSBHNO5rbWdOArH04KingAAAW4"] [Tue Aug 18 12:58:20.752598 2026] [security2:error] [pid 66623:tid 66666] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.backup"] [unique_id "aoSBHNO5rbWdOArH04KinwABEh0"] [Tue Aug 18 12:58:20.759156 2026] [security2:error] [pid 66623:tid 66681] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/api/.env"] [unique_id "aoSBHNO5rbWdOArH04KioAABbSw"] [Tue Aug 18 12:58:20.778356 2026] [security2:error] [pid 66623:tid 66756] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/info.php"] [unique_id "aoSBHNO5rbWdOArH04KiogABWnc"] [Tue Aug 18 12:58:20.791792 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ag.php"] [unique_id "aoSBHNO5rbWdOArH04KipAABaRQ"] [Tue Aug 18 12:58:20.831958 2026] [security2:error] [pid 66623:tid 66885] [client 20.206.73.37:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/wsomini.php"] [unique_id "aoSBHNO5rbWdOArH04KipwAAAYE"] [Tue Aug 18 12:58:20.866937 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBHNO5rbWdOArH04KiqwAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:20.879204 2026] [security2:error] [pid 66623:tid 66830] [client 20.206.73.37:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.schuenckimoveis.com.br"] [uri "/vr.php"] [unique_id "aoSBHNO5rbWdOArH04KirAAAAUo"] [Tue Aug 18 12:58:20.893387 2026] [security2:error] [pid 66623:tid 66869] [client 20.203.183.135:41537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/fpwch.php"] [unique_id "aoSBHNO5rbWdOArH04KirgAAAXE"] [Tue Aug 18 12:58:20.901967 2026] [security2:error] [pid 66623:tid 66827] [client 20.48.236.86:31085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/puc.php"] [unique_id "aoSBHNO5rbWdOArH04KirwAAAUc"] [Tue Aug 18 12:58:20.902559 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:20.902980 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:20.907282 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.217.32:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ss.php"] [unique_id "aoSBHNO5rbWdOArH04KisAAAAUg"] [Tue Aug 18 12:58:20.933209 2026] [security2:error] [pid 66623:tid 66768] [client 20.104.85.180:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/alfa.php"] [unique_id "aoSBHNO5rbWdOArH04KisgAAAQw"] [Tue Aug 18 12:58:20.950686 2026] [security2:error] [pid 66623:tid 66890] [client 172.182.200.96:14190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBHNO5rbWdOArH04KiswAAAYY"] [Tue Aug 18 12:58:20.952688 2026] [security2:error] [pid 66623:tid 66849] [client 20.127.136.245:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBHNO5rbWdOArH04KitAAAAV0"] [Tue Aug 18 12:58:20.953654 2026] [security2:error] [pid 66623:tid 66807] [client 40.74.65.169:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/8pyceeo.php"] [unique_id "aoSBHNO5rbWdOArH04KitQAAATM"] [Tue Aug 18 12:58:20.958650 2026] [security2:error] [pid 66623:tid 66795] [client 20.100.185.105:16780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/alfanew.php7"] [unique_id "aoSBHNO5rbWdOArH04KitgAAASc"] [Tue Aug 18 12:58:20.963430 2026] [security2:error] [pid 66623:tid 66688] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/install.php"] [unique_id "aoSBHNO5rbWdOArH04KitwABdzM"] [Tue Aug 18 12:58:20.989688 2026] [security2:error] [pid 66623:tid 66753] [remote 108.167.161.148:20190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoSBHNO5rbWdOArH04KiuAABLHQ"] [Tue Aug 18 12:58:21.014585 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ig.php"] [unique_id "aoSBHdO5rbWdOArH04KiugABewQ"] [Tue Aug 18 12:58:21.038279 2026] [security2:error] [pid 66623:tid 66726] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/backend/.env"] [unique_id "aoSBHdO5rbWdOArH04KivAABelk"] [Tue Aug 18 12:58:21.059132 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:11896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ebs.php7"] [unique_id "aoSBHdO5rbWdOArH04KivgAAAX0"] [Tue Aug 18 12:58:21.115936 2026] [security2:error] [pid 66623:tid 66751] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config/.env"] [unique_id "aoSBHdO5rbWdOArH04KiwwABQnI"] [Tue Aug 18 12:58:21.116584 2026] [security2:error] [pid 66623:tid 66831] [client 20.79.204.6:11667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBHdO5rbWdOArH04KixAAAAUs"] [Tue Aug 18 12:58:21.148314 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/item.php"] [unique_id "aoSBHdO5rbWdOArH04KixgABVFA"] [Tue Aug 18 12:58:21.184510 2026] [security2:error] [pid 66623:tid 66872] [client 68.155.155.199:10029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/rip.php"] [unique_id "aoSBHdO5rbWdOArH04KixwAAAXQ"] [Tue Aug 18 12:58:21.191212 2026] [security2:error] [pid 66623:tid 66697] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ta.php"] [unique_id "aoSBHdO5rbWdOArH04KiyQABdjw"] [Tue Aug 18 12:58:21.247199 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.169.31:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/w1.php"] [unique_id "aoSBHdO5rbWdOArH04KiywAAATQ"] [Tue Aug 18 12:58:21.268430 2026] [security2:error] [pid 66623:tid 66790] [client 20.118.133.132:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/btx25.php"] [unique_id "aoSBHdO5rbWdOArH04KizAAAASI"] [Tue Aug 18 12:58:21.277027 2026] [security2:error] [pid 66623:tid 66799] [client 74.248.18.37:7217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/post.php"] [unique_id "aoSBHdO5rbWdOArH04KizgAAASs"] [Tue Aug 18 12:58:21.286308 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:17967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBHdO5rbWdOArH04KizwAAAT4"] [Tue Aug 18 12:58:21.328229 2026] [security2:error] [pid 66623:tid 66839] [client 172.182.200.96:14188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0AAAAVM"] [Tue Aug 18 12:58:21.329529 2026] [security2:error] [pid 66623:tid 66746] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/kir.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0QABIW0"] [Tue Aug 18 12:58:21.330694 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:18769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0wAAARc"] [Tue Aug 18 12:58:21.330883 2026] [security2:error] [pid 66623:tid 66793] [client 74.248.18.37:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBHdO5rbWdOArH04Ki0gAAASU"] [Tue Aug 18 12:58:21.355184 2026] [security2:error] [pid 66623:tid 66834] [client 20.203.138.185:54985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/kj.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1AAAAU4"] [Tue Aug 18 12:58:21.405245 2026] [security2:error] [pid 66623:tid 66781] [client 40.74.65.169:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/images.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1gAAARk"] [Tue Aug 18 12:58:21.408379 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/34.php"] [unique_id "aoSBHdO5rbWdOArH04Ki1wABf2Q"] [Tue Aug 18 12:58:21.409128 2026] [security2:error] [pid 66623:tid 66782] [client 172.182.217.32:15615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/sts.php"] [unique_id "aoSBHdO5rbWdOArH04Ki2AAAARo"] [Tue Aug 18 12:58:21.410531 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ws.php7"] [unique_id "aoSBHdO5rbWdOArH04Ki2QAAARY"] [Tue Aug 18 12:58:21.433622 2026] [security2:error] [pid 66623:tid 66802] [client 4.232.151.198:5287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/options.php"] [unique_id "aoSBHdO5rbWdOArH04Ki2gAAAS4"] [Tue Aug 18 12:58:21.500950 2026] [security2:error] [pid 66623:tid 66801] [client 192.141.172.134:50522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4QAAAS0"] [Tue Aug 18 12:58:21.501139 2026] [security2:error] [pid 66623:tid 66801] [client 192.141.172.134:50522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4QAAAS0"] [Tue Aug 18 12:58:21.501170 2026] [authz_core:error] [pid 66623:tid 66662] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:21.501487 2026] [authz_core:error] [pid 66623:tid 66662] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:21.513926 2026] [security2:error] [pid 66623:tid 66796] [client 20.250.13.23:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/file.php"] [unique_id "aoSBHdO5rbWdOArH04Ki4wAAASg"] [Tue Aug 18 12:58:21.575580 2026] [security2:error] [pid 66623:tid 66767] [client 20.100.185.105:34615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/admin-header.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5QAAAQs"] [Tue Aug 18 12:58:21.587417 2026] [security2:error] [pid 66623:tid 66861] [client 20.104.85.180:27933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/lock360.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5gAAAWk"] [Tue Aug 18 12:58:21.598350 2026] [security2:error] [pid 66623:tid 66806] [client 20.118.172.148:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/function/function.php"] [unique_id "aoSBHdO5rbWdOArH04Ki5wAAATI"] [Tue Aug 18 12:58:21.612000 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/he.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6AABN2s"] [Tue Aug 18 12:58:21.642460 2026] [security2:error] [pid 66623:tid 66873] [client 20.127.136.245:13482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6QAAAXU"] [Tue Aug 18 12:58:21.654760 2026] [security2:error] [pid 66623:tid 66855] [client 40.74.65.169:27748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/.admin.php"] [unique_id "aoSBHdO5rbWdOArH04Ki6wAAAWM"] [Tue Aug 18 12:58:21.723508 2026] [security2:error] [pid 66623:tid 66870] [client 20.79.204.6:11678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBHdO5rbWdOArH04Ki8AAAAXI"] [Tue Aug 18 12:58:21.780073 2026] [security2:error] [pid 66623:tid 66735] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/log.php"] [unique_id "aoSBHdO5rbWdOArH04Ki9AABe2I"] [Tue Aug 18 12:58:21.780087 2026] [security2:error] [pid 66623:tid 66869] [client 20.119.58.187:11881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfanew2.php7"] [unique_id "aoSBHdO5rbWdOArH04Ki9QAAAXE"] [Tue Aug 18 12:58:21.790826 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gz.php"] [unique_id "aoSBHdO5rbWdOArH04Ki9gABHSM"] [Tue Aug 18 12:58:21.803497 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:21.803772 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:21.819561 2026] [security2:error] [pid 66623:tid 66871] [client 158.158.74.177:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-config.php"] [unique_id "aoSBHdO5rbWdOArH04Ki-AAAAXM"] [Tue Aug 18 12:58:21.869419 2026] [security2:error] [pid 66623:tid 66766] [client 158.23.17.4:32514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ns.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_gAAAQo"] [Tue Aug 18 12:58:21.891002 2026] [security2:error] [pid 66623:tid 66866] [client 213.35.127.232:49391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBHdO5rbWdOArH04KjAAAAAW4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:21.897091 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.217.32:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/shell.php"] [unique_id "aoSBHdO5rbWdOArH04KjAQAAAV0"] [Tue Aug 18 12:58:21.898581 2026] [security2:error] [pid 66623:tid 66826] [client 37.40.227.74:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_wAAAUY"] [Tue Aug 18 12:58:21.898707 2026] [security2:error] [pid 66623:tid 66826] [client 37.40.227.74:57044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHdO5rbWdOArH04Ki_wAAAUY"] [Tue Aug 18 12:58:21.936515 2026] [security2:error] [pid 66623:tid 66822] [client 52.173.121.69:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBHdO5rbWdOArH04KjAwAAAUI"] [Tue Aug 18 12:58:21.940044 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/r.php"] [unique_id "aoSBHdO5rbWdOArH04KjBAAAAYY"] [Tue Aug 18 12:58:21.956559 2026] [security2:error] [pid 66623:tid 66738] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/logins.php"] [unique_id "aoSBHdO5rbWdOArH04KjBQABJmU"] [Tue Aug 18 12:58:21.959123 2026] [security2:error] [pid 66623:tid 66832] [client 20.104.85.180:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/flower.php"] [unique_id "aoSBHdO5rbWdOArH04KjBgAAAUw"] [Tue Aug 18 12:58:21.967398 2026] [security2:error] [pid 66623:tid 66840] [client 172.182.200.96:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.advocaciasc.com"] [uri "/images/security.php"] [unique_id "aoSBHdO5rbWdOArH04KjCAAAAVQ"] [Tue Aug 18 12:58:21.968940 2026] [authz_core:error] [pid 66623:tid 66640] [remote 57.141.22.16:28110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:21.969200 2026] [authz_core:error] [pid 66623:tid 66640] [remote 57.141.22.16:28110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:21.982601 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nf.php"] [unique_id "aoSBHdO5rbWdOArH04KjCQABO0A"] [Tue Aug 18 12:58:22.073576 2026] [security2:error] [pid 66623:tid 66821] [client 4.232.151.198:5301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/new.php"] [unique_id "aoSBHtO5rbWdOArH04KjDQAAAUE"] [Tue Aug 18 12:58:22.085711 2026] [security2:error] [pid 66623:tid 66863] [client 74.248.18.37:7743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSBHtO5rbWdOArH04KjDgAAAWs"] [Tue Aug 18 12:58:22.101190 2026] [security2:error] [pid 66623:tid 66893] [client 20.118.172.148:50086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBHtO5rbWdOArH04KjEAAAAYk"] [Tue Aug 18 12:58:22.104171 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:22.104448 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:22.137032 2026] [security2:error] [pid 66623:tid 66747] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/mailer.php"] [unique_id "aoSBHtO5rbWdOArH04KjEwABOW4"] [Tue Aug 18 12:58:22.139556 2026] [security2:error] [pid 66623:tid 66874] [client 20.119.58.187:11866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa-rex2.php7"] [unique_id "aoSBHtO5rbWdOArH04KjFAAAAXY"] [Tue Aug 18 12:58:22.150482 2026] [security2:error] [pid 66623:tid 66706] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.github/.env"] [unique_id "aoSBHtO5rbWdOArH04KjFgABQEU"] [Tue Aug 18 12:58:22.184842 2026] [security2:error] [pid 66623:tid 66782] [client 68.155.155.199:14209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/update/da222.php"] [unique_id "aoSBHtO5rbWdOArH04KjGQAAARo"] [Tue Aug 18 12:58:22.193980 2026] [security2:error] [pid 66623:tid 66888] [client 20.100.185.105:6769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/83064.php"] [unique_id "aoSBHtO5rbWdOArH04KjGgAAAYQ"] [Tue Aug 18 12:58:22.194754 2026] [security2:error] [pid 66623:tid 66778] [client 20.104.85.180:19765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBHtO5rbWdOArH04KjGwAAARY"] [Tue Aug 18 12:58:22.249062 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.85:32532] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:22.249372 2026] [authz_core:error] [pid 66623:tid 66721] [remote 57.141.22.85:32532] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:22.249802 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/mac.php"] [unique_id "aoSBHtO5rbWdOArH04KjHgAAAS4"] [Tue Aug 18 12:58:22.251402 2026] [security2:error] [pid 66623:tid 66713] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xv.php"] [unique_id "aoSBHtO5rbWdOArH04KjHwABZ0w"] [Tue Aug 18 12:58:22.316652 2026] [security2:error] [pid 66623:tid 66637] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/min.php"] [unique_id "aoSBHtO5rbWdOArH04KjIQABLQA"] [Tue Aug 18 12:58:22.329211 2026] [security2:error] [pid 66623:tid 66789] [client 20.79.204.6:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBHtO5rbWdOArH04KjIgAAASE"] [Tue Aug 18 12:58:22.352505 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjIwAAAVg"] [Tue Aug 18 12:58:22.352653 2026] [security2:error] [pid 66623:tid 66844] [client 103.120.71.157:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjIwAAAVg"] [Tue Aug 18 12:58:22.356224 2026] [security2:error] [pid 66623:tid 66780] [client 40.74.65.169:43198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/wsomini.php"] [unique_id "aoSBHtO5rbWdOArH04KjJAAAARg"] [Tue Aug 18 12:58:22.362590 2026] [security2:error] [pid 66623:tid 66852] [client 103.184.169.37:42343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjJQAAAWA"] [Tue Aug 18 12:58:22.362678 2026] [security2:error] [pid 66623:tid 66852] [client 103.184.169.37:42343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBHtO5rbWdOArH04KjJQAAAWA"] [Tue Aug 18 12:58:22.384806 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.217.32:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/setup-config.php"] [unique_id "aoSBHtO5rbWdOArH04KjKgAAATw"] [Tue Aug 18 12:58:22.400219 2026] [security2:error] [pid 66623:tid 66787] [client 172.202.39.151:44603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/admin.php"] [unique_id "aoSBHtO5rbWdOArH04KjLAAAAR8"] [Tue Aug 18 12:58:22.463797 2026] [security2:error] [pid 66623:tid 66835] [client 20.203.138.185:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bes.php"] [unique_id "aoSBHtO5rbWdOArH04KjLQAAAU8"] [Tue Aug 18 12:58:22.474810 2026] [security2:error] [pid 66623:tid 66647] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mx.php"] [unique_id "aoSBHtO5rbWdOArH04KjMAABFQo"] [Tue Aug 18 12:58:22.494238 2026] [security2:error] [pid 66623:tid 66838] [client 20.119.58.187:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aoSBHtO5rbWdOArH04KjMwAAAVI"] [Tue Aug 18 12:58:22.508229 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:22.508567 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:22.521890 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/f35.php"] [unique_id "aoSBHtO5rbWdOArH04KjNgAAAWw"] [Tue Aug 18 12:58:22.546455 2026] [security2:error] [pid 66623:tid 66855] [client 158.23.17.4:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gk.php"] [unique_id "aoSBHtO5rbWdOArH04KjNwAAAWM"] [Tue Aug 18 12:58:22.555067 2026] [security2:error] [pid 66623:tid 66865] [client 20.104.85.180:31236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/13.php"] [unique_id "aoSBHtO5rbWdOArH04KjOAAAAW0"] [Tue Aug 18 12:58:22.601111 2026] [authz_core:error] [pid 66623:tid 66648] [remote 136.110.27.48:37542] AH01630: client denied by server configuration: /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/.htpasswd [Tue Aug 18 12:58:22.632123 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:7705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/radio.php"] [unique_id "aoSBHtO5rbWdOArH04KjPQAAAYg"] [Tue Aug 18 12:58:22.650572 2026] [security2:error] [pid 66623:tid 66869] [client 20.48.236.86:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/19.php"] [unique_id "aoSBHtO5rbWdOArH04KjQAAAAXE"] [Tue Aug 18 12:58:22.659407 2026] [security2:error] [pid 66623:tid 66878] [client 52.173.121.69:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBHtO5rbWdOArH04KjQgAAAXo"] [Tue Aug 18 12:58:22.703490 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/45.php"] [unique_id "aoSBHtO5rbWdOArH04KjRAABDTs"] [Tue Aug 18 12:58:22.710595 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/petz/inc/plugins/wp-links-opml.php"] [unique_id "aoSBHtO5rbWdOArH04KjRgAAAVc"] [Tue Aug 18 12:58:22.760852 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.105:48902] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:22.761113 2026] [authz_core:error] [pid 66623:tid 66707] [remote 57.141.22.105:48902] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:22.768873 2026] [security2:error] [pid 66623:tid 66684] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/mini.php"] [unique_id "aoSBHtO5rbWdOArH04KjSQABJi8"] [Tue Aug 18 12:58:22.775659 2026] [security2:error] [pid 66623:tid 66815] [client 20.127.136.245:14516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/goods.php"] [unique_id "aoSBHtO5rbWdOArH04KjSgAAATs"] [Tue Aug 18 12:58:22.776561 2026] [security2:error] [pid 66623:tid 66828] [client 74.248.18.37:40994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBHtO5rbWdOArH04KjSwAAAUg"] [Tue Aug 18 12:58:22.812381 2026] [security2:error] [pid 66623:tid 66786] [client 20.100.185.105:21690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSBHtO5rbWdOArH04KjTQAAAR4"] [Tue Aug 18 12:58:22.864973 2026] [security2:error] [pid 66623:tid 66890] [client 20.119.58.187:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "aoSBHtO5rbWdOArH04KjUgAAAYY"] [Tue Aug 18 12:58:22.876476 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.217.32:15566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/t.php"] [unique_id "aoSBHtO5rbWdOArH04KjUwAAAV0"] [Tue Aug 18 12:58:22.878434 2026] [security2:error] [pid 66623:tid 66702] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBHtO5rbWdOArH04KjVAABQUE"] [Tue Aug 18 12:58:22.892908 2026] [security2:error] [pid 66623:tid 66863] [client 20.206.73.37:11907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/zi-936.php"] [unique_id "aoSBHtO5rbWdOArH04KjVgAAAWs"] [Tue Aug 18 12:58:22.903163 2026] [security2:error] [pid 66623:tid 66837] [client 213.35.127.232:49590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBHtO5rbWdOArH04KjVwAAAVE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:22.929107 2026] [security2:error] [pid 66623:tid 66694] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wy.php"] [unique_id "aoSBHtO5rbWdOArH04KjWQABWTk"] [Tue Aug 18 12:58:22.937628 2026] [security2:error] [pid 66623:tid 66822] [client 20.79.204.6:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBHtO5rbWdOArH04KjWwAAAUI"] [Tue Aug 18 12:58:22.942117 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/ops.php"] [unique_id "aoSBHtO5rbWdOArH04KjXAAAAUA"] [Tue Aug 18 12:58:22.958366 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.155.199:6956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/upload.php"] [unique_id "aoSBHtO5rbWdOArH04KjXgAAAWQ"] [Tue Aug 18 12:58:22.960184 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/moddofuns.php"] [unique_id "aoSBHtO5rbWdOArH04KjXwABf2c"] [Tue Aug 18 12:58:22.973834 2026] [security2:error] [pid 66623:tid 66679] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBHtO5rbWdOArH04KjYQABNSo"] [Tue Aug 18 12:58:22.993249 2026] [security2:error] [pid 66623:tid 66825] [client 20.118.172.148:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/gg.php"] [unique_id "aoSBHtO5rbWdOArH04KjZAAAAUU"] [Tue Aug 18 12:58:23.006401 2026] [authz_core:error] [pid 66623:tid 66734] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:23.006662 2026] [authz_core:error] [pid 66623:tid 66734] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:23.065821 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:35747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.openlencois.tur.br.slweb.net.br"] [uri "/vr.php"] [unique_id "aoSBH9O5rbWdOArH04KjaAAAASg"] [Tue Aug 18 12:58:23.067333 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:54979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws60.php"] [unique_id "aoSBH9O5rbWdOArH04KjaQAAAVg"] [Tue Aug 18 12:58:23.080213 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:29030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-login.php"] [unique_id "aoSBH9O5rbWdOArH04KjagAAARg"] [Tue Aug 18 12:58:23.104765 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:27959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cc.php"] [unique_id "aoSBH9O5rbWdOArH04KjbQAAAR8"] [Tue Aug 18 12:58:23.111707 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:34149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wn.php"] [unique_id "aoSBH9O5rbWdOArH04KjbgAAASM"] [Tue Aug 18 12:58:23.141585 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/f.php"] [unique_id "aoSBH9O5rbWdOArH04KjcAABDg4"] [Tue Aug 18 12:58:23.145406 2026] [security2:error] [pid 66623:tid 66638] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSBH9O5rbWdOArH04KjcQABNwE"] [Tue Aug 18 12:58:23.182367 2026] [security2:error] [pid 66623:tid 66859] [client 79.127.164.8:33122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/scriptsacplibinserts.sql"] [unique_id "aoSBH9O5rbWdOArH04KjdAAAAWc"], referer: https://medihub.com.br/scriptsacplibinserts.sql [Tue Aug 18 12:58:23.218112 2026] [security2:error] [pid 66623:tid 66846] [client 20.119.58.187:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjdQAAAVo"] [Tue Aug 18 12:58:23.267009 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:19731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/admin.php"] [unique_id "aoSBH9O5rbWdOArH04KjeQAAATI"] [Tue Aug 18 12:58:23.307535 2026] [authz_core:error] [pid 66623:tid 66714] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:23.307802 2026] [authz_core:error] [pid 66623:tid 66714] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:23.323297 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/moduless.php"] [unique_id "aoSBH9O5rbWdOArH04KjfQABiEo"] [Tue Aug 18 12:58:23.337311 2026] [security2:error] [pid 66623:tid 66785] [client 20.118.172.148:46752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/class.php"] [unique_id "aoSBH9O5rbWdOArH04KjfwAAAR0"] [Tue Aug 18 12:58:23.348784 2026] [security2:error] [pid 66623:tid 66871] [client 68.155.155.199:13477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wk/index.php"] [unique_id "aoSBH9O5rbWdOArH04KjgAAAAXM"] [Tue Aug 18 12:58:23.358450 2026] [security2:error] [pid 66623:tid 66680] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/30.php"] [unique_id "aoSBH9O5rbWdOArH04KjgQABeSs"] [Tue Aug 18 12:58:23.369064 2026] [security2:error] [pid 66623:tid 66855] [client 172.182.217.32:15773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/up.php"] [unique_id "aoSBH9O5rbWdOArH04KjgwAAAWM"] [Tue Aug 18 12:58:23.392037 2026] [security2:error] [pid 66623:tid 66722] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/id_rsa"] [unique_id "aoSBH9O5rbWdOArH04KjhQABRlU"] [Tue Aug 18 12:58:23.433339 2026] [security2:error] [pid 66623:tid 66739] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/id_dsa"] [unique_id "aoSBH9O5rbWdOArH04KjhwABaWY"] [Tue Aug 18 12:58:23.489249 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:24801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBH9O5rbWdOArH04KjigAAAR4"] [Tue Aug 18 12:58:23.493976 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:6841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dxc.php"] [unique_id "aoSBH9O5rbWdOArH04KjiwAAASo"] [Tue Aug 18 12:58:23.528740 2026] [security2:error] [pid 66623:tid 66681] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBH9O5rbWdOArH04KjjgABcCw"] [Tue Aug 18 12:58:23.557307 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.133.132:16868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBH9O5rbWdOArH04KjkAAAAV0"] [Tue Aug 18 12:58:23.560986 2026] [security2:error] [pid 66623:tid 66766] [client 20.79.204.6:11685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBH9O5rbWdOArH04KjkQAAAQo"] [Tue Aug 18 12:58:23.571078 2026] [security2:error] [pid 66623:tid 66794] [client 20.119.58.187:12033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjkgAAASY"] [Tue Aug 18 12:58:23.581096 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:36139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/133.php"] [unique_id "aoSBH9O5rbWdOArH04KjlAAAAWY"] [Tue Aug 18 12:58:23.585386 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pu.php"] [unique_id "aoSBH9O5rbWdOArH04KjlQABdhs"] [Tue Aug 18 12:58:23.589600 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.151.198:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/Cap.php"] [unique_id "aoSBH9O5rbWdOArH04KjlgAAASk"] [Tue Aug 18 12:58:23.595956 2026] [security2:error] [pid 66623:tid 66800] [client 158.158.74.177:2652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBH9O5rbWdOArH04KjlwAAASw"] [Tue Aug 18 12:58:23.598802 2026] [security2:error] [pid 66623:tid 66769] [client 74.248.18.37:7206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSBH9O5rbWdOArH04KjmAAAAQ0"] [Tue Aug 18 12:58:23.612302 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:23.612588 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:23.679733 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/flower.php"] [unique_id "aoSBH9O5rbWdOArH04KjnQAAAX8"] [Tue Aug 18 12:58:23.691846 2026] [security2:error] [pid 66623:tid 66829] [client 149.34.210.141:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjngAAAUk"] [Tue Aug 18 12:58:23.705982 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/new.php"] [unique_id "aoSBH9O5rbWdOArH04KjnwABW3Q"] [Tue Aug 18 12:58:23.724061 2026] [security2:error] [pid 66623:tid 66893] [client 157.20.138.62:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjoAAAAYk"] [Tue Aug 18 12:58:23.724157 2026] [security2:error] [pid 66623:tid 66893] [client 157.20.138.62:51948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjoAAAAYk"] [Tue Aug 18 12:58:23.748691 2026] [security2:error] [pid 66623:tid 66801] [client 5.31.227.224:7809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjogAAAS0"] [Tue Aug 18 12:58:23.748892 2026] [security2:error] [pid 66623:tid 66801] [client 5.31.227.224:7809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjogAAAS0"] [Tue Aug 18 12:58:23.755429 2026] [security2:error] [pid 66623:tid 66774] [client 20.203.138.185:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/olfclass.php"] [unique_id "aoSBH9O5rbWdOArH04KjpAAAARI"] [Tue Aug 18 12:58:23.771483 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ry.php"] [unique_id "aoSBH9O5rbWdOArH04KjpQABPAQ"] [Tue Aug 18 12:58:23.781059 2026] [security2:error] [pid 66623:tid 66852] [client 20.104.85.180:26735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBH9O5rbWdOArH04KjpgAAAWA"] [Tue Aug 18 12:58:23.832367 2026] [autoindex:error] [pid 66623:tid 66811] [client 85.204.70.114:46956] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:23.862883 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.217.32:15552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ultra.php"] [unique_id "aoSBH9O5rbWdOArH04KjrAAAAUU"] [Tue Aug 18 12:58:23.882365 2026] [security2:error] [pid 66623:tid 66652] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSBH9O5rbWdOArH04KjrgABZw8"] [Tue Aug 18 12:58:23.921466 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBH9O5rbWdOArH04KjsAAAASU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:23.926523 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBH9O5rbWdOArH04KjsQAAAVw"] [Tue Aug 18 12:58:23.943167 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pm.php"] [unique_id "aoSBH9O5rbWdOArH04KjswABZVM"] [Tue Aug 18 12:58:23.951068 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.155.199:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-act.php"] [unique_id "aoSBH9O5rbWdOArH04KjtQAAAQw"] [Tue Aug 18 12:58:23.958690 2026] [security2:error] [pid 66623:tid 66829] [client 149.34.210.141:61315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBH9O5rbWdOArH04KjngAAAUk"] [Tue Aug 18 12:58:23.960967 2026] [security2:error] [pid 66623:tid 66795] [client 40.74.65.169:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/coffexium.php"] [unique_id "aoSBH9O5rbWdOArH04KjtgAAASc"] [Tue Aug 18 12:58:23.978244 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/app.php"] [unique_id "aoSBH9O5rbWdOArH04KjuQAAAXE"] [Tue Aug 18 12:58:23.994743 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:11847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aoSBH9O5rbWdOArH04KjugAAARU"] [Tue Aug 18 12:58:24.009218 2026] [security2:error] [pid 66623:tid 66876] [client 20.127.136.245:21472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/php8.php"] [unique_id "aoSBINO5rbWdOArH04KjuwAAAXg"] [Tue Aug 18 12:58:24.059891 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:14576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/public/css.php"] [unique_id "aoSBINO5rbWdOArH04KjvQAAAU8"] [Tue Aug 18 12:58:24.075469 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/num.php"] [unique_id "aoSBINO5rbWdOArH04KjvgABblA"] [Tue Aug 18 12:58:24.085038 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSBINO5rbWdOArH04KjvwAAAUY"] [Tue Aug 18 12:58:24.093165 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.172.148:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/motu.php"] [unique_id "aoSBINO5rbWdOArH04KjwAAAAUc"] [Tue Aug 18 12:58:24.113105 2026] [security2:error] [pid 66623:tid 66865] [client 20.100.185.105:6810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/v4.php"] [unique_id "aoSBINO5rbWdOArH04KjwQAAAW0"] [Tue Aug 18 12:58:24.142168 2026] [security2:error] [pid 66623:tid 66798] [client 20.206.73.37:20728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBINO5rbWdOArH04KjxAAAASo"] [Tue Aug 18 12:58:24.145621 2026] [security2:error] [pid 66623:tid 66709] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/key.pem"] [unique_id "aoSBINO5rbWdOArH04KjxQABVkg"] [Tue Aug 18 12:58:24.145625 2026] [security2:error] [pid 66623:tid 66718] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/privatekey.key"] [unique_id "aoSBINO5rbWdOArH04KjxwABVlE"] [Tue Aug 18 12:58:24.162154 2026] [security2:error] [pid 66623:tid 66862] [client 20.79.204.6:11524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBINO5rbWdOArH04KjyQAAAWo"] [Tue Aug 18 12:58:24.184613 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dr.php"] [unique_id "aoSBINO5rbWdOArH04KjzAABhnU"] [Tue Aug 18 12:58:24.185937 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.51:42726] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:24.186191 2026] [authz_core:error] [pid 66623:tid 66690] [remote 57.141.22.51:42726] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:24.186781 2026] [security2:error] [pid 66623:tid 66878] [client 223.185.37.47:21759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KjzQAAAXo"] [Tue Aug 18 12:58:24.186903 2026] [security2:error] [pid 66623:tid 66878] [client 223.185.37.47:21759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KjzQAAAXo"] [Tue Aug 18 12:58:24.233649 2026] [autoindex:error] [pid 66623:tid 66794] [client 85.204.70.114:46956] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:24.244959 2026] [security2:error] [pid 66623:tid 66830] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBINO5rbWdOArH04Kj0QAAAUo"] [Tue Aug 18 12:58:24.259587 2026] [security2:error] [pid 66623:tid 66660] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php.php"] [unique_id "aoSBINO5rbWdOArH04Kj0wABLBc"] [Tue Aug 18 12:58:24.273894 2026] [security2:error] [pid 66623:tid 66783] [client 158.158.34.183:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.34.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aesexaustores.com.br"] [uri "/log.php"] [unique_id "aoSBINO5rbWdOArH04Kj1AAAARs"] [Tue Aug 18 12:58:24.348776 2026] [security2:error] [pid 66623:tid 66872] [client 4.232.151.198:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "aoSBINO5rbWdOArH04Kj1wAAAXQ"] [Tue Aug 18 12:58:24.351740 2026] [security2:error] [pid 66623:tid 66863] [client 20.119.58.187:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "aoSBINO5rbWdOArH04Kj2AAAAWs"] [Tue Aug 18 12:58:24.369093 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.217.32:15790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/vv.php"] [unique_id "aoSBINO5rbWdOArH04Kj2gAAAQo"] [Tue Aug 18 12:58:24.398817 2026] [security2:error] [pid 66623:tid 66847] [client 20.104.85.180:23993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBINO5rbWdOArH04Kj3QAAAVs"] [Tue Aug 18 12:58:24.410241 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ts.php"] [unique_id "aoSBINO5rbWdOArH04Kj3gABD3k"] [Tue Aug 18 12:58:24.422883 2026] [security2:error] [pid 66623:tid 66796] [client 85.204.70.114:46956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSBINO5rbWdOArH04Kj3wAAASg"] [Tue Aug 18 12:58:24.422946 2026] [security2:error] [pid 66623:tid 66789] [client 20.215.241.237:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/coffexium.php"] [unique_id "aoSBINO5rbWdOArH04Kj4AAAASE"] [Tue Aug 18 12:58:24.430454 2026] [security2:error] [pid 66623:tid 66893] [client 68.155.155.199:6067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBINO5rbWdOArH04Kj4QAAAYk"] [Tue Aug 18 12:58:24.441881 2026] [security2:error] [pid 66623:tid 66663] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php/eval-stdin.php"] [unique_id "aoSBINO5rbWdOArH04Kj4gABLRo"] [Tue Aug 18 12:58:24.477529 2026] [security2:error] [pid 66623:tid 66846] [client 178.153.171.161:20542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04Kj5QAAAVo"] [Tue Aug 18 12:58:24.477633 2026] [security2:error] [pid 66623:tid 66846] [client 178.153.171.161:20542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04Kj5QAAAVo"] [Tue Aug 18 12:58:24.485145 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:38326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/87.php"] [unique_id "aoSBINO5rbWdOArH04Kj6AAAASM"] [Tue Aug 18 12:58:24.512917 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:24.513180 2026] [authz_core:error] [pid 66623:tid 66672] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:24.549452 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:24805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBINO5rbWdOArH04Kj9wAAAUU"] [Tue Aug 18 12:58:24.559142 2026] [security2:error] [pid 66623:tid 66889] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/img.php"] [unique_id "aoSBINO5rbWdOArH04Kj-AAAAYU"] [Tue Aug 18 12:58:24.564612 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:20239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBINO5rbWdOArH04Kj-QAAAVw"] [Tue Aug 18 12:58:24.569984 2026] [security2:error] [pid 66623:tid 66857] [client 20.118.172.148:58753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/404.php"] [unique_id "aoSBINO5rbWdOArH04Kj-gAAAWU"] [Tue Aug 18 12:58:24.583192 2026] [security2:error] [pid 66623:tid 66870] [client 74.248.18.37:7207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/red.php"] [unique_id "aoSBINO5rbWdOArH04Kj_AAAAXI"] [Tue Aug 18 12:58:24.593223 2026] [security2:error] [pid 66623:tid 66762] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/53.php"] [unique_id "aoSBINO5rbWdOArH04Kj_gABUH0"] [Tue Aug 18 12:58:24.621337 2026] [security2:error] [pid 66623:tid 66654] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/php8.php"] [unique_id "aoSBINO5rbWdOArH04Kj_wABcRE"] [Tue Aug 18 12:58:24.654497 2026] [security2:error] [pid 66623:tid 66876] [client 20.48.236.86:25955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBINO5rbWdOArH04KkAwAAAXg"] [Tue Aug 18 12:58:24.673384 2026] [security2:error] [pid 66623:tid 66686] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkBQABfTE"] [Tue Aug 18 12:58:24.673597 2026] [security2:error] [pid 66623:tid 66881] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkBQABfTE"] [Tue Aug 18 12:58:24.682939 2026] [security2:error] [pid 66623:tid 66826] [client 172.202.39.151:44560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/public/css.php"] [unique_id "aoSBINO5rbWdOArH04KkBwAAAUY"] [Tue Aug 18 12:58:24.705298 2026] [security2:error] [pid 66623:tid 66829] [client 20.119.58.187:11873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBINO5rbWdOArH04KkCAAAAUk"] [Tue Aug 18 12:58:24.735977 2026] [security2:error] [pid 66623:tid 66811] [client 20.100.185.105:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/error.php"] [unique_id "aoSBINO5rbWdOArH04KkCgAAATc"] [Tue Aug 18 12:58:24.763905 2026] [security2:error] [pid 66623:tid 66793] [client 20.79.204.6:11648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBINO5rbWdOArH04KkCwAAASU"] [Tue Aug 18 12:58:24.777935 2026] [security2:error] [pid 66623:tid 66842] [client 20.203.138.185:44077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wpver.php"] [unique_id "aoSBINO5rbWdOArH04KkDQAAAVY"] [Tue Aug 18 12:58:24.793503 2026] [security2:error] [pid 66623:tid 66665] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lq.php"] [unique_id "aoSBINO5rbWdOArH04KkDwABNhw"] [Tue Aug 18 12:58:24.812818 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBINO5rbWdOArH04KkEQAAATA"] [Tue Aug 18 12:58:24.814866 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:24.815138 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:24.823161 2026] [security2:error] [pid 66623:tid 66890] [client 85.204.70.114:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intersul.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkEgAAAYY"] [Tue Aug 18 12:58:24.833196 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:40969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBINO5rbWdOArH04KkEwAAAQw"] [Tue Aug 18 12:58:24.834161 2026] [security2:error] [pid 66623:tid 66849] [client 20.118.133.132:14126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBINO5rbWdOArH04KkFAAAAV0"] [Tue Aug 18 12:58:24.857396 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/V5.php"] [unique_id "aoSBINO5rbWdOArH04KkFgAAAU0"] [Tue Aug 18 12:58:24.892851 2026] [security2:error] [pid 66623:tid 66799] [client 201.32.74.208:56519] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSBINO5rbWdOArH04KkGAAAASs"] [Tue Aug 18 12:58:24.894338 2026] [security2:error] [pid 66623:tid 66814] [client 68.155.155.199:5695] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSBINO5rbWdOArH04KkGQAAATo"] [Tue Aug 18 12:58:24.900041 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/aa.php"] [unique_id "aoSBINO5rbWdOArH04KkGgAAAVQ"] [Tue Aug 18 12:58:24.908199 2026] [security2:error] [pid 66623:tid 66640] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBINO5rbWdOArH04KkGwABQAM"] [Tue Aug 18 12:58:24.920322 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkIAAAAUo"] [Tue Aug 18 12:58:24.938946 2026] [security2:error] [pid 66623:tid 66795] [client 213.35.127.232:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBINO5rbWdOArH04KkIQAAASc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:24.941166 2026] [security2:error] [pid 66623:tid 66838] [client 20.100.169.31:38653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/default.php"] [unique_id "aoSBINO5rbWdOArH04KkIgAAAVI"] [Tue Aug 18 12:58:24.975780 2026] [security2:error] [pid 66623:tid 66798] [client 4.232.151.198:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/.tmb/dropdown.php"] [unique_id "aoSBINO5rbWdOArH04KkJgAAASo"] [Tue Aug 18 12:58:24.980519 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.200.96:7563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBINO5rbWdOArH04KkJwAAAYk"] [Tue Aug 18 12:58:24.986088 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/you.php"] [unique_id "aoSBINO5rbWdOArH04KkKAABPAs"] [Tue Aug 18 12:58:24.987640 2026] [security2:error] [pid 66623:tid 66767] [client 20.118.172.148:33493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lite.php"] [unique_id "aoSBINO5rbWdOArH04KkKQAAAQs"] [Tue Aug 18 12:58:24.987665 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/01.php"] [unique_id "aoSBINO5rbWdOArH04KkKgAAATE"] [Tue Aug 18 12:58:25.079439 2026] [security2:error] [pid 66623:tid 66778] [client 20.119.58.187:11854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkQwAAARY"] [Tue Aug 18 12:58:25.104576 2026] [security2:error] [pid 66623:tid 66824] [client 158.23.17.4:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zi.php"] [unique_id "aoSBIdO5rbWdOArH04KkRQAAAUQ"] [Tue Aug 18 12:58:25.114669 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.85.180:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBIdO5rbWdOArH04KkRwAAAVM"] [Tue Aug 18 12:58:25.116261 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:25.116526 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:25.128150 2026] [security2:error] [pid 66623:tid 66812] [client 20.250.13.23:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBIdO5rbWdOArH04KkSAAAATg"] [Tue Aug 18 12:58:25.142938 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBIdO5rbWdOArH04KkTAAAAXw"], referer: www.google.com [Tue Aug 18 12:58:25.143106 2026] [security2:error] [pid 66623:tid 66810] [client 132.196.30.78:32069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-plain.php"] [unique_id "aoSBIdO5rbWdOArH04KkTQAAATY"], referer: www.google.com [Tue Aug 18 12:58:25.178240 2026] [security2:error] [pid 66623:tid 66821] [client 20.127.136.245:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/info.php"] [unique_id "aoSBIdO5rbWdOArH04KkUAAAAUE"] [Tue Aug 18 12:58:25.225458 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ez.php"] [unique_id "aoSBIdO5rbWdOArH04KkUgABKQ4"] [Tue Aug 18 12:58:25.245872 2026] [autoindex:error] [pid 66623:tid 66800] [client 85.204.70.114:46970] AH01276: Cannot serve directory /home2/combrazilcoa/intersul.ind.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:25.250432 2026] [security2:error] [pid 66623:tid 66730] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBIdO5rbWdOArH04KkVQABOl0"] [Tue Aug 18 12:58:25.255916 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.89:64074] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:25.256319 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.89:64074] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:25.264166 2026] [security2:error] [pid 66623:tid 66820] [client 172.202.39.151:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBIdO5rbWdOArH04KkVgAAAUA"] [Tue Aug 18 12:58:25.291403 2026] [security2:error] [pid 66623:tid 66830] [client 138.36.100.162:41700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBINO5rbWdOArH04KkIAAAAUo"] [Tue Aug 18 12:58:25.305912 2026] [security2:error] [pid 66623:tid 66803] [client 158.23.17.4:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBIdO5rbWdOArH04KkWgAAAS8"] [Tue Aug 18 12:58:25.319985 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.172.148:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lock360.php"] [unique_id "aoSBIdO5rbWdOArH04KkXAAAAS0"] [Tue Aug 18 12:58:25.348050 2026] [security2:error] [pid 66623:tid 66794] [client 172.182.217.32:15445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-user.php"] [unique_id "aoSBIdO5rbWdOArH04KkZgAAASY"] [Tue Aug 18 12:58:25.357878 2026] [security2:error] [pid 66623:tid 66786] [client 74.248.18.37:7691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/release.php"] [unique_id "aoSBIdO5rbWdOArH04KkagAAAR4"] [Tue Aug 18 12:58:25.359036 2026] [security2:error] [pid 66623:tid 66804] [client 20.100.185.105:6796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/disagrsod.php"] [unique_id "aoSBIdO5rbWdOArH04KkawAAATA"] [Tue Aug 18 12:58:25.367667 2026] [security2:error] [pid 66623:tid 66849] [client 20.79.204.6:11534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBIdO5rbWdOArH04KkbAAAAV0"] [Tue Aug 18 12:58:25.409160 2026] [security2:error] [pid 66623:tid 66760] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/asus.php"] [unique_id "aoSBIdO5rbWdOArH04KkcwABTns"] [Tue Aug 18 12:58:25.427762 2026] [security2:error] [pid 66623:tid 66876] [client 132.196.30.78:32090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/ambjerfi.php"] [unique_id "aoSBIdO5rbWdOArH04KkdQAAAXg"], referer: www.google.com [Tue Aug 18 12:58:25.436240 2026] [security2:error] [pid 66623:tid 66877] [client 20.119.58.187:11863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkdwAAAXk"] [Tue Aug 18 12:58:25.437754 2026] [security2:error] [pid 66623:tid 66835] [client 85.154.68.202:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkeAAAAU8"] [Tue Aug 18 12:58:25.437842 2026] [security2:error] [pid 66623:tid 66835] [client 85.154.68.202:57224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkeAAAAU8"] [Tue Aug 18 12:58:25.495520 2026] [security2:error] [pid 66623:tid 66826] [client 20.48.236.86:2802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/mosty.php"] [unique_id "aoSBIdO5rbWdOArH04KkeQAAAUY"] [Tue Aug 18 12:58:25.547056 2026] [security2:error] [pid 66623:tid 66855] [client 68.155.155.199:5682] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSBIdO5rbWdOArH04KkegAAAWM"] [Tue Aug 18 12:58:25.573882 2026] [security2:error] [pid 66623:tid 66809] [client 132.196.30.78:32075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBIdO5rbWdOArH04KkewAAATU"], referer: www.google.com [Tue Aug 18 12:58:25.582075 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:7733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBIdO5rbWdOArH04KkfAAAASo"] [Tue Aug 18 12:58:25.585655 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/22.php"] [unique_id "aoSBIdO5rbWdOArH04KkfQABQx0"] [Tue Aug 18 12:58:25.605422 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/av.php"] [unique_id "aoSBIdO5rbWdOArH04KkfgAAARE"] [Tue Aug 18 12:58:25.618194 2026] [security2:error] [pid 66623:tid 66880] [client 85.204.70.114:46970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSBIdO5rbWdOArH04KkfwAAAXw"] [Tue Aug 18 12:58:25.620122 2026] [security2:error] [pid 66623:tid 66810] [client 20.104.85.180:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gelay.php"] [unique_id "aoSBIdO5rbWdOArH04KkgAAAATY"] [Tue Aug 18 12:58:25.656952 2026] [security2:error] [pid 66623:tid 66768] [client 20.203.138.185:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/thui.php"] [unique_id "aoSBIdO5rbWdOArH04KkgwAAAQw"] [Tue Aug 18 12:58:25.682995 2026] [security2:error] [pid 66623:tid 66821] [client 20.118.172.148:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSBIdO5rbWdOArH04KkhQAAAUE"] [Tue Aug 18 12:58:25.703404 2026] [security2:error] [pid 66623:tid 66657] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/plugins.php"] [unique_id "aoSBIdO5rbWdOArH04KkhgABURQ"] [Tue Aug 18 12:58:25.722660 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:25.723112 2026] [authz_core:error] [pid 66623:tid 66652] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:25.738911 2026] [security2:error] [pid 66623:tid 66772] [client 40.74.65.169:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/sf.php"] [unique_id "aoSBIdO5rbWdOArH04KkiAAAARA"] [Tue Aug 18 12:58:25.793578 2026] [security2:error] [pid 66623:tid 66793] [client 20.119.58.187:11876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBIdO5rbWdOArH04KkjgAAASU"] [Tue Aug 18 12:58:25.794842 2026] [security2:error] [pid 66623:tid 66726] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zs.php"] [unique_id "aoSBIdO5rbWdOArH04KkjwABOlk"] [Tue Aug 18 12:58:25.833155 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.217.32:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBIdO5rbWdOArH04KkkQAAAWI"] [Tue Aug 18 12:58:25.847154 2026] [security2:error] [pid 66623:tid 66881] [client 4.232.151.198:30016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "aoSBIdO5rbWdOArH04KkkgAAAX0"] [Tue Aug 18 12:58:25.853139 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:24989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBIdO5rbWdOArH04KkkwAAAS8"] [Tue Aug 18 12:58:25.857761 2026] [security2:error] [pid 66623:tid 66833] [client 132.196.30.78:32078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-plain.php"] [unique_id "aoSBIdO5rbWdOArH04KklAAAAU0"], referer: www.google.com [Tue Aug 18 12:58:25.860870 2026] [security2:error] [pid 66623:tid 66771] [client 20.104.85.180:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/lv.php"] [unique_id "aoSBIdO5rbWdOArH04KklQAAAQ8"] [Tue Aug 18 12:58:25.887279 2026] [security2:error] [pid 66623:tid 66736] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/radio.php"] [unique_id "aoSBIdO5rbWdOArH04KklgABLWM"] [Tue Aug 18 12:58:25.914124 2026] [security2:error] [pid 66623:tid 66865] [client 213.202.253.4:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/filefuns.php"] [unique_id "aoSBIdO5rbWdOArH04KkmQAAAW0"], referer: www.google.com [Tue Aug 18 12:58:25.928842 2026] [security2:error] [pid 66623:tid 66816] [client 68.155.155.199:6957] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/maint/"] [unique_id "aoSBIdO5rbWdOArH04KknAAAATw"] [Tue Aug 18 12:58:25.937508 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:18713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBIdO5rbWdOArH04KknQAAAUU"] [Tue Aug 18 12:58:25.953966 2026] [security2:error] [pid 66623:tid 66879] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/media.php"] [unique_id "aoSBIdO5rbWdOArH04KkngAAAXs"] [Tue Aug 18 12:58:25.955136 2026] [security2:error] [pid 66623:tid 66868] [client 213.35.127.232:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBIdO5rbWdOArH04KknwAAAXA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:25.978114 2026] [security2:error] [pid 66623:tid 66800] [client 20.100.185.105:6843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/eNtnKM.php"] [unique_id "aoSBIdO5rbWdOArH04KkogAAASw"] [Tue Aug 18 12:58:25.988787 2026] [autoindex:error] [pid 66623:tid 66832] [client 20.79.204.6:11660] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:26.000049 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iz.php"] [unique_id "aoSBIdO5rbWdOArH04KkowABMUk"] [Tue Aug 18 12:58:26.019855 2026] [security2:error] [pid 66623:tid 66848] [client 85.204.70.114:46984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04KkpQAAAVw"] [Tue Aug 18 12:58:26.019922 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:26.020233 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:26.026972 2026] [security2:error] [pid 66623:tid 66794] [client 20.118.172.148:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBItO5rbWdOArH04KkpgAAASY"] [Tue Aug 18 12:58:26.065978 2026] [security2:error] [pid 66623:tid 66644] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/rem.php"] [unique_id "aoSBItO5rbWdOArH04KkqQABZwc"] [Tue Aug 18 12:58:26.110090 2026] [security2:error] [pid 66623:tid 66813] [client 74.248.18.37:40979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/reop3.php"] [unique_id "aoSBItO5rbWdOArH04KkrgAAATk"] [Tue Aug 18 12:58:26.146226 2026] [security2:error] [pid 66623:tid 66857] [client 20.119.58.187:12079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04KkrwAAAWU"] [Tue Aug 18 12:58:26.192384 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/se.php"] [unique_id "aoSBItO5rbWdOArH04KkswABc20"] [Tue Aug 18 12:58:26.201652 2026] [autoindex:error] [pid 66623:tid 66888] [client 20.79.204.6:11660] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:26.227836 2026] [security2:error] [pid 66623:tid 66663] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBItO5rbWdOArH04KktQABExo"] [Tue Aug 18 12:58:26.248680 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/server.php"] [unique_id "aoSBItO5rbWdOArH04KkuAABYyI"] [Tue Aug 18 12:58:26.283438 2026] [security2:error] [pid 66623:tid 66869] [client 132.196.30.78:32082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/kigpfegm.php"] [unique_id "aoSBItO5rbWdOArH04KkuQAAAXE"], referer: www.google.com [Tue Aug 18 12:58:26.284512 2026] [security2:error] [pid 66623:tid 66811] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/images.php"] [unique_id "aoSBItO5rbWdOArH04KkvgAAATc"] [Tue Aug 18 12:58:26.314180 2026] [security2:error] [pid 66623:tid 66778] [client 201.32.74.208:56527] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSBItO5rbWdOArH04KkwAAAARY"] [Tue Aug 18 12:58:26.326746 2026] [authz_core:error] [pid 66623:tid 66705] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:26.327207 2026] [authz_core:error] [pid 66623:tid 66705] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:26.339341 2026] [security2:error] [pid 66623:tid 66659] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSBItO5rbWdOArH04KkwwABKhY"] [Tue Aug 18 12:58:26.353047 2026] [security2:error] [pid 66623:tid 66823] [client 20.104.85.180:15125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/new.php"] [unique_id "aoSBItO5rbWdOArH04KkxAAAAUM"] [Tue Aug 18 12:58:26.356892 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.217.32:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp.php"] [unique_id "aoSBItO5rbWdOArH04KkxQAAAU8"] [Tue Aug 18 12:58:26.380321 2026] [security2:error] [pid 66623:tid 66716] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vp.php"] [unique_id "aoSBItO5rbWdOArH04KkxgABOE8"] [Tue Aug 18 12:58:26.401544 2026] [security2:error] [pid 66623:tid 66810] [client 20.79.204.6:11660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBItO5rbWdOArH04KkyQAAATY"] [Tue Aug 18 12:58:26.410086 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBItO5rbWdOArH04KkygAAASI"] [Tue Aug 18 12:58:26.415015 2026] [security2:error] [pid 66623:tid 66831] [client 85.204.70.114:46992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04KkzAAAAUs"] [Tue Aug 18 12:58:26.426333 2026] [security2:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/settings.php"] [unique_id "aoSBItO5rbWdOArH04KkzgABd0A"] [Tue Aug 18 12:58:26.466929 2026] [security2:error] [pid 66623:tid 66828] [client 20.48.236.86:25921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/blurbs.php"] [unique_id "aoSBItO5rbWdOArH04Kk0AAAAUg"] [Tue Aug 18 12:58:26.495696 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/network/file.php"] [unique_id "aoSBItO5rbWdOArH04Kk0gAAAUk"] [Tue Aug 18 12:58:26.504096 2026] [security2:error] [pid 66623:tid 66773] [client 20.119.58.187:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/css/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk0wAAARE"] [Tue Aug 18 12:58:26.517228 2026] [security2:error] [pid 66623:tid 66772] [client 68.155.155.199:12375] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/"] [unique_id "aoSBItO5rbWdOArH04Kk1QAAARA"] [Tue Aug 18 12:58:26.524776 2026] [security2:error] [pid 66623:tid 66814] [client 20.118.172.148:46730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.alf.php"] [unique_id "aoSBItO5rbWdOArH04Kk1gAAATo"] [Tue Aug 18 12:58:26.537903 2026] [security2:error] [pid 66623:tid 66820] [client 20.203.138.185:47668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tmpls.php"] [unique_id "aoSBItO5rbWdOArH04Kk1wAAAUA"] [Tue Aug 18 12:58:26.546769 2026] [security2:error] [pid 66623:tid 66882] [client 20.215.241.237:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBItO5rbWdOArH04Kk2AAAAX4"] [Tue Aug 18 12:58:26.593045 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ph.php"] [unique_id "aoSBItO5rbWdOArH04Kk3AABa24"] [Tue Aug 18 12:58:26.593115 2026] [security2:error] [pid 66623:tid 66795] [client 40.74.65.169:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/k.php"] [unique_id "aoSBItO5rbWdOArH04Kk2wAAASc"] [Tue Aug 18 12:58:26.596790 2026] [security2:error] [pid 66623:tid 66880] [client 20.100.185.105:43130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/buy.php"] [unique_id "aoSBItO5rbWdOArH04Kk3QAAAXw"] [Tue Aug 18 12:58:26.609412 2026] [security2:error] [pid 66623:tid 66706] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/sf.php"] [unique_id "aoSBItO5rbWdOArH04Kk3gABSkU"] [Tue Aug 18 12:58:26.622769 2026] [security2:error] [pid 66623:tid 66833] [client 158.23.17.4:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/92.php"] [unique_id "aoSBItO5rbWdOArH04Kk4AAAAU0"] [Tue Aug 18 12:58:26.639971 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/admin.php"] [unique_id "aoSBItO5rbWdOArH04Kk4gAAAVU"] [Tue Aug 18 12:58:26.648698 2026] [security2:error] [pid 66623:tid 66838] [client 192.141.172.134:50851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk4wAAAVI"] [Tue Aug 18 12:58:26.648818 2026] [security2:error] [pid 66623:tid 66838] [client 192.141.172.134:50851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk4wAAAVI"] [Tue Aug 18 12:58:26.674794 2026] [security2:error] [pid 66623:tid 66840] [client 74.248.18.37:7732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBItO5rbWdOArH04Kk5QAAAVQ"] [Tue Aug 18 12:58:26.779187 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/s.php"] [unique_id "aoSBItO5rbWdOArH04Kk6QABJks"] [Tue Aug 18 12:58:26.780822 2026] [security2:error] [pid 66623:tid 66665] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/laravel/.env"] [unique_id "aoSBItO5rbWdOArH04Kk6wABQhw"] [Tue Aug 18 12:58:26.817897 2026] [security2:error] [pid 66623:tid 66832] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoSBItO5rbWdOArH04Kk7wABTAo"], referer: https://graices.com.br/ [Tue Aug 18 12:58:26.824138 2026] [security2:error] [pid 66623:tid 66786] [client 85.204.70.114:47006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSBItO5rbWdOArH04Kk8QAAAR4"] [Tue Aug 18 12:58:26.836052 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/size.php"] [unique_id "aoSBItO5rbWdOArH04Kk8wABXUw"] [Tue Aug 18 12:58:26.843579 2026] [security2:error] [pid 66623:tid 66761] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config/.env.php"] [unique_id "aoSBItO5rbWdOArH04Kk9QABaHw"] [Tue Aug 18 12:58:26.844765 2026] [security2:error] [pid 66623:tid 66725] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/core/.env"] [unique_id "aoSBItO5rbWdOArH04Kk9AABaFg"] [Tue Aug 18 12:58:26.850274 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/worksec.php"] [unique_id "aoSBItO5rbWdOArH04Kk9gAAARQ"] [Tue Aug 18 12:58:26.858711 2026] [security2:error] [pid 66623:tid 66780] [client 20.119.58.187:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSBItO5rbWdOArH04Kk-AAAARg"] [Tue Aug 18 12:58:26.869154 2026] [security2:error] [pid 66623:tid 66723] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBItO5rbWdOArH04Kk-gABZVY"] [Tue Aug 18 12:58:26.888928 2026] [security2:error] [pid 66623:tid 66815] [client 161.118.247.229:51558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSBItO5rbWdOArH04Kk_AAAATs"] [Tue Aug 18 12:58:26.892062 2026] [security2:error] [pid 66623:tid 66877] [client 52.173.121.69:24816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBItO5rbWdOArH04Kk_QAAAXk"] [Tue Aug 18 12:58:26.928779 2026] [security2:error] [pid 66623:tid 66801] [client 74.248.18.37:41015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/robots.php"] [unique_id "aoSBItO5rbWdOArH04KlAAAAAS0"] [Tue Aug 18 12:58:26.937952 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:26.938208 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:26.956774 2026] [security2:error] [pid 66623:tid 66853] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/222.php"] [unique_id "aoSBItO5rbWdOArH04KlAgAAAWE"] [Tue Aug 18 12:58:26.964315 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uo.php"] [unique_id "aoSBItO5rbWdOArH04KlAwABcRM"] [Tue Aug 18 12:58:26.970410 2026] [security2:error] [pid 66623:tid 66811] [client 172.202.39.151:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBItO5rbWdOArH04KlBAAAATc"] [Tue Aug 18 12:58:26.991997 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBItO5rbWdOArH04KlBQAAAVg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:27.005503 2026] [security2:error] [pid 66623:tid 66781] [client 20.79.204.6:11531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBI9O5rbWdOArH04KlBgAAARk"] [Tue Aug 18 12:58:27.005545 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlBwAAARY"] [Tue Aug 18 12:58:27.012826 2026] [security2:error] [pid 66623:tid 66721] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/staging/wp-content/test.php"] [unique_id "aoSBI9O5rbWdOArH04KlCAABQ1Q"] [Tue Aug 18 12:58:27.024751 2026] [security2:error] [pid 66623:tid 66812] [client 68.155.155.199:1550] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/"] [unique_id "aoSBI9O5rbWdOArH04KlCgAAATg"] [Tue Aug 18 12:58:27.054137 2026] [security2:error] [pid 66623:tid 66890] [client 20.118.133.132:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBI9O5rbWdOArH04KlCwAAAYY"] [Tue Aug 18 12:58:27.104892 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.85.180:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBI9O5rbWdOArH04KlFAAAASk"] [Tue Aug 18 12:58:27.124340 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/222.php"] [unique_id "aoSBI9O5rbWdOArH04KlFgAAARs"] [Tue Aug 18 12:58:27.124635 2026] [security2:error] [pid 66623:tid 66871] [client 4.232.151.198:30052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/upgrade/alfa.php"] [unique_id "aoSBI9O5rbWdOArH04KlFwAAAXM"] [Tue Aug 18 12:58:27.188849 2026] [security2:error] [pid 66623:tid 66643] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/storage/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlGgABJwY"] [Tue Aug 18 12:58:27.206950 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kx.php"] [unique_id "aoSBI9O5rbWdOArH04KlHgABfT0"] [Tue Aug 18 12:58:27.213281 2026] [security2:error] [pid 66623:tid 66828] [client 20.119.58.187:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlIAAAAUg"] [Tue Aug 18 12:58:27.218186 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:20622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ae.php"] [unique_id "aoSBI9O5rbWdOArH04KlIgAAASo"] [Tue Aug 18 12:58:27.222927 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:27.223465 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:27.239807 2026] [security2:error] [pid 66623:tid 66833] [client 85.204.70.114:51398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSBI9O5rbWdOArH04KlIwAAAU0"] [Tue Aug 18 12:58:27.264306 2026] [security2:error] [pid 66623:tid 66821] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSBI9O5rbWdOArH04KlHwABQS0"], referer: https://graices.com.br/ [Tue Aug 18 12:58:27.268865 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mac.php"] [unique_id "aoSBI9O5rbWdOArH04KlJQAAAVQ"] [Tue Aug 18 12:58:27.276826 2026] [security2:error] [pid 66623:tid 66816] [client 158.23.17.4:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBI9O5rbWdOArH04KlJgAAATw"] [Tue Aug 18 12:58:27.290105 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jm.php"] [unique_id "aoSBI9O5rbWdOArH04KlJwAAASM"] [Tue Aug 18 12:58:27.352198 2026] [security2:error] [pid 66623:tid 66802] [client 172.182.217.32:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBI9O5rbWdOArH04KlKwAAAS4"] [Tue Aug 18 12:58:27.356432 2026] [security2:error] [pid 66623:tid 66676] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBI9O5rbWdOArH04KlLQABKCc"] [Tue Aug 18 12:58:27.366337 2026] [security2:error] [pid 66623:tid 66819] [client 20.118.172.148:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlLgAAAT8"] [Tue Aug 18 12:58:27.378177 2026] [security2:error] [pid 66623:tid 66678] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/storage/min.php"] [unique_id "aoSBI9O5rbWdOArH04KlLwABISk"] [Tue Aug 18 12:58:27.384247 2026] [security2:error] [pid 66623:tid 66651] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/public/.env"] [unique_id "aoSBI9O5rbWdOArH04KlMgABJg4"] [Tue Aug 18 12:58:27.384538 2026] [security2:error] [pid 66623:tid 66749] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/.env.swp"] [unique_id "aoSBI9O5rbWdOArH04KlMQABJnA"] [Tue Aug 18 12:58:27.387956 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/va.php"] [unique_id "aoSBI9O5rbWdOArH04KlNAABQkY"] [Tue Aug 18 12:58:27.436114 2026] [security2:error] [pid 66623:tid 66763] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/web/.env"] [unique_id "aoSBI9O5rbWdOArH04KlNQABHn4"] [Tue Aug 18 12:58:27.449459 2026] [security2:error] [pid 66623:tid 66727] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/config.php.bak"] [unique_id "aoSBI9O5rbWdOArH04KlNgABaFo"] [Tue Aug 18 12:58:27.495426 2026] [security2:error] [pid 66623:tid 66867] [client 20.48.236.86:25983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bajah.php"] [unique_id "aoSBI9O5rbWdOArH04KlOAAAAW8"] [Tue Aug 18 12:58:27.500467 2026] [security2:error] [pid 66623:tid 66852] [client 20.203.138.185:10789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nzv.php"] [unique_id "aoSBI9O5rbWdOArH04KlOgAAAWA"] [Tue Aug 18 12:58:27.514693 2026] [security2:error] [pid 66623:tid 66892] [client 74.248.18.37:7197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlOwAAAYg"] [Tue Aug 18 12:58:27.524913 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:27.525163 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:27.550189 2026] [security2:error] [pid 66623:tid 66877] [client 68.155.155.199:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBI9O5rbWdOArH04KlPgAAAXk"] [Tue Aug 18 12:58:27.551547 2026] [security2:error] [pid 66623:tid 66793] [client 40.74.65.169:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/82.php"] [unique_id "aoSBI9O5rbWdOArH04KlPwAAASU"] [Tue Aug 18 12:58:27.554693 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:27932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/chosen.php"] [unique_id "aoSBI9O5rbWdOArH04KlQAAAAYQ"] [Tue Aug 18 12:58:27.568861 2026] [security2:error] [pid 66623:tid 66849] [client 20.119.58.187:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlQwAAAV0"] [Tue Aug 18 12:58:27.570585 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:29028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/i.php"] [unique_id "aoSBI9O5rbWdOArH04KlRAAAAQ8"] [Tue Aug 18 12:58:27.624995 2026] [autoindex:error] [pid 66623:tid 66825] [client 20.79.204.6:11693] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:27.634161 2026] [security2:error] [pid 66623:tid 66869] [client 85.204.70.114:51402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSBI9O5rbWdOArH04KlSgAAAXE"] [Tue Aug 18 12:58:27.648091 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fo.php"] [unique_id "aoSBI9O5rbWdOArH04KlSwABNSM"] [Tue Aug 18 12:58:27.651972 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:25016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBI9O5rbWdOArH04KlTQAAAVg"] [Tue Aug 18 12:58:27.652044 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/root.php"] [unique_id "aoSBI9O5rbWdOArH04KlTgAAATA"] [Tue Aug 18 12:58:27.776308 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.151.198:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/xmlrpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlVAAAAWQ"] [Tue Aug 18 12:58:27.808907 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:1592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/about.php"] [unique_id "aoSBI9O5rbWdOArH04KlVwAAARs"] [Tue Aug 18 12:58:27.837066 2026] [autoindex:error] [pid 66623:tid 66814] [client 20.79.204.6:11693] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:27.837081 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/test.php"] [unique_id "aoSBI9O5rbWdOArH04KlXAABJx8"] [Tue Aug 18 12:58:27.842286 2026] [security2:error] [pid 66623:tid 66834] [client 172.182.217.32:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBI9O5rbWdOArH04KlXgAAAU4"] [Tue Aug 18 12:58:27.847007 2026] [security2:error] [pid 66623:tid 66853] [client 20.100.185.105:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/raf.php"] [unique_id "aoSBI9O5rbWdOArH04KlXwAAAWE"] [Tue Aug 18 12:58:27.856554 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/loading.php"] [unique_id "aoSBI9O5rbWdOArH04KlYAABgiA"] [Tue Aug 18 12:58:27.926651 2026] [security2:error] [pid 66623:tid 66842] [client 20.119.58.187:11858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "aoSBI9O5rbWdOArH04KlaQAAAVY"] [Tue Aug 18 12:58:27.935777 2026] [security2:error] [pid 66623:tid 66838] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ops.php"] [unique_id "aoSBI9O5rbWdOArH04KlawAAAVI"] [Tue Aug 18 12:58:27.941878 2026] [security2:error] [pid 66623:tid 66883] [client 161.118.247.229:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.247.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSBI9O5rbWdOArH04KlbAAAAX8"] [Tue Aug 18 12:58:27.945864 2026] [security2:error] [pid 66623:tid 66841] [client 158.23.17.4:34157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wj.php"] [unique_id "aoSBI9O5rbWdOArH04KlbQAAAVU"] [Tue Aug 18 12:58:27.949271 2026] [security2:error] [pid 66623:tid 66879] [client 20.203.183.135:45463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/adminner.php"] [unique_id "aoSBI9O5rbWdOArH04KlbgAAAXs"] [Tue Aug 18 12:58:28.002736 2026] [security2:error] [pid 66623:tid 66779] [client 3.20.63.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSBI9O5rbWdOArH04KlaAABFzc"], referer: https://1ba.com.br/ [Tue Aug 18 12:58:28.014028 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/test1.php"] [unique_id "aoSBJNO5rbWdOArH04KlbwABDjQ"] [Tue Aug 18 12:58:28.020526 2026] [security2:error] [pid 66623:tid 66823] [client 213.35.127.232:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBJNO5rbWdOArH04KlcQAAAUM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:28.038084 2026] [security2:error] [pid 66623:tid 66846] [client 20.79.204.6:11693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlcgAAAVo"] [Tue Aug 18 12:58:28.056367 2026] [security2:error] [pid 66623:tid 66819] [client 85.204.70.114:51416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJNO5rbWdOArH04KlcwAAAT8"] [Tue Aug 18 12:58:28.057649 2026] [security2:error] [pid 66623:tid 66806] [client 20.118.172.148:53063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSBJNO5rbWdOArH04KldAAAATI"] [Tue Aug 18 12:58:28.059096 2026] [security2:error] [pid 66623:tid 66794] [client 20.104.85.180:31285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/info.php"] [unique_id "aoSBJNO5rbWdOArH04KldQAAASY"] [Tue Aug 18 12:58:28.059221 2026] [security2:error] [pid 66623:tid 66788] [client 158.158.74.177:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content.php"] [unique_id "aoSBJNO5rbWdOArH04KldgAAASA"] [Tue Aug 18 12:58:28.111225 2026] [security2:error] [pid 66623:tid 66858] [client 172.182.200.96:7649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBJNO5rbWdOArH04KlegAAAWY"] [Tue Aug 18 12:58:28.114971 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ke.php"] [unique_id "aoSBJNO5rbWdOArH04KlfAABbwE"] [Tue Aug 18 12:58:28.194957 2026] [security2:error] [pid 66623:tid 66641] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/thoms.php"] [unique_id "aoSBJNO5rbWdOArH04KlgAABMwQ"] [Tue Aug 18 12:58:28.212339 2026] [security2:error] [pid 66623:tid 66864] [client 5.161.117.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoSBItO5rbWdOArH04Kk8AABbBU"], referer: https://alsconsultoria.com.br/ [Tue Aug 18 12:58:28.279336 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:11878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlhAAAAXg"] [Tue Aug 18 12:58:28.286641 2026] [security2:error] [pid 66623:tid 66827] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/8.php"] [unique_id "aoSBJNO5rbWdOArH04KlhQAAAUc"] [Tue Aug 18 12:58:28.328701 2026] [security2:error] [pid 66623:tid 66852] [client 74.248.18.37:7182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/rrr.php"] [unique_id "aoSBJNO5rbWdOArH04KlhwAAAWA"] [Tue Aug 18 12:58:28.331090 2026] [security2:error] [pid 66623:tid 66776] [client 172.182.217.32:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBJNO5rbWdOArH04KliAAAARQ"] [Tue Aug 18 12:58:28.344219 2026] [security2:error] [pid 66623:tid 66810] [client 40.74.65.169:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/dex.php"] [unique_id "aoSBJNO5rbWdOArH04KliQAAATY"] [Tue Aug 18 12:58:28.371550 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/tiny.php"] [unique_id "aoSBJNO5rbWdOArH04KliwABUFA"] [Tue Aug 18 12:58:28.377662 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nh.php"] [unique_id "aoSBJNO5rbWdOArH04KljAABYlM"] [Tue Aug 18 12:58:28.384610 2026] [security2:error] [pid 66623:tid 66856] [client 20.203.138.185:47229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/error1.php"] [unique_id "aoSBJNO5rbWdOArH04KljgAAAWQ"] [Tue Aug 18 12:58:28.395153 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:12063] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/uploads/"] [unique_id "aoSBJNO5rbWdOArH04KlkAAAARE"] [Tue Aug 18 12:58:28.407491 2026] [security2:error] [pid 66623:tid 66783] [client 20.206.73.37:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/php.php"] [unique_id "aoSBJNO5rbWdOArH04KlkQAAARs"] [Tue Aug 18 12:58:28.427632 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:28.427918 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:28.434879 2026] [security2:error] [pid 66623:tid 66880] [client 74.248.18.37:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlkwAAAXw"] [Tue Aug 18 12:58:28.440739 2026] [autoindex:error] [pid 66623:tid 66829] [client 169.58.72.248:63638] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:28.442891 2026] [security2:error] [pid 66623:tid 66814] [client 85.204.70.114:51418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJNO5rbWdOArH04KllAAAATo"] [Tue Aug 18 12:58:28.449966 2026] [security2:error] [pid 66623:tid 66885] [client 4.232.151.198:30027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/.tmb/cloud.php"] [unique_id "aoSBJNO5rbWdOArH04KllQAAAYE"] [Tue Aug 18 12:58:28.466356 2026] [security2:error] [pid 66623:tid 66801] [client 20.100.185.105:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cloud.php"] [unique_id "aoSBJNO5rbWdOArH04KlmAAAAS0"] [Tue Aug 18 12:58:28.567060 2026] [security2:error] [pid 66623:tid 66697] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/tool.php"] [unique_id "aoSBJNO5rbWdOArH04KlnAABTTw"] [Tue Aug 18 12:58:28.604544 2026] [security2:error] [pid 66623:tid 66821] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/biufile.php"] [unique_id "aoSBJNO5rbWdOArH04KlogAAAUE"] [Tue Aug 18 12:58:28.612975 2026] [security2:error] [pid 66623:tid 66840] [client 161.118.247.229:52386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSBJNO5rbWdOArH04KlowAAAVQ"] [Tue Aug 18 12:58:28.613282 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/oo.php"] [unique_id "aoSBJNO5rbWdOArH04KlpAABVSg"] [Tue Aug 18 12:58:28.631155 2026] [security2:error] [pid 66623:tid 66816] [client 20.118.172.148:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSBJNO5rbWdOArH04KlpgAAATw"] [Tue Aug 18 12:58:28.635830 2026] [security2:error] [pid 66623:tid 66872] [client 20.119.58.187:12030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlpwAAAXQ"] [Tue Aug 18 12:58:28.651701 2026] [security2:error] [pid 66623:tid 66795] [client 20.79.204.6:11676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBJNO5rbWdOArH04KlqAAAASc"] [Tue Aug 18 12:58:28.733088 2026] [security2:error] [pid 66623:tid 66806] [client 158.23.17.4:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/74.php"] [unique_id "aoSBJNO5rbWdOArH04KlrAAAATI"] [Tue Aug 18 12:58:28.742711 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/top.php"] [unique_id "aoSBJNO5rbWdOArH04KlrQABJh4"] [Tue Aug 18 12:58:28.779207 2026] [security2:error] [pid 66623:tid 66766] [client 79.127.164.8:40836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/server.bak"] [unique_id "aoSBJNO5rbWdOArH04KlsQAAAQo"], referer: https://medihub.com.br/server.bak [Tue Aug 18 12:58:28.800312 2026] [security2:error] [pid 66623:tid 66659] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ja.php"] [unique_id "aoSBJNO5rbWdOArH04KlswABQBY"] [Tue Aug 18 12:58:28.805787 2026] [security2:error] [pid 66623:tid 66875] [client 20.118.133.132:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/sky.php"] [unique_id "aoSBJNO5rbWdOArH04KltQAAAXc"] [Tue Aug 18 12:58:28.917303 2026] [security2:error] [pid 66623:tid 66750] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/txets.php"] [unique_id "aoSBJNO5rbWdOArH04KlvAABbHE"] [Tue Aug 18 12:58:28.917953 2026] [security2:error] [pid 66623:tid 66793] [client 20.127.136.245:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/chosen.php"] [unique_id "aoSBJNO5rbWdOArH04KlvQAAASU"] [Tue Aug 18 12:58:28.920866 2026] [security2:error] [pid 66623:tid 66865] [client 68.155.155.199:12691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBJNO5rbWdOArH04KlvgAAAW0"] [Tue Aug 18 12:58:28.922611 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/coffexium.php"] [unique_id "aoSBJNO5rbWdOArH04KlvwAAAQ8"] [Tue Aug 18 12:58:28.946407 2026] [authz_core:error] [pid 66623:tid 66738] [remote 57.141.22.8:43226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:28.946663 2026] [authz_core:error] [pid 66623:tid 66738] [remote 57.141.22.8:43226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:28.966192 2026] [security2:error] [pid 66623:tid 66778] [client 196.12.128.158:58443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlxgAAARY"] [Tue Aug 18 12:58:28.966329 2026] [security2:error] [pid 66623:tid 66778] [client 196.12.128.158:58443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlxgAAARY"] [Tue Aug 18 12:58:28.971428 2026] [security2:error] [pid 66623:tid 66703] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xx.php"] [unique_id "aoSBJNO5rbWdOArH04KlxwABcUI"] [Tue Aug 18 12:58:28.971936 2026] [security2:error] [pid 66623:tid 66809] [client 52.173.121.69:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBJNO5rbWdOArH04KlyAAAATU"] [Tue Aug 18 12:58:28.982129 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBJNO5rbWdOArH04KlyQAAAR0"] [Tue Aug 18 12:58:28.990100 2026] [security2:error] [pid 66623:tid 66782] [client 20.119.58.187:12015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "aoSBJNO5rbWdOArH04KlygAAARo"] [Tue Aug 18 12:58:29.004512 2026] [security2:error] [pid 66623:tid 66887] [client 20.118.172.148:50073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSBJdO5rbWdOArH04KlzwAAAYM"] [Tue Aug 18 12:58:29.014685 2026] [security2:error] [pid 66623:tid 66776] [client 85.204.70.114:51420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04Kl0AAAARQ"] [Tue Aug 18 12:58:29.031458 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:29.031740 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:29.042370 2026] [security2:error] [pid 66623:tid 66882] [client 213.35.127.232:50897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1QAAAX4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:29.084583 2026] [security2:error] [pid 66623:tid 66857] [client 20.100.185.105:43107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cookie.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1gAAAWU"] [Tue Aug 18 12:58:29.085475 2026] [security2:error] [pid 66623:tid 66780] [client 4.232.151.198:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "aoSBJdO5rbWdOArH04Kl1wAAARg"] [Tue Aug 18 12:58:29.100364 2026] [security2:error] [pid 66623:tid 66884] [client 74.248.18.37:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/s.php"] [unique_id "aoSBJdO5rbWdOArH04Kl2QAAAYA"] [Tue Aug 18 12:58:29.104145 2026] [security2:error] [pid 66623:tid 66662] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/virus.php"] [unique_id "aoSBJdO5rbWdOArH04Kl2wABSRk"] [Tue Aug 18 12:58:29.162043 2026] [security2:error] [pid 66623:tid 66654] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/conn-test.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4AABShE"] [Tue Aug 18 12:58:29.177937 2026] [security2:error] [pid 66623:tid 66828] [client 20.203.138.185:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/155.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4QAAAUg"] [Tue Aug 18 12:58:29.187710 2026] [security2:error] [pid 66623:tid 66833] [client 172.182.217.32:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/ws.php"] [unique_id "aoSBJdO5rbWdOArH04Kl4gAAAU0"] [Tue Aug 18 12:58:29.214384 2026] [security2:error] [pid 66623:tid 66883] [client 20.250.13.23:1834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5AAAAX8"] [Tue Aug 18 12:58:29.231180 2026] [security2:error] [pid 66623:tid 66841] [client 40.74.65.169:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/puc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5gAAAVU"] [Tue Aug 18 12:58:29.234508 2026] [security2:error] [pid 66623:tid 66799] [client 157.51.166.53:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5wAAASs"] [Tue Aug 18 12:58:29.234588 2026] [security2:error] [pid 66623:tid 66799] [client 157.51.166.53:52840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl5wAAASs"] [Tue Aug 18 12:58:29.275835 2026] [autoindex:error] [pid 66623:tid 66836] [client 20.79.204.6:12245] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:29.281501 2026] [security2:error] [pid 66623:tid 66725] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/we.php"] [unique_id "aoSBJdO5rbWdOArH04Kl6gABJ1g"] [Tue Aug 18 12:58:29.291910 2026] [security2:error] [pid 66623:tid 66846] [client 161.118.247.229:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.247.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hsinfinity.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSBJdO5rbWdOArH04Kl6wAAAVo"] [Tue Aug 18 12:58:29.343110 2026] [security2:error] [pid 66623:tid 66773] [client 74.248.18.37:7715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBJdO5rbWdOArH04Kl8wAAARE"] [Tue Aug 18 12:58:29.344586 2026] [security2:error] [pid 66623:tid 66840] [client 20.119.58.187:12539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9AAAAVQ"] [Tue Aug 18 12:58:29.370351 2026] [security2:error] [pid 66623:tid 66822] [client 158.158.74.177:22734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9gAAAUI"] [Tue Aug 18 12:58:29.375926 2026] [security2:error] [pid 66623:tid 66786] [client 20.118.172.148:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/xmr.php"] [unique_id "aoSBJdO5rbWdOArH04Kl9wAAAR4"] [Tue Aug 18 12:58:29.377703 2026] [security2:error] [pid 66623:tid 66721] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fg.php"] [unique_id "aoSBJdO5rbWdOArH04Kl-AABClQ"] [Tue Aug 18 12:58:29.407856 2026] [security2:error] [pid 66623:tid 66860] [client 85.204.70.114:51430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04Kl_AAAAWg"] [Tue Aug 18 12:58:29.460264 2026] [security2:error] [pid 66623:tid 66868] [client 158.23.17.4:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/av.php"] [unique_id "aoSBJdO5rbWdOArH04Kl_wAAAXA"] [Tue Aug 18 12:58:29.473672 2026] [security2:error] [pid 66623:tid 66881] [client 68.155.155.199:4327] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/"] [unique_id "aoSBJdO5rbWdOArH04KmAAAAAX0"] [Tue Aug 18 12:58:29.474737 2026] [security2:error] [pid 66623:tid 66807] [client 20.100.169.31:29054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBJdO5rbWdOArH04KmAQAAATM"] [Tue Aug 18 12:58:29.477867 2026] [security2:error] [pid 66623:tid 66864] [client 20.79.204.6:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBJdO5rbWdOArH04KmBAAAAWw"] [Tue Aug 18 12:58:29.521245 2026] [security2:error] [pid 66623:tid 66815] [client 20.250.13.23:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/404.php"] [unique_id "aoSBJdO5rbWdOArH04KmBQAAATs"] [Tue Aug 18 12:58:29.550021 2026] [security2:error] [pid 66623:tid 66876] [client 172.202.39.151:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/admin.php"] [unique_id "aoSBJdO5rbWdOArH04KmBwAAAXg"] [Tue Aug 18 12:58:29.633913 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:29.634258 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:29.645167 2026] [security2:error] [pid 66623:tid 66743] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ve.php"] [unique_id "aoSBJdO5rbWdOArH04KmDAABfmo"] [Tue Aug 18 12:58:29.678139 2026] [security2:error] [pid 66623:tid 66790] [client 114.5.214.109:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEAAAASI"] [Tue Aug 18 12:58:29.688704 2026] [security2:error] [pid 66623:tid 66790] [client 114.5.214.109:50409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEAAAASI"] [Tue Aug 18 12:58:29.699792 2026] [security2:error] [pid 66623:tid 66782] [client 20.119.58.187:11848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmEwAAARo"] [Tue Aug 18 12:58:29.701875 2026] [security2:error] [pid 66623:tid 66793] [client 20.100.185.105:21670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/aleXus.php"] [unique_id "aoSBJdO5rbWdOArH04KmFAAAASU"] [Tue Aug 18 12:58:29.710950 2026] [security2:error] [pid 66623:tid 66825] [client 172.182.217.32:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/wsa.php"] [unique_id "aoSBJdO5rbWdOArH04KmFQAAAUU"] [Tue Aug 18 12:58:29.747098 2026] [security2:error] [pid 66623:tid 66779] [client 4.232.151.198:30021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gettest.php"] [unique_id "aoSBJdO5rbWdOArH04KmFgAAARc"] [Tue Aug 18 12:58:29.766328 2026] [security2:error] [pid 66623:tid 66861] [client 158.23.17.4:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/st.php"] [unique_id "aoSBJdO5rbWdOArH04KmGgAAAWk"] [Tue Aug 18 12:58:29.771795 2026] [security2:error] [pid 66623:tid 66883] [client 20.118.172.148:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/about.php"] [unique_id "aoSBJdO5rbWdOArH04KmGwAAAX8"] [Tue Aug 18 12:58:29.792054 2026] [security2:error] [pid 66623:tid 66804] [client 85.204.70.114:51442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJdO5rbWdOArH04KmHAAAATA"] [Tue Aug 18 12:58:29.818759 2026] [security2:error] [pid 66623:tid 66890] [client 197.184.64.235:41944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmHQAAAYY"] [Tue Aug 18 12:58:29.821044 2026] [security2:error] [pid 66623:tid 66682] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ia.php"] [unique_id "aoSBJdO5rbWdOArH04KmHgABXy0"] [Tue Aug 18 12:58:29.823467 2026] [security2:error] [pid 66623:tid 66890] [client 197.184.64.235:41944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmHQAAAYY"] [Tue Aug 18 12:58:29.849383 2026] [security2:error] [pid 66623:tid 66764] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmIQABUH8"] [Tue Aug 18 12:58:29.849524 2026] [security2:error] [pid 66623:tid 66836] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJdO5rbWdOArH04KmIQABUH8"] [Tue Aug 18 12:58:29.857275 2026] [security2:error] [pid 66623:tid 66795] [client 172.182.200.96:14081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBJdO5rbWdOArH04KmIgAAASc"] [Tue Aug 18 12:58:29.872013 2026] [security2:error] [pid 66623:tid 66824] [client 20.250.13.23:53677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/0x.php"] [unique_id "aoSBJdO5rbWdOArH04KmIwAAAUQ"] [Tue Aug 18 12:58:29.898573 2026] [security2:error] [pid 66623:tid 66797] [client 74.248.18.37:47259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/s93.php"] [unique_id "aoSBJdO5rbWdOArH04KmJQAAASk"] [Tue Aug 18 12:58:29.933178 2026] [authz_core:error] [pid 66623:tid 66651] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:29.933446 2026] [authz_core:error] [pid 66623:tid 66651] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:29.953783 2026] [security2:error] [pid 66623:tid 66773] [client 20.203.138.185:10795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fasx.php"] [unique_id "aoSBJdO5rbWdOArH04KmKgAAARE"] [Tue Aug 18 12:58:29.987426 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/dex.php"] [unique_id "aoSBJdO5rbWdOArH04KmLQAAAR4"] [Tue Aug 18 12:58:29.988705 2026] [security2:error] [pid 66623:tid 66766] [client 20.48.236.86:25982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/h.php"] [unique_id "aoSBJdO5rbWdOArH04KmLgAAAQo"] [Tue Aug 18 12:58:29.991859 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kn.php"] [unique_id "aoSBJdO5rbWdOArH04KmLwABTkY"] [Tue Aug 18 12:58:30.006276 2026] [security2:error] [pid 66623:tid 66785] [client 40.74.65.169:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/inso.php"] [unique_id "aoSBJtO5rbWdOArH04KmMAAAAR0"] [Tue Aug 18 12:58:30.012393 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.155.199:5678] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-includes/js/crop/"] [unique_id "aoSBJtO5rbWdOArH04KmMQAAARQ"] [Tue Aug 18 12:58:30.020855 2026] [security2:error] [pid 66623:tid 66829] [client 158.23.17.4:31924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ag.php"] [unique_id "aoSBJtO5rbWdOArH04KmMgAAAUk"] [Tue Aug 18 12:58:30.056241 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:11892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmNgAAASg"] [Tue Aug 18 12:58:30.067403 2026] [security2:error] [pid 66623:tid 66792] [client 213.35.127.232:51121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBJtO5rbWdOArH04KmNwAAASQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:30.076994 2026] [security2:error] [pid 66623:tid 66775] [client 20.118.133.132:21636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file5.php"] [unique_id "aoSBJtO5rbWdOArH04KmOQAAARM"] [Tue Aug 18 12:58:30.100953 2026] [security2:error] [pid 66623:tid 66869] [client 20.104.85.180:27954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBJtO5rbWdOArH04KmPAAAAXE"] [Tue Aug 18 12:58:30.104699 2026] [autoindex:error] [pid 66623:tid 66803] [client 20.79.204.6:11579] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:30.137047 2026] [security2:error] [pid 66623:tid 66821] [client 20.118.172.148:2712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmPgAAAUE"] [Tue Aug 18 12:58:30.169256 2026] [security2:error] [pid 66623:tid 66704] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wm.php"] [unique_id "aoSBJtO5rbWdOArH04KmQwABY0M"] [Tue Aug 18 12:58:30.175526 2026] [security2:error] [pid 66623:tid 66770] [client 85.204.70.114:51450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmRAAAAQ4"] [Tue Aug 18 12:58:30.201774 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.217.32:15607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/w.php"] [unique_id "aoSBJtO5rbWdOArH04KmRwAAAYU"] [Tue Aug 18 12:58:30.207659 2026] [security2:error] [pid 66623:tid 66840] [client 20.206.73.37:11926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/sf.php"] [unique_id "aoSBJtO5rbWdOArH04KmSQAAAVQ"] [Tue Aug 18 12:58:30.239840 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:30.240272 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:30.307654 2026] [security2:error] [pid 66623:tid 66815] [client 20.79.204.6:11579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBJtO5rbWdOArH04KmUAAAATs"] [Tue Aug 18 12:58:30.319628 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.153.139:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSBJtO5rbWdOArH04KmUwAAAVs"] [Tue Aug 18 12:58:30.319748 2026] [security2:error] [pid 66623:tid 66847] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSBJtO5rbWdOArH04KmUwAAAVs"] [Tue Aug 18 12:58:30.330196 2026] [security2:error] [pid 66623:tid 66833] [client 20.100.185.105:59222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-signup.php"] [unique_id "aoSBJtO5rbWdOArH04KmVAAAAU0"] [Tue Aug 18 12:58:30.365076 2026] [security2:error] [pid 66623:tid 66680] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/work.php"] [unique_id "aoSBJtO5rbWdOArH04KmVgABYSs"] [Tue Aug 18 12:58:30.374354 2026] [security2:error] [pid 66623:tid 66861] [client 158.158.74.177:22763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmVwAAAWk"] [Tue Aug 18 12:58:30.387445 2026] [security2:error] [pid 66623:tid 66791] [client 4.232.151.198:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/void.php"] [unique_id "aoSBJtO5rbWdOArH04KmWgAAASM"] [Tue Aug 18 12:58:30.410748 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/mail.php"] [unique_id "aoSBJtO5rbWdOArH04KmWwAAAX0"] [Tue Aug 18 12:58:30.424376 2026] [security2:error] [pid 66623:tid 66661] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ac.php"] [unique_id "aoSBJtO5rbWdOArH04KmXAABJRg"] [Tue Aug 18 12:58:30.487882 2026] [security2:error] [pid 66623:tid 66828] [client 20.127.136.245:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/simple.php"] [unique_id "aoSBJtO5rbWdOArH04KmXgAAAUg"] [Tue Aug 18 12:58:30.489767 2026] [security2:error] [pid 66623:tid 66869] [client 68.155.155.199:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBJtO5rbWdOArH04KmXwAAAXE"] [Tue Aug 18 12:58:30.498353 2026] [security2:error] [pid 66623:tid 66831] [client 20.118.172.148:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBJtO5rbWdOArH04KmYQAAAUs"] [Tue Aug 18 12:58:30.498969 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:45714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/222.php"] [unique_id "aoSBJtO5rbWdOArH04KmYgAAATM"] [Tue Aug 18 12:58:30.534699 2026] [authz_core:error] [pid 66623:tid 66753] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:30.534967 2026] [authz_core:error] [pid 66623:tid 66753] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:30.544759 2026] [security2:error] [pid 66623:tid 66722] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBJtO5rbWdOArH04KmZwABZ1U"] [Tue Aug 18 12:58:30.562357 2026] [security2:error] [pid 66623:tid 66799] [client 85.204.70.114:51452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmaAAAASs"] [Tue Aug 18 12:58:30.614148 2026] [security2:error] [pid 66623:tid 66826] [client 74.248.18.37:54923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/server.php"] [unique_id "aoSBJtO5rbWdOArH04KmawAAAUY"] [Tue Aug 18 12:58:30.637396 2026] [security2:error] [pid 66623:tid 66711] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yz.php"] [unique_id "aoSBJtO5rbWdOArH04KmbAABREo"] [Tue Aug 18 12:58:30.644421 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/coffee.php"] [unique_id "aoSBJtO5rbWdOArH04KmbQAAASk"] [Tue Aug 18 12:58:30.688284 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.217.32:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/x.php"] [unique_id "aoSBJtO5rbWdOArH04KmcAAAAYg"] [Tue Aug 18 12:58:30.747075 2026] [security2:error] [pid 66623:tid 66778] [client 20.48.236.86:32839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ano.php"] [unique_id "aoSBJtO5rbWdOArH04KmdgAAARY"] [Tue Aug 18 12:58:30.768303 2026] [security2:error] [pid 66623:tid 66850] [client 20.119.58.187:11892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/upfile.php"] [unique_id "aoSBJtO5rbWdOArH04KmeAAAAV4"] [Tue Aug 18 12:58:30.800843 2026] [security2:error] [pid 66623:tid 66845] [client 40.74.65.169:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/aa.php"] [unique_id "aoSBJtO5rbWdOArH04KmeQAAAVk"] [Tue Aug 18 12:58:30.818683 2026] [security2:error] [pid 66623:tid 66832] [client 4.232.94.69:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/f5.php"] [unique_id "aoSBJtO5rbWdOArH04KmewAAAUw"] [Tue Aug 18 12:58:30.837876 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:30.838178 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:30.838286 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kj.php"] [unique_id "aoSBJtO5rbWdOArH04KmfQABbR0"] [Tue Aug 18 12:58:30.851645 2026] [security2:error] [pid 66623:tid 66876] [client 20.118.172.148:31292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/as.php"] [unique_id "aoSBJtO5rbWdOArH04KmgAAAAXg"] [Tue Aug 18 12:58:30.902910 2026] [security2:error] [pid 66623:tid 66812] [client 74.248.18.37:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiAAAATg"] [Tue Aug 18 12:58:30.910134 2026] [security2:error] [pid 66623:tid 66806] [client 20.79.204.6:11560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBJtO5rbWdOArH04KmiQAAATI"] [Tue Aug 18 12:58:30.947861 2026] [security2:error] [pid 66623:tid 66839] [client 86.120.159.145:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiwAAAVM"] [Tue Aug 18 12:58:30.947983 2026] [security2:error] [pid 66623:tid 66839] [client 86.120.159.145:60196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJtO5rbWdOArH04KmiwAAAVM"] [Tue Aug 18 12:58:30.949029 2026] [security2:error] [pid 66623:tid 66878] [client 20.100.185.105:43117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/moon.php"] [unique_id "aoSBJtO5rbWdOArH04KmjAAAAXo"] [Tue Aug 18 12:58:30.977457 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/classwithtostring.php"] [unique_id "aoSBJtO5rbWdOArH04KmjQAAAWQ"] [Tue Aug 18 12:58:30.986763 2026] [security2:error] [pid 66623:tid 66817] [client 85.204.70.114:51460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJtO5rbWdOArH04KmjgAAAT0"] [Tue Aug 18 12:58:31.013052 2026] [security2:error] [pid 66623:tid 66829] [client 20.104.85.180:47124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/k.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkAAAAUk"] [Tue Aug 18 12:58:31.013163 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vg.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkQABaVM"] [Tue Aug 18 12:58:31.054394 2026] [security2:error] [pid 66623:tid 66709] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlAABRUg"] [Tue Aug 18 12:58:31.054624 2026] [security2:error] [pid 66623:tid 66745] [remote 162.55.89.48:53396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSBJ9O5rbWdOArH04KmkwABcmw"] [Tue Aug 18 12:58:31.061902 2026] [security2:error] [pid 66623:tid 66789] [client 158.23.17.4:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/le.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlQAAASE"] [Tue Aug 18 12:58:31.064038 2026] [security2:error] [pid 66623:tid 66847] [client 158.158.74.177:16569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclog.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04KmlgAAAVs"] [Tue Aug 18 12:58:31.071461 2026] [security2:error] [pid 66623:tid 66790] [client 192.141.172.134:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmAAAASI"] [Tue Aug 18 12:58:31.071579 2026] [security2:error] [pid 66623:tid 66790] [client 192.141.172.134:51087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmAAAASI"] [Tue Aug 18 12:58:31.075646 2026] [security2:error] [pid 66623:tid 66769] [client 20.215.241.237:41263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/sf.php"] [unique_id "aoSBJ9O5rbWdOArH04KmmgAAAQ0"] [Tue Aug 18 12:58:31.079436 2026] [security2:error] [pid 66623:tid 66863] [client 213.35.127.232:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBJ9O5rbWdOArH04KmnAAAAWs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:31.085211 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wpsml-sys.php"] [unique_id "aoSBJ9O5rbWdOArH04KmnQAAAV0"] [Tue Aug 18 12:58:31.113444 2026] [security2:error] [pid 66623:tid 66697] [remote 136.110.27.48:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.app.gueirosadvocacia.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBJ9O5rbWdOArH04KmoAABFzw"] [Tue Aug 18 12:58:31.134582 2026] [security2:error] [pid 66623:tid 66774] [client 20.119.58.187:11887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBJ9O5rbWdOArH04KmogAAARI"] [Tue Aug 18 12:58:31.141985 2026] [security2:error] [pid 66623:tid 66777] [client 114.119.157.196:50113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "abrilbranco.org"] [uri "/tipos_de_cancer/tumores-neuroendocrinos"] [unique_id "aoSBJ9O5rbWdOArH04KmowAAARU"], referer: http://abrilbranco.org/?pid=129085669 [Tue Aug 18 12:58:31.148440 2026] [security2:error] [pid 66623:tid 66874] [client 20.250.13.23:1819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/aa.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpAAAAXY"] [Tue Aug 18 12:58:31.171578 2026] [security2:error] [pid 66623:tid 66821] [client 20.203.138.185:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-good.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpQAAAUE"] [Tue Aug 18 12:58:31.176744 2026] [security2:error] [pid 66623:tid 66853] [client 172.182.217.32:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xx.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpgAAAWE"] [Tue Aug 18 12:58:31.190794 2026] [security2:error] [pid 66623:tid 66795] [client 20.118.172.148:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/bolt.php"] [unique_id "aoSBJ9O5rbWdOArH04KmpwAAASc"] [Tue Aug 18 12:58:31.193313 2026] [security2:error] [pid 66623:tid 66663] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sm.php"] [unique_id "aoSBJ9O5rbWdOArH04KmqAABRho"] [Tue Aug 18 12:58:31.219380 2026] [security2:error] [pid 66623:tid 66885] [client 114.119.152.142:62277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "telesaopedro.com.br"] [uri "/cvc-sao-pedro-agencia-de-turismo/"] [unique_id "aoSBJ9O5rbWdOArH04KmqgAAAYE"], referer: https://telesaopedro.com.br/empresa/page/35 [Tue Aug 18 12:58:31.238080 2026] [security2:error] [pid 66623:tid 66671] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04KmqwABRCI"] [Tue Aug 18 12:58:31.294765 2026] [security2:error] [pid 66623:tid 66889] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-ws68.php"] [unique_id "aoSBJ9O5rbWdOArH04KmrgAAAYU"] [Tue Aug 18 12:58:31.297331 2026] [security2:error] [pid 66623:tid 66871] [client 74.248.18.37:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/settings.php"] [unique_id "aoSBJ9O5rbWdOArH04KmrwAAAXM"] [Tue Aug 18 12:58:31.312117 2026] [security2:error] [pid 66623:tid 66844] [client 158.23.17.4:34143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ig.php"] [unique_id "aoSBJ9O5rbWdOArH04KmsQAAAVg"] [Tue Aug 18 12:58:31.344997 2026] [security2:error] [pid 66623:tid 66868] [client 68.155.155.199:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBJ9O5rbWdOArH04KmswAAAXA"] [Tue Aug 18 12:58:31.389028 2026] [security2:error] [pid 66623:tid 66822] [client 172.182.200.96:7640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBJ9O5rbWdOArH04KmtgAAAUI"] [Tue Aug 18 12:58:31.397696 2026] [security2:error] [pid 66623:tid 66781] [client 85.204.70.114:51462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJ9O5rbWdOArH04KmuQAAARk"] [Tue Aug 18 12:58:31.404789 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/28.php"] [unique_id "aoSBJ9O5rbWdOArH04KmugABYEc"] [Tue Aug 18 12:58:31.466839 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:27893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/lddxs.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvAAAAW8"] [Tue Aug 18 12:58:31.471892 2026] [autoindex:error] [pid 66623:tid 66701] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:31.518345 2026] [security2:error] [pid 66623:tid 66851] [client 20.79.204.6:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvgAAAV8"] [Tue Aug 18 12:58:31.519736 2026] [security2:error] [pid 66623:tid 66887] [client 20.119.58.187:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmvwAAAYM"] [Tue Aug 18 12:58:31.563369 2026] [security2:error] [pid 66623:tid 66829] [client 20.118.133.132:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/xyn.php"] [unique_id "aoSBJ9O5rbWdOArH04KmwQAAAUk"] [Tue Aug 18 12:58:31.591745 2026] [security2:error] [pid 66623:tid 66846] [client 20.100.169.31:29060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBJ9O5rbWdOArH04KmwwAAAVo"] [Tue Aug 18 12:58:31.606477 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/m.php"] [unique_id "aoSBJ9O5rbWdOArH04KmygABSks"] [Tue Aug 18 12:58:31.609238 2026] [security2:error] [pid 66623:tid 66823] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mgrr.php"] [unique_id "aoSBJ9O5rbWdOArH04KmywAAAUM"] [Tue Aug 18 12:58:31.616150 2026] [security2:error] [pid 66623:tid 66833] [client 20.100.185.105:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/exif.php"] [unique_id "aoSBJ9O5rbWdOArH04KmzgAAAU0"] [Tue Aug 18 12:58:31.656661 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:31.656937 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:31.657992 2026] [security2:error] [pid 66623:tid 66800] [client 74.248.18.37:40997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBJ9O5rbWdOArH04Km0gAAASw"] [Tue Aug 18 12:58:31.658027 2026] [security2:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBJ9O5rbWdOArH04Km0QABfHg"] [Tue Aug 18 12:58:31.675055 2026] [security2:error] [pid 66623:tid 66881] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04KmzwABfU8"] [Tue Aug 18 12:58:31.680328 2026] [security2:error] [pid 66623:tid 66857] [client 172.182.217.32:15459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBJ9O5rbWdOArH04Km1QAAAWU"] [Tue Aug 18 12:58:31.711584 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBJ9O5rbWdOArH04Km1wAAAUs"] [Tue Aug 18 12:58:31.717084 2026] [security2:error] [pid 66623:tid 66854] [client 4.232.151.198:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/l.php"] [unique_id "aoSBJ9O5rbWdOArH04Km2AAAAWI"] [Tue Aug 18 12:58:31.794362 2026] [security2:error] [pid 66623:tid 66777] [client 85.204.70.114:51472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "intersul.ind.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSBJ9O5rbWdOArH04Km3gAAARU"] [Tue Aug 18 12:58:31.802345 2026] [security2:error] [pid 66623:tid 66776] [client 4.232.94.69:20775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/al.php"] [unique_id "aoSBJ9O5rbWdOArH04Km3wAAARQ"] [Tue Aug 18 12:58:31.816065 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:32702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wk/index.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4QAAAQ4"] [Tue Aug 18 12:58:31.820680 2026] [security2:error] [pid 66623:tid 66644] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nl.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4gABdgc"] [Tue Aug 18 12:58:31.831628 2026] [security2:error] [pid 66623:tid 66825] [client 20.250.13.23:45756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/abcd.php"] [unique_id "aoSBJ9O5rbWdOArH04Km4wAAAUU"] [Tue Aug 18 12:58:31.844567 2026] [security2:error] [pid 66623:tid 66804] [client 20.118.172.148:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBJ9O5rbWdOArH04Km5QAAATA"] [Tue Aug 18 12:58:31.868803 2026] [security2:error] [pid 66623:tid 66795] [client 20.48.236.86:31043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ai.php"] [unique_id "aoSBJ9O5rbWdOArH04Km5wAAASc"] [Tue Aug 18 12:58:31.878164 2026] [security2:error] [pid 66623:tid 66886] [client 20.119.58.187:12543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ae.php"] [unique_id "aoSBJ9O5rbWdOArH04Km6AAAAYI"] [Tue Aug 18 12:58:31.881766 2026] [autoindex:error] [pid 66623:tid 66648] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:31.900690 2026] [security2:error] [pid 66623:tid 66824] [client 158.23.17.4:15786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hr.php"] [unique_id "aoSBJ9O5rbWdOArH04Km6QAAAUQ"] [Tue Aug 18 12:58:31.948037 2026] [security2:error] [pid 66623:tid 66840] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/55.php"] [unique_id "aoSBJ9O5rbWdOArH04Km7AAAAVQ"] [Tue Aug 18 12:58:31.957064 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:31.957320 2026] [authz_core:error] [pid 66623:tid 66762] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:31.961611 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:6746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/0x.php"] [unique_id "aoSBJ9O5rbWdOArH04Km7wAAARE"] [Tue Aug 18 12:58:31.969674 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:7209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sf.php"] [unique_id "aoSBJ9O5rbWdOArH04Km8QAAAQ8"] [Tue Aug 18 12:58:31.976051 2026] [security2:error] [pid 66623:tid 66848] [client 20.203.183.135:49668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.amigosdoronron.com.br"] [uri "/abcd.php"] [unique_id "aoSBJ9O5rbWdOArH04Km8gAAAVw"] [Tue Aug 18 12:58:32.001406 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/68.php"] [unique_id "aoSBKNO5rbWdOArH04Km8wABKms"] [Tue Aug 18 12:58:32.008428 2026] [security2:error] [pid 66623:tid 66686] [remote 66.249.74.227:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "donfalconebarbearia.com.br"] [uri "/robots.txt"] [unique_id "aoSBKNO5rbWdOArH04Km9AABWDE"] [Tue Aug 18 12:58:32.017949 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:45400] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/1.php"] [unique_id "aoSBKNO5rbWdOArH04Km9QAAAUA"] [Tue Aug 18 12:58:32.018070 2026] [security2:error] [pid 66623:tid 66820] [client 40.74.65.169:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/1.php"] [unique_id "aoSBKNO5rbWdOArH04Km9QAAAUA"] [Tue Aug 18 12:58:32.020919 2026] [security2:error] [pid 66623:tid 66884] [client 52.173.121.69:47306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zjggu.php"] [unique_id "aoSBKNO5rbWdOArH04Km9gAAAYA"] [Tue Aug 18 12:58:32.066119 2026] [security2:error] [pid 66623:tid 66647] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSBKNO5rbWdOArH04Km-QABOwo"] [Tue Aug 18 12:58:32.089307 2026] [security2:error] [pid 66623:tid 66842] [client 213.35.127.232:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBKNO5rbWdOArH04Km-gAAAVY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:32.113463 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/403.php"] [unique_id "aoSBKNO5rbWdOArH04Km-wAAAYk"] [Tue Aug 18 12:58:32.141801 2026] [autoindex:error] [pid 66623:tid 66797] [client 20.79.204.6:11533] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:32.159018 2026] [security2:error] [pid 66623:tid 66786] [client 158.23.17.4:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ta.php"] [unique_id "aoSBKNO5rbWdOArH04Km_gAAAR4"] [Tue Aug 18 12:58:32.160581 2026] [security2:error] [pid 66623:tid 66890] [client 172.202.39.151:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/public/css.php"] [unique_id "aoSBKNO5rbWdOArH04Km_wAAAYY"] [Tue Aug 18 12:58:32.168243 2026] [security2:error] [pid 66623:tid 66766] [client 172.182.217.32:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/y.php"] [unique_id "aoSBKNO5rbWdOArH04KnAAAAAQo"] [Tue Aug 18 12:58:32.196604 2026] [security2:error] [pid 66623:tid 66656] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jl.php"] [unique_id "aoSBKNO5rbWdOArH04KnAgABXxM"] [Tue Aug 18 12:58:32.235232 2026] [security2:error] [pid 66623:tid 66808] [client 20.100.185.105:21652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/0.php"] [unique_id "aoSBKNO5rbWdOArH04KnBQAAATQ"] [Tue Aug 18 12:58:32.238251 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/moon.php"] [unique_id "aoSBKNO5rbWdOArH04KnBgAAAWA"] [Tue Aug 18 12:58:32.249603 2026] [security2:error] [pid 66623:tid 66761] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnCAABC3w"] [Tue Aug 18 12:58:32.265265 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ajax.php"] [unique_id "aoSBKNO5rbWdOArH04KnCwAAAVE"] [Tue Aug 18 12:58:32.313479 2026] [security2:error] [pid 66623:tid 66781] [client 79.127.164.8:40880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/server.sql"] [unique_id "aoSBKNO5rbWdOArH04KnDwAAARk"], referer: https://medihub.com.br/server.sql [Tue Aug 18 12:58:32.351757 2026] [security2:error] [pid 66623:tid 66737] [remote 72.167.40.62:55648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKNO5rbWdOArH04KnEgABZmQ"] [Tue Aug 18 12:58:32.378021 2026] [security2:error] [pid 66623:tid 66755] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tq.php"] [unique_id "aoSBKNO5rbWdOArH04KnEwABPnY"] [Tue Aug 18 12:58:32.379909 2026] [security2:error] [pid 66623:tid 66785] [client 4.232.151.198:30030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/file.php"] [unique_id "aoSBKNO5rbWdOArH04KnFAAAAR0"] [Tue Aug 18 12:58:32.381891 2026] [security2:error] [pid 66623:tid 66835] [client 20.203.138.185:47213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zxin.php"] [unique_id "aoSBKNO5rbWdOArH04KnFQAAAU8"] [Tue Aug 18 12:58:32.417214 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:17946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/rezor.php"] [unique_id "aoSBKNO5rbWdOArH04KnGAAAAUs"] [Tue Aug 18 12:58:32.421369 2026] [security2:error] [pid 66623:tid 66854] [client 20.118.172.148:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/edit.php"] [unique_id "aoSBKNO5rbWdOArH04KnGQAAAWI"] [Tue Aug 18 12:58:32.439049 2026] [security2:error] [pid 66623:tid 66705] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBKNO5rbWdOArH04KnGgABM0Q"] [Tue Aug 18 12:58:32.456966 2026] [security2:error] [pid 66623:tid 66814] [client 20.250.13.23:53632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/admin.php"] [unique_id "aoSBKNO5rbWdOArH04KnGwAAATo"] [Tue Aug 18 12:58:32.556450 2026] [security2:error] [pid 66623:tid 66804] [client 52.173.121.69:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/dlvqo.php"] [unique_id "aoSBKNO5rbWdOArH04KnMgAAATA"] [Tue Aug 18 12:58:32.565040 2026] [security2:error] [pid 66623:tid 66660] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/cv.php"] [unique_id "aoSBKNO5rbWdOArH04KnMwABYRc"] [Tue Aug 18 12:58:32.575004 2026] [security2:error] [pid 66623:tid 66836] [client 20.79.204.6:11533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBKNO5rbWdOArH04KnNQAAAVA"] [Tue Aug 18 12:58:32.581415 2026] [security2:error] [pid 66623:tid 66795] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/yj09.php"] [unique_id "aoSBKNO5rbWdOArH04KnNwAAASc"] [Tue Aug 18 12:58:32.583434 2026] [authz_core:error] [pid 66623:tid 66752] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:32.583703 2026] [authz_core:error] [pid 66623:tid 66752] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:32.599486 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.94.69:44546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/inc.php"] [unique_id "aoSBKNO5rbWdOArH04KnOAAAAQ0"] [Tue Aug 18 12:58:32.599628 2026] [security2:error] [pid 66623:tid 66777] [client 20.119.58.187:12531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ini.php"] [unique_id "aoSBKNO5rbWdOArH04KnOQAAARU"] [Tue Aug 18 12:58:32.602756 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:40982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/shell.php"] [unique_id "aoSBKNO5rbWdOArH04KnOgAAAX0"] [Tue Aug 18 12:58:32.610022 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:47275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBKNO5rbWdOArH04KnPQAAATE"] [Tue Aug 18 12:58:32.628106 2026] [security2:error] [pid 66623:tid 66680] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBKNO5rbWdOArH04KnPwABESs"] [Tue Aug 18 12:58:32.648856 2026] [security2:error] [pid 66623:tid 66778] [client 20.127.136.245:13467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBKNO5rbWdOArH04KnRQAAARY"] [Tue Aug 18 12:58:32.676532 2026] [security2:error] [pid 66623:tid 66860] [client 68.155.155.199:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSBKNO5rbWdOArH04KnSAAAAWg"] [Tue Aug 18 12:58:32.716048 2026] [security2:error] [pid 66623:tid 66847] [client 20.118.133.132:19636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBKNO5rbWdOArH04KnSQAAAVs"] [Tue Aug 18 12:58:32.734549 2026] [security2:error] [pid 66623:tid 66801] [client 158.23.17.4:8935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/34.php"] [unique_id "aoSBKNO5rbWdOArH04KnTQAAAS0"] [Tue Aug 18 12:58:32.737696 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/un.php"] [unique_id "aoSBKNO5rbWdOArH04KnTgABcXI"] [Tue Aug 18 12:58:32.823549 2026] [security2:error] [pid 66623:tid 66740] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSBKNO5rbWdOArH04KnUgABYGc"] [Tue Aug 18 12:58:32.852707 2026] [security2:error] [pid 66623:tid 66798] [client 20.100.185.105:59250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.185.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/embed.php"] [unique_id "aoSBKNO5rbWdOArH04KnVgAAASo"] [Tue Aug 18 12:58:32.858908 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:32.859164 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:32.868129 2026] [security2:error] [pid 66623:tid 66809] [client 158.23.17.4:7229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kt.php"] [unique_id "aoSBKNO5rbWdOArH04KnWAAAATU"] [Tue Aug 18 12:58:32.913335 2026] [security2:error] [pid 66623:tid 66739] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/evil.php"] [unique_id "aoSBKNO5rbWdOArH04KnWgABGWY"] [Tue Aug 18 12:58:32.933827 2026] [security2:error] [pid 66623:tid 66887] [client 103.184.169.37:42385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnXQAAAYM"] [Tue Aug 18 12:58:32.933969 2026] [security2:error] [pid 66623:tid 66887] [client 103.184.169.37:42385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKNO5rbWdOArH04KnXQAAAYM"] [Tue Aug 18 12:58:32.954752 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/shell.php"] [unique_id "aoSBKNO5rbWdOArH04KnXwAAASM"] [Tue Aug 18 12:58:32.984409 2026] [security2:error] [pid 66623:tid 66789] [client 20.118.172.148:2717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ff1.php"] [unique_id "aoSBKNO5rbWdOArH04KnYAAAASE"] [Tue Aug 18 12:58:33.007212 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.151.198:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-comments-post.php"] [unique_id "aoSBKdO5rbWdOArH04KnYgAAAWQ"] [Tue Aug 18 12:58:33.009057 2026] [security2:error] [pid 66623:tid 66692] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSBKdO5rbWdOArH04KnZAABTzc"] [Tue Aug 18 12:58:33.022058 2026] [security2:error] [pid 66623:tid 66880] [client 103.120.71.157:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnZQAAAXw"] [Tue Aug 18 12:58:33.022171 2026] [security2:error] [pid 66623:tid 66880] [client 103.120.71.157:58854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnZQAAAXw"] [Tue Aug 18 12:58:33.026403 2026] [security2:error] [pid 66623:tid 66857] [client 40.74.65.169:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/img.php"] [unique_id "aoSBKdO5rbWdOArH04KnZgAAAWU"] [Tue Aug 18 12:58:33.037553 2026] [security2:error] [pid 66623:tid 66831] [client 20.48.236.86:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/w1px.php"] [unique_id "aoSBKdO5rbWdOArH04KnaAAAAUs"] [Tue Aug 18 12:58:33.049729 2026] [security2:error] [pid 66623:tid 66779] [client 52.173.121.69:24790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBKdO5rbWdOArH04KnagAAARc"] [Tue Aug 18 12:58:33.059171 2026] [security2:error] [pid 66623:tid 66807] [client 20.104.85.180:50311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/gecko.php"] [unique_id "aoSBKdO5rbWdOArH04KnawAAATM"] [Tue Aug 18 12:58:33.086483 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pw.php"] [unique_id "aoSBKdO5rbWdOArH04KnbQABSAE"] [Tue Aug 18 12:58:33.103952 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBKdO5rbWdOArH04KncAAAAR4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:33.159552 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:33.159835 2026] [authz_core:error] [pid 66623:tid 66690] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:33.163391 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:32699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/about.php"] [unique_id "aoSBKdO5rbWdOArH04KndAAAAXI"] [Tue Aug 18 12:58:33.187248 2026] [security2:error] [pid 66623:tid 66753] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSBKdO5rbWdOArH04KndgABUHQ"] [Tue Aug 18 12:58:33.197495 2026] [autoindex:error] [pid 66623:tid 66800] [client 20.79.204.6:11670] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:33.201504 2026] [security2:error] [pid 66623:tid 66799] [client 52.173.121.69:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/pkmoj.php"] [unique_id "aoSBKdO5rbWdOArH04KndwAAASs"] [Tue Aug 18 12:58:33.216052 2026] [security2:error] [pid 66623:tid 66805] [client 172.202.39.151:40329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBKdO5rbWdOArH04KneQAAATE"] [Tue Aug 18 12:58:33.260623 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.18.37:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBKdO5rbWdOArH04KnfAAAAWI"] [Tue Aug 18 12:58:33.276524 2026] [security2:error] [pid 66623:tid 66861] [client 74.248.18.37:47290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/shiny.php"] [unique_id "aoSBKdO5rbWdOArH04KnfQAAAWk"] [Tue Aug 18 12:58:33.286139 2026] [security2:error] [pid 66623:tid 66745] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fn.php"] [unique_id "aoSBKdO5rbWdOArH04KnfwABXmw"] [Tue Aug 18 12:58:33.310125 2026] [security2:error] [pid 66623:tid 66768] [client 20.250.13.23:1814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBKdO5rbWdOArH04KnhAAAAQw"] [Tue Aug 18 12:58:33.310412 2026] [security2:error] [pid 66623:tid 66795] [client 20.119.58.187:12512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBKdO5rbWdOArH04KngwAAASc"] [Tue Aug 18 12:58:33.322480 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/scxy.php"] [unique_id "aoSBKdO5rbWdOArH04KnhgAAASA"] [Tue Aug 18 12:58:33.366014 2026] [security2:error] [pid 66623:tid 66713] [remote 115.146.125.52:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KniAABQEw"] [Tue Aug 18 12:58:33.376986 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/css/min.php"] [unique_id "aoSBKdO5rbWdOArH04KniQABRRU"] [Tue Aug 18 12:58:33.399233 2026] [security2:error] [pid 66623:tid 66893] [client 20.79.204.6:11670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBKdO5rbWdOArH04KniwAAAYk"] [Tue Aug 18 12:58:33.433792 2026] [security2:error] [pid 66623:tid 66822] [client 158.23.17.4:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/he.php"] [unique_id "aoSBKdO5rbWdOArH04KnjwAAAUI"] [Tue Aug 18 12:58:33.493540 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kf.php"] [unique_id "aoSBKdO5rbWdOArH04KnkgABbyI"] [Tue Aug 18 12:58:33.562192 2026] [security2:error] [pid 66623:tid 66741] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBKdO5rbWdOArH04KnlAABhGg"] [Tue Aug 18 12:58:33.589330 2026] [security2:error] [pid 66623:tid 66736] [remote 165.173.18.124:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.173.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnlwABHWM"] [Tue Aug 18 12:58:33.604516 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/aa.php"] [unique_id "aoSBKdO5rbWdOArH04KnmAAAAWQ"] [Tue Aug 18 12:58:33.612810 2026] [security2:error] [pid 66623:tid 66835] [client 20.215.241.237:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/k.php"] [unique_id "aoSBKdO5rbWdOArH04KnmQAAAU8"] [Tue Aug 18 12:58:33.624437 2026] [security2:error] [pid 66623:tid 66872] [client 37.40.227.74:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnmwAAAXQ"] [Tue Aug 18 12:58:33.624552 2026] [security2:error] [pid 66623:tid 66872] [client 37.40.227.74:57206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnmwAAAXQ"] [Tue Aug 18 12:58:33.646315 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:32593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/kopyw.php"] [unique_id "aoSBKdO5rbWdOArH04KnnQAAAWU"] [Tue Aug 18 12:58:33.650515 2026] [security2:error] [pid 66623:tid 66808] [client 4.232.151.198:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnngAAATQ"] [Tue Aug 18 12:58:33.665351 2026] [security2:error] [pid 66623:tid 66791] [client 20.119.58.187:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-sigunq.php"] [unique_id "aoSBKdO5rbWdOArH04KnnwAAASM"] [Tue Aug 18 12:58:33.669704 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ws13.php"] [unique_id "aoSBKdO5rbWdOArH04KnoQAAAVE"] [Tue Aug 18 12:58:33.678150 2026] [security2:error] [pid 66623:tid 66734] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/su.php"] [unique_id "aoSBKdO5rbWdOArH04KnogABE2E"] [Tue Aug 18 12:58:33.698393 2026] [security2:error] [pid 66623:tid 66871] [client 213.202.253.4:55783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSBKdO5rbWdOArH04KnowAAAXM"], referer: www.google.com [Tue Aug 18 12:58:33.725332 2026] [security2:error] [pid 66623:tid 66828] [client 40.74.65.169:55837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/222.php"] [unique_id "aoSBKdO5rbWdOArH04KnpAAAAUg"] [Tue Aug 18 12:58:33.751797 2026] [security2:error] [pid 66623:tid 66758] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/home.php"] [unique_id "aoSBKdO5rbWdOArH04KnpQABf3k"] [Tue Aug 18 12:58:33.760776 2026] [authz_core:error] [pid 66623:tid 66659] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:33.761196 2026] [authz_core:error] [pid 66623:tid 66659] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:33.776790 2026] [security2:error] [pid 66623:tid 66833] [client 20.104.85.180:18864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKdO5rbWdOArH04KnqAAAAU0"] [Tue Aug 18 12:58:33.786755 2026] [security2:error] [pid 66623:tid 66882] [client 20.206.73.37:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/xx.php"] [unique_id "aoSBKdO5rbWdOArH04KnqQAAAX4"] [Tue Aug 18 12:58:33.789685 2026] [security2:error] [pid 66623:tid 66701] [remote 162.214.96.231:36390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnqgABeUA"] [Tue Aug 18 12:58:33.816950 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.133.132:20217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/inso.php"] [unique_id "aoSBKdO5rbWdOArH04KnqwAAASg"] [Tue Aug 18 12:58:33.887439 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wp-key.php"] [unique_id "aoSBKdO5rbWdOArH04KnsAABdSQ"] [Tue Aug 18 12:58:33.916436 2026] [security2:error] [pid 66623:tid 66840] [client 20.48.236.86:2217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/zi-936.php"] [unique_id "aoSBKdO5rbWdOArH04KnsgAAAVQ"] [Tue Aug 18 12:58:33.917322 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBKdO5rbWdOArH04KnswAAAUs"] [Tue Aug 18 12:58:33.938832 2026] [security2:error] [pid 66623:tid 66813] [client 52.173.121.69:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBKdO5rbWdOArH04KntAAAATk"] [Tue Aug 18 12:58:33.939423 2026] [security2:error] [pid 66623:tid 66816] [client 20.250.13.23:45743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/akc.php"] [unique_id "aoSBKdO5rbWdOArH04KntQAAATw"] [Tue Aug 18 12:58:33.944862 2026] [security2:error] [pid 66623:tid 66848] [client 158.23.17.4:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ww.php"] [unique_id "aoSBKdO5rbWdOArH04KntwAAAVw"] [Tue Aug 18 12:58:33.949812 2026] [security2:error] [pid 66623:tid 66807] [client 74.248.18.37:7681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sid3.php"] [unique_id "aoSBKdO5rbWdOArH04KnuAAAATM"] [Tue Aug 18 12:58:33.985523 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/btx25.php"] [unique_id "aoSBKdO5rbWdOArH04KnugAAASA"] [Tue Aug 18 12:58:34.000210 2026] [security2:error] [pid 66623:tid 66853] [client 20.79.204.6:11539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBKdO5rbWdOArH04KnuwAAAWE"] [Tue Aug 18 12:58:34.022274 2026] [autoindex:error] [pid 66623:tid 66724] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:34.033054 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wso112233.php"] [unique_id "aoSBKtO5rbWdOArH04KnvgAAATE"] [Tue Aug 18 12:58:34.058824 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.85.180:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/moon.php"] [unique_id "aoSBKtO5rbWdOArH04KnwAAAAYU"] [Tue Aug 18 12:58:34.064116 2026] [authz_core:error] [pid 66623:tid 66691] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:34.064378 2026] [authz_core:error] [pid 66623:tid 66691] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:34.069647 2026] [security2:error] [pid 66623:tid 66793] [client 172.202.39.151:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSBKtO5rbWdOArH04KnwgAAASU"] [Tue Aug 18 12:58:34.089457 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gg.php"] [unique_id "aoSBKtO5rbWdOArH04KnwwABQBk"] [Tue Aug 18 12:58:34.105396 2026] [security2:error] [pid 66623:tid 66790] [client 158.23.17.4:34156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gz.php"] [unique_id "aoSBKtO5rbWdOArH04KnxAAAASI"] [Tue Aug 18 12:58:34.118386 2026] [security2:error] [pid 66623:tid 66841] [client 213.35.127.232:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBKtO5rbWdOArH04KnxQAAAVU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:34.126250 2026] [security2:error] [pid 66623:tid 66757] [remote 165.173.18.124:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.173.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBKtO5rbWdOArH04KnxwABeng"], referer: https://eccellenzaconsultoria.com.br/wp-login.php [Tue Aug 18 12:58:34.126540 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:14854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zznmg.php"] [unique_id "aoSBKtO5rbWdOArH04KnyAAAAUU"] [Tue Aug 18 12:58:34.143337 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:14088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBKtO5rbWdOArH04KnyQAAAUw"] [Tue Aug 18 12:58:34.149494 2026] [security2:error] [pid 66623:tid 66780] [client 20.118.172.148:2743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/fff.php"] [unique_id "aoSBKtO5rbWdOArH04KnywAAARg"] [Tue Aug 18 12:58:34.203319 2026] [security2:error] [pid 66623:tid 66667] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/images/min.php"] [unique_id "aoSBKtO5rbWdOArH04KnzQABQx4"] [Tue Aug 18 12:58:34.208082 2026] [security2:error] [pid 66623:tid 66794] [client 20.250.13.23:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/term.php"] [unique_id "aoSBKtO5rbWdOArH04KnzgAAASY"] [Tue Aug 18 12:58:34.236685 2026] [security2:error] [pid 66623:tid 66783] [client 68.155.155.199:23081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0QAAARs"] [Tue Aug 18 12:58:34.243119 2026] [security2:error] [pid 66623:tid 66786] [client 149.34.210.141:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0gAAAR4"] [Tue Aug 18 12:58:34.264867 2026] [security2:error] [pid 66623:tid 66879] [client 20.104.85.180:15224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/0x.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0wAAAXs"] [Tue Aug 18 12:58:34.295446 2026] [security2:error] [pid 66623:tid 66842] [client 4.232.151.198:30044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/aj.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1AAAAVY"] [Tue Aug 18 12:58:34.300856 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/SDsadqwrf.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1QAAAU8"] [Tue Aug 18 12:58:34.306388 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gi.php"] [unique_id "aoSBKtO5rbWdOArH04Kn1gABdAQ"] [Tue Aug 18 12:58:34.340738 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:43541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/cache.php"] [unique_id "aoSBKtO5rbWdOArH04Kn2AAAARM"] [Tue Aug 18 12:58:34.365209 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:34.365484 2026] [authz_core:error] [pid 66623:tid 66756] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:34.393991 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/fw.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-QAAASE"] [Tue Aug 18 12:58:34.396583 2026] [security2:error] [pid 66623:tid 66811] [client 5.31.227.224:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-gAAATc"] [Tue Aug 18 12:58:34.411953 2026] [security2:error] [pid 66623:tid 66811] [client 5.31.227.224:59070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn-gAAATc"] [Tue Aug 18 12:58:34.415981 2026] [security2:error] [pid 66623:tid 66849] [client 157.20.138.62:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoBwAAAV0"] [Tue Aug 18 12:58:34.416133 2026] [security2:error] [pid 66623:tid 66849] [client 157.20.138.62:52576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoBwAAAV0"] [Tue Aug 18 12:58:34.434434 2026] [autoindex:error] [pid 66623:tid 66732] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:34.478332 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:10763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pass4.php"] [unique_id "aoSBKtO5rbWdOArH04KoDAAAASg"] [Tue Aug 18 12:58:34.503771 2026] [security2:error] [pid 66623:tid 66738] [remote 103.56.163.133:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalinox.pt.cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSBKtO5rbWdOArH04KoEAABDWU"] [Tue Aug 18 12:58:34.520185 2026] [security2:error] [pid 66623:tid 66786] [client 149.34.210.141:62026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04Kn0gAAAR4"] [Tue Aug 18 12:58:34.543015 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pz.php"] [unique_id "aoSBKtO5rbWdOArH04KoEwABS1E"] [Tue Aug 18 12:58:34.545213 2026] [security2:error] [pid 66623:tid 66813] [client 40.74.65.169:45379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/key.php"] [unique_id "aoSBKtO5rbWdOArH04KoFAAAATk"] [Tue Aug 18 12:58:34.583865 2026] [security2:error] [pid 66623:tid 66814] [client 20.250.13.23:53660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/buy.php"] [unique_id "aoSBKtO5rbWdOArH04KoLgAAATo"] [Tue Aug 18 12:58:34.601467 2026] [security2:error] [pid 66623:tid 66883] [client 20.79.204.6:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBKtO5rbWdOArH04KoOAAAAX8"] [Tue Aug 18 12:58:34.614414 2026] [security2:error] [pid 66623:tid 66788] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBKtO5rbWdOArH04KoOQAAASA"] [Tue Aug 18 12:58:34.623466 2026] [security2:error] [pid 66623:tid 66806] [client 138.36.100.162:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoPAAAATI"] [Tue Aug 18 12:58:34.623572 2026] [security2:error] [pid 66623:tid 66806] [client 138.36.100.162:42094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBKtO5rbWdOArH04KoPAAAATI"] [Tue Aug 18 12:58:34.631075 2026] [security2:error] [pid 66623:tid 66815] [client 40.74.65.169:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBKtO5rbWdOArH04KoPQAAATs"] [Tue Aug 18 12:58:34.637053 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSBKtO5rbWdOArH04KoPgABWBU"] [Tue Aug 18 12:58:34.645128 2026] [security2:error] [pid 66623:tid 66863] [client 52.173.121.69:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/bhfnd.php"] [unique_id "aoSBKtO5rbWdOArH04KoPwAAAWs"] [Tue Aug 18 12:58:34.669559 2026] [authz_core:error] [pid 66623:tid 66729] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:34.669836 2026] [authz_core:error] [pid 66623:tid 66729] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:34.686672 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:8116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBKtO5rbWdOArH04KoQwAAAXc"] [Tue Aug 18 12:58:34.686689 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:7692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sid4.php"] [unique_id "aoSBKtO5rbWdOArH04KoRAAAAXk"] [Tue Aug 18 12:58:34.704697 2026] [security2:error] [pid 66623:tid 66820] [client 20.104.85.180:42269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/zxz.php"] [unique_id "aoSBKtO5rbWdOArH04KoRgAAAUA"] [Tue Aug 18 12:58:34.706798 2026] [security2:error] [pid 66623:tid 66869] [client 20.118.172.148:19662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/inputs.php"] [unique_id "aoSBKtO5rbWdOArH04KoRwAAAXE"] [Tue Aug 18 12:58:34.764780 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "aoSBKtO5rbWdOArH04KoSQAAATE"] [Tue Aug 18 12:58:34.806976 2026] [security2:error] [pid 66623:tid 66697] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kk.php"] [unique_id "aoSBKtO5rbWdOArH04KoUgABGDw"] [Tue Aug 18 12:58:34.815442 2026] [security2:error] [pid 66623:tid 66711] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBKtO5rbWdOArH04KoVAABaEo"] [Tue Aug 18 12:58:34.859105 2026] [security2:error] [pid 66623:tid 66781] [client 158.23.17.4:34020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nf.php"] [unique_id "aoSBKtO5rbWdOArH04KoWQAAARk"] [Tue Aug 18 12:58:34.939917 2026] [security2:error] [pid 66623:tid 66773] [client 4.232.151.198:30020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "aoSBKtO5rbWdOArH04KoWgAAARE"] [Tue Aug 18 12:58:34.970345 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:34.970624 2026] [authz_core:error] [pid 66623:tid 66758] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:34.980048 2026] [security2:error] [pid 66623:tid 66827] [client 20.118.133.132:26302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/puc.php"] [unique_id "aoSBKtO5rbWdOArH04KoXQAAAUc"] [Tue Aug 18 12:58:35.000385 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBKtO5rbWdOArH04KoXwABdEA"] [Tue Aug 18 12:58:35.012617 2026] [security2:error] [pid 66623:tid 66880] [client 68.155.155.199:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/abcd.php"] [unique_id "aoSBK9O5rbWdOArH04KoYAAAAXw"] [Tue Aug 18 12:58:35.043307 2026] [autoindex:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:35.088566 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/qfvqu.php"] [unique_id "aoSBK9O5rbWdOArH04KoZgAAAUg"] [Tue Aug 18 12:58:35.099622 2026] [security2:error] [pid 66623:tid 66774] [client 20.127.136.245:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/av.php"] [unique_id "aoSBK9O5rbWdOArH04KoZwAAARI"] [Tue Aug 18 12:58:35.114631 2026] [security2:error] [pid 66623:tid 66803] [client 178.153.171.161:9936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoaQAAAS8"] [Tue Aug 18 12:58:35.114936 2026] [security2:error] [pid 66623:tid 66803] [client 178.153.171.161:9936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoaQAAAS8"] [Tue Aug 18 12:58:35.128961 2026] [security2:error] [pid 66623:tid 66893] [client 213.35.127.232:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBK9O5rbWdOArH04KoawAAAYk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:35.182462 2026] [security2:error] [pid 66623:tid 66847] [client 20.119.58.187:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/classsmtps.php"] [unique_id "aoSBK9O5rbWdOArH04KobAAAAVs"] [Tue Aug 18 12:58:35.204391 2026] [security2:error] [pid 66623:tid 66675] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KobQABhCY"] [Tue Aug 18 12:58:35.204539 2026] [security2:error] [pid 66623:tid 66888] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KobQABhCY"] [Tue Aug 18 12:58:35.207275 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dg.php"] [unique_id "aoSBK9O5rbWdOArH04KocAABUDM"] [Tue Aug 18 12:58:35.219262 2026] [autoindex:error] [pid 66623:tid 66808] [client 20.79.204.6:11688] AH01276: Cannot serve directory /home2/rscon195/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:35.247190 2026] [security2:error] [pid 66623:tid 66835] [client 20.250.13.23:1812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/cong.php"] [unique_id "aoSBK9O5rbWdOArH04KodQAAAU8"] [Tue Aug 18 12:58:35.267833 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:35.268107 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:35.285502 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:54563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/www.php"] [unique_id "aoSBK9O5rbWdOArH04KoeQAAATw"] [Tue Aug 18 12:58:35.294951 2026] [security2:error] [pid 66623:tid 66814] [client 40.74.65.169:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/chosen.php"] [unique_id "aoSBK9O5rbWdOArH04KoegAAATo"] [Tue Aug 18 12:58:35.296575 2026] [autoindex:error] [pid 66623:tid 66757] [remote 68.155.154.146:0] AH01276: Cannot serve directory /home4/bioclimaarcondic/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:35.336197 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:19460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBK9O5rbWdOArH04KofAAAAWE"] [Tue Aug 18 12:58:35.349096 2026] [security2:error] [pid 66623:tid 66815] [client 52.173.121.69:16473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/index/function.php"] [unique_id "aoSBK9O5rbWdOArH04KofQAAATs"] [Tue Aug 18 12:58:35.367534 2026] [security2:error] [pid 66623:tid 66770] [client 20.118.172.148:63079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBK9O5rbWdOArH04KofwAAAQ4"] [Tue Aug 18 12:58:35.420339 2026] [security2:error] [pid 66623:tid 66807] [client 20.79.204.6:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBK9O5rbWdOArH04KogQAAATM"] [Tue Aug 18 12:58:35.436032 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bm.php"] [unique_id "aoSBK9O5rbWdOArH04KohAABgkc"] [Tue Aug 18 12:58:35.487149 2026] [security2:error] [pid 66623:tid 66750] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBK9O5rbWdOArH04KoiAABP3E"] [Tue Aug 18 12:58:35.535904 2026] [security2:error] [pid 66623:tid 66820] [client 20.119.58.187:11877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBK9O5rbWdOArH04KojAAAAUA"] [Tue Aug 18 12:58:35.538212 2026] [security2:error] [pid 66623:tid 66829] [client 52.173.121.69:49021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/oivcl.php"] [unique_id "aoSBK9O5rbWdOArH04KojQAAAUk"] [Tue Aug 18 12:58:35.572816 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:35.573253 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:35.578915 2026] [security2:error] [pid 66623:tid 66801] [client 20.48.236.86:36116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBK9O5rbWdOArH04KokAAAAS0"] [Tue Aug 18 12:58:35.605272 2026] [security2:error] [pid 66623:tid 66879] [client 158.23.17.4:44857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xv.php"] [unique_id "aoSBK9O5rbWdOArH04KomAAAAXs"] [Tue Aug 18 12:58:35.624083 2026] [security2:error] [pid 66623:tid 66810] [client 20.100.169.31:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBK9O5rbWdOArH04KonQAAATY"] [Tue Aug 18 12:58:35.633733 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBK9O5rbWdOArH04KongAAARE"] [Tue Aug 18 12:58:35.637397 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vu.php"] [unique_id "aoSBK9O5rbWdOArH04KonwABWgs"] [Tue Aug 18 12:58:35.669197 2026] [security2:error] [pid 66623:tid 66775] [client 74.248.18.37:47288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/size.php"] [unique_id "aoSBK9O5rbWdOArH04KooQAAARM"] [Tue Aug 18 12:58:35.670739 2026] [security2:error] [pid 66623:tid 66686] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/login.php"] [unique_id "aoSBK9O5rbWdOArH04KoogABUzE"] [Tue Aug 18 12:58:35.692429 2026] [security2:error] [pid 66623:tid 66864] [client 74.248.18.37:47238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBK9O5rbWdOArH04KopAAAAWw"] [Tue Aug 18 12:58:35.706983 2026] [security2:error] [pid 66623:tid 66774] [client 20.104.85.180:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wicked.php"] [unique_id "aoSBK9O5rbWdOArH04KopQAAARI"] [Tue Aug 18 12:58:35.765459 2026] [security2:error] [pid 66623:tid 66849] [client 20.206.73.37:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/uwu.php"] [unique_id "aoSBK9O5rbWdOArH04KopwAAAV0"] [Tue Aug 18 12:58:35.789460 2026] [security2:error] [pid 66623:tid 66851] [client 223.185.37.47:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoqAAAAV8"] [Tue Aug 18 12:58:35.789564 2026] [security2:error] [pid 66623:tid 66851] [client 223.185.37.47:3937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KoqAAAAV8"] [Tue Aug 18 12:58:35.793257 2026] [security2:error] [pid 66623:tid 66882] [client 4.232.151.198:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/images/Mhbgf.php"] [unique_id "aoSBK9O5rbWdOArH04KoqQAAAX4"] [Tue Aug 18 12:58:35.815669 2026] [security2:error] [pid 66623:tid 66653] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ic.php"] [unique_id "aoSBK9O5rbWdOArH04KorQABhBA"] [Tue Aug 18 12:58:35.821752 2026] [security2:error] [pid 66623:tid 66811] [client 85.154.68.202:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KorwAAATc"] [Tue Aug 18 12:58:35.821894 2026] [security2:error] [pid 66623:tid 66811] [client 85.154.68.202:57796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBK9O5rbWdOArH04KorwAAATc"] [Tue Aug 18 12:58:35.833265 2026] [security2:error] [pid 66623:tid 66737] [remote 172.238.58.237:50604] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBK9O5rbWdOArH04KosAABdGQ"] [Tue Aug 18 12:58:35.853175 2026] [security2:error] [pid 66623:tid 66755] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/min.php"] [unique_id "aoSBK9O5rbWdOArH04KosQABKHY"] [Tue Aug 18 12:58:35.863141 2026] [security2:error] [pid 66623:tid 66837] [client 20.250.13.23:45753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBK9O5rbWdOArH04KotAAAAVE"] [Tue Aug 18 12:58:35.869089 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:35.869380 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:35.887979 2026] [security2:error] [pid 66623:tid 66868] [client 20.119.58.187:11879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBK9O5rbWdOArH04KotgAAAXA"] [Tue Aug 18 12:58:35.901601 2026] [security2:error] [pid 66623:tid 66771] [client 20.203.138.185:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBK9O5rbWdOArH04KouQAAAQ8"] [Tue Aug 18 12:58:35.970186 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/sky.php"] [unique_id "aoSBK9O5rbWdOArH04KovAAAAWQ"] [Tue Aug 18 12:58:35.989944 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/thoms.php"] [unique_id "aoSBK9O5rbWdOArH04KovgAAAWE"] [Tue Aug 18 12:58:36.003796 2026] [security2:error] [pid 66623:tid 66763] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ue.php"] [unique_id "aoSBLNO5rbWdOArH04KovwABa34"] [Tue Aug 18 12:58:36.036332 2026] [security2:error] [pid 66623:tid 66776] [client 40.74.65.169:20102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/domvf.php"] [unique_id "aoSBLNO5rbWdOArH04KowgAAARQ"] [Tue Aug 18 12:58:36.043898 2026] [security2:error] [pid 66623:tid 66639] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBLNO5rbWdOArH04KowwABTQI"] [Tue Aug 18 12:58:36.048398 2026] [access_compat:error] [pid 66623:tid 66881] [client 173.252.70.82:41546] AH01797: client denied by server configuration: /home1/canabarro/public_html/meta.json [Tue Aug 18 12:58:36.094841 2026] [security2:error] [pid 66623:tid 66854] [client 20.79.204.6:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rsconstrutora.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBLNO5rbWdOArH04KoyQAAAWI"] [Tue Aug 18 12:58:36.144848 2026] [security2:error] [pid 66623:tid 66817] [client 213.35.127.232:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBLNO5rbWdOArH04KoywAAAT0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:36.168073 2026] [security2:error] [pid 66623:tid 66820] [client 172.202.39.151:40338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBLNO5rbWdOArH04KozwAAAUA"] [Tue Aug 18 12:58:36.171525 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:36.171798 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:36.174763 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lr.php"] [unique_id "aoSBLNO5rbWdOArH04Ko0AABLUE"] [Tue Aug 18 12:58:36.223887 2026] [security2:error] [pid 66623:tid 66714] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/network/post.php"] [unique_id "aoSBLNO5rbWdOArH04Ko1AABNk0"] [Tue Aug 18 12:58:36.242770 2026] [security2:error] [pid 66623:tid 66825] [client 20.119.58.187:12508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-cron.php"] [unique_id "aoSBLNO5rbWdOArH04Ko1gAAAUU"] [Tue Aug 18 12:58:36.265683 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:35569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zugvi.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2AAAAUc"] [Tue Aug 18 12:58:36.277490 2026] [security2:error] [pid 66623:tid 66839] [client 20.104.85.180:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2QAAAVM"] [Tue Aug 18 12:58:36.283068 2026] [security2:error] [pid 66623:tid 66850] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file5.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2gAAAV4"] [Tue Aug 18 12:58:36.285437 2026] [security2:error] [pid 66623:tid 66823] [client 20.250.13.23:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBLNO5rbWdOArH04Ko2wAAAUM"] [Tue Aug 18 12:58:36.324035 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3QAAATI"] [Tue Aug 18 12:58:36.331532 2026] [security2:error] [pid 66623:tid 66774] [client 4.232.94.69:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3gAAARI"] [Tue Aug 18 12:58:36.351317 2026] [security2:error] [pid 66623:tid 66660] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ka.php"] [unique_id "aoSBLNO5rbWdOArH04Ko3wABLxc"] [Tue Aug 18 12:58:36.363859 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSBLNO5rbWdOArH04Ko4QAAAV8"] [Tue Aug 18 12:58:36.403613 2026] [security2:error] [pid 66623:tid 66718] [remote 172.238.58.237:50620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLNO5rbWdOArH04Ko4wABW1E"] [Tue Aug 18 12:58:36.413188 2026] [security2:error] [pid 66623:tid 66668] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/test.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5QABhB8"] [Tue Aug 18 12:58:36.414902 2026] [security2:error] [pid 66623:tid 66811] [client 20.215.241.237:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/82.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5gAAATc"] [Tue Aug 18 12:58:36.426243 2026] [security2:error] [pid 66623:tid 66819] [client 74.248.18.37:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/special.php"] [unique_id "aoSBLNO5rbWdOArH04Ko5wAAAT8"] [Tue Aug 18 12:58:36.432460 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:47261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko6AAAARg"] [Tue Aug 18 12:58:36.473510 2026] [authz_core:error] [pid 66623:tid 66680] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:36.473804 2026] [authz_core:error] [pid 66623:tid 66680] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:36.489361 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:12296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/NewFile.php"] [unique_id "aoSBLNO5rbWdOArH04Ko6wAAAXg"] [Tue Aug 18 12:58:36.525085 2026] [security2:error] [pid 66623:tid 66791] [client 20.250.13.23:1807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/db.php"] [unique_id "aoSBLNO5rbWdOArH04Ko7wAAASM"] [Tue Aug 18 12:58:36.533675 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ot.php"] [unique_id "aoSBLNO5rbWdOArH04Ko8QABbwE"] [Tue Aug 18 12:58:36.592841 2026] [security2:error] [pid 66623:tid 66642] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9AABbgU"] [Tue Aug 18 12:58:36.596365 2026] [security2:error] [pid 66623:tid 66824] [client 52.173.121.69:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9QAAAUQ"] [Tue Aug 18 12:58:36.600022 2026] [security2:error] [pid 66623:tid 66769] [client 20.119.58.187:11899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-load.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9gAAAQ0"] [Tue Aug 18 12:58:36.600119 2026] [security2:error] [pid 66623:tid 66856] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/xyn.php"] [unique_id "aoSBLNO5rbWdOArH04Ko9wAAAWQ"] [Tue Aug 18 12:58:36.656761 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSBLNO5rbWdOArH04Ko-gAAAVQ"] [Tue Aug 18 12:58:36.706158 2026] [security2:error] [pid 66623:tid 66783] [client 20.104.85.180:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_AAAARs"] [Tue Aug 18 12:58:36.725299 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:20300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_QAAATA"] [Tue Aug 18 12:58:36.732709 2026] [security2:error] [pid 66623:tid 66859] [client 158.23.17.4:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mx.php"] [unique_id "aoSBLNO5rbWdOArH04Ko_gAAAWc"] [Tue Aug 18 12:58:36.754257 2026] [security2:error] [pid 66623:tid 66852] [client 40.74.65.169:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/wpxml.php"] [unique_id "aoSBLNO5rbWdOArH04KpAQAAAWA"] [Tue Aug 18 12:58:36.777619 2026] [security2:error] [pid 66623:tid 66820] [client 20.48.236.86:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/php.php"] [unique_id "aoSBLNO5rbWdOArH04KpAwAAAUA"] [Tue Aug 18 12:58:36.780191 2026] [security2:error] [pid 66623:tid 66728] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ih.php"] [unique_id "aoSBLNO5rbWdOArH04KpBAABg1s"] [Tue Aug 18 12:58:36.841898 2026] [security2:error] [pid 66623:tid 66879] [client 20.127.136.245:7631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp.php"] [unique_id "aoSBLNO5rbWdOArH04KpBgAAAXs"] [Tue Aug 18 12:58:36.923153 2026] [security2:error] [pid 66623:tid 66839] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBLNO5rbWdOArH04KpCgAAAVM"] [Tue Aug 18 12:58:36.941219 2026] [security2:error] [pid 66623:tid 66864] [client 52.173.121.69:32607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wsrer.php"] [unique_id "aoSBLNO5rbWdOArH04KpDgAAAWw"] [Tue Aug 18 12:58:36.952274 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/k.php"] [unique_id "aoSBLNO5rbWdOArH04KpEAABICk"] [Tue Aug 18 12:58:36.962487 2026] [security2:error] [pid 66623:tid 66719] [remote 172.238.58.237:50626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLNO5rbWdOArH04KpEQABGVI"] [Tue Aug 18 12:58:36.969280 2026] [security2:error] [pid 66623:tid 66860] [client 20.119.58.187:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBLNO5rbWdOArH04KpEgAAAWg"] [Tue Aug 18 12:58:37.023597 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:43485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/lite.php"] [unique_id "aoSBLdO5rbWdOArH04KpEwAAAS8"] [Tue Aug 18 12:58:37.078473 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:37.078760 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:37.084440 2026] [security2:error] [pid 66623:tid 66689] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/user/min.php"] [unique_id "aoSBLdO5rbWdOArH04KpFwABfjQ"] [Tue Aug 18 12:58:37.105483 2026] [security2:error] [pid 66623:tid 66825] [client 74.248.18.37:8127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBLdO5rbWdOArH04KpGAAAAUU"] [Tue Aug 18 12:58:37.137322 2026] [security2:error] [pid 66623:tid 66823] [client 20.250.13.23:1822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/dropdown.php"] [unique_id "aoSBLdO5rbWdOArH04KpGgAAAUM"] [Tue Aug 18 12:58:37.155655 2026] [security2:error] [pid 66623:tid 66807] [client 213.35.127.232:52544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBLdO5rbWdOArH04KpHgAAATM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:37.158884 2026] [authz_core:error] [pid 66623:tid 66745] [remote 57.141.22.95:45588] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:37.159158 2026] [authz_core:error] [pid 66623:tid 66745] [remote 57.141.22.95:45588] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:37.160336 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.155.199:7036] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin/controller/extension/extension/"] [unique_id "aoSBLdO5rbWdOArH04KpHwAAASk"] [Tue Aug 18 12:58:37.162711 2026] [security2:error] [pid 66623:tid 66731] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iu.php"] [unique_id "aoSBLdO5rbWdOArH04KpIAABRl4"] [Tue Aug 18 12:58:37.178696 2026] [security2:error] [pid 66623:tid 66780] [client 20.203.138.185:10812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/z.php"] [unique_id "aoSBLdO5rbWdOArH04KpIQAAARg"] [Tue Aug 18 12:58:37.185229 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.18.37:7690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSBLdO5rbWdOArH04KpIgAAAVo"] [Tue Aug 18 12:58:37.187417 2026] [security2:error] [pid 66623:tid 66811] [client 192.141.172.134:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBLdO5rbWdOArH04KpIwAAATc"] [Tue Aug 18 12:58:37.187496 2026] [security2:error] [pid 66623:tid 66811] [client 192.141.172.134:51411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBLdO5rbWdOArH04KpIwAAATc"] [Tue Aug 18 12:58:37.231551 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cah.php"] [unique_id "aoSBLdO5rbWdOArH04KpJwAAAXU"] [Tue Aug 18 12:58:37.263574 2026] [security2:error] [pid 66623:tid 66733] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/users.php"] [unique_id "aoSBLdO5rbWdOArH04KpKAABQmA"] [Tue Aug 18 12:58:37.286752 2026] [security2:error] [pid 66623:tid 66851] [client 4.232.151.198:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/router.php"] [unique_id "aoSBLdO5rbWdOArH04KpKQAAAV8"] [Tue Aug 18 12:58:37.322677 2026] [security2:error] [pid 66623:tid 66796] [client 20.119.58.187:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/berlin.php"] [unique_id "aoSBLdO5rbWdOArH04KpKwAAASg"] [Tue Aug 18 12:58:37.347858 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pk.php"] [unique_id "aoSBLdO5rbWdOArH04KpLAABaXc"] [Tue Aug 18 12:58:37.375071 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:37.375354 2026] [authz_core:error] [pid 66623:tid 66694] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:37.404746 2026] [security2:error] [pid 66623:tid 66842] [client 40.74.65.169:42467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gec.php"] [unique_id "aoSBLdO5rbWdOArH04KpNQAAAVY"] [Tue Aug 18 12:58:37.444557 2026] [security2:error] [pid 66623:tid 66645] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSBLdO5rbWdOArH04KpNgABRAg"] [Tue Aug 18 12:58:37.521656 2026] [security2:error] [pid 66623:tid 66799] [client 20.100.169.31:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBLdO5rbWdOArH04KpOgAAASs"] [Tue Aug 18 12:58:37.552531 2026] [security2:error] [pid 66623:tid 66710] [remote 172.238.58.237:50634] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "cargaedescargatiofe.com.br"] [uri "/"] [unique_id "aoSBLdO5rbWdOArH04KpPAABhkk"] [Tue Aug 18 12:58:37.556682 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ge.php"] [unique_id "aoSBLdO5rbWdOArH04KpPwABiDA"] [Tue Aug 18 12:58:37.590992 2026] [security2:error] [pid 66623:tid 66783] [client 40.74.65.169:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/file1221.php"] [unique_id "aoSBLdO5rbWdOArH04KpQgAAARs"] [Tue Aug 18 12:58:37.633874 2026] [security2:error] [pid 66623:tid 66726] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSBLdO5rbWdOArH04KpRAABV1k"] [Tue Aug 18 12:58:37.679131 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:37.679579 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:37.709843 2026] [security2:error] [pid 66623:tid 66854] [client 20.48.236.86:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/sf.php"] [unique_id "aoSBLdO5rbWdOArH04KpSAAAAWI"] [Tue Aug 18 12:58:37.710962 2026] [security2:error] [pid 66623:tid 66848] [client 20.206.73.37:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/signon.php"] [unique_id "aoSBLdO5rbWdOArH04KpSQAAAVw"] [Tue Aug 18 12:58:37.743108 2026] [security2:error] [pid 66623:tid 66790] [client 20.119.58.187:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/not/includes/php8.php"] [unique_id "aoSBLdO5rbWdOArH04KpTAAAASI"] [Tue Aug 18 12:58:37.751584 2026] [security2:error] [pid 66623:tid 66840] [client 20.250.13.23:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/file.php"] [unique_id "aoSBLdO5rbWdOArH04KpTgAAAVQ"] [Tue Aug 18 12:58:37.768137 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/ucpfr.php"] [unique_id "aoSBLdO5rbWdOArH04KpTwAAAT4"] [Tue Aug 18 12:58:37.782524 2026] [security2:error] [pid 66623:tid 66752] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kl.php"] [unique_id "aoSBLdO5rbWdOArH04KpUQABNnM"] [Tue Aug 18 12:58:37.805880 2026] [security2:error] [pid 66623:tid 66877] [client 74.248.18.37:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBLdO5rbWdOArH04KpUwAAAXk"] [Tue Aug 18 12:58:37.811089 2026] [security2:error] [pid 66623:tid 66777] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/inso.php"] [unique_id "aoSBLdO5rbWdOArH04KpVAAAARU"] [Tue Aug 18 12:58:37.816455 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSBLdO5rbWdOArH04KpVgABZVA"] [Tue Aug 18 12:58:37.877856 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/storage/index.php"] [unique_id "aoSBLdO5rbWdOArH04KpWgAAAYI"] [Tue Aug 18 12:58:37.928381 2026] [security2:error] [pid 66623:tid 66882] [client 20.104.85.180:50357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/system_log.php"] [unique_id "aoSBLdO5rbWdOArH04KpXQAAAX4"] [Tue Aug 18 12:58:37.928863 2026] [security2:error] [pid 66623:tid 66767] [client 79.127.164.8:45708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sessions.bak"] [unique_id "aoSBLdO5rbWdOArH04KpXAAAAQs"], referer: https://medihub.com.br/sessions.bak [Tue Aug 18 12:58:37.978226 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:37.978494 2026] [authz_core:error] [pid 66623:tid 66663] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:37.991999 2026] [security2:error] [pid 66623:tid 66661] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSBLdO5rbWdOArH04KpYgABKRg"] [Tue Aug 18 12:58:38.008566 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gs.php"] [unique_id "aoSBLtO5rbWdOArH04KpZAABRig"] [Tue Aug 18 12:58:38.038794 2026] [security2:error] [pid 66623:tid 66839] [client 4.232.151.198:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/shop.php"] [unique_id "aoSBLtO5rbWdOArH04KpZgAAAVM"] [Tue Aug 18 12:58:38.060106 2026] [security2:error] [pid 66623:tid 66812] [client 216.73.161.209:45265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSBLtO5rbWdOArH04KpaAAAATg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:58:38.089677 2026] [security2:error] [pid 66623:tid 66837] [client 40.74.65.169:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/sky.php"] [unique_id "aoSBLtO5rbWdOArH04KpagAAAVE"] [Tue Aug 18 12:58:38.100784 2026] [security2:error] [pid 66623:tid 66830] [client 20.119.58.187:12499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-theme-editor/php8.php/wp-content/themes/aahana/json.php"] [unique_id "aoSBLtO5rbWdOArH04KpbAAAAUo"] [Tue Aug 18 12:58:38.131915 2026] [security2:error] [pid 66623:tid 66789] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/puc.php"] [unique_id "aoSBLtO5rbWdOArH04KpbQAAASE"] [Tue Aug 18 12:58:38.168991 2026] [security2:error] [pid 66623:tid 66871] [client 213.35.127.232:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBLtO5rbWdOArH04KpcQAAAXM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:38.171931 2026] [security2:error] [pid 66623:tid 66736] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBLtO5rbWdOArH04KpcgABD2M"] [Tue Aug 18 12:58:38.172945 2026] [security2:error] [pid 66623:tid 66893] [client 172.202.39.151:44491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gelay.php"] [unique_id "aoSBLtO5rbWdOArH04KpcwAAAYk"] [Tue Aug 18 12:58:38.186115 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lw.php"] [unique_id "aoSBLtO5rbWdOArH04KpdAABJ3k"] [Tue Aug 18 12:58:38.245706 2026] [security2:error] [pid 66623:tid 66884] [client 4.232.94.69:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/x.php"] [unique_id "aoSBLtO5rbWdOArH04KpdwAAAYA"] [Tue Aug 18 12:58:38.282409 2026] [security2:error] [pid 66623:tid 66799] [client 40.74.65.169:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/nox.php"] [unique_id "aoSBLtO5rbWdOArH04KpfAAAASs"] [Tue Aug 18 12:58:38.342547 2026] [authz_core:error] [pid 66623:tid 66656] [remote 57.141.22.123:20168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:38.342830 2026] [authz_core:error] [pid 66623:tid 66656] [remote 57.141.22.123:20168] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:38.354420 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/yxijx.php"] [unique_id "aoSBLtO5rbWdOArH04KpgQAAAUs"] [Tue Aug 18 12:58:38.355222 2026] [security2:error] [pid 66623:tid 66648] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-admin/x.php"] [unique_id "aoSBLtO5rbWdOArH04KpggABfQs"] [Tue Aug 18 12:58:38.364356 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/45.php"] [unique_id "aoSBLtO5rbWdOArH04KpgwAAAXE"] [Tue Aug 18 12:58:38.365212 2026] [security2:error] [pid 66623:tid 66867] [client 20.250.13.23:17835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/goods.php"] [unique_id "aoSBLtO5rbWdOArH04KphAAAAW8"] [Tue Aug 18 12:58:38.443676 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:28658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/f35.php"] [unique_id "aoSBLtO5rbWdOArH04KpjgAAAVw"] [Tue Aug 18 12:58:38.443886 2026] [security2:error] [pid 66623:tid 66859] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/19.php"] [unique_id "aoSBLtO5rbWdOArH04KpjwAAAWc"] [Tue Aug 18 12:58:38.445021 2026] [security2:error] [pid 66623:tid 66737] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vj.php"] [unique_id "aoSBLtO5rbWdOArH04KpkAABZ2Q"] [Tue Aug 18 12:58:38.454688 2026] [security2:error] [pid 66623:tid 66809] [client 20.119.58.187:11893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/php8.php"] [unique_id "aoSBLtO5rbWdOArH04KpkQAAATU"] [Tue Aug 18 12:58:38.485993 2026] [security2:error] [pid 66623:tid 66820] [client 20.203.138.185:24300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/222.php"] [unique_id "aoSBLtO5rbWdOArH04KpkwAAAUA"] [Tue Aug 18 12:58:38.504779 2026] [security2:error] [pid 66623:tid 66793] [client 68.155.155.199:6207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBLtO5rbWdOArH04KplQAAASU"] [Tue Aug 18 12:58:38.534080 2026] [security2:error] [pid 66623:tid 66676] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBLtO5rbWdOArH04KplgABNic"] [Tue Aug 18 12:58:38.591168 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:7674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBLtO5rbWdOArH04KpmQAAAVI"] [Tue Aug 18 12:58:38.604161 2026] [security2:error] [pid 66623:tid 66864] [client 20.48.236.86:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/xx.php"] [unique_id "aoSBLtO5rbWdOArH04KpmgAAAWw"] [Tue Aug 18 12:58:38.631429 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBLtO5rbWdOArH04KpmwAAATA"] [Tue Aug 18 12:58:38.662904 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mimes.php"] [unique_id "aoSBLtO5rbWdOArH04KpnAABLwY"] [Tue Aug 18 12:58:38.668986 2026] [security2:error] [pid 66623:tid 66889] [client 20.104.85.180:15163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBLtO5rbWdOArH04KpogAAAYU"] [Tue Aug 18 12:58:38.671028 2026] [security2:error] [pid 66623:tid 66790] [client 4.232.151.198:30064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-info.php"] [unique_id "aoSBLtO5rbWdOArH04KpowAAASI"] [Tue Aug 18 12:58:38.703147 2026] [security2:error] [pid 66623:tid 66882] [client 20.118.133.132:26254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/19.php"] [unique_id "aoSBLtO5rbWdOArH04KppQAAAX4"] [Tue Aug 18 12:58:38.726024 2026] [security2:error] [pid 66623:tid 66847] [client 52.173.121.69:24994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/Cachex.php"] [unique_id "aoSBLtO5rbWdOArH04KppwAAAVs"] [Tue Aug 18 12:58:38.736407 2026] [security2:error] [pid 66623:tid 66700] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSBLtO5rbWdOArH04KpqQABGj8"] [Tue Aug 18 12:58:38.743671 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:11959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file61.php"] [unique_id "aoSBLtO5rbWdOArH04KpqwAAARg"] [Tue Aug 18 12:58:38.776874 2026] [security2:error] [pid 66623:tid 66873] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/133.php"] [unique_id "aoSBLtO5rbWdOArH04KpswAAAXU"] [Tue Aug 18 12:58:38.783945 2026] [security2:error] [pid 66623:tid 66851] [client 40.74.65.169:20125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/sixxis.php"] [unique_id "aoSBLtO5rbWdOArH04KptAAAAV8"] [Tue Aug 18 12:58:38.822142 2026] [security2:error] [pid 66623:tid 66767] [client 20.119.58.187:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/php8.php"] [unique_id "aoSBLtO5rbWdOArH04KpuQAAAQs"] [Tue Aug 18 12:58:38.834765 2026] [security2:error] [pid 66623:tid 66879] [client 74.248.18.37:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/storage/rip.php"] [unique_id "aoSBLtO5rbWdOArH04KpugAAAXs"] [Tue Aug 18 12:58:38.873131 2026] [security2:error] [pid 66623:tid 66825] [client 20.25.139.174:4645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/inputs.php"] [unique_id "aoSBLtO5rbWdOArH04KpwAAAAUU"] [Tue Aug 18 12:58:38.927132 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ni.php"] [unique_id "aoSBLtO5rbWdOArH04KpwgABFEE"] [Tue Aug 18 12:58:38.946536 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:48992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/zwlsv.php"] [unique_id "aoSBLtO5rbWdOArH04KpxAAAAUs"] [Tue Aug 18 12:58:38.979549 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBLtO5rbWdOArH04KpyAAAARY"] [Tue Aug 18 12:58:39.038037 2026] [security2:error] [pid 66623:tid 66764] [remote 162.43.94.44:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.94.43.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBL9O5rbWdOArH04KpygABYn8"] [Tue Aug 18 12:58:39.126377 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "suporte.automasantos.com.br"] [uri "/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp1QABSQE"] [Tue Aug 18 12:58:39.126493 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp1QABSQE"] [Tue Aug 18 12:58:39.161214 2026] [security2:error] [pid 66623:tid 66868] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mo.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2QAAAXA"] [Tue Aug 18 12:58:39.165556 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2gABKE4"] [Tue Aug 18 12:58:39.165641 2026] [security2:error] [pid 66623:tid 66715] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2gABKE4"] [Tue Aug 18 12:58:39.174695 2026] [security2:error] [pid 66623:tid 66852] [client 20.119.58.187:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/banners/php8.php"] [unique_id "aoSBL9O5rbWdOArH04Kp2wAAAWA"] [Tue Aug 18 12:58:39.183112 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:39.183393 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:39.184669 2026] [security2:error] [pid 66623:tid 66787] [client 213.35.127.232:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBL9O5rbWdOArH04Kp3QAAAR8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:39.243122 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:31259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBL9O5rbWdOArH04Kp4gAAAS8"] [Tue Aug 18 12:58:39.253636 2026] [security2:error] [pid 66623:tid 66889] [client 172.202.39.151:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp4wAAAYU"] [Tue Aug 18 12:58:39.254016 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/akismet.php"] [unique_id "aoSBL9O5rbWdOArH04Kp5AAAAXY"] [Tue Aug 18 12:58:39.279221 2026] [security2:error] [pid 66623:tid 66878] [client 4.232.94.69:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/filemanager.php"] [unique_id "aoSBL9O5rbWdOArH04Kp5gAAAXo"] [Tue Aug 18 12:58:39.306396 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/88.php"] [unique_id "aoSBL9O5rbWdOArH04Kp6AABhCM"] [Tue Aug 18 12:58:39.342539 2026] [security2:error] [pid 66623:tid 66742] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp6wABGGk"] [Tue Aug 18 12:58:39.354570 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:42688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/jrpga.php"] [unique_id "aoSBL9O5rbWdOArH04Kp7QAAAUY"] [Tue Aug 18 12:58:39.389517 2026] [security2:error] [pid 66623:tid 66887] [client 74.248.18.37:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBL9O5rbWdOArH04Kp7wAAAYM"] [Tue Aug 18 12:58:39.393933 2026] [security2:error] [pid 66623:tid 66860] [client 20.25.139.174:4632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/admin.php"] [unique_id "aoSBL9O5rbWdOArH04Kp8AAAAWg"] [Tue Aug 18 12:58:39.397038 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.151.198:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/public_html/wp-content/uploads/users.php"] [unique_id "aoSBL9O5rbWdOArH04Kp8QAAAQ0"] [Tue Aug 18 12:58:39.440973 2026] [security2:error] [pid 66623:tid 66830] [client 20.127.136.245:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file2.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9AAAAUo"] [Tue Aug 18 12:58:39.472783 2026] [security2:error] [pid 66623:tid 66792] [client 40.74.65.169:20106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/yj09.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9QAAASQ"] [Tue Aug 18 12:58:39.484343 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:39.484611 2026] [authz_core:error] [pid 66623:tid 66704] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:39.492456 2026] [security2:error] [pid 66623:tid 66824] [client 196.12.128.158:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9wAAAUQ"] [Tue Aug 18 12:58:39.492552 2026] [security2:error] [pid 66623:tid 66824] [client 196.12.128.158:59191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04Kp9wAAAUQ"] [Tue Aug 18 12:58:39.496420 2026] [security2:error] [pid 66623:tid 66882] [client 74.248.18.37:47253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sts.php"] [unique_id "aoSBL9O5rbWdOArH04Kp-AAAAX4"] [Tue Aug 18 12:58:39.520368 2026] [security2:error] [pid 66623:tid 66649] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/api.php"] [unique_id "aoSBL9O5rbWdOArH04Kp-wABcgw"] [Tue Aug 18 12:58:39.528618 2026] [security2:error] [pid 66623:tid 66785] [client 20.119.58.187:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/php8.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_AAAAR0"] [Tue Aug 18 12:58:39.565310 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:14549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/inputs.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_gAAAYk"] [Tue Aug 18 12:58:39.565777 2026] [security2:error] [pid 66623:tid 66692] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hj.php"] [unique_id "aoSBL9O5rbWdOArH04Kp_wABLDc"] [Tue Aug 18 12:58:39.595617 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/1xmomo.php"] [unique_id "aoSBL9O5rbWdOArH04KqBAAAAW4"] [Tue Aug 18 12:58:39.614258 2026] [security2:error] [pid 66623:tid 66812] [client 20.250.13.23:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/htaccess.php"] [unique_id "aoSBL9O5rbWdOArH04KqBQAAATg"] [Tue Aug 18 12:58:39.720064 2026] [security2:error] [pid 66623:tid 66658] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSBL9O5rbWdOArH04KqGgABfRU"] [Tue Aug 18 12:58:39.736646 2026] [authz_core:error] [pid 66623:tid 66734] [remote 57.141.22.114:31732] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:39.736924 2026] [authz_core:error] [pid 66623:tid 66734] [remote 57.141.22.114:31732] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:39.756934 2026] [security2:error] [pid 66623:tid 66801] [client 52.173.121.69:14860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBL9O5rbWdOArH04KqHQAAAS0"] [Tue Aug 18 12:58:39.788624 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:39.789065 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:39.809429 2026] [security2:error] [pid 66623:tid 66690] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ij.php"] [unique_id "aoSBL9O5rbWdOArH04KqIQABZzU"] [Tue Aug 18 12:58:39.881626 2026] [security2:error] [pid 66623:tid 66828] [client 20.119.58.187:11867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/php8.php"] [unique_id "aoSBL9O5rbWdOArH04KqJgAAAUg"] [Tue Aug 18 12:58:39.902387 2026] [security2:error] [pid 66623:tid 66717] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/db-status.php"] [unique_id "aoSBL9O5rbWdOArH04KqJwABFVA"] [Tue Aug 18 12:58:39.908874 2026] [security2:error] [pid 66623:tid 66857] [client 68.155.155.199:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/akc.php"] [unique_id "aoSBL9O5rbWdOArH04KqKAAAAWU"] [Tue Aug 18 12:58:39.909742 2026] [security2:error] [pid 66623:tid 66841] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/mosty.php"] [unique_id "aoSBL9O5rbWdOArH04KqKQAAAVU"] [Tue Aug 18 12:58:39.943935 2026] [security2:error] [pid 66623:tid 66854] [client 20.25.139.174:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/goods.php"] [unique_id "aoSBL9O5rbWdOArH04KqKgAAAWI"] [Tue Aug 18 12:58:39.950488 2026] [security2:error] [pid 66623:tid 66787] [client 20.203.138.185:15943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/G-in.php"] [unique_id "aoSBL9O5rbWdOArH04KqLAAAAR8"] [Tue Aug 18 12:58:39.981945 2026] [security2:error] [pid 66623:tid 66766] [client 157.51.166.53:53483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04KqLgAAAQo"] [Tue Aug 18 12:58:39.982119 2026] [security2:error] [pid 66623:tid 66766] [client 157.51.166.53:53483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBL9O5rbWdOArH04KqLgAAAQo"] [Tue Aug 18 12:58:40.003756 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMNO5rbWdOArH04KqNQAAATE"] [Tue Aug 18 12:58:40.003860 2026] [security2:error] [pid 66623:tid 66805] [client 197.184.64.235:41945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMNO5rbWdOArH04KqNQAAATE"] [Tue Aug 18 12:58:40.010844 2026] [security2:error] [pid 66623:tid 66809] [client 40.74.65.169:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/admin.php"] [unique_id "aoSBMNO5rbWdOArH04KqOAAAATU"] [Tue Aug 18 12:58:40.027295 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ud.php"] [unique_id "aoSBMNO5rbWdOArH04KqOgABWyU"] [Tue Aug 18 12:58:40.058098 2026] [security2:error] [pid 66623:tid 66840] [client 4.232.151.198:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/x.php"] [unique_id "aoSBMNO5rbWdOArH04KqPAAAAVQ"] [Tue Aug 18 12:58:40.080879 2026] [security2:error] [pid 66623:tid 66713] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSBMNO5rbWdOArH04KqPgABGkw"] [Tue Aug 18 12:58:40.132315 2026] [security2:error] [pid 66623:tid 66883] [client 20.104.85.180:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/abc.php"] [unique_id "aoSBMNO5rbWdOArH04KqPwAAAX8"] [Tue Aug 18 12:58:40.161671 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:43060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/k.php"] [unique_id "aoSBMNO5rbWdOArH04KqQwAAAYE"] [Tue Aug 18 12:58:40.175216 2026] [security2:error] [pid 66623:tid 66830] [client 20.104.85.180:20259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/alfa.php"] [unique_id "aoSBMNO5rbWdOArH04KqRAAAAUo"] [Tue Aug 18 12:58:40.198338 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBMNO5rbWdOArH04KqRwAAASU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:40.226672 2026] [security2:error] [pid 66623:tid 66886] [client 20.250.13.23:45715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/images/wso.php"] [unique_id "aoSBMNO5rbWdOArH04KqSAAAAYI"] [Tue Aug 18 12:58:40.226988 2026] [security2:error] [pid 66623:tid 66768] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/blurbs.php"] [unique_id "aoSBMNO5rbWdOArH04KqSQAAAQw"] [Tue Aug 18 12:58:40.233903 2026] [security2:error] [pid 66623:tid 66870] [client 52.173.121.69:12163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/nwwha.php"] [unique_id "aoSBMNO5rbWdOArH04KqSwAAAXI"] [Tue Aug 18 12:58:40.236651 2026] [security2:error] [pid 66623:tid 66846] [client 20.119.58.187:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqTAAAAVo"] [Tue Aug 18 12:58:40.254078 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:8110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBMNO5rbWdOArH04KqTQAAASo"] [Tue Aug 18 12:58:40.255792 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.18.37:47276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/system_log.php"] [unique_id "aoSBMNO5rbWdOArH04KqTgAAAS8"] [Tue Aug 18 12:58:40.258336 2026] [security2:error] [pid 66623:tid 66708] [remote 68.155.154.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/wp-content/home.php"] [unique_id "aoSBMNO5rbWdOArH04KqTwABHUc"] [Tue Aug 18 12:58:40.265859 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ip.php"] [unique_id "aoSBMNO5rbWdOArH04KqUAABTwQ"] [Tue Aug 18 12:58:40.274860 2026] [security2:error] [pid 66623:tid 66838] [client 213.202.253.4:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSBMNO5rbWdOArH04KqUQAAAVI"], referer: www.google.com [Tue Aug 18 12:58:40.293676 2026] [security2:error] [pid 66623:tid 66771] [client 20.48.236.86:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/uwu.php"] [unique_id "aoSBMNO5rbWdOArH04KqUwAAAQ8"] [Tue Aug 18 12:58:40.386593 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:40.386877 2026] [authz_core:error] [pid 66623:tid 66750] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:40.413586 2026] [security2:error] [pid 66623:tid 66836] [client 172.182.200.96:7648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBMNO5rbWdOArH04KqWQAAAVA"] [Tue Aug 18 12:58:40.475507 2026] [security2:error] [pid 66623:tid 66747] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/99.php"] [unique_id "aoSBMNO5rbWdOArH04KqWgABQW4"] [Tue Aug 18 12:58:40.511273 2026] [security2:error] [pid 66623:tid 66893] [client 20.25.139.174:4641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/file.php"] [unique_id "aoSBMNO5rbWdOArH04KqXQAAAYk"] [Tue Aug 18 12:58:40.540894 2026] [autoindex:error] [pid 66623:tid 66887] [client 4.232.94.69:57478] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:40.541370 2026] [security2:error] [pid 66623:tid 66845] [client 20.206.73.37:59881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/copypaths.php"] [unique_id "aoSBMNO5rbWdOArH04KqXwAAAVk"] [Tue Aug 18 12:58:40.556552 2026] [security2:error] [pid 66623:tid 66832] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bajah.php"] [unique_id "aoSBMNO5rbWdOArH04KqYAAAAUw"] [Tue Aug 18 12:58:40.597629 2026] [security2:error] [pid 66623:tid 66831] [client 20.119.58.187:12023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ID3/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqYwAAAUs"] [Tue Aug 18 12:58:40.622178 2026] [security2:error] [pid 66623:tid 66852] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qr.php"] [unique_id "aoSBMNO5rbWdOArH04KqZAAAAWA"] [Tue Aug 18 12:58:40.675363 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/er.php"] [unique_id "aoSBMNO5rbWdOArH04KqZgABVW0"] [Tue Aug 18 12:58:40.685985 2026] [authz_core:error] [pid 66623:tid 66686] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:40.686235 2026] [authz_core:error] [pid 66623:tid 66686] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:40.690280 2026] [security2:error] [pid 66623:tid 66775] [client 4.232.151.198:30033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/stem.php"] [unique_id "aoSBMNO5rbWdOArH04KqaQAAARM"] [Tue Aug 18 12:58:40.749255 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.95:45606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:40.749536 2026] [authz_core:error] [pid 66623:tid 66662] [remote 57.141.22.95:45606] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:40.750183 2026] [security2:error] [pid 66623:tid 66805] [client 4.232.94.69:57478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBMNO5rbWdOArH04KqbgAAATE"] [Tue Aug 18 12:58:40.767394 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/akcc.php"] [unique_id "aoSBMNO5rbWdOArH04KqbwAAATI"] [Tue Aug 18 12:58:40.811512 2026] [security2:error] [pid 66623:tid 66840] [client 20.118.133.132:15903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/133.php"] [unique_id "aoSBMNO5rbWdOArH04KqcQAAAVQ"] [Tue Aug 18 12:58:40.844062 2026] [security2:error] [pid 66623:tid 66849] [client 20.250.13.23:53639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/index/function.php"] [unique_id "aoSBMNO5rbWdOArH04KqcwAAAV0"] [Tue Aug 18 12:58:40.851637 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBMNO5rbWdOArH04KqdAAAARg"] [Tue Aug 18 12:58:40.863250 2026] [security2:error] [pid 66623:tid 66827] [client 40.74.65.169:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/w.php"] [unique_id "aoSBMNO5rbWdOArH04KqdwAAAUc"] [Tue Aug 18 12:58:40.887414 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/opsqt.php"] [unique_id "aoSBMNO5rbWdOArH04KqegAAARE"] [Tue Aug 18 12:58:40.896458 2026] [security2:error] [pid 66623:tid 66769] [client 20.203.138.185:17852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xxx.php"] [unique_id "aoSBMNO5rbWdOArH04KqewAAAQ0"] [Tue Aug 18 12:58:40.898154 2026] [security2:error] [pid 66623:tid 66885] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/h.php"] [unique_id "aoSBMNO5rbWdOArH04KqfAAAAYE"] [Tue Aug 18 12:58:40.906924 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qk.php"] [unique_id "aoSBMNO5rbWdOArH04KqfQABNwY"] [Tue Aug 18 12:58:40.956884 2026] [security2:error] [pid 66623:tid 66781] [client 20.119.58.187:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/php8.php"] [unique_id "aoSBMNO5rbWdOArH04KqgAAAARk"] [Tue Aug 18 12:58:40.987187 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:40.987460 2026] [authz_core:error] [pid 66623:tid 66644] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:40.994604 2026] [security2:error] [pid 66623:tid 66804] [client 74.248.18.37:8113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/t.php"] [unique_id "aoSBMNO5rbWdOArH04KqhgAAATA"] [Tue Aug 18 12:58:40.994664 2026] [security2:error] [pid 66623:tid 66766] [client 74.248.18.37:40992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBMNO5rbWdOArH04KqhQAAAQo"] [Tue Aug 18 12:58:41.006335 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:7400] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSBMdO5rbWdOArH04KqiAAAAQ4"] [Tue Aug 18 12:58:41.006463 2026] [security2:error] [pid 66623:tid 66770] [client 20.250.13.23:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/1.php"] [unique_id "aoSBMdO5rbWdOArH04KqiAAAAQ4"] [Tue Aug 18 12:58:41.033858 2026] [security2:error] [pid 66623:tid 66785] [client 20.104.85.180:22874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/lock360.php"] [unique_id "aoSBMdO5rbWdOArH04KqigAAAR0"] [Tue Aug 18 12:58:41.057642 2026] [security2:error] [pid 66623:tid 66883] [client 20.25.139.174:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMdO5rbWdOArH04KqjAAAAX8"] [Tue Aug 18 12:58:41.079563 2026] [security2:error] [pid 66623:tid 66666] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBMdO5rbWdOArH04KqjgABDx0"] [Tue Aug 18 12:58:41.155116 2026] [security2:error] [pid 66623:tid 66884] [client 20.127.136.245:23883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBMdO5rbWdOArH04KqkQAAAYA"] [Tue Aug 18 12:58:41.208965 2026] [security2:error] [pid 66623:tid 66844] [client 68.155.155.199:4887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/buy.php"] [unique_id "aoSBMdO5rbWdOArH04KqkgAAAVg"] [Tue Aug 18 12:58:41.214671 2026] [security2:error] [pid 66623:tid 66826] [client 213.35.127.232:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqkwAAAUY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:41.249522 2026] [security2:error] [pid 66623:tid 66861] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ano.php"] [unique_id "aoSBMdO5rbWdOArH04KqlgAAAWk"] [Tue Aug 18 12:58:41.249554 2026] [security2:error] [pid 66623:tid 66796] [client 20.100.169.31:25140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqlQAAASg"] [Tue Aug 18 12:58:41.251362 2026] [security2:error] [pid 66623:tid 66869] [client 172.202.39.151:44569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMdO5rbWdOArH04KqlwAAAXE"] [Tue Aug 18 12:58:41.279801 2026] [security2:error] [pid 66623:tid 66807] [client 40.74.65.169:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/bajah.php"] [unique_id "aoSBMdO5rbWdOArH04KqmQAAATM"] [Tue Aug 18 12:58:41.292051 2026] [security2:error] [pid 66623:tid 66663] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fs.php"] [unique_id "aoSBMdO5rbWdOArH04KqmwABTRo"] [Tue Aug 18 12:58:41.313065 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/php8.php"] [unique_id "aoSBMdO5rbWdOArH04KqnAAAAVA"] [Tue Aug 18 12:58:41.371499 2026] [security2:error] [pid 66623:tid 66859] [client 114.119.140.102:20941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rhemahost.com.br"] [uri "/robots.txt"] [unique_id "aoSBMdO5rbWdOArH04KqngAAAWc"], referer: http://rhemahost.com.br/robots.txt [Tue Aug 18 12:58:41.391978 2026] [security2:error] [pid 66623:tid 66890] [client 52.173.121.69:35579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/jvcpa.php"] [unique_id "aoSBMdO5rbWdOArH04KqoAAAAYY"] [Tue Aug 18 12:58:41.428474 2026] [security2:error] [pid 66623:tid 66866] [client 4.232.151.198:30025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/UomnmTO0r9.php"] [unique_id "aoSBMdO5rbWdOArH04KqowAAAW4"] [Tue Aug 18 12:58:41.439143 2026] [security2:error] [pid 66623:tid 66863] [client 79.127.164.8:45764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sessions.sql"] [unique_id "aoSBMdO5rbWdOArH04KqpAAAAWs"], referer: https://medihub.com.br/sessions.sql [Tue Aug 18 12:58:41.471367 2026] [security2:error] [pid 66623:tid 66867] [client 20.250.13.23:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/info.php"] [unique_id "aoSBMdO5rbWdOArH04KqpgAAAW8"] [Tue Aug 18 12:58:41.509000 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rb.php"] [unique_id "aoSBMdO5rbWdOArH04KqqQABEz0"] [Tue Aug 18 12:58:41.511362 2026] [security2:error] [pid 66623:tid 66787] [client 20.104.85.180:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wk/index.php"] [unique_id "aoSBMdO5rbWdOArH04KqqgAAAR8"] [Tue Aug 18 12:58:41.511802 2026] [security2:error] [pid 66623:tid 66774] [client 20.48.236.86:25943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/signon.php"] [unique_id "aoSBMdO5rbWdOArH04KqqwAAARI"] [Tue Aug 18 12:58:41.518011 2026] [security2:error] [pid 66623:tid 66871] [client 86.120.159.145:9729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqrAAAAXM"] [Tue Aug 18 12:58:41.518298 2026] [security2:error] [pid 66623:tid 66871] [client 86.120.159.145:9729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqrAAAAXM"] [Tue Aug 18 12:58:41.562390 2026] [security2:error] [pid 66623:tid 66874] [client 40.74.65.169:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fpwch.php"] [unique_id "aoSBMdO5rbWdOArH04KqrQAAAXY"] [Tue Aug 18 12:58:41.577066 2026] [autoindex:error] [pid 66623:tid 66808] [client 87.236.176.216:35909] AH01276: Cannot serve directory /home4/joadv/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:41.589718 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:41.590007 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:41.620523 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/flower.php"] [unique_id "aoSBMdO5rbWdOArH04KqsQAAAYQ"] [Tue Aug 18 12:58:41.625014 2026] [security2:error] [pid 66623:tid 66840] [client 158.23.17.4:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dirs.php"] [unique_id "aoSBMdO5rbWdOArH04KqsgAAAVQ"] [Tue Aug 18 12:58:41.637488 2026] [security2:error] [pid 66623:tid 66857] [client 20.25.139.174:4567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/404.php"] [unique_id "aoSBMdO5rbWdOArH04KqswAAAWU"] [Tue Aug 18 12:58:41.666954 2026] [security2:error] [pid 66623:tid 66812] [client 4.232.94.69:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/storage/rip.php"] [unique_id "aoSBMdO5rbWdOArH04KquQAAATg"] [Tue Aug 18 12:58:41.672224 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/customize/php8.php"] [unique_id "aoSBMdO5rbWdOArH04KqugAAATE"] [Tue Aug 18 12:58:41.681791 2026] [security2:error] [pid 66623:tid 66668] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/37.php"] [unique_id "aoSBMdO5rbWdOArH04KquwABER8"] [Tue Aug 18 12:58:41.837529 2026] [security2:error] [pid 66623:tid 66721] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqvwABMFQ"] [Tue Aug 18 12:58:41.837672 2026] [security2:error] [pid 66623:tid 66804] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMdO5rbWdOArH04KqvwABMFQ"] [Tue Aug 18 12:58:41.862632 2026] [security2:error] [pid 66623:tid 66865] [client 74.248.18.37:7722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBMdO5rbWdOArH04KqwAAAAW0"] [Tue Aug 18 12:58:41.886116 2026] [security2:error] [pid 66623:tid 66770] [client 52.173.121.69:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBMdO5rbWdOArH04KqxQAAAQ4"] [Tue Aug 18 12:58:41.889439 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:41.889697 2026] [authz_core:error] [pid 66623:tid 66716] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:41.901947 2026] [security2:error] [pid 66623:tid 66740] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/md.php"] [unique_id "aoSBMdO5rbWdOArH04KqxwABHWc"] [Tue Aug 18 12:58:41.903825 2026] [security2:error] [pid 66623:tid 66791] [client 20.215.241.237:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/dex.php"] [unique_id "aoSBMdO5rbWdOArH04KqyAAAASM"] [Tue Aug 18 12:58:41.909550 2026] [security2:error] [pid 66623:tid 66824] [client 74.248.18.37:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/templates.php"] [unique_id "aoSBMdO5rbWdOArH04KqyQAAAUQ"] [Tue Aug 18 12:58:42.015464 2026] [security2:error] [pid 66623:tid 66795] [client 172.182.200.96:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBMtO5rbWdOArH04Kq0QAAASc"] [Tue Aug 18 12:58:42.028114 2026] [security2:error] [pid 66623:tid 66835] [client 20.119.58.187:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes.bak/html-api/php8.php"] [unique_id "aoSBMtO5rbWdOArH04Kq0gAAAU8"] [Tue Aug 18 12:58:42.046113 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15162] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/1.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1QAAAWQ"] [Tue Aug 18 12:58:42.046215 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/1.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1QAAAWQ"] [Tue Aug 18 12:58:42.050662 2026] [security2:error] [pid 66623:tid 66868] [client 20.104.85.180:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/13.php"] [unique_id "aoSBMtO5rbWdOArH04Kq1wAAAXA"] [Tue Aug 18 12:58:42.060007 2026] [security2:error] [pid 66623:tid 66802] [client 40.74.65.169:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/ajax.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2QAAAS4"] [Tue Aug 18 12:58:42.061541 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/un.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2gAAAWE"] [Tue Aug 18 12:58:42.086273 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:53668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/profile.php"] [unique_id "aoSBMtO5rbWdOArH04Kq2wAAAXI"] [Tue Aug 18 12:58:42.105514 2026] [security2:error] [pid 66623:tid 66722] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/iy.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3QABWFU"] [Tue Aug 18 12:58:42.109957 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/New.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3gAAAVo"] [Tue Aug 18 12:58:42.133993 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ai.php"] [unique_id "aoSBMtO5rbWdOArH04Kq3wAAAR4"] [Tue Aug 18 12:58:42.168838 2026] [security2:error] [pid 66623:tid 66821] [client 68.155.155.199:12024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/cong.php"] [unique_id "aoSBMtO5rbWdOArH04Kq4gAAAUE"] [Tue Aug 18 12:58:42.208559 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wk/index.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5AAAAT8"] [Tue Aug 18 12:58:42.220120 2026] [security2:error] [pid 66623:tid 66836] [client 20.206.73.37:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bless6.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5QAAAVA"] [Tue Aug 18 12:58:42.234785 2026] [security2:error] [pid 66623:tid 66876] [client 213.35.127.232:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBMtO5rbWdOArH04Kq5wAAAXg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:42.259760 2026] [security2:error] [pid 66623:tid 66832] [client 40.74.65.169:47059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBMtO5rbWdOArH04Kq6QAAAUw"] [Tue Aug 18 12:58:42.297246 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBMtO5rbWdOArH04Kq6wAAARY"] [Tue Aug 18 12:58:42.326067 2026] [security2:error] [pid 66623:tid 66649] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/og.php"] [unique_id "aoSBMtO5rbWdOArH04Kq7gABaww"] [Tue Aug 18 12:58:42.353012 2026] [security2:error] [pid 66623:tid 66893] [client 20.127.136.245:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/alfa.php"] [unique_id "aoSBMtO5rbWdOArH04Kq7wAAAYk"] [Tue Aug 18 12:58:42.396606 2026] [security2:error] [pid 66623:tid 66871] [client 20.118.172.148:2718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBMtO5rbWdOArH04Kq8AAAAXM"] [Tue Aug 18 12:58:42.425618 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:12275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/php8.php"] [unique_id "aoSBMtO5rbWdOArH04Kq9QAAAT0"] [Tue Aug 18 12:58:42.430768 2026] [security2:error] [pid 66623:tid 66840] [client 91.92.47.210:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autoconfig.equipecamisavermelha.com.br"] [uri "/"] [unique_id "aoSBMtO5rbWdOArH04Kq9gAAAVQ"] [Tue Aug 18 12:58:42.441065 2026] [security2:error] [pid 66623:tid 66818] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/w1px.php"] [unique_id "aoSBMtO5rbWdOArH04Kq9wAAAT4"] [Tue Aug 18 12:58:42.463316 2026] [security2:error] [pid 66623:tid 66848] [client 172.202.39.151:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBMtO5rbWdOArH04Kq-AAAAVw"] [Tue Aug 18 12:58:42.492915 2026] [authz_core:error] [pid 66623:tid 66697] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:42.493173 2026] [authz_core:error] [pid 66623:tid 66697] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:42.503804 2026] [security2:error] [pid 66623:tid 66690] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lp.php"] [unique_id "aoSBMtO5rbWdOArH04KrCwABETU"] [Tue Aug 18 12:58:42.526468 2026] [security2:error] [pid 66623:tid 66827] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrCQABR0g"] [Tue Aug 18 12:58:42.544717 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:19715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cc.php"] [unique_id "aoSBMtO5rbWdOArH04KrDwAAATc"] [Tue Aug 18 12:58:42.570653 2026] [security2:error] [pid 66623:tid 66830] [client 20.48.236.86:36108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file61.php"] [unique_id "aoSBMtO5rbWdOArH04KrEAAAAUo"] [Tue Aug 18 12:58:42.592484 2026] [security2:error] [pid 66623:tid 66854] [client 74.248.18.37:40984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBMtO5rbWdOArH04KrFQAAAWI"] [Tue Aug 18 12:58:42.595605 2026] [security2:error] [pid 66623:tid 66875] [client 114.5.214.109:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrFgAAAXc"] [Tue Aug 18 12:58:42.595676 2026] [security2:error] [pid 66623:tid 66875] [client 114.5.214.109:50410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBMtO5rbWdOArH04KrFgAAAXc"] [Tue Aug 18 12:58:42.691878 2026] [security2:error] [pid 66623:tid 66785] [client 52.173.121.69:24779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBMtO5rbWdOArH04KrHQAAAR0"] [Tue Aug 18 12:58:42.695140 2026] [security2:error] [pid 66623:tid 66711] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ey.php"] [unique_id "aoSBMtO5rbWdOArH04KrHgABI0o"] [Tue Aug 18 12:58:42.739998 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:8095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/term.php"] [unique_id "aoSBMtO5rbWdOArH04KrIQAAARg"] [Tue Aug 18 12:58:42.743472 2026] [security2:error] [pid 66623:tid 66839] [client 20.250.13.23:53665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/sx.php"] [unique_id "aoSBMtO5rbWdOArH04KrIgAAAVM"] [Tue Aug 18 12:58:42.763783 2026] [security2:error] [pid 66623:tid 66769] [client 4.232.151.198:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/panel.php"] [unique_id "aoSBMtO5rbWdOArH04KrJAAAAQ0"] [Tue Aug 18 12:58:42.777312 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/zi-936.php"] [unique_id "aoSBMtO5rbWdOArH04KrJgAAAUs"] [Tue Aug 18 12:58:42.784569 2026] [security2:error] [pid 66623:tid 66789] [client 20.119.58.187:11844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/IXR/php8.php"] [unique_id "aoSBMtO5rbWdOArH04KrKAAAASE"] [Tue Aug 18 12:58:42.804888 2026] [security2:error] [pid 66623:tid 66804] [client 20.25.139.174:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/about.php"] [unique_id "aoSBMtO5rbWdOArH04KrKQAAATA"] [Tue Aug 18 12:58:42.808919 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:48990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBMtO5rbWdOArH04KrKgAAATo"] [Tue Aug 18 12:58:42.825679 2026] [security2:error] [pid 66623:tid 66771] [client 20.100.169.31:29036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/themes.php"] [unique_id "aoSBMtO5rbWdOArH04KrKwAAAQ8"] [Tue Aug 18 12:58:42.866688 2026] [security2:error] [pid 66623:tid 66647] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lv.php"] [unique_id "aoSBMtO5rbWdOArH04KrLAABYQo"] [Tue Aug 18 12:58:42.925402 2026] [security2:error] [pid 66623:tid 66766] [client 40.74.65.169:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.savvyoffshore.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBMtO5rbWdOArH04KrPgAAAQo"] [Tue Aug 18 12:58:42.955562 2026] [security2:error] [pid 66623:tid 66796] [client 40.74.65.169:20128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/blurbs.php"] [unique_id "aoSBMtO5rbWdOArH04KrTgAAASg"] [Tue Aug 18 12:58:42.981663 2026] [security2:error] [pid 66623:tid 66795] [client 132.196.30.78:14980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/inputs.php"] [unique_id "aoSBMtO5rbWdOArH04KrWAAAASc"] [Tue Aug 18 12:58:43.026455 2026] [security2:error] [pid 66623:tid 66845] [client 4.232.94.69:40084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/.__info.php"] [unique_id "aoSBM9O5rbWdOArH04KrWQAAAVk"] [Tue Aug 18 12:58:43.038013 2026] [security2:error] [pid 66623:tid 66876] [client 20.203.138.185:47205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/autogooey.php"] [unique_id "aoSBM9O5rbWdOArH04KrWgAAAXg"] [Tue Aug 18 12:58:43.042880 2026] [security2:error] [pid 66623:tid 66652] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/51.php"] [unique_id "aoSBM9O5rbWdOArH04KrWwABZw8"] [Tue Aug 18 12:58:43.070833 2026] [security2:error] [pid 66623:tid 66829] [client 172.202.39.151:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSBM9O5rbWdOArH04KrXQAAAUk"] [Tue Aug 18 12:58:43.095876 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:43.096150 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:43.104838 2026] [security2:error] [pid 66623:tid 66863] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/dcsgumnm.php"] [unique_id "aoSBM9O5rbWdOArH04KrYAAAAWs"] [Tue Aug 18 12:58:43.130609 2026] [security2:error] [pid 66623:tid 66809] [client 20.104.85.180:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrZAAAATU"] [Tue Aug 18 12:58:43.138400 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/php8.php"] [unique_id "aoSBM9O5rbWdOArH04KrZQAAAVA"] [Tue Aug 18 12:58:43.152138 2026] [security2:error] [pid 66623:tid 66881] [client 20.206.73.37:11943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/special.php"] [unique_id "aoSBM9O5rbWdOArH04KraAAAAX0"] [Tue Aug 18 12:58:43.173311 2026] [security2:error] [pid 66623:tid 66767] [client 20.250.13.23:44959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/alfa.php"] [unique_id "aoSBM9O5rbWdOArH04KraQAAAQs"] [Tue Aug 18 12:58:43.177623 2026] [security2:error] [pid 66623:tid 66888] [client 52.173.121.69:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBM9O5rbWdOArH04KragAAAYQ"] [Tue Aug 18 12:58:43.221425 2026] [security2:error] [pid 66623:tid 66705] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ew.php"] [unique_id "aoSBM9O5rbWdOArH04KrawABOEQ"] [Tue Aug 18 12:58:43.246578 2026] [security2:error] [pid 66623:tid 66844] [client 213.35.127.232:53813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBM9O5rbWdOArH04KrbQAAAVg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:43.295253 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBM9O5rbWdOArH04KrbgAAAWI"] [Tue Aug 18 12:58:43.305470 2026] [security2:error] [pid 66623:tid 66834] [client 172.202.39.151:40359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/about.php"] [unique_id "aoSBM9O5rbWdOArH04KrcAAAAU4"] [Tue Aug 18 12:58:43.308730 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:16469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrcQAAATQ"] [Tue Aug 18 12:58:43.361837 2026] [security2:error] [pid 66623:tid 66787] [client 20.250.13.23:45749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBM9O5rbWdOArH04KrdwAAAR8"] [Tue Aug 18 12:58:43.362553 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:22894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBM9O5rbWdOArH04KreAAAAUQ"] [Tue Aug 18 12:58:43.383893 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/term.php"] [unique_id "aoSBM9O5rbWdOArH04KrfgAAARo"] [Tue Aug 18 12:58:43.415484 2026] [security2:error] [pid 66623:tid 66873] [client 4.232.151.198:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/ID/module.audio.flac.php"] [unique_id "aoSBM9O5rbWdOArH04KrgwAAAXU"] [Tue Aug 18 12:58:43.441755 2026] [security2:error] [pid 66623:tid 66857] [client 74.248.18.37:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBM9O5rbWdOArH04KrnAAAAWU"] [Tue Aug 18 12:58:43.449575 2026] [autoindex:error] [pid 66623:tid 66814] [client 68.155.153.139:0] AH01276: Cannot serve directory /home1/cnascimentoasses/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:43.462278 2026] [security2:error] [pid 66623:tid 66815] [client 74.248.18.37:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/test.php"] [unique_id "aoSBM9O5rbWdOArH04KrnwAAATs"] [Tue Aug 18 12:58:43.498473 2026] [security2:error] [pid 66623:tid 66798] [client 20.119.58.187:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/php8.php"] [unique_id "aoSBM9O5rbWdOArH04KroQAAASo"] [Tue Aug 18 12:58:43.521382 2026] [security2:error] [pid 66623:tid 66785] [client 132.196.30.78:15668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/admin.php"] [unique_id "aoSBM9O5rbWdOArH04KrqQAAAR0"] [Tue Aug 18 12:58:43.538146 2026] [security2:error] [pid 66623:tid 66741] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pqr.php"] [unique_id "aoSBM9O5rbWdOArH04KrqgABK2g"] [Tue Aug 18 12:58:43.539716 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:57194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrqwAAASw"] [Tue Aug 18 12:58:43.539887 2026] [security2:error] [pid 66623:tid 66800] [client 37.40.227.74:57194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrqwAAASw"] [Tue Aug 18 12:58:43.567214 2026] [security2:error] [pid 66623:tid 66868] [client 103.184.169.37:42422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrrQAAAXA"] [Tue Aug 18 12:58:43.567333 2026] [security2:error] [pid 66623:tid 66868] [client 103.184.169.37:42422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KrrQAAAXA"] [Tue Aug 18 12:58:43.629819 2026] [security2:error] [pid 66623:tid 66869] [client 20.127.136.245:23429] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.turial.com.br"] [uri "/1.php"] [unique_id "aoSBM9O5rbWdOArH04KrsgAAAXE"] [Tue Aug 18 12:58:43.629949 2026] [security2:error] [pid 66623:tid 66869] [client 20.127.136.245:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/1.php"] [unique_id "aoSBM9O5rbWdOArH04KrsgAAAXE"] [Tue Aug 18 12:58:43.631119 2026] [security2:error] [pid 66623:tid 66864] [client 40.74.65.169:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/100.php"] [unique_id "aoSBM9O5rbWdOArH04KrswAAAWw"] [Tue Aug 18 12:58:43.639388 2026] [security2:error] [pid 66623:tid 66807] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/php.php"] [unique_id "aoSBM9O5rbWdOArH04KrtgAAATM"] [Tue Aug 18 12:58:43.644609 2026] [security2:error] [pid 66623:tid 66877] [client 52.173.121.69:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBM9O5rbWdOArH04KrtwAAAXk"] [Tue Aug 18 12:58:43.645406 2026] [security2:error] [pid 66623:tid 66819] [client 103.120.71.157:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KruAAAAT8"] [Tue Aug 18 12:58:43.645512 2026] [security2:error] [pid 66623:tid 66819] [client 103.120.71.157:59458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBM9O5rbWdOArH04KruAAAAT8"] [Tue Aug 18 12:58:43.696257 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:43.696546 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:43.727227 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/an.php"] [unique_id "aoSBM9O5rbWdOArH04Kr4QABiTs"] [Tue Aug 18 12:58:43.781217 2026] [security2:error] [pid 66623:tid 66867] [client 20.203.138.185:63780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sty.php"] [unique_id "aoSBM9O5rbWdOArH04Kr4wAAAW8"] [Tue Aug 18 12:58:43.845589 2026] [security2:error] [pid 66623:tid 66803] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSBMtO5rbWdOArH04Kq4QABL2U"], referer: https://1td.com.br [Tue Aug 18 12:58:43.860736 2026] [security2:error] [pid 66623:tid 66855] [client 20.119.58.187:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/pomo/php8.php"] [unique_id "aoSBM9O5rbWdOArH04Kr6wAAAWM"] [Tue Aug 18 12:58:43.904272 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:24987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBM9O5rbWdOArH04Kr7gAAAUc"] [Tue Aug 18 12:58:43.919651 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:27930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBM9O5rbWdOArH04Kr7wAAAVg"] [Tue Aug 18 12:58:43.924594 2026] [security2:error] [pid 66623:tid 66676] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sy.php"] [unique_id "aoSBM9O5rbWdOArH04Kr8AABJSc"] [Tue Aug 18 12:58:43.950796 2026] [security2:error] [pid 66623:tid 66809] [client 20.25.139.174:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBM9O5rbWdOArH04Kr8wAAATU"] [Tue Aug 18 12:58:43.951378 2026] [security2:error] [pid 66623:tid 66876] [client 20.100.169.31:27714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/cv.php"] [unique_id "aoSBM9O5rbWdOArH04Kr9AAAAXg"] [Tue Aug 18 12:58:43.971297 2026] [security2:error] [pid 66623:tid 66776] [client 20.250.13.23:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBM9O5rbWdOArH04Kr9wAAARQ"] [Tue Aug 18 12:58:43.981404 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:32598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBM9O5rbWdOArH04Kr-AAAAVc"] [Tue Aug 18 12:58:43.997296 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:43.997576 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:44.055369 2026] [authz_core:error] [pid 66623:tid 66650] [remote 57.141.22.31:33026] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:44.055765 2026] [authz_core:error] [pid 66623:tid 66650] [remote 57.141.22.31:33026] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:44.065435 2026] [security2:error] [pid 66623:tid 66848] [client 4.232.151.198:30073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/gallery.php"] [unique_id "aoSBNNO5rbWdOArH04KsBwAAAVw"] [Tue Aug 18 12:58:44.094638 2026] [security2:error] [pid 66623:tid 66705] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/57.php"] [unique_id "aoSBNNO5rbWdOArH04KsCgABHUQ"] [Tue Aug 18 12:58:44.128453 2026] [security2:error] [pid 66623:tid 66890] [client 20.104.85.180:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBNNO5rbWdOArH04KsCwAAAYY"] [Tue Aug 18 12:58:44.142041 2026] [security2:error] [pid 66623:tid 66851] [client 74.248.18.37:8076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/test1.php"] [unique_id "aoSBNNO5rbWdOArH04KsDQAAAV8"] [Tue Aug 18 12:58:44.155772 2026] [security2:error] [pid 66623:tid 66643] [remote 129.121.123.168:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNNO5rbWdOArH04KsDgABdQY"] [Tue Aug 18 12:58:44.174259 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:8099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBNNO5rbWdOArH04KsEQAAAQw"] [Tue Aug 18 12:58:44.186223 2026] [security2:error] [pid 66623:tid 66778] [client 46.232.235.137:8070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.235.232.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.blueorbit.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNNO5rbWdOArH04KsEgAAARY"] [Tue Aug 18 12:58:44.210404 2026] [security2:error] [pid 66623:tid 66878] [client 20.119.58.187:12051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/block-patterns/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsHgAAAXo"] [Tue Aug 18 12:58:44.231312 2026] [security2:error] [pid 66623:tid 66868] [client 138.36.100.162:42982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsLAAAAXA"] [Tue Aug 18 12:58:44.231425 2026] [security2:error] [pid 66623:tid 66868] [client 138.36.100.162:42982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsLAAAAXA"] [Tue Aug 18 12:58:44.261874 2026] [security2:error] [pid 66623:tid 66830] [client 213.35.127.232:54047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBNNO5rbWdOArH04KsMAAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:44.291011 2026] [security2:error] [pid 66623:tid 66854] [client 132.196.30.78:14996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/goods.php"] [unique_id "aoSBNNO5rbWdOArH04KsMgAAAWI"] [Tue Aug 18 12:58:44.306644 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:20124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ccc.php"] [unique_id "aoSBNNO5rbWdOArH04KsMwAAARc"] [Tue Aug 18 12:58:44.315603 2026] [security2:error] [pid 66623:tid 66866] [client 20.48.236.86:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/copypaths.php"] [unique_id "aoSBNNO5rbWdOArH04KsNAAAAW4"] [Tue Aug 18 12:58:44.368642 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ah.php"] [unique_id "aoSBNNO5rbWdOArH04KsOwABTHI"] [Tue Aug 18 12:58:44.394349 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsPAAAARI"] [Tue Aug 18 12:58:44.444315 2026] [security2:error] [pid 66623:tid 66838] [client 172.182.200.96:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBNNO5rbWdOArH04KsPgAAAVI"] [Tue Aug 18 12:58:44.459997 2026] [security2:error] [pid 66623:tid 66861] [client 158.23.17.4:14076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sn.php"] [unique_id "aoSBNNO5rbWdOArH04KsQAAAAWk"] [Tue Aug 18 12:58:44.481833 2026] [security2:error] [pid 66623:tid 66887] [client 20.25.139.174:4548] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.clickseo.com.br"] [uri "/1.php"] [unique_id "aoSBNNO5rbWdOArH04KsQQAAAYM"] [Tue Aug 18 12:58:44.481912 2026] [security2:error] [pid 66623:tid 66887] [client 20.25.139.174:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/1.php"] [unique_id "aoSBNNO5rbWdOArH04KsQQAAAYM"] [Tue Aug 18 12:58:44.497343 2026] [security2:error] [pid 66623:tid 66823] [client 142.111.55.8:38312] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBNNO5rbWdOArH04KsRQAAAUM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 12:58:44.513084 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBNNO5rbWdOArH04KsTAAAAUc"] [Tue Aug 18 12:58:44.530630 2026] [security2:error] [pid 66623:tid 66773] [client 68.155.155.199:19989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBNNO5rbWdOArH04KsTgAAARE"] [Tue Aug 18 12:58:44.559280 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsTwAAAXQ"] [Tue Aug 18 12:58:44.565397 2026] [security2:error] [pid 66623:tid 66767] [client 20.119.58.187:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updraft/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsUAAAAQs"] [Tue Aug 18 12:58:44.593071 2026] [security2:error] [pid 66623:tid 66723] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vw.php"] [unique_id "aoSBNNO5rbWdOArH04KsUgABTlY"] [Tue Aug 18 12:58:44.600636 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:44.600912 2026] [authz_core:error] [pid 66623:tid 66755] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:44.606444 2026] [security2:error] [pid 66623:tid 66809] [client 20.203.138.185:24267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wio.php"] [unique_id "aoSBNNO5rbWdOArH04KsVQAAATU"] [Tue Aug 18 12:58:44.702149 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/Cache.php"] [unique_id "aoSBNNO5rbWdOArH04KsXQAAAUk"] [Tue Aug 18 12:58:44.714568 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/as.php"] [unique_id "aoSBNNO5rbWdOArH04KsXgAAAWQ"] [Tue Aug 18 12:58:44.740037 2026] [security2:error] [pid 66623:tid 66835] [client 192.141.172.134:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsXwAAAU8"] [Tue Aug 18 12:58:44.740172 2026] [security2:error] [pid 66623:tid 66835] [client 192.141.172.134:51661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsXwAAAU8"] [Tue Aug 18 12:58:44.767906 2026] [security2:error] [pid 66623:tid 66859] [client 149.34.210.141:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsYAAAAWc"] [Tue Aug 18 12:58:44.794083 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lj.php"] [unique_id "aoSBNNO5rbWdOArH04KsZQABKyg"] [Tue Aug 18 12:58:44.801488 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:45699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBNNO5rbWdOArH04KsZwAAAV8"] [Tue Aug 18 12:58:44.840399 2026] [security2:error] [pid 66623:tid 66778] [client 91.92.47.210:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.equipecamisavermelha.com.br"] [uri "/"] [unique_id "aoSBNNO5rbWdOArH04KsaAAAARY"] [Tue Aug 18 12:58:44.845302 2026] [security2:error] [pid 66623:tid 66878] [client 20.38.3.247:41489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBNNO5rbWdOArH04KsaQAAAXo"] [Tue Aug 18 12:58:44.874866 2026] [security2:error] [pid 66623:tid 66789] [client 132.196.30.78:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/file.php"] [unique_id "aoSBNNO5rbWdOArH04KsbQAAASE"] [Tue Aug 18 12:58:44.884658 2026] [security2:error] [pid 66623:tid 66780] [client 74.248.18.37:47236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-config.php"] [unique_id "aoSBNNO5rbWdOArH04KsbgAAARg"] [Tue Aug 18 12:58:44.894196 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:25011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBNNO5rbWdOArH04KscAAAAR4"] [Tue Aug 18 12:58:44.905031 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:44.905451 2026] [authz_core:error] [pid 66623:tid 66713] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:44.922850 2026] [security2:error] [pid 66623:tid 66873] [client 20.119.58.187:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/upgrade-temp-backup/php8.php"] [unique_id "aoSBNNO5rbWdOArH04KsdAAAAXU"] [Tue Aug 18 12:58:44.957838 2026] [security2:error] [pid 66623:tid 66820] [client 74.248.18.37:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/thoms.php"] [unique_id "aoSBNNO5rbWdOArH04KsdQAAAUA"] [Tue Aug 18 12:58:44.958463 2026] [security2:error] [pid 66623:tid 66830] [client 52.173.121.69:48984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBNNO5rbWdOArH04KsdgAAAUo"] [Tue Aug 18 12:58:44.985483 2026] [security2:error] [pid 66623:tid 66846] [client 157.20.138.62:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KseAAAAVo"] [Tue Aug 18 12:58:44.985777 2026] [security2:error] [pid 66623:tid 66846] [client 157.20.138.62:53215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KseAAAAVo"] [Tue Aug 18 12:58:44.989701 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kh.php"] [unique_id "aoSBNNO5rbWdOArH04KseQABTTM"] [Tue Aug 18 12:58:45.003678 2026] [security2:error] [pid 66623:tid 66819] [client 40.74.65.169:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/get.php"] [unique_id "aoSBNdO5rbWdOArH04KsegAAAT8"] [Tue Aug 18 12:58:45.031207 2026] [security2:error] [pid 66623:tid 66859] [client 149.34.210.141:62738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNNO5rbWdOArH04KsYAAAAWc"] [Tue Aug 18 12:58:45.035066 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/alfa.php"] [unique_id "aoSBNdO5rbWdOArH04KsewAAASI"] [Tue Aug 18 12:58:45.099978 2026] [security2:error] [pid 66623:tid 66863] [client 20.206.73.37:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/fz.php"] [unique_id "aoSBNdO5rbWdOArH04KsfAAAAWs"] [Tue Aug 18 12:58:45.112069 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsfQAAAWo"] [Tue Aug 18 12:58:45.112227 2026] [security2:error] [pid 66623:tid 66862] [client 5.31.227.224:7815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsfQAAAWo"] [Tue Aug 18 12:58:45.115305 2026] [security2:error] [pid 66623:tid 66823] [client 142.111.55.8:38312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBNNO5rbWdOArH04KsRQAAAUM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 12:58:45.156955 2026] [security2:error] [pid 66623:tid 66774] [client 20.104.85.180:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/01.php"] [unique_id "aoSBNdO5rbWdOArH04KsfwAAARI"] [Tue Aug 18 12:58:45.161956 2026] [security2:error] [pid 66623:tid 66641] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jb.php"] [unique_id "aoSBNdO5rbWdOArH04KsgAABewQ"] [Tue Aug 18 12:58:45.183780 2026] [security2:error] [pid 66623:tid 66888] [client 20.104.85.180:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBNdO5rbWdOArH04KsggAAAYQ"] [Tue Aug 18 12:58:45.208648 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:45.209063 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:45.219985 2026] [security2:error] [pid 66623:tid 66887] [client 52.173.121.69:16461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBNdO5rbWdOArH04KshgAAAYM"] [Tue Aug 18 12:58:45.221576 2026] [security2:error] [pid 66623:tid 66772] [client 20.250.13.23:32643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/edit.php"] [unique_id "aoSBNdO5rbWdOArH04KshwAAARA"] [Tue Aug 18 12:58:45.284700 2026] [security2:error] [pid 66623:tid 66889] [client 172.182.200.96:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBNdO5rbWdOArH04KsigAAAYU"] [Tue Aug 18 12:58:45.286346 2026] [security2:error] [pid 66623:tid 66831] [client 213.35.127.232:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBNdO5rbWdOArH04KsiwAAAUs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:45.305847 2026] [security2:error] [pid 66623:tid 66817] [client 20.119.58.187:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/php8.php"] [unique_id "aoSBNdO5rbWdOArH04KskAAAAT0"] [Tue Aug 18 12:58:45.337286 2026] [security2:error] [pid 66623:tid 66701] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/do.php"] [unique_id "aoSBNdO5rbWdOArH04KskQABd0A"] [Tue Aug 18 12:58:45.341565 2026] [security2:error] [pid 66623:tid 66852] [client 4.232.151.198:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-add.php"] [unique_id "aoSBNdO5rbWdOArH04KskgAAAWA"] [Tue Aug 18 12:58:45.409336 2026] [security2:error] [pid 66623:tid 66828] [client 52.173.121.69:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBNdO5rbWdOArH04KslAAAAUg"] [Tue Aug 18 12:58:45.457085 2026] [security2:error] [pid 66623:tid 66883] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/sf.php"] [unique_id "aoSBNdO5rbWdOArH04KslwAAAX8"] [Tue Aug 18 12:58:45.462968 2026] [security2:error] [pid 66623:tid 66800] [client 4.232.94.69:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/access.php"] [unique_id "aoSBNdO5rbWdOArH04KsmAAAASw"] [Tue Aug 18 12:58:45.499930 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:14979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBNdO5rbWdOArH04KsmwAAASg"] [Tue Aug 18 12:58:45.503969 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:45.504236 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:45.527114 2026] [security2:error] [pid 66623:tid 66848] [client 223.185.37.47:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsnQAAAVw"] [Tue Aug 18 12:58:45.527213 2026] [security2:error] [pid 66623:tid 66848] [client 223.185.37.47:11697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsnQAAAVw"] [Tue Aug 18 12:58:45.527540 2026] [security2:error] [pid 66623:tid 66651] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yw.php"] [unique_id "aoSBNdO5rbWdOArH04KsnAABSQ4"] [Tue Aug 18 12:58:45.608256 2026] [security2:error] [pid 66623:tid 66776] [client 20.25.139.174:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/edit.php"] [unique_id "aoSBNdO5rbWdOArH04KsogAAARQ"] [Tue Aug 18 12:58:45.609831 2026] [security2:error] [pid 66623:tid 66834] [client 74.248.18.37:47237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBNdO5rbWdOArH04KsowAAAU4"] [Tue Aug 18 12:58:45.610413 2026] [security2:error] [pid 66623:tid 66876] [client 74.248.18.37:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tool.php"] [unique_id "aoSBNdO5rbWdOArH04KspAAAAXg"] [Tue Aug 18 12:58:45.627344 2026] [security2:error] [pid 66623:tid 66885] [client 20.203.138.185:37287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/1061.php"] [unique_id "aoSBNdO5rbWdOArH04KspwAAAYE"] [Tue Aug 18 12:58:45.646618 2026] [security2:error] [pid 66623:tid 66778] [client 52.173.121.69:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBNdO5rbWdOArH04KsqAAAARY"] [Tue Aug 18 12:58:45.647804 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:45702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBNdO5rbWdOArH04KsqQAAAXw"] [Tue Aug 18 12:58:45.648126 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.155.199:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/db.php"] [unique_id "aoSBNdO5rbWdOArH04KsqgAAAXo"] [Tue Aug 18 12:58:45.654487 2026] [security2:error] [pid 66623:tid 66877] [client 178.153.171.161:13359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsqwAAAXk"] [Tue Aug 18 12:58:45.654592 2026] [security2:error] [pid 66623:tid 66877] [client 178.153.171.161:13359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsqwAAAXk"] [Tue Aug 18 12:58:45.667754 2026] [security2:error] [pid 66623:tid 66856] [client 20.119.58.187:11882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/php8.php"] [unique_id "aoSBNdO5rbWdOArH04KsrAAAAWQ"] [Tue Aug 18 12:58:45.682220 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:42465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/images.php"] [unique_id "aoSBNdO5rbWdOArH04KsrgAAAWE"] [Tue Aug 18 12:58:45.703204 2026] [security2:error] [pid 66623:tid 66837] [client 172.182.200.96:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBNdO5rbWdOArH04KsrwAAAVE"] [Tue Aug 18 12:58:45.753772 2026] [security2:error] [pid 66623:tid 66637] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsswABMgA"] [Tue Aug 18 12:58:45.753922 2026] [security2:error] [pid 66623:tid 66806] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBNdO5rbWdOArH04KsswABMgA"] [Tue Aug 18 12:58:45.760467 2026] [security2:error] [pid 66623:tid 66787] [client 20.118.172.148:19683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/rip.php"] [unique_id "aoSBNdO5rbWdOArH04KstAAAAR8"] [Tue Aug 18 12:58:45.760851 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/qh.php"] [unique_id "aoSBNdO5rbWdOArH04KstQABQCA"] [Tue Aug 18 12:58:45.782469 2026] [security2:error] [pid 66623:tid 66768] [client 5.253.84.92:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNdO5rbWdOArH04KstgAAAQw"] [Tue Aug 18 12:58:45.797693 2026] [security2:error] [pid 66623:tid 66771] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/xx.php"] [unique_id "aoSBNdO5rbWdOArH04KsuAAAAQ8"] [Tue Aug 18 12:58:45.804275 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:45.804541 2026] [authz_core:error] [pid 66623:tid 66746] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:45.833727 2026] [security2:error] [pid 66623:tid 66792] [client 20.104.85.180:23943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBNdO5rbWdOArH04KsugAAASQ"] [Tue Aug 18 12:58:45.900176 2026] [security2:error] [pid 66623:tid 66823] [client 20.48.236.86:2789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bless6.php"] [unique_id "aoSBNdO5rbWdOArH04KswAAAAUM"] [Tue Aug 18 12:58:45.924093 2026] [security2:error] [pid 66623:tid 66879] [client 20.100.169.31:38650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBNdO5rbWdOArH04KswQAAAXs"] [Tue Aug 18 12:58:45.955270 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBNdO5rbWdOArH04KswwAAATY"] [Tue Aug 18 12:58:45.982473 2026] [security2:error] [pid 66623:tid 66830] [client 4.232.151.198:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSBNdO5rbWdOArH04KsxQAAAUo"] [Tue Aug 18 12:58:46.006239 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/r.php"] [unique_id "aoSBNtO5rbWdOArH04KsxwABEBs"] [Tue Aug 18 12:58:46.022134 2026] [security2:error] [pid 66623:tid 66860] [client 132.196.30.78:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/404.php"] [unique_id "aoSBNtO5rbWdOArH04KsyAAAAWg"] [Tue Aug 18 12:58:46.026990 2026] [security2:error] [pid 66623:tid 66836] [client 20.119.58.187:11997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/php8.php"] [unique_id "aoSBNtO5rbWdOArH04KsyQAAAVA"] [Tue Aug 18 12:58:46.056039 2026] [security2:error] [pid 66623:tid 66767] [client 20.104.85.180:18815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/lv.php"] [unique_id "aoSBNtO5rbWdOArH04KsygAAAQs"] [Tue Aug 18 12:58:46.100424 2026] [security2:error] [pid 66623:tid 66793] [client 52.173.121.69:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBNtO5rbWdOArH04KszQAAASU"] [Tue Aug 18 12:58:46.114495 2026] [security2:error] [pid 66623:tid 66867] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/uwu.php"] [unique_id "aoSBNtO5rbWdOArH04KszwAAAW8"] [Tue Aug 18 12:58:46.179950 2026] [security2:error] [pid 66623:tid 66858] [client 20.25.139.174:4639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/elp.php"] [unique_id "aoSBNtO5rbWdOArH04Ks0gAAAWY"] [Tue Aug 18 12:58:46.187040 2026] [security2:error] [pid 66623:tid 66712] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/17.php"] [unique_id "aoSBNtO5rbWdOArH04Ks0wABOUs"] [Tue Aug 18 12:58:46.257465 2026] [security2:error] [pid 66623:tid 66889] [client 20.250.13.23:1813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBNtO5rbWdOArH04Ks1QAAAYU"] [Tue Aug 18 12:58:46.282755 2026] [security2:error] [pid 66623:tid 66788] [client 158.23.17.4:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/43.php"] [unique_id "aoSBNtO5rbWdOArH04Ks2AAAASA"] [Tue Aug 18 12:58:46.299257 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks3QAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:46.329159 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:15149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks3wAAASo"] [Tue Aug 18 12:58:46.331392 2026] [security2:error] [pid 66623:tid 66834] [client 20.203.138.185:17843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gec.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4AAAAU4"] [Tue Aug 18 12:58:46.359507 2026] [security2:error] [pid 66623:tid 66875] [client 74.248.18.37:8111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tools.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4gAAAXc"] [Tue Aug 18 12:58:46.361381 2026] [security2:error] [pid 66623:tid 66770] [client 74.248.18.37:47279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content.php"] [unique_id "aoSBNtO5rbWdOArH04Ks4wAAAQ4"] [Tue Aug 18 12:58:46.368682 2026] [security2:error] [pid 66623:tid 66851] [client 20.127.136.245:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/222.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5AAAAV8"] [Tue Aug 18 12:58:46.368686 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/alls.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5QAAAYE"] [Tue Aug 18 12:58:46.374883 2026] [security2:error] [pid 66623:tid 66797] [client 85.154.68.202:17889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5wAAASk"] [Tue Aug 18 12:58:46.375001 2026] [security2:error] [pid 66623:tid 66797] [client 85.154.68.202:17889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBNtO5rbWdOArH04Ks5wAAASk"] [Tue Aug 18 12:58:46.382947 2026] [security2:error] [pid 66623:tid 66829] [client 20.119.58.187:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/blogs.dir/php8.php"] [unique_id "aoSBNtO5rbWdOArH04Ks6AAAAUk"] [Tue Aug 18 12:58:46.386445 2026] [security2:error] [pid 66623:tid 66686] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ev.php"] [unique_id "aoSBNtO5rbWdOArH04Ks6QABejE"] [Tue Aug 18 12:58:46.407323 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:46.407598 2026] [authz_core:error] [pid 66623:tid 66646] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:46.442123 2026] [security2:error] [pid 66623:tid 66837] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/signon.php"] [unique_id "aoSBNtO5rbWdOArH04Ks7QAAAVE"] [Tue Aug 18 12:58:46.492220 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:42736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBNtO5rbWdOArH04Ks8wAAAUA"] [Tue Aug 18 12:58:46.511231 2026] [core:notice] [pid 66623:tid 66697] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 12:58:46.538832 2026] [security2:error] [pid 66623:tid 66833] [client 52.173.121.69:25009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks-wAAAU0"] [Tue Aug 18 12:58:46.546769 2026] [security2:error] [pid 66623:tid 66825] [client 68.155.155.199:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/dropdown.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_AAAAUU"] [Tue Aug 18 12:58:46.600806 2026] [security2:error] [pid 66623:tid 66821] [client 132.196.30.78:14651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wk/index.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_QAAAUE"] [Tue Aug 18 12:58:46.602171 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xs.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_gABTCU"] [Tue Aug 18 12:58:46.605552 2026] [security2:error] [pid 66623:tid 66789] [client 4.232.151.198:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/moddofuns.php"] [unique_id "aoSBNtO5rbWdOArH04Ks_wAAASE"] [Tue Aug 18 12:58:46.691429 2026] [security2:error] [pid 66623:tid 66810] [client 20.104.85.180:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/new.php"] [unique_id "aoSBNtO5rbWdOArH04KtBQAAATY"] [Tue Aug 18 12:58:46.714569 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:46.715040 2026] [authz_core:error] [pid 66623:tid 66643] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:46.738216 2026] [security2:error] [pid 66623:tid 66795] [client 20.25.139.174:4666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBNtO5rbWdOArH04KtCAAAASc"] [Tue Aug 18 12:58:46.746676 2026] [security2:error] [pid 66623:tid 66862] [client 20.119.58.187:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/php8.php"] [unique_id "aoSBNtO5rbWdOArH04KtCgAAAWo"] [Tue Aug 18 12:58:46.757779 2026] [security2:error] [pid 66623:tid 66772] [client 172.182.200.96:14116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBNtO5rbWdOArH04KtCwAAARA"] [Tue Aug 18 12:58:46.806595 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBNtO5rbWdOArH04KtDAABUEU"] [Tue Aug 18 12:58:46.855600 2026] [security2:error] [pid 66623:tid 66767] [client 20.118.172.148:58803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/update/da222.php"] [unique_id "aoSBNtO5rbWdOArH04KtEAAAAQs"] [Tue Aug 18 12:58:46.892416 2026] [security2:error] [pid 66623:tid 66874] [client 20.250.13.23:1800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBNtO5rbWdOArH04KtEgAAAXY"] [Tue Aug 18 12:58:46.900426 2026] [security2:error] [pid 66623:tid 66808] [client 5.253.84.92:59751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.84.253.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sindsecurpr.com.br"] [uri "/wp-login.php"] [unique_id "aoSBNtO5rbWdOArH04KtFAAAATQ"] [Tue Aug 18 12:58:46.949239 2026] [security2:error] [pid 66623:tid 66865] [client 20.48.236.86:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/special.php"] [unique_id "aoSBNtO5rbWdOArH04KtGQAAAW0"] [Tue Aug 18 12:58:46.960203 2026] [security2:error] [pid 66623:tid 66841] [client 4.232.94.69:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/02.php"] [unique_id "aoSBNtO5rbWdOArH04KtGgAAAVU"] [Tue Aug 18 12:58:46.988735 2026] [security2:error] [pid 66623:tid 66883] [client 52.173.121.69:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBNtO5rbWdOArH04KtHAAAAX8"] [Tue Aug 18 12:58:47.004395 2026] [security2:error] [pid 66623:tid 66794] [client 79.127.164.8:35150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/site.bak"] [unique_id "aoSBN9O5rbWdOArH04KtIAAAASY"], referer: https://medihub.com.br/site.bak [Tue Aug 18 12:58:47.008338 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:47.008608 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:47.014476 2026] [security2:error] [pid 66623:tid 66889] [client 20.127.136.245:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/asasx.php"] [unique_id "aoSBN9O5rbWdOArH04KtIQAAAYU"] [Tue Aug 18 12:58:47.024987 2026] [security2:error] [pid 66623:tid 66815] [client 68.155.155.199:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file.php"] [unique_id "aoSBN9O5rbWdOArH04KtIgAAATs"] [Tue Aug 18 12:58:47.043385 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fd.php"] [unique_id "aoSBN9O5rbWdOArH04KtIwABHUE"] [Tue Aug 18 12:58:47.049392 2026] [security2:error] [pid 66623:tid 66838] [client 40.74.65.169:20150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/coffexium.php"] [unique_id "aoSBN9O5rbWdOArH04KtJAAAAVI"] [Tue Aug 18 12:58:47.070834 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.133.132:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBN9O5rbWdOArH04KtJwAAAU4"] [Tue Aug 18 12:58:47.070885 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:27965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtKAAAASo"] [Tue Aug 18 12:58:47.096074 2026] [security2:error] [pid 66623:tid 66844] [client 74.248.18.37:7613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/txets.php"] [unique_id "aoSBN9O5rbWdOArH04KtKgAAAVg"] [Tue Aug 18 12:58:47.099325 2026] [security2:error] [pid 66623:tid 66770] [client 20.206.73.37:20684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/clque.php"] [unique_id "aoSBN9O5rbWdOArH04KtKwAAAQ4"] [Tue Aug 18 12:58:47.102789 2026] [security2:error] [pid 66623:tid 66805] [client 20.119.58.187:12277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtLAAAATE"] [Tue Aug 18 12:58:47.158628 2026] [security2:error] [pid 66623:tid 66813] [client 132.196.30.78:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtLgAAATk"] [Tue Aug 18 12:58:47.213987 2026] [security2:error] [pid 66623:tid 66837] [client 52.173.121.69:25021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtMQAAAVE"] [Tue Aug 18 12:58:47.227647 2026] [security2:error] [pid 66623:tid 66788] [client 4.232.151.198:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/system_log.php"] [unique_id "aoSBN9O5rbWdOArH04KtMgAAASA"] [Tue Aug 18 12:58:47.244548 2026] [security2:error] [pid 66623:tid 66749] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/info2.php"] [unique_id "aoSBN9O5rbWdOArH04KtNQABMnA"] [Tue Aug 18 12:58:47.251346 2026] [security2:error] [pid 66623:tid 66775] [client 20.104.85.180:20268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/222.php"] [unique_id "aoSBN9O5rbWdOArH04KtNgAAARM"] [Tue Aug 18 12:58:47.256694 2026] [security2:error] [pid 66623:tid 66880] [client 20.203.138.185:18337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/scx.php7"] [unique_id "aoSBN9O5rbWdOArH04KtNwAAAXw"] [Tue Aug 18 12:58:47.286476 2026] [security2:error] [pid 66623:tid 66851] [client 20.25.139.174:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/666.php"] [unique_id "aoSBN9O5rbWdOArH04KtOQAAAV8"] [Tue Aug 18 12:58:47.316607 2026] [security2:error] [pid 66623:tid 66782] [client 213.35.127.232:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBN9O5rbWdOArH04KtOgAAARo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:47.354527 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file61.php"] [unique_id "aoSBN9O5rbWdOArH04KtPAAAAWI"] [Tue Aug 18 12:58:47.388584 2026] [security2:error] [pid 66623:tid 66771] [client 74.248.18.37:7727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtQAAAAQ8"] [Tue Aug 18 12:58:47.398900 2026] [security2:error] [pid 66623:tid 66823] [client 158.23.17.4:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fresh.php"] [unique_id "aoSBN9O5rbWdOArH04KtQQAAAUM"] [Tue Aug 18 12:58:47.445112 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:48319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBN9O5rbWdOArH04KtRwAAATY"] [Tue Aug 18 12:58:47.448993 2026] [security2:error] [pid 66623:tid 66866] [client 213.202.253.4:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/postnews.php"] [unique_id "aoSBN9O5rbWdOArH04KtSgAAAW4"], referer: www.google.com [Tue Aug 18 12:58:47.475220 2026] [security2:error] [pid 66623:tid 66742] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sx.php"] [unique_id "aoSBN9O5rbWdOArH04KtTQABamk"] [Tue Aug 18 12:58:47.502194 2026] [security2:error] [pid 66623:tid 66777] [client 20.250.13.23:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBN9O5rbWdOArH04KtUgAAARU"] [Tue Aug 18 12:58:47.511475 2026] [security2:error] [pid 66623:tid 66856] [client 114.119.149.169:45915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "classeamotel.com"] [uri "/robots.txt"] [unique_id "aoSBN9O5rbWdOArH04KtUwAAAWQ"], referer: https://classeamotel.com/robots.txt [Tue Aug 18 12:58:47.537386 2026] [security2:error] [pid 66623:tid 66792] [client 20.119.58.187:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtWgAAASQ"] [Tue Aug 18 12:58:47.595430 2026] [security2:error] [pid 66623:tid 66874] [client 20.127.136.245:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/filemanager.php"] [unique_id "aoSBN9O5rbWdOArH04KtYgAAAXY"] [Tue Aug 18 12:58:47.608604 2026] [authz_core:error] [pid 66623:tid 66718] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:47.608871 2026] [authz_core:error] [pid 66623:tid 66718] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:47.637912 2026] [security2:error] [pid 66623:tid 66858] [client 52.173.121.69:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBN9O5rbWdOArH04KtaQAAAWY"] [Tue Aug 18 12:58:47.666578 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/copypaths.php"] [unique_id "aoSBN9O5rbWdOArH04KtbAAAARQ"] [Tue Aug 18 12:58:47.680781 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:51988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBN9O5rbWdOArH04KtbgAAAX8"] [Tue Aug 18 12:58:47.680906 2026] [security2:error] [pid 66623:tid 66883] [client 192.141.172.134:51988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBN9O5rbWdOArH04KtbgAAAX8"] [Tue Aug 18 12:58:47.681333 2026] [security2:error] [pid 66623:tid 66739] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nu.php"] [unique_id "aoSBN9O5rbWdOArH04KtbwABTmY"] [Tue Aug 18 12:58:47.717418 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/chosen.php"] [unique_id "aoSBN9O5rbWdOArH04KtcQAAAVg"] [Tue Aug 18 12:58:47.724537 2026] [security2:error] [pid 66623:tid 66770] [client 172.182.200.96:7679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBN9O5rbWdOArH04KtdAAAAQ4"] [Tue Aug 18 12:58:47.735796 2026] [security2:error] [pid 66623:tid 66885] [client 40.74.65.169:20101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/red.php"] [unique_id "aoSBN9O5rbWdOArH04KtdQAAAYE"] [Tue Aug 18 12:58:47.782628 2026] [security2:error] [pid 66623:tid 66778] [client 20.118.172.148:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/upload.php"] [unique_id "aoSBN9O5rbWdOArH04KtdwAAARY"] [Tue Aug 18 12:58:47.795784 2026] [security2:error] [pid 66623:tid 66867] [client 132.196.30.78:15660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/term.php"] [unique_id "aoSBN9O5rbWdOArH04KteAAAAW8"] [Tue Aug 18 12:58:47.812623 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/u.php"] [unique_id "aoSBN9O5rbWdOArH04KtegAAAYI"] [Tue Aug 18 12:58:47.858533 2026] [security2:error] [pid 66623:tid 66835] [client 4.232.151.198:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/motu.php"] [unique_id "aoSBN9O5rbWdOArH04KtfgAAAU8"] [Tue Aug 18 12:58:47.878544 2026] [security2:error] [pid 66623:tid 66882] [client 20.48.236.86:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/fz.php"] [unique_id "aoSBN9O5rbWdOArH04KtfwAAAX4"] [Tue Aug 18 12:58:47.890731 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ko.php"] [unique_id "aoSBN9O5rbWdOArH04KtgQABLlM"] [Tue Aug 18 12:58:47.891988 2026] [security2:error] [pid 66623:tid 66876] [client 20.119.58.187:12246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/gallery/php8.php"] [unique_id "aoSBN9O5rbWdOArH04KtggAAAXg"] [Tue Aug 18 12:58:47.894527 2026] [security2:error] [pid 66623:tid 66857] [client 172.202.39.151:44500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/f35.php"] [unique_id "aoSBN9O5rbWdOArH04KtgwAAAWU"] [Tue Aug 18 12:58:47.901903 2026] [security2:error] [pid 66623:tid 66818] [client 52.173.121.69:35546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBN9O5rbWdOArH04KthwAAAT4"] [Tue Aug 18 12:58:47.904217 2026] [authz_core:error] [pid 66623:tid 66741] [remote 57.141.22.33:46288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:47.904571 2026] [authz_core:error] [pid 66623:tid 66741] [remote 57.141.22.33:46288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:47.910573 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:47.910845 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:47.912008 2026] [security2:error] [pid 66623:tid 66860] [client 20.100.169.31:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ws83.php"] [unique_id "aoSBN9O5rbWdOArH04KtiQAAAWg"] [Tue Aug 18 12:58:48.012329 2026] [security2:error] [pid 66623:tid 66864] [client 158.23.17.4:40441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gj.php"] [unique_id "aoSBONO5rbWdOArH04KtkAAAAWw"] [Tue Aug 18 12:58:48.036917 2026] [security2:error] [pid 66623:tid 66854] [client 68.155.155.199:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/goods.php"] [unique_id "aoSBONO5rbWdOArH04KtkgAAAWI"] [Tue Aug 18 12:58:48.067124 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:8102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBONO5rbWdOArH04KtkwAAAT0"] [Tue Aug 18 12:58:48.069028 2026] [security2:error] [pid 66623:tid 66869] [client 172.202.39.151:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gelay.php"] [unique_id "aoSBONO5rbWdOArH04KtlAAAAXE"] [Tue Aug 18 12:58:48.160095 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/pl.php"] [unique_id "aoSBONO5rbWdOArH04KtmQABhFI"] [Tue Aug 18 12:58:48.173699 2026] [security2:error] [pid 66623:tid 66851] [client 20.250.13.23:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBONO5rbWdOArH04KtmgAAAV8"] [Tue Aug 18 12:58:48.220085 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:48.220377 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:48.236140 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBONO5rbWdOArH04KtoQAAARA"] [Tue Aug 18 12:58:48.261415 2026] [security2:error] [pid 66623:tid 66881] [client 20.119.58.187:11969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/blocks/php8.php"] [unique_id "aoSBONO5rbWdOArH04KtpAAAAX0"] [Tue Aug 18 12:58:48.263182 2026] [security2:error] [pid 66623:tid 66836] [client 20.203.138.185:18495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSBONO5rbWdOArH04KtpQAAAVA"] [Tue Aug 18 12:58:48.274263 2026] [security2:error] [pid 66623:tid 66821] [client 20.206.73.37:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/nano.php"] [unique_id "aoSBONO5rbWdOArH04KtqAAAAUE"] [Tue Aug 18 12:58:48.278397 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:7570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBONO5rbWdOArH04KtqQAAATA"] [Tue Aug 18 12:58:48.282315 2026] [security2:error] [pid 66623:tid 66822] [client 52.173.121.69:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBONO5rbWdOArH04KtqgAAAUI"] [Tue Aug 18 12:58:48.300823 2026] [security2:error] [pid 66623:tid 66874] [client 20.104.85.180:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/info.php"] [unique_id "aoSBONO5rbWdOArH04KtqwAAAXY"] [Tue Aug 18 12:58:48.329732 2026] [security2:error] [pid 66623:tid 66872] [client 213.35.127.232:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBONO5rbWdOArH04KtrAAAAXQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:48.335770 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/env.php"] [unique_id "aoSBONO5rbWdOArH04KtrQABNEg"] [Tue Aug 18 12:58:48.386907 2026] [security2:error] [pid 66623:tid 66890] [client 20.25.139.174:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ws54.php"] [unique_id "aoSBONO5rbWdOArH04KtsQAAAYY"] [Tue Aug 18 12:58:48.391867 2026] [security2:error] [pid 66623:tid 66856] [client 178.156.185.231:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSBONO5rbWdOArH04KtogAAAWQ"], referer: https://bn2s.com.br/ [Tue Aug 18 12:58:48.435468 2026] [security2:error] [pid 66623:tid 66776] [client 20.118.172.148:33488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wk/index.php"] [unique_id "aoSBONO5rbWdOArH04KttgAAARQ"] [Tue Aug 18 12:58:48.456757 2026] [security2:error] [pid 66623:tid 66798] [client 52.173.121.69:24982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBONO5rbWdOArH04KtuAAAASo"] [Tue Aug 18 12:58:48.478610 2026] [security2:error] [pid 66623:tid 66871] [client 74.248.18.37:8084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ultra.php"] [unique_id "aoSBONO5rbWdOArH04KtuQAAAXM"] [Tue Aug 18 12:58:48.486626 2026] [security2:error] [pid 66623:tid 66792] [client 132.196.30.78:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBONO5rbWdOArH04KtugAAASQ"] [Tue Aug 18 12:58:48.498754 2026] [security2:error] [pid 66623:tid 66870] [client 4.232.151.198:30023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/uploads/2024//chosen.php"] [unique_id "aoSBONO5rbWdOArH04KtuwAAAXI"] [Tue Aug 18 12:58:48.521825 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:48.522094 2026] [authz_core:error] [pid 66623:tid 66637] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:48.576672 2026] [security2:error] [pid 66623:tid 66848] [client 20.127.136.245:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/themes.php"] [unique_id "aoSBONO5rbWdOArH04KtvgAAAVw"] [Tue Aug 18 12:58:48.587343 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mz.php"] [unique_id "aoSBONO5rbWdOArH04KtvwABfiQ"] [Tue Aug 18 12:58:48.600109 2026] [security2:error] [pid 66623:tid 66815] [client 20.25.139.174:4656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/inputs.php"] [unique_id "aoSBONO5rbWdOArH04KtwAAAATs"] [Tue Aug 18 12:58:48.672865 2026] [security2:error] [pid 66623:tid 66791] [client 20.250.13.23:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/elp.php"] [unique_id "aoSBONO5rbWdOArH04KtwwAAASM"] [Tue Aug 18 12:58:48.728111 2026] [security2:error] [pid 66623:tid 66816] [client 74.248.18.37:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruthers.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBONO5rbWdOArH04KtxgAAATw"] [Tue Aug 18 12:58:48.773972 2026] [security2:error] [pid 66623:tid 66675] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ft.php"] [unique_id "aoSBONO5rbWdOArH04KtyAABYiY"] [Tue Aug 18 12:58:48.775044 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/an.php"] [unique_id "aoSBONO5rbWdOArH04KtyQAAAUU"] [Tue Aug 18 12:58:48.801748 2026] [security2:error] [pid 66623:tid 66863] [client 168.62.48.100:1116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBONO5rbWdOArH04KtygAAAWs"] [Tue Aug 18 12:58:48.812978 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:14535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBONO5rbWdOArH04KtzAAAASE"] [Tue Aug 18 12:58:48.818949 2026] [security2:error] [pid 66623:tid 66817] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bless6.php"] [unique_id "aoSBONO5rbWdOArH04KtzQAAAT0"] [Tue Aug 18 12:58:48.819602 2026] [security2:error] [pid 66623:tid 66835] [client 20.250.13.23:53663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBONO5rbWdOArH04KtzgAAAU8"] [Tue Aug 18 12:58:48.867030 2026] [security2:error] [pid 66623:tid 66851] [client 68.155.155.199:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBONO5rbWdOArH04KtzwAAAV8"] [Tue Aug 18 12:58:48.935334 2026] [security2:error] [pid 66623:tid 66836] [client 20.206.73.37:59941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "villasgarage.com.br"] [uri "/.mopj.php"] [unique_id "aoSBONO5rbWdOArH04Kt0gAAAVA"] [Tue Aug 18 12:58:48.963871 2026] [security2:error] [pid 66623:tid 66859] [client 20.25.139.174:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBONO5rbWdOArH04Kt1AAAAWc"] [Tue Aug 18 12:58:48.972412 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/h.php"] [unique_id "aoSBONO5rbWdOArH04Kt1QABQjA"] [Tue Aug 18 12:58:48.988341 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-act.php"] [unique_id "aoSBONO5rbWdOArH04Kt1gAAASA"] [Tue Aug 18 12:58:48.998757 2026] [security2:error] [pid 66623:tid 66874] [client 52.173.121.69:16449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBONO5rbWdOArH04Kt2AAAAXY"] [Tue Aug 18 12:58:49.041099 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:14992] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.cadema.com.br"] [uri "/1.php"] [unique_id "aoSBOdO5rbWdOArH04Kt2gAAARM"] [Tue Aug 18 12:58:49.041200 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:14992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/1.php"] [unique_id "aoSBOdO5rbWdOArH04Kt2gAAARM"] [Tue Aug 18 12:58:49.069453 2026] [security2:error] [pid 66623:tid 66808] [client 168.62.48.100:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBOdO5rbWdOArH04Kt3AAAATQ"] [Tue Aug 18 12:58:49.101674 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:7657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBOdO5rbWdOArH04Kt3wAAAQ0"] [Tue Aug 18 12:58:49.113709 2026] [security2:error] [pid 66623:tid 66800] [client 20.25.139.174:4668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/admin.php"] [unique_id "aoSBOdO5rbWdOArH04Kt4QAAASw"] [Tue Aug 18 12:58:49.117348 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:49.117607 2026] [authz_core:error] [pid 66623:tid 66727] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:49.125490 2026] [security2:error] [pid 66623:tid 66803] [client 74.248.18.37:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/un.php"] [unique_id "aoSBOdO5rbWdOArH04Kt4gAAAS8"] [Tue Aug 18 12:58:49.129238 2026] [security2:error] [pid 66623:tid 66890] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/special.php"] [unique_id "aoSBOdO5rbWdOArH04Kt5AAAAYY"] [Tue Aug 18 12:58:49.182020 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:50236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBOdO5rbWdOArH04Kt6QAAAVY"] [Tue Aug 18 12:58:49.184553 2026] [security2:error] [pid 66623:tid 66768] [client 4.232.151.198:6135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/help.php"] [unique_id "aoSBOdO5rbWdOArH04Kt6gAAAQw"] [Tue Aug 18 12:58:49.263642 2026] [security2:error] [pid 66623:tid 66792] [client 158.23.17.4:7190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pd.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7AAAASQ"] [Tue Aug 18 12:58:49.266758 2026] [security2:error] [pid 66623:tid 66738] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/40.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7gABgWU"] [Tue Aug 18 12:58:49.321317 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:1095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/weozh.php"] [unique_id "aoSBOdO5rbWdOArH04Kt7wAAARY"] [Tue Aug 18 12:58:49.324699 2026] [security2:error] [pid 66623:tid 66867] [client 20.203.138.185:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp5.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8AAAAW8"] [Tue Aug 18 12:58:49.341654 2026] [security2:error] [pid 66623:tid 66873] [client 20.104.85.180:20272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8QAAAXU"] [Tue Aug 18 12:58:49.353581 2026] [security2:error] [pid 66623:tid 66852] [client 213.35.127.232:55051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBOdO5rbWdOArH04Kt8gAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:49.410697 2026] [security2:error] [pid 66623:tid 66876] [client 52.173.121.69:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBOdO5rbWdOArH04Kt9QAAAXg"] [Tue Aug 18 12:58:49.418980 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:49.419243 2026] [authz_core:error] [pid 66623:tid 66689] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:49.445609 2026] [security2:error] [pid 66623:tid 66733] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ee.php"] [unique_id "aoSBOdO5rbWdOArH04Kt9wABPmA"] [Tue Aug 18 12:58:49.485283 2026] [security2:error] [pid 66623:tid 66870] [client 20.250.13.23:53637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBOdO5rbWdOArH04Kt-gAAAXI"] [Tue Aug 18 12:58:49.512350 2026] [security2:error] [pid 66623:tid 66819] [client 20.48.236.86:36109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/clque.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_AAAAT8"] [Tue Aug 18 12:58:49.541374 2026] [security2:error] [pid 66623:tid 66833] [client 68.155.155.199:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/htaccess.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_gAAAU0"] [Tue Aug 18 12:58:49.589946 2026] [security2:error] [pid 66623:tid 66826] [client 168.62.48.100:1105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/rymmm.php"] [unique_id "aoSBOdO5rbWdOArH04Kt_wAAAUY"] [Tue Aug 18 12:58:49.621551 2026] [security2:error] [pid 66623:tid 66868] [client 20.118.172.148:46763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBOdO5rbWdOArH04KuAQAAAXA"] [Tue Aug 18 12:58:49.629351 2026] [security2:error] [pid 66623:tid 66825] [client 20.104.85.180:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/404.php"] [unique_id "aoSBOdO5rbWdOArH04KuAgAAAUU"] [Tue Aug 18 12:58:49.635346 2026] [security2:error] [pid 66623:tid 66882] [client 20.25.139.174:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/function/function.php"] [unique_id "aoSBOdO5rbWdOArH04KuBQAAAX4"] [Tue Aug 18 12:58:49.636700 2026] [security2:error] [pid 66623:tid 66849] [client 52.173.121.69:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBOdO5rbWdOArH04KuBgAAAV0"] [Tue Aug 18 12:58:49.669414 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ak.php"] [unique_id "aoSBOdO5rbWdOArH04KuBwABIWs"] [Tue Aug 18 12:58:49.670267 2026] [security2:error] [pid 66623:tid 66860] [client 132.196.30.78:22174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/alfa.php"] [unique_id "aoSBOdO5rbWdOArH04KuCAAAAWg"] [Tue Aug 18 12:58:49.684322 2026] [security2:error] [pid 66623:tid 66820] [client 20.127.136.245:17047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBOdO5rbWdOArH04KuCQAAAUA"] [Tue Aug 18 12:58:49.721777 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:49.722031 2026] [authz_core:error] [pid 66623:tid 66696] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:49.791585 2026] [security2:error] [pid 66623:tid 66827] [client 74.248.18.37:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/up.php"] [unique_id "aoSBOdO5rbWdOArH04KuDQAAAUc"] [Tue Aug 18 12:58:49.829644 2026] [security2:error] [pid 66623:tid 66863] [client 20.25.139.174:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/goods.php"] [unique_id "aoSBOdO5rbWdOArH04KuEAAAAWs"] [Tue Aug 18 12:58:49.830177 2026] [security2:error] [pid 66623:tid 66880] [client 4.232.151.198:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBOdO5rbWdOArH04KuEQAAAXw"] [Tue Aug 18 12:58:49.854999 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/lddxs.php"] [unique_id "aoSBOdO5rbWdOArH04KuFAAAAUE"] [Tue Aug 18 12:58:49.906520 2026] [security2:error] [pid 66623:tid 66728] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/test_info.php"] [unique_id "aoSBOdO5rbWdOArH04KuFwABJVs"] [Tue Aug 18 12:58:49.936637 2026] [security2:error] [pid 66623:tid 66788] [client 52.173.121.69:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBOdO5rbWdOArH04KuGQAAASA"] [Tue Aug 18 12:58:49.970261 2026] [security2:error] [pid 66623:tid 66865] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/fz.php"] [unique_id "aoSBOdO5rbWdOArH04KuHwAAAW0"] [Tue Aug 18 12:58:50.021759 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:50.022019 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:50.030427 2026] [security2:error] [pid 66623:tid 66877] [client 196.12.128.158:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuIwAAAXk"] [Tue Aug 18 12:58:50.030532 2026] [security2:error] [pid 66623:tid 66877] [client 196.12.128.158:59939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuIwAAAXk"] [Tue Aug 18 12:58:50.044220 2026] [security2:error] [pid 66623:tid 66797] [client 52.173.121.69:48296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBOtO5rbWdOArH04KuJAAAASk"] [Tue Aug 18 12:58:50.051359 2026] [security2:error] [pid 66623:tid 66806] [client 20.250.13.23:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBOtO5rbWdOArH04KuJQAAATI"] [Tue Aug 18 12:58:50.082183 2026] [security2:error] [pid 66623:tid 66776] [client 68.155.155.199:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/images/wso.php"] [unique_id "aoSBOtO5rbWdOArH04KuJwAAARQ"] [Tue Aug 18 12:58:50.115581 2026] [security2:error] [pid 66623:tid 66831] [client 20.250.13.23:53659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBOtO5rbWdOArH04KuKQAAAUs"] [Tue Aug 18 12:58:50.128267 2026] [security2:error] [pid 66623:tid 66855] [client 20.25.139.174:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/nw.php"] [unique_id "aoSBOtO5rbWdOArH04KuKgAAAWM"] [Tue Aug 18 12:58:50.129262 2026] [security2:error] [pid 66623:tid 66862] [client 168.62.48.100:1059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zjggu.php"] [unique_id "aoSBOtO5rbWdOArH04KuKwAAAWo"] [Tue Aug 18 12:58:50.136451 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/14.php"] [unique_id "aoSBOtO5rbWdOArH04KuLAABDBQ"] [Tue Aug 18 12:58:50.164174 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:26705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KuLgAAAXM"] [Tue Aug 18 12:58:50.224926 2026] [security2:error] [pid 66623:tid 66884] [client 4.232.94.69:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/menu.php"] [unique_id "aoSBOtO5rbWdOArH04KuMQAAAYA"] [Tue Aug 18 12:58:50.243058 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.30.78:14990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/edit.php"] [unique_id "aoSBOtO5rbWdOArH04KuMgAAASo"] [Tue Aug 18 12:58:50.287535 2026] [security2:error] [pid 66623:tid 66848] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/clque.php"] [unique_id "aoSBOtO5rbWdOArH04KuNAAAAVw"] [Tue Aug 18 12:58:50.333352 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tk.php"] [unique_id "aoSBOtO5rbWdOArH04KuNQABeDg"] [Tue Aug 18 12:58:50.342263 2026] [security2:error] [pid 66623:tid 66843] [client 20.25.139.174:4661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/file.php"] [unique_id "aoSBOtO5rbWdOArH04KuOAAAAVc"] [Tue Aug 18 12:58:50.347891 2026] [security2:error] [pid 66623:tid 66791] [client 158.23.17.4:56755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/th.php"] [unique_id "aoSBOtO5rbWdOArH04KuOQAAASM"] [Tue Aug 18 12:58:50.374632 2026] [security2:error] [pid 66623:tid 66856] [client 213.35.127.232:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KuPAAAAWQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:50.434755 2026] [security2:error] [pid 66623:tid 66864] [client 168.62.48.100:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBOtO5rbWdOArH04KuQQAAAWw"] [Tue Aug 18 12:58:50.472117 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:17978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBOtO5rbWdOArH04KuQwAAAUU"] [Tue Aug 18 12:58:50.496834 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:7651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBOtO5rbWdOArH04KuRAAAAV0"] [Tue Aug 18 12:58:50.510064 2026] [security2:error] [pid 66623:tid 66770] [client 4.232.151.198:30017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/hplfuns.php"] [unique_id "aoSBOtO5rbWdOArH04KuRgAAAQ4"] [Tue Aug 18 12:58:50.519528 2026] [security2:error] [pid 66623:tid 66832] [client 172.202.39.151:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBOtO5rbWdOArH04KuRwAAAUw"] [Tue Aug 18 12:58:50.522717 2026] [security2:error] [pid 66623:tid 66756] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/hp.php"] [unique_id "aoSBOtO5rbWdOArH04KuSgABT3c"] [Tue Aug 18 12:58:50.523911 2026] [security2:error] [pid 66623:tid 66820] [client 52.173.121.69:50224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBOtO5rbWdOArH04KuSwAAAUA"] [Tue Aug 18 12:58:50.572516 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:54127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuTgAAAVo"] [Tue Aug 18 12:58:50.572668 2026] [security2:error] [pid 66623:tid 66846] [client 157.51.166.53:54127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuTgAAAVo"] [Tue Aug 18 12:58:50.585013 2026] [security2:error] [pid 66623:tid 66847] [client 79.127.164.8:35198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/site.sql"] [unique_id "aoSBOtO5rbWdOArH04KuTwAAAVs"], referer: https://medihub.com.br/site.sql [Tue Aug 18 12:58:50.615905 2026] [security2:error] [pid 66623:tid 66866] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/nano.php"] [unique_id "aoSBOtO5rbWdOArH04KuUAAAAW4"] [Tue Aug 18 12:58:50.619260 2026] [security2:error] [pid 66623:tid 66790] [client 20.203.138.185:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/a2.php"] [unique_id "aoSBOtO5rbWdOArH04KuUgAAASI"] [Tue Aug 18 12:58:50.624577 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:50.624842 2026] [authz_core:error] [pid 66623:tid 66639] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:50.639581 2026] [security2:error] [pid 66623:tid 66882] [client 20.25.139.174:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/xleet.php"] [unique_id "aoSBOtO5rbWdOArH04KuVQAAAX4"] [Tue Aug 18 12:58:50.692357 2026] [security2:error] [pid 66623:tid 66793] [client 168.62.48.100:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBOtO5rbWdOArH04KuWAAAASU"] [Tue Aug 18 12:58:50.736371 2026] [security2:error] [pid 66623:tid 66775] [client 68.155.155.199:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/index/function.php"] [unique_id "aoSBOtO5rbWdOArH04KuWwAAARM"] [Tue Aug 18 12:58:50.746175 2026] [security2:error] [pid 66623:tid 66808] [client 74.248.18.37:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/users.php"] [unique_id "aoSBOtO5rbWdOArH04KuXAAAATQ"] [Tue Aug 18 12:58:50.757971 2026] [security2:error] [pid 66623:tid 66841] [client 20.127.136.245:7659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/buy.php"] [unique_id "aoSBOtO5rbWdOArH04KuXQAAAVU"] [Tue Aug 18 12:58:50.773012 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:18721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBOtO5rbWdOArH04KuXgAAAS8"] [Tue Aug 18 12:58:50.778985 2026] [security2:error] [pid 66623:tid 66725] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wx.php"] [unique_id "aoSBOtO5rbWdOArH04KuYAABeVg"] [Tue Aug 18 12:58:50.807871 2026] [security2:error] [pid 66623:tid 66797] [client 20.48.236.86:25926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/nano.php"] [unique_id "aoSBOtO5rbWdOArH04KuYQAAASk"] [Tue Aug 18 12:58:50.819164 2026] [security2:error] [pid 66623:tid 66800] [client 197.184.64.235:41946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuYwAAASw"] [Tue Aug 18 12:58:50.828457 2026] [security2:error] [pid 66623:tid 66800] [client 197.184.64.235:41946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBOtO5rbWdOArH04KuYwAAASw"] [Tue Aug 18 12:58:50.862488 2026] [security2:error] [pid 66623:tid 66768] [client 68.221.73.131:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBOtO5rbWdOArH04KuZwAAAQw"] [Tue Aug 18 12:58:50.877942 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBOtO5rbWdOArH04KuawAAASA"] [Tue Aug 18 12:58:50.892330 2026] [security2:error] [pid 66623:tid 66821] [client 20.250.13.23:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBOtO5rbWdOArH04KubAAAAUE"] [Tue Aug 18 12:58:50.922228 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:50.922524 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:50.922898 2026] [security2:error] [pid 66623:tid 66812] [client 132.196.30.78:15012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/elp.php"] [unique_id "aoSBOtO5rbWdOArH04KucwAAATg"] [Tue Aug 18 12:58:50.928323 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.153.139:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cnascimentoassessoria.com"] [uri "/.mopj.php"] [unique_id "aoSBOtO5rbWdOArH04KudAAAAYA"] [Tue Aug 18 12:58:50.952997 2026] [security2:error] [pid 66623:tid 66695] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/dj.php"] [unique_id "aoSBOtO5rbWdOArH04KudQABbzo"] [Tue Aug 18 12:58:50.974685 2026] [security2:error] [pid 66623:tid 66813] [client 20.104.85.180:42245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBOtO5rbWdOArH04KudwAAATk"] [Tue Aug 18 12:58:50.978062 2026] [security2:error] [pid 66623:tid 66848] [client 168.62.48.100:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/kopyw.php"] [unique_id "aoSBOtO5rbWdOArH04KueAAAAVw"] [Tue Aug 18 12:58:51.003393 2026] [security2:error] [pid 66623:tid 66780] [client 20.206.73.37:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/bengi.php"] [unique_id "aoSBO9O5rbWdOArH04KuegAAARg"] [Tue Aug 18 12:58:51.066086 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBO9O5rbWdOArH04KufQAAAWU"] [Tue Aug 18 12:58:51.131638 2026] [security2:error] [pid 66623:tid 66764] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fa.php"] [unique_id "aoSBO9O5rbWdOArH04KugwABcH8"] [Tue Aug 18 12:58:51.144394 2026] [security2:error] [pid 66623:tid 66781] [client 4.232.151.198:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/02.php"] [unique_id "aoSBO9O5rbWdOArH04KuhQAAARk"] [Tue Aug 18 12:58:51.152454 2026] [security2:error] [pid 66623:tid 66816] [client 127.0.0.1:37358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aoSBO9O5rbWdOArH04KuggAAATw"] [Tue Aug 18 12:58:51.152507 2026] [security2:error] [pid 66623:tid 66852] [client 74.7.175.172:50386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.inovartararas.com.br"] [uri "/robots.txt"] [unique_id "aoSBO9O5rbWdOArH04KugAABYCE"] [Tue Aug 18 12:58:51.180287 2026] [security2:error] [pid 66623:tid 66773] [client 20.25.139.174:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp.php"] [unique_id "aoSBO9O5rbWdOArH04KuiAAAARE"] [Tue Aug 18 12:58:51.226821 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:51.227081 2026] [authz_core:error] [pid 66623:tid 66655] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:51.244942 2026] [security2:error] [pid 66623:tid 66802] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/bengi.php"] [unique_id "aoSBO9O5rbWdOArH04KujgAAAS4"] [Tue Aug 18 12:58:51.249995 2026] [security2:error] [pid 66623:tid 66792] [client 20.250.13.23:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/666.php"] [unique_id "aoSBO9O5rbWdOArH04KujwAAASQ"] [Tue Aug 18 12:58:51.292191 2026] [security2:error] [pid 66623:tid 66790] [client 168.62.48.100:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zznmg.php"] [unique_id "aoSBO9O5rbWdOArH04KukgAAASI"] [Tue Aug 18 12:58:51.312643 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/fb.php"] [unique_id "aoSBO9O5rbWdOArH04KukwABfik"] [Tue Aug 18 12:58:51.321457 2026] [security2:error] [pid 66623:tid 66777] [client 20.127.136.245:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/dropdown.php"] [unique_id "aoSBO9O5rbWdOArH04KulAAAARU"] [Tue Aug 18 12:58:51.359567 2026] [security2:error] [pid 66623:tid 66858] [client 4.232.94.69:16057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/spip.php"] [unique_id "aoSBO9O5rbWdOArH04KulgAAAWY"] [Tue Aug 18 12:58:51.386414 2026] [security2:error] [pid 66623:tid 66843] [client 213.35.127.232:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBO9O5rbWdOArH04KumQAAAVc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:51.403377 2026] [security2:error] [pid 66623:tid 66771] [client 20.25.139.174:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/404.php"] [unique_id "aoSBO9O5rbWdOArH04KumwAAAQ8"] [Tue Aug 18 12:58:51.415514 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.18.37:41014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/v.php"] [unique_id "aoSBO9O5rbWdOArH04KunAAAAUw"] [Tue Aug 18 12:58:51.505997 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:45709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBO9O5rbWdOArH04KuowAAAUc"] [Tue Aug 18 12:58:51.527049 2026] [authz_core:error] [pid 66623:tid 66660] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:51.527320 2026] [authz_core:error] [pid 66623:tid 66660] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:51.528134 2026] [security2:error] [pid 66623:tid 66677] [remote 216.38.28.47:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "castroeferres.com.br"] [uri "/wp-login.php"] [unique_id "aoSBO9O5rbWdOArH04KupQABbig"] [Tue Aug 18 12:58:51.549463 2026] [security2:error] [pid 66623:tid 66720] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gw.php"] [unique_id "aoSBO9O5rbWdOArH04KupgABL1M"] [Tue Aug 18 12:58:51.556314 2026] [security2:error] [pid 66623:tid 66877] [client 40.74.65.169:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBO9O5rbWdOArH04KuqAAAAXk"] [Tue Aug 18 12:58:51.559967 2026] [security2:error] [pid 66623:tid 66892] [client 168.62.48.100:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBO9O5rbWdOArH04KuqQAAAYg"] [Tue Aug 18 12:58:51.566918 2026] [security2:error] [pid 66623:tid 66797] [client 68.155.155.199:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/info.php"] [unique_id "aoSBO9O5rbWdOArH04KuqgAAASk"] [Tue Aug 18 12:58:51.575412 2026] [security2:error] [pid 66623:tid 66834] [client 20.118.172.148:43513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBO9O5rbWdOArH04KuqwAAAU4"] [Tue Aug 18 12:58:51.580688 2026] [security2:error] [pid 66623:tid 66831] [client 52.173.121.69:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBO9O5rbWdOArH04KurAAAAUs"] [Tue Aug 18 12:58:51.581982 2026] [security2:error] [pid 66623:tid 66800] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/file2.php"] [unique_id "aoSBO9O5rbWdOArH04KurQAAASw"] [Tue Aug 18 12:58:51.671684 2026] [security2:error] [pid 66623:tid 66796] [client 132.196.30.78:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBO9O5rbWdOArH04KusgAAASg"] [Tue Aug 18 12:58:51.696231 2026] [security2:error] [pid 66623:tid 66828] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBO9O5rbWdOArH04KuswAAAUg"] [Tue Aug 18 12:58:51.746384 2026] [security2:error] [pid 66623:tid 66785] [client 158.23.17.4:40446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/admin404.php"] [unique_id "aoSBO9O5rbWdOArH04KuuAAAAR0"] [Tue Aug 18 12:58:51.775934 2026] [security2:error] [pid 66623:tid 66815] [client 172.182.200.96:14194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBO9O5rbWdOArH04KuuQAAATs"] [Tue Aug 18 12:58:51.777167 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/155.php"] [unique_id "aoSBO9O5rbWdOArH04KuugAAARo"] [Tue Aug 18 12:58:51.787715 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/sw.php"] [unique_id "aoSBO9O5rbWdOArH04KuvAABPkk"] [Tue Aug 18 12:58:51.796494 2026] [security2:error] [pid 66623:tid 66878] [client 20.203.138.185:18465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/app.php"] [unique_id "aoSBO9O5rbWdOArH04KuvQAAAXo"] [Tue Aug 18 12:58:51.797300 2026] [security2:error] [pid 66623:tid 66838] [client 4.232.151.198:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "aoSBO9O5rbWdOArH04KuvgAAAVI"] [Tue Aug 18 12:58:51.809887 2026] [security2:error] [pid 66623:tid 66845] [client 20.127.136.245:1345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/inputs.php"] [unique_id "aoSBO9O5rbWdOArH04KuvwAAAVk"] [Tue Aug 18 12:58:51.827069 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBO9O5rbWdOArH04KuwgAAAXI"] [Tue Aug 18 12:58:51.832498 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:51.832951 2026] [authz_core:error] [pid 66623:tid 66711] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:51.871427 2026] [security2:error] [pid 66623:tid 66807] [client 168.62.48.100:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBO9O5rbWdOArH04KuwwAAATM"] [Tue Aug 18 12:58:51.915390 2026] [security2:error] [pid 66623:tid 66861] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/gm.php"] [unique_id "aoSBO9O5rbWdOArH04KuxgAAAWk"] [Tue Aug 18 12:58:51.917031 2026] [security2:error] [pid 66623:tid 66868] [client 52.173.121.69:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBO9O5rbWdOArH04KuxwAAAXA"] [Tue Aug 18 12:58:51.951172 2026] [security2:error] [pid 66623:tid 66806] [client 20.104.85.180:15111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wso.php"] [unique_id "aoSBO9O5rbWdOArH04KuyQAAATI"] [Tue Aug 18 12:58:51.960386 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gc.php"] [unique_id "aoSBO9O5rbWdOArH04KuygABQFI"] [Tue Aug 18 12:58:51.970625 2026] [security2:error] [pid 66623:tid 66876] [client 20.25.139.174:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wk/index.php"] [unique_id "aoSBO9O5rbWdOArH04KuzAAAAXg"] [Tue Aug 18 12:58:51.984159 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBO9O5rbWdOArH04KuzQAAAXs"] [Tue Aug 18 12:58:52.011218 2026] [security2:error] [pid 66623:tid 66776] [client 86.120.159.145:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04KuzwAAARQ"] [Tue Aug 18 12:58:52.011368 2026] [security2:error] [pid 66623:tid 66776] [client 86.120.159.145:9995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04KuzwAAARQ"] [Tue Aug 18 12:58:52.083673 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBPNO5rbWdOArH04Ku0wAAASY"] [Tue Aug 18 12:58:52.118507 2026] [security2:error] [pid 66623:tid 66843] [client 168.62.48.100:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/oivcl.php"] [unique_id "aoSBPNO5rbWdOArH04Ku1wAAAVc"] [Tue Aug 18 12:58:52.131387 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:52.131701 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:52.152324 2026] [security2:error] [pid 66623:tid 66817] [client 20.250.13.23:1806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2QAAAT0"] [Tue Aug 18 12:58:52.160122 2026] [security2:error] [pid 66623:tid 66709] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uq.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2gABYkg"] [Tue Aug 18 12:58:52.161702 2026] [security2:error] [pid 66623:tid 66774] [client 52.173.121.69:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBPNO5rbWdOArH04Ku2wAAARI"] [Tue Aug 18 12:58:52.235131 2026] [security2:error] [pid 66623:tid 66877] [client 20.48.236.86:25940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cabeceiragrandemg.com.br"] [uri "/.mopj.php"] [unique_id "aoSBPNO5rbWdOArH04Ku3wAAAXk"] [Tue Aug 18 12:58:52.247939 2026] [security2:error] [pid 66623:tid 66842] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/ws55.php"] [unique_id "aoSBPNO5rbWdOArH04Ku4QAAAVY"] [Tue Aug 18 12:58:52.261147 2026] [security2:error] [pid 66623:tid 66768] [client 40.74.65.169:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBPNO5rbWdOArH04Ku4wAAAQw"] [Tue Aug 18 12:58:52.272286 2026] [security2:error] [pid 66623:tid 66805] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5AAAATE"] [Tue Aug 18 12:58:52.272463 2026] [security2:error] [pid 66623:tid 66866] [client 192.141.172.134:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5gAAAW4"] [Tue Aug 18 12:58:52.272484 2026] [security2:error] [pid 66623:tid 66844] [client 20.104.85.180:38024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/sf.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5QAAAVg"] [Tue Aug 18 12:58:52.272570 2026] [security2:error] [pid 66623:tid 66866] [client 192.141.172.134:52235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPNO5rbWdOArH04Ku5gAAAW4"] [Tue Aug 18 12:58:52.286245 2026] [security2:error] [pid 66623:tid 66846] [client 74.248.18.37:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/v5.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6AAAAVo"] [Tue Aug 18 12:58:52.304884 2026] [security2:error] [pid 66623:tid 66771] [client 132.196.30.78:15839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/666.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6QAAAQ8"] [Tue Aug 18 12:58:52.313102 2026] [security2:error] [pid 66623:tid 66822] [client 20.25.139.174:4609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/96i.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6gAAAUI"] [Tue Aug 18 12:58:52.338594 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/img.php"] [unique_id "aoSBPNO5rbWdOArH04Ku6wAAASg"] [Tue Aug 18 12:58:52.351976 2026] [security2:error] [pid 66623:tid 66694] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/32.php"] [unique_id "aoSBPNO5rbWdOArH04Ku7QABFjk"] [Tue Aug 18 12:58:52.408054 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:55677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBPNO5rbWdOArH04Ku7wAAARU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:52.449274 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.151.198:5492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "aoSBPNO5rbWdOArH04Ku8gAAASk"] [Tue Aug 18 12:58:52.463179 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zugvi.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9AAAAR0"] [Tue Aug 18 12:58:52.481389 2026] [security2:error] [pid 66623:tid 66815] [client 20.206.73.37:20726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/file2.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9QAAATs"] [Tue Aug 18 12:58:52.488895 2026] [security2:error] [pid 66623:tid 66812] [client 20.25.139.174:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/about.php"] [unique_id "aoSBPNO5rbWdOArH04Ku9gAAATg"] [Tue Aug 18 12:58:52.550027 2026] [security2:error] [pid 66623:tid 66826] [client 20.127.136.245:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/100.php"] [unique_id "aoSBPNO5rbWdOArH04Ku-gAAAUY"] [Tue Aug 18 12:58:52.573449 2026] [security2:error] [pid 66623:tid 66786] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/m.php"] [unique_id "aoSBPNO5rbWdOArH04Ku_gAAAR4"] [Tue Aug 18 12:58:52.596101 2026] [security2:error] [pid 66623:tid 66773] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/aa.php"] [unique_id "aoSBPNO5rbWdOArH04KvAAAAARE"] [Tue Aug 18 12:58:52.611607 2026] [security2:error] [pid 66623:tid 66669] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/73.php"] [unique_id "aoSBPNO5rbWdOArH04KvAQABCyA"] [Tue Aug 18 12:58:52.625930 2026] [security2:error] [pid 66623:tid 66874] [client 158.23.17.4:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qo.php"] [unique_id "aoSBPNO5rbWdOArH04KvAgAAAXY"] [Tue Aug 18 12:58:52.670836 2026] [security2:error] [pid 66623:tid 66821] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/cok.php"] [unique_id "aoSBPNO5rbWdOArH04KvBgAAAUE"] [Tue Aug 18 12:58:52.729270 2026] [security2:error] [pid 66623:tid 66858] [client 52.173.121.69:30393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBPNO5rbWdOArH04KvCgAAAWY"] [Tue Aug 18 12:58:52.733119 2026] [authz_core:error] [pid 66623:tid 66757] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:52.733380 2026] [authz_core:error] [pid 66623:tid 66757] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:52.735186 2026] [security2:error] [pid 66623:tid 66787] [client 168.62.48.100:1034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wsrer.php"] [unique_id "aoSBPNO5rbWdOArH04KvDAAAAR8"] [Tue Aug 18 12:58:52.755311 2026] [security2:error] [pid 66623:tid 66779] [client 20.104.85.180:38634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/index/function.php"] [unique_id "aoSBPNO5rbWdOArH04KvDQAAARc"] [Tue Aug 18 12:58:52.779489 2026] [security2:error] [pid 66623:tid 66832] [client 172.182.200.96:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBPNO5rbWdOArH04KvDgAAAUw"] [Tue Aug 18 12:58:52.781967 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:53634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBPNO5rbWdOArH04KvDwAAATM"] [Tue Aug 18 12:58:52.804470 2026] [security2:error] [pid 66623:tid 66664] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ib.php"] [unique_id "aoSBPNO5rbWdOArH04KvEAABYhs"] [Tue Aug 18 12:58:52.873716 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:53093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBPNO5rbWdOArH04KvEwAAAS8"] [Tue Aug 18 12:58:52.907018 2026] [security2:error] [pid 66623:tid 66802] [client 20.25.139.174:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/as.php"] [unique_id "aoSBPNO5rbWdOArH04KvFgAAAS4"] [Tue Aug 18 12:58:52.914888 2026] [security2:error] [pid 66623:tid 66831] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/33.php"] [unique_id "aoSBPNO5rbWdOArH04KvGQAAAUs"] [Tue Aug 18 12:58:52.915153 2026] [security2:error] [pid 66623:tid 66800] [client 68.155.155.199:6331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/profile.php"] [unique_id "aoSBPNO5rbWdOArH04KvFwAAASw"] [Tue Aug 18 12:58:52.957516 2026] [security2:error] [pid 66623:tid 66811] [client 40.74.65.169:20105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file52.php"] [unique_id "aoSBPNO5rbWdOArH04KvGwAAATc"] [Tue Aug 18 12:58:52.961542 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/accesson.php"] [unique_id "aoSBPNO5rbWdOArH04KvHAAAAUI"] [Tue Aug 18 12:58:52.994636 2026] [security2:error] [pid 66623:tid 66884] [client 168.62.48.100:1156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBPNO5rbWdOArH04KvHgAAAYA"] [Tue Aug 18 12:58:52.996696 2026] [security2:error] [pid 66623:tid 66640] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xm.php"] [unique_id "aoSBPNO5rbWdOArH04KvHwABKAM"] [Tue Aug 18 12:58:53.002349 2026] [security2:error] [pid 66623:tid 66840] [client 172.202.39.151:40357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/inputs.php"] [unique_id "aoSBPdO5rbWdOArH04KvIQAAAVQ"] [Tue Aug 18 12:58:53.031965 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:53.032239 2026] [authz_core:error] [pid 66623:tid 66721] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:53.040509 2026] [security2:error] [pid 66623:tid 66892] [client 20.25.139.174:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/term.php"] [unique_id "aoSBPdO5rbWdOArH04KvJAAAAYg"] [Tue Aug 18 12:58:53.061507 2026] [security2:error] [pid 66623:tid 66890] [client 74.248.18.37:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/we.php"] [unique_id "aoSBPdO5rbWdOArH04KvJQAAAYY"] [Tue Aug 18 12:58:53.093178 2026] [security2:error] [pid 66623:tid 66808] [client 4.232.151.198:58749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "aoSBPdO5rbWdOArH04KvJgAAATQ"] [Tue Aug 18 12:58:53.118716 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/edit.php"] [unique_id "aoSBPdO5rbWdOArH04KvKQAAATs"] [Tue Aug 18 12:58:53.145666 2026] [autoindex:error] [pid 66623:tid 66785] [client 169.58.72.248:53716] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:58:53.178133 2026] [security2:error] [pid 66623:tid 66883] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/av.php"] [unique_id "aoSBPdO5rbWdOArH04KvLQAAAX8"] [Tue Aug 18 12:58:53.179987 2026] [security2:error] [pid 66623:tid 66699] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zy.php"] [unique_id "aoSBPdO5rbWdOArH04KvLgABKz4"] [Tue Aug 18 12:58:53.192139 2026] [security2:error] [pid 66623:tid 66826] [client 52.173.121.69:30364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBPdO5rbWdOArH04KvMAAAAUY"] [Tue Aug 18 12:58:53.209267 2026] [security2:error] [pid 66623:tid 66781] [client 20.203.138.185:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBPdO5rbWdOArH04KvMwAAARk"] [Tue Aug 18 12:58:53.227737 2026] [security2:error] [pid 66623:tid 66816] [client 172.182.200.96:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBPdO5rbWdOArH04KvNAAAATw"] [Tue Aug 18 12:58:53.246911 2026] [security2:error] [pid 66623:tid 66835] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/packed.php"] [unique_id "aoSBPdO5rbWdOArH04KvNQAAAU8"] [Tue Aug 18 12:58:53.253930 2026] [security2:error] [pid 66623:tid 66767] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/av.php"] [unique_id "aoSBPdO5rbWdOArH04KvNgAAAQs"] [Tue Aug 18 12:58:53.309425 2026] [security2:error] [pid 66623:tid 66776] [client 20.215.241.237:65234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/puc.php"] [unique_id "aoSBPdO5rbWdOArH04KvOAAAARQ"] [Tue Aug 18 12:58:53.310786 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBPdO5rbWdOArH04KvOQAAAUE"] [Tue Aug 18 12:58:53.340487 2026] [security2:error] [pid 66623:tid 66858] [client 168.62.48.100:1069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/yxijx.php"] [unique_id "aoSBPdO5rbWdOArH04KvQAAAAWY"] [Tue Aug 18 12:58:53.372389 2026] [security2:error] [pid 66623:tid 66689] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/q.php"] [unique_id "aoSBPdO5rbWdOArH04KvSQABVzQ"] [Tue Aug 18 12:58:53.388744 2026] [security2:error] [pid 66623:tid 66832] [client 20.127.136.245:17065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/akc.php"] [unique_id "aoSBPdO5rbWdOArH04KvSwAAAUw"] [Tue Aug 18 12:58:53.403999 2026] [security2:error] [pid 66623:tid 66836] [client 20.65.98.162:18329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBPdO5rbWdOArH04KvTAAAAVA"] [Tue Aug 18 12:58:53.406523 2026] [security2:error] [pid 66623:tid 66803] [client 20.48.236.86:32841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/bengi.php"] [unique_id "aoSBPdO5rbWdOArH04KvTQAAAS8"] [Tue Aug 18 12:58:53.420552 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/min.php"] [unique_id "aoSBPdO5rbWdOArH04KvTgAAASA"] [Tue Aug 18 12:58:53.425827 2026] [security2:error] [pid 66623:tid 66797] [client 213.35.127.232:55871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBPdO5rbWdOArH04KvUAAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:53.428138 2026] [security2:error] [pid 66623:tid 66770] [client 20.100.169.31:12481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/atex1.php"] [unique_id "aoSBPdO5rbWdOArH04KvUQAAAQ4"] [Tue Aug 18 12:58:53.433260 2026] [security2:error] [pid 66623:tid 66814] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/media.php"] [unique_id "aoSBPdO5rbWdOArH04KvUgAAATo"] [Tue Aug 18 12:58:53.453482 2026] [security2:error] [pid 66623:tid 66889] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvTwABhSU"] [Tue Aug 18 12:58:53.539669 2026] [security2:error] [pid 66623:tid 66789] [client 20.250.13.23:45757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBPdO5rbWdOArH04KvVgAAASE"] [Tue Aug 18 12:58:53.541359 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/kj.php"] [unique_id "aoSBPdO5rbWdOArH04KvVwAAARs"] [Tue Aug 18 12:58:53.552396 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xf.php"] [unique_id "aoSBPdO5rbWdOArH04KvWQABVDg"] [Tue Aug 18 12:58:53.566213 2026] [security2:error] [pid 66623:tid 66804] [client 20.25.139.174:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBPdO5rbWdOArH04KvXAAAATA"] [Tue Aug 18 12:58:53.577280 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:47357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBPdO5rbWdOArH04KvXQAAAYg"] [Tue Aug 18 12:58:53.612515 2026] [security2:error] [pid 66623:tid 66819] [client 158.23.17.4:47630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sd.php"] [unique_id "aoSBPdO5rbWdOArH04KvYAAAAT8"] [Tue Aug 18 12:58:53.659423 2026] [security2:error] [pid 66623:tid 66791] [client 168.62.48.100:1073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBPdO5rbWdOArH04KvYgAAASM"] [Tue Aug 18 12:58:53.662407 2026] [security2:error] [pid 66623:tid 66815] [client 40.74.65.169:20156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/geck.php"] [unique_id "aoSBPdO5rbWdOArH04KvYwAAATs"] [Tue Aug 18 12:58:53.662940 2026] [security2:error] [pid 66623:tid 66877] [client 213.202.253.4:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/postnews.php"] [unique_id "aoSBPdO5rbWdOArH04KvZAAAAXk"], referer: www.google.com [Tue Aug 18 12:58:53.665906 2026] [security2:error] [pid 66623:tid 66782] [client 20.206.73.37:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/gm.php"] [unique_id "aoSBPdO5rbWdOArH04KvZQAAARo"] [Tue Aug 18 12:58:53.703930 2026] [security2:error] [pid 66623:tid 66818] [client 20.104.85.180:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBPdO5rbWdOArH04KvZgAAAT4"] [Tue Aug 18 12:58:53.708671 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/images.php"] [unique_id "aoSBPdO5rbWdOArH04KvZwAAAVI"] [Tue Aug 18 12:58:53.733621 2026] [security2:error] [pid 66623:tid 66750] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gb.php"] [unique_id "aoSBPdO5rbWdOArH04KvaQABWXE"] [Tue Aug 18 12:58:53.737166 2026] [security2:error] [pid 66623:tid 66849] [client 172.182.200.96:14189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBPdO5rbWdOArH04KvawAAAV0"] [Tue Aug 18 12:58:53.757246 2026] [security2:error] [pid 66623:tid 66778] [client 4.232.151.198:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/json.php"] [unique_id "aoSBPdO5rbWdOArH04KvcAAAARY"] [Tue Aug 18 12:58:53.764269 2026] [security2:error] [pid 66623:tid 66662] [remote 66.102.134.13:48530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-login.php"] [unique_id "aoSBPdO5rbWdOArH04KvcQABHhk"] [Tue Aug 18 12:58:53.773077 2026] [security2:error] [pid 66623:tid 66811] [client 74.248.18.37:47255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wkl.php"] [unique_id "aoSBPdO5rbWdOArH04KvcgAAATc"] [Tue Aug 18 12:58:53.820388 2026] [security2:error] [pid 66623:tid 66820] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBPdO5rbWdOArH04KvcwAAAUA"] [Tue Aug 18 12:58:53.919369 2026] [security2:error] [pid 66623:tid 66810] [client 149.50.220.157:13873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.220.50.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "informatik.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvbAAAATY"] [Tue Aug 18 12:58:53.919494 2026] [security2:error] [pid 66623:tid 66810] [client 149.50.220.157:13873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "informatik.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvbAAAATY"] [Tue Aug 18 12:58:53.931367 2026] [security2:error] [pid 66623:tid 66885] [client 168.62.48.100:1064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/jrpga.php"] [unique_id "aoSBPdO5rbWdOArH04KveAAAAYE"] [Tue Aug 18 12:58:53.935186 2026] [security2:error] [pid 66623:tid 66725] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jp.php"] [unique_id "aoSBPdO5rbWdOArH04KvewABZlg"] [Tue Aug 18 12:58:53.937505 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:53.937813 2026] [authz_core:error] [pid 66623:tid 66761] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:53.976811 2026] [security2:error] [pid 66623:tid 66854] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/admin.php"] [unique_id "aoSBPdO5rbWdOArH04KvfwAAAWI"] [Tue Aug 18 12:58:53.977260 2026] [security2:error] [pid 66623:tid 66749] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvfgABTHA"] [Tue Aug 18 12:58:53.977442 2026] [security2:error] [pid 66623:tid 66832] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPdO5rbWdOArH04KvfgABTHA"] [Tue Aug 18 12:58:54.020080 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBPtO5rbWdOArH04KvgwAAAS8"] [Tue Aug 18 12:58:54.068952 2026] [security2:error] [pid 66623:tid 66770] [client 20.104.85.180:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-good.php"] [unique_id "aoSBPtO5rbWdOArH04KvhQAAAQ4"] [Tue Aug 18 12:58:54.075733 2026] [security2:error] [pid 66623:tid 66814] [client 52.173.121.69:14855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBPtO5rbWdOArH04KvhgAAATo"] [Tue Aug 18 12:58:54.087492 2026] [security2:error] [pid 66623:tid 66829] [client 20.25.139.174:4614] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cadema.com.br"] [uri "/1.php"] [unique_id "aoSBPtO5rbWdOArH04KvhwAAAUk"] [Tue Aug 18 12:58:54.087594 2026] [security2:error] [pid 66623:tid 66829] [client 20.25.139.174:4614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/1.php"] [unique_id "aoSBPtO5rbWdOArH04KvhwAAAUk"] [Tue Aug 18 12:58:54.107995 2026] [security2:error] [pid 66623:tid 66831] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/png.php"] [unique_id "aoSBPtO5rbWdOArH04KviQAAAUs"] [Tue Aug 18 12:58:54.115956 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.105:37446] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:54.116215 2026] [authz_core:error] [pid 66623:tid 66638] [remote 57.141.22.105:37446] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:54.117299 2026] [security2:error] [pid 66623:tid 66800] [client 158.23.17.4:47621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/km.php"] [unique_id "aoSBPtO5rbWdOArH04KviwAAASw"] [Tue Aug 18 12:58:54.147480 2026] [security2:error] [pid 66623:tid 66866] [client 172.182.200.96:7644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBPtO5rbWdOArH04KvjAAAAW4"] [Tue Aug 18 12:58:54.149571 2026] [security2:error] [pid 66623:tid 66827] [client 37.40.227.74:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjQAAAUc"] [Tue Aug 18 12:58:54.149666 2026] [security2:error] [pid 66623:tid 66827] [client 37.40.227.74:56856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjQAAAUc"] [Tue Aug 18 12:58:54.152710 2026] [security2:error] [pid 66623:tid 66844] [client 20.203.138.185:37271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/cxc.php"] [unique_id "aoSBPtO5rbWdOArH04KvjgAAAVg"] [Tue Aug 18 12:58:54.185884 2026] [security2:error] [pid 66623:tid 66822] [client 168.62.48.100:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBPtO5rbWdOArH04KvkAAAAUI"] [Tue Aug 18 12:58:54.202761 2026] [security2:error] [pid 66623:tid 66884] [client 68.155.155.199:12927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/sx.php"] [unique_id "aoSBPtO5rbWdOArH04KvkwAAAYA"] [Tue Aug 18 12:58:54.230826 2026] [security2:error] [pid 66623:tid 66828] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/222.php"] [unique_id "aoSBPtO5rbWdOArH04KvlgAAAUg"] [Tue Aug 18 12:58:54.238131 2026] [security2:error] [pid 66623:tid 66672] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eq.php"] [unique_id "aoSBPtO5rbWdOArH04KvlwABMCM"] [Tue Aug 18 12:58:54.276612 2026] [security2:error] [pid 66623:tid 66862] [client 103.184.169.37:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvmgAAAWo"] [Tue Aug 18 12:58:54.276760 2026] [security2:error] [pid 66623:tid 66862] [client 103.184.169.37:42460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvmgAAAWo"] [Tue Aug 18 12:58:54.339318 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:54.339780 2026] [authz_core:error] [pid 66623:tid 66670] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:54.340990 2026] [security2:error] [pid 66623:tid 66877] [client 20.127.136.245:3259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBPtO5rbWdOArH04KvngAAAXk"] [Tue Aug 18 12:58:54.359328 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:20140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/biufile.php"] [unique_id "aoSBPtO5rbWdOArH04KvoAAAAWE"] [Tue Aug 18 12:58:54.382354 2026] [security2:error] [pid 66623:tid 66834] [client 52.173.121.69:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBPtO5rbWdOArH04KvowAAAU4"] [Tue Aug 18 12:58:54.387147 2026] [security2:error] [pid 66623:tid 66778] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ab.php"] [unique_id "aoSBPtO5rbWdOArH04KvpAAAARY"] [Tue Aug 18 12:58:54.396545 2026] [security2:error] [pid 66623:tid 66883] [client 103.120.71.157:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvpgAAAX8"] [Tue Aug 18 12:58:54.396638 2026] [security2:error] [pid 66623:tid 66883] [client 103.120.71.157:60068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBPtO5rbWdOArH04KvpgAAAX8"] [Tue Aug 18 12:58:54.414510 2026] [security2:error] [pid 66623:tid 66846] [client 4.232.151.198:5482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/css/index.php"] [unique_id "aoSBPtO5rbWdOArH04KvpwAAAVo"] [Tue Aug 18 12:58:54.415056 2026] [security2:error] [pid 66623:tid 66864] [client 20.118.172.148:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBPtO5rbWdOArH04KvqAAAAWw"] [Tue Aug 18 12:58:54.416373 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ep.php"] [unique_id "aoSBPtO5rbWdOArH04KvqQABHl8"] [Tue Aug 18 12:58:54.446688 2026] [security2:error] [pid 66623:tid 66889] [client 213.35.127.232:56084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBPtO5rbWdOArH04KvqgAAAYU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:54.474305 2026] [security2:error] [pid 66623:tid 66806] [client 168.62.48.100:1038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/nwwha.php"] [unique_id "aoSBPtO5rbWdOArH04KvrQAAATI"] [Tue Aug 18 12:58:54.491219 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mac.php"] [unique_id "aoSBPtO5rbWdOArH04KvsQAAAQs"] [Tue Aug 18 12:58:54.511759 2026] [security2:error] [pid 66623:tid 66873] [client 20.25.139.174:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/php8.php"] [unique_id "aoSBPtO5rbWdOArH04KvsgAAAXU"] [Tue Aug 18 12:58:54.513385 2026] [security2:error] [pid 66623:tid 66874] [client 172.182.200.96:14166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBPtO5rbWdOArH04KvswAAAXY"] [Tue Aug 18 12:58:54.532267 2026] [security2:error] [pid 66623:tid 66882] [client 20.100.169.31:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBPtO5rbWdOArH04KvtAAAAX4"] [Tue Aug 18 12:58:54.578969 2026] [security2:error] [pid 66623:tid 66858] [client 20.206.73.37:20685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/ws55.php"] [unique_id "aoSBPtO5rbWdOArH04KvugAAAWY"] [Tue Aug 18 12:58:54.581341 2026] [security2:error] [pid 66623:tid 66807] [client 20.250.13.23:1815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBPtO5rbWdOArH04KvuwAAATM"] [Tue Aug 18 12:58:54.609012 2026] [security2:error] [pid 66623:tid 66754] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rf.php"] [unique_id "aoSBPtO5rbWdOArH04KvvgABH3U"] [Tue Aug 18 12:58:54.631099 2026] [security2:error] [pid 66623:tid 66781] [client 20.25.139.174:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/alfa.php"] [unique_id "aoSBPtO5rbWdOArH04KvwAAAARk"] [Tue Aug 18 12:58:54.724496 2026] [security2:error] [pid 66623:tid 66872] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/12.php"] [unique_id "aoSBPtO5rbWdOArH04KvyAAAAXQ"] [Tue Aug 18 12:58:54.725247 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:48290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBPtO5rbWdOArH04KvyQAAAWk"] [Tue Aug 18 12:58:54.732579 2026] [security2:error] [pid 66623:tid 66822] [client 20.48.236.86:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/file2.php"] [unique_id "aoSBPtO5rbWdOArH04KvygAAAUI"] [Tue Aug 18 12:58:54.742348 2026] [security2:error] [pid 66623:tid 66783] [client 168.62.48.100:1103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/opsqt.php"] [unique_id "aoSBPtO5rbWdOArH04KvzQAAARs"] [Tue Aug 18 12:58:54.756568 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ops.php"] [unique_id "aoSBPtO5rbWdOArH04KvzgAAAUM"] [Tue Aug 18 12:58:54.761058 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/work.php"] [unique_id "aoSBPtO5rbWdOArH04KvzwAAASQ"] [Tue Aug 18 12:58:54.763676 2026] [security2:error] [pid 66623:tid 66698] [remote 57.141.22.99:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSBPtO5rbWdOArH04Kv0QABST0"] [Tue Aug 18 12:58:54.824454 2026] [security2:error] [pid 66623:tid 66862] [client 20.127.136.245:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/php.php"] [unique_id "aoSBPtO5rbWdOArH04Kv0gAAAWo"] [Tue Aug 18 12:58:54.839580 2026] [authz_core:error] [pid 66623:tid 66739] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:54.839871 2026] [authz_core:error] [pid 66623:tid 66739] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:54.841042 2026] [security2:error] [pid 66623:tid 66658] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xynz1.php"] [unique_id "aoSBPtO5rbWdOArH04Kv1QABNRU"] [Tue Aug 18 12:58:54.841492 2026] [security2:error] [pid 66623:tid 66780] [client 20.104.85.180:38031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/tes.php"] [unique_id "aoSBPtO5rbWdOArH04Kv1gAAARg"] [Tue Aug 18 12:58:54.871588 2026] [security2:error] [pid 66623:tid 66857] [client 20.203.138.185:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBPtO5rbWdOArH04Kv2AAAAWU"] [Tue Aug 18 12:58:54.914603 2026] [security2:error] [pid 66623:tid 66848] [client 172.182.200.96:14083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBPtO5rbWdOArH04Kv2QAAAVw"] [Tue Aug 18 12:58:55.017919 2026] [security2:error] [pid 66623:tid 66769] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/x1da.php"] [unique_id "aoSBP9O5rbWdOArH04Kv4wAAAQ0"] [Tue Aug 18 12:58:55.021357 2026] [security2:error] [pid 66623:tid 66668] [remote 172.237.150.158:46238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04Kv4gABUh8"] [Tue Aug 18 12:58:55.023303 2026] [security2:error] [pid 66623:tid 66835] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/8.php"] [unique_id "aoSBP9O5rbWdOArH04Kv5gAAAU8"] [Tue Aug 18 12:58:55.041208 2026] [security2:error] [pid 66623:tid 66818] [client 20.25.139.174:4655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBP9O5rbWdOArH04Kv6gAAAT4"] [Tue Aug 18 12:58:55.043818 2026] [security2:error] [pid 66623:tid 66819] [client 4.232.151.198:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/assets/images/tinyimg.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7QAAAT8"] [Tue Aug 18 12:58:55.056782 2026] [security2:error] [pid 66623:tid 66847] [client 40.74.65.169:43042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dejavu.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7gAAAVs"] [Tue Aug 18 12:58:55.087707 2026] [security2:error] [pid 66623:tid 66801] [client 168.62.48.100:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBP9O5rbWdOArH04Kv7wAAAS0"] [Tue Aug 18 12:58:55.146348 2026] [security2:error] [pid 66623:tid 66889] [client 20.25.139.174:4664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/edit.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9AAAAYU"] [Tue Aug 18 12:58:55.167614 2026] [security2:error] [pid 66623:tid 66832] [client 52.173.121.69:29013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9QAAAUw"] [Tue Aug 18 12:58:55.192156 2026] [security2:error] [pid 66623:tid 66855] [client 20.250.13.23:1855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBP9O5rbWdOArH04Kv9gAAAWM"] [Tue Aug 18 12:58:55.228812 2026] [security2:error] [pid 66623:tid 66784] [client 149.34.210.141:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04Kv-AAAARw"] [Tue Aug 18 12:58:55.253601 2026] [security2:error] [pid 66623:tid 66854] [client 172.182.200.96:7628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBP9O5rbWdOArH04Kv_gAAAWI"] [Tue Aug 18 12:58:55.289435 2026] [security2:error] [pid 66623:tid 66701] [remote 110.249.202.144:19298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gustavofrison.com.br"] [uri "/wp-content/uploads/2016/10/facebook.png"] [unique_id "aoSBP9O5rbWdOArH04KwAQABNEA"] [Tue Aug 18 12:58:55.290161 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:46756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/files/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwAgAAASI"] [Tue Aug 18 12:58:55.295972 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/biufile.php"] [unique_id "aoSBP9O5rbWdOArH04KwAwAAAW0"] [Tue Aug 18 12:58:55.296302 2026] [security2:error] [pid 66623:tid 66773] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mcs.php"] [unique_id "aoSBP9O5rbWdOArH04KwBAAAARE"] [Tue Aug 18 12:58:55.363559 2026] [security2:error] [pid 66623:tid 66783] [client 20.118.172.148:19688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/0x.php"] [unique_id "aoSBP9O5rbWdOArH04KwCQAAARs"] [Tue Aug 18 12:58:55.377849 2026] [security2:error] [pid 66623:tid 66823] [client 20.127.136.245:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/t.php"] [unique_id "aoSBP9O5rbWdOArH04KwCgAAAUM"] [Tue Aug 18 12:58:55.386811 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:1096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBP9O5rbWdOArH04KwCwAAASQ"] [Tue Aug 18 12:58:55.398257 2026] [security2:error] [pid 66623:tid 66837] [client 74.248.18.37:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/worksec.php"] [unique_id "aoSBP9O5rbWdOArH04KwDQAAAVE"] [Tue Aug 18 12:58:55.401747 2026] [security2:error] [pid 66623:tid 66804] [client 158.23.17.4:56544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mf.php"] [unique_id "aoSBP9O5rbWdOArH04KwDgAAATA"] [Tue Aug 18 12:58:55.459272 2026] [security2:error] [pid 66623:tid 66779] [client 213.35.127.232:56289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBP9O5rbWdOArH04KwEQAAARc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:55.483971 2026] [security2:error] [pid 66623:tid 66763] [remote 172.237.150.158:46252] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04KwEwABQn4"] [Tue Aug 18 12:58:55.487089 2026] [security2:error] [pid 66623:tid 66800] [client 157.20.138.62:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwFgAAASw"] [Tue Aug 18 12:58:55.487179 2026] [security2:error] [pid 66623:tid 66800] [client 157.20.138.62:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwFgAAASw"] [Tue Aug 18 12:58:55.491260 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/k.php"] [unique_id "aoSBP9O5rbWdOArH04KwFwAAAUQ"] [Tue Aug 18 12:58:55.495220 2026] [security2:error] [pid 66623:tid 66784] [client 149.34.210.141:63442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04Kv-AAAARw"] [Tue Aug 18 12:58:55.530075 2026] [security2:error] [pid 66623:tid 66796] [client 20.25.139.174:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/222.php"] [unique_id "aoSBP9O5rbWdOArH04KwGAAAASg"] [Tue Aug 18 12:58:55.542903 2026] [security2:error] [pid 66623:tid 66782] [client 52.173.121.69:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwGQAAARo"] [Tue Aug 18 12:58:55.546881 2026] [security2:error] [pid 66623:tid 66845] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/coffexium.php"] [unique_id "aoSBP9O5rbWdOArH04KwGgAAAVk"] [Tue Aug 18 12:58:55.555784 2026] [security2:error] [pid 66623:tid 66853] [client 20.203.138.185:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/0.php"] [unique_id "aoSBP9O5rbWdOArH04KwGwAAAWE"] [Tue Aug 18 12:58:55.610367 2026] [security2:error] [pid 66623:tid 66883] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/adminner.php"] [unique_id "aoSBP9O5rbWdOArH04KwHQAAAX8"] [Tue Aug 18 12:58:55.638715 2026] [security2:error] [pid 66623:tid 66786] [client 168.62.48.100:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBP9O5rbWdOArH04KwHwAAAR4"] [Tue Aug 18 12:58:55.643208 2026] [security2:error] [pid 66623:tid 66881] [client 20.25.139.174:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/elp.php"] [unique_id "aoSBP9O5rbWdOArH04KwIAAAAX0"] [Tue Aug 18 12:58:55.678836 2026] [security2:error] [pid 66623:tid 66769] [client 52.173.121.69:48298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBP9O5rbWdOArH04KwJAAAAQ0"] [Tue Aug 18 12:58:55.685703 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:5470] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSBP9O5rbWdOArH04KwJQAAARU"] [Tue Aug 18 12:58:55.685816 2026] [security2:error] [pid 66623:tid 66777] [client 4.232.151.198:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSBP9O5rbWdOArH04KwJQAAARU"] [Tue Aug 18 12:58:55.737236 2026] [security2:error] [pid 66623:tid 66851] [client 172.182.200.96:14181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/rezor.php"] [unique_id "aoSBP9O5rbWdOArH04KwKAAAAV8"] [Tue Aug 18 12:58:55.738748 2026] [security2:error] [pid 66623:tid 66882] [client 40.74.65.169:20138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aaf.php"] [unique_id "aoSBP9O5rbWdOArH04KwKQAAAX4"] [Tue Aug 18 12:58:55.739508 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwKgAAAUE"] [Tue Aug 18 12:58:55.739597 2026] [security2:error] [pid 66623:tid 66821] [client 5.31.227.224:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBP9O5rbWdOArH04KwKgAAAUE"] [Tue Aug 18 12:58:55.760363 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:55.760627 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:55.847902 2026] [security2:error] [pid 66623:tid 66727] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vo.php"] [unique_id "aoSBP9O5rbWdOArH04KwMQABQFo"] [Tue Aug 18 12:58:55.879410 2026] [security2:error] [pid 66623:tid 66871] [client 20.104.85.180:35895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBP9O5rbWdOArH04KwNQAAAXM"] [Tue Aug 18 12:58:55.888553 2026] [security2:error] [pid 66623:tid 66880] [client 168.62.48.100:1133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBP9O5rbWdOArH04KwNwAAAXw"] [Tue Aug 18 12:58:55.896572 2026] [security2:error] [pid 66623:tid 66836] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBP9O5rbWdOArH04KwOAAAAVA"] [Tue Aug 18 12:58:55.944282 2026] [security2:error] [pid 66623:tid 66743] [remote 172.237.150.158:46262] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBP9O5rbWdOArH04KwOwABRmo"] [Tue Aug 18 12:58:55.985647 2026] [security2:error] [pid 66623:tid 66868] [client 20.250.13.23:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ws54.php"] [unique_id "aoSBP9O5rbWdOArH04KwPQAAAXA"] [Tue Aug 18 12:58:56.042455 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:56.042715 2026] [authz_core:error] [pid 66623:tid 66728] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:56.046403 2026] [security2:error] [pid 66623:tid 66855] [client 20.25.139.174:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBQNO5rbWdOArH04KwQgAAAWM"] [Tue Aug 18 12:58:56.053303 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:17924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBQNO5rbWdOArH04KwQwAAAWk"] [Tue Aug 18 12:58:56.065792 2026] [security2:error] [pid 66623:tid 66850] [client 20.127.136.245:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/index/function.php"] [unique_id "aoSBQNO5rbWdOArH04KwRAAAAV4"] [Tue Aug 18 12:58:56.066834 2026] [security2:error] [pid 66623:tid 66844] [client 20.48.236.86:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/gm.php"] [unique_id "aoSBQNO5rbWdOArH04KwRQAAAVg"] [Tue Aug 18 12:58:56.071353 2026] [security2:error] [pid 66623:tid 66792] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/dex.php"] [unique_id "aoSBQNO5rbWdOArH04KwRgAAASQ"] [Tue Aug 18 12:58:56.082047 2026] [security2:error] [pid 66623:tid 66834] [client 138.36.100.162:43092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwRwAAAU4"] [Tue Aug 18 12:58:56.082153 2026] [security2:error] [pid 66623:tid 66834] [client 138.36.100.162:43092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwRwAAAU4"] [Tue Aug 18 12:58:56.084885 2026] [security2:error] [pid 66623:tid 66887] [client 172.182.200.96:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBQNO5rbWdOArH04KwSAAAAYM"] [Tue Aug 18 12:58:56.111889 2026] [security2:error] [pid 66623:tid 66780] [client 178.153.171.161:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwSgAAARg"] [Tue Aug 18 12:58:56.112061 2026] [security2:error] [pid 66623:tid 66780] [client 178.153.171.161:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwSgAAARg"] [Tue Aug 18 12:58:56.158324 2026] [security2:error] [pid 66623:tid 66802] [client 68.221.73.131:27442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBQNO5rbWdOArH04KwUAAAAS4"] [Tue Aug 18 12:58:56.161514 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBQNO5rbWdOArH04KwUQAAASI"] [Tue Aug 18 12:58:56.179167 2026] [security2:error] [pid 66623:tid 66808] [client 79.127.164.8:58254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/spider/uninstallmysql.bak"] [unique_id "aoSBQNO5rbWdOArH04KwUgAAATQ"], referer: https://medihub.com.br/spider/uninstallmysql.bak [Tue Aug 18 12:58:56.213160 2026] [security2:error] [pid 66623:tid 66815] [client 20.104.85.180:31252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBQNO5rbWdOArH04KwUwAAATs"] [Tue Aug 18 12:58:56.220345 2026] [security2:error] [pid 66623:tid 66796] [client 20.250.13.23:1798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBQNO5rbWdOArH04KwVQAAASg"] [Tue Aug 18 12:58:56.243030 2026] [security2:error] [pid 66623:tid 66776] [client 172.202.39.151:40364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/alfa.php"] [unique_id "aoSBQNO5rbWdOArH04KwVgAAARQ"] [Tue Aug 18 12:58:56.256813 2026] [security2:error] [pid 66623:tid 66781] [client 74.248.18.37:19269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-activate.php"] [unique_id "aoSBQNO5rbWdOArH04KwWAAAARk"] [Tue Aug 18 12:58:56.269664 2026] [security2:error] [pid 66623:tid 66810] [client 223.185.37.47:17159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwWgAAATY"] [Tue Aug 18 12:58:56.269800 2026] [security2:error] [pid 66623:tid 66810] [client 223.185.37.47:17159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwWgAAATY"] [Tue Aug 18 12:58:56.281433 2026] [security2:error] [pid 66623:tid 66888] [client 158.23.17.4:15766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ie.php"] [unique_id "aoSBQNO5rbWdOArH04KwXAAAAYQ"] [Tue Aug 18 12:58:56.290754 2026] [security2:error] [pid 66623:tid 66883] [client 20.206.73.37:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/m.php"] [unique_id "aoSBQNO5rbWdOArH04KwXwAAAX8"] [Tue Aug 18 12:58:56.310974 2026] [security2:error] [pid 66623:tid 66674] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wu.php"] [unique_id "aoSBQNO5rbWdOArH04KwYgABPCU"] [Tue Aug 18 12:58:56.332381 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSBQNO5rbWdOArH04KwZQAAAVI"] [Tue Aug 18 12:58:56.332472 2026] [security2:error] [pid 66623:tid 66838] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSBQNO5rbWdOArH04KwZQAAAVI"] [Tue Aug 18 12:58:56.346767 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:56.347053 2026] [authz_core:error] [pid 66623:tid 66676] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:56.372543 2026] [security2:error] [pid 66623:tid 66819] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/setup-config.php"] [unique_id "aoSBQNO5rbWdOArH04KwaAAAAT8"] [Tue Aug 18 12:58:56.374927 2026] [security2:error] [pid 66623:tid 66793] [client 4.232.94.69:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSBQNO5rbWdOArH04KwaQAAASU"] [Tue Aug 18 12:58:56.378281 2026] [security2:error] [pid 66623:tid 66882] [client 168.62.48.100:1177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBQNO5rbWdOArH04KwagAAAX4"] [Tue Aug 18 12:58:56.393328 2026] [security2:error] [pid 66623:tid 66799] [client 20.118.172.148:63071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/222.php"] [unique_id "aoSBQNO5rbWdOArH04KwawAAASs"] [Tue Aug 18 12:58:56.400740 2026] [security2:error] [pid 66623:tid 66867] [client 20.104.85.180:20258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/403.php"] [unique_id "aoSBQNO5rbWdOArH04KwbwAAAW8"] [Tue Aug 18 12:58:56.401567 2026] [security2:error] [pid 66623:tid 66721] [remote 172.237.150.158:46272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "capecodcleaningservice.com"] [uri "/"] [unique_id "aoSBQNO5rbWdOArH04KwbQABXVQ"] [Tue Aug 18 12:58:56.402960 2026] [security2:error] [pid 66623:tid 66659] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwbgABeBY"] [Tue Aug 18 12:58:56.403140 2026] [security2:error] [pid 66623:tid 66876] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwbgABeBY"] [Tue Aug 18 12:58:56.436623 2026] [security2:error] [pid 66623:tid 66848] [client 40.74.65.169:20346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBQNO5rbWdOArH04KwcAAAAVw"] [Tue Aug 18 12:58:56.472940 2026] [security2:error] [pid 66623:tid 66779] [client 213.35.127.232:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBQNO5rbWdOArH04KwcQAAARc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:56.504574 2026] [security2:error] [pid 66623:tid 66852] [client 172.182.200.96:14115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBQNO5rbWdOArH04KwcwAAAWA"] [Tue Aug 18 12:58:56.531838 2026] [security2:error] [pid 66623:tid 66803] [client 20.203.138.185:10412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/dom.php"] [unique_id "aoSBQNO5rbWdOArH04KwdAAAAS8"] [Tue Aug 18 12:58:56.537925 2026] [security2:error] [pid 66623:tid 66851] [client 20.25.139.174:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/info.php"] [unique_id "aoSBQNO5rbWdOArH04KwdQAAAV8"] [Tue Aug 18 12:58:56.563439 2026] [security2:error] [pid 66623:tid 66842] [client 20.65.98.162:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBQNO5rbWdOArH04KweAAAAVY"] [Tue Aug 18 12:58:56.573941 2026] [security2:error] [pid 66623:tid 66826] [client 4.232.151.198:58708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/filefuns.php"] [unique_id "aoSBQNO5rbWdOArH04KwegAAAUY"] [Tue Aug 18 12:58:56.621411 2026] [security2:error] [pid 66623:tid 66860] [client 20.127.136.245:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wk/index.php"] [unique_id "aoSBQNO5rbWdOArH04KwfgAAAWg"] [Tue Aug 18 12:58:56.630090 2026] [security2:error] [pid 66623:tid 66855] [client 20.104.85.180:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBQNO5rbWdOArH04KwfwAAAWM"] [Tue Aug 18 12:58:56.650197 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/de.php"] [unique_id "aoSBQNO5rbWdOArH04KwgAABG20"] [Tue Aug 18 12:58:56.683814 2026] [security2:error] [pid 66623:tid 66833] [client 20.25.139.174:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/666.php"] [unique_id "aoSBQNO5rbWdOArH04KwhAAAAU0"] [Tue Aug 18 12:58:56.741076 2026] [security2:error] [pid 66623:tid 66802] [client 52.173.121.69:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBQNO5rbWdOArH04KwhgAAAS4"] [Tue Aug 18 12:58:56.744821 2026] [security2:error] [pid 66623:tid 66790] [client 168.62.48.100:1102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBQNO5rbWdOArH04KwhwAAASI"] [Tue Aug 18 12:58:56.819594 2026] [security2:error] [pid 66623:tid 66810] [client 20.48.236.86:31056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/ws55.php"] [unique_id "aoSBQNO5rbWdOArH04KwiwAAATY"] [Tue Aug 18 12:58:56.835763 2026] [security2:error] [pid 66623:tid 66809] [client 85.154.68.202:18233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwjAAAATU"] [Tue Aug 18 12:58:56.835913 2026] [security2:error] [pid 66623:tid 66809] [client 85.154.68.202:18233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwjAAAATU"] [Tue Aug 18 12:58:56.856081 2026] [security2:error] [pid 66623:tid 66653] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/album.php"] [unique_id "aoSBQNO5rbWdOArH04KwjwABOhA"] [Tue Aug 18 12:58:56.863184 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:53674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBQNO5rbWdOArH04KwkAAAAUc"] [Tue Aug 18 12:58:56.888378 2026] [security2:error] [pid 66623:tid 66846] [client 172.182.200.96:14205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/index/function.php"] [unique_id "aoSBQNO5rbWdOArH04KwkwAAAVo"] [Tue Aug 18 12:58:56.942061 2026] [security2:error] [pid 66623:tid 66881] [client 20.127.136.245:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBQNO5rbWdOArH04KwlgAAAX0"] [Tue Aug 18 12:58:56.969343 2026] [security2:error] [pid 66623:tid 66892] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/f35.update.php"] [unique_id "aoSBQNO5rbWdOArH04KwmAAAAYg"] [Tue Aug 18 12:58:57.021330 2026] [security2:error] [pid 66623:tid 66784] [client 74.248.18.37:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBQdO5rbWdOArH04KwmQAAARw"] [Tue Aug 18 12:58:57.036351 2026] [security2:error] [pid 66623:tid 66794] [client 168.62.48.100:1091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBQdO5rbWdOArH04KwmwAAASY"] [Tue Aug 18 12:58:57.050995 2026] [security2:error] [pid 66623:tid 66798] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/coffee.php"] [unique_id "aoSBQdO5rbWdOArH04KwnAAAASo"] [Tue Aug 18 12:58:57.055744 2026] [security2:error] [pid 66623:tid 66839] [client 102.213.179.104:58109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwkgAAAVM"] [Tue Aug 18 12:58:57.055953 2026] [security2:error] [pid 66623:tid 66839] [client 102.213.179.104:58109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQNO5rbWdOArH04KwkgAAAVM"] [Tue Aug 18 12:58:57.058979 2026] [security2:error] [pid 66623:tid 66864] [client 20.25.139.174:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/a.php"] [unique_id "aoSBQdO5rbWdOArH04KwngAAAWw"] [Tue Aug 18 12:58:57.060958 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kv.php"] [unique_id "aoSBQdO5rbWdOArH04KwnwABe0Y"] [Tue Aug 18 12:58:57.071413 2026] [security2:error] [pid 66623:tid 66793] [client 20.118.172.148:53092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/aa.php"] [unique_id "aoSBQdO5rbWdOArH04KwogAAASU"] [Tue Aug 18 12:58:57.098568 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:25017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBQdO5rbWdOArH04KwowAAAUE"] [Tue Aug 18 12:58:57.112864 2026] [security2:error] [pid 66623:tid 66804] [client 40.74.65.169:20114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/155.php"] [unique_id "aoSBQdO5rbWdOArH04KwpQAAATA"] [Tue Aug 18 12:58:57.118826 2026] [security2:error] [pid 66623:tid 66867] [client 20.206.73.37:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/33.php"] [unique_id "aoSBQdO5rbWdOArH04KwpgAAAW8"] [Tue Aug 18 12:58:57.136374 2026] [security2:error] [pid 66623:tid 66876] [client 20.104.85.180:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/rip.php"] [unique_id "aoSBQdO5rbWdOArH04KwqAAAAXg"] [Tue Aug 18 12:58:57.192232 2026] [security2:error] [pid 66623:tid 66801] [client 20.118.133.132:14426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/mosty.php"] [unique_id "aoSBQdO5rbWdOArH04KwqgAAAS0"] [Tue Aug 18 12:58:57.204982 2026] [security2:error] [pid 66623:tid 66837] [client 20.250.13.23:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQdO5rbWdOArH04KwqwAAAVE"] [Tue Aug 18 12:58:57.230858 2026] [security2:error] [pid 66623:tid 66886] [client 172.202.39.151:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSBQdO5rbWdOArH04KwrgAAAYI"] [Tue Aug 18 12:58:57.253568 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:57.254031 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:57.256253 2026] [security2:error] [pid 66623:tid 66865] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/bdroot.php"] [unique_id "aoSBQdO5rbWdOArH04KwtAAAAW0"] [Tue Aug 18 12:58:57.273015 2026] [security2:error] [pid 66623:tid 66874] [client 4.232.151.198:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/h.php"] [unique_id "aoSBQdO5rbWdOArH04KwtQAAAXY"] [Tue Aug 18 12:58:57.294685 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:48299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBQdO5rbWdOArH04KwtwAAAVg"] [Tue Aug 18 12:58:57.330367 2026] [security2:error] [pid 66623:tid 66823] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBQdO5rbWdOArH04KwvAAAAUM"] [Tue Aug 18 12:58:57.345793 2026] [security2:error] [pid 66623:tid 66642] [remote 74.208.9.170:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.9.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSBQdO5rbWdOArH04KwvgABUgU"] [Tue Aug 18 12:58:57.369252 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/z.php"] [unique_id "aoSBQdO5rbWdOArH04KwwQABSCk"] [Tue Aug 18 12:58:57.399439 2026] [security2:error] [pid 66623:tid 66770] [client 172.182.200.96:14147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBQdO5rbWdOArH04KwxQAAAQ4"] [Tue Aug 18 12:58:57.406776 2026] [security2:error] [pid 66623:tid 66796] [client 20.203.138.185:18448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/bb.php"] [unique_id "aoSBQdO5rbWdOArH04KwxgAAASg"] [Tue Aug 18 12:58:57.425682 2026] [security2:error] [pid 66623:tid 66781] [client 20.206.73.37:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villasgarage.com.br"] [uri "/packed.php"] [unique_id "aoSBQdO5rbWdOArH04KwxwAAARk"] [Tue Aug 18 12:58:57.442553 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git/config"] [unique_id "aoSBQdO5rbWdOArH04KwywABNgE"] [Tue Aug 18 12:58:57.443351 2026] [security2:error] [pid 66623:tid 66754] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aws/config"] [unique_id "aoSBQdO5rbWdOArH04KwzAABNnU"] [Tue Aug 18 12:58:57.446949 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aws/credentials"] [unique_id "aoSBQdO5rbWdOArH04KwzgABhSw"] [Tue Aug 18 12:58:57.450267 2026] [security2:error] [pid 66623:tid 66687] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git/HEAD"] [unique_id "aoSBQdO5rbWdOArH04KwzwABhDI"] [Tue Aug 18 12:58:57.451774 2026] [security2:error] [pid 66623:tid 66677] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/rclone.conf"] [unique_id "aoSBQdO5rbWdOArH04Kw0AABOig"] [Tue Aug 18 12:58:57.489795 2026] [security2:error] [pid 66623:tid 66843] [client 213.35.127.232:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBQdO5rbWdOArH04Kw0wAAAVc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:57.534002 2026] [security2:error] [pid 66623:tid 66800] [client 168.62.48.100:1085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBQdO5rbWdOArH04Kw1gAAASw"] [Tue Aug 18 12:58:57.549207 2026] [security2:error] [pid 66623:tid 66698] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xg.php"] [unique_id "aoSBQdO5rbWdOArH04Kw1wABIT0"] [Tue Aug 18 12:58:57.554256 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBQdO5rbWdOArH04Kw2AAAAUI"] [Tue Aug 18 12:58:57.559167 2026] [security2:error] [pid 66623:tid 66646] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/z9x8c7v6b5-debug-trigger-acpecasebaterias.com.br"] [unique_id "aoSBQdO5rbWdOArH04Kw2gABOwk"] [Tue Aug 18 12:58:57.566689 2026] [authz_core:error] [pid 66623:tid 66658] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:57.566988 2026] [authz_core:error] [pid 66623:tid 66658] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:57.601824 2026] [security2:error] [pid 66623:tid 66794] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBQdO5rbWdOArH04Kw3gAAASY"] [Tue Aug 18 12:58:57.605917 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/chosen.php"] [unique_id "aoSBQdO5rbWdOArH04Kw3wAAARo"] [Tue Aug 18 12:58:57.636566 2026] [security2:error] [pid 66623:tid 66811] [client 4.232.94.69:16021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/aksinet.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4AAAATc"] [Tue Aug 18 12:58:57.643742 2026] [security2:error] [pid 66623:tid 66864] [client 20.127.136.245:18649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/xfun.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4QAAAWw"] [Tue Aug 18 12:58:57.654805 2026] [security2:error] [pid 66623:tid 66893] [client 20.104.85.180:52580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/gecko.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4gAAAYk"] [Tue Aug 18 12:58:57.678108 2026] [security2:error] [pid 66623:tid 66710] [remote 74.208.9.170:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.9.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSBQdO5rbWdOArH04Kw4wABdUk"], referer: https://themenstyle.com.br/wp-login.php [Tue Aug 18 12:58:57.684413 2026] [security2:error] [pid 66623:tid 66882] [client 20.250.13.23:45703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBQdO5rbWdOArH04Kw5QAAAX4"] [Tue Aug 18 12:58:57.708350 2026] [security2:error] [pid 66623:tid 66805] [client 68.221.73.131:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBQdO5rbWdOArH04Kw5gAAATE"] [Tue Aug 18 12:58:57.722422 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:29024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBQdO5rbWdOArH04Kw6QAAAW8"] [Tue Aug 18 12:58:57.749151 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/nd.php"] [unique_id "aoSBQdO5rbWdOArH04Kw8QABOFE"] [Tue Aug 18 12:58:57.809441 2026] [security2:error] [pid 66623:tid 66779] [client 40.74.65.169:20135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ops.php"] [unique_id "aoSBQdO5rbWdOArH04Kw-AAAARc"] [Tue Aug 18 12:58:57.838524 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-css.php"] [unique_id "aoSBQdO5rbWdOArH04Kw_wAAARA"] [Tue Aug 18 12:58:57.838554 2026] [security2:error] [pid 66623:tid 66852] [client 168.62.48.100:1138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBQdO5rbWdOArH04Kw_gAAAWA"] [Tue Aug 18 12:58:57.845511 2026] [security2:error] [pid 66623:tid 66869] [client 158.23.17.4:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nw.php"] [unique_id "aoSBQdO5rbWdOArH04KxAQAAAXE"] [Tue Aug 18 12:58:57.864620 2026] [security2:error] [pid 66623:tid 66851] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mgrr.php"] [unique_id "aoSBQdO5rbWdOArH04KxAgAAAV8"] [Tue Aug 18 12:58:57.907111 2026] [security2:error] [pid 66623:tid 66821] [client 4.232.151.198:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/link.php"] [unique_id "aoSBQdO5rbWdOArH04KxBgAAAUE"] [Tue Aug 18 12:58:57.907314 2026] [security2:error] [pid 66623:tid 66826] [client 172.182.200.96:14191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/Cachex.php"] [unique_id "aoSBQdO5rbWdOArH04KxBwAAAUY"] [Tue Aug 18 12:58:57.942132 2026] [security2:error] [pid 66623:tid 66866] [client 52.173.121.69:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBQdO5rbWdOArH04KxCQAAAW4"] [Tue Aug 18 12:58:57.948793 2026] [security2:error] [pid 66623:tid 66786] [client 20.250.13.23:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/function/function.php"] [unique_id "aoSBQdO5rbWdOArH04KxCwAAAR4"] [Tue Aug 18 12:58:57.958738 2026] [security2:error] [pid 66623:tid 66855] [client 132.196.30.78:14997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ws54.php"] [unique_id "aoSBQdO5rbWdOArH04KxEAAAAWM"] [Tue Aug 18 12:58:57.968127 2026] [security2:error] [pid 66623:tid 66708] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ri.php"] [unique_id "aoSBQdO5rbWdOArH04KxEQABWEc"] [Tue Aug 18 12:58:58.008074 2026] [security2:error] [pid 66623:tid 66792] [client 74.248.18.37:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSBQtO5rbWdOArH04KxEwAAASQ"] [Tue Aug 18 12:58:58.113987 2026] [security2:error] [pid 66623:tid 66872] [client 20.25.139.174:4523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxHQAAAXQ"] [Tue Aug 18 12:58:58.127601 2026] [security2:error] [pid 66623:tid 66781] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/flox.php"] [unique_id "aoSBQtO5rbWdOArH04KxHwAAARk"] [Tue Aug 18 12:58:58.140379 2026] [security2:error] [pid 66623:tid 66683] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tp.php"] [unique_id "aoSBQtO5rbWdOArH04KxIgABay4"] [Tue Aug 18 12:58:58.151360 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:58.151654 2026] [authz_core:error] [pid 66623:tid 66647] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:58.154468 2026] [security2:error] [pid 66623:tid 66778] [client 168.62.48.100:1087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBQtO5rbWdOArH04KxJAAAARY"] [Tue Aug 18 12:58:58.170898 2026] [security2:error] [pid 66623:tid 66712] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gitconfig"] [unique_id "aoSBQtO5rbWdOArH04KxJwABZUs"] [Tue Aug 18 12:58:58.175997 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.git-credentials"] [unique_id "aoSBQtO5rbWdOArH04KxKAABZSY"] [Tue Aug 18 12:58:58.256762 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSBQtO5rbWdOArH04KxLAABLHM"] [Tue Aug 18 12:58:58.268754 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "aoSBQtO5rbWdOArH04KxLwABLGo"] [Tue Aug 18 12:58:58.275831 2026] [security2:error] [pid 66623:tid 66856] [client 20.203.138.185:10414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ok.php"] [unique_id "aoSBQtO5rbWdOArH04KxMAAAAWQ"] [Tue Aug 18 12:58:58.276203 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env"] [unique_id "aoSBQtO5rbWdOArH04KxMQABLGw"] [Tue Aug 18 12:58:58.276550 2026] [security2:error] [pid 66623:tid 66850] [client 172.182.200.96:7646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBQtO5rbWdOArH04KxMgAAAV4"] [Tue Aug 18 12:58:58.298766 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:47332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBQtO5rbWdOArH04KxMwAAAYg"] [Tue Aug 18 12:58:58.301508 2026] [security2:error] [pid 66623:tid 66713] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.example"] [unique_id "aoSBQtO5rbWdOArH04KxNAABLEw"] [Tue Aug 18 12:58:58.308760 2026] [security2:error] [pid 66623:tid 66769] [client 20.104.85.180:22896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/aa.php"] [unique_id "aoSBQtO5rbWdOArH04KxNgAAAQ0"] [Tue Aug 18 12:58:58.338643 2026] [security2:error] [pid 66623:tid 66794] [client 20.127.136.245:18658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/p.php"] [unique_id "aoSBQtO5rbWdOArH04KxOgAAASY"] [Tue Aug 18 12:58:58.359900 2026] [security2:error] [pid 66623:tid 66816] [client 192.141.172.134:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxOwAAATw"] [Tue Aug 18 12:58:58.360012 2026] [security2:error] [pid 66623:tid 66816] [client 192.141.172.134:52560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxOwAAATw"] [Tue Aug 18 12:58:58.370008 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/zj.php"] [unique_id "aoSBQtO5rbWdOArH04KxPAABcCI"] [Tue Aug 18 12:58:58.387387 2026] [security2:error] [pid 66623:tid 66839] [client 20.118.172.148:63091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/abcd.php"] [unique_id "aoSBQtO5rbWdOArH04KxPQAAAVM"] [Tue Aug 18 12:58:58.389822 2026] [security2:error] [pid 66623:tid 66699] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.production"] [unique_id "aoSBQtO5rbWdOArH04KxPgABez4"] [Tue Aug 18 12:58:58.425358 2026] [security2:error] [pid 66623:tid 66873] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/op.php"] [unique_id "aoSBQtO5rbWdOArH04KxQwAAAXU"] [Tue Aug 18 12:58:58.455714 2026] [authz_core:error] [pid 66623:tid 66700] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:58.455971 2026] [authz_core:error] [pid 66623:tid 66700] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:58.494843 2026] [security2:error] [pid 66623:tid 66848] [client 20.104.85.180:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBQtO5rbWdOArH04KxRwAAAVw"] [Tue Aug 18 12:58:58.506487 2026] [security2:error] [pid 66623:tid 66888] [client 213.35.127.232:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBQtO5rbWdOArH04KxSgAAAYQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:58.511947 2026] [security2:error] [pid 66623:tid 66775] [client 40.74.65.169:20149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/mac.php"] [unique_id "aoSBQtO5rbWdOArH04KxSwAAARM"] [Tue Aug 18 12:58:58.512183 2026] [security2:error] [pid 66623:tid 66825] [client 20.250.13.23:17064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxTAAAAUU"] [Tue Aug 18 12:58:58.540342 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.local"] [unique_id "aoSBQtO5rbWdOArH04KxTQABd3k"] [Tue Aug 18 12:58:58.550039 2026] [security2:error] [pid 66623:tid 66801] [client 158.23.17.4:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sb.php"] [unique_id "aoSBQtO5rbWdOArH04KxTgAAAS0"] [Tue Aug 18 12:58:58.552773 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.30.78:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQtO5rbWdOArH04KxTwAAARw"] [Tue Aug 18 12:58:58.572480 2026] [security2:error] [pid 66623:tid 66721] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/x.php"] [unique_id "aoSBQtO5rbWdOArH04KxUgABfFQ"] [Tue Aug 18 12:58:58.589595 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.bak"] [unique_id "aoSBQtO5rbWdOArH04KxUwABURY"] [Tue Aug 18 12:58:58.605815 2026] [security2:error] [pid 66623:tid 66886] [client 172.182.200.96:14162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBQtO5rbWdOArH04KxVgAAAYI"] [Tue Aug 18 12:58:58.607169 2026] [security2:error] [pid 66623:tid 66736] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.old"] [unique_id "aoSBQtO5rbWdOArH04KxVwABJWM"] [Tue Aug 18 12:58:58.609445 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.backup"] [unique_id "aoSBQtO5rbWdOArH04KxWAABZws"] [Tue Aug 18 12:58:58.610387 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/55.php"] [unique_id "aoSBQtO5rbWdOArH04KxWQAAAYA"] [Tue Aug 18 12:58:58.626117 2026] [security2:error] [pid 66623:tid 66744] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/.env"] [unique_id "aoSBQtO5rbWdOArH04KxWwABhms"] [Tue Aug 18 12:58:58.629645 2026] [security2:error] [pid 66623:tid 66807] [client 168.62.48.100:1098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBQtO5rbWdOArH04KxXAAAATM"] [Tue Aug 18 12:58:58.630340 2026] [security2:error] [pid 66623:tid 66788] [client 20.65.98.162:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/admin.php"] [unique_id "aoSBQtO5rbWdOArH04KxXQAAASA"] [Tue Aug 18 12:58:58.631681 2026] [security2:error] [pid 66623:tid 66780] [client 20.25.139.174:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/vx.php"] [unique_id "aoSBQtO5rbWdOArH04KxXgAAARg"] [Tue Aug 18 12:58:58.663882 2026] [security2:error] [pid 66623:tid 66666] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/admin/.env"] [unique_id "aoSBQtO5rbWdOArH04KxYAABhh0"] [Tue Aug 18 12:58:58.683746 2026] [security2:error] [pid 66623:tid 66804] [client 20.48.236.86:2324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/m.php"] [unique_id "aoSBQtO5rbWdOArH04KxYQAAATA"] [Tue Aug 18 12:58:58.755396 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/backend/.env"] [unique_id "aoSBQtO5rbWdOArH04KxZgABSRA"] [Tue Aug 18 12:58:58.755873 2026] [security2:error] [pid 66623:tid 66823] [client 52.173.121.69:16504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBQtO5rbWdOArH04KxaAAAAUM"] [Tue Aug 18 12:58:58.783231 2026] [security2:error] [pid 66623:tid 66852] [client 74.248.18.37:7558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBQtO5rbWdOArH04KxagAAAWA"] [Tue Aug 18 12:58:58.799188 2026] [security2:error] [pid 66623:tid 66696] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yn.php"] [unique_id "aoSBQtO5rbWdOArH04KxawABWTs"] [Tue Aug 18 12:58:58.808124 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/.env"] [unique_id "aoSBQtO5rbWdOArH04KxbAABgw8"] [Tue Aug 18 12:58:58.821148 2026] [security2:error] [pid 66623:tid 66749] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/secrets.yml"] [unique_id "aoSBQtO5rbWdOArH04KxbgABaHA"] [Tue Aug 18 12:58:58.848787 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/secrets.json"] [unique_id "aoSBQtO5rbWdOArH04KxcAABDlw"] [Tue Aug 18 12:58:58.875144 2026] [security2:error] [pid 66623:tid 66813] [client 4.232.94.69:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/simple.php"] [unique_id "aoSBQtO5rbWdOArH04KxcgAAATk"] [Tue Aug 18 12:58:58.876578 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/service-account.json"] [unique_id "aoSBQtO5rbWdOArH04KxcwABMiQ"] [Tue Aug 18 12:58:58.884298 2026] [security2:error] [pid 66623:tid 66796] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ajax.php"] [unique_id "aoSBQtO5rbWdOArH04KxdAAAASg"] [Tue Aug 18 12:58:58.896082 2026] [security2:error] [pid 66623:tid 66707] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/credentials.json"] [unique_id "aoSBQtO5rbWdOArH04KxdQABa0Y"] [Tue Aug 18 12:58:58.901733 2026] [security2:error] [pid 66623:tid 66889] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBQtO5rbWdOArH04KxdwAAAYU"] [Tue Aug 18 12:58:58.914774 2026] [security2:error] [pid 66623:tid 66814] [client 20.203.138.185:63779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp9.php"] [unique_id "aoSBQtO5rbWdOArH04KxeAAAATo"] [Tue Aug 18 12:58:58.937970 2026] [security2:error] [pid 66623:tid 66878] [client 68.155.155.199:13536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBQtO5rbWdOArH04KxegAAAXo"] [Tue Aug 18 12:58:58.942321 2026] [security2:error] [pid 66623:tid 66857] [client 20.215.241.237:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/inso.php"] [unique_id "aoSBQtO5rbWdOArH04KxewAAAWU"] [Tue Aug 18 12:58:58.968578 2026] [security2:error] [pid 66623:tid 66877] [client 168.62.48.100:1107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBQtO5rbWdOArH04KxfQAAAXk"] [Tue Aug 18 12:58:58.969236 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.151.198:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/class-t.api.php"] [unique_id "aoSBQtO5rbWdOArH04KxfgAAAVc"] [Tue Aug 18 12:58:58.970660 2026] [security2:error] [pid 66623:tid 66803] [client 172.202.39.151:44547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/lock360.php"] [unique_id "aoSBQtO5rbWdOArH04KxfwAAAS8"] [Tue Aug 18 12:58:58.987226 2026] [security2:error] [pid 66623:tid 66725] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/key.json"] [unique_id "aoSBQtO5rbWdOArH04KxgAABIVg"] [Tue Aug 18 12:58:58.990379 2026] [security2:error] [pid 66623:tid 66657] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/11.php"] [unique_id "aoSBQtO5rbWdOArH04KxgQABQhQ"] [Tue Aug 18 12:58:59.033911 2026] [security2:error] [pid 66623:tid 66676] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSBQ9O5rbWdOArH04KxgwABIic"] [Tue Aug 18 12:58:59.034199 2026] [security2:error] [pid 66623:tid 66892] [client 172.182.200.96:14157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBQ9O5rbWdOArH04KxggAAAYg"] [Tue Aug 18 12:58:59.054651 2026] [security2:error] [pid 66623:tid 66644] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "aoSBQ9O5rbWdOArH04KxhgABSwc"] [Tue Aug 18 12:58:59.055374 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:59.055642 2026] [authz_core:error] [pid 66623:tid 66706] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:59.078598 2026] [security2:error] [pid 66623:tid 66800] [client 20.104.85.180:59540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/moon.php"] [unique_id "aoSBQ9O5rbWdOArH04KxiAAAASw"] [Tue Aug 18 12:58:59.101377 2026] [security2:error] [pid 66623:tid 66846] [client 20.250.13.23:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/nw.php"] [unique_id "aoSBQ9O5rbWdOArH04KxigAAAVo"] [Tue Aug 18 12:58:59.126032 2026] [security2:error] [pid 66623:tid 66809] [client 20.250.13.23:1835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBQ9O5rbWdOArH04KxiwAAATU"] [Tue Aug 18 12:58:59.132885 2026] [security2:error] [pid 66623:tid 66799] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/yj09.php"] [unique_id "aoSBQ9O5rbWdOArH04KxjAAAASs"] [Tue Aug 18 12:58:59.145445 2026] [security2:error] [pid 66623:tid 66827] [client 20.127.136.245:18624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxjgAAAUc"] [Tue Aug 18 12:58:59.155397 2026] [security2:error] [pid 66623:tid 66695] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/service_account.json"] [unique_id "aoSBQ9O5rbWdOArH04KxjwABMTo"] [Tue Aug 18 12:58:59.165936 2026] [security2:error] [pid 66623:tid 66751] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vm.php"] [unique_id "aoSBQ9O5rbWdOArH04KxkQABW3I"] [Tue Aug 18 12:58:59.174977 2026] [security2:error] [pid 66623:tid 66858] [client 20.48.236.86:31062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/33.php"] [unique_id "aoSBQ9O5rbWdOArH04KxkgAAAWY"] [Tue Aug 18 12:58:59.201564 2026] [security2:error] [pid 66623:tid 66801] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/txets.php"] [unique_id "aoSBQ9O5rbWdOArH04KxmAAAAS0"] [Tue Aug 18 12:58:59.206224 2026] [security2:error] [pid 66623:tid 66784] [client 168.62.48.100:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBQ9O5rbWdOArH04KxmQAAARw"] [Tue Aug 18 12:58:59.218539 2026] [security2:error] [pid 66623:tid 66678] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-service-account.json"] [unique_id "aoSBQ9O5rbWdOArH04KxmgABTCk"] [Tue Aug 18 12:58:59.235178 2026] [security2:error] [pid 66623:tid 66883] [client 132.196.30.78:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/function/function.php"] [unique_id "aoSBQ9O5rbWdOArH04KxnAAAAX8"] [Tue Aug 18 12:58:59.247689 2026] [security2:error] [pid 66623:tid 66880] [client 52.173.121.69:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBQ9O5rbWdOArH04KxnQAAAXw"] [Tue Aug 18 12:58:59.259445 2026] [security2:error] [pid 66623:tid 66772] [client 52.173.121.69:17965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBQ9O5rbWdOArH04KxngAAARA"] [Tue Aug 18 12:58:59.307180 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.github/.env"] [unique_id "aoSBQ9O5rbWdOArH04KxoAABgAE"] [Tue Aug 18 12:58:59.307504 2026] [security2:error] [pid 66623:tid 66724] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/Dockerfile"] [unique_id "aoSBQ9O5rbWdOArH04KxoQABgFc"] [Tue Aug 18 12:58:59.320360 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.docker/config.json"] [unique_id "aoSBQ9O5rbWdOArH04KxpAABMyw"] [Tue Aug 18 12:58:59.324318 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:2697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxpQAAASA"] [Tue Aug 18 12:58:59.339265 2026] [security2:error] [pid 66623:tid 66687] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.npmrc"] [unique_id "aoSBQ9O5rbWdOArH04KxpwABiTI"] [Tue Aug 18 12:58:59.348382 2026] [security2:error] [pid 66623:tid 66773] [client 20.25.139.174:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ws54.php"] [unique_id "aoSBQ9O5rbWdOArH04KxqAAAARE"] [Tue Aug 18 12:58:59.356763 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:58:59.357033 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:58:59.361217 2026] [security2:error] [pid 66623:tid 66804] [client 172.182.200.96:7502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBQ9O5rbWdOArH04KxqgAAATA"] [Tue Aug 18 12:58:59.388711 2026] [security2:error] [pid 66623:tid 66767] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/scxy.php"] [unique_id "aoSBQ9O5rbWdOArH04KxrAAAAQs"] [Tue Aug 18 12:58:59.395168 2026] [security2:error] [pid 66623:tid 66715] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.s3cfg"] [unique_id "aoSBQ9O5rbWdOArH04KxrQABJ04"] [Tue Aug 18 12:58:59.417114 2026] [security2:error] [pid 66623:tid 66732] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eg.php"] [unique_id "aoSBQ9O5rbWdOArH04KxrwABSV8"] [Tue Aug 18 12:58:59.443824 2026] [security2:error] [pid 66623:tid 66853] [client 74.248.18.37:7595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxsgAAAWE"] [Tue Aug 18 12:58:59.463097 2026] [security2:error] [pid 66623:tid 66682] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.boto"] [unique_id "aoSBQ9O5rbWdOArH04KxtAABJC0"] [Tue Aug 18 12:58:59.488108 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/img.php"] [unique_id "aoSBQ9O5rbWdOArH04KxtgAAATc"] [Tue Aug 18 12:58:59.520035 2026] [security2:error] [pid 66623:tid 66812] [client 213.35.127.232:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBQ9O5rbWdOArH04KxuQAAATg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:58:59.521759 2026] [security2:error] [pid 66623:tid 66887] [client 68.221.73.131:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBQ9O5rbWdOArH04KxugAAAYM"] [Tue Aug 18 12:58:59.543790 2026] [security2:error] [pid 66623:tid 66710] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.svn/entries"] [unique_id "aoSBQ9O5rbWdOArH04KxuwABNEk"] [Tue Aug 18 12:58:59.547466 2026] [security2:error] [pid 66623:tid 66740] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.htpasswd"] [unique_id "aoSBQ9O5rbWdOArH04KxvAABcmc"] [Tue Aug 18 12:58:59.564080 2026] [security2:error] [pid 66623:tid 66742] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/terraform.tfstate"] [unique_id "aoSBQ9O5rbWdOArH04KxvQABI2k"] [Tue Aug 18 12:58:59.569952 2026] [security2:error] [pid 66623:tid 66874] [client 20.127.136.245:17062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/aaa.php"] [unique_id "aoSBQ9O5rbWdOArH04KxvgAAAXY"] [Tue Aug 18 12:58:59.580315 2026] [security2:error] [pid 66623:tid 66872] [client 168.62.48.100:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBQ9O5rbWdOArH04KxwAAAAXQ"] [Tue Aug 18 12:58:59.582214 2026] [security2:error] [pid 66623:tid 66781] [client 68.155.155.199:12924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.155.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04KxwQAAARk"] [Tue Aug 18 12:58:59.614878 2026] [security2:error] [pid 66623:tid 66785] [client 4.232.151.198:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBQ9O5rbWdOArH04KxxQAAAR0"] [Tue Aug 18 12:58:59.619366 2026] [security2:error] [pid 66623:tid 66718] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/uk.php"] [unique_id "aoSBQ9O5rbWdOArH04KxxgABhVE"] [Tue Aug 18 12:58:59.630204 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSBQ9O5rbWdOArH04KxyAABekg"] [Tue Aug 18 12:58:59.645247 2026] [security2:error] [pid 66623:tid 66877] [client 20.203.138.185:27995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws59.php"] [unique_id "aoSBQ9O5rbWdOArH04KxyQAAAXk"] [Tue Aug 18 12:58:59.651075 2026] [security2:error] [pid 66623:tid 66843] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ws13.php"] [unique_id "aoSBQ9O5rbWdOArH04KxywAAAVc"] [Tue Aug 18 12:58:59.669691 2026] [security2:error] [pid 66623:tid 66755] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.vscode/launch.json"] [unique_id "aoSBQ9O5rbWdOArH04KxzQABKXY"] [Tue Aug 18 12:58:59.736541 2026] [security2:error] [pid 66623:tid 66790] [client 20.104.85.180:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/0x.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0QAAASI"] [Tue Aug 18 12:58:59.738264 2026] [security2:error] [pid 66623:tid 66892] [client 52.173.121.69:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0gAAAYg"] [Tue Aug 18 12:58:59.746278 2026] [security2:error] [pid 66623:tid 66813] [client 20.25.139.174:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wap.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx0wAAATk"] [Tue Aug 18 12:58:59.764034 2026] [security2:error] [pid 66623:tid 66865] [client 172.182.200.96:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx1QAAAW0"] [Tue Aug 18 12:58:59.768863 2026] [security2:error] [pid 66623:tid 66747] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx1gABS24"] [Tue Aug 18 12:58:59.788249 2026] [security2:error] [pid 66623:tid 66800] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx2AAAASw"] [Tue Aug 18 12:58:59.801227 2026] [security2:error] [pid 66623:tid 66690] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx2QABUzU"] [Tue Aug 18 12:58:59.805635 2026] [security2:error] [pid 66623:tid 66863] [client 79.127.164.8:58286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/spider/uninstallmysql.sql"] [unique_id "aoSBQ9O5rbWdOArH04Kx2gAAAWs"], referer: https://medihub.com.br/spider/uninstallmysql.sql [Tue Aug 18 12:58:59.808236 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/creds.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx2wABbFI"] [Tue Aug 18 12:58:59.820793 2026] [security2:error] [pid 66623:tid 66810] [client 132.196.30.78:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/nw.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx3QAAATY"] [Tue Aug 18 12:58:59.826314 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoSBQ9O5rbWdOArH04Kx3gABe1M"] [Tue Aug 18 12:58:59.850196 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBQ9O5rbWdOArH04Kx3wABdSs"] [Tue Aug 18 12:58:59.906191 2026] [security2:error] [pid 66623:tid 66655] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/authorized_keys"] [unique_id "aoSBQ9O5rbWdOArH04Kx4gABbxI"] [Tue Aug 18 12:58:59.906904 2026] [security2:error] [pid 66623:tid 66856] [client 20.250.13.23:17075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx4wAAAWQ"] [Tue Aug 18 12:58:59.913111 2026] [security2:error] [pid 66623:tid 66847] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/btx25.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx5AAAAVs"] [Tue Aug 18 12:58:59.926706 2026] [security2:error] [pid 66623:tid 66828] [client 20.25.139.174:4686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBQ9O5rbWdOArH04Kx5QAAAUg"] [Tue Aug 18 12:58:59.967245 2026] [security2:error] [pid 66623:tid 66684] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/config"] [unique_id "aoSBQ9O5rbWdOArH04Kx5wABLS8"] [Tue Aug 18 12:59:00.027967 2026] [security2:error] [pid 66623:tid 66775] [client 168.62.48.100:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBRNO5rbWdOArH04Kx6AAAARM"] [Tue Aug 18 12:59:00.056972 2026] [security2:error] [pid 66623:tid 66772] [client 114.119.141.40:41249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sindifisconacional-pel.org.br"] [uri "/curtir_noticia_todas.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7QAAARA"], referer: http://www.sindifisconacional-pel.org.br/todasnoticias.php?pg=2 [Tue Aug 18 12:59:00.066337 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7gAAAYI"] [Tue Aug 18 12:59:00.067960 2026] [security2:error] [pid 66623:tid 66753] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ho.php"] [unique_id "aoSBRNO5rbWdOArH04Kx7wABZ3Q"] [Tue Aug 18 12:59:00.074019 2026] [security2:error] [pid 66623:tid 66807] [client 158.23.17.4:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xj.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8AAAATM"] [Tue Aug 18 12:59:00.093170 2026] [security2:error] [pid 66623:tid 66805] [client 74.248.18.37:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8QAAATE"] [Tue Aug 18 12:59:00.115842 2026] [security2:error] [pid 66623:tid 66893] [client 172.182.200.96:7576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBRNO5rbWdOArH04Kx8wAAAYk"] [Tue Aug 18 12:59:00.168163 2026] [security2:error] [pid 66623:tid 66773] [client 20.127.136.245:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/term.php"] [unique_id "aoSBRNO5rbWdOArH04Kx9QAAARE"] [Tue Aug 18 12:59:00.225545 2026] [security2:error] [pid 66623:tid 66784] [client 20.250.13.23:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/xleet.php"] [unique_id "aoSBRNO5rbWdOArH04Kx9wAAARw"] [Tue Aug 18 12:59:00.232653 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:50099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBRNO5rbWdOArH04Kx-AAAAVA"] [Tue Aug 18 12:59:00.239783 2026] [security2:error] [pid 66623:tid 66658] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_rsa"] [unique_id "aoSBRNO5rbWdOArH04Kx-gABWBU"] [Tue Aug 18 12:59:00.248993 2026] [security2:error] [pid 66623:tid 66840] [client 20.65.98.162:17815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/biufile.php"] [unique_id "aoSBRNO5rbWdOArH04Kx-wAAAVQ"] [Tue Aug 18 12:59:00.257100 2026] [security2:error] [pid 66623:tid 66651] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_dsa"] [unique_id "aoSBRNO5rbWdOArH04Kx_gABYQ4"] [Tue Aug 18 12:59:00.261266 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_ed25519"] [unique_id "aoSBRNO5rbWdOArH04Kx_wABJEo"] [Tue Aug 18 12:59:00.267978 2026] [security2:error] [pid 66623:tid 66849] [client 4.232.151.198:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/vx.php"] [unique_id "aoSBRNO5rbWdOArH04KyAAAAAV0"] [Tue Aug 18 12:59:00.271923 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/cache.php"] [unique_id "aoSBRNO5rbWdOArH04KyAQAAATc"] [Tue Aug 18 12:59:00.290387 2026] [security2:error] [pid 66623:tid 66788] [client 20.25.139.174:4570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBRNO5rbWdOArH04KyAgAAASA"] [Tue Aug 18 12:59:00.306332 2026] [security2:error] [pid 66623:tid 66683] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/97.php"] [unique_id "aoSBRNO5rbWdOArH04KyBAABOC4"] [Tue Aug 18 12:59:00.312555 2026] [security2:error] [pid 66623:tid 66688] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/id_ecdsa"] [unique_id "aoSBRNO5rbWdOArH04KyBQABLjM"] [Tue Aug 18 12:59:00.342818 2026] [security2:error] [pid 66623:tid 66712] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/server.key"] [unique_id "aoSBRNO5rbWdOArH04KyBwABQ0s"] [Tue Aug 18 12:59:00.348957 2026] [security2:error] [pid 66623:tid 66890] [client 132.196.30.78:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/xleet.php"] [unique_id "aoSBRNO5rbWdOArH04KyCAAAAYY"] [Tue Aug 18 12:59:00.351252 2026] [security2:error] [pid 66623:tid 66870] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBRNO5rbWdOArH04KyCQAAAXI"] [Tue Aug 18 12:59:00.351602 2026] [security2:error] [pid 66623:tid 66692] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.ssh/known_hosts"] [unique_id "aoSBRNO5rbWdOArH04KyCwABdDc"] [Tue Aug 18 12:59:00.355835 2026] [security2:error] [pid 66623:tid 66781] [client 168.62.48.100:1070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBRNO5rbWdOArH04KyDAAAARk"] [Tue Aug 18 12:59:00.378613 2026] [security2:error] [pid 66623:tid 66780] [client 4.232.94.69:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/berax.php"] [unique_id "aoSBRNO5rbWdOArH04KyDQAAARg"] [Tue Aug 18 12:59:00.402628 2026] [security2:error] [pid 66623:tid 66889] [client 20.203.138.185:10401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSBRNO5rbWdOArH04KyDgAAAYU"] [Tue Aug 18 12:59:00.444634 2026] [security2:error] [pid 66623:tid 66852] [client 20.25.139.174:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/function/function.php"] [unique_id "aoSBRNO5rbWdOArH04KyEwAAAWA"] [Tue Aug 18 12:59:00.478177 2026] [security2:error] [pid 66623:tid 66892] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBRNO5rbWdOArH04KyFQAAAYg"] [Tue Aug 18 12:59:00.504253 2026] [security2:error] [pid 66623:tid 66745] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rh.php"] [unique_id "aoSBRNO5rbWdOArH04KyFwABa2w"] [Tue Aug 18 12:59:00.535900 2026] [security2:error] [pid 66623:tid 66727] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/key.pem"] [unique_id "aoSBRNO5rbWdOArH04KyGgABJlo"] [Tue Aug 18 12:59:00.539998 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/private-key"] [unique_id "aoSBRNO5rbWdOArH04KyHAABWjA"] [Tue Aug 18 12:59:00.540144 2026] [security2:error] [pid 66623:tid 66786] [client 213.35.127.232:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBRNO5rbWdOArH04KyHQAAAR4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:00.556791 2026] [security2:error] [pid 66623:tid 66862] [client 196.12.128.158:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBRNO5rbWdOArH04KyIAAAAWo"] [Tue Aug 18 12:59:00.556946 2026] [security2:error] [pid 66623:tid 66862] [client 196.12.128.158:60750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBRNO5rbWdOArH04KyIAAAAWo"] [Tue Aug 18 12:59:00.559253 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:00.559554 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:00.576505 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/privatekey.key"] [unique_id "aoSBRNO5rbWdOArH04KyJQABTmI"] [Tue Aug 18 12:59:00.577122 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/localhost.key"] [unique_id "aoSBRNO5rbWdOArH04KyJgABfhs"] [Tue Aug 18 12:59:00.598279 2026] [security2:error] [pid 66623:tid 66654] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/ssl/server.key"] [unique_id "aoSBRNO5rbWdOArH04KyKAABbxE"] [Tue Aug 18 12:59:00.604183 2026] [security2:error] [pid 66623:tid 66856] [client 52.173.121.69:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBRNO5rbWdOArH04KyKgAAAWQ"] [Tue Aug 18 12:59:00.612458 2026] [security2:error] [pid 66623:tid 66738] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/host.key"] [unique_id "aoSBRNO5rbWdOArH04KyLAABW2U"] [Tue Aug 18 12:59:00.621229 2026] [security2:error] [pid 66623:tid 66835] [client 172.182.200.96:7630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBRNO5rbWdOArH04KyLgAAAU8"] [Tue Aug 18 12:59:00.627256 2026] [security2:error] [pid 66623:tid 66888] [client 20.127.136.245:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/7.php"] [unique_id "aoSBRNO5rbWdOArH04KyLwAAAYQ"] [Tue Aug 18 12:59:00.644919 2026] [security2:error] [pid 66623:tid 66857] [client 213.202.253.4:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/userfuns.php"] [unique_id "aoSBRNO5rbWdOArH04KyMAAAAWU"], referer: www.google.com [Tue Aug 18 12:59:00.651677 2026] [security2:error] [pid 66623:tid 66825] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBRNO5rbWdOArH04KyMQAAAUU"] [Tue Aug 18 12:59:00.662976 2026] [security2:error] [pid 66623:tid 66885] [client 168.62.48.100:1093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBRNO5rbWdOArH04KyMgAAAYE"] [Tue Aug 18 12:59:00.742356 2026] [security2:error] [pid 66623:tid 66850] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBRNO5rbWdOArH04KyNgAAAV4"] [Tue Aug 18 12:59:00.747628 2026] [security2:error] [pid 66623:tid 66866] [client 20.104.85.180:18749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/zxz.php"] [unique_id "aoSBRNO5rbWdOArH04KyNwAAAW4"] [Tue Aug 18 12:59:00.750934 2026] [security2:error] [pid 66623:tid 66659] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/yg.php"] [unique_id "aoSBRNO5rbWdOArH04KyOAABfBY"] [Tue Aug 18 12:59:00.757867 2026] [security2:error] [pid 66623:tid 66768] [client 68.221.73.131:25278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/xx.php"] [unique_id "aoSBRNO5rbWdOArH04KyOQAAAQw"] [Tue Aug 18 12:59:00.821169 2026] [security2:error] [pid 66623:tid 66827] [client 20.25.139.174:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bgymj.php"] [unique_id "aoSBRNO5rbWdOArH04KyQAAAAUc"] [Tue Aug 18 12:59:00.861960 2026] [security2:error] [pid 66623:tid 66773] [client 52.173.121.69:17983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBRNO5rbWdOArH04KyQwAAARE"] [Tue Aug 18 12:59:00.862115 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:00.862376 2026] [authz_core:error] [pid 66623:tid 66666] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:00.912686 2026] [security2:error] [pid 66623:tid 66875] [client 4.232.151.198:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/mjq.php"] [unique_id "aoSBRNO5rbWdOArH04KyRwAAAXc"] [Tue Aug 18 12:59:00.926703 2026] [security2:error] [pid 66623:tid 66792] [client 168.62.48.100:1060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBRNO5rbWdOArH04KySAAAASQ"] [Tue Aug 18 12:59:00.928875 2026] [security2:error] [pid 66623:tid 66849] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/term.php"] [unique_id "aoSBRNO5rbWdOArH04KySQAAAV0"] [Tue Aug 18 12:59:00.933495 2026] [security2:error] [pid 66623:tid 66811] [client 20.250.13.23:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBRNO5rbWdOArH04KySgAAATc"] [Tue Aug 18 12:59:00.957206 2026] [security2:error] [pid 66623:tid 66693] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/et.php"] [unique_id "aoSBRNO5rbWdOArH04KyTQABgzg"] [Tue Aug 18 12:59:00.982885 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/ssl/localhost.key"] [unique_id "aoSBRNO5rbWdOArH04KyTwABhhA"] [Tue Aug 18 12:59:00.991163 2026] [security2:error] [pid 66623:tid 66870] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBRNO5rbWdOArH04KyUAAAAXI"] [Tue Aug 18 12:59:00.994004 2026] [security2:error] [pid 66623:tid 66872] [client 74.248.18.37:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSBRNO5rbWdOArH04KyUQAAAXQ"] [Tue Aug 18 12:59:01.003353 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoSBRdO5rbWdOArH04KyUgABGSU"] [Tue Aug 18 12:59:01.003678 2026] [security2:error] [pid 66623:tid 66804] [client 157.51.166.53:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyUwAAATA"] [Tue Aug 18 12:59:01.003781 2026] [security2:error] [pid 66623:tid 66804] [client 157.51.166.53:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyUwAAATA"] [Tue Aug 18 12:59:01.015323 2026] [security2:error] [pid 66623:tid 66893] [client 20.25.139.174:4636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/nw.php"] [unique_id "aoSBRdO5rbWdOArH04KyVAAAAYk"] [Tue Aug 18 12:59:01.083784 2026] [security2:error] [pid 66623:tid 66775] [client 132.196.30.78:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp.php"] [unique_id "aoSBRdO5rbWdOArH04KyVgAAARM"] [Tue Aug 18 12:59:01.103895 2026] [security2:error] [pid 66623:tid 66762] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.aider.conf.yml"] [unique_id "aoSBRdO5rbWdOArH04KyWQABeX0"] [Tue Aug 18 12:59:01.119611 2026] [security2:error] [pid 66623:tid 66696] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.cursor/mcp.json"] [unique_id "aoSBRdO5rbWdOArH04KyWwABTTs"] [Tue Aug 18 12:59:01.120175 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBRdO5rbWdOArH04KyXAABKQ8"] [Tue Aug 18 12:59:01.149915 2026] [security2:error] [pid 66623:tid 66822] [client 20.118.172.148:33489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/akc.php"] [unique_id "aoSBRdO5rbWdOArH04KyXgAAAUI"] [Tue Aug 18 12:59:01.161938 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:01.162196 2026] [authz_core:error] [pid 66623:tid 66749] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:01.169900 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.continue/config.json"] [unique_id "aoSBRdO5rbWdOArH04KyYAABQVw"] [Tue Aug 18 12:59:01.184813 2026] [security2:error] [pid 66623:tid 66673] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/of.php"] [unique_id "aoSBRdO5rbWdOArH04KyYQABiCQ"] [Tue Aug 18 12:59:01.203103 2026] [security2:error] [pid 66623:tid 66816] [client 168.62.48.100:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBRdO5rbWdOArH04KyYgAAATw"] [Tue Aug 18 12:59:01.208593 2026] [security2:error] [pid 66623:tid 66839] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/black.php"] [unique_id "aoSBRdO5rbWdOArH04KyYwAAAVM"] [Tue Aug 18 12:59:01.225487 2026] [security2:error] [pid 66623:tid 66794] [client 40.74.65.169:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBRdO5rbWdOArH04KyZQAAASY"] [Tue Aug 18 12:59:01.234754 2026] [security2:error] [pid 66623:tid 66846] [client 20.203.138.185:18480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSBRdO5rbWdOArH04KyZwAAAVo"] [Tue Aug 18 12:59:01.235926 2026] [security2:error] [pid 66623:tid 66786] [client 52.173.121.69:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBRdO5rbWdOArH04KyaQAAAR4"] [Tue Aug 18 12:59:01.238531 2026] [security2:error] [pid 66623:tid 66864] [client 197.184.64.235:41947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyawAAAWw"] [Tue Aug 18 12:59:01.238953 2026] [security2:error] [pid 66623:tid 66862] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/sky.php"] [unique_id "aoSBRdO5rbWdOArH04KyagAAAWo"] [Tue Aug 18 12:59:01.239096 2026] [security2:error] [pid 66623:tid 66868] [client 20.250.13.23:48479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp.php"] [unique_id "aoSBRdO5rbWdOArH04KybAAAAXA"] [Tue Aug 18 12:59:01.243377 2026] [security2:error] [pid 66623:tid 66864] [client 197.184.64.235:41947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRdO5rbWdOArH04KyawAAAWw"] [Tue Aug 18 12:59:01.301002 2026] [security2:error] [pid 66623:tid 66771] [client 158.23.17.4:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ns.php"] [unique_id "aoSBRdO5rbWdOArH04KycwAAAQ8"] [Tue Aug 18 12:59:01.328318 2026] [security2:error] [pid 66623:tid 66824] [client 20.104.85.180:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/www.php"] [unique_id "aoSBRdO5rbWdOArH04KydQAAAUQ"] [Tue Aug 18 12:59:01.350481 2026] [security2:error] [pid 66623:tid 66790] [client 20.25.139.174:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/aa.php"] [unique_id "aoSBRdO5rbWdOArH04KydwAAASI"] [Tue Aug 18 12:59:01.388868 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBRdO5rbWdOArH04KyeQAAAS0"] [Tue Aug 18 12:59:01.431983 2026] [security2:error] [pid 66623:tid 66662] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bu.php"] [unique_id "aoSBRdO5rbWdOArH04KyfwABPhk"] [Tue Aug 18 12:59:01.457746 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.codex/config.toml"] [unique_id "aoSBRdO5rbWdOArH04KygQABUXc"] [Tue Aug 18 12:59:01.460882 2026] [security2:error] [pid 66623:tid 66678] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBRdO5rbWdOArH04KyggABcyk"] [Tue Aug 18 12:59:01.474274 2026] [security2:error] [pid 66623:tid 66865] [client 4.232.94.69:45406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fi2.php"] [unique_id "aoSBRdO5rbWdOArH04KygwAAAW0"] [Tue Aug 18 12:59:01.518844 2026] [security2:error] [pid 66623:tid 66805] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file5.php"] [unique_id "aoSBRdO5rbWdOArH04KyhAAAATE"] [Tue Aug 18 12:59:01.522475 2026] [security2:error] [pid 66623:tid 66854] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/as.php"] [unique_id "aoSBRdO5rbWdOArH04KyhQAAAWI"] [Tue Aug 18 12:59:01.530838 2026] [security2:error] [pid 66623:tid 66885] [client 20.25.139.174:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/xleet.php"] [unique_id "aoSBRdO5rbWdOArH04KyhgAAAYE"] [Tue Aug 18 12:59:01.531005 2026] [security2:error] [pid 66623:tid 66803] [client 168.62.48.100:1129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBRdO5rbWdOArH04KyhwAAAS8"] [Tue Aug 18 12:59:01.531033 2026] [security2:error] [pid 66623:tid 66704] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/config.yaml"] [unique_id "aoSBRdO5rbWdOArH04KyiAABJ0M"] [Tue Aug 18 12:59:01.531905 2026] [security2:error] [pid 66623:tid 66827] [client 52.173.121.69:17921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBRdO5rbWdOArH04KyiQAAAUc"] [Tue Aug 18 12:59:01.549805 2026] [security2:error] [pid 66623:tid 66773] [client 20.104.85.180:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyiwAAARE"] [Tue Aug 18 12:59:01.552320 2026] [security2:error] [pid 66623:tid 66817] [client 213.35.127.232:57520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBRdO5rbWdOArH04KyjAAAAT0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:01.552632 2026] [security2:error] [pid 66623:tid 66642] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "aoSBRdO5rbWdOArH04KyjQABGwU"] [Tue Aug 18 12:59:01.560590 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.hermes/auth.json"] [unique_id "aoSBRdO5rbWdOArH04KyjgABaR4"] [Tue Aug 18 12:59:01.567930 2026] [security2:error] [pid 66623:tid 66888] [client 4.232.151.198:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-includes/PHPMailer/about.php"] [unique_id "aoSBRdO5rbWdOArH04KykAAAAYQ"] [Tue Aug 18 12:59:01.583472 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:12167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/rezor.php"] [unique_id "aoSBRdO5rbWdOArH04KykQAAAVg"] [Tue Aug 18 12:59:01.601556 2026] [security2:error] [pid 66623:tid 66700] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.claude.json"] [unique_id "aoSBRdO5rbWdOArH04KykgABJD8"] [Tue Aug 18 12:59:01.673337 2026] [security2:error] [pid 66623:tid 66872] [client 20.127.136.245:14789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file5.php"] [unique_id "aoSBRdO5rbWdOArH04KyngAAAXQ"] [Tue Aug 18 12:59:01.677335 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:01.677583 2026] [authz_core:error] [pid 66623:tid 66754] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:01.729401 2026] [security2:error] [pid 66623:tid 66889] [client 20.118.172.148:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/buy.php"] [unique_id "aoSBRdO5rbWdOArH04KyoAAAAYU"] [Tue Aug 18 12:59:01.738037 2026] [security2:error] [pid 66623:tid 66764] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.mcp.json"] [unique_id "aoSBRdO5rbWdOArH04KyoQABV38"] [Tue Aug 18 12:59:01.756848 2026] [security2:error] [pid 66623:tid 66858] [client 132.196.30.78:15648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/155.php"] [unique_id "aoSBRdO5rbWdOArH04KyogAAAWY"] [Tue Aug 18 12:59:01.756971 2026] [security2:error] [pid 66623:tid 66833] [client 20.250.13.23:53633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyowAAAU0"] [Tue Aug 18 12:59:01.757393 2026] [security2:error] [pid 66623:tid 66731] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.claude/settings.json"] [unique_id "aoSBRdO5rbWdOArH04KypAABKV4"] [Tue Aug 18 12:59:01.775287 2026] [security2:error] [pid 66623:tid 66710] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rn.php"] [unique_id "aoSBRdO5rbWdOArH04KypgABIUk"] [Tue Aug 18 12:59:01.783124 2026] [security2:error] [pid 66623:tid 66822] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/xyn.php"] [unique_id "aoSBRdO5rbWdOArH04KypwAAAUI"] [Tue Aug 18 12:59:01.794998 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBRdO5rbWdOArH04KyqAAAAUE"] [Tue Aug 18 12:59:01.807273 2026] [security2:error] [pid 66623:tid 66777] [client 172.202.39.151:44599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/flower.php"] [unique_id "aoSBRdO5rbWdOArH04KyqwAAARU"] [Tue Aug 18 12:59:01.807417 2026] [security2:error] [pid 66623:tid 66816] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/pucci.php"] [unique_id "aoSBRdO5rbWdOArH04KyrAAAATw"] [Tue Aug 18 12:59:01.815166 2026] [security2:error] [pid 66623:tid 66798] [client 74.248.18.37:19295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBRdO5rbWdOArH04KyrQAAASo"] [Tue Aug 18 12:59:01.830669 2026] [security2:error] [pid 66623:tid 66748] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.bashrc"] [unique_id "aoSBRdO5rbWdOArH04KyrwABU28"] [Tue Aug 18 12:59:01.834692 2026] [security2:error] [pid 66623:tid 66718] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.bash_profile"] [unique_id "aoSBRdO5rbWdOArH04KysAABJlE"] [Tue Aug 18 12:59:01.837069 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.zshrc"] [unique_id "aoSBRdO5rbWdOArH04KysQABWkg"] [Tue Aug 18 12:59:01.879062 2026] [security2:error] [pid 66623:tid 66820] [client 20.25.139.174:4652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBRdO5rbWdOArH04KyswAAAUA"] [Tue Aug 18 12:59:01.906255 2026] [security2:error] [pid 66623:tid 66755] [remote 185.227.135.83:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.135.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSBRdO5rbWdOArH04KytQABW3Y"] [Tue Aug 18 12:59:01.909047 2026] [authz_core:error] [pid 66623:tid 66769] [client 192.178.4.133:60828] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:01.909311 2026] [authz_core:error] [pid 66623:tid 66769] [client 192.178.4.133:60828] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:01.914516 2026] [security2:error] [pid 66623:tid 66698] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.profile"] [unique_id "aoSBRdO5rbWdOArH04KytwABbD0"] [Tue Aug 18 12:59:01.932882 2026] [security2:error] [pid 66623:tid 66882] [client 40.74.65.169:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBRdO5rbWdOArH04KyuAAAAX4"] [Tue Aug 18 12:59:01.991221 2026] [security2:error] [pid 66623:tid 66809] [client 20.48.236.86:2814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cabeceiragrandemg.com.br"] [uri "/packed.php"] [unique_id "aoSBRdO5rbWdOArH04KyvQAAATU"] [Tue Aug 18 12:59:02.000395 2026] [security2:error] [pid 66623:tid 66857] [client 52.173.121.69:49012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBRdO5rbWdOArH04KywAAAAWU"] [Tue Aug 18 12:59:02.003215 2026] [security2:error] [pid 66623:tid 66719] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ut.php"] [unique_id "aoSBRtO5rbWdOArH04KywQABRVI"] [Tue Aug 18 12:59:02.052053 2026] [security2:error] [pid 66623:tid 66869] [client 20.65.98.162:21357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/coffexium.php"] [unique_id "aoSBRtO5rbWdOArH04KywwAAAXE"] [Tue Aug 18 12:59:02.056009 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:16464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBRtO5rbWdOArH04KyxAAAAV4"] [Tue Aug 18 12:59:02.086507 2026] [security2:error] [pid 66623:tid 66768] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wicked.php"] [unique_id "aoSBRtO5rbWdOArH04KyxgAAAQw"] [Tue Aug 18 12:59:02.113347 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acpecasebaterias.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBRtO5rbWdOArH04KyyQABUVM"] [Tue Aug 18 12:59:02.116498 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acpecasebaterias.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSBRtO5rbWdOArH04KyygABcys"] [Tue Aug 18 12:59:02.119855 2026] [security2:error] [pid 66623:tid 66812] [client 20.25.139.174:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp.php"] [unique_id "aoSBRtO5rbWdOArH04KyywAAATg"] [Tue Aug 18 12:59:02.132662 2026] [security2:error] [pid 66623:tid 66865] [client 168.62.48.100:1056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBRtO5rbWdOArH04KyzQAAAW0"] [Tue Aug 18 12:59:02.180840 2026] [security2:error] [pid 66623:tid 66702] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky0AABMUE"] [Tue Aug 18 12:59:02.191004 2026] [security2:error] [pid 66623:tid 66824] [client 4.232.151.198:5500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/twentytwelve/inc/.php"] [unique_id "aoSBRtO5rbWdOArH04Ky0gAAAUQ"] [Tue Aug 18 12:59:02.201264 2026] [security2:error] [pid 66623:tid 66826] [client 20.203.138.185:17809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/vx.php"] [unique_id "aoSBRtO5rbWdOArH04Ky0wAAAUY"] [Tue Aug 18 12:59:02.216187 2026] [security2:error] [pid 66623:tid 66655] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/eh.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1AABLxI"] [Tue Aug 18 12:59:02.223758 2026] [security2:error] [pid 66623:tid 66795] [client 20.104.85.180:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wicked.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1QAAASc"] [Tue Aug 18 12:59:02.250343 2026] [security2:error] [pid 66623:tid 66817] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBRtO5rbWdOArH04Ky1gAAAT0"] [Tue Aug 18 12:59:02.295276 2026] [security2:error] [pid 66623:tid 66722] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/.env.php"] [unique_id "aoSBRtO5rbWdOArH04Ky2QABd1U"] [Tue Aug 18 12:59:02.341534 2026] [security2:error] [pid 66623:tid 66649] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "aoSBRtO5rbWdOArH04Ky2gABJAw"] [Tue Aug 18 12:59:02.341535 2026] [security2:error] [pid 66623:tid 66656] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/laravel/.env"] [unique_id "aoSBRtO5rbWdOArH04Ky2wABJBM"] [Tue Aug 18 12:59:02.412620 2026] [security2:error] [pid 66623:tid 66679] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ad.php"] [unique_id "aoSBRtO5rbWdOArH04Ky3wABIyo"] [Tue Aug 18 12:59:02.431148 2026] [security2:error] [pid 66623:tid 66827] [client 20.250.13.23:17053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBRtO5rbWdOArH04Ky4QAAAUc"] [Tue Aug 18 12:59:02.438977 2026] [security2:error] [pid 66623:tid 66888] [client 20.25.139.174:4618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bolt.php"] [unique_id "aoSBRtO5rbWdOArH04Ky4gAAAYQ"] [Tue Aug 18 12:59:02.448655 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:14850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5AAAAXQ"] [Tue Aug 18 12:59:02.466943 2026] [security2:error] [pid 66623:tid 66783] [client 74.248.18.37:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5gAAARs"] [Tue Aug 18 12:59:02.476228 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:50089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/cong.php"] [unique_id "aoSBRtO5rbWdOArH04Ky5wAAASg"] [Tue Aug 18 12:59:02.494470 2026] [security2:error] [pid 66623:tid 66893] [client 168.62.48.100:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6AAAAYk"] [Tue Aug 18 12:59:02.508400 2026] [security2:error] [pid 66623:tid 66784] [client 132.196.30.78:25104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/96i.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6QAAARw"] [Tue Aug 18 12:59:02.531063 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/inso.php"] [unique_id "aoSBRtO5rbWdOArH04Ky6gAAAR0"] [Tue Aug 18 12:59:02.576788 2026] [authz_core:error] [pid 66623:tid 66650] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:02.577054 2026] [authz_core:error] [pid 66623:tid 66650] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:02.584984 2026] [security2:error] [pid 66623:tid 66838] [client 213.35.127.232:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBRtO5rbWdOArH04Ky7gAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:02.597342 2026] [security2:error] [pid 66623:tid 66677] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/vd.php"] [unique_id "aoSBRtO5rbWdOArH04Ky7wABdig"] [Tue Aug 18 12:59:02.599758 2026] [security2:error] [pid 66623:tid 66708] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/core/.env"] [unique_id "aoSBRtO5rbWdOArH04Ky8AABDkc"] [Tue Aug 18 12:59:02.603431 2026] [security2:error] [pid 66623:tid 66891] [client 86.120.159.145:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8QAAAYc"] [Tue Aug 18 12:59:02.603545 2026] [security2:error] [pid 66623:tid 66891] [client 86.120.159.145:61785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8QAAAYc"] [Tue Aug 18 12:59:02.610061 2026] [security2:error] [pid 66623:tid 66658] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/auth.json"] [unique_id "aoSBRtO5rbWdOArH04Ky8gABhRU"] [Tue Aug 18 12:59:02.610996 2026] [security2:error] [pid 66623:tid 66781] [client 20.25.139.174:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/155.php"] [unique_id "aoSBRtO5rbWdOArH04Ky8wAAARk"] [Tue Aug 18 12:59:02.618073 2026] [security2:error] [pid 66623:tid 66858] [client 40.74.65.169:43069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/system_log.php"] [unique_id "aoSBRtO5rbWdOArH04Ky9AAAAWY"] [Tue Aug 18 12:59:02.619573 2026] [fcgid:warn] [pid 66623:tid 66833] (70014)End of file found: [client 167.94.146.51:8968] mod_fcgid: can't get data from http client [Tue Aug 18 12:59:02.636799 2026] [security2:error] [pid 66623:tid 66789] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/water.php"] [unique_id "aoSBRtO5rbWdOArH04Ky-QAAASE"] [Tue Aug 18 12:59:02.640908 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky-gABQko"] [Tue Aug 18 12:59:02.664567 2026] [security2:error] [pid 66623:tid 66816] [client 20.104.85.180:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBRtO5rbWdOArH04Ky-wAAATw"] [Tue Aug 18 12:59:02.689000 2026] [security2:error] [pid 66623:tid 66716] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBRtO5rbWdOArH04Ky_AABU08"] [Tue Aug 18 12:59:02.692513 2026] [security2:error] [pid 66623:tid 66683] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.dev"] [unique_id "aoSBRtO5rbWdOArH04Ky_QABJi4"] [Tue Aug 18 12:59:02.700918 2026] [security2:error] [pid 66623:tid 66688] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.swp"] [unique_id "aoSBRtO5rbWdOArH04Ky_gABWjM"] [Tue Aug 18 12:59:02.733751 2026] [security2:error] [pid 66623:tid 66879] [client 168.62.48.100:1142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBRtO5rbWdOArH04KzAAAAAXs"] [Tue Aug 18 12:59:02.768092 2026] [security2:error] [pid 66623:tid 66868] [client 68.221.73.131:39579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/av.php"] [unique_id "aoSBRtO5rbWdOArH04KzAQAAAXA"] [Tue Aug 18 12:59:02.810641 2026] [security2:error] [pid 66623:tid 66864] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/puc.php"] [unique_id "aoSBRtO5rbWdOArH04KzAwAAAWw"] [Tue Aug 18 12:59:02.839008 2026] [security2:error] [pid 66623:tid 66841] [client 4.232.151.198:5445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wsa.php"] [unique_id "aoSBRtO5rbWdOArH04KzBQAAAVU"] [Tue Aug 18 12:59:02.841420 2026] [security2:error] [pid 66623:tid 66878] [client 192.141.172.134:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04KzBgAAAXo"] [Tue Aug 18 12:59:02.841583 2026] [security2:error] [pid 66623:tid 66878] [client 192.141.172.134:52803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBRtO5rbWdOArH04KzBgAAAXo"] [Tue Aug 18 12:59:02.844847 2026] [security2:error] [pid 66623:tid 66692] [remote 185.227.135.83:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.135.227.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSBRtO5rbWdOArH04KzCAABVjc"], referer: https://rafaelbuzatto.com.br/wp-login.php [Tue Aug 18 12:59:02.844983 2026] [security2:error] [pid 66623:tid 66876] [client 52.173.121.69:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/index/function.php"] [unique_id "aoSBRtO5rbWdOArH04KzBwAAAXg"] [Tue Aug 18 12:59:02.867417 2026] [security2:error] [pid 66623:tid 66675] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/56.php"] [unique_id "aoSBRtO5rbWdOArH04KzCQABLSY"] [Tue Aug 18 12:59:02.876816 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:02.877076 2026] [authz_core:error] [pid 66623:tid 66661] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:02.885575 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gk.php"] [unique_id "aoSBRtO5rbWdOArH04KzCwAAAV4"] [Tue Aug 18 12:59:02.927308 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/public/.env"] [unique_id "aoSBRtO5rbWdOArH04KzDQABb3M"] [Tue Aug 18 12:59:02.946076 2026] [security2:error] [pid 66623:tid 66730] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/web/.env"] [unique_id "aoSBRtO5rbWdOArH04KzDwABc10"] [Tue Aug 18 12:59:02.981764 2026] [security2:error] [pid 66623:tid 66774] [client 20.25.139.174:4667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bthil.php"] [unique_id "aoSBRtO5rbWdOArH04KzEAAAARI"] [Tue Aug 18 12:59:02.985012 2026] [security2:error] [pid 66623:tid 66772] [client 168.62.48.100:1113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBRtO5rbWdOArH04KzEQAAARA"] [Tue Aug 18 12:59:03.005060 2026] [security2:error] [pid 66623:tid 66727] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/application.yml"] [unique_id "aoSBR9O5rbWdOArH04KzEwABbVo"] [Tue Aug 18 12:59:03.016668 2026] [security2:error] [pid 66623:tid 66797] [client 4.232.94.69:57515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/feeds.php"] [unique_id "aoSBR9O5rbWdOArH04KzFAAAASk"] [Tue Aug 18 12:59:03.046140 2026] [security2:error] [pid 66623:tid 66685] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/rx.php"] [unique_id "aoSBR9O5rbWdOArH04KzFgABdTA"] [Tue Aug 18 12:59:03.047948 2026] [security2:error] [pid 66623:tid 66790] [client 20.203.138.185:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ah25.php"] [unique_id "aoSBR9O5rbWdOArH04KzFwAAASI"] [Tue Aug 18 12:59:03.048880 2026] [security2:error] [pid 66623:tid 66809] [client 20.250.13.23:17034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBR9O5rbWdOArH04KzGAAAATU"] [Tue Aug 18 12:59:03.050003 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/application.properties"] [unique_id "aoSBR9O5rbWdOArH04KzGQABM2I"] [Tue Aug 18 12:59:03.050184 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/application.properties"] [unique_id "aoSBR9O5rbWdOArH04KzGgABMxs"] [Tue Aug 18 12:59:03.051520 2026] [security2:error] [pid 66623:tid 66717] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/bootstrap.yml"] [unique_id "aoSBR9O5rbWdOArH04KzGwABMVA"] [Tue Aug 18 12:59:03.078538 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/19.php"] [unique_id "aoSBR9O5rbWdOArH04KzHQAAAUY"] [Tue Aug 18 12:59:03.095609 2026] [security2:error] [pid 66623:tid 66793] [client 132.196.30.78:14976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/as.php"] [unique_id "aoSBR9O5rbWdOArH04KzHwAAASU"] [Tue Aug 18 12:59:03.171503 2026] [security2:error] [pid 66623:tid 66787] [client 20.25.139.174:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/96i.php"] [unique_id "aoSBR9O5rbWdOArH04KzJAAAAR8"] [Tue Aug 18 12:59:03.178883 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:03.179143 2026] [authz_core:error] [pid 66623:tid 66763] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:03.217362 2026] [security2:error] [pid 66623:tid 66778] [client 20.250.13.23:38246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/155.php"] [unique_id "aoSBR9O5rbWdOArH04KzJgAAARY"] [Tue Aug 18 12:59:03.219701 2026] [security2:error] [pid 66623:tid 66671] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mandrill.php"] [unique_id "aoSBR9O5rbWdOArH04KzJwABUCI"] [Tue Aug 18 12:59:03.226354 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBR9O5rbWdOArH04KzKQAAAVg"] [Tue Aug 18 12:59:03.229190 2026] [security2:error] [pid 66623:tid 66840] [client 168.62.48.100:1179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBR9O5rbWdOArH04KzKgAAAVQ"] [Tue Aug 18 12:59:03.248552 2026] [security2:error] [pid 66623:tid 66792] [client 20.118.172.148:63103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBR9O5rbWdOArH04KzLAAAASQ"] [Tue Aug 18 12:59:03.257768 2026] [security2:error] [pid 66623:tid 66640] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/bootstrap.properties"] [unique_id "aoSBR9O5rbWdOArH04KzLwABWQM"] [Tue Aug 18 12:59:03.260550 2026] [security2:error] [pid 66623:tid 66814] [client 20.104.85.180:15148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBR9O5rbWdOArH04KzMQAAATo"] [Tue Aug 18 12:59:03.262085 2026] [security2:error] [pid 66623:tid 66808] [client 52.173.121.69:16500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBR9O5rbWdOArH04KzMgAAATQ"] [Tue Aug 18 12:59:03.289415 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/secrets.yml"] [unique_id "aoSBR9O5rbWdOArH04KzMwABRwA"] [Tue Aug 18 12:59:03.372312 2026] [security2:error] [pid 66623:tid 66860] [client 74.248.18.37:19322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBR9O5rbWdOArH04KzNgAAAWg"] [Tue Aug 18 12:59:03.413070 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/actuator/env"] [unique_id "aoSBR9O5rbWdOArH04KzOAABHWo"] [Tue Aug 18 12:59:03.424745 2026] [security2:error] [pid 66623:tid 66758] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/main.php"] [unique_id "aoSBR9O5rbWdOArH04KzOgABUnk"] [Tue Aug 18 12:59:03.465949 2026] [security2:error] [pid 66623:tid 66782] [client 4.232.151.198:5483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/add.php"] [unique_id "aoSBR9O5rbWdOArH04KzPQAAARo"] [Tue Aug 18 12:59:03.480384 2026] [authz_core:error] [pid 66623:tid 66736] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:03.480640 2026] [authz_core:error] [pid 66623:tid 66736] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:03.514483 2026] [security2:error] [pid 66623:tid 66713] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.gradle/gradle.properties"] [unique_id "aoSBR9O5rbWdOArH04KzQQABZkw"] [Tue Aug 18 12:59:03.514484 2026] [security2:error] [pid 66623:tid 66741] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gradle.properties"] [unique_id "aoSBR9O5rbWdOArH04KzQAABZmg"] [Tue Aug 18 12:59:03.514979 2026] [security2:error] [pid 66623:tid 66744] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.json"] [unique_id "aoSBR9O5rbWdOArH04KzQgABTWs"] [Tue Aug 18 12:59:03.518478 2026] [security2:error] [pid 66623:tid 66779] [client 168.62.48.100:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBR9O5rbWdOArH04KzQwAAARc"] [Tue Aug 18 12:59:03.608468 2026] [security2:error] [pid 66623:tid 66791] [client 213.35.127.232:57982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBR9O5rbWdOArH04KzSQAAASM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:03.613705 2026] [security2:error] [pid 66623:tid 66777] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/133.php"] [unique_id "aoSBR9O5rbWdOArH04KzSwAAARU"] [Tue Aug 18 12:59:03.646656 2026] [security2:error] [pid 66623:tid 66859] [client 132.196.30.78:15000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/min.php"] [unique_id "aoSBR9O5rbWdOArH04KzTQAAAWc"] [Tue Aug 18 12:59:03.648346 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.Development.json"] [unique_id "aoSBR9O5rbWdOArH04KzTgABJnE"] [Tue Aug 18 12:59:03.652049 2026] [security2:error] [pid 66623:tid 66846] [client 52.173.121.69:32629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/Cachex.php"] [unique_id "aoSBR9O5rbWdOArH04KzTwAAAVo"] [Tue Aug 18 12:59:03.667349 2026] [security2:error] [pid 66623:tid 66648] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ga.php"] [unique_id "aoSBR9O5rbWdOArH04KzUgABQAs"] [Tue Aug 18 12:59:03.676054 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/appsettings.Production.json"] [unique_id "aoSBR9O5rbWdOArH04KzUwABaiU"] [Tue Aug 18 12:59:03.697839 2026] [security2:error] [pid 66623:tid 66789] [client 20.25.139.174:4637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/as.php"] [unique_id "aoSBR9O5rbWdOArH04KzVQAAASE"] [Tue Aug 18 12:59:03.740115 2026] [security2:error] [pid 66623:tid 66762] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/web.config"] [unique_id "aoSBR9O5rbWdOArH04KzWAABbH0"] [Tue Aug 18 12:59:03.810214 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBR9O5rbWdOArH04KzXQAAAVY"] [Tue Aug 18 12:59:03.814568 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/master.key"] [unique_id "aoSBR9O5rbWdOArH04KzXgABNyQ"] [Tue Aug 18 12:59:03.816195 2026] [security2:error] [pid 66623:tid 66689] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/database.yml"] [unique_id "aoSBR9O5rbWdOArH04KzXwABZTQ"] [Tue Aug 18 12:59:03.822549 2026] [security2:error] [pid 66623:tid 66828] [client 172.182.200.96:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBR9O5rbWdOArH04KzYAAAAUg"] [Tue Aug 18 12:59:03.845743 2026] [security2:error] [pid 66623:tid 66686] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/wb.php"] [unique_id "aoSBR9O5rbWdOArH04KzYgABLTE"] [Tue Aug 18 12:59:03.872226 2026] [security2:error] [pid 66623:tid 66676] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/local.settings.json"] [unique_id "aoSBR9O5rbWdOArH04KzYwABgic"] [Tue Aug 18 12:59:03.873266 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBR9O5rbWdOArH04KzZAAAAW8"] [Tue Aug 18 12:59:03.878773 2026] [security2:error] [pid 66623:tid 66775] [client 20.100.169.31:32652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/w.php"] [unique_id "aoSBR9O5rbWdOArH04KzZQAAARM"] [Tue Aug 18 12:59:03.913977 2026] [security2:error] [pid 66623:tid 66880] [client 20.250.13.23:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBR9O5rbWdOArH04KzZwAAAXw"] [Tue Aug 18 12:59:03.929452 2026] [fcgid:warn] [pid 66623:tid 66774] (70014)End of file found: [client 66.132.172.140:56148] mod_fcgid: can't get data from http client [Tue Aug 18 12:59:04.034039 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/storage.yml"] [unique_id "aoSBSNO5rbWdOArH04KzbgABf3c"] [Tue Aug 18 12:59:04.064884 2026] [security2:error] [pid 66623:tid 66803] [client 20.118.172.148:46783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/db.php"] [unique_id "aoSBSNO5rbWdOArH04KzcAAAAS8"] [Tue Aug 18 12:59:04.067010 2026] [security2:error] [pid 66623:tid 66678] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/xn.php"] [unique_id "aoSBSNO5rbWdOArH04KzcQABgSk"] [Tue Aug 18 12:59:04.080434 2026] [security2:error] [pid 66623:tid 66869] [client 74.248.18.37:7608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSBSNO5rbWdOArH04KzcwAAAXE"] [Tue Aug 18 12:59:04.082940 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBSNO5rbWdOArH04KzdAAAAU8"] [Tue Aug 18 12:59:04.085030 2026] [security2:error] [pid 66623:tid 66871] [client 20.25.139.174:4608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/x.php"] [unique_id "aoSBSNO5rbWdOArH04KzdgAAAXM"] [Tue Aug 18 12:59:04.085192 2026] [security2:error] [pid 66623:tid 66823] [client 20.38.3.247:46716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/media.php"] [unique_id "aoSBSNO5rbWdOArH04KzdwAAAUM"] [Tue Aug 18 12:59:04.110706 2026] [security2:error] [pid 66623:tid 66816] [client 4.232.94.69:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/curl.php"] [unique_id "aoSBSNO5rbWdOArH04KzeQAAATw"] [Tue Aug 18 12:59:04.116024 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.pypirc"] [unique_id "aoSBSNO5rbWdOArH04KzegABFh4"] [Tue Aug 18 12:59:04.116168 2026] [security2:error] [pid 66623:tid 66667] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzfAABFh4"] [Tue Aug 18 12:59:04.117318 2026] [security2:error] [pid 66623:tid 66787] [client 52.173.121.69:14554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBSNO5rbWdOArH04KzfQAAAR8"] [Tue Aug 18 12:59:04.126681 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fine.php"] [unique_id "aoSBSNO5rbWdOArH04KzfwAAAVQ"] [Tue Aug 18 12:59:04.133587 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:24998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/first.php"] [unique_id "aoSBSNO5rbWdOArH04KzgAAAAXc"] [Tue Aug 18 12:59:04.165349 2026] [security2:error] [pid 66623:tid 66834] [client 4.232.151.198:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/cron.php"] [unique_id "aoSBSNO5rbWdOArH04KzggAAAU4"] [Tue Aug 18 12:59:04.239879 2026] [autoindex:error] [pid 66623:tid 66793] [client 132.196.30.78:15651] AH01276: Cannot serve directory /home3/cadema/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:04.275020 2026] [security2:error] [pid 66623:tid 66806] [client 20.25.139.174:4615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/min.php"] [unique_id "aoSBSNO5rbWdOArH04KziQAAATI"] [Tue Aug 18 12:59:04.302613 2026] [security2:error] [pid 66623:tid 66639] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.streamlit/secrets.toml"] [unique_id "aoSBSNO5rbWdOArH04KziwABiQI"] [Tue Aug 18 12:59:04.308591 2026] [security2:error] [pid 66623:tid 66681] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/47.php"] [unique_id "aoSBSNO5rbWdOArH04KzjAABaCw"] [Tue Aug 18 12:59:04.315892 2026] [security2:error] [pid 66623:tid 66785] [client 158.23.17.4:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wn.php"] [unique_id "aoSBSNO5rbWdOArH04KzjgAAAR0"] [Tue Aug 18 12:59:04.335128 2026] [security2:error] [pid 66623:tid 66877] [client 168.62.48.100:1258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBSNO5rbWdOArH04KzkAAAAXk"] [Tue Aug 18 12:59:04.345430 2026] [security2:error] [pid 66623:tid 66672] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/core/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzkgABZiM"] [Tue Aug 18 12:59:04.376609 2026] [security2:error] [pid 66623:tid 66695] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzmAABSzo"] [Tue Aug 18 12:59:04.386434 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:04.386898 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:04.398937 2026] [security2:error] [pid 66623:tid 66855] [client 20.104.85.180:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/o.php"] [unique_id "aoSBSNO5rbWdOArH04KznAAAAWM"] [Tue Aug 18 12:59:04.411995 2026] [security2:error] [pid 66623:tid 66748] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzngABg28"] [Tue Aug 18 12:59:04.415388 2026] [security2:error] [pid 66623:tid 66815] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/loader.php"] [unique_id "aoSBSNO5rbWdOArH04KznwAAATs"] [Tue Aug 18 12:59:04.426289 2026] [security2:error] [pid 66623:tid 66770] [client 132.196.30.78:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/php8.php"] [unique_id "aoSBSNO5rbWdOArH04KzoAAAAQ4"] [Tue Aug 18 12:59:04.489382 2026] [security2:error] [pid 66623:tid 66709] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/backend/settings.py"] [unique_id "aoSBSNO5rbWdOArH04KzogABU0g"] [Tue Aug 18 12:59:04.497398 2026] [security2:error] [pid 66623:tid 66746] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/payout.php"] [unique_id "aoSBSNO5rbWdOArH04KzowABJm0"] [Tue Aug 18 12:59:04.509251 2026] [security2:error] [pid 66623:tid 66638] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.py"] [unique_id "aoSBSNO5rbWdOArH04KzpQABewE"] [Tue Aug 18 12:59:04.533653 2026] [security2:error] [pid 66623:tid 66782] [client 20.250.13.23:53666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adepol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04KzpwAAARo"] [Tue Aug 18 12:59:04.537839 2026] [security2:error] [pid 66623:tid 66789] [client 20.104.85.180:14582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBSNO5rbWdOArH04KzqAAAASE"] [Tue Aug 18 12:59:04.553960 2026] [security2:error] [pid 66623:tid 66889] [client 52.173.121.69:50249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-2019.php"] [unique_id "aoSBSNO5rbWdOArH04KzqgAAAYU"] [Tue Aug 18 12:59:04.561742 2026] [security2:error] [pid 66623:tid 66862] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04KzpgABanY"] [Tue Aug 18 12:59:04.612325 2026] [security2:error] [pid 66623:tid 66740] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/instance/config.py"] [unique_id "aoSBSNO5rbWdOArH04KzrgABhmc"] [Tue Aug 18 12:59:04.627783 2026] [security2:error] [pid 66623:tid 66680] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.development"] [unique_id "aoSBSNO5rbWdOArH04KzsAABRSs"] [Tue Aug 18 12:59:04.631594 2026] [security2:error] [pid 66623:tid 66824] [client 213.35.127.232:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBSNO5rbWdOArH04KzsgAAAUQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:04.640960 2026] [security2:error] [pid 66623:tid 66857] [client 168.62.48.100:1119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBSNO5rbWdOArH04KztAAAAWU"] [Tue Aug 18 12:59:04.672096 2026] [security2:error] [pid 66623:tid 66690] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.staging"] [unique_id "aoSBSNO5rbWdOArH04KztQABLTU"] [Tue Aug 18 12:59:04.674455 2026] [security2:error] [pid 66623:tid 66702] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bh.php"] [unique_id "aoSBSNO5rbWdOArH04KztgABXkE"] [Tue Aug 18 12:59:04.678135 2026] [security2:error] [pid 66623:tid 66798] [client 20.25.139.174:4603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/index/function.php"] [unique_id "aoSBSNO5rbWdOArH04KztwAAASo"] [Tue Aug 18 12:59:04.687158 2026] [authz_core:error] [pid 66623:tid 66760] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:04.687442 2026] [authz_core:error] [pid 66623:tid 66760] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:04.693493 2026] [security2:error] [pid 66623:tid 66867] [client 40.74.65.169:20147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/pucci.php"] [unique_id "aoSBSNO5rbWdOArH04KzuQAAAW8"] [Tue Aug 18 12:59:04.702152 2026] [security2:error] [pid 66623:tid 66775] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/zero.php"] [unique_id "aoSBSNO5rbWdOArH04KzugAAARM"] [Tue Aug 18 12:59:04.723224 2026] [security2:error] [pid 66623:tid 66884] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/mosty.php"] [unique_id "aoSBSNO5rbWdOArH04KzuwAAAYA"] [Tue Aug 18 12:59:04.733927 2026] [security2:error] [pid 66623:tid 66774] [client 20.118.172.148:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/dropdown.php"] [unique_id "aoSBSNO5rbWdOArH04KzvgAAARI"] [Tue Aug 18 12:59:04.734415 2026] [security2:error] [pid 66623:tid 66761] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.test"] [unique_id "aoSBSNO5rbWdOArH04KzvwABdXw"] [Tue Aug 18 12:59:04.791903 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.98.162:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/dex.php"] [unique_id "aoSBSNO5rbWdOArH04KzwgAAAWQ"] [Tue Aug 18 12:59:04.830086 2026] [security2:error] [pid 66623:tid 66771] [client 4.232.151.198:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/we.php"] [unique_id "aoSBSNO5rbWdOArH04KzxAAAAQ8"] [Tue Aug 18 12:59:04.854100 2026] [security2:error] [pid 66623:tid 66656] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.env"] [unique_id "aoSBSNO5rbWdOArH04KzxQABgRM"] [Tue Aug 18 12:59:04.871402 2026] [security2:error] [pid 66623:tid 66714] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/sendgrid.env"] [unique_id "aoSBSNO5rbWdOArH04KzyAABaU0"] [Tue Aug 18 12:59:04.877095 2026] [autoindex:error] [pid 66623:tid 66848] [client 20.25.139.174:4624] AH01276: Cannot serve directory /home3/cadema/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:04.892753 2026] [security2:error] [pid 66623:tid 66835] [client 168.62.48.100:1092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBSNO5rbWdOArH04KzyQAAAU8"] [Tue Aug 18 12:59:04.895347 2026] [security2:error] [pid 66623:tid 66679] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/ct.php"] [unique_id "aoSBSNO5rbWdOArH04KzygABFCo"] [Tue Aug 18 12:59:04.926758 2026] [security2:error] [pid 66623:tid 66886] [client 74.248.18.37:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSBSNO5rbWdOArH04KzzAAAAYI"] [Tue Aug 18 12:59:04.965375 2026] [security2:error] [pid 66623:tid 66826] [client 132.196.30.78:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBSNO5rbWdOArH04KzzgAAAUY"] [Tue Aug 18 12:59:04.975912 2026] [security2:error] [pid 66623:tid 66863] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/blurbs.php"] [unique_id "aoSBSNO5rbWdOArH04KzzwAAAWs"] [Tue Aug 18 12:59:04.979367 2026] [security2:error] [pid 66623:tid 66808] [client 103.184.169.37:42511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04Kz0AAAATQ"] [Tue Aug 18 12:59:04.979654 2026] [security2:error] [pid 66623:tid 66808] [client 103.184.169.37:42511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSNO5rbWdOArH04Kz0AAAATQ"] [Tue Aug 18 12:59:04.981692 2026] [security2:error] [pid 66623:tid 66706] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app/.env"] [unique_id "aoSBSNO5rbWdOArH04Kz0QABH0U"] [Tue Aug 18 12:59:04.988991 2026] [authz_core:error] [pid 66623:tid 66645] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:04.989245 2026] [authz_core:error] [pid 66623:tid 66645] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:05.006510 2026] [security2:error] [pid 66623:tid 66684] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/src/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz1QABPS8"] [Tue Aug 18 12:59:05.006528 2026] [security2:error] [pid 66623:tid 66844] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/002.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1AAAAVg"] [Tue Aug 18 12:59:05.046648 2026] [security2:error] [pid 66623:tid 66853] [client 68.221.73.131:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/media.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1gAAAWE"] [Tue Aug 18 12:59:05.049412 2026] [security2:error] [pid 66623:tid 66845] [client 20.25.139.174:4624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/php8.php"] [unique_id "aoSBSdO5rbWdOArH04Kz1wAAAVk"] [Tue Aug 18 12:59:05.072269 2026] [security2:error] [pid 66623:tid 66854] [client 52.173.121.69:29019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBSdO5rbWdOArH04Kz2AAAAWI"] [Tue Aug 18 12:59:05.091173 2026] [security2:error] [pid 66623:tid 66828] [client 4.232.94.69:54142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/Njima.php"] [unique_id "aoSBSdO5rbWdOArH04Kz2QAAAUg"] [Tue Aug 18 12:59:05.123265 2026] [security2:error] [pid 66623:tid 66872] [client 52.173.121.69:16457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3AAAAXQ"] [Tue Aug 18 12:59:05.129110 2026] [security2:error] [pid 66623:tid 66658] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/gy.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3QABMBU"] [Tue Aug 18 12:59:05.172709 2026] [security2:error] [pid 66623:tid 66846] [client 103.120.71.157:18181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3gAAAVo"] [Tue Aug 18 12:59:05.172849 2026] [security2:error] [pid 66623:tid 66846] [client 103.120.71.157:18181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz3gAAAVo"] [Tue Aug 18 12:59:05.183634 2026] [security2:error] [pid 66623:tid 66802] [client 20.118.172.148:43465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/file.php"] [unique_id "aoSBSdO5rbWdOArH04Kz4AAAAS4"] [Tue Aug 18 12:59:05.184450 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBSdO5rbWdOArH04Kz4gAAAR0"] [Tue Aug 18 12:59:05.222460 2026] [security2:error] [pid 66623:tid 66711] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/frontend/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz5QABF0o"] [Tue Aug 18 12:59:05.222829 2026] [security2:error] [pid 66623:tid 66795] [client 158.23.17.4:56704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/app.php"] [unique_id "aoSBSdO5rbWdOArH04Kz5AAAASc"] [Tue Aug 18 12:59:05.235511 2026] [security2:error] [pid 66623:tid 66830] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bajah.php"] [unique_id "aoSBSdO5rbWdOArH04Kz5wAAAUo"] [Tue Aug 18 12:59:05.244826 2026] [security2:error] [pid 66623:tid 66797] [client 20.250.13.23:46901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/96i.php"] [unique_id "aoSBSdO5rbWdOArH04Kz6AAAASk"] [Tue Aug 18 12:59:05.254839 2026] [security2:error] [pid 66623:tid 66814] [client 20.25.139.174:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/aaa.php"] [unique_id "aoSBSdO5rbWdOArH04Kz6QAAATo"] [Tue Aug 18 12:59:05.276422 2026] [security2:error] [pid 66623:tid 66683] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/server/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz6wABYy4"] [Tue Aug 18 12:59:05.298037 2026] [security2:error] [pid 66623:tid 66783] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/zxz.php"] [unique_id "aoSBSdO5rbWdOArH04Kz7AAAARs"] [Tue Aug 18 12:59:05.332154 2026] [security2:error] [pid 66623:tid 66688] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/tt.php"] [unique_id "aoSBSdO5rbWdOArH04Kz7QABZzM"] [Tue Aug 18 12:59:05.387640 2026] [security2:error] [pid 66623:tid 66753] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/production/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz7wABIXQ"] [Tue Aug 18 12:59:05.412091 2026] [authz_core:error] [pid 66623:tid 66668] [remote 57.141.22.127:30348] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:05.412359 2026] [authz_core:error] [pid 66623:tid 66668] [remote 57.141.22.127:30348] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:05.437435 2026] [security2:error] [pid 66623:tid 66692] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/docker/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz9AABQDc"] [Tue Aug 18 12:59:05.446185 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/staging/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz9QABhiY"] [Tue Aug 18 12:59:05.453361 2026] [security2:error] [pid 66623:tid 66824] [client 20.203.138.185:10964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tt.php"] [unique_id "aoSBSdO5rbWdOArH04Kz9wAAAUQ"] [Tue Aug 18 12:59:05.463032 2026] [security2:error] [pid 66623:tid 66831] [client 79.127.164.8:58368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sql.bak"] [unique_id "aoSBSdO5rbWdOArH04Kz-QAAAUs"], referer: https://medihub.com.br/sql.bak [Tue Aug 18 12:59:05.468142 2026] [security2:error] [pid 66623:tid 66842] [client 52.173.121.69:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/.cache/x.php"] [unique_id "aoSBSdO5rbWdOArH04Kz-gAAAVY"] [Tue Aug 18 12:59:05.487131 2026] [security2:error] [pid 66623:tid 66813] [client 138.36.100.162:42273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_AAAATk"] [Tue Aug 18 12:59:05.487238 2026] [security2:error] [pid 66623:tid 66813] [client 138.36.100.162:42273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_AAAATk"] [Tue Aug 18 12:59:05.487926 2026] [security2:error] [pid 66623:tid 66790] [client 4.232.151.198:30045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/themes/newsfeed-theme/bbh.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_QAAASI"] [Tue Aug 18 12:59:05.499440 2026] [security2:error] [pid 66623:tid 66768] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/h.php"] [unique_id "aoSBSdO5rbWdOArH04Kz_gAAAQw"] [Tue Aug 18 12:59:05.509120 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/dev/.env"] [unique_id "aoSBSdO5rbWdOArH04Kz_wABXnM"] [Tue Aug 18 12:59:05.520458 2026] [security2:error] [pid 66623:tid 66819] [client 168.62.48.100:1121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBSdO5rbWdOArH04K0AAAAAT8"] [Tue Aug 18 12:59:05.536790 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:28628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cah.php"] [unique_id "aoSBSdO5rbWdOArH04K0AgAAARA"] [Tue Aug 18 12:59:05.541048 2026] [security2:error] [pid 66623:tid 66782] [client 20.25.139.174:4662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBSdO5rbWdOArH04K0AwAAARo"] [Tue Aug 18 12:59:05.582478 2026] [security2:error] [pid 66623:tid 66727] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/mq.php"] [unique_id "aoSBSdO5rbWdOArH04K0BQABiFo"] [Tue Aug 18 12:59:05.583590 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBSdO5rbWdOArH04K0BgAAATY"] [Tue Aug 18 12:59:05.592030 2026] [security2:error] [pid 66623:tid 66889] [client 132.196.30.78:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/222.php"] [unique_id "aoSBSdO5rbWdOArH04K0CAAAAYU"] [Tue Aug 18 12:59:05.594910 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:05.595163 2026] [authz_core:error] [pid 66623:tid 66685] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:05.610436 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.docker"] [unique_id "aoSBSdO5rbWdOArH04K0CgABD2I"] [Tue Aug 18 12:59:05.638787 2026] [security2:error] [pid 66623:tid 66664] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.production.bak"] [unique_id "aoSBSdO5rbWdOArH04K0CwABgRs"] [Tue Aug 18 12:59:05.644220 2026] [security2:error] [pid 66623:tid 66777] [client 213.35.127.232:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBSdO5rbWdOArH04K0DQAAARU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:05.667829 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:47121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/bb.php"] [unique_id "aoSBSdO5rbWdOArH04K0DwAAAU8"] [Tue Aug 18 12:59:05.669836 2026] [security2:error] [pid 66623:tid 66836] [client 37.40.227.74:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0EAAAAVA"] [Tue Aug 18 12:59:05.679007 2026] [security2:error] [pid 66623:tid 66836] [client 37.40.227.74:57061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0EAAAAVA"] [Tue Aug 18 12:59:05.728979 2026] [security2:error] [pid 66623:tid 66705] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSBSdO5rbWdOArH04K0EgABH0Q"] [Tue Aug 18 12:59:05.756839 2026] [security2:error] [pid 66623:tid 66874] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ano.php"] [unique_id "aoSBSdO5rbWdOArH04K0FQAAAXY"] [Tue Aug 18 12:59:05.763823 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/.env"] [unique_id "aoSBSdO5rbWdOArH04K0FgABbWw"] [Tue Aug 18 12:59:05.774023 2026] [security2:error] [pid 66623:tid 66640] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/13.php"] [unique_id "aoSBSdO5rbWdOArH04K0FwABJAM"] [Tue Aug 18 12:59:05.783013 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSBSdO5rbWdOArH04K0GAABWQA"] [Tue Aug 18 12:59:05.795733 2026] [security2:error] [pid 66623:tid 66881] [client 168.62.48.100:1088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBSdO5rbWdOArH04K0GgAAAX0"] [Tue Aug 18 12:59:05.797782 2026] [security2:error] [pid 66623:tid 66839] [client 149.34.210.141:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0GwAAAVM"] [Tue Aug 18 12:59:05.813356 2026] [security2:error] [pid 66623:tid 66832] [client 74.248.18.37:32076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSBSdO5rbWdOArH04K0HQAAAUw"] [Tue Aug 18 12:59:05.825641 2026] [security2:error] [pid 66623:tid 66803] [client 20.25.139.174:4616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/abcd.php"] [unique_id "aoSBSdO5rbWdOArH04K0HwAAAS8"] [Tue Aug 18 12:59:05.846619 2026] [security2:error] [pid 66623:tid 66800] [client 52.173.121.69:14543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBSdO5rbWdOArH04K0IgAAASw"] [Tue Aug 18 12:59:05.850672 2026] [security2:error] [pid 66623:tid 66872] [client 172.202.39.151:44548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/13.php"] [unique_id "aoSBSdO5rbWdOArH04K0IwAAAXQ"] [Tue Aug 18 12:59:05.852001 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBSdO5rbWdOArH04K0JAABMHk"] [Tue Aug 18 12:59:05.856939 2026] [security2:error] [pid 66623:tid 66796] [client 20.118.172.148:63081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/goods.php"] [unique_id "aoSBSdO5rbWdOArH04K0JQAAASg"] [Tue Aug 18 12:59:05.861440 2026] [security2:error] [pid 66623:tid 66893] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/aa.php"] [unique_id "aoSBSdO5rbWdOArH04K0JgAAAYk"] [Tue Aug 18 12:59:05.875731 2026] [security2:error] [pid 66623:tid 66818] [client 68.221.73.131:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/images.php"] [unique_id "aoSBSdO5rbWdOArH04K0KQAAAT4"] [Tue Aug 18 12:59:05.902954 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:05.903404 2026] [authz_core:error] [pid 66623:tid 66654] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:05.931574 2026] [security2:error] [pid 66623:tid 66856] [client 4.232.94.69:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/colors.php"] [unique_id "aoSBSdO5rbWdOArH04K0LAAAAWQ"] [Tue Aug 18 12:59:05.941884 2026] [security2:error] [pid 66623:tid 66741] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-credentials.json"] [unique_id "aoSBSdO5rbWdOArH04K0LQABEWg"] [Tue Aug 18 12:59:05.975055 2026] [security2:error] [pid 66623:tid 66783] [client 172.202.39.151:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBSdO5rbWdOArH04K0LgAAARs"] [Tue Aug 18 12:59:05.986044 2026] [security2:error] [pid 66623:tid 66744] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/so.php"] [unique_id "aoSBSdO5rbWdOArH04K0LwABJms"] [Tue Aug 18 12:59:06.007314 2026] [security2:error] [pid 66623:tid 66891] [client 157.20.138.62:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0MgAAAYc"] [Tue Aug 18 12:59:06.007417 2026] [security2:error] [pid 66623:tid 66891] [client 157.20.138.62:54497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0MgAAAYc"] [Tue Aug 18 12:59:06.012351 2026] [security2:error] [pid 66623:tid 66786] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ai.php"] [unique_id "aoSBStO5rbWdOArH04K0MwAAAR4"] [Tue Aug 18 12:59:06.014486 2026] [security2:error] [pid 66623:tid 66733] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0NAABQGA"] [Tue Aug 18 12:59:06.023350 2026] [security2:error] [pid 66623:tid 66739] [remote 129.121.123.168:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0NQABVWY"] [Tue Aug 18 12:59:06.042607 2026] [security2:error] [pid 66623:tid 66767] [client 168.62.48.100:1163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBStO5rbWdOArH04K0NwAAAQs"] [Tue Aug 18 12:59:06.049642 2026] [security2:error] [pid 66623:tid 66838] [client 20.25.139.174:4654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/222.php"] [unique_id "aoSBStO5rbWdOArH04K0OAAAAVI"] [Tue Aug 18 12:59:06.076514 2026] [security2:error] [pid 66623:tid 66839] [client 149.34.210.141:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBSdO5rbWdOArH04K0GwAAAVM"] [Tue Aug 18 12:59:06.080694 2026] [security2:error] [pid 66623:tid 66768] [client 172.182.200.96:7650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBStO5rbWdOArH04K0OgAAAQw"] [Tue Aug 18 12:59:06.115319 2026] [security2:error] [pid 66623:tid 66850] [client 52.173.121.69:16453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBStO5rbWdOArH04K0PgAAAV4"] [Tue Aug 18 12:59:06.121172 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/keys/service-account.json"] [unique_id "aoSBStO5rbWdOArH04K0PwABPws"] [Tue Aug 18 12:59:06.133508 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/sa.json"] [unique_id "aoSBStO5rbWdOArH04K0QgABECU"] [Tue Aug 18 12:59:06.133798 2026] [security2:error] [pid 66623:tid 66834] [client 4.232.151.198:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/network/xleet.php"] [unique_id "aoSBStO5rbWdOArH04K0QQAAAU4"] [Tue Aug 18 12:59:06.151019 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0QwABGRY"] [Tue Aug 18 12:59:06.158553 2026] [security2:error] [pid 66623:tid 66879] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/echkm.php"] [unique_id "aoSBStO5rbWdOArH04K0RAAAAXs"] [Tue Aug 18 12:59:06.162428 2026] [security2:error] [pid 66623:tid 66661] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/10.php"] [unique_id "aoSBStO5rbWdOArH04K0RQABDxg"] [Tue Aug 18 12:59:06.196356 2026] [security2:error] [pid 66623:tid 66696] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-admin.json"] [unique_id "aoSBStO5rbWdOArH04K0SQABgTs"] [Tue Aug 18 12:59:06.202043 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:06.202515 2026] [authz_core:error] [pid 66623:tid 66641] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:06.213917 2026] [security2:error] [pid 66623:tid 66775] [client 114.5.214.109:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0SgAAARM"] [Tue Aug 18 12:59:06.215667 2026] [security2:error] [pid 66623:tid 66775] [client 114.5.214.109:50412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0SgAAARM"] [Tue Aug 18 12:59:06.220193 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBStO5rbWdOArH04K0TAAAAX4"] [Tue Aug 18 12:59:06.224224 2026] [security2:error] [pid 66623:tid 66835] [client 20.104.85.180:35886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBStO5rbWdOArH04K0TgAAAU8"] [Tue Aug 18 12:59:06.224742 2026] [security2:error] [pid 66623:tid 66886] [client 52.173.121.69:30384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBStO5rbWdOArH04K0TwAAAYI"] [Tue Aug 18 12:59:06.226102 2026] [security2:error] [pid 66623:tid 66689] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-key.json"] [unique_id "aoSBStO5rbWdOArH04K0UAABUDQ"] [Tue Aug 18 12:59:06.275273 2026] [security2:error] [pid 66623:tid 66686] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/public/admin.json"] [unique_id "aoSBStO5rbWdOArH04K0UgABWDE"] [Tue Aug 18 12:59:06.307113 2026] [security2:error] [pid 66623:tid 66865] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/w1px.php"] [unique_id "aoSBStO5rbWdOArH04K0VAAAAW0"] [Tue Aug 18 12:59:06.317743 2026] [security2:error] [pid 66623:tid 66810] [client 20.25.139.174:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-good.php"] [unique_id "aoSBStO5rbWdOArH04K0VQAAATY"] [Tue Aug 18 12:59:06.358549 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/firebase-admin.json"] [unique_id "aoSBStO5rbWdOArH04K0WAABLw8"] [Tue Aug 18 12:59:06.368661 2026] [security2:error] [pid 66623:tid 66707] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/te.php"] [unique_id "aoSBStO5rbWdOArH04K0WQABSEY"] [Tue Aug 18 12:59:06.378113 2026] [security2:error] [pid 66623:tid 66763] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/gcp-credentials.json"] [unique_id "aoSBStO5rbWdOArH04K0WwABMn4"] [Tue Aug 18 12:59:06.380288 2026] [security2:error] [pid 66623:tid 66756] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase.json"] [unique_id "aoSBStO5rbWdOArH04K0XAABLHc"] [Tue Aug 18 12:59:06.383909 2026] [security2:error] [pid 66623:tid 66872] [client 168.62.48.100:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBStO5rbWdOArH04K0XQAAAXQ"] [Tue Aug 18 12:59:06.387028 2026] [security2:error] [pid 66623:tid 66678] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0XgABOSk"] [Tue Aug 18 12:59:06.387225 2026] [security2:error] [pid 66623:tid 66813] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0XgABOSk"] [Tue Aug 18 12:59:06.416910 2026] [security2:error] [pid 66623:tid 66875] [client 5.31.227.224:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0YgAAAXc"] [Tue Aug 18 12:59:06.417034 2026] [security2:error] [pid 66623:tid 66875] [client 5.31.227.224:7835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0YgAAAXc"] [Tue Aug 18 12:59:06.442303 2026] [security2:error] [pid 66623:tid 66693] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-service-account.json"] [unique_id "aoSBStO5rbWdOArH04K0ZgABSjg"] [Tue Aug 18 12:59:06.444604 2026] [security2:error] [pid 66623:tid 66797] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/domvf.php"] [unique_id "aoSBStO5rbWdOArH04K0ZwAAASk"] [Tue Aug 18 12:59:06.447714 2026] [security2:error] [pid 66623:tid 66822] [client 20.203.138.185:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xqq.php"] [unique_id "aoSBStO5rbWdOArH04K0aAAAAUI"] [Tue Aug 18 12:59:06.449104 2026] [security2:error] [pid 66623:tid 66856] [client 20.104.85.180:18735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/system_log.php"] [unique_id "aoSBStO5rbWdOArH04K0aQAAAWQ"] [Tue Aug 18 12:59:06.462828 2026] [security2:error] [pid 66623:tid 66725] [remote 162.214.205.212:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0agABYVg"] [Tue Aug 18 12:59:06.477404 2026] [security2:error] [pid 66623:tid 66700] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/push_config.json"] [unique_id "aoSBStO5rbWdOArH04K0bAABQz8"] [Tue Aug 18 12:59:06.527910 2026] [security2:error] [pid 66623:tid 66724] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gc-service.json"] [unique_id "aoSBStO5rbWdOArH04K0cAABI1c"] [Tue Aug 18 12:59:06.535700 2026] [security2:error] [pid 66623:tid 66814] [client 178.153.171.161:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0cQAAATo"] [Tue Aug 18 12:59:06.535817 2026] [security2:error] [pid 66623:tid 66814] [client 178.153.171.161:8532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBStO5rbWdOArH04K0cQAAATo"] [Tue Aug 18 12:59:06.554794 2026] [security2:error] [pid 66623:tid 66643] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/kc.php"] [unique_id "aoSBStO5rbWdOArH04K0cwABJgY"] [Tue Aug 18 12:59:06.570344 2026] [security2:error] [pid 66623:tid 66877] [client 20.25.139.174:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBStO5rbWdOArH04K0dAAAAXk"] [Tue Aug 18 12:59:06.575768 2026] [security2:error] [pid 66623:tid 66736] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/gcp-service.json"] [unique_id "aoSBStO5rbWdOArH04K0dgABNWM"] [Tue Aug 18 12:59:06.580578 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:25338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSBStO5rbWdOArH04K0dQAAAX0"] [Tue Aug 18 12:59:06.591671 2026] [security2:error] [pid 66623:tid 66788] [client 20.118.172.148:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBStO5rbWdOArH04K0dwAAASA"] [Tue Aug 18 12:59:06.592345 2026] [security2:error] [pid 66623:tid 66639] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/pprof/"] [unique_id "aoSBStO5rbWdOArH04K0eAABHgI"] [Tue Aug 18 12:59:06.592933 2026] [security2:error] [pid 66623:tid 66681] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/google-services.json"] [unique_id "aoSBStO5rbWdOArH04K0eQABHiw"] [Tue Aug 18 12:59:06.596070 2026] [security2:error] [pid 66623:tid 66864] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/zi-936.php"] [unique_id "aoSBStO5rbWdOArH04K0egAAAWw"] [Tue Aug 18 12:59:06.653901 2026] [security2:error] [pid 66623:tid 66793] [client 213.35.127.232:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBStO5rbWdOArH04K0hwAAASU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:06.666857 2026] [security2:error] [pid 66623:tid 66838] [client 168.62.48.100:1108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBStO5rbWdOArH04K0iAAAAVI"] [Tue Aug 18 12:59:06.687856 2026] [security2:error] [pid 66623:tid 66825] [client 52.173.121.69:14874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBStO5rbWdOArH04K0iQAAAUU"] [Tue Aug 18 12:59:06.747281 2026] [security2:error] [pid 66623:tid 66728] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSBStO5rbWdOArH04K0jQABP1s"] [Tue Aug 18 12:59:06.762411 2026] [security2:error] [pid 66623:tid 66859] [client 4.232.151.198:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSBStO5rbWdOArH04K0jwAAAWc"] [Tue Aug 18 12:59:06.764475 2026] [security2:error] [pid 66623:tid 66820] [client 132.196.30.78:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/info.php"] [unique_id "aoSBStO5rbWdOArH04K0kAAAAUA"] [Tue Aug 18 12:59:06.773782 2026] [security2:error] [pid 66623:tid 66774] [client 40.74.65.169:20139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBStO5rbWdOArH04K0kQAAARI"] [Tue Aug 18 12:59:06.774072 2026] [security2:error] [pid 66623:tid 66892] [client 20.250.13.23:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/as.php"] [unique_id "aoSBStO5rbWdOArH04K0kgAAAYg"] [Tue Aug 18 12:59:06.775823 2026] [security2:error] [pid 66623:tid 66801] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/red.php"] [unique_id "aoSBStO5rbWdOArH04K0kwAAAS0"] [Tue Aug 18 12:59:06.788371 2026] [security2:error] [pid 66623:tid 66638] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/jn.php"] [unique_id "aoSBStO5rbWdOArH04K0lAABewE"] [Tue Aug 18 12:59:06.798511 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:06.798792 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:06.799084 2026] [security2:error] [pid 66623:tid 66755] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/debug/vars"] [unique_id "aoSBStO5rbWdOArH04K0lgABdXY"] [Tue Aug 18 12:59:06.816922 2026] [security2:error] [pid 66623:tid 66824] [client 20.25.139.174:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/simple.php"] [unique_id "aoSBStO5rbWdOArH04K0mAAAAUQ"] [Tue Aug 18 12:59:06.859448 2026] [security2:error] [pid 66623:tid 66780] [client 20.100.169.31:24428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/archive.php"] [unique_id "aoSBStO5rbWdOArH04K0ngAAARg"] [Tue Aug 18 12:59:06.872727 2026] [security2:error] [pid 66623:tid 66720] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/metrics"] [unique_id "aoSBStO5rbWdOArH04K0oAABT1M"] [Tue Aug 18 12:59:06.874331 2026] [security2:error] [pid 66623:tid 66886] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBStO5rbWdOArH04K0oQAAAYI"] [Tue Aug 18 12:59:06.930222 2026] [security2:error] [pid 66623:tid 66718] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.yaml"] [unique_id "aoSBStO5rbWdOArH04K0pwABVlE"] [Tue Aug 18 12:59:06.945776 2026] [security2:error] [pid 66623:tid 66817] [client 168.62.48.100:1164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBStO5rbWdOArH04K0qAAAAT0"] [Tue Aug 18 12:59:06.999710 2026] [security2:error] [pid 66623:tid 66781] [client 132.196.30.78:15036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/inputs.php"] [unique_id "aoSBStO5rbWdOArH04K0rgAAARk"] [Tue Aug 18 12:59:07.031688 2026] [security2:error] [pid 66623:tid 66706] [remote 20.29.77.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suporte.automasantos.com.br"] [uri "/bf.php"] [unique_id "aoSBS9O5rbWdOArH04K0sQABOUU"] [Tue Aug 18 12:59:07.052473 2026] [security2:error] [pid 66623:tid 66655] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.toml"] [unique_id "aoSBS9O5rbWdOArH04K0swABFBI"] [Tue Aug 18 12:59:07.065062 2026] [security2:error] [pid 66623:tid 66787] [client 20.25.139.174:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/info.php"] [unique_id "aoSBS9O5rbWdOArH04K0tQAAAR8"] [Tue Aug 18 12:59:07.081240 2026] [security2:error] [pid 66623:tid 66874] [client 223.185.37.47:24499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0tgAAAXY"] [Tue Aug 18 12:59:07.085727 2026] [security2:error] [pid 66623:tid 66874] [client 223.185.37.47:24499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0tgAAAXY"] [Tue Aug 18 12:59:07.107005 2026] [authz_core:error] [pid 66623:tid 66723] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:07.107426 2026] [authz_core:error] [pid 66623:tid 66723] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:07.119052 2026] [security2:error] [pid 66623:tid 66773] [client 20.104.85.180:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBS9O5rbWdOArH04K0vQAAARE"] [Tue Aug 18 12:59:07.122469 2026] [security2:error] [pid 66623:tid 66812] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBS9O5rbWdOArH04K0vgAAATg"] [Tue Aug 18 12:59:07.153448 2026] [security2:error] [pid 66623:tid 66747] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0wAABHW4"] [Tue Aug 18 12:59:07.153682 2026] [security2:error] [pid 66623:tid 66785] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K0wAABHW4"] [Tue Aug 18 12:59:07.157794 2026] [security2:error] [pid 66623:tid 66791] [client 52.173.121.69:30353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBS9O5rbWdOArH04K0wgAAASM"] [Tue Aug 18 12:59:07.216228 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:1100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/rezor.php"] [unique_id "aoSBS9O5rbWdOArH04K0yQAAAYc"] [Tue Aug 18 12:59:07.246363 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/dashboard"] [unique_id "aoSBS9O5rbWdOArH04K0ygABbCY"] [Tue Aug 18 12:59:07.246656 2026] [security2:error] [pid 66623:tid 66754] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/info"] [unique_id "aoSBS9O5rbWdOArH04K0ywABbHU"] [Tue Aug 18 12:59:07.248132 2026] [security2:error] [pid 66623:tid 66645] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/_health"] [unique_id "aoSBS9O5rbWdOArH04K0zQABXwg"] [Tue Aug 18 12:59:07.299776 2026] [security2:error] [pid 66623:tid 66818] [client 74.248.18.37:25312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBS9O5rbWdOArH04K01wAAAT4"] [Tue Aug 18 12:59:07.303839 2026] [security2:error] [pid 66623:tid 66880] [client 85.154.68.202:18593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K02AAAAXw"] [Tue Aug 18 12:59:07.303971 2026] [security2:error] [pid 66623:tid 66880] [client 85.154.68.202:18593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K02AAAAXw"] [Tue Aug 18 12:59:07.320393 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:29290] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lecarveiculospira.com.br"] [uri "/1.php"] [unique_id "aoSBS9O5rbWdOArH04K02QAAAW8"] [Tue Aug 18 12:59:07.320502 2026] [security2:error] [pid 66623:tid 66867] [client 20.65.98.162:29290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/1.php"] [unique_id "aoSBS9O5rbWdOArH04K02QAAAW8"] [Tue Aug 18 12:59:07.356846 2026] [security2:error] [pid 66623:tid 66794] [client 132.196.30.78:22144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/a.php"] [unique_id "aoSBS9O5rbWdOArH04K02wAAASY"] [Tue Aug 18 12:59:07.390401 2026] [security2:error] [pid 66623:tid 66860] [client 20.25.139.174:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBS9O5rbWdOArH04K03gAAAWg"] [Tue Aug 18 12:59:07.406656 2026] [security2:error] [pid 66623:tid 66789] [client 4.232.151.198:5499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/num.php"] [unique_id "aoSBS9O5rbWdOArH04K04AAAASE"] [Tue Aug 18 12:59:07.409491 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:07.409770 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:07.414799 2026] [security2:error] [pid 66623:tid 66770] [client 4.232.94.69:52543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSBS9O5rbWdOArH04K04QAAAQ4"] [Tue Aug 18 12:59:07.430810 2026] [security2:error] [pid 66623:tid 66637] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/runtime.exs"] [unique_id "aoSBS9O5rbWdOArH04K04gABWgA"] [Tue Aug 18 12:59:07.435690 2026] [security2:error] [pid 66623:tid 66883] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBS9O5rbWdOArH04K04wAAAX8"] [Tue Aug 18 12:59:07.466106 2026] [security2:error] [pid 66623:tid 66758] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config/prod.exs"] [unique_id "aoSBS9O5rbWdOArH04K06AABGHk"] [Tue Aug 18 12:59:07.467173 2026] [security2:error] [pid 66623:tid 66835] [client 40.74.65.169:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBS9O5rbWdOArH04K06QAAAU8"] [Tue Aug 18 12:59:07.512135 2026] [security2:error] [pid 66623:tid 66841] [client 213.202.253.4:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/userfuns.php"] [unique_id "aoSBS9O5rbWdOArH04K06wAAAVU"], referer: www.google.com [Tue Aug 18 12:59:07.514148 2026] [security2:error] [pid 66623:tid 66826] [client 20.118.172.148:43479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/htaccess.php"] [unique_id "aoSBS9O5rbWdOArH04K07AAAAUY"] [Tue Aug 18 12:59:07.535164 2026] [security2:error] [pid 66623:tid 66816] [client 20.203.138.185:18467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/06.php"] [unique_id "aoSBS9O5rbWdOArH04K07QAAATw"] [Tue Aug 18 12:59:07.542937 2026] [security2:error] [pid 66623:tid 66842] [client 168.62.48.100:1115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBS9O5rbWdOArH04K07gAAAVY"] [Tue Aug 18 12:59:07.579527 2026] [security2:error] [pid 66623:tid 66803] [client 20.104.85.180:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBS9O5rbWdOArH04K08gAAAS8"] [Tue Aug 18 12:59:07.590549 2026] [security2:error] [pid 66623:tid 66873] [client 20.25.139.174:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/a.php"] [unique_id "aoSBS9O5rbWdOArH04K08wAAAXU"] [Tue Aug 18 12:59:07.599866 2026] [security2:error] [pid 66623:tid 66843] [client 52.173.121.69:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBS9O5rbWdOArH04K09QAAAVc"] [Tue Aug 18 12:59:07.601241 2026] [security2:error] [pid 66623:tid 66861] [client 52.173.121.69:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBS9O5rbWdOArH04K09wAAAWk"] [Tue Aug 18 12:59:07.609940 2026] [security2:error] [pid 66623:tid 66772] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSBS9O5rbWdOArH04K05gABEEA"], referer: https://jgbdominiosolucoes.com.br/ [Tue Aug 18 12:59:07.647172 2026] [security2:error] [pid 66623:tid 66868] [client 132.196.30.78:13466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBS9O5rbWdOArH04K0-QAAAXA"] [Tue Aug 18 12:59:07.655032 2026] [security2:error] [pid 66623:tid 66827] [client 20.104.85.180:18757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBS9O5rbWdOArH04K0-wAAAUc"] [Tue Aug 18 12:59:07.658009 2026] [security2:error] [pid 66623:tid 66776] [client 158.23.17.4:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/87.php"] [unique_id "aoSBS9O5rbWdOArH04K0_AAAARQ"] [Tue Aug 18 12:59:07.665773 2026] [security2:error] [pid 66623:tid 66824] [client 20.100.169.31:24494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/bless.php"] [unique_id "aoSBS9O5rbWdOArH04K0_QAAAUQ"] [Tue Aug 18 12:59:07.669591 2026] [security2:error] [pid 66623:tid 66738] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/aws-exports.js"] [unique_id "aoSBS9O5rbWdOArH04K0_gABH2U"] [Tue Aug 18 12:59:07.670004 2026] [security2:error] [pid 66623:tid 66829] [client 213.35.127.232:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBS9O5rbWdOArH04K0_wAAAUk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:07.710313 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:07.710582 2026] [authz_core:error] [pid 66623:tid 66733] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:07.716123 2026] [security2:error] [pid 66623:tid 66866] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBS9O5rbWdOArH04K1AQAAAW4"] [Tue Aug 18 12:59:07.735471 2026] [security2:error] [pid 66623:tid 66739] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/aws-config.js"] [unique_id "aoSBS9O5rbWdOArH04K1AgABQmY"] [Tue Aug 18 12:59:07.748098 2026] [security2:error] [pid 66623:tid 66648] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/awsConfig.js"] [unique_id "aoSBS9O5rbWdOArH04K1BAABQQs"] [Tue Aug 18 12:59:07.761183 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/amplifyconfiguration.json"] [unique_id "aoSBS9O5rbWdOArH04K1BQABGyU"] [Tue Aug 18 12:59:07.765467 2026] [security2:error] [pid 66623:tid 66769] [client 172.182.200.96:14112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBS9O5rbWdOArH04K1BgAAAQ0"] [Tue Aug 18 12:59:07.812634 2026] [security2:error] [pid 66623:tid 66795] [client 102.213.179.104:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K1BwAAASc"] [Tue Aug 18 12:59:07.812752 2026] [security2:error] [pid 66623:tid 66795] [client 102.213.179.104:58589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBS9O5rbWdOArH04K1BwAAASc"] [Tue Aug 18 12:59:07.830063 2026] [security2:error] [pid 66623:tid 66823] [client 168.62.48.100:1159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBS9O5rbWdOArH04K1CgAAAUM"] [Tue Aug 18 12:59:07.834483 2026] [security2:error] [pid 66623:tid 66653] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/values.yaml"] [unique_id "aoSBS9O5rbWdOArH04K1CwABXxA"] [Tue Aug 18 12:59:07.838261 2026] [security2:error] [pid 66623:tid 66661] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/wp-json"] [unique_id "aoSBS9O5rbWdOArH04K1DAABHBg"] [Tue Aug 18 12:59:07.877640 2026] [security2:error] [pid 66623:tid 66779] [client 20.25.139.174:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/u.php"] [unique_id "aoSBS9O5rbWdOArH04K1DgAAARc"] [Tue Aug 18 12:59:08.000543 2026] [security2:error] [pid 66623:tid 66689] [remote 203.99.146.53:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoSBS9O5rbWdOArH04K1EwABZjQ"] [Tue Aug 18 12:59:08.002944 2026] [security2:error] [pid 66623:tid 66846] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBTNO5rbWdOArH04K1FQAAAVo"] [Tue Aug 18 12:59:08.035954 2026] [security2:error] [pid 66623:tid 66768] [client 74.7.228.45:57906] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "marcellomeneghel.com.br"] [uri "/robots.txt"] [unique_id "aoSBTNO5rbWdOArH04K1GQABDA8"] [Tue Aug 18 12:59:08.060963 2026] [security2:error] [pid 66623:tid 66836] [client 20.118.172.148:53107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/images/wso.php"] [unique_id "aoSBTNO5rbWdOArH04K1HQAAAVA"] [Tue Aug 18 12:59:08.061421 2026] [security2:error] [pid 66623:tid 66786] [client 132.196.30.78:22168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/chosen.php"] [unique_id "aoSBTNO5rbWdOArH04K1HgAAAR4"] [Tue Aug 18 12:59:08.069087 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/__/firebase/init.json"] [unique_id "aoSBTNO5rbWdOArH04K1IAABRnE"] [Tue Aug 18 12:59:08.081025 2026] [security2:error] [pid 66623:tid 66850] [client 20.25.139.174:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/chosen.php"] [unique_id "aoSBTNO5rbWdOArH04K1IQAAAV4"] [Tue Aug 18 12:59:08.083582 2026] [security2:error] [pid 66623:tid 66816] [client 168.62.48.100:1101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/index/function.php"] [unique_id "aoSBTNO5rbWdOArH04K1IgAAATw"] [Tue Aug 18 12:59:08.085346 2026] [security2:error] [pid 66623:tid 66831] [client 74.248.18.37:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSBTNO5rbWdOArH04K1JAAAAUs"] [Tue Aug 18 12:59:08.123908 2026] [security2:error] [pid 66623:tid 66865] [client 52.173.121.69:30383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1KQAAAW0"] [Tue Aug 18 12:59:08.148127 2026] [security2:error] [pid 66623:tid 66729] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.json"] [unique_id "aoSBTNO5rbWdOArH04K1KgABZVw"] [Tue Aug 18 12:59:08.154012 2026] [security2:error] [pid 66623:tid 66803] [client 52.173.121.69:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBTNO5rbWdOArH04K1KwAAAS8"] [Tue Aug 18 12:59:08.155322 2026] [security2:error] [pid 66623:tid 66873] [client 158.23.17.4:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zi.php"] [unique_id "aoSBTNO5rbWdOArH04K1LAAAAXU"] [Tue Aug 18 12:59:08.155507 2026] [security2:error] [pid 66623:tid 66843] [client 40.74.65.169:20355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/puc.php"] [unique_id "aoSBTNO5rbWdOArH04K1LQAAAVc"] [Tue Aug 18 12:59:08.184440 2026] [security2:error] [pid 66623:tid 66673] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/config"] [unique_id "aoSBTNO5rbWdOArH04K1LgABSCQ"] [Tue Aug 18 12:59:08.184440 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/config.js"] [unique_id "aoSBTNO5rbWdOArH04K1LwABSDA"] [Tue Aug 18 12:59:08.187910 2026] [security2:error] [pid 66623:tid 66772] [client 20.104.85.180:18765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBTNO5rbWdOArH04K1MAAAARA"] [Tue Aug 18 12:59:08.192021 2026] [security2:error] [pid 66623:tid 66882] [client 132.196.30.78:14999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/goods.php"] [unique_id "aoSBTNO5rbWdOArH04K1MQAAAX4"] [Tue Aug 18 12:59:08.196382 2026] [security2:error] [pid 66623:tid 66800] [client 68.221.73.131:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/mac.php"] [unique_id "aoSBTNO5rbWdOArH04K1MwAAASw"] [Tue Aug 18 12:59:08.262644 2026] [security2:error] [pid 66623:tid 66829] [client 4.232.151.198:30038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/xmlrpc.php0"] [unique_id "aoSBTNO5rbWdOArH04K1NQAAAUk"] [Tue Aug 18 12:59:08.266884 2026] [security2:error] [pid 66623:tid 66725] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/settings.json"] [unique_id "aoSBTNO5rbWdOArH04K1NwABZFg"] [Tue Aug 18 12:59:08.282578 2026] [security2:error] [pid 66623:tid 66822] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/output.php"] [unique_id "aoSBTNO5rbWdOArH04K1OQAAAUI"] [Tue Aug 18 12:59:08.319953 2026] [security2:error] [pid 66623:tid 66812] [client 20.104.85.180:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/file.php"] [unique_id "aoSBTNO5rbWdOArH04K1OwAAATg"] [Tue Aug 18 12:59:08.346518 2026] [security2:error] [pid 66623:tid 66848] [client 168.62.48.100:1104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBTNO5rbWdOArH04K1PgAAAVw"] [Tue Aug 18 12:59:08.350415 2026] [security2:error] [pid 66623:tid 66890] [client 20.203.138.185:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/166.php"] [unique_id "aoSBTNO5rbWdOArH04K1PwAAAYY"] [Tue Aug 18 12:59:08.379377 2026] [security2:error] [pid 66623:tid 66796] [client 20.25.139.174:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBTNO5rbWdOArH04K1QwAAASg"] [Tue Aug 18 12:59:08.441968 2026] [security2:error] [pid 66623:tid 66732] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/settings"] [unique_id "aoSBTNO5rbWdOArH04K1ZQABN18"] [Tue Aug 18 12:59:08.459640 2026] [security2:error] [pid 66623:tid 66698] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBTNO5rbWdOArH04K1ZwABbz0"] [Tue Aug 18 12:59:08.561903 2026] [security2:error] [pid 66623:tid 66768] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/tiny2.php"] [unique_id "aoSBTNO5rbWdOArH04K1dQAAAQw"] [Tue Aug 18 12:59:08.576441 2026] [security2:error] [pid 66623:tid 66767] [client 20.25.139.174:4643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1dwAAAQs"] [Tue Aug 18 12:59:08.579392 2026] [security2:error] [pid 66623:tid 66840] [client 132.196.30.78:22147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1eAAAAVQ"] [Tue Aug 18 12:59:08.584962 2026] [security2:error] [pid 66623:tid 66844] [client 52.173.121.69:14566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1egAAAVg"] [Tue Aug 18 12:59:08.615949 2026] [security2:error] [pid 66623:tid 66747] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/env.js"] [unique_id "aoSBTNO5rbWdOArH04K1ewABdm4"] [Tue Aug 18 12:59:08.625528 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:08.625830 2026] [authz_core:error] [pid 66623:tid 66764] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:08.632747 2026] [security2:error] [pid 66623:tid 66649] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/firebase-config.json"] [unique_id "aoSBTNO5rbWdOArH04K1fgABXQw"] [Tue Aug 18 12:59:08.635397 2026] [security2:error] [pid 66623:tid 66677] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/env.json"] [unique_id "aoSBTNO5rbWdOArH04K1fwABbSg"] [Tue Aug 18 12:59:08.649399 2026] [security2:error] [pid 66623:tid 66832] [client 20.118.172.148:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/index/function.php"] [unique_id "aoSBTNO5rbWdOArH04K1gQAAAUw"] [Tue Aug 18 12:59:08.658125 2026] [security2:error] [pid 66623:tid 66675] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/.well-known/jwks.json"] [unique_id "aoSBTNO5rbWdOArH04K1gwABWyY"] [Tue Aug 18 12:59:08.686895 2026] [security2:error] [pid 66623:tid 66785] [client 213.35.127.232:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBTNO5rbWdOArH04K1hQAAAR0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:08.707775 2026] [security2:error] [pid 66623:tid 66781] [client 168.62.48.100:1026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/Cachex.php"] [unique_id "aoSBTNO5rbWdOArH04K1iAAAARk"] [Tue Aug 18 12:59:08.737393 2026] [security2:error] [pid 66623:tid 66893] [client 132.196.30.78:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/file.php"] [unique_id "aoSBTNO5rbWdOArH04K1igAAAYk"] [Tue Aug 18 12:59:08.744440 2026] [security2:error] [pid 66623:tid 66716] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v2/config"] [unique_id "aoSBTNO5rbWdOArH04K1jAABOU8"] [Tue Aug 18 12:59:08.761893 2026] [security2:error] [pid 66623:tid 66752] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v1/config"] [unique_id "aoSBTNO5rbWdOArH04K1jQABRHM"] [Tue Aug 18 12:59:08.798571 2026] [security2:error] [pid 66623:tid 66839] [client 47.128.99.181:65228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elitepaintball.com.br"] [uri "/robots.txt"] [unique_id "aoSBTNO5rbWdOArH04K1jgAAAVM"] [Tue Aug 18 12:59:08.851327 2026] [security2:error] [pid 66623:tid 66810] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wpxml.php"] [unique_id "aoSBTNO5rbWdOArH04K1lQAAATY"] [Tue Aug 18 12:59:08.859454 2026] [security2:error] [pid 66623:tid 66821] [client 52.173.121.69:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBTNO5rbWdOArH04K1lgAAAUE"] [Tue Aug 18 12:59:08.899363 2026] [security2:error] [pid 66623:tid 66873] [client 4.232.151.198:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gotap.cc"] [uri "/wp-admin/maint/item.php"] [unique_id "aoSBTNO5rbWdOArH04K1mAAAAXU"] [Tue Aug 18 12:59:08.901505 2026] [security2:error] [pid 66623:tid 66735] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/env"] [unique_id "aoSBTNO5rbWdOArH04K1mQABNGI"] [Tue Aug 18 12:59:08.903214 2026] [security2:error] [pid 66623:tid 66726] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/runtime-config.js"] [unique_id "aoSBTNO5rbWdOArH04K1mgABG1k"] [Tue Aug 18 12:59:08.909015 2026] [security2:error] [pid 66623:tid 66705] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/v2/settings"] [unique_id "aoSBTNO5rbWdOArH04K1mwABDUQ"] [Tue Aug 18 12:59:08.917778 2026] [security2:error] [pid 66623:tid 66802] [client 20.25.139.174:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/h.php"] [unique_id "aoSBTNO5rbWdOArH04K1nAAAAS4"] [Tue Aug 18 12:59:08.926839 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:08.927090 2026] [authz_core:error] [pid 66623:tid 66687] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:08.940579 2026] [security2:error] [pid 66623:tid 66745] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/manifest.webmanifest"] [unique_id "aoSBTNO5rbWdOArH04K1oAABY2w"] [Tue Aug 18 12:59:08.970080 2026] [security2:error] [pid 66623:tid 66843] [client 4.232.94.69:20784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/radio.php"] [unique_id "aoSBTNO5rbWdOArH04K1owAAAVc"] [Tue Aug 18 12:59:08.986027 2026] [security2:error] [pid 66623:tid 66829] [client 79.127.164.8:41498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/sql.sql"] [unique_id "aoSBTNO5rbWdOArH04K1rwAAAUk"], referer: https://medihub.com.br/sql.sql [Tue Aug 18 12:59:08.995080 2026] [security2:error] [pid 66623:tid 66809] [client 172.202.39.151:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/about.php"] [unique_id "aoSBTNO5rbWdOArH04K1sAAAATU"] [Tue Aug 18 12:59:09.017612 2026] [security2:error] [pid 66623:tid 66743] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/openapi.json"] [unique_id "aoSBTdO5rbWdOArH04K1swABg2o"] [Tue Aug 18 12:59:09.018250 2026] [autoindex:error] [pid 66623:tid 66838] [client 3.210.118.109:55408] AH01276: Cannot serve directory /home1/agencialkx/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:09.026763 2026] [security2:error] [pid 66623:tid 66674] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/openapi.json"] [unique_id "aoSBTdO5rbWdOArH04K1tQABeSU"] [Tue Aug 18 12:59:09.035870 2026] [security2:error] [pid 66623:tid 66868] [client 20.100.169.31:15204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/sagax1.php"] [unique_id "aoSBTdO5rbWdOArH04K1tgAAAXA"] [Tue Aug 18 12:59:09.039876 2026] [security2:error] [pid 66623:tid 66798] [client 20.104.85.180:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/epinyins.php"] [unique_id "aoSBTdO5rbWdOArH04K1twAAASo"] [Tue Aug 18 12:59:09.047387 2026] [security2:error] [pid 66623:tid 66867] [client 52.173.121.69:42719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBTdO5rbWdOArH04K1uAAAAW8"] [Tue Aug 18 12:59:09.059314 2026] [security2:error] [pid 66623:tid 66833] [client 168.62.48.100:1028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBTdO5rbWdOArH04K1uQAAAU0"] [Tue Aug 18 12:59:09.082484 2026] [security2:error] [pid 66623:tid 66892] [client 172.202.39.151:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cc.php"] [unique_id "aoSBTdO5rbWdOArH04K1uwAAAYg"] [Tue Aug 18 12:59:09.097088 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/abc.php"] [unique_id "aoSBTdO5rbWdOArH04K1vAAAATE"] [Tue Aug 18 12:59:09.139049 2026] [security2:error] [pid 66623:tid 66789] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBTdO5rbWdOArH04K1wgAAASE"] [Tue Aug 18 12:59:09.143149 2026] [security2:error] [pid 66623:tid 66788] [client 132.196.30.78:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/vx.php"] [unique_id "aoSBTdO5rbWdOArH04K1wwAAASA"] [Tue Aug 18 12:59:09.176255 2026] [security2:error] [pid 66623:tid 66768] [client 20.203.138.185:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/snq.php"] [unique_id "aoSBTdO5rbWdOArH04K1xQAAAQw"] [Tue Aug 18 12:59:09.187894 2026] [security2:error] [pid 66623:tid 66823] [client 20.25.139.174:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/vx.php"] [unique_id "aoSBTdO5rbWdOArH04K1yAAAAUM"] [Tue Aug 18 12:59:09.230832 2026] [security2:error] [pid 66623:tid 66778] [client 20.215.241.237:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/aa.php"] [unique_id "aoSBTdO5rbWdOArH04K1zwAAARY"] [Tue Aug 18 12:59:09.234233 2026] [security2:error] [pid 66623:tid 66652] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/app-config.json"] [unique_id "aoSBTdO5rbWdOArH04K10AABdg8"] [Tue Aug 18 12:59:09.234536 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:09.234804 2026] [authz_core:error] [pid 66623:tid 66699] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:09.249030 2026] [security2:error] [pid 66623:tid 66707] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/account"] [unique_id "aoSBTdO5rbWdOArH04K10QABWUY"] [Tue Aug 18 12:59:09.267329 2026] [security2:error] [pid 66623:tid 66750] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/api/health"] [unique_id "aoSBTdO5rbWdOArH04K10gABTHE"] [Tue Aug 18 12:59:09.303026 2026] [security2:error] [pid 66623:tid 66794] [client 168.62.48.100:1114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBTdO5rbWdOArH04K11gAAASY"] [Tue Aug 18 12:59:09.306805 2026] [security2:error] [pid 66623:tid 66880] [client 132.196.30.78:15016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBTdO5rbWdOArH04K11wAAAXw"] [Tue Aug 18 12:59:09.310002 2026] [security2:error] [pid 66623:tid 66659] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/health"] [unique_id "aoSBTdO5rbWdOArH04K12AABLxY"] [Tue Aug 18 12:59:09.365751 2026] [security2:error] [pid 66623:tid 66759] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/swagger.json"] [unique_id "aoSBTdO5rbWdOArH04K12gABMno"] [Tue Aug 18 12:59:09.381411 2026] [security2:error] [pid 66623:tid 66685] [remote 34.158.8.33:52872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "acpecasebaterias.com.br"] [uri "/__env.js"] [unique_id "aoSBTdO5rbWdOArH04K12wABLDA"] [Tue Aug 18 12:59:09.407635 2026] [security2:error] [pid 66623:tid 66865] [client 20.25.139.174:4644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBTdO5rbWdOArH04K13gAAAW0"] [Tue Aug 18 12:59:09.438009 2026] [security2:error] [pid 66623:tid 66886] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ccou.php"] [unique_id "aoSBTdO5rbWdOArH04K14AAAAYI"] [Tue Aug 18 12:59:09.472792 2026] [security2:error] [pid 66623:tid 66856] [client 20.65.98.162:32258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/coffee.php"] [unique_id "aoSBTdO5rbWdOArH04K14gAAAWQ"] [Tue Aug 18 12:59:09.485183 2026] [security2:error] [pid 66623:tid 66842] [client 74.248.18.37:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTdO5rbWdOArH04K15AAAAVY"] [Tue Aug 18 12:59:09.513268 2026] [security2:error] [pid 66623:tid 66853] [client 40.74.65.169:20117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/8.php"] [unique_id "aoSBTdO5rbWdOArH04K15gAAAWE"] [Tue Aug 18 12:59:09.521685 2026] [security2:error] [pid 66623:tid 66810] [client 52.173.121.69:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBTdO5rbWdOArH04K15wAAATY"] [Tue Aug 18 12:59:09.583604 2026] [security2:error] [pid 66623:tid 66777] [client 168.62.48.100:1110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBTdO5rbWdOArH04K16wAAARU"] [Tue Aug 18 12:59:09.592214 2026] [security2:error] [pid 66623:tid 66890] [client 52.173.121.69:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBTdO5rbWdOArH04K17AAAAYY"] [Tue Aug 18 12:59:09.671176 2026] [security2:error] [pid 66623:tid 66850] [client 158.23.17.4:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/92.php"] [unique_id "aoSBTdO5rbWdOArH04K18QAAAV4"] [Tue Aug 18 12:59:09.674822 2026] [security2:error] [pid 66623:tid 66851] [client 172.182.200.96:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBTdO5rbWdOArH04K18gAAAV8"] [Tue Aug 18 12:59:09.695841 2026] [security2:error] [pid 66623:tid 66784] [client 20.118.172.148:2740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/info.php"] [unique_id "aoSBTdO5rbWdOArH04K18wAAARw"] [Tue Aug 18 12:59:09.703950 2026] [security2:error] [pid 66623:tid 66828] [client 213.35.127.232:59358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBTdO5rbWdOArH04K19AAAAUg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:09.720831 2026] [security2:error] [pid 66623:tid 66811] [client 20.104.85.180:14534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/akcc.php"] [unique_id "aoSBTdO5rbWdOArH04K19QAAATc"] [Tue Aug 18 12:59:09.725875 2026] [security2:error] [pid 66623:tid 66790] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/crgio.php"] [unique_id "aoSBTdO5rbWdOArH04K1-AAAASI"] [Tue Aug 18 12:59:09.761191 2026] [security2:error] [pid 66623:tid 66814] [client 20.104.85.180:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTdO5rbWdOArH04K1-wAAATo"] [Tue Aug 18 12:59:09.836005 2026] [authz_core:error] [pid 66623:tid 66681] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:09.836263 2026] [authz_core:error] [pid 66623:tid 66681] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:09.874981 2026] [security2:error] [pid 66623:tid 66885] [client 20.250.13.23:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/min.php"] [unique_id "aoSBTdO5rbWdOArH04K2AQAAAYE"] [Tue Aug 18 12:59:09.882188 2026] [autoindex:error] [pid 66623:tid 66639] [remote 20.65.98.162:0] AH01276: Cannot serve directory /home4/tecpolo/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:09.904599 2026] [security2:error] [pid 66623:tid 66788] [client 168.62.48.100:1182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBTdO5rbWdOArH04K2AwAAASA"] [Tue Aug 18 12:59:09.949831 2026] [security2:error] [pid 66623:tid 66867] [client 20.25.139.174:4711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/a7.php"] [unique_id "aoSBTdO5rbWdOArH04K2BQAAAW8"] [Tue Aug 18 12:59:09.955754 2026] [security2:error] [pid 66623:tid 66798] [client 132.196.30.78:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/404.php"] [unique_id "aoSBTdO5rbWdOArH04K2BgAAASo"] [Tue Aug 18 12:59:09.969322 2026] [security2:error] [pid 66623:tid 66780] [client 52.173.121.69:47308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/update/wpupex.php"] [unique_id "aoSBTdO5rbWdOArH04K2CAAAARg"] [Tue Aug 18 12:59:10.012517 2026] [security2:error] [pid 66623:tid 66796] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBTtO5rbWdOArH04K2CgAAASg"] [Tue Aug 18 12:59:10.016937 2026] [security2:error] [pid 66623:tid 66826] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/php.php"] [unique_id "aoSBTtO5rbWdOArH04K2CwAAAUY"] [Tue Aug 18 12:59:10.111917 2026] [security2:error] [pid 66623:tid 66849] [client 52.173.121.69:6062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.oscarasdodrone.com.br"] [uri "/images/security.php"] [unique_id "aoSBTtO5rbWdOArH04K2DwAAAV0"] [Tue Aug 18 12:59:10.136038 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:10.136290 2026] [authz_core:error] [pid 66623:tid 66748] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:10.140445 2026] [security2:error] [pid 66623:tid 66768] [client 74.248.18.37:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSBTtO5rbWdOArH04K2EgAAAQw"] [Tue Aug 18 12:59:10.175546 2026] [security2:error] [pid 66623:tid 66857] [client 20.203.138.185:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-access.php"] [unique_id "aoSBTtO5rbWdOArH04K2EwAAAWU"] [Tue Aug 18 12:59:10.204329 2026] [security2:error] [pid 66623:tid 66880] [client 40.74.65.169:38789] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "maisautoveiculo.com.br"] [uri "/1.php"] [unique_id "aoSBTtO5rbWdOArH04K2FAAAAXw"] [Tue Aug 18 12:59:10.204457 2026] [security2:error] [pid 66623:tid 66880] [client 40.74.65.169:38789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/1.php"] [unique_id "aoSBTtO5rbWdOArH04K2FAAAAXw"] [Tue Aug 18 12:59:10.220107 2026] [security2:error] [pid 66623:tid 66785] [client 168.62.48.100:1118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2FgAAAR0"] [Tue Aug 18 12:59:10.270751 2026] [security2:error] [pid 66623:tid 66806] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/sf.php"] [unique_id "aoSBTtO5rbWdOArH04K2GAAAATI"] [Tue Aug 18 12:59:10.280201 2026] [security2:error] [pid 66623:tid 66889] [client 158.23.17.4:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jm.php"] [unique_id "aoSBTtO5rbWdOArH04K2GQAAAYU"] [Tue Aug 18 12:59:10.328468 2026] [security2:error] [pid 66623:tid 66772] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/css.php"] [unique_id "aoSBTtO5rbWdOArH04K2HAAAARA"] [Tue Aug 18 12:59:10.329408 2026] [security2:error] [pid 66623:tid 66813] [client 20.118.172.148:46757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/profile.php"] [unique_id "aoSBTtO5rbWdOArH04K2HQAAATk"] [Tue Aug 18 12:59:10.373540 2026] [security2:error] [pid 66623:tid 66875] [client 52.173.121.69:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBTtO5rbWdOArH04K2HwAAAXc"] [Tue Aug 18 12:59:10.409379 2026] [security2:error] [pid 66623:tid 66797] [client 20.104.85.180:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wk/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2IwAAASk"] [Tue Aug 18 12:59:10.498262 2026] [security2:error] [pid 66623:tid 66821] [client 168.62.48.100:1109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2KwAAAUE"] [Tue Aug 18 12:59:10.501750 2026] [security2:error] [pid 66623:tid 66766] [client 4.232.94.69:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBTtO5rbWdOArH04K2LAAAAQo"] [Tue Aug 18 12:59:10.522808 2026] [security2:error] [pid 66623:tid 66769] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/xx.php"] [unique_id "aoSBTtO5rbWdOArH04K2LQAAAQ0"] [Tue Aug 18 12:59:10.531065 2026] [security2:error] [pid 66623:tid 66859] [client 172.202.39.151:4732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2LgAAAWc"] [Tue Aug 18 12:59:10.544857 2026] [security2:error] [pid 66623:tid 66776] [client 20.25.139.174:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/manager.php"] [unique_id "aoSBTtO5rbWdOArH04K2MAAAARQ"] [Tue Aug 18 12:59:10.615338 2026] [security2:error] [pid 66623:tid 66871] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2MgAAAXM"] [Tue Aug 18 12:59:10.704473 2026] [security2:error] [pid 66623:tid 66884] [client 132.196.30.78:13688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wk/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2NgAAAYA"] [Tue Aug 18 12:59:10.718706 2026] [security2:error] [pid 66623:tid 66787] [client 213.35.127.232:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBTtO5rbWdOArH04K2OAAAAR8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:10.772533 2026] [security2:error] [pid 66623:tid 66861] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/uwu.php"] [unique_id "aoSBTtO5rbWdOArH04K2OgAAAWk"] [Tue Aug 18 12:59:10.816898 2026] [security2:error] [pid 66623:tid 66801] [client 172.182.200.96:14118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBTtO5rbWdOArH04K2OwAAAS0"] [Tue Aug 18 12:59:10.825653 2026] [security2:error] [pid 66623:tid 66881] [client 74.248.18.37:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSBTtO5rbWdOArH04K2PAAAAX0"] [Tue Aug 18 12:59:10.856655 2026] [security2:error] [pid 66623:tid 66789] [client 52.173.121.69:48315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2QAAAASE"] [Tue Aug 18 12:59:10.873425 2026] [security2:error] [pid 66623:tid 66870] [client 132.196.30.78:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wap.php"] [unique_id "aoSBTtO5rbWdOArH04K2QwAAAXI"] [Tue Aug 18 12:59:10.884307 2026] [security2:error] [pid 66623:tid 66786] [client 45.131.195.97:22149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alltimeadm.com.br"] [uri "/wp-login.php"] [unique_id "aoSBTtO5rbWdOArH04K2NwAAAR4"] [Tue Aug 18 12:59:10.888259 2026] [security2:error] [pid 66623:tid 66788] [client 40.74.65.169:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/about.php"] [unique_id "aoSBTtO5rbWdOArH04K2RAAAASA"] [Tue Aug 18 12:59:10.900441 2026] [security2:error] [pid 66623:tid 66869] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/epinyins.php"] [unique_id "aoSBTtO5rbWdOArH04K2RgAAAXE"] [Tue Aug 18 12:59:10.906067 2026] [security2:error] [pid 66623:tid 66780] [client 20.25.139.174:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wap.php"] [unique_id "aoSBTtO5rbWdOArH04K2SAAAARg"] [Tue Aug 18 12:59:10.925954 2026] [security2:error] [pid 66623:tid 66891] [client 168.62.48.100:1197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBTtO5rbWdOArH04K2SQAAAYc"] [Tue Aug 18 12:59:10.972541 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:15691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nw.php"] [unique_id "aoSBTtO5rbWdOArH04K2SwAAARY"] [Tue Aug 18 12:59:11.029152 2026] [security2:error] [pid 66623:tid 66812] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/signon.php"] [unique_id "aoSBT9O5rbWdOArH04K2TQAAATg"] [Tue Aug 18 12:59:11.037012 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:11.037268 2026] [authz_core:error] [pid 66623:tid 66732] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:11.048125 2026] [security2:error] [pid 66623:tid 66830] [client 196.12.128.158:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2TwAAAUo"] [Tue Aug 18 12:59:11.048279 2026] [security2:error] [pid 66623:tid 66830] [client 196.12.128.158:61617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2TwAAAUo"] [Tue Aug 18 12:59:11.148742 2026] [security2:error] [pid 66623:tid 66826] [client 20.25.139.174:4557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/w1.php"] [unique_id "aoSBT9O5rbWdOArH04K2VgAAAUY"] [Tue Aug 18 12:59:11.172090 2026] [security2:error] [pid 66623:tid 66824] [client 20.118.172.148:43489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/sx.php"] [unique_id "aoSBT9O5rbWdOArH04K2VwAAAUQ"] [Tue Aug 18 12:59:11.205336 2026] [security2:error] [pid 66623:tid 66779] [client 172.182.200.96:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBT9O5rbWdOArH04K2WQAAARc"] [Tue Aug 18 12:59:11.258025 2026] [security2:error] [pid 66623:tid 66810] [client 168.62.48.100:1194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBT9O5rbWdOArH04K2XQAAATY"] [Tue Aug 18 12:59:11.296685 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:28634] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/1.php"] [unique_id "aoSBT9O5rbWdOArH04K2XgAAAUE"] [Tue Aug 18 12:59:11.296760 2026] [security2:error] [pid 66623:tid 66766] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file61.php"] [unique_id "aoSBT9O5rbWdOArH04K2XwAAAQo"] [Tue Aug 18 12:59:11.296788 2026] [security2:error] [pid 66623:tid 66821] [client 20.104.85.180:28634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/1.php"] [unique_id "aoSBT9O5rbWdOArH04K2XgAAAUE"] [Tue Aug 18 12:59:11.312456 2026] [security2:error] [pid 66623:tid 66769] [client 158.23.17.4:7193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wj.php"] [unique_id "aoSBT9O5rbWdOArH04K2YQAAAQ0"] [Tue Aug 18 12:59:11.323191 2026] [security2:error] [pid 66623:tid 66859] [client 52.173.121.69:48270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2YwAAAWc"] [Tue Aug 18 12:59:11.339894 2026] [security2:error] [pid 66623:tid 66777] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/load.php"] [unique_id "aoSBT9O5rbWdOArH04K2ZgAAARU"] [Tue Aug 18 12:59:11.340272 2026] [authz_core:error] [pid 66623:tid 66709] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:11.340651 2026] [authz_core:error] [pid 66623:tid 66709] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:11.378501 2026] [security2:error] [pid 66623:tid 66813] [client 132.196.30.78:21967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/about.php"] [unique_id "aoSBT9O5rbWdOArH04K2aQAAATk"] [Tue Aug 18 12:59:11.399180 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBT9O5rbWdOArH04K2bAAAAT8"] [Tue Aug 18 12:59:11.436895 2026] [security2:error] [pid 66623:tid 66846] [client 197.184.64.235:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2bgAAAVo"] [Tue Aug 18 12:59:11.437035 2026] [security2:error] [pid 66623:tid 66846] [client 197.184.64.235:41948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2bgAAAVo"] [Tue Aug 18 12:59:11.491072 2026] [security2:error] [pid 66623:tid 66856] [client 132.196.30.78:13691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBT9O5rbWdOArH04K2cQAAAWQ"] [Tue Aug 18 12:59:11.491097 2026] [security2:error] [pid 66623:tid 66817] [client 74.248.18.37:25341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSBT9O5rbWdOArH04K2cgAAAT0"] [Tue Aug 18 12:59:11.546849 2026] [security2:error] [pid 66623:tid 66805] [client 20.104.85.180:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2dAAAATE"] [Tue Aug 18 12:59:11.561117 2026] [security2:error] [pid 66623:tid 66771] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/copypaths.php"] [unique_id "aoSBT9O5rbWdOArH04K2dQAAAQ8"] [Tue Aug 18 12:59:11.597238 2026] [security2:error] [pid 66623:tid 66788] [client 40.74.65.169:19508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBT9O5rbWdOArH04K2eAAAASA"] [Tue Aug 18 12:59:11.601496 2026] [security2:error] [pid 66623:tid 66867] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env"] [unique_id "aoSBT9O5rbWdOArH04K2eQAAAW8"] [Tue Aug 18 12:59:11.616043 2026] [security2:error] [pid 66623:tid 66798] [client 172.182.200.96:7642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBT9O5rbWdOArH04K2egAAASo"] [Tue Aug 18 12:59:11.631033 2026] [security2:error] [pid 66623:tid 66780] [client 168.62.48.100:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBT9O5rbWdOArH04K2ewAAARg"] [Tue Aug 18 12:59:11.641574 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:11.641915 2026] [authz_core:error] [pid 66623:tid 66640] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:11.642511 2026] [security2:error] [pid 66623:tid 66811] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBT9O5rbWdOArH04K2fQAAATc"] [Tue Aug 18 12:59:11.658955 2026] [security2:error] [pid 66623:tid 66770] [client 52.173.121.69:14571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBT9O5rbWdOArH04K2fwAAAQ4"] [Tue Aug 18 12:59:11.673499 2026] [security2:error] [pid 66623:tid 66778] [client 20.203.138.185:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws62.php"] [unique_id "aoSBT9O5rbWdOArH04K2gwAAARY"] [Tue Aug 18 12:59:11.713602 2026] [security2:error] [pid 66623:tid 66849] [client 172.202.39.151:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/f35.php"] [unique_id "aoSBT9O5rbWdOArH04K2hAAAAV0"] [Tue Aug 18 12:59:11.733858 2026] [security2:error] [pid 66623:tid 66809] [client 213.35.127.232:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2iAAAATU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:11.797326 2026] [security2:error] [pid 66623:tid 66773] [client 20.100.169.31:39058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2iwAAARE"] [Tue Aug 18 12:59:11.841153 2026] [security2:error] [pid 66623:tid 66785] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bless6.php"] [unique_id "aoSBT9O5rbWdOArH04K2jQAAAR0"] [Tue Aug 18 12:59:11.852424 2026] [security2:error] [pid 66623:tid 66835] [client 157.51.166.53:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2jwAAAU8"] [Tue Aug 18 12:59:11.852523 2026] [security2:error] [pid 66623:tid 66835] [client 157.51.166.53:55417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2jwAAAU8"] [Tue Aug 18 12:59:11.877196 2026] [security2:error] [pid 66623:tid 66827] [client 20.65.98.162:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBT9O5rbWdOArH04K2kAAAAUc"] [Tue Aug 18 12:59:11.898709 2026] [security2:error] [pid 66623:tid 66875] [client 158.23.17.4:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/74.php"] [unique_id "aoSBT9O5rbWdOArH04K2kgAAAXc"] [Tue Aug 18 12:59:11.903868 2026] [security2:error] [pid 66623:tid 66854] [client 20.25.139.174:4638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bgymj.php"] [unique_id "aoSBT9O5rbWdOArH04K2kwAAAWI"] [Tue Aug 18 12:59:11.929240 2026] [security2:error] [pid 66623:tid 66839] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.bak"] [unique_id "aoSBT9O5rbWdOArH04K2lQAAAVM"] [Tue Aug 18 12:59:11.944582 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:11.945053 2026] [authz_core:error] [pid 66623:tid 66677] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:11.954144 2026] [security2:error] [pid 66623:tid 66824] [client 192.141.172.134:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2mQAAAUQ"] [Tue Aug 18 12:59:11.955855 2026] [security2:error] [pid 66623:tid 66824] [client 192.141.172.134:53131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBT9O5rbWdOArH04K2mQAAAUQ"] [Tue Aug 18 12:59:11.977520 2026] [security2:error] [pid 66623:tid 66783] [client 168.62.48.100:1117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBT9O5rbWdOArH04K2mwAAARs"] [Tue Aug 18 12:59:12.045795 2026] [security2:error] [pid 66623:tid 66840] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ty.php"] [unique_id "aoSBUNO5rbWdOArH04K2oAAAAVQ"] [Tue Aug 18 12:59:12.099752 2026] [security2:error] [pid 66623:tid 66813] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/special.php"] [unique_id "aoSBUNO5rbWdOArH04K2oQAAATk"] [Tue Aug 18 12:59:12.104573 2026] [security2:error] [pid 66623:tid 66851] [client 52.173.121.69:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/well-known/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2ogAAAV8"] [Tue Aug 18 12:59:12.137164 2026] [security2:error] [pid 66623:tid 66828] [client 66.187.6.102:57610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.backup"] [unique_id "aoSBUNO5rbWdOArH04K2pgAAAUg"] [Tue Aug 18 12:59:12.141918 2026] [security2:error] [pid 66623:tid 66772] [client 132.196.30.78:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bgymj.php"] [unique_id "aoSBUNO5rbWdOArH04K2pwAAARA"] [Tue Aug 18 12:59:12.152197 2026] [security2:error] [pid 66623:tid 66846] [client 20.104.85.180:19733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2qQAAAVo"] [Tue Aug 18 12:59:12.210059 2026] [security2:error] [pid 66623:tid 66794] [client 132.196.30.78:15028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/term.php"] [unique_id "aoSBUNO5rbWdOArH04K2rAAAASY"] [Tue Aug 18 12:59:12.242937 2026] [authz_core:error] [pid 66623:tid 66722] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:12.243192 2026] [authz_core:error] [pid 66623:tid 66722] [remote 216.73.216.206:28729] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:12.253038 2026] [security2:error] [pid 66623:tid 66817] [client 168.62.48.100:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBUNO5rbWdOArH04K2rgAAAT0"] [Tue Aug 18 12:59:12.317014 2026] [security2:error] [pid 66623:tid 66819] [client 20.25.139.174:4663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-login.php"] [unique_id "aoSBUNO5rbWdOArH04K2rwAAAT8"] [Tue Aug 18 12:59:12.973024 2026] [security2:error] [pid 66623:tid 66871] [client 4.232.94.69:36320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBUNO5rbWdOArH04K2swAAAXM"] [Tue Aug 18 12:59:13.047266 2026] [http2:info] [pid 123784:tid 123784] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 12:59:13.069381 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/edit.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcBwAAAAA"] [Tue Aug 18 12:59:13.070421 2026] [security2:error] [pid 123784:tid 123920] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCAAAAAI"] [Tue Aug 18 12:59:13.070833 2026] [security2:error] [pid 123784:tid 123922] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/fz.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCQAAAAQ"] [Tue Aug 18 12:59:13.071491 2026] [security2:error] [pid 123784:tid 123924] [client 158.23.17.4:15790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/av.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCgAAAAY"] [Tue Aug 18 12:59:13.071953 2026] [security2:error] [pid 123784:tid 123928] [client 168.62.48.100:1269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcCwAAAAo"] [Tue Aug 18 12:59:13.072964 2026] [security2:error] [pid 123784:tid 123930] [client 172.202.39.151:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDAAAAAw"] [Tue Aug 18 12:59:13.073335 2026] [security2:error] [pid 123784:tid 123927] [client 52.173.121.69:50282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDQAAAAk"] [Tue Aug 18 12:59:13.073345 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.85.180:35893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDgAAAA4"] [Tue Aug 18 12:59:13.073624 2026] [security2:error] [pid 123784:tid 123934] [client 20.203.138.185:15472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/vx.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcDwAAABA"] [Tue Aug 18 12:59:13.172170 2026] [security2:error] [pid 123784:tid 123960] [client 20.104.85.180:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcFAAAACo"] [Tue Aug 18 12:59:13.227911 2026] [security2:error] [pid 123784:tid 123946] [client 132.196.30.78:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJAAAABw"] [Tue Aug 18 12:59:13.232425 2026] [security2:error] [pid 123784:tid 123937] [client 132.196.30.78:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/aa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJgAAABM"] [Tue Aug 18 12:59:13.271478 2026] [security2:error] [pid 123784:tid 123926] [client 20.25.139.174:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/aa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcJwAAAAg"] [Tue Aug 18 12:59:13.278155 2026] [security2:error] [pid 123784:tid 123945] [client 20.25.139.174:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/default.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcKQAAABs"] [Tue Aug 18 12:59:13.323401 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:25305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcKwAAAB4"] [Tue Aug 18 12:59:13.374010 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dot.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcMAAAAEI"] [Tue Aug 18 12:59:13.375088 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcMwAAAEM"] [Tue Aug 18 12:59:13.376826 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNAAAAEQ"] [Tue Aug 18 12:59:13.377981 2026] [security2:error] [pid 123784:tid 123988] [client 52.173.121.69:12218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNQAAAEY"] [Tue Aug 18 12:59:13.395576 2026] [security2:error] [pid 123784:tid 123994] [client 20.215.241.237:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/img.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcNwAAAEw"] [Tue Aug 18 12:59:13.415305 2026] [security2:error] [pid 123784:tid 123933] [client 213.35.127.232:60048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcOwAAAA8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:13.424493 2026] [security2:error] [pid 123784:tid 123935] [client 20.100.169.31:25978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/fone1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcPgAAABE"] [Tue Aug 18 12:59:13.424944 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:13.425365 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:13.428855 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:13.429245 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:13.473017 2026] [security2:error] [pid 123784:tid 123935] [client 192.141.172.134:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcQgAAABE"] [Tue Aug 18 12:59:13.473189 2026] [security2:error] [pid 123784:tid 123935] [client 192.141.172.134:53376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcQgAAABE"] [Tue Aug 18 12:59:13.525102 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:13.525561 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:13.529995 2026] [security2:error] [pid 123784:tid 123943] [client 86.120.159.145:10515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcSwAAABk"] [Tue Aug 18 12:59:13.530192 2026] [security2:error] [pid 123784:tid 123943] [client 86.120.159.145:10515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcSwAAABk"] [Tue Aug 18 12:59:13.571733 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcTQAAAHY"] [Tue Aug 18 12:59:13.662195 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUAAAABo"] [Tue Aug 18 12:59:13.663583 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/005.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUQAAACc"] [Tue Aug 18 12:59:13.776614 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:13686] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUgAAAHE"] [Tue Aug 18 12:59:13.776794 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcUgAAAHE"] [Tue Aug 18 12:59:13.780437 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVAAAABs"] [Tue Aug 18 12:59:13.780843 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVQAAAAY"] [Tue Aug 18 12:59:13.783389 2026] [security2:error] [pid 123784:tid 123959] [client 52.173.121.69:14559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVgAAACk"] [Tue Aug 18 12:59:13.786377 2026] [security2:error] [pid 123784:tid 123976] [client 20.118.172.148:34213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcVwAAADo"] [Tue Aug 18 12:59:13.817415 2026] [security2:error] [pid 123784:tid 123930] [client 20.25.139.174:4671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcWQAAAAw"] [Tue Aug 18 12:59:13.822176 2026] [security2:error] [pid 123784:tid 123928] [client 20.25.139.174:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/i.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcWgAAAAo"] [Tue Aug 18 12:59:13.859543 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.85.180:18804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/as.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcXAAAAEU"] [Tue Aug 18 12:59:13.891106 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.85.180:27266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcXQAAAD8"] [Tue Aug 18 12:59:13.928629 2026] [security2:error] [pid 123784:tid 123994] [client 168.62.48.100:1078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcYgAAAEw"] [Tue Aug 18 12:59:13.942954 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcZAAAADg"] [Tue Aug 18 12:59:13.949496 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/v2.php"] [unique_id "aoSBUWwDnJBNj2tDbYbcZQAAAA8"] [Tue Aug 18 12:59:14.019736 2026] [security2:error] [pid 123784:tid 124007] [client 20.203.138.185:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/loxi-o.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcaAAAAFk"] [Tue Aug 18 12:59:14.048114 2026] [security2:error] [pid 123784:tid 123979] [client 74.248.18.37:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcagAAAD0"] [Tue Aug 18 12:59:14.072750 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:14.073061 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:14.150111 2026] [security2:error] [pid 123784:tid 124008] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.old"] [unique_id "aoSBUmwDnJBNj2tDbYbccgAAAFo"] [Tue Aug 18 12:59:14.190095 2026] [security2:error] [pid 123784:tid 123989] [client 20.250.13.23:38227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/php8.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcdgAAAEc"] [Tue Aug 18 12:59:14.204876 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:1176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbceAAAAHM"] [Tue Aug 18 12:59:14.209416 2026] [security2:error] [pid 123784:tid 124035] [client 52.173.121.69:30338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/mt/byp.php"] [unique_id "aoSBUmwDnJBNj2tDbYbceQAAAHU"] [Tue Aug 18 12:59:14.264021 2026] [security2:error] [pid 123784:tid 124040] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/api/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcfwAAAHo"] [Tue Aug 18 12:59:14.265143 2026] [security2:error] [pid 123784:tid 124010] [client 20.100.169.31:24417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ncx.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgAAAAFw"] [Tue Aug 18 12:59:14.268138 2026] [security2:error] [pid 123784:tid 124019] [client 132.196.30.78:13694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/alfa.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgQAAAGU"] [Tue Aug 18 12:59:14.289751 2026] [security2:error] [pid 123784:tid 124043] [client 20.65.98.162:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcggAAAH0"] [Tue Aug 18 12:59:14.296479 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/weozh.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcgwAAAH4"] [Tue Aug 18 12:59:14.321907 2026] [security2:error] [pid 123784:tid 124045] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/clque.php"] [unique_id "aoSBUmwDnJBNj2tDbYbchQAAAH8"] [Tue Aug 18 12:59:14.341169 2026] [security2:error] [pid 123784:tid 123932] [client 20.38.3.247:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUmwDnJBNj2tDbYbciAAAAA4"] [Tue Aug 18 12:59:14.361326 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bolt.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcigAAAGo"] [Tue Aug 18 12:59:14.367420 2026] [security2:error] [pid 123784:tid 124028] [client 20.25.139.174:4489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bolt.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcjAAAAG4"] [Tue Aug 18 12:59:14.368405 2026] [security2:error] [pid 123784:tid 124037] [client 66.187.6.102:57660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/backend/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcjQAAAHc"] [Tue Aug 18 12:59:14.378320 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/config/.env"] [unique_id "aoSBUmwDnJBNj2tDbYbcjwAAADc"] [Tue Aug 18 12:59:14.413170 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wkl.php"] [unique_id "aoSBUmwDnJBNj2tDbYbclAAAAGg"] [Tue Aug 18 12:59:14.440832 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBUmwDnJBNj2tDbYbclQAAAGI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:14.458440 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcmAAAAB8"] [Tue Aug 18 12:59:14.477322 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:19519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inputs.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcmQAAADU"] [Tue Aug 18 12:59:14.535087 2026] [security2:error] [pid 123784:tid 123924] [client 20.104.85.180:15205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/function/function.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcnQAAAAY"] [Tue Aug 18 12:59:14.578571 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ag.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcoQAAADE"] [Tue Aug 18 12:59:14.596101 2026] [security2:error] [pid 123784:tid 123984] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/nano.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcowAAAEI"] [Tue Aug 18 12:59:14.622592 2026] [security2:error] [pid 123784:tid 123987] [client 20.251.48.93:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcpAAAAEU"] [Tue Aug 18 12:59:14.630462 2026] [security2:error] [pid 123784:tid 123988] [client 52.173.121.69:49009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcpQAAAEY"] [Tue Aug 18 12:59:14.650942 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:14.651209 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:14.659361 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/rymmm.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcqAAAAEw"] [Tue Aug 18 12:59:14.659382 2026] [security2:error] [pid 123784:tid 123947] [client 213.202.253.4:64391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/gdftps.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcqQAAAB0"], referer: www.google.com [Tue Aug 18 12:59:14.690817 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.85.180:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcrAAAADg"] [Tue Aug 18 12:59:14.712462 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcrQAAAE8"] [Tue Aug 18 12:59:14.778385 2026] [security2:error] [pid 123784:tid 123935] [client 168.62.48.100:1168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcsQAAABE"] [Tue Aug 18 12:59:14.815229 2026] [autoindex:error] [pid 123784:tid 123966] [client 43.155.157.239:48154] AH01276: Cannot serve directory /home4/movei611/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.teresinahost.site [Tue Aug 18 12:59:14.840875 2026] [security2:error] [pid 123784:tid 124012] [client 74.248.18.37:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcuAAAAF4"] [Tue Aug 18 12:59:14.852059 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:40378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcugAAAHM"] [Tue Aug 18 12:59:14.872594 2026] [security2:error] [pid 123784:tid 124038] [client 20.65.98.162:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "tecpolorefrigeracao.com.br"] [uri "/.mopj.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcvQAAAHg"] [Tue Aug 18 12:59:14.905631 2026] [security2:error] [pid 123784:tid 124002] [client 20.25.139.174:4647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bthil.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcvwAAAFQ"] [Tue Aug 18 12:59:14.907339 2026] [security2:error] [pid 123784:tid 124004] [client 20.25.139.174:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcwQAAAFY"] [Tue Aug 18 12:59:14.951285 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:14.951574 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:14.962257 2026] [security2:error] [pid 123784:tid 124003] [client 132.196.30.78:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/edit.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcxwAAAFU"] [Tue Aug 18 12:59:15.014113 2026] [security2:error] [pid 123784:tid 124022] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/lddxs.php"] [unique_id "aoSBU2wDnJBNj2tDbYbcyQAAAGg"] [Tue Aug 18 12:59:15.014083 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/az.php"] [unique_id "aoSBU2wDnJBNj2tDbYbcygAAABg"] [Tue Aug 18 12:59:15.062030 2026] [security2:error] [pid 123784:tid 123931] [client 168.62.48.100:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbczQAAAA0"] [Tue Aug 18 12:59:15.067678 2026] [security2:error] [pid 123784:tid 123954] [client 20.118.172.148:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.secretplaceangradosreis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBU2wDnJBNj2tDbYbczgAAACQ"] [Tue Aug 18 12:59:15.110327 2026] [security2:error] [pid 123784:tid 124010] [client 132.196.30.78:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bthil.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0AAAAFw"] [Tue Aug 18 12:59:15.116090 2026] [security2:error] [pid 123784:tid 123944] [client 20.91.215.254:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/lock360.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0QAAABo"] [Tue Aug 18 12:59:15.151052 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/bengi.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc0wAAAAY"] [Tue Aug 18 12:59:15.175130 2026] [security2:error] [pid 123784:tid 124021] [client 40.74.65.169:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/av.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1AAAAGc"] [Tue Aug 18 12:59:15.205810 2026] [security2:error] [pid 123784:tid 123948] [client 52.173.121.69:12194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1gAAAB4"] [Tue Aug 18 12:59:15.211088 2026] [security2:error] [pid 123784:tid 124005] [client 20.100.169.31:38054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc1wAAAFc"] [Tue Aug 18 12:59:15.293861 2026] [security2:error] [pid 123784:tid 123993] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/z43agz.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc2gAAAEs"] [Tue Aug 18 12:59:15.313521 2026] [security2:error] [pid 123784:tid 123945] [client 20.203.138.185:25499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sdsa.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc3QAAABs"] [Tue Aug 18 12:59:15.321619 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:1203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc3gAAAEg"] [Tue Aug 18 12:59:15.363814 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zjggu.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc4AAAAE4"] [Tue Aug 18 12:59:15.384895 2026] [security2:error] [pid 123784:tid 124029] [client 110.249.201.76:41368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rakhomed.com.br"] [uri "/robots.txt"] [unique_id "aoSBU2wDnJBNj2tDbYbc5AAAAG8"] [Tue Aug 18 12:59:15.385903 2026] [security2:error] [pid 123784:tid 123997] [client 20.104.85.180:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc5QAAAE8"] [Tue Aug 18 12:59:15.406206 2026] [security2:error] [pid 123784:tid 123929] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/file2.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc6QAAAAs"] [Tue Aug 18 12:59:15.420003 2026] [security2:error] [pid 123784:tid 123919] [client 172.182.200.96:14150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc6gAAAAE"] [Tue Aug 18 12:59:15.430254 2026] [security2:error] [pid 123784:tid 123978] [client 79.127.164.8:41552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/structure.bak"] [unique_id "aoSBU2wDnJBNj2tDbYbc6wAAADw"], referer: https://medihub.com.br/structure.bak [Tue Aug 18 12:59:15.455955 2026] [security2:error] [pid 123784:tid 124041] [client 20.25.139.174:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7AAAAHs"] [Tue Aug 18 12:59:15.457127 2026] [security2:error] [pid 123784:tid 123937] [client 213.35.127.232:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7gAAABM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:15.458142 2026] [core:crit] [pid 123784:tid 123981] (13)Permission denied: [client 20.25.139.174:4675] AH00529: /home3/cadema/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/cadema/public_html/cgi-bin/' is executable [Tue Aug 18 12:59:15.511857 2026] [security2:error] [pid 123784:tid 124013] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc7wAAX1M"] [Tue Aug 18 12:59:15.553021 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:15.553374 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:15.582201 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/3.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc9gAAAGA"] [Tue Aug 18 12:59:15.600026 2026] [security2:error] [pid 123784:tid 124038] [client 52.173.121.69:41121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc-AAAAHg"] [Tue Aug 18 12:59:15.604114 2026] [security2:error] [pid 123784:tid 124040] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.orig"] [unique_id "aoSBU2wDnJBNj2tDbYbc-gAAAHo"] [Tue Aug 18 12:59:15.623864 2026] [security2:error] [pid 123784:tid 124042] [client 20.25.139.174:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/x.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc-wAAAHw"] [Tue Aug 18 12:59:15.648634 2026] [security2:error] [pid 123784:tid 123966] [client 132.196.30.78:15808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/elp.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_QAAADA"] [Tue Aug 18 12:59:15.652003 2026] [security2:error] [pid 123784:tid 123920] [client 103.184.169.37:42549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_gAAAAI"] [Tue Aug 18 12:59:15.652113 2026] [security2:error] [pid 123784:tid 123920] [client 103.184.169.37:42549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_gAAAAI"] [Tue Aug 18 12:59:15.654760 2026] [security2:error] [pid 123784:tid 124025] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/gm.php"] [unique_id "aoSBU2wDnJBNj2tDbYbc_wAAAGs"] [Tue Aug 18 12:59:15.671687 2026] [security2:error] [pid 123784:tid 124044] [client 4.232.94.69:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/u.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAQAAAH4"] [Tue Aug 18 12:59:15.694009 2026] [security2:error] [pid 123784:tid 123991] [client 168.62.48.100:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBAAAAEk"] [Tue Aug 18 12:59:15.698762 2026] [security2:error] [pid 123784:tid 123961] [client 103.120.71.157:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAwAAACs"] [Tue Aug 18 12:59:15.698907 2026] [security2:error] [pid 123784:tid 123961] [client 103.120.71.157:18801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdAwAAACs"] [Tue Aug 18 12:59:15.716768 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBQAAAHk"] [Tue Aug 18 12:59:15.745497 2026] [core:crit] [pid 123784:tid 124017] (13)Permission denied: [client 132.196.30.78:13649] AH00529: /home3/cadema/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/cadema/public_html/cgi-bin/' is executable [Tue Aug 18 12:59:15.751955 2026] [security2:error] [pid 123784:tid 124034] [client 20.91.215.254:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/log.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdBwAAAHQ"] [Tue Aug 18 12:59:15.766531 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:44511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/01.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdFwAAAG4"] [Tue Aug 18 12:59:15.774341 2026] [security2:error] [pid 123784:tid 123973] [client 158.23.17.4:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ig.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdHgAAADc"] [Tue Aug 18 12:59:15.798098 2026] [security2:error] [pid 123784:tid 124027] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.copy"] [unique_id "aoSBU2wDnJBNj2tDbYbdJAAAAG0"] [Tue Aug 18 12:59:15.800215 2026] [security2:error] [pid 123784:tid 123938] [client 138.36.100.162:41761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJQAAABQ"] [Tue Aug 18 12:59:15.800290 2026] [security2:error] [pid 123784:tid 123938] [client 138.36.100.162:41761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJQAAABQ"] [Tue Aug 18 12:59:15.826844 2026] [security2:error] [pid 123784:tid 123951] [client 68.221.73.131:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/ops.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdJwAAACE"] [Tue Aug 18 12:59:15.869271 2026] [security2:error] [pid 123784:tid 123972] [client 40.74.65.169:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdLAAAADY"] [Tue Aug 18 12:59:15.884850 2026] [security2:error] [pid 123784:tid 123976] [client 132.196.30.78:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/x.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdLwAAADo"] [Tue Aug 18 12:59:15.901896 2026] [security2:error] [pid 123784:tid 123927] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/log.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdMQAAAAk"] [Tue Aug 18 12:59:15.924767 2026] [security2:error] [pid 123784:tid 123948] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/ws55.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdNQAAAB4"] [Tue Aug 18 12:59:15.983807 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:64734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBU2wDnJBNj2tDbYbdTQAAAEY"] [Tue Aug 18 12:59:16.001223 2026] [security2:error] [pid 123784:tid 123968] [client 20.25.139.174:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdTwAAADI"] [Tue Aug 18 12:59:16.035319 2026] [security2:error] [pid 123784:tid 123935] [client 20.215.241.237:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/222.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdUwAAABE"] [Tue Aug 18 12:59:16.039659 2026] [security2:error] [pid 123784:tid 123919] [client 168.62.48.100:1082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdVQAAAAE"] [Tue Aug 18 12:59:16.064692 2026] [security2:error] [pid 123784:tid 124041] [client 52.173.121.69:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdWAAAAHs"] [Tue Aug 18 12:59:16.073639 2026] [security2:error] [pid 123784:tid 123981] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdWQAAAD8"] [Tue Aug 18 12:59:16.159527 2026] [security2:error] [pid 123784:tid 124045] [client 49.13.24.81:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSBUmwDnJBNj2tDbYbcwwAAAH8"], referer: http://blog.tinna.com.br [Tue Aug 18 12:59:16.189470 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ohct.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdXQAAAHg"] [Tue Aug 18 12:59:16.204675 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/m.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdXgAAAFg"] [Tue Aug 18 12:59:16.228099 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.85.180:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYAAAAB0"] [Tue Aug 18 12:59:16.230062 2026] [security2:error] [pid 123784:tid 123937] [client 20.25.139.174:4676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/index/function.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYQAAABM"] [Tue Aug 18 12:59:16.243868 2026] [security2:error] [pid 123784:tid 124018] [client 66.187.6.102:57670] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/.env.yaml"] [unique_id "aoSBVGwDnJBNj2tDbYbdYgAAAGQ"] [Tue Aug 18 12:59:16.249738 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdYwAAAGo"] [Tue Aug 18 12:59:16.254466 2026] [security2:error] [pid 123784:tid 123953] [client 74.248.18.37:32099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdZAAAACM"] [Tue Aug 18 12:59:16.290300 2026] [security2:error] [pid 123784:tid 123961] [client 20.203.138.185:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-freya.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdZwAAACs"] [Tue Aug 18 12:59:16.319331 2026] [security2:error] [pid 123784:tid 124010] [client 149.34.210.141:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdaQAAAFw"] [Tue Aug 18 12:59:16.358563 2026] [security2:error] [pid 123784:tid 123960] [client 168.62.48.100:1219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdagAAACo"] [Tue Aug 18 12:59:16.392341 2026] [security2:error] [pid 123784:tid 124014] [client 20.91.215.254:10176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/lv.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdbgAAAGA"] [Tue Aug 18 12:59:16.415490 2026] [security2:error] [pid 123784:tid 123920] [client 132.196.30.78:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/index/function.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdcAAAAAI"] [Tue Aug 18 12:59:16.450000 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/kopyw.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdcgAAAHY"] [Tue Aug 18 12:59:16.459018 2026] [security2:error] [pid 123784:tid 123934] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.local.bak"] [unique_id "aoSBVGwDnJBNj2tDbYbdcwAAABA"] [Tue Aug 18 12:59:16.474941 2026] [security2:error] [pid 123784:tid 123943] [client 213.35.127.232:60813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddAAAABk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:16.476366 2026] [security2:error] [pid 123784:tid 124016] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ot.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddQAAAGI"] [Tue Aug 18 12:59:16.480647 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/33.php"] [unique_id "aoSBVGwDnJBNj2tDbYbddgAAAHI"] [Tue Aug 18 12:59:16.520133 2026] [security2:error] [pid 123784:tid 123962] [client 157.20.138.62:55135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdeQAAACw"] [Tue Aug 18 12:59:16.520275 2026] [security2:error] [pid 123784:tid 123962] [client 157.20.138.62:55135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdeQAAACw"] [Tue Aug 18 12:59:16.532352 2026] [security2:error] [pid 123784:tid 124043] [client 52.173.121.69:27886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdewAAAH0"] [Tue Aug 18 12:59:16.543670 2026] [security2:error] [pid 123784:tid 123972] [client 40.74.65.169:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdfAAAADY"] [Tue Aug 18 12:59:16.575410 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:4678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/NewFile.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdfQAAADc"] [Tue Aug 18 12:59:16.595529 2026] [security2:error] [pid 123784:tid 124010] [client 149.34.210.141:64851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdaQAAAFw"] [Tue Aug 18 12:59:16.629840 2026] [security2:error] [pid 123784:tid 123930] [client 172.202.39.151:40382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/lv.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdgAAAAAw"] [Tue Aug 18 12:59:16.632481 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:29799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/media.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdgQAAADQ"] [Tue Aug 18 12:59:16.632700 2026] [security2:error] [pid 123784:tid 123971] [client 20.250.13.23:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdggAAADU"] [Tue Aug 18 12:59:16.688539 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhAAAAEg"] [Tue Aug 18 12:59:16.695904 2026] [security2:error] [pid 123784:tid 123968] [client 20.104.85.180:42297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhgAAADI"] [Tue Aug 18 12:59:16.739960 2026] [security2:error] [pid 123784:tid 123974] [client 20.65.98.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracao.com.br"] [uri "/packed.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdhwAAADg"] [Tue Aug 18 12:59:16.752128 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/v5.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdigAAAA8"] [Tue Aug 18 12:59:16.756096 2026] [security2:error] [pid 123784:tid 124021] [client 20.25.139.174:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/aaa.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdiwAAAGc"] [Tue Aug 18 12:59:16.758321 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:16.758601 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:16.776614 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ta.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdjQAAAAE"] [Tue Aug 18 12:59:16.805841 2026] [security2:error] [pid 123784:tid 123929] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zznmg.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdkAAAAAs"] [Tue Aug 18 12:59:16.819846 2026] [security2:error] [pid 123784:tid 123958] [client 173.239.254.5:48729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriacristal.com.br"] [uri "/wp-login.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdkQAAACg"] [Tue Aug 18 12:59:16.916778 2026] [security2:error] [pid 123784:tid 123993] [client 132.196.30.78:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/666.php"] [unique_id "aoSBVGwDnJBNj2tDbYbdlAAAAEs"] [Tue Aug 18 12:59:17.002374 2026] [security2:error] [pid 123784:tid 123935] [client 74.248.18.37:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdlwAAABE"] [Tue Aug 18 12:59:17.010992 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:1126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmAAAAFg"] [Tue Aug 18 12:59:17.022223 2026] [security2:error] [pid 123784:tid 124041] [client 20.91.215.254:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mah/function.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmQAAAHs"] [Tue Aug 18 12:59:17.027797 2026] [security2:error] [pid 123784:tid 123932] [client 5.31.227.224:30444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmgAAAA4"] [Tue Aug 18 12:59:17.037702 2026] [security2:error] [pid 123784:tid 123932] [client 5.31.227.224:30444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdmgAAAA4"] [Tue Aug 18 12:59:17.040849 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:34435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnAAAACc"] [Tue Aug 18 12:59:17.041005 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:34435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnAAAACc"] [Tue Aug 18 12:59:17.054380 2026] [security2:error] [pid 123784:tid 124019] [client 68.155.154.236:25358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdnwAAAGU"] [Tue Aug 18 12:59:17.092981 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/aaa.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdoAAAAEw"] [Tue Aug 18 12:59:17.096329 2026] [security2:error] [pid 123784:tid 123997] [client 20.203.138.185:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fleen.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdoQAAAE8"] [Tue Aug 18 12:59:17.110000 2026] [security2:error] [pid 123784:tid 124033] [client 20.25.139.174:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdogAAAHM"] [Tue Aug 18 12:59:17.138979 2026] [security2:error] [pid 123784:tid 123966] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSBVWwDnJBNj2tDbYbdpQAAADA"] [Tue Aug 18 12:59:17.158063 2026] [security2:error] [pid 123784:tid 123953] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdpgAAACM"] [Tue Aug 18 12:59:17.165234 2026] [security2:error] [pid 123784:tid 124026] [client 52.173.121.69:27883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdpwAAAGw"] [Tue Aug 18 12:59:17.193611 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.85.180:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/ok.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdqQAAAH4"] [Tue Aug 18 12:59:17.219368 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.85.180:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdqwAAAGM"] [Tue Aug 18 12:59:17.224220 2026] [security2:error] [pid 123784:tid 124034] [client 40.74.65.169:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdrQAAAHQ"] [Tue Aug 18 12:59:17.285871 2026] [security2:error] [pid 123784:tid 123920] [client 168.62.48.100:1057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdrwAAAAI"] [Tue Aug 18 12:59:17.316996 2026] [security2:error] [pid 123784:tid 123938] [client 20.38.3.247:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/admin.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdsgAAABQ"] [Tue Aug 18 12:59:17.486269 2026] [security2:error] [pid 123784:tid 123918] [client 20.25.139.174:4619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/abcd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdugAAAAA"] [Tue Aug 18 12:59:17.486269 2026] [security2:error] [pid 123784:tid 124018] [client 213.35.127.232:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbduQAAAGQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:17.488029 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBVWwDnJBNj2tDbYbduwAAABU"] [Tue Aug 18 12:59:17.512679 2026] [security2:error] [pid 123784:tid 123925] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdvgAAAAc"] [Tue Aug 18 12:59:17.565872 2026] [security2:error] [pid 123784:tid 123970] [client 68.221.73.131:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/coffexium.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdwAAAADQ"] [Tue Aug 18 12:59:17.570593 2026] [security2:error] [pid 123784:tid 123971] [client 168.62.48.100:1162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdwQAAADU"] [Tue Aug 18 12:59:17.639502 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/.env.development.old"] [unique_id "aoSBVWwDnJBNj2tDbYbdyAAAAD4"] [Tue Aug 18 12:59:17.642595 2026] [security2:error] [pid 123784:tid 123949] [client 223.185.37.47:5876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdygAAAB8"] [Tue Aug 18 12:59:17.642832 2026] [security2:error] [pid 123784:tid 123949] [client 223.185.37.47:5876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdygAAAB8"] [Tue Aug 18 12:59:17.667812 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:17.668159 2026] [security2:error] [pid 123784:tid 123927] [client 132.196.30.78:15038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/abcd.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdzgAAAAk"] [Tue Aug 18 12:59:17.668237 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:17.673385 2026] [security2:error] [pid 123784:tid 124043] [client 20.91.215.254:10238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBVWwDnJBNj2tDbYbdzwAAAH0"] [Tue Aug 18 12:59:17.707592 2026] [security2:error] [pid 123784:tid 123919] [client 20.251.48.93:53319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1AAAAAE"] [Tue Aug 18 12:59:17.736086 2026] [security2:error] [pid 123784:tid 123950] [client 52.173.121.69:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1gAAACA"] [Tue Aug 18 12:59:17.737538 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd1wAAACI"] [Tue Aug 18 12:59:17.790912 2026] [security2:error] [pid 123784:tid 124031] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd3QAAAHE"] [Tue Aug 18 12:59:17.837156 2026] [security2:error] [pid 123784:tid 123975] [client 168.62.48.100:1199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd3wAAADk"] [Tue Aug 18 12:59:17.848491 2026] [security2:error] [pid 123784:tid 124025] [client 85.154.68.202:60396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4AAAAGs"] [Tue Aug 18 12:59:17.848656 2026] [security2:error] [pid 123784:tid 124025] [client 85.154.68.202:60396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4AAAAGs"] [Tue Aug 18 12:59:17.870043 2026] [security2:error] [pid 123784:tid 124008] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/oivcl.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd4wAAAFo"] [Tue Aug 18 12:59:17.931270 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:9378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/mac.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd6AAAAEw"] [Tue Aug 18 12:59:17.945826 2026] [security2:error] [pid 123784:tid 124040] [client 74.248.18.37:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd6QAAAHo"] [Tue Aug 18 12:59:17.970284 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:17.970729 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:17.982497 2026] [security2:error] [pid 123784:tid 123961] [client 4.232.94.69:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/k.php"] [unique_id "aoSBVWwDnJBNj2tDbYbd7QAAACs"] [Tue Aug 18 12:59:18.010188 2026] [security2:error] [pid 123784:tid 124028] [client 20.203.138.185:11118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/e.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd7gAAAG4"] [Tue Aug 18 12:59:18.087124 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:1180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8QAAAHY"] [Tue Aug 18 12:59:18.090949 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-good.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8gAAAEA"] [Tue Aug 18 12:59:18.092338 2026] [security2:error] [pid 123784:tid 123934] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dk.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd8wAAABA"] [Tue Aug 18 12:59:18.117754 2026] [security2:error] [pid 123784:tid 123951] [client 20.104.85.180:29534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.vidracariafroesbox.com.br"] [uri "/item.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd9AAAACE"] [Tue Aug 18 12:59:18.129267 2026] [security2:error] [pid 123784:tid 123984] [client 52.173.121.69:48981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/first.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd9QAAAEI"] [Tue Aug 18 12:59:18.177649 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/.env.beta"] [unique_id "aoSBVmwDnJBNj2tDbYbd-QAAADc"] [Tue Aug 18 12:59:18.177762 2026] [security2:error] [pid 123784:tid 123973] [client 66.187.6.102:57724] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/.env.beta"] [unique_id "aoSBVmwDnJBNj2tDbYbd-QAAADc"] [Tue Aug 18 12:59:18.188612 2026] [security2:error] [pid 123784:tid 123937] [client 185.191.171.10:27756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752011076/1753920000/"] [unique_id "aoSBVmwDnJBNj2tDbYbd-wAAABM"] [Tue Aug 18 12:59:18.188774 2026] [security2:error] [pid 123784:tid 123937] [client 185.191.171.10:27756] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752011076/1753920000/"] [unique_id "aoSBVmwDnJBNj2tDbYbd-wAAABM"] [Tue Aug 18 12:59:18.189081 2026] [security2:error] [pid 123784:tid 123993] [client 20.250.13.23:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/222.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_AAAAEs"] [Tue Aug 18 12:59:18.203981 2026] [security2:error] [pid 123784:tid 124023] [client 132.196.30.78:15019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ws54.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_QAAAGk"] [Tue Aug 18 12:59:18.220177 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zugvi.php"] [unique_id "aoSBVmwDnJBNj2tDbYbd_wAAAEk"] [Tue Aug 18 12:59:18.238692 2026] [security2:error] [pid 123784:tid 123942] [client 20.25.139.174:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/themes.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeAQAAABg"] [Tue Aug 18 12:59:18.244215 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:15015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-good.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeAgAAAGE"] [Tue Aug 18 12:59:18.271168 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:18.271430 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:18.313096 2026] [security2:error] [pid 123784:tid 123943] [client 20.91.215.254:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mass.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeCQAAABk"] [Tue Aug 18 12:59:18.322685 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:44584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/new.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeCwAAAAs"] [Tue Aug 18 12:59:18.345400 2026] [security2:error] [pid 123784:tid 123893] [remote 203.99.146.53:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDQAAOGg"] [Tue Aug 18 12:59:18.349351 2026] [security2:error] [pid 123784:tid 123990] [client 37.40.227.74:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDgAAAEg"] [Tue Aug 18 12:59:18.349465 2026] [security2:error] [pid 123784:tid 123990] [client 37.40.227.74:57070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDgAAAEg"] [Tue Aug 18 12:59:18.373564 2026] [security2:error] [pid 123784:tid 124031] [client 20.104.85.180:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeDwAAAHE"] [Tue Aug 18 12:59:18.377182 2026] [security2:error] [pid 123784:tid 124013] [client 168.62.48.100:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeEAAAAF8"] [Tue Aug 18 12:59:18.396852 2026] [security2:error] [pid 123784:tid 124025] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/bal.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeEgAAAGs"] [Tue Aug 18 12:59:18.413356 2026] [security2:error] [pid 123784:tid 123882] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFAAAA10"] [Tue Aug 18 12:59:18.413594 2026] [security2:error] [pid 123784:tid 123921] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFAAAA10"] [Tue Aug 18 12:59:18.421062 2026] [security2:error] [pid 123784:tid 123888] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFQAAGmM"] [Tue Aug 18 12:59:18.421307 2026] [security2:error] [pid 123784:tid 123944] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeFQAAGmM"] [Tue Aug 18 12:59:18.447704 2026] [security2:error] [pid 123784:tid 123979] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/server/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeFgAAAD0"] [Tue Aug 18 12:59:18.497640 2026] [security2:error] [pid 123784:tid 123940] [client 213.35.127.232:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGAAAABY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:18.538954 2026] [security2:error] [pid 123784:tid 123997] [client 20.38.3.247:64090] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGQAAAE8"] [Tue Aug 18 12:59:18.539094 2026] [security2:error] [pid 123784:tid 123997] [client 20.38.3.247:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGQAAAE8"] [Tue Aug 18 12:59:18.569400 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:18.569668 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:18.574831 2026] [security2:error] [pid 123784:tid 124040] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wsrer.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeGwAAAHo"] [Tue Aug 18 12:59:18.615335 2026] [security2:error] [pid 123784:tid 124008] [client 20.25.139.174:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/simple.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeHgAAAFo"] [Tue Aug 18 12:59:18.622439 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.98.162:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/mgrr.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeHwAAAG4"] [Tue Aug 18 12:59:18.670090 2026] [security2:error] [pid 123784:tid 124030] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/app/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeIAAAAHA"] [Tue Aug 18 12:59:18.683012 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yawa.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeIgAAAGA"] [Tue Aug 18 12:59:18.690012 2026] [security2:error] [pid 123784:tid 123920] [client 52.173.121.69:14872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeIwAAAAI"] [Tue Aug 18 12:59:18.722302 2026] [security2:error] [pid 123784:tid 124035] [client 168.62.48.100:1211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/first.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJAAAAHU"] [Tue Aug 18 12:59:18.754957 2026] [security2:error] [pid 123784:tid 123952] [client 114.5.214.109:50413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJgAAACI"] [Tue Aug 18 12:59:18.755636 2026] [security2:error] [pid 123784:tid 123952] [client 114.5.214.109:50413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJgAAACI"] [Tue Aug 18 12:59:18.761531 2026] [security2:error] [pid 123784:tid 124044] [client 132.196.30.78:15002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/simple.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeJwAAAH4"] [Tue Aug 18 12:59:18.772071 2026] [security2:error] [pid 123784:tid 123947] [client 20.25.139.174:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/cv.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKQAAAB0"] [Tue Aug 18 12:59:18.783861 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKgAAAAY"] [Tue Aug 18 12:59:18.834529 2026] [security2:error] [pid 123784:tid 123976] [client 20.203.138.185:21039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/hello.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeKwAAADo"] [Tue Aug 18 12:59:18.889931 2026] [security2:error] [pid 123784:tid 123953] [client 79.127.164.8:41868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/structure.sql"] [unique_id "aoSBVmwDnJBNj2tDbYbeMAAAACM"], referer: https://medihub.com.br/structure.sql [Tue Aug 18 12:59:18.935712 2026] [security2:error] [pid 123784:tid 124005] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNAAAAFc"] [Tue Aug 18 12:59:18.937340 2026] [security2:error] [pid 123784:tid 124027] [client 74.248.18.37:26477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNQAAAG0"] [Tue Aug 18 12:59:18.950460 2026] [security2:error] [pid 123784:tid 124032] [client 20.91.215.254:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeNwAAAHI"] [Tue Aug 18 12:59:18.952388 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/src/.env"] [unique_id "aoSBVmwDnJBNj2tDbYbeOAAAAD4"] [Tue Aug 18 12:59:18.957696 2026] [security2:error] [pid 123784:tid 123961] [client 4.232.94.69:37533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/elp.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeOwAAACs"] [Tue Aug 18 12:59:18.968563 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePAAAAEQ"] [Tue Aug 18 12:59:18.981898 2026] [security2:error] [pid 123784:tid 123942] [client 168.62.48.100:1195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePQAAABg"] [Tue Aug 18 12:59:18.996174 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.85.180:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbePwAAAGE"] [Tue Aug 18 12:59:18.996903 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.200.96:7654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeQAAAAE4"] [Tue Aug 18 12:59:19.127796 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeRQAAAEk"] [Tue Aug 18 12:59:19.136788 2026] [security2:error] [pid 123784:tid 123929] [client 20.65.98.162:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/55.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeTQAAAAs"] [Tue Aug 18 12:59:19.188033 2026] [security2:error] [pid 123784:tid 123967] [client 20.100.169.31:39099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wso.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeTwAAADE"] [Tue Aug 18 12:59:19.246336 2026] [security2:error] [pid 123784:tid 123987] [client 52.173.121.69:32611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeVgAAAEU"] [Tue Aug 18 12:59:19.249364 2026] [security2:error] [pid 123784:tid 123923] [client 20.215.241.237:65267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/key.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeVwAAAAU"] [Tue Aug 18 12:59:19.260870 2026] [security2:error] [pid 123784:tid 124045] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/docker/.env"] [unique_id "aoSBV2wDnJBNj2tDbYbeWQAAAH8"] [Tue Aug 18 12:59:19.266263 2026] [security2:error] [pid 123784:tid 124000] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/7.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeWgAAAFI"] [Tue Aug 18 12:59:19.314147 2026] [security2:error] [pid 123784:tid 124038] [client 40.74.65.169:42485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXAAAAHg"] [Tue Aug 18 12:59:19.316022 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/yxijx.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXgAAAC0"] [Tue Aug 18 12:59:19.316514 2026] [security2:error] [pid 123784:tid 123935] [client 168.62.48.100:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeXwAAABE"] [Tue Aug 18 12:59:19.391439 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/function/function.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeYwAAAGs"] [Tue Aug 18 12:59:19.471998 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:19.472274 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:19.482956 2026] [security2:error] [pid 123784:tid 124035] [client 20.38.3.247:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/coffee.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeaQAAAHU"] [Tue Aug 18 12:59:19.519172 2026] [security2:error] [pid 123784:tid 124031] [client 213.35.127.232:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBV2wDnJBNj2tDbYbebgAAAHE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:19.521729 2026] [security2:error] [pid 123784:tid 123951] [client 68.155.154.236:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBV2wDnJBNj2tDbYbebwAAACE"] [Tue Aug 18 12:59:19.607773 2026] [security2:error] [pid 123784:tid 123930] [client 168.62.48.100:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecQAAAAw"] [Tue Aug 18 12:59:19.635582 2026] [security2:error] [pid 123784:tid 123925] [client 20.104.85.180:43579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecgAAAAc"] [Tue Aug 18 12:59:19.664633 2026] [security2:error] [pid 123784:tid 124034] [client 20.91.215.254:10208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/meta.php"] [unique_id "aoSBV2wDnJBNj2tDbYbecwAAAHQ"] [Tue Aug 18 12:59:19.669324 2026] [security2:error] [pid 123784:tid 124005] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedAAAAFc"] [Tue Aug 18 12:59:19.670289 2026] [security2:error] [pid 123784:tid 124030] [client 132.196.30.78:14996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedQAAAHA"] [Tue Aug 18 12:59:19.672281 2026] [security2:error] [pid 123784:tid 124027] [client 20.203.138.185:11131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/brc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedgAAAG0"] [Tue Aug 18 12:59:19.687339 2026] [security2:error] [pid 123784:tid 123993] [client 192.141.172.134:53713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedwAAAEs"] [Tue Aug 18 12:59:19.687444 2026] [security2:error] [pid 123784:tid 123993] [client 192.141.172.134:53713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbedwAAAEs"] [Tue Aug 18 12:59:19.699082 2026] [security2:error] [pid 123784:tid 124032] [client 20.251.48.93:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeeAAAAHI"] [Tue Aug 18 12:59:19.718943 2026] [security2:error] [pid 123784:tid 123924] [client 20.25.139.174:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/u.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeegAAAAY"] [Tue Aug 18 12:59:19.721046 2026] [security2:error] [pid 123784:tid 123791] [remote 162.55.89.48:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villanobreeventos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeeQAAYwI"] [Tue Aug 18 12:59:19.785567 2026] [security2:error] [pid 123784:tid 123919] [client 52.173.121.69:42731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbefwAAAAE"] [Tue Aug 18 12:59:19.791255 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:19.791571 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:19.811099 2026] [security2:error] [pid 123784:tid 123952] [client 4.232.94.69:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSBV2wDnJBNj2tDbYbegQAAACI"] [Tue Aug 18 12:59:19.851305 2026] [security2:error] [pid 123784:tid 123955] [client 168.62.48.100:1149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBV2wDnJBNj2tDbYbegwAAACU"] [Tue Aug 18 12:59:19.866660 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:57245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/f.php"] [unique_id "aoSBV2wDnJBNj2tDbYbehAAAADg"] [Tue Aug 18 12:59:19.890903 2026] [security2:error] [pid 123784:tid 123927] [client 20.25.139.174:4685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBV2wDnJBNj2tDbYbehgAAAAk"] [Tue Aug 18 12:59:19.936789 2026] [security2:error] [pid 123784:tid 124037] [client 102.213.179.104:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeiQAAAHc"] [Tue Aug 18 12:59:19.936937 2026] [security2:error] [pid 123784:tid 124037] [client 102.213.179.104:59271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBV2wDnJBNj2tDbYbeiQAAAHc"] [Tue Aug 18 12:59:20.019620 2026] [security2:error] [pid 123784:tid 123956] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/jrpga.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejAAAACY"] [Tue Aug 18 12:59:20.027608 2026] [security2:error] [pid 123784:tid 124038] [client 40.74.65.169:19485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejQAAAHg"] [Tue Aug 18 12:59:20.035948 2026] [security2:error] [pid 123784:tid 124026] [client 132.196.30.78:15655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/nw.php"] [unique_id "aoSBWGwDnJBNj2tDbYbejgAAAGw"] [Tue Aug 18 12:59:20.102454 2026] [security2:error] [pid 123784:tid 124042] [client 74.248.18.37:19271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekAAAAHw"] [Tue Aug 18 12:59:20.107026 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:1212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekQAAAHo"] [Tue Aug 18 12:59:20.111956 2026] [security2:error] [pid 123784:tid 123928] [client 68.221.73.131:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBWGwDnJBNj2tDbYbekgAAAAo"] [Tue Aug 18 12:59:20.225868 2026] [security2:error] [pid 123784:tid 124012] [client 52.173.121.69:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/blog/byp.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenAAAAF4"] [Tue Aug 18 12:59:20.230521 2026] [security2:error] [pid 123784:tid 123968] [client 20.25.139.174:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenQAAADI"] [Tue Aug 18 12:59:20.239132 2026] [security2:error] [pid 123784:tid 123982] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSBVmwDnJBNj2tDbYbeLQAAQGU"], referer: https://markettohome.com.br/ [Tue Aug 18 12:59:20.245472 2026] [security2:error] [pid 123784:tid 124035] [client 20.38.3.247:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBWGwDnJBNj2tDbYbenwAAAHU"] [Tue Aug 18 12:59:20.269421 2026] [security2:error] [pid 123784:tid 124013] [client 132.196.30.78:15014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/u.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeoAAAAF8"] [Tue Aug 18 12:59:20.303890 2026] [security2:error] [pid 123784:tid 123994] [client 20.91.215.254:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mini.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeoQAAAEw"] [Tue Aug 18 12:59:20.359934 2026] [security2:error] [pid 123784:tid 124022] [client 168.62.48.100:1127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeqwAAAGg"] [Tue Aug 18 12:59:20.373412 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:20.373690 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:20.390575 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.85.180:18783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/an.php"] [unique_id "aoSBWGwDnJBNj2tDbYberQAAABU"] [Tue Aug 18 12:59:20.395764 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBWGwDnJBNj2tDbYbergAAAH4"] [Tue Aug 18 12:59:20.414569 2026] [security2:error] [pid 123784:tid 124005] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ws77.php"] [unique_id "aoSBWGwDnJBNj2tDbYbesAAAAFc"] [Tue Aug 18 12:59:20.450353 2026] [security2:error] [pid 123784:tid 123954] [client 20.25.139.174:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ws83.php"] [unique_id "aoSBWGwDnJBNj2tDbYbesQAAACQ"] [Tue Aug 18 12:59:20.500045 2026] [security2:error] [pid 123784:tid 124003] [client 172.202.39.151:40381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/222.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeswAAAFU"] [Tue Aug 18 12:59:20.535884 2026] [security2:error] [pid 123784:tid 123966] [client 213.35.127.232:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBWGwDnJBNj2tDbYbetQAAADA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:20.544181 2026] [security2:error] [pid 123784:tid 124029] [client 20.203.138.185:11104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/file52.php"] [unique_id "aoSBWGwDnJBNj2tDbYbetgAAAG8"] [Tue Aug 18 12:59:20.602578 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:1106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.velasmagica.com.br"] [uri "/images/security.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeuwAAAFY"] [Tue Aug 18 12:59:20.613140 2026] [security2:error] [pid 123784:tid 123971] [client 213.202.253.4:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/gdftps.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevQAAADU"], referer: www.google.com [Tue Aug 18 12:59:20.614186 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/34.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevgAAACg"] [Tue Aug 18 12:59:20.619832 2026] [security2:error] [pid 123784:tid 123937] [client 158.23.17.4:33466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/30.php"] [unique_id "aoSBWGwDnJBNj2tDbYbevwAAABM"] [Tue Aug 18 12:59:20.642005 2026] [security2:error] [pid 123784:tid 123969] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBWGwDnJBNj2tDbYbewQAAADM"] [Tue Aug 18 12:59:20.677897 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:20.678370 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:20.699614 2026] [autoindex:error] [pid 123784:tid 124034] [client 4.232.94.69:46050] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:20.715508 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:42478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/222.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeygAAAAA"] [Tue Aug 18 12:59:20.715544 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:14977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/xleet.php"] [unique_id "aoSBWGwDnJBNj2tDbYbeywAAAFQ"] [Tue Aug 18 12:59:20.718420 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/read.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezAAAAAU"] [Tue Aug 18 12:59:20.738249 2026] [security2:error] [pid 123784:tid 123987] [client 52.173.121.69:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezgAAAEU"] [Tue Aug 18 12:59:20.747122 2026] [security2:error] [pid 123784:tid 123944] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/nwwha.php"] [unique_id "aoSBWGwDnJBNj2tDbYbezwAAABo"] [Tue Aug 18 12:59:20.759514 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/h.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe0AAAACI"] [Tue Aug 18 12:59:20.771030 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/weozh.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe0wAAAB8"] [Tue Aug 18 12:59:20.793430 2026] [security2:error] [pid 123784:tid 123970] [client 74.248.18.37:32112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe1AAAADQ"] [Tue Aug 18 12:59:20.862257 2026] [security2:error] [pid 123784:tid 124006] [client 20.251.48.93:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/av.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe2AAAAFg"] [Tue Aug 18 12:59:20.874630 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:15013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe2gAAADg"] [Tue Aug 18 12:59:20.909453 2026] [security2:error] [pid 123784:tid 124042] [client 4.232.94.69:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/o.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe3gAAAHw"] [Tue Aug 18 12:59:20.926068 2026] [security2:error] [pid 123784:tid 123977] [client 20.38.3.247:8683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe3wAAADs"] [Tue Aug 18 12:59:20.962363 2026] [security2:error] [pid 123784:tid 123956] [client 20.25.139.174:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/atex1.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe4gAAACY"] [Tue Aug 18 12:59:20.966095 2026] [security2:error] [pid 123784:tid 124045] [client 20.91.215.254:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/mm.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe4wAAAH8"] [Tue Aug 18 12:59:20.980765 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:20.981216 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:20.985147 2026] [security2:error] [pid 123784:tid 123997] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe5QAAAE8"] [Tue Aug 18 12:59:20.997845 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/albin.php"] [unique_id "aoSBWGwDnJBNj2tDbYbe5gAAAF4"] [Tue Aug 18 12:59:21.071679 2026] [security2:error] [pid 123784:tid 124013] [client 66.187.6.102:57720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/secrets.json"] [unique_id "aoSBWWwDnJBNj2tDbYbe6gAAAF8"] [Tue Aug 18 12:59:21.095367 2026] [security2:error] [pid 123784:tid 123946] [client 52.173.121.69:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe6wAAABw"] [Tue Aug 18 12:59:21.098116 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/opsqt.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe7AAAAFs"] [Tue Aug 18 12:59:21.218040 2026] [security2:error] [pid 123784:tid 123953] [client 20.203.138.185:25123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe9AAAACM"] [Tue Aug 18 12:59:21.286860 2026] [security2:error] [pid 123784:tid 123954] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fw/34.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe9wAAACQ"] [Tue Aug 18 12:59:21.310784 2026] [security2:error] [pid 123784:tid 124003] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe-AAAAFU"] [Tue Aug 18 12:59:21.321068 2026] [security2:error] [pid 123784:tid 123984] [client 20.25.139.174:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe-wAAAEI"] [Tue Aug 18 12:59:21.338085 2026] [security2:error] [pid 123784:tid 124020] [client 20.250.13.23:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_AAAAGY"] [Tue Aug 18 12:59:21.341167 2026] [security2:error] [pid 123784:tid 123986] [client 172.182.200.96:7545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_QAAAEQ"] [Tue Aug 18 12:59:21.390448 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.85.180:20248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/404.php"] [unique_id "aoSBWWwDnJBNj2tDbYbe_gAAAEk"] [Tue Aug 18 12:59:21.397011 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/he.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAAAAABI"] [Tue Aug 18 12:59:21.416636 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAgAAADU"] [Tue Aug 18 12:59:21.426838 2026] [security2:error] [pid 123784:tid 123937] [client 158.23.17.4:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pu.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfAwAAABM"] [Tue Aug 18 12:59:21.460011 2026] [security2:error] [pid 123784:tid 124007] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfBQAAAFk"] [Tue Aug 18 12:59:21.489812 2026] [security2:error] [pid 123784:tid 124043] [client 20.25.139.174:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfCAAAAH0"] [Tue Aug 18 12:59:21.516193 2026] [security2:error] [pid 123784:tid 124034] [client 51.195.183.37:41748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSBWWwDnJBNj2tDbYbfCwAAAHQ"] [Tue Aug 18 12:59:21.516351 2026] [security2:error] [pid 123784:tid 124034] [client 51.195.183.37:41748] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/robots.txt"] [unique_id "aoSBWWwDnJBNj2tDbYbfCwAAAHQ"] [Tue Aug 18 12:59:21.559890 2026] [security2:error] [pid 123784:tid 123939] [client 213.35.127.232:61853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfDQAAABU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:21.573800 2026] [security2:error] [pid 123784:tid 123949] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp9.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEAAAAB8"] [Tue Aug 18 12:59:21.580078 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:21.580340 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:21.594312 2026] [security2:error] [pid 123784:tid 123963] [client 52.173.121.69:42705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hospitalhacos.org.br"] [uri "/images/security.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEgAAAC0"] [Tue Aug 18 12:59:21.600014 2026] [security2:error] [pid 123784:tid 123943] [client 20.91.215.254:10206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfEwAAABk"] [Tue Aug 18 12:59:21.627350 2026] [security2:error] [pid 123784:tid 124014] [client 196.12.128.158:62391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFAAAAGA"] [Tue Aug 18 12:59:21.627452 2026] [security2:error] [pid 123784:tid 124014] [client 196.12.128.158:62391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFAAAAGA"] [Tue Aug 18 12:59:21.628299 2026] [security2:error] [pid 123784:tid 124041] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/av.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfFQAAAHs"] [Tue Aug 18 12:59:21.701066 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfGwAAAFQ"] [Tue Aug 18 12:59:21.737073 2026] [autoindex:error] [pid 123784:tid 124018] [client 198.235.24.25:64108] AH01276: Cannot serve directory /home1/activevaluecom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:21.774388 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/zup.php73"] [unique_id "aoSBWWwDnJBNj2tDbYbfIQAAAGI"] [Tue Aug 18 12:59:21.778860 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/rymmm.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfIgAAAF4"] [Tue Aug 18 12:59:21.801873 2026] [security2:error] [pid 123784:tid 123982] [client 74.248.18.37:32118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJAAAAEA"] [Tue Aug 18 12:59:21.814860 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJQAAAFs"] [Tue Aug 18 12:59:21.856664 2026] [security2:error] [pid 123784:tid 124028] [client 20.25.139.174:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/a7.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfJwAAAG4"] [Tue Aug 18 12:59:21.859886 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/save.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfKgAAACc"] [Tue Aug 18 12:59:21.874086 2026] [security2:error] [pid 123784:tid 123848] [remote 14.194.153.54:40684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.153.194.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLQAAbzs"] [Tue Aug 18 12:59:21.877737 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:21.877999 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:21.939393 2026] [security2:error] [pid 123784:tid 123950] [client 197.184.64.235:41949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLgAAACA"] [Tue Aug 18 12:59:21.944102 2026] [security2:error] [pid 123784:tid 123950] [client 197.184.64.235:41949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWWwDnJBNj2tDbYbfLgAAACA"] [Tue Aug 18 12:59:22.027299 2026] [security2:error] [pid 123784:tid 124044] [client 172.202.39.151:44561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/chosen.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfMgAAAH4"] [Tue Aug 18 12:59:22.055417 2026] [security2:error] [pid 123784:tid 123994] [client 20.25.139.174:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/w.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNAAAAEw"] [Tue Aug 18 12:59:22.093061 2026] [security2:error] [pid 123784:tid 124008] [client 132.196.30.78:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/h.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNQAAAFo"] [Tue Aug 18 12:59:22.114334 2026] [security2:error] [pid 123784:tid 123935] [client 40.74.65.169:43047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfNgAAABE"] [Tue Aug 18 12:59:22.151007 2026] [security2:error] [pid 123784:tid 123998] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfOAAAAFA"] [Tue Aug 18 12:59:22.171314 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfOgAAAEI"] [Tue Aug 18 12:59:22.183498 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:22.183784 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:22.193101 2026] [security2:error] [pid 123784:tid 123942] [client 66.187.6.102:57708] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSBWmwDnJBNj2tDbYbfPQAAABg"] [Tue Aug 18 12:59:22.193655 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:56563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gz.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfPgAAAGU"] [Tue Aug 18 12:59:22.225877 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/path.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQQAAAEc"] [Tue Aug 18 12:59:22.236825 2026] [security2:error] [pid 123784:tid 123936] [client 20.38.3.247:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/yj09.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQgAAABI"] [Tue Aug 18 12:59:22.237683 2026] [security2:error] [pid 123784:tid 123978] [client 20.91.215.254:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/moon.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfQwAAADw"] [Tue Aug 18 12:59:22.327090 2026] [security2:error] [pid 123784:tid 123918] [client 68.155.154.236:25369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/lddxs.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfRwAAAAA"] [Tue Aug 18 12:59:22.394197 2026] [security2:error] [pid 123784:tid 124023] [client 20.25.139.174:4539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/manager.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfSgAAAGk"] [Tue Aug 18 12:59:22.404139 2026] [security2:error] [pid 123784:tid 124022] [client 4.232.94.69:21133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/theme.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfSwAAAGg"] [Tue Aug 18 12:59:22.432732 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfTgAAAD4"] [Tue Aug 18 12:59:22.458970 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.48.93:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/images.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUAAAAEo"] [Tue Aug 18 12:59:22.479419 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.85.180:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-login.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUgAAAC0"] [Tue Aug 18 12:59:22.482376 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:22.482585 2026] [security2:error] [pid 123784:tid 123975] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/images.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfUwAAADk"] [Tue Aug 18 12:59:22.482642 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:22.515115 2026] [security2:error] [pid 123784:tid 123977] [client 157.51.166.53:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVQAAADs"] [Tue Aug 18 12:59:22.516311 2026] [security2:error] [pid 123784:tid 123977] [client 157.51.166.53:56079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVQAAADs"] [Tue Aug 18 12:59:22.541545 2026] [security2:error] [pid 123784:tid 124014] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVwAAAGA"] [Tue Aug 18 12:59:22.541668 2026] [security2:error] [pid 123784:tid 124043] [client 74.248.18.37:7806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfVgAAAH0"] [Tue Aug 18 12:59:22.575024 2026] [security2:error] [pid 123784:tid 124004] [client 213.35.127.232:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfWgAAAFY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:22.606981 2026] [security2:error] [pid 123784:tid 123939] [client 20.25.139.174:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/archive.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXQAAABU"] [Tue Aug 18 12:59:22.634080 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:40330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/sf.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXgAAAB4"] [Tue Aug 18 12:59:22.638322 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:8941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ry.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfXwAAAFQ"] [Tue Aug 18 12:59:22.660330 2026] [security2:error] [pid 123784:tid 123920] [client 132.196.30.78:13674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/155.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfYAAAAAI"] [Tue Aug 18 12:59:22.677096 2026] [security2:error] [pid 123784:tid 123997] [client 66.187.6.102:57702] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/.docker/config.json"] [unique_id "aoSBWmwDnJBNj2tDbYbfYQAAAE8"] [Tue Aug 18 12:59:22.713377 2026] [security2:error] [pid 123784:tid 123981] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/df.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfZQAAAD8"] [Tue Aug 18 12:59:22.752736 2026] [security2:error] [pid 123784:tid 123969] [client 20.100.169.31:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/k.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfZwAAADM"] [Tue Aug 18 12:59:22.795428 2026] [security2:error] [pid 123784:tid 124029] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/ops.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfbAAAAG8"] [Tue Aug 18 12:59:22.801859 2026] [security2:error] [pid 123784:tid 124011] [client 132.196.30.78:14987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfbQAAAF0"] [Tue Aug 18 12:59:22.912955 2026] [security2:error] [pid 123784:tid 123953] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfcAAAACM"] [Tue Aug 18 12:59:22.927657 2026] [security2:error] [pid 123784:tid 123938] [client 20.91.215.254:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/n.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfcgAAABQ"] [Tue Aug 18 12:59:22.948970 2026] [security2:error] [pid 123784:tid 124008] [client 54.39.136.223:55818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/"] [unique_id "aoSBWmwDnJBNj2tDbYbfcwAAAFo"] [Tue Aug 18 12:59:22.949064 2026] [security2:error] [pid 123784:tid 124008] [client 54.39.136.223:55818] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "padariaeconfeitariabrasil.com.br"] [uri "/"] [unique_id "aoSBWmwDnJBNj2tDbYbfcwAAAFo"] [Tue Aug 18 12:59:22.960945 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/w1.php"] [unique_id "aoSBWmwDnJBNj2tDbYbfdgAAAEg"] [Tue Aug 18 12:59:23.035995 2026] [security2:error] [pid 123784:tid 123951] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfewAAACE"] [Tue Aug 18 12:59:23.084787 2026] [security2:error] [pid 123784:tid 123991] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/coffexium.php"] [unique_id "aoSBW2wDnJBNj2tDbYbffgAAAEk"] [Tue Aug 18 12:59:23.111046 2026] [security2:error] [pid 123784:tid 123978] [client 20.104.85.180:13070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfgQAAADw"] [Tue Aug 18 12:59:23.125756 2026] [security2:error] [pid 123784:tid 123935] [client 20.25.139.174:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/bless.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfggAAABE"] [Tue Aug 18 12:59:23.135632 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:14077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nf.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfhAAAACU"] [Tue Aug 18 12:59:23.178698 2026] [autoindex:error] [pid 123784:tid 123871] [remote 23.80.142.158:59948] AH01276: Cannot serve directory /home3/bergon98/contabiltax.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:23.238224 2026] [security2:error] [pid 123784:tid 124003] [client 74.248.18.37:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfiQAAAFU"] [Tue Aug 18 12:59:23.278127 2026] [security2:error] [pid 123784:tid 123998] [client 132.196.30.78:22157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/96i.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfigAAAFA"] [Tue Aug 18 12:59:23.280330 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfiwAAACI"] [Tue Aug 18 12:59:23.301836 2026] [security2:error] [pid 123784:tid 123885] [remote 162.214.205.212:44812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ezycolor.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfjQAAbWA"] [Tue Aug 18 12:59:23.314186 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/usr.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfjgAAAHg"] [Tue Aug 18 12:59:23.404928 2026] [security2:error] [pid 123784:tid 123892] [remote 162.214.205.212:44818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflAAARWc"] [Tue Aug 18 12:59:23.412924 2026] [security2:error] [pid 123784:tid 123939] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflgAAABU"] [Tue Aug 18 12:59:23.415107 2026] [security2:error] [pid 123784:tid 123941] [client 132.196.30.78:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/a7.php"] [unique_id "aoSBW2wDnJBNj2tDbYbflwAAABc"] [Tue Aug 18 12:59:23.428712 2026] [security2:error] [pid 123784:tid 124042] [client 20.251.48.93:57515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/ops.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfmgAAAHw"] [Tue Aug 18 12:59:23.449588 2026] [security2:error] [pid 123784:tid 123924] [client 20.203.138.185:24955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wpo.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfmwAAAAY"] [Tue Aug 18 12:59:23.471063 2026] [security2:error] [pid 123784:tid 124045] [client 40.74.65.169:20344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfnAAAAH8"] [Tue Aug 18 12:59:23.485729 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.154.236:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zjggu.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfnQAAAEY"] [Tue Aug 18 12:59:23.545141 2026] [autoindex:error] [pid 123784:tid 124006] [client 20.25.139.174:4482] AH01276: Cannot serve directory /home3/cadema/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:23.560457 2026] [security2:error] [pid 123784:tid 123932] [client 20.91.215.254:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/nc4.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfoQAAAA4"] [Tue Aug 18 12:59:23.563409 2026] [security2:error] [pid 123784:tid 123894] [remote 156.59.198.135:36672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mempel.com.br"] [uri "/wp-content/uploads/2023/01/work-pdf.pdf"] [unique_id "aoSBW2wDnJBNj2tDbYbfogAAKmk"] [Tue Aug 18 12:59:23.570545 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xv.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfowAAAA8"] [Tue Aug 18 12:59:23.597976 2026] [security2:error] [pid 123784:tid 123967] [client 213.35.127.232:62292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfpgAAADE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:23.617800 2026] [security2:error] [pid 123784:tid 123983] [client 66.187.6.102:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.6.187.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pinceisroma.com.br"] [uri "/wp-config.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfpwAAAEE"] [Tue Aug 18 12:59:23.631815 2026] [security2:error] [pid 123784:tid 123973] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqAAAADc"] [Tue Aug 18 12:59:23.636790 2026] [access_compat:error] [pid 123784:tid 124010] [client 52.167.144.64:39768] AH01797: client denied by server configuration: /home2/maxxbox/public_html/robots.txt [Tue Aug 18 12:59:23.642013 2026] [security2:error] [pid 123784:tid 123963] [client 20.100.169.31:28413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqgAAAC0"] [Tue Aug 18 12:59:23.647647 2026] [security2:error] [pid 123784:tid 124040] [client 86.120.159.145:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqwAAAHo"] [Tue Aug 18 12:59:23.648095 2026] [security2:error] [pid 123784:tid 124040] [client 86.120.159.145:62836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfqwAAAHo"] [Tue Aug 18 12:59:23.685117 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:23.685387 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:23.706074 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/sagax1.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfsgAAAEA"] [Tue Aug 18 12:59:23.708133 2026] [security2:error] [pid 123784:tid 123953] [client 20.25.139.174:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-login.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftQAAACM"] [Tue Aug 18 12:59:23.741971 2026] [security2:error] [pid 123784:tid 124008] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/sf.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftgAAAFo"] [Tue Aug 18 12:59:23.765068 2026] [security2:error] [pid 123784:tid 123954] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBW2wDnJBNj2tDbYbftwAAACQ"] [Tue Aug 18 12:59:23.767955 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:34003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pm.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfuAAAAA0"] [Tue Aug 18 12:59:23.845445 2026] [security2:error] [pid 123784:tid 123965] [client 66.187.6.102:57684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "pinceisroma.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSBW2wDnJBNj2tDbYbfvQAAAC8"] [Tue Aug 18 12:59:23.860125 2026] [security2:error] [pid 123784:tid 123976] [client 20.127.136.245:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/inputs.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfvgAAADo"] [Tue Aug 18 12:59:23.872924 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.154.236:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfwAAAAEc"] [Tue Aug 18 12:59:23.946601 2026] [security2:error] [pid 123784:tid 123937] [client 20.38.3.247:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/scxy.php"] [unique_id "aoSBW2wDnJBNj2tDbYbfwQAAABM"] [Tue Aug 18 12:59:23.992122 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:23.992415 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:24.006513 2026] [security2:error] [pid 123784:tid 124023] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfxAAAAGk"] [Tue Aug 18 12:59:24.015860 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:14981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/as.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfxQAAAEw"] [Tue Aug 18 12:59:24.062890 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:53953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzAAAAAU"] [Tue Aug 18 12:59:24.062999 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:53953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzAAAAAU"] [Tue Aug 18 12:59:24.064306 2026] [security2:error] [pid 123784:tid 123945] [client 4.232.94.69:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzQAAABs"] [Tue Aug 18 12:59:24.077336 2026] [security2:error] [pid 123784:tid 123975] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/k.php"] [unique_id "aoSBXGwDnJBNj2tDbYbfzgAAADk"] [Tue Aug 18 12:59:24.103995 2026] [security2:error] [pid 123784:tid 123978] [client 132.196.30.78:14598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/manager.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0AAAADw"] [Tue Aug 18 12:59:24.107821 2026] [security2:error] [pid 123784:tid 123935] [client 74.248.18.37:7783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0QAAABE"] [Tue Aug 18 12:59:24.163331 2026] [security2:error] [pid 123784:tid 124004] [client 20.38.3.247:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/mac.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf0wAAAFY"] [Tue Aug 18 12:59:24.168497 2026] [security2:error] [pid 123784:tid 123987] [client 40.74.65.169:38809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/i.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1AAAAEU"] [Tue Aug 18 12:59:24.186258 2026] [security2:error] [pid 123784:tid 124042] [client 20.203.138.185:10670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/a1vx.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1QAAAHw"] [Tue Aug 18 12:59:24.217344 2026] [security2:error] [pid 123784:tid 124025] [client 20.25.139.174:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/default.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf1wAAAGs"] [Tue Aug 18 12:59:24.222740 2026] [security2:error] [pid 123784:tid 123944] [client 20.91.215.254:10188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/new.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf2AAAABo"] [Tue Aug 18 12:59:24.226788 2026] [security2:error] [pid 123784:tid 124027] [client 20.25.139.174:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wpc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf2QAAAG0"] [Tue Aug 18 12:59:24.276911 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:47654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mx.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf3wAAAF4"] [Tue Aug 18 12:59:24.287616 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:24.287902 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:24.303287 2026] [security2:error] [pid 123784:tid 123941] [client 20.127.136.245:28090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/admin.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf4gAAABc"] [Tue Aug 18 12:59:24.372136 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5AAAAAo"] [Tue Aug 18 12:59:24.387623 2026] [security2:error] [pid 123784:tid 124006] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/css/database.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5QAAAFg"] [Tue Aug 18 12:59:24.389040 2026] [security2:error] [pid 123784:tid 123929] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/82.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf5gAAAAs"] [Tue Aug 18 12:59:24.413119 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf6gAAACc"] [Tue Aug 18 12:59:24.471266 2026] [security2:error] [pid 123784:tid 123796] [remote 103.56.163.133:58862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf6wAAEAc"] [Tue Aug 18 12:59:24.475561 2026] [security2:error] [pid 123784:tid 124024] [client 20.104.85.180:28648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wso.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf7AAAAGo"] [Tue Aug 18 12:59:24.503466 2026] [security2:error] [pid 123784:tid 123922] [client 20.251.48.93:9932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/coffexium.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf7QAAAAQ"] [Tue Aug 18 12:59:24.562980 2026] [security2:error] [pid 123784:tid 123993] [client 20.215.241.237:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/chosen.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf8AAAAEs"] [Tue Aug 18 12:59:24.589552 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:24.589869 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:24.613864 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf9QAAAFE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:24.669948 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/privdayz.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf9wAAAC8"] [Tue Aug 18 12:59:24.679442 2026] [security2:error] [pid 123784:tid 123971] [client 132.196.30.78:13653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/w1.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf-AAAADU"] [Tue Aug 18 12:59:24.685886 2026] [security2:error] [pid 123784:tid 123942] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/dex.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf-gAAABg"] [Tue Aug 18 12:59:24.733899 2026] [security2:error] [pid 123784:tid 123936] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBXGwDnJBNj2tDbYbf_AAAABI"] [Tue Aug 18 12:59:24.787004 2026] [security2:error] [pid 123784:tid 124026] [client 20.25.139.174:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/i.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgAgAAAGw"] [Tue Aug 18 12:59:24.788596 2026] [security2:error] [pid 123784:tid 124017] [client 20.25.139.174:4670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/fone1.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgAwAAAGM"] [Tue Aug 18 12:59:24.802127 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgBAAAAG8"] [Tue Aug 18 12:59:24.874961 2026] [security2:error] [pid 123784:tid 124015] [client 20.127.136.245:28049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/goods.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgBwAAAGE"] [Tue Aug 18 12:59:24.878805 2026] [security2:error] [pid 123784:tid 123968] [client 132.196.30.78:14978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/min.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCAAAADI"] [Tue Aug 18 12:59:24.880082 2026] [security2:error] [pid 123784:tid 123949] [client 40.74.65.169:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/abcd.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCgAAAB8"] [Tue Aug 18 12:59:24.881595 2026] [security2:error] [pid 123784:tid 124044] [client 20.91.215.254:10200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/packed.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgCwAAAH4"] [Tue Aug 18 12:59:24.966374 2026] [security2:error] [pid 123784:tid 123927] [client 74.248.18.37:7786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgDwAAAAk"] [Tue Aug 18 12:59:24.971621 2026] [security2:error] [pid 123784:tid 124042] [client 20.38.3.247:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgEAAAAHw"] [Tue Aug 18 12:59:24.984970 2026] [security2:error] [pid 123784:tid 124032] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/puc.php"] [unique_id "aoSBXGwDnJBNj2tDbYbgEQAAAHI"] [Tue Aug 18 12:59:25.004199 2026] [security2:error] [pid 123784:tid 124018] [client 20.203.138.185:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ty.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFQAAAGQ"] [Tue Aug 18 12:59:25.004259 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:32532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dr.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFAAAAGs"] [Tue Aug 18 12:59:25.036991 2026] [security2:error] [pid 123784:tid 124027] [client 20.51.153.15:7275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgFwAAAG0"] [Tue Aug 18 12:59:25.074088 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.13.23:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/info.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgGgAAAHM"] [Tue Aug 18 12:59:25.099078 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgHAAAADg"] [Tue Aug 18 12:59:25.113746 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:47677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/45.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgHQAAABw"] [Tue Aug 18 12:59:25.191079 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:25.191358 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:25.199760 2026] [security2:error] [pid 123784:tid 123929] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wg459o.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgIwAAAAs"] [Tue Aug 18 12:59:25.200766 2026] [security2:error] [pid 123784:tid 124002] [client 79.127.164.8:41938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/tables.bak"] [unique_id "aoSBXWwDnJBNj2tDbYbgIgAAAFQ"], referer: https://medihub.com.br/tables.bak [Tue Aug 18 12:59:25.202482 2026] [security2:error] [pid 123784:tid 124034] [client 68.221.73.131:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/k.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgJQAAAHQ"] [Tue Aug 18 12:59:25.296705 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.154.236:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/kopyw.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgKQAAADY"] [Tue Aug 18 12:59:25.317619 2026] [security2:error] [pid 123784:tid 123925] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/inso.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgKgAAAAc"] [Tue Aug 18 12:59:25.340252 2026] [security2:error] [pid 123784:tid 124006] [client 20.127.136.245:28077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/file.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgLQAAAFg"] [Tue Aug 18 12:59:25.352657 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/dirs.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMAAAAFc"] [Tue Aug 18 12:59:25.371569 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.85.180:52586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/sf.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMQAAACQ"] [Tue Aug 18 12:59:25.379164 2026] [security2:error] [pid 123784:tid 123931] [client 172.202.39.151:44518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/info.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgMgAAAA0"] [Tue Aug 18 12:59:25.424479 2026] [security2:error] [pid 123784:tid 123956] [client 20.25.139.174:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ncx.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgNAAAACY"] [Tue Aug 18 12:59:25.436977 2026] [autoindex:error] [pid 123784:tid 123981] [client 20.25.139.174:4505] AH01276: Cannot serve directory /home3/cadema/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:25.443550 2026] [autoindex:error] [pid 123784:tid 124009] [client 132.196.30.78:14983] AH01276: Cannot serve directory /home3/cadema/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:25.458689 2026] [security2:error] [pid 123784:tid 124035] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgOAAAAHU"] [Tue Aug 18 12:59:25.494685 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:25.495133 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:25.566214 2026] [security2:error] [pid 123784:tid 124017] [client 40.74.65.169:19515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgQQAAAGM"] [Tue Aug 18 12:59:25.591912 2026] [security2:error] [pid 123784:tid 123979] [client 132.196.30.78:14983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-login.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgRAAAAD0"] [Tue Aug 18 12:59:25.624173 2026] [security2:error] [pid 123784:tid 123998] [client 20.38.3.247:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgRwAAAFA"] [Tue Aug 18 12:59:25.626000 2026] [security2:error] [pid 123784:tid 123921] [client 20.25.139.174:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSAAAAAM"] [Tue Aug 18 12:59:25.631797 2026] [security2:error] [pid 123784:tid 123992] [client 213.35.127.232:62744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSQAAAEo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:25.638186 2026] [security2:error] [pid 123784:tid 124015] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/aa.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSgAAAGE"] [Tue Aug 18 12:59:25.682997 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fresh.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgSwAAADI"] [Tue Aug 18 12:59:25.699332 2026] [security2:error] [pid 123784:tid 124003] [client 66.187.6.102:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBXWwDnJBNj2tDbYbgTwAAAFU"] [Tue Aug 18 12:59:25.699451 2026] [security2:error] [pid 123784:tid 124003] [client 66.187.6.102:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/api/v1/settings"] [unique_id "aoSBXWwDnJBNj2tDbYbgTwAAAFU"] [Tue Aug 18 12:59:25.713041 2026] [security2:error] [pid 123784:tid 123971] [client 74.248.18.37:7605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUAAAADU"] [Tue Aug 18 12:59:25.718441 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.154.236:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zznmg.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUQAAADk"] [Tue Aug 18 12:59:25.723912 2026] [security2:error] [pid 123784:tid 124038] [client 20.91.215.254:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/plugin.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUgAAAHg"] [Tue Aug 18 12:59:25.745229 2026] [security2:error] [pid 123784:tid 124001] [client 20.203.138.185:25498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/vgtyu.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgUwAAAFM"] [Tue Aug 18 12:59:25.802791 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:25.803361 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:25.808166 2026] [authz_core:error] [pid 123784:tid 123828] [remote 57.141.22.120:48344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:25.808436 2026] [authz_core:error] [pid 123784:tid 123828] [remote 57.141.22.120:48344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:25.822166 2026] [security2:error] [pid 123784:tid 124036] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgWQAAAHY"] [Tue Aug 18 12:59:25.844228 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:57253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ts.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgWwAAAF4"] [Tue Aug 18 12:59:25.894874 2026] [security2:error] [pid 123784:tid 123983] [client 37.40.227.74:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgXwAAAEE"] [Tue Aug 18 12:59:25.899123 2026] [security2:error] [pid 123784:tid 123983] [client 37.40.227.74:57196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgXwAAAEE"] [Tue Aug 18 12:59:25.922799 2026] [security2:error] [pid 123784:tid 123987] [client 20.127.136.245:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/adminfuns.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgYAAAAEU"] [Tue Aug 18 12:59:25.929189 2026] [security2:error] [pid 123784:tid 123988] [client 66.187.6.102:51566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/openapi.json"] [unique_id "aoSBXWwDnJBNj2tDbYbgYQAAAEY"] [Tue Aug 18 12:59:25.929274 2026] [security2:error] [pid 123784:tid 123988] [client 66.187.6.102:51566] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/openapi.json"] [unique_id "aoSBXWwDnJBNj2tDbYbgYQAAAEY"] [Tue Aug 18 12:59:25.957676 2026] [security2:error] [pid 123784:tid 124011] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/img.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgYgAAAF0"] [Tue Aug 18 12:59:25.962940 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:40413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wy.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZAAAAAs"] [Tue Aug 18 12:59:25.965211 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mifta.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZQAAAHQ"] [Tue Aug 18 12:59:25.978064 2026] [security2:error] [pid 123784:tid 123960] [client 20.51.153.15:7271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/admin404.php"] [unique_id "aoSBXWwDnJBNj2tDbYbgZgAAACo"] [Tue Aug 18 12:59:26.025260 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.13.23:7232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/a.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgZwAAAAI"] [Tue Aug 18 12:59:26.051519 2026] [security2:error] [pid 123784:tid 123941] [client 20.25.139.174:4529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgaAAAABc"] [Tue Aug 18 12:59:26.098925 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgbAAAAAU"] [Tue Aug 18 12:59:26.099075 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:26.099535 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:26.187357 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcAAAADc"] [Tue Aug 18 12:59:26.222513 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/default.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcQAAAFQ"] [Tue Aug 18 12:59:26.228143 2026] [security2:error] [pid 123784:tid 124009] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgcgAAAFs"] [Tue Aug 18 12:59:26.235306 2026] [security2:error] [pid 123784:tid 123919] [client 68.155.154.236:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdAAAAAE"] [Tue Aug 18 12:59:26.238947 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdQAAAD4"] [Tue Aug 18 12:59:26.241604 2026] [security2:error] [pid 123784:tid 124028] [client 132.196.30.78:14985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/php8.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdgAAAG4"] [Tue Aug 18 12:59:26.244020 2026] [security2:error] [pid 123784:tid 123967] [client 40.74.65.169:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgdwAAADE"] [Tue Aug 18 12:59:26.259136 2026] [security2:error] [pid 123784:tid 123958] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/222.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgeAAAACg"] [Tue Aug 18 12:59:26.276150 2026] [security2:error] [pid 123784:tid 124023] [client 103.120.71.157:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgegAAAGk"] [Tue Aug 18 12:59:26.276340 2026] [security2:error] [pid 123784:tid 124023] [client 103.120.71.157:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgegAAAGk"] [Tue Aug 18 12:59:26.293351 2026] [security2:error] [pid 123784:tid 124030] [client 103.184.169.37:42590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgewAAAHA"] [Tue Aug 18 12:59:26.293525 2026] [security2:error] [pid 123784:tid 124030] [client 103.184.169.37:42590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgewAAAHA"] [Tue Aug 18 12:59:26.294907 2026] [security2:error] [pid 123784:tid 123937] [client 20.38.3.247:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/blurbs.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfAAAABM"] [Tue Aug 18 12:59:26.305957 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/loading.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfgAAAG8"] [Tue Aug 18 12:59:26.311798 2026] [security2:error] [pid 123784:tid 123976] [client 20.251.48.93:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgfwAAADo"] [Tue Aug 18 12:59:26.325755 2026] [security2:error] [pid 123784:tid 124008] [client 4.232.94.69:21122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bi.php"] [unique_id "aoSBXmwDnJBNj2tDbYbggQAAAFo"] [Tue Aug 18 12:59:26.391322 2026] [security2:error] [pid 123784:tid 123955] [client 66.187.6.102:51568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "pinceisroma.com.br"] [uri "/id_rsa"] [unique_id "aoSBXmwDnJBNj2tDbYbghgAAACU"] [Tue Aug 18 12:59:26.410740 2026] [security2:error] [pid 123784:tid 123943] [client 20.127.136.245:28499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/404.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgjAAAABk"] [Tue Aug 18 12:59:26.415155 2026] [security2:error] [pid 123784:tid 123945] [client 185.198.240.227:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgjQAAABs"] [Tue Aug 18 12:59:26.430414 2026] [security2:error] [pid 123784:tid 123948] [client 216.244.66.243:36666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/buser777.cc-1/"] [unique_id "aoSBXmwDnJBNj2tDbYbglQAAAB4"] [Tue Aug 18 12:59:26.430516 2026] [security2:error] [pid 123784:tid 123948] [client 216.244.66.243:36666] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/buser777.cc-1/"] [unique_id "aoSBXmwDnJBNj2tDbYbglQAAAB4"] [Tue Aug 18 12:59:26.507100 2026] [security2:error] [pid 123784:tid 124036] [client 20.203.138.185:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mans.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgmwAAAHY"] [Tue Aug 18 12:59:26.521637 2026] [security2:error] [pid 123784:tid 123938] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/index2.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgngAAABQ"] [Tue Aug 18 12:59:26.528792 2026] [security2:error] [pid 123784:tid 123994] [client 20.100.169.31:12656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/ww5.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgnwAAAEw"] [Tue Aug 18 12:59:26.530556 2026] [security2:error] [pid 123784:tid 124033] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgmQAAcyw"] [Tue Aug 18 12:59:26.540676 2026] [security2:error] [pid 123784:tid 124022] [client 74.248.18.37:7761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgoAAAAGg"] [Tue Aug 18 12:59:26.543329 2026] [security2:error] [pid 123784:tid 124007] [client 20.51.153.15:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/conn-test.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgoQAAAFk"] [Tue Aug 18 12:59:26.551874 2026] [security2:error] [pid 123784:tid 123952] [client 20.25.139.174:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wso.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgowAAACI"] [Tue Aug 18 12:59:26.577249 2026] [security2:error] [pid 123784:tid 124034] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/key.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpAAAAHQ"] [Tue Aug 18 12:59:26.578560 2026] [security2:error] [pid 123784:tid 124013] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpQAAAF8"] [Tue Aug 18 12:59:26.599688 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:10192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/public/moon.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgpgAAAAI"] [Tue Aug 18 12:59:26.613544 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/f.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgqAAAABc"] [Tue Aug 18 12:59:26.647743 2026] [security2:error] [pid 123784:tid 123979] [client 213.35.127.232:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgqwAAAD0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:26.694321 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:26.694592 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:26.709067 2026] [security2:error] [pid 123784:tid 123981] [client 138.36.100.162:41486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgrwAAAD8"] [Tue Aug 18 12:59:26.709183 2026] [security2:error] [pid 123784:tid 123981] [client 138.36.100.162:41486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgrwAAAD8"] [Tue Aug 18 12:59:26.722415 2026] [security2:error] [pid 123784:tid 123988] [client 20.25.139.174:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgsAAAAEY"] [Tue Aug 18 12:59:26.746405 2026] [security2:error] [pid 123784:tid 124006] [client 20.38.3.247:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/bajah.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgsgAAAFg"] [Tue Aug 18 12:59:26.766677 2026] [security2:error] [pid 123784:tid 124044] [client 66.187.6.102:51568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/app/.git/HEAD"] [unique_id "aoSBXmwDnJBNj2tDbYbgswAAAH4"] [Tue Aug 18 12:59:26.766793 2026] [security2:error] [pid 123784:tid 124044] [client 66.187.6.102:51568] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/app/.git/HEAD"] [unique_id "aoSBXmwDnJBNj2tDbYbgswAAAH4"] [Tue Aug 18 12:59:26.794173 2026] [security2:error] [pid 123784:tid 123951] [client 149.34.210.141:49176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtgAAACE"] [Tue Aug 18 12:59:26.795079 2026] [security2:error] [pid 123784:tid 123926] [client 132.196.30.78:13693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtwAAAAg"] [Tue Aug 18 12:59:26.801863 2026] [security2:error] [pid 123784:tid 124017] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/8.php"] [unique_id "aoSBXmwDnJBNj2tDbYbguAAAAGM"] [Tue Aug 18 12:59:26.807457 2026] [security2:error] [pid 123784:tid 123950] [client 132.196.30.78:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/i.php"] [unique_id "aoSBXmwDnJBNj2tDbYbguQAAACA"] [Tue Aug 18 12:59:26.825221 2026] [security2:error] [pid 123784:tid 123985] [client 20.51.153.15:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/evil.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgugAAAEM"] [Tue Aug 18 12:59:26.876627 2026] [security2:error] [pid 123784:tid 124015] [client 68.221.73.131:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/82.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgwAAAAGE"] [Tue Aug 18 12:59:26.900105 2026] [security2:error] [pid 123784:tid 123953] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/chosen.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgwwAAACM"] [Tue Aug 18 12:59:26.923706 2026] [security2:error] [pid 123784:tid 124009] [client 20.127.136.245:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wk/index.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxAAAAFs"] [Tue Aug 18 12:59:26.935928 2026] [security2:error] [pid 123784:tid 123940] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxQAAABY"] [Tue Aug 18 12:59:26.938913 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgxgAAABk"] [Tue Aug 18 12:59:26.996338 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:26.996610 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:27.056969 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.154.236:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBX2wDnJBNj2tDbYbgzwAAAE8"] [Tue Aug 18 12:59:27.059257 2026] [security2:error] [pid 123784:tid 123951] [client 149.34.210.141:49176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBXmwDnJBNj2tDbYbgtgAAACE"] [Tue Aug 18 12:59:27.087241 2026] [security2:error] [pid 123784:tid 123974] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/images.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg0AAAADg"] [Tue Aug 18 12:59:27.098513 2026] [security2:error] [pid 123784:tid 123986] [client 20.25.139.174:4526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/zup.php73"] [unique_id "aoSBX2wDnJBNj2tDbYbg0gAAAEQ"] [Tue Aug 18 12:59:27.126849 2026] [security2:error] [pid 123784:tid 124016] [client 20.51.153.15:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-key.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg0wAAAGI"] [Tue Aug 18 12:59:27.141652 2026] [security2:error] [pid 123784:tid 123987] [client 20.38.3.247:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/domvf.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1AAAAEU"] [Tue Aug 18 12:59:27.155308 2026] [security2:error] [pid 123784:tid 123918] [client 157.20.138.62:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1wAAAAA"] [Tue Aug 18 12:59:27.155431 2026] [security2:error] [pid 123784:tid 123918] [client 157.20.138.62:55786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg1wAAAAA"] [Tue Aug 18 12:59:27.239341 2026] [security2:error] [pid 123784:tid 124013] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/wpxml.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg2gAAAF8"] [Tue Aug 18 12:59:27.245921 2026] [security2:error] [pid 123784:tid 123991] [client 20.215.241.237:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/wpxml.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg2wAAAEk"] [Tue Aug 18 12:59:27.246912 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/public/storage.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3AAAAGQ"] [Tue Aug 18 12:59:27.260230 2026] [security2:error] [pid 123784:tid 124012] [client 20.25.139.174:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/NewFile.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3QAAAF4"] [Tue Aug 18 12:59:27.268740 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3gAAAB4"] [Tue Aug 18 12:59:27.271816 2026] [security2:error] [pid 123784:tid 124005] [client 213.202.253.4:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg3wAAAFc"], referer: www.google.com [Tue Aug 18 12:59:27.290905 2026] [security2:error] [pid 123784:tid 123971] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg4QAAADU"] [Tue Aug 18 12:59:27.297630 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:27.297909 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:27.308214 2026] [security2:error] [pid 123784:tid 123941] [client 20.203.138.185:24913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/co.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg4gAAABc"] [Tue Aug 18 12:59:27.373514 2026] [security2:error] [pid 123784:tid 123982] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/a.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg5gAAAEA"] [Tue Aug 18 12:59:27.393254 2026] [security2:error] [pid 123784:tid 124034] [client 20.127.136.245:28046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/about.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg5wAAAHQ"] [Tue Aug 18 12:59:27.466247 2026] [security2:error] [pid 123784:tid 124028] [client 20.51.153.15:7259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpcheck.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg6wAAAG4"] [Tue Aug 18 12:59:27.541475 2026] [security2:error] [pid 123784:tid 123956] [client 178.153.171.161:55221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg8QAAACY"] [Tue Aug 18 12:59:27.541597 2026] [security2:error] [pid 123784:tid 123956] [client 178.153.171.161:55221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg8QAAACY"] [Tue Aug 18 12:59:27.563006 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg9AAAAGo"] [Tue Aug 18 12:59:27.570120 2026] [autoindex:error] [pid 123784:tid 123934] [client 132.196.30.78:14989] AH01276: Cannot serve directory /home3/cadema/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:27.589852 2026] [security2:error] [pid 123784:tid 123950] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/file1221.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg9QAAACA"] [Tue Aug 18 12:59:27.617619 2026] [security2:error] [pid 123784:tid 123999] [client 5.31.227.224:30460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-gAAAFE"] [Tue Aug 18 12:59:27.622335 2026] [security2:error] [pid 123784:tid 123999] [client 5.31.227.224:30460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-gAAAFE"] [Tue Aug 18 12:59:27.639221 2026] [security2:error] [pid 123784:tid 123936] [client 20.25.139.174:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/k.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg-wAAABI"] [Tue Aug 18 12:59:27.654223 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_QAAADI"] [Tue Aug 18 12:59:27.659156 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_gAAAE0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:27.666182 2026] [security2:error] [pid 123784:tid 124026] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSBX2wDnJBNj2tDbYbg_wAAAGw"] [Tue Aug 18 12:59:27.670918 2026] [security2:error] [pid 123784:tid 123946] [client 20.38.3.247:34984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fpwch.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhAAAAABw"] [Tue Aug 18 12:59:27.682205 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:25352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/oivcl.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhAQAAACQ"] [Tue Aug 18 12:59:27.767598 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:40415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/30.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhBwAAACw"] [Tue Aug 18 12:59:27.770063 2026] [security2:error] [pid 123784:tid 124043] [client 132.196.30.78:14989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCAAAAH0"] [Tue Aug 18 12:59:27.772557 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:34027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/53.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCQAAACU"] [Tue Aug 18 12:59:27.783195 2026] [security2:error] [pid 123784:tid 124042] [client 20.51.153.15:7268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/mimes.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhCwAAAHw"] [Tue Aug 18 12:59:27.823073 2026] [security2:error] [pid 123784:tid 123930] [client 20.25.139.174:4531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhDgAAAAw"] [Tue Aug 18 12:59:27.879182 2026] [security2:error] [pid 123784:tid 123943] [client 20.127.136.245:28071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/term.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhFAAAABk"] [Tue Aug 18 12:59:27.905162 2026] [security2:error] [pid 123784:tid 124014] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/nox.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhFwAAAGA"] [Tue Aug 18 12:59:27.905303 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:27.905561 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:27.918552 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/radio.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhGAAAACM"] [Tue Aug 18 12:59:27.946002 2026] [security2:error] [pid 123784:tid 124007] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/99.php"] [unique_id "aoSBX2wDnJBNj2tDbYbhGwAAAFk"] [Tue Aug 18 12:59:28.046422 2026] [security2:error] [pid 123784:tid 123906] [remote 162.214.96.231:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhHwAAMHU"] [Tue Aug 18 12:59:28.060850 2026] [security2:error] [pid 123784:tid 124005] [client 68.155.154.236:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zugvi.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhIgAAAFc"] [Tue Aug 18 12:59:28.061975 2026] [security2:error] [pid 123784:tid 123963] [client 20.51.153.15:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fraie1p4.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhIwAAAC0"] [Tue Aug 18 12:59:28.122191 2026] [security2:error] [pid 123784:tid 123923] [client 20.203.138.185:33236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/btx25.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhJgAAAAU"] [Tue Aug 18 12:59:28.154491 2026] [security2:error] [pid 123784:tid 123980] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhKgAAAD4"] [Tue Aug 18 12:59:28.170506 2026] [security2:error] [pid 123784:tid 123918] [client 74.248.18.37:32113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhKwAAAAA"] [Tue Aug 18 12:59:28.192608 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pu.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLAAAAEA"] [Tue Aug 18 12:59:28.202887 2026] [security2:error] [pid 123784:tid 123924] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/akismet.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLgAAAAY"] [Tue Aug 18 12:59:28.202955 2026] [security2:error] [pid 123784:tid 123978] [client 20.25.139.174:4646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhLQAAADw"] [Tue Aug 18 12:59:28.252748 2026] [security2:error] [pid 123784:tid 123981] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yup.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhMQAAAD8"] [Tue Aug 18 12:59:28.268041 2026] [security2:error] [pid 123784:tid 123932] [client 132.196.30.78:14995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhMgAAAA4"] [Tue Aug 18 12:59:28.299283 2026] [security2:error] [pid 123784:tid 124025] [client 40.74.65.169:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/simple.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhNgAAAGs"] [Tue Aug 18 12:59:28.341923 2026] [security2:error] [pid 123784:tid 123964] [client 223.185.37.47:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOAAAAC4"] [Tue Aug 18 12:59:28.345863 2026] [security2:error] [pid 123784:tid 123964] [client 223.185.37.47:14604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOAAAAC4"] [Tue Aug 18 12:59:28.346151 2026] [security2:error] [pid 123784:tid 123925] [client 132.196.30.78:14632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOQAAAAc"] [Tue Aug 18 12:59:28.365379 2026] [security2:error] [pid 123784:tid 124009] [client 85.154.68.202:19301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOwAAAFs"] [Tue Aug 18 12:59:28.365403 2026] [security2:error] [pid 123784:tid 123938] [client 20.25.139.174:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOgAAABQ"] [Tue Aug 18 12:59:28.365499 2026] [security2:error] [pid 123784:tid 124009] [client 85.154.68.202:19301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhOwAAAFs"] [Tue Aug 18 12:59:28.385332 2026] [security2:error] [pid 123784:tid 124024] [client 20.51.153.15:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/pqr.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhPgAAAGo"] [Tue Aug 18 12:59:28.435729 2026] [security2:error] [pid 123784:tid 123999] [client 68.155.154.236:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wsrer.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhQQAAAFE"] [Tue Aug 18 12:59:28.448246 2026] [security2:error] [pid 123784:tid 124015] [client 20.38.3.247:35000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/adminner.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhQgAAAGE"] [Tue Aug 18 12:59:28.505881 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:28.506329 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:28.531944 2026] [security2:error] [pid 123784:tid 123935] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhRwAAABE"] [Tue Aug 18 12:59:28.532257 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/222.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSAAAABY"] [Tue Aug 18 12:59:28.538590 2026] [security2:error] [pid 123784:tid 124021] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/admin.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSQAAAGc"] [Tue Aug 18 12:59:28.551177 2026] [security2:error] [pid 123784:tid 124038] [client 20.251.48.93:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/sf.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSgAAAHg"] [Tue Aug 18 12:59:28.556407 2026] [security2:error] [pid 123784:tid 123945] [client 20.104.85.180:20237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/index/function.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhSwAAABs"] [Tue Aug 18 12:59:28.566076 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:13410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/root.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhTQAAAHE"] [Tue Aug 18 12:59:28.671362 2026] [security2:error] [pid 123784:tid 124030] [client 213.35.127.232:63417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhUAAAAHA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:28.695980 2026] [security2:error] [pid 123784:tid 123986] [client 20.51.153.15:7286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/lmfi2.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhUwAAAEQ"] [Tue Aug 18 12:59:28.748009 2026] [security2:error] [pid 123784:tid 124020] [client 20.100.169.31:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/2.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhWwAAAGY"] [Tue Aug 18 12:59:28.789320 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.13.23:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/chosen.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhXwAAAE0"] [Tue Aug 18 12:59:28.805781 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:28.806069 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:28.819456 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhYwAAAEI"] [Tue Aug 18 12:59:28.861823 2026] [security2:error] [pid 123784:tid 123930] [client 74.248.18.37:26451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhaAAAAAw"] [Tue Aug 18 12:59:28.866175 2026] [security2:error] [pid 123784:tid 123948] [client 74.249.206.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "desenvolvimento.condominiopratico.com.br"] [uri "/ajax.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhaQAAAB4"] [Tue Aug 18 12:59:28.900215 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhbgAAAAU"] [Tue Aug 18 12:59:28.938083 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.154.236:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhbwAAAD4"] [Tue Aug 18 12:59:28.938416 2026] [security2:error] [pid 123784:tid 123996] [client 132.196.30.78:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhcAAAAE4"] [Tue Aug 18 12:59:28.971858 2026] [security2:error] [pid 123784:tid 124018] [client 20.25.139.174:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/themes.php"] [unique_id "aoSBYGwDnJBNj2tDbYbhdgAAAGQ"] [Tue Aug 18 12:59:28.989762 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/info.php"] [unique_id "aoSBYGwDnJBNj2tDbYbheAAAAEo"] [Tue Aug 18 12:59:29.050795 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/info2.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhfQAAAEY"] [Tue Aug 18 12:59:29.078262 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:33431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lq.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhfwAAAC4"] [Tue Aug 18 12:59:29.094738 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ioxi-o.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhgAAAADc"] [Tue Aug 18 12:59:29.256791 2026] [security2:error] [pid 123784:tid 123999] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhigAAAFE"] [Tue Aug 18 12:59:29.265173 2026] [security2:error] [pid 123784:tid 123824] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhiwAAViM"] [Tue Aug 18 12:59:29.265412 2026] [security2:error] [pid 123784:tid 124004] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhiwAAViM"] [Tue Aug 18 12:59:29.288347 2026] [security2:error] [pid 123784:tid 123968] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/spadex.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhjAAAADI"] [Tue Aug 18 12:59:29.291863 2026] [security2:error] [pid 123784:tid 124023] [client 20.91.215.254:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/server.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhjQAAAGk"] [Tue Aug 18 12:59:29.297895 2026] [security2:error] [pid 123784:tid 123925] [client 79.127.164.8:58604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/tables.sql"] [unique_id "aoSBYWwDnJBNj2tDbYbhjgAAAAc"], referer: https://medihub.com.br/tables.sql [Tue Aug 18 12:59:29.309861 2026] [security2:error] [pid 123784:tid 124001] [client 20.51.153.15:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/test_info.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhkAAAAFM"] [Tue Aug 18 12:59:29.383016 2026] [security2:error] [pid 123784:tid 123979] [client 114.5.214.109:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmAAAAD0"] [Tue Aug 18 12:59:29.383129 2026] [security2:error] [pid 123784:tid 123979] [client 114.5.214.109:50414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmAAAAD0"] [Tue Aug 18 12:59:29.398877 2026] [security2:error] [pid 123784:tid 123951] [client 20.38.3.247:60312] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmQAAACE"] [Tue Aug 18 12:59:29.398984 2026] [security2:error] [pid 123784:tid 123951] [client 20.38.3.247:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmQAAACE"] [Tue Aug 18 12:59:29.405491 2026] [security2:error] [pid 123784:tid 124008] [client 20.203.138.185:24934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/avim.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhmgAAAFo"] [Tue Aug 18 12:59:29.447671 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:7569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhnAAAADg"] [Tue Aug 18 12:59:29.476080 2026] [security2:error] [pid 123784:tid 124039] [client 20.25.139.174:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/cv.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhngAAAHk"] [Tue Aug 18 12:59:29.476182 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhnQAAABI"] [Tue Aug 18 12:59:29.493306 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ry.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhoAAAAGU"] [Tue Aug 18 12:59:29.510156 2026] [security2:error] [pid 123784:tid 123945] [client 132.196.30.78:14998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/NewFile.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhogAAABs"] [Tue Aug 18 12:59:29.565788 2026] [security2:error] [pid 123784:tid 124031] [client 74.248.18.37:32097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhpwAAAHE"] [Tue Aug 18 12:59:29.567775 2026] [security2:error] [pid 123784:tid 123958] [client 20.38.3.247:8692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/abcd.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhqAAAACg"] [Tue Aug 18 12:59:29.610561 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhqwAAACI"] [Tue Aug 18 12:59:29.612908 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28495] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrAAAAGA"] [Tue Aug 18 12:59:29.613009 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrAAAAGA"] [Tue Aug 18 12:59:29.634266 2026] [security2:error] [pid 123784:tid 123941] [client 68.155.154.236:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/yxijx.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrQAAABc"] [Tue Aug 18 12:59:29.665972 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhrwAAAE4"] [Tue Aug 18 12:59:29.673625 2026] [security2:error] [pid 123784:tid 123918] [client 20.51.153.15:7182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/xynz1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhsAAAAAA"] [Tue Aug 18 12:59:29.685276 2026] [security2:error] [pid 123784:tid 124043] [client 213.35.127.232:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhsgAAAH0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:29.693985 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10500] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tomiogroup.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtQAAAEo"] [Tue Aug 18 12:59:29.694069 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/1.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtQAAAEo"] [Tue Aug 18 12:59:29.697244 2026] [security2:error] [pid 123784:tid 123981] [client 40.74.65.169:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/chosen.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhtwAAAD8"] [Tue Aug 18 12:59:29.702223 2026] [security2:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/"] [unique_id "aoSBYWwDnJBNj2tDbYbhuAAAbCY"] [Tue Aug 18 12:59:29.729503 2026] [security2:error] [pid 123784:tid 123986] [client 132.196.30.78:22204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/a.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhugAAAEQ"] [Tue Aug 18 12:59:29.816645 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/2.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhvAAAADw"] [Tue Aug 18 12:59:29.928126 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:10212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhxgAAAAI"] [Tue Aug 18 12:59:29.929097 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:7292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/album.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhxwAAADI"] [Tue Aug 18 12:59:29.967854 2026] [security2:error] [pid 123784:tid 123940] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhyQAAABY"] [Tue Aug 18 12:59:30.010377 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:30.010633 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:30.030017 2026] [security2:error] [pid 123784:tid 123935] [client 172.202.39.151:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/inputs.php"] [unique_id "aoSBYmwDnJBNj2tDbYbhzQAAABE"] [Tue Aug 18 12:59:30.044864 2026] [autoindex:error] [pid 123784:tid 124017] [client 20.25.139.174:4669] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:30.051090 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBYmwDnJBNj2tDbYbhzwAAAF4"] [Tue Aug 18 12:59:30.069005 2026] [security2:error] [pid 123784:tid 123969] [client 20.38.3.247:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/simple.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh0wAAADM"] [Tue Aug 18 12:59:30.070177 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1AAAAEg"] [Tue Aug 18 12:59:30.081067 2026] [security2:error] [pid 123784:tid 124023] [client 20.127.136.245:28509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/alfa.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1QAAAGk"] [Tue Aug 18 12:59:30.129930 2026] [security2:error] [pid 123784:tid 124039] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/srontol.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh1wAAAHk"] [Tue Aug 18 12:59:30.167593 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:44849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/you.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh2gAAAFk"] [Tue Aug 18 12:59:30.169599 2026] [security2:error] [pid 123784:tid 123951] [client 20.119.58.187:10508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/7.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh2wAAACE"] [Tue Aug 18 12:59:30.194541 2026] [security2:error] [pid 123784:tid 123945] [client 20.51.153.15:7249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/creds.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh3gAAABs"] [Tue Aug 18 12:59:30.210510 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh4QAAAEk"] [Tue Aug 18 12:59:30.215201 2026] [security2:error] [pid 123784:tid 123944] [client 132.196.30.78:13677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh4wAAABo"] [Tue Aug 18 12:59:30.216449 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pm.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh5AAAAFA"] [Tue Aug 18 12:59:30.249174 2026] [security2:error] [pid 123784:tid 124037] [client 74.248.18.37:32091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh5gAAAHc"] [Tue Aug 18 12:59:30.314659 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:30.315004 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:30.325085 2026] [security2:error] [pid 123784:tid 124028] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh6gAAAG4"] [Tue Aug 18 12:59:30.351842 2026] [security2:error] [pid 123784:tid 124034] [client 168.119.53.160:56740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSBYWwDnJBNj2tDbYbhhQAAAHQ"], referer: https://www.connectformaturas.com.br [Tue Aug 18 12:59:30.403036 2026] [security2:error] [pid 123784:tid 123856] [remote 103.56.163.133:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh7wAAH0M"] [Tue Aug 18 12:59:30.419134 2026] [security2:error] [pid 123784:tid 123948] [client 20.25.139.174:4500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/ww5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh8gAAAB4"] [Tue Aug 18 12:59:30.498368 2026] [security2:error] [pid 123784:tid 123967] [client 20.51.153.15:7241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/mandrill.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh-AAAADE"] [Tue Aug 18 12:59:30.522658 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/10.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh_AAAAH0"] [Tue Aug 18 12:59:30.539017 2026] [security2:error] [pid 123784:tid 124011] [client 132.196.30.78:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoSBYmwDnJBNj2tDbYbh_wAAAF0"] [Tue Aug 18 12:59:30.542201 2026] [security2:error] [pid 123784:tid 123956] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/file5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiAQAAACY"] [Tue Aug 18 12:59:30.605760 2026] [security2:error] [pid 123784:tid 123966] [client 20.203.138.185:21042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/myfile.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiBwAAADA"] [Tue Aug 18 12:59:30.611986 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:30.612292 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:30.614662 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCQAAAAU"] [Tue Aug 18 12:59:30.614801 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCQAAAAU"] [Tue Aug 18 12:59:30.620125 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/edit.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiCgAAAAQ"] [Tue Aug 18 12:59:30.630916 2026] [security2:error] [pid 123784:tid 123963] [client 20.91.215.254:9909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/shell.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiDAAAAC0"] [Tue Aug 18 12:59:30.653101 2026] [security2:error] [pid 123784:tid 123919] [client 216.244.66.243:44400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/firebotblaze-0/"] [unique_id "aoSBYmwDnJBNj2tDbYbiDgAAAAE"] [Tue Aug 18 12:59:30.653219 2026] [security2:error] [pid 123784:tid 123919] [client 216.244.66.243:44400] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/firebotblaze-0/"] [unique_id "aoSBYmwDnJBNj2tDbYbiDgAAAAE"] [Tue Aug 18 12:59:30.665943 2026] [security2:error] [pid 123784:tid 123968] [client 20.38.3.247:29793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiDwAAADI"] [Tue Aug 18 12:59:30.672802 2026] [security2:error] [pid 123784:tid 123861] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEAAAPkg"] [Tue Aug 18 12:59:30.672992 2026] [security2:error] [pid 123784:tid 123980] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEAAAPkg"] [Tue Aug 18 12:59:30.700302 2026] [security2:error] [pid 123784:tid 123996] [client 213.35.127.232:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiEgAAAE4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:30.708276 2026] [security2:error] [pid 123784:tid 124021] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFQAAAGc"] [Tue Aug 18 12:59:30.713090 2026] [security2:error] [pid 123784:tid 123955] [client 20.215.241.237:18154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/file1221.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFgAAACU"] [Tue Aug 18 12:59:30.718896 2026] [security2:error] [pid 123784:tid 124035] [client 20.25.139.174:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ws83.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiFwAAAHU"] [Tue Aug 18 12:59:30.750655 2026] [security2:error] [pid 123784:tid 123979] [client 68.155.154.236:25405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/jrpga.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiGgAAAD0"] [Tue Aug 18 12:59:30.777162 2026] [security2:error] [pid 123784:tid 123954] [client 20.51.153.15:7227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/main.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiGwAAACQ"] [Tue Aug 18 12:59:30.823632 2026] [security2:error] [pid 123784:tid 124030] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yup.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiHQAAAHA"] [Tue Aug 18 12:59:30.874787 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/13.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiIQAAAF4"] [Tue Aug 18 12:59:30.890445 2026] [security2:error] [pid 123784:tid 124033] [client 132.196.30.78:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiJgAAAHM"] [Tue Aug 18 12:59:30.933997 2026] [security2:error] [pid 123784:tid 124038] [client 74.248.18.37:32095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKAAAAHg"] [Tue Aug 18 12:59:30.948932 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:38307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ez.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKQAAABo"] [Tue Aug 18 12:59:30.987423 2026] [security2:error] [pid 123784:tid 123965] [client 20.25.139.174:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/2.php"] [unique_id "aoSBYmwDnJBNj2tDbYbiKwAAAC8"] [Tue Aug 18 12:59:31.043571 2026] [security2:error] [pid 123784:tid 123962] [client 20.51.153.15:7212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/payout.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLQAAACw"] [Tue Aug 18 12:59:31.043888 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:28053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/elp.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLAAAAGo"] [Tue Aug 18 12:59:31.052481 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/xiugai.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiLwAAAFw"] [Tue Aug 18 12:59:31.065975 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMQAAACI"] [Tue Aug 18 12:59:31.092081 2026] [security2:error] [pid 123784:tid 123941] [client 40.74.65.169:19473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/als.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMgAAABc"] [Tue Aug 18 12:59:31.117849 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dr.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiMwAAADU"] [Tue Aug 18 12:59:31.119424 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiNAAAABg"] [Tue Aug 18 12:59:31.160445 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:25108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiOAAAAEI"] [Tue Aug 18 12:59:31.212797 2026] [security2:error] [pid 123784:tid 123975] [client 102.213.179.104:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPAAAADk"] [Tue Aug 18 12:59:31.212997 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:31.213024 2026] [security2:error] [pid 123784:tid 123975] [client 102.213.179.104:59984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPAAAADk"] [Tue Aug 18 12:59:31.213243 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:31.226509 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/100.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPQAAAFM"] [Tue Aug 18 12:59:31.251968 2026] [security2:error] [pid 123784:tid 124014] [client 20.25.139.174:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/atex1.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiPwAAAGA"] [Tue Aug 18 12:59:31.261457 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:10230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/sim.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiQQAAAHE"] [Tue Aug 18 12:59:31.279155 2026] [security2:error] [pid 123784:tid 124011] [client 20.38.3.247:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/coffee.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiQgAAAF0"] [Tue Aug 18 12:59:31.322064 2026] [security2:error] [pid 123784:tid 123877] [remote 178.156.200.16:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiRAAAblg"] [Tue Aug 18 12:59:31.374713 2026] [security2:error] [pid 123784:tid 123966] [client 20.51.153.15:7281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/Mailgun.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSAAAADA"] [Tue Aug 18 12:59:31.405157 2026] [security2:error] [pid 123784:tid 123978] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-the.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSgAAADw"] [Tue Aug 18 12:59:31.421878 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiSwAAAC0"] [Tue Aug 18 12:59:31.428598 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.85.180:28609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/edit.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiTQAAAHw"] [Tue Aug 18 12:59:31.446289 2026] [security2:error] [pid 123784:tid 123985] [client 20.38.3.247:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wp-load.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiTwAAAEM"] [Tue Aug 18 12:59:31.468030 2026] [security2:error] [pid 123784:tid 123940] [client 68.155.154.236:25361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUAAAABY"] [Tue Aug 18 12:59:31.487242 2026] [security2:error] [pid 123784:tid 124021] [client 20.203.138.185:24944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xmy.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUQAAAGc"] [Tue Aug 18 12:59:31.487697 2026] [security2:error] [pid 123784:tid 124009] [client 20.25.139.174:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiUgAAAFs"] [Tue Aug 18 12:59:31.550568 2026] [security2:error] [pid 123784:tid 123999] [client 20.127.136.245:28056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/classwithtostring.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiVQAAAFE"] [Tue Aug 18 12:59:31.580157 2026] [security2:error] [pid 123784:tid 123922] [client 132.196.30.78:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/themes.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiVwAAAAQ"] [Tue Aug 18 12:59:31.604652 2026] [security2:error] [pid 123784:tid 123977] [client 20.119.58.187:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/222.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWAAAADs"] [Tue Aug 18 12:59:31.649919 2026] [security2:error] [pid 123784:tid 124033] [client 20.51.153.15:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/oauth.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWgAAAHM"] [Tue Aug 18 12:59:31.654637 2026] [security2:error] [pid 123784:tid 123957] [client 74.248.18.37:26450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiWwAAACc"] [Tue Aug 18 12:59:31.686769 2026] [security2:error] [pid 123784:tid 123928] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiXAAAAAo"] [Tue Aug 18 12:59:31.688129 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ts.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiXwAAAGg"] [Tue Aug 18 12:59:31.717090 2026] [security2:error] [pid 123784:tid 123923] [client 213.35.127.232:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiZgAAAAU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:31.766775 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/asus.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiaQAAAGo"] [Tue Aug 18 12:59:31.770473 2026] [security2:error] [pid 123784:tid 124010] [client 40.74.65.169:20342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/nox.php"] [unique_id "aoSBY2wDnJBNj2tDbYbiagAAAFw"] [Tue Aug 18 12:59:31.778384 2026] [security2:error] [pid 123784:tid 124003] [client 132.196.30.78:15029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/vx.php"] [unique_id "aoSBY2wDnJBNj2tDbYbibAAAAFU"] [Tue Aug 18 12:59:31.780022 2026] [security2:error] [pid 123784:tid 123932] [client 20.25.139.174:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBY2wDnJBNj2tDbYbibQAAAA4"] [Tue Aug 18 12:59:31.794274 2026] [security2:error] [pid 123784:tid 123971] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBY2wDnJBNj2tDbYbicgAAADU"] [Tue Aug 18 12:59:31.819049 2026] [security2:error] [pid 123784:tid 123807] [remote 8.29.155.129:36225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.155.29.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbidAAAERI"] [Tue Aug 18 12:59:31.832349 2026] [security2:error] [pid 123784:tid 123988] [client 4.232.94.69:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/24.php"] [unique_id "aoSBY2wDnJBNj2tDbYbidQAAAEY"] [Tue Aug 18 12:59:31.907688 2026] [security2:error] [pid 123784:tid 124038] [client 20.91.215.254:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/simple.php"] [unique_id "aoSBY2wDnJBNj2tDbYbieQAAAHg"] [Tue Aug 18 12:59:31.940122 2026] [security2:error] [pid 123784:tid 123881] [remote 162.214.96.231:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifAAATFw"] [Tue Aug 18 12:59:31.957502 2026] [security2:error] [pid 123784:tid 123992] [client 20.119.58.187:10504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifQAAAEo"] [Tue Aug 18 12:59:31.969939 2026] [security2:error] [pid 123784:tid 123986] [client 20.38.3.247:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/155.php"] [unique_id "aoSBY2wDnJBNj2tDbYbifgAAAEQ"] [Tue Aug 18 12:59:31.993849 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:31.994106 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:32.002135 2026] [security2:error] [pid 123784:tid 123989] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xwpg.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiggAAAEc"] [Tue Aug 18 12:59:32.007148 2026] [security2:error] [pid 123784:tid 123933] [client 20.25.139.174:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/atomlib.php"] [unique_id "aoSBZGwDnJBNj2tDbYbigwAAAA8"] [Tue Aug 18 12:59:32.024564 2026] [security2:error] [pid 123784:tid 123929] [client 20.127.136.245:28088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/666.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihAAAAAs"] [Tue Aug 18 12:59:32.051841 2026] [security2:error] [pid 123784:tid 123970] [client 68.155.154.236:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/nwwha.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihQAAADQ"] [Tue Aug 18 12:59:32.058777 2026] [security2:error] [pid 123784:tid 124042] [client 20.51.153.15:7263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/timeclock.php"] [unique_id "aoSBZGwDnJBNj2tDbYbihgAAAHw"] [Tue Aug 18 12:59:32.108247 2026] [security2:error] [pid 123784:tid 123925] [client 196.12.128.158:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiQAAAAc"] [Tue Aug 18 12:59:32.108366 2026] [security2:error] [pid 123784:tid 123925] [client 196.12.128.158:63143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiQAAAAc"] [Tue Aug 18 12:59:32.145580 2026] [security2:error] [pid 123784:tid 124030] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiiwAAAHA"] [Tue Aug 18 12:59:32.155754 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:35124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbijAAAAHk"] [Tue Aug 18 12:59:32.189596 2026] [security2:error] [pid 123784:tid 123921] [client 132.196.30.78:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/cv.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikAAAAAM"] [Tue Aug 18 12:59:32.284998 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:47620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/53.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikgAAACc"] [Tue Aug 18 12:59:32.287879 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/dex.php"] [unique_id "aoSBZGwDnJBNj2tDbYbikwAAABI"] [Tue Aug 18 12:59:32.307831 2026] [security2:error] [pid 123784:tid 123983] [client 20.119.58.187:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/abcd.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilQAAAEE"] [Tue Aug 18 12:59:32.320641 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/w.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilgAAAEg"] [Tue Aug 18 12:59:32.325394 2026] [security2:error] [pid 123784:tid 123951] [client 20.251.48.93:57172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/k.php"] [unique_id "aoSBZGwDnJBNj2tDbYbilwAAACE"] [Tue Aug 18 12:59:32.370606 2026] [security2:error] [pid 123784:tid 124025] [client 20.203.138.185:24904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xda.php"] [unique_id "aoSBZGwDnJBNj2tDbYbimQAAAGs"] [Tue Aug 18 12:59:32.377008 2026] [security2:error] [pid 123784:tid 123965] [client 20.38.3.247:8640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbimwAAAC8"] [Tue Aug 18 12:59:32.389839 2026] [authz_core:error] [pid 123784:tid 123945] [client 82.102.18.182:55188] AH01630: client denied by server configuration: /home4/ctrrefrigeracao/public_html/wp-content/plugins/akismet/ [Tue Aug 18 12:59:32.395345 2026] [security2:error] [pid 123784:tid 123812] [remote 208.122.213.225:38078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSBZGwDnJBNj2tDbYbinQAAQBc"] [Tue Aug 18 12:59:32.425245 2026] [security2:error] [pid 123784:tid 124024] [client 172.182.200.96:7664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBZGwDnJBNj2tDbYbioQAAAGo"] [Tue Aug 18 12:59:32.463889 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiowAAAAY"] [Tue Aug 18 12:59:32.464039 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiowAAAAY"] [Tue Aug 18 12:59:32.466856 2026] [security2:error] [pid 123784:tid 123997] [client 74.248.18.37:26453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBZGwDnJBNj2tDbYbipAAAAE8"] [Tue Aug 18 12:59:32.480386 2026] [security2:error] [pid 123784:tid 123964] [client 40.74.65.169:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file59.php"] [unique_id "aoSBZGwDnJBNj2tDbYbipwAAAC4"] [Tue Aug 18 12:59:32.521807 2026] [security2:error] [pid 123784:tid 123998] [client 20.25.139.174:4693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/rip.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiqQAAAFA"] [Tue Aug 18 12:59:32.533014 2026] [security2:error] [pid 123784:tid 124015] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiqgAAAGE"] [Tue Aug 18 12:59:32.551988 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/st.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirAAAAFc"] [Tue Aug 18 12:59:32.574124 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xyn.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirQAAABE"] [Tue Aug 18 12:59:32.614013 2026] [security2:error] [pid 123784:tid 124019] [client 20.65.98.162:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ajax.php"] [unique_id "aoSBZGwDnJBNj2tDbYbirwAAAGU"] [Tue Aug 18 12:59:32.616733 2026] [security2:error] [pid 123784:tid 123960] [client 20.127.136.245:28485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ws54.php"] [unique_id "aoSBZGwDnJBNj2tDbYbisAAAACo"] [Tue Aug 18 12:59:32.660607 2026] [security2:error] [pid 123784:tid 123918] [client 20.119.58.187:10499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/al.php"] [unique_id "aoSBZGwDnJBNj2tDbYbisgAAAAA"] [Tue Aug 18 12:59:32.683776 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:20196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/22.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiswAAAG4"] [Tue Aug 18 12:59:32.729315 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiuQAAADc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:32.832831 2026] [security2:error] [pid 123784:tid 123953] [client 20.38.3.247:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/aaa.php"] [unique_id "aoSBZGwDnJBNj2tDbYbivQAAACM"] [Tue Aug 18 12:59:32.833038 2026] [security2:error] [pid 123784:tid 123925] [client 68.155.154.236:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/opsqt.php"] [unique_id "aoSBZGwDnJBNj2tDbYbivgAAAAc"] [Tue Aug 18 12:59:32.857835 2026] [security2:error] [pid 123784:tid 124037] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiwAAAAHc"] [Tue Aug 18 12:59:32.892044 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBZGwDnJBNj2tDbYbixAAAAHk"] [Tue Aug 18 12:59:32.894363 2026] [security2:error] [pid 123784:tid 123933] [client 20.25.139.174:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/archive.php"] [unique_id "aoSBZGwDnJBNj2tDbYbixQAAAA8"] [Tue Aug 18 12:59:32.899936 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:32.900195 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:32.902464 2026] [autoindex:error] [pid 123784:tid 124040] [client 132.196.30.78:22119] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:32.943235 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:44508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBZGwDnJBNj2tDbYbiywAAAHM"] [Tue Aug 18 12:59:33.012400 2026] [security2:error] [pid 123784:tid 123999] [client 20.119.58.187:10541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/alfa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi0QAAAFE"] [Tue Aug 18 12:59:33.039440 2026] [security2:error] [pid 123784:tid 124009] [client 20.25.139.174:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/p.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi1AAAAFs"] [Tue Aug 18 12:59:33.047534 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:22119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi1gAAAGs"] [Tue Aug 18 12:59:33.076798 2026] [autoindex:error] [pid 123784:tid 123946] [client 169.58.72.248:50450] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:33.113982 2026] [security2:error] [pid 123784:tid 123976] [client 74.248.18.37:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi2QAAADo"] [Tue Aug 18 12:59:33.123611 2026] [security2:error] [pid 123784:tid 123834] [remote 97.74.87.194:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi2gAAXC0"] [Tue Aug 18 12:59:33.128870 2026] [security2:error] [pid 123784:tid 123954] [client 132.196.30.78:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wap.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi3gAAACQ"] [Tue Aug 18 12:59:33.141086 2026] [security2:error] [pid 123784:tid 123943] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-good.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi3wAAABk"] [Tue Aug 18 12:59:33.163125 2026] [security2:error] [pid 123784:tid 123964] [client 68.221.73.131:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/dex.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5AAAAC4"] [Tue Aug 18 12:59:33.164509 2026] [security2:error] [pid 123784:tid 123951] [client 20.127.136.245:28085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/deepseek_d.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5QAAACE"] [Tue Aug 18 12:59:33.168391 2026] [security2:error] [pid 123784:tid 123955] [client 40.74.65.169:20338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/admin.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5gAAACU"] [Tue Aug 18 12:59:33.185730 2026] [security2:error] [pid 123784:tid 124015] [client 172.202.39.151:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/alfa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi5wAAAGE"] [Tue Aug 18 12:59:33.198941 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:33.199207 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:33.210325 2026] [security2:error] [pid 123784:tid 123928] [client 20.91.215.254:9919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6gAAAAo"] [Tue Aug 18 12:59:33.217256 2026] [security2:error] [pid 123784:tid 124017] [client 157.51.166.53:56631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.166.51.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6wAAAGM"] [Tue Aug 18 12:59:33.217401 2026] [security2:error] [pid 123784:tid 124017] [client 157.51.166.53:56631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi6wAAAGM"] [Tue Aug 18 12:59:33.246933 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zs.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi7gAAADk"] [Tue Aug 18 12:59:33.251683 2026] [security2:error] [pid 123784:tid 124019] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi8AAAAGU"] [Tue Aug 18 12:59:33.290521 2026] [security2:error] [pid 123784:tid 124031] [client 168.62.48.100:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi8gAAAHE"] [Tue Aug 18 12:59:33.331079 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:17535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi9AAAAG4"] [Tue Aug 18 12:59:33.365175 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/as.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi9wAAAFM"] [Tue Aug 18 12:59:33.386456 2026] [security2:error] [pid 123784:tid 124016] [client 20.104.85.180:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-AAAAGI"] [Tue Aug 18 12:59:33.387315 2026] [security2:error] [pid 123784:tid 123927] [client 20.25.139.174:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/bless.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-QAAAAk"] [Tue Aug 18 12:59:33.443996 2026] [security2:error] [pid 123784:tid 123919] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wmore1.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi-wAAAAE"] [Tue Aug 18 12:59:33.446699 2026] [security2:error] [pid 123784:tid 123939] [client 20.38.3.247:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi_AAAABU"] [Tue Aug 18 12:59:33.448073 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.154.236:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbi_QAAACY"] [Tue Aug 18 12:59:33.503312 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:33.503565 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:33.539677 2026] [security2:error] [pid 123784:tid 124027] [client 213.202.253.4:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjAwAAAG0"], referer: www.google.com [Tue Aug 18 12:59:33.573964 2026] [security2:error] [pid 123784:tid 123989] [client 20.25.139.174:4543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.clickseo.com.br"] [uri "/php.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjBQAAAEc"] [Tue Aug 18 12:59:33.581224 2026] [security2:error] [pid 123784:tid 123929] [client 132.196.30.78:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ws83.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjBgAAAAs"] [Tue Aug 18 12:59:33.615555 2026] [security2:error] [pid 123784:tid 123945] [client 20.250.13.23:33157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/vx.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjCQAAABs"] [Tue Aug 18 12:59:33.627439 2026] [security2:error] [pid 123784:tid 124040] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjCwAAAHo"] [Tue Aug 18 12:59:33.695783 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/function/function.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjDQAAAB8"] [Tue Aug 18 12:59:33.717941 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/aa.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjDwAAAHA"] [Tue Aug 18 12:59:33.736930 2026] [security2:error] [pid 123784:tid 124011] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/special.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjEAAAAF0"] [Tue Aug 18 12:59:33.748716 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:64532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjEQAAADc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:33.791251 2026] [security2:error] [pid 123784:tid 124037] [client 74.248.18.37:26442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-config.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjFAAAAHc"] [Tue Aug 18 12:59:33.808259 2026] [security2:error] [pid 123784:tid 123990] [client 20.51.153.15:7295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/email.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjFgAAAEg"] [Tue Aug 18 12:59:33.843001 2026] [security2:error] [pid 123784:tid 123996] [client 216.244.66.243:44416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/xxx+bet-3/"] [unique_id "aoSBZWwDnJBNj2tDbYbjGgAAAE4"] [Tue Aug 18 12:59:33.843134 2026] [security2:error] [pid 123784:tid 123996] [client 216.244.66.243:44416] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/xxx+bet-3/"] [unique_id "aoSBZWwDnJBNj2tDbYbjGgAAAE4"] [Tue Aug 18 12:59:33.846093 2026] [authz_core:error] [pid 123784:tid 123957] [client 192.178.4.133:50505] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:33.846359 2026] [authz_core:error] [pid 123784:tid 123957] [client 192.178.4.133:50505] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:33.847769 2026] [security2:error] [pid 123784:tid 124004] [client 20.91.215.254:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/system.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjGwAAAFY"] [Tue Aug 18 12:59:33.862195 2026] [security2:error] [pid 123784:tid 123982] [client 40.74.65.169:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aa2.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjHQAAAEA"] [Tue Aug 18 12:59:33.875663 2026] [security2:error] [pid 123784:tid 123946] [client 20.251.48.93:10091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/82.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjHgAAABw"] [Tue Aug 18 12:59:33.889136 2026] [security2:error] [pid 123784:tid 123926] [client 20.25.139.174:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/sagax1.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjIAAAAAg"] [Tue Aug 18 12:59:33.982234 2026] [security2:error] [pid 123784:tid 123997] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBZWwDnJBNj2tDbYbjJAAAAE8"] [Tue Aug 18 12:59:34.023003 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjJQAAAF4"] [Tue Aug 18 12:59:34.069070 2026] [security2:error] [pid 123784:tid 124017] [client 20.51.153.15:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/profile.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjKAAAAGM"] [Tue Aug 18 12:59:34.070255 2026] [security2:error] [pid 123784:tid 123943] [client 20.119.58.187:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/abc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjKQAAABk"] [Tue Aug 18 12:59:34.103030 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:34.103313 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:34.173548 2026] [security2:error] [pid 123784:tid 123936] [client 86.120.159.145:11033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjLwAAABI"] [Tue Aug 18 12:59:34.175662 2026] [security2:error] [pid 123784:tid 123936] [client 86.120.159.145:11033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjLwAAABI"] [Tue Aug 18 12:59:34.179790 2026] [security2:error] [pid 123784:tid 123979] [client 132.196.30.78:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjMAAAAD0"] [Tue Aug 18 12:59:34.189812 2026] [security2:error] [pid 123784:tid 124036] [client 132.196.30.78:22124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/atex1.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjMwAAAHY"] [Tue Aug 18 12:59:34.223219 2026] [security2:error] [pid 123784:tid 124013] [client 20.127.136.245:28484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/nw.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjOAAAAF8"] [Tue Aug 18 12:59:34.244945 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lq.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjOgAAAGI"] [Tue Aug 18 12:59:34.265931 2026] [autoindex:error] [pid 123784:tid 123971] [client 4.232.94.69:17324] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:34.306640 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iz.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjPAAAADQ"] [Tue Aug 18 12:59:34.313920 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/thoms.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjPQAAABU"] [Tue Aug 18 12:59:34.342795 2026] [security2:error] [pid 123784:tid 123938] [client 20.51.153.15:7178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/summary.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQQAAABQ"] [Tue Aug 18 12:59:34.345058 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQgAAAEM"] [Tue Aug 18 12:59:34.354796 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/lock360.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjQwAAAFg"] [Tue Aug 18 12:59:34.396007 2026] [security2:error] [pid 123784:tid 123941] [client 20.25.139.174:4596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjRQAAABc"] [Tue Aug 18 12:59:34.404385 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:34.404637 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:34.423399 2026] [security2:error] [pid 123784:tid 124041] [client 20.119.58.187:10559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/av.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjRwAAAHs"] [Tue Aug 18 12:59:34.443704 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.18.37:25285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjSQAAAB4"] [Tue Aug 18 12:59:34.506031 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/site.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjTwAAAH8"] [Tue Aug 18 12:59:34.568862 2026] [security2:error] [pid 123784:tid 123920] [client 40.74.65.169:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/xamp.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjUgAAAAI"] [Tue Aug 18 12:59:34.571863 2026] [security2:error] [pid 123784:tid 123980] [client 20.91.215.254:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjUwAAAD4"] [Tue Aug 18 12:59:34.599904 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVAAAABw"] [Tue Aug 18 12:59:34.614350 2026] [security2:error] [pid 123784:tid 123930] [client 192.141.172.134:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVgAAAAw"] [Tue Aug 18 12:59:34.614470 2026] [security2:error] [pid 123784:tid 123930] [client 192.141.172.134:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVgAAAAw"] [Tue Aug 18 12:59:34.661446 2026] [security2:error] [pid 123784:tid 123981] [client 20.51.153.15:7230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/conf.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjVwAAAD8"] [Tue Aug 18 12:59:34.706890 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:34.707146 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:34.709827 2026] [security2:error] [pid 123784:tid 124020] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjXgAAAGY"] [Tue Aug 18 12:59:34.739085 2026] [security2:error] [pid 123784:tid 123996] [client 20.127.136.245:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/xleet.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjXwAAAE4"] [Tue Aug 18 12:59:34.761423 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/you.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYAAAADE"] [Tue Aug 18 12:59:34.762604 2026] [security2:error] [pid 123784:tid 123958] [client 213.35.127.232:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYQAAACg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:34.767736 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:13647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bgymj.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjYgAAADg"] [Tue Aug 18 12:59:34.789911 2026] [security2:error] [pid 123784:tid 124010] [client 20.119.58.187:10549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjZQAAAFw"] [Tue Aug 18 12:59:34.809111 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.154.236:25368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjZwAAADk"] [Tue Aug 18 12:59:34.840052 2026] [security2:error] [pid 123784:tid 123990] [client 132.196.30.78:22111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjawAAAEg"] [Tue Aug 18 12:59:34.840191 2026] [autoindex:error] [pid 123784:tid 124014] [client 4.232.94.69:17324] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:34.870478 2026] [security2:error] [pid 123784:tid 124044] [client 20.203.138.185:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zz.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjbAAAAH4"] [Tue Aug 18 12:59:34.890392 2026] [security2:error] [pid 123784:tid 123932] [client 20.25.139.174:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/fone1.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjcAAAAA4"] [Tue Aug 18 12:59:34.905898 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/root.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjcgAAABg"] [Tue Aug 18 12:59:34.948278 2026] [security2:error] [pid 123784:tid 123985] [client 20.104.85.180:43531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjeAAAAEM"] [Tue Aug 18 12:59:34.952870 2026] [security2:error] [pid 123784:tid 124006] [client 20.51.153.15:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/bala.php"] [unique_id "aoSBZmwDnJBNj2tDbYbjeQAAAFg"] [Tue Aug 18 12:59:35.010475 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:35.010935 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:35.011229 2026] [security2:error] [pid 123784:tid 123929] [client 20.38.3.247:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/ccc.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjgAAAAAs"] [Tue Aug 18 12:59:35.026649 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:31901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/se.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjggAAAHs"] [Tue Aug 18 12:59:35.045517 2026] [security2:error] [pid 123784:tid 123936] [client 79.127.164.8:58670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/temp.bak"] [unique_id "aoSBZ2wDnJBNj2tDbYbjgwAAABI"], referer: https://medihub.com.br/temp.bak [Tue Aug 18 12:59:35.047515 2026] [security2:error] [pid 123784:tid 123933] [client 4.232.94.69:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-block.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjhQAAAA8"] [Tue Aug 18 12:59:35.068872 2026] [security2:error] [pid 123784:tid 123949] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjiQAAAB8"] [Tue Aug 18 12:59:35.128438 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.85.180:22852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-good.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjjQAAAEE"] [Tue Aug 18 12:59:35.149242 2026] [security2:error] [pid 123784:tid 123925] [client 20.119.58.187:10516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/asus.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjjwAAAAc"] [Tue Aug 18 12:59:35.163587 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:60118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjkwAAAGg"] [Tue Aug 18 12:59:35.183200 2026] [security2:error] [pid 123784:tid 123790] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/web/.env"] [unique_id "aoSBZ2wDnJBNj2tDbYbjlQAABgE"] [Tue Aug 18 12:59:35.193255 2026] [security2:error] [pid 123784:tid 124009] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/fpwch.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjmwAAAFs"] [Tue Aug 18 12:59:35.199569 2026] [security2:error] [pid 123784:tid 123980] [client 20.51.153.15:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/222.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjnQAAAD4"] [Tue Aug 18 12:59:35.237800 2026] [security2:error] [pid 123784:tid 124013] [client 74.248.18.37:26447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjoAAAAF8"] [Tue Aug 18 12:59:35.248467 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjogAAACM"] [Tue Aug 18 12:59:35.258386 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/bless.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjowAAAAg"] [Tue Aug 18 12:59:35.267653 2026] [security2:error] [pid 123784:tid 123876] [remote 95.111.251.70:53738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjpQAAdFc"] [Tue Aug 18 12:59:35.306537 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.85.180:43551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/o.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqAAAACQ"] [Tue Aug 18 12:59:35.309817 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:28076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqQAAADc"] [Tue Aug 18 12:59:35.311200 2026] [security2:error] [pid 123784:tid 123923] [client 20.215.241.237:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/nox.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjqgAAAAU"] [Tue Aug 18 12:59:35.313034 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:35.313473 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:35.390173 2026] [security2:error] [pid 123784:tid 124035] [client 132.196.30.78:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjrgAAAHU"] [Tue Aug 18 12:59:35.390186 2026] [security2:error] [pid 123784:tid 123982] [client 20.25.139.174:4511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ncx.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjrwAAAEA"] [Tue Aug 18 12:59:35.392466 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.154.236:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjsAAAACg"] [Tue Aug 18 12:59:35.396844 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjsQAAAGk"] [Tue Aug 18 12:59:35.420458 2026] [security2:error] [pid 123784:tid 123965] [client 132.196.30.78:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/w.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjswAAAC8"] [Tue Aug 18 12:59:35.425318 2026] [security2:error] [pid 123784:tid 123961] [client 20.203.138.185:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xa.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtAAAACs"] [Tue Aug 18 12:59:35.431778 2026] [security2:error] [pid 123784:tid 124018] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtQAAAGQ"] [Tue Aug 18 12:59:35.454196 2026] [security2:error] [pid 123784:tid 124017] [client 20.38.3.247:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/admin.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjtwAAAGM"] [Tue Aug 18 12:59:35.468420 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:7273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/routes.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuAAAABE"] [Tue Aug 18 12:59:35.469523 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ez.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuQAAAEg"] [Tue Aug 18 12:59:35.500947 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/mg.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjugAAAH4"] [Tue Aug 18 12:59:35.503874 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/about.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjuwAAAF4"] [Tue Aug 18 12:59:35.510577 2026] [security2:error] [pid 123784:tid 123986] [client 172.182.200.96:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjvAAAAEQ"] [Tue Aug 18 12:59:35.547765 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.113:41714] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:35.548209 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.113:41714] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:35.590438 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.85.180:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/bb.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjwgAAADQ"] [Tue Aug 18 12:59:35.607847 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:35.608108 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:35.722483 2026] [security2:error] [pid 123784:tid 123936] [client 20.251.48.93:10096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/dex.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbjzAAAABI"] [Tue Aug 18 12:59:35.773594 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/155.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj0gAAAGo"] [Tue Aug 18 12:59:35.777557 2026] [security2:error] [pid 123784:tid 123928] [client 213.35.127.232:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1AAAAAo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:35.792335 2026] [security2:error] [pid 123784:tid 124007] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/reop3.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1QAAAFk"] [Tue Aug 18 12:59:35.792359 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj1gAAAHA"] [Tue Aug 18 12:59:35.796587 2026] [security2:error] [pid 123784:tid 123983] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/rezor.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2AAAAEE"] [Tue Aug 18 12:59:35.811957 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/php5.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2gAAAGg"] [Tue Aug 18 12:59:35.855914 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/atomlib.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj2wAAAFM"] [Tue Aug 18 12:59:35.876544 2026] [security2:error] [pid 123784:tid 123980] [client 20.104.85.180:6922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj3QAAAD4"] [Tue Aug 18 12:59:35.888504 2026] [security2:error] [pid 123784:tid 123978] [client 20.91.215.254:18771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/test.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj3wAAADw"] [Tue Aug 18 12:59:35.910394 2026] [security2:error] [pid 123784:tid 123966] [client 20.25.139.174:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj4gAAADA"] [Tue Aug 18 12:59:35.932556 2026] [security2:error] [pid 123784:tid 123973] [client 20.38.3.247:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/reviall.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj5wAAADc"] [Tue Aug 18 12:59:35.957176 2026] [security2:error] [pid 123784:tid 123951] [client 40.74.65.169:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file25.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj7QAAACE"] [Tue Aug 18 12:59:35.969910 2026] [security2:error] [pid 123784:tid 124040] [client 4.232.94.69:19685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wk/index.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj7wAAAHo"] [Tue Aug 18 12:59:35.975286 2026] [security2:error] [pid 123784:tid 123961] [client 158.23.17.4:57233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vp.php"] [unique_id "aoSBZ2wDnJBNj2tDbYbj8AAAACs"] [Tue Aug 18 12:59:36.064351 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/php5.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj9gAAAEI"] [Tue Aug 18 12:59:36.111267 2026] [security2:error] [pid 123784:tid 123922] [client 132.196.30.78:22096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/archive.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj-gAAAAQ"] [Tue Aug 18 12:59:36.130799 2026] [security2:error] [pid 123784:tid 123999] [client 20.51.153.15:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/Black.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj_QAAAFE"] [Tue Aug 18 12:59:36.162242 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.13.23:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wap.php"] [unique_id "aoSBaGwDnJBNj2tDbYbj_wAAAFw"] [Tue Aug 18 12:59:36.162406 2026] [security2:error] [pid 123784:tid 124031] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkAAAAAHE"] [Tue Aug 18 12:59:36.206778 2026] [security2:error] [pid 123784:tid 123918] [client 20.119.58.187:10537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSBaGwDnJBNj2tDbYbkBgAAAAA"] [Tue Aug 18 12:59:36.211821 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:36.212082 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:36.237222 2026] [security2:error] [pid 123784:tid 123940] [client 68.221.73.131:49775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/puc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkCAAAABY"] [Tue Aug 18 12:59:36.288241 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.154.236:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkCwAAABI"] [Tue Aug 18 12:59:36.302186 2026] [security2:error] [pid 123784:tid 124042] [client 74.248.18.37:26452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkDAAAAHw"] [Tue Aug 18 12:59:36.303923 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:44418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/fatal+model+em+eunapolis+bahia-2/"] [unique_id "aoSBaGwDnJBNj2tDbYbkDgAAAHw"] [Tue Aug 18 12:59:36.304017 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:44418] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/fatal+model+em+eunapolis+bahia-2/"] [unique_id "aoSBaGwDnJBNj2tDbYbkDgAAAHw"] [Tue Aug 18 12:59:36.310132 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/asus.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkEAAAAB8"] [Tue Aug 18 12:59:36.361516 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/acp.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkFQAAAGg"] [Tue Aug 18 12:59:36.408120 2026] [security2:error] [pid 123784:tid 123969] [client 20.25.139.174:4597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wso.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkGgAAADM"] [Tue Aug 18 12:59:36.415594 2026] [security2:error] [pid 123784:tid 123992] [client 20.104.85.180:18719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/tes.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkGwAAAEo"] [Tue Aug 18 12:59:36.420541 2026] [security2:error] [pid 123784:tid 124043] [client 20.127.136.245:28061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/96i.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHAAAAH0"] [Tue Aug 18 12:59:36.439326 2026] [security2:error] [pid 123784:tid 124004] [client 20.51.153.15:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/filesystems.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHQAAAFY"] [Tue Aug 18 12:59:36.458936 2026] [security2:error] [pid 123784:tid 124045] [client 132.196.30.78:15018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkHwAAAH8"] [Tue Aug 18 12:59:36.518612 2026] [security2:error] [pid 123784:tid 124014] [client 20.91.215.254:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/test1.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkJgAAAGA"] [Tue Aug 18 12:59:36.530814 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkKQAAADI"] [Tue Aug 18 12:59:36.561009 2026] [security2:error] [pid 123784:tid 123998] [client 20.119.58.187:10542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/b.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkKwAAAFA"] [Tue Aug 18 12:59:36.657483 2026] [security2:error] [pid 123784:tid 124023] [client 40.74.65.169:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file15.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkMQAAAGk"] [Tue Aug 18 12:59:36.685361 2026] [security2:error] [pid 123784:tid 123959] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/yas.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkMgAAACk"] [Tue Aug 18 12:59:36.711898 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.154.236:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkNQAAABE"] [Tue Aug 18 12:59:36.734322 2026] [security2:error] [pid 123784:tid 124013] [client 20.51.153.15:7190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/showphpinfo.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkOgAAAF8"] [Tue Aug 18 12:59:36.790203 2026] [security2:error] [pid 123784:tid 123962] [client 213.35.127.232:65164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkPgAAACw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:36.814935 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:36.815192 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:36.816118 2026] [security2:error] [pid 123784:tid 123994] [client 20.104.85.180:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/files/index.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkQQAAAEw"] [Tue Aug 18 12:59:36.843259 2026] [security2:error] [pid 123784:tid 123931] [client 4.232.94.69:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/w.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkQgAAAA0"] [Tue Aug 18 12:59:36.855930 2026] [security2:error] [pid 123784:tid 123954] [client 132.196.30.78:22141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/bless.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkRQAAACQ"] [Tue Aug 18 12:59:36.887909 2026] [security2:error] [pid 123784:tid 123944] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/index/function.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkSgAAABo"] [Tue Aug 18 12:59:36.913107 2026] [security2:error] [pid 123784:tid 123923] [client 20.119.58.187:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/buy.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkTQAAAAU"] [Tue Aug 18 12:59:36.918791 2026] [security2:error] [pid 123784:tid 123986] [client 20.127.136.245:28036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/as.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkTgAAAEQ"] [Tue Aug 18 12:59:36.950507 2026] [security2:error] [pid 123784:tid 124036] [client 103.184.169.37:42643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUQAAAHY"] [Tue Aug 18 12:59:36.950619 2026] [security2:error] [pid 123784:tid 124036] [client 103.184.169.37:42643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUQAAAHY"] [Tue Aug 18 12:59:36.967652 2026] [security2:error] [pid 123784:tid 124016] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ah25.php"] [unique_id "aoSBaGwDnJBNj2tDbYbkUwAAAGI"] [Tue Aug 18 12:59:37.046319 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ph.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkWAAAAHw"] [Tue Aug 18 12:59:37.065738 2026] [security2:error] [pid 123784:tid 123991] [client 20.25.139.174:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/zup.php73"] [unique_id "aoSBaWwDnJBNj2tDbYbkWQAAAEk"] [Tue Aug 18 12:59:37.078513 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpstatus.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkWgAAAHA"] [Tue Aug 18 12:59:37.140312 2026] [security2:error] [pid 123784:tid 123978] [client 103.120.71.157:20045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkYwAAADw"] [Tue Aug 18 12:59:37.140449 2026] [security2:error] [pid 123784:tid 123978] [client 103.120.71.157:20045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkYwAAADw"] [Tue Aug 18 12:59:37.158973 2026] [security2:error] [pid 123784:tid 124028] [client 20.91.215.254:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/text.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkZAAAAG4"] [Tue Aug 18 12:59:37.171408 2026] [security2:error] [pid 123784:tid 124027] [client 132.196.30.78:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bolt.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkZwAAAG0"] [Tue Aug 18 12:59:37.221090 2026] [security2:error] [pid 123784:tid 124006] [client 74.248.18.37:7804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkdQAAAFg"] [Tue Aug 18 12:59:37.240671 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/ano.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkdwAAAD4"] [Tue Aug 18 12:59:37.248684 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkeAAAADg"] [Tue Aug 18 12:59:37.265254 2026] [security2:error] [pid 123784:tid 124022] [client 20.119.58.187:10523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/bless.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkeQAAAGg"] [Tue Aug 18 12:59:37.273362 2026] [security2:error] [pid 123784:tid 123920] [client 149.34.210.141:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkewAAAAI"] [Tue Aug 18 12:59:37.316100 2026] [security2:error] [pid 123784:tid 123926] [client 20.51.153.15:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/del.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkfwAAAAg"] [Tue Aug 18 12:59:37.337606 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/f35.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkggAAADA"] [Tue Aug 18 12:59:37.339372 2026] [security2:error] [pid 123784:tid 123933] [client 20.104.85.180:18759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkgwAAAA8"] [Tue Aug 18 12:59:37.386666 2026] [security2:error] [pid 123784:tid 123992] [client 20.127.136.245:28488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/min.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkhgAAAEo"] [Tue Aug 18 12:59:37.424214 2026] [security2:error] [pid 123784:tid 124033] [client 20.100.169.31:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/atomlib.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiAAAAHM"] [Tue Aug 18 12:59:37.446547 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:31087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiQAAAAA"] [Tue Aug 18 12:59:37.470048 2026] [security2:error] [pid 123784:tid 123958] [client 20.38.3.247:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/nope.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkiwAAACg"] [Tue Aug 18 12:59:37.514293 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:40942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkjAAAAFc"] [Tue Aug 18 12:59:37.539873 2026] [security2:error] [pid 123784:tid 123920] [client 149.34.210.141:49891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkewAAAAI"] [Tue Aug 18 12:59:37.545098 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/nwflm.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkkQAAABE"] [Tue Aug 18 12:59:37.573414 2026] [security2:error] [pid 123784:tid 123996] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkjgAATgQ"] [Tue Aug 18 12:59:37.583390 2026] [security2:error] [pid 123784:tid 123976] [client 68.155.154.236:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkkwAAADo"] [Tue Aug 18 12:59:37.586354 2026] [security2:error] [pid 123784:tid 123998] [client 20.25.139.174:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/k.php"] [unique_id "aoSBaWwDnJBNj2tDbYbklAAAAFA"] [Tue Aug 18 12:59:37.593595 2026] [security2:error] [pid 123784:tid 123924] [client 20.203.138.185:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/f6.php"] [unique_id "aoSBaWwDnJBNj2tDbYbklQAAAAY"] [Tue Aug 18 12:59:37.612832 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/Cachex.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmAAAAEw"] [Tue Aug 18 12:59:37.615982 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/moderator.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmQAAAEY"] [Tue Aug 18 12:59:37.619019 2026] [security2:error] [pid 123784:tid 123955] [client 20.119.58.187:10545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkmgAAACU"] [Tue Aug 18 12:59:37.632570 2026] [security2:error] [pid 123784:tid 123922] [client 172.182.200.96:7626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBaWwDnJBNj2tDbYbknAAAAAQ"] [Tue Aug 18 12:59:37.689141 2026] [security2:error] [pid 123784:tid 123919] [client 157.20.138.62:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkngAAAAE"] [Tue Aug 18 12:59:37.689307 2026] [security2:error] [pid 123784:tid 123919] [client 157.20.138.62:56435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkngAAAAE"] [Tue Aug 18 12:59:37.691019 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:20194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/s.php"] [unique_id "aoSBaWwDnJBNj2tDbYbknwAAAE8"] [Tue Aug 18 12:59:37.722432 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:37.722906 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:37.738623 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:14601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bthil.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpAAAAGE"] [Tue Aug 18 12:59:37.749187 2026] [security2:error] [pid 123784:tid 124013] [client 132.196.30.78:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/sagax1.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpQAAAF8"] [Tue Aug 18 12:59:37.808997 2026] [security2:error] [pid 123784:tid 124023] [client 213.35.127.232:65388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkpgAAAGk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:37.818239 2026] [security2:error] [pid 123784:tid 123960] [client 20.91.215.254:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqAAAACo"] [Tue Aug 18 12:59:37.820401 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/weozh.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqQAAAB8"] [Tue Aug 18 12:59:37.852532 2026] [security2:error] [pid 123784:tid 124044] [client 20.51.153.15:7185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/infoinfo.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkqwAAAH4"] [Tue Aug 18 12:59:37.857764 2026] [security2:error] [pid 123784:tid 124027] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/wp-load.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkrQAAAG0"] [Tue Aug 18 12:59:37.956249 2026] [security2:error] [pid 123784:tid 123977] [client 68.155.154.236:25365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBaWwDnJBNj2tDbYbksQAAADs"] [Tue Aug 18 12:59:37.960598 2026] [security2:error] [pid 123784:tid 123953] [client 158.23.17.4:7208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/22.php"] [unique_id "aoSBaWwDnJBNj2tDbYbksgAAACM"] [Tue Aug 18 12:59:37.968519 2026] [security2:error] [pid 123784:tid 124045] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktAAAAH8"] [Tue Aug 18 12:59:37.969266 2026] [security2:error] [pid 123784:tid 123940] [client 74.248.18.37:26432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktQAAABY"] [Tue Aug 18 12:59:37.970750 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/cache.php"] [unique_id "aoSBaWwDnJBNj2tDbYbktgAAADw"] [Tue Aug 18 12:59:37.975153 2026] [security2:error] [pid 123784:tid 124041] [client 20.38.3.247:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/nope.php"] [unique_id "aoSBaWwDnJBNj2tDbYbkuAAAAHs"] [Tue Aug 18 12:59:38.021534 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:19491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-load.php"] [unique_id "aoSBamwDnJBNj2tDbYbkvAAAABs"] [Tue Aug 18 12:59:38.079425 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.85.180:19723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBamwDnJBNj2tDbYbkyAAAADE"] [Tue Aug 18 12:59:38.080222 2026] [security2:error] [pid 123784:tid 123980] [client 20.25.139.174:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBamwDnJBNj2tDbYbkygAAAD4"] [Tue Aug 18 12:59:38.135983 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/php8.php"] [unique_id "aoSBamwDnJBNj2tDbYbkywAAABQ"] [Tue Aug 18 12:59:38.144997 2026] [security2:error] [pid 123784:tid 123959] [client 178.153.171.161:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzAAAACk"] [Tue Aug 18 12:59:38.145177 2026] [security2:error] [pid 123784:tid 123959] [client 178.153.171.161:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzAAAACk"] [Tue Aug 18 12:59:38.184666 2026] [security2:error] [pid 123784:tid 124035] [client 20.251.48.93:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/puc.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzQAAAHU"] [Tue Aug 18 12:59:38.196336 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/c99shell.php"] [unique_id "aoSBamwDnJBNj2tDbYbkzgAAAEY"] [Tue Aug 18 12:59:38.199261 2026] [security2:error] [pid 123784:tid 124042] [client 4.232.94.69:19648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSBamwDnJBNj2tDbYbkwgAAAHw"] [Tue Aug 18 12:59:38.235117 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/jj.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0AAAAF4"] [Tue Aug 18 12:59:38.238458 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0QAAADk"] [Tue Aug 18 12:59:38.242787 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:7818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk0QAAADk"] [Tue Aug 18 12:59:38.306266 2026] [security2:error] [pid 123784:tid 123985] [client 20.100.169.31:30799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/rip.php"] [unique_id "aoSBamwDnJBNj2tDbYbk2gAAAEM"] [Tue Aug 18 12:59:38.324304 2026] [security2:error] [pid 123784:tid 124034] [client 20.119.58.187:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/content.php"] [unique_id "aoSBamwDnJBNj2tDbYbk3AAAAHQ"] [Tue Aug 18 12:59:38.334952 2026] [security2:error] [pid 123784:tid 124002] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBamwDnJBNj2tDbYbk3QAAAFQ"] [Tue Aug 18 12:59:38.424005 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:38308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/uo.php"] [unique_id "aoSBamwDnJBNj2tDbYbk4AAAAGo"] [Tue Aug 18 12:59:38.453290 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.154.236:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBamwDnJBNj2tDbYbk4wAAAG0"] [Tue Aug 18 12:59:38.457104 2026] [security2:error] [pid 123784:tid 123950] [client 20.91.215.254:18792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoSBamwDnJBNj2tDbYbk5QAAACA"] [Tue Aug 18 12:59:38.460081 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:38.460346 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:38.462586 2026] [security2:error] [pid 123784:tid 124043] [client 20.51.153.15:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/profiler.php"] [unique_id "aoSBamwDnJBNj2tDbYbk5wAAAH0"] [Tue Aug 18 12:59:38.480191 2026] [security2:error] [pid 123784:tid 123955] [client 132.196.30.78:22087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wpc.php"] [unique_id "aoSBamwDnJBNj2tDbYbk6QAAACU"] [Tue Aug 18 12:59:38.515137 2026] [security2:error] [pid 123784:tid 123977] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/img.php"] [unique_id "aoSBamwDnJBNj2tDbYbk7AAAADs"] [Tue Aug 18 12:59:38.613009 2026] [security2:error] [pid 123784:tid 123962] [client 20.38.3.247:34989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/new.php"] [unique_id "aoSBamwDnJBNj2tDbYbk9QAAACw"] [Tue Aug 18 12:59:38.614018 2026] [security2:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "bioarquitetar.com"] [uri "/page/2/"] [unique_id "aoSBamwDnJBNj2tDbYbk9gAAZTs"] [Tue Aug 18 12:59:38.677649 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBamwDnJBNj2tDbYbk-wAAADw"] [Tue Aug 18 12:59:38.711232 2026] [security2:error] [pid 123784:tid 123968] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBamwDnJBNj2tDbYbk_AAAADI"] [Tue Aug 18 12:59:38.721332 2026] [security2:error] [pid 123784:tid 123992] [client 20.51.153.15:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/findes.php"] [unique_id "aoSBamwDnJBNj2tDbYbk_wAAAEo"] [Tue Aug 18 12:59:38.748447 2026] [security2:error] [pid 123784:tid 123851] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBamwDnJBNj2tDbYbk8QAAcD4"], referer: https://tecpolorefrigeracaosp.com.br/login [Tue Aug 18 12:59:38.770219 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBamwDnJBNj2tDbYblAAAAAEA"] [Tue Aug 18 12:59:38.779390 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/flower.php"] [unique_id "aoSBamwDnJBNj2tDbYblAgAAAFg"] [Tue Aug 18 12:59:38.793096 2026] [security2:error] [pid 123784:tid 123918] [client 20.116.17.175:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/we.php"] [unique_id "aoSBamwDnJBNj2tDbYblBAAAAAA"] [Tue Aug 18 12:59:38.800204 2026] [security2:error] [pid 123784:tid 123941] [client 79.127.164.8:43438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/temp.sql"] [unique_id "aoSBamwDnJBNj2tDbYblBQAAABc"], referer: https://medihub.com.br/temp.sql [Tue Aug 18 12:59:38.823508 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.154.236:25364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBamwDnJBNj2tDbYblCAAAACs"] [Tue Aug 18 12:59:38.827030 2026] [security2:error] [pid 123784:tid 124029] [client 213.35.127.232:49215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBamwDnJBNj2tDbYblCQAAAG8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:38.902218 2026] [security2:error] [pid 123784:tid 123995] [client 85.154.68.202:61557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYblDQAAAE0"] [Tue Aug 18 12:59:38.902337 2026] [security2:error] [pid 123784:tid 123995] [client 85.154.68.202:61557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBamwDnJBNj2tDbYblDQAAAE0"] [Tue Aug 18 12:59:38.903268 2026] [security2:error] [pid 123784:tid 124037] [client 213.202.253.4:61323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBamwDnJBNj2tDbYblDgAAAHc"], referer: www.google.com [Tue Aug 18 12:59:38.923705 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:38.923964 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:38.930858 2026] [security2:error] [pid 123784:tid 123956] [client 68.221.73.131:10557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/inso.php"] [unique_id "aoSBamwDnJBNj2tDbYblEAAAACY"] [Tue Aug 18 12:59:38.957028 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.85.180:18751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBamwDnJBNj2tDbYblEQAAAHU"] [Tue Aug 18 12:59:38.972144 2026] [security2:error] [pid 123784:tid 124000] [client 20.51.153.15:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/fedora.php"] [unique_id "aoSBamwDnJBNj2tDbYblEgAAAFI"] [Tue Aug 18 12:59:39.041887 2026] [security2:error] [pid 123784:tid 123925] [client 20.119.58.187:10534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/css.php"] [unique_id "aoSBa2wDnJBNj2tDbYblFwAAAAc"] [Tue Aug 18 12:59:39.056329 2026] [security2:error] [pid 123784:tid 123904] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGAAARnM"], referer: https://tecpolorefrigeracaosp.com.br/wp-admin/ [Tue Aug 18 12:59:39.060161 2026] [security2:error] [pid 123784:tid 123927] [client 223.185.37.47:6512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGQAAAAk"] [Tue Aug 18 12:59:39.060267 2026] [security2:error] [pid 123784:tid 123927] [client 223.185.37.47:6512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGQAAAAk"] [Tue Aug 18 12:59:39.064232 2026] [security2:error] [pid 123784:tid 123980] [client 132.196.30.78:22123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/x.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGgAAAD4"] [Tue Aug 18 12:59:39.070984 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBa2wDnJBNj2tDbYblGwAAAEI"] [Tue Aug 18 12:59:39.088076 2026] [security2:error] [pid 123784:tid 123935] [client 132.196.30.78:22085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/fone1.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHAAAABE"] [Tue Aug 18 12:59:39.089177 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/updates.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHgAAAFc"] [Tue Aug 18 12:59:39.113406 2026] [security2:error] [pid 123784:tid 123872] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/wp-login.php"] [unique_id "aoSBa2wDnJBNj2tDbYblHwAAE1M"], referer: https://tecpolorefrigeracaosp.com.br/wp-admin/ [Tue Aug 18 12:59:39.209801 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.154.236:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBa2wDnJBNj2tDbYblJQAAADU"] [Tue Aug 18 12:59:39.226633 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:39.227069 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:39.249124 2026] [security2:error] [pid 123784:tid 124032] [client 20.127.136.245:28306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/222.php"] [unique_id "aoSBa2wDnJBNj2tDbYblKQAAAHI"] [Tue Aug 18 12:59:39.290746 2026] [security2:error] [pid 123784:tid 124038] [client 20.38.3.247:34975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/new.php"] [unique_id "aoSBa2wDnJBNj2tDbYblKwAAAHg"] [Tue Aug 18 12:59:39.372480 2026] [security2:error] [pid 123784:tid 123919] [client 20.100.169.31:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/p.php"] [unique_id "aoSBa2wDnJBNj2tDbYblLwAAAAE"] [Tue Aug 18 12:59:39.374606 2026] [security2:error] [pid 123784:tid 124010] [client 20.51.153.15:7201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/path.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMAAAAFw"] [Tue Aug 18 12:59:39.393695 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/chosen.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMgAAAH0"] [Tue Aug 18 12:59:39.435654 2026] [security2:error] [pid 123784:tid 123978] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblMwAAADw"] [Tue Aug 18 12:59:39.528588 2026] [authz_core:error] [pid 123784:tid 123843] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:39.529035 2026] [authz_core:error] [pid 123784:tid 123843] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:39.558403 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.154.236:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBa2wDnJBNj2tDbYblOQAAAAI"] [Tue Aug 18 12:59:39.572376 2026] [security2:error] [pid 123784:tid 123998] [client 4.232.94.69:19677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblOwAAAFA"] [Tue Aug 18 12:59:39.575238 2026] [security2:error] [pid 123784:tid 124030] [client 20.203.138.185:23412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mcs.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPAAAAHA"] [Tue Aug 18 12:59:39.683667 2026] [security2:error] [pid 123784:tid 123976] [client 20.51.153.15:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/456.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPgAAADo"] [Tue Aug 18 12:59:39.702696 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:28529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBa2wDnJBNj2tDbYblPwAAAG8"] [Tue Aug 18 12:59:39.709762 2026] [security2:error] [pid 123784:tid 123994] [client 37.40.227.74:56761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQAAAAEw"] [Tue Aug 18 12:59:39.709928 2026] [security2:error] [pid 123784:tid 123994] [client 37.40.227.74:56761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQAAAAEw"] [Tue Aug 18 12:59:39.724185 2026] [security2:error] [pid 123784:tid 123958] [client 20.91.215.254:18761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQwAAACg"] [Tue Aug 18 12:59:39.727202 2026] [security2:error] [pid 123784:tid 124035] [client 168.62.48.100:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/rymmm.php"] [unique_id "aoSBa2wDnJBNj2tDbYblRAAAAHU"] [Tue Aug 18 12:59:39.743800 2026] [security2:error] [pid 123784:tid 123995] [client 20.119.58.187:10521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/doc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSAAAAE0"] [Tue Aug 18 12:59:39.747993 2026] [security2:error] [pid 123784:tid 124042] [client 20.38.3.247:18817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/apreset.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSQAAAHw"] [Tue Aug 18 12:59:39.769316 2026] [autoindex:error] [pid 123784:tid 123956] [client 20.25.139.174:4468] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:39.777537 2026] [security2:error] [pid 123784:tid 123974] [client 132.196.30.78:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/index/function.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSgAAADg"] [Tue Aug 18 12:59:39.787776 2026] [security2:error] [pid 123784:tid 123954] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblSwAAACQ"] [Tue Aug 18 12:59:39.839386 2026] [security2:error] [pid 123784:tid 123918] [client 213.35.127.232:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUAAAAAA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:39.910675 2026] [security2:error] [pid 123784:tid 124008] [client 68.155.154.236:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUQAAAFo"] [Tue Aug 18 12:59:39.921555 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUwAAAE8"] [Tue Aug 18 12:59:39.921686 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:41816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBa2wDnJBNj2tDbYblUwAAAE8"] [Tue Aug 18 12:59:39.943170 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.13.23:35101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bgymj.php"] [unique_id "aoSBa2wDnJBNj2tDbYblVgAAAEU"] [Tue Aug 18 12:59:39.987319 2026] [security2:error] [pid 123784:tid 123940] [client 20.51.153.15:7194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/SMTP.php"] [unique_id "aoSBa2wDnJBNj2tDbYblXAAAABY"] [Tue Aug 18 12:59:40.017938 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kx.php"] [unique_id "aoSBbGwDnJBNj2tDbYblXQAAAE4"] [Tue Aug 18 12:59:40.095682 2026] [security2:error] [pid 123784:tid 123922] [client 20.119.58.187:10498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/elp.php"] [unique_id "aoSBbGwDnJBNj2tDbYblXwAAAAQ"] [Tue Aug 18 12:59:40.101707 2026] [security2:error] [pid 123784:tid 123950] [client 20.25.139.174:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/ww5.php"] [unique_id "aoSBbGwDnJBNj2tDbYblYAAAACA"] [Tue Aug 18 12:59:40.131865 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:40.132307 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:40.146033 2026] [security2:error] [pid 123784:tid 124044] [client 74.7.228.30:36466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "carnescapellari.top"] [uri "/index.php"] [unique_id "aoSBamwDnJBNj2tDbYbk7gAAfno"] [Tue Aug 18 12:59:40.154590 2026] [security2:error] [pid 123784:tid 123939] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBbGwDnJBNj2tDbYblZwAAABU"] [Tue Aug 18 12:59:40.155016 2026] [security2:error] [pid 123784:tid 124012] [client 132.196.30.78:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ncx.php"] [unique_id "aoSBbGwDnJBNj2tDbYblaAAAAF4"] [Tue Aug 18 12:59:40.175207 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/info.php"] [unique_id "aoSBbGwDnJBNj2tDbYblawAAAHk"] [Tue Aug 18 12:59:40.187850 2026] [security2:error] [pid 123784:tid 123807] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbAAABRI"] [Tue Aug 18 12:59:40.188077 2026] [security2:error] [pid 123784:tid 123923] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbAAABRI"] [Tue Aug 18 12:59:40.233917 2026] [security2:error] [pid 123784:tid 123952] [client 20.38.3.247:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1mage.php"] [unique_id "aoSBbGwDnJBNj2tDbYblbgAAACI"] [Tue Aug 18 12:59:40.280766 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.154.236:25357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcAAAAFg"] [Tue Aug 18 12:59:40.304791 2026] [security2:error] [pid 123784:tid 123914] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcQAASH0"] [Tue Aug 18 12:59:40.307625 2026] [security2:error] [pid 123784:tid 123921] [client 172.202.39.151:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/13.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcgAAAAM"] [Tue Aug 18 12:59:40.311259 2026] [security2:error] [pid 123784:tid 123870] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/pi.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldQAAMVE"] [Tue Aug 18 12:59:40.311289 2026] [security2:error] [pid 123784:tid 123912] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/i.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldgAAMXs"] [Tue Aug 18 12:59:40.311314 2026] [security2:error] [pid 123784:tid 123891] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/info.php"] [unique_id "aoSBbGwDnJBNj2tDbYblcwAAMWY"] [Tue Aug 18 12:59:40.311350 2026] [security2:error] [pid 123784:tid 123896] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/test.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldAAAMWs"] [Tue Aug 18 12:59:40.332575 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.85.180:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/rip.php"] [unique_id "aoSBbGwDnJBNj2tDbYbldwAAAD8"] [Tue Aug 18 12:59:40.354463 2026] [security2:error] [pid 123784:tid 124025] [client 20.91.215.254:18782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trokarautomoveis.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBbGwDnJBNj2tDbYbleQAAAGs"] [Tue Aug 18 12:59:40.371390 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/vbseo.php"] [unique_id "aoSBbGwDnJBNj2tDbYblegAAAHA"] [Tue Aug 18 12:59:40.398684 2026] [security2:error] [pid 123784:tid 124020] [client 114.5.214.109:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblggAAAGY"] [Tue Aug 18 12:59:40.404700 2026] [security2:error] [pid 123784:tid 124020] [client 114.5.214.109:50415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblggAAAGY"] [Tue Aug 18 12:59:40.428119 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:40.428391 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:40.450172 2026] [security2:error] [pid 123784:tid 124007] [client 20.119.58.187:10126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/Exception-class.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhQAAAFk"] [Tue Aug 18 12:59:40.475771 2026] [security2:error] [pid 123784:tid 123991] [client 20.203.138.185:22635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/xleet.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhgAAAEk"] [Tue Aug 18 12:59:40.526832 2026] [security2:error] [pid 123784:tid 123945] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBbGwDnJBNj2tDbYblhwAAABs"] [Tue Aug 18 12:59:40.555958 2026] [security2:error] [pid 123784:tid 123791] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSBbGwDnJBNj2tDbYbligAACQI"] [Tue Aug 18 12:59:40.559946 2026] [security2:error] [pid 123784:tid 123790] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/app_dev.php"] [unique_id "aoSBbGwDnJBNj2tDbYbliwAACQE"] [Tue Aug 18 12:59:40.600267 2026] [security2:error] [pid 123784:tid 123953] [client 20.25.139.174:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/2.php"] [unique_id "aoSBbGwDnJBNj2tDbYblkgAAACM"] [Tue Aug 18 12:59:40.612078 2026] [security2:error] [pid 123784:tid 124015] [client 20.51.153.15:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sysinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYbllAAAAGE"] [Tue Aug 18 12:59:40.638091 2026] [security2:error] [pid 123784:tid 123954] [client 20.127.136.245:28060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/a.php"] [unique_id "aoSBbGwDnJBNj2tDbYbllgAAACQ"] [Tue Aug 18 12:59:40.670506 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.154.236:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBbGwDnJBNj2tDbYblmAAAAF8"] [Tue Aug 18 12:59:40.670899 2026] [security2:error] [pid 123784:tid 123965] [client 132.196.30.78:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBbGwDnJBNj2tDbYblmQAAAC8"] [Tue Aug 18 12:59:40.737141 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:40.737591 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:40.759768 2026] [security2:error] [pid 123784:tid 123869] [remote 109.205.180.55:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.180.205.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbGwDnJBNj2tDbYbloAAAVlA"] [Tue Aug 18 12:59:40.761976 2026] [security2:error] [pid 123784:tid 123964] [client 132.196.30.78:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/aaa.php"] [unique_id "aoSBbGwDnJBNj2tDbYbloQAAAC4"] [Tue Aug 18 12:59:40.766728 2026] [security2:error] [pid 123784:tid 123968] [client 40.74.65.169:43024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBbGwDnJBNj2tDbYblogAAADI"] [Tue Aug 18 12:59:40.768448 2026] [security2:error] [pid 123784:tid 123938] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSBa2wDnJBNj2tDbYblQQAAFE4"], referer: https://www.doroincorporacoes.com.br/ [Tue Aug 18 12:59:40.803581 2026] [security2:error] [pid 123784:tid 124033] [client 20.119.58.187:10555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ee.php"] [unique_id "aoSBbGwDnJBNj2tDbYblqAAAAHM"] [Tue Aug 18 12:59:40.844174 2026] [security2:error] [pid 123784:tid 123989] [client 20.38.3.247:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/imsc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrAAAAEc"] [Tue Aug 18 12:59:40.852559 2026] [security2:error] [pid 123784:tid 123931] [client 213.35.127.232:49593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrgAAAA0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:40.853583 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.13.23:41760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/aa.php"] [unique_id "aoSBbGwDnJBNj2tDbYblrwAAAD4"] [Tue Aug 18 12:59:40.878964 2026] [authz_core:error] [pid 123784:tid 123817] [remote 57.141.22.113:41742] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:40.879248 2026] [authz_core:error] [pid 123784:tid 123817] [remote 57.141.22.113:41742] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:40.883619 2026] [security2:error] [pid 123784:tid 123939] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBbGwDnJBNj2tDbYblswAAABU"] [Tue Aug 18 12:59:40.905970 2026] [security2:error] [pid 123784:tid 124010] [client 20.51.153.15:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ppinfo.php"] [unique_id "aoSBbGwDnJBNj2tDbYbltgAAAFw"] [Tue Aug 18 12:59:40.953521 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/va.php"] [unique_id "aoSBbGwDnJBNj2tDbYbluwAAAAg"] [Tue Aug 18 12:59:40.970840 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblvgAAAAU"] [Tue Aug 18 12:59:40.970982 2026] [security2:error] [pid 123784:tid 123923] [client 192.141.172.134:54861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbGwDnJBNj2tDbYblvgAAAAU"] [Tue Aug 18 12:59:40.984189 2026] [security2:error] [pid 123784:tid 123903] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/server-info"] [unique_id "aoSBbGwDnJBNj2tDbYblwAAAN3I"] [Tue Aug 18 12:59:41.028868 2026] [security2:error] [pid 123784:tid 123978] [client 172.182.200.96:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBbWwDnJBNj2tDbYblzQAAADw"] [Tue Aug 18 12:59:41.053710 2026] [access_compat:error] [pid 123784:tid 123895] [remote 136.66.23.178:0] AH01797: client denied by server configuration: /home4/tecpolosp/public_html/server-status [Tue Aug 18 12:59:41.073620 2026] [security2:error] [pid 123784:tid 123811] [remote 203.99.146.53:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl0AAAJhY"] [Tue Aug 18 12:59:41.112920 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/chosen.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl1QAAAEA"] [Tue Aug 18 12:59:41.123856 2026] [security2:error] [pid 123784:tid 123990] [client 20.25.139.174:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl1gAAAEg"] [Tue Aug 18 12:59:41.141390 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cc.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl2gAAAF0"] [Tue Aug 18 12:59:41.155671 2026] [security2:error] [pid 123784:tid 124023] [client 20.119.58.187:10520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/edit.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl3AAAAGk"] [Tue Aug 18 12:59:41.208628 2026] [security2:error] [pid 123784:tid 123985] [client 20.51.153.15:7254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/globals.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl3wAAAEM"] [Tue Aug 18 12:59:41.226782 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.154.236:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4gAAAC8"] [Tue Aug 18 12:59:41.230028 2026] [security2:error] [pid 123784:tid 123801] [remote 129.121.74.194:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4AAAMAw"] [Tue Aug 18 12:59:41.249402 2026] [security2:error] [pid 123784:tid 124014] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl4wAAAGA"] [Tue Aug 18 12:59:41.277710 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:14986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6QAAAEw"] [Tue Aug 18 12:59:41.297907 2026] [security2:error] [pid 123784:tid 123968] [client 20.38.3.247:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6wAAADI"] [Tue Aug 18 12:59:41.324113 2026] [security2:error] [pid 123784:tid 123958] [client 132.196.30.78:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wso.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl7QAAACg"] [Tue Aug 18 12:59:41.332590 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:41.332876 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:41.426202 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:53769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fr/ms.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl9gAAABU"] [Tue Aug 18 12:59:41.454367 2026] [security2:error] [pid 123784:tid 124039] [client 40.74.65.169:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/aaa.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl-AAAAHk"] [Tue Aug 18 12:59:41.467359 2026] [security2:error] [pid 123784:tid 124004] [client 20.104.85.180:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl6gAAAFY"] [Tue Aug 18 12:59:41.485340 2026] [security2:error] [pid 123784:tid 123996] [client 20.51.153.15:7109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/yindu.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl-wAAAE4"] [Tue Aug 18 12:59:41.508768 2026] [security2:error] [pid 123784:tid 124027] [client 20.119.58.187:10512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/f35.php"] [unique_id "aoSBbWwDnJBNj2tDbYbl_QAAAG0"] [Tue Aug 18 12:59:41.572498 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:25363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmBAAAAAM"] [Tue Aug 18 12:59:41.614492 2026] [security2:error] [pid 123784:tid 123998] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmBgAAAFA"] [Tue Aug 18 12:59:41.629560 2026] [security2:error] [pid 123784:tid 123962] [client 20.25.139.174:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/atomlib.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmCQAAACw"] [Tue Aug 18 12:59:41.630783 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:41.631052 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:41.637734 2026] [security2:error] [pid 123784:tid 123978] [client 20.251.48.93:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/inso.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmCgAAADw"] [Tue Aug 18 12:59:41.686872 2026] [security2:error] [pid 123784:tid 123882] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env"] [unique_id "aoSBbWwDnJBNj2tDbYbmDgAAWF0"] [Tue Aug 18 12:59:41.705349 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmEAAAADE"] [Tue Aug 18 12:59:41.826153 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:14624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-good.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmFgAAAEo"] [Tue Aug 18 12:59:41.860572 2026] [security2:error] [pid 123784:tid 124037] [client 20.119.58.187:10473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/fff.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmGQAAAHc"] [Tue Aug 18 12:59:41.866114 2026] [security2:error] [pid 123784:tid 123926] [client 213.35.127.232:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmHAAAAAg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:41.867514 2026] [security2:error] [pid 123784:tid 123999] [client 20.51.153.15:7269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sxx.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmHQAAAFE"] [Tue Aug 18 12:59:41.915392 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.154.236:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmJgAAADM"] [Tue Aug 18 12:59:41.918440 2026] [security2:error] [pid 123784:tid 123814] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.backup"] [unique_id "aoSBbWwDnJBNj2tDbYbmJwAAcRk"] [Tue Aug 18 12:59:41.923606 2026] [security2:error] [pid 123784:tid 123864] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.bak"] [unique_id "aoSBbWwDnJBNj2tDbYbmKAAAcUs"] [Tue Aug 18 12:59:41.930758 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:41.931069 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:41.969814 2026] [security2:error] [pid 123784:tid 123985] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmKwAAAEM"] [Tue Aug 18 12:59:41.970853 2026] [security2:error] [pid 123784:tid 123906] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.old"] [unique_id "aoSBbWwDnJBNj2tDbYbmKgAAcXU"] [Tue Aug 18 12:59:41.989371 2026] [security2:error] [pid 123784:tid 124034] [client 20.38.3.247:34998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/qlex1.php"] [unique_id "aoSBbWwDnJBNj2tDbYbmLwAAAHQ"] [Tue Aug 18 12:59:42.005106 2026] [security2:error] [pid 123784:tid 123994] [client 20.215.241.237:43698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/akismet.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmMQAAAEw"] [Tue Aug 18 12:59:42.014378 2026] [security2:error] [pid 123784:tid 123947] [client 132.196.30.78:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/zup.php73"] [unique_id "aoSBbmwDnJBNj2tDbYbmMwAAAB0"] [Tue Aug 18 12:59:42.077511 2026] [security2:error] [pid 123784:tid 123896] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/api/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmOQAAAGs"] [Tue Aug 18 12:59:42.116550 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:31926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fo.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmOwAAAHU"] [Tue Aug 18 12:59:42.142715 2026] [security2:error] [pid 123784:tid 123965] [client 20.25.139.174:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/rip.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmPAAAAC8"] [Tue Aug 18 12:59:42.155262 2026] [security2:error] [pid 123784:tid 123857] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/backend/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmPQAABEQ"] [Tue Aug 18 12:59:42.160979 2026] [security2:error] [pid 123784:tid 124033] [client 40.74.65.169:20104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gecko.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmPwAAAHM"] [Tue Aug 18 12:59:42.164049 2026] [security2:error] [pid 123784:tid 123865] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmQAAABEw"] [Tue Aug 18 12:59:42.214630 2026] [security2:error] [pid 123784:tid 123936] [client 20.119.58.187:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ff1.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmQgAAABI"] [Tue Aug 18 12:59:42.215361 2026] [security2:error] [pid 123784:tid 123946] [client 20.51.153.15:7106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/settings.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmQwAAABw"] [Tue Aug 18 12:59:42.287700 2026] [security2:error] [pid 123784:tid 124015] [client 20.250.13.23:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmRwAAAGE"] [Tue Aug 18 12:59:42.300765 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/vx.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmSgAAABQ"] [Tue Aug 18 12:59:42.338086 2026] [security2:error] [pid 123784:tid 123941] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmTgAAABc"] [Tue Aug 18 12:59:42.362374 2026] [autoindex:error] [pid 123784:tid 123952] [client 169.58.72.248:60775] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:42.367371 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmUgAAAAM"] [Tue Aug 18 12:59:42.480565 2026] [security2:error] [pid 123784:tid 123976] [client 102.213.179.104:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWAAAADo"] [Tue Aug 18 12:59:42.481061 2026] [security2:error] [pid 123784:tid 123976] [client 102.213.179.104:60650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWAAAADo"] [Tue Aug 18 12:59:42.482781 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:7224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/spip.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmWQAAAGg"] [Tue Aug 18 12:59:42.534990 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:42.535442 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:42.549115 2026] [security2:error] [pid 123784:tid 123943] [client 158.23.17.4:25399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zs.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYAAAABk"] [Tue Aug 18 12:59:42.567317 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/flower.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYQAAAHA"] [Tue Aug 18 12:59:42.575732 2026] [security2:error] [pid 123784:tid 124029] [client 68.221.73.131:18857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/aa.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmYwAAAG8"] [Tue Aug 18 12:59:42.638966 2026] [security2:error] [pid 123784:tid 123933] [client 20.251.48.93:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/aa.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbAAAAA8"] [Tue Aug 18 12:59:42.656333 2026] [security2:error] [pid 123784:tid 123990] [client 20.203.138.185:45493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/gool.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbgAAAEg"] [Tue Aug 18 12:59:42.680685 2026] [security2:error] [pid 123784:tid 123927] [client 196.12.128.158:63892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbwAAAAk"] [Tue Aug 18 12:59:42.680817 2026] [security2:error] [pid 123784:tid 123927] [client 196.12.128.158:63892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmbwAAAAk"] [Tue Aug 18 12:59:42.683813 2026] [security2:error] [pid 123784:tid 123959] [client 132.196.30.78:22139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/k.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmcAAAACk"] [Tue Aug 18 12:59:42.684489 2026] [security2:error] [pid 123784:tid 123978] [client 20.25.139.174:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/p.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmcQAAADw"] [Tue Aug 18 12:59:42.715002 2026] [security2:error] [pid 123784:tid 123974] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdQAAADg"] [Tue Aug 18 12:59:42.717289 2026] [security2:error] [pid 123784:tid 124023] [client 20.38.3.247:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/mariju.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdgAAAGk"] [Tue Aug 18 12:59:42.723359 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.154.236:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmdwAAACM"] [Tue Aug 18 12:59:42.732810 2026] [security2:error] [pid 123784:tid 123982] [client 4.232.94.69:29414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/file5.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmeAAAAEA"] [Tue Aug 18 12:59:42.762397 2026] [security2:error] [pid 123784:tid 123960] [client 132.196.30.78:13654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/simple.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmegAAACo"] [Tue Aug 18 12:59:42.812945 2026] [security2:error] [pid 123784:tid 124001] [client 20.215.241.237:52740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/admin.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmfQAAAFM"] [Tue Aug 18 12:59:42.834006 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:42.834266 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:42.835214 2026] [security2:error] [pid 123784:tid 123897] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.github/.env"] [unique_id "aoSBbmwDnJBNj2tDbYbmfwAAMGw"] [Tue Aug 18 12:59:42.851640 2026] [security2:error] [pid 123784:tid 123994] [client 40.74.65.169:43015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/xiugai.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmggAAAEw"] [Tue Aug 18 12:59:42.857020 2026] [security2:error] [pid 123784:tid 124031] [client 20.51.153.15:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/search.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmgwAAAHE"] [Tue Aug 18 12:59:42.880638 2026] [security2:error] [pid 123784:tid 123937] [client 213.35.127.232:50040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmhQAAABM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:42.921637 2026] [security2:error] [pid 123784:tid 123988] [client 20.119.58.187:10515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/file.php"] [unique_id "aoSBbmwDnJBNj2tDbYbmiAAAAEY"] [Tue Aug 18 12:59:43.001571 2026] [security2:error] [pid 123784:tid 123970] [client 20.127.136.245:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wap.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmjQAAADQ"] [Tue Aug 18 12:59:43.076264 2026] [authz_core:error] [pid 123784:tid 123799] [remote 136.66.23.178:0] AH01630: client denied by server configuration: /home4/tecpolosp/public_html/.htpasswd [Tue Aug 18 12:59:43.088849 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmlAAAAH4"] [Tue Aug 18 12:59:43.127976 2026] [security2:error] [pid 123784:tid 124039] [client 20.38.3.247:8681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmlgAAAHk"] [Tue Aug 18 12:59:43.135905 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:43.136162 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:43.178054 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:22110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmmQAAAEI"] [Tue Aug 18 12:59:43.190029 2026] [security2:error] [pid 123784:tid 124043] [client 168.62.48.100:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/lddxs.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmmwAAAH0"] [Tue Aug 18 12:59:43.216671 2026] [security2:error] [pid 123784:tid 124026] [client 68.155.154.236:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmngAAAGw"] [Tue Aug 18 12:59:43.245190 2026] [security2:error] [pid 123784:tid 124024] [client 20.51.153.15:7244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/build.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmnwAAAGo"] [Tue Aug 18 12:59:43.274285 2026] [security2:error] [pid 123784:tid 123949] [client 197.184.64.235:41951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmoQAAAB8"] [Tue Aug 18 12:59:43.274439 2026] [security2:error] [pid 123784:tid 123949] [client 197.184.64.235:41951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmoQAAAB8"] [Tue Aug 18 12:59:43.274867 2026] [security2:error] [pid 123784:tid 123919] [client 20.119.58.187:10495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/goods.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmogAAAAE"] [Tue Aug 18 12:59:43.274986 2026] [security2:error] [pid 123784:tid 123980] [client 20.25.139.174:4495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadema.com.br"] [uri "/php.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmowAAAD4"] [Tue Aug 18 12:59:43.356037 2026] [security2:error] [pid 123784:tid 124030] [client 20.104.85.180:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/moon.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmpwAAAHA"] [Tue Aug 18 12:59:43.379410 2026] [security2:error] [pid 123784:tid 124015] [client 132.196.30.78:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmqgAAAGE"] [Tue Aug 18 12:59:43.425107 2026] [security2:error] [pid 123784:tid 123977] [client 20.251.48.93:9616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/img.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmrAAAADs"] [Tue Aug 18 12:59:43.460518 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmsQAAAC0"] [Tue Aug 18 12:59:43.467880 2026] [security2:error] [pid 123784:tid 123830] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmsgAAdCk"] [Tue Aug 18 12:59:43.471984 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmswAAADE"] [Tue Aug 18 12:59:43.498995 2026] [security2:error] [pid 123784:tid 123794] [remote 108.167.161.148:29664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmtgAAXgU"] [Tue Aug 18 12:59:43.533109 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/defaul.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmugAAAFc"] [Tue Aug 18 12:59:43.533793 2026] [security2:error] [pid 123784:tid 123834] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/id_rsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmuQAAdC0"] [Tue Aug 18 12:59:43.546320 2026] [security2:error] [pid 123784:tid 123960] [client 40.74.65.169:43054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/adminner.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmuwAAACo"] [Tue Aug 18 12:59:43.626977 2026] [security2:error] [pid 123784:tid 123999] [client 20.119.58.187:10548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/g.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwAAAAFE"] [Tue Aug 18 12:59:43.632951 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:33992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/loading.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwQAAAAc"] [Tue Aug 18 12:59:43.637509 2026] [security2:error] [pid 123784:tid 124036] [client 68.155.154.236:25356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmwgAAAHY"] [Tue Aug 18 12:59:43.679009 2026] [security2:error] [pid 123784:tid 123964] [client 20.38.3.247:37121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/contacto.php"] [unique_id "aoSBb2wDnJBNj2tDbYbmxgAAAC4"] [Tue Aug 18 12:59:43.701499 2026] [security2:error] [pid 123784:tid 123825] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSBb2wDnJBNj2tDbYbmyAAAJSQ"] [Tue Aug 18 12:59:43.742274 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:43.742714 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:43.803740 2026] [security2:error] [pid 123784:tid 123932] [client 20.51.153.15:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/twin.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm0wAAAA4"] [Tue Aug 18 12:59:43.839602 2026] [security2:error] [pid 123784:tid 123993] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm1gAAAEs"] [Tue Aug 18 12:59:43.893795 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm2AAAABE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:43.926590 2026] [security2:error] [pid 123784:tid 123995] [client 20.38.3.247:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm2QAAAE0"] [Tue Aug 18 12:59:43.947221 2026] [security2:error] [pid 123784:tid 123847] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/id_dsa"] [unique_id "aoSBb2wDnJBNj2tDbYbm2gAAFTo"] [Tue Aug 18 12:59:43.974702 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:28511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bgymj.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm4AAAAAY"] [Tue Aug 18 12:59:43.991467 2026] [security2:error] [pid 123784:tid 123972] [client 20.119.58.187:10517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm5AAAADY"] [Tue Aug 18 12:59:43.992216 2026] [security2:error] [pid 123784:tid 123957] [client 132.196.30.78:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/u.php"] [unique_id "aoSBb2wDnJBNj2tDbYbm5QAAACc"] [Tue Aug 18 12:59:44.014210 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm5gAAAH0"] [Tue Aug 18 12:59:44.017323 2026] [security2:error] [pid 123784:tid 124040] [client 20.203.138.185:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/maxro.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm5wAAAHo"] [Tue Aug 18 12:59:44.039287 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:44.039564 2026] [authz_core:error] [pid 123784:tid 123850] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:44.091357 2026] [security2:error] [pid 123784:tid 124014] [client 20.250.13.23:31084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bolt.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm6gAAAGA"] [Tue Aug 18 12:59:44.160633 2026] [security2:error] [pid 123784:tid 124003] [client 20.51.153.15:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/new2.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm7AAAAFU"] [Tue Aug 18 12:59:44.194122 2026] [security2:error] [pid 123784:tid 123831] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/privatekey.key"] [unique_id "aoSBcGwDnJBNj2tDbYbm8QAAMyo"] [Tue Aug 18 12:59:44.201370 2026] [security2:error] [pid 123784:tid 124010] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm9AAAAFw"] [Tue Aug 18 12:59:44.213664 2026] [security2:error] [pid 123784:tid 123911] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/key.pem"] [unique_id "aoSBcGwDnJBNj2tDbYbm-QAAM3o"] [Tue Aug 18 12:59:44.243661 2026] [security2:error] [pid 123784:tid 123977] [client 20.38.3.247:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/image2.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm-wAAADs"] [Tue Aug 18 12:59:44.249174 2026] [security2:error] [pid 123784:tid 123933] [client 40.74.65.169:19461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file1221.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm_AAAAA8"] [Tue Aug 18 12:59:44.291709 2026] [security2:error] [pid 123784:tid 124025] [client 172.182.200.96:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbm_wAAAGs"] [Tue Aug 18 12:59:44.340686 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:44.341049 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:44.350945 2026] [security2:error] [pid 123784:tid 123962] [client 20.119.58.187:10514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnBQAAACw"] [Tue Aug 18 12:59:44.425999 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:10333] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/1.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnCQAAACk"] [Tue Aug 18 12:59:44.426118 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/1.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnCQAAACk"] [Tue Aug 18 12:59:44.441264 2026] [security2:error] [pid 123784:tid 124013] [client 20.51.153.15:7288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/rex.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnDgAAAF8"] [Tue Aug 18 12:59:44.447385 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/aa.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnDwAAADE"] [Tue Aug 18 12:59:44.474714 2026] [security2:error] [pid 123784:tid 124019] [client 68.155.154.236:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnEgAAAGU"] [Tue Aug 18 12:59:44.534608 2026] [security2:error] [pid 123784:tid 124011] [client 79.127.164.8:43514] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/test.bak"] [unique_id "aoSBcGwDnJBNj2tDbYbnGQAAAF0"], referer: https://medihub.com.br/test.bak [Tue Aug 18 12:59:44.567381 2026] [security2:error] [pid 123784:tid 123918] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnHAAAAAA"] [Tue Aug 18 12:59:44.590859 2026] [security2:error] [pid 123784:tid 123951] [client 132.196.30.78:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnIAAAACE"] [Tue Aug 18 12:59:44.591340 2026] [security2:error] [pid 123784:tid 123891] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSBcGwDnJBNj2tDbYbnHwAAM2Y"] [Tue Aug 18 12:59:44.688744 2026] [security2:error] [pid 123784:tid 123992] [client 86.120.159.145:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKAAAAEo"] [Tue Aug 18 12:59:44.688871 2026] [security2:error] [pid 123784:tid 123992] [client 86.120.159.145:11293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKAAAAEo"] [Tue Aug 18 12:59:44.705192 2026] [security2:error] [pid 123784:tid 123981] [client 20.119.58.187:10536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/in.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnKQAAAD8"] [Tue Aug 18 12:59:44.742497 2026] [security2:error] [pid 123784:tid 123936] [client 20.38.3.247:29763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fb.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnLgAAABI"] [Tue Aug 18 12:59:44.785183 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:38131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.noise2.com.br"] [uri "/php.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnMQAAAGI"] [Tue Aug 18 12:59:44.786145 2026] [autoindex:error] [pid 123784:tid 123924] [client 132.196.30.78:22138] AH01276: Cannot serve directory /home3/cadema/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:44.859409 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/verification.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnNwAAAHo"] [Tue Aug 18 12:59:44.867915 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.85.180:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/cache.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnOAAAADU"] [Tue Aug 18 12:59:44.874370 2026] [security2:error] [pid 123784:tid 123942] [client 68.155.154.236:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnOQAAABg"] [Tue Aug 18 12:59:44.904063 2026] [security2:error] [pid 123784:tid 123876] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBcGwDnJBNj2tDbYbnOwAARVc"] [Tue Aug 18 12:59:44.906830 2026] [security2:error] [pid 123784:tid 123932] [client 213.35.127.232:50459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnPAAAAA4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:44.907894 2026] [security2:error] [pid 123784:tid 123941] [client 20.203.138.185:22639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wdf.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnPQAAABc"] [Tue Aug 18 12:59:44.931169 2026] [security2:error] [pid 123784:tid 123952] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnQAAAACI"] [Tue Aug 18 12:59:44.941151 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:44.941421 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:44.943836 2026] [security2:error] [pid 123784:tid 123938] [client 40.74.65.169:20103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inx.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnQwAAABQ"] [Tue Aug 18 12:59:44.960902 2026] [security2:error] [pid 123784:tid 123972] [client 20.127.136.245:28508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-mail.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnRgAAADY"] [Tue Aug 18 12:59:45.058748 2026] [security2:error] [pid 123784:tid 124024] [client 20.119.58.187:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/info.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnTQAAAGo"] [Tue Aug 18 12:59:45.131764 2026] [security2:error] [pid 123784:tid 123973] [client 20.38.3.247:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/gi.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnUgAAADc"] [Tue Aug 18 12:59:45.154948 2026] [security2:error] [pid 123784:tid 124042] [client 132.196.30.78:22138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/ww5.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnVQAAAHw"] [Tue Aug 18 12:59:45.159389 2026] [security2:error] [pid 123784:tid 124038] [client 213.202.253.4:57502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnVgAAAHg"], referer: www.google.com [Tue Aug 18 12:59:45.193226 2026] [security2:error] [pid 123784:tid 123955] [client 49.13.134.145:37158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSBcGwDnJBNj2tDbYbnJAAAACU"], referer: http://www.webeb.com.br [Tue Aug 18 12:59:45.202914 2026] [security2:error] [pid 123784:tid 124005] [client 20.251.48.93:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/222.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnXgAAAFc"] [Tue Aug 18 12:59:45.216991 2026] [security2:error] [pid 123784:tid 123996] [client 20.215.241.237:36129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jotamotos.com.br"] [uri "/ajax.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYAAAAE4"] [Tue Aug 18 12:59:45.220584 2026] [security2:error] [pid 123784:tid 123940] [client 192.141.172.134:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYgAAABY"] [Tue Aug 18 12:59:45.220705 2026] [security2:error] [pid 123784:tid 123940] [client 192.141.172.134:55095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnYgAAABY"] [Tue Aug 18 12:59:45.235214 2026] [security2:error] [pid 123784:tid 124023] [client 20.51.153.15:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/smtp.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnZAAAAGk"] [Tue Aug 18 12:59:45.244980 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:45.245246 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:45.250198 2026] [security2:error] [pid 123784:tid 124013] [client 20.38.3.247:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/yj09.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnZgAAAF8"] [Tue Aug 18 12:59:45.272389 2026] [authz_core:error] [pid 123784:tid 123812] [remote 57.141.14.91:30200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:45.272680 2026] [authz_core:error] [pid 123784:tid 123812] [remote 57.141.14.91:30200] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:45.292866 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnbAAAAEw"] [Tue Aug 18 12:59:45.328509 2026] [security2:error] [pid 123784:tid 123921] [client 132.196.30.78:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/h.php"] [unique_id "aoSBcWwDnJBNj2tDbYbncAAAAAM"] [Tue Aug 18 12:59:45.347647 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.154.236:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBcWwDnJBNj2tDbYbncgAAABo"] [Tue Aug 18 12:59:45.410930 2026] [security2:error] [pid 123784:tid 123966] [client 20.119.58.187:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/inputs.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnegAAADA"] [Tue Aug 18 12:59:45.478096 2026] [security2:error] [pid 123784:tid 123992] [client 20.51.153.15:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/teste.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnfwAAAEo"] [Tue Aug 18 12:59:45.516378 2026] [security2:error] [pid 123784:tid 124000] [client 20.127.136.245:28083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bolt.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnggAAAFI"] [Tue Aug 18 12:59:45.548206 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:45.548668 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:45.580343 2026] [security2:error] [pid 123784:tid 123827] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/laravel/.env"] [unique_id "aoSBcWwDnJBNj2tDbYbniQAAMyY"] [Tue Aug 18 12:59:45.592889 2026] [security2:error] [pid 123784:tid 124033] [client 3.149.0.107:59994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSBcWwDnJBNj2tDbYbnjAAAAHM"] [Tue Aug 18 12:59:45.599960 2026] [security2:error] [pid 123784:tid 123979] [client 158.23.17.4:34042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ke.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnjQAAAD0"] [Tue Aug 18 12:59:45.620591 2026] [security2:error] [pid 123784:tid 124040] [client 40.74.65.169:42489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/reviall.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnjwAAAHo"] [Tue Aug 18 12:59:45.639380 2026] [security2:error] [pid 123784:tid 123895] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config/.env.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnlgAAM2o"] [Tue Aug 18 12:59:45.642165 2026] [security2:error] [pid 123784:tid 123942] [client 20.38.3.247:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/video.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnlwAAABg"] [Tue Aug 18 12:59:45.658796 2026] [security2:error] [pid 123784:tid 124027] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnmAAAAG0"] [Tue Aug 18 12:59:45.753606 2026] [security2:error] [pid 123784:tid 123938] [client 20.251.48.93:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/key.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnnAAAABQ"] [Tue Aug 18 12:59:45.765595 2026] [security2:error] [pid 123784:tid 123947] [client 20.119.58.187:10455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/item.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnnQAAAB0"] [Tue Aug 18 12:59:45.801711 2026] [security2:error] [pid 123784:tid 124016] [client 132.196.30.78:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/2.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnngAAAGI"] [Tue Aug 18 12:59:45.804311 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.154.236:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnoAAAAEU"] [Tue Aug 18 12:59:45.813953 2026] [authz_core:error] [pid 123784:tid 123826] [remote 57.141.22.18:41402] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:45.814214 2026] [authz_core:error] [pid 123784:tid 123826] [remote 57.141.22.18:41402] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:45.815033 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/local.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnogAAAHA"] [Tue Aug 18 12:59:45.825885 2026] [security2:error] [pid 123784:tid 123797] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnpQAAWQg"] [Tue Aug 18 12:59:45.916399 2026] [security2:error] [pid 123784:tid 123866] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/config.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnqwAAG00"] [Tue Aug 18 12:59:45.916488 2026] [security2:error] [pid 123784:tid 123831] [remote 136.66.23.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.23.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBcWwDnJBNj2tDbYbnrAAAGyo"] [Tue Aug 18 12:59:45.928835 2026] [security2:error] [pid 123784:tid 123957] [client 213.35.127.232:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBcWwDnJBNj2tDbYbnrwAAACc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:45.942921 2026] [security2:error] [pid 123784:tid 123843] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/core/.env"] [unique_id "aoSBcWwDnJBNj2tDbYbnsQAAQDY"] [Tue Aug 18 12:59:45.972475 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/hel.php"] [unique_id "aoSBcWwDnJBNj2tDbYbntAAAADQ"] [Tue Aug 18 12:59:46.026015 2026] [security2:error] [pid 123784:tid 123980] [client 20.127.136.245:28315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bthil.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnuQAAAD4"] [Tue Aug 18 12:59:46.035445 2026] [security2:error] [pid 123784:tid 123997] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnugAAAE8"] [Tue Aug 18 12:59:46.057431 2026] [authz_core:error] [pid 123784:tid 123908] [remote 57.141.22.34:36012] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:46.057696 2026] [authz_core:error] [pid 123784:tid 123908] [remote 57.141.22.34:36012] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:46.060390 2026] [security2:error] [pid 123784:tid 123893] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/.env.swp"] [unique_id "aoSBcmwDnJBNj2tDbYbnvQAAQGg"] [Tue Aug 18 12:59:46.062662 2026] [security2:error] [pid 123784:tid 124029] [client 20.51.153.15:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp_sitting.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnvgAAAG8"] [Tue Aug 18 12:59:46.075795 2026] [security2:error] [pid 123784:tid 124006] [client 172.202.39.151:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/admin.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnvwAAAFg"] [Tue Aug 18 12:59:46.116769 2026] [security2:error] [pid 123784:tid 123944] [client 20.119.58.187:10558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/k.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnxQAAABo"] [Tue Aug 18 12:59:46.143183 2026] [security2:error] [pid 123784:tid 123874] [remote 136.66.23.178:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/public/.env"] [unique_id "aoSBcmwDnJBNj2tDbYbnyQAAKFU"] [Tue Aug 18 12:59:46.158852 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:46.159306 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:46.176627 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.154.236:25380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBcmwDnJBNj2tDbYbnzgAAAEo"] [Tue Aug 18 12:59:46.190325 2026] [security2:error] [pid 123784:tid 124000] [client 20.203.138.185:24946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ff1.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn0gAAAFI"] [Tue Aug 18 12:59:46.302954 2026] [security2:error] [pid 123784:tid 124027] [client 20.118.133.132:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bajah.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn2QAAAG0"] [Tue Aug 18 12:59:46.319197 2026] [security2:error] [pid 123784:tid 124020] [client 40.74.65.169:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/11.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn2gAAAGY"] [Tue Aug 18 12:59:46.330569 2026] [security2:error] [pid 123784:tid 123959] [client 3.149.0.107:59992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "natupedras.com.br"] [uri "/"] [unique_id "aoSBcmwDnJBNj2tDbYbn2wAAACk"] [Tue Aug 18 12:59:46.349558 2026] [security2:error] [pid 123784:tid 123969] [client 20.51.153.15:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ninja.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn3QAAADM"] [Tue Aug 18 12:59:46.372305 2026] [security2:error] [pid 123784:tid 123972] [client 132.196.30.78:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn4AAAADY"] [Tue Aug 18 12:59:46.378493 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:44855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nh.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn4gAAAB0"] [Tue Aug 18 12:59:46.402476 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/public/css.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn5gAAAEY"] [Tue Aug 18 12:59:46.402948 2026] [security2:error] [pid 123784:tid 123954] [client 4.232.94.69:14980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/new.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn5wAAACQ"] [Tue Aug 18 12:59:46.414081 2026] [security2:error] [pid 123784:tid 123989] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn6AAAAEc"] [Tue Aug 18 12:59:46.450775 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:46.451131 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:46.469454 2026] [security2:error] [pid 123784:tid 123923] [client 20.119.58.187:10532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/license.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn7QAAAAU"] [Tue Aug 18 12:59:46.565586 2026] [security2:error] [pid 123784:tid 123963] [client 158.23.17.4:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iz.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn9gAAAC0"] [Tue Aug 18 12:59:46.598988 2026] [security2:error] [pid 123784:tid 123852] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-AAACD8"] [Tue Aug 18 12:59:46.599221 2026] [security2:error] [pid 123784:tid 123926] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-AAACD8"] [Tue Aug 18 12:59:46.614640 2026] [security2:error] [pid 123784:tid 123996] [client 20.38.3.247:8685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/grok.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn-QAAAE4"] [Tue Aug 18 12:59:46.627715 2026] [security2:error] [pid 123784:tid 123929] [client 20.51.153.15:7294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/phpprobe.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn_QAAAAs"] [Tue Aug 18 12:59:46.651211 2026] [security2:error] [pid 123784:tid 123994] [client 20.127.136.245:28062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/x.php"] [unique_id "aoSBcmwDnJBNj2tDbYbn_wAAAEw"] [Tue Aug 18 12:59:46.683452 2026] [security2:error] [pid 123784:tid 123974] [client 3.149.0.107:59978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSBcmwDnJBNj2tDbYboAgAAADg"] [Tue Aug 18 12:59:46.689276 2026] [security2:error] [pid 123784:tid 124042] [client 68.155.154.236:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBcmwDnJBNj2tDbYboAwAAAHw"] [Tue Aug 18 12:59:46.739680 2026] [security2:error] [pid 123784:tid 123973] [client 132.196.30.78:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBcmwDnJBNj2tDbYboBgAAADc"] [Tue Aug 18 12:59:46.747233 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:46.747521 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:46.780052 2026] [security2:error] [pid 123784:tid 123951] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBcmwDnJBNj2tDbYboCAAAACE"] [Tue Aug 18 12:59:46.823996 2026] [security2:error] [pid 123784:tid 124011] [client 20.119.58.187:10552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/load.php"] [unique_id "aoSBcmwDnJBNj2tDbYboCgAAAF0"] [Tue Aug 18 12:59:46.934059 2026] [security2:error] [pid 123784:tid 123854] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/config/.env.php"] [unique_id "aoSBcmwDnJBNj2tDbYboEQAATUE"] [Tue Aug 18 12:59:46.944345 2026] [security2:error] [pid 123784:tid 123945] [client 213.35.127.232:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBcmwDnJBNj2tDbYboEgAAABs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:46.954914 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/indes.php"] [unique_id "aoSBcmwDnJBNj2tDbYboFAAAAH8"] [Tue Aug 18 12:59:46.956169 2026] [security2:error] [pid 123784:tid 123824] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBcmwDnJBNj2tDbYboGwAAXCM"] [Tue Aug 18 12:59:47.017053 2026] [security2:error] [pid 123784:tid 124032] [client 40.74.65.169:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/File.php"] [unique_id "aoSBc2wDnJBNj2tDbYboHwAAAHI"] [Tue Aug 18 12:59:47.035631 2026] [security2:error] [pid 123784:tid 124043] [client 172.202.39.151:44497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIAAAAH0"] [Tue Aug 18 12:59:47.046994 2026] [security2:error] [pid 123784:tid 123968] [client 20.104.85.180:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIgAAADI"] [Tue Aug 18 12:59:47.050059 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/wp-title.php"] [unique_id "aoSBc2wDnJBNj2tDbYboIwAAAHo"] [Tue Aug 18 12:59:47.060445 2026] [security2:error] [pid 123784:tid 124029] [client 132.196.30.78:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/a7.php"] [unique_id "aoSBc2wDnJBNj2tDbYboJQAAAG8"] [Tue Aug 18 12:59:47.116807 2026] [security2:error] [pid 123784:tid 123820] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/config.php.bak"] [unique_id "aoSBc2wDnJBNj2tDbYboJwAABB8"] [Tue Aug 18 12:59:47.119777 2026] [security2:error] [pid 123784:tid 123890] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSBc2wDnJBNj2tDbYboKAAAD2U"] [Tue Aug 18 12:59:47.162454 2026] [security2:error] [pid 123784:tid 123959] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYboKwAAACk"] [Tue Aug 18 12:59:47.175999 2026] [security2:error] [pid 123784:tid 124039] [client 20.119.58.187:10454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/manager.php"] [unique_id "aoSBc2wDnJBNj2tDbYboLQAAAHk"] [Tue Aug 18 12:59:47.179052 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.154.236:25379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBc2wDnJBNj2tDbYboLgAAADw"] [Tue Aug 18 12:59:47.200130 2026] [security2:error] [pid 123784:tid 124044] [client 3.149.0.107:50058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/ads.txt"] [unique_id "aoSBc2wDnJBNj2tDbYboMAAAAH4"] [Tue Aug 18 12:59:47.254499 2026] [security2:error] [pid 123784:tid 123948] [client 20.127.136.245:28510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/index/function.php"] [unique_id "aoSBc2wDnJBNj2tDbYboMQAAAB4"] [Tue Aug 18 12:59:47.271769 2026] [security2:error] [pid 123784:tid 124027] [client 132.196.30.78:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/atomlib.php"] [unique_id "aoSBc2wDnJBNj2tDbYboMwAAAG0"] [Tue Aug 18 12:59:47.314232 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zjggu.php"] [unique_id "aoSBc2wDnJBNj2tDbYboNQAAAHA"] [Tue Aug 18 12:59:47.391280 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/oo.php"] [unique_id "aoSBc2wDnJBNj2tDbYboPgAAAGs"] [Tue Aug 18 12:59:47.393069 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:53699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/classwithtostring.php"] [unique_id "aoSBc2wDnJBNj2tDbYboPwAAAFA"] [Tue Aug 18 12:59:47.410171 2026] [security2:error] [pid 123784:tid 123962] [client 20.51.153.15:7257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/styles.php"] [unique_id "aoSBc2wDnJBNj2tDbYboQAAAACw"] [Tue Aug 18 12:59:47.422563 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:41773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/bthil.php"] [unique_id "aoSBc2wDnJBNj2tDbYboQwAAAFc"] [Tue Aug 18 12:59:47.462018 2026] [security2:error] [pid 123784:tid 123949] [client 20.38.3.247:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRgAAAB8"] [Tue Aug 18 12:59:47.475179 2026] [security2:error] [pid 123784:tid 123963] [client 138.36.100.162:42205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRwAAAC0"] [Tue Aug 18 12:59:47.475291 2026] [security2:error] [pid 123784:tid 123963] [client 138.36.100.162:42205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboRwAAAC0"] [Tue Aug 18 12:59:47.528773 2026] [security2:error] [pid 123784:tid 123923] [client 3.149.0.107:50046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.natupedras.com.br"] [uri "/"] [unique_id "aoSBc2wDnJBNj2tDbYboSQAAAAU"] [Tue Aug 18 12:59:47.534573 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:42715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboSwAAAEA"] [Tue Aug 18 12:59:47.535051 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:42715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYboSwAAAEA"] [Tue Aug 18 12:59:47.536420 2026] [security2:error] [pid 123784:tid 124028] [client 20.119.58.187:10474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/media.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTAAAAG4"] [Tue Aug 18 12:59:47.542535 2026] [security2:error] [pid 123784:tid 123977] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTQAAADs"] [Tue Aug 18 12:59:47.559446 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:57031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBc2wDnJBNj2tDbYboTwAAAHw"] [Tue Aug 18 12:59:47.648819 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:47.649082 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:47.671838 2026] [security2:error] [pid 123784:tid 124018] [client 20.51.153.15:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/server.php"] [unique_id "aoSBc2wDnJBNj2tDbYboWgAAAGQ"] [Tue Aug 18 12:59:47.725757 2026] [security2:error] [pid 123784:tid 123983] [client 40.74.65.169:42455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fi22.php"] [unique_id "aoSBc2wDnJBNj2tDbYboYAAAAEE"] [Tue Aug 18 12:59:47.787716 2026] [security2:error] [pid 123784:tid 123990] [client 216.73.161.213:60125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBc2wDnJBNj2tDbYboZQAAAEg"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 12:59:47.832504 2026] [security2:error] [pid 123784:tid 124029] [client 20.38.3.247:34993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/bs1.php"] [unique_id "aoSBc2wDnJBNj2tDbYboagAAAG8"] [Tue Aug 18 12:59:47.832776 2026] [security2:error] [pid 123784:tid 123961] [client 172.182.200.96:7600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBc2wDnJBNj2tDbYboawAAACs"] [Tue Aug 18 12:59:47.837353 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.154.236:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBc2wDnJBNj2tDbYbobAAAAAQ"] [Tue Aug 18 12:59:47.873067 2026] [security2:error] [pid 123784:tid 124023] [client 149.34.210.141:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocQAAAGk"] [Tue Aug 18 12:59:47.873660 2026] [security2:error] [pid 123784:tid 124041] [client 20.127.136.245:28291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/aaa.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocgAAAHs"] [Tue Aug 18 12:59:47.884840 2026] [security2:error] [pid 123784:tid 124045] [client 132.196.30.78:20456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/manager.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocwAAAH8"] [Tue Aug 18 12:59:47.889953 2026] [security2:error] [pid 123784:tid 123924] [client 20.119.58.187:10528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/mar.php"] [unique_id "aoSBc2wDnJBNj2tDbYbodAAAAAY"] [Tue Aug 18 12:59:47.906177 2026] [security2:error] [pid 123784:tid 123993] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBc2wDnJBNj2tDbYbodgAAAEs"] [Tue Aug 18 12:59:47.913614 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:12486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ja.php"] [unique_id "aoSBc2wDnJBNj2tDbYboeAAAAAk"] [Tue Aug 18 12:59:47.936933 2026] [security2:error] [pid 123784:tid 123948] [client 172.202.39.151:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/admin.php"] [unique_id "aoSBc2wDnJBNj2tDbYboegAAAB4"] [Tue Aug 18 12:59:47.941755 2026] [security2:error] [pid 123784:tid 124022] [client 20.203.138.185:32842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/guk.php"] [unique_id "aoSBc2wDnJBNj2tDbYboewAAAGg"] [Tue Aug 18 12:59:47.942341 2026] [security2:error] [pid 123784:tid 124027] [client 20.104.85.180:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofAAAAG0"] [Tue Aug 18 12:59:47.952808 2026] [security2:error] [pid 123784:tid 123936] [client 132.196.30.78:15652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/rip.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofgAAABI"] [Tue Aug 18 12:59:47.953122 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:47.953482 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:47.957209 2026] [security2:error] [pid 123784:tid 123988] [client 20.51.153.15:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/xinfo.php"] [unique_id "aoSBc2wDnJBNj2tDbYbofwAAAEY"] [Tue Aug 18 12:59:47.958198 2026] [security2:error] [pid 123784:tid 123973] [client 213.35.127.232:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBc2wDnJBNj2tDbYbogAAAADc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:47.973759 2026] [security2:error] [pid 123784:tid 124014] [client 20.251.48.93:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/chosen.php"] [unique_id "aoSBc2wDnJBNj2tDbYbogQAAAGA"] [Tue Aug 18 12:59:48.040122 2026] [security2:error] [pid 123784:tid 124035] [client 4.232.94.69:14969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fm.php"] [unique_id "aoSBdGwDnJBNj2tDbYbohwAAAHU"] [Tue Aug 18 12:59:48.089287 2026] [autoindex:error] [pid 123784:tid 123947] [client 39.46.181.96:34610] AH01276: Cannot serve directory /home3/worldportascom/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://worldportas.com.br/wp-includes/ [Tue Aug 18 12:59:48.089845 2026] [security2:error] [pid 123784:tid 124024] [client 79.127.164.8:36272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/test.sql"] [unique_id "aoSBdGwDnJBNj2tDbYbojAAAAGo"], referer: https://medihub.com.br/test.sql [Tue Aug 18 12:59:48.128500 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:17552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBdGwDnJBNj2tDbYbojgAAABg"] [Tue Aug 18 12:59:48.140690 2026] [security2:error] [pid 123784:tid 124023] [client 149.34.210.141:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBc2wDnJBNj2tDbYbocQAAAGk"] [Tue Aug 18 12:59:48.200559 2026] [security2:error] [pid 123784:tid 123921] [client 20.38.3.247:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/hp2.php"] [unique_id "aoSBdGwDnJBNj2tDbYbokwAAAAM"] [Tue Aug 18 12:59:48.236140 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:56006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/car+parking+dinheiro+infinito+e+tudo+desbloqueado-3/"] [unique_id "aoSBdGwDnJBNj2tDbYbolgAAAHw"] [Tue Aug 18 12:59:48.236240 2026] [security2:error] [pid 123784:tid 124042] [client 216.244.66.243:56006] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/car+parking+dinheiro+infinito+e+tudo+desbloqueado-3/"] [unique_id "aoSBdGwDnJBNj2tDbYbolgAAAHw"] [Tue Aug 18 12:59:48.244284 2026] [security2:error] [pid 123784:tid 124015] [client 20.119.58.187:10544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/my1.php"] [unique_id "aoSBdGwDnJBNj2tDbYbomAAAAGE"] [Tue Aug 18 12:59:48.250629 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:48.250894 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:48.269942 2026] [security2:error] [pid 123784:tid 124031] [client 68.155.154.236:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBdGwDnJBNj2tDbYbonQAAAHE"] [Tue Aug 18 12:59:48.278411 2026] [security2:error] [pid 123784:tid 123987] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBdGwDnJBNj2tDbYbonwAAAEU"] [Tue Aug 18 12:59:48.284279 2026] [security2:error] [pid 123784:tid 123951] [client 20.51.153.15:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/sym.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooAAAACE"] [Tue Aug 18 12:59:48.305119 2026] [security2:error] [pid 123784:tid 123929] [client 157.20.138.62:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooQAAAAs"] [Tue Aug 18 12:59:48.305257 2026] [security2:error] [pid 123784:tid 123929] [client 157.20.138.62:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbooQAAAAs"] [Tue Aug 18 12:59:48.333062 2026] [security2:error] [pid 123784:tid 124002] [client 20.104.85.180:18693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/o.php"] [unique_id "aoSBdGwDnJBNj2tDbYboowAAAFQ"] [Tue Aug 18 12:59:48.365112 2026] [security2:error] [pid 123784:tid 123999] [client 20.127.136.245:28084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/abcd.php"] [unique_id "aoSBdGwDnJBNj2tDbYboqAAAAFE"] [Tue Aug 18 12:59:48.410303 2026] [security2:error] [pid 123784:tid 123995] [client 40.74.65.169:19478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBdGwDnJBNj2tDbYboqwAAAE0"] [Tue Aug 18 12:59:48.444891 2026] [security2:error] [pid 123784:tid 123965] [client 68.221.73.131:21303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/img.php"] [unique_id "aoSBdGwDnJBNj2tDbYbosQAAAC8"] [Tue Aug 18 12:59:48.452453 2026] [security2:error] [pid 123784:tid 123983] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYborQAAQTM"] [Tue Aug 18 12:59:48.467792 2026] [security2:error] [pid 123784:tid 123935] [client 172.202.39.151:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gelay.php"] [unique_id "aoSBdGwDnJBNj2tDbYbosgAAABE"] [Tue Aug 18 12:59:48.544641 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protech.seg.br"] [uri "/ye.php"] [unique_id "aoSBdGwDnJBNj2tDbYbotwAAAHo"] [Tue Aug 18 12:59:48.593914 2026] [security2:error] [pid 123784:tid 124012] [client 132.196.30.78:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/w1.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovAAAAF4"] [Tue Aug 18 12:59:48.597324 2026] [security2:error] [pid 123784:tid 124043] [client 20.119.58.187:10543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/mm.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovQAAAH0"] [Tue Aug 18 12:59:48.619555 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovwAAABc"] [Tue Aug 18 12:59:48.619710 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:56921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbovwAAABc"] [Tue Aug 18 12:59:48.625099 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:15771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/se.php"] [unique_id "aoSBdGwDnJBNj2tDbYbowQAAAGw"] [Tue Aug 18 12:59:48.631792 2026] [security2:error] [pid 123784:tid 123918] [client 132.196.30.78:22091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/p.php"] [unique_id "aoSBdGwDnJBNj2tDbYbowwAAAAA"] [Tue Aug 18 12:59:48.654714 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBdGwDnJBNj2tDbYboxgAAAEk"] [Tue Aug 18 12:59:48.715147 2026] [security2:error] [pid 123784:tid 123928] [client 178.153.171.161:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYboygAAAAo"] [Tue Aug 18 12:59:48.715347 2026] [security2:error] [pid 123784:tid 123928] [client 178.153.171.161:63451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYboygAAAAo"] [Tue Aug 18 12:59:48.726017 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/yb.php"] [unique_id "aoSBdGwDnJBNj2tDbYbozAAAAEY"] [Tue Aug 18 12:59:48.786400 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/st.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0gAAACo"] [Tue Aug 18 12:59:48.803099 2026] [security2:error] [pid 123784:tid 124028] [client 5.31.227.224:29897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0wAAAG4"] [Tue Aug 18 12:59:48.807603 2026] [security2:error] [pid 123784:tid 124028] [client 5.31.227.224:29897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo0wAAAG4"] [Tue Aug 18 12:59:48.816383 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.154.236:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo1wAAAGs"] [Tue Aug 18 12:59:48.838751 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-good.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo2QAAAH4"] [Tue Aug 18 12:59:48.859032 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:48.859480 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:48.910794 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.28:56226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:48.911054 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.28:56226] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:48.928677 2026] [security2:error] [pid 123784:tid 123880] [remote 192.250.229.214:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo3gAAZls"] [Tue Aug 18 12:59:48.950028 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/network.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo3wAAACM"] [Tue Aug 18 12:59:48.974760 2026] [security2:error] [pid 123784:tid 124045] [client 213.35.127.232:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBdGwDnJBNj2tDbYbo4QAAAH8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:49.019829 2026] [security2:error] [pid 123784:tid 123970] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/first.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6AAAADQ"] [Tue Aug 18 12:59:49.058673 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:33425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xx.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6QAAAHM"] [Tue Aug 18 12:59:49.059968 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.85.180:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/bb.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo6gAAAHw"] [Tue Aug 18 12:59:49.099057 2026] [security2:error] [pid 123784:tid 123977] [client 40.74.65.169:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7AAAADs"] [Tue Aug 18 12:59:49.119680 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vp.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7QAAABU"] [Tue Aug 18 12:59:49.136757 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.138.185:53777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-the.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo7wAAAGI"] [Tue Aug 18 12:59:49.155979 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:49.156256 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:49.223589 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:15144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/le.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo9QAAACA"] [Tue Aug 18 12:59:49.239543 2026] [security2:error] [pid 123784:tid 123923] [client 132.196.30.78:14635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cadema.com.br"] [uri "/php.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo9gAAAAU"] [Tue Aug 18 12:59:49.296079 2026] [security2:error] [pid 123784:tid 123796] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbo-wAATQc"] [Tue Aug 18 12:59:49.303269 2026] [security2:error] [pid 123784:tid 123929] [client 20.119.58.187:10462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/new.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo_AAAAAs"] [Tue Aug 18 12:59:49.309751 2026] [security2:error] [pid 123784:tid 123945] [client 20.38.3.247:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/vc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbo_QAAABs"] [Tue Aug 18 12:59:49.369477 2026] [security2:error] [pid 123784:tid 123966] [client 20.127.136.245:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/simple.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCAAAADA"] [Tue Aug 18 12:59:49.383018 2026] [security2:error] [pid 123784:tid 123983] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCQAAAEE"] [Tue Aug 18 12:59:49.415415 2026] [security2:error] [pid 123784:tid 123990] [client 172.202.39.151:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/k.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpCwAAAEg"] [Tue Aug 18 12:59:49.418690 2026] [security2:error] [pid 123784:tid 123912] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpDgAAens"] [Tue Aug 18 12:59:49.435748 2026] [security2:error] [pid 123784:tid 123989] [client 85.154.68.202:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpFAAAAEc"] [Tue Aug 18 12:59:49.435921 2026] [security2:error] [pid 123784:tid 123989] [client 85.154.68.202:62134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpFAAAAEc"] [Tue Aug 18 12:59:49.456778 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:49.457185 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:49.541997 2026] [security2:error] [pid 123784:tid 123800] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpHQAAGQs"] [Tue Aug 18 12:59:49.549038 2026] [security2:error] [pid 123784:tid 124022] [client 68.155.154.236:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpIAAAAGg"] [Tue Aug 18 12:59:49.572109 2026] [security2:error] [pid 123784:tid 123972] [client 168.62.48.100:5614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/dlvqo.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpIQAAADY"] [Tue Aug 18 12:59:49.600552 2026] [security2:error] [pid 123784:tid 123932] [client 223.185.37.47:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpJQAAAA4"] [Tue Aug 18 12:59:49.600649 2026] [security2:error] [pid 123784:tid 123932] [client 223.185.37.47:30862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpJQAAAA4"] [Tue Aug 18 12:59:49.657227 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:7223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ph.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpLgAAAG4"] [Tue Aug 18 12:59:49.663510 2026] [security2:error] [pid 123784:tid 123914] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpMAAAa30"] [Tue Aug 18 12:59:49.668267 2026] [security2:error] [pid 123784:tid 123936] [client 20.119.58.187:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/0x.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpMgAAABI"] [Tue Aug 18 12:59:49.685787 2026] [security2:error] [pid 123784:tid 123920] [client 172.182.200.96:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpNAAAAAI"] [Tue Aug 18 12:59:49.699321 2026] [security2:error] [pid 123784:tid 124007] [client 114.119.132.101:60885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "uniaoac.com.br"] [uri "/solucoes-contabeis/restaurantes"] [unique_id "aoSBdWwDnJBNj2tDbYbpNwAAAFk"], referer: https://uniaoac.com.br/blog/28/voce-ja-ouviu-falar-em-acordo-por-fora-na-rescisao [Tue Aug 18 12:59:49.751304 2026] [security2:error] [pid 123784:tid 124029] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpOgAAAG8"] [Tue Aug 18 12:59:49.784070 2026] [security2:error] [pid 123784:tid 123802] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpPAAAfw0"] [Tue Aug 18 12:59:49.792994 2026] [security2:error] [pid 123784:tid 123947] [client 40.74.65.169:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpQQAAAB0"] [Tue Aug 18 12:59:49.844128 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/conn-test.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRQAAAAM"] [Tue Aug 18 12:59:49.878143 2026] [security2:error] [pid 123784:tid 123937] [client 20.127.136.245:28066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/edit-tags.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRgAAABM"] [Tue Aug 18 12:59:49.894288 2026] [security2:error] [pid 123784:tid 124033] [client 20.104.85.180:19751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpRwAAAHM"] [Tue Aug 18 12:59:49.904761 2026] [security2:error] [pid 123784:tid 123872] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdWwDnJBNj2tDbYbpSgAAYVM"] [Tue Aug 18 12:59:49.918107 2026] [security2:error] [pid 123784:tid 124013] [client 20.38.3.247:35005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/pema.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpTgAAAF8"] [Tue Aug 18 12:59:49.945034 2026] [security2:error] [pid 123784:tid 124031] [client 158.23.17.4:47873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/hr.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpTwAAAHE"] [Tue Aug 18 12:59:49.982135 2026] [authz_core:error] [pid 123784:tid 123843] [remote 57.141.22.30:22340] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:49.982406 2026] [authz_core:error] [pid 123784:tid 123843] [remote 57.141.22.30:22340] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:49.989652 2026] [security2:error] [pid 123784:tid 124009] [client 213.35.127.232:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBdWwDnJBNj2tDbYbpUwAAAFs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:50.010259 2026] [security2:error] [pid 123784:tid 123986] [client 20.250.13.23:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/x.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpVgAAAEQ"] [Tue Aug 18 12:59:50.029820 2026] [security2:error] [pid 123784:tid 123963] [client 20.119.58.187:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/0.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpWAAAAC0"] [Tue Aug 18 12:59:50.055855 2026] [autoindex:error] [pid 123784:tid 124037] [client 52.73.140.57:45514] AH01276: Cannot serve directory /home3/viadupla/aeromodelismounai.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:50.060322 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:50.060582 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:50.080712 2026] [security2:error] [pid 123784:tid 123995] [client 216.244.66.243:56016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/jogos+de+fogo+e+agua+poki-2/"] [unique_id "aoSBdmwDnJBNj2tDbYbpXAAAAE0"] [Tue Aug 18 12:59:50.080857 2026] [security2:error] [pid 123784:tid 123995] [client 216.244.66.243:56016] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/jogos+de+fogo+e+agua+poki-2/"] [unique_id "aoSBdmwDnJBNj2tDbYbpXAAAAE0"] [Tue Aug 18 12:59:50.081446 2026] [security2:error] [pid 123784:tid 123978] [client 132.196.30.78:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpXQAAADw"] [Tue Aug 18 12:59:50.113934 2026] [security2:error] [pid 123784:tid 123980] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpXwAAAD4"] [Tue Aug 18 12:59:50.280332 2026] [security2:error] [pid 123784:tid 123840] [remote 35.185.79.185:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "webdisk.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBdmwDnJBNj2tDbYbpawAAETM"] [Tue Aug 18 12:59:50.323550 2026] [security2:error] [pid 123784:tid 123927] [client 20.203.138.185:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sbhu.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpbAAAAAk"] [Tue Aug 18 12:59:50.335358 2026] [authz_core:error] [pid 123784:tid 123823] [remote 57.141.22.111:45870] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:50.335741 2026] [authz_core:error] [pid 123784:tid 123823] [remote 57.141.22.111:45870] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:50.373190 2026] [security2:error] [pid 123784:tid 124022] [client 158.158.74.177:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/lock360.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpcgAAAGg"] [Tue Aug 18 12:59:50.382641 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/oxshell.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpcwAAAFM"] [Tue Aug 18 12:59:50.387600 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.154.236:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpdQAAADY"] [Tue Aug 18 12:59:50.388980 2026] [security2:error] [pid 123784:tid 123988] [client 20.38.3.247:8654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/sh.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpdgAAAEY"] [Tue Aug 18 12:59:50.477459 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/u.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpeAAAAHk"] [Tue Aug 18 12:59:50.490137 2026] [security2:error] [pid 123784:tid 123991] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpeQAAAEk"] [Tue Aug 18 12:59:50.509262 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/s.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpewAAAFA"] [Tue Aug 18 12:59:50.510544 2026] [security2:error] [pid 123784:tid 123936] [client 40.74.65.169:20096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpfAAAABI"] [Tue Aug 18 12:59:50.567628 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fg.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpgAAAADg"] [Tue Aug 18 12:59:50.605153 2026] [security2:error] [pid 123784:tid 124004] [client 114.119.134.80:63129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.higicenterpel.com.br"] [uri "/dados_produtos.php"] [unique_id "aoSBdmwDnJBNj2tDbYbphgAAAFY"], referer: http://www.higicenterpel.com.br/listaprodutossub.php?subcategoria=11 [Tue Aug 18 12:59:50.607930 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kt.php"] [unique_id "aoSBdmwDnJBNj2tDbYbphwAAACQ"] [Tue Aug 18 12:59:50.661130 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:50.661441 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:50.682443 2026] [security2:error] [pid 123784:tid 123968] [client 132.196.30.78:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/default.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpjAAAADI"] [Tue Aug 18 12:59:50.723584 2026] [security2:error] [pid 123784:tid 123946] [client 20.104.85.180:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpjwAAABw"] [Tue Aug 18 12:59:50.734199 2026] [security2:error] [pid 123784:tid 123969] [client 20.119.58.187:10456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/php8.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpkAAAADM"] [Tue Aug 18 12:59:50.761252 2026] [security2:error] [pid 123784:tid 124024] [client 4.232.94.69:34421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bolt.php"] [unique_id "aoSBdmwDnJBNj2tDbYbplwAAAGo"] [Tue Aug 18 12:59:50.827091 2026] [autoindex:error] [pid 123784:tid 123950] [client 147.185.132.51:63668] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:50.852273 2026] [security2:error] [pid 123784:tid 123923] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpnwAAAAU"] [Tue Aug 18 12:59:50.926512 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:63737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpogAAAC8"] [Tue Aug 18 12:59:50.959742 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ww.php"] [unique_id "aoSBdmwDnJBNj2tDbYbppQAAAC4"] [Tue Aug 18 12:59:50.962852 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:50.963105 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:50.979081 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/uo.php"] [unique_id "aoSBdmwDnJBNj2tDbYbppgAAAEA"] [Tue Aug 18 12:59:51.000468 2026] [security2:error] [pid 123784:tid 124015] [client 158.158.74.177:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/log.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqgAAAGE"] [Tue Aug 18 12:59:51.000498 2026] [security2:error] [pid 123784:tid 123921] [client 213.35.127.232:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqwAAAAM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:51.010947 2026] [security2:error] [pid 123784:tid 123966] [client 20.38.3.247:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/button.php"] [unique_id "aoSBd2wDnJBNj2tDbYbprAAAADA"] [Tue Aug 18 12:59:51.032999 2026] [security2:error] [pid 123784:tid 123869] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpsQAAc1A"] [Tue Aug 18 12:59:51.033135 2026] [security2:error] [pid 123784:tid 124033] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpsQAAc1A"] [Tue Aug 18 12:59:51.077383 2026] [security2:error] [pid 123784:tid 123995] [client 20.127.136.245:28497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpswAAAE0"] [Tue Aug 18 12:59:51.086330 2026] [security2:error] [pid 123784:tid 123990] [client 20.119.58.187:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/p.php"] [unique_id "aoSBd2wDnJBNj2tDbYbptQAAAEg"] [Tue Aug 18 12:59:51.139755 2026] [security2:error] [pid 123784:tid 124037] [client 54.162.181.231:23938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBdmwDnJBNj2tDbYbpqAAAd24"] [Tue Aug 18 12:59:51.216647 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpugAAAHk"] [Tue Aug 18 12:59:51.221884 2026] [security2:error] [pid 123784:tid 123993] [client 40.74.65.169:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvAAAAEs"] [Tue Aug 18 12:59:51.243213 2026] [security2:error] [pid 123784:tid 123960] [client 68.155.154.236:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvQAAACo"] [Tue Aug 18 12:59:51.264287 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.85.180:18859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpvwAAABQ"] [Tue Aug 18 12:59:51.315587 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mo.php"] [unique_id "aoSBd2wDnJBNj2tDbYbpxgAAAEo"] [Tue Aug 18 12:59:51.369111 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/pkmoj.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp0gAAAGk"] [Tue Aug 18 12:59:51.371400 2026] [security2:error] [pid 123784:tid 123924] [client 132.196.30.78:21956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/i.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1AAAAAY"] [Tue Aug 18 12:59:51.381833 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kx.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1QAAACc"] [Tue Aug 18 12:59:51.437251 2026] [security2:error] [pid 123784:tid 123945] [client 20.119.58.187:10557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/php.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp1wAAABs"] [Tue Aug 18 12:59:51.531271 2026] [security2:error] [pid 123784:tid 124009] [client 192.141.172.134:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp4QAAAFs"] [Tue Aug 18 12:59:51.531416 2026] [security2:error] [pid 123784:tid 124009] [client 192.141.172.134:55495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp4QAAAFs"] [Tue Aug 18 12:59:51.568932 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:51.569406 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:51.599832 2026] [security2:error] [pid 123784:tid 123965] [client 172.182.200.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rota100.com.br"] [uri "/images/security.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp5wAAAC8"] [Tue Aug 18 12:59:51.612119 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/h.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp6AAAABw"] [Tue Aug 18 12:59:51.618591 2026] [security2:error] [pid 123784:tid 124031] [client 158.158.74.177:3891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/lv.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp7AAAAHE"] [Tue Aug 18 12:59:51.628446 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.85.180:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp7QAAAFo"] [Tue Aug 18 12:59:51.654239 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/kopyw.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp8AAAAHY"] [Tue Aug 18 12:59:51.708203 2026] [security2:error] [pid 123784:tid 123920] [client 4.232.94.69:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSBd2wDnJBNj2tDbYbp_wAAAAI"] [Tue Aug 18 12:59:51.747651 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.154.236:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAQAAAAk"] [Tue Aug 18 12:59:51.749598 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/va.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAgAAAAE"] [Tue Aug 18 12:59:51.753053 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:60790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qr.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqAwAAAH8"] [Tue Aug 18 12:59:51.769450 2026] [security2:error] [pid 123784:tid 123995] [client 20.203.138.185:24942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/zc-318.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqBAAAAE0"] [Tue Aug 18 12:59:51.789152 2026] [security2:error] [pid 123784:tid 123982] [client 20.119.58.187:10442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/past.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqBgAAAEA"] [Tue Aug 18 12:59:51.833641 2026] [security2:error] [pid 123784:tid 123943] [client 20.38.3.247:35007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/wlc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqCwAAABk"] [Tue Aug 18 12:59:51.856686 2026] [security2:error] [pid 123784:tid 123988] [client 20.104.85.180:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqDQAAAEY"] [Tue Aug 18 12:59:51.868692 2026] [security2:error] [pid 123784:tid 123958] [client 172.182.200.96:7560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqDwAAACg"] [Tue Aug 18 12:59:51.870507 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:51.871384 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:51.895600 2026] [security2:error] [pid 123784:tid 124019] [client 40.74.65.169:20381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqEAAAAGU"] [Tue Aug 18 12:59:51.967332 2026] [security2:error] [pid 123784:tid 123847] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/inputs.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqFAAAKTo"] [Tue Aug 18 12:59:51.999508 2026] [security2:error] [pid 123784:tid 123967] [client 112.171.203.65:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.203.171.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldportas.com.br"] [uri "/wp-login.php"] [unique_id "aoSBd2wDnJBNj2tDbYbqCgAAADE"], referer: https://worldportas.com.br/wp-login.php [Tue Aug 18 12:59:52.013554 2026] [security2:error] [pid 123784:tid 123921] [client 213.35.127.232:51970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqFgAAAAM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:52.045602 2026] [security2:error] [pid 123784:tid 123957] [client 20.104.85.180:6991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqGAAAACc"] [Tue Aug 18 12:59:52.115259 2026] [security2:error] [pid 123784:tid 123942] [client 20.127.136.245:28055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ms-edit.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIAAAABg"] [Tue Aug 18 12:59:52.144282 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/root.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIwAAACM"] [Tue Aug 18 12:59:52.147892 2026] [security2:error] [pid 123784:tid 124032] [client 114.5.214.109:50416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIgAAAHI"] [Tue Aug 18 12:59:52.148028 2026] [security2:error] [pid 123784:tid 124032] [client 114.5.214.109:50416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpcash.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqIgAAAHI"] [Tue Aug 18 12:59:52.154691 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:62980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fo.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqJQAAACE"] [Tue Aug 18 12:59:52.204303 2026] [security2:error] [pid 123784:tid 123989] [client 20.251.48.93:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/wpxml.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqKwAAAEc"] [Tue Aug 18 12:59:52.234472 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:57259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ve.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqLgAAAAs"] [Tue Aug 18 12:59:52.236067 2026] [security2:error] [pid 123784:tid 123984] [client 178.128.23.175:56653] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.caminhosdaregiao.com.br"] [uri "/"] [unique_id "aoSBeGwDnJBNj2tDbYbqLwAAAEI"] [Tue Aug 18 12:59:52.269036 2026] [security2:error] [pid 123784:tid 123954] [client 158.158.74.177:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mah/function.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqMQAAACQ"] [Tue Aug 18 12:59:52.290149 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.154.236:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqMwAAABw"] [Tue Aug 18 12:59:52.331255 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/fi.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqOQAAAG4"] [Tue Aug 18 12:59:52.340767 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dirs.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqOgAAAGI"] [Tue Aug 18 12:59:52.409374 2026] [security2:error] [pid 123784:tid 123935] [client 103.120.71.157:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQQAAABE"] [Tue Aug 18 12:59:52.409514 2026] [security2:error] [pid 123784:tid 123935] [client 103.120.71.157:63533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQQAAABE"] [Tue Aug 18 12:59:52.441840 2026] [security2:error] [pid 123784:tid 123987] [client 4.232.94.69:54411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/php.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQgAAAEU"] [Tue Aug 18 12:59:52.441891 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.85.180:18817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/epinyins.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqQwAAAAk"] [Tue Aug 18 12:59:52.467539 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:52.467811 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:52.468269 2026] [security2:error] [pid 123784:tid 123990] [client 172.202.39.151:44570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/403.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSQAAAEg"] [Tue Aug 18 12:59:52.500254 2026] [security2:error] [pid 123784:tid 123920] [client 20.119.58.187:10546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/r.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSgAAAAI"] [Tue Aug 18 12:59:52.503611 2026] [security2:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/admin.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqSwAAfUQ"] [Tue Aug 18 12:59:52.572472 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/loading.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqUgAAAHc"] [Tue Aug 18 12:59:52.576163 2026] [security2:error] [pid 123784:tid 123988] [client 40.74.65.169:20157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/media.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqUwAAAEY"] [Tue Aug 18 12:59:52.677351 2026] [security2:error] [pid 123784:tid 123921] [client 20.203.138.185:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ccou.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqXAAAAAM"] [Tue Aug 18 12:59:52.686849 2026] [security2:error] [pid 123784:tid 123868] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/goods.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqYAAADE8"] [Tue Aug 18 12:59:52.695137 2026] [security2:error] [pid 123784:tid 123982] [client 20.127.136.245:28316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/a7.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqYQAAAEA"] [Tue Aug 18 12:59:52.768201 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:52.768472 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:52.774379 2026] [security2:error] [pid 123784:tid 124039] [client 132.196.30.78:22132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqaQAAAHk"] [Tue Aug 18 12:59:52.774406 2026] [security2:error] [pid 123784:tid 123969] [client 168.62.48.100:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zznmg.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqagAAADM"] [Tue Aug 18 12:59:52.813621 2026] [security2:error] [pid 123784:tid 124035] [client 213.202.253.4:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/delpaths.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqbAAAAHU"], referer: www.google.com [Tue Aug 18 12:59:52.831317 2026] [security2:error] [pid 123784:tid 124025] [client 20.104.85.180:7011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqbgAAAGs"] [Tue Aug 18 12:59:52.849487 2026] [security2:error] [pid 123784:tid 123869] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcQAADVA"] [Tue Aug 18 12:59:52.854891 2026] [security2:error] [pid 123784:tid 123998] [client 20.119.58.187:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/sid3.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcgAAAFA"] [Tue Aug 18 12:59:52.886633 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.85.180:19713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/file.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqcwAAAFw"] [Tue Aug 18 12:59:52.895370 2026] [security2:error] [pid 123784:tid 123924] [client 158.158.74.177:3884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBeGwDnJBNj2tDbYbqdAAAAAY"] [Tue Aug 18 12:59:53.024142 2026] [security2:error] [pid 123784:tid 124023] [client 213.35.127.232:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqegAAAGk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:53.060248 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sn.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqfAAAAB4"] [Tue Aug 18 12:59:53.071399 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:53.071663 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:53.079312 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqfgAACD8"] [Tue Aug 18 12:59:53.130919 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:28034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/manager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqgQAAABs"] [Tue Aug 18 12:59:53.148264 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:48997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ke.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhgAAAHc"] [Tue Aug 18 12:59:53.164981 2026] [security2:error] [pid 123784:tid 123961] [client 196.12.128.158:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhwAAACs"] [Tue Aug 18 12:59:53.165116 2026] [security2:error] [pid 123784:tid 123961] [client 196.12.128.158:64639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqhwAAACs"] [Tue Aug 18 12:59:53.211150 2026] [security2:error] [pid 123784:tid 124003] [client 20.119.58.187:10480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ss.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqigAAAFU"] [Tue Aug 18 12:59:53.213089 2026] [security2:error] [pid 123784:tid 123934] [client 172.182.200.96:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqiwAAABA"] [Tue Aug 18 12:59:53.220283 2026] [security2:error] [pid 123784:tid 123993] [client 68.155.154.236:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjAAAAEs"] [Tue Aug 18 12:59:53.238002 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.138.185:23368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/txets.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjQAAABI"] [Tue Aug 18 12:59:53.242970 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/404.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjgAABAk"] [Tue Aug 18 12:59:53.258658 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/inso.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqjwAAAH4"] [Tue Aug 18 12:59:53.272574 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:10985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqkQAAAC4"] [Tue Aug 18 12:59:53.317091 2026] [security2:error] [pid 123784:tid 123995] [client 132.196.30.78:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqlQAAAE0"] [Tue Aug 18 12:59:53.332610 2026] [autoindex:error] [pid 123784:tid 123979] [client 4.232.94.69:31723] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:53.335507 2026] [security2:error] [pid 123784:tid 123982] [client 172.202.39.151:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/adminfuns.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqlgAAAEA"] [Tue Aug 18 12:59:53.369605 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:53.369870 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:53.404936 2026] [security2:error] [pid 123784:tid 123959] [client 20.38.3.247:63479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/chris.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnAAAACk"] [Tue Aug 18 12:59:53.411941 2026] [security2:error] [pid 123784:tid 123890] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnQAAWWU"] [Tue Aug 18 12:59:53.429134 2026] [security2:error] [pid 123784:tid 123859] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wk/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqnwAALEY"] [Tue Aug 18 12:59:53.441914 2026] [security2:error] [pid 123784:tid 123975] [client 20.104.85.180:22857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/epinyins.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqoQAAADk"] [Tue Aug 18 12:59:53.475553 2026] [security2:error] [pid 123784:tid 123989] [client 168.62.48.100:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/bhfnd.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqogAAAEc"] [Tue Aug 18 12:59:53.511994 2026] [security2:error] [pid 123784:tid 123921] [client 158.158.74.177:3881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mass.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqowAAAAM"] [Tue Aug 18 12:59:53.562938 2026] [security2:error] [pid 123784:tid 124025] [client 20.119.58.187:10486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/sts.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqpAAAAGs"] [Tue Aug 18 12:59:53.579165 2026] [security2:error] [pid 123784:tid 124002] [client 4.232.94.69:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqpgAAAFQ"] [Tue Aug 18 12:59:53.650954 2026] [security2:error] [pid 123784:tid 123876] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/about.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqrAAAD1c"] [Tue Aug 18 12:59:53.672167 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:53.672436 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:53.678142 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:44820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ia.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqsAAAAAk"] [Tue Aug 18 12:59:53.685156 2026] [security2:error] [pid 123784:tid 123953] [client 158.23.17.4:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nh.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqsQAAACM"] [Tue Aug 18 12:59:53.696877 2026] [security2:error] [pid 123784:tid 123945] [client 20.203.138.185:22603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fun.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqswAAABs"] [Tue Aug 18 12:59:53.735082 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:28534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/w1.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqtgAAAAY"] [Tue Aug 18 12:59:53.740948 2026] [security2:error] [pid 123784:tid 123961] [client 158.23.17.4:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/43.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqtwAAACs"] [Tue Aug 18 12:59:53.748599 2026] [security2:error] [pid 123784:tid 123937] [client 197.184.64.235:41952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbquQAAABM"] [Tue Aug 18 12:59:53.748674 2026] [security2:error] [pid 123784:tid 123937] [client 197.184.64.235:41952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBeWwDnJBNj2tDbYbquQAAABM"] [Tue Aug 18 12:59:53.786321 2026] [security2:error] [pid 123784:tid 124019] [client 172.182.200.96:7612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/first.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqvwAAAGU"] [Tue Aug 18 12:59:53.838164 2026] [security2:error] [pid 123784:tid 124023] [client 79.127.164.8:36338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/transferdrupalbackup.bak"] [unique_id "aoSBeWwDnJBNj2tDbYbqwgAAAGk"], referer: https://medihub.com.br/transferdrupalbackup.bak [Tue Aug 18 12:59:53.861363 2026] [security2:error] [pid 123784:tid 123862] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/term.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqwwAAGkk"] [Tue Aug 18 12:59:53.916441 2026] [security2:error] [pid 123784:tid 124003] [client 20.119.58.187:10547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/shell.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqzQAAAFU"] [Tue Aug 18 12:59:53.956619 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:20413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/shiny.php"] [unique_id "aoSBeWwDnJBNj2tDbYbqzwAAAAA"] [Tue Aug 18 12:59:53.980732 2026] [security2:error] [pid 123784:tid 124014] [client 20.104.85.180:28636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBeWwDnJBNj2tDbYbq0gAAAGA"] [Tue Aug 18 12:59:54.012770 2026] [security2:error] [pid 123784:tid 123960] [client 102.213.179.104:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1QAAACo"] [Tue Aug 18 12:59:54.012894 2026] [security2:error] [pid 123784:tid 123960] [client 102.213.179.104:61310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1QAAACo"] [Tue Aug 18 12:59:54.019057 2026] [security2:error] [pid 123784:tid 123792] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1gAAeQM"] [Tue Aug 18 12:59:54.024452 2026] [security2:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBemwDnJBNj2tDbYbq1wAAIho"] [Tue Aug 18 12:59:54.033179 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.154.236:25367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/rezor.php"] [unique_id "aoSBemwDnJBNj2tDbYbq2AAAAGY"] [Tue Aug 18 12:59:54.046932 2026] [security2:error] [pid 123784:tid 124043] [client 213.35.127.232:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBemwDnJBNj2tDbYbq2wAAAH0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:54.052558 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:27943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/index/function.php"] [unique_id "aoSBemwDnJBNj2tDbYbq3QAAAFc"] [Tue Aug 18 12:59:54.103473 2026] [security2:error] [pid 123784:tid 123900] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/info.php"] [unique_id "aoSBemwDnJBNj2tDbYbq3wAAR28"] [Tue Aug 18 12:59:54.120553 2026] [security2:error] [pid 123784:tid 123930] [client 132.196.30.78:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4QAAAAw"] [Tue Aug 18 12:59:54.131704 2026] [security2:error] [pid 123784:tid 123995] [client 158.158.74.177:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4gAAAE0"] [Tue Aug 18 12:59:54.136498 2026] [security2:error] [pid 123784:tid 123818] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/pi.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4wAALR0"] [Tue Aug 18 12:59:54.142518 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:63483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/doc.php"] [unique_id "aoSBemwDnJBNj2tDbYbq5AAAAFw"] [Tue Aug 18 12:59:54.171913 2026] [security2:error] [pid 123784:tid 123962] [client 74.7.228.42:33226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bfautomovel.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSBemwDnJBNj2tDbYbq5gAALA0"] [Tue Aug 18 12:59:54.199048 2026] [security2:error] [pid 123784:tid 123965] [client 172.182.200.96:7518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbq6QAAAC8"] [Tue Aug 18 12:59:54.225806 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/oo.php"] [unique_id "aoSBemwDnJBNj2tDbYbq6wAAACQ"] [Tue Aug 18 12:59:54.240412 2026] [security2:error] [pid 123784:tid 123909] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/test.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7gAAcXg"] [Tue Aug 18 12:59:54.258477 2026] [security2:error] [pid 123784:tid 123833] [remote 74.248.18.37:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.alsconsultoria.com.br"] [uri "/1.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7wAAByw"] [Tue Aug 18 12:59:54.258559 2026] [security2:error] [pid 123784:tid 123833] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/1.php"] [unique_id "aoSBemwDnJBNj2tDbYbq7wAAByw"] [Tue Aug 18 12:59:54.274945 2026] [security2:error] [pid 123784:tid 123978] [client 20.119.58.187:10553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/setup-config.php"] [unique_id "aoSBemwDnJBNj2tDbYbq8QAAADw"] [Tue Aug 18 12:59:54.275796 2026] [security2:error] [pid 123784:tid 123834] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/i.php"] [unique_id "aoSBemwDnJBNj2tDbYbq8gAAbi0"] [Tue Aug 18 12:59:54.276050 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:54.276305 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:54.358126 2026] [security2:error] [pid 123784:tid 123805] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBemwDnJBNj2tDbYbq9gAAORA"] [Tue Aug 18 12:59:54.362270 2026] [security2:error] [pid 123784:tid 123915] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSBemwDnJBNj2tDbYbq9wAARX4"] [Tue Aug 18 12:59:54.374066 2026] [security2:error] [pid 123784:tid 123898] [remote 35.185.79.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.79.185.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.outlimit.com.br"] [uri "/app_dev.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-AAAf20"] [Tue Aug 18 12:59:54.422287 2026] [security2:error] [pid 123784:tid 123904] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/alfa.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-gAAE3M"] [Tue Aug 18 12:59:54.543672 2026] [security2:error] [pid 123784:tid 124009] [client 20.203.138.185:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/jq.php"] [unique_id "aoSBemwDnJBNj2tDbYbq_gAAAFs"] [Tue Aug 18 12:59:54.552621 2026] [security2:error] [pid 123784:tid 123932] [client 172.182.200.96:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrAwAAAA4"] [Tue Aug 18 12:59:54.556557 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-login.php"] [unique_id "aoSBemwDnJBNj2tDbYbq-QAAAEg"] [Tue Aug 18 12:59:54.567067 2026] [security2:error] [pid 123784:tid 124023] [client 68.155.154.236:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBemwDnJBNj2tDbYbrBAAAAGk"] [Tue Aug 18 12:59:54.606078 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ja.php"] [unique_id "aoSBemwDnJBNj2tDbYbrCwAAABo"] [Tue Aug 18 12:59:54.619187 2026] [security2:error] [pid 123784:tid 123810] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/edit.php"] [unique_id "aoSBemwDnJBNj2tDbYbrDQAABBU"] [Tue Aug 18 12:59:54.632604 2026] [security2:error] [pid 123784:tid 123981] [client 20.119.58.187:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/t.php"] [unique_id "aoSBemwDnJBNj2tDbYbrDwAAAD8"] [Tue Aug 18 12:59:54.636140 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:20131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/403dd.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEAAAABk"] [Tue Aug 18 12:59:54.697064 2026] [security2:error] [pid 123784:tid 124026] [client 4.232.94.69:35813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEgAAAGw"] [Tue Aug 18 12:59:54.717275 2026] [security2:error] [pid 123784:tid 124042] [client 132.196.30.78:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/NewFile.php"] [unique_id "aoSBemwDnJBNj2tDbYbrEwAAAHw"] [Tue Aug 18 12:59:54.737462 2026] [security2:error] [pid 123784:tid 123838] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/domvf.php"] [unique_id "aoSBemwDnJBNj2tDbYbrFQAAQzE"] [Tue Aug 18 12:59:54.770423 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/1337.php"] [unique_id "aoSBemwDnJBNj2tDbYbrFgAAAEw"] [Tue Aug 18 12:59:54.843927 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/elp.php"] [unique_id "aoSBemwDnJBNj2tDbYbrHAAAClI"] [Tue Aug 18 12:59:54.882941 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:54.883427 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:54.889911 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fresh.php"] [unique_id "aoSBemwDnJBNj2tDbYbrIQAAAAs"] [Tue Aug 18 12:59:54.913911 2026] [security2:error] [pid 123784:tid 123984] [client 172.182.200.96:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrIwAAAEI"] [Tue Aug 18 12:59:54.964395 2026] [security2:error] [pid 123784:tid 123919] [client 20.104.85.180:18795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJgAAAAE"] [Tue Aug 18 12:59:54.964460 2026] [security2:error] [pid 123784:tid 124035] [client 20.127.136.245:28086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/default.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJQAAAHU"] [Tue Aug 18 12:59:54.979479 2026] [security2:error] [pid 123784:tid 124014] [client 158.158.74.177:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/meta.php"] [unique_id "aoSBemwDnJBNj2tDbYbrJwAAAGA"] [Tue Aug 18 12:59:54.986272 2026] [security2:error] [pid 123784:tid 124005] [client 20.119.58.187:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/up.php"] [unique_id "aoSBemwDnJBNj2tDbYbrKAAAAFc"] [Tue Aug 18 12:59:55.011551 2026] [security2:error] [pid 123784:tid 123865] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLAAAO0w"] [Tue Aug 18 12:59:55.021012 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:57255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kn.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLQAAAB0"] [Tue Aug 18 12:59:55.059140 2026] [security2:error] [pid 123784:tid 123893] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrLwAAHGg"] [Tue Aug 18 12:59:55.068416 2026] [security2:error] [pid 123784:tid 123957] [client 213.35.127.232:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMAAAACc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:55.133415 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:56561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xx.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMgAAAGM"] [Tue Aug 18 12:59:55.153905 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/qfvqu.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrMwAAAEQ"] [Tue Aug 18 12:59:55.178703 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/666.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOAAAOQg"] [Tue Aug 18 12:59:55.213034 2026] [security2:error] [pid 123784:tid 123935] [client 20.251.48.93:51709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/file1221.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOQAAABE"] [Tue Aug 18 12:59:55.221879 2026] [security2:error] [pid 123784:tid 124001] [client 86.120.159.145:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOgAAAFM"] [Tue Aug 18 12:59:55.222372 2026] [security2:error] [pid 123784:tid 124001] [client 86.120.159.145:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrOgAAAFM"] [Tue Aug 18 12:59:55.298580 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:27574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrPgAAAB8"] [Tue Aug 18 12:59:55.306738 2026] [security2:error] [pid 123784:tid 123997] [client 132.196.30.78:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrPwAAAE8"] [Tue Aug 18 12:59:55.335537 2026] [security2:error] [pid 123784:tid 123945] [client 40.74.65.169:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/baba.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrQAAAABs"] [Tue Aug 18 12:59:55.339600 2026] [security2:error] [pid 123784:tid 123987] [client 20.119.58.187:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ultra.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrQQAAAEU"] [Tue Aug 18 12:59:55.351203 2026] [core:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:55.351226 2026] [core:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:55.355587 2026] [security2:error] [pid 123784:tid 123970] [client 20.38.3.247:38141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/Njima.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrRAAAADQ"] [Tue Aug 18 12:59:55.437465 2026] [security2:error] [pid 123784:tid 123908] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gec.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrRgAADnc"] [Tue Aug 18 12:59:55.478577 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:55.478849 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:55.519510 2026] [security2:error] [pid 123784:tid 123896] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ws54.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrSwAARms"] [Tue Aug 18 12:59:55.598021 2026] [security2:error] [pid 123784:tid 124016] [client 158.158.74.177:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mini.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrUwAAAGI"] [Tue Aug 18 12:59:55.598051 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/conn-test.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrUgAAAEM"] [Tue Aug 18 12:59:55.614808 2026] [security2:error] [pid 123784:tid 124037] [client 20.127.136.245:28078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/i.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrVwAAAHc"] [Tue Aug 18 12:59:55.631639 2026] [security2:error] [pid 123784:tid 123979] [client 20.203.138.185:22617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sys.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrWgAAAD0"] [Tue Aug 18 12:59:55.636558 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:33458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wm.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrWwAAABc"] [Tue Aug 18 12:59:55.686873 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrXgAAfT8"] [Tue Aug 18 12:59:55.693509 2026] [security2:error] [pid 123784:tid 123991] [client 20.119.58.187:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/vv.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrXwAAAEk"] [Tue Aug 18 12:59:55.734529 2026] [security2:error] [pid 123784:tid 124034] [client 192.141.172.134:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYQAAAHQ"] [Tue Aug 18 12:59:55.734679 2026] [security2:error] [pid 123784:tid 124034] [client 192.141.172.134:55810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYQAAAHQ"] [Tue Aug 18 12:59:55.747247 2026] [security2:error] [pid 123784:tid 123948] [client 20.250.13.23:36074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/aaa.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrYgAAAB4"] [Tue Aug 18 12:59:55.768019 2026] [security2:error] [pid 123784:tid 124041] [client 154.72.114.68:7287] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nolancollection.com.br"] [uri "/index.php"] [unique_id "aoSBemwDnJBNj2tDbYbq4AAAAHs"] [Tue Aug 18 12:59:55.781610 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:55.781923 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:55.854003 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/function/function.php"] [unique_id "aoSBe2wDnJBNj2tDbYbraQAAXgk"] [Tue Aug 18 12:59:55.857422 2026] [security2:error] [pid 123784:tid 123813] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/sky.php"] [unique_id "aoSBe2wDnJBNj2tDbYbragAAaxg"] [Tue Aug 18 12:59:55.878454 2026] [security2:error] [pid 123784:tid 123957] [client 172.182.200.96:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrbAAAACc"] [Tue Aug 18 12:59:55.888589 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gecko-new.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrbgAAAG4"] [Tue Aug 18 12:59:55.904455 2026] [authz_core:error] [pid 123784:tid 123864] [remote 57.141.22.0:55326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:55.904916 2026] [authz_core:error] [pid 123784:tid 123864] [remote 57.141.22.0:55326] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:55.914390 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gj.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrcwAAAG0"] [Tue Aug 18 12:59:55.923622 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/index/function.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrdQAAADA"] [Tue Aug 18 12:59:55.944490 2026] [security2:error] [pid 123784:tid 123926] [client 20.38.3.247:8665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBe2wDnJBNj2tDbYbrdwAAAAg"] [Tue Aug 18 12:59:55.990530 2026] [security2:error] [pid 123784:tid 124001] [client 20.104.85.180:22873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBe2wDnJBNj2tDbYbreQAAAFM"] [Tue Aug 18 12:59:56.014410 2026] [security2:error] [pid 123784:tid 123927] [client 40.74.65.169:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/site.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrewAAAAk"] [Tue Aug 18 12:59:56.024599 2026] [security2:error] [pid 123784:tid 123953] [client 135.225.78.186:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfAAAACM"] [Tue Aug 18 12:59:56.046442 2026] [security2:error] [pid 123784:tid 123986] [client 20.119.58.187:10491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/V5.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfQAAAEQ"] [Tue Aug 18 12:59:56.059694 2026] [security2:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/nw.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrfgAARWU"] [Tue Aug 18 12:59:56.080291 2026] [security2:error] [pid 123784:tid 124022] [client 213.35.127.232:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrgAAAAGg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:56.086810 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:56.087136 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:56.149938 2026] [security2:error] [pid 123784:tid 123933] [client 132.196.30.78:16183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrhQAAAA8"] [Tue Aug 18 12:59:56.176427 2026] [security2:error] [pid 123784:tid 124023] [client 172.202.39.151:41132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBfGwDnJBNj2tDbYbriAAAAGk"] [Tue Aug 18 12:59:56.206796 2026] [security2:error] [pid 123784:tid 123799] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/sixxis.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrigAAZQo"] [Tue Aug 18 12:59:56.216671 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fg.php"] [unique_id "aoSBfGwDnJBNj2tDbYbriwAAABA"] [Tue Aug 18 12:59:56.227756 2026] [security2:error] [pid 123784:tid 123819] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/xleet.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrjAAAVB4"] [Tue Aug 18 12:59:56.238308 2026] [security2:error] [pid 123784:tid 123925] [client 158.158.74.177:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/mm.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrjQAAAAc"] [Tue Aug 18 12:59:56.278158 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrkAAAAAQ"] [Tue Aug 18 12:59:56.287141 2026] [security2:error] [pid 123784:tid 124040] [client 68.155.154.236:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrkQAAAHo"] [Tue Aug 18 12:59:56.389118 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:56.389562 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:56.394849 2026] [security2:error] [pid 123784:tid 123901] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlQAAM3A"] [Tue Aug 18 12:59:56.400609 2026] [security2:error] [pid 123784:tid 123974] [client 20.119.58.187:10149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-user.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlgAAADg"] [Tue Aug 18 12:59:56.401480 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ac.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrlwAAAGI"] [Tue Aug 18 12:59:56.489612 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.85.180:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbroAAAAGY"] [Tue Aug 18 12:59:56.500089 2026] [security2:error] [pid 123784:tid 124043] [client 20.203.138.185:32863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/pp.php"] [unique_id "aoSBfGwDnJBNj2tDbYbroQAAAH0"] [Tue Aug 18 12:59:56.504835 2026] [security2:error] [pid 123784:tid 123991] [client 20.38.3.247:15283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/too.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrogAAAEk"] [Tue Aug 18 12:59:56.522503 2026] [security2:error] [pid 123784:tid 123862] [remote 62.60.130.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sttudio.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrpAAAakk"] [Tue Aug 18 12:59:56.561336 2026] [security2:error] [pid 123784:tid 123888] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/155.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrqAAAdWM"] [Tue Aug 18 12:59:56.655472 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ve.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrrwAAABw"] [Tue Aug 18 12:59:56.712284 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:19476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrsgAAAAg"] [Tue Aug 18 12:59:56.748868 2026] [security2:error] [pid 123784:tid 123965] [client 20.127.136.245:28489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrtQAAAC8"] [Tue Aug 18 12:59:56.750471 2026] [authz_core:error] [pid 123784:tid 123792] [remote 57.141.22.42:40470] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:56.750928 2026] [authz_core:error] [pid 123784:tid 123792] [remote 57.141.22.42:40470] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:56.755354 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrtgAAAF4"] [Tue Aug 18 12:59:56.771840 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.154.236:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/Cachex.php"] [unique_id "aoSBfGwDnJBNj2tDbYbruQAAACM"] [Tue Aug 18 12:59:56.798642 2026] [security2:error] [pid 123784:tid 123804] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/96i.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrvAAAGw8"] [Tue Aug 18 12:59:56.845382 2026] [security2:error] [pid 123784:tid 123920] [client 172.202.39.151:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content.php.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrxAAAAAI"] [Tue Aug 18 12:59:56.869705 2026] [security2:error] [pid 123784:tid 123947] [client 158.158.74.177:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrxQAAAB0"] [Tue Aug 18 12:59:56.919240 2026] [security2:error] [pid 123784:tid 123879] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/yj09.php"] [unique_id "aoSBfGwDnJBNj2tDbYbryAAAD1o"] [Tue Aug 18 12:59:56.947656 2026] [security2:error] [pid 123784:tid 124000] [client 172.202.39.151:60139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/about.php"] [unique_id "aoSBfGwDnJBNj2tDbYbryQAAAFI"] [Tue Aug 18 12:59:56.966511 2026] [security2:error] [pid 123784:tid 123909] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/as.php"] [unique_id "aoSBfGwDnJBNj2tDbYbrywAAVHg"] [Tue Aug 18 12:59:56.986150 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:56.986471 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:57.009789 2026] [security2:error] [pid 123784:tid 123943] [client 20.38.3.247:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mudancasmb.com.br"] [uri "/g3.php"] [unique_id "aoSBfWwDnJBNj2tDbYbrzgAAABk"] [Tue Aug 18 12:59:57.040661 2026] [security2:error] [pid 123784:tid 123971] [client 168.62.48.100:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/oivcl.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0AAAADU"] [Tue Aug 18 12:59:57.059450 2026] [security2:error] [pid 123784:tid 123854] [remote 62.60.130.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sttudio.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0QAAWkE"] [Tue Aug 18 12:59:57.070842 2026] [security2:error] [pid 123784:tid 124011] [client 68.221.73.131:16063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/222.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr0gAAAF0"] [Tue Aug 18 12:59:57.095198 2026] [security2:error] [pid 123784:tid 124006] [client 132.196.30.78:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/themes.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr1gAAAFg"] [Tue Aug 18 12:59:57.097122 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr1wAAABE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:57.109394 2026] [security2:error] [pid 123784:tid 123944] [client 20.119.58.187:10497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr2QAAABo"] [Tue Aug 18 12:59:57.134085 2026] [security2:error] [pid 123784:tid 123805] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/min.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr2gAAcxA"] [Tue Aug 18 12:59:57.164240 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pd.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr3AAAAGI"] [Tue Aug 18 12:59:57.206070 2026] [security2:error] [pid 123784:tid 123928] [client 20.127.136.245:28481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/gecko-new.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr3gAAAAo"] [Tue Aug 18 12:59:57.231877 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:20217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yz.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr4AAAABc"] [Tue Aug 18 12:59:57.256062 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.154.236:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr4QAAAD4"] [Tue Aug 18 12:59:57.283003 2026] [security2:error] [pid 123784:tid 123816] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/k.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr5AAAdBs"] [Tue Aug 18 12:59:57.286787 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:57.287221 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:57.305201 2026] [core:error] [pid 123784:tid 123841] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:57.305221 2026] [core:error] [pid 123784:tid 123841] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:57.310858 2026] [security2:error] [pid 123784:tid 123998] [client 20.104.85.180:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/function/function.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr5wAAAFA"] [Tue Aug 18 12:59:57.323763 2026] [security2:error] [pid 123784:tid 124010] [client 20.38.3.247:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/scxy.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr6AAAAFw"] [Tue Aug 18 12:59:57.419363 2026] [security2:error] [pid 123784:tid 123931] [client 40.74.65.169:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/cabs.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr6gAAAA0"] [Tue Aug 18 12:59:57.439063 2026] [security2:error] [pid 123784:tid 123952] [client 79.127.164.8:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/transferdrupalbackup.sql"] [unique_id "aoSBfWwDnJBNj2tDbYbr6wAAACI"], referer: https://medihub.com.br/transferdrupalbackup.sql [Tue Aug 18 12:59:57.443972 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:7231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ia.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr7AAAAGs"] [Tue Aug 18 12:59:57.459788 2026] [security2:error] [pid 123784:tid 124032] [client 20.251.48.93:57981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/nox.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr7wAAAHI"] [Tue Aug 18 12:59:57.461465 2026] [security2:error] [pid 123784:tid 123962] [client 20.119.58.187:10478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/worksec.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr8AAAACw"] [Tue Aug 18 12:59:57.490844 2026] [security2:error] [pid 123784:tid 123991] [client 158.158.74.177:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/moon.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr8gAAAEk"] [Tue Aug 18 12:59:57.521659 2026] [security2:error] [pid 123784:tid 123810] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/php8.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr9gAAIRU"] [Tue Aug 18 12:59:57.558768 2026] [security2:error] [pid 123784:tid 123926] [client 135.225.78.186:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr9wAAAAg"] [Tue Aug 18 12:59:57.586609 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:57.586894 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:57.627352 2026] [security2:error] [pid 123784:tid 123875] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/w.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr-wAAI1Y"] [Tue Aug 18 12:59:57.635987 2026] [security2:error] [pid 123784:tid 123997] [client 20.203.138.185:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wqqs.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr_AAAAE8"] [Tue Aug 18 12:59:57.646999 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.85.180:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBfWwDnJBNj2tDbYbr_QAAAC0"] [Tue Aug 18 12:59:57.690727 2026] [security2:error] [pid 123784:tid 123830] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsAQAADCk"] [Tue Aug 18 12:59:57.733391 2026] [security2:error] [pid 123784:tid 123996] [client 132.196.30.78:9937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/cv.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsAwAAAE4"] [Tue Aug 18 12:59:57.792634 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/NewFile.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsBgAAAG8"] [Tue Aug 18 12:59:57.815797 2026] [security2:error] [pid 123784:tid 123939] [client 20.119.58.187:10522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsCAAAABU"] [Tue Aug 18 12:59:57.860405 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/222.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsCwAAMVI"] [Tue Aug 18 12:59:57.887279 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:57.887607 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:57.911155 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/th.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsDQAAAFg"] [Tue Aug 18 12:59:57.926737 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:63617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEAAAAHM"] [Tue Aug 18 12:59:57.935051 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:20209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kj.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEQAAAEA"] [Tue Aug 18 12:59:57.944808 2026] [security2:error] [pid 123784:tid 123865] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fpwch.php"] [unique_id "aoSBfWwDnJBNj2tDbYbsEgAAcUw"] [Tue Aug 18 12:59:58.014759 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:25396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsFwAAAGA"] [Tue Aug 18 12:59:58.028153 2026] [security2:error] [pid 123784:tid 123847] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsGAAAPjo"] [Tue Aug 18 12:59:58.069624 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kn.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsGwAAAEw"] [Tue Aug 18 12:59:58.114595 2026] [security2:error] [pid 123784:tid 123919] [client 40.74.65.169:19486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/insc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsHgAAAAE"] [Tue Aug 18 12:59:58.115542 2026] [security2:error] [pid 123784:tid 124000] [client 213.35.127.232:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsHwAAAFI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:58.147886 2026] [security2:error] [pid 123784:tid 123935] [client 158.158.74.177:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/n.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIAAAABE"] [Tue Aug 18 12:59:58.151534 2026] [security2:error] [pid 123784:tid 123814] [remote 47.128.124.115:15438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/galeria/trekking-lencois-maranhenses/"] [unique_id "aoSBfmwDnJBNj2tDbYbsIQAAaxk"] [Tue Aug 18 12:59:58.183250 2026] [security2:error] [pid 123784:tid 123999] [client 103.184.169.37:42751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIgAAAFE"] [Tue Aug 18 12:59:58.183379 2026] [security2:error] [pid 123784:tid 123999] [client 103.184.169.37:42751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIgAAAFE"] [Tue Aug 18 12:59:58.194422 2026] [security2:error] [pid 123784:tid 123929] [client 20.119.58.187:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsIwAAAAs"] [Tue Aug 18 12:59:58.202541 2026] [security2:error] [pid 123784:tid 123855] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/info.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJQAAbkI"] [Tue Aug 18 12:59:58.211728 2026] [security2:error] [pid 123784:tid 124032] [client 20.203.138.185:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/clasa99.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJgAAAHI"] [Tue Aug 18 12:59:58.217354 2026] [security2:error] [pid 123784:tid 123962] [client 172.202.39.151:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsJwAAACw"] [Tue Aug 18 12:59:58.235287 2026] [security2:error] [pid 123784:tid 123921] [client 20.127.136.245:28095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsKAAAAAM"] [Tue Aug 18 12:59:58.271291 2026] [security2:error] [pid 123784:tid 123822] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/FWAZ.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsKQAAcCE"] [Tue Aug 18 12:59:58.311758 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:58.312181 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:58.361432 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:42755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsLwAAAE8"] [Tue Aug 18 12:59:58.361555 2026] [security2:error] [pid 123784:tid 123997] [client 138.36.100.162:42755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsLwAAAE8"] [Tue Aug 18 12:59:58.369316 2026] [security2:error] [pid 123784:tid 123907] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/a.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMQAAf3Y"] [Tue Aug 18 12:59:58.389962 2026] [security2:error] [pid 123784:tid 123945] [client 37.40.227.74:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMwAAABs"] [Tue Aug 18 12:59:58.393887 2026] [security2:error] [pid 123784:tid 123945] [client 37.40.227.74:56528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsMwAAABs"] [Tue Aug 18 12:59:58.403250 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/admin404.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNQAAAHU"] [Tue Aug 18 12:59:58.415359 2026] [security2:error] [pid 123784:tid 124024] [client 20.104.85.180:52559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNgAAAGo"] [Tue Aug 18 12:59:58.421773 2026] [security2:error] [pid 123784:tid 123986] [client 149.34.210.141:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNwAAAEQ"] [Tue Aug 18 12:59:58.466437 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:20215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vg.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsOQAAAGk"] [Tue Aug 18 12:59:58.516832 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsPgAAADM"] [Tue Aug 18 12:59:58.536514 2026] [security2:error] [pid 123784:tid 123826] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/chosen.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQAAAYiU"] [Tue Aug 18 12:59:58.561494 2026] [security2:error] [pid 123784:tid 124040] [client 20.119.58.187:10513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQQAAAHo"] [Tue Aug 18 12:59:58.604641 2026] [security2:error] [pid 123784:tid 123883] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/blurbs.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsQwAAJF4"] [Tue Aug 18 12:59:58.621626 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wm.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsRQAAAB4"] [Tue Aug 18 12:59:58.685096 2026] [security2:error] [pid 123784:tid 123986] [client 149.34.210.141:51299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsNwAAAEQ"] [Tue Aug 18 12:59:58.686349 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsSgAAAGs"] [Tue Aug 18 12:59:58.701407 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.154.236:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTAAAAEc"] [Tue Aug 18 12:59:58.703258 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:29463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/st.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTQAAACc"] [Tue Aug 18 12:59:58.703705 2026] [security2:error] [pid 123784:tid 123793] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTgAAUQQ"] [Tue Aug 18 12:59:58.718309 2026] [security2:error] [pid 123784:tid 124004] [client 4.232.94.69:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/go.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsTwAAAFY"] [Tue Aug 18 12:59:58.746771 2026] [security2:error] [pid 123784:tid 123991] [client 20.38.3.247:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsUgAAAEk"] [Tue Aug 18 12:59:58.762887 2026] [security2:error] [pid 123784:tid 123988] [client 135.225.78.186:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsUwAAAEY"] [Tue Aug 18 12:59:58.767364 2026] [security2:error] [pid 123784:tid 124002] [client 158.158.74.177:16185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/nc4.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsVAAAAFQ"] [Tue Aug 18 12:59:58.791793 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:58.792092 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:58.818698 2026] [autoindex:error] [pid 123784:tid 123980] [client 20.100.169.31:23955] AH01276: Cannot serve directory /home1/xsolutions/ciacard-adm.3xsolutions.com/admin/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 12:59:58.820412 2026] [security2:error] [pid 123784:tid 123947] [client 40.74.65.169:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/file.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsWQAAAB0"] [Tue Aug 18 12:59:58.853983 2026] [security2:error] [pid 123784:tid 123994] [client 20.127.136.245:28296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXAAAAEw"] [Tue Aug 18 12:59:58.871343 2026] [security2:error] [pid 123784:tid 123866] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/vx.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXQAAY00"] [Tue Aug 18 12:59:58.888454 2026] [security2:error] [pid 123784:tid 123961] [client 157.20.138.62:57721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXwAAACs"] [Tue Aug 18 12:59:58.888598 2026] [security2:error] [pid 123784:tid 123961] [client 157.20.138.62:57721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsXwAAACs"] [Tue Aug 18 12:59:58.914113 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:14144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsYgAAAAo"] [Tue Aug 18 12:59:58.943664 2026] [security2:error] [pid 123784:tid 124035] [client 20.116.17.175:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsZgAAAHU"] [Tue Aug 18 12:59:58.966053 2026] [security2:error] [pid 123784:tid 123813] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/100.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsZwAABBg"] [Tue Aug 18 12:59:58.999515 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.56.190:15202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/st.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsawAAAC4"] [Tue Aug 18 12:59:59.075931 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/666.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsbgAAABU"] [Tue Aug 18 12:59:59.091510 2026] [core:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:59.091533 2026] [core:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 12:59:59.096882 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:59.097093 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qo.php"] [unique_id "aoSBf2wDnJBNj2tDbYbscQAAABo"] [Tue Aug 18 12:59:59.097354 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:59.099666 2026] [security2:error] [pid 123784:tid 123974] [client 20.79.204.6:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSBf2wDnJBNj2tDbYbscgAAADg"] [Tue Aug 18 12:59:59.122774 2026] [security2:error] [pid 123784:tid 123953] [client 132.196.30.78:25174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdAAAACM"] [Tue Aug 18 12:59:59.130770 2026] [security2:error] [pid 123784:tid 123959] [client 213.35.127.232:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdQAAACk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 12:59:59.163276 2026] [security2:error] [pid 123784:tid 123982] [client 68.155.154.236:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/.cache/x.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsdgAAAEA"] [Tue Aug 18 12:59:59.218217 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:60462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBf2wDnJBNj2tDbYbseAAAAHo"] [Tue Aug 18 12:59:59.245929 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:57249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sm.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfAAAAFU"] [Tue Aug 18 12:59:59.251333 2026] [security2:error] [pid 123784:tid 124010] [client 178.153.171.161:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfgAAAFw"] [Tue Aug 18 12:59:59.251461 2026] [security2:error] [pid 123784:tid 124010] [client 178.153.171.161:57712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfgAAAFw"] [Tue Aug 18 12:59:59.258995 2026] [security2:error] [pid 123784:tid 123819] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wap.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsfwAAFx4"] [Tue Aug 18 12:59:59.282004 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/key.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsgQAAAB4"] [Tue Aug 18 12:59:59.293515 2026] [security2:error] [pid 123784:tid 123853] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ccc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsggAAUEA"] [Tue Aug 18 12:59:59.305965 2026] [security2:error] [pid 123784:tid 123926] [client 20.119.58.187:10487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/ws.php"] [unique_id "aoSBf2wDnJBNj2tDbYbshAAAAAg"] [Tue Aug 18 12:59:59.332404 2026] [security2:error] [pid 123784:tid 123952] [client 20.104.85.180:20266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/ok.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsjgAAACI"] [Tue Aug 18 12:59:59.345526 2026] [security2:error] [pid 123784:tid 123999] [client 172.202.39.151:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/f35.php"] [unique_id "aoSBf2wDnJBNj2tDbYbskAAAAFE"] [Tue Aug 18 12:59:59.373999 2026] [security2:error] [pid 123784:tid 123957] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsjwAAJwY"] [Tue Aug 18 12:59:59.391837 2026] [security2:error] [pid 123784:tid 124031] [client 158.158.74.177:3883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/new.php"] [unique_id "aoSBf2wDnJBNj2tDbYbskwAAAHE"] [Tue Aug 18 12:59:59.398179 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:59.398627 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:59.416467 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:28094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/themes.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslgAAAH4"] [Tue Aug 18 12:59:59.426402 2026] [security2:error] [pid 123784:tid 123862] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmAAAcEk"] [Tue Aug 18 12:59:59.428876 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslwAAADk"] [Tue Aug 18 12:59:59.429886 2026] [security2:error] [pid 123784:tid 123975] [client 5.31.227.224:59009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbslwAAADk"] [Tue Aug 18 12:59:59.453054 2026] [security2:error] [pid 123784:tid 124002] [client 172.202.39.151:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/01.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmQAAAFQ"] [Tue Aug 18 12:59:59.460449 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:20445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ac.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsmgAAAFM"] [Tue Aug 18 12:59:59.492884 2026] [security2:error] [pid 123784:tid 123947] [client 20.116.17.175:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsnQAAAB0"] [Tue Aug 18 12:59:59.514826 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:46742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsoAAAAEw"] [Tue Aug 18 12:59:59.514891 2026] [security2:error] [pid 123784:tid 124045] [client 40.74.65.169:20302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/dex.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsnwAAAH8"] [Tue Aug 18 12:59:59.531007 2026] [security2:error] [pid 123784:tid 123971] [client 20.226.56.190:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/le.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsoQAAADU"] [Tue Aug 18 12:59:59.555807 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zugvi.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsogAAAFg"] [Tue Aug 18 12:59:59.594147 2026] [security2:error] [pid 123784:tid 123806] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bgymj.php"] [unique_id "aoSBf2wDnJBNj2tDbYbspgAANBE"] [Tue Aug 18 12:59:59.598807 2026] [security2:error] [pid 123784:tid 123918] [client 213.202.253.4:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/delpaths.php"] [unique_id "aoSBf2wDnJBNj2tDbYbspwAAAAA"], referer: www.google.com [Tue Aug 18 12:59:59.625153 2026] [security2:error] [pid 123784:tid 123870] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/get.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsqAAAalE"] [Tue Aug 18 12:59:59.660255 2026] [security2:error] [pid 123784:tid 123961] [client 20.119.58.187:10554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wsa.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsqgAAACs"] [Tue Aug 18 12:59:59.694924 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 12:59:59.695181 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 12:59:59.708067 2026] [security2:error] [pid 123784:tid 123979] [client 20.79.204.6:14084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsrAAAAD0"] [Tue Aug 18 12:59:59.754078 2026] [security2:error] [pid 123784:tid 124017] [client 132.196.30.78:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ws83.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsrwAAAGM"] [Tue Aug 18 12:59:59.763076 2026] [security2:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/aa.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssAAAfBo"] [Tue Aug 18 12:59:59.774182 2026] [security2:error] [pid 123784:tid 123939] [client 20.116.17.175:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/cok.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssQAAABU"] [Tue Aug 18 12:59:59.819556 2026] [security2:error] [pid 123784:tid 123804] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssgAAOA8"] [Tue Aug 18 12:59:59.819787 2026] [security2:error] [pid 123784:tid 123974] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBf2wDnJBNj2tDbYbssgAAOA8"] [Tue Aug 18 12:59:59.872775 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/28.php"] [unique_id "aoSBf2wDnJBNj2tDbYbstgAAAGw"] [Tue Aug 18 12:59:59.928677 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:10580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hr.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsugAAABc"] [Tue Aug 18 12:59:59.930734 2026] [security2:error] [pid 123784:tid 123803] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-mail.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsuwAAYA4"] [Tue Aug 18 12:59:59.947574 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:28318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/cv.php"] [unique_id "aoSBf2wDnJBNj2tDbYbsvQAAACg"] [Tue Aug 18 12:59:59.982516 2026] [security2:error] [pid 123784:tid 123965] [client 157.90.156.63:17428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSBfmwDnJBNj2tDbYbsaAAAAC8"], referer: https://www.institutoferiani.com.br [Tue Aug 18 13:00:00.012690 2026] [security2:error] [pid 123784:tid 124037] [client 20.119.58.187:10159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/w.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsvgAAAHc"] [Tue Aug 18 13:00:00.015337 2026] [security2:error] [pid 123784:tid 123944] [client 158.158.74.177:3387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/packed.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsvwAAABo"] [Tue Aug 18 13:00:00.023923 2026] [security2:error] [pid 123784:tid 123821] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/images.php"] [unique_id "aoSBgGwDnJBNj2tDbYbswAAATSA"] [Tue Aug 18 13:00:00.038075 2026] [security2:error] [pid 123784:tid 123972] [client 20.251.48.93:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/akismet.php"] [unique_id "aoSBgGwDnJBNj2tDbYbswwAAADY"] [Tue Aug 18 13:00:00.042132 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yz.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxAAAAAg"] [Tue Aug 18 13:00:00.056388 2026] [security2:error] [pid 123784:tid 124005] [client 68.155.154.236:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxQAAAFc"] [Tue Aug 18 13:00:00.065365 2026] [security2:error] [pid 123784:tid 124022] [client 20.116.17.175:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/accesson.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxgAAAGg"] [Tue Aug 18 13:00:00.077853 2026] [security2:error] [pid 123784:tid 123935] [client 85.154.68.202:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.68.154.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxwAAABE"] [Tue Aug 18 13:00:00.078032 2026] [security2:error] [pid 123784:tid 123935] [client 85.154.68.202:62639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "faroleditorial.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsxwAAABE"] [Tue Aug 18 13:00:00.098363 2026] [security2:error] [pid 123784:tid 123879] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bolt.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsyAAAVlo"] [Tue Aug 18 13:00:00.156025 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:53725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBgGwDnJBNj2tDbYbsywAAAGI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:00.184786 2026] [security2:error] [pid 123784:tid 123988] [client 223.185.37.47:17634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbszAAAAEY"] [Tue Aug 18 13:00:00.184903 2026] [security2:error] [pid 123784:tid 123988] [client 223.185.37.47:17634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBgGwDnJBNj2tDbYbszAAAAEY"] [Tue Aug 18 13:00:00.211750 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:20297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/key.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs0QAAAH4"] [Tue Aug 18 13:00:00.233020 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kt.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs0gAAADk"] [Tue Aug 18 13:00:00.241035 2026] [security2:error] [pid 123784:tid 124002] [client 135.225.78.186:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/av.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1AAAAFQ"] [Tue Aug 18 13:00:00.262180 2026] [security2:error] [pid 123784:tid 123930] [client 20.203.138.185:22609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/thui.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1QAAAAw"] [Tue Aug 18 13:00:00.265027 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.85.180:18714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.avenidaveiculossc.com.br"] [uri "/item.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1gAAABQ"] [Tue Aug 18 13:00:00.265246 2026] [security2:error] [pid 123784:tid 123846] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bthil.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs1wAAGDk"] [Tue Aug 18 13:00:00.297798 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:00.298066 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:00.330471 2026] [security2:error] [pid 123784:tid 123915] [remote 185.118.190.176:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs2gAAUn4"] [Tue Aug 18 13:00:00.332485 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:14105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs2wAAACw"] [Tue Aug 18 13:00:00.356136 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/av.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3AAAAAU"] [Tue Aug 18 13:00:00.365311 2026] [security2:error] [pid 123784:tid 124031] [client 132.196.30.78:25196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/atex1.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3QAAAHE"] [Tue Aug 18 13:00:00.377393 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/x.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs3gAAAFM"] [Tue Aug 18 13:00:00.399356 2026] [security2:error] [pid 123784:tid 123876] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/alls.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs4QAAHVc"] [Tue Aug 18 13:00:00.442046 2026] [security2:error] [pid 123784:tid 123994] [client 20.226.56.190:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ww.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs4gAAAEw"] [Tue Aug 18 13:00:00.492474 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kj.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5AAAAGU"] [Tue Aug 18 13:00:00.508403 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sd.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5QAAABs"] [Tue Aug 18 13:00:00.510642 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.56.190:10569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mo.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs5gAAADQ"] [Tue Aug 18 13:00:00.515043 2026] [core:error] [pid 123784:tid 123816] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:00.515059 2026] [core:error] [pid 123784:tid 123816] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:00.524416 2026] [security2:error] [pid 123784:tid 123983] [client 158.23.17.4:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/m.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs6AAAAEE"] [Tue Aug 18 13:00:00.591955 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/le.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8QAAAGM"] [Tue Aug 18 13:00:00.601223 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:00.601692 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:00.631070 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:60445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/kj.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8gAAAAc"] [Tue Aug 18 13:00:00.636409 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.56.190:11615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qr.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs8wAAAE8"] [Tue Aug 18 13:00:00.649268 2026] [security2:error] [pid 123784:tid 123953] [client 20.250.27.191:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs-AAAACM"] [Tue Aug 18 13:00:00.682294 2026] [security2:error] [pid 123784:tid 123898] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/x.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs-wAAXG0"] [Tue Aug 18 13:00:00.717962 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:44132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/inputs.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_QAAABc"] [Tue Aug 18 13:00:00.730929 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_gAAADA"] [Tue Aug 18 13:00:00.731213 2026] [security2:error] [pid 123784:tid 123969] [client 20.119.58.187:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/xx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbs_wAAADM"] [Tue Aug 18 13:00:00.732039 2026] [security2:error] [pid 123784:tid 123904] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/coffexium.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtAAAAIHM"] [Tue Aug 18 13:00:00.745657 2026] [security2:error] [pid 123784:tid 123922] [client 20.127.136.245:28042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtAQAAAAQ"] [Tue Aug 18 13:00:00.849187 2026] [security2:error] [pid 123784:tid 124032] [client 158.158.74.177:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/plugin.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtCgAAAHI"] [Tue Aug 18 13:00:00.858970 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:20912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dirs.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtCwAAAEM"] [Tue Aug 18 13:00:00.868277 2026] [security2:error] [pid 123784:tid 123789] [remote 97.74.87.194:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDAAAAwA"] [Tue Aug 18 13:00:00.881378 2026] [security2:error] [pid 123784:tid 123856] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/index/function.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDgAAfkM"] [Tue Aug 18 13:00:00.886698 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:47057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/kir.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDwAAAHA"] [Tue Aug 18 13:00:00.901070 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:00.901493 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:00.913065 2026] [security2:error] [pid 123784:tid 124013] [client 20.116.17.175:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtEgAAAF8"] [Tue Aug 18 13:00:00.939772 2026] [security2:error] [pid 123784:tid 123958] [client 20.79.204.6:14030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/st.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtFgAAACg"] [Tue Aug 18 13:00:01.046200 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vg.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtHQAAAFM"] [Tue Aug 18 13:00:01.055156 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:28029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtHgAAAE4"] [Tue Aug 18 13:00:01.075692 2026] [security2:error] [pid 123784:tid 123902] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/aaa.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIAAATHE"] [Tue Aug 18 13:00:01.101257 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:40136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sn.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIgAAAA8"] [Tue Aug 18 13:00:01.110106 2026] [security2:error] [pid 123784:tid 123892] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/red.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIwAAWGc"] [Tue Aug 18 13:00:01.134820 2026] [security2:error] [pid 123784:tid 124009] [client 20.203.138.185:24920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/agg.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJQAAAFs"] [Tue Aug 18 13:00:01.171091 2026] [security2:error] [pid 123784:tid 123989] [client 213.35.127.232:53949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJgAAAEc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:01.177358 2026] [security2:error] [pid 123784:tid 124000] [client 132.196.30.78:25191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtJwAAAFI"] [Tue Aug 18 13:00:01.196235 2026] [security2:error] [pid 123784:tid 123977] [client 20.116.17.175:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/png.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtKAAAADs"] [Tue Aug 18 13:00:01.204179 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:01.205567 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:01.213504 2026] [security2:error] [pid 123784:tid 123932] [client 147.53.121.226:9883] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDQAAAA4"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:01.243892 2026] [security2:error] [pid 123784:tid 123814] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/abcd.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtLQAAKxk"] [Tue Aug 18 13:00:01.250345 2026] [security2:error] [pid 123784:tid 123942] [client 20.119.58.187:10461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtIQAAABg"] [Tue Aug 18 13:00:01.270647 2026] [security2:error] [pid 123784:tid 123928] [client 20.127.136.245:28521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ws83.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtLwAAAAo"] [Tue Aug 18 13:00:01.337446 2026] [security2:error] [pid 123784:tid 124042] [client 172.182.200.96:7554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtMgAAAHw"] [Tue Aug 18 13:00:01.375971 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.154.236:27559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtNQAAAAY"] [Tue Aug 18 13:00:01.421872 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-good.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOAAAIwg"] [Tue Aug 18 13:00:01.437953 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:44839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nl.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOQAAACk"] [Tue Aug 18 13:00:01.440320 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:7221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sm.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtOgAAAGw"] [Tue Aug 18 13:00:01.462609 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.27.191:40183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/domvf.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtPAAAAEU"] [Tue Aug 18 13:00:01.474876 2026] [security2:error] [pid 123784:tid 123941] [client 20.116.17.175:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ab.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtPQAAABc"] [Tue Aug 18 13:00:01.536163 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/43.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQQAAAB4"] [Tue Aug 18 13:00:01.578338 2026] [security2:error] [pid 123784:tid 123925] [client 20.79.204.6:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQgAAAAc"] [Tue Aug 18 13:00:01.583572 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:20915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fresh.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtQwAAAE0"] [Tue Aug 18 13:00:01.590006 2026] [security2:error] [pid 123784:tid 124020] [client 40.74.65.169:47043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/nofile.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRQAAAGY"] [Tue Aug 18 13:00:01.590847 2026] [security2:error] [pid 123784:tid 123891] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/simple.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRgAANmY"] [Tue Aug 18 13:00:01.606587 2026] [security2:error] [pid 123784:tid 123966] [client 20.119.58.187:10530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/y.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtRwAAADA"] [Tue Aug 18 13:00:01.623891 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:15122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/km.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtSQAAAG4"] [Tue Aug 18 13:00:01.650788 2026] [security2:error] [pid 123784:tid 123844] [remote 47.89.174.181:26996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.api.atlas-ia.com"] [uri "/.env"] [unique_id "aoSBgWwDnJBNj2tDbYbtSgAAdDc"] [Tue Aug 18 13:00:01.695048 2026] [security2:error] [pid 123784:tid 124027] [client 135.225.78.186:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/images.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUAAAAG0"] [Tue Aug 18 13:00:01.703099 2026] [security2:error] [pid 123784:tid 124021] [client 158.158.74.177:3855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/public/moon.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUQAAAGc"] [Tue Aug 18 13:00:01.728464 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.154.236:25398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtUwAAAH4"] [Tue Aug 18 13:00:01.729409 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:01.729883 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:01.764560 2026] [security2:error] [pid 123784:tid 123912] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtVwAAcHs"] [Tue Aug 18 13:00:01.769355 2026] [security2:error] [pid 123784:tid 124024] [client 20.116.17.175:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/12.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtWAAAAGo"] [Tue Aug 18 13:00:01.801172 2026] [security2:error] [pid 123784:tid 123952] [client 132.196.30.78:25155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/w.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtWQAAACI"] [Tue Aug 18 13:00:01.874810 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:17962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gj.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtXgAAACQ"] [Tue Aug 18 13:00:01.882192 2026] [security2:error] [pid 123784:tid 124031] [client 20.251.48.93:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/admin.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtXwAAAHE"] [Tue Aug 18 13:00:01.893603 2026] [security2:error] [pid 123784:tid 123947] [client 20.250.27.191:43479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYAAAAB0"] [Tue Aug 18 13:00:01.903593 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:47671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/28.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYQAAAH8"] [Tue Aug 18 13:00:01.923547 2026] [security2:error] [pid 123784:tid 123932] [client 147.53.121.226:9883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBgGwDnJBNj2tDbYbtDQAAAA4"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:01.939048 2026] [security2:error] [pid 123784:tid 123793] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/u.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtYgAAGwQ"] [Tue Aug 18 13:00:01.963806 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/lv.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtZAAAADQ"] [Tue Aug 18 13:00:01.965809 2026] [security2:error] [pid 123784:tid 123977] [client 20.203.138.185:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/erty.php"] [unique_id "aoSBgWwDnJBNj2tDbYbtZQAAADs"] [Tue Aug 18 13:00:01.999433 2026] [autoindex:error] [pid 123784:tid 123984] [client 4.232.94.69:37658] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:02.018687 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pd.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtbAAAAEg"] [Tue Aug 18 13:00:02.019683 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/images/security.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtbQAAAAo"] [Tue Aug 18 13:00:02.061129 2026] [security2:error] [pid 123784:tid 124017] [client 20.116.17.175:60429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/x1da.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcAAAAGM"] [Tue Aug 18 13:00:02.075732 2026] [security2:error] [pid 123784:tid 124042] [client 192.141.172.134:56231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcQAAAHw"] [Tue Aug 18 13:00:02.075955 2026] [security2:error] [pid 123784:tid 124042] [client 192.141.172.134:56231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcQAAAHw"] [Tue Aug 18 13:00:02.090220 2026] [security2:error] [pid 123784:tid 123996] [client 20.127.136.245:28542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/atex1.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtcgAAAE4"] [Tue Aug 18 13:00:02.113532 2026] [security2:error] [pid 123784:tid 123858] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtdAAAI0U"] [Tue Aug 18 13:00:02.164491 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/68.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtdwAAAH0"] [Tue Aug 18 13:00:02.171429 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:15184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/th.php"] [unique_id "aoSBgmwDnJBNj2tDbYbteAAAAFk"] [Tue Aug 18 13:00:02.188677 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:14088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbteQAAABk"] [Tue Aug 18 13:00:02.193007 2026] [security2:error] [pid 123784:tid 123960] [client 213.35.127.232:54155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtegAAACo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:02.209910 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.154.236:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtewAAAAg"] [Tue Aug 18 13:00:02.236619 2026] [security2:error] [pid 123784:tid 123966] [client 4.232.94.69:37658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/atomlib.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtfQAAADA"] [Tue Aug 18 13:00:02.258039 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:17955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/admin404.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtfwAAAGg"] [Tue Aug 18 13:00:02.265600 2026] [security2:error] [pid 123784:tid 123890] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgAAAUmU"] [Tue Aug 18 13:00:02.267518 2026] [security2:error] [pid 123784:tid 124000] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgAAAUmU"] [Tue Aug 18 13:00:02.281870 2026] [security2:error] [pid 123784:tid 123881] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/h.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtggAAc1w"] [Tue Aug 18 13:00:02.292904 2026] [security2:error] [pid 123784:tid 124028] [client 40.74.65.169:19496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/fling.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtgwAAAG4"] [Tue Aug 18 13:00:02.313974 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gec.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtiAAAABM"] [Tue Aug 18 13:00:02.317345 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:21150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qo.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtiQAAAEY"] [Tue Aug 18 13:00:02.325218 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:02.325700 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:02.338067 2026] [security2:error] [pid 123784:tid 124041] [client 158.158.74.177:3861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/public/storage.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtigAAAHs"] [Tue Aug 18 13:00:02.412699 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mcs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkAAAAFQ"] [Tue Aug 18 13:00:02.424110 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:7324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sd.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkQAAAAw"] [Tue Aug 18 13:00:02.449538 2026] [security2:error] [pid 123784:tid 123853] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkgAALEA"] [Tue Aug 18 13:00:02.452905 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:15797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/m.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtkwAAABY"] [Tue Aug 18 13:00:02.458249 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:17952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/km.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtlAAAAAk"] [Tue Aug 18 13:00:02.517738 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.56.190:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mf.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtmgAAAHg"] [Tue Aug 18 13:00:02.524959 2026] [security2:error] [pid 123784:tid 123994] [client 20.38.3.247:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/blurbs.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtmwAAAEw"] [Tue Aug 18 13:00:02.531457 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mf.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtnAAAAGQ"] [Tue Aug 18 13:00:02.538095 2026] [security2:error] [pid 123784:tid 124005] [client 132.196.30.78:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/archive.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtnQAAAFc"] [Tue Aug 18 13:00:02.609781 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.56.190:17946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ie.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtoAAAABw"] [Tue Aug 18 13:00:02.619326 2026] [security2:error] [pid 123784:tid 123850] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/a7.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtogAAQj0"] [Tue Aug 18 13:00:02.630436 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:02.631168 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:02.642593 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/class-t.api.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtpAAAAHE"] [Tue Aug 18 13:00:02.655502 2026] [security2:error] [pid 123784:tid 123928] [client 20.226.56.190:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nw.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtpQAAAAo"] [Tue Aug 18 13:00:02.677309 2026] [security2:error] [pid 123784:tid 123920] [client 20.203.138.185:53761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mini.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqAAAAAI"] [Tue Aug 18 13:00:02.689638 2026] [security2:error] [pid 123784:tid 124042] [client 20.116.17.175:60463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/adminner.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqQAAAHw"] [Tue Aug 18 13:00:02.720614 2026] [security2:error] [pid 123784:tid 124009] [client 68.155.154.236:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqgAAAFs"] [Tue Aug 18 13:00:02.726706 2026] [security2:error] [pid 123784:tid 123949] [client 20.250.27.191:28007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/sky.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtqwAAAB8"] [Tue Aug 18 13:00:02.738171 2026] [security2:error] [pid 123784:tid 123905] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/index.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtrAAANXQ"] [Tue Aug 18 13:00:02.764783 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jl.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtrwAAADo"] [Tue Aug 18 13:00:02.788879 2026] [security2:error] [pid 123784:tid 123807] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/manager.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtsAAAbRI"] [Tue Aug 18 13:00:02.819853 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.204.6:14086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-post.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtsQAAAD4"] [Tue Aug 18 13:00:02.859601 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sb.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtswAAAEA"] [Tue Aug 18 13:00:02.929531 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nl.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtugAAAG8"] [Tue Aug 18 13:00:02.935046 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:02.939668 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:02.957793 2026] [security2:error] [pid 123784:tid 123929] [client 136.66.149.90:38974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/graphql"] [unique_id "aoSBgmwDnJBNj2tDbYbtvQAAAAs"], referer: https://cpcontacts.lojasmemo.com.br [Tue Aug 18 13:00:02.959516 2026] [security2:error] [pid 123784:tid 123939] [client 158.158.74.177:16145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/radio.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtvgAAABU"] [Tue Aug 18 13:00:02.959583 2026] [security2:error] [pid 123784:tid 123992] [client 136.66.149.90:39036] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proc/self/environ"] [unique_id "aoSBgmwDnJBNj2tDbYbtvwAAAEo"] [Tue Aug 18 13:00:02.963473 2026] [security2:error] [pid 123784:tid 124011] [client 136.66.149.90:39026] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBgmwDnJBNj2tDbYbtwAAAAF0"] [Tue Aug 18 13:00:02.975251 2026] [security2:error] [pid 123784:tid 124018] [client 40.74.65.169:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/zoo1.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtxQAAAGQ"] [Tue Aug 18 13:00:02.976113 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:60446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBgmwDnJBNj2tDbYbtygAAAH4"] [Tue Aug 18 13:00:02.994220 2026] [security2:error] [pid 123784:tid 124016] [client 136.66.149.90:39166] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@vite/env"] [unique_id "aoSBgmwDnJBNj2tDbYbt1QAAAGI"] [Tue Aug 18 13:00:03.005497 2026] [core:error] [pid 123784:tid 123988] [client 136.66.149.90:39268] AH10244: invalid URI path (/assets../../../etc/passwd) [Tue Aug 18 13:00:03.008495 2026] [security2:error] [pid 123784:tid 123897] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/w1.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt3AAAD2w"] [Tue Aug 18 13:00:03.011899 2026] [security2:error] [pid 123784:tid 124020] [client 136.66.149.90:38986] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBg2wDnJBNj2tDbYbt3gAAAGY"] [Tue Aug 18 13:00:03.015101 2026] [security2:error] [pid 123784:tid 124033] [client 136.66.149.90:39184] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/etc/passwd"] [unique_id "aoSBg2wDnJBNj2tDbYbt4AAAAHM"] [Tue Aug 18 13:00:03.017013 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:38970] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBg2wDnJBNj2tDbYbt4gAAAH0"] [Tue Aug 18 13:00:03.018239 2026] [security2:error] [pid 123784:tid 124025] [client 136.66.149.90:39124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/home/ec2-user/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbt4wAAAGs"] [Tue Aug 18 13:00:03.019427 2026] [security2:error] [pid 123784:tid 124043] [client 168.62.48.100:18048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt5AAAAH0"] [Tue Aug 18 13:00:03.021553 2026] [security2:error] [pid 123784:tid 123966] [client 136.66.149.90:39182] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/read"] [unique_id "aoSBg2wDnJBNj2tDbYbt6AAAADA"] [Tue Aug 18 13:00:03.023251 2026] [security2:error] [pid 123784:tid 123944] [client 136.66.149.90:39240] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbt6gAAABo"] [Tue Aug 18 13:00:03.025586 2026] [security2:error] [pid 123784:tid 123926] [client 136.66.149.90:39096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/actuator/env"] [unique_id "aoSBg2wDnJBNj2tDbYbt6wAAAAg"] [Tue Aug 18 13:00:03.064398 2026] [security2:error] [pid 123784:tid 123911] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt8AAAHHo"] [Tue Aug 18 13:00:03.064912 2026] [security2:error] [pid 123784:tid 123967] [client 68.155.154.236:25360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt8QAAADE"] [Tue Aug 18 13:00:03.075753 2026] [security2:error] [pid 123784:tid 123983] [client 190.92.174.183:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbttgAAAEE"] [Tue Aug 18 13:00:03.075984 2026] [security2:error] [pid 123784:tid 123983] [client 190.92.174.183:47178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBgmwDnJBNj2tDbYbttgAAAEE"] [Tue Aug 18 13:00:03.142285 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.27.191:27985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/sixxis.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt9QAAADc"] [Tue Aug 18 13:00:03.156098 2026] [security2:error] [pid 123784:tid 123994] [client 132.196.30.78:16993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/bless.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt9wAAAEw"] [Tue Aug 18 13:00:03.169101 2026] [security2:error] [pid 123784:tid 124019] [client 20.127.136.245:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/w.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt-AAAAGU"] [Tue Aug 18 13:00:03.181444 2026] [core:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:03.181469 2026] [core:error] [pid 123784:tid 123815] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:03.187676 2026] [security2:error] [pid 123784:tid 124009] [client 20.251.48.93:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.luvhost.com.br"] [uri "/ajax.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt-wAAAFs"] [Tue Aug 18 13:00:03.206799 2026] [security2:error] [pid 123784:tid 123974] [client 168.62.48.100:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wsrer.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt_QAAADg"] [Tue Aug 18 13:00:03.212536 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbt_wAAAHI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:03.247171 2026] [security2:error] [pid 123784:tid 123985] [client 103.120.71.157:21211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuAwAAAEM"] [Tue Aug 18 13:00:03.247370 2026] [security2:error] [pid 123784:tid 123985] [client 103.120.71.157:21211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuAwAAAEM"] [Tue Aug 18 13:00:03.263735 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xj.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuBQAAAAw"] [Tue Aug 18 13:00:03.275120 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:18144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuBgAAAGk"] [Tue Aug 18 13:00:03.298754 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/68.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCAAAACg"] [Tue Aug 18 13:00:03.332236 2026] [security2:error] [pid 123784:tid 123927] [client 20.65.98.162:45619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCgAAAAk"] [Tue Aug 18 13:00:03.351918 2026] [security2:error] [pid 123784:tid 123863] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuCwAAeEo"] [Tue Aug 18 13:00:03.367031 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/setup-config.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuDAAAAH4"] [Tue Aug 18 13:00:03.441858 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:14022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuFAAAABE"] [Tue Aug 18 13:00:03.452330 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.56.190:17961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ns.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuFQAAAFg"] [Tue Aug 18 13:00:03.480352 2026] [security2:error] [pid 123784:tid 123959] [client 20.203.138.185:32212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sid3.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuGQAAACk"] [Tue Aug 18 13:00:03.532037 2026] [security2:error] [pid 123784:tid 123968] [client 168.62.48.100:18117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/weozh.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJAAAADI"] [Tue Aug 18 13:00:03.543302 2026] [security2:error] [pid 123784:tid 123915] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/default.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJQAAK34"] [Tue Aug 18 13:00:03.546928 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:03.547475 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:03.560543 2026] [security2:error] [pid 123784:tid 123802] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file52.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuJwAAcA0"] [Tue Aug 18 13:00:03.563339 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKAAAAHA"] [Tue Aug 18 13:00:03.571205 2026] [security2:error] [pid 123784:tid 123948] [client 20.250.27.191:40159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/yj09.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKQAAAB4"] [Tue Aug 18 13:00:03.582094 2026] [security2:error] [pid 123784:tid 123931] [client 158.158.74.177:16182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/root.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuKgAAAA0"] [Tue Aug 18 13:00:03.590394 2026] [security2:error] [pid 123784:tid 124007] [client 79.127.164.8:60088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/upload.bak"] [unique_id "aoSBg2wDnJBNj2tDbYbuLAAAAFk"], referer: https://medihub.com.br/upload.bak [Tue Aug 18 13:00:03.610333 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gk.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuLQAAAGM"] [Tue Aug 18 13:00:03.645044 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/archive.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuLgAAABw"] [Tue Aug 18 13:00:03.654593 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/f35.update.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMAAAACc"] [Tue Aug 18 13:00:03.657560 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:15175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wn.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMQAAAE0"] [Tue Aug 18 13:00:03.663437 2026] [security2:error] [pid 123784:tid 124041] [client 172.202.39.151:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/alfa.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuMwAAAHs"] [Tue Aug 18 13:00:03.675178 2026] [security2:error] [pid 123784:tid 123974] [client 40.74.65.169:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/zoo2.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOAAAADg"] [Tue Aug 18 13:00:03.677799 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/hr.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOQAAAE8"] [Tue Aug 18 13:00:03.693597 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ie.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuOwAAAEk"] [Tue Aug 18 13:00:03.714372 2026] [security2:error] [pid 123784:tid 123805] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/i.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuPQAAIxA"] [Tue Aug 18 13:00:03.721419 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jl.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuPgAAAGk"] [Tue Aug 18 13:00:03.780863 2026] [security2:error] [pid 123784:tid 123986] [client 168.62.48.100:18116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/rymmm.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuQQAAAEQ"] [Tue Aug 18 13:00:03.782165 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/app.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuQgAAAEU"] [Tue Aug 18 13:00:03.819481 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:10586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/87.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuRQAAAFQ"] [Tue Aug 18 13:00:03.829271 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:03.829707 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:03.857475 2026] [security2:error] [pid 123784:tid 123925] [client 136.66.149.90:39136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.save"] [unique_id "aoSBg2wDnJBNj2tDbYbuSAAAAAc"] [Tue Aug 18 13:00:03.859201 2026] [security2:error] [pid 123784:tid 123969] [client 136.66.149.90:39034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/core/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbuVAAAADM"] [Tue Aug 18 13:00:03.860253 2026] [security2:error] [pid 123784:tid 123967] [client 136.66.149.90:38930] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.backup"] [unique_id "aoSBg2wDnJBNj2tDbYbuVgAAADE"] [Tue Aug 18 13:00:03.861064 2026] [security2:error] [pid 123784:tid 123972] [client 136.66.149.90:39134] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/back/.env"] [unique_id "aoSBg2wDnJBNj2tDbYbuVwAAADY"] [Tue Aug 18 13:00:03.886240 2026] [core:error] [pid 123784:tid 123792] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:03.886260 2026] [core:error] [pid 123784:tid 123792] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:03.890960 2026] [security2:error] [pid 123784:tid 123836] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/geck.php"] [unique_id "aoSBg2wDnJBNj2tDbYbuYQAAGC8"] [Tue Aug 18 13:00:03.935285 2026] [security2:error] [pid 123784:tid 124019] [client 135.225.78.186:24071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/ops.php"] [unique_id "aoSBg2wDnJBNj2tDbYbubAAAAGU"] [Tue Aug 18 13:00:03.943349 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/bdroot.php"] [unique_id "aoSBg2wDnJBNj2tDbYbubQAAABw"] [Tue Aug 18 13:00:03.948240 2026] [security2:error] [pid 123784:tid 123957] [client 136.66.149.90:38982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/root/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbubgAAACc"] [Tue Aug 18 13:00:03.955627 2026] [security2:error] [pid 123784:tid 123976] [client 132.196.30.78:25156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/sagax1.php"] [unique_id "aoSBg2wDnJBNj2tDbYbucQAAADo"] [Tue Aug 18 13:00:03.987797 2026] [security2:error] [pid 123784:tid 123934] [client 136.66.149.90:38946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/home/node/.aws/credentials"] [unique_id "aoSBg2wDnJBNj2tDbYbudAAAABA"] [Tue Aug 18 13:00:04.011795 2026] [security2:error] [pid 123784:tid 123977] [client 20.250.27.191:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/k.php"] [unique_id "aoSBhGwDnJBNj2tDbYbudQAAADs"] [Tue Aug 18 13:00:04.037987 2026] [security2:error] [pid 123784:tid 123958] [client 168.62.48.100:18057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/lddxs.php"] [unique_id "aoSBhGwDnJBNj2tDbYbudgAAACg"] [Tue Aug 18 13:00:04.053266 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbueQAACVI"] [Tue Aug 18 13:00:04.057715 2026] [security2:error] [pid 123784:tid 123943] [client 190.92.174.183:47194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuewAAABk"] [Tue Aug 18 13:00:04.057880 2026] [security2:error] [pid 123784:tid 123943] [client 190.92.174.183:47194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuewAAABk"] [Tue Aug 18 13:00:04.076738 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:14029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSBhGwDnJBNj2tDbYbufgAAAFo"] [Tue Aug 18 13:00:04.118581 2026] [security2:error] [pid 123784:tid 123989] [client 136.66.149.90:39256] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/app/.aws/credentials"] [unique_id "aoSBhGwDnJBNj2tDbYbulAAAAEc"] [Tue Aug 18 13:00:04.120499 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:7319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zi.php"] [unique_id "aoSBhGwDnJBNj2tDbYbulQAAAH0"] [Tue Aug 18 13:00:04.124282 2026] [security2:error] [pid 123784:tid 123981] [client 20.203.138.185:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/moon.php"] [unique_id "aoSBhGwDnJBNj2tDbYbulgAAAD8"] [Tue Aug 18 13:00:04.130823 2026] [security2:error] [pid 123784:tid 123998] [client 136.66.149.90:39208] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbumAAAAFA"] [Tue Aug 18 13:00:04.147467 2026] [security2:error] [pid 123784:tid 123959] [client 136.66.149.90:39192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/1/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbumwAAACk"] [Tue Aug 18 13:00:04.162127 2026] [security2:error] [pid 123784:tid 123979] [client 158.23.17.4:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tq.php"] [unique_id "aoSBhGwDnJBNj2tDbYbunQAAAD0"] [Tue Aug 18 13:00:04.187239 2026] [security2:error] [pid 123784:tid 124031] [client 158.23.17.4:47924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nw.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuoQAAAHE"] [Tue Aug 18 13:00:04.202247 2026] [security2:error] [pid 123784:tid 123974] [client 20.127.136.245:28073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/bless.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuowAAADg"] [Tue Aug 18 13:00:04.204151 2026] [security2:error] [pid 123784:tid 123952] [client 197.184.64.235:41953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupAAAACI"] [Tue Aug 18 13:00:04.204325 2026] [security2:error] [pid 123784:tid 123952] [client 197.184.64.235:41953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupAAAACI"] [Tue Aug 18 13:00:04.208260 2026] [security2:error] [pid 123784:tid 123971] [client 158.158.74.177:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/server.php"] [unique_id "aoSBhGwDnJBNj2tDbYbupgAAADU"] [Tue Aug 18 13:00:04.210425 2026] [core:error] [pid 123784:tid 124012] [client 136.66.149.90:39436] AH10244: invalid URI path (/assets../../../.env) [Tue Aug 18 13:00:04.225324 2026] [security2:error] [pid 123784:tid 123840] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYburAAAWDM"] [Tue Aug 18 13:00:04.225396 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.56.190:21126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/92.php"] [unique_id "aoSBhGwDnJBNj2tDbYburQAAAHQ"] [Tue Aug 18 13:00:04.226628 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:56456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBhGwDnJBNj2tDbYburgAAABw"] [Tue Aug 18 13:00:04.230514 2026] [security2:error] [pid 123784:tid 123942] [client 213.35.127.232:54629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbusAAAABg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:04.241287 2026] [security2:error] [pid 123784:tid 124013] [client 136.66.149.90:39442] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.github/workflows/ci.yml"] [unique_id "aoSBhGwDnJBNj2tDbYbusgAAAF8"] [Tue Aug 18 13:00:04.242372 2026] [security2:error] [pid 123784:tid 123929] [client 136.66.149.90:39460] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.github/.env"] [unique_id "aoSBhGwDnJBNj2tDbYbuswAAAAs"] [Tue Aug 18 13:00:04.255424 2026] [security2:error] [pid 123784:tid 123960] [client 136.66.149.90:39298] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhGwDnJBNj2tDbYbuuAAAACo"] [Tue Aug 18 13:00:04.258825 2026] [security2:error] [pid 123784:tid 123935] [client 20.116.17.175:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuvAAAABE"] [Tue Aug 18 13:00:04.280676 2026] [security2:error] [pid 123784:tid 123866] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/biufile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuxgAAb00"] [Tue Aug 18 13:00:04.286591 2026] [security2:error] [pid 123784:tid 123937] [client 168.62.48.100:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zjggu.php"] [unique_id "aoSBhGwDnJBNj2tDbYbuxwAAABM"] [Tue Aug 18 13:00:04.305879 2026] [security2:error] [pid 123784:tid 123993] [client 136.66.149.90:39490] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSBhGwDnJBNj2tDbYbuywAAAEs"] [Tue Aug 18 13:00:04.348135 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.56.190:20894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jm.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu0gAAAG0"] [Tue Aug 18 13:00:04.367449 2026] [security2:error] [pid 123784:tid 123989] [client 51.89.129.243:61280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marcellomeneghel.com"] [uri "/robots.txt"] [unique_id "aoSBhGwDnJBNj2tDbYbu1QAAAEc"] [Tue Aug 18 13:00:04.367603 2026] [security2:error] [pid 123784:tid 123989] [client 51.89.129.243:61280] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marcellomeneghel.com"] [uri "/robots.txt"] [unique_id "aoSBhGwDnJBNj2tDbYbu1QAAAEc"] [Tue Aug 18 13:00:04.376798 2026] [security2:error] [pid 123784:tid 124043] [client 40.74.65.169:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/org.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu1gAAAH0"] [Tue Aug 18 13:00:04.393686 2026] [security2:error] [pid 123784:tid 123858] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu2AAAMUU"] [Tue Aug 18 13:00:04.397694 2026] [security2:error] [pid 123784:tid 124030] [client 136.66.149.90:39262] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbu2QAAAHA"] [Tue Aug 18 13:00:04.418954 2026] [security2:error] [pid 123784:tid 123952] [client 136.66.149.90:39014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/read"] [unique_id "aoSBhGwDnJBNj2tDbYbu3AAAACI"] [Tue Aug 18 13:00:04.424476 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:43492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/w.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu3gAAAFI"] [Tue Aug 18 13:00:04.433216 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:04.433713 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:04.463419 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.156.252:21939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu4AAAAFg"] [Tue Aug 18 13:00:04.536608 2026] [security2:error] [pid 123784:tid 123984] [client 136.66.149.90:39220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhGwDnJBNj2tDbYbu5AAAAEI"] [Tue Aug 18 13:00:04.542954 2026] [security2:error] [pid 123784:tid 123924] [client 168.62.48.100:18133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu5QAAAAY"] [Tue Aug 18 13:00:04.554137 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-css.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu5gAAACw"] [Tue Aug 18 13:00:04.584273 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/cv.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6AAAAFQ"] [Tue Aug 18 13:00:04.585267 2026] [security2:error] [pid 123784:tid 123988] [client 68.221.73.131:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/chosen.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6QAAAEY"] [Tue Aug 18 13:00:04.591994 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.154.236:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu6gAAABs"] [Tue Aug 18 13:00:04.603888 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tq.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7AAAAH4"] [Tue Aug 18 13:00:04.611487 2026] [security2:error] [pid 123784:tid 123881] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/NewFile.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7QAAeVw"] [Tue Aug 18 13:00:04.617154 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:39114] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbu7gAAAH0"] [Tue Aug 18 13:00:04.619628 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wj.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu7wAAAGI"] [Tue Aug 18 13:00:04.711222 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu8gAAAF8"] [Tue Aug 18 13:00:04.726156 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:04.726448 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:04.734962 2026] [security2:error] [pid 123784:tid 124017] [client 132.196.30.78:25175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wpc.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu9QAAAGM"] [Tue Aug 18 13:00:04.779540 2026] [security2:error] [pid 123784:tid 123798] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu9wAAFQk"] [Tue Aug 18 13:00:04.781195 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu-AAAAFY"] [Tue Aug 18 13:00:04.789906 2026] [autoindex:error] [pid 123784:tid 124001] [client 4.232.94.69:42501] AH01276: Cannot serve directory /home2/vfunnelcrmcom/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:04.793215 2026] [security2:error] [pid 123784:tid 123869] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dejavu.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu_AAARVA"] [Tue Aug 18 13:00:04.796373 2026] [security2:error] [pid 123784:tid 124038] [client 20.127.136.245:28300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/sagax1.php"] [unique_id "aoSBhGwDnJBNj2tDbYbu_gAAAHg"] [Tue Aug 18 13:00:04.829236 2026] [security2:error] [pid 123784:tid 123984] [client 136.66.149.90:39232] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhGwDnJBNj2tDbYbvAAAAAEI"] [Tue Aug 18 13:00:04.831592 2026] [security2:error] [pid 123784:tid 124003] [client 158.158.74.177:3366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAQAAAFU"] [Tue Aug 18 13:00:04.833734 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fpwch.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAgAAAAY"] [Tue Aug 18 13:00:04.835102 2026] [security2:error] [pid 123784:tid 124045] [client 20.116.17.175:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/flox.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvAwAAAH8"] [Tue Aug 18 13:00:04.948051 2026] [security2:error] [pid 123784:tid 123883] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCAAAfl4"] [Tue Aug 18 13:00:04.959155 2026] [security2:error] [pid 123784:tid 123812] [remote 3.109.96.140:33626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.96.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCQAACBc"] [Tue Aug 18 13:00:04.996667 2026] [security2:error] [pid 123784:tid 124024] [client 4.232.94.69:42501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBhGwDnJBNj2tDbYbvCwAAAGo"] [Tue Aug 18 13:00:05.019189 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:39506] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvDQAAAGc"] [Tue Aug 18 13:00:05.025061 2026] [security2:error] [pid 123784:tid 123959] [client 168.62.48.100:18153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/kopyw.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvEAAAACk"] [Tue Aug 18 13:00:05.030058 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:05.030396 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:33796] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:05.033094 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:42435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/74.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvEQAAADE"] [Tue Aug 18 13:00:05.056958 2026] [security2:error] [pid 123784:tid 123964] [client 20.203.138.185:45468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFQAAAC4"] [Tue Aug 18 13:00:05.060672 2026] [security2:error] [pid 123784:tid 124026] [client 40.74.65.169:43027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/imageskir.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFgAAAGw"] [Tue Aug 18 13:00:05.116445 2026] [security2:error] [pid 123784:tid 123999] [client 20.116.17.175:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/op.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvFwAAAFE"] [Tue Aug 18 13:00:05.131437 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:15189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/av.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvGQAAAHU"] [Tue Aug 18 13:00:05.159856 2026] [security2:error] [pid 123784:tid 123905] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/themes.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvHQAAY3Q"] [Tue Aug 18 13:00:05.160403 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/abcd.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvHgAAABQ"] [Tue Aug 18 13:00:05.176347 2026] [security2:error] [pid 123784:tid 124023] [client 172.202.39.151:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/new.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvIAAAAGk"] [Tue Aug 18 13:00:05.190256 2026] [security2:error] [pid 123784:tid 123958] [client 136.66.149.90:39508] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvIgAAACg"] [Tue Aug 18 13:00:05.247566 2026] [security2:error] [pid 123784:tid 123980] [client 213.35.127.232:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvJgAAAD4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:05.248626 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.27.191:40153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvJwAAABY"] [Tue Aug 18 13:00:05.252117 2026] [security2:error] [pid 123784:tid 124038] [client 158.23.17.4:10966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kt.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKAAAAHg"] [Tue Aug 18 13:00:05.285077 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/un.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKQAAAFU"] [Tue Aug 18 13:00:05.287206 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ag.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKgAAAAY"] [Tue Aug 18 13:00:05.294136 2026] [security2:error] [pid 123784:tid 123932] [client 20.127.136.245:28289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvKwAAAA4"] [Tue Aug 18 13:00:05.297159 2026] [security2:error] [pid 123784:tid 123948] [client 168.62.48.100:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zznmg.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvLAAAAB4"] [Tue Aug 18 13:00:05.308246 2026] [security2:error] [pid 123784:tid 123807] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aaf.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvLgAAcBI"] [Tue Aug 18 13:00:05.322713 2026] [security2:error] [pid 123784:tid 123925] [client 20.79.204.6:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/cjfuns.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvMAAAAAc"] [Tue Aug 18 13:00:05.361802 2026] [security2:error] [pid 123784:tid 123945] [client 136.66.149.90:39100] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvNgAAABs"] [Tue Aug 18 13:00:05.379198 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/cv.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvOAAAAH0"] [Tue Aug 18 13:00:05.379623 2026] [security2:error] [pid 123784:tid 123897] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/cv.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvOQAAfmw"] [Tue Aug 18 13:00:05.451767 2026] [security2:error] [pid 123784:tid 124004] [client 132.196.30.78:25208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/fone1.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvPgAAAFY"] [Tue Aug 18 13:00:05.465103 2026] [security2:error] [pid 123784:tid 123959] [client 20.116.17.175:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvPwAAACk"] [Tue Aug 18 13:00:05.466238 2026] [security2:error] [pid 123784:tid 123937] [client 158.158.74.177:3862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/shell.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvQAAAABM"] [Tue Aug 18 13:00:05.533087 2026] [security2:error] [pid 123784:tid 123952] [client 136.66.149.90:39052] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvSgAAACI"] [Tue Aug 18 13:00:05.541063 2026] [security2:error] [pid 123784:tid 123999] [client 168.62.48.100:18171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvTAAAAFE"] [Tue Aug 18 13:00:05.579193 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.56.190:20870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ig.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvUAAAAHQ"] [Tue Aug 18 13:00:05.581209 2026] [core:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:05.581232 2026] [core:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:05.583356 2026] [security2:error] [pid 123784:tid 123923] [client 20.65.98.162:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/img.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvUQAAAAU"] [Tue Aug 18 13:00:05.656405 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.27.191:45781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/blurbs.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVAAAACg"] [Tue Aug 18 13:00:05.658576 2026] [security2:error] [pid 123784:tid 123842] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/h02ugyh.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVQAAPjU"] [Tue Aug 18 13:00:05.672230 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:51138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sb.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvVgAAAEo"] [Tue Aug 18 13:00:05.701924 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:40166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ta.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvWwAAAAY"] [Tue Aug 18 13:00:05.704204 2026] [security2:error] [pid 123784:tid 123933] [client 136.66.149.90:39480] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvXAAAAA8"] [Tue Aug 18 13:00:05.729837 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.56.190:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/34.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvXwAAAHM"] [Tue Aug 18 13:00:05.741248 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/txets.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvYgAAABg"] [Tue Aug 18 13:00:05.744778 2026] [security2:error] [pid 123784:tid 123954] [client 136.66.149.90:39386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/api/preview"] [unique_id "aoSBhWwDnJBNj2tDbYbvYwAAACQ"] [Tue Aug 18 13:00:05.744824 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:05.745015 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:05.745121 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:05.745316 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:05.749143 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/lock360.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZAAAAFw"] [Tue Aug 18 13:00:05.758333 2026] [security2:error] [pid 123784:tid 123974] [client 20.203.138.185:49918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wsws.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZQAAADg"] [Tue Aug 18 13:00:05.761453 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/fone1.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZgAAAEg"] [Tue Aug 18 13:00:05.761996 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/indexo.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvZwAAAAA"] [Tue Aug 18 13:00:05.772138 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvaQAAAFA"] [Tue Aug 18 13:00:05.772295 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:61968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvaQAAAFA"] [Tue Aug 18 13:00:05.779259 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvawAAAEA"] [Tue Aug 18 13:00:05.792412 2026] [security2:error] [pid 123784:tid 123829] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvbgAAfig"] [Tue Aug 18 13:00:05.793374 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:25397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvbwAAAH0"] [Tue Aug 18 13:00:05.822309 2026] [security2:error] [pid 123784:tid 123922] [client 86.120.159.145:64930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvcQAAAAQ"] [Tue Aug 18 13:00:05.822667 2026] [security2:error] [pid 123784:tid 123922] [client 86.120.159.145:64930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvcQAAAAQ"] [Tue Aug 18 13:00:05.875465 2026] [security2:error] [pid 123784:tid 124042] [client 136.66.149.90:39284] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhWwDnJBNj2tDbYbvdQAAAHw"] [Tue Aug 18 13:00:05.897626 2026] [security2:error] [pid 123784:tid 123984] [client 190.92.174.183:50468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbveQAAAEI"] [Tue Aug 18 13:00:05.897717 2026] [security2:error] [pid 123784:tid 123984] [client 190.92.174.183:50468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSBhWwDnJBNj2tDbYbveQAAAEI"] [Tue Aug 18 13:00:05.910334 2026] [security2:error] [pid 123784:tid 123953] [client 136.66.149.90:39768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhWwDnJBNj2tDbYbvegAAACM"] [Tue Aug 18 13:00:05.916273 2026] [security2:error] [pid 123784:tid 123964] [client 136.66.149.90:38912] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhWwDnJBNj2tDbYbvewAAAC4"] [Tue Aug 18 13:00:05.927146 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:40447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/evil.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvfgAAAEM"] [Tue Aug 18 13:00:05.931811 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:05.932247 2026] [authz_core:error] [pid 123784:tid 123864] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:05.948859 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:39420] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhWwDnJBNj2tDbYbvgAAAAGw"] [Tue Aug 18 13:00:05.958336 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvggAAAHA"] [Tue Aug 18 13:00:05.976139 2026] [security2:error] [pid 123784:tid 124034] [client 54.39.136.154:26394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marcellomeneghel.com"] [uri "/"] [unique_id "aoSBhWwDnJBNj2tDbYbvhQAAAHQ"] [Tue Aug 18 13:00:05.976258 2026] [security2:error] [pid 123784:tid 124034] [client 54.39.136.154:26394] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marcellomeneghel.com"] [uri "/"] [unique_id "aoSBhWwDnJBNj2tDbYbvhQAAAHQ"] [Tue Aug 18 13:00:05.981448 2026] [security2:error] [pid 123784:tid 123945] [client 132.196.30.78:25206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ncx.php"] [unique_id "aoSBhWwDnJBNj2tDbYbvhgAAABs"] [Tue Aug 18 13:00:05.992612 2026] [security2:error] [pid 123784:tid 123790] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ws83.php"] [unique_id "aoSBhWwDnJBNj2tDbYbviAAAdQE"] [Tue Aug 18 13:00:06.000160 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:32555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/un.php"] [unique_id "aoSBhWwDnJBNj2tDbYbviQAAAAI"] [Tue Aug 18 13:00:06.022577 2026] [security2:error] [pid 123784:tid 123995] [client 168.62.48.100:18126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/oivcl.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvigAAAE0"] [Tue Aug 18 13:00:06.023159 2026] [security2:error] [pid 123784:tid 124023] [client 20.116.17.175:60417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/img.php"] [unique_id "aoSBhmwDnJBNj2tDbYbviwAAAGk"] [Tue Aug 18 13:00:06.039706 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/155.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvjAAAZn4"] [Tue Aug 18 13:00:06.047082 2026] [security2:error] [pid 123784:tid 123977] [client 136.66.149.90:39076] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvjQAAADs"] [Tue Aug 18 13:00:06.070583 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:15179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/he.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvjwAAAEo"] [Tue Aug 18 13:00:06.071976 2026] [security2:error] [pid 123784:tid 123924] [client 136.66.149.90:39520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhmwDnJBNj2tDbYbvkAAAAAY"] [Tue Aug 18 13:00:06.074067 2026] [security2:error] [pid 123784:tid 124045] [client 68.155.156.252:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvkQAAAH8"] [Tue Aug 18 13:00:06.083950 2026] [security2:error] [pid 123784:tid 124000] [client 136.66.149.90:39376] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/fetch"] [unique_id "aoSBhmwDnJBNj2tDbYbvlAAAAFI"] [Tue Aug 18 13:00:06.087576 2026] [security2:error] [pid 123784:tid 123933] [client 136.66.149.90:39382] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvlQAAAA8"] [Tue Aug 18 13:00:06.087936 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.27.191:34821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/100.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvlgAAAHM"] [Tue Aug 18 13:00:06.089780 2026] [security2:error] [pid 123784:tid 124004] [client 158.158.74.177:3886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/sim.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvlwAAAFY"] [Tue Aug 18 13:00:06.154170 2026] [security2:error] [pid 123784:tid 123846] [remote 129.121.123.168:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvmgAAfjk"] [Tue Aug 18 13:00:06.159604 2026] [security2:error] [pid 123784:tid 123802] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/atex1.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvmwAATw0"] [Tue Aug 18 13:00:06.214536 2026] [security2:error] [pid 123784:tid 123937] [client 20.65.98.162:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/aa.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvngAAABM"] [Tue Aug 18 13:00:06.218313 2026] [security2:error] [pid 123784:tid 124002] [client 136.66.149.90:39346] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvnwAAAFQ"] [Tue Aug 18 13:00:06.259037 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:39468] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvogAAAGw"] [Tue Aug 18 13:00:06.261375 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvowAAAFE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:06.277137 2026] [security2:error] [pid 123784:tid 124034] [client 172.202.39.151:4448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/222.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpAAAAHQ"] [Tue Aug 18 13:00:06.299433 2026] [security2:error] [pid 123784:tid 123960] [client 20.116.17.175:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpQAAACo"] [Tue Aug 18 13:00:06.328287 2026] [security2:error] [pid 123784:tid 123859] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/class-t.api.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvpwAAGUY"] [Tue Aug 18 13:00:06.332166 2026] [security2:error] [pid 123784:tid 123919] [client 20.127.136.245:28538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ncx.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqAAAAAE"] [Tue Aug 18 13:00:06.339656 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:18049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zugvi.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqgAAAHo"] [Tue Aug 18 13:00:06.340559 2026] [security2:error] [pid 123784:tid 124009] [client 158.23.17.4:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pw.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvqwAAAFs"] [Tue Aug 18 13:00:06.344863 2026] [security2:error] [pid 123784:tid 123927] [client 192.141.172.134:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvrAAAAAk"] [Tue Aug 18 13:00:06.345022 2026] [security2:error] [pid 123784:tid 123927] [client 192.141.172.134:56509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvrAAAAAk"] [Tue Aug 18 13:00:06.408529 2026] [security2:error] [pid 123784:tid 124041] [client 136.66.149.90:39410] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbvrwAAAHs"] [Tue Aug 18 13:00:06.430070 2026] [security2:error] [pid 123784:tid 123923] [client 135.225.78.186:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/coffexium.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvsgAAAAU"] [Tue Aug 18 13:00:06.444519 2026] [security2:error] [pid 123784:tid 124006] [client 136.66.149.90:39218] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBhmwDnJBNj2tDbYbvswAAAFg"] [Tue Aug 18 13:00:06.464386 2026] [security2:error] [pid 123784:tid 123954] [client 40.74.65.169:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvtQAAACQ"] [Tue Aug 18 13:00:06.498469 2026] [security2:error] [pid 123784:tid 123806] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/w.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvugAAABE"] [Tue Aug 18 13:00:06.503314 2026] [security2:error] [pid 123784:tid 124025] [client 20.250.27.191:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ccc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvuwAAAGs"] [Tue Aug 18 13:00:06.523424 2026] [security2:error] [pid 123784:tid 124038] [client 20.250.13.23:38288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-good.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvQAAAHg"] [Tue Aug 18 13:00:06.526355 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:5623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/ucpfr.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvgAAAHY"] [Tue Aug 18 13:00:06.557705 2026] [security2:error] [pid 123784:tid 123836] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ops.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvvwAAfi8"] [Tue Aug 18 13:00:06.560337 2026] [security2:error] [pid 123784:tid 123958] [client 20.79.204.6:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvwAAAACg"] [Tue Aug 18 13:00:06.570391 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:8280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gz.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvwgAAAAw"] [Tue Aug 18 13:00:06.589663 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:18114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wsrer.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvxAAAAGo"] [Tue Aug 18 13:00:06.602400 2026] [security2:error] [pid 123784:tid 124039] [client 20.116.17.175:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvxQAAAHk"] [Tue Aug 18 13:00:06.666049 2026] [security2:error] [pid 123784:tid 123825] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/archive.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvyAAAbiQ"] [Tue Aug 18 13:00:06.681254 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fn.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvygAAAAo"] [Tue Aug 18 13:00:06.683593 2026] [security2:error] [pid 123784:tid 123968] [client 20.203.138.185:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/motu.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvywAAADI"] [Tue Aug 18 13:00:06.687362 2026] [security2:error] [pid 123784:tid 124014] [client 132.196.30.78:22168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzAAAAGA"] [Tue Aug 18 13:00:06.712899 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/evil.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzgAAAG8"] [Tue Aug 18 13:00:06.728006 2026] [security2:error] [pid 123784:tid 123959] [client 172.202.39.151:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/chosen.php"] [unique_id "aoSBhmwDnJBNj2tDbYbvzwAAACk"] [Tue Aug 18 13:00:06.728992 2026] [security2:error] [pid 123784:tid 124022] [client 68.221.73.131:32034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/thoms.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv0AAAAGg"] [Tue Aug 18 13:00:06.735612 2026] [security2:error] [pid 123784:tid 123941] [client 158.158.74.177:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/simple.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv0QAAABc"] [Tue Aug 18 13:00:06.791196 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.56.190:10588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nf.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv1wAAABw"] [Tue Aug 18 13:00:06.829693 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:06.829994 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:06.831909 2026] [security2:error] [pid 123784:tid 124032] [client 168.62.48.100:18053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv2wAAAHI"] [Tue Aug 18 13:00:06.854205 2026] [security2:error] [pid 123784:tid 123925] [client 190.92.174.183:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3AAAAAc"] [Tue Aug 18 13:00:06.854316 2026] [security2:error] [pid 123784:tid 123925] [client 190.92.174.183:50484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3AAAAAc"] [Tue Aug 18 13:00:06.861640 2026] [security2:error] [pid 123784:tid 123876] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/bless.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3QAATVc"] [Tue Aug 18 13:00:06.882702 2026] [security2:error] [pid 123784:tid 124023] [client 20.116.17.175:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv3gAAAGk"] [Tue Aug 18 13:00:06.914087 2026] [security2:error] [pid 123784:tid 124020] [client 20.250.27.191:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/get.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv4AAAAGY"] [Tue Aug 18 13:00:06.985107 2026] [security2:error] [pid 123784:tid 123966] [client 136.66.149.90:39826] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSBhmwDnJBNj2tDbYbv4wAAADA"] [Tue Aug 18 13:00:06.985371 2026] [security2:error] [pid 123784:tid 124007] [client 20.127.136.245:28305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBhmwDnJBNj2tDbYbv5AAAAFk"] [Tue Aug 18 13:00:07.012014 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.154.236:25376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv5QAAAAs"] [Tue Aug 18 13:00:07.030753 2026] [security2:error] [pid 123784:tid 123871] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/sagax1.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv5wAAElI"] [Tue Aug 18 13:00:07.036141 2026] [security2:error] [pid 123784:tid 124027] [client 136.66.149.90:39842] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/proxy"] [unique_id "aoSBh2wDnJBNj2tDbYbv6AAAAG0"] [Tue Aug 18 13:00:07.071268 2026] [security2:error] [pid 123784:tid 124000] [client 20.38.3.247:46776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/bajah.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv6wAAAFI"] [Tue Aug 18 13:00:07.084494 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/yxijx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7AAAAFY"] [Tue Aug 18 13:00:07.108035 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.56.190:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xv.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7gAAAB0"] [Tue Aug 18 13:00:07.115886 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kf.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv7wAAAFo"] [Tue Aug 18 13:00:07.132936 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:56465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/av.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv8QAAAHY"] [Tue Aug 18 13:00:07.135289 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:07.135755 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:07.162174 2026] [security2:error] [pid 123784:tid 123981] [client 40.74.65.169:20316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv9gAAAD8"] [Tue Aug 18 13:00:07.176519 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.204.6:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/import.php"] [unique_id "aoSBh2wDnJBNj2tDbYbv_gAAACM"] [Tue Aug 18 13:00:07.190212 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xj.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwAgAAADI"] [Tue Aug 18 13:00:07.199388 2026] [security2:error] [pid 123784:tid 123908] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwAwAAfHc"] [Tue Aug 18 13:00:07.200695 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:29502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ww.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwBAAAAGA"] [Tue Aug 18 13:00:07.237736 2026] [security2:error] [pid 123784:tid 123992] [client 132.196.30.78:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwBwAAAEo"] [Tue Aug 18 13:00:07.247275 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/info.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwFAAAAFA"] [Tue Aug 18 13:00:07.275404 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.56.190:40153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwHgAAACk"] [Tue Aug 18 13:00:07.280967 2026] [security2:error] [pid 123784:tid 124040] [client 213.35.127.232:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwHwAAAHo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:07.287757 2026] [security2:error] [pid 123784:tid 123934] [client 20.116.17.175:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwIAAAABA"] [Tue Aug 18 13:00:07.320182 2026] [security2:error] [pid 123784:tid 123973] [client 79.127.164.8:56702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/upload.sql"] [unique_id "aoSBh2wDnJBNj2tDbYbwIgAAADc"], referer: https://medihub.com.br/upload.sql [Tue Aug 18 13:00:07.344888 2026] [security2:error] [pid 123784:tid 123964] [client 168.62.48.100:18149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJAAAAC4"] [Tue Aug 18 13:00:07.357647 2026] [security2:error] [pid 123784:tid 124043] [client 158.158.74.177:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/st.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJQAAAH0"] [Tue Aug 18 13:00:07.358524 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:45767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/images.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJgAAAAg"] [Tue Aug 18 13:00:07.367207 2026] [security2:error] [pid 123784:tid 123794] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/fone1.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwJwAAOAU"] [Tue Aug 18 13:00:07.395442 2026] [security2:error] [pid 123784:tid 123835] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/mac.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwLAAAWi4"] [Tue Aug 18 13:00:07.421087 2026] [security2:error] [pid 123784:tid 124021] [client 20.127.136.245:28313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwLgAAAGc"] [Tue Aug 18 13:00:07.517527 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:6388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/45.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwOwAAAEY"] [Tue Aug 18 13:00:07.517532 2026] [security2:error] [pid 123784:tid 123951] [client 136.66.149.90:11438] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/config.xml.bak"] [unique_id "aoSBh2wDnJBNj2tDbYbwOgAAACE"] [Tue Aug 18 13:00:07.519954 2026] [security2:error] [pid 123784:tid 123993] [client 136.66.149.90:11410] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/credentials.xml"] [unique_id "aoSBh2wDnJBNj2tDbYbwQAAAAEs"] [Tue Aug 18 13:00:07.526179 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cloudbuild.yaml"] [unique_id "aoSBh2wDnJBNj2tDbYbwTAAAAAE"] [Tue Aug 18 13:00:07.529888 2026] [security2:error] [pid 123784:tid 123976] [client 136.66.149.90:11650] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/jenkins/secrets/master.key"] [unique_id "aoSBh2wDnJBNj2tDbYbwVQAAADo"] [Tue Aug 18 13:00:07.531745 2026] [security2:error] [pid 123784:tid 123936] [client 136.66.149.90:11738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.local.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwWgAAABI"] [Tue Aug 18 13:00:07.533080 2026] [security2:error] [pid 123784:tid 123960] [client 136.66.149.90:11516] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.travis.yml"] [unique_id "aoSBh2wDnJBNj2tDbYbwXwAAACo"] [Tue Aug 18 13:00:07.533106 2026] [security2:error] [pid 123784:tid 124045] [client 136.66.149.90:11680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.development.local"] [unique_id "aoSBh2wDnJBNj2tDbYbwYAAAAH8"] [Tue Aug 18 13:00:07.538824 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwWwAAABY"] [Tue Aug 18 13:00:07.559334 2026] [security2:error] [pid 123784:tid 123928] [client 20.116.17.175:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/term.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZAAAAAo"] [Tue Aug 18 13:00:07.574540 2026] [security2:error] [pid 123784:tid 123883] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ncx.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZQAAYF4"] [Tue Aug 18 13:00:07.584174 2026] [security2:error] [pid 123784:tid 123931] [client 20.203.138.185:45501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fff.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwZwAAAA0"] [Tue Aug 18 13:00:07.602055 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:18135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/jrpga.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwcQAAAFA"] [Tue Aug 18 13:00:07.656682 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ns.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwdgAAAF4"] [Tue Aug 18 13:00:07.692505 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:40397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/su.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwhgAAAH0"] [Tue Aug 18 13:00:07.719806 2026] [security2:error] [pid 123784:tid 123942] [client 136.66.149.90:11530] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/%2eenv"] [unique_id "aoSBh2wDnJBNj2tDbYbwiQAAABg"] [Tue Aug 18 13:00:07.736438 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:07.736896 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:07.747745 2026] [security2:error] [pid 123784:tid 123970] [client 136.66.149.90:11362] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwjQAAADQ"] [Tue Aug 18 13:00:07.773146 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11346] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwjwAAAAE"] [Tue Aug 18 13:00:07.787514 2026] [security2:error] [pid 123784:tid 123976] [client 136.66.149.90:11394] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.netlify/.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwkAAAADo"] [Tue Aug 18 13:00:07.787869 2026] [security2:error] [pid 123784:tid 123921] [client 20.79.204.6:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/cropper.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwkQAAAAM"] [Tue Aug 18 13:00:07.794848 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:17965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wy.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwkgAAAH8"] [Tue Aug 18 13:00:07.799510 2026] [core:error] [pid 123784:tid 123960] [client 136.66.149.90:11426] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 13:00:07.800638 2026] [security2:error] [pid 123784:tid 123790] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlQAAHAE"] [Tue Aug 18 13:00:07.807621 2026] [security2:error] [pid 123784:tid 124028] [client 190.92.174.183:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlgAAAG4"] [Tue Aug 18 13:00:07.807756 2026] [security2:error] [pid 123784:tid 124028] [client 190.92.174.183:50498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwlgAAAG4"] [Tue Aug 18 13:00:07.813814 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.yml"] [unique_id "aoSBh2wDnJBNj2tDbYbwlwAAABY"] [Tue Aug 18 13:00:07.828120 2026] [security2:error] [pid 123784:tid 123922] [client 136.66.149.90:11452] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwmAAAAAQ"] [Tue Aug 18 13:00:07.838663 2026] [security2:error] [pid 123784:tid 123928] [client 40.74.65.169:20159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/.admin.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmQAAAAo"] [Tue Aug 18 13:00:07.839890 2026] [security2:error] [pid 123784:tid 124044] [client 168.62.48.100:18160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmgAAAH4"] [Tue Aug 18 13:00:07.840062 2026] [security2:error] [pid 123784:tid 123971] [client 20.250.27.191:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/alls.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwmwAAADU"] [Tue Aug 18 13:00:07.842055 2026] [security2:error] [pid 123784:tid 124034] [client 136.66.149.90:11356] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwnAAAAHQ"] [Tue Aug 18 13:00:07.848818 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/black.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwnQAAAGA"] [Tue Aug 18 13:00:07.862787 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:38887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mo.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwoAAAAHA"] [Tue Aug 18 13:00:07.875850 2026] [core:error] [pid 123784:tid 123937] [client 136.66.149.90:11444] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:00:07.877091 2026] [security2:error] [pid 123784:tid 123944] [client 132.196.30.78:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/zup.php73"] [unique_id "aoSBh2wDnJBNj2tDbYbwogAAABo"] [Tue Aug 18 13:00:07.879932 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/f.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwowAAADE"] [Tue Aug 18 13:00:07.880228 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:27664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/zup.php73"] [unique_id "aoSBh2wDnJBNj2tDbYbwpAAAAAY"] [Tue Aug 18 13:00:07.884992 2026] [security2:error] [pid 123784:tid 123992] [client 136.66.149.90:11462] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252F.env"] [unique_id "aoSBh2wDnJBNj2tDbYbwpQAAAEo"] [Tue Aug 18 13:00:07.941135 2026] [security2:error] [pid 123784:tid 123985] [client 136.66.149.90:11606] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/debug.log"] [unique_id "aoSBh2wDnJBNj2tDbYbwrwAAAEM"] [Tue Aug 18 13:00:07.967339 2026] [security2:error] [pid 123784:tid 123888] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wso.php"] [unique_id "aoSBh2wDnJBNj2tDbYbwswAALmM"] [Tue Aug 18 13:00:07.993684 2026] [security2:error] [pid 123784:tid 124006] [client 136.66.149.90:11668] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSBh2wDnJBNj2tDbYbwuQAAAFg"] [Tue Aug 18 13:00:08.009519 2026] [authz_core:error] [pid 123784:tid 123903] [remote 57.141.22.114:28570] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:08.009804 2026] [authz_core:error] [pid 123784:tid 123903] [remote 57.141.22.114:28570] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:08.019610 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.56.190:20908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/30.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwvQAAAGc"] [Tue Aug 18 13:00:08.034136 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:08.034416 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:08.034748 2026] [security2:error] [pid 123784:tid 123845] [remote 20.54.134.42:3671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwwAAAIzg"] [Tue Aug 18 13:00:08.045949 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:10603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pu.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwwwAAAF8"] [Tue Aug 18 13:00:08.046856 2026] [security2:error] [pid 123784:tid 123968] [client 158.158.74.177:16174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwxAAAADI"] [Tue Aug 18 13:00:08.059893 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:20879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ry.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwxgAAAB4"] [Tue Aug 18 13:00:08.073662 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:18162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/nwwha.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwywAAAGk"] [Tue Aug 18 13:00:08.090960 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.56.190:15210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pm.php"] [unique_id "aoSBiGwDnJBNj2tDbYbwzgAAABk"] [Tue Aug 18 13:00:08.137572 2026] [security2:error] [pid 123784:tid 124001] [client 20.116.17.175:58117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/as.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw0wAAAFM"] [Tue Aug 18 13:00:08.179092 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:7323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dr.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw2AAAAFk"] [Tue Aug 18 13:00:08.182788 2026] [security2:error] [pid 123784:tid 123800] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/zup.php73"] [unique_id "aoSBiGwDnJBNj2tDbYbw2QAAQgs"] [Tue Aug 18 13:00:08.202001 2026] [security2:error] [pid 123784:tid 124030] [client 20.104.85.180:18858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw2wAAAHA"] [Tue Aug 18 13:00:08.218556 2026] [security2:error] [pid 123784:tid 123939] [client 136.66.149.90:11374] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbw3QAAABU"] [Tue Aug 18 13:00:08.249449 2026] [security2:error] [pid 123784:tid 123959] [client 20.250.27.191:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/coffexium.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw5wAAACk"] [Tue Aug 18 13:00:08.259113 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:60774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gk.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw6gAAAD4"] [Tue Aug 18 13:00:08.274855 2026] [security2:error] [pid 123784:tid 123923] [client 136.66.149.90:11380] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/docker/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbw6wAAAAU"] [Tue Aug 18 13:00:08.294218 2026] [security2:error] [pid 123784:tid 124035] [client 213.35.127.232:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw7QAAAHU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:08.327387 2026] [security2:error] [pid 123784:tid 124000] [client 168.62.48.100:18139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/opsqt.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw8gAAAFI"] [Tue Aug 18 13:00:08.329241 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:7317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ts.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw9AAAAEE"] [Tue Aug 18 13:00:08.337634 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:08.337989 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:08.342683 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/53.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw9gAAAEU"] [Tue Aug 18 13:00:08.347906 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.98.162:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/media.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw-AAAAHI"] [Tue Aug 18 13:00:08.350212 2026] [security2:error] [pid 123784:tid 123834] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw-QAANi0"] [Tue Aug 18 13:00:08.352850 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:11546] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/internal/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbw-gAAAGc"] [Tue Aug 18 13:00:08.365217 2026] [security2:error] [pid 123784:tid 124038] [client 136.66.149.90:11640] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/private/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbw-wAAAHg"] [Tue Aug 18 13:00:08.370220 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lq.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_AAAAA8"] [Tue Aug 18 13:00:08.413958 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:17926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/you.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_gAAACQ"] [Tue Aug 18 13:00:08.415838 2026] [security2:error] [pid 123784:tid 124013] [client 20.116.17.175:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/pucci.php"] [unique_id "aoSBiGwDnJBNj2tDbYbw_wAAAF8"] [Tue Aug 18 13:00:08.420456 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:20361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wp-key.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxAAAAAHM"] [Tue Aug 18 13:00:08.420717 2026] [security2:error] [pid 123784:tid 123948] [client 136.66.149.90:11696] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app/.env.production"] [unique_id "aoSBiGwDnJBNj2tDbYbxAQAAAB4"] [Tue Aug 18 13:00:08.426556 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ez.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxAgAAAEY"] [Tue Aug 18 13:00:08.439371 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxBgAAAGA"] [Tue Aug 18 13:00:08.441075 2026] [security2:error] [pid 123784:tid 124018] [client 20.127.136.245:28063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxBwAAAGQ"] [Tue Aug 18 13:00:08.449617 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/asus.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxCAAAAGU"] [Tue Aug 18 13:00:08.457137 2026] [security2:error] [pid 123784:tid 123994] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.bini.imb.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSBiGwDnJBNj2tDbYbxCQAATFY"] [Tue Aug 18 13:00:08.488863 2026] [security2:error] [pid 123784:tid 124028] [client 68.155.156.252:12626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxEAAAAG4"] [Tue Aug 18 13:00:08.491844 2026] [security2:error] [pid 123784:tid 124022] [client 136.66.149.90:11694] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbxEQAAAGg"] [Tue Aug 18 13:00:08.521577 2026] [security2:error] [pid 123784:tid 123941] [client 40.74.65.169:20132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/wsomini.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxFAAAABc"] [Tue Aug 18 13:00:08.531963 2026] [security2:error] [pid 123784:tid 123920] [client 20.104.85.180:18841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxFgAAAAI"] [Tue Aug 18 13:00:08.563207 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.56.190:40161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/22.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxGAAAABo"] [Tue Aug 18 13:00:08.569431 2026] [security2:error] [pid 123784:tid 123932] [client 20.203.138.185:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/66.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxGwAAAA4"] [Tue Aug 18 13:00:08.569966 2026] [security2:error] [pid 123784:tid 123902] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxHAAAUHE"] [Tue Aug 18 13:00:08.577355 2026] [security2:error] [pid 123784:tid 124003] [client 136.66.149.90:11724] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/backup/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxHQAAAFU"] [Tue Aug 18 13:00:08.611548 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:18172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxIQAAAGI"] [Tue Aug 18 13:00:08.620924 2026] [security2:error] [pid 123784:tid 123963] [client 132.196.30.78:2803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxIgAAAC0"] [Tue Aug 18 13:00:08.651841 2026] [security2:error] [pid 123784:tid 123919] [client 136.66.149.90:11384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/sendgrid/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJQAAAAE"] [Tue Aug 18 13:00:08.658571 2026] [security2:error] [pid 123784:tid 123961] [client 20.250.27.191:40186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/red.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJgAAACs"] [Tue Aug 18 13:00:08.665102 2026] [security2:error] [pid 123784:tid 123943] [client 158.158.74.177:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/system.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxJwAAABk"] [Tue Aug 18 13:00:08.667425 2026] [security2:error] [pid 123784:tid 124043] [client 136.66.149.90:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/twilio/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxKAAAAH0"] [Tue Aug 18 13:00:08.669466 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:42476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zs.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxKwAAAFI"] [Tue Aug 18 13:00:08.685138 2026] [security2:error] [pid 123784:tid 124021] [client 136.66.149.90:11502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app_dev.php/_profiler/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxMAAAAGc"] [Tue Aug 18 13:00:08.691109 2026] [security2:error] [pid 123784:tid 123940] [client 136.66.149.90:11708] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSBiGwDnJBNj2tDbYbxMQAAABY"] [Tue Aug 18 13:00:08.707305 2026] [security2:error] [pid 123784:tid 124038] [client 136.66.149.90:11592] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.hermes/.env"] [unique_id "aoSBiGwDnJBNj2tDbYbxMgAAAHg"] [Tue Aug 18 13:00:08.724309 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wicked.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxNQAAACM"] [Tue Aug 18 13:00:08.743353 2026] [core:error] [pid 123784:tid 123849] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:08.743378 2026] [core:error] [pid 123784:tid 123849] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:08.744260 2026] [security2:error] [pid 123784:tid 123971] [client 136.66.149.90:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/_profiler/phpinfo.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOAAAADU"] [Tue Aug 18 13:00:08.751678 2026] [security2:error] [pid 123784:tid 124013] [client 68.221.73.131:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/wpxml.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOQAAAF8"] [Tue Aug 18 13:00:08.756057 2026] [security2:error] [pid 123784:tid 123957] [client 136.66.149.90:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/config/.env.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxOwAAACc"] [Tue Aug 18 13:00:08.775078 2026] [security2:error] [pid 123784:tid 124033] [client 136.66.149.90:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.php.bak"] [unique_id "aoSBiGwDnJBNj2tDbYbxPAAAAHM"] [Tue Aug 18 13:00:08.795393 2026] [security2:error] [pid 123784:tid 124020] [client 136.66.149.90:11494] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.env.test"] [unique_id "aoSBiGwDnJBNj2tDbYbxPQAAAGY"] [Tue Aug 18 13:00:08.796565 2026] [security2:error] [pid 123784:tid 123891] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/makeasmtp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxPgAANGY"] [Tue Aug 18 13:00:08.812670 2026] [security2:error] [pid 123784:tid 123936] [client 20.104.85.180:43568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxQAAAABI"] [Tue Aug 18 13:00:08.812757 2026] [security2:error] [pid 123784:tid 123925] [client 136.66.149.90:11784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/phpinfo.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxQQAAAAc"] [Tue Aug 18 13:00:08.828552 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:42792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxRAAAAFs"] [Tue Aug 18 13:00:08.828762 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:42792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxRAAAAFs"] [Tue Aug 18 13:00:08.903952 2026] [security2:error] [pid 123784:tid 124004] [client 168.62.48.100:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxSgAAAFY"] [Tue Aug 18 13:00:08.910270 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qr.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTAAAAAo"] [Tue Aug 18 13:00:08.918235 2026] [core:error] [pid 123784:tid 123916] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:08.918272 2026] [core:error] [pid 123784:tid 123916] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:08.918697 2026] [security2:error] [pid 123784:tid 124034] [client 149.34.210.141:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTgAAAHQ"] [Tue Aug 18 13:00:08.922674 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTwAAADw"] [Tue Aug 18 13:00:08.922835 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTwAAADw"] [Tue Aug 18 13:00:08.967378 2026] [security2:error] [pid 123784:tid 123966] [client 68.155.154.236:27536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxUwAAADA"] [Tue Aug 18 13:00:08.982713 2026] [security2:error] [pid 123784:tid 124010] [client 158.23.17.4:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pw.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxVAAAAFw"] [Tue Aug 18 13:00:08.990226 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:28080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-blink.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxVgAAAAA"] [Tue Aug 18 13:00:09.003545 2026] [security2:error] [pid 123784:tid 124016] [client 135.225.78.186:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxVwAAAGI"] [Tue Aug 18 13:00:09.013496 2026] [security2:error] [pid 123784:tid 123963] [client 20.116.17.175:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/water.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxWQAAAC0"] [Tue Aug 18 13:00:09.039617 2026] [security2:error] [pid 123784:tid 124023] [client 20.79.204.6:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxXAAAAGk"] [Tue Aug 18 13:00:09.047193 2026] [security2:error] [pid 123784:tid 124039] [client 136.66.149.90:11580] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/aws/metadata/iam/security-credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxXgAAAHk"] [Tue Aug 18 13:00:09.103001 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.85.180:18867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/function/function.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxZwAAADE"] [Tue Aug 18 13:00:09.128952 2026] [security2:error] [pid 123784:tid 124027] [client 136.66.149.90:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.149.66.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "aoSBiWwDnJBNj2tDbYbxagAAAG0"] [Tue Aug 18 13:00:09.143265 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxawAAAEA"] [Tue Aug 18 13:00:09.147800 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:15782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gg.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxbAAAAD4"] [Tue Aug 18 13:00:09.165973 2026] [core:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:09.165995 2026] [core:error] [pid 123784:tid 123857] [remote 74.248.18.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:00:09.185029 2026] [security2:error] [pid 123784:tid 124034] [client 149.34.210.141:52006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBiGwDnJBNj2tDbYbxTgAAAHQ"] [Tue Aug 18 13:00:09.210810 2026] [security2:error] [pid 123784:tid 124036] [client 138.36.100.162:41566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxcwAAAHY"] [Tue Aug 18 13:00:09.210949 2026] [security2:error] [pid 123784:tid 124036] [client 138.36.100.162:41566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxcwAAAHY"] [Tue Aug 18 13:00:09.218706 2026] [security2:error] [pid 123784:tid 123991] [client 136.66.149.90:11772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/aws-credentials.json"] [unique_id "aoSBiWwDnJBNj2tDbYbxdAAAAEk"] [Tue Aug 18 13:00:09.238832 2026] [security2:error] [pid 123784:tid 123948] [client 40.74.65.169:20376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maisautoveiculo.com.br"] [uri "/vr.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxdgAAAB4"] [Tue Aug 18 13:00:09.243163 2026] [security2:error] [pid 123784:tid 123844] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxdwAARjc"] [Tue Aug 18 13:00:09.244311 2026] [security2:error] [pid 123784:tid 123943] [client 132.196.30.78:2769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxeAAAABk"] [Tue Aug 18 13:00:09.244559 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:09.245016 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:09.247521 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:15123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wn.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxeQAAAGY"] [Tue Aug 18 13:00:09.247783 2026] [security2:error] [pid 123784:tid 123970] [client 136.66.149.90:11712] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/data/aws/credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxegAAADQ"] [Tue Aug 18 13:00:09.270329 2026] [security2:error] [pid 123784:tid 124026] [client 136.66.149.90:11424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/ecs/task-credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxfAAAAGw"] [Tue Aug 18 13:00:09.291693 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.98.162:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/images.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxgAAAAAY"] [Tue Aug 18 13:00:09.310134 2026] [security2:error] [pid 123784:tid 123977] [client 213.35.127.232:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhAAAADs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:09.326727 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fine.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhgAAACw"] [Tue Aug 18 13:00:09.334040 2026] [security2:error] [pid 123784:tid 123797] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/ww5.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxhwAAVgg"] [Tue Aug 18 13:00:09.358644 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:8317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iz.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxiQAAAFc"] [Tue Aug 18 13:00:09.380428 2026] [security2:error] [pid 123784:tid 124032] [client 136.66.149.90:11750] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/html/.env"] [unique_id "aoSBiWwDnJBNj2tDbYbxiwAAAHI"] [Tue Aug 18 13:00:09.388420 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:3865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/system_log.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxjAAAAD8"] [Tue Aug 18 13:00:09.420611 2026] [security2:error] [pid 123784:tid 123998] [client 20.104.85.180:43581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxjwAAAFA"] [Tue Aug 18 13:00:09.422235 2026] [security2:error] [pid 123784:tid 124041] [client 157.20.138.62:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkAAAAHs"] [Tue Aug 18 13:00:09.422378 2026] [security2:error] [pid 123784:tid 124041] [client 157.20.138.62:58325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkAAAAHs"] [Tue Aug 18 13:00:09.442774 2026] [security2:error] [pid 123784:tid 124029] [client 168.62.48.100:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxkQAAAG8"] [Tue Aug 18 13:00:09.473559 2026] [security2:error] [pid 123784:tid 124022] [client 136.66.149.90:11470] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/vendor/aws/credentials"] [unique_id "aoSBiWwDnJBNj2tDbYbxlQAAAGg"] [Tue Aug 18 13:00:09.502253 2026] [security2:error] [pid 123784:tid 123895] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/2.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxmQAAamo"] [Tue Aug 18 13:00:09.505710 2026] [security2:error] [pid 123784:tid 123985] [client 20.203.138.185:32195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/g.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxmgAAAEM"] [Tue Aug 18 13:00:09.541227 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:09.541507 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:09.563742 2026] [security2:error] [pid 123784:tid 123929] [client 20.226.56.190:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/se.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxnwAAAAs"] [Tue Aug 18 13:00:09.622938 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/loader.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxoQAAACM"] [Tue Aug 18 13:00:09.630528 2026] [security2:error] [pid 123784:tid 123984] [client 102.214.136.52:54883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.136.214.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactoveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxogAAAEI"] [Tue Aug 18 13:00:09.630690 2026] [security2:error] [pid 123784:tid 123984] [client 102.214.136.52:54883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "impactoveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxogAAAEI"] [Tue Aug 18 13:00:09.639804 2026] [security2:error] [pid 123784:tid 123841] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/system_log.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpQAABDQ"] [Tue Aug 18 13:00:09.645930 2026] [security2:error] [pid 123784:tid 123966] [client 20.79.204.6:14089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/goat.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpgAAADA"] [Tue Aug 18 13:00:09.658551 2026] [security2:error] [pid 123784:tid 124034] [client 40.74.65.169:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxpwAAAHQ"] [Tue Aug 18 13:00:09.691737 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gi.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxqQAAADg"] [Tue Aug 18 13:00:09.707694 2026] [security2:error] [pid 123784:tid 123942] [client 20.104.85.180:43580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxqgAAABg"] [Tue Aug 18 13:00:09.714406 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:18124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxrAAAAHM"] [Tue Aug 18 13:00:09.727900 2026] [security2:error] [pid 123784:tid 123890] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxrwAAfGU"] [Tue Aug 18 13:00:09.743653 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:20926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vp.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxsAAAABI"] [Tue Aug 18 13:00:09.749014 2026] [security2:error] [pid 123784:tid 124009] [client 20.250.27.191:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxsQAAAFs"] [Tue Aug 18 13:00:09.779792 2026] [security2:error] [pid 123784:tid 124028] [client 20.226.56.190:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ph.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxswAAAG4"] [Tue Aug 18 13:00:09.804029 2026] [security2:error] [pid 123784:tid 123946] [client 178.153.171.161:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtAAAABw"] [Tue Aug 18 13:00:09.804236 2026] [security2:error] [pid 123784:tid 123946] [client 178.153.171.161:28483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtAAAABw"] [Tue Aug 18 13:00:09.814196 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:10975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dirs.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxtgAAAA0"] [Tue Aug 18 13:00:09.859879 2026] [security2:error] [pid 123784:tid 123981] [client 136.66.149.90:11620] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.lojasmemo.com.br"] [uri "/.aws/metadata/iam/security-credentials/"] [unique_id "aoSBiWwDnJBNj2tDbYbxuwAAAD8"] [Tue Aug 18 13:00:09.885040 2026] [security2:error] [pid 123784:tid 124000] [client 190.92.174.183:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvAAAAFI"] [Tue Aug 18 13:00:09.885143 2026] [security2:error] [pid 123784:tid 124000] [client 190.92.174.183:50518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvAAAAFI"] [Tue Aug 18 13:00:09.895393 2026] [security2:error] [pid 123784:tid 123831] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/atomlib.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxvgAAayo"] [Tue Aug 18 13:00:09.909014 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/zero.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxwgAAABo"] [Tue Aug 18 13:00:09.918811 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/s.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxwwAAACE"] [Tue Aug 18 13:00:09.969132 2026] [security2:error] [pid 123784:tid 124017] [client 20.65.98.162:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/admin.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxAAAAGM"] [Tue Aug 18 13:00:09.984538 2026] [security2:error] [pid 123784:tid 123937] [client 37.40.227.74:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxwAAABM"] [Tue Aug 18 13:00:09.984651 2026] [security2:error] [pid 123784:tid 123937] [client 37.40.227.74:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxwAAABM"] [Tue Aug 18 13:00:09.999984 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.85.180:18868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/ok.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxygAAAAA"] [Tue Aug 18 13:00:10.027563 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:18068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzAAAAGI"] [Tue Aug 18 13:00:10.028737 2026] [security2:error] [pid 123784:tid 123963] [client 20.127.136.245:28082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/ww5.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzQAAAC0"] [Tue Aug 18 13:00:10.039658 2026] [security2:error] [pid 123784:tid 123985] [client 68.155.156.252:40761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/av.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzgAAAEM"] [Tue Aug 18 13:00:10.061462 2026] [security2:error] [pid 123784:tid 124032] [client 158.158.74.177:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBimwDnJBNj2tDbYbxzwAAAHI"] [Tue Aug 18 13:00:10.063344 2026] [security2:error] [pid 123784:tid 123899] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/rip.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0QAAcW4"] [Tue Aug 18 13:00:10.077739 2026] [security2:error] [pid 123784:tid 123978] [client 5.31.227.224:30422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0wAAADw"] [Tue Aug 18 13:00:10.082455 2026] [security2:error] [pid 123784:tid 123978] [client 5.31.227.224:30422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx0wAAADw"] [Tue Aug 18 13:00:10.136212 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fn.php"] [unique_id "aoSBimwDnJBNj2tDbYbx1gAAAEU"] [Tue Aug 18 13:00:10.145328 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:10.145777 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:10.162692 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBimwDnJBNj2tDbYbx1wAAAEA"] [Tue Aug 18 13:00:10.202804 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/002.php"] [unique_id "aoSBimwDnJBNj2tDbYbx4AAAADc"] [Tue Aug 18 13:00:10.204400 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/app.php"] [unique_id "aoSBimwDnJBNj2tDbYbx4QAAAEk"] [Tue Aug 18 13:00:10.230454 2026] [security2:error] [pid 123784:tid 123852] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/p.php"] [unique_id "aoSBimwDnJBNj2tDbYbx5wAAGT8"] [Tue Aug 18 13:00:10.246361 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/Session.php"] [unique_id "aoSBimwDnJBNj2tDbYbx6QAAAF4"] [Tue Aug 18 13:00:10.252401 2026] [security2:error] [pid 123784:tid 124026] [client 172.202.39.151:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbx6gAAAGw"] [Tue Aug 18 13:00:10.261503 2026] [security2:error] [pid 123784:tid 123988] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbx5gAARnY"] [Tue Aug 18 13:00:10.273417 2026] [security2:error] [pid 123784:tid 124020] [client 168.62.48.100:18146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBimwDnJBNj2tDbYbx7AAAAGY"] [Tue Aug 18 13:00:10.281354 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.85.180:18828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "certificado.numem.com.br"] [uri "/item.php"] [unique_id "aoSBimwDnJBNj2tDbYbx7QAAABU"] [Tue Aug 18 13:00:10.326280 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8AAAAEE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:10.349366 2026] [security2:error] [pid 123784:tid 124023] [client 68.221.73.131:32055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/file1221.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8QAAAGk"] [Tue Aug 18 13:00:10.355455 2026] [security2:error] [pid 123784:tid 123965] [client 40.74.65.169:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBimwDnJBNj2tDbYbx8gAAAC8"] [Tue Aug 18 13:00:10.398684 2026] [security2:error] [pid 123784:tid 123870] [remote 74.248.18.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alsconsultoria.com.br"] [uri "/php.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9AAADVE"] [Tue Aug 18 13:00:10.417882 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:27553] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9QAAAEg"] [Tue Aug 18 13:00:10.417997 2026] [security2:error] [pid 123784:tid 123990] [client 4.232.94.69:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9QAAAEg"] [Tue Aug 18 13:00:10.420009 2026] [security2:error] [pid 123784:tid 124011] [client 20.203.138.185:32253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/x7.php"] [unique_id "aoSBimwDnJBNj2tDbYbx9gAAAF0"] [Tue Aug 18 13:00:10.423881 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uo.php"] [unique_id "aoSBimwDnJBNj2tDbYbx-AAAABc"] [Tue Aug 18 13:00:10.443382 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:10.443645 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:10.452407 2026] [security2:error] [pid 123784:tid 124045] [client 20.127.136.245:28047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/2.php"] [unique_id "aoSBimwDnJBNj2tDbYbx_gAAAH8"] [Tue Aug 18 13:00:10.488478 2026] [authz_core:error] [pid 123784:tid 123813] [remote 57.141.22.49:20090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:10.488766 2026] [authz_core:error] [pid 123784:tid 123813] [remote 57.141.22.49:20090] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:10.510126 2026] [security2:error] [pid 123784:tid 123913] [remote 212.29.237.5:38564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSBimwDnJBNj2tDbYbyAAAAU3w"] [Tue Aug 18 13:00:10.513149 2026] [security2:error] [pid 123784:tid 123993] [client 20.116.17.175:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/zxz.php"] [unique_id "aoSBimwDnJBNj2tDbYbyAwAAAEs"] [Tue Aug 18 13:00:10.517406 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:21182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kx.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBAAAAFA"] [Tue Aug 18 13:00:10.532659 2026] [security2:error] [pid 123784:tid 123923] [client 20.226.56.190:42466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/va.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBQAAAAU"] [Tue Aug 18 13:00:10.534544 2026] [security2:error] [pid 123784:tid 124003] [client 168.62.48.100:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/yxijx.php"] [unique_id "aoSBimwDnJBNj2tDbYbyBgAAAFU"] [Tue Aug 18 13:00:10.547717 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:18127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCQAAAGM"] [Tue Aug 18 13:00:10.573554 2026] [security2:error] [pid 123784:tid 123996] [client 20.226.56.190:15182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fo.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCgAAAE4"] [Tue Aug 18 13:00:10.575046 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file52.php"] [unique_id "aoSBimwDnJBNj2tDbYbyCwAAAFw"] [Tue Aug 18 13:00:10.584518 2026] [security2:error] [pid 123784:tid 123963] [client 20.226.56.190:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/loading.php"] [unique_id "aoSBimwDnJBNj2tDbYbyDwAAAC0"] [Tue Aug 18 13:00:10.647870 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.154.236:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbyIQAAAH0"] [Tue Aug 18 13:00:10.672500 2026] [security2:error] [pid 123784:tid 123947] [client 172.202.39.151:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBimwDnJBNj2tDbYbyKQAAAB0"] [Tue Aug 18 13:00:10.683487 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:16187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/test.php"] [unique_id "aoSBimwDnJBNj2tDbYbyKgAAAGs"] [Tue Aug 18 13:00:10.729396 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.156.252:10110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/images.php"] [unique_id "aoSBimwDnJBNj2tDbYbyLAAAACA"] [Tue Aug 18 13:00:10.731047 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:40436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pz.php"] [unique_id "aoSBimwDnJBNj2tDbYbyLQAAAHY"] [Tue Aug 18 13:00:10.744899 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:10.745163 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:10.818666 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/pucci.php"] [unique_id "aoSBimwDnJBNj2tDbYbyMwAAXiQ"] [Tue Aug 18 13:00:10.835401 2026] [security2:error] [pid 123784:tid 123988] [client 168.62.48.100:18085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNAAAAEY"] [Tue Aug 18 13:00:10.845449 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNQAAABY"] [Tue Aug 18 13:00:10.846814 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNgAAAFg"] [Tue Aug 18 13:00:10.871784 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:21167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ke.php"] [unique_id "aoSBimwDnJBNj2tDbYbyNwAAAFs"] [Tue Aug 18 13:00:10.900208 2026] [security2:error] [pid 123784:tid 123957] [client 223.185.37.47:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOAAAACc"] [Tue Aug 18 13:00:10.900372 2026] [security2:error] [pid 123784:tid 123957] [client 223.185.37.47:30107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOAAAACc"] [Tue Aug 18 13:00:10.901971 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sn.php"] [unique_id "aoSBimwDnJBNj2tDbYbyOQAAAEc"] [Tue Aug 18 13:00:10.950789 2026] [security2:error] [pid 123784:tid 123991] [client 20.127.136.245:28068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBimwDnJBNj2tDbYbyPwAAAEk"] [Tue Aug 18 13:00:11.012454 2026] [security2:error] [pid 123784:tid 123919] [client 190.92.174.183:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQgAAAAE"] [Tue Aug 18 13:00:11.012545 2026] [security2:error] [pid 123784:tid 123919] [client 190.92.174.183:50524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQgAAAAE"] [Tue Aug 18 13:00:11.013063 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/inputs.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyQwAAABI"] [Tue Aug 18 13:00:11.031984 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.27.191:27977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/geck.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyRAAAAH8"] [Tue Aug 18 13:00:11.044325 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyRwAAAFk"] [Tue Aug 18 13:00:11.048078 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:11.048506 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:11.049549 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/87.php"] [unique_id "aoSBi2wDnJBNj2tDbYbySAAAAFc"] [Tue Aug 18 13:00:11.089139 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:18156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBi2wDnJBNj2tDbYbySQAAAHA"] [Tue Aug 18 13:00:11.108295 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:20901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nh.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyTwAAAGM"] [Tue Aug 18 13:00:11.124511 2026] [security2:error] [pid 123784:tid 123962] [client 20.116.17.175:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/aa.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyUQAAACw"] [Tue Aug 18 13:00:11.137185 2026] [security2:error] [pid 123784:tid 123958] [client 172.202.39.151:4706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/k.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyUgAAACg"] [Tue Aug 18 13:00:11.146824 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:41125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/flower.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyVAAAAFw"] [Tue Aug 18 13:00:11.212875 2026] [security2:error] [pid 123784:tid 124039] [client 68.221.73.131:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/nox.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyaAAAAHk"] [Tue Aug 18 13:00:11.330118 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:40172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/oo.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycAAAAGs"] [Tue Aug 18 13:00:11.332258 2026] [security2:error] [pid 123784:tid 123998] [client 158.158.74.177:3877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/test1.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycQAAAFA"] [Tue Aug 18 13:00:11.341951 2026] [security2:error] [pid 123784:tid 123990] [client 213.35.127.232:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBi2wDnJBNj2tDbYbycwAAAEg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:11.350807 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:11.351239 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:11.351332 2026] [security2:error] [pid 123784:tid 123982] [client 168.62.48.100:18101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBi2wDnJBNj2tDbYbydAAAAEA"] [Tue Aug 18 13:00:11.360642 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.154.236:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBi2wDnJBNj2tDbYbydQAAAB8"] [Tue Aug 18 13:00:11.406472 2026] [security2:error] [pid 123784:tid 124033] [client 20.116.17.175:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/echkm.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyeAAAAHM"] [Tue Aug 18 13:00:11.425213 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/atomlib.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyegAAABs"] [Tue Aug 18 13:00:11.447941 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.27.191:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/biufile.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyewAAABY"] [Tue Aug 18 13:00:11.453223 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/222.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyfAAAAFg"] [Tue Aug 18 13:00:11.453943 2026] [security2:error] [pid 123784:tid 123995] [client 20.79.204.6:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/abcd.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyfQAAAE0"] [Tue Aug 18 13:00:11.461251 2026] [security2:error] [pid 123784:tid 123981] [client 4.232.94.69:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSBi2wDnJBNj2tDbYbygAAAAD8"] [Tue Aug 18 13:00:11.521020 2026] [security2:error] [pid 123784:tid 124023] [client 138.199.60.10:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "jgbdominiosolucoes.com.br"] [uri "/"] [unique_id "aoSBi2wDnJBNj2tDbYbyggAAAGk"] [Tue Aug 18 13:00:11.545369 2026] [security2:error] [pid 123784:tid 124004] [client 20.203.138.185:42436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/god.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyhgAAAFY"] [Tue Aug 18 13:00:11.575515 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:15220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ja.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyigAAAF0"] [Tue Aug 18 13:00:11.602546 2026] [security2:error] [pid 123784:tid 123932] [client 168.62.48.100:18095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyiwAAAA4"] [Tue Aug 18 13:00:11.671616 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.56.190:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xx.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyjQAAAEs"] [Tue Aug 18 13:00:11.696113 2026] [security2:error] [pid 123784:tid 123923] [client 20.116.17.175:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/domvf.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyjwAAAAU"] [Tue Aug 18 13:00:11.696672 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/conn-test.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykAAAACw"] [Tue Aug 18 13:00:11.708562 2026] [security2:error] [pid 123784:tid 123918] [client 20.226.56.190:7302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fg.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykQAAAAA"] [Tue Aug 18 13:00:11.727643 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:21153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ve.php"] [unique_id "aoSBi2wDnJBNj2tDbYbykwAAAHI"] [Tue Aug 18 13:00:11.733498 2026] [security2:error] [pid 123784:tid 124024] [client 40.74.65.169:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/av.php"] [unique_id "aoSBi2wDnJBNj2tDbYbylQAAAGo"] [Tue Aug 18 13:00:11.746029 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.156.252:15667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/ops.php"] [unique_id "aoSBi2wDnJBNj2tDbYbylwAAACI"] [Tue Aug 18 13:00:11.746695 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:63024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kk.php"] [unique_id "aoSBi2wDnJBNj2tDbYbymAAAAAM"] [Tue Aug 18 13:00:11.779496 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:38323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kf.php"] [unique_id "aoSBi2wDnJBNj2tDbYbymgAAADk"] [Tue Aug 18 13:00:11.812678 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ia.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyngAAACE"] [Tue Aug 18 13:00:11.841307 2026] [security2:error] [pid 123784:tid 123998] [client 68.155.154.236:25350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/well-known/index.php"] [unique_id "aoSBi2wDnJBNj2tDbYbynwAAAFA"] [Tue Aug 18 13:00:11.849104 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:47927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zi.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyoAAAAEg"] [Tue Aug 18 13:00:11.862834 2026] [security2:error] [pid 123784:tid 123949] [client 168.62.48.100:18054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyoQAAAB8"] [Tue Aug 18 13:00:11.887103 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.27.191:34829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dejavu.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyogAAADc"] [Tue Aug 18 13:00:11.898102 2026] [security2:error] [pid 123784:tid 124039] [client 20.127.136.245:28074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/rip.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyowAAAHk"] [Tue Aug 18 13:00:11.950618 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:11.951048 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:11.952067 2026] [security2:error] [pid 123784:tid 123959] [client 158.158.74.177:3860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/text.php"] [unique_id "aoSBi2wDnJBNj2tDbYbypgAAACk"] [Tue Aug 18 13:00:11.958430 2026] [security2:error] [pid 123784:tid 123965] [client 20.250.13.23:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/simple.php"] [unique_id "aoSBi2wDnJBNj2tDbYbypwAAAC8"] [Tue Aug 18 13:00:11.972447 2026] [security2:error] [pid 123784:tid 123968] [client 74.7.244.10:60068] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.old.useemede.com.br"] [uri "/index.php"] [unique_id "aoSBiWwDnJBNj2tDbYbxxgAAMkI"] [Tue Aug 18 13:00:11.977395 2026] [security2:error] [pid 123784:tid 123810] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-temp.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyqgAATRU"] [Tue Aug 18 13:00:11.990209 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/red.php"] [unique_id "aoSBi2wDnJBNj2tDbYbyqwAAAEQ"] [Tue Aug 18 13:00:12.021782 2026] [security2:error] [pid 123784:tid 123972] [client 132.196.30.78:14600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/ww5.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyrQAAADY"] [Tue Aug 18 13:00:12.056592 2026] [security2:error] [pid 123784:tid 123982] [client 20.79.204.6:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/kj.php"] [unique_id "aoSBjGwDnJBNj2tDbYbysAAAAEA"] [Tue Aug 18 13:00:12.098459 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:15191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kn.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytQAAAFQ"] [Tue Aug 18 13:00:12.129631 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytwAAADw"] [Tue Aug 18 13:00:12.129793 2026] [security2:error] [pid 123784:tid 123978] [client 190.92.174.183:50540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbytwAAADw"] [Tue Aug 18 13:00:12.142815 2026] [security2:error] [pid 123784:tid 124008] [client 168.62.48.100:18129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuAAAAFo"] [Tue Aug 18 13:00:12.170191 2026] [security2:error] [pid 123784:tid 123853] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuQAAZUA"] [Tue Aug 18 13:00:12.170438 2026] [security2:error] [pid 123784:tid 124019] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyuQAAZUA"] [Tue Aug 18 13:00:12.228236 2026] [security2:error] [pid 123784:tid 123937] [client 68.155.154.236:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBjGwDnJBNj2tDbYbywAAAABM"] [Tue Aug 18 13:00:12.250002 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:12.250262 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:12.263546 2026] [security2:error] [pid 123784:tid 123987] [client 20.116.17.175:60444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxAAAAEU"] [Tue Aug 18 13:00:12.267144 2026] [security2:error] [pid 123784:tid 123939] [client 20.79.204.6:10738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/admin.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxQAAABU"] [Tue Aug 18 13:00:12.297091 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.27.191:27974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aaf.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxgAAAD4"] [Tue Aug 18 13:00:12.327625 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/43.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyxwAAAAo"] [Tue Aug 18 13:00:12.350774 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/p.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyyAAAAAA"] [Tue Aug 18 13:00:12.357069 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyyQAAAAI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:12.387564 2026] [security2:error] [pid 123784:tid 123897] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyywAAdGw"] [Tue Aug 18 13:00:12.396217 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.56.190:21142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wm.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzAAAAB8"] [Tue Aug 18 13:00:12.416822 2026] [security2:error] [pid 123784:tid 124013] [client 40.74.65.169:60230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/media.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzQAAAF8"] [Tue Aug 18 13:00:12.447507 2026] [security2:error] [pid 123784:tid 123959] [client 68.155.156.252:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/coffexium.php"] [unique_id "aoSBjGwDnJBNj2tDbYbyzwAAACk"] [Tue Aug 18 13:00:12.468492 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBjGwDnJBNj2tDbYby0AAAAA8"] [Tue Aug 18 13:00:12.470896 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:18115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBjGwDnJBNj2tDbYby0QAAABY"] [Tue Aug 18 13:00:12.510156 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ac.php"] [unique_id "aoSBjGwDnJBNj2tDbYby1AAAAEE"] [Tue Aug 18 13:00:12.553020 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:12.553280 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:12.562925 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/92.php"] [unique_id "aoSBjGwDnJBNj2tDbYby1wAAADY"] [Tue Aug 18 13:00:12.575837 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.154.236:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYby2AAAACA"] [Tue Aug 18 13:00:12.580542 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBjGwDnJBNj2tDbYby2QAAAE8"] [Tue Aug 18 13:00:12.609854 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:40133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yz.php"] [unique_id "aoSBjGwDnJBNj2tDbYby3gAAAEA"] [Tue Aug 18 13:00:12.640635 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kj.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4AAAAA0"] [Tue Aug 18 13:00:12.653273 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4QAAAGs"] [Tue Aug 18 13:00:12.663033 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/languages.php"] [unique_id "aoSBjGwDnJBNj2tDbYby4gAAABE"] [Tue Aug 18 13:00:12.668269 2026] [security2:error] [pid 123784:tid 123905] [remote 47.89.174.181:33496] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.api.devota.com.br"] [uri "/.env"] [unique_id "aoSBjGwDnJBNj2tDbYby5QAAYXQ"] [Tue Aug 18 13:00:12.676421 2026] [security2:error] [pid 123784:tid 124026] [client 132.196.30.78:16184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/2.php"] [unique_id "aoSBjGwDnJBNj2tDbYby5gAAAGw"] [Tue Aug 18 13:00:12.690595 2026] [security2:error] [pid 123784:tid 123984] [client 20.203.138.185:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6AAAAEI"] [Tue Aug 18 13:00:12.704263 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.27.191:63168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6gAAACg"] [Tue Aug 18 13:00:12.706164 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:21156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vg.php"] [unique_id "aoSBjGwDnJBNj2tDbYby6wAAAFQ"] [Tue Aug 18 13:00:12.719906 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:21176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sm.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7AAAAFw"] [Tue Aug 18 13:00:12.735306 2026] [security2:error] [pid 123784:tid 123978] [client 172.202.39.151:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/403.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7QAAADw"] [Tue Aug 18 13:00:12.747165 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.56.190:7322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/28.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7gAAAHA"] [Tue Aug 18 13:00:12.761705 2026] [security2:error] [pid 123784:tid 124040] [client 20.226.56.190:11589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/m.php"] [unique_id "aoSBjGwDnJBNj2tDbYby7wAAAHo"] [Tue Aug 18 13:00:12.769694 2026] [security2:error] [pid 123784:tid 123981] [client 74.7.244.10:60078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "old.useemede.com.br"] [uri "/index.php"] [unique_id "aoSBjGwDnJBNj2tDbYby3wAAPwI"], referer: https://www.old.useemede.com.br/robots.txt [Tue Aug 18 13:00:12.780394 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nl.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8AAAAGg"] [Tue Aug 18 13:00:12.817023 2026] [security2:error] [pid 123784:tid 123953] [client 168.62.48.100:18074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8QAAACM"] [Tue Aug 18 13:00:12.826600 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:20904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/68.php"] [unique_id "aoSBjGwDnJBNj2tDbYby8gAAAEM"] [Tue Aug 18 13:00:12.852570 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:12.852832 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:12.866457 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:60437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBjGwDnJBNj2tDbYby9QAAAAQ"] [Tue Aug 18 13:00:12.873963 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/zwlsv.php"] [unique_id "aoSBjGwDnJBNj2tDbYby9wAAAGI"] [Tue Aug 18 13:00:12.877941 2026] [security2:error] [pid 123784:tid 124033] [client 20.127.136.245:28543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cma-rj.org.br"] [uri "/php.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-QAAAHM"] [Tue Aug 18 13:00:12.878333 2026] [security2:error] [pid 123784:tid 123951] [client 4.232.94.69:32031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-gAAACE"] [Tue Aug 18 13:00:12.881110 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:31923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/su.php"] [unique_id "aoSBjGwDnJBNj2tDbYby-wAAAEc"] [Tue Aug 18 13:00:12.913293 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jl.php"] [unique_id "aoSBjGwDnJBNj2tDbYby_QAAAEg"] [Tue Aug 18 13:00:12.919981 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:10994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fresh.php"] [unique_id "aoSBjGwDnJBNj2tDbYby_wAAADk"] [Tue Aug 18 13:00:12.925745 2026] [security2:error] [pid 123784:tid 123974] [client 68.155.154.236:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAAAAADg"] [Tue Aug 18 13:00:12.968250 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tq.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAgAAAF8"] [Tue Aug 18 13:00:12.972556 2026] [security2:error] [pid 123784:tid 123913] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/puc.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzAwAAMHw"] [Tue Aug 18 13:00:12.988069 2026] [security2:error] [pid 123784:tid 123940] [client 172.202.39.151:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/13.php"] [unique_id "aoSBjGwDnJBNj2tDbYbzBAAAABY"] [Tue Aug 18 13:00:13.041737 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:40179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/cv.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBQAAAEo"] [Tue Aug 18 13:00:13.067947 2026] [security2:error] [pid 123784:tid 124014] [client 168.62.48.100:18023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBgAAAGA"] [Tue Aug 18 13:00:13.078777 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:10576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/un.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzBwAAACc"] [Tue Aug 18 13:00:13.104746 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:11609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/evil.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDAAAAB4"] [Tue Aug 18 13:00:13.109173 2026] [security2:error] [pid 123784:tid 124042] [client 20.250.27.191:43505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/155.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDQAAAHw"] [Tue Aug 18 13:00:13.133105 2026] [security2:error] [pid 123784:tid 123935] [client 40.74.65.169:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/images.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzDwAAABE"] [Tue Aug 18 13:00:13.148453 2026] [security2:error] [pid 123784:tid 124011] [client 20.116.17.175:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzEQAAAF0"] [Tue Aug 18 13:00:13.150488 2026] [security2:error] [pid 123784:tid 123984] [client 20.226.56.190:11617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pw.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzEwAAAEI"] [Tue Aug 18 13:00:13.155313 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:13.155602 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:13.162393 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:10575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fn.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFAAAAEY"] [Tue Aug 18 13:00:13.181366 2026] [security2:error] [pid 123784:tid 124002] [client 20.226.56.190:8282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kf.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFQAAAFQ"] [Tue Aug 18 13:00:13.192585 2026] [security2:error] [pid 123784:tid 123995] [client 20.118.133.132:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ano.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFgAAAE0"] [Tue Aug 18 13:00:13.193474 2026] [security2:error] [pid 123784:tid 124033] [client 190.92.174.183:50542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFwAAAHM"] [Tue Aug 18 13:00:13.193559 2026] [security2:error] [pid 123784:tid 124033] [client 190.92.174.183:50542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "viaduplaseguros.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzFwAAAHM"] [Tue Aug 18 13:00:13.201421 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:15206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/su.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzGAAAAFw"] [Tue Aug 18 13:00:13.217533 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.56.190:10601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-key.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzGgAAAGQ"] [Tue Aug 18 13:00:13.245337 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jm.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHAAAAFM"] [Tue Aug 18 13:00:13.268321 2026] [security2:error] [pid 123784:tid 124008] [client 172.202.39.151:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/gecko.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHQAAAFo"] [Tue Aug 18 13:00:13.275088 2026] [security2:error] [pid 123784:tid 124020] [client 158.158.74.177:3864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/u.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHgAAAGY"] [Tue Aug 18 13:00:13.277074 2026] [security2:error] [pid 123784:tid 123790] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHwAAGwE"] [Tue Aug 18 13:00:13.277222 2026] [security2:error] [pid 123784:tid 123945] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzHwAAGwE"] [Tue Aug 18 13:00:13.285511 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzIgAAAHA"] [Tue Aug 18 13:00:13.287542 2026] [security2:error] [pid 123784:tid 124025] [client 132.196.30.78:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzJAAAAGs"] [Tue Aug 18 13:00:13.298296 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:15203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzJgAAAGU"] [Tue Aug 18 13:00:13.357357 2026] [security2:error] [pid 123784:tid 123999] [client 168.62.48.100:18145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzKQAAAFE"] [Tue Aug 18 13:00:13.379209 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzKwAAAEE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:13.380605 2026] [security2:error] [pid 123784:tid 124024] [client 68.155.154.236:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/mt/byp.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLAAAAGo"] [Tue Aug 18 13:00:13.414428 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.56.190:42472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gi.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLQAAADo"] [Tue Aug 18 13:00:13.457228 2026] [security2:error] [pid 123784:tid 124043] [client 20.116.17.175:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/output.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzLwAAAH0"] [Tue Aug 18 13:00:13.474228 2026] [security2:error] [pid 123784:tid 124021] [client 20.203.138.185:32526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/8.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMAAAAGc"] [Tue Aug 18 13:00:13.481693 2026] [security2:error] [pid 123784:tid 123989] [client 20.79.204.6:14017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/nw.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMQAAAEc"] [Tue Aug 18 13:00:13.533547 2026] [security2:error] [pid 123784:tid 123990] [client 68.155.156.252:40740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzMgAAAEg"] [Tue Aug 18 13:00:13.564459 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:8259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pz.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzNAAAADk"] [Tue Aug 18 13:00:13.595417 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.27.191:45799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ops.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzNgAAAHk"] [Tue Aug 18 13:00:13.625594 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:18118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOAAAABY"] [Tue Aug 18 13:00:13.637707 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.56.190:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kk.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOQAAAG0"] [Tue Aug 18 13:00:13.650956 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wp-key.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzOwAAAEo"] [Tue Aug 18 13:00:13.652953 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzPAAAAEQ"] [Tue Aug 18 13:00:13.680338 2026] [security2:error] [pid 123784:tid 123939] [client 79.127.164.8:56770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/users.bak"] [unique_id "aoSBjWwDnJBNj2tDbYbzPQAAABU"], referer: https://medihub.com.br/users.bak [Tue Aug 18 13:00:13.684467 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/8.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzPgAAe0E"] [Tue Aug 18 13:00:13.714371 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dg.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQAAAAA0"] [Tue Aug 18 13:00:13.715167 2026] [security2:error] [pid 123784:tid 123960] [client 135.225.78.186:48113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/sf.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQQAAACo"] [Tue Aug 18 13:00:13.727169 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bm.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQgAAAFY"] [Tue Aug 18 13:00:13.737458 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:40182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vu.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzQwAAAF0"] [Tue Aug 18 13:00:13.737518 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/tiny2.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRAAAAEI"] [Tue Aug 18 13:00:13.740217 2026] [security2:error] [pid 123784:tid 123918] [client 4.232.94.69:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/aaa.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRQAAAAA"] [Tue Aug 18 13:00:13.742635 2026] [security2:error] [pid 123784:tid 123936] [client 172.202.39.151:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/gecko.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzRgAAABI"] [Tue Aug 18 13:00:13.757537 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:13.757807 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:13.779479 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:63640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gj.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSQAAAEY"] [Tue Aug 18 13:00:13.793921 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.154.236:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSgAAAHg"] [Tue Aug 18 13:00:13.800668 2026] [security2:error] [pid 123784:tid 124015] [client 192.141.172.134:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSwAAAGE"] [Tue Aug 18 13:00:13.800848 2026] [security2:error] [pid 123784:tid 124015] [client 192.141.172.134:56867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzSwAAAGE"] [Tue Aug 18 13:00:13.829143 2026] [security2:error] [pid 123784:tid 124033] [client 40.74.65.169:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzTAAAAHM"] [Tue Aug 18 13:00:13.834788 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.56.190:21161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ic.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzTwAAAFw"] [Tue Aug 18 13:00:13.853852 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.56.190:42489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ue.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUAAAAGQ"] [Tue Aug 18 13:00:13.861525 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:18112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUQAAABo"] [Tue Aug 18 13:00:13.871586 2026] [security2:error] [pid 123784:tid 123978] [client 20.226.56.190:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lr.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUgAAADw"] [Tue Aug 18 13:00:13.893183 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:15219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ka.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzUwAAAFc"] [Tue Aug 18 13:00:13.901541 2026] [security2:error] [pid 123784:tid 123977] [client 158.158.74.177:3853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/updates.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVQAAADs"] [Tue Aug 18 13:00:13.925099 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.56.190:8303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ot.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVgAAAC4"] [Tue Aug 18 13:00:13.962498 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ih.php"] [unique_id "aoSBjWwDnJBNj2tDbYbzVwAAAGU"] [Tue Aug 18 13:00:14.006682 2026] [security2:error] [pid 123784:tid 123896] [remote 20.196.200.88:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.paypix.co"] [uri "/1.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWAAAaGs"] [Tue Aug 18 13:00:14.006823 2026] [security2:error] [pid 123784:tid 123896] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/1.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWAAAaGs"] [Tue Aug 18 13:00:14.041541 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wpxml.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzWgAAACM"] [Tue Aug 18 13:00:14.057869 2026] [security2:error] [pid 123784:tid 124002] [client 132.196.30.78:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/atomlib.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXAAAAFQ"] [Tue Aug 18 13:00:14.061411 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:14.061817 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:14.072238 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.56.190:21173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXQAAAEM"] [Tue Aug 18 13:00:14.086140 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:15162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wj.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXgAAADo"] [Tue Aug 18 13:00:14.088238 2026] [security2:error] [pid 123784:tid 124020] [client 20.79.204.6:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzXwAAAGY"] [Tue Aug 18 13:00:14.099355 2026] [security2:error] [pid 123784:tid 123926] [client 168.62.48.100:18064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYAAAAAg"] [Tue Aug 18 13:00:14.111509 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:40133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/mac.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYQAAAFI"] [Tue Aug 18 13:00:14.139179 2026] [security2:error] [pid 123784:tid 123922] [client 158.23.17.4:34131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gg.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzYgAAAAQ"] [Tue Aug 18 13:00:14.187395 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:40323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/aa.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZQAAACE"] [Tue Aug 18 13:00:14.187427 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:62988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/bm.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZgAAAD4"] [Tue Aug 18 13:00:14.197191 2026] [security2:error] [pid 123784:tid 124007] [client 20.250.13.23:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/edit-tags.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzZwAAAFk"] [Tue Aug 18 13:00:14.222443 2026] [security2:error] [pid 123784:tid 123974] [client 196.12.128.158:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaAAAADg"] [Tue Aug 18 13:00:14.222587 2026] [security2:error] [pid 123784:tid 123974] [client 196.12.128.158:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaAAAADg"] [Tue Aug 18 13:00:14.223133 2026] [security2:error] [pid 123784:tid 123800] [remote 162.214.205.212:38440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzaQAALws"] [Tue Aug 18 13:00:14.299664 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.154.236:25385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzbgAAAAs"] [Tue Aug 18 13:00:14.351938 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcAAAABY"] [Tue Aug 18 13:00:14.361362 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:8284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iu.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcgAAAAY"] [Tue Aug 18 13:00:14.364717 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:14.365174 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:14.387020 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/about.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzcwAASn4"] [Tue Aug 18 13:00:14.388660 2026] [security2:error] [pid 123784:tid 123986] [client 68.155.156.252:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdAAAAEQ"] [Tue Aug 18 13:00:14.396119 2026] [security2:error] [pid 123784:tid 123993] [client 213.35.127.232:56804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdQAAAEs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:14.406575 2026] [security2:error] [pid 123784:tid 123957] [client 168.62.48.100:18128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzdgAAACc"] [Tue Aug 18 13:00:14.412429 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pd.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzeAAAAHs"] [Tue Aug 18 13:00:14.508548 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzfAAAAAA"] [Tue Aug 18 13:00:14.526379 2026] [security2:error] [pid 123784:tid 123927] [client 158.158.74.177:16132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzfgAAAAk"] [Tue Aug 18 13:00:14.629915 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ccou.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzgAAAAGQ"] [Tue Aug 18 13:00:14.636880 2026] [security2:error] [pid 123784:tid 123944] [client 20.203.138.185:32216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/koiy.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzgQAAABo"] [Tue Aug 18 13:00:14.650774 2026] [security2:error] [pid 123784:tid 123960] [client 132.196.30.78:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/rip.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzggAAACo"] [Tue Aug 18 13:00:14.661528 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:14.661802 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:14.695340 2026] [security2:error] [pid 123784:tid 124008] [client 68.155.154.236:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhQAAAFo"] [Tue Aug 18 13:00:14.710734 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhgAAYAw"] [Tue Aug 18 13:00:14.723147 2026] [security2:error] [pid 123784:tid 123945] [client 168.62.48.100:18097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzhwAAABs"] [Tue Aug 18 13:00:14.723181 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pk.php"] [unique_id "aoSBjmwDnJBNj2tDbYbziAAAAFc"] [Tue Aug 18 13:00:14.742278 2026] [autoindex:error] [pid 123784:tid 123988] [client 20.79.204.6:14138] AH01276: Cannot serve directory /home4/soraya/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:14.768460 2026] [security2:error] [pid 123784:tid 124024] [client 197.184.64.235:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjQAAAGo"] [Tue Aug 18 13:00:14.768562 2026] [security2:error] [pid 123784:tid 124024] [client 197.184.64.235:41954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjQAAAGo"] [Tue Aug 18 13:00:14.788019 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:11438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vu.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzjwAAAGg"] [Tue Aug 18 13:00:14.818710 2026] [security2:error] [pid 123784:tid 123934] [client 68.155.156.252:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzkQAAABA"] [Tue Aug 18 13:00:14.869687 2026] [security2:error] [pid 123784:tid 123942] [client 20.65.98.162:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mac.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzlQAAABg"] [Tue Aug 18 13:00:14.910918 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/crgio.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmAAAAD4"] [Tue Aug 18 13:00:14.928830 2026] [security2:error] [pid 123784:tid 123958] [client 20.226.56.190:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ge.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmQAAACg"] [Tue Aug 18 13:00:14.947236 2026] [security2:error] [pid 123784:tid 123989] [client 20.79.204.6:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmgAAAEc"] [Tue Aug 18 13:00:14.953131 2026] [security2:error] [pid 123784:tid 124012] [client 172.202.39.151:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/0x.php"] [unique_id "aoSBjmwDnJBNj2tDbYbzmwAAAF4"] [Tue Aug 18 13:00:14.955525 2026] [security2:error] [pid 123784:tid 123974] [client 20.250.27.191:43495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBjmwDnJBNj2tDbYbznQAAADg"] [Tue Aug 18 13:00:14.962068 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:14.962364 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:15.035282 2026] [security2:error] [pid 123784:tid 124039] [client 20.226.56.190:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kl.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzoQAAAHk"] [Tue Aug 18 13:00:15.041071 2026] [security2:error] [pid 123784:tid 123809] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/edit.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzogAAbxQ"] [Tue Aug 18 13:00:15.053895 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:20902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzpQAAAEQ"] [Tue Aug 18 13:00:15.059266 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:18075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzpgAAAEs"] [Tue Aug 18 13:00:15.100252 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/74.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzqgAAABU"] [Tue Aug 18 13:00:15.101662 2026] [security2:error] [pid 123784:tid 124031] [client 20.226.56.190:42433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lw.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzqwAAAHE"] [Tue Aug 18 13:00:15.114187 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/aa.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrAAAAEE"] [Tue Aug 18 13:00:15.116878 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vj.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrQAAAAM"] [Tue Aug 18 13:00:15.162156 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:10567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mimes.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrgAAAFY"] [Tue Aug 18 13:00:15.165091 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:29489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/th.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzrwAAABE"] [Tue Aug 18 13:00:15.175076 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sorayasalloum.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzsAAAAC8"] [Tue Aug 18 13:00:15.186792 2026] [security2:error] [pid 123784:tid 123954] [client 40.74.65.169:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mac.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzsgAAACQ"] [Tue Aug 18 13:00:15.188000 2026] [security2:error] [pid 123784:tid 124026] [client 20.116.17.175:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzswAAAGw"] [Tue Aug 18 13:00:15.193913 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:11629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ni.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztAAAAH8"] [Tue Aug 18 13:00:15.217518 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:17923] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztQAAABI"] [Tue Aug 18 13:00:15.217615 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:17923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztQAAABI"] [Tue Aug 18 13:00:15.219031 2026] [security2:error] [pid 123784:tid 123996] [client 68.155.156.252:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/media.php"] [unique_id "aoSBj2wDnJBNj2tDbYbztgAAAE4"] [Tue Aug 18 13:00:15.256594 2026] [security2:error] [pid 123784:tid 124033] [client 68.155.156.252:40953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/sf.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuAAAAHM"] [Tue Aug 18 13:00:15.262363 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:15.262512 2026] [security2:error] [pid 123784:tid 124021] [client 190.92.174.183:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viaduplaseguros.com.br"] [uri "/wp-login.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuQAAAGc"] [Tue Aug 18 13:00:15.262613 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:15.277906 2026] [security2:error] [pid 123784:tid 123946] [client 132.196.30.78:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/p.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzuwAAABw"] [Tue Aug 18 13:00:15.283076 2026] [security2:error] [pid 123784:tid 123978] [client 20.226.56.190:8302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/88.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvAAAADw"] [Tue Aug 18 13:00:15.323541 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gi.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvgAAAH0"] [Tue Aug 18 13:00:15.324541 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.56.190:45247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hj.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzvwAAABs"] [Tue Aug 18 13:00:15.354233 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.154.236:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzwgAAAGs"] [Tue Aug 18 13:00:15.356602 2026] [security2:error] [pid 123784:tid 123964] [client 168.62.48.100:17991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzwwAAAC4"] [Tue Aug 18 13:00:15.360098 2026] [security2:error] [pid 123784:tid 124030] [client 20.250.27.191:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxAAAAHA"] [Tue Aug 18 13:00:15.389295 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:40188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ij.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxgAAAHc"] [Tue Aug 18 13:00:15.396763 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.13.23:42700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/u.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzxwAAABM"] [Tue Aug 18 13:00:15.416362 2026] [security2:error] [pid 123784:tid 123968] [client 213.35.127.232:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzyQAAADI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:15.430677 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.56.190:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ud.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzygAAADE"] [Tue Aug 18 13:00:15.466069 2026] [security2:error] [pid 123784:tid 123863] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzywAAZko"] [Tue Aug 18 13:00:15.490872 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.56.190:8292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ip.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzAAAAAQ"] [Tue Aug 18 13:00:15.492526 2026] [security2:error] [pid 123784:tid 123980] [client 20.116.17.175:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/css.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzQAAAD4"] [Tue Aug 18 13:00:15.505114 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/99.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzgAAAEc"] [Tue Aug 18 13:00:15.556993 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:14030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSBj2wDnJBNj2tDbYbzzwAAAEY"] [Tue Aug 18 13:00:15.573348 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.56.190:6364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/er.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz0AAAAE0"] [Tue Aug 18 13:00:15.627682 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:32278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz0wAAAHs"] [Tue Aug 18 13:00:15.639119 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qk.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1AAAAA8"] [Tue Aug 18 13:00:15.641920 2026] [security2:error] [pid 123784:tid 123931] [client 168.62.48.100:18164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1QAAAA0"] [Tue Aug 18 13:00:15.666123 2026] [security2:error] [pid 123784:tid 123966] [client 20.226.56.190:40187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz1gAAADA"] [Tue Aug 18 13:00:15.690615 2026] [authz_core:error] [pid 123784:tid 123901] [remote 57.141.22.13:29544] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:15.690882 2026] [authz_core:error] [pid 123784:tid 123901] [remote 57.141.22.13:29544] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:15.697807 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.56.190:40130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2AAAABE"] [Tue Aug 18 13:00:15.736207 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/zxz.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2QAAADM"] [Tue Aug 18 13:00:15.779064 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:18598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rb.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2gAAAAk"] [Tue Aug 18 13:00:15.783431 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:58170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz2wAAAE4"] [Tue Aug 18 13:00:15.803251 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.154.236:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz3AAAAC0"] [Tue Aug 18 13:00:15.810163 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/admin404.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz3QAAAHM"] [Tue Aug 18 13:00:15.847487 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:57222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pz.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4AAAAGc"] [Tue Aug 18 13:00:15.859337 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/37.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4QAAAEA"] [Tue Aug 18 13:00:15.861643 2026] [security2:error] [pid 123784:tid 124018] [client 40.74.65.169:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ops.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz4gAAAGQ"] [Tue Aug 18 13:00:15.869396 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:15.869648 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:15.888463 2026] [security2:error] [pid 123784:tid 123984] [client 132.196.30.78:9956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.canabarromultimarcas.com.br"] [uri "/php.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz5gAAAEI"] [Tue Aug 18 13:00:15.913160 2026] [security2:error] [pid 123784:tid 123817] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inputs.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6AAAPBw"] [Tue Aug 18 13:00:15.931447 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ic.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6QAAAHI"] [Tue Aug 18 13:00:15.947739 2026] [security2:error] [pid 123784:tid 124014] [client 20.250.27.191:63221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/system_log.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6gAAAGA"] [Tue Aug 18 13:00:15.949016 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:42447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/md.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz6wAAAH0"] [Tue Aug 18 13:00:15.961782 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:42451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/iy.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7AAAADs"] [Tue Aug 18 13:00:15.980792 2026] [security2:error] [pid 123784:tid 123961] [client 168.62.48.100:18071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7QAAACs"] [Tue Aug 18 13:00:15.987376 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7gAAAC4"] [Tue Aug 18 13:00:15.991716 2026] [security2:error] [pid 123784:tid 123952] [client 172.202.39.151:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/0x.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz7wAAACI"] [Tue Aug 18 13:00:15.994260 2026] [security2:error] [pid 123784:tid 123971] [client 20.203.138.185:46431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/iko.php"] [unique_id "aoSBj2wDnJBNj2tDbYbz8AAAADU"] [Tue Aug 18 13:00:16.022538 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cc.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz8QAAAHo"] [Tue Aug 18 13:00:16.042122 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:40189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/og.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz8gAAAHc"] [Tue Aug 18 13:00:16.077580 2026] [security2:error] [pid 123784:tid 123967] [client 68.155.156.252:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/mac.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz9gAAADE"] [Tue Aug 18 13:00:16.122173 2026] [security2:error] [pid 123784:tid 123930] [client 20.116.17.175:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/epinyins.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz-AAAAAw"] [Tue Aug 18 13:00:16.149046 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.56.190:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lp.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz-QAAADc"] [Tue Aug 18 13:00:16.161963 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.204.6:14140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/f7.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_AAAABs"] [Tue Aug 18 13:00:16.164483 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.56.190:6367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ey.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_QAAAAQ"] [Tue Aug 18 13:00:16.166275 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:16.166561 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:16.187685 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/av.php"] [unique_id "aoSBkGwDnJBNj2tDbYbz_gAAAEc"] [Tue Aug 18 13:00:16.203135 2026] [security2:error] [pid 123784:tid 123990] [client 20.226.56.190:11622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lv.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AQAAAEg"] [Tue Aug 18 13:00:16.225205 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.56.190:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/51.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AgAAABk"] [Tue Aug 18 13:00:16.258501 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/k.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0AwAAAAI"] [Tue Aug 18 13:00:16.295475 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:40177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ew.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BAAAAFc"] [Tue Aug 18 13:00:16.311101 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/www.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BQAAAHE"] [Tue Aug 18 13:00:16.323520 2026] [security2:error] [pid 123784:tid 123983] [client 168.62.48.100:18174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0BwAAAEE"] [Tue Aug 18 13:00:16.354752 2026] [security2:error] [pid 123784:tid 123849] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/av.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0CgAAHjw"] [Tue Aug 18 13:00:16.391240 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:8269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pqr.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0DgAAAF0"] [Tue Aug 18 13:00:16.401201 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/load.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0DwAAAA4"] [Tue Aug 18 13:00:16.404247 2026] [security2:error] [pid 123784:tid 123981] [client 20.100.169.31:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/0x.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EAAAAD8"] [Tue Aug 18 13:00:16.413820 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qo.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EQAAAAA"] [Tue Aug 18 13:00:16.424126 2026] [security2:error] [pid 123784:tid 124025] [client 86.120.159.145:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EgAAAGs"] [Tue Aug 18 13:00:16.424241 2026] [security2:error] [pid 123784:tid 124025] [client 86.120.159.145:12085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EgAAAGs"] [Tue Aug 18 13:00:16.430495 2026] [security2:error] [pid 123784:tid 123953] [client 213.35.127.232:57236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0EwAAACM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:16.461664 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.56.190:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/an.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FQAAAGw"] [Tue Aug 18 13:00:16.462254 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ue.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FgAAAGk"] [Tue Aug 18 13:00:16.466140 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.156.252:50913] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FwAAABI"] [Tue Aug 18 13:00:16.466213 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.156.252:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0FwAAABI"] [Tue Aug 18 13:00:16.466682 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:16.466948 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:16.487439 2026] [security2:error] [pid 123784:tid 124015] [client 20.226.56.190:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sy.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GAAAAGE"] [Tue Aug 18 13:00:16.538383 2026] [security2:error] [pid 123784:tid 124010] [client 40.74.65.169:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/8.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GgAAAFw"] [Tue Aug 18 13:00:16.540219 2026] [security2:error] [pid 123784:tid 123982] [client 68.155.154.236:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0GwAAAEA"] [Tue Aug 18 13:00:16.556565 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:11627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/57.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0HAAAACo"] [Tue Aug 18 13:00:16.579926 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:34027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kk.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0HwAAAHY"] [Tue Aug 18 13:00:16.605540 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ah.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0IAAAAHI"] [Tue Aug 18 13:00:16.631087 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:13096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vw.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0IQAAAH0"] [Tue Aug 18 13:00:16.663344 2026] [security2:error] [pid 123784:tid 123949] [client 20.250.13.23:39055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JAAAAB8"] [Tue Aug 18 13:00:16.692282 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JgAAACI"] [Tue Aug 18 13:00:16.726461 2026] [security2:error] [pid 123784:tid 123944] [client 168.62.48.100:18058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JwAAABo"] [Tue Aug 18 13:00:16.767367 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:16.767664 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:16.776165 2026] [security2:error] [pid 123784:tid 123984] [client 20.79.204.6:13699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/photo.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0KgAAAEI"] [Tue Aug 18 13:00:16.789104 2026] [security2:error] [pid 123784:tid 123999] [client 20.250.27.191:34838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/pucci.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0KwAAAFE"] [Tue Aug 18 13:00:16.833449 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lj.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LQAAAGY"] [Tue Aug 18 13:00:16.855744 2026] [security2:error] [pid 123784:tid 123893] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/classwithtostring.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LgAAGGg"] [Tue Aug 18 13:00:16.882132 2026] [security2:error] [pid 123784:tid 123945] [client 20.118.133.132:13943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ai.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0LwAAABs"] [Tue Aug 18 13:00:16.909639 2026] [security2:error] [pid 123784:tid 124029] [client 68.155.154.236:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0MgAAAG8"] [Tue Aug 18 13:00:16.919748 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:10734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/goods.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0MwAAAHU"] [Tue Aug 18 13:00:16.929116 2026] [security2:error] [pid 123784:tid 123974] [client 20.226.56.190:15223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kh.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NAAAADg"] [Tue Aug 18 13:00:16.984342 2026] [security2:error] [pid 123784:tid 123988] [client 20.116.17.175:60009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ty.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NgAAAEY"] [Tue Aug 18 13:00:16.992379 2026] [security2:error] [pid 123784:tid 123943] [client 68.155.156.252:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/coffee.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0NwAAABk"] [Tue Aug 18 13:00:16.997363 2026] [security2:error] [pid 123784:tid 123959] [client 168.62.48.100:18120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0OAAAACk"] [Tue Aug 18 13:00:17.001574 2026] [security2:error] [pid 123784:tid 123998] [client 172.202.39.151:44565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wicked.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0OQAAAFA"] [Tue Aug 18 13:00:17.008245 2026] [security2:error] [pid 123784:tid 123958] [client 20.203.138.185:16783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/raw.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0OgAAACg"] [Tue Aug 18 13:00:17.027378 2026] [security2:error] [pid 123784:tid 124002] [client 20.100.169.31:3796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/222.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PAAAAFQ"] [Tue Aug 18 13:00:17.072031 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:17.072286 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:17.072953 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.56.190:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jb.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PgAAAEE"] [Tue Aug 18 13:00:17.127840 2026] [security2:error] [pid 123784:tid 124028] [client 172.202.39.151:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/zxz.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0PwAAAG4"] [Tue Aug 18 13:00:17.164366 2026] [security2:error] [pid 123784:tid 123932] [client 20.226.56.190:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/do.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QQAAAA4"] [Tue Aug 18 13:00:17.176294 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yw.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QgAAAGI"] [Tue Aug 18 13:00:17.202806 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.56.190:20921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/qh.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0QwAAAGw"] [Tue Aug 18 13:00:17.220403 2026] [security2:error] [pid 123784:tid 124044] [client 20.226.56.190:21163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/r.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RQAAAH4"] [Tue Aug 18 13:00:17.235568 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/17.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RgAAAEA"] [Tue Aug 18 13:00:17.235592 2026] [security2:error] [pid 123784:tid 123960] [client 40.74.65.169:60189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/biufile.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0RwAAACo"] [Tue Aug 18 13:00:17.265290 2026] [security2:error] [pid 123784:tid 124031] [client 79.127.164.8:42736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/users.sql"] [unique_id "aoSBkWwDnJBNj2tDbYb0SQAAAHE"], referer: https://medihub.com.br/users.sql [Tue Aug 18 13:00:17.273327 2026] [security2:error] [pid 123784:tid 124043] [client 20.116.17.175:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0SgAAAH0"] [Tue Aug 18 13:00:17.273799 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.154.236:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/first.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0SwAAAHQ"] [Tue Aug 18 13:00:17.284277 2026] [security2:error] [pid 123784:tid 123977] [client 172.202.39.151:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gecko-new.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TAAAADs"] [Tue Aug 18 13:00:17.297631 2026] [security2:error] [pid 123784:tid 123803] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TgAAcA4"] [Tue Aug 18 13:00:17.306680 2026] [security2:error] [pid 123784:tid 123952] [client 168.62.48.100:18108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0TwAAACI"] [Tue Aug 18 13:00:17.312096 2026] [security2:error] [pid 123784:tid 124040] [client 20.226.56.190:21129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ev.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0UAAAAHo"] [Tue Aug 18 13:00:17.328656 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xs.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0UgAAAGM"] [Tue Aug 18 13:00:17.369115 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:17.369504 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:17.383476 2026] [security2:error] [pid 123784:tid 124025] [client 20.79.204.6:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-aa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0WwAAAGs"] [Tue Aug 18 13:00:17.398791 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:11641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XQAAAH8"] [Tue Aug 18 13:00:17.403364 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XgAAACE"] [Tue Aug 18 13:00:17.417247 2026] [security2:error] [pid 123784:tid 123980] [client 68.155.156.252:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0XwAAAD4"] [Tue Aug 18 13:00:17.425215 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.56.190:42461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0YgAAAG8"] [Tue Aug 18 13:00:17.445604 2026] [security2:error] [pid 123784:tid 123948] [client 213.35.127.232:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZAAAAB4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:17.446129 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.56.190:10606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/info2.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZQAAAGU"] [Tue Aug 18 13:00:17.452764 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:40339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZgAAAEY"] [Tue Aug 18 13:00:17.461547 2026] [security2:error] [pid 123784:tid 123959] [client 68.221.73.131:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/akismet.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ZwAAACk"] [Tue Aug 18 13:00:17.489845 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/h.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0egAAADw"] [Tue Aug 18 13:00:17.506062 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:51189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ag.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0fQAAAFQ"] [Tue Aug 18 13:00:17.596105 2026] [security2:error] [pid 123784:tid 124000] [client 20.116.17.175:58147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dot.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0jgAAAFI"] [Tue Aug 18 13:00:17.600057 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.56.190:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sx.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0jwAAAHw"] [Tue Aug 18 13:00:17.605841 2026] [security2:error] [pid 123784:tid 124038] [client 49.13.130.29:7646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBkGwDnJBNj2tDbYb0JQAAAHg"], referer: https://www.saojudas.com.br/ [Tue Aug 18 13:00:17.605913 2026] [security2:error] [pid 123784:tid 123965] [client 128.140.106.114:34940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0WgAAAC8"], referer: https://www.saojudas.com.br [Tue Aug 18 13:00:17.644358 2026] [security2:error] [pid 123784:tid 123928] [client 168.62.48.100:18161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0kgAAAAo"] [Tue Aug 18 13:00:17.644375 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0kwAAAAg"] [Tue Aug 18 13:00:17.651181 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:44826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lAAAADI"] [Tue Aug 18 13:00:17.663624 2026] [security2:error] [pid 123784:tid 124013] [client 20.100.169.31:4026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/aa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lQAAAF8"] [Tue Aug 18 13:00:17.672905 2026] [security2:error] [pid 123784:tid 123920] [client 102.213.179.104:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lgAAAAI"] [Tue Aug 18 13:00:17.673001 2026] [security2:error] [pid 123784:tid 123920] [client 102.213.179.104:62609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lgAAAAI"] [Tue Aug 18 13:00:17.688268 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.56.190:7304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nu.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0lwAAABE"] [Tue Aug 18 13:00:17.738760 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:55171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ops.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mAAAAGI"] [Tue Aug 18 13:00:17.760730 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:42475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ko.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mQAAACQ"] [Tue Aug 18 13:00:17.768696 2026] [security2:error] [pid 123784:tid 123905] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-blog.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0mwAAbHQ"] [Tue Aug 18 13:00:17.769861 2026] [security2:error] [pid 123784:tid 123942] [client 97.74.89.162:35632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "massagemrelax.com"] [uri "/wp-json/batch/v1"] [unique_id "aoSBkWwDnJBNj2tDbYb0mgAAABg"] [Tue Aug 18 13:00:17.796042 2026] [security2:error] [pid 123784:tid 124027] [client 4.232.94.69:17521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/alfa.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0nAAAAG0"] [Tue Aug 18 13:00:17.815077 2026] [security2:error] [pid 123784:tid 124001] [client 68.155.156.252:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0nQAAAFM"] [Tue Aug 18 13:00:17.820044 2026] [security2:error] [pid 123784:tid 124008] [client 135.225.78.186:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/k.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ngAAAFo"] [Tue Aug 18 13:00:17.844605 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:41944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/pl.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0oAAAAH0"] [Tue Aug 18 13:00:17.854994 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.56.190:20909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/env.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0oQAAACs"] [Tue Aug 18 13:00:17.866573 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:21147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mz.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0ogAAADM"] [Tue Aug 18 13:00:17.880364 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.56.190:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ft.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0owAAAHA"] [Tue Aug 18 13:00:17.889448 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:60019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/005.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pAAAAHo"] [Tue Aug 18 13:00:17.894989 2026] [security2:error] [pid 123784:tid 124007] [client 20.226.56.190:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/h.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pQAAAFk"] [Tue Aug 18 13:00:17.909979 2026] [security2:error] [pid 123784:tid 123971] [client 40.74.65.169:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/coffexium.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0pwAAADU"] [Tue Aug 18 13:00:17.919819 2026] [security2:error] [pid 123784:tid 123937] [client 168.62.48.100:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0qAAAABM"] [Tue Aug 18 13:00:17.940505 2026] [fcgid:warn] [pid 123784:tid 123934] (70014)End of file found: [client 199.45.155.87:40250] mod_fcgid: can't get data from http client [Tue Aug 18 13:00:17.971640 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:17.971923 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:17.998609 2026] [security2:error] [pid 123784:tid 124021] [client 20.79.204.6:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/d.php"] [unique_id "aoSBkWwDnJBNj2tDbYb0qwAAAGc"] [Tue Aug 18 13:00:18.037019 2026] [security2:error] [pid 123784:tid 124025] [client 172.202.39.151:44495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0rQAAAGs"] [Tue Aug 18 13:00:18.058288 2026] [security2:error] [pid 123784:tid 123951] [client 68.155.154.236:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0rgAAACE"] [Tue Aug 18 13:00:18.122770 2026] [security2:error] [pid 123784:tid 123948] [client 20.203.138.185:11020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/05.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0sQAAAB4"] [Tue Aug 18 13:00:18.130206 2026] [security2:error] [pid 123784:tid 123988] [client 20.250.27.191:40129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0swAAAEY"] [Tue Aug 18 13:00:18.153359 2026] [security2:error] [pid 123784:tid 123883] [remote 91.86.16.6:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.16.86.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0tAAAKV4"] [Tue Aug 18 13:00:18.154763 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/km.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0tQAAACg"] [Tue Aug 18 13:00:18.172936 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/v2.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0twAAAE0"] [Tue Aug 18 13:00:18.202567 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uAAAAFQ"] [Tue Aug 18 13:00:18.207307 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lr.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uQAAAEQ"] [Tue Aug 18 13:00:18.272078 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:18.272328 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:18.286233 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.156.252:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/yj09.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0uwAAAC8"] [Tue Aug 18 13:00:18.289569 2026] [security2:error] [pid 123784:tid 124037] [client 20.100.169.31:3989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/abcd.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0vwAAAHc"] [Tue Aug 18 13:00:18.347582 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ig.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0wQAAAAA"] [Tue Aug 18 13:00:18.450875 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wkl.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0xgAAABI"] [Tue Aug 18 13:00:18.460422 2026] [security2:error] [pid 123784:tid 124019] [client 213.35.127.232:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0yAAAAGU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:18.483125 2026] [security2:error] [pid 123784:tid 124036] [client 168.62.48.100:17989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0ygAAAHY"] [Tue Aug 18 13:00:18.536833 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0zAAAAGA"] [Tue Aug 18 13:00:18.552514 2026] [security2:error] [pid 123784:tid 123843] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/adminfuns.php"] [unique_id "aoSBkmwDnJBNj2tDbYb0zQAAdDY"] [Tue Aug 18 13:00:18.578707 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:18.579179 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:18.587438 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.27.191:45816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/puc.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00gAAADM"] [Tue Aug 18 13:00:18.594102 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:60182] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00wAAAHA"] [Tue Aug 18 13:00:18.594178 2026] [security2:error] [pid 123784:tid 124030] [client 40.74.65.169:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSBkmwDnJBNj2tDbYb00wAAAHA"] [Tue Aug 18 13:00:18.601158 2026] [security2:error] [pid 123784:tid 124023] [client 20.79.204.6:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01AAAAGk"] [Tue Aug 18 13:00:18.611286 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:44493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cah.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01QAAAHo"] [Tue Aug 18 13:00:18.615924 2026] [security2:error] [pid 123784:tid 123944] [client 68.221.73.131:29026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/admin.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01gAAABo"] [Tue Aug 18 13:00:18.620404 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:38278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dg.php"] [unique_id "aoSBkmwDnJBNj2tDbYb01wAAAGo"] [Tue Aug 18 13:00:18.626049 2026] [security2:error] [pid 123784:tid 123925] [client 20.104.100.201:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02AAAAAc"] [Tue Aug 18 13:00:18.682872 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.156.252:7187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/scxy.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02gAAADU"] [Tue Aug 18 13:00:18.729755 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:53728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content.php.php"] [unique_id "aoSBkmwDnJBNj2tDbYb02wAAABc"] [Tue Aug 18 13:00:18.791598 2026] [security2:error] [pid 123784:tid 123930] [client 168.62.48.100:18016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBkmwDnJBNj2tDbYb03AAAAAw"] [Tue Aug 18 13:00:18.810023 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:59975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBkmwDnJBNj2tDbYb03gAAAAQ"] [Tue Aug 18 13:00:18.842949 2026] [security2:error] [pid 123784:tid 124035] [client 20.203.138.185:16769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/public/hi.php"] [unique_id "aoSBkmwDnJBNj2tDbYb04QAAAHU"] [Tue Aug 18 13:00:18.872588 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:18.872870 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:18.916795 2026] [security2:error] [pid 123784:tid 124018] [client 20.104.100.201:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBkmwDnJBNj2tDbYb05gAAAGQ"] [Tue Aug 18 13:00:18.941491 2026] [security2:error] [pid 123784:tid 123802] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/ms-edit.php"] [unique_id "aoSBkmwDnJBNj2tDbYb05wAAUQ0"] [Tue Aug 18 13:00:18.945858 2026] [security2:error] [pid 123784:tid 124010] [client 20.100.169.31:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/admin.php"] [unique_id "aoSBkmwDnJBNj2tDbYb06AAAAFw"] [Tue Aug 18 13:00:18.964591 2026] [security2:error] [pid 123784:tid 124016] [client 4.232.94.69:14542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSBkmwDnJBNj2tDbYb06wAAAGI"] [Tue Aug 18 13:00:19.040003 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mf.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08QAAAAA"] [Tue Aug 18 13:00:19.066480 2026] [security2:error] [pid 123784:tid 123940] [client 168.62.48.100:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/jrpga.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08gAAABY"] [Tue Aug 18 13:00:19.091919 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.56.190:17982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/40.php"] [unique_id "aoSBk2wDnJBNj2tDbYb08wAAAAY"] [Tue Aug 18 13:00:19.098645 2026] [security2:error] [pid 123784:tid 124028] [client 20.116.17.175:58145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/az.php"] [unique_id "aoSBk2wDnJBNj2tDbYb09QAAAG4"] [Tue Aug 18 13:00:19.116816 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.156.252:39843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBk2wDnJBNj2tDbYb09gAAAAk"] [Tue Aug 18 13:00:19.146831 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:15201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ee.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-AAAACo"] [Tue Aug 18 13:00:19.167970 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:10594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ak.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-QAAAFA"] [Tue Aug 18 13:00:19.207075 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0-wAAAF8"] [Tue Aug 18 13:00:19.215618 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:58729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ta.php"] [unique_id "aoSBk2wDnJBNj2tDbYb0_AAAAHM"] [Tue Aug 18 13:00:19.223311 2026] [security2:error] [pid 123784:tid 123983] [client 85.208.96.204:57770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754458104/1756598400/"] [unique_id "aoSBk2wDnJBNj2tDbYb0_gAAAEE"] [Tue Aug 18 13:00:19.223461 2026] [security2:error] [pid 123784:tid 123983] [client 85.208.96.204:57770] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754458104/1756598400/"] [unique_id "aoSBk2wDnJBNj2tDbYb0_gAAAEE"] [Tue Aug 18 13:00:19.236106 2026] [security2:error] [pid 123784:tid 124040] [client 20.250.27.191:43487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/8.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AAAAAHo"] [Tue Aug 18 13:00:19.268048 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:6390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/test_info.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AQAAAAc"] [Tue Aug 18 13:00:19.286735 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/coffee.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AgAAAFk"] [Tue Aug 18 13:00:19.287951 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1AwAAADU"] [Tue Aug 18 13:00:19.290740 2026] [security2:error] [pid 123784:tid 123915] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/222.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BQAAE34"] [Tue Aug 18 13:00:19.310280 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/www.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BgAAAAs"] [Tue Aug 18 13:00:19.346411 2026] [security2:error] [pid 123784:tid 123984] [client 158.23.17.4:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ka.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1BwAAAEI"] [Tue Aug 18 13:00:19.362403 2026] [security2:error] [pid 123784:tid 124021] [client 172.202.39.151:44513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/system_log.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CAAAAGc"] [Tue Aug 18 13:00:19.384694 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:58150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/z43agz.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CQAAAA4"] [Tue Aug 18 13:00:19.387933 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/14.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1CgAAAGY"] [Tue Aug 18 13:00:19.433363 2026] [security2:error] [pid 123784:tid 123951] [client 20.226.56.190:11634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tk.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DQAAACE"] [Tue Aug 18 13:00:19.438087 2026] [security2:error] [pid 123784:tid 124015] [client 20.79.204.6:10717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/file.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DgAAAGE"] [Tue Aug 18 13:00:19.446923 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.154.236:3973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1DwAAAAQ"] [Tue Aug 18 13:00:19.449377 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:35146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EAAAAF4"] [Tue Aug 18 13:00:19.471697 2026] [security2:error] [pid 123784:tid 123963] [client 213.35.127.232:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EgAAAC0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:19.489775 2026] [security2:error] [pid 123784:tid 124032] [client 172.202.39.151:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/01.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1EwAAAHI"] [Tue Aug 18 13:00:19.530933 2026] [security2:error] [pid 123784:tid 123953] [client 149.34.210.141:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FgAAACM"] [Tue Aug 18 13:00:19.532735 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.56.190:40151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/hp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FwAAAFg"] [Tue Aug 18 13:00:19.568703 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:42836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GQAAABk"] [Tue Aug 18 13:00:19.569062 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:42836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GQAAABk"] [Tue Aug 18 13:00:19.602420 2026] [security2:error] [pid 123784:tid 124010] [client 158.23.17.4:32567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/bm.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1GwAAAFw"] [Tue Aug 18 13:00:19.621913 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cgi-bin/index.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HAAAYgw"] [Tue Aug 18 13:00:19.680846 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.13.23:7712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HgAAAHU"] [Tue Aug 18 13:00:19.680862 2026] [security2:error] [pid 123784:tid 123933] [client 20.104.100.201:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/cok.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1HwAAAA8"] [Tue Aug 18 13:00:19.682318 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.27.191:27981] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IAAAAAI"] [Tue Aug 18 13:00:19.682380 2026] [security2:error] [pid 123784:tid 123920] [client 20.250.27.191:27981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IAAAAAI"] [Tue Aug 18 13:00:19.692797 2026] [security2:error] [pid 123784:tid 123918] [client 20.116.17.175:60459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/3.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IQAAAAA"] [Tue Aug 18 13:00:19.698662 2026] [security2:error] [pid 123784:tid 123982] [client 20.118.133.132:16602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/w1px.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1IgAAAEA"] [Tue Aug 18 13:00:19.749389 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:55216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/8.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1JAAAABI"] [Tue Aug 18 13:00:19.761769 2026] [security2:error] [pid 123784:tid 123987] [client 20.203.138.185:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/get.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1JQAAAEU"] [Tue Aug 18 13:00:19.776609 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:19.776899 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:19.793838 2026] [security2:error] [pid 123784:tid 124027] [client 20.100.169.31:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1KAAAAG0"] [Tue Aug 18 13:00:19.797137 2026] [security2:error] [pid 123784:tid 123953] [client 149.34.210.141:52857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1FgAAACM"] [Tue Aug 18 13:00:19.814075 2026] [security2:error] [pid 123784:tid 123965] [client 20.79.204.6:14118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1KgAAAC8"] [Tue Aug 18 13:00:19.845885 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wx.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1LAAAADs"] [Tue Aug 18 13:00:19.853461 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.156.252:61795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/blurbs.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1LgAAADY"] [Tue Aug 18 13:00:19.917583 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.154.236:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/blog/byp.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MQAAAFY"] [Tue Aug 18 13:00:19.978296 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:60454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/log.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MgAAAAc"] [Tue Aug 18 13:00:19.985217 2026] [security2:error] [pid 123784:tid 124007] [client 40.74.65.169:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1MwAAAFk"] [Tue Aug 18 13:00:19.994037 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/accesson.php"] [unique_id "aoSBk2wDnJBNj2tDbYb1NAAAADU"] [Tue Aug 18 13:00:20.013507 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/BDKR28WP.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1NQAAHSQ"] [Tue Aug 18 13:00:20.045703 2026] [security2:error] [pid 123784:tid 123923] [client 172.202.39.151:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1NwAAAAU"] [Tue Aug 18 13:00:20.076331 2026] [security2:error] [pid 123784:tid 124024] [client 157.20.138.62:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OQAAAGo"] [Tue Aug 18 13:00:20.076502 2026] [security2:error] [pid 123784:tid 124024] [client 157.20.138.62:58937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OQAAAGo"] [Tue Aug 18 13:00:20.082235 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:20.082520 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:20.110388 2026] [security2:error] [pid 123784:tid 124029] [client 20.250.27.191:35651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/about.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1OgAAAG8"] [Tue Aug 18 13:00:20.158455 2026] [security2:error] [pid 123784:tid 123932] [client 68.221.73.131:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/bajah.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PAAAAA4"] [Tue Aug 18 13:00:20.206350 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:30960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PgAAACc"] [Tue Aug 18 13:00:20.206479 2026] [security2:error] [pid 123784:tid 123957] [client 178.153.171.161:30960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PgAAACc"] [Tue Aug 18 13:00:20.224540 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/bajah.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1PwAAAF4"] [Tue Aug 18 13:00:20.251127 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:60327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/34.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QAAAADg"] [Tue Aug 18 13:00:20.256787 2026] [security2:error] [pid 123784:tid 123967] [client 20.116.17.175:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ohct.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QQAAADE"] [Tue Aug 18 13:00:20.264407 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:33993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vu.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1QgAAAGs"] [Tue Aug 18 13:00:20.310118 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ot.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1RQAAAB8"] [Tue Aug 18 13:00:20.380820 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:20.381076 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:20.414786 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.204.6:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1SgAAAD4"] [Tue Aug 18 13:00:20.428569 2026] [security2:error] [pid 123784:tid 123922] [client 20.100.169.31:17218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/akc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1SwAAAAQ"] [Tue Aug 18 13:00:20.461624 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:38868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ie.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1TAAAAFI"] [Tue Aug 18 13:00:20.484332 2026] [security2:error] [pid 123784:tid 124017] [client 213.35.127.232:58047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1TgAAAGM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:20.515928 2026] [security2:error] [pid 123784:tid 123939] [client 20.203.138.185:32192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rpk.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UQAAABU"] [Tue Aug 18 13:00:20.529629 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.27.191:34853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UgAAABE"] [Tue Aug 18 13:00:20.535634 2026] [security2:error] [pid 123784:tid 123933] [client 20.116.17.175:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ot.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1UwAAAA8"] [Tue Aug 18 13:00:20.546010 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/av.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VAAAAHU"] [Tue Aug 18 13:00:20.559243 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:39827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/domvf.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VgAAAAI"] [Tue Aug 18 13:00:20.631450 2026] [security2:error] [pid 123784:tid 123924] [client 172.202.39.151:40328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1VwAAAAY"] [Tue Aug 18 13:00:20.661278 2026] [security2:error] [pid 123784:tid 123987] [client 40.74.65.169:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WQAAAEU"] [Tue Aug 18 13:00:20.673062 2026] [security2:error] [pid 123784:tid 123937] [client 5.31.227.224:30435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WgAAABM"] [Tue Aug 18 13:00:20.673176 2026] [security2:error] [pid 123784:tid 123937] [client 5.31.227.224:30435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1WgAAABM"] [Tue Aug 18 13:00:20.680312 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:20.680562 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:20.688585 2026] [security2:error] [pid 123784:tid 123806] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XQAAIxE"] [Tue Aug 18 13:00:20.735025 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.154.236:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XgAAAAg"] [Tue Aug 18 13:00:20.764858 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XwAAABc"] [Tue Aug 18 13:00:20.764991 2026] [security2:error] [pid 123784:tid 123941] [client 37.40.227.74:57008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1XwAAABc"] [Tue Aug 18 13:00:20.816712 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:38332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ic.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YQAAAD8"] [Tue Aug 18 13:00:20.821574 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/kj.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YgAAAEE"] [Tue Aug 18 13:00:20.827295 2026] [security2:error] [pid 123784:tid 123968] [client 20.116.17.175:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/v5.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1YwAAADI"] [Tue Aug 18 13:00:20.871008 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.56.190:6337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/dj.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZQAAADk"] [Tue Aug 18 13:00:20.875760 2026] [security2:error] [pid 123784:tid 123944] [client 172.202.39.151:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/lv.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZgAAABo"] [Tue Aug 18 13:00:20.884852 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/he.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1ZwAAAHA"] [Tue Aug 18 13:00:20.917809 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:11642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fa.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1agAAAAc"] [Tue Aug 18 13:00:20.967429 2026] [security2:error] [pid 123784:tid 123934] [client 20.250.27.191:35678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/edit.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1awAAABA"] [Tue Aug 18 13:00:20.980440 2026] [security2:error] [pid 123784:tid 123964] [client 20.65.98.162:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/scxy.php"] [unique_id "aoSBlGwDnJBNj2tDbYb1bQAAAC4"] [Tue Aug 18 13:00:20.982678 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:20.982925 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:21.008360 2026] [security2:error] [pid 123784:tid 124038] [client 168.62.48.100:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1bgAAAHg"] [Tue Aug 18 13:00:21.015999 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1bwAAAF8"] [Tue Aug 18 13:00:21.018333 2026] [security2:error] [pid 123784:tid 123863] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/i.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cQAAG0o"] [Tue Aug 18 13:00:21.022851 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:7321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fb.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cgAAACc"] [Tue Aug 18 13:00:21.037557 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:6351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gw.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1cwAAAF4"] [Tue Aug 18 13:00:21.063090 2026] [security2:error] [pid 123784:tid 124040] [client 20.100.169.31:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/buy.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dQAAAHo"] [Tue Aug 18 13:00:21.063813 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:6348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sw.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dgAAAGs"] [Tue Aug 18 13:00:21.066238 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:57297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fpwch.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1dwAAAHs"] [Tue Aug 18 13:00:21.070745 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ih.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1eAAAAHI"] [Tue Aug 18 13:00:21.074004 2026] [security2:error] [pid 123784:tid 124034] [client 20.118.133.132:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/zi-936.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1eQAAAHQ"] [Tue Aug 18 13:00:21.082501 2026] [security2:error] [pid 123784:tid 123959] [client 172.202.39.151:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wicked.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1egAAACk"] [Tue Aug 18 13:00:21.108762 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ewAAAE0"] [Tue Aug 18 13:00:21.138367 2026] [security2:error] [pid 123784:tid 123930] [client 188.166.118.89:52844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fAAAAAw"] [Tue Aug 18 13:00:21.138481 2026] [security2:error] [pid 123784:tid 123930] [client 188.166.118.89:52844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fAAAAAw"] [Tue Aug 18 13:00:21.154653 2026] [security2:error] [pid 123784:tid 124002] [client 20.104.100.201:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fgAAAFQ"] [Tue Aug 18 13:00:21.185060 2026] [security2:error] [pid 123784:tid 123922] [client 68.155.156.252:10971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/82.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fwAAAAQ"] [Tue Aug 18 13:00:21.235376 2026] [security2:error] [pid 123784:tid 124000] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1gAAAUiI"] [Tue Aug 18 13:00:21.321287 2026] [security2:error] [pid 123784:tid 123938] [client 20.203.138.185:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hAAAABQ"] [Tue Aug 18 13:00:21.341332 2026] [security2:error] [pid 123784:tid 124037] [client 40.74.65.169:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yj09.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hQAAAHc"] [Tue Aug 18 13:00:21.355044 2026] [security2:error] [pid 123784:tid 123927] [client 68.221.73.131:28062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/ajax.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1hgAAAAk"] [Tue Aug 18 13:00:21.359755 2026] [security2:error] [pid 123784:tid 123986] [client 45.117.63.159:49263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.63.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fQAAAEQ"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:21.359855 2026] [security2:error] [pid 123784:tid 123986] [client 45.117.63.159:49263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1fQAAAEQ"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:21.383925 2026] [security2:error] [pid 123784:tid 123954] [client 172.202.39.151:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/abc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iAAAACQ"] [Tue Aug 18 13:00:21.388577 2026] [security2:error] [pid 123784:tid 124019] [client 20.116.17.175:57975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iQAAAGU"] [Tue Aug 18 13:00:21.405460 2026] [security2:error] [pid 123784:tid 123817] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/abcd.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1igAAUBw"] [Tue Aug 18 13:00:21.405703 2026] [security2:error] [pid 123784:tid 123960] [client 20.250.27.191:34841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1iwAAACo"] [Tue Aug 18 13:00:21.427600 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:32566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ue.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jQAAAAM"] [Tue Aug 18 13:00:21.449817 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.100.201:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/png.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jgAAAFo"] [Tue Aug 18 13:00:21.498238 2026] [security2:error] [pid 123784:tid 123950] [client 213.35.127.232:58255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1jwAAACA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:21.526056 2026] [security2:error] [pid 123784:tid 123952] [client 138.36.100.162:42146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kAAAACI"] [Tue Aug 18 13:00:21.526201 2026] [security2:error] [pid 123784:tid 123952] [client 138.36.100.162:42146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kAAAACI"] [Tue Aug 18 13:00:21.542025 2026] [security2:error] [pid 123784:tid 124033] [client 68.155.156.252:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/adminner.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kgAAAHM"] [Tue Aug 18 13:00:21.594405 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:21.594664 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:21.616585 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gz.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mAAAAAc"] [Tue Aug 18 13:00:21.616677 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.204.6:14110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/abc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mQAAACM"] [Tue Aug 18 13:00:21.627641 2026] [security2:error] [pid 123784:tid 123996] [client 223.185.37.47:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mgAAAE4"] [Tue Aug 18 13:00:21.627717 2026] [security2:error] [pid 123784:tid 123996] [client 223.185.37.47:10693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1mgAAAE4"] [Tue Aug 18 13:00:21.693807 2026] [security2:error] [pid 123784:tid 123947] [client 20.116.17.175:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dk.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nAAAAB0"] [Tue Aug 18 13:00:21.706578 2026] [security2:error] [pid 123784:tid 124014] [client 20.100.169.31:4024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/cong.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nQAAAGA"] [Tue Aug 18 13:00:21.723950 2026] [security2:error] [pid 123784:tid 123795] [remote 162.214.205.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ngAAMwY"] [Tue Aug 18 13:00:21.725883 2026] [security2:error] [pid 123784:tid 123838] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-manager.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1nwAAQjE"] [Tue Aug 18 13:00:21.729409 2026] [security2:error] [pid 123784:tid 123914] [remote 103.13.51.160:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.51.13.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1kwAABX0"] [Tue Aug 18 13:00:21.816314 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:40165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inputs.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1oAAAAF0"] [Tue Aug 18 13:00:21.818705 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ab.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1oQAAAGY"] [Tue Aug 18 13:00:21.834275 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.154.236:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1ogAAAF8"] [Tue Aug 18 13:00:21.887842 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:21.888105 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:21.967002 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/bal.php"] [unique_id "aoSBlWwDnJBNj2tDbYb1pQAAAHQ"] [Tue Aug 18 13:00:22.030671 2026] [security2:error] [pid 123784:tid 123958] [client 40.74.65.169:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/scxy.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1pwAAACg"] [Tue Aug 18 13:00:22.067090 2026] [security2:error] [pid 123784:tid 124002] [client 172.202.39.151:44553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/akcc.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qAAAAFQ"] [Tue Aug 18 13:00:22.080040 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/k.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qQAAABg"] [Tue Aug 18 13:00:22.103635 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.56.190:18595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gc.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1qwAAAFE"] [Tue Aug 18 13:00:22.115307 2026] [security2:error] [pid 123784:tid 124039] [client 172.202.39.151:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/new.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rAAAAHk"] [Tue Aug 18 13:00:22.131739 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/nwwha.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rQAAAGI"] [Tue Aug 18 13:00:22.145405 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.98.162:56487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/biufile.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1rgAAACE"] [Tue Aug 18 13:00:22.153597 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.100.201:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/12.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1sAAAABU"] [Tue Aug 18 13:00:22.168872 2026] [security2:error] [pid 123784:tid 123876] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1sQAAWFc"] [Tue Aug 18 13:00:22.189127 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:22.189402 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:22.227787 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nw.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1twAAAEA"] [Tue Aug 18 13:00:22.239401 2026] [autoindex:error] [pid 123784:tid 123839] [remote 158.158.74.177:0] AH01276: Cannot serve directory /home1/w32lie55icas3ua4/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:22.247131 2026] [security2:error] [pid 123784:tid 123938] [client 20.116.17.175:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yawa.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1uQAAABQ"] [Tue Aug 18 13:00:22.248844 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:35707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/av.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1ugAAAAY"] [Tue Aug 18 13:00:22.251609 2026] [security2:error] [pid 123784:tid 124005] [client 20.79.204.6:14104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/sf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1uwAAAFc"] [Tue Aug 18 13:00:22.308958 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:31902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lr.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1wgAAACo"] [Tue Aug 18 13:00:22.342880 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:44487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ws13.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1wwAAABw"] [Tue Aug 18 13:00:22.366684 2026] [security2:error] [pid 123784:tid 124026] [client 20.100.169.31:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xAAAAGw"] [Tue Aug 18 13:00:22.429747 2026] [security2:error] [pid 123784:tid 124033] [client 68.221.73.131:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lineaplas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xgAAAHM"] [Tue Aug 18 13:00:22.443576 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/HLA-dd.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1xwAAAEE"] [Tue Aug 18 13:00:22.477338 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/x1da.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1yQAAAB4"] [Tue Aug 18 13:00:22.511661 2026] [security2:error] [pid 123784:tid 123933] [client 213.35.127.232:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1ywAAAA8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:22.539393 2026] [security2:error] [pid 123784:tid 123996] [client 20.116.17.175:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1zQAAAE4"] [Tue Aug 18 13:00:22.592646 2026] [security2:error] [pid 123784:tid 123929] [client 20.203.138.185:16242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/mga.php"] [unique_id "aoSBlmwDnJBNj2tDbYb1zwAAAAs"] [Tue Aug 18 13:00:22.661204 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:10744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10QAAAEo"] [Tue Aug 18 13:00:22.712033 2026] [security2:error] [pid 123784:tid 123984] [client 20.250.27.191:34820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10gAAAEI"] [Tue Aug 18 13:00:22.715285 2026] [security2:error] [pid 123784:tid 123920] [client 4.232.94.69:20017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb10wAAAAI"] [Tue Aug 18 13:00:22.717342 2026] [security2:error] [pid 123784:tid 123923] [client 40.74.65.169:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11AAAAAU"] [Tue Aug 18 13:00:22.731686 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ka.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11QAAAC4"] [Tue Aug 18 13:00:22.752033 2026] [security2:error] [pid 123784:tid 124009] [client 135.225.78.186:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/82.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11wAAAFs"] [Tue Aug 18 13:00:22.752078 2026] [security2:error] [pid 123784:tid 123895] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBlmwDnJBNj2tDbYb11gAAb2o"] [Tue Aug 18 13:00:22.789968 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:22.790240 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:22.796111 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nf.php"] [unique_id "aoSBlmwDnJBNj2tDbYb12QAAABs"] [Tue Aug 18 13:00:22.822717 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:60457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/7.php"] [unique_id "aoSBlmwDnJBNj2tDbYb12wAAAC8"] [Tue Aug 18 13:00:22.826835 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mcs.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13AAAAHw"] [Tue Aug 18 13:00:22.846489 2026] [security2:error] [pid 123784:tid 124012] [client 172.202.39.151:12744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wk/index.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13QAAAF4"] [Tue Aug 18 13:00:22.870487 2026] [security2:error] [pid 123784:tid 124040] [client 68.155.154.236:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lenhardmotors.com.br"] [uri "/images/security.php"] [unique_id "aoSBlmwDnJBNj2tDbYb13gAAAHo"] [Tue Aug 18 13:00:22.902658 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:9396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sb.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14AAAAGs"] [Tue Aug 18 13:00:22.910288 2026] [security2:error] [pid 123784:tid 123969] [client 20.79.204.6:14115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/chosen.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14QAAADM"] [Tue Aug 18 13:00:22.945124 2026] [security2:error] [pid 123784:tid 124027] [client 168.62.48.100:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/opsqt.php"] [unique_id "aoSBlmwDnJBNj2tDbYb14gAAAG0"] [Tue Aug 18 13:00:23.048626 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/db.php"] [unique_id "aoSBl2wDnJBNj2tDbYb15wAAABY"] [Tue Aug 18 13:00:23.098225 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:23.098685 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:23.119847 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.27.191:35663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb16gAAABE"] [Tue Aug 18 13:00:23.139517 2026] [security2:error] [pid 123784:tid 123990] [client 20.116.17.175:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ws77.php"] [unique_id "aoSBl2wDnJBNj2tDbYb16wAAAEg"] [Tue Aug 18 13:00:23.155626 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uq.php"] [unique_id "aoSBl2wDnJBNj2tDbYb17gAAAH8"] [Tue Aug 18 13:00:23.185070 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/adminner.php"] [unique_id "aoSBl2wDnJBNj2tDbYb17wAAAA0"] [Tue Aug 18 13:00:23.189270 2026] [security2:error] [pid 123784:tid 123938] [client 68.155.156.252:23111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBl2wDnJBNj2tDbYb18gAAABQ"] [Tue Aug 18 13:00:23.223461 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.56.190:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/32.php"] [unique_id "aoSBl2wDnJBNj2tDbYb18wAAAAk"] [Tue Aug 18 13:00:23.261050 2026] [security2:error] [pid 123784:tid 123999] [client 79.127.164.8:42804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wbboardacplibinserts.bak"] [unique_id "aoSBl2wDnJBNj2tDbYb19AAAAFE"], referer: https://medihub.com.br/wbboardacplibinserts.bak [Tue Aug 18 13:00:23.301010 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/73.php"] [unique_id "aoSBl2wDnJBNj2tDbYb19QAAACo"] [Tue Aug 18 13:00:23.327989 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xv.php"] [unique_id "aoSBl2wDnJBNj2tDbYb19wAAACA"] [Tue Aug 18 13:00:23.360585 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:23695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/lock360.php"] [unique_id "aoSBl2wDnJBNj2tDbYb1-wAAAD8"] [Tue Aug 18 13:00:23.361468 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:12523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ot.php"] [unique_id "aoSBl2wDnJBNj2tDbYb1_AAAAHM"] [Tue Aug 18 13:00:23.389960 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:23.390123 2026] [security2:error] [pid 123784:tid 123919] [client 40.74.65.169:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2AAAAAAE"] [Tue Aug 18 13:00:23.390223 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:23.410185 2026] [autoindex:error] [pid 123784:tid 123975] [client 169.58.72.248:50954] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:23.412325 2026] [security2:error] [pid 123784:tid 124043] [client 156.59.198.135:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/ms/campo-grande/jardim-mansur/img/rua-jane-rodrigues-pache-jardim-mansur-campo-grande-ms.webp"] [unique_id "aoSBl2wDnJBNj2tDbYb2AgAAAH0"], referer: https://www.icep.com.br/livrocep/ms/campo-grande/jardim-mansur/rua-jane-rodrigues-pache-cep-79051630/ [Tue Aug 18 13:00:23.416488 2026] [security2:error] [pid 123784:tid 123948] [client 20.116.17.175:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/read.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2AwAAAB4"] [Tue Aug 18 13:00:23.421539 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:17947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ib.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BAAAAAc"] [Tue Aug 18 13:00:23.425397 2026] [security2:error] [pid 123784:tid 123968] [client 192.141.172.134:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BQAAADI"] [Tue Aug 18 13:00:23.425503 2026] [security2:error] [pid 123784:tid 123968] [client 192.141.172.134:57451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BQAAADI"] [Tue Aug 18 13:00:23.449347 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.156.252:37107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/dex.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2BgAAAC0"] [Tue Aug 18 13:00:23.472955 2026] [security2:error] [pid 123784:tid 123929] [client 20.226.56.190:11636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xm.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CAAAAAs"] [Tue Aug 18 13:00:23.484239 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.56.190:15230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zy.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CQAAABo"] [Tue Aug 18 13:00:23.485517 2026] [security2:error] [pid 123784:tid 123984] [client 20.104.100.201:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dragonshell.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CgAAAEI"] [Tue Aug 18 13:00:23.494750 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xj.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2CwAAAAI"] [Tue Aug 18 13:00:23.517276 2026] [security2:error] [pid 123784:tid 124003] [client 20.226.56.190:41950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/q.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DAAAAFU"] [Tue Aug 18 13:00:23.521445 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/u.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DQAAAFo"] [Tue Aug 18 13:00:23.531595 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DgAAAHc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:23.540240 2026] [security2:error] [pid 123784:tid 123873] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/simple.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2DwAAb1Q"] [Tue Aug 18 13:00:23.545470 2026] [security2:error] [pid 123784:tid 124021] [client 20.250.27.191:45820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-blog.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2EAAAAGc"] [Tue Aug 18 13:00:23.592235 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.56.190:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xf.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2EgAAAE8"] [Tue Aug 18 13:00:23.606818 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gb.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FAAAAF4"] [Tue Aug 18 13:00:23.611963 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.156.252:42176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/simple.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FQAAAFY"] [Tue Aug 18 13:00:23.614617 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FgAAHTs"] [Tue Aug 18 13:00:23.669978 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/dropdown.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2FwAAAEs"] [Tue Aug 18 13:00:23.696579 2026] [security2:error] [pid 123784:tid 124032] [client 20.116.17.175:60440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/albin.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2GAAAAHI"] [Tue Aug 18 13:00:23.715055 2026] [security2:error] [pid 123784:tid 123957] [client 20.203.138.185:18841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/fs.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2GQAAACc"] [Tue Aug 18 13:00:23.734910 2026] [security2:error] [pid 123784:tid 124015] [client 20.65.98.162:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/coffexium.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2HAAAAGE"] [Tue Aug 18 13:00:23.735439 2026] [security2:error] [pid 123784:tid 123922] [client 216.244.66.243:55626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/garotas+de+programa+serrinha+ba-0/"] [unique_id "aoSBl2wDnJBNj2tDbYb2HQAAAAQ"] [Tue Aug 18 13:00:23.735560 2026] [security2:error] [pid 123784:tid 123922] [client 216.244.66.243:55626] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/garotas+de+programa+serrinha+ba-0/"] [unique_id "aoSBl2wDnJBNj2tDbYb2HQAAAAQ"] [Tue Aug 18 13:00:23.775071 2026] [security2:error] [pid 123784:tid 123966] [client 20.250.13.23:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/a7.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2HwAAADA"] [Tue Aug 18 13:00:23.838432 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:44605] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/1.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IAAAACE"] [Tue Aug 18 13:00:23.838558 2026] [security2:error] [pid 123784:tid 123951] [client 172.202.39.151:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/1.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IAAAACE"] [Tue Aug 18 13:00:23.840358 2026] [security2:error] [pid 123784:tid 123939] [client 172.202.39.151:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IQAAABU"] [Tue Aug 18 13:00:23.845492 2026] [security2:error] [pid 123784:tid 124006] [client 135.225.78.186:27967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/dex.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IgAAAFg"] [Tue Aug 18 13:00:23.845945 2026] [security2:error] [pid 123784:tid 123935] [client 20.65.98.162:20824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/btx25.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2IwAAABE"] [Tue Aug 18 13:00:23.852882 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ih.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2JAAAAEg"] [Tue Aug 18 13:00:23.894651 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/setup-config.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2JQAAAA0"] [Tue Aug 18 13:00:23.940666 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KAAAABI"] [Tue Aug 18 13:00:23.941793 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.56.190:11636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jp.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KgAAAFA"] [Tue Aug 18 13:00:23.976463 2026] [security2:error] [pid 123784:tid 123837] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KwAAMzA"] [Tue Aug 18 13:00:23.976858 2026] [security2:error] [pid 123784:tid 123969] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2KwAAMzA"] [Tue Aug 18 13:00:23.980255 2026] [security2:error] [pid 123784:tid 123961] [client 158.158.74.177:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/log.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2LAAAACs"] [Tue Aug 18 13:00:23.984256 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.56.190:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eq.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2LgAAADs"] [Tue Aug 18 13:00:23.992725 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:23.992998 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:23.996460 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:13104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ep.php"] [unique_id "aoSBl2wDnJBNj2tDbYb2MAAAACI"] [Tue Aug 18 13:00:24.029854 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:58133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fw/34.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2MgAAAAc"] [Tue Aug 18 13:00:24.049084 2026] [security2:error] [pid 123784:tid 123996] [client 172.202.39.151:41109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/222.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NQAAAE4"] [Tue Aug 18 13:00:24.067711 2026] [security2:error] [pid 123784:tid 123963] [client 40.74.65.169:60247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NgAAAC0"] [Tue Aug 18 13:00:24.081612 2026] [security2:error] [pid 123784:tid 123793] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2NwAARwQ"] [Tue Aug 18 13:00:24.103479 2026] [security2:error] [pid 123784:tid 123855] [remote 52.167.144.183:58978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memo.ind.br"] [uri "/index.php/atendimento/fale-conosco"] [unique_id "aoSBl2wDnJBNj2tDbYb2KQAASUI"] [Tue Aug 18 13:00:24.159040 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2OwAAAAI"] [Tue Aug 18 13:00:24.169655 2026] [security2:error] [pid 123784:tid 123923] [client 20.226.56.190:10573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rf.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PAAAAAU"] [Tue Aug 18 13:00:24.197322 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.27.191:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PQAAAGo"] [Tue Aug 18 13:00:24.213491 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:8267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xynz1.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PwAAAFs"] [Tue Aug 18 13:00:24.262190 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/f35.update.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QQAAAGY"] [Tue Aug 18 13:00:24.279231 2026] [security2:error] [pid 123784:tid 123840] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/chosen.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QwAALzM"] [Tue Aug 18 13:00:24.281491 2026] [security2:error] [pid 123784:tid 123841] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RAAAfDQ"] [Tue Aug 18 13:00:24.284208 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.204.6:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/404.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RQAAADw"] [Tue Aug 18 13:00:24.290256 2026] [security2:error] [pid 123784:tid 124012] [client 168.62.48.100:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/jvcpa.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SAAAAF4"] [Tue Aug 18 13:00:24.290786 2026] [security2:error] [pid 123784:tid 123890] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RwAAVmU"] [Tue Aug 18 13:00:24.290959 2026] [security2:error] [pid 123784:tid 124004] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2RwAAVmU"] [Tue Aug 18 13:00:24.292786 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:63667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ns.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SQAAAB0"] [Tue Aug 18 13:00:24.294195 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:24.294458 2026] [authz_core:error] [pid 123784:tid 123804] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:24.295795 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:41977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vo.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SwAAAEU"] [Tue Aug 18 13:00:24.311911 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:7187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iu.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2TQAAACQ"] [Tue Aug 18 13:00:24.313228 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2TgAAAGs"] [Tue Aug 18 13:00:24.323009 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:57037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mx.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UAAAAB8"] [Tue Aug 18 13:00:24.328169 2026] [security2:error] [pid 123784:tid 124034] [client 20.116.17.175:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp9.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UQAAAHQ"] [Tue Aug 18 13:00:24.329553 2026] [security2:error] [pid 123784:tid 123992] [client 20.100.169.31:3780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/file.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UgAAAEo"] [Tue Aug 18 13:00:24.333875 2026] [security2:error] [pid 123784:tid 124032] [client 20.79.204.6:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/customize.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2UwAAAHI"] [Tue Aug 18 13:00:24.335964 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.56.190:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wu.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2VAAAAHI"] [Tue Aug 18 13:00:24.427467 2026] [security2:error] [pid 123784:tid 124019] [client 45.117.63.159:49368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "plenitude.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2QgAAAGU"], referer: https://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:24.457907 2026] [security2:error] [pid 123784:tid 123822] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/public/css.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2WAAAWCE"] [Tue Aug 18 13:00:24.557596 2026] [security2:error] [pid 123784:tid 124007] [client 3.12.251.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2PgAAWW4"], referer: https://thatianysantana.com.br/ [Tue Aug 18 13:00:24.559432 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2WwAAAHc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:24.567242 2026] [security2:error] [pid 123784:tid 123938] [client 68.155.156.252:32257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/xiugai.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2XAAAABQ"] [Tue Aug 18 13:00:24.596099 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:24.596367 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:24.625566 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:40326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2XwAAAFc"] [Tue Aug 18 13:00:24.632807 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.27.191:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2YAAAAAM"] [Tue Aug 18 13:00:24.633685 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2YgAAABw"] [Tue Aug 18 13:00:24.637815 2026] [security2:error] [pid 123784:tid 123969] [client 20.116.17.175:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/save.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZAAAADM"] [Tue Aug 18 13:00:24.647422 2026] [authz_core:error] [pid 123784:tid 123821] [remote 57.141.22.18:47344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:24.647854 2026] [authz_core:error] [pid 123784:tid 123821] [remote 57.141.22.18:47344] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:24.651081 2026] [security2:error] [pid 123784:tid 123928] [client 68.155.156.252:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/puc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZQAAAAo"] [Tue Aug 18 13:00:24.653984 2026] [security2:error] [pid 123784:tid 123792] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/classwithtostring.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZgAAKwM"] [Tue Aug 18 13:00:24.664991 2026] [security2:error] [pid 123784:tid 123922] [client 158.158.74.177:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/lv.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2ZwAAAAQ"] [Tue Aug 18 13:00:24.709880 2026] [security2:error] [pid 123784:tid 124026] [client 20.118.133.132:28280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2aQAAAGw"] [Tue Aug 18 13:00:24.714511 2026] [security2:error] [pid 123784:tid 123971] [client 20.104.100.201:61390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/bdroot.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2agAAADU"] [Tue Aug 18 13:00:24.749198 2026] [security2:error] [pid 123784:tid 124043] [client 40.74.65.169:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2awAAAH0"] [Tue Aug 18 13:00:24.812626 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bQAAABo"] [Tue Aug 18 13:00:24.812765 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bQAAABo"] [Tue Aug 18 13:00:24.815236 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bgAAAGM"] [Tue Aug 18 13:00:24.846473 2026] [security2:error] [pid 123784:tid 123976] [client 172.202.39.151:4445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cah.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2bwAAADo"] [Tue Aug 18 13:00:24.859262 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-supports/"] [unique_id "aoSBmGwDnJBNj2tDbYb2cAAARGw"] [Tue Aug 18 13:00:24.869661 2026] [security2:error] [pid 123784:tid 123991] [client 172.202.39.151:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/chosen.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2cQAAAEk"] [Tue Aug 18 13:00:24.938295 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.156.252:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wp-load.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2cgAAACg"] [Tue Aug 18 13:00:24.952053 2026] [security2:error] [pid 123784:tid 123975] [client 20.100.169.31:3810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/goods.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dAAAADk"] [Tue Aug 18 13:00:24.959710 2026] [security2:error] [pid 123784:tid 123810] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/als.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dgAALhU"] [Tue Aug 18 13:00:24.961711 2026] [security2:error] [pid 123784:tid 124018] [client 197.184.64.235:41955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dQAAAGQ"] [Tue Aug 18 13:00:24.961845 2026] [security2:error] [pid 123784:tid 124018] [client 197.184.64.235:41955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dQAAAGQ"] [Tue Aug 18 13:00:24.971523 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2dwAAAFo"] [Tue Aug 18 13:00:25.020669 2026] [security2:error] [pid 123784:tid 123973] [client 20.104.100.201:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2eAAAADc"] [Tue Aug 18 13:00:25.040659 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/45.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2eQAAAHY"] [Tue Aug 18 13:00:25.054921 2026] [security2:error] [pid 123784:tid 124029] [client 20.250.27.191:28124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/222.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2egAAAG8"] [Tue Aug 18 13:00:25.080997 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/edit.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fAAAAF0"] [Tue Aug 18 13:00:25.138751 2026] [security2:error] [pid 123784:tid 123950] [client 20.203.138.185:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/wp-tem.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fQAAACA"] [Tue Aug 18 13:00:25.147160 2026] [security2:error] [pid 123784:tid 123967] [client 20.79.204.6:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/mah/function.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2fgAAADE"] [Tue Aug 18 13:00:25.198971 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:25.199241 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:25.201020 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/admin.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gAAAemA"] [Tue Aug 18 13:00:25.226703 2026] [security2:error] [pid 123784:tid 123949] [client 135.225.78.186:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/puc.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gQAAAB8"] [Tue Aug 18 13:00:25.227507 2026] [security2:error] [pid 123784:tid 124034] [client 158.23.17.4:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/k.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ggAAAHQ"] [Tue Aug 18 13:00:25.264516 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:58164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2gwAAAFQ"] [Tue Aug 18 13:00:25.268929 2026] [security2:error] [pid 123784:tid 123933] [client 20.79.204.6:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wk/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hAAAAA8"] [Tue Aug 18 13:00:25.281171 2026] [security2:error] [pid 123784:tid 123835] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/nox.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hQAAPi4"] [Tue Aug 18 13:00:25.293787 2026] [security2:error] [pid 123784:tid 123995] [client 20.65.98.162:28941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hgAAAE0"] [Tue Aug 18 13:00:25.302409 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mah/function.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2hwAAAC8"] [Tue Aug 18 13:00:25.378263 2026] [security2:error] [pid 123784:tid 124019] [client 168.62.48.100:5446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2iQAAAGU"] [Tue Aug 18 13:00:25.400319 2026] [security2:error] [pid 123784:tid 123908] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gelay.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2iwAAYnc"] [Tue Aug 18 13:00:25.435435 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gk.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jAAAADQ"] [Tue Aug 18 13:00:25.441949 2026] [security2:error] [pid 123784:tid 123990] [client 40.74.65.169:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/blurbs.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jQAAAEg"] [Tue Aug 18 13:00:25.444083 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-css.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jgAAAAA"] [Tue Aug 18 13:00:25.445332 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/w.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2jwAAAGA"] [Tue Aug 18 13:00:25.464127 2026] [security2:error] [pid 123784:tid 124045] [client 68.155.156.252:7206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/155.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kAAAAH8"] [Tue Aug 18 13:00:25.469836 2026] [security2:error] [pid 123784:tid 123932] [client 20.250.27.191:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kQAAAA4"] [Tue Aug 18 13:00:25.505657 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/de.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2kwAAAFI"] [Tue Aug 18 13:00:25.522336 2026] [security2:error] [pid 123784:tid 123960] [client 20.226.56.190:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/album.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lAAAACo"] [Tue Aug 18 13:00:25.527533 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/manager.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lQAAACY"] [Tue Aug 18 13:00:25.532881 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:7306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kv.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2lgAAAAM"] [Tue Aug 18 13:00:25.546330 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.56.190:21179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/z.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mAAAACs"] [Tue Aug 18 13:00:25.561019 2026] [security2:error] [pid 123784:tid 123972] [client 20.116.17.175:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/df.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mgAAADY"] [Tue Aug 18 13:00:25.574313 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2mwAAAHI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:25.579677 2026] [security2:error] [pid 123784:tid 123819] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2nAAAbB4"] [Tue Aug 18 13:00:25.594371 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.56.190:10577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xg.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2nQAAAHs"] [Tue Aug 18 13:00:25.606645 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:10619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/nd.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ngAAAH0"] [Tue Aug 18 13:00:25.622364 2026] [security2:error] [pid 123784:tid 123955] [client 74.7.228.25:59238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "site.domcoworking.com.br"] [uri "/index.php"] [unique_id "aoSBmGwDnJBNj2tDbYb2SgAAJWI"] [Tue Aug 18 13:00:25.626479 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:6588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ri.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pAAAAHU"] [Tue Aug 18 13:00:25.629986 2026] [security2:error] [pid 123784:tid 123939] [client 20.100.169.31:4020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pQAAABU"] [Tue Aug 18 13:00:25.659917 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pk.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2pgAAAGg"] [Tue Aug 18 13:00:25.752269 2026] [security2:error] [pid 123784:tid 123922] [client 20.79.204.6:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/filter.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2rQAAAAQ"] [Tue Aug 18 13:00:25.768532 2026] [security2:error] [pid 123784:tid 123843] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/adminfuns.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2rwAAWzY"] [Tue Aug 18 13:00:25.799251 2026] [security2:error] [pid 123784:tid 124038] [client 20.104.100.201:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/flox.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2sgAAAHg"] [Tue Aug 18 13:00:25.800610 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:25.800879 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:25.828510 2026] [security2:error] [pid 123784:tid 123877] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file59.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2tAAAZlg"] [Tue Aug 18 13:00:25.840624 2026] [security2:error] [pid 123784:tid 123997] [client 20.226.36.136:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2twAAAE8"] [Tue Aug 18 13:00:25.844188 2026] [security2:error] [pid 123784:tid 123919] [client 20.116.17.175:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2uAAAAAE"] [Tue Aug 18 13:00:25.844997 2026] [security2:error] [pid 123784:tid 124042] [client 68.155.156.252:37105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/inso.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2uQAAAHw"] [Tue Aug 18 13:00:25.877447 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.156.252:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/index.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2ugAAAF4"] [Tue Aug 18 13:00:25.890535 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wy.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2vAAAAB0"] [Tue Aug 18 13:00:25.911789 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:28129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2vQAAAEA"] [Tue Aug 18 13:00:25.953256 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:34119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iu.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2wAAAAEs"] [Tue Aug 18 13:00:25.959068 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2wwAAACc"] [Tue Aug 18 13:00:25.965166 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBmWwDnJBNj2tDbYb2xAAAAGo"] [Tue Aug 18 13:00:25.976493 2026] [security2:error] [pid 123784:tid 123796] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/"] [unique_id "aoSBmWwDnJBNj2tDbYb2xQAAVAc"] [Tue Aug 18 13:00:26.092820 2026] [authz_core:error] [pid 123784:tid 123874] [remote 57.141.22.2:53486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:26.093264 2026] [authz_core:error] [pid 123784:tid 123874] [remote 57.141.22.2:53486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:26.103238 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:26.103516 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:26.108222 2026] [security2:error] [pid 123784:tid 124006] [client 20.104.100.201:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/op.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2yAAAAFg"] [Tue Aug 18 13:00:26.134829 2026] [security2:error] [pid 123784:tid 124014] [client 40.74.65.169:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bajah.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2ygAAAGA"] [Tue Aug 18 13:00:26.144585 2026] [security2:error] [pid 123784:tid 123983] [client 20.116.17.175:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/usr.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2ywAAAEE"] [Tue Aug 18 13:00:26.145863 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/admin.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zAAAE0E"] [Tue Aug 18 13:00:26.151451 2026] [security2:error] [pid 123784:tid 124045] [client 172.202.39.151:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/info.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zQAAAH8"] [Tue Aug 18 13:00:26.157515 2026] [security2:error] [pid 123784:tid 123800] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2zgAADgs"] [Tue Aug 18 13:00:26.163045 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wn.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20QAAAEU"] [Tue Aug 18 13:00:26.163434 2026] [security2:error] [pid 123784:tid 123850] [remote 74.220.219.216:37410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.219.220.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20AAAOz0"] [Tue Aug 18 13:00:26.166159 2026] [security2:error] [pid 123784:tid 124037] [client 172.202.39.151:44507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20gAAAHc"] [Tue Aug 18 13:00:26.274603 2026] [security2:error] [pid 123784:tid 123956] [client 20.124.247.79:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBmmwDnJBNj2tDbYb20wAAACY"] [Tue Aug 18 13:00:26.277432 2026] [security2:error] [pid 123784:tid 123921] [client 20.203.138.185:40983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/sadd.php"] [unique_id "aoSBmmwDnJBNj2tDbYb21AAAAAM"] [Tue Aug 18 13:00:26.298930 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22AAAACs"] [Tue Aug 18 13:00:26.306053 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.36.136:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22gAAADY"] [Tue Aug 18 13:00:26.312328 2026] [security2:error] [pid 123784:tid 123971] [client 68.155.156.252:50939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/aaa.php"] [unique_id "aoSBmmwDnJBNj2tDbYb22wAAADU"] [Tue Aug 18 13:00:26.316485 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/htaccess.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23AAAABY"] [Tue Aug 18 13:00:26.332163 2026] [security2:error] [pid 123784:tid 124004] [client 20.79.204.6:10689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/about.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23gAAAFY"] [Tue Aug 18 13:00:26.371207 2026] [security2:error] [pid 123784:tid 123815] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/about.php"] [unique_id "aoSBmmwDnJBNj2tDbYb23wAAIxo"] [Tue Aug 18 13:00:26.413146 2026] [security2:error] [pid 123784:tid 123989] [client 135.225.78.186:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/inso.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24AAAAEc"] [Tue Aug 18 13:00:26.435560 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:34247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/1xmomo.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24gAAAAk"] [Tue Aug 18 13:00:26.438617 2026] [security2:error] [pid 123784:tid 123991] [client 20.116.17.175:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBmmwDnJBNj2tDbYb24wAAAEk"] [Tue Aug 18 13:00:26.450283 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:14037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/input.php"] [unique_id "aoSBmmwDnJBNj2tDbYb25AAAABI"] [Tue Aug 18 13:00:26.508421 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.36.136:61449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/weozh.php"] [unique_id "aoSBmmwDnJBNj2tDbYb25wAAAC4"] [Tue Aug 18 13:00:26.534690 2026] [security2:error] [pid 123784:tid 124009] [client 20.250.27.191:40142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26AAAAFs"] [Tue Aug 18 13:00:26.536053 2026] [security2:error] [pid 123784:tid 123922] [client 20.124.247.79:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26QAAAAQ"] [Tue Aug 18 13:00:26.552600 2026] [security2:error] [pid 123784:tid 123881] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26gAARlw"] [Tue Aug 18 13:00:26.562674 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aa2.php"] [unique_id "aoSBmmwDnJBNj2tDbYb26wAAeAw"] [Tue Aug 18 13:00:26.588947 2026] [security2:error] [pid 123784:tid 124031] [client 213.35.127.232:59389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27AAAAHE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:26.594750 2026] [security2:error] [pid 123784:tid 123996] [client 158.158.74.177:23737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mass.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27QAAAE4"] [Tue Aug 18 13:00:26.655316 2026] [security2:error] [pid 123784:tid 123947] [client 68.155.156.252:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/FWAZ.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27gAAAB0"] [Tue Aug 18 13:00:26.658797 2026] [security2:error] [pid 123784:tid 124013] [client 158.23.17.4:12487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pk.php"] [unique_id "aoSBmmwDnJBNj2tDbYb27wAAAF8"] [Tue Aug 18 13:00:26.690406 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28AAAAHo"] [Tue Aug 18 13:00:26.702997 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:26.703255 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:26.722622 2026] [security2:error] [pid 123784:tid 123992] [client 20.116.17.175:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/css/database.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28gAAAEo"] [Tue Aug 18 13:00:26.727580 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aa.php"] [unique_id "aoSBmmwDnJBNj2tDbYb28wAAAHQ"] [Tue Aug 18 13:00:26.765123 2026] [security2:error] [pid 123784:tid 123825] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/f35.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29gAAaiQ"] [Tue Aug 18 13:00:26.785152 2026] [security2:error] [pid 123784:tid 123926] [client 20.104.100.201:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/txets.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29wAAAAg"] [Tue Aug 18 13:00:26.811502 2026] [security2:error] [pid 123784:tid 124021] [client 78.46.190.63:18424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSBmmwDnJBNj2tDbYb29QAAAGc"], referer: https://www.saojudas.com.br [Tue Aug 18 13:00:26.828709 2026] [security2:error] [pid 123784:tid 123942] [client 20.124.247.79:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2-gAAABg"] [Tue Aug 18 13:00:26.832146 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/domvf.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2-wAAADA"] [Tue Aug 18 13:00:26.873496 2026] [security2:error] [pid 123784:tid 124018] [client 79.127.164.8:34676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wbboardacplibinserts.sql"] [unique_id "aoSBmmwDnJBNj2tDbYb2_AAAAGQ"], referer: https://medihub.com.br/wbboardacplibinserts.sql [Tue Aug 18 13:00:26.898021 2026] [security2:error] [pid 123784:tid 123880] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/xamp.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2_gAANFs"] [Tue Aug 18 13:00:26.941563 2026] [security2:error] [pid 123784:tid 123923] [client 86.120.159.145:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AAAAAAU"] [Tue Aug 18 13:00:26.941635 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:17268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/images/wso.php"] [unique_id "aoSBmmwDnJBNj2tDbYb2_wAAAEs"] [Tue Aug 18 13:00:26.941673 2026] [security2:error] [pid 123784:tid 123923] [client 86.120.159.145:49608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AAAAAAU"] [Tue Aug 18 13:00:26.942161 2026] [security2:error] [pid 123784:tid 123859] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/"] [unique_id "aoSBmmwDnJBNj2tDbYb3AQAADkY"] [Tue Aug 18 13:00:26.944386 2026] [security2:error] [pid 123784:tid 123987] [client 20.250.27.191:35709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/i.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3AwAAAEU"] [Tue Aug 18 13:00:26.952843 2026] [security2:error] [pid 123784:tid 123938] [client 158.23.17.4:38863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/app.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3BAAAABQ"] [Tue Aug 18 13:00:26.982836 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:65319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/rymmm.php"] [unique_id "aoSBmmwDnJBNj2tDbYb3BQAAAFI"] [Tue Aug 18 13:00:27.003157 2026] [security2:error] [pid 123784:tid 124005] [client 20.116.17.175:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/privdayz.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CAAAAFc"] [Tue Aug 18 13:00:27.003459 2026] [security2:error] [pid 123784:tid 123998] [client 20.65.98.162:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/dex.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CQAAAFA"] [Tue Aug 18 13:00:27.029026 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ge.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3CwAAAGw"] [Tue Aug 18 13:00:27.034756 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.36.136:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/lddxs.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DAAAACI"] [Tue Aug 18 13:00:27.062320 2026] [security2:error] [pid 123784:tid 124019] [client 20.79.204.6:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/jquery.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DgAAAGU"] [Tue Aug 18 13:00:27.071383 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:47917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/f.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3DwAAAFY"] [Tue Aug 18 13:00:27.088673 2026] [security2:error] [pid 123784:tid 123953] [client 20.226.36.136:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zjggu.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EAAAACM"] [Tue Aug 18 13:00:27.103943 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:46855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/w1.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EQAAAAA"] [Tue Aug 18 13:00:27.119886 2026] [security2:error] [pid 123784:tid 123963] [client 172.202.39.151:44579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/as.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3EgAAAC0"] [Tue Aug 18 13:00:27.128661 2026] [security2:error] [pid 123784:tid 123991] [client 20.124.247.79:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/av.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3FgAAAEk"] [Tue Aug 18 13:00:27.130358 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.100.201:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/img.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3FwAAAGM"] [Tue Aug 18 13:00:27.131094 2026] [security2:error] [pid 123784:tid 123909] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/inputs.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3GAAAEng"] [Tue Aug 18 13:00:27.138450 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3GgAAADM"] [Tue Aug 18 13:00:27.170788 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ge.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3IgAAADk"] [Tue Aug 18 13:00:27.177931 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.36.136:62199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/dlvqo.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3IwAAAEQ"] [Tue Aug 18 13:00:27.213043 2026] [security2:error] [pid 123784:tid 123921] [client 158.158.74.177:23724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JQAAAAM"] [Tue Aug 18 13:00:27.238591 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.156.252:7218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/site.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JgAAAHg"] [Tue Aug 18 13:00:27.249995 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.36.136:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/pkmoj.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3JwAAAB4"] [Tue Aug 18 13:00:27.276296 2026] [security2:error] [pid 123784:tid 123901] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/bless.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3KQAAIHA"] [Tue Aug 18 13:00:27.286699 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wg459o.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3KgAAAF4"] [Tue Aug 18 13:00:27.308578 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:27.309045 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:27.326761 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/aa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3LQAAAF8"] [Tue Aug 18 13:00:27.340220 2026] [security2:error] [pid 123784:tid 123957] [client 20.203.138.185:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ex.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3LwAAACc"] [Tue Aug 18 13:00:27.350022 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.27.191:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/abcd.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3MAAAAGo"] [Tue Aug 18 13:00:27.379142 2026] [security2:error] [pid 123784:tid 123795] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/"] [unique_id "aoSBm2wDnJBNj2tDbYb3MgAAPAY"] [Tue Aug 18 13:00:27.421358 2026] [security2:error] [pid 123784:tid 123966] [client 20.124.247.79:16643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/images.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3MwAAADA"] [Tue Aug 18 13:00:27.450858 2026] [security2:error] [pid 123784:tid 124018] [client 20.65.98.162:28975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3OQAAAGQ"] [Tue Aug 18 13:00:27.473479 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.36.136:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/kopyw.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3OwAAAHw"] [Tue Aug 18 13:00:27.517473 2026] [security2:error] [pid 123784:tid 123923] [client 40.74.65.169:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/fpwch.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3PQAAAAU"] [Tue Aug 18 13:00:27.523052 2026] [security2:error] [pid 123784:tid 123933] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3PwAAAA8"] [Tue Aug 18 13:00:27.536016 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.100.201:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QAAAAEU"] [Tue Aug 18 13:00:27.555100 2026] [security2:error] [pid 123784:tid 123849] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/alfa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QQAAUTw"] [Tue Aug 18 13:00:27.564549 2026] [security2:error] [pid 123784:tid 123926] [client 20.100.169.31:22599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/index/function.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3QgAAAAg"] [Tue Aug 18 13:00:27.597684 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.156.252:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/ccc.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RAAAACY"] [Tue Aug 18 13:00:27.604952 2026] [security2:error] [pid 123784:tid 123919] [client 213.35.127.232:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RQAAAAE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:27.609066 2026] [security2:error] [pid 123784:tid 123891] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file25.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RgAANmY"] [Tue Aug 18 13:00:27.615659 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mifta.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3RwAAACI"] [Tue Aug 18 13:00:27.639413 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tp.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3SgAAACw"] [Tue Aug 18 13:00:27.681142 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.36.136:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zznmg.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3SwAAADs"] [Tue Aug 18 13:00:27.698217 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/media-new.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TAAAAGA"] [Tue Aug 18 13:00:27.713328 2026] [security2:error] [pid 123784:tid 124017] [client 20.124.247.79:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/ops.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TQAAAGM"] [Tue Aug 18 13:00:27.732406 2026] [security2:error] [pid 123784:tid 123857] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lock360.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TgAAdUQ"] [Tue Aug 18 13:00:27.733879 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kl.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3TwAAAD8"] [Tue Aug 18 13:00:27.757420 2026] [security2:error] [pid 123784:tid 123974] [client 135.225.78.186:27960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/aa.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3UAAAADg"] [Tue Aug 18 13:00:27.770825 2026] [security2:error] [pid 123784:tid 123924] [client 20.250.27.191:43459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3UgAAAAY"] [Tue Aug 18 13:00:27.796162 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:65307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/bhfnd.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VAAAADo"] [Tue Aug 18 13:00:27.846742 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/goods.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VQAAAHA"] [Tue Aug 18 13:00:27.860882 2026] [security2:error] [pid 123784:tid 123971] [client 158.158.74.177:23727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/meta.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VgAAADU"] [Tue Aug 18 13:00:27.870796 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3VwAAAC4"] [Tue Aug 18 13:00:27.901042 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XAAAAAQ"] [Tue Aug 18 13:00:27.906995 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:27.907283 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:27.938083 2026] [security2:error] [pid 123784:tid 123864] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/flower.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XQAAeEs"] [Tue Aug 18 13:00:27.940411 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.36.136:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/qfvqu.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XgAAAB4"] [Tue Aug 18 13:00:27.943777 2026] [security2:error] [pid 123784:tid 123834] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file15.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3XwAAMi0"] [Tue Aug 18 13:00:27.964180 2026] [security2:error] [pid 123784:tid 123833] [remote 162.214.184.71:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3YQAAHCw"] [Tue Aug 18 13:00:27.987832 2026] [security2:error] [pid 123784:tid 123947] [client 20.124.247.79:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/coffexium.php"] [unique_id "aoSBm2wDnJBNj2tDbYb3ZAAAAB0"] [Tue Aug 18 13:00:28.018031 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:29446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/87.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ZQAAAHY"] [Tue Aug 18 13:00:28.033713 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.156.252:23165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ZgAAAH0"] [Tue Aug 18 13:00:28.101789 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.36.136:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/oivcl.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3aQAAAGc"] [Tue Aug 18 13:00:28.120514 2026] [security2:error] [pid 123784:tid 123934] [client 172.202.39.151:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3awAAABA"] [Tue Aug 18 13:00:28.132495 2026] [security2:error] [pid 123784:tid 123916] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/13.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3bAAAGH8"] [Tue Aug 18 13:00:28.161587 2026] [security2:error] [pid 123784:tid 124003] [client 20.203.138.185:10555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/tax.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3bQAAAFU"] [Tue Aug 18 13:00:28.186574 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.27.191:40130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cAAAADQ"] [Tue Aug 18 13:00:28.188158 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/index2.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cQAAAFQ"] [Tue Aug 18 13:00:28.195888 2026] [security2:error] [pid 123784:tid 123941] [client 20.100.169.31:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/info.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3cgAAABc"] [Tue Aug 18 13:00:28.209033 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:28.209307 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:28.219230 2026] [security2:error] [pid 123784:tid 123980] [client 40.74.65.169:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/sf.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3dQAAAD4"] [Tue Aug 18 13:00:28.281939 2026] [security2:error] [pid 123784:tid 124015] [client 20.124.247.79:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3eQAAAGE"] [Tue Aug 18 13:00:28.301614 2026] [security2:error] [pid 123784:tid 123926] [client 20.104.100.201:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ewAAAAg"] [Tue Aug 18 13:00:28.306317 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:20203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gs.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3fAAAAFc"] [Tue Aug 18 13:00:28.322631 2026] [security2:error] [pid 123784:tid 123856] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/f35.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3fgAAEUM"] [Tue Aug 18 13:00:28.332639 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gAAAKFQ"] [Tue Aug 18 13:00:28.342861 2026] [security2:error] [pid 123784:tid 123990] [client 103.120.71.157:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gQAAAEg"] [Tue Aug 18 13:00:28.343040 2026] [security2:error] [pid 123784:tid 123990] [client 103.120.71.157:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gQAAAEg"] [Tue Aug 18 13:00:28.371714 2026] [security2:error] [pid 123784:tid 123995] [client 20.79.204.6:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3gwAAAE0"] [Tue Aug 18 13:00:28.376166 2026] [security2:error] [pid 123784:tid 123961] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/php8.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3hAAAACs"] [Tue Aug 18 13:00:28.468830 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/8.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iAAAABo"] [Tue Aug 18 13:00:28.481552 2026] [security2:error] [pid 123784:tid 123925] [client 158.158.74.177:23683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mini.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iQAAAAc"] [Tue Aug 18 13:00:28.494865 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.156.252:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/reviall.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3iwAAAA4"] [Tue Aug 18 13:00:28.505288 2026] [security2:error] [pid 123784:tid 123963] [client 20.226.36.136:61460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zugvi.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jQAAAC0"] [Tue Aug 18 13:00:28.513528 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:28.513806 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:28.518117 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:55193] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lavobotafogo.com"] [uri "/1.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jwAAAHU"] [Tue Aug 18 13:00:28.518233 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:55193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/1.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3jwAAAHU"] [Tue Aug 18 13:00:28.555438 2026] [security2:error] [pid 123784:tid 123872] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko-new.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3kgAAP1M"] [Tue Aug 18 13:00:28.571772 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.156.252:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/img.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3kwAAADM"] [Tue Aug 18 13:00:28.575862 2026] [security2:error] [pid 123784:tid 123939] [client 20.124.247.79:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/sf.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3lAAAABU"] [Tue Aug 18 13:00:28.608065 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:29494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zi.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3lwAAAAI"] [Tue Aug 18 13:00:28.615025 2026] [security2:error] [pid 123784:tid 124022] [client 20.250.27.191:63182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3mAAAAGg"] [Tue Aug 18 13:00:28.622605 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3mQAAAFE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:28.659211 2026] [security2:error] [pid 123784:tid 123866] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-load.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3nAAANU0"] [Tue Aug 18 13:00:28.699516 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/info.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ngAAAF0"] [Tue Aug 18 13:00:28.745938 2026] [security2:error] [pid 123784:tid 124020] [client 20.116.17.175:58114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/images.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3oQAAAGY"] [Tue Aug 18 13:00:28.753908 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/30.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3ogAAADI"] [Tue Aug 18 13:00:28.764792 2026] [security2:error] [pid 123784:tid 123855] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content.php.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3pAAAHEI"] [Tue Aug 18 13:00:28.776771 2026] [security2:error] [pid 123784:tid 123996] [client 20.104.100.201:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3pQAAAE4"] [Tue Aug 18 13:00:28.811154 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:28.811564 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:28.821796 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.36.136:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wsrer.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3qQAAAF4"] [Tue Aug 18 13:00:28.829052 2026] [security2:error] [pid 123784:tid 124043] [client 20.124.247.79:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/k.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3rgAAAH0"] [Tue Aug 18 13:00:28.830608 2026] [security2:error] [pid 123784:tid 124030] [client 20.100.169.31:4027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/profile.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3rwAAAHA"] [Tue Aug 18 13:00:28.869845 2026] [security2:error] [pid 123784:tid 124021] [client 68.155.156.252:48090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/nope.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3sAAAAGc"] [Tue Aug 18 13:00:28.902921 2026] [security2:error] [pid 123784:tid 123966] [client 40.74.65.169:60227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xx.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3sQAAADA"] [Tue Aug 18 13:00:28.913534 2026] [security2:error] [pid 123784:tid 124003] [client 172.202.39.151:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3swAAAFU"] [Tue Aug 18 13:00:28.939699 2026] [security2:error] [pid 123784:tid 123890] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/01.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3tAAAVGU"] [Tue Aug 18 13:00:28.978048 2026] [security2:error] [pid 123784:tid 124031] [client 20.79.204.6:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSBnGwDnJBNj2tDbYb3tgAAAHE"] [Tue Aug 18 13:00:29.034439 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vAAAACQ"] [Tue Aug 18 13:00:29.038786 2026] [security2:error] [pid 123784:tid 123992] [client 20.116.17.175:58148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/a.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vQAAAEo"] [Tue Aug 18 13:00:29.078757 2026] [security2:error] [pid 123784:tid 123990] [client 20.124.247.79:16663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/82.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3vwAAAEg"] [Tue Aug 18 13:00:29.113747 2026] [security2:error] [pid 123784:tid 124024] [client 20.203.138.185:18852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/X7x.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3wwAAAGo"] [Tue Aug 18 13:00:29.115916 2026] [security2:error] [pid 123784:tid 123792] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lv.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xAAAJgM"] [Tue Aug 18 13:00:29.116658 2026] [security2:error] [pid 123784:tid 124016] [client 158.158.74.177:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/mm.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xQAAAGI"] [Tue Aug 18 13:00:29.122247 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:29.122712 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:29.128333 2026] [security2:error] [pid 123784:tid 123995] [client 20.104.100.201:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/term.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3xgAAAE0"] [Tue Aug 18 13:00:29.224457 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/92.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3ygAAAAc"] [Tue Aug 18 13:00:29.238021 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.36.136:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/ucpfr.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3ywAAABs"] [Tue Aug 18 13:00:29.243864 2026] [security2:error] [pid 123784:tid 124014] [client 172.202.39.151:40373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zAAAAGA"] [Tue Aug 18 13:00:29.269761 2026] [security2:error] [pid 123784:tid 123981] [client 20.250.27.191:28004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/simple.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zgAAAD8"] [Tue Aug 18 13:00:29.270534 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:38276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lw.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3zwAAAFo"] [Tue Aug 18 13:00:29.297159 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/new.php"] [unique_id "aoSBnWwDnJBNj2tDbYb30gAADWw"] [Tue Aug 18 13:00:29.306809 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.36.136:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/yxijx.php"] [unique_id "aoSBnWwDnJBNj2tDbYb30wAAAG8"] [Tue Aug 18 13:00:29.306826 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:23160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/nope.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31AAAAAI"] [Tue Aug 18 13:00:29.329413 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:65294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/zwlsv.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31gAAAEc"] [Tue Aug 18 13:00:29.342902 2026] [security2:error] [pid 123784:tid 123922] [client 20.124.247.79:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/dex.php"] [unique_id "aoSBnWwDnJBNj2tDbYb31wAAAAQ"] [Tue Aug 18 13:00:29.364535 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSBnWwDnJBNj2tDbYb32gAAAHg"] [Tue Aug 18 13:00:29.377908 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.36.136:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/jrpga.php"] [unique_id "aoSBnWwDnJBNj2tDbYb33AAAADI"] [Tue Aug 18 13:00:29.409229 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBnWwDnJBNj2tDbYb33wAAADo"] [Tue Aug 18 13:00:29.415758 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:29.416019 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:29.437687 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/simple.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34AAAAH0"] [Tue Aug 18 13:00:29.452579 2026] [security2:error] [pid 123784:tid 124017] [client 20.100.169.31:3781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/sx.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34QAAAGM"] [Tue Aug 18 13:00:29.473569 2026] [security2:error] [pid 123784:tid 123835] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/222.php"] [unique_id "aoSBnWwDnJBNj2tDbYb34wAAAC4"] [Tue Aug 18 13:00:29.499231 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/nwwha.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35QAAADc"] [Tue Aug 18 13:00:29.515192 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/black.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35gAAAFw"] [Tue Aug 18 13:00:29.518935 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pu.php"] [unique_id "aoSBnWwDnJBNj2tDbYb35wAAAGQ"] [Tue Aug 18 13:00:29.567453 2026] [security2:error] [pid 123784:tid 124001] [client 20.226.36.136:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/opsqt.php"] [unique_id "aoSBnWwDnJBNj2tDbYb36gAAAFM"] [Tue Aug 18 13:00:29.587499 2026] [security2:error] [pid 123784:tid 123946] [client 20.79.204.6:14043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSBnWwDnJBNj2tDbYb36wAAABw"] [Tue Aug 18 13:00:29.601424 2026] [security2:error] [pid 123784:tid 123951] [client 40.74.65.169:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/adminner.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37AAAACE"] [Tue Aug 18 13:00:29.610326 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.36.136:53556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/jvcpa.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37QAAAFA"] [Tue Aug 18 13:00:29.616567 2026] [security2:error] [pid 123784:tid 123956] [client 135.225.78.186:65174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/img.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37gAAACY"] [Tue Aug 18 13:00:29.635564 2026] [security2:error] [pid 123784:tid 124032] [client 213.35.127.232:60037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBnWwDnJBNj2tDbYb37wAAAHI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:29.636621 2026] [security2:error] [pid 123784:tid 124016] [client 20.124.247.79:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/puc.php"] [unique_id "aoSBnWwDnJBNj2tDbYb38AAAAGI"] [Tue Aug 18 13:00:29.672246 2026] [security2:error] [pid 123784:tid 123847] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39QAAPDo"] [Tue Aug 18 13:00:29.674436 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/99.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39gAAACI"] [Tue Aug 18 13:00:29.675626 2026] [security2:error] [pid 123784:tid 124019] [client 20.226.36.136:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBnWwDnJBNj2tDbYb39wAAAGU"] [Tue Aug 18 13:00:29.697185 2026] [security2:error] [pid 123784:tid 123925] [client 68.155.156.252:50903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/new.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3-QAAAAc"] [Tue Aug 18 13:00:29.704846 2026] [security2:error] [pid 123784:tid 123877] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3-gAAdVg"] [Tue Aug 18 13:00:29.715463 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:29.715730 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:29.716465 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.36.136:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBnWwDnJBNj2tDbYb3_AAAABI"] [Tue Aug 18 13:00:29.725878 2026] [security2:error] [pid 123784:tid 123842] [remote 156.59.198.135:40946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/semed2022-1/convocacao_26-04-2022.pdf"] [unique_id "aoSBnWwDnJBNj2tDbYb3_gAAWjU"] [Tue Aug 18 13:00:29.746425 2026] [security2:error] [pid 123784:tid 123941] [client 158.158.74.177:23705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4AAAAABc"] [Tue Aug 18 13:00:29.758249 2026] [security2:error] [pid 123784:tid 124029] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4BAAAAG8"] [Tue Aug 18 13:00:29.785376 2026] [security2:error] [pid 123784:tid 123999] [client 20.203.138.185:16788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ocxla.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4CQAAAFE"] [Tue Aug 18 13:00:29.820469 2026] [security2:error] [pid 123784:tid 123922] [client 20.226.36.136:62157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DAAAAAQ"] [Tue Aug 18 13:00:29.863637 2026] [security2:error] [pid 123784:tid 123796] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/info.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DwAAXwc"] [Tue Aug 18 13:00:29.899759 2026] [security2:error] [pid 123784:tid 123927] [client 20.124.247.79:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/inso.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4EQAAAAk"] [Tue Aug 18 13:00:29.908282 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:31928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vj.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4EwAAADo"] [Tue Aug 18 13:00:29.921514 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.100.201:61960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/as.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4FQAAAB0"] [Tue Aug 18 13:00:29.973031 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.27.191:35685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/chosen.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4FgAAAFc"] [Tue Aug 18 13:00:29.992059 2026] [security2:error] [pid 123784:tid 123965] [client 20.116.17.175:59981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yup.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4GAAAAC8"] [Tue Aug 18 13:00:30.017834 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.36.136:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4GwAAAFw"] [Tue Aug 18 13:00:30.026075 2026] [security2:error] [pid 123784:tid 123940] [client 20.250.13.23:46093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBnWwDnJBNj2tDbYb4DgAAABY"] [Tue Aug 18 13:00:30.035124 2026] [security2:error] [pid 123784:tid 123789] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/aaa.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HAAANAA"] [Tue Aug 18 13:00:30.059971 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HQAAACg"] [Tue Aug 18 13:00:30.062067 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.36.136:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HgAAAEs"] [Tue Aug 18 13:00:30.062356 2026] [security2:error] [pid 123784:tid 123870] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/html-api/"] [unique_id "aoSBnmwDnJBNj2tDbYb4HwAAFFE"] [Tue Aug 18 13:00:30.063246 2026] [security2:error] [pid 123784:tid 124028] [client 66.132.172.99:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.172.132.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlantica.goptur.app.br"] [uri "/index.php/login"] [unique_id "aoSBnWwDnJBNj2tDbYb4EAAAAG4"] [Tue Aug 18 13:00:30.063803 2026] [security2:error] [pid 123784:tid 124031] [client 68.155.156.252:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IAAAAHE"] [Tue Aug 18 13:00:30.091247 2026] [security2:error] [pid 123784:tid 123968] [client 20.100.169.31:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IQAAADI"] [Tue Aug 18 13:00:30.091931 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/av.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4IwAAAAg"] [Tue Aug 18 13:00:30.121552 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jm.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JAAAACE"] [Tue Aug 18 13:00:30.168189 2026] [security2:error] [pid 123784:tid 123956] [client 20.124.247.79:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/aa.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JgAAACY"] [Tue Aug 18 13:00:30.171469 2026] [security2:error] [pid 123784:tid 124032] [client 20.226.36.136:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4JwAAAHI"] [Tue Aug 18 13:00:30.195665 2026] [security2:error] [pid 123784:tid 124027] [client 20.79.204.6:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KQAAAG0"] [Tue Aug 18 13:00:30.242365 2026] [security2:error] [pid 123784:tid 123997] [client 103.184.169.37:42884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KwAAAE8"] [Tue Aug 18 13:00:30.242474 2026] [security2:error] [pid 123784:tid 123997] [client 103.184.169.37:42884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4KwAAAE8"] [Tue Aug 18 13:00:30.247473 2026] [security2:error] [pid 123784:tid 123845] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4LAAAaTg"] [Tue Aug 18 13:00:30.313188 2026] [security2:error] [pid 123784:tid 123929] [client 114.119.153.50:21583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "petceu.com.br"] [uri "/2017/12/page/2/"] [unique_id "aoSBnmwDnJBNj2tDbYb4MgAAAAs"], referer: https://petceu.com.br/2017/12?post_type=anjinhos [Tue Aug 18 13:00:30.317606 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:30.317992 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:30.325214 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:53679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4HQAAACg"] [Tue Aug 18 13:00:30.334847 2026] [security2:error] [pid 123784:tid 123941] [client 20.116.17.175:58159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NAAAABc"] [Tue Aug 18 13:00:30.362527 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NQAAAFI"] [Tue Aug 18 13:00:30.363109 2026] [security2:error] [pid 123784:tid 123801] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gecko.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4NgAAbww"] [Tue Aug 18 13:00:30.378774 2026] [security2:error] [pid 123784:tid 123920] [client 68.155.156.252:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/new.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4OAAAAAI"] [Tue Aug 18 13:00:30.420732 2026] [security2:error] [pid 123784:tid 123952] [client 158.158.74.177:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/moon.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4OwAAACI"] [Tue Aug 18 13:00:30.423687 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/post.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PAAAAEc"] [Tue Aug 18 13:00:30.431843 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/pucci.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PgAAAGw"] [Tue Aug 18 13:00:30.438338 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:10710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/term.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4PwAAAF4"] [Tue Aug 18 13:00:30.442717 2026] [security2:error] [pid 123784:tid 123986] [client 20.124.247.79:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/img.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QQAAAEQ"] [Tue Aug 18 13:00:30.462027 2026] [security2:error] [pid 123784:tid 123974] [client 102.213.179.104:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QwAAADg"] [Tue Aug 18 13:00:30.462246 2026] [security2:error] [pid 123784:tid 123974] [client 102.213.179.104:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4QwAAADg"] [Tue Aug 18 13:00:30.483196 2026] [security2:error] [pid 123784:tid 123798] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RAAAHgk"] [Tue Aug 18 13:00:30.487847 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.36.136:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RQAAAGY"] [Tue Aug 18 13:00:30.498100 2026] [security2:error] [pid 123784:tid 123972] [client 172.202.39.151:44575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RgAAADY"] [Tue Aug 18 13:00:30.515032 2026] [security2:error] [pid 123784:tid 124015] [client 135.225.78.186:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4RwAAAGE"] [Tue Aug 18 13:00:30.536618 2026] [security2:error] [pid 123784:tid 123933] [client 158.23.17.4:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kl.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4SwAAAA8"] [Tue Aug 18 13:00:30.549343 2026] [security2:error] [pid 123784:tid 123922] [client 138.36.100.162:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TQAAAAQ"] [Tue Aug 18 13:00:30.549436 2026] [security2:error] [pid 123784:tid 123922] [client 138.36.100.162:42684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TQAAAAQ"] [Tue Aug 18 13:00:30.553633 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mimes.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TgAAAHw"] [Tue Aug 18 13:00:30.577545 2026] [security2:error] [pid 123784:tid 124043] [client 20.38.3.247:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4TwAAAH0"] [Tue Aug 18 13:00:30.598678 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.36.136:61470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4UQAAAEY"] [Tue Aug 18 13:00:30.616594 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:30.616932 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:30.627179 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-temp.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VAAAAGQ"] [Tue Aug 18 13:00:30.637339 2026] [security2:error] [pid 123784:tid 123966] [client 158.23.17.4:47877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ry.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VQAAADA"] [Tue Aug 18 13:00:30.637402 2026] [security2:error] [pid 123784:tid 124009] [client 40.74.65.169:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4VgAAAFs"] [Tue Aug 18 13:00:30.642714 2026] [security2:error] [pid 123784:tid 124011] [client 157.20.138.62:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WAAAAF0"] [Tue Aug 18 13:00:30.642845 2026] [security2:error] [pid 123784:tid 124011] [client 157.20.138.62:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WAAAAF0"] [Tue Aug 18 13:00:30.649568 2026] [security2:error] [pid 123784:tid 124002] [client 20.250.27.191:63211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/als.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WQAAAFQ"] [Tue Aug 18 13:00:30.653594 2026] [security2:error] [pid 123784:tid 123981] [client 213.35.127.232:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WgAAAD8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:30.673168 2026] [security2:error] [pid 123784:tid 123799] [remote 129.121.48.235:48546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boscoagriturismo.com"] [uri "/wp-login.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4WwAAcwo"] [Tue Aug 18 13:00:30.683264 2026] [security2:error] [pid 123784:tid 123859] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/k.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XAAAd0Y"] [Tue Aug 18 13:00:30.689030 2026] [security2:error] [pid 123784:tid 123985] [client 20.100.169.31:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XQAAAEM"] [Tue Aug 18 13:00:30.693905 2026] [security2:error] [pid 123784:tid 124007] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4XgAAAFk"] [Tue Aug 18 13:00:30.695603 2026] [security2:error] [pid 123784:tid 123888] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/xiugai.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4YAAAcWM"] [Tue Aug 18 13:00:30.702868 2026] [security2:error] [pid 123784:tid 123957] [client 20.124.247.79:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/222.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4YQAAACc"] [Tue Aug 18 13:00:30.732889 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.36.136:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZAAAAFA"] [Tue Aug 18 13:00:30.733663 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.98.162:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/coffee.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZQAAACE"] [Tue Aug 18 13:00:30.749227 2026] [security2:error] [pid 123784:tid 124040] [client 20.104.100.201:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wicked.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ZwAAAHo"] [Tue Aug 18 13:00:30.798524 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wj.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4agAAAG0"] [Tue Aug 18 13:00:30.810103 2026] [security2:error] [pid 123784:tid 124005] [client 20.79.204.6:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/ebs.php7"] [unique_id "aoSBnmwDnJBNj2tDbYb4awAAAFc"] [Tue Aug 18 13:00:30.811645 2026] [security2:error] [pid 123784:tid 124019] [client 172.202.39.151:41114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bAAAAGU"] [Tue Aug 18 13:00:30.817986 2026] [security2:error] [pid 123784:tid 123919] [client 178.153.171.161:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bQAAAAE"] [Tue Aug 18 13:00:30.818142 2026] [security2:error] [pid 123784:tid 123919] [client 178.153.171.161:63445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bQAAAAE"] [Tue Aug 18 13:00:30.851836 2026] [security2:error] [pid 123784:tid 123977] [client 52.173.121.69:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4bwAAADs"] [Tue Aug 18 13:00:30.874192 2026] [security2:error] [pid 123784:tid 123829] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/"] [unique_id "aoSBnmwDnJBNj2tDbYb4cQAACyg"] [Tue Aug 18 13:00:30.922420 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:57977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/spadex.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4eQAAABo"] [Tue Aug 18 13:00:30.925040 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:30.925378 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:30.948466 2026] [security2:error] [pid 123784:tid 123949] [client 20.124.247.79:15331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/key.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4ewAAAB8"] [Tue Aug 18 13:00:30.963965 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.36.136:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4fgAAAEQ"] [Tue Aug 18 13:00:30.971611 2026] [security2:error] [pid 123784:tid 123930] [client 20.65.98.162:26923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4fwAAAAw"] [Tue Aug 18 13:00:31.014616 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/adminner.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4gQAACT4"] [Tue Aug 18 13:00:31.041080 2026] [security2:error] [pid 123784:tid 124023] [client 158.158.74.177:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/n.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ggAAAGk"] [Tue Aug 18 13:00:31.050214 2026] [security2:error] [pid 123784:tid 123894] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/403.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4gwAAD2k"] [Tue Aug 18 13:00:31.059489 2026] [security2:error] [pid 123784:tid 123922] [client 158.23.17.4:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ni.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hQAAAAQ"] [Tue Aug 18 13:00:31.074849 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.156.252:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/apreset.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hgAAAHQ"] [Tue Aug 18 13:00:31.095485 2026] [security2:error] [pid 123784:tid 124017] [client 20.104.100.201:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/water.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4hwAAAGM"] [Tue Aug 18 13:00:31.107990 2026] [security2:error] [pid 123784:tid 124010] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file2.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4iwAAAFw"] [Tue Aug 18 13:00:31.191872 2026] [security2:error] [pid 123784:tid 124036] [client 20.124.247.79:16672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/chosen.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4jgAAAHY"] [Tue Aug 18 13:00:31.193822 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/74.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4jwAAADQ"] [Tue Aug 18 13:00:31.206291 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:56761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gs.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4kAAAAF0"] [Tue Aug 18 13:00:31.224032 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:31.224458 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:31.235807 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.36.136:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4kgAAAEs"] [Tue Aug 18 13:00:31.244621 2026] [security2:error] [pid 123784:tid 123879] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/"] [unique_id "aoSBn2wDnJBNj2tDbYb4lAAABlo"] [Tue Aug 18 13:00:31.249662 2026] [security2:error] [pid 123784:tid 123985] [client 20.116.17.175:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lQAAAEM"] [Tue Aug 18 13:00:31.262654 2026] [security2:error] [pid 123784:tid 124030] [client 5.31.227.224:7826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lgAAAHA"] [Tue Aug 18 13:00:31.263698 2026] [security2:error] [pid 123784:tid 124001] [client 20.203.138.185:18839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/nhr.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lwAAAFM"] [Tue Aug 18 13:00:31.267319 2026] [security2:error] [pid 123784:tid 124030] [client 5.31.227.224:7826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4lgAAAHA"] [Tue Aug 18 13:00:31.302266 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4mgAAAAU"] [Tue Aug 18 13:00:31.308146 2026] [security2:error] [pid 123784:tid 123957] [client 20.250.27.191:40169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/nox.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4mwAAACc"] [Tue Aug 18 13:00:31.330467 2026] [security2:error] [pid 123784:tid 123926] [client 40.74.65.169:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wpxml.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4nQAAAAg"] [Tue Aug 18 13:00:31.334530 2026] [security2:error] [pid 123784:tid 123902] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file1221.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ngAAUHE"] [Tue Aug 18 13:00:31.335267 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pm.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4nwAAABE"] [Tue Aug 18 13:00:31.354629 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.156.252:62124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/key.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4oQAAADc"] [Tue Aug 18 13:00:31.417865 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/cache/"] [unique_id "aoSBn2wDnJBNj2tDbYb4swAALFQ"] [Tue Aug 18 13:00:31.419585 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:14079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4tAAAAFQ"] [Tue Aug 18 13:00:31.451182 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4tgAAAFg"] [Tue Aug 18 13:00:31.458239 2026] [security2:error] [pid 123784:tid 123892] [remote 115.146.125.52:42002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4twAAa2c"] [Tue Aug 18 13:00:31.492666 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/default.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vAAAAAA"] [Tue Aug 18 13:00:31.499006 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.156.252:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1mage.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vQAAAAs"] [Tue Aug 18 13:00:31.507531 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:34279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fine.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vgAAAA0"] [Tue Aug 18 13:00:31.511062 2026] [security2:error] [pid 123784:tid 123939] [client 68.155.154.236:55481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4vwAAABU"] [Tue Aug 18 13:00:31.526330 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:4025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4wgAAAGg"] [Tue Aug 18 13:00:31.536122 2026] [security2:error] [pid 123784:tid 123954] [client 20.124.247.79:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/wpxml.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4wwAAACQ"] [Tue Aug 18 13:00:31.554952 2026] [security2:error] [pid 123784:tid 123944] [client 20.116.17.175:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/srontol.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4xQAAABo"] [Tue Aug 18 13:00:31.559872 2026] [security2:error] [pid 123784:tid 123989] [client 135.225.78.186:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/key.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4xgAAAEc"] [Tue Aug 18 13:00:31.566110 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:32556] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vistadasmangueiras.com.br"] [uri "/1.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4yAAAAGw"] [Tue Aug 18 13:00:31.566234 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:32556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/1.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4yAAAAGw"] [Tue Aug 18 13:00:31.603133 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4ygAADDs"] [Tue Aug 18 13:00:31.661916 2026] [security2:error] [pid 123784:tid 123982] [client 158.158.74.177:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/nc4.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4zAAAAEA"] [Tue Aug 18 13:00:31.676003 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4zQAAABw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:31.703536 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/av.php"] [unique_id "aoSBn2wDnJBNj2tDbYb42QAAADU"] [Tue Aug 18 13:00:31.723240 2026] [security2:error] [pid 123784:tid 123789] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inx.php"] [unique_id "aoSBn2wDnJBNj2tDbYb4_AAAJQA"] [Tue Aug 18 13:00:31.758088 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file59.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5AQAAAFw"] [Tue Aug 18 13:00:31.776248 2026] [security2:error] [pid 123784:tid 123800] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/"] [unique_id "aoSBn2wDnJBNj2tDbYb5AwAAFgs"] [Tue Aug 18 13:00:31.816986 2026] [security2:error] [pid 123784:tid 123981] [client 52.173.121.69:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5CgAAAD8"] [Tue Aug 18 13:00:31.820457 2026] [security2:error] [pid 123784:tid 123993] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/alfa.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5CwAAAEs"] [Tue Aug 18 13:00:31.820538 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:31.820807 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:31.825974 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/loader.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5DQAAAC4"] [Tue Aug 18 13:00:31.844596 2026] [security2:error] [pid 123784:tid 124031] [client 20.116.17.175:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/file5.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5EgAAAHE"] [Tue Aug 18 13:00:31.879864 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/imsc.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5EwAAABs"] [Tue Aug 18 13:00:31.879864 2026] [security2:error] [pid 123784:tid 123961] [client 20.124.247.79:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/file1221.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5FAAAACs"] [Tue Aug 18 13:00:31.926892 2026] [security2:error] [pid 123784:tid 123990] [client 78.46.215.1:25058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSBnmwDnJBNj2tDbYb4MwAAAEg"], referer: https://www.parquefazendadasflores.com.br [Tue Aug 18 13:00:31.968763 2026] [security2:error] [pid 123784:tid 123915] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/aa.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5GAAAfn4"] [Tue Aug 18 13:00:31.969247 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.138.185:19767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBn2wDnJBNj2tDbYb5GQAAAGI"] [Tue Aug 18 13:00:32.018833 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.120:28824] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:32.019120 2026] [authz_core:error] [pid 123784:tid 123888] [remote 57.141.22.120:28824] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:32.028176 2026] [security2:error] [pid 123784:tid 124025] [client 168.62.48.100:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5HgAAAGs"] [Tue Aug 18 13:00:32.050354 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5IAAAAHc"] [Tue Aug 18 13:00:32.126763 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:44852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/88.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KAAAAGg"] [Tue Aug 18 13:00:32.143098 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.36.136:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KQAAAAM"] [Tue Aug 18 13:00:32.144966 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KgAAABo"] [Tue Aug 18 13:00:32.145072 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KgAAABo"] [Tue Aug 18 13:00:32.145110 2026] [security2:error] [pid 123784:tid 123900] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/0x.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5KwAAFG8"] [Tue Aug 18 13:00:32.150535 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/reviall.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5LQAAXj4"] [Tue Aug 18 13:00:32.154526 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yup.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5LgAAAEQ"] [Tue Aug 18 13:00:32.163172 2026] [security2:error] [pid 123784:tid 123977] [client 52.22.236.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5HwAAOwg"], referer: https://tecpolorefrigeracaosp.com.br/ [Tue Aug 18 13:00:32.181000 2026] [security2:error] [pid 123784:tid 123997] [client 223.185.37.47:24175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NAAAAE8"] [Tue Aug 18 13:00:32.181158 2026] [security2:error] [pid 123784:tid 123997] [client 223.185.37.47:24175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NAAAAE8"] [Tue Aug 18 13:00:32.202696 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:40173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/admin.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NgAAABM"] [Tue Aug 18 13:00:32.208074 2026] [security2:error] [pid 123784:tid 123930] [client 20.104.100.201:61399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/zero.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5NwAAAAw"] [Tue Aug 18 13:00:32.221711 2026] [security2:error] [pid 123784:tid 123948] [client 51.116.232.28:19067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OAAAAB4"] [Tue Aug 18 13:00:32.226297 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.156.252:8106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/imscjpg.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OQAAAGY"] [Tue Aug 18 13:00:32.254428 2026] [security2:error] [pid 123784:tid 123879] [remote 115.146.125.52:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5OwAAPlo"] [Tue Aug 18 13:00:32.274109 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10737] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PAAAABI"] [Tue Aug 18 13:00:32.274233 2026] [security2:error] [pid 123784:tid 123936] [client 20.79.204.6:10737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PAAAABI"] [Tue Aug 18 13:00:32.284241 2026] [security2:error] [pid 123784:tid 123929] [client 158.158.74.177:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/new.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PgAAAAs"] [Tue Aug 18 13:00:32.293306 2026] [security2:error] [pid 123784:tid 123946] [client 20.124.247.79:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/nox.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5PwAAABw"] [Tue Aug 18 13:00:32.294067 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:25406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lw.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5QAAAAAc"] [Tue Aug 18 13:00:32.321806 2026] [security2:error] [pid 123784:tid 123901] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/zxz.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5RQAAHXA"] [Tue Aug 18 13:00:32.333098 2026] [security2:error] [pid 123784:tid 123933] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5QgAAD3o"] [Tue Aug 18 13:00:32.410932 2026] [security2:error] [pid 123784:tid 124009] [client 20.100.169.31:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5SAAAAFs"] [Tue Aug 18 13:00:32.472061 2026] [security2:error] [pid 123784:tid 123964] [client 20.116.17.175:58127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5SwAAAC4"] [Tue Aug 18 13:00:32.510097 2026] [security2:error] [pid 123784:tid 124028] [client 20.104.100.201:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/002.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5TgAAAG4"] [Tue Aug 18 13:00:32.516905 2026] [security2:error] [pid 123784:tid 124034] [client 4.232.94.69:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/file56.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5TwAAAHQ"] [Tue Aug 18 13:00:32.527442 2026] [security2:error] [pid 123784:tid 124001] [client 147.53.121.226:56689] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UAAAAFM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:32.529735 2026] [security2:error] [pid 123784:tid 123814] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/www.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UQAAcBk"] [Tue Aug 18 13:00:32.540042 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/222.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UgAAABs"] [Tue Aug 18 13:00:32.563048 2026] [security2:error] [pid 123784:tid 123916] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/11.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5VgAAZ38"] [Tue Aug 18 13:00:32.580147 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.156.252:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/chosen.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5VwAAAH4"] [Tue Aug 18 13:00:32.602518 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dr.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WAAAAGI"] [Tue Aug 18 13:00:32.608422 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.156.252:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/qlex1.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WQAAAEU"] [Tue Aug 18 13:00:32.642774 2026] [security2:error] [pid 123784:tid 124006] [client 51.116.232.28:19013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5WwAAAFg"] [Tue Aug 18 13:00:32.650176 2026] [security2:error] [pid 123784:tid 124025] [client 20.124.247.79:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/akismet.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5XQAAAGs"] [Tue Aug 18 13:00:32.655161 2026] [security2:error] [pid 123784:tid 123993] [client 20.79.204.6:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/lite.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5XgAAAEs"] [Tue Aug 18 13:00:32.658367 2026] [security2:error] [pid 123784:tid 123963] [client 52.173.121.69:57720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/weozh.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5YAAAAC0"] [Tue Aug 18 13:00:32.676424 2026] [security2:error] [pid 123784:tid 124037] [client 20.250.27.191:40163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aa2.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5YQAAAHc"] [Tue Aug 18 13:00:32.693863 2026] [security2:error] [pid 123784:tid 124045] [client 213.35.127.232:60665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZAAAAH8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:32.710378 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wicked.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZQAAVmE"] [Tue Aug 18 13:00:32.710792 2026] [security2:error] [pid 123784:tid 123931] [client 20.226.56.190:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/zj.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ZgAAAA0"] [Tue Aug 18 13:00:32.728903 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:32.729337 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:32.748793 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.138.185:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ws79.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5aQAAAEc"] [Tue Aug 18 13:00:32.778100 2026] [security2:error] [pid 123784:tid 124040] [client 79.127.164.8:34732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wpbackup.bak"] [unique_id "aoSBoGwDnJBNj2tDbYb5agAAAHo"], referer: https://medihub.com.br/wpbackup.bak [Tue Aug 18 13:00:32.779436 2026] [security2:error] [pid 123784:tid 123962] [client 20.127.136.245:27842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/inputs.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5awAAACw"] [Tue Aug 18 13:00:32.789288 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:44813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hj.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bAAAAF4"] [Tue Aug 18 13:00:32.793854 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.100.201:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/zxz.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bQAAADg"] [Tue Aug 18 13:00:32.839160 2026] [security2:error] [pid 123784:tid 123937] [client 20.116.17.175:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-the.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bgAAABM"] [Tue Aug 18 13:00:32.867930 2026] [security2:error] [pid 123784:tid 123972] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/asasx.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5bwAAADY"] [Tue Aug 18 13:00:32.888857 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:40368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5cQAAAF8"] [Tue Aug 18 13:00:32.903330 2026] [security2:error] [pid 123784:tid 123956] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5JwAAACY"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:00:32.904513 2026] [security2:error] [pid 123784:tid 124008] [client 158.158.74.177:23725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/packed.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5dAAAAFo"] [Tue Aug 18 13:00:32.913311 2026] [security2:error] [pid 123784:tid 123806] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/HLA-dd.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5dQAAYRE"] [Tue Aug 18 13:00:32.949417 2026] [security2:error] [pid 123784:tid 123929] [client 20.124.247.79:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/admin.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5eAAAAAs"] [Tue Aug 18 13:00:32.984100 2026] [security2:error] [pid 123784:tid 123955] [client 20.65.98.162:56502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/classwithtostring.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5egAAACU"] [Tue Aug 18 13:00:32.992346 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.156.252:7222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/mariju.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5ewAAAH0"] [Tue Aug 18 13:00:32.993079 2026] [security2:error] [pid 123784:tid 123942] [client 135.225.78.186:33973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/chosen.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5fAAAABg"] [Tue Aug 18 13:00:33.018014 2026] [security2:error] [pid 123784:tid 123794] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/File.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5gAAAagU"] [Tue Aug 18 13:00:33.030383 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5gQAAADs"] [Tue Aug 18 13:00:33.084329 2026] [security2:error] [pid 123784:tid 124009] [client 51.116.232.28:19041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5hgAAAFs"] [Tue Aug 18 13:00:33.093331 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/memberfuns.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5hwAAAFw"] [Tue Aug 18 13:00:33.097241 2026] [security2:error] [pid 123784:tid 123938] [client 20.79.204.6:10702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/alfa.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5iQAAABQ"] [Tue Aug 18 13:00:33.105868 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/i.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5iwAAADw"] [Tue Aug 18 13:00:33.107874 2026] [security2:error] [pid 123784:tid 123893] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5jAAAP2g"] [Tue Aug 18 13:00:33.117181 2026] [security2:error] [pid 123784:tid 123964] [client 20.116.17.175:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5jQAAAC4"] [Tue Aug 18 13:00:33.134982 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:33.135361 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:33.137761 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.27.191:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/xamp.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kAAAAG4"] [Tue Aug 18 13:00:33.158623 2026] [security2:error] [pid 123784:tid 124001] [client 147.53.121.226:56689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5UAAAAFM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:00:33.161667 2026] [security2:error] [pid 123784:tid 124035] [client 158.23.17.4:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vj.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kQAAAHU"] [Tue Aug 18 13:00:33.187551 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/filemanager.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5kgAAABE"] [Tue Aug 18 13:00:33.190953 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ag.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lAAAAGc"] [Tue Aug 18 13:00:33.211122 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:31882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ij.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lQAAADI"] [Tue Aug 18 13:00:33.239701 2026] [security2:error] [pid 123784:tid 123919] [client 20.124.247.79:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rgmadvogados.adv.br"] [uri "/ajax.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5lgAAAAE"] [Tue Aug 18 13:00:33.272334 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSBoWwDnJBNj2tDbYb5lwAAABY"] [Tue Aug 18 13:00:33.281309 2026] [security2:error] [pid 123784:tid 124037] [client 52.173.121.69:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/rymmm.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5mgAAAHc"] [Tue Aug 18 13:00:33.298010 2026] [security2:error] [pid 123784:tid 123855] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cah.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5mwAAf0I"] [Tue Aug 18 13:00:33.325123 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:47882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ts.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5nQAAAGg"] [Tue Aug 18 13:00:33.326081 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.36.136:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ngAAAFE"] [Tue Aug 18 13:00:33.328779 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:33.329184 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:33.351015 2026] [security2:error] [pid 123784:tid 123974] [client 20.203.138.185:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/rtx.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5oQAAADg"] [Tue Aug 18 13:00:33.357667 2026] [security2:error] [pid 123784:tid 123878] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fi22.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ogAAVVk"] [Tue Aug 18 13:00:33.374069 2026] [security2:error] [pid 123784:tid 123989] [client 167.235.143.113:15928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5nwAAAEc"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:00:33.396199 2026] [security2:error] [pid 123784:tid 123937] [client 68.155.156.252:8124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5pQAAABM"] [Tue Aug 18 13:00:33.404578 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/xwpg.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5pwAAAHg"] [Tue Aug 18 13:00:33.424789 2026] [security2:error] [pid 123784:tid 123918] [client 20.127.136.245:27888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5qQAAAAA"] [Tue Aug 18 13:00:33.439706 2026] [security2:error] [pid 123784:tid 123956] [client 20.104.100.201:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/aa.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5qgAAACY"] [Tue Aug 18 13:00:33.465262 2026] [autoindex:error] [pid 123784:tid 123973] [client 20.91.215.254:26311] AH01276: Cannot serve directory /home3/cp38imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:33.474783 2026] [security2:error] [pid 123784:tid 123897] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aoSBoWwDnJBNj2tDbYb5rgAAZmw"] [Tue Aug 18 13:00:33.513517 2026] [security2:error] [pid 123784:tid 123926] [client 51.116.232.28:18959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/av.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5sQAAAAg"] [Tue Aug 18 13:00:33.557842 2026] [security2:error] [pid 123784:tid 124032] [client 20.250.27.191:45814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/bless.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5tQAAAHI"] [Tue Aug 18 13:00:33.574772 2026] [security2:error] [pid 123784:tid 123992] [client 37.40.227.74:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5uAAAAEo"] [Tue Aug 18 13:00:33.579095 2026] [security2:error] [pid 123784:tid 123992] [client 37.40.227.74:56961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5uAAAAEo"] [Tue Aug 18 13:00:33.609122 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/themes.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ugAAAH0"] [Tue Aug 18 13:00:33.629914 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:33.630198 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:33.648796 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/system_log.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5vgAAamA"] [Tue Aug 18 13:00:33.674387 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:4009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5vwAAABI"] [Tue Aug 18 13:00:33.685819 2026] [security2:error] [pid 123784:tid 123977] [client 158.23.17.4:33419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ud.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wAAAADs"] [Tue Aug 18 13:00:33.688468 2026] [security2:error] [pid 123784:tid 123975] [client 20.116.17.175:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/dex.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wQAAADk"] [Tue Aug 18 13:00:33.710003 2026] [security2:error] [pid 123784:tid 123998] [client 213.35.127.232:60863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wgAAAFA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:33.726185 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.56.190:41945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/x.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5wwAAAFs"] [Tue Aug 18 13:00:33.767649 2026] [security2:error] [pid 123784:tid 124033] [client 158.158.74.177:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/plugin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5xQAAAHM"] [Tue Aug 18 13:00:33.768500 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.156.252:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/contacto.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5xgAAADM"] [Tue Aug 18 13:00:33.782306 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:51197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/53.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5yAAAAFk"] [Tue Aug 18 13:00:33.805474 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:63784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ig.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5ygAAABs"] [Tue Aug 18 13:00:33.827707 2026] [security2:error] [pid 123784:tid 123904] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/pomo/"] [unique_id "aoSBoWwDnJBNj2tDbYb5zAAAK3M"] [Tue Aug 18 13:00:33.831099 2026] [security2:error] [pid 123784:tid 123990] [client 20.104.100.201:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/echkm.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zQAAAEg"] [Tue Aug 18 13:00:33.837816 2026] [security2:error] [pid 123784:tid 123821] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zgAAESA"] [Tue Aug 18 13:00:33.883656 2026] [security2:error] [pid 123784:tid 123934] [client 20.79.204.6:14072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5zwAAABA"] [Tue Aug 18 13:00:33.906451 2026] [security2:error] [pid 123784:tid 123908] [remote 172.238.58.237:39336] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBoWwDnJBNj2tDbYb50AAAAnc"] [Tue Aug 18 13:00:33.926074 2026] [security2:error] [pid 123784:tid 124018] [client 51.116.232.28:19036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/images.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51AAAAGQ"] [Tue Aug 18 13:00:33.930537 2026] [security2:error] [pid 123784:tid 123810] [remote 47.128.57.70:46752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "igsautomoveis.com.br"] [uri "/veiculo/1019039/vw-volkswagen-polo-track-1-0-flex-12v-5p-2024"] [unique_id "aoSBoWwDnJBNj2tDbYb51QAAFxU"] [Tue Aug 18 13:00:33.931665 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:33.932110 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:33.972478 2026] [security2:error] [pid 123784:tid 124037] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51wAAAHc"] [Tue Aug 18 13:00:33.978572 2026] [security2:error] [pid 123784:tid 123927] [client 20.250.27.191:27969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file25.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52AAAAAk"] [Tue Aug 18 13:00:33.986658 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:25380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mimes.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52gAAAFY"] [Tue Aug 18 13:00:33.986924 2026] [security2:error] [pid 123784:tid 123950] [client 20.79.204.6:10743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/edit.php"] [unique_id "aoSBoWwDnJBNj2tDbYb52wAAACA"] [Tue Aug 18 13:00:34.003031 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb53AAANEA"] [Tue Aug 18 13:00:34.023539 2026] [security2:error] [pid 123784:tid 123999] [client 20.226.36.136:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBomwDnJBNj2tDbYb53gAAAFE"] [Tue Aug 18 13:00:34.029695 2026] [security2:error] [pid 123784:tid 123931] [client 192.141.172.134:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb54AAAAA0"] [Tue Aug 18 13:00:34.029870 2026] [security2:error] [pid 123784:tid 123931] [client 192.141.172.134:58033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojaodovidraceiro.com"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb54AAAAA0"] [Tue Aug 18 13:00:34.053617 2026] [security2:error] [pid 123784:tid 123923] [client 172.202.39.151:53753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/k.php"] [unique_id "aoSBomwDnJBNj2tDbYb54QAAAAU"] [Tue Aug 18 13:00:34.070364 2026] [security2:error] [pid 123784:tid 124003] [client 20.116.17.175:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/xyn.php"] [unique_id "aoSBomwDnJBNj2tDbYb54gAAAFU"] [Tue Aug 18 13:00:34.081365 2026] [security2:error] [pid 123784:tid 123997] [client 20.65.98.162:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-ws68.php"] [unique_id "aoSBomwDnJBNj2tDbYb54wAAAE8"] [Tue Aug 18 13:00:34.095266 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.56.190:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yn.php"] [unique_id "aoSBomwDnJBNj2tDbYb55AAAAD4"] [Tue Aug 18 13:00:34.132179 2026] [security2:error] [pid 123784:tid 124041] [client 49.13.164.148:61698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSBoGwDnJBNj2tDbYb5RAAAAHs"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:00:34.133930 2026] [security2:error] [pid 123784:tid 124032] [client 20.104.100.201:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/domvf.php"] [unique_id "aoSBomwDnJBNj2tDbYb56wAAAHI"] [Tue Aug 18 13:00:34.147130 2026] [security2:error] [pid 123784:tid 123946] [client 172.202.39.151:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/system_log.php"] [unique_id "aoSBomwDnJBNj2tDbYb57AAAABw"] [Tue Aug 18 13:00:34.176239 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.56.190:42467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/11.php"] [unique_id "aoSBomwDnJBNj2tDbYb57QAAAGs"] [Tue Aug 18 13:00:34.196515 2026] [security2:error] [pid 123784:tid 123869] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ioxi-o.php"] [unique_id "aoSBomwDnJBNj2tDbYb58AAAKlA"] [Tue Aug 18 13:00:34.205158 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.138.185:18849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/end.php"] [unique_id "aoSBomwDnJBNj2tDbYb58gAAABI"] [Tue Aug 18 13:00:34.213382 2026] [security2:error] [pid 123784:tid 123899] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBomwDnJBNj2tDbYb59AAAKG4"] [Tue Aug 18 13:00:34.235465 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:34.235899 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:34.241517 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.156.252:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/image2.php"] [unique_id "aoSBomwDnJBNj2tDbYb59gAAAAM"] [Tue Aug 18 13:00:34.245556 2026] [security2:error] [pid 123784:tid 123938] [client 20.226.56.190:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vm.php"] [unique_id "aoSBomwDnJBNj2tDbYb59wAAABQ"] [Tue Aug 18 13:00:34.261807 2026] [security2:error] [pid 123784:tid 123981] [client 135.225.78.186:37147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/wpxml.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-AAAAD8"] [Tue Aug 18 13:00:34.278434 2026] [security2:error] [pid 123784:tid 123964] [client 167.235.143.113:59918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb51gAAAC4"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:00:34.302255 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/buy.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-gAAAHA"] [Tue Aug 18 13:00:34.302287 2026] [security2:error] [pid 123784:tid 124038] [client 20.100.169.31:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBomwDnJBNj2tDbYb5-wAAAHg"] [Tue Aug 18 13:00:34.322535 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:9324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ta.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_AAAACw"] [Tue Aug 18 13:00:34.336464 2026] [security2:error] [pid 123784:tid 123933] [client 4.232.94.69:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/2.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_QAAAA8"] [Tue Aug 18 13:00:34.350307 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:21151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eg.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_gAAAHU"] [Tue Aug 18 13:00:34.350876 2026] [security2:error] [pid 123784:tid 123961] [client 20.116.17.175:58122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb5_wAAACs"] [Tue Aug 18 13:00:34.364419 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:15105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lq.php"] [unique_id "aoSBomwDnJBNj2tDbYb6AQAAAEg"] [Tue Aug 18 13:00:34.370684 2026] [security2:error] [pid 123784:tid 123948] [client 51.116.232.28:18972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/ops.php"] [unique_id "aoSBomwDnJBNj2tDbYb6AgAAAB4"] [Tue Aug 18 13:00:34.383426 2026] [security2:error] [pid 123784:tid 123790] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/abc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6BAAAQwE"] [Tue Aug 18 13:00:34.407408 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:40429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ni.php"] [unique_id "aoSBomwDnJBNj2tDbYb6BwAAADI"] [Tue Aug 18 13:00:34.419343 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.56.190:17979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/uk.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CAAAAEU"] [Tue Aug 18 13:00:34.423359 2026] [security2:error] [pid 123784:tid 123988] [client 20.250.27.191:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file15.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CQAAAEY"] [Tue Aug 18 13:00:34.432138 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:21179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/creds.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CgAAACc"] [Tue Aug 18 13:00:34.437443 2026] [security2:error] [pid 123784:tid 124009] [client 20.127.136.245:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/goods.php"] [unique_id "aoSBomwDnJBNj2tDbYb6CwAAAFs"] [Tue Aug 18 13:00:34.448784 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:31892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ip.php"] [unique_id "aoSBomwDnJBNj2tDbYb6DAAAAGQ"] [Tue Aug 18 13:00:34.484633 2026] [security2:error] [pid 123784:tid 123913] [remote 172.238.58.237:39340] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBomwDnJBNj2tDbYb6DwAAbnw"] [Tue Aug 18 13:00:34.486578 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ho.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EAAAAH8"] [Tue Aug 18 13:00:34.507949 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EQAAAGA"] [Tue Aug 18 13:00:34.511267 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBomwDnJBNj2tDbYb6EgAAAFI"] [Tue Aug 18 13:00:34.549692 2026] [security2:error] [pid 123784:tid 123949] [client 20.104.100.201:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/red.php"] [unique_id "aoSBomwDnJBNj2tDbYb6FQAAAB8"] [Tue Aug 18 13:00:34.553471 2026] [security2:error] [pid 123784:tid 123796] [remote 172.238.58.237:39356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBomwDnJBNj2tDbYb6FAAAEQc"] [Tue Aug 18 13:00:34.567807 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.156.252:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/wpxml.php"] [unique_id "aoSBomwDnJBNj2tDbYb6FwAAAFU"] [Tue Aug 18 13:00:34.576122 2026] [security2:error] [pid 123784:tid 123802] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6GAAAIg0"] [Tue Aug 18 13:00:34.576262 2026] [security2:error] [pid 123784:tid 123952] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6GAAAIg0"] [Tue Aug 18 13:00:34.604654 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/public/moon.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HAAAAEs"] [Tue Aug 18 13:00:34.609035 2026] [security2:error] [pid 123784:tid 123852] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HgAAXz8"] [Tue Aug 18 13:00:34.620758 2026] [security2:error] [pid 123784:tid 123887] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/akcc.php"] [unique_id "aoSBomwDnJBNj2tDbYb6HwAAAGI"] [Tue Aug 18 13:00:34.654735 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.56.190:10570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/97.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IgAAAEA"] [Tue Aug 18 13:00:34.654803 2026] [security2:error] [pid 123784:tid 123953] [client 68.155.156.252:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fb.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IQAAACM"] [Tue Aug 18 13:00:34.667990 2026] [security2:error] [pid 123784:tid 123976] [client 20.116.17.175:58169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-good.php"] [unique_id "aoSBomwDnJBNj2tDbYb6IwAAADo"] [Tue Aug 18 13:00:34.670464 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/dropdown.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JAAAAAY"] [Tue Aug 18 13:00:34.673284 2026] [security2:error] [pid 123784:tid 123928] [client 20.65.98.162:41709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mgrr.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JQAAAAo"] [Tue Aug 18 13:00:34.690744 2026] [authz_core:error] [pid 123784:tid 123800] [remote 57.141.22.85:47140] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:34.691194 2026] [authz_core:error] [pid 123784:tid 123800] [remote 57.141.22.85:47140] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:34.724769 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBomwDnJBNj2tDbYb6KAAAAE0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:34.728314 2026] [security2:error] [pid 123784:tid 124023] [client 49.13.164.148:31140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6JwAAAGk"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:00:34.749311 2026] [security2:error] [pid 123784:tid 123936] [client 52.173.121.69:42918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/lddxs.php"] [unique_id "aoSBomwDnJBNj2tDbYb6KwAAABI"] [Tue Aug 18 13:00:34.755375 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:10699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/elp.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LAAAAHc"] [Tue Aug 18 13:00:34.783992 2026] [security2:error] [pid 123784:tid 123958] [client 51.116.232.28:19043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/coffexium.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LQAAACg"] [Tue Aug 18 13:00:34.798412 2026] [security2:error] [pid 123784:tid 123910] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wk/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6LwAAA3k"] [Tue Aug 18 13:00:34.832080 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:34.832353 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:34.853092 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSBomwDnJBNj2tDbYb6MwAAAC4"] [Tue Aug 18 13:00:34.918408 2026] [security2:error] [pid 123784:tid 123791] [remote 66.102.134.13:33162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samarapraseres.com.br"] [uri "/wp-login.php"] [unique_id "aoSBomwDnJBNj2tDbYb6NwAAJgI"] [Tue Aug 18 13:00:34.922178 2026] [security2:error] [pid 123784:tid 123962] [client 20.38.3.247:19580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBomwDnJBNj2tDbYb6OQAAACw"] [Tue Aug 18 13:00:34.929842 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBomwDnJBNj2tDbYb6OgAAD0E"] [Tue Aug 18 13:00:34.948603 2026] [security2:error] [pid 123784:tid 123990] [client 20.116.17.175:59971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wmore1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6PQAAAEg"] [Tue Aug 18 13:00:34.954794 2026] [security2:error] [pid 123784:tid 123960] [client 20.100.169.31:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6PgAAACo"] [Tue Aug 18 13:00:34.972896 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QAAAMRA"] [Tue Aug 18 13:00:34.972996 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QAAAMRA"] [Tue Aug 18 13:00:34.989999 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:44607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QQAAAEY"] [Tue Aug 18 13:00:34.993847 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:34120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/99.php"] [unique_id "aoSBomwDnJBNj2tDbYb6QgAAAAI"] [Tue Aug 18 13:00:35.001881 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.56.190:42449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rh.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6QwAAACc"] [Tue Aug 18 13:00:35.005360 2026] [security2:error] [pid 123784:tid 124009] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/inputs.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6RQAAAFs"] [Tue Aug 18 13:00:35.023250 2026] [security2:error] [pid 123784:tid 124006] [client 20.203.138.185:29933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.138.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lopesmultimarcasmg.com.br"] [uri "/ae.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6RwAAAFg"] [Tue Aug 18 13:00:35.036793 2026] [security2:error] [pid 123784:tid 123941] [client 68.155.156.252:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/gi.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SAAAABc"] [Tue Aug 18 13:00:35.038818 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:15120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/you.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SQAAABY"] [Tue Aug 18 13:00:35.043075 2026] [security2:error] [pid 123784:tid 124042] [client 168.62.48.100:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6SwAAAHw"] [Tue Aug 18 13:00:35.047702 2026] [security2:error] [pid 123784:tid 123871] [remote 172.238.58.237:39362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6SgAAcVI"] [Tue Aug 18 13:00:35.050580 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.27.191:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/f35.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TAAAAG4"] [Tue Aug 18 13:00:35.051229 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/yg.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TQAAAH8"] [Tue Aug 18 13:00:35.073657 2026] [security2:error] [pid 123784:tid 124010] [client 45.131.193.56:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nasbeauty.com.br"] [uri "/wp-login.php"] [unique_id "aoSBomwDnJBNj2tDbYb6NgAAAFw"] [Tue Aug 18 13:00:35.092318 2026] [security2:error] [pid 123784:tid 123966] [client 20.226.56.190:8279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/et.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6TgAAADA"] [Tue Aug 18 13:00:35.105004 2026] [security2:error] [pid 123784:tid 123875] [remote 172.238.58.237:39368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6TwAAeFY"] [Tue Aug 18 13:00:35.132097 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6UwAAAHA"] [Tue Aug 18 13:00:35.135798 2026] [security2:error] [pid 123784:tid 123971] [client 18.192.166.72:51060] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSBoWwDnJBNj2tDbYb5twAAADU"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:00:35.153397 2026] [security2:error] [pid 123784:tid 123989] [client 20.104.100.201:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6VAAAAEc"] [Tue Aug 18 13:00:35.166029 2026] [security2:error] [pid 123784:tid 123811] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6VwAAExY"] [Tue Aug 18 13:00:35.172444 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:29445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/34.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6WAAAAEs"] [Tue Aug 18 13:00:35.206761 2026] [security2:error] [pid 123784:tid 124015] [client 51.116.232.28:18957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6WwAAAGE"] [Tue Aug 18 13:00:35.223318 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/special.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6XgAAACM"] [Tue Aug 18 13:00:35.233584 2026] [security2:error] [pid 123784:tid 124018] [client 4.232.94.69:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YAAAAGQ"] [Tue Aug 18 13:00:35.233615 2026] [security2:error] [pid 123784:tid 123929] [client 158.158.74.177:17333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/public/storage.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6XwAAAAs"] [Tue Aug 18 13:00:35.240341 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.36.136:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YQAAABw"] [Tue Aug 18 13:00:35.254384 2026] [security2:error] [pid 123784:tid 124025] [client 172.202.39.151:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/user/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YgAAAGs"] [Tue Aug 18 13:00:35.259336 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:20353] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/1.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YwAAAE0"] [Tue Aug 18 13:00:35.259443 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/1.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6YwAAAE0"] [Tue Aug 18 13:00:35.283929 2026] [security2:error] [pid 123784:tid 123950] [client 20.127.136.245:27897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/file.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZAAAACA"] [Tue Aug 18 13:00:35.292084 2026] [security2:error] [pid 123784:tid 124026] [client 196.12.128.158:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZgAAAGw"] [Tue Aug 18 13:00:35.292234 2026] [security2:error] [pid 123784:tid 124026] [client 196.12.128.158:51293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZgAAAGw"] [Tue Aug 18 13:00:35.297492 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.56.190:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/of.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ZwAAAHc"] [Tue Aug 18 13:00:35.297877 2026] [security2:error] [pid 123784:tid 123900] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6aAAAdm8"] [Tue Aug 18 13:00:35.335914 2026] [security2:error] [pid 123784:tid 123981] [client 52.173.121.69:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zjggu.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6agAAAD8"] [Tue Aug 18 13:00:35.350627 2026] [security2:error] [pid 123784:tid 123797] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6bQAADAg"] [Tue Aug 18 13:00:35.354798 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/file1221.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6bgAAAC4"] [Tue Aug 18 13:00:35.384638 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/video.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cQAAABs"] [Tue Aug 18 13:00:35.414750 2026] [security2:error] [pid 123784:tid 123998] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/100.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cgAAAFA"] [Tue Aug 18 13:00:35.414988 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.98.162:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/55.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6cwAAACo"] [Tue Aug 18 13:00:35.427016 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/er.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dAAAADE"] [Tue Aug 18 13:00:35.463447 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.56.190:7301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bu.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dQAAAEY"] [Tue Aug 18 13:00:35.509272 2026] [security2:error] [pid 123784:tid 124001] [client 20.116.17.175:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6dwAAAFM"] [Tue Aug 18 13:00:35.520339 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.56.190:10587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rn.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6eAAAABc"] [Tue Aug 18 13:00:35.531599 2026] [security2:error] [pid 123784:tid 123823] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/as.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6eQAAcSI"] [Tue Aug 18 13:00:35.554146 2026] [security2:error] [pid 123784:tid 124004] [client 20.104.100.201:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ewAAAFY"] [Tue Aug 18 13:00:35.561014 2026] [authz_core:error] [pid 123784:tid 124044] [client 192.178.4.133:41600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:35.561448 2026] [authz_core:error] [pid 123784:tid 124044] [client 192.178.4.133:41600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:35.567226 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.56.190:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ut.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6fQAAADQ"] [Tue Aug 18 13:00:35.576056 2026] [security2:error] [pid 123784:tid 124016] [client 20.100.169.31:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBo2wDnJBNj2tDbYb6fgAAAGI"] [Tue Aug 18 13:00:35.588060 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.36.136:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6fwAAAHg"] [Tue Aug 18 13:00:35.603592 2026] [security2:error] [pid 123784:tid 123818] [remote 172.238.58.237:39374] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlafiorinofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6gAAAHh0"] [Tue Aug 18 13:00:35.618317 2026] [security2:error] [pid 123784:tid 123881] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6gQAAJVw"] [Tue Aug 18 13:00:35.633370 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/eh.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6hAAAAEc"] [Tue Aug 18 13:00:35.656083 2026] [security2:error] [pid 123784:tid 123911] [remote 172.238.58.237:39390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBo2wDnJBNj2tDbYb6hwAAEHo"] [Tue Aug 18 13:00:35.700392 2026] [authz_core:error] [pid 123784:tid 124014] [client 192.178.4.134:57534] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:35.700664 2026] [authz_core:error] [pid 123784:tid 124014] [client 192.178.4.134:57534] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:35.709100 2026] [security2:error] [pid 123784:tid 123987] [client 197.184.64.235:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iQAAAEU"] [Tue Aug 18 13:00:35.712692 2026] [security2:error] [pid 123784:tid 123937] [client 20.250.27.191:40175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-load.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iwAAABM"] [Tue Aug 18 13:00:35.712762 2026] [security2:error] [pid 123784:tid 123795] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6igAAOwY"] [Tue Aug 18 13:00:35.713697 2026] [security2:error] [pid 123784:tid 123987] [client 197.184.64.235:41958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6iQAAAEU"] [Tue Aug 18 13:00:35.715552 2026] [security2:error] [pid 123784:tid 123993] [client 51.116.232.28:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6jQAAAEs"] [Tue Aug 18 13:00:35.737766 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.156.252:8090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/hel.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6kgAAAF0"] [Tue Aug 18 13:00:35.739812 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6kwAAADc"] [Tue Aug 18 13:00:35.742017 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.56.190:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ad.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lQAAAEQ"] [Tue Aug 18 13:00:35.749113 2026] [security2:error] [pid 123784:tid 124015] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/akc.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lgAAAGE"] [Tue Aug 18 13:00:35.750516 2026] [security2:error] [pid 123784:tid 123990] [client 213.35.127.232:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6lwAAAEg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:35.750973 2026] [security2:error] [pid 123784:tid 123931] [client 20.127.136.245:28304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mAAAAA0"] [Tue Aug 18 13:00:35.784592 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mQAAABk"] [Tue Aug 18 13:00:35.792350 2026] [security2:error] [pid 123784:tid 124018] [client 20.116.17.175:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/thoms.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mgAAAGQ"] [Tue Aug 18 13:00:35.797190 2026] [security2:error] [pid 123784:tid 123928] [client 158.23.17.4:9391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/he.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6mwAAAAo"] [Tue Aug 18 13:00:35.817705 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.56.190:11638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/vd.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6nAAAAF4"] [Tue Aug 18 13:00:35.851114 2026] [security2:error] [pid 123784:tid 123997] [client 158.158.74.177:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/radio.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6oQAAAE8"] [Tue Aug 18 13:00:35.854403 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:10370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6ogAAAA4"] [Tue Aug 18 13:00:35.869732 2026] [security2:error] [pid 123784:tid 123940] [client 18.192.166.72:1694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6jAAAABY"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:00:35.892956 2026] [security2:error] [pid 123784:tid 124036] [client 158.23.17.4:34159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qk.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pQAAAHY"] [Tue Aug 18 13:00:35.893866 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pgAAACg"] [Tue Aug 18 13:00:35.897953 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-config-sample.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6pwAAFGE"] [Tue Aug 18 13:00:35.932504 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.156.252:12604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/nox.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6qgAAAHk"] [Tue Aug 18 13:00:35.937599 2026] [security2:error] [pid 123784:tid 123833] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/media.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6qwAACSw"] [Tue Aug 18 13:00:35.943808 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.100.201:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rAAAAEk"] [Tue Aug 18 13:00:35.950922 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:35.951165 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:35.962333 2026] [security2:error] [pid 123784:tid 123933] [client 20.65.98.162:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ajax.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rgAAAA8"] [Tue Aug 18 13:00:35.965259 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:10609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/56.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6rwAAAHU"] [Tue Aug 18 13:00:35.990837 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ez.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6sAAAAH0"] [Tue Aug 18 13:00:35.995249 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.56.190:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/rx.php"] [unique_id "aoSBo2wDnJBNj2tDbYb6sgAAADI"] [Tue Aug 18 13:00:36.018874 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.56.190:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mandrill.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6tQAAACk"] [Tue Aug 18 13:00:36.104997 2026] [security2:error] [pid 123784:tid 124016] [client 20.38.3.247:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/fpwch.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uAAAAGI"] [Tue Aug 18 13:00:36.106853 2026] [security2:error] [pid 123784:tid 124038] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uQAAAHg"] [Tue Aug 18 13:00:36.112233 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ugAAZSM"] [Tue Aug 18 13:00:36.115087 2026] [security2:error] [pid 123784:tid 123948] [client 20.116.17.175:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6uwAAAB4"] [Tue Aug 18 13:00:36.128520 2026] [security2:error] [pid 123784:tid 123971] [client 20.226.56.190:42469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/main.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6vQAAADU"] [Tue Aug 18 13:00:36.151219 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.56.190:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ga.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6wwAAAEc"] [Tue Aug 18 13:00:36.151959 2026] [security2:error] [pid 123784:tid 124003] [client 20.65.98.162:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/sky.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6xAAAAFU"] [Tue Aug 18 13:00:36.157687 2026] [security2:error] [pid 123784:tid 124021] [client 51.116.232.28:19023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/k.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6xQAAAGc"] [Tue Aug 18 13:00:36.207812 2026] [security2:error] [pid 123784:tid 123829] [remote 172.238.58.237:39404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carlaflorianofraga.adv.br"] [uri "/"] [unique_id "aoSBpGwDnJBNj2tDbYb6yAAAASg"] [Tue Aug 18 13:00:36.210001 2026] [security2:error] [pid 123784:tid 123965] [client 20.100.169.31:19776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6yQAAAC8"] [Tue Aug 18 13:00:36.218523 2026] [security2:error] [pid 123784:tid 123918] [client 20.226.36.136:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ygAAAAA"] [Tue Aug 18 13:00:36.224974 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.56.190:10604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/wb.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6ywAAAF0"] [Tue Aug 18 13:00:36.225424 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6zAAAAF8"] [Tue Aug 18 13:00:36.230414 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.156.252:48126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/grok.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6zQAAADc"] [Tue Aug 18 13:00:36.252119 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:36.252386 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:36.272044 2026] [security2:error] [pid 123784:tid 123953] [client 20.104.100.201:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/output.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60QAAACM"] [Tue Aug 18 13:00:36.276481 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60gAAAE4"] [Tue Aug 18 13:00:36.283956 2026] [security2:error] [pid 123784:tid 123884] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/inso.php"] [unique_id "aoSBpGwDnJBNj2tDbYb60wAAGV8"] [Tue Aug 18 13:00:36.310941 2026] [security2:error] [pid 123784:tid 123895] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb61gAAZGo"] [Tue Aug 18 13:00:36.314838 2026] [security2:error] [pid 123784:tid 123928] [client 20.79.204.6:2233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBpGwDnJBNj2tDbYb61wAAAAo"] [Tue Aug 18 13:00:36.320780 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.36.136:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62AAAABw"] [Tue Aug 18 13:00:36.325708 2026] [security2:error] [pid 123784:tid 124005] [client 52.173.121.69:48430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/dlvqo.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62QAAAFc"] [Tue Aug 18 13:00:36.336310 2026] [security2:error] [pid 123784:tid 123995] [client 68.221.73.131:46213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62gAAAE0"] [Tue Aug 18 13:00:36.344497 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.56.190:20925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/xn.php"] [unique_id "aoSBpGwDnJBNj2tDbYb62wAAAEo"] [Tue Aug 18 13:00:36.387597 2026] [security2:error] [pid 123784:tid 123922] [client 20.116.17.175:58155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/root.php"] [unique_id "aoSBpGwDnJBNj2tDbYb63QAAAAQ"] [Tue Aug 18 13:00:36.399852 2026] [security2:error] [pid 123784:tid 124037] [client 168.62.48.100:5626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64AAAAHc"] [Tue Aug 18 13:00:36.410357 2026] [security2:error] [pid 123784:tid 123937] [client 20.127.136.245:27863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/404.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64QAAABM"] [Tue Aug 18 13:00:36.417217 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:21149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/47.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64gAAAAw"] [Tue Aug 18 13:00:36.417612 2026] [security2:error] [pid 123784:tid 123969] [client 158.23.17.4:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gz.php"] [unique_id "aoSBpGwDnJBNj2tDbYb64wAAADM"] [Tue Aug 18 13:00:36.449309 2026] [security2:error] [pid 123784:tid 124020] [client 79.127.164.8:32906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/wpbackup.sql"] [unique_id "aoSBpGwDnJBNj2tDbYb65QAAAGY"], referer: https://medihub.com.br/wpbackup.sql [Tue Aug 18 13:00:36.451329 2026] [security2:error] [pid 123784:tid 124017] [client 4.232.94.69:31424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb65gAAAGM"] [Tue Aug 18 13:00:36.458268 2026] [security2:error] [pid 123784:tid 123961] [client 20.250.13.23:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSBpGwDnJBNj2tDbYb65wAAACs"] [Tue Aug 18 13:00:36.469190 2026] [security2:error] [pid 123784:tid 123931] [client 158.158.74.177:23690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/root.php"] [unique_id "aoSBpGwDnJBNj2tDbYb66QAAAA0"] [Tue Aug 18 13:00:36.490631 2026] [security2:error] [pid 123784:tid 123863] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aoSBpGwDnJBNj2tDbYb67AAAQ0o"] [Tue Aug 18 13:00:36.514649 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/0x.php"] [unique_id "aoSBpGwDnJBNj2tDbYb67wAAAHA"] [Tue Aug 18 13:00:36.521572 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.156.252:47953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/akismet.php"] [unique_id "aoSBpGwDnJBNj2tDbYb68QAAAEY"] [Tue Aug 18 13:00:36.552759 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/php.php"] [unique_id "aoSBpGwDnJBNj2tDbYb68wAAAG0"] [Tue Aug 18 13:00:36.553228 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.36.136:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBpGwDnJBNj2tDbYb69AAAAFg"] [Tue Aug 18 13:00:36.563619 2026] [security2:error] [pid 123784:tid 123941] [client 20.65.98.162:45616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/yj09.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-QAAABc"] [Tue Aug 18 13:00:36.565146 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/asus.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-gAAAH4"] [Tue Aug 18 13:00:36.565808 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:36.566217 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:36.574822 2026] [security2:error] [pid 123784:tid 124031] [client 20.151.109.219:14317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/st.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6-wAAAHE"] [Tue Aug 18 13:00:36.596387 2026] [security2:error] [pid 123784:tid 123954] [client 20.79.204.6:14112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/ku.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_AAAACQ"] [Tue Aug 18 13:00:36.606312 2026] [security2:error] [pid 123784:tid 124010] [client 51.116.232.28:19031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/82.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_QAAAFw"] [Tue Aug 18 13:00:36.608389 2026] [security2:error] [pid 123784:tid 123963] [client 20.250.27.191:34834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_gAAAC0"] [Tue Aug 18 13:00:36.617703 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.156.252:48076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/indes.php"] [unique_id "aoSBpGwDnJBNj2tDbYb6_wAAAHs"] [Tue Aug 18 13:00:36.624166 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/tiny2.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7AAAAAFI"] [Tue Aug 18 13:00:36.668335 2026] [security2:error] [pid 123784:tid 123936] [client 20.116.17.175:59985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/fpwch.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7AwAAABI"] [Tue Aug 18 13:00:36.672459 2026] [security2:error] [pid 123784:tid 123873] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BAAANVQ"] [Tue Aug 18 13:00:36.709116 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:20169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fs.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BQAAAGc"] [Tue Aug 18 13:00:36.730309 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:47619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/88.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7BgAAAAE"] [Tue Aug 18 13:00:36.767104 2026] [security2:error] [pid 123784:tid 123927] [client 213.35.127.232:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7CgAAAAk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:36.767558 2026] [security2:error] [pid 123784:tid 123825] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/shiny.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7CwAARCQ"] [Tue Aug 18 13:00:36.792690 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.36.136:61481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DQAAAEA"] [Tue Aug 18 13:00:36.815668 2026] [security2:error] [pid 123784:tid 123928] [client 20.226.56.190:17975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/payout.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DgAAAAo"] [Tue Aug 18 13:00:36.816541 2026] [security2:error] [pid 123784:tid 124012] [client 20.206.73.37:34791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7DwAAAF4"] [Tue Aug 18 13:00:36.830141 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:19791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7EAAAAGg"] [Tue Aug 18 13:00:36.854184 2026] [security2:error] [pid 123784:tid 123841] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/an.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7EwAAbjQ"] [Tue Aug 18 13:00:36.854645 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:36.855082 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:36.856297 2026] [security2:error] [pid 123784:tid 123962] [client 172.202.39.151:40356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/an.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FAAAACw"] [Tue Aug 18 13:00:36.874878 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/t.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FQAAACA"] [Tue Aug 18 13:00:36.894714 2026] [security2:error] [pid 123784:tid 124011] [client 20.127.136.245:27873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wk/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7FgAAAF0"] [Tue Aug 18 13:00:36.925656 2026] [security2:error] [pid 123784:tid 124026] [client 52.173.121.69:15026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/pkmoj.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7GQAAAGw"] [Tue Aug 18 13:00:36.935948 2026] [security2:error] [pid 123784:tid 124037] [client 20.151.109.219:60897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/le.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7GwAAAHc"] [Tue Aug 18 13:00:36.954684 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:58113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/mg.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HAAAABY"] [Tue Aug 18 13:00:36.987590 2026] [security2:error] [pid 123784:tid 123930] [client 158.23.17.4:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nf.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HgAAAAw"] [Tue Aug 18 13:00:36.990847 2026] [security2:error] [pid 123784:tid 124039] [client 20.104.100.201:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wpxml.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HwAAAHk"] [Tue Aug 18 13:00:37.029315 2026] [security2:error] [pid 123784:tid 123945] [client 68.155.156.252:48091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/tTPcH.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7JAAAABs"] [Tue Aug 18 13:00:37.034308 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/"] [unique_id "aoSBpWwDnJBNj2tDbYb7JQAAZkA"] [Tue Aug 18 13:00:37.041698 2026] [security2:error] [pid 123784:tid 124035] [client 51.116.232.28:19064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/dex.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7JgAAAHU"] [Tue Aug 18 13:00:37.090727 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/server.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KAAAAGo"] [Tue Aug 18 13:00:37.104400 2026] [security2:error] [pid 123784:tid 123937] [client 159.69.158.189:7528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSBpGwDnJBNj2tDbYb7HQAAABM"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:00:37.105104 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:33455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rb.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KQAAADE"] [Tue Aug 18 13:00:37.114787 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/22.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7KwAAAAI"] [Tue Aug 18 13:00:37.144770 2026] [security2:error] [pid 123784:tid 123812] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LAAATRc"] [Tue Aug 18 13:00:37.144972 2026] [security2:error] [pid 123784:tid 123995] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LAAATRc"] [Tue Aug 18 13:00:37.165960 2026] [security2:error] [pid 123784:tid 124006] [client 68.221.73.131:29628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LgAAAFg"] [Tue Aug 18 13:00:37.174780 2026] [security2:error] [pid 123784:tid 124002] [client 20.65.98.162:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/scxy.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7LwAAAFQ"] [Tue Aug 18 13:00:37.189373 2026] [security2:error] [pid 123784:tid 123964] [client 20.79.204.6:2397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/222.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MAAAAC4"] [Tue Aug 18 13:00:37.192186 2026] [security2:error] [pid 123784:tid 123987] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/index/function.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MQAAAEU"] [Tue Aug 18 13:00:37.195123 2026] [security2:error] [pid 123784:tid 123975] [client 20.250.13.23:23681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7MgAAADk"] [Tue Aug 18 13:00:37.205801 2026] [security2:error] [pid 123784:tid 123926] [client 20.250.27.191:28008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/aaa.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NAAAAAg"] [Tue Aug 18 13:00:37.208241 2026] [security2:error] [pid 123784:tid 123869] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/404.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NQAAJFA"] [Tue Aug 18 13:00:37.232307 2026] [security2:error] [pid 123784:tid 124041] [client 20.116.17.175:57933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/reop3.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7NwAAAHs"] [Tue Aug 18 13:00:37.290529 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PAAAAB4"] [Tue Aug 18 13:00:37.298422 2026] [security2:error] [pid 123784:tid 124021] [client 20.151.109.219:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/hr.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PQAAAGc"] [Tue Aug 18 13:00:37.365952 2026] [security2:error] [pid 123784:tid 123919] [client 20.226.56.190:8306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bh.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7PwAAAAE"] [Tue Aug 18 13:00:37.387796 2026] [security2:error] [pid 123784:tid 123835] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QQAAUy4"] [Tue Aug 18 13:00:37.395452 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.36.136:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QgAAAF4"] [Tue Aug 18 13:00:37.406891 2026] [security2:error] [pid 123784:tid 123980] [client 20.127.136.245:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/about.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7QwAAAD4"] [Tue Aug 18 13:00:37.420591 2026] [security2:error] [pid 123784:tid 123958] [client 86.120.159.145:50142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RAAAACg"] [Tue Aug 18 13:00:37.421005 2026] [security2:error] [pid 123784:tid 123958] [client 86.120.159.145:50142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RAAAACg"] [Tue Aug 18 13:00:37.435499 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.156.252:47714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/admin.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7RgAAAE8"] [Tue Aug 18 13:00:37.456531 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:37.456793 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:37.474237 2026] [security2:error] [pid 123784:tid 124037] [client 20.79.204.6:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/chosen.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7SwAAAHc"] [Tue Aug 18 13:00:37.485203 2026] [security2:error] [pid 123784:tid 124036] [client 20.226.36.136:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TAAAAHY"] [Tue Aug 18 13:00:37.512909 2026] [security2:error] [pid 123784:tid 123940] [client 20.116.17.175:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/php5.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TQAAABY"] [Tue Aug 18 13:00:37.524153 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.13.23:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TgAAADM"] [Tue Aug 18 13:00:37.539330 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wk/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7TwAAAHk"] [Tue Aug 18 13:00:37.541447 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.156.252:32284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/bs1.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7UAAAACY"] [Tue Aug 18 13:00:37.577809 2026] [security2:error] [pid 123784:tid 123913] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7UgAAZnw"] [Tue Aug 18 13:00:37.600094 2026] [security2:error] [pid 123784:tid 123978] [client 51.116.232.28:19035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/puc.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7VAAAADw"] [Tue Aug 18 13:00:37.602270 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ccou.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7VQAAAA0"] [Tue Aug 18 13:00:37.620234 2026] [security2:error] [pid 123784:tid 123970] [client 20.100.169.31:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7SAAAADQ"] [Tue Aug 18 13:00:37.654979 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.36.136:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WQAAAEY"] [Tue Aug 18 13:00:37.683630 2026] [security2:error] [pid 123784:tid 124008] [client 20.100.169.31:24192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WgAAAFo"] [Tue Aug 18 13:00:37.693607 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7WwAAAG0"] [Tue Aug 18 13:00:37.703266 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:38302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/37.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XAAAABc"] [Tue Aug 18 13:00:37.713013 2026] [security2:error] [pid 123784:tid 123959] [client 158.158.74.177:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XQAAACk"] [Tue Aug 18 13:00:37.751080 2026] [security2:error] [pid 123784:tid 123852] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/"] [unique_id "aoSBpWwDnJBNj2tDbYb7aAAALj8"] [Tue Aug 18 13:00:37.755970 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:37.756227 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:37.774709 2026] [security2:error] [pid 123784:tid 124044] [client 20.250.27.191:34822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gecko.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bQAAAH4"] [Tue Aug 18 13:00:37.794765 2026] [security2:error] [pid 123784:tid 123961] [client 20.79.204.6:2380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/aa.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bgAAACs"] [Tue Aug 18 13:00:37.799861 2026] [security2:error] [pid 123784:tid 123926] [client 20.116.17.175:58119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/acp.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7cAAAAAg"] [Tue Aug 18 13:00:37.800799 2026] [security2:error] [pid 123784:tid 124011] [client 213.35.127.232:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7bwAAAF0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:37.821365 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.13.23:44048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7cwAAAAM"] [Tue Aug 18 13:00:37.828812 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:62182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dAAAAFI"] [Tue Aug 18 13:00:37.833686 2026] [security2:error] [pid 123784:tid 123949] [client 159.69.158.189:34332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7XgAAAB8"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:00:37.840368 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/ct.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dgAAAAc"] [Tue Aug 18 13:00:37.843937 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:9378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xv.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7dwAAAEk"] [Tue Aug 18 13:00:37.866364 2026] [security2:error] [pid 123784:tid 123856] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/403dd.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7eQAABUM"] [Tue Aug 18 13:00:37.877236 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zs.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7egAAABI"] [Tue Aug 18 13:00:37.880297 2026] [security2:error] [pid 123784:tid 123974] [client 68.155.156.252:61791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/hp2.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7ewAAADg"] [Tue Aug 18 13:00:37.903211 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-blink.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7fAAAABE"] [Tue Aug 18 13:00:37.911983 2026] [security2:error] [pid 123784:tid 123965] [client 168.62.48.100:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSBpWwDnJBNj2tDbYb7fQAAAC8"] [Tue Aug 18 13:00:37.960560 2026] [security2:error] [pid 123784:tid 123910] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/"] [unique_id "aoSBpWwDnJBNj2tDbYb7gQAAPnk"] [Tue Aug 18 13:00:37.973128 2026] [autoindex:error] [pid 123784:tid 123918] [client 172.202.39.151:40355] AH01276: Cannot serve directory /home2/ctamcursos/grupoctam.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:37.979392 2026] [authz_core:error] [pid 123784:tid 123842] [remote 57.141.22.2:38240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:37.979648 2026] [authz_core:error] [pid 123784:tid 123842] [remote 57.141.22.2:38240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.008261 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kt.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7hQAAACg"] [Tue Aug 18 13:00:38.012773 2026] [security2:error] [pid 123784:tid 123962] [client 20.65.98.162:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ws13.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7hgAAACw"] [Tue Aug 18 13:00:38.019203 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/crgio.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7iAAAAGw"] [Tue Aug 18 13:00:38.034268 2026] [security2:error] [pid 123784:tid 123969] [client 68.221.73.131:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/media.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7igAAADM"] [Tue Aug 18 13:00:38.036093 2026] [security2:error] [pid 123784:tid 123956] [client 51.116.232.28:19062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/inso.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7iwAAACY"] [Tue Aug 18 13:00:38.044445 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:15798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hj.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7jAAAAHM"] [Tue Aug 18 13:00:38.055515 2026] [security2:error] [pid 123784:tid 124035] [client 172.202.39.151:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7jwAAAHU"] [Tue Aug 18 13:00:38.063052 2026] [authz_core:error] [pid 123784:tid 123844] [remote 57.141.22.104:60584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:38.063332 2026] [authz_core:error] [pid 123784:tid 123844] [remote 57.141.22.104:60584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.070275 2026] [autoindex:error] [pid 123784:tid 123989] [client 20.118.133.132:14958] AH01276: Cannot serve directory /home4/agrimotor/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:38.095518 2026] [security2:error] [pid 123784:tid 123967] [client 20.116.17.175:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/yas.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lAAAADE"] [Tue Aug 18 13:00:38.095890 2026] [security2:error] [pid 123784:tid 123952] [client 20.100.169.31:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/0x.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lQAAACI"] [Tue Aug 18 13:00:38.097255 2026] [security2:error] [pid 123784:tid 124028] [client 20.127.136.245:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/term.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lgAAAG4"] [Tue Aug 18 13:00:38.105868 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.156.252:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.orientalbrindes.com.br"] [uri "/ajax.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7lwAAAG0"] [Tue Aug 18 13:00:38.108097 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.204.6:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/asd.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7mQAAAB4"] [Tue Aug 18 13:00:38.142614 2026] [security2:error] [pid 123784:tid 123892] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wso.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7mwAATmc"] [Tue Aug 18 13:00:38.151696 2026] [security2:error] [pid 123784:tid 123871] [remote 20.87.239.85:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7nAAAClI"] [Tue Aug 18 13:00:38.159999 2026] [security2:error] [pid 123784:tid 123963] [client 4.232.94.69:15650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dav.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7ngAAAC0"] [Tue Aug 18 13:00:38.168297 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.36.136:65295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7nwAAAH8"] [Tue Aug 18 13:00:38.203910 2026] [security2:error] [pid 123784:tid 123845] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/baba.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7oQAAUDg"] [Tue Aug 18 13:00:38.242068 2026] [security2:error] [pid 123784:tid 124039] [client 20.100.169.31:3718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7ogAAAHk"] [Tue Aug 18 13:00:38.259058 2026] [security2:error] [pid 123784:tid 123923] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/xfun.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pAAAAAU"] [Tue Aug 18 13:00:38.296273 2026] [security2:error] [pid 123784:tid 124014] [client 168.62.48.100:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pgAAAGA"] [Tue Aug 18 13:00:38.309609 2026] [security2:error] [pid 123784:tid 123939] [client 20.250.27.191:40171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/xiugai.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7pwAAABU"] [Tue Aug 18 13:00:38.324701 2026] [security2:error] [pid 123784:tid 123930] [client 68.155.156.252:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/yb.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qAAAAAw"] [Tue Aug 18 13:00:38.343875 2026] [security2:error] [pid 123784:tid 123919] [client 20.104.100.201:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qQAAAAE"] [Tue Aug 18 13:00:38.345543 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:60405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ww.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qgAAAF8"] [Tue Aug 18 13:00:38.348612 2026] [security2:error] [pid 123784:tid 123811] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/sf.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7qwAAZBY"] [Tue Aug 18 13:00:38.361388 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:38.361654 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.383012 2026] [security2:error] [pid 123784:tid 124012] [client 20.116.17.175:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ah25.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7rgAAAF4"] [Tue Aug 18 13:00:38.391235 2026] [security2:error] [pid 123784:tid 124011] [client 158.158.74.177:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/shell.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7rwAAAF0"] [Tue Aug 18 13:00:38.417012 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:29456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mx.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7sQAAAH0"] [Tue Aug 18 13:00:38.465136 2026] [security2:error] [pid 123784:tid 123962] [client 51.116.232.28:19010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/aa.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7tAAAACw"] [Tue Aug 18 13:00:38.474490 2026] [security2:error] [pid 123784:tid 124026] [client 20.226.36.136:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7tgAAAGw"] [Tue Aug 18 13:00:38.474845 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:34117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/md.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7twAAAHc"] [Tue Aug 18 13:00:38.484848 2026] [security2:error] [pid 123784:tid 124003] [client 20.250.13.23:23725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/st.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uAAAAFU"] [Tue Aug 18 13:00:38.492855 2026] [security2:error] [pid 123784:tid 124021] [client 20.79.204.6:2640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/abcd.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uQAAAGc"] [Tue Aug 18 13:00:38.504970 2026] [security2:error] [pid 123784:tid 124033] [client 172.202.39.151:40355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/404.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7uwAAAHM"] [Tue Aug 18 13:00:38.529607 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iz.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7vAAAAEc"] [Tue Aug 18 13:00:38.550729 2026] [security2:error] [pid 123784:tid 123826] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/index/function.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7vgAAPCU"] [Tue Aug 18 13:00:38.583472 2026] [security2:error] [pid 123784:tid 123906] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/site.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7wQAAAnU"] [Tue Aug 18 13:00:38.587986 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/btx25.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7wgAAAGI"] [Tue Aug 18 13:00:38.617064 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/p.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7xgAAAG0"] [Tue Aug 18 13:00:38.627092 2026] [security2:error] [pid 123784:tid 123948] [client 20.104.100.201:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/css.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7yAAAAB4"] [Tue Aug 18 13:00:38.628056 2026] [security2:error] [pid 123784:tid 123992] [client 168.62.48.100:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7yQAAAEo"] [Tue Aug 18 13:00:38.630546 2026] [authz_core:error] [pid 123784:tid 123836] [remote 57.141.22.35:24686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:38.630999 2026] [authz_core:error] [pid 123784:tid 123836] [remote 57.141.22.35:24686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.661761 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:38.662154 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.672331 2026] [security2:error] [pid 123784:tid 123927] [client 20.65.98.162:57905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/file5.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zAAAAAk"] [Tue Aug 18 13:00:38.673134 2026] [security2:error] [pid 123784:tid 123986] [client 20.116.17.175:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/ano.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zQAAAEQ"] [Tue Aug 18 13:00:38.674511 2026] [security2:error] [pid 123784:tid 123990] [client 135.225.78.186:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/file1221.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zgAAAEg"] [Tue Aug 18 13:00:38.712913 2026] [security2:error] [pid 123784:tid 123938] [client 20.79.204.6:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/akc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb7zwAAABQ"] [Tue Aug 18 13:00:38.715709 2026] [security2:error] [pid 123784:tid 123952] [client 20.127.136.245:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70AAAACI"] [Tue Aug 18 13:00:38.726709 2026] [security2:error] [pid 123784:tid 123843] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/edit.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70QAATjY"] [Tue Aug 18 13:00:38.729606 2026] [security2:error] [pid 123784:tid 124035] [client 20.100.169.31:4946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/222.php"] [unique_id "aoSBpmwDnJBNj2tDbYb70gAAAHU"] [Tue Aug 18 13:00:38.771190 2026] [security2:error] [pid 123784:tid 123943] [client 172.202.39.151:48904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/403.php"] [unique_id "aoSBpmwDnJBNj2tDbYb71QAAABk"] [Tue Aug 18 13:00:38.796018 2026] [security2:error] [pid 123784:tid 123975] [client 20.151.109.219:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mo.php"] [unique_id "aoSBpmwDnJBNj2tDbYb71wAAADk"] [Tue Aug 18 13:00:38.796953 2026] [autoindex:error] [pid 123784:tid 123955] [client 54.204.43.183:60073] AH01276: Cannot serve directory /home1/peretsites/admin.peretsites.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:38.798942 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.27.191:40179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/adminner.php"] [unique_id "aoSBpmwDnJBNj2tDbYb72AAAAFw"] [Tue Aug 18 13:00:38.812880 2026] [security2:error] [pid 123784:tid 123940] [client 213.35.127.232:61861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb72QAAABY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:38.874284 2026] [security2:error] [pid 123784:tid 123930] [client 68.155.156.252:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/vc.php"] [unique_id "aoSBpmwDnJBNj2tDbYb73gAAAAw"] [Tue Aug 18 13:00:38.894479 2026] [security2:error] [pid 123784:tid 123919] [client 51.116.232.28:19030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/img.php"] [unique_id "aoSBpmwDnJBNj2tDbYb73wAAAAE"] [Tue Aug 18 13:00:38.913709 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:37398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/iy.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74AAAAF0"] [Tue Aug 18 13:00:38.919616 2026] [security2:error] [pid 123784:tid 123881] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74QAAe1w"] [Tue Aug 18 13:00:38.927140 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74gAAAAA"] [Tue Aug 18 13:00:38.928615 2026] [security2:error] [pid 123784:tid 123924] [client 68.221.73.131:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/admin.php"] [unique_id "aoSBpmwDnJBNj2tDbYb74wAAAAY"] [Tue Aug 18 13:00:38.935811 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.36.136:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSBpmwDnJBNj2tDbYb75QAAACw"] [Tue Aug 18 13:00:38.944744 2026] [security2:error] [pid 123784:tid 123879] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/rest-api/"] [unique_id "aoSBpmwDnJBNj2tDbYb75wAAKlo"] [Tue Aug 18 13:00:38.947003 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.56.190:17932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/gy.php"] [unique_id "aoSBpmwDnJBNj2tDbYb76AAAAFY"] [Tue Aug 18 13:00:38.949870 2026] [security2:error] [pid 123784:tid 123956] [client 20.116.17.175:57923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/nwflm.php"] [unique_id "aoSBpmwDnJBNj2tDbYb76QAAACY"] [Tue Aug 18 13:00:38.962135 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:38.962405 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:38.976407 2026] [security2:error] [pid 123784:tid 124042] [client 20.100.169.31:3728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77AAAAHw"] [Tue Aug 18 13:00:38.978608 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:10371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/666.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77QAAAG8"] [Tue Aug 18 13:00:38.980826 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.13.23:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBpmwDnJBNj2tDbYb77wAAAEA"] [Tue Aug 18 13:00:39.020465 2026] [security2:error] [pid 123784:tid 123949] [client 158.158.74.177:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/sim.php"] [unique_id "aoSBp2wDnJBNj2tDbYb78gAAAB8"] [Tue Aug 18 13:00:39.022795 2026] [security2:error] [pid 123784:tid 124022] [client 103.120.71.157:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79AAAAGg"] [Tue Aug 18 13:00:39.022897 2026] [security2:error] [pid 123784:tid 124022] [client 103.120.71.157:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79AAAAGg"] [Tue Aug 18 13:00:39.052005 2026] [security2:error] [pid 123784:tid 123989] [client 158.23.17.4:56727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ij.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79gAAAEc"] [Tue Aug 18 13:00:39.065401 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:13091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/tt.php"] [unique_id "aoSBp2wDnJBNj2tDbYb79wAAAFc"] [Tue Aug 18 13:00:39.101342 2026] [security2:error] [pid 123784:tid 124012] [client 20.79.204.6:2646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7-gAAAF4"] [Tue Aug 18 13:00:39.119519 2026] [security2:error] [pid 123784:tid 123809] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_AAAbhQ"] [Tue Aug 18 13:00:39.121236 2026] [security2:error] [pid 123784:tid 124027] [client 158.23.17.4:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/45.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_gAAAG0"] [Tue Aug 18 13:00:39.121438 2026] [security2:error] [pid 123784:tid 124008] [client 20.226.56.190:20876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/mq.php"] [unique_id "aoSBp2wDnJBNj2tDbYb7_wAAAFo"] [Tue Aug 18 13:00:39.148366 2026] [security2:error] [pid 123784:tid 123968] [client 20.250.13.23:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8AAAAADI"] [Tue Aug 18 13:00:39.178662 2026] [security2:error] [pid 123784:tid 123938] [client 20.151.109.219:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qr.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8AwAAABQ"] [Tue Aug 18 13:00:39.191692 2026] [security2:error] [pid 123784:tid 124035] [client 52.173.121.69:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/kopyw.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8CAAAAHU"] [Tue Aug 18 13:00:39.206527 2026] [security2:error] [pid 123784:tid 124044] [client 168.62.48.100:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8DgAAAH4"] [Tue Aug 18 13:00:39.213140 2026] [security2:error] [pid 123784:tid 123954] [client 20.226.56.190:18560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/13.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8EQAAACQ"] [Tue Aug 18 13:00:39.215238 2026] [security2:error] [pid 123784:tid 123926] [client 158.23.17.4:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/se.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8EgAAAAg"] [Tue Aug 18 13:00:39.221617 2026] [security2:error] [pid 123784:tid 123955] [client 20.65.98.162:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/SDsadqwrf.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8FQAAACU"] [Tue Aug 18 13:00:39.228210 2026] [security2:error] [pid 123784:tid 123921] [client 20.226.56.190:18560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/so.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8GQAAAAM"] [Tue Aug 18 13:00:39.233173 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/wp-load.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8GwAAADc"] [Tue Aug 18 13:00:39.247339 2026] [security2:error] [pid 123784:tid 123901] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/cabs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8HgAAFnA"] [Tue Aug 18 13:00:39.265519 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:39.265978 2026] [authz_core:error] [pid 123784:tid 123866] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:39.268688 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27901] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "whm.eezy.site"] [uri "/1.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8IgAAABw"] [Tue Aug 18 13:00:39.268795 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/1.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8IgAAABw"] [Tue Aug 18 13:00:39.289880 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file1221.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8MQAAAF0"] [Tue Aug 18 13:00:39.294997 2026] [security2:error] [pid 123784:tid 123933] [client 20.226.56.190:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/10.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8RQAAAA8"] [Tue Aug 18 13:00:39.300963 2026] [security2:error] [pid 123784:tid 124041] [client 51.116.232.28:19061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/222.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8WAAAAHs"] [Tue Aug 18 13:00:39.320687 2026] [security2:error] [pid 123784:tid 123877] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-good.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XAAAQ1g"] [Tue Aug 18 13:00:39.322375 2026] [security2:error] [pid 123784:tid 124036] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XQAAAHY"] [Tue Aug 18 13:00:39.330278 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/maintenance.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8XgAAAEo"] [Tue Aug 18 13:00:39.341529 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/aa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8YAAAAEs"] [Tue Aug 18 13:00:39.345496 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.156.252:23137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/pema.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8YQAAAFU"] [Tue Aug 18 13:00:39.408392 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.100.201:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/epinyins.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8aAAAAD8"] [Tue Aug 18 13:00:39.428562 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.56.190:40140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/te.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8agAAAGk"] [Tue Aug 18 13:00:39.463400 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-login.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8bAAAAEY"] [Tue Aug 18 13:00:39.513884 2026] [security2:error] [pid 123784:tid 123789] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSBp2wDnJBNj2tDbYb8fAAAWgA"] [Tue Aug 18 13:00:39.514688 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/kc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8fQAAAB4"] [Tue Aug 18 13:00:39.523474 2026] [authz_core:error] [pid 123784:tid 123791] [remote 57.141.22.40:27228] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:39.523896 2026] [authz_core:error] [pid 123784:tid 123791] [remote 57.141.22.40:27228] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:39.530469 2026] [security2:error] [pid 123784:tid 123927] [client 20.116.17.175:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/jj.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8gAAAAAk"] [Tue Aug 18 13:00:39.557038 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/og.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8gQAAADo"] [Tue Aug 18 13:00:39.582544 2026] [security2:error] [pid 123784:tid 123980] [client 20.151.109.219:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dirs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8hAAAAD4"] [Tue Aug 18 13:00:39.623955 2026] [security2:error] [pid 123784:tid 123974] [client 20.226.56.190:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/jn.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8hwAAADg"] [Tue Aug 18 13:00:39.635231 2026] [security2:error] [pid 123784:tid 123931] [client 20.100.169.31:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8mgAAAA0"] [Tue Aug 18 13:00:39.669434 2026] [security2:error] [pid 123784:tid 124006] [client 168.62.48.100:5462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8owAAAFg"] [Tue Aug 18 13:00:39.686167 2026] [security2:error] [pid 123784:tid 123958] [client 4.232.94.69:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp_wol.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pQAAACg"] [Tue Aug 18 13:00:39.691024 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:29479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wy.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pgAAAGA"] [Tue Aug 18 13:00:39.702708 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/load.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8pwAAABE"] [Tue Aug 18 13:00:39.726014 2026] [security2:error] [pid 123784:tid 123851] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/insc.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rAAAeD4"] [Tue Aug 18 13:00:39.733899 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aaa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rQAAAA4"] [Tue Aug 18 13:00:39.738908 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:42231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/sh.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rgAAAF8"] [Tue Aug 18 13:00:39.757198 2026] [security2:error] [pid 123784:tid 123929] [client 51.116.232.28:19020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/key.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8rwAAAAs"] [Tue Aug 18 13:00:39.763242 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.13.23:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-configs.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8tAAAAC4"] [Tue Aug 18 13:00:39.786337 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.27.191:43484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inx.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8tgAAAAA"] [Tue Aug 18 13:00:39.792070 2026] [security2:error] [pid 123784:tid 123952] [client 158.158.74.177:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/simple.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8twAAACI"] [Tue Aug 18 13:00:39.794170 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.36.136:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uAAAAAY"] [Tue Aug 18 13:00:39.822408 2026] [security2:error] [pid 123784:tid 124037] [client 20.116.17.175:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/img.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8ugAAAHc"] [Tue Aug 18 13:00:39.827409 2026] [security2:error] [pid 123784:tid 124036] [client 20.226.56.190:17981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rncarmultimarcas.com.br"] [uri "/bf.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uwAAAHY"] [Tue Aug 18 13:00:39.827967 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8vAAAAAI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:39.838616 2026] [security2:error] [pid 123784:tid 123992] [client 20.65.98.162:56501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8vQAAAEo"] [Tue Aug 18 13:00:39.865147 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:39.865425 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:39.880514 2026] [security2:error] [pid 123784:tid 123950] [client 20.127.136.245:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/alfa.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8xAAAACA"] [Tue Aug 18 13:00:39.889287 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aoSBp2wDnJBNj2tDbYb8xQAAbyM"] [Tue Aug 18 13:00:39.936046 2026] [security2:error] [pid 123784:tid 123946] [client 20.79.204.6:14034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/options-writing.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8yAAAABw"] [Tue Aug 18 13:00:39.978033 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sn.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8zwAAAFQ"] [Tue Aug 18 13:00:39.988903 2026] [security2:error] [pid 123784:tid 124018] [client 20.100.169.31:4955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/abcd.php"] [unique_id "aoSBp2wDnJBNj2tDbYb80QAAAGQ"] [Tue Aug 18 13:00:40.043842 2026] [security2:error] [pid 123784:tid 123816] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/file.php"] [unique_id "aoSBqGwDnJBNj2tDbYb80wAAIxs"] [Tue Aug 18 13:00:40.063283 2026] [security2:error] [pid 123784:tid 123885] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/tes.php"] [unique_id "aoSBqGwDnJBNj2tDbYb81AAAOmA"] [Tue Aug 18 13:00:40.073078 2026] [security2:error] [pid 123784:tid 123938] [client 20.104.100.201:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSBqGwDnJBNj2tDbYb81QAAABQ"] [Tue Aug 18 13:00:40.097764 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/f.php"] [unique_id "aoSBqGwDnJBNj2tDbYb82gAAABI"] [Tue Aug 18 13:00:40.105799 2026] [security2:error] [pid 123784:tid 124044] [client 20.116.17.175:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutoelisacarvalho.com.br"] [uri "/we.php"] [unique_id "aoSBqGwDnJBNj2tDbYb82wAAAH4"] [Tue Aug 18 13:00:40.138729 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/term.php"] [unique_id "aoSBqGwDnJBNj2tDbYb83wAAACQ"] [Tue Aug 18 13:00:40.167109 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:40.167377 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:40.208583 2026] [security2:error] [pid 123784:tid 123947] [client 51.116.232.28:19056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSBqGwDnJBNj2tDbYb84QAAAB0"] [Tue Aug 18 13:00:40.244229 2026] [security2:error] [pid 123784:tid 123864] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/files/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85AAAEUs"] [Tue Aug 18 13:00:40.256921 2026] [security2:error] [pid 123784:tid 123939] [client 20.250.27.191:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/reviall.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85QAAABU"] [Tue Aug 18 13:00:40.257140 2026] [security2:error] [pid 123784:tid 123940] [client 20.65.98.162:45622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/BDKR28WP.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85gAAABY"] [Tue Aug 18 13:00:40.273402 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/button.php"] [unique_id "aoSBqGwDnJBNj2tDbYb85wAAAC4"] [Tue Aug 18 13:00:40.290547 2026] [security2:error] [pid 123784:tid 123980] [client 20.100.169.31:19780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb86gAAAD4"] [Tue Aug 18 13:00:40.302003 2026] [security2:error] [pid 123784:tid 123918] [client 172.202.39.151:44588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSBqGwDnJBNj2tDbYb87QAAAAA"] [Tue Aug 18 13:00:40.304461 2026] [security2:error] [pid 123784:tid 123933] [client 135.225.78.186:33523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/nox.php"] [unique_id "aoSBqGwDnJBNj2tDbYb87wAAAA8"] [Tue Aug 18 13:00:40.335322 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:31903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb88wAAAE8"] [Tue Aug 18 13:00:40.372260 2026] [security2:error] [pid 123784:tid 123985] [client 20.151.109.219:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/43.php"] [unique_id "aoSBqGwDnJBNj2tDbYb8_QAAAEM"] [Tue Aug 18 13:00:40.422907 2026] [security2:error] [pid 123784:tid 124014] [client 158.158.74.177:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/st.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AQAAAGA"] [Tue Aug 18 13:00:40.424427 2026] [security2:error] [pid 123784:tid 123812] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/dex.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AwAAZhc"] [Tue Aug 18 13:00:40.424435 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.13.23:6181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-post.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9AgAAAAU"] [Tue Aug 18 13:00:40.426519 2026] [security2:error] [pid 123784:tid 124029] [client 20.104.100.201:34256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ty.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BAAAAG8"] [Tue Aug 18 13:00:40.427018 2026] [security2:error] [pid 123784:tid 123973] [client 20.127.136.245:27883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BQAAADc"] [Tue Aug 18 13:00:40.430273 2026] [security2:error] [pid 123784:tid 123982] [client 158.23.17.4:51145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9BgAAAEA"] [Tue Aug 18 13:00:40.440935 2026] [security2:error] [pid 123784:tid 123853] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9CgAAc0A"] [Tue Aug 18 13:00:40.466698 2026] [security2:error] [pid 123784:tid 123971] [client 68.221.73.131:55161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/mac.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EAAAADU"] [Tue Aug 18 13:00:40.467572 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:40.467862 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:40.472636 2026] [security2:error] [pid 123784:tid 123956] [client 138.36.100.162:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EQAAACY"] [Tue Aug 18 13:00:40.472740 2026] [security2:error] [pid 123784:tid 123956] [client 138.36.100.162:42405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9EQAAACY"] [Tue Aug 18 13:00:40.551537 2026] [security2:error] [pid 123784:tid 124036] [client 20.79.204.6:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9FgAAAHY"] [Tue Aug 18 13:00:40.563635 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ud.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9FwAAACk"] [Tue Aug 18 13:00:40.571026 2026] [security2:error] [pid 123784:tid 124017] [client 20.79.204.6:2415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GAAAAGM"] [Tue Aug 18 13:00:40.591306 2026] [security2:error] [pid 123784:tid 123943] [client 149.34.210.141:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GgAAABk"] [Tue Aug 18 13:00:40.611965 2026] [security2:error] [pid 123784:tid 123993] [client 20.100.169.31:32472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/admin.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HAAAAEs"] [Tue Aug 18 13:00:40.624805 2026] [security2:error] [pid 123784:tid 123953] [client 20.65.98.162:45583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/sky.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HQAAACM"] [Tue Aug 18 13:00:40.633900 2026] [security2:error] [pid 123784:tid 123850] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/images/images/about.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HgAAXT0"] [Tue Aug 18 13:00:40.648464 2026] [security2:error] [pid 123784:tid 123938] [client 168.62.48.100:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9HwAAABQ"] [Tue Aug 18 13:00:40.650446 2026] [security2:error] [pid 123784:tid 123996] [client 51.116.232.28:19065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/wpxml.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IAAAAE4"] [Tue Aug 18 13:00:40.719667 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.36.136:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IgAAADY"] [Tue Aug 18 13:00:40.739145 2026] [security2:error] [pid 123784:tid 123921] [client 20.79.204.6:10758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ws54.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9IwAAAAM"] [Tue Aug 18 13:00:40.758133 2026] [security2:error] [pid 123784:tid 123935] [client 20.151.109.219:24405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fresh.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9JAAAABE"] [Tue Aug 18 13:00:40.784948 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.156.252:35147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/wlc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9JwAAAF8"] [Tue Aug 18 13:00:40.789558 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.27.191:43513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/11.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KAAAAC4"] [Tue Aug 18 13:00:40.801868 2026] [security2:error] [pid 123784:tid 123795] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/key.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KgAAPgY"] [Tue Aug 18 13:00:40.822432 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.100.201:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9KwAAADQ"] [Tue Aug 18 13:00:40.826002 2026] [security2:error] [pid 123784:tid 123877] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ms-edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LAAAAFg"] [Tue Aug 18 13:00:40.852676 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/7.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LQAAADw"] [Tue Aug 18 13:00:40.853390 2026] [security2:error] [pid 123784:tid 124001] [client 4.232.94.69:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fm2.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9LgAAAFM"] [Tue Aug 18 13:00:40.858162 2026] [security2:error] [pid 123784:tid 123943] [client 149.34.210.141:54388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9GgAAABk"] [Tue Aug 18 13:00:40.862114 2026] [security2:error] [pid 123784:tid 124008] [client 213.35.127.232:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MQAAAFo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:40.895745 2026] [security2:error] [pid 123784:tid 124035] [client 103.184.169.37:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MwAAAHU"] [Tue Aug 18 13:00:40.895890 2026] [security2:error] [pid 123784:tid 124035] [client 103.184.169.37:42946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9MwAAAHU"] [Tue Aug 18 13:00:40.906137 2026] [security2:error] [pid 123784:tid 123998] [client 74.7.230.62:34044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "babiferreiraarquitetura.com.br"] [uri "/index.php"] [unique_id "aoSBp2wDnJBNj2tDbYb8uQAAUDw"] [Tue Aug 18 13:00:40.925190 2026] [security2:error] [pid 123784:tid 123977] [client 20.127.136.245:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/elp.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9NgAAADs"] [Tue Aug 18 13:00:40.982912 2026] [security2:error] [pid 123784:tid 124034] [client 20.65.98.162:56451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file5.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9PgAAAHQ"] [Tue Aug 18 13:00:40.985415 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ph.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9PwAAADU"] [Tue Aug 18 13:00:40.988505 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:9326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/30.php"] [unique_id "aoSBqGwDnJBNj2tDbYb9QQAAACY"] [Tue Aug 18 13:00:41.003954 2026] [security2:error] [pid 123784:tid 123789] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/rip.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9RQAAVAA"] [Tue Aug 18 13:00:41.039671 2026] [security2:error] [pid 123784:tid 123933] [client 20.250.13.23:44064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9RwAAAA8"] [Tue Aug 18 13:00:41.051945 2026] [security2:error] [pid 123784:tid 123924] [client 20.151.109.219:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gj.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9SwAAAAY"] [Tue Aug 18 13:00:41.077827 2026] [security2:error] [pid 123784:tid 123968] [client 51.116.232.28:19059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/file1221.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9TQAAADI"] [Tue Aug 18 13:00:41.100842 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9UgAAAGs"] [Tue Aug 18 13:00:41.127442 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ip.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9VAAAAGU"] [Tue Aug 18 13:00:41.134312 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:34146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ey.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9VgAAABI"] [Tue Aug 18 13:00:41.155715 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:5589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9WQAAAGo"] [Tue Aug 18 13:00:41.156635 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/maint.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9WgAAAA4"] [Tue Aug 18 13:00:41.175256 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:61402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dot.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9XAAAAA0"] [Tue Aug 18 13:00:41.177954 2026] [security2:error] [pid 123784:tid 123929] [client 20.79.204.6:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/akc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9XQAAAAs"] [Tue Aug 18 13:00:41.182506 2026] [security2:error] [pid 123784:tid 123961] [client 54.167.223.174:6580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.autocred360.com.br"] [uri "/index.php"] [unique_id "aoSBqGwDnJBNj2tDbYb86QAAACs"], referer: https://www.autocred360.com.br [Tue Aug 18 13:00:41.185221 2026] [security2:error] [pid 123784:tid 123805] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/"] [unique_id "aoSBqWwDnJBNj2tDbYb9XgAAJRA"] [Tue Aug 18 13:00:41.249843 2026] [security2:error] [pid 123784:tid 123843] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/kir.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YAAAHTY"] [Tue Aug 18 13:00:41.256689 2026] [security2:error] [pid 123784:tid 124040] [client 178.153.171.161:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YQAAAHo"] [Tue Aug 18 13:00:41.256838 2026] [security2:error] [pid 123784:tid 124040] [client 178.153.171.161:7100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YQAAAHo"] [Tue Aug 18 13:00:41.261974 2026] [security2:error] [pid 123784:tid 123989] [client 68.155.156.252:32302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/fi.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YgAAAEc"] [Tue Aug 18 13:00:41.292579 2026] [security2:error] [pid 123784:tid 123988] [client 157.20.138.62:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YwAAAEY"] [Tue Aug 18 13:00:41.292739 2026] [security2:error] [pid 123784:tid 123988] [client 157.20.138.62:60219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9YwAAAEY"] [Tue Aug 18 13:00:41.329517 2026] [security2:error] [pid 123784:tid 123958] [client 20.65.98.162:45569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/xyn.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9aAAAACg"] [Tue Aug 18 13:00:41.345177 2026] [security2:error] [pid 123784:tid 124030] [client 20.226.36.136:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9agAAAHA"] [Tue Aug 18 13:00:41.348001 2026] [security2:error] [pid 123784:tid 123970] [client 52.173.121.69:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zznmg.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9awAAADQ"] [Tue Aug 18 13:00:41.353293 2026] [security2:error] [pid 123784:tid 123918] [client 20.100.169.31:3753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bAAAAAA"] [Tue Aug 18 13:00:41.371379 2026] [security2:error] [pid 123784:tid 123991] [client 20.127.136.245:28069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bQAAAEk"] [Tue Aug 18 13:00:41.371818 2026] [security2:error] [pid 123784:tid 123943] [client 20.250.27.191:45791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/File.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9bgAAABk"] [Tue Aug 18 13:00:41.382531 2026] [security2:error] [pid 123784:tid 123799] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9cAAAaAo"] [Tue Aug 18 13:00:41.479781 2026] [security2:error] [pid 123784:tid 123994] [client 216.73.161.219:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ZgAAAEw"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:00:41.486034 2026] [security2:error] [pid 123784:tid 124041] [client 20.100.169.31:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ewAAAHs"] [Tue Aug 18 13:00:41.513374 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:41.513772 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:41.550046 2026] [security2:error] [pid 123784:tid 123925] [client 51.116.232.28:18978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/nox.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gAAAAAc"] [Tue Aug 18 13:00:41.572954 2026] [security2:error] [pid 123784:tid 124028] [client 20.79.204.6:10383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gQAAAG4"] [Tue Aug 18 13:00:41.573908 2026] [security2:error] [pid 123784:tid 123852] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/moon.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ggAAHj8"] [Tue Aug 18 13:00:41.583863 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:14125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pd.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9gwAAAHk"] [Tue Aug 18 13:00:41.634291 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.98.162:45618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9hgAAAFg"] [Tue Aug 18 13:00:41.635178 2026] [security2:error] [pid 123784:tid 123968] [client 68.155.156.252:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/chris.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9hwAAADI"] [Tue Aug 18 13:00:41.636850 2026] [security2:error] [pid 123784:tid 123804] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/nofile.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9iAAAEA8"] [Tue Aug 18 13:00:41.659551 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.13.23:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9iQAAAHU"] [Tue Aug 18 13:00:41.718590 2026] [security2:error] [pid 123784:tid 124023] [client 158.158.74.177:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/system.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jAAAAGk"] [Tue Aug 18 13:00:41.726540 2026] [security2:error] [pid 123784:tid 123953] [client 20.104.100.201:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/005.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jQAAACM"] [Tue Aug 18 13:00:41.762385 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.13.23:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9jwAAADc"] [Tue Aug 18 13:00:41.768264 2026] [security2:error] [pid 123784:tid 123874] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cache.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kAAAAVU"] [Tue Aug 18 13:00:41.769573 2026] [security2:error] [pid 123784:tid 123949] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file5.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kQAAAB8"] [Tue Aug 18 13:00:41.789969 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:2229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/buy.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9kwAAAGQ"] [Tue Aug 18 13:00:41.794466 2026] [security2:error] [pid 123784:tid 123942] [client 20.250.27.191:35690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fi22.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lAAAABg"] [Tue Aug 18 13:00:41.813798 2026] [security2:error] [pid 123784:tid 124011] [client 158.23.17.4:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lv.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lQAAAF0"] [Tue Aug 18 13:00:41.814199 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:17323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/xyn.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lgAAABI"] [Tue Aug 18 13:00:41.828495 2026] [security2:error] [pid 123784:tid 123996] [client 20.38.3.247:24269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9lwAAAE4"] [Tue Aug 18 13:00:41.828858 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/666.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mAAAAEg"] [Tue Aug 18 13:00:41.832863 2026] [security2:error] [pid 123784:tid 123851] [remote 20.54.134.42:3697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mQAASj4"] [Tue Aug 18 13:00:41.840382 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/phpMailer.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9mgAAAFQ"] [Tue Aug 18 13:00:41.860389 2026] [security2:error] [pid 123784:tid 123972] [client 5.31.227.224:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9nAAAADY"] [Tue Aug 18 13:00:41.860559 2026] [security2:error] [pid 123784:tid 123972] [client 5.31.227.224:1439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9nAAAADY"] [Tue Aug 18 13:00:41.861762 2026] [security2:error] [pid 123784:tid 123790] [remote 47.128.19.249:52060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSBqWwDnJBNj2tDbYb9ngAAagE"] [Tue Aug 18 13:00:41.880661 2026] [security2:error] [pid 123784:tid 123963] [client 168.62.48.100:5610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9oAAAAC0"] [Tue Aug 18 13:00:41.885407 2026] [security2:error] [pid 123784:tid 123971] [client 213.35.127.232:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9oQAAADU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:41.896992 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:29490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pu.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9ogAAAA0"] [Tue Aug 18 13:00:41.952384 2026] [security2:error] [pid 123784:tid 123921] [client 51.116.232.28:18958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/akismet.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9pgAAAAM"] [Tue Aug 18 13:00:41.955449 2026] [security2:error] [pid 123784:tid 123901] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSBqWwDnJBNj2tDbYb9qAAAHXA"] [Tue Aug 18 13:00:41.968393 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/abc.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9qgAAAC8"] [Tue Aug 18 13:00:41.973790 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:41.974073 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:41.981142 2026] [security2:error] [pid 123784:tid 124019] [client 20.100.169.31:19808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9qwAAAGU"] [Tue Aug 18 13:00:41.990280 2026] [security2:error] [pid 123784:tid 123854] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/fling.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9rAAAR0E"] [Tue Aug 18 13:00:41.994381 2026] [security2:error] [pid 123784:tid 123940] [client 135.225.78.186:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/akismet.php"] [unique_id "aoSBqWwDnJBNj2tDbYb9rQAAABY"] [Tue Aug 18 13:00:42.014074 2026] [security2:error] [pid 123784:tid 124013] [client 20.151.109.219:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/th.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9rwAAAF8"] [Tue Aug 18 13:00:42.049554 2026] [security2:error] [pid 123784:tid 123918] [client 68.155.156.252:48105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/doc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9swAAAAA"] [Tue Aug 18 13:00:42.089368 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tAAAACI"] [Tue Aug 18 13:00:42.118190 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:61414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/v2.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tQAAAHc"] [Tue Aug 18 13:00:42.125911 2026] [security2:error] [pid 123784:tid 123961] [client 20.100.169.31:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/akc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9tgAAACs"] [Tue Aug 18 13:00:42.137735 2026] [security2:error] [pid 123784:tid 123828] [remote 47.128.19.249:51956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSBqmwDnJBNj2tDbYb9uAAAaCc"] [Tue Aug 18 13:00:42.139209 2026] [security2:error] [pid 123784:tid 123824] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/vendor/"] [unique_id "aoSBqmwDnJBNj2tDbYb9uQAALCM"] [Tue Aug 18 13:00:42.201987 2026] [security2:error] [pid 123784:tid 124012] [client 68.221.73.131:55163] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9uwAAAF4"] [Tue Aug 18 13:00:42.202090 2026] [security2:error] [pid 123784:tid 124012] [client 68.221.73.131:55163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9uwAAAF4"] [Tue Aug 18 13:00:42.208426 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/99.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9vQAAABc"] [Tue Aug 18 13:00:42.239483 2026] [security2:error] [pid 123784:tid 124017] [client 20.65.98.162:56497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/inso.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wAAAAGM"] [Tue Aug 18 13:00:42.274133 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:42.274416 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:42.279947 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:63937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wwAAAFA"] [Tue Aug 18 13:00:42.280335 2026] [security2:error] [pid 123784:tid 123998] [client 102.213.179.104:63937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9wwAAAFA"] [Tue Aug 18 13:00:42.281352 2026] [security2:error] [pid 123784:tid 123953] [client 20.250.27.191:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9xAAAACM"] [Tue Aug 18 13:00:42.297836 2026] [autoindex:error] [pid 123784:tid 124032] [client 201.69.204.147:52297] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.309743 2026] [security2:error] [pid 123784:tid 123791] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/zoo1.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9yAAAHwI"] [Tue Aug 18 13:00:42.323751 2026] [security2:error] [pid 123784:tid 123997] [client 20.250.13.23:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9ygAAAE8"] [Tue Aug 18 13:00:42.325176 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/s.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9ywAAAGQ"] [Tue Aug 18 13:00:42.334840 2026] [security2:error] [pid 123784:tid 123886] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/"] [unique_id "aoSBqmwDnJBNj2tDbYb9zQAAFGE"] [Tue Aug 18 13:00:42.367701 2026] [security2:error] [pid 123784:tid 123936] [client 51.116.232.28:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/admin.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9zgAAABI"] [Tue Aug 18 13:00:42.372197 2026] [security2:error] [pid 123784:tid 124044] [client 20.151.109.219:14085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/admin404.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9zwAAAH4"] [Tue Aug 18 13:00:42.377619 2026] [security2:error] [pid 123784:tid 124026] [client 20.206.73.37:29991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90AAAAGw"] [Tue Aug 18 13:00:42.391055 2026] [security2:error] [pid 123784:tid 123926] [client 20.79.204.6:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/cong.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90QAAAAg"] [Tue Aug 18 13:00:42.398130 2026] [security2:error] [pid 123784:tid 124002] [client 20.91.215.254:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/backup.php"] [unique_id "aoSBqmwDnJBNj2tDbYb90gAAAFQ"] [Tue Aug 18 13:00:42.407496 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91AAAAGY"] [Tue Aug 18 13:00:42.440143 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91gAAAFg"] [Tue Aug 18 13:00:42.450524 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:44829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/51.php"] [unique_id "aoSBqmwDnJBNj2tDbYb91wAAAHM"] [Tue Aug 18 13:00:42.455216 2026] [security2:error] [pid 123784:tid 123963] [client 20.104.100.201:61433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wkl.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92AAAAC0"] [Tue Aug 18 13:00:42.458384 2026] [security2:error] [pid 123784:tid 123971] [client 20.127.136.245:28048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ws54.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92QAAADU"] [Tue Aug 18 13:00:42.466108 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/system_log.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92gAAAEs"] [Tue Aug 18 13:00:42.467218 2026] [security2:error] [pid 123784:tid 124045] [client 168.62.48.100:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSBqmwDnJBNj2tDbYb92wAAAH8"] [Tue Aug 18 13:00:42.492339 2026] [security2:error] [pid 123784:tid 123956] [client 20.226.36.136:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSBqmwDnJBNj2tDbYb93QAAACY"] [Tue Aug 18 13:00:42.509432 2026] [security2:error] [pid 123784:tid 123973] [client 79.127.164.8:32978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/www.bak"] [unique_id "aoSBqmwDnJBNj2tDbYb93wAAADc"], referer: https://medihub.com.br/www.bak [Tue Aug 18 13:00:42.538810 2026] [security2:error] [pid 123784:tid 123914] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBqmwDnJBNj2tDbYb94wAAZX0"] [Tue Aug 18 13:00:42.551193 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:9369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ry.php"] [unique_id "aoSBqmwDnJBNj2tDbYb95AAAABY"] [Tue Aug 18 13:00:42.575477 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:42.575741 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:42.599147 2026] [security2:error] [pid 123784:tid 123964] [client 68.155.156.252:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/1337.php"] [unique_id "aoSBqmwDnJBNj2tDbYb95wAAAC4"] [Tue Aug 18 13:00:42.634045 2026] [autoindex:error] [pid 123784:tid 123980] [client 172.202.39.151:40344] AH01276: Cannot serve directory /home2/ctamcursos/grupoctam.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.638046 2026] [security2:error] [pid 123784:tid 123859] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/zoo2.php"] [unique_id "aoSBqmwDnJBNj2tDbYb96wAANEY"] [Tue Aug 18 13:00:42.675963 2026] [autoindex:error] [pid 123784:tid 123978] [client 201.69.204.147:52301] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.693964 2026] [security2:error] [pid 123784:tid 123961] [client 20.151.109.219:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb97gAAACs"] [Tue Aug 18 13:00:42.697384 2026] [autoindex:error] [pid 123784:tid 124037] [client 169.58.72.248:54025] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.721243 2026] [security2:error] [pid 123784:tid 123994] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98AAAAEw"] [Tue Aug 18 13:00:42.746150 2026] [security2:error] [pid 123784:tid 124030] [client 20.65.98.162:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/puc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98QAAAHA"] [Tue Aug 18 13:00:42.762977 2026] [security2:error] [pid 123784:tid 123950] [client 168.62.48.100:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSBqmwDnJBNj2tDbYb98wAAACA"] [Tue Aug 18 13:00:42.770453 2026] [security2:error] [pid 123784:tid 123863] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/crop/"] [unique_id "aoSBqmwDnJBNj2tDbYb99AAAYko"] [Tue Aug 18 13:00:42.771328 2026] [security2:error] [pid 123784:tid 124012] [client 20.104.100.201:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb99QAAAF4"] [Tue Aug 18 13:00:42.779711 2026] [security2:error] [pid 123784:tid 123941] [client 51.116.232.28:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "queroficarnanet.com"] [uri "/ajax.php"] [unique_id "aoSBqmwDnJBNj2tDbYb99wAAABc"] [Tue Aug 18 13:00:42.796875 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.27.191:3597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9-AAAAHk"] [Tue Aug 18 13:00:42.832366 2026] [autoindex:error] [pid 123784:tid 123927] [client 201.69.204.147:52305] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.875126 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:42.875381 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:42.902621 2026] [security2:error] [pid 123784:tid 123988] [client 213.35.127.232:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBqmwDnJBNj2tDbYb9_wAAAEY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:42.909510 2026] [security2:error] [pid 123784:tid 124022] [client 20.100.169.31:24230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/buy.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AAAAAGg"] [Tue Aug 18 13:00:42.909839 2026] [autoindex:error] [pid 123784:tid 123998] [client 201.69.204.147:52308] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:42.910872 2026] [security2:error] [pid 123784:tid 124031] [client 223.185.37.47:2599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AQAAAHE"] [Tue Aug 18 13:00:42.919500 2026] [security2:error] [pid 123784:tid 124031] [client 223.185.37.47:2599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-AQAAAHE"] [Tue Aug 18 13:00:42.958182 2026] [security2:error] [pid 123784:tid 123862] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-mail.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BAAAFEk"] [Tue Aug 18 13:00:42.969200 2026] [security2:error] [pid 123784:tid 123924] [client 20.127.136.245:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/deepseek_d.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BQAAAAY"] [Tue Aug 18 13:00:42.969329 2026] [security2:error] [pid 123784:tid 124027] [client 20.250.13.23:44063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/cjfuns.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BgAAAG0"] [Tue Aug 18 13:00:42.973318 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/uo.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-BwAAAFk"] [Tue Aug 18 13:00:42.976619 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:40344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wso.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-CAAAAF0"] [Tue Aug 18 13:00:42.992167 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.36.136:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSBqmwDnJBNj2tDbYb-CQAAABI"] [Tue Aug 18 13:00:43.014174 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.204.6:2409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-CgAAAB4"] [Tue Aug 18 13:00:43.027517 2026] [security2:error] [pid 123784:tid 123926] [client 20.151.109.219:39325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sd.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-CwAAAAg"] [Tue Aug 18 13:00:43.028637 2026] [security2:error] [pid 123784:tid 124009] [client 20.100.169.31:38657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DAAAAFs"] [Tue Aug 18 13:00:43.034380 2026] [security2:error] [pid 123784:tid 124002] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/atomlib.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DQAAAFQ"] [Tue Aug 18 13:00:43.042557 2026] [security2:error] [pid 123784:tid 123968] [client 20.79.204.6:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/al.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-DgAAADI"] [Tue Aug 18 13:00:43.059966 2026] [security2:error] [pid 123784:tid 123792] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/org.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EAAAZgM"] [Tue Aug 18 13:00:43.076324 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.156.252:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/Njima.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EQAAAFg"] [Tue Aug 18 13:00:43.081508 2026] [security2:error] [pid 123784:tid 123919] [client 158.23.17.4:31918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ew.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EgAAAAE"] [Tue Aug 18 13:00:43.089787 2026] [security2:error] [pid 123784:tid 124004] [client 158.158.74.177:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-EwAAAFY"] [Tue Aug 18 13:00:43.104068 2026] [security2:error] [pid 123784:tid 124033] [client 168.62.48.100:5629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GAAAAHM"] [Tue Aug 18 13:00:43.136328 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:27402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GgAAACM"] [Tue Aug 18 13:00:43.139671 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/az.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-GwAAAH8"] [Tue Aug 18 13:00:43.145034 2026] [security2:error] [pid 123784:tid 123976] [client 185.191.171.8:42568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/robots.txt"] [unique_id "aoSBq2wDnJBNj2tDbYb-HQAAADo"] [Tue Aug 18 13:00:43.145178 2026] [security2:error] [pid 123784:tid 123976] [client 185.191.171.8:42568] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/robots.txt"] [unique_id "aoSBq2wDnJBNj2tDbYb-HQAAADo"] [Tue Aug 18 13:00:43.146408 2026] [security2:error] [pid 123784:tid 123931] [client 68.221.73.131:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/coffee.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-HgAAAA0"] [Tue Aug 18 13:00:43.151751 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/NewFile.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-HwAAAFc"] [Tue Aug 18 13:00:43.154956 2026] [security2:error] [pid 123784:tid 123810] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/o.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-IAAACxU"] [Tue Aug 18 13:00:43.176002 2026] [security2:error] [pid 123784:tid 123973] [client 135.225.78.186:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/admin.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-IwAAADc"] [Tue Aug 18 13:00:43.254893 2026] [security2:error] [pid 123784:tid 123921] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-JQAAAzs"] [Tue Aug 18 13:00:43.292126 2026] [security2:error] [pid 123784:tid 123954] [client 20.250.27.191:43467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-JwAAACQ"] [Tue Aug 18 13:00:43.348897 2026] [security2:error] [pid 123784:tid 123912] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/bb.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-KgAAQHs"] [Tue Aug 18 13:00:43.397755 2026] [security2:error] [pid 123784:tid 124037] [client 20.65.98.162:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/19.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-LQAAAHc"] [Tue Aug 18 13:00:43.428276 2026] [security2:error] [pid 123784:tid 123841] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/imageskir.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-LwAAOTQ"] [Tue Aug 18 13:00:43.473003 2026] [security2:error] [pid 123784:tid 124016] [client 168.62.48.100:5581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-MgAAAGI"] [Tue Aug 18 13:00:43.477853 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:43.478124 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:43.498046 2026] [security2:error] [pid 123784:tid 123941] [client 20.104.100.201:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/z43agz.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-NAAAABc"] [Tue Aug 18 13:00:43.529443 2026] [security2:error] [pid 123784:tid 124003] [client 4.232.94.69:15676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSBq2wDnJBNj2tDbYb-NgAAAFU"] [Tue Aug 18 13:00:43.529543 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/er.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-NwAAADE"] [Tue Aug 18 13:00:43.533282 2026] [security2:error] [pid 123784:tid 123819] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OAAAYx4"] [Tue Aug 18 13:00:43.558931 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pm.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OgAAABA"] [Tue Aug 18 13:00:43.561429 2026] [security2:error] [pid 123784:tid 123958] [client 20.100.169.31:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/cong.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-OwAAACg"] [Tue Aug 18 13:00:43.567686 2026] [security2:error] [pid 123784:tid 123962] [client 20.127.136.245:27851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/function/function.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PAAAACw"] [Tue Aug 18 13:00:43.579211 2026] [security2:error] [pid 123784:tid 124001] [client 20.79.204.6:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/function/function.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PQAAAFM"] [Tue Aug 18 13:00:43.587244 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.56.190:28849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-PgAAAHs"] [Tue Aug 18 13:00:43.606698 2026] [security2:error] [pid 123784:tid 124022] [client 68.155.156.252:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/BIBIL.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-QQAAAGg"] [Tue Aug 18 13:00:43.627786 2026] [security2:error] [pid 123784:tid 124030] [client 20.79.204.6:2221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/db.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-QgAAAHA"] [Tue Aug 18 13:00:43.650635 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.36.136:62197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RAAAAAY"] [Tue Aug 18 13:00:43.651909 2026] [security2:error] [pid 123784:tid 123974] [client 20.79.204.6:14090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RQAAADg"] [Tue Aug 18 13:00:43.670713 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:3760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-RgAAAAc"] [Tue Aug 18 13:00:43.709041 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-SwAAAHk"] [Tue Aug 18 13:00:43.734234 2026] [security2:error] [pid 123784:tid 123825] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/"] [unique_id "aoSBq2wDnJBNj2tDbYb-TAAAHiQ"] [Tue Aug 18 13:00:43.746956 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/km.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-TQAAAFQ"] [Tue Aug 18 13:00:43.748346 2026] [security2:error] [pid 123784:tid 123845] [remote 57.141.22.7:29010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSBq2wDnJBNj2tDbYb-TgAACTg"] [Tue Aug 18 13:00:43.751130 2026] [security2:error] [pid 123784:tid 123861] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/indexo.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-TwAAaUg"] [Tue Aug 18 13:00:43.757855 2026] [security2:error] [pid 123784:tid 123957] [client 168.62.48.100:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UAAAACc"] [Tue Aug 18 13:00:43.760983 2026] [security2:error] [pid 123784:tid 124020] [client 172.202.39.151:12736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/sf.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UQAAAGY"] [Tue Aug 18 13:00:43.776198 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/pqr.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-UwAAAFg"] [Tue Aug 18 13:00:43.778642 2026] [security2:error] [pid 123784:tid 124035] [client 158.158.74.177:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/test.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VAAAAHU"] [Tue Aug 18 13:00:43.779324 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:43.779585 2026] [authz_core:error] [pid 123784:tid 123899] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:43.805261 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/min.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VQAAAFY"] [Tue Aug 18 13:00:43.811803 2026] [security2:error] [pid 123784:tid 124000] [client 20.91.215.254:12009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/sx.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-VgAAAFI"] [Tue Aug 18 13:00:43.855434 2026] [security2:error] [pid 123784:tid 123963] [client 52.141.58.175:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tmp/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-WAAAAC0"] [Tue Aug 18 13:00:43.857860 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/3.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-WQAAAH8"] [Tue Aug 18 13:00:43.909906 2026] [security2:error] [pid 123784:tid 123882] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XAAAdl0"] [Tue Aug 18 13:00:43.917977 2026] [security2:error] [pid 123784:tid 124025] [client 213.35.127.232:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XQAAAGs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:43.954550 2026] [security2:error] [pid 123784:tid 123977] [client 68.155.156.252:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/too.php"] [unique_id "aoSBq2wDnJBNj2tDbYb-XwAAADs"] [Tue Aug 18 13:00:44.016334 2026] [security2:error] [pid 123784:tid 124040] [client 172.202.39.151:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/akcc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-YQAAAHo"] [Tue Aug 18 13:00:44.032414 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-YgAAAEc"] [Tue Aug 18 13:00:44.068409 2026] [security2:error] [pid 123784:tid 123956] [client 20.127.136.245:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ZQAAACY"] [Tue Aug 18 13:00:44.082743 2026] [security2:error] [pid 123784:tid 123814] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmrlpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-aAAAXxk"] [Tue Aug 18 13:00:44.083663 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:44.084121 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:44.100444 2026] [security2:error] [pid 123784:tid 124029] [client 20.65.98.162:45614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/133.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-aQAAAG8"] [Tue Aug 18 13:00:44.107487 2026] [security2:error] [pid 123784:tid 123992] [client 68.221.73.131:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-agAAAEo"] [Tue Aug 18 13:00:44.122596 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/an.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-cwAAAD4"] [Tue Aug 18 13:00:44.134168 2026] [security2:error] [pid 123784:tid 123943] [client 158.23.17.4:47928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kx.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dQAAABk"] [Tue Aug 18 13:00:44.145086 2026] [security2:error] [pid 123784:tid 123985] [client 37.40.227.74:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dgAAAEM"] [Tue Aug 18 13:00:44.145243 2026] [security2:error] [pid 123784:tid 123985] [client 37.40.227.74:57058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-dgAAAEM"] [Tue Aug 18 13:00:44.157770 2026] [security2:error] [pid 123784:tid 123933] [client 20.151.109.219:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mf.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-eAAAAA8"] [Tue Aug 18 13:00:44.178202 2026] [security2:error] [pid 123784:tid 124008] [client 20.104.100.201:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/log.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-eQAAAFo"] [Tue Aug 18 13:00:44.194246 2026] [security2:error] [pid 123784:tid 123879] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ewAAflo"] [Tue Aug 18 13:00:44.195514 2026] [autoindex:error] [pid 123784:tid 124037] [client 137.184.230.120:55150] AH01276: Cannot serve directory /home3/andrades/mail.andradesales.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:44.197969 2026] [security2:error] [pid 123784:tid 124019] [client 20.100.169.31:4948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-fAAAAGU"] [Tue Aug 18 13:00:44.221259 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:20444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qk.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-fgAAAGc"] [Tue Aug 18 13:00:44.258933 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.204.6:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-activat.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-gQAAAGA"] [Tue Aug 18 13:00:44.270810 2026] [security2:error] [pid 123784:tid 123913] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/file.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ggAAbnw"] [Tue Aug 18 13:00:44.275432 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:2196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/dropdown.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-gwAAABY"] [Tue Aug 18 13:00:44.278511 2026] [security2:error] [pid 123784:tid 123932] [client 52.173.121.69:15020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/bhfnd.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-hAAAAA4"] [Tue Aug 18 13:00:44.336358 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.13.23:51902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-iAAAADc"] [Tue Aug 18 13:00:44.347894 2026] [autoindex:error] [pid 123784:tid 124032] [client 205.210.31.18:63808] AH01276: Cannot serve directory /home1/gfrison965/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:44.354571 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:44040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-iwAAADQ"] [Tue Aug 18 13:00:44.358779 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-jAAAAFA"] [Tue Aug 18 13:00:44.392342 2026] [security2:error] [pid 123784:tid 123938] [client 172.202.39.151:60121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/gecko.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-jwAAABQ"] [Tue Aug 18 13:00:44.406762 2026] [security2:error] [pid 123784:tid 124027] [client 68.155.156.252:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.autocompanymultimarcas.com.br"] [uri "/g3.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kAAAAG0"] [Tue Aug 18 13:00:44.409472 2026] [security2:error] [pid 123784:tid 123930] [client 20.79.204.6:10388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kQAAAAw"] [Tue Aug 18 13:00:44.419308 2026] [security2:error] [pid 123784:tid 123996] [client 43.157.22.57:56188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bioarquitetar.com"] [uri "/wp-admin/upgrade.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-kgAAAE4"] [Tue Aug 18 13:00:44.422436 2026] [security2:error] [pid 123784:tid 123995] [client 158.158.74.177:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/test1.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lAAAAE0"] [Tue Aug 18 13:00:44.423347 2026] [security2:error] [pid 123784:tid 123945] [client 52.141.58.175:11682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tmpls.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lQAAABs"] [Tue Aug 18 13:00:44.449552 2026] [security2:error] [pid 123784:tid 123948] [client 172.202.39.151:40333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/index/function.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lgAAAB4"] [Tue Aug 18 13:00:44.450892 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:4346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-lwAAAAg"] [Tue Aug 18 13:00:44.489619 2026] [security2:error] [pid 123784:tid 123942] [client 20.250.27.191:35676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ngAAABg"] [Tue Aug 18 13:00:44.500273 2026] [security2:error] [pid 123784:tid 124006] [client 20.151.109.219:14103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ie.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-oAAAAFg"] [Tue Aug 18 13:00:44.502590 2026] [security2:error] [pid 123784:tid 124035] [client 20.100.169.31:19826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-oQAAAHU"] [Tue Aug 18 13:00:44.524575 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ohct.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-owAAAFI"] [Tue Aug 18 13:00:44.526233 2026] [security2:error] [pid 123784:tid 124033] [client 20.118.133.132:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/php.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pAAAAHM"] [Tue Aug 18 13:00:44.535160 2026] [security2:error] [pid 123784:tid 123807] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/8pyceeo.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pQAASxI"] [Tue Aug 18 13:00:44.552575 2026] [security2:error] [pid 123784:tid 123963] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/mac.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-pgAAAC0"] [Tue Aug 18 13:00:44.566848 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.56.190:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qQAAAFc"] [Tue Aug 18 13:00:44.574103 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/xleet.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qgAAAB8"] [Tue Aug 18 13:00:44.574419 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/st.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-qwAAAHA"] [Tue Aug 18 13:00:44.627209 2026] [security2:error] [pid 123784:tid 123803] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/epinyins.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-rgAAaw4"] [Tue Aug 18 13:00:44.782103 2026] [security2:error] [pid 123784:tid 123982] [client 20.65.98.162:56479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/1xmomo.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-sgAAAEA"] [Tue Aug 18 13:00:44.792385 2026] [security2:error] [pid 123784:tid 123918] [client 20.151.109.219:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nw.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-tQAAAAA"] [Tue Aug 18 13:00:44.804097 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/va.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-tgAAAFo"] [Tue Aug 18 13:00:44.813387 2026] [security2:error] [pid 123784:tid 123840] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-twAAfjM"] [Tue Aug 18 13:00:44.827805 2026] [security2:error] [pid 123784:tid 124037] [client 68.221.73.131:55151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uAAAAHc"] [Tue Aug 18 13:00:44.865709 2026] [security2:error] [pid 123784:tid 123994] [client 20.75.92.165:4345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uQAAAEw"] [Tue Aug 18 13:00:44.869417 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-ugAAAEY"] [Tue Aug 18 13:00:44.872212 2026] [security2:error] [pid 123784:tid 123923] [client 20.100.169.31:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/db.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-uwAAAAU"] [Tue Aug 18 13:00:44.881574 2026] [security2:error] [pid 123784:tid 124040] [client 20.79.204.6:2232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/file.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vQAAAHo"] [Tue Aug 18 13:00:44.884066 2026] [security2:error] [pid 123784:tid 123852] [remote 89.185.225.24:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vgAAOT8"] [Tue Aug 18 13:00:44.896973 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.36.136:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/rezor.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-vwAAAGI"] [Tue Aug 18 13:00:44.931272 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-wAAAABw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:44.965446 2026] [security2:error] [pid 123784:tid 124003] [client 4.232.94.69:19564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gebase.php69"] [unique_id "aoSBrGwDnJBNj2tDbYb-wgAAAFU"] [Tue Aug 18 13:00:44.975834 2026] [security2:error] [pid 123784:tid 123804] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/.admin.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-wwAAEA8"] [Tue Aug 18 13:00:44.983775 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.13.23:23741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/import.php"] [unique_id "aoSBrGwDnJBNj2tDbYb-xAAAAC4"] [Tue Aug 18 13:00:44.997143 2026] [security2:error] [pid 123784:tid 123881] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/php-compat/"] [unique_id "aoSBrGwDnJBNj2tDbYb-xQAAClw"] [Tue Aug 18 13:00:45.019677 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/nc4.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-yQAAADc"] [Tue Aug 18 13:00:45.032567 2026] [security2:error] [pid 123784:tid 124032] [client 20.104.100.201:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ot.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-ygAAAHI"] [Tue Aug 18 13:00:45.035284 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:34133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sy.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-ywAAAFA"] [Tue Aug 18 13:00:45.056118 2026] [security2:error] [pid 123784:tid 124019] [client 158.158.74.177:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/text.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-zAAAAGU"] [Tue Aug 18 13:00:45.068230 2026] [security2:error] [pid 123784:tid 123967] [client 20.127.136.245:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-zgAAADE"] [Tue Aug 18 13:00:45.112934 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.27.191:45783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0AAAAE0"] [Tue Aug 18 13:00:45.113036 2026] [security2:error] [pid 123784:tid 123945] [client 158.23.17.4:63676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dr.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0QAAABs"] [Tue Aug 18 13:00:45.114292 2026] [security2:error] [pid 123784:tid 123922] [client 20.151.109.219:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sb.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0gAAAAQ"] [Tue Aug 18 13:00:45.136714 2026] [security2:error] [pid 123784:tid 123851] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0wAAKj4"] [Tue Aug 18 13:00:45.136933 2026] [security2:error] [pid 123784:tid 123960] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-0wAAKj4"] [Tue Aug 18 13:00:45.164291 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-1QAAABU"] [Tue Aug 18 13:00:45.173514 2026] [security2:error] [pid 123784:tid 123865] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-1gAAGEw"] [Tue Aug 18 13:00:45.184562 2026] [security2:error] [pid 123784:tid 124035] [client 20.65.98.162:45613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/mosty.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2AAAAHU"] [Tue Aug 18 13:00:45.208293 2026] [security2:error] [pid 123784:tid 124033] [client 20.75.92.165:4335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/admin.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2gAAAHM"] [Tue Aug 18 13:00:45.212516 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-2wAAAFM"] [Tue Aug 18 13:00:45.289486 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:45.289938 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:45.312244 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-3QAAAEc"] [Tue Aug 18 13:00:45.331098 2026] [autoindex:error] [pid 123784:tid 123940] [client 137.184.230.120:35224] AH01276: Cannot serve directory /home3/andrades/mail.andradesales.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:45.332107 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fo.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-3wAAAAI"] [Tue Aug 18 13:00:45.358955 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wk/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4AAAAF8"] [Tue Aug 18 13:00:45.379435 2026] [security2:error] [pid 123784:tid 123826] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/wsomini.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4QAAPiU"] [Tue Aug 18 13:00:45.380168 2026] [security2:error] [pid 123784:tid 123836] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4wAASi8"] [Tue Aug 18 13:00:45.380515 2026] [security2:error] [pid 123784:tid 123981] [client 20.100.169.31:19794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-4gAAAD8"] [Tue Aug 18 13:00:45.391441 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.36.136:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/index/function.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5AAAABk"] [Tue Aug 18 13:00:45.410769 2026] [security2:error] [pid 123784:tid 124037] [client 20.226.36.136:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5QAAAHc"] [Tue Aug 18 13:00:45.427990 2026] [security2:error] [pid 123784:tid 123923] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/as.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-5gAAAAU"] [Tue Aug 18 13:00:45.451069 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.36.136:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/Cachex.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6AAAAEU"] [Tue Aug 18 13:00:45.453943 2026] [security2:error] [pid 123784:tid 123941] [client 20.151.109.219:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xj.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6QAAABc"] [Tue Aug 18 13:00:45.458218 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:1287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/57.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6gAAAHw"] [Tue Aug 18 13:00:45.460742 2026] [security2:error] [pid 123784:tid 124028] [client 20.104.100.201:34763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/v5.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-6wAAAG4"] [Tue Aug 18 13:00:45.471550 2026] [security2:error] [pid 123784:tid 124031] [client 52.141.58.175:4221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/tool.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7AAAAHE"] [Tue Aug 18 13:00:45.473983 2026] [security2:error] [pid 123784:tid 123991] [client 68.221.73.131:55133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/yj09.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7QAAAEk"] [Tue Aug 18 13:00:45.475092 2026] [security2:error] [pid 123784:tid 124025] [client 20.79.204.6:14134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/past1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-7gAAAGs"] [Tue Aug 18 13:00:45.498986 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.36.136:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8QAAADc"] [Tue Aug 18 13:00:45.501790 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:40371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8gAAAGg"] [Tue Aug 18 13:00:45.504640 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/dropdown.php"] [unique_id "aoSBrWwDnJBNj2tDbYb-8wAAADs"] [Tue Aug 18 13:00:45.525194 2026] [security2:error] [pid 123784:tid 124010] [client 20.79.204.6:2395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/goods.php"] [unique_id "aoSBrWwDnJBNj2tDbYb--QAAAFw"] [Tue Aug 18 13:00:45.566289 2026] [security2:error] [pid 123784:tid 123985] [client 20.127.136.245:27849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/155.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_AQAAAEM"] [Tue Aug 18 13:00:45.577037 2026] [security2:error] [pid 123784:tid 123827] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_BgAAEiY"] [Tue Aug 18 13:00:45.585296 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:45.585747 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:45.592412 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.36.136:65280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-2019.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_CAAAAE0"] [Tue Aug 18 13:00:45.625876 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.36.136:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_CwAAAFg"] [Tue Aug 18 13:00:45.643513 2026] [security2:error] [pid 123784:tid 124035] [client 20.75.92.165:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DQAAAHU"] [Tue Aug 18 13:00:45.644507 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.56.190:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/dirs.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DgAAADY"] [Tue Aug 18 13:00:45.646088 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/.cache/x.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_DwAAAFI"] [Tue Aug 18 13:00:45.675474 2026] [security2:error] [pid 123784:tid 124018] [client 158.158.74.177:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_EgAAAGQ"] [Tue Aug 18 13:00:45.679708 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_EwAAADo"] [Tue Aug 18 13:00:45.719505 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:43787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/cropper.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_FQAAADw"] [Tue Aug 18 13:00:45.753771 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.36.136:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GAAAAD4"] [Tue Aug 18 13:00:45.761000 2026] [security2:error] [pid 123784:tid 123876] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/function/function.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GQAASlc"] [Tue Aug 18 13:00:45.803635 2026] [security2:error] [pid 123784:tid 123943] [client 20.104.100.201:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_GwAAABk"] [Tue Aug 18 13:00:45.808126 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.36.136:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HAAAAHg"] [Tue Aug 18 13:00:45.814424 2026] [security2:error] [pid 123784:tid 123957] [client 196.12.128.158:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HgAAACc"] [Tue Aug 18 13:00:45.814555 2026] [security2:error] [pid 123784:tid 123957] [client 196.12.128.158:52045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HgAAACc"] [Tue Aug 18 13:00:45.821676 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_HwAAAHc"] [Tue Aug 18 13:00:45.829024 2026] [security2:error] [pid 123784:tid 123994] [client 20.250.27.191:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IAAAAEw"] [Tue Aug 18 13:00:45.844688 2026] [security2:error] [pid 123784:tid 123859] [remote 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.paypix.co"] [uri "/vr.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IQAAC0Y"] [Tue Aug 18 13:00:45.846555 2026] [security2:error] [pid 123784:tid 123923] [client 52.173.121.69:48403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/qfvqu.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_IgAAAAU"] [Tue Aug 18 13:00:45.859940 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.36.136:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JAAAADI"] [Tue Aug 18 13:00:45.861578 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:4434] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eezy.site"] [uri "/1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JQAAAEU"] [Tue Aug 18 13:00:45.861677 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/1.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_JQAAAEU"] [Tue Aug 18 13:00:45.884175 2026] [security2:error] [pid 123784:tid 123934] [client 158.23.17.4:33991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ah.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_MwAAABA"] [Tue Aug 18 13:00:45.886702 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:45.886969 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:45.893750 2026] [security2:error] [pid 123784:tid 124025] [client 20.226.36.136:61469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_OgAAAGs"] [Tue Aug 18 13:00:45.903552 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:18119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-configs.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_PAAAAHA"] [Tue Aug 18 13:00:45.913929 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_QAAAAAY"] [Tue Aug 18 13:00:45.914047 2026] [security2:error] [pid 123784:tid 123924] [client 197.184.64.235:41959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_QAAAAAY"] [Tue Aug 18 13:00:45.935996 2026] [security2:error] [pid 123784:tid 123937] [client 20.226.36.136:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RAAAABM"] [Tue Aug 18 13:00:45.937395 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/loading.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RQAAACk"] [Tue Aug 18 13:00:45.938195 2026] [security2:error] [pid 123784:tid 123898] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RgAALm0"] [Tue Aug 18 13:00:45.942783 2026] [security2:error] [pid 123784:tid 123960] [client 213.35.127.232:63357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_RwAAACo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:45.986446 2026] [security2:error] [pid 123784:tid 123997] [client 168.62.48.100:5620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSBrWwDnJBNj2tDbYb_SQAAAE8"] [Tue Aug 18 13:00:46.001900 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:52641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_SgAAAG0"] [Tue Aug 18 13:00:46.007136 2026] [security2:error] [pid 123784:tid 123985] [client 20.75.92.165:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/w.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TAAAAEM"] [Tue Aug 18 13:00:46.013489 2026] [security2:error] [pid 123784:tid 123982] [client 20.100.169.31:19803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TQAAAEA"] [Tue Aug 18 13:00:46.034473 2026] [security2:error] [pid 123784:tid 124039] [client 20.102.65.165:8313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_TgAAAHk"] [Tue Aug 18 13:00:46.044438 2026] [security2:error] [pid 123784:tid 123979] [client 20.65.98.162:56477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/blurbs.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_UQAAAD0"] [Tue Aug 18 13:00:46.063457 2026] [security2:error] [pid 123784:tid 124000] [client 20.151.109.219:24411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_UwAAAFI"] [Tue Aug 18 13:00:46.084051 2026] [security2:error] [pid 123784:tid 124042] [client 20.79.204.6:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/file61.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_VQAAAHw"] [Tue Aug 18 13:00:46.106522 2026] [security2:error] [pid 123784:tid 124045] [client 135.225.78.186:21801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pagazulrecovery.3xsolutions.com"] [uri "/ajax.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WAAAAH8"] [Tue Aug 18 13:00:46.107537 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.36.136:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WQAAAGQ"] [Tue Aug 18 13:00:46.109421 2026] [security2:error] [pid 123784:tid 123990] [client 20.127.136.245:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/96i.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WgAAAEg"] [Tue Aug 18 13:00:46.127519 2026] [security2:error] [pid 123784:tid 123905] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_WwAADnQ"] [Tue Aug 18 13:00:46.128685 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/k.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XAAAAF0"] [Tue Aug 18 13:00:46.137603 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XQAAAFU"] [Tue Aug 18 13:00:46.144843 2026] [security2:error] [pid 123784:tid 123970] [client 20.100.169.31:24218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_XgAAADQ"] [Tue Aug 18 13:00:46.159125 2026] [security2:error] [pid 123784:tid 123991] [client 20.79.204.6:10748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/xleet.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_YAAAAEk"] [Tue Aug 18 13:00:46.195008 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:46.195589 2026] [authz_core:error] [pid 123784:tid 123789] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:46.204336 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:29474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ts.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_cgAAAFQ"] [Tue Aug 18 13:00:46.223064 2026] [security2:error] [pid 123784:tid 124008] [client 68.221.73.131:29580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/scxy.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_cwAAAFo"] [Tue Aug 18 13:00:46.230307 2026] [security2:error] [pid 123784:tid 123975] [client 20.104.100.201:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_dAAAADk"] [Tue Aug 18 13:00:46.255056 2026] [security2:error] [pid 123784:tid 123969] [client 4.232.94.69:14480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/akcc.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_dwAAADM"] [Tue Aug 18 13:00:46.292687 2026] [security2:error] [pid 123784:tid 123993] [client 158.158.74.177:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/u.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_lQAAAEs"] [Tue Aug 18 13:00:46.329924 2026] [security2:error] [pid 123784:tid 123872] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ok.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_nQAAKVM"] [Tue Aug 18 13:00:46.343049 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.36.136:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_ngAAAGA"] [Tue Aug 18 13:00:46.345970 2026] [security2:error] [pid 123784:tid 123978] [client 20.250.13.23:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_nwAAADw"] [Tue Aug 18 13:00:46.375097 2026] [security2:error] [pid 123784:tid 123946] [client 20.75.92.165:4343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_owAAABw"] [Tue Aug 18 13:00:46.379932 2026] [security2:error] [pid 123784:tid 123925] [client 20.65.98.162:45615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bajah.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pAAAAAc"] [Tue Aug 18 13:00:46.391993 2026] [security2:error] [pid 123784:tid 123985] [client 20.250.27.191:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/media.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pQAAAEM"] [Tue Aug 18 13:00:46.403159 2026] [security2:error] [pid 123784:tid 123996] [client 20.102.65.165:8266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_pgAAAE4"] [Tue Aug 18 13:00:46.472915 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:34164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vw.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_vQAAACw"] [Tue Aug 18 13:00:46.489141 2026] [security2:error] [pid 123784:tid 124015] [client 158.23.17.4:17548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ke.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_0QAAAGE"] [Tue Aug 18 13:00:46.503127 2026] [security2:error] [pid 123784:tid 124045] [client 172.202.39.151:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/x/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_1gAAAH8"] [Tue Aug 18 13:00:46.504358 2026] [security2:error] [pid 123784:tid 123848] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/item.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_1wAASDs"] [Tue Aug 18 13:00:46.533132 2026] [security2:error] [pid 123784:tid 123992] [client 52.141.58.175:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/txets.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_2gAAAEo"] [Tue Aug 18 13:00:46.534402 2026] [security2:error] [pid 123784:tid 124036] [client 20.151.109.219:39309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gk.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_2wAAAHY"] [Tue Aug 18 13:00:46.541996 2026] [security2:error] [pid 123784:tid 124011] [client 20.104.100.201:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dk.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3AAAAF0"] [Tue Aug 18 13:00:46.546706 2026] [security2:error] [pid 123784:tid 123964] [client 20.91.215.254:27411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-post.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3QAAAC4"] [Tue Aug 18 13:00:46.554740 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fresh.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_3wAAAH0"] [Tue Aug 18 13:00:46.565797 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.36.136:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/update/wpupex.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4AAAADQ"] [Tue Aug 18 13:00:46.592071 2026] [security2:error] [pid 123784:tid 123980] [client 20.102.65.165:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4gAAAD4"] [Tue Aug 18 13:00:46.592106 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fs.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4QAAAEk"] [Tue Aug 18 13:00:46.595584 2026] [security2:error] [pid 123784:tid 123942] [client 20.127.136.245:27871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/as.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_4wAAABg"] [Tue Aug 18 13:00:46.628418 2026] [security2:error] [pid 123784:tid 123995] [client 79.127.164.8:33074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "medihub.com.br"] [uri "/www.sql"] [unique_id "aoSBrmwDnJBNj2tDbYb_5AAAAE0"], referer: https://medihub.com.br/www.sql [Tue Aug 18 13:00:46.633896 2026] [security2:error] [pid 123784:tid 124021] [client 20.226.36.136:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/install.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_5QAAAGc"] [Tue Aug 18 13:00:46.639539 2026] [security2:error] [pid 123784:tid 123982] [client 20.100.169.31:19788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_5gAAAEA"] [Tue Aug 18 13:00:46.643356 2026] [security2:error] [pid 123784:tid 124002] [client 20.75.92.165:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_6AAAAFQ"] [Tue Aug 18 13:00:46.706694 2026] [security2:error] [pid 123784:tid 123923] [client 52.173.121.69:15022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/oivcl.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_6wAAAAU"] [Tue Aug 18 13:00:46.717359 2026] [security2:error] [pid 123784:tid 123969] [client 68.221.73.131:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_7AAAADM"] [Tue Aug 18 13:00:46.732297 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_7QAAAEU"] [Tue Aug 18 13:00:46.749799 2026] [security2:error] [pid 123784:tid 124025] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_8QAAAGs"] [Tue Aug 18 13:00:46.757927 2026] [security2:error] [pid 123784:tid 124007] [client 20.79.204.6:2383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/htaccess.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_8gAAAFk"] [Tue Aug 18 13:00:46.762581 2026] [security2:error] [pid 123784:tid 123993] [client 20.65.98.162:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/h.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_9AAAAEs"] [Tue Aug 18 13:00:46.766059 2026] [security2:error] [pid 123784:tid 123920] [client 20.100.169.31:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/goods.php"] [unique_id "aoSBrmwDnJBNj2tDbYb_9QAAAAI"] [Tue Aug 18 13:00:46.809463 2026] [security2:error] [pid 123784:tid 123937] [client 172.202.39.151:44139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/aa.php"] [unique_id "aoSBrmwDnJBNj2tDbYYABAAAABM"] [Tue Aug 18 13:00:46.842292 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.36.136:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSBrmwDnJBNj2tDbYYACQAAAGA"] [Tue Aug 18 13:00:46.890860 2026] [security2:error] [pid 123784:tid 123869] [remote 136.110.27.48:47426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "_dc-mx.5306886f3ecd.brazriosimoveis.com.br"] [uri "/.env"] [unique_id "aoSBrmwDnJBNj2tDbYYADgAAdFA"] [Tue Aug 18 13:00:46.912234 2026] [security2:error] [pid 123784:tid 123949] [client 20.104.100.201:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/bal.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAFwAAAB8"] [Tue Aug 18 13:00:46.912310 2026] [security2:error] [pid 123784:tid 123919] [client 20.75.92.165:4342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/aa.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAGAAAAAE"] [Tue Aug 18 13:00:46.924962 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAGQAAAFw"] [Tue Aug 18 13:00:46.957616 2026] [security2:error] [pid 123784:tid 123981] [client 213.35.127.232:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAHwAAAD8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:46.962059 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sorayasalloum.com.br"] [uri "/license.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAIAAAAFg"] [Tue Aug 18 13:00:46.975214 2026] [security2:error] [pid 123784:tid 124024] [client 158.158.74.177:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/updates.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAIQAAAGo"] [Tue Aug 18 13:00:46.982961 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lj.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAJgAAADU"] [Tue Aug 18 13:00:46.990849 2026] [security2:error] [pid 123784:tid 124012] [client 20.250.13.23:23726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBrmwDnJBNj2tDbYYAKgAAAF4"] [Tue Aug 18 13:00:47.010220 2026] [security2:error] [pid 123784:tid 123952] [client 20.250.27.191:45763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/inso.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAKwAAACI"] [Tue Aug 18 13:00:47.070033 2026] [security2:error] [pid 123784:tid 124011] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/system_log.php"] [unique_id "aoSBr2wDnJBNj2tDbYYALgAAAF0"] [Tue Aug 18 13:00:47.082160 2026] [security2:error] [pid 123784:tid 123964] [client 20.151.109.219:14142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wn.php"] [unique_id "aoSBr2wDnJBNj2tDbYYALwAAAC4"] [Tue Aug 18 13:00:47.124054 2026] [security2:error] [pid 123784:tid 124015] [client 20.127.136.245:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/min.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAMQAAAGE"] [Tue Aug 18 13:00:47.139447 2026] [security2:error] [pid 123784:tid 123997] [client 4.232.94.69:29667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSBr2wDnJBNj2tDbYYANAAAAE8"] [Tue Aug 18 13:00:47.153597 2026] [security2:error] [pid 123784:tid 123980] [client 20.48.236.86:14489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBr2wDnJBNj2tDbYYANQAAAD4"] [Tue Aug 18 13:00:47.193077 2026] [security2:error] [pid 123784:tid 123929] [client 20.79.204.6:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOAAAAAs"] [Tue Aug 18 13:00:47.196453 2026] [security2:error] [pid 123784:tid 123943] [client 20.75.92.165:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOQAAABk"] [Tue Aug 18 13:00:47.235550 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp/images/my.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAOwAAAFM"] [Tue Aug 18 13:00:47.254949 2026] [security2:error] [pid 123784:tid 123994] [client 20.102.65.165:8286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/media.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAPwAAAEw"] [Tue Aug 18 13:00:47.274628 2026] [security2:error] [pid 123784:tid 123961] [client 20.127.136.245:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAQgAAACs"] [Tue Aug 18 13:00:47.303928 2026] [security2:error] [pid 123784:tid 123941] [client 20.104.100.201:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yawa.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARAAAABc"] [Tue Aug 18 13:00:47.309677 2026] [security2:error] [pid 123784:tid 123987] [client 20.65.98.162:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ano.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARQAAAEU"] [Tue Aug 18 13:00:47.318534 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:44482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/53.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARgAAACA"] [Tue Aug 18 13:00:47.327949 2026] [security2:error] [pid 123784:tid 123965] [client 20.226.36.136:62196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYARwAAAC8"] [Tue Aug 18 13:00:47.340456 2026] [security2:error] [pid 123784:tid 124030] [client 68.221.73.131:18801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBr2wDnJBNj2tDbYYASQAAAHA"] [Tue Aug 18 13:00:47.360978 2026] [security2:error] [pid 123784:tid 123955] [client 20.79.204.6:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/images/wso.php"] [unique_id "aoSBr2wDnJBNj2tDbYYATAAAACU"] [Tue Aug 18 13:00:47.393146 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:34041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kh.php"] [unique_id "aoSBr2wDnJBNj2tDbYYATgAAAEs"] [Tue Aug 18 13:00:47.393911 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:47.394152 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:47.394407 2026] [security2:error] [pid 123784:tid 123995] [client 20.100.169.31:4959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAUAAAAE0"] [Tue Aug 18 13:00:47.395018 2026] [security2:error] [pid 123784:tid 123920] [client 172.202.39.151:44509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAUQAAAAI"] [Tue Aug 18 13:00:47.467079 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:54732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nh.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVAAAADE"] [Tue Aug 18 13:00:47.476642 2026] [security2:error] [pid 123784:tid 123946] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/x.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVgAAABw"] [Tue Aug 18 13:00:47.479455 2026] [security2:error] [pid 123784:tid 124027] [client 20.48.236.86:14501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/img.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAVwAAAG0"] [Tue Aug 18 13:00:47.481399 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.36.136:61450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAWAAAAAc"] [Tue Aug 18 13:00:47.486548 2026] [security2:error] [pid 123784:tid 123996] [client 20.75.92.165:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAWwAAAE4"] [Tue Aug 18 13:00:47.564869 2026] [security2:error] [pid 123784:tid 123981] [client 20.226.56.190:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/admin404.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAXgAAAD8"] [Tue Aug 18 13:00:47.603272 2026] [security2:error] [pid 123784:tid 123957] [client 52.141.58.175:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/ty.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYQAAACc"] [Tue Aug 18 13:00:47.603644 2026] [security2:error] [pid 123784:tid 123924] [client 158.158.74.177:23692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYgAAAAY"] [Tue Aug 18 13:00:47.619507 2026] [security2:error] [pid 123784:tid 124012] [client 20.250.27.191:27992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/shiny.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAYwAAAF4"] [Tue Aug 18 13:00:47.621052 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAZAAAAHw"] [Tue Aug 18 13:00:47.624572 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.36.136:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/well-known/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAZgAAABs"] [Tue Aug 18 13:00:47.664238 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:23685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/goat.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAaAAAAAA"] [Tue Aug 18 13:00:47.685176 2026] [security2:error] [pid 123784:tid 123983] [client 20.100.169.31:3713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAawAAAEE"] [Tue Aug 18 13:00:47.693642 2026] [security2:error] [pid 123784:tid 123921] [client 20.102.65.165:8303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/admin.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAbAAAAAM"] [Tue Aug 18 13:00:47.705785 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:47.706024 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:47.714840 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAdgAAABU"] [Tue Aug 18 13:00:47.717003 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/app.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAdwAAAHk"] [Tue Aug 18 13:00:47.739134 2026] [security2:error] [pid 123784:tid 124026] [client 20.75.92.165:4339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/goods.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAeAAAAGw"] [Tue Aug 18 13:00:47.773474 2026] [security2:error] [pid 123784:tid 123929] [client 52.173.121.69:61922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zugvi.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAegAAAAs"] [Tue Aug 18 13:00:47.781671 2026] [security2:error] [pid 123784:tid 124038] [client 20.127.136.245:28043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/php8.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAewAAAHg"] [Tue Aug 18 13:00:47.825622 2026] [security2:error] [pid 123784:tid 123935] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAfQAAABE"] [Tue Aug 18 13:00:47.844680 2026] [security2:error] [pid 123784:tid 123883] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgQAAR14"] [Tue Aug 18 13:00:47.844825 2026] [security2:error] [pid 123784:tid 123989] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgQAAR14"] [Tue Aug 18 13:00:47.859034 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:44801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jb.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAgwAAADk"] [Tue Aug 18 13:00:47.885119 2026] [security2:error] [pid 123784:tid 124009] [client 20.226.36.136:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhAAAAFs"] [Tue Aug 18 13:00:47.952607 2026] [security2:error] [pid 123784:tid 123997] [client 20.91.215.254:27428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/function.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhgAAAE8"] [Tue Aug 18 13:00:47.962374 2026] [security2:error] [pid 123784:tid 123949] [client 86.120.159.145:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhwAAAB8"] [Tue Aug 18 13:00:47.962511 2026] [security2:error] [pid 123784:tid 123949] [client 86.120.159.145:50666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAhwAAAB8"] [Tue Aug 18 13:00:47.971628 2026] [security2:error] [pid 123784:tid 124016] [client 213.35.127.232:63774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiAAAAGI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:47.986603 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:2636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/index/function.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiQAAAG8"] [Tue Aug 18 13:00:47.987483 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/adminner.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAigAAAG4"] [Tue Aug 18 13:00:47.988712 2026] [security2:error] [pid 123784:tid 123958] [client 20.75.92.165:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/php8.php"] [unique_id "aoSBr2wDnJBNj2tDbYYAiwAAACg"] [Tue Aug 18 13:00:48.002126 2026] [security2:error] [pid 123784:tid 123993] [client 20.104.100.201:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/7.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjAAAAEs"] [Tue Aug 18 13:00:48.005437 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/oo.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjQAAAE0"] [Tue Aug 18 13:00:48.017577 2026] [security2:error] [pid 123784:tid 124032] [client 68.221.73.131:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/blurbs.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjgAAAHI"] [Tue Aug 18 13:00:48.028761 2026] [security2:error] [pid 123784:tid 124023] [client 168.62.48.100:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAjwAAAGk"] [Tue Aug 18 13:00:48.041090 2026] [security2:error] [pid 123784:tid 123959] [client 20.226.36.136:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAkgAAACk"] [Tue Aug 18 13:00:48.041232 2026] [security2:error] [pid 123784:tid 124001] [client 20.100.169.31:4930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/htaccess.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAkwAAAFM"] [Tue Aug 18 13:00:48.055582 2026] [security2:error] [pid 123784:tid 123946] [client 20.102.65.165:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/mac.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAlQAAABw"] [Tue Aug 18 13:00:48.071688 2026] [security2:error] [pid 123784:tid 124027] [client 20.226.36.136:65287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/mt/byp.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAlwAAAG0"] [Tue Aug 18 13:00:48.097907 2026] [security2:error] [pid 123784:tid 123996] [client 20.48.236.86:14499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/aa.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAmQAAAE4"] [Tue Aug 18 13:00:48.105096 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.36.136:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/MTOS/byp.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAmgAAAEM"] [Tue Aug 18 13:00:48.109698 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ai.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnAAAABI"] [Tue Aug 18 13:00:48.110182 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnQAAADM"] [Tue Aug 18 13:00:48.176381 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.36.136:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAnwAAACw"] [Tue Aug 18 13:00:48.216984 2026] [security2:error] [pid 123784:tid 123940] [client 20.79.204.6:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/155.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAogAAABY"] [Tue Aug 18 13:00:48.255242 2026] [security2:error] [pid 123784:tid 124042] [client 20.151.109.219:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/87.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApAAAAHw"] [Tue Aug 18 13:00:48.266936 2026] [security2:error] [pid 123784:tid 123918] [client 20.75.92.165:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/info.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApQAAAAA"] [Tue Aug 18 13:00:48.270437 2026] [security2:error] [pid 123784:tid 123972] [client 158.158.74.177:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "penseforte.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYApgAAADY"] [Tue Aug 18 13:00:48.294188 2026] [security2:error] [pid 123784:tid 123932] [client 158.23.17.4:57265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/do.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqAAAAA4"] [Tue Aug 18 13:00:48.298787 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:48.299235 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:48.313830 2026] [security2:error] [pid 123784:tid 124034] [client 20.250.13.23:23719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/Session.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqgAAAHQ"] [Tue Aug 18 13:00:48.319212 2026] [security2:error] [pid 123784:tid 124011] [client 20.250.27.191:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/403dd.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAqwAAAF0"] [Tue Aug 18 13:00:48.337367 2026] [security2:error] [pid 123784:tid 124014] [client 20.127.136.245:28052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArQAAAGA"] [Tue Aug 18 13:00:48.341430 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ws77.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArgAAAGE"] [Tue Aug 18 13:00:48.365730 2026] [security2:error] [pid 123784:tid 123939] [client 20.226.36.136:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYArwAAABU"] [Tue Aug 18 13:00:48.380923 2026] [security2:error] [pid 123784:tid 124039] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/hosty.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAsAAAAHk"] [Tue Aug 18 13:00:48.387435 2026] [security2:error] [pid 123784:tid 124026] [client 20.206.73.37:35303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/admin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAsQAAAGw"] [Tue Aug 18 13:00:48.416490 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lq.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtAAAAAs"] [Tue Aug 18 13:00:48.425617 2026] [security2:error] [pid 123784:tid 123934] [client 20.102.65.165:8240] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtQAAABA"] [Tue Aug 18 13:00:48.425710 2026] [security2:error] [pid 123784:tid 123934] [client 20.102.65.165:8240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtQAAABA"] [Tue Aug 18 13:00:48.444781 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:53747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/0x.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAtgAAACM"] [Tue Aug 18 13:00:48.447555 2026] [security2:error] [pid 123784:tid 124035] [client 4.232.94.69:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/updates.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuAAAAHU"] [Tue Aug 18 13:00:48.471735 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.98.162:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/inso.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuQAAAH4"] [Tue Aug 18 13:00:48.533998 2026] [security2:error] [pid 123784:tid 123923] [client 20.100.169.31:19814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAuwAAAAU"] [Tue Aug 18 13:00:48.549603 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ja.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAvAAAAEU"] [Tue Aug 18 13:00:48.591220 2026] [security2:error] [pid 123784:tid 124041] [client 20.79.204.6:2215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/info.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwAAAAHs"] [Tue Aug 18 13:00:48.594623 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:48.594891 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:48.600054 2026] [security2:error] [pid 123784:tid 123980] [client 20.91.215.254:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-2019.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwgAAAD4"] [Tue Aug 18 13:00:48.617111 2026] [security2:error] [pid 123784:tid 123949] [client 20.151.109.219:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zi.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAwwAAAB8"] [Tue Aug 18 13:00:48.623608 2026] [security2:error] [pid 123784:tid 124016] [client 20.48.236.86:14789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/av.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxAAAAGI"] [Tue Aug 18 13:00:48.634349 2026] [security2:error] [pid 123784:tid 123958] [client 20.104.100.201:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/read.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxgAAACg"] [Tue Aug 18 13:00:48.634357 2026] [security2:error] [pid 123784:tid 124028] [client 20.75.92.165:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/chosen.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxQAAAG4"] [Tue Aug 18 13:00:48.663417 2026] [security2:error] [pid 123784:tid 123983] [client 52.141.58.175:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/u.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAyAAAAEE"] [Tue Aug 18 13:00:48.687240 2026] [security2:error] [pid 123784:tid 123959] [client 20.102.65.165:8259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/coffee.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAzAAAACk"] [Tue Aug 18 13:00:48.704188 2026] [security2:error] [pid 123784:tid 123978] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/test1.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAzwAAADw"] [Tue Aug 18 13:00:48.705762 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:20172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yw.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0AAAAEY"] [Tue Aug 18 13:00:48.706443 2026] [security2:error] [pid 123784:tid 124008] [client 20.100.169.31:4743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/images/wso.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0QAAAFo"] [Tue Aug 18 13:00:48.719477 2026] [security2:error] [pid 123784:tid 123967] [client 172.202.39.151:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-good.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA0wAAADE"] [Tue Aug 18 13:00:48.738313 2026] [security2:error] [pid 123784:tid 123938] [client 20.118.133.132:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/sf.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA1AAAABQ"] [Tue Aug 18 13:00:48.776382 2026] [security2:error] [pid 123784:tid 124009] [client 5.161.61.238:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yycc.com.br"] [uri "/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYAxwAAW1Q"], referer: https://yycc.com.br/ [Tue Aug 18 13:00:48.821926 2026] [security2:error] [pid 123784:tid 123956] [client 114.119.131.123:63541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ceussmedicina.com.br"] [uri "/zwdt/xzdt/202205/t20220531_1655934.html"] [unique_id "aoSBsGwDnJBNj2tDbYYA2AAAACY"], referer: https://ceussmedicina.com.br/zwdt/xzdt/202205/t20220531_1655934.html [Tue Aug 18 13:00:48.822941 2026] [security2:error] [pid 123784:tid 124000] [client 20.250.27.191:28010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/baba.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA2QAAAFI"] [Tue Aug 18 13:00:48.878087 2026] [security2:error] [pid 123784:tid 123926] [client 192.141.172.134:58832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.172.141.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3AAAAAg"] [Tue Aug 18 13:00:48.878204 2026] [security2:error] [pid 123784:tid 123926] [client 192.141.172.134:58832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natyou.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3AAAAAg"] [Tue Aug 18 13:00:48.880104 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/222.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3QAAABw"] [Tue Aug 18 13:00:48.884567 2026] [security2:error] [pid 123784:tid 124012] [client 20.75.92.165:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/simple.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA3gAAAF4"] [Tue Aug 18 13:00:48.901283 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:48.901704 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:48.918796 2026] [security2:error] [pid 123784:tid 123992] [client 20.65.98.162:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/w1px.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA4wAAAEo"] [Tue Aug 18 13:00:48.920034 2026] [security2:error] [pid 123784:tid 123972] [client 20.226.56.190:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/loading.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA5AAAADY"] [Tue Aug 18 13:00:48.932677 2026] [security2:error] [pid 123784:tid 124027] [client 20.250.13.23:23730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA5gAAAG0"] [Tue Aug 18 13:00:48.948503 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.36.136:61467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6QAAAF0"] [Tue Aug 18 13:00:48.950165 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6gAAAFw"] [Tue Aug 18 13:00:48.969775 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:9374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/you.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA6wAAAGA"] [Tue Aug 18 13:00:48.972415 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/albin.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA7AAAAGE"] [Tue Aug 18 13:00:48.985661 2026] [security2:error] [pid 123784:tid 123993] [client 213.35.127.232:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBsGwDnJBNj2tDbYYA7QAAAEs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:49.058789 2026] [security2:error] [pid 123784:tid 123982] [client 20.151.109.219:24404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/92.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA7wAAAEA"] [Tue Aug 18 13:00:49.074334 2026] [security2:error] [pid 123784:tid 123935] [client 20.48.236.86:14495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/media.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8QAAABE"] [Tue Aug 18 13:00:49.077329 2026] [security2:error] [pid 123784:tid 124044] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/zwso.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8gAAAH4"] [Tue Aug 18 13:00:49.124073 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.36.136:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA8wAAAGM"] [Tue Aug 18 13:00:49.150518 2026] [security2:error] [pid 123784:tid 123975] [client 20.226.36.136:61462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9QAAADk"] [Tue Aug 18 13:00:49.167950 2026] [security2:error] [pid 123784:tid 123923] [client 20.75.92.165:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9gAAAAU"] [Tue Aug 18 13:00:49.172514 2026] [security2:error] [pid 123784:tid 124005] [client 20.226.36.136:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA9wAAAFc"] [Tue Aug 18 13:00:49.178217 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA-AAAAC4"] [Tue Aug 18 13:00:49.184013 2026] [security2:error] [pid 123784:tid 123976] [client 158.23.17.4:40400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rb.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA-QAAADo"] [Tue Aug 18 13:00:49.201535 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:49.201956 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:49.210175 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.36.136:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/first.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_AAAAHs"] [Tue Aug 18 13:00:49.229522 2026] [security2:error] [pid 123784:tid 124026] [client 20.79.204.6:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/profile.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_gAAAGw"] [Tue Aug 18 13:00:49.257627 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.36.136:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYA_wAAAH8"] [Tue Aug 18 13:00:49.274511 2026] [security2:error] [pid 123784:tid 124029] [client 20.104.100.201:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fw/34.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBAAAAAG8"] [Tue Aug 18 13:00:49.279078 2026] [security2:error] [pid 123784:tid 123958] [client 172.202.39.151:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/as.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBAgAAACg"] [Tue Aug 18 13:00:49.319583 2026] [security2:error] [pid 123784:tid 124035] [client 20.91.215.254:11912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/cjfuns.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBQAAAHU"] [Tue Aug 18 13:00:49.327022 2026] [security2:error] [pid 123784:tid 124008] [client 20.250.27.191:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/site.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBgAAAFo"] [Tue Aug 18 13:00:49.344274 2026] [security2:error] [pid 123784:tid 123961] [client 20.100.169.31:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/index/function.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBBwAAACs"] [Tue Aug 18 13:00:49.361157 2026] [security2:error] [pid 123784:tid 123950] [client 20.226.36.136:52609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCAAAACA"] [Tue Aug 18 13:00:49.371222 2026] [security2:error] [pid 123784:tid 124022] [client 158.23.17.4:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/qh.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCQAAAGg"] [Tue Aug 18 13:00:49.413869 2026] [security2:error] [pid 123784:tid 123985] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/Geforce.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBCwAAAEM"] [Tue Aug 18 13:00:49.417373 2026] [security2:error] [pid 123784:tid 123969] [client 20.102.65.165:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDAAAADM"] [Tue Aug 18 13:00:49.451937 2026] [security2:error] [pid 123784:tid 123987] [client 20.127.136.245:28528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDQAAAEU"] [Tue Aug 18 13:00:49.461098 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.56.190:52047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/conn-test.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDgAAAB4"] [Tue Aug 18 13:00:49.463004 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:47910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xx.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBDwAAAD8"] [Tue Aug 18 13:00:49.540101 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.36.136:62204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBEQAAAFI"] [Tue Aug 18 13:00:49.571987 2026] [security2:error] [pid 123784:tid 123946] [client 20.75.92.165:4308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/av.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFAAAABw"] [Tue Aug 18 13:00:49.595877 2026] [security2:error] [pid 123784:tid 124019] [client 20.250.13.23:44050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/abcd.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFgAAAGU"] [Tue Aug 18 13:00:49.596662 2026] [security2:error] [pid 123784:tid 123979] [client 20.104.100.201:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp9.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBFwAAAD0"] [Tue Aug 18 13:00:49.599349 2026] [security2:error] [pid 123784:tid 123918] [client 20.151.109.219:39322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jm.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGAAAAAA"] [Tue Aug 18 13:00:49.637686 2026] [security2:error] [pid 123784:tid 123972] [client 20.65.98.162:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/zi-936.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGQAAADY"] [Tue Aug 18 13:00:49.650443 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:10728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/96i.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGgAAAEg"] [Tue Aug 18 13:00:49.670986 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.36.136:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/blog/byp.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBGwAAAFw"] [Tue Aug 18 13:00:49.713626 2026] [security2:error] [pid 123784:tid 123977] [client 52.141.58.175:11668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/ultra.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBIQAAADs"] [Tue Aug 18 13:00:49.725752 2026] [security2:error] [pid 123784:tid 123939] [client 68.221.73.131:13767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/bajah.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBIwAAABU"] [Tue Aug 18 13:00:49.751687 2026] [security2:error] [pid 123784:tid 124004] [client 20.102.65.165:8292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/media.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBJwAAAFY"] [Tue Aug 18 13:00:49.753951 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:10995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ez.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBKQAAAHc"] [Tue Aug 18 13:00:49.798219 2026] [security2:error] [pid 123784:tid 124032] [client 20.100.169.31:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBKwAAAHI"] [Tue Aug 18 13:00:49.833358 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:49.833614 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:49.835854 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:2231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/sx.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBLgAAAEo"] [Tue Aug 18 13:00:49.842022 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.36.136:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBLwAAAB0"] [Tue Aug 18 13:00:49.844567 2026] [security2:error] [pid 123784:tid 124017] [client 20.102.65.165:8299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/yj09.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBMAAAAGM"] [Tue Aug 18 13:00:49.893810 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.100.201:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/save.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBMwAAAA4"] [Tue Aug 18 13:00:49.924362 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:20205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/r.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBNQAAADk"] [Tue Aug 18 13:00:49.937758 2026] [security2:error] [pid 123784:tid 124027] [client 4.232.94.69:25510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBNgAAAG0"] [Tue Aug 18 13:00:49.949848 2026] [security2:error] [pid 123784:tid 123941] [client 20.48.236.86:14521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/images.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBOQAAABc"] [Tue Aug 18 13:00:49.975029 2026] [security2:error] [pid 123784:tid 123942] [client 20.91.215.254:11986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPAAAABg"] [Tue Aug 18 13:00:49.975092 2026] [security2:error] [pid 123784:tid 124041] [client 158.23.17.4:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/conn-test.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPQAAAHs"] [Tue Aug 18 13:00:49.977087 2026] [security2:error] [pid 123784:tid 124038] [client 20.100.169.31:32509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/info.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPgAAAHg"] [Tue Aug 18 13:00:49.980068 2026] [security2:error] [pid 123784:tid 123980] [client 20.250.27.191:63224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBPwAAAD4"] [Tue Aug 18 13:00:49.999450 2026] [security2:error] [pid 123784:tid 124011] [client 213.35.127.232:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSBsWwDnJBNj2tDbYYBQAAAAF0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:50.023997 2026] [security2:error] [pid 123784:tid 123955] [client 20.75.92.165:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBQQAAACU"] [Tue Aug 18 13:00:50.156221 2026] [security2:error] [pid 123784:tid 123967] [client 20.102.65.165:8195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/admin.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBSgAAADE"] [Tue Aug 18 13:00:50.172231 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:50.172666 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:50.208991 2026] [security2:error] [pid 123784:tid 123861] [remote 178.156.200.16:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agatrend.com.br"] [uri "/wp-login.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTAAADUg"] [Tue Aug 18 13:00:50.236478 2026] [security2:error] [pid 123784:tid 123996] [client 20.102.65.165:8205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/scxy.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTgAAAE4"] [Tue Aug 18 13:00:50.237405 2026] [security2:error] [pid 123784:tid 124026] [client 20.250.13.23:23714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/kj.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBTwAAAGw"] [Tue Aug 18 13:00:50.305730 2026] [security2:error] [pid 123784:tid 123969] [client 20.75.92.165:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file2.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBUwAAADM"] [Tue Aug 18 13:00:50.312690 2026] [security2:error] [pid 123784:tid 123998] [client 20.151.109.219:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wj.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVAAAAFA"] [Tue Aug 18 13:00:50.353107 2026] [security2:error] [pid 123784:tid 123960] [client 20.104.100.201:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVgAAACo"] [Tue Aug 18 13:00:50.365142 2026] [security2:error] [pid 123784:tid 123948] [client 20.65.98.162:41683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/dcsgumnm.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBVwAAAB4"] [Tue Aug 18 13:00:50.408035 2026] [security2:error] [pid 123784:tid 123928] [client 20.250.13.23:7680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBWQAAAAo"] [Tue Aug 18 13:00:50.433126 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:34016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/17.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBWwAAAFI"] [Tue Aug 18 13:00:50.437585 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:50.437869 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:50.445818 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/info.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXQAAABA"] [Tue Aug 18 13:00:50.446050 2026] [security2:error] [pid 123784:tid 123973] [client 20.79.204.6:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXAAAADc"] [Tue Aug 18 13:00:50.471108 2026] [security2:error] [pid 123784:tid 124024] [client 172.202.39.151:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/tes.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBXwAAAGo"] [Tue Aug 18 13:00:50.573959 2026] [security2:error] [pid 123784:tid 123946] [client 172.202.39.151:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/zxz.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBYQAAABw"] [Tue Aug 18 13:00:50.633804 2026] [security2:error] [pid 123784:tid 123937] [client 20.102.65.165:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/mac.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBYgAAABM"] [Tue Aug 18 13:00:50.766115 2026] [security2:error] [pid 123784:tid 123977] [client 20.75.92.165:4314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/images/class-config.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBZAAAADs"] [Tue Aug 18 13:00:50.851616 2026] [security2:error] [pid 123784:tid 123939] [client 20.163.43.14:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBZgAAABU"] [Tue Aug 18 13:00:50.865563 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/74.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBbgAAAHk"] [Tue Aug 18 13:00:50.907120 2026] [security2:error] [pid 123784:tid 124004] [client 20.102.65.165:8293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBbwAAAFY"] [Tue Aug 18 13:00:50.923814 2026] [security2:error] [pid 123784:tid 123956] [client 103.120.71.157:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcAAAACY"] [Tue Aug 18 13:00:50.923918 2026] [security2:error] [pid 123784:tid 123956] [client 103.120.71.157:50124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcAAAACY"] [Tue Aug 18 13:00:50.930746 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:35536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/languages.php"] [unique_id "aoSBsmwDnJBNj2tDbYYBcQAAAAA"] [Tue Aug 18 13:00:51.006971 2026] [security2:error] [pid 123784:tid 123947] [client 158.23.17.4:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/asus.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBcwAAAB0"] [Tue Aug 18 13:00:51.016712 2026] [autoindex:error] [pid 123784:tid 123992] [client 20.65.98.162:56500] AH01276: Cannot serve directory /home4/labotafogo/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:51.066992 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.36.136:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdAAAAEc"] [Tue Aug 18 13:00:51.094568 2026] [security2:error] [pid 123784:tid 124027] [client 20.75.92.165:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/alfa.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdQAAAG0"] [Tue Aug 18 13:00:51.099712 2026] [security2:error] [pid 123784:tid 123923] [client 158.23.17.4:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fg.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdgAAAAU"] [Tue Aug 18 13:00:51.115562 2026] [security2:error] [pid 123784:tid 123941] [client 20.251.112.238:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBdwAAABc"] [Tue Aug 18 13:00:51.239405 2026] [security2:error] [pid 123784:tid 124038] [client 172.202.39.151:53703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/www.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBeQAAAHg"] [Tue Aug 18 13:00:51.269959 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.36.136:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.multiveicular.org.br"] [uri "/images/security.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBegAAAB8"] [Tue Aug 18 13:00:51.328686 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.98.162:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/php.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfAAAAGI"] [Tue Aug 18 13:00:51.361760 2026] [security2:error] [pid 123784:tid 123958] [client 20.226.56.190:28260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/evil.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfQAAACg"] [Tue Aug 18 13:00:51.520405 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:12028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBfgAAAGQ"] [Tue Aug 18 13:00:51.600648 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/cabs.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBggAAAE4"] [Tue Aug 18 13:00:51.621462 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:33997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ev.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBgwAAAGY"] [Tue Aug 18 13:00:51.625364 2026] [security2:error] [pid 123784:tid 123980] [client 138.36.100.162:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBhAAAAD4"] [Tue Aug 18 13:00:51.625431 2026] [security2:error] [pid 123784:tid 123980] [client 138.36.100.162:43114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBhAAAAD4"] [Tue Aug 18 13:00:51.757697 2026] [security2:error] [pid 123784:tid 124028] [client 20.38.3.247:39108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/av.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBiAAAAG4"] [Tue Aug 18 13:00:51.791837 2026] [security2:error] [pid 123784:tid 123973] [client 20.206.73.37:29985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/biufile.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBigAAADc"] [Tue Aug 18 13:00:51.817872 2026] [security2:error] [pid 123784:tid 123924] [client 20.104.100.201:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/gecko-new.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBiwAAAAY"] [Tue Aug 18 13:00:51.849750 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/fpwch.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBjgAAAEI"] [Tue Aug 18 13:00:51.922795 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:51.923065 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:51.959106 2026] [security2:error] [pid 123784:tid 123962] [client 52.141.58.175:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/up.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkQAAACw"] [Tue Aug 18 13:00:51.979697 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:19802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/wp-themes.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkgAAAAc"] [Tue Aug 18 13:00:51.997404 2026] [security2:error] [pid 123784:tid 123936] [client 20.100.169.31:4945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/profile.php"] [unique_id "aoSBs2wDnJBNj2tDbYYBkwAAABI"] [Tue Aug 18 13:00:52.022497 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/a.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBlAAAABA"] [Tue Aug 18 13:00:52.063808 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:8755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/22.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBlwAAAAA"] [Tue Aug 18 13:00:52.091367 2026] [security2:error] [pid 123784:tid 123932] [client 20.250.13.23:46088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/themes.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBmAAAAA4"] [Tue Aug 18 13:00:52.145163 2026] [security2:error] [pid 123784:tid 124010] [client 20.79.204.6:2210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBmQAAAFw"] [Tue Aug 18 13:00:52.179758 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/37.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBngAAAEw"] [Tue Aug 18 13:00:52.222628 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:52.222900 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:52.227637 2026] [security2:error] [pid 123784:tid 123940] [client 172.202.39.151:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBoQAAABY"] [Tue Aug 18 13:00:52.362639 2026] [security2:error] [pid 123784:tid 124030] [client 20.250.27.191:28024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/insc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrQAAAHA"] [Tue Aug 18 13:00:52.363132 2026] [security2:error] [pid 123784:tid 124038] [client 20.102.65.165:8288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrgAAAHg"] [Tue Aug 18 13:00:52.427825 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.13.23:44071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/nw.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrwAAAH8"] [Tue Aug 18 13:00:52.508331 2026] [security2:error] [pid 123784:tid 124035] [client 20.127.136.245:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/atomlib.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBsgAAAHU"] [Tue Aug 18 13:00:52.620221 2026] [security2:error] [pid 123784:tid 124020] [client 52.173.121.69:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wsrer.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBtAAAAGY"] [Tue Aug 18 13:00:52.651155 2026] [security2:error] [pid 123784:tid 123991] [client 103.184.169.37:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBuAAAAEk"] [Tue Aug 18 13:00:52.651263 2026] [security2:error] [pid 123784:tid 123991] [client 103.184.169.37:42991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBuAAAAEk"] [Tue Aug 18 13:00:52.674141 2026] [security2:error] [pid 123784:tid 123985] [client 168.62.48.100:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvAAAAEM"] [Tue Aug 18 13:00:52.679051 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:27857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/chosen.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvQAAACg"] [Tue Aug 18 13:00:52.740130 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/files/index.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBvgAAADQ"] [Tue Aug 18 13:00:52.776996 2026] [security2:error] [pid 123784:tid 124002] [client 157.20.138.62:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwAAAAFQ"] [Tue Aug 18 13:00:52.777145 2026] [security2:error] [pid 123784:tid 124002] [client 157.20.138.62:60872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwAAAAFQ"] [Tue Aug 18 13:00:52.826570 2026] [security2:error] [pid 123784:tid 123930] [client 20.91.215.254:27424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/import.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwQAAAAw"] [Tue Aug 18 13:00:52.848990 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBwgAAAAk"] [Tue Aug 18 13:00:52.947872 2026] [security2:error] [pid 123784:tid 123928] [client 20.250.27.191:45762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/file.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBxgAAAAo"] [Tue Aug 18 13:00:52.952327 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.98.162:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/sf.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBxwAAACo"] [Tue Aug 18 13:00:53.133430 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:53.133683 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:53.149036 2026] [security2:error] [pid 123784:tid 123919] [client 20.250.13.23:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/cv.php"] [unique_id "aoSBtWwDnJBNj2tDbYYBywAAAAE"] [Tue Aug 18 13:00:53.222184 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ve.php"] [unique_id "aoSBtWwDnJBNj2tDbYYBzQAAAHI"] [Tue Aug 18 13:00:53.323489 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:45415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0AAAAGs"] [Tue Aug 18 13:00:53.323647 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:45415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0AAAAGs"] [Tue Aug 18 13:00:53.339254 2026] [security2:error] [pid 123784:tid 123797] [remote 162.214.96.231:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSBtGwDnJBNj2tDbYYBrAAAJwg"] [Tue Aug 18 13:00:53.384943 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.56.190:23776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-key.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB0QAAAGM"] [Tue Aug 18 13:00:53.438928 2026] [autoindex:error] [pid 123784:tid 124037] [client 20.79.204.6:2386] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:53.597584 2026] [security2:error] [pid 123784:tid 124041] [client 172.202.39.151:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-config-sample.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB2gAAAHs"] [Tue Aug 18 13:00:53.671523 2026] [security2:error] [pid 123784:tid 124029] [client 20.79.204.6:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB3QAAAG8"] [Tue Aug 18 13:00:53.717856 2026] [security2:error] [pid 123784:tid 123923] [client 20.91.215.254:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/cropper.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB3wAAAAU"] [Tue Aug 18 13:00:53.804647 2026] [security2:error] [pid 123784:tid 123926] [client 20.100.169.31:4967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/sx.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB4gAAAAg"] [Tue Aug 18 13:00:53.840767 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:47891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ia.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB4wAAADU"] [Tue Aug 18 13:00:53.865581 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:18517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB5AAAABQ"] [Tue Aug 18 13:00:53.958762 2026] [security2:error] [pid 123784:tid 123977] [client 213.202.253.4:51961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/schallfuns.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB5wAAADs"], referer: www.google.com [Tue Aug 18 13:00:53.971082 2026] [security2:error] [pid 123784:tid 123969] [client 172.202.39.151:40379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6AAAADM"] [Tue Aug 18 13:00:53.977284 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6QAAADE"] [Tue Aug 18 13:00:53.982047 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:30426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtWwDnJBNj2tDbYYB6QAAADE"] [Tue Aug 18 13:00:54.068740 2026] [security2:error] [pid 123784:tid 123974] [client 52.141.58.175:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/upload.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB6wAAADg"] [Tue Aug 18 13:00:54.081711 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:63673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zs.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB7AAAAFg"] [Tue Aug 18 13:00:54.097714 2026] [security2:error] [pid 123784:tid 123930] [client 20.118.133.132:30864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/xx.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB7QAAAAw"] [Tue Aug 18 13:00:54.215082 2026] [security2:error] [pid 123784:tid 124013] [client 172.202.39.151:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wicked.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8QAAAF8"] [Tue Aug 18 13:00:54.235256 2026] [security2:error] [pid 123784:tid 124024] [client 20.127.136.245:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/min.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8gAAAGo"] [Tue Aug 18 13:00:54.243891 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:55194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/xx.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB8wAAAHY"] [Tue Aug 18 13:00:54.317346 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:54.317612 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:54.369292 2026] [security2:error] [pid 123784:tid 123939] [client 20.38.3.247:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/images.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB9wAAABU"] [Tue Aug 18 13:00:54.478262 2026] [security2:error] [pid 123784:tid 124011] [client 223.185.37.47:7659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-QAAAF0"] [Tue Aug 18 13:00:54.478400 2026] [security2:error] [pid 123784:tid 124011] [client 223.185.37.47:7659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-QAAAF0"] [Tue Aug 18 13:00:54.478803 2026] [security2:error] [pid 123784:tid 124000] [client 68.221.73.131:21977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/domvf.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB-gAAAFI"] [Tue Aug 18 13:00:54.490197 2026] [security2:error] [pid 123784:tid 124032] [client 114.119.138.140:25025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "copemsa.com.br"] [uri "/"] [unique_id "aoSBtmwDnJBNj2tDbYYB-wAAAHI"], referer: https://www.brazilwebdirectory.com/redirect.php?s=whois/zhizi-medical.com [Tue Aug 18 13:00:54.514280 2026] [security2:error] [pid 123784:tid 124025] [client 20.151.109.219:14331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/av.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_AAAAGs"] [Tue Aug 18 13:00:54.565605 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:47673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/md.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_QAAAEo"] [Tue Aug 18 13:00:54.575110 2026] [security2:error] [pid 123784:tid 123995] [client 158.23.17.4:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kn.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_gAAAE0"] [Tue Aug 18 13:00:54.583752 2026] [security2:error] [pid 123784:tid 124027] [client 20.102.65.165:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "aoSBtmwDnJBNj2tDbYYB_wAAAG0"] [Tue Aug 18 13:00:54.688820 2026] [security2:error] [pid 123784:tid 123941] [client 20.48.236.86:14471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/admin.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAAAAABc"] [Tue Aug 18 13:00:54.747318 2026] [security2:error] [pid 123784:tid 123989] [client 52.173.121.69:9953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/ucpfr.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAQAAAEc"] [Tue Aug 18 13:00:54.909056 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.27.191:34819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/dex.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCBQAAAAU"] [Tue Aug 18 13:00:54.918429 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:54.918697 2026] [authz_core:error] [pid 123784:tid 123837] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:54.977057 2026] [security2:error] [pid 123784:tid 124035] [client 20.102.65.165:8212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/bajah.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCBwAAAHU"] [Tue Aug 18 13:00:55.042407 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.204.6:10705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/as.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCAAAABk"] [Tue Aug 18 13:00:55.082669 2026] [security2:error] [pid 123784:tid 123960] [client 20.100.169.31:24217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCgAAACo"] [Tue Aug 18 13:00:55.101472 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:1929] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/1.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCwAAAAg"] [Tue Aug 18 13:00:55.101583 2026] [security2:error] [pid 123784:tid 123926] [client 20.75.92.165:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/1.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCCwAAAAg"] [Tue Aug 18 13:00:55.109651 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ag.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDAAAAFk"] [Tue Aug 18 13:00:55.128603 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.13.23:30134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDQAAAE4"] [Tue Aug 18 13:00:55.162921 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:15136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wm.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCDwAAAEk"] [Tue Aug 18 13:00:55.188126 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/df.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCEgAAADE"] [Tue Aug 18 13:00:55.215642 2026] [security2:error] [pid 123784:tid 123975] [client 4.232.94.69:29694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCEwAAADk"] [Tue Aug 18 13:00:55.298616 2026] [security2:error] [pid 123784:tid 124028] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about/function.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFAAAAG4"] [Tue Aug 18 13:00:55.320627 2026] [security2:error] [pid 123784:tid 123930] [client 20.163.43.14:8957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFQAAAAw"] [Tue Aug 18 13:00:55.325207 2026] [security2:error] [pid 123784:tid 123968] [client 168.62.48.100:18027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/rezor.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFgAAADI"] [Tue Aug 18 13:00:55.328998 2026] [security2:error] [pid 123784:tid 123937] [client 149.34.210.141:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFwAAABM"] [Tue Aug 18 13:00:55.394602 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xs.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCGgAAAGU"] [Tue Aug 18 13:00:55.419210 2026] [autoindex:error] [pid 123784:tid 123956] [client 20.79.204.6:2389] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:55.424122 2026] [security2:error] [pid 123784:tid 123997] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCGQAAT2o"] [Tue Aug 18 13:00:55.433954 2026] [security2:error] [pid 123784:tid 124013] [client 20.102.65.165:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/domvf.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCHAAAAF8"] [Tue Aug 18 13:00:55.509157 2026] [security2:error] [pid 123784:tid 123983] [client 213.35.127.232:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCJAAAAEE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:00:55.572423 2026] [security2:error] [pid 123784:tid 123939] [client 20.104.100.201:34262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCKAAAABU"] [Tue Aug 18 13:00:55.606934 2026] [security2:error] [pid 123784:tid 124043] [client 20.91.215.254:11925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/images/xmrlpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCKQAAAH0"] [Tue Aug 18 13:00:55.624434 2026] [security2:error] [pid 123784:tid 123937] [client 149.34.210.141:55104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCFwAAABM"] [Tue Aug 18 13:00:55.647655 2026] [security2:error] [pid 123784:tid 123924] [client 20.79.204.6:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCLQAAAAY"] [Tue Aug 18 13:00:55.675357 2026] [autoindex:error] [pid 123784:tid 124045] [client 20.250.13.23:23736] AH01276: Cannot serve directory /home3/ezycolorcom/formeskin.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:55.691792 2026] [security2:error] [pid 123784:tid 124025] [client 20.151.109.219:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ig.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCLwAAAGs"] [Tue Aug 18 13:00:55.699811 2026] [security2:error] [pid 123784:tid 123957] [client 20.163.43.14:8924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/admin.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMAAAACc"] [Tue Aug 18 13:00:55.732547 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/function/function.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMQAAAEo"] [Tue Aug 18 13:00:55.803434 2026] [security2:error] [pid 123784:tid 123941] [client 20.75.92.165:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/222.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCMgAAABc"] [Tue Aug 18 13:00:55.863222 2026] [security2:error] [pid 123784:tid 123976] [client 20.38.3.247:35631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/ops.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCNgAAADo"] [Tue Aug 18 13:00:55.907882 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.13.23:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCOwAAAAU"] [Tue Aug 18 13:00:55.976074 2026] [security2:error] [pid 123784:tid 124029] [client 68.221.73.131:46220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/fpwch.php"] [unique_id "aoSBt2wDnJBNj2tDbYYCPwAAAG8"] [Tue Aug 18 13:00:56.022078 2026] [security2:error] [pid 123784:tid 123973] [client 20.226.56.190:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/phpcheck.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCQgAAADc"] [Tue Aug 18 13:00:56.149811 2026] [security2:error] [pid 123784:tid 123991] [client 20.206.73.37:34801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/coffexium.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCRwAAAEk"] [Tue Aug 18 13:00:56.182568 2026] [security2:error] [pid 123784:tid 123967] [client 158.23.17.4:9365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/iz.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCSgAAADE"] [Tue Aug 18 13:00:56.285331 2026] [security2:error] [pid 123784:tid 124033] [client 158.23.17.4:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/iy.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCSwAAAHM"] [Tue Aug 18 13:00:56.326643 2026] [security2:error] [pid 123784:tid 123925] [client 20.100.169.31:19833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ferreiralucas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCUAAAAAc"] [Tue Aug 18 13:00:56.326661 2026] [security2:error] [pid 123784:tid 123959] [client 20.100.169.31:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCTwAAACk"] [Tue Aug 18 13:00:56.344944 2026] [security2:error] [pid 123784:tid 123958] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-signin.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCUQAAACg"] [Tue Aug 18 13:00:56.423238 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:56.423513 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:56.524699 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:17563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ac.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVQAAAE8"] [Tue Aug 18 13:00:56.534119 2026] [security2:error] [pid 123784:tid 123934] [client 20.127.136.245:27856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVgAAABA"] [Tue Aug 18 13:00:56.562063 2026] [security2:error] [pid 123784:tid 123942] [client 20.75.92.165:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/asasx.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCVwAAABg"] [Tue Aug 18 13:00:56.577890 2026] [security2:error] [pid 123784:tid 123943] [client 197.184.64.235:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWQAAABk"] [Tue Aug 18 13:00:56.578025 2026] [security2:error] [pid 123784:tid 123943] [client 197.184.64.235:41960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWQAAABk"] [Tue Aug 18 13:00:56.585790 2026] [security2:error] [pid 123784:tid 124036] [client 20.163.43.14:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/public/css.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCWgAAAHY"] [Tue Aug 18 13:00:56.597827 2026] [security2:error] [pid 123784:tid 124011] [client 114.119.148.208:62919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "advogadocriminalgoiania.com.br"] [uri "/2022/01/"] [unique_id "aoSBuGwDnJBNj2tDbYYCWwAAAF0"], referer: https://advogadocriminalgoiania.com.br [Tue Aug 18 13:00:56.614050 2026] [security2:error] [pid 123784:tid 123984] [client 20.250.27.191:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/key.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXQAAAEI"] [Tue Aug 18 13:00:56.634219 2026] [security2:error] [pid 123784:tid 123971] [client 102.213.179.104:64597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXgAAADU"] [Tue Aug 18 13:00:56.634346 2026] [security2:error] [pid 123784:tid 123971] [client 102.213.179.104:64597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXgAAADU"] [Tue Aug 18 13:00:56.639977 2026] [security2:error] [pid 123784:tid 123914] [remote 129.121.74.194:40546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCXAAAPX0"] [Tue Aug 18 13:00:56.689572 2026] [security2:error] [pid 123784:tid 123981] [client 172.202.39.151:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/HLA-dd.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCZwAAAD8"] [Tue Aug 18 13:00:56.724585 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:56.724910 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:56.813729 2026] [security2:error] [pid 123784:tid 124024] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/f35.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCawAAAGo"] [Tue Aug 18 13:00:56.893856 2026] [security2:error] [pid 123784:tid 123995] [client 20.75.92.165:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/filemanager.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbAAAAE0"] [Tue Aug 18 13:00:56.968369 2026] [security2:error] [pid 123784:tid 124001] [client 20.163.43.14:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbgAAAFM"] [Tue Aug 18 13:00:57.063157 2026] [security2:error] [pid 123784:tid 123969] [client 20.226.56.190:3051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/mimes.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCcQAAADM"] [Tue Aug 18 13:00:57.066040 2026] [security2:error] [pid 123784:tid 123936] [client 78.46.215.1:1176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCbwAAABI"], referer: https://www.meucrescer.com.br [Tue Aug 18 13:00:57.096596 2026] [security2:error] [pid 123784:tid 123863] [remote 129.121.123.168:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaseventos.com"] [uri "/wp-login.php"] [unique_id "aoSBuGwDnJBNj2tDbYYCRgAAXko"] [Tue Aug 18 13:00:57.145515 2026] [security2:error] [pid 123784:tid 123931] [client 52.141.58.175:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/v5.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCcwAAAA0"] [Tue Aug 18 13:00:57.156955 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:47887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/yz.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdAAAAGw"] [Tue Aug 18 13:00:57.169638 2026] [security2:error] [pid 123784:tid 123930] [client 20.250.13.23:18549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdQAAAAw"] [Tue Aug 18 13:00:57.179319 2026] [security2:error] [pid 123784:tid 123982] [client 20.250.27.191:35703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/kir.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCdgAAAEA"] [Tue Aug 18 13:00:57.204881 2026] [security2:error] [pid 123784:tid 124029] [client 20.75.92.165:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/themes.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCeAAAAG8"] [Tue Aug 18 13:00:57.232387 2026] [security2:error] [pid 123784:tid 123932] [client 52.173.121.69:9939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/yxijx.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCeQAAAA4"] [Tue Aug 18 13:00:57.241557 2026] [security2:error] [pid 123784:tid 124018] [client 172.202.39.151:44535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/images/images/about.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCegAAAGQ"] [Tue Aug 18 13:00:57.242700 2026] [security2:error] [pid 123784:tid 124019] [client 196.12.128.158:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCewAAAGU"] [Tue Aug 18 13:00:57.242851 2026] [security2:error] [pid 123784:tid 124019] [client 196.12.128.158:52793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCewAAAGU"] [Tue Aug 18 13:00:57.268634 2026] [security2:error] [pid 123784:tid 123973] [client 88.90.243.36:49372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSBuWwDnJBNj2tDbYYCfQAAADc"] [Tue Aug 18 13:00:57.268751 2026] [security2:error] [pid 123784:tid 123973] [client 88.90.243.36:49372] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSBuWwDnJBNj2tDbYYCfQAAADc"] [Tue Aug 18 13:00:57.471904 2026] [security2:error] [pid 123784:tid 123992] [client 4.232.94.69:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/Casper.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCgQAAAEo"] [Tue Aug 18 13:00:57.479021 2026] [security2:error] [pid 123784:tid 123940] [client 185.168.30.19:51317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBtmwDnJBNj2tDbYYCAwAAABY"] [Tue Aug 18 13:00:57.499152 2026] [security2:error] [pid 123784:tid 123987] [client 168.62.48.100:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCgwAAAEU"] [Tue Aug 18 13:00:57.499864 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSBuWwDnJBNj2tDbYYChAAAAFQ"] [Tue Aug 18 13:00:57.555691 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/og.php"] [unique_id "aoSBuWwDnJBNj2tDbYYChwAAACg"] [Tue Aug 18 13:00:57.606913 2026] [security2:error] [pid 123784:tid 123977] [client 20.79.204.6:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCiAAAADs"] [Tue Aug 18 13:00:57.715184 2026] [security2:error] [pid 123784:tid 123927] [client 20.250.27.191:27991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/nofile.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCigAAAAk"] [Tue Aug 18 13:00:57.750853 2026] [security2:error] [pid 123784:tid 123956] [client 172.202.39.151:4714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCiwAAACY"] [Tue Aug 18 13:00:57.817450 2026] [security2:error] [pid 123784:tid 123942] [client 20.100.169.31:4939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCjAAAABg"] [Tue Aug 18 13:00:57.878479 2026] [security2:error] [pid 123784:tid 124044] [client 20.91.215.254:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCjgAAAH4"] [Tue Aug 18 13:00:57.938788 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:57.939042 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:57.966218 2026] [security2:error] [pid 123784:tid 124003] [client 20.102.65.165:8282] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.lpcor.com.br"] [uri "/1.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCkwAAAFU"] [Tue Aug 18 13:00:57.966337 2026] [security2:error] [pid 123784:tid 124003] [client 20.102.65.165:8282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/1.php"] [unique_id "aoSBuWwDnJBNj2tDbYYCkwAAAFU"] [Tue Aug 18 13:00:58.087409 2026] [security2:error] [pid 123784:tid 124025] [client 20.163.43.14:8851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmAAAAGs"] [Tue Aug 18 13:00:58.170159 2026] [security2:error] [pid 123784:tid 123964] [client 20.151.109.219:60392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ta.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmQAAAC4"] [Tue Aug 18 13:00:58.198378 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.13.23:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/f7.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmgAAAG4"] [Tue Aug 18 13:00:58.234490 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kj.php"] [unique_id "aoSBumwDnJBNj2tDbYYCmwAAAFI"] [Tue Aug 18 13:00:58.252216 2026] [security2:error] [pid 123784:tid 123989] [client 68.221.73.131:13788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/adminner.php"] [unique_id "aoSBumwDnJBNj2tDbYYCngAAAEc"] [Tue Aug 18 13:00:58.267112 2026] [security2:error] [pid 123784:tid 123990] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/gg.php"] [unique_id "aoSBumwDnJBNj2tDbYYCnwAAAEg"] [Tue Aug 18 13:00:58.398616 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:28491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/vx.php"] [unique_id "aoSBumwDnJBNj2tDbYYCoQAAABw"] [Tue Aug 18 13:00:58.446595 2026] [security2:error] [pid 123784:tid 124029] [client 20.102.65.165:8208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/coffee.php"] [unique_id "aoSBumwDnJBNj2tDbYYCpQAAAG8"] [Tue Aug 18 13:00:58.488067 2026] [security2:error] [pid 123784:tid 124019] [client 20.163.43.14:8839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gelay.php"] [unique_id "aoSBumwDnJBNj2tDbYYCpwAAAGU"] [Tue Aug 18 13:00:58.533481 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:58.533763 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:58.658132 2026] [security2:error] [pid 123784:tid 123843] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBumwDnJBNj2tDbYYCqwAAMTY"] [Tue Aug 18 13:00:58.658370 2026] [security2:error] [pid 123784:tid 123967] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBumwDnJBNj2tDbYYCqwAAMTY"] [Tue Aug 18 13:00:58.819794 2026] [security2:error] [pid 123784:tid 123950] [client 20.251.112.238:7773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsAAAACA"] [Tue Aug 18 13:00:58.935249 2026] [security2:error] [pid 123784:tid 123977] [client 20.65.98.162:56507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/uwu.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsQAAADs"] [Tue Aug 18 13:00:58.959875 2026] [security2:error] [pid 123784:tid 124012] [client 144.76.22.181:58082] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBumwDnJBNj2tDbYYCoAAAAF4"] [Tue Aug 18 13:00:58.965091 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:30987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSBumwDnJBNj2tDbYYCsgAAACI"] [Tue Aug 18 13:00:58.984734 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:10948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/se.php"] [unique_id "aoSBumwDnJBNj2tDbYYCswAAADQ"] [Tue Aug 18 13:00:59.020791 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:34771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/usr.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCtAAAAAk"] [Tue Aug 18 13:00:59.067926 2026] [autoindex:error] [pid 123784:tid 123998] [client 169.58.72.248:53799] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:00:59.109295 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:8194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCtwAAABk"] [Tue Aug 18 13:00:59.139943 2026] [security2:error] [pid 123784:tid 124011] [client 20.75.92.165:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCuAAAAF0"] [Tue Aug 18 13:00:59.156393 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vg.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCugAAAH4"] [Tue Aug 18 13:00:59.289580 2026] [security2:error] [pid 123784:tid 123983] [client 20.250.27.191:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/fling.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCwAAAAEE"] [Tue Aug 18 13:00:59.372960 2026] [security2:error] [pid 123784:tid 123924] [client 20.251.112.238:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws61.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxQAAAAY"] [Tue Aug 18 13:00:59.398161 2026] [security2:error] [pid 123784:tid 124025] [client 20.48.236.86:14785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/222.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxgAAAGs"] [Tue Aug 18 13:00:59.410839 2026] [security2:error] [pid 123784:tid 123957] [client 20.102.65.165:8262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/adminner.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCxwAAACc"] [Tue Aug 18 13:00:59.436610 2026] [security2:error] [pid 123784:tid 124028] [client 20.118.133.132:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/uwu.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCyAAAAG4"] [Tue Aug 18 13:00:59.440061 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCyQAAAHE"] [Tue Aug 18 13:00:59.509889 2026] [security2:error] [pid 123784:tid 123971] [client 20.79.204.6:10381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/min.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCzAAAADU"] [Tue Aug 18 13:00:59.707696 2026] [security2:error] [pid 123784:tid 123958] [client 185.168.30.19:29507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBu2wDnJBNj2tDbYYCzQAAACg"] [Tue Aug 18 13:00:59.738140 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:00:59.738421 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:00:59.869531 2026] [security2:error] [pid 123784:tid 123973] [client 20.100.169.31:4929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC4QAAADc"] [Tue Aug 18 13:00:59.881979 2026] [security2:error] [pid 123784:tid 124007] [client 20.163.43.14:8946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC4gAAAFk"] [Tue Aug 18 13:00:59.905513 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.27.191:35686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/zoo1.php"] [unique_id "aoSBu2wDnJBNj2tDbYYC5QAAAE4"] [Tue Aug 18 13:01:00.092546 2026] [security2:error] [pid 123784:tid 123932] [client 20.91.215.254:12138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/goat.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC6gAAAA4"] [Tue Aug 18 13:01:00.256117 2026] [security2:error] [pid 123784:tid 123960] [client 20.79.204.6:2200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8AAAACo"] [Tue Aug 18 13:01:00.258547 2026] [security2:error] [pid 123784:tid 123969] [client 168.119.96.239:41686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7AAAADM"], referer: https://www.meucrescer.com.br [Tue Aug 18 13:01:00.282170 2026] [security2:error] [pid 123784:tid 124013] [client 213.202.253.4:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "showprimeautomoveis.com.br"] [uri "/schallfuns.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8QAAAF8"], referer: www.google.com [Tue Aug 18 13:01:00.318589 2026] [security2:error] [pid 123784:tid 123948] [client 20.127.136.245:28057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wap.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC8gAAAB4"] [Tue Aug 18 13:01:00.352296 2026] [security2:error] [pid 123784:tid 124009] [client 20.151.109.219:60885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/34.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9AAAAFs"] [Tue Aug 18 13:01:00.401067 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:5622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9QAAAEs"] [Tue Aug 18 13:01:00.446325 2026] [security2:error] [pid 123784:tid 123956] [client 20.38.3.247:48508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rkazuoveiculos.com.br"] [uri "/abcd.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC9wAAACY"] [Tue Aug 18 13:01:00.510539 2026] [security2:error] [pid 123784:tid 124042] [client 52.141.58.175:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/w.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-AAAAHw"] [Tue Aug 18 13:01:00.579565 2026] [security2:error] [pid 123784:tid 124035] [client 20.250.27.191:35657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/zoo2.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-gAAAHU"] [Tue Aug 18 13:01:00.624936 2026] [security2:error] [pid 123784:tid 123939] [client 20.251.112.238:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/rum.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC-wAAABU"] [Tue Aug 18 13:01:00.640047 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:00.640328 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:00.645242 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/pqr.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_QAAAGY"] [Tue Aug 18 13:01:00.769785 2026] [security2:error] [pid 123784:tid 123983] [client 20.102.65.165:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gueirosadvocacia.com.br"] [uri "/abcd.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_gAAAEE"] [Tue Aug 18 13:01:00.820078 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sm.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC_wAAACc"] [Tue Aug 18 13:01:00.877364 2026] [security2:error] [pid 123784:tid 123926] [client 114.119.133.87:34453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brindesoxente.com"] [uri "/index.php/product/caneta-ecologica/"] [unique_id "aoSBvGwDnJBNj2tDbYYDBAAAAAg"], referer: https://www.brindesoxente.com/index.php/product/caneta-ecologica [Tue Aug 18 13:01:00.917245 2026] [security2:error] [pid 123784:tid 124037] [client 20.127.136.245:12440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/mac.php"] [unique_id "aoSBvGwDnJBNj2tDbYYDBQAAAHc"] [Tue Aug 18 13:01:01.027567 2026] [security2:error] [pid 123784:tid 124043] [client 20.38.3.247:19557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/coffexium.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDBgAAAH0"] [Tue Aug 18 13:01:01.249412 2026] [security2:error] [pid 123784:tid 123997] [client 4.232.94.69:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/beence.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDDgAAAE8"] [Tue Aug 18 13:01:01.274007 2026] [security2:error] [pid 123784:tid 123964] [client 86.120.159.145:51193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7wAAAC4"] [Tue Aug 18 13:01:01.275756 2026] [security2:error] [pid 123784:tid 123920] [client 20.163.43.14:8898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDDwAAAAI"] [Tue Aug 18 13:01:01.298410 2026] [security2:error] [pid 123784:tid 124002] [client 20.250.13.23:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/photo.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDEAAAAFQ"] [Tue Aug 18 13:01:01.421564 2026] [security2:error] [pid 123784:tid 123977] [client 20.100.169.31:4779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDFAAAADs"] [Tue Aug 18 13:01:01.482120 2026] [security2:error] [pid 123784:tid 123919] [client 20.127.136.245:28054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/wp.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDGAAAAAE"] [Tue Aug 18 13:01:01.544631 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:01.544909 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:55872] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:01.656121 2026] [security2:error] [pid 123784:tid 123925] [client 172.202.39.151:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cah.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDIwAAAAc"] [Tue Aug 18 13:01:01.673493 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.98.162:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/signon.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJQAAABI"] [Tue Aug 18 13:01:01.727440 2026] [security2:error] [pid 123784:tid 124016] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/class.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJgAAAGI"] [Tue Aug 18 13:01:01.741822 2026] [security2:error] [pid 123784:tid 124012] [client 52.173.121.69:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zwlsv.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDJwAAAF4"] [Tue Aug 18 13:01:01.795691 2026] [security2:error] [pid 123784:tid 123927] [client 68.221.73.131:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/abcd.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDLwAAAAk"] [Tue Aug 18 13:01:01.848153 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDNAAAACg"] [Tue Aug 18 13:01:01.963503 2026] [security2:error] [pid 123784:tid 123972] [client 20.102.65.165:8264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDOwAAADY"] [Tue Aug 18 13:01:01.963907 2026] [security2:error] [pid 123784:tid 123952] [client 20.79.204.6:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDPAAAACI"] [Tue Aug 18 13:01:01.970193 2026] [security2:error] [pid 123784:tid 124038] [client 20.48.236.86:14486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mac.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDPQAAAHg"] [Tue Aug 18 13:01:01.970476 2026] [security2:error] [pid 123784:tid 123967] [client 185.168.30.19:34431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "leguizaimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDLAAAADE"] [Tue Aug 18 13:01:02.003284 2026] [security2:error] [pid 123784:tid 123968] [client 172.202.39.151:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDPgAAADI"] [Tue Aug 18 13:01:02.049489 2026] [security2:error] [pid 123784:tid 123964] [client 86.120.159.145:51193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvGwDnJBNj2tDbYYC7wAAAC4"] [Tue Aug 18 13:01:02.070090 2026] [security2:error] [pid 123784:tid 123983] [client 20.65.98.162:28944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/puc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDRwAAAEE"] [Tue Aug 18 13:01:02.153350 2026] [security2:error] [pid 123784:tid 123958] [client 149.34.210.141:55809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSBvWwDnJBNj2tDbYYDNAAAACg"] [Tue Aug 18 13:01:02.161217 2026] [security2:error] [pid 123784:tid 123962] [client 20.91.215.254:22263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/Session.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDTwAAACw"] [Tue Aug 18 13:01:02.199226 2026] [security2:error] [pid 123784:tid 124037] [client 20.251.112.238:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ze.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDUgAAAHc"] [Tue Aug 18 13:01:02.206917 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.204.6:10713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/php8.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDUwAAAEY"] [Tue Aug 18 13:01:02.306849 2026] [security2:error] [pid 123784:tid 123998] [client 138.36.100.162:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVQAAAFA"] [Tue Aug 18 13:01:02.306985 2026] [security2:error] [pid 123784:tid 123998] [client 138.36.100.162:42290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVQAAAFA"] [Tue Aug 18 13:01:02.372701 2026] [security2:error] [pid 123784:tid 123986] [client 20.102.65.165:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVgAAAEQ"] [Tue Aug 18 13:01:02.438365 2026] [security2:error] [pid 123784:tid 123946] [client 168.62.48.100:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDVwAAABw"] [Tue Aug 18 13:01:02.525944 2026] [security2:error] [pid 123784:tid 124019] [client 20.104.100.201:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDWgAAAGU"] [Tue Aug 18 13:01:02.537963 2026] [security2:error] [pid 123784:tid 123945] [client 20.206.73.37:29982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/dex.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDWwAAABs"] [Tue Aug 18 13:01:02.651710 2026] [security2:error] [pid 123784:tid 123947] [client 52.141.58.175:11653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/we.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDZAAAAB0"] [Tue Aug 18 13:01:02.660126 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:2204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDZwAAAFQ"] [Tue Aug 18 13:01:02.736953 2026] [security2:error] [pid 123784:tid 124020] [client 20.127.136.245:27865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bgymj.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDaQAAAGY"] [Tue Aug 18 13:01:02.805389 2026] [security2:error] [pid 123784:tid 124009] [client 168.62.48.100:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/index/function.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDcAAAAFs"] [Tue Aug 18 13:01:02.857924 2026] [security2:error] [pid 123784:tid 124011] [client 20.251.112.238:51100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gjm.php"] [unique_id "aoSBvmwDnJBNj2tDbYYDdAAAAF0"] [Tue Aug 18 13:01:03.111535 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfAAAAFc"] [Tue Aug 18 13:01:03.144631 2026] [security2:error] [pid 123784:tid 123980] [client 103.184.169.37:43028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfQAAAD4"] [Tue Aug 18 13:01:03.144772 2026] [security2:error] [pid 123784:tid 123980] [client 103.184.169.37:43028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDfQAAAD4"] [Tue Aug 18 13:01:03.150371 2026] [security2:error] [pid 123784:tid 123983] [client 168.62.48.100:18167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDgAAAAEE"] [Tue Aug 18 13:01:03.250171 2026] [security2:error] [pid 123784:tid 123962] [client 68.221.73.131:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/simple.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDggAAACw"] [Tue Aug 18 13:01:03.408866 2026] [security2:error] [pid 123784:tid 124037] [client 20.75.92.165:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/buy.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDhwAAAHc"] [Tue Aug 18 13:01:03.493297 2026] [security2:error] [pid 123784:tid 123998] [client 168.62.48.100:18137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/Cachex.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDiQAAAFA"] [Tue Aug 18 13:01:03.578135 2026] [security2:error] [pid 123784:tid 124025] [client 20.127.136.245:27892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aa.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDjAAAAGs"] [Tue Aug 18 13:01:03.597532 2026] [security2:error] [pid 123784:tid 123946] [client 20.118.133.132:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/signon.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDkAAAABw"] [Tue Aug 18 13:01:03.660986 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:13761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/nc4.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDkgAAABs"] [Tue Aug 18 13:01:03.799144 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:9382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vp.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDlQAAAEM"] [Tue Aug 18 13:01:03.800129 2026] [security2:error] [pid 123784:tid 123947] [client 168.62.48.100:18165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDlgAAAB0"] [Tue Aug 18 13:01:03.873456 2026] [security2:error] [pid 123784:tid 123960] [client 20.102.65.165:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/yj09.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDnAAAACo"] [Tue Aug 18 13:01:03.905545 2026] [security2:error] [pid 123784:tid 124019] [client 20.91.215.254:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/acme-challenge.php"] [unique_id "aoSBv2wDnJBNj2tDbYYDnwAAAGU"] [Tue Aug 18 13:01:04.012818 2026] [security2:error] [pid 123784:tid 123926] [client 213.35.127.232:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDogAAAAg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:04.085597 2026] [security2:error] [pid 123784:tid 123938] [client 20.151.109.219:39352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/he.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDowAAABQ"] [Tue Aug 18 13:01:04.130037 2026] [security2:error] [pid 123784:tid 123953] [client 20.38.3.247:39000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpAAAACM"] [Tue Aug 18 13:01:04.199046 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/flower.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqAAAAFg"] [Tue Aug 18 13:01:04.209692 2026] [security2:error] [pid 123784:tid 123972] [client 20.102.65.165:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/scxy.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqQAAADY"] [Tue Aug 18 13:01:04.212958 2026] [security2:error] [pid 123784:tid 123993] [client 74.7.228.22:47208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gvc.eng.br"] [uri "/index.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpQAASyI"] [Tue Aug 18 13:01:04.378865 2026] [security2:error] [pid 123784:tid 124035] [client 20.226.56.190:31035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/lmfi2.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDqgAAAHU"] [Tue Aug 18 13:01:04.489613 2026] [security2:error] [pid 123784:tid 124026] [client 20.151.109.219:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gz.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDrAAAAGw"] [Tue Aug 18 13:01:04.703034 2026] [security2:error] [pid 123784:tid 123957] [client 20.100.169.31:4956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDtwAAACc"] [Tue Aug 18 13:01:04.769338 2026] [fcgid:warn] [pid 123784:tid 124018] (70014)End of file found: [client 66.132.195.121:50640] mod_fcgid: can't get data from http client [Tue Aug 18 13:01:04.901691 2026] [security2:error] [pid 123784:tid 123996] [client 20.226.56.190:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/info2.php"] [unique_id "aoSBwGwDnJBNj2tDbYYD4wAAAE4"] [Tue Aug 18 13:01:05.088996 2026] [security2:error] [pid 123784:tid 123960] [client 52.28.162.93:14674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6AAAACo"], referer: http://www.pinceisroma.com.br [Tue Aug 18 13:01:05.142248 2026] [security2:error] [pid 123784:tid 123959] [client 52.141.58.175:11650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wk/index.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6gAAACk"] [Tue Aug 18 13:01:05.210597 2026] [security2:error] [pid 123784:tid 123988] [client 37.40.227.74:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpwAAAEY"] [Tue Aug 18 13:01:05.210744 2026] [security2:error] [pid 123784:tid 123988] [client 37.40.227.74:56733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDpwAAAEY"] [Tue Aug 18 13:01:05.211817 2026] [security2:error] [pid 123784:tid 124023] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD6QAAaXo"] [Tue Aug 18 13:01:05.265506 2026] [security2:error] [pid 123784:tid 123938] [client 158.23.17.4:29462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ph.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD7QAAABQ"] [Tue Aug 18 13:01:05.342430 2026] [security2:error] [pid 123784:tid 124013] [client 20.91.215.254:12101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/abcd.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD8QAAAF8"] [Tue Aug 18 13:01:05.366676 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:05.366941 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:05.367083 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:05.367427 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:05.367910 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:05.368178 2026] [authz_core:error] [pid 123784:tid 123820] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:05.419318 2026] [security2:error] [pid 123784:tid 123954] [client 20.206.73.37:29981] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "novoverona.com.br"] [uri "/1.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9QAAACQ"] [Tue Aug 18 13:01:05.419408 2026] [security2:error] [pid 123784:tid 123954] [client 20.206.73.37:29981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/1.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9QAAACQ"] [Tue Aug 18 13:01:05.453459 2026] [security2:error] [pid 123784:tid 123819] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9gAAFR4"] [Tue Aug 18 13:01:05.476436 2026] [security2:error] [pid 123784:tid 123925] [client 20.118.133.132:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file61.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD9wAAAAc"] [Tue Aug 18 13:01:05.494361 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.112.238:54431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/new4.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-AAAAEo"] [Tue Aug 18 13:01:05.515122 2026] [security2:error] [pid 123784:tid 123944] [client 213.35.127.232:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-QAAABo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:05.574339 2026] [security2:error] [pid 123784:tid 123980] [client 20.102.65.165:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD-gAAAD4"] [Tue Aug 18 13:01:05.615665 2026] [security2:error] [pid 123784:tid 123943] [client 20.48.236.86:14813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ops.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD_QAAABk"] [Tue Aug 18 13:01:05.657219 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.56.190:3012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/test_info.php"] [unique_id "aoSBwWwDnJBNj2tDbYYD_gAAAFI"] [Tue Aug 18 13:01:05.669373 2026] [security2:error] [pid 123784:tid 123881] [remote 216.194.122.158:38534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDsgAAXlw"] [Tue Aug 18 13:01:05.762053 2026] [security2:error] [pid 123784:tid 123949] [client 20.1.169.243:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/as.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEDgAAAB8"] [Tue Aug 18 13:01:05.899474 2026] [security2:error] [pid 123784:tid 123930] [client 20.127.136.245:8261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/as.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEDwAAAAw"] [Tue Aug 18 13:01:05.908116 2026] [security2:error] [pid 123784:tid 123945] [client 20.102.65.165:8265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEEAAAABs"] [Tue Aug 18 13:01:05.936809 2026] [security2:error] [pid 123784:tid 123984] [client 20.151.109.219:39297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nf.php"] [unique_id "aoSBwWwDnJBNj2tDbYYEEgAAAEI"] [Tue Aug 18 13:01:06.031153 2026] [security2:error] [pid 123784:tid 123953] [client 20.127.136.245:28032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-mail.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEFgAAACM"] [Tue Aug 18 13:01:06.039817 2026] [security2:error] [pid 123784:tid 123990] [client 168.62.48.100:18131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-2019.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEFwAAAEg"] [Tue Aug 18 13:01:06.053816 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:47884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/28.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGAAAACU"] [Tue Aug 18 13:01:06.231431 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:56747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lp.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGgAAAC4"] [Tue Aug 18 13:01:06.235181 2026] [security2:error] [pid 123784:tid 123919] [client 52.28.162.93:14684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGQAAAAE"], referer: http://www.pinceisroma.com.br [Tue Aug 18 13:01:06.273252 2026] [security2:error] [pid 123784:tid 123959] [client 52.173.121.69:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/jrpga.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEGwAAACk"] [Tue Aug 18 13:01:06.303662 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.56.190:31650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/xynz1.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEHQAAADo"] [Tue Aug 18 13:01:06.484051 2026] [security2:error] [pid 123784:tid 123954] [client 20.151.109.219:60895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xv.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIQAAACQ"] [Tue Aug 18 13:01:06.487892 2026] [security2:error] [pid 123784:tid 123993] [client 68.221.73.131:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-manager.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIgAAAEs"] [Tue Aug 18 13:01:06.493125 2026] [security2:error] [pid 123784:tid 123952] [client 172.202.39.151:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEIwAAACI"] [Tue Aug 18 13:01:06.493189 2026] [security2:error] [pid 123784:tid 123940] [client 20.91.215.254:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/kj.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEJAAAABY"] [Tue Aug 18 13:01:06.585450 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:17583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/m.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKgAAAH8"] [Tue Aug 18 13:01:06.591136 2026] [security2:error] [pid 123784:tid 124002] [client 102.213.179.104:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKwAAAFQ"] [Tue Aug 18 13:01:06.591251 2026] [security2:error] [pid 123784:tid 124002] [client 102.213.179.104:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEKwAAAFQ"] [Tue Aug 18 13:01:06.647554 2026] [security2:error] [pid 123784:tid 124042] [client 20.1.169.243:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/atex1.php"] [unique_id "aoSBwmwDnJBNj2tDbYYELAAAAHw"] [Tue Aug 18 13:01:06.683992 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:06.684255 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:06.693419 2026] [security2:error] [pid 123784:tid 124000] [client 20.48.236.86:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/8.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEMwAAAFI"] [Tue Aug 18 13:01:06.703839 2026] [security2:error] [pid 123784:tid 123805] [remote 162.241.152.27:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSBwGwDnJBNj2tDbYYDtgAAMhA"] [Tue Aug 18 13:01:06.763560 2026] [security2:error] [pid 123784:tid 124025] [client 20.100.169.31:4990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSBwmwDnJBNj2tDbYYENAAAAGs"] [Tue Aug 18 13:01:06.824312 2026] [security2:error] [pid 123784:tid 123949] [client 20.151.109.219:24403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mx.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOAAAAB8"] [Tue Aug 18 13:01:06.852672 2026] [security2:error] [pid 123784:tid 124009] [client 4.232.94.69:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/configs.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOgAAAFs"] [Tue Aug 18 13:01:06.872077 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.56.190:31003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/album.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEOwAAAAw"] [Tue Aug 18 13:01:06.946593 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:29454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/s.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPQAAAE4"] [Tue Aug 18 13:01:06.958107 2026] [security2:error] [pid 123784:tid 123950] [client 20.104.100.201:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/css/database.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPgAAACA"] [Tue Aug 18 13:01:06.960389 2026] [security2:error] [pid 123784:tid 123955] [client 20.118.133.132:15620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/copypaths.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEPwAAACU"] [Tue Aug 18 13:01:06.981081 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:28050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bolt.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEQAAAABQ"] [Tue Aug 18 13:01:06.983390 2026] [security2:error] [pid 123784:tid 123985] [client 20.206.73.37:34765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/coffee.php"] [unique_id "aoSBwmwDnJBNj2tDbYYEQQAAAEM"] [Tue Aug 18 13:01:07.018598 2026] [security2:error] [pid 123784:tid 123964] [client 52.173.121.69:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEQwAAAC4"] [Tue Aug 18 13:01:07.198939 2026] [security2:error] [pid 123784:tid 123972] [client 49.13.24.81:39662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSBw2wDnJBNj2tDbYYERwAAADY"], referer: http://rakhomed.com.br [Tue Aug 18 13:01:07.237101 2026] [security2:error] [pid 123784:tid 123952] [client 20.102.65.165:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/blurbs.php"] [unique_id "aoSBw2wDnJBNj2tDbYYESgAAACI"] [Tue Aug 18 13:01:07.286204 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nl.php"] [unique_id "aoSBw2wDnJBNj2tDbYYETAAAAH8"] [Tue Aug 18 13:01:07.548784 2026] [security2:error] [pid 123784:tid 123943] [client 20.79.222.117:17940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEUwAAABk"] [Tue Aug 18 13:01:07.633433 2026] [security2:error] [pid 123784:tid 123990] [client 20.1.169.243:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/atomlib.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEVQAAAEg"] [Tue Aug 18 13:01:07.652708 2026] [security2:error] [pid 123784:tid 124001] [client 52.173.121.69:47601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/nwwha.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEVgAAAFM"] [Tue Aug 18 13:01:07.722695 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:20378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/creds.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEWQAAACw"] [Tue Aug 18 13:01:07.822697 2026] [security2:error] [pid 123784:tid 123890] [remote 178.156.200.16:45080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEWwAAN2U"] [Tue Aug 18 13:01:07.932249 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/motu.php"] [unique_id "aoSBw2wDnJBNj2tDbYYEXgAAACA"] [Tue Aug 18 13:01:08.017643 2026] [security2:error] [pid 123784:tid 123985] [client 20.79.222.117:18020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYAAAAEM"] [Tue Aug 18 13:01:08.117387 2026] [security2:error] [pid 123784:tid 124029] [client 20.127.136.245:27894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/bthil.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYgAAAG8"] [Tue Aug 18 13:01:08.125557 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:58691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/68.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEYwAAAFo"] [Tue Aug 18 13:01:08.235543 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:08.235981 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:08.238127 2026] [security2:error] [pid 123784:tid 123948] [client 20.251.112.238:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-act.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEbgAAAB4"] [Tue Aug 18 13:01:08.240863 2026] [security2:error] [pid 123784:tid 123936] [client 52.141.58.175:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/worksec.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEbwAAABI"] [Tue Aug 18 13:01:08.259154 2026] [security2:error] [pid 123784:tid 123991] [client 172.202.39.151:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/rip.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEcAAAAEk"] [Tue Aug 18 13:01:08.286779 2026] [security2:error] [pid 123784:tid 123988] [client 216.244.66.243:43436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/cascaaapg.com-0/"] [unique_id "aoSBxGwDnJBNj2tDbYYEcQAAAEY"] [Tue Aug 18 13:01:08.286883 2026] [security2:error] [pid 123784:tid 123988] [client 216.244.66.243:43436] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/cascaaapg.com-0/"] [unique_id "aoSBxGwDnJBNj2tDbYYEcQAAAEY"] [Tue Aug 18 13:01:08.317667 2026] [security2:error] [pid 123784:tid 124018] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/404.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEegAAAGQ"] [Tue Aug 18 13:01:08.333127 2026] [security2:error] [pid 123784:tid 123931] [client 20.151.109.219:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/45.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEewAAAA0"] [Tue Aug 18 13:01:08.362957 2026] [security2:error] [pid 123784:tid 124045] [client 20.38.3.247:39397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/sf.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEfAAAAH8"] [Tue Aug 18 13:01:08.401973 2026] [security2:error] [pid 123784:tid 124002] [client 49.13.130.29:48508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSBxGwDnJBNj2tDbYYEfgAAAFQ"], referer: http://rakhomed.com.br [Tue Aug 18 13:01:08.454163 2026] [security2:error] [pid 123784:tid 123987] [client 20.206.73.37:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEgQAAAEU"] [Tue Aug 18 13:01:08.539521 2026] [security2:error] [pid 123784:tid 123980] [client 20.79.222.117:18000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEhQAAAD4"] [Tue Aug 18 13:01:08.553396 2026] [security2:error] [pid 123784:tid 124001] [client 20.226.56.190:23783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/mandrill.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEhwAAAFM"] [Tue Aug 18 13:01:08.604586 2026] [security2:error] [pid 123784:tid 123955] [client 20.1.169.243:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/black.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEiAAAACU"] [Tue Aug 18 13:01:08.638696 2026] [security2:error] [pid 123784:tid 123971] [client 157.90.155.240:26670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.portaltomazzi.com.br"] [uri "/index.php"] [unique_id "aoSBw2wDnJBNj2tDbYYETwAAADU"], referer: https://www.portaltomazzi.com.br/ [Tue Aug 18 13:01:08.714756 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jl.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEjgAAAFA"] [Tue Aug 18 13:01:08.717804 2026] [security2:error] [pid 123784:tid 124009] [client 52.173.121.69:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/opsqt.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEjwAAAFs"] [Tue Aug 18 13:01:08.767448 2026] [security2:error] [pid 123784:tid 124013] [client 20.100.169.31:4974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEkgAAAF8"] [Tue Aug 18 13:01:08.954249 2026] [security2:error] [pid 123784:tid 123991] [client 20.118.133.132:17766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bless6.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmAAAAEk"] [Tue Aug 18 13:01:08.959049 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ey.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmQAAAEY"] [Tue Aug 18 13:01:08.979191 2026] [security2:error] [pid 123784:tid 123952] [client 20.251.112.238:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/grsiuk.php"] [unique_id "aoSBxGwDnJBNj2tDbYYEmgAAACI"] [Tue Aug 18 13:01:09.062261 2026] [security2:error] [pid 123784:tid 123976] [client 20.1.169.243:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/bs1.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEnQAAADo"] [Tue Aug 18 13:01:09.093590 2026] [security2:error] [pid 123784:tid 123954] [client 20.127.136.245:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/k.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEnwAAACQ"] [Tue Aug 18 13:01:09.179690 2026] [http2:info] [pid 139043:tid 139043] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 13:01:09.181917 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:31891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fd.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEoAAAAGA"] [Tue Aug 18 13:01:09.222575 2026] [security2:error] [pid 123784:tid 123893] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEogAAUmg"] [Tue Aug 18 13:01:09.222735 2026] [security2:error] [pid 123784:tid 124000] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEogAAUmg"] [Tue Aug 18 13:01:09.239766 2026] [security2:error] [pid 123784:tid 123919] [client 49.13.134.145:31698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEngAAAAE"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 13:01:09.387324 2026] [security2:error] [pid 123784:tid 123984] [client 52.173.121.69:56391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/jvcpa.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEpgAAAEI"] [Tue Aug 18 13:01:09.436689 2026] [authz_core:error] [pid 123784:tid 123916] [remote 57.141.22.42:32292] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:09.436960 2026] [authz_core:error] [pid 123784:tid 123916] [remote 57.141.22.42:32292] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:09.467284 2026] [security2:error] [pid 123784:tid 123983] [client 20.163.43.14:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEqQAAAEE"] [Tue Aug 18 13:01:09.562812 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.222.117:18039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/av.php"] [unique_id "aoSBxWwDnJBNj2tDbYYErgAAACM"] [Tue Aug 18 13:01:09.594641 2026] [security2:error] [pid 123784:tid 123942] [client 4.232.94.69:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/delpaths.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEsAAAABg"] [Tue Aug 18 13:01:09.914014 2026] [security2:error] [pid 139043:tid 139177] [client 158.23.17.4:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/info2.php"] [unique_id "aoSBxf2v-lWn9OzQT7UO0AAAAIk"] [Tue Aug 18 13:01:09.957783 2026] [security2:error] [pid 123784:tid 124020] [client 168.62.48.100:18002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSBxWwDnJBNj2tDbYYEtgAAAGY"] [Tue Aug 18 13:01:10.047641 2026] [security2:error] [pid 123784:tid 124014] [client 68.221.73.131:35111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/xiugai.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEuQAAAGA"] [Tue Aug 18 13:01:10.053456 2026] [security2:error] [pid 123784:tid 123863] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEugAAP0o"] [Tue Aug 18 13:01:10.147194 2026] [security2:error] [pid 123784:tid 123940] [client 20.1.169.243:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/colors/blue/about.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvAAAABY"] [Tue Aug 18 13:01:10.164681 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lv.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvQAAACY"] [Tue Aug 18 13:01:10.226296 2026] [security2:error] [pid 123784:tid 123949] [client 20.127.136.245:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/x.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEvwAAAB8"] [Tue Aug 18 13:01:10.280087 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:10.280339 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:10.317601 2026] [security2:error] [pid 123784:tid 123955] [client 172.202.39.151:44563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEwgAAACU"] [Tue Aug 18 13:01:10.325095 2026] [security2:error] [pid 123784:tid 123938] [client 52.173.121.69:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEwwAAABQ"] [Tue Aug 18 13:01:10.347924 2026] [security2:error] [pid 123784:tid 123983] [client 20.206.73.37:35317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExAAAAEE"] [Tue Aug 18 13:01:10.350863 2026] [security2:error] [pid 123784:tid 124013] [client 20.163.43.14:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/about.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExQAAAF8"] [Tue Aug 18 13:01:10.372092 2026] [security2:error] [pid 123784:tid 123989] [client 20.65.98.162:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file61.php"] [unique_id "aoSBxmwDnJBNj2tDbYYExwAAAEc"] [Tue Aug 18 13:01:10.379042 2026] [security2:error] [pid 139043:tid 139183] [client 20.79.204.6:2369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBxv2v-lWn9OzQT7UO0gAAAI8"] [Tue Aug 18 13:01:10.607924 2026] [security2:error] [pid 123784:tid 123971] [client 20.1.169.243:5779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/con7.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEygAAADU"] [Tue Aug 18 13:01:10.638627 2026] [security2:error] [pid 123784:tid 123899] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEywAATm4"] [Tue Aug 18 13:01:10.648769 2026] [security2:error] [pid 139043:tid 139185] [client 158.23.17.4:63628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/uo.php"] [unique_id "aoSBxv2v-lWn9OzQT7UO1AAAAJE"] [Tue Aug 18 13:01:10.749694 2026] [security2:error] [pid 123784:tid 123936] [client 20.163.43.14:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBxmwDnJBNj2tDbYYEzQAAABI"] [Tue Aug 18 13:01:10.816251 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lite.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE0QAAAGA"] [Tue Aug 18 13:01:10.824147 2026] [security2:error] [pid 123784:tid 124044] [client 20.127.136.245:27885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/index/function.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE0gAAAH4"] [Tue Aug 18 13:01:10.930122 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.13.23:44057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-aa.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE1AAAADM"] [Tue Aug 18 13:01:11.007983 2026] [security2:error] [pid 123784:tid 124045] [client 49.13.130.29:45190] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSBxmwDnJBNj2tDbYYE1QAAAH8"], referer: http://rakhomed.com.br [Tue Aug 18 13:01:11.139975 2026] [security2:error] [pid 123784:tid 124001] [client 20.163.43.14:8942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/f35.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE1gAAAFM"] [Tue Aug 18 13:01:11.198328 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lock360.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE1wAAAEI"] [Tue Aug 18 13:01:11.223059 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.56.190:31651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/main.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE2QAAAG8"] [Tue Aug 18 13:01:11.447173 2026] [security2:error] [pid 123784:tid 123920] [client 20.104.100.201:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/privdayz.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE8gAAAAI"] [Tue Aug 18 13:01:11.483381 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:11.483644 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:11.505477 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:28358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sx.php"] [unique_id "aoSBx_2v-lWn9OzQT7UO2AAAAJk"] [Tue Aug 18 13:01:11.541711 2026] [security2:error] [pid 123784:tid 124026] [client 158.23.17.4:29450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kx.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE9QAAAGw"] [Tue Aug 18 13:01:11.606834 2026] [security2:error] [pid 123784:tid 123996] [client 20.79.222.117:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/images.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE-QAAAE4"] [Tue Aug 18 13:01:11.742748 2026] [access_compat:error] [pid 123784:tid 123919] [client 74.7.175.173:0] AH01797: client denied by server configuration: /home1/rakhomed/public_html/robots.txt [Tue Aug 18 13:01:11.744116 2026] [security2:error] [pid 123784:tid 123919] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "rakhomed.com.br"] [uri "/cgi-sys/403.html"] [unique_id "aoSBx2wDnJBNj2tDbYYE-wAAAAE"] [Tue Aug 18 13:01:11.749430 2026] [security2:error] [pid 139043:tid 139197] [client 158.23.17.4:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/51.php"] [unique_id "aoSBx_2v-lWn9OzQT7UO2QAAAJ0"] [Tue Aug 18 13:01:11.777401 2026] [security2:error] [pid 123784:tid 123993] [client 74.7.175.173:46614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "rakhomed.com.br"] [uri "/robots.txt"] [unique_id "aoSBxmwDnJBNj2tDbYYEzgAAS2M"] [Tue Aug 18 13:01:11.786510 2026] [security2:error] [pid 139043:tid 139195] [client 20.100.169.31:4795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSBx_2v-lWn9OzQT7UO2gAAAJs"] [Tue Aug 18 13:01:11.812831 2026] [security2:error] [pid 123784:tid 123954] [client 52.141.58.175:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-access.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_AAAACQ"] [Tue Aug 18 13:01:11.893544 2026] [security2:error] [pid 123784:tid 123925] [client 68.221.73.131:33036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wp-load.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_gAAAAc"] [Tue Aug 18 13:01:11.919314 2026] [security2:error] [pid 123784:tid 123932] [client 20.79.204.6:10716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSBx2wDnJBNj2tDbYYE_wAAAA4"] [Tue Aug 18 13:01:11.924962 2026] [security2:error] [pid 123784:tid 124000] [client 172.202.39.151:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cgi-bin/index.php"] [unique_id "aoSBx2wDnJBNj2tDbYYFAAAAAFI"] [Tue Aug 18 13:01:12.044274 2026] [security2:error] [pid 123784:tid 123995] [client 4.232.94.69:25520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/NewFile.php"] [unique_id "aoSByGwDnJBNj2tDbYYFAgAAAE0"] [Tue Aug 18 13:01:12.096070 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSByGwDnJBNj2tDbYYFBAAAAFg"] [Tue Aug 18 13:01:12.244961 2026] [security2:error] [pid 123784:tid 123813] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/public/css.php"] [unique_id "aoSByGwDnJBNj2tDbYYFBwAAPxg"] [Tue Aug 18 13:01:12.288615 2026] [security2:error] [pid 123784:tid 124010] [client 20.104.100.201:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wg459o.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCAAAAFw"] [Tue Aug 18 13:01:12.374141 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:9320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/va.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCgAAAG8"] [Tue Aug 18 13:01:12.400105 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:12.400929 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:12.450328 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSByGwDnJBNj2tDbYYFDAAAQRQ"] [Tue Aug 18 13:01:12.451814 2026] [security2:error] [pid 123784:tid 124013] [client 20.118.133.132:30853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/special.php"] [unique_id "aoSByGwDnJBNj2tDbYYFDQAAAF8"] [Tue Aug 18 13:01:12.495241 2026] [security2:error] [pid 139043:tid 139206] [client 172.202.39.151:44601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/moon.php"] [unique_id "aoSByP2v-lWn9OzQT7UO4gAAAKY"] [Tue Aug 18 13:01:12.532456 2026] [security2:error] [pid 123784:tid 124023] [client 20.65.98.162:2842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/19.php"] [unique_id "aoSByGwDnJBNj2tDbYYFEAAAAGk"] [Tue Aug 18 13:01:12.564663 2026] [security2:error] [pid 139043:tid 139208] [client 172.202.39.151:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/an.php"] [unique_id "aoSByP2v-lWn9OzQT7UO4wAAAKg"] [Tue Aug 18 13:01:12.688648 2026] [autoindex:error] [pid 123784:tid 124008] [client 83.140.110.35:18989] AH01276: Cannot serve directory /home4/varandasgp/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:12.720571 2026] [security2:error] [pid 139043:tid 139210] [client 20.163.43.14:8950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/inputs.php"] [unique_id "aoSByP2v-lWn9OzQT7UO5AAAAKo"] [Tue Aug 18 13:01:12.745131 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/d.php"] [unique_id "aoSByGwDnJBNj2tDbYYFFQAAACY"] [Tue Aug 18 13:01:12.882413 2026] [security2:error] [pid 123784:tid 123988] [client 20.127.136.245:15058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSByGwDnJBNj2tDbYYFGQAAAEY"] [Tue Aug 18 13:01:12.912939 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:12.913197 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:13.040286 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.73.37:35285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/mgrr.php"] [unique_id "aoSByWwDnJBNj2tDbYYFHwAAADo"] [Tue Aug 18 13:01:13.058877 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:9361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fo.php"] [unique_id "aoSByf2v-lWn9OzQT7UO5QAAALM"] [Tue Aug 18 13:01:13.154155 2026] [security2:error] [pid 123784:tid 124020] [client 138.36.100.162:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIQAAAGY"] [Tue Aug 18 13:01:13.155793 2026] [security2:error] [pid 123784:tid 124020] [client 138.36.100.162:42439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIQAAAGY"] [Tue Aug 18 13:01:13.260005 2026] [security2:error] [pid 123784:tid 123890] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSByWwDnJBNj2tDbYYFIgAADWU"] [Tue Aug 18 13:01:13.334508 2026] [security2:error] [pid 123784:tid 124014] [client 103.120.71.157:51356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJAAAAGA"] [Tue Aug 18 13:01:13.334712 2026] [security2:error] [pid 123784:tid 124014] [client 103.120.71.157:51356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJAAAAGA"] [Tue Aug 18 13:01:13.363601 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:18113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/.cache/x.php"] [unique_id "aoSByf2v-lWn9OzQT7UO6QAAALY"] [Tue Aug 18 13:01:13.393003 2026] [security2:error] [pid 123784:tid 124044] [client 149.34.210.141:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCQAAAH4"] [Tue Aug 18 13:01:13.393146 2026] [security2:error] [pid 123784:tid 124044] [client 149.34.210.141:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSByGwDnJBNj2tDbYYFCQAAAH4"] [Tue Aug 18 13:01:13.464229 2026] [security2:error] [pid 123784:tid 123964] [client 49.13.24.81:52624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJQAAAC4"], referer: http://rakhomed.com.br [Tue Aug 18 13:01:13.475359 2026] [security2:error] [pid 123784:tid 123995] [client 20.251.112.238:26124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/h.php"] [unique_id "aoSByWwDnJBNj2tDbYYFJgAAAE0"] [Tue Aug 18 13:01:13.568437 2026] [security2:error] [pid 123784:tid 124003] [client 20.118.133.132:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/fz.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKAAAAFU"] [Tue Aug 18 13:01:13.581683 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.222.117:18040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/ops.php"] [unique_id "aoSByf2v-lWn9OzQT7UO6wAAAL0"] [Tue Aug 18 13:01:13.610113 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:13.610386 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:13.789988 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:18018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSByf2v-lWn9OzQT7UO7QAAAME"] [Tue Aug 18 13:01:13.866554 2026] [security2:error] [pid 123784:tid 123856] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gelay.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKgAAX0M"] [Tue Aug 18 13:01:13.874113 2026] [security2:error] [pid 123784:tid 124022] [client 68.221.73.131:42687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/155.php"] [unique_id "aoSByWwDnJBNj2tDbYYFKwAAAGg"] [Tue Aug 18 13:01:13.882145 2026] [core:error] [pid 139043:tid 139227] [client 20.79.204.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:01:13.882171 2026] [core:error] [pid 139043:tid 139227] [client 20.79.204.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:01:13.910796 2026] [security2:error] [pid 139043:tid 139236] [client 20.65.98.162:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/copypaths.php"] [unique_id "aoSByf2v-lWn9OzQT7UO8AAAAMQ"] [Tue Aug 18 13:01:14.084045 2026] [security2:error] [pid 123784:tid 123953] [client 20.79.222.117:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/coffexium.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLAAAACM"] [Tue Aug 18 13:01:14.122558 2026] [security2:error] [pid 123784:tid 123946] [client 20.127.136.245:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aaa.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLQAAABw"] [Tue Aug 18 13:01:14.128729 2026] [security2:error] [pid 139043:tid 139244] [client 168.62.48.100:17986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSByv2v-lWn9OzQT7UO8gAAAMw"] [Tue Aug 18 13:01:14.206294 2026] [security2:error] [pid 123784:tid 123992] [client 20.251.112.238:7819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/koiy.php"] [unique_id "aoSBymwDnJBNj2tDbYYFLwAAAEo"] [Tue Aug 18 13:01:14.261030 2026] [security2:error] [pid 123784:tid 123925] [client 20.250.13.23:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSBymwDnJBNj2tDbYYFMQAAAAc"] [Tue Aug 18 13:01:14.410982 2026] [security2:error] [pid 139043:tid 139220] [client 20.100.169.31:4965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSByv2v-lWn9OzQT7UO9gAAALQ"] [Tue Aug 18 13:01:14.580816 2026] [security2:error] [pid 139043:tid 139248] [client 172.202.39.151:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/cache.php"] [unique_id "aoSByv2v-lWn9OzQT7UO9wAAANA"] [Tue Aug 18 13:01:14.590423 2026] [security2:error] [pid 123784:tid 123984] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSBymwDnJBNj2tDbYYFNwAAAEI"] [Tue Aug 18 13:01:14.730374 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.56.190:31663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/payout.php"] [unique_id "aoSByv2v-lWn9OzQT7UO-AAAANY"] [Tue Aug 18 13:01:14.752103 2026] [security2:error] [pid 139043:tid 139255] [client 20.104.100.201:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mifta.php"] [unique_id "aoSByv2v-lWn9OzQT7UO-QAAANc"] [Tue Aug 18 13:01:14.954799 2026] [security2:error] [pid 123784:tid 124000] [client 157.20.138.62:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPQAAAFI"] [Tue Aug 18 13:01:14.954910 2026] [security2:error] [pid 123784:tid 124000] [client 157.20.138.62:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPQAAAFI"] [Tue Aug 18 13:01:14.973107 2026] [security2:error] [pid 123784:tid 123985] [client 52.141.58.175:11658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.58.141.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.iarj.com.br"] [uri "/wp-admin.php"] [unique_id "aoSBymwDnJBNj2tDbYYFPgAAAEM"] [Tue Aug 18 13:01:15.051113 2026] [security2:error] [pid 139043:tid 139249] [client 20.127.136.245:28333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abcd.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_QAAANE"] [Tue Aug 18 13:01:15.087007 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.94.69:19547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/system.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_gAAANg"] [Tue Aug 18 13:01:15.117442 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:15.117861 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:15.131338 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFQQAAAH8"] [Tue Aug 18 13:01:15.136108 2026] [security2:error] [pid 139043:tid 139265] [client 20.79.222.117:18046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSBy_2v-lWn9OzQT7UO_wAAAOE"] [Tue Aug 18 13:01:15.220423 2026] [security2:error] [pid 123784:tid 123837] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFQgAANzA"] [Tue Aug 18 13:01:15.225871 2026] [security2:error] [pid 123784:tid 123954] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atekrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSBymwDnJBNj2tDbYYFNgAAJGo"], referer: https://atekrefrigeracao.com.br/ [Tue Aug 18 13:01:15.312227 2026] [security2:error] [pid 139043:tid 139216] [client 5.31.227.224:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAAAAALA"] [Tue Aug 18 13:01:15.312495 2026] [security2:error] [pid 139043:tid 139216] [client 5.31.227.224:7846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAAAAALA"] [Tue Aug 18 13:01:15.505100 2026] [security2:error] [pid 139043:tid 139280] [client 68.221.73.131:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/index.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPAwAAAPA"] [Tue Aug 18 13:01:15.558888 2026] [security2:error] [pid 139043:tid 139281] [client 20.48.236.86:14496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/biufile.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBQAAAPE"] [Tue Aug 18 13:01:15.683679 2026] [autoindex:error] [pid 123784:tid 123796] [remote 34.122.173.216:10336] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:15.702761 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:2222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFSwAAAFU"] [Tue Aug 18 13:01:15.754063 2026] [security2:error] [pid 139043:tid 139286] [client 20.65.98.162:45571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bless6.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBgAAAPY"] [Tue Aug 18 13:01:15.757932 2026] [security2:error] [pid 139043:tid 139287] [client 20.251.112.238:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fff.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPBwAAAPc"] [Tue Aug 18 13:01:15.798204 2026] [security2:error] [pid 123784:tid 123920] [client 213.35.127.232:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSBy2wDnJBNj2tDbYYFUwAAAAI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:16.011574 2026] [security2:error] [pid 139043:tid 139295] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBy_2v-lWn9OzQT7UPDAAA_x0"] [Tue Aug 18 13:01:16.018822 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:16.019189 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:16.072410 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.11:27910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:16.072770 2026] [authz_core:error] [pid 123784:tid 123811] [remote 57.141.22.11:27910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:16.190343 2026] [security2:error] [pid 139043:tid 139180] [client 20.48.236.86:14475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/coffexium.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPEAAAAIw"] [Tue Aug 18 13:01:16.200462 2026] [security2:error] [pid 123784:tid 124013] [client 20.91.215.254:12287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/languages.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFYwAAAF8"] [Tue Aug 18 13:01:16.212489 2026] [security2:error] [pid 139043:tid 139182] [client 158.23.17.4:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ew.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFAAAAI4"] [Tue Aug 18 13:01:16.343112 2026] [security2:error] [pid 139043:tid 139264] [client 223.185.37.47:21731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFQAAAOA"] [Tue Aug 18 13:01:16.363931 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:10715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/222.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFZAAAACw"] [Tue Aug 18 13:01:16.419000 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.56.190:2507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/Mailgun.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPHAAAAJM"] [Tue Aug 18 13:01:16.575910 2026] [security2:error] [pid 123784:tid 124007] [client 20.127.136.245:27841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-good.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFZwAAAFk"] [Tue Aug 18 13:01:16.619877 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:16.620144 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:16.625290 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/adminfuns.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFagAAQgQ"] [Tue Aug 18 13:01:16.758271 2026] [security2:error] [pid 139043:tid 139294] [client 20.100.169.31:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKAAAAP4"] [Tue Aug 18 13:01:16.845453 2026] [security2:error] [pid 123784:tid 124019] [client 20.250.13.23:6787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSBzGwDnJBNj2tDbYYFbQAAAGU"] [Tue Aug 18 13:01:16.924656 2026] [security2:error] [pid 139043:tid 139177] [client 20.79.204.6:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKQAAAIk"] [Tue Aug 18 13:01:16.944316 2026] [security2:error] [pid 139043:tid 139211] [client 20.163.43.14:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/alfa.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPKgAAAKs"] [Tue Aug 18 13:01:17.000951 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.alf.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPLgAAALE"] [Tue Aug 18 13:01:17.015429 2026] [security2:error] [pid 123784:tid 123823] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFcQAAWCI"] [Tue Aug 18 13:01:17.062271 2026] [security2:error] [pid 123784:tid 124045] [client 20.48.236.86:14482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/dex.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFdAAAAH8"] [Tue Aug 18 13:01:17.203015 2026] [security2:error] [pid 139043:tid 139191] [client 178.153.171.161:27409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPMwAAAJc"] [Tue Aug 18 13:01:17.203156 2026] [security2:error] [pid 139043:tid 139191] [client 178.153.171.161:27409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPMwAAAJc"] [Tue Aug 18 13:01:17.204454 2026] [security2:error] [pid 123784:tid 123870] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/about.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFdgAAeVE"] [Tue Aug 18 13:01:17.221506 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:17.221766 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:17.228235 2026] [security2:error] [pid 139043:tid 139234] [client 168.62.48.100:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPNAAAAMI"] [Tue Aug 18 13:01:17.431922 2026] [security2:error] [pid 123784:tid 123932] [client 20.127.136.245:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/system_log.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFeQAAAA4"] [Tue Aug 18 13:01:17.491483 2026] [security2:error] [pid 139043:tid 139242] [client 20.251.112.238:7137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/pouhg.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPNwAAAMo"] [Tue Aug 18 13:01:17.590113 2026] [security2:error] [pid 123784:tid 123839] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFggAAcTI"] [Tue Aug 18 13:01:17.590218 2026] [security2:error] [pid 123784:tid 124031] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFggAAcTI"] [Tue Aug 18 13:01:17.706100 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:27874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/simple.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPOwAAALY"] [Tue Aug 18 13:01:17.762287 2026] [security2:error] [pid 123784:tid 123805] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSBzWwDnJBNj2tDbYYFiQAAOxA"] [Tue Aug 18 13:01:17.832848 2026] [security2:error] [pid 123784:tid 123860] [remote 111.225.149.175:28970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2019/05/11-10-400x284.jpg"] [unique_id "aoSBzWwDnJBNj2tDbYYFiwAAK0c"] [Tue Aug 18 13:01:17.852119 2026] [security2:error] [pid 139043:tid 139173] [client 4.232.94.69:25016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPPAAAAIU"] [Tue Aug 18 13:01:18.070386 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14487] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "treinolab.com.br"] [uri "/1.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkAAAAEQ"] [Tue Aug 18 13:01:18.070495 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/1.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkAAAAEQ"] [Tue Aug 18 13:01:18.119416 2026] [security2:error] [pid 139043:tid 139249] [client 168.62.48.100:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPQAAAANE"] [Tue Aug 18 13:01:18.124886 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:10411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPQQAAAL0"] [Tue Aug 18 13:01:18.174438 2026] [security2:error] [pid 123784:tid 123996] [client 172.202.39.151:44557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkQAAAE4"] [Tue Aug 18 13:01:18.193255 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.56.190:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/oauth.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFkwAAACw"] [Tue Aug 18 13:01:18.238752 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:48433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pqr.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFlAAAAAk"] [Tue Aug 18 13:01:18.316813 2026] [security2:error] [pid 123784:tid 123901] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/f35.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFlgAAdXA"] [Tue Aug 18 13:01:18.363337 2026] [security2:error] [pid 139043:tid 139216] [client 20.163.43.14:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/lock360.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPRgAAALA"] [Tue Aug 18 13:01:18.447088 2026] [security2:error] [pid 139043:tid 139274] [client 20.118.133.132:15139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/clque.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSAAAAOo"] [Tue Aug 18 13:01:18.483976 2026] [security2:error] [pid 139043:tid 139277] [client 168.62.48.100:18099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSgAAAO0"] [Tue Aug 18 13:01:18.523786 2026] [security2:error] [pid 139043:tid 139280] [client 20.104.100.201:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/index2.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPSwAAAPA"] [Tue Aug 18 13:01:18.651267 2026] [security2:error] [pid 139043:tid 139257] [client 20.1.169.243:5789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTAAAANk"] [Tue Aug 18 13:01:18.716345 2026] [security2:error] [pid 139043:tid 139287] [client 20.250.27.191:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/imageskir.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTQAAAPc"] [Tue Aug 18 13:01:18.743180 2026] [authz_core:error] [pid 123784:tid 123909] [remote 57.141.22.44:21502] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:18.743453 2026] [authz_core:error] [pid 123784:tid 123909] [remote 57.141.22.44:21502] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:18.810077 2026] [security2:error] [pid 139043:tid 139295] [client 168.62.48.100:18081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPTwAAAP8"] [Tue Aug 18 13:01:18.829101 2026] [security2:error] [pid 123784:tid 123992] [client 20.127.136.245:28308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/edit-tags.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFnQAAAEo"] [Tue Aug 18 13:01:18.951249 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:32535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nu.php"] [unique_id "aoSBzv2v-lWn9OzQT7UPUQAAAQM"] [Tue Aug 18 13:01:19.000937 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPUgAAAIY"] [Tue Aug 18 13:01:19.016663 2026] [security2:error] [pid 139043:tid 139264] [client 223.185.37.47:21731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSBzP2v-lWn9OzQT7UPFQAAAOA"] [Tue Aug 18 13:01:19.032937 2026] [security2:error] [pid 123784:tid 124014] [client 20.79.222.117:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/sf.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFoAAAAGA"] [Tue Aug 18 13:01:19.039654 2026] [security2:error] [pid 139043:tid 139214] [client 68.221.73.131:13810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/aaa.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPUwAAAK4"] [Tue Aug 18 13:01:19.044044 2026] [security2:error] [pid 139043:tid 139228] [client 20.48.236.86:14508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/coffee.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVAAAALw"] [Tue Aug 18 13:01:19.060699 2026] [security2:error] [pid 123784:tid 123905] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/inputs.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFogAAInQ"] [Tue Aug 18 13:01:19.072692 2026] [security2:error] [pid 139043:tid 139179] [client 52.173.121.69:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVgAAAIs"] [Tue Aug 18 13:01:19.123384 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:7194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/an.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPVwAAAJQ"] [Tue Aug 18 13:01:19.209348 2026] [security2:error] [pid 139043:tid 139260] [client 197.184.64.235:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWAAAANw"] [Tue Aug 18 13:01:19.209492 2026] [security2:error] [pid 139043:tid 139260] [client 197.184.64.235:41962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWAAAANw"] [Tue Aug 18 13:01:19.281145 2026] [security2:error] [pid 139043:tid 139200] [client 168.62.48.100:17992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWgAAAKA"] [Tue Aug 18 13:01:19.282844 2026] [security2:error] [pid 123784:tid 123976] [client 196.12.128.158:54294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpAAAADo"] [Tue Aug 18 13:01:19.282975 2026] [security2:error] [pid 123784:tid 123976] [client 196.12.128.158:54294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpAAAADo"] [Tue Aug 18 13:01:19.321653 2026] [security2:error] [pid 139043:tid 139204] [client 20.251.112.238:26122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/moon3.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPWwAAAKQ"] [Tue Aug 18 13:01:19.331346 2026] [security2:error] [pid 123784:tid 123957] [client 20.79.204.6:10378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/info.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpQAAACc"] [Tue Aug 18 13:01:19.435214 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXAAAAKw"] [Tue Aug 18 13:01:19.474470 2026] [security2:error] [pid 139043:tid 139215] [client 20.127.136.245:12169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/x.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXQAAAK8"] [Tue Aug 18 13:01:19.498516 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown [Tue Aug 18 13:01:19.498534 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache [Tue Aug 18 13:01:19.498542 2026] [lsapi:error] [pid 123784:tid 123929] [client 201.32.74.208:56764] [host pensamentosimperfeitos.com.br] Client error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(23018): user_get_body(tmpstackbuf, 16384): read from client failed [Tue Aug 18 13:01:19.541623 2026] [security2:error] [pid 123784:tid 123954] [client 20.79.222.117:17921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/k.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFpwAAACQ"] [Tue Aug 18 13:01:19.547349 2026] [security2:error] [pid 139043:tid 139217] [client 20.104.100.201:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPXwAAALE"] [Tue Aug 18 13:01:19.665255 2026] [security2:error] [pid 139043:tid 139184] [client 20.48.236.86:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPYQAAAJA"] [Tue Aug 18 13:01:19.666399 2026] [security2:error] [pid 139043:tid 139221] [client 20.91.215.254:25846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/nw.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPYgAAALU"] [Tue Aug 18 13:01:19.724821 2026] [security2:error] [pid 123784:tid 124045] [client 20.1.169.243:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFrQAAAH8"] [Tue Aug 18 13:01:19.794739 2026] [security2:error] [pid 123784:tid 123838] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/alfa.php"] [unique_id "aoSBz2wDnJBNj2tDbYYFrwAABTE"] [Tue Aug 18 13:01:19.846738 2026] [security2:error] [pid 139043:tid 139209] [client 20.79.204.6:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSBzf2v-lWn9OzQT7UPOQAAAKk"] [Tue Aug 18 13:01:19.886400 2026] [security2:error] [pid 139043:tid 139250] [client 20.104.100.201:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSBz_2v-lWn9OzQT7UPZgAAANI"] [Tue Aug 18 13:01:20.128161 2026] [security2:error] [pid 123784:tid 123955] [client 168.62.48.100:18079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFsgAAACU"] [Tue Aug 18 13:01:20.188591 2026] [security2:error] [pid 139043:tid 139255] [client 20.104.100.201:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/8.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPbQAAANc"] [Tue Aug 18 13:01:20.348552 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/lock360.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFtQAANhQ"] [Tue Aug 18 13:01:20.454953 2026] [security2:error] [pid 123784:tid 123949] [client 20.102.65.165:8476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvAAAAB8"] [Tue Aug 18 13:01:20.471515 2026] [security2:error] [pid 123784:tid 124004] [client 158.23.17.4:44822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ko.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvQAAAFY"] [Tue Aug 18 13:01:20.558471 2026] [security2:error] [pid 123784:tid 123857] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/flower.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFvwAALEQ"] [Tue Aug 18 13:01:20.618179 2026] [security2:error] [pid 139043:tid 139237] [client 20.65.98.162:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/special.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPcwAAAMU"] [Tue Aug 18 13:01:20.715967 2026] [security2:error] [pid 139043:tid 139225] [client 185.191.171.11:55138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754314111/1756598400/"] [unique_id "aoSB0P2v-lWn9OzQT7UPdQAAALk"] [Tue Aug 18 13:01:20.716083 2026] [security2:error] [pid 139043:tid 139225] [client 185.191.171.11:55138] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754314111/1756598400/"] [unique_id "aoSB0P2v-lWn9OzQT7UPdQAAALk"] [Tue Aug 18 13:01:20.759518 2026] [security2:error] [pid 123784:tid 123913] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/13.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFwQAAT3w"] [Tue Aug 18 13:01:20.769638 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.56.190:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/timeclock.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFxQAAAGI"] [Tue Aug 18 13:01:20.808661 2026] [security2:error] [pid 139043:tid 139224] [client 20.100.169.31:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPdgAAALg"] [Tue Aug 18 13:01:20.837126 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:20.837394 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:20.920733 2026] [security2:error] [pid 139043:tid 139129] [remote 72.167.40.62:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSB0P2v-lWn9OzQT7UPdwAAzFU"] [Tue Aug 18 13:01:20.936362 2026] [security2:error] [pid 123784:tid 123832] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cc.php"] [unique_id "aoSB0GwDnJBNj2tDbYYFxwAAeis"] [Tue Aug 18 13:01:21.113642 2026] [security2:error] [pid 139043:tid 139281] [client 20.65.98.162:24530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/133.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPeAAAAPE"] [Tue Aug 18 13:01:21.123290 2026] [security2:error] [pid 123784:tid 123880] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gecko-new.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFyAAAVFs"] [Tue Aug 18 13:01:21.172162 2026] [security2:error] [pid 123784:tid 123968] [client 20.79.204.6:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/a.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFyQAAADI"] [Tue Aug 18 13:01:21.198865 2026] [autoindex:error] [pid 123784:tid 123986] [client 149.104.78.207:41376] AH01276: Cannot serve directory /home4/lomatel/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://lomatel.com.br/ [Tue Aug 18 13:01:21.274782 2026] [security2:error] [pid 139043:tid 139283] [client 20.104.100.201:49437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/makeasmtp.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPeQAAAPM"] [Tue Aug 18 13:01:21.285201 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:7192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sy.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFywAAAH4"] [Tue Aug 18 13:01:21.300089 2026] [security2:error] [pid 123784:tid 123885] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzAAAcmA"] [Tue Aug 18 13:01:21.363938 2026] [security2:error] [pid 123784:tid 124000] [client 20.102.65.165:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzQAAAFI"] [Tue Aug 18 13:01:21.606108 2026] [security2:error] [pid 139043:tid 139298] [client 20.226.56.190:3017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/email.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPfQAAAQI"] [Tue Aug 18 13:01:21.619192 2026] [security2:error] [pid 123784:tid 123929] [client 20.104.100.201:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/cok.php"] [unique_id "aoSB0WwDnJBNj2tDbYYFzgAAAAs"] [Tue Aug 18 13:01:21.726348 2026] [security2:error] [pid 139043:tid 139180] [client 68.221.73.131:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/FWAZ.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPgAAAAIw"] [Tue Aug 18 13:01:21.850074 2026] [security2:error] [pid 123784:tid 123817] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/01.php"] [unique_id "aoSB0WwDnJBNj2tDbYYF0QAAfxw"] [Tue Aug 18 13:01:21.860699 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/images.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPgwAAALw"] [Tue Aug 18 13:01:21.956140 2026] [security2:error] [pid 123784:tid 123789] [remote 34.176.82.226:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.82.176.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoSBzmwDnJBNj2tDbYYFnwAAWgA"] [Tue Aug 18 13:01:21.958371 2026] [security2:error] [pid 123784:tid 123923] [client 20.104.100.201:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/accesson.php"] [unique_id "aoSB0WwDnJBNj2tDbYYF0gAAAAU"] [Tue Aug 18 13:01:22.040143 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:22.040411 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:22.048866 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhAAAAJQ"] [Tue Aug 18 13:01:22.054621 2026] [security2:error] [pid 123784:tid 123837] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/lv.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2QAAGDA"] [Tue Aug 18 13:01:22.091016 2026] [security2:error] [pid 123784:tid 124024] [client 172.202.39.151:41099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/system_log.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2gAAAGo"] [Tue Aug 18 13:01:22.240972 2026] [security2:error] [pid 123784:tid 123895] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/new.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF2wAAP2o"] [Tue Aug 18 13:01:22.244917 2026] [security2:error] [pid 123784:tid 123960] [client 20.102.65.165:3064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF3AAAACo"] [Tue Aug 18 13:01:22.310940 2026] [security2:error] [pid 139043:tid 139220] [client 20.79.204.6:2384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhgAAALQ"] [Tue Aug 18 13:01:22.311857 2026] [security2:error] [pid 139043:tid 139204] [client 20.104.100.201:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/a.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPhwAAAKQ"] [Tue Aug 18 13:01:22.417549 2026] [security2:error] [pid 139043:tid 139212] [client 20.102.65.165:8460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPiQAAAKw"] [Tue Aug 18 13:01:22.583813 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/chosen.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPjQAAAOs"] [Tue Aug 18 13:01:22.605356 2026] [security2:error] [pid 123784:tid 123952] [client 4.232.94.69:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF3wAAACI"] [Tue Aug 18 13:01:22.610783 2026] [security2:error] [pid 139043:tid 139240] [client 114.119.140.64:27089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "viaduplaseguros.com.br"] [uri "/site/conteudo/61-Seguro_de_Cargas"] [unique_id "aoSB0v2v-lWn9OzQT7UPjwAAAMg"], referer: https://viaduplaseguros.com.br/site/ [Tue Aug 18 13:01:22.632711 2026] [security2:error] [pid 139043:tid 139226] [client 20.65.98.162:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/fz.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPkAAAALo"] [Tue Aug 18 13:01:22.698455 2026] [security2:error] [pid 123784:tid 124022] [client 20.104.100.201:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF4AAAAGg"] [Tue Aug 18 13:01:22.738937 2026] [security2:error] [pid 139043:tid 139297] [client 138.36.100.162:42333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlAAAAQE"] [Tue Aug 18 13:01:22.807085 2026] [security2:error] [pid 123784:tid 123877] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF4QAANlg"] [Tue Aug 18 13:01:22.850247 2026] [security2:error] [pid 139043:tid 139209] [client 172.202.39.151:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlwAAAKk"] [Tue Aug 18 13:01:22.956671 2026] [security2:error] [pid 123784:tid 124004] [client 109.122.18.177:54502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dulaomultimarcas.com.br"] [uri "/.env"] [unique_id "aoSB0mwDnJBNj2tDbYYF4wAAAFY"] [Tue Aug 18 13:01:22.979936 2026] [security2:error] [pid 123784:tid 123874] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSB0mwDnJBNj2tDbYYF5AAAb1U"] [Tue Aug 18 13:01:23.100229 2026] [security2:error] [pid 139043:tid 139258] [client 20.226.56.190:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/profile.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPmgAAANo"] [Tue Aug 18 13:01:23.168763 2026] [security2:error] [pid 123784:tid 123814] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/info.php"] [unique_id "aoSB02wDnJBNj2tDbYYF5QAAGhk"] [Tue Aug 18 13:01:23.171845 2026] [security2:error] [pid 139043:tid 139273] [client 20.250.13.23:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPmwAAAOk"] [Tue Aug 18 13:01:23.328407 2026] [security2:error] [pid 123784:tid 124010] [client 213.35.127.232:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB02wDnJBNj2tDbYYF5wAAAFw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:23.332052 2026] [autoindex:error] [pid 139043:tid 139143] [remote 34.158.8.33:53386] AH01276: Cannot serve directory /home4/adf/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:23.333841 2026] [security2:error] [pid 139043:tid 139208] [client 20.102.65.165:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPngAAAKg"] [Tue Aug 18 13:01:23.348067 2026] [security2:error] [pid 123784:tid 123827] [remote 198.244.183.167:38626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSB02wDnJBNj2tDbYYF6QAAASY"] [Tue Aug 18 13:01:23.348246 2026] [security2:error] [pid 123784:tid 123919] [client 198.244.183.167:38626] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSB02wDnJBNj2tDbYYF6QAAASY"] [Tue Aug 18 13:01:23.458009 2026] [security2:error] [pid 139043:tid 139262] [client 20.48.236.86:14483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPnwAAAN4"] [Tue Aug 18 13:01:23.475378 2026] [security2:error] [pid 139043:tid 139297] [client 138.36.100.162:42333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0v2v-lWn9OzQT7UPlAAAAQE"] [Tue Aug 18 13:01:23.509627 2026] [security2:error] [pid 123784:tid 123984] [client 20.104.100.201:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/99.php"] [unique_id "aoSB02wDnJBNj2tDbYYF7AAAAEI"] [Tue Aug 18 13:01:23.512352 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.9:37070] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:23.512643 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.9:37070] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:23.514546 2026] [security2:error] [pid 139043:tid 139229] [client 20.116.17.175:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPowAAAL0"] [Tue Aug 18 13:01:23.535714 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB02wDnJBNj2tDbYYF7gAADxo"] [Tue Aug 18 13:01:23.581524 2026] [security2:error] [pid 123784:tid 123945] [client 20.118.133.132:25770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/nano.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8QAAABs"] [Tue Aug 18 13:01:23.644857 2026] [security2:error] [pid 123784:tid 123968] [client 52.173.121.69:32512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8gAAADI"] [Tue Aug 18 13:01:23.714431 2026] [security2:error] [pid 123784:tid 123876] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSB02wDnJBNj2tDbYYF8wAAflc"] [Tue Aug 18 13:01:23.808274 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.86:40646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:23.808547 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.86:40646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:23.888818 2026] [security2:error] [pid 139043:tid 139241] [client 20.250.13.23:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqAAAAMk"] [Tue Aug 18 13:01:23.906830 2026] [security2:error] [pid 123784:tid 123831] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/k.php"] [unique_id "aoSB02wDnJBNj2tDbYYF9wAAQyo"] [Tue Aug 18 13:01:23.946990 2026] [security2:error] [pid 123784:tid 123994] [client 20.102.65.165:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/av.php"] [unique_id "aoSB02wDnJBNj2tDbYYF-AAAAEw"] [Tue Aug 18 13:01:23.975677 2026] [security2:error] [pid 139043:tid 139178] [client 86.120.159.145:13729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqQAAAIo"] [Tue Aug 18 13:01:23.975847 2026] [security2:error] [pid 139043:tid 139178] [client 86.120.159.145:13729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqQAAAIo"] [Tue Aug 18 13:01:23.994203 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/57.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPqgAAAKM"] [Tue Aug 18 13:01:24.057660 2026] [security2:error] [pid 123784:tid 124017] [client 20.206.73.37:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/55.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-QAAAGM"] [Tue Aug 18 13:01:24.070819 2026] [security2:error] [pid 123784:tid 124045] [client 20.104.100.201:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/av.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-gAAAH8"] [Tue Aug 18 13:01:24.075267 2026] [security2:error] [pid 123784:tid 124008] [client 20.75.92.165:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/inputs.php"] [unique_id "aoSB1GwDnJBNj2tDbYYF-wAAAFo"] [Tue Aug 18 13:01:24.236267 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.10:60554] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:24.236533 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.10:60554] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:24.278001 2026] [security2:error] [pid 139043:tid 139264] [client 158.23.17.4:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/cv.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPsAAAAOA"] [Tue Aug 18 13:01:24.362983 2026] [security2:error] [pid 139043:tid 139185] [client 20.102.65.165:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPsQAAAJE"] [Tue Aug 18 13:01:24.399799 2026] [security2:error] [pid 139043:tid 139274] [client 20.1.169.243:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSB0f2v-lWn9OzQT7UPegAAAOo"] [Tue Aug 18 13:01:24.502804 2026] [authz_core:error] [pid 139043:tid 139152] [remote 57.141.22.116:48838] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:24.503078 2026] [authz_core:error] [pid 139043:tid 139152] [remote 57.141.22.116:48838] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:24.507594 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:33092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPoAAAALI"] [Tue Aug 18 13:01:24.525312 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:33092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB0_2v-lWn9OzQT7UPoAAAALI"] [Tue Aug 18 13:01:24.528340 2026] [security2:error] [pid 139043:tid 139187] [client 20.65.98.162:27927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPtAAAAJM"] [Tue Aug 18 13:01:24.565760 2026] [security2:error] [pid 123784:tid 124014] [client 157.20.138.62:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAQAAAGA"] [Tue Aug 18 13:01:24.565871 2026] [security2:error] [pid 123784:tid 124014] [client 157.20.138.62:62842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAQAAAGA"] [Tue Aug 18 13:01:24.638656 2026] [security2:error] [pid 123784:tid 123812] [remote 57.141.22.40:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB1GwDnJBNj2tDbYYGAgAAHhc"] [Tue Aug 18 13:01:24.741616 2026] [security2:error] [pid 139043:tid 139260] [client 168.119.53.160:31336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chicodareia.com.br"] [uri "/index.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPqwAAANw"], referer: https://www.chicodareia.com.br/ [Tue Aug 18 13:01:24.741869 2026] [security2:error] [pid 139043:tid 139222] [client 20.79.204.6:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB1P2v-lWn9OzQT7UPtwAAALY"] [Tue Aug 18 13:01:24.782859 2026] [security2:error] [pid 123784:tid 123983] [client 20.127.136.245:10843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGAwAAAEE"] [Tue Aug 18 13:01:24.962227 2026] [security2:error] [pid 123784:tid 124031] [client 20.91.215.254:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lofmebwd.php"] [unique_id "aoSB1GwDnJBNj2tDbYYGBwAAAHE"] [Tue Aug 18 13:01:25.018282 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ah.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCQAAAE4"] [Tue Aug 18 13:01:25.043771 2026] [security2:error] [pid 123784:tid 124009] [client 20.65.98.162:45580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/clque.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCgAAAFs"] [Tue Aug 18 13:01:25.103143 2026] [security2:error] [pid 123784:tid 123988] [client 4.232.94.69:39251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/akc.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGCwAAAEY"] [Tue Aug 18 13:01:25.155386 2026] [security2:error] [pid 123784:tid 123940] [client 20.100.169.31:4954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGDAAAABY"] [Tue Aug 18 13:01:25.313840 2026] [security2:error] [pid 123784:tid 124018] [client 20.48.236.86:14505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mgrr.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGDQAAAGQ"] [Tue Aug 18 13:01:25.537206 2026] [security2:error] [pid 139043:tid 139278] [client 20.116.17.175:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPvQAAAO4"] [Tue Aug 18 13:01:25.682948 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:7200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vw.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGEQAAADI"] [Tue Aug 18 13:01:25.714881 2026] [security2:error] [pid 123784:tid 123841] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/403.php"] [unique_id "aoSB1WwDnJBNj2tDbYYGEgAAIDQ"] [Tue Aug 18 13:01:25.761633 2026] [security2:error] [pid 139043:tid 139262] [client 20.163.43.14:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/flower.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxAAAAN4"] [Tue Aug 18 13:01:25.776022 2026] [security2:error] [pid 139043:tid 139239] [client 20.116.17.175:3437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxQAAAMc"] [Tue Aug 18 13:01:25.840573 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/un.php"] [unique_id "aoSB1f2v-lWn9OzQT7UPxwAAANE"] [Tue Aug 18 13:01:26.040684 2026] [security2:error] [pid 139043:tid 139267] [client 20.102.65.165:8529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/images.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP1QAAAOM"] [Tue Aug 18 13:01:26.109144 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:49104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/kj.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP1wAAALk"] [Tue Aug 18 13:01:26.120407 2026] [security2:error] [pid 123784:tid 123954] [client 52.173.121.69:32521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGGwAAACQ"] [Tue Aug 18 13:01:26.163993 2026] [security2:error] [pid 139043:tid 139277] [client 20.163.43.14:8940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/13.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP2QAAAO0"] [Tue Aug 18 13:01:26.189201 2026] [security2:error] [pid 123784:tid 123944] [client 213.35.127.232:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGHQAAABo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:26.268139 2026] [security2:error] [pid 123784:tid 124017] [client 168.62.48.100:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGHwAAAGM"] [Tue Aug 18 13:01:26.313013 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP3AAAAKM"] [Tue Aug 18 13:01:26.412366 2026] [security2:error] [pid 123784:tid 123931] [client 20.102.65.165:3027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/av.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGIAAAAA0"] [Tue Aug 18 13:01:26.445584 2026] [security2:error] [pid 123784:tid 123969] [client 20.104.100.201:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGIQAAADM"] [Tue Aug 18 13:01:26.495373 2026] [security2:error] [pid 139043:tid 139300] [client 172.202.39.151:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/404.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP4wAAAQQ"] [Tue Aug 18 13:01:26.557334 2026] [security2:error] [pid 139043:tid 139250] [client 20.163.43.14:8834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5QAAANI"] [Tue Aug 18 13:01:26.562438 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:26.562716 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:1124] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:26.587274 2026] [security2:error] [pid 139043:tid 139218] [client 20.127.136.245:23366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/hosty.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP6AAAALI"] [Tue Aug 18 13:01:26.613328 2026] [security2:error] [pid 139043:tid 139289] [client 103.184.169.37:43115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5wAAAPk"] [Tue Aug 18 13:01:26.613479 2026] [security2:error] [pid 139043:tid 139289] [client 103.184.169.37:43115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP5wAAAPk"] [Tue Aug 18 13:01:26.736800 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7AAAAMI"] [Tue Aug 18 13:01:26.788089 2026] [security2:error] [pid 139043:tid 139233] [client 216.244.66.232:49954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7QAAAME"] [Tue Aug 18 13:01:26.788223 2026] [security2:error] [pid 139043:tid 139233] [client 216.244.66.232:49954] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP7QAAAME"] [Tue Aug 18 13:01:26.841705 2026] [security2:error] [pid 123784:tid 123978] [client 20.65.98.162:45573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/nano.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKAAAADw"] [Tue Aug 18 13:01:26.968963 2026] [security2:error] [pid 123784:tid 123918] [client 172.202.39.151:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/o.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKQAAAAA"] [Tue Aug 18 13:01:26.992396 2026] [security2:error] [pid 123784:tid 123804] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/gecko.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGKwAAIg8"] [Tue Aug 18 13:01:26.997266 2026] [security2:error] [pid 123784:tid 123943] [client 20.65.98.162:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/mosty.php"] [unique_id "aoSB1mwDnJBNj2tDbYYGLAAAABk"] [Tue Aug 18 13:01:26.997384 2026] [security2:error] [pid 139043:tid 139069] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env"] [unique_id "aoSB1v2v-lWn9OzQT7UP8QAApBk"] [Tue Aug 18 13:01:26.997740 2026] [security2:error] [pid 139043:tid 139073] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.backup"] [unique_id "aoSB1v2v-lWn9OzQT7UP9QAApB0"] [Tue Aug 18 13:01:27.033590 2026] [security2:error] [pid 139043:tid 139290] [client 20.91.215.254:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSB1_2v-lWn9OzQT7UP_QAAAPo"] [Tue Aug 18 13:01:27.036443 2026] [security2:error] [pid 123784:tid 124015] [client 20.102.65.165:3055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/images.php"] [unique_id "aoSB12wDnJBNj2tDbYYGLQAAAGE"] [Tue Aug 18 13:01:27.125591 2026] [security2:error] [pid 139043:tid 139272] [client 20.226.56.190:31664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/summary.php"] [unique_id "aoSB1_2v-lWn9OzQT7UP_wAAAOg"] [Tue Aug 18 13:01:27.184500 2026] [security2:error] [pid 123784:tid 123946] [client 20.48.236.86:14839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/55.php"] [unique_id "aoSB12wDnJBNj2tDbYYGNgAAABw"] [Tue Aug 18 13:01:27.194627 2026] [security2:error] [pid 139043:tid 139230] [client 20.102.65.165:8526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/ops.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQAgAAAL4"] [Tue Aug 18 13:01:27.234369 2026] [autoindex:error] [pid 123784:tid 124004] [client 169.58.72.248:62363] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:27.236395 2026] [security2:error] [pid 139043:tid 139202] [client 20.75.92.165:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/100.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQAwAAAKI"] [Tue Aug 18 13:01:27.260771 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:55223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/evil.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBAAAAKA"] [Tue Aug 18 13:01:27.305436 2026] [security2:error] [pid 139043:tid 139231] [client 20.116.17.175:22967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBgAAAL8"] [Tue Aug 18 13:01:27.336601 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lj.php"] [unique_id "aoSB12wDnJBNj2tDbYYGOgAAAAc"] [Tue Aug 18 13:01:27.372104 2026] [security2:error] [pid 123784:tid 123865] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSB12wDnJBNj2tDbYYGOwAAW0w"] [Tue Aug 18 13:01:27.390152 2026] [security2:error] [pid 123784:tid 123988] [client 20.79.222.117:17948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/82.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPAAAAEY"] [Tue Aug 18 13:01:27.394953 2026] [security2:error] [pid 139043:tid 139258] [client 20.1.169.243:5770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/goat1.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQBwAAANo"] [Tue Aug 18 13:01:27.451528 2026] [security2:error] [pid 123784:tid 124003] [client 5.31.227.224:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPQAAAFU"] [Tue Aug 18 13:01:27.451665 2026] [security2:error] [pid 123784:tid 124003] [client 5.31.227.224:59066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPQAAAFU"] [Tue Aug 18 13:01:27.540487 2026] [security2:error] [pid 123784:tid 123997] [client 20.250.27.191:28016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/indexo.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPgAAAE8"] [Tue Aug 18 13:01:27.555179 2026] [security2:error] [pid 123784:tid 123850] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/0x.php"] [unique_id "aoSB12wDnJBNj2tDbYYGPwAAZD0"] [Tue Aug 18 13:01:27.568242 2026] [security2:error] [pid 123784:tid 124020] [client 20.102.65.165:3070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ops.php"] [unique_id "aoSB12wDnJBNj2tDbYYGQAAAAGY"] [Tue Aug 18 13:01:27.585097 2026] [security2:error] [pid 139043:tid 139226] [client 20.102.65.165:8223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/domvf.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCgAAALo"] [Tue Aug 18 13:01:27.614893 2026] [security2:error] [pid 139043:tid 139082] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCwAAzCY"] [Tue Aug 18 13:01:27.614954 2026] [security2:error] [pid 139043:tid 139082] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQCwAAzCY"] [Tue Aug 18 13:01:27.718542 2026] [security2:error] [pid 139043:tid 139295] [client 168.62.48.100:18110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQDAAAAP8"] [Tue Aug 18 13:01:27.784503 2026] [security2:error] [pid 123784:tid 124013] [client 158.23.17.4:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pw.php"] [unique_id "aoSB12wDnJBNj2tDbYYGRgAAAF8"] [Tue Aug 18 13:01:27.820911 2026] [autoindex:error] [pid 139043:tid 139245] [client 82.102.18.182:37508] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:27.841074 2026] [security2:error] [pid 139043:tid 139065] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.bak"] [unique_id "aoSB1_2v-lWn9OzQT7UQGwAA3hU"] [Tue Aug 18 13:01:27.841152 2026] [security2:error] [pid 139043:tid 139088] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.env.old"] [unique_id "aoSB1_2v-lWn9OzQT7UQFgAA3iw"] [Tue Aug 18 13:01:27.937055 2026] [security2:error] [pid 123784:tid 123939] [client 158.23.17.4:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kh.php"] [unique_id "aoSB12wDnJBNj2tDbYYGSQAAABU"] [Tue Aug 18 13:01:27.939990 2026] [security2:error] [pid 123784:tid 123911] [remote 54.39.210.30:16006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/"] [unique_id "aoSB12wDnJBNj2tDbYYGSgAAe3o"] [Tue Aug 18 13:01:27.940177 2026] [security2:error] [pid 123784:tid 124041] [client 54.39.210.30:16006] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sergiopontesadvocacia.com.br"] [uri "/"] [unique_id "aoSB12wDnJBNj2tDbYYGSgAAe3o"] [Tue Aug 18 13:01:27.953346 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/vx.php"] [unique_id "aoSB12wDnJBNj2tDbYYGSwAAAAU"] [Tue Aug 18 13:01:27.968587 2026] [security2:error] [pid 123784:tid 123936] [client 172.202.39.151:44517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/bb.php"] [unique_id "aoSB12wDnJBNj2tDbYYGTAAAABI"] [Tue Aug 18 13:01:27.974120 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.222.117:18032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/dex.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHgAAAL0"] [Tue Aug 18 13:01:28.022230 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.27.191:45761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQIQAAAQE"] [Tue Aug 18 13:01:28.082791 2026] [security2:error] [pid 139043:tid 139223] [client 168.62.48.100:18119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQIwAAALc"] [Tue Aug 18 13:01:28.088027 2026] [security2:error] [pid 123784:tid 123799] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/zxz.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGUAAAWQo"] [Tue Aug 18 13:01:28.245099 2026] [security2:error] [pid 123784:tid 123955] [client 114.119.133.236:46681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/index.php/netvasco%2Bmobile-1/"] [unique_id "aoSB2GwDnJBNj2tDbYYGUgAAACU"], referer: http://cdlpinheiros.com.br/janaina%2Bsantos%2Bgata%2Bpop-3/ [Tue Aug 18 13:01:28.260340 2026] [security2:error] [pid 139043:tid 139293] [client 20.250.13.23:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/abc.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQJQAAAP0"] [Tue Aug 18 13:01:28.300280 2026] [security2:error] [pid 139043:tid 139107] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/api/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQKgAAvD8"] [Tue Aug 18 13:01:28.300283 2026] [security2:error] [pid 139043:tid 139105] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/backend/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQKAAAvD0"] [Tue Aug 18 13:01:28.363259 2026] [security2:error] [pid 139043:tid 139261] [client 20.91.215.254:11631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQLAAAAN0"] [Tue Aug 18 13:01:28.427580 2026] [security2:error] [pid 123784:tid 124011] [client 20.48.236.86:14494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ajax.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGUwAAAF0"] [Tue Aug 18 13:01:28.451587 2026] [security2:error] [pid 123784:tid 124010] [client 4.232.94.69:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/flower.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVAAAAFw"] [Tue Aug 18 13:01:28.640921 2026] [security2:error] [pid 123784:tid 123999] [client 20.118.133.132:13708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "agrimotor.com.br"] [uri "/.mopj.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVgAAAFE"] [Tue Aug 18 13:01:28.646646 2026] [security2:error] [pid 123784:tid 123901] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/www.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGVwAAPXA"] [Tue Aug 18 13:01:28.680323 2026] [security2:error] [pid 139043:tid 139099] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/config/.env"] [unique_id "aoSB2P2v-lWn9OzQT7UQMgAAozc"] [Tue Aug 18 13:01:28.787643 2026] [security2:error] [pid 123784:tid 124024] [client 158.23.17.4:9384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ke.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWAAAAGo"] [Tue Aug 18 13:01:28.789682 2026] [security2:error] [pid 123784:tid 123921] [client 20.75.92.165:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/akc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWQAAAAM"] [Tue Aug 18 13:01:28.802486 2026] [security2:error] [pid 139043:tid 139183] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSB1v2v-lWn9OzQT7UP4gAAjws"], referer: https://tecpolorefrigeracao.com.br/ [Tue Aug 18 13:01:28.829994 2026] [security2:error] [pid 123784:tid 123892] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wicked.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGWgAAVGc"] [Tue Aug 18 13:01:28.842800 2026] [security2:error] [pid 139043:tid 139201] [client 20.151.109.219:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/f.php"] [unique_id "aoSB2P2v-lWn9OzQT7UQNQAAAKE"] [Tue Aug 18 13:01:28.910618 2026] [security2:error] [pid 139043:tid 139212] [client 102.213.179.104:50209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHQAAAKw"] [Tue Aug 18 13:01:28.910754 2026] [security2:error] [pid 139043:tid 139212] [client 102.213.179.104:50209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB1_2v-lWn9OzQT7UQHQAAAKw"] [Tue Aug 18 13:01:28.957637 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:28.957856 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:28.957894 2026] [authz_core:error] [pid 123784:tid 123808] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:28.958101 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:28.975118 2026] [security2:error] [pid 123784:tid 123987] [client 20.102.65.165:8479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/coffexium.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGXwAAAEU"] [Tue Aug 18 13:01:29.018050 2026] [security2:error] [pid 123784:tid 123816] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYAAAKhs"] [Tue Aug 18 13:01:29.052990 2026] [security2:error] [pid 123784:tid 123956] [client 20.1.169.243:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYQAAACY"] [Tue Aug 18 13:01:29.087473 2026] [security2:error] [pid 123784:tid 123978] [client 158.23.17.4:47931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fn.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGYgAAADw"] [Tue Aug 18 13:01:29.106841 2026] [security2:error] [pid 139043:tid 139259] [client 20.91.215.254:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/f7.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPAAAANs"] [Tue Aug 18 13:01:29.123128 2026] [security2:error] [pid 123784:tid 124035] [client 196.12.128.158:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGTwAAAHU"] [Tue Aug 18 13:01:29.127454 2026] [security2:error] [pid 139043:tid 139186] [client 4.232.151.198:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/inputs.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPQAAAJI"] [Tue Aug 18 13:01:29.183031 2026] [security2:error] [pid 123784:tid 124035] [client 196.12.128.158:55045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB2GwDnJBNj2tDbYYGTwAAAHU"] [Tue Aug 18 13:01:29.186874 2026] [security2:error] [pid 139043:tid 139179] [client 172.202.39.151:44538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQPwAAAIs"] [Tue Aug 18 13:01:29.271639 2026] [security2:error] [pid 123784:tid 123943] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZAAAGXc"] [Tue Aug 18 13:01:29.405363 2026] [security2:error] [pid 123784:tid 123935] [client 20.38.3.247:32593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/82.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZQAAABE"] [Tue Aug 18 13:01:29.449027 2026] [autoindex:error] [pid 139043:tid 139139] [remote 34.31.203.120:2496] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:29.462760 2026] [security2:error] [pid 123784:tid 124016] [client 20.79.222.117:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/puc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGZgAAAGI"] [Tue Aug 18 13:01:29.614420 2026] [security2:error] [pid 123784:tid 124022] [client 223.185.37.47:31056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGaAAAAGg"] [Tue Aug 18 13:01:29.614541 2026] [security2:error] [pid 123784:tid 124022] [client 223.185.37.47:31056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB2WwDnJBNj2tDbYYGaAAAAGg"] [Tue Aug 18 13:01:29.638401 2026] [security2:error] [pid 139043:tid 139230] [client 68.221.73.131:38499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/site.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQWgAAAL4"] [Tue Aug 18 13:01:29.662323 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/30.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQXAAAAJ0"] [Tue Aug 18 13:01:29.850056 2026] [security2:error] [pid 139043:tid 139217] [client 168.62.48.100:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQXwAAALE"] [Tue Aug 18 13:01:29.891469 2026] [security2:error] [pid 139043:tid 139244] [client 20.206.73.37:29961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ajax.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYQAAAMw"] [Tue Aug 18 13:01:29.924189 2026] [security2:error] [pid 139043:tid 139227] [client 20.79.222.117:18038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/inso.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYgAAALs"] [Tue Aug 18 13:01:29.927204 2026] [security2:error] [pid 139043:tid 139295] [client 20.79.204.6:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wap.php"] [unique_id "aoSB2f2v-lWn9OzQT7UQYwAAAP8"] [Tue Aug 18 13:01:29.958962 2026] [security2:error] [pid 139043:tid 139131] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.github/.env"] [unique_id "aoSB2f2v-lWn9OzQT7UQZwAA8Fc"] [Tue Aug 18 13:01:30.006934 2026] [security2:error] [pid 139043:tid 139260] [client 20.1.169.243:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/h.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQawAAANw"] [Tue Aug 18 13:01:30.024955 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:14122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pu.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGbQAAAGY"] [Tue Aug 18 13:01:30.077213 2026] [security2:error] [pid 139043:tid 139237] [client 20.104.100.201:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/png.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQbQAAAMU"] [Tue Aug 18 13:01:30.147410 2026] [security2:error] [pid 123784:tid 123855] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGcAAAdEI"] [Tue Aug 18 13:01:30.148039 2026] [security2:error] [pid 139043:tid 139268] [client 172.202.39.151:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-login.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQcgAAAOQ"] [Tue Aug 18 13:01:30.159433 2026] [security2:error] [pid 139043:tid 139198] [client 20.250.27.191:3612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQcwAAAJ4"] [Tue Aug 18 13:01:30.161793 2026] [security2:error] [pid 123784:tid 123968] [client 20.65.98.162:31089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/blurbs.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGcgAAADI"] [Tue Aug 18 13:01:30.262363 2026] [security2:error] [pid 139043:tid 139243] [client 20.65.98.162:56473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "lavobotafogo.com"] [uri "/.mopj.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQdgAAAMs"] [Tue Aug 18 13:01:30.292412 2026] [security2:error] [pid 139043:tid 139224] [client 20.80.111.3:17824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/as.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQeQAAALg"] [Tue Aug 18 13:01:30.300329 2026] [security2:error] [pid 123784:tid 124045] [client 20.250.13.23:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/sf.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdAAAAH8"] [Tue Aug 18 13:01:30.323255 2026] [security2:error] [pid 123784:tid 123888] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cah.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdQAAFWM"] [Tue Aug 18 13:01:30.369710 2026] [security2:error] [pid 139043:tid 139240] [client 109.122.18.177:54662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dulaomultimarcas.com.br"] [uri "/"] [unique_id "aoSB2v2v-lWn9OzQT7UQjAAAAMg"] [Tue Aug 18 13:01:30.383173 2026] [security2:error] [pid 123784:tid 123998] [client 20.151.109.219:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ry.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGdwAAAFA"] [Tue Aug 18 13:01:30.403538 2026] [security2:error] [pid 139043:tid 139251] [client 20.1.169.243:5799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/import/csv1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQjwAAANM"] [Tue Aug 18 13:01:30.435432 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ab.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQkgAAAJE"] [Tue Aug 18 13:01:30.441025 2026] [security2:error] [pid 139043:tid 139186] [client 158.23.17.4:29468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nh.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQkwAAAJI"] [Tue Aug 18 13:01:30.533019 2026] [security2:error] [pid 123784:tid 123961] [client 213.35.127.232:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGewAAACs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:30.563187 2026] [security2:error] [pid 139043:tid 139238] [client 20.127.136.245:1526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/test1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQuQAAAMY"] [Tue Aug 18 13:01:30.570714 2026] [security2:error] [pid 123784:tid 123994] [client 20.250.27.191:43478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/.admin.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGfAAAAEw"] [Tue Aug 18 13:01:30.574878 2026] [security2:error] [pid 123784:tid 124011] [client 20.75.92.165:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGfQAAAF0"] [Tue Aug 18 13:01:30.583699 2026] [security2:error] [pid 139043:tid 139211] [client 20.102.65.165:8548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/BDKR28WP.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQugAAAKs"] [Tue Aug 18 13:01:30.593800 2026] [security2:error] [pid 139043:tid 139191] [client 20.80.111.3:31037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atex1.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQuwAAAJc"] [Tue Aug 18 13:01:30.636186 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:30.636459 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:30.649732 2026] [security2:error] [pid 123784:tid 123887] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/system_log.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGgQAAfGI"] [Tue Aug 18 13:01:30.660026 2026] [security2:error] [pid 139043:tid 139247] [client 45.92.229.105:50133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/profile.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQlAAAAM8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:01:30.669296 2026] [security2:error] [pid 139043:tid 139197] [client 135.225.78.186:11747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQwQAAAJ0"] [Tue Aug 18 13:01:30.688852 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pm.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQzgAAAKA"] [Tue Aug 18 13:01:30.711537 2026] [security2:error] [pid 139043:tid 139258] [client 20.104.100.201:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/12.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQzwAAANo"] [Tue Aug 18 13:01:30.713453 2026] [authz_core:error] [pid 139043:tid 139127] [remote 34.158.8.33:53386] AH01630: client denied by server configuration: /home4/adf/public_html/.htpasswd [Tue Aug 18 13:01:30.745011 2026] [security2:error] [pid 123784:tid 123955] [client 20.91.215.254:11619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/photo.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGjAAAACU"] [Tue Aug 18 13:01:30.769088 2026] [security2:error] [pid 139043:tid 139286] [client 20.1.169.243:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/index.bak.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ1QAAAPY"] [Tue Aug 18 13:01:30.860438 2026] [security2:error] [pid 123784:tid 124001] [client 158.23.17.4:9297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/oo.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGkwAAAFM"] [Tue Aug 18 13:01:30.883599 2026] [security2:error] [pid 139043:tid 139297] [client 20.186.30.159:9993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ2QAAAQE"] [Tue Aug 18 13:01:30.903106 2026] [security2:error] [pid 123784:tid 123981] [client 20.75.92.165:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/php.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGmQAAAD8"] [Tue Aug 18 13:01:30.905158 2026] [security2:error] [pid 139043:tid 139136] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3QAA_Vw"] [Tue Aug 18 13:01:30.907176 2026] [security2:error] [pid 139043:tid 139198] [client 109.122.18.177:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dulaomultimarcas.com.br"] [uri "/"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3gAAAJ4"] [Tue Aug 18 13:01:30.911055 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yup.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ3wAAALw"] [Tue Aug 18 13:01:30.914328 2026] [security2:error] [pid 123784:tid 124043] [client 185.198.240.186:20235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riobrancoconsultorios.com.br"] [uri "/wp-login.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGmwAAAH0"] [Tue Aug 18 13:01:30.925676 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.56.190:17871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/conf.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQ4AAAAIg"] [Tue Aug 18 13:01:30.925895 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.13.23:55970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/chosen.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGnwAAAGo"] [Tue Aug 18 13:01:30.975107 2026] [security2:error] [pid 123784:tid 123789] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGogAAbgA"] [Tue Aug 18 13:01:30.986252 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/x1da.php"] [unique_id "aoSB2mwDnJBNj2tDbYYGowAAAEE"] [Tue Aug 18 13:01:31.009137 2026] [security2:error] [pid 139043:tid 139281] [client 20.102.65.165:3020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/coffexium.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ5AAAAPE"] [Tue Aug 18 13:01:31.020096 2026] [security2:error] [pid 123784:tid 123946] [client 20.250.27.191:45794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/wsomini.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpQAAABw"] [Tue Aug 18 13:01:31.022583 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:31.023017 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:31.023333 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kf.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpgAAAD4"] [Tue Aug 18 13:01:31.038007 2026] [security2:error] [pid 139043:tid 139178] [client 20.80.111.3:3639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atomlib.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ5wAAAIo"] [Tue Aug 18 13:01:31.051983 2026] [security2:error] [pid 123784:tid 124029] [client 20.116.17.175:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/cok.php"] [unique_id "aoSB22wDnJBNj2tDbYYGpwAAAG8"] [Tue Aug 18 13:01:31.054759 2026] [security2:error] [pid 123784:tid 124023] [client 20.151.109.219:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dr.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqAAAAGk"] [Tue Aug 18 13:01:31.079835 2026] [security2:error] [pid 139043:tid 139255] [client 172.202.39.151:4679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6AAAANc"] [Tue Aug 18 13:01:31.082939 2026] [security2:error] [pid 139043:tid 139106] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/0x.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6QABAD4"] [Tue Aug 18 13:01:31.109681 2026] [security2:error] [pid 123784:tid 123947] [client 68.221.73.131:35119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/ccc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqQAAAB0"] [Tue Aug 18 13:01:31.122022 2026] [security2:error] [pid 139043:tid 139215] [client 20.79.204.6:10690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ6wAAAK8"] [Tue Aug 18 13:01:31.132748 2026] [security2:error] [pid 123784:tid 123971] [client 20.1.169.243:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/lite.php"] [unique_id "aoSB22wDnJBNj2tDbYYGqgAAADU"] [Tue Aug 18 13:01:31.143310 2026] [security2:error] [pid 139043:tid 139259] [client 213.202.253.4:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/txets.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ7AAAANs"], referer: www.google.com [Tue Aug 18 13:01:31.148647 2026] [security2:error] [pid 123784:tid 123867] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB22wDnJBNj2tDbYYGrAAADU4"] [Tue Aug 18 13:01:31.197157 2026] [autoindex:error] [pid 123784:tid 124009] [client 169.58.72.248:62363] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:31.204329 2026] [security2:error] [pid 139043:tid 139189] [client 20.104.100.201:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/222.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8AAAAJU"] [Tue Aug 18 13:01:31.213647 2026] [security2:error] [pid 123784:tid 123984] [client 20.186.30.159:9998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB22wDnJBNj2tDbYYGrwAAAEI"] [Tue Aug 18 13:01:31.245281 2026] [security2:error] [pid 139043:tid 139246] [client 20.127.136.245:3869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/zwso.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8QAAAM4"] [Tue Aug 18 13:01:31.256883 2026] [security2:error] [pid 139043:tid 139133] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8gAAx1k"] [Tue Aug 18 13:01:31.264575 2026] [security2:error] [pid 123784:tid 124033] [client 86.120.159.145:52786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGsAAAAHM"] [Tue Aug 18 13:01:31.264772 2026] [security2:error] [pid 123784:tid 124033] [client 86.120.159.145:52786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGsAAAAHM"] [Tue Aug 18 13:01:31.272024 2026] [security2:error] [pid 139043:tid 139177] [client 20.104.100.201:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mcs.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ8wAAAIk"] [Tue Aug 18 13:01:31.305280 2026] [security2:error] [pid 123784:tid 123803] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/abc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGtQAAXg4"] [Tue Aug 18 13:01:31.329607 2026] [security2:error] [pid 139043:tid 139243] [client 20.79.204.6:2206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ9QAAAMs"] [Tue Aug 18 13:01:31.351843 2026] [security2:error] [pid 123784:tid 124041] [client 20.151.109.219:14136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ts.php"] [unique_id "aoSB22wDnJBNj2tDbYYGtgAAAHs"] [Tue Aug 18 13:01:31.382235 2026] [security2:error] [pid 139043:tid 139258] [client 20.79.222.117:18027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/aa.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ-QAAANo"] [Tue Aug 18 13:01:31.402374 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_AAAALY"] [Tue Aug 18 13:01:31.426384 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:54747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/su.php"] [unique_id "aoSB22wDnJBNj2tDbYYGuQAAAFk"] [Tue Aug 18 13:01:31.435569 2026] [security2:error] [pid 139043:tid 139188] [client 20.250.27.191:34842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.forzamotor.com.br"] [uri "/vr.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_QAAAJQ"] [Tue Aug 18 13:01:31.436061 2026] [security2:error] [pid 139043:tid 139138] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSB2_2v-lWn9OzQT7UQ_gAAzF4"] [Tue Aug 18 13:01:31.436683 2026] [security2:error] [pid 123784:tid 123945] [client 20.91.215.254:11647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-aa.php"] [unique_id "aoSB22wDnJBNj2tDbYYGugAAABs"] [Tue Aug 18 13:01:31.451594 2026] [security2:error] [pid 123784:tid 123970] [client 20.226.112.14:28746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvAAAADQ"] [Tue Aug 18 13:01:31.460074 2026] [security2:error] [pid 123784:tid 123929] [client 20.75.92.165:4340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/t.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvQAAAAs"] [Tue Aug 18 13:01:31.472935 2026] [security2:error] [pid 123784:tid 123814] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/akcc.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvwAAKxk"] [Tue Aug 18 13:01:31.472988 2026] [security2:error] [pid 123784:tid 123954] [client 20.102.65.165:8569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/sf.php"] [unique_id "aoSB22wDnJBNj2tDbYYGvgAAACQ"] [Tue Aug 18 13:01:31.473540 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ja.php"] [unique_id "aoSB22wDnJBNj2tDbYYGwAAAAEw"] [Tue Aug 18 13:01:31.477063 2026] [security2:error] [pid 123784:tid 124045] [client 20.80.111.3:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/black.php"] [unique_id "aoSB22wDnJBNj2tDbYYGwQAAAH8"] [Tue Aug 18 13:01:31.497746 2026] [security2:error] [pid 139043:tid 139283] [client 20.1.169.243:5783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/live.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAAAAAPM"] [Tue Aug 18 13:01:31.508080 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:34757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-temp.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAQAAAP8"] [Tue Aug 18 13:01:31.515906 2026] [security2:error] [pid 139043:tid 139173] [client 20.116.17.175:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/accesson.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAgAAAIU"] [Tue Aug 18 13:01:31.533258 2026] [security2:error] [pid 123784:tid 123974] [client 20.102.65.165:3016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxAAAADg"] [Tue Aug 18 13:01:31.540183 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jb.php"] [unique_id "aoSB2_2v-lWn9OzQT7URBQAAAKY"] [Tue Aug 18 13:01:31.547358 2026] [security2:error] [pid 139043:tid 139276] [client 20.104.100.201:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/adminner.php"] [unique_id "aoSB2_2v-lWn9OzQT7URBwAAAOw"] [Tue Aug 18 13:01:31.548157 2026] [security2:error] [pid 123784:tid 123972] [client 213.35.127.232:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxQAAADY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:31.561895 2026] [security2:error] [pid 139043:tid 139294] [client 20.250.13.23:55942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/u.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCQAAAP4"] [Tue Aug 18 13:01:31.565845 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:31.566277 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:31.568785 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:22877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCgAAAM0"] [Tue Aug 18 13:01:31.576806 2026] [security2:error] [pid 139043:tid 139140] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCwAAl2A"] [Tue Aug 18 13:01:31.576993 2026] [security2:error] [pid 139043:tid 139191] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB2_2v-lWn9OzQT7URCwAAl2A"] [Tue Aug 18 13:01:31.614079 2026] [security2:error] [pid 139043:tid 139131] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/abcd.php"] [unique_id "aoSB2_2v-lWn9OzQT7URDQAAw1c"] [Tue Aug 18 13:01:31.637540 2026] [security2:error] [pid 123784:tid 123796] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wk/index.php"] [unique_id "aoSB22wDnJBNj2tDbYYGxwAAPQc"] [Tue Aug 18 13:01:31.648508 2026] [security2:error] [pid 123784:tid 124002] [client 168.62.48.100:18025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSB22wDnJBNj2tDbYYGyAAAAFQ"] [Tue Aug 18 13:01:31.700570 2026] [security2:error] [pid 139043:tid 139219] [client 20.151.109.219:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/53.php"] [unique_id "aoSB2_2v-lWn9OzQT7UREQAAALM"] [Tue Aug 18 13:01:31.706290 2026] [security2:error] [pid 139043:tid 139154] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSB2_2v-lWn9OzQT7UREgAA5W4"] [Tue Aug 18 13:01:31.757043 2026] [security2:error] [pid 139043:tid 139224] [client 20.186.30.159:10079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB2_2v-lWn9OzQT7URFAAAALg"] [Tue Aug 18 13:01:31.791104 2026] [security2:error] [pid 139043:tid 139155] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSB2_2v-lWn9OzQT7URFQAA8W8"] [Tue Aug 18 13:01:31.797989 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSB22wDnJBNj2tDbYYGywAAGTw"] [Tue Aug 18 13:01:31.798069 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSB22wDnJBNj2tDbYYGywAAGTw"] [Tue Aug 18 13:01:31.805194 2026] [security2:error] [pid 139043:tid 139214] [client 74.7.228.13:41454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.innacorp.com.br"] [uri "/site/index.php"] [unique_id "aoSB2v2v-lWn9OzQT7UQagAArnE"] [Tue Aug 18 13:01:31.810434 2026] [security2:error] [pid 123784:tid 123876] [remote 47.128.31.181:18016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSB22wDnJBNj2tDbYYGzAAAP1c"] [Tue Aug 18 13:01:31.814641 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wp-key.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzQAAAH0"] [Tue Aug 18 13:01:31.823743 2026] [security2:error] [pid 123784:tid 124015] [client 20.104.100.201:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dragonshell.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzgAAAGE"] [Tue Aug 18 13:01:31.824967 2026] [security2:error] [pid 123784:tid 123948] [client 20.79.222.117:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/img.php"] [unique_id "aoSB22wDnJBNj2tDbYYGzwAAAB4"] [Tue Aug 18 13:01:31.836837 2026] [security2:error] [pid 139043:tid 139201] [client 20.104.100.201:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/spadex.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGAAAAKE"] [Tue Aug 18 13:01:31.847912 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:31.848188 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:31.858289 2026] [security2:error] [pid 123784:tid 123977] [client 20.65.98.162:27962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/bajah.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0QAAADs"] [Tue Aug 18 13:01:31.861968 2026] [security2:error] [pid 123784:tid 123989] [client 4.232.151.198:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/admin.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0gAAAEc"] [Tue Aug 18 13:01:31.862098 2026] [security2:error] [pid 139043:tid 139227] [client 20.1.169.243:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/bypass.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGgAAALs"] [Tue Aug 18 13:01:31.871156 2026] [security2:error] [pid 139043:tid 139251] [client 20.226.112.14:32516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws61.php"] [unique_id "aoSB2_2v-lWn9OzQT7URGwAAANM"] [Tue Aug 18 13:01:31.876603 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/Geforce.php"] [unique_id "aoSB22wDnJBNj2tDbYYG0wAAACg"] [Tue Aug 18 13:01:31.883520 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:10382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bgymj.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHQAAAL0"] [Tue Aug 18 13:01:31.912574 2026] [security2:error] [pid 123784:tid 124006] [client 20.80.111.3:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bs1.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1AAAAFg"] [Tue Aug 18 13:01:31.913983 2026] [security2:error] [pid 139043:tid 139240] [client 168.62.48.100:18105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHgAAAMg"] [Tue Aug 18 13:01:31.916374 2026] [security2:error] [pid 139043:tid 139232] [client 20.119.58.187:10533] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tinoequipamentos.com.br"] [uri "/1.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHwAAAMA"] [Tue Aug 18 13:01:31.916489 2026] [security2:error] [pid 139043:tid 139232] [client 20.119.58.187:10533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/1.php"] [unique_id "aoSB2_2v-lWn9OzQT7URHwAAAMA"] [Tue Aug 18 13:01:31.952782 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:2627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1gAAAHU"] [Tue Aug 18 13:01:31.969785 2026] [security2:error] [pid 123784:tid 123893] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSB22wDnJBNj2tDbYYG1wAAH2g"] [Tue Aug 18 13:01:31.971130 2026] [security2:error] [pid 123784:tid 124039] [client 158.23.17.4:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/do.php"] [unique_id "aoSB22wDnJBNj2tDbYYG2AAAAHk"] [Tue Aug 18 13:01:32.015549 2026] [security2:error] [pid 139043:tid 139189] [client 20.75.92.165:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/index/function.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJAAAAJU"] [Tue Aug 18 13:01:32.032110 2026] [security2:error] [pid 123784:tid 124029] [client 20.102.65.165:3032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/sf.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG2gAAAG8"] [Tue Aug 18 13:01:32.033346 2026] [security2:error] [pid 123784:tid 124030] [client 20.119.58.187:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/2.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG2wAAAHA"] [Tue Aug 18 13:01:32.034207 2026] [security2:error] [pid 123784:tid 124023] [client 158.23.17.4:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xx.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3AAAAGk"] [Tue Aug 18 13:01:32.051928 2026] [security2:error] [pid 139043:tid 139239] [client 20.226.112.14:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/rum.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJQAAAMc"] [Tue Aug 18 13:01:32.054715 2026] [security2:error] [pid 139043:tid 139204] [client 20.102.65.165:8555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/k.php"] [unique_id "aoSB3P2v-lWn9OzQT7URJgAAAKQ"] [Tue Aug 18 13:01:32.078994 2026] [security2:error] [pid 123784:tid 123971] [client 20.151.109.219:60925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lq.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3gAAADU"] [Tue Aug 18 13:01:32.086476 2026] [security2:error] [pid 123784:tid 123920] [client 20.91.215.254:11629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/d.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG3wAAAAI"] [Tue Aug 18 13:01:32.097696 2026] [security2:error] [pid 123784:tid 123999] [client 20.104.100.201:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/setup-config.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG4AAAAFE"] [Tue Aug 18 13:01:32.117904 2026] [security2:error] [pid 139043:tid 139220] [client 68.221.73.131:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/admin.php"] [unique_id "aoSB3P2v-lWn9OzQT7URKAAAALQ"] [Tue Aug 18 13:01:32.134483 2026] [security2:error] [pid 123784:tid 123869] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG4gAAVVA"] [Tue Aug 18 13:01:32.139749 2026] [security2:error] [pid 139043:tid 139164] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSB3P2v-lWn9OzQT7URKQAA6Hg"] [Tue Aug 18 13:01:32.140271 2026] [security2:error] [pid 139043:tid 139256] [client 20.104.100.201:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URKgAAANg"] [Tue Aug 18 13:01:32.152892 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/yj09.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG5QAAAEU"] [Tue Aug 18 13:01:32.154140 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:32.154397 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:32.215466 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.112.14:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ze.php"] [unique_id "aoSB3P2v-lWn9OzQT7URLQAAAJk"] [Tue Aug 18 13:01:32.271000 2026] [security2:error] [pid 123784:tid 123986] [client 20.65.98.162:45599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/bengi.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6AAAAEQ"] [Tue Aug 18 13:01:32.274688 2026] [security2:error] [pid 123784:tid 123939] [client 20.79.204.6:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6QAAABU"] [Tue Aug 18 13:01:32.283314 2026] [security2:error] [pid 123784:tid 123835] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/as.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6gAAey4"] [Tue Aug 18 13:01:32.294045 2026] [security2:error] [pid 139043:tid 139244] [client 20.116.17.175:22992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/av.php"] [unique_id "aoSB3P2v-lWn9OzQT7URLwAAAMw"] [Tue Aug 18 13:01:32.303851 2026] [security2:error] [pid 123784:tid 123950] [client 20.79.222.117:17945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/222.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG6wAAACA"] [Tue Aug 18 13:01:32.335504 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7AAAAE8"] [Tue Aug 18 13:01:32.351439 2026] [security2:error] [pid 123784:tid 123924] [client 20.1.169.243:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/lock360.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7QAAAAY"] [Tue Aug 18 13:01:32.355650 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:39319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/you.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7gAAAFk"] [Tue Aug 18 13:01:32.357972 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.94.69:14471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSB3P2v-lWn9OzQT7URNAAAAMY"] [Tue Aug 18 13:01:32.359583 2026] [security2:error] [pid 139043:tid 139181] [client 20.80.111.3:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/colors/blue/about.php"] [unique_id "aoSB3P2v-lWn9OzQT7URNQAAAI0"] [Tue Aug 18 13:01:32.374856 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:49471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/f35.update.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROAAAAP8"] [Tue Aug 18 13:01:32.386631 2026] [security2:error] [pid 123784:tid 124012] [client 20.119.58.187:10492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/7.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG7wAAAF4"] [Tue Aug 18 13:01:32.392345 2026] [security2:error] [pid 139043:tid 139175] [client 168.62.48.100:5605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROQAAAIc"] [Tue Aug 18 13:01:32.416818 2026] [security2:error] [pid 139043:tid 139280] [client 168.62.48.100:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7UROwAAAPA"] [Tue Aug 18 13:01:32.429231 2026] [security2:error] [pid 139043:tid 139226] [client 20.104.100.201:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/srontol.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPAAAALo"] [Tue Aug 18 13:01:32.437629 2026] [security2:error] [pid 123784:tid 123875] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG8wAAC1Y"] [Tue Aug 18 13:01:32.449593 2026] [security2:error] [pid 139043:tid 139210] [client 20.102.65.165:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/k.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPQAAAKo"] [Tue Aug 18 13:01:32.469577 2026] [security2:error] [pid 139043:tid 139285] [client 74.7.228.13:41470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "innacorp.com.br"] [uri "/site/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URMAAA9Qo"], referer: https://www.innacorp.com.br/robots.txt [Tue Aug 18 13:01:32.482227 2026] [security2:error] [pid 139043:tid 139276] [client 158.23.17.4:11401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yw.php"] [unique_id "aoSB3P2v-lWn9OzQT7URPwAAAOw"] [Tue Aug 18 13:01:32.491428 2026] [security2:error] [pid 139043:tid 139052] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQAAAygg"] [Tue Aug 18 13:01:32.493485 2026] [security2:error] [pid 123784:tid 124044] [client 20.186.30.159:10095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/xx.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG9gAAAH4"] [Tue Aug 18 13:01:32.493595 2026] [security2:error] [pid 139043:tid 139294] [client 20.226.112.14:28771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gjm.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQQAAAP4"] [Tue Aug 18 13:01:32.512445 2026] [security2:error] [pid 139043:tid 139297] [client 20.226.56.190:28279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/bala.php"] [unique_id "aoSB3P2v-lWn9OzQT7URQgAAAQE"] [Tue Aug 18 13:01:32.521769 2026] [security2:error] [pid 139043:tid 139051] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/id_rsa"] [unique_id "aoSB3P2v-lWn9OzQT7URQwAAkAc"] [Tue Aug 18 13:01:32.535249 2026] [security2:error] [pid 123784:tid 124008] [client 216.244.66.232:37430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-QAAAFo"] [Tue Aug 18 13:01:32.535361 2026] [security2:error] [pid 123784:tid 124008] [client 216.244.66.232:37430] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-QAAAFo"] [Tue Aug 18 13:01:32.545638 2026] [security2:error] [pid 123784:tid 124025] [client 158.23.17.4:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gg.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG-gAAAGs"] [Tue Aug 18 13:01:32.556473 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.204.6:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYG_QAAABs"] [Tue Aug 18 13:01:32.563214 2026] [security2:error] [pid 139043:tid 139275] [client 213.35.127.232:56367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRAAAAOs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:32.575501 2026] [security2:error] [pid 139043:tid 139228] [client 20.250.13.23:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/customize.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRQAAALw"] [Tue Aug 18 13:01:32.588143 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHAAAAMwQ"] [Tue Aug 18 13:01:32.614319 2026] [security2:error] [pid 139043:tid 139198] [client 20.75.92.165:4311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wk/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRgAAAJ4"] [Tue Aug 18 13:01:32.639261 2026] [security2:error] [pid 139043:tid 139187] [client 197.184.64.235:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRwAAAJM"] [Tue Aug 18 13:01:32.649884 2026] [security2:error] [pid 139043:tid 139203] [client 20.104.100.201:49455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/bdroot.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSAAAAKM"] [Tue Aug 18 13:01:32.656881 2026] [security2:error] [pid 139043:tid 139156] [remote 110.249.201.61:50556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "germania.com.br"] [uri "/Estofados_Germania_Igualdade_02.pdf"] [unique_id "aoSB3P2v-lWn9OzQT7URSQAA-3A"] [Tue Aug 18 13:01:32.658081 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:14265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ez.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSgAAALk"] [Tue Aug 18 13:01:32.667394 2026] [security2:error] [pid 139043:tid 139214] [client 135.225.78.186:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTAAAAK4"] [Tue Aug 18 13:01:32.667590 2026] [security2:error] [pid 139043:tid 139059] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/akc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URSwAAoQ8"] [Tue Aug 18 13:01:32.683141 2026] [security2:error] [pid 139043:tid 139255] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTQAAANc"] [Tue Aug 18 13:01:32.703653 2026] [security2:error] [pid 123784:tid 124010] [client 168.62.48.100:18052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHBwAAAFw"] [Tue Aug 18 13:01:32.716949 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.222.117:18033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/key.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCAAAADw"] [Tue Aug 18 13:01:32.718170 2026] [security2:error] [pid 139043:tid 139299] [client 20.226.112.14:28760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/new4.php"] [unique_id "aoSB3P2v-lWn9OzQT7URTwAAAQM"] [Tue Aug 18 13:01:32.738769 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/10.php"] [unique_id "aoSB3P2v-lWn9OzQT7URUgAAANA"] [Tue Aug 18 13:01:32.739625 2026] [security2:error] [pid 139043:tid 139284] [client 20.127.136.245:22172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/fpwch.php"] [unique_id "aoSB3P2v-lWn9OzQT7URUwAAAPQ"] [Tue Aug 18 13:01:32.743620 2026] [security2:error] [pid 123784:tid 123851] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCQAAUz4"] [Tue Aug 18 13:01:32.747150 2026] [security2:error] [pid 139043:tid 139229] [client 20.104.100.201:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/file5.php"] [unique_id "aoSB3P2v-lWn9OzQT7URVAAAAL0"] [Tue Aug 18 13:01:32.757647 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:32.758105 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:32.758592 2026] [security2:error] [pid 139043:tid 139215] [client 20.79.204.6:11696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ioxi-o.php"] [unique_id "aoSB3P2v-lWn9OzQT7URVQAAAK8"] [Tue Aug 18 13:01:32.777082 2026] [security2:error] [pid 139043:tid 139168] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/id_dsa"] [unique_id "aoSB3P2v-lWn9OzQT7URVwAAwHw"] [Tue Aug 18 13:01:32.796975 2026] [security2:error] [pid 123784:tid 123979] [client 20.100.169.31:4981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHCwAAAD0"] [Tue Aug 18 13:01:32.797553 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:32555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-act.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWQAAAKU"] [Tue Aug 18 13:01:32.798903 2026] [security2:error] [pid 139043:tid 139281] [client 20.80.111.3:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/con7.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWgAAAPE"] [Tue Aug 18 13:01:32.805368 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:3069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/82.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHDAAAABk"] [Tue Aug 18 13:01:32.806395 2026] [security2:error] [pid 123784:tid 124043] [client 68.221.73.131:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/reviall.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHDQAAAH0"] [Tue Aug 18 13:01:32.811326 2026] [security2:error] [pid 139043:tid 139269] [client 20.91.215.254:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/widgets.php"] [unique_id "aoSB3P2v-lWn9OzQT7URWwAAAOU"] [Tue Aug 18 13:01:32.824959 2026] [security2:error] [pid 139043:tid 139246] [client 20.102.65.165:8458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/82.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXQAAAM4"] [Tue Aug 18 13:01:32.829331 2026] [security2:error] [pid 139043:tid 139253] [client 20.226.112.14:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/grsiuk.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXgAAANU"] [Tue Aug 18 13:01:32.841699 2026] [security2:error] [pid 139043:tid 139081] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/buy.php"] [unique_id "aoSB3P2v-lWn9OzQT7URXwAAvyU"] [Tue Aug 18 13:01:32.850568 2026] [security2:error] [pid 139043:tid 139204] [client 20.1.169.243:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URYgAAAKQ"] [Tue Aug 18 13:01:32.876093 2026] [security2:error] [pid 139043:tid 139212] [client 20.79.204.6:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/0x.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZAAAAKw"] [Tue Aug 18 13:01:32.904919 2026] [security2:error] [pid 123784:tid 123842] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHEwAAKDU"] [Tue Aug 18 13:01:32.906117 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.98.162:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/h.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFAAAAG4"] [Tue Aug 18 13:01:32.920842 2026] [security2:error] [pid 123784:tid 124031] [client 47.128.42.236:60528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "designacao2022.cabeceiragrandemg.com.br"] [uri "/robots.txt"] [unique_id "aoSB3GwDnJBNj2tDbYYHFQAAAHE"] [Tue Aug 18 13:01:32.923214 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.112.14:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/h.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFgAAAFg"] [Tue Aug 18 13:01:32.929671 2026] [security2:error] [pid 123784:tid 123983] [client 20.104.100.201:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-temp.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHFwAAAEE"] [Tue Aug 18 13:01:32.938323 2026] [security2:error] [pid 123784:tid 124039] [client 20.151.109.219:60871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/asus.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGAAAAHk"] [Tue Aug 18 13:01:32.963870 2026] [security2:error] [pid 123784:tid 124016] [client 20.186.30.159:10048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/av.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGQAAAGI"] [Tue Aug 18 13:01:32.966290 2026] [security2:error] [pid 123784:tid 123946] [client 20.48.236.86:14509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/scxy.php"] [unique_id "aoSB3GwDnJBNj2tDbYYHGgAAABw"] [Tue Aug 18 13:01:32.971751 2026] [security2:error] [pid 139043:tid 139188] [client 20.75.92.165:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-blink.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZgAAAJQ"] [Tue Aug 18 13:01:32.979973 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/well-known/index.php"] [unique_id "aoSB3P2v-lWn9OzQT7URZwAAAMk"] [Tue Aug 18 13:01:33.001193 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.112.14:28602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/koiy.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHGwAAAFY"] [Tue Aug 18 13:01:33.003134 2026] [security2:error] [pid 139043:tid 139187] [client 197.184.64.235:41963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3P2v-lWn9OzQT7URRwAAAJM"] [Tue Aug 18 13:01:33.019315 2026] [security2:error] [pid 139043:tid 139097] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/cong.php"] [unique_id "aoSB3f2v-lWn9OzQT7URaAAAjTU"] [Tue Aug 18 13:01:33.052728 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:33.053014 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:33.067685 2026] [security2:error] [pid 139043:tid 139280] [client 20.116.17.175:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/kj.php"] [unique_id "aoSB3f2v-lWn9OzQT7URagAAAPA"] [Tue Aug 18 13:01:33.069827 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gi.php"] [unique_id "aoSB3f2v-lWn9OzQT7URawAAALo"] [Tue Aug 18 13:01:33.089878 2026] [security2:error] [pid 139043:tid 139244] [client 20.119.58.187:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/13.php"] [unique_id "aoSB3f2v-lWn9OzQT7URbAAAAMw"] [Tue Aug 18 13:01:33.090264 2026] [security2:error] [pid 139043:tid 139285] [client 20.102.65.165:3014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/dex.php"] [unique_id "aoSB3f2v-lWn9OzQT7URbQAAAPU"] [Tue Aug 18 13:01:33.117428 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/xmr.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHIAAAABo"] [Tue Aug 18 13:01:33.128748 2026] [security2:error] [pid 139043:tid 139286] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlypiscinas.com.br"] [uri "/index.php"] [unique_id "aoSB2_2v-lWn9OzQT7URAwAA9mU"], referer: https://jlypiscinas.com.br/ [Tue Aug 18 13:01:33.131619 2026] [security2:error] [pid 139043:tid 139206] [client 103.120.71.157:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URcAAAAKY"] [Tue Aug 18 13:01:33.131759 2026] [security2:error] [pid 139043:tid 139206] [client 103.120.71.157:26173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URcAAAAKY"] [Tue Aug 18 13:01:33.162411 2026] [security2:error] [pid 123784:tid 124020] [client 20.104.100.201:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yup.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHIgAAAGY"] [Tue Aug 18 13:01:33.164825 2026] [authz_core:error] [pid 123784:tid 123850] [remote 57.141.22.30:61218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:33.165101 2026] [authz_core:error] [pid 123784:tid 123850] [remote 57.141.22.30:61218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:33.168366 2026] [security2:error] [pid 139043:tid 139294] [client 20.79.222.117:18014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/chosen.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdAAAAP4"] [Tue Aug 18 13:01:33.169090 2026] [security2:error] [pid 139043:tid 139263] [client 20.79.204.6:11543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/0x.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdQAAAN8"] [Tue Aug 18 13:01:33.177954 2026] [autoindex:error] [pid 139043:tid 139193] [client 20.79.204.6:2220] AH01276: Cannot serve directory /home3/brto26/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:33.193355 2026] [security2:error] [pid 139043:tid 139058] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB3f2v-lWn9OzQT7URdwAA3A4"] [Tue Aug 18 13:01:33.205247 2026] [security2:error] [pid 139043:tid 139278] [client 20.104.100.201:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-css.php"] [unique_id "aoSB3f2v-lWn9OzQT7UReQAAAO4"] [Tue Aug 18 13:01:33.209282 2026] [security2:error] [pid 139043:tid 139107] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/key.pem"] [unique_id "aoSB3f2v-lWn9OzQT7URegAAkD8"] [Tue Aug 18 13:01:33.213623 2026] [security2:error] [pid 139043:tid 139276] [client 20.1.169.243:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/pwnd/as.php"] [unique_id "aoSB3f2v-lWn9OzQT7URewAAAOw"] [Tue Aug 18 13:01:33.222545 2026] [security2:error] [pid 123784:tid 123805] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJAAAMhA"] [Tue Aug 18 13:01:33.231253 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fff.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJQAAAHM"] [Tue Aug 18 13:01:33.233584 2026] [security2:error] [pid 139043:tid 139210] [client 20.80.111.3:18452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSB3f2v-lWn9OzQT7URfAAAAKo"] [Tue Aug 18 13:01:33.308026 2026] [security2:error] [pid 139043:tid 139075] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/privatekey.key"] [unique_id "aoSB3f2v-lWn9OzQT7URfgAA6R8"] [Tue Aug 18 13:01:33.308810 2026] [security2:error] [pid 123784:tid 123948] [client 149.34.210.141:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJwAAAB4"] [Tue Aug 18 13:01:33.324021 2026] [security2:error] [pid 139043:tid 139261] [client 20.75.92.165:4271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/xfun.php"] [unique_id "aoSB3f2v-lWn9OzQT7URfwAAAN0"] [Tue Aug 18 13:01:33.333681 2026] [security2:error] [pid 139043:tid 139176] [client 168.62.48.100:18098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSB3f2v-lWn9OzQT7URgAAAAIg"] [Tue Aug 18 13:01:33.354209 2026] [security2:error] [pid 123784:tid 123934] [client 20.186.30.159:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/media.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLAAAABA"] [Tue Aug 18 13:01:33.360821 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:60398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/22.php"] [unique_id "aoSB3f2v-lWn9OzQT7URggAAANk"] [Tue Aug 18 13:01:33.368273 2026] [security2:error] [pid 139043:tid 139083] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/db.php"] [unique_id "aoSB3f2v-lWn9OzQT7URgwAA1yc"] [Tue Aug 18 13:01:33.392393 2026] [security2:error] [pid 123784:tid 124007] [client 68.221.73.131:21952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/nope.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLQAAAFk"] [Tue Aug 18 13:01:33.409051 2026] [security2:error] [pid 139043:tid 139248] [client 20.250.13.23:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/mah/function.php"] [unique_id "aoSB3f2v-lWn9OzQT7URhQAAANA"] [Tue Aug 18 13:01:33.412971 2026] [security2:error] [pid 123784:tid 123898] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/an.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLgAAXm0"] [Tue Aug 18 13:01:33.423148 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.112.14:22904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pouhg.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHLwAAACc"] [Tue Aug 18 13:01:33.424044 2026] [security2:error] [pid 139043:tid 139298] [client 20.100.169.31:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3f2v-lWn9OzQT7URhgAAAQI"] [Tue Aug 18 13:01:33.435777 2026] [security2:error] [pid 123784:tid 123959] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/about.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHMAAAACk"] [Tue Aug 18 13:01:33.442159 2026] [security2:error] [pid 123784:tid 123975] [client 20.119.58.187:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/100.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHMQAAADk"] [Tue Aug 18 13:01:33.449011 2026] [security2:error] [pid 123784:tid 123954] [client 20.102.65.165:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/dex.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHNQAAACQ"] [Tue Aug 18 13:01:33.465219 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:25804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHOAAAACM"] [Tue Aug 18 13:01:33.475758 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.100.201:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHQgAAAH4"] [Tue Aug 18 13:01:33.478016 2026] [security2:error] [pid 139043:tid 139179] [client 20.104.100.201:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/flox.php"] [unique_id "aoSB3f2v-lWn9OzQT7URiAAAAIs"] [Tue Aug 18 13:01:33.482289 2026] [security2:error] [pid 139043:tid 139279] [client 20.79.204.6:11559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/222.php"] [unique_id "aoSB3f2v-lWn9OzQT7URiQAAAO8"] [Tue Aug 18 13:01:33.492539 2026] [security2:error] [pid 123784:tid 123972] [client 20.206.73.37:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/yj09.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSAAAADY"] [Tue Aug 18 13:01:33.506307 2026] [security2:error] [pid 123784:tid 123967] [client 20.102.65.165:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/puc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSQAAADE"] [Tue Aug 18 13:01:33.526989 2026] [security2:error] [pid 123784:tid 123945] [client 20.226.112.14:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/moon3.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHSgAAABs"] [Tue Aug 18 13:01:33.542512 2026] [security2:error] [pid 139043:tid 139061] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/dropdown.php"] [unique_id "aoSB3f2v-lWn9OzQT7URjQAAjBE"] [Tue Aug 18 13:01:33.571245 2026] [security2:error] [pid 123784:tid 123933] [client 20.79.204.6:10368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/aa.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHTgAAAA8"] [Tue Aug 18 13:01:33.578418 2026] [security2:error] [pid 139043:tid 139232] [client 20.1.169.243:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/rk2.php"] [unique_id "aoSB3f2v-lWn9OzQT7URjwAAAMA"] [Tue Aug 18 13:01:33.587348 2026] [security2:error] [pid 123784:tid 123948] [client 149.34.210.141:57935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHJwAAAB4"] [Tue Aug 18 13:01:33.595950 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB3f2v-lWn9OzQT7URkQAAAMQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:33.597388 2026] [security2:error] [pid 139043:tid 139253] [client 168.62.48.100:18008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3f2v-lWn9OzQT7URkgAAANU"] [Tue Aug 18 13:01:33.613937 2026] [security2:error] [pid 123784:tid 124011] [client 20.79.222.117:17942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/wpxml.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUQAAAF0"] [Tue Aug 18 13:01:33.618410 2026] [security2:error] [pid 123784:tid 123981] [client 158.23.17.4:47880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pz.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUgAAAD8"] [Tue Aug 18 13:01:33.628486 2026] [security2:error] [pid 123784:tid 124032] [client 20.186.30.159:10027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/images.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHUwAAAHI"] [Tue Aug 18 13:01:33.672717 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:14061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/qh.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVQAAAEk"] [Tue Aug 18 13:01:33.673646 2026] [security2:error] [pid 123784:tid 124025] [client 20.80.111.3:39565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/dist/alfa-rex.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVgAAAGs"] [Tue Aug 18 13:01:33.689873 2026] [security2:error] [pid 123784:tid 123964] [client 138.36.100.162:43152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVwAAAC4"] [Tue Aug 18 13:01:33.690012 2026] [security2:error] [pid 123784:tid 123964] [client 138.36.100.162:43152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHVwAAAC4"] [Tue Aug 18 13:01:33.724320 2026] [security2:error] [pid 139043:tid 139213] [client 20.151.109.219:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zs.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmAAAAK0"] [Tue Aug 18 13:01:33.724805 2026] [security2:error] [pid 123784:tid 123910] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/404.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWAAAEnk"] [Tue Aug 18 13:01:33.751440 2026] [security2:error] [pid 139043:tid 139087] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/file.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmQAA2is"] [Tue Aug 18 13:01:33.752935 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/op.php"] [unique_id "aoSB3f2v-lWn9OzQT7URmgAAAOI"] [Tue Aug 18 13:01:33.755993 2026] [security2:error] [pid 139043:tid 139192] [client 20.116.17.175:54856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/makeasmtp.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnAAAAJg"] [Tue Aug 18 13:01:33.756092 2026] [security2:error] [pid 123784:tid 124031] [client 172.202.39.151:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWQAAAHE"] [Tue Aug 18 13:01:33.773813 2026] [security2:error] [pid 123784:tid 123963] [client 20.79.204.6:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/222.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWgAAAC0"] [Tue Aug 18 13:01:33.787828 2026] [security2:error] [pid 123784:tid 124039] [client 20.226.112.14:32574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/opts.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHWwAAAHk"] [Tue Aug 18 13:01:33.792124 2026] [security2:error] [pid 139043:tid 139252] [client 20.75.92.165:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/p.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnQAAANQ"] [Tue Aug 18 13:01:33.794955 2026] [security2:error] [pid 139043:tid 139243] [client 20.119.58.187:10153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/222.php"] [unique_id "aoSB3f2v-lWn9OzQT7URngAAAMs"] [Tue Aug 18 13:01:33.797381 2026] [security2:error] [pid 139043:tid 139209] [client 20.104.100.201:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-the.php"] [unique_id "aoSB3f2v-lWn9OzQT7URnwAAAKk"] [Tue Aug 18 13:01:33.803552 2026] [security2:error] [pid 123784:tid 123946] [client 20.118.133.132:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/bengi.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHXQAAABw"] [Tue Aug 18 13:01:33.816940 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHXgAAAFY"] [Tue Aug 18 13:01:33.823557 2026] [security2:error] [pid 139043:tid 139270] [client 178.153.171.161:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URogAAAOY"] [Tue Aug 18 13:01:33.823675 2026] [security2:error] [pid 139043:tid 139270] [client 178.153.171.161:55736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3f2v-lWn9OzQT7URogAAAOY"] [Tue Aug 18 13:01:33.855110 2026] [security2:error] [pid 123784:tid 123927] [client 20.102.65.165:3041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/inso.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYAAAAAk"] [Tue Aug 18 13:01:33.884709 2026] [security2:error] [pid 123784:tid 123806] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-login.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYQAANRE"] [Tue Aug 18 13:01:33.914352 2026] [security2:error] [pid 123784:tid 123962] [client 20.163.43.14:8836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gecko-new.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHYgAAACw"] [Tue Aug 18 13:01:33.926586 2026] [security2:error] [pid 139043:tid 139078] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/goods.php"] [unique_id "aoSB3f2v-lWn9OzQT7URpwAA9iI"] [Tue Aug 18 13:01:33.926769 2026] [security2:error] [pid 123784:tid 124018] [client 168.62.48.100:5631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSB3WwDnJBNj2tDbYYHZAAAAGQ"] [Tue Aug 18 13:01:33.935663 2026] [security2:error] [pid 139043:tid 139263] [client 168.62.48.100:17987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqAAAAN8"] [Tue Aug 18 13:01:33.943009 2026] [security2:error] [pid 139043:tid 139288] [client 20.1.169.243:5778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/storage/rip.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqQAAAPg"] [Tue Aug 18 13:01:33.955454 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:33.955734 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:33.969549 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wso.php"] [unique_id "aoSB3f2v-lWn9OzQT7URqwAAANw"] [Tue Aug 18 13:01:33.976424 2026] [security2:error] [pid 139043:tid 139228] [client 62.113.113.162:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orientaldistribuidora.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB3f2v-lWn9OzQT7URoAAAALw"], referer: https://orientaldistribuidora.com.br/ [Tue Aug 18 13:01:34.004866 2026] [security2:error] [pid 139043:tid 139278] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrQAAAO4"] [Tue Aug 18 13:01:34.031803 2026] [security2:error] [pid 123784:tid 124033] [client 20.151.109.219:60926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iz.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHZwAAAHM"] [Tue Aug 18 13:01:34.033652 2026] [security2:error] [pid 139043:tid 139235] [client 20.104.100.201:49089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/1xmomo.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrgAAAMM"] [Tue Aug 18 13:01:34.038056 2026] [security2:error] [pid 139043:tid 139221] [client 20.79.222.117:17920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/file1221.php"] [unique_id "aoSB3v2v-lWn9OzQT7URrwAAALU"] [Tue Aug 18 13:01:34.038347 2026] [security2:error] [pid 123784:tid 123915] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHagAAFn4"] [Tue Aug 18 13:01:34.059844 2026] [security2:error] [pid 139043:tid 139238] [client 20.250.13.23:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/filter.php"] [unique_id "aoSB3v2v-lWn9OzQT7URsAAAAMY"] [Tue Aug 18 13:01:34.062352 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zwq13.php"] [unique_id "aoSB3v2v-lWn9OzQT7URsQAAAOk"] [Tue Aug 18 13:01:34.079604 2026] [security2:error] [pid 123784:tid 123990] [client 158.158.74.177:9271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHawAAAEg"] [Tue Aug 18 13:01:34.088953 2026] [security2:error] [pid 123784:tid 123950] [client 20.186.30.159:10020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/mac.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbAAAACA"] [Tue Aug 18 13:01:34.091491 2026] [security2:error] [pid 139043:tid 139268] [client 20.104.100.201:34797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB3v2v-lWn9OzQT7URswAAAOQ"] [Tue Aug 18 13:01:34.092765 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kk.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtAAAAKM"] [Tue Aug 18 13:01:34.093574 2026] [security2:error] [pid 139043:tid 139291] [client 20.102.65.165:8525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/puc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtQAAAPs"] [Tue Aug 18 13:01:34.100841 2026] [security2:error] [pid 139043:tid 139085] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtgAAmyk"] [Tue Aug 18 13:01:34.103394 2026] [security2:error] [pid 139043:tid 139217] [client 20.79.204.6:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URtwAAALE"] [Tue Aug 18 13:01:34.106363 2026] [security2:error] [pid 139043:tid 139227] [client 20.79.204.6:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7URuQAAALs"] [Tue Aug 18 13:01:34.112806 2026] [security2:error] [pid 139043:tid 139244] [client 20.100.169.31:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB3v2v-lWn9OzQT7URugAAAMw"] [Tue Aug 18 13:01:34.113115 2026] [security2:error] [pid 123784:tid 124020] [client 20.80.111.3:41250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/elementor/wp-login.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbQAAAGY"] [Tue Aug 18 13:01:34.154572 2026] [security2:error] [pid 139043:tid 139245] [client 20.91.215.254:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/abc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URvQAAAM0"] [Tue Aug 18 13:01:34.154827 2026] [security2:error] [pid 123784:tid 123931] [client 20.48.236.86:14477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ws13.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHbgAAAA0"] [Tue Aug 18 13:01:34.156389 2026] [security2:error] [pid 139043:tid 139184] [client 20.119.58.187:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB3v2v-lWn9OzQT7URvgAAAJA"] [Tue Aug 18 13:01:34.190578 2026] [security2:error] [pid 139043:tid 139279] [client 20.102.65.165:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URwQAAAO8"] [Tue Aug 18 13:01:34.197459 2026] [security2:error] [pid 123784:tid 123924] [client 20.75.92.165:4244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcAAAAAY"] [Tue Aug 18 13:01:34.221982 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:22937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcQAAADc"] [Tue Aug 18 13:01:34.242509 2026] [security2:error] [pid 139043:tid 139095] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/phpinfo.php"] [unique_id "aoSB3v2v-lWn9OzQT7URwwAA5TM"] [Tue Aug 18 13:01:34.274992 2026] [security2:error] [pid 139043:tid 139070] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/htaccess.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxAAA1Ro"] [Tue Aug 18 13:01:34.278788 2026] [security2:error] [pid 139043:tid 139262] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/as.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxQAAAN4"] [Tue Aug 18 13:01:34.283295 2026] [security2:error] [pid 123784:tid 124019] [client 168.62.48.100:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/mt/byp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHcwAAAGU"] [Tue Aug 18 13:01:34.304627 2026] [security2:error] [pid 139043:tid 139205] [client 157.20.138.62:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxgAAAKU"] [Tue Aug 18 13:01:34.304827 2026] [security2:error] [pid 139043:tid 139205] [client 157.20.138.62:63500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxgAAAKU"] [Tue Aug 18 13:01:34.307102 2026] [security2:error] [pid 139043:tid 139179] [client 20.1.169.243:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/tool.php"] [unique_id "aoSB3v2v-lWn9OzQT7URxwAAAIs"] [Tue Aug 18 13:01:34.311519 2026] [security2:error] [pid 139043:tid 139292] [client 20.163.43.14:8941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSB3v2v-lWn9OzQT7URyAAAAPw"] [Tue Aug 18 13:01:34.312144 2026] [security2:error] [pid 123784:tid 123995] [client 103.184.169.37:43157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdAAAAE0"] [Tue Aug 18 13:01:34.312263 2026] [security2:error] [pid 123784:tid 123995] [client 103.184.169.37:43157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdAAAAE0"] [Tue Aug 18 13:01:34.314449 2026] [security2:error] [pid 139043:tid 139290] [client 20.104.100.201:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/txets.php"] [unique_id "aoSB3v2v-lWn9OzQT7URyQAAAPo"] [Tue Aug 18 13:01:34.338991 2026] [security2:error] [pid 123784:tid 123919] [client 20.151.109.219:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/se.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHdwAAAAE"] [Tue Aug 18 13:01:34.348580 2026] [security2:error] [pid 139043:tid 139190] [client 135.225.78.186:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB3v2v-lWn9OzQT7URywAAAJY"] [Tue Aug 18 13:01:34.365900 2026] [security2:error] [pid 139043:tid 139258] [client 68.221.73.131:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/nope.php"] [unique_id "aoSB3v2v-lWn9OzQT7URzQAAANo"] [Tue Aug 18 13:01:34.376346 2026] [autoindex:error] [pid 139043:tid 139282] [client 20.79.204.6:8371] AH01276: Cannot serve directory /home4/dp305k87/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:34.379010 2026] [security2:error] [pid 139043:tid 139240] [client 20.79.204.6:11664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aa.php"] [unique_id "aoSB3v2v-lWn9OzQT7URzwAAAMg"] [Tue Aug 18 13:01:34.379442 2026] [security2:error] [pid 139043:tid 139167] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSB3v2v-lWn9OzQT7URzgAA4ns"] [Tue Aug 18 13:01:34.400316 2026] [security2:error] [pid 139043:tid 139259] [client 66.249.66.35:36431] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "testing.giordaniturismo.com.br"] [uri "/robots.txt"] [unique_id "aoSB3v2v-lWn9OzQT7UR0AAAANs"] [Tue Aug 18 13:01:34.402855 2026] [security2:error] [pid 139043:tid 139069] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/info.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0QAAlBk"] [Tue Aug 18 13:01:34.445298 2026] [security2:error] [pid 139043:tid 139079] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/pi.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0gAA5iM"] [Tue Aug 18 13:01:34.446122 2026] [security2:error] [pid 123784:tid 123945] [client 20.79.222.117:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/nox.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHeQAAABs"] [Tue Aug 18 13:01:34.455110 2026] [security2:error] [pid 139043:tid 139066] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/images/wso.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR0wAA4RY"] [Tue Aug 18 13:01:34.456268 2026] [security2:error] [pid 123784:tid 124042] [client 158.23.17.4:47659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/r.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHegAAAHw"] [Tue Aug 18 13:01:34.498053 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/xwpg.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1QAAAIU"] [Tue Aug 18 13:01:34.499238 2026] [security2:error] [pid 139043:tid 139094] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/test.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1gAA6DI"] [Tue Aug 18 13:01:34.510149 2026] [security2:error] [pid 139043:tid 139192] [client 20.119.58.187:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/abcd.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR1wAAAJg"] [Tue Aug 18 13:01:34.526434 2026] [security2:error] [pid 139043:tid 139285] [client 20.226.112.14:34181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/Okxob.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR2QAAAPU"] [Tue Aug 18 13:01:34.545475 2026] [security2:error] [pid 123784:tid 123886] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wso.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHfQAAAGE"] [Tue Aug 18 13:01:34.546028 2026] [security2:error] [pid 123784:tid 123933] [client 168.62.48.100:18034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHfgAAAA8"] [Tue Aug 18 13:01:34.558417 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:34.558697 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:34.583190 2026] [security2:error] [pid 139043:tid 139122] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/i.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR3gAAmU4"] [Tue Aug 18 13:01:34.594527 2026] [security2:error] [pid 123784:tid 123932] [client 20.104.100.201:49428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/img.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHgAAAAA4"] [Tue Aug 18 13:01:34.611822 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:56810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR3wAAAMQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:34.621935 2026] [security2:error] [pid 123784:tid 123952] [client 20.75.92.165:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/aaa.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHgQAAACI"] [Tue Aug 18 13:01:34.629110 2026] [security2:error] [pid 139043:tid 139055] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/index/function.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4AAA7gs"] [Tue Aug 18 13:01:34.634152 2026] [security2:error] [pid 139043:tid 139178] [client 20.79.204.6:10727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4QAAAIo"] [Tue Aug 18 13:01:34.643831 2026] [security2:error] [pid 123784:tid 123979] [client 20.186.30.159:9986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/ops.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHggAAAD0"] [Tue Aug 18 13:01:34.647301 2026] [security2:error] [pid 123784:tid 123943] [client 20.102.65.165:8462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/inso.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhAAAABk"] [Tue Aug 18 13:01:34.647853 2026] [security2:error] [pid 123784:tid 124032] [client 20.151.109.219:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vp.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhQAAAHI"] [Tue Aug 18 13:01:34.649146 2026] [security2:error] [pid 139043:tid 139276] [client 20.163.43.14:8845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/01.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR4gAAAOw"] [Tue Aug 18 13:01:34.670312 2026] [security2:error] [pid 123784:tid 124010] [client 20.1.169.243:5332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHhgAAAFw"] [Tue Aug 18 13:01:34.695225 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/input.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5QAAAMI"] [Tue Aug 18 13:01:34.702153 2026] [security2:error] [pid 139043:tid 139280] [client 20.79.204.6:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/abcd.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5gAAAPA"] [Tue Aug 18 13:01:34.705301 2026] [security2:error] [pid 123784:tid 123863] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/sf.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHiAAALko"] [Tue Aug 18 13:01:34.725995 2026] [security2:error] [pid 139043:tid 139238] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/bolt.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR5wAAAMY"] [Tue Aug 18 13:01:34.741010 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.98.162:22549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ano.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR6gAAAN0"] [Tue Aug 18 13:01:34.744018 2026] [security2:error] [pid 139043:tid 139206] [client 158.158.74.177:22870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR6wAAAKY"] [Tue Aug 18 13:01:34.764022 2026] [security2:error] [pid 139043:tid 139230] [client 20.102.65.165:3046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/img.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR7QAAAL4"] [Tue Aug 18 13:01:34.770896 2026] [security2:error] [pid 139043:tid 139300] [client 20.79.204.6:2404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR7gAAAQQ"] [Tue Aug 18 13:01:34.802934 2026] [security2:error] [pid 139043:tid 139119] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/info.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8AAAoUs"] [Tue Aug 18 13:01:34.811432 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/dex.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHigAAAHU"] [Tue Aug 18 13:01:34.815909 2026] [security2:error] [pid 139043:tid 139227] [client 20.127.136.245:9009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8QAAALs"] [Tue Aug 18 13:01:34.858900 2026] [security2:error] [pid 139043:tid 139257] [client 20.79.222.117:17933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/akismet.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR8wAAANk"] [Tue Aug 18 13:01:34.862294 2026] [security2:error] [pid 139043:tid 139268] [client 20.119.58.187:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/al.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9AAAAOQ"] [Tue Aug 18 13:01:34.869535 2026] [security2:error] [pid 139043:tid 139298] [client 20.116.17.175:53762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/cok.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9QAAAQI"] [Tue Aug 18 13:01:34.872763 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR9gAAAJA"] [Tue Aug 18 13:01:34.887478 2026] [security2:error] [pid 123784:tid 123913] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/index/function.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjAAAH3w"] [Tue Aug 18 13:01:34.918469 2026] [security2:error] [pid 123784:tid 124001] [client 20.91.215.254:11462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/classwithtostring.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjQAAAFM"] [Tue Aug 18 13:01:34.946815 2026] [security2:error] [pid 139043:tid 139189] [client 168.62.48.100:18143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR-gAAAJU"] [Tue Aug 18 13:01:34.956889 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjgAAOjM"] [Tue Aug 18 13:01:34.971995 2026] [security2:error] [pid 139043:tid 139231] [client 5.31.227.224:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_AAAAL8"] [Tue Aug 18 13:01:34.976580 2026] [security2:error] [pid 139043:tid 139231] [client 5.31.227.224:29946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_AAAAL8"] [Tue Aug 18 13:01:34.977097 2026] [security2:error] [pid 139043:tid 139253] [client 20.163.43.14:8920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/lv.php"] [unique_id "aoSB3v2v-lWn9OzQT7UR_gAAANU"] [Tue Aug 18 13:01:34.979704 2026] [security2:error] [pid 139043:tid 139204] [client 20.75.92.165:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/term.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAAAAAKQ"] [Tue Aug 18 13:01:34.982909 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.112.14:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/file59.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAQAAAI4"] [Tue Aug 18 13:01:34.986907 2026] [security2:error] [pid 123784:tid 124000] [client 20.79.204.6:11575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abcd.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHjwAAAFI"] [Tue Aug 18 13:01:34.987439 2026] [security2:error] [pid 139043:tid 139205] [client 20.48.236.86:14472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/btx25.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAgAAAKU"] [Tue Aug 18 13:01:34.987716 2026] [security2:error] [pid 139043:tid 139233] [client 20.80.111.3:31260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/goat1.php"] [unique_id "aoSB3v2v-lWn9OzQT7USAwAAAME"] [Tue Aug 18 13:01:34.988310 2026] [security2:error] [pid 123784:tid 124016] [client 68.221.73.131:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/new.php"] [unique_id "aoSB3mwDnJBNj2tDbYYHkAAAAGI"] [Tue Aug 18 13:01:34.989505 2026] [security2:error] [pid 139043:tid 139124] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/profile.php"] [unique_id "aoSB3v2v-lWn9OzQT7USBAAArFA"] [Tue Aug 18 13:01:34.990781 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/png.php"] [unique_id "aoSB3v2v-lWn9OzQT7USBQAAANA"] [Tue Aug 18 13:01:35.002683 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB3_2v-lWn9OzQT7USBgAAAIs"] [Tue Aug 18 13:01:35.022361 2026] [security2:error] [pid 139043:tid 139099] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/app_dev.php"] [unique_id "aoSB3_2v-lWn9OzQT7USBwAA0jc"] [Tue Aug 18 13:01:35.034646 2026] [security2:error] [pid 139043:tid 139218] [client 20.1.169.243:5801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCAAAALI"] [Tue Aug 18 13:01:35.048480 2026] [security2:error] [pid 123784:tid 123904] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/edit.php"] [unique_id "aoSB32wDnJBNj2tDbYYHkgAAVnM"] [Tue Aug 18 13:01:35.054368 2026] [security2:error] [pid 139043:tid 139219] [client 20.186.30.159:10066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/coffexium.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCQAAALM"] [Tue Aug 18 13:01:35.060105 2026] [security2:error] [pid 139043:tid 139199] [client 66.187.6.102:56114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/pinceis-artisticos"] [unique_id "aoSB3_2v-lWn9OzQT7USCgAAAJ8"] [Tue Aug 18 13:01:35.060213 2026] [security2:error] [pid 139043:tid 139199] [client 66.187.6.102:56114] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/produtos/pinceis-artisticos"] [unique_id "aoSB3_2v-lWn9OzQT7USCgAAAJ8"] [Tue Aug 18 13:01:35.060929 2026] [security2:error] [pid 139043:tid 139213] [client 158.23.17.4:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/17.php"] [unique_id "aoSB3_2v-lWn9OzQT7USCwAAAK0"] [Tue Aug 18 13:01:35.086411 2026] [security2:error] [pid 139043:tid 139240] [client 20.102.65.165:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/222.php"] [unique_id "aoSB3_2v-lWn9OzQT7USDgAAAMg"] [Tue Aug 18 13:01:35.111485 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ph.php"] [unique_id "aoSB3_2v-lWn9OzQT7USDwAAAMs"] [Tue Aug 18 13:01:35.140855 2026] [security2:error] [pid 123784:tid 123960] [client 20.251.112.238:26144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zwq13.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlAAAACo"] [Tue Aug 18 13:01:35.144518 2026] [security2:error] [pid 123784:tid 123947] [client 20.104.100.201:49671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/index.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlQAAAB0"] [Tue Aug 18 13:01:35.144716 2026] [security2:error] [pid 123784:tid 123880] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB32wDnJBNj2tDbYYHlgAACVs"] [Tue Aug 18 13:01:35.152004 2026] [security2:error] [pid 139043:tid 139197] [client 20.104.100.201:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/xyn.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEAAAAJ0"] [Tue Aug 18 13:01:35.158250 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:35.158509 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:35.165218 2026] [security2:error] [pid 139043:tid 139271] [client 20.100.169.31:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEQAAAOc"] [Tue Aug 18 13:01:35.165912 2026] [security2:error] [pid 139043:tid 139104] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/sx.php"] [unique_id "aoSB3_2v-lWn9OzQT7USEgAA_zw"] [Tue Aug 18 13:01:35.167883 2026] [security2:error] [pid 139043:tid 139125] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adfschopan.com.br"] [uri "/.hermes/.env"] [unique_id "aoSB3_2v-lWn9OzQT7USEwAAz1E"] [Tue Aug 18 13:01:35.195551 2026] [security2:error] [pid 139043:tid 139224] [client 172.202.39.151:40911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/ioxi-o.php"] [unique_id "aoSB3_2v-lWn9OzQT7USFAAAALg"] [Tue Aug 18 13:01:35.206188 2026] [security2:error] [pid 123784:tid 124038] [client 4.232.94.69:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/OK.php"] [unique_id "aoSB32wDnJBNj2tDbYYHmgAAAHg"] [Tue Aug 18 13:01:35.214922 2026] [security2:error] [pid 139043:tid 139259] [client 20.119.58.187:10198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/alfa.php"] [unique_id "aoSB3_2v-lWn9OzQT7USFgAAANs"] [Tue Aug 18 13:01:35.236854 2026] [security2:error] [pid 139043:tid 139130] [remote 34.158.8.33:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adfschopan.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSB3_2v-lWn9OzQT7USGAAA_lY"] [Tue Aug 18 13:01:35.270370 2026] [security2:error] [pid 139043:tid 139260] [client 20.79.222.117:18031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USGwAAANw"] [Tue Aug 18 13:01:35.302366 2026] [security2:error] [pid 139043:tid 139297] [client 20.163.43.14:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/new.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHAAAAQE"] [Tue Aug 18 13:01:35.309514 2026] [security2:error] [pid 139043:tid 139073] [remote 89.185.225.24:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ofertas.vidracariafroesbox.com.br"] [uri "/wp-login.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHQAAyh0"] [Tue Aug 18 13:01:35.313539 2026] [security2:error] [pid 123784:tid 124023] [client 20.250.13.23:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/jquery.php"] [unique_id "aoSB32wDnJBNj2tDbYYHnwAAAGk"] [Tue Aug 18 13:01:35.314895 2026] [security2:error] [pid 139043:tid 139221] [client 20.102.65.165:8278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/fpwch.php"] [unique_id "aoSB3_2v-lWn9OzQT7USHgAAALU"] [Tue Aug 18 13:01:35.342602 2026] [security2:error] [pid 139043:tid 139053] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USIQAAqgk"] [Tue Aug 18 13:01:35.358911 2026] [security2:error] [pid 123784:tid 123821] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB32wDnJBNj2tDbYYHoAAARCA"] [Tue Aug 18 13:01:35.363203 2026] [security2:error] [pid 123784:tid 123939] [client 20.65.98.162:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/file2.php"] [unique_id "aoSB32wDnJBNj2tDbYYHoQAAABU"] [Tue Aug 18 13:01:35.375753 2026] [security2:error] [pid 139043:tid 139202] [client 158.23.17.4:15138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dg.php"] [unique_id "aoSB3_2v-lWn9OzQT7USIwAAAKI"] [Tue Aug 18 13:01:35.379909 2026] [security2:error] [pid 139043:tid 139251] [client 168.62.48.100:18042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJAAAANM"] [Tue Aug 18 13:01:35.381179 2026] [security2:error] [pid 139043:tid 139176] [client 20.79.204.6:11541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJQAAAIg"] [Tue Aug 18 13:01:35.388805 2026] [security2:error] [pid 123784:tid 123923] [client 20.38.3.247:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/dex.php"] [unique_id "aoSB32wDnJBNj2tDbYYHogAAAAU"] [Tue Aug 18 13:01:35.391805 2026] [security2:error] [pid 139043:tid 139238] [client 20.75.92.165:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/7.php"] [unique_id "aoSB3_2v-lWn9OzQT7USJgAAAMY"] [Tue Aug 18 13:01:35.397608 2026] [security2:error] [pid 139043:tid 139228] [client 20.1.169.243:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSB3_2v-lWn9OzQT7USKAAAALw"] [Tue Aug 18 13:01:35.410377 2026] [autoindex:error] [pid 139043:tid 139192] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:35.422688 2026] [authz_core:error] [pid 139043:tid 139106] [remote 57.141.22.94:52650] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:35.423004 2026] [authz_core:error] [pid 139043:tid 139106] [remote 57.141.22.94:52650] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:35.423803 2026] [security2:error] [pid 139043:tid 139261] [client 20.116.17.175:23014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ab.php"] [unique_id "aoSB3_2v-lWn9OzQT7USKwAAAN0"] [Tue Aug 18 13:01:35.424479 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:49435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLAAAAO0"] [Tue Aug 18 13:01:35.429246 2026] [security2:error] [pid 123784:tid 123968] [client 20.80.111.3:33467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/google-seo-rank/module.php"] [unique_id "aoSB32wDnJBNj2tDbYYHowAAADI"] [Tue Aug 18 13:01:35.437582 2026] [security2:error] [pid 139043:tid 139203] [client 172.202.39.151:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/sf.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLQAAAKM"] [Tue Aug 18 13:01:35.455268 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLgAAAK4"] [Tue Aug 18 13:01:35.460080 2026] [security2:error] [pid 139043:tid 139299] [client 20.102.65.165:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/key.php"] [unique_id "aoSB3_2v-lWn9OzQT7USLwAAAQM"] [Tue Aug 18 13:01:35.460188 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:35.460451 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:35.505428 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/s.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMAAAANU"] [Tue Aug 18 13:01:35.508992 2026] [security2:error] [pid 123784:tid 123830] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-good.php"] [unique_id "aoSB32wDnJBNj2tDbYYHpgAANyk"] [Tue Aug 18 13:01:35.518705 2026] [security2:error] [pid 139043:tid 139109] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMQAApUE"] [Tue Aug 18 13:01:35.530296 2026] [security2:error] [pid 139043:tid 139174] [client 158.158.74.177:9236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSB3_2v-lWn9OzQT7USMgAAAIY"] [Tue Aug 18 13:01:35.567690 2026] [security2:error] [pid 139043:tid 139230] [client 20.119.58.187:10132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/as.php"] [unique_id "aoSB3_2v-lWn9OzQT7USNwAAAL4"] [Tue Aug 18 13:01:35.574331 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:56222] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/img/download.png"] [unique_id "aoSB32wDnJBNj2tDbYYHqgAAAD4"] [Tue Aug 18 13:01:35.590542 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:11537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/admin.php"] [unique_id "aoSB32wDnJBNj2tDbYYHrwAAAEg"] [Tue Aug 18 13:01:35.607193 2026] [security2:error] [pid 139043:tid 139293] [client 159.69.158.189:64106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USRwAAAP0"], referer: https://dadicamotors.com.br/ [Tue Aug 18 13:01:35.613855 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/eauu.php"] [unique_id "aoSB3_2v-lWn9OzQT7USSQAAAK0"] [Tue Aug 18 13:01:35.618470 2026] [security2:error] [pid 139043:tid 139232] [client 66.187.6.102:56358] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/acessorios"] [unique_id "aoSB3_2v-lWn9OzQT7USSgAAAMA"] [Tue Aug 18 13:01:35.622353 2026] [security2:error] [pid 139043:tid 139177] [client 20.127.136.245:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about/function.php"] [unique_id "aoSB3_2v-lWn9OzQT7USSwAAAIk"] [Tue Aug 18 13:01:35.628300 2026] [autoindex:error] [pid 139043:tid 139199] [client 20.79.204.6:2372] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:35.628908 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTAAAAMQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:35.631553 2026] [security2:error] [pid 123784:tid 123970] [client 20.163.43.14:8931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/222.php"] [unique_id "aoSB32wDnJBNj2tDbYYHsQAAADQ"] [Tue Aug 18 13:01:35.646476 2026] [security2:error] [pid 123784:tid 123950] [client 20.91.215.254:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/adminfuns.php"] [unique_id "aoSB32wDnJBNj2tDbYYHsgAAACA"] [Tue Aug 18 13:01:35.683830 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:8013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/Okxob.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTgAAAJM"] [Tue Aug 18 13:01:35.691195 2026] [security2:error] [pid 139043:tid 139197] [client 20.79.222.117:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cfdesmontagem.com.br"] [uri "/ajax.php"] [unique_id "aoSB3_2v-lWn9OzQT7USTwAAAJ0"] [Tue Aug 18 13:01:35.699343 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:49456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtAAAADE"] [Tue Aug 18 13:01:35.708943 2026] [security2:error] [pid 123784:tid 123984] [client 168.62.48.100:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtQAAAEI"] [Tue Aug 18 13:01:35.715280 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/st.php"] [unique_id "aoSB32wDnJBNj2tDbYYHtgAAG3I"] [Tue Aug 18 13:01:35.736008 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.122:58000] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:35.736460 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.122:58000] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:35.745495 2026] [autoindex:error] [pid 139043:tid 139128] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:35.761022 2026] [security2:error] [pid 139043:tid 139272] [client 20.75.92.165:4276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file5.php"] [unique_id "aoSB3_2v-lWn9OzQT7USUgAAAOg"] [Tue Aug 18 13:01:35.763541 2026] [security2:error] [pid 123784:tid 123918] [client 168.62.48.100:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSB32wDnJBNj2tDbYYHuwAAAAA"] [Tue Aug 18 13:01:35.765193 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:35.765616 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:35.790685 2026] [security2:error] [pid 123784:tid 123932] [client 20.116.17.175:3438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/accesson.php"] [unique_id "aoSB32wDnJBNj2tDbYYHvAAAAA4"] [Tue Aug 18 13:01:35.791697 2026] [security2:error] [pid 139043:tid 139285] [client 52.173.121.69:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSB3_2v-lWn9OzQT7USVgAAAPU"] [Tue Aug 18 13:01:35.792588 2026] [security2:error] [pid 139043:tid 139250] [client 20.100.169.31:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB3_2v-lWn9OzQT7USVwAAANI"] [Tue Aug 18 13:01:35.826951 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/12.php"] [unique_id "aoSB3_2v-lWn9OzQT7USWgAAAJk"] [Tue Aug 18 13:01:35.829117 2026] [security2:error] [pid 139043:tid 139260] [client 20.79.204.6:2372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB3_2v-lWn9OzQT7USWwAAANw"] [Tue Aug 18 13:01:35.861581 2026] [security2:error] [pid 139043:tid 139297] [client 20.102.65.165:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/chosen.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXAAAAQE"] [Tue Aug 18 13:01:35.868616 2026] [security2:error] [pid 123784:tid 123925] [client 20.80.111.3:31005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/h.php"] [unique_id "aoSB32wDnJBNj2tDbYYHvgAAAAc"] [Tue Aug 18 13:01:35.878199 2026] [security2:error] [pid 139043:tid 139178] [client 20.104.100.201:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-good.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXQAAAIo"] [Tue Aug 18 13:01:35.878276 2026] [security2:error] [pid 139043:tid 139242] [client 20.102.65.165:8542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/aa.php"] [unique_id "aoSB3_2v-lWn9OzQT7USXgAAAMo"] [Tue Aug 18 13:01:35.919966 2026] [security2:error] [pid 123784:tid 123943] [client 20.119.58.187:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/aa.php"] [unique_id "aoSB32wDnJBNj2tDbYYHzgAAABk"] [Tue Aug 18 13:01:35.924122 2026] [security2:error] [pid 139043:tid 139133] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB3_2v-lWn9OzQT7USYgAAqlk"] [Tue Aug 18 13:01:35.935222 2026] [security2:error] [pid 139043:tid 139247] [client 20.250.13.23:6847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/media-new.php"] [unique_id "aoSB3_2v-lWn9OzQT7USYwAAAM8"] [Tue Aug 18 13:01:35.936704 2026] [security2:error] [pid 123784:tid 124035] [client 20.151.109.219:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/uo.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0QAAAHU"] [Tue Aug 18 13:01:35.948796 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/le.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0gAAQVc"] [Tue Aug 18 13:01:35.962932 2026] [security2:error] [pid 123784:tid 123965] [client 20.163.43.14:8835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/chosen.php"] [unique_id "aoSB32wDnJBNj2tDbYYH0wAAAC8"] [Tue Aug 18 13:01:35.974106 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/term.php"] [unique_id "aoSB3_2v-lWn9OzQT7USZAAAANM"] [Tue Aug 18 13:01:35.975032 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/index/function.php"] [unique_id "aoSB32wDnJBNj2tDbYYH1AAAAF0"] [Tue Aug 18 13:01:35.995869 2026] [security2:error] [pid 123784:tid 123893] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/tes.php"] [unique_id "aoSB32wDnJBNj2tDbYYH1gAAR2g"] [Tue Aug 18 13:01:36.002869 2026] [security2:error] [pid 139043:tid 139261] [client 158.23.17.4:10953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/conn-test.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZQAAAN0"] [Tue Aug 18 13:01:36.006356 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZgAAAKM"] [Tue Aug 18 13:01:36.006422 2026] [security2:error] [pid 139043:tid 139264] [client 158.23.17.4:47899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/bm.php"] [unique_id "aoSB4P2v-lWn9OzQT7USZwAAAOA"] [Tue Aug 18 13:01:36.008483 2026] [security2:error] [pid 139043:tid 139255] [client 20.1.169.243:5804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB4P2v-lWn9OzQT7USaAAAANc"] [Tue Aug 18 13:01:36.023818 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:18089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSB4P2v-lWn9OzQT7USagAAAJA"] [Tue Aug 18 13:01:36.093164 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.112.14:22901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/dsd.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2QAAAGI"] [Tue Aug 18 13:01:36.145643 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/files/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2gAAYxo"] [Tue Aug 18 13:01:36.151778 2026] [autoindex:error] [pid 139043:tid 139134] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:36.162694 2026] [security2:error] [pid 123784:tid 123920] [client 20.75.92.165:4299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH2wAAAAI"] [Tue Aug 18 13:01:36.162709 2026] [security2:error] [pid 123784:tid 123869] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/hr.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH3AAAGFA"] [Tue Aug 18 13:01:36.185101 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:12244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4AAAAGQ"] [Tue Aug 18 13:01:36.193910 2026] [security2:error] [pid 123784:tid 124009] [client 20.79.204.6:10783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bolt.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4QAAAFs"] [Tue Aug 18 13:01:36.194747 2026] [security2:error] [pid 123784:tid 123958] [client 68.221.73.131:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/new.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4gAAACg"] [Tue Aug 18 13:01:36.204270 2026] [security2:error] [pid 139043:tid 139238] [client 158.158.74.177:18952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/st.php"] [unique_id "aoSB4P2v-lWn9OzQT7USbwAAAMY"] [Tue Aug 18 13:01:36.214657 2026] [security2:error] [pid 139043:tid 139227] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB4P2v-lWn9OzQT7UScQAAALs"] [Tue Aug 18 13:01:36.228690 2026] [security2:error] [pid 123784:tid 124023] [client 20.104.100.201:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wmore1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH4wAAAGk"] [Tue Aug 18 13:01:36.256009 2026] [security2:error] [pid 139043:tid 139268] [client 20.104.100.201:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/black.php"] [unique_id "aoSB4P2v-lWn9OzQT7UScwAAAOQ"] [Tue Aug 18 13:01:36.270206 2026] [security2:error] [pid 139043:tid 139290] [client 20.116.17.175:22986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/x1da.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdAAAAPo"] [Tue Aug 18 13:01:36.272005 2026] [security2:error] [pid 123784:tid 123971] [client 20.119.58.187:10119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/abc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH5QAAADU"] [Tue Aug 18 13:01:36.284808 2026] [security2:error] [pid 139043:tid 139237] [client 20.102.65.165:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wpxml.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdQAAAMU"] [Tue Aug 18 13:01:36.285809 2026] [security2:error] [pid 139043:tid 139208] [client 20.48.236.86:14801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdgAAAKg"] [Tue Aug 18 13:01:36.293859 2026] [security2:error] [pid 123784:tid 123847] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6AAAZzo"] [Tue Aug 18 13:01:36.294052 2026] [security2:error] [pid 123784:tid 123923] [client 20.151.109.219:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kx.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH5wAAAAU"] [Tue Aug 18 13:01:36.294079 2026] [security2:error] [pid 123784:tid 124030] [client 168.62.48.100:18169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6QAAAHA"] [Tue Aug 18 13:01:36.305910 2026] [security2:error] [pid 139043:tid 139239] [client 20.127.136.245:8973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/function/function.php"] [unique_id "aoSB4P2v-lWn9OzQT7USdwAAAMc"] [Tue Aug 18 13:01:36.308060 2026] [security2:error] [pid 123784:tid 123999] [client 20.80.111.3:39591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/import/csv1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH6gAAAFE"] [Tue Aug 18 13:01:36.318360 2026] [security2:error] [pid 139043:tid 139218] [client 20.163.43.14:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/info.php"] [unique_id "aoSB4P2v-lWn9OzQT7USeQAAALI"] [Tue Aug 18 13:01:36.332155 2026] [security2:error] [pid 139043:tid 139148] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSB4P2v-lWn9OzQT7USegAAmmg"] [Tue Aug 18 13:01:36.344234 2026] [security2:error] [pid 139043:tid 139204] [client 20.91.215.254:11607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/abc.php"] [unique_id "aoSB4P2v-lWn9OzQT7USewAAAKQ"] [Tue Aug 18 13:01:36.369559 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:36.369872 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:36.380884 2026] [security2:error] [pid 123784:tid 124007] [client 172.202.39.151:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/abc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH7gAAAFk"] [Tue Aug 18 13:01:36.388365 2026] [security2:error] [pid 139043:tid 139293] [client 85.204.70.114:57557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4P2v-lWn9OzQT7USfgAAAP0"] [Tue Aug 18 13:01:36.404608 2026] [security2:error] [pid 139043:tid 139267] [client 20.79.204.6:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSB4P2v-lWn9OzQT7USfwAAAOM"] [Tue Aug 18 13:01:36.438194 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:2203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH8AAAAF8"] [Tue Aug 18 13:01:36.439471 2026] [security2:error] [pid 139043:tid 139236] [client 20.251.112.238:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/file59.php"] [unique_id "aoSB4P2v-lWn9OzQT7USgAAAAMQ"] [Tue Aug 18 13:01:36.450776 2026] [security2:error] [pid 123784:tid 123826] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/images/images/about.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH8QAACyU"] [Tue Aug 18 13:01:36.472613 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/env.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9AAAAEw"] [Tue Aug 18 13:01:36.502547 2026] [security2:error] [pid 139043:tid 139266] [client 20.75.92.165:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USggAAAOI"] [Tue Aug 18 13:01:36.505844 2026] [security2:error] [pid 139043:tid 139139] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB4P2v-lWn9OzQT7USgwAAlF8"] [Tue Aug 18 13:01:36.505844 2026] [security2:error] [pid 123784:tid 123953] [client 20.118.133.132:25301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/file2.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9gAAACM"] [Tue Aug 18 13:01:36.510921 2026] [security2:error] [pid 139043:tid 139283] [client 223.185.37.47:14429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShAAAAPM"] [Tue Aug 18 13:01:36.511027 2026] [security2:error] [pid 139043:tid 139283] [client 223.185.37.47:14429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShAAAAPM"] [Tue Aug 18 13:01:36.518634 2026] [security2:error] [pid 139043:tid 139270] [client 158.23.17.4:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vu.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShQAAAOY"] [Tue Aug 18 13:01:36.528822 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/av.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH9wAAAE0"] [Tue Aug 18 13:01:36.537245 2026] [security2:error] [pid 139043:tid 139187] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/edit.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShgAAAJM"] [Tue Aug 18 13:01:36.537283 2026] [security2:error] [pid 123784:tid 123997] [client 20.104.100.201:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/special.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-AAAAE8"] [Tue Aug 18 13:01:36.539473 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/as.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-QAAAHc"] [Tue Aug 18 13:01:36.562596 2026] [security2:error] [pid 139043:tid 139190] [client 20.250.13.23:6802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSB4P2v-lWn9OzQT7UShwAAAJY"] [Tue Aug 18 13:01:36.602056 2026] [security2:error] [pid 123784:tid 123841] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH-wAANDQ"] [Tue Aug 18 13:01:36.626681 2026] [security2:error] [pid 139043:tid 139183] [client 20.119.58.187:10496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/av.php"] [unique_id "aoSB4P2v-lWn9OzQT7USigAAAI8"] [Tue Aug 18 13:01:36.627861 2026] [security2:error] [pid 139043:tid 139259] [client 168.62.48.100:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSB4P2v-lWn9OzQT7USiwAAANs"] [Tue Aug 18 13:01:36.640421 2026] [security2:error] [pid 139043:tid 139211] [client 20.102.65.165:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/adminner.php"] [unique_id "aoSB4P2v-lWn9OzQT7USjAAAAKs"] [Tue Aug 18 13:01:36.647958 2026] [security2:error] [pid 139043:tid 139195] [client 213.35.127.232:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB4P2v-lWn9OzQT7USjQAAAJs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:36.664559 2026] [security2:error] [pid 139043:tid 139260] [client 20.186.30.159:10081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/sf.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkAAAANw"] [Tue Aug 18 13:01:36.679750 2026] [security2:error] [pid 139043:tid 139120] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkQABAUw"] [Tue Aug 18 13:01:36.686494 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:36.686757 2026] [authz_core:error] [pid 123784:tid 123916] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:36.706699 2026] [security2:error] [pid 123784:tid 123798] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kt.php"] [unique_id "aoSB4GwDnJBNj2tDbYYH_gAAJQk"] [Tue Aug 18 13:01:36.706699 2026] [security2:error] [pid 139043:tid 139242] [client 168.62.48.100:17995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkgAAAMo"] [Tue Aug 18 13:01:36.745101 2026] [security2:error] [pid 139043:tid 139234] [client 20.1.169.243:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSB4P2v-lWn9OzQT7USkwAAAMI"] [Tue Aug 18 13:01:36.754618 2026] [security2:error] [pid 139043:tid 139282] [client 20.80.111.3:18456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/index.bak.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlQAAAPI"] [Tue Aug 18 13:01:36.763551 2026] [security2:error] [pid 123784:tid 123906] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/rip.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAAAAAHU"] [Tue Aug 18 13:01:36.771023 2026] [security2:error] [pid 139043:tid 139198] [client 20.151.109.219:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/va.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlgAAAJ4"] [Tue Aug 18 13:01:36.777280 2026] [security2:error] [pid 123784:tid 123981] [client 20.102.65.165:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/file1221.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAQAAAD8"] [Tue Aug 18 13:01:36.788828 2026] [security2:error] [pid 123784:tid 123932] [client 85.204.70.114:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elietecamargosadv.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAgAAAA4"] [Tue Aug 18 13:01:36.792299 2026] [security2:error] [pid 139043:tid 139175] [client 20.79.204.6:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/akc.php"] [unique_id "aoSB4P2v-lWn9OzQT7USlwAAAIc"] [Tue Aug 18 13:01:36.794959 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.112.14:13038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/c4.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIAwAAADs"] [Tue Aug 18 13:01:36.815339 2026] [security2:error] [pid 123784:tid 123991] [client 20.104.100.201:49463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/pucci.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBQAAAEk"] [Tue Aug 18 13:01:36.816887 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.56.190:47107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBgAAAAc"] [Tue Aug 18 13:01:36.827523 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ev.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIBwAAAEo"] [Tue Aug 18 13:01:36.839063 2026] [security2:error] [pid 123784:tid 123964] [client 20.100.169.31:24196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICAAAAC4"] [Tue Aug 18 13:01:36.845179 2026] [security2:error] [pid 139043:tid 139249] [client 20.163.43.14:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmQAAANE"] [Tue Aug 18 13:01:36.847682 2026] [security2:error] [pid 123784:tid 124015] [client 213.202.253.4:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/txets.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICQAAAGE"], referer: www.google.com [Tue Aug 18 13:01:36.850559 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/mcs.php"] [unique_id "aoSB4GwDnJBNj2tDbYYICgAAAGA"] [Tue Aug 18 13:01:36.852624 2026] [security2:error] [pid 139043:tid 139147] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmgAAw2c"] [Tue Aug 18 13:01:36.860736 2026] [security2:error] [pid 123784:tid 124002] [client 135.225.78.186:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/av.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIDAAAAFQ"] [Tue Aug 18 13:01:36.892578 2026] [security2:error] [pid 139043:tid 139181] [client 158.158.74.177:22869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSB4P2v-lWn9OzQT7USmwAAAI0"] [Tue Aug 18 13:01:36.905015 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/edit.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIDwAAAEE"] [Tue Aug 18 13:01:36.913896 2026] [security2:error] [pid 123784:tid 123965] [client 20.48.236.86:14466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEAAAAC8"] [Tue Aug 18 13:01:36.925399 2026] [security2:error] [pid 123784:tid 123948] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ff1.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEgAAAB4"] [Tue Aug 18 13:01:36.928057 2026] [security2:error] [pid 123784:tid 123989] [client 20.127.136.245:1276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIEwAAAEc"] [Tue Aug 18 13:01:36.934395 2026] [security2:error] [pid 139043:tid 139178] [client 20.79.204.6:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bthil.php"] [unique_id "aoSB4P2v-lWn9OzQT7USnQAAAIo"] [Tue Aug 18 13:01:36.967100 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:36.967366 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:36.977852 2026] [security2:error] [pid 123784:tid 123933] [client 20.119.58.187:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIFQAAAA8"] [Tue Aug 18 13:01:36.986022 2026] [security2:error] [pid 123784:tid 123952] [client 20.91.215.254:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSB4GwDnJBNj2tDbYYIFwAAACI"] [Tue Aug 18 13:01:37.008808 2026] [security2:error] [pid 123784:tid 123993] [client 20.79.204.6:11520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/akc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGAAAAEs"] [Tue Aug 18 13:01:37.012177 2026] [security2:error] [pid 123784:tid 123976] [client 20.104.100.201:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGQAAADo"] [Tue Aug 18 13:01:37.021173 2026] [security2:error] [pid 123784:tid 124022] [client 20.75.92.165:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIGgAAAGg"] [Tue Aug 18 13:01:37.028772 2026] [security2:error] [pid 139043:tid 139098] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB4f2v-lWn9OzQT7USngAApTY"] [Tue Aug 18 13:01:37.040773 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ic.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIHQAAAGM"] [Tue Aug 18 13:01:37.064487 2026] [autoindex:error] [pid 123784:tid 123936] [client 20.79.204.6:2226] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:37.075138 2026] [security2:error] [pid 123784:tid 123793] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIHwAAaQQ"] [Tue Aug 18 13:01:37.093117 2026] [security2:error] [pid 139043:tid 139191] [client 20.104.100.201:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wicked.php"] [unique_id "aoSB4f2v-lWn9OzQT7USnwAAAJc"] [Tue Aug 18 13:01:37.096312 2026] [security2:error] [pid 123784:tid 124041] [client 20.251.112.238:7142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/eauu.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIQAAAHs"] [Tue Aug 18 13:01:37.108846 2026] [security2:error] [pid 139043:tid 139174] [client 20.151.109.219:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fo.php"] [unique_id "aoSB4f2v-lWn9OzQT7USoQAAAIY"] [Tue Aug 18 13:01:37.134402 2026] [security2:error] [pid 123784:tid 123949] [client 52.173.121.69:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIgAAAB8"] [Tue Aug 18 13:01:37.166694 2026] [security2:error] [pid 139043:tid 139248] [client 20.102.65.165:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/nox.php"] [unique_id "aoSB4f2v-lWn9OzQT7USogAAANA"] [Tue Aug 18 13:01:37.174204 2026] [security2:error] [pid 123784:tid 124003] [client 20.163.43.14:8923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIIwAAAFU"] [Tue Aug 18 13:01:37.183035 2026] [security2:error] [pid 139043:tid 139179] [client 168.62.48.100:18007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/first.php"] [unique_id "aoSB4f2v-lWn9OzQT7USowAAAIs"] [Tue Aug 18 13:01:37.186058 2026] [security2:error] [pid 123784:tid 123920] [client 20.80.111.3:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/lite.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJAAAAAI"] [Tue Aug 18 13:01:37.190964 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJgAAAHk"] [Tue Aug 18 13:01:37.226592 2026] [security2:error] [pid 123784:tid 123828] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/moon.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIJwAAJyc"] [Tue Aug 18 13:01:37.228675 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:22866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/an7.php"] [unique_id "aoSB4f2v-lWn9OzQT7USpQAAAL4"] [Tue Aug 18 13:01:37.245211 2026] [security2:error] [pid 123784:tid 123870] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ww.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKAAAOVE"] [Tue Aug 18 13:01:37.264610 2026] [security2:error] [pid 139043:tid 139140] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB4f2v-lWn9OzQT7USpwABBGA"] [Tue Aug 18 13:01:37.265867 2026] [security2:error] [pid 123784:tid 123931] [client 20.79.204.6:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKgAAAA0"] [Tue Aug 18 13:01:37.270112 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:37.270386 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:37.308379 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/fff.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIKwAAAAs"] [Tue Aug 18 13:01:37.323480 2026] [security2:error] [pid 139043:tid 139186] [client 20.186.30.159:10003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/k.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqAAAAJI"] [Tue Aug 18 13:01:37.331371 2026] [security2:error] [pid 123784:tid 124007] [client 20.119.58.187:10485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/asus.php"] [unique_id "aoSB4WwDnJBNj2tDbYYILQAAAFk"] [Tue Aug 18 13:01:37.357160 2026] [security2:error] [pid 139043:tid 139208] [client 20.116.17.175:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/adminner.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqgAAAKg"] [Tue Aug 18 13:01:37.368712 2026] [security2:error] [pid 139043:tid 139228] [client 20.104.100.201:49091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/water.php"] [unique_id "aoSB4f2v-lWn9OzQT7USqwAAALw"] [Tue Aug 18 13:01:37.370890 2026] [security2:error] [pid 139043:tid 139218] [client 20.48.236.86:14485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrAAAALI"] [Tue Aug 18 13:01:37.375323 2026] [security2:error] [pid 123784:tid 123794] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/cache.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMAAATwU"] [Tue Aug 18 13:01:37.387708 2026] [security2:error] [pid 123784:tid 123953] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYILwAAIw8"] [Tue Aug 18 13:01:37.421321 2026] [security2:error] [pid 123784:tid 123972] [client 216.244.66.232:37446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMQAAADY"] [Tue Aug 18 13:01:37.421428 2026] [security2:error] [pid 123784:tid 123972] [client 216.244.66.232:37446] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMQAAADY"] [Tue Aug 18 13:01:37.423564 2026] [security2:error] [pid 139043:tid 139194] [client 20.127.136.245:8062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/f35.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrQAAAJo"] [Tue Aug 18 13:01:37.424699 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mo.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMgAAUD4"] [Tue Aug 18 13:01:37.431838 2026] [security2:error] [pid 139043:tid 139204] [client 68.221.73.131:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/apreset.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrgAAAKQ"] [Tue Aug 18 13:01:37.443808 2026] [security2:error] [pid 139043:tid 139126] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USrwAA7VI"] [Tue Aug 18 13:01:37.444374 2026] [security2:error] [pid 139043:tid 139292] [client 20.75.92.165:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/atomlib.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsAAAAPw"] [Tue Aug 18 13:01:37.460081 2026] [security2:error] [pid 123784:tid 123984] [client 20.116.17.175:53787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/kj.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIMwAAAEI"] [Tue Aug 18 13:01:37.471536 2026] [security2:error] [pid 123784:tid 124042] [client 20.104.100.201:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/thoms.php"] [unique_id "aoSB4WwDnJBNj2tDbYYINAAAAHw"] [Tue Aug 18 13:01:37.479490 2026] [security2:error] [pid 139043:tid 139268] [client 20.79.204.6:11681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/buy.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsQAAAOQ"] [Tue Aug 18 13:01:37.479828 2026] [security2:error] [pid 139043:tid 139245] [client 20.1.169.243:5800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-mail.php"] [unique_id "aoSB4f2v-lWn9OzQT7USsgAAAM0"] [Tue Aug 18 13:01:37.480695 2026] [security2:error] [pid 139043:tid 139200] [client 20.100.169.31:24250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4f2v-lWn9OzQT7USswAAAKA"] [Tue Aug 18 13:01:37.510676 2026] [security2:error] [pid 139043:tid 139215] [client 158.23.17.4:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xs.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStAAAAK8"] [Tue Aug 18 13:01:37.555347 2026] [security2:error] [pid 139043:tid 139236] [client 20.163.43.14:8938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/k.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStQAAAMQ"] [Tue Aug 18 13:01:37.556940 2026] [security2:error] [pid 123784:tid 124032] [client 37.40.227.74:57190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIOQAAAHI"] [Tue Aug 18 13:01:37.557044 2026] [security2:error] [pid 123784:tid 124032] [client 37.40.227.74:57190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIOQAAAHI"] [Tue Aug 18 13:01:37.572094 2026] [security2:error] [pid 139043:tid 139266] [client 85.204.70.114:60988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4f2v-lWn9OzQT7UStgAAAOI"] [Tue Aug 18 13:01:37.576965 2026] [security2:error] [pid 139043:tid 139206] [client 20.186.30.159:10021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/82.php"] [unique_id "aoSB4f2v-lWn9OzQT7UStwAAAKY"] [Tue Aug 18 13:01:37.586601 2026] [security2:error] [pid 139043:tid 139283] [client 158.23.17.4:31895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mz.php"] [unique_id "aoSB4f2v-lWn9OzQT7USuAAAAPM"] [Tue Aug 18 13:01:37.619458 2026] [security2:error] [pid 139043:tid 139131] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB4f2v-lWn9OzQT7USugAAk1c"] [Tue Aug 18 13:01:37.621244 2026] [security2:error] [pid 139043:tid 139213] [client 20.80.111.3:41256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/live.php"] [unique_id "aoSB4f2v-lWn9OzQT7USuwAAAK0"] [Tue Aug 18 13:01:37.625971 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ue.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPAAAAEk"] [Tue Aug 18 13:01:37.642009 2026] [security2:error] [pid 123784:tid 123919] [client 20.91.215.254:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPQAAAAE"] [Tue Aug 18 13:01:37.643205 2026] [security2:error] [pid 139043:tid 139197] [client 20.104.100.201:49420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fine.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvAAAAJ0"] [Tue Aug 18 13:01:37.663884 2026] [security2:error] [pid 123784:tid 123935] [client 213.35.127.232:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIPwAAABE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:37.685049 2026] [security2:error] [pid 139043:tid 139267] [client 20.79.204.6:11577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/buy.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvQAAAOM"] [Tue Aug 18 13:01:37.685187 2026] [security2:error] [pid 139043:tid 139199] [client 20.119.58.187:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USvgAAAJ8"] [Tue Aug 18 13:01:37.688765 2026] [security2:error] [pid 123784:tid 123992] [client 168.62.48.100:18080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIQQAAAEo"] [Tue Aug 18 13:01:37.710599 2026] [security2:error] [pid 123784:tid 123970] [client 158.158.74.177:22873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-configs.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIQwAAADQ"] [Tue Aug 18 13:01:37.724839 2026] [security2:error] [pid 139043:tid 139279] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/inputs.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwAAAAO8"] [Tue Aug 18 13:01:37.761449 2026] [security2:error] [pid 139043:tid 139259] [client 20.102.65.165:3061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/akismet.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwQAAANs"] [Tue Aug 18 13:01:37.785794 2026] [security2:error] [pid 139043:tid 139260] [client 20.75.92.165:4338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/min.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwgAAANw"] [Tue Aug 18 13:01:37.792683 2026] [security2:error] [pid 123784:tid 123943] [client 135.225.78.186:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/images.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIRwAAABk"] [Tue Aug 18 13:01:37.794755 2026] [security2:error] [pid 139043:tid 139154] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB4f2v-lWn9OzQT7USwwABAW4"] [Tue Aug 18 13:01:37.821193 2026] [security2:error] [pid 123784:tid 123965] [client 172.202.39.151:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/akcc.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISAAAAC8"] [Tue Aug 18 13:01:37.843201 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.112.14:34213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bsg-management/php.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISgAAAB4"] [Tue Aug 18 13:01:37.844234 2026] [security2:error] [pid 123784:tid 124015] [client 20.1.169.243:5812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-the.php"] [unique_id "aoSB4WwDnJBNj2tDbYYISwAAAGE"] [Tue Aug 18 13:01:37.855935 2026] [security2:error] [pid 123784:tid 123977] [client 20.250.13.23:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSB4WwDnJBNj2tDbYYITQAAADs"] [Tue Aug 18 13:01:37.869236 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:37.869506 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:37.890932 2026] [autoindex:error] [pid 123784:tid 124025] [client 20.79.204.6:2625] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:37.917089 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSB4f2v-lWn9OzQT7USyAAAALk"] [Tue Aug 18 13:01:37.918031 2026] [security2:error] [pid 139043:tid 139175] [client 20.104.100.201:49683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/loader.php"] [unique_id "aoSB4f2v-lWn9OzQT7USyQAAAIc"] [Tue Aug 18 13:01:37.940281 2026] [security2:error] [pid 139043:tid 139202] [client 20.251.112.238:20210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/dsd.php"] [unique_id "aoSB4f2v-lWn9OzQT7USygAAAKI"] [Tue Aug 18 13:01:37.968281 2026] [security2:error] [pid 139043:tid 139251] [client 85.204.70.114:32768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4f2v-lWn9OzQT7USywAAANM"] [Tue Aug 18 13:01:37.969672 2026] [security2:error] [pid 139043:tid 139157] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB4f2v-lWn9OzQT7USzAAAqXE"] [Tue Aug 18 13:01:37.975419 2026] [security2:error] [pid 139043:tid 139153] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB4f2v-lWn9OzQT7USzQAA0W0"] [Tue Aug 18 13:01:37.997029 2026] [security2:error] [pid 123784:tid 123889] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qr.php"] [unique_id "aoSB4WwDnJBNj2tDbYYIUwAAHWQ"] [Tue Aug 18 13:01:38.015611 2026] [security2:error] [pid 123784:tid 123848] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVAAAEjs"] [Tue Aug 18 13:01:38.017771 2026] [security2:error] [pid 123784:tid 123911] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVQAAW3o"] [Tue Aug 18 13:01:38.036349 2026] [security2:error] [pid 139043:tid 139159] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/media.php"] [unique_id "aoSB4v2v-lWn9OzQT7USzwAA4HM"] [Tue Aug 18 13:01:38.037220 2026] [security2:error] [pid 139043:tid 139275] [client 20.119.58.187:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/atomlib.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0AAAAOs"] [Tue Aug 18 13:01:38.054268 2026] [security2:error] [pid 123784:tid 123898] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/admin.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVgAAFm0"] [Tue Aug 18 13:01:38.059985 2026] [security2:error] [pid 123784:tid 123993] [client 20.80.111.3:18449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bypass.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIVwAAAEs"] [Tue Aug 18 13:01:38.060882 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:10004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/dex.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0QAAAKM"] [Tue Aug 18 13:01:38.068983 2026] [security2:error] [pid 123784:tid 124038] [client 20.163.43.14:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/403.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIWAAAAHg"] [Tue Aug 18 13:01:38.075443 2026] [security2:error] [pid 123784:tid 123988] [client 20.151.109.219:14111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/loading.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIWwAAAEY"] [Tue Aug 18 13:01:38.086471 2026] [security2:error] [pid 123784:tid 123952] [client 20.79.204.6:11691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/cong.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXAAAACI"] [Tue Aug 18 13:01:38.089367 2026] [security2:error] [pid 123784:tid 123892] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/mac.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXQAAPWc"] [Tue Aug 18 13:01:38.090754 2026] [security2:error] [pid 123784:tid 123956] [client 20.79.204.6:2625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIXgAAACY"] [Tue Aug 18 13:01:38.103096 2026] [security2:error] [pid 139043:tid 139294] [client 20.75.92.165:4341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/mac.php"] [unique_id "aoSB4v2v-lWn9OzQT7US0wAAAP4"] [Tue Aug 18 13:01:38.116764 2026] [security2:error] [pid 139043:tid 139047] [remote 191.237.254.161:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1AABAwM"] [Tue Aug 18 13:01:38.116854 2026] [security2:error] [pid 139043:tid 139047] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1AABAwM"] [Tue Aug 18 13:01:38.119119 2026] [security2:error] [pid 139043:tid 139184] [client 20.102.65.165:2991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1QAAAJA"] [Tue Aug 18 13:01:38.133071 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1gAAANU"] [Tue Aug 18 13:01:38.140022 2026] [security2:error] [pid 123784:tid 123829] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/coffee.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIYAAAeyg"] [Tue Aug 18 13:01:38.147684 2026] [security2:error] [pid 139043:tid 139151] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB4v2v-lWn9OzQT7US1wAAyWs"] [Tue Aug 18 13:01:38.165612 2026] [security2:error] [pid 123784:tid 123858] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIYgAAH0U"] [Tue Aug 18 13:01:38.172535 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:38.172798 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:38.177969 2026] [security2:error] [pid 139043:tid 139191] [client 20.116.17.175:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2AAAAJc"] [Tue Aug 18 13:01:38.195801 2026] [security2:error] [pid 139043:tid 139149] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2QAA1mk"] [Tue Aug 18 13:01:38.198085 2026] [security2:error] [pid 139043:tid 139269] [client 20.104.100.201:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/zero.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2gAAAOU"] [Tue Aug 18 13:01:38.198907 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lr.php"] [unique_id "aoSB4v2v-lWn9OzQT7US2wAAAME"] [Tue Aug 18 13:01:38.207916 2026] [security2:error] [pid 139043:tid 139176] [client 20.1.169.243:5791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3AAAAIg"] [Tue Aug 18 13:01:38.227156 2026] [security2:error] [pid 139043:tid 139248] [client 20.79.204.6:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/x.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3QAAANA"] [Tue Aug 18 13:01:38.233261 2026] [security2:error] [pid 139043:tid 139179] [client 172.202.39.151:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wk/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3gAAAIs"] [Tue Aug 18 13:01:38.233381 2026] [security2:error] [pid 139043:tid 139182] [client 168.62.48.100:18092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US3wAAAI4"] [Tue Aug 18 13:01:38.257684 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.112.14:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/byp8.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIZgAAACc"] [Tue Aug 18 13:01:38.269640 2026] [security2:error] [pid 123784:tid 123931] [client 20.104.100.201:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/root.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIZwAAAA0"] [Tue Aug 18 13:01:38.270519 2026] [security2:error] [pid 123784:tid 123790] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/yj09.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIaAAAcwE"] [Tue Aug 18 13:01:38.286119 2026] [security2:error] [pid 139043:tid 139255] [client 20.79.204.6:11569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/cong.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4AAAANc"] [Tue Aug 18 13:01:38.307213 2026] [security2:error] [pid 123784:tid 123864] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/scxy.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIagAAWUs"] [Tue Aug 18 13:01:38.318734 2026] [security2:error] [pid 139043:tid 139296] [client 20.91.215.254:27116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/u.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4QAAAQA"] [Tue Aug 18 13:01:38.324015 2026] [security2:error] [pid 139043:tid 139162] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7US4wABAnY"] [Tue Aug 18 13:01:38.325875 2026] [security2:error] [pid 139043:tid 139169] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSB4v2v-lWn9OzQT7US5AAA6n0"] [Tue Aug 18 13:01:38.327797 2026] [security2:error] [pid 123784:tid 124045] [client 20.100.169.31:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbAAAAH8"] [Tue Aug 18 13:01:38.330359 2026] [security2:error] [pid 123784:tid 123891] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbQAAJGY"] [Tue Aug 18 13:01:38.342122 2026] [security2:error] [pid 123784:tid 123995] [client 20.186.30.159:9999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/puc.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbgAAAE0"] [Tue Aug 18 13:01:38.352734 2026] [security2:error] [pid 123784:tid 123791] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIbwAAIwI"] [Tue Aug 18 13:01:38.353904 2026] [security2:error] [pid 139043:tid 139208] [client 85.204.70.114:32770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4v2v-lWn9OzQT7US5QAAAKg"] [Tue Aug 18 13:01:38.363086 2026] [security2:error] [pid 123784:tid 123972] [client 20.116.17.175:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/dragonshell.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIcAAAADY"] [Tue Aug 18 13:01:38.391876 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.98.162:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/gm.php"] [unique_id "aoSB4v2v-lWn9OzQT7US5wAAAMc"] [Tue Aug 18 13:01:38.391911 2026] [security2:error] [pid 139043:tid 139227] [client 20.119.58.187:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSB4v2v-lWn9OzQT7US5gAAALs"] [Tue Aug 18 13:01:38.398334 2026] [security2:error] [pid 123784:tid 123860] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/blurbs.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIcwAAMUc"] [Tue Aug 18 13:01:38.401669 2026] [security2:error] [pid 139043:tid 139243] [client 158.158.74.177:9244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-post.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6AAAAMs"] [Tue Aug 18 13:01:38.413066 2026] [security2:error] [pid 139043:tid 139218] [client 20.75.92.165:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/nc4.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6QAAALI"] [Tue Aug 18 13:01:38.426100 2026] [security2:error] [pid 139043:tid 139164] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/bajah.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6gAApHg"] [Tue Aug 18 13:01:38.445262 2026] [security2:error] [pid 139043:tid 139277] [client 20.151.109.219:60887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ke.php"] [unique_id "aoSB4v2v-lWn9OzQT7US6wAAAO0"] [Tue Aug 18 13:01:38.456095 2026] [security2:error] [pid 139043:tid 139268] [client 20.48.236.86:14825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/sky.php"] [unique_id "aoSB4v2v-lWn9OzQT7US7gAAAOQ"] [Tue Aug 18 13:01:38.463657 2026] [security2:error] [pid 123784:tid 123888] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/domvf.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIdAAAfGM"] [Tue Aug 18 13:01:38.470903 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:38.471149 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:38.475971 2026] [security2:error] [pid 139043:tid 139215] [client 20.104.100.201:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/002.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8AAAAK8"] [Tue Aug 18 13:01:38.480046 2026] [security2:error] [pid 123784:tid 123882] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/o.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIdgAAQ10"] [Tue Aug 18 13:01:38.489057 2026] [security2:error] [pid 139043:tid 139177] [client 20.102.65.165:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ajax.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8QAAAIk"] [Tue Aug 18 13:01:38.492083 2026] [security2:error] [pid 139043:tid 139252] [client 20.250.13.23:6784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8gAAANQ"] [Tue Aug 18 13:01:38.494400 2026] [security2:error] [pid 123784:tid 123871] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fpwch.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIeAAAA1I"] [Tue Aug 18 13:01:38.500482 2026] [security2:error] [pid 139043:tid 139161] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB4v2v-lWn9OzQT7US8wAA4nU"] [Tue Aug 18 13:01:38.512313 2026] [security2:error] [pid 139043:tid 139137] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/adminner.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9AAAk10"] [Tue Aug 18 13:01:38.520390 2026] [security2:error] [pid 139043:tid 139210] [client 196.12.128.158:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9QAAAKo"] [Tue Aug 18 13:01:38.520541 2026] [security2:error] [pid 139043:tid 139210] [client 196.12.128.158:55797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7US9QAAAKo"] [Tue Aug 18 13:01:38.529847 2026] [security2:error] [pid 123784:tid 123846] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/abcd.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIegAAcjk"] [Tue Aug 18 13:01:38.546577 2026] [security2:error] [pid 123784:tid 123894] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/simple.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIewAAP2k"] [Tue Aug 18 13:01:38.562872 2026] [security2:error] [pid 123784:tid 123839] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dirs.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfQAATDI"] [Tue Aug 18 13:01:38.568867 2026] [security2:error] [pid 123784:tid 123974] [client 20.104.100.201:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/fpwch.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfgAAADg"] [Tue Aug 18 13:01:38.573148 2026] [security2:error] [pid 139043:tid 139171] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-manager.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-AAAnH8"] [Tue Aug 18 13:01:38.576616 2026] [security2:error] [pid 139043:tid 139291] [client 20.1.169.243:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wso.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-QAAAPs"] [Tue Aug 18 13:01:38.586102 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/lite.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-gAAAJ8"] [Tue Aug 18 13:01:38.599389 2026] [security2:error] [pid 123784:tid 123905] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/xiugai.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIfwAASXQ"] [Tue Aug 18 13:01:38.616204 2026] [security2:error] [pid 139043:tid 139286] [client 20.251.112.238:33941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/c4.php"] [unique_id "aoSB4v2v-lWn9OzQT7US-wAAAPY"] [Tue Aug 18 13:01:38.616684 2026] [security2:error] [pid 123784:tid 123881] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wp-load.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIgAAAB1w"] [Tue Aug 18 13:01:38.629967 2026] [security2:error] [pid 123784:tid 123910] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/bb.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIgQAAAXk"] [Tue Aug 18 13:01:38.638093 2026] [security2:error] [pid 123784:tid 124010] [client 20.186.30.159:9984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/inso.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIggAAAFw"] [Tue Aug 18 13:01:38.641903 2026] [security2:error] [pid 139043:tid 139142] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/155.php"] [unique_id "aoSB4v2v-lWn9OzQT7US_QAAq2I"] [Tue Aug 18 13:01:38.647127 2026] [security2:error] [pid 139043:tid 139263] [client 20.102.65.165:8485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/img.php"] [unique_id "aoSB4v2v-lWn9OzQT7US_gAAAN8"] [Tue Aug 18 13:01:38.676974 2026] [security2:error] [pid 139043:tid 139195] [client 68.221.73.131:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1mage.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTAAAAAJs"] [Tue Aug 18 13:01:38.683393 2026] [security2:error] [pid 123784:tid 123997] [client 213.35.127.232:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIhAAAAE8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:38.688510 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:11532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTAwAAAMQ"] [Tue Aug 18 13:01:38.690532 2026] [authz_core:error] [pid 139043:tid 139048] [remote 20.79.204.6:0] AH01630: client denied by server configuration: /home2/dtbbrasilcom/public_html/wp-content/uploads/index.php [Tue Aug 18 13:01:38.697871 2026] [security2:error] [pid 139043:tid 139189] [client 20.79.204.6:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBAAAAJU"] [Tue Aug 18 13:01:38.701757 2026] [security2:error] [pid 139043:tid 139235] [client 197.184.64.235:41964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBQAAAMM"] [Tue Aug 18 13:01:38.701860 2026] [security2:error] [pid 139043:tid 139235] [client 197.184.64.235:41964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBQAAAMM"] [Tue Aug 18 13:01:38.703228 2026] [security2:error] [pid 123784:tid 123850] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/index.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIhgAASj0"] [Tue Aug 18 13:01:38.735656 2026] [security2:error] [pid 123784:tid 123792] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/aaa.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIiAAAZgM"] [Tue Aug 18 13:01:38.742067 2026] [security2:error] [pid 139043:tid 139257] [client 20.127.136.245:23221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/gg.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTBwAAANk"] [Tue Aug 18 13:01:38.745692 2026] [security2:error] [pid 139043:tid 139282] [client 85.204.70.114:32780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4v2v-lWn9OzQT7UTCAAAAPI"] [Tue Aug 18 13:01:38.746803 2026] [security2:error] [pid 139043:tid 139265] [client 20.119.58.187:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/b.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCQAAAOE"] [Tue Aug 18 13:01:38.758041 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/zxz.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCgAAAIU"] [Tue Aug 18 13:01:38.767043 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:39298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nh.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTCwAAALk"] [Tue Aug 18 13:01:38.773090 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:38.773371 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:38.784950 2026] [security2:error] [pid 123784:tid 123806] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIigAAThE"] [Tue Aug 18 13:01:38.786326 2026] [security2:error] [pid 139043:tid 139054] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/FWAZ.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDAAAyAo"] [Tue Aug 18 13:01:38.789552 2026] [security2:error] [pid 139043:tid 139261] [client 20.102.65.165:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lpcor.com.br"] [uri "/abcd.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDQAAAN0"] [Tue Aug 18 13:01:38.804200 2026] [security2:error] [pid 123784:tid 123915] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/site.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIiwAAdX4"] [Tue Aug 18 13:01:38.808215 2026] [security2:error] [pid 139043:tid 139209] [client 52.173.121.69:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTDgAAAKk"] [Tue Aug 18 13:01:38.827029 2026] [security2:error] [pid 123784:tid 123859] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/ccc.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIjAAAQUY"] [Tue Aug 18 13:01:38.828220 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:8847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/gecko.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEAAAAJE"] [Tue Aug 18 13:01:38.841075 2026] [security2:error] [pid 139043:tid 139181] [client 20.48.236.86:14465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file5.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEQAAAI0"] [Tue Aug 18 13:01:38.855183 2026] [security2:error] [pid 139043:tid 139052] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/admin.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTEgAA_gg"] [Tue Aug 18 13:01:38.862208 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:15148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ka.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIjwAAAB4"] [Tue Aug 18 13:01:38.870382 2026] [security2:error] [pid 123784:tid 123989] [client 20.104.100.201:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/mg.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkAAAAEc"] [Tue Aug 18 13:01:38.875504 2026] [security2:error] [pid 123784:tid 123887] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/reviall.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkQAAU2I"] [Tue Aug 18 13:01:38.888870 2026] [authz_core:error] [pid 139043:tid 139051] [remote 20.79.204.6:0] AH01630: client denied by server configuration: /home2/dtbbrasilcom/public_html/wp-content/uploads/2025/index.php [Tue Aug 18 13:01:38.890063 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIkgAAAH0"] [Tue Aug 18 13:01:38.892069 2026] [security2:error] [pid 123784:tid 123977] [client 216.244.66.243:51274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/exus+mais+perigosos-3/"] [unique_id "aoSB4mwDnJBNj2tDbYYIkwAAADs"] [Tue Aug 18 13:01:38.892182 2026] [security2:error] [pid 123784:tid 123977] [client 216.244.66.243:51274] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/exus+mais+perigosos-3/"] [unique_id "aoSB4mwDnJBNj2tDbYYIkwAAADs"] [Tue Aug 18 13:01:38.893154 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:11655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/css/classwithtostring.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFAAAAPg"] [Tue Aug 18 13:01:38.895457 2026] [security2:error] [pid 123784:tid 123813] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/nope.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlAAAcRg"] [Tue Aug 18 13:01:38.915278 2026] [security2:error] [pid 123784:tid 124025] [client 20.80.111.3:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/lock360.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlQAAAGs"] [Tue Aug 18 13:01:38.915282 2026] [security2:error] [pid 139043:tid 139156] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/nope.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFQAA-XA"] [Tue Aug 18 13:01:38.916296 2026] [security2:error] [pid 139043:tid 139205] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFgAAAKU"] [Tue Aug 18 13:01:38.939631 2026] [security2:error] [pid 139043:tid 139269] [client 158.23.17.4:12517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ft.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTFwAAAOU"] [Tue Aug 18 13:01:38.941161 2026] [security2:error] [pid 139043:tid 139273] [client 20.1.169.243:5816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/www.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTGAAAAOk"] [Tue Aug 18 13:01:38.950716 2026] [security2:error] [pid 123784:tid 123797] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/new.php"] [unique_id "aoSB4mwDnJBNj2tDbYYIlwAAOgg"] [Tue Aug 18 13:01:38.974221 2026] [security2:error] [pid 123784:tid 123886] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/new.php"] [unique_id "aoSB4mwDnJBNj2tDbYYImAAAHGE"] [Tue Aug 18 13:01:38.979015 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.112.14:34221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/plugins.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHAAAAIg"] [Tue Aug 18 13:01:38.993946 2026] [security2:error] [pid 139043:tid 139059] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/apreset.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHQAA0A8"] [Tue Aug 18 13:01:38.999321 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.56.190:47153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/routes.php"] [unique_id "aoSB4v2v-lWn9OzQT7UTHgAAAKE"] [Tue Aug 18 13:01:39.000149 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:10372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/index/function.php"] [unique_id "aoSB4mwDnJBNj2tDbYYImgAAAFQ"] [Tue Aug 18 13:01:39.021599 2026] [security2:error] [pid 123784:tid 123941] [client 20.75.92.165:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/as.php"] [unique_id "aoSB42wDnJBNj2tDbYYImwAAABc"] [Tue Aug 18 13:01:39.023622 2026] [security2:error] [pid 123784:tid 123990] [client 102.213.179.104:50872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYInAAAAEg"] [Tue Aug 18 13:01:39.023745 2026] [security2:error] [pid 123784:tid 123990] [client 102.213.179.104:50872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYInAAAAEg"] [Tue Aug 18 13:01:39.036856 2026] [security2:error] [pid 123784:tid 123927] [client 20.104.100.201:49414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/memberfuns.php"] [unique_id "aoSB42wDnJBNj2tDbYYInQAAAAk"] [Tue Aug 18 13:01:39.042488 2026] [security2:error] [pid 123784:tid 123863] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1mage.php"] [unique_id "aoSB42wDnJBNj2tDbYYIngAAY0o"] [Tue Aug 18 13:01:39.062641 2026] [security2:error] [pid 123784:tid 123947] [client 20.151.109.219:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/oo.php"] [unique_id "aoSB42wDnJBNj2tDbYYInwAAAB0"] [Tue Aug 18 13:01:39.064882 2026] [security2:error] [pid 139043:tid 139270] [client 158.158.74.177:9279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIAAAAOY"] [Tue Aug 18 13:01:39.065009 2026] [security2:error] [pid 123784:tid 123861] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/imsc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIoAAALEg"] [Tue Aug 18 13:01:39.074143 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/png.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIQAAAQA"] [Tue Aug 18 13:01:39.076219 2026] [security2:error] [pid 139043:tid 139062] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIgABAhI"] [Tue Aug 18 13:01:39.080433 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:39.080757 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:39.084026 2026] [security2:error] [pid 139043:tid 139168] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/imscjpg.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTIwAA6nw"] [Tue Aug 18 13:01:39.097943 2026] [security2:error] [pid 123784:tid 123907] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIogAAEnY"] [Tue Aug 18 13:01:39.098694 2026] [security2:error] [pid 123784:tid 124016] [client 20.119.58.187:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/buy.php"] [unique_id "aoSB42wDnJBNj2tDbYYIowAAAGI"] [Tue Aug 18 13:01:39.120728 2026] [security2:error] [pid 123784:tid 123913] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/qlex1.php"] [unique_id "aoSB42wDnJBNj2tDbYYIpAAAW3w"] [Tue Aug 18 13:01:39.133735 2026] [security2:error] [pid 139043:tid 139239] [client 85.204.70.114:32786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4_2v-lWn9OzQT7UTJQAAAMc"] [Tue Aug 18 13:01:39.134794 2026] [security2:error] [pid 139043:tid 139227] [client 168.62.48.100:18032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTJgAAALs"] [Tue Aug 18 13:01:39.139085 2026] [security2:error] [pid 123784:tid 123933] [client 20.250.13.23:6800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/ebs.php7"] [unique_id "aoSB42wDnJBNj2tDbYYIpgAAAA8"] [Tue Aug 18 13:01:39.146275 2026] [security2:error] [pid 123784:tid 123883] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/mariju.php"] [unique_id "aoSB42wDnJBNj2tDbYYIpwAAel4"] [Tue Aug 18 13:01:39.160131 2026] [security2:error] [pid 139043:tid 139219] [client 20.251.112.238:18217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/an7.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKAAAALM"] [Tue Aug 18 13:01:39.161577 2026] [security2:error] [pid 139043:tid 139277] [client 20.100.169.31:4316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKQAAAO0"] [Tue Aug 18 13:01:39.179506 2026] [security2:error] [pid 139043:tid 139166] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKgAAzXo"] [Tue Aug 18 13:01:39.182343 2026] [security2:error] [pid 139043:tid 139287] [client 20.91.215.254:27092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/customize.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTKwAAAPc"] [Tue Aug 18 13:01:39.184568 2026] [security2:error] [pid 139043:tid 139200] [client 20.186.30.159:9996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLAAAAKA"] [Tue Aug 18 13:01:39.198217 2026] [security2:error] [pid 123784:tid 123857] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/contacto.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqQAAeEQ"] [Tue Aug 18 13:01:39.222932 2026] [security2:error] [pid 123784:tid 123904] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/image2.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqgAAUnM"] [Tue Aug 18 13:01:39.244065 2026] [security2:error] [pid 139043:tid 139252] [client 20.104.100.201:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/reop3.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLQAAANQ"] [Tue Aug 18 13:01:39.244852 2026] [security2:error] [pid 123784:tid 123809] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIqwAAexQ"] [Tue Aug 18 13:01:39.250125 2026] [security2:error] [pid 139043:tid 139160] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLgAApnQ"] [Tue Aug 18 13:01:39.251048 2026] [security2:error] [pid 139043:tid 139081] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fb.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTLwAAjCU"] [Tue Aug 18 13:01:39.261856 2026] [security2:error] [pid 139043:tid 139197] [client 20.48.236.86:14519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/xyn.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMAAAAJ0"] [Tue Aug 18 13:01:39.268166 2026] [security2:error] [pid 139043:tid 139210] [client 20.116.17.175:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/setup-config.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMQAAAKo"] [Tue Aug 18 13:01:39.269773 2026] [security2:error] [pid 123784:tid 123880] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/gi.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrAAAKls"] [Tue Aug 18 13:01:39.287661 2026] [security2:error] [pid 123784:tid 123872] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/video.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrQAAZ1M"] [Tue Aug 18 13:01:39.295744 2026] [security2:error] [pid 123784:tid 123923] [client 135.225.78.186:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/ops.php"] [unique_id "aoSB42wDnJBNj2tDbYYIrwAAAAU"] [Tue Aug 18 13:01:39.300088 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/rip.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMgAAAJQ"] [Tue Aug 18 13:01:39.302647 2026] [security2:error] [pid 139043:tid 139237] [client 20.79.204.6:11710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/db.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTMwAAAMU"] [Tue Aug 18 13:01:39.306614 2026] [security2:error] [pid 139043:tid 139258] [client 20.1.169.243:5822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/x.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNAAAANo"] [Tue Aug 18 13:01:39.315631 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNQAAAOM"] [Tue Aug 18 13:01:39.320590 2026] [security2:error] [pid 139043:tid 139102] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/hel.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNgAAnzo"] [Tue Aug 18 13:01:39.321488 2026] [security2:error] [pid 139043:tid 139208] [client 20.79.204.6:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTNwAAAKg"] [Tue Aug 18 13:01:39.331147 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:8860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/aa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTOAAAAO8"] [Tue Aug 18 13:01:39.338333 2026] [security2:error] [pid 123784:tid 123817] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/grok.php"] [unique_id "aoSB42wDnJBNj2tDbYYIsAAAURw"] [Tue Aug 18 13:01:39.359128 2026] [security2:error] [pid 123784:tid 123821] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/indes.php"] [unique_id "aoSB42wDnJBNj2tDbYYIswAAaCA"] [Tue Aug 18 13:01:39.376162 2026] [security2:error] [pid 139043:tid 139097] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/tTPcH.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTOgAA7jU"] [Tue Aug 18 13:01:39.396159 2026] [security2:error] [pid 123784:tid 123795] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/file.php"] [unique_id "aoSB42wDnJBNj2tDbYYItAAAagY"] [Tue Aug 18 13:01:39.397856 2026] [security2:error] [pid 123784:tid 123856] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/bs1.php"] [unique_id "aoSB42wDnJBNj2tDbYYItQAAJ0M"] [Tue Aug 18 13:01:39.409263 2026] [security2:error] [pid 123784:tid 123975] [client 20.151.109.219:39358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ja.php"] [unique_id "aoSB42wDnJBNj2tDbYYItgAAADk"] [Tue Aug 18 13:01:39.426912 2026] [security2:error] [pid 123784:tid 123789] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/hp2.php"] [unique_id "aoSB42wDnJBNj2tDbYYIuAAADQA"] [Tue Aug 18 13:01:39.436963 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ot.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPAAAAOE"] [Tue Aug 18 13:01:39.445768 2026] [autoindex:error] [pid 139043:tid 139103] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:39.452246 2026] [security2:error] [pid 139043:tid 139145] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/yb.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPQAAuWU"] [Tue Aug 18 13:01:39.460806 2026] [security2:error] [pid 139043:tid 139286] [client 20.119.58.187:10463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bless.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPgAAAPY"] [Tue Aug 18 13:01:39.464253 2026] [security2:error] [pid 123784:tid 124013] [client 68.221.73.131:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/imsc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIuwAAAF8"] [Tue Aug 18 13:01:39.492230 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sn.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvQAAWXI"] [Tue Aug 18 13:01:39.492626 2026] [security2:error] [pid 123784:tid 123832] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/vc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvgAAfys"] [Tue Aug 18 13:01:39.508575 2026] [security2:error] [pid 139043:tid 139261] [client 20.186.30.159:10107] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "marquesti.fabioweb.com.br"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPwAAAN0"] [Tue Aug 18 13:01:39.508693 2026] [security2:error] [pid 139043:tid 139261] [client 20.186.30.159:10107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTPwAAAN0"] [Tue Aug 18 13:01:39.529518 2026] [security2:error] [pid 139043:tid 139276] [client 85.204.70.114:32802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSB4_2v-lWn9OzQT7UTQAAAAOw"] [Tue Aug 18 13:01:39.531411 2026] [security2:error] [pid 123784:tid 123845] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/pema.php"] [unique_id "aoSB42wDnJBNj2tDbYYIvwAATTg"] [Tue Aug 18 13:01:39.534316 2026] [security2:error] [pid 139043:tid 139264] [client 20.127.136.245:8025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/class.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQQAAAOA"] [Tue Aug 18 13:01:39.555550 2026] [security2:error] [pid 123784:tid 123885] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/epinyins.php"] [unique_id "aoSB42wDnJBNj2tDbYYIwAAANmA"] [Tue Aug 18 13:01:39.557686 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:11677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/db.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQgAAAJY"] [Tue Aug 18 13:01:39.559367 2026] [security2:error] [pid 139043:tid 139110] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/sh.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTQwAAo0I"] [Tue Aug 18 13:01:39.583252 2026] [security2:error] [pid 139043:tid 139299] [client 20.104.100.201:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/php5.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRAAAAQM"] [Tue Aug 18 13:01:39.590903 2026] [security2:error] [pid 139043:tid 139178] [client 20.104.100.201:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/echkm.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRQAAAIo"] [Tue Aug 18 13:01:39.599273 2026] [security2:error] [pid 139043:tid 139231] [client 20.75.92.165:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/k.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTRgAAAL8"] [Tue Aug 18 13:01:39.622361 2026] [security2:error] [pid 139043:tid 139289] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/update/da222.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSAAAAPk"] [Tue Aug 18 13:01:39.634149 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/h.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSgAAAOk"] [Tue Aug 18 13:01:39.636509 2026] [autoindex:error] [pid 139043:tid 139058] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:39.636908 2026] [security2:error] [pid 139043:tid 139234] [client 20.102.65.165:8454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/222.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTSwAAAMI"] [Tue Aug 18 13:01:39.640461 2026] [security2:error] [pid 139043:tid 139247] [client 20.251.112.238:26141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTAAAAM8"] [Tue Aug 18 13:01:39.661879 2026] [security2:error] [pid 139043:tid 139176] [client 172.202.39.151:61736] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.sfcacessorios.com"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTQAAAIg"] [Tue Aug 18 13:01:39.661993 2026] [security2:error] [pid 139043:tid 139176] [client 172.202.39.151:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTQAAAIg"] [Tue Aug 18 13:01:39.672940 2026] [security2:error] [pid 139043:tid 139214] [client 20.1.169.243:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTTwAAAK4"] [Tue Aug 18 13:01:39.674906 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:39.675160 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:39.691406 2026] [security2:error] [pid 123784:tid 123877] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/button.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxAAAWlg"] [Tue Aug 18 13:01:39.693574 2026] [security2:error] [pid 123784:tid 123822] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/43.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxQAAMSE"] [Tue Aug 18 13:01:39.695603 2026] [security2:error] [pid 139043:tid 139263] [client 213.35.127.232:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUQAAAN8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:39.697209 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:8915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/0x.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUgAAAKE"] [Tue Aug 18 13:01:39.717455 2026] [security2:error] [pid 123784:tid 123890] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/wlc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxgAAQmU"] [Tue Aug 18 13:01:39.726364 2026] [security2:error] [pid 139043:tid 139244] [client 158.158.74.177:9226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTUwAAAMw"] [Tue Aug 18 13:01:39.730128 2026] [security2:error] [pid 123784:tid 123803] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIxwAAGw4"] [Tue Aug 18 13:01:39.734561 2026] [security2:error] [pid 139043:tid 139063] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/fi.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVQAA5hM"] [Tue Aug 18 13:01:39.752770 2026] [security2:error] [pid 123784:tid 123874] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/chris.php"] [unique_id "aoSB42wDnJBNj2tDbYYIyQAAQ1U"] [Tue Aug 18 13:01:39.762504 2026] [security2:error] [pid 139043:tid 139185] [client 20.79.204.6:10712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/aaa.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVgAAAJE"] [Tue Aug 18 13:01:39.770459 2026] [security2:error] [pid 123784:tid 123934] [client 20.80.111.3:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSB42wDnJBNj2tDbYYIygAAABA"] [Tue Aug 18 13:01:39.772270 2026] [security2:error] [pid 123784:tid 123900] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/doc.php"] [unique_id "aoSB42wDnJBNj2tDbYYIywAAZW8"] [Tue Aug 18 13:01:39.782440 2026] [security2:error] [pid 139043:tid 139293] [client 20.100.169.31:4940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTVwAAAP0"] [Tue Aug 18 13:01:39.804430 2026] [security2:error] [pid 139043:tid 139204] [client 20.186.30.159:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/img.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWQAAAKQ"] [Tue Aug 18 13:01:39.808237 2026] [security2:error] [pid 139043:tid 139091] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/1337.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWgAAsy8"] [Tue Aug 18 13:01:39.815130 2026] [security2:error] [pid 139043:tid 139238] [client 20.119.58.187:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTWwAAAMY"] [Tue Aug 18 13:01:39.816741 2026] [security2:error] [pid 139043:tid 139068] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXAAAmhg"] [Tue Aug 18 13:01:39.821533 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xx.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXQAAAK8"] [Tue Aug 18 13:01:39.842210 2026] [security2:error] [pid 139043:tid 139200] [client 20.116.17.175:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ab.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXgAAAKA"] [Tue Aug 18 13:01:39.850466 2026] [security2:error] [pid 123784:tid 123814] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/Njima.php"] [unique_id "aoSB42wDnJBNj2tDbYYIzAAAABk"] [Tue Aug 18 13:01:39.855153 2026] [security2:error] [pid 139043:tid 139226] [client 20.250.13.23:6805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTXwAAALo"] [Tue Aug 18 13:01:39.874931 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/domvf.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYQAAAOI"] [Tue Aug 18 13:01:39.884107 2026] [security2:error] [pid 123784:tid 123837] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/BIBIL.php"] [unique_id "aoSB42wDnJBNj2tDbYYIzgAATDA"] [Tue Aug 18 13:01:39.905392 2026] [security2:error] [pid 139043:tid 139083] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/too.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYgAA8yc"] [Tue Aug 18 13:01:39.907139 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.56.190:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/php5.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTYwAAAKY"] [Tue Aug 18 13:01:39.915108 2026] [security2:error] [pid 139043:tid 139210] [client 20.65.98.162:45572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/ws55.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTZQAAAKo"] [Tue Aug 18 13:01:39.922249 2026] [security2:error] [pid 123784:tid 123876] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.savanasolucoesfinanceiras.com.br"] [uri "/g3.php"] [unique_id "aoSB42wDnJBNj2tDbYYI0AAASVc"] [Tue Aug 18 13:01:39.929088 2026] [security2:error] [pid 123784:tid 123925] [client 85.204.70.114:32808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSB42wDnJBNj2tDbYYI0QAAAAc"] [Tue Aug 18 13:01:39.936623 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fresh.php"] [unique_id "aoSB42wDnJBNj2tDbYYI0gAAAWg"] [Tue Aug 18 13:01:39.942382 2026] [security2:error] [pid 139043:tid 139258] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/upload.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTaAAAANo"] [Tue Aug 18 13:01:39.951869 2026] [autoindex:error] [pid 139043:tid 139255] [client 20.79.204.6:2194] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:39.957456 2026] [security2:error] [pid 139043:tid 139267] [client 20.48.236.86:14512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTagAAAOM"] [Tue Aug 18 13:01:39.972941 2026] [security2:error] [pid 139043:tid 139279] [client 158.23.17.4:17558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ih.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTawAAAO8"] [Tue Aug 18 13:01:39.976673 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:39.976938 2026] [authz_core:error] [pid 123784:tid 123884] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:39.992501 2026] [security2:error] [pid 139043:tid 139061] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB4_2v-lWn9OzQT7UTbAAA2xE"] [Tue Aug 18 13:01:40.024347 2026] [security2:error] [pid 139043:tid 139245] [client 20.79.204.6:11680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/dropdown.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbQAAAM0"] [Tue Aug 18 13:01:40.034575 2026] [security2:error] [pid 139043:tid 139281] [client 20.1.169.243:5338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/aaa.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbgAAAPE"] [Tue Aug 18 13:01:40.042107 2026] [security2:error] [pid 139043:tid 139278] [client 20.163.43.14:8916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/zxz.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTbwAAAO4"] [Tue Aug 18 13:01:40.043600 2026] [security2:error] [pid 139043:tid 139260] [client 168.62.48.100:18175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/blog/byp.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcAAAANw"] [Tue Aug 18 13:01:40.052898 2026] [security2:error] [pid 123784:tid 123849] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1QAAXDw"] [Tue Aug 18 13:01:40.058790 2026] [security2:error] [pid 123784:tid 123980] [client 172.213.243.2:18365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1gAAAD4"] [Tue Aug 18 13:01:40.064301 2026] [security2:error] [pid 139043:tid 139216] [client 20.104.100.201:34267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/acp.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcQAAALA"] [Tue Aug 18 13:01:40.079585 2026] [security2:error] [pid 139043:tid 139265] [client 20.116.17.175:23036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/f35.update.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcgAAAOE"] [Tue Aug 18 13:01:40.083788 2026] [security2:error] [pid 139043:tid 139246] [client 20.251.112.238:26127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/byp8.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTcwAAAM4"] [Tue Aug 18 13:01:40.095711 2026] [security2:error] [pid 139043:tid 139225] [client 20.91.215.254:11471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/mah/function.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTdgAAALk"] [Tue Aug 18 13:01:40.110503 2026] [security2:error] [pid 123784:tid 123997] [client 20.118.133.132:1493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/gm.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI1wAAAE8"] [Tue Aug 18 13:01:40.121333 2026] [security2:error] [pid 139043:tid 139250] [client 172.202.39.151:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTeAAAANI"] [Tue Aug 18 13:01:40.137422 2026] [security2:error] [pid 139043:tid 139240] [client 20.75.92.165:4309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTeQAAAMg"] [Tue Aug 18 13:01:40.149462 2026] [security2:error] [pid 123784:tid 123992] [client 20.186.30.159:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/222.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2QAAAEo"] [Tue Aug 18 13:01:40.150399 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/red.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2gAAAC4"] [Tue Aug 18 13:01:40.167796 2026] [security2:error] [pid 139043:tid 139242] [client 20.119.58.187:10120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/cache.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfAAAAMo"] [Tue Aug 18 13:01:40.173092 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/dropdown.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfQAAALg"] [Tue Aug 18 13:01:40.176833 2026] [security2:error] [pid 123784:tid 123820] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gj.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI2wAAfh8"] [Tue Aug 18 13:01:40.179456 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fd.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTfgAAAKk"] [Tue Aug 18 13:01:40.187032 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.73.37:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/scxy.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgAAAAOw"] [Tue Aug 18 13:01:40.189196 2026] [autoindex:error] [pid 139043:tid 139165] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:40.214035 2026] [security2:error] [pid 139043:tid 139221] [client 20.80.111.3:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/pwnd/as.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgQAAALU"] [Tue Aug 18 13:01:40.224848 2026] [security2:error] [pid 139043:tid 139184] [client 20.127.136.245:23404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/flower.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTggAAAJA"] [Tue Aug 18 13:01:40.225378 2026] [security2:error] [pid 123784:tid 123815] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI3AAAZho"] [Tue Aug 18 13:01:40.241233 2026] [security2:error] [pid 123784:tid 123968] [client 52.173.121.69:38563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI3QAAADI"] [Tue Aug 18 13:01:40.278101 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:40.278374 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:40.284204 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:24443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/conn-test.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTgwAAANU"] [Tue Aug 18 13:01:40.307892 2026] [security2:error] [pid 139043:tid 139234] [client 85.204.70.114:32822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5P2v-lWn9OzQT7UThwAAAMI"] [Tue Aug 18 13:01:40.360629 2026] [security2:error] [pid 139043:tid 139187] [client 20.104.100.201:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/yas.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiAAAAJM"] [Tue Aug 18 13:01:40.363210 2026] [security2:error] [pid 139043:tid 139201] [client 20.79.204.6:2194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiQAAAKE"] [Tue Aug 18 13:01:40.369859 2026] [security2:error] [pid 139043:tid 139230] [client 20.163.43.14:8930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/www.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTigAAAL4"] [Tue Aug 18 13:01:40.371276 2026] [security2:error] [pid 139043:tid 139220] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wk/index.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTiwAAALQ"] [Tue Aug 18 13:01:40.373511 2026] [security2:error] [pid 123784:tid 123835] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4AAADi4"] [Tue Aug 18 13:01:40.374636 2026] [security2:error] [pid 139043:tid 139217] [client 20.65.98.162:2470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ai.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjAAAALE"] [Tue Aug 18 13:01:40.375665 2026] [security2:error] [pid 139043:tid 139074] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjQAA5h4"] [Tue Aug 18 13:01:40.397138 2026] [security2:error] [pid 123784:tid 123943] [client 20.1.169.243:5357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4gAAABk"] [Tue Aug 18 13:01:40.406665 2026] [security2:error] [pid 139043:tid 139264] [client 20.100.169.31:4794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTjwAAAOA"] [Tue Aug 18 13:01:40.406920 2026] [authz_core:error] [pid 139043:tid 139087] [remote 57.141.22.107:22500] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:40.407275 2026] [authz_core:error] [pid 139043:tid 139087] [remote 57.141.22.107:22500] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:40.419078 2026] [security2:error] [pid 123784:tid 123977] [client 168.62.48.100:18148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI4wAAADs"] [Tue Aug 18 13:01:40.432786 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/JawirGenk.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkQAAAJE"] [Tue Aug 18 13:01:40.449656 2026] [security2:error] [pid 139043:tid 139290] [client 20.75.92.165:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/system_log.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkgAAAPo"] [Tue Aug 18 13:01:40.458486 2026] [security2:error] [pid 123784:tid 123935] [client 158.158.74.177:22887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-2019.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI5QAAABE"] [Tue Aug 18 13:01:40.475918 2026] [security2:error] [pid 139043:tid 139186] [client 172.213.243.2:16869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTkwAAAJI"] [Tue Aug 18 13:01:40.480495 2026] [security2:error] [pid 139043:tid 139288] [client 20.250.13.23:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlAAAAPg"] [Tue Aug 18 13:01:40.520441 2026] [security2:error] [pid 123784:tid 124001] [client 20.119.58.187:10469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/content.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6AAAAFM"] [Tue Aug 18 13:01:40.530229 2026] [security2:error] [pid 123784:tid 124026] [client 68.221.73.131:18644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/imscjpg.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6QAAAGw"] [Tue Aug 18 13:01:40.536000 2026] [security2:error] [pid 123784:tid 123866] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/function/function.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI6gAAY00"] [Tue Aug 18 13:01:40.566983 2026] [autoindex:error] [pid 139043:tid 139152] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:40.595479 2026] [security2:error] [pid 123784:tid 124009] [client 20.116.17.175:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/12.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7AAAAFs"] [Tue Aug 18 13:01:40.623559 2026] [security2:error] [pid 139043:tid 139188] [client 20.186.30.159:10052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/key.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlgAAAJQ"] [Tue Aug 18 13:01:40.629828 2026] [security2:error] [pid 123784:tid 123978] [client 20.79.204.6:11689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/file.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7QAAADw"] [Tue Aug 18 13:01:40.635678 2026] [security2:error] [pid 123784:tid 123993] [client 20.151.109.219:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fg.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7gAAAEs"] [Tue Aug 18 13:01:40.649324 2026] [security2:error] [pid 123784:tid 124029] [client 20.80.111.3:3603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/rk2.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI7wAAAG8"] [Tue Aug 18 13:01:40.659573 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.112.14:22880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/100.kb.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8AAAAEY"] [Tue Aug 18 13:01:40.677744 2026] [security2:error] [pid 123784:tid 123956] [client 20.251.112.238:33951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/plugins.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8QAAACY"] [Tue Aug 18 13:01:40.688933 2026] [security2:error] [pid 123784:tid 123825] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8gAAUiQ"] [Tue Aug 18 13:01:40.696144 2026] [security2:error] [pid 123784:tid 124041] [client 20.163.43.14:8947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wicked.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI8wAAAHs"] [Tue Aug 18 13:01:40.705708 2026] [security2:error] [pid 123784:tid 123841] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pd.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9AAAHzQ"] [Tue Aug 18 13:01:40.707821 2026] [security2:error] [pid 123784:tid 124021] [client 20.104.100.201:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/options.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9QAAAGc"] [Tue Aug 18 13:01:40.708196 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/k.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI9gAAAHA"] [Tue Aug 18 13:01:40.715192 2026] [security2:error] [pid 139043:tid 139300] [client 213.35.127.232:58038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTlwAAAQQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:40.721927 2026] [security2:error] [pid 123784:tid 124006] [client 85.204.70.114:32838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5GwDnJBNj2tDbYYI9wAAAFg"] [Tue Aug 18 13:01:40.723598 2026] [security2:error] [pid 123784:tid 124003] [client 158.23.17.4:34047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/40.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-AAAAFU"] [Tue Aug 18 13:01:40.735392 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.98.162:41689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/m.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-QAAAGg"] [Tue Aug 18 13:01:40.741079 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:17998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-gAAAGo"] [Tue Aug 18 13:01:40.781129 2026] [security2:error] [pid 123784:tid 123947] [client 20.79.204.6:11570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/file.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI-wAAAB0"] [Tue Aug 18 13:01:40.784463 2026] [security2:error] [pid 123784:tid 123952] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-act.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_AAAACI"] [Tue Aug 18 13:01:40.793152 2026] [security2:error] [pid 123784:tid 124018] [client 20.91.215.254:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/filter.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_QAAAGQ"] [Tue Aug 18 13:01:40.797123 2026] [security2:error] [pid 123784:tid 123972] [client 20.104.100.201:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ah25.php"] [unique_id "aoSB5GwDnJBNj2tDbYYI_gAAADY"] [Tue Aug 18 13:01:40.799841 2026] [security2:error] [pid 139043:tid 139214] [client 86.120.159.145:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmAAAAK4"] [Tue Aug 18 13:01:40.800024 2026] [security2:error] [pid 139043:tid 139214] [client 86.120.159.145:14325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmAAAAK4"] [Tue Aug 18 13:01:40.839822 2026] [security2:error] [pid 123784:tid 123798] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJAAAAGwk"] [Tue Aug 18 13:01:40.872731 2026] [security2:error] [pid 123784:tid 123975] [client 20.119.58.187:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJAgAAADk"] [Tue Aug 18 13:01:40.879806 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:40.880078 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:40.882571 2026] [security2:error] [pid 139043:tid 139105] [remote 72.167.40.62:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/wp-login.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTmwAA0z0"] [Tue Aug 18 13:01:40.888614 2026] [security2:error] [pid 123784:tid 123973] [client 172.213.243.2:5227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws61.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBAAAADc"] [Tue Aug 18 13:01:40.900900 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/info2.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBQAAAAA"] [Tue Aug 18 13:01:40.909545 2026] [security2:error] [pid 123784:tid 123994] [client 20.75.92.165:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/x.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBgAAAEw"] [Tue Aug 18 13:01:40.917138 2026] [security2:error] [pid 123784:tid 123974] [client 135.225.78.186:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/coffexium.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJBwAAADg"] [Tue Aug 18 13:01:40.922930 2026] [security2:error] [pid 123784:tid 123920] [client 20.48.236.86:14476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/inso.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJCAAAAAI"] [Tue Aug 18 13:01:40.972904 2026] [security2:error] [pid 139043:tid 139294] [client 20.151.109.219:24428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ve.php"] [unique_id "aoSB5P2v-lWn9OzQT7UTogAAAP4"] [Tue Aug 18 13:01:40.986445 2026] [security2:error] [pid 123784:tid 123906] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/ok.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJCwAASnU"] [Tue Aug 18 13:01:40.990074 2026] [autoindex:error] [pid 123784:tid 123929] [client 20.79.204.6:2225] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:40.990104 2026] [security2:error] [pid 123784:tid 123970] [client 20.104.100.201:49459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSB5GwDnJBNj2tDbYYJDAAAADQ"] [Tue Aug 18 13:01:41.008151 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metalford.com.br"] [uri "/images/security.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTpQAAAME"] [Tue Aug 18 13:01:41.034764 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTqQAAAKE"] [Tue Aug 18 13:01:41.089368 2026] [security2:error] [pid 139043:tid 139217] [client 20.102.65.165:8561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/key.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTrgAAALE"] [Tue Aug 18 13:01:41.089376 2026] [security2:error] [pid 123784:tid 123793] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEAAAHgQ"] [Tue Aug 18 13:01:41.089408 2026] [security2:error] [pid 123784:tid 123919] [client 20.80.111.3:41231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/storage/rip.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEQAAAAE"] [Tue Aug 18 13:01:41.098374 2026] [security2:error] [pid 123784:tid 123943] [client 85.204.70.114:32850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5WwDnJBNj2tDbYYJEgAAABk"] [Tue Aug 18 13:01:41.098486 2026] [security2:error] [pid 139043:tid 139276] [client 158.158.74.177:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/cjfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsAAAAOw"] [Tue Aug 18 13:01:41.102828 2026] [security2:error] [pid 123784:tid 124043] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJEwAAAH0"] [Tue Aug 18 13:01:41.136067 2026] [security2:error] [pid 123784:tid 123844] [remote 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dtbbrasil.com.br"] [uri "/item.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFAAAHDc"] [Tue Aug 18 13:01:41.144314 2026] [security2:error] [pid 123784:tid 123959] [client 20.104.100.201:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/ano.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFQAAACk"] [Tue Aug 18 13:01:41.147396 2026] [security2:error] [pid 123784:tid 123981] [client 20.250.13.23:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/lite.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJFgAAAD8"] [Tue Aug 18 13:01:41.158437 2026] [security2:error] [pid 139043:tid 139185] [client 158.23.17.4:11832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iu.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsQAAAJE"] [Tue Aug 18 13:01:41.191637 2026] [security2:error] [pid 123784:tid 123941] [client 172.202.39.151:61735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJGgAAABc"] [Tue Aug 18 13:01:41.192176 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:2225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJGwAAAEg"] [Tue Aug 18 13:01:41.231464 2026] [security2:error] [pid 123784:tid 123977] [client 20.119.58.187:10476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/css.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHAAAADs"] [Tue Aug 18 13:01:41.233484 2026] [security2:error] [pid 139043:tid 139187] [client 20.79.204.6:11578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/goods.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTsgAAAJM"] [Tue Aug 18 13:01:41.266333 2026] [security2:error] [pid 139043:tid 139239] [client 20.104.100.201:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTswAAAMc"] [Tue Aug 18 13:01:41.271443 2026] [security2:error] [pid 123784:tid 123870] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHgAAYlE"] [Tue Aug 18 13:01:41.278920 2026] [security2:error] [pid 123784:tid 123933] [client 20.75.92.165:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJHwAAAA8"] [Tue Aug 18 13:01:41.279435 2026] [security2:error] [pid 123784:tid 123958] [client 20.151.109.219:24447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ia.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIAAAACg"] [Tue Aug 18 13:01:41.300138 2026] [security2:error] [pid 123784:tid 123993] [client 172.213.243.2:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/rum.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIQAAAEs"] [Tue Aug 18 13:01:41.304415 2026] [security2:error] [pid 139043:tid 139243] [client 20.186.30.159:10067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/chosen.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTtQAAAMs"] [Tue Aug 18 13:01:41.347546 2026] [security2:error] [pid 123784:tid 124000] [client 20.127.136.245:18419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/motu.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJIwAAAFI"] [Tue Aug 18 13:01:41.356248 2026] [security2:error] [pid 123784:tid 123949] [client 20.226.112.14:22932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mamzi.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJAAAAB8"] [Tue Aug 18 13:01:41.358269 2026] [security2:error] [pid 139043:tid 139268] [client 20.163.43.14:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTtwAAAOQ"] [Tue Aug 18 13:01:41.380475 2026] [security2:error] [pid 139043:tid 139238] [client 20.29.77.16:62872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTuAAAAMY"] [Tue Aug 18 13:01:41.391842 2026] [security2:error] [pid 139043:tid 139293] [client 20.79.204.6:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/goods.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTuQAAAP0"] [Tue Aug 18 13:01:41.406933 2026] [security2:error] [pid 139043:tid 139200] [client 68.221.73.131:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/qlex1.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTugAAAKA"] [Tue Aug 18 13:01:41.439186 2026] [security2:error] [pid 123784:tid 123976] [client 20.91.215.254:11514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/input.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJgAAADo"] [Tue Aug 18 13:01:41.448492 2026] [security2:error] [pid 123784:tid 123851] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJJwAAVT4"] [Tue Aug 18 13:01:41.453597 2026] [security2:error] [pid 123784:tid 124022] [client 20.48.236.86:14794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/puc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKAAAAGg"] [Tue Aug 18 13:01:41.464413 2026] [security2:error] [pid 123784:tid 123957] [client 20.116.17.175:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/x1da.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKQAAACc"] [Tue Aug 18 13:01:41.483225 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:41.483486 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:41.491951 2026] [security2:error] [pid 139043:tid 139206] [client 85.204.70.114:32854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5f2v-lWn9OzQT7UTvQAAAKY"] [Tue Aug 18 13:01:41.505975 2026] [security2:error] [pid 139043:tid 139197] [client 20.100.169.31:4934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTvgAAAJ0"] [Tue Aug 18 13:01:41.530099 2026] [security2:error] [pid 139043:tid 139196] [client 20.65.98.162:56499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/33.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTwAAAAJw"] [Tue Aug 18 13:01:41.535624 2026] [security2:error] [pid 123784:tid 124021] [client 20.80.111.3:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/tool.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJKwAAAGc"] [Tue Aug 18 13:01:41.541389 2026] [security2:error] [pid 123784:tid 124007] [client 20.104.100.201:49447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/output.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJLQAAAFk"] [Tue Aug 18 13:01:41.541495 2026] [autoindex:error] [pid 139043:tid 139204] [client 20.100.169.31:13487] AH01276: Cannot serve directory /home1/xsolutions/vooo-api.3xsolutions.com/public/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:41.583770 2026] [security2:error] [pid 123784:tid 123931] [client 20.119.58.187:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/chosen.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMAAAAA0"] [Tue Aug 18 13:01:41.591511 2026] [security2:error] [pid 123784:tid 123953] [client 216.244.66.232:37454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMQAAACM"] [Tue Aug 18 13:01:41.591599 2026] [security2:error] [pid 123784:tid 123953] [client 216.244.66.232:37454] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMQAAACM"] [Tue Aug 18 13:01:41.596592 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/nwflm.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTwgAAAOM"] [Tue Aug 18 13:01:41.617166 2026] [security2:error] [pid 123784:tid 123853] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMwAAUEA"] [Tue Aug 18 13:01:41.617465 2026] [security2:error] [pid 123784:tid 123998] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJMwAAUEA"] [Tue Aug 18 13:01:41.619457 2026] [security2:error] [pid 123784:tid 124008] [client 20.151.109.219:60387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kn.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJNAAAAFo"] [Tue Aug 18 13:01:41.625080 2026] [security2:error] [pid 123784:tid 123967] [client 20.251.112.238:8015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/100.kb.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJNQAAADE"] [Tue Aug 18 13:01:41.649125 2026] [autoindex:error] [pid 123784:tid 123879] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:41.710607 2026] [security2:error] [pid 123784:tid 123975] [client 172.213.243.2:18459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ze.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOAAAADk"] [Tue Aug 18 13:01:41.729380 2026] [security2:error] [pid 139043:tid 139194] [client 213.35.127.232:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxAAAAJo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:41.741040 2026] [security2:error] [pid 139043:tid 139211] [client 20.163.43.14:8866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cah.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxQAAAKs"] [Tue Aug 18 13:01:41.744953 2026] [security2:error] [pid 123784:tid 124039] [client 20.186.30.159:10108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/thoms.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOgAAAHk"] [Tue Aug 18 13:01:41.750892 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTxwAAAM0"] [Tue Aug 18 13:01:41.768371 2026] [security2:error] [pid 123784:tid 123954] [client 158.158.74.177:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJOwAAACQ"] [Tue Aug 18 13:01:41.771286 2026] [security2:error] [pid 123784:tid 123973] [client 20.75.92.165:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/hosty.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJPAAAADc"] [Tue Aug 18 13:01:41.781738 2026] [security2:error] [pid 123784:tid 123995] [client 20.250.13.23:6925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSB5WwDnJBNj2tDbYYJPgAAAE0"] [Tue Aug 18 13:01:41.797289 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJPwAAAGQ"] [Tue Aug 18 13:01:41.809684 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pk.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJQAAAAEk"] [Tue Aug 18 13:01:41.824804 2026] [security2:error] [pid 123784:tid 124037] [client 20.104.100.201:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/tiny2.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJQgAAAHc"] [Tue Aug 18 13:01:41.848768 2026] [security2:error] [pid 139043:tid 139272] [client 20.79.204.6:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTyQAAAOg"] [Tue Aug 18 13:01:41.862109 2026] [security2:error] [pid 123784:tid 123987] [client 20.118.133.132:1510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/ws55.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRAAAAEU"] [Tue Aug 18 13:01:41.862204 2026] [security2:error] [pid 123784:tid 123924] [client 172.202.39.151:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-good.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRQAAAAY"] [Tue Aug 18 13:01:41.869883 2026] [security2:error] [pid 123784:tid 124035] [client 213.202.253.4:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJRwAAAHU"], referer: www.google.com [Tue Aug 18 13:01:41.880214 2026] [security2:error] [pid 123784:tid 123992] [client 85.204.70.114:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5WwDnJBNj2tDbYYJSAAAAEo"] [Tue Aug 18 13:01:41.934193 2026] [security2:error] [pid 139043:tid 139257] [client 20.116.17.175:23024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/bdroot.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTygAAANk"] [Tue Aug 18 13:01:41.938341 2026] [security2:error] [pid 123784:tid 123920] [client 20.119.58.187:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/doc.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJSgAAAAI"] [Tue Aug 18 13:01:41.963944 2026] [security2:error] [pid 123784:tid 124044] [client 20.151.109.219:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wm.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJSwAAAH4"] [Tue Aug 18 13:01:41.973452 2026] [security2:error] [pid 139043:tid 139297] [client 20.80.111.3:33438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTywAAAQE"] [Tue Aug 18 13:01:41.993715 2026] [security2:error] [pid 123784:tid 123996] [client 158.23.17.4:63002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sx.php"] [unique_id "aoSB5WwDnJBNj2tDbYYJTAAAAE4"] [Tue Aug 18 13:01:41.997546 2026] [security2:error] [pid 139043:tid 139278] [client 20.79.204.6:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/hplfuns.php"] [unique_id "aoSB5f2v-lWn9OzQT7UTzAAAAO4"] [Tue Aug 18 13:01:42.001423 2026] [security2:error] [pid 139043:tid 139190] [client 4.232.151.198:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/goods.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzQAAAJY"] [Tue Aug 18 13:01:42.023637 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gfile.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzgAAAPQ"] [Tue Aug 18 13:01:42.024623 2026] [security2:error] [pid 139043:tid 139286] [client 20.186.30.159:10012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UTzwAAAPY"] [Tue Aug 18 13:01:42.032667 2026] [security2:error] [pid 123784:tid 123898] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTQAAHm0"] [Tue Aug 18 13:01:42.052755 2026] [security2:error] [pid 139043:tid 139174] [client 20.102.65.165:8471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/chosen.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT0AAAAIY"] [Tue Aug 18 13:01:42.069358 2026] [security2:error] [pid 123784:tid 123892] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/th.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTgAAfWc"] [Tue Aug 18 13:01:42.084207 2026] [security2:error] [pid 139043:tid 139299] [client 20.79.204.6:10722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/abcd.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT0wAAAQM"] [Tue Aug 18 13:01:42.089991 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:34787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/wp-load.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1AAAANY"] [Tue Aug 18 13:01:42.090454 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:22203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/404.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJTwAAAHE"] [Tue Aug 18 13:01:42.105642 2026] [security2:error] [pid 139043:tid 139275] [client 20.104.100.201:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1QAAAOs"] [Tue Aug 18 13:01:42.122470 2026] [security2:error] [pid 139043:tid 139253] [client 20.29.77.16:40519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT1wAAANU"] [Tue Aug 18 13:01:42.125137 2026] [security2:error] [pid 139043:tid 139205] [client 172.213.243.2:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gjm.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2AAAAKU"] [Tue Aug 18 13:01:42.129928 2026] [security2:error] [pid 139043:tid 139223] [client 20.65.98.162:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/packed.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2QAAALc"] [Tue Aug 18 13:01:42.146976 2026] [security2:error] [pid 139043:tid 139246] [client 20.91.215.254:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/jquery.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT2wAAAM4"] [Tue Aug 18 13:01:42.198098 2026] [security2:error] [pid 139043:tid 139244] [client 135.225.78.186:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3AAAAMw"] [Tue Aug 18 13:01:42.205786 2026] [security2:error] [pid 139043:tid 139217] [client 20.251.112.238:7150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mamzi.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3QAAALE"] [Tue Aug 18 13:01:42.215020 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.56.190:17862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/Black.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT3wAAAOw"] [Tue Aug 18 13:01:42.220770 2026] [security2:error] [pid 123784:tid 123977] [client 172.202.39.151:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJUgAAADs"] [Tue Aug 18 13:01:42.225728 2026] [autoindex:error] [pid 123784:tid 123829] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:42.245770 2026] [security2:error] [pid 139043:tid 139256] [client 20.163.43.14:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/system_log.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT4QAAANg"] [Tue Aug 18 13:01:42.249820 2026] [security2:error] [pid 123784:tid 123858] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/admin404.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJVAAAGEU"] [Tue Aug 18 13:01:42.279845 2026] [security2:error] [pid 139043:tid 139222] [client 85.204.70.114:32880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5v2v-lWn9OzQT7UT5AAAALY"] [Tue Aug 18 13:01:42.293044 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/Exception-class.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT5QAAANA"] [Tue Aug 18 13:01:42.314579 2026] [security2:error] [pid 139043:tid 139288] [client 20.100.169.31:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT5wAAAPg"] [Tue Aug 18 13:01:42.335109 2026] [security2:error] [pid 139043:tid 139239] [client 158.23.17.4:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ge.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6QAAAMc"] [Tue Aug 18 13:01:42.353125 2026] [security2:error] [pid 139043:tid 139218] [client 20.186.30.159:10022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/file1221.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6gAAALI"] [Tue Aug 18 13:01:42.381237 2026] [security2:error] [pid 139043:tid 139293] [client 20.104.100.201:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/min.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6wAAAP0"] [Tue Aug 18 13:01:42.386946 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:42.387222 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:42.402260 2026] [security2:error] [pid 139043:tid 139261] [client 20.79.204.6:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT7gAAAN0"] [Tue Aug 18 13:01:42.405761 2026] [security2:error] [pid 123784:tid 123936] [client 20.80.111.3:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWQAAABI"] [Tue Aug 18 13:01:42.405828 2026] [security2:error] [pid 123784:tid 123935] [client 20.250.13.23:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWgAAABE"] [Tue Aug 18 13:01:42.405958 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:34286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/jj.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT7wAAAO0"] [Tue Aug 18 13:01:42.408470 2026] [security2:error] [pid 123784:tid 123914] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJWwAAb30"] [Tue Aug 18 13:01:42.409892 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:5611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8QAAAMk"] [Tue Aug 18 13:01:42.412897 2026] [security2:error] [pid 139043:tid 139219] [client 20.75.92.165:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/test1.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8gAAALM"] [Tue Aug 18 13:01:42.414923 2026] [security2:error] [pid 139043:tid 139252] [client 20.151.109.219:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ac.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT8wAAANQ"] [Tue Aug 18 13:01:42.422431 2026] [security2:error] [pid 123784:tid 123864] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qo.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXAAACEs"] [Tue Aug 18 13:01:42.426551 2026] [security2:error] [pid 123784:tid 123979] [client 20.116.17.175:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/mcs.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXQAAAD0"] [Tue Aug 18 13:01:42.452177 2026] [security2:error] [pid 123784:tid 123962] [client 20.79.204.6:11567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/htaccess.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJXgAAACw"] [Tue Aug 18 13:01:42.461315 2026] [security2:error] [pid 139043:tid 139203] [client 158.158.74.177:18961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT9AAAAKM"] [Tue Aug 18 13:01:42.530906 2026] [security2:error] [pid 139043:tid 139199] [client 20.226.112.14:28604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/wp-blog.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT9QAAAJ8"] [Tue Aug 18 13:01:42.551539 2026] [security2:error] [pid 123784:tid 123960] [client 172.213.243.2:16867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/new4.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYAAAACo"] [Tue Aug 18 13:01:42.584357 2026] [security2:error] [pid 123784:tid 123791] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYgAAUQI"] [Tue Aug 18 13:01:42.598812 2026] [security2:error] [pid 123784:tid 124026] [client 20.79.204.6:11551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/htaccess.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJYwAAAGw"] [Tue Aug 18 13:01:42.646809 2026] [security2:error] [pid 139043:tid 139179] [client 20.119.58.187:10161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ee.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-AAAAIs"] [Tue Aug 18 13:01:42.653980 2026] [security2:error] [pid 139043:tid 139259] [client 20.104.100.201:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ccou.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-QAAANs"] [Tue Aug 18 13:01:42.685975 2026] [security2:error] [pid 139043:tid 139189] [client 85.204.70.114:32890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5v2v-lWn9OzQT7UT-gAAAJU"] [Tue Aug 18 13:01:42.689431 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:42.689731 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:42.697563 2026] [security2:error] [pid 139043:tid 139235] [client 158.23.17.4:15788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nu.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT-wAAAMM"] [Tue Aug 18 13:01:42.697890 2026] [security2:error] [pid 139043:tid 139265] [client 20.102.65.165:8452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/wpxml.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_AAAAOE"] [Tue Aug 18 13:01:42.719916 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/yz.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_gAAANk"] [Tue Aug 18 13:01:42.745818 2026] [security2:error] [pid 123784:tid 124022] [client 20.163.43.14:8837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJZgAAAGg"] [Tue Aug 18 13:01:42.750418 2026] [security2:error] [pid 123784:tid 124024] [client 20.29.77.16:40521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/dirs.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJZwAAAGo"] [Tue Aug 18 13:01:42.751087 2026] [security2:error] [pid 139043:tid 139226] [client 213.35.127.232:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT_wAAALo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:42.761254 2026] [security2:error] [pid 123784:tid 123888] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJaAAAc2M"] [Tue Aug 18 13:01:42.762561 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:34169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ee.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJaQAAABY"] [Tue Aug 18 13:01:42.766174 2026] [security2:error] [pid 123784:tid 124013] [client 20.226.56.190:3023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/filesystems.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJagAAAF8"] [Tue Aug 18 13:01:42.790221 2026] [security2:error] [pid 123784:tid 123923] [client 20.91.215.254:11498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/media-new.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJawAAAAU"] [Tue Aug 18 13:01:42.793818 2026] [security2:error] [pid 123784:tid 123983] [client 158.23.17.4:15151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kl.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbAAAAEE"] [Tue Aug 18 13:01:42.798096 2026] [security2:error] [pid 123784:tid 123947] [client 172.202.39.151:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/index.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbQAAAB0"] [Tue Aug 18 13:01:42.799271 2026] [security2:error] [pid 139043:tid 139250] [client 20.127.136.245:8044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lite.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUAQAAANI"] [Tue Aug 18 13:01:42.825627 2026] [security2:error] [pid 123784:tid 123931] [client 20.116.17.175:22997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-temp.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJbgAAAA0"] [Tue Aug 18 13:01:42.840569 2026] [security2:error] [pid 139043:tid 139198] [client 20.80.111.3:39612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBAAAAJ4"] [Tue Aug 18 13:01:42.868224 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/img.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBQAAANM"] [Tue Aug 18 13:01:42.890414 2026] [security2:error] [pid 139043:tid 139221] [client 20.251.112.238:33961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ms.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUBwAAALU"] [Tue Aug 18 13:01:42.897382 2026] [security2:error] [pid 139043:tid 139183] [client 20.186.30.159:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/nox.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCAAAAI8"] [Tue Aug 18 13:01:42.942742 2026] [security2:error] [pid 139043:tid 139297] [client 20.100.169.31:4938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCgAAAQE"] [Tue Aug 18 13:01:42.943236 2026] [security2:error] [pid 139043:tid 139253] [client 20.104.100.201:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/crgio.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUCwAAANU"] [Tue Aug 18 13:01:42.946606 2026] [security2:error] [pid 123784:tid 123846] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sd.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcQAAWjk"] [Tue Aug 18 13:01:42.952236 2026] [autoindex:error] [pid 123784:tid 123871] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home2/dtbbrasilcom/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:42.966196 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-act.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUDgAAAME"] [Tue Aug 18 13:01:42.967073 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.112.14:34209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/cu.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcgAAAAw"] [Tue Aug 18 13:01:42.971686 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/adminner.php"] [unique_id "aoSB5mwDnJBNj2tDbYYJcwAAAHo"] [Tue Aug 18 13:01:42.980200 2026] [security2:error] [pid 139043:tid 139243] [client 195.2.84.198:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.84.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUAgAAAMs"], referer: http://paciolli.com.br/contato/ [Tue Aug 18 13:01:42.990357 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:42.990619 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:43.000824 2026] [security2:error] [pid 139043:tid 139294] [client 20.119.58.187:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/edit.php"] [unique_id "aoSB5v2v-lWn9OzQT7UUEAAAAP4"] [Tue Aug 18 13:01:43.004604 2026] [security2:error] [pid 139043:tid 139192] [client 135.225.78.186:50123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/sf.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUEQAAAJg"] [Tue Aug 18 13:01:43.007521 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUEgAAALE"] [Tue Aug 18 13:01:43.024130 2026] [security2:error] [pid 139043:tid 139181] [client 20.151.109.219:39309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kj.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFAAAAI0"] [Tue Aug 18 13:01:43.026694 2026] [autoindex:error] [pid 139043:tid 139193] [client 20.79.204.6:2236] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:43.061700 2026] [security2:error] [pid 139043:tid 139254] [client 20.79.204.6:11706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/images/wso.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFQAAANY"] [Tue Aug 18 13:01:43.066398 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:8904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFgAAAOo"] [Tue Aug 18 13:01:43.094158 2026] [security2:error] [pid 139043:tid 139212] [client 20.250.13.23:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUFwAAAKw"] [Tue Aug 18 13:01:43.099652 2026] [security2:error] [pid 139043:tid 139290] [client 52.173.121.69:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGAAAAPo"] [Tue Aug 18 13:01:43.106903 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:10398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-good.php"] [unique_id "aoSB52wDnJBNj2tDbYYJeAAAAFU"] [Tue Aug 18 13:01:43.112102 2026] [security2:error] [pid 123784:tid 124039] [client 20.75.92.165:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/zwso.php"] [unique_id "aoSB52wDnJBNj2tDbYYJeQAAAHk"] [Tue Aug 18 13:01:43.114914 2026] [security2:error] [pid 123784:tid 123905] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/km.php"] [unique_id "aoSB52wDnJBNj2tDbYYJegAAcnQ"] [Tue Aug 18 13:01:43.115042 2026] [security2:error] [pid 139043:tid 139222] [client 20.102.65.165:8453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/file1221.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGQAAALY"] [Tue Aug 18 13:01:43.132106 2026] [security2:error] [pid 123784:tid 123800] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB52wDnJBNj2tDbYYJewAAJAs"] [Tue Aug 18 13:01:43.133537 2026] [security2:error] [pid 139043:tid 139216] [client 158.158.74.177:22882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/import.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGgAAALA"] [Tue Aug 18 13:01:43.149776 2026] [security2:error] [pid 139043:tid 139227] [client 158.23.17.4:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gs.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUGwAAALs"] [Tue Aug 18 13:01:43.166233 2026] [security2:error] [pid 139043:tid 139287] [client 20.226.112.14:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/X57.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUHAAAAPc"] [Tue Aug 18 13:01:43.182237 2026] [security2:error] [pid 139043:tid 139280] [client 68.221.73.131:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/mariju.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUHgAAAPA"] [Tue Aug 18 13:01:43.199854 2026] [security2:error] [pid 139043:tid 139277] [client 85.204.70.114:32898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5_2v-lWn9OzQT7UUHwAAAO0"] [Tue Aug 18 13:01:43.201992 2026] [security2:error] [pid 139043:tid 139230] [client 20.79.204.6:11669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/images/wso.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIAAAAL4"] [Tue Aug 18 13:01:43.220159 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIgAAAOI"] [Tue Aug 18 13:01:43.227987 2026] [security2:error] [pid 139043:tid 139283] [client 20.79.204.6:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUIwAAAPM"] [Tue Aug 18 13:01:43.264165 2026] [security2:error] [pid 139043:tid 139295] [client 4.232.94.69:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/config.php7"] [unique_id "aoSB5_2v-lWn9OzQT7UUJAAAAP8"] [Tue Aug 18 13:01:43.273816 2026] [security2:error] [pid 139043:tid 139258] [client 158.23.17.4:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ak.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUJQAAANo"] [Tue Aug 18 13:01:43.286572 2026] [security2:error] [pid 123784:tid 123797] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mf.php"] [unique_id "aoSB52wDnJBNj2tDbYYJiAAAZAg"] [Tue Aug 18 13:01:43.289325 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:43.289600 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:43.311954 2026] [security2:error] [pid 123784:tid 123886] [remote 20.79.204.6:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJigAAOGE"] [Tue Aug 18 13:01:43.313091 2026] [security2:error] [pid 123784:tid 124037] [client 20.151.109.219:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vg.php"] [unique_id "aoSB52wDnJBNj2tDbYYJiwAAAHc"] [Tue Aug 18 13:01:43.339797 2026] [security2:error] [pid 123784:tid 124042] [client 20.226.112.14:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/forbidals.php"] [unique_id "aoSB52wDnJBNj2tDbYYJjAAAAHw"] [Tue Aug 18 13:01:43.340628 2026] [security2:error] [pid 139043:tid 139201] [client 20.104.100.201:34253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.sorayasalloum.com.br"] [uri "/we.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKAAAAKE"] [Tue Aug 18 13:01:43.354151 2026] [security2:error] [pid 139043:tid 139203] [client 20.119.58.187:10168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/f35.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKQAAAKM"] [Tue Aug 18 13:01:43.375268 2026] [security2:error] [pid 139043:tid 139300] [client 20.118.133.132:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/m.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUKwAAAQQ"] [Tue Aug 18 13:01:43.378029 2026] [security2:error] [pid 139043:tid 139211] [client 20.186.30.159:10068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/akismet.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULAAAAKs"] [Tue Aug 18 13:01:43.382559 2026] [security2:error] [pid 139043:tid 139195] [client 172.213.243.2:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/grsiuk.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULQAAAJs"] [Tue Aug 18 13:01:43.384036 2026] [security2:error] [pid 139043:tid 139182] [client 157.90.156.63:44644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alcorseguros.com.br"] [uri "/index.php"] [unique_id "aoSB5v2v-lWn9OzQT7UT6AAAAI4"], referer: https://www.alcorseguros.com.br [Tue Aug 18 13:01:43.388557 2026] [security2:error] [pid 123784:tid 123987] [client 20.48.236.86:14481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/19.php"] [unique_id "aoSB52wDnJBNj2tDbYYJjQAAAEU"] [Tue Aug 18 13:01:43.391841 2026] [security2:error] [pid 139043:tid 139245] [client 20.163.43.14:8849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/abc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULgAAAM0"] [Tue Aug 18 13:01:43.412816 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:44559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UULwAAANw"] [Tue Aug 18 13:01:43.413710 2026] [security2:error] [pid 139043:tid 139189] [client 20.127.136.245:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lock360.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMAAAAJU"] [Tue Aug 18 13:01:43.420610 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:7174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gfile.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMQAAAJM"] [Tue Aug 18 13:01:43.430645 2026] [security2:error] [pid 123784:tid 124010] [client 20.102.65.165:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/nox.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkAAAAFw"] [Tue Aug 18 13:01:43.434743 2026] [security2:error] [pid 139043:tid 139219] [client 20.91.215.254:11592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUMgAAALM"] [Tue Aug 18 13:01:43.453463 2026] [security2:error] [pid 123784:tid 123907] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ie.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkQAAdXY"] [Tue Aug 18 13:01:43.492034 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/css.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUNAAAAK4"] [Tue Aug 18 13:01:43.506157 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.112.14:34228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/edit.php"] [unique_id "aoSB52wDnJBNj2tDbYYJkgAAAEQ"] [Tue Aug 18 13:01:43.540433 2026] [security2:error] [pid 123784:tid 124020] [client 20.75.92.165:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/Geforce.php"] [unique_id "aoSB52wDnJBNj2tDbYYJlAAAAGY"] [Tue Aug 18 13:01:43.576791 2026] [security2:error] [pid 139043:tid 139207] [client 20.100.169.31:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOAAAAKc"] [Tue Aug 18 13:01:43.597300 2026] [security2:error] [pid 139043:tid 139196] [client 158.23.17.4:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lw.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOQAAAJw"] [Tue Aug 18 13:01:43.598893 2026] [security2:error] [pid 139043:tid 139183] [client 85.204.70.114:32908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elietecamargosadv.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSB5_2v-lWn9OzQT7UUOgAAAI8"] [Tue Aug 18 13:01:43.610622 2026] [security2:error] [pid 139043:tid 139174] [client 172.202.39.151:49865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/as.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUOwAAAIY"] [Tue Aug 18 13:01:43.665805 2026] [security2:error] [pid 123784:tid 123992] [client 20.79.204.6:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/index/function.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmQAAAEo"] [Tue Aug 18 13:01:43.672698 2026] [security2:error] [pid 123784:tid 123965] [client 20.29.77.16:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fresh.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmgAAAC8"] [Tue Aug 18 13:01:43.700678 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.112.14:22893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/kj.php"] [unique_id "aoSB52wDnJBNj2tDbYYJmwAAAEc"] [Tue Aug 18 13:01:43.706072 2026] [security2:error] [pid 123784:tid 124043] [client 20.186.30.159:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/admin.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnAAAAH0"] [Tue Aug 18 13:01:43.710507 2026] [security2:error] [pid 139043:tid 139221] [client 20.119.58.187:10137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/fff.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPQAAALU"] [Tue Aug 18 13:01:43.714192 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnQAAADQ"] [Tue Aug 18 13:01:43.715042 2026] [security2:error] [pid 139043:tid 139223] [client 20.80.111.3:18438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPgAAALc"] [Tue Aug 18 13:01:43.721088 2026] [security2:error] [pid 139043:tid 139176] [client 20.163.43.14:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/akcc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUPwAAAIg"] [Tue Aug 18 13:01:43.746016 2026] [security2:error] [pid 123784:tid 123971] [client 20.151.109.219:24401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sm.php"] [unique_id "aoSB52wDnJBNj2tDbYYJnwAAADU"] [Tue Aug 18 13:01:43.763317 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.98.162:27493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/sf.php"] [unique_id "aoSB52wDnJBNj2tDbYYJoAAAABw"] [Tue Aug 18 13:01:43.764655 2026] [security2:error] [pid 139043:tid 139235] [client 213.35.127.232:58670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQAAAAMM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:43.764752 2026] [security2:error] [pid 123784:tid 123959] [client 20.104.100.201:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB52wDnJBNj2tDbYYJoQAAACk"] [Tue Aug 18 13:01:43.774694 2026] [security2:error] [pid 139043:tid 139192] [client 20.116.17.175:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/dragonshell.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQQAAAJg"] [Tue Aug 18 13:01:43.792912 2026] [security2:error] [pid 123784:tid 123980] [client 4.232.151.198:12204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/file.php"] [unique_id "aoSB52wDnJBNj2tDbYYJowAAAD4"] [Tue Aug 18 13:01:43.807584 2026] [security2:error] [pid 139043:tid 139236] [client 172.213.243.2:18450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/h.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQgAAAMQ"] [Tue Aug 18 13:01:43.807793 2026] [security2:error] [pid 139043:tid 139253] [client 20.79.204.6:11527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/index/function.php"] [unique_id "aoSB5_2v-lWn9OzQT7UUQwAAANU"] [Tue Aug 18 13:01:43.810237 2026] [security2:error] [pid 123784:tid 123939] [client 158.158.74.177:9250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/cropper.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpAAAABU"] [Tue Aug 18 13:01:43.828207 2026] [security2:error] [pid 123784:tid 123938] [client 149.34.210.141:58642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpQAAABQ"] [Tue Aug 18 13:01:43.852470 2026] [security2:error] [pid 139043:tid 139291] [client 20.79.204.6:2178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURAAAAPs"] [Tue Aug 18 13:01:43.858406 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.112.14:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bes.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURgAAANY"] [Tue Aug 18 13:01:43.892347 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:43.892675 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:43.899083 2026] [security2:error] [pid 139043:tid 139177] [client 103.120.71.157:26799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURwAAAIk"] [Tue Aug 18 13:01:43.899254 2026] [security2:error] [pid 139043:tid 139177] [client 103.120.71.157:26799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB5_2v-lWn9OzQT7UURwAAAIk"] [Tue Aug 18 13:01:43.915537 2026] [security2:error] [pid 123784:tid 123978] [client 20.116.17.175:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-css.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqQAAADw"] [Tue Aug 18 13:01:43.932173 2026] [security2:error] [pid 123784:tid 123958] [client 158.23.17.4:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/test_info.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqgAAACg"] [Tue Aug 18 13:01:43.946231 2026] [security2:error] [pid 123784:tid 124023] [client 20.75.92.165:2033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/fpwch.php"] [unique_id "aoSB52wDnJBNj2tDbYYJqwAAAGk"] [Tue Aug 18 13:01:43.989751 2026] [security2:error] [pid 139043:tid 139244] [client 159.69.158.189:9900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lifetreemarketing.com"] [uri "/wp-content/cache/all/index.html"] [unique_id "aoSB5_2v-lWn9OzQT7UUSQAAAMw"], referer: https://lifetreemarketing.com/ [Tue Aug 18 13:01:44.009896 2026] [security2:error] [pid 123784:tid 123988] [client 20.226.112.14:22848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws60.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJrAAAAEY"] [Tue Aug 18 13:01:44.019333 2026] [security2:error] [pid 123784:tid 123962] [client 20.251.112.238:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJrQAAACw"] [Tue Aug 18 13:01:44.039183 2026] [security2:error] [pid 123784:tid 124000] [client 20.104.100.201:49443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/epinyins.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsAAAAFI"] [Tue Aug 18 13:01:44.060055 2026] [security2:error] [pid 123784:tid 123999] [client 20.163.43.14:8949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wk/index.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsQAAAFE"] [Tue Aug 18 13:01:44.063808 2026] [security2:error] [pid 123784:tid 123993] [client 20.119.58.187:10135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ff1.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJsgAAAEs"] [Tue Aug 18 13:01:44.075698 2026] [security2:error] [pid 139043:tid 139256] [client 20.91.215.254:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUSgAAANg"] [Tue Aug 18 13:01:44.080291 2026] [autoindex:error] [pid 123784:tid 124041] [client 169.58.72.248:58322] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:44.093177 2026] [security2:error] [pid 123784:tid 124017] [client 20.48.236.86:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/133.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJswAAAGM"] [Tue Aug 18 13:01:44.094805 2026] [security2:error] [pid 123784:tid 123938] [client 149.34.210.141:58642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB52wDnJBNj2tDbYYJpQAAABQ"] [Tue Aug 18 13:01:44.113045 2026] [security2:error] [pid 139043:tid 139218] [client 68.221.73.131:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUSwAAALI"] [Tue Aug 18 13:01:44.121416 2026] [security2:error] [pid 123784:tid 123942] [client 20.79.204.6:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/simple.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJtAAAABg"] [Tue Aug 18 13:01:44.125138 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:23767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJuwAAAGg"] [Tue Aug 18 13:01:44.166462 2026] [security2:error] [pid 139043:tid 139293] [client 20.29.77.16:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/admin404.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTAAAAP0"] [Tue Aug 18 13:01:44.167566 2026] [security2:error] [pid 123784:tid 123957] [client 20.127.136.245:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJwAAAACc"] [Tue Aug 18 13:01:44.192407 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:44.192673 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:44.216416 2026] [security2:error] [pid 139043:tid 139230] [client 158.23.17.4:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vj.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTQAAAL4"] [Tue Aug 18 13:01:44.225366 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/koiy.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTgAAAL0"] [Tue Aug 18 13:01:44.247114 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJyQAAACM"] [Tue Aug 18 13:01:44.262951 2026] [security2:error] [pid 123784:tid 123944] [client 20.226.112.14:22896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/olfclass.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJywAAABo"] [Tue Aug 18 13:01:44.276316 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/info.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUTwAAALA"] [Tue Aug 18 13:01:44.300370 2026] [security2:error] [pid 139043:tid 139273] [client 20.151.109.219:24384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/28.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUAAAAOk"] [Tue Aug 18 13:01:44.310025 2026] [security2:error] [pid 123784:tid 124038] [client 20.116.17.175:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/setup-config.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ2wAAAHg"] [Tue Aug 18 13:01:44.314405 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:49451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/load.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUQAAAP8"] [Tue Aug 18 13:01:44.341329 2026] [security2:error] [pid 139043:tid 139258] [client 158.23.17.4:25364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ko.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUgAAANo"] [Tue Aug 18 13:01:44.342020 2026] [security2:error] [pid 123784:tid 123943] [client 178.153.171.161:23465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ4gAAABk"] [Tue Aug 18 13:01:44.342110 2026] [security2:error] [pid 123784:tid 123943] [client 178.153.171.161:23465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ4gAAABk"] [Tue Aug 18 13:01:44.388359 2026] [security2:error] [pid 139043:tid 139267] [client 135.225.78.186:16794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/k.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUUwAAAOM"] [Tue Aug 18 13:01:44.402806 2026] [security2:error] [pid 139043:tid 139199] [client 20.186.30.159:10102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/bajah.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVAAAAJ8"] [Tue Aug 18 13:01:44.407914 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:8873] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/1.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVQAAAKg"] [Tue Aug 18 13:01:44.408030 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:8873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/1.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVQAAAKg"] [Tue Aug 18 13:01:44.409503 2026] [security2:error] [pid 123784:tid 124034] [client 20.100.169.31:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ5QAAAHQ"] [Tue Aug 18 13:01:44.411996 2026] [security2:error] [pid 123784:tid 124002] [client 20.79.204.6:11707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/info.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ5gAAAFQ"] [Tue Aug 18 13:01:44.416670 2026] [security2:error] [pid 139043:tid 139285] [client 20.119.58.187:10494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/flower.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVgAAAPU"] [Tue Aug 18 13:01:44.433893 2026] [security2:error] [pid 139043:tid 139241] [client 158.158.74.177:9278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUVwAAAMk"] [Tue Aug 18 13:01:44.457407 2026] [security2:error] [pid 139043:tid 139266] [client 20.250.13.23:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWQAAAOI"] [Tue Aug 18 13:01:44.471606 2026] [security2:error] [pid 123784:tid 124018] [client 20.226.112.14:28767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wpver.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ-gAAAGQ"] [Tue Aug 18 13:01:44.494840 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:44.495102 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:44.499566 2026] [security2:error] [pid 123784:tid 123994] [client 52.139.47.57:16592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB6GwDnJBNj2tDbYYJ_QAAAEw"] [Tue Aug 18 13:01:44.508907 2026] [security2:error] [pid 139043:tid 139179] [client 20.48.236.86:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWgAAAIs"] [Tue Aug 18 13:01:44.564443 2026] [security2:error] [pid 139043:tid 139265] [client 20.102.65.165:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/akismet.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUWwAAAOE"] [Tue Aug 18 13:01:44.594190 2026] [security2:error] [pid 139043:tid 139190] [client 20.104.100.201:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXAAAAJY"] [Tue Aug 18 13:01:44.619005 2026] [security2:error] [pid 123784:tid 123924] [client 20.80.111.3:3604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKAAAAAAY"] [Tue Aug 18 13:01:44.642099 2026] [security2:error] [pid 139043:tid 139240] [client 172.213.243.2:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fff.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXgAAAMg"] [Tue Aug 18 13:01:44.680871 2026] [security2:error] [pid 139043:tid 139194] [client 52.173.121.69:9741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUXwAAAJo"] [Tue Aug 18 13:01:44.718733 2026] [security2:error] [pid 139043:tid 139289] [client 20.226.112.14:22958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/thui.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYAAAAPk"] [Tue Aug 18 13:01:44.725058 2026] [security2:error] [pid 123784:tid 123995] [client 4.232.151.198:11590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKAwAAAE0"] [Tue Aug 18 13:01:44.732865 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/m.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBAAAAGY"] [Tue Aug 18 13:01:44.735044 2026] [security2:error] [pid 123784:tid 123968] [client 20.163.43.14:8854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBQAAADI"] [Tue Aug 18 13:01:44.736848 2026] [security2:error] [pid 123784:tid 124014] [client 20.116.17.175:23016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/flox.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBgAAAGA"] [Tue Aug 18 13:01:44.737162 2026] [security2:error] [pid 123784:tid 123996] [client 20.75.92.165:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKBwAAAE4"] [Tue Aug 18 13:01:44.739247 2026] [security2:error] [pid 123784:tid 123921] [client 20.116.17.175:54892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/f35.update.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKCAAAAAM"] [Tue Aug 18 13:01:44.739631 2026] [security2:error] [pid 139043:tid 139260] [client 20.91.215.254:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/import.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYQAAANw"] [Tue Aug 18 13:01:44.770470 2026] [security2:error] [pid 139043:tid 139220] [client 20.119.58.187:10472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/file.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYgAAALQ"] [Tue Aug 18 13:01:44.774873 2026] [security2:error] [pid 139043:tid 139299] [client 20.29.77.16:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/loading.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUYwAAAQM"] [Tue Aug 18 13:01:44.779556 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZAAAAI4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:44.786885 2026] [security2:error] [pid 123784:tid 123952] [client 68.221.73.131:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/contacto.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKCwAAACI"] [Tue Aug 18 13:01:44.799170 2026] [security2:error] [pid 123784:tid 123989] [client 20.127.136.245:22206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKDQAAAEc"] [Tue Aug 18 13:01:44.828358 2026] [security2:error] [pid 139043:tid 139275] [client 20.186.30.159:10073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/ajax.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZQAAAOs"] [Tue Aug 18 13:01:44.872992 2026] [security2:error] [pid 139043:tid 139239] [client 157.20.138.62:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZgAAAMc"] [Tue Aug 18 13:01:44.873140 2026] [security2:error] [pid 139043:tid 139239] [client 157.20.138.62:64149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZgAAAMc"] [Tue Aug 18 13:01:44.873398 2026] [security2:error] [pid 139043:tid 139278] [client 20.48.236.86:14513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/mosty.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUZwAAAO4"] [Tue Aug 18 13:01:44.875093 2026] [security2:error] [pid 139043:tid 139174] [client 20.104.100.201:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ty.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUaAAAAIY"] [Tue Aug 18 13:01:44.883485 2026] [security2:error] [pid 139043:tid 139202] [client 20.79.204.6:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/profile.php"] [unique_id "aoSB6P2v-lWn9OzQT7UUaQAAAKI"] [Tue Aug 18 13:01:44.902376 2026] [security2:error] [pid 123784:tid 123959] [client 20.251.112.238:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/cu.php"] [unique_id "aoSB6GwDnJBNj2tDbYYKEAAAACk"] [Tue Aug 18 13:01:45.006578 2026] [security2:error] [pid 139043:tid 139197] [client 103.184.169.37:43205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUagAAAJ0"] [Tue Aug 18 13:01:45.006690 2026] [security2:error] [pid 139043:tid 139197] [client 103.184.169.37:43205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUagAAAJ0"] [Tue Aug 18 13:01:45.023243 2026] [security2:error] [pid 139043:tid 139236] [client 158.23.17.4:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mimes.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUawAAAMQ"] [Tue Aug 18 13:01:45.023494 2026] [security2:error] [pid 139043:tid 139251] [client 20.79.204.6:11566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/profile.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUbAAAANM"] [Tue Aug 18 13:01:45.048498 2026] [security2:error] [pid 139043:tid 139253] [client 20.75.92.165:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about/function.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUbQAAANU"] [Tue Aug 18 13:01:45.066038 2026] [security2:error] [pid 123784:tid 124031] [client 20.100.169.31:4336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.deliciasdaisa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKFAAAAHE"] [Tue Aug 18 13:01:45.067129 2026] [security2:error] [pid 139043:tid 139249] [client 172.213.243.2:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/pouhg.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUcAAAANE"] [Tue Aug 18 13:01:45.090826 2026] [security2:error] [pid 123784:tid 123956] [client 52.173.121.69:53634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKFwAAACY"] [Tue Aug 18 13:01:45.094866 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:45.095129 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:45.124426 2026] [security2:error] [pid 139043:tid 139192] [client 20.119.58.187:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/goods.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUcwAAAJg"] [Tue Aug 18 13:01:45.131790 2026] [security2:error] [pid 123784:tid 123981] [client 158.158.74.177:9239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGQAAAD8"] [Tue Aug 18 13:01:45.139586 2026] [security2:error] [pid 123784:tid 123819] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nw.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGgAALB4"] [Tue Aug 18 13:01:45.142247 2026] [security2:error] [pid 139043:tid 139254] [client 20.163.43.14:8918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdAAAANY"] [Tue Aug 18 13:01:45.152443 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdQAAAJA"] [Tue Aug 18 13:01:45.164117 2026] [security2:error] [pid 123784:tid 124000] [client 216.244.66.232:51596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGwAAAFI"] [Tue Aug 18 13:01:45.164197 2026] [security2:error] [pid 123784:tid 124000] [client 216.244.66.232:51596] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKGwAAAFI"] [Tue Aug 18 13:01:45.167880 2026] [security2:error] [pid 123784:tid 123948] [client 20.151.109.219:39313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nl.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKHAAAAB4"] [Tue Aug 18 13:01:45.171332 2026] [security2:error] [pid 139043:tid 139203] [client 4.232.94.69:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdgAAAKM"] [Tue Aug 18 13:01:45.191815 2026] [security2:error] [pid 139043:tid 139177] [client 158.23.17.4:20408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/pl.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUdwAAAIk"] [Tue Aug 18 13:01:45.258935 2026] [security2:error] [pid 139043:tid 139288] [client 20.29.77.16:40542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/conn-test.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUeQAAAPg"] [Tue Aug 18 13:01:45.301581 2026] [security2:error] [pid 139043:tid 139218] [client 20.250.13.23:6808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/ku.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUewAAALI"] [Tue Aug 18 13:01:45.319031 2026] [security2:error] [pid 139043:tid 139268] [client 20.75.92.165:4310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/function/function.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfAAAAOQ"] [Tue Aug 18 13:01:45.328908 2026] [security2:error] [pid 139043:tid 139270] [client 20.48.236.86:14523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/blurbs.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfQAAAOY"] [Tue Aug 18 13:01:45.341396 2026] [security2:error] [pid 139043:tid 139277] [client 20.116.17.175:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/bdroot.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUfwAAAO0"] [Tue Aug 18 13:01:45.347465 2026] [security2:error] [pid 139043:tid 139232] [client 114.119.138.172:27291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cainelli.com.br"] [uri "/uploads/site/nifedipine-35-weeks-pregnant-neurontin-d2b316"] [unique_id "aoSB6f2v-lWn9OzQT7UUgAAAAMA"], referer: http://cainelli.com.br/uploads/site/ferrellgas-rumors-paroxetine-d2b316 [Tue Aug 18 13:01:45.354117 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sb.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKHwAAbG0"] [Tue Aug 18 13:01:45.400311 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:45.400716 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:45.427382 2026] [security2:error] [pid 139043:tid 139295] [client 20.186.30.159:9988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marquesti.fabioweb.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUggAAAP8"] [Tue Aug 18 13:01:45.431212 2026] [security2:error] [pid 139043:tid 139180] [client 20.104.100.201:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dot.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUgwAAAIw"] [Tue Aug 18 13:01:45.470395 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:8926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/as.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhAAAAPU"] [Tue Aug 18 13:01:45.474915 2026] [security2:error] [pid 139043:tid 139279] [client 172.213.243.2:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/moon3.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhQAAAO8"] [Tue Aug 18 13:01:45.477074 2026] [security2:error] [pid 139043:tid 139195] [client 20.151.109.219:24409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/68.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhgAAAJs"] [Tue Aug 18 13:01:45.481598 2026] [security2:error] [pid 139043:tid 139283] [client 20.119.58.187:10131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/g.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUhwAAAPM"] [Tue Aug 18 13:01:45.486198 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/sx.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUiQAAALg"] [Tue Aug 18 13:01:45.503099 2026] [security2:error] [pid 139043:tid 139248] [client 20.91.215.254:11591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUigAAANA"] [Tue Aug 18 13:01:45.504165 2026] [security2:error] [pid 139043:tid 139241] [client 20.80.111.3:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUiwAAAMk"] [Tue Aug 18 13:01:45.519445 2026] [security2:error] [pid 123784:tid 123938] [client 20.127.136.245:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.alf.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKIwAAABQ"] [Tue Aug 18 13:01:45.532795 2026] [security2:error] [pid 123784:tid 123911] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xj.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKJAAAOno"] [Tue Aug 18 13:01:45.546035 2026] [security2:error] [pid 139043:tid 139280] [client 52.139.47.57:3817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/hosty.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjQAAAPA"] [Tue Aug 18 13:01:45.565494 2026] [security2:error] [pid 123784:tid 123829] [remote 104.248.149.255:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.149.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gustavofrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKJgAAKCg"] [Tue Aug 18 13:01:45.584055 2026] [security2:error] [pid 123784:tid 124022] [client 172.202.39.151:53739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-config-sample.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKKAAAAGg"] [Tue Aug 18 13:01:45.592045 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:47915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ni.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKKQAAAAI"] [Tue Aug 18 13:01:45.602088 2026] [security2:error] [pid 139043:tid 139247] [client 20.116.17.175:22956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/op.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjgAAAM8"] [Tue Aug 18 13:01:45.623366 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/sx.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUjwAAAOc"] [Tue Aug 18 13:01:45.644218 2026] [security2:error] [pid 139043:tid 139257] [client 20.226.112.14:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tmpls.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkAAAANk"] [Tue Aug 18 13:01:45.655385 2026] [security2:error] [pid 139043:tid 139246] [client 4.232.151.198:45061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/404.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkQAAAM4"] [Tue Aug 18 13:01:45.664728 2026] [security2:error] [pid 139043:tid 139284] [client 20.75.92.165:4306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkgAAAPQ"] [Tue Aug 18 13:01:45.705878 2026] [security2:error] [pid 139043:tid 139194] [client 20.104.100.201:49427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/005.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUkwAAAJo"] [Tue Aug 18 13:01:45.726604 2026] [security2:error] [pid 123784:tid 124023] [client 5.31.227.224:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLQAAAGk"] [Tue Aug 18 13:01:45.726700 2026] [security2:error] [pid 123784:tid 124023] [client 5.31.227.224:59035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLQAAAGk"] [Tue Aug 18 13:01:45.739696 2026] [security2:error] [pid 139043:tid 139188] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlAAAAJQ"] [Tue Aug 18 13:01:45.740843 2026] [security2:error] [pid 139043:tid 139220] [client 20.29.77.16:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/evil.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlQAAALQ"] [Tue Aug 18 13:01:45.779854 2026] [security2:error] [pid 139043:tid 139242] [client 20.151.109.219:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jl.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUlgAAAMo"] [Tue Aug 18 13:01:45.790967 2026] [security2:error] [pid 123784:tid 123901] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ns.php"] [unique_id "aoSB6WwDnJBNj2tDbYYKLwAAc3A"] [Tue Aug 18 13:01:45.795239 2026] [security2:error] [pid 139043:tid 139199] [client 213.35.127.232:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmAAAAJ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:45.799504 2026] [security2:error] [pid 139043:tid 139196] [client 20.251.112.238:62515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/X57.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmQAAAJw"] [Tue Aug 18 13:01:45.802476 2026] [security2:error] [pid 139043:tid 139189] [client 158.158.74.177:9237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/goat.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmgAAAJU"] [Tue Aug 18 13:01:45.808570 2026] [security2:error] [pid 139043:tid 139183] [client 20.163.43.14:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUmwAAAI8"] [Tue Aug 18 13:01:45.825325 2026] [security2:error] [pid 139043:tid 139239] [client 20.48.236.86:14804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bajah.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnAAAAMc"] [Tue Aug 18 13:01:45.825975 2026] [security2:error] [pid 139043:tid 139278] [client 158.23.17.4:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/env.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnQAAAO4"] [Tue Aug 18 13:01:45.837316 2026] [security2:error] [pid 139043:tid 139289] [client 20.119.58.187:10160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUngAAAPk"] [Tue Aug 18 13:01:45.883362 2026] [security2:error] [pid 139043:tid 139243] [client 172.213.243.2:36147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/opts.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUnwAAAMs"] [Tue Aug 18 13:01:45.936860 2026] [security2:error] [pid 139043:tid 139175] [client 20.118.133.132:25778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/33.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUoAAAAIc"] [Tue Aug 18 13:01:45.939006 2026] [security2:error] [pid 139043:tid 139173] [client 20.80.111.3:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-the.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUoQAAAIU"] [Tue Aug 18 13:01:45.950779 2026] [security2:error] [pid 139043:tid 139235] [client 52.173.121.69:60619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUogAAAMM"] [Tue Aug 18 13:01:45.963680 2026] [security2:error] [pid 123784:tid 123935] [client 74.7.241.191:47706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "riovacinas.com.br"] [uri "/index.html"] [unique_id "aoSB6WwDnJBNj2tDbYYKNwAAEVI"] [Tue Aug 18 13:01:45.980781 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/v2.php"] [unique_id "aoSB6f2v-lWn9OzQT7UUqQAAANM"] [Tue Aug 18 13:01:46.016406 2026] [security2:error] [pid 139043:tid 139185] [client 138.185.145.78:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUsQAAAJE"] [Tue Aug 18 13:01:46.016506 2026] [security2:error] [pid 139043:tid 139185] [client 138.185.145.78:39228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUsQAAAJE"] [Tue Aug 18 13:01:46.020348 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.56.190:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUvQAAAOU"] [Tue Aug 18 13:01:46.045324 2026] [security2:error] [pid 123784:tid 123998] [client 20.75.92.165:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/f35.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKOwAAAFA"] [Tue Aug 18 13:01:46.077239 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-temp.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKPAAAAFo"] [Tue Aug 18 13:01:46.079241 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:60737] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "floripaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUygAAAIo"] [Tue Aug 18 13:01:46.079336 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUygAAAIo"] [Tue Aug 18 13:01:46.085466 2026] [security2:error] [pid 139043:tid 139212] [client 148.113.128.234:50254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cstcoop.co.mz"] [uri "/robots.txt"] [unique_id "aoSB6v2v-lWn9OzQT7UUywAAAKw"] [Tue Aug 18 13:01:46.085552 2026] [security2:error] [pid 139043:tid 139212] [client 148.113.128.234:50254] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cstcoop.co.mz"] [uri "/robots.txt"] [unique_id "aoSB6v2v-lWn9OzQT7UUywAAAKw"] [Tue Aug 18 13:01:46.101038 2026] [security2:error] [pid 139043:tid 139176] [client 20.79.204.6:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzAAAAIg"] [Tue Aug 18 13:01:46.115799 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzgAAALY"] [Tue Aug 18 13:01:46.125046 2026] [security2:error] [pid 139043:tid 139255] [client 37.40.227.74:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzwAAANc"] [Tue Aug 18 13:01:46.125192 2026] [security2:error] [pid 139043:tid 139255] [client 37.40.227.74:57039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UUzwAAANc"] [Tue Aug 18 13:01:46.125407 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:24424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/tq.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0AAAAJI"] [Tue Aug 18 13:01:46.130648 2026] [security2:error] [pid 139043:tid 139288] [client 20.29.77.16:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp-key.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0QAAAPg"] [Tue Aug 18 13:01:46.143012 2026] [security2:error] [pid 139043:tid 139234] [client 20.163.43.14:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU0gAAAMI"] [Tue Aug 18 13:01:46.185451 2026] [security2:error] [pid 139043:tid 139276] [client 20.91.215.254:11501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/ebs.php7"] [unique_id "aoSB6v2v-lWn9OzQT7UU1AAAAOw"] [Tue Aug 18 13:01:46.188493 2026] [security2:error] [pid 139043:tid 139184] [client 20.119.58.187:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1QAAAJA"] [Tue Aug 18 13:01:46.191053 2026] [security2:error] [pid 123784:tid 123943] [client 20.250.13.23:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/chosen.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQAAAABk"] [Tue Aug 18 13:01:46.232178 2026] [security2:error] [pid 139043:tid 139274] [client 20.79.204.6:11672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1gAAAOo"] [Tue Aug 18 13:01:46.233977 2026] [security2:error] [pid 123784:tid 123919] [client 52.139.47.57:18083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/t.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQgAAAAE"] [Tue Aug 18 13:01:46.237452 2026] [security2:error] [pid 123784:tid 124019] [client 20.48.236.86:14803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/h.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKQwAAAGU"] [Tue Aug 18 13:01:46.245700 2026] [security2:error] [pid 139043:tid 139232] [client 20.226.112.14:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nzv.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU1wAAAMA"] [Tue Aug 18 13:01:46.255948 2026] [security2:error] [pid 139043:tid 139264] [client 20.104.100.201:49429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wkl.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2AAAAOA"] [Tue Aug 18 13:01:46.258200 2026] [security2:error] [pid 139043:tid 139216] [client 172.202.39.151:52897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2QAAALA"] [Tue Aug 18 13:01:46.294676 2026] [security2:error] [pid 139043:tid 139258] [client 172.213.243.2:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zwq13.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2gAAANo"] [Tue Aug 18 13:01:46.301434 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:46.301812 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:46.332822 2026] [security2:error] [pid 123784:tid 123873] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gk.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKRgAAclQ"] [Tue Aug 18 13:01:46.368342 2026] [security2:error] [pid 123784:tid 123954] [client 20.75.92.165:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/gg.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKRwAAACQ"] [Tue Aug 18 13:01:46.378622 2026] [security2:error] [pid 139043:tid 139268] [client 20.80.111.3:3320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU2wAAAOQ"] [Tue Aug 18 13:01:46.395221 2026] [security2:error] [pid 139043:tid 139195] [client 20.116.17.175:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/1xmomo.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3AAAAJs"] [Tue Aug 18 13:01:46.404746 2026] [security2:error] [pid 139043:tid 139224] [client 20.102.65.165:8524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/admin.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3QAAALg"] [Tue Aug 18 13:01:46.435106 2026] [security2:error] [pid 123784:tid 124041] [client 114.119.131.28:26211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "plenitude.com.br"] [uri "/sobre"] [unique_id "aoSB6mwDnJBNj2tDbYYKSQAAAHs"], referer: https://plenitude.com.br/e-book-o-segredo-da-felicidade/ [Tue Aug 18 13:01:46.444779 2026] [security2:error] [pid 139043:tid 139241] [client 20.151.109.219:14131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/cv.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3gAAAMk"] [Tue Aug 18 13:01:46.449182 2026] [security2:error] [pid 139043:tid 139230] [client 158.158.74.177:9257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/Session.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU3wAAAL4"] [Tue Aug 18 13:01:46.498646 2026] [security2:error] [pid 139043:tid 139187] [client 20.163.43.14:8881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6AAAAJM"] [Tue Aug 18 13:01:46.508194 2026] [security2:error] [pid 123784:tid 124037] [client 158.23.17.4:38291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/14.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTAAAAHc"] [Tue Aug 18 13:01:46.518664 2026] [security2:error] [pid 123784:tid 123792] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wn.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTQAABwM"] [Tue Aug 18 13:01:46.522406 2026] [security2:error] [pid 139043:tid 139262] [client 172.202.39.151:40354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/file.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6QAAAN4"] [Tue Aug 18 13:01:46.529542 2026] [security2:error] [pid 123784:tid 123987] [client 20.104.100.201:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-asudo.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTgAAAEU"] [Tue Aug 18 13:01:46.535599 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/error1.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6gAAAPQ"] [Tue Aug 18 13:01:46.540408 2026] [security2:error] [pid 123784:tid 124018] [client 20.119.58.187:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/in.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKTwAAAGQ"] [Tue Aug 18 13:01:46.563447 2026] [security2:error] [pid 139043:tid 139240] [client 20.29.77.16:16536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU6wAAAMg"] [Tue Aug 18 13:01:46.594568 2026] [security2:error] [pid 123784:tid 124010] [client 20.48.236.86:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ano.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKUQAAAFw"] [Tue Aug 18 13:01:46.595336 2026] [security2:error] [pid 139043:tid 139237] [client 20.127.136.245:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7QAAAMU"] [Tue Aug 18 13:01:46.663430 2026] [security2:error] [pid 139043:tid 139229] [client 4.232.151.198:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wk/index.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7gAAAL0"] [Tue Aug 18 13:01:46.699918 2026] [security2:error] [pid 123784:tid 123894] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/app.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVQAAYGk"] [Tue Aug 18 13:01:46.704000 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU7wAAAOc"] [Tue Aug 18 13:01:46.707508 2026] [security2:error] [pid 123784:tid 123996] [client 172.213.243.2:34410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/Okxob.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVgAAAE4"] [Tue Aug 18 13:01:46.711587 2026] [security2:error] [pid 123784:tid 123921] [client 20.251.112.238:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/forbidals.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKVwAAAAM"] [Tue Aug 18 13:01:46.720484 2026] [security2:error] [pid 139043:tid 139259] [client 213.202.253.4:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU8gAAANs"], referer: www.google.com [Tue Aug 18 13:01:46.762269 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKWQAAAAs"] [Tue Aug 18 13:01:46.782873 2026] [security2:error] [pid 139043:tid 139239] [client 20.116.17.175:54851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-css.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU9gAAAMc"] [Tue Aug 18 13:01:46.792346 2026] [security2:error] [pid 123784:tid 123952] [client 20.226.56.190:17858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/del.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKWwAAACI"] [Tue Aug 18 13:01:46.801385 2026] [security2:error] [pid 123784:tid 123928] [client 20.104.100.201:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/az.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXAAAAAo"] [Tue Aug 18 13:01:46.811767 2026] [security2:error] [pid 123784:tid 123989] [client 20.75.92.165:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/class.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXQAAAEc"] [Tue Aug 18 13:01:46.815152 2026] [security2:error] [pid 123784:tid 123968] [client 20.80.111.3:18454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wso.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXgAAADI"] [Tue Aug 18 13:01:46.818177 2026] [security2:error] [pid 123784:tid 123994] [client 213.35.127.232:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKXwAAAEw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:46.826222 2026] [security2:error] [pid 123784:tid 124043] [client 20.163.43.14:8855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYAAAAH0"] [Tue Aug 18 13:01:46.835374 2026] [security2:error] [pid 123784:tid 123970] [client 135.225.78.186:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/82.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYQAAADQ"] [Tue Aug 18 13:01:46.838667 2026] [security2:error] [pid 123784:tid 123964] [client 20.79.204.6:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKYgAAAC4"] [Tue Aug 18 13:01:46.847078 2026] [security2:error] [pid 139043:tid 139272] [client 20.91.215.254:19396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/include/Lurd.class.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU-AAAAOg"] [Tue Aug 18 13:01:46.865292 2026] [security2:error] [pid 139043:tid 139228] [client 52.139.47.57:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU-QAAALw"] [Tue Aug 18 13:01:46.893924 2026] [security2:error] [pid 123784:tid 123997] [client 20.119.58.187:10490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/info.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZAAAAE8"] [Tue Aug 18 13:01:46.895865 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.112.14:28772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/155.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZgAAABw"] [Tue Aug 18 13:01:46.902039 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:46.902310 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:46.914128 2026] [security2:error] [pid 123784:tid 123907] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/87.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKZwAADnY"] [Tue Aug 18 13:01:46.918571 2026] [security2:error] [pid 123784:tid 123990] [client 20.151.109.219:39345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/un.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKaAAAAEg"] [Tue Aug 18 13:01:46.950334 2026] [security2:error] [pid 123784:tid 124028] [client 20.250.13.23:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/asd.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKagAAAG4"] [Tue Aug 18 13:01:46.962628 2026] [security2:error] [pid 123784:tid 123978] [client 138.185.145.78:39702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbAAAADw"] [Tue Aug 18 13:01:46.962709 2026] [security2:error] [pid 123784:tid 123978] [client 138.185.145.78:39702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbAAAADw"] [Tue Aug 18 13:01:46.966912 2026] [security2:error] [pid 139043:tid 139270] [client 223.185.37.47:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU_wAAAOY"] [Tue Aug 18 13:01:46.967028 2026] [security2:error] [pid 139043:tid 139270] [client 223.185.37.47:10425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB6v2v-lWn9OzQT7UU_wAAAOY"] [Tue Aug 18 13:01:46.993563 2026] [security2:error] [pid 123784:tid 123950] [client 20.29.77.16:13663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/mimes.php"] [unique_id "aoSB6mwDnJBNj2tDbYYKbQAAACA"] [Tue Aug 18 13:01:47.033544 2026] [security2:error] [pid 123784:tid 123988] [client 20.48.236.86:14799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ai.php"] [unique_id "aoSB62wDnJBNj2tDbYYKbwAAAEY"] [Tue Aug 18 13:01:47.038446 2026] [security2:error] [pid 123784:tid 123981] [client 20.203.183.135:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcAAAAD8"] [Tue Aug 18 13:01:47.062206 2026] [security2:error] [pid 123784:tid 124044] [client 20.79.204.6:10409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/edit-tags.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcQAAAH4"] [Tue Aug 18 13:01:47.075903 2026] [security2:error] [pid 139043:tid 139236] [client 20.104.100.201:49670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/z43agz.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVAgAAAMQ"] [Tue Aug 18 13:01:47.077388 2026] [security2:error] [pid 139043:tid 139251] [client 158.23.17.4:17545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/88.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVAwAAANM"] [Tue Aug 18 13:01:47.085016 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBAAAANU"] [Tue Aug 18 13:01:47.090658 2026] [security2:error] [pid 139043:tid 139233] [client 158.158.74.177:18984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBQAAAME"] [Tue Aug 18 13:01:47.110806 2026] [security2:error] [pid 123784:tid 123868] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zi.php"] [unique_id "aoSB62wDnJBNj2tDbYYKcgAAbE8"] [Tue Aug 18 13:01:47.119610 2026] [security2:error] [pid 123784:tid 123938] [client 172.213.243.2:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/file59.php"] [unique_id "aoSB62wDnJBNj2tDbYYKdAAAABQ"] [Tue Aug 18 13:01:47.135739 2026] [security2:error] [pid 139043:tid 139221] [client 172.202.39.151:53735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVBwAAALU"] [Tue Aug 18 13:01:47.224895 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:38945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fasx.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCAAAAKU"] [Tue Aug 18 13:01:47.226981 2026] [security2:error] [pid 139043:tid 139269] [client 68.221.73.131:13514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/image2.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCQAAAOU"] [Tue Aug 18 13:01:47.242103 2026] [security2:error] [pid 123784:tid 124013] [client 20.75.92.165:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/flower.php"] [unique_id "aoSB62wDnJBNj2tDbYYKeAAAAF8"] [Tue Aug 18 13:01:47.247878 2026] [security2:error] [pid 123784:tid 123976] [client 20.119.58.187:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/inputs.php"] [unique_id "aoSB62wDnJBNj2tDbYYKeQAAADo"] [Tue Aug 18 13:01:47.248316 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.56.190:23793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/moderator.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCgAAAIo"] [Tue Aug 18 13:01:47.252282 2026] [security2:error] [pid 123784:tid 124030] [client 20.80.111.3:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/www.php"] [unique_id "aoSB62wDnJBNj2tDbYYKegAAAHA"] [Tue Aug 18 13:01:47.266553 2026] [security2:error] [pid 139043:tid 139191] [client 52.173.121.69:9790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVCwAAAJc"] [Tue Aug 18 13:01:47.272301 2026] [security2:error] [pid 123784:tid 123880] [remote 57.141.22.25:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB62wDnJBNj2tDbYYKewAAAls"] [Tue Aug 18 13:01:47.279390 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/0x.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDAAAAKw"] [Tue Aug 18 13:01:47.288201 2026] [security2:error] [pid 139043:tid 139206] [client 20.251.112.238:20220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/edit.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDQAAAKY"] [Tue Aug 18 13:01:47.294706 2026] [security2:error] [pid 123784:tid 123958] [client 52.139.47.57:3831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/xx.php"] [unique_id "aoSB62wDnJBNj2tDbYYKfAAAACg"] [Tue Aug 18 13:01:47.299679 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/evil.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVDgAAAKA"] [Tue Aug 18 13:01:47.305513 2026] [security2:error] [pid 139043:tid 139225] [client 216.73.161.208:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/edit.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVEAAAALk"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:01:47.314225 2026] [security2:error] [pid 123784:tid 123904] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/92.php"] [unique_id "aoSB62wDnJBNj2tDbYYKfgAAQXM"] [Tue Aug 18 13:01:47.327583 2026] [security2:error] [pid 123784:tid 124007] [client 20.163.43.14:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgAAAAFk"] [Tue Aug 18 13:01:47.351501 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:49419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/3.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgQAAABE"] [Tue Aug 18 13:01:47.422060 2026] [security2:error] [pid 139043:tid 139282] [client 20.127.136.245:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVEwAAAPI"] [Tue Aug 18 13:01:47.465074 2026] [security2:error] [pid 123784:tid 123945] [client 172.202.39.151:44496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/epinyins.php"] [unique_id "aoSB62wDnJBNj2tDbYYKgwAAABs"] [Tue Aug 18 13:01:47.490960 2026] [security2:error] [pid 139043:tid 139276] [client 20.116.17.175:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/flox.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFQAAAOw"] [Tue Aug 18 13:01:47.495819 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:13655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFgAAAOk"] [Tue Aug 18 13:01:47.514615 2026] [security2:error] [pid 123784:tid 124017] [client 114.119.131.112:44355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuenckimoveis.com.br"] [uri "/detalhes-do-imovel/niteroi/itacoatiara/497/cobertura/"] [unique_id "aoSB62wDnJBNj2tDbYYKhQAAAGM"], referer: https://schuenckimoveis.com.br/detalhes-do-imovel/niteroi/itacoatiara/497/cobertura/ [Tue Aug 18 13:01:47.516705 2026] [security2:error] [pid 139043:tid 139274] [client 20.116.17.175:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/txets.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVFwAAAOo"] [Tue Aug 18 13:01:47.520356 2026] [security2:error] [pid 123784:tid 124003] [client 20.79.204.6:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKhwAAAFU"] [Tue Aug 18 13:01:47.521597 2026] [security2:error] [pid 123784:tid 123930] [client 20.226.112.14:28738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-good.php"] [unique_id "aoSB62wDnJBNj2tDbYYKiAAAAAw"] [Tue Aug 18 13:01:47.524304 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:47.524569 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:47.526331 2026] [security2:error] [pid 139043:tid 139298] [client 142.44.228.234:48604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cstcoop.co.mz"] [uri "/"] [unique_id "aoSB6_2v-lWn9OzQT7UVGAAAAQI"] [Tue Aug 18 13:01:47.526429 2026] [security2:error] [pid 139043:tid 139298] [client 142.44.228.234:48604] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cstcoop.co.mz"] [uri "/"] [unique_id "aoSB6_2v-lWn9OzQT7UVGAAAAQI"] [Tue Aug 18 13:01:47.532036 2026] [security2:error] [pid 139043:tid 139264] [client 172.213.243.2:19875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/eauu.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGQAAAOA"] [Tue Aug 18 13:01:47.545574 2026] [security2:error] [pid 123784:tid 123821] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jm.php"] [unique_id "aoSB62wDnJBNj2tDbYYKiQAAVCA"] [Tue Aug 18 13:01:47.564951 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mz.php"] [unique_id "aoSB62wDnJBNj2tDbYYKigAAACQ"] [Tue Aug 18 13:01:47.573873 2026] [security2:error] [pid 139043:tid 139255] [client 20.250.13.23:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/akc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGgAAANc"] [Tue Aug 18 13:01:47.592431 2026] [security2:error] [pid 123784:tid 123953] [client 20.91.215.254:11496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjAAAACM"] [Tue Aug 18 13:01:47.598631 2026] [security2:error] [pid 123784:tid 123975] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/222.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjQAAADk"] [Tue Aug 18 13:01:47.601016 2026] [security2:error] [pid 123784:tid 124040] [client 20.119.58.187:10464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/item.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjgAAAHo"] [Tue Aug 18 13:01:47.615209 2026] [security2:error] [pid 139043:tid 139258] [client 20.151.109.219:60399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pw.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVGwAAANo"] [Tue Aug 18 13:01:47.616538 2026] [security2:error] [pid 139043:tid 139210] [client 138.185.145.78:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHAAAAKo"] [Tue Aug 18 13:01:47.616616 2026] [security2:error] [pid 139043:tid 139210] [client 138.185.145.78:37618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHAAAAKo"] [Tue Aug 18 13:01:47.625046 2026] [security2:error] [pid 139043:tid 139267] [client 158.23.17.4:28375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tk.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHQAAAOM"] [Tue Aug 18 13:01:47.627473 2026] [security2:error] [pid 123784:tid 123918] [client 20.104.100.201:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/log.php"] [unique_id "aoSB62wDnJBNj2tDbYYKjwAAAAA"] [Tue Aug 18 13:01:47.641449 2026] [security2:error] [pid 139043:tid 139300] [client 20.75.92.165:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/motu.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHgAAAQQ"] [Tue Aug 18 13:01:47.651696 2026] [security2:error] [pid 123784:tid 124033] [client 138.36.100.162:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkAAAAHM"] [Tue Aug 18 13:01:47.651812 2026] [security2:error] [pid 123784:tid 124033] [client 138.36.100.162:42462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkAAAAHM"] [Tue Aug 18 13:01:47.656473 2026] [security2:error] [pid 139043:tid 139224] [client 20.163.43.14:8953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/an.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVHwAAALg"] [Tue Aug 18 13:01:47.658907 2026] [security2:error] [pid 139043:tid 139248] [client 20.79.204.6:11521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIAAAANA"] [Tue Aug 18 13:01:47.662026 2026] [security2:error] [pid 139043:tid 139241] [client 20.29.77.16:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIQAAAMk"] [Tue Aug 18 13:01:47.688283 2026] [security2:error] [pid 139043:tid 139252] [client 20.80.111.3:27126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/x.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVIgAAANQ"] [Tue Aug 18 13:01:47.708946 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.112.14:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zxin.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJQAAAIs"] [Tue Aug 18 13:01:47.711795 2026] [security2:error] [pid 139043:tid 139187] [client 20.102.65.165:8570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.filialweb.com"] [uri "/ajax.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJgAAAJM"] [Tue Aug 18 13:01:47.716107 2026] [security2:error] [pid 139043:tid 139247] [client 138.185.145.78:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/blog/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJwAAAM8"] [Tue Aug 18 13:01:47.716182 2026] [security2:error] [pid 139043:tid 139247] [client 138.185.145.78:40168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/blog/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVJwAAAM8"] [Tue Aug 18 13:01:47.723754 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wj.php"] [unique_id "aoSB62wDnJBNj2tDbYYKkgAAODM"] [Tue Aug 18 13:01:47.772693 2026] [security2:error] [pid 139043:tid 139190] [client 20.51.153.15:13582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKAAAAJY"] [Tue Aug 18 13:01:47.798392 2026] [security2:error] [pid 123784:tid 123969] [client 52.139.47.57:17574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/zwso.php"] [unique_id "aoSB62wDnJBNj2tDbYYKlAAAADM"] [Tue Aug 18 13:01:47.806717 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:47.806989 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:47.814947 2026] [security2:error] [pid 139043:tid 139240] [client 138.185.145.78:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKQAAAMg"] [Tue Aug 18 13:01:47.815028 2026] [security2:error] [pid 139043:tid 139240] [client 138.185.145.78:40230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKQAAAMg"] [Tue Aug 18 13:01:47.822384 2026] [security2:error] [pid 139043:tid 139184] [client 4.232.94.69:14423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/randkeyword.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVKgAAAJA"] [Tue Aug 18 13:01:47.828221 2026] [security2:error] [pid 123784:tid 123919] [client 213.35.127.232:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB62wDnJBNj2tDbYYKlgAAAAE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:47.841677 2026] [security2:error] [pid 139043:tid 139279] [client 158.158.74.177:22859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLAAAAO8"] [Tue Aug 18 13:01:47.842550 2026] [security2:error] [pid 139043:tid 139188] [client 20.48.236.86:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/w1px.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLQAAAJQ"] [Tue Aug 18 13:01:47.859007 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/hj.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLgAAALQ"] [Tue Aug 18 13:01:47.903333 2026] [security2:error] [pid 123784:tid 123845] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/74.php"] [unique_id "aoSB62wDnJBNj2tDbYYKmQAATjg"] [Tue Aug 18 13:01:47.905404 2026] [security2:error] [pid 139043:tid 139182] [client 20.104.100.201:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ohct.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVLwAAAI4"] [Tue Aug 18 13:01:47.912775 2026] [security2:error] [pid 139043:tid 139275] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/aa.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMAAAAOs"] [Tue Aug 18 13:01:47.916502 2026] [security2:error] [pid 139043:tid 139242] [client 138.185.145.78:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wordpress/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMQAAAMo"] [Tue Aug 18 13:01:47.916575 2026] [security2:error] [pid 139043:tid 139242] [client 138.185.145.78:40284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wordpress/xmlrpc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMQAAAMo"] [Tue Aug 18 13:01:47.947082 2026] [security2:error] [pid 123784:tid 124035] [client 172.213.243.2:18483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/dsd.php"] [unique_id "aoSB62wDnJBNj2tDbYYKnAAAAHU"] [Tue Aug 18 13:01:47.954958 2026] [security2:error] [pid 139043:tid 139260] [client 20.119.58.187:10457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/k.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVMwAAANw"] [Tue Aug 18 13:01:47.976679 2026] [security2:error] [pid 139043:tid 139278] [client 20.38.3.247:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/puc.php"] [unique_id "aoSB6_2v-lWn9OzQT7UVNAAAAO4"] [Tue Aug 18 13:01:48.014475 2026] [security2:error] [pid 139043:tid 139228] [client 138.185.145.78:40352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/news/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVNwAAALw"] [Tue Aug 18 13:01:48.014556 2026] [security2:error] [pid 139043:tid 139228] [client 138.185.145.78:40352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/news/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVNwAAALw"] [Tue Aug 18 13:01:48.027887 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/dirs.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOAAAAKk"] [Tue Aug 18 13:01:48.053677 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fn.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOQAAAMM"] [Tue Aug 18 13:01:48.065179 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVOwAAAME"] [Tue Aug 18 13:01:48.106865 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:48.107130 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:48.113764 2026] [security2:error] [pid 139043:tid 139254] [client 138.185.145.78:40422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/web/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPAAAANY"] [Tue Aug 18 13:01:48.113844 2026] [security2:error] [pid 139043:tid 139254] [client 138.185.145.78:40422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/web/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPAAAANY"] [Tue Aug 18 13:01:48.121479 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.112.14:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pass4.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPQAAAPs"] [Tue Aug 18 13:01:48.124244 2026] [security2:error] [pid 139043:tid 139174] [client 20.80.111.3:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPgAAAIY"] [Tue Aug 18 13:01:48.126750 2026] [security2:error] [pid 139043:tid 139261] [client 4.232.151.198:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVPwAAAN0"] [Tue Aug 18 13:01:48.134587 2026] [security2:error] [pid 139043:tid 139178] [client 20.127.136.245:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQAAAAIo"] [Tue Aug 18 13:01:48.149283 2026] [security2:error] [pid 139043:tid 139212] [client 20.251.112.238:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/kj.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQQAAAKw"] [Tue Aug 18 13:01:48.154495 2026] [security2:error] [pid 139043:tid 139206] [client 172.202.39.151:40937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQgAAAKY"] [Tue Aug 18 13:01:48.158200 2026] [security2:error] [pid 139043:tid 139200] [client 20.163.43.14:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVQwAAAKA"] [Tue Aug 18 13:01:48.182680 2026] [security2:error] [pid 139043:tid 139186] [client 20.104.100.201:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ot.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVRgAAAJI"] [Tue Aug 18 13:01:48.213385 2026] [security2:error] [pid 139043:tid 139289] [client 138.185.145.78:40466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/cms/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSAAAAPk"] [Tue Aug 18 13:01:48.213477 2026] [security2:error] [pid 139043:tid 139289] [client 138.185.145.78:40466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/cms/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSAAAAPk"] [Tue Aug 18 13:01:48.220149 2026] [security2:error] [pid 123784:tid 123989] [client 216.244.66.232:51610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKogAAAEc"] [Tue Aug 18 13:01:48.220242 2026] [security2:error] [pid 123784:tid 123989] [client 216.244.66.232:51610] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKogAAAEc"] [Tue Aug 18 13:01:48.263466 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:6794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/maintenance.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVSgAAAQE"] [Tue Aug 18 13:01:48.273223 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:13570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fresh.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVTQAAAOw"] [Tue Aug 18 13:01:48.289818 2026] [security2:error] [pid 139043:tid 139249] [client 20.91.215.254:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lite.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVTgAAANE"] [Tue Aug 18 13:01:48.307522 2026] [security2:error] [pid 139043:tid 139232] [client 20.203.183.135:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUAAAAMA"] [Tue Aug 18 13:01:48.309480 2026] [security2:error] [pid 139043:tid 139222] [client 20.48.236.86:14490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/zi-936.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUQAAALY"] [Tue Aug 18 13:01:48.311664 2026] [security2:error] [pid 139043:tid 139274] [client 138.185.145.78:40532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-site/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUgAAAOo"] [Tue Aug 18 13:01:48.311751 2026] [security2:error] [pid 139043:tid 139274] [client 138.185.145.78:40532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-site/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUgAAAOo"] [Tue Aug 18 13:01:48.312522 2026] [security2:error] [pid 139043:tid 139298] [client 68.221.73.131:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/fb.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVUwAAAQI"] [Tue Aug 18 13:01:48.314406 2026] [security2:error] [pid 123784:tid 123970] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/abcd.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKpQAAADQ"] [Tue Aug 18 13:01:48.319002 2026] [security2:error] [pid 139043:tid 139234] [client 20.119.58.187:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/license.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVVAAAAMI"] [Tue Aug 18 13:01:48.335588 2026] [security2:error] [pid 139043:tid 139295] [client 20.226.112.14:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-conflg.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVVgAAAP8"] [Tue Aug 18 13:01:48.360056 2026] [security2:error] [pid 139043:tid 139210] [client 172.213.243.2:19569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/c4.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVWAAAAKo"] [Tue Aug 18 13:01:48.365971 2026] [security2:error] [pid 123784:tid 123924] [client 20.79.204.6:11861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKpgAAAAY"] [Tue Aug 18 13:01:48.375705 2026] [security2:error] [pid 139043:tid 139285] [client 20.151.109.219:24439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kf.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVWwAAAPU"] [Tue Aug 18 13:01:48.380267 2026] [security2:error] [pid 139043:tid 139268] [client 52.139.47.57:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/x.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXAAAAOQ"] [Tue Aug 18 13:01:48.403620 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:32554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/z.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXQAAAPM"] [Tue Aug 18 13:01:48.410233 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:48.410385 2026] [security2:error] [pid 139043:tid 139211] [client 20.29.77.16:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/pqr.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXgAAAKs"] [Tue Aug 18 13:01:48.410672 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:48.412163 2026] [security2:error] [pid 139043:tid 139248] [client 138.185.145.78:40582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wpsite/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXwAAANA"] [Tue Aug 18 13:01:48.412228 2026] [security2:error] [pid 139043:tid 139248] [client 138.185.145.78:40582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wpsite/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVXwAAANA"] [Tue Aug 18 13:01:48.443813 2026] [security2:error] [pid 139043:tid 139266] [client 52.173.121.69:14999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYgAAAOI"] [Tue Aug 18 13:01:48.459036 2026] [security2:error] [pid 139043:tid 139187] [client 20.104.100.201:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/v5.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYwAAAJM"] [Tue Aug 18 13:01:48.465770 2026] [security2:error] [pid 139043:tid 139218] [client 20.116.17.175:22968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/img.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZQAAALI"] [Tue Aug 18 13:01:48.470587 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/op.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKqgAAABw"] [Tue Aug 18 13:01:48.473287 2026] [security2:error] [pid 139043:tid 139246] [client 20.79.204.6:11673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/about.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZgAAAM4"] [Tue Aug 18 13:01:48.475195 2026] [security2:error] [pid 139043:tid 139230] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVYAAAvhI"] [Tue Aug 18 13:01:48.492637 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/av.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKrAAAFVc"] [Tue Aug 18 13:01:48.495051 2026] [security2:error] [pid 139043:tid 139205] [client 20.79.204.6:10716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/u.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVaAAAAKU"] [Tue Aug 18 13:01:48.503315 2026] [security2:error] [pid 139043:tid 139237] [client 135.225.78.186:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/dex.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVaQAAAMU"] [Tue Aug 18 13:01:48.509358 2026] [security2:error] [pid 123784:tid 123968] [client 158.158.74.177:18983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/kj.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKrQAAADI"] [Tue Aug 18 13:01:48.511742 2026] [security2:error] [pid 139043:tid 139194] [client 138.185.145.78:40638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/new/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVagAAAJo"] [Tue Aug 18 13:01:48.511809 2026] [security2:error] [pid 139043:tid 139194] [client 138.185.145.78:40638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/new/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVagAAAJo"] [Tue Aug 18 13:01:48.527361 2026] [security2:error] [pid 139043:tid 139279] [client 20.118.133.132:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrimotor.com.br"] [uri "/packed.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVawAAAO8"] [Tue Aug 18 13:01:48.558427 2026] [security2:error] [pid 139043:tid 139241] [client 20.80.111.3:33421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/aaa.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbAAAAMk"] [Tue Aug 18 13:01:48.582046 2026] [security2:error] [pid 139043:tid 139292] [client 158.23.17.4:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ij.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbgAAAPw"] [Tue Aug 18 13:01:48.584490 2026] [security2:error] [pid 139043:tid 139259] [client 20.51.153.15:13688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/admin404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVbwAAANs"] [Tue Aug 18 13:01:48.594753 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/222.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcAAAAI8"] [Tue Aug 18 13:01:48.601028 2026] [security2:error] [pid 139043:tid 139239] [client 20.75.92.165:4332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/404.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcQAAAMc"] [Tue Aug 18 13:01:48.613514 2026] [security2:error] [pid 139043:tid 139196] [client 138.185.145.78:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcgAAAJw"] [Tue Aug 18 13:01:48.613583 2026] [security2:error] [pid 139043:tid 139196] [client 138.185.145.78:40694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVcgAAAJw"] [Tue Aug 18 13:01:48.663450 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:8868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-login.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVZwAAAPQ"] [Tue Aug 18 13:01:48.673130 2026] [security2:error] [pid 139043:tid 139214] [client 20.119.58.187:10138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/load.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdQAAAK4"] [Tue Aug 18 13:01:48.684363 2026] [security2:error] [pid 139043:tid 139231] [client 20.151.109.219:14116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/su.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdgAAAL8"] [Tue Aug 18 13:01:48.701451 2026] [security2:error] [pid 123784:tid 123814] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ag.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKsAAAWxk"] [Tue Aug 18 13:01:48.702290 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/admin.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVdwAAANU"] [Tue Aug 18 13:01:48.708819 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:48.709161 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:48.712298 2026] [security2:error] [pid 123784:tid 123991] [client 20.48.236.86:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKsgAAAEk"] [Tue Aug 18 13:01:48.715777 2026] [security2:error] [pid 123784:tid 124028] [client 138.185.145.78:40758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKswAAAG4"] [Tue Aug 18 13:01:48.715854 2026] [security2:error] [pid 123784:tid 124028] [client 138.185.145.78:40758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKswAAAG4"] [Tue Aug 18 13:01:48.736787 2026] [security2:error] [pid 139043:tid 139221] [client 20.104.100.201:49460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/replace.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVegAAALU"] [Tue Aug 18 13:01:48.769129 2026] [security2:error] [pid 123784:tid 123978] [client 172.213.243.2:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/an7.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtQAAADw"] [Tue Aug 18 13:01:48.815186 2026] [security2:error] [pid 123784:tid 123982] [client 138.185.145.78:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtgAAAEA"] [Tue Aug 18 13:01:48.815317 2026] [security2:error] [pid 123784:tid 123982] [client 138.185.145.78:40830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtgAAAEA"] [Tue Aug 18 13:01:48.815987 2026] [security2:error] [pid 139043:tid 139206] [client 20.251.112.238:59537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/bes.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVfwAAAKY"] [Tue Aug 18 13:01:48.820077 2026] [security2:error] [pid 139043:tid 139200] [client 20.51.153.15:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/loading.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVgAAAAKA"] [Tue Aug 18 13:01:48.840670 2026] [security2:error] [pid 123784:tid 123941] [client 213.35.127.232:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKtwAAABc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:48.872763 2026] [security2:error] [pid 123784:tid 123852] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ig.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKuQAAbz8"] [Tue Aug 18 13:01:48.873955 2026] [security2:error] [pid 123784:tid 123990] [client 52.139.47.57:36847] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.compratec.com.br"] [uri "/1.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKugAAAEg"] [Tue Aug 18 13:01:48.874077 2026] [security2:error] [pid 123784:tid 123990] [client 52.139.47.57:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/1.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKugAAAEg"] [Tue Aug 18 13:01:48.883762 2026] [security2:error] [pid 139043:tid 139213] [client 20.250.13.23:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/options-writing.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVgQAAAK0"] [Tue Aug 18 13:01:48.907817 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKuwAAAHE"] [Tue Aug 18 13:01:48.907817 2026] [security2:error] [pid 139043:tid 139203] [client 20.226.112.14:39455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/G-in.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVhAAAAKM"] [Tue Aug 18 13:01:48.908697 2026] [security2:error] [pid 123784:tid 123956] [client 20.29.77.16:33566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvAAAACY"] [Tue Aug 18 13:01:48.917983 2026] [security2:error] [pid 123784:tid 123962] [client 138.185.145.78:40876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvQAAACw"] [Tue Aug 18 13:01:48.918055 2026] [security2:error] [pid 123784:tid 123962] [client 138.185.145.78:40876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKvQAAACw"] [Tue Aug 18 13:01:48.924919 2026] [security2:error] [pid 123784:tid 123934] [client 20.91.215.254:19433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSB7GwDnJBNj2tDbYYKvgAAABA"] [Tue Aug 18 13:01:48.970641 2026] [security2:error] [pid 139043:tid 139254] [client 20.79.204.6:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB7P2v-lWn9OzQT7UVhgAAANY"] [Tue Aug 18 13:01:48.987616 2026] [security2:error] [pid 123784:tid 123949] [client 20.163.43.14:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB7GwDnJBNj2tDbYYKwAAAAB8"] [Tue Aug 18 13:01:48.999006 2026] [security2:error] [pid 139043:tid 139289] [client 20.80.111.3:31240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/fpwch.php"] [unique_id "aoSB7P2v-lWn9OzQT7UViAAAAPk"] [Tue Aug 18 13:01:49.008420 2026] [security2:error] [pid 123784:tid 124044] [client 20.104.100.201:49665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fw/faiyy.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKwgAAAH4"] [Tue Aug 18 13:01:49.011831 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:49.012236 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:49.018858 2026] [security2:error] [pid 139043:tid 139277] [client 138.185.145.78:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViQAAAO0"] [Tue Aug 18 13:01:49.018955 2026] [security2:error] [pid 139043:tid 139277] [client 138.185.145.78:40938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViQAAAO0"] [Tue Aug 18 13:01:49.026674 2026] [security2:error] [pid 123784:tid 123988] [client 20.119.58.187:10481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/manager.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKxAAAAEY"] [Tue Aug 18 13:01:49.060152 2026] [security2:error] [pid 139043:tid 139224] [client 196.12.128.158:56553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViwAAALg"] [Tue Aug 18 13:01:49.060257 2026] [security2:error] [pid 139043:tid 139224] [client 196.12.128.158:56553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UViwAAALg"] [Tue Aug 18 13:01:49.062987 2026] [security2:error] [pid 123784:tid 123942] [client 20.51.153.15:13694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/conn-test.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKxgAAABg"] [Tue Aug 18 13:01:49.085142 2026] [security2:error] [pid 123784:tid 123817] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ta.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKyAAAahw"] [Tue Aug 18 13:01:49.095745 2026] [security2:error] [pid 123784:tid 123926] [client 20.116.17.175:23027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKyQAAAAg"] [Tue Aug 18 13:01:49.096867 2026] [security2:error] [pid 139043:tid 139297] [client 20.79.204.6:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin-header.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVjgAAAQE"] [Tue Aug 18 13:01:49.115340 2026] [security2:error] [pid 139043:tid 139290] [client 4.232.151.198:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/term.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVjwAAAPo"] [Tue Aug 18 13:01:49.127052 2026] [autoindex:error] [pid 123784:tid 123940] [client 20.48.236.86:14827] AH01276: Cannot serve directory /home2/treinolab/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:49.127204 2026] [security2:error] [pid 139043:tid 139255] [client 138.185.145.78:40996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkAAAANc"] [Tue Aug 18 13:01:49.127278 2026] [security2:error] [pid 139043:tid 139255] [client 138.185.145.78:40996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkAAAANc"] [Tue Aug 18 13:01:49.128755 2026] [security2:error] [pid 139043:tid 139295] [client 20.151.109.219:20101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wp-key.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkQAAAP8"] [Tue Aug 18 13:01:49.133440 2026] [security2:error] [pid 123784:tid 123976] [client 172.202.39.151:12737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzAAAADo"] [Tue Aug 18 13:01:49.151638 2026] [security2:error] [pid 123784:tid 123947] [client 20.226.112.14:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xxx.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzgAAAB0"] [Tue Aug 18 13:01:49.178829 2026] [security2:error] [pid 139043:tid 139252] [client 197.184.64.235:41965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkgAAANQ"] [Tue Aug 18 13:01:49.183594 2026] [security2:error] [pid 139043:tid 139252] [client 197.184.64.235:41965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVkgAAANQ"] [Tue Aug 18 13:01:49.184393 2026] [security2:error] [pid 123784:tid 123935] [client 158.23.17.4:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ud.php"] [unique_id "aoSB7WwDnJBNj2tDbYYKzwAAABE"] [Tue Aug 18 13:01:49.215839 2026] [security2:error] [pid 139043:tid 139268] [client 172.213.243.2:34411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlQAAAOQ"] [Tue Aug 18 13:01:49.221586 2026] [security2:error] [pid 139043:tid 139300] [client 20.29.77.16:16540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/info2.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlgAAAQQ"] [Tue Aug 18 13:01:49.224703 2026] [security2:error] [pid 139043:tid 139195] [client 138.185.145.78:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlwAAAJs"] [Tue Aug 18 13:01:49.224783 2026] [security2:error] [pid 139043:tid 139195] [client 138.185.145.78:41048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVlwAAAJs"] [Tue Aug 18 13:01:49.236915 2026] [security2:error] [pid 139043:tid 139283] [client 68.221.73.131:13339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/gi.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmAAAAPM"] [Tue Aug 18 13:01:49.246054 2026] [security2:error] [pid 139043:tid 139232] [client 158.158.74.177:9249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/languages.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmgAAAMA"] [Tue Aug 18 13:01:49.251421 2026] [security2:error] [pid 139043:tid 139281] [client 20.75.92.165:4337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lite.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVmwAAAPE"] [Tue Aug 18 13:01:49.280203 2026] [security2:error] [pid 123784:tid 123967] [client 20.104.100.201:49469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dk.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK0gAAADE"] [Tue Aug 18 13:01:49.295683 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/34.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK0wAAXh0"] [Tue Aug 18 13:01:49.303641 2026] [security2:error] [pid 139043:tid 139262] [client 20.226.112.14:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/un.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVnAAAAN4"] [Tue Aug 18 13:01:49.311833 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:49.312198 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:49.324090 2026] [security2:error] [pid 139043:tid 139257] [client 138.185.145.78:41104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVngAAANk"] [Tue Aug 18 13:01:49.324182 2026] [security2:error] [pid 139043:tid 139257] [client 138.185.145.78:41104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasiltocantins.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVngAAANk"] [Tue Aug 18 13:01:49.329277 2026] [security2:error] [pid 139043:tid 139208] [client 52.139.47.57:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/z.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVnwAAAKg"] [Tue Aug 18 13:01:49.354973 2026] [security2:error] [pid 139043:tid 139230] [client 20.51.153.15:13590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/evil.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVoAAAAL4"] [Tue Aug 18 13:01:49.380667 2026] [security2:error] [pid 139043:tid 139266] [client 20.119.58.187:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/media.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVowAAAOI"] [Tue Aug 18 13:01:49.401935 2026] [security2:error] [pid 123784:tid 123945] [client 20.48.236.86:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/php.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK1wAAABs"] [Tue Aug 18 13:01:49.448792 2026] [security2:error] [pid 139043:tid 139242] [client 20.151.109.219:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gg.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpQAAAMo"] [Tue Aug 18 13:01:49.451204 2026] [security2:error] [pid 139043:tid 139190] [client 20.226.112.14:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/autogooey.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpgAAAJY"] [Tue Aug 18 13:01:49.468667 2026] [security2:error] [pid 139043:tid 139259] [client 20.251.112.238:7112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws60.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVpwAAANs"] [Tue Aug 18 13:01:49.470367 2026] [security2:error] [pid 123784:tid 123854] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/he.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK2QAAY0E"] [Tue Aug 18 13:01:49.509973 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqQAAAJ4"] [Tue Aug 18 13:01:49.559403 2026] [security2:error] [pid 139043:tid 139223] [client 20.104.100.201:49139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/bal.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqgAAALc"] [Tue Aug 18 13:01:49.572584 2026] [security2:error] [pid 139043:tid 139250] [client 20.91.215.254:11460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/alfa-rex1.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVqwAAANI"] [Tue Aug 18 13:01:49.573450 2026] [security2:error] [pid 139043:tid 139194] [client 20.79.204.6:11557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrAAAAJo"] [Tue Aug 18 13:01:49.577686 2026] [security2:error] [pid 139043:tid 139246] [client 20.250.13.23:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrQAAAM4"] [Tue Aug 18 13:01:49.614424 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:49.614674 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:49.620659 2026] [security2:error] [pid 139043:tid 139235] [client 20.75.92.165:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lock360.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVrwAAAMM"] [Tue Aug 18 13:01:49.628371 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/byp8.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVsAAAAME"] [Tue Aug 18 13:01:49.666701 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wso.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVswAAAPs"] [Tue Aug 18 13:01:49.680646 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:13653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp-key.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVtAAAAI4"] [Tue Aug 18 13:01:49.704794 2026] [security2:error] [pid 123784:tid 123931] [client 20.79.204.6:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/admin.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK3wAAAA0"] [Tue Aug 18 13:01:49.707361 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gz.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK4AAAIw0"] [Tue Aug 18 13:01:49.712909 2026] [security2:error] [pid 139043:tid 139179] [client 20.79.204.6:10707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVvwAAAIs"] [Tue Aug 18 13:01:49.714656 2026] [security2:error] [pid 139043:tid 139212] [client 20.206.73.37:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ws13.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwAAAAKw"] [Tue Aug 18 13:01:49.734774 2026] [security2:error] [pid 139043:tid 139263] [client 20.119.58.187:10113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/mar.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwQAAAN8"] [Tue Aug 18 13:01:49.738296 2026] [security2:error] [pid 139043:tid 139206] [client 20.151.109.219:39359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gi.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwgAAAKY"] [Tue Aug 18 13:01:49.752367 2026] [security2:error] [pid 139043:tid 139231] [client 52.139.47.57:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ee.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVwwAAAL8"] [Tue Aug 18 13:01:49.758632 2026] [security2:error] [pid 139043:tid 139225] [client 138.185.145.78:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wordpress/wp-login.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxAAAALk"] [Tue Aug 18 13:01:49.793190 2026] [security2:error] [pid 139043:tid 139288] [client 158.23.17.4:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/hp.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxQAAAPg"] [Tue Aug 18 13:01:49.800926 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.112.14:28786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sty.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxgAAAOU"] [Tue Aug 18 13:01:49.801752 2026] [security2:error] [pid 139043:tid 139213] [client 172.202.39.151:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/an.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVxwAAAK0"] [Tue Aug 18 13:01:49.814754 2026] [security2:error] [pid 139043:tid 139177] [client 20.48.236.86:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/sf.php"] [unique_id "aoSB7f2v-lWn9OzQT7UVyAAAAIk"] [Tue Aug 18 13:01:49.839187 2026] [security2:error] [pid 139043:tid 139289] [client 20.104.100.201:49461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yawa.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV5wAAAPk"] [Tue Aug 18 13:01:49.842575 2026] [security2:error] [pid 123784:tid 124040] [client 20.116.17.175:22929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK4gAAAHo"] [Tue Aug 18 13:01:49.857756 2026] [security2:error] [pid 139043:tid 139278] [client 213.35.127.232:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6AAAAO4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:49.876051 2026] [security2:error] [pid 123784:tid 123906] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nf.php"] [unique_id "aoSB7WwDnJBNj2tDbYYK5AAAN3U"] [Tue Aug 18 13:01:49.908075 2026] [security2:error] [pid 139043:tid 139298] [client 20.29.77.16:33563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/test_info.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6gAAAQI"] [Tue Aug 18 13:01:49.909036 2026] [security2:error] [pid 139043:tid 139297] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/akc.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV6wAAAQE"] [Tue Aug 18 13:01:49.913716 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:49.913994 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:49.945580 2026] [security2:error] [pid 139043:tid 139295] [client 20.51.153.15:13676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV7QAAAP8"] [Tue Aug 18 13:01:49.959256 2026] [security2:error] [pid 139043:tid 139201] [client 68.221.73.131:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/video.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV7wAAAKE"] [Tue Aug 18 13:01:49.994211 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:8862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/sf.php"] [unique_id "aoSB7f2v-lWn9OzQT7UV8QAAAQQ"] [Tue Aug 18 13:01:50.032412 2026] [security2:error] [pid 123784:tid 124001] [client 20.151.109.219:39311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pz.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7QAAAFM"] [Tue Aug 18 13:01:50.036434 2026] [security2:error] [pid 123784:tid 124041] [client 172.213.243.2:16848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/plugins.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7gAAAHs"] [Tue Aug 18 13:01:50.084103 2026] [security2:error] [pid 123784:tid 124037] [client 135.225.78.186:58109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/puc.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK7wAAAHc"] [Tue Aug 18 13:01:50.085011 2026] [security2:error] [pid 139043:tid 139187] [client 20.75.92.165:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV9AAAAJM"] [Tue Aug 18 13:01:50.086431 2026] [security2:error] [pid 139043:tid 139191] [client 20.119.58.187:10550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/my1.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV9QAAAJc"] [Tue Aug 18 13:01:50.089029 2026] [security2:error] [pid 123784:tid 123890] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xv.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK8AAAOGU"] [Tue Aug 18 13:01:50.101450 2026] [security2:error] [pid 139043:tid 139257] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/robots.txt"] [unique_id "aoSB7v2v-lWn9OzQT7UV9wAAANk"] [Tue Aug 18 13:01:50.115147 2026] [security2:error] [pid 139043:tid 139208] [client 20.104.100.201:49431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-AAAAKg"] [Tue Aug 18 13:01:50.117284 2026] [security2:error] [pid 139043:tid 139218] [client 158.158.74.177:22899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/nw.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-QAAALI"] [Tue Aug 18 13:01:50.122466 2026] [security2:error] [pid 139043:tid 139247] [client 20.203.183.135:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/media.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV-gAAAM8"] [Tue Aug 18 13:01:50.157051 2026] [security2:error] [pid 139043:tid 139205] [client 20.251.112.238:26163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/olfclass.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_AAAAKU"] [Tue Aug 18 13:01:50.164688 2026] [security2:error] [pid 139043:tid 139184] [client 158.23.17.4:15155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ip.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_gAAAJA"] [Tue Aug 18 13:01:50.171291 2026] [security2:error] [pid 123784:tid 123925] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/ms/campo-grande/santa-fe/img/rua-abrao-julio-rahe-de-2116-2117-ao-fim-santa-fe-campo-grande-ms.webp"] [unique_id "aoSB7mwDnJBNj2tDbYYK8gAAAAc"] [Tue Aug 18 13:01:50.180103 2026] [security2:error] [pid 139043:tid 139268] [client 20.79.204.6:11554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSB7v2v-lWn9OzQT7UV_wAAAOQ"] [Tue Aug 18 13:01:50.197998 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/buy.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK8wAAADM"] [Tue Aug 18 13:01:50.210044 2026] [security2:error] [pid 139043:tid 139281] [client 52.139.47.57:3843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/we.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAAAAAPE"] [Tue Aug 18 13:01:50.214706 2026] [security2:error] [pid 139043:tid 139248] [client 20.226.112.14:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wio.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAQAAANA"] [Tue Aug 18 13:01:50.215894 2026] [security2:error] [pid 139043:tid 139283] [client 20.250.13.23:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/maint.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAgAAAPM"] [Tue Aug 18 13:01:50.255211 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/mimes.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWAwAAAQM"] [Tue Aug 18 13:01:50.259643 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mx.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK9QAAZiM"] [Tue Aug 18 13:01:50.290252 2026] [security2:error] [pid 123784:tid 124014] [client 20.65.98.162:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/xx.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK9gAAAGA"] [Tue Aug 18 13:01:50.295741 2026] [security2:error] [pid 139043:tid 139190] [client 20.48.236.86:14786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/xx.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWEgAAAJY"] [Tue Aug 18 13:01:50.310383 2026] [security2:error] [pid 139043:tid 139219] [client 20.79.204.6:11699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/content.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWFQAAALM"] [Tue Aug 18 13:01:50.322579 2026] [security2:error] [pid 139043:tid 139211] [client 20.91.215.254:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWFwAAAKs"] [Tue Aug 18 13:01:50.333091 2026] [security2:error] [pid 139043:tid 139294] [client 102.213.179.104:51529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGAAAAP4"] [Tue Aug 18 13:01:50.333234 2026] [security2:error] [pid 139043:tid 139294] [client 102.213.179.104:51529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGAAAAP4"] [Tue Aug 18 13:01:50.361947 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/1061.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGQAAAI8"] [Tue Aug 18 13:01:50.373959 2026] [security2:error] [pid 139043:tid 139198] [client 20.151.109.219:39301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kk.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGgAAAJ4"] [Tue Aug 18 13:01:50.380448 2026] [security2:error] [pid 139043:tid 139272] [client 20.163.43.14:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/index/function.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWGwAAAOg"] [Tue Aug 18 13:01:50.389334 2026] [security2:error] [pid 139043:tid 139128] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHAAA91Q"] [Tue Aug 18 13:01:50.389490 2026] [security2:error] [pid 139043:tid 139287] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHAAA91Q"] [Tue Aug 18 13:01:50.391640 2026] [security2:error] [pid 139043:tid 139223] [client 20.104.100.201:49664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/7.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWHQAAALc"] [Tue Aug 18 13:01:50.439533 2026] [security2:error] [pid 123784:tid 123921] [client 20.119.58.187:10163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/mm.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK-gAAAAM"] [Tue Aug 18 13:01:50.448382 2026] [security2:error] [pid 139043:tid 139270] [client 172.213.243.2:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/100.kb.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWJQAAAOY"] [Tue Aug 18 13:01:50.482599 2026] [security2:error] [pid 123784:tid 123929] [client 20.116.17.175:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK-wAAAAs"] [Tue Aug 18 13:01:50.511478 2026] [security2:error] [pid 139043:tid 139221] [client 20.51.153.15:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWKQAAALU"] [Tue Aug 18 13:01:50.579534 2026] [security2:error] [pid 139043:tid 139225] [client 172.202.39.151:40351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWLgAAALk"] [Tue Aug 18 13:01:50.592075 2026] [security2:error] [pid 139043:tid 139175] [client 20.226.112.14:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gec.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWMwAAAIc"] [Tue Aug 18 13:01:50.599367 2026] [security2:error] [pid 139043:tid 139186] [client 20.29.77.16:16530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/xynz1.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWNAAAAJI"] [Tue Aug 18 13:01:50.658031 2026] [security2:error] [pid 123784:tid 123997] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/cong.php"] [unique_id "aoSB7mwDnJBNj2tDbYYK_wAAAE8"] [Tue Aug 18 13:01:50.669703 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ws77.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWNgAAANY"] [Tue Aug 18 13:01:50.712278 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/edit.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOAAAAOo"] [Tue Aug 18 13:01:50.713416 2026] [security2:error] [pid 139043:tid 139200] [client 52.139.47.57:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/to.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOQAAAKA"] [Tue Aug 18 13:01:50.741004 2026] [security2:error] [pid 139043:tid 139220] [client 78.47.98.55:61510] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWOgAAALQ"], referer: https://dadicamotors.com.br/ [Tue Aug 18 13:01:50.767575 2026] [security2:error] [pid 123784:tid 123978] [client 20.51.153.15:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/pqr.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLBgAAADw"] [Tue Aug 18 13:01:50.790850 2026] [security2:error] [pid 123784:tid 123959] [client 20.119.58.187:10470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/network.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLCQAAACk"] [Tue Aug 18 13:01:50.792398 2026] [security2:error] [pid 123784:tid 124025] [client 66.187.6.102:55102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/js/splitting.js"] [unique_id "aoSB7mwDnJBNj2tDbYYLCwAAAGs"] [Tue Aug 18 13:01:50.809783 2026] [security2:error] [pid 123784:tid 123955] [client 158.158.74.177:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLDQAAACU"] [Tue Aug 18 13:01:50.809886 2026] [security2:error] [pid 139043:tid 139255] [client 20.75.92.165:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWQQAAANc"] [Tue Aug 18 13:01:50.810031 2026] [security2:error] [pid 139043:tid 139295] [client 20.127.136.245:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/xmr.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWQgAAAP8"] [Tue Aug 18 13:01:50.814073 2026] [security2:error] [pid 123784:tid 123939] [client 66.187.6.102:55024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/categories/thumbs/a9781358edccedce831bca15a7f77824.svg"] [unique_id "aoSB7mwDnJBNj2tDbYYLDwAAABU"] [Tue Aug 18 13:01:50.814182 2026] [security2:error] [pid 123784:tid 123939] [client 66.187.6.102:55024] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/categories/thumbs/a9781358edccedce831bca15a7f77824.svg"] [unique_id "aoSB7mwDnJBNj2tDbYYLDwAAABU"] [Tue Aug 18 13:01:50.817710 2026] [security2:error] [pid 123784:tid 123980] [client 66.187.6.102:55010] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/plasticos"] [unique_id "aoSB7mwDnJBNj2tDbYYLEgAAAD4"] [Tue Aug 18 13:01:50.818840 2026] [security2:error] [pid 123784:tid 123927] [client 66.187.6.102:55064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/6351ef1a0d96cf5bfb60bda2109f0bdc.png"] [unique_id "aoSB7mwDnJBNj2tDbYYLFgAAAAk"] [Tue Aug 18 13:01:50.818955 2026] [security2:error] [pid 123784:tid 123927] [client 66.187.6.102:55064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/6351ef1a0d96cf5bfb60bda2109f0bdc.png"] [unique_id "aoSB7mwDnJBNj2tDbYYLFgAAAAk"] [Tue Aug 18 13:01:50.819765 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:50.820070 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:50.826982 2026] [security2:error] [pid 139043:tid 139201] [client 158.23.17.4:44840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wx.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSAAAAKE"] [Tue Aug 18 13:01:50.835934 2026] [security2:error] [pid 139043:tid 139252] [client 20.48.236.86:14795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/uwu.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSQAAANQ"] [Tue Aug 18 13:01:50.836068 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/45.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLGQAAEm0"] [Tue Aug 18 13:01:50.841523 2026] [security2:error] [pid 139043:tid 139285] [client 20.203.183.135:20626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/admin.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSgAAAPU"] [Tue Aug 18 13:01:50.851449 2026] [security2:error] [pid 139043:tid 139232] [client 216.244.66.232:51626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSwAAAMA"] [Tue Aug 18 13:01:50.851576 2026] [security2:error] [pid 139043:tid 139232] [client 216.244.66.232:51626] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWSwAAAMA"] [Tue Aug 18 13:01:50.854852 2026] [security2:error] [pid 139043:tid 139293] [client 66.187.6.102:55144] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/js/scrolltrigger.js"] [unique_id "aoSB7v2v-lWn9OzQT7UWTAAAAP0"] [Tue Aug 18 13:01:50.859324 2026] [security2:error] [pid 123784:tid 123970] [client 20.250.13.23:6468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/phpMailer.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLHQAAADQ"] [Tue Aug 18 13:01:50.862872 2026] [security2:error] [pid 139043:tid 139251] [client 66.187.6.102:55124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/limpeza"] [unique_id "aoSB7v2v-lWn9OzQT7UWTwAAANM"] [Tue Aug 18 13:01:50.870675 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUAAAAI4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:50.878061 2026] [security2:error] [pid 139043:tid 139187] [client 172.213.243.2:36107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mamzi.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUQAAAJM"] [Tue Aug 18 13:01:50.885320 2026] [security2:error] [pid 139043:tid 139191] [client 20.251.112.238:18228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wpver.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUgAAAJc"] [Tue Aug 18 13:01:50.941751 2026] [security2:error] [pid 139043:tid 139247] [client 20.104.100.201:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/read.php"] [unique_id "aoSB7v2v-lWn9OzQT7UWUwAAAM8"] [Tue Aug 18 13:01:50.970839 2026] [security2:error] [pid 123784:tid 123988] [client 20.116.17.175:53821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/1xmomo.php"] [unique_id "aoSB7mwDnJBNj2tDbYYLIAAAAEY"] [Tue Aug 18 13:01:51.011869 2026] [security2:error] [pid 139043:tid 139245] [client 158.23.17.4:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/99.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVQAAAM0"] [Tue Aug 18 13:01:51.017495 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:13599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/lmfi2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVgAAANA"] [Tue Aug 18 13:01:51.035220 2026] [security2:error] [pid 139043:tid 139290] [client 20.91.215.254:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/xmrlpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWVwAAAPo"] [Tue Aug 18 13:01:51.036074 2026] [security2:error] [pid 139043:tid 139176] [client 20.226.112.14:22968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/scx.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWWAAAAIg"] [Tue Aug 18 13:01:51.079700 2026] [security2:error] [pid 123784:tid 123836] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wy.php"] [unique_id "aoSB72wDnJBNj2tDbYYLIwAAXS8"] [Tue Aug 18 13:01:51.101428 2026] [security2:error] [pid 139043:tid 139294] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWXAAAAP4"] [Tue Aug 18 13:01:51.110653 2026] [security2:error] [pid 139043:tid 139189] [client 20.151.109.219:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/phpcheck.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWZQAAAJU"] [Tue Aug 18 13:01:51.110916 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.112.14:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-admin/sc.php"] [unique_id "aoSB72wDnJBNj2tDbYYLJgAAAFI"] [Tue Aug 18 13:01:51.115999 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:51.116256 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:51.136879 2026] [security2:error] [pid 123784:tid 123958] [client 20.48.236.86:14807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/signon.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKAAAACg"] [Tue Aug 18 13:01:51.138329 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.112.14:39431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp5.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKQAAAEE"] [Tue Aug 18 13:01:51.145121 2026] [security2:error] [pid 123784:tid 123942] [client 20.119.58.187:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/new.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKgAAABg"] [Tue Aug 18 13:01:51.152422 2026] [security2:error] [pid 139043:tid 139183] [client 20.29.77.16:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/album.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWegAAAI8"] [Tue Aug 18 13:01:51.173337 2026] [security2:error] [pid 123784:tid 124007] [client 172.202.39.151:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/tes.php"] [unique_id "aoSB72wDnJBNj2tDbYYLKwAAAFk"] [Tue Aug 18 13:01:51.179983 2026] [security2:error] [pid 139043:tid 139229] [client 52.139.47.57:3819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ty.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfAAAAL0"] [Tue Aug 18 13:01:51.213028 2026] [security2:error] [pid 139043:tid 139202] [client 20.104.100.201:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/albin.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfQAAAKI"] [Tue Aug 18 13:01:51.216549 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:8838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWfgAAAJE"] [Tue Aug 18 13:01:51.251960 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/a2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWgAAAAM4"] [Tue Aug 18 13:01:51.252328 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/info2.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWgQAAAKk"] [Tue Aug 18 13:01:51.293909 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:11657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkAAAAMk"] [Tue Aug 18 13:01:51.295704 2026] [security2:error] [pid 139043:tid 139265] [client 86.120.159.145:14589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkQAAAOE"] [Tue Aug 18 13:01:51.296085 2026] [security2:error] [pid 139043:tid 139265] [client 86.120.159.145:14589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkQAAAOE"] [Tue Aug 18 13:01:51.296630 2026] [security2:error] [pid 139043:tid 139296] [client 172.213.243.2:19534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ms.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkgAAAQA"] [Tue Aug 18 13:01:51.308363 2026] [security2:error] [pid 139043:tid 139192] [client 20.79.204.6:11859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWkwAAAJg"] [Tue Aug 18 13:01:51.340731 2026] [security2:error] [pid 123784:tid 123967] [client 20.226.112.14:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/app.php"] [unique_id "aoSB72wDnJBNj2tDbYYLLgAAADE"] [Tue Aug 18 13:01:51.418279 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:51.418559 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:51.429752 2026] [security2:error] [pid 123784:tid 123945] [client 66.187.6.102:54974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/1d40fb9ad67c3ac6459bc693cadb7c0c.png"] [unique_id "aoSB72wDnJBNj2tDbYYLMgAAABs"] [Tue Aug 18 13:01:51.429889 2026] [security2:error] [pid 123784:tid 123945] [client 66.187.6.102:54974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/1d40fb9ad67c3ac6459bc693cadb7c0c.png"] [unique_id "aoSB72wDnJBNj2tDbYYLMgAAABs"] [Tue Aug 18 13:01:51.447476 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/db.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWmAAAAMQ"] [Tue Aug 18 13:01:51.461710 2026] [security2:error] [pid 139043:tid 139199] [client 20.79.204.6:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/h.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWnwAAAJ8"] [Tue Aug 18 13:01:51.466334 2026] [security2:error] [pid 139043:tid 139274] [client 20.75.92.165:2035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.alf.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWoAAAAOo"] [Tue Aug 18 13:01:51.469189 2026] [autoindex:error] [pid 139043:tid 139238] [client 158.158.74.177:25544] AH01276: Cannot serve directory /home2/guscarautomoveis/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:51.472970 2026] [security2:error] [pid 123784:tid 124032] [client 20.151.109.219:60905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dg.php"] [unique_id "aoSB72wDnJBNj2tDbYYLPQAAAHI"] [Tue Aug 18 13:01:51.485228 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/er.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWowAAAIY"] [Tue Aug 18 13:01:51.486025 2026] [security2:error] [pid 139043:tid 139220] [client 20.104.100.201:49666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fw/34.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpAAAALQ"] [Tue Aug 18 13:01:51.488637 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:13657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/test_info.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpQAAAPg"] [Tue Aug 18 13:01:51.491421 2026] [security2:error] [pid 139043:tid 139197] [client 20.250.13.23:6526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpgAAAJ0"] [Tue Aug 18 13:01:51.497864 2026] [security2:error] [pid 139043:tid 139225] [client 20.119.58.187:10143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/0x.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWpwAAALk"] [Tue Aug 18 13:01:51.511294 2026] [security2:error] [pid 139043:tid 139276] [client 20.116.17.175:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWqAAAAOw"] [Tue Aug 18 13:01:51.581752 2026] [security2:error] [pid 139043:tid 139213] [client 20.48.236.86:14818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file61.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrAAAAK0"] [Tue Aug 18 13:01:51.602527 2026] [security2:error] [pid 139043:tid 139252] [client 20.163.43.14:8768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-good.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrQAAANQ"] [Tue Aug 18 13:01:51.610281 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.112.14:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-content/admin.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWrgAAAJs"] [Tue Aug 18 13:01:51.610395 2026] [security2:error] [pid 123784:tid 123790] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/f.php"] [unique_id "aoSB72wDnJBNj2tDbYYLQAAANwE"] [Tue Aug 18 13:01:51.620291 2026] [security2:error] [pid 123784:tid 123930] [client 52.139.47.57:60545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ak.php"] [unique_id "aoSB72wDnJBNj2tDbYYLQQAAAAw"] [Tue Aug 18 13:01:51.649916 2026] [security2:error] [pid 139043:tid 139216] [client 68.221.73.131:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/hel.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWsgAAALA"] [Tue Aug 18 13:01:51.674933 2026] [security2:error] [pid 139043:tid 139247] [client 158.158.74.177:25544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWswAAAM8"] [Tue Aug 18 13:01:51.692407 2026] [security2:error] [pid 139043:tid 139237] [client 20.29.77.16:61115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/creds.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWtAAAAMU"] [Tue Aug 18 13:01:51.712707 2026] [security2:error] [pid 123784:tid 124005] [client 20.91.215.254:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/user/12.php"] [unique_id "aoSB72wDnJBNj2tDbYYLSAAAAFc"] [Tue Aug 18 13:01:51.718216 2026] [security2:error] [pid 123784:tid 124042] [client 172.213.243.2:45921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gfile.php"] [unique_id "aoSB72wDnJBNj2tDbYYLSQAAAHw"] [Tue Aug 18 13:01:51.744031 2026] [security2:error] [pid 123784:tid 123996] [client 20.51.153.15:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/xynz1.php"] [unique_id "aoSB72wDnJBNj2tDbYYLTwAAAE4"] [Tue Aug 18 13:01:51.759294 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:49441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp9.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWuQAAAO8"] [Tue Aug 18 13:01:51.769874 2026] [security2:error] [pid 139043:tid 139190] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/dropdown.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWugAAAJY"] [Tue Aug 18 13:01:51.796704 2026] [security2:error] [pid 139043:tid 139280] [client 20.226.112.14:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/cxc.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWuwAAAPA"] [Tue Aug 18 13:01:51.807256 2026] [security2:error] [pid 139043:tid 139294] [client 66.187.6.102:54952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos"] [unique_id "aoSB7_2v-lWn9OzQT7UWvAAAAP4"] [Tue Aug 18 13:01:51.807363 2026] [security2:error] [pid 139043:tid 139294] [client 66.187.6.102:54952] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos"] [unique_id "aoSB7_2v-lWn9OzQT7UWvAAAAP4"] [Tue Aug 18 13:01:51.841617 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/bm.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWvQAAAK8"] [Tue Aug 18 13:01:51.848765 2026] [security2:error] [pid 139043:tid 139180] [client 52.173.121.69:15003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWvwAAAIw"] [Tue Aug 18 13:01:51.851536 2026] [security2:error] [pid 139043:tid 139290] [client 20.119.58.187:10534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/0.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWwAAAAPo"] [Tue Aug 18 13:01:51.890952 2026] [security2:error] [pid 139043:tid 139295] [client 213.35.127.232:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWwQAAAP8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:51.896697 2026] [security2:error] [pid 123784:tid 123921] [client 20.75.92.165:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSB72wDnJBNj2tDbYYLVAAAAAM"] [Tue Aug 18 13:01:51.909534 2026] [security2:error] [pid 139043:tid 139188] [client 20.79.204.6:11583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWwgAAAJQ"] [Tue Aug 18 13:01:51.910353 2026] [security2:error] [pid 139043:tid 139249] [client 20.79.204.6:11581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSB7_2v-lWn9OzQT7UWwwAAANE"] [Tue Aug 18 13:01:51.922641 2026] [security2:error] [pid 123784:tid 123997] [client 20.116.17.175:22942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/term.php"] [unique_id "aoSB72wDnJBNj2tDbYYLVQAAAE8"] [Tue Aug 18 13:01:51.952089 2026] [security2:error] [pid 139043:tid 139287] [client 158.23.17.4:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qk.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxQAAAPc"] [Tue Aug 18 13:01:51.952122 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:40335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxAAAANw"] [Tue Aug 18 13:01:52.000048 2026] [security2:error] [pid 139043:tid 139244] [client 20.206.96.72:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/inputs.php"] [unique_id "aoSB7_2v-lWn9OzQT7UWxgAAAMw"] [Tue Aug 18 13:01:52.019362 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:52.019617 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:52.031770 2026] [security2:error] [pid 139043:tid 139192] [client 20.104.100.201:49703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/save.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWygAAAJg"] [Tue Aug 18 13:01:52.032415 2026] [security2:error] [pid 139043:tid 139258] [client 20.206.96.72:15461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/admin.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWywAAANo"] [Tue Aug 18 13:01:52.051327 2026] [security2:error] [pid 123784:tid 123965] [client 20.51.153.15:13611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/album.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLWwAAAC8"] [Tue Aug 18 13:01:52.057191 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.96.72:15465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/goods.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWzQAAAPs"] [Tue Aug 18 13:01:52.073970 2026] [security2:error] [pid 139043:tid 139226] [client 20.251.112.238:33969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/thui.php"] [unique_id "aoSB8P2v-lWn9OzQT7UWzwAAALo"] [Tue Aug 18 13:01:52.109673 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:28563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/alfa-rex.php7"] [unique_id "aoSB8P2v-lWn9OzQT7UW0AAAAL8"] [Tue Aug 18 13:01:52.110246 2026] [security2:error] [pid 123784:tid 123952] [client 52.139.47.57:18310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/fm.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLXAAAACI"] [Tue Aug 18 13:01:52.113490 2026] [security2:error] [pid 139043:tid 139175] [client 20.48.236.86:14517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/copypaths.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW0QAAAIc"] [Tue Aug 18 13:01:52.120893 2026] [security2:error] [pid 139043:tid 139178] [client 20.206.96.72:15459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/file.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW0wAAAIo"] [Tue Aug 18 13:01:52.126550 2026] [security2:error] [pid 139043:tid 139212] [client 172.213.243.2:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW1QAAAKw"] [Tue Aug 18 13:01:52.189905 2026] [security2:error] [pid 123784:tid 123936] [client 20.29.77.16:40563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/mandrill.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYAAAABI"] [Tue Aug 18 13:01:52.189905 2026] [security2:error] [pid 139043:tid 139220] [client 20.206.96.72:15278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/adminfuns.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW1gAAALQ"] [Tue Aug 18 13:01:52.203411 2026] [security2:error] [pid 123784:tid 123941] [client 20.119.58.187:10519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/oxshell.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYgAAABc"] [Tue Aug 18 13:01:52.206433 2026] [security2:error] [pid 123784:tid 123905] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/30.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLYwAAHHQ"] [Tue Aug 18 13:01:52.208334 2026] [security2:error] [pid 123784:tid 124018] [client 4.232.151.198:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZAAAAGQ"] [Tue Aug 18 13:01:52.218409 2026] [security2:error] [pid 123784:tid 123950] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/file.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZQAAACA"] [Tue Aug 18 13:01:52.243084 2026] [security2:error] [pid 123784:tid 123970] [client 20.206.96.72:15279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/404.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLZwAAADQ"] [Tue Aug 18 13:01:52.255275 2026] [security2:error] [pid 123784:tid 124016] [client 20.151.109.219:39327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vu.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLaAAAAGI"] [Tue Aug 18 13:01:52.264196 2026] [security2:error] [pid 139043:tid 139265] [client 20.250.13.23:6508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/al.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2AAAAOE"] [Tue Aug 18 13:01:52.287839 2026] [security2:error] [pid 123784:tid 124031] [client 20.206.96.72:15282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wk/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLawAAAHE"] [Tue Aug 18 13:01:52.298731 2026] [security2:error] [pid 123784:tid 123962] [client 20.163.43.14:8886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/tes.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLbAAAACw"] [Tue Aug 18 13:01:52.302262 2026] [security2:error] [pid 139043:tid 139179] [client 158.158.74.177:22908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2gAAAIs"] [Tue Aug 18 13:01:52.306072 2026] [security2:error] [pid 139043:tid 139263] [client 20.104.100.201:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-rrtx.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW2wAAAN8"] [Tue Aug 18 13:01:52.308539 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/creds.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3AAAAOw"] [Tue Aug 18 13:01:52.321214 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:52.321527 2026] [authz_core:error] [pid 123784:tid 123842] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:52.355978 2026] [security2:error] [pid 139043:tid 139300] [client 20.203.183.135:12932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/mac.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3gAAAQQ"] [Tue Aug 18 13:01:52.393244 2026] [security2:error] [pid 139043:tid 139252] [client 158.23.17.4:58742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW3wAAANQ"] [Tue Aug 18 13:01:52.404797 2026] [security2:error] [pid 139043:tid 139282] [client 20.206.96.72:15431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4AAAAPI"] [Tue Aug 18 13:01:52.415539 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:10740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4QAAAMk"] [Tue Aug 18 13:01:52.448975 2026] [security2:error] [pid 123784:tid 123988] [client 20.75.92.165:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLdQAAAEY"] [Tue Aug 18 13:01:52.464535 2026] [security2:error] [pid 139043:tid 139200] [client 20.206.96.72:15445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/term.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW4gAAAKA"] [Tue Aug 18 13:01:52.492738 2026] [security2:error] [pid 139043:tid 139247] [client 20.206.96.72:15274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ioxi-o.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5QAAAM8"] [Tue Aug 18 13:01:52.510778 2026] [security2:error] [pid 123784:tid 124011] [client 20.127.136.245:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/about.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLdwAAAF0"] [Tue Aug 18 13:01:52.513512 2026] [security2:error] [pid 139043:tid 139264] [client 20.79.204.6:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5gAAAOA"] [Tue Aug 18 13:01:52.523685 2026] [security2:error] [pid 123784:tid 123977] [client 52.139.47.57:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLeAAAADs"] [Tue Aug 18 13:01:52.524179 2026] [security2:error] [pid 123784:tid 123949] [client 20.79.204.6:11848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLeQAAAB8"] [Tue Aug 18 13:01:52.537090 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:22931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/black.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW5wAAANA"] [Tue Aug 18 13:01:52.538120 2026] [security2:error] [pid 139043:tid 139279] [client 172.213.243.2:19546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/cu.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6AAAAO8"] [Tue Aug 18 13:01:52.543569 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/mandrill.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6QAAAQM"] [Tue Aug 18 13:01:52.566465 2026] [security2:error] [pid 139043:tid 139191] [client 20.119.58.187:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/php8.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW6gAAAJc"] [Tue Aug 18 13:01:52.576955 2026] [security2:error] [pid 139043:tid 139259] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/goods.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7AAAANs"] [Tue Aug 18 13:01:52.584816 2026] [security2:error] [pid 139043:tid 139215] [client 20.91.215.254:11461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/ku.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7QAAAK8"] [Tue Aug 18 13:01:52.585733 2026] [security2:error] [pid 139043:tid 139180] [client 20.104.100.201:49442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/gecko-new.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7gAAAIw"] [Tue Aug 18 13:01:52.588558 2026] [security2:error] [pid 139043:tid 139290] [client 20.48.236.86:14537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bless6.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW7wAAAPo"] [Tue Aug 18 13:01:52.616521 2026] [security2:error] [pid 139043:tid 139262] [client 158.23.17.4:6340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/dj.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8AAAAN4"] [Tue Aug 18 13:01:52.618302 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15249] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/1.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8QAAAM0"] [Tue Aug 18 13:01:52.618402 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/1.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8QAAAM0"] [Tue Aug 18 13:01:52.623007 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:52.623267 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:52.686316 2026] [security2:error] [pid 123784:tid 124030] [client 20.206.96.72:15427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/alfa.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLfQAAAHA"] [Tue Aug 18 13:01:52.695229 2026] [security2:error] [pid 123784:tid 123983] [client 20.163.43.14:8844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/files/index.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLfgAAAEE"] [Tue Aug 18 13:01:52.712062 2026] [security2:error] [pid 139043:tid 139223] [client 135.225.78.186:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/inso.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW8wAAALc"] [Tue Aug 18 13:01:52.718345 2026] [security2:error] [pid 139043:tid 139260] [client 20.206.96.72:15436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/edit.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW9AAAANw"] [Tue Aug 18 13:01:52.746861 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:28777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/0.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW9gAAAPM"] [Tue Aug 18 13:01:52.767419 2026] [security2:error] [pid 139043:tid 139219] [client 20.29.77.16:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/main.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW-AAAALM"] [Tue Aug 18 13:01:52.796972 2026] [security2:error] [pid 139043:tid 139243] [client 20.206.96.72:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/elp.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW-gAAAMs"] [Tue Aug 18 13:01:52.801684 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pu.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLgAAAZ0Y"] [Tue Aug 18 13:01:52.824064 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ic.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_QAAAJI"] [Tue Aug 18 13:01:52.844037 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/main.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLgQAAABE"] [Tue Aug 18 13:01:52.850300 2026] [security2:error] [pid 139043:tid 139178] [client 20.75.92.165:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_gAAAIo"] [Tue Aug 18 13:01:52.860522 2026] [security2:error] [pid 123784:tid 123944] [client 20.104.100.201:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/df.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLggAAABo"] [Tue Aug 18 13:01:52.861522 2026] [security2:error] [pid 139043:tid 139269] [client 20.206.96.72:15243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/classwithtostring.php"] [unique_id "aoSB8P2v-lWn9OzQT7UW_wAAAOU"] [Tue Aug 18 13:01:52.881136 2026] [security2:error] [pid 139043:tid 139067] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAAAAjRc"] [Tue Aug 18 13:01:52.881312 2026] [security2:error] [pid 139043:tid 139181] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAAAAjRc"] [Tue Aug 18 13:01:52.883995 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.13.23:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhAAAACg"] [Tue Aug 18 13:01:52.900080 2026] [security2:error] [pid 139043:tid 139198] [client 4.232.94.69:19570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAQAAAJ4"] [Tue Aug 18 13:01:52.902866 2026] [security2:error] [pid 139043:tid 139190] [client 213.35.127.232:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXAgAAAJY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:52.913235 2026] [security2:error] [pid 123784:tid 123967] [client 20.206.96.72:15261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/666.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhQAAADE"] [Tue Aug 18 13:01:52.919331 2026] [security2:error] [pid 139043:tid 139256] [client 20.119.58.187:10148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/p.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBAAAANg"] [Tue Aug 18 13:01:52.924332 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:52.924599 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:52.945186 2026] [security2:error] [pid 139043:tid 139197] [client 172.202.39.151:47693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/404.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBQAAAJ0"] [Tue Aug 18 13:01:52.954840 2026] [security2:error] [pid 123784:tid 123982] [client 172.213.243.2:45938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/X57.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLhwAAAEA"] [Tue Aug 18 13:01:52.959922 2026] [security2:error] [pid 123784:tid 124007] [client 52.139.47.57:12609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/33.php"] [unique_id "aoSB8GwDnJBNj2tDbYYLiQAAAFk"] [Tue Aug 18 13:01:52.963407 2026] [security2:error] [pid 139043:tid 139196] [client 20.226.112.14:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/dom.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBgAAAJw"] [Tue Aug 18 13:01:52.970831 2026] [security2:error] [pid 139043:tid 139265] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/hplfuns.php"] [unique_id "aoSB8P2v-lWn9OzQT7UXBwAAAOE"] [Tue Aug 18 13:01:53.012076 2026] [security2:error] [pid 139043:tid 139179] [client 20.116.17.175:23009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/as.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCAAAAIs"] [Tue Aug 18 13:01:53.014944 2026] [security2:error] [pid 139043:tid 139193] [client 158.158.74.177:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/f7.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCQAAAJk"] [Tue Aug 18 13:01:53.020392 2026] [security2:error] [pid 123784:tid 124017] [client 20.206.96.72:15288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ws54.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjAAAAGM"] [Tue Aug 18 13:01:53.022095 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCgAAAN8"] [Tue Aug 18 13:01:53.028408 2026] [security2:error] [pid 123784:tid 124003] [client 20.226.112.14:32525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/bb.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjQAAAFU"] [Tue Aug 18 13:01:53.080495 2026] [security2:error] [pid 139043:tid 139234] [client 20.51.153.15:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/payout.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXCwAAAMI"] [Tue Aug 18 13:01:53.099616 2026] [security2:error] [pid 123784:tid 124002] [client 20.206.96.72:15280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/deepseek_d.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLjwAAAFQ"] [Tue Aug 18 13:01:53.106946 2026] [security2:error] [pid 139043:tid 139274] [client 132.196.30.78:17682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDAAAAOo"] [Tue Aug 18 13:01:53.111120 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:11536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDQAAAPg"] [Tue Aug 18 13:01:53.114952 2026] [security2:error] [pid 139043:tid 139252] [client 216.244.66.232:57764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDwAAANQ"] [Tue Aug 18 13:01:53.115039 2026] [security2:error] [pid 139043:tid 139252] [client 216.244.66.232:57764] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXDwAAANQ"] [Tue Aug 18 13:01:53.116488 2026] [security2:error] [pid 139043:tid 139282] [client 20.29.77.16:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/payout.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEAAAAPI"] [Tue Aug 18 13:01:53.118446 2026] [security2:error] [pid 139043:tid 139285] [client 20.48.236.86:14498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/special.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEQAAAPU"] [Tue Aug 18 13:01:53.125954 2026] [security2:error] [pid 123784:tid 124019] [client 20.79.204.6:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkAAAAGU"] [Tue Aug 18 13:01:53.130334 2026] [security2:error] [pid 123784:tid 124008] [client 20.79.204.6:10709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/a7.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkQAAAFo"] [Tue Aug 18 13:01:53.137827 2026] [security2:error] [pid 123784:tid 123930] [client 20.104.100.201:49701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLkgAAAAw"] [Tue Aug 18 13:01:53.142582 2026] [security2:error] [pid 139043:tid 139293] [client 20.226.112.14:22867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ok.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEgAAAP0"] [Tue Aug 18 13:01:53.153293 2026] [security2:error] [pid 139043:tid 139195] [client 20.206.96.72:15277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/function/function.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXEwAAAJs"] [Tue Aug 18 13:01:53.177084 2026] [security2:error] [pid 139043:tid 139208] [client 20.151.109.219:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ue.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFAAAAKg"] [Tue Aug 18 13:01:53.230805 2026] [security2:error] [pid 123784:tid 124036] [client 20.206.96.72:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/nw.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLlQAAAHY"] [Tue Aug 18 13:01:53.248717 2026] [security2:error] [pid 139043:tid 139281] [client 158.23.17.4:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fs.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFgAAAPE"] [Tue Aug 18 13:01:53.259627 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp9.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLlgAAAHM"] [Tue Aug 18 13:01:53.273734 2026] [security2:error] [pid 139043:tid 139204] [client 20.119.58.187:10477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/php.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXFwAAAKQ"] [Tue Aug 18 13:01:53.288407 2026] [security2:error] [pid 139043:tid 139211] [client 172.202.39.151:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/files/index.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGAAAAKs"] [Tue Aug 18 13:01:53.303009 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/txets.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGQAAAQA"] [Tue Aug 18 13:01:53.317381 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/Mailgun.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGgAAAIw"] [Tue Aug 18 13:01:53.321324 2026] [security2:error] [pid 139043:tid 139294] [client 20.206.96.72:15248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/xleet.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXGwAAAP4"] [Tue Aug 18 13:01:53.352132 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/htaccess.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHAAAAOk"] [Tue Aug 18 13:01:53.360991 2026] [security2:error] [pid 123784:tid 124014] [client 20.163.43.14:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/images/images/about.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmAAAAGA"] [Tue Aug 18 13:01:53.367944 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/forbidals.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHgAAAL0"] [Tue Aug 18 13:01:53.379821 2026] [security2:error] [pid 139043:tid 139298] [client 20.206.96.72:15468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXHwAAAQI"] [Tue Aug 18 13:01:53.382402 2026] [security2:error] [pid 139043:tid 139207] [client 52.139.47.57:39477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/az.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIAAAAKc"] [Tue Aug 18 13:01:53.408928 2026] [security2:error] [pid 139043:tid 139249] [client 20.104.100.201:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/usr.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIQAAANE"] [Tue Aug 18 13:01:53.421771 2026] [security2:error] [pid 139043:tid 139228] [client 20.226.112.14:39484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws59.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXIgAAALw"] [Tue Aug 18 13:01:53.475483 2026] [security2:error] [pid 123784:tid 124041] [client 20.48.236.86:14815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/fz.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmgAAAHs"] [Tue Aug 18 13:01:53.481865 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-login.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLmwAAAAs"] [Tue Aug 18 13:01:53.493825 2026] [security2:error] [pid 123784:tid 123971] [client 20.206.96.72:15247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/155.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLnAAAADU"] [Tue Aug 18 13:01:53.509266 2026] [security2:error] [pid 139043:tid 139191] [client 20.250.13.23:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-activat.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJAAAAJc"] [Tue Aug 18 13:01:53.518590 2026] [security2:error] [pid 139043:tid 139286] [client 20.151.109.219:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lr.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJQAAAPY"] [Tue Aug 18 13:01:53.527170 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:53.527455 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:53.543974 2026] [security2:error] [pid 123784:tid 123994] [client 20.206.96.72:15256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/96i.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLnwAAAEw"] [Tue Aug 18 13:01:53.547114 2026] [security2:error] [pid 139043:tid 139283] [client 158.23.17.4:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ft.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJgAAAPM"] [Tue Aug 18 13:01:53.559411 2026] [security2:error] [pid 139043:tid 139291] [client 20.51.153.15:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/oauth.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXJwAAAPs"] [Tue Aug 18 13:01:53.574868 2026] [security2:error] [pid 123784:tid 123919] [client 20.38.3.247:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/inso.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLoAAAAAE"] [Tue Aug 18 13:01:53.579962 2026] [security2:error] [pid 139043:tid 139226] [client 20.91.215.254:25798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKAAAALo"] [Tue Aug 18 13:01:53.590709 2026] [security2:error] [pid 139043:tid 139184] [client 213.202.253.4:64505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/filefuns.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKQAAAJA"], referer: www.google.com [Tue Aug 18 13:01:53.594325 2026] [security2:error] [pid 123784:tid 123937] [client 20.206.96.72:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/as.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLoQAAABM"] [Tue Aug 18 13:01:53.622974 2026] [security2:error] [pid 123784:tid 123924] [client 20.29.77.16:16517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/Mailgun.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLowAAAAY"] [Tue Aug 18 13:01:53.626557 2026] [security2:error] [pid 123784:tid 123928] [client 20.119.58.187:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/past.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLpAAAAAo"] [Tue Aug 18 13:01:53.632505 2026] [security2:error] [pid 123784:tid 123991] [client 20.226.112.14:38925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/Ov-Simple1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLpQAAAEk"] [Tue Aug 18 13:01:53.650986 2026] [security2:error] [pid 139043:tid 139287] [client 158.158.74.177:18979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/photo.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKgAAAPc"] [Tue Aug 18 13:01:53.681504 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.112.14:38973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXKwAAAKY"] [Tue Aug 18 13:01:53.685041 2026] [security2:error] [pid 139043:tid 139243] [client 20.104.100.201:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLAAAAMs"] [Tue Aug 18 13:01:53.721820 2026] [security2:error] [pid 123784:tid 123941] [client 3.79.134.69:41980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.stampi.ind.br"] [uri "/index.html"] [unique_id "aoSB8WwDnJBNj2tDbYYLqAAAABc"], referer: http://www.stampi.ind.br/ [Tue Aug 18 13:01:53.726759 2026] [security2:error] [pid 139043:tid 139258] [client 20.79.204.6:11544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLgAAANo"] [Tue Aug 18 13:01:53.732741 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/min.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXLwAAAOI"] [Tue Aug 18 13:01:53.742700 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:47888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rb.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMAAAAIo"] [Tue Aug 18 13:01:53.760235 2026] [security2:error] [pid 139043:tid 139209] [client 20.163.43.14:8843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMQAAAKk"] [Tue Aug 18 13:01:53.761815 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/weozh.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXMgAAAJ8"] [Tue Aug 18 13:01:53.771162 2026] [security2:error] [pid 139043:tid 139202] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/images/wso.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNAAAAKI"] [Tue Aug 18 13:01:53.776293 2026] [security2:error] [pid 139043:tid 139213] [client 20.79.204.6:11550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNQAAAK0"] [Tue Aug 18 13:01:53.781896 2026] [security2:error] [pid 139043:tid 139198] [client 20.206.96.72:15241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/php8.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXNgAAAJ4"] [Tue Aug 18 13:01:53.786029 2026] [security2:error] [pid 123784:tid 124029] [client 172.213.243.2:14354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/edit.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLqwAAAG8"] [Tue Aug 18 13:01:53.790437 2026] [security2:error] [pid 123784:tid 123968] [client 20.226.112.14:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/vx.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrAAAADI"] [Tue Aug 18 13:01:53.791120 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.183.135:25996] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ww2.pan.com.br"] [uri "/1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrQAAAGI"] [Tue Aug 18 13:01:53.791188 2026] [security2:error] [pid 123784:tid 124016] [client 20.203.183.135:25996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/1.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLrQAAAGI"] [Tue Aug 18 13:01:53.813107 2026] [security2:error] [pid 139043:tid 139174] [client 20.51.153.15:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/timeclock.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXOAAAAIY"] [Tue Aug 18 13:01:53.826889 2026] [security2:error] [pid 123784:tid 123934] [client 20.206.96.72:15254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/admin.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLsAAAABA"] [Tue Aug 18 13:01:53.827416 2026] [security2:error] [pid 139043:tid 139271] [client 20.151.109.219:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ka.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXOQAAAOc"] [Tue Aug 18 13:01:53.829923 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:53.830382 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:53.894344 2026] [security2:error] [pid 123784:tid 124044] [client 20.75.92.165:1997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLsgAAAH4"] [Tue Aug 18 13:01:53.913675 2026] [security2:error] [pid 123784:tid 124025] [client 213.35.127.232:60800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLtAAAAGs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:53.915666 2026] [security2:error] [pid 139043:tid 139212] [client 52.139.47.57:19751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/sx.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPAAAAKw"] [Tue Aug 18 13:01:53.945634 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.56.190:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLtwAAAGg"] [Tue Aug 18 13:01:53.951784 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:19223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLuAAAAGo"] [Tue Aug 18 13:01:53.961333 2026] [security2:error] [pid 139043:tid 139252] [client 20.104.100.201:49668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/css/database.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPQAAANQ"] [Tue Aug 18 13:01:53.968682 2026] [security2:error] [pid 123784:tid 124011] [client 20.206.96.72:15233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/222.php"] [unique_id "aoSB8WwDnJBNj2tDbYYLugAAAF0"] [Tue Aug 18 13:01:53.981128 2026] [security2:error] [pid 139043:tid 139225] [client 20.119.58.187:10157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/root.php"] [unique_id "aoSB8f2v-lWn9OzQT7UXPwAAALk"] [Tue Aug 18 13:01:54.012183 2026] [security2:error] [pid 123784:tid 123955] [client 172.202.39.151:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvAAAACU"] [Tue Aug 18 13:01:54.024276 2026] [security2:error] [pid 139043:tid 139195] [client 20.48.236.86:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/clque.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXQQAAAJs"] [Tue Aug 18 13:01:54.026780 2026] [security2:error] [pid 123784:tid 123920] [client 20.206.96.72:15238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvQAAAAI"] [Tue Aug 18 13:01:54.030047 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:10390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/manager.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXQgAAAMQ"] [Tue Aug 18 13:01:54.037555 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:63742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLvgAAAEE"] [Tue Aug 18 13:01:54.046532 2026] [security2:error] [pid 139043:tid 139200] [client 20.251.112.238:33975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/tmpls.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRAAAAKA"] [Tue Aug 18 13:01:54.063460 2026] [security2:error] [pid 139043:tid 139208] [client 20.51.153.15:13593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/email.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRQAAAKg"] [Tue Aug 18 13:01:54.095954 2026] [security2:error] [pid 139043:tid 139227] [client 68.221.73.131:30311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/grok.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRgAAALs"] [Tue Aug 18 13:01:54.098792 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:8848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/rip.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXRwAAAMU"] [Tue Aug 18 13:01:54.101106 2026] [security2:error] [pid 139043:tid 139194] [client 20.206.96.72:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/info.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSAAAAJo"] [Tue Aug 18 13:01:54.105960 2026] [security2:error] [pid 139043:tid 139264] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/index/function.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSQAAAOA"] [Tue Aug 18 13:01:54.111672 2026] [security2:error] [pid 139043:tid 139281] [client 20.127.136.245:8043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/admin.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSgAAAPE"] [Tue Aug 18 13:01:54.118622 2026] [security2:error] [pid 123784:tid 123947] [client 20.29.77.16:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/oauth.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLwgAAAB0"] [Tue Aug 18 13:01:54.123433 2026] [security2:error] [pid 123784:tid 124021] [client 172.202.39.151:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLxAAAAGc"] [Tue Aug 18 13:01:54.127841 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:54.128103 2026] [authz_core:error] [pid 123784:tid 123885] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:54.129950 2026] [security2:error] [pid 123784:tid 123956] [client 20.250.13.23:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLxgAAACY"] [Tue Aug 18 13:01:54.165795 2026] [security2:error] [pid 123784:tid 123981] [client 20.226.112.14:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ah25.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLyQAAAD8"] [Tue Aug 18 13:01:54.170992 2026] [security2:error] [pid 123784:tid 123967] [client 20.151.109.219:60916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ot.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLygAAADE"] [Tue Aug 18 13:01:54.183507 2026] [security2:error] [pid 139043:tid 139279] [client 20.206.96.72:15455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/a.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXSwAAAO8"] [Tue Aug 18 13:01:54.199125 2026] [security2:error] [pid 123784:tid 123982] [client 172.213.243.2:5725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/kj.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLywAAAEA"] [Tue Aug 18 13:01:54.227395 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/chosen.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTQAAANs"] [Tue Aug 18 13:01:54.236300 2026] [security2:error] [pid 123784:tid 123954] [client 20.104.100.201:49433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/privdayz.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzQAAACQ"] [Tue Aug 18 13:01:54.253817 2026] [security2:error] [pid 123784:tid 124030] [client 20.91.215.254:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/asd.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzgAAAHA"] [Tue Aug 18 13:01:54.261832 2026] [security2:error] [pid 139043:tid 139229] [client 20.206.96.72:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/index.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTgAAAL0"] [Tue Aug 18 13:01:54.274479 2026] [security2:error] [pid 139043:tid 139207] [client 158.23.17.4:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/37.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXTwAAAKc"] [Tue Aug 18 13:01:54.300116 2026] [security2:error] [pid 139043:tid 139188] [client 20.51.153.15:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/profile.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUAAAAJQ"] [Tue Aug 18 13:01:54.303553 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.112.14:28551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tt.php"] [unique_id "aoSB8mwDnJBNj2tDbYYLzwAAAGM"] [Tue Aug 18 13:01:54.331315 2026] [security2:error] [pid 123784:tid 123935] [client 20.79.204.6:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL0AAAABE"] [Tue Aug 18 13:01:54.335262 2026] [security2:error] [pid 139043:tid 139180] [client 20.119.58.187:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/r.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUQAAAIw"] [Tue Aug 18 13:01:54.344194 2026] [security2:error] [pid 139043:tid 139296] [client 52.139.47.57:39613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/tfm.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXUgAAAQA"] [Tue Aug 18 13:01:54.378905 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.96.72:15449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/vx.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVAAAALw"] [Tue Aug 18 13:01:54.384343 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:11538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVQAAAOs"] [Tue Aug 18 13:01:54.428239 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/info.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXVwAAAMw"] [Tue Aug 18 13:01:54.431167 2026] [security2:error] [pid 139043:tid 139274] [client 149.34.210.141:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWQAAAOo"] [Tue Aug 18 13:01:54.445068 2026] [security2:error] [pid 139043:tid 139214] [client 20.206.96.72:15443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wap.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWgAAAK4"] [Tue Aug 18 13:01:54.473237 2026] [security2:error] [pid 139043:tid 139221] [client 20.226.112.14:28552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xqq.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWwAAALU"] [Tue Aug 18 13:01:54.477096 2026] [security2:error] [pid 139043:tid 139215] [client 158.158.74.177:9265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-aa.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXAAAAK8"] [Tue Aug 18 13:01:54.477259 2026] [security2:error] [pid 123784:tid 123973] [client 20.116.17.175:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/pucci.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL1AAAADc"] [Tue Aug 18 13:01:54.512651 2026] [security2:error] [pid 139043:tid 139291] [client 20.104.100.201:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wg459o.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXgAAAPs"] [Tue Aug 18 13:01:54.528875 2026] [security2:error] [pid 123784:tid 123927] [client 4.232.94.69:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL1wAAAAk"] [Tue Aug 18 13:01:54.530141 2026] [security2:error] [pid 123784:tid 123918] [client 132.196.30.78:19215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/admin.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2AAAAAA"] [Tue Aug 18 13:01:54.537093 2026] [autoindex:error] [pid 123784:tid 123930] [client 172.202.39.151:53724] AH01276: Cannot serve directory /home2/sfca23/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:54.541466 2026] [security2:error] [pid 123784:tid 124036] [client 20.65.98.162:2288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/uwu.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2QAAAHY"] [Tue Aug 18 13:01:54.551513 2026] [security2:error] [pid 123784:tid 124005] [client 20.75.92.165:4283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2gAAAFc"] [Tue Aug 18 13:01:54.553222 2026] [security2:error] [pid 139043:tid 139226] [client 20.29.77.16:47343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/timeclock.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXXwAAALo"] [Tue Aug 18 13:01:54.554202 2026] [security2:error] [pid 123784:tid 124019] [client 138.36.100.162:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2wAAAGU"] [Tue Aug 18 13:01:54.556847 2026] [security2:error] [pid 139043:tid 139184] [client 20.51.153.15:13598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/summary.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYAAAAJA"] [Tue Aug 18 13:01:54.567397 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.96.72:15483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/wp.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYQAAAKM"] [Tue Aug 18 13:01:54.578560 2026] [security2:error] [pid 139043:tid 139239] [client 20.203.183.135:26032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/coffee.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYgAAAMc"] [Tue Aug 18 13:01:54.600639 2026] [security2:error] [pid 139043:tid 139243] [client 20.163.43.14:8832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXYwAAAMs"] [Tue Aug 18 13:01:54.609936 2026] [security2:error] [pid 139043:tid 139300] [client 103.120.71.157:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZAAAAQQ"] [Tue Aug 18 13:01:54.610032 2026] [security2:error] [pid 139043:tid 139300] [client 103.120.71.157:53804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZAAAAQQ"] [Tue Aug 18 13:01:54.610617 2026] [security2:error] [pid 139043:tid 139175] [client 172.213.243.2:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/bes.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZQAAAIc"] [Tue Aug 18 13:01:54.633373 2026] [security2:error] [pid 123784:tid 124020] [client 20.206.96.72:15430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bgymj.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL3QAAAGY"] [Tue Aug 18 13:01:54.652129 2026] [security2:error] [pid 139043:tid 139217] [client 20.151.109.219:39329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ih.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXZwAAALE"] [Tue Aug 18 13:01:54.663832 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/aa.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXaAAAAOI"] [Tue Aug 18 13:01:54.680522 2026] [security2:error] [pid 123784:tid 123987] [client 172.202.39.151:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wso.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL3gAAAEU"] [Tue Aug 18 13:01:54.688791 2026] [security2:error] [pid 139043:tid 139287] [client 20.119.58.187:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/sid3.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXaQAAAPc"] [Tue Aug 18 13:01:54.698273 2026] [security2:error] [pid 139043:tid 139181] [client 20.206.96.72:15434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-mail.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXagAAAI0"] [Tue Aug 18 13:01:54.699502 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/06.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXawAAAK0"] [Tue Aug 18 13:01:54.711436 2026] [security2:error] [pid 139043:tid 139274] [client 149.34.210.141:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXWQAAAOo"] [Tue Aug 18 13:01:54.730025 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:54.730288 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:54.733132 2026] [security2:error] [pid 139043:tid 139238] [client 172.202.39.151:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/images/images/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbAAAAMY"] [Tue Aug 18 13:01:54.747365 2026] [security2:error] [pid 123784:tid 123929] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/profile.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL4QAAAAs"] [Tue Aug 18 13:01:54.786622 2026] [security2:error] [pid 139043:tid 139297] [client 20.104.100.201:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mifta.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbgAAAQE"] [Tue Aug 18 13:01:54.789421 2026] [security2:error] [pid 123784:tid 124014] [client 52.139.47.57:28870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/asd.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL4wAAAGA"] [Tue Aug 18 13:01:54.791530 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/conf.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXbwAAAIU"] [Tue Aug 18 13:01:54.812108 2026] [security2:error] [pid 139043:tid 139271] [client 20.206.96.72:15433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bolt.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcAAAAOc"] [Tue Aug 18 13:01:54.835424 2026] [security2:error] [pid 123784:tid 124043] [client 20.48.236.86:14797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/nano.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL6QAAAH0"] [Tue Aug 18 13:01:54.845409 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.96.72:16005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bthil.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcQAAAOw"] [Tue Aug 18 13:01:54.876586 2026] [security2:error] [pid 139043:tid 139233] [client 20.250.13.23:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/past1.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXcwAAAME"] [Tue Aug 18 13:01:54.886111 2026] [security2:error] [pid 123784:tid 123939] [client 68.155.154.236:41490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/rymmm.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL6wAAABU"] [Tue Aug 18 13:01:54.887888 2026] [security2:error] [pid 139043:tid 139272] [client 178.153.171.161:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdAAAAOg"] [Tue Aug 18 13:01:54.888029 2026] [security2:error] [pid 139043:tid 139272] [client 178.153.171.161:41470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdAAAAOg"] [Tue Aug 18 13:01:54.914453 2026] [security2:error] [pid 123784:tid 123991] [client 20.206.96.72:15235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/x.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7QAAAEk"] [Tue Aug 18 13:01:54.920417 2026] [security2:error] [pid 123784:tid 123979] [client 20.91.215.254:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/akc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7gAAAD0"] [Tue Aug 18 13:01:54.930604 2026] [security2:error] [pid 123784:tid 124018] [client 20.163.43.14:8856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/moon.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL7wAAAGQ"] [Tue Aug 18 13:01:54.931405 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:12264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdQAAAJY"] [Tue Aug 18 13:01:54.932392 2026] [security2:error] [pid 123784:tid 123969] [client 213.35.127.232:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8AAAADM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:54.957806 2026] [security2:error] [pid 123784:tid 124019] [client 138.36.100.162:41793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL2wAAAGU"] [Tue Aug 18 13:01:54.960121 2026] [security2:error] [pid 123784:tid 123970] [client 20.151.109.219:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/k.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8QAAADQ"] [Tue Aug 18 13:01:54.974637 2026] [security2:error] [pid 123784:tid 123968] [client 20.29.77.16:40518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/email.php"] [unique_id "aoSB8mwDnJBNj2tDbYYL8wAAADI"] [Tue Aug 18 13:01:54.984257 2026] [security2:error] [pid 139043:tid 139257] [client 132.196.30.78:19196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/edit.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXdgAAANk"] [Tue Aug 18 13:01:54.993561 2026] [security2:error] [pid 139043:tid 139265] [client 20.79.204.6:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/about.php"] [unique_id "aoSB8v2v-lWn9OzQT7UXeAAAAOE"] [Tue Aug 18 13:01:55.013655 2026] [security2:error] [pid 139043:tid 139187] [client 172.202.39.151:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/function/function.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXeQAAAJM"] [Tue Aug 18 13:01:55.024400 2026] [security2:error] [pid 139043:tid 139289] [client 172.213.243.2:14393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws60.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXegAAAPk"] [Tue Aug 18 13:01:55.033061 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:55.033328 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:55.036825 2026] [security2:error] [pid 139043:tid 139227] [client 20.51.153.15:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/bala.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXewAAALs"] [Tue Aug 18 13:01:55.053636 2026] [security2:error] [pid 139043:tid 139195] [client 20.119.58.187:10468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ss.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfAAAAJs"] [Tue Aug 18 13:01:55.056952 2026] [security2:error] [pid 139043:tid 139247] [client 158.23.17.4:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fa.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfQAAAM8"] [Tue Aug 18 13:01:55.061964 2026] [security2:error] [pid 123784:tid 123962] [client 20.104.100.201:49685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-AAAACw"] [Tue Aug 18 13:01:55.062436 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.112.14:28795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/166.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfgAAAKU"] [Tue Aug 18 13:01:55.064691 2026] [security2:error] [pid 123784:tid 123948] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/sx.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-QAAAB4"] [Tue Aug 18 13:01:55.064903 2026] [security2:error] [pid 139043:tid 139240] [client 216.244.66.232:57800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfwAAAMg"] [Tue Aug 18 13:01:55.065014 2026] [security2:error] [pid 139043:tid 139240] [client 216.244.66.232:57800] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXfwAAAMg"] [Tue Aug 18 13:01:55.075026 2026] [security2:error] [pid 123784:tid 123992] [client 20.206.96.72:15944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/index/function.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-gAAAEo"] [Tue Aug 18 13:01:55.105258 2026] [security2:error] [pid 123784:tid 123928] [client 158.158.74.177:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/d.php"] [unique_id "aoSB82wDnJBNj2tDbYYL-wAAAAo"] [Tue Aug 18 13:01:55.107172 2026] [security2:error] [pid 123784:tid 123946] [client 20.206.96.72:15263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/aaa.php"] [unique_id "aoSB82wDnJBNj2tDbYYL_AAAABw"] [Tue Aug 18 13:01:55.116402 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:11778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/md.php"] [unique_id "aoSB82wDnJBNj2tDbYYL_QAAAEY"] [Tue Aug 18 13:01:55.145422 2026] [security2:error] [pid 139043:tid 139248] [client 20.206.96.72:15273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/abcd.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXgQAAANA"] [Tue Aug 18 13:01:55.222836 2026] [security2:error] [pid 139043:tid 139228] [client 172.202.39.151:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/ms-edit.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhQAAALw"] [Tue Aug 18 13:01:55.223979 2026] [security2:error] [pid 139043:tid 139292] [client 20.251.112.238:33956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/nzv.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhgAAAPw"] [Tue Aug 18 13:01:55.233941 2026] [security2:error] [pid 139043:tid 139194] [client 52.139.47.57:16599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/nij.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXhwAAAJo"] [Tue Aug 18 13:01:55.240816 2026] [security2:error] [pid 123784:tid 123955] [client 20.206.96.72:15281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-good.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAQAAACU"] [Tue Aug 18 13:01:55.243572 2026] [security2:error] [pid 123784:tid 123920] [client 20.127.136.245:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAgAAAAI"] [Tue Aug 18 13:01:55.265257 2026] [security2:error] [pid 123784:tid 124028] [client 20.163.43.14:8869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/cache.php"] [unique_id "aoSB82wDnJBNj2tDbYYMAwAAAG4"] [Tue Aug 18 13:01:55.280430 2026] [security2:error] [pid 123784:tid 123983] [client 20.206.96.72:15464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/simple.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBAAAAEE"] [Tue Aug 18 13:01:55.283200 2026] [security2:error] [pid 123784:tid 123923] [client 20.51.153.15:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/222.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBQAAAAU"] [Tue Aug 18 13:01:55.294853 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.112.14:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/snq.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiAAAAPQ"] [Tue Aug 18 13:01:55.305769 2026] [security2:error] [pid 123784:tid 123956] [client 20.206.96.72:15255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/edit-tags.php"] [unique_id "aoSB82wDnJBNj2tDbYYMBgAAACY"] [Tue Aug 18 13:01:55.334642 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:55.334905 2026] [authz_core:error] [pid 123784:tid 123909] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:55.336618 2026] [security2:error] [pid 123784:tid 123993] [client 20.104.100.201:49457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/index2.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCQAAAEs"] [Tue Aug 18 13:01:55.342669 2026] [security2:error] [pid 139043:tid 139286] [client 20.206.96.72:15239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/u.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiQAAAPY"] [Tue Aug 18 13:01:55.355553 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:14134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iu.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXigAAAPM"] [Tue Aug 18 13:01:55.384121 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.56.190:23784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/c99shell.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXiwAAALo"] [Tue Aug 18 13:01:55.387963 2026] [security2:error] [pid 139043:tid 139184] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjAAAAJA"] [Tue Aug 18 13:01:55.393300 2026] [security2:error] [pid 139043:tid 139177] [client 172.202.39.151:53707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/sf.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjQAAAIk"] [Tue Aug 18 13:01:55.397537 2026] [security2:error] [pid 139043:tid 139239] [client 20.75.92.165:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/xmr.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjgAAAMc"] [Tue Aug 18 13:01:55.403650 2026] [security2:error] [pid 123784:tid 124021] [client 20.119.58.187:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/sts.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCgAAAGc"] [Tue Aug 18 13:01:55.405597 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/h.php"] [unique_id "aoSB82wDnJBNj2tDbYYMCwAAAF4"] [Tue Aug 18 13:01:55.408314 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjwAAAO4"] [Tue Aug 18 13:01:55.408397 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:64801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXjwAAAO4"] [Tue Aug 18 13:01:55.427210 2026] [security2:error] [pid 139043:tid 139243] [client 20.29.77.16:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/profile.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXkAAAAMs"] [Tue Aug 18 13:01:55.432047 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.96.72:15484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXkQAAAPs"] [Tue Aug 18 13:01:55.438648 2026] [security2:error] [pid 139043:tid 139280] [client 172.213.243.2:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/olfclass.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlAAAAPA"] [Tue Aug 18 13:01:55.486412 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.112.14:32550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-access.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlQAAAIo"] [Tue Aug 18 13:01:55.493676 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.96.72:15286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/h.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlgAAAOI"] [Tue Aug 18 13:01:55.520550 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/routes.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXlwAAAPc"] [Tue Aug 18 13:01:55.524394 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.96.72:15271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ms-edit.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmAAAAKI"] [Tue Aug 18 13:01:55.541966 2026] [security2:error] [pid 139043:tid 139221] [client 20.79.204.6:11528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmQAAALU"] [Tue Aug 18 13:01:55.545218 2026] [security2:error] [pid 123784:tid 123884] [remote 47.89.174.181:15648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.app.decision.foxalpha.com.br"] [uri "/.env"] [unique_id "aoSB82wDnJBNj2tDbYYMDwAAIF8"] [Tue Aug 18 13:01:55.548492 2026] [security2:error] [pid 123784:tid 123944] [client 20.250.13.23:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/file61.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEAAAABo"] [Tue Aug 18 13:01:55.559863 2026] [security2:error] [pid 139043:tid 139238] [client 20.206.96.72:15480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/a7.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXmgAAAMY"] [Tue Aug 18 13:01:55.568027 2026] [security2:error] [pid 123784:tid 123960] [client 158.23.17.4:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/iy.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEQAAACo"] [Tue Aug 18 13:01:55.569050 2026] [security2:error] [pid 123784:tid 123958] [client 20.91.215.254:27088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/maintenance.php"] [unique_id "aoSB82wDnJBNj2tDbYYMEgAAACg"] [Tue Aug 18 13:01:55.598717 2026] [security2:error] [pid 139043:tid 139232] [client 20.79.204.6:12250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnAAAAMA"] [Tue Aug 18 13:01:55.608377 2026] [security2:error] [pid 139043:tid 139297] [client 20.104.100.201:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/8.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnQAAAQE"] [Tue Aug 18 13:01:55.631450 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.112.14:22917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nw.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXnwAAAIU"] [Tue Aug 18 13:01:55.658868 2026] [security2:error] [pid 139043:tid 139179] [client 20.206.96.72:15441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/manager.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXoAAAAIs"] [Tue Aug 18 13:01:55.682360 2026] [security2:error] [pid 139043:tid 139255] [client 20.65.98.162:29727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/signon.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXogAAANc"] [Tue Aug 18 13:01:55.699813 2026] [security2:error] [pid 139043:tid 139276] [client 20.151.109.219:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pk.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXowAAAOw"] [Tue Aug 18 13:01:55.711984 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.146.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.146.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thatianysantana.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpAAAAME"] [Tue Aug 18 13:01:55.715245 2026] [security2:error] [pid 139043:tid 139282] [client 20.206.96.72:15283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/w1.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpQAAAPI"] [Tue Aug 18 13:01:55.758755 2026] [security2:error] [pid 139043:tid 139271] [client 20.119.58.187:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/shell.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqAAAAOc"] [Tue Aug 18 13:01:55.766345 2026] [security2:error] [pid 123784:tid 124017] [client 158.158.74.177:22852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGAAAAGM"] [Tue Aug 18 13:01:55.797125 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:13691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/php5.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqgAAALQ"] [Tue Aug 18 13:01:55.805995 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:43246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGwAAAFs"] [Tue Aug 18 13:01:55.806435 2026] [security2:error] [pid 123784:tid 124009] [client 103.184.169.37:43246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB82wDnJBNj2tDbYYMGwAAAFs"] [Tue Aug 18 13:01:55.829573 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.112.14:34217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws62.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXqwAAAOE"] [Tue Aug 18 13:01:55.840696 2026] [security2:error] [pid 123784:tid 123975] [client 132.196.30.78:6170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/w.php"] [unique_id "aoSB82wDnJBNj2tDbYYMHAAAADk"] [Tue Aug 18 13:01:55.847290 2026] [security2:error] [pid 139043:tid 139289] [client 172.213.243.2:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wpver.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrAAAAPk"] [Tue Aug 18 13:01:55.888829 2026] [security2:error] [pid 139043:tid 139240] [client 20.104.100.201:49465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/images.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrgAAAMg"] [Tue Aug 18 13:01:55.891727 2026] [security2:error] [pid 139043:tid 139237] [client 172.202.39.151:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/index/function.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXrwAAAMU"] [Tue Aug 18 13:01:55.924427 2026] [security2:error] [pid 139043:tid 139299] [client 20.48.236.86:14796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "treinolab.com.br"] [uri "/.mopj.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXsAAAAQM"] [Tue Aug 18 13:01:55.924613 2026] [security2:error] [pid 139043:tid 139190] [client 20.206.96.72:15270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-login.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXpwAAAJY"] [Tue Aug 18 13:01:55.937446 2026] [authz_core:error] [pid 123784:tid 123793] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:55.937708 2026] [authz_core:error] [pid 123784:tid 123793] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:55.944543 2026] [security2:error] [pid 139043:tid 139279] [client 20.29.77.16:40520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/summary.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXsQAAAO8"] [Tue Aug 18 13:01:55.947685 2026] [security2:error] [pid 123784:tid 124003] [client 213.35.127.232:61182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB82wDnJBNj2tDbYYMHwAAAFU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:55.950828 2026] [security2:error] [pid 123784:tid 124002] [client 52.139.47.57:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/404.php"] [unique_id "aoSB82wDnJBNj2tDbYYMIAAAAFQ"] [Tue Aug 18 13:01:55.969138 2026] [security2:error] [pid 139043:tid 139211] [client 20.203.183.135:13009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXswAAAKs"] [Tue Aug 18 13:01:55.975583 2026] [security2:error] [pid 139043:tid 139259] [client 20.127.136.245:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/as.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtQAAANs"] [Tue Aug 18 13:01:55.978873 2026] [security2:error] [pid 139043:tid 139262] [client 20.75.92.165:4264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/about.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtgAAAN4"] [Tue Aug 18 13:01:55.991497 2026] [security2:error] [pid 139043:tid 139273] [client 20.206.96.72:15451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/default.php"] [unique_id "aoSB8_2v-lWn9OzQT7UXtwAAAOk"] [Tue Aug 18 13:01:56.022016 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:60769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/og.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuAAAANI"] [Tue Aug 18 13:01:56.039507 2026] [security2:error] [pid 123784:tid 124008] [client 20.206.96.72:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/i.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMIgAAAFo"] [Tue Aug 18 13:01:56.052602 2026] [security2:error] [pid 139043:tid 139186] [client 20.51.153.15:13621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/Black.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuQAAAJI"] [Tue Aug 18 13:01:56.082462 2026] [security2:error] [pid 139043:tid 139246] [client 20.151.109.219:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ge.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXugAAAM4"] [Tue Aug 18 13:01:56.091881 2026] [security2:error] [pid 123784:tid 123798] [remote 89.185.225.24:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihostiweb.com"] [uri "/wp-login.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMIwAADgk"] [Tue Aug 18 13:01:56.099539 2026] [security2:error] [pid 139043:tid 139295] [client 158.23.17.4:40393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/40.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXuwAAAP8"] [Tue Aug 18 13:01:56.113204 2026] [security2:error] [pid 139043:tid 139284] [client 135.225.78.186:11359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/aa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvAAAAPQ"] [Tue Aug 18 13:01:56.113650 2026] [security2:error] [pid 139043:tid 139251] [client 20.119.58.187:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/setup-config.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvQAAANM"] [Tue Aug 18 13:01:56.119418 2026] [security2:error] [pid 139043:tid 139214] [client 20.163.43.14:8842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvgAAAK4"] [Tue Aug 18 13:01:56.138408 2026] [security2:error] [pid 139043:tid 139191] [client 172.202.39.151:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/rip.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXvwAAAJc"] [Tue Aug 18 13:01:56.168455 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.112.14:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/vx.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMJAAAAGY"] [Tue Aug 18 13:01:56.169749 2026] [security2:error] [pid 139043:tid 139215] [client 20.104.100.201:49691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/a.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXwQAAAK8"] [Tue Aug 18 13:01:56.173677 2026] [security2:error] [pid 139043:tid 139294] [client 20.79.204.6:11694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXwgAAAP4"] [Tue Aug 18 13:01:56.185738 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.96.72:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXyAAAAKM"] [Tue Aug 18 13:01:56.202681 2026] [security2:error] [pid 139043:tid 139298] [client 20.79.204.6:12273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXyQAAAQI"] [Tue Aug 18 13:01:56.230300 2026] [security2:error] [pid 139043:tid 139206] [client 20.206.96.72:15267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXzQAAAKY"] [Tue Aug 18 13:01:56.246337 2026] [security2:error] [pid 139043:tid 139217] [client 20.75.92.165:2047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/admin.php"] [unique_id "aoSB9P2v-lWn9OzQT7UXzgAAALE"] [Tue Aug 18 13:01:56.258155 2026] [security2:error] [pid 123784:tid 124035] [client 172.213.243.2:5731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/thui.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMJwAAAHU"] [Tue Aug 18 13:01:56.259200 2026] [security2:error] [pid 123784:tid 123986] [client 20.29.77.16:13654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/conf.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKAAAAEQ"] [Tue Aug 18 13:01:56.271928 2026] [security2:error] [pid 139043:tid 139209] [client 20.38.3.247:32619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/aa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0AAAAKk"] [Tue Aug 18 13:01:56.290476 2026] [security2:error] [pid 123784:tid 123930] [client 20.91.215.254:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/options-writing.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKQAAAAw"] [Tue Aug 18 13:01:56.318788 2026] [autoindex:error] [pid 139043:tid 139136] [remote 34.31.203.120:34304] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:01:56.320962 2026] [security2:error] [pid 139043:tid 139223] [client 4.232.151.198:30703] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0wAAALc"] [Tue Aug 18 13:01:56.321082 2026] [security2:error] [pid 139043:tid 139223] [client 4.232.151.198:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX0wAAALc"] [Tue Aug 18 13:01:56.330011 2026] [security2:error] [pid 139043:tid 139199] [client 20.206.96.72:15285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/gecko-new.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1AAAAJ8"] [Tue Aug 18 13:01:56.336329 2026] [security2:error] [pid 123784:tid 123921] [client 68.155.154.236:53650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/lddxs.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKgAAAAM"] [Tue Aug 18 13:01:56.350041 2026] [security2:error] [pid 139043:tid 139221] [client 20.116.17.175:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wicked.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1QAAALU"] [Tue Aug 18 13:01:56.385409 2026] [security2:error] [pid 139043:tid 139197] [client 20.206.96.72:15454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/NewFile.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX1wAAAJ0"] [Tue Aug 18 13:01:56.394767 2026] [security2:error] [pid 139043:tid 139212] [client 20.51.153.15:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/filesystems.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2AAAAKw"] [Tue Aug 18 13:01:56.413335 2026] [security2:error] [pid 139043:tid 139239] [client 158.158.74.177:18981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2QAAAMc"] [Tue Aug 18 13:01:56.415743 2026] [security2:error] [pid 139043:tid 139288] [client 5.31.227.224:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2gAAAPg"] [Tue Aug 18 13:01:56.415829 2026] [security2:error] [pid 139043:tid 139288] [client 5.31.227.224:30459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2gAAAPg"] [Tue Aug 18 13:01:56.418964 2026] [security2:error] [pid 139043:tid 139179] [client 20.206.96.72:16045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-Blogs.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX2wAAAIs"] [Tue Aug 18 13:01:56.438346 2026] [security2:error] [pid 123784:tid 123965] [client 20.250.13.23:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/license.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMKwAAAC8"] [Tue Aug 18 13:01:56.440629 2026] [security2:error] [pid 139043:tid 139196] [client 20.104.100.201:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3AAAAJw"] [Tue Aug 18 13:01:56.456481 2026] [security2:error] [pid 139043:tid 139233] [client 20.206.96.72:15444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3gAAAME"] [Tue Aug 18 13:01:56.459669 2026] [security2:error] [pid 123784:tid 123991] [client 158.23.17.4:47919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lp.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMLQAAAEk"] [Tue Aug 18 13:01:56.464274 2026] [security2:error] [pid 139043:tid 139198] [client 20.119.58.187:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/t.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX3wAAAJ4"] [Tue Aug 18 13:01:56.482648 2026] [security2:error] [pid 123784:tid 124018] [client 20.151.109.219:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kl.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMLgAAAGQ"] [Tue Aug 18 13:01:56.488202 2026] [security2:error] [pid 139043:tid 139236] [client 20.206.96.72:15428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/themes.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX4AAAAMQ"] [Tue Aug 18 13:01:56.502936 2026] [security2:error] [pid 123784:tid 123970] [client 172.202.39.151:52893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/edit.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMMAAAADQ"] [Tue Aug 18 13:01:56.537043 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:56.537319 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:56.567797 2026] [security2:error] [pid 139043:tid 139174] [client 52.139.47.57:16597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/mah.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX4gAAAIY"] [Tue Aug 18 13:01:56.590546 2026] [security2:error] [pid 123784:tid 123962] [client 20.75.92.165:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMNwAAACw"] [Tue Aug 18 13:01:56.598291 2026] [security2:error] [pid 139043:tid 139240] [client 20.226.112.14:34219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/loxi-o.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX5AAAAMg"] [Tue Aug 18 13:01:56.605204 2026] [security2:error] [pid 123784:tid 124032] [client 20.206.96.72:15272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/cv.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOQAAAHI"] [Tue Aug 18 13:01:56.609974 2026] [security2:error] [pid 139043:tid 139200] [client 74.7.175.137:45368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "a3veiculossc.com.br"] [uri "/robots.txt"] [unique_id "aoSB9P2v-lWn9OzQT7UX5QAAoFg"] [Tue Aug 18 13:01:56.618710 2026] [security2:error] [pid 139043:tid 139299] [client 132.196.30.78:1130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/file.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX5wAAAQM"] [Tue Aug 18 13:01:56.632375 2026] [security2:error] [pid 139043:tid 139190] [client 20.163.43.14:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-mail.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX6AAAAJY"] [Tue Aug 18 13:01:56.674535 2026] [security2:error] [pid 123784:tid 124025] [client 172.213.243.2:48368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/tmpls.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOgAAAGs"] [Tue Aug 18 13:01:56.674640 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:15435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX6gAAANs"] [Tue Aug 18 13:01:56.685641 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMOwAAAGg"] [Tue Aug 18 13:01:56.710548 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.96.72:15292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ws83.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7AAAAM0"] [Tue Aug 18 13:01:56.720934 2026] [security2:error] [pid 123784:tid 124026] [client 20.104.100.201:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/99.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMPQAAAGw"] [Tue Aug 18 13:01:56.769979 2026] [security2:error] [pid 139043:tid 139194] [client 20.127.136.245:22155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/bolt.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7QAAAJo"] [Tue Aug 18 13:01:56.773892 2026] [security2:error] [pid 139043:tid 139244] [client 216.244.66.232:57816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7gAAAMw"] [Tue Aug 18 13:01:56.774016 2026] [security2:error] [pid 139043:tid 139244] [client 216.244.66.232:57816] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX7gAAAMw"] [Tue Aug 18 13:01:56.799986 2026] [security2:error] [pid 139043:tid 139270] [client 37.40.227.74:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8QAAAOY"] [Tue Aug 18 13:01:56.800154 2026] [security2:error] [pid 139043:tid 139270] [client 37.40.227.74:56883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8QAAAOY"] [Tue Aug 18 13:01:56.814357 2026] [security2:error] [pid 123784:tid 123949] [client 20.119.58.187:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/up.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMPwAAAB8"] [Tue Aug 18 13:01:56.816706 2026] [security2:error] [pid 139043:tid 139286] [client 20.206.96.72:15470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/atex1.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX8gAAAPY"] [Tue Aug 18 13:01:56.828577 2026] [security2:error] [pid 123784:tid 124006] [client 20.29.77.16:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/bala.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMQAAAAFg"] [Tue Aug 18 13:01:56.842348 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:56.842790 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:56.866963 2026] [security2:error] [pid 139043:tid 139192] [client 20.206.96.72:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/class-t.api.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9AAAAJg"] [Tue Aug 18 13:01:56.907883 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.96.72:16006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/w.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRAAAADo"] [Tue Aug 18 13:01:56.913147 2026] [security2:error] [pid 123784:tid 123982] [client 20.151.109.219:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gs.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRQAAAEA"] [Tue Aug 18 13:01:56.919118 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:20211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/fb.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRgAAAHA"] [Tue Aug 18 13:01:56.925077 2026] [security2:error] [pid 123784:tid 124000] [client 20.91.215.254:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMRwAAAFI"] [Tue Aug 18 13:01:56.951254 2026] [security2:error] [pid 139043:tid 139287] [client 20.75.92.165:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/as.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9gAAAPc"] [Tue Aug 18 13:01:56.954648 2026] [security2:error] [pid 139043:tid 139260] [client 20.51.153.15:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX9wAAANw"] [Tue Aug 18 13:01:56.961468 2026] [security2:error] [pid 123784:tid 123946] [client 213.35.127.232:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSAAAABw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:56.974702 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.112.14:28789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sdsa.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX-AAAAI0"] [Tue Aug 18 13:01:56.982358 2026] [security2:error] [pid 123784:tid 123950] [client 158.23.17.4:56539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ee.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSQAAACA"] [Tue Aug 18 13:01:56.989365 2026] [security2:error] [pid 123784:tid 123947] [client 52.139.47.57:3838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ws.php7"] [unique_id "aoSB9GwDnJBNj2tDbYYMSgAAAB0"] [Tue Aug 18 13:01:56.990492 2026] [security2:error] [pid 123784:tid 123985] [client 20.206.96.72:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/archive.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMSwAAAEM"] [Tue Aug 18 13:01:56.993223 2026] [security2:error] [pid 139043:tid 139269] [client 68.155.154.236:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zjggu.php"] [unique_id "aoSB9P2v-lWn9OzQT7UX-gAAAOU"] [Tue Aug 18 13:01:57.000881 2026] [security2:error] [pid 123784:tid 123935] [client 20.104.100.201:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yup.php"] [unique_id "aoSB9GwDnJBNj2tDbYYMTgAAABE"] [Tue Aug 18 13:01:57.007209 2026] [security2:error] [pid 123784:tid 123999] [client 4.232.94.69:29854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/manager.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMTwAAAFE"] [Tue Aug 18 13:01:57.018730 2026] [security2:error] [pid 123784:tid 124013] [client 20.163.43.14:8861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/o.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMUQAAAF8"] [Tue Aug 18 13:01:57.046152 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-freya.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMUwAAAH8"] [Tue Aug 18 13:01:57.046848 2026] [security2:error] [pid 123784:tid 123989] [client 4.232.151.198:11597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/alfa.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMVAAAAEc"] [Tue Aug 18 13:01:57.049122 2026] [security2:error] [pid 123784:tid 123975] [client 20.206.96.72:16025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/bless.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMVQAAADk"] [Tue Aug 18 13:01:57.074268 2026] [security2:error] [pid 139043:tid 139232] [client 20.116.17.175:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/water.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_AAAAMA"] [Tue Aug 18 13:01:57.094104 2026] [security2:error] [pid 139043:tid 139297] [client 20.206.96.72:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/sagax1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_QAAAQE"] [Tue Aug 18 13:01:57.124031 2026] [security2:error] [pid 139043:tid 139239] [client 172.213.243.2:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/nzv.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_gAAAMc"] [Tue Aug 18 13:01:57.151733 2026] [security2:error] [pid 139043:tid 139235] [client 158.158.74.177:9242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UX_wAAAMM"] [Tue Aug 18 13:01:57.160175 2026] [security2:error] [pid 139043:tid 139282] [client 20.48.236.86:14802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/bengi.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAAAAAPI"] [Tue Aug 18 13:01:57.168135 2026] [security2:error] [pid 123784:tid 123973] [client 20.119.58.187:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ultra.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWAAAADc"] [Tue Aug 18 13:01:57.185576 2026] [security2:error] [pid 139043:tid 139285] [client 20.29.77.16:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/222.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAQAAAPU"] [Tue Aug 18 13:01:57.186192 2026] [security2:error] [pid 139043:tid 139225] [client 20.79.204.6:12265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAgAAALk"] [Tue Aug 18 13:01:57.190297 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:13677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fleen.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYAwAAAMk"] [Tue Aug 18 13:01:57.212055 2026] [security2:error] [pid 139043:tid 139288] [client 20.206.96.72:15236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wpc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYBQAAAPg"] [Tue Aug 18 13:01:57.213461 2026] [security2:error] [pid 123784:tid 123983] [client 20.79.204.6:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/w1.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWQAAAEE"] [Tue Aug 18 13:01:57.221132 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:11841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWgAAAHU"] [Tue Aug 18 13:01:57.238360 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ry.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXAAANW0"] [Tue Aug 18 13:01:57.238391 2026] [security2:error] [pid 123784:tid 123986] [client 20.51.153.15:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/del.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMWwAAAEQ"] [Tue Aug 18 13:01:57.268548 2026] [security2:error] [pid 123784:tid 123930] [client 20.206.96.72:15471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/fone1.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXQAAAAw"] [Tue Aug 18 13:01:57.277440 2026] [security2:error] [pid 139043:tid 139289] [client 20.104.100.201:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/222.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYBwAAAPk"] [Tue Aug 18 13:01:57.279952 2026] [security2:error] [pid 139043:tid 139227] [client 132.196.30.78:1498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCAAAALs"] [Tue Aug 18 13:01:57.294264 2026] [security2:error] [pid 139043:tid 139195] [client 20.75.92.165:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/bolt.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCgAAAJs"] [Tue Aug 18 13:01:57.311335 2026] [security2:error] [pid 139043:tid 139205] [client 20.206.96.72:15460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ncx.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYCwAAAKU"] [Tue Aug 18 13:01:57.339094 2026] [security2:error] [pid 123784:tid 123936] [client 20.203.183.135:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMXwAAABI"] [Tue Aug 18 13:01:57.340559 2026] [security2:error] [pid 139043:tid 139299] [client 20.206.96.72:15262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDQAAAQM"] [Tue Aug 18 13:01:57.342083 2026] [security2:error] [pid 139043:tid 139264] [client 20.151.109.219:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lw.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDgAAAOA"] [Tue Aug 18 13:01:57.346760 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:8888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/bb.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYDwAAAO8"] [Tue Aug 18 13:01:57.372471 2026] [security2:error] [pid 139043:tid 139211] [client 20.206.96.72:16002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wso.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEQAAAKs"] [Tue Aug 18 13:01:57.388752 2026] [security2:error] [pid 139043:tid 139290] [client 20.251.112.238:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/error1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEwAAAPo"] [Tue Aug 18 13:01:57.388774 2026] [security2:error] [pid 139043:tid 139228] [client 158.23.17.4:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ak.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYEgAAALw"] [Tue Aug 18 13:01:57.394647 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.112.14:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/e.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYFAAAAM0"] [Tue Aug 18 13:01:57.418109 2026] [security2:error] [pid 123784:tid 124014] [client 52.139.47.57:28871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/jga.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMYQAAAGA"] [Tue Aug 18 13:01:57.439051 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:57.439317 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:57.442550 2026] [security2:error] [pid 139043:tid 139250] [client 20.127.136.245:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYFgAAANI"] [Tue Aug 18 13:01:57.473062 2026] [security2:error] [pid 123784:tid 123970] [client 20.51.153.15:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/moderator.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMYwAAADQ"] [Tue Aug 18 13:01:57.490267 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:15137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ey.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZAAAAG8"] [Tue Aug 18 13:01:57.494564 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pm.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZQAAMj4"] [Tue Aug 18 13:01:57.509084 2026] [security2:error] [pid 139043:tid 139296] [client 20.206.96.72:15440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/zup.php73"] [unique_id "aoSB9f2v-lWn9OzQT7UYFwAAAQA"] [Tue Aug 18 13:01:57.520554 2026] [security2:error] [pid 123784:tid 123939] [client 20.119.58.187:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/vv.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMZwAAABU"] [Tue Aug 18 13:01:57.536435 2026] [security2:error] [pid 139043:tid 139208] [client 20.206.96.72:16010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/k.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYGQAAAKg"] [Tue Aug 18 13:01:57.541013 2026] [security2:error] [pid 139043:tid 139251] [client 172.213.243.2:19881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/error1.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYGgAAANM"] [Tue Aug 18 13:01:57.555861 2026] [security2:error] [pid 139043:tid 139278] [client 20.104.100.201:49422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-temp.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYHAAAAO4"] [Tue Aug 18 13:01:57.558214 2026] [security2:error] [pid 139043:tid 139191] [client 20.206.96.72:15293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-blink.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYHQAAAJc"] [Tue Aug 18 13:01:57.633544 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vj.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYIQAAAMs"] [Tue Aug 18 13:01:57.650283 2026] [security2:error] [pid 123784:tid 124004] [client 68.155.154.236:8343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/dlvqo.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbAAAAFY"] [Tue Aug 18 13:01:57.681146 2026] [security2:error] [pid 139043:tid 139209] [client 20.206.96.72:15294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/ww5.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJAAAAKk"] [Tue Aug 18 13:01:57.681980 2026] [security2:error] [pid 139043:tid 139287] [client 20.163.43.14:8906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJQAAAPc"] [Tue Aug 18 13:01:57.687950 2026] [security2:error] [pid 139043:tid 139260] [client 20.29.77.16:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/routes.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYJgAAANw"] [Tue Aug 18 13:01:57.708253 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.124:60816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:57.708390 2026] [security2:error] [pid 139043:tid 139199] [client 20.226.112.14:38975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/hello.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKQAAAJ8"] [Tue Aug 18 13:01:57.708537 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.124:60816] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:57.715681 2026] [security2:error] [pid 139043:tid 139221] [client 135.225.78.186:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/img.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKgAAALU"] [Tue Aug 18 13:01:57.715729 2026] [security2:error] [pid 123784:tid 123911] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dr.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbQAAa3o"] [Tue Aug 18 13:01:57.720529 2026] [security2:error] [pid 139043:tid 139185] [client 20.65.98.162:21928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/file61.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYKwAAAJE"] [Tue Aug 18 13:01:57.733389 2026] [security2:error] [pid 123784:tid 123969] [client 20.206.96.72:15811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/2.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMbgAAADM"] [Tue Aug 18 13:01:57.741911 2026] [security2:error] [pid 139043:tid 139216] [client 20.51.153.15:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYLgAAALA"] [Tue Aug 18 13:01:57.744893 2026] [security2:error] [pid 139043:tid 139295] [client 20.91.215.254:11473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/maint.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYLwAAAP8"] [Tue Aug 18 13:01:57.777405 2026] [security2:error] [pid 139043:tid 139188] [client 20.116.17.175:22990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/fine.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMAAAAJQ"] [Tue Aug 18 13:01:57.781111 2026] [security2:error] [pid 139043:tid 139212] [client 20.206.96.72:16023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMQAAAKw"] [Tue Aug 18 13:01:57.783597 2026] [security2:error] [pid 139043:tid 139179] [client 20.75.92.165:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/class-t.api.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMgAAAIs"] [Tue Aug 18 13:01:57.784216 2026] [security2:error] [pid 139043:tid 139226] [client 20.79.204.6:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYMwAAALo"] [Tue Aug 18 13:01:57.802538 2026] [security2:error] [pid 139043:tid 139283] [client 158.158.74.177:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYNgAAAPM"] [Tue Aug 18 13:01:57.814223 2026] [security2:error] [pid 123784:tid 124024] [client 20.206.96.72:15475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/atomlib.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMcAAAAGo"] [Tue Aug 18 13:01:57.829972 2026] [security2:error] [pid 139043:tid 139291] [client 20.79.204.6:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-fclass.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOAAAAPs"] [Tue Aug 18 13:01:57.832778 2026] [security2:error] [pid 139043:tid 139238] [client 20.104.100.201:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/spadex.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOQAAAMY"] [Tue Aug 18 13:01:57.873969 2026] [security2:error] [pid 139043:tid 139277] [client 20.119.58.187:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/V5.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYOwAAAO0"] [Tue Aug 18 13:01:57.874275 2026] [security2:error] [pid 123784:tid 123955] [client 20.127.136.245:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/edit.php"] [unique_id "aoSB9WwDnJBNj2tDbYYMcgAAACU"] [Tue Aug 18 13:01:57.876798 2026] [security2:error] [pid 139043:tid 139236] [client 20.48.236.86:14525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/file2.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPAAAAMQ"] [Tue Aug 18 13:01:57.907268 2026] [security2:error] [pid 139043:tid 139269] [client 52.139.47.57:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/166.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPQAAAOU"] [Tue Aug 18 13:01:57.907381 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/brc.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYPgAAAL8"] [Tue Aug 18 13:01:57.950106 2026] [security2:error] [pid 139043:tid 139289] [client 20.206.96.72:15469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/rip.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYQAAAAPk"] [Tue Aug 18 13:01:57.953667 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:57.953770 2026] [security2:error] [pid 139043:tid 139227] [client 172.213.243.2:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/155.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYQQAAALs"] [Tue Aug 18 13:01:57.953927 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:57.978257 2026] [security2:error] [pid 139043:tid 139206] [client 213.35.127.232:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYRQAAAKY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:57.988366 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.56.190:28265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/profiler.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYSQAAAMo"] [Tue Aug 18 13:01:57.989033 2026] [security2:error] [pid 139043:tid 139200] [client 20.206.96.72:16050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/p.php"] [unique_id "aoSB9f2v-lWn9OzQT7UYSgAAAKA"] [Tue Aug 18 13:01:58.003998 2026] [security2:error] [pid 139043:tid 139290] [client 172.202.39.151:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYSwAAAPo"] [Tue Aug 18 13:01:58.024460 2026] [security2:error] [pid 123784:tid 123992] [client 20.151.109.219:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mimes.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdQAAAEo"] [Tue Aug 18 13:01:58.031227 2026] [security2:error] [pid 139043:tid 139250] [client 20.206.96.72:15244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.paulocardosoimoveis.com"] [uri "/php.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUAAAANI"] [Tue Aug 18 13:01:58.081712 2026] [security2:error] [pid 139043:tid 139220] [client 223.185.37.47:25959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUgAAALQ"] [Tue Aug 18 13:01:58.081824 2026] [security2:error] [pid 139043:tid 139220] [client 223.185.37.47:25959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYUgAAALQ"] [Tue Aug 18 13:01:58.117635 2026] [security2:error] [pid 139043:tid 139251] [client 20.104.100.201:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVQAAANM"] [Tue Aug 18 13:01:58.144545 2026] [security2:error] [pid 139043:tid 139270] [client 20.29.77.16:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/php5.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVgAAAOY"] [Tue Aug 18 13:01:58.159029 2026] [security2:error] [pid 139043:tid 139214] [client 20.51.153.15:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/c99shell.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYVwAAAK4"] [Tue Aug 18 13:01:58.184105 2026] [security2:error] [pid 139043:tid 139191] [client 20.163.43.14:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWAAAAJc"] [Tue Aug 18 13:01:58.184818 2026] [security2:error] [pid 123784:tid 123923] [client 158.23.17.4:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lv.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdgAAAAU"] [Tue Aug 18 13:01:58.208146 2026] [security2:error] [pid 139043:tid 139233] [client 20.226.112.14:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/file52.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWgAAAME"] [Tue Aug 18 13:01:58.209635 2026] [security2:error] [pid 123784:tid 123998] [client 20.75.92.165:4266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/edit.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMdwAAAFA"] [Tue Aug 18 13:01:58.228890 2026] [security2:error] [pid 139043:tid 139244] [client 20.119.58.187:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-user.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYWwAAAMw"] [Tue Aug 18 13:01:58.250027 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:58.250302 2026] [authz_core:error] [pid 123784:tid 123848] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:58.268586 2026] [security2:error] [pid 139043:tid 139192] [client 216.244.66.232:57830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXAAAAJg"] [Tue Aug 18 13:01:58.268678 2026] [security2:error] [pid 139043:tid 139192] [client 216.244.66.232:57830] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXAAAAJg"] [Tue Aug 18 13:01:58.281089 2026] [security2:error] [pid 123784:tid 123812] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ts.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMeQAASxc"] [Tue Aug 18 13:01:58.328444 2026] [security2:error] [pid 123784:tid 123942] [client 52.139.47.57:3754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/log.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMegAAABg"] [Tue Aug 18 13:01:58.358507 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/loader.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXgAAANo"] [Tue Aug 18 13:01:58.368185 2026] [security2:error] [pid 139043:tid 139298] [client 172.213.243.2:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fasx.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYXwAAAQI"] [Tue Aug 18 13:01:58.380528 2026] [security2:error] [pid 123784:tid 123976] [client 20.48.236.86:14497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/gm.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMewAAADo"] [Tue Aug 18 13:01:58.392624 2026] [security2:error] [pid 139043:tid 139213] [client 20.104.100.201:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/srontol.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYYwAAAK0"] [Tue Aug 18 13:01:58.400337 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:28558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sxdfrt.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYZAAAALc"] [Tue Aug 18 13:01:58.404323 2026] [security2:error] [pid 139043:tid 139199] [client 20.151.109.219:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ni.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYZQAAAJ8"] [Tue Aug 18 13:01:58.412019 2026] [security2:error] [pid 123784:tid 124038] [client 20.51.153.15:13605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/profiler.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfQAAAHg"] [Tue Aug 18 13:01:58.462979 2026] [security2:error] [pid 123784:tid 123889] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/53.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfgAAJGQ"] [Tue Aug 18 13:01:58.464216 2026] [security2:error] [pid 123784:tid 123938] [client 158.158.74.177:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMfwAAABQ"] [Tue Aug 18 13:01:58.466414 2026] [security2:error] [pid 139043:tid 139173] [client 68.221.73.131:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/indes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYaQAAAIU"] [Tue Aug 18 13:01:58.483908 2026] [security2:error] [pid 139043:tid 139184] [client 20.91.215.254:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/phpMailer.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYagAAAJA"] [Tue Aug 18 13:01:58.514704 2026] [security2:error] [pid 139043:tid 139239] [client 132.196.30.78:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/aa.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYawAAAMc"] [Tue Aug 18 13:01:58.515512 2026] [security2:error] [pid 139043:tid 139226] [client 20.163.43.14:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbAAAALo"] [Tue Aug 18 13:01:58.527255 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.112.14:32562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/path.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbQAAAKE"] [Tue Aug 18 13:01:58.530129 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.154.236:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/pkmoj.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYbgAAAPM"] [Tue Aug 18 13:01:58.537098 2026] [security2:error] [pid 139043:tid 139235] [client 20.75.92.165:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ff1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYcAAAAMM"] [Tue Aug 18 13:01:58.561165 2026] [security2:error] [pid 139043:tid 139219] [client 4.232.94.69:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/csv.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYcwAAALM"] [Tue Aug 18 13:01:58.565852 2026] [security2:error] [pid 123784:tid 123945] [client 20.127.136.245:22189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ff1.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMgwAAABs"] [Tue Aug 18 13:01:58.580717 2026] [security2:error] [pid 139043:tid 139295] [client 20.119.58.187:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-blog.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYdAAAAP8"] [Tue Aug 18 13:01:58.594037 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wpo.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYdQAAAMk"] [Tue Aug 18 13:01:58.661665 2026] [security2:error] [pid 139043:tid 139277] [client 20.51.153.15:13613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/findes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYeQAAAO0"] [Tue Aug 18 13:01:58.686774 2026] [security2:error] [pid 139043:tid 139174] [client 20.104.100.201:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/file5.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYegAAAIY"] [Tue Aug 18 13:01:58.710024 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/test_info.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfAAAAQQ"] [Tue Aug 18 13:01:58.712205 2026] [security2:error] [pid 139043:tid 139237] [client 158.23.17.4:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/51.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfQAAAMU"] [Tue Aug 18 13:01:58.728417 2026] [security2:error] [pid 139043:tid 139299] [client 20.29.77.16:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/Black.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYfgAAAQM"] [Tue Aug 18 13:01:58.747157 2026] [security2:error] [pid 139043:tid 139271] [client 52.139.47.57:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/file.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgAAAAOc"] [Tue Aug 18 13:01:58.779408 2026] [security2:error] [pid 123784:tid 123897] [remote 129.121.48.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMhAAAKmw"] [Tue Aug 18 13:01:58.784067 2026] [security2:error] [pid 139043:tid 139190] [client 172.213.243.2:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-good.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgQAAAJY"] [Tue Aug 18 13:01:58.800915 2026] [security2:error] [pid 139043:tid 139242] [client 158.23.17.4:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gw.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYgwAAAMo"] [Tue Aug 18 13:01:58.808657 2026] [security2:error] [pid 139043:tid 139200] [client 20.79.204.6:11654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhAAAAKA"] [Tue Aug 18 13:01:58.837263 2026] [security2:error] [pid 139043:tid 139228] [client 20.116.17.175:55295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/zero.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhgAAALw"] [Tue Aug 18 13:01:58.841960 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/file.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYhwAAAOk"] [Tue Aug 18 13:01:58.847121 2026] [security2:error] [pid 139043:tid 139259] [client 20.48.236.86:14464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/ws55.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiAAAANs"] [Tue Aug 18 13:01:58.850335 2026] [security2:error] [pid 139043:tid 139229] [client 20.79.204.6:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiQAAAL0"] [Tue Aug 18 13:01:58.852362 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:58.852619 2026] [authz_core:error] [pid 123784:tid 123858] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:58.854791 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14254] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "varandasgp.com.br"] [uri "/1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYigAAAIw"] [Tue Aug 18 13:01:58.854884 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/1.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYigAAAIw"] [Tue Aug 18 13:01:58.898604 2026] [security2:error] [pid 123784:tid 123931] [client 20.51.153.15:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/fedora.php"] [unique_id "aoSB9mwDnJBNj2tDbYYMhgAAAA0"] [Tue Aug 18 13:01:58.901136 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.56.190:17875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/findes.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYiwAAAKc"] [Tue Aug 18 13:01:58.926807 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.112.14:39450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/a1vx.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYjQAAAOs"] [Tue Aug 18 13:01:58.931901 2026] [security2:error] [pid 139043:tid 139248] [client 20.119.58.187:10222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYjwAAANA"] [Tue Aug 18 13:01:58.959765 2026] [security2:error] [pid 139043:tid 139270] [client 132.196.30.78:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkQAAAOY"] [Tue Aug 18 13:01:58.965341 2026] [security2:error] [pid 139043:tid 139284] [client 20.104.100.201:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yup.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkgAAAPQ"] [Tue Aug 18 13:01:58.991900 2026] [security2:error] [pid 139043:tid 139272] [client 213.35.127.232:61803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYkwAAAOg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:01:58.998476 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.112.14:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ty.php"] [unique_id "aoSB9v2v-lWn9OzQT7UYlAAAAO4"] [Tue Aug 18 13:01:59.010697 2026] [security2:error] [pid 123784:tid 123999] [client 172.202.39.151:47683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-good.php"] [unique_id "aoSB92wDnJBNj2tDbYYMiQAAAFE"] [Tue Aug 18 13:01:59.058537 2026] [security2:error] [pid 139043:tid 139280] [client 20.251.112.238:33939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/155.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYmQAAAPA"] [Tue Aug 18 13:01:59.111303 2026] [security2:error] [pid 139043:tid 139081] [remote 203.99.146.53:35660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnAAAziU"] [Tue Aug 18 13:01:59.114368 2026] [security2:error] [pid 139043:tid 139217] [client 20.203.183.135:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/yj09.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnQAAALE"] [Tue Aug 18 13:01:59.125108 2026] [security2:error] [pid 139043:tid 139196] [client 172.202.39.151:40346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYnwAAAJw"] [Tue Aug 18 13:01:59.136022 2026] [security2:error] [pid 139043:tid 139296] [client 20.91.215.254:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYoAAAAQA"] [Tue Aug 18 13:01:59.145291 2026] [security2:error] [pid 139043:tid 139181] [client 68.155.154.236:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/kopyw.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYoQAAAI0"] [Tue Aug 18 13:01:59.147903 2026] [security2:error] [pid 123784:tid 124034] [client 20.51.153.15:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/path.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjAAAAHQ"] [Tue Aug 18 13:01:59.153923 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:59.154179 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:59.185667 2026] [security2:error] [pid 123784:tid 124002] [client 20.75.92.165:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/fff.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjQAAAFQ"] [Tue Aug 18 13:01:59.195363 2026] [security2:error] [pid 139043:tid 139215] [client 20.163.43.14:8877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/epinyins.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpAAAAK8"] [Tue Aug 18 13:01:59.195964 2026] [security2:error] [pid 139043:tid 139185] [client 20.226.112.14:28573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/vgtyu.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpQAAAJE"] [Tue Aug 18 13:01:59.201637 2026] [security2:error] [pid 139043:tid 139256] [client 172.213.243.2:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zxin.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpgAAANg"] [Tue Aug 18 13:01:59.227126 2026] [security2:error] [pid 139043:tid 139173] [client 172.202.39.151:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYpwAAAIU"] [Tue Aug 18 13:01:59.232713 2026] [security2:error] [pid 139043:tid 139193] [client 20.29.77.16:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/filesystems.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqAAAAJk"] [Tue Aug 18 13:01:59.236917 2026] [security2:error] [pid 139043:tid 139184] [client 20.104.100.201:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/classwithtostring.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqQAAAJA"] [Tue Aug 18 13:01:59.254949 2026] [security2:error] [pid 123784:tid 124031] [client 52.139.47.57:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/bolt.php"] [unique_id "aoSB92wDnJBNj2tDbYYMjwAAAHE"] [Tue Aug 18 13:01:59.255143 2026] [security2:error] [pid 139043:tid 139179] [client 20.79.204.6:10389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqgAAAIs"] [Tue Aug 18 13:01:59.276877 2026] [security2:error] [pid 123784:tid 124008] [client 20.151.109.219:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/88.php"] [unique_id "aoSB92wDnJBNj2tDbYYMkAAAAFo"] [Tue Aug 18 13:01:59.283446 2026] [security2:error] [pid 139043:tid 139251] [client 158.158.74.177:10163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/abc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYqwAAANM"] [Tue Aug 18 13:01:59.284752 2026] [security2:error] [pid 139043:tid 139262] [client 20.119.58.187:10217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/worksec.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYrAAAAN4"] [Tue Aug 18 13:01:59.331427 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:48409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/14.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYrwAAALM"] [Tue Aug 18 13:01:59.341229 2026] [security2:error] [pid 139043:tid 139295] [client 20.226.112.14:28741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mans.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsAAAAP8"] [Tue Aug 18 13:01:59.367666 2026] [security2:error] [pid 139043:tid 139222] [client 20.127.136.245:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/fff.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsQAAALY"] [Tue Aug 18 13:01:59.375359 2026] [security2:error] [pid 139043:tid 139253] [client 20.116.17.175:23032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/002.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYswAAANU"] [Tue Aug 18 13:01:59.405700 2026] [security2:error] [pid 139043:tid 139285] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYsgAA9QQ"] [Tue Aug 18 13:01:59.416386 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYtQAAALA"] [Tue Aug 18 13:01:59.421525 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.112.14:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/co.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYtgAAAI4"] [Tue Aug 18 13:01:59.457993 2026] [security2:error] [pid 139043:tid 139239] [client 20.79.204.6:12281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuAAAAMc"] [Tue Aug 18 13:01:59.457994 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:01:59.458475 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:01:59.464652 2026] [security2:error] [pid 139043:tid 139299] [client 20.226.56.190:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/fedora.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuQAAAQM"] [Tue Aug 18 13:01:59.472117 2026] [security2:error] [pid 139043:tid 139271] [client 132.196.30.78:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/about.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYuwAAAOc"] [Tue Aug 18 13:01:59.479434 2026] [security2:error] [pid 139043:tid 139206] [client 20.48.236.86:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/m.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvAAAAKY"] [Tue Aug 18 13:01:59.484035 2026] [security2:error] [pid 123784:tid 124042] [client 20.75.92.165:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/inputs.php"] [unique_id "aoSB92wDnJBNj2tDbYYMkgAAAHw"] [Tue Aug 18 13:01:59.500198 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.112.14:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/btx25.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvQAAAMo"] [Tue Aug 18 13:01:59.512045 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-the.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvgAAAO8"] [Tue Aug 18 13:01:59.521650 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/456.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYvwAAAOk"] [Tue Aug 18 13:01:59.523931 2026] [security2:error] [pid 139043:tid 139229] [client 20.163.43.14:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwAAAAL0"] [Tue Aug 18 13:01:59.547666 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.112.14:38965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/avim.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwQAAAIw"] [Tue Aug 18 13:01:59.569654 2026] [security2:error] [pid 139043:tid 139207] [client 68.155.154.236:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zznmg.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYwwAAAKc"] [Tue Aug 18 13:01:59.571464 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/hj.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxAAAAJ0"] [Tue Aug 18 13:01:59.590504 2026] [security2:error] [pid 139043:tid 139208] [client 196.12.128.158:57314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxQAAAKg"] [Tue Aug 18 13:01:59.592753 2026] [security2:error] [pid 139043:tid 139208] [client 196.12.128.158:57314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxQAAAKg"] [Tue Aug 18 13:01:59.593879 2026] [security2:error] [pid 139043:tid 139248] [client 216.244.66.232:57838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxwAAANA"] [Tue Aug 18 13:01:59.593994 2026] [security2:error] [pid 139043:tid 139248] [client 216.244.66.232:57838] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYxwAAANA"] [Tue Aug 18 13:01:59.618487 2026] [security2:error] [pid 139043:tid 139233] [client 172.213.243.2:14558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/pass4.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYyAAAAME"] [Tue Aug 18 13:01:59.634851 2026] [security2:error] [pid 139043:tid 139228] [client 20.119.58.187:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB9_2v-lWn9OzQT7UYygAAALw"] [Tue Aug 18 13:01:59.668573 2026] [security2:error] [pid 139043:tid 139269] [client 213.202.253.4:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/filefuns.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY2AAAAOU"], referer: www.google.com [Tue Aug 18 13:01:59.683924 2026] [security2:error] [pid 123784:tid 123977] [client 197.184.64.235:41966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlAAAADs"] [Tue Aug 18 13:01:59.684024 2026] [security2:error] [pid 123784:tid 123977] [client 197.184.64.235:41966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlAAAADs"] [Tue Aug 18 13:01:59.689606 2026] [security2:error] [pid 139043:tid 139280] [client 20.226.112.14:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/myfile.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY9wAAAPA"] [Tue Aug 18 13:01:59.701115 2026] [security2:error] [pid 139043:tid 139245] [client 52.139.47.57:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/item.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY-AAAAM0"] [Tue Aug 18 13:01:59.754731 2026] [security2:error] [pid 139043:tid 139217] [client 20.226.112.14:39476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xmy.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY-gAAALE"] [Tue Aug 18 13:01:59.770675 2026] [security2:error] [pid 123784:tid 123983] [client 20.38.3.247:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/img.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlgAAAEE"] [Tue Aug 18 13:01:59.778534 2026] [security2:error] [pid 123784:tid 124005] [client 20.51.153.15:13687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/SMTP.php"] [unique_id "aoSB92wDnJBNj2tDbYYMlwAAAFc"] [Tue Aug 18 13:01:59.783456 2026] [security2:error] [pid 123784:tid 124041] [client 20.29.77.16:40515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmAAAAHs"] [Tue Aug 18 13:01:59.789772 2026] [security2:error] [pid 123784:tid 124035] [client 20.104.100.201:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/cong.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmQAAAHU"] [Tue Aug 18 13:01:59.815629 2026] [security2:error] [pid 123784:tid 123986] [client 20.48.236.86:14507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/33.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmgAAAEQ"] [Tue Aug 18 13:01:59.867378 2026] [security2:error] [pid 139043:tid 139175] [client 158.23.17.4:11432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tk.php"] [unique_id "aoSB9_2v-lWn9OzQT7UY_wAAAIc"] [Tue Aug 18 13:01:59.870108 2026] [security2:error] [pid 139043:tid 139214] [client 20.91.215.254:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/al.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAAAAAK4"] [Tue Aug 18 13:01:59.888954 2026] [security2:error] [pid 139043:tid 139266] [client 135.225.78.186:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/222.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAQAAAOI"] [Tue Aug 18 13:01:59.899187 2026] [security2:error] [pid 139043:tid 139215] [client 20.75.92.165:4328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZAgAAAK8"] [Tue Aug 18 13:01:59.912933 2026] [security2:error] [pid 123784:tid 123934] [client 158.158.74.177:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/sf.php"] [unique_id "aoSB92wDnJBNj2tDbYYMmwAAABA"] [Tue Aug 18 13:01:59.934704 2026] [security2:error] [pid 123784:tid 124023] [client 132.196.30.78:35541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/goods.php"] [unique_id "aoSB92wDnJBNj2tDbYYMnAAAAGk"] [Tue Aug 18 13:01:59.947846 2026] [security2:error] [pid 139043:tid 139078] [remote 162.214.205.212:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZBwABASI"] [Tue Aug 18 13:01:59.952473 2026] [security2:error] [pid 123784:tid 123965] [client 20.151.109.219:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ij.php"] [unique_id "aoSB92wDnJBNj2tDbYYMnQAAAC8"] [Tue Aug 18 13:01:59.969806 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:22913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/zxz.php"] [unique_id "aoSB9_2v-lWn9OzQT7UZCAAAAJk"] [Tue Aug 18 13:02:00.004897 2026] [security2:error] [pid 139043:tid 139221] [client 20.119.58.187:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-signin.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJAAAALU"] [Tue Aug 18 13:02:00.009892 2026] [security2:error] [pid 123784:tid 124020] [client 213.35.127.232:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMngAAAGY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:00.020540 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.112.14:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xda.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJgAAALo"] [Tue Aug 18 13:02:00.032462 2026] [security2:error] [pid 123784:tid 123952] [client 172.213.243.2:16679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMoAAAACI"] [Tue Aug 18 13:02:00.035075 2026] [security2:error] [pid 139043:tid 139255] [client 20.163.43.14:8859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZJwAAANc"] [Tue Aug 18 13:02:00.035083 2026] [security2:error] [pid 123784:tid 123991] [client 20.51.153.15:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/vbseo.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMoQAAAEk"] [Tue Aug 18 13:02:00.068166 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/bhfnd.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZKQAAAJ8"] [Tue Aug 18 13:02:00.073584 2026] [security2:error] [pid 139043:tid 139276] [client 20.104.100.201:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/xwpg.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZKgAAAOw"] [Tue Aug 18 13:02:00.077795 2026] [security2:error] [pid 123784:tid 123941] [client 161.118.206.101:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.206.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-login.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMowAAABc"] [Tue Aug 18 13:02:00.107454 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zz.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLQAAAMk"] [Tue Aug 18 13:02:00.108854 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.154.236:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLgAAAJ4"] [Tue Aug 18 13:02:00.117047 2026] [security2:error] [pid 123784:tid 123800] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lq.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpAAANAs"] [Tue Aug 18 13:02:00.131401 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.112.14:28791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xa.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZLwAAAMI"] [Tue Aug 18 13:02:00.136885 2026] [security2:error] [pid 139043:tid 139231] [client 158.23.17.4:20220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/sw.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZMAAAAL8"] [Tue Aug 18 13:02:00.191060 2026] [security2:error] [pid 139043:tid 139285] [client 20.75.92.165:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/lite.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZMQAAAPU"] [Tue Aug 18 13:02:00.192516 2026] [security2:error] [pid 123784:tid 123962] [client 20.29.77.16:47349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/phpstatus.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpQAAACw"] [Tue Aug 18 13:02:00.215693 2026] [security2:error] [pid 123784:tid 123980] [client 20.226.112.14:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/f6.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpgAAAD4"] [Tue Aug 18 13:02:00.219255 2026] [security2:error] [pid 139043:tid 139254] [client 52.139.47.57:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/sid3.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZNQAAANY"] [Tue Aug 18 13:02:00.222072 2026] [security2:error] [pid 123784:tid 123951] [client 20.79.204.6:11858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMpwAAACE"] [Tue Aug 18 13:02:00.243175 2026] [security2:error] [pid 123784:tid 124004] [client 20.127.136.245:3863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/inputs.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqAAAAFY"] [Tue Aug 18 13:02:00.263164 2026] [security2:error] [pid 139043:tid 139271] [client 20.79.204.6:11852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZNwAAAOc"] [Tue Aug 18 13:02:00.273377 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ud.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQAAAAJY"] [Tue Aug 18 13:02:00.291033 2026] [security2:error] [pid 123784:tid 123969] [client 20.48.236.86:14841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "treinolab.com.br"] [uri "/packed.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqQAAADM"] [Tue Aug 18 13:02:00.298739 2026] [security2:error] [pid 139043:tid 139250] [client 20.51.153.15:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/sysinfo.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQgAAANI"] [Tue Aug 18 13:02:00.302762 2026] [security2:error] [pid 123784:tid 124022] [client 20.226.112.14:29889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mcs.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMqgAAAGg"] [Tue Aug 18 13:02:00.312300 2026] [security2:error] [pid 123784:tid 123996] [client 4.232.94.69:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/404.php123123"] [unique_id "aoSB-GwDnJBNj2tDbYYMqwAAAE4"] [Tue Aug 18 13:02:00.324180 2026] [security2:error] [pid 139043:tid 139259] [client 168.62.48.100:5510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZQwAAANs"] [Tue Aug 18 13:02:00.327230 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/xleet.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZRAAAAOk"] [Tue Aug 18 13:02:00.357824 2026] [security2:error] [pid 139043:tid 139281] [client 20.119.58.187:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZSAAAAPE"] [Tue Aug 18 13:02:00.359845 2026] [security2:error] [pid 123784:tid 123964] [client 20.104.100.201:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/dex.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrQAAAC4"] [Tue Aug 18 13:02:00.360841 2026] [security2:error] [pid 123784:tid 123891] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/you.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrgAATWY"] [Tue Aug 18 13:02:00.361920 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:00.362319 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:00.364235 2026] [security2:error] [pid 139043:tid 139275] [client 20.163.43.14:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZTAAAAOs"] [Tue Aug 18 13:02:00.365502 2026] [security2:error] [pid 139043:tid 139208] [client 20.251.112.238:7170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fasx.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZTQAAAKg"] [Tue Aug 18 13:02:00.421789 2026] [security2:error] [pid 123784:tid 123924] [client 20.226.112.14:32552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fr/ms.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMrwAAAAY"] [Tue Aug 18 13:02:00.436480 2026] [security2:error] [pid 139043:tid 139278] [client 132.196.30.78:9383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/php8.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZUAAAAO4"] [Tue Aug 18 13:02:00.453762 2026] [security2:error] [pid 139043:tid 139244] [client 172.213.243.2:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/z.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZUwAAAMw"] [Tue Aug 18 13:02:00.453791 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:64145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/qfvqu.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZVAAAAP0"] [Tue Aug 18 13:02:00.522444 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:47644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/hp.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsAAAAAI"] [Tue Aug 18 13:02:00.549386 2026] [security2:error] [pid 139043:tid 139200] [client 20.91.215.254:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWAAAAKA"] [Tue Aug 18 13:02:00.550323 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:10749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/default.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWQAAAPg"] [Tue Aug 18 13:02:00.552108 2026] [security2:error] [pid 123784:tid 123894] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ez.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsQAAWGk"] [Tue Aug 18 13:02:00.552113 2026] [security2:error] [pid 139043:tid 139282] [client 158.158.74.177:18951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZWgAAAPI"] [Tue Aug 18 13:02:00.557430 2026] [security2:error] [pid 123784:tid 123992] [client 20.75.92.165:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMsgAAAEo"] [Tue Aug 18 13:02:00.563613 2026] [security2:error] [pid 123784:tid 124019] [client 20.151.109.219:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ip.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMswAAAGU"] [Tue Aug 18 13:02:00.571560 2026] [security2:error] [pid 123784:tid 123923] [client 20.51.153.15:13601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/ppinfo.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtAAAAAU"] [Tue Aug 18 13:02:00.594203 2026] [security2:error] [pid 139043:tid 139258] [client 172.202.39.151:63720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/tes.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXQAAANo"] [Tue Aug 18 13:02:00.598780 2026] [security2:error] [pid 139043:tid 139245] [client 20.116.17.175:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/memberfuns.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXgAAAM0"] [Tue Aug 18 13:02:00.599216 2026] [security2:error] [pid 123784:tid 124043] [client 114.119.158.31:63353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casacorba.com.br"] [uri "/blog"] [unique_id "aoSB-GwDnJBNj2tDbYYMtQAAAH0"], referer: https://casacorba.com.br/verificacao [Tue Aug 18 13:02:00.600836 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:53687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtgAAACc"] [Tue Aug 18 13:02:00.603429 2026] [security2:error] [pid 123784:tid 123956] [client 68.221.73.131:41608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/tTPcH.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMtwAAACY"] [Tue Aug 18 13:02:00.628417 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.112.14:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/gool.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuAAAAEs"] [Tue Aug 18 13:02:00.635456 2026] [security2:error] [pid 123784:tid 123981] [client 20.104.100.201:49689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/xyn.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuQAAAD8"] [Tue Aug 18 13:02:00.641507 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/maxro.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZXwAAAM4"] [Tue Aug 18 13:02:00.661081 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:00.661345 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:00.671803 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.112.14:34233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wdf.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMuwAAADo"] [Tue Aug 18 13:02:00.673550 2026] [security2:error] [pid 139043:tid 139287] [client 20.203.183.135:58149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/scxy.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZYQAAAPc"] [Tue Aug 18 13:02:00.679912 2026] [security2:error] [pid 123784:tid 123997] [client 158.23.17.4:46575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ew.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvAAAAE8"] [Tue Aug 18 13:02:00.684762 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.112.14:22849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ff1.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvQAAAHg"] [Tue Aug 18 13:02:00.692871 2026] [security2:error] [pid 123784:tid 123982] [client 20.163.43.14:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMvgAAAEA"] [Tue Aug 18 13:02:00.701605 2026] [security2:error] [pid 123784:tid 124030] [client 20.65.98.162:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/copypaths.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwAAAAHA"] [Tue Aug 18 13:02:00.705912 2026] [security2:error] [pid 123784:tid 123946] [client 158.23.17.4:34125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gc.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwgAAABw"] [Tue Aug 18 13:02:00.708470 2026] [security2:error] [pid 139043:tid 139296] [client 20.226.112.14:13043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/guk.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZYwAAAQA"] [Tue Aug 18 13:02:00.780950 2026] [security2:error] [pid 139043:tid 139291] [client 52.139.47.57:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/size.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZZwAAAPs"] [Tue Aug 18 13:02:00.799088 2026] [security2:error] [pid 123784:tid 123931] [client 216.244.66.232:57850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwwAAAA0"] [Tue Aug 18 13:02:00.799191 2026] [security2:error] [pid 123784:tid 123931] [client 216.244.66.232:57850] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMwwAAAA0"] [Tue Aug 18 13:02:00.810519 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/globals.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMxAAAABE"] [Tue Aug 18 13:02:00.816702 2026] [security2:error] [pid 139043:tid 139185] [client 20.226.112.14:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-the.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZaAAAAJE"] [Tue Aug 18 13:02:00.845907 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.56.190:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/path.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZagAAAIU"] [Tue Aug 18 13:02:00.866121 2026] [security2:error] [pid 139043:tid 139297] [client 172.213.243.2:19556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/222.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZawAAAQE"] [Tue Aug 18 13:02:00.879541 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.112.14:28553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sbhu.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZcQAAAJk"] [Tue Aug 18 13:02:00.912534 2026] [security2:error] [pid 139043:tid 139179] [client 20.104.100.201:49453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZcgAAAIs"] [Tue Aug 18 13:02:00.931419 2026] [security2:error] [pid 123784:tid 124009] [client 20.151.109.219:14138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/99.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMxwAAAFs"] [Tue Aug 18 13:02:00.931470 2026] [security2:error] [pid 123784:tid 124034] [client 20.226.112.14:29915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/zc-318.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMyAAAAHQ"] [Tue Aug 18 13:02:00.952357 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.112.14:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ccou.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMyQAAAEc"] [Tue Aug 18 13:02:00.956963 2026] [security2:error] [pid 139043:tid 139201] [client 20.116.17.175:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/aa.php"] [unique_id "aoSB-P2v-lWn9OzQT7UZdgAAAKE"] [Tue Aug 18 13:02:00.961875 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:00.962170 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:00.989902 2026] [security2:error] [pid 123784:tid 124001] [client 20.29.77.16:47350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/del.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMzAAAAFM"] [Tue Aug 18 13:02:00.992412 2026] [security2:error] [pid 123784:tid 124008] [client 20.116.17.175:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/img.php"] [unique_id "aoSB-GwDnJBNj2tDbYYMzQAAAFo"] [Tue Aug 18 13:02:01.004580 2026] [security2:error] [pid 123784:tid 123953] [client 172.202.39.151:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/moon.php"] [unique_id "aoSB-WwDnJBNj2tDbYYMzgAAACM"] [Tue Aug 18 13:02:01.014131 2026] [security2:error] [pid 123784:tid 124010] [client 20.226.112.14:39431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/txets.php"] [unique_id "aoSB-WwDnJBNj2tDbYYMzwAAAFw"] [Tue Aug 18 13:02:01.024231 2026] [security2:error] [pid 123784:tid 124042] [client 20.163.43.14:8925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/function/function.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0AAAAHw"] [Tue Aug 18 13:02:01.028205 2026] [security2:error] [pid 123784:tid 123977] [client 20.79.204.6:12239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0QAAADs"] [Tue Aug 18 13:02:01.028376 2026] [security2:error] [pid 123784:tid 123938] [client 213.35.127.232:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0gAAABQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:01.036838 2026] [security2:error] [pid 123784:tid 123983] [client 172.202.39.151:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/files/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM0wAAAEE"] [Tue Aug 18 13:02:01.052190 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fun.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZeAAAAPM"] [Tue Aug 18 13:02:01.069172 2026] [security2:error] [pid 123784:tid 124005] [client 20.75.92.165:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/rip.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1AAAAFc"] [Tue Aug 18 13:02:01.075831 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZegAAAMk"] [Tue Aug 18 13:02:01.088433 2026] [security2:error] [pid 123784:tid 124035] [client 20.251.112.238:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-good.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1QAAAHU"] [Tue Aug 18 13:02:01.090713 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:48428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wx.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1gAAAEQ"] [Tue Aug 18 13:02:01.096829 2026] [security2:error] [pid 139043:tid 139277] [client 68.155.154.236:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/weozh.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZewAAAO0"] [Tue Aug 18 13:02:01.097917 2026] [security2:error] [pid 139043:tid 139253] [client 20.127.136.245:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfAAAANU"] [Tue Aug 18 13:02:01.099256 2026] [security2:error] [pid 139043:tid 139236] [client 20.51.153.15:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/yindu.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfQAAAMQ"] [Tue Aug 18 13:02:01.125244 2026] [security2:error] [pid 139043:tid 139187] [client 20.119.58.187:10471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ws.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZfwAAAJM"] [Tue Aug 18 13:02:01.140581 2026] [security2:error] [pid 123784:tid 123816] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/asus.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM1wAADBs"] [Tue Aug 18 13:02:01.142408 2026] [security2:error] [pid 123784:tid 123934] [client 132.196.30.78:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/info.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2AAAABA"] [Tue Aug 18 13:02:01.180131 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.112.14:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/jq.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2QAAAGk"] [Tue Aug 18 13:02:01.187018 2026] [security2:error] [pid 123784:tid 123936] [client 20.104.100.201:49121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-good.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2gAAABI"] [Tue Aug 18 13:02:01.222095 2026] [security2:error] [pid 139043:tid 139220] [client 68.155.154.236:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/oivcl.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZggAAALQ"] [Tue Aug 18 13:02:01.222640 2026] [security2:error] [pid 139043:tid 139199] [client 20.91.215.254:11490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-activat.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZgwAAAJ8"] [Tue Aug 18 13:02:01.230459 2026] [security2:error] [pid 123784:tid 123932] [client 158.158.74.177:18985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/u.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM2wAAAA4"] [Tue Aug 18 13:02:01.242499 2026] [security2:error] [pid 139043:tid 139234] [client 52.139.47.57:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/tgrs.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhAAAAMI"] [Tue Aug 18 13:02:01.267486 2026] [security2:error] [pid 123784:tid 124018] [client 88.99.80.227:49728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/"] [unique_id "aoSB-WwDnJBNj2tDbYYM3QAAAGQ"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 13:02:01.272565 2026] [security2:error] [pid 139043:tid 139300] [client 20.226.112.14:28784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sys.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhQAAAQQ"] [Tue Aug 18 13:02:01.279120 2026] [security2:error] [pid 139043:tid 139254] [client 172.213.243.2:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/G-in.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZhgAAANY"] [Tue Aug 18 13:02:01.316495 2026] [security2:error] [pid 123784:tid 123850] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/22.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM3gAAMj0"] [Tue Aug 18 13:02:01.337422 2026] [security2:error] [pid 139043:tid 139239] [client 20.51.153.15:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/sxx.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZiQAAAMc"] [Tue Aug 18 13:02:01.353687 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pqr.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM3wAAAHI"] [Tue Aug 18 13:02:01.362166 2026] [security2:error] [pid 123784:tid 124025] [client 20.163.43.14:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4AAAAGs"] [Tue Aug 18 13:02:01.363334 2026] [security2:error] [pid 139043:tid 139271] [client 52.173.121.69:9485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZigAAAOc"] [Tue Aug 18 13:02:01.372383 2026] [security2:error] [pid 123784:tid 123969] [client 20.75.92.165:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/update/da222.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4QAAADM"] [Tue Aug 18 13:02:01.391422 2026] [security2:error] [pid 139043:tid 139259] [client 20.226.112.14:22855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/pp.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZiwAAANs"] [Tue Aug 18 13:02:01.399180 2026] [security2:error] [pid 123784:tid 124022] [client 20.151.109.219:24400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/er.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4gAAAGg"] [Tue Aug 18 13:02:01.458223 2026] [security2:error] [pid 139043:tid 139281] [client 20.116.17.175:22922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/echkm.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZjQAAAPE"] [Tue Aug 18 13:02:01.463373 2026] [security2:error] [pid 139043:tid 139197] [client 20.226.112.14:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wqqs.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZjwAAAJ0"] [Tue Aug 18 13:02:01.465794 2026] [security2:error] [pid 123784:tid 124011] [client 20.104.100.201:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wmore1.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM4wAAAF0"] [Tue Aug 18 13:02:01.467681 2026] [authz_core:error] [pid 139043:tid 139299] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:01.467981 2026] [authz_core:error] [pid 139043:tid 139299] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:01.478598 2026] [security2:error] [pid 123784:tid 123951] [client 20.119.58.187:10173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wsa.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5AAAACE"] [Tue Aug 18 13:02:01.495673 2026] [security2:error] [pid 123784:tid 123926] [client 20.226.112.14:28761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/clasa99.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5QAAAAg"] [Tue Aug 18 13:02:01.525172 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zs.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5gAATUY"] [Tue Aug 18 13:02:01.547684 2026] [security2:error] [pid 139043:tid 139203] [client 20.29.77.16:40547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/moderator.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZnQAAAKM"] [Tue Aug 18 13:02:01.615014 2026] [security2:error] [pid 139043:tid 139228] [client 20.251.112.238:53142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zxin.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZoQAAALw"] [Tue Aug 18 13:02:01.624029 2026] [security2:error] [pid 139043:tid 139177] [client 132.196.30.78:19157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/chosen.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZogAAAIk"] [Tue Aug 18 13:02:01.630559 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/666.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM5wAAAH8"] [Tue Aug 18 13:02:01.634540 2026] [security2:error] [pid 139043:tid 139180] [client 20.79.204.6:11878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZpAAAAIw"] [Tue Aug 18 13:02:01.635570 2026] [security2:error] [pid 123784:tid 123958] [client 4.232.94.69:29842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/log.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6AAAACg"] [Tue Aug 18 13:02:01.638662 2026] [security2:error] [pid 123784:tid 124028] [client 20.75.92.165:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/upload.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6QAAAG4"] [Tue Aug 18 13:02:01.655367 2026] [security2:error] [pid 139043:tid 139269] [client 158.23.17.4:34026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/uq.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZpQAAAOU"] [Tue Aug 18 13:02:01.671358 2026] [security2:error] [pid 139043:tid 139272] [client 52.139.47.57:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/ws83.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqAAAAOg"] [Tue Aug 18 13:02:01.680768 2026] [security2:error] [pid 139043:tid 139208] [client 20.79.204.6:11561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqQAAAKg"] [Tue Aug 18 13:02:01.691792 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:8796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqgAAAN8"] [Tue Aug 18 13:02:01.692864 2026] [security2:error] [pid 139043:tid 139288] [client 172.213.243.2:11820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xxx.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZqwAAAPg"] [Tue Aug 18 13:02:01.709276 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/settings.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrAAAAPA"] [Tue Aug 18 13:02:01.727320 2026] [authz_core:error] [pid 139043:tid 139096] [remote 57.141.22.86:27498] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:01.727798 2026] [authz_core:error] [pid 139043:tid 139096] [remote 57.141.22.86:27498] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:01.738128 2026] [security2:error] [pid 139043:tid 139245] [client 20.151.109.219:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qk.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrgAAAM0"] [Tue Aug 18 13:02:01.747841 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:10704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/i.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZrwAAAJY"] [Tue Aug 18 13:02:01.751779 2026] [security2:error] [pid 123784:tid 124043] [client 20.104.100.201:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/special.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6gAAAH0"] [Tue Aug 18 13:02:01.754325 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/thui.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZsAAAAM4"] [Tue Aug 18 13:02:01.779349 2026] [security2:error] [pid 123784:tid 124033] [client 102.213.179.104:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6wAAAHM"] [Tue Aug 18 13:02:01.779550 2026] [security2:error] [pid 123784:tid 124033] [client 102.213.179.104:52183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM6wAAAHM"] [Tue Aug 18 13:02:01.793211 2026] [security2:error] [pid 123784:tid 123915] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/iz.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM7AAAJn4"] [Tue Aug 18 13:02:01.797986 2026] [security2:error] [pid 139043:tid 139287] [client 20.226.112.14:22946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/agg.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZswAAAPc"] [Tue Aug 18 13:02:01.829293 2026] [security2:error] [pid 139043:tid 139242] [client 86.120.159.145:14859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtgAAAMo"] [Tue Aug 18 13:02:01.829392 2026] [security2:error] [pid 139043:tid 139242] [client 86.120.159.145:14859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtgAAAMo"] [Tue Aug 18 13:02:01.836678 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.56.190:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/456.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZtwAAAI0"] [Tue Aug 18 13:02:01.841266 2026] [security2:error] [pid 139043:tid 139175] [client 68.221.73.131:41659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/bs1.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuAAAAIc"] [Tue Aug 18 13:02:01.844352 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/erty.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuQAAALc"] [Tue Aug 18 13:02:01.861796 2026] [security2:error] [pid 139043:tid 139261] [client 20.119.58.187:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/w.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZuwAAAN0"] [Tue Aug 18 13:02:01.867996 2026] [security2:error] [pid 123784:tid 123976] [client 20.203.183.135:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8AAAADo"] [Tue Aug 18 13:02:01.873007 2026] [security2:error] [pid 123784:tid 124012] [client 20.226.112.14:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mini.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8QAAAF4"] [Tue Aug 18 13:02:01.882880 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.112.14:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sid3.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvAAAAIU"] [Tue Aug 18 13:02:01.890787 2026] [security2:error] [pid 139043:tid 139252] [client 20.75.92.165:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wk/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvQAAANQ"] [Tue Aug 18 13:02:01.896135 2026] [security2:error] [pid 123784:tid 124038] [client 20.226.112.14:22934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/moon.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8gAAAHg"] [Tue Aug 18 13:02:01.897797 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:8345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zugvi.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM8wAAACQ"] [Tue Aug 18 13:02:01.902294 2026] [security2:error] [pid 139043:tid 139193] [client 216.244.66.232:57686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvgAAAJk"] [Tue Aug 18 13:02:01.902377 2026] [security2:error] [pid 139043:tid 139193] [client 216.244.66.232:57686] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZvgAAAJk"] [Tue Aug 18 13:02:01.921574 2026] [security2:error] [pid 123784:tid 123982] [client 135.225.78.186:39556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/key.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM9AAAAEA"] [Tue Aug 18 13:02:01.932848 2026] [security2:error] [pid 139043:tid 139072] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwAAAixw"] [Tue Aug 18 13:02:01.933002 2026] [security2:error] [pid 139043:tid 139179] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwAAAixw"] [Tue Aug 18 13:02:01.936036 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.112.14:13046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwQAAALo"] [Tue Aug 18 13:02:01.959798 2026] [security2:error] [pid 139043:tid 139298] [client 20.91.215.254:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZwwAAAQI"] [Tue Aug 18 13:02:01.960349 2026] [security2:error] [pid 123784:tid 124000] [client 132.196.30.78:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/simple.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM9gAAAFI"] [Tue Aug 18 13:02:01.960745 2026] [security2:error] [pid 139043:tid 139201] [client 20.226.112.14:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wsws.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxAAAAKE"] [Tue Aug 18 13:02:01.961207 2026] [security2:error] [pid 139043:tid 139211] [client 20.51.153.15:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/spip.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxQAAAKs"] [Tue Aug 18 13:02:01.972320 2026] [fcgid:warn] [pid 123784:tid 123946] (70014)End of file found: [client 199.45.155.75:45442] mod_fcgid: can't get data from http client [Tue Aug 18 13:02:02.000061 2026] [security2:error] [pid 139043:tid 139276] [client 20.127.136.245:11804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/lite.php"] [unique_id "aoSB-f2v-lWn9OzQT7UZxgAAAOw"] [Tue Aug 18 13:02:02.005914 2026] [security2:error] [pid 123784:tid 123902] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/se.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM-AAAG3E"] [Tue Aug 18 13:02:02.033037 2026] [security2:error] [pid 139043:tid 139198] [client 20.104.100.201:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZyQAAAJ4"] [Tue Aug 18 13:02:02.038743 2026] [security2:error] [pid 139043:tid 139238] [client 20.163.43.14:8870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/ok.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZywAAAMY"] [Tue Aug 18 13:02:02.045005 2026] [security2:error] [pid 139043:tid 139282] [client 213.35.127.232:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzAAAAPI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:02.059996 2026] [security2:error] [pid 139043:tid 139174] [client 20.226.112.14:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/motu.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzQAAAIY"] [Tue Aug 18 13:02:02.064549 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/dj.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzgAAALQ"] [Tue Aug 18 13:02:02.085039 2026] [security2:error] [pid 139043:tid 139234] [client 20.29.77.16:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/infoinfo.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZzwAAAMI"] [Tue Aug 18 13:02:02.092749 2026] [security2:error] [pid 139043:tid 139111] [remote 68.178.165.65:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "historiasparadormir.top"] [uri "/wp-login.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ0QAA0UM"] [Tue Aug 18 13:02:02.116220 2026] [security2:error] [pid 139043:tid 139239] [client 172.213.243.2:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/un.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1AAAAMc"] [Tue Aug 18 13:02:02.130204 2026] [security2:error] [pid 123784:tid 123999] [client 158.23.17.4:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/an.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM-gAAAFE"] [Tue Aug 18 13:02:02.139054 2026] [security2:error] [pid 139043:tid 139271] [client 158.158.74.177:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/customize.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1gAAAOc"] [Tue Aug 18 13:02:02.150203 2026] [security2:error] [pid 139043:tid 139279] [client 20.75.92.165:4344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-act.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ1wAAAO8"] [Tue Aug 18 13:02:02.152014 2026] [security2:error] [pid 139043:tid 139259] [client 20.116.17.175:23038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/domvf.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ2AAAANs"] [Tue Aug 18 13:02:02.163672 2026] [security2:error] [pid 139043:tid 139229] [client 20.151.109.219:20127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3AAAAL0"] [Tue Aug 18 13:02:02.183776 2026] [security2:error] [pid 123784:tid 124017] [client 172.202.39.151:52407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_AAAAGM"] [Tue Aug 18 13:02:02.193239 2026] [security2:error] [pid 139043:tid 139283] [client 52.139.47.57:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/style.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3QAAAPM"] [Tue Aug 18 13:02:02.197204 2026] [security2:error] [pid 123784:tid 123842] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vp.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_QAAMTU"] [Tue Aug 18 13:02:02.210749 2026] [security2:error] [pid 123784:tid 123928] [client 20.251.112.238:26648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/pass4.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_gAAAAo"] [Tue Aug 18 13:02:02.211499 2026] [security2:error] [pid 123784:tid 123940] [client 20.51.153.15:13581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/search.php"] [unique_id "aoSB-mwDnJBNj2tDbYYM_wAAABY"] [Tue Aug 18 13:02:02.215711 2026] [security2:error] [pid 139043:tid 139182] [client 20.119.58.187:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/x.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ3gAAAI4"] [Tue Aug 18 13:02:02.262554 2026] [security2:error] [pid 139043:tid 139231] [client 20.79.204.6:12272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ4QAAAL8"] [Tue Aug 18 13:02:02.297222 2026] [security2:error] [pid 139043:tid 139177] [client 20.38.3.247:25845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/222.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ4wAAAIk"] [Tue Aug 18 13:02:02.307227 2026] [security2:error] [pid 139043:tid 139180] [client 68.155.154.236:64180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/rymmm.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5AAAAIw"] [Tue Aug 18 13:02:02.308482 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:12282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5gAAALA"] [Tue Aug 18 13:02:02.312384 2026] [security2:error] [pid 139043:tid 139269] [client 20.104.100.201:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/thoms.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ5wAAAOU"] [Tue Aug 18 13:02:02.323102 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/32.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6AAAAJg"] [Tue Aug 18 13:02:02.341288 2026] [security2:error] [pid 139043:tid 139086] [remote 40.77.167.254:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6QAA-Co"], referer: https://siderurgiabrasil.com.br/2020/09/02/iabr-icia-indice-de-confianca-da-industria-do-aco/ [Tue Aug 18 13:02:02.350059 2026] [security2:error] [pid 123784:tid 124002] [client 68.155.154.236:55461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wsrer.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAAAAAFQ"] [Tue Aug 18 13:02:02.361797 2026] [security2:error] [pid 139043:tid 139188] [client 20.163.43.14:8885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autoescolabrinhosa.com.br"] [uri "/item.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ6gAAAJQ"] [Tue Aug 18 13:02:02.402339 2026] [security2:error] [pid 123784:tid 123927] [client 20.226.112.14:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fff.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAQAAAAk"] [Tue Aug 18 13:02:02.438991 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fa.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNAgAAAFo"] [Tue Aug 18 13:02:02.468133 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:02.468418 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:02.469793 2026] [security2:error] [pid 123784:tid 124042] [client 20.75.92.165:4294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBAAAAHw"] [Tue Aug 18 13:02:02.470957 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:13591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/build.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ7QAAAPc"] [Tue Aug 18 13:02:02.483098 2026] [security2:error] [pid 123784:tid 123987] [client 20.226.112.14:38919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/66.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBgAAAEU"] [Tue Aug 18 13:02:02.491659 2026] [security2:error] [pid 139043:tid 139196] [client 20.29.77.16:33575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/c99shell.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ7wAAAJw"] [Tue Aug 18 13:02:02.530006 2026] [security2:error] [pid 139043:tid 139265] [client 172.213.243.2:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/autogooey.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ8QAAAOE"] [Tue Aug 18 13:02:02.548939 2026] [security2:error] [pid 139043:tid 139181] [client 20.127.136.245:3561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ms-edit.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ8gAAAI0"] [Tue Aug 18 13:02:02.553191 2026] [security2:error] [pid 123784:tid 124003] [client 20.151.109.219:39335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fs.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNBwAAAFU"] [Tue Aug 18 13:02:02.568677 2026] [security2:error] [pid 123784:tid 123953] [client 20.119.58.187:10175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/xx.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNCAAAACM"] [Tue Aug 18 13:02:02.573212 2026] [security2:error] [pid 123784:tid 124005] [client 172.202.39.151:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/cache.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNCQAAAFc"] [Tue Aug 18 13:02:02.584349 2026] [security2:error] [pid 139043:tid 139266] [client 20.104.100.201:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9AAAAOI"] [Tue Aug 18 13:02:02.614483 2026] [security2:error] [pid 139043:tid 139294] [client 52.139.47.57:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp-the.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9QAAAP4"] [Tue Aug 18 13:02:02.653904 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:22897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/g.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ9wAAAL4"] [Tue Aug 18 13:02:02.689553 2026] [security2:error] [pid 123784:tid 123975] [client 20.91.215.254:27075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/past1.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNDAAAADk"] [Tue Aug 18 13:02:02.690430 2026] [security2:error] [pid 139043:tid 139178] [client 40.77.167.254:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ-QAAAIo"], referer: http://siderurgiabrasil.com.br/2026/06/30/industria-de-maquinas-enfrenta-desaceleracao-persistente/ [Tue Aug 18 13:02:02.741528 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.112.14:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/x7.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ-wAAAJs"] [Tue Aug 18 13:02:02.765291 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:02.765596 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:02.768499 2026] [security2:error] [pid 139043:tid 139225] [client 20.51.153.15:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/defaul.php"] [unique_id "aoSB-v2v-lWn9OzQT7UZ_gAAALk"] [Tue Aug 18 13:02:02.774995 2026] [security2:error] [pid 139043:tid 139268] [client 132.196.30.78:25625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaAAAAAOQ"] [Tue Aug 18 13:02:02.799767 2026] [security2:error] [pid 139043:tid 139255] [client 20.251.112.238:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaAQAAANc"] [Tue Aug 18 13:02:02.859354 2026] [security2:error] [pid 139043:tid 139262] [client 20.104.100.201:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/root.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaBAAAAN4"] [Tue Aug 18 13:02:02.923682 2026] [security2:error] [pid 123784:tid 123979] [client 20.79.204.6:10772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNEwAAAD0"] [Tue Aug 18 13:02:02.925957 2026] [security2:error] [pid 123784:tid 123937] [client 20.119.58.187:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNEgAAABM"] [Tue Aug 18 13:02:02.935212 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.112.14:34222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/god.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaCAAAAJ4"] [Tue Aug 18 13:02:02.940666 2026] [security2:error] [pid 123784:tid 123932] [client 172.213.243.2:11632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sty.php"] [unique_id "aoSB-mwDnJBNj2tDbYYNFAAAAA4"] [Tue Aug 18 13:02:02.966793 2026] [security2:error] [pid 139043:tid 139238] [client 158.158.74.177:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/mah/function.php"] [unique_id "aoSB-v2v-lWn9OzQT7UaCwAAAMY"] [Tue Aug 18 13:02:03.010352 2026] [security2:error] [pid 123784:tid 124029] [client 20.116.17.175:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/red.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFQAAAG8"] [Tue Aug 18 13:02:03.026510 2026] [security2:error] [pid 123784:tid 123970] [client 158.23.17.4:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sy.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFgAAADQ"] [Tue Aug 18 13:02:03.029166 2026] [security2:error] [pid 139043:tid 139276] [client 52.139.47.57:39079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/plugin.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDAAAAOw"] [Tue Aug 18 13:02:03.033470 2026] [security2:error] [pid 139043:tid 139189] [client 20.151.109.219:60921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rb.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDQAAAJU"] [Tue Aug 18 13:02:03.037627 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:5110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/twin.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNFwAAADI"] [Tue Aug 18 13:02:03.054224 2026] [security2:error] [pid 123784:tid 123962] [client 68.155.154.236:41531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/ucpfr.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNGAAAACw"] [Tue Aug 18 13:02:03.061201 2026] [security2:error] [pid 139043:tid 139297] [client 213.35.127.232:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaDwAAAQE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:03.067506 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:03.067804 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:03.104262 2026] [security2:error] [pid 123784:tid 123949] [client 88.99.80.227:18396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/index.php"] [unique_id "aoSB-WwDnJBNj2tDbYYM7wAAAB8"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 13:02:03.123247 2026] [security2:error] [pid 123784:tid 123799] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ph.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNJQAATgo"] [Tue Aug 18 13:02:03.136637 2026] [security2:error] [pid 139043:tid 139254] [client 20.104.100.201:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/fpwch.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFQAAANY"] [Tue Aug 18 13:02:03.160751 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:30986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/73.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFgAAAKY"] [Tue Aug 18 13:02:03.169734 2026] [security2:error] [pid 123784:tid 123867] [remote 57.141.22.2:34674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSB-2wDnJBNj2tDbYYNJwAAVk4"] [Tue Aug 18 13:02:03.173013 2026] [security2:error] [pid 139043:tid 139279] [client 20.226.112.14:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ebahvhhh.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaFwAAAO8"] [Tue Aug 18 13:02:03.185521 2026] [security2:error] [pid 139043:tid 139127] [remote 40.77.167.254:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaGQAA_FM"], referer: https://siderurgiabrasil.com.br/2022/10/25/gerdau-e-seu-papel-social/ [Tue Aug 18 13:02:03.249804 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.112.14:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/8.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHAAAAJM"] [Tue Aug 18 13:02:03.257253 2026] [security2:error] [pid 139043:tid 139247] [client 20.29.77.16:64903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/profiler.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHQAAAM8"] [Tue Aug 18 13:02:03.278558 2026] [security2:error] [pid 139043:tid 139239] [client 20.119.58.187:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/y.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHgAAAMc"] [Tue Aug 18 13:02:03.288716 2026] [security2:error] [pid 123784:tid 123955] [client 20.51.153.15:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/new2.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNKQAAACU"] [Tue Aug 18 13:02:03.292868 2026] [security2:error] [pid 123784:tid 123883] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/s.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNKwAAbF4"] [Tue Aug 18 13:02:03.294438 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:12286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaHwAAAOs"] [Tue Aug 18 13:02:03.303484 2026] [security2:error] [pid 123784:tid 123958] [client 20.127.136.245:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/rip.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNLAAAACg"] [Tue Aug 18 13:02:03.308517 2026] [security2:error] [pid 139043:tid 139270] [client 20.251.112.238:22366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/z.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIAAAAOY"] [Tue Aug 18 13:02:03.330613 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.112.14:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/koiy.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIgAAAO4"] [Tue Aug 18 13:02:03.331427 2026] [security2:error] [pid 139043:tid 139219] [client 20.79.204.6:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaIwAAALM"] [Tue Aug 18 13:02:03.334919 2026] [security2:error] [pid 123784:tid 124006] [client 20.151.109.219:14098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/37.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNMQAAAFg"] [Tue Aug 18 13:02:03.360610 2026] [security2:error] [pid 139043:tid 139237] [client 20.91.215.254:11517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/file61.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJAAAAMU"] [Tue Aug 18 13:02:03.386403 2026] [security2:error] [pid 139043:tid 139228] [client 172.213.243.2:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wio.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJgAAALw"] [Tue Aug 18 13:02:03.403370 2026] [security2:error] [pid 139043:tid 139216] [client 20.226.112.14:39468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/iko.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaJwAAALA"] [Tue Aug 18 13:02:03.412477 2026] [security2:error] [pid 139043:tid 139208] [client 20.104.100.201:49705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/mg.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaKQAAAKg"] [Tue Aug 18 13:02:03.454997 2026] [security2:error] [pid 139043:tid 139191] [client 52.139.47.57:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/readme.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLQAAAJc"] [Tue Aug 18 13:02:03.456925 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:25392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/fb.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLgAAAJQ"] [Tue Aug 18 13:02:03.465175 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaLwAAANo"] [Tue Aug 18 13:02:03.472077 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/lddxs.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNNwAAACc"] [Tue Aug 18 13:02:03.475342 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:28774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/raw.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNOQAAAHM"] [Tue Aug 18 13:02:03.518686 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/uo.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNOgAAQ1c"] [Tue Aug 18 13:02:03.531161 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/rex.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMQAAAKQ"] [Tue Aug 18 13:02:03.533029 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:8861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/yxijx.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMgAAALE"] [Tue Aug 18 13:02:03.559829 2026] [security2:error] [pid 139043:tid 139196] [client 68.221.73.131:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/hp2.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaMwAAAJw"] [Tue Aug 18 13:02:03.566797 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.56.190:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/SMTP.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaNQAAAOE"] [Tue Aug 18 13:02:03.586878 2026] [security2:error] [pid 139043:tid 139181] [client 20.203.183.135:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaNgAAAI0"] [Tue Aug 18 13:02:03.594493 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.112.14:39428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/05.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOAAAAK4"] [Tue Aug 18 13:02:03.620007 2026] [security2:error] [pid 139043:tid 139240] [client 20.151.109.219:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/md.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOgAAAMg"] [Tue Aug 18 13:02:03.620652 2026] [security2:error] [pid 139043:tid 139180] [client 158.158.74.177:22878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/filter.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaOwAAAIw"] [Tue Aug 18 13:02:03.623041 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:32546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/public/hi.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaPAAAAL4"] [Tue Aug 18 13:02:03.653418 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/get.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaPQAAAM4"] [Tue Aug 18 13:02:03.685668 2026] [security2:error] [pid 139043:tid 139261] [client 20.104.100.201:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/reop3.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQAAAAN0"] [Tue Aug 18 13:02:03.698909 2026] [security2:error] [pid 123784:tid 123835] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kx.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPQAAOC4"] [Tue Aug 18 13:02:03.712049 2026] [security2:error] [pid 123784:tid 123837] [remote 115.146.125.52:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPgAAPjA"] [Tue Aug 18 13:02:03.737647 2026] [security2:error] [pid 123784:tid 123976] [client 20.75.92.165:4350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNPwAAADo"] [Tue Aug 18 13:02:03.739238 2026] [security2:error] [pid 139043:tid 139221] [client 20.226.112.14:28594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/rpk.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQgAAALU"] [Tue Aug 18 13:02:03.743005 2026] [security2:error] [pid 123784:tid 123923] [client 20.79.204.6:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQAAAAAU"] [Tue Aug 18 13:02:03.766985 2026] [security2:error] [pid 139043:tid 139225] [client 132.196.30.78:25642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/av.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaQwAAALk"] [Tue Aug 18 13:02:03.767508 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/verification.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRAAAAOQ"] [Tue Aug 18 13:02:03.772633 2026] [security2:error] [pid 123784:tid 124012] [client 20.29.77.16:27105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/findes.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQgAAAF4"] [Tue Aug 18 13:02:03.778258 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:17567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/57.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNQwAAADY"] [Tue Aug 18 13:02:03.807819 2026] [security2:error] [pid 123784:tid 124007] [client 172.213.243.2:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/1061.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNRQAAAFk"] [Tue Aug 18 13:02:03.834965 2026] [security2:error] [pid 139043:tid 139251] [client 20.251.112.238:40618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/222.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSAAAANM"] [Tue Aug 18 13:02:03.836179 2026] [security2:error] [pid 139043:tid 139108] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRwAAq0A"] [Tue Aug 18 13:02:03.836347 2026] [security2:error] [pid 139043:tid 139211] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaRwAAq0A"] [Tue Aug 18 13:02:03.840843 2026] [security2:error] [pid 139043:tid 139262] [client 172.202.39.151:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/images/images/about.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSQAAAN4"] [Tue Aug 18 13:02:03.843995 2026] [security2:error] [pid 123784:tid 124044] [client 4.232.151.198:38792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/edit.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNRgAAAH4"] [Tue Aug 18 13:02:03.886650 2026] [security2:error] [pid 139043:tid 139195] [client 52.139.47.57:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/chosen.php"] [unique_id "aoSB-_2v-lWn9OzQT7UaSwAAAJs"] [Tue Aug 18 13:02:03.920887 2026] [security2:error] [pid 123784:tid 123877] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/va.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSAAAHFg"] [Tue Aug 18 13:02:03.939429 2026] [security2:error] [pid 123784:tid 123945] [client 20.151.109.219:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/iy.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSQAAABs"] [Tue Aug 18 13:02:03.943215 2026] [security2:error] [pid 123784:tid 123950] [client 20.116.17.175:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSgAAACA"] [Tue Aug 18 13:02:03.951586 2026] [security2:error] [pid 123784:tid 123984] [client 20.226.112.14:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-blog.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNSwAAAEI"] [Tue Aug 18 13:02:03.955862 2026] [security2:error] [pid 123784:tid 124040] [client 20.104.100.201:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/php5.php"] [unique_id "aoSB-2wDnJBNj2tDbYYNTAAAAHo"] [Tue Aug 18 13:02:03.970799 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:03.971054 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:04.011014 2026] [security2:error] [pid 123784:tid 124013] [client 20.127.136.245:11777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/update/da222.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNUAAAAF8"] [Tue Aug 18 13:02:04.035101 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.112.14:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/mga.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaUQAAAJ4"] [Tue Aug 18 13:02:04.048874 2026] [security2:error] [pid 139043:tid 139277] [client 20.38.3.247:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/key.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaUwAAAO0"] [Tue Aug 18 13:02:04.053351 2026] [security2:error] [pid 139043:tid 139282] [client 20.51.153.15:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/smtp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVAAAAPI"] [Tue Aug 18 13:02:04.078381 2026] [security2:error] [pid 139043:tid 139193] [client 213.35.127.232:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVQAAAJk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:04.090239 2026] [security2:error] [pid 123784:tid 123856] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fo.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNUwAAHUM"] [Tue Aug 18 13:02:04.096096 2026] [security2:error] [pid 139043:tid 139236] [client 20.226.112.14:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/fs.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVgAAAMQ"] [Tue Aug 18 13:02:04.102647 2026] [security2:error] [pid 139043:tid 139174] [client 20.79.204.6:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaVwAAAIY"] [Tue Aug 18 13:02:04.124298 2026] [security2:error] [pid 139043:tid 139220] [client 52.173.121.69:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWAAAALQ"] [Tue Aug 18 13:02:04.143350 2026] [security2:error] [pid 139043:tid 139297] [client 158.23.17.4:25391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gw.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWgAAAQE"] [Tue Aug 18 13:02:04.145941 2026] [security2:error] [pid 139043:tid 139224] [client 20.79.204.6:11563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaWwAAALg"] [Tue Aug 18 13:02:04.149106 2026] [security2:error] [pid 139043:tid 139285] [client 20.75.92.165:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaXAAAAPU"] [Tue Aug 18 13:02:04.194978 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ve.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaXwAAANs"] [Tue Aug 18 13:02:04.203557 2026] [security2:error] [pid 123784:tid 124010] [client 172.202.39.151:44578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNVQAAAFw"] [Tue Aug 18 13:02:04.221274 2026] [security2:error] [pid 123784:tid 123987] [client 20.91.215.254:11500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/license.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNVwAAAEU"] [Tue Aug 18 13:02:04.228029 2026] [security2:error] [pid 139043:tid 139273] [client 172.213.243.2:11807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gec.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaYAAAAOk"] [Tue Aug 18 13:02:04.231031 2026] [security2:error] [pid 139043:tid 139283] [client 20.104.100.201:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/acp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaYgAAAPM"] [Tue Aug 18 13:02:04.243729 2026] [security2:error] [pid 123784:tid 124003] [client 68.155.154.236:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/zwlsv.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNWAAAAFU"] [Tue Aug 18 13:02:04.274953 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:04.275234 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:04.287581 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/loading.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXAAAcR0"] [Tue Aug 18 13:02:04.287736 2026] [security2:error] [pid 123784:tid 124035] [client 20.51.153.15:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/teste.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXQAAAHU"] [Tue Aug 18 13:02:04.289054 2026] [security2:error] [pid 123784:tid 124017] [client 158.158.74.177:22911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/input.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNXgAAAGM"] [Tue Aug 18 13:02:04.300026 2026] [security2:error] [pid 139043:tid 139249] [client 52.139.47.57:18352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/system.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaZAAAANE"] [Tue Aug 18 13:02:04.304136 2026] [security2:error] [pid 139043:tid 139231] [client 20.151.109.219:39299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/og.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaZQAAAL8"] [Tue Aug 18 13:02:04.359394 2026] [security2:error] [pid 123784:tid 123936] [client 158.23.17.4:20201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ib.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNZAAAABI"] [Tue Aug 18 13:02:04.370938 2026] [security2:error] [pid 139043:tid 139208] [client 20.226.112.14:60107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/wp-tem.php"] [unique_id "aoSB_P2v-lWn9OzQT7UabAAAAKg"] [Tue Aug 18 13:02:04.378460 2026] [security2:error] [pid 139043:tid 139288] [client 20.127.136.245:11836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/upload.php"] [unique_id "aoSB_P2v-lWn9OzQT7UabQAAAPg"] [Tue Aug 18 13:02:04.406087 2026] [security2:error] [pid 139043:tid 139279] [client 66.187.6.102:33492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/trinchas/trincha-angular"] [unique_id "aoSB_P2v-lWn9OzQT7UabgAAAO8"] [Tue Aug 18 13:02:04.406175 2026] [security2:error] [pid 139043:tid 139279] [client 66.187.6.102:33492] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/produtos/trinchas/trincha-angular"] [unique_id "aoSB_P2v-lWn9OzQT7UabgAAAO8"] [Tue Aug 18 13:02:04.434588 2026] [security2:error] [pid 123784:tid 123932] [client 68.155.154.236:45864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/zjggu.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNawAAAA4"] [Tue Aug 18 13:02:04.442150 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.112.14:13013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/sadd.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbAAAAGA"] [Tue Aug 18 13:02:04.460015 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ke.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbQAAZA0"] [Tue Aug 18 13:02:04.481508 2026] [security2:error] [pid 123784:tid 123854] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/.env.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNYgAAaUE"] [Tue Aug 18 13:02:04.486883 2026] [security2:error] [pid 123784:tid 123884] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/config/.env.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNYQAAaV8"] [Tue Aug 18 13:02:04.498977 2026] [security2:error] [pid 123784:tid 123970] [client 20.251.112.238:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/G-in.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNbwAAADQ"] [Tue Aug 18 13:02:04.514604 2026] [security2:error] [pid 139043:tid 139242] [client 20.104.100.201:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/yas.php"] [unique_id "aoSB_P2v-lWn9OzQT7UafgAAAMo"] [Tue Aug 18 13:02:04.516811 2026] [security2:error] [pid 123784:tid 123962] [client 20.29.77.16:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/fedora.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNdQAAACw"] [Tue Aug 18 13:02:04.526120 2026] [security2:error] [pid 123784:tid 123959] [client 20.51.153.15:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/local.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNdgAAACk"] [Tue Aug 18 13:02:04.545682 2026] [security2:error] [pid 139043:tid 139216] [client 66.187.6.102:33510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/site/plugins/jquerymask/jquery.mask.min.js"] [unique_id "aoSB_P2v-lWn9OzQT7UagAAAALA"] [Tue Aug 18 13:02:04.545775 2026] [security2:error] [pid 139043:tid 139216] [client 66.187.6.102:33510] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/site/plugins/jquerymask/jquery.mask.min.js"] [unique_id "aoSB_P2v-lWn9OzQT7UagAAAALA"] [Tue Aug 18 13:02:04.571539 2026] [security2:error] [pid 123784:tid 123909] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNZwAAaXg"] [Tue Aug 18 13:02:04.572864 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:04.573139 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:04.580359 2026] [security2:error] [pid 123784:tid 123843] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/config.php.bak"] [unique_id "aoSB_GwDnJBNj2tDbYYNaQAAaTY"] [Tue Aug 18 13:02:04.590148 2026] [security2:error] [pid 123784:tid 124011] [client 20.151.109.219:24441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lp.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNewAAAF0"] [Tue Aug 18 13:02:04.606474 2026] [security2:error] [pid 123784:tid 124024] [client 20.226.112.14:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ex.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNfwAAAGo"] [Tue Aug 18 13:02:04.654430 2026] [security2:error] [pid 123784:tid 123995] [client 172.213.243.2:11823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/scx.php7"] [unique_id "aoSB_GwDnJBNj2tDbYYNhQAAAE0"] [Tue Aug 18 13:02:04.680007 2026] [security2:error] [pid 123784:tid 123961] [client 20.116.17.175:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNhgAAACs"] [Tue Aug 18 13:02:04.693083 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nh.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNiAAAASM"] [Tue Aug 18 13:02:04.711955 2026] [security2:error] [pid 123784:tid 124032] [client 20.79.204.6:12276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNiQAAAHI"] [Tue Aug 18 13:02:04.722577 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.112.14:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/tax.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjAAAAH8"] [Tue Aug 18 13:02:04.725030 2026] [security2:error] [pid 139043:tid 139266] [client 52.139.47.57:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/wp-load.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaigAAAOI"] [Tue Aug 18 13:02:04.733196 2026] [security2:error] [pid 139043:tid 139194] [client 20.75.92.165:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSB_P2v-lWn9OzQT7UaiwAAAJo"] [Tue Aug 18 13:02:04.754267 2026] [security2:error] [pid 123784:tid 123969] [client 20.79.204.6:11665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjgAAADM"] [Tue Aug 18 13:02:04.757048 2026] [security2:error] [pid 123784:tid 124006] [client 68.155.154.236:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/jrpga.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNjwAAAFg"] [Tue Aug 18 13:02:04.776547 2026] [security2:error] [pid 139043:tid 139185] [client 20.127.136.245:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wk/index.php"] [unique_id "aoSB_P2v-lWn9OzQT7UajQAAAJE"] [Tue Aug 18 13:02:04.789178 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ah25.php"] [unique_id "aoSB_P2v-lWn9OzQT7UajgAAAIU"] [Tue Aug 18 13:02:04.803885 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:55231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ah.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNlAAAAH0"] [Tue Aug 18 13:02:04.824550 2026] [security2:error] [pid 123784:tid 124033] [client 20.51.153.15:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNlgAAAHM"] [Tue Aug 18 13:02:04.866020 2026] [security2:error] [pid 139043:tid 139225] [client 20.226.112.14:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/X7x.php"] [unique_id "aoSB_P2v-lWn9OzQT7UakgAAALk"] [Tue Aug 18 13:02:04.868099 2026] [security2:error] [pid 123784:tid 123866] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/oo.php"] [unique_id "aoSB_GwDnJBNj2tDbYYNmgAAeU0"] [Tue Aug 18 13:02:04.868758 2026] [security2:error] [pid 139043:tid 139268] [client 158.23.17.4:41969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ia.php"] [unique_id "aoSB_P2v-lWn9OzQT7UakwAAAOQ"] [Tue Aug 18 13:02:04.871684 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:04.871951 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:04.916093 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.112.14:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ocxla.php"] [unique_id "aoSB_P2v-lWn9OzQT7UamAAAAIs"] [Tue Aug 18 13:02:04.960574 2026] [security2:error] [pid 139043:tid 139181] [client 4.232.151.198:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/elp.php"] [unique_id "aoSB_P2v-lWn9OzQT7UamwAAAI0"] [Tue Aug 18 13:02:04.965336 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:63735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ey.php"] [unique_id "aoSB_P2v-lWn9OzQT7UanAAAANk"] [Tue Aug 18 13:02:04.966063 2026] [authz_core:error] [pid 139043:tid 139290] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:04.966324 2026] [authz_core:error] [pid 139043:tid 139290] [client 192.178.4.134:56975] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:05.021116 2026] [security2:error] [pid 139043:tid 139267] [client 158.158.74.177:9224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/jquery.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaoAAAAOM"] [Tue Aug 18 13:02:05.036091 2026] [security2:error] [pid 139043:tid 139198] [client 20.203.183.135:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/blurbs.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaoQAAAJ4"] [Tue Aug 18 13:02:05.054653 2026] [security2:error] [pid 139043:tid 139241] [client 20.116.17.175:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaowAAAMk"] [Tue Aug 18 13:02:05.055404 2026] [security2:error] [pid 123784:tid 123944] [client 149.34.210.141:60062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnQAAABo"] [Tue Aug 18 13:02:05.057483 2026] [security2:error] [pid 139043:tid 139222] [client 20.75.92.165:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapAAAALY"] [Tue Aug 18 13:02:05.061293 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:15792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/sw.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnwAAAFk"] [Tue Aug 18 13:02:05.065011 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/ano.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapQAAAO0"] [Tue Aug 18 13:02:05.066026 2026] [security2:error] [pid 123784:tid 124044] [client 172.213.243.2:16857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNoAAAAH4"] [Tue Aug 18 13:02:05.070930 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.112.14:28794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/post.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNoQAAAFI"] [Tue Aug 18 13:02:05.072793 2026] [security2:error] [pid 123784:tid 123879] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ja.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNogAAcFo"] [Tue Aug 18 13:02:05.073250 2026] [security2:error] [pid 139043:tid 139193] [client 132.196.30.78:35576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapgAAAJk"] [Tue Aug 18 13:02:05.090251 2026] [security2:error] [pid 139043:tid 139246] [client 213.35.127.232:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSB_f2v-lWn9OzQT7UapwAAAM4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:05.115402 2026] [security2:error] [pid 123784:tid 123945] [client 172.202.39.151:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/ms-edit.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNowAAABs"] [Tue Aug 18 13:02:05.127752 2026] [security2:error] [pid 123784:tid 123950] [client 20.251.112.238:22355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xxx.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNpAAAACA"] [Tue Aug 18 13:02:05.142613 2026] [security2:error] [pid 123784:tid 123960] [client 20.51.153.15:13596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/ninja.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNpQAAACo"] [Tue Aug 18 13:02:05.152691 2026] [security2:error] [pid 139043:tid 139235] [client 52.139.47.57:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.compratec.com.br"] [uri "/files/8.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqQAAAMM"] [Tue Aug 18 13:02:05.155250 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.154.236:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqgAAAMQ"] [Tue Aug 18 13:02:05.170077 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.112.14:39449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/nhr.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaqwAAAOw"] [Tue Aug 18 13:02:05.178692 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:05.179191 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:05.181207 2026] [security2:error] [pid 123784:tid 123984] [client 20.29.77.16:47298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/path.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqAAAAEI"] [Tue Aug 18 13:02:05.239237 2026] [security2:error] [pid 123784:tid 123935] [client 20.226.112.14:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ms-edit.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqgAAABE"] [Tue Aug 18 13:02:05.248253 2026] [security2:error] [pid 123784:tid 123794] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xx.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNqwAAeAU"] [Tue Aug 18 13:02:05.265535 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrAAAACE"] [Tue Aug 18 13:02:05.265655 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:28059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrAAAACE"] [Tue Aug 18 13:02:05.272257 2026] [security2:error] [pid 123784:tid 123933] [client 138.36.100.162:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrQAAAA8"] [Tue Aug 18 13:02:05.272368 2026] [security2:error] [pid 123784:tid 123933] [client 138.36.100.162:42190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrQAAAA8"] [Tue Aug 18 13:02:05.305302 2026] [security2:error] [pid 139043:tid 139213] [client 20.75.92.165:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/0x.php"] [unique_id "aoSB_f2v-lWn9OzQT7UargAAAK0"] [Tue Aug 18 13:02:05.313978 2026] [security2:error] [pid 123784:tid 123981] [client 20.79.204.6:12269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNrwAAAD8"] [Tue Aug 18 13:02:05.323258 2026] [security2:error] [pid 123784:tid 123944] [client 149.34.210.141:60062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNnQAAABo"] [Tue Aug 18 13:02:05.333848 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.56.190:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/vbseo.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasAAAAOs"] [Tue Aug 18 13:02:05.346785 2026] [security2:error] [pid 139043:tid 139249] [client 20.104.100.201:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/nwflm.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasQAAANE"] [Tue Aug 18 13:02:05.354536 2026] [security2:error] [pid 139043:tid 139274] [client 20.79.204.6:11868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSB_f2v-lWn9OzQT7UasgAAAOo"] [Tue Aug 18 13:02:05.374641 2026] [security2:error] [pid 139043:tid 139212] [client 20.151.109.219:60377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lv.php"] [unique_id "aoSB_f2v-lWn9OzQT7UatAAAAKw"] [Tue Aug 18 13:02:05.383162 2026] [security2:error] [pid 123784:tid 123947] [client 20.51.153.15:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/phpprobe.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNsQAAAB0"] [Tue Aug 18 13:02:05.383684 2026] [security2:error] [pid 139043:tid 139231] [client 135.225.78.186:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/chosen.php"] [unique_id "aoSB_f2v-lWn9OzQT7UatQAAAL8"] [Tue Aug 18 13:02:05.414394 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:22888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ws79.php"] [unique_id "aoSB_f2v-lWn9OzQT7UatwAAAJA"] [Tue Aug 18 13:02:05.415221 2026] [security2:error] [pid 123784:tid 123836] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/conn-test.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNtAAARy8"] [Tue Aug 18 13:02:05.417222 2026] [security2:error] [pid 139043:tid 139228] [client 158.23.17.4:31898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xm.php"] [unique_id "aoSB_f2v-lWn9OzQT7UauAAAALw"] [Tue Aug 18 13:02:05.429328 2026] [security2:error] [pid 139043:tid 139118] [remote 54.39.203.198:35274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thautomoveislimeira.com.br"] [uri "/robots.txt"] [unique_id "aoSB_f2v-lWn9OzQT7UauQAA80o"] [Tue Aug 18 13:02:05.429463 2026] [security2:error] [pid 139043:tid 139283] [client 54.39.203.198:35274] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thautomoveislimeira.com.br"] [uri "/robots.txt"] [unique_id "aoSB_f2v-lWn9OzQT7UauQAA80o"] [Tue Aug 18 13:02:05.480899 2026] [security2:error] [pid 139043:tid 139269] [client 172.213.243.2:14542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp5.php"] [unique_id "aoSB_f2v-lWn9OzQT7UauwAAAOU"] [Tue Aug 18 13:02:05.503683 2026] [security2:error] [pid 139043:tid 139291] [client 213.202.253.4:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSB_f2v-lWn9OzQT7UavAAAAPs"], referer: www.google.com [Tue Aug 18 13:02:05.553874 2026] [security2:error] [pid 139043:tid 139208] [client 132.196.30.78:1299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/file2.php"] [unique_id "aoSB_f2v-lWn9OzQT7UavgAAAKg"] [Tue Aug 18 13:02:05.561316 2026] [security2:error] [pid 139043:tid 139262] [client 178.153.171.161:26050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_f2v-lWn9OzQT7UavwAAAN4"] [Tue Aug 18 13:02:05.561475 2026] [security2:error] [pid 139043:tid 139262] [client 178.153.171.161:26050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_f2v-lWn9OzQT7UavwAAAN4"] [Tue Aug 18 13:02:05.561835 2026] [security2:error] [pid 139043:tid 139191] [client 20.75.92.165:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/222.php"] [unique_id "aoSB_f2v-lWn9OzQT7UawAAAAJc"] [Tue Aug 18 13:02:05.563965 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:11808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vw.php"] [unique_id "aoSB_f2v-lWn9OzQT7UawQAAAJQ"] [Tue Aug 18 13:02:05.621259 2026] [security2:error] [pid 123784:tid 124017] [client 20.51.153.15:5101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/wp-title.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNwgAAAGM"] [Tue Aug 18 13:02:05.624990 2026] [security2:error] [pid 123784:tid 123977] [client 20.104.100.201:50024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/wp-load.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNwwAAADs"] [Tue Aug 18 13:02:05.632570 2026] [fcgid:warn] [pid 123784:tid 123965] (70014)End of file found: [client 199.45.154.61:48816] mod_fcgid: can't get data from http client [Tue Aug 18 13:02:05.644821 2026] [security2:error] [pid 139043:tid 139229] [client 68.221.73.131:62903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/yb.php"] [unique_id "aoSB_f2v-lWn9OzQT7UawwAAAL0"] [Tue Aug 18 13:02:05.660164 2026] [security2:error] [pid 139043:tid 139247] [client 20.226.112.14:39443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/rtx.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaxAAAAM8"] [Tue Aug 18 13:02:05.678083 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:29476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kn.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaxQAAALc"] [Tue Aug 18 13:02:05.686678 2026] [security2:error] [pid 123784:tid 123994] [client 20.29.77.16:40560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/456.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNxQAAAEw"] [Tue Aug 18 13:02:05.695379 2026] [security2:error] [pid 139043:tid 139189] [client 158.158.74.177:9233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/media-new.php"] [unique_id "aoSB_f2v-lWn9OzQT7UaxwAAAJU"] [Tue Aug 18 13:02:05.699532 2026] [security2:error] [pid 123784:tid 123848] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fg.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNxgAAAzs"] [Tue Aug 18 13:02:05.702551 2026] [security2:error] [pid 123784:tid 123952] [client 20.251.112.238:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/un.php"] [unique_id "aoSB_WwDnJBNj2tDbYYNxwAAACI"] [Tue Aug 18 13:02:05.712774 2026] [security2:error] [pid 139043:tid 139250] [client 20.151.109.219:14082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/51.php"] [unique_id "aoSB_f2v-lWn9OzQT7UayAAAANI"] [Tue Aug 18 13:02:05.741433 2026] [security2:error] [pid 123784:tid 123983] [client 20.226.112.14:22872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/end.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN0gAAAEE"] [Tue Aug 18 13:02:05.775701 2026] [authz_core:error] [pid 123784:tid 123891] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:05.775967 2026] [authz_core:error] [pid 123784:tid 123891] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:05.821427 2026] [security2:error] [pid 123784:tid 123968] [client 20.127.136.245:22707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-act.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN1AAAADI"] [Tue Aug 18 13:02:05.858572 2026] [security2:error] [pid 123784:tid 123930] [client 20.75.92.165:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/aa.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN2AAAAAw"] [Tue Aug 18 13:02:05.858741 2026] [security2:error] [pid 123784:tid 123929] [client 20.51.153.15:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/styles.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN2QAAAAs"] [Tue Aug 18 13:02:05.869716 2026] [security2:error] [pid 123784:tid 123816] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ve.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN2wAALBs"] [Tue Aug 18 13:02:05.886694 2026] [security2:error] [pid 139043:tid 139215] [client 20.226.112.14:22974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com"] [uri "/ae.php"] [unique_id "aoSB_f2v-lWn9OzQT7UazAAAAK8"] [Tue Aug 18 13:02:05.896065 2026] [security2:error] [pid 123784:tid 123959] [client 20.104.100.201:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/jj.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN3QAAACk"] [Tue Aug 18 13:02:05.897104 2026] [security2:error] [pid 139043:tid 139214] [client 172.213.243.2:19475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/a2.php"] [unique_id "aoSB_f2v-lWn9OzQT7UazQAAAK4"] [Tue Aug 18 13:02:05.934054 2026] [security2:error] [pid 123784:tid 124023] [client 20.116.17.175:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/output.php"] [unique_id "aoSB_WwDnJBNj2tDbYYN3gAAAGk"] [Tue Aug 18 13:02:05.946163 2026] [security2:error] [pid 139043:tid 139280] [client 68.155.154.236:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/dlvqo.php"] [unique_id "aoSB_f2v-lWn9OzQT7UazwAAAPA"] [Tue Aug 18 13:02:05.973233 2026] [authz_core:error] [pid 123784:tid 123902] [remote 57.141.22.47:42060] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:05.973671 2026] [authz_core:error] [pid 123784:tid 123902] [remote 57.141.22.47:42060] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:06.036827 2026] [security2:error] [pid 123784:tid 123908] [remote 162.214.205.212:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN8QAAQHc"] [Tue Aug 18 13:02:06.039857 2026] [security2:error] [pid 123784:tid 123998] [client 157.20.138.62:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN8gAAAFA"] [Tue Aug 18 13:02:06.040029 2026] [security2:error] [pid 123784:tid 123998] [client 157.20.138.62:65460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN8gAAAFA"] [Tue Aug 18 13:02:06.059623 2026] [security2:error] [pid 123784:tid 123863] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ia.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN9AAAAUo"] [Tue Aug 18 13:02:06.069827 2026] [security2:error] [pid 123784:tid 123924] [client 20.151.109.219:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ew.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN9QAAAAY"] [Tue Aug 18 13:02:06.080411 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:06.080871 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:06.096230 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:13667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/server.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua0gAAAIw"] [Tue Aug 18 13:02:06.103556 2026] [security2:error] [pid 139043:tid 139233] [client 213.35.127.232:63280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua0wAAAME"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:06.120149 2026] [security2:error] [pid 139043:tid 139266] [client 20.79.204.6:12259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/wp-themes.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua1AAAAOI"] [Tue Aug 18 13:02:06.161767 2026] [security2:error] [pid 123784:tid 124006] [client 20.79.204.6:12110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-themes.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN_gAAAFg"] [Tue Aug 18 13:02:06.164967 2026] [security2:error] [pid 123784:tid 123958] [client 20.65.98.162:23009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/bless6.php"] [unique_id "aoSB_mwDnJBNj2tDbYYN_wAAACg"] [Tue Aug 18 13:02:06.172957 2026] [security2:error] [pid 139043:tid 139194] [client 20.104.100.201:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/img.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua1wAAAJo"] [Tue Aug 18 13:02:06.183439 2026] [security2:error] [pid 123784:tid 123855] [remote 62.60.130.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dtbbrasil.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOAwAAK0I"] [Tue Aug 18 13:02:06.208677 2026] [security2:error] [pid 123784:tid 124043] [client 20.226.56.190:3008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/sysinfo.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOBQAAAH0"] [Tue Aug 18 13:02:06.223988 2026] [security2:error] [pid 139043:tid 139173] [client 20.29.77.16:33593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/SMTP.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua2gAAAIU"] [Tue Aug 18 13:02:06.227192 2026] [security2:error] [pid 123784:tid 123789] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kn.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOCQAAJgA"] [Tue Aug 18 13:02:06.243620 2026] [security2:error] [pid 139043:tid 139226] [client 20.75.92.165:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/abcd.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua3AAAALo"] [Tue Aug 18 13:02:06.265888 2026] [security2:error] [pid 123784:tid 123985] [client 68.155.154.236:64155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/nwwha.php"] [unique_id "aoSB_mwDnJBNj2tDbYYODwAAAEM"] [Tue Aug 18 13:02:06.277367 2026] [security2:error] [pid 123784:tid 124039] [client 172.202.39.151:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/rip.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOEAAAAHk"] [Tue Aug 18 13:02:06.296173 2026] [security2:error] [pid 123784:tid 123975] [client 20.127.136.245:16892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOEQAAADk"] [Tue Aug 18 13:02:06.310508 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:14059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gc.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOEgAAABg"] [Tue Aug 18 13:02:06.332416 2026] [security2:error] [pid 123784:tid 123920] [client 172.213.243.2:24337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/app.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOEwAAAAI"] [Tue Aug 18 13:02:06.352906 2026] [security2:error] [pid 139043:tid 139201] [client 20.251.112.238:22398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/autogooey.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua4QAAAKE"] [Tue Aug 18 13:02:06.356132 2026] [security2:error] [pid 139043:tid 139211] [client 20.151.109.219:60891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pqr.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua4gAAAKs"] [Tue Aug 18 13:02:06.371684 2026] [security2:error] [pid 123784:tid 123976] [client 20.51.153.15:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/xinfo.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOGAAAADo"] [Tue Aug 18 13:02:06.378951 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:06.379227 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:06.439360 2026] [security2:error] [pid 139043:tid 139175] [client 158.158.74.177:9217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua5gAAAIc"] [Tue Aug 18 13:02:06.449361 2026] [security2:error] [pid 123784:tid 123945] [client 20.104.100.201:49713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slopes.adv.br"] [uri "/we.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOIgAAABs"] [Tue Aug 18 13:02:06.452352 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wm.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOIwAAIB0"] [Tue Aug 18 13:02:06.522613 2026] [security2:error] [pid 123784:tid 124041] [client 103.184.169.37:43289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOZAAAAHs"] [Tue Aug 18 13:02:06.522732 2026] [security2:error] [pid 123784:tid 124041] [client 103.184.169.37:43289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOZAAAAHs"] [Tue Aug 18 13:02:06.635143 2026] [security2:error] [pid 123784:tid 123940] [client 20.51.153.15:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/sym.php"] [unique_id "aoSB_mwDnJBNj2tDbYYObwAAABY"] [Tue Aug 18 13:02:06.658202 2026] [security2:error] [pid 123784:tid 124034] [client 135.225.78.186:60040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/wpxml.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOfQAAAHQ"] [Tue Aug 18 13:02:06.665709 2026] [security2:error] [pid 139043:tid 139174] [client 20.75.92.165:4225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/admin.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua7QAAAIY"] [Tue Aug 18 13:02:06.683453 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:06.683906 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:06.699896 2026] [security2:error] [pid 139043:tid 139297] [client 132.196.30.78:26091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/images/class-config.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua7wAAAQE"] [Tue Aug 18 13:02:06.701991 2026] [security2:error] [pid 123784:tid 123855] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ac.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOgQAAR0I"] [Tue Aug 18 13:02:06.722731 2026] [security2:error] [pid 123784:tid 123925] [client 20.151.109.219:39342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/an.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOiQAAAAc"] [Tue Aug 18 13:02:06.733659 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hotelvipempresas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua8AAAAMk"] [Tue Aug 18 13:02:06.766980 2026] [security2:error] [pid 139043:tid 139193] [client 20.79.204.6:11703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/xmlrpc.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua8wAAAJk"] [Tue Aug 18 13:02:06.778214 2026] [security2:error] [pid 139043:tid 139209] [client 20.29.77.16:8755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/vbseo.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua9AAAAKk"] [Tue Aug 18 13:02:06.873394 2026] [security2:error] [pid 139043:tid 139270] [client 158.23.17.4:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lj.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua9wAAAOY"] [Tue Aug 18 13:02:06.888600 2026] [security2:error] [pid 139043:tid 139271] [client 20.251.112.238:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sty.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua-QAAAOc"] [Tue Aug 18 13:02:06.893390 2026] [security2:error] [pid 139043:tid 139061] [remote 62.60.130.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dtbbrasil.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSB_v2v-lWn9OzQT7Ua-gAA4BE"] [Tue Aug 18 13:02:06.895912 2026] [security2:error] [pid 123784:tid 124008] [client 158.23.17.4:7228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/uq.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOmwAAAFo"] [Tue Aug 18 13:02:06.902505 2026] [security2:error] [pid 123784:tid 123991] [client 20.51.153.15:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferreirafreitas.com.br"] [uri "/ye.php"] [unique_id "aoSB_mwDnJBNj2tDbYYOnAAAAEk"] [Tue Aug 18 13:02:06.965664 2026] [autoindex:error] [pid 139043:tid 139231] [client 172.213.243.2:11473] AH01276: Cannot serve directory /home2/onlidesp/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:07.015951 2026] [security2:error] [pid 123784:tid 123983] [client 158.23.17.4:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wm.php"] [unique_id "aoSB_2wDnJBNj2tDbYYOpgAAAEE"] [Tue Aug 18 13:02:07.018691 2026] [security2:error] [pid 139043:tid 139289] [client 68.155.154.236:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/pkmoj.php"] [unique_id "aoSB__2v-lWn9OzQT7UbAQAAAPk"] [Tue Aug 18 13:02:07.019265 2026] [security2:error] [pid 123784:tid 123874] [remote 51.161.37.165:57454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "thautomoveislimeira.com.br"] [uri "/"] [unique_id "aoSB_2wDnJBNj2tDbYYOqAAAIlU"] [Tue Aug 18 13:02:07.019427 2026] [security2:error] [pid 123784:tid 123952] [client 51.161.37.165:57454] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thautomoveislimeira.com.br"] [uri "/"] [unique_id "aoSB_2wDnJBNj2tDbYYOqAAAIlU"] [Tue Aug 18 13:02:07.033609 2026] [security2:error] [pid 139043:tid 139192] [client 20.151.109.219:39331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sy.php"] [unique_id "aoSB__2v-lWn9OzQT7UbAgAAAJg"] [Tue Aug 18 13:02:07.045921 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:38304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zy.php"] [unique_id "aoSB__2v-lWn9OzQT7UbAwAAAKA"] [Tue Aug 18 13:02:07.116106 2026] [security2:error] [pid 139043:tid 139259] [client 213.35.127.232:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSB__2v-lWn9OzQT7UbCwAAANs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:07.121667 2026] [security2:error] [pid 123784:tid 124007] [client 5.31.227.224:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_2wDnJBNj2tDbYYOsgAAAFk"] [Tue Aug 18 13:02:07.121795 2026] [security2:error] [pid 123784:tid 124007] [client 5.31.227.224:59034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSB_2wDnJBNj2tDbYYOsgAAAFk"] [Tue Aug 18 13:02:07.140019 2026] [security2:error] [pid 123784:tid 123921] [client 158.158.74.177:22857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSB_2wDnJBNj2tDbYYOtwAAAAM"] [Tue Aug 18 13:02:07.281181 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:07.281451 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:07.322124 2026] [security2:error] [pid 123784:tid 123836] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/yz.php"] [unique_id "aoSB_2wDnJBNj2tDbYYOxQAANS8"] [Tue Aug 18 13:02:07.329261 2026] [security2:error] [pid 123784:tid 123995] [client 114.119.136.113:24261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "empresasunai.com.br"] [uri "/guia"] [unique_id "aoSB_2wDnJBNj2tDbYYOxgAAAE0"], referer: http://empresasunai.com.br/guia?categoria=25-AUTOMoVEIS [Tue Aug 18 13:02:07.345871 2026] [security2:error] [pid 123784:tid 123812] [remote 8.229.129.72:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "whm.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSB_2wDnJBNj2tDbYYOyAAAJBc"] [Tue Aug 18 13:02:07.371531 2026] [security2:error] [pid 139043:tid 139256] [client 20.29.77.16:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/sysinfo.php"] [unique_id "aoSB__2v-lWn9OzQT7UbFwAAANg"] [Tue Aug 18 13:02:07.372476 2026] [security2:error] [pid 139043:tid 139210] [client 20.251.112.238:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wio.php"] [unique_id "aoSB__2v-lWn9OzQT7UbGAAAAKo"] [Tue Aug 18 13:02:07.373834 2026] [security2:error] [pid 139043:tid 139207] [client 172.213.243.2:11473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSB__2v-lWn9OzQT7UbGQAAAKc"] [Tue Aug 18 13:02:07.391022 2026] [security2:error] [pid 139043:tid 139202] [client 20.151.109.219:39345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/57.php"] [unique_id "aoSB__2v-lWn9OzQT7UbGgAAAKI"] [Tue Aug 18 13:02:07.400545 2026] [security2:error] [pid 139043:tid 139278] [client 158.23.17.4:14026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/32.php"] [unique_id "aoSB__2v-lWn9OzQT7UbGwAAAO4"] [Tue Aug 18 13:02:07.402049 2026] [security2:error] [pid 139043:tid 139205] [client 68.155.154.236:63583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/opsqt.php"] [unique_id "aoSB__2v-lWn9OzQT7UbHAAAAKU"] [Tue Aug 18 13:02:07.408025 2026] [security2:error] [pid 139043:tid 139197] [client 20.75.92.165:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/adminfuns.php"] [unique_id "aoSB__2v-lWn9OzQT7UbHgAAAJ0"] [Tue Aug 18 13:02:07.413978 2026] [security2:error] [pid 139043:tid 139216] [client 20.116.17.175:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/tiny2.php"] [unique_id "aoSB__2v-lWn9OzQT7UbHwAAALA"] [Tue Aug 18 13:02:07.576649 2026] [security2:error] [pid 139043:tid 139243] [client 172.202.39.151:4718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSB__2v-lWn9OzQT7UbIwAAAMs"] [Tue Aug 18 13:02:07.577422 2026] [security2:error] [pid 123784:tid 123942] [client 172.202.39.151:44537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/ok.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO3gAAABg"] [Tue Aug 18 13:02:07.582905 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:07.583162 2026] [authz_core:error] [pid 123784:tid 123847] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:07.597527 2026] [security2:error] [pid 123784:tid 123828] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.env"] [unique_id "aoSB_2wDnJBNj2tDbYYO3wAAOCc"] [Tue Aug 18 13:02:07.675109 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.98.162:29006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/special.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO5AAAAH4"] [Tue Aug 18 13:02:07.681687 2026] [security2:error] [pid 139043:tid 139230] [client 20.151.109.219:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ah.php"] [unique_id "aoSB__2v-lWn9OzQT7UbJwAAAL4"] [Tue Aug 18 13:02:07.693687 2026] [security2:error] [pid 139043:tid 139255] [client 20.226.56.190:47161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/ppinfo.php"] [unique_id "aoSB__2v-lWn9OzQT7UbKQAAANc"] [Tue Aug 18 13:02:07.697693 2026] [security2:error] [pid 139043:tid 139176] [client 20.75.92.165:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/akc.php"] [unique_id "aoSB__2v-lWn9OzQT7UbKgAAAIg"] [Tue Aug 18 13:02:07.772630 2026] [security2:error] [pid 123784:tid 124013] [client 132.196.30.78:21264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/alfa.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO7gAAAF8"] [Tue Aug 18 13:02:07.779836 2026] [security2:error] [pid 123784:tid 123916] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kj.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO8AAAe38"] [Tue Aug 18 13:02:07.784511 2026] [security2:error] [pid 139043:tid 139195] [client 158.23.17.4:25352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/73.php"] [unique_id "aoSB__2v-lWn9OzQT7UbLQAAAJs"] [Tue Aug 18 13:02:07.801620 2026] [security2:error] [pid 123784:tid 123990] [client 172.213.243.2:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/cxc.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO8QAAAEg"] [Tue Aug 18 13:02:07.812795 2026] [security2:error] [pid 123784:tid 123951] [client 68.155.154.236:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/kopyw.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO8gAAACE"] [Tue Aug 18 13:02:07.814139 2026] [security2:error] [pid 139043:tid 139293] [client 20.79.204.6:10726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/gecko-new.php"] [unique_id "aoSB__2v-lWn9OzQT7UbLwAAAP0"] [Tue Aug 18 13:02:07.842247 2026] [security2:error] [pid 123784:tid 123940] [client 20.29.77.16:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/ppinfo.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO9QAAABY"] [Tue Aug 18 13:02:07.866868 2026] [security2:error] [pid 139043:tid 139267] [client 172.202.39.151:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/xmlrpc.php"] [unique_id "aoSB__2v-lWn9OzQT7UbMAAAAOM"] [Tue Aug 18 13:02:07.883102 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:07.883370 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:07.888084 2026] [security2:error] [pid 123784:tid 123989] [client 20.203.183.135:24376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/bajah.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO_AAAAEc"] [Tue Aug 18 13:02:07.899386 2026] [security2:error] [pid 123784:tid 123910] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.env.backup"] [unique_id "aoSB_2wDnJBNj2tDbYYO_QAACXk"] [Tue Aug 18 13:02:07.902692 2026] [security2:error] [pid 123784:tid 123797] [remote 8.229.129.72:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "whm.outlimit.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSB_2wDnJBNj2tDbYYO_gAAUwg"] [Tue Aug 18 13:02:07.920709 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kh.php"] [unique_id "aoSB_2wDnJBNj2tDbYYO_wAAAAc"] [Tue Aug 18 13:02:07.929449 2026] [security2:error] [pid 139043:tid 139260] [client 20.127.136.245:16877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSB__2v-lWn9OzQT7UbNgAAANw"] [Tue Aug 18 13:02:07.939513 2026] [security2:error] [pid 139043:tid 139257] [client 158.158.74.177:9997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSB__2v-lWn9OzQT7UbNwAAANk"] [Tue Aug 18 13:02:07.947057 2026] [security2:error] [pid 123784:tid 123863] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vg.php"] [unique_id "aoSB_2wDnJBNj2tDbYYPAgAAV0o"] [Tue Aug 18 13:02:07.967745 2026] [security2:error] [pid 139043:tid 139246] [client 20.251.112.238:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/1061.php"] [unique_id "aoSB__2v-lWn9OzQT7UbOAAAAM4"] [Tue Aug 18 13:02:08.010755 2026] [security2:error] [pid 123784:tid 123799] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.env.old"] [unique_id "aoSCAGwDnJBNj2tDbYYPBgAAIgo"] [Tue Aug 18 13:02:08.023422 2026] [security2:error] [pid 123784:tid 124021] [client 20.75.92.165:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/buy.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPCgAAAGc"] [Tue Aug 18 13:02:08.126129 2026] [security2:error] [pid 139043:tid 139183] [client 20.151.109.219:39300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vw.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbPAAAAI8"] [Tue Aug 18 13:02:08.129765 2026] [security2:error] [pid 139043:tid 139175] [client 213.35.127.232:63754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbPQAAAIc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:08.143939 2026] [security2:error] [pid 123784:tid 123887] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sm.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPDwAAbmI"] [Tue Aug 18 13:02:08.169691 2026] [security2:error] [pid 123784:tid 123832] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/api/.env"] [unique_id "aoSCAGwDnJBNj2tDbYYPEgAATis"] [Tue Aug 18 13:02:08.219115 2026] [security2:error] [pid 139043:tid 139270] [client 172.213.243.2:14558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCAP2v-lWn9OzQT7UbRAAAAOY"] [Tue Aug 18 13:02:08.237114 2026] [security2:error] [pid 139043:tid 139264] [client 135.225.78.186:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/file1221.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbRgAAAOA"] [Tue Aug 18 13:02:08.242645 2026] [security2:error] [pid 139043:tid 139219] [client 68.221.73.131:29205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/vc.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbRwAAALM"] [Tue Aug 18 13:02:08.334325 2026] [security2:error] [pid 123784:tid 123988] [client 172.202.39.151:4673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-mail.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPHgAAAEY"] [Tue Aug 18 13:02:08.376222 2026] [security2:error] [pid 139043:tid 139184] [client 20.29.77.16:16523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/globals.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbSgAAAJA"] [Tue Aug 18 13:02:08.400691 2026] [security2:error] [pid 123784:tid 123954] [client 20.118.133.132:7826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPIQAAACQ"] [Tue Aug 18 13:02:08.401179 2026] [security2:error] [pid 139043:tid 139226] [client 223.185.37.47:23479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbTQAAALo"] [Tue Aug 18 13:02:08.401296 2026] [security2:error] [pid 139043:tid 139226] [client 223.185.37.47:23479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbTQAAALo"] [Tue Aug 18 13:02:08.403925 2026] [security2:error] [pid 139043:tid 139269] [client 20.116.17.175:22958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wpxml.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbTwAAAOU"] [Tue Aug 18 13:02:08.409241 2026] [authz_core:error] [pid 139043:tid 139089] [remote 57.141.22.35:56604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:08.409513 2026] [authz_core:error] [pid 139043:tid 139089] [remote 57.141.22.35:56604] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:08.457182 2026] [security2:error] [pid 123784:tid 123867] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.env.bak"] [unique_id "aoSCAGwDnJBNj2tDbYYPJwAAHk4"] [Tue Aug 18 13:02:08.472688 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:29457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ac.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPKgAAACc"] [Tue Aug 18 13:02:08.486332 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:08.486590 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:08.504136 2026] [security2:error] [pid 123784:tid 123942] [client 132.196.30.78:10434] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.zanseg.com.br"] [uri "/1.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPLgAAABg"] [Tue Aug 18 13:02:08.504256 2026] [security2:error] [pid 123784:tid 123942] [client 132.196.30.78:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/1.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPLgAAABg"] [Tue Aug 18 13:02:08.507088 2026] [security2:error] [pid 139043:tid 139288] [client 20.251.112.238:59482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gec.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbUQAAAPg"] [Tue Aug 18 13:02:08.523943 2026] [security2:error] [pid 123784:tid 123973] [client 20.151.109.219:39310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lj.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPLwAAADc"] [Tue Aug 18 13:02:08.539515 2026] [security2:error] [pid 123784:tid 123976] [client 20.75.92.165:4285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/cong.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPMAAAADo"] [Tue Aug 18 13:02:08.550398 2026] [security2:error] [pid 123784:tid 123913] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/backend/.env"] [unique_id "aoSCAGwDnJBNj2tDbYYPMQAAXnw"] [Tue Aug 18 13:02:08.576196 2026] [security2:error] [pid 123784:tid 123818] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/config/.env"] [unique_id "aoSCAGwDnJBNj2tDbYYPMgAANh0"] [Tue Aug 18 13:02:08.588194 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/zznmg.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPNgAAAHA"] [Tue Aug 18 13:02:08.622802 2026] [security2:error] [pid 139043:tid 139200] [client 158.158.74.177:9989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbVAAAAKA"] [Tue Aug 18 13:02:08.638835 2026] [security2:error] [pid 123784:tid 124038] [client 172.213.243.2:11461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/0.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPPAAAAHg"] [Tue Aug 18 13:02:08.678751 2026] [security2:error] [pid 123784:tid 123854] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/id_rsa"] [unique_id "aoSCAGwDnJBNj2tDbYYPPwAAfEE"] [Tue Aug 18 13:02:08.688743 2026] [security2:error] [pid 123784:tid 123831] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/28.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPQAAAISo"] [Tue Aug 18 13:02:08.705074 2026] [security2:error] [pid 123784:tid 123798] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/id_dsa"] [unique_id "aoSCAGwDnJBNj2tDbYYPQwAAfAk"] [Tue Aug 18 13:02:08.725660 2026] [security2:error] [pid 139043:tid 139218] [client 158.23.17.4:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jb.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbVwAAALI"] [Tue Aug 18 13:02:08.761748 2026] [security2:error] [pid 139043:tid 139217] [client 20.29.77.16:47359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/yindu.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbWAAAALE"] [Tue Aug 18 13:02:08.789237 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:08.789517 2026] [authz_core:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:08.817665 2026] [security2:error] [pid 123784:tid 124002] [client 158.23.17.4:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ib.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPTQAAAFQ"] [Tue Aug 18 13:02:08.818540 2026] [security2:error] [pid 139043:tid 139223] [client 20.75.92.165:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbWgAAALc"] [Tue Aug 18 13:02:08.849690 2026] [security2:error] [pid 123784:tid 123875] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/m.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPUgAAU1Y"] [Tue Aug 18 13:02:08.860354 2026] [security2:error] [pid 139043:tid 139189] [client 20.151.109.219:14269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kh.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbXQAAAJU"] [Tue Aug 18 13:02:08.953948 2026] [security2:error] [pid 139043:tid 139207] [client 158.23.17.4:33424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/q.php"] [unique_id "aoSCAP2v-lWn9OzQT7UbXwAAAKc"] [Tue Aug 18 13:02:08.954510 2026] [security2:error] [pid 123784:tid 123977] [client 172.202.39.151:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/o.php"] [unique_id "aoSCAGwDnJBNj2tDbYYPWgAAADs"] [Tue Aug 18 13:02:09.032776 2026] [security2:error] [pid 123784:tid 123949] [client 20.251.112.238:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/scx.php7"] [unique_id "aoSCAWwDnJBNj2tDbYYPXwAAAB8"] [Tue Aug 18 13:02:09.034062 2026] [security2:error] [pid 123784:tid 123914] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nl.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPYAAAWn0"] [Tue Aug 18 13:02:09.079062 2026] [security2:error] [pid 139043:tid 139278] [client 172.213.243.2:11493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/dom.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbYwAAAO4"] [Tue Aug 18 13:02:09.091569 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:09.092020 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:09.106261 2026] [security2:error] [pid 123784:tid 123925] [client 20.79.204.6:10400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/NewFile.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPZwAAAAc"] [Tue Aug 18 13:02:09.155206 2026] [security2:error] [pid 123784:tid 124000] [client 213.35.127.232:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPcgAAAFI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:09.162256 2026] [security2:error] [pid 123784:tid 124007] [client 20.75.92.165:2025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/db.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPcwAAAFk"] [Tue Aug 18 13:02:09.188392 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jb.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbZwAAAIw"] [Tue Aug 18 13:02:09.216110 2026] [security2:error] [pid 123784:tid 123930] [client 172.202.39.151:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/moon.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPeQAAAAw"] [Tue Aug 18 13:02:09.242267 2026] [security2:error] [pid 123784:tid 124028] [client 20.29.77.16:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/sxx.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPewAAAG4"] [Tue Aug 18 13:02:09.300019 2026] [security2:error] [pid 139043:tid 139272] [client 68.155.154.236:55459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbagAAAOg"] [Tue Aug 18 13:02:09.326526 2026] [security2:error] [pid 123784:tid 123864] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/phpinfo.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPgQAAfEs"] [Tue Aug 18 13:02:09.328210 2026] [security2:error] [pid 139043:tid 139208] [client 172.202.39.151:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/bb.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbawAAAKg"] [Tue Aug 18 13:02:09.330960 2026] [security2:error] [pid 139043:tid 139221] [client 20.65.98.162:23021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/fz.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbbAAAALU"] [Tue Aug 18 13:02:09.351122 2026] [security2:error] [pid 139043:tid 139214] [client 158.158.74.177:22881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/ebs.php7"] [unique_id "aoSCAf2v-lWn9OzQT7UbbgAAAK4"] [Tue Aug 18 13:02:09.354668 2026] [security2:error] [pid 123784:tid 123816] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/key.pem"] [unique_id "aoSCAWwDnJBNj2tDbYYPggAAfBs"] [Tue Aug 18 13:02:09.368038 2026] [security2:error] [pid 123784:tid 123916] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/info.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPgwAAfH8"] [Tue Aug 18 13:02:09.394487 2026] [security2:error] [pid 139043:tid 139255] [client 20.226.56.190:23760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/globals.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbcQAAANc"] [Tue Aug 18 13:02:09.396866 2026] [security2:error] [pid 123784:tid 124011] [client 20.127.136.245:14520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPhwAAAF0"] [Tue Aug 18 13:02:09.406858 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:11003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/yz.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbcgAAAQM"] [Tue Aug 18 13:02:09.474918 2026] [security2:error] [pid 123784:tid 123873] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/privatekey.key"] [unique_id "aoSCAWwDnJBNj2tDbYYPiQAAfFQ"] [Tue Aug 18 13:02:09.482483 2026] [security2:error] [pid 139043:tid 139257] [client 20.75.92.165:1950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/dropdown.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbdQAAANk"] [Tue Aug 18 13:02:09.494123 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/do.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbdgAAAJI"] [Tue Aug 18 13:02:09.497229 2026] [security2:error] [pid 139043:tid 139222] [client 20.116.17.175:22998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbdwAAALY"] [Tue Aug 18 13:02:09.516179 2026] [security2:error] [pid 139043:tid 139236] [client 20.251.112.238:26679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbeAAAAMQ"] [Tue Aug 18 13:02:09.540468 2026] [security2:error] [pid 139043:tid 139199] [client 158.23.17.4:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xm.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbegAAAJ8"] [Tue Aug 18 13:02:09.548606 2026] [security2:error] [pid 123784:tid 123998] [client 172.182.200.96:15735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPkQAAAFA"] [Tue Aug 18 13:02:09.559258 2026] [security2:error] [pid 123784:tid 124045] [client 172.213.243.2:14530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/bb.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPkwAAAH8"] [Tue Aug 18 13:02:09.584520 2026] [security2:error] [pid 123784:tid 123982] [client 37.40.227.74:56993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPlAAAAEA"] [Tue Aug 18 13:02:09.584646 2026] [security2:error] [pid 123784:tid 123982] [client 37.40.227.74:56993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPlAAAAEA"] [Tue Aug 18 13:02:09.615439 2026] [security2:error] [pid 123784:tid 123880] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/68.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPlwAAE1s"] [Tue Aug 18 13:02:09.666106 2026] [security2:error] [pid 123784:tid 123973] [client 20.29.77.16:62911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/settings.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPnwAAADc"] [Tue Aug 18 13:02:09.691701 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:09.692121 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:09.709759 2026] [security2:error] [pid 123784:tid 124044] [client 172.202.39.151:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPpAAAAH4"] [Tue Aug 18 13:02:09.755709 2026] [security2:error] [pid 123784:tid 124038] [client 132.196.30.78:16304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/222.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPqAAAAHg"] [Tue Aug 18 13:02:09.787354 2026] [security2:error] [pid 123784:tid 123881] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jl.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPrwAAdFw"] [Tue Aug 18 13:02:09.828097 2026] [security2:error] [pid 123784:tid 123983] [client 208.74.105.168:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.105.74.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "invictambiental.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPngAAAEE"] [Tue Aug 18 13:02:09.828250 2026] [security2:error] [pid 123784:tid 123983] [client 208.74.105.168:54418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "invictambiental.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPngAAAEE"] [Tue Aug 18 13:02:09.837612 2026] [security2:error] [pid 139043:tid 139191] [client 20.75.92.165:1942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/file.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbggAAAJc"] [Tue Aug 18 13:02:09.852878 2026] [security2:error] [pid 123784:tid 123941] [client 20.151.109.219:37307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/yw.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPtAAAABc"] [Tue Aug 18 13:02:09.876324 2026] [security2:error] [pid 123784:tid 123896] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.github/.env"] [unique_id "aoSCAWwDnJBNj2tDbYYPtQAADWs"] [Tue Aug 18 13:02:09.888092 2026] [security2:error] [pid 123784:tid 123936] [client 68.155.154.236:64138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPtwAAABI"] [Tue Aug 18 13:02:09.910934 2026] [security2:error] [pid 123784:tid 123814] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/pi.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPvQAAMhk"] [Tue Aug 18 13:02:09.949362 2026] [security2:error] [pid 139043:tid 139230] [client 197.184.64.235:41967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbiAAAAL4"] [Tue Aug 18 13:02:09.949513 2026] [security2:error] [pid 139043:tid 139230] [client 197.184.64.235:41967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbiAAAAL4"] [Tue Aug 18 13:02:09.952901 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/tq.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPvgAADGg"] [Tue Aug 18 13:02:09.955768 2026] [security2:error] [pid 139043:tid 139218] [client 20.251.112.238:20218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp5.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbiQAAALI"] [Tue Aug 18 13:02:09.976805 2026] [security2:error] [pid 123784:tid 123986] [client 172.213.243.2:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ok.php"] [unique_id "aoSCAWwDnJBNj2tDbYYPwwAAAEQ"] [Tue Aug 18 13:02:09.989860 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:09.990126 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:09.994537 2026] [security2:error] [pid 139043:tid 139277] [client 158.158.74.177:10047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbjAAAAO0"] [Tue Aug 18 13:02:09.998119 2026] [security2:error] [pid 139043:tid 139217] [client 20.116.17.175:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ccou.php"] [unique_id "aoSCAf2v-lWn9OzQT7UbjQAAALE"] [Tue Aug 18 13:02:10.046259 2026] [security2:error] [pid 123784:tid 124024] [client 172.202.39.151:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoctam.ctamcursos.com.br"] [uri "/item.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP0AAAAGo"] [Tue Aug 18 13:02:10.058397 2026] [security2:error] [pid 123784:tid 124040] [client 158.23.17.4:9405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kj.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP0gAAAHo"] [Tue Aug 18 13:02:10.058891 2026] [security2:error] [pid 139043:tid 139211] [client 196.12.128.158:58071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbjwAAAKs"] [Tue Aug 18 13:02:10.058978 2026] [security2:error] [pid 139043:tid 139211] [client 196.12.128.158:58071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbjwAAAKs"] [Tue Aug 18 13:02:10.074112 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:25394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zy.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbmQAAAKM"] [Tue Aug 18 13:02:10.081446 2026] [security2:error] [pid 139043:tid 139254] [client 172.182.200.96:15702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbmgAAANY"] [Tue Aug 18 13:02:10.114609 2026] [security2:error] [pid 123784:tid 123995] [client 168.62.48.100:5537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP1QAAAE0"] [Tue Aug 18 13:02:10.128191 2026] [security2:error] [pid 123784:tid 123999] [client 20.29.77.16:21766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/spip.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP1gAAAFE"] [Tue Aug 18 13:02:10.135159 2026] [security2:error] [pid 123784:tid 124025] [client 20.38.3.247:39589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/chosen.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP1wAAAGs"] [Tue Aug 18 13:02:10.171665 2026] [security2:error] [pid 139043:tid 139228] [client 213.35.127.232:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbnAAAALw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:10.195288 2026] [security2:error] [pid 139043:tid 139247] [client 158.23.17.4:55199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/do.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbnQAAAM8"] [Tue Aug 18 13:02:10.199520 2026] [security2:error] [pid 123784:tid 123884] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/test.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP3gAAf18"] [Tue Aug 18 13:02:10.203278 2026] [security2:error] [pid 123784:tid 123827] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP3wAAfCY"] [Tue Aug 18 13:02:10.219920 2026] [security2:error] [pid 139043:tid 139256] [client 20.151.109.219:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/qh.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbngAAANg"] [Tue Aug 18 13:02:10.265954 2026] [security2:error] [pid 139043:tid 139265] [client 132.196.30.78:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/asasx.php"] [unique_id "aoSCAv2v-lWn9OzQT7UboAAAAOE"] [Tue Aug 18 13:02:10.278478 2026] [security2:error] [pid 123784:tid 123948] [client 20.75.92.165:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/goods.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP6AAAAB4"] [Tue Aug 18 13:02:10.291822 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:10.292282 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:10.325432 2026] [security2:error] [pid 123784:tid 124010] [client 20.79.204.6:10745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP8wAAAFw"] [Tue Aug 18 13:02:10.339918 2026] [security2:error] [pid 139043:tid 139215] [client 20.127.136.245:7782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSCAv2v-lWn9OzQT7UboQAAAK8"] [Tue Aug 18 13:02:10.403423 2026] [security2:error] [pid 123784:tid 123803] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/un.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP-QAAOg4"] [Tue Aug 18 13:02:10.421239 2026] [security2:error] [pid 139043:tid 139194] [client 172.213.243.2:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp9.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbpwAAAJo"] [Tue Aug 18 13:02:10.422025 2026] [security2:error] [pid 139043:tid 139180] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbpAAAjCE"] [Tue Aug 18 13:02:10.446490 2026] [security2:error] [pid 139043:tid 139221] [client 20.251.112.238:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/a2.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbqQAAALU"] [Tue Aug 18 13:02:10.470349 2026] [security2:error] [pid 123784:tid 123972] [client 20.203.183.135:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/domvf.php"] [unique_id "aoSCAmwDnJBNj2tDbYYP_wAAADY"] [Tue Aug 18 13:02:10.533093 2026] [security2:error] [pid 123784:tid 123905] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.openclaw/.env"] [unique_id "aoSCAmwDnJBNj2tDbYYQBQAALHQ"] [Tue Aug 18 13:02:10.552552 2026] [authz_core:error] [pid 123784:tid 123872] [remote 34.26.175.209:52038] AH01630: client denied by server configuration: /var/www/html/.htpasswd [Tue Aug 18 13:02:10.566385 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/evil.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQCQAAET4"] [Tue Aug 18 13:02:10.578149 2026] [security2:error] [pid 123784:tid 124013] [client 158.23.17.4:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xf.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQCgAAAF8"] [Tue Aug 18 13:02:10.584329 2026] [security2:error] [pid 123784:tid 123800] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/i.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQDAAALAs"] [Tue Aug 18 13:02:10.590904 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:10.591159 2026] [authz_core:error] [pid 123784:tid 123888] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:10.595699 2026] [security2:error] [pid 139043:tid 139293] [client 172.182.200.96:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/weozh.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbrgAAAP0"] [Tue Aug 18 13:02:10.598450 2026] [security2:error] [pid 139043:tid 139295] [client 68.221.73.131:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/pema.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbrwAAAP8"] [Tue Aug 18 13:02:10.644849 2026] [security2:error] [pid 139043:tid 139201] [client 20.75.92.165:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbsgAAAKE"] [Tue Aug 18 13:02:10.657067 2026] [security2:error] [pid 139043:tid 139214] [client 158.158.74.177:10000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbswAAAK4"] [Tue Aug 18 13:02:10.667665 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/q.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQDwAAAEg"] [Tue Aug 18 13:02:10.675624 2026] [security2:error] [pid 139043:tid 139181] [client 172.202.39.151:4272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbtAAAAI0"] [Tue Aug 18 13:02:10.681906 2026] [security2:error] [pid 139043:tid 139198] [client 20.29.77.16:16524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/search.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbtQAAAJ4"] [Tue Aug 18 13:02:10.752390 2026] [access_compat:error] [pid 123784:tid 123906] [remote 34.26.175.209:52038] AH01797: client denied by server configuration: /var/www/html/server-status [Tue Aug 18 13:02:10.759123 2026] [security2:error] [pid 123784:tid 124009] [client 20.151.109.219:39337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/r.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQGgAAAFs"] [Tue Aug 18 13:02:10.799582 2026] [security2:error] [pid 123784:tid 124002] [client 68.155.154.236:55468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/oivcl.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQHQAAAFQ"] [Tue Aug 18 13:02:10.815646 2026] [security2:error] [pid 123784:tid 123981] [client 132.196.30.78:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/filemanager.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQIAAAAD8"] [Tue Aug 18 13:02:10.832521 2026] [security2:error] [pid 139043:tid 139246] [client 20.116.17.175:23031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/crgio.php"] [unique_id "aoSCAv2v-lWn9OzQT7UbuAAAAM4"] [Tue Aug 18 13:02:10.855400 2026] [security2:error] [pid 123784:tid 123839] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/server-info"] [unique_id "aoSCAmwDnJBNj2tDbYYQIgAALDI"] [Tue Aug 18 13:02:10.878055 2026] [security2:error] [pid 123784:tid 123945] [client 20.65.98.162:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/clque.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQJQAAABs"] [Tue Aug 18 13:02:10.900410 2026] [security2:error] [pid 123784:tid 124001] [client 172.213.243.2:11787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws59.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQJwAAAFM"] [Tue Aug 18 13:02:10.918856 2026] [security2:error] [pid 123784:tid 123931] [client 172.202.39.151:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/cache.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQKAAAAA0"] [Tue Aug 18 13:02:10.953143 2026] [security2:error] [pid 123784:tid 123994] [client 20.127.136.245:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQLQAAAEw"] [Tue Aug 18 13:02:10.962818 2026] [security2:error] [pid 123784:tid 124008] [client 20.251.112.238:33943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/app.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQLgAAAFo"] [Tue Aug 18 13:02:10.990040 2026] [security2:error] [pid 123784:tid 123963] [client 20.75.92.165:4274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/htaccess.php"] [unique_id "aoSCAmwDnJBNj2tDbYYQMwAAAC0"] [Tue Aug 18 13:02:11.046911 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xf.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQOAAAAEU"] [Tue Aug 18 13:02:11.067964 2026] [security2:error] [pid 123784:tid 123921] [client 20.29.77.16:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/build.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQOgAAAAM"] [Tue Aug 18 13:02:11.087814 2026] [security2:error] [pid 123784:tid 123810] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pw.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQPAAAKRU"] [Tue Aug 18 13:02:11.101526 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vg.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbvAAAALQ"] [Tue Aug 18 13:02:11.124775 2026] [security2:error] [pid 139043:tid 139241] [client 20.151.109.219:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/17.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbvQAAAMk"] [Tue Aug 18 13:02:11.139949 2026] [security2:error] [pid 123784:tid 123887] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.ssh/id_rsa"] [unique_id "aoSCA2wDnJBNj2tDbYYQQwAALGI"] [Tue Aug 18 13:02:11.189387 2026] [security2:error] [pid 123784:tid 123947] [client 213.35.127.232:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQSAAAAB0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:11.193846 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:11.194105 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:11.245692 2026] [security2:error] [pid 123784:tid 123835] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.hermes/.env"] [unique_id "aoSCA2wDnJBNj2tDbYYQTgAALC4"] [Tue Aug 18 13:02:11.257671 2026] [security2:error] [pid 123784:tid 124024] [client 172.182.200.96:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/rymmm.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQUAAAAGo"] [Tue Aug 18 13:02:11.316265 2026] [security2:error] [pid 123784:tid 123819] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fn.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQUgAALh4"] [Tue Aug 18 13:02:11.334198 2026] [security2:error] [pid 139043:tid 139209] [client 132.196.30.78:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/themes.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbwAAAAKk"] [Tue Aug 18 13:02:11.340358 2026] [security2:error] [pid 139043:tid 139276] [client 158.158.74.177:10015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/lite.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbwQAAAOw"] [Tue Aug 18 13:02:11.352459 2026] [security2:error] [pid 123784:tid 123856] [remote 66.29.134.113:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.134.29.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQVgAAAEM"] [Tue Aug 18 13:02:11.367954 2026] [security2:error] [pid 123784:tid 123924] [client 172.213.243.2:5738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQVwAAAAY"] [Tue Aug 18 13:02:11.379577 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.154.236:8850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/zugvi.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbxAAAAOk"] [Tue Aug 18 13:02:11.389853 2026] [security2:error] [pid 123784:tid 123993] [client 213.202.253.4:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQXQAAAEs"], referer: www.google.com [Tue Aug 18 13:02:11.404262 2026] [security2:error] [pid 139043:tid 139178] [client 20.118.133.132:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbxQAAAIo"] [Tue Aug 18 13:02:11.408149 2026] [security2:error] [pid 123784:tid 124032] [client 20.29.77.16:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/defaul.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQXwAAAHI"] [Tue Aug 18 13:02:11.416281 2026] [security2:error] [pid 123784:tid 123937] [client 20.75.92.165:1952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/images/wso.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQYQAAABM"] [Tue Aug 18 13:02:11.448691 2026] [security2:error] [pid 123784:tid 123950] [client 20.151.109.219:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ev.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQZQAAACA"] [Tue Aug 18 13:02:11.468978 2026] [security2:error] [pid 123784:tid 123818] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.ssh/id_dsa"] [unique_id "aoSCA2wDnJBNj2tDbYYQZwAAQh0"] [Tue Aug 18 13:02:11.479443 2026] [security2:error] [pid 123784:tid 123913] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kf.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQaAAASnw"] [Tue Aug 18 13:02:11.533636 2026] [security2:error] [pid 123784:tid 123895] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/app_dev.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQbQAAAmo"] [Tue Aug 18 13:02:11.552446 2026] [security2:error] [pid 139043:tid 139287] [client 158.23.17.4:15763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gb.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbywAAAPc"] [Tue Aug 18 13:02:11.554835 2026] [security2:error] [pid 139043:tid 139182] [client 158.158.74.177:3248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/lock360.php"] [unique_id "aoSCA_2v-lWn9OzQT7UbzAAAAI4"] [Tue Aug 18 13:02:11.604059 2026] [security2:error] [pid 123784:tid 123874] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/app_dev.php/_profiler"] [unique_id "aoSCA2wDnJBNj2tDbYYQcAAAHFU"] [Tue Aug 18 13:02:11.634805 2026] [security2:error] [pid 123784:tid 123939] [client 172.202.39.151:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/xmrlpc.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQcgAAABU"] [Tue Aug 18 13:02:11.684702 2026] [autoindex:error] [pid 139043:tid 139269] [client 20.251.112.238:20207] AH01276: Cannot serve directory /home4/consiliumbr/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:11.710326 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:24143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sm.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub2QAAAPA"] [Tue Aug 18 13:02:11.729190 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.69.59:43269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQeAAAACE"] [Tue Aug 18 13:02:11.734566 2026] [security2:error] [pid 139043:tid 139248] [client 20.250.13.23:20349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/g.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub2wAAANA"] [Tue Aug 18 13:02:11.749627 2026] [security2:error] [pid 123784:tid 123884] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/su.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQeQAAFl8"] [Tue Aug 18 13:02:11.759664 2026] [security2:error] [pid 139043:tid 139261] [client 158.158.74.177:3240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/log.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub3AAAAN0"] [Tue Aug 18 13:02:11.770114 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:22939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub3QAAAIY"] [Tue Aug 18 13:02:11.782554 2026] [security2:error] [pid 139043:tid 139187] [client 20.29.77.16:40544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/twin.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub3gAAAJM"] [Tue Aug 18 13:02:11.788799 2026] [security2:error] [pid 123784:tid 123927] [client 68.155.154.236:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wsrer.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQgAAAAAk"] [Tue Aug 18 13:02:11.795079 2026] [security2:error] [pid 139043:tid 139262] [client 172.213.243.2:14563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub3wAAAN4"] [Tue Aug 18 13:02:11.797439 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:11.797452 2026] [security2:error] [pid 123784:tid 124001] [client 20.151.109.219:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xs.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQggAAAFM"] [Tue Aug 18 13:02:11.797734 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:11.858068 2026] [security2:error] [pid 139043:tid 139291] [client 132.196.30.78:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub4QAAAPs"] [Tue Aug 18 13:02:11.861774 2026] [security2:error] [pid 139043:tid 139206] [client 172.182.200.96:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/lddxs.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub5AAAAKY"] [Tue Aug 18 13:02:11.883882 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gb.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub5QAAAKA"] [Tue Aug 18 13:02:11.940527 2026] [security2:error] [pid 139043:tid 139217] [client 20.75.92.165:4286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/index/function.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub6QAAALE"] [Tue Aug 18 13:02:11.941832 2026] [security2:error] [pid 139043:tid 139173] [client 20.127.136.245:4827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/0x.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub6gAAAIU"] [Tue Aug 18 13:02:11.958463 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:25401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jp.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub6wAAAKM"] [Tue Aug 18 13:02:11.993242 2026] [security2:error] [pid 139043:tid 139189] [client 20.65.69.59:5752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub7gAAAJU"] [Tue Aug 18 13:02:11.996679 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/yw.php"] [unique_id "aoSCA_2v-lWn9OzQT7Ub7wAAAJg"] [Tue Aug 18 13:02:12.009512 2026] [security2:error] [pid 123784:tid 123836] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ns2.filialweb.com"] [uri "/wp-config.php.old"] [unique_id "aoSCBGwDnJBNj2tDbYYQkgAATi8"] [Tue Aug 18 13:02:12.016656 2026] [security2:error] [pid 123784:tid 123914] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ns2.filialweb.com"] [uri "/wp-config.php.bak"] [unique_id "aoSCBGwDnJBNj2tDbYYQlAAAPn0"] [Tue Aug 18 13:02:12.028654 2026] [security2:error] [pid 139043:tid 139191] [client 158.158.74.177:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSCBP2v-lWn9OzQT7Ub8AAAAJc"] [Tue Aug 18 13:02:12.075353 2026] [security2:error] [pid 139043:tid 139207] [client 135.225.78.186:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/nox.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub8gAAAKc"] [Tue Aug 18 13:02:12.097825 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:24445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub9AAAAJY"] [Tue Aug 18 13:02:12.103340 2026] [security2:error] [pid 139043:tid 139205] [client 20.251.112.238:20207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub9QAAAKU"] [Tue Aug 18 13:02:12.111840 2026] [security2:error] [pid 123784:tid 123803] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/laravel/.env"] [unique_id "aoSCBGwDnJBNj2tDbYYQlwAAag4"] [Tue Aug 18 13:02:12.120367 2026] [security2:error] [pid 139043:tid 139215] [client 20.29.77.16:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/new2.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub9gAAAK8"] [Tue Aug 18 13:02:12.129803 2026] [security2:error] [pid 123784:tid 123812] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/config/.env.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQmAAALBc"] [Tue Aug 18 13:02:12.137496 2026] [security2:error] [pid 139043:tid 139197] [client 20.38.3.247:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/wpxml.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub9wAAAJ0"] [Tue Aug 18 13:02:12.147160 2026] [security2:error] [pid 123784:tid 123890] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wp-key.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQmQAAEGU"] [Tue Aug 18 13:02:12.149117 2026] [security2:error] [pid 123784:tid 123889] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/core/.env"] [unique_id "aoSCBGwDnJBNj2tDbYYQmgAAGWQ"] [Tue Aug 18 13:02:12.163549 2026] [security2:error] [pid 123784:tid 123808] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/.env.php.bak"] [unique_id "aoSCBGwDnJBNj2tDbYYQmwAATRM"] [Tue Aug 18 13:02:12.205533 2026] [security2:error] [pid 139043:tid 139252] [client 213.35.127.232:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub_gAAANQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:12.207063 2026] [security2:error] [pid 139043:tid 139286] [client 68.155.154.236:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCBP2v-lWn9OzQT7Ub_wAAAPY"] [Tue Aug 18 13:02:12.210377 2026] [security2:error] [pid 139043:tid 139194] [client 20.226.56.190:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/yindu.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcAAAAAJo"] [Tue Aug 18 13:02:12.213588 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.13.23:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/gecko.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQnwAAACg"] [Tue Aug 18 13:02:12.220294 2026] [security2:error] [pid 123784:tid 123924] [client 172.213.243.2:16695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/vx.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQoAAAAAY"] [Tue Aug 18 13:02:12.233505 2026] [security2:error] [pid 123784:tid 123791] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/config.php.bak"] [unique_id "aoSCBGwDnJBNj2tDbYYQoQAASwI"] [Tue Aug 18 13:02:12.235038 2026] [security2:error] [pid 139043:tid 139225] [client 132.196.30.78:35546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/buy.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcAgAAALk"] [Tue Aug 18 13:02:12.244351 2026] [security2:error] [pid 139043:tid 139299] [client 20.65.69.59:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/st.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcBAAAAQM"] [Tue Aug 18 13:02:12.250844 2026] [security2:error] [pid 123784:tid 123858] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.175.26.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.filialweb.com"] [uri "/configuration.php.bak"] [unique_id "aoSCBGwDnJBNj2tDbYYQogAAfEU"] [Tue Aug 18 13:02:12.293949 2026] [security2:error] [pid 123784:tid 123795] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/public/.env"] [unique_id "aoSCBGwDnJBNj2tDbYYQowAAcgY"] [Tue Aug 18 13:02:12.298242 2026] [security2:error] [pid 123784:tid 123905] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/web/.env"] [unique_id "aoSCBGwDnJBNj2tDbYYQpAAAE3Q"] [Tue Aug 18 13:02:12.306849 2026] [security2:error] [pid 123784:tid 123828] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gg.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQpQAAKyc"] [Tue Aug 18 13:02:12.316074 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/sh.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQpwAAAB4"] [Tue Aug 18 13:02:12.319853 2026] [security2:error] [pid 139043:tid 139179] [client 20.75.92.165:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/info.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcCAAAAIs"] [Tue Aug 18 13:02:12.327163 2026] [security2:error] [pid 139043:tid 139198] [client 20.65.98.162:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/nano.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcCQAAAJ4"] [Tue Aug 18 13:02:12.341808 2026] [security2:error] [pid 139043:tid 139267] [client 20.127.136.245:17648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/222.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcCgAAAOM"] [Tue Aug 18 13:02:12.352927 2026] [security2:error] [pid 139043:tid 139257] [client 172.202.39.151:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/file.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcDAAAANk"] [Tue Aug 18 13:02:12.354228 2026] [security2:error] [pid 123784:tid 123950] [client 20.116.17.175:22963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/css.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQqQAAACA"] [Tue Aug 18 13:02:12.368096 2026] [security2:error] [pid 123784:tid 124028] [client 86.120.159.145:55124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQqgAAAG4"] [Tue Aug 18 13:02:12.368220 2026] [security2:error] [pid 123784:tid 124028] [client 86.120.159.145:55124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQqgAAAG4"] [Tue Aug 18 13:02:12.374303 2026] [security2:error] [pid 123784:tid 123892] [remote 34.26.175.209:52038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "ns2.filialweb.com"] [uri "/.env.swp"] [unique_id "aoSCBGwDnJBNj2tDbYYQrAAASmc"] [Tue Aug 18 13:02:12.398008 2026] [security2:error] [pid 123784:tid 123988] [client 158.158.74.177:3263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/lv.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQrwAAAEY"] [Tue Aug 18 13:02:12.398010 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:12.398285 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:12.411162 2026] [security2:error] [pid 123784:tid 124033] [client 20.151.109.219:39355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fd.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQsAAAAHM"] [Tue Aug 18 13:02:12.420469 2026] [security2:error] [pid 139043:tid 139176] [client 172.182.200.96:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/zjggu.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcEAAAAIg"] [Tue Aug 18 13:02:12.429093 2026] [security2:error] [pid 123784:tid 124026] [client 20.79.204.6:10739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQsQAAAGw"] [Tue Aug 18 13:02:12.480234 2026] [security2:error] [pid 123784:tid 123804] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gi.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQswAAXA8"] [Tue Aug 18 13:02:12.504240 2026] [security2:error] [pid 123784:tid 123925] [client 20.65.69.59:59249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/le.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQtQAAAAc"] [Tue Aug 18 13:02:12.531463 2026] [security2:error] [pid 123784:tid 124012] [client 158.23.17.4:38901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/28.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQtgAAAF4"] [Tue Aug 18 13:02:12.562171 2026] [security2:error] [pid 123784:tid 123972] [client 20.251.112.238:7200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/cxc.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQtwAAADY"] [Tue Aug 18 13:02:12.563600 2026] [security2:error] [pid 123784:tid 124044] [client 20.29.77.16:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/rex.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQuAAAAH4"] [Tue Aug 18 13:02:12.631816 2026] [security2:error] [pid 123784:tid 124040] [client 20.75.92.165:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/profile.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQuQAAAHo"] [Tue Aug 18 13:02:12.639864 2026] [security2:error] [pid 123784:tid 123864] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pz.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQugAAAUs"] [Tue Aug 18 13:02:12.645454 2026] [security2:error] [pid 123784:tid 123928] [client 172.213.243.2:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ah25.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQvAAAAAo"] [Tue Aug 18 13:02:12.699684 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:12.700089 2026] [authz_core:error] [pid 123784:tid 123870] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:12.704037 2026] [security2:error] [pid 139043:tid 139234] [client 132.196.30.78:1294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/dropdown.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcIQAAAMI"] [Tue Aug 18 13:02:12.710369 2026] [security2:error] [pid 139043:tid 139269] [client 20.151.109.219:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/info2.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcIgAAAOU"] [Tue Aug 18 13:02:12.736704 2026] [security2:error] [pid 123784:tid 123923] [client 158.158.74.177:9823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQvwAAAAU"] [Tue Aug 18 13:02:12.745261 2026] [security2:error] [pid 123784:tid 124037] [client 20.65.69.59:59259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/hr.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQwAAAAHc"] [Tue Aug 18 13:02:12.759586 2026] [security2:error] [pid 139043:tid 139290] [client 158.23.17.4:47637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/eq.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcJwAAAPo"] [Tue Aug 18 13:02:12.825969 2026] [security2:error] [pid 139043:tid 139174] [client 20.127.136.245:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/aa.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcLwAAAIY"] [Tue Aug 18 13:02:12.867003 2026] [security2:error] [pid 139043:tid 139219] [client 20.250.13.23:30802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/gettest.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcMgAAALM"] [Tue Aug 18 13:02:12.867881 2026] [security2:error] [pid 123784:tid 123916] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kk.php"] [unique_id "aoSCBGwDnJBNj2tDbYYQxwAADX8"] [Tue Aug 18 13:02:12.914864 2026] [security2:error] [pid 139043:tid 139204] [client 172.202.39.151:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/epinyins.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcOwAAAKQ"] [Tue Aug 18 13:02:12.925501 2026] [security2:error] [pid 139043:tid 139284] [client 20.29.77.16:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/verification.php"] [unique_id "aoSCBP2v-lWn9OzQT7UcPAAAAPQ"] [Tue Aug 18 13:02:13.000527 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:13.000941 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:13.003296 2026] [security2:error] [pid 123784:tid 124000] [client 20.65.69.59:12033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kt.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQygAAAFI"] [Tue Aug 18 13:02:13.021208 2026] [security2:error] [pid 123784:tid 123983] [client 158.158.74.177:3208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/mah/function.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQywAAAEE"] [Tue Aug 18 13:02:13.027224 2026] [security2:error] [pid 139043:tid 139285] [client 20.151.109.219:39333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sx.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcQAAAAPU"] [Tue Aug 18 13:02:13.034917 2026] [security2:error] [pid 123784:tid 123938] [client 20.251.112.238:7144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCBWwDnJBNj2tDbYYQzAAAABQ"] [Tue Aug 18 13:02:13.036235 2026] [security2:error] [pid 123784:tid 123930] [client 132.196.30.78:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/inputs.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQzQAAAAw"] [Tue Aug 18 13:02:13.045375 2026] [security2:error] [pid 139043:tid 139282] [client 20.116.17.175:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcQQAAAPI"] [Tue Aug 18 13:02:13.065922 2026] [security2:error] [pid 139043:tid 139189] [client 172.182.200.96:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/dlvqo.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcQwAAAJU"] [Tue Aug 18 13:02:13.067051 2026] [security2:error] [pid 139043:tid 139082] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/phpinfo.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcRAAAmCY"] [Tue Aug 18 13:02:13.067154 2026] [security2:error] [pid 123784:tid 123959] [client 172.213.243.2:11498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/tt.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQzgAAACk"] [Tue Aug 18 13:02:13.097032 2026] [security2:error] [pid 139043:tid 139212] [client 20.65.98.162:56930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "lecarveiculospira.com.br"] [uri "/.mopj.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcTgAAAKw"] [Tue Aug 18 13:02:13.099677 2026] [security2:error] [pid 139043:tid 139228] [client 20.75.92.165:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/sx.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcTwAAALw"] [Tue Aug 18 13:02:13.110787 2026] [security2:error] [pid 139043:tid 139117] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/info.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcUAAAl0k"] [Tue Aug 18 13:02:13.126631 2026] [security2:error] [pid 139043:tid 139288] [client 158.23.17.4:42601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ep.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcUQAAAPg"] [Tue Aug 18 13:02:13.171657 2026] [security2:error] [pid 139043:tid 139207] [client 20.116.17.175:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/admin.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcUwAAAKc"] [Tue Aug 18 13:02:13.171884 2026] [security2:error] [pid 139043:tid 139214] [client 4.232.151.198:24858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcVAAAAK4"] [Tue Aug 18 13:02:13.221708 2026] [security2:error] [pid 139043:tid 139200] [client 213.35.127.232:64817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcVwAAAKA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:13.238270 2026] [security2:error] [pid 139043:tid 139071] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/pi.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcWAAArRs"] [Tue Aug 18 13:02:13.258859 2026] [security2:error] [pid 139043:tid 139294] [client 20.65.69.59:27873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ww.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcWQAAAP4"] [Tue Aug 18 13:02:13.276852 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/m.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcWwAAANs"] [Tue Aug 18 13:02:13.301942 2026] [security2:error] [pid 139043:tid 139286] [client 158.23.17.4:51147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/qh.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcXAAAAPY"] [Tue Aug 18 13:02:13.321673 2026] [security2:error] [pid 139043:tid 139101] [remote 68.178.165.65:33404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcXQAAzjk"] [Tue Aug 18 13:02:13.325288 2026] [security2:error] [pid 139043:tid 139079] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/test.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcXgAAjCM"] [Tue Aug 18 13:02:13.338156 2026] [security2:error] [pid 123784:tid 123901] [remote 66.116.199.98:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/wp-login.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ0gAAJXA"] [Tue Aug 18 13:02:13.338334 2026] [security2:error] [pid 139043:tid 139225] [client 135.225.78.186:63010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/akismet.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcXwAAALk"] [Tue Aug 18 13:02:13.349156 2026] [security2:error] [pid 139043:tid 139299] [client 172.202.39.151:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcYAAAAQM"] [Tue Aug 18 13:02:13.375185 2026] [security2:error] [pid 139043:tid 139256] [client 158.158.74.177:22879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcYwAAANg"] [Tue Aug 18 13:02:13.381014 2026] [security2:error] [pid 123784:tid 123829] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ1AAAZig"] [Tue Aug 18 13:02:13.392438 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:60384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nu.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ1gAAAFk"] [Tue Aug 18 13:02:13.426865 2026] [security2:error] [pid 123784:tid 123934] [client 132.196.30.78:1336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/100.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ1wAAABA"] [Tue Aug 18 13:02:13.462987 2026] [security2:error] [pid 139043:tid 139295] [client 20.75.92.165:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcZQAAAP8"] [Tue Aug 18 13:02:13.476757 2026] [security2:error] [pid 123784:tid 123995] [client 20.251.112.238:8011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/0.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ2QAAAE0"] [Tue Aug 18 13:02:13.502372 2026] [security2:error] [pid 139043:tid 139198] [client 20.65.69.59:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mo.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcaAAAAJ4"] [Tue Aug 18 13:02:13.502519 2026] [security2:error] [pid 123784:tid 123979] [client 66.187.6.102:33544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/produtos/plasticos/plasticos-diversos"] [unique_id "aoSCBWwDnJBNj2tDbYYQ2gAAAD0"] [Tue Aug 18 13:02:13.502614 2026] [security2:error] [pid 123784:tid 123979] [client 66.187.6.102:33544] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/produtos/plasticos/plasticos-diversos"] [unique_id "aoSCBWwDnJBNj2tDbYYQ2gAAAD0"] [Tue Aug 18 13:02:13.535154 2026] [security2:error] [pid 139043:tid 139238] [client 20.127.136.245:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/abcd.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcbAAAAMY"] [Tue Aug 18 13:02:13.537782 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.200.96:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/pkmoj.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcbQAAALY"] [Tue Aug 18 13:02:13.538854 2026] [security2:error] [pid 139043:tid 139176] [client 172.202.39.151:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcbgAAAIg"] [Tue Aug 18 13:02:13.546103 2026] [security2:error] [pid 123784:tid 124041] [client 172.213.243.2:24380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xqq.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ3AAAAHs"] [Tue Aug 18 13:02:13.546272 2026] [security2:error] [pid 123784:tid 123915] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/i.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ3QAAa34"] [Tue Aug 18 13:02:13.556826 2026] [security2:error] [pid 123784:tid 123792] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dg.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ3gAAMgM"] [Tue Aug 18 13:02:13.584497 2026] [security2:error] [pid 123784:tid 123918] [client 20.226.56.190:45050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/sxx.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ3wAAAAA"] [Tue Aug 18 13:02:13.598824 2026] [security2:error] [pid 123784:tid 123924] [client 20.116.17.175:22983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/epinyins.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ4QAAAAY"] [Tue Aug 18 13:02:13.604559 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:13.604824 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:13.609258 2026] [security2:error] [pid 139043:tid 139220] [client 68.221.73.131:48777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/button.php"] [unique_id "aoSCBf2v-lWn9OzQT7UccgAAALQ"] [Tue Aug 18 13:02:13.625633 2026] [security2:error] [pid 139043:tid 139209] [client 68.155.154.236:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcegAAAKk"] [Tue Aug 18 13:02:13.650494 2026] [security2:error] [pid 139043:tid 139293] [client 20.250.13.23:53172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/goods.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcfAAAAP0"] [Tue Aug 18 13:02:13.681021 2026] [security2:error] [pid 139043:tid 139179] [client 158.158.74.177:3217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcfwAAAIs"] [Tue Aug 18 13:02:13.683328 2026] [security2:error] [pid 123784:tid 124006] [client 158.23.17.4:56709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rf.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ4gAAAFg"] [Tue Aug 18 13:02:13.719517 2026] [security2:error] [pid 139043:tid 139234] [client 20.75.92.165:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.92.75.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.orientadoraespiritualbhsp.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcgQAAAMI"] [Tue Aug 18 13:02:13.720129 2026] [security2:error] [pid 139043:tid 139211] [client 102.213.179.104:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcggAAAKs"] [Tue Aug 18 13:02:13.720216 2026] [security2:error] [pid 139043:tid 139211] [client 102.213.179.104:52859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcggAAAKs"] [Tue Aug 18 13:02:13.736491 2026] [security2:error] [pid 123784:tid 123797] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/bm.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ5AAAKwg"] [Tue Aug 18 13:02:13.754790 2026] [security2:error] [pid 139043:tid 139283] [client 20.65.69.59:48481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/qr.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcgwAAAPM"] [Tue Aug 18 13:02:13.778115 2026] [security2:error] [pid 139043:tid 139174] [client 68.155.154.236:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/yxijx.php"] [unique_id "aoSCBf2v-lWn9OzQT7UchQAAAIY"] [Tue Aug 18 13:02:13.800480 2026] [security2:error] [pid 139043:tid 139262] [client 20.151.109.219:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ko.php"] [unique_id "aoSCBf2v-lWn9OzQT7UchgAAAN4"] [Tue Aug 18 13:02:13.826103 2026] [security2:error] [pid 139043:tid 139258] [client 132.196.30.78:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/akc.php"] [unique_id "aoSCBf2v-lWn9OzQT7UcigAAANo"] [Tue Aug 18 13:02:13.828107 2026] [security2:error] [pid 139043:tid 139077] [remote 47.89.174.181:9886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sengerclimatizacao.pixmidias.com.br"] [uri "/.env"] [unique_id "aoSCBf2v-lWn9OzQT7UcjAAA-SE"] [Tue Aug 18 13:02:13.828111 2026] [security2:error] [pid 139043:tid 139073] [remote 47.89.174.181:9872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sengerclimatizacao.com.br.pixmidias.com.br"] [uri "/.env"] [unique_id "aoSCBf2v-lWn9OzQT7UciwAAkB0"] [Tue Aug 18 13:02:13.903416 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:13.903640 2026] [security2:error] [pid 123784:tid 123842] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/app_dev.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ6AAASjU"] [Tue Aug 18 13:02:13.903683 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:13.913081 2026] [security2:error] [pid 123784:tid 123825] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vu.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ6QAARiQ"] [Tue Aug 18 13:02:13.923699 2026] [security2:error] [pid 139043:tid 139189] [client 20.251.112.238:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/dom.php"] [unique_id "aoSCBf2v-lWn9OzQT7UckQAAAJU"] [Tue Aug 18 13:02:13.951192 2026] [security2:error] [pid 139043:tid 139191] [client 172.202.39.151:4269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCBf2v-lWn9OzQT7UckwAAAJc"] [Tue Aug 18 13:02:13.957257 2026] [security2:error] [pid 139043:tid 139227] [client 20.127.136.245:7760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/admin.php"] [unique_id "aoSCBf2v-lWn9OzQT7UclQAAALs"] [Tue Aug 18 13:02:13.958109 2026] [security2:error] [pid 139043:tid 139147] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBf2v-lWn9OzQT7UclAAAh2c"] [Tue Aug 18 13:02:13.958289 2026] [security2:error] [pid 139043:tid 139175] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBf2v-lWn9OzQT7UclAAAh2c"] [Tue Aug 18 13:02:13.982350 2026] [security2:error] [pid 123784:tid 124039] [client 172.213.243.2:11481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/06.php"] [unique_id "aoSCBWwDnJBNj2tDbYYQ6wAAAHk"] [Tue Aug 18 13:02:14.021637 2026] [security2:error] [pid 139043:tid 139278] [client 20.65.69.59:9673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/dirs.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcmAAAAO4"] [Tue Aug 18 13:02:14.036818 2026] [security2:error] [pid 139043:tid 139248] [client 4.232.151.198:11647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/666.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcmQAAANA"] [Tue Aug 18 13:02:14.043030 2026] [security2:error] [pid 123784:tid 123942] [client 158.23.17.4:9301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nl.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ7AAAABg"] [Tue Aug 18 13:02:14.060408 2026] [security2:error] [pid 123784:tid 123863] [remote 191.96.150.246:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "belmais.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSCBmwDnJBNj2tDbYYQ7QAAXEo"] [Tue Aug 18 13:02:14.092643 2026] [security2:error] [pid 139043:tid 139294] [client 158.23.17.4:12482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jp.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcnAAAAP4"] [Tue Aug 18 13:02:14.106156 2026] [security2:error] [pid 139043:tid 139271] [client 158.158.74.177:22854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcnQAAAOc"] [Tue Aug 18 13:02:14.110925 2026] [security2:error] [pid 139043:tid 139286] [client 172.182.200.96:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/kopyw.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcoAAAAPY"] [Tue Aug 18 13:02:14.123359 2026] [security2:error] [pid 139043:tid 139230] [client 20.79.204.6:10742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/themes.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcoQAAAL4"] [Tue Aug 18 13:02:14.134441 2026] [security2:error] [pid 139043:tid 139098] [remote 8.229.129.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.129.229.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.outlimit.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSCBv2v-lWn9OzQT7UcpQAA4jY"] [Tue Aug 18 13:02:14.135394 2026] [security2:error] [pid 139043:tid 139299] [client 20.151.109.219:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/pl.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcpgAAAQM"] [Tue Aug 18 13:02:14.152186 2026] [security2:error] [pid 139043:tid 139207] [client 66.187.6.102:36720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/8089c4202d9c39ed6e0fd1e24df285c0.png"] [unique_id "aoSCBv2v-lWn9OzQT7UcpwAAAKc"] [Tue Aug 18 13:02:14.152335 2026] [security2:error] [pid 139043:tid 139207] [client 66.187.6.102:36720] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/8089c4202d9c39ed6e0fd1e24df285c0.png"] [unique_id "aoSCBv2v-lWn9OzQT7UcpwAAAKc"] [Tue Aug 18 13:02:14.153824 2026] [security2:error] [pid 139043:tid 139195] [client 20.116.17.175:23023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/load.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcqAAAAJs"] [Tue Aug 18 13:02:14.203815 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:14.204073 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:14.232893 2026] [security2:error] [pid 123784:tid 123939] [client 20.118.133.132:43509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/admin.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ9QAAABU"] [Tue Aug 18 13:02:14.234939 2026] [security2:error] [pid 139043:tid 139282] [client 213.35.127.232:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcrwAAAPI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:14.267330 2026] [security2:error] [pid 123784:tid 123908] [remote 212.29.237.5:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ9gAAOXc"] [Tue Aug 18 13:02:14.275905 2026] [security2:error] [pid 123784:tid 123919] [client 20.65.69.59:48473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sn.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ-AAAAAE"] [Tue Aug 18 13:02:14.285193 2026] [security2:error] [pid 139043:tid 139245] [client 20.226.56.190:17884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/settings.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcswAAAM0"] [Tue Aug 18 13:02:14.288086 2026] [security2:error] [pid 139043:tid 139197] [client 20.250.13.23:30838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/gulu.php"] [unique_id "aoSCBv2v-lWn9OzQT7UctAAAAJ0"] [Tue Aug 18 13:02:14.302603 2026] [security2:error] [pid 139043:tid 139236] [client 172.202.39.151:4431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcuQAAAMQ"] [Tue Aug 18 13:02:14.321611 2026] [security2:error] [pid 139043:tid 139213] [client 158.158.74.177:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/mass.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcugAAAK0"] [Tue Aug 18 13:02:14.328572 2026] [security2:error] [pid 139043:tid 139183] [client 132.196.30.78:35581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcuwAAAI8"] [Tue Aug 18 13:02:14.341781 2026] [security2:error] [pid 123784:tid 123940] [client 135.225.78.186:65377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/admin.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ_gAAABY"] [Tue Aug 18 13:02:14.353579 2026] [security2:error] [pid 123784:tid 123946] [client 66.187.6.102:36866] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/downloads/2"] [unique_id "aoSCBmwDnJBNj2tDbYYQ_wAAABw"] [Tue Aug 18 13:02:14.373961 2026] [security2:error] [pid 139043:tid 139224] [client 66.187.6.102:36658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/processes/thumbs/843d94a992b46cf265b320b80760d73c.jpg"] [unique_id "aoSCBv2v-lWn9OzQT7UcvQAAALg"] [Tue Aug 18 13:02:14.380350 2026] [security2:error] [pid 139043:tid 139293] [client 20.251.112.238:51077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/bb.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcvgAAAP0"] [Tue Aug 18 13:02:14.381477 2026] [security2:error] [pid 139043:tid 139205] [client 68.221.73.131:41221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/wlc.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcvwAAAKU"] [Tue Aug 18 13:02:14.383548 2026] [security2:error] [pid 139043:tid 139239] [client 216.244.66.232:53466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcwAAAAMc"] [Tue Aug 18 13:02:14.383663 2026] [security2:error] [pid 139043:tid 139239] [client 216.244.66.232:53466] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcwAAAAMc"] [Tue Aug 18 13:02:14.389034 2026] [security2:error] [pid 123784:tid 123882] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRAAAAG10"] [Tue Aug 18 13:02:14.404660 2026] [security2:error] [pid 123784:tid 123925] [client 66.187.6.102:36790] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/a6e42909368b9f34ff7c2fa06a49f529.jpg"] [unique_id "aoSCBmwDnJBNj2tDbYYRAQAAAAc"] [Tue Aug 18 13:02:14.406016 2026] [security2:error] [pid 123784:tid 123927] [client 172.213.243.2:50121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/166.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRAgAAAAk"] [Tue Aug 18 13:02:14.463199 2026] [security2:error] [pid 139043:tid 139255] [client 20.151.109.219:24385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/env.php"] [unique_id "aoSCBv2v-lWn9OzQT7UcxwAAANc"] [Tue Aug 18 13:02:14.467966 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ic.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRBQAAUyM"] [Tue Aug 18 13:02:14.496382 2026] [security2:error] [pid 123784:tid 123809] [remote 191.96.150.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.150.96.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBmwDnJBNj2tDbYYQ-wAAMRQ"] [Tue Aug 18 13:02:14.524251 2026] [security2:error] [pid 123784:tid 123887] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRBgAAL2I"] [Tue Aug 18 13:02:14.545272 2026] [security2:error] [pid 139043:tid 139219] [client 66.187.6.102:36660] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/downloads/3"] [unique_id "aoSCBv2v-lWn9OzQT7UczwAAALM"] [Tue Aug 18 13:02:14.560027 2026] [security2:error] [pid 123784:tid 123983] [client 20.65.69.59:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/43.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRCAAAAEE"] [Tue Aug 18 13:02:14.576693 2026] [security2:error] [pid 139043:tid 139223] [client 20.116.17.175:23030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc1AAAALc"] [Tue Aug 18 13:02:14.592902 2026] [security2:error] [pid 139043:tid 139189] [client 158.23.17.4:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xynz1.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc1QAAAJU"] [Tue Aug 18 13:02:14.614763 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:41923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/68.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc1gAAAJg"] [Tue Aug 18 13:02:14.658600 2026] [security2:error] [pid 139043:tid 139283] [client 66.187.6.102:36874] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/es/produtos/rolos/rolos-de-la-natural-poliester"] [unique_id "aoSCBv2v-lWn9OzQT7Uc2QAAAPM"] [Tue Aug 18 13:02:14.668040 2026] [security2:error] [pid 123784:tid 123878] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ue.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRCwAARFk"] [Tue Aug 18 13:02:14.669886 2026] [security2:error] [pid 139043:tid 139204] [client 172.182.200.96:15642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/zznmg.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc3AAAAKQ"] [Tue Aug 18 13:02:14.678971 2026] [security2:error] [pid 123784:tid 123832] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/dirs.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRDAAASCs"] [Tue Aug 18 13:02:14.735560 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:60322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/r.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc4QAAAQM"] [Tue Aug 18 13:02:14.738906 2026] [security2:error] [pid 139043:tid 139229] [client 158.158.74.177:9253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc4gAAAL0"] [Tue Aug 18 13:02:14.751387 2026] [security2:error] [pid 139043:tid 139228] [client 74.7.241.147:45926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "proj.villar.adv.br"] [uri "/robots.txt"] [unique_id "aoSCBv2v-lWn9OzQT7Uc5AAAALw"] [Tue Aug 18 13:02:14.771019 2026] [security2:error] [pid 139043:tid 139288] [client 66.187.6.102:36832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/acessorios/acessorios-diversos"] [unique_id "aoSCBv2v-lWn9OzQT7Uc5QAAAPg"] [Tue Aug 18 13:02:14.771116 2026] [security2:error] [pid 139043:tid 139288] [client 66.187.6.102:36832] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/acessorios/acessorios-diversos"] [unique_id "aoSCBv2v-lWn9OzQT7Uc5QAAAPg"] [Tue Aug 18 13:02:14.802152 2026] [security2:error] [pid 123784:tid 123997] [client 132.196.30.78:1184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/php.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRFAAAAE8"] [Tue Aug 18 13:02:14.806495 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:14.806806 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:14.816658 2026] [security2:error] [pid 123784:tid 123789] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/fresh.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRFgAAJQA"] [Tue Aug 18 13:02:14.817885 2026] [security2:error] [pid 139043:tid 139238] [client 20.127.136.245:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc8AAAAMY"] [Tue Aug 18 13:02:14.823811 2026] [security2:error] [pid 139043:tid 139222] [client 20.251.112.238:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ok.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc8QAAALY"] [Tue Aug 18 13:02:14.833075 2026] [security2:error] [pid 139043:tid 139251] [client 20.65.69.59:27884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fresh.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc8gAAANM"] [Tue Aug 18 13:02:14.835087 2026] [security2:error] [pid 123784:tid 123904] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lr.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRFwAAZHM"] [Tue Aug 18 13:02:14.854438 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mz.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc8wAAAJ0"] [Tue Aug 18 13:02:14.864344 2026] [security2:error] [pid 123784:tid 124035] [client 172.202.39.151:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-mail.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRGAAAAHU"] [Tue Aug 18 13:02:14.872787 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.56.190:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/spip.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRGQAAAGY"] [Tue Aug 18 13:02:14.892850 2026] [security2:error] [pid 139043:tid 139252] [client 172.202.39.151:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc9gAAANQ"] [Tue Aug 18 13:02:14.900871 2026] [security2:error] [pid 139043:tid 139162] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc-AAAtHY"] [Tue Aug 18 13:02:14.901048 2026] [security2:error] [pid 139043:tid 139220] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc-AAAtHY"] [Tue Aug 18 13:02:14.912298 2026] [security2:error] [pid 123784:tid 124007] [client 172.213.243.2:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/snq.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRGwAAAFk"] [Tue Aug 18 13:02:14.937267 2026] [security2:error] [pid 139043:tid 139236] [client 74.7.241.147:45926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "proj.villar.adv.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSCBv2v-lWn9OzQT7Uc9QAAAMQ"], referer: https://proj.villar.adv.br/robots.txt [Tue Aug 18 13:02:14.950395 2026] [security2:error] [pid 139043:tid 139256] [client 158.158.74.177:36001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/memberfuns.php"] [unique_id "aoSCBv2v-lWn9OzQT7Uc_QAAANg"] [Tue Aug 18 13:02:14.969877 2026] [security2:error] [pid 123784:tid 123835] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/admin404.php"] [unique_id "aoSCBmwDnJBNj2tDbYYRHQAAJi4"] [Tue Aug 18 13:02:14.990234 2026] [security2:error] [pid 139043:tid 139254] [client 20.250.13.23:30786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/h.php"] [unique_id "aoSCBv2v-lWn9OzQT7UdAQAAANY"] [Tue Aug 18 13:02:15.023004 2026] [security2:error] [pid 123784:tid 124025] [client 20.116.17.175:23005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ty.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRIAAAAGs"] [Tue Aug 18 13:02:15.054281 2026] [security2:error] [pid 139043:tid 139241] [client 158.23.17.4:7206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vo.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdBQAAAMk"] [Tue Aug 18 13:02:15.063748 2026] [security2:error] [pid 123784:tid 123943] [client 20.29.77.16:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/smtp.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRIQAAABk"] [Tue Aug 18 13:02:15.089423 2026] [security2:error] [pid 139043:tid 139237] [client 20.79.204.6:10421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/cv.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdBwAAAMU"] [Tue Aug 18 13:02:15.100696 2026] [security2:error] [pid 123784:tid 123821] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ka.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRIgAAMiA"] [Tue Aug 18 13:02:15.103159 2026] [security2:error] [pid 123784:tid 123970] [client 20.65.69.59:27902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gj.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRJAAAADQ"] [Tue Aug 18 13:02:15.129683 2026] [security2:error] [pid 123784:tid 123924] [client 20.38.3.247:4949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/file1221.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRJgAAAAY"] [Tue Aug 18 13:02:15.135801 2026] [security2:error] [pid 123784:tid 123954] [client 20.151.109.219:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ft.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRKAAAACQ"] [Tue Aug 18 13:02:15.150416 2026] [security2:error] [pid 123784:tid 123993] [client 68.221.73.131:41222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/fi.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRLgAAAEs"] [Tue Aug 18 13:02:15.201343 2026] [security2:error] [pid 123784:tid 123937] [client 172.202.39.151:4430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/function/function.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRLwAAABM"] [Tue Aug 18 13:02:15.215350 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:57264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/eq.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdCgAAAPA"] [Tue Aug 18 13:02:15.216387 2026] [security2:error] [pid 123784:tid 124024] [client 20.65.98.162:26300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/bengi.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRMAAAAGo"] [Tue Aug 18 13:02:15.230680 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/loading.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRMQAAZWg"] [Tue Aug 18 13:02:15.250748 2026] [security2:error] [pid 139043:tid 139221] [client 20.251.112.238:7178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp9.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdDAAAALU"] [Tue Aug 18 13:02:15.255262 2026] [security2:error] [pid 139043:tid 139273] [client 213.35.127.232:65228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdDQAAAOk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:15.333173 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jl.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdEQAAAPk"] [Tue Aug 18 13:02:15.347755 2026] [security2:error] [pid 139043:tid 139204] [client 172.213.243.2:11826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-access.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdEgAAAKQ"] [Tue Aug 18 13:02:15.358907 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.69.59:48448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pd.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdEwAAAO8"] [Tue Aug 18 13:02:15.397433 2026] [security2:error] [pid 139043:tid 139200] [client 20.29.77.16:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/teste.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdFAAAAKA"] [Tue Aug 18 13:02:15.407994 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:15.408252 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:15.422459 2026] [security2:error] [pid 123784:tid 123847] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/conn-test.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRNQAAeTo"] [Tue Aug 18 13:02:15.425102 2026] [security2:error] [pid 139043:tid 139296] [client 20.118.133.132:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/biufile.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdFwAAAQA"] [Tue Aug 18 13:02:15.490967 2026] [security2:error] [pid 123784:tid 123942] [client 20.151.109.219:20136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/h.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRNgAAABg"] [Tue Aug 18 13:02:15.515330 2026] [security2:error] [pid 123784:tid 123989] [client 5.161.215.244:29096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSCA2wDnJBNj2tDbYYQiQAAAEc"], referer: https://ealoggroup.com.br/ [Tue Aug 18 13:02:15.565985 2026] [security2:error] [pid 139043:tid 139288] [client 20.116.17.175:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdHwAAAPg"] [Tue Aug 18 13:02:15.566524 2026] [security2:error] [pid 139043:tid 139281] [client 149.34.210.141:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdIAAAAPE"] [Tue Aug 18 13:02:15.579237 2026] [security2:error] [pid 139043:tid 139216] [client 158.158.74.177:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/meta.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdIQAAALA"] [Tue Aug 18 13:02:15.596207 2026] [security2:error] [pid 139043:tid 139250] [client 172.202.39.151:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdIwAAANI"] [Tue Aug 18 13:02:15.606742 2026] [security2:error] [pid 123784:tid 123801] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/evil.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRNwAAcAw"] [Tue Aug 18 13:02:15.607848 2026] [security2:error] [pid 139043:tid 139238] [client 172.182.200.96:15682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/bhfnd.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdJAAAAMY"] [Tue Aug 18 13:02:15.619585 2026] [security2:error] [pid 139043:tid 139257] [client 158.23.17.4:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/17.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdJQAAANk"] [Tue Aug 18 13:02:15.651971 2026] [security2:error] [pid 123784:tid 124011] [client 20.65.69.59:48455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/th.php"] [unique_id "aoSCB2wDnJBNj2tDbYYROQAAAF0"] [Tue Aug 18 13:02:15.662177 2026] [security2:error] [pid 123784:tid 123919] [client 135.225.78.186:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.78.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.grupogeper.com.br"] [uri "/ajax.php"] [unique_id "aoSCB2wDnJBNj2tDbYYROgAAAAE"] [Tue Aug 18 13:02:15.678236 2026] [security2:error] [pid 139043:tid 139229] [client 20.250.13.23:3605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/hello.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdKAAAAL0"] [Tue Aug 18 13:02:15.679628 2026] [security2:error] [pid 139043:tid 139176] [client 20.127.136.245:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/akc.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdKQAAAIg"] [Tue Aug 18 13:02:15.682100 2026] [security2:error] [pid 123784:tid 123888] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ot.php"] [unique_id "aoSCB2wDnJBNj2tDbYYROwAAFmM"] [Tue Aug 18 13:02:15.692575 2026] [security2:error] [pid 139043:tid 139242] [client 20.251.112.238:18178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws59.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdKgAAAMo"] [Tue Aug 18 13:02:15.706579 2026] [security2:error] [pid 139043:tid 139197] [client 158.23.17.4:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wu.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdKwAAAJ0"] [Tue Aug 18 13:02:15.710345 2026] [security2:error] [pid 139043:tid 139235] [client 68.221.73.131:41629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/chris.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdLAAAAMM"] [Tue Aug 18 13:02:15.710501 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:15.710771 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:15.722775 2026] [security2:error] [pid 139043:tid 139220] [client 20.29.77.16:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/local.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdLgAAALQ"] [Tue Aug 18 13:02:15.727336 2026] [security2:error] [pid 139043:tid 139199] [client 158.158.74.177:9984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/ku.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdLwAAAJ8"] [Tue Aug 18 13:02:15.732353 2026] [security2:error] [pid 123784:tid 123928] [client 138.36.100.162:42765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRPQAAAAo"] [Tue Aug 18 13:02:15.734805 2026] [security2:error] [pid 123784:tid 123928] [client 138.36.100.162:42765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRPQAAAAo"] [Tue Aug 18 13:02:15.760960 2026] [security2:error] [pid 123784:tid 123913] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/wp-key.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRQAAAHHw"] [Tue Aug 18 13:02:15.782132 2026] [security2:error] [pid 139043:tid 139275] [client 172.213.243.2:24337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/nw.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdMQAAAOs"] [Tue Aug 18 13:02:15.839045 2026] [security2:error] [pid 139043:tid 139281] [client 149.34.210.141:60777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdIAAAAPE"] [Tue Aug 18 13:02:15.842460 2026] [security2:error] [pid 139043:tid 139245] [client 158.23.17.4:41932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/tq.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdNAAAAM0"] [Tue Aug 18 13:02:15.847275 2026] [security2:error] [pid 139043:tid 139254] [client 4.232.151.198:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ws54.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdNQAAANY"] [Tue Aug 18 13:02:15.853150 2026] [security2:error] [pid 123784:tid 123806] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ih.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRQQAABxE"] [Tue Aug 18 13:02:15.897190 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRQgAAGg0"] [Tue Aug 18 13:02:15.913873 2026] [security2:error] [pid 139043:tid 139231] [client 216.244.66.232:53478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdOAAAAL8"] [Tue Aug 18 13:02:15.913999 2026] [security2:error] [pid 139043:tid 139231] [client 216.244.66.232:53478] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdOAAAAL8"] [Tue Aug 18 13:02:15.915615 2026] [security2:error] [pid 123784:tid 123927] [client 20.151.109.219:24410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/40.php"] [unique_id "aoSCB2wDnJBNj2tDbYYRQwAAAAk"] [Tue Aug 18 13:02:15.951754 2026] [security2:error] [pid 139043:tid 139262] [client 20.65.69.59:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/admin404.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdOQAAAN4"] [Tue Aug 18 13:02:15.988500 2026] [security2:error] [pid 139043:tid 139274] [client 132.196.30.78:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/t.php"] [unique_id "aoSCB_2v-lWn9OzQT7UdOgAAAOo"] [Tue Aug 18 13:02:16.027126 2026] [security2:error] [pid 123784:tid 123895] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/mimes.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRRAAAWmo"] [Tue Aug 18 13:02:16.042891 2026] [security2:error] [pid 139043:tid 139110] [remote 162.55.89.48:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdPQAAi0I"] [Tue Aug 18 13:02:16.062283 2026] [security2:error] [pid 123784:tid 123868] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/k.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRRQAAU08"] [Tue Aug 18 13:02:16.123982 2026] [security2:error] [pid 123784:tid 123952] [client 20.116.17.175:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/dot.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRRwAAACI"] [Tue Aug 18 13:02:16.139779 2026] [security2:error] [pid 123784:tid 123982] [client 20.29.77.16:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRSAAAAEA"] [Tue Aug 18 13:02:16.163820 2026] [security2:error] [pid 123784:tid 124014] [client 20.251.112.238:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRSQAAAGA"] [Tue Aug 18 13:02:16.194021 2026] [security2:error] [pid 123784:tid 123830] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRSwAAQSk"] [Tue Aug 18 13:02:16.196120 2026] [security2:error] [pid 139043:tid 139210] [client 172.213.243.2:18134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws62.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdQQAAAKo"] [Tue Aug 18 13:02:16.197343 2026] [security2:error] [pid 139043:tid 139295] [client 158.158.74.177:36003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/mini.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdQgAAAP8"] [Tue Aug 18 13:02:16.216146 2026] [security2:error] [pid 123784:tid 124004] [client 20.65.69.59:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/qo.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRTAAAAFY"] [Tue Aug 18 13:02:16.233168 2026] [security2:error] [pid 123784:tid 123921] [client 172.182.200.96:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/qfvqu.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRTQAAAAM"] [Tue Aug 18 13:02:16.235863 2026] [security2:error] [pid 123784:tid 123854] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/iu.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRTgAAEUE"] [Tue Aug 18 13:02:16.242865 2026] [security2:error] [pid 139043:tid 139222] [client 178.153.171.161:14845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdQwAAALY"] [Tue Aug 18 13:02:16.243057 2026] [security2:error] [pid 139043:tid 139222] [client 178.153.171.161:14845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdQwAAALY"] [Tue Aug 18 13:02:16.244858 2026] [security2:error] [pid 123784:tid 124045] [client 20.127.136.245:23641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/buy.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRTwAAAH8"] [Tue Aug 18 13:02:16.255099 2026] [authz_core:error] [pid 123784:tid 123814] [remote 57.141.22.106:21258] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:16.255362 2026] [authz_core:error] [pid 123784:tid 123814] [remote 57.141.22.106:21258] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:16.259560 2026] [security2:error] [pid 139043:tid 139175] [client 68.221.73.131:50745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/doc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdRAAAAIc"] [Tue Aug 18 13:02:16.262994 2026] [security2:error] [pid 139043:tid 139278] [client 20.151.109.219:14091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ee.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdRQAAAO4"] [Tue Aug 18 13:02:16.271016 2026] [security2:error] [pid 123784:tid 123831] [remote 191.96.150.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.150.96.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRUQAASCo"] [Tue Aug 18 13:02:16.271185 2026] [security2:error] [pid 123784:tid 123990] [client 191.96.150.246:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRUQAASCo"] [Tue Aug 18 13:02:16.272476 2026] [security2:error] [pid 139043:tid 139232] [client 213.35.127.232:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdRwAAAMA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:16.278963 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/de.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdSAAAAPk"] [Tue Aug 18 13:02:16.313889 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:16.314144 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:16.322811 2026] [security2:error] [pid 123784:tid 123967] [client 20.250.13.23:20304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/images/index.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRVAAAADE"] [Tue Aug 18 13:02:16.325919 2026] [security2:error] [pid 123784:tid 123909] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/pqr.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRVQAAcXg"] [Tue Aug 18 13:02:16.327755 2026] [security2:error] [pid 123784:tid 124009] [client 172.202.39.151:4455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRVgAAAFs"] [Tue Aug 18 13:02:16.373887 2026] [security2:error] [pid 139043:tid 139204] [client 158.23.17.4:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ev.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdSgAAAKQ"] [Tue Aug 18 13:02:16.437589 2026] [security2:error] [pid 123784:tid 123977] [client 132.196.30.78:25810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/index/function.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRWQAAADs"] [Tue Aug 18 13:02:16.465384 2026] [security2:error] [pid 139043:tid 139259] [client 20.65.69.59:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sd.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdTgAAANs"] [Tue Aug 18 13:02:16.478053 2026] [security2:error] [pid 123784:tid 123997] [client 20.38.3.247:4502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/nox.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRWgAAAE8"] [Tue Aug 18 13:02:16.498356 2026] [security2:error] [pid 123784:tid 123850] [remote 191.96.150.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.150.96.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRWwAAJT0"] [Tue Aug 18 13:02:16.498519 2026] [security2:error] [pid 123784:tid 123955] [client 191.96.150.246:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRWwAAJT0"] [Tue Aug 18 13:02:16.513324 2026] [security2:error] [pid 139043:tid 139285] [client 20.116.17.175:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/005.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdUAAAAPU"] [Tue Aug 18 13:02:16.524640 2026] [security2:error] [pid 123784:tid 123884] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRXAAAZF8"] [Tue Aug 18 13:02:16.548833 2026] [security2:error] [pid 139043:tid 139293] [client 157.20.138.62:49759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdUgAAAP0"] [Tue Aug 18 13:02:16.548931 2026] [security2:error] [pid 139043:tid 139293] [client 157.20.138.62:49759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdUgAAAP0"] [Tue Aug 18 13:02:16.559260 2026] [security2:error] [pid 123784:tid 124035] [client 158.158.74.177:9804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRXQAAAHU"] [Tue Aug 18 13:02:16.560924 2026] [security2:error] [pid 139043:tid 139276] [client 20.203.183.135:12737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/fpwch.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdVAAAAOw"] [Tue Aug 18 13:02:16.580712 2026] [security2:error] [pid 123784:tid 124016] [client 20.151.109.219:27712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRXgAAAGI"] [Tue Aug 18 13:02:16.581466 2026] [security2:error] [pid 139043:tid 139207] [client 20.29.77.16:16564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/ninja.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdVQAAAKc"] [Tue Aug 18 13:02:16.597385 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:10741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdVgAAALA"] [Tue Aug 18 13:02:16.612692 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:16.612965 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:16.624213 2026] [security2:error] [pid 123784:tid 123920] [client 20.151.109.219:34019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ak.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRYgAAAAI"] [Tue Aug 18 13:02:16.630889 2026] [security2:error] [pid 139043:tid 139198] [client 172.213.243.2:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/public/vx.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdWAAAAJ4"] [Tue Aug 18 13:02:16.639756 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/cv.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRYwAAACY"] [Tue Aug 18 13:02:16.646753 2026] [security2:error] [pid 139043:tid 139188] [client 128.79.71.90:46459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.71.79.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovareinstitutoluanda.com"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdTwAAAJQ"] [Tue Aug 18 13:02:16.646877 2026] [security2:error] [pid 139043:tid 139188] [client 128.79.71.90:46459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovareinstitutoluanda.com"] [uri "/xmlrpc.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdTwAAAJQ"] [Tue Aug 18 13:02:16.717032 2026] [security2:error] [pid 139043:tid 139177] [client 20.65.69.59:12086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/km.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdWQAAAIk"] [Tue Aug 18 13:02:16.725557 2026] [security2:error] [pid 139043:tid 139174] [client 20.251.112.238:45068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdXAAAAIY"] [Tue Aug 18 13:02:16.782793 2026] [security2:error] [pid 123784:tid 123968] [client 68.221.73.131:17697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/1337.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRZAAAADI"] [Tue Aug 18 13:02:16.786684 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pk.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRZQAANEY"] [Tue Aug 18 13:02:16.824910 2026] [security2:error] [pid 123784:tid 123964] [client 158.158.74.177:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/mm.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRZgAAAC4"] [Tue Aug 18 13:02:16.828441 2026] [security2:error] [pid 139043:tid 139180] [client 68.155.154.236:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdXwAAAIw"] [Tue Aug 18 13:02:16.837065 2026] [security2:error] [pid 123784:tid 123883] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/info2.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRZwAABl4"] [Tue Aug 18 13:02:16.880620 2026] [security2:error] [pid 139043:tid 139199] [client 158.23.17.4:38281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ep.php"] [unique_id "aoSCCP2v-lWn9OzQT7UdYwAAAJ8"] [Tue Aug 18 13:02:16.884446 2026] [security2:error] [pid 123784:tid 123954] [client 20.127.136.245:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/cong.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRaQAAACQ"] [Tue Aug 18 13:02:16.896399 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/album.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRagAAAGc"] [Tue Aug 18 13:02:16.914123 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:16.914463 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:16.960988 2026] [security2:error] [pid 123784:tid 123993] [client 20.151.109.219:33985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/test_info.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRbAAAAEs"] [Tue Aug 18 13:02:16.999683 2026] [security2:error] [pid 123784:tid 124006] [client 20.116.17.175:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/v2.php"] [unique_id "aoSCCGwDnJBNj2tDbYYRbgAAAFg"] [Tue Aug 18 13:02:17.006650 2026] [security2:error] [pid 123784:tid 123879] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ge.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRbwAAPVo"] [Tue Aug 18 13:02:17.008022 2026] [security2:error] [pid 123784:tid 123937] [client 20.65.69.59:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mf.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRcAAAABM"] [Tue Aug 18 13:02:17.014060 2026] [security2:error] [pid 123784:tid 124024] [client 20.151.109.219:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRcQAAAGo"] [Tue Aug 18 13:02:17.040119 2026] [security2:error] [pid 123784:tid 123958] [client 20.250.13.23:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/index.bak.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRcgAAACg"] [Tue Aug 18 13:02:17.040379 2026] [security2:error] [pid 139043:tid 139182] [client 172.202.39.151:4716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/ok.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdZwAAAI4"] [Tue Aug 18 13:02:17.130868 2026] [security2:error] [pid 123784:tid 123962] [client 172.202.39.151:44103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/o.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRdAAAACw"] [Tue Aug 18 13:02:17.168824 2026] [security2:error] [pid 123784:tid 123875] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kl.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRdgAAGFY"] [Tue Aug 18 13:02:17.169090 2026] [security2:error] [pid 139043:tid 139254] [client 20.29.77.16:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/phpprobe.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdaQAAANY"] [Tue Aug 18 13:02:17.169507 2026] [security2:error] [pid 139043:tid 139249] [client 37.40.227.74:57120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdagAAANE"] [Tue Aug 18 13:02:17.170191 2026] [security2:error] [pid 139043:tid 139263] [client 172.213.243.2:17463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/loxi-o.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdawAAAN8"] [Tue Aug 18 13:02:17.173778 2026] [security2:error] [pid 139043:tid 139249] [client 37.40.227.74:57120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdagAAANE"] [Tue Aug 18 13:02:17.260123 2026] [security2:error] [pid 123784:tid 123975] [client 216.244.66.232:53482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRdwAAADk"] [Tue Aug 18 13:02:17.260227 2026] [security2:error] [pid 123784:tid 123975] [client 216.244.66.232:53482] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRdwAAADk"] [Tue Aug 18 13:02:17.266044 2026] [security2:error] [pid 139043:tid 139226] [client 20.151.109.219:24389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/14.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdbgAAALo"] [Tue Aug 18 13:02:17.287542 2026] [security2:error] [pid 139043:tid 139268] [client 213.35.127.232:49289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdcQAAAOQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:17.296802 2026] [security2:error] [pid 139043:tid 139183] [client 20.65.69.59:27855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ie.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdcgAAAI8"] [Tue Aug 18 13:02:17.306505 2026] [security2:error] [pid 123784:tid 123919] [client 20.251.112.238:8042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/vx.php"] [unique_id "aoSCCWwDnJBNj2tDbYYReAAAAAE"] [Tue Aug 18 13:02:17.314424 2026] [security2:error] [pid 123784:tid 123973] [client 68.221.73.131:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/Njima.php"] [unique_id "aoSCCWwDnJBNj2tDbYYReQAAADc"] [Tue Aug 18 13:02:17.321829 2026] [security2:error] [pid 139043:tid 139212] [client 103.120.71.157:28689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdcwAAAKw"] [Tue Aug 18 13:02:17.321970 2026] [security2:error] [pid 139043:tid 139212] [client 103.120.71.157:28689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdcwAAAKw"] [Tue Aug 18 13:02:17.341562 2026] [security2:error] [pid 123784:tid 124043] [client 158.158.74.177:9987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/asd.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRegAAAH0"] [Tue Aug 18 13:02:17.364860 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gs.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRewAAX3I"] [Tue Aug 18 13:02:17.402707 2026] [security2:error] [pid 139043:tid 139262] [client 172.182.200.96:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/oivcl.php"] [unique_id "aoSCCf2v-lWn9OzQT7UddwAAAN4"] [Tue Aug 18 13:02:17.410620 2026] [security2:error] [pid 139043:tid 139219] [client 132.196.30.78:25808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wk/index.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdeAAAALM"] [Tue Aug 18 13:02:17.444392 2026] [security2:error] [pid 139043:tid 139186] [client 158.158.74.177:35975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdegAAAJI"] [Tue Aug 18 13:02:17.447941 2026] [security2:error] [pid 139043:tid 139179] [client 172.202.39.151:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eezy.site"] [uri "/item.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdewAAAIs"] [Tue Aug 18 13:02:17.463653 2026] [security2:error] [pid 139043:tid 139217] [client 158.23.17.4:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kv.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdfQAAALE"] [Tue Aug 18 13:02:17.493626 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rf.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdfwAAALc"] [Tue Aug 18 13:02:17.504712 2026] [security2:error] [pid 139043:tid 139173] [client 20.118.133.132:41531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/coffexium.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdgAAAAIU"] [Tue Aug 18 13:02:17.538324 2026] [security2:error] [pid 123784:tid 123811] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/test_info.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRfgAAUxY"] [Tue Aug 18 13:02:17.538579 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:17.538859 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:17.581804 2026] [security2:error] [pid 139043:tid 139222] [client 20.65.69.59:5412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nw.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdgwAAALY"] [Tue Aug 18 13:02:17.592488 2026] [security2:error] [pid 139043:tid 139192] [client 172.213.243.2:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sdsa.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdhAAAAJg"] [Tue Aug 18 13:02:17.605810 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:14297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/tk.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdhgAAAPM"] [Tue Aug 18 13:02:17.633904 2026] [security2:error] [pid 139043:tid 139228] [client 213.202.253.4:57105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/postnews.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdiAAAALw"], referer: www.google.com [Tue Aug 18 13:02:17.644644 2026] [security2:error] [pid 139043:tid 139289] [client 20.127.136.245:11790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdigAAAPk"] [Tue Aug 18 13:02:17.645503 2026] [security2:error] [pid 139043:tid 139204] [client 20.116.17.175:22957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wkl.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdiwAAAKQ"] [Tue Aug 18 13:02:17.706905 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/index/function.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdjAAAAPQ"] [Tue Aug 18 13:02:17.717353 2026] [security2:error] [pid 139043:tid 139296] [client 20.65.98.162:26281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/file2.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdjgAAAQA"] [Tue Aug 18 13:02:17.735214 2026] [security2:error] [pid 139043:tid 139269] [client 20.251.112.238:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ah25.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdkAAAAOU"] [Tue Aug 18 13:02:17.825076 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:17.825365 2026] [authz_core:error] [pid 123784:tid 123798] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:17.832955 2026] [security2:error] [pid 139043:tid 139297] [client 5.31.227.224:1415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdkgAAAQE"] [Tue Aug 18 13:02:17.836055 2026] [security2:error] [pid 139043:tid 139207] [client 20.65.69.59:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sb.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdkwAAAKc"] [Tue Aug 18 13:02:17.837481 2026] [security2:error] [pid 139043:tid 139297] [client 5.31.227.224:1415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdkgAAAQE"] [Tue Aug 18 13:02:17.843003 2026] [security2:error] [pid 123784:tid 123836] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/xynz1.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRgQAAaS8"] [Tue Aug 18 13:02:17.855040 2026] [security2:error] [pid 139043:tid 139225] [client 20.29.77.16:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/wp-title.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdlAAAALk"] [Tue Aug 18 13:02:17.890040 2026] [security2:error] [pid 139043:tid 139198] [client 68.221.73.131:48033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdlQAAAJ4"] [Tue Aug 18 13:02:17.908430 2026] [security2:error] [pid 123784:tid 123794] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lw.php"] [unique_id "aoSCCWwDnJBNj2tDbYYRggAAAwU"] [Tue Aug 18 13:02:17.933464 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:15794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/z.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdlwAAAIY"] [Tue Aug 18 13:02:17.968595 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:24395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/hp.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdmQAAAJ0"] [Tue Aug 18 13:02:17.970072 2026] [security2:error] [pid 139043:tid 139206] [client 158.158.74.177:9853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/akc.php"] [unique_id "aoSCCf2v-lWn9OzQT7UdmgAAAKY"] [Tue Aug 18 13:02:18.023069 2026] [security2:error] [pid 139043:tid 139260] [client 20.151.109.219:10600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/st.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdnQAAANw"] [Tue Aug 18 13:02:18.042200 2026] [security2:error] [pid 123784:tid 124045] [client 172.213.243.2:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-freya.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRgwAAAH8"] [Tue Aug 18 13:02:18.056164 2026] [security2:error] [pid 123784:tid 123914] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/album.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRhAAARH0"] [Tue Aug 18 13:02:18.067397 2026] [security2:error] [pid 139043:tid 139288] [client 158.158.74.177:36019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/moon.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdnwAAAPg"] [Tue Aug 18 13:02:18.090788 2026] [security2:error] [pid 123784:tid 123790] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vj.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRhQAAXgE"] [Tue Aug 18 13:02:18.097838 2026] [security2:error] [pid 139043:tid 139220] [client 168.62.48.100:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdogAAALQ"] [Tue Aug 18 13:02:18.115706 2026] [security2:error] [pid 123784:tid 123990] [client 20.65.69.59:48505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xj.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRhwAAAEg"] [Tue Aug 18 13:02:18.121006 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:18.121254 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:18.129534 2026] [security2:error] [pid 139043:tid 139199] [client 20.38.3.247:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/akismet.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdowAAAJ8"] [Tue Aug 18 13:02:18.135717 2026] [security2:error] [pid 139043:tid 139209] [client 20.116.17.175:22979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdpQAAAKk"] [Tue Aug 18 13:02:18.151879 2026] [security2:error] [pid 123784:tid 124031] [client 20.127.136.245:22665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/db.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRiAAAAHE"] [Tue Aug 18 13:02:18.195020 2026] [security2:error] [pid 123784:tid 123834] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/creds.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRiQAAWy0"] [Tue Aug 18 13:02:18.235237 2026] [security2:error] [pid 139043:tid 139281] [client 20.251.112.238:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/tt.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdpwAAAPE"] [Tue Aug 18 13:02:18.250923 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:43329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRigAAAEA"] [Tue Aug 18 13:02:18.251021 2026] [security2:error] [pid 123784:tid 123982] [client 103.184.169.37:43329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRigAAAEA"] [Tue Aug 18 13:02:18.265059 2026] [security2:error] [pid 123784:tid 123932] [client 172.182.200.96:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/zugvi.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRiwAAAA4"] [Tue Aug 18 13:02:18.302650 2026] [security2:error] [pid 139043:tid 139180] [client 213.35.127.232:49503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdqwAAAIw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:18.327153 2026] [security2:error] [pid 123784:tid 123977] [client 158.23.17.4:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xs.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRjQAAADs"] [Tue Aug 18 13:02:18.348116 2026] [security2:error] [pid 123784:tid 123812] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/mandrill.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRjwAAJRc"] [Tue Aug 18 13:02:18.362461 2026] [security2:error] [pid 123784:tid 124018] [client 20.29.77.16:47323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/styles.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRkAAAAGQ"] [Tue Aug 18 13:02:18.380137 2026] [security2:error] [pid 139043:tid 139211] [client 20.79.204.6:10375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ws83.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdrQAAAKs"] [Tue Aug 18 13:02:18.434690 2026] [security2:error] [pid 123784:tid 123920] [client 158.23.17.4:49053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xg.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRkgAAAAI"] [Tue Aug 18 13:02:18.446909 2026] [security2:error] [pid 139043:tid 139268] [client 132.196.30.78:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdrwAAAOQ"] [Tue Aug 18 13:02:18.458280 2026] [security2:error] [pid 123784:tid 123956] [client 20.65.69.59:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ns.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRlwAAACY"] [Tue Aug 18 13:02:18.459047 2026] [security2:error] [pid 123784:tid 124040] [client 172.213.243.2:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fleen.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRmAAAAHo"] [Tue Aug 18 13:02:18.460648 2026] [security2:error] [pid 123784:tid 123999] [client 216.244.66.232:53484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRmQAAAFE"] [Tue Aug 18 13:02:18.460727 2026] [security2:error] [pid 123784:tid 123999] [client 216.244.66.232:53484] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRmQAAAFE"] [Tue Aug 18 13:02:18.466512 2026] [security2:error] [pid 139043:tid 139218] [client 20.250.13.23:53176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/info.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdsQAAALI"] [Tue Aug 18 13:02:18.485954 2026] [security2:error] [pid 123784:tid 123943] [client 68.221.73.131:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/too.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRmwAAABk"] [Tue Aug 18 13:02:18.487516 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:9283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/un.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRnAAAADI"] [Tue Aug 18 13:02:18.493400 2026] [security2:error] [pid 123784:tid 123970] [client 20.151.109.219:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wx.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRnQAAADQ"] [Tue Aug 18 13:02:18.537623 2026] [security2:error] [pid 139043:tid 139255] [client 20.226.56.190:17906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/search.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdsgAAANc"] [Tue Aug 18 13:02:18.540854 2026] [security2:error] [pid 123784:tid 123848] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/main.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRngAAZzs"] [Tue Aug 18 13:02:18.597530 2026] [security2:error] [pid 123784:tid 123805] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mimes.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRnwAAPRA"] [Tue Aug 18 13:02:18.634163 2026] [security2:error] [pid 123784:tid 124016] [client 158.158.74.177:10025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/maintenance.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRoAAAAGI"] [Tue Aug 18 13:02:18.654915 2026] [security2:error] [pid 139043:tid 139208] [client 20.127.136.245:22682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/dropdown.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdtQAAAKg"] [Tue Aug 18 13:02:18.684690 2026] [security2:error] [pid 139043:tid 139237] [client 20.116.17.175:23002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/az.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdtgAAAMU"] [Tue Aug 18 13:02:18.687446 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:35991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/n.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRogAAAC8"] [Tue Aug 18 13:02:18.695498 2026] [security2:error] [pid 139043:tid 139292] [client 158.23.17.4:38300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xynz1.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdtwAAAPw"] [Tue Aug 18 13:02:18.709758 2026] [security2:error] [pid 123784:tid 123793] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/payout.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRowAAbgQ"] [Tue Aug 18 13:02:18.720297 2026] [security2:error] [pid 139043:tid 139219] [client 20.65.69.59:5424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gk.php"] [unique_id "aoSCCv2v-lWn9OzQT7UduAAAALM"] [Tue Aug 18 13:02:18.720651 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:18.720924 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:18.747462 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:40578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xqq.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdugAAAJM"] [Tue Aug 18 13:02:18.757393 2026] [security2:error] [pid 139043:tid 139217] [client 20.29.77.16:13637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/server.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdvAAAALE"] [Tue Aug 18 13:02:18.757978 2026] [security2:error] [pid 139043:tid 139186] [client 130.89.144.170:10249] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "maisutil.ind.br"] [uri "/robots.txt"] [unique_id "aoSCCv2v-lWn9OzQT7UduwAAAJI"] [Tue Aug 18 13:02:18.760538 2026] [security2:error] [pid 139043:tid 139173] [client 68.155.154.236:9162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/jrpga.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdvQAAAIU"] [Tue Aug 18 13:02:18.760972 2026] [security2:error] [pid 123784:tid 123858] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ni.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRpQAALEU"] [Tue Aug 18 13:02:18.773938 2026] [security2:error] [pid 139043:tid 139280] [client 20.151.109.219:34041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/dj.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdvgAAAPA"] [Tue Aug 18 13:02:18.868229 2026] [security2:error] [pid 139043:tid 139273] [client 172.202.39.151:49379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/bb.php"] [unique_id "aoSCCv2v-lWn9OzQT7UdwAAAAOk"] [Tue Aug 18 13:02:18.885987 2026] [security2:error] [pid 123784:tid 123989] [client 172.213.243.2:30570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/e.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRpgAAAEc"] [Tue Aug 18 13:02:18.915828 2026] [security2:error] [pid 123784:tid 123795] [remote 20.51.153.15:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRpwAAOAY"] [Tue Aug 18 13:02:18.915933 2026] [security2:error] [pid 123784:tid 123795] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCCmwDnJBNj2tDbYYRpwAAOAY"] [Tue Aug 18 13:02:19.022419 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:19.022688 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:19.041218 2026] [security2:error] [pid 139043:tid 139245] [client 223.185.37.47:18343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdxAAAAM0"] [Tue Aug 18 13:02:19.041341 2026] [security2:error] [pid 139043:tid 139245] [client 223.185.37.47:18343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdxAAAAM0"] [Tue Aug 18 13:02:19.078896 2026] [security2:error] [pid 139043:tid 139189] [client 158.23.17.4:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/nd.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdxQAAAJU"] [Tue Aug 18 13:02:19.087752 2026] [security2:error] [pid 139043:tid 139269] [client 20.151.109.219:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fa.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdxgAAAOU"] [Tue Aug 18 13:02:19.091054 2026] [security2:error] [pid 123784:tid 123975] [client 20.29.77.16:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/xinfo.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRqQAAADk"] [Tue Aug 18 13:02:19.100683 2026] [security2:error] [pid 123784:tid 123828] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/Mailgun.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRqgAAASc"] [Tue Aug 18 13:02:19.101608 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.200.96:15634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wsrer.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdyQAAALg"] [Tue Aug 18 13:02:19.124287 2026] [security2:error] [pid 139043:tid 139228] [client 20.250.13.23:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/inputs.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdygAAALw"] [Tue Aug 18 13:02:19.154744 2026] [security2:error] [pid 139043:tid 139276] [client 20.65.69.59:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wn.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdywAAAOw"] [Tue Aug 18 13:02:19.170618 2026] [security2:error] [pid 123784:tid 123928] [client 130.89.144.170:16571] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "maisutil.ind.br"] [uri "/"] [unique_id "aoSCC2wDnJBNj2tDbYYRqwAAAAo"] [Tue Aug 18 13:02:19.199005 2026] [security2:error] [pid 123784:tid 123946] [client 20.251.112.238:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/06.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRrQAAABw"] [Tue Aug 18 13:02:19.223113 2026] [security2:error] [pid 123784:tid 124038] [client 158.23.17.4:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vo.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRrgAAAHg"] [Tue Aug 18 13:02:19.286493 2026] [security2:error] [pid 139043:tid 139284] [client 158.158.74.177:10009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/options-writing.php"] [unique_id "aoSCC_2v-lWn9OzQT7UdzwAAAPQ"] [Tue Aug 18 13:02:19.321093 2026] [security2:error] [pid 139043:tid 139200] [client 213.35.127.232:49721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud0AAAAKA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:19.324486 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:19.324744 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:19.325695 2026] [security2:error] [pid 139043:tid 139293] [client 158.158.74.177:36018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/nc4.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud0QAAAP0"] [Tue Aug 18 13:02:19.327450 2026] [security2:error] [pid 139043:tid 139191] [client 172.213.243.2:17430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/hello.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud0gAAAJc"] [Tue Aug 18 13:02:19.372348 2026] [security2:error] [pid 123784:tid 123892] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/oauth.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRswAAH2c"] [Tue Aug 18 13:02:19.393228 2026] [security2:error] [pid 123784:tid 123960] [client 20.151.109.219:20135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/fb.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRtQAAACo"] [Tue Aug 18 13:02:19.394007 2026] [security2:error] [pid 123784:tid 124017] [client 20.127.136.245:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/file.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRtgAAAGM"] [Tue Aug 18 13:02:19.414211 2026] [security2:error] [pid 123784:tid 123925] [client 132.196.30.78:10456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/xfun.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRtwAAAAc"] [Tue Aug 18 13:02:19.442972 2026] [security2:error] [pid 139043:tid 139213] [client 172.202.39.151:63726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud2AAAAK0"] [Tue Aug 18 13:02:19.443099 2026] [security2:error] [pid 139043:tid 139288] [client 68.221.73.131:50705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.acecdlunai.com.br"] [uri "/g3.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud1wAAAPg"] [Tue Aug 18 13:02:19.443220 2026] [security2:error] [pid 139043:tid 139220] [client 20.65.69.59:5742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/app.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud2QAAALQ"] [Tue Aug 18 13:02:19.445956 2026] [security2:error] [pid 123784:tid 123804] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/88.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRuAAATA8"] [Tue Aug 18 13:02:19.447447 2026] [security2:error] [pid 139043:tid 139250] [client 168.62.48.100:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud2gAAANI"] [Tue Aug 18 13:02:19.510536 2026] [security2:error] [pid 139043:tid 139239] [client 20.29.77.16:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/sym.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud3QAAAMc"] [Tue Aug 18 13:02:19.531551 2026] [security2:error] [pid 139043:tid 139094] [remote 20.87.239.85:6833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud3gAAqjI"] [Tue Aug 18 13:02:19.550612 2026] [security2:error] [pid 139043:tid 139182] [client 20.116.17.175:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/z43agz.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud4AAAAI4"] [Tue Aug 18 13:02:19.552522 2026] [security2:error] [pid 139043:tid 139291] [client 20.251.48.93:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud4QAAAPs"] [Tue Aug 18 13:02:19.554684 2026] [security2:error] [pid 123784:tid 123941] [client 216.244.66.232:53500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRuwAAABc"] [Tue Aug 18 13:02:19.554820 2026] [security2:error] [pid 123784:tid 123941] [client 216.244.66.232:53500] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRuwAAABc"] [Tue Aug 18 13:02:19.565790 2026] [security2:error] [pid 123784:tid 123841] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/timeclock.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRvAAAaTQ"] [Tue Aug 18 13:02:19.599538 2026] [security2:error] [pid 139043:tid 139211] [client 20.38.3.247:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/admin.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud4wAAAKs"] [Tue Aug 18 13:02:19.624160 2026] [security2:error] [pid 123784:tid 123948] [client 158.23.17.4:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ri.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRxAAAAB4"] [Tue Aug 18 13:02:19.637993 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:38911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/evil.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRxgAAAH8"] [Tue Aug 18 13:02:19.648644 2026] [security2:error] [pid 123784:tid 123870] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/hj.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRxwAARFE"] [Tue Aug 18 13:02:19.680751 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud5QAAAOE"] [Tue Aug 18 13:02:19.688525 2026] [security2:error] [pid 139043:tid 139266] [client 20.251.112.238:8005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/166.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud5gAAAOI"] [Tue Aug 18 13:02:19.705031 2026] [security2:error] [pid 139043:tid 139247] [client 20.65.69.59:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/87.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud6AAAAM8"] [Tue Aug 18 13:02:19.739858 2026] [security2:error] [pid 139043:tid 139219] [client 20.151.109.219:60886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gw.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud6gAAALM"] [Tue Aug 18 13:02:19.744954 2026] [security2:error] [pid 139043:tid 139181] [client 172.213.243.2:45938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/brc.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud6wAAAI0"] [Tue Aug 18 13:02:19.837216 2026] [security2:error] [pid 123784:tid 123906] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ij.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRywAADHU"] [Tue Aug 18 13:02:19.880252 2026] [security2:error] [pid 139043:tid 139283] [client 172.182.200.96:15622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/ucpfr.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud7QAAAPM"] [Tue Aug 18 13:02:19.914786 2026] [security2:error] [pid 139043:tid 139196] [client 20.127.136.245:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/goods.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud8AAAAJw"] [Tue Aug 18 13:02:19.928316 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:19.928587 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:19.944233 2026] [security2:error] [pid 139043:tid 139262] [client 158.158.74.177:35997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/new.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud8QAAAN4"] [Tue Aug 18 13:02:19.961560 2026] [security2:error] [pid 139043:tid 139224] [client 20.29.77.16:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.77.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cadidetruckpartes.com.br"] [uri "/ye.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud8gAAALg"] [Tue Aug 18 13:02:19.976508 2026] [security2:error] [pid 123784:tid 123839] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ud.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRzgAAcjI"] [Tue Aug 18 13:02:19.989671 2026] [security2:error] [pid 139043:tid 139225] [client 20.65.69.59:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/zi.php"] [unique_id "aoSCC_2v-lWn9OzQT7Ud8wAAALk"] [Tue Aug 18 13:02:20.029168 2026] [security2:error] [pid 123784:tid 123936] [client 158.158.74.177:9842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSCDGwDnJBNj2tDbYYRzwAAABI"] [Tue Aug 18 13:02:20.035428 2026] [security2:error] [pid 123784:tid 123829] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/email.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR0AAAPig"] [Tue Aug 18 13:02:20.049628 2026] [security2:error] [pid 123784:tid 123923] [client 20.250.13.23:53159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/install.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR0QAAAAU"] [Tue Aug 18 13:02:20.114008 2026] [security2:error] [pid 123784:tid 123853] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ip.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR0gAAC0A"] [Tue Aug 18 13:02:20.132173 2026] [security2:error] [pid 139043:tid 139293] [client 20.226.56.190:17899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/build.php"] [unique_id "aoSCDP2v-lWn9OzQT7Ud-QAAAP0"] [Tue Aug 18 13:02:20.151064 2026] [security2:error] [pid 139043:tid 139197] [client 20.151.109.219:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/le.php"] [unique_id "aoSCDP2v-lWn9OzQT7Ud-gAAAJ0"] [Tue Aug 18 13:02:20.190096 2026] [security2:error] [pid 139043:tid 139239] [client 172.213.243.2:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/file52.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeEgAAAMc"] [Tue Aug 18 13:02:20.209820 2026] [security2:error] [pid 139043:tid 139278] [client 20.251.112.238:22375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/snq.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeFAAAAO4"] [Tue Aug 18 13:02:20.220649 2026] [security2:error] [pid 123784:tid 123873] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/profile.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR1AAAZVQ"] [Tue Aug 18 13:02:20.227359 2026] [security2:error] [pid 139043:tid 139201] [client 20.151.109.219:60393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/sw.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeFQAAAKE"] [Tue Aug 18 13:02:20.231221 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:20.231681 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:20.233970 2026] [security2:error] [pid 139043:tid 139291] [client 20.65.69.59:59255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/92.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeFgAAAPs"] [Tue Aug 18 13:02:20.238121 2026] [security2:error] [pid 139043:tid 139281] [client 158.23.17.4:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tp.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeFwAAAPE"] [Tue Aug 18 13:02:20.274361 2026] [security2:error] [pid 123784:tid 123933] [client 68.155.154.236:8875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR1gAAAA8"] [Tue Aug 18 13:02:20.284273 2026] [security2:error] [pid 139043:tid 139254] [client 132.196.30.78:24051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/p.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeGQAAANY"] [Tue Aug 18 13:02:20.290447 2026] [security2:error] [pid 123784:tid 123792] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/99.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR1wAAewM"] [Tue Aug 18 13:02:20.335950 2026] [security2:error] [pid 139043:tid 139240] [client 213.35.127.232:49927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeKAAAAMg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:20.382519 2026] [security2:error] [pid 123784:tid 123910] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/summary.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR2gAARnk"] [Tue Aug 18 13:02:20.416990 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.56.190:23762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/defaul.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeLAAAAJk"] [Tue Aug 18 13:02:20.432848 2026] [security2:error] [pid 139043:tid 139142] [remote 47.128.123.59:28818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ergoclinica.com.br"] [uri "/robots.txt"] [unique_id "aoSCDP2v-lWn9OzQT7UeMAAA3WI"] [Tue Aug 18 13:02:20.457767 2026] [security2:error] [pid 123784:tid 123797] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/er.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR2wAAOAg"] [Tue Aug 18 13:02:20.463437 2026] [security2:error] [pid 139043:tid 139173] [client 158.23.17.4:31931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wu.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeNQAAAIU"] [Tue Aug 18 13:02:20.468654 2026] [security2:error] [pid 123784:tid 124011] [client 172.202.39.151:52903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR3AAAAF0"] [Tue Aug 18 13:02:20.507471 2026] [security2:error] [pid 139043:tid 139221] [client 20.151.109.219:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gc.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeNwAAALU"] [Tue Aug 18 13:02:20.523769 2026] [security2:error] [pid 139043:tid 139271] [client 158.23.17.4:17544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fd.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeOAAAAOc"] [Tue Aug 18 13:02:20.529633 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:20.529749 2026] [security2:error] [pid 123784:tid 123953] [client 20.65.69.59:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/jm.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR3gAAACM"] [Tue Aug 18 13:02:20.529931 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:20.537410 2026] [security2:error] [pid 123784:tid 123975] [client 158.23.17.4:16910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pw.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR3wAAADk"] [Tue Aug 18 13:02:20.543680 2026] [security2:error] [pid 123784:tid 123860] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/conf.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR4AAAAUc"] [Tue Aug 18 13:02:20.560990 2026] [security2:error] [pid 139043:tid 139268] [client 158.158.74.177:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/packed.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeOwAAAOQ"] [Tue Aug 18 13:02:20.594121 2026] [security2:error] [pid 139043:tid 139215] [client 196.12.128.158:58829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeQAAAAK8"] [Tue Aug 18 13:02:20.594225 2026] [security2:error] [pid 139043:tid 139215] [client 196.12.128.158:58829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeQAAAAK8"] [Tue Aug 18 13:02:20.598469 2026] [security2:error] [pid 139043:tid 139175] [client 20.127.136.245:22711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeQQAAAIc"] [Tue Aug 18 13:02:20.606976 2026] [security2:error] [pid 139043:tid 139227] [client 172.213.243.2:16018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeQgAAALs"] [Tue Aug 18 13:02:20.625521 2026] [security2:error] [pid 123784:tid 123825] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qk.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR4gAAbyQ"] [Tue Aug 18 13:02:20.648987 2026] [security2:error] [pid 139043:tid 139196] [client 20.251.112.238:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-access.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeRAAAAJw"] [Tue Aug 18 13:02:20.669053 2026] [security2:error] [pid 123784:tid 124033] [client 20.118.133.132:39697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/dex.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR4wAAAHM"] [Tue Aug 18 13:02:20.676351 2026] [security2:error] [pid 123784:tid 123863] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/bala.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR5AAAHEo"] [Tue Aug 18 13:02:20.677447 2026] [autoindex:error] [pid 139043:tid 139075] [remote 34.62.54.143:48908] AH01276: Cannot serve directory /home3/tentac25/_wildcard_.tentaclehost.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:20.677870 2026] [security2:error] [pid 139043:tid 139203] [client 20.250.13.23:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ioxi-o.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeRgAAAKM"] [Tue Aug 18 13:02:20.703977 2026] [security2:error] [pid 139043:tid 139276] [client 197.184.64.235:41968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeRwAAAOw"] [Tue Aug 18 13:02:20.704087 2026] [security2:error] [pid 139043:tid 139276] [client 197.184.64.235:41968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeRwAAAOw"] [Tue Aug 18 13:02:20.704935 2026] [security2:error] [pid 123784:tid 123945] [client 20.116.17.175:23037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/3.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR5QAAABs"] [Tue Aug 18 13:02:20.715707 2026] [security2:error] [pid 139043:tid 139251] [client 172.182.200.96:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/yxijx.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeSgAAANM"] [Tue Aug 18 13:02:20.721741 2026] [security2:error] [pid 123784:tid 123962] [client 130.89.144.170:63524] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.levalixo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSCDGwDnJBNj2tDbYYR5gAAACw"] [Tue Aug 18 13:02:20.724273 2026] [security2:error] [pid 123784:tid 123944] [client 20.151.109.219:27775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/hr.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR5wAAABo"] [Tue Aug 18 13:02:20.725492 2026] [security2:error] [pid 139043:tid 139295] [client 158.158.74.177:9852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/maint.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeTAAAAP8"] [Tue Aug 18 13:02:20.785172 2026] [security2:error] [pid 123784:tid 123971] [client 20.65.69.59:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wj.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR6gAAADU"] [Tue Aug 18 13:02:20.787934 2026] [security2:error] [pid 123784:tid 123882] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR6wAAH10"] [Tue Aug 18 13:02:20.796346 2026] [security2:error] [pid 123784:tid 123963] [client 158.23.17.4:11394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/zj.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR7AAAAC0"] [Tue Aug 18 13:02:20.837650 2026] [security2:error] [pid 123784:tid 123925] [client 20.151.109.219:24391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/uq.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR7QAAAAc"] [Tue Aug 18 13:02:20.855803 2026] [security2:error] [pid 123784:tid 123861] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/222.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR7gAAVEg"] [Tue Aug 18 13:02:20.889261 2026] [autoindex:error] [pid 139043:tid 139299] [client 169.58.72.248:53085] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:20.944791 2026] [security2:error] [pid 123784:tid 123907] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fs.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR7wAAaXY"] [Tue Aug 18 13:02:20.952277 2026] [security2:error] [pid 123784:tid 124014] [client 34.198.201.66:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "amigosdoronron.com.br"] [uri "/index.php"] [unique_id "aoSCC2wDnJBNj2tDbYYRuQAAYD8"], referer: https://amigosdoronron.com.br/ [Tue Aug 18 13:02:20.952940 2026] [security2:error] [pid 139043:tid 139246] [client 20.251.48.93:20180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeVgAAAM4"] [Tue Aug 18 13:02:20.998366 2026] [security2:error] [pid 139043:tid 139206] [client 216.244.66.232:53512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeVwAAAKY"] [Tue Aug 18 13:02:20.998463 2026] [security2:error] [pid 139043:tid 139206] [client 216.244.66.232:53512] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCDP2v-lWn9OzQT7UeVwAAAKY"] [Tue Aug 18 13:02:20.998573 2026] [security2:error] [pid 123784:tid 123824] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/routes.php"] [unique_id "aoSCDGwDnJBNj2tDbYYR8AAAHiM"] [Tue Aug 18 13:02:21.032631 2026] [security2:error] [pid 139043:tid 139213] [client 132.196.30.78:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeWQAAAK0"] [Tue Aug 18 13:02:21.049061 2026] [security2:error] [pid 139043:tid 139288] [client 172.213.243.2:17696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/path.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeWgAAAPg"] [Tue Aug 18 13:02:21.073023 2026] [security2:error] [pid 139043:tid 139199] [client 20.127.136.245:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/htaccess.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeWwAAAJ8"] [Tue Aug 18 13:02:21.078947 2026] [security2:error] [pid 123784:tid 123921] [client 20.65.69.59:5381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/74.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR8QAAAAM"] [Tue Aug 18 13:02:21.108056 2026] [security2:error] [pid 139043:tid 139209] [client 20.65.98.162:2536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/gm.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeXgAAAKk"] [Tue Aug 18 13:02:21.110222 2026] [security2:error] [pid 123784:tid 123844] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/rb.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR8gAAETc"] [Tue Aug 18 13:02:21.130036 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:21.130300 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:21.131781 2026] [security2:error] [pid 123784:tid 123810] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/php5.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR9AAARBU"] [Tue Aug 18 13:02:21.136048 2026] [security2:error] [pid 123784:tid 124012] [client 20.251.112.238:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/nw.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR9QAAAF4"] [Tue Aug 18 13:02:21.187394 2026] [security2:error] [pid 139043:tid 139182] [client 20.151.109.219:14102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/32.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeawAAAI4"] [Tue Aug 18 13:02:21.205363 2026] [security2:error] [pid 139043:tid 139281] [client 158.23.17.4:25345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/x.php"] [unique_id "aoSCDf2v-lWn9OzQT7UebgAAAPE"] [Tue Aug 18 13:02:21.205889 2026] [security2:error] [pid 123784:tid 124031] [client 20.151.109.219:58720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kt.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR9gAAAHE"] [Tue Aug 18 13:02:21.251357 2026] [security2:error] [pid 123784:tid 123887] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/37.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR9wAAW2I"] [Tue Aug 18 13:02:21.263736 2026] [security2:error] [pid 123784:tid 123857] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/Black.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR-AAACUQ"] [Tue Aug 18 13:02:21.321092 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.69.59:59243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/av.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR-QAAAH4"] [Tue Aug 18 13:02:21.351426 2026] [security2:error] [pid 123784:tid 124013] [client 213.35.127.232:50156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR-gAAAF8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:21.366450 2026] [security2:error] [pid 123784:tid 124026] [client 20.206.73.37:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR-wAAAGw"] [Tue Aug 18 13:02:21.370012 2026] [security2:error] [pid 123784:tid 124015] [client 185.191.171.14:46986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750238724/1751241600/"] [unique_id "aoSCDWwDnJBNj2tDbYYR_QAAAGE"] [Tue Aug 18 13:02:21.370124 2026] [security2:error] [pid 123784:tid 124015] [client 185.191.171.14:46986] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1750238724/1751241600/"] [unique_id "aoSCDWwDnJBNj2tDbYYR_QAAAGE"] [Tue Aug 18 13:02:21.383059 2026] [security2:error] [pid 139043:tid 139078] [remote 103.56.163.133:36434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adkw.org"] [uri "/wp-login.php"] [unique_id "aoSCDf2v-lWn9OzQT7UecgAA2yI"] [Tue Aug 18 13:02:21.391503 2026] [security2:error] [pid 123784:tid 123832] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/md.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR_gAADCs"] [Tue Aug 18 13:02:21.396266 2026] [security2:error] [pid 123784:tid 123947] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR_AAAHVk"] [Tue Aug 18 13:02:21.398420 2026] [security2:error] [pid 139043:tid 139183] [client 158.158.74.177:3255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/plugin.php"] [unique_id "aoSCDf2v-lWn9OzQT7UecwAAAI8"] [Tue Aug 18 13:02:21.400677 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/filesystems.php"] [unique_id "aoSCDWwDnJBNj2tDbYYR_wAAAlc"] [Tue Aug 18 13:02:21.402443 2026] [security2:error] [pid 123784:tid 124020] [client 172.182.200.96:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/zwlsv.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSAAAAAGY"] [Tue Aug 18 13:02:21.406571 2026] [security2:error] [pid 123784:tid 123990] [client 158.158.74.177:22862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/phpMailer.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSAQAAAEg"] [Tue Aug 18 13:02:21.432803 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:21.433083 2026] [authz_core:error] [pid 123784:tid 123880] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:21.437618 2026] [security2:error] [pid 139043:tid 139291] [client 20.250.13.23:30829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/item.php"] [unique_id "aoSCDf2v-lWn9OzQT7UedQAAAPs"] [Tue Aug 18 13:02:21.449501 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSAwAAAHo"] [Tue Aug 18 13:02:21.456134 2026] [security2:error] [pid 139043:tid 139255] [client 158.23.17.4:8707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fn.php"] [unique_id "aoSCDf2v-lWn9OzQT7UedgAAANc"] [Tue Aug 18 13:02:21.467372 2026] [security2:error] [pid 123784:tid 123999] [client 172.213.243.2:16042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wpo.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSBAAAAFE"] [Tue Aug 18 13:02:21.491916 2026] [security2:error] [pid 123784:tid 124025] [client 20.151.109.219:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/73.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSBQAAAGs"] [Tue Aug 18 13:02:21.499441 2026] [security2:error] [pid 139043:tid 139237] [client 172.202.39.151:63704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/xmrlpc.php"] [unique_id "aoSCDf2v-lWn9OzQT7UefQAAAMU"] [Tue Aug 18 13:02:21.509688 2026] [security2:error] [pid 139043:tid 139283] [client 47.128.57.222:12798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ergoclinica.com.br"] [uri "/robots.txt"] [unique_id "aoSCDf2v-lWn9OzQT7UefwAAAPM"] [Tue Aug 18 13:02:21.527207 2026] [security2:error] [pid 139043:tid 139218] [client 158.23.17.4:47878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/info2.php"] [unique_id "aoSCDf2v-lWn9OzQT7UegAAAALI"] [Tue Aug 18 13:02:21.534585 2026] [security2:error] [pid 123784:tid 123998] [client 4.232.151.198:39196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSCAAAAFA"] [Tue Aug 18 13:02:21.536502 2026] [security2:error] [pid 123784:tid 123904] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSCQAABnM"] [Tue Aug 18 13:02:21.548179 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:55478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/nwwha.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSCgAAACQ"] [Tue Aug 18 13:02:21.568735 2026] [security2:error] [pid 139043:tid 139282] [client 66.187.6.102:37038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/plasticos"] [unique_id "aoSCDf2v-lWn9OzQT7UeggAAAPI"] [Tue Aug 18 13:02:21.568846 2026] [security2:error] [pid 139043:tid 139282] [client 66.187.6.102:37038] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/plasticos"] [unique_id "aoSCDf2v-lWn9OzQT7UeggAAAPI"] [Tue Aug 18 13:02:21.570802 2026] [security2:error] [pid 139043:tid 139244] [client 66.187.6.102:36998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/d96d0c0ac1d8c4c9c4bfb25acf771156.png"] [unique_id "aoSCDf2v-lWn9OzQT7UehgAAAMw"] [Tue Aug 18 13:02:21.570954 2026] [security2:error] [pid 139043:tid 139244] [client 66.187.6.102:36998] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/d96d0c0ac1d8c4c9c4bfb25acf771156.png"] [unique_id "aoSCDf2v-lWn9OzQT7UehgAAAMw"] [Tue Aug 18 13:02:21.572289 2026] [security2:error] [pid 139043:tid 139230] [client 66.187.6.102:36976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/03b064b399c12366e59dbab2ed80ee46.png"] [unique_id "aoSCDf2v-lWn9OzQT7UehwAAAL4"] [Tue Aug 18 13:02:21.572402 2026] [security2:error] [pid 139043:tid 139230] [client 66.187.6.102:36976] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/content/display/03b064b399c12366e59dbab2ed80ee46.png"] [unique_id "aoSCDf2v-lWn9OzQT7UehwAAAL4"] [Tue Aug 18 13:02:21.581657 2026] [security2:error] [pid 139043:tid 139173] [client 20.127.136.245:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/images/wso.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeigAAAIU"] [Tue Aug 18 13:02:21.582764 2026] [security2:error] [pid 139043:tid 139221] [client 20.65.69.59:5411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ag.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeiwAAALU"] [Tue Aug 18 13:02:21.603532 2026] [security2:error] [pid 123784:tid 123846] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/iy.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSDgAAcjk"] [Tue Aug 18 13:02:21.639840 2026] [security2:error] [pid 139043:tid 139215] [client 20.251.112.238:39186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws62.php"] [unique_id "aoSCDf2v-lWn9OzQT7UejgAAAK8"] [Tue Aug 18 13:02:21.701491 2026] [security2:error] [pid 123784:tid 123896] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/phpstatus.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSEgAAYms"] [Tue Aug 18 13:02:21.733571 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:21.733856 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:21.734119 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:15793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yn.php"] [unique_id "aoSCDf2v-lWn9OzQT7UelAAAAOk"] [Tue Aug 18 13:02:21.764337 2026] [security2:error] [pid 139043:tid 139286] [client 20.65.105.233:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCDf2v-lWn9OzQT7UemAAAAPY"] [Tue Aug 18 13:02:21.770499 2026] [security2:error] [pid 123784:tid 123856] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/og.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSFAAAZUM"] [Tue Aug 18 13:02:21.812420 2026] [security2:error] [pid 139043:tid 139203] [client 20.151.109.219:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ww.php"] [unique_id "aoSCDf2v-lWn9OzQT7UemQAAAKM"] [Tue Aug 18 13:02:21.827835 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.200.96:15692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/jrpga.php"] [unique_id "aoSCDf2v-lWn9OzQT7UemgAAAMQ"] [Tue Aug 18 13:02:21.875874 2026] [security2:error] [pid 123784:tid 123799] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/del.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSFgAAIAo"] [Tue Aug 18 13:02:21.879335 2026] [security2:error] [pid 139043:tid 139258] [client 20.65.69.59:5381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ig.php"] [unique_id "aoSCDf2v-lWn9OzQT7UenAAAANo"] [Tue Aug 18 13:02:21.881671 2026] [security2:error] [pid 139043:tid 139207] [client 172.213.243.2:30573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/a1vx.php"] [unique_id "aoSCDf2v-lWn9OzQT7UenQAAAKc"] [Tue Aug 18 13:02:21.886737 2026] [security2:error] [pid 123784:tid 123957] [client 66.187.6.102:36992] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/9550a980ed9257a5621bd9a4d8a6d537.png"] [unique_id "aoSCDWwDnJBNj2tDbYYSFwAAACc"] [Tue Aug 18 13:02:21.890226 2026] [security2:error] [pid 139043:tid 139188] [client 20.65.98.162:2551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/ws55.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeoAAAAJQ"] [Tue Aug 18 13:02:21.906199 2026] [security2:error] [pid 139043:tid 139238] [client 20.151.109.219:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ib.php"] [unique_id "aoSCDf2v-lWn9OzQT7UeowAAAMY"] [Tue Aug 18 13:02:21.908098 2026] [security2:error] [pid 123784:tid 123838] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lp.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSGQAAbjE"] [Tue Aug 18 13:02:21.999754 2026] [security2:error] [pid 139043:tid 139288] [client 132.196.30.78:7683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/aaa.php"] [unique_id "aoSCDf2v-lWn9OzQT7UerQAAAPg"] [Tue Aug 18 13:02:22.002836 2026] [security2:error] [pid 139043:tid 139250] [client 66.187.6.102:37020] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/content/display/4f266cc47b55b9307c830f977753893b.png"] [unique_id "aoSCDv2v-lWn9OzQT7UergAAANI"] [Tue Aug 18 13:02:22.005333 2026] [security2:error] [pid 139043:tid 139209] [client 20.65.105.233:12789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCDv2v-lWn9OzQT7UerwAAAKk"] [Tue Aug 18 13:02:22.013304 2026] [security2:error] [pid 139043:tid 139260] [client 20.116.17.175:55213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/log.php"] [unique_id "aoSCDv2v-lWn9OzQT7UesQAAANw"] [Tue Aug 18 13:02:22.021944 2026] [security2:error] [pid 123784:tid 124039] [client 172.202.39.151:40922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/file.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSGgAAAHk"] [Tue Aug 18 13:02:22.026010 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/moderator.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSGwAAR2g"] [Tue Aug 18 13:02:22.030665 2026] [security2:error] [pid 123784:tid 123988] [client 66.187.6.102:37060] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/es/produtos/trinchas/pads-para-pintura"] [unique_id "aoSCDmwDnJBNj2tDbYYSHAAAAEY"] [Tue Aug 18 13:02:22.034883 2026] [security2:error] [pid 139043:tid 139281] [client 20.251.48.93:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCDv2v-lWn9OzQT7UetAAAAPE"] [Tue Aug 18 13:02:22.044359 2026] [security2:error] [pid 123784:tid 123931] [client 20.79.204.6:10393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/atex1.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSHQAAAA0"] [Tue Aug 18 13:02:22.048109 2026] [security2:error] [pid 139043:tid 139234] [client 216.244.66.232:58656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCDv2v-lWn9OzQT7UeuAAAAMI"] [Tue Aug 18 13:02:22.048209 2026] [security2:error] [pid 139043:tid 139234] [client 216.244.66.232:58656] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCDv2v-lWn9OzQT7UeuAAAAMI"] [Tue Aug 18 13:02:22.052134 2026] [security2:error] [pid 123784:tid 123965] [client 158.158.74.177:10004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSHgAAAC8"] [Tue Aug 18 13:02:22.059456 2026] [security2:error] [pid 123784:tid 123881] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ey.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSHwAAE1w"] [Tue Aug 18 13:02:22.093286 2026] [security2:error] [pid 139043:tid 139263] [client 20.251.112.238:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/public/vx.php"] [unique_id "aoSCDv2v-lWn9OzQT7UeuwAAAN8"] [Tue Aug 18 13:02:22.108342 2026] [security2:error] [pid 123784:tid 124045] [client 130.89.144.170:18990] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.levalixo.com.br"] [uri "/index.php"] [unique_id "aoSCDWwDnJBNj2tDbYYSCwAAAH8"] [Tue Aug 18 13:02:22.134681 2026] [security2:error] [pid 139043:tid 139299] [client 20.250.13.23:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/js.php"] [unique_id "aoSCDv2v-lWn9OzQT7UevQAAAQM"] [Tue Aug 18 13:02:22.155854 2026] [security2:error] [pid 139043:tid 139073] [remote 103.56.163.133:36434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adkw.org"] [uri "/wp-login.php"] [unique_id "aoSCDv2v-lWn9OzQT7UevgAAmx0"], referer: https://adkw.org/wp-login.php [Tue Aug 18 13:02:22.159897 2026] [security2:error] [pid 123784:tid 123975] [client 20.65.69.59:27854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ta.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSIQAAADk"] [Tue Aug 18 13:02:22.160780 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/11.php"] [unique_id "aoSCDv2v-lWn9OzQT7UewAAAALM"] [Tue Aug 18 13:02:22.201760 2026] [security2:error] [pid 123784:tid 123847] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/infoinfo.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSIwAAbzo"] [Tue Aug 18 13:02:22.214483 2026] [security2:error] [pid 139043:tid 139244] [client 20.127.136.245:23636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/index/function.php"] [unique_id "aoSCDv2v-lWn9OzQT7UewgAAAMw"] [Tue Aug 18 13:02:22.232252 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lv.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSJAAAczM"] [Tue Aug 18 13:02:22.236402 2026] [security2:error] [pid 139043:tid 139221] [client 66.187.6.102:36958] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/pinceis-artisticos/diversos-2"] [unique_id "aoSCDv2v-lWn9OzQT7UexQAAALU"] [Tue Aug 18 13:02:22.240949 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.200.96:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/museu/yhweq.php"] [unique_id "aoSCDv2v-lWn9OzQT7UexgAAANA"] [Tue Aug 18 13:02:22.241327 2026] [security2:error] [pid 139043:tid 139222] [client 20.151.109.219:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xm.php"] [unique_id "aoSCDv2v-lWn9OzQT7UexwAAALY"] [Tue Aug 18 13:02:22.244880 2026] [security2:error] [pid 139043:tid 139271] [client 20.65.105.233:12774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ws61.php"] [unique_id "aoSCDv2v-lWn9OzQT7UeyAAAAOc"] [Tue Aug 18 13:02:22.269204 2026] [security2:error] [pid 139043:tid 139267] [client 158.158.74.177:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/public/moon.php"] [unique_id "aoSCDv2v-lWn9OzQT7UeywAAAOM"] [Tue Aug 18 13:02:22.280018 2026] [security2:error] [pid 139043:tid 139268] [client 158.23.17.4:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/de.php"] [unique_id "aoSCDv2v-lWn9OzQT7UezgAAAOQ"] [Tue Aug 18 13:02:22.286775 2026] [security2:error] [pid 139043:tid 139187] [client 66.187.6.102:44974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/es/produtos/pinceis-artisticos/diversos-2"] [unique_id "aoSCDv2v-lWn9OzQT7Ue0AAAAJM"] [Tue Aug 18 13:02:22.286881 2026] [security2:error] [pid 139043:tid 139187] [client 66.187.6.102:44974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/es/produtos/pinceis-artisticos/diversos-2"] [unique_id "aoSCDv2v-lWn9OzQT7Ue0AAAAJM"] [Tue Aug 18 13:02:22.288111 2026] [security2:error] [pid 139043:tid 139180] [client 66.187.6.102:44982] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/es/produtos/limpeza/acessorios-de-limpeza"] [unique_id "aoSCDv2v-lWn9OzQT7Ue0QAAAIw"] [Tue Aug 18 13:02:22.299628 2026] [security2:error] [pid 123784:tid 124037] [client 172.213.243.2:35300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ty.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSJQAAAHc"] [Tue Aug 18 13:02:22.321191 2026] [security2:error] [pid 139043:tid 139282] [client 66.187.6.102:44962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/pinceis-artisticos/diversos-2"] [unique_id "aoSCDv2v-lWn9OzQT7Ue0gAAAPI"] [Tue Aug 18 13:02:22.321326 2026] [security2:error] [pid 139043:tid 139282] [client 66.187.6.102:44962] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/pinceis-artisticos/diversos-2"] [unique_id "aoSCDv2v-lWn9OzQT7Ue0gAAAPI"] [Tue Aug 18 13:02:22.337731 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mo.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue1AAAAPk"] [Tue Aug 18 13:02:22.339262 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:22.339549 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:22.367773 2026] [security2:error] [pid 123784:tid 123888] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/c99shell.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSJwAAU2M"] [Tue Aug 18 13:02:22.369626 2026] [security2:error] [pid 139043:tid 139197] [client 213.35.127.232:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue1gAAAJ0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:22.380503 2026] [security2:error] [pid 123784:tid 123913] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/51.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSKAAATHw"] [Tue Aug 18 13:02:22.441696 2026] [security2:error] [pid 123784:tid 124023] [client 20.118.133.132:53165] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bateriasexpress.aju.br"] [uri "/1.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSKQAAAGk"] [Tue Aug 18 13:02:22.441820 2026] [security2:error] [pid 123784:tid 124023] [client 20.118.133.132:53165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/1.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSKQAAAGk"] [Tue Aug 18 13:02:22.444059 2026] [security2:error] [pid 123784:tid 124014] [client 20.65.69.59:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/34.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSKgAAAGA"] [Tue Aug 18 13:02:22.498394 2026] [security2:error] [pid 123784:tid 123959] [client 20.65.105.233:12748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/rum.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSLAAAACk"] [Tue Aug 18 13:02:22.508881 2026] [security2:error] [pid 123784:tid 123806] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/profiler.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSLQAAAxE"] [Tue Aug 18 13:02:22.511675 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vm.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue3wAAAIs"] [Tue Aug 18 13:02:22.524819 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ew.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSLgAAaA0"] [Tue Aug 18 13:02:22.570989 2026] [security2:error] [pid 139043:tid 139241] [client 20.251.112.238:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/loxi-o.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue5QAAAMk"] [Tue Aug 18 13:02:22.581025 2026] [security2:error] [pid 139043:tid 139265] [client 20.38.3.247:4953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rsmoto.com.br"] [uri "/ajax.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue5gAAAOE"] [Tue Aug 18 13:02:22.588244 2026] [security2:error] [pid 139043:tid 139235] [client 66.187.6.102:36974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/rolos/rolos-de-la-natural"] [unique_id "aoSCDv2v-lWn9OzQT7Ue6AAAAMM"] [Tue Aug 18 13:02:22.616853 2026] [security2:error] [pid 139043:tid 139209] [client 20.151.109.219:39350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zy.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue6gAAAKk"] [Tue Aug 18 13:02:22.627169 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.200.96:15727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/nwwha.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue6wAAAQA"] [Tue Aug 18 13:02:22.640876 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:22.641294 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:22.663531 2026] [security2:error] [pid 123784:tid 123877] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pqr.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSMwAAFFg"] [Tue Aug 18 13:02:22.680430 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/findes.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSNAAAcR0"] [Tue Aug 18 13:02:22.692020 2026] [security2:error] [pid 139043:tid 139269] [client 68.155.154.236:41533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/opsqt.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue9AAAAOU"] [Tue Aug 18 13:02:22.695700 2026] [security2:error] [pid 123784:tid 124043] [client 20.65.69.59:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/he.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSNQAAAH0"] [Tue Aug 18 13:02:22.720966 2026] [security2:error] [pid 139043:tid 139232] [client 172.213.243.2:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/vgtyu.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue9QAAAMA"] [Tue Aug 18 13:02:22.728391 2026] [security2:error] [pid 139043:tid 139297] [client 20.203.183.135:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/adminner.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue9gAAAQE"] [Tue Aug 18 13:02:22.729250 2026] [security2:error] [pid 123784:tid 124044] [client 20.151.109.219:13819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/qr.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSNwAAAH4"] [Tue Aug 18 13:02:22.738604 2026] [security2:error] [pid 139043:tid 139189] [client 158.158.74.177:22860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/al.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue9wAAAJU"] [Tue Aug 18 13:02:22.753888 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.105.233:12418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ze.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue-wAAALA"] [Tue Aug 18 13:02:22.768709 2026] [security2:error] [pid 123784:tid 123941] [client 66.187.6.102:45116] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/trinchas/trinchas-medias"] [unique_id "aoSCDmwDnJBNj2tDbYYSOAAAABc"] [Tue Aug 18 13:02:22.802576 2026] [security2:error] [pid 123784:tid 123867] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/an.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSOQAAX04"] [Tue Aug 18 13:02:22.811685 2026] [security2:error] [pid 139043:tid 139261] [client 20.127.136.245:23807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/info.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue_QAAAN0"] [Tue Aug 18 13:02:22.812318 2026] [security2:error] [pid 139043:tid 139206] [client 20.250.13.23:3134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/k.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue_gAAAKY"] [Tue Aug 18 13:02:22.837169 2026] [security2:error] [pid 123784:tid 123895] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/fedora.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSOgAAO2o"] [Tue Aug 18 13:02:22.861441 2026] [security2:error] [pid 139043:tid 139203] [client 168.119.96.239:38842] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCDv2v-lWn9OzQT7Ue5wAAAKM"], referer: https://agrimotor.com.br [Tue Aug 18 13:02:22.866004 2026] [security2:error] [pid 139043:tid 139252] [client 114.119.135.120:52955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/wp-content/uploads/2021/07/configuracoes_gestao_conteudo_caminho.gif"] [unique_id "aoSCDv2v-lWn9OzQT7UfBgAAANQ"], referer: https://ajuda.oruc.com.br/wp-content/uploads/2021/07/configuracoes_gestao_conteudo_caminho.gif [Tue Aug 18 13:02:22.866175 2026] [security2:error] [pid 139043:tid 139173] [client 168.62.48.100:5479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCDv2v-lWn9OzQT7UfBQAAAIU"] [Tue Aug 18 13:02:22.878901 2026] [security2:error] [pid 123784:tid 123983] [client 86.120.159.145:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSPAAAAEE"] [Tue Aug 18 13:02:22.879088 2026] [security2:error] [pid 123784:tid 123983] [client 86.120.159.145:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSPAAAAEE"] [Tue Aug 18 13:02:22.901191 2026] [security2:error] [pid 123784:tid 124009] [client 158.158.74.177:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/public/storage.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSPQAAAFs"] [Tue Aug 18 13:02:22.939429 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:22.939674 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:22.941879 2026] [security2:error] [pid 123784:tid 123912] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sy.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSPwAAM3s"] [Tue Aug 18 13:02:22.943653 2026] [security2:error] [pid 123784:tid 123930] [client 20.65.69.59:5728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gz.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSQAAAAAw"] [Tue Aug 18 13:02:22.993889 2026] [security2:error] [pid 123784:tid 123830] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/path.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSQQAAHSk"] [Tue Aug 18 13:02:22.996354 2026] [security2:error] [pid 139043:tid 139217] [client 20.65.105.233:12762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/gjm.php"] [unique_id "aoSCDv2v-lWn9OzQT7UfFAAAALE"] [Tue Aug 18 13:02:22.998163 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/q.php"] [unique_id "aoSCDmwDnJBNj2tDbYYSQgAAAGY"] [Tue Aug 18 13:02:23.013828 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/eg.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSQwAAADY"] [Tue Aug 18 13:02:23.014166 2026] [authz_core:error] [pid 139043:tid 139109] [remote 57.141.22.109:36288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:23.014452 2026] [authz_core:error] [pid 139043:tid 139109] [remote 57.141.22.109:36288] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:23.020859 2026] [security2:error] [pid 123784:tid 124017] [client 4.232.151.198:24834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/function/function.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSRAAAAGM"] [Tue Aug 18 13:02:23.039779 2026] [security2:error] [pid 139043:tid 139264] [client 20.251.112.238:15019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sdsa.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfGAAAAOA"] [Tue Aug 18 13:02:23.063813 2026] [security2:error] [pid 139043:tid 139276] [client 68.155.154.236:41525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfGQAAAOw"] [Tue Aug 18 13:02:23.092531 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:34017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/album.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfGwAAANs"] [Tue Aug 18 13:02:23.108515 2026] [security2:error] [pid 123784:tid 123822] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/57.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSRQAAACE"] [Tue Aug 18 13:02:23.114448 2026] [security2:error] [pid 139043:tid 139251] [client 158.23.17.4:10976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kf.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfHAAAANM"] [Tue Aug 18 13:02:23.149618 2026] [security2:error] [pid 139043:tid 139224] [client 172.213.243.2:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mans.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfHgAAALg"] [Tue Aug 18 13:02:23.151911 2026] [security2:error] [pid 139043:tid 139154] [remote 114.119.153.215:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "altostima.com.br"] [uri "/tricologia/tricologista-profissional-cuida-dos-cabelos"] [unique_id "aoSCD_2v-lWn9OzQT7UfHwAAzG4"], referer: https://www.altostima.com.br/cliente/index.php?rp=%2Fknowledgebase%2F14%2F-QUEDA-DE-CABELO-EMOCIONAL-UM-PROBLEMA-DA-MODERNIDADE.html&language=portuguese-pt [Tue Aug 18 13:02:23.159605 2026] [security2:error] [pid 123784:tid 123854] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/456.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSRgAAUEE"] [Tue Aug 18 13:02:23.198213 2026] [security2:error] [pid 139043:tid 139233] [client 20.127.136.245:16876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/profile.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfIgAAAME"] [Tue Aug 18 13:02:23.236653 2026] [security2:error] [pid 139043:tid 139179] [client 20.65.105.233:12761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/new4.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfJQAAAIs"] [Tue Aug 18 13:02:23.242470 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:23.242759 2026] [authz_core:error] [pid 123784:tid 123831] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:23.245800 2026] [security2:error] [pid 123784:tid 124010] [client 68.155.154.236:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSSAAAAFw"] [Tue Aug 18 13:02:23.248337 2026] [security2:error] [pid 123784:tid 123909] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ah.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSSQAAEHg"] [Tue Aug 18 13:02:23.249643 2026] [security2:error] [pid 139043:tid 139200] [client 172.182.200.96:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/opsqt.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfKAAAAKA"] [Tue Aug 18 13:02:23.267655 2026] [security2:error] [pid 139043:tid 139279] [client 172.202.39.151:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/epinyins.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfKQAAAO8"] [Tue Aug 18 13:02:23.277272 2026] [security2:error] [pid 139043:tid 139275] [client 20.251.48.93:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/av.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfKgAAAOs"] [Tue Aug 18 13:02:23.296170 2026] [security2:error] [pid 139043:tid 139191] [client 20.151.109.219:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xf.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfLQAAAJc"] [Tue Aug 18 13:02:23.318876 2026] [security2:error] [pid 139043:tid 139257] [client 20.116.17.175:23000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ohct.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfLwAAANk"] [Tue Aug 18 13:02:23.326184 2026] [security2:error] [pid 123784:tid 123850] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/SMTP.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSSgAASz0"] [Tue Aug 18 13:02:23.376984 2026] [security2:error] [pid 139043:tid 139285] [client 158.158.74.177:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfMAAAAPU"] [Tue Aug 18 13:02:23.384074 2026] [security2:error] [pid 139043:tid 139220] [client 20.65.69.59:9679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nf.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfMQAAALQ"] [Tue Aug 18 13:02:23.385838 2026] [security2:error] [pid 139043:tid 139286] [client 213.35.127.232:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfMgAAAPY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:23.392520 2026] [security2:error] [pid 123784:tid 124040] [client 20.79.204.6:10428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSSwAAAHo"] [Tue Aug 18 13:02:23.448550 2026] [security2:error] [pid 123784:tid 123884] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vw.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSTQAAK18"] [Tue Aug 18 13:02:23.449055 2026] [security2:error] [pid 123784:tid 123996] [client 20.250.13.23:3590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/media/index.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSTgAAAE4"] [Tue Aug 18 13:02:23.471834 2026] [security2:error] [pid 123784:tid 123827] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/vbseo.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSTwAAPiY"] [Tue Aug 18 13:02:23.473474 2026] [security2:error] [pid 123784:tid 123923] [client 20.151.109.219:13822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dirs.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSUAAAAAU"] [Tue Aug 18 13:02:23.477033 2026] [security2:error] [pid 139043:tid 139181] [client 20.65.105.233:12426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-act.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfNgAAAI0"] [Tue Aug 18 13:02:23.499657 2026] [security2:error] [pid 139043:tid 139232] [client 20.251.112.238:40637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-freya.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfOAAAAMA"] [Tue Aug 18 13:02:23.505840 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.56.190:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/twin.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfOQAAAJ4"] [Tue Aug 18 13:02:23.522959 2026] [security2:error] [pid 123784:tid 124006] [client 158.158.74.177:3688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/radio.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSUQAAAFg"] [Tue Aug 18 13:02:23.535065 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:46803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/uk.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSUwAAAAs"] [Tue Aug 18 13:02:23.536901 2026] [security2:error] [pid 139043:tid 139231] [client 68.155.154.236:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfOgAAAL8"] [Tue Aug 18 13:02:23.542485 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:23.542743 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:23.565206 2026] [security2:error] [pid 123784:tid 123968] [client 172.213.243.2:15038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/co.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSVAAAADI"] [Tue Aug 18 13:02:23.606244 2026] [security2:error] [pid 139043:tid 139183] [client 20.151.109.219:16286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gb.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfPQAAAI8"] [Tue Aug 18 13:02:23.631110 2026] [security2:error] [pid 123784:tid 123874] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lj.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSVgAAIFU"] [Tue Aug 18 13:02:23.638359 2026] [security2:error] [pid 123784:tid 123957] [client 172.182.200.96:15716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/jvcpa.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSVwAAACc"] [Tue Aug 18 13:02:23.660776 2026] [security2:error] [pid 139043:tid 139195] [client 20.65.69.59:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xv.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfQgAAAJs"] [Tue Aug 18 13:02:23.717447 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.105.233:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/grsiuk.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfRAAAAN0"] [Tue Aug 18 13:02:23.719305 2026] [security2:error] [pid 123784:tid 123814] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/sysinfo.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSWAAAexk"] [Tue Aug 18 13:02:23.808695 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kh.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSWQAAE0Y"] [Tue Aug 18 13:02:23.844887 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:23.845172 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:23.880175 2026] [security2:error] [pid 139043:tid 139212] [client 158.23.17.4:57231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kv.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfWQAAAKw"] [Tue Aug 18 13:02:23.904954 2026] [security2:error] [pid 123784:tid 123879] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/ppinfo.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSXAAAXVo"] [Tue Aug 18 13:02:23.917015 2026] [security2:error] [pid 139043:tid 139268] [client 20.127.136.245:23753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/sx.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfXAAAAOQ"] [Tue Aug 18 13:02:23.933191 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jp.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfXgAAAIw"] [Tue Aug 18 13:02:23.946128 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ot.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSXQAAACM"] [Tue Aug 18 13:02:23.948111 2026] [security2:error] [pid 139043:tid 139192] [client 20.65.69.59:5437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mx.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfYgAAAJg"] [Tue Aug 18 13:02:23.955243 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:14035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/creds.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfYwAAAIY"] [Tue Aug 18 13:02:23.956946 2026] [security2:error] [pid 139043:tid 139282] [client 20.65.105.233:12419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/h.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfZAAAAPI"] [Tue Aug 18 13:02:23.978139 2026] [security2:error] [pid 123784:tid 123855] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jb.php"] [unique_id "aoSCD2wDnJBNj2tDbYYSXgAAf0I"] [Tue Aug 18 13:02:23.989138 2026] [security2:error] [pid 139043:tid 139204] [client 172.213.243.2:30530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/btx25.php"] [unique_id "aoSCD_2v-lWn9OzQT7UfZgAAAKQ"] [Tue Aug 18 13:02:24.001174 2026] [security2:error] [pid 139043:tid 139289] [client 20.251.112.238:18206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fleen.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfaAAAAPk"] [Tue Aug 18 13:02:24.003739 2026] [security2:error] [pid 139043:tid 139253] [client 172.182.200.96:15700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfaQAAANU"] [Tue Aug 18 13:02:24.023982 2026] [security2:error] [pid 139043:tid 139221] [client 158.158.74.177:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-activat.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfagAAALU"] [Tue Aug 18 13:02:24.036924 2026] [security2:error] [pid 123784:tid 123866] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/globals.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSXwAAT00"] [Tue Aug 18 13:02:24.039881 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.154.236:41480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfbAAAAOk"] [Tue Aug 18 13:02:24.058258 2026] [security2:error] [pid 139043:tid 139105] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/phpinfo.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfbQAAzT0"] [Tue Aug 18 13:02:24.096958 2026] [security2:error] [pid 139043:tid 139078] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/info.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfbgAAuiI"] [Tue Aug 18 13:02:24.126374 2026] [security2:error] [pid 139043:tid 139225] [client 213.202.253.4:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/postnews.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfcgAAALk"], referer: www.google.com [Tue Aug 18 13:02:24.142184 2026] [security2:error] [pid 139043:tid 139274] [client 20.151.109.219:27747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sn.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfcwAAAOo"] [Tue Aug 18 13:02:24.144410 2026] [security2:error] [pid 139043:tid 139179] [client 20.65.98.162:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/m.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfdAAAAIs"] [Tue Aug 18 13:02:24.145048 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:24.145290 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:24.153805 2026] [security2:error] [pid 139043:tid 139271] [client 158.158.74.177:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/root.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfdQAAAOc"] [Tue Aug 18 13:02:24.163970 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/do.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSYgAAb3I"] [Tue Aug 18 13:02:24.185290 2026] [security2:error] [pid 139043:tid 139092] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/test.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfdgABBDA"] [Tue Aug 18 13:02:24.192154 2026] [security2:error] [pid 139043:tid 139127] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/pi.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfdwAAkVM"] [Tue Aug 18 13:02:24.203879 2026] [security2:error] [pid 139043:tid 139284] [client 20.65.105.233:12441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/koiy.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfeAAAAPQ"] [Tue Aug 18 13:02:24.209262 2026] [security2:error] [pid 139043:tid 139197] [client 20.250.13.23:20345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/memberfuns.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfeQAAAJ0"] [Tue Aug 18 13:02:24.271625 2026] [security2:error] [pid 139043:tid 139059] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/i.php"] [unique_id "aoSCEP2v-lWn9OzQT7UffQAArQ8"] [Tue Aug 18 13:02:24.287972 2026] [security2:error] [pid 139043:tid 139220] [client 20.151.109.219:24423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/eq.php"] [unique_id "aoSCEP2v-lWn9OzQT7UffgAAALQ"] [Tue Aug 18 13:02:24.298535 2026] [security2:error] [pid 139043:tid 139287] [client 20.65.69.59:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/45.php"] [unique_id "aoSCEP2v-lWn9OzQT7UffwAAAPc"] [Tue Aug 18 13:02:24.324642 2026] [security2:error] [pid 139043:tid 139250] [client 132.196.30.78:24267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/term.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfggAAANI"] [Tue Aug 18 13:02:24.358823 2026] [security2:error] [pid 139043:tid 139296] [client 158.23.17.4:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ho.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfhAAAAQA"] [Tue Aug 18 13:02:24.391184 2026] [security2:error] [pid 139043:tid 139079] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/app_dev.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfhQAA3CM"] [Tue Aug 18 13:02:24.398032 2026] [security2:error] [pid 139043:tid 139100] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSCEP2v-lWn9OzQT7UfiQAApTg"] [Tue Aug 18 13:02:24.401251 2026] [security2:error] [pid 139043:tid 139276] [client 213.35.127.232:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfiwAAAOw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:24.403942 2026] [security2:error] [pid 123784:tid 123914] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/yw.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSaQAAd30"] [Tue Aug 18 13:02:24.410434 2026] [security2:error] [pid 123784:tid 123971] [client 172.213.243.2:18000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/avim.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSagAAADU"] [Tue Aug 18 13:02:24.413894 2026] [security2:error] [pid 123784:tid 123949] [client 172.182.200.96:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSawAAAB8"] [Tue Aug 18 13:02:24.430761 2026] [security2:error] [pid 123784:tid 123790] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/yindu.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSbAAALQE"] [Tue Aug 18 13:02:24.444054 2026] [security2:error] [pid 123784:tid 123952] [client 20.65.105.233:12438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fff.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSbgAAACI"] [Tue Aug 18 13:02:24.445093 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:24.445360 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:24.455408 2026] [security2:error] [pid 123784:tid 124001] [client 20.251.112.238:40584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/e.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSbwAAAFM"] [Tue Aug 18 13:02:24.482267 2026] [security2:error] [pid 123784:tid 123925] [client 20.116.17.175:22925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/v5.php"] [unique_id "aoSCEGwDnJBNj2tDbYYScAAAAAc"] [Tue Aug 18 13:02:24.559549 2026] [security2:error] [pid 139043:tid 139291] [client 158.23.17.4:60345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sx.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfkAAAAPs"] [Tue Aug 18 13:02:24.572524 2026] [security2:error] [pid 139043:tid 139237] [client 158.23.17.4:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/su.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfkQAAAMU"] [Tue Aug 18 13:02:24.587120 2026] [security2:error] [pid 123784:tid 123812] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/qh.php"] [unique_id "aoSCEGwDnJBNj2tDbYYScgAAVBc"] [Tue Aug 18 13:02:24.610897 2026] [security2:error] [pid 123784:tid 123886] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/sxx.php"] [unique_id "aoSCEGwDnJBNj2tDbYYScwAAVmE"] [Tue Aug 18 13:02:24.611577 2026] [security2:error] [pid 123784:tid 124014] [client 20.151.109.219:34032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ep.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSdAAAAGA"] [Tue Aug 18 13:02:24.613003 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.69.59:43299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wy.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfkwAAAMc"] [Tue Aug 18 13:02:24.635928 2026] [access_compat:error] [pid 139043:tid 139108] [remote 34.62.54.143:48908] AH01797: client denied by server configuration: /home3/tentac25/_wildcard_.tentaclehost.com.br/server-status [Tue Aug 18 13:02:24.684274 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.105.233:12753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/pouhg.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfmQAAAN0"] [Tue Aug 18 13:02:24.705822 2026] [security2:error] [pid 123784:tid 123991] [client 158.158.74.177:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSdQAAAEk"] [Tue Aug 18 13:02:24.725495 2026] [security2:error] [pid 123784:tid 123813] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/r.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSdgAAKhg"] [Tue Aug 18 13:02:24.745869 2026] [security2:error] [pid 139043:tid 139175] [client 20.127.136.245:19595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfnQAAAIc"] [Tue Aug 18 13:02:24.748694 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:24.749069 2026] [authz_core:error] [pid 123784:tid 123900] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:24.773413 2026] [security2:error] [pid 139043:tid 139231] [client 158.158.74.177:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/server.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfnwAAAL8"] [Tue Aug 18 13:02:24.775740 2026] [security2:error] [pid 139043:tid 139218] [client 158.23.17.4:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/97.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfoAAAALI"] [Tue Aug 18 13:02:24.779166 2026] [security2:error] [pid 123784:tid 123803] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/settings.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSeAAARA4"] [Tue Aug 18 13:02:24.783299 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:28362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/z.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfoQAAAJk"] [Tue Aug 18 13:02:24.807736 2026] [security2:error] [pid 123784:tid 124012] [client 172.202.39.151:40921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSeQAAAF4"] [Tue Aug 18 13:02:24.807788 2026] [security2:error] [pid 139043:tid 139113] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/server-info"] [unique_id "aoSCEP2v-lWn9OzQT7UfogAA5kU"] [Tue Aug 18 13:02:24.811544 2026] [security2:error] [pid 139043:tid 139117] [remote 57.141.22.51:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCEP2v-lWn9OzQT7UfpAAAvkk"] [Tue Aug 18 13:02:24.828639 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:17456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/myfile.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfpQAAAL0"] [Tue Aug 18 13:02:24.839562 2026] [security2:error] [pid 139043:tid 139294] [client 20.250.13.23:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/mgrr.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfpgAAAP4"] [Tue Aug 18 13:02:24.876522 2026] [security2:error] [pid 139043:tid 139187] [client 20.79.204.6:10376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/w.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfqAAAAJM"] [Tue Aug 18 13:02:24.880796 2026] [security2:error] [pid 139043:tid 139277] [client 20.65.69.59:5392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/f.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfqQAAAO0"] [Tue Aug 18 13:02:24.895228 2026] [security2:error] [pid 139043:tid 139189] [client 20.251.112.238:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/hello.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfqgAAAJU"] [Tue Aug 18 13:02:24.913179 2026] [security2:error] [pid 123784:tid 123848] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/spip.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSegAAFTs"] [Tue Aug 18 13:02:24.914677 2026] [security2:error] [pid 123784:tid 123805] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/17.php"] [unique_id "aoSCEGwDnJBNj2tDbYYSewAAFBA"] [Tue Aug 18 13:02:24.924571 2026] [security2:error] [pid 139043:tid 139174] [client 20.151.109.219:37267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rf.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfrAAAAIY"] [Tue Aug 18 13:02:24.925249 2026] [security2:error] [pid 139043:tid 139282] [client 20.65.105.233:12791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/moon3.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfrQAAAPI"] [Tue Aug 18 13:02:24.959837 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.154.236:55445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfsAAAAOk"] [Tue Aug 18 13:02:24.970236 2026] [security2:error] [pid 139043:tid 139251] [client 172.182.200.96:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCEP2v-lWn9OzQT7UftQAAANM"] [Tue Aug 18 13:02:24.998282 2026] [security2:error] [pid 139043:tid 139211] [client 132.196.30.78:24292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/7.php"] [unique_id "aoSCEP2v-lWn9OzQT7UfuQAAAKs"] [Tue Aug 18 13:02:25.049736 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:25.050186 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:25.051653 2026] [security2:error] [pid 123784:tid 123898] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/search.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSfQAAOm0"] [Tue Aug 18 13:02:25.080236 2026] [security2:error] [pid 123784:tid 123897] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ev.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSfgAAF2w"] [Tue Aug 18 13:02:25.152612 2026] [security2:error] [pid 139043:tid 139298] [client 20.226.56.190:2801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/new2.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfvwAAAQI"] [Tue Aug 18 13:02:25.158665 2026] [security2:error] [pid 139043:tid 139200] [client 20.65.69.59:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/30.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfwAAAAKA"] [Tue Aug 18 13:02:25.164960 2026] [security2:error] [pid 139043:tid 139300] [client 20.65.105.233:12432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/opts.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfwQAAAQQ"] [Tue Aug 18 13:02:25.216971 2026] [security2:error] [pid 139043:tid 139265] [client 20.151.109.219:60397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xynz1.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfwwAAAOE"] [Tue Aug 18 13:02:25.237656 2026] [security2:error] [pid 123784:tid 123793] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/build.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSfwAAOwQ"] [Tue Aug 18 13:02:25.242876 2026] [security2:error] [pid 139043:tid 139202] [client 172.213.243.2:11482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xmy.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfxQAAAKI"] [Tue Aug 18 13:02:25.251471 2026] [security2:error] [pid 123784:tid 123858] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xs.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSgAAAYUU"] [Tue Aug 18 13:02:25.269331 2026] [security2:error] [pid 139043:tid 139216] [client 102.213.179.104:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfxgAAALA"] [Tue Aug 18 13:02:25.270654 2026] [security2:error] [pid 139043:tid 139216] [client 102.213.179.104:53519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfxgAAALA"] [Tue Aug 18 13:02:25.298276 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:9356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wp-key.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfxwAAAME"] [Tue Aug 18 13:02:25.308760 2026] [security2:error] [pid 123784:tid 124009] [client 158.23.17.4:40403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rh.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSgQAAAFs"] [Tue Aug 18 13:02:25.349422 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:25.349680 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:25.356030 2026] [security2:error] [pid 139043:tid 139199] [client 20.251.112.238:40598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/brc.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfzAAAAJ8"] [Tue Aug 18 13:02:25.360470 2026] [security2:error] [pid 139043:tid 139271] [client 158.158.74.177:22885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/past1.php"] [unique_id "aoSCEf2v-lWn9OzQT7UfzQAAAOc"] [Tue Aug 18 13:02:25.373112 2026] [security2:error] [pid 139043:tid 139085] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.env"] [unique_id "aoSCEf2v-lWn9OzQT7UfzwAA9yk"] [Tue Aug 18 13:02:25.389658 2026] [security2:error] [pid 139043:tid 139209] [client 20.116.17.175:22952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf0QAAAKk"] [Tue Aug 18 13:02:25.393190 2026] [security2:error] [pid 123784:tid 123872] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCEWwDnJBNj2tDbYYShAAADlM"] [Tue Aug 18 13:02:25.396473 2026] [security2:error] [pid 139043:tid 139275] [client 158.158.74.177:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf0gAAAOs"] [Tue Aug 18 13:02:25.399653 2026] [security2:error] [pid 139043:tid 139250] [client 20.127.136.245:6043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.turial.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf0wAAANI"] [Tue Aug 18 13:02:25.405183 2026] [security2:error] [pid 139043:tid 139278] [client 20.65.105.233:12767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/zwq13.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf1QAAAO4"] [Tue Aug 18 13:02:25.409297 2026] [security2:error] [pid 123784:tid 123892] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/defaul.php"] [unique_id "aoSCEWwDnJBNj2tDbYYShQAAM2c"] [Tue Aug 18 13:02:25.421934 2026] [security2:error] [pid 139043:tid 139214] [client 213.35.127.232:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf1gAAAK4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:25.471459 2026] [security2:error] [pid 139043:tid 139234] [client 172.182.200.96:15723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf2AAAAMI"] [Tue Aug 18 13:02:25.534410 2026] [security2:error] [pid 123784:tid 123862] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fd.php"] [unique_id "aoSCEWwDnJBNj2tDbYYShgAADEk"] [Tue Aug 18 13:02:25.544610 2026] [security2:error] [pid 123784:tid 123804] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/twin.php"] [unique_id "aoSCEWwDnJBNj2tDbYYShwAAHQ8"] [Tue Aug 18 13:02:25.545757 2026] [security2:error] [pid 139043:tid 139240] [client 20.65.69.59:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pu.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf2wAAAMg"] [Tue Aug 18 13:02:25.583012 2026] [security2:error] [pid 139043:tid 139232] [client 20.151.109.219:39317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vo.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf3AAAAMA"] [Tue Aug 18 13:02:25.585915 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.56.190:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/rex.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf3gAAAI4"] [Tue Aug 18 13:02:25.646906 2026] [security2:error] [pid 139043:tid 139247] [client 20.65.105.233:12785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/Okxob.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf3wAAAM8"] [Tue Aug 18 13:02:25.649399 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:25.649666 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:25.651985 2026] [security2:error] [pid 139043:tid 139256] [client 172.213.243.2:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xda.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf4QAAANg"] [Tue Aug 18 13:02:25.703768 2026] [security2:error] [pid 123784:tid 123841] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/info2.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSiQAAZjQ"] [Tue Aug 18 13:02:25.723629 2026] [security2:error] [pid 123784:tid 123990] [client 20.151.109.219:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/43.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSigAAAEg"] [Tue Aug 18 13:02:25.749091 2026] [security2:error] [pid 139043:tid 139157] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.env.bak"] [unique_id "aoSCEf2v-lWn9OzQT7Uf4wAA1HE"] [Tue Aug 18 13:02:25.751443 2026] [security2:error] [pid 139043:tid 139147] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf5AAAzmc"] [Tue Aug 18 13:02:25.751617 2026] [security2:error] [pid 139043:tid 139246] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf5AAAzmc"] [Tue Aug 18 13:02:25.800734 2026] [security2:error] [pid 139043:tid 139193] [client 132.196.30.78:1366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/file5.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf5wAAAJk"] [Tue Aug 18 13:02:25.828259 2026] [security2:error] [pid 139043:tid 139270] [client 20.65.69.59:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ry.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf6AAAAOY"] [Tue Aug 18 13:02:25.841648 2026] [security2:error] [pid 123784:tid 123791] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSiwAANgI"] [Tue Aug 18 13:02:25.869542 2026] [security2:error] [pid 139043:tid 139294] [client 20.251.48.93:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/images.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf6gAAAP4"] [Tue Aug 18 13:02:25.877778 2026] [security2:error] [pid 139043:tid 139190] [client 158.23.17.4:63032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/yg.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf6wAAAJY"] [Tue Aug 18 13:02:25.884378 2026] [security2:error] [pid 123784:tid 124005] [client 20.251.112.238:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/file52.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSjAAAAFc"] [Tue Aug 18 13:02:25.888072 2026] [security2:error] [pid 139043:tid 139187] [client 20.65.105.233:12765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/file59.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf7AAAAJM"] [Tue Aug 18 13:02:25.936929 2026] [security2:error] [pid 123784:tid 123823] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/new2.php"] [unique_id "aoSCEWwDnJBNj2tDbYYSjQAAACI"] [Tue Aug 18 13:02:25.937744 2026] [security2:error] [pid 139043:tid 139277] [client 20.250.13.23:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/mini.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf7QAAAO0"] [Tue Aug 18 13:02:25.950337 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:25.950604 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:25.960383 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wu.php"] [unique_id "aoSCEf2v-lWn9OzQT7Uf7wAAAIw"] [Tue Aug 18 13:02:26.003496 2026] [security2:error] [pid 139043:tid 139215] [client 158.23.17.4:9300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gg.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf8AAAAK8"] [Tue Aug 18 13:02:26.011432 2026] [security2:error] [pid 123784:tid 123843] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nu.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSkAAAJDY"] [Tue Aug 18 13:02:26.017829 2026] [security2:error] [pid 139043:tid 139186] [client 158.158.74.177:3246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/shell.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf8QAAAJI"] [Tue Aug 18 13:02:26.044757 2026] [security2:error] [pid 139043:tid 139060] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/backend/.env"] [unique_id "aoSCEv2v-lWn9OzQT7Uf8wAA6RA"] [Tue Aug 18 13:02:26.075230 2026] [security2:error] [pid 139043:tid 139255] [client 172.213.243.2:17723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zz.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf9QAAANc"] [Tue Aug 18 13:02:26.080879 2026] [security2:error] [pid 139043:tid 139154] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/api/.env"] [unique_id "aoSCEv2v-lWn9OzQT7Uf9wAA224"] [Tue Aug 18 13:02:26.084512 2026] [security2:error] [pid 139043:tid 139155] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.env.old"] [unique_id "aoSCEv2v-lWn9OzQT7Uf-AAA028"] [Tue Aug 18 13:02:26.087761 2026] [security2:error] [pid 139043:tid 139103] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.env.backup"] [unique_id "aoSCEv2v-lWn9OzQT7Uf-QAAyzs"] [Tue Aug 18 13:02:26.101669 2026] [security2:error] [pid 139043:tid 139263] [client 20.79.204.6:10395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/archive.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf-wAAAN8"] [Tue Aug 18 13:02:26.105095 2026] [security2:error] [pid 139043:tid 139195] [client 149.34.210.141:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf_AAAAJs"] [Tue Aug 18 13:02:26.115107 2026] [security2:error] [pid 123784:tid 123936] [client 20.226.56.190:47122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/verification.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSkgAAABI"] [Tue Aug 18 13:02:26.118928 2026] [security2:error] [pid 123784:tid 123911] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/rex.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSkwAAK3o"] [Tue Aug 18 13:02:26.128640 2026] [security2:error] [pid 139043:tid 139177] [client 20.65.105.233:12756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/eauu.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf_gAAAIk"] [Tue Aug 18 13:02:26.147242 2026] [security2:error] [pid 123784:tid 124025] [client 158.158.74.177:9821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/file61.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSlAAAAGs"] [Tue Aug 18 13:02:26.156102 2026] [security2:error] [pid 123784:tid 123816] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ko.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSlQAAZBs"] [Tue Aug 18 13:02:26.171183 2026] [security2:error] [pid 123784:tid 123980] [client 158.23.17.4:8959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xg.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSlwAAAD4"] [Tue Aug 18 13:02:26.177261 2026] [security2:error] [pid 123784:tid 123923] [client 20.65.69.59:27863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pm.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSmAAAAAU"] [Tue Aug 18 13:02:26.251782 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:26.252043 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:26.270325 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:8664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nu.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgBgAAAOE"] [Tue Aug 18 13:02:26.285411 2026] [security2:error] [pid 123784:tid 124006] [client 172.182.200.96:15640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSmgAAAFg"] [Tue Aug 18 13:02:26.292351 2026] [security2:error] [pid 123784:tid 123899] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/verification.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSmwAAam4"] [Tue Aug 18 13:02:26.296392 2026] [security2:error] [pid 139043:tid 139202] [client 20.151.109.219:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/de.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgCAAAAKI"] [Tue Aug 18 13:02:26.307007 2026] [security2:error] [pid 139043:tid 139213] [client 20.206.73.37:34805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgCQAAAK0"] [Tue Aug 18 13:02:26.341543 2026] [security2:error] [pid 123784:tid 123870] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/pl.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSnAAAKFE"] [Tue Aug 18 13:02:26.343862 2026] [security2:error] [pid 139043:tid 139271] [client 20.151.109.219:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fresh.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgCwAAAOc"] [Tue Aug 18 13:02:26.368880 2026] [security2:error] [pid 139043:tid 139287] [client 20.65.105.233:12779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/dsd.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgDAAAAPc"] [Tue Aug 18 13:02:26.373129 2026] [security2:error] [pid 139043:tid 139195] [client 149.34.210.141:61487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7Uf_AAAAJs"] [Tue Aug 18 13:02:26.383603 2026] [security2:error] [pid 139043:tid 139233] [client 138.36.100.162:41432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgDgAAAME"] [Tue Aug 18 13:02:26.383685 2026] [security2:error] [pid 139043:tid 139233] [client 138.36.100.162:41432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgDgAAAME"] [Tue Aug 18 13:02:26.384388 2026] [security2:error] [pid 139043:tid 139139] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/config/.env"] [unique_id "aoSCEv2v-lWn9OzQT7UgDwAAqV8"] [Tue Aug 18 13:02:26.392555 2026] [security2:error] [pid 139043:tid 139250] [client 68.155.154.236:8365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgEgAAANI"] [Tue Aug 18 13:02:26.400985 2026] [security2:error] [pid 123784:tid 123957] [client 20.251.112.238:34729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSnQAAACc"] [Tue Aug 18 13:02:26.411105 2026] [security2:error] [pid 139043:tid 139217] [client 158.23.17.4:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/et.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgFwAAALE"] [Tue Aug 18 13:02:26.437203 2026] [security2:error] [pid 139043:tid 139228] [client 213.35.127.232:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgGAAAALw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:26.459055 2026] [security2:error] [pid 123784:tid 124039] [client 20.65.69.59:9664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/dr.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSngAAAHk"] [Tue Aug 18 13:02:26.479846 2026] [security2:error] [pid 123784:tid 123851] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/env.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSnwAABj4"] [Tue Aug 18 13:02:26.483886 2026] [security2:error] [pid 139043:tid 139269] [client 132.196.30.78:19188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgGQAAAOU"] [Tue Aug 18 13:02:26.508046 2026] [security2:error] [pid 139043:tid 139258] [client 172.213.243.2:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xa.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgGwAAANo"] [Tue Aug 18 13:02:26.519688 2026] [security2:error] [pid 123784:tid 123864] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/smtp.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSoAAAR0s"] [Tue Aug 18 13:02:26.552344 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:26.552613 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:26.576163 2026] [security2:error] [pid 139043:tid 139291] [client 158.23.17.4:9292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gi.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgHwAAAPs"] [Tue Aug 18 13:02:26.582451 2026] [security2:error] [pid 123784:tid 124019] [client 20.250.13.23:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/minishell.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSpAAAAGU"] [Tue Aug 18 13:02:26.609292 2026] [security2:error] [pid 139043:tid 139183] [client 20.65.105.233:12792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/c4.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgIQAAAI8"] [Tue Aug 18 13:02:26.613300 2026] [security2:error] [pid 139043:tid 139162] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.github/.env"] [unique_id "aoSCEv2v-lWn9OzQT7UgIgAA_HY"] [Tue Aug 18 13:02:26.619180 2026] [security2:error] [pid 123784:tid 123833] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mz.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSpQAAEyw"] [Tue Aug 18 13:02:26.623043 2026] [security2:error] [pid 139043:tid 139247] [client 20.151.109.219:24438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/album.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgJQAAAM8"] [Tue Aug 18 13:02:26.635613 2026] [security2:error] [pid 139043:tid 139260] [client 158.158.74.177:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/sim.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgJwAAANw"] [Tue Aug 18 13:02:26.652352 2026] [security2:error] [pid 123784:tid 123839] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/teste.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSpwAAIzI"] [Tue Aug 18 13:02:26.663803 2026] [security2:error] [pid 123784:tid 124045] [client 20.226.56.190:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/smtp.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSqAAAAH8"] [Tue Aug 18 13:02:26.682851 2026] [ssl:error] [pid 139043:tid 139153] [remote 195.91.109.227:43845] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 13:02:26.719443 2026] [security2:error] [pid 139043:tid 139203] [client 20.65.69.59:5403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ts.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgLQAAAKM"] [Tue Aug 18 13:02:26.787158 2026] [security2:error] [pid 123784:tid 123829] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/local.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSqgAATyg"] [Tue Aug 18 13:02:26.793197 2026] [security2:error] [pid 139043:tid 139231] [client 172.182.200.96:15632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgMQAAAL8"] [Tue Aug 18 13:02:26.796578 2026] [security2:error] [pid 123784:tid 123853] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ft.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSqwAAAUA"] [Tue Aug 18 13:02:26.825313 2026] [security2:error] [pid 139043:tid 139126] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgMgAAslI"] [Tue Aug 18 13:02:26.825462 2026] [security2:error] [pid 139043:tid 139218] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgMgAAslI"] [Tue Aug 18 13:02:26.843096 2026] [security2:error] [pid 139043:tid 139290] [client 20.116.17.175:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgMwAAAPo"] [Tue Aug 18 13:02:26.849112 2026] [security2:error] [pid 139043:tid 139270] [client 20.65.105.233:12754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/an7.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgNAAAAOY"] [Tue Aug 18 13:02:26.852298 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:26.852551 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:26.868489 2026] [security2:error] [pid 139043:tid 139190] [client 20.251.112.238:28278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/path.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgNwAAAJY"] [Tue Aug 18 13:02:26.871178 2026] [security2:error] [pid 139043:tid 139232] [client 20.79.204.6:10725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/bless.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgOAAAAMA"] [Tue Aug 18 13:02:26.898856 2026] [security2:error] [pid 139043:tid 139216] [client 178.153.171.161:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgOQAAALA"] [Tue Aug 18 13:02:26.898987 2026] [security2:error] [pid 139043:tid 139216] [client 178.153.171.161:57027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgOQAAALA"] [Tue Aug 18 13:02:26.904776 2026] [security2:error] [pid 139043:tid 139189] [client 158.23.17.4:20176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/nd.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgOgAAAJU"] [Tue Aug 18 13:02:26.924500 2026] [security2:error] [pid 123784:tid 123910] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSrwAAQHk"] [Tue Aug 18 13:02:26.926398 2026] [security2:error] [pid 139043:tid 139268] [client 172.213.243.2:17697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/f6.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgOwAAAOQ"] [Tue Aug 18 13:02:26.953008 2026] [security2:error] [pid 139043:tid 139107] [remote 162.241.152.27:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgPAAAyj8"] [Tue Aug 18 13:02:26.962930 2026] [security2:error] [pid 139043:tid 139215] [client 20.118.133.132:7815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/coffee.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgPgAAAK8"] [Tue Aug 18 13:02:26.966818 2026] [security2:error] [pid 139043:tid 139204] [client 20.151.109.219:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kv.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgPwAAAKQ"] [Tue Aug 18 13:02:26.973373 2026] [security2:error] [pid 123784:tid 123797] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/h.php"] [unique_id "aoSCEmwDnJBNj2tDbYYSsAAAbwg"] [Tue Aug 18 13:02:27.000082 2026] [security2:error] [pid 139043:tid 139255] [client 132.196.30.78:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCEv2v-lWn9OzQT7UgRwAAANc"] [Tue Aug 18 13:02:27.004287 2026] [authz_core:error] [pid 139043:tid 139058] [remote 34.62.54.143:48908] AH01630: client denied by server configuration: /home3/tentac25/_wildcard_.tentaclehost.com.br/.htpasswd [Tue Aug 18 13:02:27.014753 2026] [security2:error] [pid 123784:tid 123962] [client 158.158.74.177:26791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guscarautomoveis.com.br"] [uri "/license.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSsQAAACw"] [Tue Aug 18 13:02:27.015594 2026] [security2:error] [pid 123784:tid 123944] [client 20.65.69.59:43273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/53.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSsgAAABo"] [Tue Aug 18 13:02:27.103052 2026] [security2:error] [pid 139043:tid 139298] [client 20.65.105.233:12771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgSgAAAQI"] [Tue Aug 18 13:02:27.109943 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:33515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pz.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSswAAAB8"] [Tue Aug 18 13:02:27.119753 2026] [security2:error] [pid 139043:tid 139200] [client 168.62.48.100:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/rezor.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgSwAAAKA"] [Tue Aug 18 13:02:27.119753 2026] [security2:error] [pid 123784:tid 124030] [client 68.155.154.236:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCE2wDnJBNj2tDbYYStAAAAHA"] [Tue Aug 18 13:02:27.148112 2026] [security2:error] [pid 123784:tid 123825] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/40.php"] [unique_id "aoSCE2wDnJBNj2tDbYYStQAALSQ"] [Tue Aug 18 13:02:27.150339 2026] [security2:error] [pid 139043:tid 139199] [client 157.20.138.62:50610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgTwAAAJ8"] [Tue Aug 18 13:02:27.150444 2026] [security2:error] [pid 139043:tid 139199] [client 157.20.138.62:50610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgTwAAAJ8"] [Tue Aug 18 13:02:27.154239 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:27.154574 2026] [authz_core:error] [pid 123784:tid 123860] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:27.218660 2026] [security2:error] [pid 123784:tid 124038] [client 20.250.13.23:30787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/mm.php"] [unique_id "aoSCE2wDnJBNj2tDbYYStwAAAHg"] [Tue Aug 18 13:02:27.253348 2026] [security2:error] [pid 123784:tid 124037] [client 158.158.74.177:3212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/simple.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSuAAAAHc"] [Tue Aug 18 13:02:27.277507 2026] [security2:error] [pid 139043:tid 139205] [client 68.155.154.236:40474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgUQAAAKU"] [Tue Aug 18 13:02:27.293586 2026] [security2:error] [pid 139043:tid 139276] [client 20.65.69.59:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lq.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgUgAAAOw"] [Tue Aug 18 13:02:27.302774 2026] [security2:error] [pid 139043:tid 139234] [client 20.251.112.238:26118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wpo.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgUwAAAMI"] [Tue Aug 18 13:02:27.312690 2026] [security2:error] [pid 139043:tid 139245] [client 158.23.17.4:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/of.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgVAAAAM0"] [Tue Aug 18 13:02:27.315382 2026] [security2:error] [pid 123784:tid 123863] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ee.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSugAAB0o"] [Tue Aug 18 13:02:27.343040 2026] [security2:error] [pid 123784:tid 123942] [client 20.65.105.233:12794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/byp8.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSuwAAABg"] [Tue Aug 18 13:02:27.343598 2026] [security2:error] [pid 123784:tid 123994] [client 172.213.243.2:18044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mcs.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSvAAAAEw"] [Tue Aug 18 13:02:27.354764 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:20105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/z.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSvQAAAFQ"] [Tue Aug 18 13:02:27.380073 2026] [security2:error] [pid 123784:tid 124023] [client 20.251.48.93:25218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/ops.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSvgAAAGk"] [Tue Aug 18 13:02:27.445006 2026] [security2:error] [pid 139043:tid 139198] [client 172.202.39.151:49364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgWQAAAJ4"] [Tue Aug 18 13:02:27.448948 2026] [security2:error] [pid 139043:tid 139274] [client 213.35.127.232:51507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgWgAAAOo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:27.453632 2026] [security2:error] [pid 123784:tid 123901] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ak.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSwAAAHHA"] [Tue Aug 18 13:02:27.454985 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:27.455250 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:27.484498 2026] [security2:error] [pid 139043:tid 139237] [client 132.196.30.78:12780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgWwAAAMU"] [Tue Aug 18 13:02:27.497969 2026] [security2:error] [pid 123784:tid 123861] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/ninja.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSwgAAXkg"] [Tue Aug 18 13:02:27.538512 2026] [security2:error] [pid 139043:tid 139082] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCE_2v-lWn9OzQT7UgXQAAxyY"] [Tue Aug 18 13:02:27.542058 2026] [security2:error] [pid 139043:tid 139292] [client 68.155.154.236:8329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgXgAAAPw"] [Tue Aug 18 13:02:27.581137 2026] [security2:error] [pid 123784:tid 123907] [remote 203.99.146.53:33584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSxAAAN3Y"] [Tue Aug 18 13:02:27.583107 2026] [security2:error] [pid 123784:tid 123938] [client 20.65.69.59:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/you.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSxQAAABQ"] [Tue Aug 18 13:02:27.583294 2026] [security2:error] [pid 139043:tid 139206] [client 20.65.105.233:12798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/plugins.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgYwAAAKY"] [Tue Aug 18 13:02:27.589580 2026] [security2:error] [pid 139043:tid 139203] [client 172.182.200.96:2018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgZAAAAKM"] [Tue Aug 18 13:02:27.630890 2026] [security2:error] [pid 123784:tid 123844] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/test_info.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSyAAAfTc"] [Tue Aug 18 13:02:27.662642 2026] [security2:error] [pid 123784:tid 123810] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/phpprobe.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSyQAAOhU"] [Tue Aug 18 13:02:27.678279 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:14042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/bu.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgaAAAAJk"] [Tue Aug 18 13:02:27.712754 2026] [security2:error] [pid 123784:tid 123977] [client 20.151.109.219:63734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xg.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSywAAADs"] [Tue Aug 18 13:02:27.763907 2026] [security2:error] [pid 123784:tid 123932] [client 20.251.112.238:26154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/a1vx.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSzAAAAA4"] [Tue Aug 18 13:02:27.764361 2026] [security2:error] [pid 139043:tid 139216] [client 172.213.243.2:14987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/xleet.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgagAAALA"] [Tue Aug 18 13:02:27.771742 2026] [security2:error] [pid 139043:tid 139225] [client 37.40.227.74:57088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgawAAALk"] [Tue Aug 18 13:02:27.774224 2026] [security2:error] [pid 139043:tid 139225] [client 37.40.227.74:57088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgawAAALk"] [Tue Aug 18 13:02:27.793473 2026] [security2:error] [pid 139043:tid 139102] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCE_2v-lWn9OzQT7UgbQAA-To"] [Tue Aug 18 13:02:27.796973 2026] [security2:error] [pid 123784:tid 123887] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/14.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSzQAAM2I"] [Tue Aug 18 13:02:27.803463 2026] [security2:error] [pid 139043:tid 139186] [client 132.196.30.78:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/atomlib.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgbgAAAJI"] [Tue Aug 18 13:02:27.823358 2026] [security2:error] [pid 139043:tid 139099] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/id_dsa"] [unique_id "aoSCE_2v-lWn9OzQT7UgcAAAtTc"] [Tue Aug 18 13:02:27.832903 2026] [security2:error] [pid 139043:tid 139248] [client 104.222.31.70:39337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "fioplastic.com.br"] [uri "/wp-content/plugins/woocommerce-abandoned-cart/readme.txt"] [unique_id "aoSCE_2v-lWn9OzQT7UgcQAAANA"] [Tue Aug 18 13:02:27.836819 2026] [security2:error] [pid 139043:tid 139251] [client 20.65.105.233:12579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/100.kb.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgcgAAANM"] [Tue Aug 18 13:02:27.838699 2026] [security2:error] [pid 139043:tid 139196] [client 20.250.13.23:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ms-edit.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgcwAAAJw"] [Tue Aug 18 13:02:27.850953 2026] [security2:error] [pid 139043:tid 139257] [client 20.65.69.59:48451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ez.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgdQAAANk"] [Tue Aug 18 13:02:27.855412 2026] [security2:error] [pid 139043:tid 139069] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/id_rsa"] [unique_id "aoSCE_2v-lWn9OzQT7UgeAAAqxk"] [Tue Aug 18 13:02:27.881373 2026] [security2:error] [pid 123784:tid 123908] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/wp-title.php"] [unique_id "aoSCE2wDnJBNj2tDbYYSzgAAQXc"] [Tue Aug 18 13:02:27.900236 2026] [security2:error] [pid 139043:tid 139265] [client 103.184.169.37:43363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgegAAAOE"] [Tue Aug 18 13:02:27.900386 2026] [security2:error] [pid 139043:tid 139265] [client 103.184.169.37:43363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgegAAAOE"] [Tue Aug 18 13:02:27.901604 2026] [security2:error] [pid 139043:tid 139298] [client 20.151.109.219:27770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gj.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgewAAAQI"] [Tue Aug 18 13:02:27.914246 2026] [security2:error] [pid 139043:tid 139108] [remote 129.121.103.155:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sprintlimp.com.br"] [uri "/wp-login.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgfAAA9EA"] [Tue Aug 18 13:02:27.919492 2026] [security2:error] [pid 139043:tid 139229] [client 158.158.74.177:3260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/st.php"] [unique_id "aoSCE_2v-lWn9OzQT7UgfQAAAL0"] [Tue Aug 18 13:02:27.959354 2026] [security2:error] [pid 139043:tid 139130] [remote 157.55.39.193:36948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCE_2v-lWn9OzQT7UggQAAyVY"] [Tue Aug 18 13:02:27.970443 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:27.970735 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:27.985960 2026] [security2:error] [pid 123784:tid 123871] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/tk.php"] [unique_id "aoSCE2wDnJBNj2tDbYYS0QAAJFI"] [Tue Aug 18 13:02:28.021884 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rn.php"] [unique_id "aoSCFP2v-lWn9OzQT7UghAAAANI"] [Tue Aug 18 13:02:28.021922 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.56.190:30986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/teste.php"] [unique_id "aoSCFP2v-lWn9OzQT7UggwAAAO4"] [Tue Aug 18 13:02:28.045457 2026] [security2:error] [pid 139043:tid 139230] [client 20.79.204.6:10408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/sagax1.php"] [unique_id "aoSCFP2v-lWn9OzQT7UghgAAAL4"] [Tue Aug 18 13:02:28.055182 2026] [security2:error] [pid 123784:tid 124032] [client 20.151.109.219:14132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/nd.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS0gAAAHI"] [Tue Aug 18 13:02:28.069458 2026] [security2:error] [pid 123784:tid 124021] [client 172.182.200.96:15683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS0wAAAGc"] [Tue Aug 18 13:02:28.080430 2026] [security2:error] [pid 123784:tid 123979] [client 20.65.105.233:12778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/mamzi.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS1QAAAD0"] [Tue Aug 18 13:02:28.108481 2026] [security2:error] [pid 139043:tid 139201] [client 158.23.17.4:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ko.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgiAAAAKE"] [Tue Aug 18 13:02:28.110473 2026] [security2:error] [pid 123784:tid 123961] [client 20.203.183.135:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ww2.pan.com.br"] [uri "/abcd.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS1gAAACs"] [Tue Aug 18 13:02:28.167894 2026] [security2:error] [pid 123784:tid 123878] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/hp.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS1wAAa1k"] [Tue Aug 18 13:02:28.184456 2026] [security2:error] [pid 139043:tid 139208] [client 172.213.243.2:35275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fr/ms.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgjQAAAKg"] [Tue Aug 18 13:02:28.192893 2026] [security2:error] [pid 123784:tid 123923] [client 132.196.30.78:24620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/min.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS2gAAAAU"] [Tue Aug 18 13:02:28.197582 2026] [security2:error] [pid 123784:tid 124024] [client 20.65.69.59:12091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/asus.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS2wAAAGo"] [Tue Aug 18 13:02:28.216381 2026] [security2:error] [pid 139043:tid 139117] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/privatekey.key"] [unique_id "aoSCFP2v-lWn9OzQT7UgkQAA8Ek"] [Tue Aug 18 13:02:28.227442 2026] [security2:error] [pid 139043:tid 139203] [client 20.251.112.238:7802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ty.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgkgAAAKM"] [Tue Aug 18 13:02:28.231969 2026] [security2:error] [pid 139043:tid 139050] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/key.pem"] [unique_id "aoSCFP2v-lWn9OzQT7UgkwAA3AY"] [Tue Aug 18 13:02:28.252079 2026] [security2:error] [pid 139043:tid 139175] [client 20.226.56.190:28245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/local.php"] [unique_id "aoSCFP2v-lWn9OzQT7UglgAAAIc"] [Tue Aug 18 13:02:28.288792 2026] [security2:error] [pid 123784:tid 123846] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/styles.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS4QAALjk"] [Tue Aug 18 13:02:28.310262 2026] [security2:error] [pid 123784:tid 123819] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wx.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS4gAAIB4"] [Tue Aug 18 13:02:28.320087 2026] [security2:error] [pid 139043:tid 139193] [client 20.65.105.233:12749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ms.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgmQAAAJk"] [Tue Aug 18 13:02:28.360192 2026] [security2:error] [pid 139043:tid 139300] [client 20.151.109.219:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ri.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgnAAAAQQ"] [Tue Aug 18 13:02:28.395542 2026] [security2:error] [pid 139043:tid 139227] [client 158.23.17.4:14070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ut.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgnQAAALs"] [Tue Aug 18 13:02:28.408388 2026] [security2:error] [pid 123784:tid 124041] [client 68.155.154.236:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS5QAAAHs"] [Tue Aug 18 13:02:28.412315 2026] [security2:error] [pid 123784:tid 124039] [client 158.23.17.4:38850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kk.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS5gAAAHk"] [Tue Aug 18 13:02:28.425162 2026] [security2:error] [pid 123784:tid 123896] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/server.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS5wAARms"] [Tue Aug 18 13:02:28.433732 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pd.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgnwAAAK8"] [Tue Aug 18 13:02:28.465430 2026] [security2:error] [pid 139043:tid 139274] [client 213.35.127.232:51731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgoAAAAOo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:28.473241 2026] [security2:error] [pid 123784:tid 123856] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/dj.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS6AAAZUM"] [Tue Aug 18 13:02:28.478845 2026] [security2:error] [pid 139043:tid 139246] [client 20.250.13.23:3638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ms-themes.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgpgAAAM4"] [Tue Aug 18 13:02:28.499877 2026] [security2:error] [pid 123784:tid 123937] [client 20.65.69.59:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/22.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS7AAAABM"] [Tue Aug 18 13:02:28.505940 2026] [security2:error] [pid 139043:tid 139121] [remote 162.214.184.71:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgqwAA0E0"] [Tue Aug 18 13:02:28.539022 2026] [security2:error] [pid 123784:tid 123929] [client 172.202.39.151:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS7gAAAAs"] [Tue Aug 18 13:02:28.541911 2026] [security2:error] [pid 139043:tid 139232] [client 158.158.74.177:19331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgrgAAAMA"] [Tue Aug 18 13:02:28.542144 2026] [security2:error] [pid 123784:tid 124020] [client 5.31.227.224:30068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS7wAAAGY"] [Tue Aug 18 13:02:28.544474 2026] [security2:error] [pid 123784:tid 124020] [client 5.31.227.224:30068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS7wAAAGY"] [Tue Aug 18 13:02:28.560688 2026] [security2:error] [pid 139043:tid 139196] [client 20.65.105.233:12773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/gfile.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgrwAAAJw"] [Tue Aug 18 13:02:28.585459 2026] [security2:error] [pid 123784:tid 123799] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/xinfo.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS8QAAfwo"] [Tue Aug 18 13:02:28.619399 2026] [security2:error] [pid 123784:tid 123970] [client 66.187.6.102:45070] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/trinchas/trincha-angular"] [unique_id "aoSCFGwDnJBNj2tDbYYS8gAAADQ"] [Tue Aug 18 13:02:28.620746 2026] [security2:error] [pid 139043:tid 139211] [client 66.187.6.102:45178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "pinceisroma.com.br"] [uri "/en/produtos/rolos/rolos-de-la-poliester"] [unique_id "aoSCFP2v-lWn9OzQT7UgsgAAAKs"] [Tue Aug 18 13:02:28.629183 2026] [security2:error] [pid 123784:tid 123997] [client 172.213.243.2:50736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/gool.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS8wAAAE8"] [Tue Aug 18 13:02:28.629339 2026] [security2:error] [pid 123784:tid 123919] [client 132.196.30.78:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/mac.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS9AAAAAE"] [Tue Aug 18 13:02:28.642893 2026] [security2:error] [pid 123784:tid 123835] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fa.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS9gAAbi4"] [Tue Aug 18 13:02:28.665796 2026] [security2:error] [pid 123784:tid 123985] [client 20.251.112.238:40617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/vgtyu.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS-AAAAEM"] [Tue Aug 18 13:02:28.679970 2026] [security2:error] [pid 123784:tid 123982] [client 20.151.109.219:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/tp.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS-QAAAEA"] [Tue Aug 18 13:02:28.701899 2026] [security2:error] [pid 139043:tid 139229] [client 172.182.200.96:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgtwAAAL0"] [Tue Aug 18 13:02:28.715065 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ri.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS-wAAABo"] [Tue Aug 18 13:02:28.729161 2026] [security2:error] [pid 139043:tid 139173] [client 158.23.17.4:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/eh.php"] [unique_id "aoSCFP2v-lWn9OzQT7UguAAAAIU"] [Tue Aug 18 13:02:28.745668 2026] [security2:error] [pid 139043:tid 139281] [client 20.65.69.59:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/zs.php"] [unique_id "aoSCFP2v-lWn9OzQT7UguQAAAPE"] [Tue Aug 18 13:02:28.785226 2026] [security2:error] [pid 123784:tid 124037] [client 168.62.48.100:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/weozh.php"] [unique_id "aoSCFGwDnJBNj2tDbYYS_wAAAHc"] [Tue Aug 18 13:02:28.797053 2026] [security2:error] [pid 123784:tid 123838] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/sym.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTAAAABzE"] [Tue Aug 18 13:02:28.801507 2026] [security2:error] [pid 123784:tid 123945] [client 20.65.105.233:12766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTAQAAABs"] [Tue Aug 18 13:02:28.803172 2026] [security2:error] [pid 123784:tid 123942] [client 20.116.17.175:22972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/dk.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTAgAAABg"] [Tue Aug 18 13:02:28.803909 2026] [security2:error] [pid 139043:tid 139294] [client 158.23.17.4:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/pl.php"] [unique_id "aoSCFP2v-lWn9OzQT7UgvgAAAP4"] [Tue Aug 18 13:02:28.825026 2026] [security2:error] [pid 123784:tid 123821] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/fb.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTAwAAVCA"] [Tue Aug 18 13:02:28.864602 2026] [security2:error] [pid 139043:tid 139134] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCFP2v-lWn9OzQT7UgxAAAqVo"] [Tue Aug 18 13:02:28.872517 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:28.872829 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:28.967245 2026] [security2:error] [pid 123784:tid 123881] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gw.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTBgAAN1w"] [Tue Aug 18 13:02:28.968111 2026] [security2:error] [pid 123784:tid 123891] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.altostima.com.br"] [uri "/ye.php"] [unique_id "aoSCFGwDnJBNj2tDbYYTBwAAFGY"] [Tue Aug 18 13:02:29.002061 2026] [security2:error] [pid 139043:tid 139235] [client 20.65.69.59:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/iz.php"] [unique_id "aoSCFf2v-lWn9OzQT7UgyAAAAMM"] [Tue Aug 18 13:02:29.044831 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.105.233:12463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/cu.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTCQAAAH4"] [Tue Aug 18 13:02:29.045562 2026] [security2:error] [pid 123784:tid 123976] [client 172.213.243.2:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/maxro.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTCgAAADo"] [Tue Aug 18 13:02:29.081679 2026] [security2:error] [pid 123784:tid 124026] [client 20.151.109.219:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/zj.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTDAAAAGw"] [Tue Aug 18 13:02:29.098549 2026] [security2:error] [pid 139043:tid 139258] [client 132.196.30.78:24633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/nc4.php"] [unique_id "aoSCFf2v-lWn9OzQT7UgzwAAANo"] [Tue Aug 18 13:02:29.106417 2026] [security2:error] [pid 123784:tid 123847] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/sw.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTDQAAOzo"] [Tue Aug 18 13:02:29.115417 2026] [security2:error] [pid 139043:tid 139174] [client 20.251.112.238:7146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mans.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug0QAAAIY"] [Tue Aug 18 13:02:29.119547 2026] [security2:error] [pid 139043:tid 139198] [client 168.62.48.100:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug0gAAAJ4"] [Tue Aug 18 13:02:29.130045 2026] [security2:error] [pid 139043:tid 139237] [client 20.118.133.132:39692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/classwithtostring.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug0wAAAMU"] [Tue Aug 18 13:02:29.141206 2026] [security2:error] [pid 139043:tid 139288] [client 20.250.13.23:30790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/my1.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug1AAAAPg"] [Tue Aug 18 13:02:29.156104 2026] [ssl:error] [pid 139043:tid 139060] [remote 195.91.109.227:43845] AH02032: Hostname ondaseventos.com provided via SNI and hostname en.ondaseventos.com provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 13:02:29.161272 2026] [security2:error] [pid 139043:tid 139205] [client 158.158.74.177:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/system.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug2QAAAKU"] [Tue Aug 18 13:02:29.173300 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:29.173636 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:29.178770 2026] [security2:error] [pid 123784:tid 123880] [remote 203.99.146.53:33596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ezycolor.com.br"] [uri "/wp-login.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTDwAABls"] [Tue Aug 18 13:02:29.180142 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:25376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ad.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug2gAAANg"] [Tue Aug 18 13:02:29.214396 2026] [security2:error] [pid 139043:tid 139154] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCFf2v-lWn9OzQT7Ug3AAApm4"] [Tue Aug 18 13:02:29.286096 2026] [security2:error] [pid 139043:tid 139188] [client 20.65.105.233:12472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/X57.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug3wAAAJQ"] [Tue Aug 18 13:02:29.289924 2026] [security2:error] [pid 123784:tid 123885] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gc.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTEQAADGA"] [Tue Aug 18 13:02:29.410656 2026] [security2:error] [pid 139043:tid 139231] [client 68.155.154.236:53660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug4QAAAL8"] [Tue Aug 18 13:02:29.413872 2026] [security2:error] [pid 123784:tid 123948] [client 20.151.109.219:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/x.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTEwAAAB4"] [Tue Aug 18 13:02:29.437917 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.69.59:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/se.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug4wAAAN0"] [Tue Aug 18 13:02:29.466841 2026] [security2:error] [pid 123784:tid 123888] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/uq.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTFAAAAmM"] [Tue Aug 18 13:02:29.474445 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:29.474701 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:29.480383 2026] [security2:error] [pid 139043:tid 139272] [client 213.35.127.232:51953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug5QAAAOg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:29.486366 2026] [security2:error] [pid 139043:tid 139212] [client 172.182.200.96:15638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug5gAAAKw"] [Tue Aug 18 13:02:29.492261 2026] [security2:error] [pid 139043:tid 139193] [client 172.213.243.2:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wdf.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug5wAAAJk"] [Tue Aug 18 13:02:29.517977 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/vd.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug6QAAAQQ"] [Tue Aug 18 13:02:29.526448 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.105.233:12788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/forbidals.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug6gAAALA"] [Tue Aug 18 13:02:29.528434 2026] [security2:error] [pid 123784:tid 123991] [client 20.251.112.238:40619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/co.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTFgAAAEk"] [Tue Aug 18 13:02:29.551598 2026] [security2:error] [pid 123784:tid 123990] [client 158.23.17.4:9322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTFwAAAEg"] [Tue Aug 18 13:02:29.591703 2026] [security2:error] [pid 123784:tid 124017] [client 158.23.17.4:33446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tp.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTGAAAAGM"] [Tue Aug 18 13:02:29.597330 2026] [security2:error] [pid 123784:tid 123999] [client 132.196.30.78:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/as.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTGQAAAFE"] [Tue Aug 18 13:02:29.645487 2026] [security2:error] [pid 123784:tid 124007] [client 20.151.109.219:23492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/th.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTGgAAAFk"] [Tue Aug 18 13:02:29.652294 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:58713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/env.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug7gAAAPk"] [Tue Aug 18 13:02:29.681517 2026] [security2:error] [pid 123784:tid 123865] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/32.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTGwAAJEw"] [Tue Aug 18 13:02:29.760117 2026] [security2:error] [pid 139043:tid 139232] [client 20.65.69.59:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vp.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug8QAAAMA"] [Tue Aug 18 13:02:29.777290 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:29.777556 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:29.780344 2026] [security2:error] [pid 139043:tid 139211] [client 20.65.105.233:12772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/edit.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug8gAAAKs"] [Tue Aug 18 13:02:29.782730 2026] [security2:error] [pid 123784:tid 123972] [client 20.250.13.23:3596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/new.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTHQAAADY"] [Tue Aug 18 13:02:29.784599 2026] [security2:error] [pid 139043:tid 139215] [client 158.158.74.177:3681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/system_log.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug9AAAAK8"] [Tue Aug 18 13:02:29.830289 2026] [security2:error] [pid 123784:tid 123802] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/73.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTHgAATg0"] [Tue Aug 18 13:02:29.862282 2026] [security2:error] [pid 139043:tid 139182] [client 20.151.109.219:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/yn.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug9gAAAI4"] [Tue Aug 18 13:02:29.901447 2026] [security2:error] [pid 139043:tid 139291] [client 172.213.243.2:15704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ff1.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug-QAAAPs"] [Tue Aug 18 13:02:29.908261 2026] [security2:error] [pid 139043:tid 139191] [client 158.23.17.4:40392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/56.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug-gAAAJc"] [Tue Aug 18 13:02:29.948034 2026] [security2:error] [pid 139043:tid 139267] [client 223.185.37.47:12125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug-wAAAOM"] [Tue Aug 18 13:02:29.948152 2026] [security2:error] [pid 139043:tid 139267] [client 223.185.37.47:12125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug-wAAAOM"] [Tue Aug 18 13:02:29.951905 2026] [security2:error] [pid 139043:tid 139229] [client 158.23.17.4:11004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dg.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug_AAAAL0"] [Tue Aug 18 13:02:29.965619 2026] [security2:error] [pid 139043:tid 139173] [client 20.251.112.238:7222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/btx25.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug_gAAAIU"] [Tue Aug 18 13:02:29.968615 2026] [security2:error] [pid 139043:tid 139262] [client 4.232.151.198:37583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/nw.php"] [unique_id "aoSCFf2v-lWn9OzQT7Ug_wAAAN4"] [Tue Aug 18 13:02:29.991509 2026] [security2:error] [pid 123784:tid 123877] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ib.php"] [unique_id "aoSCFWwDnJBNj2tDbYYTHwAAPlg"] [Tue Aug 18 13:02:30.020072 2026] [security2:error] [pid 139043:tid 139209] [client 20.65.105.233:12448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/kj.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhAgAAAKk"] [Tue Aug 18 13:02:30.029413 2026] [security2:error] [pid 139043:tid 139214] [client 132.196.30.78:24289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/k.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhAwAAAK4"] [Tue Aug 18 13:02:30.084565 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:30.084872 2026] [authz_core:error] [pid 123784:tid 123818] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:30.094194 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.69.59:12079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ph.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTIQAAAFg"] [Tue Aug 18 13:02:30.109860 2026] [security2:error] [pid 139043:tid 139230] [client 68.155.154.236:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhBwAAAL4"] [Tue Aug 18 13:02:30.135049 2026] [security2:error] [pid 123784:tid 123867] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xm.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTIgAAHU4"] [Tue Aug 18 13:02:30.213383 2026] [security2:error] [pid 139043:tid 139205] [client 172.182.200.96:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhDQAAAKU"] [Tue Aug 18 13:02:30.242153 2026] [security2:error] [pid 123784:tid 124024] [client 20.151.109.219:34010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/11.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTIwAAAGo"] [Tue Aug 18 13:02:30.260800 2026] [security2:error] [pid 139043:tid 139250] [client 20.65.105.233:12430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/bes.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhEgAAANI"] [Tue Aug 18 13:02:30.283915 2026] [security2:error] [pid 139043:tid 139188] [client 20.251.48.93:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/coffexium.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhEwAAAJQ"] [Tue Aug 18 13:02:30.299387 2026] [security2:error] [pid 139043:tid 139203] [client 216.244.66.232:58670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFAAAAKM"] [Tue Aug 18 13:02:30.299558 2026] [security2:error] [pid 139043:tid 139203] [client 216.244.66.232:58670] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sixsaude.com.br"] [uri "/index.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFAAAAKM"] [Tue Aug 18 13:02:30.300044 2026] [security2:error] [pid 123784:tid 123895] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zy.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTJAAAYmo"] [Tue Aug 18 13:02:30.300827 2026] [security2:error] [pid 139043:tid 139266] [client 172.202.39.151:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFQAAAOI"] [Tue Aug 18 13:02:30.309237 2026] [security2:error] [pid 139043:tid 139260] [client 20.116.17.175:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/bal.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFgAAANw"] [Tue Aug 18 13:02:30.310572 2026] [security2:error] [pid 139043:tid 139180] [client 103.120.71.157:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFwAAAIw"] [Tue Aug 18 13:02:30.310676 2026] [security2:error] [pid 139043:tid 139180] [client 103.120.71.157:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhFwAAAIw"] [Tue Aug 18 13:02:30.312533 2026] [security2:error] [pid 139043:tid 139252] [client 172.213.243.2:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/guk.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhGAAAANQ"] [Tue Aug 18 13:02:30.365961 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:2035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/zj.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTJQAAAGQ"] [Tue Aug 18 13:02:30.378290 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:30.378572 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:30.398964 2026] [security2:error] [pid 123784:tid 124008] [client 20.226.56.190:2099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTJwAAAFo"] [Tue Aug 18 13:02:30.415976 2026] [security2:error] [pid 123784:tid 123951] [client 158.23.17.4:20360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/rx.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTKAAAACE"] [Tue Aug 18 13:02:30.418357 2026] [security2:error] [pid 123784:tid 123964] [client 20.251.112.238:63909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/avim.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTKQAAAC4"] [Tue Aug 18 13:02:30.435946 2026] [security2:error] [pid 139043:tid 139183] [client 20.250.13.23:20324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/norn.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhIQAAAI8"] [Tue Aug 18 13:02:30.440099 2026] [security2:error] [pid 123784:tid 123950] [client 20.151.109.219:56034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/admin404.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTKgAAACA"] [Tue Aug 18 13:02:30.497009 2026] [security2:error] [pid 139043:tid 139274] [client 20.65.69.59:59207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/s.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhIwAAAOo"] [Tue Aug 18 13:02:30.500208 2026] [security2:error] [pid 139043:tid 139276] [client 20.65.105.233:12433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ws60.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhJAAAAOw"] [Tue Aug 18 13:02:30.501328 2026] [security2:error] [pid 123784:tid 123955] [client 158.23.17.4:41937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/bm.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTKwAAACU"] [Tue Aug 18 13:02:30.503923 2026] [security2:error] [pid 123784:tid 123992] [client 213.202.253.4:58011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/userfuns.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTLAAAAEo"], referer: www.google.com [Tue Aug 18 13:02:30.506818 2026] [security2:error] [pid 139043:tid 139285] [client 213.35.127.232:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhJQAAAPU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:30.511788 2026] [security2:error] [pid 139043:tid 139246] [client 158.23.17.4:15157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mz.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhJgAAAM4"] [Tue Aug 18 13:02:30.515226 2026] [security2:error] [pid 123784:tid 123912] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/q.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTLQAATXs"] [Tue Aug 18 13:02:30.523643 2026] [security2:error] [pid 139043:tid 139249] [client 132.196.30.78:8073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhKAAAANE"] [Tue Aug 18 13:02:30.525577 2026] [security2:error] [pid 139043:tid 139228] [client 158.158.74.177:3685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhKQAAALw"] [Tue Aug 18 13:02:30.560294 2026] [security2:error] [pid 139043:tid 139221] [client 20.151.109.219:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vm.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhKwAAALU"] [Tue Aug 18 13:02:30.596825 2026] [security2:error] [pid 139043:tid 139186] [client 68.155.154.236:63554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhLwAAAJI"] [Tue Aug 18 13:02:30.680899 2026] [security2:error] [pid 123784:tid 123822] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xf.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTLwAADSE"] [Tue Aug 18 13:02:30.686422 2026] [security2:error] [pid 123784:tid 123993] [client 68.155.154.236:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTMAAAAEs"] [Tue Aug 18 13:02:30.739105 2026] [security2:error] [pid 139043:tid 139298] [client 172.213.243.2:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-the.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhQwAAAQI"] [Tue Aug 18 13:02:30.753063 2026] [security2:error] [pid 123784:tid 124042] [client 20.65.105.233:12797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/olfclass.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTMQAAAHw"] [Tue Aug 18 13:02:30.840658 2026] [security2:error] [pid 139043:tid 139191] [client 158.23.17.4:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mandrill.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhRgAAAJc"] [Tue Aug 18 13:02:30.850810 2026] [security2:error] [pid 139043:tid 139267] [client 172.182.200.96:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhRwAAAOM"] [Tue Aug 18 13:02:30.850829 2026] [security2:error] [pid 139043:tid 139229] [client 20.251.112.238:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/myfile.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhSAAAAL0"] [Tue Aug 18 13:02:30.859714 2026] [security2:error] [pid 139043:tid 139173] [client 20.151.109.219:14319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/eg.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhSQAAAIU"] [Tue Aug 18 13:02:30.867828 2026] [security2:error] [pid 123784:tid 123909] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gb.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTMwAAf3g"] [Tue Aug 18 13:02:30.890012 2026] [security2:error] [pid 139043:tid 139099] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCFv2v-lWn9OzQT7UhUgAAqTc"] [Tue Aug 18 13:02:30.891615 2026] [security2:error] [pid 139043:tid 139096] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCFv2v-lWn9OzQT7UhVAAAijQ"] [Tue Aug 18 13:02:30.923817 2026] [security2:error] [pid 139043:tid 139088] [remote 47.86.33.52:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhVQAA4Cw"] [Tue Aug 18 13:02:30.931934 2026] [security2:error] [pid 123784:tid 123975] [client 20.118.133.132:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/wp-ws68.php"] [unique_id "aoSCFmwDnJBNj2tDbYYTNAAAADk"] [Tue Aug 18 13:02:30.983832 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:30.984297 2026] [authz_core:error] [pid 123784:tid 123845] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:30.994104 2026] [security2:error] [pid 139043:tid 139179] [client 20.65.105.233:12429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wpver.php"] [unique_id "aoSCFv2v-lWn9OzQT7UhWQAAAIs"] [Tue Aug 18 13:02:31.009693 2026] [security2:error] [pid 123784:tid 123850] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jp.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTNgAATz0"] [Tue Aug 18 13:02:31.051189 2026] [security2:error] [pid 139043:tid 139259] [client 20.151.109.219:56029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/qo.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhWgAAANs"] [Tue Aug 18 13:02:31.080332 2026] [security2:error] [pid 139043:tid 139275] [client 158.23.17.4:9380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vu.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhXAAAAOs"] [Tue Aug 18 13:02:31.117911 2026] [security2:error] [pid 139043:tid 139189] [client 196.12.128.158:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhXwAAAJU"] [Tue Aug 18 13:02:31.118039 2026] [security2:error] [pid 139043:tid 139189] [client 196.12.128.158:59595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhXwAAAJU"] [Tue Aug 18 13:02:31.144615 2026] [security2:error] [pid 139043:tid 139230] [client 158.158.74.177:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/test.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhYAAAAL4"] [Tue Aug 18 13:02:31.149445 2026] [security2:error] [pid 139043:tid 139278] [client 20.151.109.219:14216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/uk.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhYQAAAO4"] [Tue Aug 18 13:02:31.154841 2026] [security2:error] [pid 139043:tid 139256] [client 172.213.243.2:17984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sbhu.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhZAAAANg"] [Tue Aug 18 13:02:31.162795 2026] [security2:error] [pid 139043:tid 139244] [client 20.250.13.23:3587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/num.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhZQAAAMw"] [Tue Aug 18 13:02:31.175578 2026] [security2:error] [pid 123784:tid 123884] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/eq.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTOAAAKF8"] [Tue Aug 18 13:02:31.204202 2026] [security2:error] [pid 123784:tid 123927] [client 197.184.64.235:41970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTOQAAAAk"] [Tue Aug 18 13:02:31.204327 2026] [security2:error] [pid 123784:tid 123927] [client 197.184.64.235:41970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTOQAAAAk"] [Tue Aug 18 13:02:31.213230 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:7275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ft.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhZwAAAKM"] [Tue Aug 18 13:02:31.243401 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.105.233:12416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/thui.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTOwAAAG4"] [Tue Aug 18 13:02:31.263994 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.154.236:65448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTPAAAAC8"] [Tue Aug 18 13:02:31.271760 2026] [security2:error] [pid 123784:tid 123985] [client 20.65.69.59:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/uo.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTPQAAAEM"] [Tue Aug 18 13:02:31.280362 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:31.280655 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:31.282572 2026] [security2:error] [pid 123784:tid 123982] [client 20.251.112.238:7784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xmy.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTPwAAAEA"] [Tue Aug 18 13:02:31.292515 2026] [security2:error] [pid 123784:tid 124029] [client 68.155.154.236:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTQAAAAG8"] [Tue Aug 18 13:02:31.317358 2026] [security2:error] [pid 123784:tid 123868] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ep.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTQQAAGk8"] [Tue Aug 18 13:02:31.352636 2026] [security2:error] [pid 139043:tid 139277] [client 20.79.204.6:10765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wpc.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhawAAAO0"] [Tue Aug 18 13:02:31.365200 2026] [security2:error] [pid 123784:tid 123949] [client 158.23.17.4:46820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/main.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTQgAAAB8"] [Tue Aug 18 13:02:31.373489 2026] [security2:error] [pid 139043:tid 139212] [client 158.23.17.4:33989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/x.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhbAAAAKw"] [Tue Aug 18 13:02:31.429404 2026] [security2:error] [pid 139043:tid 139113] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/laravel/.env"] [unique_id "aoSCF_2v-lWn9OzQT7UhbQAAyUU"] [Tue Aug 18 13:02:31.435097 2026] [security2:error] [pid 123784:tid 124001] [client 168.62.48.100:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTQwAAAFM"] [Tue Aug 18 13:02:31.437973 2026] [security2:error] [pid 139043:tid 139295] [client 20.151.109.219:60927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/creds.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhbwAAAP8"] [Tue Aug 18 13:02:31.484370 2026] [security2:error] [pid 123784:tid 124037] [client 20.65.105.233:12547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/tmpls.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTRAAAAHc"] [Tue Aug 18 13:02:31.506781 2026] [security2:error] [pid 123784:tid 123874] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/rf.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTRQAAG1U"] [Tue Aug 18 13:02:31.519968 2026] [security2:error] [pid 139043:tid 139250] [client 213.35.127.232:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhcAAAANI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:31.554934 2026] [security2:error] [pid 123784:tid 124030] [client 172.182.200.96:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTRgAAAHA"] [Tue Aug 18 13:02:31.566819 2026] [security2:error] [pid 123784:tid 124023] [client 172.202.39.151:49357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/function/function.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTRwAAAGk"] [Tue Aug 18 13:02:31.582395 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:31.582656 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:31.585748 2026] [security2:error] [pid 139043:tid 139184] [client 172.213.243.2:15708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/zc-318.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhcwAAAJA"] [Tue Aug 18 13:02:31.638301 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.69.59:48479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kx.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTSQAAABw"] [Tue Aug 18 13:02:31.658217 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xynz1.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTSgAAKUY"] [Tue Aug 18 13:02:31.682474 2026] [security2:error] [pid 139043:tid 139285] [client 68.155.154.236:41484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhdQAAAPU"] [Tue Aug 18 13:02:31.694550 2026] [security2:error] [pid 123784:tid 123921] [client 20.251.112.238:19035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xda.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTSwAAAAM"] [Tue Aug 18 13:02:31.720605 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:25357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ga.php"] [unique_id "aoSCF_2v-lWn9OzQT7UheAAAANE"] [Tue Aug 18 13:02:31.724982 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.105.233:12424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/nzv.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTTAAAAGg"] [Tue Aug 18 13:02:31.734463 2026] [security2:error] [pid 139043:tid 139228] [client 158.23.17.4:16945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ic.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhegAAALw"] [Tue Aug 18 13:02:31.755857 2026] [security2:error] [pid 139043:tid 139221] [client 20.151.109.219:63725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ho.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhewAAALU"] [Tue Aug 18 13:02:31.767435 2026] [security2:error] [pid 123784:tid 124038] [client 158.158.74.177:3677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/test1.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTTQAAAHg"] [Tue Aug 18 13:02:31.796152 2026] [security2:error] [pid 123784:tid 123831] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vo.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTTgAAFSo"] [Tue Aug 18 13:02:31.823055 2026] [security2:error] [pid 139043:tid 139204] [client 20.151.109.219:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sd.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhfQAAAKQ"] [Tue Aug 18 13:02:31.842749 2026] [security2:error] [pid 139043:tid 139274] [client 20.250.13.23:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/options-reading.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhfgAAAOo"] [Tue Aug 18 13:02:31.882953 2026] [authz_core:error] [pid 123784:tid 123879] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:31.883214 2026] [authz_core:error] [pid 123784:tid 123879] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:31.933885 2026] [security2:error] [pid 123784:tid 123866] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wu.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTUQAAfk0"] [Tue Aug 18 13:02:31.936183 2026] [security2:error] [pid 123784:tid 124044] [client 158.23.17.4:17539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/h.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTUgAAAH4"] [Tue Aug 18 13:02:31.937394 2026] [security2:error] [pid 123784:tid 123935] [client 20.65.69.59:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/va.php"] [unique_id "aoSCF2wDnJBNj2tDbYYTUwAAABE"] [Tue Aug 18 13:02:31.965595 2026] [security2:error] [pid 139043:tid 139200] [client 20.65.105.233:12740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/error1.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhgQAAAKA"] [Tue Aug 18 13:02:31.997972 2026] [security2:error] [pid 139043:tid 139191] [client 172.213.243.2:17593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ccou.php"] [unique_id "aoSCF_2v-lWn9OzQT7UhgwAAAJc"] [Tue Aug 18 13:02:32.072984 2026] [security2:error] [pid 123784:tid 123902] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/de.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTVAAABnE"] [Tue Aug 18 13:02:32.120624 2026] [security2:error] [pid 123784:tid 124009] [client 158.23.17.4:20474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/wb.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTVQAAAFs"] [Tue Aug 18 13:02:32.134902 2026] [security2:error] [pid 139043:tid 139173] [client 20.251.112.238:8009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zz.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhhgAAAIU"] [Tue Aug 18 13:02:32.184323 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:32.184586 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:32.207590 2026] [security2:error] [pid 139043:tid 139262] [client 20.65.105.233:12768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/155.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhiAAAAN4"] [Tue Aug 18 13:02:32.223661 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yn.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhigAAALQ"] [Tue Aug 18 13:02:32.224349 2026] [security2:error] [pid 123784:tid 123903] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/album.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTVwAAKnI"] [Tue Aug 18 13:02:32.236174 2026] [security2:error] [pid 139043:tid 139136] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/config/.env.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhiwAA51w"] [Tue Aug 18 13:02:32.240854 2026] [security2:error] [pid 123784:tid 123869] [remote 185.23.70.16:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.70.23.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTWAAAFFA"] [Tue Aug 18 13:02:32.243236 2026] [security2:error] [pid 139043:tid 139121] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/core/.env"] [unique_id "aoSCGP2v-lWn9OzQT7UhjAAAxk0"] [Tue Aug 18 13:02:32.245397 2026] [security2:error] [pid 139043:tid 139094] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/config.php.bak"] [unique_id "aoSCGP2v-lWn9OzQT7UhjgAAxjI"] [Tue Aug 18 13:02:32.246148 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:41980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ue.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhjwAAAKk"] [Tue Aug 18 13:02:32.247916 2026] [security2:error] [pid 139043:tid 139118] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCGP2v-lWn9OzQT7UhkAAAiko"] [Tue Aug 18 13:02:32.247941 2026] [security2:error] [pid 139043:tid 139095] [remote 34.62.54.143:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dev.dashboard.tentaclehost.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCGP2v-lWn9OzQT7UhkQAAijM"] [Tue Aug 18 13:02:32.295737 2026] [security2:error] [pid 139043:tid 139213] [client 68.155.154.236:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhkwAAAK0"] [Tue Aug 18 13:02:32.315960 2026] [security2:error] [pid 139043:tid 139223] [client 20.206.73.37:35271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhlgAAALc"] [Tue Aug 18 13:02:32.332354 2026] [security2:error] [pid 139043:tid 139217] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhlAAAsQU"] [Tue Aug 18 13:02:32.366084 2026] [security2:error] [pid 123784:tid 123914] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kv.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTWQAAQX0"] [Tue Aug 18 13:02:32.367194 2026] [security2:error] [pid 123784:tid 123990] [client 20.65.69.59:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fo.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTWgAAAEg"] [Tue Aug 18 13:02:32.411682 2026] [security2:error] [pid 139043:tid 139279] [client 172.213.243.2:11387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/txets.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhmgAAAO8"] [Tue Aug 18 13:02:32.415894 2026] [security2:error] [pid 139043:tid 139299] [client 172.202.39.151:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhmwAAAQM"] [Tue Aug 18 13:02:32.426250 2026] [security2:error] [pid 139043:tid 139192] [client 172.182.200.96:15686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhnAAAAJg"] [Tue Aug 18 13:02:32.431813 2026] [security2:error] [pid 123784:tid 123930] [client 158.158.74.177:19369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/text.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTWwAAAAw"] [Tue Aug 18 13:02:32.450790 2026] [security2:error] [pid 123784:tid 123999] [client 20.65.105.233:12469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fasx.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTXAAAAFE"] [Tue Aug 18 13:02:32.486779 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:32.487066 2026] [authz_core:error] [pid 123784:tid 123811] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:32.496086 2026] [security2:error] [pid 123784:tid 124035] [client 20.79.204.6:10423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/fone1.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTXwAAAHU"] [Tue Aug 18 13:02:32.511518 2026] [security2:error] [pid 123784:tid 123837] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/z.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTYAAAEDA"] [Tue Aug 18 13:02:32.512483 2026] [security2:error] [pid 123784:tid 124032] [client 66.187.6.102:45188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/rolos/rolos-para-textura"] [unique_id "aoSCGGwDnJBNj2tDbYYTYQAAAHI"] [Tue Aug 18 13:02:32.512622 2026] [security2:error] [pid 123784:tid 124032] [client 66.187.6.102:45188] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pinceisroma.com.br"] [uri "/pt/produtos/rolos/rolos-para-textura"] [unique_id "aoSCGGwDnJBNj2tDbYYTYQAAAHI"] [Tue Aug 18 13:02:32.537225 2026] [security2:error] [pid 139043:tid 139196] [client 213.35.127.232:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhqgAAAJw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:32.537581 2026] [security2:error] [pid 139043:tid 139237] [client 20.250.13.23:53153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ors32envu.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhqwAAAMU"] [Tue Aug 18 13:02:32.545172 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:63034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/xn.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTYwAAADY"] [Tue Aug 18 13:02:32.567770 2026] [security2:error] [pid 123784:tid 123979] [client 20.251.112.238:18237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xa.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTZAAAAD0"] [Tue Aug 18 13:02:32.680393 2026] [security2:error] [pid 123784:tid 123826] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xg.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTZgAAWCU"] [Tue Aug 18 13:02:32.696013 2026] [security2:error] [pid 123784:tid 123923] [client 20.65.105.233:12764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-good.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTZwAAAAU"] [Tue Aug 18 13:02:32.704691 2026] [security2:error] [pid 123784:tid 124008] [client 20.65.69.59:27869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/loading.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTaAAAAFo"] [Tue Aug 18 13:02:32.783566 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.154.236:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTcQAAAEY"] [Tue Aug 18 13:02:32.789616 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:32.789914 2026] [authz_core:error] [pid 123784:tid 123813] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:32.818241 2026] [security2:error] [pid 123784:tid 123803] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/nd.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTcwAAEg4"] [Tue Aug 18 13:02:32.836692 2026] [security2:error] [pid 123784:tid 124020] [client 172.213.243.2:16061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fun.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTdQAAAGY"] [Tue Aug 18 13:02:32.916495 2026] [security2:error] [pid 139043:tid 139212] [client 158.23.17.4:40432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/47.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhtQAAAKw"] [Tue Aug 18 13:02:32.936834 2026] [security2:error] [pid 139043:tid 139283] [client 20.65.105.233:12742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/zxin.php"] [unique_id "aoSCGP2v-lWn9OzQT7UhtgAAAPM"] [Tue Aug 18 13:02:32.960535 2026] [security2:error] [pid 123784:tid 123970] [client 20.151.109.219:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/km.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTdgAAADQ"] [Tue Aug 18 13:02:32.984792 2026] [security2:error] [pid 123784:tid 123929] [client 20.251.112.238:64440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/f6.php"] [unique_id "aoSCGGwDnJBNj2tDbYYTeAAAAAs"] [Tue Aug 18 13:02:33.010550 2026] [security2:error] [pid 123784:tid 123805] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ri.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTeQAAKBA"] [Tue Aug 18 13:02:33.017142 2026] [security2:error] [pid 123784:tid 124028] [client 20.65.69.59:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ke.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTegAAAG4"] [Tue Aug 18 13:02:33.058927 2026] [security2:error] [pid 123784:tid 123953] [client 158.158.74.177:4004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTewAAACM"] [Tue Aug 18 13:02:33.059197 2026] [security2:error] [pid 123784:tid 124029] [client 20.251.48.93:53106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTfAAAAG8"] [Tue Aug 18 13:02:33.086865 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:33.087129 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:33.092042 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/40.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTfwAAADg"] [Tue Aug 18 13:02:33.119332 2026] [security2:error] [pid 139043:tid 139242] [client 20.118.133.132:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/mgrr.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh1AAAAMo"] [Tue Aug 18 13:02:33.163941 2026] [security2:error] [pid 123784:tid 123793] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/tp.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTgQAAUwQ"] [Tue Aug 18 13:02:33.168902 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/11.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTggAAADU"] [Tue Aug 18 13:02:33.171188 2026] [security2:error] [pid 123784:tid 123975] [client 20.250.13.23:20288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ov-simple1.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTgwAAADk"] [Tue Aug 18 13:02:33.176599 2026] [security2:error] [pid 123784:tid 124037] [client 20.65.105.233:12763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/pass4.php"] [unique_id "aoSCGWwDnJBNj2tDbYYThAAAAHc"] [Tue Aug 18 13:02:33.228187 2026] [security2:error] [pid 123784:tid 123927] [client 20.79.204.6:10380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ncx.php"] [unique_id "aoSCGWwDnJBNj2tDbYYThgAAAAk"] [Tue Aug 18 13:02:33.243612 2026] [security2:error] [pid 139043:tid 139246] [client 172.182.200.96:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh1wAAAM4"] [Tue Aug 18 13:02:33.277882 2026] [security2:error] [pid 123784:tid 124023] [client 172.213.243.2:35293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/jq.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTiAAAAGk"] [Tue Aug 18 13:02:33.299098 2026] [security2:error] [pid 123784:tid 123959] [client 158.23.17.4:48421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/payout.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTiQAAACk"] [Tue Aug 18 13:02:33.301292 2026] [security2:error] [pid 123784:tid 123872] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/zj.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTigAAA1M"] [Tue Aug 18 13:02:33.338653 2026] [security2:error] [pid 123784:tid 123986] [client 20.65.69.59:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nh.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTiwAAAEQ"] [Tue Aug 18 13:02:33.376686 2026] [security2:error] [pid 123784:tid 124034] [client 68.155.154.236:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTjQAAAHQ"] [Tue Aug 18 13:02:33.389458 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:33.389730 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:33.395029 2026] [security2:error] [pid 139043:tid 139241] [client 86.120.159.145:15663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh3AAAAMk"] [Tue Aug 18 13:02:33.395190 2026] [security2:error] [pid 139043:tid 139241] [client 86.120.159.145:15663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh3AAAAMk"] [Tue Aug 18 13:02:33.417750 2026] [security2:error] [pid 123784:tid 124000] [client 20.65.105.233:12595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTjwAAAFI"] [Tue Aug 18 13:02:33.449383 2026] [security2:error] [pid 123784:tid 123862] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/x.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTkAAAOkk"] [Tue Aug 18 13:02:33.470463 2026] [security2:error] [pid 123784:tid 123941] [client 20.251.112.238:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mcs.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTkQAAABc"] [Tue Aug 18 13:02:33.535794 2026] [security2:error] [pid 139043:tid 139186] [client 68.155.154.236:8702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh3gAAAJI"] [Tue Aug 18 13:02:33.550713 2026] [security2:error] [pid 139043:tid 139285] [client 213.35.127.232:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh3wAAAPU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:33.599936 2026] [security2:error] [pid 123784:tid 123804] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/yn.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTkgAAKg8"] [Tue Aug 18 13:02:33.659632 2026] [security2:error] [pid 123784:tid 123920] [client 20.65.105.233:12757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/z.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTkwAAAAI"] [Tue Aug 18 13:02:33.690950 2026] [security2:error] [pid 139043:tid 139190] [client 172.213.243.2:15726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sys.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh4AAAAJY"] [Tue Aug 18 13:02:33.692023 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:33.692307 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:33.692392 2026] [security2:error] [pid 139043:tid 139240] [client 158.158.74.177:3656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/u.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh4QAAAMg"] [Tue Aug 18 13:02:33.703593 2026] [security2:error] [pid 139043:tid 139211] [client 20.65.69.59:5383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/oo.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh4gAAAKs"] [Tue Aug 18 13:02:33.738327 2026] [security2:error] [pid 123784:tid 123828] [remote 192.250.229.214:43888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTlQAAYSc"] [Tue Aug 18 13:02:33.740607 2026] [security2:error] [pid 123784:tid 123990] [client 20.65.98.162:25383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lecarveiculospira.com.br"] [uri "/33.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTlgAAAEg"] [Tue Aug 18 13:02:33.823846 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/bh.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTlwAAAFc"] [Tue Aug 18 13:02:33.899629 2026] [security2:error] [pid 139043:tid 139227] [client 20.65.105.233:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/222.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh5AAAALs"] [Tue Aug 18 13:02:33.917486 2026] [security2:error] [pid 123784:tid 123934] [client 20.251.112.238:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/xleet.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTmAAAABA"] [Tue Aug 18 13:02:33.940396 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:8918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vm.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTmQAAAGc"] [Tue Aug 18 13:02:33.957905 2026] [security2:error] [pid 139043:tid 139263] [client 20.250.13.23:30827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ova.php"] [unique_id "aoSCGf2v-lWn9OzQT7Uh5QAAAN8"] [Tue Aug 18 13:02:33.992651 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:33.992914 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:34.004973 2026] [security2:error] [pid 123784:tid 123795] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/11.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTnAAAPgY"] [Tue Aug 18 13:02:34.018919 2026] [security2:error] [pid 123784:tid 124006] [client 20.65.69.59:5746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ja.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTnQAAAFg"] [Tue Aug 18 13:02:34.074713 2026] [security2:error] [pid 123784:tid 124008] [client 172.202.39.151:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTngAAAFo"] [Tue Aug 18 13:02:34.127711 2026] [security2:error] [pid 139043:tid 139176] [client 172.213.243.2:17753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/pp.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh5wAAAIg"] [Tue Aug 18 13:02:34.129326 2026] [security2:error] [pid 123784:tid 123995] [client 20.116.17.175:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/yawa.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTpQAAAE0"] [Tue Aug 18 13:02:34.139086 2026] [security2:error] [pid 123784:tid 123928] [client 20.65.105.233:12745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/G-in.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTpgAAAAo"] [Tue Aug 18 13:02:34.157269 2026] [security2:error] [pid 139043:tid 139219] [client 20.251.48.93:31646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/sf.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh6AAAALM"] [Tue Aug 18 13:02:34.162865 2026] [security2:error] [pid 123784:tid 123899] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vm.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTqAAAe24"] [Tue Aug 18 13:02:34.198423 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/ct.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh6QAAALQ"] [Tue Aug 18 13:02:34.220784 2026] [security2:error] [pid 123784:tid 123931] [client 68.155.154.236:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTqQAAAA0"] [Tue Aug 18 13:02:34.231994 2026] [security2:error] [pid 123784:tid 123998] [client 20.79.204.6:10746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTqgAAAFA"] [Tue Aug 18 13:02:34.240517 2026] [security2:error] [pid 123784:tid 124045] [client 68.155.154.236:41473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTrQAAAH8"] [Tue Aug 18 13:02:34.294167 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:34.294465 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:34.307244 2026] [security2:error] [pid 123784:tid 123833] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/eg.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTsgAAKCw"] [Tue Aug 18 13:02:34.313821 2026] [security2:error] [pid 123784:tid 123950] [client 158.158.74.177:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/updates.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTswAAACA"] [Tue Aug 18 13:02:34.346283 2026] [security2:error] [pid 123784:tid 123987] [client 20.251.112.238:18180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fr/ms.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTtQAAAEU"] [Tue Aug 18 13:02:34.354653 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lr.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh6wAAAIs"] [Tue Aug 18 13:02:34.363125 2026] [security2:error] [pid 139043:tid 139181] [client 172.182.200.96:15620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh7AAAAI0"] [Tue Aug 18 13:02:34.379780 2026] [security2:error] [pid 139043:tid 139198] [client 20.65.105.233:12799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xxx.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh7QAAAJ4"] [Tue Aug 18 13:02:34.427964 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.69.59:9691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xx.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh8gAAAO8"] [Tue Aug 18 13:02:34.510799 2026] [security2:error] [pid 123784:tid 123807] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/uk.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTuQAAGxI"] [Tue Aug 18 13:02:34.564997 2026] [security2:error] [pid 139043:tid 139238] [client 213.35.127.232:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh9AAAAMY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:34.574145 2026] [security2:error] [pid 139043:tid 139267] [client 172.213.243.2:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wqqs.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh9QAAAOM"] [Tue Aug 18 13:02:34.592415 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/gy.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTvAAAAEw"] [Tue Aug 18 13:02:34.598699 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:34.599141 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:34.609464 2026] [security2:error] [pid 123784:tid 124002] [client 20.151.109.219:10566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mf.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTvQAAAFQ"] [Tue Aug 18 13:02:34.623218 2026] [security2:error] [pid 139043:tid 139185] [client 20.65.105.233:12462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/un.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh9gAAAJE"] [Tue Aug 18 13:02:34.633365 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.56.190:28239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/ninja.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTvwAAAGk"] [Tue Aug 18 13:02:34.648941 2026] [security2:error] [pid 123784:tid 123910] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/creds.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTwQAAHHk"] [Tue Aug 18 13:02:34.649949 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.13.23:30791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/p.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTwgAAAHM"] [Tue Aug 18 13:02:34.721223 2026] [security2:error] [pid 123784:tid 123959] [client 20.65.69.59:27848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/conn-test.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTxAAAACk"] [Tue Aug 18 13:02:34.757836 2026] [security2:error] [pid 139043:tid 139239] [client 20.251.112.238:18195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/gool.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh-AAAAMc"] [Tue Aug 18 13:02:34.811810 2026] [security2:error] [pid 123784:tid 123825] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ho.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTxgAARCQ"] [Tue Aug 18 13:02:34.814258 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:45841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTxwAAAF4"] [Tue Aug 18 13:02:34.865971 2026] [security2:error] [pid 123784:tid 123939] [client 20.65.105.233:12436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/autogooey.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTyAAAABU"] [Tue Aug 18 13:02:34.879941 2026] [security2:error] [pid 139043:tid 139244] [client 20.118.133.132:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/55.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh-gAAAMw"] [Tue Aug 18 13:02:34.881876 2026] [security2:error] [pid 139043:tid 139214] [client 168.62.48.100:4161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/rymmm.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh-wAAAK4"] [Tue Aug 18 13:02:34.895217 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:34.895490 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:34.935474 2026] [security2:error] [pid 139043:tid 139273] [client 158.158.74.177:3985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh_QAAAOk"] [Tue Aug 18 13:02:34.949429 2026] [security2:error] [pid 123784:tid 123901] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/97.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTywAAOnA"] [Tue Aug 18 13:02:34.959879 2026] [security2:error] [pid 123784:tid 124044] [client 172.182.200.96:15676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCGmwDnJBNj2tDbYYTzAAAAH4"] [Tue Aug 18 13:02:34.968005 2026] [security2:error] [pid 139043:tid 139254] [client 158.23.17.4:17555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ee.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh_gAAANY"] [Tue Aug 18 13:02:34.979950 2026] [security2:error] [pid 139043:tid 139260] [client 158.23.17.4:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/tt.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh_wAAANw"] [Tue Aug 18 13:02:34.985325 2026] [security2:error] [pid 139043:tid 139297] [client 172.213.243.2:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/clasa99.php"] [unique_id "aoSCGv2v-lWn9OzQT7UiAAAAAQE"] [Tue Aug 18 13:02:35.015081 2026] [security2:error] [pid 139043:tid 139278] [client 20.65.69.59:5398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fg.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiAQAAAO4"] [Tue Aug 18 13:02:35.095950 2026] [security2:error] [pid 123784:tid 123861] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/rh.php"] [unique_id "aoSCG2wDnJBNj2tDbYYTzwAAM0g"] [Tue Aug 18 13:02:35.106566 2026] [security2:error] [pid 139043:tid 139212] [client 20.65.105.233:12446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sty.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiBAAAAKw"] [Tue Aug 18 13:02:35.192097 2026] [security2:error] [pid 123784:tid 123948] [client 172.202.39.151:44145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/ok.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT0QAAAB4"] [Tue Aug 18 13:02:35.199127 2026] [security2:error] [pid 123784:tid 123999] [client 78.47.173.76:20926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.petceu.com.br"] [uri "/index.php"] [unique_id "aoSCGWwDnJBNj2tDbYYTmgAAAFE"], referer: https://www.petceu.com.br [Tue Aug 18 13:02:35.200480 2026] [security2:error] [pid 139043:tid 139294] [client 20.251.112.238:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/maxro.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiBQAAAP4"] [Tue Aug 18 13:02:35.208435 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:35.208914 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:35.231023 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:12485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/eg.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiBwAAAPk"] [Tue Aug 18 13:02:35.233051 2026] [security2:error] [pid 123784:tid 123844] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/yg.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT0wAAVjc"] [Tue Aug 18 13:02:35.262790 2026] [security2:error] [pid 139043:tid 139300] [client 20.151.109.219:14109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/97.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiCgAAAQQ"] [Tue Aug 18 13:02:35.319508 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ie.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiCwAAAMs"] [Tue Aug 18 13:02:35.347622 2026] [security2:error] [pid 123784:tid 123963] [client 20.65.105.233:12777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wio.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT1QAAAC0"] [Tue Aug 18 13:02:35.374977 2026] [security2:error] [pid 123784:tid 123887] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/et.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT1wAASWI"] [Tue Aug 18 13:02:35.375871 2026] [security2:error] [pid 139043:tid 139186] [client 168.62.48.100:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/index/function.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiDQAAAJI"] [Tue Aug 18 13:02:35.386127 2026] [security2:error] [pid 123784:tid 123983] [client 68.155.154.236:63593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT2AAAAEE"] [Tue Aug 18 13:02:35.395182 2026] [security2:error] [pid 123784:tid 123930] [client 158.23.17.4:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/mq.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT2QAAAAw"] [Tue Aug 18 13:02:35.397371 2026] [security2:error] [pid 139043:tid 139285] [client 172.213.243.2:11334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/666.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiDgAAAPU"] [Tue Aug 18 13:02:35.404539 2026] [security2:error] [pid 139043:tid 139242] [client 20.250.13.23:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/pages.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiDwAAAMo"] [Tue Aug 18 13:02:35.452888 2026] [security2:error] [pid 123784:tid 124030] [client 20.251.48.93:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/k.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT3QAAAHA"] [Tue Aug 18 13:02:35.466513 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:8742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ka.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT3gAAACQ"] [Tue Aug 18 13:02:35.479550 2026] [security2:error] [pid 139043:tid 139196] [client 168.119.96.239:52514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.capecodcleaningservice.com"] [uri "/index.php"] [unique_id "aoSCGv2v-lWn9OzQT7Uh-QAAAJw"], referer: https://www.capecodcleaningservice.com [Tue Aug 18 13:02:35.517793 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:35.518131 2026] [authz_core:error] [pid 123784:tid 123852] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:35.535335 2026] [security2:error] [pid 123784:tid 123908] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/of.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT4AAAZ3c"] [Tue Aug 18 13:02:35.552539 2026] [security2:error] [pid 139043:tid 139200] [client 4.232.151.198:11601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/xleet.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiEgAAAKA"] [Tue Aug 18 13:02:35.558940 2026] [security2:error] [pid 123784:tid 123972] [client 20.65.69.59:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ve.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT4gAAADY"] [Tue Aug 18 13:02:35.562102 2026] [security2:error] [pid 139043:tid 139226] [client 158.158.74.177:3708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seunegociopodemais.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiEwAAALo"] [Tue Aug 18 13:02:35.577508 2026] [security2:error] [pid 139043:tid 139228] [client 213.35.127.232:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiFAAAALw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:35.588748 2026] [security2:error] [pid 123784:tid 123979] [client 20.65.105.233:12427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/1061.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT4wAAAD0"] [Tue Aug 18 13:02:35.610428 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.56.190:3019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/phpprobe.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT5QAAACs"] [Tue Aug 18 13:02:35.628661 2026] [security2:error] [pid 139043:tid 139177] [client 20.251.112.238:7199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wdf.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiGQAAAIk"] [Tue Aug 18 13:02:35.630127 2026] [security2:error] [pid 123784:tid 123938] [client 20.79.204.6:10770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wso.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT5wAAABQ"] [Tue Aug 18 13:02:35.728141 2026] [security2:error] [pid 123784:tid 123857] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/bu.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT6gAALkQ"] [Tue Aug 18 13:02:35.807915 2026] [security2:error] [pid 139043:tid 139248] [client 172.213.243.2:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/thui.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiHwAAANA"] [Tue Aug 18 13:02:35.818241 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:35.818514 2026] [authz_core:error] [pid 123784:tid 123846] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:35.824218 2026] [security2:error] [pid 139043:tid 139176] [client 20.151.109.219:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rh.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiIAAAAIg"] [Tue Aug 18 13:02:35.829042 2026] [security2:error] [pid 123784:tid 123984] [client 20.65.105.233:12782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/gec.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT7AAAAEI"] [Tue Aug 18 13:02:35.923939 2026] [security2:error] [pid 123784:tid 123876] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/rn.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT8QAAZlc"] [Tue Aug 18 13:02:35.937521 2026] [security2:error] [pid 123784:tid 123931] [client 20.116.17.175:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT8gAAAA0"] [Tue Aug 18 13:02:35.938620 2026] [security2:error] [pid 139043:tid 139178] [client 20.151.109.219:27753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nw.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiIQAAAIo"] [Tue Aug 18 13:02:35.973869 2026] [security2:error] [pid 123784:tid 123998] [client 68.155.154.236:41476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCG2wDnJBNj2tDbYYT8wAAAFA"] [Tue Aug 18 13:02:36.006944 2026] [security2:error] [pid 123784:tid 123835] [remote 84.205.178.135:16310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gvc.eng.br"] [uri "/wp-login.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT9QAASi4"] [Tue Aug 18 13:02:36.068889 2026] [security2:error] [pid 123784:tid 123929] [client 158.23.17.4:20164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/uk.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT9wAAAAs"] [Tue Aug 18 13:02:36.069076 2026] [security2:error] [pid 139043:tid 139179] [client 20.251.112.238:18188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ff1.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiIwAAAIs"] [Tue Aug 18 13:02:36.072952 2026] [security2:error] [pid 139043:tid 139281] [client 172.182.200.96:15641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiJAAAAPE"] [Tue Aug 18 13:02:36.076006 2026] [security2:error] [pid 123784:tid 123957] [client 20.65.105.233:12439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/scx.php7"] [unique_id "aoSCHGwDnJBNj2tDbYYT-AAAACc"] [Tue Aug 18 13:02:36.083581 2026] [security2:error] [pid 123784:tid 123821] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ut.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT-QAAKCA"] [Tue Aug 18 13:02:36.086108 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/13.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiJQAAAIY"] [Tue Aug 18 13:02:36.107339 2026] [security2:error] [pid 123784:tid 123928] [client 20.250.13.23:3627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/past.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT_AAAAAo"] [Tue Aug 18 13:02:36.126659 2026] [security2:error] [pid 123784:tid 123985] [client 52.173.121.69:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT_gAAAEM"] [Tue Aug 18 13:02:36.126659 2026] [security2:error] [pid 139043:tid 139299] [client 20.65.69.59:5714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ia.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiJgAAAQM"] [Tue Aug 18 13:02:36.149300 2026] [security2:error] [pid 123784:tid 123953] [client 20.251.48.93:32911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/82.php"] [unique_id "aoSCHGwDnJBNj2tDbYYT_wAAACM"] [Tue Aug 18 13:02:36.160910 2026] [authz_core:error] [pid 123784:tid 123970] [client 192.178.4.133:52393] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:36.161172 2026] [authz_core:error] [pid 123784:tid 123970] [client 192.178.4.133:52393] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:36.198907 2026] [security2:error] [pid 139043:tid 139292] [client 20.151.109.219:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/yg.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiKQAAAPw"] [Tue Aug 18 13:02:36.219806 2026] [security2:error] [pid 139043:tid 139208] [client 172.213.243.2:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/agg.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiKgAAAKg"] [Tue Aug 18 13:02:36.220881 2026] [security2:error] [pid 123784:tid 123815] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/eh.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUAgAAUxo"] [Tue Aug 18 13:02:36.316739 2026] [security2:error] [pid 123784:tid 123925] [client 20.65.105.233:12747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUBQAAAAc"] [Tue Aug 18 13:02:36.358224 2026] [security2:error] [pid 123784:tid 123789] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ad.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUBgAAGAA"] [Tue Aug 18 13:02:36.394537 2026] [security2:error] [pid 123784:tid 123988] [client 158.23.17.4:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ot.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUCAAAAEY"] [Tue Aug 18 13:02:36.431613 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:36.431961 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:36.439897 2026] [security2:error] [pid 139043:tid 139259] [client 34.156.195.117:46582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/graphql"] [unique_id "aoSCHP2v-lWn9OzQT7UiNwAAANs"], referer: https://mail.gigapixelhost.com.br [Tue Aug 18 13:02:36.457393 2026] [security2:error] [pid 139043:tid 139288] [client 34.156.195.117:46570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/static../.env"] [unique_id "aoSCHP2v-lWn9OzQT7UiOQAAAPg"] [Tue Aug 18 13:02:36.484351 2026] [security2:error] [pid 139043:tid 139254] [client 20.65.69.59:5399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kn.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiOwAAANY"] [Tue Aug 18 13:02:36.494621 2026] [security2:error] [pid 123784:tid 123893] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/vd.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUCgAATGg"] [Tue Aug 18 13:02:36.525428 2026] [security2:error] [pid 139043:tid 139260] [client 172.202.39.151:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sfcacessorios.com"] [uri "/item.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiPAAAANw"] [Tue Aug 18 13:02:36.528450 2026] [autoindex:error] [pid 123784:tid 123996] [client 34.156.195.117:46568] AH01276: Cannot serve directory /home1/gigapi05/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:36.534786 2026] [security2:error] [pid 139043:tid 139180] [client 158.23.17.4:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ak.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiPQAAAIw"] [Tue Aug 18 13:02:36.562351 2026] [security2:error] [pid 139043:tid 139222] [client 20.151.109.219:24392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/et.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiPgAAALY"] [Tue Aug 18 13:02:36.563857 2026] [security2:error] [pid 139043:tid 139231] [client 20.65.105.233:12428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp5.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiPwAAAL8"] [Tue Aug 18 13:02:36.570024 2026] [security2:error] [pid 139043:tid 139261] [client 20.251.112.238:8003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/guk.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiQAAAAN0"] [Tue Aug 18 13:02:36.576578 2026] [security2:error] [pid 139043:tid 139277] [client 116.179.37.189:48421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiQQAAAO0"], referer: http://siderurgiabrasil.com.br/2025/11/07/as-estruturas-em-aco-do-grande-premio-de-sao-paulo/ [Tue Aug 18 13:02:36.588809 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:63036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/so.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUDgAAAG8"] [Tue Aug 18 13:02:36.593890 2026] [security2:error] [pid 139043:tid 139207] [client 213.35.127.232:53493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiQwAAAKc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:36.607238 2026] [security2:error] [pid 123784:tid 123946] [client 172.182.200.96:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUDwAAABw"] [Tue Aug 18 13:02:36.617157 2026] [security2:error] [pid 139043:tid 139216] [client 157.90.155.240:35644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rhsolucionar.com.br"] [uri "/index.php"] [unique_id "aoSCG_2v-lWn9OzQT7UiGAAAALA"], referer: https://www.rhsolucionar.com.br/ [Tue Aug 18 13:02:36.624386 2026] [security2:error] [pid 123784:tid 123974] [client 149.34.210.141:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUEAAAADg"] [Tue Aug 18 13:02:36.631695 2026] [security2:error] [pid 123784:tid 123840] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/56.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUEQAAczM"] [Tue Aug 18 13:02:36.637483 2026] [security2:error] [pid 123784:tid 124011] [client 172.213.243.2:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/erty.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUEwAAAF0"] [Tue Aug 18 13:02:36.732015 2026] [security2:error] [pid 139043:tid 139293] [client 20.151.109.219:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sb.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiRAAAAP0"] [Tue Aug 18 13:02:36.739332 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:36.739716 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:36.741974 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/php.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiRQAAAQE"] [Tue Aug 18 13:02:36.804500 2026] [security2:error] [pid 123784:tid 123967] [client 20.65.105.233:12736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/a2.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUGgAAADE"] [Tue Aug 18 13:02:36.814848 2026] [security2:error] [pid 123784:tid 123806] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/rx.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUGwAADBE"] [Tue Aug 18 13:02:36.822316 2026] [security2:error] [pid 139043:tid 139186] [client 68.155.154.236:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiRwAAAJI"] [Tue Aug 18 13:02:36.827879 2026] [security2:error] [pid 139043:tid 139285] [client 20.65.69.59:5418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wm.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiSAAAAPU"] [Tue Aug 18 13:02:36.841578 2026] [security2:error] [pid 139043:tid 139255] [client 20.151.109.219:24432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/of.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiSQAAANc"] [Tue Aug 18 13:02:36.855891 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:57263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/creds.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUHQAAAHA"] [Tue Aug 18 13:02:36.861810 2026] [security2:error] [pid 123784:tid 124013] [client 68.155.154.236:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUHgAAAF8"] [Tue Aug 18 13:02:36.878533 2026] [security2:error] [pid 123784:tid 123989] [client 102.213.179.104:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUHwAAAEc"] [Tue Aug 18 13:02:36.878715 2026] [security2:error] [pid 123784:tid 123989] [client 102.213.179.104:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUHwAAAEc"] [Tue Aug 18 13:02:36.892037 2026] [security2:error] [pid 123784:tid 123974] [client 149.34.210.141:62201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUEAAAADg"] [Tue Aug 18 13:02:36.907130 2026] [security2:error] [pid 139043:tid 139282] [client 34.156.195.117:46576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/media../.env"] [unique_id "aoSCHP2v-lWn9OzQT7UiSwAAAPI"] [Tue Aug 18 13:02:36.959011 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:40425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/10.php"] [unique_id "aoSCHP2v-lWn9OzQT7UiTgAAAKA"] [Tue Aug 18 13:02:36.971971 2026] [security2:error] [pid 123784:tid 123818] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mandrill.php"] [unique_id "aoSCHGwDnJBNj2tDbYYUIQAAJB0"] [Tue Aug 18 13:02:37.016202 2026] [security2:error] [pid 139043:tid 139262] [client 213.202.253.4:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/userfuns.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiUAAAAN4"], referer: www.google.com [Tue Aug 18 13:02:37.036430 2026] [security2:error] [pid 139043:tid 139175] [client 20.251.112.238:18236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-the.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiUQAAAIc"] [Tue Aug 18 13:02:37.043995 2026] [security2:error] [pid 139043:tid 139177] [client 20.65.105.233:12795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/app.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiUgAAAIk"] [Tue Aug 18 13:02:37.074543 2026] [security2:error] [pid 123784:tid 123801] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUIwAASAw"] [Tue Aug 18 13:02:37.074709 2026] [security2:error] [pid 123784:tid 123990] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUIwAASAw"] [Tue Aug 18 13:02:37.084375 2026] [security2:error] [pid 123784:tid 123972] [client 172.213.243.2:5654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mini.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUJAAAADY"] [Tue Aug 18 13:02:37.090620 2026] [security2:error] [pid 139043:tid 139210] [client 20.65.69.59:27875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ac.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiUwAAAKo"] [Tue Aug 18 13:02:37.091051 2026] [security2:error] [pid 139043:tid 139191] [client 172.182.200.96:15628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiVAAAAJc"] [Tue Aug 18 13:02:37.104943 2026] [security2:error] [pid 139043:tid 139298] [client 34.156.195.117:46570] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCHf2v-lWn9OzQT7UiVQAAAQI"] [Tue Aug 18 13:02:37.137687 2026] [security2:error] [pid 123784:tid 123854] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/main.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUJgAAK0E"] [Tue Aug 18 13:02:37.202932 2026] [security2:error] [pid 123784:tid 124025] [client 20.251.48.93:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/dex.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUKAAAAGs"] [Tue Aug 18 13:02:37.231898 2026] [security2:error] [pid 139043:tid 139219] [client 20.116.17.175:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/7.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiVwAAALM"] [Tue Aug 18 13:02:37.251687 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:15152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/test_info.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUKQAAAGQ"] [Tue Aug 18 13:02:37.275014 2026] [security2:error] [pid 139043:tid 139233] [client 20.151.109.219:58734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xj.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiWAAAAME"] [Tue Aug 18 13:02:37.280640 2026] [security2:error] [pid 123784:tid 123868] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ga.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUKwAAPk8"] [Tue Aug 18 13:02:37.308297 2026] [security2:error] [pid 123784:tid 123951] [client 20.151.109.219:24436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/bu.php"] [unique_id "aoSCHWwDnJBNj2tDbYYULAAAACE"] [Tue Aug 18 13:02:37.341271 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:37.341544 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:37.366351 2026] [security2:error] [pid 139043:tid 139101] [remote 162.214.205.212:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiXQAA6Tk"] [Tue Aug 18 13:02:37.385590 2026] [security2:error] [pid 123784:tid 123965] [client 34.156.195.117:46276] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/etc/passwd"] [unique_id "aoSCHWwDnJBNj2tDbYYUMAAAAC8"] [Tue Aug 18 13:02:37.396626 2026] [security2:error] [pid 123784:tid 124012] [client 34.156.195.117:46502] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHWwDnJBNj2tDbYYUMQAAAF4"] [Tue Aug 18 13:02:37.413095 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:30835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/php8.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUMwAAABQ"] [Tue Aug 18 13:02:37.420479 2026] [security2:error] [pid 139043:tid 139232] [client 20.65.69.59:52139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/yz.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiYQAAAMA"] [Tue Aug 18 13:02:37.423778 2026] [core:error] [pid 123784:tid 124026] [client 34.156.195.117:46212] AH10244: invalid URI path (/assets../../../etc/passwd) [Tue Aug 18 13:02:37.434492 2026] [security2:error] [pid 139043:tid 139174] [client 20.118.133.132:47926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/ajax.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiYgAAAIY"] [Tue Aug 18 13:02:37.438613 2026] [security2:error] [pid 123784:tid 123859] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/wb.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUOwAATUY"] [Tue Aug 18 13:02:37.442203 2026] [security2:error] [pid 123784:tid 124041] [client 20.251.112.238:45056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sbhu.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUPAAAAHs"] [Tue Aug 18 13:02:37.456343 2026] [security2:error] [pid 123784:tid 123969] [client 34.156.195.117:46294] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/static../etc/passwd"] [unique_id "aoSCHWwDnJBNj2tDbYYUPwAAADM"] [Tue Aug 18 13:02:37.458905 2026] [security2:error] [pid 123784:tid 124009] [client 34.156.195.117:46328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/files../etc/passwd"] [unique_id "aoSCHWwDnJBNj2tDbYYUQAAAAFs"] [Tue Aug 18 13:02:37.468477 2026] [security2:error] [pid 123784:tid 123986] [client 34.156.195.117:46424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.git/HEAD"] [unique_id "aoSCHWwDnJBNj2tDbYYUQgAAAEQ"] [Tue Aug 18 13:02:37.470600 2026] [security2:error] [pid 123784:tid 123947] [client 34.156.195.117:46386] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/proc/self/environ"] [unique_id "aoSCHWwDnJBNj2tDbYYURAAAAB0"] [Tue Aug 18 13:02:37.471216 2026] [security2:error] [pid 139043:tid 139205] [client 34.156.195.117:46340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env"] [unique_id "aoSCHf2v-lWn9OzQT7UiYwAAAKU"] [Tue Aug 18 13:02:37.473708 2026] [security2:error] [pid 123784:tid 123926] [client 34.156.195.117:46470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/download"] [unique_id "aoSCHWwDnJBNj2tDbYYURQAAAAg"] [Tue Aug 18 13:02:37.475195 2026] [security2:error] [pid 139043:tid 139272] [client 34.156.195.117:46324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/media../etc/passwd"] [unique_id "aoSCHf2v-lWn9OzQT7UiZgAAAOg"] [Tue Aug 18 13:02:37.475793 2026] [security2:error] [pid 123784:tid 123921] [client 34.156.195.117:46476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/"] [unique_id "aoSCHWwDnJBNj2tDbYYURgAAAAM"] [Tue Aug 18 13:02:37.487579 2026] [security2:error] [pid 139043:tid 139279] [client 158.23.17.4:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/te.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiaAAAAO8"] [Tue Aug 18 13:02:37.500816 2026] [security2:error] [pid 139043:tid 139275] [client 172.213.243.2:17736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sid3.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiaQAAAOs"] [Tue Aug 18 13:02:37.512374 2026] [security2:error] [pid 139043:tid 139184] [client 34.156.195.117:46542] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHf2v-lWn9OzQT7UiagAAAJA"] [Tue Aug 18 13:02:37.512626 2026] [security2:error] [pid 139043:tid 139258] [client 34.156.195.117:46444] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCHf2v-lWn9OzQT7UiawAAANo"] [Tue Aug 18 13:02:37.523994 2026] [security2:error] [pid 123784:tid 123999] [client 34.156.195.117:46564] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCHWwDnJBNj2tDbYYUSQAAAFE"] [Tue Aug 18 13:02:37.524004 2026] [security2:error] [pid 139043:tid 139253] [client 34.156.195.117:46550] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHf2v-lWn9OzQT7UibgAAANU"] [Tue Aug 18 13:02:37.545946 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:63658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ih.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUSwAAAGY"] [Tue Aug 18 13:02:37.581817 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:52455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UicAAAALI"] [Tue Aug 18 13:02:37.581998 2026] [security2:error] [pid 139043:tid 139218] [client 178.153.171.161:52455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UicAAAALI"] [Tue Aug 18 13:02:37.597542 2026] [security2:error] [pid 139043:tid 139238] [client 20.151.109.219:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rn.php"] [unique_id "aoSCHf2v-lWn9OzQT7UicgAAAMY"] [Tue Aug 18 13:02:37.619626 2026] [security2:error] [pid 139043:tid 139264] [client 213.35.127.232:53729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCHf2v-lWn9OzQT7UicwAAAOA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:37.636558 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.154.236:9171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUTQAAAEo"] [Tue Aug 18 13:02:37.656744 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:37.657181 2026] [authz_core:error] [pid 123784:tid 123903] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:37.657716 2026] [security2:error] [pid 139043:tid 139206] [client 20.65.105.233:12769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCHf2v-lWn9OzQT7UidAAAAKY"] [Tue Aug 18 13:02:37.677475 2026] [security2:error] [pid 123784:tid 123929] [client 20.51.153.15:9750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUUAAAAAs"] [Tue Aug 18 13:02:37.681656 2026] [security2:error] [pid 139043:tid 139204] [client 157.20.138.62:51339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UidQAAAKQ"] [Tue Aug 18 13:02:37.681783 2026] [security2:error] [pid 139043:tid 139204] [client 157.20.138.62:51339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UidQAAAKQ"] [Tue Aug 18 13:02:37.693146 2026] [security2:error] [pid 123784:tid 123869] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/xn.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUUQAAS1A"] [Tue Aug 18 13:02:37.707673 2026] [security2:error] [pid 123784:tid 123957] [client 172.182.200.96:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUUwAAACc"] [Tue Aug 18 13:02:37.712217 2026] [security2:error] [pid 123784:tid 124038] [client 34.156.195.117:46368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/app/.env"] [unique_id "aoSCHWwDnJBNj2tDbYYUVQAAAHg"] [Tue Aug 18 13:02:37.712359 2026] [security2:error] [pid 123784:tid 123939] [client 34.156.195.117:46266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env"] [unique_id "aoSCHWwDnJBNj2tDbYYUVgAAABU"] [Tue Aug 18 13:02:37.851899 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:27739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ns.php"] [unique_id "aoSCHf2v-lWn9OzQT7UiegAAAIw"] [Tue Aug 18 13:02:37.871784 2026] [security2:error] [pid 123784:tid 123971] [client 20.65.69.59:43311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kj.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUXQAAADU"] [Tue Aug 18 13:02:37.894713 2026] [security2:error] [pid 139043:tid 139244] [client 20.251.112.238:45067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/zc-318.php"] [unique_id "aoSCHf2v-lWn9OzQT7UifQAAAMw"] [Tue Aug 18 13:02:37.897647 2026] [security2:error] [pid 139043:tid 139234] [client 20.65.105.233:12783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/cxc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UifgAAAMI"] [Tue Aug 18 13:02:37.911583 2026] [security2:error] [pid 139043:tid 139294] [client 172.213.243.2:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/moon.php"] [unique_id "aoSCHf2v-lWn9OzQT7UifwAAAP4"] [Tue Aug 18 13:02:37.916472 2026] [security2:error] [pid 139043:tid 139230] [client 20.151.109.219:14128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ut.php"] [unique_id "aoSCHf2v-lWn9OzQT7UigAAAAL4"] [Tue Aug 18 13:02:37.925744 2026] [security2:error] [pid 123784:tid 123817] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/47.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUXwAAORw"] [Tue Aug 18 13:02:37.943295 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:37.943565 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:37.969260 2026] [security2:error] [pid 139043:tid 139297] [client 20.226.56.190:28264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-title.php"] [unique_id "aoSCHf2v-lWn9OzQT7UihAAAAQE"] [Tue Aug 18 13:02:37.985562 2026] [security2:error] [pid 139043:tid 139252] [client 103.120.71.157:29945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UihgAAANQ"] [Tue Aug 18 13:02:37.985695 2026] [security2:error] [pid 139043:tid 139252] [client 103.120.71.157:29945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHf2v-lWn9OzQT7UihgAAANQ"] [Tue Aug 18 13:02:37.994081 2026] [security2:error] [pid 123784:tid 123925] [client 20.51.153.15:9753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCHWwDnJBNj2tDbYYUYQAAAAc"] [Tue Aug 18 13:02:38.031957 2026] [security2:error] [pid 123784:tid 123944] [client 158.23.17.4:32512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ho.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUYwAAABo"] [Tue Aug 18 13:02:38.055895 2026] [security2:error] [pid 123784:tid 123959] [client 34.156.195.117:46480] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCHmwDnJBNj2tDbYYUZAAAACk"] [Tue Aug 18 13:02:38.062382 2026] [security2:error] [pid 123784:tid 123794] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/payout.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUZgAATAU"] [Tue Aug 18 13:02:38.103068 2026] [security2:error] [pid 139043:tid 139250] [client 20.250.13.23:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/plugins.php"] [unique_id "aoSCHv2v-lWn9OzQT7UiiQAAANI"] [Tue Aug 18 13:02:38.155465 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.105.233:12743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCHmwDnJBNj2tDbYYUaAAAABw"] [Tue Aug 18 13:02:38.172827 2026] [security2:error] [pid 139043:tid 139196] [client 20.226.56.190:31033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/styles.php"] [unique_id "aoSCHv2v-lWn9OzQT7UiiwAAAJw"] [Tue Aug 18 13:02:38.179339 2026] [security2:error] [pid 123784:tid 123963] [client 172.182.200.96:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUaQAAAC0"] [Tue Aug 18 13:02:38.205065 2026] [security2:error] [pid 123784:tid 123790] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/bh.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUawAAMQE"] [Tue Aug 18 13:02:38.213100 2026] [security2:error] [pid 123784:tid 123918] [client 20.151.109.219:60901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/eh.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUbQAAAAA"] [Tue Aug 18 13:02:38.217595 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:46813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/kc.php"] [unique_id "aoSCHv2v-lWn9OzQT7UijQAAALo"] [Tue Aug 18 13:02:38.229162 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/14.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUbgAAAFk"] [Tue Aug 18 13:02:38.240261 2026] [security2:error] [pid 123784:tid 124030] [client 34.156.195.117:46548] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCHmwDnJBNj2tDbYYUcAAAAHA"] [Tue Aug 18 13:02:38.245251 2026] [security2:error] [pid 123784:tid 124013] [client 20.65.69.59:5754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vg.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUcQAAAF8"] [Tue Aug 18 13:02:38.245689 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:38.245955 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:38.257089 2026] [security2:error] [pid 123784:tid 123991] [client 138.36.100.162:41725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUcgAAAEk"] [Tue Aug 18 13:02:38.258939 2026] [security2:error] [pid 123784:tid 123991] [client 138.36.100.162:41725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUcgAAAEk"] [Tue Aug 18 13:02:38.300271 2026] [security2:error] [pid 139043:tid 139217] [client 20.79.204.6:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/zup.php73"] [unique_id "aoSCHv2v-lWn9OzQT7UijwAAALE"] [Tue Aug 18 13:02:38.324082 2026] [security2:error] [pid 139043:tid 139197] [client 20.251.112.238:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ccou.php"] [unique_id "aoSCHv2v-lWn9OzQT7UikAAAAJ0"] [Tue Aug 18 13:02:38.324866 2026] [security2:error] [pid 139043:tid 139229] [client 172.213.243.2:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ms.php"] [unique_id "aoSCHv2v-lWn9OzQT7UikQAAAL0"] [Tue Aug 18 13:02:38.359369 2026] [security2:error] [pid 123784:tid 124035] [client 34.156.195.117:46368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHmwDnJBNj2tDbYYUcwAAAHU"] [Tue Aug 18 13:02:38.363911 2026] [security2:error] [pid 123784:tid 123990] [client 34.156.195.117:46402] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHmwDnJBNj2tDbYYUdAAAAEg"] [Tue Aug 18 13:02:38.366425 2026] [security2:error] [pid 123784:tid 123883] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/ct.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUdQAANl4"] [Tue Aug 18 13:02:38.369328 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:9761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/st.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUdgAAAHo"] [Tue Aug 18 13:02:38.370433 2026] [security2:error] [pid 123784:tid 123979] [client 20.206.73.37:34755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/sky.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUdwAAAD0"] [Tue Aug 18 13:02:38.382483 2026] [security2:error] [pid 139043:tid 139219] [client 20.118.133.132:60051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/yj09.php"] [unique_id "aoSCHv2v-lWn9OzQT7UikgAAALM"] [Tue Aug 18 13:02:38.401762 2026] [security2:error] [pid 139043:tid 139194] [client 158.23.17.4:16926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/k.php"] [unique_id "aoSCHv2v-lWn9OzQT7UilAAAAJo"] [Tue Aug 18 13:02:38.406417 2026] [security2:error] [pid 139043:tid 139233] [client 20.65.105.233:12471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/0.php"] [unique_id "aoSCHv2v-lWn9OzQT7UilQAAAME"] [Tue Aug 18 13:02:38.466508 2026] [security2:error] [pid 123784:tid 124025] [client 40.74.65.169:44283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUfAAAAGs"] [Tue Aug 18 13:02:38.489715 2026] [security2:error] [pid 123784:tid 124006] [client 20.151.109.219:14113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ad.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUfgAAAFg"] [Tue Aug 18 13:02:38.508602 2026] [security2:error] [pid 139043:tid 139268] [client 20.65.69.59:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sm.php"] [unique_id "aoSCHv2v-lWn9OzQT7UilwAAAOQ"] [Tue Aug 18 13:02:38.546617 2026] [security2:error] [pid 123784:tid 123980] [client 20.151.109.219:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gk.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUgAAAAD4"] [Tue Aug 18 13:02:38.547001 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:38.547267 2026] [authz_core:error] [pid 123784:tid 123875] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:38.556458 2026] [security2:error] [pid 123784:tid 123793] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/gy.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUgQAAcgQ"] [Tue Aug 18 13:02:38.623954 2026] [security2:error] [pid 139043:tid 139291] [client 193.148.57.33:53854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "drogavilla.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCHv2v-lWn9OzQT7UimAAAAPs"] [Tue Aug 18 13:02:38.635877 2026] [security2:error] [pid 139043:tid 139177] [client 213.35.127.232:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCHv2v-lWn9OzQT7UimQAAAIk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:38.647569 2026] [security2:error] [pid 123784:tid 123933] [client 20.65.105.233:12422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/dom.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUgwAAAA8"] [Tue Aug 18 13:02:38.660678 2026] [security2:error] [pid 139043:tid 139235] [client 103.184.169.37:43399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHv2v-lWn9OzQT7UimgAAAMM"] [Tue Aug 18 13:02:38.660843 2026] [security2:error] [pid 139043:tid 139235] [client 103.184.169.37:43399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCHv2v-lWn9OzQT7UimgAAAMM"] [Tue Aug 18 13:02:38.661551 2026] [security2:error] [pid 139043:tid 139283] [client 168.62.48.100:4179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/lddxs.php"] [unique_id "aoSCHv2v-lWn9OzQT7UimwAAAPM"] [Tue Aug 18 13:02:38.690194 2026] [security2:error] [pid 123784:tid 123965] [client 172.182.200.96:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUhQAAAC8"] [Tue Aug 18 13:02:38.695950 2026] [security2:error] [pid 139043:tid 139184] [client 20.51.153.15:9754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/le.php"] [unique_id "aoSCHv2v-lWn9OzQT7UinAAAAJA"] [Tue Aug 18 13:02:38.705578 2026] [security2:error] [pid 123784:tid 123872] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/tt.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUhgAAXlM"] [Tue Aug 18 13:02:38.720620 2026] [security2:error] [pid 123784:tid 124018] [client 20.250.13.23:30799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/post.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUhwAAAGQ"] [Tue Aug 18 13:02:38.744894 2026] [security2:error] [pid 123784:tid 123938] [client 172.213.243.2:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wsws.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUiQAAABQ"] [Tue Aug 18 13:02:38.767579 2026] [security2:error] [pid 123784:tid 123984] [client 20.251.112.238:18192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/txets.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUigAAAEI"] [Tue Aug 18 13:02:38.849866 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:38.850137 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:38.864977 2026] [security2:error] [pid 123784:tid 123834] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/mq.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUjgAABi0"] [Tue Aug 18 13:02:38.873632 2026] [security2:error] [pid 139043:tid 139267] [client 158.23.17.4:56519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/jn.php"] [unique_id "aoSCHv2v-lWn9OzQT7UioAAAAOM"] [Tue Aug 18 13:02:38.886423 2026] [security2:error] [pid 139043:tid 139206] [client 20.65.69.59:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/28.php"] [unique_id "aoSCHv2v-lWn9OzQT7UioQAAAKY"] [Tue Aug 18 13:02:38.888203 2026] [security2:error] [pid 139043:tid 139204] [client 20.65.105.233:12552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/bb.php"] [unique_id "aoSCHv2v-lWn9OzQT7UiogAAAKQ"] [Tue Aug 18 13:02:38.915605 2026] [security2:error] [pid 139043:tid 139237] [client 20.151.109.219:14093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/vd.php"] [unique_id "aoSCHv2v-lWn9OzQT7UiowAAAMU"] [Tue Aug 18 13:02:38.919457 2026] [security2:error] [pid 123784:tid 123935] [client 168.62.48.100:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUjwAAABE"] [Tue Aug 18 13:02:38.964092 2026] [security2:error] [pid 139043:tid 139239] [client 68.155.154.236:8335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCHv2v-lWn9OzQT7UipQAAAMc"] [Tue Aug 18 13:02:38.977707 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:63616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/iu.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUlAAAAEQ"] [Tue Aug 18 13:02:38.978086 2026] [security2:error] [pid 123784:tid 123948] [client 34.156.195.117:46464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCHmwDnJBNj2tDbYYUkwAAAB4"] [Tue Aug 18 13:02:38.979564 2026] [security2:error] [pid 123784:tid 123892] [remote 129.121.103.155:40848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSCHmwDnJBNj2tDbYYUlQAAWmc"] [Tue Aug 18 13:02:38.981398 2026] [autoindex:error] [pid 139043:tid 139214] [client 169.58.72.248:56241] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:39.024395 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:9779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/hr.php"] [unique_id "aoSCH_2v-lWn9OzQT7UipwAAAPg"] [Tue Aug 18 13:02:39.030448 2026] [security2:error] [pid 139043:tid 139257] [client 34.156.195.117:46514] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCH_2v-lWn9OzQT7UiqAAAANk"] [Tue Aug 18 13:02:39.056138 2026] [security2:error] [pid 139043:tid 139176] [client 172.182.200.96:15691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiqQAAAIg"] [Tue Aug 18 13:02:39.060855 2026] [security2:error] [pid 123784:tid 123899] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/13.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUlwAAA24"] [Tue Aug 18 13:02:39.132926 2026] [security2:error] [pid 139043:tid 139207] [client 20.65.105.233:12787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ok.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiqgAAAKc"] [Tue Aug 18 13:02:39.149091 2026] [security2:error] [pid 139043:tid 139244] [client 20.116.17.175:54909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiqwAAAMw"] [Tue Aug 18 13:02:39.150455 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:39.150502 2026] [authz_core:error] [pid 123784:tid 123999] [client 192.178.4.133:52393] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:39.150715 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:39.150759 2026] [authz_core:error] [pid 123784:tid 123999] [client 192.178.4.133:52393] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:39.157245 2026] [security2:error] [pid 123784:tid 124019] [client 40.74.65.169:44226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUmwAAAGU"] [Tue Aug 18 13:02:39.161324 2026] [security2:error] [pid 123784:tid 123934] [client 20.65.69.59:5747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/m.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUnAAAABA"] [Tue Aug 18 13:02:39.164687 2026] [security2:error] [pid 139043:tid 139234] [client 172.213.243.2:12147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/motu.php"] [unique_id "aoSCH_2v-lWn9OzQT7UirAAAAMI"] [Tue Aug 18 13:02:39.168684 2026] [security2:error] [pid 139043:tid 139294] [client 158.23.17.4:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/tk.php"] [unique_id "aoSCH_2v-lWn9OzQT7UirQAAAP4"] [Tue Aug 18 13:02:39.173521 2026] [security2:error] [pid 139043:tid 139189] [client 20.79.204.6:10730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/k.php"] [unique_id "aoSCH_2v-lWn9OzQT7UirwAAAJU"] [Tue Aug 18 13:02:39.186227 2026] [security2:error] [pid 139043:tid 139293] [client 20.251.112.238:19009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fun.php"] [unique_id "aoSCH_2v-lWn9OzQT7UisAAAAP0"] [Tue Aug 18 13:02:39.194095 2026] [security2:error] [pid 139043:tid 139299] [client 4.232.151.198:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp.php"] [unique_id "aoSCH_2v-lWn9OzQT7UisQAAAQM"] [Tue Aug 18 13:02:39.210620 2026] [security2:error] [pid 123784:tid 123843] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/so.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUngAASzY"] [Tue Aug 18 13:02:39.273265 2026] [security2:error] [pid 139043:tid 139285] [client 158.23.17.4:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgrassessoriaempresarial.com.br"] [uri "/bf.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiswAAAPU"] [Tue Aug 18 13:02:39.300411 2026] [security2:error] [pid 139043:tid 139245] [client 20.151.109.219:24394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/56.php"] [unique_id "aoSCH_2v-lWn9OzQT7UitAAAAM0"] [Tue Aug 18 13:02:39.301049 2026] [security2:error] [pid 123784:tid 123925] [client 20.51.153.15:9828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kt.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUoQAAAAc"] [Tue Aug 18 13:02:39.353139 2026] [security2:error] [pid 123784:tid 123816] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/10.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUowAAGBs"] [Tue Aug 18 13:02:39.368477 2026] [security2:error] [pid 139043:tid 139279] [client 5.31.227.224:29899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCH_2v-lWn9OzQT7UitgAAAO8"] [Tue Aug 18 13:02:39.368593 2026] [security2:error] [pid 139043:tid 139279] [client 5.31.227.224:29899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCH_2v-lWn9OzQT7UitgAAAO8"] [Tue Aug 18 13:02:39.373908 2026] [security2:error] [pid 139043:tid 139211] [client 20.65.105.233:12566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp9.php"] [unique_id "aoSCH_2v-lWn9OzQT7UitwAAAKs"] [Tue Aug 18 13:02:39.421737 2026] [security2:error] [pid 123784:tid 124045] [client 34.156.195.117:46584] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCH2wDnJBNj2tDbYYUpQAAAH8"] [Tue Aug 18 13:02:39.428209 2026] [security2:error] [pid 123784:tid 123957] [client 20.250.13.23:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/r.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUpgAAACc"] [Tue Aug 18 13:02:39.451880 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:39.452148 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:39.512762 2026] [security2:error] [pid 139043:tid 139217] [client 172.182.200.96:15658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiuwAAALE"] [Tue Aug 18 13:02:39.528697 2026] [security2:error] [pid 139043:tid 139191] [client 20.65.69.59:38914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nl.php"] [unique_id "aoSCH_2v-lWn9OzQT7UivAAAAJc"] [Tue Aug 18 13:02:39.539554 2026] [security2:error] [pid 123784:tid 123864] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/te.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUqQAAKUs"] [Tue Aug 18 13:02:39.551052 2026] [security2:error] [pid 139043:tid 139050] [remote 69.72.136.99:39780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.136.72.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoSCH_2v-lWn9OzQT7UivQAAqAY"] [Tue Aug 18 13:02:39.555444 2026] [security2:error] [pid 123784:tid 123994] [client 34.156.195.117:46454] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCH2wDnJBNj2tDbYYUqgAAAEw"] [Tue Aug 18 13:02:39.576057 2026] [security2:error] [pid 123784:tid 124029] [client 158.23.17.4:9328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pk.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUrAAAAG8"] [Tue Aug 18 13:02:39.582401 2026] [security2:error] [pid 139043:tid 139215] [client 172.213.243.2:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fff.php"] [unique_id "aoSCH_2v-lWn9OzQT7UivwAAAK8"] [Tue Aug 18 13:02:39.587291 2026] [security2:error] [pid 139043:tid 139188] [client 20.151.109.219:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/rx.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiwAAAAJQ"] [Tue Aug 18 13:02:39.601830 2026] [security2:error] [pid 123784:tid 124011] [client 20.251.112.238:26170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/jq.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUrQAAAF0"] [Tue Aug 18 13:02:39.624475 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.105.233:12590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ws59.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUrgAAABw"] [Tue Aug 18 13:02:39.651621 2026] [security2:error] [pid 139043:tid 139249] [client 213.35.127.232:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiwwAAANE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:39.667147 2026] [security2:error] [pid 139043:tid 139263] [client 34.156.195.117:46576] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCH_2v-lWn9OzQT7UixAAAAN8"] [Tue Aug 18 13:02:39.687491 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:44818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/97.php"] [unique_id "aoSCH_2v-lWn9OzQT7UixgAAALM"] [Tue Aug 18 13:02:39.693833 2026] [security2:error] [pid 123784:tid 123870] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/kc.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUsQAAVlE"] [Tue Aug 18 13:02:39.724306 2026] [security2:error] [pid 139043:tid 139298] [client 172.182.217.32:21513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSCH_2v-lWn9OzQT7UivgAAAQI"] [Tue Aug 18 13:02:39.752316 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:39.752605 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:39.792639 2026] [security2:error] [pid 123784:tid 123983] [client 34.156.195.117:46568] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCH2wDnJBNj2tDbYYUtAAAAEE"] [Tue Aug 18 13:02:39.811885 2026] [security2:error] [pid 123784:tid 123930] [client 20.65.69.59:12052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/68.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUtQAAAAw"] [Tue Aug 18 13:02:39.837383 2026] [security2:error] [pid 123784:tid 123800] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/jn.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUtgAAWQs"] [Tue Aug 18 13:02:39.853676 2026] [security2:error] [pid 139043:tid 139183] [client 52.173.121.69:9499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCH_2v-lWn9OzQT7UixwAAAI8"] [Tue Aug 18 13:02:39.865053 2026] [security2:error] [pid 139043:tid 139181] [client 20.65.105.233:12453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiyAAAAI0"] [Tue Aug 18 13:02:39.866917 2026] [security2:error] [pid 139043:tid 139281] [client 40.74.65.169:44285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/media.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiyQAAAPE"] [Tue Aug 18 13:02:39.878819 2026] [security2:error] [pid 139043:tid 139291] [client 172.182.200.96:15659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCH_2v-lWn9OzQT7UiygAAAPs"] [Tue Aug 18 13:02:39.888167 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.217.32:21510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/index.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUuAAAAE4"] [Tue Aug 18 13:02:39.913860 2026] [security2:error] [pid 139043:tid 139212] [client 20.151.109.219:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mandrill.php"] [unique_id "aoSCH_2v-lWn9OzQT7UizAAAAKw"] [Tue Aug 18 13:02:39.915348 2026] [security2:error] [pid 123784:tid 123989] [client 20.118.133.132:53153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/scxy.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUugAAAEc"] [Tue Aug 18 13:02:39.937120 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.154.236:65421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCH_2v-lWn9OzQT7UizQAAAMM"] [Tue Aug 18 13:02:39.987394 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/hp.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUvAAAADg"] [Tue Aug 18 13:02:39.996195 2026] [security2:error] [pid 123784:tid 123932] [client 172.213.243.2:18740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/66.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUvQAAAA4"] [Tue Aug 18 13:02:39.999019 2026] [security2:error] [pid 123784:tid 123954] [client 68.155.154.236:8838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCH2wDnJBNj2tDbYYUvgAAACQ"] [Tue Aug 18 13:02:40.008706 2026] [security2:error] [pid 123784:tid 123825] [remote 20.51.153.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.diegorobertoimoveis.com.br"] [uri "/bf.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUvwAAASQ"] [Tue Aug 18 13:02:40.010790 2026] [security2:error] [pid 123784:tid 123982] [client 20.116.17.175:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ws77.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUwAAAAEA"] [Tue Aug 18 13:02:40.015041 2026] [security2:error] [pid 123784:tid 124035] [client 20.251.112.238:7209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sys.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUwQAAAHU"] [Tue Aug 18 13:02:40.042677 2026] [security2:error] [pid 123784:tid 123918] [client 20.250.13.23:3114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/radio.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUxAAAAAA"] [Tue Aug 18 13:02:40.042707 2026] [security2:error] [pid 123784:tid 124021] [client 20.251.48.93:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/puc.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUwwAAAGc"] [Tue Aug 18 13:02:40.046707 2026] [security2:error] [pid 123784:tid 123972] [client 20.51.153.15:9843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ww.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUxQAAADY"] [Tue Aug 18 13:02:40.058954 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:40.059462 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:40.098970 2026] [security2:error] [pid 123784:tid 123797] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUxwAAEwg"] [Tue Aug 18 13:02:40.099188 2026] [security2:error] [pid 123784:tid 123937] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUxwAAEwg"] [Tue Aug 18 13:02:40.115954 2026] [security2:error] [pid 139043:tid 139197] [client 38.246.32.104:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.32.246.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIP2v-lWn9OzQT7UizwAAAJ0"] [Tue Aug 18 13:02:40.116091 2026] [security2:error] [pid 139043:tid 139197] [client 38.246.32.104:65412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIP2v-lWn9OzQT7UizwAAAJ0"] [Tue Aug 18 13:02:40.116875 2026] [security2:error] [pid 139043:tid 139267] [client 20.65.105.233:12786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui0AAAAOM"] [Tue Aug 18 13:02:40.208212 2026] [security2:error] [pid 139043:tid 139237] [client 20.65.69.59:9682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/jl.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui0QAAAMU"] [Tue Aug 18 13:02:40.215259 2026] [security2:error] [pid 139043:tid 139193] [client 20.151.109.219:37288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/main.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui0gAAAJk"] [Tue Aug 18 13:02:40.253053 2026] [security2:error] [pid 139043:tid 139214] [client 158.23.17.4:8728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ge.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui0wAAAK4"] [Tue Aug 18 13:02:40.328850 2026] [security2:error] [pid 123784:tid 124017] [client 20.79.204.6:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCIGwDnJBNj2tDbYYUzgAAAGM"] [Tue Aug 18 13:02:40.356740 2026] [security2:error] [pid 139043:tid 139257] [client 20.65.105.233:12467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/vx.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui1AAAANk"] [Tue Aug 18 13:02:40.357356 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:40.357604 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:40.362283 2026] [security2:error] [pid 139043:tid 139227] [client 223.185.37.47:6258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui1QAAALs"] [Tue Aug 18 13:02:40.366835 2026] [security2:error] [pid 139043:tid 139227] [client 223.185.37.47:6258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui1QAAALs"] [Tue Aug 18 13:02:40.380854 2026] [security2:error] [pid 123784:tid 123995] [client 172.182.200.96:15623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU0AAAAE0"] [Tue Aug 18 13:02:40.406736 2026] [security2:error] [pid 123784:tid 123969] [client 158.23.17.4:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rh.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU0gAAADM"] [Tue Aug 18 13:02:40.409200 2026] [security2:error] [pid 139043:tid 139201] [client 172.182.217.32:21826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/pomo/user-new.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui1gAAAKE"] [Tue Aug 18 13:02:40.420113 2026] [security2:error] [pid 123784:tid 124009] [client 172.213.243.2:5648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/g.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU0wAAAFs"] [Tue Aug 18 13:02:40.457011 2026] [security2:error] [pid 123784:tid 124008] [client 20.51.153.15:9846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mo.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU1AAAAFo"] [Tue Aug 18 13:02:40.536000 2026] [security2:error] [pid 139043:tid 139234] [client 20.251.112.238:18219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/pp.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui2gAAAMI"] [Tue Aug 18 13:02:40.537911 2026] [security2:error] [pid 123784:tid 123926] [client 68.155.154.236:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU1gAAAAg"] [Tue Aug 18 13:02:40.566227 2026] [security2:error] [pid 123784:tid 124019] [client 40.74.65.169:44194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/admin.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU2gAAAGU"] [Tue Aug 18 13:02:40.596605 2026] [security2:error] [pid 123784:tid 123998] [client 20.65.105.233:12750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ah25.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU3AAAAFA"] [Tue Aug 18 13:02:40.623153 2026] [security2:error] [pid 123784:tid 124016] [client 20.151.109.219:20120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ga.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU3QAAAGI"] [Tue Aug 18 13:02:40.625165 2026] [security2:error] [pid 139043:tid 139213] [client 114.119.133.253:54931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "saojudas.com.br"] [uri "/page-sitemap.xml"] [unique_id "aoSCIP2v-lWn9OzQT7Ui2wAAAK0"], referer: https://saojudas.com.br/page-sitemap.xml [Tue Aug 18 13:02:40.635591 2026] [security2:error] [pid 139043:tid 139299] [client 20.151.109.219:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wn.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui3AAAAQM"] [Tue Aug 18 13:02:40.643391 2026] [security2:error] [pid 139043:tid 139252] [client 20.65.69.59:5404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/tq.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui3gAAANQ"] [Tue Aug 18 13:02:40.657430 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:40.657695 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:40.670995 2026] [security2:error] [pid 139043:tid 139259] [client 213.35.127.232:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui4AAAANs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:40.680116 2026] [autoindex:error] [pid 139043:tid 139246] [client 169.58.72.248:56241] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:40.683658 2026] [security2:error] [pid 139043:tid 139276] [client 168.62.48.100:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/zjggu.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui4QAAAOw"] [Tue Aug 18 13:02:40.719051 2026] [security2:error] [pid 123784:tid 123973] [client 172.182.200.96:15732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU4AAAADc"] [Tue Aug 18 13:02:40.768194 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.13.23:3135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/randkeyword.php7"] [unique_id "aoSCIGwDnJBNj2tDbYYU4wAAAAM"] [Tue Aug 18 13:02:40.775846 2026] [security2:error] [pid 123784:tid 124041] [client 34.156.195.117:46598] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCIGwDnJBNj2tDbYYU5AAAAHs"] [Tue Aug 18 13:02:40.810670 2026] [security2:error] [pid 123784:tid 123985] [client 20.51.153.15:9774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/qr.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU5QAAAEM"] [Tue Aug 18 13:02:40.835497 2026] [security2:error] [pid 123784:tid 124042] [client 38.246.32.104:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.32.246.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU6QAAAHw"] [Tue Aug 18 13:02:40.837233 2026] [security2:error] [pid 123784:tid 123953] [client 20.65.105.233:12477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/tt.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU6gAAACM"] [Tue Aug 18 13:02:40.840032 2026] [security2:error] [pid 123784:tid 124039] [client 172.213.243.2:18752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/x7.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU6wAAAHk"] [Tue Aug 18 13:02:40.840702 2026] [security2:error] [pid 123784:tid 124042] [client 38.246.32.104:49233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU6QAAAHw"] [Tue Aug 18 13:02:40.860296 2026] [security2:error] [pid 123784:tid 123971] [client 34.156.195.117:46464] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCIGwDnJBNj2tDbYYU7QAAADU"] [Tue Aug 18 13:02:40.893539 2026] [security2:error] [pid 139043:tid 139211] [client 158.23.17.4:15149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wx.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui5AAAAKs"] [Tue Aug 18 13:02:40.909322 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.217.32:21829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/sodium_compat/src/about.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui5QAAANc"] [Tue Aug 18 13:02:40.913023 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kl.php"] [unique_id "aoSCIP2v-lWn9OzQT7Ui5gAAAKA"] [Tue Aug 18 13:02:40.944674 2026] [security2:error] [pid 123784:tid 124001] [client 20.151.109.219:37256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/wb.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU7gAAAFM"] [Tue Aug 18 13:02:40.958583 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:40.958848 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:40.962009 2026] [security2:error] [pid 123784:tid 123927] [client 20.251.112.238:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wqqs.php"] [unique_id "aoSCIGwDnJBNj2tDbYYU8QAAAAk"] [Tue Aug 18 13:02:41.015329 2026] [security2:error] [pid 139043:tid 139191] [client 20.65.69.59:59222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/cv.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui7AAAAJc"] [Tue Aug 18 13:02:41.048469 2026] [security2:error] [pid 139043:tid 139185] [client 193.148.57.33:54720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "drogavilla.com.br"] [uri "/wp-content/plugins/wp_kuwvgqo/wp_kuwvgqo.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui7wAAAJE"] [Tue Aug 18 13:02:41.067731 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.200.96:15671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui8AAAAJQ"] [Tue Aug 18 13:02:41.078556 2026] [security2:error] [pid 139043:tid 139263] [client 20.65.105.233:12549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xqq.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui8gAAAN8"] [Tue Aug 18 13:02:41.141605 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.154.236:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui9AAAAME"] [Tue Aug 18 13:02:41.236476 2026] [security2:error] [pid 139043:tid 139174] [client 20.151.109.219:14092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/xn.php"] [unique_id "aoSCIf2v-lWn9OzQT7Ui9wAAAIY"] [Tue Aug 18 13:02:41.257969 2026] [security2:error] [pid 123784:tid 123989] [client 172.213.243.2:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/god.php"] [unique_id "aoSCIWwDnJBNj2tDbYYU-gAAAEc"] [Tue Aug 18 13:02:41.263430 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:41.263862 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:41.269983 2026] [security2:error] [pid 123784:tid 123991] [client 40.74.65.169:44176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/mac.php"] [unique_id "aoSCIWwDnJBNj2tDbYYU-wAAAEk"] [Tue Aug 18 13:02:41.296801 2026] [security2:error] [pid 139043:tid 139205] [client 20.51.153.15:9792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/dirs.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjBgAAAKU"] [Tue Aug 18 13:02:41.318755 2026] [security2:error] [pid 123784:tid 123919] [client 20.65.105.233:12435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/06.php"] [unique_id "aoSCIWwDnJBNj2tDbYYU_QAAAAE"] [Tue Aug 18 13:02:41.326166 2026] [security2:error] [pid 123784:tid 124035] [client 20.116.17.175:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/read.php"] [unique_id "aoSCIWwDnJBNj2tDbYYU_gAAAHU"] [Tue Aug 18 13:02:41.343474 2026] [security2:error] [pid 123784:tid 123972] [client 158.23.17.4:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/yg.php"] [unique_id "aoSCIWwDnJBNj2tDbYYU_wAAADY"] [Tue Aug 18 13:02:41.356530 2026] [security2:error] [pid 139043:tid 139258] [client 20.80.111.3:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjCQAAANo"] [Tue Aug 18 13:02:41.386517 2026] [security2:error] [pid 139043:tid 139173] [client 20.250.13.23:3112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/red.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjDAAAAIU"] [Tue Aug 18 13:02:41.391767 2026] [security2:error] [pid 123784:tid 123963] [client 20.251.112.238:45100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/clasa99.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVAAAAAC0"] [Tue Aug 18 13:02:41.400162 2026] [security2:error] [pid 139043:tid 139181] [client 172.182.217.32:21876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjDQAAAI0"] [Tue Aug 18 13:02:41.414376 2026] [security2:error] [pid 139043:tid 139289] [client 37.40.227.74:56711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjDwAAAPk"] [Tue Aug 18 13:02:41.414459 2026] [security2:error] [pid 139043:tid 139289] [client 37.40.227.74:56711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjDwAAAPk"] [Tue Aug 18 13:02:41.428548 2026] [security2:error] [pid 139043:tid 139198] [client 197.184.64.235:41971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjEQAAAJ4"] [Tue Aug 18 13:02:41.428617 2026] [security2:error] [pid 139043:tid 139198] [client 197.184.64.235:41971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjEQAAAJ4"] [Tue Aug 18 13:02:41.489641 2026] [security2:error] [pid 123784:tid 123965] [client 168.62.48.100:5460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/Cachex.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVBgAAAC8"] [Tue Aug 18 13:02:41.524576 2026] [security2:error] [pid 139043:tid 139267] [client 20.151.109.219:60378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/47.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjGgAAAOM"] [Tue Aug 18 13:02:41.535600 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:29453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gs.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjHQAAAJk"] [Tue Aug 18 13:02:41.548214 2026] [security2:error] [pid 123784:tid 124018] [client 172.182.200.96:15654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVBwAAAGQ"] [Tue Aug 18 13:02:41.556634 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.105.233:12434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/166.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjIgAAAMc"] [Tue Aug 18 13:02:41.631742 2026] [security2:error] [pid 139043:tid 139192] [client 20.51.153.15:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sn.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjKAAAAJg"] [Tue Aug 18 13:02:41.641921 2026] [security2:error] [pid 139043:tid 139227] [client 20.65.69.59:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/un.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjKQAAALs"] [Tue Aug 18 13:02:41.645177 2026] [security2:error] [pid 123784:tid 124033] [client 196.12.128.158:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVDAAAAHM"] [Tue Aug 18 13:02:41.645307 2026] [security2:error] [pid 123784:tid 124033] [client 196.12.128.158:60344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVDAAAAHM"] [Tue Aug 18 13:02:41.673471 2026] [security2:error] [pid 123784:tid 123935] [client 172.213.243.2:12143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVDgAAABE"] [Tue Aug 18 13:02:41.687699 2026] [security2:error] [pid 123784:tid 124002] [client 213.35.127.232:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVDwAAAFQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:41.790673 2026] [authz_core:error] [pid 139043:tid 139080] [remote 57.141.22.10:55812] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:41.790959 2026] [authz_core:error] [pid 139043:tid 139080] [remote 57.141.22.10:55812] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:41.795916 2026] [security2:error] [pid 139043:tid 139248] [client 20.65.105.233:12790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/snq.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjNgAAANA"] [Tue Aug 18 13:02:41.824202 2026] [security2:error] [pid 139043:tid 139269] [client 20.251.112.238:16973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/666.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjNwAAAOU"] [Tue Aug 18 13:02:41.880763 2026] [security2:error] [pid 123784:tid 124008] [client 20.51.153.15:9763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/43.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVEwAAAFo"] [Tue Aug 18 13:02:41.881530 2026] [security2:error] [pid 123784:tid 124022] [client 34.156.195.117:46496] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCIWwDnJBNj2tDbYYVEgAAAGg"] [Tue Aug 18 13:02:41.893899 2026] [security2:error] [pid 139043:tid 139213] [client 172.182.217.32:21836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjOwAAAK0"] [Tue Aug 18 13:02:41.900258 2026] [security2:error] [pid 139043:tid 139250] [client 20.151.109.219:10585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/app.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjPAAAANI"] [Tue Aug 18 13:02:41.906926 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:24390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/payout.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjPQAAAIw"] [Tue Aug 18 13:02:41.923300 2026] [security2:error] [pid 139043:tid 139275] [client 68.155.154.236:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjPgAAAOs"] [Tue Aug 18 13:02:41.938800 2026] [security2:error] [pid 123784:tid 124028] [client 20.251.48.93:37395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/inso.php"] [unique_id "aoSCIWwDnJBNj2tDbYYVFAAAAG4"] [Tue Aug 18 13:02:41.944861 2026] [security2:error] [pid 139043:tid 139274] [client 40.74.65.169:44278] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "maximusblocos.com.br"] [uri "/1.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjQQAAAOo"] [Tue Aug 18 13:02:41.944941 2026] [security2:error] [pid 139043:tid 139274] [client 40.74.65.169:44278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/1.php"] [unique_id "aoSCIf2v-lWn9OzQT7UjQQAAAOo"] [Tue Aug 18 13:02:41.948715 2026] [security2:error] [pid 123784:tid 124019] [client 34.156.195.117:46598] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCIWwDnJBNj2tDbYYVFgAAAGU"] [Tue Aug 18 13:02:42.035845 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.105.233:12457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-access.php"] [unique_id "aoSCImwDnJBNj2tDbYYVGAAAABI"] [Tue Aug 18 13:02:42.036847 2026] [security2:error] [pid 139043:tid 139200] [client 20.80.111.3:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/admin.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjRAAAAKA"] [Tue Aug 18 13:02:42.047926 2026] [security2:error] [pid 123784:tid 123929] [client 172.182.200.96:15728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCImwDnJBNj2tDbYYVGQAAAAs"] [Tue Aug 18 13:02:42.059197 2026] [security2:error] [pid 123784:tid 123993] [client 20.116.17.175:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/albin.php"] [unique_id "aoSCImwDnJBNj2tDbYYVGgAAAEs"] [Tue Aug 18 13:02:42.085550 2026] [security2:error] [pid 139043:tid 139300] [client 20.65.69.59:48497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/evil.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjRwAAAQQ"] [Tue Aug 18 13:02:42.109377 2026] [security2:error] [pid 139043:tid 139182] [client 20.79.204.6:10782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/ww5.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjSAAAAI4"] [Tue Aug 18 13:02:42.115685 2026] [security2:error] [pid 139043:tid 139217] [client 158.23.17.4:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lw.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjSQAAALE"] [Tue Aug 18 13:02:42.119159 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:42.119443 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:42.123039 2026] [security2:error] [pid 123784:tid 123997] [client 172.213.243.2:17775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/8.php"] [unique_id "aoSCImwDnJBNj2tDbYYVHQAAAE8"] [Tue Aug 18 13:02:42.125510 2026] [security2:error] [pid 123784:tid 123952] [client 20.250.13.23:30819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/release.php"] [unique_id "aoSCImwDnJBNj2tDbYYVHgAAACI"] [Tue Aug 18 13:02:42.131405 2026] [security2:error] [pid 123784:tid 124038] [client 20.51.153.15:9817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fresh.php"] [unique_id "aoSCImwDnJBNj2tDbYYVHwAAAHg"] [Tue Aug 18 13:02:42.138134 2026] [security2:error] [pid 139043:tid 139191] [client 20.206.73.37:35321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/file5.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjSgAAAJc"] [Tue Aug 18 13:02:42.190776 2026] [security2:error] [pid 139043:tid 139178] [client 20.25.139.174:2380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/inputs.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjSwAAAIo"] [Tue Aug 18 13:02:42.238474 2026] [security2:error] [pid 139043:tid 139263] [client 20.251.112.238:26160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/thui.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjTAAAAN8"] [Tue Aug 18 13:02:42.245800 2026] [security2:error] [pid 139043:tid 139249] [client 20.118.133.132:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/ws13.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjTQAAANE"] [Tue Aug 18 13:02:42.272836 2026] [security2:error] [pid 123784:tid 123986] [client 158.23.17.4:57049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/dj.php"] [unique_id "aoSCImwDnJBNj2tDbYYVIgAAAEQ"] [Tue Aug 18 13:02:42.276552 2026] [security2:error] [pid 123784:tid 123985] [client 20.65.105.233:12545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/nw.php"] [unique_id "aoSCImwDnJBNj2tDbYYVIwAAAEM"] [Tue Aug 18 13:02:42.280936 2026] [security2:error] [pid 139043:tid 139219] [client 20.151.109.219:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/bh.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjTgAAALM"] [Tue Aug 18 13:02:42.315702 2026] [security2:error] [pid 123784:tid 123987] [client 158.23.17.4:32574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/et.php"] [unique_id "aoSCImwDnJBNj2tDbYYVJQAAAEU"] [Tue Aug 18 13:02:42.328702 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:4117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjUAAAAME"] [Tue Aug 18 13:02:42.336661 2026] [security2:error] [pid 139043:tid 139294] [client 34.156.195.117:46624] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCIv2v-lWn9OzQT7UjUgAAAP4"] [Tue Aug 18 13:02:42.338058 2026] [security2:error] [pid 139043:tid 139241] [client 34.156.195.117:46618] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCIv2v-lWn9OzQT7UjUQAAAMk"] [Tue Aug 18 13:02:42.369663 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:9797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gj.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjUwAAANM"] [Tue Aug 18 13:02:42.385524 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.217.32:21841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjVAAAALY"] [Tue Aug 18 13:02:42.443172 2026] [security2:error] [pid 123784:tid 123969] [client 34.156.195.117:46604] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCImwDnJBNj2tDbYYVJwAAADM"] [Tue Aug 18 13:02:42.468751 2026] [security2:error] [pid 139043:tid 139232] [client 172.182.200.96:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjVQAAAMA"] [Tue Aug 18 13:02:42.469914 2026] [security2:error] [pid 139043:tid 139183] [client 20.65.69.59:54136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pw.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjVgAAAI8"] [Tue Aug 18 13:02:42.476730 2026] [security2:error] [pid 123784:tid 124009] [client 34.156.195.117:46644] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCImwDnJBNj2tDbYYVKAAAAFs"] [Tue Aug 18 13:02:42.483530 2026] [security2:error] [pid 123784:tid 124042] [client 20.80.111.3:12572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/api.php"] [unique_id "aoSCImwDnJBNj2tDbYYVKQAAAHw"] [Tue Aug 18 13:02:42.518953 2026] [security2:error] [pid 123784:tid 123945] [client 20.65.105.233:12556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ws62.php"] [unique_id "aoSCImwDnJBNj2tDbYYVKwAAABs"] [Tue Aug 18 13:02:42.524143 2026] [security2:error] [pid 123784:tid 123942] [client 34.156.195.117:46496] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCImwDnJBNj2tDbYYVLAAAABg"] [Tue Aug 18 13:02:42.538253 2026] [security2:error] [pid 123784:tid 124045] [client 172.213.243.2:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/koiy.php"] [unique_id "aoSCImwDnJBNj2tDbYYVLgAAAH8"] [Tue Aug 18 13:02:42.601384 2026] [security2:error] [pid 139043:tid 139261] [client 34.156.195.117:46660] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCIv2v-lWn9OzQT7UjWQAAAN0"] [Tue Aug 18 13:02:42.602092 2026] [security2:error] [pid 139043:tid 139253] [client 158.23.17.4:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vj.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjWgAAANU"] [Tue Aug 18 13:02:42.641397 2026] [security2:error] [pid 123784:tid 124020] [client 20.151.109.219:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/ct.php"] [unique_id "aoSCImwDnJBNj2tDbYYVMAAAAGY"] [Tue Aug 18 13:02:42.645328 2026] [security2:error] [pid 123784:tid 123999] [client 68.155.154.236:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCImwDnJBNj2tDbYYVMQAAAFE"] [Tue Aug 18 13:02:42.651534 2026] [security2:error] [pid 123784:tid 123946] [client 40.74.65.169:38414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/coffee.php"] [unique_id "aoSCImwDnJBNj2tDbYYVMgAAABw"] [Tue Aug 18 13:02:42.653337 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.154.236:55474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCImwDnJBNj2tDbYYVMwAAAEo"] [Tue Aug 18 13:02:42.662825 2026] [authz_core:error] [pid 139043:tid 139064] [remote 57.141.20.35:49880] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:42.663104 2026] [authz_core:error] [pid 139043:tid 139064] [remote 57.141.20.35:49880] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:42.670647 2026] [security2:error] [pid 123784:tid 123920] [client 20.116.17.175:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/fw/34.php"] [unique_id "aoSCImwDnJBNj2tDbYYVNAAAAAI"] [Tue Aug 18 13:02:42.682889 2026] [security2:error] [pid 123784:tid 123983] [client 20.251.112.238:26137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/agg.php"] [unique_id "aoSCImwDnJBNj2tDbYYVNgAAAEE"] [Tue Aug 18 13:02:42.702420 2026] [security2:error] [pid 139043:tid 139298] [client 213.35.127.232:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjXAAAAQI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:42.745202 2026] [security2:error] [pid 139043:tid 139210] [client 20.250.13.23:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/reop3.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjXgAAAKo"] [Tue Aug 18 13:02:42.748709 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pd.php"] [unique_id "aoSCImwDnJBNj2tDbYYVNwAAAHA"] [Tue Aug 18 13:02:42.763564 2026] [security2:error] [pid 123784:tid 123957] [client 20.25.139.174:2370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/admin.php"] [unique_id "aoSCImwDnJBNj2tDbYYVOQAAACc"] [Tue Aug 18 13:02:42.763713 2026] [security2:error] [pid 123784:tid 124011] [client 20.65.105.233:12744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/public/vx.php"] [unique_id "aoSCImwDnJBNj2tDbYYVOgAAAF0"] [Tue Aug 18 13:02:42.776402 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:42.776671 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:42.855892 2026] [security2:error] [pid 123784:tid 124043] [client 213.202.253.4:54401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/gdftps.php"] [unique_id "aoSCImwDnJBNj2tDbYYVPgAAAH0"], referer: www.google.com [Tue Aug 18 13:02:42.886135 2026] [security2:error] [pid 123784:tid 123927] [client 193.148.57.33:55722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "drogavilla.com.br"] [uri "/wp-content/plugins/wp_kuwvgqo/wp_kuwvgqo.php"] [unique_id "aoSCImwDnJBNj2tDbYYVPwAAAAk"] [Tue Aug 18 13:02:42.894233 2026] [security2:error] [pid 123784:tid 123930] [client 172.182.217.32:21872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/wp-widgets.php"] [unique_id "aoSCImwDnJBNj2tDbYYVQAAAAAw"] [Tue Aug 18 13:02:42.897996 2026] [security2:error] [pid 139043:tid 139063] [remote 72.167.40.62:44530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjXwAA-xM"] [Tue Aug 18 13:02:42.924137 2026] [security2:error] [pid 123784:tid 124025] [client 172.182.200.96:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCImwDnJBNj2tDbYYVQQAAAGs"] [Tue Aug 18 13:02:42.925437 2026] [security2:error] [pid 123784:tid 123974] [client 20.80.111.3:12602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/ms-files.php"] [unique_id "aoSCImwDnJBNj2tDbYYVQgAAADg"] [Tue Aug 18 13:02:42.948806 2026] [security2:error] [pid 139043:tid 139296] [client 20.151.109.219:14107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/gy.php"] [unique_id "aoSCIv2v-lWn9OzQT7UjYAAAAQA"] [Tue Aug 18 13:02:42.973759 2026] [security2:error] [pid 123784:tid 123976] [client 172.213.243.2:11380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/iko.php"] [unique_id "aoSCImwDnJBNj2tDbYYVRAAAADo"] [Tue Aug 18 13:02:42.978900 2026] [security2:error] [pid 123784:tid 123996] [client 20.79.204.6:10785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/2.php"] [unique_id "aoSCImwDnJBNj2tDbYYVRQAAAE4"] [Tue Aug 18 13:02:42.995784 2026] [security2:error] [pid 123784:tid 123956] [client 20.51.153.15:9766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/th.php"] [unique_id "aoSCImwDnJBNj2tDbYYVRwAAACY"] [Tue Aug 18 13:02:43.003160 2026] [security2:error] [pid 139043:tid 139218] [client 20.65.105.233:12546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/loxi-o.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjYQAAALI"] [Tue Aug 18 13:02:43.056911 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.69.59:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fn.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjYgAAAO8"] [Tue Aug 18 13:02:43.073065 2026] [security2:error] [pid 123784:tid 123961] [client 34.156.195.117:46604] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCI2wDnJBNj2tDbYYVSgAAACs"] [Tue Aug 18 13:02:43.080781 2026] [security2:error] [pid 139043:tid 139284] [client 20.151.109.219:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/87.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjZwAAAPQ"] [Tue Aug 18 13:02:43.102617 2026] [security2:error] [pid 123784:tid 123918] [client 20.251.112.238:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/erty.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVSwAAAAA"] [Tue Aug 18 13:02:43.187219 2026] [security2:error] [pid 123784:tid 123962] [client 158.23.17.4:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fa.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVTgAAACw"] [Tue Aug 18 13:02:43.243706 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.105.233:12770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sdsa.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjagAAAMc"] [Tue Aug 18 13:02:43.246492 2026] [security2:error] [pid 123784:tid 124017] [client 20.51.153.15:9768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/admin404.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVUQAAAGM"] [Tue Aug 18 13:02:43.252976 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.154.236:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVUgAAAAY"] [Tue Aug 18 13:02:43.255240 2026] [security2:error] [pid 123784:tid 124033] [client 172.182.200.96:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVUwAAAHM"] [Tue Aug 18 13:02:43.272384 2026] [security2:error] [pid 139043:tid 139177] [client 20.116.17.175:22991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp9.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjbAAAAIk"] [Tue Aug 18 13:02:43.283246 2026] [security2:error] [pid 123784:tid 123933] [client 132.196.30.78:25802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/system_log.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVVAAAAA8"] [Tue Aug 18 13:02:43.308409 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/tt.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjbQAAANk"] [Tue Aug 18 13:02:43.322427 2026] [security2:error] [pid 123784:tid 123935] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVVQAAESo"] [Tue Aug 18 13:02:43.329545 2026] [security2:error] [pid 139043:tid 139201] [client 158.23.17.4:47105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mimes.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjbgAAAKE"] [Tue Aug 18 13:02:43.345562 2026] [security2:error] [pid 123784:tid 123995] [client 40.74.65.169:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVVwAAAE0"] [Tue Aug 18 13:02:43.352904 2026] [security2:error] [pid 123784:tid 124000] [client 20.25.139.174:2206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/goods.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVWAAAAFI"] [Tue Aug 18 13:02:43.370848 2026] [security2:error] [pid 123784:tid 123941] [client 20.80.111.3:12566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/plugin-install.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVWQAAABc"] [Tue Aug 18 13:02:43.378415 2026] [authz_core:error] [pid 123784:tid 123830] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:43.378703 2026] [authz_core:error] [pid 123784:tid 123830] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:43.384934 2026] [security2:error] [pid 139043:tid 139256] [client 172.182.217.32:21521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-signup.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjcAAAANg"] [Tue Aug 18 13:02:43.392123 2026] [security2:error] [pid 139043:tid 139216] [client 172.213.243.2:18689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/raw.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjcQAAALA"] [Tue Aug 18 13:02:43.483929 2026] [security2:error] [pid 139043:tid 139293] [client 20.65.105.233:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-freya.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjcgAAAP0"] [Tue Aug 18 13:02:43.502076 2026] [security2:error] [pid 123784:tid 123940] [client 34.156.195.117:46666] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCI2wDnJBNj2tDbYYVXwAAABY"] [Tue Aug 18 13:02:43.502176 2026] [security2:error] [pid 123784:tid 123998] [client 158.23.17.4:44812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/of.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVYAAAAFA"] [Tue Aug 18 13:02:43.523682 2026] [security2:error] [pid 139043:tid 139227] [client 20.250.13.23:30796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/robots.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjcwAAALs"] [Tue Aug 18 13:02:43.551649 2026] [security2:error] [pid 139043:tid 139187] [client 20.251.112.238:54442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mini.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjdAAAAJM"] [Tue Aug 18 13:02:43.568448 2026] [security2:error] [pid 139043:tid 139221] [client 20.51.153.15:9729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/qo.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjdQAAALU"] [Tue Aug 18 13:02:43.573094 2026] [security2:error] [pid 139043:tid 139152] [remote 57.141.22.123:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCI_2v-lWn9OzQT7UjdwAA52w"] [Tue Aug 18 13:02:43.581740 2026] [security2:error] [pid 139043:tid 139243] [client 34.156.195.117:46612] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCI_2v-lWn9OzQT7UjeAAAAMs"] [Tue Aug 18 13:02:43.583489 2026] [autoindex:error] [pid 139043:tid 139269] [client 169.58.72.248:56241] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:43.627940 2026] [security2:error] [pid 123784:tid 123997] [client 172.182.200.96:15741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVYwAAAE8"] [Tue Aug 18 13:02:43.636235 2026] [security2:error] [pid 123784:tid 123952] [client 20.151.109.219:37249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/mq.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVZAAAACI"] [Tue Aug 18 13:02:43.658820 2026] [security2:error] [pid 123784:tid 124038] [client 20.65.69.59:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kf.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVZQAAAHg"] [Tue Aug 18 13:02:43.679364 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:43.679628 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:43.717120 2026] [security2:error] [pid 139043:tid 139244] [client 213.35.127.232:55041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjewAAAMw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:43.723496 2026] [security2:error] [pid 139043:tid 139200] [client 20.65.105.233:12417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fleen.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjfAAAAKA"] [Tue Aug 18 13:02:43.798628 2026] [security2:error] [pid 123784:tid 123943] [client 20.226.56.190:52037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/server.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVagAAABk"] [Tue Aug 18 13:02:43.808972 2026] [security2:error] [pid 123784:tid 123939] [client 20.80.111.3:43675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/wp-activate.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVawAAABU"] [Tue Aug 18 13:02:43.814964 2026] [security2:error] [pid 123784:tid 123987] [client 172.213.243.2:18738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/05.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVbAAAAEU"] [Tue Aug 18 13:02:43.816987 2026] [security2:error] [pid 139043:tid 139182] [client 68.155.154.236:64154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjfQAAAI4"] [Tue Aug 18 13:02:43.884421 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.217.32:21522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjfwAAANc"] [Tue Aug 18 13:02:43.910784 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:10762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjgAAAAOs"] [Tue Aug 18 13:02:43.911576 2026] [security2:error] [pid 139043:tid 139215] [client 20.51.153.15:9775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sd.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjgQAAAK8"] [Tue Aug 18 13:02:43.917886 2026] [security2:error] [pid 139043:tid 139226] [client 20.25.139.174:2382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/file.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjggAAALo"] [Tue Aug 18 13:02:43.926417 2026] [security2:error] [pid 123784:tid 123931] [client 86.120.159.145:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVcAAAAA0"] [Tue Aug 18 13:02:43.926529 2026] [security2:error] [pid 123784:tid 123931] [client 86.120.159.145:56840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVcAAAAA0"] [Tue Aug 18 13:02:43.945518 2026] [security2:error] [pid 139043:tid 139263] [client 20.151.109.219:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/13.php"] [unique_id "aoSCI_2v-lWn9OzQT7UjgwAAAN8"] [Tue Aug 18 13:02:43.963041 2026] [security2:error] [pid 123784:tid 123971] [client 20.65.105.233:12455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/e.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVcwAAADU"] [Tue Aug 18 13:02:43.983205 2026] [security2:error] [pid 123784:tid 123928] [client 20.251.112.238:19061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sid3.php"] [unique_id "aoSCI2wDnJBNj2tDbYYVdQAAAAo"] [Tue Aug 18 13:02:44.041194 2026] [security2:error] [pid 123784:tid 123960] [client 40.74.65.169:44279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVeAAAACo"] [Tue Aug 18 13:02:44.043908 2026] [security2:error] [pid 123784:tid 124045] [client 40.74.65.169:51609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVeQAAAH8"] [Tue Aug 18 13:02:44.061715 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/fb.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjhQAAAME"] [Tue Aug 18 13:02:44.064566 2026] [security2:error] [pid 139043:tid 139294] [client 20.65.69.59:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/su.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjhgAAAP4"] [Tue Aug 18 13:02:44.106372 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjhwAAALc"] [Tue Aug 18 13:02:44.110922 2026] [security2:error] [pid 123784:tid 123988] [client 20.151.109.219:27720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/zi.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVegAAAEY"] [Tue Aug 18 13:02:44.119668 2026] [security2:error] [pid 139043:tid 139072] [remote 57.141.22.53:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJP2v-lWn9OzQT7UjiAAAqBw"] [Tue Aug 18 13:02:44.147060 2026] [security2:error] [pid 139043:tid 139273] [client 20.116.17.175:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/save.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjigAAAOk"] [Tue Aug 18 13:02:44.160955 2026] [security2:error] [pid 123784:tid 123949] [client 20.250.13.23:4060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/root.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVfgAAAB8"] [Tue Aug 18 13:02:44.171190 2026] [security2:error] [pid 139043:tid 139254] [client 172.182.200.96:15660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjiwAAANY"] [Tue Aug 18 13:02:44.203542 2026] [security2:error] [pid 123784:tid 123946] [client 20.65.105.233:12479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/hello.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVfwAAABw"] [Tue Aug 18 13:02:44.207746 2026] [security2:error] [pid 123784:tid 123992] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVgAAAAEo"] [Tue Aug 18 13:02:44.224965 2026] [security2:error] [pid 123784:tid 124004] [client 34.156.195.117:46672] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCJGwDnJBNj2tDbYYVggAAAFY"] [Tue Aug 18 13:02:44.229162 2026] [security2:error] [pid 139043:tid 139212] [client 172.213.243.2:54856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/public/hi.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjjQAAAKw"] [Tue Aug 18 13:02:44.244143 2026] [security2:error] [pid 123784:tid 123951] [client 34.156.195.117:46640] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCJGwDnJBNj2tDbYYVgwAAACE"] [Tue Aug 18 13:02:44.247030 2026] [security2:error] [pid 123784:tid 124007] [client 158.23.17.4:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ni.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVhAAAAFk"] [Tue Aug 18 13:02:44.259572 2026] [security2:error] [pid 139043:tid 139251] [client 20.80.111.3:12575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/plugins/wp-load.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjjwAAANM"] [Tue Aug 18 13:02:44.263754 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ws61.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVhgAAAF0"] [Tue Aug 18 13:02:44.280857 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:44.281120 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:44.285460 2026] [security2:error] [pid 123784:tid 123989] [client 20.206.96.72:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/inputs.php"] [unique_id "aoSCJGwDnJBNj2tDbYYViQAAAEc"] [Tue Aug 18 13:02:44.308183 2026] [security2:error] [pid 123784:tid 124035] [client 20.151.109.219:20148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/so.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVigAAAHU"] [Tue Aug 18 13:02:44.324165 2026] [security2:error] [pid 123784:tid 123959] [client 20.206.96.72:16164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/admin.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVjAAAACk"] [Tue Aug 18 13:02:44.349201 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.96.72:16129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/goods.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVjgAAADo"] [Tue Aug 18 13:02:44.354081 2026] [security2:error] [pid 123784:tid 123996] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/rum.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVjwAAAE4"] [Tue Aug 18 13:02:44.378474 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.217.32:21875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ws.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjkwAAALg"] [Tue Aug 18 13:02:44.385071 2026] [security2:error] [pid 123784:tid 123980] [client 20.206.96.72:16187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/file.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVkAAAAD4"] [Tue Aug 18 13:02:44.397172 2026] [security2:error] [pid 139043:tid 139184] [client 20.251.112.238:8026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/moon.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjlAAAAJA"] [Tue Aug 18 13:02:44.406752 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.69.59:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wp-key.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVkgAAAH4"] [Tue Aug 18 13:02:44.419117 2026] [security2:error] [pid 123784:tid 123872] [remote 57.141.22.47:35754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJGwDnJBNj2tDbYYVkwAANlM"] [Tue Aug 18 13:02:44.425801 2026] [security2:error] [pid 139043:tid 139289] [client 34.156.195.117:46684] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCJP2v-lWn9OzQT7UjlQAAAPk"] [Tue Aug 18 13:02:44.428002 2026] [security2:error] [pid 123784:tid 123957] [client 20.25.139.174:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVlQAAACc"] [Tue Aug 18 13:02:44.443855 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.105.233:12425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/brc.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVlgAAAAY"] [Tue Aug 18 13:02:44.445709 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ze.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVlwAAAHM"] [Tue Aug 18 13:02:44.448778 2026] [security2:error] [pid 123784:tid 124032] [client 20.251.48.93:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/aa.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVmAAAAHI"] [Tue Aug 18 13:02:44.453383 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:34024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/bu.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjlwAAAOE"] [Tue Aug 18 13:02:44.490691 2026] [security2:error] [pid 139043:tid 139285] [client 20.206.96.72:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjmwAAAPU"] [Tue Aug 18 13:02:44.493599 2026] [security2:error] [pid 123784:tid 123932] [client 193.148.57.33:56446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "drogavilla.com.br"] [uri "/wp-content/plugins/wp_kuwvgqo/wp_kuwvgqo.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVmgAAAA4"] [Tue Aug 18 13:02:44.547438 2026] [security2:error] [pid 123784:tid 123941] [client 20.206.96.72:15812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/404.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVmwAAABc"] [Tue Aug 18 13:02:44.567754 2026] [security2:error] [pid 139043:tid 139242] [client 20.206.96.72:16182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wk/index.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjnQAAAMo"] [Tue Aug 18 13:02:44.579169 2026] [security2:error] [pid 139043:tid 139239] [client 168.62.48.100:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjngAAAMc"] [Tue Aug 18 13:02:44.582131 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:44.582607 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:44.591794 2026] [security2:error] [pid 139043:tid 139287] [client 20.206.96.72:16167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/about.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjnwAAAPc"] [Tue Aug 18 13:02:44.612422 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.96.72:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/term.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjoAAAAKM"] [Tue Aug 18 13:02:44.640214 2026] [security2:error] [pid 123784:tid 123998] [client 20.206.96.72:16142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVoAAAAFA"] [Tue Aug 18 13:02:44.643567 2026] [security2:error] [pid 123784:tid 123940] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/gjm.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVoQAAABY"] [Tue Aug 18 13:02:44.646809 2026] [security2:error] [pid 139043:tid 139190] [client 172.213.243.2:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/get.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjowAAAJY"] [Tue Aug 18 13:02:44.662872 2026] [security2:error] [pid 123784:tid 123929] [client 20.151.109.219:60409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/10.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVogAAAAs"] [Tue Aug 18 13:02:44.669169 2026] [security2:error] [pid 139043:tid 139256] [client 20.206.96.72:15814] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "admin.rhemahost.com.br"] [uri "/1.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjpAAAANg"] [Tue Aug 18 13:02:44.669262 2026] [security2:error] [pid 139043:tid 139256] [client 20.206.96.72:15814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/1.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjpAAAANg"] [Tue Aug 18 13:02:44.684774 2026] [security2:error] [pid 139043:tid 139192] [client 20.65.105.233:12796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/file52.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjpQAAAJg"] [Tue Aug 18 13:02:44.689593 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.154.236:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjpgAAAMI"] [Tue Aug 18 13:02:44.698414 2026] [security2:error] [pid 123784:tid 123997] [client 20.65.69.59:58597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gg.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVpQAAAE8"] [Tue Aug 18 13:02:44.700891 2026] [security2:error] [pid 139043:tid 139199] [client 20.80.111.3:39888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/themes/api.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjpwAAAJ8"] [Tue Aug 18 13:02:44.715007 2026] [security2:error] [pid 139043:tid 139267] [client 20.51.153.15:9789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/km.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjqAAAAOM"] [Tue Aug 18 13:02:44.715145 2026] [security2:error] [pid 123784:tid 123983] [client 34.156.195.117:46788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.bak"] [unique_id "aoSCJGwDnJBNj2tDbYYVpwAAAEE"] [Tue Aug 18 13:02:44.718494 2026] [security2:error] [pid 139043:tid 139280] [client 172.182.200.96:15722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjqQAAAPA"] [Tue Aug 18 13:02:44.736048 2026] [security2:error] [pid 139043:tid 139195] [client 213.35.127.232:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjqgAAAJs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:44.748967 2026] [security2:error] [pid 139043:tid 139247] [client 40.74.65.169:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/yj09.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjqwAAAM8"] [Tue Aug 18 13:02:44.749439 2026] [security2:error] [pid 123784:tid 124038] [client 40.74.65.169:51705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVqAAAAHg"] [Tue Aug 18 13:02:44.761886 2026] [security2:error] [pid 123784:tid 123973] [client 20.118.133.132:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/btx25.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVqQAAADc"] [Tue Aug 18 13:02:44.777111 2026] [security2:error] [pid 123784:tid 123958] [client 20.206.96.72:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/alfa.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVqwAAACg"] [Tue Aug 18 13:02:44.806865 2026] [security2:error] [pid 123784:tid 124016] [client 20.206.96.72:15816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/edit.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVrAAAAGI"] [Tue Aug 18 13:02:44.831084 2026] [security2:error] [pid 123784:tid 123943] [client 20.206.96.72:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/elp.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVrgAAABk"] [Tue Aug 18 13:02:44.838877 2026] [security2:error] [pid 139043:tid 139257] [client 20.79.204.6:10697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/atomlib.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjrgAAANk"] [Tue Aug 18 13:02:44.852208 2026] [security2:error] [pid 123784:tid 123939] [client 20.206.96.72:15813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVrwAAABU"] [Tue Aug 18 13:02:44.859390 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.13.23:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/rrr.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjrwAAAIc"] [Tue Aug 18 13:02:44.871837 2026] [security2:error] [pid 123784:tid 124014] [client 20.206.96.72:15818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/666.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVsAAAAGA"] [Tue Aug 18 13:02:44.872912 2026] [security2:error] [pid 139043:tid 139293] [client 172.182.217.32:21850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wso.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjsAAAAP0"] [Tue Aug 18 13:02:44.875082 2026] [security2:error] [pid 139043:tid 139250] [client 20.251.112.238:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ms.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjsQAAANI"] [Tue Aug 18 13:02:44.875755 2026] [security2:error] [pid 123784:tid 124039] [client 132.196.30.78:24597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/x.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVsgAAAHk"] [Tue Aug 18 13:02:44.880712 2026] [security2:error] [pid 139043:tid 139180] [client 20.116.17.175:22965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjsgAAAIw"] [Tue Aug 18 13:02:44.882776 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:44.883041 2026] [authz_core:error] [pid 123784:tid 123892] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:44.903452 2026] [security2:error] [pid 139043:tid 139204] [client 4.223.113.180:41347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/f5.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjtAAAAKQ"] [Tue Aug 18 13:02:44.912128 2026] [security2:error] [pid 139043:tid 139225] [client 20.206.96.72:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ws54.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjtQAAALk"] [Tue Aug 18 13:02:44.925481 2026] [security2:error] [pid 139043:tid 139197] [client 20.65.105.233:12551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjtgAAAJ0"] [Tue Aug 18 13:02:44.961368 2026] [security2:error] [pid 139043:tid 139260] [client 20.151.109.219:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/te.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjtwAAANw"] [Tue Aug 18 13:02:44.975374 2026] [security2:error] [pid 123784:tid 123948] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/new4.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVtAAAAB4"] [Tue Aug 18 13:02:44.988763 2026] [security2:error] [pid 139043:tid 139246] [client 20.25.139.174:2423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/404.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjuAAAAM4"] [Tue Aug 18 13:02:44.994149 2026] [security2:error] [pid 139043:tid 139300] [client 20.206.96.72:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjuQAAAQQ"] [Tue Aug 18 13:02:44.995172 2026] [security2:error] [pid 139043:tid 139286] [client 20.51.153.15:9795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mf.php"] [unique_id "aoSCJP2v-lWn9OzQT7UjugAAAPY"] [Tue Aug 18 13:02:45.030054 2026] [security2:error] [pid 139043:tid 139185] [client 20.206.96.72:16184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/function/function.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjuwAAAJE"] [Tue Aug 18 13:02:45.062825 2026] [security2:error] [pid 139043:tid 139215] [client 172.213.243.2:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/rpk.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjvAAAAK8"] [Tue Aug 18 13:02:45.065425 2026] [security2:error] [pid 139043:tid 139275] [client 20.206.96.72:15826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/nw.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjvQAAAOs"] [Tue Aug 18 13:02:45.088510 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-act.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVtwAAAAc"] [Tue Aug 18 13:02:45.093417 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.96.72:15457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/xleet.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjvwAAALw"] [Tue Aug 18 13:02:45.104635 2026] [security2:error] [pid 139043:tid 139194] [client 20.65.69.59:5409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gi.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjwAAAAJo"] [Tue Aug 18 13:02:45.124011 2026] [security2:error] [pid 139043:tid 139233] [client 20.206.96.72:16176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjwQAAAME"] [Tue Aug 18 13:02:45.145543 2026] [security2:error] [pid 123784:tid 123988] [client 68.155.154.236:41477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVuQAAAEY"] [Tue Aug 18 13:02:45.150957 2026] [security2:error] [pid 139043:tid 139217] [client 20.80.111.3:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/themes/db-status.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjwgAAALE"] [Tue Aug 18 13:02:45.165009 2026] [security2:error] [pid 123784:tid 123919] [client 34.156.195.117:46814] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.backup"] [unique_id "aoSCJWwDnJBNj2tDbYYVugAAAAE"] [Tue Aug 18 13:02:45.178350 2026] [security2:error] [pid 139043:tid 139273] [client 20.65.105.233:12738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/path.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjwwAAAOk"] [Tue Aug 18 13:02:45.188469 2026] [security2:error] [pid 123784:tid 123982] [client 34.156.195.117:46790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.old"] [unique_id "aoSCJWwDnJBNj2tDbYYVvAAAAEA"] [Tue Aug 18 13:02:45.190096 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:45.190545 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:45.190733 2026] [security2:error] [pid 123784:tid 123954] [client 34.156.195.117:46800] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.save"] [unique_id "aoSCJWwDnJBNj2tDbYYVvQAAACQ"] [Tue Aug 18 13:02:45.194394 2026] [security2:error] [pid 123784:tid 123963] [client 34.156.195.117:46824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.swp"] [unique_id "aoSCJWwDnJBNj2tDbYYVvgAAAC0"] [Tue Aug 18 13:02:45.218751 2026] [security2:error] [pid 139043:tid 139177] [client 20.151.109.219:45849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/92.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjxQAAAIk"] [Tue Aug 18 13:02:45.228237 2026] [security2:error] [pid 139043:tid 139287] [client 20.206.96.72:15485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/155.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjxgAAAPc"] [Tue Aug 18 13:02:45.239419 2026] [security2:error] [pid 139043:tid 139248] [client 20.100.169.31:29099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/inputs.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjxwAAANA"] [Tue Aug 18 13:02:45.255252 2026] [security2:error] [pid 139043:tid 139203] [client 20.51.153.15:9776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ie.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjyAAAAKM"] [Tue Aug 18 13:02:45.270479 2026] [security2:error] [pid 139043:tid 139230] [client 34.156.195.117:46618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/api/.env"] [unique_id "aoSCJf2v-lWn9OzQT7UjygAAAL4"] [Tue Aug 18 13:02:45.274135 2026] [security2:error] [pid 123784:tid 124015] [client 20.206.96.72:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/96i.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVwgAAAGE"] [Tue Aug 18 13:02:45.279086 2026] [security2:error] [pid 123784:tid 123843] [remote 57.141.22.55:37924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJWwDnJBNj2tDbYYVwwAARzY"] [Tue Aug 18 13:02:45.299536 2026] [security2:error] [pid 139043:tid 139256] [client 172.182.200.96:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjywAAANg"] [Tue Aug 18 13:02:45.301635 2026] [security2:error] [pid 139043:tid 139234] [client 158.23.17.4:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gw.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjzAAAAMI"] [Tue Aug 18 13:02:45.309070 2026] [security2:error] [pid 139043:tid 139216] [client 20.206.96.72:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/as.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjzQAAALA"] [Tue Aug 18 13:02:45.334912 2026] [security2:error] [pid 123784:tid 123959] [client 20.206.96.72:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/min.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVxQAAACk"] [Tue Aug 18 13:02:45.339668 2026] [security2:error] [pid 139043:tid 139267] [client 20.151.109.219:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/kc.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjzgAAAOM"] [Tue Aug 18 13:02:45.351995 2026] [security2:error] [pid 123784:tid 123956] [client 20.251.112.238:26175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wsws.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVxgAAACY"] [Tue Aug 18 13:02:45.354367 2026] [security2:error] [pid 123784:tid 124023] [client 34.156.195.117:46838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/server/.env"] [unique_id "aoSCJWwDnJBNj2tDbYYVxwAAAGk"] [Tue Aug 18 13:02:45.362901 2026] [security2:error] [pid 123784:tid 123996] [client 34.156.195.117:46700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/backend/.env"] [unique_id "aoSCJWwDnJBNj2tDbYYVyAAAAE4"] [Tue Aug 18 13:02:45.369022 2026] [security2:error] [pid 139043:tid 139242] [client 172.182.217.32:21877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/meta.php"] [unique_id "aoSCJf2v-lWn9OzQT7UjzwAAAMo"] [Tue Aug 18 13:02:45.392602 2026] [security2:error] [pid 123784:tid 124018] [client 158.23.17.4:34036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rn.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVygAAAGQ"] [Tue Aug 18 13:02:45.419091 2026] [security2:error] [pid 123784:tid 123918] [client 20.65.105.233:12423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wpo.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVzAAAAAA"] [Tue Aug 18 13:02:45.436992 2026] [security2:error] [pid 123784:tid 124044] [client 20.206.96.72:15828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/php8.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVzQAAAH4"] [Tue Aug 18 13:02:45.443819 2026] [security2:error] [pid 123784:tid 124021] [client 40.74.65.169:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/media.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVzgAAAGc"] [Tue Aug 18 13:02:45.444192 2026] [security2:error] [pid 123784:tid 123957] [client 40.74.65.169:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/scxy.php"] [unique_id "aoSCJWwDnJBNj2tDbYYVzwAAACc"] [Tue Aug 18 13:02:45.457173 2026] [security2:error] [pid 123784:tid 123962] [client 34.156.195.117:46750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/config/.env"] [unique_id "aoSCJWwDnJBNj2tDbYYV0AAAACw"] [Tue Aug 18 13:02:45.457579 2026] [security2:error] [pid 139043:tid 139299] [client 34.156.195.117:46734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/src/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj0AAAAQM"] [Tue Aug 18 13:02:45.465173 2026] [security2:error] [pid 123784:tid 124017] [client 20.116.17.175:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV0QAAAGM"] [Tue Aug 18 13:02:45.482921 2026] [security2:error] [pid 123784:tid 124033] [client 34.156.195.117:46772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/apps/api/.env"] [unique_id "aoSCJWwDnJBNj2tDbYYV0gAAAHM"] [Tue Aug 18 13:02:45.486487 2026] [security2:error] [pid 139043:tid 139271] [client 158.23.17.4:8715] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ariatec.com.br"] [uri "/1.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj0gAAAOc"] [Tue Aug 18 13:02:45.486599 2026] [security2:error] [pid 139043:tid 139271] [client 158.23.17.4:8715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/1.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj0gAAAOc"] [Tue Aug 18 13:02:45.492278 2026] [security2:error] [pid 123784:tid 124032] [client 20.51.153.15:9799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nw.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV1gAAAHI"] [Tue Aug 18 13:02:45.492967 2026] [security2:error] [pid 123784:tid 123933] [client 34.156.195.117:46790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/web/.env"] [unique_id "aoSCJWwDnJBNj2tDbYYV1QAAAA8"] [Tue Aug 18 13:02:45.494058 2026] [security2:error] [pid 139043:tid 139189] [client 34.156.195.117:38118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.aws/credentials.old"] [unique_id "aoSCJf2v-lWn9OzQT7Uj0wAAAJU"] [Tue Aug 18 13:02:45.497661 2026] [security2:error] [pid 123784:tid 123932] [client 172.213.243.2:17730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV1wAAAA4"] [Tue Aug 18 13:02:45.501693 2026] [security2:error] [pid 139043:tid 139201] [client 20.250.13.23:3448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/s.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj1QAAAKE"] [Tue Aug 18 13:02:45.511770 2026] [security2:error] [pid 139043:tid 139282] [client 34.156.195.117:38146] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/backend/.aws/credentials"] [unique_id "aoSCJf2v-lWn9OzQT7Uj1gAAAPI"] [Tue Aug 18 13:02:45.525702 2026] [security2:error] [pid 123784:tid 123926] [client 20.65.69.59:48470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pz.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV2wAAAAg"] [Tue Aug 18 13:02:45.537137 2026] [security2:error] [pid 123784:tid 123941] [client 20.206.96.72:16037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV3QAAABc"] [Tue Aug 18 13:02:45.538548 2026] [security2:error] [pid 123784:tid 124040] [client 20.25.139.174:2397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wk/index.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV3wAAAHo"] [Tue Aug 18 13:02:45.538562 2026] [security2:error] [pid 123784:tid 123864] [remote 57.141.22.104:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJWwDnJBNj2tDbYYV3gAAQks"] [Tue Aug 18 13:02:45.574504 2026] [security2:error] [pid 123784:tid 124029] [client 20.206.96.72:16183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/222.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV4QAAAG8"] [Tue Aug 18 13:02:45.585798 2026] [security2:error] [pid 123784:tid 123972] [client 20.80.111.3:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/themes/module.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV4gAAADY"] [Tue Aug 18 13:02:45.597564 2026] [security2:error] [pid 123784:tid 123940] [client 68.155.154.236:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV5AAAABY"] [Tue Aug 18 13:02:45.632356 2026] [security2:error] [pid 123784:tid 123920] [client 52.173.121.69:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV5QAAAAI"] [Tue Aug 18 13:02:45.650284 2026] [security2:error] [pid 123784:tid 123936] [client 20.206.96.72:16161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV5gAAABI"] [Tue Aug 18 13:02:45.660052 2026] [security2:error] [pid 123784:tid 123921] [client 20.65.105.233:12474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/a1vx.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV5wAAAAM"] [Tue Aug 18 13:02:45.684633 2026] [security2:error] [pid 123784:tid 123994] [client 5.161.117.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlyclimatizacao.com.br"] [uri "/index.php"] [unique_id "aoSCJGwDnJBNj2tDbYYVfAAATC8"], referer: https://jlyclimatizacao.com.br/ [Tue Aug 18 13:02:45.692595 2026] [security2:error] [pid 123784:tid 123986] [client 20.151.109.219:60415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/jn.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV6gAAAEQ"] [Tue Aug 18 13:02:45.708733 2026] [security2:error] [pid 123784:tid 123931] [client 20.251.48.93:53077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/img.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV6wAAAA0"] [Tue Aug 18 13:02:45.739912 2026] [security2:error] [pid 123784:tid 123925] [client 172.182.200.96:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/rezor.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV7AAAAAc"] [Tue Aug 18 13:02:45.743040 2026] [security2:error] [pid 123784:tid 124042] [client 20.206.96.72:16165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/info.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV7QAAAHw"] [Tue Aug 18 13:02:45.753232 2026] [security2:error] [pid 139043:tid 139252] [client 213.35.127.232:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj1wAAANQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:45.766778 2026] [security2:error] [pid 123784:tid 124031] [client 20.206.96.72:16172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/a.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV7wAAAHE"] [Tue Aug 18 13:02:45.782974 2026] [security2:error] [pid 139043:tid 139257] [client 4.223.113.180:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/al.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj2QAAANk"] [Tue Aug 18 13:02:45.788923 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:45.789196 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:45.791214 2026] [security2:error] [pid 123784:tid 123919] [client 20.206.96.72:15289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/chosen.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV8wAAAAE"] [Tue Aug 18 13:02:45.796390 2026] [security2:error] [pid 123784:tid 123995] [client 20.251.112.238:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/motu.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV9AAAAE0"] [Tue Aug 18 13:02:45.817113 2026] [core:error] [pid 139043:tid 139208] [client 34.156.195.117:38170] AH10244: invalid URI path (/assets../../../.env) [Tue Aug 18 13:02:45.818735 2026] [security2:error] [pid 123784:tid 124020] [client 20.206.96.72:16171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCJWwDnJBNj2tDbYYV9QAAAGY"] [Tue Aug 18 13:02:45.834487 2026] [security2:error] [pid 123784:tid 123989] [client 34.156.195.117:46838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/files../.env"] [unique_id "aoSCJWwDnJBNj2tDbYYV9gAAAEc"] [Tue Aug 18 13:02:45.835101 2026] [security2:error] [pid 139043:tid 139241] [client 34.156.195.117:38512] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/core/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj2wAAAMk"] [Tue Aug 18 13:02:45.836122 2026] [security2:error] [pid 123784:tid 123946] [client 34.156.195.117:38184] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/home/ec2-user/.aws/credentials"] [unique_id "aoSCJWwDnJBNj2tDbYYV-AAAABw"] [Tue Aug 18 13:02:45.836402 2026] [security2:error] [pid 139043:tid 139176] [client 34.156.195.117:38404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/public/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj3AAAAIg"] [Tue Aug 18 13:02:45.836716 2026] [security2:error] [pid 139043:tid 139232] [client 34.156.195.117:38526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj3QAAAMA"] [Tue Aug 18 13:02:45.848102 2026] [security2:error] [pid 123784:tid 123951] [client 34.156.195.117:38380] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/home/ubuntu/.aws/credentials"] [unique_id "aoSCJWwDnJBNj2tDbYYV_AAAACE"] [Tue Aug 18 13:02:45.848274 2026] [security2:error] [pid 139043:tid 139253] [client 34.156.195.117:38486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj4wAAANU"] [Tue Aug 18 13:02:45.848364 2026] [security2:error] [pid 123784:tid 124004] [client 34.156.195.117:38342] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCJWwDnJBNj2tDbYYV_QAAAFY"] [Tue Aug 18 13:02:45.848575 2026] [security2:error] [pid 139043:tid 139173] [client 34.156.195.117:38212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/_next/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj4AAAAIU"] [Tue Aug 18 13:02:45.848856 2026] [security2:error] [pid 139043:tid 139179] [client 34.156.195.117:38410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/app/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj4QAAAIs"] [Tue Aug 18 13:02:45.849136 2026] [security2:error] [pid 139043:tid 139219] [client 34.156.195.117:38480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj5QAAALM"] [Tue Aug 18 13:02:45.849455 2026] [security2:error] [pid 123784:tid 123992] [client 34.156.195.117:38444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.aws/credentials.bak"] [unique_id "aoSCJWwDnJBNj2tDbYYV_gAAAEo"] [Tue Aug 18 13:02:45.852772 2026] [security2:error] [pid 139043:tid 139205] [client 34.156.195.117:38200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.vercel/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj5wAAAKU"] [Tue Aug 18 13:02:45.857509 2026] [security2:error] [pid 123784:tid 123959] [client 132.196.30.78:20895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWAAAAACk"] [Tue Aug 18 13:02:45.857565 2026] [security2:error] [pid 139043:tid 139237] [client 34.156.195.117:38534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/back/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj6gAAAMU"] [Tue Aug 18 13:02:45.858676 2026] [security2:error] [pid 139043:tid 139238] [client 34.156.195.117:38364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.github/.env"] [unique_id "aoSCJf2v-lWn9OzQT7Uj6QAAAMY"] [Tue Aug 18 13:02:45.866718 2026] [security2:error] [pid 123784:tid 124039] [client 172.182.217.32:21519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/hehe.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWAgAAAHk"] [Tue Aug 18 13:02:45.868770 2026] [security2:error] [pid 139043:tid 139220] [client 34.156.195.117:38272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/webhook"] [unique_id "aoSCJf2v-lWn9OzQT7Uj7gAAALQ"] [Tue Aug 18 13:02:45.870324 2026] [security2:error] [pid 139043:tid 139197] [client 20.116.17.175:22987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/df.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj8QAAAJ0"] [Tue Aug 18 13:02:45.870947 2026] [security2:error] [pid 139043:tid 139235] [client 34.156.195.117:38424] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/image"] [unique_id "aoSCJf2v-lWn9OzQT7Uj8gAAAMM"] [Tue Aug 18 13:02:45.871364 2026] [security2:error] [pid 139043:tid 139212] [client 34.156.195.117:38430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSCJf2v-lWn9OzQT7Uj9AAAAKw"] [Tue Aug 18 13:02:45.877953 2026] [security2:error] [pid 123784:tid 124024] [client 20.79.204.6:10583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/rip.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWAwAAAGo"] [Tue Aug 18 13:02:45.899829 2026] [security2:error] [pid 139043:tid 139246] [client 20.65.105.233:12478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ty.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj9QAAAM4"] [Tue Aug 18 13:02:45.907047 2026] [security2:error] [pid 123784:tid 124005] [client 172.213.243.2:49447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/mga.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWBAAAAFc"] [Tue Aug 18 13:02:45.925237 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.154.236:40223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWBQAAACY"] [Tue Aug 18 13:02:45.925716 2026] [security2:error] [pid 139043:tid 139286] [client 20.206.96.72:16001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/vx.php"] [unique_id "aoSCJf2v-lWn9OzQT7Uj9gAAAPY"] [Tue Aug 18 13:02:45.946479 2026] [security2:error] [pid 123784:tid 123841] [remote 57.141.22.28:47304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJWwDnJBNj2tDbYYWBgAAWzQ"] [Tue Aug 18 13:02:45.975532 2026] [security2:error] [pid 123784:tid 123980] [client 20.151.109.219:60903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "varandasgp.com.br"] [uri "/bf.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWCQAAAD4"] [Tue Aug 18 13:02:45.995214 2026] [security2:error] [pid 123784:tid 124012] [client 20.65.69.59:9670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kk.php"] [unique_id "aoSCJWwDnJBNj2tDbYYWCwAAAF4"] [Tue Aug 18 13:02:46.002233 2026] [security2:error] [pid 139043:tid 139191] [client 20.206.96.72:16140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wap.php"] [unique_id "aoSCJv2v-lWn9OzQT7Uj-AAAAJc"] [Tue Aug 18 13:02:46.030778 2026] [security2:error] [pid 139043:tid 139178] [client 20.206.96.72:16029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSCJv2v-lWn9OzQT7Uj-QAAAIo"] [Tue Aug 18 13:02:46.032968 2026] [security2:error] [pid 123784:tid 123974] [client 20.25.139.174:2412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/about.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWDAAAADg"] [Tue Aug 18 13:02:46.034306 2026] [security2:error] [pid 139043:tid 139260] [client 20.80.111.3:30028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/languages/themes/wp-activate.php"] [unique_id "aoSCJv2v-lWn9OzQT7Uj-gAAANw"] [Tue Aug 18 13:02:46.077964 2026] [security2:error] [pid 123784:tid 124021] [client 20.51.153.15:9851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sb.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWDgAAAGc"] [Tue Aug 18 13:02:46.089336 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:46.089589 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:46.100890 2026] [security2:error] [pid 123784:tid 123957] [client 158.23.17.4:8733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/88.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWEAAAACc"] [Tue Aug 18 13:02:46.119581 2026] [security2:error] [pid 123784:tid 124017] [client 40.74.65.169:44165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWEQAAAGM"] [Tue Aug 18 13:02:46.134427 2026] [security2:error] [pid 139043:tid 139294] [client 40.74.65.169:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/admin.php"] [unique_id "aoSCJv2v-lWn9OzQT7Uj_wAAAP4"] [Tue Aug 18 13:02:46.134888 2026] [security2:error] [pid 123784:tid 124028] [client 193.148.57.33:57079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "drogavilla.com.br"] [uri "/wp-content/plugins/wp_kuwvgqo/wp_kuwvgqo.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWEgAAAG4"] [Tue Aug 18 13:02:46.140996 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.105.233:12458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/vgtyu.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWFAAAAHI"] [Tue Aug 18 13:02:46.142320 2026] [security2:error] [pid 139043:tid 139207] [client 20.206.96.72:16170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/bgymj.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkAAAAAKc"] [Tue Aug 18 13:02:46.147101 2026] [security2:error] [pid 139043:tid 139233] [client 34.156.195.117:46734] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/runtime-config.js"] [unique_id "aoSCJv2v-lWn9OzQT7UkAQAAAME"] [Tue Aug 18 13:02:46.193360 2026] [security2:error] [pid 123784:tid 123977] [client 20.206.96.72:16189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/aa.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWFgAAADs"] [Tue Aug 18 13:02:46.216850 2026] [security2:error] [pid 123784:tid 124026] [client 20.116.17.175:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWGAAAAGw"] [Tue Aug 18 13:02:46.225668 2026] [security2:error] [pid 139043:tid 139193] [client 20.250.13.23:30804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/s93.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkAgAAAJk"] [Tue Aug 18 13:02:46.230243 2026] [security2:error] [pid 123784:tid 124006] [client 20.206.96.72:15827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWGQAAAFg"] [Tue Aug 18 13:02:46.271760 2026] [security2:error] [pid 139043:tid 139227] [client 20.251.112.238:39911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fff.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkDQAAALs"] [Tue Aug 18 13:02:46.273416 2026] [security2:error] [pid 123784:tid 123929] [client 34.156.195.117:38354] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/google-services.json"] [unique_id "aoSCJmwDnJBNj2tDbYYWHwAAAAs"] [Tue Aug 18 13:02:46.286140 2026] [security2:error] [pid 123784:tid 123993] [client 34.156.195.117:38130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/download"] [unique_id "aoSCJmwDnJBNj2tDbYYWIAAAAEs"] [Tue Aug 18 13:02:46.306159 2026] [security2:error] [pid 139043:tid 139259] [client 172.182.200.96:15703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/uploads/bypass.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkEQAAANs"] [Tue Aug 18 13:02:46.315330 2026] [security2:error] [pid 139043:tid 139271] [client 20.51.153.15:9751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xj.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkEgAAAOc"] [Tue Aug 18 13:02:46.316574 2026] [security2:error] [pid 123784:tid 123958] [client 172.213.243.2:25091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/fs.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWIwAAACg"] [Tue Aug 18 13:02:46.319980 2026] [security2:error] [pid 139043:tid 139189] [client 34.156.195.117:46720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/api/image"] [unique_id "aoSCJv2v-lWn9OzQT7UkEwAAAJU"] [Tue Aug 18 13:02:46.321135 2026] [security2:error] [pid 139043:tid 139256] [client 20.206.96.72:15462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/bolt.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkFAAAANg"] [Tue Aug 18 13:02:46.321614 2026] [security2:error] [pid 139043:tid 139300] [client 20.100.169.31:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/admin.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkFQAAAQQ"] [Tue Aug 18 13:02:46.334643 2026] [security2:error] [pid 123784:tid 123955] [client 34.156.195.117:46788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCJmwDnJBNj2tDbYYWJgAAACU"] [Tue Aug 18 13:02:46.340502 2026] [security2:error] [pid 139043:tid 139078] [remote 57.141.22.7:59294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/2025/08/17/depuis-l-avenement-des-plateformes-numeriques-l-industrie-du-jeu-en-ligne-a-connu-une-croissance-ex/feed/"] [unique_id "aoSCJv2v-lWn9OzQT7UkFgAAiSI"] [Tue Aug 18 13:02:46.358151 2026] [security2:error] [pid 123784:tid 124019] [client 172.182.217.32:21776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/yindu.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWJwAAAGU"] [Tue Aug 18 13:02:46.373991 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/grsiuk.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkGAAAAOU"] [Tue Aug 18 13:02:46.381179 2026] [security2:error] [pid 139043:tid 139268] [client 20.65.105.233:12605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/mans.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkGQAAAOQ"] [Tue Aug 18 13:02:46.414813 2026] [security2:error] [pid 139043:tid 139293] [client 20.206.96.72:16156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/bthil.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkHQAAAP0"] [Tue Aug 18 13:02:46.415539 2026] [security2:error] [pid 139043:tid 139274] [client 34.156.195.117:38118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/read?url=file:///proc/1/environ"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/read"] [unique_id "aoSCJv2v-lWn9OzQT7UkHAAAAOo"] [Tue Aug 18 13:02:46.453716 2026] [security2:error] [pid 123784:tid 124014] [client 34.156.195.117:46750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/download"] [unique_id "aoSCJmwDnJBNj2tDbYYWLgAAAGA"] [Tue Aug 18 13:02:46.457082 2026] [security2:error] [pid 123784:tid 123931] [client 20.65.69.59:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWLwAAAA0"] [Tue Aug 18 13:02:46.462751 2026] [security2:error] [pid 123784:tid 123969] [client 20.206.96.72:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/x.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWMAAAADM"] [Tue Aug 18 13:02:46.474736 2026] [security2:error] [pid 123784:tid 123921] [client 20.80.111.3:30042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWMQAAAAM"] [Tue Aug 18 13:02:46.480594 2026] [security2:error] [pid 139043:tid 139209] [client 34.156.195.117:38568] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCJv2v-lWn9OzQT7UkHgAAAKk"] [Tue Aug 18 13:02:46.531849 2026] [security2:error] [pid 123784:tid 123935] [client 34.156.195.117:38572] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/api/file"] [unique_id "aoSCJmwDnJBNj2tDbYYWNAAAABE"] [Tue Aug 18 13:02:46.532192 2026] [security2:error] [pid 123784:tid 124000] [client 34.156.195.117:38608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/"] [unique_id "aoSCJmwDnJBNj2tDbYYWMwAAAFI"] [Tue Aug 18 13:02:46.541211 2026] [security2:error] [pid 139043:tid 139262] [client 20.25.139.174:2237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/term.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkHwAAAN4"] [Tue Aug 18 13:02:46.586913 2026] [security2:error] [pid 123784:tid 123979] [client 132.196.30.78:8076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/hosty.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWNQAAAD0"] [Tue Aug 18 13:02:46.588037 2026] [security2:error] [pid 123784:tid 124031] [client 68.155.154.236:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWNgAAAHE"] [Tue Aug 18 13:02:46.598906 2026] [security2:error] [pid 123784:tid 123965] [client 20.206.96.72:15458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/index/function.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWOAAAAC8"] [Tue Aug 18 13:02:46.599317 2026] [security2:error] [pid 139043:tid 139251] [client 158.23.17.4:63623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/hj.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkIQAAANM"] [Tue Aug 18 13:02:46.624475 2026] [security2:error] [pid 123784:tid 123982] [client 20.65.105.233:12475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/co.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWOQAAAEA"] [Tue Aug 18 13:02:46.638277 2026] [security2:error] [pid 139043:tid 139211] [client 20.206.96.72:15821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/aaa.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkIgAAAKs"] [Tue Aug 18 13:02:46.639818 2026] [security2:error] [pid 139043:tid 139244] [client 158.23.17.4:34015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ut.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkIwAAAMw"] [Tue Aug 18 13:02:46.668718 2026] [security2:error] [pid 139043:tid 139220] [client 20.206.96.72:16138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/abcd.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkJAAAALQ"] [Tue Aug 18 13:02:46.675880 2026] [security2:error] [pid 139043:tid 139235] [client 20.51.153.15:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ns.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkJQAAAMM"] [Tue Aug 18 13:02:46.688762 2026] [security2:error] [pid 139043:tid 139283] [client 20.251.112.238:7853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/66.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkJgAAAPM"] [Tue Aug 18 13:02:46.690963 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:46.691251 2026] [authz_core:error] [pid 123784:tid 123873] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:46.708283 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.200.96:15666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkKAAAAMg"] [Tue Aug 18 13:02:46.729388 2026] [security2:error] [pid 139043:tid 139255] [client 172.213.243.2:18708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/wp-tem.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkKQAAANc"] [Tue Aug 18 13:02:46.767251 2026] [security2:error] [pid 139043:tid 139260] [client 34.156.195.117:38384] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCJv2v-lWn9OzQT7UkKgAAANw"] [Tue Aug 18 13:02:46.769163 2026] [security2:error] [pid 123784:tid 123943] [client 213.35.127.232:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWPwAAABk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:46.769765 2026] [security2:error] [pid 139043:tid 139284] [client 20.206.96.72:15822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-good.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkKwAAAPQ"] [Tue Aug 18 13:02:46.769935 2026] [security2:error] [pid 139043:tid 139200] [client 20.116.17.175:23003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/usr.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkLAAAAKA"] [Tue Aug 18 13:02:46.795375 2026] [security2:error] [pid 139043:tid 139275] [client 40.74.65.169:44177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkLQAAAOs"] [Tue Aug 18 13:02:46.816616 2026] [security2:error] [pid 139043:tid 139290] [client 20.65.69.59:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/dg.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkLgAAAPo"] [Tue Aug 18 13:02:46.830197 2026] [security2:error] [pid 139043:tid 139223] [client 40.74.65.169:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/mac.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkLwAAALc"] [Tue Aug 18 13:02:46.837377 2026] [security2:error] [pid 139043:tid 139207] [client 20.206.96.72:16162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/simple.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkMAAAAKc"] [Tue Aug 18 13:02:46.837975 2026] [security2:error] [pid 123784:tid 123939] [client 4.223.113.180:17909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/inc.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWQQAAABU"] [Tue Aug 18 13:02:46.847712 2026] [security2:error] [pid 139043:tid 139212] [client 172.182.217.32:21848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkMQAAAKw"] [Tue Aug 18 13:02:46.861233 2026] [security2:error] [pid 123784:tid 124013] [client 20.250.13.23:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/server.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWQgAAAF8"] [Tue Aug 18 13:02:46.872240 2026] [security2:error] [pid 123784:tid 123949] [client 20.65.105.233:12450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/btx25.php"] [unique_id "aoSCJmwDnJBNj2tDbYYWRAAAAB8"] [Tue Aug 18 13:02:46.887811 2026] [security2:error] [pid 139043:tid 139273] [client 20.206.96.72:16154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/edit-tags.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkMgAAAOk"] [Tue Aug 18 13:02:46.932474 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/sw.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkNAAAAQM"] [Tue Aug 18 13:02:46.949335 2026] [security2:error] [pid 139043:tid 139259] [client 20.118.133.132:47165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkNQAAANs"] [Tue Aug 18 13:02:46.964172 2026] [security2:error] [pid 139043:tid 139187] [client 68.155.154.236:8659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkNwAAAJM"] [Tue Aug 18 13:02:46.992047 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:46.992333 2026] [authz_core:error] [pid 123784:tid 123887] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:47.001330 2026] [security2:error] [pid 139043:tid 139300] [client 20.51.153.15:9839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gk.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkOAAAAQQ"] [Tue Aug 18 13:02:47.018417 2026] [security2:error] [pid 139043:tid 139280] [client 20.206.96.72:15295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/u.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkOQAAAPA"] [Tue Aug 18 13:02:47.037600 2026] [security2:error] [pid 139043:tid 139194] [client 20.25.139.174:2203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkOgAAAJo"] [Tue Aug 18 13:02:47.054688 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.200.96:15710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/index/function.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkOwAAAOg"] [Tue Aug 18 13:02:47.061898 2026] [security2:error] [pid 123784:tid 123976] [client 20.206.96.72:16134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWSQAAADo"] [Tue Aug 18 13:02:47.092465 2026] [security2:error] [pid 123784:tid 123996] [client 20.80.111.3:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/panel.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWSgAAAE4"] [Tue Aug 18 13:02:47.092573 2026] [security2:error] [pid 123784:tid 123963] [client 149.34.210.141:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWSwAAAC0"] [Tue Aug 18 13:02:47.106642 2026] [security2:error] [pid 139043:tid 139285] [client 20.206.96.72:16152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/h.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkPgAAAPU"] [Tue Aug 18 13:02:47.113613 2026] [security2:error] [pid 139043:tid 139201] [client 20.65.105.233:12751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/avim.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkPwAAAKE"] [Tue Aug 18 13:02:47.141552 2026] [security2:error] [pid 139043:tid 139261] [client 172.213.243.2:17653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/sadd.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkQQAAAN0"] [Tue Aug 18 13:02:47.156427 2026] [security2:error] [pid 123784:tid 124012] [client 20.251.112.238:43618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/g.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWTQAAAF4"] [Tue Aug 18 13:02:47.161817 2026] [security2:error] [pid 139043:tid 139175] [client 3.79.134.69:55122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkGgAAAIc"], referer: http://www.idealquimica.com [Tue Aug 18 13:02:47.183825 2026] [security2:error] [pid 123784:tid 123919] [client 114.119.154.65:65387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/selos-e-scripts/"] [unique_id "aoSCJ2wDnJBNj2tDbYYWTgAAAAE"], referer: https://ajuda.oruc.com.br/seo/ [Tue Aug 18 13:02:47.227556 2026] [security2:error] [pid 139043:tid 139293] [client 20.65.69.59:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/bm.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkQgAAAP0"] [Tue Aug 18 13:02:47.233056 2026] [security2:error] [pid 139043:tid 139180] [client 20.206.96.72:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkQwAAAIw"] [Tue Aug 18 13:02:47.234738 2026] [security2:error] [pid 139043:tid 139274] [client 20.51.153.15:9793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wn.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkRAAAAOo"] [Tue Aug 18 13:02:47.237546 2026] [security2:error] [pid 139043:tid 139256] [client 20.100.169.31:20260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/goods.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkRQAAANg"] [Tue Aug 18 13:02:47.292881 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:47.293151 2026] [authz_core:error] [pid 123784:tid 123915] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:47.306053 2026] [security2:error] [pid 139043:tid 139241] [client 20.206.96.72:15448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/a7.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkSQAAAMk"] [Tue Aug 18 13:02:47.345758 2026] [security2:error] [pid 123784:tid 123970] [client 20.206.96.72:16179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/manager.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWUgAAADQ"] [Tue Aug 18 13:02:47.353401 2026] [security2:error] [pid 123784:tid 123974] [client 158.23.17.4:9401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ij.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWUwAAADg"] [Tue Aug 18 13:02:47.355024 2026] [security2:error] [pid 123784:tid 123938] [client 20.65.105.233:13136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/myfile.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWVAAAABQ"] [Tue Aug 18 13:02:47.359329 2026] [security2:error] [pid 123784:tid 123963] [client 149.34.210.141:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWSwAAAC0"] [Tue Aug 18 13:02:47.372527 2026] [security2:error] [pid 139043:tid 139231] [client 168.62.48.100:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/kopyw.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkTgAAAL8"] [Tue Aug 18 13:02:47.487984 2026] [security2:error] [pid 123784:tid 123984] [client 20.151.109.219:27758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/jm.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWdgAAAEI"] [Tue Aug 18 13:02:47.492518 2026] [security2:error] [pid 139043:tid 139238] [client 40.74.65.169:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/blurbs.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkUwAAAMY"] [Tue Aug 18 13:02:47.504404 2026] [security2:error] [pid 123784:tid 123929] [client 40.74.65.169:55269] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.r3telhas.com.br"] [uri "/1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWeAAAAAs"] [Tue Aug 18 13:02:47.504512 2026] [security2:error] [pid 123784:tid 123929] [client 40.74.65.169:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWeAAAAAs"] [Tue Aug 18 13:02:47.517507 2026] [security2:error] [pid 123784:tid 123967] [client 168.62.48.100:5624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWfQAAADE"] [Tue Aug 18 13:02:47.517844 2026] [security2:error] [pid 123784:tid 124038] [client 20.251.48.93:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/222.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWfgAAAHg"] [Tue Aug 18 13:02:47.538383 2026] [security2:error] [pid 123784:tid 124011] [client 20.65.69.59:5379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vu.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWgQAAAF0"] [Tue Aug 18 13:02:47.542077 2026] [security2:error] [pid 123784:tid 124021] [client 20.25.139.174:2196] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.gfrison.com.br"] [uri "/1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWggAAAGc"] [Tue Aug 18 13:02:47.542182 2026] [security2:error] [pid 123784:tid 124021] [client 20.25.139.174:2196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWggAAAGc"] [Tue Aug 18 13:02:47.542830 2026] [security2:error] [pid 123784:tid 124017] [client 20.80.111.3:39876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins//about.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWgwAAAGM"] [Tue Aug 18 13:02:47.546042 2026] [security2:error] [pid 139043:tid 139178] [client 78.46.190.63:19216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSCJv2v-lWn9OzQT7UkNgAAAIo"], referer: https://www.idealquimica.com [Tue Aug 18 13:02:47.546199 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.154.236:45839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkVQAAAMw"] [Tue Aug 18 13:02:47.550470 2026] [security2:error] [pid 139043:tid 139246] [client 20.79.204.6:10779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/p.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkVgAAAM4"] [Tue Aug 18 13:02:47.551018 2026] [security2:error] [pid 139043:tid 139197] [client 172.213.243.2:16486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ex.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkVwAAAJ0"] [Tue Aug 18 13:02:47.557206 2026] [security2:error] [pid 139043:tid 139173] [client 20.250.13.23:3110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/settings.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkWAAAAIU"] [Tue Aug 18 13:02:47.589556 2026] [security2:error] [pid 123784:tid 123948] [client 20.51.153.15:9800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/app.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWhQAAAB4"] [Tue Aug 18 13:02:47.596341 2026] [security2:error] [pid 123784:tid 123931] [client 20.65.105.233:12793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xmy.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWhwAAAA0"] [Tue Aug 18 13:02:47.602221 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:47.602681 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:47.611811 2026] [security2:error] [pid 123784:tid 123971] [client 132.196.30.78:5610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/test1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWjgAAADU"] [Tue Aug 18 13:02:47.640153 2026] [security2:error] [pid 123784:tid 123964] [client 20.251.112.238:43613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/x7.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWkAAAAC4"] [Tue Aug 18 13:02:47.710145 2026] [security2:error] [pid 123784:tid 124043] [client 34.156.195.117:46772] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCJ2wDnJBNj2tDbYYWoQAAAH0"] [Tue Aug 18 13:02:47.741438 2026] [security2:error] [pid 123784:tid 123985] [client 20.116.17.175:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWowAAAEM"] [Tue Aug 18 13:02:47.742667 2026] [security2:error] [pid 123784:tid 123992] [client 172.182.200.96:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWpAAAAEo"] [Tue Aug 18 13:02:47.745151 2026] [security2:error] [pid 139043:tid 139185] [client 20.116.17.175:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/cong.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkWQAAAJE"] [Tue Aug 18 13:02:47.764187 2026] [security2:error] [pid 123784:tid 123939] [client 20.206.73.37:35277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/xyn.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWpQAAABU"] [Tue Aug 18 13:02:47.768146 2026] [security2:error] [pid 123784:tid 124030] [client 158.23.17.4:8897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/eh.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWpgAAAHA"] [Tue Aug 18 13:02:47.778992 2026] [security2:error] [pid 123784:tid 123932] [client 213.35.127.232:55935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWqAAAAA4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:47.794019 2026] [security2:error] [pid 139043:tid 139263] [client 172.182.217.32:21511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known//index.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkWwAAAN8"] [Tue Aug 18 13:02:47.833377 2026] [security2:error] [pid 123784:tid 123976] [client 20.51.153.15:9825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/87.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWqwAAADo"] [Tue Aug 18 13:02:47.835872 2026] [security2:error] [pid 123784:tid 123956] [client 158.23.17.4:16918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ud.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWrAAAACY"] [Tue Aug 18 13:02:47.836222 2026] [security2:error] [pid 123784:tid 124023] [client 20.65.105.233:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xda.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWrQAAAGk"] [Tue Aug 18 13:02:47.888175 2026] [security2:error] [pid 123784:tid 123957] [client 20.65.69.59:48461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ic.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYW6AAAACc"] [Tue Aug 18 13:02:47.893530 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:47.893758 2026] [security2:error] [pid 123784:tid 123947] [client 20.206.96.72:15453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/w1.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYW6QAAAB0"] [Tue Aug 18 13:02:47.893814 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:47.906934 2026] [security2:error] [pid 123784:tid 123828] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYW6wAAByc"] [Tue Aug 18 13:02:47.907152 2026] [security2:error] [pid 123784:tid 123925] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYW6wAAByc"] [Tue Aug 18 13:02:47.934151 2026] [security2:error] [pid 123784:tid 124041] [client 3.79.134.69:4440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSCJ2wDnJBNj2tDbYYWogAAAHs"], referer: http://www.idealquimica.com [Tue Aug 18 13:02:47.942090 2026] [security2:error] [pid 139043:tid 139245] [client 138.36.100.162:43049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkXwAAAM0"] [Tue Aug 18 13:02:47.942209 2026] [security2:error] [pid 139043:tid 139245] [client 138.36.100.162:43049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkXwAAAM0"] [Tue Aug 18 13:02:47.960653 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:16169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-login.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkYQAAANs"] [Tue Aug 18 13:02:47.962799 2026] [security2:error] [pid 123784:tid 124025] [client 34.156.195.117:46788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCJ2wDnJBNj2tDbYYW7QAAAGs"] [Tue Aug 18 13:02:47.965249 2026] [security2:error] [pid 139043:tid 139271] [client 172.213.243.2:16793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/tax.php"] [unique_id "aoSCJ_2v-lWn9OzQT7UkYgAAAOc"] [Tue Aug 18 13:02:48.015917 2026] [security2:error] [pid 123784:tid 124012] [client 20.80.111.3:39913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins//index.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW7wAAAF4"] [Tue Aug 18 13:02:48.043651 2026] [security2:error] [pid 139043:tid 139177] [client 20.206.96.72:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/default.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkYwAAAIk"] [Tue Aug 18 13:02:48.050138 2026] [security2:error] [pid 123784:tid 124005] [client 20.100.169.31:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/file.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW8AAAAFc"] [Tue Aug 18 13:02:48.055047 2026] [security2:error] [pid 139043:tid 139243] [client 20.251.112.238:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/god.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkZAAAAMs"] [Tue Aug 18 13:02:48.069267 2026] [autoindex:error] [pid 139043:tid 139209] [client 4.223.113.180:17879] AH01276: Cannot serve directory /home1/esteticar/public_html/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:48.072797 2026] [security2:error] [pid 123784:tid 124044] [client 20.25.139.174:2398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/alfa.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW8gAAAH4"] [Tue Aug 18 13:02:48.077572 2026] [security2:error] [pid 139043:tid 139272] [client 20.65.105.233:12461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/zz.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkZgAAAOg"] [Tue Aug 18 13:02:48.100110 2026] [security2:error] [pid 139043:tid 139270] [client 20.51.153.15:9752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/zi.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkZwAAAOY"] [Tue Aug 18 13:02:48.117674 2026] [security2:error] [pid 123784:tid 124026] [client 178.153.171.161:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW8wAAAGw"] [Tue Aug 18 13:02:48.117816 2026] [security2:error] [pid 123784:tid 124026] [client 178.153.171.161:50069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW8wAAAGw"] [Tue Aug 18 13:02:48.132535 2026] [security2:error] [pid 139043:tid 139218] [client 20.206.96.72:15993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/i.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkaAAAALI"] [Tue Aug 18 13:02:48.178549 2026] [security2:error] [pid 139043:tid 139261] [client 158.23.17.4:47926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gc.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkagAAAN0"] [Tue Aug 18 13:02:48.186526 2026] [security2:error] [pid 139043:tid 139175] [client 132.196.30.78:12767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/zwso.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkawAAAIc"] [Tue Aug 18 13:02:48.187904 2026] [security2:error] [pid 139043:tid 139198] [client 40.74.65.169:44222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/bajah.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkbAAAAJ4"] [Tue Aug 18 13:02:48.192329 2026] [security2:error] [pid 123784:tid 123944] [client 34.156.195.117:38722] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCKGwDnJBNj2tDbYYW9wAAABo"] [Tue Aug 18 13:02:48.192470 2026] [security2:error] [pid 139043:tid 139199] [client 40.74.65.169:51682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/coffee.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkbQAAAJ8"] [Tue Aug 18 13:02:48.195201 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:48.195467 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:48.228736 2026] [security2:error] [pid 139043:tid 139204] [client 20.206.96.72:15819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkbgAAAKQ"] [Tue Aug 18 13:02:48.235457 2026] [security2:error] [pid 123784:tid 124032] [client 157.20.138.62:51999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW-AAAAHI"] [Tue Aug 18 13:02:48.235488 2026] [security2:error] [pid 139043:tid 139196] [client 68.155.154.236:8354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkbwAAAJw"] [Tue Aug 18 13:02:48.235588 2026] [security2:error] [pid 123784:tid 124032] [client 157.20.138.62:51999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW-AAAAHI"] [Tue Aug 18 13:02:48.281178 2026] [security2:error] [pid 139043:tid 139194] [client 20.250.13.23:30800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/sf.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkcAAAAJo"] [Tue Aug 18 13:02:48.282769 2026] [security2:error] [pid 123784:tid 124016] [client 158.23.17.4:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ip.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW-gAAAGI"] [Tue Aug 18 13:02:48.284585 2026] [security2:error] [pid 139043:tid 139180] [client 4.223.113.180:17879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkcQAAAIw"] [Tue Aug 18 13:02:48.287695 2026] [security2:error] [pid 139043:tid 139201] [client 172.182.217.32:21851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/libraries/phpmailer//index.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkcgAAAKE"] [Tue Aug 18 13:02:48.332480 2026] [security2:error] [pid 123784:tid 123987] [client 20.65.105.233:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xa.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW-wAAAEU"] [Tue Aug 18 13:02:48.341571 2026] [security2:error] [pid 123784:tid 124017] [client 20.206.96.72:15446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW_QAAAGM"] [Tue Aug 18 13:02:48.375541 2026] [security2:error] [pid 123784:tid 124010] [client 103.120.71.157:56886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW_gAAAFw"] [Tue Aug 18 13:02:48.375672 2026] [security2:error] [pid 123784:tid 124010] [client 103.120.71.157:56886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW_gAAAFw"] [Tue Aug 18 13:02:48.375931 2026] [security2:error] [pid 123784:tid 123986] [client 20.206.96.72:16128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCKGwDnJBNj2tDbYYW_wAAAEQ"] [Tue Aug 18 13:02:48.383208 2026] [security2:error] [pid 123784:tid 123975] [client 172.213.243.2:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/X7x.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXAAAAADk"] [Tue Aug 18 13:02:48.388396 2026] [security2:error] [pid 139043:tid 139256] [client 34.156.195.117:38314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/proxy?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCKP2v-lWn9OzQT7UkcwAAANg"] [Tue Aug 18 13:02:48.395391 2026] [security2:error] [pid 123784:tid 123969] [client 20.65.69.59:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ue.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXAQAAADM"] [Tue Aug 18 13:02:48.395404 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/Cachex.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXAgAAAAo"] [Tue Aug 18 13:02:48.400867 2026] [security2:error] [pid 139043:tid 139297] [client 34.156.195.117:38306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCKP2v-lWn9OzQT7UkdAAAAQE"] [Tue Aug 18 13:02:48.403468 2026] [security2:error] [pid 123784:tid 123951] [client 102.213.179.104:54863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXBAAAACE"] [Tue Aug 18 13:02:48.403536 2026] [security2:error] [pid 123784:tid 123931] [client 20.206.96.72:15472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/NewFile.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXAwAAAA0"] [Tue Aug 18 13:02:48.403577 2026] [security2:error] [pid 123784:tid 123951] [client 102.213.179.104:54863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXBAAAACE"] [Tue Aug 18 13:02:48.414462 2026] [security2:error] [pid 123784:tid 123971] [client 20.51.153.15:9847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/92.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXBQAAADU"] [Tue Aug 18 13:02:48.449789 2026] [security2:error] [pid 123784:tid 124011] [client 20.80.111.3:30024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins//min.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXBwAAAF0"] [Tue Aug 18 13:02:48.476331 2026] [security2:error] [pid 139043:tid 139219] [client 20.251.112.238:46097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkdQAAALM"] [Tue Aug 18 13:02:48.482846 2026] [security2:error] [pid 139043:tid 139179] [client 20.116.17.175:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/css/database.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkdgAAAIs"] [Tue Aug 18 13:02:48.506850 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:48.507112 2026] [authz_core:error] [pid 123784:tid 123824] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:48.522497 2026] [security2:error] [pid 139043:tid 139224] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/h.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkeAAAALg"] [Tue Aug 18 13:02:48.549105 2026] [security2:error] [pid 123784:tid 123995] [client 34.156.195.117:38112] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCKGwDnJBNj2tDbYYXCwAAAE0"] [Tue Aug 18 13:02:48.554740 2026] [security2:error] [pid 123784:tid 123982] [client 20.206.96.72:16061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXDAAAAEA"] [Tue Aug 18 13:02:48.577460 2026] [security2:error] [pid 123784:tid 124015] [client 34.156.195.117:38154] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCKGwDnJBNj2tDbYYXDQAAAGE"] [Tue Aug 18 13:02:48.583890 2026] [security2:error] [pid 139043:tid 139206] [client 20.65.105.233:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/f6.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkeQAAAKY"] [Tue Aug 18 13:02:48.609816 2026] [security2:error] [pid 123784:tid 123935] [client 20.25.139.174:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/edit.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXDwAAABE"] [Tue Aug 18 13:02:48.615834 2026] [security2:error] [pid 139043:tid 139238] [client 20.206.96.72:15981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkegAAAMY"] [Tue Aug 18 13:02:48.642916 2026] [security2:error] [pid 139043:tid 139211] [client 20.206.96.72:15481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/themes.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkewAAAKs"] [Tue Aug 18 13:02:48.741530 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:34127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ad.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXEQAAAEo"] [Tue Aug 18 13:02:48.773529 2026] [security2:error] [pid 123784:tid 124013] [client 20.206.96.72:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/cv.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXEgAAAF8"] [Tue Aug 18 13:02:48.793059 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXFQAAAHc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:48.793316 2026] [security2:error] [pid 139043:tid 139185] [client 158.23.17.4:9802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/uq.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkfQAAAJE"] [Tue Aug 18 13:02:48.794291 2026] [security2:error] [pid 123784:tid 124039] [client 172.213.243.2:49461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ocxla.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXFgAAAHk"] [Tue Aug 18 13:02:48.795321 2026] [security2:error] [pid 139043:tid 139208] [client 172.182.217.32:21508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkfgAAAKg"] [Tue Aug 18 13:02:48.798207 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:9772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/jm.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkfwAAAPw"] [Tue Aug 18 13:02:48.799337 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:48.799599 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:48.806385 2026] [security2:error] [pid 139043:tid 139255] [client 132.196.30.78:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/Geforce.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkgAAAANc"] [Tue Aug 18 13:02:48.820486 2026] [security2:error] [pid 139043:tid 139260] [client 20.206.96.72:15478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkggAAANw"] [Tue Aug 18 13:02:48.824390 2026] [security2:error] [pid 139043:tid 139200] [client 20.65.105.233:12440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/mcs.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkgwAAAKA"] [Tue Aug 18 13:02:48.841541 2026] [security2:error] [pid 123784:tid 123938] [client 213.202.253.4:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/gdftps.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXFwAAABQ"], referer: www.google.com [Tue Aug 18 13:02:48.853900 2026] [security2:error] [pid 123784:tid 124024] [client 20.206.96.72:16060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ws83.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXGAAAAGo"] [Tue Aug 18 13:02:48.870643 2026] [security2:error] [pid 123784:tid 124033] [client 68.155.154.236:8882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXGgAAAHM"] [Tue Aug 18 13:02:48.882427 2026] [security2:error] [pid 139043:tid 139174] [client 40.74.65.169:38402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/domvf.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkhAAAAIY"] [Tue Aug 18 13:02:48.888030 2026] [security2:error] [pid 123784:tid 123976] [client 40.74.65.169:51651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXHAAAADo"] [Tue Aug 18 13:02:48.896242 2026] [security2:error] [pid 139043:tid 139191] [client 20.80.111.3:26136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/111/wp-polls/tinymce/plugins/security.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkhQAAAJc"] [Tue Aug 18 13:02:48.906841 2026] [security2:error] [pid 123784:tid 123996] [client 20.251.112.238:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/8.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXHQAAAE4"] [Tue Aug 18 13:02:48.916640 2026] [security2:error] [pid 139043:tid 139286] [client 20.250.13.23:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/shell.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkhgAAAPY"] [Tue Aug 18 13:02:48.925334 2026] [security2:error] [pid 139043:tid 139249] [client 20.251.48.93:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/key.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkhwAAANE"] [Tue Aug 18 13:02:48.935643 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.200.96:15673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCKP2v-lWn9OzQT7UkiAAAAOs"] [Tue Aug 18 13:02:48.939190 2026] [security2:error] [pid 123784:tid 123936] [client 37.40.227.74:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXHgAAABI"] [Tue Aug 18 13:02:48.943847 2026] [security2:error] [pid 123784:tid 123936] [client 37.40.227.74:56834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXHgAAABI"] [Tue Aug 18 13:02:48.943875 2026] [security2:error] [pid 123784:tid 123997] [client 20.206.96.72:15941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/atex1.php"] [unique_id "aoSCKGwDnJBNj2tDbYYXHwAAAE8"] [Tue Aug 18 13:02:49.022710 2026] [security2:error] [pid 123784:tid 123970] [client 20.206.96.72:15276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXIQAAADQ"] [Tue Aug 18 13:02:49.024497 2026] [security2:error] [pid 123784:tid 123963] [client 158.23.17.4:8756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/99.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXIgAAAC0"] [Tue Aug 18 13:02:49.055387 2026] [security2:error] [pid 123784:tid 123924] [client 20.206.96.72:15257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/w.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXIwAAAAY"] [Tue Aug 18 13:02:49.063800 2026] [security2:error] [pid 123784:tid 123947] [client 20.65.105.233:12593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/xleet.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXJQAAAB0"] [Tue Aug 18 13:02:49.071085 2026] [security2:error] [pid 123784:tid 123942] [client 20.65.69.59:27857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lr.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXJgAAABg"] [Tue Aug 18 13:02:49.086952 2026] [security2:error] [pid 139043:tid 139268] [client 20.206.96.72:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/archive.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkigAAAOQ"] [Tue Aug 18 13:02:49.101084 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:49.101351 2026] [authz_core:error] [pid 123784:tid 123815] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:49.123168 2026] [security2:error] [pid 123784:tid 123933] [client 20.206.96.72:16015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/bless.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXKAAAAA8"] [Tue Aug 18 13:02:49.132630 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wj.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkiwAAAOk"] [Tue Aug 18 13:02:49.136003 2026] [security2:error] [pid 123784:tid 123960] [client 20.25.139.174:2395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/elp.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXKQAAACo"] [Tue Aug 18 13:02:49.210210 2026] [security2:error] [pid 139043:tid 139248] [client 172.213.243.2:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/post.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkjQAAANA"] [Tue Aug 18 13:02:49.257639 2026] [security2:error] [pid 139043:tid 139227] [client 20.206.96.72:16047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/sagax1.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkjwAAALs"] [Tue Aug 18 13:02:49.263128 2026] [security2:error] [pid 139043:tid 139245] [client 52.173.121.69:53646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkkAAAAM0"] [Tue Aug 18 13:02:49.269850 2026] [security2:error] [pid 139043:tid 139229] [client 20.116.17.175:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/privdayz.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkkQAAAL0"] [Tue Aug 18 13:02:49.283962 2026] [security2:error] [pid 139043:tid 139280] [client 20.79.204.6:10401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.redmotoslimeira.com.br"] [uri "/php.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkkgAAAPA"] [Tue Aug 18 13:02:49.283981 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.96.72:15942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wpc.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkkwAAANs"] [Tue Aug 18 13:02:49.290372 2026] [security2:error] [pid 123784:tid 124022] [client 172.182.217.32:21871] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXLQAAAGg"] [Tue Aug 18 13:02:49.290444 2026] [security2:error] [pid 123784:tid 124022] [client 172.182.217.32:21871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/blue//1.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXLQAAAGg"] [Tue Aug 18 13:02:49.305922 2026] [security2:error] [pid 139043:tid 139279] [client 34.156.195.117:38712] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCKf2v-lWn9OzQT7UklAAAAO8"] [Tue Aug 18 13:02:49.311714 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.105.233:12449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fr/ms.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXLgAAAH4"] [Tue Aug 18 13:02:49.322230 2026] [security2:error] [pid 123784:tid 124005] [client 20.206.96.72:16157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/fone1.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXLwAAAFc"] [Tue Aug 18 13:02:49.335291 2026] [security2:error] [pid 123784:tid 124026] [client 20.251.112.238:46092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/koiy.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXMAAAAGw"] [Tue Aug 18 13:02:49.343122 2026] [security2:error] [pid 139043:tid 139205] [client 20.100.169.31:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCKf2v-lWn9OzQT7UklQAAAKU"] [Tue Aug 18 13:02:49.359828 2026] [security2:error] [pid 123784:tid 124041] [client 20.80.111.3:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXMgAAAHs"] [Tue Aug 18 13:02:49.370345 2026] [security2:error] [pid 123784:tid 123923] [client 20.51.153.15:9809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/74.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXMwAAAAU"] [Tue Aug 18 13:02:49.393492 2026] [security2:error] [pid 139043:tid 139300] [client 172.182.200.96:15618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-2019.php"] [unique_id "aoSCKf2v-lWn9OzQT7UklgAAAQQ"] [Tue Aug 18 13:02:49.400143 2026] [security2:error] [pid 123784:tid 123989] [client 20.206.96.72:16003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ncx.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXNgAAAEc"] [Tue Aug 18 13:02:49.404213 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:49.404491 2026] [authz_core:error] [pid 123784:tid 123796] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:49.452754 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:43435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXOAAAABk"] [Tue Aug 18 13:02:49.452899 2026] [security2:error] [pid 123784:tid 123943] [client 103.184.169.37:43435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXOAAAABk"] [Tue Aug 18 13:02:49.519092 2026] [security2:error] [pid 139043:tid 139214] [client 20.206.96.72:16009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkmwAAAK4"] [Tue Aug 18 13:02:49.522066 2026] [security2:error] [pid 123784:tid 124035] [client 34.156.195.117:46788] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCKWwDnJBNj2tDbYYXOgAAAHU"] [Tue Aug 18 13:02:49.537174 2026] [security2:error] [pid 139043:tid 139264] [client 34.156.195.117:38240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCKf2v-lWn9OzQT7UknAAAAOA"] [Tue Aug 18 13:02:49.550905 2026] [security2:error] [pid 123784:tid 124017] [client 20.65.105.233:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/gool.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXOwAAAGM"] [Tue Aug 18 13:02:49.550907 2026] [security2:error] [pid 139043:tid 139204] [client 20.65.69.59:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ka.php"] [unique_id "aoSCKf2v-lWn9OzQT7UknQAAAKQ"] [Tue Aug 18 13:02:49.561874 2026] [security2:error] [pid 123784:tid 123987] [client 20.206.96.72:16031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wso.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXPAAAAEU"] [Tue Aug 18 13:02:49.563457 2026] [security2:error] [pid 139043:tid 139196] [client 40.74.65.169:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkngAAAJw"] [Tue Aug 18 13:02:49.567734 2026] [security2:error] [pid 139043:tid 139276] [client 40.74.65.169:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/fpwch.php"] [unique_id "aoSCKf2v-lWn9OzQT7UknwAAAOw"] [Tue Aug 18 13:02:49.602194 2026] [security2:error] [pid 139043:tid 139189] [client 20.250.13.23:30826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/shiny.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkoQAAAJU"] [Tue Aug 18 13:02:49.606582 2026] [security2:error] [pid 139043:tid 139180] [client 158.23.17.4:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/vd.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkogAAAIw"] [Tue Aug 18 13:02:49.611257 2026] [security2:error] [pid 139043:tid 139201] [client 20.51.153.15:9829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/av.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkowAAAKE"] [Tue Aug 18 13:02:49.628504 2026] [security2:error] [pid 139043:tid 139267] [client 172.213.243.2:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/nhr.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkpQAAAOM"] [Tue Aug 18 13:02:49.677607 2026] [security2:error] [pid 123784:tid 123928] [client 20.151.109.219:27360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wj.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXQAAAAAo"] [Tue Aug 18 13:02:49.681271 2026] [security2:error] [pid 139043:tid 139175] [client 20.25.139.174:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkpgAAAIc"] [Tue Aug 18 13:02:49.683326 2026] [security2:error] [pid 123784:tid 123931] [client 68.155.154.236:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXQQAAAA0"] [Tue Aug 18 13:02:49.704305 2026] [authz_core:error] [pid 123784:tid 123856] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:49.704750 2026] [authz_core:error] [pid 123784:tid 123856] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:49.730491 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:11007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/er.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkpwAAANg"] [Tue Aug 18 13:02:49.744130 2026] [security2:error] [pid 123784:tid 124001] [client 20.251.112.238:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/iko.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXRQAAAFM"] [Tue Aug 18 13:02:49.752266 2026] [security2:error] [pid 123784:tid 123959] [client 20.206.96.72:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/zup.php73"] [unique_id "aoSCKWwDnJBNj2tDbYYXRgAAACk"] [Tue Aug 18 13:02:49.756740 2026] [security2:error] [pid 139043:tid 139257] [client 34.156.195.117:38306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCKf2v-lWn9OzQT7UkqAAAANk"] [Tue Aug 18 13:02:49.757022 2026] [security2:error] [pid 123784:tid 124000] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/koiy.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXRwAAAFI"] [Tue Aug 18 13:02:49.779344 2026] [security2:error] [pid 123784:tid 124010] [client 172.182.217.32:21830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/uploads/BbUMY/flower.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXSAAAAFw"] [Tue Aug 18 13:02:49.790672 2026] [security2:error] [pid 139043:tid 139241] [client 20.65.105.233:12561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/maxro.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkqQAAAMk"] [Tue Aug 18 13:02:49.795989 2026] [security2:error] [pid 123784:tid 123964] [client 20.206.96.72:15971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/k.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXSgAAAC4"] [Tue Aug 18 13:02:49.800597 2026] [security2:error] [pid 123784:tid 123975] [client 20.80.111.3:26168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/bolvo-features/inc/plugins/data.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXSwAAADk"] [Tue Aug 18 13:02:49.804366 2026] [security2:error] [pid 139043:tid 139261] [client 213.35.127.232:56383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkqgAAAN0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:49.811082 2026] [security2:error] [pid 123784:tid 124045] [client 158.23.17.4:7772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/32.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXTAAAAH8"] [Tue Aug 18 13:02:49.837035 2026] [security2:error] [pid 123784:tid 123982] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fff.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXTgAAAEA"] [Tue Aug 18 13:02:49.840752 2026] [security2:error] [pid 139043:tid 139281] [client 34.156.195.117:38314] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCKf2v-lWn9OzQT7UkrAAAAPE"] [Tue Aug 18 13:02:49.917098 2026] [security2:error] [pid 139043:tid 139288] [client 20.65.69.59:5393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ot.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkrQAAAPg"] [Tue Aug 18 13:02:49.928153 2026] [security2:error] [pid 123784:tid 123946] [client 172.182.200.96:15743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXUAAAABw"] [Tue Aug 18 13:02:49.935160 2026] [security2:error] [pid 123784:tid 123954] [client 20.206.96.72:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXUQAAACQ"] [Tue Aug 18 13:02:49.955257 2026] [security2:error] [pid 123784:tid 124012] [client 5.31.227.224:1460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXUgAAAF4"] [Tue Aug 18 13:02:49.955371 2026] [security2:error] [pid 123784:tid 124012] [client 5.31.227.224:1460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCKWwDnJBNj2tDbYYXUgAAAF4"] [Tue Aug 18 13:02:50.001876 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:50.002140 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:50.006219 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:9561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ag.php"] [unique_id "aoSCKv2v-lWn9OzQT7UksAAAANM"] [Tue Aug 18 13:02:50.017462 2026] [security2:error] [pid 139043:tid 139210] [client 20.206.96.72:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/ww5.php"] [unique_id "aoSCKv2v-lWn9OzQT7UksgAAAKo"] [Tue Aug 18 13:02:50.039116 2026] [security2:error] [pid 123784:tid 124004] [client 20.65.105.233:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wdf.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXVwAAAFY"] [Tue Aug 18 13:02:50.042679 2026] [security2:error] [pid 123784:tid 124037] [client 172.213.243.2:54861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXWAAAAHc"] [Tue Aug 18 13:02:50.044171 2026] [security2:error] [pid 123784:tid 123952] [client 20.206.96.72:16020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/2.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXWQAAACI"] [Tue Aug 18 13:02:50.078072 2026] [security2:error] [pid 123784:tid 124024] [client 132.196.30.78:6353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/fpwch.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXXAAAAGo"] [Tue Aug 18 13:02:50.098415 2026] [security2:error] [pid 123784:tid 123956] [client 168.62.48.100:4221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/zznmg.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXXQAAACY"] [Tue Aug 18 13:02:50.136876 2026] [security2:error] [pid 123784:tid 123938] [client 20.206.96.72:15437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXXgAAABQ"] [Tue Aug 18 13:02:50.163687 2026] [security2:error] [pid 139043:tid 139198] [client 178.156.189.113:47902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSCKf2v-lWn9OzQT7UkpAAAAJ4"], referer: https://rota85motorshop.com.br/ [Tue Aug 18 13:02:50.172052 2026] [security2:error] [pid 123784:tid 123961] [client 20.251.112.238:34721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/raw.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXYAAAACs"] [Tue Aug 18 13:02:50.203408 2026] [security2:error] [pid 139043:tid 139197] [client 20.25.139.174:2420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/666.php"] [unique_id "aoSCKv2v-lWn9OzQT7UktAAAAJ0"] [Tue Aug 18 13:02:50.205941 2026] [security2:error] [pid 123784:tid 123974] [client 20.116.17.175:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/term.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXYgAAADg"] [Tue Aug 18 13:02:50.208516 2026] [security2:error] [pid 123784:tid 124018] [client 20.206.96.72:16163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/atomlib.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXYwAAAGQ"] [Tue Aug 18 13:02:50.230750 2026] [security2:error] [pid 139043:tid 139235] [client 20.206.96.72:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/rip.php"] [unique_id "aoSCKv2v-lWn9OzQT7UktQAAAMM"] [Tue Aug 18 13:02:50.242985 2026] [security2:error] [pid 123784:tid 123957] [client 40.74.65.169:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/adminner.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXZQAAACc"] [Tue Aug 18 13:02:50.244749 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:9773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ig.php"] [unique_id "aoSCKv2v-lWn9OzQT7UktgAAAPw"] [Tue Aug 18 13:02:50.248732 2026] [security2:error] [pid 139043:tid 139260] [client 40.74.65.169:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/yj09.php"] [unique_id "aoSCKv2v-lWn9OzQT7UktwAAANw"] [Tue Aug 18 13:02:50.250080 2026] [security2:error] [pid 123784:tid 124023] [client 20.80.111.3:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/about.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXZgAAAGk"] [Tue Aug 18 13:02:50.256833 2026] [security2:error] [pid 139043:tid 139186] [client 20.206.96.72:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/p.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkuAAAAJI"] [Tue Aug 18 13:02:50.267382 2026] [security2:error] [pid 123784:tid 123996] [client 172.182.217.32:21760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/ID3//file.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXaAAAAE4"] [Tue Aug 18 13:02:50.289092 2026] [security2:error] [pid 139043:tid 139191] [client 20.206.96.72:16174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.96.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.rhemahost.com.br"] [uri "/php.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkugAAAJc"] [Tue Aug 18 13:02:50.294165 2026] [security2:error] [pid 139043:tid 139249] [client 20.65.105.233:12437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ff1.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkvAAAANE"] [Tue Aug 18 13:02:50.302439 2026] [security2:error] [pid 139043:tid 139178] [client 20.250.13.23:30832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/sid3.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkvgAAAIo"] [Tue Aug 18 13:02:50.305347 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:50.305594 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:50.340897 2026] [security2:error] [pid 123784:tid 123942] [client 20.65.69.59:27862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ih.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXagAAABg"] [Tue Aug 18 13:02:50.373001 2026] [security2:error] [pid 139043:tid 139223] [client 20.116.17.175:55183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wg459o.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkwAAAALc"] [Tue Aug 18 13:02:50.386598 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/pouhg.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkwQAAAKc"] [Tue Aug 18 13:02:50.468448 2026] [security2:error] [pid 123784:tid 123926] [client 172.213.243.2:5674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ws79.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXbQAAAAg"] [Tue Aug 18 13:02:50.534553 2026] [security2:error] [pid 123784:tid 123941] [client 20.65.105.233:12560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/guk.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXbwAAABc"] [Tue Aug 18 13:02:50.535670 2026] [security2:error] [pid 139043:tid 139248] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/moon3.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkwwAAANA"] [Tue Aug 18 13:02:50.554016 2026] [security2:error] [pid 139043:tid 139234] [client 172.182.200.96:15711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/.cache/x.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkxAAAAMI"] [Tue Aug 18 13:02:50.593755 2026] [security2:error] [pid 139043:tid 139227] [client 20.251.112.238:29249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/05.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkxQAAALs"] [Tue Aug 18 13:02:50.609278 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:50.609546 2026] [authz_core:error] [pid 123784:tid 123822] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:50.614892 2026] [security2:error] [pid 139043:tid 139245] [client 68.155.154.236:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkxgAAAM0"] [Tue Aug 18 13:02:50.620625 2026] [security2:error] [pid 139043:tid 139229] [client 20.65.69.59:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/k.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkxwAAAL0"] [Tue Aug 18 13:02:50.698518 2026] [security2:error] [pid 139043:tid 139244] [client 20.80.111.3:30032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/admin.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkyAAAAMw"] [Tue Aug 18 13:02:50.721612 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:8737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qk.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkywAAAPA"] [Tue Aug 18 13:02:50.742516 2026] [security2:error] [pid 139043:tid 139205] [client 20.51.153.15:9783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ta.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkzQAAAKU"] [Tue Aug 18 13:02:50.772768 2026] [security2:error] [pid 139043:tid 139195] [client 172.182.217.32:21887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/Text/Diff/Engine//about.php"] [unique_id "aoSCKv2v-lWn9OzQT7UkzgAAAJs"] [Tue Aug 18 13:02:50.774478 2026] [security2:error] [pid 123784:tid 124026] [client 20.65.105.233:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-the.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXcwAAAGw"] [Tue Aug 18 13:02:50.802111 2026] [security2:error] [pid 139043:tid 139243] [client 34.156.195.117:38240] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCKv2v-lWn9OzQT7UkzwAAAMs"] [Tue Aug 18 13:02:50.816826 2026] [security2:error] [pid 139043:tid 139215] [client 213.35.127.232:56583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk0QAAAK8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:50.859464 2026] [security2:error] [pid 123784:tid 123993] [client 20.251.48.93:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/chosen.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXdgAAAEs"] [Tue Aug 18 13:02:50.884107 2026] [security2:error] [pid 123784:tid 123967] [client 172.213.243.2:16452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/rtx.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXdwAAADE"] [Tue Aug 18 13:02:50.907426 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:50.907685 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:50.908807 2026] [security2:error] [pid 139043:tid 139218] [client 20.25.139.174:2209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ws54.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk0wAAALI"] [Tue Aug 18 13:02:50.923539 2026] [security2:error] [pid 139043:tid 139225] [client 40.74.65.169:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/abcd.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk1AAAALk"] [Tue Aug 18 13:02:50.943225 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/scxy.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXewAAABk"] [Tue Aug 18 13:02:50.969140 2026] [security2:error] [pid 123784:tid 124005] [client 20.250.13.23:3392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/sid4.php"] [unique_id "aoSCKmwDnJBNj2tDbYYXfAAAAFc"] [Tue Aug 18 13:02:50.970707 2026] [security2:error] [pid 139043:tid 139264] [client 20.206.73.37:29952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/inso.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk1QAAAOA"] [Tue Aug 18 13:02:50.985303 2026] [security2:error] [pid 139043:tid 139200] [client 223.185.37.47:27903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk1gAAAKA"] [Tue Aug 18 13:02:50.989000 2026] [security2:error] [pid 139043:tid 139200] [client 223.185.37.47:27903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCKv2v-lWn9OzQT7Uk1gAAAKA"] [Tue Aug 18 13:02:51.014029 2026] [security2:error] [pid 123784:tid 123955] [client 20.65.105.233:12776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sbhu.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXfwAAACU"] [Tue Aug 18 13:02:51.032012 2026] [security2:error] [pid 139043:tid 139189] [client 20.51.153.15:9826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/34.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk1wAAAJU"] [Tue Aug 18 13:02:51.052258 2026] [security2:error] [pid 139043:tid 139180] [client 20.251.112.238:42057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/public/hi.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk2AAAAIw"] [Tue Aug 18 13:02:51.060480 2026] [security2:error] [pid 139043:tid 139201] [client 34.156.195.117:38306] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCK_2v-lWn9OzQT7Uk2QAAAKE"] [Tue Aug 18 13:02:51.085422 2026] [autoindex:error] [pid 123784:tid 123973] [client 205.210.31.25:58002] AH01276: Cannot serve directory /home3/cp39imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:51.137454 2026] [security2:error] [pid 123784:tid 123987] [client 172.182.200.96:15688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXhAAAAEU"] [Tue Aug 18 13:02:51.143951 2026] [security2:error] [pid 139043:tid 139199] [client 20.80.111.3:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk3QAAAJ8"] [Tue Aug 18 13:02:51.156454 2026] [security2:error] [pid 123784:tid 124014] [client 132.196.30.78:20912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXhQAAAGA"] [Tue Aug 18 13:02:51.174454 2026] [security2:error] [pid 139043:tid 139296] [client 34.156.195.117:38786] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCK_2v-lWn9OzQT7Uk3gAAAQA"] [Tue Aug 18 13:02:51.190391 2026] [security2:error] [pid 139043:tid 139297] [client 20.116.17.175:55175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/mifta.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk3wAAAQE"] [Tue Aug 18 13:02:51.194955 2026] [security2:error] [pid 139043:tid 139241] [client 20.65.69.59:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/iu.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk4AAAAMk"] [Tue Aug 18 13:02:51.206225 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:51.206510 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:51.229202 2026] [security2:error] [pid 139043:tid 139273] [client 34.156.195.117:38770] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCK_2v-lWn9OzQT7Uk4QAAAOk"] [Tue Aug 18 13:02:51.253817 2026] [security2:error] [pid 123784:tid 123931] [client 20.65.105.233:12420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/zc-318.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXiQAAAA0"] [Tue Aug 18 13:02:51.262458 2026] [security2:error] [pid 123784:tid 124035] [client 172.182.217.32:21859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/Text/Diff/Engine//index.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXiwAAAHU"] [Tue Aug 18 13:02:51.270757 2026] [security2:error] [pid 139043:tid 139231] [client 20.51.153.15:9473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/he.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk4gAAAL8"] [Tue Aug 18 13:02:51.301413 2026] [security2:error] [pid 139043:tid 139226] [client 172.213.243.2:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/end.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk4wAAALo"] [Tue Aug 18 13:02:51.328425 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:33413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/56.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk5AAAALg"] [Tue Aug 18 13:02:51.463014 2026] [security2:error] [pid 139043:tid 139219] [client 20.25.139.174:2428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk5gAAALM"] [Tue Aug 18 13:02:51.473429 2026] [security2:error] [pid 139043:tid 139246] [client 20.251.112.238:54405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/get.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk5wAAAM4"] [Tue Aug 18 13:02:51.493273 2026] [security2:error] [pid 123784:tid 123948] [client 20.65.105.233:12565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ccou.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXjgAAAB4"] [Tue Aug 18 13:02:51.505644 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:51.505905 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:51.534368 2026] [security2:error] [pid 123784:tid 123995] [client 20.65.69.59:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pk.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXkAAAAE0"] [Tue Aug 18 13:02:51.540441 2026] [security2:error] [pid 139043:tid 139208] [client 20.51.153.15:9525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gz.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk7AAAAKg"] [Tue Aug 18 13:02:51.576695 2026] [security2:error] [pid 123784:tid 124015] [client 172.182.200.96:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/index.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXkQAAAGE"] [Tue Aug 18 13:02:51.597381 2026] [security2:error] [pid 123784:tid 124043] [client 158.23.17.4:10949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXkgAAAH0"] [Tue Aug 18 13:02:51.612814 2026] [security2:error] [pid 139043:tid 139211] [client 20.80.111.3:15638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/db-status.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk7QAAAKs"] [Tue Aug 18 13:02:51.616248 2026] [security2:error] [pid 123784:tid 123935] [client 40.74.65.169:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/simple.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXlAAAABE"] [Tue Aug 18 13:02:51.616338 2026] [security2:error] [pid 123784:tid 123888] [remote 161.18.228.63:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.228.18.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-login.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXkwAAW2M"] [Tue Aug 18 13:02:51.623286 2026] [security2:error] [pid 139043:tid 139179] [client 4.232.151.198:32935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/155.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk7gAAAIs"] [Tue Aug 18 13:02:51.641363 2026] [security2:error] [pid 139043:tid 139228] [client 40.74.65.169:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk7wAAALw"] [Tue Aug 18 13:02:51.712904 2026] [security2:error] [pid 139043:tid 139114] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk8gAA3kY"] [Tue Aug 18 13:02:51.713100 2026] [security2:error] [pid 139043:tid 139262] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk8gAA3kY"] [Tue Aug 18 13:02:51.715800 2026] [security2:error] [pid 139043:tid 139290] [client 172.213.243.2:18692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlidesp.com.br"] [uri "/ae.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk8wAAAPo"] [Tue Aug 18 13:02:51.733514 2026] [security2:error] [pid 123784:tid 123992] [client 20.65.105.233:12466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/txets.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXmgAAAEo"] [Tue Aug 18 13:02:51.752922 2026] [security2:error] [pid 123784:tid 124030] [client 20.116.17.175:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXnAAAAHA"] [Tue Aug 18 13:02:51.761654 2026] [security2:error] [pid 123784:tid 124002] [client 172.182.217.32:21864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/css//index.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXnQAAAFQ"] [Tue Aug 18 13:02:51.780837 2026] [security2:error] [pid 123784:tid 123990] [client 20.79.204.6:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/inputs.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXnwAAAEg"] [Tue Aug 18 13:02:51.794639 2026] [security2:error] [pid 139043:tid 139233] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/opts.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk9AAAAME"] [Tue Aug 18 13:02:51.809458 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:51.809712 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:51.836319 2026] [security2:error] [pid 123784:tid 124045] [client 213.35.127.232:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCK2wDnJBNj2tDbYYXoQAAAH8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:51.861657 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.69.59:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ge.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk9QAAALA"] [Tue Aug 18 13:02:51.886778 2026] [security2:error] [pid 139043:tid 139299] [client 20.251.112.238:29283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/rpk.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk9wAAAQM"] [Tue Aug 18 13:02:51.903643 2026] [security2:error] [pid 139043:tid 139245] [client 20.51.153.15:9849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nf.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk-AAAAM0"] [Tue Aug 18 13:02:51.934883 2026] [security2:error] [pid 139043:tid 139244] [client 20.250.13.23:3119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/size.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk-QAAAMw"] [Tue Aug 18 13:02:51.989678 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.105.233:12550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fun.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk-gAAAO8"] [Tue Aug 18 13:02:51.991244 2026] [security2:error] [pid 139043:tid 139195] [client 20.151.109.219:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/74.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk-wAAAJs"] [Tue Aug 18 13:02:51.992032 2026] [security2:error] [pid 139043:tid 139278] [client 168.62.48.100:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCK_2v-lWn9OzQT7Uk_AAAAO4"] [Tue Aug 18 13:02:52.011729 2026] [security2:error] [pid 139043:tid 139202] [client 20.25.139.174:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/function/function.php"] [unique_id "aoSCLP2v-lWn9OzQT7Uk_QAAAKI"] [Tue Aug 18 13:02:52.114161 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:52.114626 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:52.130647 2026] [security2:error] [pid 123784:tid 124024] [client 20.65.69.59:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kl.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXpwAAAGo"] [Tue Aug 18 13:02:52.139470 2026] [security2:error] [pid 139043:tid 139265] [client 172.182.200.96:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlAQAAAOE"] [Tue Aug 18 13:02:52.167673 2026] [security2:error] [pid 139043:tid 139185] [client 196.12.128.158:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlAgAAAJE"] [Tue Aug 18 13:02:52.167827 2026] [security2:error] [pid 139043:tid 139185] [client 196.12.128.158:61218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlAgAAAJE"] [Tue Aug 18 13:02:52.170907 2026] [security2:error] [pid 139043:tid 139214] [client 20.51.153.15:9778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xv.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlAwAAAK4"] [Tue Aug 18 13:02:52.213634 2026] [security2:error] [pid 139043:tid 139213] [client 197.184.64.235:41972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlBQAAAK0"] [Tue Aug 18 13:02:52.213793 2026] [security2:error] [pid 139043:tid 139213] [client 197.184.64.235:41972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlBQAAAK0"] [Tue Aug 18 13:02:52.214737 2026] [security2:error] [pid 139043:tid 139200] [client 20.80.111.3:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/elementor/core/admin/ui/components/min.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlBgAAAKA"] [Tue Aug 18 13:02:52.249130 2026] [security2:error] [pid 139043:tid 139194] [client 20.65.105.233:12759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/jq.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlBwAAAJo"] [Tue Aug 18 13:02:52.253755 2026] [security2:error] [pid 123784:tid 123956] [client 68.155.154.236:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXqgAAACY"] [Tue Aug 18 13:02:52.254257 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.217.32:21854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/css//xc.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlCAAAAOg"] [Tue Aug 18 13:02:52.291576 2026] [security2:error] [pid 139043:tid 139201] [client 40.74.65.169:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlCQAAAKE"] [Tue Aug 18 13:02:52.307058 2026] [security2:error] [pid 123784:tid 123936] [client 20.251.48.93:53117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/wpxml.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXqwAAABI"] [Tue Aug 18 13:02:52.322121 2026] [security2:error] [pid 139043:tid 139212] [client 20.251.112.238:54423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlCwAAAKw"] [Tue Aug 18 13:02:52.332198 2026] [security2:error] [pid 123784:tid 123938] [client 20.116.17.175:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/index2.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXrQAAABQ"] [Tue Aug 18 13:02:52.349068 2026] [security2:error] [pid 123784:tid 123980] [client 40.74.65.169:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXrwAAAD4"] [Tue Aug 18 13:02:52.350685 2026] [security2:error] [pid 123784:tid 123961] [client 158.23.17.4:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/rx.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXsAAAACs"] [Tue Aug 18 13:02:52.407589 2026] [security2:error] [pid 123784:tid 124038] [client 20.51.153.15:9855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mx.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXsgAAAHg"] [Tue Aug 18 13:02:52.409177 2026] [security2:error] [pid 139043:tid 139256] [client 132.196.30.78:24021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/about/function.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlDAAAANg"] [Tue Aug 18 13:02:52.414351 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:52.414676 2026] [authz_core:error] [pid 123784:tid 123889] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:52.488956 2026] [security2:error] [pid 139043:tid 139183] [client 20.65.69.59:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gs.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlDQAAAI8"] [Tue Aug 18 13:02:52.490010 2026] [security2:error] [pid 123784:tid 123918] [client 158.23.17.4:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/73.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXtAAAAAA"] [Tue Aug 18 13:02:52.496863 2026] [security2:error] [pid 139043:tid 139281] [client 20.65.105.233:12553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sys.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlDgAAAPE"] [Tue Aug 18 13:02:52.533524 2026] [security2:error] [pid 139043:tid 139223] [client 34.156.195.117:38792] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCLP2v-lWn9OzQT7UlDwAAALc"] [Tue Aug 18 13:02:52.560410 2026] [security2:error] [pid 139043:tid 139293] [client 4.232.151.198:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/96i.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlEAAAAP0"] [Tue Aug 18 13:02:52.582014 2026] [security2:error] [pid 139043:tid 139176] [client 34.156.195.117:38806] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCLP2v-lWn9OzQT7UlEQAAAIg"] [Tue Aug 18 13:02:52.599348 2026] [security2:error] [pid 139043:tid 139251] [client 20.116.17.175:3398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/black.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlEgAAANM"] [Tue Aug 18 13:02:52.623885 2026] [security2:error] [pid 139043:tid 139210] [client 172.182.200.96:2001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlEwAAAKo"] [Tue Aug 18 13:02:52.626906 2026] [security2:error] [pid 139043:tid 139219] [client 68.155.154.236:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlFAAAALM"] [Tue Aug 18 13:02:52.656739 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:30833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/special.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlFgAAAQE"] [Tue Aug 18 13:02:52.660927 2026] [security2:error] [pid 123784:tid 123924] [client 20.51.153.15:9747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/45.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXuQAAAAY"] [Tue Aug 18 13:02:52.712372 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:52.712628 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:52.723817 2026] [security2:error] [pid 139043:tid 139188] [client 20.25.139.174:2431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/nw.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlGgAAAJQ"] [Tue Aug 18 13:02:52.733870 2026] [security2:error] [pid 139043:tid 139260] [client 20.251.112.238:39935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/mga.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlGwAAANw"] [Tue Aug 18 13:02:52.735879 2026] [security2:error] [pid 139043:tid 139230] [client 20.65.105.233:12573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/pp.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlHAAAAL4"] [Tue Aug 18 13:02:52.744028 2026] [security2:error] [pid 139043:tid 139277] [client 172.182.217.32:21886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/images//about.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlHQAAAO0"] [Tue Aug 18 13:02:52.799043 2026] [security2:error] [pid 123784:tid 123920] [client 20.151.109.219:21916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/av.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXvAAAAAI"] [Tue Aug 18 13:02:52.802322 2026] [security2:error] [pid 139043:tid 139282] [client 20.80.111.3:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlHwAAAPI"] [Tue Aug 18 13:02:52.847107 2026] [security2:error] [pid 139043:tid 139226] [client 213.35.127.232:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlIAAAALo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:52.868093 2026] [security2:error] [pid 139043:tid 139294] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/zwq13.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlIQAAAP4"] [Tue Aug 18 13:02:52.894195 2026] [security2:error] [pid 139043:tid 139262] [client 20.65.69.59:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lw.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlIgAAAN4"] [Tue Aug 18 13:02:52.945670 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/Okxob.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXwAAAAFA"] [Tue Aug 18 13:02:52.966672 2026] [security2:error] [pid 139043:tid 139275] [client 40.74.65.169:44168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/xiugai.php"] [unique_id "aoSCLP2v-lWn9OzQT7UlJQAAAOs"] [Tue Aug 18 13:02:52.975572 2026] [security2:error] [pid 123784:tid 123929] [client 20.65.105.233:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wqqs.php"] [unique_id "aoSCLGwDnJBNj2tDbYYXwgAAAAs"] [Tue Aug 18 13:02:53.016063 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.016484 2026] [authz_core:error] [pid 123784:tid 123872] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.080125 2026] [security2:error] [pid 139043:tid 139298] [client 4.223.113.180:39320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/x.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlJwAAAQI"] [Tue Aug 18 13:02:53.081509 2026] [security2:error] [pid 139043:tid 139254] [client 40.74.65.169:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/blurbs.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlKAAAANY"] [Tue Aug 18 13:02:53.095364 2026] [authz_core:error] [pid 123784:tid 124029] [client 192.178.4.133:47237] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.095632 2026] [authz_core:error] [pid 123784:tid 124029] [client 192.178.4.133:47237] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.098973 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:33459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mandrill.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlKQAAANI"] [Tue Aug 18 13:02:53.148614 2026] [security2:error] [pid 139043:tid 139193] [client 20.51.153.15:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wy.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlKgAAAJk"] [Tue Aug 18 13:02:53.153493 2026] [security2:error] [pid 123784:tid 124041] [client 20.251.112.238:46080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/fs.php"] [unique_id "aoSCLWwDnJBNj2tDbYYXxwAAAHs"] [Tue Aug 18 13:02:53.164903 2026] [security2:error] [pid 139043:tid 139205] [client 158.23.17.4:44512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fs.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlKwAAAKU"] [Tue Aug 18 13:02:53.176483 2026] [security2:error] [pid 139043:tid 139279] [client 172.182.200.96:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlLAAAAO8"] [Tue Aug 18 13:02:53.215991 2026] [security2:error] [pid 139043:tid 139202] [client 20.65.105.233:12755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/clasa99.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlLQAAAKI"] [Tue Aug 18 13:02:53.233953 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/images/crystal//index.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlLgAAAMg"] [Tue Aug 18 13:02:53.265291 2026] [security2:error] [pid 139043:tid 139245] [client 20.25.139.174:2415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/xleet.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlMAAAAM0"] [Tue Aug 18 13:02:53.294179 2026] [security2:error] [pid 139043:tid 139177] [client 20.65.69.59:9678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vj.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlMgAAAIk"] [Tue Aug 18 13:02:53.314941 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.315466 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.361622 2026] [security2:error] [pid 139043:tid 139280] [client 20.250.13.23:3420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ssjpxze.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlMwAAAPA"] [Tue Aug 18 13:02:53.396171 2026] [security2:error] [pid 139043:tid 139189] [client 20.51.153.15:9737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/f.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlNAAAAJU"] [Tue Aug 18 13:02:53.428752 2026] [security2:error] [pid 139043:tid 139175] [client 20.116.17.175:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/8.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlNQAAAIc"] [Tue Aug 18 13:02:53.441735 2026] [security2:error] [pid 123784:tid 124021] [client 158.23.17.4:54776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ib.php"] [unique_id "aoSCLWwDnJBNj2tDbYYXzwAAAGc"] [Tue Aug 18 13:02:53.444237 2026] [security2:error] [pid 139043:tid 139190] [client 20.80.111.3:12577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/post-types-order/compatibility/themes/db-status.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlNwAAAJY"] [Tue Aug 18 13:02:53.454690 2026] [security2:error] [pid 123784:tid 123973] [client 20.65.105.233:12468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/666.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX0AAAADc"] [Tue Aug 18 13:02:53.500175 2026] [security2:error] [pid 123784:tid 124044] [client 20.118.133.132:41083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX0QAAAH4"] [Tue Aug 18 13:02:53.566374 2026] [security2:error] [pid 139043:tid 139291] [client 20.251.112.238:29265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/wp-tem.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlOgAAAPs"] [Tue Aug 18 13:02:53.616020 2026] [security2:error] [pid 139043:tid 139203] [client 20.79.204.6:9664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/admin.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlOwAAAKM"] [Tue Aug 18 13:02:53.618962 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.619397 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.651957 2026] [security2:error] [pid 139043:tid 139206] [client 20.65.69.59:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mimes.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlPAAAAKY"] [Tue Aug 18 13:02:53.661198 2026] [security2:error] [pid 139043:tid 139251] [client 40.74.65.169:44166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/wp-load.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlPQAAANM"] [Tue Aug 18 13:02:53.671825 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.200.96:15726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX2QAAAAo"] [Tue Aug 18 13:02:53.696653 2026] [security2:error] [pid 123784:tid 123931] [client 20.51.153.15:9545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/30.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX2wAAAA0"] [Tue Aug 18 13:02:53.698199 2026] [security2:error] [pid 139043:tid 139192] [client 20.65.105.233:12592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/thui.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlPgAAAJg"] [Tue Aug 18 13:02:53.699573 2026] [security2:error] [pid 123784:tid 123940] [client 4.232.151.198:39227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/as.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX3AAAABY"] [Tue Aug 18 13:02:53.718491 2026] [security2:error] [pid 123784:tid 124035] [client 20.116.17.175:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/as.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX3QAAAHU"] [Tue Aug 18 13:02:53.725906 2026] [security2:error] [pid 139043:tid 139273] [client 172.182.217.32:21834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp//index.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlPwAAAOk"] [Tue Aug 18 13:02:53.735599 2026] [authz_core:error] [pid 139043:tid 139232] [client 192.178.4.133:37024] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.735905 2026] [authz_core:error] [pid 139043:tid 139232] [client 192.178.4.133:37024] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.772420 2026] [security2:error] [pid 139043:tid 139173] [client 20.151.109.219:21890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ag.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlQQAAAIU"] [Tue Aug 18 13:02:53.784331 2026] [security2:error] [pid 123784:tid 123959] [client 40.74.65.169:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/bajah.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX3wAAACk"] [Tue Aug 18 13:02:53.818606 2026] [security2:error] [pid 139043:tid 139176] [client 20.25.139.174:2205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlQgAAAIg"] [Tue Aug 18 13:02:53.845840 2026] [security2:error] [pid 139043:tid 139187] [client 68.155.154.236:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlRAAAAJM"] [Tue Aug 18 13:02:53.869988 2026] [security2:error] [pid 139043:tid 139174] [client 213.35.127.232:57254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlRQAAAIY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:53.874007 2026] [security2:error] [pid 139043:tid 139249] [client 34.156.195.117:38820] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCLf2v-lWn9OzQT7UlRgAAANE"] [Tue Aug 18 13:02:53.899208 2026] [security2:error] [pid 123784:tid 124001] [client 20.80.111.3:1425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/post.php"] [unique_id "aoSCLWwDnJBNj2tDbYYX4QAAAFM"] [Tue Aug 18 13:02:53.915211 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:53.915477 2026] [authz_core:error] [pid 123784:tid 123833] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:53.922003 2026] [security2:error] [pid 139043:tid 139227] [client 34.156.195.117:38834] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCLf2v-lWn9OzQT7UlRwAAALs"] [Tue Aug 18 13:02:53.929454 2026] [security2:error] [pid 139043:tid 139230] [client 168.62.48.100:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlSAAAAL4"] [Tue Aug 18 13:02:53.938664 2026] [security2:error] [pid 139043:tid 139277] [client 20.65.105.233:12587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/agg.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlSQAAAO0"] [Tue Aug 18 13:02:53.965369 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.73.37:29971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/puc.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlSgAAALw"] [Tue Aug 18 13:02:53.973226 2026] [security2:error] [pid 139043:tid 139286] [client 20.65.69.59:5420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ni.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlSwAAAPY"] [Tue Aug 18 13:02:53.986296 2026] [security2:error] [pid 139043:tid 139287] [client 20.251.112.238:22173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/sadd.php"] [unique_id "aoSCLf2v-lWn9OzQT7UlTAAAAPc"] [Tue Aug 18 13:02:54.037059 2026] [security2:error] [pid 139043:tid 139266] [client 20.250.13.23:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/storage/index.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlTQAAAOI"] [Tue Aug 18 13:02:54.062203 2026] [autoindex:error] [pid 139043:tid 139241] [client 205.169.39.48:37921] AH01276: Cannot serve directory /home3/reciclagem01/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:54.073614 2026] [security2:error] [pid 123784:tid 123968] [client 158.23.17.4:9379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/rb.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX5gAAADI"] [Tue Aug 18 13:02:54.076450 2026] [security2:error] [pid 139043:tid 139263] [client 20.51.153.15:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pu.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlTwAAAN8"] [Tue Aug 18 13:02:54.093178 2026] [security2:error] [pid 139043:tid 139233] [client 132.196.30.78:5428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/function/function.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlUQAAAME"] [Tue Aug 18 13:02:54.098293 2026] [security2:error] [pid 139043:tid 139222] [client 158.23.17.4:33984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/main.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlUgAAALY"] [Tue Aug 18 13:02:54.115578 2026] [security2:error] [pid 123784:tid 124015] [client 216.244.66.243:52846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jclareteimoveis.com.br"] [uri "/mega+hd+50-2/"] [unique_id "aoSCLmwDnJBNj2tDbYYX5wAAAGE"] [Tue Aug 18 13:02:54.115689 2026] [security2:error] [pid 123784:tid 124015] [client 216.244.66.243:52846] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jclareteimoveis.com.br"] [uri "/mega+hd+50-2/"] [unique_id "aoSCLmwDnJBNj2tDbYYX5wAAAGE"] [Tue Aug 18 13:02:54.150175 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/file59.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlUwAAAMI"] [Tue Aug 18 13:02:54.157959 2026] [security2:error] [pid 139043:tid 139213] [client 34.156.195.117:38840] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCLv2v-lWn9OzQT7UlVAAAAK0"] [Tue Aug 18 13:02:54.178685 2026] [security2:error] [pid 139043:tid 139268] [client 20.65.105.233:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/erty.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlVgAAAOQ"] [Tue Aug 18 13:02:54.187607 2026] [security2:error] [pid 139043:tid 139221] [client 20.116.17.175:22915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/images.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlVwAAALU"] [Tue Aug 18 13:02:54.214036 2026] [security2:error] [pid 139043:tid 139298] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/eauu.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlWAAAAQI"] [Tue Aug 18 13:02:54.215848 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:54.216109 2026] [authz_core:error] [pid 123784:tid 123790] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:54.220028 2026] [security2:error] [pid 139043:tid 139276] [client 172.182.217.32:21847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/user.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlWQAAAOw"] [Tue Aug 18 13:02:54.262983 2026] [security2:error] [pid 139043:tid 139300] [client 20.65.69.59:5738] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rbrgestaofinanceira.com.br"] [uri "/1.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlXQAAAQQ"] [Tue Aug 18 13:02:54.263102 2026] [security2:error] [pid 139043:tid 139300] [client 20.65.69.59:5738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/1.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlXQAAAQQ"] [Tue Aug 18 13:02:54.273392 2026] [security2:error] [pid 139043:tid 139245] [client 172.182.200.96:15650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlXgAAAM0"] [Tue Aug 18 13:02:54.320206 2026] [security2:error] [pid 123784:tid 123946] [client 20.51.153.15:9782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ry.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX7AAAABw"] [Tue Aug 18 13:02:54.324003 2026] [security2:error] [pid 139043:tid 139177] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlXwAAiWo"] [Tue Aug 18 13:02:54.337172 2026] [security2:error] [pid 139043:tid 139229] [client 40.74.65.169:44232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/155.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlYAAAAL0"] [Tue Aug 18 13:02:54.344465 2026] [security2:error] [pid 123784:tid 123999] [client 20.80.111.3:1434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/simply-gallery-block/plugins/ms-files.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX7QAAAFE"] [Tue Aug 18 13:02:54.395895 2026] [security2:error] [pid 139043:tid 139218] [client 20.251.112.238:63831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ex.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlYgAAALI"] [Tue Aug 18 13:02:54.410466 2026] [security2:error] [pid 123784:tid 123965] [client 86.120.159.145:16201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX7wAAAC8"] [Tue Aug 18 13:02:54.410583 2026] [security2:error] [pid 123784:tid 123965] [client 86.120.159.145:16201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX7wAAAC8"] [Tue Aug 18 13:02:54.418751 2026] [security2:error] [pid 139043:tid 139225] [client 20.65.105.233:13125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/mini.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlYwAAALk"] [Tue Aug 18 13:02:54.421866 2026] [security2:error] [pid 139043:tid 139244] [client 20.25.139.174:2211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/155.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlZAAAAMw"] [Tue Aug 18 13:02:54.460147 2026] [security2:error] [pid 139043:tid 139264] [client 40.74.65.169:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/domvf.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlZwAAAOA"] [Tue Aug 18 13:02:54.515841 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:54.516092 2026] [authz_core:error] [pid 123784:tid 123895] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:54.560652 2026] [security2:error] [pid 139043:tid 139267] [client 20.51.153.15:9734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pm.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlaAAAAOM"] [Tue Aug 18 13:02:54.568051 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.154.236:45842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlaQAAAKw"] [Tue Aug 18 13:02:54.609384 2026] [security2:error] [pid 123784:tid 124012] [client 20.65.69.59:5434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/88.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX9AAAAF4"] [Tue Aug 18 13:02:54.658480 2026] [security2:error] [pid 123784:tid 124020] [client 20.65.105.233:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sid3.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX9gAAAGY"] [Tue Aug 18 13:02:54.661033 2026] [security2:error] [pid 123784:tid 123921] [client 20.250.13.23:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/storage/rip.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX9wAAAAM"] [Tue Aug 18 13:02:54.667382 2026] [security2:error] [pid 139043:tid 139257] [client 158.23.17.4:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/37.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlawAAANk"] [Tue Aug 18 13:02:54.674926 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:13782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ig.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlbQAAAPk"] [Tue Aug 18 13:02:54.710016 2026] [security2:error] [pid 139043:tid 139189] [client 172.182.217.32:21853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlbgAAAJU"] [Tue Aug 18 13:02:54.734694 2026] [security2:error] [pid 123784:tid 124011] [client 172.182.200.96:15675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX-QAAAF0"] [Tue Aug 18 13:02:54.736620 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/dsd.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlbwAAAI8"] [Tue Aug 18 13:02:54.788494 2026] [security2:error] [pid 123784:tid 123953] [client 20.80.111.3:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/softaculous-pro/assets/images/plugins/plugin-install.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX_AAAACM"] [Tue Aug 18 13:02:54.799045 2026] [security2:error] [pid 123784:tid 124033] [client 52.173.121.69:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCLmwDnJBNj2tDbYYX_QAAAHM"] [Tue Aug 18 13:02:54.810034 2026] [security2:error] [pid 139043:tid 139293] [client 20.251.112.238:23370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/tax.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlcQAAAP0"] [Tue Aug 18 13:02:54.818173 2026] [authz_core:error] [pid 123784:tid 123914] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:54.818455 2026] [authz_core:error] [pid 123784:tid 123914] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:54.854245 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:38335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ga.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlcgAAAKY"] [Tue Aug 18 13:02:54.888481 2026] [security2:error] [pid 139043:tid 139180] [client 213.35.127.232:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCLv2v-lWn9OzQT7UldQAAAIw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:54.890756 2026] [security2:error] [pid 123784:tid 124037] [client 20.116.17.175:53181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/pucci.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYAAAAAHc"] [Tue Aug 18 13:02:54.898653 2026] [security2:error] [pid 123784:tid 123997] [client 20.65.105.233:12582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/moon.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYAQAAAE8"] [Tue Aug 18 13:02:54.984187 2026] [security2:error] [pid 123784:tid 123990] [client 4.223.113.180:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/filemanager.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYBQAAAEg"] [Tue Aug 18 13:02:54.985044 2026] [fcgid:warn] [pid 123784:tid 123957] (70014)End of file found: [client 167.94.146.56:64276] mod_fcgid: can't get data from http client [Tue Aug 18 13:02:54.985604 2026] [security2:error] [pid 123784:tid 124023] [client 20.65.69.59:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/hj.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYBwAAAGk"] [Tue Aug 18 13:02:54.988640 2026] [security2:error] [pid 123784:tid 123962] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/c4.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYCAAAACw"] [Tue Aug 18 13:02:54.989890 2026] [security2:error] [pid 139043:tid 139203] [client 20.25.139.174:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/96i.php"] [unique_id "aoSCLv2v-lWn9OzQT7UlegAAAKM"] [Tue Aug 18 13:02:54.998293 2026] [security2:error] [pid 123784:tid 123996] [client 4.232.151.198:22269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/backup.php"] [unique_id "aoSCLmwDnJBNj2tDbYYYCQAAAE4"] [Tue Aug 18 13:02:55.028334 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:60753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xm.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYCgAAADU"] [Tue Aug 18 13:02:55.029050 2026] [security2:error] [pid 139043:tid 139231] [client 20.51.153.15:9802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/dr.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlewAAAL8"] [Tue Aug 18 13:02:55.042510 2026] [security2:error] [pid 139043:tid 139197] [client 40.74.65.169:44184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/index.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlfAAAAJ0"] [Tue Aug 18 13:02:55.139938 2026] [security2:error] [pid 139043:tid 139284] [client 20.65.105.233:12473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ms.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlfQAAAPQ"] [Tue Aug 18 13:02:55.145070 2026] [security2:error] [pid 123784:tid 123939] [client 40.74.65.169:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/fpwch.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYEAAAABU"] [Tue Aug 18 13:02:55.171662 2026] [security2:error] [pid 123784:tid 123963] [client 4.232.151.198:24865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/min.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYEQAAAC0"] [Tue Aug 18 13:02:55.197662 2026] [security2:error] [pid 139043:tid 139237] [client 20.116.17.175:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/a.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlgAAAAMU"] [Tue Aug 18 13:02:55.206419 2026] [security2:error] [pid 139043:tid 139258] [client 172.182.217.32:21547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/functions.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlgQAAANo"] [Tue Aug 18 13:02:55.215201 2026] [security2:error] [pid 139043:tid 139195] [client 34.156.195.117:38844] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCL_2v-lWn9OzQT7UlggAAAJs"] [Tue Aug 18 13:02:55.245881 2026] [security2:error] [pid 139043:tid 139261] [client 20.80.111.3:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/updraftplus/templates/wp-admin/options.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlgwAAAN0"] [Tue Aug 18 13:02:55.261737 2026] [security2:error] [pid 139043:tid 139207] [client 20.251.112.238:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/X7x.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlhAAAAKc"] [Tue Aug 18 13:02:55.266533 2026] [security2:error] [pid 123784:tid 124006] [client 20.51.153.15:9848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ts.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYEwAAAFg"] [Tue Aug 18 13:02:55.291165 2026] [security2:error] [pid 123784:tid 123954] [client 20.79.204.6:9295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/goods.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYFAAAACQ"] [Tue Aug 18 13:02:55.305596 2026] [security2:error] [pid 139043:tid 139241] [client 132.196.30.78:25843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-signin.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlhQAAAMk"] [Tue Aug 18 13:02:55.327402 2026] [security2:error] [pid 139043:tid 139190] [client 34.156.195.117:38852] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCL_2v-lWn9OzQT7UlhgAAAJY"] [Tue Aug 18 13:02:55.331653 2026] [security2:error] [pid 139043:tid 139259] [client 172.182.200.96:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlhwAAANs"] [Tue Aug 18 13:02:55.371154 2026] [security2:error] [pid 123784:tid 123925] [client 20.250.13.23:3418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/sts.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYFgAAAAc"] [Tue Aug 18 13:02:55.380244 2026] [security2:error] [pid 139043:tid 139222] [client 158.23.17.4:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/md.php"] [unique_id "aoSCL_2v-lWn9OzQT7UliAAAALY"] [Tue Aug 18 13:02:55.380323 2026] [security2:error] [pid 139043:tid 139239] [client 20.65.105.233:13166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wsws.php"] [unique_id "aoSCL_2v-lWn9OzQT7UliQAAAMc"] [Tue Aug 18 13:02:55.410161 2026] [security2:error] [pid 139043:tid 139275] [client 20.65.69.59:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ij.php"] [unique_id "aoSCL_2v-lWn9OzQT7UligAAAOs"] [Tue Aug 18 13:02:55.418828 2026] [security2:error] [pid 139043:tid 139226] [client 4.232.151.198:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSCL_2v-lWn9OzQT7UliwAAALo"] [Tue Aug 18 13:02:55.420353 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:55.420626 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:55.564730 2026] [security2:error] [pid 139043:tid 139279] [client 158.23.17.4:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/wb.php"] [unique_id "aoSCL_2v-lWn9OzQT7UljQAAAO8"] [Tue Aug 18 13:02:55.565282 2026] [security2:error] [pid 139043:tid 139194] [client 213.202.253.4:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCL_2v-lWn9OzQT7UljgAAAJo"], referer: www.google.com [Tue Aug 18 13:02:55.581035 2026] [security2:error] [pid 139043:tid 139274] [client 20.25.139.174:2268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/as.php"] [unique_id "aoSCL_2v-lWn9OzQT7UljwAAAOo"] [Tue Aug 18 13:02:55.588856 2026] [security2:error] [pid 123784:tid 124016] [client 20.51.153.15:9756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/53.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYHAAAAGI"] [Tue Aug 18 13:02:55.616519 2026] [security2:error] [pid 123784:tid 123927] [client 20.116.17.175:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYHgAAAAk"] [Tue Aug 18 13:02:55.632334 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.105.233:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/motu.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYHwAAAH4"] [Tue Aug 18 13:02:55.663048 2026] [security2:error] [pid 139043:tid 139280] [client 20.251.112.238:16972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ocxla.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlkgAAAPA"] [Tue Aug 18 13:02:55.672856 2026] [security2:error] [pid 139043:tid 139199] [client 20.65.69.59:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ud.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlkwAAAJ8"] [Tue Aug 18 13:02:55.689833 2026] [security2:error] [pid 139043:tid 139250] [client 20.80.111.3:30040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/admin.php"] [unique_id "aoSCL_2v-lWn9OzQT7UllAAAANI"] [Tue Aug 18 13:02:55.705972 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.217.32:21865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cron.php"] [unique_id "aoSCL_2v-lWn9OzQT7UllgAAANA"] [Tue Aug 18 13:02:55.706110 2026] [security2:error] [pid 139043:tid 139289] [client 172.182.200.96:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/update/wpupex.php"] [unique_id "aoSCL_2v-lWn9OzQT7UllQAAAPk"] [Tue Aug 18 13:02:55.714954 2026] [security2:error] [pid 123784:tid 123878] [remote 216.73.216.206:7861] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "bioarquitetar.com"] [uri "/"] [unique_id "aoSCL2wDnJBNj2tDbYYYIwAAIVk"] [Tue Aug 18 13:02:55.737750 2026] [security2:error] [pid 123784:tid 124001] [client 40.74.65.169:38412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/aaa.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYJAAAAFM"] [Tue Aug 18 13:02:55.776859 2026] [security2:error] [pid 123784:tid 123948] [client 20.251.48.93:37415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/file1221.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYJQAAAB4"] [Tue Aug 18 13:02:55.803673 2026] [security2:error] [pid 139043:tid 139223] [client 168.62.48.100:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-2019.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlmAAAALc"] [Tue Aug 18 13:02:55.828394 2026] [security2:error] [pid 139043:tid 139206] [client 40.74.65.169:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/adminner.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlmQAAAKY"] [Tue Aug 18 13:02:55.872877 2026] [security2:error] [pid 139043:tid 139236] [client 20.65.105.233:12460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fff.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlmgAAAMQ"] [Tue Aug 18 13:02:55.905104 2026] [security2:error] [pid 139043:tid 139205] [client 213.35.127.232:57714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCL_2v-lWn9OzQT7UlmwAAAKU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:55.930992 2026] [security2:error] [pid 123784:tid 124009] [client 20.51.153.15:9798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lq.php"] [unique_id "aoSCL2wDnJBNj2tDbYYYKwAAAFs"] [Tue Aug 18 13:02:55.985440 2026] [security2:error] [pid 123784:tid 123815] [remote 2400:6180:0:d2:0:2:f943:8000:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arsenalimoveis.com.br"] [uri "/"] [unique_id "aoSCL2wDnJBNj2tDbYYYLgAAURo"] [Tue Aug 18 13:02:56.026179 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:56.026632 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:56.033256 2026] [security2:error] [pid 139043:tid 139293] [client 20.250.13.23:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/system_log.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlnAAAAP0"] [Tue Aug 18 13:02:56.033710 2026] [security2:error] [pid 139043:tid 139187] [client 20.65.69.59:5748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ip.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlnQAAAJM"] [Tue Aug 18 13:02:56.043263 2026] [security2:error] [pid 139043:tid 139288] [client 4.232.151.198:24782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/sx.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlngAAAPg"] [Tue Aug 18 13:02:56.099146 2026] [security2:error] [pid 139043:tid 139203] [client 20.25.139.174:2388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/min.php"] [unique_id "aoSCMP2v-lWn9OzQT7UloAAAAKM"] [Tue Aug 18 13:02:56.114226 2026] [security2:error] [pid 139043:tid 139211] [client 20.65.105.233:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/66.php"] [unique_id "aoSCMP2v-lWn9OzQT7UloQAAAKs"] [Tue Aug 18 13:02:56.123126 2026] [security2:error] [pid 123784:tid 124018] [client 20.251.112.238:23405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/post.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYMgAAAGQ"] [Tue Aug 18 13:02:56.128787 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/iy.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlogAAAIY"] [Tue Aug 18 13:02:56.147014 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:34123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/xn.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlpAAAANE"] [Tue Aug 18 13:02:56.149878 2026] [security2:error] [pid 123784:tid 124014] [client 20.80.111.3:30026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/maintenance.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYNAAAAGA"] [Tue Aug 18 13:02:56.193524 2026] [security2:error] [pid 139043:tid 139176] [client 172.182.217.32:21827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlpQAAAIg"] [Tue Aug 18 13:02:56.212458 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/an7.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYNgAAAFY"] [Tue Aug 18 13:02:56.233343 2026] [security2:error] [pid 139043:tid 139230] [client 20.116.17.175:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/99.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlpwAAAL4"] [Tue Aug 18 13:02:56.268080 2026] [security2:error] [pid 123784:tid 123952] [client 20.151.109.219:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ta.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYOwAAACI"] [Tue Aug 18 13:02:56.273021 2026] [security2:error] [pid 123784:tid 123959] [client 34.156.195.117:62806] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/job/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYPgAAACk"] [Tue Aug 18 13:02:56.273586 2026] [security2:error] [pid 139043:tid 139254] [client 34.156.195.117:62776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/jenkins/config.xml.bak"] [unique_id "aoSCMP2v-lWn9OzQT7UlrAAAANY"] [Tue Aug 18 13:02:56.273601 2026] [security2:error] [pid 139043:tid 139244] [client 34.156.195.117:63132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.yml"] [unique_id "aoSCMP2v-lWn9OzQT7UlsAAAAMw"] [Tue Aug 18 13:02:56.273705 2026] [security2:error] [pid 123784:tid 123940] [client 34.156.195.117:62768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/jenkins/Jenkinsfile"] [unique_id "aoSCMGwDnJBNj2tDbYYYQAAAABY"] [Tue Aug 18 13:02:56.274470 2026] [security2:error] [pid 123784:tid 123931] [client 34.156.195.117:62878] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/cloudbuild.yaml"] [unique_id "aoSCMGwDnJBNj2tDbYYYQQAAAA0"] [Tue Aug 18 13:02:56.274526 2026] [security2:error] [pid 139043:tid 139201] [client 34.156.195.117:63018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.production.bak"] [unique_id "aoSCMP2v-lWn9OzQT7UlrwAAAKE"] [Tue Aug 18 13:02:56.275138 2026] [security2:error] [pid 123784:tid 123937] [client 34.156.195.117:62918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.github/workflows/test.yml"] [unique_id "aoSCMGwDnJBNj2tDbYYYQwAAABM"] [Tue Aug 18 13:02:56.275396 2026] [security2:error] [pid 139043:tid 139185] [client 34.156.195.117:62680] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/home/gitlab-runner/.aws/credentials"] [unique_id "aoSCMP2v-lWn9OzQT7UlswAAAJE"] [Tue Aug 18 13:02:56.278935 2026] [security2:error] [pid 123784:tid 123969] [client 34.156.195.117:63064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/var/www/html/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYRQAAADM"] [Tue Aug 18 13:02:56.278995 2026] [security2:error] [pid 139043:tid 139243] [client 34.156.195.117:62756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/jenkins/.env"] [unique_id "aoSCMP2v-lWn9OzQT7UluwAAAMs"] [Tue Aug 18 13:02:56.279901 2026] [security2:error] [pid 123784:tid 124019] [client 34.156.195.117:63094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.local.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYRAAAAGU"] [Tue Aug 18 13:02:56.286087 2026] [security2:error] [pid 139043:tid 139256] [client 34.156.195.117:63034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSCMP2v-lWn9OzQT7UlvwAAANg"] [Tue Aug 18 13:02:56.286135 2026] [security2:error] [pid 123784:tid 124007] [client 34.156.195.117:63090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYSQAAAFk"] [Tue Aug 18 13:02:56.286417 2026] [security2:error] [pid 139043:tid 139238] [client 34.156.195.117:63048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/var/www/.env"] [unique_id "aoSCMP2v-lWn9OzQT7UlvQAAAMY"] [Tue Aug 18 13:02:56.287210 2026] [security2:error] [pid 139043:tid 139214] [client 34.156.195.117:63004] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.production.local"] [unique_id "aoSCMP2v-lWn9OzQT7UlwQAAAK4"] [Tue Aug 18 13:02:56.321656 2026] [security2:error] [pid 139043:tid 139258] [client 172.182.200.96:15647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-admin/install.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlwwAAANo"] [Tue Aug 18 13:02:56.322800 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:56.323052 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:56.325148 2026] [autoindex:error] [pid 123784:tid 123934] [client 4.232.151.198:49093] AH01276: Cannot serve directory /home1/mabelinicom/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:56.354652 2026] [security2:error] [pid 139043:tid 139182] [client 20.65.105.233:12588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/g.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlxAAAAI4"] [Tue Aug 18 13:02:56.363596 2026] [security2:error] [pid 139043:tid 139261] [client 20.65.69.59:5382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/99.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlxgAAAN0"] [Tue Aug 18 13:02:56.376899 2026] [security2:error] [pid 139043:tid 139207] [client 20.51.153.15:9532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/you.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlxwAAAKc"] [Tue Aug 18 13:02:56.412406 2026] [security2:error] [pid 139043:tid 139190] [client 40.74.65.169:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlyAAAAJY"] [Tue Aug 18 13:02:56.454448 2026] [security2:error] [pid 139043:tid 139263] [client 20.251.48.93:14792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/nox.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlygAAAN8"] [Tue Aug 18 13:02:56.516355 2026] [security2:error] [pid 139043:tid 139216] [client 40.74.65.169:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/abcd.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlzAAAALA"] [Tue Aug 18 13:02:56.532301 2026] [security2:error] [pid 139043:tid 139268] [client 20.251.112.238:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/nhr.php"] [unique_id "aoSCMP2v-lWn9OzQT7UlzQAAAOQ"] [Tue Aug 18 13:02:56.533421 2026] [security2:error] [pid 123784:tid 123938] [client 4.232.151.198:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/php8.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYUgAAABQ"] [Tue Aug 18 13:02:56.594280 2026] [security2:error] [pid 123784:tid 123918] [client 20.65.105.233:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/x7.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYVAAAAAA"] [Tue Aug 18 13:02:56.624610 2026] [security2:error] [pid 139043:tid 139298] [client 20.51.153.15:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ez.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul0AAAAQI"] [Tue Aug 18 13:02:56.630468 2026] [security2:error] [pid 139043:tid 139222] [client 20.80.111.3:39892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/module.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul0QAAALY"] [Tue Aug 18 13:02:56.658921 2026] [autoindex:error] [pid 123784:tid 123976] [client 20.25.139.174:2396] AH01276: Cannot serve directory /home1/gfrison965/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:56.672481 2026] [security2:error] [pid 139043:tid 139217] [client 4.232.151.198:24795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/st.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul0gAAALE"] [Tue Aug 18 13:02:56.684094 2026] [security2:error] [pid 123784:tid 124037] [client 172.182.217.32:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cookie.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYWQAAAHc"] [Tue Aug 18 13:02:56.686409 2026] [security2:error] [pid 139043:tid 139276] [client 68.155.154.236:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul0wAAAOw"] [Tue Aug 18 13:02:56.734126 2026] [security2:error] [pid 139043:tid 139194] [client 20.65.69.59:27871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/er.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul1QAAAJo"] [Tue Aug 18 13:02:56.790605 2026] [security2:error] [pid 123784:tid 123924] [client 158.23.17.4:32515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/47.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYXQAAAAY"] [Tue Aug 18 13:02:56.810940 2026] [security2:error] [pid 139043:tid 139283] [client 20.250.13.23:3427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/t.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul1wAAAPM"] [Tue Aug 18 13:02:56.833243 2026] [security2:error] [pid 123784:tid 123947] [client 34.156.195.117:62990] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/fetch"] [unique_id "aoSCMGwDnJBNj2tDbYYYXwAAAB0"] [Tue Aug 18 13:02:56.833394 2026] [security2:error] [pid 139043:tid 139280] [client 20.65.105.233:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/god.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul2AAAAPA"] [Tue Aug 18 13:02:56.833758 2026] [security2:error] [pid 123784:tid 123971] [client 20.25.139.174:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/php8.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYYAAAADU"] [Tue Aug 18 13:02:56.835137 2026] [security2:error] [pid 123784:tid 123942] [client 34.156.195.117:62672] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/proxy"] [unique_id "aoSCMGwDnJBNj2tDbYYYYQAAABg"] [Tue Aug 18 13:02:56.862653 2026] [security2:error] [pid 139043:tid 139252] [client 172.182.200.96:15724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul2gAAANQ"] [Tue Aug 18 13:02:56.867874 2026] [security2:error] [pid 123784:tid 123960] [client 20.51.153.15:9582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/asus.php"] [unique_id "aoSCMGwDnJBNj2tDbYYYYgAAACo"] [Tue Aug 18 13:02:56.896247 2026] [security2:error] [pid 139043:tid 139204] [client 34.156.195.117:62776] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/%2eenv"] [unique_id "aoSCMP2v-lWn9OzQT7Ul2wAAAKQ"] [Tue Aug 18 13:02:56.896910 2026] [security2:error] [pid 139043:tid 139223] [client 34.156.195.117:63012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/.netlify/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul3AAAALc"] [Tue Aug 18 13:02:56.899594 2026] [security2:error] [pid 139043:tid 139180] [client 34.156.195.117:62790] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSCMP2v-lWn9OzQT7Ul3wAAAIw"] [Tue Aug 18 13:02:56.899643 2026] [security2:error] [pid 139043:tid 139206] [client 34.156.195.117:62892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/supabase/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul3QAAAKY"] [Tue Aug 18 13:02:56.899739 2026] [core:error] [pid 123784:tid 123926] [client 34.156.195.117:62826] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../.env) [Tue Aug 18 13:02:56.899948 2026] [core:error] [pid 123784:tid 123972] [client 34.156.195.117:62944] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 13:02:56.900068 2026] [core:error] [pid 139043:tid 139273] [client 34.156.195.117:62820] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:02:56.900164 2026] [security2:error] [pid 139043:tid 139251] [client 34.156.195.117:62828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.supabase/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul3gAAANM"] [Tue Aug 18 13:02:56.909389 2026] [security2:error] [pid 139043:tid 139220] [client 34.156.195.117:62858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/client/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul4QAAALQ"] [Tue Aug 18 13:02:56.917478 2026] [security2:error] [pid 139043:tid 139226] [client 213.35.127.232:57945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul4gAAALo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:56.925041 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:56.925358 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:56.926068 2026] [security2:error] [pid 139043:tid 139205] [client 158.23.17.4:9330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/og.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul4wAAAKU"] [Tue Aug 18 13:02:56.942806 2026] [security2:error] [pid 123784:tid 124022] [client 34.156.195.117:62720] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSCMGwDnJBNj2tDbYYYaQAAAGg"] [Tue Aug 18 13:02:56.942992 2026] [security2:error] [pid 139043:tid 139219] [client 20.251.112.238:63819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul5AAAALM"] [Tue Aug 18 13:02:56.946440 2026] [security2:error] [pid 123784:tid 123930] [client 34.156.195.117:62732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/..;/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYawAAAAw"] [Tue Aug 18 13:02:56.946731 2026] [security2:error] [pid 139043:tid 139187] [client 34.156.195.117:62756] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/api/..;/actuator/env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul6QAAAJM"] [Tue Aug 18 13:02:56.948194 2026] [security2:error] [pid 139043:tid 139191] [client 34.156.195.117:62744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.orig"] [unique_id "aoSCMP2v-lWn9OzQT7Ul6gAAAJc"] [Tue Aug 18 13:02:56.953207 2026] [security2:error] [pid 139043:tid 139174] [client 34.156.195.117:63104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/private/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul7QAAAIY"] [Tue Aug 18 13:02:56.965657 2026] [security2:error] [pid 123784:tid 123958] [client 34.156.195.117:62982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/frontend/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYcAAAACg"] [Tue Aug 18 13:02:56.965740 2026] [security2:error] [pid 123784:tid 123989] [client 34.156.195.117:63116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/internal/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYcQAAAEc"] [Tue Aug 18 13:02:56.966085 2026] [security2:error] [pid 139043:tid 139196] [client 34.156.195.117:62872] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/production/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul7gAAAJw"] [Tue Aug 18 13:02:56.971669 2026] [security2:error] [pid 139043:tid 139227] [client 20.116.17.175:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wicked.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul7wAAALs"] [Tue Aug 18 13:02:56.974979 2026] [security2:error] [pid 139043:tid 139284] [client 34.156.195.117:63066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/development/.env"] [unique_id "aoSCMP2v-lWn9OzQT7Ul8AAAAPQ"] [Tue Aug 18 13:02:56.977947 2026] [security2:error] [pid 123784:tid 123944] [client 34.156.195.117:62698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/prod/.env"] [unique_id "aoSCMGwDnJBNj2tDbYYYcgAAABo"] [Tue Aug 18 13:02:57.049802 2026] [security2:error] [pid 123784:tid 124016] [client 20.65.69.59:27892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/qk.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYdAAAAGI"] [Tue Aug 18 13:02:57.072874 2026] [security2:error] [pid 139043:tid 139246] [client 20.65.105.233:12571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul8QAAAM4"] [Tue Aug 18 13:02:57.078904 2026] [security2:error] [pid 139043:tid 139236] [client 20.80.111.3:39891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/wp-super-cache/plugins/index.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul8gAAAMQ"] [Tue Aug 18 13:02:57.093439 2026] [security2:error] [pid 139043:tid 139286] [client 40.74.65.169:44191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/site.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul8wAAAPY"] [Tue Aug 18 13:02:57.146197 2026] [security2:error] [pid 139043:tid 139299] [client 20.79.204.6:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/file.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul9AAAAQM"] [Tue Aug 18 13:02:57.170636 2026] [security2:error] [pid 139043:tid 139292] [client 34.156.195.117:63048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/staging/.env"] [unique_id "aoSCMf2v-lWn9OzQT7Ul9QAAAPw"] [Tue Aug 18 13:02:57.173605 2026] [security2:error] [pid 123784:tid 124031] [client 20.51.153.15:9796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/22.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYfwAAAHE"] [Tue Aug 18 13:02:57.181083 2026] [security2:error] [pid 139043:tid 139230] [client 172.182.217.32:21882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/xleet.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul9gAAAL4"] [Tue Aug 18 13:02:57.191302 2026] [security2:error] [pid 139043:tid 139269] [client 34.156.195.117:62960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/dev/.env"] [unique_id "aoSCMf2v-lWn9OzQT7Ul9wAAAOU"] [Tue Aug 18 13:02:57.194553 2026] [security2:error] [pid 139043:tid 139285] [client 34.156.195.117:63076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/..%2F..%2F..%2F..%2F..%2F.env"] [unique_id "aoSCMf2v-lWn9OzQT7Ul-AAAAPU"] [Tue Aug 18 13:02:57.211788 2026] [security2:error] [pid 139043:tid 139265] [client 40.74.65.169:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/simple.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul-QAAAOE"] [Tue Aug 18 13:02:57.212541 2026] [security2:error] [pid 139043:tid 139270] [client 20.116.17.175:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/yup.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul-gAAAOY"] [Tue Aug 18 13:02:57.213699 2026] [security2:error] [pid 139043:tid 139209] [client 20.206.73.37:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/19.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul-wAAAKk"] [Tue Aug 18 13:02:57.215491 2026] [core:error] [pid 139043:tid 139243] [client 34.156.195.117:62846] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:02:57.226324 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:57.226581 2026] [authz_core:error] [pid 123784:tid 123827] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:57.296968 2026] [security2:error] [pid 139043:tid 139238] [client 172.182.200.96:15714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul_QAAAMY"] [Tue Aug 18 13:02:57.305620 2026] [security2:error] [pid 123784:tid 123982] [client 20.65.69.59:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYhAAAAEA"] [Tue Aug 18 13:02:57.311066 2026] [security2:error] [pid 139043:tid 139254] [client 4.232.151.198:22231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul_gAAANY"] [Tue Aug 18 13:02:57.338833 2026] [security2:error] [pid 139043:tid 139212] [client 20.65.105.233:12465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/8.php"] [unique_id "aoSCMf2v-lWn9OzQT7Ul_wAAAKw"] [Tue Aug 18 13:02:57.351777 2026] [security2:error] [pid 139043:tid 139294] [client 158.23.17.4:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zy.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmAAAAAP4"] [Tue Aug 18 13:02:57.354053 2026] [security2:error] [pid 139043:tid 139266] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/bsg-management/php.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmAQAAAOI"] [Tue Aug 18 13:02:57.371012 2026] [security2:error] [pid 139043:tid 139290] [client 20.251.112.238:46538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ws79.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmAgAAAPo"] [Tue Aug 18 13:02:57.373745 2026] [security2:error] [pid 139043:tid 139225] [client 20.25.139.174:2413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmAwAAALk"] [Tue Aug 18 13:02:57.456250 2026] [security2:error] [pid 139043:tid 139260] [client 20.51.153.15:9480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/zs.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmBQAAANw"] [Tue Aug 18 13:02:57.467498 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/byp8.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmBgAAAK0"] [Tue Aug 18 13:02:57.490065 2026] [security2:error] [pid 139043:tid 139245] [client 20.250.13.23:3438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/templates.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmBwAAAM0"] [Tue Aug 18 13:02:57.516202 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.151.198:43097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmCAAAANg"] [Tue Aug 18 13:02:57.527363 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:57.527623 2026] [authz_core:error] [pid 123784:tid 123817] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:57.578081 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/plugins.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYiwAAABw"] [Tue Aug 18 13:02:57.578382 2026] [security2:error] [pid 123784:tid 124032] [client 20.65.105.233:12452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/koiy.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYjAAAAHI"] [Tue Aug 18 13:02:57.581024 2026] [security2:error] [pid 139043:tid 139232] [client 158.23.17.4:8751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lp.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmCQAAAMA"] [Tue Aug 18 13:02:57.627185 2026] [security2:error] [pid 123784:tid 124001] [client 149.34.210.141:63617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYjgAAAFM"] [Tue Aug 18 13:02:57.646074 2026] [security2:error] [pid 139043:tid 139276] [client 20.65.69.59:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fs.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmCwAAAOw"] [Tue Aug 18 13:02:57.676589 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.217.32:21874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/spip.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmDQAAAJQ"] [Tue Aug 18 13:02:57.695060 2026] [security2:error] [pid 139043:tid 139194] [client 34.156.195.117:63076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/static/..;/.env"] [unique_id "aoSCMf2v-lWn9OzQT7UmDgAAAJo"] [Tue Aug 18 13:02:57.719169 2026] [security2:error] [pid 139043:tid 139274] [client 20.51.153.15:9785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/iz.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmDwAAAOo"] [Tue Aug 18 13:02:57.719836 2026] [security2:error] [pid 139043:tid 139235] [client 172.182.200.96:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmEAAAAMM"] [Tue Aug 18 13:02:57.728095 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYkAAAAGA"] [Tue Aug 18 13:02:57.784327 2026] [security2:error] [pid 139043:tid 139289] [client 20.80.111.3:1442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/style-engine/style-engine/ixr/plugins/wp-mail.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmEgAAAPk"] [Tue Aug 18 13:02:57.801623 2026] [security2:error] [pid 139043:tid 139189] [client 40.74.65.169:44201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/ccc.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmEwAAAJU"] [Tue Aug 18 13:02:57.814711 2026] [security2:error] [pid 139043:tid 139183] [client 20.118.133.132:56292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmFAAAAI8"] [Tue Aug 18 13:02:57.819955 2026] [security2:error] [pid 123784:tid 124045] [client 20.65.105.233:12569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/iko.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYlAAAAH8"] [Tue Aug 18 13:02:57.836955 2026] [security2:error] [pid 139043:tid 139204] [client 20.251.112.238:22182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/rtx.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmFgAAAKQ"] [Tue Aug 18 13:02:57.865735 2026] [security2:error] [pid 139043:tid 139192] [client 20.151.109.219:56005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/34.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmFwAAAJg"] [Tue Aug 18 13:02:57.892183 2026] [security2:error] [pid 123784:tid 124001] [client 149.34.210.141:63617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYjgAAAFM"] [Tue Aug 18 13:02:57.894495 2026] [autoindex:error] [pid 139043:tid 139206] [client 169.58.72.248:55838] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:57.897414 2026] [security2:error] [pid 139043:tid 139180] [client 40.74.65.169:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmGQAAAIw"] [Tue Aug 18 13:02:57.903755 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/100.kb.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYlgAAAGY"] [Tue Aug 18 13:02:57.929491 2026] [security2:error] [pid 139043:tid 139300] [client 4.232.151.198:10381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-configs.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmGgAAAQQ"] [Tue Aug 18 13:02:57.937810 2026] [security2:error] [pid 123784:tid 123988] [client 213.35.127.232:58165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCMWwDnJBNj2tDbYYYlwAAAEY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:57.946104 2026] [security2:error] [pid 123784:tid 123987] [client 34.156.195.117:62930] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSCMWwDnJBNj2tDbYYYmAAAAEU"] [Tue Aug 18 13:02:57.952164 2026] [security2:error] [pid 139043:tid 139199] [client 20.25.139.174:2281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/222.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmGwAAAJ8"] [Tue Aug 18 13:02:57.968154 2026] [security2:error] [pid 139043:tid 139187] [client 34.156.195.117:62840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/docker/.env"] [unique_id "aoSCMf2v-lWn9OzQT7UmHAAAAJM"] [Tue Aug 18 13:02:57.975985 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/mamzi.php"] [unique_id "aoSCMf2v-lWn9OzQT7UmHgAAAJA"] [Tue Aug 18 13:02:57.983748 2026] [security2:error] [pid 123784:tid 123952] [client 34.156.195.117:62732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/crm/.env"] [unique_id "aoSCMWwDnJBNj2tDbYYYmgAAACI"] [Tue Aug 18 13:02:57.986214 2026] [security2:error] [pid 123784:tid 123959] [client 34.156.195.117:63116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/apps/.env"] [unique_id "aoSCMWwDnJBNj2tDbYYYmwAAACk"] [Tue Aug 18 13:02:57.989201 2026] [security2:error] [pid 123784:tid 123940] [client 34.156.195.117:62982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/application/.env"] [unique_id "aoSCMWwDnJBNj2tDbYYYnQAAABY"] [Tue Aug 18 13:02:57.992119 2026] [security2:error] [pid 139043:tid 139174] [client 34.156.195.117:62892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/www/.env"] [unique_id "aoSCMf2v-lWn9OzQT7UmHwAAAIY"] [Tue Aug 18 13:02:57.992283 2026] [security2:error] [pid 139043:tid 139196] [client 34.156.195.117:62828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/app/api/.env"] [unique_id "aoSCMf2v-lWn9OzQT7UmIAAAAJw"] [Tue Aug 18 13:02:57.992336 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:57.992585 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:58.002306 2026] [security2:error] [pid 139043:tid 139202] [client 34.156.195.117:62972] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/internal/.env.production"] [unique_id "aoSCMv2v-lWn9OzQT7UmIgAAAKI"] [Tue Aug 18 13:02:58.002306 2026] [security2:error] [pid 123784:tid 124000] [client 34.156.195.117:62850] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/services/.env"] [unique_id "aoSCMmwDnJBNj2tDbYYYngAAAFI"] [Tue Aug 18 13:02:58.002822 2026] [security2:error] [pid 139043:tid 139262] [client 34.156.195.117:62946] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/frontend/.env.local"] [unique_id "aoSCMv2v-lWn9OzQT7UmJAAAAN4"] [Tue Aug 18 13:02:58.007488 2026] [security2:error] [pid 139043:tid 139277] [client 20.116.17.175:22940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/222.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmJQAAAO0"] [Tue Aug 18 13:02:58.012069 2026] [security2:error] [pid 139043:tid 139236] [client 34.156.195.117:62858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env~"] [unique_id "aoSCMv2v-lWn9OzQT7UmKAAAAMQ"] [Tue Aug 18 13:02:58.022807 2026] [security2:error] [pid 139043:tid 139286] [client 20.51.153.15:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/se.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmKQAAAPY"] [Tue Aug 18 13:02:58.028781 2026] [security2:error] [pid 139043:tid 139287] [client 20.65.69.59:27888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/rb.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmKgAAAPc"] [Tue Aug 18 13:02:58.053165 2026] [security2:error] [pid 139043:tid 139267] [client 34.156.195.117:63048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/v1/.env"] [unique_id "aoSCMv2v-lWn9OzQT7UmLAAAAOM"] [Tue Aug 18 13:02:58.057425 2026] [security2:error] [pid 123784:tid 124035] [client 34.156.195.117:62698] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSCMmwDnJBNj2tDbYYYogAAAHU"] [Tue Aug 18 13:02:58.059869 2026] [security2:error] [pid 123784:tid 123928] [client 20.65.105.233:12760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/raw.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYowAAAAo"] [Tue Aug 18 13:02:58.082895 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ey.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmLQAAAQM"] [Tue Aug 18 13:02:58.098865 2026] [security2:error] [pid 139043:tid 139272] [client 34.156.195.117:62960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/backup/.env"] [unique_id "aoSCMv2v-lWn9OzQT7UmLgAAAOg"] [Tue Aug 18 13:02:58.136101 2026] [security2:error] [pid 139043:tid 139253] [client 20.79.204.6:9681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/adminfuns.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmLwAAANU"] [Tue Aug 18 13:02:58.165222 2026] [security2:error] [pid 123784:tid 123931] [client 172.182.217.32:21566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/22.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYpQAAAA0"] [Tue Aug 18 13:02:58.187599 2026] [security2:error] [pid 123784:tid 124013] [client 20.163.43.14:6608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYpgAAAF8"] [Tue Aug 18 13:02:58.195972 2026] [security2:error] [pid 123784:tid 123919] [client 68.155.154.236:9190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYpwAAAAE"] [Tue Aug 18 13:02:58.205800 2026] [security2:error] [pid 123784:tid 124010] [client 20.251.48.93:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/akismet.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYqAAAAFw"] [Tue Aug 18 13:02:58.222412 2026] [security2:error] [pid 123784:tid 124039] [client 20.250.13.23:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/term.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYqQAAAHk"] [Tue Aug 18 13:02:58.249090 2026] [security2:error] [pid 123784:tid 123934] [client 20.251.112.238:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/end.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYqwAAABA"] [Tue Aug 18 13:02:58.250474 2026] [security2:error] [pid 139043:tid 139264] [client 20.80.111.3:17983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/test.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmMQAAAOA"] [Tue Aug 18 13:02:58.250853 2026] [security2:error] [pid 139043:tid 139240] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pousadadoreiarthur.com.br"] [uri "/index.php"] [unique_id "aoSCMP2v-lWn9OzQT7Ul1AAAyGY"], referer: https://www.pousadadoreiarthur.com.br/ [Tue Aug 18 13:02:58.258262 2026] [security2:error] [pid 123784:tid 123932] [client 158.23.17.4:47881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/q.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYrQAAAA4"] [Tue Aug 18 13:02:58.263895 2026] [security2:error] [pid 139043:tid 139060] [remote 185.118.190.176:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmMgAArxA"] [Tue Aug 18 13:02:58.269167 2026] [security2:error] [pid 123784:tid 123985] [client 158.23.17.4:33986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/payout.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYrgAAAEM"] [Tue Aug 18 13:02:58.273211 2026] [security2:error] [pid 139043:tid 139292] [client 20.25.139.174:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/inputs.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmNAAAAPw"] [Tue Aug 18 13:02:58.296507 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:58.296818 2026] [authz_core:error] [pid 123784:tid 123910] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:58.300693 2026] [security2:error] [pid 123784:tid 123945] [client 20.65.105.233:13165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/05.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYsAAAABs"] [Tue Aug 18 13:02:58.304172 2026] [security2:error] [pid 139043:tid 139218] [client 138.36.100.162:42148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmNQAAALI"] [Tue Aug 18 13:02:58.304318 2026] [security2:error] [pid 139043:tid 139218] [client 138.36.100.162:42148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmNQAAALI"] [Tue Aug 18 13:02:58.315859 2026] [security2:error] [pid 139043:tid 139214] [client 20.51.153.15:9806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vp.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmNgAAAK4"] [Tue Aug 18 13:02:58.316521 2026] [security2:error] [pid 139043:tid 139247] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ms.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmNwAAAM8"] [Tue Aug 18 13:02:58.325339 2026] [security2:error] [pid 139043:tid 139258] [client 34.156.195.117:63076] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/v2/.env"] [unique_id "aoSCMv2v-lWn9OzQT7UmOAAAANo"] [Tue Aug 18 13:02:58.448554 2026] [security2:error] [pid 139043:tid 139233] [client 20.65.69.59:9666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/37.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmOQAAAME"] [Tue Aug 18 13:02:58.457150 2026] [security2:error] [pid 139043:tid 139239] [client 172.182.200.96:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/well-known/index.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmOgAAAMc"] [Tue Aug 18 13:02:58.506290 2026] [security2:error] [pid 139043:tid 139213] [client 40.74.65.169:44277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/admin.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmPgAAAK0"] [Tue Aug 18 13:02:58.506795 2026] [security2:error] [pid 139043:tid 139212] [client 20.25.139.174:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmPwAAAKw"] [Tue Aug 18 13:02:58.507622 2026] [security2:error] [pid 139043:tid 139178] [client 20.116.17.175:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmQAAAAIo"] [Tue Aug 18 13:02:58.511005 2026] [security2:error] [pid 139043:tid 139216] [client 20.163.43.14:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmQQAAALA"] [Tue Aug 18 13:02:58.540982 2026] [security2:error] [pid 139043:tid 139256] [client 20.65.105.233:12737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/public/hi.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmQwAAANg"] [Tue Aug 18 13:02:58.542627 2026] [autoindex:error] [pid 139043:tid 139162] [remote 23.251.146.115:12256] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:02:58.550931 2026] [security2:error] [pid 139043:tid 139181] [client 158.23.17.4:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lv.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmRAAAAI0"] [Tue Aug 18 13:02:58.553030 2026] [security2:error] [pid 139043:tid 139298] [client 20.51.153.15:9808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ph.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmRQAAAQI"] [Tue Aug 18 13:02:58.593142 2026] [security2:error] [pid 139043:tid 139220] [client 103.120.71.157:31211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmRgAAALQ"] [Tue Aug 18 13:02:58.593276 2026] [security2:error] [pid 139043:tid 139220] [client 103.120.71.157:31211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmRgAAALQ"] [Tue Aug 18 13:02:58.595193 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:58.595458 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:58.601096 2026] [security2:error] [pid 139043:tid 139276] [client 40.74.65.169:51660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/xiugai.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmRwAAAOw"] [Tue Aug 18 13:02:58.614443 2026] [security2:error] [pid 139043:tid 139279] [client 144.76.22.51:36222] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/robots.txt"] [unique_id "aoSCMv2v-lWn9OzQT7UmSAAAAO8"] [Tue Aug 18 13:02:58.621920 2026] [security2:error] [pid 139043:tid 139149] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmSQAA2Wk"] [Tue Aug 18 13:02:58.622048 2026] [security2:error] [pid 139043:tid 139257] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmSQAA2Wk"] [Tue Aug 18 13:02:58.635261 2026] [security2:error] [pid 139043:tid 139195] [client 4.232.151.198:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-post.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmSwAAAJs"] [Tue Aug 18 13:02:58.653660 2026] [security2:error] [pid 139043:tid 139234] [client 172.182.217.32:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/room.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmTAAAAMI"] [Tue Aug 18 13:02:58.654457 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/gfile.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmTQAAAPM"] [Tue Aug 18 13:02:58.660972 2026] [security2:error] [pid 123784:tid 123971] [client 20.251.112.238:63868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.112.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consiliumbr.com.br"] [uri "/ae.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYtwAAADU"] [Tue Aug 18 13:02:58.672872 2026] [security2:error] [pid 139043:tid 139201] [client 178.153.171.161:7685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmTgAAAKE"] [Tue Aug 18 13:02:58.672972 2026] [security2:error] [pid 139043:tid 139201] [client 178.153.171.161:7685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmTgAAAKE"] [Tue Aug 18 13:02:58.689906 2026] [security2:error] [pid 139043:tid 139275] [client 20.80.111.3:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmUQAAAOs"] [Tue Aug 18 13:02:58.740350 2026] [security2:error] [pid 139043:tid 139190] [client 4.232.151.198:34054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/222.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmUgAAAJY"] [Tue Aug 18 13:02:58.749897 2026] [security2:error] [pid 123784:tid 123942] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/public/wp-blog.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYuQAAABg"] [Tue Aug 18 13:02:58.753322 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.69.59:48511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/md.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYugAAACo"] [Tue Aug 18 13:02:58.758080 2026] [security2:error] [pid 139043:tid 139219] [client 157.20.138.62:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmVAAAALM"] [Tue Aug 18 13:02:58.758741 2026] [security2:error] [pid 139043:tid 139219] [client 157.20.138.62:52656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmVAAAALM"] [Tue Aug 18 13:02:58.767076 2026] [security2:error] [pid 139043:tid 139271] [client 20.25.139.174:4679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/admin.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmVQAAAOc"] [Tue Aug 18 13:02:58.782201 2026] [security2:error] [pid 123784:tid 123936] [client 20.65.105.233:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/get.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYuwAAABI"] [Tue Aug 18 13:02:58.783230 2026] [security2:error] [pid 139043:tid 139266] [client 103.59.160.82:55035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.danielesilveira.com.br"] [uri "/index.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmVgAAAOI"] [Tue Aug 18 13:02:58.841416 2026] [security2:error] [pid 139043:tid 139274] [client 20.250.13.23:3402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/test.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmWAAAAOo"] [Tue Aug 18 13:02:58.888926 2026] [security2:error] [pid 139043:tid 139199] [client 20.163.43.14:6617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmWQAAAJ8"] [Tue Aug 18 13:02:58.891586 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.36.136:57232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmWgAAAKU"] [Tue Aug 18 13:02:58.895047 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:58.895337 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:58.897932 2026] [security2:error] [pid 139043:tid 139210] [client 20.51.153.15:9834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/s.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmWwAAAKo"] [Tue Aug 18 13:02:58.906596 2026] [security2:error] [pid 139043:tid 139231] [client 158.23.17.4:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/bh.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmXAAAAL8"] [Tue Aug 18 13:02:58.909160 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/cu.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYwQAAADs"] [Tue Aug 18 13:02:58.915782 2026] [security2:error] [pid 139043:tid 139288] [client 20.226.36.136:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmXQAAAPg"] [Tue Aug 18 13:02:58.957140 2026] [security2:error] [pid 139043:tid 139278] [client 213.35.127.232:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmXgAAAO4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:58.973371 2026] [security2:error] [pid 139043:tid 139227] [client 132.196.30.78:25832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/f35.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmYAAAALs"] [Tue Aug 18 13:02:58.977804 2026] [security2:error] [pid 139043:tid 139262] [client 68.155.154.236:40447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmYQAAAN4"] [Tue Aug 18 13:02:58.978409 2026] [security2:error] [pid 139043:tid 139259] [client 172.182.200.96:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCMv2v-lWn9OzQT7UmYgAAANs"] [Tue Aug 18 13:02:58.988330 2026] [security2:error] [pid 123784:tid 124041] [client 20.116.17.175:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/water.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYxAAAAHs"] [Tue Aug 18 13:02:58.997582 2026] [security2:error] [pid 123784:tid 123993] [client 20.65.69.59:52145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/iy.php"] [unique_id "aoSCMmwDnJBNj2tDbYYYxQAAAEs"] [Tue Aug 18 13:02:59.012475 2026] [security2:error] [pid 139043:tid 139286] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/X57.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmYwAAAPY"] [Tue Aug 18 13:02:59.028232 2026] [security2:error] [pid 123784:tid 124042] [client 20.65.105.233:12443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/rpk.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYxgAAAHw"] [Tue Aug 18 13:02:59.057606 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/forbidals.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmZAAAAL4"] [Tue Aug 18 13:02:59.066994 2026] [security2:error] [pid 139043:tid 139300] [client 20.25.139.174:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/info.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmZQAAAQQ"] [Tue Aug 18 13:02:59.143067 2026] [security2:error] [pid 139043:tid 139246] [client 172.182.217.32:21846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/disagreed.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmZwAAAM4"] [Tue Aug 18 13:02:59.151656 2026] [security2:error] [pid 123784:tid 123989] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/edit.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYyQAAAEc"] [Tue Aug 18 13:02:59.157285 2026] [security2:error] [pid 139043:tid 139228] [client 20.80.111.3:17959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/elementra/skins/politics/plugins/security.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmaAAAALw"] [Tue Aug 18 13:02:59.184497 2026] [security2:error] [pid 139043:tid 139264] [client 34.156.195.117:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/sendgrid/.env.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmagAAAOA"] [Tue Aug 18 13:02:59.185135 2026] [security2:error] [pid 139043:tid 139177] [client 34.156.195.117:62892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.docker/.env"] [unique_id "aoSCM_2v-lWn9OzQT7UmaQAAAIk"] [Tue Aug 18 13:02:59.197737 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:59.198000 2026] [authz_core:error] [pid 123784:tid 123855] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:59.200565 2026] [security2:error] [pid 139043:tid 139193] [client 40.74.65.169:44275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/reviall.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmawAAAJk"] [Tue Aug 18 13:02:59.213894 2026] [security2:error] [pid 123784:tid 124008] [client 20.163.43.14:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/public/css.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYywAAAFo"] [Tue Aug 18 13:02:59.220904 2026] [security2:error] [pid 123784:tid 124028] [client 20.79.204.6:9298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/404.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYzAAAAG4"] [Tue Aug 18 13:02:59.227595 2026] [security2:error] [pid 139043:tid 139292] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/kj.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmbQAAAPw"] [Tue Aug 18 13:02:59.228124 2026] [security2:error] [pid 123784:tid 123955] [client 20.51.153.15:9852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/uo.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYzQAAACU"] [Tue Aug 18 13:02:59.253609 2026] [security2:error] [pid 123784:tid 123933] [client 34.156.195.117:62732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/twilio/.env.php"] [unique_id "aoSCM2wDnJBNj2tDbYYYzwAAAA8"] [Tue Aug 18 13:02:59.263076 2026] [security2:error] [pid 139043:tid 139299] [client 4.232.151.198:10377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp/images/my.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmbwAAAQM"] [Tue Aug 18 13:02:59.272820 2026] [security2:error] [pid 123784:tid 124021] [client 20.65.105.233:12558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY0AAAAGc"] [Tue Aug 18 13:02:59.274652 2026] [security2:error] [pid 123784:tid 123973] [client 158.23.17.4:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/51.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY0QAAADc"] [Tue Aug 18 13:02:59.282493 2026] [security2:error] [pid 123784:tid 124016] [client 20.226.36.136:57801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/weozh.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY0gAAAGI"] [Tue Aug 18 13:02:59.297017 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/wp-load.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY0wAAAH4"] [Tue Aug 18 13:02:59.306285 2026] [security2:error] [pid 139043:tid 139209] [client 20.25.139.174:4506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/goods.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmcAAAAKk"] [Tue Aug 18 13:02:59.310500 2026] [security2:error] [pid 123784:tid 124031] [client 34.156.195.117:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/app_dev.php/_profiler/.env"] [unique_id "aoSCM2wDnJBNj2tDbYYY1QAAAHE"] [Tue Aug 18 13:02:59.310537 2026] [security2:error] [pid 123784:tid 123964] [client 20.116.17.175:23018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/spadex.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY1AAAAC4"] [Tue Aug 18 13:02:59.347029 2026] [security2:error] [pid 139043:tid 139233] [client 20.65.69.59:27847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/og.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmcQAAAME"] [Tue Aug 18 13:02:59.354531 2026] [security2:error] [pid 139043:tid 139239] [client 168.62.48.100:5586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmcgAAAMc"] [Tue Aug 18 13:02:59.359272 2026] [security2:error] [pid 139043:tid 139213] [client 34.156.195.117:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/_profiler/phpinfo.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmcwAAAK0"] [Tue Aug 18 13:02:59.361636 2026] [security2:error] [pid 123784:tid 123957] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/bes.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY2QAAACc"] [Tue Aug 18 13:02:59.364187 2026] [security2:error] [pid 123784:tid 124009] [client 34.156.195.117:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "aoSCM2wDnJBNj2tDbYYY2gAAAFs"] [Tue Aug 18 13:02:59.370343 2026] [security2:error] [pid 139043:tid 139178] [client 34.156.195.117:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/config/.env.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmdAAAAIo"] [Tue Aug 18 13:02:59.375642 2026] [security2:error] [pid 139043:tid 139216] [client 172.182.200.96:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmdQAAALA"] [Tue Aug 18 13:02:59.406001 2026] [security2:error] [pid 123784:tid 123999] [client 68.155.154.236:8895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY2wAAAFE"] [Tue Aug 18 13:02:59.407071 2026] [security2:error] [pid 139043:tid 139182] [client 68.155.154.236:8866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmdgAAAI4"] [Tue Aug 18 13:02:59.418202 2026] [security2:error] [pid 123784:tid 123949] [client 34.156.195.117:62704] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSCM2wDnJBNj2tDbYYY3AAAAB8"] [Tue Aug 18 13:02:59.442851 2026] [security2:error] [pid 139043:tid 139181] [client 34.156.195.117:62744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/phpinfo.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmdwAAAI0"] [Tue Aug 18 13:02:59.443394 2026] [security2:error] [pid 139043:tid 139222] [client 34.156.195.117:63018] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/ci/.env"] [unique_id "aoSCM_2v-lWn9OzQT7UmeQAAALY"] [Tue Aug 18 13:02:59.445014 2026] [security2:error] [pid 139043:tid 139232] [client 52.173.121.69:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmegAAAMA"] [Tue Aug 18 13:02:59.476483 2026] [security2:error] [pid 139043:tid 139220] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ws60.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmfAAAALQ"] [Tue Aug 18 13:02:59.477321 2026] [security2:error] [pid 139043:tid 139207] [client 158.23.17.4:9818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xf.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmfQAAAKc"] [Tue Aug 18 13:02:59.514132 2026] [security2:error] [pid 123784:tid 124045] [client 20.65.105.233:12781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/mga.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY4AAAAH8"] [Tue Aug 18 13:02:59.525481 2026] [security2:error] [pid 123784:tid 123923] [client 144.76.22.51:60362] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY1gAAAAU"], referer: http://www.agrimotor.com.br/robots.txt [Tue Aug 18 13:02:59.539648 2026] [security2:error] [pid 123784:tid 123921] [client 20.163.43.14:6536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY4wAAAAM"] [Tue Aug 18 13:02:59.541076 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.36.136:57231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/rymmm.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmfwAAAPM"] [Tue Aug 18 13:02:59.546776 2026] [security2:error] [pid 123784:tid 124004] [client 20.51.153.15:9559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kx.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY5AAAAFY"] [Tue Aug 18 13:02:59.568368 2026] [security2:error] [pid 139043:tid 139212] [client 20.250.13.23:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/test1.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmgAAAAKw"] [Tue Aug 18 13:02:59.604501 2026] [security2:error] [pid 123784:tid 123992] [client 20.25.139.174:2400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/a.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY5wAAAEo"] [Tue Aug 18 13:02:59.630156 2026] [security2:error] [pid 123784:tid 123983] [client 172.182.217.32:21824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY6AAAAEE"] [Tue Aug 18 13:02:59.643255 2026] [security2:error] [pid 139043:tid 139194] [client 20.80.111.3:17949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmgQAAAJo"] [Tue Aug 18 13:02:59.676217 2026] [security2:error] [pid 123784:tid 123979] [client 20.65.69.59:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lp.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY6gAAAD0"] [Tue Aug 18 13:02:59.755006 2026] [security2:error] [pid 123784:tid 123969] [client 20.65.105.233:12470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/fs.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY7AAAADM"] [Tue Aug 18 13:02:59.755717 2026] [security2:error] [pid 139043:tid 139272] [client 102.213.179.104:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmgwAAAOg"] [Tue Aug 18 13:02:59.755867 2026] [security2:error] [pid 139043:tid 139272] [client 102.213.179.104:55520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmgwAAAOg"] [Tue Aug 18 13:02:59.757463 2026] [security2:error] [pid 123784:tid 124005] [client 4.232.151.198:42323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY7QAAAFc"] [Tue Aug 18 13:02:59.758435 2026] [security2:error] [pid 123784:tid 124019] [client 158.23.17.4:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ew.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY7gAAAGU"] [Tue Aug 18 13:02:59.799420 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:02:59.799673 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:02:59.842212 2026] [security2:error] [pid 139043:tid 139271] [client 20.51.153.15:9850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/va.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmhAAAAOc"] [Tue Aug 18 13:02:59.868915 2026] [security2:error] [pid 139043:tid 139204] [client 20.25.139.174:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/file.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmhQAAAKQ"] [Tue Aug 18 13:02:59.870731 2026] [security2:error] [pid 139043:tid 139291] [client 172.182.200.96:15694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmhgAAAPs"] [Tue Aug 18 13:02:59.881692 2026] [security2:error] [pid 139043:tid 139251] [client 40.74.65.169:44208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/nope.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmhwAAANM"] [Tue Aug 18 13:02:59.899937 2026] [security2:error] [pid 123784:tid 124000] [client 4.232.151.198:10392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/function.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY9QAAAFI"] [Tue Aug 18 13:02:59.900827 2026] [security2:error] [pid 123784:tid 123953] [client 20.116.17.175:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY9gAAACM"] [Tue Aug 18 13:02:59.921129 2026] [security2:error] [pid 123784:tid 123945] [client 52.173.121.69:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY9wAAABs"] [Tue Aug 18 13:02:59.971589 2026] [security2:error] [pid 123784:tid 123959] [client 213.35.127.232:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY-QAAACk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:02:59.975563 2026] [security2:error] [pid 139043:tid 139180] [client 52.173.121.69:35765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCM_2v-lWn9OzQT7UmigAAAIw"] [Tue Aug 18 13:02:59.985342 2026] [security2:error] [pid 139043:tid 139280] [client 34.156.195.117:62960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/backend/api/.env"] [unique_id "aoSCM_2v-lWn9OzQT7UmiwAAAPA"] [Tue Aug 18 13:02:59.985657 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/155.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY-gAAAAA"] [Tue Aug 18 13:02:59.994874 2026] [security2:error] [pid 123784:tid 123976] [client 20.65.105.233:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/wp-tem.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY-wAAADo"] [Tue Aug 18 13:03:00.002506 2026] [security2:error] [pid 123784:tid 123990] [client 20.65.69.59:48453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ey.php"] [unique_id "aoSCNGwDnJBNj2tDbYYY_AAAAEg"] [Tue Aug 18 13:03:00.024758 2026] [security2:error] [pid 123784:tid 124023] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/olfclass.php"] [unique_id "aoSCNGwDnJBNj2tDbYYY_QAAAGk"] [Tue Aug 18 13:03:00.027488 2026] [security2:error] [pid 123784:tid 124012] [client 68.155.154.236:41502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/rezor.php"] [unique_id "aoSCNGwDnJBNj2tDbYYY_gAAAF4"] [Tue Aug 18 13:03:00.093713 2026] [security2:error] [pid 139043:tid 139288] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wpver.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmjAAAAPg"] [Tue Aug 18 13:03:00.101779 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:00.102042 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:00.104689 2026] [security2:error] [pid 139043:tid 139206] [client 20.80.111.3:17933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/login.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmjQAAAKY"] [Tue Aug 18 13:03:00.119935 2026] [security2:error] [pid 123784:tid 123961] [client 172.182.217.32:21867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCNGwDnJBNj2tDbYYZAgAAACs"] [Tue Aug 18 13:03:00.139623 2026] [security2:error] [pid 139043:tid 139296] [client 103.184.169.37:43470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmjgAAAQA"] [Tue Aug 18 13:03:00.139787 2026] [security2:error] [pid 139043:tid 139296] [client 103.184.169.37:43470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmjgAAAQA"] [Tue Aug 18 13:03:00.155993 2026] [security2:error] [pid 123784:tid 123938] [client 20.25.139.174:2291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/chosen.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZBQAAABQ"] [Tue Aug 18 13:03:00.163757 2026] [security2:error] [pid 123784:tid 124018] [client 20.79.204.6:9299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wk/index.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZBgAAAGQ"] [Tue Aug 18 13:03:00.169594 2026] [security2:error] [pid 123784:tid 123972] [client 20.51.153.15:9840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fo.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZCAAAADY"] [Tue Aug 18 13:03:00.180164 2026] [security2:error] [pid 123784:tid 123984] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/thui.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZCQAAAEI"] [Tue Aug 18 13:03:00.225740 2026] [security2:error] [pid 139043:tid 139262] [client 172.182.200.96:15626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/mt/byp.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmkQAAAN4"] [Tue Aug 18 13:03:00.236030 2026] [security2:error] [pid 123784:tid 123998] [client 20.65.105.233:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/sadd.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZCgAAAFA"] [Tue Aug 18 13:03:00.261771 2026] [security2:error] [pid 139043:tid 139210] [client 20.250.13.23:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/thoms.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmkwAAAKo"] [Tue Aug 18 13:03:00.269862 2026] [security2:error] [pid 139043:tid 139267] [client 20.65.69.59:56923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lv.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmlQAAAOM"] [Tue Aug 18 13:03:00.283993 2026] [security2:error] [pid 123784:tid 123993] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/tmpls.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZDAAAAEs"] [Tue Aug 18 13:03:00.306278 2026] [security2:error] [pid 139043:tid 139230] [client 20.151.109.219:13778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/he.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmlgAAAL4"] [Tue Aug 18 13:03:00.325643 2026] [security2:error] [pid 139043:tid 139300] [client 34.156.195.117:62694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/old/.env"] [unique_id "aoSCNP2v-lWn9OzQT7UmmAAAAQQ"] [Tue Aug 18 13:03:00.332572 2026] [security2:error] [pid 139043:tid 139253] [client 34.156.195.117:63048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/html/.env"] [unique_id "aoSCNP2v-lWn9OzQT7UmmQAAANU"] [Tue Aug 18 13:03:00.347623 2026] [security2:error] [pid 123784:tid 124008] [client 20.226.36.136:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/lddxs.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZDwAAAFo"] [Tue Aug 18 13:03:00.392544 2026] [security2:error] [pid 123784:tid 123973] [client 68.155.154.236:41474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZEQAAADc"] [Tue Aug 18 13:03:00.400509 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:00.400802 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:00.410271 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/nzv.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmmwAAAM4"] [Tue Aug 18 13:03:00.422575 2026] [security2:error] [pid 139043:tid 139266] [client 20.116.17.175:44043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/srontol.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmnQAAAOI"] [Tue Aug 18 13:03:00.436330 2026] [security2:error] [pid 139043:tid 139264] [client 52.173.121.69:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmngAAAOA"] [Tue Aug 18 13:03:00.476794 2026] [security2:error] [pid 123784:tid 124044] [client 20.65.105.233:12421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ex.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZFAAAAH4"] [Tue Aug 18 13:03:00.494436 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/ct.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZFQAAAC4"] [Tue Aug 18 13:03:00.505052 2026] [security2:error] [pid 123784:tid 124031] [client 20.51.153.15:9771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/loading.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZFgAAAHE"] [Tue Aug 18 13:03:00.516606 2026] [security2:error] [pid 123784:tid 123975] [client 20.116.17.175:53790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/fine.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZGAAAADk"] [Tue Aug 18 13:03:00.529784 2026] [security2:error] [pid 139043:tid 139238] [client 34.156.195.117:62840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/conf/.env"] [unique_id "aoSCNP2v-lWn9OzQT7UmnwAAAMY"] [Tue Aug 18 13:03:00.572117 2026] [security2:error] [pid 123784:tid 123958] [client 4.232.151.198:10981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-2019.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZGQAAACg"] [Tue Aug 18 13:03:00.575126 2026] [security2:error] [pid 123784:tid 124043] [client 172.182.200.96:15731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/MTOS/byp.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZGgAAAH0"] [Tue Aug 18 13:03:00.587220 2026] [security2:error] [pid 123784:tid 123989] [client 20.25.139.174:4599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/adminfuns.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZGwAAAEc"] [Tue Aug 18 13:03:00.587771 2026] [security2:error] [pid 123784:tid 124016] [client 20.80.111.3:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/plugin-install.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZHAAAAGI"] [Tue Aug 18 13:03:00.589171 2026] [security2:error] [pid 139043:tid 139299] [client 40.74.65.169:44241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/nope.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmoAAAAQM"] [Tue Aug 18 13:03:00.628807 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/feeds.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmoQAAAMg"] [Tue Aug 18 13:03:00.629389 2026] [security2:error] [pid 139043:tid 139282] [client 20.65.69.59:59235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/51.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmogAAAPI"] [Tue Aug 18 13:03:00.657408 2026] [security2:error] [pid 123784:tid 123997] [client 5.31.227.224:29913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZHwAAAE8"] [Tue Aug 18 13:03:00.657524 2026] [security2:error] [pid 123784:tid 123997] [client 5.31.227.224:29913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZHwAAAE8"] [Tue Aug 18 13:03:00.681111 2026] [security2:error] [pid 139043:tid 139269] [client 20.25.139.174:2426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmpAAAAOU"] [Tue Aug 18 13:03:00.704030 2026] [security2:error] [pid 123784:tid 124002] [client 20.163.43.14:6600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZIgAAAFQ"] [Tue Aug 18 13:03:00.704667 2026] [security2:error] [pid 123784:tid 124037] [client 37.40.227.74:56638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZIwAAAHc"] [Tue Aug 18 13:03:00.704837 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:00.705096 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:00.711563 2026] [security2:error] [pid 139043:tid 139198] [client 40.74.65.169:55203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/index.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmpgAAAJ4"] [Tue Aug 18 13:03:00.712265 2026] [security2:error] [pid 139043:tid 139260] [client 34.156.195.117:62892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/laravel/.env"] [unique_id "aoSCNP2v-lWn9OzQT7UmpQAAANw"] [Tue Aug 18 13:03:00.713880 2026] [security2:error] [pid 123784:tid 124037] [client 37.40.227.74:56638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZIwAAAHc"] [Tue Aug 18 13:03:00.716288 2026] [security2:error] [pid 123784:tid 123968] [client 20.65.105.233:12459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/tax.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZJAAAADI"] [Tue Aug 18 13:03:00.759271 2026] [security2:error] [pid 139043:tid 139200] [client 68.155.154.236:63582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmqAAAAKA"] [Tue Aug 18 13:03:00.778037 2026] [security2:error] [pid 123784:tid 123927] [client 144.76.22.51:60370] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZHQAAAAk"], referer: https://www.agrimotor.com.br/robots.txt [Tue Aug 18 13:03:00.787461 2026] [security2:error] [pid 123784:tid 123921] [client 20.51.153.15:9733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ke.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZJQAAAAM"] [Tue Aug 18 13:03:00.829023 2026] [security2:error] [pid 139043:tid 139298] [client 20.116.17.175:22984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/file5.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmqwAAAQI"] [Tue Aug 18 13:03:00.908496 2026] [security2:error] [pid 139043:tid 139209] [client 20.250.13.23:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/tool.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmrQAAAKk"] [Tue Aug 18 13:03:00.940263 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:31872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/gy.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmrwAAALg"] [Tue Aug 18 13:03:00.956984 2026] [security2:error] [pid 139043:tid 139237] [client 20.65.105.233:12601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/X7x.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmsAAAAMU"] [Tue Aug 18 13:03:00.959501 2026] [security2:error] [pid 139043:tid 139202] [client 172.182.200.96:15695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmsQAAAKI"] [Tue Aug 18 13:03:00.966030 2026] [security2:error] [pid 139043:tid 139250] [client 20.65.69.59:9694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ew.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmsgAAANI"] [Tue Aug 18 13:03:00.987759 2026] [security2:error] [pid 139043:tid 139294] [client 213.35.127.232:58839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCNP2v-lWn9OzQT7UmswAAAP4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:00.999937 2026] [security2:error] [pid 123784:tid 124005] [client 158.23.17.4:17573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gb.php"] [unique_id "aoSCNGwDnJBNj2tDbYYZKwAAAFc"] [Tue Aug 18 13:03:01.003658 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:01.003933 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:01.018172 2026] [security2:error] [pid 139043:tid 139216] [client 20.79.204.6:9677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/about.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmtAAAALA"] [Tue Aug 18 13:03:01.026979 2026] [security2:error] [pid 123784:tid 123979] [client 20.80.111.3:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/test.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZLAAAAD0"] [Tue Aug 18 13:03:01.029973 2026] [security2:error] [pid 123784:tid 123986] [client 20.51.153.15:9838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nh.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZLQAAAEQ"] [Tue Aug 18 13:03:01.052250 2026] [security2:error] [pid 123784:tid 124013] [client 20.206.73.37:35289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/133.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZLgAAAF8"] [Tue Aug 18 13:03:01.060222 2026] [security2:error] [pid 123784:tid 124010] [client 20.163.43.14:6640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/gelay.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZMQAAAFw"] [Tue Aug 18 13:03:01.122673 2026] [security2:error] [pid 123784:tid 123928] [client 172.182.217.32:21763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/defaults.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZMwAAAAo"] [Tue Aug 18 13:03:01.124026 2026] [security2:error] [pid 139043:tid 139283] [client 20.25.139.174:4543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/404.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmtgAAAPM"] [Tue Aug 18 13:03:01.126946 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pqr.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmtwAAAJg"] [Tue Aug 18 13:03:01.156519 2026] [security2:error] [pid 139043:tid 139271] [client 34.156.195.117:62960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCNf2v-lWn9OzQT7UmugAAAOc"] [Tue Aug 18 13:03:01.174545 2026] [security2:error] [pid 139043:tid 139291] [client 34.156.195.117:62694] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/management/env"] [unique_id "aoSCNf2v-lWn9OzQT7UmuwAAAPs"] [Tue Aug 18 13:03:01.177933 2026] [security2:error] [pid 139043:tid 139273] [client 168.62.48.100:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/.cache/x.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmvAAAAOk"] [Tue Aug 18 13:03:01.187419 2026] [security2:error] [pid 139043:tid 139173] [client 20.116.17.175:22996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/yup.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmvQAAAIU"] [Tue Aug 18 13:03:01.199640 2026] [security2:error] [pid 139043:tid 139248] [client 4.232.151.198:24777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/cjfuns.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmvgAAANA"] [Tue Aug 18 13:03:01.200205 2026] [security2:error] [pid 139043:tid 139274] [client 20.65.105.233:12594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ocxla.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmvwAAAOo"] [Tue Aug 18 13:03:01.211936 2026] [security2:error] [pid 139043:tid 139221] [client 20.25.139.174:2177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/vx.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmwAAAALU"] [Tue Aug 18 13:03:01.292611 2026] [security2:error] [pid 139043:tid 139231] [client 40.74.65.169:44193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/new.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmwgAAAL8"] [Tue Aug 18 13:03:01.308016 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:01.308465 2026] [authz_core:error] [pid 123784:tid 123908] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:01.313145 2026] [security2:error] [pid 139043:tid 139176] [client 52.173.121.69:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/weozh.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmxAAAAIg"] [Tue Aug 18 13:03:01.344868 2026] [security2:error] [pid 139043:tid 139297] [client 20.65.69.59:27880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pqr.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmyAAAAQE"] [Tue Aug 18 13:03:01.352109 2026] [security2:error] [pid 123784:tid 123980] [client 20.51.153.15:9842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/oo.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZOwAAAD4"] [Tue Aug 18 13:03:01.385911 2026] [security2:error] [pid 123784:tid 123934] [client 20.163.43.14:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZPAAAABA"] [Tue Aug 18 13:03:01.424331 2026] [security2:error] [pid 123784:tid 124038] [client 172.182.200.96:15633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZPQAAAHg"] [Tue Aug 18 13:03:01.435041 2026] [security2:error] [pid 139043:tid 139259] [client 40.74.65.169:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/aaa.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmyQAAANs"] [Tue Aug 18 13:03:01.444422 2026] [security2:error] [pid 123784:tid 123959] [client 20.65.105.233:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/post.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZPwAAACk"] [Tue Aug 18 13:03:01.453754 2026] [security2:error] [pid 123784:tid 123976] [client 168.62.48.100:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/oivcl.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZQQAAADo"] [Tue Aug 18 13:03:01.476968 2026] [security2:error] [pid 139043:tid 139184] [client 20.80.111.3:17974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmygAAAJA"] [Tue Aug 18 13:03:01.483602 2026] [security2:error] [pid 139043:tid 139235] [client 144.76.22.51:36224] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/"] [unique_id "aoSCNf2v-lWn9OzQT7UmywAAAMM"] [Tue Aug 18 13:03:01.510806 2026] [security2:error] [pid 139043:tid 139230] [client 20.251.48.93:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/admin.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmzQAAAL4"] [Tue Aug 18 13:03:01.592228 2026] [security2:error] [pid 139043:tid 139174] [client 20.51.153.15:9483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ja.php"] [unique_id "aoSCNf2v-lWn9OzQT7UmzwAAAIY"] [Tue Aug 18 13:03:01.596908 2026] [security2:error] [pid 123784:tid 123987] [client 34.0.61.43:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCM2wDnJBNj2tDbYYY5QAARWc"] [Tue Aug 18 13:03:01.597447 2026] [security2:error] [pid 123784:tid 123987] [client 34.0.61.43:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZNQAARTU"] [Tue Aug 18 13:03:01.600561 2026] [security2:error] [pid 139043:tid 139265] [client 20.116.17.175:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um0AAAAOE"] [Tue Aug 18 13:03:01.611965 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:01.612450 2026] [authz_core:error] [pid 123784:tid 123835] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:01.636299 2026] [security2:error] [pid 123784:tid 124023] [client 172.182.217.32:21840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/system.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZRwAAAGk"] [Tue Aug 18 13:03:01.640616 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.154.236:40248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/index/function.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um0QAAAMw"] [Tue Aug 18 13:03:01.642942 2026] [security2:error] [pid 123784:tid 124012] [client 20.25.139.174:4519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wk/index.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZSAAAAF4"] [Tue Aug 18 13:03:01.646006 2026] [security2:error] [pid 139043:tid 139277] [client 20.250.13.23:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/tools.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um0gAAAO0"] [Tue Aug 18 13:03:01.668904 2026] [security2:error] [pid 139043:tid 139292] [client 20.65.69.59:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/an.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um1gAAAPw"] [Tue Aug 18 13:03:01.697650 2026] [security2:error] [pid 139043:tid 139207] [client 223.185.37.47:16606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um1wAAAKc"] [Tue Aug 18 13:03:01.697804 2026] [security2:error] [pid 139043:tid 139207] [client 223.185.37.47:16606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um1wAAAKc"] [Tue Aug 18 13:03:01.699164 2026] [security2:error] [pid 139043:tid 139218] [client 20.65.105.233:12600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/nhr.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um2AAAALI"] [Tue Aug 18 13:03:01.712239 2026] [security2:error] [pid 123784:tid 123941] [client 20.163.43.14:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZSgAAABc"] [Tue Aug 18 13:03:01.721699 2026] [security2:error] [pid 123784:tid 123952] [client 46.232.235.4:61462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "blog.sobanheiras.com.br"] [uri "/"] [unique_id "aoSCNWwDnJBNj2tDbYYZSwAAACI"] [Tue Aug 18 13:03:01.739989 2026] [security2:error] [pid 139043:tid 139214] [client 158.23.17.4:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/an.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um2QAAAK4"] [Tue Aug 18 13:03:01.746446 2026] [security2:error] [pid 139043:tid 139299] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/error1.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um2wAAAQM"] [Tue Aug 18 13:03:01.778296 2026] [security2:error] [pid 139043:tid 139258] [client 20.151.109.219:21926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gz.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um3AAAANo"] [Tue Aug 18 13:03:01.798136 2026] [security2:error] [pid 123784:tid 124018] [client 172.182.200.96:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZTAAAAGQ"] [Tue Aug 18 13:03:01.827297 2026] [security2:error] [pid 123784:tid 124020] [client 213.202.253.4:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZZQAAAGY"], referer: www.google.com [Tue Aug 18 13:03:01.858217 2026] [security2:error] [pid 139043:tid 139241] [client 4.223.113.180:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um3gAAAMk"] [Tue Aug 18 13:03:01.862180 2026] [security2:error] [pid 139043:tid 139229] [client 4.232.151.198:10394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um3wAAAL0"] [Tue Aug 18 13:03:01.910073 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:01.910365 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:01.922320 2026] [security2:error] [pid 139043:tid 139217] [client 20.25.139.174:2182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wap.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um4gAAALE"] [Tue Aug 18 13:03:01.939885 2026] [security2:error] [pid 139043:tid 139220] [client 20.65.105.233:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um4wAAALQ"] [Tue Aug 18 13:03:01.957848 2026] [security2:error] [pid 139043:tid 139269] [client 20.80.111.3:30023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/themes/index.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um5AAAAOU"] [Tue Aug 18 13:03:01.962787 2026] [security2:error] [pid 123784:tid 123974] [client 20.65.69.59:9670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sy.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZsAAAADg"] [Tue Aug 18 13:03:01.970977 2026] [security2:error] [pid 139043:tid 139213] [client 34.0.61.43:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um3QAArXc"] [Tue Aug 18 13:03:01.971570 2026] [security2:error] [pid 123784:tid 123925] [client 34.0.61.43:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZqgAAByU"] [Tue Aug 18 13:03:01.974831 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:9767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xx.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um5QAAAOw"] [Tue Aug 18 13:03:01.976774 2026] [security2:error] [pid 139043:tid 139257] [client 40.74.65.169:44171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/new.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um5wAAANk"] [Tue Aug 18 13:03:01.996860 2026] [security2:error] [pid 139043:tid 139279] [client 52.173.121.69:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCNf2v-lWn9OzQT7Um6QAAAO8"] [Tue Aug 18 13:03:02.007028 2026] [security2:error] [pid 139043:tid 139238] [client 213.35.127.232:59042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um6gAAAMY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:02.055577 2026] [security2:error] [pid 123784:tid 124028] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/155.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZswAAAG4"] [Tue Aug 18 13:03:02.056360 2026] [security2:error] [pid 139043:tid 139237] [client 20.118.133.132:56276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/sky.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um7AAAAMU"] [Tue Aug 18 13:03:02.111042 2026] [security2:error] [pid 139043:tid 139223] [client 132.196.30.78:15042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/gg.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um7gAAALc"] [Tue Aug 18 13:03:02.125179 2026] [security2:error] [pid 123784:tid 124026] [client 172.182.217.32:21884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZtQAAAGw"] [Tue Aug 18 13:03:02.130047 2026] [security2:error] [pid 139043:tid 139219] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fasx.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um8gAAALM"] [Tue Aug 18 13:03:02.133811 2026] [security2:error] [pid 139043:tid 139192] [client 40.74.65.169:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um8wAAAJg"] [Tue Aug 18 13:03:02.156644 2026] [security2:error] [pid 139043:tid 139209] [client 20.25.139.174:4604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/about.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um9QAAAKk"] [Tue Aug 18 13:03:02.160767 2026] [security2:error] [pid 139043:tid 139273] [client 34.156.195.117:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.195.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gigapixelhost.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCNv2v-lWn9OzQT7Um9wAAAOk"] [Tue Aug 18 13:03:02.180423 2026] [security2:error] [pid 139043:tid 139173] [client 20.65.105.233:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ws79.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um-AAAAIU"] [Tue Aug 18 13:03:02.181405 2026] [security2:error] [pid 123784:tid 124044] [client 168.62.48.100:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/zugvi.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZtgAAAH4"] [Tue Aug 18 13:03:02.186085 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/loader.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um-QAAANA"] [Tue Aug 18 13:03:02.191684 2026] [security2:error] [pid 139043:tid 139274] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-good.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um-gAAAOo"] [Tue Aug 18 13:03:02.212501 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:02.212790 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:02.241193 2026] [security2:error] [pid 123784:tid 123961] [client 128.140.41.193:64154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pan.com.br"] [uri "/server.php"] [unique_id "aoSCNWwDnJBNj2tDbYYZrAAAACs"], referer: https://pan.com.br/?lang=pt-br [Tue Aug 18 13:03:02.250076 2026] [security2:error] [pid 139043:tid 139199] [client 52.173.121.69:41269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/rymmm.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um_AAAAJ8"] [Tue Aug 18 13:03:02.258698 2026] [security2:error] [pid 139043:tid 139231] [client 20.51.153.15:9728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/conn-test.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um_QAAAL8"] [Tue Aug 18 13:03:02.259659 2026] [security2:error] [pid 139043:tid 139187] [client 20.65.69.59:48465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/57.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um_gAAAJM"] [Tue Aug 18 13:03:02.262857 2026] [security2:error] [pid 139043:tid 139191] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/zxin.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um_wAAAJc"] [Tue Aug 18 13:03:02.267648 2026] [security2:error] [pid 123784:tid 124031] [client 172.182.200.96:1992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZuQAAAHE"] [Tue Aug 18 13:03:02.270990 2026] [security2:error] [pid 139043:tid 139176] [client 20.116.17.175:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-the.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnAAAAAIg"] [Tue Aug 18 13:03:02.279481 2026] [security2:error] [pid 123784:tid 123975] [client 34.156.195.117:63064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.gigapixelhost.com.br"] [uri "/aws/s3/credentials.bak"] [unique_id "aoSCNmwDnJBNj2tDbYYZuwAAADk"] [Tue Aug 18 13:03:02.292064 2026] [security2:error] [pid 139043:tid 139291] [client 34.0.61.43:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCNv2v-lWn9OzQT7Um9gAA-xI"] [Tue Aug 18 13:03:02.301090 2026] [security2:error] [pid 123784:tid 124021] [client 20.250.13.23:4051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/txets.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZvAAAAGc"] [Tue Aug 18 13:03:02.319728 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:38293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/tt.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnAwAAANs"] [Tue Aug 18 13:03:02.375496 2026] [security2:error] [pid 123784:tid 123935] [client 20.163.43.14:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZvQAAABE"] [Tue Aug 18 13:03:02.404021 2026] [security2:error] [pid 123784:tid 124041] [client 197.184.64.235:41973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZwAAAAHs"] [Tue Aug 18 13:03:02.404118 2026] [security2:error] [pid 123784:tid 124041] [client 197.184.64.235:41973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZwAAAAHs"] [Tue Aug 18 13:03:02.421155 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:33503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sy.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnBQAAAQQ"] [Tue Aug 18 13:03:02.432975 2026] [security2:error] [pid 123784:tid 123957] [client 20.65.105.233:12784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/rtx.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZwgAAACc"] [Tue Aug 18 13:03:02.436742 2026] [security2:error] [pid 139043:tid 139285] [client 158.23.17.4:55228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jp.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnBgAAAPU"] [Tue Aug 18 13:03:02.474286 2026] [security2:error] [pid 139043:tid 139296] [client 20.25.139.174:2387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnBwAAAQA"] [Tue Aug 18 13:03:02.499595 2026] [security2:error] [pid 139043:tid 139242] [client 4.232.151.198:10379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnCAAAAMo"] [Tue Aug 18 13:03:02.519831 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:02.520091 2026] [authz_core:error] [pid 123784:tid 123803] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:02.540747 2026] [security2:error] [pid 139043:tid 139266] [client 168.62.48.100:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wsrer.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnCQAAAOI"] [Tue Aug 18 13:03:02.540796 2026] [security2:error] [pid 139043:tid 139264] [client 68.155.154.236:40196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnCgAAAOA"] [Tue Aug 18 13:03:02.548176 2026] [security2:error] [pid 139043:tid 139277] [client 20.65.69.59:43321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ah.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnCwAAAO0"] [Tue Aug 18 13:03:02.549711 2026] [security2:error] [pid 139043:tid 139270] [client 20.80.111.3:39895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/alfa-rex.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnDAAAAOY"] [Tue Aug 18 13:03:02.585742 2026] [security2:error] [pid 123784:tid 124002] [client 20.116.17.175:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZxgAAAFQ"] [Tue Aug 18 13:03:02.600651 2026] [security2:error] [pid 123784:tid 124037] [client 20.206.73.37:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZxwAAAHc"] [Tue Aug 18 13:03:02.611253 2026] [security2:error] [pid 123784:tid 123951] [client 172.182.217.32:21866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSCNmwDnJBNj2tDbYYZyAAAACE"] [Tue Aug 18 13:03:02.613100 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:9764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fg.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnDwAAAPw"] [Tue Aug 18 13:03:02.638676 2026] [security2:error] [pid 139043:tid 139228] [client 172.182.200.96:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnEAAAALw"] [Tue Aug 18 13:03:02.673014 2026] [security2:error] [pid 139043:tid 139177] [client 40.74.65.169:44167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/apreset.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnEQAAAIk"] [Tue Aug 18 13:03:02.682307 2026] [security2:error] [pid 139043:tid 139214] [client 20.65.105.233:12557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/end.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnEgAAAK4"] [Tue Aug 18 13:03:02.684897 2026] [security2:error] [pid 139043:tid 139244] [client 20.25.139.174:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/term.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnEwAAAMw"] [Tue Aug 18 13:03:02.694218 2026] [security2:error] [pid 139043:tid 139185] [client 20.116.17.175:56087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/zero.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnFAAAAJE"] [Tue Aug 18 13:03:02.698253 2026] [security2:error] [pid 139043:tid 139240] [client 20.163.43.14:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/about.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnFQAAAMg"] [Tue Aug 18 13:03:02.708295 2026] [security2:error] [pid 123784:tid 124009] [client 4.223.113.180:12102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/storage/rip.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZywAAAFs"] [Tue Aug 18 13:03:02.777083 2026] [security2:error] [pid 139043:tid 139283] [client 196.12.128.158:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnFwAAAPM"] [Tue Aug 18 13:03:02.777186 2026] [security2:error] [pid 139043:tid 139283] [client 196.12.128.158:62035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnFwAAAPM"] [Tue Aug 18 13:03:02.799069 2026] [security2:error] [pid 139043:tid 139268] [client 20.65.69.59:48488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vw.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnGQAAAOQ"] [Tue Aug 18 13:03:02.802429 2026] [security2:error] [pid 123784:tid 123926] [client 52.173.121.69:62881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZzgAAAAg"] [Tue Aug 18 13:03:02.812270 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:02.812534 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:02.831070 2026] [security2:error] [pid 139043:tid 139269] [client 158.23.17.4:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/57.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnHAAAAOU"] [Tue Aug 18 13:03:02.835332 2026] [security2:error] [pid 139043:tid 139257] [client 40.74.65.169:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/site.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnHQAAANk"] [Tue Aug 18 13:03:02.850677 2026] [security2:error] [pid 139043:tid 139195] [client 142.44.233.17:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.transitalian.com.br"] [uri "/robots.txt"] [unique_id "aoSCNv2v-lWn9OzQT7UnHgAAAJs"] [Tue Aug 18 13:03:02.850765 2026] [security2:error] [pid 139043:tid 139195] [client 142.44.233.17:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitalian.com.br"] [uri "/robots.txt"] [unique_id "aoSCNv2v-lWn9OzQT7UnHgAAAJs"] [Tue Aug 18 13:03:02.851740 2026] [security2:error] [pid 123784:tid 124004] [client 20.51.153.15:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ve.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZ0AAAAFY"] [Tue Aug 18 13:03:02.923086 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.105.233:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiafloreseplantas.com.br"] [uri "/ae.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnIgAAALA"] [Tue Aug 18 13:03:02.928017 2026] [security2:error] [pid 139043:tid 139260] [client 20.250.13.23:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/u.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnIwAAANw"] [Tue Aug 18 13:03:02.938565 2026] [security2:error] [pid 123784:tid 124040] [client 168.62.48.100:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZ0gAAAHo"] [Tue Aug 18 13:03:02.978939 2026] [security2:error] [pid 123784:tid 123979] [client 158.23.17.4:31929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/mq.php"] [unique_id "aoSCNmwDnJBNj2tDbYYZ4AAAAD0"] [Tue Aug 18 13:03:02.981907 2026] [security2:error] [pid 139043:tid 139281] [client 20.116.17.175:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/xwpg.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnJAAAAPE"] [Tue Aug 18 13:03:03.015896 2026] [security2:error] [pid 139043:tid 139213] [client 20.25.139.174:2223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/bgymj.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnJgAAAK0"] [Tue Aug 18 13:03:03.032880 2026] [security2:error] [pid 139043:tid 139258] [client 213.35.127.232:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnKAAAANo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:03.079434 2026] [security2:error] [pid 139043:tid 139245] [client 144.76.22.51:44010] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCNv2v-lWn9OzQT7UnHwAAAM0"], referer: http://www.agrimotor.com.br/ [Tue Aug 18 13:03:03.089643 2026] [security2:error] [pid 123784:tid 123931] [client 20.163.43.14:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCN2wDnJBNj2tDbYYZ8gAAAA0"] [Tue Aug 18 13:03:03.100839 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:9546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ia.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnKQAAAKQ"] [Tue Aug 18 13:03:03.106376 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.217.32:21825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/colors.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnKgAAAOs"] [Tue Aug 18 13:03:03.111732 2026] [security2:error] [pid 139043:tid 139202] [client 20.65.69.59:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lj.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnKwAAAKI"] [Tue Aug 18 13:03:03.114793 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:03.115037 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:03.138522 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.200.96:15627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnLAAAANA"] [Tue Aug 18 13:03:03.141385 2026] [security2:error] [pid 139043:tid 139274] [client 132.196.30.78:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/class.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnLQAAAOo"] [Tue Aug 18 13:03:03.157198 2026] [security2:error] [pid 139043:tid 139226] [client 20.80.111.3:41019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnLgAAALo"] [Tue Aug 18 13:03:03.159318 2026] [security2:error] [pid 139043:tid 139183] [client 4.232.151.198:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/import.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnLwAAAI8"] [Tue Aug 18 13:03:03.195651 2026] [security2:error] [pid 139043:tid 139201] [client 158.23.17.4:47878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/eq.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnMAAAAKE"] [Tue Aug 18 13:03:03.207618 2026] [security2:error] [pid 123784:tid 123980] [client 20.251.48.93:37411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rhemahost.com.br"] [uri "/ajax.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaAgAAAD4"] [Tue Aug 18 13:03:03.267643 2026] [security2:error] [pid 139043:tid 139297] [client 52.173.121.69:10874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/lddxs.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnNAAAAQE"] [Tue Aug 18 13:03:03.272357 2026] [security2:error] [pid 123784:tid 123932] [client 20.25.139.174:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ioxi-o.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaBwAAAA4"] [Tue Aug 18 13:03:03.311423 2026] [security2:error] [pid 139043:tid 139287] [client 20.151.109.219:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nf.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnNQAAAPc"] [Tue Aug 18 13:03:03.346129 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.154.236:41497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnNgAAAMM"] [Tue Aug 18 13:03:03.355376 2026] [security2:error] [pid 123784:tid 123960] [client 52.173.121.69:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaDAAAACo"] [Tue Aug 18 13:03:03.366671 2026] [security2:error] [pid 139043:tid 139186] [client 40.74.65.169:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/1mage.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnNwAAAJI"] [Tue Aug 18 13:03:03.406178 2026] [security2:error] [pid 139043:tid 139253] [client 20.65.69.59:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kh.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnOAAAANU"] [Tue Aug 18 13:03:03.415135 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:03.415413 2026] [authz_core:error] [pid 123784:tid 123876] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:03.417537 2026] [security2:error] [pid 123784:tid 123924] [client 20.163.43.14:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/f35.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaDgAAAAY"] [Tue Aug 18 13:03:03.439999 2026] [security2:error] [pid 139043:tid 139296] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/pass4.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnOwAAAQA"] [Tue Aug 18 13:03:03.457408 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:9544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kn.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnPQAAAIw"] [Tue Aug 18 13:03:03.512948 2026] [security2:error] [pid 123784:tid 123941] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-conflg.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaEAAAABc"] [Tue Aug 18 13:03:03.515259 2026] [security2:error] [pid 139043:tid 139264] [client 168.62.48.100:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/yxijx.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnPgAAAOA"] [Tue Aug 18 13:03:03.559388 2026] [security2:error] [pid 123784:tid 123996] [client 68.155.154.236:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/Cachex.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaFAAAAE4"] [Tue Aug 18 13:03:03.559428 2026] [security2:error] [pid 123784:tid 123943] [client 40.74.65.169:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/ccc.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaEwAAABk"] [Tue Aug 18 13:03:03.573216 2026] [security2:error] [pid 123784:tid 123939] [client 20.25.139.174:2216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/aa.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaFQAAABU"] [Tue Aug 18 13:03:03.602484 2026] [security2:error] [pid 123784:tid 124023] [client 172.182.217.32:21878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/updates.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaFgAAAGk"] [Tue Aug 18 13:03:03.616893 2026] [security2:error] [pid 139043:tid 139243] [client 20.80.111.3:41012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/wp-pridmag/layout.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnQAAAAMs"] [Tue Aug 18 13:03:03.624907 2026] [security2:error] [pid 139043:tid 139300] [client 20.250.13.23:3444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/ultra.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnQQAAAQQ"] [Tue Aug 18 13:03:03.630349 2026] [security2:error] [pid 123784:tid 124018] [client 172.182.200.96:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/first.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaGAAAAGQ"] [Tue Aug 18 13:03:03.646947 2026] [security2:error] [pid 123784:tid 123938] [client 158.23.17.4:9311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ah.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaGQAAABQ"] [Tue Aug 18 13:03:03.682759 2026] [security2:error] [pid 139043:tid 139218] [client 20.65.69.59:48460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/jb.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnQwAAALI"] [Tue Aug 18 13:03:03.706016 2026] [security2:error] [pid 139043:tid 139290] [client 20.116.17.175:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/dex.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnRAAAAPo"] [Tue Aug 18 13:03:03.716518 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:03.716809 2026] [authz_core:error] [pid 123784:tid 123869] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:03.720614 2026] [security2:error] [pid 139043:tid 139299] [client 20.116.17.175:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/002.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnRQAAAQM"] [Tue Aug 18 13:03:03.767825 2026] [security2:error] [pid 139043:tid 139228] [client 20.25.139.174:4497] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.advocaciasc.com"] [uri "/1.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnRwAAALw"] [Tue Aug 18 13:03:03.767936 2026] [security2:error] [pid 139043:tid 139228] [client 20.25.139.174:4497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/1.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnRwAAALw"] [Tue Aug 18 13:03:03.770706 2026] [security2:error] [pid 123784:tid 123998] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/z.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaHAAAAFA"] [Tue Aug 18 13:03:03.782137 2026] [security2:error] [pid 123784:tid 124020] [client 20.226.36.136:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/zjggu.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaHQAAAGY"] [Tue Aug 18 13:03:03.784589 2026] [security2:error] [pid 139043:tid 139278] [client 4.232.151.198:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/cropper.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnSAAAAO4"] [Tue Aug 18 13:03:03.803566 2026] [security2:error] [pid 123784:tid 123947] [client 20.51.153.15:9791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wm.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaHwAAAB0"] [Tue Aug 18 13:03:03.813052 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/13.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnSQAAAME"] [Tue Aug 18 13:03:03.823512 2026] [security2:error] [pid 139043:tid 139239] [client 158.23.17.4:54767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ep.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnSgAAAMc"] [Tue Aug 18 13:03:03.844373 2026] [security2:error] [pid 139043:tid 139236] [client 20.206.73.37:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/mosty.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnSwAAAMQ"] [Tue Aug 18 13:03:03.847513 2026] [security2:error] [pid 123784:tid 123944] [client 52.173.121.69:9484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCN2wDnJBNj2tDbYYaIAAAABo"] [Tue Aug 18 13:03:03.951510 2026] [security2:error] [pid 139043:tid 139276] [client 52.173.121.69:10875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/zjggu.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnTwAAAOw"] [Tue Aug 18 13:03:03.997962 2026] [security2:error] [pid 139043:tid 139234] [client 20.65.69.59:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/do.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnUgAAAMI"] [Tue Aug 18 13:03:04.020539 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:04.020988 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:04.022946 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnVAAAALE"] [Tue Aug 18 13:03:04.038499 2026] [security2:error] [pid 139043:tid 139237] [client 20.51.153.15:9745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ac.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnVQAAAMU"] [Tue Aug 18 13:03:04.046539 2026] [security2:error] [pid 123784:tid 124044] [client 40.74.65.169:44245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/imsc.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaJgAAAH4"] [Tue Aug 18 13:03:04.047142 2026] [security2:error] [pid 139043:tid 139177] [client 213.35.127.232:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnVgAAAIk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:04.054607 2026] [security2:error] [pid 123784:tid 123933] [client 20.80.111.3:39889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaJwAAAA8"] [Tue Aug 18 13:03:04.074111 2026] [security2:error] [pid 139043:tid 139222] [client 20.25.139.174:2385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnVwAAALY"] [Tue Aug 18 13:03:04.092073 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:6604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/inputs.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnWQAAAPQ"] [Tue Aug 18 13:03:04.097665 2026] [security2:error] [pid 139043:tid 139220] [client 172.182.217.32:21562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnWgAAALQ"] [Tue Aug 18 13:03:04.165262 2026] [security2:error] [pid 139043:tid 139223] [client 168.62.48.100:4167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnWwAAALc"] [Tue Aug 18 13:03:04.203658 2026] [security2:error] [pid 123784:tid 124034] [client 158.23.17.4:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vw.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaKgAAAHQ"] [Tue Aug 18 13:03:04.245387 2026] [security2:error] [pid 139043:tid 139192] [client 40.74.65.169:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/admin.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnXQAAAJg"] [Tue Aug 18 13:03:04.250690 2026] [security2:error] [pid 123784:tid 123961] [client 172.182.200.96:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaKwAAACs"] [Tue Aug 18 13:03:04.251994 2026] [security2:error] [pid 139043:tid 139250] [client 20.250.13.23:3455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/un.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnXwAAANI"] [Tue Aug 18 13:03:04.288379 2026] [security2:error] [pid 139043:tid 139281] [client 20.25.139.174:4491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/alfa.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnYQAAAPE"] [Tue Aug 18 13:03:04.321258 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:04.321683 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:04.337255 2026] [security2:error] [pid 139043:tid 139275] [client 20.65.69.59:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/yw.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnYwAAAOs"] [Tue Aug 18 13:03:04.355494 2026] [security2:error] [pid 123784:tid 124021] [client 52.173.121.69:54233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaMAAAAGc"] [Tue Aug 18 13:03:04.432940 2026] [security2:error] [pid 123784:tid 123949] [client 20.116.17.175:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/xyn.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaNAAAAB8"] [Tue Aug 18 13:03:04.438149 2026] [security2:error] [pid 139043:tid 139198] [client 144.76.22.51:44026] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnUwAAAJ4"], referer: https://www.agrimotor.com.br/ [Tue Aug 18 13:03:04.447967 2026] [security2:error] [pid 139043:tid 139252] [client 4.232.151.198:22208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/images/xmrlpc.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnZQAAANQ"] [Tue Aug 18 13:03:04.451743 2026] [security2:error] [pid 123784:tid 124002] [client 20.51.153.15:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/yz.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaNgAAAFQ"] [Tue Aug 18 13:03:04.467971 2026] [security2:error] [pid 123784:tid 124037] [client 191.237.254.161:56137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaNwAAAHc"] [Tue Aug 18 13:03:04.494321 2026] [security2:error] [pid 139043:tid 139202] [client 20.80.111.3:39930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/updraft/plugins-old/updraftplus/templates/wp-admin/data.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnZwAAAKI"] [Tue Aug 18 13:03:04.530917 2026] [security2:error] [pid 139043:tid 139293] [client 191.237.254.161:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnaAAAAP0"] [Tue Aug 18 13:03:04.536588 2026] [security2:error] [pid 123784:tid 124001] [client 132.196.30.78:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/flower.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaOwAAAFM"] [Tue Aug 18 13:03:04.582108 2026] [security2:error] [pid 123784:tid 123946] [client 20.25.139.174:2406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/bolt.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaPQAAABw"] [Tue Aug 18 13:03:04.585797 2026] [security2:error] [pid 123784:tid 124032] [client 172.182.217.32:21862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-index.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaPgAAAHI"] [Tue Aug 18 13:03:04.592041 2026] [security2:error] [pid 123784:tid 123927] [client 158.23.17.4:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/so.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaPwAAAAk"] [Tue Aug 18 13:03:04.599249 2026] [security2:error] [pid 123784:tid 123973] [client 191.237.254.161:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaQAAAADc"] [Tue Aug 18 13:03:04.618364 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:04.618627 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:04.631645 2026] [security2:error] [pid 123784:tid 123988] [client 52.173.121.69:39378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaRAAAAEY"] [Tue Aug 18 13:03:04.636851 2026] [security2:error] [pid 123784:tid 124043] [client 20.100.169.31:32710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ebenezerpocos.com.br"] [uri "/404.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaRQAAAH0"] [Tue Aug 18 13:03:04.652429 2026] [security2:error] [pid 139043:tid 139289] [client 20.206.73.37:16738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnaQAAAPk"] [Tue Aug 18 13:03:04.675811 2026] [security2:error] [pid 139043:tid 139286] [client 172.182.200.96:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnagAAAPY"] [Tue Aug 18 13:03:04.700307 2026] [security2:error] [pid 139043:tid 139235] [client 191.237.254.161:53563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/av.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnawAAAMM"] [Tue Aug 18 13:03:04.713309 2026] [security2:error] [pid 139043:tid 139210] [client 20.51.153.15:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kj.php"] [unique_id "aoSCOP2v-lWn9OzQT7UnbQAAAKo"] [Tue Aug 18 13:03:04.740148 2026] [security2:error] [pid 139043:tid 139179] [client 20.65.69.59:48484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/qh.php"] [unique_id "aoSCOP2v-lWn9OzQT7UncAAAAIs"] [Tue Aug 18 13:03:04.749882 2026] [security2:error] [pid 123784:tid 123969] [client 40.74.65.169:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaSwAAADM"] [Tue Aug 18 13:03:04.773894 2026] [security2:error] [pid 123784:tid 123921] [client 20.25.139.174:4518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/edit.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaTQAAAAM"] [Tue Aug 18 13:03:04.776127 2026] [security2:error] [pid 123784:tid 124005] [client 191.237.254.161:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/images.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaTgAAAFc"] [Tue Aug 18 13:03:04.784933 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/alfa.php"] [unique_id "aoSCOP2v-lWn9OzQT7UncQAAAPU"] [Tue Aug 18 13:03:04.813150 2026] [security2:error] [pid 123784:tid 123818] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaUQAAfx0"] [Tue Aug 18 13:03:04.813286 2026] [security2:error] [pid 123784:tid 124045] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaUQAAfx0"] [Tue Aug 18 13:03:04.875597 2026] [security2:error] [pid 123784:tid 124010] [client 142.44.233.141:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.transitalian.com.br"] [uri "/"] [unique_id "aoSCOGwDnJBNj2tDbYYaVAAAAFw"] [Tue Aug 18 13:03:04.875714 2026] [security2:error] [pid 123784:tid 124010] [client 142.44.233.141:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitalian.com.br"] [uri "/"] [unique_id "aoSCOGwDnJBNj2tDbYYaVAAAAFw"] [Tue Aug 18 13:03:04.892407 2026] [security2:error] [pid 123784:tid 124039] [client 52.173.121.69:54179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaVgAAAHk"] [Tue Aug 18 13:03:04.894895 2026] [security2:error] [pid 123784:tid 124029] [client 191.237.254.161:51479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ops.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaVwAAAG8"] [Tue Aug 18 13:03:04.895097 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.13.23:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/up.php"] [unique_id "aoSCOP2v-lWn9OzQT7UndAAAAIc"] [Tue Aug 18 13:03:04.911757 2026] [security2:error] [pid 139043:tid 139261] [client 86.120.159.145:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCOP2v-lWn9OzQT7UndQAAAN0"] [Tue Aug 18 13:03:04.911885 2026] [security2:error] [pid 139043:tid 139261] [client 86.120.159.145:57960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCOP2v-lWn9OzQT7UndQAAAN0"] [Tue Aug 18 13:03:04.920042 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:04.920321 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:04.935586 2026] [security2:error] [pid 123784:tid 123980] [client 40.74.65.169:55273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/reviall.php"] [unique_id "aoSCOGwDnJBNj2tDbYYaXgAAAD4"] [Tue Aug 18 13:03:04.954558 2026] [security2:error] [pid 139043:tid 139280] [client 34.156.195.117:62858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/aws/iam/temporary-credentials"] [unique_id "aoSCOP2v-lWn9OzQT7UndgAAAPA"] [Tue Aug 18 13:03:04.964615 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:9539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vg.php"] [unique_id "aoSCOP2v-lWn9OzQT7UneAAAAPw"] [Tue Aug 18 13:03:04.970379 2026] [security2:error] [pid 139043:tid 139225] [client 74.7.175.180:55238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "clinlead.com.br"] [uri "/index.php"] [unique_id "aoSCN_2v-lWn9OzQT7UnTgAAuWw"] [Tue Aug 18 13:03:04.985601 2026] [security2:error] [pid 139043:tid 139300] [client 20.116.17.175:22993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCOP2v-lWn9OzQT7UneQAAAQQ"] [Tue Aug 18 13:03:05.009022 2026] [security2:error] [pid 123784:tid 124033] [client 20.116.17.175:53141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/zxz.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaYQAAAHM"] [Tue Aug 18 13:03:05.029559 2026] [security2:error] [pid 139043:tid 139288] [client 20.65.69.59:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/r.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnewAAAPg"] [Tue Aug 18 13:03:05.064877 2026] [security2:error] [pid 139043:tid 139267] [client 213.35.127.232:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnfAAAAOM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:05.069114 2026] [security2:error] [pid 123784:tid 123924] [client 158.23.17.4:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lj.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaYgAAAAY"] [Tue Aug 18 13:03:05.069171 2026] [security2:error] [pid 139043:tid 139266] [client 4.232.151.198:22259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnfQAAAOI"] [Tue Aug 18 13:03:05.078962 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.217.32:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfanew.php7"] [unique_id "aoSCOf2v-lWn9OzQT7UnfgAAAJ0"] [Tue Aug 18 13:03:05.087398 2026] [security2:error] [pid 123784:tid 123953] [client 20.25.139.174:2198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/bthil.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaZAAAACM"] [Tue Aug 18 13:03:05.091225 2026] [security2:error] [pid 123784:tid 123970] [client 20.80.111.3:40982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaZQAAADQ"] [Tue Aug 18 13:03:05.108953 2026] [security2:error] [pid 123784:tid 123941] [client 20.163.43.14:6597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/lock360.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaZwAAABc"] [Tue Aug 18 13:03:05.116168 2026] [security2:error] [pid 139043:tid 139244] [client 168.62.48.100:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/jrpga.php"] [unique_id "aoSCOf2v-lWn9OzQT7UngAAAAMw"] [Tue Aug 18 13:03:05.137640 2026] [security2:error] [pid 139043:tid 139215] [client 34.156.195.117:63048] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSCOf2v-lWn9OzQT7UngQAAAK8"] [Tue Aug 18 13:03:05.141391 2026] [security2:error] [pid 139043:tid 139092] [remote 212.29.237.5:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnggAA1TA"] [Tue Aug 18 13:03:05.205978 2026] [security2:error] [pid 123784:tid 123972] [client 20.51.153.15:9759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sm.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaaQAAADY"] [Tue Aug 18 13:03:05.226001 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:05.226467 2026] [authz_core:error] [pid 123784:tid 123799] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:05.285604 2026] [security2:error] [pid 123784:tid 124020] [client 68.155.154.236:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCOWwDnJBNj2tDbYYabAAAAGY"] [Tue Aug 18 13:03:05.297411 2026] [security2:error] [pid 139043:tid 139247] [client 20.25.139.174:4733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/elp.php"] [unique_id "aoSCOf2v-lWn9OzQT7UngwAAAM8"] [Tue Aug 18 13:03:05.325667 2026] [security2:error] [pid 123784:tid 123974] [client 20.226.36.136:57815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCOWwDnJBNj2tDbYYabwAAADg"] [Tue Aug 18 13:03:05.371229 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:32517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/10.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnhQAAANg"] [Tue Aug 18 13:03:05.371829 2026] [security2:error] [pid 139043:tid 139276] [client 20.65.69.59:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/17.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnhgAAAOw"] [Tue Aug 18 13:03:05.376783 2026] [security2:error] [pid 139043:tid 139229] [client 132.196.30.78:25723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/motu.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnhwAAAL0"] [Tue Aug 18 13:03:05.387111 2026] [security2:error] [pid 123784:tid 124028] [client 158.23.17.4:17547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rf.php"] [unique_id "aoSCOWwDnJBNj2tDbYYacQAAAG4"] [Tue Aug 18 13:03:05.405110 2026] [security2:error] [pid 139043:tid 139269] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnhAAA5WI"] [Tue Aug 18 13:03:05.405787 2026] [security2:error] [pid 123784:tid 123936] [client 46.232.235.4:61478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "blog.sobanheiras.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSCOWwDnJBNj2tDbYYabQAAABI"] [Tue Aug 18 13:03:05.429706 2026] [security2:error] [pid 123784:tid 123954] [client 40.74.65.169:44260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/qlex1.php"] [unique_id "aoSCOWwDnJBNj2tDbYYacwAAACQ"] [Tue Aug 18 13:03:05.440506 2026] [security2:error] [pid 139043:tid 139177] [client 20.163.43.14:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/flower.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnigAAAIk"] [Tue Aug 18 13:03:05.466561 2026] [security2:error] [pid 139043:tid 139294] [client 52.173.121.69:27732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCOf2v-lWn9OzQT7UniwAAAP4"] [Tue Aug 18 13:03:05.468221 2026] [security2:error] [pid 139043:tid 139260] [client 20.116.17.175:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-good.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnjAAAANw"] [Tue Aug 18 13:03:05.470410 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.200.96:15643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnjQAAAJQ"] [Tue Aug 18 13:03:05.517406 2026] [security2:error] [pid 139043:tid 139190] [client 34.156.195.117:62840] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSCOf2v-lWn9OzQT7UnkAAAAJY"] [Tue Aug 18 13:03:05.523758 2026] [security2:error] [pid 139043:tid 139238] [client 20.80.111.3:41000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnkQAAAMY"] [Tue Aug 18 13:03:05.529834 2026] [authz_core:error] [pid 123784:tid 123819] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:05.530094 2026] [authz_core:error] [pid 123784:tid 123819] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:05.545941 2026] [security2:error] [pid 123784:tid 123962] [client 20.51.153.15:9512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/28.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaeAAAACw"] [Tue Aug 18 13:03:05.560816 2026] [security2:error] [pid 139043:tid 139250] [client 52.173.121.69:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnkwAAANI"] [Tue Aug 18 13:03:05.575783 2026] [security2:error] [pid 139043:tid 139237] [client 172.182.217.32:21833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/locale.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnmgAAAMU"] [Tue Aug 18 13:03:05.623658 2026] [cgid:error] [pid 139043:tid 139222] [client 20.25.139.174:2384] AH01265: stderr from /home1/gfrison965/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:03:05.627282 2026] [security2:error] [pid 123784:tid 123964] [client 40.74.65.169:51686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/nope.php"] [unique_id "aoSCOWwDnJBNj2tDbYYaegAAAC4"] [Tue Aug 18 13:03:05.686165 2026] [security2:error] [pid 139043:tid 139275] [client 158.23.17.4:9288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kh.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnnQAAAOs"] [Tue Aug 18 13:03:05.688290 2026] [security2:error] [pid 139043:tid 139248] [client 20.65.69.59:27876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ev.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnngAAANA"] [Tue Aug 18 13:03:05.735995 2026] [security2:error] [pid 139043:tid 139212] [client 4.232.151.198:10390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/goat.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnnwAAAKw"] [Tue Aug 18 13:03:05.742899 2026] [security2:error] [pid 123784:tid 123975] [client 20.250.13.23:30822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/users.php"] [unique_id "aoSCOWwDnJBNj2tDbYYafwAAADk"] [Tue Aug 18 13:03:05.773094 2026] [security2:error] [pid 123784:tid 123982] [client 20.163.43.14:6649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/13.php"] [unique_id "aoSCOWwDnJBNj2tDbYYagAAAAEA"] [Tue Aug 18 13:03:05.774052 2026] [security2:error] [pid 123784:tid 124044] [client 74.7.175.180:55250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.clinlead.com.br"] [uri "/index.php"] [unique_id "aoSCOWwDnJBNj2tDbYYafAAAfkk"], referer: https://clinlead.com.br/robots.txt [Tue Aug 18 13:03:05.785275 2026] [security2:error] [pid 123784:tid 123933] [client 20.25.139.174:4508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/classwithtostring.php"] [unique_id "aoSCOWwDnJBNj2tDbYYagQAAAA8"] [Tue Aug 18 13:03:05.785863 2026] [security2:error] [pid 139043:tid 139199] [client 20.25.139.174:2384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/x.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnoAAAAJ8"] [Tue Aug 18 13:03:05.790977 2026] [security2:error] [pid 139043:tid 139283] [client 144.76.22.51:44028] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnjgAAAPM"], referer: http://www.agrimotor.com.br/ [Tue Aug 18 13:03:05.823505 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:05.823778 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:05.842294 2026] [security2:error] [pid 123784:tid 124006] [client 4.232.151.198:43126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/info.php"] [unique_id "aoSCOWwDnJBNj2tDbYYahAAAAFg"] [Tue Aug 18 13:03:05.870466 2026] [security2:error] [pid 123784:tid 124041] [client 132.196.30.78:10906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/404.php"] [unique_id "aoSCOWwDnJBNj2tDbYYahQAAAHs"] [Tue Aug 18 13:03:05.918631 2026] [security2:error] [pid 139043:tid 139297] [client 168.62.48.100:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnogAAAQE"] [Tue Aug 18 13:03:05.951084 2026] [security2:error] [pid 139043:tid 139286] [client 20.65.69.59:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xs.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnowAAAPY"] [Tue Aug 18 13:03:05.959738 2026] [security2:error] [pid 139043:tid 139173] [client 20.80.111.3:17966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/api.php"] [unique_id "aoSCOf2v-lWn9OzQT7UnpAAAAIU"] [Tue Aug 18 13:03:06.011224 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/te.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnqAAAAIs"] [Tue Aug 18 13:03:06.066830 2026] [security2:error] [pid 123784:tid 123929] [client 172.182.217.32:21565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wxo.php"] [unique_id "aoSCOmwDnJBNj2tDbYYaiwAAAAs"] [Tue Aug 18 13:03:06.084882 2026] [security2:error] [pid 139043:tid 139226] [client 213.35.127.232:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnqQAAALo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:06.098372 2026] [security2:error] [pid 139043:tid 139242] [client 20.163.43.14:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/cc.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnqwAAAMo"] [Tue Aug 18 13:03:06.118009 2026] [security2:error] [pid 139043:tid 139261] [client 40.74.65.169:38407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/mariju.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnrAAAAN0"] [Tue Aug 18 13:03:06.118171 2026] [security2:error] [pid 123784:tid 124001] [client 172.182.200.96:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/blog/byp.php"] [unique_id "aoSCOmwDnJBNj2tDbYYajwAAAFM"] [Tue Aug 18 13:03:06.124136 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:06.124437 2026] [authz_core:error] [pid 123784:tid 123881] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:06.136686 2026] [security2:error] [pid 139043:tid 139280] [client 34.156.195.117:62960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gigapixelhost.com.br"] [uri "/vendor/.aws/credentials"] [unique_id "aoSCOv2v-lWn9OzQT7UnrgAAAPA"] [Tue Aug 18 13:03:06.149468 2026] [security2:error] [pid 139043:tid 139207] [client 4.223.113.180:17899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/.__info.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnsgAAAKc"] [Tue Aug 18 13:03:06.208862 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:9475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/m.php"] [unique_id "aoSCOv2v-lWn9OzQT7UntAAAANM"] [Tue Aug 18 13:03:06.219608 2026] [security2:error] [pid 139043:tid 139266] [client 158.23.17.4:44513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jb.php"] [unique_id "aoSCOv2v-lWn9OzQT7UntQAAAOI"] [Tue Aug 18 13:03:06.224465 2026] [security2:error] [pid 139043:tid 139218] [client 20.65.69.59:27887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCOv2v-lWn9OzQT7UntgAAALI"] [Tue Aug 18 13:03:06.281850 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:60795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xynz1.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnuAAAAQM"] [Tue Aug 18 13:03:06.301945 2026] [security2:error] [pid 139043:tid 139253] [client 52.173.121.69:31584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/kopyw.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnugAAANU"] [Tue Aug 18 13:03:06.305866 2026] [security2:error] [pid 123784:tid 124004] [client 20.116.17.175:56077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/memberfuns.php"] [unique_id "aoSCOmwDnJBNj2tDbYYalAAAAFY"] [Tue Aug 18 13:03:06.307306 2026] [security2:error] [pid 123784:tid 123988] [client 20.116.17.175:22927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wmore1.php"] [unique_id "aoSCOmwDnJBNj2tDbYYalQAAAEY"] [Tue Aug 18 13:03:06.320576 2026] [security2:error] [pid 139043:tid 139277] [client 20.25.139.174:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/index/function.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnuwAAAO0"] [Tue Aug 18 13:03:06.342200 2026] [security2:error] [pid 139043:tid 139079] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.env"] [unique_id "aoSCOv2v-lWn9OzQT7UnwAAAxyM"] [Tue Aug 18 13:03:06.356635 2026] [security2:error] [pid 139043:tid 139292] [client 4.232.151.198:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/Session.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnwQAAAPw"] [Tue Aug 18 13:03:06.359786 2026] [security2:error] [pid 139043:tid 139185] [client 20.25.139.174:4499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/666.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnwgAAAJE"] [Tue Aug 18 13:03:06.382939 2026] [security2:error] [pid 123784:tid 123946] [client 20.250.13.23:30830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/v.php"] [unique_id "aoSCOmwDnJBNj2tDbYYalwAAABw"] [Tue Aug 18 13:03:06.390112 2026] [security2:error] [pid 139043:tid 139247] [client 168.62.48.100:4143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/nwwha.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnwwAAAM8"] [Tue Aug 18 13:03:06.402262 2026] [security2:error] [pid 123784:tid 123927] [client 20.80.111.3:17955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/core.php"] [unique_id "aoSCOmwDnJBNj2tDbYYamAAAAAk"] [Tue Aug 18 13:03:06.409198 2026] [security2:error] [pid 123784:tid 124043] [client 40.74.65.169:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/nope.php"] [unique_id "aoSCOmwDnJBNj2tDbYYamQAAAH0"] [Tue Aug 18 13:03:06.421436 2026] [security2:error] [pid 139043:tid 139298] [client 20.163.43.14:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCOv2v-lWn9OzQT7UnxQAAAQI"] [Tue Aug 18 13:03:06.427638 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:06.427933 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:06.440689 2026] [security2:error] [pid 123784:tid 123992] [client 34.156.195.117:63064] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.gigapixelhost.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSCOmwDnJBNj2tDbYYamwAAAEo"] [Tue Aug 18 13:03:06.461652 2026] [security2:error] [pid 123784:tid 123920] [client 20.206.73.37:29976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/blurbs.php"] [unique_id "aoSCOmwDnJBNj2tDbYYangAAAAI"] [Tue Aug 18 13:03:06.517451 2026] [security2:error] [pid 123784:tid 123921] [client 20.65.69.59:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fd.php"] [unique_id "aoSCOmwDnJBNj2tDbYYanwAAAAM"] [Tue Aug 18 13:03:06.591522 2026] [security2:error] [pid 139043:tid 139258] [client 20.51.153.15:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nl.php"] [unique_id "aoSCOv2v-lWn9OzQT7Un2AAAANo"] [Tue Aug 18 13:03:06.631265 2026] [security2:error] [pid 123784:tid 123971] [client 158.23.17.4:34006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/kc.php"] [unique_id "aoSCOmwDnJBNj2tDbYYapAAAADU"] [Tue Aug 18 13:03:06.646995 2026] [security2:error] [pid 139043:tid 139200] [client 172.182.217.32:21549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/colour.php"] [unique_id "aoSCOv2v-lWn9OzQT7Un2wAAAKA"] [Tue Aug 18 13:03:06.677512 2026] [security2:error] [pid 123784:tid 124029] [client 172.182.200.96:15649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCOmwDnJBNj2tDbYYapgAAAG8"] [Tue Aug 18 13:03:06.696630 2026] [security2:error] [pid 123784:tid 123931] [client 158.23.17.4:9399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/do.php"] [unique_id "aoSCOmwDnJBNj2tDbYYapwAAAA0"] [Tue Aug 18 13:03:06.731173 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:06.731642 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:06.754997 2026] [security2:error] [pid 123784:tid 124035] [client 132.196.30.78:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/lite.php"] [unique_id "aoSCOmwDnJBNj2tDbYYaqwAAAHU"] [Tue Aug 18 13:03:06.787842 2026] [security2:error] [pid 139043:tid 139201] [client 20.65.69.59:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/info2.php"] [unique_id "aoSCOv2v-lWn9OzQT7Un3wAAAKE"] [Tue Aug 18 13:03:06.799817 2026] [security2:error] [pid 123784:tid 123932] [client 168.62.48.100:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/opsqt.php"] [unique_id "aoSCOmwDnJBNj2tDbYYarAAAAA4"] [Tue Aug 18 13:03:06.806524 2026] [security2:error] [pid 123784:tid 123918] [client 40.74.65.169:38435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCOmwDnJBNj2tDbYYarQAAAAA"] [Tue Aug 18 13:03:06.828382 2026] [security2:error] [pid 139043:tid 139121] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/api/.env"] [unique_id "aoSCOv2v-lWn9OzQT7Un4AAAok0"] [Tue Aug 18 13:03:06.831435 2026] [security2:error] [pid 139043:tid 139150] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.env.bak"] [unique_id "aoSCOv2v-lWn9OzQT7Un4QAAk2o"] [Tue Aug 18 13:03:06.834663 2026] [security2:error] [pid 139043:tid 139118] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.env.backup"] [unique_id "aoSCOv2v-lWn9OzQT7Un4gAA_Uo"] [Tue Aug 18 13:03:06.836990 2026] [security2:error] [pid 139043:tid 139077] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.env.old"] [unique_id "aoSCOv2v-lWn9OzQT7Un4wAA_SE"] [Tue Aug 18 13:03:06.862984 2026] [security2:error] [pid 123784:tid 123970] [client 20.118.133.132:47144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/file5.php"] [unique_id "aoSCOmwDnJBNj2tDbYYasAAAADQ"] [Tue Aug 18 13:03:06.863847 2026] [security2:error] [pid 139043:tid 139191] [client 20.51.153.15:9585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/68.php"] [unique_id "aoSCOv2v-lWn9OzQT7Un5AAAAJc"] [Tue Aug 18 13:03:06.870012 2026] [security2:error] [pid 123784:tid 124010] [client 20.25.139.174:2427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/aaa.php"] [unique_id "aoSCOmwDnJBNj2tDbYYasQAAAFw"] [Tue Aug 18 13:03:06.908595 2026] [security2:error] [pid 123784:tid 123959] [client 20.80.111.3:30016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/data.php"] [unique_id "aoSCOmwDnJBNj2tDbYYaswAAACk"] [Tue Aug 18 13:03:06.928558 2026] [security2:error] [pid 123784:tid 124012] [client 20.163.43.14:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSCOmwDnJBNj2tDbYYatAAAAF4"] [Tue Aug 18 13:03:06.964417 2026] [security2:error] [pid 139043:tid 139286] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/222.php"] [unique_id "aoSCOv2v-lWn9OzQT7Un5gAAAPY"] [Tue Aug 18 13:03:06.974170 2026] [security2:error] [pid 123784:tid 123976] [client 4.232.151.198:24827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/acme-challenge.php"] [unique_id "aoSCOmwDnJBNj2tDbYYatgAAADo"] [Tue Aug 18 13:03:07.020162 2026] [security2:error] [pid 123784:tid 124024] [client 4.223.113.180:41363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/access.php"] [unique_id "aoSCO2wDnJBNj2tDbYYauAAAAGo"] [Tue Aug 18 13:03:07.027657 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:07.027939 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:07.032217 2026] [security2:error] [pid 123784:tid 124033] [client 20.250.13.23:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/v5.php"] [unique_id "aoSCO2wDnJBNj2tDbYYaugAAAHM"] [Tue Aug 18 13:03:07.036169 2026] [security2:error] [pid 123784:tid 124025] [client 191.237.254.161:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/coffexium.php"] [unique_id "aoSCO2wDnJBNj2tDbYYauwAAAGs"] [Tue Aug 18 13:03:07.048740 2026] [security2:error] [pid 139043:tid 139252] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/G-in.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un6AAAANQ"] [Tue Aug 18 13:03:07.071305 2026] [security2:error] [pid 139043:tid 139175] [client 52.173.121.69:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un6gAAAIc"] [Tue Aug 18 13:03:07.099259 2026] [security2:error] [pid 123784:tid 124038] [client 213.35.127.232:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCO2wDnJBNj2tDbYYavQAAAHg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:07.099263 2026] [security2:error] [pid 139043:tid 139280] [client 20.65.69.59:58618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sx.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un6wAAAPA"] [Tue Aug 18 13:03:07.111955 2026] [security2:error] [pid 139043:tid 139270] [client 52.173.121.69:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/zznmg.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un7AAAAOY"] [Tue Aug 18 13:03:07.120434 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:23035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/special.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un7gAAAJk"] [Tue Aug 18 13:03:07.128910 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.200.96:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un7wAAAPc"] [Tue Aug 18 13:03:07.134687 2026] [security2:error] [pid 139043:tid 139225] [client 40.74.65.169:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/new.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un8AAAALk"] [Tue Aug 18 13:03:07.136128 2026] [security2:error] [pid 139043:tid 139173] [client 172.182.217.32:21534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-contentt.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un8QAAAIU"] [Tue Aug 18 13:03:07.146164 2026] [security2:error] [pid 123784:tid 123943] [client 144.76.22.51:44030] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/wp-content/uploads/2026/08/Nota-FGVAgro-18-08.jpg"] [unique_id "aoSCO2wDnJBNj2tDbYYavgAAABk"], referer: https://agrimotor.com.br/2026/08/18/agroindustria-recua-em-junho-de-2026-aponta-fgvagro/ [Tue Aug 18 13:03:07.149766 2026] [security2:error] [pid 139043:tid 139182] [client 20.25.139.174:4484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ws54.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un8wAAAI4"] [Tue Aug 18 13:03:07.152607 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:9730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/jl.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un9AAAAPg"] [Tue Aug 18 13:03:07.184458 2026] [security2:error] [pid 139043:tid 139290] [client 68.155.154.236:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un-QAAAPo"] [Tue Aug 18 13:03:07.232057 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.154.236:8352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCO2wDnJBNj2tDbYYawQAAABo"] [Tue Aug 18 13:03:07.254351 2026] [security2:error] [pid 139043:tid 139230] [client 20.163.43.14:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/01.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un-wAAAL4"] [Tue Aug 18 13:03:07.333580 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:07.333973 2026] [authz_core:error] [pid 123784:tid 123841] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:07.347877 2026] [security2:error] [pid 139043:tid 139180] [client 20.80.111.3:40969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/db-status.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un_gAAAIw"] [Tue Aug 18 13:03:07.352778 2026] [security2:error] [pid 139043:tid 139124] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/backend/.env"] [unique_id "aoSCO_2v-lWn9OzQT7Un_wAAz1A"] [Tue Aug 18 13:03:07.367810 2026] [security2:error] [pid 139043:tid 139208] [client 158.23.17.4:12516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/jn.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoAgAAAKg"] [Tue Aug 18 13:03:07.391638 2026] [security2:error] [pid 139043:tid 139244] [client 20.25.139.174:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/abcd.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoBwAAAMw"] [Tue Aug 18 13:03:07.439474 2026] [security2:error] [pid 139043:tid 139217] [client 20.65.69.59:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nu.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoCQAAALE"] [Tue Aug 18 13:03:07.454154 2026] [security2:error] [pid 139043:tid 139245] [client 20.79.204.6:9676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/term.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoCgAAAM0"] [Tue Aug 18 13:03:07.478866 2026] [security2:error] [pid 139043:tid 139220] [client 172.182.200.96:15674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atwturismo.com.br.bergoninf.com"] [uri "/images/security.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoDAAAALQ"] [Tue Aug 18 13:03:07.493395 2026] [security2:error] [pid 139043:tid 139294] [client 40.74.65.169:44189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/contacto.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoDgAAAP4"] [Tue Aug 18 13:03:07.507626 2026] [security2:error] [pid 139043:tid 139081] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/config/.env"] [unique_id "aoSCO_2v-lWn9OzQT7UoDwAA6CU"] [Tue Aug 18 13:03:07.509045 2026] [security2:error] [pid 139043:tid 139250] [client 168.62.48.100:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoEQAAANI"] [Tue Aug 18 13:03:07.511712 2026] [security2:error] [pid 139043:tid 139255] [client 20.206.73.37:30215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoEgAAANc"] [Tue Aug 18 13:03:07.512195 2026] [security2:error] [pid 139043:tid 139271] [client 20.116.17.175:53822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/aa.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoEwAAAOc"] [Tue Aug 18 13:03:07.526234 2026] [security2:error] [pid 123784:tid 123993] [client 158.23.17.4:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/yw.php"] [unique_id "aoSCO2wDnJBNj2tDbYYayQAAAEs"] [Tue Aug 18 13:03:07.529183 2026] [security2:error] [pid 139043:tid 139222] [client 20.51.153.15:9844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/tq.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoFAAAALY"] [Tue Aug 18 13:03:07.601877 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.151.198:11000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abcd.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoFgAAANg"] [Tue Aug 18 13:03:07.611700 2026] [security2:error] [pid 139043:tid 139273] [client 52.173.121.69:39214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoFwAAAOk"] [Tue Aug 18 13:03:07.616038 2026] [security2:error] [pid 139043:tid 139248] [client 20.163.43.14:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/lv.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoGQAAANA"] [Tue Aug 18 13:03:07.623071 2026] [security2:error] [pid 139043:tid 139227] [client 172.182.217.32:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/config.php7"] [unique_id "aoSCO_2v-lWn9OzQT7UoHQAAALs"] [Tue Aug 18 13:03:07.664305 2026] [security2:error] [pid 139043:tid 139265] [client 20.250.13.23:3452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/we.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoHwAAAOE"] [Tue Aug 18 13:03:07.680193 2026] [security2:error] [pid 123784:tid 123939] [client 4.232.151.198:43472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/a.php"] [unique_id "aoSCO2wDnJBNj2tDbYYazQAAABU"] [Tue Aug 18 13:03:07.683772 2026] [security2:error] [pid 139043:tid 139284] [client 20.65.69.59:58601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ko.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoKwAAAPQ"] [Tue Aug 18 13:03:07.690660 2026] [security2:error] [pid 139043:tid 139258] [client 20.25.139.174:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/deepseek_d.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoLAAAANo"] [Tue Aug 18 13:03:07.770396 2026] [security2:error] [pid 139043:tid 139293] [client 20.51.153.15:9475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/cv.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoNwAAAP0"] [Tue Aug 18 13:03:07.777832 2026] [security2:error] [pid 123784:tid 123958] [client 40.74.65.169:5673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCO2wDnJBNj2tDbYYazwAAACg"] [Tue Aug 18 13:03:07.819407 2026] [security2:error] [pid 139043:tid 139179] [client 40.74.65.169:51589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/new.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoOQAAAIs"] [Tue Aug 18 13:03:07.829621 2026] [security2:error] [pid 139043:tid 139192] [client 4.223.113.180:45259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/02.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoOgAAAJg"] [Tue Aug 18 13:03:07.855307 2026] [security2:error] [pid 139043:tid 139226] [client 20.116.17.175:55194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoOwAAALo"] [Tue Aug 18 13:03:07.888968 2026] [security2:error] [pid 123784:tid 123948] [client 20.80.111.3:40964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCO2wDnJBNj2tDbYYa0gAAAB4"] [Tue Aug 18 13:03:07.937421 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:07.937868 2026] [authz_core:error] [pid 123784:tid 123807] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:07.942414 2026] [security2:error] [pid 123784:tid 123991] [client 132.196.30.78:5790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/lock360.php"] [unique_id "aoSCO2wDnJBNj2tDbYYa1QAAAEk"] [Tue Aug 18 13:03:07.947979 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:6605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/new.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoQAAAAOY"] [Tue Aug 18 13:03:07.954238 2026] [security2:error] [pid 139043:tid 139191] [client 20.25.139.174:2392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-good.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoQQAAAJc"] [Tue Aug 18 13:03:07.980414 2026] [security2:error] [pid 139043:tid 139243] [client 168.62.48.100:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCO_2v-lWn9OzQT7UoQgAAAMs"] [Tue Aug 18 13:03:07.987642 2026] [security2:error] [pid 123784:tid 123949] [client 20.65.69.59:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/pl.php"] [unique_id "aoSCO2wDnJBNj2tDbYYa1gAAAB8"] [Tue Aug 18 13:03:08.006753 2026] [security2:error] [pid 139043:tid 139225] [client 20.51.153.15:9841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/un.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoQwAAALk"] [Tue Aug 18 13:03:08.041209 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.87:33030] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:08.041484 2026] [authz_core:error] [pid 123784:tid 123801] [remote 57.141.22.87:33030] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:08.055434 2026] [security2:error] [pid 139043:tid 139290] [client 20.206.73.37:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoRQAAAPo"] [Tue Aug 18 13:03:08.105278 2026] [security2:error] [pid 139043:tid 139230] [client 52.173.121.69:36164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoRwAAAL4"] [Tue Aug 18 13:03:08.108292 2026] [security2:error] [pid 123784:tid 123999] [client 172.182.217.32:21880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/config.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa2gAAAFE"] [Tue Aug 18 13:03:08.111870 2026] [security2:error] [pid 139043:tid 139240] [client 149.34.210.141:64327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoSAAAAMg"] [Tue Aug 18 13:03:08.122352 2026] [security2:error] [pid 139043:tid 139297] [client 213.35.127.232:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoSQAAAQE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:08.170327 2026] [security2:error] [pid 139043:tid 139249] [client 157.90.155.240:60864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.anzenblindados.com.br"] [uri "/index.php"] [unique_id "aoSCO_2v-lWn9OzQT7Un8gAAANE"], referer: https://www.anzenblindados.com.br/ [Tue Aug 18 13:03:08.176362 2026] [security2:error] [pid 123784:tid 124015] [client 40.74.65.169:38420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/image2.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa3AAAAGE"] [Tue Aug 18 13:03:08.179016 2026] [security2:error] [pid 139043:tid 139292] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xxx.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoSwAAAPw"] [Tue Aug 18 13:03:08.180867 2026] [security2:error] [pid 139043:tid 139185] [client 20.116.17.175:53777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/echkm.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoTAAAAJE"] [Tue Aug 18 13:03:08.211150 2026] [security2:error] [pid 123784:tid 124032] [client 158.23.17.4:34013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vistadasmangueiras.com.br"] [uri "/bf.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa3wAAAHI"] [Tue Aug 18 13:03:08.217115 2026] [security2:error] [pid 139043:tid 139291] [client 20.25.139.174:4498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/function/function.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoTQAAAPs"] [Tue Aug 18 13:03:08.218176 2026] [security2:error] [pid 139043:tid 139219] [client 78.46.190.63:60836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoRAAAALM"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 13:03:08.234220 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:08.234510 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:08.235581 2026] [security2:error] [pid 139043:tid 139300] [client 4.232.151.198:22270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/kj.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoTgAAAQQ"] [Tue Aug 18 13:03:08.240045 2026] [security2:error] [pid 139043:tid 139298] [client 20.51.153.15:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/evil.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoTwAAAQI"] [Tue Aug 18 13:03:08.247449 2026] [security2:error] [pid 123784:tid 124004] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/un.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa4QAAAFY"] [Tue Aug 18 13:03:08.270115 2026] [security2:error] [pid 123784:tid 123927] [client 20.163.43.14:6569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa4gAAAAk"] [Tue Aug 18 13:03:08.274475 2026] [security2:error] [pid 139043:tid 139224] [client 20.226.36.136:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoUAAAALg"] [Tue Aug 18 13:03:08.282574 2026] [security2:error] [pid 123784:tid 123951] [client 20.65.69.59:54130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/env.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa5AAAACE"] [Tue Aug 18 13:03:08.291091 2026] [security2:error] [pid 123784:tid 124014] [client 20.118.133.132:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/xyn.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa5QAAAGA"] [Tue Aug 18 13:03:08.309654 2026] [security2:error] [pid 123784:tid 123987] [client 213.202.253.4:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/memberfuns.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa5gAAAEU"], referer: www.google.com [Tue Aug 18 13:03:08.343396 2026] [security2:error] [pid 139043:tid 139220] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/autogooey.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoVAAAALQ"] [Tue Aug 18 13:03:08.366948 2026] [security2:error] [pid 123784:tid 124001] [client 20.79.204.6:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ioxi-o.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa6AAAAFM"] [Tue Aug 18 13:03:08.377374 2026] [security2:error] [pid 139043:tid 139240] [client 149.34.210.141:64327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoSAAAAMg"] [Tue Aug 18 13:03:08.386541 2026] [security2:error] [pid 139043:tid 139161] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.github/.env"] [unique_id "aoSCPP2v-lWn9OzQT7UoVgAA0nU"] [Tue Aug 18 13:03:08.387027 2026] [security2:error] [pid 139043:tid 139244] [client 20.80.111.3:40963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/load.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoVwAAAMw"] [Tue Aug 18 13:03:08.421048 2026] [security2:error] [pid 123784:tid 124040] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sty.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa6QAAAHo"] [Tue Aug 18 13:03:08.431457 2026] [security2:error] [pid 123784:tid 123973] [client 20.250.13.23:30805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wkl.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa6gAAADc"] [Tue Aug 18 13:03:08.462357 2026] [security2:error] [pid 123784:tid 123992] [client 20.25.139.174:2418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/simple.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa7AAAAEo"] [Tue Aug 18 13:03:08.468519 2026] [security2:error] [pid 139043:tid 139183] [client 52.173.121.69:25593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/oivcl.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoWgAAAI8"] [Tue Aug 18 13:03:08.499042 2026] [security2:error] [pid 123784:tid 123923] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wio.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa7QAAAAU"] [Tue Aug 18 13:03:08.516464 2026] [security2:error] [pid 123784:tid 123967] [client 40.74.65.169:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/apreset.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa7gAAADE"] [Tue Aug 18 13:03:08.536386 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:08.536841 2026] [authz_core:error] [pid 123784:tid 123812] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:08.543710 2026] [security2:error] [pid 123784:tid 124022] [client 20.51.153.15:9581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pw.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa8AAAAGg"] [Tue Aug 18 13:03:08.572275 2026] [security2:error] [pid 123784:tid 124013] [client 168.62.48.100:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa8gAAAF8"] [Tue Aug 18 13:03:08.577903 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:55219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/thoms.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoXQAAANo"] [Tue Aug 18 13:03:08.584903 2026] [security2:error] [pid 123784:tid 123919] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/1061.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa8wAAAAE"] [Tue Aug 18 13:03:08.593941 2026] [security2:error] [pid 123784:tid 123935] [client 20.65.69.59:5725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mz.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa9AAAABE"] [Tue Aug 18 13:03:08.594344 2026] [security2:error] [pid 139043:tid 139202] [client 20.163.43.14:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoXwAAAKI"] [Tue Aug 18 13:03:08.598970 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:8748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/qh.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa9QAAAEw"] [Tue Aug 18 13:03:08.602888 2026] [security2:error] [pid 123784:tid 123940] [client 20.206.73.37:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa9gAAABY"] [Tue Aug 18 13:03:08.606842 2026] [security2:error] [pid 123784:tid 123921] [client 172.182.217.32:21525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/theme.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa9wAAAAM"] [Tue Aug 18 13:03:08.648133 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/gec.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoYAAAAKY"] [Tue Aug 18 13:03:08.670677 2026] [security2:error] [pid 139043:tid 139262] [client 20.226.36.136:57811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/kopyw.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoYgAAAN4"] [Tue Aug 18 13:03:08.688550 2026] [security2:error] [pid 139043:tid 139248] [client 4.223.113.180:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/menu.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoYwAAANA"] [Tue Aug 18 13:03:08.688934 2026] [security2:error] [pid 123784:tid 124035] [client 132.196.30.78:10884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa-gAAAHU"] [Tue Aug 18 13:03:08.716192 2026] [security2:error] [pid 123784:tid 124011] [client 20.116.17.175:3406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/domvf.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa-wAAAF0"] [Tue Aug 18 13:03:08.736860 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/scx.php7"] [unique_id "aoSCPP2v-lWn9OzQT7UoZAAAAL8"] [Tue Aug 18 13:03:08.773922 2026] [security2:error] [pid 123784:tid 123928] [client 20.25.139.174:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/nw.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa_QAAAAo"] [Tue Aug 18 13:03:08.782860 2026] [security2:error] [pid 123784:tid 123924] [client 52.173.121.69:45420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCPGwDnJBNj2tDbYYa_wAAAAY"] [Tue Aug 18 13:03:08.817319 2026] [security2:error] [pid 139043:tid 139261] [client 20.51.153.15:9516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fn.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoZgAAAN0"] [Tue Aug 18 13:03:08.819009 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoZwAAANY"] [Tue Aug 18 13:03:08.834854 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:08.835121 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:08.847918 2026] [security2:error] [pid 139043:tid 139207] [client 68.155.154.236:55434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoaAAAAKc"] [Tue Aug 18 13:03:08.850607 2026] [security2:error] [pid 139043:tid 139191] [client 52.173.121.69:34561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/zugvi.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoaQAAAJc"] [Tue Aug 18 13:03:08.872034 2026] [security2:error] [pid 139043:tid 139175] [client 138.36.100.162:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoagAAAIc"] [Tue Aug 18 13:03:08.872857 2026] [security2:error] [pid 139043:tid 139175] [client 138.36.100.162:42094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPP2v-lWn9OzQT7UoagAAAIc"] [Tue Aug 18 13:03:08.873828 2026] [security2:error] [pid 123784:tid 123959] [client 40.74.65.169:38416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/fb.php"] [unique_id "aoSCPGwDnJBNj2tDbYYbAgAAACk"] [Tue Aug 18 13:03:08.889984 2026] [authz_core:error] [pid 139043:tid 139123] [remote 136.110.27.48:38602] AH01630: client denied by server configuration: /home3/bivarcom/public_html/.htpasswd [Tue Aug 18 13:03:08.895364 2026] [security2:error] [pid 123784:tid 123934] [client 20.65.69.59:59257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ft.php"] [unique_id "aoSCPGwDnJBNj2tDbYYbAwAAABA"] [Tue Aug 18 13:03:08.902165 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp5.php"] [unique_id "aoSCPGwDnJBNj2tDbYYbBAAAAEQ"] [Tue Aug 18 13:03:08.905555 2026] [security2:error] [pid 123784:tid 123972] [client 20.206.73.37:11935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/img.php"] [unique_id "aoSCPGwDnJBNj2tDbYYbBQAAADY"] [Tue Aug 18 13:03:08.906706 2026] [security2:error] [pid 139043:tid 139259] [client 4.232.151.198:22225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/languages.php"] [unique_id "aoSCPP2v-lWn9OzQT7UobQAAANs"] [Tue Aug 18 13:03:08.916571 2026] [security2:error] [pid 139043:tid 139296] [client 20.80.111.3:40676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/maintenance.php"] [unique_id "aoSCPP2v-lWn9OzQT7UobwAAAQA"] [Tue Aug 18 13:03:08.921218 2026] [security2:error] [pid 139043:tid 139197] [client 20.163.43.14:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/info.php"] [unique_id "aoSCPP2v-lWn9OzQT7UocAAAAJ0"] [Tue Aug 18 13:03:08.940372 2026] [security2:error] [pid 123784:tid 123976] [client 20.226.36.136:57220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/zznmg.php"] [unique_id "aoSCPGwDnJBNj2tDbYYbBwAAADo"] [Tue Aug 18 13:03:08.964996 2026] [security2:error] [pid 139043:tid 139242] [client 20.25.139.174:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/edit-tags.php"] [unique_id "aoSCPP2v-lWn9OzQT7UocgAAAMo"] [Tue Aug 18 13:03:09.006049 2026] [security2:error] [pid 123784:tid 124033] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/a2.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbCQAAAHM"] [Tue Aug 18 13:03:09.020741 2026] [security2:error] [pid 139043:tid 139218] [client 168.62.48.100:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCPf2v-lWn9OzQT7UocwAAALI"] [Tue Aug 18 13:03:09.102132 2026] [security2:error] [pid 139043:tid 139267] [client 172.182.217.32:21791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/block-bindings.php"] [unique_id "aoSCPf2v-lWn9OzQT7UodAAAAOM"] [Tue Aug 18 13:03:09.135897 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:09.136156 2026] [authz_core:error] [pid 123784:tid 123905] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:09.137976 2026] [security2:error] [pid 139043:tid 139264] [client 213.35.127.232:60639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCPf2v-lWn9OzQT7UodwAAAOA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:09.139323 2026] [security2:error] [pid 139043:tid 139268] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/app.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoeAAAAOQ"] [Tue Aug 18 13:03:09.140573 2026] [security2:error] [pid 139043:tid 139219] [client 20.51.153.15:9805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kf.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoeQAAALM"] [Tue Aug 18 13:03:09.181378 2026] [security2:error] [pid 123784:tid 124042] [client 20.65.69.59:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/h.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbEAAAAHw"] [Tue Aug 18 13:03:09.197631 2026] [security2:error] [pid 139043:tid 139300] [client 20.116.17.175:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSCPf2v-lWn9OzQT7UofAAAAQQ"] [Tue Aug 18 13:03:09.205085 2026] [security2:error] [pid 139043:tid 139298] [client 40.74.65.169:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/1mage.php"] [unique_id "aoSCPf2v-lWn9OzQT7UofQAAAQI"] [Tue Aug 18 13:03:09.229761 2026] [security2:error] [pid 123784:tid 123974] [client 40.74.65.169:5659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbFQAAADg"] [Tue Aug 18 13:03:09.260844 2026] [security2:error] [pid 139043:tid 139198] [client 157.20.138.62:53306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UogAAAAJ4"] [Tue Aug 18 13:03:09.260971 2026] [security2:error] [pid 139043:tid 139198] [client 157.20.138.62:53306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UogAAAAJ4"] [Tue Aug 18 13:03:09.302813 2026] [security2:error] [pid 139043:tid 139210] [client 132.196.30.78:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoggAAAKo"] [Tue Aug 18 13:03:09.304540 2026] [security2:error] [pid 139043:tid 139188] [client 65.111.8.76:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.8.111.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interativaveiculos.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSCPf2v-lWn9OzQT7UogwAAAJQ"], referer: www.google.com [Tue Aug 18 13:03:09.336476 2026] [security2:error] [pid 123784:tid 124038] [client 20.25.139.174:4536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/xleet.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbGwAAAHg"] [Tue Aug 18 13:03:09.339931 2026] [security2:error] [pid 139043:tid 139260] [client 20.250.13.23:3409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/work.php"] [unique_id "aoSCPf2v-lWn9OzQT7UohQAAANw"] [Tue Aug 18 13:03:09.341170 2026] [security2:error] [pid 139043:tid 139068] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCPf2v-lWn9OzQT7UohAAAyBg"] [Tue Aug 18 13:03:09.345356 2026] [security2:error] [pid 139043:tid 139115] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UohgAA0kc"] [Tue Aug 18 13:03:09.345375 2026] [security2:error] [pid 139043:tid 139244] [client 20.206.73.37:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/aa.php"] [unique_id "aoSCPf2v-lWn9OzQT7UohwAAAMw"] [Tue Aug 18 13:03:09.345507 2026] [security2:error] [pid 139043:tid 139250] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UohgAA0kc"] [Tue Aug 18 13:03:09.347379 2026] [security2:error] [pid 123784:tid 123954] [client 158.23.17.4:33488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/r.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbHAAAACQ"] [Tue Aug 18 13:03:09.356806 2026] [security2:error] [pid 139043:tid 139276] [client 20.80.111.3:40677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/min.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoiAAAAOw"] [Tue Aug 18 13:03:09.423949 2026] [security2:error] [pid 139043:tid 139226] [client 178.153.171.161:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoigAAALo"] [Tue Aug 18 13:03:09.424077 2026] [security2:error] [pid 139043:tid 139226] [client 178.153.171.161:59631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoigAAALo"] [Tue Aug 18 13:03:09.434889 2026] [security2:error] [pid 139043:tid 139204] [client 52.173.121.69:35724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wsrer.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoiwAAAKQ"] [Tue Aug 18 13:03:09.438650 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:09.438931 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:09.448936 2026] [security2:error] [pid 139043:tid 139200] [client 20.51.153.15:9489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/su.php"] [unique_id "aoSCPf2v-lWn9OzQT7UojAAAAKA"] [Tue Aug 18 13:03:09.457025 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:9688] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.advocaciasc.com"] [uri "/1.php"] [unique_id "aoSCPf2v-lWn9OzQT7UojQAAAMk"] [Tue Aug 18 13:03:09.457128 2026] [security2:error] [pid 139043:tid 139241] [client 20.79.204.6:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/1.php"] [unique_id "aoSCPf2v-lWn9OzQT7UojQAAAMk"] [Tue Aug 18 13:03:09.478608 2026] [security2:error] [pid 123784:tid 124028] [client 20.25.139.174:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/u.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbJAAAAG4"] [Tue Aug 18 13:03:09.544067 2026] [security2:error] [pid 123784:tid 123975] [client 20.65.69.59:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/40.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbJgAAADk"] [Tue Aug 18 13:03:09.558922 2026] [security2:error] [pid 139043:tid 139293] [client 40.74.65.169:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/gi.php"] [unique_id "aoSCPf2v-lWn9OzQT7UokgAAAP0"] [Tue Aug 18 13:03:09.575586 2026] [security2:error] [pid 123784:tid 123939] [client 20.163.43.14:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbKAAAABU"] [Tue Aug 18 13:03:09.612157 2026] [security2:error] [pid 139043:tid 139256] [client 172.182.217.32:21885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/class_api.php"] [unique_id "aoSCPf2v-lWn9OzQT7UokwAAANg"] [Tue Aug 18 13:03:09.620207 2026] [security2:error] [pid 139043:tid 139262] [client 52.173.121.69:14633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCPf2v-lWn9OzQT7UolQAAAN4"] [Tue Aug 18 13:03:09.621002 2026] [security2:error] [pid 139043:tid 139164] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCPf2v-lWn9OzQT7UolAAA9ng"] [Tue Aug 18 13:03:09.624123 2026] [security2:error] [pid 123784:tid 123950] [client 20.206.73.37:20678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/av.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbKQAAACA"] [Tue Aug 18 13:03:09.648417 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.154.236:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCPf2v-lWn9OzQT7UolwAAAMI"] [Tue Aug 18 13:03:09.677945 2026] [security2:error] [pid 139043:tid 139209] [client 20.206.73.37:34785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/bajah.php"] [unique_id "aoSCPf2v-lWn9OzQT7UomwAAAKk"] [Tue Aug 18 13:03:09.684645 2026] [security2:error] [pid 139043:tid 139280] [client 132.196.30.78:15053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/.alf.php"] [unique_id "aoSCPf2v-lWn9OzQT7UonAAAAPA"] [Tue Aug 18 13:03:09.694747 2026] [security2:error] [pid 139043:tid 139270] [client 20.186.30.159:14282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCPf2v-lWn9OzQT7UonQAAAOY"] [Tue Aug 18 13:03:09.695883 2026] [security2:error] [pid 139043:tid 139207] [client 20.206.73.37:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/admin.php"] [unique_id "aoSCPf2v-lWn9OzQT7UongAAAKc"] [Tue Aug 18 13:03:09.727186 2026] [security2:error] [pid 123784:tid 124006] [client 20.226.36.136:57245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbKgAAAFg"] [Tue Aug 18 13:03:09.736186 2026] [security2:error] [pid 123784:tid 123991] [client 4.232.151.198:22247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/nw.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbLAAAAEk"] [Tue Aug 18 13:03:09.739472 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:09.739764 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:09.750346 2026] [security2:error] [pid 139043:tid 139243] [client 20.151.109.219:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xv.php"] [unique_id "aoSCPf2v-lWn9OzQT7UonwAAAMs"] [Tue Aug 18 13:03:09.752033 2026] [security2:error] [pid 123784:tid 124039] [client 20.116.17.175:53161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/red.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbLQAAAHk"] [Tue Aug 18 13:03:09.752370 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:9744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wp-key.php"] [unique_id "aoSCPf2v-lWn9OzQT7UooAAAAPc"] [Tue Aug 18 13:03:09.785010 2026] [security2:error] [pid 139043:tid 139184] [client 20.65.69.59:27877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ee.php"] [unique_id "aoSCPf2v-lWn9OzQT7UooQAAAJA"] [Tue Aug 18 13:03:09.793852 2026] [security2:error] [pid 139043:tid 139214] [client 20.116.17.175:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/root.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoogAAAK4"] [Tue Aug 18 13:03:09.796889 2026] [security2:error] [pid 123784:tid 123925] [client 4.223.113.180:41054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/spip.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbLwAAAAc"] [Tue Aug 18 13:03:09.840423 2026] [security2:error] [pid 139043:tid 139230] [client 168.62.48.100:1066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoowAAAL4"] [Tue Aug 18 13:03:09.899160 2026] [security2:error] [pid 123784:tid 124002] [client 20.80.111.3:40668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/ms-files.php"] [unique_id "aoSCPWwDnJBNj2tDbYYbMAAAAFQ"] [Tue Aug 18 13:03:09.903992 2026] [security2:error] [pid 139043:tid 139236] [client 20.163.43.14:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCPf2v-lWn9OzQT7UopgAAAMQ"] [Tue Aug 18 13:03:09.955220 2026] [security2:error] [pid 139043:tid 139292] [client 40.74.65.169:51598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/imsc.php"] [unique_id "aoSCPf2v-lWn9OzQT7UopwAAAPw"] [Tue Aug 18 13:03:09.974601 2026] [security2:error] [pid 139043:tid 139180] [client 52.173.121.69:37298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoqAAAAIw"] [Tue Aug 18 13:03:09.998348 2026] [security2:error] [pid 139043:tid 139242] [client 20.25.139.174:2178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCPf2v-lWn9OzQT7UoqgAAAMo"] [Tue Aug 18 13:03:10.032464 2026] [security2:error] [pid 123784:tid 124015] [client 20.186.30.159:14237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbMgAAAGE"] [Tue Aug 18 13:03:10.038589 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:10.038857 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:10.058893 2026] [security2:error] [pid 123784:tid 123948] [client 65.111.8.76:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.8.111.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "interativaveiculos.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbNAAAAB4"], referer: www.google.com [Tue Aug 18 13:03:10.067231 2026] [security2:error] [pid 139043:tid 139225] [client 20.250.13.23:30808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/worksec.php"] [unique_id "aoSCPv2v-lWn9OzQT7UorAAAALk"] [Tue Aug 18 13:03:10.068686 2026] [security2:error] [pid 139043:tid 139266] [client 20.226.36.136:57823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCPv2v-lWn9OzQT7UorQAAAOI"] [Tue Aug 18 13:03:10.084838 2026] [security2:error] [pid 139043:tid 139298] [client 20.51.153.15:9827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gg.php"] [unique_id "aoSCPv2v-lWn9OzQT7UorgAAAQI"] [Tue Aug 18 13:03:10.105182 2026] [security2:error] [pid 139043:tid 139224] [client 20.65.69.59:48504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ak.php"] [unique_id "aoSCPv2v-lWn9OzQT7UorwAAALg"] [Tue Aug 18 13:03:10.106097 2026] [security2:error] [pid 139043:tid 139228] [client 20.25.139.174:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp.php"] [unique_id "aoSCPv2v-lWn9OzQT7UosAAAALw"] [Tue Aug 18 13:03:10.112861 2026] [security2:error] [pid 139043:tid 139269] [client 168.62.48.100:4201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCPv2v-lWn9OzQT7UosgAAAOU"] [Tue Aug 18 13:03:10.120819 2026] [security2:error] [pid 139043:tid 139223] [client 172.182.217.32:21856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/root.php"] [unique_id "aoSCPv2v-lWn9OzQT7UoswAAALc"] [Tue Aug 18 13:03:10.144161 2026] [security2:error] [pid 123784:tid 123989] [client 4.232.151.198:11513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/chosen.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbNQAAAEc"] [Tue Aug 18 13:03:10.149322 2026] [security2:error] [pid 139043:tid 139220] [client 191.237.254.161:47063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCPv2v-lWn9OzQT7UotAAAALQ"] [Tue Aug 18 13:03:10.153094 2026] [security2:error] [pid 139043:tid 139299] [client 213.35.127.232:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCPv2v-lWn9OzQT7UotQAAAQM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:10.168112 2026] [security2:error] [pid 139043:tid 139257] [client 168.62.48.100:1134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCPv2v-lWn9OzQT7UotgAAANk"] [Tue Aug 18 13:03:10.232035 2026] [security2:error] [pid 139043:tid 139240] [client 20.163.43.14:6613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSCPv2v-lWn9OzQT7UouAAAAMg"] [Tue Aug 18 13:03:10.246548 2026] [security2:error] [pid 139043:tid 139255] [client 20.116.17.175:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/fpwch.php"] [unique_id "aoSCPv2v-lWn9OzQT7UougAAANc"] [Tue Aug 18 13:03:10.252461 2026] [security2:error] [pid 139043:tid 139276] [client 40.74.65.169:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/video.php"] [unique_id "aoSCPv2v-lWn9OzQT7UouwAAAOw"] [Tue Aug 18 13:03:10.310005 2026] [security2:error] [pid 139043:tid 139247] [client 20.79.204.6:9288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/alfa.php"] [unique_id "aoSCPv2v-lWn9OzQT7UovAAAAM8"] [Tue Aug 18 13:03:10.314886 2026] [security2:error] [pid 139043:tid 139096] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/id_rsa"] [unique_id "aoSCPv2v-lWn9OzQT7UovQAAtTQ"] [Tue Aug 18 13:03:10.317620 2026] [security2:error] [pid 139043:tid 139071] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/id_dsa"] [unique_id "aoSCPv2v-lWn9OzQT7UovgAArxs"] [Tue Aug 18 13:03:10.328563 2026] [security2:error] [pid 139043:tid 139245] [client 20.186.30.159:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/media.php"] [unique_id "aoSCPv2v-lWn9OzQT7UovwAAAM0"] [Tue Aug 18 13:03:10.329177 2026] [security2:error] [pid 123784:tid 124043] [client 20.51.153.15:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gi.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbNgAAAH0"] [Tue Aug 18 13:03:10.346513 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:10.346706 2026] [security2:error] [pid 139043:tid 139263] [client 20.80.111.3:40991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/options.php"] [unique_id "aoSCPv2v-lWn9OzQT7UowAAAAN8"] [Tue Aug 18 13:03:10.346962 2026] [authz_core:error] [pid 123784:tid 123911] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:10.351130 2026] [security2:error] [pid 123784:tid 124014] [client 20.226.36.136:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/oivcl.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbOAAAAGA"] [Tue Aug 18 13:03:10.367378 2026] [security2:error] [pid 139043:tid 139177] [client 4.232.151.198:22248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/lofmebwd.php"] [unique_id "aoSCPv2v-lWn9OzQT7UowQAAAIk"] [Tue Aug 18 13:03:10.397132 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.154.236:40209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbOgAAADM"] [Tue Aug 18 13:03:10.404970 2026] [security2:error] [pid 123784:tid 123973] [client 20.65.69.59:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/test_info.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbOwAAADc"] [Tue Aug 18 13:03:10.407199 2026] [security2:error] [pid 123784:tid 124005] [client 52.173.121.69:62232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbPAAAAFc"] [Tue Aug 18 13:03:10.456759 2026] [security2:error] [pid 139043:tid 139206] [client 168.62.48.100:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/weozh.php"] [unique_id "aoSCPv2v-lWn9OzQT7UoxAAAAKY"] [Tue Aug 18 13:03:10.494080 2026] [security2:error] [pid 123784:tid 123890] [remote 129.121.103.155:53514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "macambio.com"] [uri "/wp-login.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbQwAARmU"] [Tue Aug 18 13:03:10.519933 2026] [autoindex:error] [pid 139043:tid 139190] [client 20.226.112.14:0] AH01276: Cannot serve directory /home1/ledline/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:10.522686 2026] [security2:error] [pid 139043:tid 139211] [client 158.23.17.4:10973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/17.php"] [unique_id "aoSCPv2v-lWn9OzQT7UoxwAAAKs"] [Tue Aug 18 13:03:10.546920 2026] [security2:error] [pid 123784:tid 124040] [client 20.25.139.174:2213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/h.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbRAAAAHo"] [Tue Aug 18 13:03:10.556046 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCPv2v-lWn9OzQT7UoyQAAAM4"] [Tue Aug 18 13:03:10.576068 2026] [security2:error] [pid 139043:tid 139238] [client 158.23.17.4:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vo.php"] [unique_id "aoSCPv2v-lWn9OzQT7UoywAAAMY"] [Tue Aug 18 13:03:10.604150 2026] [security2:error] [pid 139043:tid 139191] [client 52.173.121.69:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/yxijx.php"] [unique_id "aoSCPv2v-lWn9OzQT7UozAAAAJc"] [Tue Aug 18 13:03:10.605616 2026] [security2:error] [pid 123784:tid 124041] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/cxc.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbRgAAAHs"] [Tue Aug 18 13:03:10.608142 2026] [security2:error] [pid 139043:tid 139293] [client 172.182.217.32:21771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/menu.php"] [unique_id "aoSCPv2v-lWn9OzQT7UozQAAAP0"] [Tue Aug 18 13:03:10.613138 2026] [security2:error] [pid 139043:tid 139251] [client 20.25.139.174:4626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/155.php"] [unique_id "aoSCPv2v-lWn9OzQT7UozgAAANM"] [Tue Aug 18 13:03:10.643895 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:10.644156 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:10.650624 2026] [authz_core:error] [pid 123784:tid 123822] [remote 57.141.22.4:40556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:10.650986 2026] [authz_core:error] [pid 123784:tid 123822] [remote 57.141.22.4:40556] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:10.654346 2026] [security2:error] [pid 139043:tid 139259] [client 40.74.65.169:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo0AAAANs"] [Tue Aug 18 13:03:10.657640 2026] [security2:error] [pid 123784:tid 123987] [client 4.223.113.180:12112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbSgAAAEU"] [Tue Aug 18 13:03:10.658839 2026] [security2:error] [pid 123784:tid 123994] [client 20.65.69.59:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/14.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbSwAAAEw"] [Tue Aug 18 13:03:10.665977 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/mg.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo0QAAAQA"] [Tue Aug 18 13:03:10.673371 2026] [security2:error] [pid 139043:tid 139197] [client 20.186.30.159:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/admin.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo0gAAAJ0"] [Tue Aug 18 13:03:10.681773 2026] [security2:error] [pid 139043:tid 139184] [client 20.51.153.15:9579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pz.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo0wAAAJA"] [Tue Aug 18 13:03:10.706339 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.36.136:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/zugvi.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo1QAAAK4"] [Tue Aug 18 13:03:10.707530 2026] [security2:error] [pid 139043:tid 139101] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/key.pem"] [unique_id "aoSCPv2v-lWn9OzQT7Uo1AAAsDk"] [Tue Aug 18 13:03:10.707736 2026] [security2:error] [pid 139043:tid 139262] [client 20.250.13.23:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-activate.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo1gAAAN4"] [Tue Aug 18 13:03:10.729019 2026] [security2:error] [pid 139043:tid 139277] [client 168.62.48.100:1204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/rymmm.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo2AAAAO0"] [Tue Aug 18 13:03:10.736632 2026] [security2:error] [pid 139043:tid 139208] [client 103.184.169.37:43510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo2QAAAKg"] [Tue Aug 18 13:03:10.736751 2026] [security2:error] [pid 139043:tid 139208] [client 103.184.169.37:43510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo2QAAAKg"] [Tue Aug 18 13:03:10.762343 2026] [security2:error] [pid 139043:tid 139288] [client 132.196.30.78:8844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo3AAAAPg"] [Tue Aug 18 13:03:10.791291 2026] [security2:error] [pid 139043:tid 139185] [client 20.206.73.37:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/media.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo3QAAAJE"] [Tue Aug 18 13:03:10.797084 2026] [security2:error] [pid 123784:tid 123935] [client 20.80.111.3:40995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/security.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbUgAAABE"] [Tue Aug 18 13:03:10.798300 2026] [security2:error] [pid 139043:tid 139289] [client 20.226.36.136:57255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wsrer.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo3gAAAPk"] [Tue Aug 18 13:03:10.887955 2026] [security2:error] [pid 139043:tid 139100] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/privatekey.key"] [unique_id "aoSCPv2v-lWn9OzQT7Uo3wABAjg"] [Tue Aug 18 13:03:10.891884 2026] [security2:error] [pid 139043:tid 139178] [client 20.163.43.14:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/403.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo4AAAAIo"] [Tue Aug 18 13:03:10.946893 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:10.947195 2026] [authz_core:error] [pid 123784:tid 123800] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:10.947701 2026] [security2:error] [pid 139043:tid 139257] [client 40.74.65.169:44249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/hel.php"] [unique_id "aoSCPv2v-lWn9OzQT7Uo4gAAANk"] [Tue Aug 18 13:03:10.957569 2026] [security2:error] [pid 123784:tid 124010] [client 20.65.69.59:5376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/tk.php"] [unique_id "aoSCPmwDnJBNj2tDbYYbVgAAAFw"] [Tue Aug 18 13:03:11.023195 2026] [security2:error] [pid 139043:tid 139278] [client 20.51.153.15:8262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kk.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo5QAAAO4"] [Tue Aug 18 13:03:11.026985 2026] [security2:error] [pid 123784:tid 123963] [client 20.186.30.159:14295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/mac.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbVwAAAC0"] [Tue Aug 18 13:03:11.029285 2026] [security2:error] [pid 139043:tid 139237] [client 168.62.48.100:1128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/lddxs.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo5gAAAMU"] [Tue Aug 18 13:03:11.036360 2026] [security2:error] [pid 123784:tid 123996] [client 68.155.154.236:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbWQAAAE4"] [Tue Aug 18 13:03:11.044021 2026] [security2:error] [pid 139043:tid 139240] [client 20.226.36.136:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo6AAAAMg"] [Tue Aug 18 13:03:11.045945 2026] [security2:error] [pid 123784:tid 123960] [client 20.25.139.174:2419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbWgAAACo"] [Tue Aug 18 13:03:11.054512 2026] [security2:error] [pid 139043:tid 139250] [client 52.173.121.69:36700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo6QAAANI"] [Tue Aug 18 13:03:11.099105 2026] [security2:error] [pid 139043:tid 139269] [client 172.182.217.32:21839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/plugin.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo6gAAAOU"] [Tue Aug 18 13:03:11.104953 2026] [security2:error] [pid 139043:tid 139226] [client 132.196.30.78:25710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo7AAAALo"] [Tue Aug 18 13:03:11.164539 2026] [security2:error] [pid 123784:tid 124011] [client 213.35.127.232:61053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbaQAAAF0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:11.167151 2026] [security2:error] [pid 139043:tid 139188] [client 20.25.139.174:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/96i.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo7gAAAJQ"] [Tue Aug 18 13:03:11.224954 2026] [security2:error] [pid 123784:tid 123943] [client 20.65.69.59:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/hp.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbhgAAABk"] [Tue Aug 18 13:03:11.244807 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:11.245063 2026] [authz_core:error] [pid 123784:tid 123792] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:11.252834 2026] [security2:error] [pid 139043:tid 139245] [client 40.74.65.169:5686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo8gAAAM0"] [Tue Aug 18 13:03:11.286908 2026] [security2:error] [pid 123784:tid 124038] [client 168.62.48.100:1166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/zjggu.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbkAAAAHg"] [Tue Aug 18 13:03:11.309488 2026] [security2:error] [pid 139043:tid 139175] [client 37.40.227.74:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo9QAAAIc"] [Tue Aug 18 13:03:11.309588 2026] [security2:error] [pid 139043:tid 139175] [client 37.40.227.74:56573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo9QAAAIc"] [Tue Aug 18 13:03:11.317207 2026] [security2:error] [pid 123784:tid 123965] [client 20.226.36.136:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/yxijx.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbkwAAAC8"] [Tue Aug 18 13:03:11.320344 2026] [security2:error] [pid 123784:tid 123962] [client 4.232.151.198:22267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSCP2wDnJBNj2tDbYYblAAAACw"] [Tue Aug 18 13:03:11.325215 2026] [security2:error] [pid 139043:tid 139194] [client 20.80.111.3:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo-AAAAJo"] [Tue Aug 18 13:03:11.326070 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wu.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo-QAAAKY"] [Tue Aug 18 13:03:11.345243 2026] [security2:error] [pid 123784:tid 123976] [client 20.250.13.23:3515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin.php"] [unique_id "aoSCP2wDnJBNj2tDbYYblQAAADo"] [Tue Aug 18 13:03:11.347762 2026] [security2:error] [pid 139043:tid 139181] [client 40.74.65.169:51653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/qlex1.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo-gAAAI0"] [Tue Aug 18 13:03:11.357125 2026] [security2:error] [pid 123784:tid 124029] [client 5.31.227.224:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP2wDnJBNj2tDbYYblgAAAG8"] [Tue Aug 18 13:03:11.357224 2026] [security2:error] [pid 123784:tid 124029] [client 5.31.227.224:1444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP2wDnJBNj2tDbYYblgAAAG8"] [Tue Aug 18 13:03:11.363294 2026] [security2:error] [pid 123784:tid 123961] [client 20.51.153.15:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/phpcheck.php"] [unique_id "aoSCP2wDnJBNj2tDbYYblwAAACs"] [Tue Aug 18 13:03:11.367360 2026] [security2:error] [pid 139043:tid 139286] [client 168.62.48.100:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo-wAAAPY"] [Tue Aug 18 13:03:11.428901 2026] [security2:error] [pid 139043:tid 139192] [client 20.186.30.159:14281] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/1.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo_wAAAJg"] [Tue Aug 18 13:03:11.429000 2026] [security2:error] [pid 139043:tid 139192] [client 20.186.30.159:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/1.php"] [unique_id "aoSCP_2v-lWn9OzQT7Uo_wAAAJg"] [Tue Aug 18 13:03:11.463945 2026] [security2:error] [pid 139043:tid 139176] [client 20.116.17.175:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/reop3.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpAQAAAIg"] [Tue Aug 18 13:03:11.504969 2026] [security2:error] [pid 123784:tid 123949] [client 20.65.69.59:27845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wx.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbogAAAB8"] [Tue Aug 18 13:03:11.548548 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:11.548826 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:11.557804 2026] [security2:error] [pid 139043:tid 139243] [client 168.62.48.100:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpBQAAAMs"] [Tue Aug 18 13:03:11.564059 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ev.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpBwAAANs"] [Tue Aug 18 13:03:11.571753 2026] [security2:error] [pid 139043:tid 139184] [client 20.206.73.37:11911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/images.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpCgAAAJA"] [Tue Aug 18 13:03:11.578486 2026] [security2:error] [pid 139043:tid 139290] [client 20.226.36.136:57264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpCwAAAPo"] [Tue Aug 18 13:03:11.580471 2026] [security2:error] [pid 123784:tid 123993] [client 20.25.139.174:2429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/a7.php"] [unique_id "aoSCP2wDnJBNj2tDbYYbvAAAAEs"] [Tue Aug 18 13:03:11.588545 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.217.32:21837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cloud.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpDAAAANA"] [Tue Aug 18 13:03:11.596936 2026] [security2:error] [pid 139043:tid 139065] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCP_2v-lWn9OzQT7UpDQAAsBU"] [Tue Aug 18 13:03:11.631901 2026] [security2:error] [pid 139043:tid 139218] [client 40.74.65.169:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/grok.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpDwAAALI"] [Tue Aug 18 13:03:11.683861 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:9810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/dg.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpGAAAAIU"] [Tue Aug 18 13:03:11.699419 2026] [security2:error] [pid 139043:tid 139264] [client 132.196.30.78:22921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpGgAAAOA"] [Tue Aug 18 13:03:11.703193 2026] [security2:error] [pid 139043:tid 139199] [client 103.120.71.157:31843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpGwAAAJ8"] [Tue Aug 18 13:03:11.703278 2026] [security2:error] [pid 139043:tid 139199] [client 103.120.71.157:31843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpGwAAAJ8"] [Tue Aug 18 13:03:11.722240 2026] [security2:error] [pid 123784:tid 123925] [client 20.25.139.174:4427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/as.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb0AAAAAc"] [Tue Aug 18 13:03:11.730997 2026] [security2:error] [pid 123784:tid 123930] [client 4.223.113.180:40483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/aksinet.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb0QAAAAw"] [Tue Aug 18 13:03:11.747142 2026] [security2:error] [pid 139043:tid 139219] [client 68.155.154.236:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpHQAAALM"] [Tue Aug 18 13:03:11.756924 2026] [security2:error] [pid 139043:tid 139298] [client 20.65.69.59:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/dj.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpIAAAAQI"] [Tue Aug 18 13:03:11.784379 2026] [security2:error] [pid 123784:tid 124037] [client 20.80.111.3:17270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb1AAAAHc"] [Tue Aug 18 13:03:11.832426 2026] [security2:error] [pid 139043:tid 139299] [client 20.116.17.175:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/JawirGenk.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpJQAAAQM"] [Tue Aug 18 13:03:11.843409 2026] [security2:error] [pid 139043:tid 139257] [client 52.173.121.69:36686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/jrpga.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpJgAAANk"] [Tue Aug 18 13:03:11.852250 2026] [security2:error] [pid 123784:tid 123977] [client 102.213.179.104:56190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb1gAAADs"] [Tue Aug 18 13:03:11.852399 2026] [security2:error] [pid 123784:tid 123977] [client 102.213.179.104:56190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb1gAAADs"] [Tue Aug 18 13:03:11.854510 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:11.854961 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:11.868489 2026] [security2:error] [pid 139043:tid 139210] [client 20.186.30.159:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/coffee.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpKAAAAKo"] [Tue Aug 18 13:03:11.873755 2026] [security2:error] [pid 139043:tid 139294] [client 20.163.43.14:6594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/gecko.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpKQAAAP4"] [Tue Aug 18 13:03:11.903141 2026] [security2:error] [pid 123784:tid 123920] [client 168.62.48.100:1172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCP2wDnJBNj2tDbYYb2AAAAAI"] [Tue Aug 18 13:03:11.968382 2026] [security2:error] [pid 139043:tid 139178] [client 4.232.151.198:10403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSCP_2v-lWn9OzQT7UpKwAAAIo"] [Tue Aug 18 13:03:12.008167 2026] [security2:error] [pid 139043:tid 139221] [client 20.116.17.175:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/php5.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpLwAAALU"] [Tue Aug 18 13:03:12.042270 2026] [security2:error] [pid 139043:tid 139222] [client 40.74.65.169:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/mariju.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpMAAAALY"] [Tue Aug 18 13:03:12.051773 2026] [security2:error] [pid 139043:tid 139297] [client 20.65.69.59:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fa.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpMQAAAQE"] [Tue Aug 18 13:03:12.053621 2026] [security2:error] [pid 123784:tid 124040] [client 20.51.153.15:9478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/bm.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb3AAAAHo"] [Tue Aug 18 13:03:12.059075 2026] [security2:error] [pid 123784:tid 124022] [client 20.151.109.219:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mx.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb3QAAAGg"] [Tue Aug 18 13:03:12.079659 2026] [security2:error] [pid 123784:tid 123973] [client 172.182.217.32:21520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/configs.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb4QAAADc"] [Tue Aug 18 13:03:12.103123 2026] [security2:error] [pid 123784:tid 124019] [client 20.25.139.174:2194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/manager.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb4wAAAGU"] [Tue Aug 18 13:03:12.143021 2026] [security2:error] [pid 123784:tid 123950] [client 20.79.204.6:9718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/edit.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb5QAAACA"] [Tue Aug 18 13:03:12.173674 2026] [security2:error] [pid 139043:tid 139203] [client 20.250.13.23:3106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/about.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpNAAAAKM"] [Tue Aug 18 13:03:12.174797 2026] [security2:error] [pid 139043:tid 139258] [client 20.186.30.159:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpNQAAANo"] [Tue Aug 18 13:03:12.184516 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:61287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpNgAAAI4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:12.186800 2026] [security2:error] [pid 139043:tid 139281] [client 168.62.48.100:1054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/kopyw.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpNwAAAPE"] [Tue Aug 18 13:03:12.212019 2026] [security2:error] [pid 139043:tid 139134] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpOAAA_Vo"] [Tue Aug 18 13:03:12.241912 2026] [security2:error] [pid 139043:tid 139284] [client 20.25.139.174:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/min.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpOwAAAPQ"] [Tue Aug 18 13:03:12.253999 2026] [security2:error] [pid 139043:tid 139140] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpPAAA-mA"] [Tue Aug 18 13:03:12.260051 2026] [security2:error] [pid 139043:tid 139214] [client 158.23.17.4:8705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xs.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpPQAAAK4"] [Tue Aug 18 13:03:12.277215 2026] [security2:error] [pid 139043:tid 139124] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/media.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpPgAA4VA"] [Tue Aug 18 13:03:12.280447 2026] [security2:error] [pid 139043:tid 139201] [client 20.80.111.3:17943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/wp-blog-header.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpPwAAAKE"] [Tue Aug 18 13:03:12.285460 2026] [security2:error] [pid 139043:tid 139191] [client 223.185.37.47:30637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQAAAAJc"] [Tue Aug 18 13:03:12.289985 2026] [security2:error] [pid 139043:tid 139191] [client 223.185.37.47:30637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQAAAAJc"] [Tue Aug 18 13:03:12.298699 2026] [security2:error] [pid 123784:tid 123970] [client 20.51.153.15:9790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vu.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb9QAAADQ"] [Tue Aug 18 13:03:12.309496 2026] [security2:error] [pid 139043:tid 139122] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/admin.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQQAAqE4"] [Tue Aug 18 13:03:12.319529 2026] [security2:error] [pid 123784:tid 124010] [client 20.65.69.59:54138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/fb.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb9wAAAFw"] [Tue Aug 18 13:03:12.322862 2026] [security2:error] [pid 123784:tid 123963] [client 40.74.65.169:44263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/indes.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb-AAAAC0"] [Tue Aug 18 13:03:12.338388 2026] [security2:error] [pid 139043:tid 139144] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/mac.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQgAA0WQ"] [Tue Aug 18 13:03:12.361215 2026] [security2:error] [pid 139043:tid 139120] [remote 191.237.254.161:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "martinmadeireira.com.br"] [uri "/1.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQwAA40w"] [Tue Aug 18 13:03:12.361335 2026] [security2:error] [pid 139043:tid 139120] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/1.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpQwAA40w"] [Tue Aug 18 13:03:12.366265 2026] [security2:error] [pid 139043:tid 139215] [client 4.232.151.198:47333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpRAAAAK8"] [Tue Aug 18 13:03:12.389149 2026] [security2:error] [pid 139043:tid 139138] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/coffee.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpRQAA_F4"] [Tue Aug 18 13:03:12.407485 2026] [security2:error] [pid 139043:tid 139131] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpRgAA9Vc"] [Tue Aug 18 13:03:12.425854 2026] [security2:error] [pid 139043:tid 139128] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpSAAAnlQ"] [Tue Aug 18 13:03:12.441473 2026] [security2:error] [pid 139043:tid 139081] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCQP2v-lWn9OzQT7UpSQAAoiU"] [Tue Aug 18 13:03:12.454875 2026] [security2:error] [pid 139043:tid 139149] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/yj09.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpTAAA2Wk"] [Tue Aug 18 13:03:12.458687 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:12.459143 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:12.472243 2026] [security2:error] [pid 139043:tid 139294] [client 168.62.48.100:1188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/zznmg.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpTQAAAP4"] [Tue Aug 18 13:03:12.479508 2026] [security2:error] [pid 139043:tid 139240] [client 20.186.30.159:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpTgAAAMg"] [Tue Aug 18 13:03:12.484525 2026] [security2:error] [pid 139043:tid 139296] [client 52.173.121.69:61862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpTwAAAQA"] [Tue Aug 18 13:03:12.484895 2026] [security2:error] [pid 139043:tid 139154] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/scxy.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpUAAAim4"] [Tue Aug 18 13:03:12.494908 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.73.37:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/admin.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpUgAAAOI"] [Tue Aug 18 13:03:12.503533 2026] [security2:error] [pid 139043:tid 139084] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpUwAAuig"] [Tue Aug 18 13:03:12.541105 2026] [security2:error] [pid 139043:tid 139106] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpVgAAlD4"] [Tue Aug 18 13:03:12.545762 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpVwAAAOk"] [Tue Aug 18 13:03:12.563183 2026] [security2:error] [pid 139043:tid 139076] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/blurbs.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpWAAAzyA"] [Tue Aug 18 13:03:12.574584 2026] [security2:error] [pid 139043:tid 139252] [client 172.182.217.32:21523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-configs.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpWQAAANQ"] [Tue Aug 18 13:03:12.579886 2026] [security2:error] [pid 123784:tid 123986] [client 20.65.69.59:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gw.php"] [unique_id "aoSCQGwDnJBNj2tDbYYb_gAAAEQ"] [Tue Aug 18 13:03:12.583709 2026] [security2:error] [pid 139043:tid 139271] [client 178.156.189.249:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "joanagaspar.com.br"] [uri "/"] [unique_id "aoSCQP2v-lWn9OzQT7UpWgAA5zY"], referer: https://joanagaspar.com.br/ [Tue Aug 18 13:03:12.585591 2026] [security2:error] [pid 123784:tid 123996] [client 4.232.151.198:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/f7.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcAAAAAE4"] [Tue Aug 18 13:03:12.613555 2026] [security2:error] [pid 139043:tid 139223] [client 20.25.139.174:2368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/w1.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpWwAAALc"] [Tue Aug 18 13:03:12.639405 2026] [security2:error] [pid 139043:tid 139046] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/bajah.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpXAAArAI"] [Tue Aug 18 13:03:12.708608 2026] [security2:error] [pid 139043:tid 139186] [client 52.173.121.69:37307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpfgAAAJI"] [Tue Aug 18 13:03:12.720817 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:9835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ic.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpgQAAAI4"] [Tue Aug 18 13:03:12.721915 2026] [security2:error] [pid 139043:tid 139281] [client 40.74.65.169:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpggAAAPE"] [Tue Aug 18 13:03:12.726953 2026] [security2:error] [pid 139043:tid 139245] [client 20.80.111.3:17260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/wp-mail.php"] [unique_id "aoSCQP2v-lWn9OzQT7UphwAAAM0"] [Tue Aug 18 13:03:12.749772 2026] [security2:error] [pid 139043:tid 139176] [client 168.62.48.100:1151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpigAAAIg"] [Tue Aug 18 13:03:12.752012 2026] [security2:error] [pid 139043:tid 139048] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/domvf.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpiwAA7AQ"] [Tue Aug 18 13:03:12.759512 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:12.759923 2026] [authz_core:error] [pid 123784:tid 123862] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:12.770382 2026] [security2:error] [pid 139043:tid 139241] [client 68.155.154.236:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpjQAAAMk"] [Tue Aug 18 13:03:12.770685 2026] [security2:error] [pid 139043:tid 139110] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/fpwch.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpjgAA3UI"] [Tue Aug 18 13:03:12.786048 2026] [security2:error] [pid 139043:tid 139254] [client 20.186.30.159:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/yj09.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpjwAAANY"] [Tue Aug 18 13:03:12.794628 2026] [security2:error] [pid 139043:tid 139092] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/adminner.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpkAAA0zA"] [Tue Aug 18 13:03:12.808191 2026] [security2:error] [pid 123784:tid 123972] [client 20.250.13.23:30825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcCAAAADY"] [Tue Aug 18 13:03:12.812616 2026] [security2:error] [pid 139043:tid 139075] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/abcd.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpkgAA_R8"] [Tue Aug 18 13:03:12.860516 2026] [security2:error] [pid 123784:tid 123943] [client 20.65.69.59:48477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/sw.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcCwAAABk"] [Tue Aug 18 13:03:12.873296 2026] [security2:error] [pid 139043:tid 139078] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/wp-json"] [unique_id "aoSCQP2v-lWn9OzQT7UplAAA-iI"] [Tue Aug 18 13:03:12.884037 2026] [security2:error] [pid 139043:tid 139156] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/z9x8c7v6b5-debug-trigger-3xsolutions.com.br"] [unique_id "aoSCQP2v-lWn9OzQT7UplwAA-nA"] [Tue Aug 18 13:03:12.885040 2026] [security2:error] [pid 139043:tid 139142] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/rclone.conf"] [unique_id "aoSCQP2v-lWn9OzQT7UpmAAA-mI"] [Tue Aug 18 13:03:12.885977 2026] [security2:error] [pid 139043:tid 139099] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.git/config"] [unique_id "aoSCQP2v-lWn9OzQT7UpmQAA-jc"] [Tue Aug 18 13:03:12.888414 2026] [security2:error] [pid 139043:tid 139096] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.aws/credentials"] [unique_id "aoSCQP2v-lWn9OzQT7UpmgAA-jQ"] [Tue Aug 18 13:03:12.906405 2026] [security2:error] [pid 139043:tid 139079] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.aws/config"] [unique_id "aoSCQP2v-lWn9OzQT7UpngAA-iM"] [Tue Aug 18 13:03:12.907377 2026] [security2:error] [pid 139043:tid 139262] [client 132.196.30.78:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpnwAAAN4"] [Tue Aug 18 13:03:12.915309 2026] [security2:error] [pid 139043:tid 139265] [client 20.163.43.14:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/0x.php"] [unique_id "aoSCQP2v-lWn9OzQT7UpoQAAAOE"] [Tue Aug 18 13:03:12.944258 2026] [security2:error] [pid 123784:tid 123959] [client 197.184.64.235:41974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcDwAAACk"] [Tue Aug 18 13:03:12.944397 2026] [security2:error] [pid 123784:tid 123959] [client 197.184.64.235:41974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcDwAAACk"] [Tue Aug 18 13:03:12.945782 2026] [security2:error] [pid 123784:tid 124008] [client 168.62.48.100:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcEAAAAFo"] [Tue Aug 18 13:03:12.967572 2026] [security2:error] [pid 123784:tid 124020] [client 20.206.73.37:11941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/222.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcEgAAAGY"] [Tue Aug 18 13:03:12.981305 2026] [security2:error] [pid 139043:tid 139275] [client 20.79.204.6:9673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/elp.php"] [unique_id "aoSCQP2v-lWn9OzQT7UppAAAAOs"] [Tue Aug 18 13:03:12.988425 2026] [security2:error] [pid 123784:tid 123954] [client 20.25.139.174:4673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/php8.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcFAAAACQ"] [Tue Aug 18 13:03:12.995281 2026] [security2:error] [pid 123784:tid 123964] [client 20.51.153.15:9831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ue.php"] [unique_id "aoSCQGwDnJBNj2tDbYYcFQAAAC4"] [Tue Aug 18 13:03:13.015402 2026] [security2:error] [pid 123784:tid 124034] [client 20.151.109.219:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/45.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcFgAAAHQ"] [Tue Aug 18 13:03:13.017498 2026] [security2:error] [pid 139043:tid 139208] [client 168.62.48.100:1242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCQf2v-lWn9OzQT7UppQAAAKg"] [Tue Aug 18 13:03:13.017546 2026] [security2:error] [pid 123784:tid 124028] [client 40.74.65.169:38095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcFwAAAG4"] [Tue Aug 18 13:03:13.026404 2026] [security2:error] [pid 139043:tid 139243] [client 178.156.189.249:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joanagaspar.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSCQP2v-lWn9OzQT7UpogAAyw8"], referer: https://joanagaspar.com.br/ [Tue Aug 18 13:03:13.050602 2026] [security2:error] [pid 139043:tid 139125] [remote 187.75.34.18:38911] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSCQf2v-lWn9OzQT7UprwAAo1E"], referer: https://barsantajulia.com.br/ [Tue Aug 18 13:03:13.059453 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:13.059879 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:13.064111 2026] [security2:error] [pid 139043:tid 139216] [client 172.182.217.32:21524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/update.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpsQAAALA"] [Tue Aug 18 13:03:13.066149 2026] [security2:error] [pid 139043:tid 139215] [client 20.116.17.175:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/acp.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpsgAAAK8"] [Tue Aug 18 13:03:13.090250 2026] [security2:error] [pid 123784:tid 123975] [client 40.74.65.169:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/av.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcGgAAADk"] [Tue Aug 18 13:03:13.099975 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:47149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCQf2v-lWn9OzQT7UptgAAAPk"] [Tue Aug 18 13:03:13.128825 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.69.59:59209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gc.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpuwAAAO8"] [Tue Aug 18 13:03:13.180539 2026] [security2:error] [pid 139043:tid 139288] [client 20.80.111.3:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/wp-signup.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpvgAAAPg"] [Tue Aug 18 13:03:13.190412 2026] [security2:error] [pid 139043:tid 139055] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/simple.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpvwAAogs"] [Tue Aug 18 13:03:13.198081 2026] [security2:error] [pid 123784:tid 124042] [client 213.35.127.232:61522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcHQAAAHw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:13.226650 2026] [security2:error] [pid 139043:tid 139233] [client 4.232.151.198:41112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/photo.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpxAAAAME"] [Tue Aug 18 13:03:13.230604 2026] [security2:error] [pid 139043:tid 139260] [client 20.51.153.15:9591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lr.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpxQAAANw"] [Tue Aug 18 13:03:13.252219 2026] [security2:error] [pid 139043:tid 139240] [client 52.173.121.69:27742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/nwwha.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpxgAAAMg"] [Tue Aug 18 13:03:13.252676 2026] [security2:error] [pid 123784:tid 124044] [client 20.163.43.14:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/zxz.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcIAAAAH4"] [Tue Aug 18 13:03:13.296439 2026] [security2:error] [pid 123784:tid 123958] [client 20.25.139.174:2199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcIQAAACg"] [Tue Aug 18 13:03:13.314082 2026] [security2:error] [pid 139043:tid 139178] [client 68.155.154.236:8375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpyQAAAIo"] [Tue Aug 18 13:03:13.328367 2026] [security2:error] [pid 139043:tid 139291] [client 196.12.128.158:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpygAAAPs"] [Tue Aug 18 13:03:13.328542 2026] [security2:error] [pid 139043:tid 139291] [client 196.12.128.158:62785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpygAAAPs"] [Tue Aug 18 13:03:13.347139 2026] [security2:error] [pid 139043:tid 139269] [client 168.62.48.100:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/oivcl.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpzAAAAOU"] [Tue Aug 18 13:03:13.354785 2026] [security2:error] [pid 139043:tid 139209] [client 4.223.113.180:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/simple.php"] [unique_id "aoSCQf2v-lWn9OzQT7UpzgAAAKk"] [Tue Aug 18 13:03:13.358836 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:13.359105 2026] [authz_core:error] [pid 123784:tid 123882] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:13.403434 2026] [security2:error] [pid 139043:tid 139177] [client 20.65.69.59:48502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/uq.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up0AAAAIk"] [Tue Aug 18 13:03:13.405041 2026] [security2:error] [pid 139043:tid 139271] [client 40.74.65.169:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/contacto.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up0QAAAOc"] [Tue Aug 18 13:03:13.449667 2026] [security2:error] [pid 139043:tid 139257] [client 20.250.13.23:30813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up0gAAANk"] [Tue Aug 18 13:03:13.473319 2026] [security2:error] [pid 139043:tid 139283] [client 20.186.30.159:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/scxy.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up1AAAAPM"] [Tue Aug 18 13:03:13.474195 2026] [security2:error] [pid 139043:tid 139087] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up1QAAvys"] [Tue Aug 18 13:03:13.480275 2026] [security2:error] [pid 139043:tid 139194] [client 20.51.153.15:9517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ka.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up1gAAAJo"] [Tue Aug 18 13:03:13.515878 2026] [security2:error] [pid 139043:tid 139136] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/xiugai.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up2AAA2Fw"] [Tue Aug 18 13:03:13.544172 2026] [security2:error] [pid 139043:tid 139085] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/wp-load.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up2gAA8Sk"] [Tue Aug 18 13:03:13.545218 2026] [security2:error] [pid 139043:tid 139273] [client 20.25.139.174:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/admin.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up2wAAAOk"] [Tue Aug 18 13:03:13.563475 2026] [security2:error] [pid 139043:tid 139117] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/155.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up3AAAsUk"] [Tue Aug 18 13:03:13.576258 2026] [security2:error] [pid 139043:tid 139221] [client 172.182.217.32:21551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/input.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up3gAAALU"] [Tue Aug 18 13:03:13.577926 2026] [security2:error] [pid 139043:tid 139179] [client 20.163.43.14:6543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/www.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up3wAAAIs"] [Tue Aug 18 13:03:13.582416 2026] [security2:error] [pid 139043:tid 139049] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/index.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up4AAAiAU"] [Tue Aug 18 13:03:13.597158 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.36.136:57260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/jrpga.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up4gAAAMk"] [Tue Aug 18 13:03:13.600414 2026] [security2:error] [pid 139043:tid 139051] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/aaa.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up4wAA3Qc"] [Tue Aug 18 13:03:13.618933 2026] [security2:error] [pid 139043:tid 139070] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up5AAArRo"] [Tue Aug 18 13:03:13.645691 2026] [security2:error] [pid 139043:tid 139284] [client 20.151.109.219:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wy.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up5gAAAPQ"] [Tue Aug 18 13:03:13.659126 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:13.659393 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:13.659572 2026] [security2:error] [pid 139043:tid 139077] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/site.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up5wAA0CE"] [Tue Aug 18 13:03:13.669285 2026] [security2:error] [pid 139043:tid 139230] [client 20.65.69.59:5395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/32.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up6AAAAL4"] [Tue Aug 18 13:03:13.678271 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:1255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/zugvi.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcMAAAAEs"] [Tue Aug 18 13:03:13.686886 2026] [security2:error] [pid 123784:tid 123968] [client 132.196.30.78:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcMQAAADI"] [Tue Aug 18 13:03:13.698230 2026] [security2:error] [pid 139043:tid 139056] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/ccc.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up6QAA4Qw"] [Tue Aug 18 13:03:13.702851 2026] [security2:error] [pid 123784:tid 123929] [client 40.74.65.169:44195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/bs1.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcMgAAAAs"] [Tue Aug 18 13:03:13.716560 2026] [security2:error] [pid 139043:tid 139086] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/admin.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up6gAAoSo"] [Tue Aug 18 13:03:13.725746 2026] [security2:error] [pid 139043:tid 139290] [client 68.155.154.236:45877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up6wAAAPo"] [Tue Aug 18 13:03:13.736182 2026] [security2:error] [pid 139043:tid 139134] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/reviall.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up7AAAl1o"] [Tue Aug 18 13:03:13.737879 2026] [security2:error] [pid 139043:tid 139218] [client 20.116.17.175:23006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/yas.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up7QAAALI"] [Tue Aug 18 13:03:13.746779 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:7262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up7wAAAKM"] [Tue Aug 18 13:03:13.746802 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:10999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fd.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up7gAAANI"] [Tue Aug 18 13:03:13.753891 2026] [security2:error] [pid 139043:tid 139140] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/nope.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up8AAAr2A"] [Tue Aug 18 13:03:13.773117 2026] [security2:error] [pid 139043:tid 139124] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/nope.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up8QAA-VA"] [Tue Aug 18 13:03:13.783964 2026] [security2:error] [pid 139043:tid 139270] [client 20.25.139.174:2240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/default.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up8gAAAOY"] [Tue Aug 18 13:03:13.792624 2026] [security2:error] [pid 139043:tid 139122] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/new.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up8wAA5E4"] [Tue Aug 18 13:03:13.793618 2026] [security2:error] [pid 139043:tid 139272] [client 20.80.111.3:41020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/xmlrpc.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up5QAAAOg"] [Tue Aug 18 13:03:13.798463 2026] [security2:error] [pid 139043:tid 139279] [client 20.51.153.15:9742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ot.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up9AAAAO8"] [Tue Aug 18 13:03:13.815197 2026] [security2:error] [pid 139043:tid 139298] [client 20.206.73.37:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/mac.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up9QAAAQI"] [Tue Aug 18 13:03:13.831294 2026] [security2:error] [pid 139043:tid 139066] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/new.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up9wAAmRY"] [Tue Aug 18 13:03:13.846547 2026] [security2:error] [pid 139043:tid 139259] [client 4.232.151.198:41131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-aa.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up-AAAANs"] [Tue Aug 18 13:03:13.850060 2026] [security2:error] [pid 139043:tid 139120] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/apreset.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up-QAA-Ew"] [Tue Aug 18 13:03:13.853585 2026] [security2:error] [pid 139043:tid 139169] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bivar.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCQf2v-lWn9OzQT7Up-gAAon0"] [Tue Aug 18 13:03:13.900911 2026] [security2:error] [pid 139043:tid 139233] [client 20.163.43.14:6553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wicked.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up-wAAAME"] [Tue Aug 18 13:03:13.925584 2026] [security2:error] [pid 139043:tid 139138] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/1mage.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up_AAAp14"] [Tue Aug 18 13:03:13.939805 2026] [security2:error] [pid 139043:tid 139232] [client 168.62.48.100:1136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wsrer.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up_gAAAMA"] [Tue Aug 18 13:03:13.950152 2026] [security2:error] [pid 139043:tid 139269] [client 20.206.73.37:26686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/biufile.php"] [unique_id "aoSCQf2v-lWn9OzQT7Up_wAAAOU"] [Tue Aug 18 13:03:13.959250 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:13.959523 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:13.960261 2026] [security2:error] [pid 139043:tid 139227] [client 20.65.69.59:12550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/73.php"] [unique_id "aoSCQf2v-lWn9OzQT7UqAAAAALs"] [Tue Aug 18 13:03:13.968772 2026] [security2:error] [pid 139043:tid 139209] [client 20.116.17.175:54867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/options.php"] [unique_id "aoSCQf2v-lWn9OzQT7UqAQAAAKk"] [Tue Aug 18 13:03:13.988967 2026] [security2:error] [pid 123784:tid 123925] [client 158.23.17.4:17543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/de.php"] [unique_id "aoSCQWwDnJBNj2tDbYYcOQAAAAc"] [Tue Aug 18 13:03:13.993443 2026] [security2:error] [pid 139043:tid 139128] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/imsc.php"] [unique_id "aoSCQf2v-lWn9OzQT7UqAgAAoFQ"] [Tue Aug 18 13:03:14.023455 2026] [security2:error] [pid 139043:tid 139081] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqAwAAlCU"] [Tue Aug 18 13:03:14.028219 2026] [security2:error] [pid 139043:tid 139263] [client 52.173.121.69:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/opsqt.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqBAAAAN8"] [Tue Aug 18 13:03:14.050054 2026] [security2:error] [pid 139043:tid 139132] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/qlex1.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqBQAA1Fg"] [Tue Aug 18 13:03:14.054555 2026] [security2:error] [pid 139043:tid 139271] [client 20.186.30.159:14297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqBgAAAOc"] [Tue Aug 18 13:03:14.057819 2026] [security2:error] [pid 139043:tid 139242] [client 20.25.139.174:4535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/222.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqBwAAAMo"] [Tue Aug 18 13:03:14.069381 2026] [security2:error] [pid 139043:tid 139294] [client 20.250.13.23:30784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqCQAAAP4"] [Tue Aug 18 13:03:14.071661 2026] [security2:error] [pid 139043:tid 139149] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/mariju.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqCgAAt2k"] [Tue Aug 18 13:03:14.074115 2026] [security2:error] [pid 139043:tid 139154] [remote 129.121.123.168:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqCwAA624"] [Tue Aug 18 13:03:14.075306 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/geju.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqDAAAAMg"] [Tue Aug 18 13:03:14.080109 2026] [autoindex:error] [pid 139043:tid 139205] [client 169.58.72.248:57139] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:14.089542 2026] [security2:error] [pid 139043:tid 139212] [client 20.226.36.136:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqDQAAAKw"] [Tue Aug 18 13:03:14.100484 2026] [security2:error] [pid 139043:tid 139297] [client 40.74.65.169:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/image2.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqDgAAAQE"] [Tue Aug 18 13:03:14.109500 2026] [security2:error] [pid 139043:tid 139104] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqDwAAvzw"] [Tue Aug 18 13:03:14.127988 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcOwAAAGA"] [Tue Aug 18 13:03:14.186373 2026] [security2:error] [pid 139043:tid 139084] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/contacto.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqEAAAvCg"] [Tue Aug 18 13:03:14.204208 2026] [security2:error] [pid 123784:tid 123977] [client 20.116.17.175:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ah25.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcPQAAADs"] [Tue Aug 18 13:03:14.204753 2026] [security2:error] [pid 139043:tid 139052] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/image2.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqEgAA6Qg"] [Tue Aug 18 13:03:14.213108 2026] [security2:error] [pid 139043:tid 139237] [client 213.35.127.232:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqFAAAAMU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:14.220837 2026] [security2:error] [pid 123784:tid 123969] [client 168.62.48.100:1141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcPgAAADM"] [Tue Aug 18 13:03:14.224993 2026] [security2:error] [pid 139043:tid 139098] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/fb.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqFwAAyTY"] [Tue Aug 18 13:03:14.237189 2026] [security2:error] [pid 139043:tid 139254] [client 20.51.153.15:9479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ih.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqGAAAANY"] [Tue Aug 18 13:03:14.245811 2026] [security2:error] [pid 139043:tid 139195] [client 20.79.204.6:9712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/classwithtostring.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqGQAAAJs"] [Tue Aug 18 13:03:14.249455 2026] [security2:error] [pid 139043:tid 139046] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/gi.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqGgAArQI"] [Tue Aug 18 13:03:14.251844 2026] [security2:error] [pid 139043:tid 139251] [client 20.163.43.14:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqGwAAANM"] [Tue Aug 18 13:03:14.258093 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:14.258371 2026] [authz_core:error] [pid 123784:tid 123839] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:14.263673 2026] [security2:error] [pid 139043:tid 139293] [client 20.65.69.59:5731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ib.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqHAAAAP0"] [Tue Aug 18 13:03:14.274132 2026] [security2:error] [pid 139043:tid 139206] [client 20.25.139.174:2186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/i.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqHgAAAKY"] [Tue Aug 18 13:03:14.279288 2026] [security2:error] [pid 139043:tid 139266] [client 213.202.253.4:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/memberfuns.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqHwAAAOI"], referer: www.google.com [Tue Aug 18 13:03:14.283512 2026] [security2:error] [pid 139043:tid 139139] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/video.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqIAAAkF8"] [Tue Aug 18 13:03:14.285273 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCQv2v-lWn9OzQT7UqIQAAAK4"] [Tue Aug 18 13:03:14.300187 2026] [security2:error] [pid 139043:tid 139166] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/hel.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqIwAA4Xo"] [Tue Aug 18 13:03:14.305087 2026] [security2:error] [pid 139043:tid 139045] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "bivar.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCQv2v-lWn9OzQT7UqJAAAtAE"] [Tue Aug 18 13:03:14.317997 2026] [security2:error] [pid 139043:tid 139103] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/grok.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqJQAA1zs"] [Tue Aug 18 13:03:14.330159 2026] [security2:error] [pid 139043:tid 139182] [client 20.80.111.3:40689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/wp-cron.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqJwAAAI4"] [Tue Aug 18 13:03:14.339737 2026] [security2:error] [pid 139043:tid 139155] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/indes.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqKAAAl28"] [Tue Aug 18 13:03:14.361596 2026] [security2:error] [pid 139043:tid 139095] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqKQAAhjM"] [Tue Aug 18 13:03:14.363336 2026] [security2:error] [pid 123784:tid 124007] [client 20.186.30.159:14319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/blurbs.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcQwAAAFk"] [Tue Aug 18 13:03:14.379506 2026] [security2:error] [pid 123784:tid 124022] [client 40.74.65.169:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/images.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcRQAAAGg"] [Tue Aug 18 13:03:14.380592 2026] [security2:error] [pid 139043:tid 139158] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/bs1.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqKgAAy3I"] [Tue Aug 18 13:03:14.397377 2026] [security2:error] [pid 139043:tid 139267] [client 20.206.73.37:59871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ops.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqKwAAAOM"] [Tue Aug 18 13:03:14.397400 2026] [security2:error] [pid 139043:tid 139249] [client 40.74.65.169:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/hp2.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqLAAAANE"] [Tue Aug 18 13:03:14.401284 2026] [security2:error] [pid 139043:tid 139157] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/hp2.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqLQAAsHE"] [Tue Aug 18 13:03:14.409386 2026] [security2:error] [pid 123784:tid 123973] [client 158.23.17.4:63639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/info2.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcRwAAADc"] [Tue Aug 18 13:03:14.418823 2026] [security2:error] [pid 139043:tid 139141] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/yb.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqLgAA5mE"] [Tue Aug 18 13:03:14.463822 2026] [security2:error] [pid 139043:tid 139146] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bivar.com.br"] [uri "/config/.env.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqMQAAjGY"] [Tue Aug 18 13:03:14.464815 2026] [security2:error] [pid 139043:tid 139162] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/laravel/.env"] [unique_id "aoSCQv2v-lWn9OzQT7UqMgAAjHY"] [Tue Aug 18 13:03:14.473114 2026] [security2:error] [pid 139043:tid 139090] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/vc.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqMwAA7S4"] [Tue Aug 18 13:03:14.478115 2026] [security2:error] [pid 139043:tid 139287] [client 4.232.151.198:41091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/d.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqNAAAAPc"] [Tue Aug 18 13:03:14.496938 2026] [security2:error] [pid 139043:tid 139060] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bivar.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCQv2v-lWn9OzQT7UqNQAA-BA"] [Tue Aug 18 13:03:14.504817 2026] [security2:error] [pid 139043:tid 139202] [client 20.51.153.15:8296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/k.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqNgAAAKI"] [Tue Aug 18 13:03:14.506058 2026] [security2:error] [pid 139043:tid 139133] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/pema.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqNwAAxFk"] [Tue Aug 18 13:03:14.524613 2026] [security2:error] [pid 139043:tid 139229] [client 168.62.48.100:1202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/yxijx.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqOQAAAL0"] [Tue Aug 18 13:03:14.556282 2026] [security2:error] [pid 139043:tid 139064] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/sh.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqPAAAihQ"] [Tue Aug 18 13:03:14.559488 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:14.559747 2026] [authz_core:error] [pid 123784:tid 123844] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:14.566598 2026] [security2:error] [pid 139043:tid 139246] [client 172.182.217.32:21507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqPQAAAM4"] [Tue Aug 18 13:03:14.573202 2026] [security2:error] [pid 139043:tid 139047] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/button.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqPgAAwAM"] [Tue Aug 18 13:03:14.578688 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqPwAAAPs"] [Tue Aug 18 13:03:14.590101 2026] [security2:error] [pid 139043:tid 139203] [client 20.25.139.174:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqQAAAAKM"] [Tue Aug 18 13:03:14.590752 2026] [security2:error] [pid 139043:tid 139111] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/wlc.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqQQAA5UM"] [Tue Aug 18 13:03:14.611942 2026] [security2:error] [pid 139043:tid 139145] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/fi.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqQwAApGU"] [Tue Aug 18 13:03:14.620281 2026] [security2:error] [pid 139043:tid 139227] [client 20.65.69.59:58564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xm.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqRAAAALs"] [Tue Aug 18 13:03:14.639554 2026] [security2:error] [pid 139043:tid 139263] [client 20.186.30.159:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/bajah.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqRgAAAN8"] [Tue Aug 18 13:03:14.650900 2026] [security2:error] [pid 139043:tid 139063] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/chris.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqRwAAzxM"] [Tue Aug 18 13:03:14.659385 2026] [security2:error] [pid 139043:tid 139271] [client 52.173.121.69:37297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqSAAAAOc"] [Tue Aug 18 13:03:14.673328 2026] [security2:error] [pid 139043:tid 139080] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/doc.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqSQAAyiQ"] [Tue Aug 18 13:03:14.691305 2026] [security2:error] [pid 139043:tid 139275] [client 169.58.45.73:48342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pixmidias.com.br"] [uri "/.env"] [unique_id "aoSCQv2v-lWn9OzQT7UqSgAAAOs"] [Tue Aug 18 13:03:14.692412 2026] [security2:error] [pid 139043:tid 139044] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/1337.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqSwAAyAA"] [Tue Aug 18 13:03:14.711769 2026] [security2:error] [pid 139043:tid 139123] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/Njima.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqTAAAuU8"] [Tue Aug 18 13:03:14.721930 2026] [security2:error] [pid 139043:tid 139297] [client 132.196.30.78:6260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/xmr.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqTQAAAQE"] [Tue Aug 18 13:03:14.735156 2026] [security2:error] [pid 139043:tid 139097] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqTwAAvzU"] [Tue Aug 18 13:03:14.737522 2026] [security2:error] [pid 123784:tid 124013] [client 114.119.136.199:41871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/categoria/suporte/ultimas-atualizacoes/"] [unique_id "aoSCQmwDnJBNj2tDbYYcUgAAAF8"], referer: https://ajuda.oruc.com.br/tag/atualizacoes/ [Tue Aug 18 13:03:14.751066 2026] [security2:error] [pid 139043:tid 139245] [client 20.116.17.175:55189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/ano.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqUQAAAM0"] [Tue Aug 18 13:03:14.754196 2026] [security2:error] [pid 139043:tid 139074] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/too.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqUgAAxR4"] [Tue Aug 18 13:03:14.766571 2026] [security2:error] [pid 139043:tid 139200] [client 20.80.111.3:17944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/wp-mail.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqUwAAAKA"] [Tue Aug 18 13:03:14.771762 2026] [security2:error] [pid 139043:tid 139161] [remote 191.237.254.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "martinmadeireira.com.br"] [uri "/g3.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqVAAAxnU"] [Tue Aug 18 13:03:14.774508 2026] [security2:error] [pid 123784:tid 123990] [client 40.74.65.169:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/fb.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcVAAAAEg"] [Tue Aug 18 13:03:14.789236 2026] [security2:error] [pid 123784:tid 123935] [client 20.51.153.15:9804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/iu.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcVQAAABE"] [Tue Aug 18 13:03:14.793056 2026] [security2:error] [pid 123784:tid 123932] [client 74.248.130.103:42034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcVgAAAA4"] [Tue Aug 18 13:03:14.811407 2026] [security2:error] [pid 123784:tid 124045] [client 168.62.48.100:1135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcVwAAAH8"] [Tue Aug 18 13:03:14.861911 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:14.862167 2026] [authz_core:error] [pid 123784:tid 123853] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:14.881408 2026] [security2:error] [pid 139043:tid 139054] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/core/.env"] [unique_id "aoSCQv2v-lWn9OzQT7UqXAAArgo"] [Tue Aug 18 13:03:14.893636 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.69.59:54128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/zy.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcWgAAAAY"] [Tue Aug 18 13:03:14.902958 2026] [security2:error] [pid 123784:tid 124016] [client 20.163.43.14:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/cah.php"] [unique_id "aoSCQmwDnJBNj2tDbYYcWwAAAGI"] [Tue Aug 18 13:03:14.940374 2026] [security2:error] [pid 139043:tid 139182] [client 20.250.13.23:30836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqXgAAAI4"] [Tue Aug 18 13:03:14.941382 2026] [security2:error] [pid 139043:tid 139290] [client 20.186.30.159:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/domvf.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqXwAAAPo"] [Tue Aug 18 13:03:14.961883 2026] [security2:error] [pid 139043:tid 139208] [client 20.25.139.174:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCQv2v-lWn9OzQT7UqYAAAAKg"] [Tue Aug 18 13:03:15.028612 2026] [security2:error] [pid 123784:tid 123960] [client 68.155.154.236:8651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcXQAAACo"] [Tue Aug 18 13:03:15.031812 2026] [security2:error] [pid 123784:tid 123941] [client 158.23.17.4:29461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sx.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcXgAAABc"] [Tue Aug 18 13:03:15.041444 2026] [security2:error] [pid 139043:tid 139272] [client 20.51.153.15:9477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pk.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqZwAAAOg"] [Tue Aug 18 13:03:15.073188 2026] [security2:error] [pid 139043:tid 139175] [client 40.74.65.169:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/yb.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqawAAAIc"] [Tue Aug 18 13:03:15.074211 2026] [security2:error] [pid 139043:tid 139194] [client 20.116.17.175:23034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/nwflm.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqbAAAAJo"] [Tue Aug 18 13:03:15.077049 2026] [security2:error] [pid 139043:tid 139220] [client 172.182.217.32:21504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/hoot.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqbQAAALQ"] [Tue Aug 18 13:03:15.108060 2026] [security2:error] [pid 139043:tid 139262] [client 4.232.151.198:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/widgets.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqbgAAAN4"] [Tue Aug 18 13:03:15.135895 2026] [security2:error] [pid 123784:tid 124033] [client 20.65.69.59:12566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/q.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcYgAAAHM"] [Tue Aug 18 13:03:15.144074 2026] [security2:error] [pid 139043:tid 139243] [client 20.25.139.174:4657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/info.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqcQAAAMs"] [Tue Aug 18 13:03:15.144509 2026] [security2:error] [pid 139043:tid 139180] [client 168.62.48.100:1155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/jrpga.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqcgAAAIw"] [Tue Aug 18 13:03:15.155643 2026] [security2:error] [pid 139043:tid 139078] [remote 187.75.34.18:38911] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqcwAA7yI"], referer: https://barsantajulia.com.br/ [Tue Aug 18 13:03:15.198714 2026] [security2:error] [pid 139043:tid 139236] [client 158.23.17.4:55221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/album.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqdAAAAMQ"] [Tue Aug 18 13:03:15.200988 2026] [security2:error] [pid 139043:tid 139298] [client 20.80.111.3:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/xmlrpc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqdQAAAQI"] [Tue Aug 18 13:03:15.213355 2026] [security2:error] [pid 139043:tid 139119] [remote 187.75.34.18:38911] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqfAAAiEs"], referer: https://barsantajulia.com.br/buffet/ [Tue Aug 18 13:03:15.229464 2026] [security2:error] [pid 139043:tid 139248] [client 213.35.127.232:61930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqfwAAANA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:15.236962 2026] [security2:error] [pid 123784:tid 124020] [client 20.186.30.159:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/fpwch.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcZgAAAGY"] [Tue Aug 18 13:03:15.286811 2026] [security2:error] [pid 139043:tid 139178] [client 20.51.153.15:9823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ge.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqgAAAAIo"] [Tue Aug 18 13:03:15.294299 2026] [security2:error] [pid 139043:tid 139171] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqgQAAzn8"] [Tue Aug 18 13:03:15.294497 2026] [security2:error] [pid 139043:tid 139246] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqgQAAzn8"] [Tue Aug 18 13:03:15.314839 2026] [security2:error] [pid 139043:tid 139281] [client 20.151.109.219:21263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/f.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqgwAAAPE"] [Tue Aug 18 13:03:15.318121 2026] [security2:error] [pid 139043:tid 139269] [client 68.155.154.236:53649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqhAAAAOU"] [Tue Aug 18 13:03:15.408100 2026] [security2:error] [pid 139043:tid 139271] [client 52.173.121.69:27712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqhwAAAOc"] [Tue Aug 18 13:03:15.408600 2026] [security2:error] [pid 139043:tid 139294] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/0.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqiQAAAP4"] [Tue Aug 18 13:03:15.410918 2026] [security2:error] [pid 139043:tid 139191] [client 86.120.159.145:58485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqigAAAJc"] [Tue Aug 18 13:03:15.410999 2026] [security2:error] [pid 139043:tid 139191] [client 86.120.159.145:58485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqigAAAJc"] [Tue Aug 18 13:03:15.428568 2026] [security2:error] [pid 139043:tid 139275] [client 20.65.69.59:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xf.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqiwAAAOs"] [Tue Aug 18 13:03:15.464141 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:15.464416 2026] [authz_core:error] [pid 123784:tid 123877] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:15.470497 2026] [security2:error] [pid 123784:tid 123974] [client 40.74.65.169:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/gi.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcbgAAADg"] [Tue Aug 18 13:03:15.486405 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/dom.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqjQAAAJM"] [Tue Aug 18 13:03:15.493558 2026] [security2:error] [pid 139043:tid 139091] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bivar.com.br"] [uri "/config.php.bak"] [unique_id "aoSCQ_2v-lWn9OzQT7UqjgABAS8"] [Tue Aug 18 13:03:15.511363 2026] [security2:error] [pid 139043:tid 139183] [client 20.186.30.159:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/adminner.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqjwAAAI8"] [Tue Aug 18 13:03:15.513891 2026] [security2:error] [pid 123784:tid 123976] [client 20.25.139.174:2416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYccQAAADo"] [Tue Aug 18 13:03:15.535703 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:9487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kl.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqkAAAAQM"] [Tue Aug 18 13:03:15.551100 2026] [security2:error] [pid 139043:tid 139088] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.git/HEAD"] [unique_id "aoSCQ_2v-lWn9OzQT7UqkQAAwyw"] [Tue Aug 18 13:03:15.557587 2026] [security2:error] [pid 139043:tid 139258] [client 168.62.48.100:1145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqkgAAANo"] [Tue Aug 18 13:03:15.564744 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/bb.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqlAAAAOk"] [Tue Aug 18 13:03:15.566092 2026] [security2:error] [pid 123784:tid 123936] [client 172.182.217.32:21811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYccgAAABI"] [Tue Aug 18 13:03:15.577641 2026] [security2:error] [pid 139043:tid 139107] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bivar.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCQ_2v-lWn9OzQT7UqlQAAxT8"] [Tue Aug 18 13:03:15.588993 2026] [security2:error] [pid 139043:tid 139221] [client 168.62.48.100:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqlgAAALU"] [Tue Aug 18 13:03:15.590079 2026] [security2:error] [pid 139043:tid 139292] [client 20.116.17.175:3443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/ms-files.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqlwAAAPw"] [Tue Aug 18 13:03:15.593510 2026] [security2:error] [pid 123784:tid 123958] [client 20.163.43.14:6654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/system_log.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYccwAAACg"] [Tue Aug 18 13:03:15.594291 2026] [security2:error] [pid 139043:tid 139108] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.gitconfig"] [unique_id "aoSCQ_2v-lWn9OzQT7UqmAAAyUA"] [Tue Aug 18 13:03:15.596291 2026] [security2:error] [pid 139043:tid 139200] [client 20.116.17.175:55199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/wp-load.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqmQAAAKA"] [Tue Aug 18 13:03:15.600383 2026] [security2:error] [pid 139043:tid 139073] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.git-credentials"] [unique_id "aoSCQ_2v-lWn9OzQT7UqmgAAsh0"] [Tue Aug 18 13:03:15.601522 2026] [security2:error] [pid 139043:tid 139127] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSCQ_2v-lWn9OzQT7UqnAAAm1M"] [Tue Aug 18 13:03:15.601765 2026] [security2:error] [pid 139043:tid 139179] [client 4.223.113.180:17374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/berax.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqmwAAAIs"] [Tue Aug 18 13:03:15.603705 2026] [security2:error] [pid 139043:tid 139093] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "aoSCQ_2v-lWn9OzQT7UqnQAAqTE"] [Tue Aug 18 13:03:15.603794 2026] [security2:error] [pid 123784:tid 123961] [client 20.250.13.23:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcdQAAACs"] [Tue Aug 18 13:03:15.622868 2026] [security2:error] [pid 139043:tid 139113] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/.env.swp"] [unique_id "aoSCQ_2v-lWn9OzQT7UqngAA1kU"] [Tue Aug 18 13:03:15.637467 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.36.136:57263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/nwwha.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqnwAAAKY"] [Tue Aug 18 13:03:15.678473 2026] [security2:error] [pid 139043:tid 139089] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env"] [unique_id "aoSCQ_2v-lWn9OzQT7UqoAAAoS0"] [Tue Aug 18 13:03:15.695062 2026] [security2:error] [pid 123784:tid 123931] [client 20.65.69.59:5430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gb.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYceQAAAA0"] [Tue Aug 18 13:03:15.705978 2026] [security2:error] [pid 123784:tid 124044] [client 20.80.111.3:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/api.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcegAAAH4"] [Tue Aug 18 13:03:15.730136 2026] [security2:error] [pid 123784:tid 123984] [client 4.232.151.198:22213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcewAAAEI"] [Tue Aug 18 13:03:15.765892 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:15.766148 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:15.771163 2026] [security2:error] [pid 139043:tid 139230] [client 40.74.65.169:38410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/vc.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqpQAAAL4"] [Tue Aug 18 13:03:15.783678 2026] [security2:error] [pid 139043:tid 139293] [client 20.25.139.174:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/a.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqpgAAAP0"] [Tue Aug 18 13:03:15.814710 2026] [security2:error] [pid 123784:tid 124030] [client 20.206.73.37:35300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/h.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcfgAAAHA"] [Tue Aug 18 13:03:15.820564 2026] [security2:error] [pid 123784:tid 123968] [client 20.51.153.15:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gs.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcfwAAADI"] [Tue Aug 18 13:03:15.849908 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ok.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqqAAAAJA"] [Tue Aug 18 13:03:15.864366 2026] [security2:error] [pid 139043:tid 139190] [client 168.62.48.100:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqqQAAAJY"] [Tue Aug 18 13:03:15.866885 2026] [security2:error] [pid 139043:tid 139277] [client 20.79.204.6:9699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/666.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqqgAAAO0"] [Tue Aug 18 13:03:15.892069 2026] [security2:error] [pid 123784:tid 124015] [client 168.62.48.100:1187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/nwwha.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYcgQAAAGE"] [Tue Aug 18 13:03:15.896942 2026] [security2:error] [pid 139043:tid 139180] [client 20.186.30.159:14221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/abcd.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqrQAAAIw"] [Tue Aug 18 13:03:15.909470 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:9314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nu.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqrwAAANs"] [Tue Aug 18 13:03:15.925671 2026] [security2:error] [pid 139043:tid 139283] [client 144.76.22.178:53940] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqogAAAPM"] [Tue Aug 18 13:03:15.981621 2026] [security2:error] [pid 139043:tid 139236] [client 20.116.17.175:22914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/jj.php"] [unique_id "aoSCQ_2v-lWn9OzQT7UqsQAAAMQ"] [Tue Aug 18 13:03:15.991662 2026] [security2:error] [pid 123784:tid 123925] [client 20.65.69.59:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/jp.php"] [unique_id "aoSCQ2wDnJBNj2tDbYYchAAAAAc"] [Tue Aug 18 13:03:16.053252 2026] [security2:error] [pid 139043:tid 139055] [remote 129.121.74.194:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rhinteligente360.com.br"] [uri "/wp-login.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqsgAAkQs"] [Tue Aug 18 13:03:16.062174 2026] [security2:error] [pid 139043:tid 139243] [client 20.25.139.174:2176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqswAAAMs"] [Tue Aug 18 13:03:16.064871 2026] [security2:error] [pid 123784:tid 123989] [client 172.182.217.32:21823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/db-cache.php"] [unique_id "aoSCRGwDnJBNj2tDbYYchwAAAEc"] [Tue Aug 18 13:03:16.083625 2026] [security2:error] [pid 139043:tid 139248] [client 20.151.109.219:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/30.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqtAAAANA"] [Tue Aug 18 13:03:16.090734 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:16.091165 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:16.109255 2026] [security2:error] [pid 139043:tid 139207] [client 20.51.153.15:9739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lw.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqtQAAAKc"] [Tue Aug 18 13:03:16.134280 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.73.37:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/8.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqtwAAAPs"] [Tue Aug 18 13:03:16.143936 2026] [security2:error] [pid 139043:tid 139227] [client 40.74.65.169:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/video.php"] [unique_id "aoSCRP2v-lWn9OzQT7UquAAAALs"] [Tue Aug 18 13:03:16.204068 2026] [security2:error] [pid 139043:tid 139298] [client 20.80.111.3:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/assets/script-loader.php"] [unique_id "aoSCRP2v-lWn9OzQT7UquQAAAQI"] [Tue Aug 18 13:03:16.229745 2026] [security2:error] [pid 139043:tid 139257] [client 20.250.13.23:3618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSCRP2v-lWn9OzQT7UquwAAANk"] [Tue Aug 18 13:03:16.247241 2026] [security2:error] [pid 139043:tid 139223] [client 20.163.43.14:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqvAAAALc"] [Tue Aug 18 13:03:16.247241 2026] [security2:error] [pid 123784:tid 123999] [client 213.35.127.232:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcjgAAAFE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:16.250372 2026] [security2:error] [pid 139043:tid 139191] [client 52.173.121.69:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqvQAAAJc"] [Tue Aug 18 13:03:16.263354 2026] [security2:error] [pid 139043:tid 139275] [client 74.248.130.103:34983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqvwAAAOs"] [Tue Aug 18 13:03:16.313425 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.69.59:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/eq.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcjwAAAGg"] [Tue Aug 18 13:03:16.316281 2026] [security2:error] [pid 139043:tid 139094] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/public/.env"] [unique_id "aoSCRP2v-lWn9OzQT7UqwgAAyDI"] [Tue Aug 18 13:03:16.318750 2026] [security2:error] [pid 123784:tid 123988] [client 20.25.139.174:4577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/chosen.php"] [unique_id "aoSCRGwDnJBNj2tDbYYckAAAAEY"] [Tue Aug 18 13:03:16.320325 2026] [security2:error] [pid 139043:tid 139205] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqwQAApUg"] [Tue Aug 18 13:03:16.344546 2026] [security2:error] [pid 139043:tid 139281] [client 4.232.151.198:10371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/abc.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqxQAAAPE"] [Tue Aug 18 13:03:16.367928 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:16.367954 2026] [security2:error] [pid 139043:tid 139187] [client 20.51.153.15:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vj.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqxgAAAJM"] [Tue Aug 18 13:03:16.369998 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:16.389011 2026] [security2:error] [pid 139043:tid 139297] [client 20.116.17.175:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/img.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqxwAAAQE"] [Tue Aug 18 13:03:16.416216 2026] [security2:error] [pid 139043:tid 139256] [client 40.74.65.169:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ops.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqyAAAANg"] [Tue Aug 18 13:03:16.422546 2026] [security2:error] [pid 139043:tid 139235] [client 158.23.17.4:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ko.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqyQAAAMM"] [Tue Aug 18 13:03:16.451500 2026] [security2:error] [pid 139043:tid 139237] [client 20.116.17.175:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqygAAAMU"] [Tue Aug 18 13:03:16.464619 2026] [security2:error] [pid 139043:tid 139292] [client 40.74.65.169:38413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/pema.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqzAAAAPw"] [Tue Aug 18 13:03:16.489434 2026] [security2:error] [pid 139043:tid 139195] [client 20.186.30.159:14240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/simple.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqzQAAAJs"] [Tue Aug 18 13:03:16.503757 2026] [security2:error] [pid 139043:tid 139251] [client 132.196.30.78:6233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/about.php"] [unique_id "aoSCRP2v-lWn9OzQT7UqzgAAANM"] [Tue Aug 18 13:03:16.537886 2026] [access_compat:error] [pid 139043:tid 139085] [remote 74.7.230.59:49076] AH01797: client denied by server configuration: /home1/classea/public_html/robots.txt [Tue Aug 18 13:03:16.539035 2026] [security2:error] [pid 139043:tid 139231] [client 74.7.230.59:49076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "classeanovohamburgo.com.br"] [uri "/cgi-sys/403.html"] [unique_id "aoSCRP2v-lWn9OzQT7Uq0AAAvyk"] [Tue Aug 18 13:03:16.552788 2026] [security2:error] [pid 123784:tid 123957] [client 168.62.48.100:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/opsqt.php"] [unique_id "aoSCRGwDnJBNj2tDbYYclwAAACc"] [Tue Aug 18 13:03:16.561104 2026] [security2:error] [pid 123784:tid 123992] [client 172.182.217.32:21858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/twentyeleven/functions.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcmAAAAEo"] [Tue Aug 18 13:03:16.573398 2026] [security2:error] [pid 139043:tid 139254] [client 20.163.43.14:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq0gAAANY"] [Tue Aug 18 13:03:16.630585 2026] [security2:error] [pid 139043:tid 139284] [client 20.65.69.59:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ep.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq1AAAAPQ"] [Tue Aug 18 13:03:16.655732 2026] [security2:error] [pid 123784:tid 123923] [client 20.25.139.174:2371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/NewFile.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcmwAAAAU"] [Tue Aug 18 13:03:16.670907 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:16.671271 2026] [authz_core:error] [pid 123784:tid 123906] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:16.673380 2026] [security2:error] [pid 139043:tid 139049] [remote 136.110.27.48:38602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bivar.com.br"] [uri "/web/.env"] [unique_id "aoSCRP2v-lWn9OzQT7Uq1gAAngU"] [Tue Aug 18 13:03:16.683869 2026] [security2:error] [pid 123784:tid 123946] [client 20.226.36.136:43658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/opsqt.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcnQAAABw"] [Tue Aug 18 13:03:16.707872 2026] [security2:error] [pid 139043:tid 139051] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.example"] [unique_id "aoSCRP2v-lWn9OzQT7Uq1wAA1wc"] [Tue Aug 18 13:03:16.717550 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mimes.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq2AAAAI4"] [Tue Aug 18 13:03:16.730533 2026] [security2:error] [pid 139043:tid 139070] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.local"] [unique_id "aoSCRP2v-lWn9OzQT7Uq2QAA-ho"] [Tue Aug 18 13:03:16.730613 2026] [security2:error] [pid 123784:tid 124013] [client 74.248.130.103:54876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/domvf.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcnwAAAF8"] [Tue Aug 18 13:03:16.731020 2026] [security2:error] [pid 139043:tid 139112] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.production"] [unique_id "aoSCRP2v-lWn9OzQT7Uq2gAA-kQ"] [Tue Aug 18 13:03:16.734323 2026] [security2:error] [pid 139043:tid 139056] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.backup"] [unique_id "aoSCRP2v-lWn9OzQT7Uq3AAA4ww"] [Tue Aug 18 13:03:16.736550 2026] [security2:error] [pid 139043:tid 139086] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.bak"] [unique_id "aoSCRP2v-lWn9OzQT7Uq3QAAhSo"] [Tue Aug 18 13:03:16.758613 2026] [security2:error] [pid 139043:tid 139175] [client 20.116.17.175:22934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drvitorpereirafaria.com.br"] [uri "/we.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq3wAAAIc"] [Tue Aug 18 13:03:16.794437 2026] [security2:error] [pid 139043:tid 139190] [client 52.173.121.69:9518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq4AAAAJY"] [Tue Aug 18 13:03:16.840554 2026] [security2:error] [pid 139043:tid 139279] [client 40.74.65.169:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/hel.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq5QAAAO8"] [Tue Aug 18 13:03:16.896028 2026] [security2:error] [pid 139043:tid 139224] [client 20.65.69.59:5391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/rf.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq6AAAALg"] [Tue Aug 18 13:03:16.899665 2026] [security2:error] [pid 123784:tid 123918] [client 20.163.43.14:6540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/abc.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcpgAAAAA"] [Tue Aug 18 13:03:16.905219 2026] [security2:error] [pid 139043:tid 139122] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.env.old"] [unique_id "aoSCRP2v-lWn9OzQT7Uq7AAA9k4"] [Tue Aug 18 13:03:16.905386 2026] [security2:error] [pid 139043:tid 139243] [client 20.186.30.159:14261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq6wAAAMs"] [Tue Aug 18 13:03:16.918811 2026] [security2:error] [pid 139043:tid 139293] [client 20.25.139.174:4722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/index.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq7QAAAP0"] [Tue Aug 18 13:03:16.975035 2026] [security2:error] [pid 139043:tid 139194] [client 4.232.151.198:41126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/classwithtostring.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq8AAAAJo"] [Tue Aug 18 13:03:16.977844 2026] [security2:error] [pid 139043:tid 139244] [client 52.173.121.69:37286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCRP2v-lWn9OzQT7Uq8QAAAMw"] [Tue Aug 18 13:03:17.003684 2026] [security2:error] [pid 123784:tid 123924] [client 20.80.111.3:41018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/blocks/heading/min.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcqgAAAAY"] [Tue Aug 18 13:03:17.004973 2026] [security2:error] [pid 123784:tid 124016] [client 20.206.73.37:20708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/biufile.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcqwAAAGI"] [Tue Aug 18 13:03:17.041284 2026] [security2:error] [pid 139043:tid 139144] [remote 129.121.74.194:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rhinteligente360.com.br"] [uri "/wp-login.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq8wAAo2Q"], referer: https://rhinteligente360.com.br/wp-login.php [Tue Aug 18 13:03:17.045162 2026] [security2:error] [pid 139043:tid 139298] [client 20.51.153.15:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ni.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq9AAAAQI"] [Tue Aug 18 13:03:17.047223 2026] [security2:error] [pid 139043:tid 139252] [client 4.223.113.180:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fi2.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq9QAAANQ"] [Tue Aug 18 13:03:17.055037 2026] [security2:error] [pid 123784:tid 123932] [client 172.182.217.32:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/oceanwp/functions.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcrAAAAA4"] [Tue Aug 18 13:03:17.059259 2026] [security2:error] [pid 123784:tid 124010] [client 20.250.13.23:30797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcrgAAAFw"] [Tue Aug 18 13:03:17.088941 2026] [security2:error] [pid 139043:tid 139247] [client 168.62.48.100:1103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq9gAAAM8"] [Tue Aug 18 13:03:17.148460 2026] [security2:error] [pid 139043:tid 139223] [client 68.155.154.236:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq9wAAALc"] [Tue Aug 18 13:03:17.152699 2026] [security2:error] [pid 123784:tid 123960] [client 74.7.244.31:53952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mhost.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSCRWwDnJBNj2tDbYYcrwAAACo"] [Tue Aug 18 13:03:17.161422 2026] [security2:error] [pid 139043:tid 139294] [client 40.74.65.169:38406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/sh.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq-AAAAP4"] [Tue Aug 18 13:03:17.177922 2026] [security2:error] [pid 139043:tid 139240] [client 191.237.254.161:51492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/sf.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq-QAAAMg"] [Tue Aug 18 13:03:17.183415 2026] [security2:error] [pid 139043:tid 139281] [client 20.65.69.59:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xynz1.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq-gAAAPE"] [Tue Aug 18 13:03:17.227346 2026] [security2:error] [pid 139043:tid 139217] [client 20.163.43.14:6606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/akcc.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq_AAAALE"] [Tue Aug 18 13:03:17.229897 2026] [security2:error] [pid 123784:tid 123951] [client 74.248.130.103:7925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcsQAAACE"] [Tue Aug 18 13:03:17.234616 2026] [security2:error] [pid 139043:tid 139174] [client 20.25.139.174:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq_QAAAIY"] [Tue Aug 18 13:03:17.237328 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:8722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/pl.php"] [unique_id "aoSCRf2v-lWn9OzQT7Uq_gAAAQM"] [Tue Aug 18 13:03:17.250918 2026] [security2:error] [pid 123784:tid 123934] [client 168.62.48.100:4199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcswAAABA"] [Tue Aug 18 13:03:17.268279 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:17.268558 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:17.269571 2026] [security2:error] [pid 139043:tid 139248] [client 213.35.127.232:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrAQAAANA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:17.284892 2026] [security2:error] [pid 139043:tid 139263] [client 4.232.151.198:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/vx.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrAgAAAN8"] [Tue Aug 18 13:03:17.294714 2026] [security2:error] [pid 123784:tid 124023] [client 20.51.153.15:9580] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bergoninf.com"] [uri "/1.php"] [unique_id "aoSCRWwDnJBNj2tDbYYctgAAAGk"] [Tue Aug 18 13:03:17.294841 2026] [security2:error] [pid 123784:tid 124023] [client 20.51.153.15:9580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/1.php"] [unique_id "aoSCRWwDnJBNj2tDbYYctgAAAGk"] [Tue Aug 18 13:03:17.438816 2026] [security2:error] [pid 139043:tid 139195] [client 168.62.48.100:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrBQAAAJs"] [Tue Aug 18 13:03:17.448988 2026] [security2:error] [pid 139043:tid 139273] [client 20.80.111.3:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/config.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrBgAAAOk"] [Tue Aug 18 13:03:17.473551 2026] [security2:error] [pid 123784:tid 123972] [client 20.65.69.59:27868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vo.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcugAAADY"] [Tue Aug 18 13:03:17.494996 2026] [security2:error] [pid 139043:tid 139256] [client 20.25.139.174:4706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/vx.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrCAAAANg"] [Tue Aug 18 13:03:17.495526 2026] [security2:error] [pid 139043:tid 139254] [client 20.116.17.175:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/output.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrCQAAANY"] [Tue Aug 18 13:03:17.528991 2026] [security2:error] [pid 123784:tid 123928] [client 68.155.154.236:55479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcvQAAAAo"] [Tue Aug 18 13:03:17.540451 2026] [security2:error] [pid 123784:tid 123959] [client 40.74.65.169:55287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/grok.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcvgAAACk"] [Tue Aug 18 13:03:17.541869 2026] [security2:error] [pid 123784:tid 123998] [client 20.151.109.219:10581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pu.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcvwAAAFA"] [Tue Aug 18 13:03:17.541958 2026] [security2:error] [pid 139043:tid 139200] [client 172.182.217.32:21857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/twentythirteen/functions.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrCgAAAKA"] [Tue Aug 18 13:03:17.567134 2026] [security2:error] [pid 139043:tid 139264] [client 20.163.43.14:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wk/index.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrCwAAAOA"] [Tue Aug 18 13:03:17.573156 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:17.573438 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:17.587579 2026] [security2:error] [pid 139043:tid 139284] [client 20.51.153.15:8293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/88.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrDAAAAPQ"] [Tue Aug 18 13:03:17.601404 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.151.198:22218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/adminfuns.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrDgAAAMY"] [Tue Aug 18 13:03:17.630650 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.126:44086] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:17.630932 2026] [authz_core:error] [pid 139043:tid 139104] [remote 57.141.22.126:44086] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:17.670364 2026] [security2:error] [pid 139043:tid 139290] [client 20.186.30.159:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/xiugai.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrEQAAAPo"] [Tue Aug 18 13:03:17.694336 2026] [security2:error] [pid 139043:tid 139285] [client 20.118.133.132:42196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/inso.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrFAAAAPU"] [Tue Aug 18 13:03:17.725021 2026] [security2:error] [pid 123784:tid 123962] [client 74.248.130.103:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/gec.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcwwAAACw"] [Tue Aug 18 13:03:17.726384 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.69.59:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wu.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrFQAAALA"] [Tue Aug 18 13:03:17.750613 2026] [security2:error] [pid 123784:tid 124000] [client 144.76.22.178:53950] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSCRGwDnJBNj2tDbYYcqQAAAFI"] [Tue Aug 18 13:03:17.792036 2026] [security2:error] [pid 123784:tid 124028] [client 52.173.121.69:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcxgAAAG4"] [Tue Aug 18 13:03:17.803985 2026] [security2:error] [pid 123784:tid 123963] [client 168.62.48.100:1184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcxwAAAC0"] [Tue Aug 18 13:03:17.812964 2026] [security2:error] [pid 139043:tid 139106] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/admin/.env"] [unique_id "aoSCRf2v-lWn9OzQT7UrGAAAwj4"] [Tue Aug 18 13:03:17.817226 2026] [security2:error] [pid 139043:tid 139098] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/api/.env"] [unique_id "aoSCRf2v-lWn9OzQT7UrGQAA9jY"] [Tue Aug 18 13:03:17.818125 2026] [security2:error] [pid 139043:tid 139114] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/secrets.json"] [unique_id "aoSCRf2v-lWn9OzQT7UrGwAA9kY"] [Tue Aug 18 13:03:17.818127 2026] [security2:error] [pid 139043:tid 139046] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/backend/.env"] [unique_id "aoSCRf2v-lWn9OzQT7UrGgAA9gI"] [Tue Aug 18 13:03:17.818600 2026] [security2:error] [pid 139043:tid 139139] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/config/.env"] [unique_id "aoSCRf2v-lWn9OzQT7UrHAAA9l8"] [Tue Aug 18 13:03:17.843444 2026] [security2:error] [pid 139043:tid 139255] [client 20.250.13.23:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrHQAAANc"] [Tue Aug 18 13:03:17.848122 2026] [security2:error] [pid 139043:tid 139260] [client 20.226.36.136:57806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrHgAAANw"] [Tue Aug 18 13:03:17.851287 2026] [security2:error] [pid 139043:tid 139207] [client 40.74.65.169:44186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/button.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrHwAAAKc"] [Tue Aug 18 13:03:17.872587 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:17.872975 2026] [authz_core:error] [pid 123784:tid 123859] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:17.893796 2026] [security2:error] [pid 123784:tid 123976] [client 20.163.43.14:6548] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "economycarsmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcywAAADo"] [Tue Aug 18 13:03:17.893927 2026] [security2:error] [pid 123784:tid 123976] [client 20.163.43.14:6548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSCRWwDnJBNj2tDbYYcywAAADo"] [Tue Aug 18 13:03:17.900511 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/env.php"] [unique_id "aoSCRWwDnJBNj2tDbYYczAAAAC4"] [Tue Aug 18 13:03:17.946443 2026] [security2:error] [pid 139043:tid 139300] [client 20.206.73.37:18705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/coffexium.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrIwAAAQQ"] [Tue Aug 18 13:03:17.968895 2026] [security2:error] [pid 139043:tid 139224] [client 20.25.139.174:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrJgAAALg"] [Tue Aug 18 13:03:17.983654 2026] [security2:error] [pid 139043:tid 139203] [client 20.51.153.15:9815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/hj.php"] [unique_id "aoSCRf2v-lWn9OzQT7UrJwAAAKM"] [Tue Aug 18 13:03:18.006750 2026] [security2:error] [pid 139043:tid 139280] [client 20.65.69.59:27898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/de.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrKgAAAPA"] [Tue Aug 18 13:03:18.030290 2026] [security2:error] [pid 123784:tid 124044] [client 20.206.73.37:59840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/coffexium.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc0AAAAH4"] [Tue Aug 18 13:03:18.034071 2026] [security2:error] [pid 139043:tid 139109] [remote 129.121.103.155:57500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrLAAA20E"] [Tue Aug 18 13:03:18.039210 2026] [security2:error] [pid 139043:tid 139244] [client 172.182.217.32:21555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrLQAAAMw"] [Tue Aug 18 13:03:18.048886 2026] [security2:error] [pid 139043:tid 139155] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/secrets.yml"] [unique_id "aoSCRv2v-lWn9OzQT7UrLgAApW8"] [Tue Aug 18 13:03:18.087407 2026] [security2:error] [pid 139043:tid 139188] [client 20.80.111.3:40667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrLwAAAJQ"] [Tue Aug 18 13:03:18.098273 2026] [security2:error] [pid 139043:tid 139192] [client 20.151.109.219:17639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ry.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrOAAAAJg"] [Tue Aug 18 13:03:18.130549 2026] [security2:error] [pid 139043:tid 139174] [client 132.196.30.78:8872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/admin.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrOQAAAIY"] [Tue Aug 18 13:03:18.142873 2026] [security2:error] [pid 139043:tid 139232] [client 20.186.30.159:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/wp-load.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrOgAAAMA"] [Tue Aug 18 13:03:18.143895 2026] [security2:error] [pid 139043:tid 139243] [client 4.223.113.180:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/feeds.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrOwAAAMs"] [Tue Aug 18 13:03:18.175339 2026] [security2:error] [pid 139043:tid 139235] [client 168.62.48.100:1140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrPAAAAMM"] [Tue Aug 18 13:03:18.176360 2026] [authz_core:error] [pid 123784:tid 123879] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:18.176814 2026] [authz_core:error] [pid 123784:tid 123879] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:18.207086 2026] [security2:error] [pid 139043:tid 139273] [client 74.248.130.103:54863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/sky.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrPwAAAOk"] [Tue Aug 18 13:03:18.218218 2026] [security2:error] [pid 123784:tid 123995] [client 20.51.153.15:9812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ij.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc1gAAAE0"] [Tue Aug 18 13:03:18.226524 2026] [security2:error] [pid 139043:tid 139251] [client 20.163.43.14:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrQQAAANM"] [Tue Aug 18 13:03:18.230287 2026] [security2:error] [pid 139043:tid 139226] [client 4.232.151.198:41097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/abc.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrQgAAALo"] [Tue Aug 18 13:03:18.233644 2026] [security2:error] [pid 139043:tid 139129] [remote 64.225.17.112:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.17.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrQwAAqFU"] [Tue Aug 18 13:03:18.234347 2026] [security2:error] [pid 123784:tid 123993] [client 20.25.139.174:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wap.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc2AAAAEs"] [Tue Aug 18 13:03:18.238049 2026] [security2:error] [pid 139043:tid 139256] [client 40.74.65.169:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/indes.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrRAAAANg"] [Tue Aug 18 13:03:18.291448 2026] [security2:error] [pid 139043:tid 139227] [client 213.35.127.232:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrTgAAALs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:18.344380 2026] [security2:error] [pid 139043:tid 139265] [client 20.65.69.59:5739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/album.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrUAAAAOE"] [Tue Aug 18 13:03:18.420428 2026] [security2:error] [pid 123784:tid 123930] [client 4.232.151.198:48778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wap.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc3AAAAAw"] [Tue Aug 18 13:03:18.440600 2026] [security2:error] [pid 139043:tid 139184] [client 158.23.17.4:29458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mz.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrUwAAAJA"] [Tue Aug 18 13:03:18.472255 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:18.472542 2026] [authz_core:error] [pid 123784:tid 123865] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:18.487939 2026] [security2:error] [pid 139043:tid 139266] [client 20.250.13.23:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrXQAAAOI"] [Tue Aug 18 13:03:18.531635 2026] [security2:error] [pid 139043:tid 139284] [client 20.25.139.174:2403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/themes.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrXgAAAPQ"] [Tue Aug 18 13:03:18.535055 2026] [security2:error] [pid 139043:tid 139201] [client 172.182.217.32:21881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/twentytwenty/functions.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrXwAAAKE"] [Tue Aug 18 13:03:18.536308 2026] [security2:error] [pid 139043:tid 139268] [client 40.74.65.169:38459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/wlc.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrYAAAAOQ"] [Tue Aug 18 13:03:18.540437 2026] [security2:error] [pid 139043:tid 139287] [client 40.74.65.169:5667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/coffexium.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrYQAAAPc"] [Tue Aug 18 13:03:18.541283 2026] [security2:error] [pid 139043:tid 139173] [client 20.80.111.3:17937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/css/min.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrYgAAAIU"] [Tue Aug 18 13:03:18.562903 2026] [security2:error] [pid 123784:tid 123979] [client 20.51.153.15:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ud.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc4wAAAD0"] [Tue Aug 18 13:03:18.568883 2026] [security2:error] [pid 123784:tid 124007] [client 20.163.43.14:6644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc5AAAAFk"] [Tue Aug 18 13:03:18.588555 2026] [security2:error] [pid 123784:tid 123999] [client 20.151.109.219:27337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pm.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc5QAAAFE"] [Tue Aug 18 13:03:18.594181 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.69.59:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kv.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc5gAAAGg"] [Tue Aug 18 13:03:18.656028 2026] [security2:error] [pid 139043:tid 139218] [client 149.34.210.141:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrYwAAALI"] [Tue Aug 18 13:03:18.657665 2026] [security2:error] [pid 139043:tid 139234] [client 168.62.48.100:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrZAAAAMI"] [Tue Aug 18 13:03:18.691947 2026] [security2:error] [pid 139043:tid 139255] [client 20.79.204.6:9284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ws54.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrZQAAANc"] [Tue Aug 18 13:03:18.700474 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.36.136:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrZgAAAKc"] [Tue Aug 18 13:03:18.712859 2026] [security2:error] [pid 139043:tid 139178] [client 74.248.130.103:48965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/sixxis.php"] [unique_id "aoSCRv2v-lWn9OzQT7UraAAAAIo"] [Tue Aug 18 13:03:18.761947 2026] [security2:error] [pid 123784:tid 123988] [client 20.25.139.174:4718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-admin/wp.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc6wAAAEY"] [Tue Aug 18 13:03:18.770271 2026] [security2:error] [pid 123784:tid 123957] [client 68.155.154.236:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc7QAAACc"] [Tue Aug 18 13:03:18.779460 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:18.779878 2026] [authz_core:error] [pid 123784:tid 123826] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:18.801300 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:9594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ip.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrawAAAPA"] [Tue Aug 18 13:03:18.827343 2026] [security2:error] [pid 139043:tid 139092] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/credentials.json"] [unique_id "aoSCRv2v-lWn9OzQT7UrbAAA-DA"] [Tue Aug 18 13:03:18.827535 2026] [security2:error] [pid 139043:tid 139072] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "aoSCRv2v-lWn9OzQT7UrbQAA-Bw"] [Tue Aug 18 13:03:18.851791 2026] [security2:error] [pid 139043:tid 139185] [client 4.232.151.198:22220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/sf.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrbgAAAJE"] [Tue Aug 18 13:03:18.862176 2026] [security2:error] [pid 139043:tid 139110] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/service-account.json"] [unique_id "aoSCRv2v-lWn9OzQT7UrbwAAz0I"] [Tue Aug 18 13:03:18.863044 2026] [security2:error] [pid 139043:tid 139078] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/key.json"] [unique_id "aoSCRv2v-lWn9OzQT7UrcAABACI"] [Tue Aug 18 13:03:18.863756 2026] [security2:error] [pid 139043:tid 139105] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSCRv2v-lWn9OzQT7UrcQABAD0"] [Tue Aug 18 13:03:18.869158 2026] [security2:error] [pid 123784:tid 123987] [client 20.65.69.59:59260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/z.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc7wAAAEU"] [Tue Aug 18 13:03:18.887122 2026] [security2:error] [pid 123784:tid 123921] [client 158.23.17.4:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kv.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc8QAAAAM"] [Tue Aug 18 13:03:18.891754 2026] [security2:error] [pid 123784:tid 123946] [client 20.206.73.37:59965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/dex.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc8gAAABw"] [Tue Aug 18 13:03:18.894085 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/as.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrcgAAALw"] [Tue Aug 18 13:03:18.916894 2026] [security2:error] [pid 123784:tid 123985] [client 168.62.48.100:1251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc8wAAAEM"] [Tue Aug 18 13:03:18.922513 2026] [security2:error] [pid 139043:tid 139218] [client 149.34.210.141:65035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrYwAAALI"] [Tue Aug 18 13:03:18.935429 2026] [security2:error] [pid 123784:tid 124009] [client 20.186.30.159:14267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/155.php"] [unique_id "aoSCRmwDnJBNj2tDbYYc9AAAAFs"] [Tue Aug 18 13:03:18.964902 2026] [security2:error] [pid 139043:tid 139275] [client 40.74.65.169:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrcwAAAOs"] [Tue Aug 18 13:03:18.989517 2026] [security2:error] [pid 139043:tid 139188] [client 20.116.17.175:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/tiny2.php"] [unique_id "aoSCRv2v-lWn9OzQT7UrdgAAAJQ"] [Tue Aug 18 13:03:19.023819 2026] [security2:error] [pid 123784:tid 123994] [client 172.182.217.32:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/not/includes/about.php"] [unique_id "aoSCR2wDnJBNj2tDbYYc9gAAAEw"] [Tue Aug 18 13:03:19.050027 2026] [security2:error] [pid 123784:tid 123924] [client 68.155.154.236:8466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCR2wDnJBNj2tDbYYc-AAAAAY"] [Tue Aug 18 13:03:19.051632 2026] [security2:error] [pid 139043:tid 139282] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp9.php"] [unique_id "aoSCR_2v-lWn9OzQT7UreAAAAPI"] [Tue Aug 18 13:03:19.079297 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:19.079619 2026] [authz_core:error] [pid 123784:tid 123794] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:19.091423 2026] [security2:error] [pid 139043:tid 139259] [client 20.25.139.174:2226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/cv.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrfAAAANs"] [Tue Aug 18 13:03:19.095534 2026] [security2:error] [pid 139043:tid 139232] [client 20.51.153.15:8278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/99.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrfQAAAMA"] [Tue Aug 18 13:03:19.096142 2026] [security2:error] [pid 139043:tid 139294] [client 20.80.111.3:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/css/wp-login.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrfgAAAP4"] [Tue Aug 18 13:03:19.135233 2026] [security2:error] [pid 123784:tid 123953] [client 20.65.69.59:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xg.php"] [unique_id "aoSCR2wDnJBNj2tDbYYc-wAAACM"] [Tue Aug 18 13:03:19.135778 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.73.37:11961] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lifetreemarketing.com"] [uri "/1.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrfwAAAKI"] [Tue Aug 18 13:03:19.135862 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.73.37:11961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/1.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrfwAAAKI"] [Tue Aug 18 13:03:19.148244 2026] [security2:error] [pid 123784:tid 123932] [client 158.23.17.4:47127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ft.php"] [unique_id "aoSCR2wDnJBNj2tDbYYc_QAAAA4"] [Tue Aug 18 13:03:19.194381 2026] [security2:error] [pid 139043:tid 139179] [client 168.62.48.100:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrgQAAAIs"] [Tue Aug 18 13:03:19.204576 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ws59.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrggAAAJs"] [Tue Aug 18 13:03:19.206846 2026] [security2:error] [pid 139043:tid 139156] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/service_account.json"] [unique_id "aoSCR_2v-lWn9OzQT7UrgwAA_HA"] [Tue Aug 18 13:03:19.209405 2026] [security2:error] [pid 139043:tid 139231] [client 40.74.65.169:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/fi.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrhAAAAL8"] [Tue Aug 18 13:03:19.211152 2026] [security2:error] [pid 139043:tid 139273] [client 114.119.148.208:28401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gustavofrison.com.br"] [uri "/wp-content/uploads/2017/01/GF-e-Nalbert.jpg"] [unique_id "aoSCR_2v-lWn9OzQT7UrhgAAAOk"], referer: http://www.gustavofrison.com.br/galeria [Tue Aug 18 13:03:19.220788 2026] [security2:error] [pid 139043:tid 139226] [client 20.163.43.14:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrhwAAALo"] [Tue Aug 18 13:03:19.234372 2026] [security2:error] [pid 123784:tid 123934] [client 74.248.130.103:50156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/yj09.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdAQAAABA"] [Tue Aug 18 13:03:19.251920 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:14047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCR_2v-lWn9OzQT7UriAAAANg"] [Tue Aug 18 13:03:19.287302 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:20849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dr.php"] [unique_id "aoSCR_2v-lWn9OzQT7UriQAAAKA"] [Tue Aug 18 13:03:19.290966 2026] [security2:error] [pid 123784:tid 123937] [client 20.25.139.174:4714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/bgymj.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdAwAAABM"] [Tue Aug 18 13:03:19.313847 2026] [security2:error] [pid 123784:tid 123918] [client 213.35.127.232:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdBAAAAAA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:19.315528 2026] [security2:error] [pid 123784:tid 123986] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdBQAAAEQ"] [Tue Aug 18 13:03:19.355854 2026] [security2:error] [pid 123784:tid 124033] [client 20.186.30.159:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/index.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdBwAAAHM"] [Tue Aug 18 13:03:19.371140 2026] [security2:error] [pid 123784:tid 124024] [client 20.250.13.23:3092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdCQAAAGo"] [Tue Aug 18 13:03:19.381894 2026] [security2:error] [pid 139043:tid 139181] [client 20.51.153.15:9596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/er.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrigAAAI0"] [Tue Aug 18 13:03:19.393763 2026] [security2:error] [pid 139043:tid 139230] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSCR_2v-lWn9OzQT7UriwAAAL4"] [Tue Aug 18 13:03:19.415929 2026] [security2:error] [pid 123784:tid 124011] [client 52.173.121.69:31585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdCgAAAF0"] [Tue Aug 18 13:03:19.440243 2026] [security2:error] [pid 139043:tid 139220] [client 20.65.69.59:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/nd.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrjAAAALQ"] [Tue Aug 18 13:03:19.468855 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/vx.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrjQAAAJA"] [Tue Aug 18 13:03:19.478166 2026] [security2:error] [pid 139043:tid 139206] [client 4.232.151.198:41108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/chosen.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrjgAAAKY"] [Tue Aug 18 13:03:19.516445 2026] [security2:error] [pid 139043:tid 139265] [client 172.182.217.32:21532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/simple/simple.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrjwAAAOE"] [Tue Aug 18 13:03:19.545344 2026] [security2:error] [pid 139043:tid 139277] [client 20.163.43.14:6588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrkAAAAO0"] [Tue Aug 18 13:03:19.554163 2026] [security2:error] [pid 123784:tid 123928] [client 138.36.100.162:42827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdEAAAAAo"] [Tue Aug 18 13:03:19.555100 2026] [security2:error] [pid 123784:tid 123928] [client 138.36.100.162:42827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdEAAAAAo"] [Tue Aug 18 13:03:19.569939 2026] [security2:error] [pid 123784:tid 123941] [client 168.62.48.100:1111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdEQAAABc"] [Tue Aug 18 13:03:19.578387 2026] [security2:error] [pid 123784:tid 124008] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ah25.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdEgAAAFo"] [Tue Aug 18 13:03:19.591372 2026] [security2:error] [pid 139043:tid 139298] [client 20.80.111.3:40678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/id3/about.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrkQAAAQI"] [Tue Aug 18 13:03:19.632664 2026] [security2:error] [pid 123784:tid 123954] [client 20.186.30.159:7234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/aaa.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdFAAAACQ"] [Tue Aug 18 13:03:19.637065 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/tt.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrkwAAAJk"] [Tue Aug 18 13:03:19.663629 2026] [security2:error] [pid 139043:tid 139067] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/Dockerfile"] [unique_id "aoSCR_2v-lWn9OzQT7UrlAAA3hc"] [Tue Aug 18 13:03:19.667929 2026] [security2:error] [pid 139043:tid 139119] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.github/.env"] [unique_id "aoSCR_2v-lWn9OzQT7UrlQAA-ks"] [Tue Aug 18 13:03:19.669559 2026] [security2:error] [pid 139043:tid 139071] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/firebase-service-account.json"] [unique_id "aoSCR_2v-lWn9OzQT7UrlgAAiBs"] [Tue Aug 18 13:03:19.669635 2026] [security2:error] [pid 139043:tid 139171] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.npmrc"] [unique_id "aoSCR_2v-lWn9OzQT7UrlwAAiH8"] [Tue Aug 18 13:03:19.671361 2026] [security2:error] [pid 139043:tid 139100] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.docker/config.json"] [unique_id "aoSCR_2v-lWn9OzQT7UrmQAAszg"] [Tue Aug 18 13:03:19.671636 2026] [security2:error] [pid 139043:tid 139279] [client 40.74.65.169:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/bs1.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrmgAAAO8"] [Tue Aug 18 13:03:19.676469 2026] [security2:error] [pid 139043:tid 139241] [client 132.196.30.78:1631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrmwAAAMk"] [Tue Aug 18 13:03:19.677209 2026] [security2:error] [pid 123784:tid 123963] [client 20.51.153.15:9584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/qk.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdFwAAAC0"] [Tue Aug 18 13:03:19.677338 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:19.677635 2026] [authz_core:error] [pid 123784:tid 123851] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:19.695702 2026] [security2:error] [pid 123784:tid 123976] [client 20.65.69.59:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ri.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdGAAAADo"] [Tue Aug 18 13:03:19.699129 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xqq.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdGQAAAC4"] [Tue Aug 18 13:03:19.735416 2026] [security2:error] [pid 139043:tid 139242] [client 20.206.73.37:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/coffee.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrnAAAAMo"] [Tue Aug 18 13:03:19.754705 2026] [security2:error] [pid 123784:tid 123990] [client 157.20.138.62:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdGwAAAEg"] [Tue Aug 18 13:03:19.754853 2026] [security2:error] [pid 123784:tid 123990] [client 157.20.138.62:53957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdGwAAAEg"] [Tue Aug 18 13:03:19.780392 2026] [security2:error] [pid 123784:tid 123965] [client 20.25.139.174:4530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/aa.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdHAAAAC8"] [Tue Aug 18 13:03:19.795025 2026] [security2:error] [pid 139043:tid 139280] [client 20.25.139.174:2189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCR_2v-lWn9OzQT7UroQAAAPA"] [Tue Aug 18 13:03:19.798526 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/z.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrogAAALg"] [Tue Aug 18 13:03:19.877329 2026] [security2:error] [pid 139043:tid 139296] [client 20.163.43.14:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrpQAAAQA"] [Tue Aug 18 13:03:19.884108 2026] [security2:error] [pid 139043:tid 139177] [client 20.151.109.219:27746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ts.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrpgAAAIk"] [Tue Aug 18 13:03:19.887142 2026] [security2:error] [pid 139043:tid 139223] [client 40.74.65.169:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/chris.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrpwAAALc"] [Tue Aug 18 13:03:19.889260 2026] [security2:error] [pid 139043:tid 139088] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.s3cfg"] [unique_id "aoSCR_2v-lWn9OzQT7UrqQAAvCw"] [Tue Aug 18 13:03:19.889524 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:32469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdHwAAACE"] [Tue Aug 18 13:03:19.889668 2026] [security2:error] [pid 123784:tid 123951] [client 103.120.71.157:32469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdHwAAACE"] [Tue Aug 18 13:03:19.954131 2026] [security2:error] [pid 123784:tid 123974] [client 20.65.69.59:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/tp.php"] [unique_id "aoSCR2wDnJBNj2tDbYYdIAAAADg"] [Tue Aug 18 13:03:19.973341 2026] [security2:error] [pid 139043:tid 139275] [client 168.62.48.100:1185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrqgAAAOs"] [Tue Aug 18 13:03:19.978957 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:19.979237 2026] [authz_core:error] [pid 123784:tid 123828] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:19.993003 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/h.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrqwAAAJQ"] [Tue Aug 18 13:03:20.004923 2026] [security2:error] [pid 123784:tid 124029] [client 52.173.121.69:45423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/rezor.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdIwAAAG8"] [Tue Aug 18 13:03:20.007709 2026] [security2:error] [pid 123784:tid 123970] [client 172.182.217.32:21860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdJAAAADQ"] [Tue Aug 18 13:03:20.015521 2026] [security2:error] [pid 139043:tid 139192] [client 68.221.73.131:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrrQAAAJg"] [Tue Aug 18 13:03:20.035588 2026] [security2:error] [pid 123784:tid 124032] [client 20.80.111.3:17928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/id3/index.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdJQAAAHI"] [Tue Aug 18 13:03:20.050442 2026] [security2:error] [pid 139043:tid 139259] [client 20.186.30.159:14212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrrwAAANs"] [Tue Aug 18 13:03:20.056083 2026] [security2:error] [pid 123784:tid 123995] [client 68.155.154.236:40425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdJgAAAE0"] [Tue Aug 18 13:03:20.063185 2026] [security2:error] [pid 139043:tid 139107] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrsAAA6j8"] [Tue Aug 18 13:03:20.063355 2026] [security2:error] [pid 139043:tid 139274] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrsAAA6j8"] [Tue Aug 18 13:03:20.072678 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:39249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdKAAAAGs"] [Tue Aug 18 13:03:20.072839 2026] [security2:error] [pid 123784:tid 124025] [client 178.153.171.161:39249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdKAAAAGs"] [Tue Aug 18 13:03:20.079232 2026] [security2:error] [pid 123784:tid 124030] [client 20.51.153.15:9777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fraie1p4.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdKQAAAHA"] [Tue Aug 18 13:03:20.098130 2026] [security2:error] [pid 139043:tid 139222] [client 20.116.17.175:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wpxml.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrsQAAALY"] [Tue Aug 18 13:03:20.102857 2026] [security2:error] [pid 123784:tid 123991] [client 4.232.151.198:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/u.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdKgAAAEk"] [Tue Aug 18 13:03:20.147613 2026] [security2:error] [pid 139043:tid 139209] [client 52.173.121.69:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrswAAAKk"] [Tue Aug 18 13:03:20.150657 2026] [security2:error] [pid 139043:tid 139199] [client 20.206.73.37:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/classwithtostring.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrtAAAAJ8"] [Tue Aug 18 13:03:20.169010 2026] [security2:error] [pid 139043:tid 139252] [client 20.250.13.23:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSCR_2v-lWn9OzQT7UrrAAAANQ"] [Tue Aug 18 13:03:20.201249 2026] [access_compat:error] [pid 139043:tid 139264] [client 169.58.72.248:57139] AH01797: client denied by server configuration: /home2/tecnomorcom/public_html/wp-content/uploads/index.php [Tue Aug 18 13:03:20.204278 2026] [security2:error] [pid 139043:tid 139227] [client 40.74.65.169:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrtwAAALs"] [Tue Aug 18 13:03:20.206540 2026] [security2:error] [pid 139043:tid 139221] [client 20.163.43.14:6603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCSP2v-lWn9OzQT7UruAAAALU"] [Tue Aug 18 13:03:20.258598 2026] [security2:error] [pid 123784:tid 123977] [client 168.62.48.100:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdLgAAADs"] [Tue Aug 18 13:03:20.268240 2026] [security2:error] [pid 139043:tid 139186] [client 20.25.139.174:4514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-mail.php"] [unique_id "aoSCSP2v-lWn9OzQT7UruwAAAJI"] [Tue Aug 18 13:03:20.272788 2026] [security2:error] [pid 139043:tid 139184] [client 20.65.69.59:54135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/zj.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrvAAAAJA"] [Tue Aug 18 13:03:20.285090 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:20.285545 2026] [authz_core:error] [pid 123784:tid 123795] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:20.312516 2026] [security2:error] [pid 123784:tid 124007] [client 168.62.48.100:1254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdMQAAAFk"] [Tue Aug 18 13:03:20.315334 2026] [security2:error] [pid 139043:tid 139265] [client 20.51.153.15:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fs.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrvQAAAOE"] [Tue Aug 18 13:03:20.335282 2026] [security2:error] [pid 139043:tid 139281] [client 213.35.127.232:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrvgAAAPE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:20.337533 2026] [security2:error] [pid 139043:tid 139208] [client 20.25.139.174:2414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ws83.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrvwAAAKg"] [Tue Aug 18 13:03:20.376286 2026] [security2:error] [pid 139043:tid 139201] [client 40.74.65.169:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/hp2.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrwAAAAKE"] [Tue Aug 18 13:03:20.440982 2026] [security2:error] [pid 139043:tid 139253] [client 213.202.253.4:53816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/delpaths.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrwQAAANU"], referer: www.google.com [Tue Aug 18 13:03:20.505439 2026] [security2:error] [pid 139043:tid 139239] [client 172.182.217.32:21553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/aahana/json.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrxAAAAMc"] [Tue Aug 18 13:03:20.513974 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.73.37:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/wp-ws68.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrxgAAAM0"] [Tue Aug 18 13:03:20.552608 2026] [security2:error] [pid 139043:tid 139050] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSCSP2v-lWn9OzQT7UrygAAygY"] [Tue Aug 18 13:03:20.553917 2026] [security2:error] [pid 139043:tid 139055] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.boto"] [unique_id "aoSCSP2v-lWn9OzQT7UrywAA_Qs"] [Tue Aug 18 13:03:20.554848 2026] [security2:error] [pid 139043:tid 139152] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/terraform.tfstate"] [unique_id "aoSCSP2v-lWn9OzQT7UrzAAAp2w"] [Tue Aug 18 13:03:20.555564 2026] [security2:error] [pid 139043:tid 139094] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.svn/entries"] [unique_id "aoSCSP2v-lWn9OzQT7UrzQAApzI"] [Tue Aug 18 13:03:20.555941 2026] [security2:error] [pid 139043:tid 139116] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.htpasswd"] [unique_id "aoSCSP2v-lWn9OzQT7UrzgAAmkg"] [Tue Aug 18 13:03:20.563833 2026] [access_compat:error] [pid 139043:tid 139233] [client 40.77.167.219:25948] AH01797: client denied by server configuration: /home2/mmmatrizes/public_html/robots.txt [Tue Aug 18 13:03:20.569541 2026] [security2:error] [pid 139043:tid 139254] [client 20.79.204.6:9294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/deepseek_d.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur0AAAANY"] [Tue Aug 18 13:03:20.578836 2026] [security2:error] [pid 139043:tid 139300] [client 40.74.65.169:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/doc.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur0QAAAQQ"] [Tue Aug 18 13:03:20.607169 2026] [security2:error] [pid 139043:tid 139280] [client 52.173.121.69:34571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur0wAAAPA"] [Tue Aug 18 13:03:20.624667 2026] [security2:error] [pid 139043:tid 139249] [client 20.65.69.59:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/x.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur1AAAANE"] [Tue Aug 18 13:03:20.644804 2026] [security2:error] [pid 123784:tid 123923] [client 20.151.109.219:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/53.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdOQAAAAU"] [Tue Aug 18 13:03:20.652174 2026] [security2:error] [pid 139043:tid 139087] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur1QAA5is"] [Tue Aug 18 13:03:20.668609 2026] [security2:error] [pid 139043:tid 139247] [client 68.155.154.236:41472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur1wAAAM8"] [Tue Aug 18 13:03:20.694517 2026] [security2:error] [pid 139043:tid 139125] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.vscode/launch.json"] [unique_id "aoSCSP2v-lWn9OzQT7Ur2QAAzFE"] [Tue Aug 18 13:03:20.704160 2026] [security2:error] [pid 139043:tid 139218] [client 158.23.17.4:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/40.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur2gAAALI"] [Tue Aug 18 13:03:20.723940 2026] [security2:error] [pid 139043:tid 139203] [client 74.248.130.103:54894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/k.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur3AAAAKM"] [Tue Aug 18 13:03:20.724621 2026] [security2:error] [pid 123784:tid 124019] [client 20.80.111.3:40683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/id3/min.php"] [unique_id "aoSCSGwDnJBNj2tDbYYdOwAAAGU"] [Tue Aug 18 13:03:20.725713 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:9738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/rb.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur3QAAAI4"] [Tue Aug 18 13:03:20.730137 2026] [security2:error] [pid 139043:tid 139211] [client 20.226.36.136:57262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur3gAAAKs"] [Tue Aug 18 13:03:20.732183 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur3wAAAJg"] [Tue Aug 18 13:03:20.782151 2026] [security2:error] [pid 139043:tid 139269] [client 20.25.139.174:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/bolt.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur4wAAAOU"] [Tue Aug 18 13:03:20.788652 2026] [security2:error] [pid 139043:tid 139217] [client 168.62.48.100:1150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur5AAAALE"] [Tue Aug 18 13:03:20.798043 2026] [security2:error] [pid 139043:tid 139287] [client 20.250.13.23:3074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur5gAAAPc"] [Tue Aug 18 13:03:20.855152 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.73.37:19582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/dex.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur6QAAAKI"] [Tue Aug 18 13:03:20.872016 2026] [security2:error] [pid 139043:tid 139222] [client 74.248.18.37:25394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur6wAAALY"] [Tue Aug 18 13:03:20.872032 2026] [security2:error] [pid 139043:tid 139246] [client 20.65.69.59:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/yn.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur6gAAAM4"] [Tue Aug 18 13:03:20.882921 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:20.883178 2026] [authz_core:error] [pid 123784:tid 123894] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:20.905309 2026] [security2:error] [pid 139043:tid 139051] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur7QAAiwc"] [Tue Aug 18 13:03:20.907445 2026] [security2:error] [pid 139043:tid 139297] [client 20.163.43.14:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur7gAAAQE"] [Tue Aug 18 13:03:20.907466 2026] [security2:error] [pid 139043:tid 139228] [client 20.25.139.174:2255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/atex1.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur7wAAALw"] [Tue Aug 18 13:03:20.931448 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:47921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xg.php"] [unique_id "aoSCSP2v-lWn9OzQT7Ur8QAAAKk"] [Tue Aug 18 13:03:21.019487 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.217.32:21516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/awesome-coming-soon/come.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur8gAAAP4"] [Tue Aug 18 13:03:21.056205 2026] [security2:error] [pid 139043:tid 139230] [client 20.186.30.159:14233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/site.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur8wAAAL4"] [Tue Aug 18 13:03:21.062157 2026] [security2:error] [pid 139043:tid 139231] [client 40.74.65.169:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/yb.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur9AAAAL8"] [Tue Aug 18 13:03:21.064252 2026] [security2:error] [pid 139043:tid 139285] [client 4.232.151.198:41125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/customize.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur9QAAAPU"] [Tue Aug 18 13:03:21.089545 2026] [security2:error] [pid 123784:tid 123953] [client 20.51.153.15:9506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/37.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdRQAAACM"] [Tue Aug 18 13:03:21.096096 2026] [security2:error] [pid 139043:tid 139257] [client 68.221.73.131:56158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur9gAAANk"] [Tue Aug 18 13:03:21.100175 2026] [security2:error] [pid 139043:tid 139183] [client 168.62.48.100:1237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur9wAAAI8"] [Tue Aug 18 13:03:21.121033 2026] [security2:error] [pid 123784:tid 123932] [client 20.206.73.37:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/mgrr.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdRgAAAA4"] [Tue Aug 18 13:03:21.123368 2026] [security2:error] [pid 139043:tid 139174] [client 4.232.151.198:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur-AAAAIY"] [Tue Aug 18 13:03:21.134604 2026] [security2:error] [pid 123784:tid 123935] [client 20.65.69.59:5712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/11.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdRwAAABE"] [Tue Aug 18 13:03:21.182547 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:21.182839 2026] [authz_core:error] [pid 123784:tid 123805] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:21.203124 2026] [security2:error] [pid 139043:tid 139201] [client 52.173.121.69:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur-gAAAKE"] [Tue Aug 18 13:03:21.204931 2026] [security2:error] [pid 139043:tid 139268] [client 74.248.130.103:48991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/w.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur-wAAAOQ"] [Tue Aug 18 13:03:21.231278 2026] [security2:error] [pid 123784:tid 123867] [remote 68.178.165.65:35708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carnescapellari.top"] [uri "/wp-login.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdSwAAfk4"] [Tue Aug 18 13:03:21.233030 2026] [security2:error] [pid 139043:tid 139225] [client 20.163.43.14:6622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/an.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur_AAAALk"] [Tue Aug 18 13:03:21.246115 2026] [security2:error] [pid 139043:tid 139262] [client 20.116.17.175:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/min.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur_QAAAN4"] [Tue Aug 18 13:03:21.266597 2026] [security2:error] [pid 139043:tid 139253] [client 40.74.65.169:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/1337.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur_gAAANU"] [Tue Aug 18 13:03:21.274585 2026] [security2:error] [pid 139043:tid 139176] [client 20.206.73.37:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/55.php"] [unique_id "aoSCSf2v-lWn9OzQT7Ur_wAAAIg"] [Tue Aug 18 13:03:21.335435 2026] [security2:error] [pid 139043:tid 139255] [client 20.65.98.162:21865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsAQAAANc"] [Tue Aug 18 13:03:21.336412 2026] [security2:error] [pid 123784:tid 123986] [client 52.173.121.69:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdTgAAAEQ"] [Tue Aug 18 13:03:21.341094 2026] [security2:error] [pid 139043:tid 139265] [client 20.25.139.174:4483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/bthil.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsAgAAAOE"] [Tue Aug 18 13:03:21.351983 2026] [security2:error] [pid 123784:tid 123924] [client 213.35.127.232:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdUAAAAAY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:21.353843 2026] [security2:error] [pid 123784:tid 123841] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdUQAAIDQ"] [Tue Aug 18 13:03:21.378082 2026] [security2:error] [pid 139043:tid 139194] [client 20.51.153.15:9501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/md.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsBQAAAJo"] [Tue Aug 18 13:03:21.405780 2026] [security2:error] [pid 139043:tid 139280] [client 20.65.69.59:5408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vm.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsBgAAAPA"] [Tue Aug 18 13:03:21.405891 2026] [security2:error] [pid 139043:tid 139224] [client 40.74.65.169:5690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/sf.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsBwAAALg"] [Tue Aug 18 13:03:21.406449 2026] [security2:error] [pid 139043:tid 139191] [client 103.184.169.37:43548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsCAAAAJc"] [Tue Aug 18 13:03:21.406715 2026] [security2:error] [pid 139043:tid 139191] [client 103.184.169.37:43548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsCAAAAJc"] [Tue Aug 18 13:03:21.419168 2026] [security2:error] [pid 139043:tid 139077] [remote 108.167.161.148:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiadasiderurgia.com.br"] [uri "/wp-login.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsCgAAqCE"] [Tue Aug 18 13:03:21.421973 2026] [security2:error] [pid 139043:tid 139180] [client 168.62.48.100:1286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsDAAAAIw"] [Tue Aug 18 13:03:21.422044 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.13.23:3413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsCwAAAIc"] [Tue Aug 18 13:03:21.436918 2026] [security2:error] [pid 123784:tid 123980] [client 132.196.30.78:24920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/as.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdUwAAAD4"] [Tue Aug 18 13:03:21.439073 2026] [security2:error] [pid 139043:tid 139290] [client 158.23.17.4:63038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/st.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsDQAAAPo"] [Tue Aug 18 13:03:21.460889 2026] [security2:error] [pid 123784:tid 123972] [client 20.80.111.3:41007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdVAAAADY"] [Tue Aug 18 13:03:21.471559 2026] [security2:error] [pid 139043:tid 139053] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "aoSCSf2v-lWn9OzQT7UsDwAAtwk"] [Tue Aug 18 13:03:21.472094 2026] [security2:error] [pid 139043:tid 139134] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCSf2v-lWn9OzQT7UsEAAAt1o"] [Tue Aug 18 13:03:21.476680 2026] [security2:error] [pid 139043:tid 139219] [client 20.25.139.174:2207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsEQAAALM"] [Tue Aug 18 13:03:21.483326 2026] [security2:error] [pid 139043:tid 139218] [client 68.155.154.236:55457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsEgAAALI"] [Tue Aug 18 13:03:21.489368 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:21.489823 2026] [authz_core:error] [pid 123784:tid 123797] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:21.491743 2026] [autoindex:error] [pid 123784:tid 123854] [remote 173.252.70.14:54276] AH01276: Cannot serve directory /home1/xsolutions/vooo.3xsolutions.com/public/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:21.509402 2026] [security2:error] [pid 123784:tid 123996] [client 74.248.18.37:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/0x.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdVwAAAE4"] [Tue Aug 18 13:03:21.511915 2026] [security2:error] [pid 123784:tid 124033] [client 172.182.217.32:21537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdWAAAAHM"] [Tue Aug 18 13:03:21.513464 2026] [security2:error] [pid 139043:tid 139140] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCSf2v-lWn9OzQT7UsEwAAo2A"] [Tue Aug 18 13:03:21.514578 2026] [security2:error] [pid 139043:tid 139065] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/authorized_keys"] [unique_id "aoSCSf2v-lWn9OzQT7UsFAAAjhU"] [Tue Aug 18 13:03:21.515576 2026] [security2:error] [pid 139043:tid 139117] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoSCSf2v-lWn9OzQT7UsFQAAlEk"] [Tue Aug 18 13:03:21.521075 2026] [security2:error] [pid 123784:tid 124023] [client 20.186.30.159:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/ccc.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdWQAAAGk"] [Tue Aug 18 13:03:21.530371 2026] [security2:error] [pid 139043:tid 139122] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsFgAAmE4"] [Tue Aug 18 13:03:21.593645 2026] [security2:error] [pid 139043:tid 139066] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/config"] [unique_id "aoSCSf2v-lWn9OzQT7UsGQAA9xY"] [Tue Aug 18 13:03:21.629518 2026] [security2:error] [pid 139043:tid 139197] [client 20.51.153.15:8276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/iy.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsGgAAAJ0"] [Tue Aug 18 13:03:21.683152 2026] [security2:error] [pid 123784:tid 123963] [client 20.206.73.37:26643] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "manoelmotosecarros.com.br"] [uri "/1.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdYAAAAC0"] [Tue Aug 18 13:03:21.683267 2026] [security2:error] [pid 123784:tid 123963] [client 20.206.73.37:26643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/1.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdYAAAAC0"] [Tue Aug 18 13:03:21.685021 2026] [security2:error] [pid 123784:tid 123884] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/xx.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdYQAAGF8"] [Tue Aug 18 13:03:21.687127 2026] [security2:error] [pid 123784:tid 123975] [client 74.248.130.103:48995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/fpwch.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdYgAAADk"] [Tue Aug 18 13:03:21.690686 2026] [security2:error] [pid 139043:tid 139228] [client 20.65.69.59:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/eg.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsHQAAALw"] [Tue Aug 18 13:03:21.692253 2026] [security2:error] [pid 139043:tid 139131] [remote 108.167.161.148:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiadasiderurgia.com.br"] [uri "/wp-login.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsHgAA6Vc"], referer: https://guiadasiderurgia.com.br/wp-login.php [Tue Aug 18 13:03:21.697149 2026] [security2:error] [pid 123784:tid 123992] [client 4.223.113.180:41371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/curl.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdYwAAAEo"] [Tue Aug 18 13:03:21.738492 2026] [security2:error] [pid 139043:tid 139239] [client 20.79.204.6:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/function/function.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsIQAAAMc"] [Tue Aug 18 13:03:21.740818 2026] [security2:error] [pid 123784:tid 124018] [client 168.62.48.100:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdZgAAAGQ"] [Tue Aug 18 13:03:21.757075 2026] [security2:error] [pid 123784:tid 123958] [client 40.74.65.169:51601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/vc.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdaAAAACg"] [Tue Aug 18 13:03:21.763016 2026] [security2:error] [pid 139043:tid 139260] [client 168.62.48.100:1298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsIgAAANw"] [Tue Aug 18 13:03:21.776999 2026] [security2:error] [pid 139043:tid 139261] [client 158.23.17.4:60340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/nd.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsJwAAAN0"] [Tue Aug 18 13:03:21.783919 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:21.784184 2026] [authz_core:error] [pid 123784:tid 123868] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:21.794626 2026] [security2:error] [pid 123784:tid 123965] [client 68.155.154.236:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdbAAAAC8"] [Tue Aug 18 13:03:21.808940 2026] [security2:error] [pid 139043:tid 139221] [client 20.65.98.162:21786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsKAAAALU"] [Tue Aug 18 13:03:21.834099 2026] [security2:error] [pid 139043:tid 139081] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/av.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsKgAAxiU"] [Tue Aug 18 13:03:21.845559 2026] [security2:error] [pid 123784:tid 123940] [client 158.23.17.4:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ee.php"] [unique_id "aoSCSWwDnJBNj2tDbYYddQAAABY"] [Tue Aug 18 13:03:21.879035 2026] [security2:error] [pid 123784:tid 124029] [client 20.226.36.136:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCSWwDnJBNj2tDbYYddgAAAG8"] [Tue Aug 18 13:03:21.893996 2026] [security2:error] [pid 139043:tid 139257] [client 20.163.43.14:6639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/404.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsLgAAANk"] [Tue Aug 18 13:03:21.894212 2026] [security2:error] [pid 139043:tid 139284] [client 20.51.153.15:9485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/og.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsLwAAAPQ"] [Tue Aug 18 13:03:21.913567 2026] [security2:error] [pid 139043:tid 139292] [client 85.208.96.202:35042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1755063278/1756598400/"] [unique_id "aoSCSf2v-lWn9OzQT7UsMAAAAPw"] [Tue Aug 18 13:03:21.913691 2026] [security2:error] [pid 139043:tid 139292] [client 85.208.96.202:35042] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1755063278/1756598400/"] [unique_id "aoSCSf2v-lWn9OzQT7UsMAAAAPw"] [Tue Aug 18 13:03:21.920448 2026] [security2:error] [pid 139043:tid 139187] [client 4.232.151.198:41101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/mah/function.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsMQAAAJM"] [Tue Aug 18 13:03:21.931782 2026] [security2:error] [pid 139043:tid 139256] [client 20.80.111.3:26033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/ixr/min.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsMwAAANg"] [Tue Aug 18 13:03:21.948994 2026] [security2:error] [pid 139043:tid 139250] [client 74.7.175.174:43184] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "pedrosoutoadvocacia.com.br"] [uri "/index.php"] [unique_id "aoSCSP2v-lWn9OzQT7UrwgAA0jE"] [Tue Aug 18 13:03:21.953132 2026] [security2:error] [pid 123784:tid 123968] [client 40.74.65.169:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/Njima.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdegAAADI"] [Tue Aug 18 13:03:21.955349 2026] [security2:error] [pid 139043:tid 139114] [remote 202.51.202.242:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsNAAA70Y"] [Tue Aug 18 13:03:21.960798 2026] [security2:error] [pid 139043:tid 139046] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsNQAAoQI"] [Tue Aug 18 13:03:21.980934 2026] [security2:error] [pid 139043:tid 139193] [client 20.186.30.159:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/admin.php"] [unique_id "aoSCSf2v-lWn9OzQT7UsOAAAAJk"] [Tue Aug 18 13:03:21.997628 2026] [security2:error] [pid 123784:tid 123812] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/media.php"] [unique_id "aoSCSWwDnJBNj2tDbYYdfAAAYRc"] [Tue Aug 18 13:03:22.004878 2026] [security2:error] [pid 139043:tid 139231] [client 172.182.217.32:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/rest-api/about.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsOQAAAL8"] [Tue Aug 18 13:03:22.025429 2026] [security2:error] [pid 123784:tid 123948] [client 68.221.73.131:16909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/domvf.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdfwAAAB4"] [Tue Aug 18 13:03:22.032416 2026] [security2:error] [pid 139043:tid 139265] [client 52.173.121.69:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsOwAAAOE"] [Tue Aug 18 13:03:22.043963 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:1447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdgAAAADE"] [Tue Aug 18 13:03:22.044092 2026] [security2:error] [pid 123784:tid 123967] [client 5.31.227.224:1447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdgAAAADE"] [Tue Aug 18 13:03:22.045633 2026] [security2:error] [pid 123784:tid 123997] [client 20.65.69.59:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/uk.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdgQAAAE8"] [Tue Aug 18 13:03:22.045666 2026] [security2:error] [pid 139043:tid 139207] [client 20.25.139.174:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/x.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsPAAAAKc"] [Tue Aug 18 13:03:22.045962 2026] [security2:error] [pid 123784:tid 123925] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/06.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdggAAAAc"] [Tue Aug 18 13:03:22.048545 2026] [security2:error] [pid 123784:tid 123984] [client 20.25.139.174:2407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/w.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdgwAAAEI"] [Tue Aug 18 13:03:22.061298 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/le.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsPgAAAME"] [Tue Aug 18 13:03:22.073010 2026] [security2:error] [pid 139043:tid 139210] [client 168.62.48.100:1157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsPwAAAKo"] [Tue Aug 18 13:03:22.085180 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:22.085460 2026] [authz_core:error] [pid 123784:tid 123836] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:22.112412 2026] [security2:error] [pid 139043:tid 139290] [client 168.62.48.100:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/index.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsQwAAAPo"] [Tue Aug 18 13:03:22.122094 2026] [security2:error] [pid 123784:tid 123977] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/166.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdhwAAADs"] [Tue Aug 18 13:03:22.134521 2026] [security2:error] [pid 139043:tid 139181] [client 20.206.73.37:11939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ajax.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsRAAAAI0"] [Tue Aug 18 13:03:22.139168 2026] [security2:error] [pid 123784:tid 123993] [client 74.248.18.37:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/222.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdiAAAAEs"] [Tue Aug 18 13:03:22.159212 2026] [security2:error] [pid 123784:tid 124022] [client 20.65.98.162:21859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdiwAAAGg"] [Tue Aug 18 13:03:22.167178 2026] [security2:error] [pid 139043:tid 139192] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/snq.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsSgAAAJg"] [Tue Aug 18 13:03:22.168487 2026] [security2:error] [pid 139043:tid 139212] [client 74.248.130.103:48987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsSwAAAKw"] [Tue Aug 18 13:03:22.193677 2026] [security2:error] [pid 139043:tid 139076] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/id_rsa"] [unique_id "aoSCSv2v-lWn9OzQT7UsTAAA_SA"] [Tue Aug 18 13:03:22.196160 2026] [security2:error] [pid 139043:tid 139095] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.ssh/known_hosts"] [unique_id "aoSCSv2v-lWn9OzQT7UsTQAA2zM"] [Tue Aug 18 13:03:22.230876 2026] [security2:error] [pid 139043:tid 139243] [client 20.163.43.14:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsTwAAAMs"] [Tue Aug 18 13:03:22.243688 2026] [security2:error] [pid 139043:tid 139160] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsUQAAm3Q"] [Tue Aug 18 13:03:22.248169 2026] [security2:error] [pid 139043:tid 139205] [client 20.51.153.15:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lp.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsUgAAAKU"] [Tue Aug 18 13:03:22.290185 2026] [security2:error] [pid 139043:tid 139104] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/id_dsa"] [unique_id "aoSCSv2v-lWn9OzQT7UsVAAAxzw"] [Tue Aug 18 13:03:22.293992 2026] [security2:error] [pid 139043:tid 139162] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/id_ecdsa"] [unique_id "aoSCSv2v-lWn9OzQT7UsVQAAqXY"] [Tue Aug 18 13:03:22.297500 2026] [security2:error] [pid 139043:tid 139090] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/id_ed25519"] [unique_id "aoSCSv2v-lWn9OzQT7UsVgAAny4"] [Tue Aug 18 13:03:22.301927 2026] [security2:error] [pid 139043:tid 139178] [client 20.206.73.37:16846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsVwAAAIo"] [Tue Aug 18 13:03:22.304641 2026] [security2:error] [pid 139043:tid 139260] [client 20.186.30.159:1981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsWAAAANw"] [Tue Aug 18 13:03:22.336946 2026] [security2:error] [pid 123784:tid 123946] [client 20.116.17.175:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ccou.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdkgAAABw"] [Tue Aug 18 13:03:22.337127 2026] [security2:error] [pid 139043:tid 139222] [client 102.213.179.104:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsWwAAALY"] [Tue Aug 18 13:03:22.337213 2026] [security2:error] [pid 139043:tid 139222] [client 102.213.179.104:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsWwAAALY"] [Tue Aug 18 13:03:22.356145 2026] [security2:error] [pid 123784:tid 124013] [client 20.65.69.59:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/creds.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdlAAAAF8"] [Tue Aug 18 13:03:22.372195 2026] [security2:error] [pid 139043:tid 139286] [client 213.35.127.232:63402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsXAAAAPY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:22.387958 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:22.388296 2026] [authz_core:error] [pid 123784:tid 123825] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:22.391336 2026] [security2:error] [pid 139043:tid 139264] [client 168.62.48.100:1165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsXQAAAOA"] [Tue Aug 18 13:03:22.399423 2026] [security2:error] [pid 139043:tid 139159] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/images.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsXgAAtXM"] [Tue Aug 18 13:03:22.422939 2026] [security2:error] [pid 139043:tid 139200] [client 158.23.17.4:63656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ak.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsYAAAAKA"] [Tue Aug 18 13:03:22.438885 2026] [security2:error] [pid 139043:tid 139184] [client 40.74.65.169:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/k.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsYQAAAJA"] [Tue Aug 18 13:03:22.451904 2026] [security2:error] [pid 139043:tid 139143] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/server.key"] [unique_id "aoSCSv2v-lWn9OzQT7UsYgAApmM"] [Tue Aug 18 13:03:22.474787 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lq.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsYwAAANk"] [Tue Aug 18 13:03:22.482381 2026] [security2:error] [pid 139043:tid 139284] [client 40.74.65.169:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/pema.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsZAAAAPQ"] [Tue Aug 18 13:03:22.490538 2026] [security2:error] [pid 139043:tid 139227] [client 20.80.111.3:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/ixr/wp-login.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsZQAAALs"] [Tue Aug 18 13:03:22.497436 2026] [security2:error] [pid 139043:tid 139292] [client 20.186.30.159:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/reviall.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsZgAAAPw"] [Tue Aug 18 13:03:22.501080 2026] [security2:error] [pid 123784:tid 123921] [client 172.182.217.32:21849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdmQAAAAM"] [Tue Aug 18 13:03:22.518989 2026] [security2:error] [pid 139043:tid 139281] [client 20.51.153.15:9535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ey.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsZwAAAPE"] [Tue Aug 18 13:03:22.539952 2026] [security2:error] [pid 123784:tid 123952] [client 20.65.98.162:21887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/av.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdnAAAACI"] [Tue Aug 18 13:03:22.551528 2026] [security2:error] [pid 123784:tid 123987] [client 4.232.151.198:41102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/filter.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdnQAAAEU"] [Tue Aug 18 13:03:22.554871 2026] [security2:error] [pid 139043:tid 139062] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsagAAtBI"] [Tue Aug 18 13:03:22.562800 2026] [security2:error] [pid 123784:tid 123815] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/mac.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdngAAQRo"] [Tue Aug 18 13:03:22.567300 2026] [security2:error] [pid 139043:tid 139262] [client 20.163.43.14:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsawAAAN4"] [Tue Aug 18 13:03:22.602254 2026] [security2:error] [pid 139043:tid 139229] [client 20.186.30.159:1688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsbQAAAL0"] [Tue Aug 18 13:03:22.609340 2026] [security2:error] [pid 139043:tid 139215] [client 20.25.139.174:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/index/function.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsbgAAAK8"] [Tue Aug 18 13:03:22.615278 2026] [security2:error] [pid 139043:tid 139186] [client 20.25.139.174:2201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/archive.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsbwAAAJI"] [Tue Aug 18 13:03:22.624217 2026] [security2:error] [pid 139043:tid 139234] [client 68.221.73.131:36083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSCSv2v-lWn9OzQT7UscAAAAMI"] [Tue Aug 18 13:03:22.628289 2026] [security2:error] [pid 139043:tid 139242] [client 52.173.121.69:31567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCSv2v-lWn9OzQT7UscQAAAMo"] [Tue Aug 18 13:03:22.640692 2026] [security2:error] [pid 139043:tid 139233] [client 40.74.65.169:44205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCSv2v-lWn9OzQT7UscgAAAME"] [Tue Aug 18 13:03:22.676228 2026] [security2:error] [pid 139043:tid 139210] [client 20.65.69.59:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ho.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsdAAAAKo"] [Tue Aug 18 13:03:22.687002 2026] [security2:error] [pid 123784:tid 123950] [client 168.62.48.100:1200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdpAAAACA"] [Tue Aug 18 13:03:22.692214 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:22.692461 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:22.712777 2026] [security2:error] [pid 139043:tid 139111] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/ops.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsdgAAqEM"] [Tue Aug 18 13:03:22.725531 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.13.23:20305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsdwAAAIc"] [Tue Aug 18 13:03:22.766197 2026] [security2:error] [pid 123784:tid 123945] [client 20.186.30.159:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/nope.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdpgAAABs"] [Tue Aug 18 13:03:22.781980 2026] [security2:error] [pid 123784:tid 123919] [client 74.248.18.37:3450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/aa.php"] [unique_id "aoSCSmwDnJBNj2tDbYYdpwAAAAE"] [Tue Aug 18 13:03:22.804201 2026] [security2:error] [pid 139043:tid 139275] [client 20.51.153.15:9508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lv.php"] [unique_id "aoSCSv2v-lWn9OzQT7UseAAAAOs"] [Tue Aug 18 13:03:22.815046 2026] [security2:error] [pid 139043:tid 139267] [client 20.65.98.162:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/images.php"] [unique_id "aoSCSv2v-lWn9OzQT7UseQAAAOM"] [Tue Aug 18 13:03:22.868427 2026] [security2:error] [pid 139043:tid 139288] [client 158.23.17.4:29469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/test_info.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsfwAAAPg"] [Tue Aug 18 13:03:22.873946 2026] [security2:error] [pid 139043:tid 139083] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/av.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsgAAAwCc"] [Tue Aug 18 13:03:22.880022 2026] [security2:error] [pid 139043:tid 139202] [client 20.186.30.159:1676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/media.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsgQAAAKI"] [Tue Aug 18 13:03:22.902684 2026] [security2:error] [pid 139043:tid 139188] [client 223.185.37.47:25606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsgwAAAJQ"] [Tue Aug 18 13:03:22.902827 2026] [security2:error] [pid 139043:tid 139188] [client 223.185.37.47:25606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsgwAAAJQ"] [Tue Aug 18 13:03:22.944670 2026] [security2:error] [pid 139043:tid 139161] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/coffexium.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsjAAAx3U"] [Tue Aug 18 13:03:22.953381 2026] [security2:error] [pid 139043:tid 139299] [client 20.65.69.59:5389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/97.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsjgAAAQM"] [Tue Aug 18 13:03:22.995761 2026] [security2:error] [pid 139043:tid 139269] [client 172.182.217.32:21772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/banners/about.php"] [unique_id "aoSCSv2v-lWn9OzQT7UsjwAAAOU"] [Tue Aug 18 13:03:23.030473 2026] [security2:error] [pid 139043:tid 139272] [client 4.223.113.180:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/Njima.php"] [unique_id "aoSCS_2v-lWn9OzQT7UskgAAAOg"] [Tue Aug 18 13:03:23.097453 2026] [security2:error] [pid 123784:tid 123886] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdsQAAdGE"] [Tue Aug 18 13:03:23.101013 2026] [security2:error] [pid 139043:tid 139273] [client 52.173.121.69:54397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCS_2v-lWn9OzQT7UslAAAAOk"] [Tue Aug 18 13:03:23.120948 2026] [security2:error] [pid 139043:tid 139179] [client 20.51.153.15:9735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/51.php"] [unique_id "aoSCS_2v-lWn9OzQT7UslwAAAIs"] [Tue Aug 18 13:03:23.137565 2026] [security2:error] [pid 139043:tid 139285] [client 168.62.48.100:1120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsmgAAAPU"] [Tue Aug 18 13:03:23.137615 2026] [security2:error] [pid 123784:tid 123963] [client 216.244.66.243:34206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/comando+filmes+hd-2/"] [unique_id "aoSCS2wDnJBNj2tDbYYdsgAAAC0"] [Tue Aug 18 13:03:23.137733 2026] [security2:error] [pid 123784:tid 123963] [client 216.244.66.243:34206] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/comando+filmes+hd-2/"] [unique_id "aoSCS2wDnJBNj2tDbYYdsgAAAC0"] [Tue Aug 18 13:03:23.140410 2026] [security2:error] [pid 123784:tid 123942] [client 20.186.30.159:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/nope.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdswAAABg"] [Tue Aug 18 13:03:23.141220 2026] [security2:error] [pid 139043:tid 139297] [client 20.151.109.219:27736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/you.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsmwAAAQE"] [Tue Aug 18 13:03:23.147306 2026] [security2:error] [pid 139043:tid 139184] [client 20.80.111.3:28217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/min.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsnAAAAJA"] [Tue Aug 18 13:03:23.157385 2026] [security2:error] [pid 123784:tid 124023] [client 20.25.139.174:2430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/bless.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdtAAAAGk"] [Tue Aug 18 13:03:23.159387 2026] [security2:error] [pid 123784:tid 123975] [client 40.74.65.169:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/sh.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdtQAAADk"] [Tue Aug 18 13:03:23.160643 2026] [security2:error] [pid 139043:tid 139209] [client 20.25.139.174:4610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/aaa.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsnQAAAKk"] [Tue Aug 18 13:03:23.166392 2026] [security2:error] [pid 139043:tid 139072] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/images.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsngAA1hw"] [Tue Aug 18 13:03:23.171207 2026] [security2:error] [pid 139043:tid 139284] [client 191.237.254.161:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/k.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsoAAAAPQ"] [Tue Aug 18 13:03:23.176491 2026] [security2:error] [pid 123784:tid 123941] [client 4.232.151.198:41124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/input.php"] [unique_id "aoSCS2wDnJBNj2tDbYYduAAAABc"] [Tue Aug 18 13:03:23.181784 2026] [security2:error] [pid 139043:tid 139292] [client 158.23.17.4:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/hr.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsoQAAAPw"] [Tue Aug 18 13:03:23.226331 2026] [security2:error] [pid 139043:tid 139250] [client 20.65.69.59:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/rh.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsowAAANI"] [Tue Aug 18 13:03:23.229494 2026] [security2:error] [pid 123784:tid 123992] [client 68.155.154.236:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdugAAAEo"] [Tue Aug 18 13:03:23.238983 2026] [security2:error] [pid 123784:tid 124028] [client 20.186.30.159:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/admin.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdvAAAAG4"] [Tue Aug 18 13:03:23.249925 2026] [security2:error] [pid 123784:tid 123936] [client 20.206.73.37:11962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/yj09.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdvQAAABI"] [Tue Aug 18 13:03:23.250341 2026] [security2:error] [pid 139043:tid 139268] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-access.php"] [unique_id "aoSCS_2v-lWn9OzQT7UspwAAAOQ"] [Tue Aug 18 13:03:23.259823 2026] [security2:error] [pid 139043:tid 139142] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/sf.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsqAAAyGI"] [Tue Aug 18 13:03:23.272549 2026] [security2:error] [pid 139043:tid 139237] [client 74.7.175.174:43196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "www.pedrosoutoadvocacia.com.br"] [uri "/index.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsqQAAxSM"], referer: https://pedrosoutoadvocacia.com.br/robots.txt [Tue Aug 18 13:03:23.292256 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:23.292543 2026] [authz_core:error] [pid 123784:tid 123893] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:23.312894 2026] [security2:error] [pid 139043:tid 139245] [client 20.65.98.162:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/ops.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsqwAAAM0"] [Tue Aug 18 13:03:23.332717 2026] [security2:error] [pid 139043:tid 139215] [client 40.74.65.169:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/too.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsrgAAAK8"] [Tue Aug 18 13:03:23.339153 2026] [security2:error] [pid 123784:tid 123814] [remote 47.128.18.209:62254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ruanautomoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSCS2wDnJBNj2tDbYYdwQAALxk"] [Tue Aug 18 13:03:23.344408 2026] [security2:error] [pid 139043:tid 139186] [client 158.23.17.4:38910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/14.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsrwAAAJI"] [Tue Aug 18 13:03:23.360788 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.36.136:57233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCS_2v-lWn9OzQT7UssAAAAOE"] [Tue Aug 18 13:03:23.361212 2026] [security2:error] [pid 139043:tid 139234] [client 158.23.17.4:15114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ri.php"] [unique_id "aoSCS_2v-lWn9OzQT7UssQAAAMI"] [Tue Aug 18 13:03:23.383781 2026] [security2:error] [pid 139043:tid 139293] [client 197.184.64.235:41975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCS_2v-lWn9OzQT7UssgAAAP0"] [Tue Aug 18 13:03:23.388597 2026] [security2:error] [pid 139043:tid 139293] [client 197.184.64.235:41975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCS_2v-lWn9OzQT7UssgAAAP0"] [Tue Aug 18 13:03:23.400295 2026] [security2:error] [pid 123784:tid 123962] [client 213.35.127.232:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdxAAAACw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:23.407366 2026] [security2:error] [pid 139043:tid 139210] [client 20.51.153.15:9524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ew.php"] [unique_id "aoSCS_2v-lWn9OzQT7UstAAAAKo"] [Tue Aug 18 13:03:23.409043 2026] [security2:error] [pid 139043:tid 139281] [client 20.250.13.23:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/data.php"] [unique_id "aoSCS_2v-lWn9OzQT7UstQAAAPE"] [Tue Aug 18 13:03:23.413366 2026] [security2:error] [pid 139043:tid 139216] [client 74.248.18.37:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/abcd.php"] [unique_id "aoSCS_2v-lWn9OzQT7UstgAAALA"] [Tue Aug 18 13:03:23.420163 2026] [security2:error] [pid 123784:tid 123904] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/k.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdxgAAcnM"] [Tue Aug 18 13:03:23.422939 2026] [autoindex:error] [pid 123784:tid 123970] [client 20.163.43.14:6641] AH01276: Cannot serve directory /home1/economycars/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:23.428207 2026] [security2:error] [pid 139043:tid 139224] [client 68.221.73.131:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/gec.php"] [unique_id "aoSCS_2v-lWn9OzQT7UstwAAALg"] [Tue Aug 18 13:03:23.445440 2026] [security2:error] [pid 139043:tid 139191] [client 20.186.30.159:14244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/new.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsuAAAAJc"] [Tue Aug 18 13:03:23.448543 2026] [security2:error] [pid 139043:tid 139167] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/ops.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsuQAAqHs"] [Tue Aug 18 13:03:23.467013 2026] [security2:error] [pid 139043:tid 139290] [client 168.62.48.100:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsvAAAAPo"] [Tue Aug 18 13:03:23.479583 2026] [security2:error] [pid 123784:tid 124026] [client 20.65.69.59:48474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/yg.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdyAAAAGw"] [Tue Aug 18 13:03:23.502173 2026] [security2:error] [pid 123784:tid 123968] [client 52.173.121.69:57067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdyQAAADI"] [Tue Aug 18 13:03:23.527439 2026] [security2:error] [pid 139043:tid 139207] [client 172.182.217.32:21816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSCS_2v-lWn9OzQT7UswQAAAKc"] [Tue Aug 18 13:03:23.529066 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.154.236:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCS_2v-lWn9OzQT7UswgAAAKw"] [Tue Aug 18 13:03:23.552898 2026] [security2:error] [pid 123784:tid 124015] [client 52.173.121.69:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdzAAAAGE"] [Tue Aug 18 13:03:23.566091 2026] [security2:error] [pid 139043:tid 139288] [client 20.186.30.159:1945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/mac.php"] [unique_id "aoSCS_2v-lWn9OzQT7UswwAAAPg"] [Tue Aug 18 13:03:23.584675 2026] [security2:error] [pid 139043:tid 139225] [client 20.79.204.6:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/nw.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsxAAAALk"] [Tue Aug 18 13:03:23.584700 2026] [security2:error] [pid 139043:tid 139217] [client 20.163.43.14:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wso.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsxQAAALE"] [Tue Aug 18 13:03:23.594995 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:23.595434 2026] [authz_core:error] [pid 123784:tid 123912] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:23.597261 2026] [security2:error] [pid 139043:tid 139071] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/82.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsxgAAvBs"] [Tue Aug 18 13:03:23.600976 2026] [security2:error] [pid 139043:tid 139280] [client 20.80.111.3:28203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/plugins/data.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsxwAAAPA"] [Tue Aug 18 13:03:23.654016 2026] [security2:error] [pid 123784:tid 123967] [client 20.51.153.15:9486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pqr.php"] [unique_id "aoSCS2wDnJBNj2tDbYYdzwAAADE"] [Tue Aug 18 13:03:23.672442 2026] [security2:error] [pid 139043:tid 139223] [client 20.25.139.174:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/abcd.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsyQAAALc"] [Tue Aug 18 13:03:23.681836 2026] [security2:error] [pid 139043:tid 139199] [client 20.116.17.175:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/crgio.php"] [unique_id "aoSCS_2v-lWn9OzQT7UsygAAAJ8"] [Tue Aug 18 13:03:23.725948 2026] [security2:error] [pid 139043:tid 139222] [client 20.65.98.162:21857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/coffexium.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us0AAAALY"] [Tue Aug 18 13:03:23.726158 2026] [security2:error] [pid 139043:tid 139203] [client 20.25.139.174:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/sagax1.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us0QAAAKM"] [Tue Aug 18 13:03:23.750770 2026] [security2:error] [pid 139043:tid 139273] [client 20.206.73.37:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/scxy.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us0gAAAOk"] [Tue Aug 18 13:03:23.761157 2026] [security2:error] [pid 123784:tid 124039] [client 20.65.69.59:48489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/et.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd0QAAAHk"] [Tue Aug 18 13:03:23.768629 2026] [security2:error] [pid 139043:tid 139088] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/key.pem"] [unique_id "aoSCS_2v-lWn9OzQT7Us1AAA5yw"] [Tue Aug 18 13:03:23.770367 2026] [security2:error] [pid 139043:tid 139091] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/privatekey.key"] [unique_id "aoSCS_2v-lWn9OzQT7Us1QAA5y8"] [Tue Aug 18 13:03:23.792129 2026] [security2:error] [pid 139043:tid 139297] [client 20.186.30.159:7285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/new.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us3QAAAQE"] [Tue Aug 18 13:03:23.800151 2026] [security2:error] [pid 139043:tid 139198] [client 4.232.151.198:49302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/jquery.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us3gAAAJ4"] [Tue Aug 18 13:03:23.811014 2026] [security2:error] [pid 123784:tid 123977] [client 168.62.48.100:1130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd0wAAADs"] [Tue Aug 18 13:03:23.812325 2026] [security2:error] [pid 139043:tid 139254] [client 20.186.30.159:1674] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mkstecnologias.com.br"] [uri "/1.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us4AAAANY"] [Tue Aug 18 13:03:23.812415 2026] [security2:error] [pid 139043:tid 139254] [client 20.186.30.159:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/1.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us4AAAANY"] [Tue Aug 18 13:03:23.815809 2026] [security2:error] [pid 123784:tid 123993] [client 20.151.109.219:10563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ez.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd1AAAAEs"] [Tue Aug 18 13:03:23.826774 2026] [security2:error] [pid 139043:tid 139232] [client 4.223.113.180:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/colors.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us4gAAAMA"] [Tue Aug 18 13:03:23.852918 2026] [security2:error] [pid 123784:tid 123827] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/dex.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd1QAAUSY"] [Tue Aug 18 13:03:23.862012 2026] [security2:error] [pid 139043:tid 139250] [client 158.23.17.4:9292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/tk.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us5gAAANI"] [Tue Aug 18 13:03:23.865272 2026] [security2:error] [pid 123784:tid 124005] [client 40.74.65.169:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/button.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd1gAAAFc"] [Tue Aug 18 13:03:23.884429 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd1wAAABo"] [Tue Aug 18 13:03:23.884528 2026] [security2:error] [pid 123784:tid 123944] [client 196.12.128.158:63548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd1wAAABo"] [Tue Aug 18 13:03:23.892669 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:23.892962 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:23.896812 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:9818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/an.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us5wAAAOQ"] [Tue Aug 18 13:03:23.908560 2026] [security2:error] [pid 139043:tid 139251] [client 40.74.65.169:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/82.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us6AAAANM"] [Tue Aug 18 13:03:23.911892 2026] [security2:error] [pid 123784:tid 124017] [client 20.163.43.14:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/sf.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd2gAAAGM"] [Tue Aug 18 13:03:23.914380 2026] [security2:error] [pid 139043:tid 139165] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/private-key"] [unique_id "aoSCS_2v-lWn9OzQT7Us6QAAtHk"] [Tue Aug 18 13:03:23.914664 2026] [security2:error] [pid 139043:tid 139135] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/localhost.key"] [unique_id "aoSCS_2v-lWn9OzQT7Us6gAAtFs"] [Tue Aug 18 13:03:23.916777 2026] [security2:error] [pid 139043:tid 139050] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/ssl/server.key"] [unique_id "aoSCS_2v-lWn9OzQT7Us6wAAyAY"] [Tue Aug 18 13:03:23.916780 2026] [security2:error] [pid 139043:tid 139055] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/host.key"] [unique_id "aoSCS_2v-lWn9OzQT7Us7AAAyAs"] [Tue Aug 18 13:03:23.935041 2026] [security2:error] [pid 123784:tid 123969] [client 68.221.73.131:37373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/sky.php"] [unique_id "aoSCS2wDnJBNj2tDbYYd2wAAADM"] [Tue Aug 18 13:03:23.946235 2026] [security2:error] [pid 139043:tid 139230] [client 52.173.121.69:27716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCS_2v-lWn9OzQT7Us7QAAAL4"] [Tue Aug 18 13:03:24.001660 2026] [security2:error] [pid 139043:tid 139094] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/puc.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us7wAA2TI"] [Tue Aug 18 13:03:24.007988 2026] [security2:error] [pid 139043:tid 139214] [client 20.65.69.59:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/of.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us8AAAAK4"] [Tue Aug 18 13:03:24.017579 2026] [security2:error] [pid 123784:tid 124022] [client 172.182.217.32:21556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/img/about.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd3gAAAGg"] [Tue Aug 18 13:03:24.028367 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:20344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us_AAAAPQ"] [Tue Aug 18 13:03:24.035801 2026] [security2:error] [pid 139043:tid 139242] [client 158.23.17.4:15786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kt.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us_QAAAMo"] [Tue Aug 18 13:03:24.036183 2026] [security2:error] [pid 139043:tid 139194] [client 40.74.65.169:44192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maximusblocos.com.br"] [uri "/g3.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us_gAAAJo"] [Tue Aug 18 13:03:24.052023 2026] [security2:error] [pid 139043:tid 139279] [client 20.80.111.3:26008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/plugins/plugin-install.php"] [unique_id "aoSCTP2v-lWn9OzQT7Us_wAAAO8"] [Tue Aug 18 13:03:24.054606 2026] [security2:error] [pid 139043:tid 139227] [client 74.248.18.37:55934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/admin.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtAAAAALs"] [Tue Aug 18 13:03:24.058400 2026] [security2:error] [pid 139043:tid 139291] [client 20.186.30.159:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/coffee.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtAQAAAPs"] [Tue Aug 18 13:03:24.059251 2026] [security2:error] [pid 139043:tid 139293] [client 20.186.30.159:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/apreset.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtAgAAAP0"] [Tue Aug 18 13:03:24.109371 2026] [security2:error] [pid 139043:tid 139263] [client 4.232.151.198:44117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/bgymj.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtBgAAAN8"] [Tue Aug 18 13:03:24.172386 2026] [security2:error] [pid 139043:tid 139208] [client 20.65.98.162:21824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtBwAAAKg"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:24.173568 2026] [fcgid:warn] [pid 139043:tid 139193] (104)Connection reset by peer: [client 103.168.66.229:51027] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:24.173583 2026] [core:error] [pid 139043:tid 139193] [client 103.168.66.229:51027] End of script output before headers: index.fcgi [Tue Aug 18 13:03:24.183988 2026] [security2:error] [pid 123784:tid 123865] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/inso.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd4QAAW0w"] [Tue Aug 18 13:03:24.192986 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:24.193232 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:24.200726 2026] [security2:error] [pid 139043:tid 139247] [client 168.62.48.100:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtCAAAAM8"] [Tue Aug 18 13:03:24.211533 2026] [security2:error] [pid 139043:tid 139265] [client 20.25.139.174:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-good.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtCgAAAOE"] [Tue Aug 18 13:03:24.222426 2026] [security2:error] [pid 139043:tid 139182] [client 20.226.36.136:57833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtDAAAAI4"] [Tue Aug 18 13:03:24.225629 2026] [security2:error] [pid 123784:tid 124010] [client 20.206.73.37:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ws13.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd4wAAAFw"] [Tue Aug 18 13:03:24.250480 2026] [security2:error] [pid 123784:tid 123952] [client 20.163.43.14:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/index/function.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd5AAAACI"] [Tue Aug 18 13:03:24.263199 2026] [security2:error] [pid 139043:tid 139112] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/coffexium.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtDQAAvUQ"] [Tue Aug 18 13:03:24.268341 2026] [security2:error] [pid 123784:tid 123983] [client 20.51.153.15:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sy.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd6AAAAEE"] [Tue Aug 18 13:03:24.274142 2026] [security2:error] [pid 139043:tid 139224] [client 20.25.139.174:2264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wpc.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtDgAAALg"] [Tue Aug 18 13:03:24.290661 2026] [security2:error] [pid 139043:tid 139287] [client 20.65.69.59:43313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/bu.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtDwAAAPc"] [Tue Aug 18 13:03:24.295538 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:17575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/tp.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtEAAAAIY"] [Tue Aug 18 13:03:24.324829 2026] [security2:error] [pid 123784:tid 123974] [client 37.40.227.74:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd6gAAADg"] [Tue Aug 18 13:03:24.328828 2026] [security2:error] [pid 123784:tid 123974] [client 37.40.227.74:57237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd6gAAADg"] [Tue Aug 18 13:03:24.342338 2026] [security2:error] [pid 139043:tid 139256] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/nw.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtEgAAANg"] [Tue Aug 18 13:03:24.343444 2026] [security2:error] [pid 123784:tid 124012] [client 20.186.30.159:1974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd6wAAAF4"] [Tue Aug 18 13:03:24.350133 2026] [security2:error] [pid 139043:tid 139053] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/aa.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtEwAAlAk"] [Tue Aug 18 13:03:24.370413 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.73.37:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtFAAAALw"] [Tue Aug 18 13:03:24.397666 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:64163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtFQAAAJ8"] [Tue Aug 18 13:03:24.405512 2026] [security2:error] [pid 139043:tid 139178] [client 20.186.30.159:7292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/1mage.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtFgAAAIo"] [Tue Aug 18 13:03:24.414863 2026] [security2:error] [pid 139043:tid 139211] [client 20.151.109.219:58708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/asus.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtFwAAAKs"] [Tue Aug 18 13:03:24.422733 2026] [security2:error] [pid 139043:tid 139281] [client 213.35.127.232:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtGAAAAPE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:24.425223 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ws62.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtGQAAAOw"] [Tue Aug 18 13:03:24.458286 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/hp.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtGwAAAOk"] [Tue Aug 18 13:03:24.463332 2026] [security2:error] [pid 139043:tid 139134] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/ssl/localhost.key"] [unique_id "aoSCTP2v-lWn9OzQT7UtHAAAi1o"] [Tue Aug 18 13:03:24.472787 2026] [security2:error] [pid 139043:tid 139140] [remote 136.110.27.48:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "3xsolutions.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoSCTP2v-lWn9OzQT7UtHQAAoGA"] [Tue Aug 18 13:03:24.475606 2026] [security2:error] [pid 139043:tid 139212] [client 4.232.151.198:22216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/media-new.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtHgAAAKw"] [Tue Aug 18 13:03:24.488408 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/public/vx.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd8QAAAF0"] [Tue Aug 18 13:03:24.511307 2026] [security2:error] [pid 123784:tid 123826] [remote 20.203.183.135:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd8wAAASU"] [Tue Aug 18 13:03:24.511414 2026] [security2:error] [pid 123784:tid 123826] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd8wAAASU"] [Tue Aug 18 13:03:24.511416 2026] [security2:error] [pid 139043:tid 139209] [client 168.62.48.100:1063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtHwAAAKk"] [Tue Aug 18 13:03:24.515526 2026] [security2:error] [pid 123784:tid 123980] [client 20.51.153.15:9816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/57.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd9AAAAD4"] [Tue Aug 18 13:03:24.540276 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.217.32:21778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/languages/about.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtIQAAANA"] [Tue Aug 18 13:03:24.542086 2026] [security2:error] [pid 123784:tid 123960] [client 20.80.111.3:28194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/plugins/users.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd9wAAACo"] [Tue Aug 18 13:03:24.544670 2026] [security2:error] [pid 139043:tid 139117] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/BDKR28WP.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtIgAA4Ek"] [Tue Aug 18 13:03:24.552115 2026] [security2:error] [pid 123784:tid 123972] [client 132.196.30.78:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/bolt.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd-AAAADY"] [Tue Aug 18 13:03:24.552754 2026] [security2:error] [pid 139043:tid 139271] [client 20.65.69.59:5377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/rn.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtIwAAAOc"] [Tue Aug 18 13:03:24.553862 2026] [security2:error] [pid 139043:tid 139192] [client 40.74.65.169:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/wlc.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtJAAAAJg"] [Tue Aug 18 13:03:24.572374 2026] [security2:error] [pid 139043:tid 139294] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/loxi-o.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtJQAAAP4"] [Tue Aug 18 13:03:24.575884 2026] [security2:error] [pid 139043:tid 139251] [client 20.163.43.14:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/edit.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtJgAAANM"] [Tue Aug 18 13:03:24.586760 2026] [security2:error] [pid 123784:tid 123947] [client 20.65.98.162:21791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/sf.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd-QAAAB0"] [Tue Aug 18 13:03:24.599642 2026] [security2:error] [pid 123784:tid 124024] [client 52.173.121.69:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCTGwDnJBNj2tDbYYd-gAAAGo"] [Tue Aug 18 13:03:24.605834 2026] [security2:error] [pid 139043:tid 139240] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sdsa.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtJwAAAMg"] [Tue Aug 18 13:03:24.635836 2026] [security2:error] [pid 139043:tid 139230] [client 20.186.30.159:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtKAAAAL4"] [Tue Aug 18 13:03:24.650700 2026] [security2:error] [pid 139043:tid 139286] [client 20.226.36.136:57842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtKQAAAPY"] [Tue Aug 18 13:03:24.664028 2026] [security2:error] [pid 139043:tid 139206] [client 20.186.30.159:14216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/imsc.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtKwAAAKY"] [Tue Aug 18 13:03:24.678786 2026] [security2:error] [pid 139043:tid 139056] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/img.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtLQAA1Qw"] [Tue Aug 18 13:03:24.717050 2026] [security2:error] [pid 139043:tid 139246] [client 20.25.139.174:4481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/simple.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtLgAAAM4"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:24.725130 2026] [fcgid:warn] [pid 139043:tid 139285] (104)Connection reset by peer: [client 103.168.66.229:51194] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:24.725150 2026] [core:error] [pid 139043:tid 139285] [client 103.168.66.229:51194] End of script output before headers: index.fcgi [Tue Aug 18 13:03:24.764108 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.56.190:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/sym.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtLwAAAPs"] [Tue Aug 18 13:03:24.796544 2026] [authz_core:error] [pid 123784:tid 123914] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:24.796826 2026] [authz_core:error] [pid 123784:tid 123914] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:24.797967 2026] [security2:error] [pid 139043:tid 139216] [client 20.65.69.59:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ut.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtMAAAALA"] [Tue Aug 18 13:03:24.801853 2026] [security2:error] [pid 123784:tid 123938] [client 20.250.13.23:3126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeAQAAABQ"] [Tue Aug 18 13:03:24.803603 2026] [security2:error] [pid 123784:tid 124034] [client 168.62.48.100:1205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeAgAAAHQ"] [Tue Aug 18 13:03:24.816336 2026] [security2:error] [pid 123784:tid 124023] [client 68.221.73.131:64584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/sixxis.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeAwAAAGk"] [Tue Aug 18 13:03:24.860610 2026] [security2:error] [pid 139043:tid 139102] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/sf.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtMQAAqDo"] [Tue Aug 18 13:03:24.864392 2026] [security2:error] [pid 139043:tid 139252] [client 20.51.153.15:9553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ah.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtMgAAANQ"] [Tue Aug 18 13:03:24.866783 2026] [security2:error] [pid 123784:tid 123833] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/222.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeCQAAYiw"] [Tue Aug 18 13:03:24.867324 2026] [security2:error] [pid 139043:tid 139257] [client 20.25.139.174:2266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/fone1.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtMwAAANk"] [Tue Aug 18 13:03:24.875018 2026] [security2:error] [pid 139043:tid 139300] [client 20.206.73.37:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/btx25.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtNAAAAQQ"] [Tue Aug 18 13:03:24.888864 2026] [security2:error] [pid 139043:tid 139231] [client 20.186.30.159:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/yj09.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtNQAAAL8"] [Tue Aug 18 13:03:24.912021 2026] [security2:error] [pid 123784:tid 123964] [client 74.248.18.37:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeCwAAAC4"] [Tue Aug 18 13:03:24.933174 2026] [security2:error] [pid 123784:tid 124000] [client 158.23.17.4:25350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ww.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeDAAAAFI"] [Tue Aug 18 13:03:24.953204 2026] [security2:error] [pid 139043:tid 139265] [client 20.186.30.159:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtNwAAAOE"] [Tue Aug 18 13:03:24.968812 2026] [security2:error] [pid 139043:tid 139187] [client 20.79.204.6:9314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/xleet.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtOQAAAJM"] [Tue Aug 18 13:03:24.974120 2026] [security2:error] [pid 123784:tid 123961] [client 20.226.36.136:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCTGwDnJBNj2tDbYYeDgAAACs"] [Tue Aug 18 13:03:25.001364 2026] [security2:error] [pid 139043:tid 139170] [remote 162.241.153.188:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSCTP2v-lWn9OzQT7UtOgAAh34"] [Tue Aug 18 13:03:25.009681 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:38905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wx.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtOwAAALg"] [Tue Aug 18 13:03:25.011083 2026] [security2:error] [pid 139043:tid 139180] [client 20.65.98.162:21863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/k.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtPAAAAIw"] [Tue Aug 18 13:03:25.014755 2026] [security2:error] [pid 139043:tid 139120] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/key.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtPQAA90w"] [Tue Aug 18 13:03:25.031183 2026] [security2:error] [pid 123784:tid 123992] [client 172.182.217.32:21852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes.bak/html-api/about.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeEQAAAEo"] [Tue Aug 18 13:03:25.056519 2026] [security2:error] [pid 139043:tid 139225] [client 158.23.17.4:54730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/zj.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtPwAAALk"] [Tue Aug 18 13:03:25.058941 2026] [security2:error] [pid 139043:tid 139185] [client 20.65.69.59:59221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/eh.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtQAAAAJE"] [Tue Aug 18 13:03:25.084824 2026] [security2:error] [pid 139043:tid 139274] [client 4.232.151.198:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/aa.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtQQAAAOo"] [Tue Aug 18 13:03:25.099295 2026] [security2:error] [pid 139043:tid 139201] [client 4.232.151.198:41120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtQgAAAKE"] [Tue Aug 18 13:03:25.100638 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:25.100926 2026] [authz_core:error] [pid 123784:tid 123809] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:25.130929 2026] [security2:error] [pid 123784:tid 124025] [client 20.186.30.159:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/scxy.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeFAAAAGs"] [Tue Aug 18 13:03:25.152832 2026] [security2:error] [pid 139043:tid 139280] [client 20.151.109.219:21895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/22.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtQwAAAPA"] [Tue Aug 18 13:03:25.165526 2026] [security2:error] [pid 139043:tid 139244] [client 20.51.153.15:9530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vw.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtRgAAAMw"] [Tue Aug 18 13:03:25.168393 2026] [security2:error] [pid 139043:tid 139138] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/k.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtRwAAx14"] [Tue Aug 18 13:03:25.172198 2026] [security2:error] [pid 139043:tid 139223] [client 20.80.111.3:5936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/themes/config.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtSAAAALc"] [Tue Aug 18 13:03:25.220500 2026] [security2:error] [pid 139043:tid 139178] [client 20.186.30.159:14210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/qlex1.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtSgAAAIo"] [Tue Aug 18 13:03:25.239665 2026] [security2:error] [pid 123784:tid 123991] [client 40.74.65.169:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/fi.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeGQAAAEk"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:25.245181 2026] [fcgid:warn] [pid 139043:tid 139288] (104)Connection reset by peer: [client 103.168.66.229:51301] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:25.245206 2026] [core:error] [pid 139043:tid 139288] [client 103.168.66.229:51301] End of script output before headers: index.fcgi [Tue Aug 18 13:03:25.265484 2026] [security2:error] [pid 123784:tid 123948] [client 74.248.130.103:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/blurbs.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeGwAAAB4"] [Tue Aug 18 13:03:25.295661 2026] [security2:error] [pid 123784:tid 123997] [client 20.163.43.14:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeHAAAAE8"] [Tue Aug 18 13:03:25.298573 2026] [security2:error] [pid 123784:tid 123984] [client 40.74.65.169:5661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/dex.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeHQAAAEI"] [Tue Aug 18 13:03:25.311202 2026] [security2:error] [pid 123784:tid 123929] [client 20.206.73.37:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/SDsadqwrf.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeHgAAAAs"] [Tue Aug 18 13:03:25.311805 2026] [security2:error] [pid 139043:tid 139169] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtSwAAo30"] [Tue Aug 18 13:03:25.328009 2026] [security2:error] [pid 123784:tid 124002] [client 20.65.69.59:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ad.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeHwAAAFQ"] [Tue Aug 18 13:03:25.335607 2026] [security2:error] [pid 139043:tid 139269] [client 52.173.121.69:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtTQAAAOU"] [Tue Aug 18 13:03:25.362501 2026] [security2:error] [pid 139043:tid 139256] [client 20.25.139.174:4649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/edit-tags.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtTgAAANg"] [Tue Aug 18 13:03:25.379297 2026] [security2:error] [pid 139043:tid 139209] [client 20.226.56.190:47125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.56.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/ye.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtTwAAAKk"] [Tue Aug 18 13:03:25.403213 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:25.403645 2026] [authz_core:error] [pid 123784:tid 123791] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:25.428828 2026] [security2:error] [pid 139043:tid 139211] [client 20.25.139.174:2409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ncx.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtUAAAAKs"] [Tue Aug 18 13:03:25.428891 2026] [security2:error] [pid 123784:tid 124031] [client 20.186.30.159:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeIgAAAHE"] [Tue Aug 18 13:03:25.433664 2026] [security2:error] [pid 139043:tid 139292] [client 20.65.98.162:21860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/82.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtUgAAAPw"] [Tue Aug 18 13:03:25.433839 2026] [security2:error] [pid 123784:tid 123977] [client 168.62.48.100:1137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeIwAAADs"] [Tue Aug 18 13:03:25.442472 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeJQAAAE0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:25.463147 2026] [security2:error] [pid 139043:tid 139081] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/thoms.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtVAAA5yU"] [Tue Aug 18 13:03:25.478700 2026] [security2:error] [pid 139043:tid 139250] [client 20.186.30.159:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/mariju.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtVgAAANI"] [Tue Aug 18 13:03:25.484943 2026] [security2:error] [pid 139043:tid 139128] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/82.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtVwAA5FQ"] [Tue Aug 18 13:03:25.492403 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:9814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lj.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtWQAAANM"] [Tue Aug 18 13:03:25.500039 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:14066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mo.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtWgAAALQ"] [Tue Aug 18 13:03:25.500597 2026] [security2:error] [pid 123784:tid 124037] [client 68.221.73.131:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/yj09.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeJgAAAHc"] [Tue Aug 18 13:03:25.519428 2026] [security2:error] [pid 139043:tid 139297] [client 172.182.217.32:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/widgets/about.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtWwAAAQE"] [Tue Aug 18 13:03:25.526779 2026] [security2:error] [pid 123784:tid 123944] [client 68.155.154.236:8832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeJwAAABo"] [Tue Aug 18 13:03:25.538209 2026] [security2:error] [pid 139043:tid 139230] [client 20.206.73.37:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtXQAAAL4"] [Tue Aug 18 13:03:25.562413 2026] [security2:error] [pid 139043:tid 139226] [client 74.248.18.37:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/akc.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtXwAAALo"] [Tue Aug 18 13:03:25.601172 2026] [security2:error] [pid 139043:tid 139215] [client 132.196.30.78:1639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtYAAAAK8"] [Tue Aug 18 13:03:25.625447 2026] [security2:error] [pid 139043:tid 139234] [client 20.163.43.14:6587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-good.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtYQAAAMI"] [Tue Aug 18 13:03:25.635808 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:30803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtYgAAAPQ"] [Tue Aug 18 13:03:25.635883 2026] [security2:error] [pid 139043:tid 139294] [client 20.80.111.3:12484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/themes/db-status.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtYwAAAP4"] [Tue Aug 18 13:03:25.644383 2026] [security2:error] [pid 123784:tid 123923] [client 20.65.69.59:5744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/vd.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeKgAAAAU"] [Tue Aug 18 13:03:25.644825 2026] [security2:error] [pid 139043:tid 139285] [client 20.116.17.175:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtZAAAAPU"] [Tue Aug 18 13:03:25.682504 2026] [security2:error] [pid 123784:tid 123985] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-freya.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeKwAAAEM"] [Tue Aug 18 13:03:25.691747 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/dj.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtZQAAANE"] [Tue Aug 18 13:03:25.702131 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:25.702393 2026] [authz_core:error] [pid 123784:tid 123832] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:25.718685 2026] [security2:error] [pid 123784:tid 124013] [client 168.62.48.100:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeLwAAAF8"] [Tue Aug 18 13:03:25.729121 2026] [security2:error] [pid 123784:tid 124041] [client 20.206.73.37:34811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ano.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeMAAAAHs"] [Tue Aug 18 13:03:25.730830 2026] [security2:error] [pid 123784:tid 124040] [client 74.248.130.103:50162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/100.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeMQAAAHo"] [Tue Aug 18 13:03:25.731625 2026] [security2:error] [pid 123784:tid 124045] [client 20.65.98.162:21761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/dex.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeMgAAAH8"] [Tue Aug 18 13:03:25.759628 2026] [security2:error] [pid 123784:tid 124017] [client 4.232.151.198:41149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeMwAAAGM"] [Tue Aug 18 13:03:25.761223 2026] [security2:error] [pid 139043:tid 139291] [client 20.51.153.15:9757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kh.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtZgAAAPs"] [Tue Aug 18 13:03:25.782931 2026] [security2:error] [pid 139043:tid 139093] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/dex.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtaAAA4jE"] [Tue Aug 18 13:03:25.808401 2026] [security2:error] [pid 139043:tid 139241] [client 52.173.121.69:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtaQAAAMk"] [Tue Aug 18 13:03:25.809989 2026] [security2:error] [pid 139043:tid 139210] [client 20.206.73.37:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/BDKR28WP.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtagAAAKo"] [Tue Aug 18 13:03:25.828563 2026] [security2:error] [pid 139043:tid 139218] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fleen.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtawAAALI"] [Tue Aug 18 13:03:25.829939 2026] [security2:error] [pid 139043:tid 139252] [client 168.62.48.100:1222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtbAAAANQ"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:25.836199 2026] [fcgid:warn] [pid 139043:tid 139246] (104)Connection reset by peer: [client 103.168.66.229:51419] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:25.836213 2026] [core:error] [pid 139043:tid 139246] [client 103.168.66.229:51419] End of script output before headers: index.fcgi [Tue Aug 18 13:03:25.846288 2026] [security2:error] [pid 139043:tid 139270] [client 20.186.30.159:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtbQAAAOY"] [Tue Aug 18 13:03:25.857703 2026] [security2:error] [pid 139043:tid 139300] [client 20.186.30.159:1960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtbgAAAQQ"] [Tue Aug 18 13:03:25.866560 2026] [security2:error] [pid 123784:tid 123957] [client 20.79.204.6:9665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeNQAAACc"] [Tue Aug 18 13:03:25.895710 2026] [security2:error] [pid 139043:tid 139277] [client 20.65.69.59:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/56.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtbwAAAO0"] [Tue Aug 18 13:03:25.899660 2026] [security2:error] [pid 139043:tid 139213] [client 4.223.113.180:12147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtcAAAAK0"] [Tue Aug 18 13:03:25.909161 2026] [security2:error] [pid 139043:tid 139114] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/wpxml.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtcQAAiUY"] [Tue Aug 18 13:03:25.926504 2026] [security2:error] [pid 123784:tid 124005] [client 86.120.159.145:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeNwAAAFc"] [Tue Aug 18 13:03:25.926649 2026] [security2:error] [pid 123784:tid 124005] [client 86.120.159.145:17009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeNwAAAFc"] [Tue Aug 18 13:03:25.931774 2026] [security2:error] [pid 123784:tid 123952] [client 40.74.65.169:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/chris.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeOAAAACI"] [Tue Aug 18 13:03:25.941477 2026] [security2:error] [pid 139043:tid 139183] [client 20.25.139.174:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/u.php"] [unique_id "aoSCTf2v-lWn9OzQT7UtcgAAAI8"] [Tue Aug 18 13:03:25.967864 2026] [security2:error] [pid 123784:tid 123983] [client 20.151.109.219:10611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/zs.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeOQAAAEE"] [Tue Aug 18 13:03:25.978368 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:2285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCTWwDnJBNj2tDbYYeOgAAADc"] [Tue Aug 18 13:03:25.999755 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:26.000119 2026] [authz_core:error] [pid 123784:tid 123867] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:26.024677 2026] [security2:error] [pid 139043:tid 139290] [client 172.182.217.32:21797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/IXR/about.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtdQAAAPo"] [Tue Aug 18 13:03:26.063402 2026] [security2:error] [pid 139043:tid 139046] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/file1221.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtdgAAsQI"] [Tue Aug 18 13:03:26.071537 2026] [security2:error] [pid 139043:tid 139225] [client 20.65.98.162:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/puc.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtdwAAALk"] [Tue Aug 18 13:03:26.097353 2026] [security2:error] [pid 139043:tid 139139] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/puc.php"] [unique_id "aoSCTv2v-lWn9OzQT7UteAAAkV8"] [Tue Aug 18 13:03:26.100051 2026] [security2:error] [pid 139043:tid 139188] [client 20.186.30.159:1701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/blurbs.php"] [unique_id "aoSCTv2v-lWn9OzQT7UteQAAAJQ"] [Tue Aug 18 13:03:26.106021 2026] [security2:error] [pid 139043:tid 139228] [client 68.155.154.236:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtegAAALw"] [Tue Aug 18 13:03:26.144625 2026] [security2:error] [pid 123784:tid 124011] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/e.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeQQAAAF0"] [Tue Aug 18 13:03:26.152228 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:9787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/jb.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtfAAAAIU"] [Tue Aug 18 13:03:26.160943 2026] [security2:error] [pid 139043:tid 139239] [client 20.186.30.159:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/contacto.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtfQAAAMc"] [Tue Aug 18 13:03:26.172829 2026] [security2:error] [pid 139043:tid 139282] [client 20.65.69.59:27842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/rx.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtfwAAAPI"] [Tue Aug 18 13:03:26.193199 2026] [security2:error] [pid 123784:tid 123988] [client 74.248.18.37:55893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/buy.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeQwAAAEY"] [Tue Aug 18 13:03:26.222739 2026] [security2:error] [pid 139043:tid 139281] [client 74.248.130.103:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/ccc.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtgQAAAPE"] [Tue Aug 18 13:03:26.228952 2026] [security2:error] [pid 139043:tid 139166] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/nox.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtggAA7Ho"] [Tue Aug 18 13:03:26.239784 2026] [security2:error] [pid 123784:tid 123947] [client 68.221.73.131:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/k.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeRAAAAB0"] [Tue Aug 18 13:03:26.259133 2026] [security2:error] [pid 139043:tid 139235] [client 20.250.13.23:3417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCTv2v-lWn9OzQT7UthAAAAMM"] [Tue Aug 18 13:03:26.272877 2026] [security2:error] [pid 123784:tid 124024] [client 168.62.48.100:1143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeRgAAAGo"] [Tue Aug 18 13:03:26.286469 2026] [security2:error] [pid 139043:tid 139269] [client 20.80.111.3:12517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSCTv2v-lWn9OzQT7UthwAAAOU"] [Tue Aug 18 13:03:26.306961 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:26.307231 2026] [authz_core:error] [pid 123784:tid 123871] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:26.363799 2026] [security2:error] [pid 139043:tid 139256] [client 20.65.98.162:21771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/inso.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtiQAAANg"] [Tue Aug 18 13:03:26.365047 2026] [security2:error] [pid 123784:tid 123924] [client 20.186.30.159:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/bajah.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeSQAAAAY"] [Tue Aug 18 13:03:26.367634 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.36.136:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtigAAAJA"] [Tue Aug 18 13:03:26.385401 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fa.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtiwAAAKk"] [Tue Aug 18 13:03:26.403141 2026] [security2:error] [pid 139043:tid 139109] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/inso.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtjAAAjUE"] [Tue Aug 18 13:03:26.405787 2026] [security2:error] [pid 139043:tid 139288] [client 4.232.151.198:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/import.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtjQAAAPg"] [Tue Aug 18 13:03:26.408751 2026] [security2:error] [pid 139043:tid 139254] [client 20.186.30.159:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/image2.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtjgAAANY"] [Tue Aug 18 13:03:26.410394 2026] [security2:error] [pid 139043:tid 139052] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/akismet.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtjwAAwAg"] [Tue Aug 18 13:03:26.429167 2026] [security2:error] [pid 139043:tid 139211] [client 20.51.153.15:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/do.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtkAAAAKs"] [Tue Aug 18 13:03:26.451442 2026] [security2:error] [pid 139043:tid 139190] [client 20.65.69.59:27882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mandrill.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtkQAAAJY"] [Tue Aug 18 13:03:26.461093 2026] [security2:error] [pid 139043:tid 139280] [client 213.35.127.232:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtkgAAAPA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:26.478103 2026] [security2:error] [pid 123784:tid 123998] [client 20.25.139.174:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeTAAAAFA"] [Tue Aug 18 13:03:26.490912 2026] [security2:error] [pid 123784:tid 123942] [client 40.74.65.169:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/puc.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeTQAAABg"] [Tue Aug 18 13:03:26.496865 2026] [security2:error] [pid 123784:tid 124042] [client 20.25.139.174:2191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wso.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeTgAAAHw"] [Tue Aug 18 13:03:26.519261 2026] [security2:error] [pid 139043:tid 139268] [client 132.196.30.78:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/edit.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtkwAAAOQ"] [Tue Aug 18 13:03:26.534340 2026] [security2:error] [pid 123784:tid 124020] [client 172.182.217.32:21552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/pomo/about.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeUAAAAGY"] [Tue Aug 18 13:03:26.586102 2026] [security2:error] [pid 123784:tid 123975] [client 20.206.73.37:44983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/coffee.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeUQAAADk"] [Tue Aug 18 13:03:26.596310 2026] [security2:error] [pid 123784:tid 124023] [client 20.206.73.37:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/sky.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeVAAAAGk"] [Tue Aug 18 13:03:26.602564 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:26.602854 2026] [authz_core:error] [pid 123784:tid 123806] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:26.608808 2026] [security2:error] [pid 123784:tid 123986] [client 40.74.65.169:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/doc.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeVQAAAEQ"] [Tue Aug 18 13:03:26.614762 2026] [security2:error] [pid 139043:tid 139226] [client 20.163.43.14:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/tes.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtlAAAALo"] [Tue Aug 18 13:03:26.644053 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/iz.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtlQAAAK8"] [Tue Aug 18 13:03:26.650002 2026] [security2:error] [pid 139043:tid 139253] [client 20.186.30.159:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/fb.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtlgAAANU"] [Tue Aug 18 13:03:26.665325 2026] [security2:error] [pid 139043:tid 139284] [client 20.186.30.159:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/domvf.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtlwAAAPQ"] [Tue Aug 18 13:03:26.686015 2026] [security2:error] [pid 139043:tid 139233] [client 168.62.48.100:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtmQAAAME"] [Tue Aug 18 13:03:26.689598 2026] [security2:error] [pid 123784:tid 124033] [client 4.232.151.198:47323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeWgAAAHM"] [Tue Aug 18 13:03:26.709718 2026] [security2:error] [pid 139043:tid 139238] [client 74.248.130.103:34977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/get.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtmwAAAMY"] [Tue Aug 18 13:03:26.713427 2026] [security2:error] [pid 139043:tid 139279] [client 20.65.69.59:63616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/main.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtnAAAAO8"] [Tue Aug 18 13:03:26.723048 2026] [security2:error] [pid 139043:tid 139095] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/aa.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtnwAA-zM"] [Tue Aug 18 13:03:26.732377 2026] [security2:error] [pid 139043:tid 139293] [client 20.51.153.15:9833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/yw.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtoAAAAP0"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:26.736325 2026] [fcgid:warn] [pid 139043:tid 139278] (104)Connection reset by peer: [client 103.168.66.229:51599] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:26.736340 2026] [core:error] [pid 139043:tid 139278] [client 103.168.66.229:51599] End of script output before headers: index.fcgi [Tue Aug 18 13:03:26.814832 2026] [security2:error] [pid 123784:tid 123939] [client 20.65.98.162:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/aa.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeYQAAABU"] [Tue Aug 18 13:03:26.823523 2026] [security2:error] [pid 139043:tid 139158] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/admin.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtogAAznI"] [Tue Aug 18 13:03:26.823893 2026] [security2:error] [pid 139043:tid 139286] [client 20.80.111.3:28190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtowAAAPY"] [Tue Aug 18 13:03:26.879529 2026] [security2:error] [pid 139043:tid 139285] [client 74.248.18.37:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/cong.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtpAAAAPU"] [Tue Aug 18 13:03:26.880623 2026] [security2:error] [pid 123784:tid 123964] [client 20.250.13.23:30815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeZAAAAC4"] [Tue Aug 18 13:03:26.905985 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:26.906425 2026] [authz_core:error] [pid 123784:tid 123883] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:26.926510 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/qr.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtpQAAAOE"] [Tue Aug 18 13:03:26.934717 2026] [security2:error] [pid 123784:tid 124025] [client 20.186.30.159:14239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/gi.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeZwAAAGs"] [Tue Aug 18 13:03:26.935480 2026] [security2:error] [pid 139043:tid 139219] [client 20.186.30.159:1697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/fpwch.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtpgAAALM"] [Tue Aug 18 13:03:26.957867 2026] [security2:error] [pid 139043:tid 139267] [client 20.163.43.14:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/files/index.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtpwAAAOM"] [Tue Aug 18 13:03:26.959084 2026] [security2:error] [pid 123784:tid 123982] [client 20.65.69.59:27878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ga.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeaAAAAEA"] [Tue Aug 18 13:03:26.985609 2026] [security2:error] [pid 139043:tid 139163] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/bajah.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtqQAAh3c"] [Tue Aug 18 13:03:26.985856 2026] [security2:error] [pid 139043:tid 139207] [client 20.118.133.132:7510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/puc.php"] [unique_id "aoSCTv2v-lWn9OzQT7UtqAAAAKc"] [Tue Aug 18 13:03:26.993531 2026] [security2:error] [pid 123784:tid 124021] [client 20.25.139.174:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/h.php"] [unique_id "aoSCTmwDnJBNj2tDbYYeagAAAGc"] [Tue Aug 18 13:03:27.021271 2026] [security2:error] [pid 139043:tid 139104] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/img.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtqwAA9zw"] [Tue Aug 18 13:03:27.025894 2026] [security2:error] [pid 123784:tid 124029] [client 172.182.217.32:21543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/updraft/about.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeawAAAG8"] [Tue Aug 18 13:03:27.044413 2026] [security2:error] [pid 123784:tid 123936] [client 20.25.139.174:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/zup.php73"] [unique_id "aoSCT2wDnJBNj2tDbYYebAAAABI"] [Tue Aug 18 13:03:27.045157 2026] [security2:error] [pid 139043:tid 139248] [client 158.23.17.4:9332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/fb.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtrQAAANA"] [Tue Aug 18 13:03:27.073561 2026] [security2:error] [pid 139043:tid 139225] [client 68.155.154.236:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/rezor.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtrgAAALk"] [Tue Aug 18 13:03:27.077326 2026] [security2:error] [pid 123784:tid 123991] [client 20.51.153.15:9854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/qh.php"] [unique_id "aoSCT2wDnJBNj2tDbYYebgAAAEk"] [Tue Aug 18 13:03:27.128123 2026] [security2:error] [pid 139043:tid 139244] [client 168.62.48.100:1131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtrwAAAMw"] [Tue Aug 18 13:03:27.130471 2026] [security2:error] [pid 123784:tid 123954] [client 4.232.151.198:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSCT2wDnJBNj2tDbYYecAAAACQ"] [Tue Aug 18 13:03:27.137460 2026] [security2:error] [pid 139043:tid 139090] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/ajax.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtsAAApC4"] [Tue Aug 18 13:03:27.161189 2026] [security2:error] [pid 139043:tid 139223] [client 20.206.73.37:17064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/admin.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtsQAAALc"] [Tue Aug 18 13:03:27.179599 2026] [security2:error] [pid 123784:tid 123807] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCT2wDnJBNj2tDbYYecgAAVBI"] [Tue Aug 18 13:03:27.179754 2026] [security2:error] [pid 123784:tid 124002] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCT2wDnJBNj2tDbYYecgAAVBI"] [Tue Aug 18 13:03:27.191680 2026] [security2:error] [pid 123784:tid 124031] [client 20.186.30.159:1670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/adminner.php"] [unique_id "aoSCT2wDnJBNj2tDbYYecwAAAHE"] [Tue Aug 18 13:03:27.193114 2026] [security2:error] [pid 123784:tid 123977] [client 20.65.98.162:21827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/img.php"] [unique_id "aoSCT2wDnJBNj2tDbYYedAAAADs"] [Tue Aug 18 13:03:27.193558 2026] [security2:error] [pid 139043:tid 139261] [client 158.23.17.4:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/x.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtsgAAAN0"] [Tue Aug 18 13:03:27.197187 2026] [security2:error] [pid 139043:tid 139281] [client 74.248.130.103:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/images.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtswAAAPE"] [Tue Aug 18 13:03:27.202831 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/se.php"] [unique_id "aoSCT_2v-lWn9OzQT7UttAAAAMM"] [Tue Aug 18 13:03:27.203234 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:27.203559 2026] [authz_core:error] [pid 123784:tid 123874] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:27.213262 2026] [security2:error] [pid 139043:tid 139222] [client 68.221.73.131:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/w.php"] [unique_id "aoSCT_2v-lWn9OzQT7UttQAAALY"] [Tue Aug 18 13:03:27.217401 2026] [security2:error] [pid 139043:tid 139236] [client 20.186.30.159:7247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/video.php"] [unique_id "aoSCT_2v-lWn9OzQT7UttgAAAMQ"] [Tue Aug 18 13:03:27.229481 2026] [security2:error] [pid 139043:tid 139221] [client 132.196.30.78:12468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ff1.php"] [unique_id "aoSCT_2v-lWn9OzQT7UttwAAALU"] [Tue Aug 18 13:03:27.246003 2026] [security2:error] [pid 139043:tid 139200] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/hello.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtuAAAAKA"] [Tue Aug 18 13:03:27.252649 2026] [security2:error] [pid 139043:tid 139184] [client 20.65.69.59:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/wb.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtuQAAAJA"] [Tue Aug 18 13:03:27.265338 2026] [security2:error] [pid 139043:tid 139201] [client 20.80.111.3:39930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/js/tinymce/themes/xmlrpc.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtugAAAKE"] [Tue Aug 18 13:03:27.297940 2026] [security2:error] [pid 139043:tid 139230] [client 20.79.204.6:9725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/155.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtuwAAAL4"] [Tue Aug 18 13:03:27.300601 2026] [security2:error] [pid 139043:tid 139060] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/222.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtvAAA8BA"] [Tue Aug 18 13:03:27.303735 2026] [security2:error] [pid 139043:tid 139264] [client 40.74.65.169:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/1337.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtvQAAAOA"] [Tue Aug 18 13:03:27.309795 2026] [security2:error] [pid 139043:tid 139159] [remote 20.203.183.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dtbbrasil.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtvgAA53M"] [Tue Aug 18 13:03:27.310464 2026] [security2:error] [pid 139043:tid 139262] [client 4.223.113.180:45293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/radio.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtvwAAAN4"] [Tue Aug 18 13:03:27.337669 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:9748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/r.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtwAAAAOQ"] [Tue Aug 18 13:03:27.348800 2026] [security2:error] [pid 139043:tid 139220] [client 20.163.43.14:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtwgAAALQ"] [Tue Aug 18 13:03:27.451355 2026] [security2:error] [pid 139043:tid 139279] [client 20.186.30.159:1920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/abcd.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtxQAAAO8"] [Tue Aug 18 13:03:27.465336 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtxwAAAP0"] [Tue Aug 18 13:03:27.473533 2026] [security2:error] [pid 139043:tid 139239] [client 213.35.127.232:64486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtyAAAAMc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:27.496053 2026] [security2:error] [pid 123784:tid 124013] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeewAAX2I"] [Tue Aug 18 13:03:27.501522 2026] [security2:error] [pid 139043:tid 139216] [client 20.186.30.159:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/hel.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtywAAALA"] [Tue Aug 18 13:03:27.503177 2026] [security2:error] [pid 123784:tid 124022] [client 20.25.139.174:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ms-edit.php"] [unique_id "aoSCT2wDnJBNj2tDbYYefQAAAGg"] [Tue Aug 18 13:03:27.504385 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:27.504650 2026] [authz_core:error] [pid 123784:tid 123801] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:27.513552 2026] [security2:error] [pid 123784:tid 124037] [client 74.248.18.37:55906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCT2wDnJBNj2tDbYYefgAAAHc"] [Tue Aug 18 13:03:27.519258 2026] [security2:error] [pid 139043:tid 139297] [client 172.182.217.32:21561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/upgrade-temp-backup/about.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtzAAAAQE"] [Tue Aug 18 13:03:27.531393 2026] [security2:error] [pid 139043:tid 139210] [client 20.65.69.59:9670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/xn.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtzQAAAKo"] [Tue Aug 18 13:03:27.581613 2026] [security2:error] [pid 139043:tid 139286] [client 20.51.153.15:9498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/17.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtzgAAAPY"] [Tue Aug 18 13:03:27.606789 2026] [security2:error] [pid 139043:tid 139270] [client 158.23.17.4:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gw.php"] [unique_id "aoSCT_2v-lWn9OzQT7UtzwAAAOY"] [Tue Aug 18 13:03:27.609578 2026] [security2:error] [pid 139043:tid 139294] [client 20.25.139.174:2477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/k.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut0AAAAP4"] [Tue Aug 18 13:03:27.623115 2026] [security2:error] [pid 139043:tid 139157] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/key.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut0QAA83E"] [Tue Aug 18 13:03:27.638196 2026] [security2:error] [pid 139043:tid 139213] [client 20.65.98.162:21762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/222.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut0gAAAK0"] [Tue Aug 18 13:03:27.658262 2026] [security2:error] [pid 123784:tid 123985] [client 4.232.151.198:48693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/bolt.php"] [unique_id "aoSCT2wDnJBNj2tDbYYegQAAAEM"] [Tue Aug 18 13:03:27.670501 2026] [security2:error] [pid 123784:tid 123953] [client 74.248.130.103:49004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/alls.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeggAAACM"] [Tue Aug 18 13:03:27.672104 2026] [security2:error] [pid 123784:tid 123932] [client 20.163.43.14:6580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/images/images/about.php"] [unique_id "aoSCT2wDnJBNj2tDbYYegwAAAA4"] [Tue Aug 18 13:03:27.689735 2026] [security2:error] [pid 123784:tid 123941] [client 213.202.253.4:65093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/delpaths.php"] [unique_id "aoSCT2wDnJBNj2tDbYYehAAAABc"], referer: www.google.com [Tue Aug 18 13:03:27.703392 2026] [security2:error] [pid 123784:tid 123921] [client 168.62.48.100:1095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCT2wDnJBNj2tDbYYehgAAAAM"] [Tue Aug 18 13:03:27.751555 2026] [security2:error] [pid 139043:tid 139208] [client 4.232.151.198:22226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ebs.php7"] [unique_id "aoSCT_2v-lWn9OzQT7Ut1gAAAKg"] [Tue Aug 18 13:03:27.770287 2026] [security2:error] [pid 123784:tid 123935] [client 20.186.30.159:1695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/simple.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeiAAAABE"] [Tue Aug 18 13:03:27.775967 2026] [security2:error] [pid 123784:tid 123957] [client 68.221.73.131:59404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/fpwch.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeiQAAACc"] [Tue Aug 18 13:03:27.784048 2026] [security2:error] [pid 139043:tid 139290] [client 20.186.30.159:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/grok.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut2AAAAPo"] [Tue Aug 18 13:03:27.794936 2026] [security2:error] [pid 123784:tid 124005] [client 20.65.69.59:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/47.php"] [unique_id "aoSCT2wDnJBNj2tDbYYeiwAAAFc"] [Tue Aug 18 13:03:27.859390 2026] [security2:error] [pid 139043:tid 139185] [client 20.80.111.3:5930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/load.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut2gAAAJE"] [Tue Aug 18 13:03:27.894360 2026] [security2:error] [pid 123784:tid 123930] [client 52.173.121.69:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/index/function.php"] [unique_id "aoSCT2wDnJBNj2tDbYYejQAAAAw"] [Tue Aug 18 13:03:27.924372 2026] [security2:error] [pid 139043:tid 139205] [client 20.116.17.175:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/css.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut3AAAAKU"] [Tue Aug 18 13:03:27.926447 2026] [security2:error] [pid 139043:tid 139047] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/chosen.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut3QAAvAM"] [Tue Aug 18 13:03:27.931893 2026] [security2:error] [pid 139043:tid 139229] [client 20.51.153.15:9495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ev.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut3gAAAL0"] [Tue Aug 18 13:03:27.994992 2026] [security2:error] [pid 123784:tid 123980] [client 20.163.43.14:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCT2wDnJBNj2tDbYYekAAAAD4"] [Tue Aug 18 13:03:27.999766 2026] [security2:error] [pid 123784:tid 124035] [client 40.74.65.169:55292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/Njima.php"] [unique_id "aoSCT2wDnJBNj2tDbYYekQAAAHU"] [Tue Aug 18 13:03:27.999805 2026] [security2:error] [pid 139043:tid 139199] [client 20.250.13.23:30814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSCT_2v-lWn9OzQT7Ut3wAAAJ8"] [Tue Aug 18 13:03:28.006311 2026] [security2:error] [pid 123784:tid 123973] [client 20.25.139.174:4486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/a7.php"] [unique_id "aoSCUGwDnJBNj2tDbYYekwAAADc"] [Tue Aug 18 13:03:28.007960 2026] [security2:error] [pid 139043:tid 139296] [client 158.23.17.4:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/sw.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut4AAAAQA"] [Tue Aug 18 13:03:28.011511 2026] [security2:error] [pid 139043:tid 139217] [client 172.182.217.32:21559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/images/about.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut4QAAALE"] [Tue Aug 18 13:03:28.019656 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:28.020097 2026] [authz_core:error] [pid 123784:tid 123913] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:28.062832 2026] [security2:error] [pid 123784:tid 123924] [client 20.65.69.59:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/payout.php"] [unique_id "aoSCUGwDnJBNj2tDbYYelQAAAAY"] [Tue Aug 18 13:03:28.073487 2026] [security2:error] [pid 123784:tid 124004] [client 20.186.30.159:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/indes.php"] [unique_id "aoSCUGwDnJBNj2tDbYYelgAAAFY"] [Tue Aug 18 13:03:28.092405 2026] [security2:error] [pid 123784:tid 124008] [client 132.196.30.78:6311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/fff.php"] [unique_id "aoSCUGwDnJBNj2tDbYYemAAAAFo"] [Tue Aug 18 13:03:28.096535 2026] [security2:error] [pid 123784:tid 124038] [client 20.186.30.159:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCUGwDnJBNj2tDbYYemgAAAHg"] [Tue Aug 18 13:03:28.110464 2026] [security2:error] [pid 123784:tid 123943] [client 20.65.98.162:21763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/key.php"] [unique_id "aoSCUGwDnJBNj2tDbYYemwAAABk"] [Tue Aug 18 13:03:28.131873 2026] [security2:error] [pid 123784:tid 123937] [client 168.62.48.100:1223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCUGwDnJBNj2tDbYYenAAAABM"] [Tue Aug 18 13:03:28.146275 2026] [security2:error] [pid 139043:tid 139202] [client 74.248.18.37:55879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/db.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut5AAAAKI"] [Tue Aug 18 13:03:28.195454 2026] [security2:error] [pid 123784:tid 123972] [client 20.25.139.174:2212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCUGwDnJBNj2tDbYYengAAADY"] [Tue Aug 18 13:03:28.219385 2026] [security2:error] [pid 139043:tid 139063] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/wpxml.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut5gAAwBM"] [Tue Aug 18 13:03:28.294061 2026] [security2:error] [pid 123784:tid 123938] [client 20.80.111.3:5942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/login.php"] [unique_id "aoSCUGwDnJBNj2tDbYYeogAAABQ"] [Tue Aug 18 13:03:28.307467 2026] [security2:error] [pid 123784:tid 123951] [client 20.51.153.15:9481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xs.php"] [unique_id "aoSCUGwDnJBNj2tDbYYeowAAACE"] [Tue Aug 18 13:03:28.319027 2026] [security2:error] [pid 123784:tid 123962] [client 20.163.43.14:6641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/rip.php"] [unique_id "aoSCUGwDnJBNj2tDbYYepQAAACw"] [Tue Aug 18 13:03:28.327086 2026] [security2:error] [pid 139043:tid 139264] [client 20.186.30.159:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut6AAAAOA"] [Tue Aug 18 13:03:28.330058 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:28.330496 2026] [authz_core:error] [pid 123784:tid 123823] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:28.333405 2026] [security2:error] [pid 139043:tid 139271] [client 20.226.36.136:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut6QAAAOc"] [Tue Aug 18 13:03:28.335013 2026] [security2:error] [pid 123784:tid 123964] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/brc.php"] [unique_id "aoSCUGwDnJBNj2tDbYYepgAAAC4"] [Tue Aug 18 13:03:28.339737 2026] [security2:error] [pid 139043:tid 139192] [client 20.186.30.159:1679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/xiugai.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut6gAAAJg"] [Tue Aug 18 13:03:28.351443 2026] [security2:error] [pid 139043:tid 139251] [client 20.65.69.59:5396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/bh.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut6wAAANM"] [Tue Aug 18 13:03:28.405495 2026] [security2:error] [pid 123784:tid 123975] [client 4.232.151.198:22209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/include/Lurd.class.php"] [unique_id "aoSCUGwDnJBNj2tDbYYeqQAAADk"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:28.409065 2026] [fcgid:warn] [pid 123784:tid 124043] (104)Connection reset by peer: [client 103.168.66.229:51843] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:28.409084 2026] [core:error] [pid 123784:tid 124043] [client 103.168.66.229:51843] End of script output before headers: index.fcgi [Tue Aug 18 13:03:28.456650 2026] [security2:error] [pid 123784:tid 123961] [client 74.7.175.174:60638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tivinalili.com.br"] [uri "/index.php"] [unique_id "aoSCUGwDnJBNj2tDbYYeqAAAKzs"] [Tue Aug 18 13:03:28.497821 2026] [security2:error] [pid 123784:tid 124034] [client 213.35.127.232:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCUGwDnJBNj2tDbYYeqwAAAHQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:28.500858 2026] [security2:error] [pid 139043:tid 139262] [client 172.182.217.32:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut7QAAAN4"] [Tue Aug 18 13:03:28.507041 2026] [security2:error] [pid 123784:tid 123928] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "store.3xsolutions.com.br"] [uri "/index.php"] [unique_id "aoSCUGwDnJBNj2tDbYYepwAACnU"] [Tue Aug 18 13:03:28.537794 2026] [security2:error] [pid 139043:tid 139291] [client 158.23.17.4:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gc.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut7gAAAPs"] [Tue Aug 18 13:03:28.540644 2026] [security2:error] [pid 139043:tid 139250] [client 20.206.73.37:11917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/file5.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut7wAAANI"] [Tue Aug 18 13:03:28.541257 2026] [security2:error] [pid 139043:tid 139240] [client 20.25.139.174:4537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/manager.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut8AAAAMg"] [Tue Aug 18 13:03:28.549846 2026] [security2:error] [pid 139043:tid 139145] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/file1221.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut8QAAx2U"] [Tue Aug 18 13:03:28.562673 2026] [security2:error] [pid 139043:tid 139278] [client 20.51.153.15:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/lmfi2.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut8wAAAO4"] [Tue Aug 18 13:03:28.595510 2026] [security2:error] [pid 139043:tid 139237] [client 20.52.168.85:5308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/aged.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut9AAAAMU"] [Tue Aug 18 13:03:28.596081 2026] [security2:error] [pid 139043:tid 139249] [client 4.223.113.180:41382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut9QAAANE"] [Tue Aug 18 13:03:28.602253 2026] [security2:error] [pid 139043:tid 139241] [client 20.186.30.159:7238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/bs1.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut9gAAAMk"] [Tue Aug 18 13:03:28.605057 2026] [security2:error] [pid 139043:tid 139210] [client 20.186.30.159:1975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/wp-load.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut-AAAAKo"] [Tue Aug 18 13:03:28.611324 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.87:23524] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:28.611444 2026] [security2:error] [pid 139043:tid 139193] [client 20.65.69.59:27895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/ct.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut-QAAAJk"] [Tue Aug 18 13:03:28.611593 2026] [authz_core:error] [pid 139043:tid 139147] [remote 57.141.22.87:23524] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:28.613692 2026] [security2:error] [pid 139043:tid 139257] [client 20.226.36.136:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut-gAAANk"] [Tue Aug 18 13:03:28.632277 2026] [security2:error] [pid 139043:tid 139283] [client 68.221.73.131:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut-wAAAPM"] [Tue Aug 18 13:03:28.716192 2026] [security2:error] [pid 139043:tid 139267] [client 40.74.65.169:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCUP2v-lWn9OzQT7Ut_QAAAOM"] [Tue Aug 18 13:03:28.735545 2026] [security2:error] [pid 139043:tid 139260] [client 20.80.111.3:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/min.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuAAAAANw"] [Tue Aug 18 13:03:28.752262 2026] [security2:error] [pid 139043:tid 139293] [client 20.250.13.23:30820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/index.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuAQAAAP0"] [Tue Aug 18 13:03:28.800521 2026] [security2:error] [pid 123784:tid 123997] [client 20.52.168.85:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/essexec.php"] [unique_id "aoSCUGwDnJBNj2tDbYYerQAAAE8"] [Tue Aug 18 13:03:28.803983 2026] [security2:error] [pid 139043:tid 139179] [client 74.248.18.37:3740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/dropdown.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuAwAAAIs"] [Tue Aug 18 13:03:28.804668 2026] [security2:error] [pid 139043:tid 139225] [client 20.51.153.15:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fd.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuBAAAALk"] [Tue Aug 18 13:03:28.807858 2026] [security2:error] [pid 139043:tid 139205] [client 168.62.48.100:1256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuBQAAAKU"] [Tue Aug 18 13:03:28.834859 2026] [security2:error] [pid 139043:tid 139123] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/nox.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuBgAAzE8"] [Tue Aug 18 13:03:28.856506 2026] [security2:error] [pid 139043:tid 139223] [client 20.65.69.59:59227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/gy.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuBwAAALc"] [Tue Aug 18 13:03:28.872952 2026] [security2:error] [pid 139043:tid 139217] [client 20.186.30.159:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/hp2.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuCQAAALE"] [Tue Aug 18 13:03:28.882849 2026] [security2:error] [pid 139043:tid 139231] [client 132.196.30.78:1624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/inputs.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuCgAAAL8"] [Tue Aug 18 13:03:28.906706 2026] [security2:error] [pid 139043:tid 139236] [client 20.65.98.162:21774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/chosen.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuDAAAAMQ"] [Tue Aug 18 13:03:28.921034 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:28.921285 2026] [authz_core:error] [pid 123784:tid 123890] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:28.928675 2026] [security2:error] [pid 139043:tid 139212] [client 20.186.30.159:1973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/155.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuDQAAAKw"] [Tue Aug 18 13:03:28.973910 2026] [security2:error] [pid 139043:tid 139288] [client 20.163.43.14:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuGAAAAPg"] [Tue Aug 18 13:03:28.996033 2026] [security2:error] [pid 139043:tid 139229] [client 172.182.217.32:21550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/about.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuGgAAAL0"] [Tue Aug 18 13:03:29.004409 2026] [security2:error] [pid 139043:tid 139173] [client 40.74.65.169:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/inso.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuHAAAAIU"] [Tue Aug 18 13:03:29.005829 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:47132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/uq.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuHQAAANg"] [Tue Aug 18 13:03:29.027897 2026] [security2:error] [pid 139043:tid 139228] [client 4.232.151.198:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuHgAAALw"] [Tue Aug 18 13:03:29.039767 2026] [security2:error] [pid 123784:tid 124039] [client 20.226.36.136:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCUWwDnJBNj2tDbYYesAAAAHk"] [Tue Aug 18 13:03:29.073330 2026] [security2:error] [pid 139043:tid 139275] [client 20.25.139.174:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/w1.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuIQAAAOs"] [Tue Aug 18 13:03:29.126456 2026] [security2:error] [pid 139043:tid 139234] [client 20.65.69.59:12090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/tt.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuJAAAAMI"] [Tue Aug 18 13:03:29.127144 2026] [security2:error] [pid 139043:tid 139242] [client 20.186.30.159:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/yb.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuJQAAAMo"] [Tue Aug 18 13:03:29.153232 2026] [security2:error] [pid 139043:tid 139079] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/akismet.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuKQAAxiM"] [Tue Aug 18 13:03:29.170205 2026] [security2:error] [pid 139043:tid 139239] [client 74.248.130.103:48989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/coffexium.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuKwAAAMc"] [Tue Aug 18 13:03:29.179852 2026] [security2:error] [pid 139043:tid 139192] [client 20.80.111.3:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/options.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuLQAAAJg"] [Tue Aug 18 13:03:29.181539 2026] [security2:error] [pid 139043:tid 139237] [client 20.51.153.15:8280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/info2.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuLgAAAMU"] [Tue Aug 18 13:03:29.187693 2026] [security2:error] [pid 123784:tid 123993] [client 20.186.30.159:1705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/index.php"] [unique_id "aoSCUWwDnJBNj2tDbYYesQAAAEs"] [Tue Aug 18 13:03:29.210972 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:1081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuLwAAAMk"] [Tue Aug 18 13:03:29.223858 2026] [security2:error] [pid 139043:tid 139151] [remote 74.7.230.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.230.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "store.3xsolutions.com.br"] [uri "/wp-login.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuCwAA7Gs"], referer: https://store.3xsolutions.com.br/robots.txt [Tue Aug 18 13:03:29.224184 2026] [security2:error] [pid 139043:tid 139276] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "store.3xsolutions.com.br"] [uri "/wp-login.php"] [unique_id "aoSCUP2v-lWn9OzQT7UuCwAA7Gs"], referer: https://store.3xsolutions.com.br/robots.txt [Tue Aug 18 13:03:29.227404 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:29.227808 2026] [authz_core:error] [pid 123784:tid 123886] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:29.239360 2026] [security2:error] [pid 139043:tid 139266] [client 149.34.210.141:49361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuMgAAAOI"] [Tue Aug 18 13:03:29.257962 2026] [security2:error] [pid 139043:tid 139213] [client 158.23.17.4:20373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/dirs.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuNAAAAK0"] [Tue Aug 18 13:03:29.332427 2026] [security2:error] [pid 139043:tid 139187] [client 20.25.139.174:2235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/ww5.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuNwAAAJM"] [Tue Aug 18 13:03:29.376361 2026] [security2:error] [pid 139043:tid 139298] [client 20.163.43.14:6621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/moon.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuOQAAAQI"] [Tue Aug 18 13:03:29.382465 2026] [security2:error] [pid 139043:tid 139260] [client 20.65.69.59:5395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/mq.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuPAAAANw"] [Tue Aug 18 13:03:29.390970 2026] [security2:error] [pid 139043:tid 139224] [client 40.74.65.169:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/too.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuPQAAALg"] [Tue Aug 18 13:03:29.405592 2026] [security2:error] [pid 123784:tid 124014] [client 158.23.17.4:10944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/32.php"] [unique_id "aoSCUWwDnJBNj2tDbYYeswAAAGA"] [Tue Aug 18 13:03:29.405803 2026] [security2:error] [pid 139043:tid 139249] [client 20.52.168.85:5123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/fw.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuPgAAANE"] [Tue Aug 18 13:03:29.425342 2026] [security2:error] [pid 139043:tid 139207] [client 20.51.153.15:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sx.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuPwAAAKc"] [Tue Aug 18 13:03:29.436333 2026] [security2:error] [pid 139043:tid 139263] [client 68.221.73.131:61608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/blurbs.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuQAAAAN8"] [Tue Aug 18 13:03:29.438487 2026] [security2:error] [pid 123784:tid 123969] [client 68.155.154.236:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCUWwDnJBNj2tDbYYetAAAADM"] [Tue Aug 18 13:03:29.438698 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/yn.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuQQAAAIs"] [Tue Aug 18 13:03:29.442809 2026] [security2:error] [pid 139043:tid 139225] [client 20.186.30.159:7261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/vc.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuQgAAALk"] [Tue Aug 18 13:03:29.443861 2026] [security2:error] [pid 139043:tid 139067] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/admin.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuRAAApRc"] [Tue Aug 18 13:03:29.445619 2026] [security2:error] [pid 139043:tid 139193] [client 74.248.18.37:3414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/file.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuRQAAAJk"] [Tue Aug 18 13:03:29.449767 2026] [security2:error] [pid 139043:tid 139204] [client 68.155.156.252:26690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuRwAAAKQ"] [Tue Aug 18 13:03:29.490783 2026] [security2:error] [pid 123784:tid 124019] [client 20.186.30.159:1696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/aaa.php"] [unique_id "aoSCUWwDnJBNj2tDbYYetQAAAGU"] [Tue Aug 18 13:03:29.504577 2026] [security2:error] [pid 139043:tid 139227] [client 172.182.217.32:21563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cgi-bin/about.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuSQAAALs"] [Tue Aug 18 13:03:29.505299 2026] [security2:error] [pid 139043:tid 139266] [client 149.34.210.141:49361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuMgAAAOI"] [Tue Aug 18 13:03:29.505782 2026] [security2:error] [pid 139043:tid 139292] [client 168.62.48.100:1051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuSgAAAPw"] [Tue Aug 18 13:03:29.515548 2026] [security2:error] [pid 123784:tid 123995] [client 213.35.127.232:64904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCUWwDnJBNj2tDbYYetgAAAE0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:29.524830 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:29.525129 2026] [authz_core:error] [pid 123784:tid 123840] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:29.540129 2026] [security2:error] [pid 139043:tid 139281] [client 52.173.121.69:62225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuTAAAAPE"] [Tue Aug 18 13:03:29.563350 2026] [security2:error] [pid 123784:tid 124009] [client 20.65.98.162:21799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/wpxml.php"] [unique_id "aoSCUWwDnJBNj2tDbYYeuAAAAFs"] [Tue Aug 18 13:03:29.615507 2026] [security2:error] [pid 139043:tid 139202] [client 20.250.13.23:3465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuTgAAAKI"] [Tue Aug 18 13:03:29.627414 2026] [security2:error] [pid 139043:tid 139188] [client 20.226.36.136:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuUAAAAJQ"] [Tue Aug 18 13:03:29.627430 2026] [security2:error] [pid 123784:tid 123979] [client 20.80.111.3:12543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/plugin-install.php"] [unique_id "aoSCUWwDnJBNj2tDbYYeugAAAD0"] [Tue Aug 18 13:03:29.646523 2026] [security2:error] [pid 139043:tid 139254] [client 20.65.69.59:27874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/13.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuUQAAANY"] [Tue Aug 18 13:03:29.655851 2026] [security2:error] [pid 139043:tid 139244] [client 4.232.151.198:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/lite.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuUgAAAMw"] [Tue Aug 18 13:03:29.662120 2026] [security2:error] [pid 139043:tid 139229] [client 20.51.153.15:9590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nu.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuUwAAAL0"] [Tue Aug 18 13:03:29.664495 2026] [security2:error] [pid 123784:tid 123953] [client 74.248.130.103:57005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/red.php"] [unique_id "aoSCUWwDnJBNj2tDbYYevAAAACM"] [Tue Aug 18 13:03:29.706387 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:10593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vp.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuVQAAAJY"] [Tue Aug 18 13:03:29.707600 2026] [security2:error] [pid 139043:tid 139280] [client 20.186.30.159:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/pema.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuVgAAAPA"] [Tue Aug 18 13:03:29.720432 2026] [security2:error] [pid 139043:tid 139177] [client 20.163.43.14:5495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/cache.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuWAAAAIk"] [Tue Aug 18 13:03:29.736226 2026] [security2:error] [pid 123784:tid 123921] [client 20.186.30.159:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCUWwDnJBNj2tDbYYevQAAAAM"] [Tue Aug 18 13:03:29.743588 2026] [security2:error] [pid 139043:tid 139130] [remote 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paypix.co"] [uri "/ajax.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuWQAA6FY"] [Tue Aug 18 13:03:29.812455 2026] [security2:error] [pid 139043:tid 139206] [client 168.62.48.100:1228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuXAAAAKY"] [Tue Aug 18 13:03:29.823526 2026] [security2:error] [pid 139043:tid 139234] [client 158.23.17.4:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/73.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuXQAAAMI"] [Tue Aug 18 13:03:29.823890 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:29.824143 2026] [authz_core:error] [pid 123784:tid 123838] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:29.825295 2026] [security2:error] [pid 123784:tid 124010] [client 20.25.139.174:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-login.php"] [unique_id "aoSCUWwDnJBNj2tDbYYevwAAAFw"] [Tue Aug 18 13:03:29.831673 2026] [security2:error] [pid 123784:tid 123935] [client 191.237.254.161:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/82.php"] [unique_id "aoSCUWwDnJBNj2tDbYYewAAAABE"] [Tue Aug 18 13:03:29.832680 2026] [security2:error] [pid 139043:tid 139194] [client 158.23.17.4:15773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sn.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuXgAAAJo"] [Tue Aug 18 13:03:29.842485 2026] [security2:error] [pid 123784:tid 124013] [client 20.79.204.6:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/96i.php"] [unique_id "aoSCUWwDnJBNj2tDbYYewQAAAF8"] [Tue Aug 18 13:03:29.872405 2026] [security2:error] [pid 139043:tid 139251] [client 20.65.98.162:21869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/file1221.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuXwAAANM"] [Tue Aug 18 13:03:29.876032 2026] [security2:error] [pid 139043:tid 139264] [client 20.25.139.174:2184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/2.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuYAAAAOA"] [Tue Aug 18 13:03:29.890205 2026] [security2:error] [pid 139043:tid 139241] [client 20.116.17.175:54874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuYQAAAMk"] [Tue Aug 18 13:03:29.892321 2026] [security2:error] [pid 139043:tid 139210] [client 20.51.153.15:9736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ko.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuYgAAAKo"] [Tue Aug 18 13:03:29.895923 2026] [security2:error] [pid 139043:tid 139276] [client 132.196.30.78:12719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuYwAAAOw"] [Tue Aug 18 13:03:29.902390 2026] [security2:error] [pid 139043:tid 139257] [client 20.65.69.59:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/so.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuZQAAANk"] [Tue Aug 18 13:03:29.994817 2026] [security2:error] [pid 123784:tid 123918] [client 20.186.30.159:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/site.php"] [unique_id "aoSCUWwDnJBNj2tDbYYewgAAAAA"] [Tue Aug 18 13:03:29.995327 2026] [security2:error] [pid 139043:tid 139242] [client 172.182.217.32:21869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/gallery/about.php"] [unique_id "aoSCUf2v-lWn9OzQT7UuZwAAAMo"] [Tue Aug 18 13:03:30.006153 2026] [security2:error] [pid 139043:tid 139195] [client 20.52.168.85:5250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/zwso.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuaAAAAJs"] [Tue Aug 18 13:03:30.060292 2026] [security2:error] [pid 139043:tid 139212] [client 114.119.136.146:55283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "savvyoffshore.com.br"] [uri "/images/produtos/INTERFACE%20ROV%20PARA%20TORQUE%20MEDIO%20%28IFTM%29.png"] [unique_id "aoSCUv2v-lWn9OzQT7UuawAAAKw"], referer: https://savvyoffshore.com.br/pt/produtos/produtos/122-interface-rov-para-torque-medio-iftm.html [Tue Aug 18 13:03:30.062851 2026] [security2:error] [pid 123784:tid 124045] [client 20.186.30.159:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/sh.php"] [unique_id "aoSCUmwDnJBNj2tDbYYexAAAAH8"] [Tue Aug 18 13:03:30.100785 2026] [security2:error] [pid 139043:tid 139260] [client 40.74.65.169:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.r3telhas.com.br"] [uri "/g3.php"] [unique_id "aoSCUv2v-lWn9OzQT7UubQAAANw"] [Tue Aug 18 13:03:30.106179 2026] [security2:error] [pid 139043:tid 139176] [client 4.232.151.198:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCUv2v-lWn9OzQT7UubwAAAIg"] [Tue Aug 18 13:03:30.128749 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:30.129187 2026] [authz_core:error] [pid 123784:tid 123821] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:30.129351 2026] [security2:error] [pid 139043:tid 139299] [client 20.80.111.3:18116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/radio.php"] [unique_id "aoSCUv2v-lWn9OzQT7UucAAAAQM"] [Tue Aug 18 13:03:30.137806 2026] [security2:error] [pid 139043:tid 139278] [client 74.248.18.37:3408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/goods.php"] [unique_id "aoSCUv2v-lWn9OzQT7UucQAAAO4"] [Tue Aug 18 13:03:30.158856 2026] [security2:error] [pid 123784:tid 123960] [client 20.65.69.59:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/10.php"] [unique_id "aoSCUmwDnJBNj2tDbYYexgAAACo"] [Tue Aug 18 13:03:30.180363 2026] [security2:error] [pid 139043:tid 139253] [client 168.62.48.100:1217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCUv2v-lWn9OzQT7UucwAAANU"] [Tue Aug 18 13:03:30.206403 2026] [security2:error] [pid 139043:tid 139220] [client 68.221.73.131:65367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/100.php"] [unique_id "aoSCUv2v-lWn9OzQT7UudAAAALQ"] [Tue Aug 18 13:03:30.252496 2026] [security2:error] [pid 123784:tid 123945] [client 20.51.153.15:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/pl.php"] [unique_id "aoSCUmwDnJBNj2tDbYYeyAAAABs"] [Tue Aug 18 13:03:30.262851 2026] [security2:error] [pid 139043:tid 139263] [client 20.186.30.159:1719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/ccc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UudgAAAN8"] [Tue Aug 18 13:03:30.266002 2026] [security2:error] [pid 139043:tid 139179] [client 20.65.98.162:21785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/nox.php"] [unique_id "aoSCUv2v-lWn9OzQT7UudwAAAIs"] [Tue Aug 18 13:03:30.266272 2026] [security2:error] [pid 139043:tid 139183] [client 20.250.13.23:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCUv2v-lWn9OzQT7UueAAAAI8"] [Tue Aug 18 13:03:30.274023 2026] [security2:error] [pid 123784:tid 123989] [client 157.20.138.62:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUmwDnJBNj2tDbYYeyQAAAEc"] [Tue Aug 18 13:03:30.274139 2026] [security2:error] [pid 123784:tid 123989] [client 157.20.138.62:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUmwDnJBNj2tDbYYeyQAAAEc"] [Tue Aug 18 13:03:30.279069 2026] [security2:error] [pid 139043:tid 139240] [client 4.232.151.198:41099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSCUv2v-lWn9OzQT7UuegAAAMg"] [Tue Aug 18 13:03:30.286071 2026] [security2:error] [pid 139043:tid 139165] [remote 129.121.103.155:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deliciasdaisa.com.br"] [uri "/wp-login.php"] [unique_id "aoSCUv2v-lWn9OzQT7UufAAAk3k"] [Tue Aug 18 13:03:30.311875 2026] [security2:error] [pid 139043:tid 139233] [client 4.232.151.198:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/0x.php"] [unique_id "aoSCUv2v-lWn9OzQT7UufQAAAME"] [Tue Aug 18 13:03:30.341002 2026] [security2:error] [pid 139043:tid 139217] [client 20.151.109.219:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ph.php"] [unique_id "aoSCUv2v-lWn9OzQT7UufgAAALE"] [Tue Aug 18 13:03:30.366181 2026] [security2:error] [pid 139043:tid 139293] [client 20.25.139.174:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/default.php"] [unique_id "aoSCUv2v-lWn9OzQT7UugAAAAP0"] [Tue Aug 18 13:03:30.406603 2026] [security2:error] [pid 139043:tid 139180] [client 20.65.69.59:51757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/te.php"] [unique_id "aoSCUv2v-lWn9OzQT7UugQAAAIw"] [Tue Aug 18 13:03:30.409895 2026] [security2:error] [pid 139043:tid 139191] [client 158.23.17.4:9340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ib.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuggAAAJc"] [Tue Aug 18 13:03:30.419413 2026] [security2:error] [pid 139043:tid 139200] [client 132.196.30.78:23792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/lite.php"] [unique_id "aoSCUv2v-lWn9OzQT7UugwAAAKA"] [Tue Aug 18 13:03:30.427761 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:30.428183 2026] [authz_core:error] [pid 123784:tid 123901] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:30.437522 2026] [security2:error] [pid 139043:tid 139248] [client 20.25.139.174:2376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuhAAAANA"] [Tue Aug 18 13:03:30.441248 2026] [security2:error] [pid 123784:tid 123963] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/file52.php"] [unique_id "aoSCUmwDnJBNj2tDbYYezAAAAC0"] [Tue Aug 18 13:03:30.458756 2026] [security2:error] [pid 139043:tid 139288] [client 20.186.30.159:7273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/button.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuhwAAAPg"] [Tue Aug 18 13:03:30.465535 2026] [security2:error] [pid 139043:tid 139254] [client 68.155.154.236:8367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuiQAAANY"] [Tue Aug 18 13:03:30.484527 2026] [security2:error] [pid 139043:tid 139261] [client 20.51.153.15:9575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/env.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuigAAAN0"] [Tue Aug 18 13:03:30.485225 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.217.32:21536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuiwAAAQA"] [Tue Aug 18 13:03:30.507571 2026] [security2:error] [pid 123784:tid 123988] [client 138.36.100.162:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUmwDnJBNj2tDbYYezQAAAEY"] [Tue Aug 18 13:03:30.507663 2026] [security2:error] [pid 123784:tid 123988] [client 138.36.100.162:42628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUmwDnJBNj2tDbYYezQAAAEY"] [Tue Aug 18 13:03:30.515589 2026] [security2:error] [pid 139043:tid 139256] [client 168.62.48.100:1123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCUv2v-lWn9OzQT7UujAAAANg"] [Tue Aug 18 13:03:30.515606 2026] [security2:error] [pid 139043:tid 139222] [client 20.186.30.159:1694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/admin.php"] [unique_id "aoSCUv2v-lWn9OzQT7UujQAAALY"] [Tue Aug 18 13:03:30.526069 2026] [security2:error] [pid 139043:tid 139192] [client 103.120.71.157:33089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UujgAAAJg"] [Tue Aug 18 13:03:30.526158 2026] [security2:error] [pid 139043:tid 139192] [client 103.120.71.157:33089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UujgAAAJg"] [Tue Aug 18 13:03:30.526759 2026] [security2:error] [pid 139043:tid 139245] [client 68.155.156.252:39441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCUv2v-lWn9OzQT7UujwAAAM0"] [Tue Aug 18 13:03:30.532909 2026] [security2:error] [pid 123784:tid 123947] [client 213.35.127.232:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCUmwDnJBNj2tDbYYezgAAAB0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:30.543142 2026] [security2:error] [pid 123784:tid 124020] [client 158.23.17.4:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/43.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe0AAAAGY"] [Tue Aug 18 13:03:30.590658 2026] [security2:error] [pid 139043:tid 139181] [client 20.80.111.3:12493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/random_compat/bala.php"] [unique_id "aoSCUv2v-lWn9OzQT7UukgAAAI0"] [Tue Aug 18 13:03:30.593244 2026] [security2:error] [pid 123784:tid 123984] [client 20.65.98.162:21790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/akismet.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe0QAAAEI"] [Tue Aug 18 13:03:30.616116 2026] [security2:error] [pid 139043:tid 139221] [client 20.52.168.85:5267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/term.php"] [unique_id "aoSCUv2v-lWn9OzQT7UulAAAALU"] [Tue Aug 18 13:03:30.647091 2026] [security2:error] [pid 139043:tid 139194] [client 20.206.73.37:11936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/xyn.php"] [unique_id "aoSCUv2v-lWn9OzQT7UulgAAAJo"] [Tue Aug 18 13:03:30.677903 2026] [security2:error] [pid 123784:tid 123976] [client 20.65.69.59:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/kc.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe0wAAADo"] [Tue Aug 18 13:03:30.678172 2026] [security2:error] [pid 123784:tid 123858] [remote 203.99.146.53:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe0gAAPkU"] [Tue Aug 18 13:03:30.721388 2026] [security2:error] [pid 139043:tid 139208] [client 178.153.171.161:20671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UumQAAAKg"] [Tue Aug 18 13:03:30.721501 2026] [security2:error] [pid 139043:tid 139208] [client 178.153.171.161:20671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UumQAAAKg"] [Tue Aug 18 13:03:30.722543 2026] [security2:error] [pid 139043:tid 139251] [client 52.173.121.69:31594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCUv2v-lWn9OzQT7UumgAAANM"] [Tue Aug 18 13:03:30.725972 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:30.726217 2026] [authz_core:error] [pid 123784:tid 123814] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:30.727364 2026] [security2:error] [pid 139043:tid 139137] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UumwAAlF0"] [Tue Aug 18 13:03:30.728375 2026] [security2:error] [pid 139043:tid 139188] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UumwAAlF0"] [Tue Aug 18 13:03:30.728807 2026] [security2:error] [pid 139043:tid 139241] [client 20.51.153.15:8275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mz.php"] [unique_id "aoSCUv2v-lWn9OzQT7UunQAAAMk"] [Tue Aug 18 13:03:30.759945 2026] [security2:error] [pid 139043:tid 139267] [client 20.186.30.159:14228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/wlc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UungAAAOM"] [Tue Aug 18 13:03:30.767799 2026] [security2:error] [pid 139043:tid 139203] [client 74.248.18.37:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCUv2v-lWn9OzQT7UunwAAAKM"] [Tue Aug 18 13:03:30.773996 2026] [security2:error] [pid 139043:tid 139272] [client 20.79.204.6:9679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/as.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuoAAAAOg"] [Tue Aug 18 13:03:30.835252 2026] [security2:error] [pid 139043:tid 139195] [client 168.62.48.100:1024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCUv2v-lWn9OzQT7UuogAAAJs"] [Tue Aug 18 13:03:30.859776 2026] [security2:error] [pid 139043:tid 139273] [client 68.221.73.131:59454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/ccc.php"] [unique_id "aoSCUv2v-lWn9OzQT7UupAAAAOk"] [Tue Aug 18 13:03:30.875381 2026] [security2:error] [pid 139043:tid 139252] [client 20.186.30.159:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/reviall.php"] [unique_id "aoSCUv2v-lWn9OzQT7UupgAAANQ"] [Tue Aug 18 13:03:30.899777 2026] [security2:error] [pid 123784:tid 124033] [client 20.25.139.174:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/i.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe1wAAAHM"] [Tue Aug 18 13:03:30.910654 2026] [security2:error] [pid 139043:tid 139279] [client 4.232.151.198:10462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/alfa-rex1.php"] [unique_id "aoSCUv2v-lWn9OzQT7UurQAAAO8"] [Tue Aug 18 13:03:30.921699 2026] [security2:error] [pid 139043:tid 139176] [client 20.65.69.59:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/jn.php"] [unique_id "aoSCUv2v-lWn9OzQT7UurgAAAIg"] [Tue Aug 18 13:03:30.929888 2026] [security2:error] [pid 139043:tid 139230] [client 158.23.17.4:8718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xm.php"] [unique_id "aoSCUv2v-lWn9OzQT7UurwAAAL4"] [Tue Aug 18 13:03:30.950240 2026] [security2:error] [pid 139043:tid 139257] [client 4.232.151.198:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/222.php"] [unique_id "aoSCUv2v-lWn9OzQT7UusAAAANk"] [Tue Aug 18 13:03:30.965328 2026] [security2:error] [pid 123784:tid 123964] [client 40.74.65.169:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/aa.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe2gAAAC4"] [Tue Aug 18 13:03:30.968972 2026] [security2:error] [pid 123784:tid 123933] [client 20.51.153.15:9746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ft.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe2wAAAA8"] [Tue Aug 18 13:03:30.969685 2026] [security2:error] [pid 139043:tid 139300] [client 20.25.139.174:2183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/atomlib.php"] [unique_id "aoSCUv2v-lWn9OzQT7UusQAAAQQ"] [Tue Aug 18 13:03:30.972491 2026] [security2:error] [pid 123784:tid 123931] [client 172.182.217.32:21805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/pki-validation/cloud.php"] [unique_id "aoSCUmwDnJBNj2tDbYYe3AAAAA0"] [Tue Aug 18 13:03:31.000963 2026] [security2:error] [pid 139043:tid 139220] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sxdfrt.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuswAAALQ"] [Tue Aug 18 13:03:31.025492 2026] [security2:error] [pid 139043:tid 139183] [client 20.186.30.159:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/fi.php"] [unique_id "aoSCU_2v-lWn9OzQT7UutAAAAI8"] [Tue Aug 18 13:03:31.026955 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:31.027221 2026] [authz_core:error] [pid 123784:tid 123829] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:31.031940 2026] [security2:error] [pid 123784:tid 124025] [client 20.163.43.14:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe3gAAAGs"] [Tue Aug 18 13:03:31.035552 2026] [security2:error] [pid 123784:tid 123965] [client 4.223.113.180:41066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe3wAAAC8"] [Tue Aug 18 13:03:31.111455 2026] [security2:error] [pid 139043:tid 139243] [client 20.65.98.162:21767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/admin.php"] [unique_id "aoSCU_2v-lWn9OzQT7UutwAAAMs"] [Tue Aug 18 13:03:31.116050 2026] [security2:error] [pid 139043:tid 139217] [client 20.186.30.159:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/nope.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuuAAAALE"] [Tue Aug 18 13:03:31.133828 2026] [security2:error] [pid 139043:tid 139231] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/path.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuuQAAAL8"] [Tue Aug 18 13:03:31.163127 2026] [security2:error] [pid 139043:tid 139191] [client 20.65.69.59:5702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rbrgestaofinanceira.com.br"] [uri "/bf.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuuwAAAJc"] [Tue Aug 18 13:03:31.196502 2026] [security2:error] [pid 123784:tid 124015] [client 68.155.154.236:63552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe4gAAAGE"] [Tue Aug 18 13:03:31.219964 2026] [security2:error] [pid 123784:tid 123982] [client 20.80.111.3:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/simplepie/library/simplepie/about.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe4wAAAEA"] [Tue Aug 18 13:03:31.220335 2026] [security2:error] [pid 139043:tid 139204] [client 158.23.17.4:17538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/11.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuvQAAAKQ"] [Tue Aug 18 13:03:31.222164 2026] [security2:error] [pid 139043:tid 139179] [client 20.52.168.85:5273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuvgAAAIs"] [Tue Aug 18 13:03:31.240691 2026] [security2:error] [pid 139043:tid 139232] [client 132.196.30.78:11716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuwAAAAMA"] [Tue Aug 18 13:03:31.252559 2026] [security2:error] [pid 139043:tid 139244] [client 20.51.153.15:9762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/h.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuwQAAAMw"] [Tue Aug 18 13:03:31.262680 2026] [security2:error] [pid 139043:tid 139229] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wpo.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuwgAAAL0"] [Tue Aug 18 13:03:31.326625 2026] [security2:error] [pid 123784:tid 123928] [client 20.186.30.159:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/chris.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe5QAAAAo"] [Tue Aug 18 13:03:31.332186 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:31.332617 2026] [authz_core:error] [pid 123784:tid 123802] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:31.359124 2026] [security2:error] [pid 139043:tid 139256] [client 20.151.109.219:27767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/s.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuxQAAANg"] [Tue Aug 18 13:03:31.363070 2026] [security2:error] [pid 139043:tid 139280] [client 168.62.48.100:1206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuxwAAAPA"] [Tue Aug 18 13:03:31.401246 2026] [security2:error] [pid 123784:tid 123948] [client 20.250.13.23:20350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe5wAAAB4"] [Tue Aug 18 13:03:31.402656 2026] [security2:error] [pid 139043:tid 139247] [client 68.221.73.131:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/get.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuyAAAAM8"] [Tue Aug 18 13:03:31.428067 2026] [security2:error] [pid 139043:tid 139178] [client 20.186.30.159:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/nope.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuygAAAIo"] [Tue Aug 18 13:03:31.436163 2026] [security2:error] [pid 139043:tid 139202] [client 74.248.18.37:3412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/htaccess.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuywAAAKI"] [Tue Aug 18 13:03:31.462191 2026] [security2:error] [pid 123784:tid 124006] [client 172.182.217.32:21792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/acme-challenge/cloud.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe6AAAAFg"] [Tue Aug 18 13:03:31.471224 2026] [security2:error] [pid 123784:tid 123970] [client 20.25.139.174:2394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/rip.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe6QAAADQ"] [Tue Aug 18 13:03:31.475901 2026] [security2:error] [pid 139043:tid 139214] [client 20.206.73.37:11913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuzgAAAK4"] [Tue Aug 18 13:03:31.515786 2026] [security2:error] [pid 139043:tid 139255] [client 52.173.121.69:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/Cachex.php"] [unique_id "aoSCU_2v-lWn9OzQT7UuzwAAANc"] [Tue Aug 18 13:03:31.540873 2026] [security2:error] [pid 139043:tid 139234] [client 20.51.153.15:9786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/40.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu0AAAAMI"] [Tue Aug 18 13:03:31.543221 2026] [security2:error] [pid 139043:tid 139222] [client 4.232.151.198:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu0gAAALY"] [Tue Aug 18 13:03:31.552381 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu1QAAAI4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:31.579270 2026] [security2:error] [pid 123784:tid 123936] [client 4.232.151.198:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/aa.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe6wAAABI"] [Tue Aug 18 13:03:31.593271 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:9290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/min.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu1gAAAJY"] [Tue Aug 18 13:03:31.604205 2026] [security2:error] [pid 139043:tid 139250] [client 68.155.156.252:26688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu1wAAANI"] [Tue Aug 18 13:03:31.611062 2026] [security2:error] [pid 139043:tid 139239] [client 168.62.48.100:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu2AAAAMc"] [Tue Aug 18 13:03:31.623298 2026] [security2:error] [pid 123784:tid 123992] [client 158.23.17.4:9333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zy.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe7AAAAEo"] [Tue Aug 18 13:03:31.632181 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:31.632438 2026] [authz_core:error] [pid 123784:tid 123904] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:31.640403 2026] [security2:error] [pid 139043:tid 139186] [client 20.25.139.174:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu2gAAAJI"] [Tue Aug 18 13:03:31.647808 2026] [security2:error] [pid 139043:tid 139251] [client 20.186.30.159:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/doc.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu2wAAANM"] [Tue Aug 18 13:03:31.672851 2026] [security2:error] [pid 139043:tid 139276] [client 20.186.30.159:1666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/new.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu3AAAAOw"] [Tue Aug 18 13:03:31.699872 2026] [security2:error] [pid 123784:tid 123977] [client 20.163.43.14:6533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe7wAAADs"] [Tue Aug 18 13:03:31.725271 2026] [security2:error] [pid 123784:tid 123993] [client 168.62.48.100:1225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe8AAAAEs"] [Tue Aug 18 13:03:31.736402 2026] [security2:error] [pid 139043:tid 139262] [client 20.80.111.3:18148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/simplepie/library/simplepie/min.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu3wAAAN4"] [Tue Aug 18 13:03:31.738729 2026] [security2:error] [pid 139043:tid 139203] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/a1vx.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu4AAAAKM"] [Tue Aug 18 13:03:31.787024 2026] [security2:error] [pid 123784:tid 123920] [client 20.51.153.15:8307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ee.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe8gAAAAI"] [Tue Aug 18 13:03:31.813591 2026] [security2:error] [pid 123784:tid 124014] [client 68.155.154.236:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe8wAAAGA"] [Tue Aug 18 13:03:31.830243 2026] [security2:error] [pid 123784:tid 124002] [client 20.52.168.85:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-access.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe9AAAAFQ"] [Tue Aug 18 13:03:31.842023 2026] [security2:error] [pid 123784:tid 123995] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ty.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe9QAAAE0"] [Tue Aug 18 13:03:31.880959 2026] [security2:error] [pid 139043:tid 139218] [client 20.116.17.175:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/epinyins.php"] [unique_id "aoSCU_2v-lWn9OzQT7Uu-gAAALI"] [Tue Aug 18 13:03:31.915021 2026] [security2:error] [pid 139043:tid 139224] [client 20.206.73.37:35297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ai.php"] [unique_id "aoSCU_2v-lWn9OzQT7UvBAAAALg"] [Tue Aug 18 13:03:31.935994 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:31.936265 2026] [authz_core:error] [pid 123784:tid 123907] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:31.952610 2026] [security2:error] [pid 123784:tid 123944] [client 172.182.217.32:21770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/network/cloud.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe-AAAABo"] [Tue Aug 18 13:03:31.956368 2026] [security2:error] [pid 139043:tid 139253] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/vgtyu.php"] [unique_id "aoSCU_2v-lWn9OzQT7UvDAAAANU"] [Tue Aug 18 13:03:31.960502 2026] [security2:error] [pid 123784:tid 124017] [client 20.186.30.159:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/new.php"] [unique_id "aoSCU2wDnJBNj2tDbYYe-QAAAGM"] [Tue Aug 18 13:03:31.994542 2026] [security2:error] [pid 139043:tid 139296] [client 37.40.227.74:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCU_2v-lWn9OzQT7UvDgAAAQA"] [Tue Aug 18 13:03:31.998674 2026] [security2:error] [pid 139043:tid 139296] [client 37.40.227.74:56764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCU_2v-lWn9OzQT7UvDgAAAQA"] [Tue Aug 18 13:03:32.006703 2026] [security2:error] [pid 123784:tid 124019] [client 20.25.139.174:2296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/p.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe-wAAAGU"] [Tue Aug 18 13:03:32.013544 2026] [security2:error] [pid 139043:tid 139263] [client 168.62.48.100:1266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/rezor.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvEAAAAN8"] [Tue Aug 18 13:03:32.018342 2026] [security2:error] [pid 139043:tid 139183] [client 20.65.98.162:21768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.creativaetal.com.br"] [uri "/ajax.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvEQAAAI8"] [Tue Aug 18 13:03:32.018361 2026] [security2:error] [pid 123784:tid 124021] [client 103.184.169.37:43588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe_AAAAGc"] [Tue Aug 18 13:03:32.018681 2026] [security2:error] [pid 123784:tid 124021] [client 103.184.169.37:43588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe_AAAAGc"] [Tue Aug 18 13:03:32.027332 2026] [security2:error] [pid 123784:tid 123969] [client 20.250.13.23:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe_QAAADM"] [Tue Aug 18 13:03:32.027363 2026] [security2:error] [pid 139043:tid 139187] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/mans.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvEgAAAJM"] [Tue Aug 18 13:03:32.035511 2026] [security2:error] [pid 123784:tid 124010] [client 20.163.43.14:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/o.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe_gAAAFw"] [Tue Aug 18 13:03:32.070064 2026] [security2:error] [pid 139043:tid 139173] [client 74.248.18.37:3759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/images/wso.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvFAAAAIU"] [Tue Aug 18 13:03:32.082064 2026] [security2:error] [pid 139043:tid 139243] [client 68.221.73.131:37273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/images.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvFQAAAMs"] [Tue Aug 18 13:03:32.090595 2026] [security2:error] [pid 139043:tid 139217] [client 20.186.30.159:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/1337.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvFgAAALE"] [Tue Aug 18 13:03:32.123240 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/co.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvGwAAAIw"] [Tue Aug 18 13:03:32.159869 2026] [security2:error] [pid 139043:tid 139201] [client 4.232.151.198:41105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/xmrlpc.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvHQAAAKE"] [Tue Aug 18 13:03:32.163618 2026] [security2:error] [pid 139043:tid 139283] [client 20.206.73.37:11931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/inso.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvHgAAAPM"] [Tue Aug 18 13:03:32.194889 2026] [security2:error] [pid 139043:tid 139289] [client 20.25.139.174:4516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvIAAAAPk"] [Tue Aug 18 13:03:32.209199 2026] [security2:error] [pid 123784:tid 123974] [client 168.62.48.100:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCVGwDnJBNj2tDbYYe_wAAADg"] [Tue Aug 18 13:03:32.229533 2026] [security2:error] [pid 139043:tid 139290] [client 4.232.151.198:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/abcd.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvIgAAAPo"] [Tue Aug 18 13:03:32.236344 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:32.236767 2026] [authz_core:error] [pid 123784:tid 123902] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:32.247868 2026] [security2:error] [pid 139043:tid 139197] [client 20.51.153.15:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ak.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvIwAAAJ0"] [Tue Aug 18 13:03:32.303178 2026] [security2:error] [pid 139043:tid 139244] [client 40.74.65.169:5694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/img.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvJQAAAMw"] [Tue Aug 18 13:03:32.323355 2026] [security2:error] [pid 139043:tid 139280] [client 20.186.30.159:1805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/apreset.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvJgAAAPA"] [Tue Aug 18 13:03:32.331340 2026] [security2:error] [pid 139043:tid 139192] [client 168.62.48.100:1243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvJwAAAJg"] [Tue Aug 18 13:03:32.363768 2026] [security2:error] [pid 139043:tid 139294] [client 20.163.43.14:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/bb.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvKQAAAP4"] [Tue Aug 18 13:03:32.365651 2026] [security2:error] [pid 139043:tid 139226] [client 85.208.98.23:35752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSCVP2v-lWn9OzQT7UvKwAAALo"] [Tue Aug 18 13:03:32.365771 2026] [security2:error] [pid 139043:tid 139226] [client 85.208.98.23:35752] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSCVP2v-lWn9OzQT7UvKwAAALo"] [Tue Aug 18 13:03:32.401545 2026] [security2:error] [pid 139043:tid 139214] [client 132.196.30.78:12709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/rip.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvMAAAAK4"] [Tue Aug 18 13:03:32.423969 2026] [security2:error] [pid 139043:tid 139209] [client 158.23.17.4:33519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/q.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvMgAAAKk"] [Tue Aug 18 13:03:32.433169 2026] [security2:error] [pid 123784:tid 123960] [client 20.80.111.3:18151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/text/diff/renderer/install.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfBQAAACo"] [Tue Aug 18 13:03:32.443204 2026] [security2:error] [pid 139043:tid 139248] [client 20.52.168.85:5261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bthil.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvMwAAANA"] [Tue Aug 18 13:03:32.456781 2026] [security2:error] [pid 139043:tid 139211] [client 172.182.217.32:21546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvRgAAAKs"] [Tue Aug 18 13:03:32.472940 2026] [security2:error] [pid 139043:tid 139238] [client 68.155.154.236:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/index/function.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvSgAAAMY"] [Tue Aug 18 13:03:32.540486 2026] [security2:error] [pid 123784:tid 123959] [client 20.51.153.15:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/test_info.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfCAAAACk"] [Tue Aug 18 13:03:32.543737 2026] [security2:error] [pid 139043:tid 139266] [client 20.25.139.174:2405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gfrison.com.br"] [uri "/php.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvTQAAAOI"] [Tue Aug 18 13:03:32.562802 2026] [security2:error] [pid 139043:tid 139208] [client 20.206.73.37:44960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvTwAAAKg"] [Tue Aug 18 13:03:32.564526 2026] [security2:error] [pid 139043:tid 139184] [client 213.35.127.232:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvUAAAAJA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:32.606560 2026] [security2:error] [pid 139043:tid 139241] [client 20.186.30.159:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/Njima.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvUQAAAMk"] [Tue Aug 18 13:03:32.617916 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fresh.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvUwAAAIY"] [Tue Aug 18 13:03:32.636410 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:1977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/1mage.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvVgAAAKM"] [Tue Aug 18 13:03:32.674918 2026] [security2:error] [pid 139043:tid 139195] [client 68.155.156.252:41681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvWAAAAJs"] [Tue Aug 18 13:03:32.676655 2026] [security2:error] [pid 139043:tid 139277] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/btx25.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvWQAAAO0"] [Tue Aug 18 13:03:32.683131 2026] [security2:error] [pid 139043:tid 139273] [client 20.79.204.6:9711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/php8.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvWgAAAOk"] [Tue Aug 18 13:03:32.695745 2026] [security2:error] [pid 139043:tid 139297] [client 4.223.113.180:40496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/u.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvXAAAAQE"] [Tue Aug 18 13:03:32.705026 2026] [security2:error] [pid 139043:tid 139265] [client 20.163.43.14:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvXQAAAOE"] [Tue Aug 18 13:03:32.721958 2026] [security2:error] [pid 139043:tid 139298] [client 52.173.121.69:62259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvXgAAAQI"] [Tue Aug 18 13:03:32.733996 2026] [security2:error] [pid 123784:tid 123989] [client 74.248.18.37:3445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/index/function.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfCwAAAEc"] [Tue Aug 18 13:03:32.741512 2026] [security2:error] [pid 123784:tid 124038] [client 20.25.139.174:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/gecko-new.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfDAAAAHg"] [Tue Aug 18 13:03:32.748938 2026] [security2:error] [pid 139043:tid 139279] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/avim.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvYwAAAO8"] [Tue Aug 18 13:03:32.767695 2026] [security2:error] [pid 139043:tid 139223] [client 5.31.227.224:29927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvZAAAALc"] [Tue Aug 18 13:03:32.767821 2026] [security2:error] [pid 139043:tid 139223] [client 5.31.227.224:29927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvZAAAALc"] [Tue Aug 18 13:03:32.802281 2026] [security2:error] [pid 123784:tid 123956] [client 191.237.254.161:11427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/dex.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfDQAAACY"] [Tue Aug 18 13:03:32.811496 2026] [security2:error] [pid 139043:tid 139175] [client 68.221.73.131:42491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/alls.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvZQAAAIc"] [Tue Aug 18 13:03:32.818461 2026] [security2:error] [pid 139043:tid 139300] [client 168.62.48.100:1198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvZgAAAQQ"] [Tue Aug 18 13:03:32.825235 2026] [security2:error] [pid 139043:tid 139253] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/myfile.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvaAAAANU"] [Tue Aug 18 13:03:32.837857 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:32.838305 2026] [authz_core:error] [pid 123784:tid 123861] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:32.839797 2026] [security2:error] [pid 123784:tid 123943] [client 4.232.151.198:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/user/12.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfEQAAABk"] [Tue Aug 18 13:03:32.871278 2026] [security2:error] [pid 139043:tid 139240] [client 20.51.153.15:9497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/14.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvagAAAMg"] [Tue Aug 18 13:03:32.881968 2026] [security2:error] [pid 123784:tid 124018] [client 20.186.30.159:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/imsc.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfEwAAAGQ"] [Tue Aug 18 13:03:32.897375 2026] [security2:error] [pid 139043:tid 139271] [client 4.232.151.198:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/admin.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvawAAAOc"] [Tue Aug 18 13:03:32.909388 2026] [security2:error] [pid 139043:tid 139260] [client 20.80.111.3:12530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/themes.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvbAAAANw"] [Tue Aug 18 13:03:32.942191 2026] [security2:error] [pid 139043:tid 139217] [client 20.250.13.23:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvbgAAALE"] [Tue Aug 18 13:03:32.947648 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.217.32:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/updates.php"] [unique_id "aoSCVP2v-lWn9OzQT7UvcgAAALg"] [Tue Aug 18 13:03:32.993993 2026] [security2:error] [pid 123784:tid 123964] [client 158.23.17.4:63753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xf.php"] [unique_id "aoSCVGwDnJBNj2tDbYYfGQAAAC4"] [Tue Aug 18 13:03:33.001016 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.36.136:57831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvdgAAAIw"] [Tue Aug 18 13:03:33.019818 2026] [security2:error] [pid 139043:tid 139281] [client 20.116.17.175:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/load.php"] [unique_id "aoSCVf2v-lWn9OzQT7UveAAAAPE"] [Tue Aug 18 13:03:33.030070 2026] [security2:error] [pid 139043:tid 139201] [client 20.186.30.159:7271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCVf2v-lWn9OzQT7UveQAAAKE"] [Tue Aug 18 13:03:33.037035 2026] [security2:error] [pid 139043:tid 139282] [client 4.232.151.198:48681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/bthil.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvegAAAPI"] [Tue Aug 18 13:03:33.042092 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.154.236:53672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvewAAAPM"] [Tue Aug 18 13:03:33.065605 2026] [security2:error] [pid 123784:tid 123976] [client 20.52.168.85:5248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/packed.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfHAAAADo"] [Tue Aug 18 13:03:33.136117 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:33.136391 2026] [authz_core:error] [pid 123784:tid 123816] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:33.185336 2026] [security2:error] [pid 139043:tid 139247] [client 20.186.30.159:1950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvfgAAAM8"] [Tue Aug 18 13:03:33.203290 2026] [security2:error] [pid 139043:tid 139294] [client 40.74.65.169:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/222.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvfwAAAP4"] [Tue Aug 18 13:03:33.219006 2026] [security2:error] [pid 139043:tid 139202] [client 20.51.153.15:9513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/tk.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvgAAAAKI"] [Tue Aug 18 13:03:33.245259 2026] [security2:error] [pid 139043:tid 139209] [client 168.62.48.100:1209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/index/function.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvgQAAAKk"] [Tue Aug 18 13:03:33.248438 2026] [security2:error] [pid 139043:tid 139206] [client 20.1.169.243:10924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.info.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvggAAAKY"] [Tue Aug 18 13:03:33.291112 2026] [security2:error] [pid 139043:tid 139222] [client 20.151.109.219:27727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/uo.php"] [unique_id "aoSCVf2v-lWn9OzQT7UviAAAALY"] [Tue Aug 18 13:03:33.316191 2026] [security2:error] [pid 123784:tid 123968] [client 20.25.139.174:4622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/NewFile.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfIgAAADI"] [Tue Aug 18 13:03:33.320952 2026] [security2:error] [pid 139043:tid 139182] [client 20.186.30.159:14214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/too.php"] [unique_id "aoSCVf2v-lWn9OzQT7UviQAAAI4"] [Tue Aug 18 13:03:33.359394 2026] [security2:error] [pid 123784:tid 123928] [client 20.163.43.14:6652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfIwAAAAo"] [Tue Aug 18 13:03:33.372249 2026] [security2:error] [pid 139043:tid 139245] [client 74.248.18.37:3758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/info.php"] [unique_id "aoSCVf2v-lWn9OzQT7UviwAAAM0"] [Tue Aug 18 13:03:33.420356 2026] [security2:error] [pid 139043:tid 139266] [client 132.196.30.78:6885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/update/da222.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvjAAAAOI"] [Tue Aug 18 13:03:33.437188 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:33.437463 2026] [authz_core:error] [pid 123784:tid 123896] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:33.439616 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.217.32:21415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/css/cloud.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvjgAAANc"] [Tue Aug 18 13:03:33.453953 2026] [security2:error] [pid 123784:tid 123940] [client 20.186.30.159:1979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/qlex1.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfJQAAABY"] [Tue Aug 18 13:03:33.459540 2026] [security2:error] [pid 139043:tid 139190] [client 20.1.169.243:10892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/about.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvkAAAAJY"] [Tue Aug 18 13:03:33.465028 2026] [security2:error] [pid 139043:tid 139248] [client 20.80.111.3:25988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/themes/plugin-install.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvkgAAANA"] [Tue Aug 18 13:03:33.569251 2026] [security2:error] [pid 139043:tid 139203] [client 20.186.30.159:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.viaduplaseguros.com.br"] [uri "/g3.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvlgAAAKM"] [Tue Aug 18 13:03:33.572852 2026] [security2:error] [pid 139043:tid 139272] [client 158.23.17.4:60775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vm.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvlwAAAOg"] [Tue Aug 18 13:03:33.580906 2026] [security2:error] [pid 139043:tid 139261] [client 213.35.127.232:49332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvmAAAAN0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:33.587622 2026] [security2:error] [pid 139043:tid 139249] [client 223.185.37.47:14835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvmQAAANE"] [Tue Aug 18 13:03:33.591368 2026] [security2:error] [pid 139043:tid 139249] [client 223.185.37.47:14835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvmQAAANE"] [Tue Aug 18 13:03:33.600992 2026] [security2:error] [pid 139043:tid 139292] [client 68.155.156.252:22027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/xx.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvmgAAAPw"] [Tue Aug 18 13:03:33.607440 2026] [security2:error] [pid 139043:tid 139228] [client 168.62.48.100:1084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvmwAAALw"] [Tue Aug 18 13:03:33.615088 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:9519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/hp.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvnAAAAOk"] [Tue Aug 18 13:03:33.618285 2026] [security2:error] [pid 139043:tid 139239] [client 20.250.13.23:3600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvngAAAMc"] [Tue Aug 18 13:03:33.657653 2026] [security2:error] [pid 123784:tid 124014] [client 68.221.73.131:32288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/coffexium.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfJgAAAGA"] [Tue Aug 18 13:03:33.671812 2026] [security2:error] [pid 123784:tid 123948] [client 20.52.168.85:5128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/admin/function.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfJwAAAB4"] [Tue Aug 18 13:03:33.679689 2026] [security2:error] [pid 139043:tid 139252] [client 4.232.151.198:10477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/ku.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvowAAANQ"] [Tue Aug 18 13:03:33.717679 2026] [security2:error] [pid 123784:tid 123946] [client 20.163.43.14:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCVWwDnJBNj2tDbYYfKAAAABw"] [Tue Aug 18 13:03:33.723277 2026] [security2:error] [pid 139043:tid 139275] [client 20.186.30.159:1680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/mariju.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvpAAAAOs"] [Tue Aug 18 13:03:33.740760 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:33.741207 2026] [authz_core:error] [pid 123784:tid 123863] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:33.745073 2026] [security2:error] [pid 139043:tid 139288] [client 102.213.179.104:57521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvpgAAAPg"] [Tue Aug 18 13:03:33.745172 2026] [security2:error] [pid 139043:tid 139288] [client 102.213.179.104:57521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvpgAAAPg"] [Tue Aug 18 13:03:33.822399 2026] [security2:error] [pid 139043:tid 139298] [client 20.25.139.174:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-Blogs.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvsQAAAQI"] [Tue Aug 18 13:03:33.853265 2026] [autoindex:error] [pid 139043:tid 139279] [client 20.1.169.243:10926] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:33.856556 2026] [security2:error] [pid 139043:tid 139262] [client 158.23.17.4:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gb.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvswAAAN4"] [Tue Aug 18 13:03:33.865002 2026] [security2:error] [pid 139043:tid 139271] [client 4.223.113.180:12157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/k.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvtAAAAOc"] [Tue Aug 18 13:03:33.893744 2026] [security2:error] [pid 139043:tid 139193] [client 68.155.154.236:8371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvtQAAAJk"] [Tue Aug 18 13:03:33.908885 2026] [security2:error] [pid 139043:tid 139191] [client 197.184.64.235:42660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvtgAAAJc"] [Tue Aug 18 13:03:33.908996 2026] [security2:error] [pid 139043:tid 139191] [client 197.184.64.235:42660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvtgAAAJc"] [Tue Aug 18 13:03:33.921530 2026] [security2:error] [pid 139043:tid 139175] [client 20.80.111.3:28185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/widgets/index.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvuAAAAIc"] [Tue Aug 18 13:03:33.927670 2026] [security2:error] [pid 139043:tid 139220] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoSCVf2v-lWn9OzQT7UvuQAAtAk"], referer: https://graices.com.br/ [Tue Aug 18 13:03:33.936032 2026] [security2:error] [pid 139043:tid 139198] [client 172.182.217.32:21765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/user/cloud.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvugAAAJ4"] [Tue Aug 18 13:03:33.942958 2026] [security2:error] [pid 139043:tid 139260] [client 40.74.65.169:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/key.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvuwAAANw"] [Tue Aug 18 13:03:33.942996 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:9509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wx.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvvAAAAIU"] [Tue Aug 18 13:03:33.973952 2026] [security2:error] [pid 139043:tid 139274] [client 20.1.169.243:10926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvvQAAAOo"] [Tue Aug 18 13:03:33.986435 2026] [security2:error] [pid 139043:tid 139246] [client 20.186.30.159:1979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCVf2v-lWn9OzQT7UvvgAAAM4"] [Tue Aug 18 13:03:34.002527 2026] [security2:error] [pid 139043:tid 139207] [client 74.248.18.37:55901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/profile.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvwAAAAKc"] [Tue Aug 18 13:03:34.005513 2026] [security2:error] [pid 139043:tid 139224] [client 168.62.48.100:1146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/Cachex.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvwQAAALg"] [Tue Aug 18 13:03:34.007055 2026] [security2:error] [pid 139043:tid 139231] [client 74.248.130.103:34991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvwgAAAL8"] [Tue Aug 18 13:03:34.038693 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:34.038983 2026] [authz_core:error] [pid 123784:tid 123810] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:34.073790 2026] [security2:error] [pid 139043:tid 139282] [client 20.163.43.14:5472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/file.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvxAAAAPI"] [Tue Aug 18 13:03:34.128044 2026] [security2:error] [pid 139043:tid 139256] [client 52.173.121.69:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvxwAAANg"] [Tue Aug 18 13:03:34.145558 2026] [security2:error] [pid 123784:tid 124017] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xmy.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfKwAAAGM"] [Tue Aug 18 13:03:34.156742 2026] [security2:error] [pid 139043:tid 139259] [client 20.226.36.136:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvyAAAANs"] [Tue Aug 18 13:03:34.180039 2026] [security2:error] [pid 139043:tid 139221] [client 20.206.73.37:29959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/sf.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvyQAAALU"] [Tue Aug 18 13:03:34.202528 2026] [security2:error] [pid 123784:tid 123994] [client 158.23.17.4:60346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/eg.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfLQAAAEw"] [Tue Aug 18 13:03:34.229100 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xda.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvywAAAMI"] [Tue Aug 18 13:03:34.243690 2026] [security2:error] [pid 139043:tid 139236] [client 20.250.13.23:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSCVv2v-lWn9OzQT7UvzAAAAMQ"] [Tue Aug 18 13:03:34.277569 2026] [security2:error] [pid 139043:tid 139283] [client 20.52.168.85:5253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/zoom1.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv0AAAAPM"] [Tue Aug 18 13:03:34.287010 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:1224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv0QAAAJA"] [Tue Aug 18 13:03:34.309420 2026] [security2:error] [pid 139043:tid 139190] [client 20.186.30.159:1718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/contacto.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv0wAAAJY"] [Tue Aug 18 13:03:34.314799 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:9527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/dj.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv1AAAANA"] [Tue Aug 18 13:03:34.335445 2026] [cgid:error] [pid 139043:tid 139174] [client 4.232.151.198:44056] AH01265: stderr from /home1/mabelinicom/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:03:34.345079 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:34.345329 2026] [authz_core:error] [pid 123784:tid 123834] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:34.348321 2026] [security2:error] [pid 123784:tid 124019] [client 20.1.169.243:10883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfMwAAAGU"] [Tue Aug 18 13:03:34.362424 2026] [security2:error] [pid 139043:tid 139287] [client 4.232.151.198:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv2AAAAPc"] [Tue Aug 18 13:03:34.365514 2026] [security2:error] [pid 139043:tid 139181] [client 196.12.128.158:64307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv2QAAAI0"] [Tue Aug 18 13:03:34.365633 2026] [security2:error] [pid 139043:tid 139181] [client 196.12.128.158:64307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv2QAAAI0"] [Tue Aug 18 13:03:34.369322 2026] [security2:error] [pid 139043:tid 139270] [client 68.155.154.236:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv3QAAAOY"] [Tue Aug 18 13:03:34.377375 2026] [security2:error] [pid 123784:tid 123985] [client 20.25.139.174:4735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfNQAAAEM"] [Tue Aug 18 13:03:34.387889 2026] [security2:error] [pid 139043:tid 139206] [client 3.212.128.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSCVv2v-lWn9OzQT7Uv1wAApjo"], referer: https://graices.com.br/ [Tue Aug 18 13:03:34.389962 2026] [security2:error] [pid 123784:tid 124021] [client 20.80.111.3:25805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/widgets/min.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfNgAAAGc"] [Tue Aug 18 13:03:34.404179 2026] [security2:error] [pid 139043:tid 139249] [client 20.163.43.14:6534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/epinyins.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv4wAAANE"] [Tue Aug 18 13:03:34.459138 2026] [security2:error] [pid 139043:tid 139219] [client 68.221.73.131:30014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/red.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv5wAAALM"] [Tue Aug 18 13:03:34.464812 2026] [security2:error] [pid 139043:tid 139251] [client 172.182.217.32:21868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/img/cloud.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv6AAAANM"] [Tue Aug 18 13:03:34.495445 2026] [security2:error] [pid 139043:tid 139275] [client 168.62.48.100:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv7AAAAOs"] [Tue Aug 18 13:03:34.541175 2026] [security2:error] [pid 139043:tid 139278] [client 4.232.151.198:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/x.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv7QAAAO4"] [Tue Aug 18 13:03:34.544863 2026] [security2:error] [pid 139043:tid 139211] [client 114.119.136.199:31069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/categoria/relatorios/"] [unique_id "aoSCVv2v-lWn9OzQT7Uv7gAAAKs"], referer: https://ajuda.oruc.com.br/tag/sistema/ [Tue Aug 18 13:03:34.548523 2026] [security2:error] [pid 139043:tid 139300] [client 20.51.153.15:9781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fa.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv7wAAAQQ"] [Tue Aug 18 13:03:34.571971 2026] [security2:error] [pid 139043:tid 139240] [client 20.186.30.159:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/image2.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv8gAAAMg"] [Tue Aug 18 13:03:34.596779 2026] [security2:error] [pid 123784:tid 123932] [client 213.35.127.232:49535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfOwAAAA4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:34.618201 2026] [security2:error] [pid 139043:tid 139279] [client 168.62.48.100:1132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv9AAAAO8"] [Tue Aug 18 13:03:34.633069 2026] [security2:error] [pid 139043:tid 139277] [client 74.248.18.37:55898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/sx.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv9gAAAO0"] [Tue Aug 18 13:03:34.638741 2026] [security2:error] [pid 123784:tid 123918] [client 4.232.151.198:10380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/chosen.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfPQAAAAA"] [Tue Aug 18 13:03:34.646412 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:34.646867 2026] [authz_core:error] [pid 123784:tid 123898] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:34.691319 2026] [security2:error] [pid 139043:tid 139235] [client 20.116.17.175:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv-QAAAMM"] [Tue Aug 18 13:03:34.727970 2026] [security2:error] [pid 139043:tid 139199] [client 20.163.43.14:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv_AAAAJ8"] [Tue Aug 18 13:03:34.740264 2026] [security2:error] [pid 139043:tid 139231] [client 158.23.17.4:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jp.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv_gAAAL8"] [Tue Aug 18 13:03:34.757991 2026] [security2:error] [pid 139043:tid 139136] [remote 50.6.169.131:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv_wAA-Fw"] [Tue Aug 18 13:03:34.773455 2026] [security2:error] [pid 139043:tid 139282] [client 20.206.73.37:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/puc.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwAAAAAPI"] [Tue Aug 18 13:03:34.791239 2026] [security2:error] [pid 139043:tid 139293] [client 20.51.153.15:9760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/fb.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwAgAAAP0"] [Tue Aug 18 13:03:34.842031 2026] [security2:error] [pid 139043:tid 139259] [client 132.196.30.78:20659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/upload.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwBAAAANs"] [Tue Aug 18 13:03:34.845815 2026] [security2:error] [pid 139043:tid 139217] [client 20.80.111.3:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/wp-cron.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwBQAAALE"] [Tue Aug 18 13:03:34.848054 2026] [security2:error] [pid 139043:tid 139294] [client 20.186.30.159:1824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/fb.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwBgAAAP4"] [Tue Aug 18 13:03:34.882467 2026] [security2:error] [pid 139043:tid 139198] [client 20.52.168.85:5276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/about.php7"] [unique_id "aoSCVv2v-lWn9OzQT7UwCAAAAJ4"] [Tue Aug 18 13:03:34.888706 2026] [security2:error] [pid 139043:tid 139284] [client 68.155.154.236:41513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwCgAAAPQ"] [Tue Aug 18 13:03:34.914440 2026] [security2:error] [pid 139043:tid 139260] [client 20.250.13.23:3424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwDgAAANw"] [Tue Aug 18 13:03:34.915366 2026] [security2:error] [pid 139043:tid 139215] [client 20.25.139.174:4731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/themes.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwDwAAAK8"] [Tue Aug 18 13:03:34.942208 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:34.942534 2026] [authz_core:error] [pid 123784:tid 123857] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:34.959213 2026] [security2:error] [pid 139043:tid 139283] [client 168.62.48.100:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwEQAAAPM"] [Tue Aug 18 13:03:34.962433 2026] [security2:error] [pid 139043:tid 139290] [client 172.182.217.32:21540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwEgAAAPo"] [Tue Aug 18 13:03:34.977459 2026] [security2:error] [pid 139043:tid 139255] [client 20.1.169.243:10942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwEwAAANc"] [Tue Aug 18 13:03:34.991365 2026] [security2:error] [pid 139043:tid 139179] [client 4.232.151.198:4216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/akc.php"] [unique_id "aoSCVv2v-lWn9OzQT7UwFAAAAIs"] [Tue Aug 18 13:03:35.013489 2026] [security2:error] [pid 139043:tid 139276] [client 40.74.65.169:5644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwFgAAAOw"] [Tue Aug 18 13:03:35.034306 2026] [security2:error] [pid 139043:tid 139287] [client 20.51.153.15:8204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gw.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwFwAAAPc"] [Tue Aug 18 13:03:35.077378 2026] [security2:error] [pid 139043:tid 139203] [client 168.62.48.100:1201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwGQAAAKM"] [Tue Aug 18 13:03:35.082015 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:7205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gj.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwGgAAAKY"] [Tue Aug 18 13:03:35.116880 2026] [security2:error] [pid 123784:tid 123919] [client 20.151.109.219:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kx.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfQAAAAAE"] [Tue Aug 18 13:03:35.140845 2026] [security2:error] [pid 139043:tid 139186] [client 20.186.30.159:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/gi.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwHQAAAJI"] [Tue Aug 18 13:03:35.265379 2026] [security2:error] [pid 139043:tid 139181] [client 4.232.151.198:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/asd.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwIAAAAI0"] [Tue Aug 18 13:03:35.272715 2026] [security2:error] [pid 139043:tid 139177] [client 74.248.18.37:55927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwIQAAAIk"] [Tue Aug 18 13:03:35.282452 2026] [security2:error] [pid 139043:tid 139200] [client 20.79.204.6:9341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/admin.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwIwAAAKA"] [Tue Aug 18 13:03:35.285045 2026] [security2:error] [pid 139043:tid 139245] [client 4.223.113.180:45306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/elp.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwJAAAAM0"] [Tue Aug 18 13:03:35.298522 2026] [security2:error] [pid 123784:tid 124011] [client 20.80.111.3:5916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/wp-links-opml.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfSAAAAF0"] [Tue Aug 18 13:03:35.300215 2026] [security2:error] [pid 139043:tid 139183] [client 158.23.17.4:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/uk.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwJQAAAI8"] [Tue Aug 18 13:03:35.353302 2026] [security2:error] [pid 123784:tid 123996] [client 20.1.169.243:10909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/admin.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfSgAAAE4"] [Tue Aug 18 13:03:35.383304 2026] [security2:error] [pid 139043:tid 139173] [client 20.163.43.14:6592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwKgAAAIU"] [Tue Aug 18 13:03:35.432261 2026] [security2:error] [pid 139043:tid 139246] [client 20.186.30.159:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/video.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwLAAAAM4"] [Tue Aug 18 13:03:35.437644 2026] [security2:error] [pid 123784:tid 123959] [client 20.51.153.15:9755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/sw.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfSwAAACk"] [Tue Aug 18 13:03:35.456767 2026] [security2:error] [pid 123784:tid 124008] [client 20.25.139.174:4641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/cv.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfTAAAAFo"] [Tue Aug 18 13:03:35.480666 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwLgAAAMg"] [Tue Aug 18 13:03:35.512809 2026] [security2:error] [pid 139043:tid 139257] [client 68.155.156.252:26744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/av.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwMAAAANk"] [Tue Aug 18 13:03:35.512829 2026] [security2:error] [pid 139043:tid 139187] [client 20.52.168.85:5125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/cron.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwMQAAAJM"] [Tue Aug 18 13:03:35.541243 2026] [security2:error] [pid 139043:tid 139227] [client 74.248.130.103:7918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwMgAAALs"] [Tue Aug 18 13:03:35.545393 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:35.545710 2026] [authz_core:error] [pid 123784:tid 123897] [remote 216.73.216.206:7861] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:35.551778 2026] [security2:error] [pid 139043:tid 139288] [client 168.62.48.100:1241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwMwAAAPg"] [Tue Aug 18 13:03:35.613050 2026] [security2:error] [pid 123784:tid 124037] [client 213.35.127.232:49761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfTwAAAHc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:35.616119 2026] [autoindex:error] [pid 139043:tid 139220] [client 74.248.18.37:37408] AH01276: Cannot serve directory /home3/wrsteelcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:35.632578 2026] [security2:error] [pid 139043:tid 139235] [client 4.232.151.198:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/buy.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwNwAAAMM"] [Tue Aug 18 13:03:35.677716 2026] [security2:error] [pid 123784:tid 124042] [client 20.206.73.37:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/biufile.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfUgAAAHw"] [Tue Aug 18 13:03:35.708380 2026] [security2:error] [pid 123784:tid 123984] [client 20.186.30.159:1976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/hel.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfUwAAAEI"] [Tue Aug 18 13:03:35.709356 2026] [security2:error] [pid 139043:tid 139259] [client 20.51.153.15:8288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gc.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwOgAAANs"] [Tue Aug 18 13:03:35.722178 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.36.136:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwOwAAAIo"] [Tue Aug 18 13:03:35.729839 2026] [security2:error] [pid 139043:tid 139262] [client 20.163.43.14:6538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwPAAAAN4"] [Tue Aug 18 13:03:35.742380 2026] [security2:error] [pid 139043:tid 139289] [client 20.80.111.3:26014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-login.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwPgAAAPk"] [Tue Aug 18 13:03:35.742822 2026] [security2:error] [pid 139043:tid 139293] [client 20.1.169.243:10938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/core.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwPwAAAP0"] [Tue Aug 18 13:03:35.769775 2026] [security2:error] [pid 139043:tid 139221] [client 68.155.154.236:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwQAAAALU"] [Tue Aug 18 13:03:35.786143 2026] [security2:error] [pid 139043:tid 139214] [client 158.23.17.4:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/eq.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwQQAAAK4"] [Tue Aug 18 13:03:35.809544 2026] [security2:error] [pid 139043:tid 139222] [client 20.250.13.23:3113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwQgAAALY"] [Tue Aug 18 13:03:35.854799 2026] [security2:error] [pid 139043:tid 139297] [client 5.161.75.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoSCVv2v-lWn9OzQT7Uv5QABAVQ"], referer: https://alsconsultoria.com.br/ [Tue Aug 18 13:03:35.900539 2026] [security2:error] [pid 139043:tid 139237] [client 168.62.48.100:1313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwSgAAAMU"] [Tue Aug 18 13:03:35.901063 2026] [security2:error] [pid 123784:tid 124023] [client 4.232.151.198:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/akc.php"] [unique_id "aoSCV2wDnJBNj2tDbYYfVAAAAGk"] [Tue Aug 18 13:03:35.903186 2026] [security2:error] [pid 139043:tid 139226] [client 74.248.18.37:3439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwSwAAALo"] [Tue Aug 18 13:03:35.923732 2026] [security2:error] [pid 139043:tid 139248] [client 40.74.65.169:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/wpxml.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwTQAAANA"] [Tue Aug 18 13:03:35.962619 2026] [security2:error] [pid 139043:tid 139276] [client 20.186.30.159:1712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/grok.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwTgAAAOw"] [Tue Aug 18 13:03:35.971411 2026] [security2:error] [pid 139043:tid 139198] [client 172.182.217.32:21802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/avaa.php"] [unique_id "aoSCV_2v-lWn9OzQT7UwTwAAAJ4"] [Tue Aug 18 13:03:36.029792 2026] [security2:error] [pid 123784:tid 123921] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSCVmwDnJBNj2tDbYYfOQAAAwU"], referer: https://1ba.com.br/ [Tue Aug 18 13:03:36.030495 2026] [security2:error] [pid 139043:tid 139286] [client 20.51.153.15:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/uq.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwVQAAAPY"] [Tue Aug 18 13:03:36.080804 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwVwAAALw"] [Tue Aug 18 13:03:36.106916 2026] [security2:error] [pid 139043:tid 139287] [client 20.1.169.243:10888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/db-status.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwWwAAAPc"] [Tue Aug 18 13:03:36.116131 2026] [security2:error] [pid 139043:tid 139280] [client 20.52.168.85:5124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwXAAAAPA"] [Tue Aug 18 13:03:36.131324 2026] [security2:error] [pid 139043:tid 139194] [client 20.116.17.175:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ty.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwXQAAAJo"] [Tue Aug 18 13:03:36.145808 2026] [security2:error] [pid 139043:tid 139278] [client 168.62.48.100:1252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwXgAAAO4"] [Tue Aug 18 13:03:36.181354 2026] [security2:error] [pid 139043:tid 139243] [client 20.79.204.6:10117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/222.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwXwAAAMs"] [Tue Aug 18 13:03:36.182217 2026] [security2:error] [pid 139043:tid 139195] [client 20.80.111.3:25796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-rss.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwYAAAAJs"] [Tue Aug 18 13:03:36.183630 2026] [security2:error] [pid 139043:tid 139174] [client 4.223.113.180:17369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwYQAAAIY"] [Tue Aug 18 13:03:36.197941 2026] [security2:error] [pid 139043:tid 139177] [client 20.25.139.174:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwYwAAAIk"] [Tue Aug 18 13:03:36.236903 2026] [security2:error] [pid 139043:tid 139183] [client 132.196.30.78:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wk/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwZQAAAI8"] [Tue Aug 18 13:03:36.286130 2026] [security2:error] [pid 139043:tid 139246] [client 20.186.30.159:1665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/indes.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwaAAAAM4"] [Tue Aug 18 13:03:36.293458 2026] [security2:error] [pid 139043:tid 139229] [client 68.155.156.252:40530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/media.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwagAAAL0"] [Tue Aug 18 13:03:36.332791 2026] [security2:error] [pid 139043:tid 139205] [client 4.232.151.198:46786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/cong.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwawAAAKU"] [Tue Aug 18 13:03:36.386985 2026] [security2:error] [pid 139043:tid 139175] [client 20.51.153.15:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/32.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwbQAAAIc"] [Tue Aug 18 13:03:36.405931 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.154.236:40228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwcAAAAMM"] [Tue Aug 18 13:03:36.421853 2026] [security2:error] [pid 139043:tid 139232] [client 20.163.43.14:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/function/function.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwcQAAAMA"] [Tue Aug 18 13:03:36.423908 2026] [security2:error] [pid 139043:tid 139298] [client 158.23.17.4:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pd.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwcgAAAQI"] [Tue Aug 18 13:03:36.444380 2026] [security2:error] [pid 139043:tid 139216] [client 20.250.13.23:3450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwdQAAALA"] [Tue Aug 18 13:03:36.466703 2026] [security2:error] [pid 139043:tid 139264] [client 172.182.217.32:21784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/images/cloud.php"] [unique_id "aoSCWP2v-lWn9OzQT7UweQAAAOA"] [Tue Aug 18 13:03:36.467892 2026] [authz_core:error] [pid 139043:tid 139082] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:36.468465 2026] [authz_core:error] [pid 139043:tid 139082] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:36.470426 2026] [authz_core:error] [pid 139043:tid 139079] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:36.470869 2026] [authz_core:error] [pid 139043:tid 139079] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:36.472885 2026] [security2:error] [pid 139043:tid 139187] [client 20.1.169.243:11149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwegAAAJM"] [Tue Aug 18 13:03:36.486514 2026] [security2:error] [pid 139043:tid 139292] [client 86.120.159.145:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwewAAAPw"] [Tue Aug 18 13:03:36.486689 2026] [security2:error] [pid 139043:tid 139292] [client 86.120.159.145:59538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwewAAAPw"] [Tue Aug 18 13:03:36.496214 2026] [security2:error] [pid 139043:tid 139178] [client 68.155.154.236:8848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/Cachex.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwfAAAAIo"] [Tue Aug 18 13:03:36.517575 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:38897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ep.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwfQAAAPk"] [Tue Aug 18 13:03:36.538392 2026] [security2:error] [pid 139043:tid 139295] [client 4.232.151.198:41106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/maintenance.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwgAAAAP8"] [Tue Aug 18 13:03:36.590491 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:1232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwggAAALY"] [Tue Aug 18 13:03:36.641942 2026] [security2:error] [pid 139043:tid 139297] [client 40.74.65.169:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/file1221.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwhQAAAQE"] [Tue Aug 18 13:03:36.643827 2026] [security2:error] [pid 139043:tid 139261] [client 213.35.127.232:49987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwhgAAAN0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:36.654820 2026] [security2:error] [pid 139043:tid 139215] [client 68.221.73.131:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwhwAAAK8"] [Tue Aug 18 13:03:36.678987 2026] [security2:error] [pid 139043:tid 139238] [client 20.186.30.159:1692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwiAAAAMY"] [Tue Aug 18 13:03:36.695741 2026] [security2:error] [pid 139043:tid 139182] [client 20.51.153.15:8163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/73.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwigAAAI4"] [Tue Aug 18 13:03:36.722593 2026] [security2:error] [pid 139043:tid 139293] [client 20.52.168.85:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwiwAAAP0"] [Tue Aug 18 13:03:36.727083 2026] [security2:error] [pid 139043:tid 139214] [client 20.80.111.3:25798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-setting.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwjAAAAK4"] [Tue Aug 18 13:03:36.745133 2026] [security2:error] [pid 139043:tid 139270] [client 74.248.18.37:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwjwAAAOY"] [Tue Aug 18 13:03:36.748699 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:36.748965 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:36.754189 2026] [security2:error] [pid 139043:tid 139206] [client 20.163.43.14:5476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwkQAAAKY"] [Tue Aug 18 13:03:36.775110 2026] [security2:error] [pid 139043:tid 139221] [client 20.25.139.174:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ws83.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwkwAAALU"] [Tue Aug 18 13:03:36.838436 2026] [security2:error] [pid 139043:tid 139226] [client 20.1.169.243:10898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/index.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwlgAAALo"] [Tue Aug 18 13:03:36.932817 2026] [security2:error] [pid 139043:tid 139278] [client 20.226.36.136:57259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwnAAAAO4"] [Tue Aug 18 13:03:36.938144 2026] [security2:error] [pid 139043:tid 139243] [client 20.186.30.159:1683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/bs1.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwnQAAAMs"] [Tue Aug 18 13:03:36.955039 2026] [security2:error] [pid 139043:tid 139192] [client 4.232.151.198:4209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwngAAAJg"] [Tue Aug 18 13:03:36.959085 2026] [security2:error] [pid 139043:tid 139203] [client 172.182.217.32:21845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwpQAAAKM"] [Tue Aug 18 13:03:36.998864 2026] [security2:error] [pid 139043:tid 139271] [client 20.51.153.15:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ib.php"] [unique_id "aoSCWP2v-lWn9OzQT7UwxwAAAOc"] [Tue Aug 18 13:03:37.049283 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:37.049564 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:37.066255 2026] [security2:error] [pid 139043:tid 139246] [client 168.62.48.100:1193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCWf2v-lWn9OzQT7UwzAAAAM4"] [Tue Aug 18 13:03:37.070451 2026] [security2:error] [pid 139043:tid 139219] [client 20.250.13.23:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSCWf2v-lWn9OzQT7UwzQAAALM"] [Tue Aug 18 13:03:37.074579 2026] [security2:error] [pid 139043:tid 139229] [client 68.155.154.236:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCWf2v-lWn9OzQT7UwzgAAAL0"] [Tue Aug 18 13:03:37.097699 2026] [security2:error] [pid 139043:tid 139257] [client 68.155.154.236:55429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCWf2v-lWn9OzQT7UwzwAAANk"] [Tue Aug 18 13:03:37.143340 2026] [security2:error] [pid 139043:tid 139191] [client 158.23.17.4:20374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/th.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw0gAAAJc"] [Tue Aug 18 13:03:37.156867 2026] [security2:error] [pid 139043:tid 139233] [client 74.248.130.103:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file52.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw0wAAAME"] [Tue Aug 18 13:03:37.159306 2026] [security2:error] [pid 139043:tid 139296] [client 4.232.151.198:10827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/options-writing.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw1QAAAQA"] [Tue Aug 18 13:03:37.161467 2026] [security2:error] [pid 139043:tid 139232] [client 158.23.17.4:47879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/creds.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw1gAAAMA"] [Tue Aug 18 13:03:37.171605 2026] [security2:error] [pid 139043:tid 139242] [client 20.163.43.14:5481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw2AAAAMo"] [Tue Aug 18 13:03:37.199806 2026] [security2:error] [pid 139043:tid 139259] [client 47.128.41.55:49394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mahokosveiculos.com.br"] [uri "/robots.txt"] [unique_id "aoSCWf2v-lWn9OzQT7Uw3AAAANs"] [Tue Aug 18 13:03:37.203679 2026] [security2:error] [pid 139043:tid 139240] [client 20.1.169.243:10885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw3gAAAMg"] [Tue Aug 18 13:03:37.243966 2026] [security2:error] [pid 139043:tid 139292] [client 20.186.30.159:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/hp2.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw4QAAAPw"] [Tue Aug 18 13:03:37.272366 2026] [security2:error] [pid 139043:tid 139252] [client 20.79.204.6:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw8gAAANQ"] [Tue Aug 18 13:03:37.281353 2026] [security2:error] [pid 139043:tid 139241] [client 20.116.17.175:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw8wAAAMk"] [Tue Aug 18 13:03:37.295616 2026] [security2:error] [pid 139043:tid 139234] [client 158.23.17.4:29500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/rf.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw9QAAAMI"] [Tue Aug 18 13:03:37.318807 2026] [security2:error] [pid 139043:tid 139284] [client 20.51.153.15:9521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xm.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw9wAAAPQ"] [Tue Aug 18 13:03:37.326824 2026] [security2:error] [pid 139043:tid 139175] [client 20.52.168.85:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/add_actualites.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw-QAAAIc"] [Tue Aug 18 13:03:37.336351 2026] [security2:error] [pid 139043:tid 139281] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/zz.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw_gAAAPE"] [Tue Aug 18 13:03:37.340508 2026] [security2:error] [pid 139043:tid 139290] [client 68.221.73.131:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/admin.php"] [unique_id "aoSCWf2v-lWn9OzQT7Uw_wAAAPo"] [Tue Aug 18 13:03:37.344999 2026] [security2:error] [pid 139043:tid 139235] [client 20.25.139.174:4430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/atex1.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxAQAAAMM"] [Tue Aug 18 13:03:37.399793 2026] [security2:error] [pid 139043:tid 139214] [client 20.206.73.37:11923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/19.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxAwAAAK4"] [Tue Aug 18 13:03:37.405175 2026] [security2:error] [pid 139043:tid 139198] [client 4.223.113.180:45299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/o.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxBAAAAJ4"] [Tue Aug 18 13:03:37.417436 2026] [security2:error] [pid 139043:tid 139270] [client 191.237.254.161:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/puc.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxBgAAAOY"] [Tue Aug 18 13:03:37.433885 2026] [security2:error] [pid 139043:tid 139249] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xa.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxBwAAANE"] [Tue Aug 18 13:03:37.446395 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.217.32:21761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/Requests/Text/admin.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxDAAAALY"] [Tue Aug 18 13:03:37.458244 2026] [security2:error] [pid 139043:tid 139228] [client 168.62.48.100:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxDgAAALw"] [Tue Aug 18 13:03:37.461541 2026] [security2:error] [pid 139043:tid 139273] [client 168.62.48.100:1262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxEgAAAOk"] [Tue Aug 18 13:03:37.468062 2026] [security2:error] [pid 139043:tid 139226] [client 20.206.73.37:35290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/xx.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxFAAAALo"] [Tue Aug 18 13:03:37.469752 2026] [security2:error] [pid 139043:tid 139291] [client 20.80.111.3:1375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wpr-addons/forms/b1ack.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxFQAAAPs"] [Tue Aug 18 13:03:37.500300 2026] [security2:error] [pid 139043:tid 139186] [client 20.163.43.14:5489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/ok.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxGgAAAJI"] [Tue Aug 18 13:03:37.516864 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/f6.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxGwAAAOs"] [Tue Aug 18 13:03:37.553808 2026] [security2:error] [pid 139043:tid 139181] [client 20.186.30.159:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/yb.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxHQAAAI0"] [Tue Aug 18 13:03:37.557091 2026] [security2:error] [pid 139043:tid 139254] [client 40.74.65.169:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/nox.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxHgAAANY"] [Tue Aug 18 13:03:37.568904 2026] [security2:error] [pid 139043:tid 139197] [client 20.1.169.243:10899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxIAAAAJ0"] [Tue Aug 18 13:03:37.588078 2026] [security2:error] [pid 139043:tid 139208] [client 4.232.151.198:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/db.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxIQAAAKg"] [Tue Aug 18 13:03:37.624367 2026] [security2:error] [pid 139043:tid 139269] [client 20.206.73.37:2551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/coffexium.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxIgAAAOU"] [Tue Aug 18 13:03:37.651507 2026] [security2:error] [pid 139043:tid 139219] [client 74.248.18.37:3743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxJAAAALM"] [Tue Aug 18 13:03:37.658041 2026] [security2:error] [pid 139043:tid 139297] [client 213.35.127.232:50221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxJgAAAQE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:37.659965 2026] [authz_core:error] [pid 139043:tid 139056] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:37.660256 2026] [authz_core:error] [pid 139043:tid 139056] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:37.693441 2026] [security2:error] [pid 139043:tid 139227] [client 20.51.153.15:9770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/zy.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxJwAAALs"] [Tue Aug 18 13:03:37.823503 2026] [security2:error] [pid 139043:tid 139247] [client 68.155.154.236:45865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxLgAAAM8"] [Tue Aug 18 13:03:37.826822 2026] [security2:error] [pid 139043:tid 139259] [client 20.163.43.14:5407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "economycarsmultimarcas.com.br"] [uri "/item.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxLwAAANs"] [Tue Aug 18 13:03:37.837060 2026] [security2:error] [pid 139043:tid 139268] [client 20.250.13.23:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/options.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxMQAAAOQ"] [Tue Aug 18 13:03:37.841796 2026] [security2:error] [pid 139043:tid 139240] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/mcs.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxMgAAAMg"] [Tue Aug 18 13:03:37.856796 2026] [security2:error] [pid 139043:tid 139184] [client 4.232.151.198:10816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxMwAAAJA"] [Tue Aug 18 13:03:37.864600 2026] [security2:error] [pid 139043:tid 139264] [client 20.186.30.159:1941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/vc.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxNAAAAOA"] [Tue Aug 18 13:03:37.868555 2026] [security2:error] [pid 139043:tid 139292] [client 158.23.17.4:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ho.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxNQAAAPw"] [Tue Aug 18 13:03:37.886898 2026] [security2:error] [pid 139043:tid 139288] [client 20.25.139.174:4716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/class-t.api.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxNgAAAPg"] [Tue Aug 18 13:03:37.908216 2026] [security2:error] [pid 139043:tid 139262] [client 168.62.48.100:1058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxNwAAAN4"] [Tue Aug 18 13:03:37.918833 2026] [security2:error] [pid 139043:tid 139220] [client 20.80.111.3:5900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/x.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxOAAAALQ"] [Tue Aug 18 13:03:37.928016 2026] [security2:error] [pid 139043:tid 139191] [client 20.52.168.85:5305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/browse.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxOgAAAJc"] [Tue Aug 18 13:03:37.939831 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.217.32:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxPAAAAQA"] [Tue Aug 18 13:03:37.940884 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:9492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/q.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxPQAAAOw"] [Tue Aug 18 13:03:37.943126 2026] [security2:error] [pid 139043:tid 139277] [client 20.1.169.243:11184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/ms-files.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxPgAAAO0"] [Tue Aug 18 13:03:37.952161 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/xleet.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxQAAAAMI"] [Tue Aug 18 13:03:37.955944 2026] [security2:error] [pid 139043:tid 139284] [client 68.155.154.236:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCWf2v-lWn9OzQT7UxQQAAAPQ"] [Tue Aug 18 13:03:38.035202 2026] [security2:error] [pid 139043:tid 139182] [client 20.116.17.175:3445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/dot.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxRAAAAI4"] [Tue Aug 18 13:03:38.052910 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xynz1.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxRQAAAIs"] [Tue Aug 18 13:03:38.116477 2026] [security2:error] [pid 139043:tid 139221] [client 68.221.73.131:26670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file52.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxSQAAALU"] [Tue Aug 18 13:03:38.138945 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxSwAAALY"] [Tue Aug 18 13:03:38.178040 2026] [security2:error] [pid 139043:tid 139258] [client 20.51.153.15:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xf.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxTAAAANo"] [Tue Aug 18 13:03:38.183935 2026] [security2:error] [pid 139043:tid 139291] [client 20.186.30.159:1672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/pema.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxTQAAAPs"] [Tue Aug 18 13:03:38.193069 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:9304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/info.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxTgAAAMQ"] [Tue Aug 18 13:03:38.222037 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.151.198:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/dropdown.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxUAAAAMY"] [Tue Aug 18 13:03:38.255165 2026] [authz_core:error] [pid 139043:tid 139156] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:38.255424 2026] [authz_core:error] [pid 139043:tid 139156] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:38.285205 2026] [security2:error] [pid 139043:tid 139280] [client 20.151.109.219:21908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/va.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxUwAAAPA"] [Tue Aug 18 13:03:38.285230 2026] [security2:error] [pid 139043:tid 139209] [client 74.248.18.37:3762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxVAAAAKk"] [Tue Aug 18 13:03:38.308763 2026] [security2:error] [pid 139043:tid 139265] [client 20.1.169.243:10923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/options.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxVgAAAOE"] [Tue Aug 18 13:03:38.320933 2026] [security2:error] [pid 139043:tid 139188] [client 20.226.36.136:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxVwAAAJQ"] [Tue Aug 18 13:03:38.330333 2026] [security2:error] [pid 139043:tid 139192] [client 132.196.30.78:9277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-act.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxWAAAAJg"] [Tue Aug 18 13:03:38.340472 2026] [security2:error] [pid 139043:tid 139200] [client 168.62.48.100:1189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxWQAAAKA"] [Tue Aug 18 13:03:38.439778 2026] [security2:error] [pid 139043:tid 139194] [client 172.182.217.32:21506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/includes/cloud.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxXQAAAJo"] [Tue Aug 18 13:03:38.450760 2026] [security2:error] [pid 139043:tid 139219] [client 40.74.65.169:5684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/akismet.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxXwAAALM"] [Tue Aug 18 13:03:38.452934 2026] [security2:error] [pid 139043:tid 139218] [client 20.25.139.174:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/w.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxYAAAALI"] [Tue Aug 18 13:03:38.470800 2026] [security2:error] [pid 139043:tid 139201] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxXgAAoWI"] [Tue Aug 18 13:03:38.470943 2026] [security2:error] [pid 139043:tid 139229] [client 20.51.153.15:9547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gb.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxYgAAAL0"] [Tue Aug 18 13:03:38.477143 2026] [security2:error] [pid 139043:tid 139205] [client 20.250.13.23:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxYwAAAKU"] [Tue Aug 18 13:03:38.482143 2026] [security2:error] [pid 139043:tid 139186] [client 4.232.151.198:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/maint.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxZAAAAJI"] [Tue Aug 18 13:03:38.495684 2026] [security2:error] [pid 139043:tid 139227] [client 20.186.30.159:1956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/sh.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxZQAAALs"] [Tue Aug 18 13:03:38.524677 2026] [security2:error] [pid 139043:tid 139203] [client 20.80.111.3:25833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/yellow.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxZgAAAKM"] [Tue Aug 18 13:03:38.526637 2026] [security2:error] [pid 139043:tid 139181] [client 20.52.168.85:5127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/contentloader1.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxZwAAAI0"] [Tue Aug 18 13:03:38.581125 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:38.581388 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:38.597111 2026] [authz_core:error] [pid 139043:tid 139145] [remote 57.141.22.88:65376] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:38.597378 2026] [authz_core:error] [pid 139043:tid 139145] [remote 57.141.22.88:65376] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:38.670734 2026] [security2:error] [pid 139043:tid 139197] [client 213.35.127.232:50423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxbgAAAJ0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:38.689056 2026] [security2:error] [pid 139043:tid 139298] [client 20.1.169.243:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/panel.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxbwAAAQI"] [Tue Aug 18 13:03:38.703479 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:9488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/jp.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxcAAAAPw"] [Tue Aug 18 13:03:38.752617 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/admin404.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxcgAAALc"] [Tue Aug 18 13:03:38.765235 2026] [security2:error] [pid 139043:tid 139202] [client 68.155.154.236:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxcwAAAKI"] [Tue Aug 18 13:03:38.811644 2026] [security2:error] [pid 139043:tid 139276] [client 20.186.30.159:1704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/button.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxdAAAAOw"] [Tue Aug 18 13:03:38.829454 2026] [security2:error] [pid 139043:tid 139230] [client 20.116.17.175:3423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/005.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxdQAAAL4"] [Tue Aug 18 13:03:38.856159 2026] [authz_core:error] [pid 139043:tid 139054] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:38.856439 2026] [authz_core:error] [pid 139043:tid 139054] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:38.879716 2026] [security2:error] [pid 139043:tid 139268] [client 4.232.151.198:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/file.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxeAAAAOQ"] [Tue Aug 18 13:03:38.925750 2026] [security2:error] [pid 139043:tid 139220] [client 172.182.217.32:21873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/blue/cloud.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxfAAAALQ"] [Tue Aug 18 13:03:38.932168 2026] [security2:error] [pid 139043:tid 139193] [client 74.248.18.37:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxfQAAAJk"] [Tue Aug 18 13:03:38.943639 2026] [security2:error] [pid 139043:tid 139248] [client 20.206.73.37:11940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/133.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxfgAAANA"] [Tue Aug 18 13:03:38.958423 2026] [security2:error] [pid 139043:tid 139270] [client 20.226.36.136:43694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxgQAAAOY"] [Tue Aug 18 13:03:38.966473 2026] [security2:error] [pid 139043:tid 139221] [client 20.51.153.15:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/eq.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxgwAAALU"] [Tue Aug 18 13:03:38.970580 2026] [security2:error] [pid 139043:tid 139176] [client 20.80.111.3:25809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/.well-known/acme-challenge/post.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxhAAAAIg"] [Tue Aug 18 13:03:38.973203 2026] [security2:error] [pid 139043:tid 139216] [client 168.62.48.100:1181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxhQAAALA"] [Tue Aug 18 13:03:38.980403 2026] [security2:error] [pid 139043:tid 139286] [client 68.221.73.131:37292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/geck.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxhgAAAPY"] [Tue Aug 18 13:03:39.000076 2026] [security2:error] [pid 139043:tid 139300] [client 20.25.139.174:4631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/archive.php"] [unique_id "aoSCWv2v-lWn9OzQT7UxhwAAAQQ"] [Tue Aug 18 13:03:39.016741 2026] [security2:error] [pid 139043:tid 139262] [client 20.79.204.6:9717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/a.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxiQAAAN4"] [Tue Aug 18 13:03:39.080175 2026] [security2:error] [pid 139043:tid 139237] [client 20.1.169.243:10941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxiwAAAMU"] [Tue Aug 18 13:03:39.084337 2026] [security2:error] [pid 139043:tid 139291] [client 158.23.17.4:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/97.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxjAAAAPs"] [Tue Aug 18 13:03:39.091294 2026] [security2:error] [pid 139043:tid 139238] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fr/ms.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxjQAAAMY"] [Tue Aug 18 13:03:39.099022 2026] [security2:error] [pid 139043:tid 139287] [client 20.186.30.159:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/wlc.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxjgAAAPc"] [Tue Aug 18 13:03:39.099703 2026] [security2:error] [pid 139043:tid 139179] [client 4.232.151.198:10875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/phpMailer.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxjwAAAIs"] [Tue Aug 18 13:03:39.109655 2026] [security2:error] [pid 139043:tid 139246] [client 20.250.13.23:3440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxkQAAAM4"] [Tue Aug 18 13:03:39.163295 2026] [security2:error] [pid 139043:tid 139213] [client 20.52.168.85:5292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/upfile.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxkwAAAK0"] [Tue Aug 18 13:03:39.178621 2026] [security2:error] [pid 139043:tid 139253] [client 20.206.73.37:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/1xmomo.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxlAAAANU"] [Tue Aug 18 13:03:39.221981 2026] [security2:error] [pid 139043:tid 139177] [client 158.23.17.4:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vo.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxmQAAAIk"] [Tue Aug 18 13:03:39.228047 2026] [security2:error] [pid 139043:tid 139271] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/gool.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxmgAAAOc"] [Tue Aug 18 13:03:39.237223 2026] [security2:error] [pid 139043:tid 139250] [client 20.51.153.15:9836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ep.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxmwAAANI"] [Tue Aug 18 13:03:39.243037 2026] [security2:error] [pid 139043:tid 139274] [client 52.173.121.69:60322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxnAAAAOo"] [Tue Aug 18 13:03:39.269759 2026] [security2:error] [pid 139043:tid 139218] [client 168.62.48.100:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxnQAAALI"] [Tue Aug 18 13:03:39.270380 2026] [security2:error] [pid 139043:tid 139256] [client 40.74.65.169:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/admin.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxngAAANg"] [Tue Aug 18 13:03:39.343391 2026] [security2:error] [pid 139043:tid 139208] [client 68.155.156.252:13348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/images.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxpQAAAKg"] [Tue Aug 18 13:03:39.344014 2026] [security2:error] [pid 139043:tid 139232] [client 20.186.30.159:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/fi.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxpgAAAMA"] [Tue Aug 18 13:03:39.347675 2026] [security2:error] [pid 139043:tid 139242] [client 168.62.48.100:1186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxpwAAAMo"] [Tue Aug 18 13:03:39.419548 2026] [security2:error] [pid 139043:tid 139223] [client 20.151.109.219:21917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fo.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxsgAAALc"] [Tue Aug 18 13:03:39.421130 2026] [security2:error] [pid 139043:tid 139194] [client 172.182.217.32:21509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/cloud.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxswAAAJo"] [Tue Aug 18 13:03:39.438182 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.73.37:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/dex.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxtAAAAKI"] [Tue Aug 18 13:03:39.447879 2026] [security2:error] [pid 139043:tid 139215] [client 20.1.169.243:10886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxtQAAAK8"] [Tue Aug 18 13:03:39.452103 2026] [security2:error] [pid 139043:tid 139277] [client 20.226.36.136:57253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxuAAAAO0"] [Tue Aug 18 13:03:39.452692 2026] [security2:error] [pid 139043:tid 139053] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxtgAAyQk"] [Tue Aug 18 13:03:39.452861 2026] [security2:error] [pid 139043:tid 139241] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxtgAAyQk"] [Tue Aug 18 13:03:39.462696 2026] [authz_core:error] [pid 139043:tid 139051] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:39.463134 2026] [authz_core:error] [pid 139043:tid 139051] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:39.488157 2026] [security2:error] [pid 139043:tid 139182] [client 158.23.17.4:54783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rh.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxugAAAI4"] [Tue Aug 18 13:03:39.495834 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:9589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/rf.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxuwAAAOQ"] [Tue Aug 18 13:03:39.510053 2026] [security2:error] [pid 139043:tid 139186] [client 4.232.151.198:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/goods.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxvAAAAJI"] [Tue Aug 18 13:03:39.538046 2026] [security2:error] [pid 139043:tid 139187] [client 20.25.139.174:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/bless.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxvgAAAJM"] [Tue Aug 18 13:03:39.547979 2026] [security2:error] [pid 139043:tid 139248] [client 68.155.154.236:8848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxvwAAANA"] [Tue Aug 18 13:03:39.575109 2026] [security2:error] [pid 139043:tid 139197] [client 74.248.18.37:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxwwAAAJ0"] [Tue Aug 18 13:03:39.584025 2026] [security2:error] [pid 139043:tid 139221] [client 132.196.30.78:6315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxxAAAALU"] [Tue Aug 18 13:03:39.627173 2026] [security2:error] [pid 139043:tid 139262] [client 20.80.111.3:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/.well-known/pki-validation/about.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxxwAAAN4"] [Tue Aug 18 13:03:39.658124 2026] [security2:error] [pid 139043:tid 139258] [client 20.186.30.159:1812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/chris.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxyQAAANo"] [Tue Aug 18 13:03:39.691855 2026] [security2:error] [pid 139043:tid 139174] [client 213.35.127.232:50639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxygAAAIY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:39.699344 2026] [security2:error] [pid 139043:tid 139180] [client 158.23.17.4:56721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/qo.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxywAAAIw"] [Tue Aug 18 13:03:39.732557 2026] [security2:error] [pid 139043:tid 139272] [client 4.232.151.198:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxzAAAAOg"] [Tue Aug 18 13:03:39.753471 2026] [security2:error] [pid 139043:tid 139289] [client 20.206.73.37:20730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/mosty.php"] [unique_id "aoSCW_2v-lWn9OzQT7UxzwAAAPk"] [Tue Aug 18 13:03:39.757079 2026] [security2:error] [pid 139043:tid 139193] [client 20.250.13.23:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux0AAAAJk"] [Tue Aug 18 13:03:39.781300 2026] [security2:error] [pid 139043:tid 139267] [client 20.52.168.85:5291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/form.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux0QAAAOM"] [Tue Aug 18 13:03:39.782065 2026] [security2:error] [pid 139043:tid 139195] [client 168.62.48.100:1173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux0gAAAJs"] [Tue Aug 18 13:03:39.791852 2026] [security2:error] [pid 139043:tid 139181] [client 149.34.210.141:50086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux1AAAAI0"] [Tue Aug 18 13:03:39.806186 2026] [security2:error] [pid 139043:tid 139266] [client 20.116.17.175:53811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/v2.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux1gAAAOI"] [Tue Aug 18 13:03:39.811392 2026] [security2:error] [pid 139043:tid 139192] [client 20.51.153.15:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xynz1.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux1wAAAJg"] [Tue Aug 18 13:03:39.820398 2026] [security2:error] [pid 139043:tid 139238] [client 20.1.169.243:10932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux2gAAAMY"] [Tue Aug 18 13:03:39.854301 2026] [security2:error] [pid 139043:tid 139178] [client 168.62.48.100:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux3wAAAIo"] [Tue Aug 18 13:03:39.897446 2026] [security2:error] [pid 139043:tid 139274] [client 68.221.73.131:48378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/biufile.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux4QAAAOo"] [Tue Aug 18 13:03:39.908976 2026] [security2:error] [pid 139043:tid 139297] [client 20.186.30.159:1943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/doc.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux4wAAAQE"] [Tue Aug 18 13:03:39.931280 2026] [security2:error] [pid 139043:tid 139280] [client 172.182.217.32:21518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/libraries/legacy/updates.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux5QAAAPA"] [Tue Aug 18 13:03:39.980888 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.36.136:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux5wAAAMo"] [Tue Aug 18 13:03:39.986348 2026] [security2:error] [pid 139043:tid 139299] [client 4.223.113.180:12110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/theme.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux6AAAAQM"] [Tue Aug 18 13:03:39.992318 2026] [security2:error] [pid 139043:tid 139264] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux6gAAAOA"] [Tue Aug 18 13:03:39.992343 2026] [security2:error] [pid 139043:tid 139190] [client 20.79.204.6:9286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/chosen.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux6QAAAJY"] [Tue Aug 18 13:03:39.998643 2026] [security2:error] [pid 139043:tid 139223] [client 52.173.121.69:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux6wAAALc"] [Tue Aug 18 13:03:40.007032 2026] [security2:error] [pid 139043:tid 139194] [client 158.23.17.4:8764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wu.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux7AAAAJo"] [Tue Aug 18 13:03:40.057029 2026] [security2:error] [pid 139043:tid 139181] [client 149.34.210.141:50086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCW_2v-lWn9OzQT7Ux1AAAAI0"] [Tue Aug 18 13:03:40.060813 2026] [authz_core:error] [pid 139043:tid 139170] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:40.061087 2026] [authz_core:error] [pid 139043:tid 139170] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:40.064410 2026] [security2:error] [pid 139043:tid 139256] [client 20.80.111.3:25984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/post.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux7wAAANg"] [Tue Aug 18 13:03:40.071644 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.73.37:28690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux8AAAAOw"] [Tue Aug 18 13:03:40.099436 2026] [security2:error] [pid 139043:tid 139201] [client 20.25.139.174:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/sagax1.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux8gAAAKE"] [Tue Aug 18 13:03:40.142136 2026] [security2:error] [pid 139043:tid 139199] [client 4.232.151.198:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux9AAAAJ8"] [Tue Aug 18 13:03:40.152505 2026] [security2:error] [pid 139043:tid 139283] [client 20.51.153.15:8257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vo.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux9QAAAPM"] [Tue Aug 18 13:03:40.154682 2026] [security2:error] [pid 139043:tid 139235] [client 20.186.30.159:1968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/1337.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux9gAAAMM"] [Tue Aug 18 13:03:40.168457 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.154.236:41485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux9wAAAOQ"] [Tue Aug 18 13:03:40.197132 2026] [security2:error] [pid 139043:tid 139209] [client 20.1.169.243:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/test.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux-AAAAKk"] [Tue Aug 18 13:03:40.202006 2026] [security2:error] [pid 139043:tid 139214] [client 168.62.48.100:1174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux-gAAAK4"] [Tue Aug 18 13:03:40.224903 2026] [security2:error] [pid 139043:tid 139176] [client 40.74.65.169:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.trokarautomoveis.com.br"] [uri "/ajax.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux_AAAAIg"] [Tue Aug 18 13:03:40.275741 2026] [security2:error] [pid 139043:tid 139260] [client 158.23.17.4:8688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/yg.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux_QAAANw"] [Tue Aug 18 13:03:40.287327 2026] [security2:error] [pid 139043:tid 139241] [client 74.248.18.37:3770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCXP2v-lWn9OzQT7Ux_gAAAMk"] [Tue Aug 18 13:03:40.357254 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyAQAAAMU"] [Tue Aug 18 13:03:40.361756 2026] [authz_core:error] [pid 139043:tid 139144] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:40.362006 2026] [authz_core:error] [pid 139043:tid 139144] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:40.365628 2026] [security2:error] [pid 139043:tid 139226] [client 20.116.17.175:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wkl.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyAgAAALo"] [Tue Aug 18 13:03:40.367212 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/maxro.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyAwAAAPs"] [Tue Aug 18 13:03:40.390086 2026] [security2:error] [pid 139043:tid 139186] [client 20.52.168.85:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-sigunq.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyBAAAAJI"] [Tue Aug 18 13:03:40.396289 2026] [security2:error] [pid 139043:tid 139246] [client 20.51.153.15:9743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wu.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyBQAAAM4"] [Tue Aug 18 13:03:40.400390 2026] [security2:error] [pid 139043:tid 139259] [client 20.186.30.159:1664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/Njima.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyBwAAANs"] [Tue Aug 18 13:03:40.418707 2026] [security2:error] [pid 139043:tid 139255] [client 20.206.73.37:20726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/blurbs.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyCAAAANc"] [Tue Aug 18 13:03:40.422545 2026] [security2:error] [pid 139043:tid 139197] [client 4.232.151.198:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/al.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyCgAAAJ0"] [Tue Aug 18 13:03:40.436916 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.217.32:21842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/libraries/phpmailer/updates.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyCwAAALY"] [Tue Aug 18 13:03:40.443105 2026] [security2:error] [pid 139043:tid 139216] [client 20.250.13.23:3619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyDAAAALA"] [Tue Aug 18 13:03:40.463535 2026] [security2:error] [pid 139043:tid 139213] [client 168.62.48.100:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyDQAAAK0"] [Tue Aug 18 13:03:40.506305 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:10612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/loading.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyDwAAANU"] [Tue Aug 18 13:03:40.536770 2026] [security2:error] [pid 139043:tid 139238] [client 68.155.154.236:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyEQAAAMY"] [Tue Aug 18 13:03:40.540643 2026] [security2:error] [pid 139043:tid 139179] [client 20.80.111.3:25816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/flower.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyEgAAAIs"] [Tue Aug 18 13:03:40.554956 2026] [security2:error] [pid 139043:tid 139263] [client 168.62.48.100:1236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyEwAAAN8"] [Tue Aug 18 13:03:40.568860 2026] [security2:error] [pid 139043:tid 139193] [client 20.1.169.243:10905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyFQAAAJk"] [Tue Aug 18 13:03:40.600809 2026] [security2:error] [pid 139043:tid 139219] [client 168.62.48.100:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyFgAAALM"] [Tue Aug 18 13:03:40.607277 2026] [security2:error] [pid 139043:tid 139218] [client 68.221.73.131:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/dejavu.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyFwAAALI"] [Tue Aug 18 13:03:40.624841 2026] [security2:error] [pid 139043:tid 139278] [client 20.25.139.174:4726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wpc.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyGAAAAO4"] [Tue Aug 18 13:03:40.635856 2026] [security2:error] [pid 139043:tid 139293] [client 158.23.17.4:40410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sd.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyGQAAAP0"] [Tue Aug 18 13:03:40.665535 2026] [authz_core:error] [pid 139043:tid 139081] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:40.665813 2026] [authz_core:error] [pid 139043:tid 139081] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:40.705882 2026] [security2:error] [pid 139043:tid 139300] [client 213.35.127.232:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyHAAAAQQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:40.710892 2026] [security2:error] [pid 139043:tid 139184] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/admin.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyHQAAAJA"] [Tue Aug 18 13:03:40.728717 2026] [security2:error] [pid 139043:tid 139295] [client 20.186.30.159:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyIAAAAP8"] [Tue Aug 18 13:03:40.766131 2026] [security2:error] [pid 139043:tid 139243] [client 4.232.151.198:4174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/htaccess.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyJAAAAMs"] [Tue Aug 18 13:03:40.770339 2026] [security2:error] [pid 139043:tid 139131] [remote 172.238.58.237:55532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carnescapellari.top"] [uri "/"] [unique_id "aoSCXP2v-lWn9OzQT7UyIwAA0lc"] [Tue Aug 18 13:03:40.771056 2026] [security2:error] [pid 139043:tid 139098] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSCXP2v-lWn9OzQT7UyJQAA_jY"] [Tue Aug 18 13:03:40.778801 2026] [security2:error] [pid 139043:tid 139223] [client 20.51.153.15:9807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/de.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyJgAAALc"] [Tue Aug 18 13:03:40.798982 2026] [security2:error] [pid 139043:tid 139229] [client 157.20.138.62:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyJwAAAL0"] [Tue Aug 18 13:03:40.799077 2026] [security2:error] [pid 139043:tid 139229] [client 157.20.138.62:55269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyJwAAAL0"] [Tue Aug 18 13:03:40.821087 2026] [security2:error] [pid 139043:tid 139181] [client 68.155.156.252:40544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/mac.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyKQAAAI0"] [Tue Aug 18 13:03:40.859029 2026] [security2:error] [pid 139043:tid 139264] [client 138.36.100.162:42413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyKwAAAOA"] [Tue Aug 18 13:03:40.859127 2026] [security2:error] [pid 139043:tid 139264] [client 138.36.100.162:42413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyKwAAAOA"] [Tue Aug 18 13:03:40.918239 2026] [security2:error] [pid 139043:tid 139240] [client 74.248.18.37:3422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSCXP2v-lWn9OzQT7UyLQAAAMg"] [Tue Aug 18 13:03:40.923715 2026] [security2:error] [pid 139043:tid 139225] [client 168.62.48.100:1257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyLgAAALk"] [Tue Aug 18 13:03:40.926467 2026] [security2:error] [pid 139043:tid 139296] [client 20.206.73.37:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/bajah.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyLwAAAQA"] [Tue Aug 18 13:03:40.927579 2026] [security2:error] [pid 139043:tid 139288] [client 172.182.217.32:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/libraries/vendor/updates.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyMAAAAPg"] [Tue Aug 18 13:03:40.939214 2026] [security2:error] [pid 139043:tid 139268] [client 20.116.17.175:3444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-asudo.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyMgAAAOQ"] [Tue Aug 18 13:03:40.939879 2026] [security2:error] [pid 139043:tid 139215] [client 20.1.169.243:10914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyMwAAAK8"] [Tue Aug 18 13:03:40.963737 2026] [authz_core:error] [pid 139043:tid 139093] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:40.963996 2026] [authz_core:error] [pid 139043:tid 139093] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:40.995133 2026] [security2:error] [pid 139043:tid 139194] [client 20.52.168.85:5134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/07.php"] [unique_id "aoSCXP2v-lWn9OzQT7UyOQAAAJo"] [Tue Aug 18 13:03:41.013441 2026] [security2:error] [pid 139043:tid 139084] [remote 139.28.219.68:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "media.idealquimica.com"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyOwAA0Sg"] [Tue Aug 18 13:03:41.025364 2026] [security2:error] [pid 139043:tid 139180] [client 68.155.154.236:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyPgAAAIw"] [Tue Aug 18 13:03:41.037830 2026] [security2:error] [pid 139043:tid 139245] [client 20.51.153.15:9788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/album.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyPwAAAM0"] [Tue Aug 18 13:03:41.052304 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.151.198:10373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyQQAAANg"] [Tue Aug 18 13:03:41.053647 2026] [security2:error] [pid 139043:tid 139276] [client 20.80.111.3:26269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyQgAAAOw"] [Tue Aug 18 13:03:41.057140 2026] [security2:error] [pid 139043:tid 139272] [client 158.23.17.4:47875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/et.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyQwAAAOg"] [Tue Aug 18 13:03:41.067729 2026] [security2:error] [pid 139043:tid 139275] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/public/css.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyRAAAAOs"] [Tue Aug 18 13:03:41.075430 2026] [security2:error] [pid 139043:tid 139261] [client 20.250.13.23:3410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-blink.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyRQAAAN0"] [Tue Aug 18 13:03:41.085107 2026] [security2:error] [pid 139043:tid 139222] [client 168.62.48.100:4141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyRgAAALY"] [Tue Aug 18 13:03:41.089619 2026] [security2:error] [pid 139043:tid 139267] [client 20.186.30.159:1671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/too.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyRwAAAOM"] [Tue Aug 18 13:03:41.179952 2026] [security2:error] [pid 139043:tid 139298] [client 158.23.17.4:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/de.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyTQAAAQI"] [Tue Aug 18 13:03:41.181847 2026] [security2:error] [pid 139043:tid 139258] [client 20.25.139.174:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/fone1.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyTgAAANo"] [Tue Aug 18 13:03:41.240520 2026] [security2:error] [pid 139043:tid 139279] [client 103.120.71.157:33717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyUAAAAO8"] [Tue Aug 18 13:03:41.240642 2026] [security2:error] [pid 139043:tid 139279] [client 103.120.71.157:33717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyUAAAAO8"] [Tue Aug 18 13:03:41.264895 2026] [authz_core:error] [pid 139043:tid 139106] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:41.265080 2026] [security2:error] [pid 139043:tid 139293] [client 168.62.48.100:1221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyUwAAAP0"] [Tue Aug 18 13:03:41.265156 2026] [authz_core:error] [pid 139043:tid 139106] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:41.276736 2026] [security2:error] [pid 139043:tid 139227] [client 20.51.153.15:9499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kv.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyVAAAALs"] [Tue Aug 18 13:03:41.299708 2026] [security2:error] [pid 139043:tid 139257] [client 178.153.171.161:35042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyVgAAANk"] [Tue Aug 18 13:03:41.299885 2026] [security2:error] [pid 139043:tid 139257] [client 178.153.171.161:35042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyVgAAANk"] [Tue Aug 18 13:03:41.307811 2026] [security2:error] [pid 139043:tid 139183] [client 20.1.169.243:10921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyWQAAAI8"] [Tue Aug 18 13:03:41.317748 2026] [security2:error] [pid 139043:tid 139155] [remote 172.238.58.237:55538] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carnescapellari.top"] [uri "/"] [unique_id "aoSCXf2v-lWn9OzQT7UyWgAA6W8"] [Tue Aug 18 13:03:41.340431 2026] [security2:error] [pid 139043:tid 139184] [client 68.155.154.236:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyXAAAAJA"] [Tue Aug 18 13:03:41.355786 2026] [security2:error] [pid 139043:tid 139138] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyXgAA214"] [Tue Aug 18 13:03:41.355974 2026] [security2:error] [pid 139043:tid 139259] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyXgAA214"] [Tue Aug 18 13:03:41.375541 2026] [security2:error] [pid 139043:tid 139243] [client 20.226.36.136:57223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyXwAAAMs"] [Tue Aug 18 13:03:41.390815 2026] [security2:error] [pid 139043:tid 139263] [client 4.232.151.198:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/images/wso.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyYgAAAN8"] [Tue Aug 18 13:03:41.414800 2026] [security2:error] [pid 139043:tid 139278] [client 172.182.217.32:21774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfanew.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyZAAAAO4"] [Tue Aug 18 13:03:41.421120 2026] [security2:error] [pid 139043:tid 139181] [client 20.151.109.219:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ke.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyZQAAAI0"] [Tue Aug 18 13:03:41.424286 2026] [security2:error] [pid 139043:tid 139281] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyZgAAAPE"] [Tue Aug 18 13:03:41.426251 2026] [security2:error] [pid 139043:tid 139284] [client 168.62.48.100:5477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyZwAAAPQ"] [Tue Aug 18 13:03:41.434117 2026] [security2:error] [pid 139043:tid 139287] [client 20.186.30.159:1947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mkstecnologias.com.br"] [uri "/g3.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyaAAAAPc"] [Tue Aug 18 13:03:41.484042 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.156.252:14779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/ops.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyagAAAPM"] [Tue Aug 18 13:03:41.496487 2026] [security2:error] [pid 139043:tid 139299] [client 20.80.111.3:26250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyawAAAQM"] [Tue Aug 18 13:03:41.565739 2026] [authz_core:error] [pid 139043:tid 139163] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:41.566001 2026] [authz_core:error] [pid 139043:tid 139163] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:41.581983 2026] [security2:error] [pid 139043:tid 139209] [client 168.62.48.100:1192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCXf2v-lWn9OzQT7UycAAAAKk"] [Tue Aug 18 13:03:41.598936 2026] [security2:error] [pid 139043:tid 139262] [client 168.62.48.100:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCXf2v-lWn9OzQT7UycQAAAN4"] [Tue Aug 18 13:03:41.604110 2026] [security2:error] [pid 139043:tid 139204] [client 68.221.73.131:29980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/aaf.php"] [unique_id "aoSCXf2v-lWn9OzQT7UycgAAAKQ"] [Tue Aug 18 13:03:41.609152 2026] [security2:error] [pid 139043:tid 139202] [client 20.52.168.85:5707] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "valeriana.com.br"] [uri "/c99.php"] [unique_id "aoSCXf2v-lWn9OzQT7UycwAAAKI"] [Tue Aug 18 13:03:41.623390 2026] [security2:error] [pid 139043:tid 139177] [client 20.51.153.15:8271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/z.php"] [unique_id "aoSCXf2v-lWn9OzQT7UydAAAAIk"] [Tue Aug 18 13:03:41.653590 2026] [security2:error] [pid 139043:tid 139230] [client 74.248.18.37:56727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSCXf2v-lWn9OzQT7UydQAAAL4"] [Tue Aug 18 13:03:41.693013 2026] [security2:error] [pid 139043:tid 139224] [client 20.1.169.243:10918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-login.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyeAAAALg"] [Tue Aug 18 13:03:41.693921 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wdf.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyeQAAAIw"] [Tue Aug 18 13:03:41.696447 2026] [security2:error] [pid 139043:tid 139179] [client 4.232.151.198:11949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/index/function.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyegAAAIs"] [Tue Aug 18 13:03:41.701604 2026] [security2:error] [pid 139043:tid 139268] [client 20.25.139.174:4446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ncx.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyewAAAOQ"] [Tue Aug 18 13:03:41.703169 2026] [security2:error] [pid 139043:tid 139182] [client 20.250.13.23:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-blog-header.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyfAAAAI4"] [Tue Aug 18 13:03:41.731544 2026] [security2:error] [pid 139043:tid 139223] [client 213.35.127.232:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyfgAAALc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:41.743542 2026] [security2:error] [pid 139043:tid 139277] [client 20.116.17.175:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/az.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyfwAAAO0"] [Tue Aug 18 13:03:41.812263 2026] [security2:error] [pid 139043:tid 139206] [client 4.232.151.198:10395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-activat.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyhQAAAKY"] [Tue Aug 18 13:03:41.826958 2026] [security2:error] [pid 139043:tid 139192] [client 68.155.154.236:40225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyhgAAAJg"] [Tue Aug 18 13:03:41.866329 2026] [security2:error] [pid 139043:tid 139159] [remote 172.238.58.237:41460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carnescapellari.top"] [uri "/"] [unique_id "aoSCXf2v-lWn9OzQT7UyiwAA-3M"] [Tue Aug 18 13:03:41.866464 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:41.866714 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:41.870012 2026] [security2:error] [pid 139043:tid 139193] [client 20.226.36.136:57250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyjAAAAJk"] [Tue Aug 18 13:03:41.907635 2026] [security2:error] [pid 139043:tid 139219] [client 20.51.153.15:9548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xg.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyjQAAALM"] [Tue Aug 18 13:03:41.921223 2026] [security2:error] [pid 139043:tid 139213] [client 74.7.230.49:39004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bjseeds.com"] [uri "/cgi-sys/404.html"] [unique_id "aoSCXf2v-lWn9OzQT7UyjgAArVk"] [Tue Aug 18 13:03:41.931553 2026] [security2:error] [pid 139043:tid 139217] [client 158.23.17.4:38895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/album.php"] [unique_id "aoSCXf2v-lWn9OzQT7UyjwAAALE"] [Tue Aug 18 13:03:41.939022 2026] [security2:error] [pid 139043:tid 139211] [client 132.196.30.78:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCXf2v-lWn9OzQT7UykQAAAKs"] [Tue Aug 18 13:03:41.946465 2026] [security2:error] [pid 139043:tid 139261] [client 172.182.217.32:21533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSCXf2v-lWn9OzQT7UykgAAAN0"] [Tue Aug 18 13:03:41.951884 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:47263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCXf2v-lWn9OzQT7UykwAAAP0"] [Tue Aug 18 13:03:41.952459 2026] [security2:error] [pid 139043:tid 139227] [client 168.62.48.100:1040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCXf2v-lWn9OzQT7UylAAAALs"] [Tue Aug 18 13:03:41.980615 2026] [security2:error] [pid 139043:tid 139257] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCXf2v-lWn9OzQT7UylQAAANk"] [Tue Aug 18 13:03:42.005679 2026] [security2:error] [pid 139043:tid 139200] [client 20.80.111.3:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/jp.php"] [unique_id "aoSCXv2v-lWn9OzQT7UylgAAAKA"] [Tue Aug 18 13:03:42.011488 2026] [security2:error] [pid 139043:tid 139270] [client 4.232.151.198:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/index/function.php"] [unique_id "aoSCXv2v-lWn9OzQT7UylwAAAOY"] [Tue Aug 18 13:03:42.018235 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/of.php"] [unique_id "aoSCXv2v-lWn9OzQT7UymAAAAOk"] [Tue Aug 18 13:03:42.066939 2026] [security2:error] [pid 139043:tid 139276] [client 114.119.136.5:47181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marciamirandaspimoveis.com.br"] [uri "/images/imoveis/451/"] [unique_id "aoSCXv2v-lWn9OzQT7UymwAAAOw"], referer: https://www.marciamirandaspimoveis.com.br/images/imoveis/451?C=N%3BO%3DD [Tue Aug 18 13:03:42.077631 2026] [security2:error] [pid 139043:tid 139188] [client 20.1.169.243:10881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSCXv2v-lWn9OzQT7UynAAAAJQ"] [Tue Aug 18 13:03:42.110536 2026] [security2:error] [pid 139043:tid 139281] [client 20.206.73.37:34806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/uwu.php"] [unique_id "aoSCXv2v-lWn9OzQT7UynQAAAPE"] [Tue Aug 18 13:03:42.167540 2026] [authz_core:error] [pid 139043:tid 139056] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:42.167840 2026] [authz_core:error] [pid 139043:tid 139056] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:42.173731 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:27359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nh.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyoQAAAPM"] [Tue Aug 18 13:03:42.177247 2026] [security2:error] [pid 139043:tid 139199] [client 20.79.204.6:9727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/index.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyogAAAJ8"] [Tue Aug 18 13:03:42.180230 2026] [security2:error] [pid 139043:tid 139235] [client 20.51.153.15:9523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/nd.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyowAAAMM"] [Tue Aug 18 13:03:42.209991 2026] [security2:error] [pid 139043:tid 139183] [client 20.52.168.85:5274] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "valeriana.com.br"] [uri "/c99.php"] [unique_id "aoSCXv2v-lWn9OzQT7UypQAAAI8"] [Tue Aug 18 13:03:42.235046 2026] [security2:error] [pid 139043:tid 139128] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSCXv2v-lWn9OzQT7UypgAA3FQ"] [Tue Aug 18 13:03:42.322086 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:30792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-blog.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyqQAAAPQ"] [Tue Aug 18 13:03:42.333385 2026] [security2:error] [pid 139043:tid 139230] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/gelay.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyqgAAAL4"] [Tue Aug 18 13:03:42.342438 2026] [security2:error] [pid 139043:tid 139174] [client 168.62.48.100:1271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyqwAAAIY"] [Tue Aug 18 13:03:42.371162 2026] [security2:error] [pid 139043:tid 139229] [client 74.248.18.37:56755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyrAAAAL0"] [Tue Aug 18 13:03:42.395277 2026] [security2:error] [pid 139043:tid 139268] [client 68.221.73.131:18617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyrgAAAOQ"] [Tue Aug 18 13:03:42.415651 2026] [security2:error] [pid 139043:tid 139074] [remote 172.238.58.237:41474] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "carnescapellari.top"] [uri "/"] [unique_id "aoSCXv2v-lWn9OzQT7UysAAA2B4"] [Tue Aug 18 13:03:42.426921 2026] [security2:error] [pid 139043:tid 139190] [client 20.25.139.174:4423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCXv2v-lWn9OzQT7UysQAAAJY"] [Tue Aug 18 13:03:42.429388 2026] [security2:error] [pid 139043:tid 139275] [client 158.23.17.4:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/bu.php"] [unique_id "aoSCXv2v-lWn9OzQT7UysgAAAOs"] [Tue Aug 18 13:03:42.440522 2026] [security2:error] [pid 139043:tid 139204] [client 172.182.217.32:21554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-p.php7"] [unique_id "aoSCXv2v-lWn9OzQT7UyswAAAKQ"] [Tue Aug 18 13:03:42.444745 2026] [security2:error] [pid 139043:tid 139226] [client 20.1.169.243:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSCXv2v-lWn9OzQT7UytAAAALo"] [Tue Aug 18 13:03:42.457809 2026] [security2:error] [pid 139043:tid 139177] [client 20.80.111.3:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSCXv2v-lWn9OzQT7UytQAAAIk"] [Tue Aug 18 13:03:42.467102 2026] [security2:error] [pid 139043:tid 139206] [client 20.51.153.15:9484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ri.php"] [unique_id "aoSCXv2v-lWn9OzQT7UytwAAAKY"] [Tue Aug 18 13:03:42.470954 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:42.471215 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:42.497013 2026] [security2:error] [pid 139043:tid 139266] [client 20.206.73.37:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/h.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyuQAAAOI"] [Tue Aug 18 13:03:42.513072 2026] [security2:error] [pid 139043:tid 139258] [client 4.223.113.180:12105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyvAAAANo"] [Tue Aug 18 13:03:42.540099 2026] [security2:error] [pid 139043:tid 139214] [client 4.232.151.198:48395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyvQAAAK4"] [Tue Aug 18 13:03:42.542176 2026] [security2:error] [pid 139043:tid 139067] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSCXv2v-lWn9OzQT7UyvgAA5Rc"] [Tue Aug 18 13:03:42.544203 2026] [security2:error] [pid 139043:tid 139274] [client 68.155.156.252:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/coffexium.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyvwAAAOo"] [Tue Aug 18 13:03:42.585362 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/km.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyxQAAAPA"] [Tue Aug 18 13:03:42.628519 2026] [security2:error] [pid 139043:tid 139277] [client 4.232.151.198:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/info.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyxwAAAO0"] [Tue Aug 18 13:03:42.652481 2026] [security2:error] [pid 139043:tid 139273] [client 20.116.17.175:56119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/z43agz.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyyQAAAOk"] [Tue Aug 18 13:03:42.693785 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyzAAAAKg"] [Tue Aug 18 13:03:42.695451 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kv.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyzQAAAQQ"] [Tue Aug 18 13:03:42.699834 2026] [security2:error] [pid 139043:tid 139210] [client 103.184.169.37:43629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyzgAAAKo"] [Tue Aug 18 13:03:42.700119 2026] [security2:error] [pid 139043:tid 139210] [client 103.184.169.37:43629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyzgAAAKo"] [Tue Aug 18 13:03:42.701867 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:1207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCXv2v-lWn9OzQT7UyzwAAAJA"] [Tue Aug 18 13:03:42.733544 2026] [security2:error] [pid 139043:tid 139205] [client 132.196.30.78:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy0gAAAKU"] [Tue Aug 18 13:03:42.747976 2026] [security2:error] [pid 139043:tid 139282] [client 213.35.127.232:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy0wAAAPI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:42.770507 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rn.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy1wAAAJQ"] [Tue Aug 18 13:03:42.775658 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:42.776132 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:42.800698 2026] [security2:error] [pid 139043:tid 139281] [client 20.51.153.15:9821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/tp.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy2AAAAPE"] [Tue Aug 18 13:03:42.804026 2026] [security2:error] [pid 139043:tid 139287] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ff1.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy2gAAAPc"] [Tue Aug 18 13:03:42.824936 2026] [security2:error] [pid 139043:tid 139203] [client 20.52.168.85:5152] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "valeriana.com.br"] [uri "/c99.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy2wAAAKM"] [Tue Aug 18 13:03:42.867975 2026] [security2:error] [pid 139043:tid 139295] [client 20.1.169.243:11187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/002.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy3QAAAP8"] [Tue Aug 18 13:03:42.883181 2026] [security2:error] [pid 139043:tid 139220] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/guk.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy3gAAALQ"] [Tue Aug 18 13:03:42.898465 2026] [security2:error] [pid 139043:tid 139243] [client 20.80.111.3:26246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy3wAAAMs"] [Tue Aug 18 13:03:42.934887 2026] [security2:error] [pid 139043:tid 139088] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSCXv2v-lWn9OzQT7Uy4QAA9iw"] [Tue Aug 18 13:03:42.952142 2026] [security2:error] [pid 139043:tid 139278] [client 172.182.217.32:21558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/repeater.php"] [unique_id "aoSCXv2v-lWn9OzQT7Uy4wAAAO4"] [Tue Aug 18 13:03:43.012360 2026] [security2:error] [pid 139043:tid 139174] [client 20.226.36.136:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy5gAAAIY"] [Tue Aug 18 13:03:43.042585 2026] [security2:error] [pid 139043:tid 139183] [client 20.25.139.174:4639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wso.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy6AAAAI8"] [Tue Aug 18 13:03:43.045967 2026] [security2:error] [pid 139043:tid 139186] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy6QAAAJI"] [Tue Aug 18 13:03:43.056372 2026] [security2:error] [pid 139043:tid 139240] [client 20.250.13.23:53173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-blogs.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy6wAAAMg"] [Tue Aug 18 13:03:43.073856 2026] [authz_core:error] [pid 139043:tid 139094] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:43.074130 2026] [authz_core:error] [pid 139043:tid 139094] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:43.087806 2026] [security2:error] [pid 139043:tid 139246] [client 20.51.153.15:9526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/zj.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy7QAAAM4"] [Tue Aug 18 13:03:43.146578 2026] [security2:error] [pid 139043:tid 139204] [client 168.62.48.100:1147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy8AAAAKQ"] [Tue Aug 18 13:03:43.169882 2026] [security2:error] [pid 139043:tid 139181] [client 74.248.18.37:3712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy5QAAAI0"] [Tue Aug 18 13:03:43.171387 2026] [security2:error] [pid 139043:tid 139249] [client 4.232.151.198:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/past1.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy8gAAANE"] [Tue Aug 18 13:03:43.187095 2026] [security2:error] [pid 139043:tid 139197] [client 68.155.154.236:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy8wAAAJ0"] [Tue Aug 18 13:03:43.190675 2026] [security2:error] [pid 139043:tid 139225] [client 4.232.151.198:44143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/aaa.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy9AAAALk"] [Tue Aug 18 13:03:43.204172 2026] [security2:error] [pid 139043:tid 139177] [client 168.62.48.100:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy9gAAAIk"] [Tue Aug 18 13:03:43.233665 2026] [security2:error] [pid 139043:tid 139228] [client 158.23.17.4:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ut.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy-QAAALw"] [Tue Aug 18 13:03:43.237122 2026] [security2:error] [pid 139043:tid 139256] [client 20.1.169.243:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/0x.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy-gAAANg"] [Tue Aug 18 13:03:43.254431 2026] [security2:error] [pid 139043:tid 139180] [client 4.232.151.198:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/profile.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy-wAAAIw"] [Tue Aug 18 13:03:43.298186 2026] [security2:error] [pid 139043:tid 139214] [client 68.221.73.131:18586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/155.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy_QAAAK4"] [Tue Aug 18 13:03:43.323769 2026] [security2:error] [pid 139043:tid 139116] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSCX_2v-lWn9OzQT7Uy_wAA1Eg"] [Tue Aug 18 13:03:43.337191 2026] [security2:error] [pid 139043:tid 139216] [client 20.80.111.3:1391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzAAAAALA"] [Tue Aug 18 13:03:43.375034 2026] [security2:error] [pid 139043:tid 139213] [client 20.51.153.15:9490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/x.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzBAAAAK0"] [Tue Aug 18 13:03:43.375527 2026] [authz_core:error] [pid 139043:tid 139105] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:43.375806 2026] [authz_core:error] [pid 139043:tid 139105] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:43.400662 2026] [security2:error] [pid 139043:tid 139284] [client 20.79.204.6:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/vx.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzBwAAAPQ"] [Tue Aug 18 13:03:43.404548 2026] [security2:error] [pid 139043:tid 139236] [client 158.23.17.4:56544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mf.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzCAAAAMQ"] [Tue Aug 18 13:03:43.416209 2026] [security2:error] [pid 139043:tid 139227] [client 158.23.17.4:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/z.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzCQAAALs"] [Tue Aug 18 13:03:43.429685 2026] [security2:error] [pid 139043:tid 139207] [client 20.52.168.85:5136] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "valeriana.com.br"] [uri "/c99.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzCgAAAKc"] [Tue Aug 18 13:03:43.430910 2026] [security2:error] [pid 139043:tid 139242] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-the.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzCwAAAMo"] [Tue Aug 18 13:03:43.441667 2026] [security2:error] [pid 139043:tid 139271] [client 172.182.217.32:21786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/repeater.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzDAAAAOc"] [Tue Aug 18 13:03:43.463004 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.73.37:17070] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "levalixo.com.br"] [uri "/1.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzDQAAAPs"] [Tue Aug 18 13:03:43.463109 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.73.37:17070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/1.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzDQAAAPs"] [Tue Aug 18 13:03:43.542604 2026] [security2:error] [pid 139043:tid 139298] [client 193.36.225.231:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.net"] [uri "/wp-login.php"] [unique_id "aoSCX_2v-lWn9OzQT7Uy9QAAAQI"] [Tue Aug 18 13:03:43.553211 2026] [security2:error] [pid 139043:tid 139261] [client 20.25.139.174:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/zup.php73"] [unique_id "aoSCX_2v-lWn9OzQT7UzEwAAAN0"] [Tue Aug 18 13:03:43.605867 2026] [security2:error] [pid 139043:tid 139205] [client 20.1.169.243:11221] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzFgAAAKU"] [Tue Aug 18 13:03:43.605960 2026] [security2:error] [pid 139043:tid 139205] [client 20.1.169.243:11221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/1.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzFgAAAKU"] [Tue Aug 18 13:03:43.616595 2026] [security2:error] [pid 139043:tid 139283] [client 168.62.48.100:1250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzFwAAAPM"] [Tue Aug 18 13:03:43.665056 2026] [security2:error] [pid 139043:tid 139235] [client 20.206.73.37:59869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ano.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzGQAAAMM"] [Tue Aug 18 13:03:43.675571 2026] [authz_core:error] [pid 139043:tid 139059] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:43.676002 2026] [authz_core:error] [pid 139043:tid 139059] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:43.682699 2026] [security2:error] [pid 139043:tid 139194] [client 37.40.227.74:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzGwAAAJo"] [Tue Aug 18 13:03:43.682840 2026] [security2:error] [pid 139043:tid 139194] [client 37.40.227.74:56729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzGwAAAJo"] [Tue Aug 18 13:03:43.683176 2026] [security2:error] [pid 139043:tid 139208] [client 20.250.13.23:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-config.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzHAAAAKg"] [Tue Aug 18 13:03:43.695592 2026] [security2:error] [pid 139043:tid 139187] [client 20.151.109.219:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/oo.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzHQAAAJM"] [Tue Aug 18 13:03:43.731995 2026] [security2:error] [pid 139043:tid 139150] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSCX_2v-lWn9OzQT7UzHgAAoWo"] [Tue Aug 18 13:03:43.755185 2026] [security2:error] [pid 139043:tid 139238] [client 132.196.30.78:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzHwAAAMY"] [Tue Aug 18 13:03:43.766109 2026] [security2:error] [pid 139043:tid 139292] [client 213.35.127.232:51471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzIQAAAPw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:43.768076 2026] [security2:error] [pid 139043:tid 139244] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzIgAAAMw"] [Tue Aug 18 13:03:43.774579 2026] [security2:error] [pid 139043:tid 139211] [client 20.80.111.3:1366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzIwAAAKs"] [Tue Aug 18 13:03:43.797713 2026] [security2:error] [pid 139043:tid 139287] [client 4.232.151.198:10369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/file61.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzJAAAAPc"] [Tue Aug 18 13:03:43.801008 2026] [security2:error] [pid 139043:tid 139121] [remote 187.75.34.18:22536] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzJQAAwE0"], referer: https://barsantajulia.com.br/buffet/ [Tue Aug 18 13:03:43.804087 2026] [security2:error] [pid 139043:tid 139224] [client 68.155.154.236:40477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzJgAAALg"] [Tue Aug 18 13:03:43.806666 2026] [security2:error] [pid 139043:tid 139183] [client 20.163.43.14:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzJwAAAI8"] [Tue Aug 18 13:03:43.806701 2026] [security2:error] [pid 139043:tid 139179] [client 20.51.153.15:9845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/yn.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzKAAAAIs"] [Tue Aug 18 13:03:43.807150 2026] [security2:error] [pid 139043:tid 139229] [client 68.155.154.236:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzKQAAAL0"] [Tue Aug 18 13:03:43.807212 2026] [security2:error] [pid 139043:tid 139245] [client 20.116.17.175:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/3.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzKgAAAM0"] [Tue Aug 18 13:03:43.807324 2026] [security2:error] [pid 139043:tid 139272] [client 74.248.18.37:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzKwAAAOg"] [Tue Aug 18 13:03:43.859475 2026] [security2:error] [pid 139043:tid 139175] [client 20.206.73.37:22311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/mgrr.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzLgAAAIc"] [Tue Aug 18 13:03:43.863463 2026] [security2:error] [pid 139043:tid 139246] [client 158.23.17.4:60338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/eh.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzLwAAAM4"] [Tue Aug 18 13:03:43.886492 2026] [security2:error] [pid 139043:tid 139197] [client 20.124.247.79:16794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzMQAAAJ0"] [Tue Aug 18 13:03:43.896580 2026] [security2:error] [pid 139043:tid 139243] [client 4.232.151.198:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/sx.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzMgAAAMs"] [Tue Aug 18 13:03:43.943590 2026] [security2:error] [pid 139043:tid 139221] [client 172.182.217.32:21399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/repeater.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzNAAAALU"] [Tue Aug 18 13:03:43.959118 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/about.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzNgAAALw"] [Tue Aug 18 13:03:43.966298 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:18804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xg.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzNwAAANg"] [Tue Aug 18 13:03:43.972875 2026] [security2:error] [pid 139043:tid 139186] [client 20.1.169.243:11231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/100.php"] [unique_id "aoSCX_2v-lWn9OzQT7UzOQAAAJI"] [Tue Aug 18 13:03:43.974750 2026] [authz_core:error] [pid 139043:tid 139096] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:43.975003 2026] [authz_core:error] [pid 139043:tid 139096] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:44.045140 2026] [security2:error] [pid 139043:tid 139204] [client 20.25.139.174:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/k.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzPAAAAKQ"] [Tue Aug 18 13:03:44.072667 2026] [security2:error] [pid 139043:tid 139223] [client 20.52.168.85:5309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wander.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzPgAAALc"] [Tue Aug 18 13:03:44.098699 2026] [security2:error] [pid 139043:tid 139207] [client 20.51.153.15:9493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/11.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzQAAAAKc"] [Tue Aug 18 13:03:44.143560 2026] [security2:error] [pid 139043:tid 139048] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYP2v-lWn9OzQT7UzQgABBAQ"] [Tue Aug 18 13:03:44.206905 2026] [security2:error] [pid 139043:tid 139250] [client 20.163.43.14:4380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzQwAAANI"] [Tue Aug 18 13:03:44.233028 2026] [security2:error] [pid 139043:tid 139263] [client 191.237.254.161:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/inso.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzRQAAAN8"] [Tue Aug 18 13:03:44.234009 2026] [security2:error] [pid 139043:tid 139206] [client 4.232.151.198:38591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/abcd.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzRgAAAKY"] [Tue Aug 18 13:03:44.234759 2026] [security2:error] [pid 139043:tid 139297] [client 20.124.247.79:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzRwAAAQE"] [Tue Aug 18 13:03:44.280028 2026] [authz_core:error] [pid 139043:tid 139075] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:44.280309 2026] [authz_core:error] [pid 139043:tid 139075] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:44.296626 2026] [security2:error] [pid 139043:tid 139184] [client 20.80.111.3:12503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/abe.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzSgAAAJA"] [Tue Aug 18 13:03:44.305382 2026] [autoindex:error] [pid 139043:tid 139259] [client 20.119.58.187:4572] AH01276: Cannot serve directory /home4/agrimotor/teste.agrimotor.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:44.310862 2026] [security2:error] [pid 139043:tid 139276] [client 223.185.37.47:4652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzTQAAAOw"] [Tue Aug 18 13:03:44.310995 2026] [security2:error] [pid 139043:tid 139276] [client 223.185.37.47:4652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzTQAAAOw"] [Tue Aug 18 13:03:44.317771 2026] [security2:error] [pid 139043:tid 139299] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzTgAAAQM"] [Tue Aug 18 13:03:44.324131 2026] [security2:error] [pid 139043:tid 139295] [client 168.62.48.100:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzTwAAAP8"] [Tue Aug 18 13:03:44.325709 2026] [security2:error] [pid 139043:tid 139273] [client 20.250.13.23:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-conflg.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzUAAAAOk"] [Tue Aug 18 13:03:44.331948 2026] [security2:error] [pid 139043:tid 139194] [client 68.221.73.131:26629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/ops.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzUQAAAJo"] [Tue Aug 18 13:03:44.350437 2026] [security2:error] [pid 139043:tid 139296] [client 5.31.227.224:30442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzUwAAAQA"] [Tue Aug 18 13:03:44.350542 2026] [security2:error] [pid 139043:tid 139296] [client 5.31.227.224:30442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzUwAAAQA"] [Tue Aug 18 13:03:44.363766 2026] [security2:error] [pid 139043:tid 139268] [client 197.184.64.235:42663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzVgAAAOQ"] [Tue Aug 18 13:03:44.363866 2026] [security2:error] [pid 139043:tid 139268] [client 197.184.64.235:42663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzVgAAAOQ"] [Tue Aug 18 13:03:44.387837 2026] [security2:error] [pid 139043:tid 139289] [client 20.1.169.243:10915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/2.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzWQAAAPk"] [Tue Aug 18 13:03:44.420058 2026] [security2:error] [pid 139043:tid 139239] [client 4.223.113.180:40509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bi.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzXwAAAMc"] [Tue Aug 18 13:03:44.435261 2026] [security2:error] [pid 139043:tid 139290] [client 172.182.217.32:21528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wsoyanz.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzYAAAAPo"] [Tue Aug 18 13:03:44.449825 2026] [security2:error] [pid 139043:tid 139253] [client 74.248.18.37:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzYQAAANU"] [Tue Aug 18 13:03:44.470660 2026] [security2:error] [pid 139043:tid 139229] [client 158.23.17.4:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/nd.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzYgAAAL0"] [Tue Aug 18 13:03:44.519197 2026] [security2:error] [pid 139043:tid 139175] [client 20.51.153.15:8303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vm.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzZQAAAIc"] [Tue Aug 18 13:03:44.519230 2026] [security2:error] [pid 139043:tid 139199] [client 4.232.151.198:20515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzZAAAAJ8"] [Tue Aug 18 13:03:44.565285 2026] [security2:error] [pid 139043:tid 139178] [client 20.25.139.174:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-blink.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzZgAAAIo"] [Tue Aug 18 13:03:44.580686 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:44.580965 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:44.583871 2026] [security2:error] [pid 139043:tid 139255] [client 20.79.204.6:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wap.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzaQAAANc"] [Tue Aug 18 13:03:44.605433 2026] [security2:error] [pid 139043:tid 139197] [client 20.124.247.79:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzawAAAJ0"] [Tue Aug 18 13:03:44.605802 2026] [security2:error] [pid 139043:tid 139267] [client 20.250.27.191:26101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzbAAAAOM"] [Tue Aug 18 13:03:44.609920 2026] [security2:error] [pid 139043:tid 139243] [client 20.163.43.14:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/admin.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzbQAAAMs"] [Tue Aug 18 13:03:44.627163 2026] [security2:error] [pid 139043:tid 139266] [client 4.232.151.198:31464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.eezy.site"] [uri "/license.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzbgAAAOI"] [Tue Aug 18 13:03:44.643645 2026] [security2:error] [pid 139043:tid 139180] [client 168.62.48.100:1183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzbwAAAIw"] [Tue Aug 18 13:03:44.644524 2026] [security2:error] [pid 139043:tid 139186] [client 168.62.48.100:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzcAAAAJI"] [Tue Aug 18 13:03:44.649975 2026] [security2:error] [pid 139043:tid 139123] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYP2v-lWn9OzQT7UzcQAAuk8"] [Tue Aug 18 13:03:44.660611 2026] [security2:error] [pid 139043:tid 139252] [client 68.155.154.236:64160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzcgAAANQ"] [Tue Aug 18 13:03:44.673085 2026] [security2:error] [pid 139043:tid 139213] [client 74.248.130.103:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/geck.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzdAAAAK0"] [Tue Aug 18 13:03:44.678832 2026] [security2:error] [pid 139043:tid 139245] [client 20.52.168.85:5298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/colour.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzdQAAAM0"] [Tue Aug 18 13:03:44.680490 2026] [security2:error] [pid 139043:tid 139218] [client 158.23.17.4:17536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ad.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzdgAAALI"] [Tue Aug 18 13:03:44.692593 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/f35.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzdwAAAO8"] [Tue Aug 18 13:03:44.715266 2026] [security2:error] [pid 139043:tid 139284] [client 20.151.109.219:17086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ja.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzeAAAAPQ"] [Tue Aug 18 13:03:44.751739 2026] [security2:error] [pid 139043:tid 139195] [client 20.80.111.3:26301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/admin/index_upload.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzewAAAJs"] [Tue Aug 18 13:03:44.757959 2026] [security2:error] [pid 139043:tid 139221] [client 20.1.169.243:10895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/222.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzfQAAALU"] [Tue Aug 18 13:03:44.777396 2026] [security2:error] [pid 139043:tid 139224] [client 213.35.127.232:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzfwAAALg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:44.782841 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.73.37:20705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ai.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzgAAAAPs"] [Tue Aug 18 13:03:44.817071 2026] [security2:error] [pid 139043:tid 139262] [client 20.51.153.15:9820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/eg.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzggAAAN4"] [Tue Aug 18 13:03:44.882193 2026] [authz_core:error] [pid 139043:tid 139132] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:44.882475 2026] [authz_core:error] [pid 139043:tid 139132] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:44.895008 2026] [security2:error] [pid 139043:tid 139261] [client 196.12.128.158:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzhgAAAN0"] [Tue Aug 18 13:03:44.895150 2026] [security2:error] [pid 139043:tid 139261] [client 196.12.128.158:65062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzhgAAAN0"] [Tue Aug 18 13:03:44.909002 2026] [security2:error] [pid 139043:tid 139205] [client 20.226.36.136:57227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzhwAAAKU"] [Tue Aug 18 13:03:44.927502 2026] [security2:error] [pid 139043:tid 139235] [client 158.23.17.4:47641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ie.php"] [unique_id "aoSCYP2v-lWn9OzQT7UziAAAAMM"] [Tue Aug 18 13:03:44.934920 2026] [security2:error] [pid 139043:tid 139270] [client 172.182.217.32:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/yanz.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzigAAAOY"] [Tue Aug 18 13:03:44.952418 2026] [security2:error] [pid 139043:tid 139207] [client 20.250.13.23:4035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-content.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzkQAAAKc"] [Tue Aug 18 13:03:44.963275 2026] [security2:error] [pid 139043:tid 139187] [client 168.62.48.100:1240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzkgAAAJM"] [Tue Aug 18 13:03:44.964427 2026] [security2:error] [pid 139043:tid 139209] [client 132.196.30.78:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzkwAAAKk"] [Tue Aug 18 13:03:44.977886 2026] [security2:error] [pid 139043:tid 139296] [client 20.51.153.15:9092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCYP2v-lWn9OzQT7UzmAAAAQA"] [Tue Aug 18 13:03:45.039271 2026] [security2:error] [pid 139043:tid 139201] [client 20.250.27.191:22598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzngAAAKE"] [Tue Aug 18 13:03:45.050022 2026] [security2:error] [pid 139043:tid 139244] [client 20.163.43.14:4423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/public/css.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzoAAAAMw"] [Tue Aug 18 13:03:45.090950 2026] [security2:error] [pid 139043:tid 139263] [client 74.248.18.37:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzoQAAAN8"] [Tue Aug 18 13:03:45.111866 2026] [security2:error] [pid 139043:tid 139272] [client 20.51.153.15:8290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/uk.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzowAAAOg"] [Tue Aug 18 13:03:45.123991 2026] [security2:error] [pid 139043:tid 139202] [client 20.1.169.243:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzpQAAAKI"] [Tue Aug 18 13:03:45.138242 2026] [security2:error] [pid 139043:tid 139138] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYf2v-lWn9OzQT7UzqgAAil4"] [Tue Aug 18 13:03:45.167865 2026] [security2:error] [pid 139043:tid 139255] [client 20.116.17.175:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/log.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzqwAAANc"] [Tue Aug 18 13:03:45.182620 2026] [authz_core:error] [pid 139043:tid 139058] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:45.182920 2026] [authz_core:error] [pid 139043:tid 139058] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:45.190283 2026] [security2:error] [pid 139043:tid 139240] [client 102.213.179.104:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzrgAAAMg"] [Tue Aug 18 13:03:45.190396 2026] [security2:error] [pid 139043:tid 139240] [client 102.213.179.104:58262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzrgAAAMg"] [Tue Aug 18 13:03:45.190548 2026] [security2:error] [pid 139043:tid 139238] [client 20.80.111.3:1378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/admin/upload/css.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzrwAAAMY"] [Tue Aug 18 13:03:45.203695 2026] [security2:error] [pid 139043:tid 139246] [client 74.248.130.103:56976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/biufile.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzsAAAAM4"] [Tue Aug 18 13:03:45.205682 2026] [security2:error] [pid 139043:tid 139181] [client 168.62.48.100:1294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzsQAAAI0"] [Tue Aug 18 13:03:45.207962 2026] [security2:error] [pid 139043:tid 139289] [client 4.232.151.198:35630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzsgAAAPk"] [Tue Aug 18 13:03:45.212170 2026] [security2:error] [pid 139043:tid 139249] [client 20.124.247.79:16864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/av.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzswAAANE"] [Tue Aug 18 13:03:45.246226 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/inputs.php"] [unique_id "aoSCYf2v-lWn9OzQT7UztQAAALw"] [Tue Aug 18 13:03:45.260845 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/vd.php"] [unique_id "aoSCYf2v-lWn9OzQT7UztgAAANg"] [Tue Aug 18 13:03:45.275704 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:9203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCYf2v-lWn9OzQT7UztwAAAIw"] [Tue Aug 18 13:03:45.277155 2026] [security2:error] [pid 139043:tid 139211] [client 20.52.168.85:5306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/file4.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzuAAAAKs"] [Tue Aug 18 13:03:45.277415 2026] [security2:error] [pid 139043:tid 139186] [client 168.62.48.100:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzuQAAAJI"] [Tue Aug 18 13:03:45.315182 2026] [security2:error] [pid 139043:tid 139214] [client 68.221.73.131:26632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/mac.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzvAAAAK4"] [Tue Aug 18 13:03:45.331145 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:10968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ri.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzvQAAALM"] [Tue Aug 18 13:03:45.375440 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:9586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/creds.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzvwAAAPA"] [Tue Aug 18 13:03:45.431996 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.217.32:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzwQAAAJk"] [Tue Aug 18 13:03:45.439820 2026] [security2:error] [pid 139043:tid 139195] [client 20.163.43.14:4381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzwgAAAJs"] [Tue Aug 18 13:03:45.443743 2026] [security2:error] [pid 139043:tid 139221] [client 172.182.200.96:15512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzwwAAALU"] [Tue Aug 18 13:03:45.458396 2026] [security2:error] [pid 139043:tid 139183] [client 4.232.151.198:40837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-good.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzxQAAAI8"] [Tue Aug 18 13:03:45.460305 2026] [security2:error] [pid 139043:tid 139191] [client 20.250.27.191:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzxgAAAJc"] [Tue Aug 18 13:03:45.477452 2026] [security2:error] [pid 139043:tid 139224] [client 52.173.121.69:55967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzxwAAALg"] [Tue Aug 18 13:03:45.503202 2026] [security2:error] [pid 139043:tid 139217] [client 20.1.169.243:10940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/403.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzywAAALE"] [Tue Aug 18 13:03:45.521389 2026] [security2:error] [pid 139043:tid 139250] [client 20.206.73.37:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/w1px.php"] [unique_id "aoSCYf2v-lWn9OzQT7UzzwAAANI"] Unable to get file status /etc/scl/conf/rh-python35: No such file or directory [Tue Aug 18 13:03:45.539251 2026] [fcgid:warn] [pid 139043:tid 139184] (104)Connection reset by peer: [client 103.168.66.229:56340] mod_fcgid: error reading data from FastCGI server [Tue Aug 18 13:03:45.539276 2026] [core:error] [pid 139043:tid 139184] [client 103.168.66.229:56340] End of script output before headers: index.fcgi [Tue Aug 18 13:03:45.544680 2026] [security2:error] [pid 139043:tid 139188] [client 20.51.153.15:9102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/st.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz0QAAAJQ"] [Tue Aug 18 13:03:45.555526 2026] [security2:error] [pid 139043:tid 139274] [client 168.62.48.100:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz0gAAAOo"] [Tue Aug 18 13:03:45.557573 2026] [security2:error] [pid 139043:tid 139264] [client 132.196.30.78:23230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/0x.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz0wAAAOA"] [Tue Aug 18 13:03:45.573185 2026] [security2:error] [pid 139043:tid 139288] [client 20.79.204.6:9714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-admin/wp.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz1QAAAPg"] [Tue Aug 18 13:03:45.611835 2026] [security2:error] [pid 139043:tid 139295] [client 20.124.247.79:16774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/images.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz2AAAAP8"] [Tue Aug 18 13:03:45.620834 2026] [security2:error] [pid 139043:tid 139162] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYf2v-lWn9OzQT7Uz2gAAp3Y"] [Tue Aug 18 13:03:45.623307 2026] [security2:error] [pid 139043:tid 139187] [client 68.155.154.236:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz2wAAAJM"] [Tue Aug 18 13:03:45.634927 2026] [security2:error] [pid 139043:tid 139268] [client 20.116.17.175:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ohct.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz3QAAAOQ"] [Tue Aug 18 13:03:45.638504 2026] [security2:error] [pid 139043:tid 139233] [client 20.80.111.3:12515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/al.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz3gAAAME"] [Tue Aug 18 13:03:45.640535 2026] [security2:error] [pid 139043:tid 139244] [client 20.51.153.15:9765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ho.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz3wAAAMw"] [Tue Aug 18 13:03:45.662879 2026] [security2:error] [pid 139043:tid 139287] [client 20.25.139.174:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/ww5.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz4QAAAPc"] [Tue Aug 18 13:03:45.700947 2026] [security2:error] [pid 139043:tid 139158] [remote 17.22.245.6:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.245.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz0AAApnI"], referer: https://siderurgiabrasil.com.br/2024/06/29/acos-trefilados-mais-qualidade-e-melhor-valor-de-mercado/ [Tue Aug 18 13:03:45.725792 2026] [security2:error] [pid 139043:tid 139300] [client 74.248.18.37:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz6QAAAQQ"] [Tue Aug 18 13:03:45.772231 2026] [security2:error] [pid 139043:tid 139180] [client 20.250.13.23:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-content/about.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz7QAAAIw"] [Tue Aug 18 13:03:45.774495 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:33531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/tp.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz7gAAAJg"] [Tue Aug 18 13:03:45.788418 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:45.788733 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:45.790377 2026] [security2:error] [pid 139043:tid 139277] [client 213.35.127.232:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz8AAAAO0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:45.805899 2026] [security2:error] [pid 139043:tid 139216] [client 172.182.200.96:15614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz8gAAALA"] [Tue Aug 18 13:03:45.808674 2026] [security2:error] [pid 139043:tid 139213] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/alfa.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz9AAAAK0"] [Tue Aug 18 13:03:45.842768 2026] [security2:error] [pid 139043:tid 139128] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYf2v-lWn9OzQT7Uz9wAApFQ"] [Tue Aug 18 13:03:45.856999 2026] [security2:error] [pid 139043:tid 139208] [client 168.62.48.100:1139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz-gAAAKg"] [Tue Aug 18 13:03:45.861423 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/56.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz-wAAAJk"] [Tue Aug 18 13:03:45.865866 2026] [security2:error] [pid 139043:tid 139227] [client 20.51.153.15:9191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/le.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz_AAAALs"] [Tue Aug 18 13:03:45.872486 2026] [security2:error] [pid 139043:tid 139228] [client 20.1.169.243:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/404.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz_QAAALw"] [Tue Aug 18 13:03:45.876801 2026] [security2:error] [pid 139043:tid 139202] [client 20.52.168.85:5299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/assets/index.php"] [unique_id "aoSCYf2v-lWn9OzQT7Uz_gAAAKI"] [Tue Aug 18 13:03:45.889414 2026] [autoindex:error] [pid 139043:tid 139278] [client 4.232.151.198:20482] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:45.898478 2026] [security2:error] [pid 139043:tid 139221] [client 20.250.27.191:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/av.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0AAAAALU"] [Tue Aug 18 13:03:45.912156 2026] [security2:error] [pid 139043:tid 139200] [client 20.124.247.79:16784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/ops.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0AQAAAKA"] [Tue Aug 18 13:03:45.931578 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.217.32:21526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0AgAAAP4"] [Tue Aug 18 13:03:45.937464 2026] [security2:error] [pid 139043:tid 139243] [client 20.206.73.37:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/zi-936.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0AwAAAMs"] [Tue Aug 18 13:03:45.937908 2026] [security2:error] [pid 139043:tid 139191] [client 132.196.30.78:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/222.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0BAAAAJc"] [Tue Aug 18 13:03:45.960176 2026] [security2:error] [pid 139043:tid 139224] [client 20.163.43.14:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCYf2v-lWn9OzQT7U0BwAAALg"] [Tue Aug 18 13:03:46.056138 2026] [security2:error] [pid 139043:tid 139205] [client 168.62.48.100:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0CgAAAKU"] [Tue Aug 18 13:03:46.060871 2026] [security2:error] [pid 139043:tid 139283] [client 158.23.17.4:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nw.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0CwAAAPM"] [Tue Aug 18 13:03:46.078787 2026] [security2:error] [pid 139043:tid 139239] [client 20.80.111.3:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/baxa1.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0DQAAAMc"] [Tue Aug 18 13:03:46.093890 2026] [security2:error] [pid 139043:tid 139270] [client 4.232.151.198:20482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0DwAAAOY"] [Tue Aug 18 13:03:46.098595 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:9740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/97.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0EAAAAOk"] [Tue Aug 18 13:03:46.119453 2026] [security2:error] [pid 139043:tid 139225] [client 168.62.48.100:1226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0EQAAALk"] [Tue Aug 18 13:03:46.160684 2026] [security2:error] [pid 139043:tid 139244] [client 20.51.153.15:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/43.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0FAAAAMw"] [Tue Aug 18 13:03:46.162653 2026] [security2:error] [pid 139043:tid 139296] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/lock360.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0FQAAAQA"] [Tue Aug 18 13:03:46.162675 2026] [security2:error] [pid 139043:tid 139230] [client 172.182.200.96:15503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/weozh.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0FgAAAL4"] [Tue Aug 18 13:03:46.204610 2026] [security2:error] [pid 139043:tid 139290] [client 20.124.247.79:16892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/coffexium.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0GAAAAPo"] [Tue Aug 18 13:03:46.206076 2026] [security2:error] [pid 139043:tid 139210] [client 68.155.154.236:53671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0GQAAAKo"] [Tue Aug 18 13:03:46.215776 2026] [security2:error] [pid 139043:tid 139264] [client 20.25.139.174:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/2.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0GgAAAOA"] [Tue Aug 18 13:03:46.231352 2026] [security2:error] [pid 139043:tid 139175] [client 191.237.254.161:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/aa.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0HwAAAIc"] [Tue Aug 18 13:03:46.232682 2026] [security2:error] [pid 139043:tid 139153] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYv2v-lWn9OzQT7U0IAAAjW0"] [Tue Aug 18 13:03:46.243712 2026] [security2:error] [pid 139043:tid 139261] [client 20.1.169.243:10893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/4mosan.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0IgAAAN0"] [Tue Aug 18 13:03:46.285762 2026] [security2:error] [pid 139043:tid 139211] [client 20.116.17.175:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ot.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0JQAAAKs"] [Tue Aug 18 13:03:46.308882 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.36.136:57229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0KAAAANY"] [Tue Aug 18 13:03:46.309374 2026] [security2:error] [pid 139043:tid 139215] [client 4.223.113.180:17392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0KQAAAK8"] [Tue Aug 18 13:03:46.313453 2026] [security2:error] [pid 139043:tid 139219] [client 74.248.130.103:48970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/dejavu.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0KgAAALM"] [Tue Aug 18 13:03:46.319676 2026] [security2:error] [pid 139043:tid 139279] [client 20.250.27.191:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/images.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0KwAAAO8"] [Tue Aug 18 13:03:46.388740 2026] [security2:error] [pid 139043:tid 139253] [client 20.250.13.23:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0LgAAANU"] [Tue Aug 18 13:03:46.390247 2026] [authz_core:error] [pid 139043:tid 139083] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:46.390485 2026] [authz_core:error] [pid 139043:tid 139083] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:46.392073 2026] [security2:error] [pid 139043:tid 139243] [client 68.221.73.131:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0LwAAAMs"] [Tue Aug 18 13:03:46.401399 2026] [security2:error] [pid 139043:tid 139259] [client 20.79.204.6:9312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/bgymj.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0MAAAANs"] [Tue Aug 18 13:03:46.414158 2026] [security2:error] [pid 139043:tid 139191] [client 168.62.48.100:1167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/first.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0MQAAAJc"] [Tue Aug 18 13:03:46.426868 2026] [security2:error] [pid 139043:tid 139257] [client 158.23.17.4:9392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/zj.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0MgAAANk"] [Tue Aug 18 13:03:46.434910 2026] [security2:error] [pid 139043:tid 139291] [client 20.51.153.15:8294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/rh.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0NAAAAPs"] [Tue Aug 18 13:03:46.442162 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.217.32:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cache-compat.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0NgAAAIk"] [Tue Aug 18 13:03:46.444067 2026] [security2:error] [pid 139043:tid 139078] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYv2v-lWn9OzQT7U0NwAAsSI"] [Tue Aug 18 13:03:46.466459 2026] [security2:error] [pid 139043:tid 139262] [client 132.196.30.78:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/aa.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0OAAAAN4"] [Tue Aug 18 13:03:46.476455 2026] [security2:error] [pid 139043:tid 139256] [client 20.52.168.85:5132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/t.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0OgAAANg"] [Tue Aug 18 13:03:46.483506 2026] [security2:error] [pid 139043:tid 139218] [client 20.51.153.15:9172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fresh.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0OwAAALI"] [Tue Aug 18 13:03:46.496709 2026] [security2:error] [pid 139043:tid 139239] [client 20.163.43.14:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/gelay.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0PAAAAMc"] [Tue Aug 18 13:03:46.517834 2026] [security2:error] [pid 139043:tid 139194] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/flower.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0PQAAAJo"] [Tue Aug 18 13:03:46.525938 2026] [security2:error] [pid 139043:tid 139228] [client 20.80.111.3:26258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/buy.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0PwAAALw"] [Tue Aug 18 13:03:46.560838 2026] [security2:error] [pid 139043:tid 139225] [client 20.124.247.79:16796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0QAAAALk"] [Tue Aug 18 13:03:46.586989 2026] [security2:error] [pid 139043:tid 139233] [client 20.206.73.37:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/55.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0QgAAAME"] [Tue Aug 18 13:03:46.613027 2026] [security2:error] [pid 139043:tid 139276] [client 20.1.169.243:11144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/504.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0RAAAAOw"] [Tue Aug 18 13:03:46.613253 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.200.96:15499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/rymmm.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0QwAAAPc"] [Tue Aug 18 13:03:46.638350 2026] [security2:error] [pid 139043:tid 139264] [client 68.155.154.236:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0RQAAAOA"] [Tue Aug 18 13:03:46.696267 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:46.696736 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:46.724309 2026] [security2:error] [pid 139043:tid 139181] [client 168.62.48.100:1275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0SQAAAI0"] [Tue Aug 18 13:03:46.746671 2026] [security2:error] [pid 139043:tid 139266] [client 20.250.27.191:19463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/ops.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0SwAAAOI"] [Tue Aug 18 13:03:46.759890 2026] [autoindex:error] [pid 139043:tid 139281] [client 4.232.151.198:4125] AH01276: Cannot serve directory /home3/brto26/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:46.772512 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:9529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/yg.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0TAAAANA"] [Tue Aug 18 13:03:46.783966 2026] [security2:error] [pid 139043:tid 139234] [client 20.25.139.174:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0TQAAAMI"] [Tue Aug 18 13:03:46.786800 2026] [security2:error] [pid 139043:tid 139186] [client 74.248.18.37:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0TgAAAJI"] [Tue Aug 18 13:03:46.810754 2026] [security2:error] [pid 139043:tid 139265] [client 213.35.127.232:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0TwAAAOE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:46.828312 2026] [security2:error] [pid 139043:tid 139277] [client 20.51.153.15:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/gj.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0UAAAAO0"] [Tue Aug 18 13:03:46.852713 2026] [security2:error] [pid 139043:tid 139213] [client 68.155.156.252:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0UQAAAK0"] [Tue Aug 18 13:03:46.852996 2026] [security2:error] [pid 139043:tid 139254] [client 20.206.73.37:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/dcsgumnm.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0UgAAANY"] [Tue Aug 18 13:03:46.871434 2026] [security2:error] [pid 139043:tid 139245] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/13.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0UwAAAM0"] [Tue Aug 18 13:03:46.888636 2026] [security2:error] [pid 139043:tid 139223] [client 20.124.247.79:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/sf.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0VAAAALc"] [Tue Aug 18 13:03:46.932620 2026] [security2:error] [pid 139043:tid 139116] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSCYv2v-lWn9OzQT7U0VwAAuEg"] [Tue Aug 18 13:03:46.939640 2026] [security2:error] [pid 139043:tid 139280] [client 172.182.217.32:21794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ajax-actions.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0WAAAAPA"] [Tue Aug 18 13:03:46.964241 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.151.198:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0WgAAANg"] [Tue Aug 18 13:03:46.983173 2026] [security2:error] [pid 139043:tid 139282] [client 168.62.48.100:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0WwAAAPI"] [Tue Aug 18 13:03:46.984119 2026] [security2:error] [pid 139043:tid 139219] [client 20.1.169.243:10901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/7.php"] [unique_id "aoSCYv2v-lWn9OzQT7U0XAAAALM"] [Tue Aug 18 13:03:46.991037 2026] [authz_core:error] [pid 139043:tid 139107] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:46.991298 2026] [authz_core:error] [pid 139043:tid 139107] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:47.007043 2026] [security2:error] [pid 139043:tid 139214] [client 20.80.111.3:26277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/cong.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0XgAAAK4"] [Tue Aug 18 13:03:47.010649 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:54260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/v5.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0XwAAAIY"] [Tue Aug 18 13:03:47.013955 2026] [security2:error] [pid 139043:tid 139205] [client 132.196.30.78:15489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/abcd.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0YAAAAKU"] [Tue Aug 18 13:03:47.016934 2026] [security2:error] [pid 139043:tid 139220] [client 20.163.43.14:4357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0YQAAALQ"] [Tue Aug 18 13:03:47.022033 2026] [security2:error] [pid 139043:tid 139247] [client 20.250.13.23:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.portopreguicas.com.br.slweb.net.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0YgAAAM8"] [Tue Aug 18 13:03:47.036604 2026] [security2:error] [pid 139043:tid 139283] [client 172.182.200.96:15592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/lddxs.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0YwAAAPM"] [Tue Aug 18 13:03:47.044475 2026] [security2:error] [pid 139043:tid 139296] [client 86.120.159.145:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ZAAAAQA"] [Tue Aug 18 13:03:47.044905 2026] [security2:error] [pid 139043:tid 139296] [client 86.120.159.145:17541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ZAAAAQA"] [Tue Aug 18 13:03:47.047484 2026] [security2:error] [pid 139043:tid 139273] [client 20.51.153.15:9496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/et.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ZQAAAOk"] [Tue Aug 18 13:03:47.062136 2026] [security2:error] [pid 139043:tid 139228] [client 68.155.154.236:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ZgAAALw"] [Tue Aug 18 13:03:47.065346 2026] [security2:error] [pid 139043:tid 139270] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sbhu.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ZwAAAOY"] [Tue Aug 18 13:03:47.071906 2026] [security2:error] [pid 139043:tid 139225] [client 20.51.153.15:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pd.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0aAAAALk"] [Tue Aug 18 13:03:47.081990 2026] [security2:error] [pid 139043:tid 139209] [client 20.52.168.85:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0aQAAAKk"] [Tue Aug 18 13:03:47.149826 2026] [security2:error] [pid 139043:tid 139229] [client 20.124.247.79:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/k.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0awAAAL0"] [Tue Aug 18 13:03:47.151243 2026] [security2:error] [pid 139043:tid 139290] [client 68.221.73.131:59441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0bAAAAPo"] [Tue Aug 18 13:03:47.177731 2026] [security2:error] [pid 139043:tid 139289] [client 20.250.27.191:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/coffexium.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0bgAAAPk"] [Tue Aug 18 13:03:47.204470 2026] [security2:error] [pid 139043:tid 139246] [client 52.173.121.69:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0bwAAAM4"] [Tue Aug 18 13:03:47.207608 2026] [security2:error] [pid 139043:tid 139266] [client 158.23.17.4:9341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/x.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0cAAAAOI"] [Tue Aug 18 13:03:47.220936 2026] [security2:error] [pid 139043:tid 139049] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "aoSCY_2v-lWn9OzQT7U0cQAA0AU"] [Tue Aug 18 13:03:47.224091 2026] [security2:error] [pid 139043:tid 139227] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/cc.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0cwAAALs"] [Tue Aug 18 13:03:47.244654 2026] [security2:error] [pid 139043:tid 139265] [client 168.62.48.100:1264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0dAAAAOE"] [Tue Aug 18 13:03:47.292050 2026] [authz_core:error] [pid 139043:tid 139118] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:47.292060 2026] [security2:error] [pid 139043:tid 139242] [client 20.51.153.15:9741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/of.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0dwAAAMo"] [Tue Aug 18 13:03:47.292311 2026] [authz_core:error] [pid 139043:tid 139118] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:47.355764 2026] [security2:error] [pid 139043:tid 139234] [client 20.1.169.243:10897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/8.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0fQAAAMI"] [Tue Aug 18 13:03:47.362424 2026] [security2:error] [pid 139043:tid 139259] [client 20.79.204.6:9667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/aa.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0fgAAANs"] [Tue Aug 18 13:03:47.385433 2026] [security2:error] [pid 139043:tid 139261] [client 20.25.139.174:4643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/atomlib.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0gAAAAN0"] [Tue Aug 18 13:03:47.403752 2026] [security2:error] [pid 139043:tid 139257] [client 20.51.153.15:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/admin404.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0gQAAANk"] [Tue Aug 18 13:03:47.406780 2026] [security2:error] [pid 139043:tid 139298] [client 172.182.200.96:15566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/zjggu.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ggAAAQI"] [Tue Aug 18 13:03:47.431537 2026] [security2:error] [pid 139043:tid 139299] [client 172.182.217.32:21801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/ajax-actions.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0hQAAAQM"] [Tue Aug 18 13:03:47.431593 2026] [security2:error] [pid 139043:tid 139203] [client 168.62.48.100:4136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0hAAAAKM"] [Tue Aug 18 13:03:47.436703 2026] [security2:error] [pid 139043:tid 139217] [client 20.226.36.136:43413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0hgAAALE"] [Tue Aug 18 13:03:47.468998 2026] [security2:error] [pid 139043:tid 139201] [client 20.80.111.3:5922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/contact.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0iAAAAKE"] [Tue Aug 18 13:03:47.483308 2026] [security2:error] [pid 139043:tid 139272] [client 158.23.17.4:7220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sb.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0iQAAAOg"] [Tue Aug 18 13:03:47.489130 2026] [security2:error] [pid 139043:tid 139274] [client 20.151.109.219:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xx.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0igAAAOo"] [Tue Aug 18 13:03:47.497424 2026] [security2:error] [pid 139043:tid 139281] [client 74.248.18.37:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0jAAAAPE"] [Tue Aug 18 13:03:47.505419 2026] [security2:error] [pid 139043:tid 139174] [client 85.208.96.206:33940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cainelli.com.br"] [uri "/blog/page/4/"] [unique_id "aoSCY_2v-lWn9OzQT7U0jQAAAIY"] [Tue Aug 18 13:03:47.505526 2026] [security2:error] [pid 139043:tid 139174] [client 85.208.96.206:33940] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cainelli.com.br"] [uri "/blog/page/4/"] [unique_id "aoSCY_2v-lWn9OzQT7U0jQAAAIY"] [Tue Aug 18 13:03:47.538801 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0kAAAAJE"] [Tue Aug 18 13:03:47.550884 2026] [security2:error] [pid 139043:tid 139194] [client 20.124.247.79:16831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/82.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0kgAAAJo"] [Tue Aug 18 13:03:47.576117 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:8194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/bu.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0lQAAAKk"] [Tue Aug 18 13:03:47.582330 2026] [security2:error] [pid 139043:tid 139232] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0lgAAAMA"] [Tue Aug 18 13:03:47.594554 2026] [authz_core:error] [pid 139043:tid 139137] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:47.594840 2026] [authz_core:error] [pid 139043:tid 139137] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:47.635146 2026] [security2:error] [pid 139043:tid 139276] [client 158.23.17.4:17598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/rx.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0mgAAAOw"] [Tue Aug 18 13:03:47.657465 2026] [security2:error] [pid 139043:tid 139073] [remote 89.185.225.24:58508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0nQAA1B0"] [Tue Aug 18 13:03:47.663372 2026] [security2:error] [pid 139043:tid 139256] [client 4.232.151.198:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ngAAANg"] [Tue Aug 18 13:03:47.675599 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/zc-318.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0oAAAAKY"] [Tue Aug 18 13:03:47.684559 2026] [security2:error] [pid 139043:tid 139289] [client 20.51.153.15:9178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/qo.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0oQAAAPk"] [Tue Aug 18 13:03:47.687819 2026] [security2:error] [pid 139043:tid 139198] [client 20.52.168.85:5135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/bgymj.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ogAAAJ4"] [Tue Aug 18 13:03:47.699750 2026] [security2:error] [pid 139043:tid 139249] [client 20.250.27.191:22647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0owAAANE"] [Tue Aug 18 13:03:47.718177 2026] [security2:error] [pid 139043:tid 139267] [client 168.62.48.100:1208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0pAAAAOM"] [Tue Aug 18 13:03:47.721124 2026] [security2:error] [pid 139043:tid 139244] [client 20.1.169.243:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/82.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0pQAAAMw"] [Tue Aug 18 13:03:47.724962 2026] [security2:error] [pid 139043:tid 139100] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSCY_2v-lWn9OzQT7U0pgAAjTg"] [Tue Aug 18 13:03:47.755246 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ccou.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0qAAAAM4"] [Tue Aug 18 13:03:47.775792 2026] [security2:error] [pid 139043:tid 139211] [client 132.196.30.78:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/admin.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0qQAAAKs"] [Tue Aug 18 13:03:47.809940 2026] [security2:error] [pid 139043:tid 139226] [client 20.206.73.37:15797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/coffee.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0qwAAALo"] [Tue Aug 18 13:03:47.826345 2026] [security2:error] [pid 139043:tid 139212] [client 213.35.127.232:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0rAAAAKw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:47.826970 2026] [security2:error] [pid 139043:tid 139215] [client 172.182.200.96:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0rgAAAK8"] [Tue Aug 18 13:03:47.843841 2026] [security2:error] [pid 139043:tid 139258] [client 158.23.17.4:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/yn.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0rwAAANo"] [Tue Aug 18 13:03:47.847373 2026] [security2:error] [pid 139043:tid 139208] [client 68.221.73.131:48355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/system_log.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0sAAAAKg"] [Tue Aug 18 13:03:47.881075 2026] [security2:error] [pid 139043:tid 139234] [client 20.104.100.201:24038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0sgAAAMI"] [Tue Aug 18 13:03:47.886546 2026] [security2:error] [pid 139043:tid 139059] [remote 47.128.29.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joanagaspar.com.br"] [uri "/robots.txt"] [unique_id "aoSCY_2v-lWn9OzQT7U0swAAxA8"] [Tue Aug 18 13:03:47.906793 2026] [security2:error] [pid 139043:tid 139259] [client 74.248.130.103:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/aaf.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0tQAAANs"] [Tue Aug 18 13:03:47.921566 2026] [security2:error] [pid 139043:tid 139266] [client 20.80.111.3:25847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/cux.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0uAAAAOI"] [Tue Aug 18 13:03:47.934419 2026] [security2:error] [pid 139043:tid 139079] [remote 139.28.219.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "media.idealquimica.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSCY_2v-lWn9OzQT7U0uQAAmCM"] [Tue Aug 18 13:03:47.935350 2026] [security2:error] [pid 139043:tid 139243] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0ugAAAMs"] [Tue Aug 18 13:03:47.961756 2026] [security2:error] [pid 139043:tid 139298] [client 20.124.247.79:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/dex.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0vAAAAQI"] [Tue Aug 18 13:03:47.964645 2026] [security2:error] [pid 139043:tid 139277] [client 172.182.217.32:21806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-consar.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0vQAAAO0"] [Tue Aug 18 13:03:47.966503 2026] [security2:error] [pid 139043:tid 139248] [client 20.25.139.174:4520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/rip.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0vgAAANA"] [Tue Aug 18 13:03:47.988820 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/sd.php"] [unique_id "aoSCY_2v-lWn9OzQT7U0wAAAAIU"] [Tue Aug 18 13:03:48.001545 2026] [security2:error] [pid 139043:tid 139223] [client 20.116.17.175:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/replace.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0wQAAALc"] [Tue Aug 18 13:03:48.010264 2026] [security2:error] [pid 139043:tid 139282] [client 20.51.153.15:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/rn.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0wwAAAPI"] [Tue Aug 18 13:03:48.055305 2026] [security2:error] [pid 139043:tid 139272] [client 168.62.48.100:1152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0xQAAAOg"] [Tue Aug 18 13:03:48.126235 2026] [security2:error] [pid 139043:tid 139284] [client 68.155.154.236:8873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0yQAAAPQ"] [Tue Aug 18 13:03:48.131973 2026] [security2:error] [pid 139043:tid 139176] [client 20.1.169.243:10882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/a.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0ygAAAIg"] [Tue Aug 18 13:03:48.145190 2026] [security2:error] [pid 139043:tid 139237] [client 20.250.27.191:22639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/sf.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0zQAAAMU"] [Tue Aug 18 13:03:48.147383 2026] [autoindex:error] [pid 139043:tid 139296] [client 20.206.73.37:59952] AH01276: Cannot serve directory /home4/lifet280/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:48.151601 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0zgAAALw"] [Tue Aug 18 13:03:48.155094 2026] [security2:error] [pid 139043:tid 139225] [client 20.206.73.37:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/php.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0zwAAALk"] [Tue Aug 18 13:03:48.187119 2026] [security2:error] [pid 139043:tid 139283] [client 172.182.200.96:15552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCZP2v-lWn9OzQT7U00AAAAPM"] [Tue Aug 18 13:03:48.275861 2026] [security2:error] [pid 139043:tid 139229] [client 20.51.153.15:9121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/km.php"] [unique_id "aoSCZP2v-lWn9OzQT7U01AAAAL0"] [Tue Aug 18 13:03:48.278996 2026] [security2:error] [pid 139043:tid 139230] [client 20.104.100.201:23938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCZP2v-lWn9OzQT7U01QAAAL4"] [Tue Aug 18 13:03:48.285070 2026] [security2:error] [pid 139043:tid 139174] [client 4.232.151.198:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCZP2v-lWn9OzQT7U01wAAAIY"] [Tue Aug 18 13:03:48.287008 2026] [security2:error] [pid 139043:tid 139290] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/01.php"] [unique_id "aoSCZP2v-lWn9OzQT7U02AAAAPo"] [Tue Aug 18 13:03:48.306021 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/txets.php"] [unique_id "aoSCZP2v-lWn9OzQT7U02gAAAIo"] [Tue Aug 18 13:03:48.306416 2026] [security2:error] [pid 139043:tid 139255] [client 20.51.153.15:9780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ut.php"] [unique_id "aoSCZP2v-lWn9OzQT7U02wAAANc"] [Tue Aug 18 13:03:48.307211 2026] [security2:error] [pid 139043:tid 139252] [client 168.62.48.100:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U03AAAANQ"] [Tue Aug 18 13:03:48.310371 2026] [autoindex:error] [pid 139043:tid 139188] [client 20.52.168.85:5717] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:48.319386 2026] [security2:error] [pid 139043:tid 139206] [client 20.124.247.79:16841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/puc.php"] [unique_id "aoSCZP2v-lWn9OzQT7U03QAAAKY"] [Tue Aug 18 13:03:48.364080 2026] [security2:error] [pid 139043:tid 139295] [client 20.80.111.3:5927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/favicon.php"] [unique_id "aoSCZP2v-lWn9OzQT7U03wAAAP8"] [Tue Aug 18 13:03:48.387527 2026] [security2:error] [pid 139043:tid 139244] [client 74.248.130.103:42030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSCZP2v-lWn9OzQT7U04QAAAMw"] [Tue Aug 18 13:03:48.397414 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fun.php"] [unique_id "aoSCZP2v-lWn9OzQT7U04gAAAI0"] [Tue Aug 18 13:03:48.400079 2026] [security2:error] [pid 139043:tid 139300] [client 68.155.154.236:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U04wAAAQQ"] [Tue Aug 18 13:03:48.414691 2026] [security2:error] [pid 139043:tid 139177] [client 4.223.113.180:40468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/24.php"] [unique_id "aoSCZP2v-lWn9OzQT7U05AAAAIk"] [Tue Aug 18 13:03:48.465838 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/jq.php"] [unique_id "aoSCZP2v-lWn9OzQT7U06AAAAK0"] [Tue Aug 18 13:03:48.489769 2026] [security2:error] [pid 139043:tid 139245] [client 158.23.17.4:54734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mandrill.php"] [unique_id "aoSCZP2v-lWn9OzQT7U06gAAAM0"] [Tue Aug 18 13:03:48.495664 2026] [security2:error] [pid 139043:tid 139249] [client 20.1.169.243:11141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/aa.php"] [unique_id "aoSCZP2v-lWn9OzQT7U07AAAANE"] [Tue Aug 18 13:03:48.496411 2026] [authz_core:error] [pid 139043:tid 139151] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:48.496674 2026] [authz_core:error] [pid 139043:tid 139151] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:48.511591 2026] [security2:error] [pid 139043:tid 139258] [client 20.52.168.85:5717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCZP2v-lWn9OzQT7U07QAAANo"] [Tue Aug 18 13:03:48.514266 2026] [security2:error] [pid 139043:tid 139221] [client 20.163.43.14:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/about.php"] [unique_id "aoSCZP2v-lWn9OzQT7U07gAAALU"] [Tue Aug 18 13:03:48.547159 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.156.252:41831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/sf.php"] [unique_id "aoSCZP2v-lWn9OzQT7U08QAAAP0"] [Tue Aug 18 13:03:48.562782 2026] [security2:error] [pid 139043:tid 139243] [client 74.248.18.37:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCZP2v-lWn9OzQT7U09AAAAMs"] [Tue Aug 18 13:03:48.568041 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.200.96:15505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/kopyw.php"] [unique_id "aoSCZP2v-lWn9OzQT7U09QAAALg"] [Tue Aug 18 13:03:48.574035 2026] [security2:error] [pid 139043:tid 139298] [client 168.62.48.100:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.h6.com.br"] [uri "/images/security.php"] [unique_id "aoSCZP2v-lWn9OzQT7U09gAAAQI"] [Tue Aug 18 13:03:48.586653 2026] [security2:error] [pid 139043:tid 139191] [client 20.51.153.15:8258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/eh.php"] [unique_id "aoSCZP2v-lWn9OzQT7U09wAAAJc"] [Tue Aug 18 13:03:48.595628 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.27.191:40622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/k.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0-QAAAIc"] [Tue Aug 18 13:03:48.612349 2026] [security2:error] [pid 139043:tid 139248] [client 52.173.121.69:64906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0-gAAANA"] [Tue Aug 18 13:03:48.620495 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:8724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ie.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0-wAAAIU"] [Tue Aug 18 13:03:48.626325 2026] [security2:error] [pid 139043:tid 139193] [client 20.124.247.79:16785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/inso.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0_AAAAJk"] [Tue Aug 18 13:03:48.633235 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/11.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0_QAAALc"] [Tue Aug 18 13:03:48.655128 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/lv.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1AQAAAOo"] [Tue Aug 18 13:03:48.737576 2026] [security2:error] [pid 139043:tid 139200] [client 20.25.139.174:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/p.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1BAAAAKA"] [Tue Aug 18 13:03:48.773894 2026] [security2:error] [pid 139043:tid 139253] [client 20.104.100.201:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1CQAAANU"] [Tue Aug 18 13:03:48.797825 2026] [authz_core:error] [pid 139043:tid 139065] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:48.798087 2026] [authz_core:error] [pid 139043:tid 139065] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:48.848453 2026] [security2:error] [pid 139043:tid 139247] [client 20.80.111.3:25991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/randkeyword.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1DwAAAM8"] [Tue Aug 18 13:03:48.855941 2026] [security2:error] [pid 139043:tid 139271] [client 213.35.127.232:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1EQAAAOc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:48.859971 2026] [security2:error] [pid 139043:tid 139296] [client 20.1.169.243:10927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/aaa.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1EgAAAQA"] [Tue Aug 18 13:03:48.878103 2026] [security2:error] [pid 139043:tid 139290] [client 74.248.130.103:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/155.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1EwAAAPo"] [Tue Aug 18 13:03:48.878939 2026] [security2:error] [pid 139043:tid 139276] [client 20.163.43.14:4386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1FAAAAOw"] [Tue Aug 18 13:03:48.898770 2026] [security2:error] [pid 139043:tid 139178] [client 20.124.247.79:16860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/aa.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1FQAAAIo"] [Tue Aug 18 13:03:48.956026 2026] [security2:error] [pid 139043:tid 139280] [client 4.232.151.198:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1GAAAAPA"] [Tue Aug 18 13:03:48.964178 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.200.96:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/zznmg.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1GQAAAMg"] [Tue Aug 18 13:03:48.982897 2026] [security2:error] [pid 139043:tid 139257] [client 20.51.153.15:9213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/nw.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1GwAAANk"] [Tue Aug 18 13:03:48.989586 2026] [security2:error] [pid 139043:tid 139197] [client 20.51.153.15:8238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ad.php"] [unique_id "aoSCZP2v-lWn9OzQT7U1HAAAAJ0"] [Tue Aug 18 13:03:49.009375 2026] [security2:error] [pid 139043:tid 139244] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sys.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1HgAAAMw"] [Tue Aug 18 13:03:49.020325 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/new.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1HwAAAQQ"] [Tue Aug 18 13:03:49.032557 2026] [security2:error] [pid 139043:tid 139241] [client 20.250.27.191:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/82.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1IAAAAMk"] [Tue Aug 18 13:03:49.049294 2026] [security2:error] [pid 139043:tid 139278] [client 20.79.204.6:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-mail.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1IQAAAO4"] [Tue Aug 18 13:03:49.098356 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:49.098607 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:49.109590 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/pp.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1JwAAANY"] [Tue Aug 18 13:03:49.116128 2026] [security2:error] [pid 139043:tid 139256] [client 20.52.168.85:5304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/tool.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1KQAAANg"] [Tue Aug 18 13:03:49.131827 2026] [security2:error] [pid 139043:tid 139195] [client 20.151.109.219:13801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/conn-test.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1LgAAAJs"] [Tue Aug 18 13:03:49.136814 2026] [security2:error] [pid 139043:tid 139234] [client 20.116.17.175:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/fw/faiyy.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1LwAAAMI"] [Tue Aug 18 13:03:49.194522 2026] [security2:error] [pid 139043:tid 139298] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wqqs.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1OQAAAQI"] [Tue Aug 18 13:03:49.194539 2026] [security2:error] [pid 139043:tid 139275] [client 74.248.18.37:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1OAAAAOs"] [Tue Aug 18 13:03:49.214461 2026] [security2:error] [pid 139043:tid 139191] [client 20.124.247.79:16893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/img.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1OgAAAJc"] [Tue Aug 18 13:03:49.233732 2026] [security2:error] [pid 139043:tid 139217] [client 20.51.153.15:9145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/sb.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1OwAAALE"] [Tue Aug 18 13:03:49.237169 2026] [security2:error] [pid 139043:tid 139245] [client 20.1.169.243:10929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/aar.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1PAAAAM0"] [Tue Aug 18 13:03:49.283116 2026] [security2:error] [pid 139043:tid 139180] [client 20.25.139.174:4373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advocaciasc.com"] [uri "/php.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1QAAAAIw"] [Tue Aug 18 13:03:49.288658 2026] [security2:error] [pid 139043:tid 139249] [client 172.182.217.32:21838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/repeater.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1QgAAANE"] [Tue Aug 18 13:03:49.288766 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/vd.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1QwAAALQ"] [Tue Aug 18 13:03:49.298658 2026] [security2:error] [pid 139043:tid 139259] [client 20.80.111.3:17240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/gebase.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1RQAAANs"] [Tue Aug 18 13:03:49.299688 2026] [security2:error] [pid 139043:tid 139223] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1PgAAt0A"] [Tue Aug 18 13:03:49.304116 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:4412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/f35.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1RwAAAPQ"] [Tue Aug 18 13:03:49.304148 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:24018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/cok.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1RgAAAJE"] [Tue Aug 18 13:03:49.335574 2026] [security2:error] [pid 139043:tid 139299] [client 172.182.200.96:15496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1SQAAAQM"] [Tue Aug 18 13:03:49.375834 2026] [security2:error] [pid 139043:tid 139228] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/222.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1TAAAALw"] [Tue Aug 18 13:03:49.400200 2026] [authz_core:error] [pid 139043:tid 139133] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:49.400462 2026] [authz_core:error] [pid 139043:tid 139133] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:49.431368 2026] [security2:error] [pid 139043:tid 139214] [client 74.248.130.103:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/ops.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1UAAAAK4"] [Tue Aug 18 13:03:49.459005 2026] [security2:error] [pid 139043:tid 139268] [client 45.131.195.78:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "media.chicodareia.com.br"] [uri "/"] [unique_id "aoSCZf2v-lWn9OzQT7U1UgAAAOQ"] [Tue Aug 18 13:03:49.459170 2026] [security2:error] [pid 139043:tid 139290] [client 68.221.73.131:29973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/pucci.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1UwAAAPo"] [Tue Aug 18 13:03:49.475284 2026] [security2:error] [pid 139043:tid 139178] [client 20.250.27.191:18830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/dex.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1VQAAAIo"] [Tue Aug 18 13:03:49.512625 2026] [security2:error] [pid 139043:tid 139240] [client 168.62.48.100:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1VwAAAMg"] [Tue Aug 18 13:03:49.529441 2026] [security2:error] [pid 139043:tid 139262] [client 20.206.73.37:59860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/sf.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1WQAAAN4"] [Tue Aug 18 13:03:49.533919 2026] [security2:error] [pid 139043:tid 139289] [client 20.51.153.15:9153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xj.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1WgAAAPk"] [Tue Aug 18 13:03:49.579418 2026] [security2:error] [pid 139043:tid 139209] [client 4.232.151.198:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1XgAAAKk"] [Tue Aug 18 13:03:49.603397 2026] [security2:error] [pid 139043:tid 139252] [client 20.1.169.243:10884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/ab.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1XwAAANQ"] [Tue Aug 18 13:03:49.641914 2026] [security2:error] [pid 139043:tid 139215] [client 20.51.153.15:9530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/56.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1YwAAAK8"] [Tue Aug 18 13:03:49.643753 2026] [security2:error] [pid 139043:tid 139256] [client 20.124.247.79:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/222.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1ZAAAANg"] [Tue Aug 18 13:03:49.687433 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/main.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1ZgAAALg"] [Tue Aug 18 13:03:49.696336 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.200.96:15515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1aQAAAOs"] [Tue Aug 18 13:03:49.700241 2026] [authz_core:error] [pid 139043:tid 139155] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:49.700517 2026] [authz_core:error] [pid 139043:tid 139155] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:49.727346 2026] [security2:error] [pid 139043:tid 139175] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/chosen.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1agAAAIc"] [Tue Aug 18 13:03:49.736319 2026] [security2:error] [pid 139043:tid 139198] [client 20.52.168.85:5290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ws.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1awAAAJ4"] [Tue Aug 18 13:03:49.764769 2026] [security2:error] [pid 139043:tid 139245] [client 191.237.254.161:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/img.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1bgAAAM0"] [Tue Aug 18 13:03:49.775970 2026] [security2:error] [pid 139043:tid 139186] [client 172.182.217.32:21769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/admin-post.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1bwAAAJI"] [Tue Aug 18 13:03:49.780668 2026] [security2:error] [pid 139043:tid 139254] [client 20.80.111.3:25851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/images/2008.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1cAAAANY"] [Tue Aug 18 13:03:49.857229 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:4368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/inputs.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1cwAAAMU"] [Tue Aug 18 13:03:49.862704 2026] [security2:error] [pid 139043:tid 139200] [client 20.51.153.15:9160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ns.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1dAAAAKA"] [Tue Aug 18 13:03:49.879631 2026] [security2:error] [pid 139043:tid 139197] [client 213.35.127.232:52747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1dQAAAJ0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:49.887039 2026] [security2:error] [pid 139043:tid 139225] [client 20.116.17.175:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/dk.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1dgAAALk"] [Tue Aug 18 13:03:49.889207 2026] [security2:error] [pid 139043:tid 139264] [client 20.250.27.191:18845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/puc.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1dwAAAOA"] [Tue Aug 18 13:03:49.892802 2026] [security2:error] [pid 139043:tid 139273] [client 158.23.17.4:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vm.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1eAAAAOk"] [Tue Aug 18 13:03:49.897631 2026] [security2:error] [pid 139043:tid 139184] [client 45.131.195.78:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "media.chicodareia.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "aoSCZf2v-lWn9OzQT7U1eQAAAJA"] [Tue Aug 18 13:03:49.931169 2026] [security2:error] [pid 139043:tid 139281] [client 74.248.130.103:42001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/mac.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1fgAAAPE"] [Tue Aug 18 13:03:49.951960 2026] [security2:error] [pid 139043:tid 139090] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/wp-json"] [unique_id "aoSCZf2v-lWn9OzQT7U1fwAAzy4"] [Tue Aug 18 13:03:49.962903 2026] [security2:error] [pid 139043:tid 139060] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/rclone.conf"] [unique_id "aoSCZf2v-lWn9OzQT7U1ggAA5hA"] [Tue Aug 18 13:03:49.966593 2026] [security2:error] [pid 139043:tid 139202] [client 20.1.169.243:10908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/abc.php"] [unique_id "aoSCZf2v-lWn9OzQT7U1gwAAAKI"] [Tue Aug 18 13:03:49.975146 2026] [security2:error] [pid 139043:tid 139143] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.git/config"] [unique_id "aoSCZf2v-lWn9OzQT7U1hAAA5GM"] [Tue Aug 18 13:03:49.976627 2026] [security2:error] [pid 139043:tid 139141] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.aws/credentials"] [unique_id "aoSCZf2v-lWn9OzQT7U1hgAA-mE"] [Tue Aug 18 13:03:49.977193 2026] [security2:error] [pid 139043:tid 139157] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/z9x8c7v6b5-debug-trigger-stremmastay.com.br"] [unique_id "aoSCZf2v-lWn9OzQT7U1hwAA-nE"] [Tue Aug 18 13:03:49.977954 2026] [security2:error] [pid 139043:tid 139067] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.aws/config"] [unique_id "aoSCZf2v-lWn9OzQT7U1igAA-hc"] [Tue Aug 18 13:03:50.002013 2026] [authz_core:error] [pid 139043:tid 139163] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:50.002273 2026] [authz_core:error] [pid 139043:tid 139163] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:50.013953 2026] [security2:error] [pid 139043:tid 139255] [client 20.124.247.79:16770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/key.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1jgAAANc"] [Tue Aug 18 13:03:50.052757 2026] [security2:error] [pid 139043:tid 139289] [client 74.248.18.37:46195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1kwAAAPk"] [Tue Aug 18 13:03:50.058810 2026] [security2:error] [pid 139043:tid 139257] [client 20.51.153.15:8274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/rx.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1lAAAANk"] [Tue Aug 18 13:03:50.067424 2026] [security2:error] [pid 139043:tid 139176] [client 20.79.204.6:9300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/bolt.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1lQAAAIg"] [Tue Aug 18 13:03:50.068700 2026] [security2:error] [pid 139043:tid 139295] [client 172.182.200.96:15608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/oivcl.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1lgAAAP8"] [Tue Aug 18 13:03:50.079977 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/info.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1lwAAAQQ"] [Tue Aug 18 13:03:50.121452 2026] [security2:error] [pid 139043:tid 139211] [client 20.51.153.15:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wn.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1nQAAAKs"] [Tue Aug 18 13:03:50.151808 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.154.236:55464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/first.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1oAAAAMI"] [Tue Aug 18 13:03:50.152615 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.156.252:20424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/k.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1oQAAAP0"] [Tue Aug 18 13:03:50.187922 2026] [security2:error] [pid 139043:tid 139243] [client 20.226.36.136:57824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1ogAAAMs"] [Tue Aug 18 13:03:50.205174 2026] [security2:error] [pid 139043:tid 139178] [client 4.232.151.198:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSCZv2v-lWn9OzQT7U1pQAAAIo"] [Tue Aug 18 13:03:50.228219 2026] [security2:error] [pid 139043:tid 139219] [client 20.104.100.201:23970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/accesson.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1pgAAALM"] [Tue Aug 18 13:03:50.252307 2026] [security2:error] [pid 139043:tid 139232] [client 20.151.109.219:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fg.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1qAAAAMA"] [Tue Aug 18 13:03:50.261571 2026] [autoindex:error] [pid 139043:tid 139181] [client 68.155.154.146:11749] AH01276: Cannot serve directory /home4/adf/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:50.277697 2026] [security2:error] [pid 139043:tid 139227] [client 172.182.217.32:21819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/maint/maint/ajax-actions.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1qQAAALs"] [Tue Aug 18 13:03:50.277712 2026] [security2:error] [pid 139043:tid 139186] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/clasa99.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1qgAAAJI"] [Tue Aug 18 13:03:50.280136 2026] [security2:error] [pid 139043:tid 139272] [client 20.206.73.37:11938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/xx.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1qwAAAOg"] [Tue Aug 18 13:03:50.280603 2026] [security2:error] [pid 139043:tid 139249] [client 149.34.210.141:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1rAAAANE"] [Tue Aug 18 13:03:50.303412 2026] [authz_core:error] [pid 139043:tid 139045] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:50.303714 2026] [authz_core:error] [pid 139043:tid 139045] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:50.306249 2026] [security2:error] [pid 139043:tid 139286] [client 20.124.247.79:16779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/chosen.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1rwAAAPY"] [Tue Aug 18 13:03:50.327899 2026] [security2:error] [pid 139043:tid 139242] [client 20.80.111.3:5926] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.formafit.com.br"] [uri "/images/c99.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1sQAAAMo"] [Tue Aug 18 13:03:50.334376 2026] [security2:error] [pid 139043:tid 139298] [client 20.1.169.243:11166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/abcd.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1sgAAAQI"] [Tue Aug 18 13:03:50.337870 2026] [security2:error] [pid 139043:tid 139203] [client 20.52.168.85:5130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1swAAAKM"] [Tue Aug 18 13:03:50.340437 2026] [security2:error] [pid 139043:tid 139223] [client 45.131.195.78:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "media.chicodareia.com.br"] [uri "/media/system/js/core.js"] [unique_id "aoSCZv2v-lWn9OzQT7U1tAAAALc"] [Tue Aug 18 13:03:50.346146 2026] [security2:error] [pid 139043:tid 139284] [client 20.51.153.15:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mandrill.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1tQAAAPQ"] [Tue Aug 18 13:03:50.348312 2026] [security2:error] [pid 139043:tid 139183] [client 20.206.73.37:34761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/signon.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1twAAAI8"] [Tue Aug 18 13:03:50.382836 2026] [security2:error] [pid 139043:tid 139212] [client 3.133.226.214:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSCZP2v-lWn9OzQT7U0_gAArFc"], referer: https://1td.com.br [Tue Aug 18 13:03:50.384642 2026] [security2:error] [pid 139043:tid 139267] [client 20.250.27.191:39719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/inso.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1uwAAAOM"] [Tue Aug 18 13:03:50.389669 2026] [security2:error] [pid 139043:tid 139250] [client 20.116.17.175:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/bal.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1vAAAANI"] [Tue Aug 18 13:03:50.413522 2026] [security2:error] [pid 139043:tid 139235] [client 20.171.51.14:44869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1vwAAAMM"] [Tue Aug 18 13:03:50.417421 2026] [security2:error] [pid 139043:tid 139281] [client 68.221.73.131:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1wAAAAPE"] [Tue Aug 18 13:03:50.479892 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:38877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/eg.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1xAAAAOE"] [Tue Aug 18 13:03:50.511471 2026] [security2:error] [pid 139043:tid 139229] [client 20.163.43.14:4469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/alfa.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1xQAAAL0"] [Tue Aug 18 13:03:50.540771 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.200.96:3012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/zugvi.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1yAAAANc"] [Tue Aug 18 13:03:50.548007 2026] [security2:error] [pid 139043:tid 139249] [client 149.34.210.141:50792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1rAAAANE"] [Tue Aug 18 13:03:50.567483 2026] [security2:error] [pid 139043:tid 139072] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.gitconfig"] [unique_id "aoSCZv2v-lWn9OzQT7U1ygAAhhw"] [Tue Aug 18 13:03:50.570926 2026] [security2:error] [pid 139043:tid 139145] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.git-credentials"] [unique_id "aoSCZv2v-lWn9OzQT7U1ywAAhmU"] [Tue Aug 18 13:03:50.570926 2026] [security2:error] [pid 139043:tid 139115] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSCZv2v-lWn9OzQT7U1zAAAhkc"] [Tue Aug 18 13:03:50.571588 2026] [security2:error] [pid 139043:tid 139094] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.git/HEAD"] [unique_id "aoSCZv2v-lWn9OzQT7U1zgAAhjI"] [Tue Aug 18 13:03:50.606681 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:50.607111 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:50.634507 2026] [security2:error] [pid 139043:tid 139244] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCZv2v-lWn9OzQT7U10wAAAMw"] [Tue Aug 18 13:03:50.669859 2026] [security2:error] [pid 139043:tid 139241] [client 20.124.247.79:16868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/wpxml.php"] [unique_id "aoSCZv2v-lWn9OzQT7U11wAAAMk"] [Tue Aug 18 13:03:50.697263 2026] [security2:error] [pid 139043:tid 139252] [client 68.155.154.236:8347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCZv2v-lWn9OzQT7U12QAAANQ"] [Tue Aug 18 13:03:50.701256 2026] [security2:error] [pid 139043:tid 139222] [client 20.1.169.243:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/about.php"] [unique_id "aoSCZv2v-lWn9OzQT7U12gAAALY"] [Tue Aug 18 13:03:50.733675 2026] [security2:error] [pid 139043:tid 139211] [client 20.104.100.201:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/av.php"] [unique_id "aoSCZv2v-lWn9OzQT7U12wAAAKs"] [Tue Aug 18 13:03:50.761061 2026] [security2:error] [pid 139043:tid 139293] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/666.php"] [unique_id "aoSCZv2v-lWn9OzQT7U13wAAAP0"] [Tue Aug 18 13:03:50.774523 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSCZv2v-lWn9OzQT7U14AAAAMg"] [Tue Aug 18 13:03:50.830280 2026] [security2:error] [pid 139043:tid 139289] [client 4.232.151.198:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSCZv2v-lWn9OzQT7U14QAAAPk"] [Tue Aug 18 13:03:50.842182 2026] [security2:error] [pid 139043:tid 139190] [client 20.80.111.3:12492] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.formafit.com.br"] [uri "/images/c99.php"] [unique_id "aoSCZv2v-lWn9OzQT7U14wAAAJY"] [Tue Aug 18 13:03:50.865740 2026] [security2:error] [pid 139043:tid 139245] [client 20.51.153.15:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/main.php"] [unique_id "aoSCZv2v-lWn9OzQT7U15QAAAM0"] [Tue Aug 18 13:03:50.868589 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.200.96:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wsrer.php"] [unique_id "aoSCZv2v-lWn9OzQT7U15gAAAJk"] [Tue Aug 18 13:03:50.869452 2026] [security2:error] [pid 139043:tid 139282] [client 20.250.27.191:40605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/aa.php"] [unique_id "aoSCZv2v-lWn9OzQT7U15wAAAPI"] [Tue Aug 18 13:03:50.889129 2026] [security2:error] [pid 139043:tid 139186] [client 20.51.153.15:9168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/app.php"] [unique_id "aoSCZv2v-lWn9OzQT7U16AAAAJI"] [Tue Aug 18 13:03:50.902091 2026] [security2:error] [pid 139043:tid 139261] [client 213.35.127.232:52937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCZv2v-lWn9OzQT7U16gAAAN0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:50.905193 2026] [security2:error] [pid 139043:tid 139227] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/thui.php"] [unique_id "aoSCZv2v-lWn9OzQT7U16wAAALs"] [Tue Aug 18 13:03:50.905207 2026] [security2:error] [pid 139043:tid 139272] [client 74.248.18.37:58552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSCZv2v-lWn9OzQT7U17AAAAOg"] [Tue Aug 18 13:03:50.905713 2026] [authz_core:error] [pid 139043:tid 139073] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:50.906032 2026] [authz_core:error] [pid 139043:tid 139073] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:50.913853 2026] [security2:error] [pid 139043:tid 139274] [client 20.151.109.219:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ve.php"] [unique_id "aoSCZv2v-lWn9OzQT7U17QAAAOo"] [Tue Aug 18 13:03:50.919897 2026] [security2:error] [pid 139043:tid 139220] [client 20.206.73.37:11910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/uwu.php"] [unique_id "aoSCZv2v-lWn9OzQT7U17gAAALQ"] [Tue Aug 18 13:03:50.925063 2026] [security2:error] [pid 139043:tid 139205] [client 20.124.247.79:16858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/file1221.php"] [unique_id "aoSCZv2v-lWn9OzQT7U18AAAAKU"] [Tue Aug 18 13:03:50.931746 2026] [security2:error] [pid 139043:tid 139298] [client 20.151.109.219:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCZv2v-lWn9OzQT7U18QAAAQI"] [Tue Aug 18 13:03:50.938120 2026] [security2:error] [pid 139043:tid 139256] [client 20.52.168.85:5121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCZv2v-lWn9OzQT7U18wAAANg"] [Tue Aug 18 13:03:50.946570 2026] [security2:error] [pid 139043:tid 139284] [client 20.171.51.14:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCZv2v-lWn9OzQT7U19AAAAPQ"] [Tue Aug 18 13:03:50.980309 2026] [security2:error] [pid 139043:tid 139100] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "aoSCZv2v-lWn9OzQT7U19gAAkTg"] [Tue Aug 18 13:03:50.982146 2026] [security2:error] [pid 139043:tid 139200] [client 20.206.73.37:2148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCZv2v-lWn9OzQT7U19wAAAKA"] [Tue Aug 18 13:03:50.992197 2026] [security2:error] [pid 139043:tid 139188] [client 168.62.48.100:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/update/wpupex.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1-AAAAJQ"] [Tue Aug 18 13:03:50.993978 2026] [security2:error] [pid 139043:tid 139225] [client 20.226.36.136:57225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1-QAAALk"] [Tue Aug 18 13:03:50.995491 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCZv2v-lWn9OzQT7U1-gAAAOk"] [Tue Aug 18 13:03:51.015923 2026] [security2:error] [pid 139043:tid 139212] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/agg.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U1-wAAAKw"] [Tue Aug 18 13:03:51.067406 2026] [security2:error] [pid 139043:tid 139287] [client 20.1.169.243:11143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/about/function.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U1_gAAAPc"] [Tue Aug 18 13:03:51.076645 2026] [security2:error] [pid 139043:tid 139270] [client 168.62.48.100:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U1_wAAAOY"] [Tue Aug 18 13:03:51.083060 2026] [security2:error] [pid 139043:tid 139217] [client 20.163.43.14:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/lock360.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2AAAAALE"] [Tue Aug 18 13:03:51.086449 2026] [security2:error] [pid 139043:tid 139265] [client 74.249.206.207:31042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2AQAAAOE"] [Tue Aug 18 13:03:51.112647 2026] [security2:error] [pid 139043:tid 139255] [client 20.51.153.15:8319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ga.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2AwAAANc"] [Tue Aug 18 13:03:51.120962 2026] [security2:error] [pid 139043:tid 139253] [client 158.23.17.4:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ga.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2BAAAANU"] [Tue Aug 18 13:03:51.126678 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/erty.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2BQAAAPs"] [Tue Aug 18 13:03:51.161376 2026] [security2:error] [pid 139043:tid 139269] [client 52.173.121.69:10079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2CAAAAOU"] [Tue Aug 18 13:03:51.176521 2026] [security2:error] [pid 139043:tid 139179] [client 20.51.153.15:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/87.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2CQAAAIs"] [Tue Aug 18 13:03:51.205744 2026] [authz_core:error] [pid 139043:tid 139118] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:51.206005 2026] [authz_core:error] [pid 139043:tid 139118] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:51.206843 2026] [security2:error] [pid 139043:tid 139252] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/mini.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2DQAAANQ"] [Tue Aug 18 13:03:51.216038 2026] [security2:error] [pid 139043:tid 139125] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env"] [unique_id "aoSCZ_2v-lWn9OzQT7U2DgAA7VE"] [Tue Aug 18 13:03:51.223323 2026] [security2:error] [pid 139043:tid 139222] [client 4.223.113.180:20216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-block.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2DwAAALY"] [Tue Aug 18 13:03:51.223689 2026] [security2:error] [pid 139043:tid 139259] [client 20.124.247.79:16843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/nox.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2EAAAANs"] [Tue Aug 18 13:03:51.264131 2026] [security2:error] [pid 139043:tid 139268] [client 172.182.217.32:21538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2EQAAAOQ"] [Tue Aug 18 13:03:51.292030 2026] [security2:error] [pid 139043:tid 139194] [client 4.232.151.198:11276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/simple.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2FAAAAJo"] [Tue Aug 18 13:03:51.300923 2026] [security2:error] [pid 139043:tid 139275] [client 20.250.27.191:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/img.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2FQAAAOs"] [Tue Aug 18 13:03:51.304732 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.200.96:15560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2FgAAAMg"] [Tue Aug 18 13:03:51.319869 2026] [security2:error] [pid 139043:tid 139276] [client 157.20.138.62:55930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2GAAAAOw"] [Tue Aug 18 13:03:51.319997 2026] [security2:error] [pid 139043:tid 139276] [client 157.20.138.62:55930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2GAAAAOw"] [Tue Aug 18 13:03:51.320643 2026] [security2:error] [pid 139043:tid 139175] [client 20.116.17.175:3448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/yawa.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2GQAAAIc"] [Tue Aug 18 13:03:51.328285 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xj.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2GgAAALM"] [Tue Aug 18 13:03:51.346002 2026] [security2:error] [pid 139043:tid 139248] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/k.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2GwAAANA"] [Tue Aug 18 13:03:51.400671 2026] [security2:error] [pid 139043:tid 139193] [client 74.249.206.207:45541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2HgAAAJk"] [Tue Aug 18 13:03:51.416979 2026] [security2:error] [pid 139043:tid 139282] [client 68.221.73.131:18587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2HwAAAPI"] [Tue Aug 18 13:03:51.433553 2026] [security2:error] [pid 139043:tid 139191] [client 20.1.169.243:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/admin/admin.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2IAAAAJc"] [Tue Aug 18 13:03:51.440831 2026] [security2:error] [pid 139043:tid 139266] [client 20.80.111.3:25832] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.formafit.com.br"] [uri "/images/c99.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2IQAAAOI"] [Tue Aug 18 13:03:51.447006 2026] [security2:error] [pid 139043:tid 139272] [client 20.51.153.15:9195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/zi.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2IgAAAOg"] [Tue Aug 18 13:03:51.447852 2026] [security2:error] [pid 139043:tid 139137] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.old"] [unique_id "aoSCZ_2v-lWn9OzQT7U2IwAA6l0"] [Tue Aug 18 13:03:51.450679 2026] [security2:error] [pid 139043:tid 139201] [client 4.232.151.198:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2JAAAAKE"] [Tue Aug 18 13:03:51.453324 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:9520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/wb.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2JQAAALQ"] [Tue Aug 18 13:03:51.477476 2026] [security2:error] [pid 139043:tid 139298] [client 20.163.43.14:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/flower.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2KQAAAQI"] [Tue Aug 18 13:03:51.486194 2026] [security2:error] [pid 139043:tid 139111] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.local"] [unique_id "aoSCZ_2v-lWn9OzQT7U2KwAA9EM"] [Tue Aug 18 13:03:51.499871 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:58725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ia.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2LAAAAKA"] [Tue Aug 18 13:03:51.506312 2026] [security2:error] [pid 139043:tid 139225] [client 20.206.73.37:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/signon.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2LgAAALk"] [Tue Aug 18 13:03:51.521644 2026] [security2:error] [pid 139043:tid 139112] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.example"] [unique_id "aoSCZ_2v-lWn9OzQT7U2MAAAlEQ"] [Tue Aug 18 13:03:51.521644 2026] [security2:error] [pid 139043:tid 139080] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.backup"] [unique_id "aoSCZ_2v-lWn9OzQT7U2MQAAlCQ"] [Tue Aug 18 13:03:51.521648 2026] [security2:error] [pid 139043:tid 139061] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.production"] [unique_id "aoSCZ_2v-lWn9OzQT7U2LwAAlBE"] [Tue Aug 18 13:03:51.543735 2026] [security2:error] [pid 139043:tid 139051] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.bak"] [unique_id "aoSCZ_2v-lWn9OzQT7U2MgAAlAc"] [Tue Aug 18 13:03:51.553197 2026] [security2:error] [pid 139043:tid 139289] [client 20.52.168.85:5146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/file.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2NQAAAPk"] [Tue Aug 18 13:03:51.560923 2026] [security2:error] [pid 139043:tid 139123] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2NgAArE8"] [Tue Aug 18 13:03:51.561089 2026] [security2:error] [pid 139043:tid 139212] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2NgAArE8"] [Tue Aug 18 13:03:51.573195 2026] [security2:error] [pid 139043:tid 139258] [client 74.248.18.37:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2OAAAANo"] [Tue Aug 18 13:03:51.575272 2026] [security2:error] [pid 139043:tid 139190] [client 20.124.247.79:16775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/akismet.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2OQAAAJY"] [Tue Aug 18 13:03:51.577838 2026] [security2:error] [pid 139043:tid 139208] [client 158.23.17.4:29486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/uk.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2OgAAAKg"] [Tue Aug 18 13:03:51.654878 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2PAAAALE"] [Tue Aug 18 13:03:51.704513 2026] [security2:error] [pid 139043:tid 139269] [client 74.249.206.207:45544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/media.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2QQAAAOU"] [Tue Aug 18 13:03:51.717269 2026] [security2:error] [pid 139043:tid 139176] [client 20.151.109.219:36313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2QwAAAIg"] [Tue Aug 18 13:03:51.720185 2026] [security2:error] [pid 139043:tid 139244] [client 20.250.27.191:39710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/222.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2RAAAAMw"] [Tue Aug 18 13:03:51.721187 2026] [security2:error] [pid 139043:tid 139295] [client 20.51.153.15:8822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/92.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2RQAAAP8"] [Tue Aug 18 13:03:51.723138 2026] [security2:error] [pid 139043:tid 139292] [client 20.104.100.201:24022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/kj.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2RgAAAPw"] [Tue Aug 18 13:03:51.754966 2026] [security2:error] [pid 139043:tid 139242] [client 138.36.100.162:43259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2SAAAAMo"] [Tue Aug 18 13:03:51.755063 2026] [security2:error] [pid 139043:tid 139242] [client 138.36.100.162:43259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2SAAAAMo"] [Tue Aug 18 13:03:51.760581 2026] [security2:error] [pid 139043:tid 139271] [client 172.182.200.96:15509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/yxijx.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2SQAAAOc"] [Tue Aug 18 13:03:51.761912 2026] [security2:error] [pid 139043:tid 139283] [client 172.182.217.32:21775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/about.php7"] [unique_id "aoSCZ_2v-lWn9OzQT7U2SgAAAPM"] [Tue Aug 18 13:03:51.797091 2026] [security2:error] [pid 139043:tid 139222] [client 20.51.153.15:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/xn.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2SwAAALY"] [Tue Aug 18 13:03:51.799892 2026] [security2:error] [pid 139043:tid 139255] [client 20.1.169.243:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/admin/function.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2TAAAANc"] [Tue Aug 18 13:03:51.827386 2026] [security2:error] [pid 139043:tid 139246] [client 20.171.51.14:18649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/st.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2TgAAAM4"] [Tue Aug 18 13:03:51.839938 2026] [security2:error] [pid 139043:tid 139211] [client 20.124.247.79:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/admin.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2UAAAAKs"] [Tue Aug 18 13:03:51.852664 2026] [security2:error] [pid 139043:tid 139234] [client 158.23.17.4:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/wb.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2UQAAAMI"] [Tue Aug 18 13:03:51.892994 2026] [security2:error] [pid 139043:tid 139179] [client 20.80.111.3:26275] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.formafit.com.br"] [uri "/images/c99.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2UwAAAIs"] [Tue Aug 18 13:03:51.893089 2026] [security2:error] [pid 139043:tid 139224] [client 68.155.154.236:8378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2VAAAALg"] [Tue Aug 18 13:03:51.900973 2026] [security2:error] [pid 139043:tid 139262] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/403.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2VQAAAN4"] [Tue Aug 18 13:03:51.914618 2026] [security2:error] [pid 139043:tid 139235] [client 213.35.127.232:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2VgAAAMM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:51.924021 2026] [security2:error] [pid 139043:tid 139243] [client 178.153.171.161:2043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2VwAAAMs"] [Tue Aug 18 13:03:51.924172 2026] [security2:error] [pid 139043:tid 139243] [client 178.153.171.161:2043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2VwAAAMs"] [Tue Aug 18 13:03:51.944670 2026] [security2:error] [pid 139043:tid 139245] [client 20.163.43.14:4372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/13.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2WwAAAM0"] [Tue Aug 18 13:03:51.972342 2026] [security2:error] [pid 139043:tid 139178] [client 103.120.71.157:34343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2XAAAAIo"] [Tue Aug 18 13:03:51.972467 2026] [security2:error] [pid 139043:tid 139178] [client 103.120.71.157:34343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2XAAAAIo"] [Tue Aug 18 13:03:51.987054 2026] [security2:error] [pid 139043:tid 139075] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/admin/.env"] [unique_id "aoSCZ_2v-lWn9OzQT7U2XQAA6B8"] [Tue Aug 18 13:03:51.995695 2026] [security2:error] [pid 139043:tid 139201] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCZ_2v-lWn9OzQT7U2XgAAAKE"] [Tue Aug 18 13:03:52.003364 2026] [security2:error] [pid 139043:tid 139218] [client 20.206.73.37:24710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/ajax.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2XwAAALI"] [Tue Aug 18 13:03:52.020762 2026] [security2:error] [pid 139043:tid 139284] [client 20.51.153.15:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/jm.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2YwAAAPQ"] [Tue Aug 18 13:03:52.020849 2026] [security2:error] [pid 139043:tid 139256] [client 74.249.206.207:45548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/admin.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2YgAAANg"] [Tue Aug 18 13:03:52.026431 2026] [security2:error] [pid 139043:tid 139151] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/.env"] [unique_id "aoSCaP2v-lWn9OzQT7U2ZAAAj2s"] [Tue Aug 18 13:03:52.033881 2026] [security2:error] [pid 139043:tid 139077] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/backend/.env"] [unique_id "aoSCaP2v-lWn9OzQT7U2ZQAAoCE"] [Tue Aug 18 13:03:52.045520 2026] [security2:error] [pid 139043:tid 139170] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config/.env"] [unique_id "aoSCaP2v-lWn9OzQT7U2ZgAA6X4"] [Tue Aug 18 13:03:52.045591 2026] [security2:error] [pid 139043:tid 139126] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/secrets.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2ZwAA6VI"] [Tue Aug 18 13:03:52.050544 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2aAAAAJA"] [Tue Aug 18 13:03:52.051518 2026] [security2:error] [pid 139043:tid 139084] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/secrets.yml"] [unique_id "aoSCaP2v-lWn9OzQT7U2aQAAnSg"] [Tue Aug 18 13:03:52.107538 2026] [security2:error] [pid 139043:tid 139233] [client 20.124.247.79:16781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orientalbrindes.com.br"] [uri "/ajax.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2bQAAAME"] [Tue Aug 18 13:03:52.115823 2026] [security2:error] [pid 139043:tid 139192] [client 4.232.151.198:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2bwAAAJg"] [Tue Aug 18 13:03:52.120143 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:52.120415 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:52.123536 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.36.136:57829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2cQAAAK4"] [Tue Aug 18 13:03:52.124711 2026] [security2:error] [pid 139043:tid 139188] [client 20.116.17.175:53555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2cgAAAJQ"] [Tue Aug 18 13:03:52.128056 2026] [security2:error] [pid 139043:tid 139217] [client 20.51.153.15:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/47.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2cwAAALE"] [Tue Aug 18 13:03:52.129028 2026] [security2:error] [pid 139043:tid 139296] [client 158.23.17.4:38857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/creds.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2dAAAAQA"] [Tue Aug 18 13:03:52.134848 2026] [security2:error] [pid 139043:tid 139081] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2dQAA2yU"] [Tue Aug 18 13:03:52.134998 2026] [security2:error] [pid 139043:tid 139259] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2dQAA2yU"] [Tue Aug 18 13:03:52.148894 2026] [security2:error] [pid 139043:tid 139206] [client 20.250.27.191:40585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/key.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2dgAAAKY"] [Tue Aug 18 13:03:52.155139 2026] [security2:error] [pid 139043:tid 139250] [client 20.52.168.85:5126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2dwAAANI"] [Tue Aug 18 13:03:52.166651 2026] [security2:error] [pid 139043:tid 139225] [client 20.1.169.243:10930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2eAAAALk"] [Tue Aug 18 13:03:52.182421 2026] [security2:error] [pid 139043:tid 139244] [client 172.182.200.96:15495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2egAAAMw"] [Tue Aug 18 13:03:52.203918 2026] [security2:error] [pid 139043:tid 139274] [client 74.248.18.37:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2fAAAAOo"] [Tue Aug 18 13:03:52.242234 2026] [security2:error] [pid 139043:tid 139205] [client 20.151.109.219:20935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/st.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2fwAAAKU"] [Tue Aug 18 13:03:52.247661 2026] [security2:error] [pid 139043:tid 139213] [client 172.182.217.32:21764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/adminfuns.php7"] [unique_id "aoSCaP2v-lWn9OzQT7U2gAAAAK0"] [Tue Aug 18 13:03:52.247772 2026] [security2:error] [pid 139043:tid 139239] [client 158.23.17.4:48444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ns.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2gQAAAMc"] [Tue Aug 18 13:03:52.332767 2026] [security2:error] [pid 139043:tid 139149] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/service-account.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2hgAA7Wk"] [Tue Aug 18 13:03:52.339614 2026] [security2:error] [pid 139043:tid 139222] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sid3.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2iAAAALY"] [Tue Aug 18 13:03:52.340217 2026] [security2:error] [pid 139043:tid 139295] [client 20.80.111.3:25808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/images/g3.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2iQAAAP8"] [Tue Aug 18 13:03:52.342634 2026] [security2:error] [pid 139043:tid 139255] [client 20.151.109.219:27391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kn.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2igAAANc"] [Tue Aug 18 13:03:52.345810 2026] [security2:error] [pid 139043:tid 139246] [client 74.248.130.103:34980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2iwAAAM4"] [Tue Aug 18 13:03:52.366678 2026] [security2:error] [pid 139043:tid 139221] [client 74.249.206.207:31070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/mac.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2jAAAALU"] [Tue Aug 18 13:03:52.376927 2026] [security2:error] [pid 139043:tid 139234] [client 20.51.153.15:9211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wj.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2jgAAAMI"] [Tue Aug 18 13:03:52.379012 2026] [security2:error] [pid 139043:tid 139279] [client 20.163.43.14:4358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/cc.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2jwAAAO8"] [Tue Aug 18 13:03:52.391927 2026] [security2:error] [pid 139043:tid 139105] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/credentials.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2kgABAT0"] [Tue Aug 18 13:03:52.410302 2026] [security2:error] [pid 139043:tid 139275] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/weozh.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2kwAAAOs"] [Tue Aug 18 13:03:52.423580 2026] [authz_core:error] [pid 139043:tid 139119] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:52.423887 2026] [authz_core:error] [pid 139043:tid 139119] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:52.436441 2026] [security2:error] [pid 139043:tid 139181] [client 20.51.153.15:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/payout.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2lwAAAI0"] [Tue Aug 18 13:03:52.444534 2026] [security2:error] [pid 139043:tid 139245] [client 20.206.73.37:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/file61.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2mAAAAM0"] [Tue Aug 18 13:03:52.449995 2026] [security2:error] [pid 139043:tid 139290] [client 20.171.51.14:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/le.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2mQAAAPo"] [Tue Aug 18 13:03:52.501703 2026] [security2:error] [pid 139043:tid 139284] [client 20.104.100.201:24039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2nwAAAPQ"] [Tue Aug 18 13:03:52.537454 2026] [security2:error] [pid 139043:tid 139113] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/key.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2oAAA6UU"] [Tue Aug 18 13:03:52.539450 2026] [security2:error] [pid 139043:tid 139235] [client 20.1.169.243:10939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2oQAAAMM"] [Tue Aug 18 13:03:52.562342 2026] [security2:error] [pid 139043:tid 139159] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2ogAA_XM"] [Tue Aug 18 13:03:52.564328 2026] [security2:error] [pid 139043:tid 139134] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/service_account.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2owAAllo"] [Tue Aug 18 13:03:52.564332 2026] [security2:error] [pid 139043:tid 139162] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2pAAAlnY"] [Tue Aug 18 13:03:52.570743 2026] [security2:error] [pid 139043:tid 139179] [client 20.250.27.191:40629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/chosen.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2pgAAAIs"] [Tue Aug 18 13:03:52.575708 2026] [security2:error] [pid 139043:tid 139208] [client 68.221.73.131:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/puc.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2pwAAAKg"] [Tue Aug 18 13:03:52.597557 2026] [security2:error] [pid 139043:tid 139281] [client 172.182.200.96:15531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/jrpga.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2qAAAAPE"] [Tue Aug 18 13:03:52.632381 2026] [security2:error] [pid 139043:tid 139214] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/moon.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2qQAAAK4"] [Tue Aug 18 13:03:52.636468 2026] [security2:error] [pid 139043:tid 139265] [client 20.51.153.15:9124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/74.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2qgAAAOE"] [Tue Aug 18 13:03:52.653669 2026] [security2:error] [pid 139043:tid 139249] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/gecko.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2qwAAANE"] [Tue Aug 18 13:03:52.703056 2026] [security2:error] [pid 139043:tid 139202] [client 74.249.206.207:45537] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2rgAAAKI"] [Tue Aug 18 13:03:52.703163 2026] [security2:error] [pid 139043:tid 139202] [client 74.249.206.207:45537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/1.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2rgAAAKI"] [Tue Aug 18 13:03:52.704442 2026] [security2:error] [pid 139043:tid 139274] [client 20.51.153.15:9784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/bh.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2rwAAAOo"] [Tue Aug 18 13:03:52.722185 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:52.722463 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:52.735425 2026] [security2:error] [pid 139043:tid 139239] [client 20.163.43.14:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2sgAAAMc"] [Tue Aug 18 13:03:52.735827 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.217.32:21782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ebs.php7"] [unique_id "aoSCaP2v-lWn9OzQT7U2swAAAMQ"] [Tue Aug 18 13:03:52.744732 2026] [security2:error] [pid 139043:tid 139264] [client 4.232.151.198:4153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2tAAAAOA"] [Tue Aug 18 13:03:52.760594 2026] [security2:error] [pid 139043:tid 139267] [client 20.52.168.85:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/news.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2twAAAOM"] [Tue Aug 18 13:03:52.807045 2026] [security2:error] [pid 139043:tid 139158] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/Dockerfile"] [unique_id "aoSCaP2v-lWn9OzQT7U2ugAA1HI"] [Tue Aug 18 13:03:52.807096 2026] [security2:error] [pid 139043:tid 139177] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/rymmm.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2uQAAAIk"] [Tue Aug 18 13:03:52.824516 2026] [security2:error] [pid 139043:tid 139270] [client 158.23.17.4:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ho.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2vAAAAOY"] [Tue Aug 18 13:03:52.824911 2026] [security2:error] [pid 139043:tid 139217] [client 20.80.111.3:25828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/img/omar.php.png"] [unique_id "aoSCaP2v-lWn9OzQT7U2uwAAALE"] [Tue Aug 18 13:03:52.891414 2026] [security2:error] [pid 139043:tid 139204] [client 20.116.17.175:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/7.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2wQAAAKQ"] [Tue Aug 18 13:03:52.908019 2026] [security2:error] [pid 139043:tid 139241] [client 20.1.169.243:10935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/ahax.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2wgAAAMk"] [Tue Aug 18 13:03:52.941117 2026] [security2:error] [pid 139043:tid 139297] [client 20.51.153.15:9126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/av.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2xAAAAQE"] [Tue Aug 18 13:03:52.942274 2026] [security2:error] [pid 139043:tid 139180] [client 213.35.127.232:53343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2xgAAAIw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:52.981968 2026] [security2:error] [pid 139043:tid 139143] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/firebase-service-account.json"] [unique_id "aoSCaP2v-lWn9OzQT7U2yAAAm2M"] [Tue Aug 18 13:03:52.999489 2026] [security2:error] [pid 139043:tid 139175] [client 20.250.27.191:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wpxml.php"] [unique_id "aoSCaP2v-lWn9OzQT7U2yQAAAIc"] [Tue Aug 18 13:03:53.002902 2026] [security2:error] [pid 139043:tid 139219] [client 74.249.206.207:26944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/coffee.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2ygAAALM"] [Tue Aug 18 13:03:53.012331 2026] [security2:error] [pid 139043:tid 139248] [client 20.171.51.14:47152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/hr.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2zAAAANA"] [Tue Aug 18 13:03:53.024495 2026] [security2:error] [pid 139043:tid 139243] [client 68.155.156.252:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/82.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2zgAAAMs"] [Tue Aug 18 13:03:53.024631 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:53.025015 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:53.026654 2026] [security2:error] [pid 139043:tid 139237] [client 20.51.153.15:9566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/ct.php"] [unique_id "aoSCaf2v-lWn9OzQT7U20AAAAMU"] [Tue Aug 18 13:03:53.062349 2026] [security2:error] [pid 139043:tid 139261] [client 172.182.200.96:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCaf2v-lWn9OzQT7U20wAAAN0"] [Tue Aug 18 13:03:53.082821 2026] [security2:error] [pid 139043:tid 139230] [client 20.206.73.37:17001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/yj09.php"] [unique_id "aoSCaf2v-lWn9OzQT7U22QAAAL4"] [Tue Aug 18 13:03:53.113131 2026] [security2:error] [pid 139043:tid 139298] [client 68.155.154.236:40458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCaf2v-lWn9OzQT7U23wAAAQI"] [Tue Aug 18 13:03:53.115558 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:4352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSCaf2v-lWn9OzQT7U24AAAAPQ"] [Tue Aug 18 13:03:53.142941 2026] [security2:error] [pid 139043:tid 139185] [client 20.206.73.37:11967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/copypaths.php"] [unique_id "aoSCaf2v-lWn9OzQT7U24wAAAJE"] [Tue Aug 18 13:03:53.145704 2026] [security2:error] [pid 139043:tid 139183] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/lddxs.php"] [unique_id "aoSCaf2v-lWn9OzQT7U25AAAAI8"] [Tue Aug 18 13:03:53.178555 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wm.php"] [unique_id "aoSCaf2v-lWn9OzQT7U25QAAAPk"] [Tue Aug 18 13:03:53.188343 2026] [security2:error] [pid 139043:tid 139208] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ms.php"] [unique_id "aoSCaf2v-lWn9OzQT7U25wAAAKg"] [Tue Aug 18 13:03:53.203262 2026] [security2:error] [pid 139043:tid 139192] [client 20.51.153.15:9214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ag.php"] [unique_id "aoSCaf2v-lWn9OzQT7U26AAAAJg"] [Tue Aug 18 13:03:53.211707 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/aa.php"] [unique_id "aoSCaf2v-lWn9OzQT7U26gAAAN8"] [Tue Aug 18 13:03:53.217542 2026] [security2:error] [pid 139043:tid 139247] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCaf2v-lWn9OzQT7U26wAAAM8"] [Tue Aug 18 13:03:53.226415 2026] [security2:error] [pid 139043:tid 139173] [client 172.182.217.32:21785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ws.php7"] [unique_id "aoSCaf2v-lWn9OzQT7U27QAAAIU"] [Tue Aug 18 13:03:53.227262 2026] [security2:error] [pid 139043:tid 139188] [client 20.104.100.201:23952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/png.php"] [unique_id "aoSCaf2v-lWn9OzQT7U27gAAAJQ"] [Tue Aug 18 13:03:53.264424 2026] [security2:error] [pid 139043:tid 139229] [client 74.248.18.37:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSCaf2v-lWn9OzQT7U28wAAAL0"] [Tue Aug 18 13:03:53.284028 2026] [security2:error] [pid 139043:tid 139232] [client 20.1.169.243:10931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/alfa.php"] [unique_id "aoSCaf2v-lWn9OzQT7U29AAAAMA"] [Tue Aug 18 13:03:53.309999 2026] [security2:error] [pid 139043:tid 139226] [client 20.51.153.15:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/gy.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2-QAAALo"] [Tue Aug 18 13:03:53.327598 2026] [authz_core:error] [pid 139043:tid 139131] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:53.327894 2026] [authz_core:error] [pid 139043:tid 139131] [remote 216.73.216.206:3105] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:53.336129 2026] [security2:error] [pid 139043:tid 139190] [client 20.80.111.3:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/index/function.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2_QAAAJY"] [Tue Aug 18 13:03:53.343789 2026] [security2:error] [pid 139043:tid 139292] [client 20.250.13.23:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2_gAAAPw"] [Tue Aug 18 13:03:53.364271 2026] [security2:error] [pid 139043:tid 139205] [client 20.79.204.6:9678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/bthil.php"] [unique_id "aoSCaf2v-lWn9OzQT7U2_wAAAKU"] [Tue Aug 18 13:03:53.372628 2026] [security2:error] [pid 139043:tid 139236] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wsws.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3AQAAAMQ"] [Tue Aug 18 13:03:53.383776 2026] [autoindex:error] [pid 139043:tid 139184] [client 20.52.168.85:5138] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:53.392684 2026] [security2:error] [pid 139043:tid 139242] [client 74.248.130.103:42011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3AwAAAMo"] [Tue Aug 18 13:03:53.396402 2026] [security2:error] [pid 139043:tid 139225] [client 103.184.169.37:43665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3BAAAALk"] [Tue Aug 18 13:03:53.396571 2026] [security2:error] [pid 139043:tid 139225] [client 103.184.169.37:43665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3BAAAALk"] [Tue Aug 18 13:03:53.397297 2026] [security2:error] [pid 139043:tid 139235] [client 4.232.151.198:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3BQAAAMM"] [Tue Aug 18 13:03:53.398841 2026] [security2:error] [pid 139043:tid 139267] [client 74.249.206.207:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3BgAAAOM"] [Tue Aug 18 13:03:53.420899 2026] [security2:error] [pid 139043:tid 139174] [client 20.250.27.191:26110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/file1221.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3CQAAAIY"] [Tue Aug 18 13:03:53.434690 2026] [security2:error] [pid 139043:tid 139252] [client 20.171.51.14:7887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kt.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3CgAAANQ"] [Tue Aug 18 13:03:53.448086 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.200.96:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/nwwha.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3CwAAAIk"] [Tue Aug 18 13:03:53.465902 2026] [security2:error] [pid 139043:tid 139222] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/zjggu.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3DQAAALY"] [Tue Aug 18 13:03:53.466637 2026] [security2:error] [pid 139043:tid 139295] [client 20.51.153.15:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ig.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3DgAAAP8"] [Tue Aug 18 13:03:53.466674 2026] [security2:error] [pid 139043:tid 139268] [client 4.223.113.180:12143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wk/index.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3DwAAAOQ"] [Tue Aug 18 13:03:53.469434 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/01.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3EAAAAOY"] [Tue Aug 18 13:03:53.480559 2026] [security2:error] [pid 139043:tid 139255] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3EQAAANc"] [Tue Aug 18 13:03:53.546378 2026] [security2:error] [pid 139043:tid 139271] [client 178.156.187.238:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3CAAAAOc"], referer: https://bn2s.com.br/ [Tue Aug 18 13:03:53.561325 2026] [security2:error] [pid 139043:tid 139274] [client 20.250.13.23:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3EwAAAOo"] [Tue Aug 18 13:03:53.565188 2026] [security2:error] [pid 139043:tid 139275] [client 158.23.17.4:15142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/xn.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3FAAAAOs"] [Tue Aug 18 13:03:53.569612 2026] [security2:error] [pid 139043:tid 139182] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/0x.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3FQAAAI4"] [Tue Aug 18 13:03:53.585523 2026] [security2:error] [pid 139043:tid 139195] [client 20.52.168.85:5138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/yanz.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3FwAAAJs"] [Tue Aug 18 13:03:53.608312 2026] [security2:error] [pid 139043:tid 139237] [client 20.51.153.15:9494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/tt.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3GAAAAMU"] [Tue Aug 18 13:03:53.617328 2026] [security2:error] [pid 139043:tid 139178] [client 52.173.121.69:52564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3GQAAAIo"] [Tue Aug 18 13:03:53.625766 2026] [security2:error] [pid 139043:tid 139276] [client 20.151.109.219:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/le.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3GgAAAOw"] [Tue Aug 18 13:03:53.626279 2026] [security2:error] [pid 139043:tid 139272] [client 20.226.36.136:57793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3GwAAAOg"] [Tue Aug 18 13:03:53.633885 2026] [security2:error] [pid 139043:tid 139254] [client 20.151.109.219:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ac.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3HAAAANY"] [Tue Aug 18 13:03:53.648032 2026] [security2:error] [pid 139043:tid 139246] [client 20.1.169.243:11156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/alfax.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3HgAAAM4"] [Tue Aug 18 13:03:53.670614 2026] [security2:error] [pid 139043:tid 139197] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/motu.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3IQAAAJ0"] [Tue Aug 18 13:03:53.677840 2026] [security2:error] [pid 139043:tid 139289] [client 68.221.73.131:26411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/8.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3IgAAAPk"] [Tue Aug 18 13:03:53.681086 2026] [security2:error] [pid 139043:tid 139179] [client 158.23.17.4:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/97.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3IwAAAIs"] [Tue Aug 18 13:03:53.706435 2026] [security2:error] [pid 139043:tid 139265] [client 20.206.73.37:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/bless6.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3JAAAAOE"] [Tue Aug 18 13:03:53.715295 2026] [security2:error] [pid 139043:tid 139180] [client 172.182.217.32:21539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfanew2.php7"] [unique_id "aoSCaf2v-lWn9OzQT7U3JQAAAIw"] [Tue Aug 18 13:03:53.715951 2026] [security2:error] [pid 139043:tid 139229] [client 74.249.206.207:7901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3JgAAAL0"] [Tue Aug 18 13:03:53.727339 2026] [security2:error] [pid 139043:tid 139206] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/admin.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3JwAAAKY"] [Tue Aug 18 13:03:53.780503 2026] [security2:error] [pid 139043:tid 139205] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3LAAAAKU"] [Tue Aug 18 13:03:53.781995 2026] [security2:error] [pid 139043:tid 139236] [client 20.116.17.175:53183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ws77.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3LQAAAMQ"] [Tue Aug 18 13:03:53.820272 2026] [security2:error] [pid 139043:tid 139273] [client 20.80.111.3:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/inputs.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3MQAAAOk"] [Tue Aug 18 13:03:53.845478 2026] [security2:error] [pid 139043:tid 139174] [client 20.104.100.201:23971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ab.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3MgAAAIY"] [Tue Aug 18 13:03:53.846469 2026] [security2:error] [pid 139043:tid 139252] [client 20.163.43.14:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/lv.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3MwAAANQ"] [Tue Aug 18 13:03:53.850331 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.200.96:15494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/opsqt.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3NQAAAIk"] [Tue Aug 18 13:03:53.866465 2026] [security2:error] [pid 139043:tid 139295] [client 20.250.27.191:25419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/nox.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3NgAAAP8"] [Tue Aug 18 13:03:53.904486 2026] [security2:error] [pid 139043:tid 139223] [client 5.31.227.224:29889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3OwAAALc"] [Tue Aug 18 13:03:53.908372 2026] [security2:error] [pid 139043:tid 139223] [client 5.31.227.224:29889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3OwAAALc"] [Tue Aug 18 13:03:53.910501 2026] [security2:error] [pid 139043:tid 139253] [client 168.62.48.100:4198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3PAAAANU"] [Tue Aug 18 13:03:53.911051 2026] [security2:error] [pid 139043:tid 139299] [client 20.51.153.15:8246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/mq.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3PQAAAQM"] [Tue Aug 18 13:03:53.921148 2026] [security2:error] [pid 139043:tid 139234] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/zxz.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3PgAAAMI"] [Tue Aug 18 13:03:53.931829 2026] [security2:error] [pid 139043:tid 139054] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.s3cfg"] [unique_id "aoSCaf2v-lWn9OzQT7U3QAAA2wo"] [Tue Aug 18 13:03:53.931830 2026] [security2:error] [pid 139043:tid 139045] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.github/.env"] [unique_id "aoSCaf2v-lWn9OzQT7U3QQAA2wE"] [Tue Aug 18 13:03:53.932596 2026] [security2:error] [pid 139043:tid 139100] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.npmrc"] [unique_id "aoSCaf2v-lWn9OzQT7U3QgAA2zg"] [Tue Aug 18 13:03:53.933573 2026] [security2:error] [pid 139043:tid 139089] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.docker/config.json"] [unique_id "aoSCaf2v-lWn9OzQT7U3QwAA2y0"] [Tue Aug 18 13:03:53.954481 2026] [security2:error] [pid 139043:tid 139261] [client 213.35.127.232:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3RgAAAN0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:53.956375 2026] [security2:error] [pid 139043:tid 139241] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fff.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3RwAAAMk"] [Tue Aug 18 13:03:53.959749 2026] [security2:error] [pid 139043:tid 139121] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stremmastay.com.br"] [uri "/wp-login.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3LwAA200"], referer: https://stremmastay.com.br/login [Tue Aug 18 13:03:53.962898 2026] [security2:error] [pid 139043:tid 139256] [client 20.171.51.14:38753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ww.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3SAAAANg"] [Tue Aug 18 13:03:53.977558 2026] [security2:error] [pid 139043:tid 139297] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/public/css.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3SQAAAQE"] [Tue Aug 18 13:03:53.994110 2026] [security2:error] [pid 139043:tid 139224] [client 20.51.153.15:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/34.php"] [unique_id "aoSCaf2v-lWn9OzQT7U3SwAAALg"] [Tue Aug 18 13:03:54.019430 2026] [security2:error] [pid 139043:tid 139225] [client 4.232.151.198:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCav2v-lWn9OzQT7U3TQAAALk"] [Tue Aug 18 13:03:54.020500 2026] [security2:error] [pid 139043:tid 139266] [client 20.1.169.243:11173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/ant.php"] [unique_id "aoSCav2v-lWn9OzQT7U3TgAAAOI"] [Tue Aug 18 13:03:54.051543 2026] [security2:error] [pid 139043:tid 139194] [client 74.249.206.207:31096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/yj09.php"] [unique_id "aoSCav2v-lWn9OzQT7U3UQAAAJo"] [Tue Aug 18 13:03:54.098325 2026] [security2:error] [pid 139043:tid 139245] [client 68.155.156.252:26710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/dex.php"] [unique_id "aoSCav2v-lWn9OzQT7U3UgAAAM0"] [Tue Aug 18 13:03:54.103085 2026] [security2:error] [pid 139043:tid 139237] [client 52.173.121.69:45540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCav2v-lWn9OzQT7U3UwAAAMU"] [Tue Aug 18 13:03:54.115179 2026] [security2:error] [pid 139043:tid 139178] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCav2v-lWn9OzQT7U3VAAAAIo"] [Tue Aug 18 13:03:54.129991 2026] [security2:error] [pid 139043:tid 139071] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.boto"] [unique_id "aoSCav2v-lWn9OzQT7U3VgAAoRs"] [Tue Aug 18 13:03:54.160570 2026] [security2:error] [pid 139043:tid 139218] [client 52.139.47.57:26364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/666.php"] [unique_id "aoSCav2v-lWn9OzQT7U3VwAAALI"] [Tue Aug 18 13:03:54.167267 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.36.136:57217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCav2v-lWn9OzQT7U3WAAAANY"] [Tue Aug 18 13:03:54.171366 2026] [security2:error] [pid 139043:tid 139185] [client 20.51.153.15:9832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/13.php"] [unique_id "aoSCav2v-lWn9OzQT7U3WQAAAJE"] [Tue Aug 18 13:03:54.206429 2026] [security2:error] [pid 139043:tid 139191] [client 172.182.217.32:21517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/alfa-rex2.php7"] [unique_id "aoSCav2v-lWn9OzQT7U3WwAAAJc"] [Tue Aug 18 13:03:54.210418 2026] [security2:error] [pid 139043:tid 139179] [client 74.248.18.37:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCav2v-lWn9OzQT7U3XAAAAIs"] [Tue Aug 18 13:03:54.217453 2026] [security2:error] [pid 139043:tid 139288] [client 20.163.43.14:4453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/new.php"] [unique_id "aoSCav2v-lWn9OzQT7U3XgAAAPg"] [Tue Aug 18 13:03:54.225568 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:17598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/47.php"] [unique_id "aoSCav2v-lWn9OzQT7U3XwAAAME"] [Tue Aug 18 13:03:54.229801 2026] [security2:error] [pid 139043:tid 139212] [client 4.232.151.198:42172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/edit-tags.php"] [unique_id "aoSCav2v-lWn9OzQT7U3YAAAAKw"] [Tue Aug 18 13:03:54.250566 2026] [security2:error] [pid 139043:tid 139215] [client 20.52.168.85:5281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/files/index.php"] [unique_id "aoSCav2v-lWn9OzQT7U3YgAAAK8"] [Tue Aug 18 13:03:54.255702 2026] [security2:error] [pid 139043:tid 139180] [client 172.182.200.96:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCav2v-lWn9OzQT7U3YwAAAIw"] [Tue Aug 18 13:03:54.257413 2026] [security2:error] [pid 139043:tid 139229] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/66.php"] [unique_id "aoSCav2v-lWn9OzQT7U3ZAAAAL0"] [Tue Aug 18 13:03:54.267083 2026] [security2:error] [pid 139043:tid 139287] [client 20.80.111.3:25814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/layout.php"] [unique_id "aoSCav2v-lWn9OzQT7U3ZgAAAPc"] [Tue Aug 18 13:03:54.272742 2026] [security2:error] [pid 139043:tid 139274] [client 20.250.13.23:37733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSCav2v-lWn9OzQT7U3ZwAAAOo"] [Tue Aug 18 13:03:54.274368 2026] [security2:error] [pid 139043:tid 139249] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/www.php"] [unique_id "aoSCav2v-lWn9OzQT7U3aAAAANE"] [Tue Aug 18 13:03:54.284281 2026] [security2:error] [pid 139043:tid 139232] [client 68.155.154.236:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCav2v-lWn9OzQT7U3agAAAMA"] [Tue Aug 18 13:03:54.287003 2026] [security2:error] [pid 139043:tid 139226] [client 68.221.73.131:63042] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.alyauto.com.br"] [uri "/1.php"] [unique_id "aoSCav2v-lWn9OzQT7U3awAAALo"] [Tue Aug 18 13:03:54.287075 2026] [security2:error] [pid 139043:tid 139226] [client 68.221.73.131:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/1.php"] [unique_id "aoSCav2v-lWn9OzQT7U3awAAALo"] [Tue Aug 18 13:03:54.290991 2026] [security2:error] [pid 139043:tid 139202] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCav2v-lWn9OzQT7U3bQAAAKI"] [Tue Aug 18 13:03:54.291014 2026] [security2:error] [pid 139043:tid 139211] [client 20.51.153.15:8800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/he.php"] [unique_id "aoSCav2v-lWn9OzQT7U3bAAAAKs"] [Tue Aug 18 13:03:54.293630 2026] [security2:error] [pid 139043:tid 139280] [client 20.250.27.191:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/akismet.php"] [unique_id "aoSCav2v-lWn9OzQT7U3bgAAAPA"] [Tue Aug 18 13:03:54.302253 2026] [security2:error] [pid 139043:tid 139230] [client 52.139.47.57:32797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/bgymj.php"] [unique_id "aoSCav2v-lWn9OzQT7U3bwAAAL4"] [Tue Aug 18 13:03:54.353190 2026] [authz_core:error] [pid 139043:tid 139112] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:54.353470 2026] [authz_core:error] [pid 139043:tid 139112] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:54.354608 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/g.php"] [unique_id "aoSCav2v-lWn9OzQT7U3cwAAAJA"] [Tue Aug 18 13:03:54.383302 2026] [security2:error] [pid 139043:tid 139279] [client 20.1.169.243:10906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/app.php"] [unique_id "aoSCav2v-lWn9OzQT7U3dAAAAO8"] [Tue Aug 18 13:03:54.391916 2026] [security2:error] [pid 139043:tid 139235] [client 74.249.206.207:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/scxy.php"] [unique_id "aoSCav2v-lWn9OzQT7U3dQAAAMM"] [Tue Aug 18 13:03:54.417434 2026] [security2:error] [pid 139043:tid 139252] [client 20.51.153.15:9528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/so.php"] [unique_id "aoSCav2v-lWn9OzQT7U3dgAAANQ"] [Tue Aug 18 13:03:54.419398 2026] [security2:error] [pid 139043:tid 139177] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/x7.php"] [unique_id "aoSCav2v-lWn9OzQT7U3dwAAAIk"] [Tue Aug 18 13:03:54.449807 2026] [autoindex:error] [pid 139043:tid 139293] [client 169.58.72.248:59297] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:54.495396 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/kopyw.php"] [unique_id "aoSCav2v-lWn9OzQT7U3fAAAAMI"] [Tue Aug 18 13:03:54.496882 2026] [security2:error] [pid 139043:tid 139241] [client 20.171.51.14:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mo.php"] [unique_id "aoSCav2v-lWn9OzQT7U3fQAAAMk"] [Tue Aug 18 13:03:54.501936 2026] [security2:error] [pid 139043:tid 139152] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSCav2v-lWn9OzQT7U3fwAA2Gw"] [Tue Aug 18 13:03:54.501936 2026] [security2:error] [pid 139043:tid 139123] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.htpasswd"] [unique_id "aoSCav2v-lWn9OzQT7U3fgAA2E8"] [Tue Aug 18 13:03:54.513457 2026] [security2:error] [pid 139043:tid 139087] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stremmastay.com.br"] [uri "/wp-login.php"] [unique_id "aoSCav2v-lWn9OzQT7U3gAAAtCs"], referer: https://stremmastay.com.br/wp-admin/ [Tue Aug 18 13:03:54.514436 2026] [security2:error] [pid 139043:tid 139129] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stremmastay.com.br"] [uri "/wp-login.php"] [unique_id "aoSCav2v-lWn9OzQT7U3gQAAtFU"], referer: https://stremmastay.com.br/wp-admin/ [Tue Aug 18 13:03:54.532651 2026] [security2:error] [pid 139043:tid 139096] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/terraform.tfstate"] [unique_id "aoSCav2v-lWn9OzQT7U3hAAAjjQ"] [Tue Aug 18 13:03:54.533484 2026] [security2:error] [pid 139043:tid 139130] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.svn/entries"] [unique_id "aoSCav2v-lWn9OzQT7U3hQAAjlY"] [Tue Aug 18 13:03:54.533602 2026] [security2:error] [pid 139043:tid 139055] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.vscode/launch.json"] [unique_id "aoSCav2v-lWn9OzQT7U3hgAAjgs"] [Tue Aug 18 13:03:54.579032 2026] [security2:error] [pid 139043:tid 139225] [client 20.163.43.14:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/222.php"] [unique_id "aoSCav2v-lWn9OzQT7U3iQAAALk"] [Tue Aug 18 13:03:54.609576 2026] [security2:error] [pid 139043:tid 139296] [client 20.51.153.15:9114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/gz.php"] [unique_id "aoSCav2v-lWn9OzQT7U3igAAAQA"] [Tue Aug 18 13:03:54.627197 2026] [security2:error] [pid 139043:tid 139175] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wicked.php"] [unique_id "aoSCav2v-lWn9OzQT7U3iwAAAIc"] [Tue Aug 18 13:03:54.653513 2026] [security2:error] [pid 139043:tid 139178] [client 20.51.153.15:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/10.php"] [unique_id "aoSCav2v-lWn9OzQT7U3jQAAAIo"] [Tue Aug 18 13:03:54.656135 2026] [security2:error] [pid 139043:tid 139190] [client 4.232.151.198:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCav2v-lWn9OzQT7U3jwAAAJY"] [Tue Aug 18 13:03:54.691436 2026] [security2:error] [pid 139043:tid 139183] [client 74.249.206.207:7877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCav2v-lWn9OzQT7U3kwAAAI8"] [Tue Aug 18 13:03:54.701028 2026] [security2:error] [pid 139043:tid 139262] [client 172.182.217.32:21814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "aoSCav2v-lWn9OzQT7U3lAAAAN4"] [Tue Aug 18 13:03:54.710018 2026] [security2:error] [pid 139043:tid 139200] [client 172.182.200.96:15513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCav2v-lWn9OzQT7U3lQAAAKA"] [Tue Aug 18 13:03:54.711138 2026] [security2:error] [pid 139043:tid 139283] [client 20.104.100.201:23961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/12.php"] [unique_id "aoSCav2v-lWn9OzQT7U3lgAAAPM"] [Tue Aug 18 13:03:54.722240 2026] [security2:error] [pid 139043:tid 139228] [client 52.139.47.57:49189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/bthil.php"] [unique_id "aoSCav2v-lWn9OzQT7U3lwAAALw"] [Tue Aug 18 13:03:54.737582 2026] [security2:error] [pid 139043:tid 139102] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCav2v-lWn9OzQT7U3mAAAizo"] [Tue Aug 18 13:03:54.739468 2026] [security2:error] [pid 139043:tid 139267] [client 20.116.17.175:3453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/read.php"] [unique_id "aoSCav2v-lWn9OzQT7U3mQAAAOM"] [Tue Aug 18 13:03:54.767636 2026] [security2:error] [pid 139043:tid 139245] [client 20.1.169.243:10936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/archive.php"] [unique_id "aoSCav2v-lWn9OzQT7U3nAAAAM0"] [Tue Aug 18 13:03:54.791111 2026] [security2:error] [pid 139043:tid 139263] [client 20.250.27.191:18832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/admin.php"] [unique_id "aoSCav2v-lWn9OzQT7U3nwAAAN8"] [Tue Aug 18 13:03:54.806516 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.94:54374] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:54.806773 2026] [authz_core:error] [pid 139043:tid 139144] [remote 57.141.22.94:54374] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:54.818014 2026] [security2:error] [pid 139043:tid 139265] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/god.php"] [unique_id "aoSCav2v-lWn9OzQT7U3ogAAAOE"] [Tue Aug 18 13:03:54.818883 2026] [security2:error] [pid 139043:tid 139188] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCav2v-lWn9OzQT7U3owAAAJQ"] [Tue Aug 18 13:03:54.848388 2026] [security2:error] [pid 139043:tid 139219] [client 158.23.17.4:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/rh.php"] [unique_id "aoSCav2v-lWn9OzQT7U3pQAAALM"] [Tue Aug 18 13:03:54.849428 2026] [security2:error] [pid 139043:tid 139237] [client 20.52.168.85:5139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSCav2v-lWn9OzQT7U3pwAAAMU"] [Tue Aug 18 13:03:54.849568 2026] [security2:error] [pid 139043:tid 139290] [client 74.248.18.37:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSCav2v-lWn9OzQT7U3pgAAAPo"] [Tue Aug 18 13:03:54.859945 2026] [security2:error] [pid 139043:tid 139291] [client 68.221.73.131:60571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/about.php"] [unique_id "aoSCav2v-lWn9OzQT7U3qAAAAPs"] [Tue Aug 18 13:03:54.860644 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ebahvhhh.php"] [unique_id "aoSCav2v-lWn9OzQT7U3qQAAAKY"] [Tue Aug 18 13:03:54.898890 2026] [security2:error] [pid 139043:tid 139298] [client 20.250.13.23:57269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/st.php"] [unique_id "aoSCav2v-lWn9OzQT7U3qgAAAQI"] [Tue Aug 18 13:03:54.903938 2026] [security2:error] [pid 139043:tid 139181] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/8.php"] [unique_id "aoSCav2v-lWn9OzQT7U3rAAAAI0"] [Tue Aug 18 13:03:54.903938 2026] [security2:error] [pid 139043:tid 139213] [client 197.184.64.235:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCav2v-lWn9OzQT7U3rQAAAK0"] [Tue Aug 18 13:03:54.904036 2026] [security2:error] [pid 139043:tid 139213] [client 197.184.64.235:42664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCav2v-lWn9OzQT7U3rQAAAK0"] [Tue Aug 18 13:03:54.931466 2026] [security2:error] [pid 139043:tid 139257] [client 20.80.111.3:26245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/text.php"] [unique_id "aoSCav2v-lWn9OzQT7U3rgAAANk"] [Tue Aug 18 13:03:54.933372 2026] [security2:error] [pid 139043:tid 139230] [client 20.51.153.15:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/nf.php"] [unique_id "aoSCav2v-lWn9OzQT7U3rwAAAL4"] [Tue Aug 18 13:03:54.952476 2026] [security2:error] [pid 139043:tid 139184] [client 20.171.51.14:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/qr.php"] [unique_id "aoSCav2v-lWn9OzQT7U3sQAAAJA"] [Tue Aug 18 13:03:54.952998 2026] [security2:error] [pid 139043:tid 139242] [client 20.163.43.14:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/chosen.php"] [unique_id "aoSCav2v-lWn9OzQT7U3sgAAAMo"] [Tue Aug 18 13:03:54.958829 2026] [security2:error] [pid 139043:tid 139279] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/gelay.php"] [unique_id "aoSCav2v-lWn9OzQT7U3swAAAO8"] [Tue Aug 18 13:03:54.967711 2026] [security2:error] [pid 139043:tid 139248] [client 213.35.127.232:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCav2v-lWn9OzQT7U3tAAAANA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:54.983401 2026] [security2:error] [pid 139043:tid 139174] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSCav2v-lWn9OzQT7U3tQAAAIY"] [Tue Aug 18 13:03:55.005296 2026] [security2:error] [pid 139043:tid 139222] [client 74.249.206.207:45507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3twAAALY"] [Tue Aug 18 13:03:55.069329 2026] [security2:error] [pid 139043:tid 139070] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoSCa_2v-lWn9OzQT7U3vQAAwho"] [Tue Aug 18 13:03:55.069334 2026] [security2:error] [pid 139043:tid 139066] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "aoSCa_2v-lWn9OzQT7U3vgAAwhY"] [Tue Aug 18 13:03:55.079977 2026] [security2:error] [pid 139043:tid 139165] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/config"] [unique_id "aoSCa_2v-lWn9OzQT7U3vwAAtHk"] [Tue Aug 18 13:03:55.086021 2026] [security2:error] [pid 139043:tid 139149] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/authorized_keys"] [unique_id "aoSCa_2v-lWn9OzQT7U3wQAA4Gk"] [Tue Aug 18 13:03:55.086123 2026] [security2:error] [pid 139043:tid 139098] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCa_2v-lWn9OzQT7U3wgAA4DY"] [Tue Aug 18 13:03:55.086132 2026] [security2:error] [pid 139043:tid 139224] [client 20.206.73.37:11397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/special.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3wAAAALg"] [Tue Aug 18 13:03:55.093219 2026] [security2:error] [pid 139043:tid 139215] [client 4.232.151.198:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/u.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3wwAAAK8"] [Tue Aug 18 13:03:55.093253 2026] [security2:error] [pid 139043:tid 139209] [client 20.51.153.15:8299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/te.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3xAAAAKk"] [Tue Aug 18 13:03:55.117470 2026] [security2:error] [pid 139043:tid 139173] [client 223.185.37.47:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3xgAAAIU"] [Tue Aug 18 13:03:55.117578 2026] [security2:error] [pid 139043:tid 139173] [client 223.185.37.47:10479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3xgAAAIU"] [Tue Aug 18 13:03:55.126837 2026] [security2:error] [pid 139043:tid 139268] [client 20.151.109.219:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/yz.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3yQAAAOQ"] [Tue Aug 18 13:03:55.135217 2026] [security2:error] [pid 139043:tid 139252] [client 52.139.47.57:37325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/xp.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3ygAAANQ"] [Tue Aug 18 13:03:55.142274 2026] [security2:error] [pid 139043:tid 139269] [client 20.1.169.243:11198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/as.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3ywAAAOU"] [Tue Aug 18 13:03:55.156802 2026] [security2:error] [pid 139043:tid 139168] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.ssh/known_hosts"] [unique_id "aoSCa_2v-lWn9OzQT7U3zQAAo3w"] [Tue Aug 18 13:03:55.189116 2026] [security2:error] [pid 139043:tid 139300] [client 172.182.217.32:21766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "aoSCa_2v-lWn9OzQT7U30wAAAQQ"] [Tue Aug 18 13:03:55.189503 2026] [security2:error] [pid 139043:tid 139294] [client 20.104.100.201:24045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/x1da.php"] [unique_id "aoSCa_2v-lWn9OzQT7U31AAAAP4"] [Tue Aug 18 13:03:55.199483 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.200.96:15489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCa_2v-lWn9OzQT7U31QAAAPc"] [Tue Aug 18 13:03:55.216836 2026] [security2:error] [pid 139043:tid 139290] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/koiy.php"] [unique_id "aoSCa_2v-lWn9OzQT7U31wAAAPo"] [Tue Aug 18 13:03:55.221470 2026] [security2:error] [pid 139043:tid 139249] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCa_2v-lWn9OzQT7U32AAAANE"] [Tue Aug 18 13:03:55.225142 2026] [security2:error] [pid 139043:tid 139197] [client 20.250.27.191:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.27.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/ajax.php"] [unique_id "aoSCa_2v-lWn9OzQT7U32QAAAJ0"] [Tue Aug 18 13:03:55.275889 2026] [security2:error] [pid 139043:tid 139181] [client 20.163.43.14:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/info.php"] [unique_id "aoSCa_2v-lWn9OzQT7U32wAAAI0"] [Tue Aug 18 13:03:55.283127 2026] [security2:error] [pid 139043:tid 139213] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/zznmg.php"] [unique_id "aoSCa_2v-lWn9OzQT7U33AAAAK0"] [Tue Aug 18 13:03:55.283657 2026] [security2:error] [pid 139043:tid 139257] [client 20.51.153.15:8797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xv.php"] [unique_id "aoSCa_2v-lWn9OzQT7U33QAAANk"] [Tue Aug 18 13:03:55.305284 2026] [autoindex:error] [pid 139043:tid 139297] [client 4.232.151.198:4106] AH01276: Cannot serve directory /home3/brto26/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:55.312168 2026] [security2:error] [pid 139043:tid 139242] [client 158.23.17.4:25347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gk.php"] [unique_id "aoSCa_2v-lWn9OzQT7U33wAAAMo"] [Tue Aug 18 13:03:55.320613 2026] [security2:error] [pid 139043:tid 139240] [client 74.249.206.207:42258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/blurbs.php"] [unique_id "aoSCa_2v-lWn9OzQT7U34QAAAMg"] [Tue Aug 18 13:03:55.336489 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCa_2v-lWn9OzQT7U34gAAAOk"] [Tue Aug 18 13:03:55.358700 2026] [security2:error] [pid 139043:tid 139277] [client 20.51.153.15:9592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/kc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U34wAAAO0"] [Tue Aug 18 13:03:55.365083 2026] [security2:error] [pid 139043:tid 139295] [client 68.221.73.131:26420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/admin.php"] [unique_id "aoSCa_2v-lWn9OzQT7U35AAAAP8"] [Tue Aug 18 13:03:55.375853 2026] [security2:error] [pid 139043:tid 139291] [client 20.80.111.3:25854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/tmp/.phpEsretb_zablokowane"] [unique_id "aoSCa_2v-lWn9OzQT7U35QAAAPs"] [Tue Aug 18 13:03:55.391326 2026] [security2:error] [pid 139043:tid 139204] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/iko.php"] [unique_id "aoSCa_2v-lWn9OzQT7U35gAAAKQ"] [Tue Aug 18 13:03:55.392889 2026] [security2:error] [pid 139043:tid 139190] [client 4.223.113.180:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/w.php"] [unique_id "aoSCa_2v-lWn9OzQT7U35wAAAJY"] [Tue Aug 18 13:03:55.409435 2026] [authz_core:error] [pid 139043:tid 139166] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:55.409682 2026] [authz_core:error] [pid 139043:tid 139166] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:55.438505 2026] [security2:error] [pid 139043:tid 139212] [client 196.12.128.158:49431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U36wAAAKw"] [Tue Aug 18 13:03:55.438662 2026] [security2:error] [pid 139043:tid 139212] [client 196.12.128.158:49431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U36wAAAKw"] [Tue Aug 18 13:03:55.463907 2026] [security2:error] [pid 139043:tid 139202] [client 20.52.168.85:5277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCa_2v-lWn9OzQT7U37QAAAKI"] [Tue Aug 18 13:03:55.471031 2026] [security2:error] [pid 139043:tid 139182] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCa_2v-lWn9OzQT7U37gAAAI4"] [Tue Aug 18 13:03:55.480236 2026] [security2:error] [pid 139043:tid 139278] [client 74.248.18.37:46149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSCa_2v-lWn9OzQT7U37wAAAO4"] [Tue Aug 18 13:03:55.506134 2026] [security2:error] [pid 139043:tid 139253] [client 20.1.169.243:11153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U38QAAANU"] [Tue Aug 18 13:03:55.506614 2026] [security2:error] [pid 139043:tid 139117] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/id_ed25519"] [unique_id "aoSCa_2v-lWn9OzQT7U38gAAy0k"] [Tue Aug 18 13:03:55.509576 2026] [security2:error] [pid 139043:tid 139132] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/server.key"] [unique_id "aoSCa_2v-lWn9OzQT7U38wAAmlg"] [Tue Aug 18 13:03:55.509582 2026] [security2:error] [pid 139043:tid 139090] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/id_dsa"] [unique_id "aoSCa_2v-lWn9OzQT7U39AAAmi4"] [Tue Aug 18 13:03:55.509754 2026] [security2:error] [pid 139043:tid 139076] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/id_ecdsa"] [unique_id "aoSCa_2v-lWn9OzQT7U39QAAmiA"] [Tue Aug 18 13:03:55.511766 2026] [security2:error] [pid 139043:tid 139143] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/key.pem"] [unique_id "aoSCa_2v-lWn9OzQT7U39wAAhWM"] [Tue Aug 18 13:03:55.514883 2026] [security2:error] [pid 139043:tid 139139] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/id_rsa"] [unique_id "aoSCa_2v-lWn9OzQT7U3-AAAuV8"] [Tue Aug 18 13:03:55.552194 2026] [security2:error] [pid 139043:tid 139261] [client 52.139.47.57:10983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/reze.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3-gAAAN0"] [Tue Aug 18 13:03:55.617146 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3_gAAAPM"] [Tue Aug 18 13:03:55.633834 2026] [security2:error] [pid 139043:tid 139258] [client 20.250.13.23:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSCa_2v-lWn9OzQT7U3_wAAANo"] [Tue Aug 18 13:03:55.644540 2026] [security2:error] [pid 139043:tid 139289] [client 74.249.206.207:7920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/bajah.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4AAAAAPk"] [Tue Aug 18 13:03:55.649576 2026] [security2:error] [pid 139043:tid 139179] [client 20.51.153.15:9202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/mx.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4AQAAAIs"] [Tue Aug 18 13:03:55.669401 2026] [security2:error] [pid 139043:tid 139281] [client 20.116.17.175:53765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/albin.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4AgAAAPE"] [Tue Aug 18 13:03:55.673029 2026] [security2:error] [pid 139043:tid 139198] [client 20.51.153.15:8212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/jn.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4AwAAAJ4"] [Tue Aug 18 13:03:55.679926 2026] [security2:error] [pid 139043:tid 139266] [client 172.182.217.32:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4BQAAAOI"] [Tue Aug 18 13:03:55.679944 2026] [security2:error] [pid 139043:tid 139199] [client 172.182.200.96:15567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4BAAAAJ8"] [Tue Aug 18 13:03:55.684733 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:33522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/yg.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4BgAAAJg"] [Tue Aug 18 13:03:55.687493 2026] [security2:error] [pid 139043:tid 139263] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/cah.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4BwAAAN8"] [Tue Aug 18 13:03:55.719954 2026] [security2:error] [pid 139043:tid 139287] [client 74.248.130.103:34954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/system_log.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4CwAAAPc"] [Tue Aug 18 13:03:55.726084 2026] [security2:error] [pid 139043:tid 139290] [client 20.151.109.219:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/hr.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4DAAAAPo"] [Tue Aug 18 13:03:55.780468 2026] [security2:error] [pid 139043:tid 139232] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/raw.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4EQAAAMA"] [Tue Aug 18 13:03:55.798341 2026] [security2:error] [pid 139043:tid 139181] [client 20.104.100.201:24049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/mcs.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4EgAAAI0"] [Tue Aug 18 13:03:55.808929 2026] [security2:error] [pid 139043:tid 139213] [client 20.226.36.136:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4FAAAAK0"] [Tue Aug 18 13:03:55.811779 2026] [security2:error] [pid 139043:tid 139257] [client 168.62.48.100:5388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4FQAAANk"] [Tue Aug 18 13:03:55.856690 2026] [security2:error] [pid 139043:tid 139235] [client 20.163.43.14:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4FwAAAMM"] [Tue Aug 18 13:03:55.874949 2026] [security2:error] [pid 139043:tid 139277] [client 20.171.51.14:18649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/dirs.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4GQAAAO0"] [Tue Aug 18 13:03:55.879189 2026] [security2:error] [pid 139043:tid 139245] [client 20.80.111.3:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/upload.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4GwAAAM0"] [Tue Aug 18 13:03:55.900050 2026] [security2:error] [pid 139043:tid 139226] [client 20.1.169.243:10902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/atomlib.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4HAAAALo"] [Tue Aug 18 13:03:55.908714 2026] [security2:error] [pid 139043:tid 139223] [client 68.155.156.252:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/puc.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4HQAAALc"] [Tue Aug 18 13:03:55.911755 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:8239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergoninf.com"] [uri "/bf.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4HgAAAKQ"] [Tue Aug 18 13:03:55.925472 2026] [security2:error] [pid 139043:tid 139221] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4HwAAALU"] [Tue Aug 18 13:03:55.941278 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:9100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/45.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4IAAAALQ"] [Tue Aug 18 13:03:55.970196 2026] [security2:error] [pid 139043:tid 139264] [client 116.179.37.45:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4EwAAAOA"], referer: http://portalosol.com.br/ [Tue Aug 18 13:03:55.976207 2026] [security2:error] [pid 139043:tid 139272] [client 68.221.73.131:47765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/edit.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4IgAAAOg"] [Tue Aug 18 13:03:55.989248 2026] [security2:error] [pid 139043:tid 139267] [client 213.35.127.232:54045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4JAAAAOM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:55.992809 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:55.993270 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:55.994272 2026] [security2:error] [pid 139043:tid 139212] [client 158.23.17.4:11815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/payout.php"] [unique_id "aoSCa_2v-lWn9OzQT7U4JQAAAKw"] [Tue Aug 18 13:03:56.008745 2026] [security2:error] [pid 139043:tid 139229] [client 4.232.151.198:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4JgAAAL0"] [Tue Aug 18 13:03:56.008912 2026] [security2:error] [pid 139043:tid 139236] [client 216.244.66.243:57430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/3300betlogin-0/"] [unique_id "aoSCbP2v-lWn9OzQT7U4JwAAAMQ"] [Tue Aug 18 13:03:56.009002 2026] [security2:error] [pid 139043:tid 139236] [client 216.244.66.243:57430] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/3300betlogin-0/"] [unique_id "aoSCbP2v-lWn9OzQT7U4JwAAAMQ"] [Tue Aug 18 13:03:56.012632 2026] [security2:error] [pid 139043:tid 139202] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4KAAAAKI"] [Tue Aug 18 13:03:56.018461 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:27336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kj.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4KQAAAJI"] [Tue Aug 18 13:03:56.024105 2026] [security2:error] [pid 139043:tid 139214] [client 74.249.206.207:45509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/domvf.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4KgAAAK4"] [Tue Aug 18 13:03:56.032778 2026] [security2:error] [pid 139043:tid 139295] [client 52.139.47.57:49197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/2026w.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4KwAAAP8"] [Tue Aug 18 13:03:56.050590 2026] [security2:error] [pid 139043:tid 139178] [client 172.182.200.96:15604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4LwAAAIo"] [Tue Aug 18 13:03:56.069384 2026] [security2:error] [pid 139043:tid 139216] [client 20.52.168.85:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/num.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4MQAAALA"] [Tue Aug 18 13:03:56.080851 2026] [security2:error] [pid 139043:tid 139047] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/localhost.key"] [unique_id "aoSCbP2v-lWn9OzQT7U4MgAAoQM"] [Tue Aug 18 13:03:56.097313 2026] [security2:error] [pid 139043:tid 139110] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/private-key"] [unique_id "aoSCbP2v-lWn9OzQT7U4NQAAzkI"] [Tue Aug 18 13:03:56.097335 2026] [security2:error] [pid 139043:tid 139060] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/ssl/server.key"] [unique_id "aoSCbP2v-lWn9OzQT7U4NgAAzhA"] [Tue Aug 18 13:03:56.097341 2026] [security2:error] [pid 139043:tid 139136] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/privatekey.key"] [unique_id "aoSCbP2v-lWn9OzQT7U4NAAAzlw"] [Tue Aug 18 13:03:56.097390 2026] [security2:error] [pid 139043:tid 139063] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/ssl/localhost.key"] [unique_id "aoSCbP2v-lWn9OzQT7U4NwAAzhM"] [Tue Aug 18 13:03:56.097564 2026] [security2:error] [pid 139043:tid 139160] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/host.key"] [unique_id "aoSCbP2v-lWn9OzQT7U4OAAAznQ"] [Tue Aug 18 13:03:56.153986 2026] [security2:error] [pid 139043:tid 139228] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/about.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4OwAAALw"] [Tue Aug 18 13:03:56.168659 2026] [security2:error] [pid 139043:tid 139299] [client 172.182.217.32:21531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4PAAAAQM"] [Tue Aug 18 13:03:56.198560 2026] [security2:error] [pid 139043:tid 139199] [client 158.23.17.4:41949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/et.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4PQAAAJ8"] [Tue Aug 18 13:03:56.199658 2026] [security2:error] [pid 139043:tid 139266] [client 68.155.154.236:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4PgAAAOI"] [Tue Aug 18 13:03:56.203479 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:4430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4PwAAAQQ"] [Tue Aug 18 13:03:56.207040 2026] [security2:error] [pid 139043:tid 139263] [client 4.232.151.198:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4QAAAAN8"] [Tue Aug 18 13:03:56.229358 2026] [security2:error] [pid 139043:tid 139290] [client 20.51.153.15:9151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ry.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4QwAAAPo"] [Tue Aug 18 13:03:56.237463 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/system_log.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4RAAAAOo"] [Tue Aug 18 13:03:56.242209 2026] [security2:error] [pid 139043:tid 139193] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/oivcl.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4RQAAAJk"] [Tue Aug 18 13:03:56.248031 2026] [security2:error] [pid 139043:tid 139249] [client 20.206.73.37:29970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/file61.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4RgAAANE"] [Tue Aug 18 13:03:56.255803 2026] [security2:error] [pid 139043:tid 139252] [client 20.250.13.23:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-configs.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4RwAAANQ"] [Tue Aug 18 13:03:56.266850 2026] [security2:error] [pid 139043:tid 139289] [client 20.1.169.243:11176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/b.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4SAAAAPk"] [Tue Aug 18 13:03:56.272500 2026] [security2:error] [pid 139043:tid 139251] [client 20.79.204.6:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/x.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4SQAAANM"] [Tue Aug 18 13:03:56.282569 2026] [security2:error] [pid 139043:tid 139211] [client 20.171.51.14:38764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sn.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4SgAAAKs"] [Tue Aug 18 13:03:56.299202 2026] [security2:error] [pid 139043:tid 139271] [client 20.151.109.219:36706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kt.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4TAAAAOc"] [Tue Aug 18 13:03:56.317888 2026] [security2:error] [pid 139043:tid 139298] [client 74.248.18.37:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-themes.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4TgAAAQI"] [Tue Aug 18 13:03:56.334457 2026] [security2:error] [pid 139043:tid 139203] [client 37.40.227.74:56952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4UAAAAKM"] [Tue Aug 18 13:03:56.337878 2026] [security2:error] [pid 139043:tid 139233] [client 20.80.111.3:5944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/upload/upload_cert.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4UQAAAME"] [Tue Aug 18 13:03:56.339021 2026] [security2:error] [pid 139043:tid 139203] [client 37.40.227.74:56952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4UAAAAKM"] [Tue Aug 18 13:03:56.372998 2026] [security2:error] [pid 139043:tid 139292] [client 20.116.17.175:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/fw/34.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4VgAAAPw"] [Tue Aug 18 13:03:56.382619 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.200.96:15528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4VwAAAMg"] [Tue Aug 18 13:03:56.384225 2026] [security2:error] [pid 139043:tid 139247] [client 74.249.206.207:42244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/fpwch.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4WAAAAM8"] [Tue Aug 18 13:03:56.390992 2026] [security2:error] [pid 139043:tid 139248] [client 20.206.73.37:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/fz.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4WQAAANA"] [Tue Aug 18 13:03:56.393588 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/bh.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4WwAAAIY"] [Tue Aug 18 13:03:56.410030 2026] [security2:error] [pid 139043:tid 139177] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4XQAAAIk"] [Tue Aug 18 13:03:56.430717 2026] [security2:error] [pid 139043:tid 139226] [client 20.104.100.201:24036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/adminner.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4XgAAALo"] [Tue Aug 18 13:03:56.452810 2026] [security2:error] [pid 139043:tid 139280] [client 52.139.47.57:32784] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eurotruckparts.com.br"] [uri "/1.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4XwAAAPA"] [Tue Aug 18 13:03:56.452906 2026] [security2:error] [pid 139043:tid 139280] [client 52.139.47.57:32784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/1.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4XwAAAPA"] [Tue Aug 18 13:03:56.473503 2026] [security2:error] [pid 139043:tid 139221] [client 20.226.36.136:57851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4YAAAALU"] [Tue Aug 18 13:03:56.520994 2026] [security2:error] [pid 139043:tid 139097] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoSCbP2v-lWn9OzQT7U4YgAA4zU"] [Tue Aug 18 13:03:56.534990 2026] [security2:error] [pid 139043:tid 139095] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.cursor/mcp.json"] [unique_id "aoSCbP2v-lWn9OzQT7U4ZAAAojM"] [Tue Aug 18 13:03:56.535081 2026] [security2:error] [pid 139043:tid 139156] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.aider.conf.yml"] [unique_id "aoSCbP2v-lWn9OzQT7U4ZgAAonA"] [Tue Aug 18 13:03:56.535151 2026] [security2:error] [pid 139043:tid 139164] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.continue/config.json"] [unique_id "aoSCbP2v-lWn9OzQT7U4ZQAAong"] [Tue Aug 18 13:03:56.535621 2026] [security2:error] [pid 139043:tid 139141] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.codex/config.toml"] [unique_id "aoSCbP2v-lWn9OzQT7U4ZwAAomE"] [Tue Aug 18 13:03:56.557347 2026] [security2:error] [pid 139043:tid 139209] [client 20.163.43.14:4373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/k.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4aQAAAKk"] [Tue Aug 18 13:03:56.557860 2026] [security2:error] [pid 139043:tid 139278] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/zugvi.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4agAAAO4"] [Tue Aug 18 13:03:56.568617 2026] [security2:error] [pid 139043:tid 139131] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCbP2v-lWn9OzQT7U4awAAh1c"] [Tue Aug 18 13:03:56.594488 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:56.594763 2026] [authz_core:error] [pid 139043:tid 139086] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:56.600284 2026] [security2:error] [pid 139043:tid 139253] [client 20.51.153.15:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pm.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4cAAAANU"] [Tue Aug 18 13:03:56.633264 2026] [security2:error] [pid 139043:tid 139273] [client 20.1.169.243:10920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/backup.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4cQAAAOk"] [Tue Aug 18 13:03:56.666518 2026] [security2:error] [pid 139043:tid 139264] [client 172.182.217.32:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4cgAAAOA"] [Tue Aug 18 13:03:56.668817 2026] [security2:error] [pid 139043:tid 139269] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/f35.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4cwAAAOU"] [Tue Aug 18 13:03:56.672183 2026] [security2:error] [pid 139043:tid 139224] [client 158.23.17.4:40442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wn.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4dAAAALg"] [Tue Aug 18 13:03:56.711262 2026] [security2:error] [pid 139043:tid 139272] [client 20.52.168.85:5285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4dwAAAOg"] [Tue Aug 18 13:03:56.727435 2026] [security2:error] [pid 139043:tid 139228] [client 172.182.200.96:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4eAAAALw"] [Tue Aug 18 13:03:56.751928 2026] [security2:error] [pid 139043:tid 139208] [client 68.221.73.131:35993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4eQAAAKg"] [Tue Aug 18 13:03:56.769016 2026] [security2:error] [pid 139043:tid 139218] [client 102.213.179.104:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4egAAALI"] [Tue Aug 18 13:03:56.769159 2026] [security2:error] [pid 139043:tid 139218] [client 102.213.179.104:59038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4egAAALI"] [Tue Aug 18 13:03:56.770337 2026] [security2:error] [pid 139043:tid 139178] [client 20.80.111.3:12498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/uploads/683584ibal.php.xxxjpg"] [unique_id "aoSCbP2v-lWn9OzQT7U4fAAAAIo"] [Tue Aug 18 13:03:56.791096 2026] [security2:error] [pid 139043:tid 139199] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4fQAAAJ8"] [Tue Aug 18 13:03:56.797812 2026] [security2:error] [pid 139043:tid 139300] [client 74.249.206.207:42286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/adminner.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4fgAAAQQ"] [Tue Aug 18 13:03:56.822861 2026] [security2:error] [pid 139043:tid 139268] [client 4.232.151.198:4199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4ggAAAOQ"] [Tue Aug 18 13:03:56.874612 2026] [security2:error] [pid 139043:tid 139290] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wsrer.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4hAAAAPo"] [Tue Aug 18 13:03:56.877199 2026] [security2:error] [pid 139043:tid 139179] [client 52.139.47.57:10949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/2.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4hQAAAIs"] [Tue Aug 18 13:03:56.890924 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:56.891189 2026] [authz_core:error] [pid 139043:tid 139072] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:56.905545 2026] [security2:error] [pid 139043:tid 139201] [client 20.250.13.23:57217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-post.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4iQAAAKE"] [Tue Aug 18 13:03:56.957241 2026] [security2:error] [pid 139043:tid 139288] [client 74.248.18.37:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4jAAAAPg"] [Tue Aug 18 13:03:56.966423 2026] [security2:error] [pid 139043:tid 139233] [client 158.23.17.4:57059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/ct.php"] [unique_id "aoSCbP2v-lWn9OzQT7U4jQAAAME"] [Tue Aug 18 13:03:57.010665 2026] [security2:error] [pid 139043:tid 139193] [client 20.1.169.243:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bak.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4jgAAAJk"] [Tue Aug 18 13:03:57.013796 2026] [security2:error] [pid 139043:tid 139246] [client 213.35.127.232:54253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4jwAAAM4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:57.025116 2026] [security2:error] [pid 139043:tid 139257] [client 20.104.100.201:24051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/dragonshell.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4kAAAANk"] [Tue Aug 18 13:03:57.025540 2026] [security2:error] [pid 139043:tid 139054] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCbf2v-lWn9OzQT7U4kQABAQo"] [Tue Aug 18 13:03:57.026581 2026] [security2:error] [pid 139043:tid 139045] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.hermes/auth.json"] [unique_id "aoSCbf2v-lWn9OzQT7U4kgAAygE"] [Tue Aug 18 13:03:57.027410 2026] [security2:error] [pid 139043:tid 139100] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.hermes/config.yaml"] [unique_id "aoSCbf2v-lWn9OzQT7U4kwAAzzg"] [Tue Aug 18 13:03:57.027416 2026] [security2:error] [pid 139043:tid 139089] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.claude.json"] [unique_id "aoSCbf2v-lWn9OzQT7U4lAAAzy0"] [Tue Aug 18 13:03:57.027613 2026] [security2:error] [pid 139043:tid 139163] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "aoSCbf2v-lWn9OzQT7U4lQAAz3c"] [Tue Aug 18 13:03:57.034676 2026] [security2:error] [pid 139043:tid 139121] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.claude/settings.json"] [unique_id "aoSCbf2v-lWn9OzQT7U4lgAAkU0"] [Tue Aug 18 13:03:57.049547 2026] [security2:error] [pid 139043:tid 139248] [client 20.163.43.14:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/403.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4mAAAANA"] [Tue Aug 18 13:03:57.060554 2026] [security2:error] [pid 139043:tid 139222] [client 158.23.17.4:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/of.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4mQAAALY"] [Tue Aug 18 13:03:57.062140 2026] [security2:error] [pid 139043:tid 139177] [client 20.171.51.14:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/43.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4mgAAAIk"] [Tue Aug 18 13:03:57.074495 2026] [security2:error] [pid 139043:tid 139270] [client 20.116.17.175:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp9.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4nAAAAOY"] [Tue Aug 18 13:03:57.101960 2026] [security2:error] [pid 139043:tid 139259] [client 20.206.73.37:11948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/clque.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4nQAAANs"] [Tue Aug 18 13:03:57.107425 2026] [security2:error] [pid 139043:tid 139226] [client 149.57.203.122:36000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "barsantajulia.com.br"] [uri "/"] [unique_id "aoSCbf2v-lWn9OzQT7U4ngAAALo"] [Tue Aug 18 13:03:57.119671 2026] [security2:error] [pid 139043:tid 139234] [client 172.182.200.96:15613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4nwAAAMI"] [Tue Aug 18 13:03:57.130384 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:9189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/dr.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4oQAAALQ"] [Tue Aug 18 13:03:57.139646 2026] [security2:error] [pid 139043:tid 139212] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4pAAAAKw"] [Tue Aug 18 13:03:57.139677 2026] [security2:error] [pid 139043:tid 139241] [client 149.57.203.122:36012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "barsantajulia.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSCbf2v-lWn9OzQT7U4owAAAMk"] [Tue Aug 18 13:03:57.140571 2026] [security2:error] [pid 139043:tid 139049] [remote 47.128.124.121:61886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/passeios-3/"] [unique_id "aoSCbf2v-lWn9OzQT7U4pQAA6wU"] [Tue Aug 18 13:03:57.142832 2026] [security2:error] [pid 139043:tid 139229] [client 74.249.206.207:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/abcd.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4pgAAAL0"] [Tue Aug 18 13:03:57.159732 2026] [security2:error] [pid 139043:tid 139227] [client 172.182.217.32:22222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/seoplugins/mar.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4pwAAALs"] [Tue Aug 18 13:03:57.180472 2026] [security2:error] [pid 139043:tid 139295] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/05.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4qQAAAP8"] [Tue Aug 18 13:03:57.187306 2026] [security2:error] [pid 139043:tid 139194] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4qwAAAJo"] [Tue Aug 18 13:03:57.188595 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.36.136:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4rAAAAIU"] [Tue Aug 18 13:03:57.193379 2026] [authz_core:error] [pid 139043:tid 139116] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:57.193647 2026] [authz_core:error] [pid 139043:tid 139116] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:57.194551 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vg.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4rQAAALk"] [Tue Aug 18 13:03:57.207418 2026] [security2:error] [pid 139043:tid 139277] [client 20.80.111.3:28170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/uploads/angulu.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4rgAAAO0"] [Tue Aug 18 13:03:57.236187 2026] [security2:error] [pid 139043:tid 139272] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/inputs.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4sAAAAOg"] [Tue Aug 18 13:03:57.302115 2026] [authz_core:error] [pid 139043:tid 139115] [remote 57.141.22.117:52892] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:57.302405 2026] [authz_core:error] [pid 139043:tid 139115] [remote 57.141.22.117:52892] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:57.306700 2026] [security2:error] [pid 139043:tid 139215] [client 52.139.47.57:33809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/7.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4tAAAAK8"] [Tue Aug 18 13:03:57.320820 2026] [security2:error] [pid 139043:tid 139221] [client 20.52.168.85:5140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/css/index.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4tgAAALU"] [Tue Aug 18 13:03:57.344639 2026] [autoindex:error] [pid 139043:tid 139199] [client 169.58.72.248:59297] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:57.374655 2026] [security2:error] [pid 139043:tid 139228] [client 20.1.169.243:10891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bgymj.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4uAAAALw"] [Tue Aug 18 13:03:57.400584 2026] [security2:error] [pid 139043:tid 139263] [client 20.51.153.15:9104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ts.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4uwAAAN8"] [Tue Aug 18 13:03:57.461880 2026] [security2:error] [pid 139043:tid 139255] [client 20.171.51.14:18680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fresh.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4vgAAANc"] [Tue Aug 18 13:03:57.462869 2026] [security2:error] [pid 139043:tid 139107] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.profile"] [unique_id "aoSCbf2v-lWn9OzQT7U4vwAA0T8"] [Tue Aug 18 13:03:57.477866 2026] [security2:error] [pid 139043:tid 139289] [client 74.249.206.207:42292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/simple.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4wAAAAPk"] [Tue Aug 18 13:03:57.494342 2026] [security2:error] [pid 139043:tid 139206] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/abc.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4wgAAAKY"] [Tue Aug 18 13:03:57.500219 2026] [security2:error] [pid 139043:tid 139251] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/yxijx.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4xAAAANM"] [Tue Aug 18 13:03:57.510395 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.200.96:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4xQAAAP4"] [Tue Aug 18 13:03:57.519893 2026] [security2:error] [pid 139043:tid 139208] [client 20.250.13.23:37703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4xgAAAKg"] [Tue Aug 18 13:03:57.534521 2026] [security2:error] [pid 139043:tid 139167] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "stremmastay.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCbf2v-lWn9OzQT7U4yAAA53s"] [Tue Aug 18 13:03:57.534631 2026] [security2:error] [pid 139043:tid 139053] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.bashrc"] [unique_id "aoSCbf2v-lWn9OzQT7U4xwAA5wk"] [Tue Aug 18 13:03:57.534633 2026] [security2:error] [pid 139043:tid 139135] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.zshrc"] [unique_id "aoSCbf2v-lWn9OzQT7U4yQAA51s"] [Tue Aug 18 13:03:57.534783 2026] [security2:error] [pid 139043:tid 139123] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.bash_profile"] [unique_id "aoSCbf2v-lWn9OzQT7U4ygAA508"] [Tue Aug 18 13:03:57.536868 2026] [security2:error] [pid 139043:tid 139152] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.mcp.json"] [unique_id "aoSCbf2v-lWn9OzQT7U4ywAAjWw"] [Tue Aug 18 13:03:57.560392 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.154.236:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4zAAAAME"] [Tue Aug 18 13:03:57.587058 2026] [security2:error] [pid 139043:tid 139202] [client 86.120.159.145:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4zgAAAKI"] [Tue Aug 18 13:03:57.587177 2026] [security2:error] [pid 139043:tid 139202] [client 86.120.159.145:17807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4zgAAAKI"] [Tue Aug 18 13:03:57.615999 2026] [security2:error] [pid 139043:tid 139184] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/public/hi.php"] [unique_id "aoSCbf2v-lWn9OzQT7U40AAAAJA"] [Tue Aug 18 13:03:57.630027 2026] [autoindex:error] [pid 139043:tid 139286] [client 4.232.151.198:4139] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:57.645135 2026] [security2:error] [pid 139043:tid 139185] [client 68.221.73.131:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/inputs.php"] [unique_id "aoSCbf2v-lWn9OzQT7U40wAAAJE"] [Tue Aug 18 13:03:57.645898 2026] [security2:error] [pid 139043:tid 139235] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/alfa.php"] [unique_id "aoSCbf2v-lWn9OzQT7U41AAAAMM"] [Tue Aug 18 13:03:57.649332 2026] [security2:error] [pid 139043:tid 139248] [client 158.23.17.4:57069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/gy.php"] [unique_id "aoSCbf2v-lWn9OzQT7U41QAAANA"] [Tue Aug 18 13:03:57.653068 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.217.32:21409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSCbf2v-lWn9OzQT7U41gAAAJ0"] [Tue Aug 18 13:03:57.663151 2026] [security2:error] [pid 139043:tid 139177] [client 20.51.153.15:8791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/53.php"] [unique_id "aoSCbf2v-lWn9OzQT7U41wAAAIk"] [Tue Aug 18 13:03:57.716883 2026] [security2:error] [pid 139043:tid 139183] [client 52.139.47.57:32785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/10.php"] [unique_id "aoSCbf2v-lWn9OzQT7U42wAAAI8"] [Tue Aug 18 13:03:57.737006 2026] [security2:error] [pid 139043:tid 139190] [client 20.163.43.14:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/gecko.php"] [unique_id "aoSCbf2v-lWn9OzQT7U43QAAAJY"] [Tue Aug 18 13:03:57.738362 2026] [security2:error] [pid 139043:tid 139257] [client 20.1.169.243:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bi.php"] [unique_id "aoSCbf2v-lWn9OzQT7U43gAAANk"] [Tue Aug 18 13:03:57.752843 2026] [security2:error] [pid 139043:tid 139205] [client 20.104.100.201:24003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/setup-config.php"] [unique_id "aoSCbf2v-lWn9OzQT7U43wAAAKU"] [Tue Aug 18 13:03:57.758110 2026] [security2:error] [pid 139043:tid 139292] [client 20.80.111.3:25853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/uploads/phUploader.php"] [unique_id "aoSCbf2v-lWn9OzQT7U44AAAAPw"] [Tue Aug 18 13:03:57.778816 2026] [security2:error] [pid 139043:tid 139275] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/lock360.php"] [unique_id "aoSCbf2v-lWn9OzQT7U44wAAAOs"] [Tue Aug 18 13:03:57.796999 2026] [authz_core:error] [pid 139043:tid 139096] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:57.797262 2026] [authz_core:error] [pid 139043:tid 139096] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:57.804740 2026] [security2:error] [pid 139043:tid 139182] [client 74.249.206.207:7883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCbf2v-lWn9OzQT7U45QAAAI4"] [Tue Aug 18 13:03:57.808836 2026] [security2:error] [pid 139043:tid 139278] [client 20.206.73.37:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/nano.php"] [unique_id "aoSCbf2v-lWn9OzQT7U45gAAAO4"] [Tue Aug 18 13:03:57.809107 2026] [security2:error] [pid 139043:tid 139214] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCbf2v-lWn9OzQT7U45wAAAK4"] [Tue Aug 18 13:03:57.810591 2026] [security2:error] [pid 139043:tid 139295] [client 158.23.17.4:40677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/bu.php"] [unique_id "aoSCbf2v-lWn9OzQT7U46AAAAP8"] [Tue Aug 18 13:03:57.824394 2026] [security2:error] [pid 139043:tid 139173] [client 20.116.17.175:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/save.php"] [unique_id "aoSCbf2v-lWn9OzQT7U46QAAAIU"] [Tue Aug 18 13:03:57.848530 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/akcc.php"] [unique_id "aoSCbf2v-lWn9OzQT7U47QAAAOk"] [Tue Aug 18 13:03:57.853169 2026] [autoindex:error] [pid 139043:tid 139225] [client 4.232.151.198:4139] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:57.878949 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.200.96:15535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCbf2v-lWn9OzQT7U47wAAALg"] [Tue Aug 18 13:03:57.936632 2026] [security2:error] [pid 139043:tid 139198] [client 20.226.36.136:57219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCbf2v-lWn9OzQT7U48QAAAJ4"] [Tue Aug 18 13:03:57.943715 2026] [security2:error] [pid 139043:tid 139142] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/laravel/.env"] [unique_id "aoSCbf2v-lWn9OzQT7U48gAAtWI"] [Tue Aug 18 13:03:57.944012 2026] [security2:error] [pid 139043:tid 139112] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/core/.env"] [unique_id "aoSCbf2v-lWn9OzQT7U49AAAtUQ"] [Tue Aug 18 13:03:57.944020 2026] [security2:error] [pid 139043:tid 139111] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "aoSCbf2v-lWn9OzQT7U48wAAtUM"] [Tue Aug 18 13:03:57.951795 2026] [security2:error] [pid 139043:tid 139061] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config/.env.php"] [unique_id "aoSCbf2v-lWn9OzQT7U49QAAnxE"] [Tue Aug 18 13:03:57.965973 2026] [security2:error] [pid 139043:tid 139051] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "stremmastay.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCbf2v-lWn9OzQT7U4-AAA-wc"] [Tue Aug 18 13:03:57.966157 2026] [security2:error] [pid 139043:tid 139075] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCbf2v-lWn9OzQT7U4-QAA-x8"] [Tue Aug 18 13:03:57.968335 2026] [security2:error] [pid 139043:tid 139228] [client 20.51.153.15:9133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lq.php"] [unique_id "aoSCbf2v-lWn9OzQT7U4-gAAALw"] [Tue Aug 18 13:03:58.009624 2026] [security2:error] [pid 139043:tid 139238] [client 185.223.152.183:38337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.152.223.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ciavazamentodf.com.br"] [uri "/wp-login.php"] [unique_id "aoSCbf2v-lWn9OzQT7U46wAAAMY"] [Tue Aug 18 13:03:58.026129 2026] [security2:error] [pid 139043:tid 139259] [client 213.35.127.232:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCbv2v-lWn9OzQT7U4_AAAANs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:58.027555 2026] [security2:error] [pid 139043:tid 139179] [client 20.215.241.237:20937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCbv2v-lWn9OzQT7U4_QAAAIs"] [Tue Aug 18 13:03:58.027889 2026] [security2:error] [pid 139043:tid 139274] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/flower.php"] [unique_id "aoSCbv2v-lWn9OzQT7U4_gAAAOo"] [Tue Aug 18 13:03:58.029437 2026] [autoindex:error] [pid 139043:tid 139241] [client 20.52.168.85:5278] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:58.033563 2026] [security2:error] [pid 139043:tid 139267] [client 4.232.151.198:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/h.php"] [unique_id "aoSCbv2v-lWn9OzQT7U4_wAAAOM"] [Tue Aug 18 13:03:58.061296 2026] [security2:error] [pid 139043:tid 139249] [client 4.232.151.198:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5AQAAANE"] [Tue Aug 18 13:03:58.095094 2026] [authz_core:error] [pid 139043:tid 139099] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:58.095361 2026] [authz_core:error] [pid 139043:tid 139099] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:58.106759 2026] [security2:error] [pid 139043:tid 139195] [client 74.249.206.207:44500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/xiugai.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5BQAAAJs"] [Tue Aug 18 13:03:58.116594 2026] [security2:error] [pid 139043:tid 139287] [client 20.1.169.243:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/blog.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5BgAAAPc"] [Tue Aug 18 13:03:58.119669 2026] [security2:error] [pid 139043:tid 139251] [client 20.151.109.219:50419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sm.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5BwAAANM"] [Tue Aug 18 13:03:58.125375 2026] [security2:error] [pid 139043:tid 139211] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/jrpga.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5CAAAAKs"] [Tue Aug 18 13:03:58.126873 2026] [security2:error] [pid 139043:tid 139263] [client 52.139.47.57:26313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/13.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5CQAAAN8"] [Tue Aug 18 13:03:58.141568 2026] [security2:error] [pid 139043:tid 139218] [client 20.250.13.23:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5DAAAALI"] [Tue Aug 18 13:03:58.145779 2026] [security2:error] [pid 139043:tid 139271] [client 158.23.17.4:62978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/app.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5DQAAAOc"] [Tue Aug 18 13:03:58.149092 2026] [security2:error] [pid 139043:tid 139176] [client 172.182.217.32:21386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/acme-challenge/xmrlpc.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5DgAAAIg"] [Tue Aug 18 13:03:58.207634 2026] [security2:error] [pid 139043:tid 139239] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wk/index.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5DwAAAMc"] [Tue Aug 18 13:03:58.216619 2026] [security2:error] [pid 139043:tid 139203] [client 20.226.36.136:57797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5EgAAAKM"] [Tue Aug 18 13:03:58.222218 2026] [security2:error] [pid 139043:tid 139289] [client 20.80.111.3:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/woh.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5FAAAAPk"] [Tue Aug 18 13:03:58.230669 2026] [security2:error] [pid 139043:tid 139202] [client 20.52.168.85:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mini.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5FgAAAKI"] [Tue Aug 18 13:03:58.251491 2026] [security2:error] [pid 139043:tid 139240] [client 20.51.153.15:8778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/you.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5FwAAAMg"] [Tue Aug 18 13:03:58.290536 2026] [security2:error] [pid 139043:tid 139197] [client 158.23.17.4:57083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/tt.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5GAAAAJ0"] [Tue Aug 18 13:03:58.297192 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.200.96:15538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5GQAAALY"] [Tue Aug 18 13:03:58.297879 2026] [security2:error] [pid 139043:tid 139177] [client 20.163.43.14:4385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/aa.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5GgAAAIk"] [Tue Aug 18 13:03:58.303642 2026] [security2:error] [pid 139043:tid 139245] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/13.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5GwAAAM0"] [Tue Aug 18 13:03:58.343313 2026] [security2:error] [pid 139043:tid 139270] [client 20.171.51.14:44895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gj.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5HQAAAOY"] [Tue Aug 18 13:03:58.362079 2026] [security2:error] [pid 139043:tid 139226] [client 74.248.130.103:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/pucci.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5HgAAALo"] [Tue Aug 18 13:03:58.366891 2026] [security2:error] [pid 139043:tid 139257] [client 20.104.100.201:24016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/f35.update.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5HwAAANk"] [Tue Aug 18 13:03:58.373217 2026] [security2:error] [pid 139043:tid 139048] [remote 129.121.103.155:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5IAAAwAQ"] [Tue Aug 18 13:03:58.397394 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:58.397641 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:58.400288 2026] [security2:error] [pid 139043:tid 139247] [client 168.62.48.100:5584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5IwAAAM8"] [Tue Aug 18 13:03:58.402520 2026] [security2:error] [pid 139043:tid 139165] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/auth.json"] [unique_id "aoSCbv2v-lWn9OzQT7U5JAAA2Hk"] [Tue Aug 18 13:03:58.415713 2026] [security2:error] [pid 139043:tid 139229] [client 74.249.206.207:7903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/wp-load.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5JgAAAL0"] [Tue Aug 18 13:03:58.421615 2026] [security2:error] [pid 139043:tid 139098] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.dev"] [unique_id "aoSCbv2v-lWn9OzQT7U5JwAAszY"] [Tue Aug 18 13:03:58.421912 2026] [security2:error] [pid 139043:tid 139079] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCbv2v-lWn9OzQT7U5KAAAsyM"] [Tue Aug 18 13:03:58.422985 2026] [security2:error] [pid 139043:tid 139105] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config.php.bak"] [unique_id "aoSCbv2v-lWn9OzQT7U5KQAAsz0"] [Tue Aug 18 13:03:58.435364 2026] [security2:error] [pid 139043:tid 139295] [client 158.23.17.4:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/rn.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5KgAAAP8"] [Tue Aug 18 13:03:58.460224 2026] [security2:error] [pid 139043:tid 139084] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.swp"] [unique_id "aoSCbv2v-lWn9OzQT7U5LQAAyyg"] [Tue Aug 18 13:03:58.465184 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5LgAAAOk"] [Tue Aug 18 13:03:58.479226 2026] [security2:error] [pid 139043:tid 139091] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/public/.env"] [unique_id "aoSCbv2v-lWn9OzQT7U5MAAAuS8"] [Tue Aug 18 13:03:58.482331 2026] [security2:error] [pid 139043:tid 139230] [client 20.1.169.243:10882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bs1.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5MQAAAL4"] [Tue Aug 18 13:03:58.493228 2026] [security2:error] [pid 139043:tid 139272] [client 20.226.36.136:43669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5MgAAAOg"] [Tue Aug 18 13:03:58.541306 2026] [security2:error] [pid 139043:tid 139281] [client 20.51.153.15:9136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ez.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5NAAAAPE"] [Tue Aug 18 13:03:58.548511 2026] [security2:error] [pid 139043:tid 139198] [client 191.237.254.161:52511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/222.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5NQAAAJ4"] [Tue Aug 18 13:03:58.554943 2026] [security2:error] [pid 139043:tid 139275] [client 52.139.47.57:15627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/100.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5NgAAAOs"] [Tue Aug 18 13:03:58.563007 2026] [security2:error] [pid 139043:tid 139266] [client 20.163.43.14:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.joanagaspar.com.br"] [uri "/1.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5NwAAAOI"] [Tue Aug 18 13:03:58.563093 2026] [security2:error] [pid 139043:tid 139266] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/1.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5NwAAAOI"] [Tue Aug 18 13:03:58.579959 2026] [security2:error] [pid 139043:tid 139244] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/cc.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5OAAAAMw"] [Tue Aug 18 13:03:58.592194 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.36.136:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5OgAAAPs"] [Tue Aug 18 13:03:58.605286 2026] [security2:error] [pid 139043:tid 139268] [client 68.221.73.131:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/av.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5OwAAAOQ"] [Tue Aug 18 13:03:58.613848 2026] [security2:error] [pid 139043:tid 139252] [client 20.79.204.6:9713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/index/function.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5PAAAANQ"] [Tue Aug 18 13:03:58.642293 2026] [security2:error] [pid 139043:tid 139216] [client 172.182.217.32:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/network/xmrlpc.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5PQAAALA"] [Tue Aug 18 13:03:58.702775 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.200.96:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5QwAAAP4"] [Tue Aug 18 13:03:58.704278 2026] [authz_core:error] [pid 139043:tid 139120] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:58.704549 2026] [authz_core:error] [pid 139043:tid 139120] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:58.707301 2026] [security2:error] [pid 139043:tid 139263] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/get.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5RAAAAN8"] [Tue Aug 18 13:03:58.720367 2026] [security2:error] [pid 139043:tid 139208] [client 20.163.43.14:3023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/0x.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5RQAAAKg"] [Tue Aug 18 13:03:58.741273 2026] [security2:error] [pid 139043:tid 139212] [client 74.249.206.207:42272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/155.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5RgAAAKw"] [Tue Aug 18 13:03:58.745070 2026] [security2:error] [pid 139043:tid 139288] [client 20.116.17.175:54902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-rrtx.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5RwAAAPg"] [Tue Aug 18 13:03:58.771167 2026] [security2:error] [pid 139043:tid 139203] [client 20.206.73.37:11965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "lifetreemarketing.com"] [uri "/.mopj.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5SQAAAKM"] [Tue Aug 18 13:03:58.775569 2026] [security2:error] [pid 139043:tid 139213] [client 20.250.13.23:37725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5SwAAAK0"] [Tue Aug 18 13:03:58.775589 2026] [security2:error] [pid 139043:tid 139202] [client 20.171.51.14:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pd.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5TAAAAKI"] [Tue Aug 18 13:03:58.785704 2026] [security2:error] [pid 139043:tid 139285] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/rpk.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5TQAAAPU"] [Tue Aug 18 13:03:58.804837 2026] [security2:error] [pid 139043:tid 139240] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/nwwha.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5TgAAAMg"] [Tue Aug 18 13:03:58.808172 2026] [security2:error] [pid 139043:tid 139242] [client 158.23.17.4:60328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/mq.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5TwAAAMo"] [Tue Aug 18 13:03:58.823433 2026] [security2:error] [pid 139043:tid 139222] [client 20.80.111.3:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5UAAAALY"] [Tue Aug 18 13:03:58.824152 2026] [security2:error] [pid 139043:tid 139081] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/web/.env"] [unique_id "aoSCbv2v-lWn9OzQT7U5UQAAiSU"] [Tue Aug 18 13:03:58.842095 2026] [security2:error] [pid 139043:tid 139246] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5UwAAAM4"] [Tue Aug 18 13:03:58.844035 2026] [security2:error] [pid 139043:tid 139283] [client 4.232.151.198:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5VQAAAPM"] [Tue Aug 18 13:03:58.844059 2026] [security2:error] [pid 139043:tid 139274] [client 20.52.168.85:5162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5VAAAAOo"] [Tue Aug 18 13:03:58.844581 2026] [security2:error] [pid 139043:tid 139162] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config.json"] [unique_id "aoSCbv2v-lWn9OzQT7U5VgAAj3Y"] [Tue Aug 18 13:03:58.846961 2026] [security2:error] [pid 139043:tid 139140] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/__/firebase/init.json"] [unique_id "aoSCbv2v-lWn9OzQT7U5VwAA_WA"] [Tue Aug 18 13:03:58.848962 2026] [security2:error] [pid 139043:tid 139218] [client 20.1.169.243:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bthil.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5WAAAALI"] [Tue Aug 18 13:03:58.850277 2026] [security2:error] [pid 139043:tid 139122] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/values.yaml"] [unique_id "aoSCbv2v-lWn9OzQT7U5WQAA5k4"] [Tue Aug 18 13:03:58.869101 2026] [security2:error] [pid 139043:tid 139257] [client 20.51.153.15:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/22.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5WwAAANk"] [Tue Aug 18 13:03:58.887592 2026] [security2:error] [pid 139043:tid 139292] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-blog.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5XAAAAPw"] [Tue Aug 18 13:03:58.900090 2026] [security2:error] [pid 139043:tid 139247] [client 20.104.100.201:24011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/bdroot.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5XQAAAM8"] [Tue Aug 18 13:03:58.913268 2026] [security2:error] [pid 139043:tid 139219] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5XgAAALM"] [Tue Aug 18 13:03:58.923604 2026] [security2:error] [pid 139043:tid 139046] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/config"] [unique_id "aoSCbv2v-lWn9OzQT7U5XwAAuwI"] [Tue Aug 18 13:03:58.942492 2026] [security2:error] [pid 139043:tid 139052] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config.js"] [unique_id "aoSCbv2v-lWn9OzQT7U5YAAA_wg"] [Tue Aug 18 13:03:58.964805 2026] [security2:error] [pid 139043:tid 139245] [client 52.139.47.57:19583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/222.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5YgAAAM0"] [Tue Aug 18 13:03:58.971143 2026] [security2:error] [pid 139043:tid 139273] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/mga.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5ZAAAAOk"] [Tue Aug 18 13:03:58.982275 2026] [security2:error] [pid 139043:tid 139230] [client 20.151.109.219:23511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/28.php"] [unique_id "aoSCbv2v-lWn9OzQT7U5ZQAAAL4"] [Tue Aug 18 13:03:59.007484 2026] [authz_core:error] [pid 139043:tid 139117] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:59.007745 2026] [authz_core:error] [pid 139043:tid 139117] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:59.022655 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.36.136:57792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/rezor.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ZwAAAPQ"] [Tue Aug 18 13:03:59.039509 2026] [security2:error] [pid 139043:tid 139251] [client 213.35.127.232:54634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5aQAAANM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:03:59.045262 2026] [security2:error] [pid 139043:tid 139178] [client 172.182.200.96:15587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5agAAAIo"] [Tue Aug 18 13:03:59.050836 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/fs.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5bAAAAOs"] [Tue Aug 18 13:03:59.095090 2026] [security2:error] [pid 139043:tid 139298] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5bwAAAQI"] [Tue Aug 18 13:03:59.096642 2026] [security2:error] [pid 139043:tid 139228] [client 74.249.206.207:42295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5cAAAALw"] [Tue Aug 18 13:03:59.101447 2026] [security2:error] [pid 139043:tid 139254] [client 20.163.43.14:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/zxz.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5cQAAANY"] [Tue Aug 18 13:03:59.103011 2026] [security2:error] [pid 139043:tid 139268] [client 132.196.30.78:9087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5cgAAAOQ"] [Tue Aug 18 13:03:59.116243 2026] [security2:error] [pid 139043:tid 139259] [client 20.151.109.219:46591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ww.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5cwAAANs"] [Tue Aug 18 13:03:59.130737 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.217.32:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5dAAAAQA"] [Tue Aug 18 13:03:59.136420 2026] [security2:error] [pid 139043:tid 139216] [client 20.51.153.15:9171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/zs.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5dQAAALA"] [Tue Aug 18 13:03:59.152509 2026] [security2:error] [pid 139043:tid 139280] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/opsqt.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5eAAAAPA"] [Tue Aug 18 13:03:59.156224 2026] [security2:error] [pid 139043:tid 139267] [client 20.206.73.37:17163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/scxy.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5eQAAAOM"] [Tue Aug 18 13:03:59.216596 2026] [security2:error] [pid 139043:tid 139291] [client 20.1.169.243:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/bypass.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ewAAAPs"] [Tue Aug 18 13:03:59.235103 2026] [security2:error] [pid 139043:tid 139223] [client 20.171.51.14:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/th.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5fQAAALc"] [Tue Aug 18 13:03:59.264432 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ggAAAPU"] [Tue Aug 18 13:03:59.269173 2026] [security2:error] [pid 139043:tid 139179] [client 20.80.111.3:5915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5hAAAAIs"] [Tue Aug 18 13:03:59.310088 2026] [authz_core:error] [pid 139043:tid 139166] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:59.310332 2026] [authz_core:error] [pid 139043:tid 139166] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:59.323547 2026] [security2:error] [pid 139043:tid 139136] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/env.js"] [unique_id "aoSCb_2v-lWn9OzQT7U5jgAA-lw"] [Tue Aug 18 13:03:59.329006 2026] [security2:error] [pid 139043:tid 139060] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/settings.json"] [unique_id "aoSCb_2v-lWn9OzQT7U5jwAAmRA"] [Tue Aug 18 13:03:59.339110 2026] [security2:error] [pid 139043:tid 139110] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/settings"] [unique_id "aoSCb_2v-lWn9OzQT7U5kAAAw0I"] [Tue Aug 18 13:03:59.343786 2026] [security2:error] [pid 139043:tid 139090] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/v1/settings"] [unique_id "aoSCb_2v-lWn9OzQT7U5kQAAhi4"] [Tue Aug 18 13:03:59.344496 2026] [security2:error] [pid 139043:tid 139197] [client 158.23.17.4:44519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ut.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5kgAAAJ0"] [Tue Aug 18 13:03:59.358546 2026] [security2:error] [pid 139043:tid 139222] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/01.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5kwAAALY"] [Tue Aug 18 13:03:59.375335 2026] [security2:error] [pid 139043:tid 139181] [client 20.51.153.15:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/iz.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5lAAAAI0"] [Tue Aug 18 13:03:59.376986 2026] [security2:error] [pid 139043:tid 139176] [client 52.139.47.57:15666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5lQAAAIg"] [Tue Aug 18 13:03:59.386483 2026] [security2:error] [pid 139043:tid 139283] [client 172.182.200.96:15522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5lgAAAPM"] [Tue Aug 18 13:03:59.403542 2026] [security2:error] [pid 139043:tid 139293] [client 74.249.206.207:31064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/aaa.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5lwAAAP0"] [Tue Aug 18 13:03:59.413470 2026] [security2:error] [pid 139043:tid 139124] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/firebase-config.json"] [unique_id "aoSCb_2v-lWn9OzQT7U5mQAA5lA"] [Tue Aug 18 13:03:59.439790 2026] [security2:error] [pid 139043:tid 139088] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/env.json"] [unique_id "aoSCb_2v-lWn9OzQT7U5nAAAwiw"] [Tue Aug 18 13:03:59.443781 2026] [security2:error] [pid 139043:tid 139249] [client 20.250.13.23:16561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/cjfuns.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5nQAAANE"] [Tue Aug 18 13:03:59.445803 2026] [security2:error] [pid 139043:tid 139232] [client 68.155.156.252:9801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/inso.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ngAAAMA"] [Tue Aug 18 13:03:59.451099 2026] [security2:error] [pid 139043:tid 139239] [client 20.52.168.85:5294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5nwAAAMc"] [Tue Aug 18 13:03:59.461386 2026] [security2:error] [pid 139043:tid 139292] [client 20.163.43.14:3048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/www.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5oAAAAPw"] [Tue Aug 18 13:03:59.485801 2026] [autoindex:error] [pid 139043:tid 139188] [client 4.232.151.198:4188] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:03:59.493786 2026] [security2:error] [pid 139043:tid 139256] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ogAAANg"] [Tue Aug 18 13:03:59.541595 2026] [security2:error] [pid 139043:tid 139209] [client 20.226.36.136:57216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5pQAAAKk"] [Tue Aug 18 13:03:59.543027 2026] [security2:error] [pid 139043:tid 139278] [client 158.23.17.4:47897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/13.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5pgAAAO4"] [Tue Aug 18 13:03:59.549423 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:23949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5pwAAAK4"] [Tue Aug 18 13:03:59.597694 2026] [security2:error] [pid 139043:tid 139252] [client 20.79.204.6:9702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/aaa.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5qwAAANQ"] [Tue Aug 18 13:03:59.609544 2026] [security2:error] [pid 139043:tid 139225] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/wp-tem.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5rQAAALk"] [Tue Aug 18 13:03:59.609811 2026] [security2:error] [pid 139043:tid 139230] [client 20.206.73.37:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/bengi.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5rgAAAL4"] [Tue Aug 18 13:03:59.613986 2026] [security2:error] [pid 139043:tid 139269] [client 68.221.73.131:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5rwAAAOU"] [Tue Aug 18 13:03:59.616328 2026] [security2:error] [pid 139043:tid 139258] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/as.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5sAAAANo"] [Tue Aug 18 13:03:59.616464 2026] [security2:error] [pid 139043:tid 139284] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/lv.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5sQAAAPQ"] [Tue Aug 18 13:03:59.620736 2026] [security2:error] [pid 139043:tid 139205] [client 172.182.217.32:21514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/css/xmrlpc.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5sgAAAKU"] [Tue Aug 18 13:03:59.621860 2026] [security2:error] [pid 139043:tid 139215] [client 52.173.121.69:64950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5swAAAK8"] [Tue Aug 18 13:03:59.673774 2026] [security2:error] [pid 139043:tid 139266] [client 20.116.17.175:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/gecko-new.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5tAAAAOI"] [Tue Aug 18 13:03:59.677348 2026] [security2:error] [pid 139043:tid 139264] [client 20.51.153.15:8738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/se.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5tQAAAOA"] [Tue Aug 18 13:03:59.684100 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.154.236:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5twAAAMw"] [Tue Aug 18 13:03:59.684387 2026] [security2:error] [pid 139043:tid 139097] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.well-known/jwks.json"] [unique_id "aoSCb_2v-lWn9OzQT7U5uAAAvDU"] [Tue Aug 18 13:03:59.693129 2026] [security2:error] [pid 139043:tid 139268] [client 4.232.151.198:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5uwAAAOQ"] [Tue Aug 18 13:03:59.713220 2026] [security2:error] [pid 139043:tid 139296] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/sadd.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5vQAAAQA"] [Tue Aug 18 13:03:59.723759 2026] [security2:error] [pid 139043:tid 139253] [client 20.80.111.3:17244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/images/wp-login.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5vgAAANU"] [Tue Aug 18 13:03:59.726811 2026] [security2:error] [pid 139043:tid 139200] [client 20.171.51.14:13411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/admin404.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5vwAAAKA"] [Tue Aug 18 13:03:59.728565 2026] [security2:error] [pid 139043:tid 139156] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/v1/config"] [unique_id "aoSCb_2v-lWn9OzQT7U5wAAA43A"] [Tue Aug 18 13:03:59.738190 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.200.96:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5wQAAANc"] [Tue Aug 18 13:03:59.766334 2026] [security2:error] [pid 139043:tid 139141] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/v2/config"] [unique_id "aoSCb_2v-lWn9OzQT7U5wwAApmE"] [Tue Aug 18 13:03:59.791232 2026] [security2:error] [pid 139043:tid 139271] [client 20.151.109.219:22947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mo.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5xQAAAOc"] [Tue Aug 18 13:03:59.796583 2026] [security2:error] [pid 139043:tid 139223] [client 20.1.169.243:11151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cc.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5xwAAALc"] [Tue Aug 18 13:03:59.811195 2026] [security2:error] [pid 139043:tid 139202] [client 74.249.206.207:31055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5yAAAAKI"] [Tue Aug 18 13:03:59.821340 2026] [security2:error] [pid 139043:tid 139298] [client 52.139.47.57:10956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/abcd.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5yQAAAQI"] [Tue Aug 18 13:03:59.856707 2026] [security2:error] [pid 139043:tid 139240] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5ywAAAMg"] [Tue Aug 18 13:03:59.870469 2026] [security2:error] [pid 139043:tid 139237] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ex.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5zgAAAMU"] [Tue Aug 18 13:03:59.872651 2026] [security2:error] [pid 139043:tid 139235] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/new.php"] [unique_id "aoSCb_2v-lWn9OzQT7U5zwAAAMM"] [Tue Aug 18 13:03:59.884068 2026] [security2:error] [pid 139043:tid 139056] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/env"] [unique_id "aoSCb_2v-lWn9OzQT7U50QAA9ww"] [Tue Aug 18 13:03:59.912902 2026] [authz_core:error] [pid 139043:tid 139068] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:03:59.913197 2026] [authz_core:error] [pid 139043:tid 139068] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:03:59.922495 2026] [security2:error] [pid 139043:tid 139154] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/runtime-config.js"] [unique_id "aoSCb_2v-lWn9OzQT7U50wAA_W4"] [Tue Aug 18 13:03:59.923443 2026] [security2:error] [pid 139043:tid 139169] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/v2/settings"] [unique_id "aoSCb_2v-lWn9OzQT7U51AAA4X0"] [Tue Aug 18 13:03:59.928759 2026] [security2:error] [pid 139043:tid 139204] [client 20.163.43.14:4378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wicked.php"] [unique_id "aoSCb_2v-lWn9OzQT7U51gAAAKQ"] [Tue Aug 18 13:03:59.941662 2026] [security2:error] [pid 139043:tid 139220] [client 4.232.151.198:12117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCb_2v-lWn9OzQT7U52AAAALQ"] [Tue Aug 18 13:03:59.946254 2026] [security2:error] [pid 139043:tid 139257] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/tax.php"] [unique_id "aoSCb_2v-lWn9OzQT7U52QAAANk"] [Tue Aug 18 13:03:59.954145 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.36.136:57818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCb_2v-lWn9OzQT7U52gAAAMI"] [Tue Aug 18 13:03:59.965584 2026] [security2:error] [pid 139043:tid 139292] [client 132.196.30.78:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/akc.php"] [unique_id "aoSCb_2v-lWn9OzQT7U52wAAAPw"] [Tue Aug 18 13:03:59.974187 2026] [security2:error] [pid 139043:tid 139247] [client 20.51.153.15:8780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vp.php"] [unique_id "aoSCb_2v-lWn9OzQT7U53AAAAM8"] [Tue Aug 18 13:03:59.974774 2026] [security2:error] [pid 139043:tid 139188] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCb_2v-lWn9OzQT7U53QAAAJQ"] [Tue Aug 18 13:03:59.975830 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:29464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/eh.php"] [unique_id "aoSCb_2v-lWn9OzQT7U53gAAANg"] [Tue Aug 18 13:04:00.039645 2026] [security2:error] [pid 139043:tid 139173] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/X7x.php"] [unique_id "aoSCcP2v-lWn9OzQT7U55gAAAIU"] [Tue Aug 18 13:04:00.064974 2026] [security2:error] [pid 139043:tid 139280] [client 213.35.127.232:54819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCcP2v-lWn9OzQT7U56QAAAPA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:00.068973 2026] [security2:error] [pid 139043:tid 139290] [client 20.250.13.23:37743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSCcP2v-lWn9OzQT7U56gAAAPo"] [Tue Aug 18 13:04:00.075328 2026] [security2:error] [pid 139043:tid 139252] [client 172.182.200.96:15559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCcP2v-lWn9OzQT7U56wAAANQ"] [Tue Aug 18 13:04:00.090026 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:23968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-css.php"] [unique_id "aoSCcP2v-lWn9OzQT7U57AAAALk"] [Tue Aug 18 13:04:00.100749 2026] [security2:error] [pid 139043:tid 139299] [client 20.215.241.237:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCcP2v-lWn9OzQT7U57gAAAQM"] [Tue Aug 18 13:04:00.115583 2026] [security2:error] [pid 139043:tid 139283] [client 20.52.168.85:5311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/404.php"] [unique_id "aoSCcP2v-lWn9OzQT7U57wAAAPM"] [Tue Aug 18 13:04:00.115612 2026] [security2:error] [pid 139043:tid 139276] [client 172.182.217.32:21767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U58AAAAOw"] [Tue Aug 18 13:04:00.120748 2026] [security2:error] [pid 139043:tid 139281] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/222.php"] [unique_id "aoSCcP2v-lWn9OzQT7U58QAAAPE"] [Tue Aug 18 13:04:00.130417 2026] [security2:error] [pid 139043:tid 139104] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/manifest.webmanifest"] [unique_id "aoSCcP2v-lWn9OzQT7U58gAA6zw"] [Tue Aug 18 13:04:00.143285 2026] [security2:error] [pid 139043:tid 139192] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ocxla.php"] [unique_id "aoSCcP2v-lWn9OzQT7U59AAAAJg"] [Tue Aug 18 13:04:00.154657 2026] [security2:error] [pid 139043:tid 139248] [client 20.171.51.14:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/qo.php"] [unique_id "aoSCcP2v-lWn9OzQT7U59QAAANA"] [Tue Aug 18 13:04:00.161695 2026] [security2:error] [pid 139043:tid 139177] [client 20.1.169.243:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSCcP2v-lWn9OzQT7U59gAAAIk"] [Tue Aug 18 13:04:00.168427 2026] [security2:error] [pid 139043:tid 139150] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/openapi.json"] [unique_id "aoSCcP2v-lWn9OzQT7U59wAAvGo"] [Tue Aug 18 13:04:00.170225 2026] [security2:error] [pid 139043:tid 139295] [client 20.80.111.3:28167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSCcP2v-lWn9OzQT7U5-AAAAP8"] [Tue Aug 18 13:04:00.175582 2026] [security2:error] [pid 139043:tid 139244] [client 158.23.17.4:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/87.php"] [unique_id "aoSCcP2v-lWn9OzQT7U5-QAAAMw"] [Tue Aug 18 13:04:00.176791 2026] [security2:error] [pid 139043:tid 139254] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCcP2v-lWn9OzQT7U5-gAAANY"] [Tue Aug 18 13:04:00.179875 2026] [security2:error] [pid 139043:tid 139268] [client 74.249.206.207:42291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/site.php"] [unique_id "aoSCcP2v-lWn9OzQT7U5-wAAAOQ"] [Tue Aug 18 13:04:00.189376 2026] [security2:error] [pid 139043:tid 139238] [client 158.23.17.4:15156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/so.php"] [unique_id "aoSCcP2v-lWn9OzQT7U5_AAAAMY"] [Tue Aug 18 13:04:00.197577 2026] [security2:error] [pid 139043:tid 139128] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/openapi.json"] [unique_id "aoSCcP2v-lWn9OzQT7U5_QABAFQ"] [Tue Aug 18 13:04:00.210951 2026] [security2:error] [pid 139043:tid 139086] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/app-config.json"] [unique_id "aoSCcP2v-lWn9OzQT7U5_wAA4yo"] [Tue Aug 18 13:04:00.211558 2026] [authz_core:error] [pid 139043:tid 139049] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:00.211843 2026] [authz_core:error] [pid 139043:tid 139049] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:00.229279 2026] [security2:error] [pid 139043:tid 139258] [client 52.139.47.57:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/al.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6AAAAANo"] [Tue Aug 18 13:04:00.263778 2026] [security2:error] [pid 139043:tid 139208] [client 20.51.153.15:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ph.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6BAAAAKg"] [Tue Aug 18 13:04:00.313228 2026] [security2:error] [pid 139043:tid 139107] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/health"] [unique_id "aoSCcP2v-lWn9OzQT7U6CAAA_j8"] [Tue Aug 18 13:04:00.313488 2026] [security2:error] [pid 139043:tid 139147] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/account"] [unique_id "aoSCcP2v-lWn9OzQT7U6CgAA_mc"] [Tue Aug 18 13:04:00.326591 2026] [autoindex:error] [pid 139043:tid 139205] [client 4.232.151.198:4147] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:00.332590 2026] [security2:error] [pid 139043:tid 139193] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6DAAAAJk"] [Tue Aug 18 13:04:00.357538 2026] [security2:error] [pid 139043:tid 139287] [client 68.221.73.131:63099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6DgAAAPc"] [Tue Aug 18 13:04:00.377048 2026] [security2:error] [pid 139043:tid 139235] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6DQAAwwk"] [Tue Aug 18 13:04:00.379595 2026] [security2:error] [pid 139043:tid 139246] [client 20.163.43.14:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6EAAAAM4"] [Tue Aug 18 13:04:00.381492 2026] [security2:error] [pid 139043:tid 139181] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/chosen.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6EQAAAI0"] [Tue Aug 18 13:04:00.441271 2026] [security2:error] [pid 139043:tid 139220] [client 20.116.17.175:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/df.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6FAAAALQ"] [Tue Aug 18 13:04:00.449811 2026] [security2:error] [pid 139043:tid 139257] [client 172.182.200.96:3058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6FgAAANk"] [Tue Aug 18 13:04:00.476057 2026] [security2:error] [pid 139043:tid 139239] [client 74.249.206.207:45531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/ccc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6GAAAAMc"] [Tue Aug 18 13:04:00.509147 2026] [security2:error] [pid 139043:tid 139219] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/post.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6HAAAALM"] [Tue Aug 18 13:04:00.537459 2026] [security2:error] [pid 139043:tid 139214] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6HwAAAK4"] [Tue Aug 18 13:04:00.544559 2026] [security2:error] [pid 139043:tid 139280] [client 4.232.151.198:4147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6IAAAAPA"] [Tue Aug 18 13:04:00.564714 2026] [security2:error] [pid 139043:tid 139290] [client 158.23.17.4:8671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/10.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6IgAAAPo"] [Tue Aug 18 13:04:00.570801 2026] [security2:error] [pid 139043:tid 139180] [client 20.51.153.15:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/s.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6IwAAAIw"] [Tue Aug 18 13:04:00.572097 2026] [security2:error] [pid 139043:tid 139225] [client 158.23.17.4:33494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ad.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6JAAAALk"] [Tue Aug 18 13:04:00.590834 2026] [security2:error] [pid 139043:tid 139269] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/nhr.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6JQAAAOU"] [Tue Aug 18 13:04:00.593262 2026] [security2:error] [pid 139043:tid 139284] [client 20.171.51.14:38755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sd.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6JgAAAPQ"] [Tue Aug 18 13:04:00.615524 2026] [security2:error] [pid 139043:tid 139232] [client 20.80.111.3:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/includes/admin-header.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6KAAAAMA"] [Tue Aug 18 13:04:00.620275 2026] [security2:error] [pid 139043:tid 139204] [client 172.182.217.32:21545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/img/xmrlpc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6KQAAAKQ"] [Tue Aug 18 13:04:00.643499 2026] [security2:error] [pid 139043:tid 139283] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/info.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6KgAAAPM"] [Tue Aug 18 13:04:00.644153 2026] [security2:error] [pid 139043:tid 139256] [client 52.139.47.57:26319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/alfa.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6KwAAANg"] [Tue Aug 18 13:04:00.651912 2026] [security2:error] [pid 139043:tid 139115] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/health"] [unique_id "aoSCcP2v-lWn9OzQT7U6LQAA8Uc"] [Tue Aug 18 13:04:00.657035 2026] [security2:error] [pid 139043:tid 139059] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/__env.js"] [unique_id "aoSCcP2v-lWn9OzQT7U6LgAA6w8"] [Tue Aug 18 13:04:00.686803 2026] [security2:error] [pid 139043:tid 139192] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6MAAAAJg"] [Tue Aug 18 13:04:00.700184 2026] [security2:error] [pid 139043:tid 139248] [client 20.226.36.136:57261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/index/function.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6MQAAANA"] [Tue Aug 18 13:04:00.705841 2026] [security2:error] [pid 139043:tid 139247] [client 20.250.13.23:16570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6MwAAAM8"] [Tue Aug 18 13:04:00.721709 2026] [security2:error] [pid 139043:tid 139278] [client 20.52.168.85:5310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/shell.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6NAAAAO4"] [Tue Aug 18 13:04:00.727649 2026] [security2:error] [pid 139043:tid 139244] [client 20.104.100.201:23960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/flox.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6NgAAAMw"] [Tue Aug 18 13:04:00.729694 2026] [security2:error] [pid 139043:tid 139268] [client 20.1.169.243:10922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6OAAAAOQ"] [Tue Aug 18 13:04:00.730857 2026] [security2:error] [pid 139043:tid 139112] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/swagger.json"] [unique_id "aoSCcP2v-lWn9OzQT7U6OQAAxkQ"] [Tue Aug 18 13:04:00.730973 2026] [security2:error] [pid 139043:tid 139111] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/api/v1/env"] [unique_id "aoSCcP2v-lWn9OzQT7U6OgAAxkM"] [Tue Aug 18 13:04:00.737052 2026] [security2:error] [pid 139043:tid 139259] [client 20.163.43.14:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6OwAAANs"] [Tue Aug 18 13:04:00.740229 2026] [security2:error] [pid 139043:tid 139061] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/runtime.js"] [unique_id "aoSCcP2v-lWn9OzQT7U6PAABABE"] [Tue Aug 18 13:04:00.748073 2026] [security2:error] [pid 139043:tid 139051] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/configuration.js"] [unique_id "aoSCcP2v-lWn9OzQT7U6PQAAsAc"] [Tue Aug 18 13:04:00.756481 2026] [security2:error] [pid 139043:tid 139267] [client 132.196.30.78:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/buy.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6PgAAAOM"] [Tue Aug 18 13:04:00.763334 2026] [security2:error] [pid 139043:tid 139258] [client 20.226.36.136:57254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6PwAAANo"] [Tue Aug 18 13:04:00.778946 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.200.96:3061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6QQAAAOg"] [Tue Aug 18 13:04:00.779059 2026] [security2:error] [pid 139043:tid 139195] [client 20.151.109.219:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/qr.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6QgAAAJs"] [Tue Aug 18 13:04:00.788236 2026] [security2:error] [pid 139043:tid 139285] [client 149.34.210.141:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6QwAAAPU"] [Tue Aug 18 13:04:00.822449 2026] [security2:error] [pid 139043:tid 139291] [client 20.226.36.136:57800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/Cachex.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6RgAAAPs"] [Tue Aug 18 13:04:00.833951 2026] [security2:error] [pid 139043:tid 139226] [client 74.249.206.207:45505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/admin.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6RwAAALo"] [Tue Aug 18 13:04:00.876862 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6SQAAAJ8"] [Tue Aug 18 13:04:00.947961 2026] [security2:error] [pid 139043:tid 139178] [client 20.151.109.219:23551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/m.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6TAAAAIo"] [Tue Aug 18 13:04:00.949633 2026] [security2:error] [pid 139043:tid 139287] [client 68.155.154.236:8884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ejsserralheriasp.com.br"] [uri "/images/security.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6TgAAAPc"] [Tue Aug 18 13:04:00.976978 2026] [security2:error] [pid 139043:tid 139235] [client 158.23.17.4:46433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/te.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6UAAAAMM"] [Tue Aug 18 13:04:01.001704 2026] [authz_core:error] [pid 139043:tid 139129] [remote 57.141.22.13:35658] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:01.001989 2026] [authz_core:error] [pid 139043:tid 139129] [remote 57.141.22.13:35658] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:01.010801 2026] [security2:error] [pid 139043:tid 139274] [client 20.206.73.37:59967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/file2.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6UgAAAOo"] [Tue Aug 18 13:04:01.036934 2026] [security2:error] [pid 139043:tid 139257] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6UwAAANk"] [Tue Aug 18 13:04:01.039337 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:04:01.039359 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:04:01.062625 2026] [security2:error] [pid 139043:tid 139285] [client 149.34.210.141:51498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCcP2v-lWn9OzQT7U6QwAAAPU"] [Tue Aug 18 13:04:01.064047 2026] [security2:error] [pid 139043:tid 139193] [client 52.139.47.57:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/as.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6VQAAAJk"] [Tue Aug 18 13:04:01.064516 2026] [security2:error] [pid 139043:tid 139292] [client 20.171.51.14:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/km.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6VgAAAPw"] [Tue Aug 18 13:04:01.068874 2026] [security2:error] [pid 139043:tid 139185] [client 20.80.111.3:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/includes/logs.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6VwAAAJE"] [Tue Aug 18 13:04:01.074798 2026] [security2:error] [pid 139043:tid 139182] [client 213.35.127.232:55013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6WAAAAI4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:01.088404 2026] [security2:error] [pid 139043:tid 139194] [client 20.51.153.15:9193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kx.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6WQAAAJo"] [Tue Aug 18 13:04:01.103976 2026] [security2:error] [pid 139043:tid 139246] [client 20.1.169.243:11195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6WgAAAM4"] [Tue Aug 18 13:04:01.108263 2026] [security2:error] [pid 139043:tid 139250] [client 172.182.217.32:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/coffee/xmrlpc.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6XAAAANI"] [Tue Aug 18 13:04:01.141519 2026] [security2:error] [pid 139043:tid 139273] [client 172.182.200.96:15504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6XgAAAOk"] [Tue Aug 18 13:04:01.157363 2026] [security2:error] [pid 139043:tid 139180] [client 74.249.206.207:45521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/reviall.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6XwAAAIw"] [Tue Aug 18 13:04:01.172280 2026] [security2:error] [pid 139043:tid 139225] [client 20.226.36.136:43421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6YAAAALk"] [Tue Aug 18 13:04:01.184850 2026] [security2:error] [pid 139043:tid 139269] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6YQAAAOU"] [Tue Aug 18 13:04:01.188866 2026] [security2:error] [pid 139043:tid 139197] [client 20.104.100.201:23963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/op.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6YgAAAJ0"] [Tue Aug 18 13:04:01.194623 2026] [security2:error] [pid 139043:tid 139299] [client 158.23.17.4:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/vd.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6YwAAAQM"] [Tue Aug 18 13:04:01.198130 2026] [security2:error] [pid 139043:tid 139183] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ZAAAAI8"] [Tue Aug 18 13:04:01.201836 2026] [security2:error] [pid 139043:tid 139232] [client 20.163.43.14:4356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/cah.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ZQAAAMA"] [Tue Aug 18 13:04:01.203238 2026] [security2:error] [pid 139043:tid 139165] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/environment.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6ZgAA03k"] [Tue Aug 18 13:04:01.223163 2026] [security2:error] [pid 139043:tid 139276] [client 68.221.73.131:26629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ZwAAAOw"] [Tue Aug 18 13:04:01.239029 2026] [security2:error] [pid 139043:tid 139079] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/settings.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6aQAAtSM"] [Tue Aug 18 13:04:01.247761 2026] [security2:error] [pid 139043:tid 139294] [client 20.79.204.6:9726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/abcd.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6awAAAP4"] [Tue Aug 18 13:04:01.281566 2026] [security2:error] [pid 139043:tid 139209] [client 4.232.151.198:5013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6bAAAAKk"] [Tue Aug 18 13:04:01.320397 2026] [security2:error] [pid 139043:tid 139238] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6bgAAAMY"] [Tue Aug 18 13:04:01.326459 2026] [security2:error] [pid 139043:tid 139243] [client 20.250.13.23:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/import.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6cAAAAMs"] [Tue Aug 18 13:04:01.344991 2026] [security2:error] [pid 139043:tid 139216] [client 158.23.17.4:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/zi.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6cwAAALA"] [Tue Aug 18 13:04:01.370223 2026] [security2:error] [pid 139043:tid 139148] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/config.json.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6dQAAl2g"] [Tue Aug 18 13:04:01.370226 2026] [security2:error] [pid 139043:tid 139096] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/.env.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6dAAAlzQ"] [Tue Aug 18 13:04:01.370892 2026] [security2:error] [pid 139043:tid 139084] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/constants.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6dgAA7yg"] [Tue Aug 18 13:04:01.371014 2026] [security2:error] [pid 139043:tid 139102] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/credentials.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6dwAA7zo"] [Tue Aug 18 13:04:01.404408 2026] [security2:error] [pid 139043:tid 139272] [client 20.226.36.136:57267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6egAAAOg"] [Tue Aug 18 13:04:01.405600 2026] [security2:error] [pid 139043:tid 139245] [client 194.219.35.172:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.35.219.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.241.203.17"] [uri "/wp-login.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6agAAAM0"] [Tue Aug 18 13:04:01.417928 2026] [authz_core:error] [pid 139043:tid 139092] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:01.418325 2026] [authz_core:error] [pid 139043:tid 139092] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:01.424852 2026] [security2:error] [pid 139043:tid 139206] [client 20.51.153.15:9170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/va.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6fQAAAKY"] [Tue Aug 18 13:04:01.460001 2026] [security2:error] [pid 139043:tid 139223] [client 74.249.206.207:7888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/nope.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6fgAAALc"] [Tue Aug 18 13:04:01.475750 2026] [security2:error] [pid 139043:tid 139200] [client 20.1.169.243:10904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6fwAAAKA"] [Tue Aug 18 13:04:01.478111 2026] [security2:error] [pid 139043:tid 139253] [client 52.139.47.57:26354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/aa.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6gAAAANU"] [Tue Aug 18 13:04:01.507371 2026] [security2:error] [pid 139043:tid 139179] [client 168.62.48.100:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ggAAAIs"] [Tue Aug 18 13:04:01.508717 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.200.96:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6gwAAAMQ"] [Tue Aug 18 13:04:01.509037 2026] [security2:error] [pid 139043:tid 139077] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/public/env.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6hAAApSE"] [Tue Aug 18 13:04:01.511361 2026] [security2:error] [pid 139043:tid 139255] [client 20.80.111.3:17223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/includes/media.php.INFECTED.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6hQAAANc"] [Tue Aug 18 13:04:01.513852 2026] [security2:error] [pid 139043:tid 139240] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6hgAAAMg"] [Tue Aug 18 13:04:01.519392 2026] [security2:error] [pid 139043:tid 139190] [client 132.196.30.78:6789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/cong.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6hwAAAJY"] [Tue Aug 18 13:04:01.523088 2026] [security2:error] [pid 139043:tid 139286] [client 20.171.51.14:13396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mf.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6iAAAAPY"] [Tue Aug 18 13:04:01.548925 2026] [security2:error] [pid 139043:tid 139099] [remote 34.62.54.143:47216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stremmastay.com.br"] [uri "/sw.js"] [unique_id "aoSCcf2v-lWn9OzQT7U6iwAAuDc"] [Tue Aug 18 13:04:01.586282 2026] [security2:error] [pid 139043:tid 139293] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/k.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6jQAAAP0"] [Tue Aug 18 13:04:01.588469 2026] [security2:error] [pid 139043:tid 139218] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6jgAAALI"] [Tue Aug 18 13:04:01.595295 2026] [security2:error] [pid 139043:tid 139263] [client 172.182.217.32:21527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/images/xmrlpc.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6jwAAAN8"] [Tue Aug 18 13:04:01.717564 2026] [authz_core:error] [pid 139043:tid 139052] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:01.717836 2026] [authz_core:error] [pid 139043:tid 139052] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:01.726402 2026] [security2:error] [pid 139043:tid 139180] [client 20.116.17.175:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6mgAAAIw"] [Tue Aug 18 13:04:01.728490 2026] [security2:error] [pid 139043:tid 139241] [client 20.206.73.37:16983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/ws13.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6mwAAAMk"] [Tue Aug 18 13:04:01.759916 2026] [security2:error] [pid 139043:tid 139217] [client 74.249.206.207:45543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/nope.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ngAAALE"] [Tue Aug 18 13:04:01.777336 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fo.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6oAAAAKQ"] [Tue Aug 18 13:04:01.821019 2026] [security2:error] [pid 139043:tid 139281] [client 20.151.109.219:20947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/dirs.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6owAAAPE"] [Tue Aug 18 13:04:01.844900 2026] [security2:error] [pid 139043:tid 139252] [client 20.1.169.243:11073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6pQAAANQ"] [Tue Aug 18 13:04:01.845527 2026] [security2:error] [pid 139043:tid 139192] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6pgAAAJg"] [Tue Aug 18 13:04:01.849846 2026] [security2:error] [pid 139043:tid 139175] [client 20.163.43.14:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/system_log.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6qQAAAIc"] [Tue Aug 18 13:04:01.866351 2026] [security2:error] [pid 139043:tid 139219] [client 157.20.138.62:56585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6qgAAALM"] [Tue Aug 18 13:04:01.866507 2026] [security2:error] [pid 139043:tid 139219] [client 157.20.138.62:56585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6qgAAALM"] [Tue Aug 18 13:04:01.896935 2026] [security2:error] [pid 139043:tid 139299] [client 52.139.47.57:19538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/abc.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6rAAAAQM"] [Tue Aug 18 13:04:01.897501 2026] [security2:error] [pid 139043:tid 139244] [client 20.226.36.136:57795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6rQAAAMw"] [Tue Aug 18 13:04:01.907469 2026] [security2:error] [pid 139043:tid 139259] [client 20.171.51.14:7928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ie.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6sAAAANs"] [Tue Aug 18 13:04:01.912135 2026] [security2:error] [pid 139043:tid 139250] [client 4.232.151.198:21691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6sQAAANI"] [Tue Aug 18 13:04:01.915978 2026] [security2:error] [pid 139043:tid 139216] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ms-edit.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6sgAAALA"] [Tue Aug 18 13:04:01.916796 2026] [security2:error] [pid 139043:tid 139267] [client 20.151.109.219:58729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nl.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6swAAAOM"] [Tue Aug 18 13:04:01.933738 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.200.96:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6tAAAAOg"] [Tue Aug 18 13:04:01.945740 2026] [security2:error] [pid 139043:tid 139215] [client 20.80.111.3:12499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6tgAAAK8"] [Tue Aug 18 13:04:01.948492 2026] [security2:error] [pid 139043:tid 139134] [remote 104.248.149.255:44136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.149.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "proj.vitimarketing.com.br"] [uri "/wp-login.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6tQAA1lo"] [Tue Aug 18 13:04:01.954188 2026] [security2:error] [pid 139043:tid 139233] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/an.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6twAAAME"] [Tue Aug 18 13:04:01.983301 2026] [security2:error] [pid 139043:tid 139225] [client 20.250.13.23:17153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/cropper.php"] [unique_id "aoSCcf2v-lWn9OzQT7U6ugAAALk"] [Tue Aug 18 13:04:02.020076 2026] [security2:error] [pid 139043:tid 139289] [client 20.226.36.136:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6vgAAAPk"] [Tue Aug 18 13:04:02.022205 2026] [authz_core:error] [pid 139043:tid 139158] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:02.022506 2026] [authz_core:error] [pid 139043:tid 139158] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:02.039785 2026] [security2:error] [pid 139043:tid 139206] [client 138.36.100.162:42301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6vwAAAKY"] [Tue Aug 18 13:04:02.039886 2026] [security2:error] [pid 139043:tid 139206] [client 138.36.100.162:42301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6vwAAAKY"] [Tue Aug 18 13:04:02.056651 2026] [security2:error] [pid 139043:tid 139253] [client 20.52.168.85:5752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/file.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6wwAAANU"] [Tue Aug 18 13:04:02.078860 2026] [security2:error] [pid 139043:tid 139237] [client 74.249.206.207:7910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/new.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6xAAAAMU"] [Tue Aug 18 13:04:02.082305 2026] [security2:error] [pid 139043:tid 139191] [client 172.182.217.32:21793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6xgAAAJc"] [Tue Aug 18 13:04:02.084350 2026] [security2:error] [pid 139043:tid 139236] [client 20.226.36.136:43414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6xwAAAMQ"] [Tue Aug 18 13:04:02.088954 2026] [security2:error] [pid 139043:tid 139297] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ws79.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6yAAAAQE"] [Tue Aug 18 13:04:02.098429 2026] [security2:error] [pid 139043:tid 139284] [client 213.35.127.232:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6yQAAAPQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:02.118952 2026] [security2:error] [pid 139043:tid 139222] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/403.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6ygAAALY"] [Tue Aug 18 13:04:02.122092 2026] [security2:error] [pid 139043:tid 139293] [client 68.221.73.131:29808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6ywAAAP0"] [Tue Aug 18 13:04:02.133108 2026] [security2:error] [pid 139043:tid 139218] [client 20.226.36.136:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6zAAAALI"] [Tue Aug 18 13:04:02.165652 2026] [security2:error] [pid 139043:tid 139261] [client 4.223.113.180:12121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6zgAAAN0"] [Tue Aug 18 13:04:02.174121 2026] [security2:error] [pid 139043:tid 139193] [client 20.124.247.79:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6zwAAAJk"] [Tue Aug 18 13:04:02.228195 2026] [security2:error] [pid 139043:tid 139182] [client 20.104.100.201:23977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCcv2v-lWn9OzQT7U60QAAAI4"] [Tue Aug 18 13:04:02.232461 2026] [security2:error] [pid 139043:tid 139178] [client 20.1.169.243:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/config.php"] [unique_id "aoSCcv2v-lWn9OzQT7U60gAAAIo"] [Tue Aug 18 13:04:02.233615 2026] [security2:error] [pid 139043:tid 139186] [client 20.226.36.136:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U60wAAAJI"] [Tue Aug 18 13:04:02.291165 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:9119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ke.php"] [unique_id "aoSCcv2v-lWn9OzQT7U61gAAAIU"] [Tue Aug 18 13:04:02.301214 2026] [security2:error] [pid 139043:tid 139235] [client 172.182.200.96:15585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCcv2v-lWn9OzQT7U61wAAAMM"] [Tue Aug 18 13:04:02.301414 2026] [security2:error] [pid 139043:tid 139256] [client 20.206.73.37:29984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/copypaths.php"] [unique_id "aoSCcv2v-lWn9OzQT7U62AAAANg"] [Tue Aug 18 13:04:02.310108 2026] [security2:error] [pid 139043:tid 139239] [client 52.139.47.57:37367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/av.php"] [unique_id "aoSCcv2v-lWn9OzQT7U62gAAAMc"] [Tue Aug 18 13:04:02.337549 2026] [security2:error] [pid 139043:tid 139192] [client 20.171.51.14:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nw.php"] [unique_id "aoSCcv2v-lWn9OzQT7U63gAAAJg"] [Tue Aug 18 13:04:02.358880 2026] [security2:error] [pid 139043:tid 139183] [client 178.153.171.161:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U64AAAAI8"] [Tue Aug 18 13:04:02.359004 2026] [security2:error] [pid 139043:tid 139183] [client 178.153.171.161:48022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U64AAAAI8"] [Tue Aug 18 13:04:02.373956 2026] [security2:error] [pid 139043:tid 139214] [client 20.80.111.3:5945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "aoSCcv2v-lWn9OzQT7U64QAAAK4"] [Tue Aug 18 13:04:02.384297 2026] [security2:error] [pid 139043:tid 139277] [client 132.196.30.78:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCcv2v-lWn9OzQT7U64gAAAO0"] [Tue Aug 18 13:04:02.389945 2026] [security2:error] [pid 139043:tid 139228] [client 74.248.130.103:34962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCcv2v-lWn9OzQT7U64wAAALw"] [Tue Aug 18 13:04:02.399968 2026] [security2:error] [pid 139043:tid 139247] [client 158.23.17.4:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/56.php"] [unique_id "aoSCcv2v-lWn9OzQT7U65QAAAM8"] [Tue Aug 18 13:04:02.450579 2026] [security2:error] [pid 139043:tid 139198] [client 74.249.206.207:31060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/new.php"] [unique_id "aoSCcv2v-lWn9OzQT7U66AAAAJ4"] [Tue Aug 18 13:04:02.467704 2026] [security2:error] [pid 139043:tid 139215] [client 20.206.73.37:11924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/gm.php"] [unique_id "aoSCcv2v-lWn9OzQT7U66gAAAK8"] [Tue Aug 18 13:04:02.468084 2026] [security2:error] [pid 139043:tid 139254] [client 20.124.247.79:16844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCcv2v-lWn9OzQT7U66wAAANY"] [Tue Aug 18 13:04:02.499697 2026] [security2:error] [pid 139043:tid 139274] [client 20.151.109.219:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/68.php"] [unique_id "aoSCcv2v-lWn9OzQT7U67AAAAOo"] [Tue Aug 18 13:04:02.500508 2026] [security2:error] [pid 139043:tid 139263] [client 20.79.204.6:9719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-good.php"] [unique_id "aoSCcv2v-lWn9OzQT7U67QAAAN8"] [Tue Aug 18 13:04:02.511399 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/404.php"] [unique_id "aoSCcv2v-lWn9OzQT7U67wAAAPs"] [Tue Aug 18 13:04:02.519022 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.36.136:57849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCcv2v-lWn9OzQT7U68AAAALo"] [Tue Aug 18 13:04:02.591475 2026] [security2:error] [pid 139043:tid 139250] [client 172.182.217.32:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U69AAAANI"] [Tue Aug 18 13:04:02.597397 2026] [security2:error] [pid 139043:tid 139177] [client 20.250.13.23:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U69gAAAIk"] [Tue Aug 18 13:04:02.599825 2026] [security2:error] [pid 139043:tid 139225] [client 20.1.169.243:10900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6-QAAALk"] [Tue Aug 18 13:04:02.600331 2026] [security2:error] [pid 139043:tid 139253] [client 158.23.17.4:15111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/kc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6-gAAANU"] [Tue Aug 18 13:04:02.607887 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6-wAAAMU"] [Tue Aug 18 13:04:02.611078 2026] [autoindex:error] [pid 139043:tid 139248] [client 4.232.151.198:4096] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:02.624820 2026] [security2:error] [pid 139043:tid 139245] [client 103.120.71.157:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6_QAAAM0"] [Tue Aug 18 13:04:02.625209 2026] [security2:error] [pid 139043:tid 139245] [client 103.120.71.157:61534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6_QAAAM0"] [Tue Aug 18 13:04:02.644133 2026] [security2:error] [pid 139043:tid 139297] [client 20.151.109.219:20952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sn.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6_gAAAQE"] [Tue Aug 18 13:04:02.667685 2026] [security2:error] [pid 139043:tid 139272] [client 20.52.168.85:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/222.php"] [unique_id "aoSCcv2v-lWn9OzQT7U6_wAAAOg"] [Tue Aug 18 13:04:02.668737 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.200.96:15510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7AAAAALY"] [Tue Aug 18 13:04:02.671509 2026] [security2:error] [pid 139043:tid 139181] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/gecko.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7AQAAAI0"] [Tue Aug 18 13:04:02.680212 2026] [security2:error] [pid 139043:tid 139218] [client 20.51.153.15:8818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/nh.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7AwAAALI"] [Tue Aug 18 13:04:02.703367 2026] [security2:error] [pid 139043:tid 139193] [client 168.62.48.100:4102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7BQAAAJk"] [Tue Aug 18 13:04:02.715823 2026] [security2:error] [pid 139043:tid 139249] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7BgAAANE"] [Tue Aug 18 13:04:02.718289 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.36.136:57826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7BwAAAIs"] [Tue Aug 18 13:04:02.727422 2026] [security2:error] [pid 139043:tid 139206] [client 52.139.47.57:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7CAAAAKY"] [Tue Aug 18 13:04:02.771404 2026] [security2:error] [pid 139043:tid 139280] [client 74.249.206.207:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/apreset.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7CQAAAPA"] [Tue Aug 18 13:04:02.782575 2026] [security2:error] [pid 139043:tid 139295] [client 20.124.247.79:16828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7CwAAAP8"] [Tue Aug 18 13:04:02.807001 2026] [security2:error] [pid 139043:tid 139220] [client 158.23.17.4:29498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/rx.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7DAAAALQ"] [Tue Aug 18 13:04:02.825384 2026] [security2:error] [pid 139043:tid 139293] [client 20.80.111.3:5918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7EAAAAP0"] [Tue Aug 18 13:04:02.825790 2026] [security2:error] [pid 139043:tid 139073] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7DwAA0x0"] [Tue Aug 18 13:04:02.826008 2026] [security2:error] [pid 139043:tid 139251] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7DwAA0x0"] [Tue Aug 18 13:04:02.843681 2026] [security2:error] [pid 139043:tid 139256] [client 74.248.130.103:49023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7EQAAANg"] [Tue Aug 18 13:04:02.865344 2026] [security2:error] [pid 139043:tid 139209] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-login.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7FAAAAKk"] [Tue Aug 18 13:04:02.907084 2026] [security2:error] [pid 139043:tid 139244] [client 20.171.51.14:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sb.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7FwAAAMw"] [Tue Aug 18 13:04:02.924308 2026] [authz_core:error] [pid 139043:tid 139047] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:02.924620 2026] [authz_core:error] [pid 139043:tid 139047] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:02.937438 2026] [security2:error] [pid 139043:tid 139278] [client 20.51.153.15:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/oo.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7GwAAAO4"] [Tue Aug 18 13:04:02.942597 2026] [security2:error] [pid 139043:tid 139267] [client 20.151.109.219:56036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/jl.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7HAAAAOM"] [Tue Aug 18 13:04:02.950245 2026] [security2:error] [pid 139043:tid 139258] [client 20.163.43.14:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7HQAAANo"] [Tue Aug 18 13:04:02.973267 2026] [security2:error] [pid 139043:tid 139221] [client 20.1.169.243:10919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/module.php"] [unique_id "aoSCcv2v-lWn9OzQT7U7HwAAALU"] [Tue Aug 18 13:04:03.002600 2026] [security2:error] [pid 139043:tid 139157] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7IQAAwnE"] [Tue Aug 18 13:04:03.002838 2026] [security2:error] [pid 139043:tid 139234] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7IQAAwnE"] [Tue Aug 18 13:04:03.010085 2026] [security2:error] [pid 139043:tid 139160] [remote 47.128.59.3:54940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mcvans.com.br"] [uri "/robots.txt"] [unique_id "aoSCc_2v-lWn9OzQT7U7IgAA6nQ"] [Tue Aug 18 13:04:03.012276 2026] [security2:error] [pid 139043:tid 139263] [client 172.182.200.96:15541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7IwAAAN8"] [Tue Aug 18 13:04:03.017917 2026] [security2:error] [pid 139043:tid 139240] [client 4.232.151.198:11428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/a7.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7JAAAAMg"] [Tue Aug 18 13:04:03.035790 2026] [security2:error] [pid 139043:tid 139271] [client 4.232.151.198:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7JgAAAOc"] [Tue Aug 18 13:04:03.052153 2026] [security2:error] [pid 139043:tid 139289] [client 20.124.247.79:16873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/av.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7JwAAAPk"] [Tue Aug 18 13:04:03.079167 2026] [security2:error] [pid 139043:tid 139199] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/aa.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7KQAAAJ8"] [Tue Aug 18 13:04:03.080474 2026] [security2:error] [pid 139043:tid 139212] [client 74.249.206.207:7919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/1mage.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7KgAAAKw"] [Tue Aug 18 13:04:03.082156 2026] [security2:error] [pid 139043:tid 139177] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7LAAAAIk"] [Tue Aug 18 13:04:03.082260 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.217.32:21844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/xmrlpc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7KwAAAQA"] [Tue Aug 18 13:04:03.114235 2026] [security2:error] [pid 139043:tid 139246] [client 213.35.127.232:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7LQAAAM4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:03.125806 2026] [security2:error] [pid 139043:tid 139229] [client 4.223.113.180:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7LgAAAL0"] [Tue Aug 18 13:04:03.128942 2026] [security2:error] [pid 139043:tid 139245] [client 20.116.17.175:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/usr.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7LwAAAM0"] [Tue Aug 18 13:04:03.141928 2026] [security2:error] [pid 139043:tid 139211] [client 52.139.47.57:19574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/asus.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7MAAAAKs"] [Tue Aug 18 13:04:03.206949 2026] [security2:error] [pid 139043:tid 139181] [client 158.23.17.4:15787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/92.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7MgAAAI0"] [Tue Aug 18 13:04:03.218130 2026] [security2:error] [pid 139043:tid 139292] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7NAAAAPw"] [Tue Aug 18 13:04:03.219252 2026] [security2:error] [pid 139043:tid 139270] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/rtx.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7NQAAAOY"] [Tue Aug 18 13:04:03.248751 2026] [security2:error] [pid 139043:tid 139208] [client 20.250.13.23:16565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7NwAAAKg"] [Tue Aug 18 13:04:03.261934 2026] [security2:error] [pid 139043:tid 139193] [client 20.51.153.15:8788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ja.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7OQAAAJk"] [Tue Aug 18 13:04:03.268782 2026] [security2:error] [pid 139043:tid 139179] [client 20.171.51.14:13404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xj.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7OwAAAIs"] [Tue Aug 18 13:04:03.275741 2026] [security2:error] [pid 139043:tid 139298] [client 20.80.111.3:26003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7PAAAAQI"] [Tue Aug 18 13:04:03.291472 2026] [security2:error] [pid 139043:tid 139206] [client 20.124.247.79:16835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/images.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7PQAAAKY"] [Tue Aug 18 13:04:03.298891 2026] [security2:error] [pid 139043:tid 139253] [client 20.52.168.85:5302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7PgAAANU"] [Tue Aug 18 13:04:03.338853 2026] [security2:error] [pid 139043:tid 139300] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/0x.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7QQAAAQQ"] [Tue Aug 18 13:04:03.344859 2026] [security2:error] [pid 139043:tid 139280] [client 172.182.200.96:15571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7QgAAAPA"] [Tue Aug 18 13:04:03.355665 2026] [security2:error] [pid 139043:tid 139200] [client 20.1.169.243:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/options.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7QwAAAKA"] [Tue Aug 18 13:04:03.356660 2026] [security2:error] [pid 139043:tid 139295] [client 20.163.43.14:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/abc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7RAAAAP8"] [Tue Aug 18 13:04:03.378629 2026] [security2:error] [pid 139043:tid 139241] [client 68.221.73.131:32261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7RQAAAMk"] [Tue Aug 18 13:04:03.386493 2026] [security2:error] [pid 139043:tid 139273] [client 74.249.206.207:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/imsc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7RgAAAOk"] [Tue Aug 18 13:04:03.403059 2026] [security2:error] [pid 139043:tid 139173] [client 132.196.30.78:9035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/db.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7RwAAAIU"] [Tue Aug 18 13:04:03.427417 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7SQAAAMM"] [Tue Aug 18 13:04:03.428775 2026] [security2:error] [pid 139043:tid 139259] [client 20.151.109.219:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/tq.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7SgAAANs"] [Tue Aug 18 13:04:03.453775 2026] [security2:error] [pid 139043:tid 139185] [client 20.79.204.6:9287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/simple.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7SwAAAJE"] [Tue Aug 18 13:04:03.499274 2026] [security2:error] [pid 139043:tid 139183] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/end.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7TQAAAI8"] [Tue Aug 18 13:04:03.529086 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:03.529530 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:03.568914 2026] [security2:error] [pid 139043:tid 139293] [client 172.182.217.32:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7UgAAAP0"] [Tue Aug 18 13:04:03.572527 2026] [security2:error] [pid 139043:tid 139278] [client 20.124.247.79:16793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/ops.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7UwAAAO4"] [Tue Aug 18 13:04:03.574748 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:23956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/txets.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7VQAAAOM"] [Tue Aug 18 13:04:03.587303 2026] [security2:error] [pid 139043:tid 139258] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/zxz.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7VwAAANo"] [Tue Aug 18 13:04:03.594980 2026] [security2:error] [pid 139043:tid 139256] [client 52.139.47.57:10981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/about.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7WAAAANg"] [Tue Aug 18 13:04:03.610310 2026] [security2:error] [pid 139043:tid 139197] [client 20.226.36.136:57265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7WgAAAJ0"] [Tue Aug 18 13:04:03.617635 2026] [security2:error] [pid 139043:tid 139195] [client 20.206.73.37:11909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/ws55.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7WwAAAJs"] [Tue Aug 18 13:04:03.622049 2026] [security2:error] [pid 139043:tid 139221] [client 158.23.17.4:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/jn.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7XAAAALU"] [Tue Aug 18 13:04:03.638201 2026] [security2:error] [pid 139043:tid 139262] [client 20.171.51.14:7891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ns.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7XQAAAN4"] [Tue Aug 18 13:04:03.641902 2026] [security2:error] [pid 139043:tid 139054] [remote 47.128.29.212:14740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoSCc_2v-lWn9OzQT7U7XgAAwgo"] [Tue Aug 18 13:04:03.664378 2026] [security2:error] [pid 139043:tid 139223] [client 20.226.112.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.net.br"] [uri "/ae.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7YAAAALc"] [Tue Aug 18 13:04:03.692435 2026] [security2:error] [pid 139043:tid 139250] [client 20.51.153.15:8806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xx.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7YgAAANI"] [Tue Aug 18 13:04:03.713356 2026] [autoindex:error] [pid 139043:tid 139266] [client 4.232.151.198:20484] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:03.728293 2026] [security2:error] [pid 139043:tid 139246] [client 74.249.206.207:7879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7ZgAAAM4"] [Tue Aug 18 13:04:03.730266 2026] [security2:error] [pid 139043:tid 139254] [client 20.1.169.243:11196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/panel.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7ZwAAANY"] [Tue Aug 18 13:04:03.732810 2026] [security2:error] [pid 139043:tid 139237] [client 158.23.17.4:63647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mandrill.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7aAAAAMU"] [Tue Aug 18 13:04:03.737666 2026] [security2:error] [pid 139043:tid 139248] [client 20.163.43.14:4371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/akcc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7aQAAANA"] [Tue Aug 18 13:04:03.778619 2026] [security2:error] [pid 139043:tid 139190] [client 4.232.151.198:26724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/catalogbypass.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7bAAAAJY"] [Tue Aug 18 13:04:03.796624 2026] [security2:error] [pid 139043:tid 139240] [client 20.80.111.3:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-admin/user/wp-login.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7bgAAAMg"] [Tue Aug 18 13:04:03.815161 2026] [security2:error] [pid 139043:tid 139292] [client 172.182.200.96:15498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7cAAAAPw"] [Tue Aug 18 13:04:03.825813 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:03.826066 2026] [authz_core:error] [pid 139043:tid 139064] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:03.851657 2026] [security2:error] [pid 139043:tid 139261] [client 20.124.247.79:16889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/coffexium.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7cgAAAN0"] [Tue Aug 18 13:04:03.873217 2026] [security2:error] [pid 139043:tid 139249] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/www.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7eQAAANE"] [Tue Aug 18 13:04:03.874351 2026] [autoindex:error] [pid 139043:tid 139131] [remote 34.158.8.33:49538] AH01276: Cannot serve directory /home4/acessoso/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:03.874353 2026] [security2:error] [pid 139043:tid 139179] [client 74.248.130.103:48971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/puc.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7egAAAIs"] [Tue Aug 18 13:04:03.879781 2026] [security2:error] [pid 139043:tid 139271] [client 20.250.13.23:16525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/goat.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7ewAAAOc"] [Tue Aug 18 13:04:03.905274 2026] [security2:error] [pid 139043:tid 139225] [client 20.52.168.85:5254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-admin/a.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7fAAAALk"] [Tue Aug 18 13:04:03.914477 2026] [security2:error] [pid 139043:tid 139186] [client 20.151.109.219:38621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/43.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7fQAAAJI"] [Tue Aug 18 13:04:03.918095 2026] [security2:error] [pid 139043:tid 139217] [client 4.232.151.198:20484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7fgAAALE"] [Tue Aug 18 13:04:03.975034 2026] [security2:error] [pid 139043:tid 139268] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wso.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7gAAAAOQ"] [Tue Aug 18 13:04:03.978923 2026] [security2:error] [pid 139043:tid 139220] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7gQAAALQ"] [Tue Aug 18 13:04:03.987158 2026] [security2:error] [pid 139043:tid 139297] [client 4.232.151.198:7741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/fitnessbase/dev.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7ggAAAQE"] [Tue Aug 18 13:04:03.995206 2026] [security2:error] [pid 139043:tid 139283] [client 20.226.36.136:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7gwAAAPM"] [Tue Aug 18 13:04:03.999354 2026] [security2:error] [pid 139043:tid 139235] [client 20.51.153.15:9200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/conn-test.php"] [unique_id "aoSCc_2v-lWn9OzQT7U7hAAAAMM"] [Tue Aug 18 13:04:04.011240 2026] [security2:error] [pid 139043:tid 139232] [client 52.139.47.57:26360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/atomlib.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7hQAAAMA"] [Tue Aug 18 13:04:04.028617 2026] [security2:error] [pid 139043:tid 139239] [client 20.226.36.136:57275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7hgAAAMc"] [Tue Aug 18 13:04:04.044810 2026] [security2:error] [pid 139043:tid 139194] [client 37.40.227.74:57241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7hwAAAJo"] [Tue Aug 18 13:04:04.044924 2026] [security2:error] [pid 139043:tid 139194] [client 37.40.227.74:57241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7hwAAAJo"] [Tue Aug 18 13:04:04.058134 2026] [security2:error] [pid 139043:tid 139202] [client 4.223.113.180:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/file5.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7iQAAAKI"] [Tue Aug 18 13:04:04.061997 2026] [security2:error] [pid 139043:tid 139192] [client 74.249.206.207:22734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/qlex1.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7igAAAJg"] [Tue Aug 18 13:04:04.067161 2026] [security2:error] [pid 139043:tid 139178] [client 172.182.217.32:21395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7jAAAAIo"] [Tue Aug 18 13:04:04.089351 2026] [security2:error] [pid 139043:tid 139184] [client 103.184.169.37:43705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7jQAAAJA"] [Tue Aug 18 13:04:04.089750 2026] [security2:error] [pid 139043:tid 139184] [client 103.184.169.37:43705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7jQAAAJA"] [Tue Aug 18 13:04:04.095690 2026] [security2:error] [pid 139043:tid 139241] [client 20.1.169.243:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7jgAAAMk"] [Tue Aug 18 13:04:04.128050 2026] [security2:error] [pid 139043:tid 139293] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wicked.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7kAAAAP0"] [Tue Aug 18 13:04:04.128081 2026] [authz_core:error] [pid 139043:tid 139094] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:04.128351 2026] [authz_core:error] [pid 139043:tid 139094] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:04.129264 2026] [security2:error] [pid 139043:tid 139272] [client 20.124.247.79:16799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7kQAAAOg"] [Tue Aug 18 13:04:04.129479 2026] [security2:error] [pid 139043:tid 139222] [client 213.35.127.232:55639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7kgAAALY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:04.152709 2026] [security2:error] [pid 139043:tid 139216] [client 20.163.43.14:4398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wk/index.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7lAAAALA"] [Tue Aug 18 13:04:04.173923 2026] [security2:error] [pid 139043:tid 139258] [client 20.215.241.237:20939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7lQAAANo"] [Tue Aug 18 13:04:04.174847 2026] [security2:error] [pid 139043:tid 139256] [client 158.23.17.4:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/jm.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7lgAAANg"] [Tue Aug 18 13:04:04.175067 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.200.96:15516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7lwAAAJ0"] [Tue Aug 18 13:04:04.178988 2026] [security2:error] [pid 139043:tid 139219] [client 20.226.36.136:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7mAAAALM"] [Tue Aug 18 13:04:04.224061 2026] [security2:error] [pid 139043:tid 139291] [client 20.206.73.37:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/m.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7mgAAAPs"] [Tue Aug 18 13:04:04.235546 2026] [security2:error] [pid 139043:tid 139212] [client 191.237.254.161:13164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/key.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7mwAAAKw"] [Tue Aug 18 13:04:04.259578 2026] [security2:error] [pid 139043:tid 139266] [client 20.51.153.15:9198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fg.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7nQAAAOI"] [Tue Aug 18 13:04:04.281473 2026] [security2:error] [pid 139043:tid 139279] [client 20.80.111.3:28166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7oAAAAO8"] [Tue Aug 18 13:04:04.289588 2026] [security2:error] [pid 139043:tid 139089] [remote 162.214.205.212:39622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7oQAAjC0"] [Tue Aug 18 13:04:04.295571 2026] [security2:error] [pid 139043:tid 139229] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7ogAAAL0"] [Tue Aug 18 13:04:04.309405 2026] [security2:error] [pid 139043:tid 139255] [client 68.221.73.131:63049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/222.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7pgAAANc"] [Tue Aug 18 13:04:04.328155 2026] [security2:error] [pid 139043:tid 139240] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/sf.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7sAAAAMg"] [Tue Aug 18 13:04:04.336363 2026] [security2:error] [pid 139043:tid 139203] [client 158.23.17.4:29475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/main.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7sQAAAKM"] [Tue Aug 18 13:04:04.357411 2026] [security2:error] [pid 139043:tid 139269] [client 74.249.206.207:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/mariju.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7sgAAAOU"] [Tue Aug 18 13:04:04.376114 2026] [security2:error] [pid 139043:tid 139281] [client 20.118.133.132:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/133.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7swAAAPE"] [Tue Aug 18 13:04:04.393140 2026] [security2:error] [pid 139043:tid 139271] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7tAAAAOc"] [Tue Aug 18 13:04:04.402047 2026] [security2:error] [pid 139043:tid 139265] [client 20.124.247.79:16820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/sf.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7tQAAAOE"] [Tue Aug 18 13:04:04.408350 2026] [security2:error] [pid 139043:tid 139298] [client 20.171.51.14:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gk.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7tgAAAQI"] [Tue Aug 18 13:04:04.428430 2026] [security2:error] [pid 139043:tid 139237] [client 52.139.47.57:26331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSCdP2v-lWn9OzQT7U7uAAAAMU"] [Tue Aug 18 13:04:04.449981 2026] [security2:error] [pid 139043:tid 139198] [client 114.119.145.225:41661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/base-de-conhecimento/"] [unique_id "aoSCdP2v-lWn9OzQT7U7uwAAAJ4"], referer: https://ajuda.oruc.com.br/configurando-bling-erp/ [Tue Aug 18 13:04:04.465573 2026] [security2:error] [pid 139043:tid 139224] [client 20.1.169.243:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7vAAAALg"] [Tue Aug 18 13:04:04.475958 2026] [security2:error] [pid 139043:tid 139295] [client 20.104.100.201:24046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/img.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7wAAAAP8"] [Tue Aug 18 13:04:04.483575 2026] [security2:error] [pid 139043:tid 139297] [client 158.23.17.4:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floripaveiculos.com.br"] [uri "/bf.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7wQAAAQE"] [Tue Aug 18 13:04:04.501638 2026] [security2:error] [pid 139043:tid 139259] [client 20.51.153.15:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ve.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7xAAAANs"] [Tue Aug 18 13:04:04.502419 2026] [security2:error] [pid 139043:tid 139235] [client 20.163.43.14:3060] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "copemsa.com.br"] [uri "/1.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7xQAAAMM"] [Tue Aug 18 13:04:04.502513 2026] [security2:error] [pid 139043:tid 139235] [client 20.163.43.14:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/1.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7xQAAAMM"] [Tue Aug 18 13:04:04.511849 2026] [security2:error] [pid 139043:tid 139245] [client 20.250.13.23:16545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/Session.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7xwAAAM0"] [Tue Aug 18 13:04:04.512128 2026] [security2:error] [pid 139043:tid 139284] [client 20.52.168.85:5155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-admin.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7yAAAAPQ"] [Tue Aug 18 13:04:04.530386 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.200.96:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7yQAAAP4"] [Tue Aug 18 13:04:04.547131 2026] [security2:error] [pid 139043:tid 139194] [client 20.116.17.175:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/privacy.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7ygAAAJo"] [Tue Aug 18 13:04:04.555906 2026] [security2:error] [pid 139043:tid 139199] [client 172.182.217.32:21381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7ywAAAJ8"] [Tue Aug 18 13:04:04.577576 2026] [security2:error] [pid 139043:tid 139287] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7zAAAAPc"] [Tue Aug 18 13:04:04.579828 2026] [security2:error] [pid 139043:tid 139181] [client 4.232.151.198:20496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7zQAAAI0"] [Tue Aug 18 13:04:04.591786 2026] [security2:error] [pid 139043:tid 139300] [client 5.31.227.224:7857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7zgAAAQQ"] [Tue Aug 18 13:04:04.591913 2026] [security2:error] [pid 139043:tid 139300] [client 5.31.227.224:7857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U7zgAAAQQ"] [Tue Aug 18 13:04:04.594877 2026] [security2:error] [pid 139043:tid 139241] [client 85.208.98.31:50072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bjagricola.com.br"] [uri "/movil-resultados-segunda-b-k.html"] [unique_id "aoSCdP2v-lWn9OzQT7U7zwAAAMk"] [Tue Aug 18 13:04:04.594959 2026] [security2:error] [pid 139043:tid 139241] [client 85.208.98.31:50072] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/movil-resultados-segunda-b-k.html"] [unique_id "aoSCdP2v-lWn9OzQT7U7zwAAAMk"] [Tue Aug 18 13:04:04.596191 2026] [security2:error] [pid 139043:tid 139277] [client 20.151.109.219:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/cv.php"] [unique_id "aoSCdP2v-lWn9OzQT7U70AAAAO0"] [Tue Aug 18 13:04:04.607927 2026] [security2:error] [pid 139043:tid 139228] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCdP2v-lWn9OzQT7U70gAAALw"] [Tue Aug 18 13:04:04.625343 2026] [security2:error] [pid 139043:tid 139182] [client 4.232.151.198:25227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/libs.php"] [unique_id "aoSCdP2v-lWn9OzQT7U70wAAAI4"] [Tue Aug 18 13:04:04.644214 2026] [security2:error] [pid 139043:tid 139267] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCdP2v-lWn9OzQT7U71AAAAOM"] [Tue Aug 18 13:04:04.667556 2026] [security2:error] [pid 139043:tid 139219] [client 20.124.247.79:16875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/k.php"] [unique_id "aoSCdP2v-lWn9OzQT7U71QAAALM"] [Tue Aug 18 13:04:04.674928 2026] [security2:error] [pid 139043:tid 139195] [client 74.249.206.207:45528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCdP2v-lWn9OzQT7U71gAAAJs"] [Tue Aug 18 13:04:04.679819 2026] [security2:error] [pid 139043:tid 139174] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/index/function.php"] [unique_id "aoSCdP2v-lWn9OzQT7U71wAAAIY"] [Tue Aug 18 13:04:04.724907 2026] [security2:error] [pid 139043:tid 139183] [client 20.80.111.3:28195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSCdP2v-lWn9OzQT7U72gAAAI8"] [Tue Aug 18 13:04:04.744141 2026] [security2:error] [pid 139043:tid 139201] [client 20.48.236.86:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCdP2v-lWn9OzQT7U73AAAAKE"] [Tue Aug 18 13:04:04.802656 2026] [security2:error] [pid 139043:tid 139255] [client 20.171.51.14:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wn.php"] [unique_id "aoSCdP2v-lWn9OzQT7U74gAAANc"] [Tue Aug 18 13:04:04.818134 2026] [security2:error] [pid 139043:tid 139205] [client 68.221.73.131:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCdP2v-lWn9OzQT7U74wAAAKU"] [Tue Aug 18 13:04:04.831313 2026] [security2:error] [pid 139043:tid 139292] [client 20.163.43.14:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSCdP2v-lWn9OzQT7U75AAAAPw"] [Tue Aug 18 13:04:04.840557 2026] [security2:error] [pid 139043:tid 139206] [client 20.79.204.6:9329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/edit-tags.php"] [unique_id "aoSCdP2v-lWn9OzQT7U75gAAAKY"] [Tue Aug 18 13:04:04.841328 2026] [security2:error] [pid 139043:tid 139209] [client 52.139.47.57:29230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/b.php"] [unique_id "aoSCdP2v-lWn9OzQT7U75wAAAKk"] [Tue Aug 18 13:04:04.846335 2026] [security2:error] [pid 139043:tid 139289] [client 20.1.169.243:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSCdP2v-lWn9OzQT7U76AAAAPk"] [Tue Aug 18 13:04:04.875832 2026] [security2:error] [pid 139043:tid 139281] [client 20.51.153.15:9173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ia.php"] [unique_id "aoSCdP2v-lWn9OzQT7U76gAAAPE"] [Tue Aug 18 13:04:04.878122 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.200.96:15523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCdP2v-lWn9OzQT7U76wAAAJk"] [Tue Aug 18 13:04:04.901230 2026] [security2:error] [pid 139043:tid 139188] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/cah.php"] [unique_id "aoSCdP2v-lWn9OzQT7U77QAAAJQ"] [Tue Aug 18 13:04:04.909833 2026] [security2:error] [pid 139043:tid 139079] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.env"] [unique_id "aoSCdP2v-lWn9OzQT7U77wABACM"] [Tue Aug 18 13:04:04.937065 2026] [security2:error] [pid 139043:tid 139242] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCdP2v-lWn9OzQT7U78gAAAMo"] [Tue Aug 18 13:04:04.989557 2026] [security2:error] [pid 139043:tid 139259] [client 20.124.247.79:16776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/82.php"] [unique_id "aoSCdP2v-lWn9OzQT7U79wAAANs"] [Tue Aug 18 13:04:05.020340 2026] [security2:error] [pid 139043:tid 139272] [client 4.223.113.180:17888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/new.php"] [unique_id "aoSCdf2v-lWn9OzQT7U7-QAAAOg"] [Tue Aug 18 13:04:05.041089 2026] [security2:error] [pid 139043:tid 139194] [client 132.196.30.78:12932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/dropdown.php"] [unique_id "aoSCdf2v-lWn9OzQT7U7-wAAAJo"] [Tue Aug 18 13:04:05.042362 2026] [security2:error] [pid 139043:tid 139199] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/edit.php"] [unique_id "aoSCdf2v-lWn9OzQT7U7_AAAAJ8"] [Tue Aug 18 13:04:05.042455 2026] [authz_core:error] [pid 139043:tid 139102] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:05.042810 2026] [authz_core:error] [pid 139043:tid 139102] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:05.049639 2026] [security2:error] [pid 139043:tid 139179] [client 172.182.217.32:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/mail.php"] [unique_id "aoSCdf2v-lWn9OzQT7U7_gAAAIs"] [Tue Aug 18 13:04:05.078693 2026] [security2:error] [pid 139043:tid 139184] [client 74.249.206.207:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/contacto.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8AAAAAJA"] [Tue Aug 18 13:04:05.109417 2026] [security2:error] [pid 139043:tid 139222] [client 20.151.109.219:21951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/un.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8AwAAALY"] [Tue Aug 18 13:04:05.109417 2026] [security2:error] [pid 139043:tid 139182] [client 20.48.236.86:16270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8AgAAAI4"] [Tue Aug 18 13:04:05.133542 2026] [security2:error] [pid 139043:tid 139217] [client 20.250.13.23:16542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8BgAAALE"] [Tue Aug 18 13:04:05.166017 2026] [security2:error] [pid 139043:tid 139203] [client 213.35.127.232:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8CgAAAKM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:05.171814 2026] [security2:error] [pid 139043:tid 139195] [client 158.23.17.4:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ga.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8DgAAAJs"] [Tue Aug 18 13:04:05.178678 2026] [security2:error] [pid 139043:tid 139185] [client 20.80.111.3:28201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/index.php.suspected"] [unique_id "aoSCdf2v-lWn9OzQT7U8DwAAAJE"] [Tue Aug 18 13:04:05.207290 2026] [security2:error] [pid 139043:tid 139232] [client 4.232.151.198:4203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8FgAAAMA"] [Tue Aug 18 13:04:05.211749 2026] [security2:error] [pid 139043:tid 139234] [client 20.226.36.136:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8GAAAAMI"] [Tue Aug 18 13:04:05.212040 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wj.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8GQAAALc"] [Tue Aug 18 13:04:05.213070 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:4383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8GgAAAPU"] [Tue Aug 18 13:04:05.218280 2026] [security2:error] [pid 139043:tid 139299] [client 20.1.169.243:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/chosen.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8HAAAAQM"] [Tue Aug 18 13:04:05.232475 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.200.96:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8HQAAAIk"] [Tue Aug 18 13:04:05.238287 2026] [security2:error] [pid 139043:tid 139290] [client 20.124.247.79:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/dex.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8HgAAAPo"] [Tue Aug 18 13:04:05.251282 2026] [security2:error] [pid 139043:tid 139288] [client 20.171.51.14:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/app.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8HwAAAPg"] [Tue Aug 18 13:04:05.255303 2026] [security2:error] [pid 139043:tid 139216] [client 52.139.47.57:15650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/buy.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8IAAAALA"] [Tue Aug 18 13:04:05.277258 2026] [security2:error] [pid 139043:tid 139200] [client 20.116.17.175:54248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/css/database.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8IwAAAKA"] [Tue Aug 18 13:04:05.280481 2026] [security2:error] [pid 139043:tid 139279] [client 20.206.73.37:20711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/33.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8JAAAAO8"] [Tue Aug 18 13:04:05.282898 2026] [security2:error] [pid 139043:tid 139180] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8JQAAAIw"] [Tue Aug 18 13:04:05.283065 2026] [security2:error] [pid 139043:tid 139229] [client 20.104.100.201:24053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8JgAAAL0"] [Tue Aug 18 13:04:05.304805 2026] [security2:error] [pid 139043:tid 139253] [client 20.52.168.85:5265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/IXR/wp-login.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8BAAAANU"] [Tue Aug 18 13:04:05.315453 2026] [security2:error] [pid 139043:tid 139247] [client 4.232.151.198:7687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8LAAAAM8"] [Tue Aug 18 13:04:05.320549 2026] [security2:error] [pid 139043:tid 139257] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/system_log.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8LQAAANk"] [Tue Aug 18 13:04:05.341868 2026] [authz_core:error] [pid 139043:tid 139134] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:05.342342 2026] [authz_core:error] [pid 139043:tid 139134] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:05.343738 2026] [security2:error] [pid 139043:tid 139252] [client 20.51.153.15:9105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kn.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8MQAAANQ"] [Tue Aug 18 13:04:05.344278 2026] [security2:error] [pid 139043:tid 139244] [client 20.151.109.219:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fresh.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8MgAAAMw"] [Tue Aug 18 13:04:05.425497 2026] [security2:error] [pid 139043:tid 139294] [client 74.249.206.207:45555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/image2.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8NQAAAP4"] [Tue Aug 18 13:04:05.524603 2026] [security2:error] [pid 139043:tid 139238] [client 20.124.247.79:16798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/puc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8OAAAAMY"] [Tue Aug 18 13:04:05.545962 2026] [security2:error] [pid 139043:tid 139280] [client 172.182.217.32:21788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/upfile.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8OQAAAPA"] [Tue Aug 18 13:04:05.550421 2026] [security2:error] [pid 139043:tid 139222] [client 74.248.130.103:42027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/8.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8OgAAALY"] [Tue Aug 18 13:04:05.575570 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.200.96:15508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8OwAAAJ0"] [Tue Aug 18 13:04:05.590301 2026] [security2:error] [pid 139043:tid 139195] [client 20.163.43.14:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/as.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8PgAAAJs"] [Tue Aug 18 13:04:05.593497 2026] [security2:error] [pid 139043:tid 139176] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8PwAAAIg"] [Tue Aug 18 13:04:05.600412 2026] [security2:error] [pid 139043:tid 139219] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8QAAAALM"] [Tue Aug 18 13:04:05.615878 2026] [security2:error] [pid 139043:tid 139221] [client 68.221.73.131:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8QQAAALU"] [Tue Aug 18 13:04:05.638399 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:05.638652 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:05.651909 2026] [security2:error] [pid 139043:tid 139198] [client 197.184.64.235:42665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8QwAAAJ4"] [Tue Aug 18 13:04:05.652031 2026] [security2:error] [pid 139043:tid 139198] [client 197.184.64.235:42665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8QwAAAJ4"] [Tue Aug 18 13:04:05.660547 2026] [security2:error] [pid 139043:tid 139214] [client 20.80.111.3:40640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/layout.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8RAAAAK4"] [Tue Aug 18 13:04:05.675118 2026] [security2:error] [pid 139043:tid 139278] [client 52.139.47.57:37317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/bless.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8RgAAAO4"] [Tue Aug 18 13:04:05.683470 2026] [security2:error] [pid 139043:tid 139183] [client 20.51.153.15:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wm.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8SAAAAI8"] [Tue Aug 18 13:04:05.684149 2026] [security2:error] [pid 139043:tid 139285] [client 158.23.17.4:16902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/wb.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8SQAAAPU"] [Tue Aug 18 13:04:05.700360 2026] [security2:error] [pid 139043:tid 139298] [client 223.185.37.47:23202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8SgAAAQI"] [Tue Aug 18 13:04:05.700471 2026] [security2:error] [pid 139043:tid 139298] [client 223.185.37.47:23202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8SgAAAQI"] [Tue Aug 18 13:04:05.720371 2026] [security2:error] [pid 139043:tid 139177] [client 74.249.206.207:31087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/fb.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8SwAAAIk"] [Tue Aug 18 13:04:05.723264 2026] [security2:error] [pid 139043:tid 139261] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8TAAAAN0"] [Tue Aug 18 13:04:05.744074 2026] [security2:error] [pid 139043:tid 139200] [client 168.62.48.100:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8TgAAAKA"] [Tue Aug 18 13:04:05.754506 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/privdayz.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8UwAAANA"] [Tue Aug 18 13:04:05.767742 2026] [security2:error] [pid 139043:tid 139217] [client 20.250.13.23:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/abcd.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8VgAAALE"] [Tue Aug 18 13:04:05.770637 2026] [security2:error] [pid 139043:tid 139218] [client 20.1.169.243:11243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/class-protect-uploads.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8VwAAALI"] [Tue Aug 18 13:04:05.792103 2026] [security2:error] [pid 139043:tid 139159] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.env.backup"] [unique_id "aoSCdf2v-lWn9OzQT7U8WAAApXM"] [Tue Aug 18 13:04:05.792956 2026] [security2:error] [pid 139043:tid 139052] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.env.bak"] [unique_id "aoSCdf2v-lWn9OzQT7U8WQAApQg"] [Tue Aug 18 13:04:05.821172 2026] [security2:error] [pid 139043:tid 139085] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.env.old"] [unique_id "aoSCdf2v-lWn9OzQT7U8WwAA5Sk"] [Tue Aug 18 13:04:05.842122 2026] [security2:error] [pid 139043:tid 139252] [client 20.124.247.79:16863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/inso.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8XAAAANQ"] [Tue Aug 18 13:04:05.858204 2026] [security2:error] [pid 139043:tid 139271] [client 20.171.51.14:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/87.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8XgAAAOc"] [Tue Aug 18 13:04:05.865353 2026] [security2:error] [pid 139043:tid 139114] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/api/.env"] [unique_id "aoSCdf2v-lWn9OzQT7U8XwAAlEY"] [Tue Aug 18 13:04:05.907750 2026] [security2:error] [pid 139043:tid 139201] [client 20.52.168.85:5255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/plugins.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8YAAAAKE"] [Tue Aug 18 13:04:05.911804 2026] [security2:error] [pid 139043:tid 139237] [client 168.62.48.100:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/well-known/index.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8YQAAAMU"] [Tue Aug 18 13:04:05.917378 2026] [security2:error] [pid 139043:tid 139242] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8YgAAAMo"] [Tue Aug 18 13:04:05.919049 2026] [security2:error] [pid 139043:tid 139230] [client 20.151.109.219:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/evil.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8YwAAAL4"] [Tue Aug 18 13:04:05.933110 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8ZQAAAOk"] [Tue Aug 18 13:04:05.935628 2026] [security2:error] [pid 139043:tid 139173] [client 20.104.100.201:24058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8ZgAAAIU"] [Tue Aug 18 13:04:05.945186 2026] [security2:error] [pid 139043:tid 139259] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-good.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8ZwAAANs"] [Tue Aug 18 13:04:05.954040 2026] [security2:error] [pid 139043:tid 139234] [client 4.223.113.180:40488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fm.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8aQAAAMI"] [Tue Aug 18 13:04:05.963851 2026] [autoindex:error] [pid 139043:tid 139274] [client 4.232.151.198:4198] AH01276: Cannot serve directory /home3/brto26/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:05.970930 2026] [security2:error] [pid 139043:tid 139190] [client 196.12.128.158:50195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8agAAAJY"] [Tue Aug 18 13:04:05.971036 2026] [security2:error] [pid 139043:tid 139190] [client 196.12.128.158:50195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8agAAAJY"] [Tue Aug 18 13:04:05.971427 2026] [security2:error] [pid 139043:tid 139255] [client 4.232.151.198:42980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins//about.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8awAAANc"] [Tue Aug 18 13:04:05.988871 2026] [security2:error] [pid 139043:tid 139240] [client 52.173.121.69:51442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8bAAAAMg"] [Tue Aug 18 13:04:06.000799 2026] [security2:error] [pid 139043:tid 139294] [client 172.182.200.96:15493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCdf2v-lWn9OzQT7U8bQAAAP4"] [Tue Aug 18 13:04:06.011352 2026] [security2:error] [pid 139043:tid 139286] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8bgAAAPY"] [Tue Aug 18 13:04:06.024121 2026] [security2:error] [pid 139043:tid 139199] [client 158.23.17.4:7209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/74.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8bwAAAJ8"] [Tue Aug 18 13:04:06.048577 2026] [security2:error] [pid 139043:tid 139265] [client 172.182.217.32:21401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8cQAAAOE"] [Tue Aug 18 13:04:06.062084 2026] [security2:error] [pid 139043:tid 139300] [client 132.196.30.78:4970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/file.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8cgAAAQQ"] [Tue Aug 18 13:04:06.064999 2026] [security2:error] [pid 139043:tid 139228] [client 20.206.73.37:21100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8cwAAALw"] [Tue Aug 18 13:04:06.084533 2026] [security2:error] [pid 139043:tid 139238] [client 20.124.247.79:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/aa.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8dQAAAMY"] [Tue Aug 18 13:04:06.096972 2026] [security2:error] [pid 139043:tid 139182] [client 20.48.236.86:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8dwAAAI4"] [Tue Aug 18 13:04:06.098215 2026] [security2:error] [pid 139043:tid 139235] [client 52.139.47.57:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8eAAAAMM"] [Tue Aug 18 13:04:06.120135 2026] [security2:error] [pid 139043:tid 139272] [client 20.80.111.3:26004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/0Rhsgxs8WrSRpDwUIbgQrf/src/ui/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8egAAAOg"] [Tue Aug 18 13:04:06.159813 2026] [security2:error] [pid 139043:tid 139287] [client 20.1.169.243:11139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8fAAAAPc"] [Tue Aug 18 13:04:06.171374 2026] [security2:error] [pid 139043:tid 139232] [client 4.232.151.198:4198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/wp-themes.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8fQAAAMA"] [Tue Aug 18 13:04:06.173716 2026] [security2:error] [pid 139043:tid 139291] [client 74.249.206.207:45542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/gi.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8fgAAAPs"] [Tue Aug 18 13:04:06.182399 2026] [security2:error] [pid 139043:tid 139244] [client 213.35.127.232:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8fwAAAMw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:06.216736 2026] [security2:error] [pid 139043:tid 139110] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/backend/.env"] [unique_id "aoSCdv2v-lWn9OzQT7U8gQAA9UI"] [Tue Aug 18 13:04:06.221987 2026] [security2:error] [pid 139043:tid 139227] [client 20.171.51.14:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/zi.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8ggAAALs"] [Tue Aug 18 13:04:06.222766 2026] [security2:error] [pid 139043:tid 139177] [client 191.237.254.161:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/chosen.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8gwAAAIk"] [Tue Aug 18 13:04:06.233106 2026] [security2:error] [pid 139043:tid 139090] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/config/.env"] [unique_id "aoSCdv2v-lWn9OzQT7U8hgAA3S4"] [Tue Aug 18 13:04:06.263243 2026] [security2:error] [pid 139043:tid 139248] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/abc.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8iQAAANA"] [Tue Aug 18 13:04:06.267066 2026] [security2:error] [pid 139043:tid 139175] [client 20.51.153.15:8804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ac.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8igAAAIc"] [Tue Aug 18 13:04:06.271462 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8iwAAALE"] [Tue Aug 18 13:04:06.276567 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:4374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8jAAAAOY"] [Tue Aug 18 13:04:06.300005 2026] [security2:error] [pid 139043:tid 139233] [client 4.232.151.198:11411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/manager.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8kQAAAME"] [Tue Aug 18 13:04:06.329147 2026] [security2:error] [pid 139043:tid 139246] [client 20.124.247.79:16777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/img.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8lAAAAM4"] [Tue Aug 18 13:04:06.333164 2026] [security2:error] [pid 139043:tid 139269] [client 172.182.200.96:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8lQAAAOU"] [Tue Aug 18 13:04:06.377742 2026] [security2:error] [pid 139043:tid 139254] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8lwAAANY"] [Tue Aug 18 13:04:06.416941 2026] [security2:error] [pid 139043:tid 139183] [client 20.250.13.23:17188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/kj.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8mgAAAI8"] [Tue Aug 18 13:04:06.417068 2026] [security2:error] [pid 139043:tid 139211] [client 20.226.36.136:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8mQAAAKs"] [Tue Aug 18 13:04:06.458041 2026] [security2:error] [pid 139043:tid 139284] [client 20.116.17.175:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wg459o.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8nAAAAPQ"] [Tue Aug 18 13:04:06.470002 2026] [security2:error] [pid 139043:tid 139275] [client 158.23.17.4:10967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/xn.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8nwAAAOs"] [Tue Aug 18 13:04:06.512773 2026] [security2:error] [pid 139043:tid 139199] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/akcc.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8pAAAAJ8"] [Tue Aug 18 13:04:06.513089 2026] [security2:error] [pid 139043:tid 139271] [client 52.139.47.57:26361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/cache.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8pQAAAOc"] [Tue Aug 18 13:04:06.517516 2026] [security2:error] [pid 139043:tid 139181] [client 20.51.153.15:9182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/yz.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8pwAAAI0"] [Tue Aug 18 13:04:06.518799 2026] [security2:error] [pid 139043:tid 139184] [client 20.206.73.37:21288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/btx25.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8qAAAAJA"] [Tue Aug 18 13:04:06.524579 2026] [security2:error] [pid 139043:tid 139268] [client 20.1.169.243:10907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/content.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8qQAAAOQ"] [Tue Aug 18 13:04:06.533296 2026] [security2:error] [pid 139043:tid 139249] [client 172.182.217.32:21808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8qwAAANE"] [Tue Aug 18 13:04:06.559566 2026] [security2:error] [pid 139043:tid 139230] [client 20.80.111.3:17241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/0x5oFSRBaxEEW4WLAIJz80/src/ui/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8rgAAAL4"] [Tue Aug 18 13:04:06.577910 2026] [autoindex:error] [pid 139043:tid 139289] [client 20.52.168.85:5704] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:06.587230 2026] [security2:error] [pid 139043:tid 139280] [client 74.249.206.207:31048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/video.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8rwAAAPA"] [Tue Aug 18 13:04:06.606202 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pw.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8sAAAAMM"] [Tue Aug 18 13:04:06.628989 2026] [security2:error] [pid 139043:tid 139203] [client 20.163.43.14:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8sQAAAKM"] [Tue Aug 18 13:04:06.643435 2026] [security2:error] [pid 139043:tid 139197] [client 20.171.51.14:13403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/92.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8sgAAAJ0"] [Tue Aug 18 13:04:06.652480 2026] [security2:error] [pid 139043:tid 139195] [client 20.124.247.79:16886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/222.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8swAAAJs"] [Tue Aug 18 13:04:06.658479 2026] [security2:error] [pid 139043:tid 139262] [client 74.248.130.103:22388] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8tAAAAN4"] [Tue Aug 18 13:04:06.658546 2026] [security2:error] [pid 139043:tid 139262] [client 74.248.130.103:22388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8tAAAAN4"] [Tue Aug 18 13:04:06.662534 2026] [security2:error] [pid 139043:tid 139234] [client 4.232.151.198:41652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/colors/coffee/autoload_classmap.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8tQAAAMI"] [Tue Aug 18 13:04:06.678827 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.200.96:15490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8tgAAAPc"] [Tue Aug 18 13:04:06.685555 2026] [security2:error] [pid 139043:tid 139232] [client 68.221.73.131:47789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8uQAAAMA"] [Tue Aug 18 13:04:06.716281 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:24032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8vQAAAK4"] [Tue Aug 18 13:04:06.719114 2026] [security2:error] [pid 139043:tid 139223] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/tes.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8vwAAALc"] [Tue Aug 18 13:04:06.761446 2026] [security2:error] [pid 139043:tid 139227] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wk/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8wQAAALs"] [Tue Aug 18 13:04:06.777405 2026] [security2:error] [pid 139043:tid 139216] [client 20.215.241.237:17500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/av.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8wwAAALA"] [Tue Aug 18 13:04:06.777539 2026] [security2:error] [pid 139043:tid 139256] [client 20.52.168.85:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-includes/customize/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8xAAAANg"] [Tue Aug 18 13:04:06.778110 2026] [security2:error] [pid 139043:tid 139279] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8xQAAAO8"] [Tue Aug 18 13:04:06.801058 2026] [security2:error] [pid 139043:tid 139267] [client 4.232.151.198:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasiltocantins.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8xwAAAOM"] [Tue Aug 18 13:04:06.839051 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:06.839352 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:06.845549 2026] [security2:error] [pid 139043:tid 139209] [client 68.155.154.236:46811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCdv2v-lWn9OzQT7U8zwAAAKk"] [Tue Aug 18 13:04:06.890285 2026] [security2:error] [pid 139043:tid 139193] [client 20.1.169.243:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/database.php"] [unique_id "aoSCdv2v-lWn9OzQT7U80AAAAJk"] [Tue Aug 18 13:04:06.916260 2026] [security2:error] [pid 139043:tid 139242] [client 74.249.206.207:42271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/hel.php"] [unique_id "aoSCdv2v-lWn9OzQT7U80gAAAMo"] [Tue Aug 18 13:04:06.937208 2026] [security2:error] [pid 139043:tid 139293] [client 52.139.47.57:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/content.php"] [unique_id "aoSCdv2v-lWn9OzQT7U80wAAAP0"] [Tue Aug 18 13:04:06.965371 2026] [security2:error] [pid 139043:tid 139243] [client 20.124.247.79:16871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/key.php"] [unique_id "aoSCdv2v-lWn9OzQT7U81gAAAMs"] [Tue Aug 18 13:04:06.969837 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:4375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCdv2v-lWn9OzQT7U81wAAAPQ"] [Tue Aug 18 13:04:06.974663 2026] [security2:error] [pid 139043:tid 139190] [client 132.196.30.78:8426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/goods.php"] [unique_id "aoSCdv2v-lWn9OzQT7U82AAAAJY"] [Tue Aug 18 13:04:07.007781 2026] [security2:error] [pid 139043:tid 139252] [client 20.80.111.3:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/duplicator/assets/about.php"] [unique_id "aoSCd_2v-lWn9OzQT7U82gAAANQ"] [Tue Aug 18 13:04:07.009866 2026] [security2:error] [pid 139043:tid 139286] [client 172.182.200.96:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCd_2v-lWn9OzQT7U82wAAAPY"] [Tue Aug 18 13:04:07.018075 2026] [security2:error] [pid 139043:tid 139181] [client 20.7.73.61:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.markettohome.com.br"] [uri "/1.php"] [unique_id "aoSCd_2v-lWn9OzQT7U83AAAAI0"] [Tue Aug 18 13:04:07.018165 2026] [security2:error] [pid 139043:tid 139181] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/1.php"] [unique_id "aoSCd_2v-lWn9OzQT7U83AAAAI0"] [Tue Aug 18 13:04:07.023174 2026] [security2:error] [pid 139043:tid 139269] [client 172.182.217.32:21405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ae.php"] [unique_id "aoSCd_2v-lWn9OzQT7U83QAAAOU"] [Tue Aug 18 13:04:07.037437 2026] [security2:error] [pid 139043:tid 139241] [client 20.171.51.14:12095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/jm.php"] [unique_id "aoSCd_2v-lWn9OzQT7U83gAAAMk"] [Tue Aug 18 13:04:07.060663 2026] [security2:error] [pid 139043:tid 139215] [client 20.250.13.23:17163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/languages.php"] [unique_id "aoSCd_2v-lWn9OzQT7U83wAAAK8"] [Tue Aug 18 13:04:07.077672 2026] [security2:error] [pid 139043:tid 139268] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/files/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U84AAAAOQ"] [Tue Aug 18 13:04:07.081615 2026] [security2:error] [pid 139043:tid 139224] [client 20.206.73.37:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/packed.php"] [unique_id "aoSCd_2v-lWn9OzQT7U84QAAALg"] [Tue Aug 18 13:04:07.094920 2026] [security2:error] [pid 139043:tid 139280] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCd_2v-lWn9OzQT7U85QAAAPA"] [Tue Aug 18 13:04:07.099592 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:21278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fn.php"] [unique_id "aoSCd_2v-lWn9OzQT7U85gAAAMM"] [Tue Aug 18 13:04:07.123554 2026] [security2:error] [pid 139043:tid 139103] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.github/.env"] [unique_id "aoSCd_2v-lWn9OzQT7U86AAAhjs"] [Tue Aug 18 13:04:07.142669 2026] [security2:error] [pid 139043:tid 139262] [client 74.248.130.103:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/about.php"] [unique_id "aoSCd_2v-lWn9OzQT7U86wAAAN4"] [Tue Aug 18 13:04:07.145918 2026] [security2:error] [pid 139043:tid 139287] [client 20.104.100.201:23946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSCd_2v-lWn9OzQT7U87AAAAPc"] [Tue Aug 18 13:04:07.173551 2026] [security2:error] [pid 139043:tid 139163] [remote 162.214.205.212:39638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guelraott.com"] [uri "/wp-login.php"] [unique_id "aoSCd_2v-lWn9OzQT7U88QAA2Xc"] [Tue Aug 18 13:04:07.189932 2026] [security2:error] [pid 139043:tid 139223] [client 20.51.153.15:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kj.php"] [unique_id "aoSCd_2v-lWn9OzQT7U88wAAALc"] [Tue Aug 18 13:04:07.199280 2026] [security2:error] [pid 139043:tid 139192] [client 213.35.127.232:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCd_2v-lWn9OzQT7U89AAAAJg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:07.232277 2026] [security2:error] [pid 139043:tid 139216] [client 20.124.247.79:16797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/chosen.php"] [unique_id "aoSCd_2v-lWn9OzQT7U8-AAAALA"] [Tue Aug 18 13:04:07.241396 2026] [security2:error] [pid 139043:tid 139266] [client 158.23.17.4:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/av.php"] [unique_id "aoSCd_2v-lWn9OzQT7U8-QAAAOI"] [Tue Aug 18 13:04:07.257291 2026] [security2:error] [pid 139043:tid 139248] [client 20.116.17.175:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/mifta.php"] [unique_id "aoSCd_2v-lWn9OzQT7U8-wAAANA"] [Tue Aug 18 13:04:07.258603 2026] [security2:error] [pid 139043:tid 139221] [client 20.1.169.243:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/db.php"] [unique_id "aoSCd_2v-lWn9OzQT7U8_AAAALU"] [Tue Aug 18 13:04:07.298120 2026] [security2:error] [pid 139043:tid 139206] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U8_gAAAKY"] [Tue Aug 18 13:04:07.349576 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.200.96:3011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9AAAAAJk"] [Tue Aug 18 13:04:07.352909 2026] [security2:error] [pid 139043:tid 139237] [client 52.139.47.57:15659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9AgAAAMU"] [Tue Aug 18 13:04:07.405374 2026] [security2:error] [pid 139043:tid 139244] [client 4.232.151.198:7455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/Core-Econ/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9BgAAAMw"] [Tue Aug 18 13:04:07.408100 2026] [security2:error] [pid 139043:tid 139288] [client 20.206.73.37:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/mgrr.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9BwAAAPg"] [Tue Aug 18 13:04:07.428002 2026] [security2:error] [pid 139043:tid 139243] [client 74.249.206.207:7900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/grok.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9CAAAAMs"] [Tue Aug 18 13:04:07.430241 2026] [security2:error] [pid 139043:tid 139284] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9CQAAAPQ"] [Tue Aug 18 13:04:07.439523 2026] [security2:error] [pid 139043:tid 139275] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9DAAAAOs"] [Tue Aug 18 13:04:07.443612 2026] [authz_core:error] [pid 139043:tid 139059] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:07.443898 2026] [authz_core:error] [pid 139043:tid 139059] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:07.445059 2026] [security2:error] [pid 139043:tid 139283] [client 20.80.111.3:26019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9DQAAAPM"] [Tue Aug 18 13:04:07.461282 2026] [autoindex:error] [pid 139043:tid 139285] [client 20.52.168.85:5161] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:07.464591 2026] [security2:error] [pid 139043:tid 139285] [client 20.151.109.219:36329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gj.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9DwAAAPU"] [Tue Aug 18 13:04:07.479526 2026] [security2:error] [pid 139043:tid 139274] [client 20.124.247.79:16783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/wpxml.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9EAAAAOo"] [Tue Aug 18 13:04:07.502136 2026] [security2:error] [pid 139043:tid 139226] [client 20.151.109.219:27762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kf.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9EQAAALo"] [Tue Aug 18 13:04:07.510920 2026] [security2:error] [pid 139043:tid 139213] [client 20.171.51.14:47130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wj.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9EgAAAK0"] [Tue Aug 18 13:04:07.511047 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.217.32:21799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/moon.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9EwAAAJQ"] [Tue Aug 18 13:04:07.517151 2026] [security2:error] [pid 139043:tid 139181] [client 20.163.43.14:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9FQAAAI0"] [Tue Aug 18 13:04:07.522558 2026] [autoindex:error] [pid 139043:tid 139286] [client 169.58.72.248:57876] AH01276: Cannot serve directory /home2/tecnomorcom/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:07.556572 2026] [security2:error] [pid 139043:tid 139215] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9GwAAAK8"] [Tue Aug 18 13:04:07.572802 2026] [security2:error] [pid 139043:tid 139293] [client 91.92.47.191:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "coffeestationbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9BQAAAP0"] [Tue Aug 18 13:04:07.574295 2026] [security2:error] [pid 139043:tid 139224] [client 20.48.236.86:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/av.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9HAAAALg"] [Tue Aug 18 13:04:07.599513 2026] [security2:error] [pid 139043:tid 139195] [client 20.226.36.136:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9HwAAAJs"] [Tue Aug 18 13:04:07.600750 2026] [security2:error] [pid 139043:tid 139262] [client 20.51.153.15:8802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vg.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9IAAAAN4"] [Tue Aug 18 13:04:07.622705 2026] [security2:error] [pid 139043:tid 139263] [client 74.248.130.103:50167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9IwAAAN8"] [Tue Aug 18 13:04:07.624540 2026] [security2:error] [pid 139043:tid 139252] [client 20.1.169.243:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/default.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9JAAAANQ"] [Tue Aug 18 13:04:07.626618 2026] [security2:error] [pid 139043:tid 139252] [client 68.221.73.131:29803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/i.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9JQAAANQ"] [Tue Aug 18 13:04:07.629576 2026] [security2:error] [pid 139043:tid 139202] [client 20.206.73.37:1274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9JgAAAKI"] [Tue Aug 18 13:04:07.655154 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/47.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9KgAAAIo"] [Tue Aug 18 13:04:07.661337 2026] [security2:error] [pid 139043:tid 139208] [client 20.104.100.201:24028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/term.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9LAAAAKg"] [Tue Aug 18 13:04:07.674872 2026] [autoindex:error] [pid 139043:tid 139192] [client 20.52.168.85:5161] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:07.675637 2026] [security2:error] [pid 139043:tid 139290] [client 172.182.200.96:15488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9LgAAAPo"] [Tue Aug 18 13:04:07.738099 2026] [security2:error] [pid 139043:tid 139267] [client 74.249.206.207:7902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/indes.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9MgAAAOM"] [Tue Aug 18 13:04:07.745069 2026] [authz_core:error] [pid 139043:tid 139111] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:07.745347 2026] [authz_core:error] [pid 139043:tid 139111] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:07.746247 2026] [security2:error] [pid 139043:tid 139247] [client 4.223.113.180:45297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/bolt.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9NAAAAM8"] [Tue Aug 18 13:04:07.766593 2026] [security2:error] [pid 139043:tid 139198] [client 52.139.47.57:10967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/css.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9NQAAAJ4"] [Tue Aug 18 13:04:07.784802 2026] [security2:error] [pid 139043:tid 139206] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/images/images/about.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9OgAAAKY"] [Tue Aug 18 13:04:07.788547 2026] [security2:error] [pid 139043:tid 139236] [client 20.124.247.79:14294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/file1221.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9QgAAAMQ"] [Tue Aug 18 13:04:07.799593 2026] [security2:error] [pid 139043:tid 139254] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9QwAAANY"] [Tue Aug 18 13:04:07.816768 2026] [security2:error] [pid 139043:tid 139242] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/as.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9RgAAAMo"] [Tue Aug 18 13:04:07.841079 2026] [security2:error] [pid 139043:tid 139211] [client 20.163.43.14:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/an.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9RwAAAKs"] [Tue Aug 18 13:04:07.876243 2026] [security2:error] [pid 139043:tid 139281] [client 20.52.168.85:5161] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "valeriana.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9SAAAAPE"] [Tue Aug 18 13:04:07.876353 2026] [security2:error] [pid 139043:tid 139281] [client 20.52.168.85:5161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9SAAAAPE"] [Tue Aug 18 13:04:07.894240 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:17180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/nw.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9SQAAAPQ"] [Tue Aug 18 13:04:07.907156 2026] [security2:error] [pid 139043:tid 139217] [client 20.80.111.3:26045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/pwnd/gecko.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9SwAAALE"] [Tue Aug 18 13:04:07.923873 2026] [security2:error] [pid 139043:tid 139229] [client 20.51.153.15:8775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/sm.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9TQAAAL0"] [Tue Aug 18 13:04:07.931707 2026] [security2:error] [pid 139043:tid 139285] [client 68.155.156.252:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/aa.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9TgAAAPU"] [Tue Aug 18 13:04:07.938489 2026] [authz_core:error] [pid 139043:tid 139116] [remote 34.158.8.33:49538] AH01630: client denied by server configuration: /home4/acessoso/public_html/.htpasswd [Tue Aug 18 13:04:07.990036 2026] [security2:error] [pid 139043:tid 139288] [client 20.1.169.243:11234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/dex.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9UwAAAPg"] [Tue Aug 18 13:04:07.997150 2026] [security2:error] [pid 139043:tid 139201] [client 172.182.217.32:21807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/ini.php"] [unique_id "aoSCd_2v-lWn9OzQT7U9VAAAAKE"] [Tue Aug 18 13:04:08.005066 2026] [security2:error] [pid 139043:tid 139245] [client 132.196.30.78:8410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9VgAAAM0"] [Tue Aug 18 13:04:08.012625 2026] [security2:error] [pid 139043:tid 139241] [client 172.182.200.96:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9WAAAAMk"] [Tue Aug 18 13:04:08.048305 2026] [authz_core:error] [pid 139043:tid 139098] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:08.048578 2026] [authz_core:error] [pid 139043:tid 139098] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:08.063090 2026] [security2:error] [pid 139043:tid 139251] [client 20.124.247.79:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/nox.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9WwAAANM"] [Tue Aug 18 13:04:08.074528 2026] [security2:error] [pid 139043:tid 139280] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9XQAAAPA"] [Tue Aug 18 13:04:08.076714 2026] [security2:error] [pid 139043:tid 139182] [client 20.151.109.219:58363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pd.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9XgAAAI4"] [Tue Aug 18 13:04:08.085306 2026] [security2:error] [pid 139043:tid 139174] [client 20.171.51.14:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/74.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9XwAAAIY"] [Tue Aug 18 13:04:08.103996 2026] [security2:error] [pid 139043:tid 139173] [client 4.232.151.198:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/120f9.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9YQAAAIU"] [Tue Aug 18 13:04:08.112484 2026] [security2:error] [pid 139043:tid 139195] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9YgAAAJs"] [Tue Aug 18 13:04:08.123856 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:24040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/black.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ZAAAAO0"] [Tue Aug 18 13:04:08.139048 2026] [security2:error] [pid 139043:tid 139252] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ZgAAANQ"] [Tue Aug 18 13:04:08.148246 2026] [security2:error] [pid 139043:tid 139266] [client 86.120.159.145:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ZwAAAOI"] [Tue Aug 18 13:04:08.148595 2026] [security2:error] [pid 139043:tid 139266] [client 86.120.159.145:61125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ZwAAAOI"] [Tue Aug 18 13:04:08.158026 2026] [security2:error] [pid 139043:tid 139214] [client 68.155.154.236:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9aAAAAK4"] [Tue Aug 18 13:04:08.158199 2026] [security2:error] [pid 139043:tid 139278] [client 74.248.130.103:35003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/edit.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9aQAAAO4"] [Tue Aug 18 13:04:08.159912 2026] [security2:error] [pid 139043:tid 139227] [client 74.249.206.207:42251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/tTPcH.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9agAAALs"] [Tue Aug 18 13:04:08.193214 2026] [security2:error] [pid 139043:tid 139224] [client 52.139.47.57:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/chosen.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9bAAAALg"] [Tue Aug 18 13:04:08.215133 2026] [security2:error] [pid 139043:tid 139200] [client 213.35.127.232:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9bQAAAKA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:08.224230 2026] [security2:error] [pid 139043:tid 139216] [client 158.23.17.4:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ag.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9bgAAALA"] [Tue Aug 18 13:04:08.235214 2026] [security2:error] [pid 139043:tid 139233] [client 20.116.17.175:54894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/xyn.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9bwAAAME"] [Tue Aug 18 13:04:08.237179 2026] [security2:error] [pid 139043:tid 139205] [client 20.51.153.15:9196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/jl.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9cAAAAKU"] [Tue Aug 18 13:04:08.246992 2026] [security2:error] [pid 139043:tid 139279] [client 168.62.48.100:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9cgAAAO8"] [Tue Aug 18 13:04:08.339064 2026] [security2:error] [pid 139043:tid 139212] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9dQAAAKw"] [Tue Aug 18 13:04:08.340919 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.200.96:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9dgAAAMQ"] [Tue Aug 18 13:04:08.353391 2026] [security2:error] [pid 139043:tid 139239] [client 20.1.169.243:11091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/df.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9eAAAAMc"] [Tue Aug 18 13:04:08.390188 2026] [security2:error] [pid 139043:tid 139298] [client 20.124.247.79:16840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/akismet.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ewAAAQI"] [Tue Aug 18 13:04:08.436201 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ggAAALE"] [Tue Aug 18 13:04:08.462172 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/404.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9hQAAAOo"] [Tue Aug 18 13:04:08.482564 2026] [security2:error] [pid 139043:tid 139206] [client 172.182.217.32:21790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/shell.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9iwAAAKY"] [Tue Aug 18 13:04:08.499888 2026] [security2:error] [pid 139043:tid 139286] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/rip.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9jQAAAPY"] [Tue Aug 18 13:04:08.500969 2026] [autoindex:error] [pid 139043:tid 139219] [client 20.52.168.85:5260] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/images/crystal/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:08.502288 2026] [security2:error] [pid 139043:tid 139272] [client 74.249.206.207:19869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/bs1.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9jgAAAOg"] [Tue Aug 18 13:04:08.532436 2026] [security2:error] [pid 139043:tid 139102] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCeP2v-lWn9OzQT7U9jwAAoTo"] [Tue Aug 18 13:04:08.538108 2026] [security2:error] [pid 139043:tid 139269] [client 20.51.153.15:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/tq.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9kAAAAOU"] [Tue Aug 18 13:04:08.540228 2026] [security2:error] [pid 139043:tid 139264] [client 20.250.13.23:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9kQAAAOA"] [Tue Aug 18 13:04:08.543307 2026] [security2:error] [pid 139043:tid 139259] [client 20.80.111.3:17233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/plugins/wp-help/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9kgAAANs"] [Tue Aug 18 13:04:08.549573 2026] [security2:error] [pid 139043:tid 139273] [client 102.213.179.104:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9lAAAAOk"] [Tue Aug 18 13:04:08.549713 2026] [security2:error] [pid 139043:tid 139273] [client 102.213.179.104:59768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9lAAAAOk"] [Tue Aug 18 13:04:08.559430 2026] [security2:error] [pid 139043:tid 139249] [client 132.196.30.78:18835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/htaccess.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9lgAAANE"] [Tue Aug 18 13:04:08.572565 2026] [security2:error] [pid 139043:tid 139280] [client 68.221.73.131:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/abcd.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9mQAAAPA"] [Tue Aug 18 13:04:08.584075 2026] [security2:error] [pid 139043:tid 139250] [client 20.206.73.37:35283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/bless6.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9mgAAANI"] [Tue Aug 18 13:04:08.613002 2026] [security2:error] [pid 139043:tid 139186] [client 20.48.236.86:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/images.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9mwAAAJI"] [Tue Aug 18 13:04:08.629493 2026] [security2:error] [pid 139043:tid 139257] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9nQAAANk"] [Tue Aug 18 13:04:08.636521 2026] [security2:error] [pid 139043:tid 139184] [client 52.139.47.57:26314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/doc.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9nwAAAJA"] [Tue Aug 18 13:04:08.647424 2026] [authz_core:error] [pid 139043:tid 139046] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:08.647652 2026] [security2:error] [pid 139043:tid 139278] [client 20.104.100.201:23951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/as.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ogAAAO4"] [Tue Aug 18 13:04:08.647673 2026] [authz_core:error] [pid 139043:tid 139046] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:08.648366 2026] [security2:error] [pid 139043:tid 139227] [client 20.226.36.136:57843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9owAAALs"] [Tue Aug 18 13:04:08.649838 2026] [security2:error] [pid 139043:tid 139208] [client 74.248.130.103:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9pAAAAKg"] [Tue Aug 18 13:04:08.658544 2026] [security2:error] [pid 139043:tid 139237] [client 4.223.113.180:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9pgAAAMU"] [Tue Aug 18 13:04:08.663564 2026] [security2:error] [pid 139043:tid 139216] [client 20.206.73.37:16845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/55.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9qAAAALA"] [Tue Aug 18 13:04:08.665427 2026] [security2:error] [pid 139043:tid 139233] [client 20.151.109.219:23534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/su.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9qQAAAME"] [Tue Aug 18 13:04:08.677027 2026] [security2:error] [pid 139043:tid 139234] [client 172.182.200.96:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/rezor.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9qgAAAMI"] [Tue Aug 18 13:04:08.702432 2026] [security2:error] [pid 139043:tid 139267] [client 20.52.168.85:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9qwAAAOM"] [Tue Aug 18 13:04:08.722942 2026] [security2:error] [pid 139043:tid 139292] [client 20.171.51.14:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/av.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9rAAAAPw"] [Tue Aug 18 13:04:08.730639 2026] [security2:error] [pid 139043:tid 139287] [client 20.1.169.243:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/disagrsxr.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9rwAAAPc"] [Tue Aug 18 13:04:08.738929 2026] [security2:error] [pid 139043:tid 139270] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9sAAAAOY"] [Tue Aug 18 13:04:08.752505 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9sQAAAJ4"] [Tue Aug 18 13:04:08.761997 2026] [security2:error] [pid 139043:tid 139300] [client 4.232.151.198:7712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/providers/ultra.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9sgAAAQQ"] [Tue Aug 18 13:04:08.771436 2026] [security2:error] [pid 139043:tid 139246] [client 20.124.247.79:16840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/admin.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9swAAAM4"] [Tue Aug 18 13:04:08.795894 2026] [security2:error] [pid 139043:tid 139276] [client 20.206.73.37:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9twAAAOw"] [Tue Aug 18 13:04:08.800059 2026] [security2:error] [pid 139043:tid 139183] [client 74.249.206.207:42301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/hp2.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9uAAAAI8"] [Tue Aug 18 13:04:08.824182 2026] [security2:error] [pid 139043:tid 139066] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCeP2v-lWn9OzQT7U9uwAA8RY"] [Tue Aug 18 13:04:08.831587 2026] [security2:error] [pid 139043:tid 139284] [client 20.116.17.175:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/index2.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9vAAAAPQ"] [Tue Aug 18 13:04:08.840263 2026] [security2:error] [pid 139043:tid 139190] [client 20.163.43.14:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-login.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9vQAAAJY"] [Tue Aug 18 13:04:08.874958 2026] [security2:error] [pid 139043:tid 139294] [client 20.51.153.15:8741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/cv.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9wAAAAP4"] [Tue Aug 18 13:04:08.891439 2026] [security2:error] [pid 139043:tid 139206] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9wgAAAKY"] [Tue Aug 18 13:04:08.917414 2026] [security2:error] [pid 139043:tid 139273] [client 52.173.121.69:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9xgAAAOk"] [Tue Aug 18 13:04:08.945323 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ig.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9yQAAANE"] [Tue Aug 18 13:04:08.971731 2026] [security2:error] [pid 139043:tid 139298] [client 172.182.217.32:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ygAAAQI"] [Tue Aug 18 13:04:08.981763 2026] [security2:error] [pid 139043:tid 139255] [client 20.80.111.3:17218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "aoSCeP2v-lWn9OzQT7U9ywAAANc"] [Tue Aug 18 13:04:09.019449 2026] [security2:error] [pid 139043:tid 139197] [client 4.232.151.198:11408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/w1.php"] [unique_id "aoSCef2v-lWn9OzQT7U9zgAAAJ0"] [Tue Aug 18 13:04:09.033914 2026] [security2:error] [pid 139043:tid 139263] [client 172.182.200.96:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCef2v-lWn9OzQT7U9zwAAAN8"] [Tue Aug 18 13:04:09.051297 2026] [security2:error] [pid 139043:tid 139269] [client 52.139.47.57:26347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/elp.php"] [unique_id "aoSCef2v-lWn9OzQT7U90AAAAOU"] [Tue Aug 18 13:04:09.062763 2026] [security2:error] [pid 139043:tid 139258] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCef2v-lWn9OzQT7U90gAAANo"] [Tue Aug 18 13:04:09.065769 2026] [security2:error] [pid 139043:tid 139202] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCef2v-lWn9OzQT7U90wAAAKI"] [Tue Aug 18 13:04:09.094524 2026] [security2:error] [pid 139043:tid 139182] [client 20.1.169.243:11191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/domvf.php"] [unique_id "aoSCef2v-lWn9OzQT7U91QAAAI4"] [Tue Aug 18 13:04:09.095035 2026] [security2:error] [pid 139043:tid 139251] [client 20.171.51.14:58017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ag.php"] [unique_id "aoSCef2v-lWn9OzQT7U91gAAANM"] [Tue Aug 18 13:04:09.144808 2026] [security2:error] [pid 139043:tid 139208] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/biufile.php"] [unique_id "aoSCef2v-lWn9OzQT7U91wAAAKg"] [Tue Aug 18 13:04:09.151888 2026] [security2:error] [pid 139043:tid 139224] [client 20.124.247.79:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paciolli.com.br"] [uri "/ajax.php"] [unique_id "aoSCef2v-lWn9OzQT7U92AAAALg"] [Tue Aug 18 13:04:09.164380 2026] [autoindex:error] [pid 139043:tid 139293] [client 20.250.13.23:6269] AH01276: Cannot serve directory /home2/plakomas/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:09.165971 2026] [security2:error] [pid 139043:tid 139237] [client 74.249.206.207:42283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/yb.php"] [unique_id "aoSCef2v-lWn9OzQT7U92wAAAMU"] [Tue Aug 18 13:04:09.166334 2026] [security2:error] [pid 139043:tid 139216] [client 20.163.43.14:4377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSCef2v-lWn9OzQT7U93AAAALA"] [Tue Aug 18 13:04:09.171576 2026] [security2:error] [pid 139043:tid 139205] [client 20.104.100.201:23985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/pucci.php"] [unique_id "aoSCef2v-lWn9OzQT7U93QAAAKU"] [Tue Aug 18 13:04:09.229493 2026] [security2:error] [pid 139043:tid 139286] [client 213.35.127.232:56629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCef2v-lWn9OzQT7U94wAAAPY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:09.250660 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:09.250931 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:09.293015 2026] [security2:error] [pid 139043:tid 139164] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/id_rsa"] [unique_id "aoSCef2v-lWn9OzQT7U95QABBHg"] [Tue Aug 18 13:04:09.313190 2026] [security2:error] [pid 139043:tid 139296] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCef2v-lWn9OzQT7U96gAAAQA"] [Tue Aug 18 13:04:09.318010 2026] [security2:error] [pid 139043:tid 139223] [client 158.23.17.4:10964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/payout.php"] [unique_id "aoSCef2v-lWn9OzQT7U96wAAALc"] [Tue Aug 18 13:04:09.321487 2026] [autoindex:error] [pid 139043:tid 139178] [client 20.52.168.85:5133] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:09.335598 2026] [security2:error] [pid 139043:tid 139244] [client 132.196.30.78:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/images/wso.php"] [unique_id "aoSCef2v-lWn9OzQT7U97QAAAMw"] [Tue Aug 18 13:04:09.360817 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.200.96:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCef2v-lWn9OzQT7U98AAAAOs"] [Tue Aug 18 13:04:09.364357 2026] [security2:error] [pid 139043:tid 139056] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/id_dsa"] [unique_id "aoSCef2v-lWn9OzQT7U98gAAlgw"] [Tue Aug 18 13:04:09.368127 2026] [security2:error] [pid 139043:tid 139229] [client 20.250.13.23:6269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSCef2v-lWn9OzQT7U98wAAAL0"] [Tue Aug 18 13:04:09.375023 2026] [security2:error] [pid 139043:tid 139226] [client 20.51.153.15:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/un.php"] [unique_id "aoSCef2v-lWn9OzQT7U99AAAALo"] [Tue Aug 18 13:04:09.411553 2026] [security2:error] [pid 139043:tid 139247] [client 4.232.151.198:25217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-edit.php"] [unique_id "aoSCef2v-lWn9OzQT7U99QAAAM8"] [Tue Aug 18 13:04:09.416883 2026] [security2:error] [pid 139043:tid 139213] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/moon.php"] [unique_id "aoSCef2v-lWn9OzQT7U99gAAAK0"] [Tue Aug 18 13:04:09.422132 2026] [security2:error] [pid 139043:tid 139242] [client 20.80.111.3:28219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "aoSCef2v-lWn9OzQT7U99wAAAMo"] [Tue Aug 18 13:04:09.427000 2026] [security2:error] [pid 139043:tid 139206] [client 68.221.73.131:29781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCef2v-lWn9OzQT7U9-AAAAKY"] [Tue Aug 18 13:04:09.456456 2026] [security2:error] [pid 139043:tid 139219] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCef2v-lWn9OzQT7U9-QAAALM"] [Tue Aug 18 13:04:09.460175 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.217.32:21812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-sigunq.php"] [unique_id "aoSCef2v-lWn9OzQT7U9-wAAAMQ"] [Tue Aug 18 13:04:09.462301 2026] [security2:error] [pid 139043:tid 139284] [client 20.1.169.243:11213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/dropdown.php"] [unique_id "aoSCef2v-lWn9OzQT7U9_AAAAPQ"] [Tue Aug 18 13:04:09.463474 2026] [security2:error] [pid 139043:tid 139243] [client 168.62.48.100:12243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCef2v-lWn9OzQT7U9_QAAAMs"] [Tue Aug 18 13:04:09.474656 2026] [security2:error] [pid 139043:tid 139281] [client 52.139.47.57:26338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/Exception-class.php"] [unique_id "aoSCef2v-lWn9OzQT7U9_wAAAPE"] [Tue Aug 18 13:04:09.474957 2026] [security2:error] [pid 139043:tid 139259] [client 20.151.109.219:45871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wp-key.php"] [unique_id "aoSCef2v-lWn9OzQT7U-AAAAANs"] [Tue Aug 18 13:04:09.486307 2026] [security2:error] [pid 139043:tid 139273] [client 74.249.206.207:45512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/vc.php"] [unique_id "aoSCef2v-lWn9OzQT7U-AQAAAOk"] [Tue Aug 18 13:04:09.495258 2026] [security2:error] [pid 139043:tid 139290] [client 185.198.240.223:36417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ancavisi.com.br"] [uri "/wp-login.php"] [unique_id "aoSCef2v-lWn9OzQT7U-AgAAAPo"] [Tue Aug 18 13:04:09.516929 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.156.252:50160] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.transitalian.com.br"] [uri "/1.php"] [unique_id "aoSCef2v-lWn9OzQT7U-BAAAAOQ"] [Tue Aug 18 13:04:09.517021 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.156.252:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/1.php"] [unique_id "aoSCef2v-lWn9OzQT7U-BAAAAOQ"] [Tue Aug 18 13:04:09.522742 2026] [security2:error] [pid 139043:tid 139245] [client 20.52.168.85:5133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/adminer.php"] [unique_id "aoSCef2v-lWn9OzQT7U-BQAAAM0"] [Tue Aug 18 13:04:09.551000 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:09.551251 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:09.563826 2026] [security2:error] [pid 139043:tid 139280] [client 20.171.51.14:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ig.php"] [unique_id "aoSCef2v-lWn9OzQT7U-CAAAAPA"] [Tue Aug 18 13:04:09.593602 2026] [security2:error] [pid 139043:tid 139197] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/an.php"] [unique_id "aoSCef2v-lWn9OzQT7U-CgAAAJ0"] [Tue Aug 18 13:04:09.604093 2026] [security2:error] [pid 139043:tid 139184] [client 20.206.73.37:17019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCef2v-lWn9OzQT7U-DQAAAJA"] [Tue Aug 18 13:04:09.604519 2026] [security2:error] [pid 139043:tid 139202] [client 20.104.100.201:23886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wicked.php"] [unique_id "aoSCef2v-lWn9OzQT7U-DgAAAKI"] [Tue Aug 18 13:04:09.693076 2026] [security2:error] [pid 139043:tid 139261] [client 172.182.200.96:15500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/index/function.php"] [unique_id "aoSCef2v-lWn9OzQT7U-EQAAAN0"] [Tue Aug 18 13:04:09.754404 2026] [autoindex:error] [pid 139043:tid 139279] [client 20.163.43.14:4406] AH01276: Cannot serve directory /home4/copemsac/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:09.770825 2026] [security2:error] [pid 139043:tid 139222] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/cache.php"] [unique_id "aoSCef2v-lWn9OzQT7U-FQAAALY"] [Tue Aug 18 13:04:09.774102 2026] [security2:error] [pid 139043:tid 139292] [client 20.215.241.237:47453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/images.php"] [unique_id "aoSCef2v-lWn9OzQT7U-FgAAAPw"] [Tue Aug 18 13:04:09.804624 2026] [security2:error] [pid 139043:tid 139150] [remote 23.235.197.206:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.197.235.23.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSCef2v-lWn9OzQT7U-FwAA1Wo"] [Tue Aug 18 13:04:09.828611 2026] [security2:error] [pid 139043:tid 139204] [client 74.249.206.207:31075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/pema.php"] [unique_id "aoSCef2v-lWn9OzQT7U-GQAAAKQ"] [Tue Aug 18 13:04:09.829354 2026] [security2:error] [pid 139043:tid 139293] [client 20.1.169.243:11168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSCef2v-lWn9OzQT7U-GgAAAP0"] [Tue Aug 18 13:04:09.836612 2026] [security2:error] [pid 139043:tid 139198] [client 20.51.153.15:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/evil.php"] [unique_id "aoSCef2v-lWn9OzQT7U-GwAAAJ4"] [Tue Aug 18 13:04:09.850101 2026] [security2:error] [pid 139043:tid 139248] [client 68.155.154.236:8357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCef2v-lWn9OzQT7U-HwAAANA"] [Tue Aug 18 13:04:09.851431 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:09.851700 2026] [authz_core:error] [pid 139043:tid 139078] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:09.881028 2026] [security2:error] [pid 139043:tid 139254] [client 20.226.36.136:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCef2v-lWn9OzQT7U-IgAAANY"] [Tue Aug 18 13:04:09.901776 2026] [security2:error] [pid 139043:tid 139267] [client 52.139.47.57:33497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ee.php"] [unique_id "aoSCef2v-lWn9OzQT7U-IwAAAOM"] [Tue Aug 18 13:04:09.911113 2026] [security2:error] [pid 139043:tid 139276] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCef2v-lWn9OzQT7U-JQAAAOw"] [Tue Aug 18 13:04:09.914065 2026] [security2:error] [pid 139043:tid 139223] [client 20.104.100.201:24056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/water.php"] [unique_id "aoSCef2v-lWn9OzQT7U-JwAAALc"] [Tue Aug 18 13:04:09.915155 2026] [security2:error] [pid 139043:tid 139183] [client 20.163.43.14:4406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wso.php"] [unique_id "aoSCef2v-lWn9OzQT7U-KAAAAI8"] [Tue Aug 18 13:04:09.926284 2026] [security2:error] [pid 139043:tid 139287] [client 20.80.111.3:28168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "aoSCef2v-lWn9OzQT7U-KgAAAPc"] [Tue Aug 18 13:04:09.947036 2026] [security2:error] [pid 139043:tid 139200] [client 20.171.51.14:42267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ta.php"] [unique_id "aoSCef2v-lWn9OzQT7U-KwAAAKA"] [Tue Aug 18 13:04:09.960603 2026] [security2:error] [pid 139043:tid 139270] [client 172.182.217.32:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wso112233.php"] [unique_id "aoSCef2v-lWn9OzQT7U-LAAAAOY"] [Tue Aug 18 13:04:09.988817 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:40443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ta.php"] [unique_id "aoSCef2v-lWn9OzQT7U-LQAAALo"] [Tue Aug 18 13:04:10.027153 2026] [security2:error] [pid 139043:tid 139247] [client 68.221.73.131:26400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSCev2v-lWn9OzQT7U-MQAAAM8"] [Tue Aug 18 13:04:10.035500 2026] [security2:error] [pid 139043:tid 139188] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/404.php"] [unique_id "aoSCev2v-lWn9OzQT7U-MgAAAJQ"] [Tue Aug 18 13:04:10.044061 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.200.96:3049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCev2v-lWn9OzQT7U-MwAAAMg"] [Tue Aug 18 13:04:10.054810 2026] [security2:error] [pid 139043:tid 139299] [client 4.232.151.198:25237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/twentytwentyfour/functions.php"] [unique_id "aoSCev2v-lWn9OzQT7U-NAAAAQM"] [Tue Aug 18 13:04:10.063574 2026] [security2:error] [pid 139043:tid 139246] [client 20.250.13.23:6209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSCev2v-lWn9OzQT7U-NQAAAM4"] [Tue Aug 18 13:04:10.090146 2026] [security2:error] [pid 139043:tid 139259] [client 20.116.17.175:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/8.php"] [unique_id "aoSCev2v-lWn9OzQT7U-NwAAANs"] [Tue Aug 18 13:04:10.103049 2026] [security2:error] [pid 139043:tid 139175] [client 20.48.236.86:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/ops.php"] [unique_id "aoSCev2v-lWn9OzQT7U-OQAAAIc"] [Tue Aug 18 13:04:10.132946 2026] [security2:error] [pid 139043:tid 139209] [client 20.52.168.85:5712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-content/themes/alera/alpha.php"] [unique_id "aoSCev2v-lWn9OzQT7U-PAAAAKk"] [Tue Aug 18 13:04:10.141903 2026] [security2:error] [pid 139043:tid 139298] [client 74.249.206.207:7916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/sh.php"] [unique_id "aoSCev2v-lWn9OzQT7U-PQAAAQI"] [Tue Aug 18 13:04:10.181428 2026] [security2:error] [pid 139043:tid 139195] [client 158.23.17.4:16896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/bh.php"] [unique_id "aoSCev2v-lWn9OzQT7U-PwAAAJs"] [Tue Aug 18 13:04:10.198755 2026] [security2:error] [pid 139043:tid 139243] [client 20.1.169.243:11207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/edit.php"] [unique_id "aoSCev2v-lWn9OzQT7U-QgAAAMs"] [Tue Aug 18 13:04:10.232778 2026] [security2:error] [pid 139043:tid 139202] [client 20.151.109.219:27364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gg.php"] [unique_id "aoSCev2v-lWn9OzQT7U-QwAAAKI"] [Tue Aug 18 13:04:10.235467 2026] [security2:error] [pid 139043:tid 139193] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCev2v-lWn9OzQT7U-RAAAAJk"] [Tue Aug 18 13:04:10.245913 2026] [security2:error] [pid 139043:tid 139234] [client 213.35.127.232:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCev2v-lWn9OzQT7U-RQAAAMI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:10.260131 2026] [security2:error] [pid 139043:tid 139167] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/key.pem"] [unique_id "aoSCev2v-lWn9OzQT7U-RgAA03s"] [Tue Aug 18 13:04:10.277450 2026] [security2:error] [pid 139043:tid 139227] [client 20.163.43.14:3049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/sf.php"] [unique_id "aoSCev2v-lWn9OzQT7U-SgAAALs"] [Tue Aug 18 13:04:10.278930 2026] [security2:error] [pid 139043:tid 139068] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/privatekey.key"] [unique_id "aoSCev2v-lWn9OzQT7U-SQAA7hg"] [Tue Aug 18 13:04:10.279289 2026] [security2:error] [pid 139043:tid 139177] [client 20.51.153.15:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pw.php"] [unique_id "aoSCev2v-lWn9OzQT7U-SwAAAIk"] [Tue Aug 18 13:04:10.330139 2026] [security2:error] [pid 139043:tid 139181] [client 132.196.30.78:4969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/index/function.php"] [unique_id "aoSCev2v-lWn9OzQT7U-UAAAAI0"] [Tue Aug 18 13:04:10.330522 2026] [security2:error] [pid 139043:tid 139233] [client 20.104.100.201:23925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/fine.php"] [unique_id "aoSCev2v-lWn9OzQT7U-UQAAAME"] [Tue Aug 18 13:04:10.331590 2026] [security2:error] [pid 139043:tid 139186] [client 52.139.47.57:35894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/edit.php"] [unique_id "aoSCev2v-lWn9OzQT7U-UwAAAJI"] [Tue Aug 18 13:04:10.362613 2026] [security2:error] [pid 139043:tid 139269] [client 20.80.111.3:40658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/414.php"] [unique_id "aoSCev2v-lWn9OzQT7U-VAAAAOU"] [Tue Aug 18 13:04:10.382002 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.200.96:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/Cachex.php"] [unique_id "aoSCev2v-lWn9OzQT7U-VgAAALY"] [Tue Aug 18 13:04:10.415831 2026] [security2:error] [pid 139043:tid 139198] [client 20.171.51.14:47137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/34.php"] [unique_id "aoSCev2v-lWn9OzQT7U-WAAAAJ4"] [Tue Aug 18 13:04:10.440337 2026] [security2:error] [pid 139043:tid 139212] [client 20.151.109.219:22940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/th.php"] [unique_id "aoSCev2v-lWn9OzQT7U-WQAAAKw"] [Tue Aug 18 13:04:10.452766 2026] [authz_core:error] [pid 139043:tid 139142] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:10.453001 2026] [security2:error] [pid 139043:tid 139289] [client 172.182.217.32:21828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/fw.php"] [unique_id "aoSCev2v-lWn9OzQT7U-WwAAAPk"] [Tue Aug 18 13:04:10.453023 2026] [authz_core:error] [pid 139043:tid 139142] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:10.462107 2026] [security2:error] [pid 139043:tid 139296] [client 74.249.206.207:42285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/button.php"] [unique_id "aoSCev2v-lWn9OzQT7U-XAAAAQA"] [Tue Aug 18 13:04:10.480543 2026] [security2:error] [pid 139043:tid 139178] [client 20.206.73.37:21059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/ajax.php"] [unique_id "aoSCev2v-lWn9OzQT7U-XwAAAIo"] [Tue Aug 18 13:04:10.498939 2026] [security2:error] [pid 139043:tid 139263] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-login.php"] [unique_id "aoSCev2v-lWn9OzQT7U-TQAAAN8"] [Tue Aug 18 13:04:10.553806 2026] [security2:error] [pid 139043:tid 139247] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCev2v-lWn9OzQT7U-ZAAAAM8"] [Tue Aug 18 13:04:10.566168 2026] [security2:error] [pid 139043:tid 139254] [client 20.1.169.243:11206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/elp.php"] [unique_id "aoSCev2v-lWn9OzQT7U-ZgAAANY"] [Tue Aug 18 13:04:10.579576 2026] [security2:error] [pid 139043:tid 139180] [client 74.248.130.103:7902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/inputs.php"] [unique_id "aoSCev2v-lWn9OzQT7U-ZwAAAIw"] [Tue Aug 18 13:04:10.583777 2026] [security2:error] [pid 139043:tid 139240] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/coffexium.php"] [unique_id "aoSCev2v-lWn9OzQT7U-aAAAAMg"] [Tue Aug 18 13:04:10.661739 2026] [security2:error] [pid 139043:tid 139259] [client 20.163.43.14:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/index/function.php"] [unique_id "aoSCev2v-lWn9OzQT7U-bAAAANs"] [Tue Aug 18 13:04:10.678884 2026] [security2:error] [pid 139043:tid 139273] [client 68.155.154.236:9160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCev2v-lWn9OzQT7U-bgAAAOk"] [Tue Aug 18 13:04:10.688540 2026] [security2:error] [pid 139043:tid 139241] [client 68.155.156.252:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/img.php"] [unique_id "aoSCev2v-lWn9OzQT7U-bwAAAMk"] [Tue Aug 18 13:04:10.692018 2026] [security2:error] [pid 139043:tid 139200] [client 20.250.13.23:16543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/f7.php"] [unique_id "aoSCev2v-lWn9OzQT7U-cAAAAKA"] [Tue Aug 18 13:04:10.707048 2026] [security2:error] [pid 139043:tid 139203] [client 172.182.200.96:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCev2v-lWn9OzQT7U-cgAAAKM"] [Tue Aug 18 13:04:10.723389 2026] [security2:error] [pid 139043:tid 139235] [client 20.51.153.15:9123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fn.php"] [unique_id "aoSCev2v-lWn9OzQT7U-dQAAAMM"] [Tue Aug 18 13:04:10.739834 2026] [security2:error] [pid 139043:tid 139280] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCev2v-lWn9OzQT7U-dwAAAPA"] [Tue Aug 18 13:04:10.744909 2026] [security2:error] [pid 139043:tid 139283] [client 4.232.151.198:25226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-oembed.php"] [unique_id "aoSCev2v-lWn9OzQT7U-eQAAAPM"] [Tue Aug 18 13:04:10.749041 2026] [security2:error] [pid 139043:tid 139272] [client 52.139.47.57:33499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/f35.php"] [unique_id "aoSCev2v-lWn9OzQT7U-fgAAAOg"] [Tue Aug 18 13:04:10.753927 2026] [security2:error] [pid 139043:tid 139173] [client 74.249.206.207:45523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/wlc.php"] [unique_id "aoSCev2v-lWn9OzQT7U-gAAAAIU"] [Tue Aug 18 13:04:10.755447 2026] [authz_core:error] [pid 139043:tid 139079] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:10.755913 2026] [authz_core:error] [pid 139043:tid 139079] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:10.759335 2026] [autoindex:error] [pid 139043:tid 139199] [client 20.52.168.85:5164] AH01276: Cannot serve directory /home2/valeriana/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:10.763927 2026] [security2:error] [pid 139043:tid 139195] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSCev2v-lWn9OzQT7U-gQAAAJs"] [Tue Aug 18 13:04:10.769570 2026] [security2:error] [pid 139043:tid 139243] [client 20.171.51.14:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/he.php"] [unique_id "aoSCev2v-lWn9OzQT7U-gwAAAMs"] [Tue Aug 18 13:04:10.781673 2026] [security2:error] [pid 139043:tid 139250] [client 20.104.100.201:24000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/loader.php"] [unique_id "aoSCev2v-lWn9OzQT7U-hAAAANI"] [Tue Aug 18 13:04:10.793468 2026] [security2:error] [pid 139043:tid 139281] [client 20.80.111.3:28188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/gbaun.php"] [unique_id "aoSCev2v-lWn9OzQT7U-hQAAAPE"] [Tue Aug 18 13:04:10.822008 2026] [security2:error] [pid 139043:tid 139184] [client 68.221.73.131:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSCev2v-lWn9OzQT7U-hwAAAJA"] [Tue Aug 18 13:04:10.863748 2026] [security2:error] [pid 139043:tid 139234] [client 132.196.30.78:13529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/info.php"] [unique_id "aoSCev2v-lWn9OzQT7U-igAAAMI"] [Tue Aug 18 13:04:10.921612 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCev2v-lWn9OzQT7U-jQAAAME"] [Tue Aug 18 13:04:10.929368 2026] [security2:error] [pid 139043:tid 139277] [client 20.1.169.243:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/email.php"] [unique_id "aoSCev2v-lWn9OzQT7U-kAAAAO0"] [Tue Aug 18 13:04:10.951209 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.217.32:21382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "aoSCev2v-lWn9OzQT7U-kQAAAJ0"] [Tue Aug 18 13:04:10.953469 2026] [security2:error] [pid 139043:tid 139269] [client 4.232.151.198:44692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-login.php"] [unique_id "aoSCev2v-lWn9OzQT7U-kgAAAOU"] [Tue Aug 18 13:04:10.960669 2026] [security2:error] [pid 139043:tid 139221] [client 20.52.168.85:5164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wso.php"] [unique_id "aoSCev2v-lWn9OzQT7U-kwAAALU"] [Tue Aug 18 13:04:10.985345 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:9159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kf.php"] [unique_id "aoSCev2v-lWn9OzQT7U-lwAAAKQ"] [Tue Aug 18 13:04:10.985819 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/dex.php"] [unique_id "aoSCev2v-lWn9OzQT7U-mAAAAP0"] [Tue Aug 18 13:04:11.005549 2026] [security2:error] [pid 139043:tid 139248] [client 20.163.43.14:4460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/edit.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-mQAAANA"] [Tue Aug 18 13:04:11.056138 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:11.056403 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:11.080311 2026] [authz_core:error] [pid 139043:tid 139130] [remote 57.141.22.32:64324] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:11.080566 2026] [authz_core:error] [pid 139043:tid 139130] [remote 57.141.22.32:64324] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:11.084576 2026] [security2:error] [pid 139043:tid 139185] [client 172.182.200.96:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-ngAAAJE"] [Tue Aug 18 13:04:11.084730 2026] [security2:error] [pid 139043:tid 139223] [client 74.249.206.207:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/fi.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-nwAAALc"] [Tue Aug 18 13:04:11.095470 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.36.136:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-oAAAAIo"] [Tue Aug 18 13:04:11.095530 2026] [security2:error] [pid 139043:tid 139244] [client 74.248.130.103:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/av.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-oQAAAMw"] [Tue Aug 18 13:04:11.131102 2026] [security2:error] [pid 139043:tid 139099] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/phpinfo.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-pwAAujc"] [Tue Aug 18 13:04:11.134029 2026] [security2:error] [pid 139043:tid 139213] [client 20.104.100.201:23964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/zero.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-qAAAAK0"] [Tue Aug 18 13:04:11.182524 2026] [security2:error] [pid 139043:tid 139140] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/info.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-qwABA2A"] [Tue Aug 18 13:04:11.198406 2026] [security2:error] [pid 139043:tid 139296] [client 52.139.47.57:33799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/fff.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-rQAAAQA"] [Tue Aug 18 13:04:11.226647 2026] [security2:error] [pid 139043:tid 139264] [client 20.171.51.14:42242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gz.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-rgAAAOA"] [Tue Aug 18 13:04:11.258650 2026] [security2:error] [pid 139043:tid 139238] [client 213.35.127.232:57041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-sAAAAMY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:11.276051 2026] [security2:error] [pid 139043:tid 139179] [client 191.237.254.161:37156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/wpxml.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-sgAAAIs"] [Tue Aug 18 13:04:11.292375 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:16959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/ct.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-tAAAAPA"] [Tue Aug 18 13:04:11.295389 2026] [security2:error] [pid 139043:tid 139283] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-tQAAAPM"] [Tue Aug 18 13:04:11.300442 2026] [security2:error] [pid 139043:tid 139245] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-sQAAzTM"] [Tue Aug 18 13:04:11.304022 2026] [security2:error] [pid 139043:tid 139252] [client 20.1.169.243:11177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/error.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-twAAANQ"] [Tue Aug 18 13:04:11.304161 2026] [security2:error] [pid 139043:tid 139173] [client 20.51.153.15:8730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/su.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-uAAAAIU"] [Tue Aug 18 13:04:11.313615 2026] [security2:error] [pid 139043:tid 139287] [client 20.80.111.3:26041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/themes.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-uQAAAPc"] [Tue Aug 18 13:04:11.313938 2026] [security2:error] [pid 139043:tid 139285] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-ugAAAPU"] [Tue Aug 18 13:04:11.321428 2026] [security2:error] [pid 139043:tid 139297] [client 20.79.204.6:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/u.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-uwAAAQE"] [Tue Aug 18 13:04:11.330824 2026] [security2:error] [pid 139043:tid 139243] [client 68.155.156.252:32705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/222.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-vgAAAMs"] [Tue Aug 18 13:04:11.357495 2026] [security2:error] [pid 139043:tid 139177] [client 149.34.210.141:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-xAAAAIk"] [Tue Aug 18 13:04:11.357944 2026] [authz_core:error] [pid 139043:tid 139087] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:11.358204 2026] [authz_core:error] [pid 139043:tid 139087] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:11.401475 2026] [security2:error] [pid 139043:tid 139227] [client 20.116.17.175:54269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/images.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-0AAAALs"] [Tue Aug 18 13:04:11.408732 2026] [security2:error] [pid 139043:tid 139236] [client 20.48.236.86:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/coffexium.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-0QAAAMQ"] [Tue Aug 18 13:04:11.409972 2026] [security2:error] [pid 139043:tid 139265] [client 20.250.13.23:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/photo.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-0gAAAOE"] [Tue Aug 18 13:04:11.415970 2026] [security2:error] [pid 139043:tid 139275] [client 4.232.151.198:18504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/allez.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-1AAAAOs"] [Tue Aug 18 13:04:11.422117 2026] [security2:error] [pid 139043:tid 139224] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wso.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-1QAAALg"] [Tue Aug 18 13:04:11.432254 2026] [security2:error] [pid 139043:tid 139233] [client 172.182.200.96:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-1wAAAME"] [Tue Aug 18 13:04:11.440654 2026] [security2:error] [pid 139043:tid 139203] [client 172.182.217.32:21394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/classsmtps.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-2AAAAKM"] [Tue Aug 18 13:04:11.455279 2026] [security2:error] [pid 139043:tid 139216] [client 74.249.206.207:7932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/chris.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-2wAAALA"] [Tue Aug 18 13:04:11.517764 2026] [security2:error] [pid 139043:tid 139293] [client 20.163.43.14:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-3gAAAP0"] [Tue Aug 18 13:04:11.532237 2026] [security2:error] [pid 139043:tid 139248] [client 158.23.17.4:40437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/34.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-3wAAANA"] [Tue Aug 18 13:04:11.549110 2026] [security2:error] [pid 139043:tid 139267] [client 68.155.154.236:8874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-4AAAAOM"] [Tue Aug 18 13:04:11.553807 2026] [security2:error] [pid 139043:tid 139230] [client 74.248.130.103:42009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-4QAAAL4"] [Tue Aug 18 13:04:11.562442 2026] [security2:error] [pid 139043:tid 139184] [client 20.52.168.85:5148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-4wAAAJA"] [Tue Aug 18 13:04:11.585881 2026] [security2:error] [pid 139043:tid 139276] [client 20.104.100.201:23966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/002.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-5AAAAOw"] [Tue Aug 18 13:04:11.597903 2026] [security2:error] [pid 139043:tid 139270] [client 20.206.73.37:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/special.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-5gAAAOY"] [Tue Aug 18 13:04:11.606538 2026] [security2:error] [pid 139043:tid 139210] [client 74.7.230.53:49620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "novosite.rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSCev2v-lWn9OzQT7U-ewAAAKo"] [Tue Aug 18 13:04:11.611494 2026] [security2:error] [pid 139043:tid 139197] [client 52.139.47.57:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ff1.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-5wAAAJ0"] [Tue Aug 18 13:04:11.612816 2026] [security2:error] [pid 139043:tid 139197] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-6AAAAJ0"] [Tue Aug 18 13:04:11.614165 2026] [security2:error] [pid 139043:tid 139247] [client 20.171.51.14:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nf.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-6QAAAM8"] [Tue Aug 18 13:04:11.624221 2026] [security2:error] [pid 139043:tid 139177] [client 149.34.210.141:52220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-xAAAAIk"] [Tue Aug 18 13:04:11.648243 2026] [security2:error] [pid 139043:tid 139159] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/i.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-6wAApnM"] [Tue Aug 18 13:04:11.656092 2026] [security2:error] [pid 139043:tid 139240] [client 20.215.241.237:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/ops.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-7gAAAMg"] [Tue Aug 18 13:04:11.658372 2026] [authz_core:error] [pid 139043:tid 139067] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:11.658634 2026] [authz_core:error] [pid 139043:tid 139067] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:11.658987 2026] [security2:error] [pid 139043:tid 139242] [client 68.221.73.131:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/simple.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-7wAAAMo"] [Tue Aug 18 13:04:11.670977 2026] [security2:error] [pid 139043:tid 139289] [client 20.1.169.243:10910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/f35.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-8AAAAPk"] [Tue Aug 18 13:04:11.674344 2026] [security2:error] [pid 139043:tid 139246] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/o.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-8QAAAM4"] [Tue Aug 18 13:04:11.682486 2026] [security2:error] [pid 139043:tid 139296] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/sf.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-8wAAAQA"] [Tue Aug 18 13:04:11.695339 2026] [security2:error] [pid 139043:tid 139110] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/pi.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-9AAAj0I"] [Tue Aug 18 13:04:11.703783 2026] [security2:error] [pid 139043:tid 139080] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/test.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-9QAA4CQ"] [Tue Aug 18 13:04:11.716951 2026] [security2:error] [pid 139043:tid 139241] [client 132.196.30.78:13537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/profile.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-9wAAAMk"] [Tue Aug 18 13:04:11.730447 2026] [security2:error] [pid 139043:tid 139209] [client 20.226.36.136:43705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCe_2v-lWn9OzQT7U--AAAAKk"] [Tue Aug 18 13:04:11.734543 2026] [security2:error] [pid 139043:tid 139298] [client 20.151.109.219:38655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/admin404.php"] [unique_id "aoSCe_2v-lWn9OzQT7U--gAAAQI"] [Tue Aug 18 13:04:11.760768 2026] [security2:error] [pid 139043:tid 139252] [client 172.182.200.96:15502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-_AAAANQ"] [Tue Aug 18 13:04:11.764424 2026] [security2:error] [pid 139043:tid 139262] [client 52.173.121.69:43413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-_QAAAN4"] [Tue Aug 18 13:04:11.771152 2026] [security2:error] [pid 139043:tid 139188] [client 20.80.111.3:26007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/wpr-addons/forms/RxRzhwix.php"] [unique_id "aoSCe_2v-lWn9OzQT7U-_gAAAJQ"] [Tue Aug 18 13:04:11.836087 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:56002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gi.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_AAAAANU"] [Tue Aug 18 13:04:11.857069 2026] [security2:error] [pid 139043:tid 139195] [client 68.155.156.252:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/key.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_AgAAAJs"] [Tue Aug 18 13:04:11.861758 2026] [security2:error] [pid 139043:tid 139294] [client 20.163.43.14:4391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-good.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_AwAAAP4"] [Tue Aug 18 13:04:11.875938 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:8786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wp-key.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_BQAAANM"] [Tue Aug 18 13:04:11.876590 2026] [security2:error] [pid 139043:tid 139291] [client 68.155.153.139:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.reinertimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_BgAAAPs"] [Tue Aug 18 13:04:11.876646 2026] [security2:error] [pid 139043:tid 139291] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/1.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_BgAAAPs"] [Tue Aug 18 13:04:11.883544 2026] [security2:error] [pid 139043:tid 139214] [client 74.249.206.207:7873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/doc.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_BwAAAK4"] [Tue Aug 18 13:04:11.912932 2026] [security2:error] [pid 139043:tid 139058] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCe_2v-lWn9OzQT7U_CgAAuA4"] [Tue Aug 18 13:04:11.927099 2026] [security2:error] [pid 139043:tid 139216] [client 20.104.100.201:24024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/zxz.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_DAAAALA"] [Tue Aug 18 13:04:11.938024 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.217.32:21796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_DwAAAPc"] [Tue Aug 18 13:04:11.951058 2026] [security2:error] [pid 139043:tid 139221] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_EQAAALU"] [Tue Aug 18 13:04:11.951662 2026] [security2:error] [pid 139043:tid 139219] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/index/function.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_EgAAALM"] [Tue Aug 18 13:04:11.961116 2026] [security2:error] [pid 139043:tid 139211] [client 20.171.51.14:38779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xv.php"] [unique_id "aoSCe_2v-lWn9OzQT7U_EwAAAKs"] [Tue Aug 18 13:04:12.023151 2026] [security2:error] [pid 139043:tid 139227] [client 52.139.47.57:15862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/flower.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_FwAAALs"] [Tue Aug 18 13:04:12.024608 2026] [security2:error] [pid 139043:tid 139194] [client 168.62.48.100:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_GAAAAJo"] [Tue Aug 18 13:04:12.027382 2026] [security2:error] [pid 139043:tid 139239] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/bb.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_GgAAAMc"] [Tue Aug 18 13:04:12.041981 2026] [security2:error] [pid 139043:tid 139277] [client 20.1.169.243:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/f35.update.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_GwAAAO0"] [Tue Aug 18 13:04:12.044615 2026] [security2:error] [pid 139043:tid 139281] [client 20.250.13.23:6242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-aa.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_HAAAAPE"] [Tue Aug 18 13:04:12.055559 2026] [security2:error] [pid 139043:tid 139250] [client 4.232.151.198:7706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/colors/coffee/mailer.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_HQAAANI"] [Tue Aug 18 13:04:12.071965 2026] [security2:error] [pid 139043:tid 139229] [client 74.248.130.103:49012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_HwAAAL0"] [Tue Aug 18 13:04:12.076806 2026] [security2:error] [pid 139043:tid 139210] [client 158.23.17.4:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/gy.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_IAAAAKo"] [Tue Aug 18 13:04:12.077389 2026] [security2:error] [pid 139043:tid 139178] [client 20.186.30.159:10058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_IQAAAIo"] [Tue Aug 18 13:04:12.119594 2026] [security2:error] [pid 139043:tid 139088] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/app_dev.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_JAAA2Sw"] [Tue Aug 18 13:04:12.141679 2026] [security2:error] [pid 139043:tid 139240] [client 20.48.236.86:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_JgAAAMg"] [Tue Aug 18 13:04:12.156688 2026] [security2:error] [pid 139043:tid 139289] [client 172.182.200.96:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_JwAAAPk"] [Tue Aug 18 13:04:12.161861 2026] [security2:error] [pid 139043:tid 139204] [client 20.52.168.85:5697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/mah.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_KAAAAKQ"] [Tue Aug 18 13:04:12.183931 2026] [authz_core:error] [pid 139043:tid 139056] [remote 57.141.22.100:26486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:12.184204 2026] [authz_core:error] [pid 139043:tid 139056] [remote 57.141.22.100:26486] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:12.196208 2026] [security2:error] [pid 139043:tid 139133] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSCfP2v-lWn9OzQT7U_LQAAr1k"] [Tue Aug 18 13:04:12.206238 2026] [security2:error] [pid 139043:tid 139244] [client 20.80.111.3:28204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-content/uploads/wpr-addons/forms/b1ack.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_LwAAAMw"] [Tue Aug 18 13:04:12.210554 2026] [security2:error] [pid 139043:tid 139209] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/edit.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_MQAAAKk"] [Tue Aug 18 13:04:12.216884 2026] [security2:error] [pid 139043:tid 139235] [client 74.249.206.207:42255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/1337.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_MgAAAMM"] [Tue Aug 18 13:04:12.229336 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:9107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/gg.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_NAAAAPA"] [Tue Aug 18 13:04:12.239864 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:10591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pz.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_NQAAAPM"] [Tue Aug 18 13:04:12.259169 2026] [authz_core:error] [pid 139043:tid 139120] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:12.259451 2026] [authz_core:error] [pid 139043:tid 139120] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:12.274192 2026] [security2:error] [pid 139043:tid 139269] [client 213.35.127.232:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_OAAAAOU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:12.275456 2026] [security2:error] [pid 139043:tid 139288] [client 20.104.100.201:24019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/memberfuns.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_OQAAAPg"] [Tue Aug 18 13:04:12.292832 2026] [security2:error] [pid 139043:tid 139259] [client 158.23.17.4:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/he.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_OgAAANs"] [Tue Aug 18 13:04:12.312432 2026] [security2:error] [pid 139043:tid 139195] [client 68.155.154.236:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_PAAAAJs"] [Tue Aug 18 13:04:12.318623 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/coffee.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_PQAAAMI"] [Tue Aug 18 13:04:12.326833 2026] [security2:error] [pid 139043:tid 139251] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_PgAAANM"] [Tue Aug 18 13:04:12.364598 2026] [security2:error] [pid 139043:tid 139233] [client 132.196.30.78:15339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/sx.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_QwAAAME"] [Tue Aug 18 13:04:12.380709 2026] [security2:error] [pid 139043:tid 139186] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_RQAAAJI"] [Tue Aug 18 13:04:12.387423 2026] [security2:error] [pid 139043:tid 139212] [client 20.171.51.14:38734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mx.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_RgAAAKw"] [Tue Aug 18 13:04:12.397967 2026] [security2:error] [pid 139043:tid 139143] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/core/.env"] [unique_id "aoSCfP2v-lWn9OzQT7U_SwAA2GM"] [Tue Aug 18 13:04:12.406346 2026] [security2:error] [pid 139043:tid 139255] [client 157.20.138.62:57246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_TgAAANc"] [Tue Aug 18 13:04:12.406450 2026] [security2:error] [pid 139043:tid 139255] [client 157.20.138.62:57246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_TgAAANc"] [Tue Aug 18 13:04:12.424754 2026] [security2:error] [pid 139043:tid 139243] [client 20.1.169.243:10896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/file.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_UAAAAMs"] [Tue Aug 18 13:04:12.425625 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.217.32:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_UQAAAJQ"] [Tue Aug 18 13:04:12.436609 2026] [security2:error] [pid 139043:tid 139217] [client 52.139.47.57:15632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/file.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_UgAAALE"] [Tue Aug 18 13:04:12.445429 2026] [security2:error] [pid 139043:tid 139065] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCfP2v-lWn9OzQT7U_UwAA0BU"] [Tue Aug 18 13:04:12.450587 2026] [security2:error] [pid 139043:tid 139194] [client 20.186.30.159:10080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_VQAAAJo"] [Tue Aug 18 13:04:12.503540 2026] [security2:error] [pid 139043:tid 139218] [client 172.182.200.96:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_WQAAALI"] [Tue Aug 18 13:04:12.552514 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/tes.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_YQAAAKE"] [Tue Aug 18 13:04:12.559153 2026] [authz_core:error] [pid 139043:tid 139050] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:12.559404 2026] [authz_core:error] [pid 139043:tid 139050] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:12.580048 2026] [security2:error] [pid 139043:tid 139112] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/config.php.bak"] [unique_id "aoSCfP2v-lWn9OzQT7U_agAApUQ"] [Tue Aug 18 13:04:12.596486 2026] [security2:error] [pid 139043:tid 139183] [client 74.249.206.207:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/Njima.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_awAAAI8"] [Tue Aug 18 13:04:12.602654 2026] [security2:error] [pid 139043:tid 139147] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCfP2v-lWn9OzQT7U_bQAA4Gc"] [Tue Aug 18 13:04:12.611712 2026] [security2:error] [pid 139043:tid 139241] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_bgAAAMk"] [Tue Aug 18 13:04:12.622060 2026] [security2:error] [pid 139043:tid 139179] [client 68.221.73.131:26649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/chosen.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_bwAAAIs"] [Tue Aug 18 13:04:12.652117 2026] [security2:error] [pid 139043:tid 139228] [client 20.80.111.3:26037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_cgAAALw"] [Tue Aug 18 13:04:12.666843 2026] [security2:error] [pid 139043:tid 139269] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_dgAAAOU"] [Tue Aug 18 13:04:12.708191 2026] [security2:error] [pid 139043:tid 139258] [client 20.116.17.175:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/a.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_egAAANo"] [Tue Aug 18 13:04:12.733264 2026] [security2:error] [pid 139043:tid 139182] [client 20.206.73.37:2155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/yj09.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_fAAAAI4"] [Tue Aug 18 13:04:12.733806 2026] [security2:error] [pid 139043:tid 139234] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_fQAAAMI"] [Tue Aug 18 13:04:12.734655 2026] [security2:error] [pid 139043:tid 139251] [client 20.51.153.15:9135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pz.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_fgAAANM"] [Tue Aug 18 13:04:12.736684 2026] [security2:error] [pid 139043:tid 139291] [client 20.186.30.159:5120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_fwAAAPs"] [Tue Aug 18 13:04:12.746119 2026] [security2:error] [pid 139043:tid 139200] [client 138.36.100.162:42484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_gAAAAKA"] [Tue Aug 18 13:04:12.746211 2026] [security2:error] [pid 139043:tid 139200] [client 138.36.100.162:42484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_gAAAAKA"] [Tue Aug 18 13:04:12.758087 2026] [security2:error] [pid 139043:tid 139226] [client 20.250.13.23:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/d.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_ggAAALo"] [Tue Aug 18 13:04:12.765976 2026] [security2:error] [pid 139043:tid 139206] [client 20.52.168.85:5272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/about.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_gwAAAKY"] [Tue Aug 18 13:04:12.773495 2026] [security2:error] [pid 139043:tid 139224] [client 20.171.51.14:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/45.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_hAAAALg"] [Tue Aug 18 13:04:12.774030 2026] [security2:error] [pid 139043:tid 139213] [client 4.232.151.198:18537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/teslav.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_hQAAAK0"] [Tue Aug 18 13:04:12.782217 2026] [security2:error] [pid 139043:tid 139165] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acessosonori.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCfP2v-lWn9OzQT7U_hgAA6Xk"] [Tue Aug 18 13:04:12.793345 2026] [security2:error] [pid 139043:tid 139297] [client 20.1.169.243:10880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/file2.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_hwAAAQE"] [Tue Aug 18 13:04:12.794520 2026] [security2:error] [pid 139043:tid 139127] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "acessosonori.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCfP2v-lWn9OzQT7U_iAAAo1M"] [Tue Aug 18 13:04:12.808222 2026] [security2:error] [pid 139043:tid 139044] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/.env.swp"] [unique_id "aoSCfP2v-lWn9OzQT7U_igAA5AA"] [Tue Aug 18 13:04:12.819461 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:24043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/aa.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_iwAAAO8"] [Tue Aug 18 13:04:12.826910 2026] [security2:error] [pid 139043:tid 139255] [client 168.62.48.100:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_jAAAANc"] [Tue Aug 18 13:04:12.830756 2026] [security2:error] [pid 139043:tid 139211] [client 172.182.200.96:3038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_jQAAAKs"] [Tue Aug 18 13:04:12.858790 2026] [security2:error] [pid 139043:tid 139193] [client 52.139.47.57:10971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/goods.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_kQAAAJk"] [Tue Aug 18 13:04:12.860783 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:12.861058 2026] [authz_core:error] [pid 139043:tid 139109] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:12.873946 2026] [security2:error] [pid 139043:tid 139115] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/public/.env"] [unique_id "aoSCfP2v-lWn9OzQT7U_kgAAu0c"] [Tue Aug 18 13:04:12.894136 2026] [security2:error] [pid 139043:tid 139232] [client 178.153.171.161:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_lAAAAMA"] [Tue Aug 18 13:04:12.894334 2026] [security2:error] [pid 139043:tid 139232] [client 178.153.171.161:61284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_lAAAAMA"] [Tue Aug 18 13:04:12.904215 2026] [security2:error] [pid 139043:tid 139225] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-good.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_lgAAALk"] [Tue Aug 18 13:04:12.915157 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.217.32:21426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-cron.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_lwAAAMQ"] [Tue Aug 18 13:04:12.938583 2026] [security2:error] [pid 139043:tid 139281] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_mQAAAPE"] [Tue Aug 18 13:04:12.946212 2026] [security2:error] [pid 139043:tid 139300] [client 20.163.43.14:3044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/files/index.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_mgAAAQQ"] [Tue Aug 18 13:04:12.978282 2026] [security2:error] [pid 139043:tid 139278] [client 20.151.109.219:10610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kk.php"] [unique_id "aoSCfP2v-lWn9OzQT7U_nAAAAO4"] [Tue Aug 18 13:04:13.010422 2026] [security2:error] [pid 139043:tid 139246] [client 158.23.17.4:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/tt.php"] [unique_id "aoSCff2v-lWn9OzQT7U_nwAAAM4"] [Tue Aug 18 13:04:13.010736 2026] [security2:error] [pid 139043:tid 139142] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/config/.env.php"] [unique_id "aoSCff2v-lWn9OzQT7U_oAAApGI"] [Tue Aug 18 13:04:13.048132 2026] [security2:error] [pid 139043:tid 139190] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCff2v-lWn9OzQT7U_ogAAAJY"] [Tue Aug 18 13:04:13.075137 2026] [security2:error] [pid 139043:tid 139266] [client 68.155.156.252:32710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/chosen.php"] [unique_id "aoSCff2v-lWn9OzQT7U_pAAAAOI"] [Tue Aug 18 13:04:13.083729 2026] [security2:error] [pid 139043:tid 139151] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acessosonori.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCff2v-lWn9OzQT7U_pQAAqWs"] [Tue Aug 18 13:04:13.096366 2026] [security2:error] [pid 139043:tid 139140] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/laravel/.env"] [unique_id "aoSCff2v-lWn9OzQT7U_qAAA-mA"] [Tue Aug 18 13:04:13.097027 2026] [security2:error] [pid 139043:tid 139148] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/web/.env"] [unique_id "aoSCff2v-lWn9OzQT7U_pwAA-mg"] [Tue Aug 18 13:04:13.098539 2026] [security2:error] [pid 139043:tid 139270] [client 20.80.111.3:30827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCff2v-lWn9OzQT7U_qgAAAOY"] [Tue Aug 18 13:04:13.139859 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:8817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kk.php"] [unique_id "aoSCff2v-lWn9OzQT7U_tQAAAPg"] [Tue Aug 18 13:04:13.142443 2026] [security2:error] [pid 139043:tid 139251] [client 20.186.30.159:10092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/av.php"] [unique_id "aoSCff2v-lWn9OzQT7U_tgAAANM"] [Tue Aug 18 13:04:13.160548 2026] [security2:error] [pid 139043:tid 139296] [client 20.1.169.243:11079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/files.php"] [unique_id "aoSCff2v-lWn9OzQT7U_uQAAAQA"] [Tue Aug 18 13:04:13.162541 2026] [authz_core:error] [pid 139043:tid 139146] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:13.162809 2026] [authz_core:error] [pid 139043:tid 139146] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:13.179929 2026] [security2:error] [pid 139043:tid 139249] [client 20.171.51.14:18686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wy.php"] [unique_id "aoSCff2v-lWn9OzQT7U_vQAAANE"] [Tue Aug 18 13:04:13.208509 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.200.96:3025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCff2v-lWn9OzQT7U_wQAAAOs"] [Tue Aug 18 13:04:13.245455 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:53153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSCff2v-lWn9OzQT7U_xQAAAIY"] [Tue Aug 18 13:04:13.270195 2026] [security2:error] [pid 139043:tid 139258] [client 52.139.47.57:26365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/g.php"] [unique_id "aoSCff2v-lWn9OzQT7U_xwAAANo"] [Tue Aug 18 13:04:13.277237 2026] [security2:error] [pid 139043:tid 139255] [client 20.226.36.136:43650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCff2v-lWn9OzQT7U_yAAAANc"] [Tue Aug 18 13:04:13.283201 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCff2v-lWn9OzQT7U_ywAAAOo"] [Tue Aug 18 13:04:13.292533 2026] [security2:error] [pid 139043:tid 139217] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCff2v-lWn9OzQT7U_zgAAALE"] [Tue Aug 18 13:04:13.294455 2026] [security2:error] [pid 139043:tid 139218] [client 213.35.127.232:57486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCff2v-lWn9OzQT7U_0AAAALI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:13.329354 2026] [security2:error] [pid 139043:tid 139232] [client 68.221.73.131:35979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/als.php"] [unique_id "aoSCff2v-lWn9OzQT7U_1gAAAMA"] [Tue Aug 18 13:04:13.359240 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCff2v-lWn9OzQT7U_1wAAANU"] [Tue Aug 18 13:04:13.366455 2026] [security2:error] [pid 139043:tid 139265] [client 20.52.168.85:5249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sid3.php"] [unique_id "aoSCff2v-lWn9OzQT7U_2AAAAOE"] [Tue Aug 18 13:04:13.377180 2026] [security2:error] [pid 139043:tid 139230] [client 20.51.153.15:8792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCff2v-lWn9OzQT7U_2QAAAL4"] [Tue Aug 18 13:04:13.377198 2026] [security2:error] [pid 139043:tid 139184] [client 52.173.121.69:52085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCff2v-lWn9OzQT7U_2gAAAJA"] [Tue Aug 18 13:04:13.381924 2026] [security2:error] [pid 139043:tid 139277] [client 74.249.206.207:31046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/BIBIL.php"] [unique_id "aoSCff2v-lWn9OzQT7U_2wAAAO0"] [Tue Aug 18 13:04:13.402403 2026] [security2:error] [pid 139043:tid 139216] [client 172.182.217.32:21384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-load.php"] [unique_id "aoSCff2v-lWn9OzQT7U_3QAAALA"] [Tue Aug 18 13:04:13.404917 2026] [security2:error] [pid 139043:tid 139224] [client 4.232.151.198:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/plugin.js.php"] [unique_id "aoSCff2v-lWn9OzQT7U_3gAAALg"] [Tue Aug 18 13:04:13.447086 2026] [security2:error] [pid 139043:tid 139178] [client 68.155.154.236:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCff2v-lWn9OzQT7U_3wAAAIo"] [Tue Aug 18 13:04:13.459866 2026] [security2:error] [pid 139043:tid 139130] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCff2v-lWn9OzQT7U_4QAAz1Y"] [Tue Aug 18 13:04:13.460003 2026] [security2:error] [pid 139043:tid 139247] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCff2v-lWn9OzQT7U_4QAAz1Y"] [Tue Aug 18 13:04:13.463515 2026] [authz_core:error] [pid 139043:tid 139091] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:13.463775 2026] [authz_core:error] [pid 139043:tid 139091] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:13.464133 2026] [security2:error] [pid 139043:tid 139256] [client 20.250.13.23:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSCff2v-lWn9OzQT7U_4gAAANg"] [Tue Aug 18 13:04:13.468959 2026] [security2:error] [pid 139043:tid 139180] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/tes.php"] [unique_id "aoSCff2v-lWn9OzQT7U_4wAAAIw"] [Tue Aug 18 13:04:13.526177 2026] [security2:error] [pid 139043:tid 139185] [client 20.1.169.243:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/fix.php"] [unique_id "aoSCff2v-lWn9OzQT7U_5gAAAJE"] [Tue Aug 18 13:04:13.532028 2026] [security2:error] [pid 139043:tid 139250] [client 20.80.111.3:17247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCff2v-lWn9OzQT7U_5wAAANI"] [Tue Aug 18 13:04:13.534464 2026] [security2:error] [pid 139043:tid 139284] [client 172.182.200.96:15564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCff2v-lWn9OzQT7U_6AAAAPQ"] [Tue Aug 18 13:04:13.535503 2026] [security2:error] [pid 139043:tid 139264] [client 20.186.30.159:10093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/images.php"] [unique_id "aoSCff2v-lWn9OzQT7U_6QAAAOA"] [Tue Aug 18 13:04:13.570696 2026] [security2:error] [pid 139043:tid 139245] [client 74.248.130.103:54875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCff2v-lWn9OzQT7U_8gAAAM0"] [Tue Aug 18 13:04:13.583202 2026] [security2:error] [pid 139043:tid 139252] [client 20.48.236.86:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/sf.php"] [unique_id "aoSCff2v-lWn9OzQT7U_9AAAANQ"] [Tue Aug 18 13:04:13.614972 2026] [security2:error] [pid 139043:tid 139200] [client 20.151.109.219:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCff2v-lWn9OzQT7U__gAAAKA"] [Tue Aug 18 13:04:13.616131 2026] [security2:error] [pid 139043:tid 139212] [client 20.163.43.14:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/images/images/about.php"] [unique_id "aoSCff2v-lWn9OzQT7U__wAAAKw"] [Tue Aug 18 13:04:13.623657 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:20473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gz.php"] [unique_id "aoSCff2v-lWn9OzQT7VAAAAAAIY"] [Tue Aug 18 13:04:13.651877 2026] [security2:error] [pid 139043:tid 139274] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/file.php"] [unique_id "aoSCff2v-lWn9OzQT7VAAQAAAOo"] [Tue Aug 18 13:04:13.665266 2026] [security2:error] [pid 139043:tid 139243] [client 20.104.100.201:23986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/echkm.php"] [unique_id "aoSCff2v-lWn9OzQT7VAAwAAAMs"] [Tue Aug 18 13:04:13.677074 2026] [security2:error] [pid 139043:tid 139194] [client 20.51.153.15:9131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/dg.php"] [unique_id "aoSCff2v-lWn9OzQT7VABAAAAJo"] [Tue Aug 18 13:04:13.679223 2026] [security2:error] [pid 139043:tid 139179] [client 52.139.47.57:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCff2v-lWn9OzQT7VABQAAAIs"] [Tue Aug 18 13:04:13.688893 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/rezor.php"] [unique_id "aoSCff2v-lWn9OzQT7VABwAAANU"] [Tue Aug 18 13:04:13.729974 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/mq.php"] [unique_id "aoSCff2v-lWn9OzQT7VACQAAAQQ"] [Tue Aug 18 13:04:13.749565 2026] [security2:error] [pid 139043:tid 139210] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/files/index.php"] [unique_id "aoSCff2v-lWn9OzQT7VADgAAAKo"] [Tue Aug 18 13:04:13.749570 2026] [security2:error] [pid 139043:tid 139106] [remote 34.158.8.33:49538] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "acessosonori.com.br"] [uri "/server-info"] [unique_id "aoSCff2v-lWn9OzQT7VACwAAoz4"] [Tue Aug 18 13:04:13.796019 2026] [access_compat:error] [pid 139043:tid 139156] [remote 34.158.8.33:49538] AH01797: client denied by server configuration: /home4/acessoso/public_html/server-status [Tue Aug 18 13:04:13.875398 2026] [security2:error] [pid 139043:tid 139280] [client 20.215.241.237:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/coffexium.php"] [unique_id "aoSCff2v-lWn9OzQT7VAGQAAAPA"] [Tue Aug 18 13:04:13.880445 2026] [security2:error] [pid 139043:tid 139270] [client 20.186.30.159:10101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/ops.php"] [unique_id "aoSCff2v-lWn9OzQT7VAGgAAAOY"] [Tue Aug 18 13:04:13.882384 2026] [security2:error] [pid 139043:tid 139190] [client 68.221.73.131:60604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/nox.php"] [unique_id "aoSCff2v-lWn9OzQT7VAGwAAAJY"] [Tue Aug 18 13:04:13.889882 2026] [security2:error] [pid 139043:tid 139276] [client 172.182.217.32:21773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-activate.php"] [unique_id "aoSCff2v-lWn9OzQT7VAHQAAAOw"] [Tue Aug 18 13:04:13.893494 2026] [security2:error] [pid 139043:tid 139272] [client 20.206.73.37:21255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/sky.php"] [unique_id "aoSCff2v-lWn9OzQT7VAHwAAAOg"] [Tue Aug 18 13:04:13.895088 2026] [security2:error] [pid 139043:tid 139173] [client 74.249.206.207:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/too.php"] [unique_id "aoSCff2v-lWn9OzQT7VAIAAAAIU"] [Tue Aug 18 13:04:13.896819 2026] [security2:error] [pid 139043:tid 139278] [client 20.1.169.243:10912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/fm.php"] [unique_id "aoSCff2v-lWn9OzQT7VAIQAAAO4"] [Tue Aug 18 13:04:13.934890 2026] [security2:error] [pid 139043:tid 139245] [client 172.182.200.96:15542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCff2v-lWn9OzQT7VAJQAAAM0"] [Tue Aug 18 13:04:13.961253 2026] [security2:error] [pid 139043:tid 139195] [client 20.51.153.15:8721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/bm.php"] [unique_id "aoSCff2v-lWn9OzQT7VAKgAAAJs"] [Tue Aug 18 13:04:13.984852 2026] [security2:error] [pid 139043:tid 139266] [client 20.80.111.3:26001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "aoSCff2v-lWn9OzQT7VALAAAAOI"] [Tue Aug 18 13:04:13.987098 2026] [security2:error] [pid 139043:tid 139198] [client 103.120.71.157:35621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCff2v-lWn9OzQT7VAKwAAAJ4"] [Tue Aug 18 13:04:13.987188 2026] [security2:error] [pid 139043:tid 139198] [client 103.120.71.157:35621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCff2v-lWn9OzQT7VAKwAAAJ4"] [Tue Aug 18 13:04:14.002274 2026] [security2:error] [pid 139043:tid 139296] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/epinyins.php"] [unique_id "aoSCfv2v-lWn9OzQT7VALQAAAQA"] [Tue Aug 18 13:04:14.006164 2026] [security2:error] [pid 139043:tid 139221] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VALgAAALU"] [Tue Aug 18 13:04:14.007198 2026] [security2:error] [pid 139043:tid 139242] [client 20.52.168.85:5283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/blog.php7"] [unique_id "aoSCfv2v-lWn9OzQT7VALwAAAMo"] [Tue Aug 18 13:04:14.011341 2026] [security2:error] [pid 139043:tid 139214] [client 20.163.43.14:3026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAMAAAAK4"] [Tue Aug 18 13:04:14.034578 2026] [security2:error] [pid 139043:tid 139233] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAMgAAAME"] [Tue Aug 18 13:04:14.042708 2026] [security2:error] [pid 139043:tid 139249] [client 168.62.48.100:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAMwAAANE"] [Tue Aug 18 13:04:14.065786 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:14.066052 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:14.088094 2026] [security2:error] [pid 139043:tid 139283] [client 52.139.47.57:26305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCfv2v-lWn9OzQT7VANgAAAPM"] [Tue Aug 18 13:04:14.092149 2026] [security2:error] [pid 139043:tid 139174] [client 20.116.17.175:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/99.php"] [unique_id "aoSCfv2v-lWn9OzQT7VANwAAAIY"] [Tue Aug 18 13:04:14.100292 2026] [security2:error] [pid 139043:tid 139228] [client 20.250.13.23:55674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAOQAAALw"] [Tue Aug 18 13:04:14.114971 2026] [security2:error] [pid 139043:tid 139258] [client 132.196.30.78:4988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAOgAAANo"] [Tue Aug 18 13:04:14.165795 2026] [security2:error] [pid 139043:tid 139248] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAPgAAANA"] [Tue Aug 18 13:04:14.190690 2026] [security2:error] [pid 139043:tid 139253] [client 168.62.48.100:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAQAAAANU"] [Tue Aug 18 13:04:14.206238 2026] [security2:error] [pid 139043:tid 139230] [client 20.206.73.37:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/scxy.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAQgAAAL4"] [Tue Aug 18 13:04:14.215129 2026] [security2:error] [pid 139043:tid 139281] [client 20.151.109.219:22929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/qo.php"] [unique_id "aoSCfv2v-lWn9OzQT7VARAAAAPE"] [Tue Aug 18 13:04:14.219760 2026] [security2:error] [pid 139043:tid 139288] [client 4.232.151.198:26691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/analytics.php"] [unique_id "aoSCfv2v-lWn9OzQT7VARQAAAPg"] [Tue Aug 18 13:04:14.258244 2026] [security2:error] [pid 139043:tid 139210] [client 20.151.109.219:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dg.php"] [unique_id "aoSCfv2v-lWn9OzQT7VASAAAAKo"] [Tue Aug 18 13:04:14.260280 2026] [security2:error] [pid 139043:tid 139199] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/images/images/about.php"] [unique_id "aoSCfv2v-lWn9OzQT7VASQAAAJ8"] [Tue Aug 18 13:04:14.264265 2026] [security2:error] [pid 139043:tid 139218] [client 20.1.169.243:11182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/footer.php"] [unique_id "aoSCfv2v-lWn9OzQT7VASgAAALI"] [Tue Aug 18 13:04:14.264611 2026] [security2:error] [pid 139043:tid 139203] [client 20.51.153.15:8829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vu.php"] [unique_id "aoSCfv2v-lWn9OzQT7VASwAAAKM"] [Tue Aug 18 13:04:14.264692 2026] [security2:error] [pid 139043:tid 139247] [client 172.182.200.96:15537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VATAAAAM8"] [Tue Aug 18 13:04:14.268546 2026] [security2:error] [pid 139043:tid 139256] [client 20.104.100.201:23979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/domvf.php"] [unique_id "aoSCfv2v-lWn9OzQT7VATQAAANg"] [Tue Aug 18 13:04:14.282933 2026] [security2:error] [pid 139043:tid 139177] [client 74.249.206.207:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ctrrefrigeracao.com.br"] [uri "/g3.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAUAAAAIk"] [Tue Aug 18 13:04:14.304375 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:58735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAUgAAALk"] [Tue Aug 18 13:04:14.310169 2026] [security2:error] [pid 139043:tid 139269] [client 213.35.127.232:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAUwAAAOU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:14.316783 2026] [security2:error] [pid 139043:tid 139204] [client 20.48.236.86:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/k.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAVQAAAKQ"] [Tue Aug 18 13:04:14.355262 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAVwAAAMM"] [Tue Aug 18 13:04:14.355978 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:3014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/rip.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAWQAAAOY"] [Tue Aug 18 13:04:14.356038 2026] [security2:error] [pid 139043:tid 139280] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAWAAAAPA"] [Tue Aug 18 13:04:14.369362 2026] [authz_core:error] [pid 139043:tid 139073] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:14.369784 2026] [authz_core:error] [pid 139043:tid 139073] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:14.376630 2026] [security2:error] [pid 139043:tid 139236] [client 172.182.217.32:21379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/berlin.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAXAAAAMQ"] [Tue Aug 18 13:04:14.396514 2026] [security2:error] [pid 139043:tid 139238] [client 158.23.17.4:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nf.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAXwAAAMY"] [Tue Aug 18 13:04:14.420056 2026] [security2:error] [pid 139043:tid 139244] [client 20.171.51.14:44877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/f.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAYQAAAMw"] [Tue Aug 18 13:04:14.446676 2026] [security2:error] [pid 139043:tid 139180] [client 20.80.111.3:26000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAZAAAAIw"] [Tue Aug 18 13:04:14.448135 2026] [security2:error] [pid 139043:tid 139193] [client 20.79.204.6:10115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAZQAAAJk"] [Tue Aug 18 13:04:14.458377 2026] [security2:error] [pid 139043:tid 139198] [client 68.155.154.236:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAZgAAAJ4"] [Tue Aug 18 13:04:14.494540 2026] [security2:error] [pid 139043:tid 139296] [client 20.116.17.175:53172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/yup.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAagAAAQA"] [Tue Aug 18 13:04:14.514235 2026] [security2:error] [pid 139043:tid 139214] [client 20.51.153.15:9108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ic.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAawAAAK4"] [Tue Aug 18 13:04:14.515184 2026] [security2:error] [pid 139043:tid 139276] [client 52.139.47.57:33827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/in.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAbAAAAOw"] [Tue Aug 18 13:04:14.519824 2026] [security2:error] [pid 139043:tid 139233] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAbQAAAME"] [Tue Aug 18 13:04:14.527928 2026] [security2:error] [pid 139043:tid 139213] [client 68.221.73.131:36000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file59.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAbgAAAK0"] [Tue Aug 18 13:04:14.539599 2026] [security2:error] [pid 139043:tid 139222] [client 68.155.156.252:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/thoms.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAcAAAALY"] [Tue Aug 18 13:04:14.587969 2026] [security2:error] [pid 139043:tid 139206] [client 158.23.17.4:9393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/13.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAcgAAAKY"] [Tue Aug 18 13:04:14.609168 2026] [security2:error] [pid 139043:tid 139283] [client 74.248.130.103:34994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAcwAAAPM"] [Tue Aug 18 13:04:14.611915 2026] [security2:error] [pid 139043:tid 139174] [client 172.182.200.96:15574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAdAAAAIY"] [Tue Aug 18 13:04:14.623000 2026] [security2:error] [pid 139043:tid 139263] [client 20.52.168.85:5720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/GOD.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAdQAAAN8"] [Tue Aug 18 13:04:14.629172 2026] [security2:error] [pid 139043:tid 139242] [client 20.1.169.243:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/form.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAdgAAAMo"] [Tue Aug 18 13:04:14.629362 2026] [security2:error] [pid 139043:tid 139268] [client 20.151.109.219:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sd.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAdwAAAOQ"] [Tue Aug 18 13:04:14.635768 2026] [security2:error] [pid 139043:tid 139279] [client 20.104.100.201:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/red.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAeAAAAO8"] [Tue Aug 18 13:04:14.667558 2026] [authz_core:error] [pid 139043:tid 139158] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:14.667839 2026] [authz_core:error] [pid 139043:tid 139158] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:14.718609 2026] [security2:error] [pid 139043:tid 139226] [client 103.184.169.37:43749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAgAAAALo"] [Tue Aug 18 13:04:14.718734 2026] [security2:error] [pid 139043:tid 139226] [client 103.184.169.37:43749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAgAAAALo"] [Tue Aug 18 13:04:14.738902 2026] [security2:error] [pid 139043:tid 139292] [client 20.226.36.136:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAgQAAAPw"] [Tue Aug 18 13:04:14.750156 2026] [security2:error] [pid 139043:tid 139288] [client 20.151.109.219:56061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAggAAAPg"] [Tue Aug 18 13:04:14.751559 2026] [security2:error] [pid 139043:tid 139275] [client 20.250.13.23:55658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAgwAAAOs"] [Tue Aug 18 13:04:14.758355 2026] [security2:error] [pid 139043:tid 139229] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/index/function.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAhQAAAL0"] [Tue Aug 18 13:04:14.783763 2026] [security2:error] [pid 139043:tid 139218] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/rip.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAigAAALI"] [Tue Aug 18 13:04:14.804521 2026] [security2:error] [pid 139043:tid 139256] [client 20.171.51.14:13407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/30.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAiwAAANg"] [Tue Aug 18 13:04:14.851507 2026] [security2:error] [pid 139043:tid 139185] [client 20.163.43.14:4410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAjwAAAJE"] [Tue Aug 18 13:04:14.860017 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:9179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ue.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAkAAAAKQ"] [Tue Aug 18 13:04:14.867884 2026] [security2:error] [pid 139043:tid 139197] [client 172.182.217.32:21865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/not/includes/php8.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAkQAAAJ0"] [Tue Aug 18 13:04:14.891513 2026] [security2:error] [pid 139043:tid 139230] [client 20.80.111.3:28164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/SimplePie/cY5ipC.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAkwAAAL4"] [Tue Aug 18 13:04:14.901876 2026] [security2:error] [pid 139043:tid 139202] [client 4.232.151.198:7685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/awesome-coming-soon/flower.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAlAAAAKI"] [Tue Aug 18 13:04:14.917196 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAlQAAAOY"] [Tue Aug 18 13:04:14.926775 2026] [security2:error] [pid 139043:tid 139203] [client 52.139.47.57:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/info.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAlwAAAKM"] [Tue Aug 18 13:04:14.931919 2026] [authz_core:error] [pid 139043:tid 139075] [remote 96.40.13.157:40110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4, referer: https://www.google.com/ [Tue Aug 18 13:04:14.932178 2026] [authz_core:error] [pid 139043:tid 139075] [remote 96.40.13.157:40110] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3, referer: https://www.google.com/ [Tue Aug 18 13:04:14.934244 2026] [security2:error] [pid 139043:tid 139236] [client 20.116.17.175:3446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/222.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAmAAAAMQ"] [Tue Aug 18 13:04:14.952073 2026] [security2:error] [pid 139043:tid 139267] [client 20.186.30.159:10006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/coffexium.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAmwAAAOM"] [Tue Aug 18 13:04:14.952626 2026] [authz_core:error] [pid 139043:tid 139056] [remote 57.141.22.125:29670] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:14.952899 2026] [authz_core:error] [pid 139043:tid 139056] [remote 57.141.22.125:29670] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:14.958292 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.200.96:15519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAnAAAAOg"] [Tue Aug 18 13:04:14.994033 2026] [security2:error] [pid 139043:tid 139254] [client 52.22.236.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSCff2v-lWn9OzQT7U_9gAA1gg"], referer: https://jgbdominiosolucoes.com.br/ [Tue Aug 18 13:04:14.995621 2026] [security2:error] [pid 139043:tid 139264] [client 20.1.169.243:10934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/fpwch.php"] [unique_id "aoSCfv2v-lWn9OzQT7VAnwAAAOA"] [Tue Aug 18 13:04:15.056929 2026] [security2:error] [pid 139043:tid 139299] [client 4.232.151.198:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/default.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAogAAAQM"] [Tue Aug 18 13:04:15.080750 2026] [security2:error] [pid 139043:tid 139214] [client 20.151.109.219:21271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bm.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAowAAAK4"] [Tue Aug 18 13:04:15.082141 2026] [security2:error] [pid 139043:tid 139261] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCf_2v-lWn9OzQT7VApAAAAN0"] [Tue Aug 18 13:04:15.110865 2026] [security2:error] [pid 139043:tid 139222] [client 68.155.154.236:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCf_2v-lWn9OzQT7VApQAAALY"] [Tue Aug 18 13:04:15.117405 2026] [security2:error] [pid 139043:tid 139200] [client 20.104.100.201:24021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSCf_2v-lWn9OzQT7VApgAAAKA"] [Tue Aug 18 13:04:15.121216 2026] [security2:error] [pid 139043:tid 139237] [client 68.221.73.131:63055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/admin.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAqAAAAMU"] [Tue Aug 18 13:04:15.137695 2026] [security2:error] [pid 139043:tid 139263] [client 20.51.153.15:9197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lr.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAqQAAAN8"] [Tue Aug 18 13:04:15.181816 2026] [security2:error] [pid 139043:tid 139279] [client 74.248.130.103:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCf_2v-lWn9OzQT7VArAAAAO8"] [Tue Aug 18 13:04:15.188250 2026] [security2:error] [pid 139043:tid 139258] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VArgAAANo"] [Tue Aug 18 13:04:15.222981 2026] [security2:error] [pid 139043:tid 139293] [client 20.163.43.14:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/moon.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAsAAAAP0"] [Tue Aug 18 13:04:15.232186 2026] [security2:error] [pid 139043:tid 139271] [client 20.52.168.85:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/alumni_reg.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAsQAAAOc"] [Tue Aug 18 13:04:15.247040 2026] [security2:error] [pid 139043:tid 139252] [client 5.31.227.224:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAswAAANQ"] [Tue Aug 18 13:04:15.247150 2026] [security2:error] [pid 139043:tid 139252] [client 5.31.227.224:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAswAAANQ"] [Tue Aug 18 13:04:15.272070 2026] [authz_core:error] [pid 139043:tid 139127] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:15.272332 2026] [authz_core:error] [pid 139043:tid 139127] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:15.272688 2026] [security2:error] [pid 139043:tid 139201] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAtQAAAKE"] [Tue Aug 18 13:04:15.282745 2026] [security2:error] [pid 139043:tid 139232] [client 20.48.236.86:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/82.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAtgAAAMA"] [Tue Aug 18 13:04:15.300197 2026] [security2:error] [pid 139043:tid 139209] [client 20.151.109.219:27751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/dirs.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAuAAAAKk"] [Tue Aug 18 13:04:15.316522 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.200.96:3051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAuwAAALg"] [Tue Aug 18 13:04:15.339393 2026] [security2:error] [pid 139043:tid 139294] [client 213.35.127.232:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAvAAAAP4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:15.345931 2026] [security2:error] [pid 139043:tid 139211] [client 52.139.47.57:10964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/inputs.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAvQAAAKs"] [Tue Aug 18 13:04:15.353432 2026] [security2:error] [pid 139043:tid 139199] [client 20.251.48.93:9197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAvgAAAJ8"] [Tue Aug 18 13:04:15.355807 2026] [security2:error] [pid 139043:tid 139242] [client 20.80.111.3:26016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAvwAAAMo"] [Tue Aug 18 13:04:15.360218 2026] [security2:error] [pid 139043:tid 139223] [client 172.182.217.32:22217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/plugins/wp-theme-editor/php8.php/wp-content/themes/aahana/json.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAwAAAALc"] [Tue Aug 18 13:04:15.367890 2026] [security2:error] [pid 139043:tid 139115] [remote 162.214.205.212:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAwQAA00c"] [Tue Aug 18 13:04:15.389536 2026] [security2:error] [pid 139043:tid 139268] [client 20.250.13.23:6229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAwgAAAOQ"] [Tue Aug 18 13:04:15.414565 2026] [security2:error] [pid 139043:tid 139292] [client 20.1.169.243:10928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/function.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAxAAAAPw"] [Tue Aug 18 13:04:15.422313 2026] [security2:error] [pid 139043:tid 139185] [client 168.62.48.100:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAxQAAAJE"] [Tue Aug 18 13:04:15.430241 2026] [security2:error] [pid 139043:tid 139204] [client 20.171.51.14:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pu.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAxgAAAKQ"] [Tue Aug 18 13:04:15.444969 2026] [security2:error] [pid 139043:tid 139241] [client 20.51.153.15:9209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ka.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAyAAAAMk"] [Tue Aug 18 13:04:15.448878 2026] [security2:error] [pid 139043:tid 139240] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/moon.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAyQAAAMg"] [Tue Aug 18 13:04:15.518158 2026] [security2:error] [pid 139043:tid 139267] [client 20.116.17.175:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-temp.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAywAAAOM"] [Tue Aug 18 13:04:15.520004 2026] [security2:error] [pid 139043:tid 139272] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/Cachex.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAzAAAAOg"] [Tue Aug 18 13:04:15.538059 2026] [security2:error] [pid 139043:tid 139245] [client 132.196.30.78:4983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zanseg.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAzgAAAM0"] [Tue Aug 18 13:04:15.543107 2026] [autoindex:error] [pid 139043:tid 139186] [client 20.250.13.23:2581] AH01276: Cannot serve directory /home4/p4ex7qyn/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:15.551564 2026] [security2:error] [pid 139043:tid 139257] [client 20.151.109.219:20715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/km.php"] [unique_id "aoSCf_2v-lWn9OzQT7VAzwAAANk"] [Tue Aug 18 13:04:15.569026 2026] [security2:error] [pid 139043:tid 139262] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/mgrr.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA0gAAAN4"] [Tue Aug 18 13:04:15.571970 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:15.572315 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:15.592896 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:4388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/cache.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA1AAAAPs"] [Tue Aug 18 13:04:15.634690 2026] [security2:error] [pid 139043:tid 139286] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA1gAAAPY"] [Tue Aug 18 13:04:15.642111 2026] [security2:error] [pid 139043:tid 139296] [client 158.23.17.4:10987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/so.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA2AAAAQA"] [Tue Aug 18 13:04:15.649657 2026] [security2:error] [pid 139043:tid 139287] [client 172.182.200.96:15521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA2QAAAPc"] [Tue Aug 18 13:04:15.681089 2026] [security2:error] [pid 139043:tid 139298] [client 4.232.151.198:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/BDKR28_nfbxj7ov.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA2wAAAQI"] [Tue Aug 18 13:04:15.689086 2026] [security2:error] [pid 139043:tid 139179] [client 20.51.153.15:8747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ot.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA3AAAAIs"] [Tue Aug 18 13:04:15.699937 2026] [security2:error] [pid 139043:tid 139200] [client 68.221.73.131:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/aa2.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA3QAAAKA"] [Tue Aug 18 13:04:15.701110 2026] [security2:error] [pid 139043:tid 139206] [client 20.104.100.201:24055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA3gAAAKY"] [Tue Aug 18 13:04:15.702881 2026] [security2:error] [pid 139043:tid 139283] [client 20.186.30.159:10002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA3wAAAPM"] [Tue Aug 18 13:04:15.704155 2026] [security2:error] [pid 139043:tid 139263] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/cache.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA4AAAAN8"] [Tue Aug 18 13:04:15.724275 2026] [security2:error] [pid 139043:tid 139215] [client 37.40.227.74:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA4QAAAK8"] [Tue Aug 18 13:04:15.724371 2026] [security2:error] [pid 139043:tid 139215] [client 37.40.227.74:56979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA4QAAAK8"] [Tue Aug 18 13:04:15.755852 2026] [security2:error] [pid 139043:tid 139252] [client 74.248.130.103:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/222.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA4wAAANQ"] [Tue Aug 18 13:04:15.759686 2026] [security2:error] [pid 139043:tid 139234] [client 52.139.47.57:26324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/item.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA5AAAAMI"] [Tue Aug 18 13:04:15.780031 2026] [security2:error] [pid 139043:tid 139214] [client 20.1.169.243:11099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/g.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA5QAAAK4"] [Tue Aug 18 13:04:15.809081 2026] [security2:error] [pid 139043:tid 139265] [client 158.23.17.4:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xv.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA5gAAAOE"] [Tue Aug 18 13:04:15.811858 2026] [security2:error] [pid 139043:tid 139233] [client 20.80.111.3:28213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/Text/about.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA5wAAAME"] [Tue Aug 18 13:04:15.837160 2026] [security2:error] [pid 139043:tid 139198] [client 4.232.151.198:32037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/i.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA6QAAAJ4"] [Tue Aug 18 13:04:15.839371 2026] [security2:error] [pid 139043:tid 139299] [client 20.52.168.85:5651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/depotcv.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA6gAAAQM"] [Tue Aug 18 13:04:15.848628 2026] [security2:error] [pid 139043:tid 139288] [client 197.184.64.235:42666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA7AAAAPg"] [Tue Aug 18 13:04:15.853257 2026] [security2:error] [pid 139043:tid 139181] [client 172.182.217.32:21810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/Requests/php8.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA7QAAAI0"] [Tue Aug 18 13:04:15.853556 2026] [security2:error] [pid 139043:tid 139288] [client 197.184.64.235:42666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA7AAAAPg"] [Tue Aug 18 13:04:15.860098 2026] [security2:error] [pid 139043:tid 139275] [client 20.48.236.86:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/dex.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA7gAAAOs"] [Tue Aug 18 13:04:15.873774 2026] [authz_core:error] [pid 139043:tid 139099] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:15.874033 2026] [authz_core:error] [pid 139043:tid 139099] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:15.882415 2026] [security2:error] [pid 139043:tid 139224] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA8AAAALg"] [Tue Aug 18 13:04:15.997529 2026] [security2:error] [pid 139043:tid 139239] [client 52.173.121.69:49714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCf_2v-lWn9OzQT7VA-AAAAMc"] [Tue Aug 18 13:04:16.001743 2026] [security2:error] [pid 139043:tid 139289] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/function/function.php"] [unique_id "aoSCgP2v-lWn9OzQT7VA-QAAAPk"] [Tue Aug 18 13:04:16.004404 2026] [security2:error] [pid 139043:tid 139268] [client 172.182.200.96:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VA-gAAAOQ"] [Tue Aug 18 13:04:16.010990 2026] [security2:error] [pid 139043:tid 139201] [client 20.250.13.23:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCgP2v-lWn9OzQT7VA-wAAAKE"] [Tue Aug 18 13:04:16.011639 2026] [security2:error] [pid 139043:tid 139292] [client 20.151.109.219:56032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/fresh.php"] [unique_id "aoSCgP2v-lWn9OzQT7VA_AAAAPw"] [Tue Aug 18 13:04:16.029012 2026] [security2:error] [pid 139043:tid 139212] [client 20.116.17.175:56103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/spadex.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBAQAAAKw"] [Tue Aug 18 13:04:16.029692 2026] [security2:error] [pid 139043:tid 139250] [client 20.171.51.14:44876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ry.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBAgAAANI"] [Tue Aug 18 13:04:16.042315 2026] [security2:error] [pid 139043:tid 139240] [client 20.51.153.15:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ih.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBBwAAAMg"] [Tue Aug 18 13:04:16.048602 2026] [security2:error] [pid 139043:tid 139221] [client 20.79.204.6:9721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/h.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBCAAAALU"] [Tue Aug 18 13:04:16.151306 2026] [security2:error] [pid 139043:tid 139246] [client 20.1.169.243:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/goods.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBFQAAAM4"] [Tue Aug 18 13:04:16.171551 2026] [security2:error] [pid 139043:tid 139280] [client 52.139.47.57:10952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/k.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBFwAAAPA"] [Tue Aug 18 13:04:16.174413 2026] [authz_core:error] [pid 139043:tid 139114] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:16.174681 2026] [authz_core:error] [pid 139043:tid 139114] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:16.251845 2026] [security2:error] [pid 139043:tid 139183] [client 223.185.37.47:22202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBGQAAAI8"] [Tue Aug 18 13:04:16.251957 2026] [security2:error] [pid 139043:tid 139183] [client 223.185.37.47:22202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBGQAAAI8"] [Tue Aug 18 13:04:16.252700 2026] [security2:error] [pid 139043:tid 139238] [client 20.80.111.3:28216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBGgAAAMY"] [Tue Aug 18 13:04:16.274663 2026] [security2:error] [pid 139043:tid 139297] [client 20.226.36.136:57802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBHQAAAQE"] [Tue Aug 18 13:04:16.276933 2026] [security2:error] [pid 139043:tid 139222] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBHgAAALY"] [Tue Aug 18 13:04:16.296966 2026] [security2:error] [pid 139043:tid 139206] [client 68.221.73.131:57503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBIAAAAKY"] [Tue Aug 18 13:04:16.299644 2026] [security2:error] [pid 139043:tid 139283] [client 68.221.73.131:29763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/xamp.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBIQAAAPM"] [Tue Aug 18 13:04:16.318001 2026] [security2:error] [pid 139043:tid 139278] [client 4.232.151.198:7715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/upload/upload_cert.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBIwAAAO4"] [Tue Aug 18 13:04:16.334288 2026] [security2:error] [pid 139043:tid 139217] [client 172.182.200.96:15551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBJQAAALE"] [Tue Aug 18 13:04:16.346038 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.217.32:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/SimplePie/php8.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBJgAAAJk"] [Tue Aug 18 13:04:16.355794 2026] [security2:error] [pid 139043:tid 139252] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBJwAAANQ"] [Tue Aug 18 13:04:16.364557 2026] [security2:error] [pid 139043:tid 139234] [client 20.104.100.201:24023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBKQAAAMI"] [Tue Aug 18 13:04:16.369596 2026] [security2:error] [pid 139043:tid 139188] [client 213.35.127.232:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBKgAAAJQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:16.370911 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/k.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBKwAAANA"] [Tue Aug 18 13:04:16.401097 2026] [security2:error] [pid 139043:tid 139182] [client 20.151.109.219:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mf.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBLQAAAI4"] [Tue Aug 18 13:04:16.412141 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:10998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/10.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBLgAAALo"] [Tue Aug 18 13:04:16.416555 2026] [security2:error] [pid 139043:tid 139232] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBLwAAAMA"] [Tue Aug 18 13:04:16.435222 2026] [security2:error] [pid 139043:tid 139279] [client 20.151.109.219:17605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/admin404.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBMgAAAO8"] [Tue Aug 18 13:04:16.440263 2026] [security2:error] [pid 139043:tid 139261] [client 20.52.168.85:5141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/admin.php7"] [unique_id "aoSCgP2v-lWn9OzQT7VBMwAAAN0"] [Tue Aug 18 13:04:16.449408 2026] [security2:error] [pid 139043:tid 139299] [client 74.248.130.103:54851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBNAAAAQM"] [Tue Aug 18 13:04:16.453264 2026] [security2:error] [pid 139043:tid 139174] [client 20.163.43.14:4436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBNQAAAIY"] [Tue Aug 18 13:04:16.475444 2026] [authz_core:error] [pid 139043:tid 139130] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:16.475752 2026] [authz_core:error] [pid 139043:tid 139130] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:16.477898 2026] [security2:error] [pid 139043:tid 139184] [client 196.12.128.158:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBNwAAAJA"] [Tue Aug 18 13:04:16.478023 2026] [security2:error] [pid 139043:tid 139184] [client 196.12.128.158:50952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBNwAAAJA"] [Tue Aug 18 13:04:16.499108 2026] [security2:error] [pid 139043:tid 139288] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/55.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBOQAAAPg"] [Tue Aug 18 13:04:16.509763 2026] [security2:error] [pid 139043:tid 139224] [client 20.186.30.159:10010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/sf.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBOgAAALg"] [Tue Aug 18 13:04:16.517488 2026] [security2:error] [pid 139043:tid 139210] [client 20.48.236.86:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/puc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBOwAAAKo"] [Tue Aug 18 13:04:16.520885 2026] [security2:error] [pid 139043:tid 139227] [client 20.1.169.243:11227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/gtt.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBPAAAALs"] [Tue Aug 18 13:04:16.547643 2026] [security2:error] [pid 139043:tid 139256] [client 68.155.156.252:13113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/wpxml.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBPgAAANg"] [Tue Aug 18 13:04:16.582830 2026] [security2:error] [pid 139043:tid 139216] [client 52.139.47.57:26348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/license.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBQQAAALA"] [Tue Aug 18 13:04:16.638393 2026] [security2:error] [pid 139043:tid 139186] [client 114.119.132.85:26025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autoescolabrinhosa.com.br"] [uri "/steps-to-start-a-discussion-on-tinder-try-these/"] [unique_id "aoSCgP2v-lWn9OzQT7VBQwAAAJI"], referer: https://autoescolabrinhosa.com.br/blog/page/233/?controller=blog&action=view&number=2 [Tue Aug 18 13:04:16.651118 2026] [security2:error] [pid 139043:tid 139198] [client 20.250.13.23:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/abc.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBRAAAAJ4"] [Tue Aug 18 13:04:16.657578 2026] [security2:error] [pid 139043:tid 139269] [client 20.171.51.14:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pm.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBRgAAAOU"] [Tue Aug 18 13:04:16.681120 2026] [security2:error] [pid 139043:tid 139221] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBSAAAALU"] [Tue Aug 18 13:04:16.686128 2026] [security2:error] [pid 139043:tid 139270] [client 172.182.200.96:15501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBSgAAAOY"] [Tue Aug 18 13:04:16.692194 2026] [security2:error] [pid 139043:tid 139295] [client 20.80.111.3:17250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/block-supports/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBSwAAAP8"] [Tue Aug 18 13:04:16.712103 2026] [security2:error] [pid 139043:tid 139173] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBTQAAAIU"] [Tue Aug 18 13:04:16.777621 2026] [authz_core:error] [pid 139043:tid 139084] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:16.777893 2026] [authz_core:error] [pid 139043:tid 139084] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:16.832184 2026] [security2:error] [pid 139043:tid 139286] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBVAAAAPY"] [Tue Aug 18 13:04:16.843051 2026] [security2:error] [pid 139043:tid 139240] [client 172.182.217.32:21560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/banners/php8.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBVQAAAMg"] [Tue Aug 18 13:04:16.843076 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:47625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mx.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBVgAAANE"] [Tue Aug 18 13:04:16.887035 2026] [security2:error] [pid 139043:tid 139300] [client 20.116.17.175:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBWQAAAQQ"] [Tue Aug 18 13:04:16.889642 2026] [security2:error] [pid 139043:tid 139246] [client 20.1.169.243:11178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/gulu.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBWgAAAM4"] [Tue Aug 18 13:04:16.893601 2026] [security2:error] [pid 139043:tid 139179] [client 20.215.241.237:9611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBWwAAAIs"] [Tue Aug 18 13:04:16.898712 2026] [security2:error] [pid 139043:tid 139297] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/ajax.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBXAAAAQE"] [Tue Aug 18 13:04:16.925658 2026] [security2:error] [pid 139043:tid 139237] [client 158.23.17.4:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/te.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBXQAAAMU"] [Tue Aug 18 13:04:16.980425 2026] [security2:error] [pid 139043:tid 139215] [client 68.155.154.236:47263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBYAAAAK8"] [Tue Aug 18 13:04:16.994682 2026] [security2:error] [pid 139043:tid 139238] [client 52.139.47.57:10989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/load.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBYgAAAMY"] [Tue Aug 18 13:04:16.997504 2026] [security2:error] [pid 139043:tid 139192] [client 68.221.73.131:48364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/bless.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBYwAAAJg"] [Tue Aug 18 13:04:16.998115 2026] [security2:error] [pid 139043:tid 139278] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCgP2v-lWn9OzQT7VBZAAAAO4"] [Tue Aug 18 13:04:17.009272 2026] [security2:error] [pid 139043:tid 139193] [client 20.51.153.15:9154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/iu.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBZQAAAJk"] [Tue Aug 18 13:04:17.022380 2026] [security2:error] [pid 139043:tid 139219] [client 172.182.200.96:15534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBZgAAALM"] [Tue Aug 18 13:04:17.039932 2026] [security2:error] [pid 139043:tid 139287] [client 20.52.168.85:5759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/f.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBaAAAAPc"] [Tue Aug 18 13:04:17.063274 2026] [security2:error] [pid 139043:tid 139229] [client 20.48.236.86:16294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/inso.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBaQAAAL0"] [Tue Aug 18 13:04:17.067826 2026] [security2:error] [pid 139043:tid 139182] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/ok.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBagAAAI4"] [Tue Aug 18 13:04:17.076335 2026] [authz_core:error] [pid 139043:tid 139146] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:17.076617 2026] [authz_core:error] [pid 139043:tid 139146] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:17.087201 2026] [security2:error] [pid 139043:tid 139232] [client 20.171.51.14:47156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/dr.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBbAAAAMA"] [Tue Aug 18 13:04:17.088989 2026] [security2:error] [pid 139043:tid 139233] [client 20.151.109.219:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ie.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBbQAAAME"] [Tue Aug 18 13:04:17.097615 2026] [security2:error] [pid 139043:tid 139279] [client 74.248.130.103:42000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBbgAAAO8"] [Tue Aug 18 13:04:17.100184 2026] [security2:error] [pid 139043:tid 139261] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/o.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBbwAAAN0"] [Tue Aug 18 13:04:17.102340 2026] [security2:error] [pid 139043:tid 139299] [client 20.163.43.14:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBcAAAAQM"] [Tue Aug 18 13:04:17.105110 2026] [security2:error] [pid 139043:tid 139184] [client 168.62.48.100:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBcQAAAJA"] [Tue Aug 18 13:04:17.162563 2026] [security2:error] [pid 139043:tid 139234] [client 20.80.111.3:17248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBdQAAAMI"] [Tue Aug 18 13:04:17.198541 2026] [security2:error] [pid 139043:tid 139243] [client 4.232.151.198:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/aquxkprm.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBdgAAAMs"] [Tue Aug 18 13:04:17.201135 2026] [security2:error] [pid 139043:tid 139242] [client 20.186.30.159:10051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/k.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBdwAAAMo"] [Tue Aug 18 13:04:17.229479 2026] [security2:error] [pid 139043:tid 139260] [client 20.226.36.136:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBeQAAANw"] [Tue Aug 18 13:04:17.255951 2026] [security2:error] [pid 139043:tid 139230] [client 20.1.169.243:11228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/hello.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBewAAAL4"] [Tue Aug 18 13:04:17.279692 2026] [security2:error] [pid 139043:tid 139239] [client 20.51.153.15:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pk.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBfAAAAMc"] [Tue Aug 18 13:04:17.289456 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/yj09.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBfQAAAOQ"] [Tue Aug 18 13:04:17.289583 2026] [security2:error] [pid 139043:tid 139226] [client 20.250.13.23:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/sf.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBfgAAALo"] [Tue Aug 18 13:04:17.331006 2026] [security2:error] [pid 139043:tid 139282] [client 172.182.217.32:21417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/php8.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBgQAAAPI"] [Tue Aug 18 13:04:17.346221 2026] [security2:error] [pid 139043:tid 139250] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBggAAANI"] [Tue Aug 18 13:04:17.379938 2026] [authz_core:error] [pid 139043:tid 139060] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:17.380352 2026] [authz_core:error] [pid 139043:tid 139060] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:17.384266 2026] [security2:error] [pid 139043:tid 139248] [client 213.35.127.232:58407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBhAAAANA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:17.391891 2026] [security2:error] [pid 139043:tid 139241] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/bb.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBhQAAAMk"] [Tue Aug 18 13:04:17.394864 2026] [security2:error] [pid 139043:tid 139221] [client 172.182.200.96:3063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBhgAAALU"] [Tue Aug 18 13:04:17.397302 2026] [security2:error] [pid 139043:tid 139270] [client 68.155.156.252:17812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/file1221.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBhwAAAOY"] [Tue Aug 18 13:04:17.417327 2026] [security2:error] [pid 139043:tid 139289] [client 52.139.47.57:26344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/manager.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBiQAAAPk"] [Tue Aug 18 13:04:17.423171 2026] [security2:error] [pid 139043:tid 139190] [client 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.joanagaspar.com.br"] [uri "/item.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBigAAAJY"] [Tue Aug 18 13:04:17.454138 2026] [security2:error] [pid 139043:tid 139173] [client 20.48.236.86:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/aa.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBjQAAAIU"] [Tue Aug 18 13:04:17.525149 2026] [security2:error] [pid 139043:tid 139212] [client 20.116.17.175:53563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/srontol.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBkgAAAKw"] [Tue Aug 18 13:04:17.534804 2026] [security2:error] [pid 139043:tid 139280] [client 20.51.153.15:9150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ge.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBkwAAAPA"] [Tue Aug 18 13:04:17.535362 2026] [security2:error] [pid 139043:tid 139180] [client 168.62.48.100:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBlAAAAIw"] [Tue Aug 18 13:04:17.555532 2026] [security2:error] [pid 139043:tid 139240] [client 20.163.43.14:3035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/o.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBlQAAAMg"] [Tue Aug 18 13:04:17.557923 2026] [security2:error] [pid 139043:tid 139213] [client 20.251.48.93:22137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBlgAAAK0"] [Tue Aug 18 13:04:17.558760 2026] [security2:error] [pid 139043:tid 139183] [client 4.232.151.198:44703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBlwAAAI8"] [Tue Aug 18 13:04:17.577700 2026] [security2:error] [pid 139043:tid 139246] [client 20.226.36.136:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBmAAAAM4"] [Tue Aug 18 13:04:17.604152 2026] [security2:error] [pid 139043:tid 139220] [client 20.104.100.201:24044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBmgAAALQ"] [Tue Aug 18 13:04:17.628252 2026] [security2:error] [pid 139043:tid 139272] [client 20.80.111.3:40694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBmwAAAOg"] [Tue Aug 18 13:04:17.632227 2026] [security2:error] [pid 139043:tid 139255] [client 20.1.169.243:10916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBnAAAANc"] [Tue Aug 18 13:04:17.642629 2026] [security2:error] [pid 139043:tid 139267] [client 20.52.168.85:5173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/c.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBnQAAAOM"] [Tue Aug 18 13:04:17.644809 2026] [security2:error] [pid 139043:tid 139192] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBngAAAJg"] [Tue Aug 18 13:04:17.669499 2026] [security2:error] [pid 139043:tid 139193] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBoAAAAJk"] [Tue Aug 18 13:04:17.672505 2026] [security2:error] [pid 139043:tid 139252] [client 68.221.73.131:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file25.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBogAAANQ"] [Tue Aug 18 13:04:17.681466 2026] [authz_core:error] [pid 139043:tid 139150] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:17.681909 2026] [authz_core:error] [pid 139043:tid 139150] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:17.688622 2026] [security2:error] [pid 139043:tid 139188] [client 158.23.17.4:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/kc.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBpAAAAJQ"] [Tue Aug 18 13:04:17.734095 2026] [security2:error] [pid 139043:tid 139184] [client 20.151.109.219:17661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/loading.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBpwAAAJA"] [Tue Aug 18 13:04:17.748555 2026] [security2:error] [pid 139043:tid 139224] [client 172.182.200.96:15558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBqQAAALg"] [Tue Aug 18 13:04:17.758496 2026] [security2:error] [pid 139043:tid 139227] [client 20.171.51.14:44866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ts.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBqgAAALs"] [Tue Aug 18 13:04:17.768868 2026] [security2:error] [pid 139043:tid 139199] [client 20.51.153.15:9212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kl.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBrAAAAJ8"] [Tue Aug 18 13:04:17.808875 2026] [security2:error] [pid 139043:tid 139177] [client 20.151.109.219:58305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/nw.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBrQAAAIk"] [Tue Aug 18 13:04:17.828426 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.151.198:22974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ice.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBrwAAAMY"] [Tue Aug 18 13:04:17.831984 2026] [security2:error] [pid 139043:tid 139274] [client 172.182.217.32:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/php8.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBsAAAAOo"] [Tue Aug 18 13:04:17.836488 2026] [security2:error] [pid 139043:tid 139229] [client 52.139.47.57:37364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/media.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBsQAAAL0"] [Tue Aug 18 13:04:17.875148 2026] [security2:error] [pid 139043:tid 139143] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBtAABAmM"] [Tue Aug 18 13:04:17.875275 2026] [security2:error] [pid 139043:tid 139298] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBtAABAmM"] [Tue Aug 18 13:04:17.927259 2026] [security2:error] [pid 139043:tid 139279] [client 20.250.13.23:6226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/chosen.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBuQAAAO8"] [Tue Aug 18 13:04:17.993898 2026] [security2:error] [pid 139043:tid 139282] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCgf2v-lWn9OzQT7VBvAAAAPI"] [Tue Aug 18 13:04:18.025825 2026] [security2:error] [pid 139043:tid 139221] [client 20.163.43.14:3024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/bb.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBvgAAALU"] [Tue Aug 18 13:04:18.035076 2026] [security2:error] [pid 139043:tid 139270] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBvwAAAOY"] [Tue Aug 18 13:04:18.038531 2026] [security2:error] [pid 139043:tid 139235] [client 20.48.236.86:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/img.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBwAAAAMM"] [Tue Aug 18 13:04:18.039639 2026] [security2:error] [pid 139043:tid 139289] [client 20.51.153.15:9122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/mimes.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBwgAAAPk"] [Tue Aug 18 13:04:18.044288 2026] [security2:error] [pid 139043:tid 139284] [client 191.237.254.161:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/file1221.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBwwAAAPQ"] [Tue Aug 18 13:04:18.097589 2026] [security2:error] [pid 139043:tid 139209] [client 20.80.111.3:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/customize/about.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBxQAAAKk"] [Tue Aug 18 13:04:18.107880 2026] [security2:error] [pid 139043:tid 139174] [client 172.182.200.96:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBxgAAAIY"] [Tue Aug 18 13:04:18.142211 2026] [security2:error] [pid 139043:tid 139251] [client 20.1.169.243:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/images/class-config.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBygAAANM"] [Tue Aug 18 13:04:18.156058 2026] [security2:error] [pid 139043:tid 139257] [client 20.116.17.175:3428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/file5.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBywAAANk"] [Tue Aug 18 13:04:18.168988 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.154.236:8655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBzAAAAKw"] [Tue Aug 18 13:04:18.226237 2026] [security2:error] [pid 139043:tid 139300] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/scxy.php"] [unique_id "aoSCgv2v-lWn9OzQT7VBzgAAAQQ"] [Tue Aug 18 13:04:18.281881 2026] [security2:error] [pid 139043:tid 139271] [client 20.52.168.85:5286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ini.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB0QAAAOc"] [Tue Aug 18 13:04:18.291289 2026] [security2:error] [pid 139043:tid 139293] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB0gAAAP0"] [Tue Aug 18 13:04:18.304341 2026] [security2:error] [pid 139043:tid 139195] [client 20.186.30.159:10034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/82.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB1AAAAJs"] [Tue Aug 18 13:04:18.305125 2026] [authz_core:error] [pid 139043:tid 139088] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:18.305460 2026] [authz_core:error] [pid 139043:tid 139088] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:18.308215 2026] [security2:error] [pid 139043:tid 139194] [client 68.221.73.131:36017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file15.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB1QAAAJo"] [Tue Aug 18 13:04:18.323058 2026] [security2:error] [pid 139043:tid 139266] [client 172.182.217.32:21529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/Text/php8.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB1wAAAOI"] [Tue Aug 18 13:04:18.333161 2026] [security2:error] [pid 139043:tid 139219] [client 20.51.153.15:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ni.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB2QAAALM"] [Tue Aug 18 13:04:18.337210 2026] [security2:error] [pid 139043:tid 139232] [client 158.23.17.4:56523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/45.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB2gAAAMA"] [Tue Aug 18 13:04:18.348750 2026] [security2:error] [pid 139043:tid 139296] [client 52.139.47.57:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/mar.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB2wAAAQA"] [Tue Aug 18 13:04:18.365870 2026] [security2:error] [pid 139043:tid 139299] [client 68.155.156.252:21170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/nox.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB3wAAAQM"] [Tue Aug 18 13:04:18.398596 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:58628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB4gAAAMQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:18.399491 2026] [security2:error] [pid 139043:tid 139234] [client 74.248.130.103:7928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB4wAAAMI"] [Tue Aug 18 13:04:18.400372 2026] [security2:error] [pid 139043:tid 139294] [client 20.163.43.14:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB5AAAAP4"] [Tue Aug 18 13:04:18.404474 2026] [security2:error] [pid 139043:tid 139223] [client 20.171.51.14:6626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/53.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB5gAAALc"] [Tue Aug 18 13:04:18.408533 2026] [security2:error] [pid 139043:tid 139199] [client 20.226.36.136:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB5wAAAJ8"] [Tue Aug 18 13:04:18.445420 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.200.96:15573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB6AAAAIk"] [Tue Aug 18 13:04:18.447456 2026] [security2:error] [pid 139043:tid 139281] [client 4.232.151.198:38785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB6QAAAPE"] [Tue Aug 18 13:04:18.466804 2026] [security2:error] [pid 139043:tid 139260] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB6gAAANw"] [Tue Aug 18 13:04:18.515065 2026] [security2:error] [pid 139043:tid 139255] [client 4.232.151.198:25276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/js-settings.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB7wAAANc"] [Tue Aug 18 13:04:18.545230 2026] [security2:error] [pid 139043:tid 139185] [client 20.250.13.23:6320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/u.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB8QAAAJE"] [Tue Aug 18 13:04:18.566553 2026] [security2:error] [pid 139043:tid 139239] [client 20.151.109.219:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sb.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB8gAAAMc"] [Tue Aug 18 13:04:18.567668 2026] [security2:error] [pid 139043:tid 139243] [client 20.80.111.3:28207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.111.80.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.formafit.com.br"] [uri "/wp-includes/images/about.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB8wAAAMs"] [Tue Aug 18 13:04:18.593438 2026] [security2:error] [pid 139043:tid 139226] [client 20.226.36.136:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB9QAAALo"] [Tue Aug 18 13:04:18.598677 2026] [security2:error] [pid 139043:tid 139186] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/ws13.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB9gAAAJI"] [Tue Aug 18 13:04:18.613959 2026] [authz_core:error] [pid 139043:tid 139123] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:18.614215 2026] [authz_core:error] [pid 139043:tid 139123] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:18.640383 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:9142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ip.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB-QAAANA"] [Tue Aug 18 13:04:18.665332 2026] [security2:error] [pid 139043:tid 139240] [client 86.120.159.145:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB-gAAAMg"] [Tue Aug 18 13:04:18.666851 2026] [security2:error] [pid 139043:tid 139240] [client 86.120.159.145:61648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB-gAAAMg"] [Tue Aug 18 13:04:18.727695 2026] [security2:error] [pid 139043:tid 139209] [client 20.1.169.243:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/images/index.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB_AAAAKk"] [Tue Aug 18 13:04:18.746695 2026] [security2:error] [pid 139043:tid 139218] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/file.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB_QAAALI"] [Tue Aug 18 13:04:18.766278 2026] [security2:error] [pid 139043:tid 139269] [client 52.139.47.57:31843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/my1.php"] [unique_id "aoSCgv2v-lWn9OzQT7VB_wAAAOU"] [Tue Aug 18 13:04:18.771295 2026] [security2:error] [pid 139043:tid 139257] [client 172.182.200.96:15549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCAQAAANk"] [Tue Aug 18 13:04:18.777215 2026] [security2:error] [pid 139043:tid 139208] [client 4.223.113.180:41039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/php.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCAgAAAKg"] [Tue Aug 18 13:04:18.780547 2026] [security2:error] [pid 139043:tid 139214] [client 20.116.17.175:53533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/yup.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCAwAAAK4"] [Tue Aug 18 13:04:18.783938 2026] [security2:error] [pid 139043:tid 139212] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCBAAAAKw"] [Tue Aug 18 13:04:18.815048 2026] [security2:error] [pid 139043:tid 139241] [client 172.182.217.32:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/ID3/php8.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCBQAAAMk"] [Tue Aug 18 13:04:18.826645 2026] [security2:error] [pid 139043:tid 139280] [client 158.23.17.4:47145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/jn.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCBgAAAPA"] [Tue Aug 18 13:04:18.844346 2026] [security2:error] [pid 139043:tid 139183] [client 20.48.236.86:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/222.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCBwAAAI8"] [Tue Aug 18 13:04:18.889511 2026] [security2:error] [pid 139043:tid 139295] [client 20.52.168.85:5178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/nf.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCCgAAAP8"] [Tue Aug 18 13:04:18.896106 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/conn-test.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCCwAAAPM"] [Tue Aug 18 13:04:18.908314 2026] [security2:error] [pid 139043:tid 139272] [client 168.62.48.100:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCDAAAAOg"] [Tue Aug 18 13:04:18.914884 2026] [security2:error] [pid 139043:tid 139192] [client 20.171.51.14:58031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lq.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCDQAAAJg"] [Tue Aug 18 13:04:18.941750 2026] [authz_core:error] [pid 139043:tid 139112] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:18.942014 2026] [authz_core:error] [pid 139043:tid 139112] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:18.971476 2026] [security2:error] [pid 139043:tid 139195] [client 68.221.73.131:16279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/f35.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCEAAAAJs"] [Tue Aug 18 13:04:18.993186 2026] [security2:error] [pid 139043:tid 139287] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/btx25.php"] [unique_id "aoSCgv2v-lWn9OzQT7VCEQAAAPc"] [Tue Aug 18 13:04:19.013809 2026] [security2:error] [pid 139043:tid 139252] [client 20.51.153.15:9161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/99.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCEwAAANQ"] [Tue Aug 18 13:04:19.014730 2026] [security2:error] [pid 139043:tid 139265] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/epinyins.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCFAAAAOE"] [Tue Aug 18 13:04:19.020081 2026] [security2:error] [pid 139043:tid 139296] [client 20.163.43.14:4364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCFQAAAQA"] [Tue Aug 18 13:04:19.042144 2026] [security2:error] [pid 139043:tid 139188] [client 65.111.8.76:14235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.8.111.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advogadocriminalgoiania.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCGAAAAJQ"], referer: www.google.com [Tue Aug 18 13:04:19.087657 2026] [security2:error] [pid 139043:tid 139249] [client 158.23.17.4:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wy.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCGQAAANE"] [Tue Aug 18 13:04:19.112459 2026] [security2:error] [pid 139043:tid 139194] [client 20.1.169.243:10943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/index/function.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCGgAAAJo"] [Tue Aug 18 13:04:19.133969 2026] [security2:error] [pid 139043:tid 139281] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCHAAAAPE"] [Tue Aug 18 13:04:19.134793 2026] [security2:error] [pid 139043:tid 139274] [client 172.182.200.96:15568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCHQAAAOo"] [Tue Aug 18 13:04:19.166662 2026] [security2:error] [pid 139043:tid 139254] [client 4.232.151.198:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ad24f.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCHgAAANY"] [Tue Aug 18 13:04:19.181807 2026] [security2:error] [pid 139043:tid 139299] [client 52.139.47.57:37322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/mm.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCHwAAAQM"] [Tue Aug 18 13:04:19.210053 2026] [security2:error] [pid 139043:tid 139263] [client 20.151.109.219:33511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xj.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCIgAAAN8"] [Tue Aug 18 13:04:19.284535 2026] [security2:error] [pid 139043:tid 139268] [client 20.226.36.136:43392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCLAAAAOQ"] [Tue Aug 18 13:04:19.289361 2026] [security2:error] [pid 139043:tid 139178] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCLQAAAIo"] [Tue Aug 18 13:04:19.299055 2026] [security2:error] [pid 139043:tid 139198] [client 20.48.236.86:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/key.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCNAAAAJ4"] [Tue Aug 18 13:04:19.315670 2026] [security2:error] [pid 139043:tid 139211] [client 172.182.217.32:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/img/php8.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCNgAAAKs"] [Tue Aug 18 13:04:19.331541 2026] [security2:error] [pid 139043:tid 139282] [client 20.51.153.15:8406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/er.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCNwAAAPI"] [Tue Aug 18 13:04:19.370699 2026] [security2:error] [pid 139043:tid 139240] [client 20.151.109.219:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/evil.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCOQAAAMg"] [Tue Aug 18 13:04:19.383764 2026] [security2:error] [pid 139043:tid 139270] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCOgAAAOY"] [Tue Aug 18 13:04:19.421520 2026] [security2:error] [pid 139043:tid 139199] [client 213.35.127.232:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCPQAAAJ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:19.424307 2026] [security2:error] [pid 139043:tid 139218] [client 20.163.43.14:4376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCPgAAALI"] [Tue Aug 18 13:04:19.435944 2026] [security2:error] [pid 139043:tid 139244] [client 20.250.13.23:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/customize.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCQAAAAMw"] [Tue Aug 18 13:04:19.440823 2026] [security2:error] [pid 139043:tid 139251] [client 20.171.51.14:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/you.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCQQAAANM"] [Tue Aug 18 13:04:19.464517 2026] [security2:error] [pid 139043:tid 139262] [client 74.248.130.103:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/i.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCQgAAAN4"] [Tue Aug 18 13:04:19.466405 2026] [security2:error] [pid 139043:tid 139208] [client 20.186.30.159:10026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/dex.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCQwAAAKg"] [Tue Aug 18 13:04:19.478023 2026] [security2:error] [pid 139043:tid 139248] [client 20.1.169.243:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/info.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCRAAAANA"] [Tue Aug 18 13:04:19.493353 2026] [security2:error] [pid 139043:tid 139186] [client 20.52.168.85:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/room.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCRQAAAJI"] [Tue Aug 18 13:04:19.501785 2026] [security2:error] [pid 139043:tid 139241] [client 168.62.48.100:5579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCSAAAAMk"] [Tue Aug 18 13:04:19.505648 2026] [security2:error] [pid 139043:tid 139180] [client 20.226.36.136:57251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCSQAAAIw"] [Tue Aug 18 13:04:19.509344 2026] [security2:error] [pid 139043:tid 139213] [client 172.182.200.96:15545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCSgAAAK0"] [Tue Aug 18 13:04:19.524206 2026] [security2:error] [pid 139043:tid 139202] [client 20.251.48.93:22132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCSwAAAKI"] [Tue Aug 18 13:04:19.571637 2026] [security2:error] [pid 139043:tid 139283] [client 20.51.153.15:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/qk.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCUAAAAPM"] [Tue Aug 18 13:04:19.591495 2026] [security2:error] [pid 139043:tid 139192] [client 158.23.17.4:8757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ariatec.com.br"] [uri "/bf.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCUwAAAJg"] [Tue Aug 18 13:04:19.628794 2026] [security2:error] [pid 139043:tid 139212] [client 52.139.47.57:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/network.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCVQAAAKw"] [Tue Aug 18 13:04:19.657256 2026] [security2:error] [pid 139043:tid 139252] [client 20.116.17.175:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/classwithtostring.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCVwAAANQ"] [Tue Aug 18 13:04:19.674091 2026] [security2:error] [pid 139043:tid 139230] [client 136.144.33.45:42861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "netfactory.com.br"] [uri "/wp-login.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCOAAAAL4"] [Tue Aug 18 13:04:19.700669 2026] [security2:error] [pid 139043:tid 139261] [client 20.226.36.136:43689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCWgAAAN0"] [Tue Aug 18 13:04:19.709170 2026] [security2:error] [pid 139043:tid 139278] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCWwAAAO4"] [Tue Aug 18 13:04:19.723245 2026] [security2:error] [pid 139043:tid 139236] [client 20.215.241.237:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/sf.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCXAAAAMQ"] [Tue Aug 18 13:04:19.764593 2026] [security2:error] [pid 139043:tid 139237] [client 20.163.43.14:3008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/file.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCXwAAAMU"] [Tue Aug 18 13:04:19.781261 2026] [security2:error] [pid 139043:tid 139260] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCYwAAANw"] [Tue Aug 18 13:04:19.786414 2026] [security2:error] [pid 139043:tid 139238] [client 20.104.100.201:23994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/output.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCZAAAAMY"] [Tue Aug 18 13:04:19.794905 2026] [security2:error] [pid 139043:tid 139274] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCZQAAAOo"] [Tue Aug 18 13:04:19.801545 2026] [security2:error] [pid 139043:tid 139271] [client 4.232.151.198:18547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/images/class-config.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCZgAAAOc"] [Tue Aug 18 13:04:19.801663 2026] [security2:error] [pid 139043:tid 139193] [client 172.182.217.32:21388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/languages/php8.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCZwAAAJk"] [Tue Aug 18 13:04:19.813805 2026] [authz_core:error] [pid 139043:tid 139144] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:19.814058 2026] [authz_core:error] [pid 139043:tid 139144] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:19.833202 2026] [security2:error] [pid 139043:tid 139216] [client 20.51.153.15:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCawAAALA"] [Tue Aug 18 13:04:19.841763 2026] [security2:error] [pid 139043:tid 139227] [client 20.1.169.243:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/install.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCbAAAALs"] [Tue Aug 18 13:04:19.852190 2026] [security2:error] [pid 139043:tid 139255] [client 172.182.200.96:15615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCbQAAANc"] [Tue Aug 18 13:04:19.944796 2026] [security2:error] [pid 139043:tid 139239] [client 20.171.51.14:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ez.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCcgAAAMc"] [Tue Aug 18 13:04:19.996597 2026] [security2:error] [pid 139043:tid 139282] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCg_2v-lWn9OzQT7VCewAAAPI"] [Tue Aug 18 13:04:20.014853 2026] [security2:error] [pid 139043:tid 139235] [client 20.48.236.86:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/chosen.php"] [unique_id "aoSChP2v-lWn9OzQT7VCgAAAAMM"] [Tue Aug 18 13:04:20.032816 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:36727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ns.php"] [unique_id "aoSChP2v-lWn9OzQT7VCgQAAAPk"] [Tue Aug 18 13:04:20.042737 2026] [security2:error] [pid 139043:tid 139175] [client 52.139.47.57:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/new.php"] [unique_id "aoSChP2v-lWn9OzQT7VCggAAAIc"] [Tue Aug 18 13:04:20.095642 2026] [security2:error] [pid 139043:tid 139174] [client 20.51.153.15:9134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fs.php"] [unique_id "aoSChP2v-lWn9OzQT7VChwAAAIY"] [Tue Aug 18 13:04:20.096415 2026] [security2:error] [pid 139043:tid 139218] [client 20.226.36.136:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/first.php"] [unique_id "aoSChP2v-lWn9OzQT7VCiAAAALI"] [Tue Aug 18 13:04:20.098949 2026] [security2:error] [pid 139043:tid 139185] [client 20.52.168.85:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-contentt.php"] [unique_id "aoSChP2v-lWn9OzQT7VCiQAAAJE"] [Tue Aug 18 13:04:20.114584 2026] [authz_core:error] [pid 139043:tid 139114] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:20.114861 2026] [authz_core:error] [pid 139043:tid 139114] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:20.125582 2026] [security2:error] [pid 139043:tid 139209] [client 20.163.43.14:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/epinyins.php"] [unique_id "aoSChP2v-lWn9OzQT7VCjQAAAKk"] [Tue Aug 18 13:04:20.145916 2026] [security2:error] [pid 139043:tid 139291] [client 20.151.109.219:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vu.php"] [unique_id "aoSChP2v-lWn9OzQT7VCjwAAAPs"] [Tue Aug 18 13:04:20.147292 2026] [security2:error] [pid 139043:tid 139286] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCkAAAAPY"] [Tue Aug 18 13:04:20.173089 2026] [security2:error] [pid 139043:tid 139183] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSChP2v-lWn9OzQT7VCkQAAAI8"] [Tue Aug 18 13:04:20.210258 2026] [security2:error] [pid 139043:tid 139199] [client 20.1.169.243:11179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/item.php"] [unique_id "aoSChP2v-lWn9OzQT7VClAAAAJ8"] [Tue Aug 18 13:04:20.252089 2026] [security2:error] [pid 139043:tid 139192] [client 172.182.200.96:15506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSChP2v-lWn9OzQT7VClwAAAJg"] [Tue Aug 18 13:04:20.254268 2026] [security2:error] [pid 139043:tid 139217] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp.php"] [unique_id "aoSChP2v-lWn9OzQT7VCmAAAALE"] [Tue Aug 18 13:04:20.262142 2026] [security2:error] [pid 139043:tid 139195] [client 68.221.73.131:43116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSChP2v-lWn9OzQT7VCmQAAAJs"] [Tue Aug 18 13:04:20.292265 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.217.32:22219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/customize/php8.php"] [unique_id "aoSChP2v-lWn9OzQT7VCmgAAANA"] [Tue Aug 18 13:04:20.334396 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/mah/function.php"] [unique_id "aoSChP2v-lWn9OzQT7VCoQAAAMI"] [Tue Aug 18 13:04:20.372872 2026] [security2:error] [pid 139043:tid 139253] [client 20.226.36.136:35523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCogAAANU"] [Tue Aug 18 13:04:20.389883 2026] [security2:error] [pid 139043:tid 139238] [client 74.248.130.103:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSChP2v-lWn9OzQT7VCpAAAAMY"] [Tue Aug 18 13:04:20.416380 2026] [authz_core:error] [pid 139043:tid 139139] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:20.416688 2026] [authz_core:error] [pid 139043:tid 139139] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:20.425552 2026] [security2:error] [pid 139043:tid 139216] [client 20.151.109.219:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/wp-key.php"] [unique_id "aoSChP2v-lWn9OzQT7VCqQAAALA"] [Tue Aug 18 13:04:20.428019 2026] [security2:error] [pid 139043:tid 139187] [client 68.221.73.131:47768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-load.php"] [unique_id "aoSChP2v-lWn9OzQT7VCqgAAAJM"] [Tue Aug 18 13:04:20.434700 2026] [security2:error] [pid 139043:tid 139283] [client 4.232.151.198:7735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ranger.php"] [unique_id "aoSChP2v-lWn9OzQT7VCqwAAAPM"] [Tue Aug 18 13:04:20.435703 2026] [security2:error] [pid 139043:tid 139298] [client 40.74.65.169:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSChP2v-lWn9OzQT7VCrAAAAQI"] [Tue Aug 18 13:04:20.440227 2026] [security2:error] [pid 139043:tid 139258] [client 213.35.127.232:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCrQAAANo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:20.487627 2026] [security2:error] [pid 139043:tid 139188] [client 52.139.47.57:33826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/0x.php"] [unique_id "aoSChP2v-lWn9OzQT7VCsgAAAJQ"] [Tue Aug 18 13:04:20.490265 2026] [security2:error] [pid 139043:tid 139182] [client 20.163.43.14:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCtAAAAI4"] [Tue Aug 18 13:04:20.492486 2026] [security2:error] [pid 139043:tid 139232] [client 20.51.153.15:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/rb.php"] [unique_id "aoSChP2v-lWn9OzQT7VCtQAAAMA"] [Tue Aug 18 13:04:20.509573 2026] [security2:error] [pid 139043:tid 139288] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/function/function.php"] [unique_id "aoSChP2v-lWn9OzQT7VCuAAAAPg"] [Tue Aug 18 13:04:20.516404 2026] [security2:error] [pid 139043:tid 139226] [client 158.23.17.4:25400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/f.php"] [unique_id "aoSChP2v-lWn9OzQT7VCuQAAALo"] [Tue Aug 18 13:04:20.529326 2026] [security2:error] [pid 139043:tid 139243] [client 20.116.17.175:3414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-the.php"] [unique_id "aoSChP2v-lWn9OzQT7VCuwAAAMs"] [Tue Aug 18 13:04:20.544654 2026] [security2:error] [pid 139043:tid 139224] [client 20.151.109.219:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gk.php"] [unique_id "aoSChP2v-lWn9OzQT7VCvAAAALg"] [Tue Aug 18 13:04:20.562450 2026] [security2:error] [pid 139043:tid 139250] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/sky.php"] [unique_id "aoSChP2v-lWn9OzQT7VCvwAAANI"] [Tue Aug 18 13:04:20.571584 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSChP2v-lWn9OzQT7VCwAAAAP0"] [Tue Aug 18 13:04:20.575868 2026] [security2:error] [pid 139043:tid 139184] [client 20.1.169.243:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/kir.php"] [unique_id "aoSChP2v-lWn9OzQT7VCxwAAAJA"] [Tue Aug 18 13:04:20.579015 2026] [security2:error] [pid 139043:tid 139261] [client 20.250.13.23:41738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/inputs.php"] [unique_id "aoSChP2v-lWn9OzQT7VCyAAAAN0"] [Tue Aug 18 13:04:20.592130 2026] [security2:error] [pid 139043:tid 139221] [client 172.182.200.96:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCygAAALU"] [Tue Aug 18 13:04:20.612250 2026] [security2:error] [pid 139043:tid 139284] [client 20.226.36.136:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VCzQAAAPQ"] [Tue Aug 18 13:04:20.627543 2026] [security2:error] [pid 139043:tid 139174] [client 20.171.51.14:9952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/asus.php"] [unique_id "aoSChP2v-lWn9OzQT7VCzgAAAIY"] [Tue Aug 18 13:04:20.641325 2026] [security2:error] [pid 139043:tid 139244] [client 52.173.121.69:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSChP2v-lWn9OzQT7VCzwAAAMw"] [Tue Aug 18 13:04:20.648071 2026] [security2:error] [pid 139043:tid 139228] [client 20.251.48.93:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/av.php"] [unique_id "aoSChP2v-lWn9OzQT7VC0AAAALw"] [Tue Aug 18 13:04:20.692008 2026] [security2:error] [pid 139043:tid 139186] [client 20.48.236.86:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/wpxml.php"] [unique_id "aoSChP2v-lWn9OzQT7VC1AAAAJI"] [Tue Aug 18 13:04:20.698946 2026] [security2:error] [pid 139043:tid 139239] [client 20.52.168.85:5168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/input.php"] [unique_id "aoSChP2v-lWn9OzQT7VC1wAAAMc"] [Tue Aug 18 13:04:20.717622 2026] [authz_core:error] [pid 139043:tid 139150] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:20.717944 2026] [authz_core:error] [pid 139043:tid 139150] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:20.758933 2026] [security2:error] [pid 139043:tid 139199] [client 4.223.113.180:41059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSChP2v-lWn9OzQT7VC2gAAAJ8"] [Tue Aug 18 13:04:20.764916 2026] [security2:error] [pid 139043:tid 139205] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSChP2v-lWn9OzQT7VC2wAAAKU"] [Tue Aug 18 13:04:20.782177 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.217.32:21530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes.bak/html-api/php8.php"] [unique_id "aoSChP2v-lWn9OzQT7VC3QAAAOs"] [Tue Aug 18 13:04:20.796629 2026] [security2:error] [pid 139043:tid 139287] [client 68.155.156.252:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/akismet.php"] [unique_id "aoSChP2v-lWn9OzQT7VC3wAAAPc"] [Tue Aug 18 13:04:20.803050 2026] [security2:error] [pid 139043:tid 139248] [client 20.51.153.15:8795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/37.php"] [unique_id "aoSChP2v-lWn9OzQT7VC4AAAANA"] [Tue Aug 18 13:04:20.887487 2026] [security2:error] [pid 139043:tid 139294] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSChP2v-lWn9OzQT7VC4wAAAP4"] [Tue Aug 18 13:04:20.901150 2026] [security2:error] [pid 139043:tid 139210] [client 52.139.47.57:37320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/0.php"] [unique_id "aoSChP2v-lWn9OzQT7VC5QAAAKo"] [Tue Aug 18 13:04:20.906890 2026] [security2:error] [pid 139043:tid 139249] [client 20.226.36.136:57809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VC5gAAANE"] [Tue Aug 18 13:04:20.912773 2026] [security2:error] [pid 139043:tid 139246] [client 102.213.179.104:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSChP2v-lWn9OzQT7VC6AAAAM4"] [Tue Aug 18 13:04:20.913050 2026] [security2:error] [pid 139043:tid 139277] [client 20.186.30.159:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/puc.php"] [unique_id "aoSChP2v-lWn9OzQT7VC5wAAAO0"] [Tue Aug 18 13:04:20.913406 2026] [security2:error] [pid 139043:tid 139246] [client 102.213.179.104:60476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSChP2v-lWn9OzQT7VC6AAAAM4"] [Tue Aug 18 13:04:20.924788 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.200.96:15606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSChP2v-lWn9OzQT7VC6QAAAIk"] [Tue Aug 18 13:04:20.951920 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:6328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/filter.php"] [unique_id "aoSChP2v-lWn9OzQT7VC6wAAAQE"] [Tue Aug 18 13:04:20.963362 2026] [security2:error] [pid 139043:tid 139271] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/file5.php"] [unique_id "aoSChP2v-lWn9OzQT7VC7wAAAOc"] [Tue Aug 18 13:04:21.020969 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:21.021231 2026] [authz_core:error] [pid 139043:tid 139138] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:21.062816 2026] [security2:error] [pid 139043:tid 139232] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSChf2v-lWn9OzQT7VC9wAAAMA"] [Tue Aug 18 13:04:21.063615 2026] [security2:error] [pid 139043:tid 139278] [client 4.232.151.198:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/indexmat_crea.php"] [unique_id "aoSChf2v-lWn9OzQT7VC-AAAAO4"] [Tue Aug 18 13:04:21.086491 2026] [security2:error] [pid 139043:tid 139178] [client 20.116.17.175:56065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/cong.php"] [unique_id "aoSChf2v-lWn9OzQT7VC-gAAAIo"] [Tue Aug 18 13:04:21.105967 2026] [security2:error] [pid 139043:tid 139201] [client 20.151.109.219:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wn.php"] [unique_id "aoSChf2v-lWn9OzQT7VC-wAAAKE"] [Tue Aug 18 13:04:21.119438 2026] [security2:error] [pid 139043:tid 139167] [remote 216.38.28.47:46686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSChf2v-lWn9OzQT7VC_AAAwns"] [Tue Aug 18 13:04:21.134407 2026] [security2:error] [pid 139043:tid 139292] [client 20.1.169.243:11183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/log.php"] [unique_id "aoSChf2v-lWn9OzQT7VC_QAAAPw"] [Tue Aug 18 13:04:21.134470 2026] [security2:error] [pid 139043:tid 139252] [client 65.111.8.76:28861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.8.111.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advogadocriminalgoiania.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSChf2v-lWn9OzQT7VC_gAAANQ"], referer: www.google.com [Tue Aug 18 13:04:21.158875 2026] [security2:error] [pid 139043:tid 139282] [client 20.48.236.86:16205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/file1221.php"] [unique_id "aoSChf2v-lWn9OzQT7VDAAAAAPI"] [Tue Aug 18 13:04:21.175939 2026] [security2:error] [pid 139043:tid 139261] [client 20.51.153.15:8805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/md.php"] [unique_id "aoSChf2v-lWn9OzQT7VDAwAAAN0"] [Tue Aug 18 13:04:21.176052 2026] [security2:error] [pid 139043:tid 139279] [client 20.206.73.37:1677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/file5.php"] [unique_id "aoSChf2v-lWn9OzQT7VDAgAAAO8"] [Tue Aug 18 13:04:21.179131 2026] [security2:error] [pid 139043:tid 139270] [client 20.104.100.201:24060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/tiny2.php"] [unique_id "aoSChf2v-lWn9OzQT7VDBAAAAOY"] [Tue Aug 18 13:04:21.224284 2026] [security2:error] [pid 139043:tid 139273] [client 20.163.43.14:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDBgAAAOk"] [Tue Aug 18 13:04:21.257425 2026] [security2:error] [pid 139043:tid 139245] [client 20.171.51.14:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/22.php"] [unique_id "aoSChf2v-lWn9OzQT7VDDQAAAM0"] [Tue Aug 18 13:04:21.268343 2026] [security2:error] [pid 139043:tid 139198] [client 172.182.217.32:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/widgets/php8.php"] [unique_id "aoSChf2v-lWn9OzQT7VDGAAAAJ4"] [Tue Aug 18 13:04:21.290393 2026] [security2:error] [pid 139043:tid 139239] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSChf2v-lWn9OzQT7VDIAAAAMc"] [Tue Aug 18 13:04:21.307094 2026] [security2:error] [pid 139043:tid 139243] [client 20.52.168.85:5739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/disagreed.php"] [unique_id "aoSChf2v-lWn9OzQT7VDIgAAAMs"] [Tue Aug 18 13:04:21.323170 2026] [security2:error] [pid 139043:tid 139275] [client 20.226.36.136:57222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/blog/byp.php"] [unique_id "aoSChf2v-lWn9OzQT7VDKgAAAOs"] [Tue Aug 18 13:04:21.324495 2026] [security2:error] [pid 139043:tid 139289] [client 52.139.47.57:37523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/oxshell.php"] [unique_id "aoSChf2v-lWn9OzQT7VDLQAAAPk"] [Tue Aug 18 13:04:21.326213 2026] [security2:error] [pid 139043:tid 139173] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/ok.php"] [unique_id "aoSChf2v-lWn9OzQT7VDLwAAAIU"] [Tue Aug 18 13:04:21.379133 2026] [security2:error] [pid 139043:tid 139242] [client 74.248.130.103:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-manager.php"] [unique_id "aoSChf2v-lWn9OzQT7VDNQAAAMo"] [Tue Aug 18 13:04:21.400955 2026] [security2:error] [pid 139043:tid 139253] [client 20.151.109.219:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ic.php"] [unique_id "aoSChf2v-lWn9OzQT7VDNgAAANU"] [Tue Aug 18 13:04:21.423572 2026] [security2:error] [pid 139043:tid 139238] [client 158.23.17.4:40397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/30.php"] [unique_id "aoSChf2v-lWn9OzQT7VDOQAAAMY"] [Tue Aug 18 13:04:21.442559 2026] [security2:error] [pid 139043:tid 139274] [client 47.128.30.69:13382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mahokosveiculos.com.br"] [uri "/robots.txt"] [unique_id "aoSChf2v-lWn9OzQT7VDOwAAAOo"] [Tue Aug 18 13:04:21.460505 2026] [security2:error] [pid 139043:tid 139211] [client 213.35.127.232:59221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSChf2v-lWn9OzQT7VDPAAAAKs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:21.498544 2026] [security2:error] [pid 139043:tid 139210] [client 20.1.169.243:11233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/logins.php"] [unique_id "aoSChf2v-lWn9OzQT7VDQAAAAKo"] [Tue Aug 18 13:04:21.540213 2026] [security2:error] [pid 139043:tid 139188] [client 20.48.236.86:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/nox.php"] [unique_id "aoSChf2v-lWn9OzQT7VDTgAAAJQ"] [Tue Aug 18 13:04:21.605884 2026] [security2:error] [pid 139043:tid 139250] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.markettohome.com.br"] [uri "/item.php"] [unique_id "aoSChf2v-lWn9OzQT7VDVwAAANI"] [Tue Aug 18 13:04:21.633815 2026] [security2:error] [pid 139043:tid 139279] [client 168.62.48.100:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSChf2v-lWn9OzQT7VDWQAAAO8"] [Tue Aug 18 13:04:21.666555 2026] [security2:error] [pid 139043:tid 139270] [client 20.163.43.14:4401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDWwAAAOY"] [Tue Aug 18 13:04:21.676173 2026] [security2:error] [pid 139043:tid 139197] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDXQAAAJ0"] [Tue Aug 18 13:04:21.721330 2026] [security2:error] [pid 139043:tid 139232] [client 20.250.13.23:55667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/input.php"] [unique_id "aoSChf2v-lWn9OzQT7VDYAAAAMA"] [Tue Aug 18 13:04:21.744579 2026] [security2:error] [pid 139043:tid 139292] [client 52.139.47.57:37323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/php8.php"] [unique_id "aoSChf2v-lWn9OzQT7VDYQAAAPw"] [Tue Aug 18 13:04:21.755907 2026] [security2:error] [pid 139043:tid 139201] [client 172.182.217.32:21564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/IXR/php8.php"] [unique_id "aoSChf2v-lWn9OzQT7VDYwAAAKE"] [Tue Aug 18 13:04:21.758086 2026] [security2:error] [pid 139043:tid 139245] [client 191.237.254.161:33548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/nox.php"] [unique_id "aoSChf2v-lWn9OzQT7VDZAAAAM0"] [Tue Aug 18 13:04:21.762499 2026] [security2:error] [pid 139043:tid 139214] [client 20.104.100.201:23939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wpxml.php"] [unique_id "aoSChf2v-lWn9OzQT7VDZgAAAK4"] [Tue Aug 18 13:04:21.765001 2026] [security2:error] [pid 139043:tid 139215] [client 4.232.151.198:7700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/geju.php"] [unique_id "aoSChf2v-lWn9OzQT7VDZwAAAK8"] [Tue Aug 18 13:04:21.782588 2026] [security2:error] [pid 139043:tid 139186] [client 20.116.17.175:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/xwpg.php"] [unique_id "aoSChf2v-lWn9OzQT7VDaAAAAJI"] [Tue Aug 18 13:04:21.812007 2026] [security2:error] [pid 139043:tid 139239] [client 20.226.36.136:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDawAAAMc"] [Tue Aug 18 13:04:21.862625 2026] [security2:error] [pid 139043:tid 139228] [client 20.1.169.243:11185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/mailer.php"] [unique_id "aoSChf2v-lWn9OzQT7VDbgAAALw"] [Tue Aug 18 13:04:21.902689 2026] [security2:error] [pid 139043:tid 139195] [client 20.51.153.15:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/iy.php"] [unique_id "aoSChf2v-lWn9OzQT7VDcgAAAJs"] [Tue Aug 18 13:04:21.902810 2026] [security2:error] [pid 139043:tid 139212] [client 20.250.13.23:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/admin.php"] [unique_id "aoSChf2v-lWn9OzQT7VDcwAAAKw"] [Tue Aug 18 13:04:21.922545 2026] [security2:error] [pid 139043:tid 139185] [client 20.52.168.85:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/defaults.php"] [unique_id "aoSChf2v-lWn9OzQT7VDdAAAAJE"] [Tue Aug 18 13:04:21.942591 2026] [security2:error] [pid 139043:tid 139298] [client 149.34.210.141:53101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSChf2v-lWn9OzQT7VDdgAAAQI"] [Tue Aug 18 13:04:21.945208 2026] [authz_core:error] [pid 139043:tid 139058] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:21.945481 2026] [authz_core:error] [pid 139043:tid 139058] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:21.953138 2026] [security2:error] [pid 139043:tid 139222] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDcAAAALY"], referer: http://blog.tinna.com.br [Tue Aug 18 13:04:21.970629 2026] [security2:error] [pid 139043:tid 139294] [client 20.206.73.37:29993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/fz.php"] [unique_id "aoSChf2v-lWn9OzQT7VDegAAAP4"] [Tue Aug 18 13:04:21.975661 2026] [security2:error] [pid 139043:tid 139296] [client 20.171.51.14:7913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/zs.php"] [unique_id "aoSChf2v-lWn9OzQT7VDfAAAAQA"] [Tue Aug 18 13:04:21.992899 2026] [security2:error] [pid 139043:tid 139208] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSChf2v-lWn9OzQT7VDfgAAAKg"] [Tue Aug 18 13:04:22.028406 2026] [security2:error] [pid 139043:tid 139211] [client 20.151.109.219:58713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ue.php"] [unique_id "aoSChv2v-lWn9OzQT7VDgAAAAKs"] [Tue Aug 18 13:04:22.100458 2026] [security2:error] [pid 139043:tid 139299] [client 20.48.236.86:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/akismet.php"] [unique_id "aoSChv2v-lWn9OzQT7VDhgAAAQM"] [Tue Aug 18 13:04:22.152399 2026] [security2:error] [pid 139043:tid 139282] [client 68.221.73.131:47779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSChv2v-lWn9OzQT7VDigAAAPI"] [Tue Aug 18 13:04:22.160547 2026] [security2:error] [pid 139043:tid 139229] [client 52.139.47.57:29239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/p.php"] [unique_id "aoSChv2v-lWn9OzQT7VDjQAAAL0"] [Tue Aug 18 13:04:22.162877 2026] [security2:error] [pid 139043:tid 139268] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSChv2v-lWn9OzQT7VDiAAA5AM"] [Tue Aug 18 13:04:22.209890 2026] [security2:error] [pid 139043:tid 139298] [client 149.34.210.141:53101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSChf2v-lWn9OzQT7VDdgAAAQI"] [Tue Aug 18 13:04:22.223011 2026] [authz_core:error] [pid 139043:tid 139133] [remote 57.141.22.39:61172] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:22.223249 2026] [authz_core:error] [pid 139043:tid 139133] [remote 57.141.22.39:61172] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:22.229196 2026] [security2:error] [pid 139043:tid 139263] [client 20.1.169.243:10890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/min.php"] [unique_id "aoSChv2v-lWn9OzQT7VDkQAAAN8"] [Tue Aug 18 13:04:22.234753 2026] [security2:error] [pid 139043:tid 139174] [client 158.23.17.4:25362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pu.php"] [unique_id "aoSChv2v-lWn9OzQT7VDkgAAAIY"] [Tue Aug 18 13:04:22.236385 2026] [security2:error] [pid 139043:tid 139273] [client 20.186.30.159:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/inso.php"] [unique_id "aoSChv2v-lWn9OzQT7VDkwAAAOk"] [Tue Aug 18 13:04:22.243364 2026] [authz_core:error] [pid 139043:tid 139143] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:22.243637 2026] [authz_core:error] [pid 139043:tid 139143] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:22.244246 2026] [security2:error] [pid 139043:tid 139258] [client 172.182.217.32:21389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/js/php8.php"] [unique_id "aoSChv2v-lWn9OzQT7VDlgAAANo"] [Tue Aug 18 13:04:22.261431 2026] [security2:error] [pid 139043:tid 139235] [client 20.104.100.201:24034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSChv2v-lWn9OzQT7VDlwAAAMM"] [Tue Aug 18 13:04:22.273932 2026] [security2:error] [pid 139043:tid 139272] [client 20.163.43.14:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp.php"] [unique_id "aoSChv2v-lWn9OzQT7VDmAAAAOg"] [Tue Aug 18 13:04:22.297232 2026] [security2:error] [pid 139043:tid 139218] [client 172.182.200.96:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/first.php"] [unique_id "aoSChv2v-lWn9OzQT7VDmQAAALI"] [Tue Aug 18 13:04:22.298129 2026] [security2:error] [pid 139043:tid 139244] [client 20.226.36.136:43701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSChv2v-lWn9OzQT7VDmgAAAMw"] [Tue Aug 18 13:04:22.310470 2026] [security2:error] [pid 139043:tid 139206] [client 20.51.153.15:9204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/og.php"] [unique_id "aoSChv2v-lWn9OzQT7VDmwAAAKY"] [Tue Aug 18 13:04:22.315741 2026] [security2:error] [pid 139043:tid 139292] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSChv2v-lWn9OzQT7VDnAAAAPw"] [Tue Aug 18 13:04:22.350388 2026] [security2:error] [pid 139043:tid 139245] [client 74.248.130.103:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSChv2v-lWn9OzQT7VDngAAAM0"] [Tue Aug 18 13:04:22.356370 2026] [security2:error] [pid 139043:tid 139257] [client 20.116.17.175:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/dex.php"] [unique_id "aoSChv2v-lWn9OzQT7VDnwAAANk"] [Tue Aug 18 13:04:22.358963 2026] [security2:error] [pid 139043:tid 139234] [client 20.250.13.23:6277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/jquery.php"] [unique_id "aoSChv2v-lWn9OzQT7VDoAAAAMI"] [Tue Aug 18 13:04:22.376484 2026] [security2:error] [pid 139043:tid 139291] [client 216.244.66.243:44546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/8888bet.com-2/"] [unique_id "aoSChv2v-lWn9OzQT7VDoQAAAPs"] [Tue Aug 18 13:04:22.376592 2026] [security2:error] [pid 139043:tid 139291] [client 216.244.66.243:44546] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/8888bet.com-2/"] [unique_id "aoSChv2v-lWn9OzQT7VDoQAAAPs"] [Tue Aug 18 13:04:22.404960 2026] [security2:error] [pid 139043:tid 139270] [client 4.232.151.198:7692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/maro.php"] [unique_id "aoSChv2v-lWn9OzQT7VDowAAAOY"] [Tue Aug 18 13:04:22.413404 2026] [security2:error] [pid 139043:tid 139221] [client 185.191.171.6:41066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754299030/1756598400/"] [unique_id "aoSChv2v-lWn9OzQT7VDpAAAALU"] [Tue Aug 18 13:04:22.413495 2026] [security2:error] [pid 139043:tid 139221] [client 185.191.171.6:41066] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754299030/1756598400/"] [unique_id "aoSChv2v-lWn9OzQT7VDpAAAALU"] [Tue Aug 18 13:04:22.433822 2026] [security2:error] [pid 139043:tid 139241] [client 20.48.236.86:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/admin.php"] [unique_id "aoSChv2v-lWn9OzQT7VDpwAAAMk"] [Tue Aug 18 13:04:22.474543 2026] [security2:error] [pid 139043:tid 139178] [client 213.35.127.232:59431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSChv2v-lWn9OzQT7VDqgAAAIo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:22.474615 2026] [security2:error] [pid 139043:tid 139195] [client 20.171.51.14:13415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/iz.php"] [unique_id "aoSChv2v-lWn9OzQT7VDqQAAAJs"] [Tue Aug 18 13:04:22.496179 2026] [security2:error] [pid 139043:tid 139212] [client 168.62.48.100:5558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/mt/byp.php"] [unique_id "aoSChv2v-lWn9OzQT7VDqwAAAKw"] [Tue Aug 18 13:04:22.506053 2026] [security2:error] [pid 139043:tid 139060] [remote 216.194.122.158:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSChv2v-lWn9OzQT7VDrAAA7xA"] [Tue Aug 18 13:04:22.561713 2026] [security2:error] [pid 139043:tid 139179] [client 20.226.36.136:43681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.comatmotos.com.br"] [uri "/images/security.php"] [unique_id "aoSChv2v-lWn9OzQT7VDrwAAAIs"] [Tue Aug 18 13:04:22.568026 2026] [security2:error] [pid 139043:tid 139198] [client 20.52.168.85:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/kyami.php"] [unique_id "aoSChv2v-lWn9OzQT7VDsQAAAJ4"] [Tue Aug 18 13:04:22.575819 2026] [security2:error] [pid 139043:tid 139202] [client 52.139.47.57:26367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/php.php"] [unique_id "aoSChv2v-lWn9OzQT7VDsgAAAKI"] [Tue Aug 18 13:04:22.635668 2026] [security2:error] [pid 139043:tid 139249] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/well-known/index.php"] [unique_id "aoSChv2v-lWn9OzQT7VDtwAAANE"] [Tue Aug 18 13:04:22.657772 2026] [security2:error] [pid 139043:tid 139253] [client 20.251.48.93:39629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/images.php"] [unique_id "aoSChv2v-lWn9OzQT7VDuAAAANU"] [Tue Aug 18 13:04:22.668636 2026] [security2:error] [pid 139043:tid 139208] [client 2602:ffe4:8:1001::4:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/sp/hortolandia/jardim-boa-esperanca/img/rua-da-garca-jardim-boa-esperanca-hortolandia-sp.webp"] [unique_id "aoSChv2v-lWn9OzQT7VDuwAAAKg"], referer: https://www.icep.com.br/livrocep/sp/hortolandia/jardim-boa-esperanca/rua-da-garca-cep-13183373/ [Tue Aug 18 13:04:22.673466 2026] [security2:error] [pid 139043:tid 139225] [client 172.182.200.96:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSChv2v-lWn9OzQT7VDvAAAALk"] [Tue Aug 18 13:04:22.682280 2026] [security2:error] [pid 139043:tid 139238] [client 20.206.73.37:21291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/xyn.php"] [unique_id "aoSChv2v-lWn9OzQT7VDvQAAAMY"] [Tue Aug 18 13:04:22.716575 2026] [security2:error] [pid 139043:tid 139207] [client 20.163.43.14:2962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/function/function.php"] [unique_id "aoSChv2v-lWn9OzQT7VDvwAAAKc"] [Tue Aug 18 13:04:22.719788 2026] [security2:error] [pid 139043:tid 139289] [client 20.250.13.23:41748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/goods.php"] [unique_id "aoSChv2v-lWn9OzQT7VDwQAAAPk"] [Tue Aug 18 13:04:22.738107 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.217.32:21412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/.well-known/pki-validation/php8.php"] [unique_id "aoSChv2v-lWn9OzQT7VDwgAAALY"] [Tue Aug 18 13:04:22.756854 2026] [security2:error] [pid 139043:tid 139193] [client 20.51.153.15:9143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lp.php"] [unique_id "aoSChv2v-lWn9OzQT7VDwwAAAJk"] [Tue Aug 18 13:04:22.786212 2026] [security2:error] [pid 139043:tid 139300] [client 4.232.151.198:38817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/gecko-new.php"] [unique_id "aoSChv2v-lWn9OzQT7VDxQAAAQQ"] [Tue Aug 18 13:04:22.786491 2026] [authz_core:error] [pid 139043:tid 139136] [remote 57.141.22.86:22584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:22.786756 2026] [authz_core:error] [pid 139043:tid 139136] [remote 57.141.22.86:22584] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:22.802198 2026] [security2:error] [pid 139043:tid 139187] [client 20.1.169.243:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/mini.php"] [unique_id "aoSChv2v-lWn9OzQT7VDxwAAAJM"] [Tue Aug 18 13:04:22.845025 2026] [security2:error] [pid 139043:tid 139204] [client 20.104.100.201:23888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ccou.php"] [unique_id "aoSChv2v-lWn9OzQT7VDywAAAKQ"] [Tue Aug 18 13:04:22.858901 2026] [security2:error] [pid 139043:tid 139180] [client 20.151.109.219:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lr.php"] [unique_id "aoSChv2v-lWn9OzQT7VDzQAAAIw"] [Tue Aug 18 13:04:22.915175 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:57903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSChv2v-lWn9OzQT7VD0AAAAO4"] [Tue Aug 18 13:04:22.915297 2026] [security2:error] [pid 139043:tid 139278] [client 157.20.138.62:57903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSChv2v-lWn9OzQT7VD0AAAAO4"] [Tue Aug 18 13:04:22.915626 2026] [autoindex:error] [pid 139043:tid 139200] [client 23.95.96.140:43678] AH01276: Cannot serve directory /home2/rstcomerciocom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:22.949157 2026] [security2:error] [pid 139043:tid 139263] [client 74.248.130.103:57001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSChv2v-lWn9OzQT7VD0gAAAN8"] [Tue Aug 18 13:04:22.954231 2026] [security2:error] [pid 139043:tid 139174] [client 20.171.51.14:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/se.php"] [unique_id "aoSChv2v-lWn9OzQT7VD0wAAAIY"] [Tue Aug 18 13:04:22.990354 2026] [security2:error] [pid 139043:tid 139288] [client 52.139.47.57:10994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/past.php"] [unique_id "aoSChv2v-lWn9OzQT7VD2AAAAPg"] [Tue Aug 18 13:04:23.011545 2026] [security2:error] [pid 139043:tid 139283] [client 20.250.13.23:55653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/media-new.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD2QAAAPM"] [Tue Aug 18 13:04:23.019558 2026] [security2:error] [pid 139043:tid 139218] [client 172.182.200.96:15595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD2gAAALI"] [Tue Aug 18 13:04:23.041156 2026] [security2:error] [pid 139043:tid 139244] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD2wAAAMw"] [Tue Aug 18 13:04:23.048798 2026] [security2:error] [pid 139043:tid 139292] [client 20.151.109.219:46552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/app.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD3AAAAPw"] [Tue Aug 18 13:04:23.112252 2026] [security2:error] [pid 139043:tid 139252] [client 4.232.151.198:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/smilies/about.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD3wAAANQ"] [Tue Aug 18 13:04:23.114398 2026] [security2:error] [pid 139043:tid 139234] [client 20.116.17.175:53180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/xyn.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD4AAAAMI"] [Tue Aug 18 13:04:23.115937 2026] [security2:error] [pid 139043:tid 139262] [client 20.51.153.15:8831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ey.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD4QAAAN4"] [Tue Aug 18 13:04:23.116896 2026] [security2:error] [pid 139043:tid 139291] [client 20.163.43.14:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD4gAAAPs"] [Tue Aug 18 13:04:23.156649 2026] [authz_core:error] [pid 139043:tid 139131] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:23.156968 2026] [authz_core:error] [pid 139043:tid 139131] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:23.171150 2026] [security2:error] [pid 139043:tid 139201] [client 20.1.169.243:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/moddofuns.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD5QAAAKE"] [Tue Aug 18 13:04:23.205948 2026] [security2:error] [pid 139043:tid 139235] [client 20.52.168.85:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/DxHhVcy2bmJ.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD5gAAAMM"] [Tue Aug 18 13:04:23.229153 2026] [security2:error] [pid 139043:tid 139257] [client 172.182.217.32:21403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/pomo/php8.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD5wAAANk"] [Tue Aug 18 13:04:23.285465 2026] [security2:error] [pid 139043:tid 139199] [client 158.23.17.4:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ry.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD6QAAAJ8"] [Tue Aug 18 13:04:23.289744 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:23935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/crgio.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD6gAAAJE"] [Tue Aug 18 13:04:23.354950 2026] [security2:error] [pid 139043:tid 139275] [client 213.202.253.4:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/schallfuns.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD7AAAAOs"], referer: www.google.com [Tue Aug 18 13:04:23.358642 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD7QAAAMQ"] [Tue Aug 18 13:04:23.366193 2026] [security2:error] [pid 139043:tid 139233] [client 20.48.236.86:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.peninsulawayma.com.br"] [uri "/ajax.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD7gAAAME"] [Tue Aug 18 13:04:23.386008 2026] [security2:error] [pid 139043:tid 139182] [client 20.186.30.159:10072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/aa.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD7wAAAI4"] [Tue Aug 18 13:04:23.394256 2026] [security2:error] [pid 139043:tid 139296] [client 172.182.200.96:3070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD8QAAAQA"] [Tue Aug 18 13:04:23.397933 2026] [security2:error] [pid 139043:tid 139224] [client 4.223.113.180:45253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD8wAAALg"] [Tue Aug 18 13:04:23.410598 2026] [security2:error] [pid 139043:tid 139212] [client 52.139.47.57:49175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/root.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD9AAAAKw"] [Tue Aug 18 13:04:23.419268 2026] [security2:error] [pid 139043:tid 139217] [client 20.251.48.93:22381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/ops.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD9QAAALE"] [Tue Aug 18 13:04:23.431489 2026] [security2:error] [pid 139043:tid 139277] [client 20.215.241.237:9404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/k.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD9wAAAO0"] [Tue Aug 18 13:04:23.436411 2026] [security2:error] [pid 139043:tid 139194] [client 20.250.13.23:35123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/file.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD-AAAAJo"] [Tue Aug 18 13:04:23.452668 2026] [security2:error] [pid 139043:tid 139210] [client 178.153.171.161:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD-gAAAKo"] [Tue Aug 18 13:04:23.452871 2026] [security2:error] [pid 139043:tid 139210] [client 178.153.171.161:64016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD-gAAAKo"] [Tue Aug 18 13:04:23.455944 2026] [authz_core:error] [pid 139043:tid 139068] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:23.456218 2026] [authz_core:error] [pid 139043:tid 139068] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:23.474096 2026] [security2:error] [pid 139043:tid 139269] [client 20.163.43.14:4393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD_AAAAOU"] [Tue Aug 18 13:04:23.474254 2026] [security2:error] [pid 139043:tid 139211] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/xyn.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD_QAAAKs"] [Tue Aug 18 13:04:23.474329 2026] [security2:error] [pid 139043:tid 139240] [client 68.221.73.131:16299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/aaa.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD-wAAAMg"] [Tue Aug 18 13:04:23.475407 2026] [security2:error] [pid 139043:tid 139193] [client 20.51.153.15:8745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lv.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD_gAAAJk"] [Tue Aug 18 13:04:23.490877 2026] [security2:error] [pid 139043:tid 139280] [client 213.35.127.232:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCh_2v-lWn9OzQT7VD_wAAAPA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:23.520589 2026] [security2:error] [pid 139043:tid 139173] [client 20.171.51.14:7882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vp.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEAQAAAIU"] [Tue Aug 18 13:04:23.535475 2026] [security2:error] [pid 139043:tid 139281] [client 20.1.169.243:11097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEAgAAAPE"] [Tue Aug 18 13:04:23.625882 2026] [security2:error] [pid 139043:tid 139238] [client 20.250.13.23:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEBwAAAMY"] [Tue Aug 18 13:04:23.649927 2026] [security2:error] [pid 139043:tid 139251] [client 20.116.17.175:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCh_2v-lWn9OzQT7VECAAAANM"] [Tue Aug 18 13:04:23.655835 2026] [security2:error] [pid 139043:tid 139206] [client 20.151.109.219:10590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ka.php"] [unique_id "aoSCh_2v-lWn9OzQT7VECQAAAKY"] [Tue Aug 18 13:04:23.675553 2026] [security2:error] [pid 139043:tid 139245] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCh_2v-lWn9OzQT7VECgAAAM0"] [Tue Aug 18 13:04:23.682462 2026] [security2:error] [pid 139043:tid 139234] [client 20.151.109.219:58310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/87.php"] [unique_id "aoSCh_2v-lWn9OzQT7VECwAAAMI"] [Tue Aug 18 13:04:23.721265 2026] [security2:error] [pid 139043:tid 139248] [client 172.182.217.32:21407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/block-patterns/php8.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEDgAAANA"] [Tue Aug 18 13:04:23.731442 2026] [security2:error] [pid 139043:tid 139221] [client 20.104.100.201:23992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEEAAAALU"] [Tue Aug 18 13:04:23.742145 2026] [security2:error] [pid 139043:tid 139239] [client 172.182.200.96:15517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEEQAAAMc"] [Tue Aug 18 13:04:23.768828 2026] [security2:error] [pid 139043:tid 139204] [client 132.196.30.78:20056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/inputs.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEEgAAAKQ"] [Tue Aug 18 13:04:23.789017 2026] [security2:error] [pid 139043:tid 139293] [client 4.232.151.198:43002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/gCdfg/autoload_classmap.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEFAAAAP0"] [Tue Aug 18 13:04:23.807419 2026] [security2:error] [pid 139043:tid 139261] [client 20.52.168.85:5166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/amaxx.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEFwAAAN0"] [Tue Aug 18 13:04:23.825362 2026] [security2:error] [pid 139043:tid 139257] [client 20.163.43.14:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/ok.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEGAAAANk"] [Tue Aug 18 13:04:23.826036 2026] [security2:error] [pid 139043:tid 139291] [client 52.139.47.57:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/r.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEGQAAAPs"] [Tue Aug 18 13:04:23.894117 2026] [security2:error] [pid 139043:tid 139199] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/inso.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEHgAAAJ8"] [Tue Aug 18 13:04:23.899918 2026] [security2:error] [pid 139043:tid 139243] [client 20.1.169.243:10889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/moduless.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEHwAAAMs"] [Tue Aug 18 13:04:23.902563 2026] [authz_core:error] [pid 139043:tid 139128] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:23.903011 2026] [authz_core:error] [pid 139043:tid 139128] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:23.966473 2026] [security2:error] [pid 139043:tid 139205] [client 20.51.153.15:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/51.php"] [unique_id "aoSCh_2v-lWn9OzQT7VEIQAAAKU"] [Tue Aug 18 13:04:24.017437 2026] [security2:error] [pid 139043:tid 139224] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEIwAAALg"] [Tue Aug 18 13:04:24.027894 2026] [security2:error] [pid 139043:tid 139292] [client 4.232.151.198:40592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/NewFile.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEJAAAAPw"] [Tue Aug 18 13:04:24.122451 2026] [security2:error] [pid 139043:tid 139277] [client 20.104.100.201:23892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/css.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEKAAAAO0"] [Tue Aug 18 13:04:24.131159 2026] [security2:error] [pid 139043:tid 139274] [client 68.155.156.252:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/admin.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEKQAAAOo"] [Tue Aug 18 13:04:24.164279 2026] [security2:error] [pid 139043:tid 139289] [client 158.23.17.4:40446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pm.php"] [unique_id "aoSCiP2v-lWn9OzQT7VELAAAAPk"] [Tue Aug 18 13:04:24.169536 2026] [security2:error] [pid 139043:tid 139269] [client 20.163.43.14:4407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "copemsa.com.br"] [uri "/item.php"] [unique_id "aoSCiP2v-lWn9OzQT7VELQAAAOU"] [Tue Aug 18 13:04:24.187914 2026] [security2:error] [pid 139043:tid 139299] [client 20.171.51.14:44890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ph.php"] [unique_id "aoSCiP2v-lWn9OzQT7VELgAAAQM"] [Tue Aug 18 13:04:24.194792 2026] [security2:error] [pid 139043:tid 139188] [client 172.182.200.96:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCiP2v-lWn9OzQT7VELwAAAJQ"] [Tue Aug 18 13:04:24.196239 2026] [security2:error] [pid 139043:tid 139280] [client 20.116.17.175:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-good.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEMQAAAPA"] [Tue Aug 18 13:04:24.203780 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:24.204040 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:24.210299 2026] [security2:error] [pid 139043:tid 139072] [remote 187.75.34.18:45400] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "barsantajulia.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEMwAAhRw"], referer: https://barsantajulia.com.br/buffet/ [Tue Aug 18 13:04:24.213891 2026] [security2:error] [pid 139043:tid 139208] [client 172.182.217.32:21421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/updraft/php8.php"] [unique_id "aoSCiP2v-lWn9OzQT7VENQAAAKg"] [Tue Aug 18 13:04:24.214530 2026] [security2:error] [pid 139043:tid 139094] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiP2v-lWn9OzQT7VENAAA8jI"] [Tue Aug 18 13:04:24.214675 2026] [security2:error] [pid 139043:tid 139282] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiP2v-lWn9OzQT7VENAAA8jI"] [Tue Aug 18 13:04:24.219089 2026] [security2:error] [pid 139043:tid 139254] [client 20.186.30.159:10109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/img.php"] [unique_id "aoSCiP2v-lWn9OzQT7VENgAAANY"] [Tue Aug 18 13:04:24.259801 2026] [security2:error] [pid 139043:tid 139192] [client 52.139.47.57:10947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/sid3.php"] [unique_id "aoSCiP2v-lWn9OzQT7VENwAAAJg"] [Tue Aug 18 13:04:24.265415 2026] [security2:error] [pid 139043:tid 139210] [client 20.1.169.243:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEOAAAAKo"] [Tue Aug 18 13:04:24.279010 2026] [security2:error] [pid 139043:tid 139296] [client 4.223.113.180:19209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/go.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEOQAAAQA"] [Tue Aug 18 13:04:24.284496 2026] [security2:error] [pid 139043:tid 139212] [client 20.250.13.23:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEOgAAAKw"] [Tue Aug 18 13:04:24.317949 2026] [security2:error] [pid 139043:tid 139215] [client 45.131.194.81:60975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.194.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gruponovaeuro.com.br"] [uri "/wp-login.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEKgAAAK8"] [Tue Aug 18 13:04:24.326987 2026] [security2:error] [pid 139043:tid 139255] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEOwAAANc"] [Tue Aug 18 13:04:24.342903 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:8816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ew.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEPAAAAPg"] [Tue Aug 18 13:04:24.356713 2026] [security2:error] [pid 139043:tid 139283] [client 20.151.109.219:33495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/zi.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEPQAAAPM"] [Tue Aug 18 13:04:24.374989 2026] [security2:error] [pid 139043:tid 139251] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/puc.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEPgAAANM"] [Tue Aug 18 13:04:24.377527 2026] [security2:error] [pid 139043:tid 139297] [client 132.196.30.78:19498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/admin.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEPwAAAQE"] [Tue Aug 18 13:04:24.398871 2026] [security2:error] [pid 139043:tid 139234] [client 74.248.130.103:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/simple.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEQAAAAMI"] [Tue Aug 18 13:04:24.413369 2026] [security2:error] [pid 139043:tid 139281] [client 20.52.168.85:5159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/BIBIL0DAY.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEQQAAAPE"] [Tue Aug 18 13:04:24.453593 2026] [security2:error] [pid 139043:tid 139186] [client 20.104.100.201:23953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEQwAAAJI"] [Tue Aug 18 13:04:24.462360 2026] [security2:error] [pid 139043:tid 139278] [client 4.232.151.198:7716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/backup-backup/includes/1a895fa06f.php"] [unique_id "aoSCiP2v-lWn9OzQT7VERAAAAO4"] [Tue Aug 18 13:04:24.518376 2026] [security2:error] [pid 139043:tid 139211] [client 213.35.127.232:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCiP2v-lWn9OzQT7VERwAAAKs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:24.552442 2026] [security2:error] [pid 139043:tid 139228] [client 172.182.200.96:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCiP2v-lWn9OzQT7VESAAAALw"] [Tue Aug 18 13:04:24.628225 2026] [security2:error] [pid 139043:tid 139271] [client 20.1.169.243:11116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/new.php"] [unique_id "aoSCiP2v-lWn9OzQT7VETAAAAOc"] [Tue Aug 18 13:04:24.643908 2026] [security2:error] [pid 139043:tid 139300] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCiP2v-lWn9OzQT7VETQAAAQQ"] [Tue Aug 18 13:04:24.676556 2026] [security2:error] [pid 139043:tid 139220] [client 52.139.47.57:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ss.php"] [unique_id "aoSCiP2v-lWn9OzQT7VETgAAALQ"] [Tue Aug 18 13:04:24.700918 2026] [security2:error] [pid 139043:tid 139293] [client 172.182.217.32:22210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/upgrade-temp-backup/php8.php"] [unique_id "aoSCiP2v-lWn9OzQT7VETwAAAP0"] [Tue Aug 18 13:04:24.755948 2026] [security2:error] [pid 139043:tid 139182] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/19.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEUQAAAI4"] [Tue Aug 18 13:04:24.761078 2026] [security2:error] [pid 139043:tid 139242] [client 68.221.73.131:60597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/gecko.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEUgAAAMo"] [Tue Aug 18 13:04:24.764235 2026] [security2:error] [pid 139043:tid 139249] [client 20.51.153.15:9089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pqr.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEVAAAANE"] [Tue Aug 18 13:04:24.846521 2026] [security2:error] [pid 139043:tid 139256] [client 20.79.204.6:9336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ms-edit.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEWwAAANg"] [Tue Aug 18 13:04:24.848278 2026] [security2:error] [pid 139043:tid 139279] [client 20.116.17.175:3449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wmore1.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEXAAAAO8"] [Tue Aug 18 13:04:24.864268 2026] [security2:error] [pid 139043:tid 139204] [client 4.232.151.198:41850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEXQAAAKQ"] [Tue Aug 18 13:04:24.882942 2026] [security2:error] [pid 139043:tid 139222] [client 172.182.200.96:15527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/images/security.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEXgAAALY"] [Tue Aug 18 13:04:24.886073 2026] [security2:error] [pid 139043:tid 139287] [client 20.186.30.159:10032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/222.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEXwAAAPc"] [Tue Aug 18 13:04:24.888181 2026] [security2:error] [pid 139043:tid 139193] [client 20.171.51.14:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/s.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEYAAAAJk"] [Tue Aug 18 13:04:24.904872 2026] [security2:error] [pid 139043:tid 139188] [client 20.104.100.201:23915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/epinyins.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEYgAAAJQ"] [Tue Aug 18 13:04:24.907942 2026] [security2:error] [pid 139043:tid 139223] [client 20.250.13.23:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEYwAAALc"] [Tue Aug 18 13:04:24.996332 2026] [security2:error] [pid 139043:tid 139289] [client 20.1.169.243:11253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSCiP2v-lWn9OzQT7VEZQAAAPk"] [Tue Aug 18 13:04:25.023428 2026] [security2:error] [pid 139043:tid 139217] [client 20.52.168.85:5721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/functions.php"] [unique_id "aoSCif2v-lWn9OzQT7VEZwAAALE"] [Tue Aug 18 13:04:25.049162 2026] [security2:error] [pid 139043:tid 139268] [client 20.206.73.37:21292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/inso.php"] [unique_id "aoSCif2v-lWn9OzQT7VEaAAAAOQ"] [Tue Aug 18 13:04:25.057248 2026] [security2:error] [pid 139043:tid 139267] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCif2v-lWn9OzQT7VEaQAAAOM"] [Tue Aug 18 13:04:25.098911 2026] [security2:error] [pid 139043:tid 139275] [client 4.232.151.198:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/locks.php"] [unique_id "aoSCif2v-lWn9OzQT7VEbQAAAOs"] [Tue Aug 18 13:04:25.100138 2026] [security2:error] [pid 139043:tid 139179] [client 52.139.47.57:33841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/sts.php"] [unique_id "aoSCif2v-lWn9OzQT7VEbgAAAIs"] [Tue Aug 18 13:04:25.107248 2026] [authz_core:error] [pid 139043:tid 139100] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:25.107560 2026] [authz_core:error] [pid 139043:tid 139100] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:25.112369 2026] [security2:error] [pid 139043:tid 139218] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/133.php"] [unique_id "aoSCif2v-lWn9OzQT7VEcQAAALI"] [Tue Aug 18 13:04:25.123608 2026] [security2:error] [pid 139043:tid 139251] [client 20.215.241.237:18636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/82.php"] [unique_id "aoSCif2v-lWn9OzQT7VEcgAAANM"] [Tue Aug 18 13:04:25.166258 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.1:49082] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:25.166529 2026] [authz_core:error] [pid 139043:tid 139112] [remote 57.141.22.1:49082] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:25.187131 2026] [security2:error] [pid 139043:tid 139192] [client 172.182.217.32:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/themes/php8.php"] [unique_id "aoSCif2v-lWn9OzQT7VEdQAAAJg"] [Tue Aug 18 13:04:25.204263 2026] [security2:error] [pid 139043:tid 139260] [client 20.51.153.15:8713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/an.php"] [unique_id "aoSCif2v-lWn9OzQT7VEdwAAANw"] [Tue Aug 18 13:04:25.282580 2026] [security2:error] [pid 139043:tid 139233] [client 132.196.30.78:20062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/goods.php"] [unique_id "aoSCif2v-lWn9OzQT7VEegAAAME"] [Tue Aug 18 13:04:25.320970 2026] [security2:error] [pid 139043:tid 139197] [client 20.171.51.14:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/uo.php"] [unique_id "aoSCif2v-lWn9OzQT7VEfAAAAJ0"] [Tue Aug 18 13:04:25.340500 2026] [security2:error] [pid 139043:tid 139187] [client 20.250.13.23:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/adminfuns.php"] [unique_id "aoSCif2v-lWn9OzQT7VEfQAAAJM"] [Tue Aug 18 13:04:25.356224 2026] [security2:error] [pid 139043:tid 139178] [client 158.23.17.4:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/dr.php"] [unique_id "aoSCif2v-lWn9OzQT7VEfwAAAIo"] [Tue Aug 18 13:04:25.372681 2026] [security2:error] [pid 139043:tid 139270] [client 20.1.169.243:11127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/num.php"] [unique_id "aoSCif2v-lWn9OzQT7VEgQAAAOY"] [Tue Aug 18 13:04:25.378411 2026] [security2:error] [pid 139043:tid 139290] [client 103.184.169.37:43785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEggAAAPo"] [Tue Aug 18 13:04:25.378521 2026] [security2:error] [pid 139043:tid 139290] [client 103.184.169.37:43785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEggAAAPo"] [Tue Aug 18 13:04:25.380279 2026] [security2:error] [pid 139043:tid 139300] [client 20.151.109.219:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ot.php"] [unique_id "aoSCif2v-lWn9OzQT7VEgwAAAQQ"] [Tue Aug 18 13:04:25.397683 2026] [security2:error] [pid 139043:tid 139247] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCif2v-lWn9OzQT7VEhQAAAM8"] [Tue Aug 18 13:04:25.404245 2026] [security2:error] [pid 139043:tid 139185] [client 20.186.30.159:10103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/key.php"] [unique_id "aoSCif2v-lWn9OzQT7VEiAAAAJE"] [Tue Aug 18 13:04:25.408128 2026] [authz_core:error] [pid 139043:tid 139050] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:25.408393 2026] [authz_core:error] [pid 139043:tid 139050] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:25.460605 2026] [security2:error] [pid 139043:tid 139249] [client 168.62.48.100:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCif2v-lWn9OzQT7VEigAAANE"] [Tue Aug 18 13:04:25.475448 2026] [security2:error] [pid 139043:tid 139253] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCif2v-lWn9OzQT7VEiwAAANU"] [Tue Aug 18 13:04:25.520135 2026] [security2:error] [pid 139043:tid 139271] [client 52.139.47.57:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/shell.php"] [unique_id "aoSCif2v-lWn9OzQT7VEjQAAAOc"] [Tue Aug 18 13:04:25.523035 2026] [security2:error] [pid 139043:tid 139240] [client 103.120.71.157:62776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEjwAAAMg"] [Tue Aug 18 13:04:25.525417 2026] [security2:error] [pid 139043:tid 139240] [client 103.120.71.157:62776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEjwAAAMg"] [Tue Aug 18 13:04:25.526575 2026] [security2:error] [pid 139043:tid 139227] [client 20.104.100.201:23943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/load.php"] [unique_id "aoSCif2v-lWn9OzQT7VEkAAAALs"] [Tue Aug 18 13:04:25.538760 2026] [security2:error] [pid 139043:tid 139186] [client 213.35.127.232:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCif2v-lWn9OzQT7VEkQAAAJI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:25.550784 2026] [security2:error] [pid 139043:tid 139280] [client 74.248.130.103:49010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSCif2v-lWn9OzQT7VElwAAAPA"] [Tue Aug 18 13:04:25.604985 2026] [security2:error] [pid 139043:tid 139243] [client 20.250.13.23:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSCif2v-lWn9OzQT7VEmwAAAMs"] [Tue Aug 18 13:04:25.612519 2026] [security2:error] [pid 139043:tid 139184] [client 4.223.113.180:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/atomlib.php"] [unique_id "aoSCif2v-lWn9OzQT7VEnAAAAJA"] [Tue Aug 18 13:04:25.646882 2026] [security2:error] [pid 139043:tid 139296] [client 68.221.73.131:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/xiugai.php"] [unique_id "aoSCif2v-lWn9OzQT7VEngAAAQA"] [Tue Aug 18 13:04:25.649221 2026] [security2:error] [pid 139043:tid 139236] [client 20.52.168.85:5150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSCif2v-lWn9OzQT7VEoAAAAMQ"] [Tue Aug 18 13:04:25.683776 2026] [security2:error] [pid 139043:tid 139194] [client 20.79.204.6:9293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/a7.php"] [unique_id "aoSCif2v-lWn9OzQT7VEoQAAAJo"] [Tue Aug 18 13:04:25.683853 2026] [security2:error] [pid 139043:tid 139267] [client 20.51.153.15:9109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/sy.php"] [unique_id "aoSCif2v-lWn9OzQT7VEogAAAOM"] [Tue Aug 18 13:04:25.686227 2026] [security2:error] [pid 139043:tid 139256] [client 172.182.217.32:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-admin/includes/php8.php"] [unique_id "aoSCif2v-lWn9OzQT7VEowAAANg"] [Tue Aug 18 13:04:25.691666 2026] [security2:error] [pid 139043:tid 139255] [client 40.74.65.169:16259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCif2v-lWn9OzQT7VEpAAAANc"] [Tue Aug 18 13:04:25.728023 2026] [authz_core:error] [pid 139043:tid 139125] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:25.728476 2026] [authz_core:error] [pid 139043:tid 139125] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:25.752552 2026] [security2:error] [pid 139043:tid 139288] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCif2v-lWn9OzQT7VEpwAAAPg"] [Tue Aug 18 13:04:25.767922 2026] [security2:error] [pid 139043:tid 139210] [client 20.1.169.243:11189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/php.php"] [unique_id "aoSCif2v-lWn9OzQT7VEsAAAAKo"] [Tue Aug 18 13:04:25.788187 2026] [security2:error] [pid 139043:tid 139218] [client 20.151.109.219:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCif2v-lWn9OzQT7VEsQAAALI"] [Tue Aug 18 13:04:25.812147 2026] [security2:error] [pid 139043:tid 139234] [client 20.116.17.175:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/special.php"] [unique_id "aoSCif2v-lWn9OzQT7VEtgAAAMI"] [Tue Aug 18 13:04:25.840691 2026] [security2:error] [pid 139043:tid 139219] [client 4.232.151.198:7723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/js/wp-login.php"] [unique_id "aoSCif2v-lWn9OzQT7VEuAAAALM"] [Tue Aug 18 13:04:25.848503 2026] [security2:error] [pid 139043:tid 139176] [client 5.31.227.224:7847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEuQAAAIg"] [Tue Aug 18 13:04:25.848590 2026] [security2:error] [pid 139043:tid 139176] [client 5.31.227.224:7847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCif2v-lWn9OzQT7VEuQAAAIg"] [Tue Aug 18 13:04:25.853153 2026] [security2:error] [pid 139043:tid 139286] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/mosty.php"] [unique_id "aoSCif2v-lWn9OzQT7VEugAAAPY"] [Tue Aug 18 13:04:25.939178 2026] [security2:error] [pid 139043:tid 139270] [client 20.186.30.159:10059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/chosen.php"] [unique_id "aoSCif2v-lWn9OzQT7VEvQAAAOY"] [Tue Aug 18 13:04:25.939507 2026] [security2:error] [pid 139043:tid 139251] [client 52.139.47.57:15634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/setup-config.php"] [unique_id "aoSCif2v-lWn9OzQT7VEvgAAANM"] [Tue Aug 18 13:04:25.943292 2026] [security2:error] [pid 139043:tid 139300] [client 20.171.51.14:44878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kx.php"] [unique_id "aoSCif2v-lWn9OzQT7VEvwAAAQQ"] [Tue Aug 18 13:04:25.972079 2026] [security2:error] [pid 139043:tid 139298] [client 132.196.30.78:22353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/file.php"] [unique_id "aoSCif2v-lWn9OzQT7VEwAAAAQI"] [Tue Aug 18 13:04:26.001065 2026] [security2:error] [pid 139043:tid 139182] [client 20.104.100.201:23962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSCiv2v-lWn9OzQT7VEwgAAAI4"] [Tue Aug 18 13:04:26.029652 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:26.030503 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:26.071666 2026] [security2:error] [pid 139043:tid 139181] [client 20.51.153.15:9163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/57.php"] [unique_id "aoSCiv2v-lWn9OzQT7VExgAAAI0"] [Tue Aug 18 13:04:26.071716 2026] [security2:error] [pid 139043:tid 139240] [client 20.151.109.219:23500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ih.php"] [unique_id "aoSCiv2v-lWn9OzQT7VExwAAAMg"] [Tue Aug 18 13:04:26.131533 2026] [security2:error] [pid 139043:tid 139253] [client 20.1.169.243:11172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/php/eval-stdin.php"] [unique_id "aoSCiv2v-lWn9OzQT7VEygAAANU"] [Tue Aug 18 13:04:26.171499 2026] [security2:error] [pid 139043:tid 139223] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VEzAAAALc"] [Tue Aug 18 13:04:26.175057 2026] [security2:error] [pid 139043:tid 139272] [client 172.182.217.32:22258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/images/php8.php"] [unique_id "aoSCiv2v-lWn9OzQT7VEzgAAAOg"] [Tue Aug 18 13:04:26.225244 2026] [security2:error] [pid 139043:tid 139292] [client 20.250.13.23:55652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/ebs.php7"] [unique_id "aoSCiv2v-lWn9OzQT7VE0gAAAPw"] [Tue Aug 18 13:04:26.250951 2026] [security2:error] [pid 139043:tid 139184] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/blurbs.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE1AAAAJA"] [Tue Aug 18 13:04:26.269099 2026] [security2:error] [pid 139043:tid 139200] [client 191.237.254.161:54870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/akismet.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE2AAAAKA"] [Tue Aug 18 13:04:26.308073 2026] [security2:error] [pid 139043:tid 139209] [client 114.119.128.244:60549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ajuda.oruc.com.br"] [uri "/adicionando-o-whatsapp-como-canal-de-atendimento-em-sua-loja/"] [unique_id "aoSCiv2v-lWn9OzQT7VE2gAAAKk"], referer: http://oruc.com.br/planos [Tue Aug 18 13:04:26.311141 2026] [security2:error] [pid 139043:tid 139204] [client 20.52.168.85:5158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/conf_upload.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE2wAAAKQ"] [Tue Aug 18 13:04:26.318855 2026] [authz_core:error] [pid 139043:tid 139048] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:26.319130 2026] [authz_core:error] [pid 139043:tid 139048] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:26.321862 2026] [security2:error] [pid 139043:tid 139273] [client 168.62.48.100:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE3QAAAOk"] [Tue Aug 18 13:04:26.335698 2026] [security2:error] [pid 139043:tid 139190] [client 20.186.30.159:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/wpxml.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE3gAAAJY"] [Tue Aug 18 13:04:26.352297 2026] [security2:error] [pid 139043:tid 139226] [client 52.139.47.57:33829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/t.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE3wAAALo"] [Tue Aug 18 13:04:26.363838 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:8409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ah.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE4QAAAPg"] [Tue Aug 18 13:04:26.377770 2026] [security2:error] [pid 139043:tid 139194] [client 138.36.100.162:41655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE4wAAAJo"] [Tue Aug 18 13:04:26.377961 2026] [security2:error] [pid 139043:tid 139194] [client 138.36.100.162:41655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE4wAAAJo"] [Tue Aug 18 13:04:26.382022 2026] [security2:error] [pid 139043:tid 139297] [client 197.184.64.235:42667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE5AAAAQE"] [Tue Aug 18 13:04:26.382114 2026] [security2:error] [pid 139043:tid 139297] [client 197.184.64.235:42667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE5AAAAQE"] [Tue Aug 18 13:04:26.388507 2026] [security2:error] [pid 139043:tid 139210] [client 20.116.17.175:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE5QAAAKo"] [Tue Aug 18 13:04:26.422235 2026] [security2:error] [pid 139043:tid 139278] [client 20.171.51.14:7929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/va.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE5wAAAO4"] [Tue Aug 18 13:04:26.441666 2026] [security2:error] [pid 139043:tid 139176] [client 68.155.154.236:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE6AAAAIg"] [Tue Aug 18 13:04:26.458911 2026] [security2:error] [pid 139043:tid 139225] [client 4.232.151.198:40576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE6gAAALk"] [Tue Aug 18 13:04:26.459189 2026] [security2:error] [pid 139043:tid 139241] [client 20.104.100.201:23944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ty.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE6wAAAMk"] [Tue Aug 18 13:04:26.465558 2026] [security2:error] [pid 139043:tid 139233] [client 20.151.109.219:33507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/92.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE7AAAAME"] [Tue Aug 18 13:04:26.475918 2026] [security2:error] [pid 139043:tid 139284] [client 20.206.73.37:21070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/ws13.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE7QAAAPQ"] [Tue Aug 18 13:04:26.493188 2026] [security2:error] [pid 139043:tid 139232] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE7gAAAMA"] [Tue Aug 18 13:04:26.496637 2026] [security2:error] [pid 139043:tid 139254] [client 20.1.169.243:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/php8.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE7wAAANY"] [Tue Aug 18 13:04:26.574849 2026] [security2:error] [pid 139043:tid 139207] [client 37.40.227.74:56527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE8wAAAKc"] [Tue Aug 18 13:04:26.575993 2026] [security2:error] [pid 139043:tid 139193] [client 213.35.127.232:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE9AAAAJk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:26.579365 2026] [security2:error] [pid 139043:tid 139207] [client 37.40.227.74:56527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE8wAAAKc"] [Tue Aug 18 13:04:26.589787 2026] [security2:error] [pid 139043:tid 139300] [client 68.221.73.131:40883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/adminner.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE9gAAAQQ"] [Tue Aug 18 13:04:26.617053 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:26.617307 2026] [authz_core:error] [pid 139043:tid 139066] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:26.623896 2026] [security2:error] [pid 139043:tid 139177] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/bajah.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE-gAAAIk"] [Tue Aug 18 13:04:26.627467 2026] [security2:error] [pid 139043:tid 139174] [client 4.232.151.198:7681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/maint/xleet.php"] [unique_id "aoSCiv2v-lWn9OzQT7VE_AAAAIY"] [Tue Aug 18 13:04:26.644623 2026] [security2:error] [pid 139043:tid 139214] [client 158.23.17.4:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ts.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFAAAAAK4"] [Tue Aug 18 13:04:26.662309 2026] [security2:error] [pid 139043:tid 139187] [client 172.182.217.32:21800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/blogs.dir/php8.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFAgAAAJM"] [Tue Aug 18 13:04:26.691145 2026] [security2:error] [pid 139043:tid 139186] [client 20.51.153.15:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vw.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFAwAAAJI"] [Tue Aug 18 13:04:26.712236 2026] [security2:error] [pid 139043:tid 139249] [client 20.186.30.159:10023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/file1221.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFBAAAANE"] [Tue Aug 18 13:04:26.755414 2026] [security2:error] [pid 139043:tid 139223] [client 74.248.130.103:7713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/als.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFBwAAALc"] [Tue Aug 18 13:04:26.760526 2026] [security2:error] [pid 139043:tid 139205] [client 4.223.113.180:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFCAAAAKU"] [Tue Aug 18 13:04:26.767081 2026] [security2:error] [pid 139043:tid 139198] [client 52.139.47.57:29198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/up.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFCQAAAJ4"] [Tue Aug 18 13:04:26.769004 2026] [security2:error] [pid 139043:tid 139272] [client 20.151.109.219:27381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/mimes.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFCgAAAOg"] [Tue Aug 18 13:04:26.814242 2026] [security2:error] [pid 139043:tid 139217] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/first.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFDQAAALE"] [Tue Aug 18 13:04:26.869817 2026] [security2:error] [pid 139043:tid 139209] [client 52.173.121.69:55611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFEQAAAKk"] [Tue Aug 18 13:04:26.922298 2026] [security2:error] [pid 139043:tid 139293] [client 20.52.168.85:5296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/content.php888"] [unique_id "aoSCiv2v-lWn9OzQT7VFFAAAAP0"] [Tue Aug 18 13:04:26.931800 2026] [security2:error] [pid 139043:tid 139182] [client 20.250.13.23:39021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/404.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFFgAAAI4"] [Tue Aug 18 13:04:26.941374 2026] [security2:error] [pid 139043:tid 139098] [remote 46.62.208.238:57314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFFwAAtTY"] [Tue Aug 18 13:04:26.960670 2026] [security2:error] [pid 139043:tid 139188] [client 52.87.72.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSCif2v-lWn9OzQT7VElgAAlDc"], referer: https://markettohome.com.br/ [Tue Aug 18 13:04:26.968599 2026] [security2:error] [pid 139043:tid 139234] [client 20.104.100.201:23969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFGAAAAMI"] [Tue Aug 18 13:04:26.975085 2026] [security2:error] [pid 139043:tid 139278] [client 20.151.109.219:21257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/k.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFGwAAAO4"] [Tue Aug 18 13:04:26.980187 2026] [security2:error] [pid 139043:tid 139260] [client 20.116.17.175:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/thoms.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFHAAAANw"] [Tue Aug 18 13:04:26.989151 2026] [security2:error] [pid 139043:tid 139269] [client 223.185.37.47:27376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFHQAAAOU"] [Tue Aug 18 13:04:26.989252 2026] [security2:error] [pid 139043:tid 139269] [client 223.185.37.47:27376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFHQAAAOU"] [Tue Aug 18 13:04:26.990933 2026] [security2:error] [pid 139043:tid 139208] [client 20.250.13.23:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSCiv2v-lWn9OzQT7VFHgAAAKg"] [Tue Aug 18 13:04:27.025496 2026] [security2:error] [pid 139043:tid 139235] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/h.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFIgAAAMM"] [Tue Aug 18 13:04:27.051704 2026] [security2:error] [pid 139043:tid 139216] [client 20.1.169.243:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/plugins.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFIwAAALA"] [Tue Aug 18 13:04:27.076561 2026] [security2:error] [pid 139043:tid 139244] [client 196.12.128.158:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFJgAAAMw"] [Tue Aug 18 13:04:27.076709 2026] [security2:error] [pid 139043:tid 139244] [client 196.12.128.158:51700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFJgAAAMw"] [Tue Aug 18 13:04:27.090833 2026] [security2:error] [pid 139043:tid 139250] [client 20.186.30.159:10024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/nox.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFKAAAANI"] [Tue Aug 18 13:04:27.127160 2026] [security2:error] [pid 139043:tid 139245] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFKgAAAM0"] [Tue Aug 18 13:04:27.153309 2026] [security2:error] [pid 139043:tid 139176] [client 172.182.217.32:21804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/images/php8.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFMAAAAIg"] [Tue Aug 18 13:04:27.171648 2026] [security2:error] [pid 139043:tid 139220] [client 20.171.51.14:58005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fo.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFMQAAALQ"] [Tue Aug 18 13:04:27.175966 2026] [security2:error] [pid 139043:tid 139228] [client 52.139.47.57:33823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ultra.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFMwAAALw"] [Tue Aug 18 13:04:27.257004 2026] [security2:error] [pid 139043:tid 139267] [client 20.151.109.219:31703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/jm.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFQQAAAOM"] [Tue Aug 18 13:04:27.300243 2026] [security2:error] [pid 139043:tid 139255] [client 132.196.30.78:19479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFRAAAANc"] [Tue Aug 18 13:04:27.343027 2026] [autoindex:error] [pid 139043:tid 139291] [client 4.232.151.198:24246] AH01276: Cannot serve directory /home2/pixmid70/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:27.397412 2026] [security2:error] [pid 139043:tid 139175] [client 20.104.100.201:23914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/dot.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFcQAAAIc"] [Tue Aug 18 13:04:27.408842 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/ano.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFcgAAAOQ"] [Tue Aug 18 13:04:27.409060 2026] [security2:error] [pid 139043:tid 139203] [client 68.155.156.252:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/bajah.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFcwAAAKM"] [Tue Aug 18 13:04:27.415523 2026] [security2:error] [pid 139043:tid 139223] [client 20.1.169.243:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/radio.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFdAAAALc"] [Tue Aug 18 13:04:27.481935 2026] [security2:error] [pid 139043:tid 139211] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFeAAAAKs"] [Tue Aug 18 13:04:27.497409 2026] [security2:error] [pid 139043:tid 139180] [client 68.221.73.131:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file1221.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFewAAAIw"] [Tue Aug 18 13:04:27.503800 2026] [security2:error] [pid 139043:tid 139275] [client 20.151.109.219:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFfAAAAOs"] [Tue Aug 18 13:04:27.529050 2026] [security2:error] [pid 139043:tid 139289] [client 20.52.168.85:5181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/gecko-new.php.1"] [unique_id "aoSCi_2v-lWn9OzQT7VFfwAAAPk"] [Tue Aug 18 13:04:27.530869 2026] [authz_core:error] [pid 139043:tid 139169] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:27.531112 2026] [authz_core:error] [pid 139043:tid 139169] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:27.548156 2026] [security2:error] [pid 139043:tid 139297] [client 4.232.151.198:24246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-signdown.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFggAAAQE"] [Tue Aug 18 13:04:27.592551 2026] [security2:error] [pid 139043:tid 139212] [client 52.139.47.57:29214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/vv.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFgwAAAKw"] [Tue Aug 18 13:04:27.600847 2026] [security2:error] [pid 139043:tid 139186] [client 213.35.127.232:56569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFhAAAAJI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:27.659040 2026] [security2:error] [pid 139043:tid 139238] [client 172.182.217.32:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/php8.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFhwAAAMY"] [Tue Aug 18 13:04:27.659756 2026] [security2:error] [pid 139043:tid 139281] [client 20.51.153.15:9147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lj.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFiAAAAPE"] [Tue Aug 18 13:04:27.683822 2026] [security2:error] [pid 139043:tid 139209] [client 20.250.13.23:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFiQAAAKk"] [Tue Aug 18 13:04:27.784084 2026] [security2:error] [pid 139043:tid 139260] [client 20.1.169.243:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/rem.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFkAAAANw"] [Tue Aug 18 13:04:27.794657 2026] [security2:error] [pid 139043:tid 139241] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFkQAAAMk"] [Tue Aug 18 13:04:27.822634 2026] [security2:error] [pid 139043:tid 139264] [client 74.248.130.103:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/nox.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFkwAAAOA"] [Tue Aug 18 13:04:27.824508 2026] [security2:error] [pid 139043:tid 139261] [client 20.206.73.37:19983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/puc.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFlgAAAN0"] [Tue Aug 18 13:04:27.830232 2026] [authz_core:error] [pid 139043:tid 139162] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:27.830577 2026] [authz_core:error] [pid 139043:tid 139162] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:27.873822 2026] [security2:error] [pid 139043:tid 139290] [client 20.171.51.14:13402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/loading.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFrwAAAPo"] [Tue Aug 18 13:04:27.894013 2026] [security2:error] [pid 139043:tid 139263] [client 52.173.121.69:45940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFsAAAAN8"] [Tue Aug 18 13:04:27.900134 2026] [security2:error] [pid 139043:tid 139298] [client 20.151.109.219:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/iu.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFsQAAAQI"] [Tue Aug 18 13:04:27.934992 2026] [security2:error] [pid 139043:tid 139286] [client 132.196.30.78:20071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/404.php"] [unique_id "aoSCi_2v-lWn9OzQT7VFtQAAAPY"] [Tue Aug 18 13:04:28.010033 2026] [security2:error] [pid 139043:tid 139176] [client 52.139.47.57:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/V5.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFuwAAAIg"] [Tue Aug 18 13:04:28.019517 2026] [security2:error] [pid 139043:tid 139265] [client 20.51.153.15:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kh.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFvAAAAOE"] [Tue Aug 18 13:04:28.028625 2026] [security2:error] [pid 139043:tid 139199] [client 68.221.73.131:36031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/inx.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFvQAAAJ8"] [Tue Aug 18 13:04:28.038943 2026] [security2:error] [pid 139043:tid 139224] [client 20.104.100.201:23967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/005.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFvgAAALg"] [Tue Aug 18 13:04:28.071343 2026] [security2:error] [pid 139043:tid 139247] [client 4.232.151.198:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/themes.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFvwAAAM8"] [Tue Aug 18 13:04:28.112927 2026] [security2:error] [pid 139043:tid 139274] [client 20.116.17.175:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFwQAAAOo"] [Tue Aug 18 13:04:28.127878 2026] [security2:error] [pid 139043:tid 139276] [client 158.23.17.4:7196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/53.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFwwAAAOw"] [Tue Aug 18 13:04:28.142518 2026] [security2:error] [pid 139043:tid 139174] [client 20.52.168.85:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/OthioNDwMEK.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFxQAAAIY"] [Tue Aug 18 13:04:28.145523 2026] [security2:error] [pid 139043:tid 139228] [client 172.182.217.32:21832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/cgi-bin/php8.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFxgAAALw"] [Tue Aug 18 13:04:28.147027 2026] [security2:error] [pid 139043:tid 139178] [client 20.1.169.243:11074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/server.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFyAAAAIo"] [Tue Aug 18 13:04:28.176941 2026] [security2:error] [pid 139043:tid 139272] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFygAAAOg"] [Tue Aug 18 13:04:28.261357 2026] [security2:error] [pid 139043:tid 139214] [client 4.232.151.198:29640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/pki-validation/flower.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFywAAAK4"] [Tue Aug 18 13:04:28.278298 2026] [security2:error] [pid 139043:tid 139173] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/ai.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFzQAAAIU"] [Tue Aug 18 13:04:28.280565 2026] [security2:error] [pid 139043:tid 139200] [client 20.51.153.15:9144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/jb.php"] [unique_id "aoSCjP2v-lWn9OzQT7VFzgAAAKA"] [Tue Aug 18 13:04:28.346151 2026] [security2:error] [pid 139043:tid 139183] [client 20.250.13.23:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/lite.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF0AAAAI8"] [Tue Aug 18 13:04:28.431521 2026] [security2:error] [pid 139043:tid 139175] [client 52.139.47.57:10999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-user.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF5QAAAIc"] [Tue Aug 18 13:04:28.453693 2026] [security2:error] [pid 139043:tid 139197] [client 20.186.30.159:10071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/akismet.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF6AAAAJ0"] [Tue Aug 18 13:04:28.510155 2026] [security2:error] [pid 139043:tid 139243] [client 20.1.169.243:10913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/settings.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF6gAAAMs"] [Tue Aug 18 13:04:28.516846 2026] [security2:error] [pid 139043:tid 139226] [client 20.104.100.201:24063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/v2.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF6wAAALo"] [Tue Aug 18 13:04:28.522682 2026] [security2:error] [pid 139043:tid 139293] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF7AAAAP0"] [Tue Aug 18 13:04:28.584193 2026] [security2:error] [pid 139043:tid 139297] [client 52.173.121.69:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF8gAAAQE"] [Tue Aug 18 13:04:28.590974 2026] [security2:error] [pid 139043:tid 139288] [client 68.155.156.252:35247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/ajax.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF8wAAAPg"] [Tue Aug 18 13:04:28.619887 2026] [security2:error] [pid 139043:tid 139236] [client 213.35.127.232:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF9AAAAMQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:28.647085 2026] [security2:error] [pid 139043:tid 139219] [client 20.51.153.15:9181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/do.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF-AAAALM"] [Tue Aug 18 13:04:28.672701 2026] [security2:error] [pid 139043:tid 139275] [client 172.182.217.32:21781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-content/gallery/php8.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF-QAAAOs"] [Tue Aug 18 13:04:28.672851 2026] [security2:error] [pid 139043:tid 139283] [client 20.206.73.37:35281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/clque.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF-gAAAPM"] [Tue Aug 18 13:04:28.733839 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:28.734099 2026] [authz_core:error] [pid 139043:tid 139141] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:28.740082 2026] [security2:error] [pid 139043:tid 139233] [client 68.221.73.131:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/reviall.php"] [unique_id "aoSCjP2v-lWn9OzQT7VF_QAAAME"] [Tue Aug 18 13:04:28.797478 2026] [security2:error] [pid 139043:tid 139262] [client 20.52.168.85:5129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/sim.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGAQAAAN4"] [Tue Aug 18 13:04:28.839208 2026] [security2:error] [pid 139043:tid 139266] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGAwAAAOI"] [Tue Aug 18 13:04:28.855503 2026] [security2:error] [pid 139043:tid 139287] [client 52.139.47.57:37545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGBAAAAPc"] [Tue Aug 18 13:04:28.872504 2026] [security2:error] [pid 139043:tid 139235] [client 20.1.169.243:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/sf.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGBQAAAMM"] [Tue Aug 18 13:04:28.885449 2026] [security2:error] [pid 139043:tid 139193] [client 20.171.51.14:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ke.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGBwAAAJk"] [Tue Aug 18 13:04:28.910575 2026] [security2:error] [pid 139043:tid 139218] [client 4.232.151.198:48540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/cv.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGCQAAALI"] [Tue Aug 18 13:04:28.938434 2026] [security2:error] [pid 139043:tid 139207] [client 20.151.109.219:46532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wj.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGCgAAAKc"] [Tue Aug 18 13:04:28.989577 2026] [security2:error] [pid 139043:tid 139216] [client 20.250.13.23:55671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSCjP2v-lWn9OzQT7VGDAAAALA"] [Tue Aug 18 13:04:28.992322 2026] [security2:error] [pid 139043:tid 139277] [client 20.51.153.15:8748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/yw.php"] [unique_id "aoSCjP2v-lWn9OzQT7VGDQAAAO0"] [Tue Aug 18 13:04:29.038029 2026] [authz_core:error] [pid 139043:tid 139165] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:29.038297 2026] [authz_core:error] [pid 139043:tid 139165] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:29.055644 2026] [security2:error] [pid 139043:tid 139286] [client 20.151.109.219:19729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pk.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGEAAAAPY"] [Tue Aug 18 13:04:29.067646 2026] [security2:error] [pid 139043:tid 139241] [client 4.232.151.198:25221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/.dj/index.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGEQAAAMk"] [Tue Aug 18 13:04:29.149803 2026] [security2:error] [pid 139043:tid 139248] [client 86.120.159.145:62169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGFwAAANA"] [Tue Aug 18 13:04:29.149905 2026] [security2:error] [pid 139043:tid 139248] [client 86.120.159.145:62169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGFwAAANA"] [Tue Aug 18 13:04:29.156589 2026] [security2:error] [pid 139043:tid 139247] [client 158.23.17.4:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lq.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGGAAAAM8"] [Tue Aug 18 13:04:29.160081 2026] [security2:error] [pid 139043:tid 139177] [client 172.182.217.32:21817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asmetaleletromecanica.com.br"] [uri "/wp-includes/blocks/php8.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGGQAAAIk"] [Tue Aug 18 13:04:29.161963 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:23877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wkl.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGGgAAAOM"] [Tue Aug 18 13:04:29.236729 2026] [security2:error] [pid 139043:tid 139246] [client 20.1.169.243:11192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/size.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGHgAAAM4"] [Tue Aug 18 13:04:29.263705 2026] [security2:error] [pid 139043:tid 139295] [client 52.139.47.57:33854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGIQAAAP8"] [Tue Aug 18 13:04:29.284171 2026] [security2:error] [pid 139043:tid 139253] [client 20.51.153.15:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/qh.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGJQAAANU"] [Tue Aug 18 13:04:29.293004 2026] [security2:error] [pid 139043:tid 139200] [client 191.237.254.161:49972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/admin.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGJgAAAKA"] [Tue Aug 18 13:04:29.297871 2026] [security2:error] [pid 139043:tid 139268] [client 68.155.154.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/images/security.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGJwAAAOQ"] [Tue Aug 18 13:04:29.335193 2026] [security2:error] [pid 139043:tid 139204] [client 68.221.73.131:26061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/11.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGKgAAAKQ"] [Tue Aug 18 13:04:29.338579 2026] [authz_core:error] [pid 139043:tid 139102] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:29.338833 2026] [authz_core:error] [pid 139043:tid 139102] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:29.373884 2026] [security2:error] [pid 139043:tid 139180] [client 20.124.247.79:16399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGLgAAAIw"] [Tue Aug 18 13:04:29.400991 2026] [security2:error] [pid 139043:tid 139255] [client 20.52.168.85:5287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/y.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGLwAAANc"] [Tue Aug 18 13:04:29.407936 2026] [security2:error] [pid 139043:tid 139205] [client 20.25.139.174:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/inputs.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGMAAAAKU"] [Tue Aug 18 13:04:29.436890 2026] [security2:error] [pid 139043:tid 139261] [client 216.73.160.239:53871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "baccovaledosvinhedos.com.br"] [uri "/wp-login.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGMQAAAN0"] [Tue Aug 18 13:04:29.450989 2026] [security2:error] [pid 139043:tid 139206] [client 168.62.48.100:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGMwAAAKY"] [Tue Aug 18 13:04:29.469961 2026] [security2:error] [pid 139043:tid 139288] [client 74.248.130.103:56981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file59.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGNAAAAPg"] [Tue Aug 18 13:04:29.478093 2026] [security2:error] [pid 139043:tid 139249] [client 20.171.51.14:38722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nh.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGNQAAANE"] [Tue Aug 18 13:04:29.484010 2026] [security2:error] [pid 139043:tid 139236] [client 20.151.109.219:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/74.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGNgAAAMQ"] [Tue Aug 18 13:04:29.510739 2026] [security2:error] [pid 139043:tid 139190] [client 20.104.100.201:23955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGOQAAAJY"] [Tue Aug 18 13:04:29.518686 2026] [security2:error] [pid 139043:tid 139252] [client 20.116.17.175:3429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/root.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGOgAAANQ"] [Tue Aug 18 13:04:29.555589 2026] [security2:error] [pid 139043:tid 139245] [client 178.20.47.39:61820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.47.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sfsengenharia.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGPAAAAM0"], referer: https://sfsengenharia.com.br/ [Tue Aug 18 13:04:29.606673 2026] [security2:error] [pid 139043:tid 139188] [client 20.1.169.243:10887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/staging/wp-content/test.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGPwAAAJQ"] [Tue Aug 18 13:04:29.631210 2026] [security2:error] [pid 139043:tid 139184] [client 52.173.121.69:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGQAAAAJA"] [Tue Aug 18 13:04:29.633732 2026] [security2:error] [pid 139043:tid 139221] [client 20.250.13.23:55649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGQgAAALU"] [Tue Aug 18 13:04:29.647450 2026] [security2:error] [pid 139043:tid 139264] [client 20.151.109.219:17609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ge.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGRAAAAOA"] [Tue Aug 18 13:04:29.648833 2026] [security2:error] [pid 139043:tid 139217] [client 213.35.127.232:57058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGRQAAALE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:29.680050 2026] [security2:error] [pid 139043:tid 139219] [client 52.139.47.57:26308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/worksec.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGRgAAALM"] [Tue Aug 18 13:04:29.707488 2026] [security2:error] [pid 139043:tid 139218] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/sf.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGSQAAALI"] [Tue Aug 18 13:04:29.869198 2026] [security2:error] [pid 139043:tid 139237] [client 4.232.151.198:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/moduleswp.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGUgAAAMU"] [Tue Aug 18 13:04:29.875046 2026] [security2:error] [pid 139043:tid 139176] [client 20.215.241.237:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/dex.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGUwAAAIg"] [Tue Aug 18 13:04:29.892905 2026] [security2:error] [pid 139043:tid 139239] [client 213.202.253.4:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/schallfuns.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGVQAAAMc"], referer: www.google.com [Tue Aug 18 13:04:29.910757 2026] [security2:error] [pid 139043:tid 139265] [client 68.221.73.131:32405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/File.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGVwAAAOE"] [Tue Aug 18 13:04:29.942145 2026] [security2:error] [pid 139043:tid 139199] [client 20.151.109.219:17084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/pqr.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGWgAAAJ8"] [Tue Aug 18 13:04:29.948431 2026] [authz_core:error] [pid 139043:tid 139100] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:29.948684 2026] [authz_core:error] [pid 139043:tid 139100] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:29.970471 2026] [security2:error] [pid 139043:tid 139280] [client 20.1.169.243:11165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/storage/index.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGXAAAAPA"] [Tue Aug 18 13:04:29.975938 2026] [security2:error] [pid 139043:tid 139187] [client 74.248.130.103:42045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGXQAAAJM"] [Tue Aug 18 13:04:29.990207 2026] [security2:error] [pid 139043:tid 139185] [client 20.25.139.174:4670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/admin.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGXgAAAJE"] [Tue Aug 18 13:04:29.997079 2026] [security2:error] [pid 139043:tid 139177] [client 40.74.65.169:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGYAAAAIk"] [Tue Aug 18 13:04:29.998687 2026] [security2:error] [pid 139043:tid 139267] [client 20.104.100.201:24057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/az.php"] [unique_id "aoSCjf2v-lWn9OzQT7VGYQAAAOM"] [Tue Aug 18 13:04:30.025871 2026] [security2:error] [pid 139043:tid 139276] [client 20.124.247.79:16408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGYgAAAOw"] [Tue Aug 18 13:04:30.057976 2026] [security2:error] [pid 139043:tid 139285] [client 20.52.168.85:5288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/xleet.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGYwAAAPU"] [Tue Aug 18 13:04:30.064065 2026] [security2:error] [pid 139043:tid 139174] [client 20.171.51.14:18684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/oo.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGZAAAAIY"] [Tue Aug 18 13:04:30.072544 2026] [security2:error] [pid 139043:tid 139228] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/xx.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGZQAAALw"] [Tue Aug 18 13:04:30.099235 2026] [security2:error] [pid 139043:tid 139240] [client 52.139.47.57:19541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-themes.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGaAAAAMg"] [Tue Aug 18 13:04:30.100737 2026] [security2:error] [pid 139043:tid 139295] [client 158.23.17.4:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/you.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGaQAAAP8"] [Tue Aug 18 13:04:30.160287 2026] [security2:error] [pid 139043:tid 139279] [client 20.51.153.15:9176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/r.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGawAAAO8"] [Tue Aug 18 13:04:30.214966 2026] [security2:error] [pid 139043:tid 139256] [client 20.151.109.219:36341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/av.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGbwAAANg"] [Tue Aug 18 13:04:30.279775 2026] [security2:error] [pid 139043:tid 139255] [client 20.186.30.159:10017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/admin.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGdgAAANc"] [Tue Aug 18 13:04:30.291094 2026] [security2:error] [pid 139043:tid 139299] [client 20.250.13.23:6308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGeAAAAQM"] [Tue Aug 18 13:04:30.344803 2026] [security2:error] [pid 139043:tid 139288] [client 20.116.17.175:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/fpwch.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGeQAAAPg"] [Tue Aug 18 13:04:30.348364 2026] [security2:error] [pid 139043:tid 139175] [client 20.1.169.243:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/storage/min.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGegAAAIc"] [Tue Aug 18 13:04:30.421999 2026] [security2:error] [pid 139043:tid 139144] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGfQAAxmQ"] [Tue Aug 18 13:04:30.422172 2026] [security2:error] [pid 139043:tid 139238] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGfQAAxmQ"] [Tue Aug 18 13:04:30.464968 2026] [security2:error] [pid 139043:tid 139208] [client 20.51.153.15:9103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/17.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGgAAAAKg"] [Tue Aug 18 13:04:30.468539 2026] [security2:error] [pid 139043:tid 139225] [client 20.104.100.201:24031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/z43agz.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGgQAAALk"] [Tue Aug 18 13:04:30.483130 2026] [security2:error] [pid 139043:tid 139188] [client 20.251.48.93:59409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/coffexium.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGggAAAJQ"] [Tue Aug 18 13:04:30.498141 2026] [security2:error] [pid 139043:tid 139183] [client 168.62.48.100:4208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/rezor.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGhQAAAI8"] [Tue Aug 18 13:04:30.523037 2026] [security2:error] [pid 139043:tid 139221] [client 74.248.130.103:35006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/aa2.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGhgAAALU"] [Tue Aug 18 13:04:30.550877 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:30.551267 2026] [authz_core:error] [pid 139043:tid 139135] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:30.567449 2026] [security2:error] [pid 139043:tid 139249] [client 20.25.139.174:4568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/goods.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGiwAAANE"] [Tue Aug 18 13:04:30.596260 2026] [autoindex:error] [pid 139043:tid 139210] [client 4.232.151.198:7693] AH01276: Cannot serve directory /home2/pixmid70/public_html/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:30.616601 2026] [security2:error] [pid 139043:tid 139207] [client 68.221.73.131:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/fi22.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGjQAAAKc"] [Tue Aug 18 13:04:30.627436 2026] [security2:error] [pid 139043:tid 139213] [client 4.223.113.180:41969] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "esteticarvca.com.br"] [uri "/1.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGjgAAAK0"] [Tue Aug 18 13:04:30.627529 2026] [security2:error] [pid 139043:tid 139213] [client 4.223.113.180:41969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/1.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGjgAAAK0"] [Tue Aug 18 13:04:30.629253 2026] [security2:error] [pid 139043:tid 139300] [client 20.124.247.79:16489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/admin.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGjwAAAQQ"] [Tue Aug 18 13:04:30.649175 2026] [security2:error] [pid 139043:tid 139182] [client 20.206.73.37:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGkQAAAI4"] [Tue Aug 18 13:04:30.661920 2026] [security2:error] [pid 139043:tid 139293] [client 213.35.127.232:57327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGkwAAAP0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:30.662738 2026] [security2:error] [pid 139043:tid 139275] [client 20.52.168.85:5156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/1index.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGlAAAAOs"] [Tue Aug 18 13:04:30.725691 2026] [security2:error] [pid 139043:tid 139241] [client 4.232.151.198:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGmAAAAMk"] [Tue Aug 18 13:04:30.786777 2026] [security2:error] [pid 139043:tid 139187] [client 20.51.153.15:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ev.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGnAAAAJM"] [Tue Aug 18 13:04:30.792529 2026] [security2:error] [pid 139043:tid 139216] [client 20.171.51.14:38733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ja.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGnQAAALA"] [Tue Aug 18 13:04:30.817786 2026] [security2:error] [pid 139043:tid 139185] [client 4.232.151.198:7693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-tinymce.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGoAAAAJE"] [Tue Aug 18 13:04:30.850478 2026] [authz_core:error] [pid 139043:tid 139085] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:30.850741 2026] [authz_core:error] [pid 139043:tid 139085] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:30.874294 2026] [security2:error] [pid 139043:tid 139178] [client 20.104.100.201:23808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/3.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGpQAAAIo"] [Tue Aug 18 13:04:30.899631 2026] [security2:error] [pid 139043:tid 139240] [client 158.23.17.4:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ez.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGqwAAAMg"] [Tue Aug 18 13:04:30.910097 2026] [security2:error] [pid 139043:tid 139292] [client 20.1.169.243:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/test.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGrQAAAPw"] [Tue Aug 18 13:04:30.922521 2026] [security2:error] [pid 139043:tid 139295] [client 20.116.17.175:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/mg.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGrwAAAP8"] [Tue Aug 18 13:04:30.929360 2026] [security2:error] [pid 139043:tid 139251] [client 20.250.13.23:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGsAAAANM"] [Tue Aug 18 13:04:30.944334 2026] [security2:error] [pid 139043:tid 139271] [client 20.186.30.159:10090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rodriguesesoutoadvocacia.com.br"] [uri "/ajax.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGsQAAAOc"] [Tue Aug 18 13:04:30.954628 2026] [security2:error] [pid 139043:tid 139177] [client 52.139.47.57:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-signin.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGsgAAAIk"] [Tue Aug 18 13:04:31.000757 2026] [security2:error] [pid 139043:tid 139289] [client 102.213.179.104:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGtAAAAPk"] [Tue Aug 18 13:04:31.000888 2026] [security2:error] [pid 139043:tid 139289] [client 102.213.179.104:61067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGtAAAAPk"] [Tue Aug 18 13:04:31.013163 2026] [security2:error] [pid 139043:tid 139263] [client 20.206.73.37:1097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/19.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGtQAAAN8"] [Tue Aug 18 13:04:31.061860 2026] [security2:error] [pid 139043:tid 139272] [client 52.167.144.195:37060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.scaclinic.com.br"] [uri "/news_page.php"] [unique_id "aoSCjv2v-lWn9OzQT7VGqgAAAOg"] [Tue Aug 18 13:04:31.135749 2026] [security2:error] [pid 139043:tid 139200] [client 20.25.139.174:4663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/file.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGuQAAAKA"] [Tue Aug 18 13:04:31.141120 2026] [security2:error] [pid 139043:tid 139261] [client 168.62.48.100:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGugAAAN0"] [Tue Aug 18 13:04:31.150288 2026] [authz_core:error] [pid 139043:tid 139168] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:31.150576 2026] [authz_core:error] [pid 139043:tid 139168] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:31.165279 2026] [security2:error] [pid 139043:tid 139190] [client 20.51.153.15:9139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xs.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGvQAAAJY"] [Tue Aug 18 13:04:31.175935 2026] [security2:error] [pid 139043:tid 139234] [client 68.221.73.131:47777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGvgAAAMI"] [Tue Aug 18 13:04:31.213937 2026] [security2:error] [pid 139043:tid 139291] [client 20.124.247.79:16405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/biufile.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGwAAAAPs"] [Tue Aug 18 13:04:31.233715 2026] [security2:error] [pid 139043:tid 139281] [client 20.250.13.23:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wk/index.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGwQAAAPE"] [Tue Aug 18 13:04:31.267948 2026] [security2:error] [pid 139043:tid 139181] [client 20.52.168.85:5303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/admin.php1"] [unique_id "aoSCj_2v-lWn9OzQT7VGwgAAAI0"] [Tue Aug 18 13:04:31.274781 2026] [security2:error] [pid 139043:tid 139192] [client 20.1.169.243:11216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/test1.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGxAAAAJg"] [Tue Aug 18 13:04:31.325110 2026] [security2:error] [pid 139043:tid 139195] [client 20.104.100.201:23945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/log.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGxgAAAJs"] [Tue Aug 18 13:04:31.338315 2026] [authz_core:error] [pid 139043:tid 139252] [client 192.178.4.133:41064] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:31.338596 2026] [authz_core:error] [pid 139043:tid 139252] [client 192.178.4.133:41064] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:31.363022 2026] [security2:error] [pid 139043:tid 139208] [client 52.139.47.57:19527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGygAAAKg"] [Tue Aug 18 13:04:31.456551 2026] [security2:error] [pid 139043:tid 139235] [client 20.51.153.15:9156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCj_2v-lWn9OzQT7VGzgAAAMM"] [Tue Aug 18 13:04:31.499771 2026] [security2:error] [pid 139043:tid 139225] [client 4.232.151.198:25219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/base.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG0QAAALk"] [Tue Aug 18 13:04:31.504209 2026] [security2:error] [pid 139043:tid 139182] [client 20.116.17.175:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/reop3.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG0gAAAI4"] [Tue Aug 18 13:04:31.565957 2026] [security2:error] [pid 139043:tid 139297] [client 20.250.13.23:6314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG1QAAAQE"] [Tue Aug 18 13:04:31.632708 2026] [security2:error] [pid 139043:tid 139222] [client 20.104.100.201:24001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ohct.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG1gAAALY"] [Tue Aug 18 13:04:31.643464 2026] [security2:error] [pid 139043:tid 139266] [client 20.1.169.243:11174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/thoms.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG1wAAAOI"] [Tue Aug 18 13:04:31.650268 2026] [security2:error] [pid 139043:tid 139269] [client 20.171.51.14:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xx.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG2AAAAOU"] [Tue Aug 18 13:04:31.655418 2026] [security2:error] [pid 139043:tid 139176] [client 20.118.133.132:7317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/mosty.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG2gAAAIg"] [Tue Aug 18 13:04:31.683503 2026] [security2:error] [pid 139043:tid 139259] [client 68.221.73.131:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG3AAAANs"] [Tue Aug 18 13:04:31.685811 2026] [security2:error] [pid 139043:tid 139217] [client 213.35.127.232:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG3QAAALE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:31.696871 2026] [security2:error] [pid 139043:tid 139300] [client 20.25.139.174:4632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG3gAAAQQ"] [Tue Aug 18 13:04:31.754865 2026] [authz_core:error] [pid 139043:tid 139162] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:31.755150 2026] [authz_core:error] [pid 139043:tid 139162] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:31.816962 2026] [security2:error] [pid 139043:tid 139276] [client 20.51.153.15:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fd.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG4wAAAOw"] [Tue Aug 18 13:04:31.868827 2026] [security2:error] [pid 139043:tid 139239] [client 20.52.168.85:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/M1.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG5QAAAMc"] [Tue Aug 18 13:04:31.885549 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:14055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/asus.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG5gAAAJk"] [Tue Aug 18 13:04:31.921534 2026] [security2:error] [pid 139043:tid 139264] [client 20.116.17.175:53823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/php5.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG5wAAAOA"] [Tue Aug 18 13:04:31.922516 2026] [security2:error] [pid 139043:tid 139295] [client 20.124.247.79:16398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/coffexium.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG6AAAAP8"] [Tue Aug 18 13:04:31.926301 2026] [security2:error] [pid 139043:tid 139238] [client 4.232.151.198:40607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ws83.php"] [unique_id "aoSCj_2v-lWn9OzQT7VG6gAAAMY"] [Tue Aug 18 13:04:32.015239 2026] [security2:error] [pid 139043:tid 139292] [client 20.1.169.243:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/tiny.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG7QAAAPw"] [Tue Aug 18 13:04:32.048110 2026] [security2:error] [pid 139043:tid 139272] [client 74.248.130.103:34945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/xamp.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG7wAAAOg"] [Tue Aug 18 13:04:32.057826 2026] [authz_core:error] [pid 139043:tid 139136] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:32.058230 2026] [authz_core:error] [pid 139043:tid 139136] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:32.087657 2026] [security2:error] [pid 139043:tid 139257] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/uwu.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG8gAAANk"] [Tue Aug 18 13:04:32.091598 2026] [security2:error] [pid 139043:tid 139200] [client 52.139.47.57:33807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ws.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG8wAAAKA"] [Tue Aug 18 13:04:32.101689 2026] [security2:error] [pid 139043:tid 139206] [client 20.226.36.136:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG9AAAAKY"] [Tue Aug 18 13:04:32.123561 2026] [security2:error] [pid 139043:tid 139248] [client 20.104.100.201:23940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ot.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG9gAAANA"] [Tue Aug 18 13:04:32.140291 2026] [security2:error] [pid 139043:tid 139234] [client 20.51.153.15:9130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/info2.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG9wAAAMI"] [Tue Aug 18 13:04:32.153688 2026] [security2:error] [pid 139043:tid 139291] [client 68.221.73.131:60567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG-QAAAPs"] [Tue Aug 18 13:04:32.173546 2026] [security2:error] [pid 139043:tid 139246] [client 20.151.109.219:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kl.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG-wAAAM4"] [Tue Aug 18 13:04:32.185294 2026] [security2:error] [pid 139043:tid 139181] [client 20.171.51.14:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/conn-test.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG_AAAAI0"] [Tue Aug 18 13:04:32.198796 2026] [security2:error] [pid 139043:tid 139204] [client 132.196.30.78:19496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wk/index.php"] [unique_id "aoSCkP2v-lWn9OzQT7VG_wAAAKQ"] [Tue Aug 18 13:04:32.201773 2026] [security2:error] [pid 139043:tid 139296] [client 20.226.36.136:65299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHAQAAAQA"] [Tue Aug 18 13:04:32.254608 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.36.136:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/weozh.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHBQAAAKc"] [Tue Aug 18 13:04:32.284896 2026] [security2:error] [pid 139043:tid 139227] [client 20.226.36.136:65289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/rymmm.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHBgAAALs"] [Tue Aug 18 13:04:32.311567 2026] [security2:error] [pid 139043:tid 139175] [client 20.25.139.174:4671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/404.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHCAAAAIc"] [Tue Aug 18 13:04:32.360701 2026] [authz_core:error] [pid 139043:tid 139139] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:32.361166 2026] [authz_core:error] [pid 139043:tid 139139] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:32.381108 2026] [security2:error] [pid 139043:tid 139262] [client 20.1.169.243:11103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/tool.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHDwAAAN4"] [Tue Aug 18 13:04:32.381132 2026] [security2:error] [pid 139043:tid 139177] [client 4.223.113.180:40225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHDgAAAIk"] [Tue Aug 18 13:04:32.425596 2026] [security2:error] [pid 139043:tid 139300] [client 20.250.13.23:6227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/ku.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHEQAAAQQ"] [Tue Aug 18 13:04:32.452594 2026] [security2:error] [pid 139043:tid 139274] [client 20.226.36.136:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/lddxs.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHEgAAAOo"] [Tue Aug 18 13:04:32.457608 2026] [security2:error] [pid 139043:tid 139216] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/signon.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHEwAAALA"] [Tue Aug 18 13:04:32.458636 2026] [security2:error] [pid 139043:tid 139254] [client 20.215.241.237:27728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/puc.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHFAAAANY"] [Tue Aug 18 13:04:32.470025 2026] [security2:error] [pid 139043:tid 139290] [client 20.52.168.85:5183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.168.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valeriana.com.br"] [uri "/ds.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHFQAAAPo"] [Tue Aug 18 13:04:32.493945 2026] [security2:error] [pid 139043:tid 139211] [client 149.34.210.141:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHFwAAAKs"] [Tue Aug 18 13:04:32.503659 2026] [security2:error] [pid 139043:tid 139285] [client 20.51.153.15:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/sx.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHGAAAAPU"] [Tue Aug 18 13:04:32.510111 2026] [security2:error] [pid 139043:tid 139221] [client 52.139.47.57:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wsa.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHGQAAALU"] [Tue Aug 18 13:04:32.579152 2026] [security2:error] [pid 139043:tid 139193] [client 20.151.109.219:46546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ag.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHHAAAAJk"] [Tue Aug 18 13:04:32.606447 2026] [security2:error] [pid 139043:tid 139299] [client 20.250.13.23:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/about.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHHQAAAQM"] [Tue Aug 18 13:04:32.615881 2026] [security2:error] [pid 139043:tid 139264] [client 20.226.36.136:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/zjggu.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHHgAAAOA"] [Tue Aug 18 13:04:32.618600 2026] [security2:error] [pid 139043:tid 139260] [client 68.155.156.252:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.transitalian.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHHwAAANw"] [Tue Aug 18 13:04:32.633040 2026] [security2:error] [pid 139043:tid 139284] [client 20.116.17.175:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/acp.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHIAAAAPQ"] [Tue Aug 18 13:04:32.663283 2026] [security2:error] [pid 139043:tid 139232] [client 20.104.100.201:23942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/v5.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHJAAAAMA"] [Tue Aug 18 13:04:32.698059 2026] [security2:error] [pid 139043:tid 139226] [client 4.232.151.198:7718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/dichku.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHKAAAALo"] [Tue Aug 18 13:04:32.716542 2026] [security2:error] [pid 139043:tid 139286] [client 20.151.109.219:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gs.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHKgAAAPY"] [Tue Aug 18 13:04:32.735036 2026] [security2:error] [pid 139043:tid 139223] [client 213.35.127.232:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHLAAAALc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:32.745631 2026] [security2:error] [pid 139043:tid 139238] [client 20.1.169.243:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/top.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHLQAAAMY"] [Tue Aug 18 13:04:32.760151 2026] [security2:error] [pid 139043:tid 139211] [client 149.34.210.141:53888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHFwAAAKs"] [Tue Aug 18 13:04:32.762704 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHLwAAAJY"] [Tue Aug 18 13:04:32.793701 2026] [security2:error] [pid 139043:tid 139233] [client 20.251.48.93:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHMAAAAME"] [Tue Aug 18 13:04:32.833870 2026] [security2:error] [pid 139043:tid 139220] [client 20.51.153.15:8385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/nu.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHNAAAALQ"] [Tue Aug 18 13:04:32.851109 2026] [security2:error] [pid 139043:tid 139296] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/file61.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHNgAAAQA"] [Tue Aug 18 13:04:32.851545 2026] [security2:error] [pid 139043:tid 139240] [client 4.232.151.198:48526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/atex1.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHNwAAAMg"] [Tue Aug 18 13:04:32.926613 2026] [security2:error] [pid 139043:tid 139186] [client 20.25.139.174:4669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wk/index.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHOQAAAJI"] [Tue Aug 18 13:04:32.944556 2026] [security2:error] [pid 139043:tid 139192] [client 52.139.47.57:19528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/w.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHOwAAAJg"] [Tue Aug 18 13:04:32.962281 2026] [authz_core:error] [pid 139043:tid 139052] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:32.962729 2026] [authz_core:error] [pid 139043:tid 139052] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:32.968932 2026] [security2:error] [pid 139043:tid 139265] [client 68.221.73.131:35987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHPgAAAOE"] [Tue Aug 18 13:04:32.984437 2026] [security2:error] [pid 139043:tid 139279] [client 20.79.204.6:9710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/manager.php"] [unique_id "aoSCkP2v-lWn9OzQT7VHPwAAAO8"] [Tue Aug 18 13:04:33.002484 2026] [security2:error] [pid 139043:tid 139244] [client 20.171.51.14:57992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fg.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHQAAAAMw"] [Tue Aug 18 13:04:33.034082 2026] [security2:error] [pid 139043:tid 139287] [client 20.151.109.219:40486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ig.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHQwAAAPc"] [Tue Aug 18 13:04:33.040513 2026] [security2:error] [pid 139043:tid 139177] [client 103.59.161.151:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpcalendars.qtag.com.br"] [uri "/index.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHRAAAAIk"] [Tue Aug 18 13:04:33.041923 2026] [security2:error] [pid 139043:tid 139262] [client 20.124.247.79:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/dex.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHRQAAAN4"] [Tue Aug 18 13:04:33.065666 2026] [access_compat:error] [pid 139043:tid 139188] [client 87.250.224.205:53344] AH01797: client denied by server configuration: /home1/classea/public_html/robots.txt [Tue Aug 18 13:04:33.077213 2026] [security2:error] [pid 139043:tid 139300] [client 158.23.17.4:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/22.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHTQAAAQQ"] [Tue Aug 18 13:04:33.084267 2026] [security2:error] [pid 139043:tid 139224] [client 20.151.109.219:46435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHTgAAALg"] [Tue Aug 18 13:04:33.102418 2026] [security2:error] [pid 139043:tid 139281] [client 132.196.30.78:19480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/about.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHTwAAAPE"] [Tue Aug 18 13:04:33.117686 2026] [security2:error] [pid 139043:tid 139222] [client 20.1.169.243:10911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/txets.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHUQAAALY"] [Tue Aug 18 13:04:33.125285 2026] [security2:error] [pid 139043:tid 139195] [client 20.51.153.15:8770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ko.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHUgAAAJs"] [Tue Aug 18 13:04:33.160690 2026] [security2:error] [pid 139043:tid 139185] [client 20.104.100.201:24048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHVAAAAJE"] [Tue Aug 18 13:04:33.210064 2026] [security2:error] [pid 139043:tid 139276] [client 20.226.36.136:62150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHWAAAAOw"] [Tue Aug 18 13:04:33.263707 2026] [security2:error] [pid 139043:tid 139263] [client 4.223.113.180:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHXAAAAN8"] [Tue Aug 18 13:04:33.266238 2026] [authz_core:error] [pid 139043:tid 139117] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:33.266688 2026] [authz_core:error] [pid 139043:tid 139117] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:33.270278 2026] [security2:error] [pid 139043:tid 139284] [client 20.250.13.23:6216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/chosen.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHXQAAAPQ"] [Tue Aug 18 13:04:33.302467 2026] [security2:error] [pid 139043:tid 139232] [client 20.116.17.175:3409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/yas.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHYAAAAMA"] [Tue Aug 18 13:04:33.307068 2026] [security2:error] [pid 139043:tid 139295] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHWwAA_2w"] [Tue Aug 18 13:04:33.366249 2026] [security2:error] [pid 139043:tid 139217] [client 52.139.47.57:37519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/x.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHYwAAALE"] [Tue Aug 18 13:04:33.366363 2026] [autoindex:error] [pid 139043:tid 139216] [client 4.232.151.198:7774] AH01276: Cannot serve directory /home2/pixmid70/public_html/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:33.373746 2026] [security2:error] [pid 139043:tid 139261] [client 20.206.73.37:24516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/nano.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHZAAAAN0"] [Tue Aug 18 13:04:33.412975 2026] [security2:error] [pid 139043:tid 139206] [client 168.62.48.100:5563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHZgAAAKY"] [Tue Aug 18 13:04:33.432267 2026] [security2:error] [pid 139043:tid 139237] [client 20.151.109.219:31696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ta.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHZwAAAMU"] [Tue Aug 18 13:04:33.435419 2026] [security2:error] [pid 139043:tid 139288] [client 20.51.153.15:8823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/pl.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHaAAAAPg"] [Tue Aug 18 13:04:33.465863 2026] [security2:error] [pid 139043:tid 139292] [client 157.20.138.62:58564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHaQAAAPw"] [Tue Aug 18 13:04:33.465965 2026] [security2:error] [pid 139043:tid 139292] [client 157.20.138.62:58564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHaQAAAPw"] [Tue Aug 18 13:04:33.481244 2026] [security2:error] [pid 139043:tid 139233] [client 68.221.73.131:32396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHawAAAME"] [Tue Aug 18 13:04:33.484219 2026] [security2:error] [pid 139043:tid 139257] [client 20.1.169.243:10933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/virus.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHbAAAANk"] [Tue Aug 18 13:04:33.495782 2026] [security2:error] [pid 139043:tid 139256] [client 20.25.139.174:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/about.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHbQAAANg"] [Tue Aug 18 13:04:33.531126 2026] [security2:error] [pid 139043:tid 139183] [client 20.151.109.219:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/st.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHcAAAAI8"] [Tue Aug 18 13:04:33.551143 2026] [security2:error] [pid 139043:tid 139194] [client 20.226.36.136:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHcgAAAJo"] [Tue Aug 18 13:04:33.562506 2026] [authz_core:error] [pid 139043:tid 139061] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:33.562776 2026] [authz_core:error] [pid 139043:tid 139061] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:33.577137 2026] [security2:error] [pid 139043:tid 139197] [client 4.232.151.198:7774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/image.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHdQAAAJ0"] [Tue Aug 18 13:04:33.582806 2026] [security2:error] [pid 139043:tid 139208] [client 40.74.65.169:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/av.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHdgAAAKg"] [Tue Aug 18 13:04:33.621889 2026] [security2:error] [pid 139043:tid 139207] [client 20.104.100.201:23973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHdwAAAKc"] [Tue Aug 18 13:04:33.679388 2026] [security2:error] [pid 139043:tid 139265] [client 74.248.130.103:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/bless.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHfQAAAOE"] [Tue Aug 18 13:04:33.698390 2026] [security2:error] [pid 139043:tid 139296] [client 132.196.30.78:19466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/term.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHfwAAAQA"] [Tue Aug 18 13:04:33.708265 2026] [security2:error] [pid 139043:tid 139266] [client 20.226.36.136:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/kopyw.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHgAAAAOI"] [Tue Aug 18 13:04:33.748358 2026] [security2:error] [pid 139043:tid 139269] [client 18.222.110.210:32812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "silviosantanaadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSCkf2v-lWn9OzQT7VHggAAAOU"] [Tue Aug 18 13:04:33.753831 2026] [security2:error] [pid 139043:tid 139238] [client 213.35.127.232:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHgwAAAMY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:33.780882 2026] [security2:error] [pid 139043:tid 139186] [client 52.139.47.57:32815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/xx.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHhQAAAJI"] [Tue Aug 18 13:04:33.802701 2026] [security2:error] [pid 139043:tid 139259] [client 18.222.110.210:32816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "silviosantanaadvocacia.com.br"] [uri "/robots.txt"] [unique_id "aoSCkf2v-lWn9OzQT7VHhgAAANs"] [Tue Aug 18 13:04:33.810224 2026] [security2:error] [pid 139043:tid 139300] [client 20.51.153.15:9164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/env.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHhwAAAQQ"] [Tue Aug 18 13:04:33.812803 2026] [security2:error] [pid 139043:tid 139224] [client 20.171.51.14:58011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ve.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHiAAAALg"] [Tue Aug 18 13:04:33.849377 2026] [security2:error] [pid 139043:tid 139241] [client 20.1.169.243:11126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/we.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHiwAAAMk"] [Tue Aug 18 13:04:33.870728 2026] [authz_core:error] [pid 139043:tid 139129] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:33.871158 2026] [authz_core:error] [pid 139043:tid 139129] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:33.872098 2026] [security2:error] [pid 139043:tid 139225] [client 20.151.109.219:46411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/le.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHjQAAALk"] [Tue Aug 18 13:04:33.881555 2026] [security2:error] [pid 139043:tid 139254] [client 20.151.109.219:31686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/34.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHjgAAANY"] [Tue Aug 18 13:04:33.893453 2026] [security2:error] [pid 139043:tid 139279] [client 20.250.13.23:6285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/asd.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHjwAAAO8"] [Tue Aug 18 13:04:33.900819 2026] [security2:error] [pid 139043:tid 139298] [client 178.153.171.161:31382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHkAAAAQI"] [Tue Aug 18 13:04:33.900965 2026] [security2:error] [pid 139043:tid 139298] [client 178.153.171.161:31382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHkAAAAQI"] [Tue Aug 18 13:04:33.908556 2026] [security2:error] [pid 139043:tid 139267] [client 158.23.17.4:56561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/zs.php"] [unique_id "aoSCkf2v-lWn9OzQT7VHkQAAAOM"] [Tue Aug 18 13:04:34.016273 2026] [security2:error] [pid 139043:tid 139284] [client 20.104.100.201:24047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/dk.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHlQAAAPQ"] [Tue Aug 18 13:04:34.020908 2026] [security2:error] [pid 139043:tid 139229] [client 20.226.36.136:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/zznmg.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHlwAAAL0"] [Tue Aug 18 13:04:34.028021 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:13772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lw.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHmAAAAPk"] [Tue Aug 18 13:04:34.032254 2026] [security2:error] [pid 139043:tid 139232] [client 18.222.110.210:32820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "silviosantanaadvocacia.com.br"] [uri "/ads.txt"] [unique_id "aoSCkv2v-lWn9OzQT7VHmQAAAMA"] [Tue Aug 18 13:04:34.039355 2026] [security2:error] [pid 139043:tid 139222] [client 20.25.139.174:4656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/term.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHmgAAALY"] [Tue Aug 18 13:04:34.053421 2026] [security2:error] [pid 139043:tid 139282] [client 68.221.73.131:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHmwAAAPI"] [Tue Aug 18 13:04:34.066193 2026] [security2:error] [pid 139043:tid 139258] [client 18.222.110.210:43710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "silviosantanaadvocacia.com.br"] [uri "/"] [unique_id "aoSCkv2v-lWn9OzQT7VHnAAAANo"] [Tue Aug 18 13:04:34.106177 2026] [security2:error] [pid 139043:tid 139286] [client 20.124.247.79:16487] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/1.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHnwAAAPY"] [Tue Aug 18 13:04:34.106281 2026] [security2:error] [pid 139043:tid 139286] [client 20.124.247.79:16487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/1.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHnwAAAPY"] [Tue Aug 18 13:04:34.138949 2026] [security2:error] [pid 139043:tid 139193] [client 20.116.17.175:53135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ah25.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHowAAAJk"] [Tue Aug 18 13:04:34.167874 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:34.168128 2026] [authz_core:error] [pid 139043:tid 139097] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:34.187661 2026] [security2:error] [pid 139043:tid 139234] [client 20.151.109.219:5320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/hr.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHpQAAAMI"] [Tue Aug 18 13:04:34.205071 2026] [security2:error] [pid 139043:tid 139264] [client 4.232.151.198:7703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/RxR_cbpre.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHqAAAAOA"] [Tue Aug 18 13:04:34.206487 2026] [security2:error] [pid 139043:tid 139295] [client 52.139.47.57:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHpgAAAP8"] [Tue Aug 18 13:04:34.237048 2026] [security2:error] [pid 139043:tid 139242] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/copypaths.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHqgAAAMo"] [Tue Aug 18 13:04:34.246112 2026] [security2:error] [pid 139043:tid 139220] [client 20.79.204.6:9709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/w1.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHqwAAALQ"] [Tue Aug 18 13:04:34.299574 2026] [security2:error] [pid 139043:tid 139268] [client 20.51.153.15:8811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/mz.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHsQAAAOQ"] [Tue Aug 18 13:04:34.343606 2026] [security2:error] [pid 139043:tid 139290] [client 138.36.100.162:42435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHtgAAAPo"] [Tue Aug 18 13:04:34.343752 2026] [security2:error] [pid 139043:tid 139290] [client 138.36.100.162:42435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHtgAAAPo"] [Tue Aug 18 13:04:34.360765 2026] [security2:error] [pid 139043:tid 139250] [client 20.104.100.201:24013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/bal.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHvAAAANI"] [Tue Aug 18 13:04:34.393410 2026] [security2:error] [pid 139043:tid 139217] [client 132.196.30.78:20054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHwQAAALE"] [Tue Aug 18 13:04:34.427911 2026] [security2:error] [pid 139043:tid 139297] [client 20.151.109.219:38597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/he.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHwgAAAQE"] [Tue Aug 18 13:04:34.526355 2026] [security2:error] [pid 139043:tid 139236] [client 68.155.154.236:8862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHxQAAAMQ"] [Tue Aug 18 13:04:34.550339 2026] [security2:error] [pid 139043:tid 139204] [client 20.51.153.15:9127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ft.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHxgAAAKQ"] [Tue Aug 18 13:04:34.556783 2026] [security2:error] [pid 139043:tid 139076] [remote 91.86.16.6:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.16.86.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHxwAAkCA"] [Tue Aug 18 13:04:34.569849 2026] [security2:error] [pid 139043:tid 139235] [client 20.250.13.23:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/akc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHygAAAMM"] [Tue Aug 18 13:04:34.576012 2026] [security2:error] [pid 139043:tid 139259] [client 20.151.109.219:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kt.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHywAAANs"] [Tue Aug 18 13:04:34.581269 2026] [security2:error] [pid 139043:tid 139224] [client 68.221.73.131:26535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/media.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHzAAAALg"] [Tue Aug 18 13:04:34.594294 2026] [security2:error] [pid 139043:tid 139199] [client 103.120.71.157:36877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHzgAAAJ8"] [Tue Aug 18 13:04:34.594398 2026] [security2:error] [pid 139043:tid 139199] [client 103.120.71.157:36877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHzgAAAJ8"] [Tue Aug 18 13:04:34.611667 2026] [security2:error] [pid 139043:tid 139296] [client 20.25.139.174:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCkv2v-lWn9OzQT7VHzwAAAQA"] [Tue Aug 18 13:04:34.627263 2026] [security2:error] [pid 139043:tid 139269] [client 52.139.47.57:37563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/y.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH0AAAAOU"] [Tue Aug 18 13:04:34.659229 2026] [security2:error] [pid 139043:tid 139241] [client 20.171.51.14:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ia.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH0wAAAMk"] [Tue Aug 18 13:04:34.677113 2026] [security2:error] [pid 139043:tid 139225] [client 20.1.169.243:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/work.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH1AAAALk"] [Tue Aug 18 13:04:34.766841 2026] [security2:error] [pid 139043:tid 139175] [client 213.35.127.232:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH2AAAAIc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:34.767705 2026] [security2:error] [pid 139043:tid 139298] [client 20.104.100.201:23981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/yawa.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH2QAAAQI"] [Tue Aug 18 13:04:34.780165 2026] [security2:error] [pid 139043:tid 139276] [client 20.215.241.237:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/inso.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH2gAAAOw"] [Tue Aug 18 13:04:34.821300 2026] [security2:error] [pid 139043:tid 139173] [client 20.250.13.23:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/term.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH2wAAAIU"] [Tue Aug 18 13:04:34.831742 2026] [security2:error] [pid 139043:tid 139253] [client 20.51.153.15:8705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/h.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH3AAAANU"] [Tue Aug 18 13:04:34.869656 2026] [security2:error] [pid 139043:tid 139289] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/bless6.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH3gAAAPk"] [Tue Aug 18 13:04:34.882451 2026] [security2:error] [pid 139043:tid 139281] [client 4.232.151.198:7690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ciis.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH3wAAAPE"] [Tue Aug 18 13:04:34.906160 2026] [security2:error] [pid 139043:tid 139282] [client 20.251.48.93:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/sf.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH4AAAAPI"] [Tue Aug 18 13:04:34.908055 2026] [security2:error] [pid 139043:tid 139258] [client 20.151.109.219:21948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vj.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH4QAAANo"] [Tue Aug 18 13:04:34.908081 2026] [security2:error] [pid 139043:tid 139203] [client 191.237.254.161:49112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jotaautos.com.br"] [uri "/ajax.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH4gAAAKM"] [Tue Aug 18 13:04:34.911556 2026] [security2:error] [pid 139043:tid 139255] [client 20.151.109.219:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ww.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH4wAAANc"] [Tue Aug 18 13:04:34.912624 2026] [security2:error] [pid 139043:tid 139212] [client 20.226.36.136:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH5AAAAKw"] [Tue Aug 18 13:04:34.933010 2026] [security2:error] [pid 139043:tid 139113] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH5gAA_kU"] [Tue Aug 18 13:04:34.933210 2026] [security2:error] [pid 139043:tid 139294] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH5gAA_kU"] [Tue Aug 18 13:04:34.985740 2026] [security2:error] [pid 139043:tid 139292] [client 20.116.17.175:55419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/ano.php"] [unique_id "aoSCkv2v-lWn9OzQT7VH5wAAAPw"] [Tue Aug 18 13:04:35.033363 2026] [security2:error] [pid 139043:tid 139181] [client 20.171.51.14:38751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kn.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH6QAAAI0"] [Tue Aug 18 13:04:35.047093 2026] [security2:error] [pid 139043:tid 139222] [client 18.222.110.210:53306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.silviosantanaadvocacia.com.br"] [uri "/"] [unique_id "aoSCk_2v-lWn9OzQT7VH6gAAALY"] [Tue Aug 18 13:04:35.050704 2026] [security2:error] [pid 139043:tid 139252] [client 20.1.169.243:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH6wAAANQ"] [Tue Aug 18 13:04:35.071494 2026] [authz_core:error] [pid 139043:tid 139093] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:35.071798 2026] [authz_core:error] [pid 139043:tid 139093] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:35.127994 2026] [security2:error] [pid 139043:tid 139240] [client 20.151.109.219:27734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH8gAAAMg"] [Tue Aug 18 13:04:35.142380 2026] [security2:error] [pid 139043:tid 139208] [client 68.221.73.131:39749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/inso.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH9AAAAKg"] [Tue Aug 18 13:04:35.164624 2026] [security2:error] [pid 139043:tid 139230] [client 158.23.17.4:40399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/iz.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH9QAAAL4"] [Tue Aug 18 13:04:35.200214 2026] [security2:error] [pid 139043:tid 139291] [client 20.250.13.23:55625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/maintenance.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH9wAAAPs"] [Tue Aug 18 13:04:35.201973 2026] [security2:error] [pid 139043:tid 139207] [client 20.226.36.136:62176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH-AAAAKc"] [Tue Aug 18 13:04:35.202014 2026] [security2:error] [pid 139043:tid 139210] [client 20.51.153.15:9210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/40.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH-QAAAKo"] [Tue Aug 18 13:04:35.223272 2026] [security2:error] [pid 139043:tid 139233] [client 20.25.139.174:4681] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/1.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH_gAAAME"] [Tue Aug 18 13:04:35.223399 2026] [security2:error] [pid 139043:tid 139233] [client 20.25.139.174:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/1.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH_gAAAME"] [Tue Aug 18 13:04:35.228168 2026] [security2:error] [pid 139043:tid 139215] [client 20.151.109.219:49953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mo.php"] [unique_id "aoSCk_2v-lWn9OzQT7VH_wAAAK8"] [Tue Aug 18 13:04:35.276576 2026] [security2:error] [pid 139043:tid 139266] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/special.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIAAAAAOI"] [Tue Aug 18 13:04:35.319792 2026] [security2:error] [pid 139043:tid 139299] [client 20.104.100.201:23990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIAgAAAQM"] [Tue Aug 18 13:04:35.374055 2026] [authz_core:error] [pid 139043:tid 139098] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:35.374326 2026] [authz_core:error] [pid 139043:tid 139098] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:35.496490 2026] [security2:error] [pid 139043:tid 139236] [client 20.79.204.6:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-login.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIAwAAAMQ"] [Tue Aug 18 13:04:35.521774 2026] [security2:error] [pid 139043:tid 139276] [client 20.151.109.219:46405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/qr.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIDQAAAOw"] [Tue Aug 18 13:04:35.524477 2026] [security2:error] [pid 139043:tid 139178] [client 20.226.36.136:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/oivcl.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIDgAAAIo"] [Tue Aug 18 13:04:35.596640 2026] [security2:error] [pid 139043:tid 139300] [client 4.232.151.198:7734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIEgAAAQQ"] [Tue Aug 18 13:04:35.608711 2026] [security2:error] [pid 139043:tid 139271] [client 74.248.130.103:7684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file25.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIEwAAAOc"] [Tue Aug 18 13:04:35.649379 2026] [security2:error] [pid 139043:tid 139289] [client 20.151.109.219:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mimes.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIFAAAAPk"] [Tue Aug 18 13:04:35.654808 2026] [security2:error] [pid 139043:tid 139281] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/fz.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIFQAAAPE"] [Tue Aug 18 13:04:35.698027 2026] [security2:error] [pid 139043:tid 139203] [client 68.221.73.131:60597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/shiny.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIFwAAAKM"] [Tue Aug 18 13:04:35.716025 2026] [security2:error] [pid 139043:tid 139205] [client 20.116.17.175:3417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/nwflm.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIGgAAAKU"] [Tue Aug 18 13:04:35.719936 2026] [security2:error] [pid 139043:tid 139286] [client 20.104.100.201:23872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/7.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIGwAAAPY"] [Tue Aug 18 13:04:35.791166 2026] [security2:error] [pid 139043:tid 139195] [client 213.35.127.232:58754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIHwAAAJs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:35.793031 2026] [security2:error] [pid 139043:tid 139186] [client 20.1.169.243:11240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIIAAAAJI"] [Tue Aug 18 13:04:35.795373 2026] [security2:error] [pid 139043:tid 139193] [client 158.23.17.4:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/se.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIIQAAAJk"] [Tue Aug 18 13:04:35.796193 2026] [security2:error] [pid 139043:tid 139288] [client 20.226.36.136:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/zugvi.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIIgAAAPg"] [Tue Aug 18 13:04:35.798205 2026] [security2:error] [pid 139043:tid 139284] [client 20.25.139.174:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/alfa.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIIwAAAPQ"] [Tue Aug 18 13:04:35.803290 2026] [security2:error] [pid 139043:tid 139292] [client 20.51.153.15:8826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ee.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIJAAAAPw"] [Tue Aug 18 13:04:35.813053 2026] [security2:error] [pid 139043:tid 139190] [client 20.151.109.219:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/dirs.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIJQAAAJY"] [Tue Aug 18 13:04:35.816171 2026] [security2:error] [pid 139043:tid 139253] [client 20.250.13.23:6279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/options-writing.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIJgAAANU"] [Tue Aug 18 13:04:35.853391 2026] [security2:error] [pid 139043:tid 139220] [client 20.226.36.136:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wsrer.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIKgAAALQ"] [Tue Aug 18 13:04:35.889135 2026] [security2:error] [pid 139043:tid 139268] [client 20.226.36.136:61488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIKwAAAOQ"] [Tue Aug 18 13:04:35.945434 2026] [security2:error] [pid 139043:tid 139248] [client 20.206.73.37:1687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/133.php"] [unique_id "aoSCk_2v-lWn9OzQT7VILgAAANA"] [Tue Aug 18 13:04:35.988689 2026] [security2:error] [pid 139043:tid 139210] [client 20.226.36.136:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/yxijx.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIMgAAAKo"] [Tue Aug 18 13:04:36.051458 2026] [security2:error] [pid 139043:tid 139287] [client 103.184.169.37:43825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VINgAAAPc"] [Tue Aug 18 13:04:36.051879 2026] [security2:error] [pid 139043:tid 139287] [client 103.184.169.37:43825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VINgAAAPc"] [Tue Aug 18 13:04:36.144087 2026] [security2:error] [pid 139043:tid 139235] [client 20.151.109.219:46454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sn.php"] [unique_id "aoSClP2v-lWn9OzQT7VIPAAAAMM"] [Tue Aug 18 13:04:36.158105 2026] [security2:error] [pid 139043:tid 139266] [client 20.1.169.243:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSClP2v-lWn9OzQT7VIPQAAAOI"] [Tue Aug 18 13:04:36.191046 2026] [security2:error] [pid 139043:tid 139213] [client 68.221.73.131:40864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/403dd.php"] [unique_id "aoSClP2v-lWn9OzQT7VIPgAAAK0"] [Tue Aug 18 13:04:36.222551 2026] [security2:error] [pid 139043:tid 139199] [client 213.202.253.4:62079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSClP2v-lWn9OzQT7VIQAAAAJ8"], referer: www.google.com [Tue Aug 18 13:04:36.236845 2026] [security2:error] [pid 139043:tid 139179] [client 74.248.130.103:50153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file15.php"] [unique_id "aoSClP2v-lWn9OzQT7VIQQAAAIs"] [Tue Aug 18 13:04:36.282460 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:36.282737 2026] [authz_core:error] [pid 139043:tid 139101] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:36.288524 2026] [security2:error] [pid 139043:tid 139206] [client 20.25.139.174:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/edit.php"] [unique_id "aoSClP2v-lWn9OzQT7VIRAAAAKY"] [Tue Aug 18 13:04:36.302274 2026] [security2:error] [pid 139043:tid 139267] [client 20.51.153.15:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ak.php"] [unique_id "aoSClP2v-lWn9OzQT7VIRgAAAOM"] [Tue Aug 18 13:04:36.307459 2026] [security2:error] [pid 139043:tid 139184] [client 4.232.151.198:25220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-rest-true-meta-fields.php"] [unique_id "aoSClP2v-lWn9OzQT7VIRwAAAJA"] [Tue Aug 18 13:04:36.312066 2026] [security2:error] [pid 139043:tid 139221] [client 20.104.100.201:24029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ws77.php"] [unique_id "aoSClP2v-lWn9OzQT7VISAAAALU"] [Tue Aug 18 13:04:36.317648 2026] [security2:error] [pid 139043:tid 139276] [client 20.215.241.237:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/aa.php"] [unique_id "aoSClP2v-lWn9OzQT7VISQAAAOw"] [Tue Aug 18 13:04:36.366989 2026] [security2:error] [pid 139043:tid 139237] [client 20.250.13.23:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/ioxi-o.php"] [unique_id "aoSClP2v-lWn9OzQT7VISgAAAMU"] [Tue Aug 18 13:04:36.410823 2026] [security2:error] [pid 139043:tid 139271] [client 158.23.17.4:7193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vp.php"] [unique_id "aoSClP2v-lWn9OzQT7VITAAAAOc"] [Tue Aug 18 13:04:36.428510 2026] [security2:error] [pid 139043:tid 139243] [client 132.196.30.78:19481] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.brasiltocantins.com.br"] [uri "/1.php"] [unique_id "aoSClP2v-lWn9OzQT7VITQAAAMs"] [Tue Aug 18 13:04:36.428619 2026] [security2:error] [pid 139043:tid 139243] [client 132.196.30.78:19481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/1.php"] [unique_id "aoSClP2v-lWn9OzQT7VITQAAAMs"] [Tue Aug 18 13:04:36.429384 2026] [security2:error] [pid 139043:tid 139175] [client 20.151.109.219:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/43.php"] [unique_id "aoSClP2v-lWn9OzQT7VITgAAAIc"] [Tue Aug 18 13:04:36.434700 2026] [security2:error] [pid 139043:tid 139187] [client 20.250.13.23:17309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSClP2v-lWn9OzQT7VITwAAAJM"] [Tue Aug 18 13:04:36.443942 2026] [security2:error] [pid 139043:tid 139192] [client 20.79.204.6:9693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/default.php"] [unique_id "aoSClP2v-lWn9OzQT7VIUQAAAJg"] [Tue Aug 18 13:04:36.466446 2026] [security2:error] [pid 139043:tid 139281] [client 20.171.51.14:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wm.php"] [unique_id "aoSClP2v-lWn9OzQT7VIUgAAAPE"] [Tue Aug 18 13:04:36.467963 2026] [security2:error] [pid 139043:tid 139239] [client 5.31.227.224:30448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VIUwAAAMc"] [Tue Aug 18 13:04:36.468057 2026] [security2:error] [pid 139043:tid 139239] [client 5.31.227.224:30448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VIUwAAAMc"] [Tue Aug 18 13:04:36.519522 2026] [security2:error] [pid 139043:tid 139205] [client 20.151.109.219:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ni.php"] [unique_id "aoSClP2v-lWn9OzQT7VIVQAAAKU"] [Tue Aug 18 13:04:36.574150 2026] [autoindex:error] [pid 139043:tid 139300] [client 20.1.169.243:11251] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:36.584004 2026] [authz_core:error] [pid 139043:tid 139136] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:36.584257 2026] [authz_core:error] [pid 139043:tid 139136] [remote 216.73.216.206:16079] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:36.592175 2026] [security2:error] [pid 139043:tid 139294] [client 20.51.153.15:8392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/test_info.php"] [unique_id "aoSClP2v-lWn9OzQT7VIWwAAAP4"] [Tue Aug 18 13:04:36.661918 2026] [security2:error] [pid 139043:tid 139234] [client 176.31.139.23:63594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.hotelvipempresas.com.br"] [uri "/robots.txt"] [unique_id "aoSClP2v-lWn9OzQT7VIXQAAAMI"] [Tue Aug 18 13:04:36.662006 2026] [security2:error] [pid 139043:tid 139234] [client 176.31.139.23:63594] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hotelvipempresas.com.br"] [uri "/robots.txt"] [unique_id "aoSClP2v-lWn9OzQT7VIXQAAAMI"] [Tue Aug 18 13:04:36.695361 2026] [security2:error] [pid 139043:tid 139295] [client 20.1.169.243:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSClP2v-lWn9OzQT7VIXgAAAP8"] [Tue Aug 18 13:04:36.723828 2026] [security2:error] [pid 139043:tid 139220] [client 20.116.17.175:3416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/wp-load.php"] [unique_id "aoSClP2v-lWn9OzQT7VIXwAAALQ"] [Tue Aug 18 13:04:36.768609 2026] [security2:error] [pid 139043:tid 139242] [client 74.248.130.103:42047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/f35.php"] [unique_id "aoSClP2v-lWn9OzQT7VIYQAAAMo"] [Tue Aug 18 13:04:36.811333 2026] [security2:error] [pid 139043:tid 139232] [client 213.35.127.232:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSClP2v-lWn9OzQT7VIYwAAAMA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:36.811713 2026] [security2:error] [pid 139043:tid 139273] [client 20.151.109.219:49310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fresh.php"] [unique_id "aoSClP2v-lWn9OzQT7VIZAAAAOk"] [Tue Aug 18 13:04:36.820257 2026] [security2:error] [pid 139043:tid 139183] [client 68.221.73.131:32394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/baba.php"] [unique_id "aoSClP2v-lWn9OzQT7VIZQAAAI8"] [Tue Aug 18 13:04:36.842119 2026] [security2:error] [pid 139043:tid 139275] [client 20.104.100.201:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/read.php"] [unique_id "aoSClP2v-lWn9OzQT7VIZgAAAOs"] [Tue Aug 18 13:04:36.842312 2026] [security2:error] [pid 139043:tid 139253] [client 20.25.139.174:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/elp.php"] [unique_id "aoSClP2v-lWn9OzQT7VIZwAAANU"] [Tue Aug 18 13:04:36.855955 2026] [security2:error] [pid 139043:tid 139298] [client 49.13.164.148:43344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSCk_2v-lWn9OzQT7VIGAAAAQI"], referer: https://www.connectformaturas.com.br [Tue Aug 18 13:04:36.861316 2026] [security2:error] [pid 139043:tid 139218] [client 20.226.36.136:61442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/zwlsv.php"] [unique_id "aoSClP2v-lWn9OzQT7VIaQAAALI"] [Tue Aug 18 13:04:36.867508 2026] [security2:error] [pid 139043:tid 139174] [client 20.51.153.15:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/14.php"] [unique_id "aoSClP2v-lWn9OzQT7VIagAAAIY"] [Tue Aug 18 13:04:36.889101 2026] [security2:error] [pid 139043:tid 139178] [client 197.184.64.235:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VIawAAAIo"] [Tue Aug 18 13:04:36.889211 2026] [security2:error] [pid 139043:tid 139178] [client 197.184.64.235:42668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSClP2v-lWn9OzQT7VIawAAAIo"] [Tue Aug 18 13:04:37.076359 2026] [security2:error] [pid 139043:tid 139249] [client 20.250.13.23:6331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/maint.php"] [unique_id "aoSClf2v-lWn9OzQT7VIbwAAANE"] [Tue Aug 18 13:04:37.078467 2026] [security2:error] [pid 139043:tid 139181] [client 4.232.151.198:7736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "aoSClf2v-lWn9OzQT7VIcAAAAI0"] [Tue Aug 18 13:04:37.099973 2026] [security2:error] [pid 139043:tid 139238] [client 20.151.109.219:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gj.php"] [unique_id "aoSClf2v-lWn9OzQT7VIcQAAAMY"] [Tue Aug 18 13:04:37.122888 2026] [security2:error] [pid 139043:tid 139299] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/clque.php"] [unique_id "aoSClf2v-lWn9OzQT7VIdQAAAQM"] [Tue Aug 18 13:04:37.137189 2026] [security2:error] [pid 139043:tid 139225] [client 20.171.51.14:6649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ac.php"] [unique_id "aoSClf2v-lWn9OzQT7VIdgAAALk"] [Tue Aug 18 13:04:37.137939 2026] [security2:error] [pid 139043:tid 139287] [client 40.74.65.169:16275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/images.php"] [unique_id "aoSClf2v-lWn9OzQT7VIdwAAAPc"] [Tue Aug 18 13:04:37.161523 2026] [autoindex:error] [pid 139043:tid 139197] [client 20.1.169.243:11181] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:37.208346 2026] [security2:error] [pid 139043:tid 139266] [client 20.51.153.15:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/tk.php"] [unique_id "aoSClf2v-lWn9OzQT7VIewAAAOI"] [Tue Aug 18 13:04:37.220557 2026] [security2:error] [pid 139043:tid 139213] [client 168.62.48.100:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSClf2v-lWn9OzQT7VIfAAAAK0"] [Tue Aug 18 13:04:37.250807 2026] [security2:error] [pid 139043:tid 139210] [client 20.79.204.6:9339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/i.php"] [unique_id "aoSClf2v-lWn9OzQT7VIfQAAAKo"] [Tue Aug 18 13:04:37.281972 2026] [security2:error] [pid 139043:tid 139219] [client 20.1.169.243:11181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSClf2v-lWn9OzQT7VIfgAAALM"] [Tue Aug 18 13:04:37.299006 2026] [security2:error] [pid 139043:tid 139179] [client 20.116.17.175:53564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/jj.php"] [unique_id "aoSClf2v-lWn9OzQT7VIfwAAAIs"] [Tue Aug 18 13:04:37.307263 2026] [authz_core:error] [pid 139043:tid 139120] [remote 57.141.22.22:34964] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:37.307528 2026] [authz_core:error] [pid 139043:tid 139120] [remote 57.141.22.22:34964] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:37.328954 2026] [security2:error] [pid 139043:tid 139263] [client 4.232.151.198:48944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/class-t.api.php"] [unique_id "aoSClf2v-lWn9OzQT7VIgwAAAN8"] [Tue Aug 18 13:04:37.341734 2026] [security2:error] [pid 139043:tid 139259] [client 20.25.139.174:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSClf2v-lWn9OzQT7VIhAAAANs"] [Tue Aug 18 13:04:37.346418 2026] [security2:error] [pid 139043:tid 139246] [client 132.196.30.78:19504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/alfa.php"] [unique_id "aoSClf2v-lWn9OzQT7VIhQAAAM4"] [Tue Aug 18 13:04:37.377485 2026] [security2:error] [pid 139043:tid 139221] [client 20.104.100.201:23972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/albin.php"] [unique_id "aoSClf2v-lWn9OzQT7VIhgAAALU"] [Tue Aug 18 13:04:37.389776 2026] [security2:error] [pid 139043:tid 139274] [client 20.151.109.219:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pd.php"] [unique_id "aoSClf2v-lWn9OzQT7VIhwAAAOo"] [Tue Aug 18 13:04:37.594053 2026] [security2:error] [pid 139043:tid 139214] [client 196.12.128.158:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjAAAAK4"] [Tue Aug 18 13:04:37.594155 2026] [security2:error] [pid 139043:tid 139214] [client 196.12.128.158:52453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjAAAAK4"] [Tue Aug 18 13:04:37.622887 2026] [security2:error] [pid 139043:tid 139230] [client 223.185.37.47:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjQAAAL4"] [Tue Aug 18 13:04:37.622990 2026] [security2:error] [pid 139043:tid 139230] [client 223.185.37.47:9433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjQAAAL4"] [Tue Aug 18 13:04:37.629946 2026] [security2:error] [pid 139043:tid 139276] [client 20.250.13.23:53477] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.journeyxperience.com"] [uri "/1.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjgAAAOw"] [Tue Aug 18 13:04:37.630303 2026] [security2:error] [pid 139043:tid 139276] [client 20.250.13.23:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/1.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjgAAAOw"] [Tue Aug 18 13:04:37.693255 2026] [security2:error] [pid 139043:tid 139243] [client 20.250.13.23:6272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/phpMailer.php"] [unique_id "aoSClf2v-lWn9OzQT7VIjwAAAMs"] [Tue Aug 18 13:04:38.393315 2026] [http2:info] [pid 157386:tid 157386] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 13:04:38.415229 2026] [security2:error] [pid 157386:tid 157517] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/nano.php"] [unique_id "aoSClk1jzAhYHVVT1WfbkAAAAQs"] [Tue Aug 18 13:04:38.415341 2026] [security2:error] [pid 157386:tid 157516] [client 68.155.154.236:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSClk1jzAhYHVVT1WfbkQAAAQo"] [Tue Aug 18 13:04:38.416830 2026] [security2:error] [pid 157386:tid 157520] [client 20.215.241.237:47315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/img.php"] [unique_id "aoSClk1jzAhYHVVT1WfbkwAAAQ4"] [Tue Aug 18 13:04:38.416883 2026] [security2:error] [pid 157386:tid 157521] [client 74.248.130.103:42013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-load.php"] [unique_id "aoSClk1jzAhYHVVT1WfbkgAAAQ8"] [Tue Aug 18 13:04:38.417218 2026] [security2:error] [pid 157386:tid 157523] [client 20.51.153.15:8774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/hp.php"] [unique_id "aoSClk1jzAhYHVVT1WfblAAAARE"] [Tue Aug 18 13:04:38.417490 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/site.php"] [unique_id "aoSClk1jzAhYHVVT1WfblQAAARM"] [Tue Aug 18 13:04:38.417587 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:27345] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSClk1jzAhYHVVT1WfblgAAARU"] [Tue Aug 18 13:04:38.417656 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:27345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/1.php"] [unique_id "aoSClk1jzAhYHVVT1WfblgAAARU"] [Tue Aug 18 13:04:38.418050 2026] [security2:error] [pid 157386:tid 157529] [client 168.62.48.100:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSClk1jzAhYHVVT1WfblwAAARc"] [Tue Aug 18 13:04:38.418182 2026] [security2:error] [pid 157386:tid 157531] [client 158.23.17.4:48399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ph.php"] [unique_id "aoSClk1jzAhYHVVT1WfbmAAAARk"] [Tue Aug 18 13:04:38.418382 2026] [security2:error] [pid 157386:tid 157533] [client 20.226.36.136:62154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/jrpga.php"] [unique_id "aoSClk1jzAhYHVVT1WfbmQAAARs"] [Tue Aug 18 13:04:38.418604 2026] [security2:error] [pid 157386:tid 157535] [client 20.104.100.201:23950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/fw/34.php"] [unique_id "aoSClk1jzAhYHVVT1WfbmgAAAR0"] [Tue Aug 18 13:04:38.418709 2026] [security2:error] [pid 157386:tid 157538] [client 20.116.17.175:54241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/img.php"] [unique_id "aoSClk1jzAhYHVVT1WfbmwAAASA"] [Tue Aug 18 13:04:38.418995 2026] [security2:error] [pid 157386:tid 157539] [client 20.124.247.79:16465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/coffee.php"] [unique_id "aoSClk1jzAhYHVVT1WfbnAAAASE"] [Tue Aug 18 13:04:38.421914 2026] [security2:error] [pid 157386:tid 157541] [client 20.151.109.219:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/th.php"] [unique_id "aoSClk1jzAhYHVVT1WfbnQAAASM"] [Tue Aug 18 13:04:38.422168 2026] [security2:error] [pid 157386:tid 157543] [client 54.39.136.255:26528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.hotelvipempresas.com.br"] [uri "/"] [unique_id "aoSClk1jzAhYHVVT1WfbngAAASU"] [Tue Aug 18 13:04:38.422241 2026] [security2:error] [pid 157386:tid 157543] [client 54.39.136.255:26528] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hotelvipempresas.com.br"] [uri "/"] [unique_id "aoSClk1jzAhYHVVT1WfbngAAASU"] [Tue Aug 18 13:04:38.423156 2026] [security2:error] [pid 157386:tid 157547] [client 20.171.51.14:57994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/yz.php"] [unique_id "aoSClk1jzAhYHVVT1WfboAAAASk"] [Tue Aug 18 13:04:38.424043 2026] [security2:error] [pid 157386:tid 157549] [client 168.62.48.100:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSClk1jzAhYHVVT1WfbogAAASs"] [Tue Aug 18 13:04:38.545064 2026] [security2:error] [pid 157386:tid 157524] [client 20.1.169.243:11095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSClk1jzAhYHVVT1WfbrgAAARI"] [Tue Aug 18 13:04:38.571550 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:38.571886 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:38.571967 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:38.572280 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:38.582835 2026] [security2:error] [pid 157386:tid 157537] [client 20.25.139.174:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/666.php"] [unique_id "aoSClk1jzAhYHVVT1WfbuwAAAR8"] [Tue Aug 18 13:04:38.636699 2026] [security2:error] [pid 157386:tid 157526] [client 4.232.151.198:7705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/rss.php"] [unique_id "aoSClk1jzAhYHVVT1WfbvwAAARQ"] [Tue Aug 18 13:04:38.641344 2026] [security2:error] [pid 157386:tid 157560] [client 20.250.13.23:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSClk1jzAhYHVVT1WfbwAAAATY"] [Tue Aug 18 13:04:38.724388 2026] [security2:error] [pid 157386:tid 157607] [client 20.151.109.219:49331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/admin404.php"] [unique_id "aoSClk1jzAhYHVVT1WfbwwAAAWU"] [Tue Aug 18 13:04:38.730553 2026] [security2:error] [pid 157386:tid 157544] [client 132.196.30.78:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/edit.php"] [unique_id "aoSClk1jzAhYHVVT1WfbxAAAASY"] [Tue Aug 18 13:04:38.758240 2026] [security2:error] [pid 157386:tid 157518] [client 213.35.127.232:59251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSClk1jzAhYHVVT1WfbxQAAAQw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:38.778857 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:42797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gz.php"] [unique_id "aoSClk1jzAhYHVVT1WfbxgAAAWk"] [Tue Aug 18 13:04:38.818984 2026] [security2:error] [pid 157386:tid 157616] [client 20.51.153.15:9158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wx.php"] [unique_id "aoSClk1jzAhYHVVT1WfbxwAAAW4"] [Tue Aug 18 13:04:38.850043 2026] [security2:error] [pid 157386:tid 157415] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/backend/.env"] [unique_id "aoSClk1jzAhYHVVT1WfbzQABcxw"] [Tue Aug 18 13:04:38.857122 2026] [security2:error] [pid 157386:tid 157416] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/config/.env"] [unique_id "aoSClk1jzAhYHVVT1WfbzgABdR0"] [Tue Aug 18 13:04:38.864929 2026] [security2:error] [pid 157386:tid 157418] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/api/.env"] [unique_id "aoSClk1jzAhYHVVT1Wfb0AABdx8"] [Tue Aug 18 13:04:38.899991 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.36.136:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSClk1jzAhYHVVT1Wfb1AAAAX0"] [Tue Aug 18 13:04:38.911662 2026] [security2:error] [pid 157386:tid 157613] [client 20.1.169.243:10917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSClk1jzAhYHVVT1Wfb1QAAAWs"] [Tue Aug 18 13:04:38.915091 2026] [security2:error] [pid 157386:tid 157633] [client 20.79.204.6:9313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSClk1jzAhYHVVT1Wfb1gAAAX8"] [Tue Aug 18 13:04:38.926128 2026] [security2:error] [pid 157386:tid 157636] [client 20.104.100.201:23906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp9.php"] [unique_id "aoSClk1jzAhYHVVT1Wfb1wAAAYI"] [Tue Aug 18 13:04:38.929865 2026] [security2:error] [pid 157386:tid 157639] [client 168.62.48.100:5377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSClk1jzAhYHVVT1Wfb2AAAAYU"] [Tue Aug 18 13:04:39.051205 2026] [security2:error] [pid 157386:tid 157531] [client 68.221.73.131:32432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb3AAAARk"] [Tue Aug 18 13:04:39.092696 2026] [security2:error] [pid 157386:tid 157549] [client 158.23.17.4:56757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/s.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb4wAAASs"] [Tue Aug 18 13:04:39.135818 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:49328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/qo.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb6AAAAUw"] [Tue Aug 18 13:04:39.137400 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:52912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb6QAAAU4"] [Tue Aug 18 13:04:39.207757 2026] [security2:error] [pid 157386:tid 157588] [client 20.124.247.79:16391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb6wAAAVI"] [Tue Aug 18 13:04:39.216036 2026] [security2:error] [pid 157386:tid 157589] [client 20.171.51.14:33177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kj.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb7AAAAVM"] [Tue Aug 18 13:04:39.216792 2026] [security2:error] [pid 157386:tid 157540] [client 20.116.17.175:56270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickcarmultimarcas.com"] [uri "/we.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb7QAAASI"] [Tue Aug 18 13:04:39.262462 2026] [security2:error] [pid 157386:tid 157561] [client 20.51.153.15:8789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/dj.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb7wAAATc"] [Tue Aug 18 13:04:39.274829 2026] [security2:error] [pid 157386:tid 157569] [client 20.215.241.237:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/222.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb8QAAAT8"] [Tue Aug 18 13:04:39.281351 2026] [security2:error] [pid 157386:tid 157546] [client 20.1.169.243:11086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb8gAAASg"] [Tue Aug 18 13:04:39.331035 2026] [security2:error] [pid 157386:tid 157578] [client 20.104.100.201:23891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/save.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb-QAAAUg"] [Tue Aug 18 13:04:39.370375 2026] [security2:error] [pid 157386:tid 157438] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.github/.env"] [unique_id "aoSCl01jzAhYHVVT1Wfb-gABYDM"] [Tue Aug 18 13:04:39.405378 2026] [security2:error] [pid 157386:tid 157534] [client 132.196.30.78:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/elp.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb_AAAARw"] [Tue Aug 18 13:04:39.446740 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:63238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sd.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb_QAAASY"] [Tue Aug 18 13:04:39.458104 2026] [security2:error] [pid 157386:tid 157552] [client 4.232.151.198:48517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/w.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb_gAAAS4"] [Tue Aug 18 13:04:39.474083 2026] [security2:error] [pid 157386:tid 157535] [client 20.250.13.23:6283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/al.php"] [unique_id "aoSCl01jzAhYHVVT1Wfb_wAAAR0"] [Tue Aug 18 13:04:39.525356 2026] [authz_core:error] [pid 157386:tid 157444] [remote 34.79.57.13:44104] AH01630: client denied by server configuration: /home4/raben7/public_html/.htpasswd [Tue Aug 18 13:04:39.610289 2026] [security2:error] [pid 157386:tid 157619] [client 168.62.48.100:5592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/first.php"] [unique_id "aoSCl01jzAhYHVVT1WfcCgAAAXE"] [Tue Aug 18 13:04:39.684984 2026] [security2:error] [pid 157386:tid 157551] [client 86.120.159.145:18879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCl01jzAhYHVVT1WfcDQAAAS0"] [Tue Aug 18 13:04:39.685091 2026] [security2:error] [pid 157386:tid 157551] [client 86.120.159.145:18879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCl01jzAhYHVVT1WfcDQAAAS0"] [Tue Aug 18 13:04:39.689480 2026] [security2:error] [pid 157386:tid 157625] [client 20.226.36.136:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/nwwha.php"] [unique_id "aoSCl01jzAhYHVVT1WfcDgAAAXc"] [Tue Aug 18 13:04:39.689861 2026] [security2:error] [pid 157386:tid 157554] [client 20.1.169.243:11113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSCl01jzAhYHVVT1WfcDwAAATA"] [Tue Aug 18 13:04:39.747404 2026] [security2:error] [pid 157386:tid 157570] [client 20.25.139.174:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ws54.php"] [unique_id "aoSCl01jzAhYHVVT1WfcFwAAAUA"] [Tue Aug 18 13:04:39.752175 2026] [security2:error] [pid 157386:tid 157453] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCl01jzAhYHVVT1WfcGAABD0I"] [Tue Aug 18 13:04:39.753464 2026] [security2:error] [pid 157386:tid 157520] [client 20.104.100.201:23901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSCl01jzAhYHVVT1WfcGQAAAQ4"] [Tue Aug 18 13:04:39.756142 2026] [security2:error] [pid 157386:tid 157523] [client 20.171.51.14:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vg.php"] [unique_id "aoSCl01jzAhYHVVT1WfcGgAAARE"] [Tue Aug 18 13:04:39.762290 2026] [security2:error] [pid 157386:tid 157525] [client 20.251.48.93:49183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/k.php"] [unique_id "aoSCl01jzAhYHVVT1WfcGwAAARM"] [Tue Aug 18 13:04:39.763418 2026] [security2:error] [pid 157386:tid 157531] [client 4.232.151.198:41600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-pluging.php"] [unique_id "aoSCl01jzAhYHVVT1WfcHQAAARk"] [Tue Aug 18 13:04:39.769489 2026] [autoindex:error] [pid 157386:tid 157527] [client 54.204.43.183:46331] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:39.786309 2026] [security2:error] [pid 157386:tid 157573] [client 213.35.127.232:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCl01jzAhYHVVT1WfcIQAAAUM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:39.842461 2026] [security2:error] [pid 157386:tid 157618] [client 20.79.204.6:9318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCl01jzAhYHVVT1WfcIgAAAXA"] [Tue Aug 18 13:04:39.843791 2026] [security2:error] [pid 157386:tid 157572] [client 68.155.153.139:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.reinertimoveis.com.br"] [uri "/.mopj.php"] [unique_id "aoSCl01jzAhYHVVT1WfcIwAAAUI"] [Tue Aug 18 13:04:39.870593 2026] [security2:error] [pid 157386:tid 157565] [client 20.151.109.219:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/info2.php"] [unique_id "aoSCl01jzAhYHVVT1WfcJgAAATs"] [Tue Aug 18 13:04:39.899227 2026] [security2:error] [pid 157386:tid 157524] [client 20.124.247.79:16456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCl01jzAhYHVVT1WfcKAAAARI"] [Tue Aug 18 13:04:39.900152 2026] [security2:error] [pid 157386:tid 157585] [client 68.221.73.131:26090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/cabs.php"] [unique_id "aoSCl01jzAhYHVVT1WfcKQAAAU8"] [Tue Aug 18 13:04:39.954736 2026] [security2:error] [pid 157386:tid 157555] [client 158.23.17.4:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/uo.php"] [unique_id "aoSCl01jzAhYHVVT1WfcKwAAATE"] [Tue Aug 18 13:04:39.976847 2026] [security2:error] [pid 157386:tid 157459] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCl01jzAhYHVVT1WfcLAABVkg"] [Tue Aug 18 13:04:39.980246 2026] [security2:error] [pid 157386:tid 157569] [client 20.151.109.219:5366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/km.php"] [unique_id "aoSCl01jzAhYHVVT1WfcLQAAAT8"] [Tue Aug 18 13:04:39.999537 2026] [security2:error] [pid 157386:tid 157594] [client 20.51.153.15:8435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fa.php"] [unique_id "aoSCl01jzAhYHVVT1WfcLwAAAVg"] [Tue Aug 18 13:04:40.008516 2026] [security2:error] [pid 157386:tid 157462] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/id_rsa"] [unique_id "aoSCmE1jzAhYHVVT1WfcMQABPUs"] [Tue Aug 18 13:04:40.055305 2026] [security2:error] [pid 157386:tid 157566] [client 20.1.169.243:11276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcNAAAATw"] [Tue Aug 18 13:04:40.094056 2026] [security2:error] [pid 157386:tid 157549] [client 132.196.30.78:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcNwAAASs"] [Tue Aug 18 13:04:40.110896 2026] [security2:error] [pid 157386:tid 157466] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/id_dsa"] [unique_id "aoSCmE1jzAhYHVVT1WfcOAABRk8"] [Tue Aug 18 13:04:40.129364 2026] [security2:error] [pid 157386:tid 157589] [client 20.250.13.23:17416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcOQAAAVM"] [Tue Aug 18 13:04:40.143008 2026] [security2:error] [pid 157386:tid 157534] [client 168.62.48.100:5628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcOgAAARw"] [Tue Aug 18 13:04:40.232301 2026] [security2:error] [pid 157386:tid 157610] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/bengi.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcPgAAAWg"] [Tue Aug 18 13:04:40.244257 2026] [security2:error] [pid 157386:tid 157614] [client 20.226.36.136:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/opsqt.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcPwAAAWw"] [Tue Aug 18 13:04:40.252655 2026] [security2:error] [pid 157386:tid 157550] [client 20.104.100.201:24054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcQAAAASw"] [Tue Aug 18 13:04:40.257284 2026] [security2:error] [pid 157386:tid 157536] [client 20.151.109.219:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mf.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcQQAAAR4"] [Tue Aug 18 13:04:40.272677 2026] [security2:error] [pid 157386:tid 157470] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/key.pem"] [unique_id "aoSCmE1jzAhYHVVT1WfcQgABdVM"] [Tue Aug 18 13:04:40.281583 2026] [security2:error] [pid 157386:tid 157603] [client 20.25.139.174:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcRAAAAWE"] [Tue Aug 18 13:04:40.290159 2026] [security2:error] [pid 157386:tid 157472] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/privatekey.key"] [unique_id "aoSCmE1jzAhYHVVT1WfcRQABh1U"] [Tue Aug 18 13:04:40.421541 2026] [security2:error] [pid 157386:tid 157626] [client 20.1.169.243:11090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcSQAAAXg"] [Tue Aug 18 13:04:40.432732 2026] [security2:error] [pid 157386:tid 157634] [client 20.226.36.136:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcSgAAAYA"] [Tue Aug 18 13:04:40.451815 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:10622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/88.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcTQAAAYY"] [Tue Aug 18 13:04:40.520793 2026] [security2:error] [pid 157386:tid 157642] [client 20.226.36.136:48835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcUQAAAYg"] [Tue Aug 18 13:04:40.530018 2026] [security2:error] [pid 157386:tid 157528] [client 20.151.109.219:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ie.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcUgAAARY"] [Tue Aug 18 13:04:40.537380 2026] [security2:error] [pid 157386:tid 157481] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCmE1jzAhYHVVT1WfcVAABKV4"] [Tue Aug 18 13:04:40.544844 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/test_info.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcVQAAAUk"] [Tue Aug 18 13:04:40.581929 2026] [security2:error] [pid 157386:tid 157577] [client 68.221.73.131:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/insc.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcVgAAAUc"] [Tue Aug 18 13:04:40.583018 2026] [security2:error] [pid 157386:tid 157519] [client 74.248.130.103:49005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcVwAAAQ0"] [Tue Aug 18 13:04:40.592329 2026] [security2:error] [pid 157386:tid 157582] [client 20.171.51.14:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sm.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcWAAAAUw"] [Tue Aug 18 13:04:40.650589 2026] [security2:error] [pid 157386:tid 157521] [client 132.196.30.78:19468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/666.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcXAAAAQ8"] [Tue Aug 18 13:04:40.689773 2026] [security2:error] [pid 157386:tid 157620] [client 4.232.151.198:41625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/mah.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcYgAAAXI"] [Tue Aug 18 13:04:40.703124 2026] [security2:error] [pid 157386:tid 157569] [client 20.51.153.15:8712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/fb.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcYwAAAT8"] [Tue Aug 18 13:04:40.749472 2026] [security2:error] [pid 157386:tid 157567] [client 20.206.73.37:32362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcZgAAAT0"] [Tue Aug 18 13:04:40.750336 2026] [security2:error] [pid 157386:tid 157491] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCmE1jzAhYHVVT1WfcZwABWmg"] [Tue Aug 18 13:04:40.755006 2026] [security2:error] [pid 157386:tid 157597] [client 20.215.241.237:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/key.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcaAAAAVs"] [Tue Aug 18 13:04:40.769112 2026] [security2:error] [pid 157386:tid 157595] [client 4.232.151.198:11580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/archive.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcaQAAAVk"] [Tue Aug 18 13:04:40.772479 2026] [security2:error] [pid 157386:tid 157562] [client 20.250.13.23:55659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-activat.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcagAAATg"] [Tue Aug 18 13:04:40.798423 2026] [security2:error] [pid 157386:tid 157516] [client 213.35.127.232:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcbQAAAQo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:40.804379 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:40.804640 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:40.820803 2026] [security2:error] [pid 157386:tid 157543] [client 158.23.17.4:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kx.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcbgAAASU"] [Tue Aug 18 13:04:40.833798 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.100.201:23929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/df.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcbwAAAUY"] [Tue Aug 18 13:04:40.846424 2026] [security2:error] [pid 157386:tid 157546] [client 20.1.169.243:11273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/css/min.php"] [unique_id "aoSCmE1jzAhYHVVT1WfccAAAASg"] [Tue Aug 18 13:04:40.855515 2026] [security2:error] [pid 157386:tid 157564] [client 20.25.139.174:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/function/function.php"] [unique_id "aoSCmE1jzAhYHVVT1WfccQAAATo"] [Tue Aug 18 13:04:40.873279 2026] [security2:error] [pid 157386:tid 157605] [client 20.151.109.219:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nw.php"] [unique_id "aoSCmE1jzAhYHVVT1WfccgAAAWM"] [Tue Aug 18 13:04:40.920959 2026] [security2:error] [pid 157386:tid 157534] [client 68.221.73.131:61271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcdAAAARw"] [Tue Aug 18 13:04:40.964552 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.36.136:65338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcdwAAAWc"] [Tue Aug 18 13:04:40.989591 2026] [security2:error] [pid 157386:tid 157538] [client 20.79.204.6:9704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/gecko-new.php"] [unique_id "aoSCmE1jzAhYHVVT1WfcegAAASA"] [Tue Aug 18 13:04:41.016501 2026] [security2:error] [pid 157386:tid 157591] [client 40.74.65.169:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/ops.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcfQAAAVU"] [Tue Aug 18 13:04:41.025479 2026] [security2:error] [pid 157386:tid 157631] [client 68.221.73.131:26415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/file.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcfgAAAX0"] [Tue Aug 18 13:04:41.088594 2026] [security2:error] [pid 157386:tid 157634] [client 20.124.247.79:16413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/mgrr.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcgQAAAYA"] [Tue Aug 18 13:04:41.107831 2026] [security2:error] [pid 157386:tid 157643] [client 20.51.153.15:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/gw.php"] [unique_id "aoSCmU1jzAhYHVVT1WfciAAAAYk"] [Tue Aug 18 13:04:41.108016 2026] [authz_core:error] [pid 157386:tid 157498] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:41.108260 2026] [authz_core:error] [pid 157386:tid 157498] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:41.153872 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sb.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcjgAAAXM"] [Tue Aug 18 13:04:41.204278 2026] [security2:error] [pid 157386:tid 157531] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/file2.php"] [unique_id "aoSCmU1jzAhYHVVT1WfckAAAARk"] [Tue Aug 18 13:04:41.216806 2026] [security2:error] [pid 157386:tid 157636] [client 20.1.169.243:11083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSCmU1jzAhYHVVT1WfckQAAAYI"] [Tue Aug 18 13:04:41.306760 2026] [security2:error] [pid 157386:tid 157577] [client 20.104.100.201:23991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSCmU1jzAhYHVVT1WfclgAAAUc"] [Tue Aug 18 13:04:41.337448 2026] [security2:error] [pid 157386:tid 157622] [client 74.248.130.103:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSCmU1jzAhYHVVT1WfclwAAAXQ"] [Tue Aug 18 13:04:41.343861 2026] [security2:error] [pid 157386:tid 157510] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "seguntabmenca.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCmU1jzAhYHVVT1WfcmAABD3s"] [Tue Aug 18 13:04:41.344077 2026] [security2:error] [pid 157386:tid 157512] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "seguntabmenca.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCmU1jzAhYHVVT1WfcmQABD30"] [Tue Aug 18 13:04:41.345663 2026] [security2:error] [pid 157386:tid 157539] [client 20.25.139.174:4676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/nw.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcnAAAASE"] [Tue Aug 18 13:04:41.364039 2026] [security2:error] [pid 157386:tid 157542] [client 68.155.154.236:63600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcnwAAASQ"] [Tue Aug 18 13:04:41.386490 2026] [security2:error] [pid 157386:tid 157588] [client 132.196.30.78:20032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ws54.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcoQAAAVI"] [Tue Aug 18 13:04:41.397570 2026] [security2:error] [pid 157386:tid 157568] [client 20.171.51.14:38736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/28.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcogAAAT4"] [Tue Aug 18 13:04:41.397964 2026] [security2:error] [pid 157386:tid 157642] [client 20.250.13.23:17410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcowAAAYg"] [Tue Aug 18 13:04:41.408357 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:41.408789 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:41.418075 2026] [security2:error] [pid 157386:tid 157514] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/laravel/.env"] [unique_id "aoSCmU1jzAhYHVVT1WfcpQABEn8"] [Tue Aug 18 13:04:41.480053 2026] [security2:error] [pid 157386:tid 157575] [client 20.151.109.219:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xj.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcqAAAAUU"] [Tue Aug 18 13:04:41.515882 2026] [security2:error] [pid 157386:tid 157567] [client 20.251.48.93:8945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/82.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcqgAAAT0"] [Tue Aug 18 13:04:41.533263 2026] [security2:error] [pid 157386:tid 157526] [client 20.51.153.15:8815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/uq.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcqwAAARQ"] [Tue Aug 18 13:04:41.534754 2026] [security2:error] [pid 157386:tid 157563] [client 4.232.151.198:48092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/myshell.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcrAAAATk"] [Tue Aug 18 13:04:41.534908 2026] [security2:error] [pid 157386:tid 157522] [client 4.223.113.180:39704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/aaa.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcrQAAARA"] [Tue Aug 18 13:04:41.573004 2026] [security2:error] [pid 157386:tid 157393] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/config/.env.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcswABYAY"] [Tue Aug 18 13:04:41.573831 2026] [security2:error] [pid 157386:tid 157391] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/core/.env"] [unique_id "aoSCmU1jzAhYHVVT1WfctAABYAQ"] [Tue Aug 18 13:04:41.589564 2026] [security2:error] [pid 157386:tid 157394] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/config.php.bak"] [unique_id "aoSCmU1jzAhYHVVT1WfctgABKwc"] [Tue Aug 18 13:04:41.590175 2026] [security2:error] [pid 157386:tid 157412] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCmU1jzAhYHVVT1WfctwABKxk"] [Tue Aug 18 13:04:41.593785 2026] [security2:error] [pid 157386:tid 157572] [client 20.1.169.243:11089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/home.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcuAAAAUI"] [Tue Aug 18 13:04:41.643654 2026] [security2:error] [pid 157386:tid 157576] [client 20.226.36.136:62158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcugAAAUY"] [Tue Aug 18 13:04:41.655781 2026] [security2:error] [pid 157386:tid 157400] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCmU1jzAhYHVVT1WfcvgABTQ0"] [Tue Aug 18 13:04:41.695444 2026] [security2:error] [pid 157386:tid 157537] [client 20.79.204.6:10129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/NewFile.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcwAAAAR8"] [Tue Aug 18 13:04:41.715807 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:41.716118 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:41.791225 2026] [security2:error] [pid 157386:tid 157418] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.swp"] [unique_id "aoSCmU1jzAhYHVVT1WfcwwABZx8"] [Tue Aug 18 13:04:41.797071 2026] [security2:error] [pid 157386:tid 157574] [client 68.221.73.131:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/dex.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcxQAAAUQ"] [Tue Aug 18 13:04:41.832856 2026] [security2:error] [pid 157386:tid 157548] [client 213.35.127.232:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCmU1jzAhYHVVT1WfcyQAAASo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:41.835699 2026] [security2:error] [pid 157386:tid 157425] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/web/.env"] [unique_id "aoSCmU1jzAhYHVVT1WfcywABYSY"] [Tue Aug 18 13:04:41.837346 2026] [security2:error] [pid 157386:tid 157427] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/public/.env"] [unique_id "aoSCmU1jzAhYHVVT1WfczAABYSg"] [Tue Aug 18 13:04:41.873561 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ns.php"] [unique_id "aoSCmU1jzAhYHVVT1WfczQAAATA"] [Tue Aug 18 13:04:41.883399 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:10616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/hj.php"] [unique_id "aoSCmU1jzAhYHVVT1WfczgAAAXU"] [Tue Aug 18 13:04:41.896143 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.100.201:24009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/usr.php"] [unique_id "aoSCmU1jzAhYHVVT1WfczwAAAX4"] [Tue Aug 18 13:04:41.958022 2026] [security2:error] [pid 157386:tid 157535] [client 20.25.139.174:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/xleet.php"] [unique_id "aoSCmU1jzAhYHVVT1Wfc2QAAAR0"] [Tue Aug 18 13:04:41.973599 2026] [security2:error] [pid 157386:tid 157523] [client 20.226.36.136:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCmU1jzAhYHVVT1Wfc2gAAARE"] [Tue Aug 18 13:04:42.006751 2026] [security2:error] [pid 157386:tid 157432] [remote 212.29.237.5:34572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-login.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc3gABGC0"] [Tue Aug 18 13:04:42.019643 2026] [autoindex:error] [pid 157386:tid 157625] [client 20.1.169.243:10937] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:42.048814 2026] [access_compat:error] [pid 157386:tid 157599] [client 52.55.58.190:12353] AH01797: client denied by server configuration: /home1/novamatronfer/public_html/robots.txt [Tue Aug 18 13:04:42.063375 2026] [security2:error] [pid 157386:tid 157536] [client 20.250.13.23:17429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/past1.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc5QAAAR4"] [Tue Aug 18 13:04:42.140393 2026] [security2:error] [pid 157386:tid 157519] [client 20.1.169.243:10937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/images/min.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc6gAAAQ0"] [Tue Aug 18 13:04:42.159654 2026] [security2:error] [pid 157386:tid 157585] [client 20.124.247.79:16469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/55.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc7AAAAU8"] [Tue Aug 18 13:04:42.171954 2026] [security2:error] [pid 157386:tid 157637] [client 20.151.109.219:5351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gk.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc7gAAAYM"] [Tue Aug 18 13:04:42.246301 2026] [security2:error] [pid 157386:tid 157636] [client 4.232.151.198:7684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/filemanagerk.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc8AAAAYI"] [Tue Aug 18 13:04:42.248310 2026] [security2:error] [pid 157386:tid 157556] [client 20.51.153.15:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/32.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc8QAAATI"] [Tue Aug 18 13:04:42.286311 2026] [security2:error] [pid 157386:tid 157590] [client 158.23.17.4:47622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/va.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc9AAAAVQ"] [Tue Aug 18 13:04:42.318518 2026] [security2:error] [pid 157386:tid 157595] [client 68.221.73.131:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/key.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc-AAAAVk"] [Tue Aug 18 13:04:42.325681 2026] [security2:error] [pid 157386:tid 157566] [client 20.226.36.136:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCmk1jzAhYHVVT1Wfc-QAAATw"] [Tue Aug 18 13:04:42.335758 2026] [security2:error] [pid 157386:tid 157448] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/web.config"] [unique_id "aoSCmk1jzAhYHVVT1Wfc-gABCj0"] [Tue Aug 18 13:04:42.396406 2026] [security2:error] [pid 157386:tid 157453] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdAQABHEI"] [Tue Aug 18 13:04:42.396538 2026] [security2:error] [pid 157386:tid 157534] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdAQABHEI"] [Tue Aug 18 13:04:42.399810 2026] [security2:error] [pid 157386:tid 157544] [client 20.104.100.201:23908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdAwAAASY"] [Tue Aug 18 13:04:42.416451 2026] [security2:error] [pid 157386:tid 157518] [client 20.171.51.14:38772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/m.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdCAAAAQw"] [Tue Aug 18 13:04:42.486627 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:5323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wn.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdCwAAARU"] [Tue Aug 18 13:04:42.507908 2026] [autoindex:error] [pid 157386:tid 157558] [client 205.210.31.14:65238] AH01276: Cannot serve directory /home1/medicaljaracaty/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:42.531900 2026] [security2:error] [pid 157386:tid 157543] [client 20.25.139.174:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdEAAAASU"] [Tue Aug 18 13:04:42.556472 2026] [autoindex:error] [pid 157386:tid 157605] [client 20.1.169.243:11265] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:42.556588 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.36.136:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdEwAAAVM"] [Tue Aug 18 13:04:42.572587 2026] [security2:error] [pid 157386:tid 157597] [client 213.202.253.4:51803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mafraveiculos.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdFQAAAVs"], referer: www.google.com [Tue Aug 18 13:04:42.587613 2026] [security2:error] [pid 157386:tid 157520] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/gm.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdFgAAAQ4"] [Tue Aug 18 13:04:42.600882 2026] [security2:error] [pid 157386:tid 157561] [client 20.79.204.6:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-Blogs.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdGAAAATc"] [Tue Aug 18 13:04:42.606899 2026] [security2:error] [pid 157386:tid 157523] [client 20.215.241.237:19040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/chosen.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdGwAAARE"] [Tue Aug 18 13:04:42.610708 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:42.610991 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:42.676944 2026] [security2:error] [pid 157386:tid 157533] [client 20.1.169.243:11265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdHgAAARs"] [Tue Aug 18 13:04:42.686669 2026] [security2:error] [pid 157386:tid 157618] [client 68.155.154.236:57957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdHwAAAXA"] [Tue Aug 18 13:04:42.688090 2026] [security2:error] [pid 157386:tid 157598] [client 20.250.13.23:17320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/file61.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdIAAAAVw"] [Tue Aug 18 13:04:42.735867 2026] [security2:error] [pid 157386:tid 157599] [client 20.51.153.15:8758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/73.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdIQAAAV0"] [Tue Aug 18 13:04:42.741192 2026] [security2:error] [pid 157386:tid 157536] [client 20.151.109.219:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ij.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdIgAAAR4"] [Tue Aug 18 13:04:42.759793 2026] [security2:error] [pid 157386:tid 157641] [client 20.151.109.219:63259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/app.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdIwAAAYc"] [Tue Aug 18 13:04:42.773262 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.36.136:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdJQAAAUk"] [Tue Aug 18 13:04:42.785451 2026] [security2:error] [pid 157386:tid 157519] [client 52.173.121.69:41179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdKQAAAQ0"] [Tue Aug 18 13:04:42.785566 2026] [security2:error] [pid 157386:tid 157617] [client 20.104.100.201:24052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/css/database.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdKAAAAW8"] [Tue Aug 18 13:04:42.850513 2026] [security2:error] [pid 157386:tid 157540] [client 20.251.48.93:29038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/dex.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdLwAAASI"] [Tue Aug 18 13:04:42.850971 2026] [security2:error] [pid 157386:tid 157548] [client 213.35.127.232:60415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdMAAAASo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:42.879655 2026] [security2:error] [pid 157386:tid 157622] [client 102.213.179.104:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdMgAAAXQ"] [Tue Aug 18 13:04:42.879801 2026] [security2:error] [pid 157386:tid 157622] [client 102.213.179.104:61753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdMgAAAXQ"] [Tue Aug 18 13:04:42.882254 2026] [security2:error] [pid 157386:tid 157628] [client 20.226.36.136:61460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdMwAAAXo"] [Tue Aug 18 13:04:42.886854 2026] [security2:error] [pid 157386:tid 157528] [client 4.232.151.198:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/luf.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdNAAAARY"] [Tue Aug 18 13:04:42.896552 2026] [security2:error] [pid 157386:tid 157524] [client 20.124.247.79:16504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/ajax.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdNQAAARI"] [Tue Aug 18 13:04:42.910159 2026] [security2:error] [pid 157386:tid 157620] [client 20.171.51.14:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nl.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdNwAAAXI"] [Tue Aug 18 13:04:42.912060 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:42.912341 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:42.954791 2026] [security2:error] [pid 157386:tid 157526] [client 20.206.73.37:32381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/mosty.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdOQAAARQ"] [Tue Aug 18 13:04:42.978062 2026] [security2:error] [pid 157386:tid 157562] [client 68.221.73.131:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/kir.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdOgAAATg"] [Tue Aug 18 13:04:42.979814 2026] [security2:error] [pid 157386:tid 157612] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/ws55.php"] [unique_id "aoSCmk1jzAhYHVVT1WfdOwAAAWo"] [Tue Aug 18 13:04:43.038219 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/87.php"] [unique_id "aoSCm01jzAhYHVVT1WfdQAAAATo"] [Tue Aug 18 13:04:43.039933 2026] [security2:error] [pid 157386:tid 157570] [client 149.34.210.141:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCm01jzAhYHVVT1WfdQQAAAUA"] [Tue Aug 18 13:04:43.040050 2026] [security2:error] [pid 157386:tid 157570] [client 149.34.210.141:54599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCm01jzAhYHVVT1WfdQQAAAUA"] [Tue Aug 18 13:04:43.046334 2026] [security2:error] [pid 157386:tid 157635] [client 20.1.169.243:11275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSCm01jzAhYHVVT1WfdQwAAAYE"] [Tue Aug 18 13:04:43.075809 2026] [security2:error] [pid 157386:tid 157471] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/app/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdRQABHFQ"] [Tue Aug 18 13:04:43.086093 2026] [security2:error] [pid 157386:tid 157596] [client 168.62.48.100:5552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCm01jzAhYHVVT1WfdRgAAAVo"] [Tue Aug 18 13:04:43.092543 2026] [security2:error] [pid 157386:tid 157544] [client 20.51.153.15:8809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ib.php"] [unique_id "aoSCm01jzAhYHVVT1WfdRwAAASY"] [Tue Aug 18 13:04:43.097783 2026] [security2:error] [pid 157386:tid 157608] [client 20.104.100.201:23894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/privdayz.php"] [unique_id "aoSCm01jzAhYHVVT1WfdSAAAAWY"] [Tue Aug 18 13:04:43.121308 2026] [security2:error] [pid 157386:tid 157592] [client 20.25.139.174:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/155.php"] [unique_id "aoSCm01jzAhYHVVT1WfdSQAAAVY"] [Tue Aug 18 13:04:43.123893 2026] [security2:error] [pid 157386:tid 157546] [client 68.221.73.131:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCm01jzAhYHVVT1WfdSgAAASg"] [Tue Aug 18 13:04:43.141979 2026] [security2:error] [pid 157386:tid 157574] [client 20.226.36.136:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCm01jzAhYHVVT1WfdSwAAAUQ"] [Tue Aug 18 13:04:43.203044 2026] [security2:error] [pid 157386:tid 157481] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/src/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdTQABfF4"] [Tue Aug 18 13:04:43.227295 2026] [security2:error] [pid 157386:tid 157480] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/frontend/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdUgABhF0"] [Tue Aug 18 13:04:43.237444 2026] [security2:error] [pid 157386:tid 157490] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/server/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdUwABgGc"] [Tue Aug 18 13:04:43.255658 2026] [security2:error] [pid 157386:tid 157517] [client 158.23.17.4:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fo.php"] [unique_id "aoSCm01jzAhYHVVT1WfdVAAAAQs"] [Tue Aug 18 13:04:43.259452 2026] [security2:error] [pid 157386:tid 157487] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/dev/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdVQABDmQ"] [Tue Aug 18 13:04:43.300966 2026] [security2:error] [pid 157386:tid 157491] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/docker/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdVwABE2g"] [Tue Aug 18 13:04:43.302255 2026] [security2:error] [pid 157386:tid 157492] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/production/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdWAABE2k"] [Tue Aug 18 13:04:43.320071 2026] [autoindex:error] [pid 157386:tid 157604] [client 199.45.154.118:55398] AH01276: Cannot serve directory /home2/galeriadoengenho/teste.galeriadoengenho.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:43.386618 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.36.136:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCm01jzAhYHVVT1WfdXAAAAS4"] [Tue Aug 18 13:04:43.394328 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/yj09.php"] [unique_id "aoSCm01jzAhYHVVT1WfdXQAAAVw"] [Tue Aug 18 13:04:43.401670 2026] [security2:error] [pid 157386:tid 157494] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/staging/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdXgABSGs"] [Tue Aug 18 13:04:43.413181 2026] [security2:error] [pid 157386:tid 157573] [client 20.51.153.15:8420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xm.php"] [unique_id "aoSCm01jzAhYHVVT1WfdYAAAAUM"] [Tue Aug 18 13:04:43.429662 2026] [security2:error] [pid 157386:tid 157565] [client 20.206.73.37:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCm01jzAhYHVVT1WfdYQAAATs"] [Tue Aug 18 13:04:43.435464 2026] [security2:error] [pid 157386:tid 157484] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.production.bak"] [unique_id "aoSCm01jzAhYHVVT1WfdYgABHmE"] [Tue Aug 18 13:04:43.445174 2026] [security2:error] [pid 157386:tid 157584] [client 20.215.241.237:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/wpxml.php"] [unique_id "aoSCm01jzAhYHVVT1WfdZAAAAU4"] [Tue Aug 18 13:04:43.449382 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:46406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/zi.php"] [unique_id "aoSCm01jzAhYHVVT1WfdZQAAAVc"] [Tue Aug 18 13:04:43.459487 2026] [autoindex:error] [pid 157386:tid 157614] [client 20.1.169.243:11278] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:43.461150 2026] [security2:error] [pid 157386:tid 157594] [client 20.250.13.23:27936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/alfa.php"] [unique_id "aoSCm01jzAhYHVVT1WfdZwAAAVg"] [Tue Aug 18 13:04:43.481533 2026] [security2:error] [pid 157386:tid 157501] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSCm01jzAhYHVVT1WfdaQABTHI"] [Tue Aug 18 13:04:43.519746 2026] [security2:error] [pid 157386:tid 157504] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdbQABI3U"] [Tue Aug 18 13:04:43.521067 2026] [security2:error] [pid 157386:tid 157545] [client 4.223.113.180:19230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/alfa.php"] [unique_id "aoSCm01jzAhYHVVT1WfdbgAAASc"] [Tue Aug 18 13:04:43.527551 2026] [security2:error] [pid 157386:tid 157539] [client 68.221.73.131:56674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/nofile.php"] [unique_id "aoSCm01jzAhYHVVT1WfdbwAAASE"] [Tue Aug 18 13:04:43.530756 2026] [security2:error] [pid 157386:tid 157619] [client 20.104.100.201:23974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wg459o.php"] [unique_id "aoSCm01jzAhYHVVT1WfdcQAAAXE"] [Tue Aug 18 13:04:43.531138 2026] [security2:error] [pid 157386:tid 157506] [remote 34.79.57.13:44104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/@fs/.env"] [unique_id "aoSCm01jzAhYHVVT1WfdcAABg3c"] [Tue Aug 18 13:04:43.560711 2026] [security2:error] [pid 157386:tid 157529] [client 20.206.73.37:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/img.php"] [unique_id "aoSCm01jzAhYHVVT1WfdcgAAARc"] [Tue Aug 18 13:04:43.590108 2026] [security2:error] [pid 157386:tid 157556] [client 20.250.13.23:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.plakomaster.com.br"] [uri "/license.php"] [unique_id "aoSCm01jzAhYHVVT1WfddAAAATI"] [Tue Aug 18 13:04:43.622619 2026] [security2:error] [pid 157386:tid 157508] [remote 34.79.57.13:44104] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "seguntabmenca.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSCm01jzAhYHVVT1WfddwABD3k"] [Tue Aug 18 13:04:43.633004 2026] [autoindex:error] [pid 157386:tid 157568] [client 20.1.169.243:11278] AH01276: Cannot serve directory /home1/jomaconstrutora/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:43.651341 2026] [security2:error] [pid 157386:tid 157567] [client 20.206.73.37:17057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCm01jzAhYHVVT1WfdeAAAAT0"] [Tue Aug 18 13:04:43.675522 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/96i.php"] [unique_id "aoSCm01jzAhYHVVT1WfdeQAAAQ0"] [Tue Aug 18 13:04:43.677904 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.36.136:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCm01jzAhYHVVT1WfdewAAAVk"] [Tue Aug 18 13:04:43.682048 2026] [authz_core:error] [pid 157386:tid 157496] [remote 57.141.22.55:52866] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:43.682304 2026] [authz_core:error] [pid 157386:tid 157496] [remote 57.141.22.55:52866] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:43.730263 2026] [security2:error] [pid 157386:tid 157585] [client 4.232.151.198:7713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/wsoyanzfv3.php"] [unique_id "aoSCm01jzAhYHVVT1WfdfQAAAU8"] [Tue Aug 18 13:04:43.736271 2026] [security2:error] [pid 157386:tid 157635] [client 20.151.109.219:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/92.php"] [unique_id "aoSCm01jzAhYHVVT1WfdfwAAAYE"] [Tue Aug 18 13:04:43.754235 2026] [security2:error] [pid 157386:tid 157611] [client 20.1.169.243:11278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSCm01jzAhYHVVT1WfdgQAAAWk"] [Tue Aug 18 13:04:43.815272 2026] [security2:error] [pid 157386:tid 157546] [client 20.171.51.14:6639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/68.php"] [unique_id "aoSCm01jzAhYHVVT1WfdiAAAASg"] [Tue Aug 18 13:04:43.818610 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:43.818955 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:43.868484 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCm01jzAhYHVVT1WfdiQAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:43.946672 2026] [security2:error] [pid 157386:tid 157551] [client 20.124.247.79:16477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/scxy.php"] [unique_id "aoSCm01jzAhYHVVT1WfdiwAAAS0"] [Tue Aug 18 13:04:43.972933 2026] [security2:error] [pid 157386:tid 157543] [client 157.20.138.62:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCm01jzAhYHVVT1WfdjQAAASU"] [Tue Aug 18 13:04:43.973030 2026] [security2:error] [pid 157386:tid 157543] [client 157.20.138.62:59224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCm01jzAhYHVVT1WfdjQAAASU"] [Tue Aug 18 13:04:43.982260 2026] [security2:error] [pid 157386:tid 157597] [client 68.221.73.131:32388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/fling.php"] [unique_id "aoSCm01jzAhYHVVT1WfdjgAAAVs"] [Tue Aug 18 13:04:44.032470 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/jm.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdkQAAATc"] [Tue Aug 18 13:04:44.121529 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:44.122029 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:44.126095 2026] [security2:error] [pid 157386:tid 157517] [client 20.1.169.243:11161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/login.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdlAAAAQs"] [Tue Aug 18 13:04:44.159271 2026] [security2:error] [pid 157386:tid 157557] [client 20.104.100.201:23904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/mifta.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdmQAAATM"] [Tue Aug 18 13:04:44.162164 2026] [security2:error] [pid 157386:tid 157607] [client 68.155.154.236:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdmgAAAWU"] [Tue Aug 18 13:04:44.245300 2026] [security2:error] [pid 157386:tid 157613] [client 20.215.241.237:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/file1221.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdpAAAAWs"] [Tue Aug 18 13:04:44.249134 2026] [security2:error] [pid 157386:tid 157532] [client 20.25.139.174:4664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/as.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdpQAAARo"] [Tue Aug 18 13:04:44.258051 2026] [security2:error] [pid 157386:tid 157571] [client 158.23.17.4:63010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/loading.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdpgAAAUE"] [Tue Aug 18 13:04:44.340706 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:65046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wj.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdqgAAAUo"] [Tue Aug 18 13:04:44.404391 2026] [security2:error] [pid 157386:tid 157573] [client 132.196.30.78:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdrQAAAUM"] [Tue Aug 18 13:04:44.404450 2026] [security2:error] [pid 157386:tid 157541] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdqwABIw0"] [Tue Aug 18 13:04:44.418522 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:44.418805 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:44.447638 2026] [security2:error] [pid 157386:tid 157524] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/m.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdrwAAARI"] [Tue Aug 18 13:04:44.461696 2026] [security2:error] [pid 157386:tid 157536] [client 4.232.151.198:7702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/imageadmin.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdsQAAAR4"] [Tue Aug 18 13:04:44.491071 2026] [security2:error] [pid 157386:tid 157545] [client 20.1.169.243:11094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/min.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdswAAASc"] [Tue Aug 18 13:04:44.529369 2026] [security2:error] [pid 157386:tid 157591] [client 178.153.171.161:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdtQAAAVU"] [Tue Aug 18 13:04:44.529494 2026] [security2:error] [pid 157386:tid 157591] [client 178.153.171.161:16363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdtQAAAVU"] [Tue Aug 18 13:04:44.575150 2026] [security2:error] [pid 157386:tid 157612] [client 68.221.73.131:60603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/zoo1.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdtgAAAWo"] [Tue Aug 18 13:04:44.612402 2026] [autoindex:error] [pid 157386:tid 157555] [client 20.1.169.243:0] AH01276: Cannot serve directory /home4/spilwf01/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:44.657416 2026] [security2:error] [pid 157386:tid 157583] [client 20.124.247.79:16409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/ws13.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdvgAAAU0"] [Tue Aug 18 13:04:44.658414 2026] [security2:error] [pid 157386:tid 157534] [client 168.62.48.100:5404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdvwAAARw"] [Tue Aug 18 13:04:44.705027 2026] [security2:error] [pid 157386:tid 157614] [client 20.250.13.23:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/edit.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdxAAAAWw"] [Tue Aug 18 13:04:44.708635 2026] [security2:error] [pid 157386:tid 157546] [client 20.251.48.93:29238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/puc.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdxQAAASg"] [Tue Aug 18 13:04:44.719475 2026] [authz_core:error] [pid 157386:tid 157428] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:44.719790 2026] [authz_core:error] [pid 157386:tid 157428] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:44.740796 2026] [security2:error] [pid 157386:tid 157610] [client 20.151.109.219:49937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/74.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdygAAAWg"] [Tue Aug 18 13:04:44.765234 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.36.136:62190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCnE1jzAhYHVVT1WfdzgAAAWE"] [Tue Aug 18 13:04:44.808372 2026] [security2:error] [pid 157386:tid 157589] [client 20.151.109.219:10565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/xynz1.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd0AAAAVM"] [Tue Aug 18 13:04:44.856292 2026] [security2:error] [pid 157386:tid 157542] [client 20.1.169.243:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd0gAAASQ"] [Tue Aug 18 13:04:44.863226 2026] [security2:error] [pid 157386:tid 157544] [client 20.25.139.174:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/min.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd0wAAASY"] [Tue Aug 18 13:04:44.875431 2026] [security2:error] [pid 157386:tid 157561] [client 20.104.100.201:24017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd1AAAATc"] [Tue Aug 18 13:04:44.887761 2026] [security2:error] [pid 157386:tid 157526] [client 213.35.127.232:60856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd1gAAARQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:44.912268 2026] [security2:error] [pid 157386:tid 157525] [client 20.206.73.37:34756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "novoverona.com.br"] [uri "/.mopj.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd1wAAARM"] [Tue Aug 18 13:04:44.917739 2026] [security2:error] [pid 157386:tid 157517] [client 68.155.154.236:46838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/first.php"] [unique_id "aoSCnE1jzAhYHVVT1Wfd2AAAAQs"] [Tue Aug 18 13:04:45.002522 2026] [security2:error] [pid 157386:tid 157439] [remote 129.121.103.155:42340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd3wABIjQ"] [Tue Aug 18 13:04:45.020152 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:45.020413 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:45.091227 2026] [security2:error] [pid 157386:tid 157594] [client 20.151.109.219:62972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/av.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd5AAAAVg"] [Tue Aug 18 13:04:45.094737 2026] [security2:error] [pid 157386:tid 157558] [client 68.221.73.131:26063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/zoo2.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd5QAAATQ"] [Tue Aug 18 13:04:45.200838 2026] [security2:error] [pid 157386:tid 157556] [client 40.74.65.169:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/coffexium.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd6gAAATI"] [Tue Aug 18 13:04:45.203138 2026] [security2:error] [pid 157386:tid 157622] [client 4.232.151.198:7791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/webwp.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd6wAAAXQ"] [Tue Aug 18 13:04:45.210091 2026] [security2:error] [pid 157386:tid 157524] [client 158.23.17.4:47630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ke.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd7gAAARI"] [Tue Aug 18 13:04:45.223142 2026] [security2:error] [pid 157386:tid 157536] [client 20.226.36.136:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd8AAAAR4"] [Tue Aug 18 13:04:45.228070 2026] [security2:error] [pid 157386:tid 157609] [client 20.1.169.243:11087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/network/post.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd8QAAAWc"] [Tue Aug 18 13:04:45.229469 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:6644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/jl.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd8gAAATU"] [Tue Aug 18 13:04:45.231920 2026] [security2:error] [pid 157386:tid 157522] [client 103.120.71.157:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd8wAAARA"] [Tue Aug 18 13:04:45.232006 2026] [security2:error] [pid 157386:tid 157522] [client 103.120.71.157:64006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd8wAAARA"] [Tue Aug 18 13:04:45.258395 2026] [security2:error] [pid 157386:tid 157642] [client 138.36.100.162:41618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd9AAAAYg"] [Tue Aug 18 13:04:45.258480 2026] [security2:error] [pid 157386:tid 157642] [client 138.36.100.162:41618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd9AAAAYg"] [Tue Aug 18 13:04:45.320846 2026] [security2:error] [pid 157386:tid 157632] [client 132.196.30.78:19473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/function/function.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd9wAAAX4"] [Tue Aug 18 13:04:45.321738 2026] [authz_core:error] [pid 157386:tid 157426] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:45.322005 2026] [authz_core:error] [pid 157386:tid 157426] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:45.341114 2026] [security2:error] [pid 157386:tid 157519] [client 20.206.73.37:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd-AAAAQ0"] [Tue Aug 18 13:04:45.377294 2026] [security2:error] [pid 157386:tid 157449] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.old"] [unique_id "aoSCnU1jzAhYHVVT1Wfd-gABMT4"] [Tue Aug 18 13:04:45.380058 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:46415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ag.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd-wAAAVA"] [Tue Aug 18 13:04:45.404565 2026] [security2:error] [pid 157386:tid 157585] [client 68.155.154.236:41483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCnU1jzAhYHVVT1Wfd_gAAAU8"] [Tue Aug 18 13:04:45.407509 2026] [security2:error] [pid 157386:tid 157453] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env"] [unique_id "aoSCnU1jzAhYHVVT1WfeAAABTUI"] [Tue Aug 18 13:04:45.443188 2026] [security2:error] [pid 157386:tid 157626] [client 20.79.204.6:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeAwAAAXg"] [Tue Aug 18 13:04:45.457393 2026] [security2:error] [pid 157386:tid 157610] [client 20.104.100.201:23889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/index2.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeBgAAAWg"] [Tue Aug 18 13:04:45.514955 2026] [security2:error] [pid 157386:tid 157627] [client 20.226.36.136:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeCgAAAXk"] [Tue Aug 18 13:04:45.586090 2026] [security2:error] [pid 157386:tid 157460] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeDQABgEk"] [Tue Aug 18 13:04:45.586242 2026] [security2:error] [pid 157386:tid 157634] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeDQABgEk"] [Tue Aug 18 13:04:45.596247 2026] [security2:error] [pid 157386:tid 157603] [client 20.1.169.243:11109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/test.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeDgAAAWE"] [Tue Aug 18 13:04:45.600507 2026] [security2:error] [pid 157386:tid 157599] [client 20.151.109.219:45881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ud.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeEAAAAV0"] [Tue Aug 18 13:04:45.608036 2026] [security2:error] [pid 157386:tid 157465] [remote 212.29.237.5:34572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br"] [uri "/wp-login.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeEQABE04"], referer: https://tigre.tur.br/wp-login.php [Tue Aug 18 13:04:45.614613 2026] [security2:error] [pid 157386:tid 157421] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.backup"] [unique_id "aoSCnU1jzAhYHVVT1WfeEgABCyI"] [Tue Aug 18 13:04:45.621107 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:45.621369 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:45.622771 2026] [security2:error] [pid 157386:tid 157466] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/.env.bak"] [unique_id "aoSCnU1jzAhYHVVT1WfeFQABM08"] [Tue Aug 18 13:04:45.640985 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:19742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/album.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeGgAAAXc"] [Tue Aug 18 13:04:45.658424 2026] [security2:error] [pid 157386:tid 157552] [client 68.221.73.131:63054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/org.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeGwAAAS4"] [Tue Aug 18 13:04:45.686508 2026] [security2:error] [pid 157386:tid 157606] [client 20.226.36.136:61481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeHAAAAWQ"] [Tue Aug 18 13:04:45.693394 2026] [security2:error] [pid 157386:tid 157570] [client 20.151.109.219:62956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ig.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeHQAAAUA"] [Tue Aug 18 13:04:45.723398 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.36.136:62153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeHwAAAUk"] [Tue Aug 18 13:04:45.737153 2026] [security2:error] [pid 157386:tid 157594] [client 20.206.73.37:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/blurbs.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeIQAAAVg"] [Tue Aug 18 13:04:45.796029 2026] [security2:error] [pid 157386:tid 157529] [client 20.215.241.237:31134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/nox.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeIgAAARc"] [Tue Aug 18 13:04:45.800929 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.36.136:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeIwAAAUM"] [Tue Aug 18 13:04:45.857077 2026] [security2:error] [pid 157386:tid 157536] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/33.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeJwAAAR4"] [Tue Aug 18 13:04:45.873414 2026] [security2:error] [pid 157386:tid 157591] [client 68.155.154.236:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeLAAAAVU"] [Tue Aug 18 13:04:45.905619 2026] [security2:error] [pid 157386:tid 157616] [client 20.226.36.136:53555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeLQAAAW4"] [Tue Aug 18 13:04:45.907081 2026] [security2:error] [pid 157386:tid 157605] [client 213.35.127.232:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeLgAAAWM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:45.927267 2026] [security2:error] [pid 157386:tid 157562] [client 20.104.100.201:23948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/8.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeMAAAATg"] [Tue Aug 18 13:04:45.941249 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:45.941526 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:45.971281 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:49325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ta.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeNAAAASA"] [Tue Aug 18 13:04:45.983428 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:11188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeNQAAAYc"] [Tue Aug 18 13:04:45.989073 2026] [security2:error] [pid 157386:tid 157578] [client 4.232.151.198:7750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "aoSCnU1jzAhYHVVT1WfeNgAAAUg"] [Tue Aug 18 13:04:46.002617 2026] [security2:error] [pid 157386:tid 157639] [client 20.226.36.136:62178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeNwAAAYU"] [Tue Aug 18 13:04:46.045344 2026] [security2:error] [pid 157386:tid 157558] [client 132.196.30.78:19459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/nw.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeOAAAATQ"] [Tue Aug 18 13:04:46.069873 2026] [security2:error] [pid 157386:tid 157463] [remote 95.111.251.70:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villanobreeventos.com.br"] [uri "/wp-login.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeOgABg0w"] [Tue Aug 18 13:04:46.167862 2026] [security2:error] [pid 157386:tid 157528] [client 20.51.153.15:9132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/zy.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeRAAAARY"] [Tue Aug 18 13:04:46.169908 2026] [security2:error] [pid 157386:tid 157555] [client 20.25.139.174:4655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/php8.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeRQAAATE"] [Tue Aug 18 13:04:46.199778 2026] [security2:error] [pid 157386:tid 157638] [client 20.226.36.136:62170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeRwAAAYQ"] [Tue Aug 18 13:04:46.223876 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:46.224154 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:46.239250 2026] [security2:error] [pid 157386:tid 157603] [client 168.62.48.100:4146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeTAAAAWE"] [Tue Aug 18 13:04:46.246138 2026] [security2:error] [pid 157386:tid 157563] [client 20.151.109.219:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/34.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeTwAAATk"] [Tue Aug 18 13:04:46.247547 2026] [security2:error] [pid 157386:tid 157621] [client 68.155.153.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.153.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.reinertimoveis.com.br"] [uri "/packed.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeUAAAAXM"] [Tue Aug 18 13:04:46.256448 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:61254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeUQAAARM"] [Tue Aug 18 13:04:46.257058 2026] [security2:error] [pid 157386:tid 157517] [client 20.226.36.136:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeUgAAAQs"] [Tue Aug 18 13:04:46.280263 2026] [security2:error] [pid 157386:tid 157612] [client 20.79.204.6:9692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/themes.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeVAAAAWo"] [Tue Aug 18 13:04:46.309939 2026] [security2:error] [pid 157386:tid 157595] [client 68.221.73.131:39777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/imageskir.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeWAAAAVk"] [Tue Aug 18 13:04:46.332994 2026] [security2:error] [pid 157386:tid 157613] [client 20.226.36.136:65310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeWwAAAWs"] [Tue Aug 18 13:04:46.417422 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.100.201:24030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/images.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeXgAAAUo"] [Tue Aug 18 13:04:46.442303 2026] [security2:error] [pid 157386:tid 157529] [client 20.51.153.15:8402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/q.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeXwAAARc"] [Tue Aug 18 13:04:46.445571 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.36.136:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeYAAAAUM"] [Tue Aug 18 13:04:46.449235 2026] [security2:error] [pid 157386:tid 157588] [client 20.171.51.14:37393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/tq.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeYQAAAVI"] [Tue Aug 18 13:04:46.466537 2026] [security2:error] [pid 157386:tid 157617] [client 20.215.241.237:31143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/akismet.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeYgAAAW8"] [Tue Aug 18 13:04:46.512562 2026] [security2:error] [pid 157386:tid 157568] [client 20.226.36.136:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeZAAAAT4"] [Tue Aug 18 13:04:46.534491 2026] [security2:error] [pid 157386:tid 157575] [client 68.155.154.236:40195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeZwAAAUU"] [Tue Aug 18 13:04:46.548878 2026] [security2:error] [pid 157386:tid 157605] [client 158.23.17.4:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nh.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeawAAAWM"] [Tue Aug 18 13:04:46.559428 2026] [security2:error] [pid 157386:tid 157516] [client 20.1.169.243:11263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/user/min.php"] [unique_id "aoSCnk1jzAhYHVVT1WfebAAAAQo"] [Tue Aug 18 13:04:46.599453 2026] [security2:error] [pid 157386:tid 157531] [client 37.40.227.74:57135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnk1jzAhYHVVT1WfebwAAARk"] [Tue Aug 18 13:04:46.599552 2026] [security2:error] [pid 157386:tid 157531] [client 37.40.227.74:57135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnk1jzAhYHVVT1WfebwAAARk"] [Tue Aug 18 13:04:46.635761 2026] [security2:error] [pid 157386:tid 157639] [client 20.226.36.136:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCnk1jzAhYHVVT1WfecAAAAYU"] [Tue Aug 18 13:04:46.636744 2026] [security2:error] [pid 157386:tid 157619] [client 4.232.151.198:25244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/module.tag.id3v3.php"] [unique_id "aoSCnk1jzAhYHVVT1WfecQAAAXE"] [Tue Aug 18 13:04:46.650432 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.36.136:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCnk1jzAhYHVVT1WfecgAAAVs"] [Tue Aug 18 13:04:46.673712 2026] [security2:error] [pid 157386:tid 157583] [client 20.151.109.219:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ip.php"] [unique_id "aoSCnk1jzAhYHVVT1WfecwAAAU0"] [Tue Aug 18 13:04:46.684225 2026] [security2:error] [pid 157386:tid 157558] [client 20.51.153.15:9208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xf.php"] [unique_id "aoSCnk1jzAhYHVVT1WfedAAAATQ"] [Tue Aug 18 13:04:46.692548 2026] [security2:error] [pid 157386:tid 157640] [client 103.184.169.37:43875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnk1jzAhYHVVT1WfedQAAAYY"] [Tue Aug 18 13:04:46.692652 2026] [security2:error] [pid 157386:tid 157640] [client 103.184.169.37:43875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCnk1jzAhYHVVT1WfedQAAAYY"] [Tue Aug 18 13:04:46.729652 2026] [security2:error] [pid 157386:tid 157616] [client 20.25.139.174:4662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeeAAAAW4"] [Tue Aug 18 13:04:46.737740 2026] [security2:error] [pid 157386:tid 157608] [client 20.226.36.136:62199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCnk1jzAhYHVVT1WfeegAAAWY"] [Tue Aug 18 13:04:46.774028 2026] [security2:error] [pid 157386:tid 157554] [client 4.232.151.198:40574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/bless.php"] [unique_id "aoSCnk1jzAhYHVVT1WfefgAAATA"] [Tue Aug 18 13:04:46.785585 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/he.php"] [unique_id "aoSCnk1jzAhYHVVT1WfegAAAAXw"] [Tue Aug 18 13:04:46.796096 2026] [security2:error] [pid 157386:tid 157555] [client 20.226.36.136:61470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCnk1jzAhYHVVT1WfegQAAATE"] [Tue Aug 18 13:04:46.816345 2026] [security2:error] [pid 157386:tid 157638] [client 20.226.36.136:61483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCnk1jzAhYHVVT1WfehAAAAYQ"] [Tue Aug 18 13:04:46.825541 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:46.825818 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:46.843244 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.36.136:62202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCnk1jzAhYHVVT1WfehgAAAWE"] [Tue Aug 18 13:04:46.874175 2026] [security2:error] [pid 157386:tid 157607] [client 20.226.36.136:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCnk1jzAhYHVVT1WfejAAAAWU"] [Tue Aug 18 13:04:46.904094 2026] [security2:error] [pid 157386:tid 157628] [client 132.196.30.78:19461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/xleet.php"] [unique_id "aoSCnk1jzAhYHVVT1WfejgAAAXo"] [Tue Aug 18 13:04:46.906120 2026] [security2:error] [pid 157386:tid 157634] [client 20.91.215.254:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSCnk1jzAhYHVVT1WfejwAAAYA"] [Tue Aug 18 13:04:46.919387 2026] [security2:error] [pid 157386:tid 157549] [client 213.35.127.232:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCnk1jzAhYHVVT1WfekQAAASs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:46.925653 2026] [security2:error] [pid 157386:tid 157633] [client 20.1.169.243:11281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/users.php"] [unique_id "aoSCnk1jzAhYHVVT1WfekgAAAX8"] [Tue Aug 18 13:04:46.987201 2026] [security2:error] [pid 157386:tid 157547] [client 20.51.153.15:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/jp.php"] [unique_id "aoSCnk1jzAhYHVVT1WfemQAAASk"] [Tue Aug 18 13:04:46.989752 2026] [security2:error] [pid 157386:tid 157417] [remote 47.89.174.181:29932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.fernandooliveiracorretor.com.br"] [uri "/.env"] [unique_id "aoSCnk1jzAhYHVVT1WfemgABJh4"] [Tue Aug 18 13:04:47.004425 2026] [security2:error] [pid 157386:tid 157571] [client 68.221.73.131:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/indexo.php"] [unique_id "aoSCn01jzAhYHVVT1WfemwAAAUE"] [Tue Aug 18 13:04:47.017456 2026] [authz_core:error] [pid 157386:tid 157496] [remote 94.100.52.46:61925] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/configs.php [Tue Aug 18 13:04:47.064396 2026] [security2:error] [pid 157386:tid 157617] [client 20.104.100.201:23820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/a.php"] [unique_id "aoSCn01jzAhYHVVT1WfenwAAAW8"] [Tue Aug 18 13:04:47.107380 2026] [security2:error] [pid 157386:tid 157565] [client 20.226.36.136:62169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCn01jzAhYHVVT1WfeoAAAATs"] [Tue Aug 18 13:04:47.119755 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:49293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gz.php"] [unique_id "aoSCn01jzAhYHVVT1WfeoQAAASc"] [Tue Aug 18 13:04:47.122584 2026] [security2:error] [pid 157386:tid 157596] [client 20.91.215.254:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSCn01jzAhYHVVT1WfeowAAAVo"] [Tue Aug 18 13:04:47.128294 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:47.128570 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:47.136892 2026] [security2:error] [pid 157386:tid 157556] [client 5.31.227.224:30402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCn01jzAhYHVVT1WfepQAAATI"] [Tue Aug 18 13:04:47.137013 2026] [security2:error] [pid 157386:tid 157556] [client 5.31.227.224:30402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCn01jzAhYHVVT1WfepQAAATI"] [Tue Aug 18 13:04:47.137527 2026] [authz_core:error] [pid 157386:tid 157483] [remote 57.141.22.19:58294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:47.137791 2026] [authz_core:error] [pid 157386:tid 157483] [remote 57.141.22.19:58294] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:47.144807 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.36.136:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCn01jzAhYHVVT1WfepgAAAWc"] [Tue Aug 18 13:04:47.183072 2026] [security2:error] [pid 157386:tid 157562] [client 20.226.36.136:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCn01jzAhYHVVT1WfeqgAAATg"] [Tue Aug 18 13:04:47.214100 2026] [security2:error] [pid 157386:tid 157578] [client 20.226.36.136:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCn01jzAhYHVVT1WferAAAAUg"] [Tue Aug 18 13:04:47.215037 2026] [security2:error] [pid 157386:tid 157639] [client 20.171.51.14:44912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/cv.php"] [unique_id "aoSCn01jzAhYHVVT1WferQAAAYU"] [Tue Aug 18 13:04:47.223102 2026] [security2:error] [pid 157386:tid 157622] [client 20.25.139.174:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/222.php"] [unique_id "aoSCn01jzAhYHVVT1WfergAAAXQ"] [Tue Aug 18 13:04:47.238169 2026] [security2:error] [pid 157386:tid 157534] [client 20.226.36.136:52671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCn01jzAhYHVVT1WferwAAARw"] [Tue Aug 18 13:04:47.250292 2026] [security2:error] [pid 157386:tid 157548] [client 20.79.204.6:9687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/cv.php"] [unique_id "aoSCn01jzAhYHVVT1WfeswAAASo"] [Tue Aug 18 13:04:47.267037 2026] [security2:error] [pid 157386:tid 157614] [client 20.215.241.237:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/admin.php"] [unique_id "aoSCn01jzAhYHVVT1WfetAAAAWw"] [Tue Aug 18 13:04:47.280821 2026] [security2:error] [pid 157386:tid 157616] [client 20.51.153.15:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/eq.php"] [unique_id "aoSCn01jzAhYHVVT1WfetQAAAW4"] [Tue Aug 18 13:04:47.285676 2026] [security2:error] [pid 157386:tid 157600] [client 20.226.36.136:61497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCn01jzAhYHVVT1WfetgAAAV4"] [Tue Aug 18 13:04:47.314921 2026] [security2:error] [pid 157386:tid 157624] [client 20.206.73.37:2852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCn01jzAhYHVVT1WfeugAAAXY"] [Tue Aug 18 13:04:47.316851 2026] [security2:error] [pid 157386:tid 157620] [client 4.232.151.198:18559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/wp-db-ajax-made/wp-ajax.php"] [unique_id "aoSCn01jzAhYHVVT1WfeuwAAAXI"] [Tue Aug 18 13:04:47.317977 2026] [security2:error] [pid 157386:tid 157631] [client 20.1.169.243:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSCn01jzAhYHVVT1WfevAAAAX0"] [Tue Aug 18 13:04:47.340216 2026] [security2:error] [pid 157386:tid 157551] [client 20.226.36.136:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCn01jzAhYHVVT1WfevwAAAS0"] [Tue Aug 18 13:04:47.363936 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.36.136:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/rezor.php"] [unique_id "aoSCn01jzAhYHVVT1WfewQAAAXw"] [Tue Aug 18 13:04:47.375191 2026] [security2:error] [pid 157386:tid 157493] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/phpinfo.php"] [unique_id "aoSCn01jzAhYHVVT1WfewgABVmo"] [Tue Aug 18 13:04:47.378146 2026] [security2:error] [pid 157386:tid 157638] [client 68.155.154.236:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCn01jzAhYHVVT1WfewwAAAYQ"] [Tue Aug 18 13:04:47.393854 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.36.136:65303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCn01jzAhYHVVT1WfexQAAATk"] [Tue Aug 18 13:04:47.412818 2026] [security2:error] [pid 157386:tid 157517] [client 20.226.36.136:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCn01jzAhYHVVT1WfexwAAAQs"] [Tue Aug 18 13:04:47.414417 2026] [security2:error] [pid 157386:tid 157561] [client 158.23.17.4:14063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/oo.php"] [unique_id "aoSCn01jzAhYHVVT1WfeyAAAATc"] [Tue Aug 18 13:04:47.426735 2026] [security2:error] [pid 157386:tid 157430] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/info.php"] [unique_id "aoSCn01jzAhYHVVT1WfeygABgCs"] [Tue Aug 18 13:04:47.445160 2026] [security2:error] [pid 157386:tid 157552] [client 20.124.247.79:16441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/btx25.php"] [unique_id "aoSCn01jzAhYHVVT1WfeywAAAS4"] [Tue Aug 18 13:04:47.458624 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nf.php"] [unique_id "aoSCn01jzAhYHVVT1WfezgAAAXA"] [Tue Aug 18 13:04:47.458663 2026] [security2:error] [pid 157386:tid 157595] [client 20.104.100.201:23957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSCn01jzAhYHVVT1WfezQAAAVk"] [Tue Aug 18 13:04:47.466864 2026] [security2:error] [pid 157386:tid 157577] [client 20.226.36.136:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/index/function.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe0AAAAUc"] [Tue Aug 18 13:04:47.466893 2026] [security2:error] [pid 157386:tid 157432] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/pi.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe0QABVy0"] [Tue Aug 18 13:04:47.475530 2026] [security2:error] [pid 157386:tid 157419] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/test.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe0gABayA"] [Tue Aug 18 13:04:47.477373 2026] [security2:error] [pid 157386:tid 157436] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/i.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe0wABKTE"] [Tue Aug 18 13:04:47.499652 2026] [security2:error] [pid 157386:tid 157594] [client 20.226.36.136:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe1gAAAVg"] [Tue Aug 18 13:04:47.501143 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:32384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe1wAAARM"] [Tue Aug 18 13:04:47.554151 2026] [security2:error] [pid 157386:tid 157596] [client 20.226.36.136:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/Cachex.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe2QAAAVo"] [Tue Aug 18 13:04:47.570983 2026] [security2:error] [pid 157386:tid 157609] [client 20.51.153.15:8729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/rf.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe2gAAAWc"] [Tue Aug 18 13:04:47.605884 2026] [security2:error] [pid 157386:tid 157587] [client 88.99.80.227:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSCnk1jzAhYHVVT1WfebgABUXw"], referer: https://www.doroincorporacoes.com.br/ [Tue Aug 18 13:04:47.619777 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe3gAAARk"] [Tue Aug 18 13:04:47.649534 2026] [security2:error] [pid 157386:tid 157401] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/app_dev.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe4AABhw4"] [Tue Aug 18 13:04:47.660030 2026] [security2:error] [pid 157386:tid 157619] [client 20.226.36.136:53514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe4QAAAXE"] [Tue Aug 18 13:04:47.680738 2026] [security2:error] [pid 157386:tid 157544] [client 132.196.30.78:20047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe4gAAASY"] [Tue Aug 18 13:04:47.683795 2026] [security2:error] [pid 157386:tid 157570] [client 197.184.64.235:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe5AAAAUA"] [Tue Aug 18 13:04:47.683889 2026] [security2:error] [pid 157386:tid 157570] [client 197.184.64.235:42670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe5AAAAUA"] [Tue Aug 18 13:04:47.688293 2026] [security2:error] [pid 157386:tid 157442] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.57.79.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSCn01jzAhYHVVT1Wfe5gABaTc"] [Tue Aug 18 13:04:47.691791 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:11102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe6AAAARA"] [Tue Aug 18 13:04:47.691825 2026] [security2:error] [pid 157386:tid 157548] [client 20.226.36.136:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe5wAAASo"] [Tue Aug 18 13:04:47.710294 2026] [security2:error] [pid 157386:tid 157536] [client 20.25.139.174:4711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe6wAAAR4"] [Tue Aug 18 13:04:47.729449 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:47.729717 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:47.733351 2026] [security2:error] [pid 157386:tid 157600] [client 216.244.66.243:40326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/bet979-3/"] [unique_id "aoSCn01jzAhYHVVT1Wfe7gAAAV4"] [Tue Aug 18 13:04:47.733451 2026] [security2:error] [pid 157386:tid 157600] [client 216.244.66.243:40326] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/bet979-3/"] [unique_id "aoSCn01jzAhYHVVT1Wfe7gAAAV4"] [Tue Aug 18 13:04:47.759206 2026] [security2:error] [pid 157386:tid 157585] [client 20.206.73.37:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/aa.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe8AAAAU8"] [Tue Aug 18 13:04:47.777289 2026] [security2:error] [pid 157386:tid 157546] [client 20.226.36.136:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe8wAAASg"] [Tue Aug 18 13:04:47.807645 2026] [security2:error] [pid 157386:tid 157643] [client 20.151.109.219:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xv.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe9QAAAYk"] [Tue Aug 18 13:04:47.862508 2026] [security2:error] [pid 157386:tid 157592] [client 20.226.36.136:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe-AAAAVY"] [Tue Aug 18 13:04:47.891604 2026] [security2:error] [pid 157386:tid 157599] [client 20.91.215.254:15642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSCn01jzAhYHVVT1Wfe-QAAAV0"] [Tue Aug 18 13:04:47.900842 2026] [access_compat:error] [pid 157386:tid 157450] [remote 34.79.57.13:44120] AH01797: client denied by server configuration: /home4/raben7/public_html/server-status [Tue Aug 18 13:04:47.917586 2026] [security2:error] [pid 157386:tid 157456] [remote 34.79.57.13:44120] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "seguntabmenca.com.br"] [uri "/server-info"] [unique_id "aoSCn01jzAhYHVVT1Wfe_gABLEU"] [Tue Aug 18 13:04:47.939646 2026] [authz_core:error] [pid 157386:tid 157561] [client 94.100.52.46:54985] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/configs.php [Tue Aug 18 13:04:47.947172 2026] [security2:error] [pid 157386:tid 157516] [client 213.35.127.232:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCn01jzAhYHVVT1WffAAAAAQo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:47.961049 2026] [security2:error] [pid 157386:tid 157590] [client 20.51.153.15:8827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xynz1.php"] [unique_id "aoSCn01jzAhYHVVT1WffAQAAAVQ"] [Tue Aug 18 13:04:47.968442 2026] [security2:error] [pid 157386:tid 157634] [client 20.226.36.136:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCn01jzAhYHVVT1WffAgAAAYA"] [Tue Aug 18 13:04:48.019133 2026] [security2:error] [pid 157386:tid 157618] [client 20.226.36.136:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffBAAAAXA"] [Tue Aug 18 13:04:48.035309 2026] [authz_core:error] [pid 157386:tid 157455] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:48.035757 2026] [authz_core:error] [pid 157386:tid 157455] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:48.038253 2026] [security2:error] [pid 157386:tid 157630] [client 4.232.151.198:29690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/comments.php"] [unique_id "aoSCoE1jzAhYHVVT1WffBwAAAXw"] [Tue Aug 18 13:04:48.042031 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:21930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/99.php"] [unique_id "aoSCoE1jzAhYHVVT1WffCAAAARo"] [Tue Aug 18 13:04:48.052083 2026] [security2:error] [pid 157386:tid 157574] [client 20.104.100.201:24026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/99.php"] [unique_id "aoSCoE1jzAhYHVVT1WffCgAAAUQ"] [Tue Aug 18 13:04:48.057233 2026] [security2:error] [pid 157386:tid 157517] [client 20.1.169.243:11235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSCoE1jzAhYHVVT1WffCwAAAQs"] [Tue Aug 18 13:04:48.060169 2026] [security2:error] [pid 157386:tid 157594] [client 20.226.36.136:61492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCoE1jzAhYHVVT1WffDAAAAVg"] [Tue Aug 18 13:04:48.063459 2026] [security2:error] [pid 157386:tid 157582] [client 196.12.128.158:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCoE1jzAhYHVVT1WffDgAAAUw"] [Tue Aug 18 13:04:48.063558 2026] [security2:error] [pid 157386:tid 157582] [client 196.12.128.158:53203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCoE1jzAhYHVVT1WffDgAAAUw"] [Tue Aug 18 13:04:48.084107 2026] [security2:error] [pid 157386:tid 157610] [client 20.226.36.136:48849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCoE1jzAhYHVVT1WffEwAAAWg"] [Tue Aug 18 13:04:48.106543 2026] [security2:error] [pid 157386:tid 157530] [client 20.151.109.219:17626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/creds.php"] [unique_id "aoSCoE1jzAhYHVVT1WffFAAAARg"] [Tue Aug 18 13:04:48.119228 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.36.136:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffFgAAAWM"] [Tue Aug 18 13:04:48.131698 2026] [security2:error] [pid 157386:tid 157589] [client 20.151.109.219:5333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mx.php"] [unique_id "aoSCoE1jzAhYHVVT1WffGAAAAVM"] [Tue Aug 18 13:04:48.153877 2026] [security2:error] [pid 157386:tid 157421] [remote 162.43.94.44:39404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.94.43.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSCoE1jzAhYHVVT1WffGgABiCI"] [Tue Aug 18 13:04:48.172511 2026] [security2:error] [pid 157386:tid 157619] [client 20.226.36.136:52661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffHgAAAXE"] [Tue Aug 18 13:04:48.191941 2026] [security2:error] [pid 157386:tid 157544] [client 158.23.17.4:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ja.php"] [unique_id "aoSCoE1jzAhYHVVT1WffIAAAASY"] [Tue Aug 18 13:04:48.199296 2026] [security2:error] [pid 157386:tid 157547] [client 20.25.139.174:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/info.php"] [unique_id "aoSCoE1jzAhYHVVT1WffIQAAASk"] [Tue Aug 18 13:04:48.221502 2026] [security2:error] [pid 157386:tid 157548] [client 20.226.36.136:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffJAAAASo"] [Tue Aug 18 13:04:48.248390 2026] [security2:error] [pid 157386:tid 157535] [client 20.51.153.15:9138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ri.php"] [unique_id "aoSCoE1jzAhYHVVT1WffKAAAAR0"] [Tue Aug 18 13:04:48.308522 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.36.136:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCoE1jzAhYHVVT1WffLAAAAQw"] [Tue Aug 18 13:04:48.347560 2026] [security2:error] [pid 157386:tid 157545] [client 223.185.37.47:18917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCoE1jzAhYHVVT1WffMAAAASc"] [Tue Aug 18 13:04:48.347677 2026] [security2:error] [pid 157386:tid 157545] [client 223.185.37.47:18917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCoE1jzAhYHVVT1WffMAAAASc"] [Tue Aug 18 13:04:48.367277 2026] [security2:error] [pid 157386:tid 157638] [client 20.226.36.136:62180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCoE1jzAhYHVVT1WffMgAAAYQ"] [Tue Aug 18 13:04:48.416669 2026] [security2:error] [pid 157386:tid 157526] [client 20.226.36.136:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCoE1jzAhYHVVT1WffNQAAARQ"] [Tue Aug 18 13:04:48.420941 2026] [security2:error] [pid 157386:tid 157624] [client 20.1.169.243:11078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSCoE1jzAhYHVVT1WffNgAAAXY"] [Tue Aug 18 13:04:48.444228 2026] [security2:error] [pid 157386:tid 157531] [client 4.223.113.180:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffOAAAARk"] [Tue Aug 18 13:04:48.446906 2026] [security2:error] [pid 157386:tid 157550] [client 40.85.222.29:17584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCoE1jzAhYHVVT1WffOQAAASw"] [Tue Aug 18 13:04:48.465494 2026] [security2:error] [pid 157386:tid 157561] [client 68.221.73.131:26056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSCoE1jzAhYHVVT1WffOgAAATc"] [Tue Aug 18 13:04:48.479159 2026] [security2:error] [pid 157386:tid 157579] [client 4.232.151.198:37184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/sagax1.php"] [unique_id "aoSCoE1jzAhYHVVT1WffOwAAAUk"] [Tue Aug 18 13:04:48.495848 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.36.136:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffPAAAAVQ"] [Tue Aug 18 13:04:48.499798 2026] [security2:error] [pid 157386:tid 157637] [client 68.155.154.236:40419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffPQAAAYM"] [Tue Aug 18 13:04:48.526384 2026] [security2:error] [pid 157386:tid 157572] [client 20.226.36.136:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffPgAAAUI"] [Tue Aug 18 13:04:48.538776 2026] [security2:error] [pid 157386:tid 157603] [client 23.22.105.143:57871] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lavobrasil.com.br"] [uri "/poazonasul/"] [unique_id "aoSCoE1jzAhYHVVT1WffPwAAAWE"] [Tue Aug 18 13:04:48.554758 2026] [security2:error] [pid 157386:tid 157595] [client 40.74.65.169:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCoE1jzAhYHVVT1WffQAAAAVk"] [Tue Aug 18 13:04:48.571927 2026] [security2:error] [pid 157386:tid 157555] [client 20.91.215.254:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/st.php"] [unique_id "aoSCoE1jzAhYHVVT1WffQQAAATE"] [Tue Aug 18 13:04:48.583332 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.100.201:23965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/yup.php"] [unique_id "aoSCoE1jzAhYHVVT1WffQgAAAXA"] [Tue Aug 18 13:04:48.584638 2026] [security2:error] [pid 157386:tid 157593] [client 20.226.36.136:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCoE1jzAhYHVVT1WffQwAAAVc"] [Tue Aug 18 13:04:48.641002 2026] [security2:error] [pid 157386:tid 157594] [client 20.51.153.15:8784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/tp.php"] [unique_id "aoSCoE1jzAhYHVVT1WffRwAAAVg"] [Tue Aug 18 13:04:48.654553 2026] [security2:error] [pid 157386:tid 157582] [client 20.226.36.136:65342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffSAAAAUw"] [Tue Aug 18 13:04:48.693687 2026] [security2:error] [pid 157386:tid 157565] [client 20.226.36.136:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCoE1jzAhYHVVT1WffSQAAATs"] [Tue Aug 18 13:04:48.700584 2026] [security2:error] [pid 157386:tid 157552] [client 20.25.139.174:4616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/a.php"] [unique_id "aoSCoE1jzAhYHVVT1WffSgAAAS4"] [Tue Aug 18 13:04:48.716371 2026] [security2:error] [pid 157386:tid 157612] [client 132.196.30.78:20086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/155.php"] [unique_id "aoSCoE1jzAhYHVVT1WffSwAAAWo"] [Tue Aug 18 13:04:48.719225 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.36.136:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCoE1jzAhYHVVT1WffTQAAATI"] [Tue Aug 18 13:04:48.730664 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:13386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/un.php"] [unique_id "aoSCoE1jzAhYHVVT1WffTgAAATU"] [Tue Aug 18 13:04:48.734202 2026] [security2:error] [pid 157386:tid 157591] [client 40.85.222.29:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCoE1jzAhYHVVT1WffTwAAAVU"] [Tue Aug 18 13:04:48.802476 2026] [security2:error] [pid 157386:tid 157554] [client 168.62.48.100:5607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/blog/byp.php"] [unique_id "aoSCoE1jzAhYHVVT1WffUQAAATA"] [Tue Aug 18 13:04:48.814243 2026] [security2:error] [pid 157386:tid 157610] [client 20.1.169.243:11122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSCoE1jzAhYHVVT1WffUgAAAWg"] [Tue Aug 18 13:04:48.920336 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:13762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/er.php"] [unique_id "aoSCoE1jzAhYHVVT1WffWAAAAR0"] [Tue Aug 18 13:04:48.933155 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:48.933432 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:48.938897 2026] [security2:error] [pid 157386:tid 157611] [client 20.226.36.136:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCoE1jzAhYHVVT1WffWwAAAWk"] [Tue Aug 18 13:04:48.964402 2026] [security2:error] [pid 157386:tid 157608] [client 213.202.253.4:49745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/txets.php"] [unique_id "aoSCoE1jzAhYHVVT1WffXAAAAWY"], referer: www.google.com [Tue Aug 18 13:04:48.967412 2026] [security2:error] [pid 157386:tid 157525] [client 213.35.127.232:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCoE1jzAhYHVVT1WffXQAAARM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:48.973151 2026] [security2:error] [pid 157386:tid 157546] [client 158.23.17.4:47651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xx.php"] [unique_id "aoSCoE1jzAhYHVVT1WffXgAAASg"] [Tue Aug 18 13:04:48.983823 2026] [security2:error] [pid 157386:tid 157527] [client 20.51.153.15:8813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/zj.php"] [unique_id "aoSCoE1jzAhYHVVT1WffYAAAARU"] [Tue Aug 18 13:04:48.996651 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.100.201:23873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/222.php"] [unique_id "aoSCoE1jzAhYHVVT1WffYQAAAQw"] [Tue Aug 18 13:04:49.047102 2026] [security2:error] [pid 157386:tid 157533] [client 40.85.222.29:6741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/weozh.php"] [unique_id "aoSCoU1jzAhYHVVT1WffYwAAARs"] [Tue Aug 18 13:04:49.143885 2026] [security2:error] [pid 157386:tid 157604] [client 68.221.73.131:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/av.php"] [unique_id "aoSCoU1jzAhYHVVT1WffZwAAAWI"] [Tue Aug 18 13:04:49.179056 2026] [security2:error] [pid 157386:tid 157550] [client 20.226.36.136:53516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCoU1jzAhYHVVT1WffaAAAASw"] [Tue Aug 18 13:04:49.186878 2026] [security2:error] [pid 157386:tid 157567] [client 20.1.169.243:11262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-admin/x.php"] [unique_id "aoSCoU1jzAhYHVVT1WffaQAAAT0"] [Tue Aug 18 13:04:49.198960 2026] [security2:error] [pid 157386:tid 157628] [client 4.232.151.198:24198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "aoSCoU1jzAhYHVVT1WffagAAAXo"] [Tue Aug 18 13:04:49.203492 2026] [security2:error] [pid 157386:tid 157516] [client 20.151.109.219:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/45.php"] [unique_id "aoSCoU1jzAhYHVVT1WffawAAAQo"] [Tue Aug 18 13:04:49.208894 2026] [security2:error] [pid 157386:tid 157524] [client 20.91.215.254:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSCoU1jzAhYHVVT1WffbAAAARI"] [Tue Aug 18 13:04:49.222035 2026] [security2:error] [pid 157386:tid 157637] [client 20.206.73.37:29773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/bajah.php"] [unique_id "aoSCoU1jzAhYHVVT1WffbQAAAYM"] [Tue Aug 18 13:04:49.233425 2026] [authz_core:error] [pid 157386:tid 157490] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:49.233686 2026] [authz_core:error] [pid 157386:tid 157490] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:49.292351 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.36.136:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCoU1jzAhYHVVT1WffcwAAAVk"] [Tue Aug 18 13:04:49.296497 2026] [security2:error] [pid 157386:tid 157592] [client 20.25.139.174:4667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/chosen.php"] [unique_id "aoSCoU1jzAhYHVVT1WffdAAAAVY"] [Tue Aug 18 13:04:49.300687 2026] [security2:error] [pid 157386:tid 157638] [client 132.196.30.78:19460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/96i.php"] [unique_id "aoSCoU1jzAhYHVVT1WffdQAAAYQ"] [Tue Aug 18 13:04:49.310670 2026] [security2:error] [pid 157386:tid 157534] [client 68.221.73.131:26100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/.admin.php"] [unique_id "aoSCoU1jzAhYHVVT1WffdgAAARw"] [Tue Aug 18 13:04:49.337337 2026] [security2:error] [pid 157386:tid 157593] [client 20.171.51.14:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/evil.php"] [unique_id "aoSCoU1jzAhYHVVT1WffeQAAAVc"] [Tue Aug 18 13:04:49.338012 2026] [security2:error] [pid 157386:tid 157532] [client 20.104.100.201:23884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCoU1jzAhYHVVT1WffewAAARo"] [Tue Aug 18 13:04:49.347081 2026] [security2:error] [pid 157386:tid 157520] [client 20.226.36.136:52667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCoU1jzAhYHVVT1WfffAAAAQ4"] [Tue Aug 18 13:04:49.349908 2026] [security2:error] [pid 157386:tid 157574] [client 40.85.222.29:17567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/rymmm.php"] [unique_id "aoSCoU1jzAhYHVVT1WfffQAAAUQ"] [Tue Aug 18 13:04:49.407312 2026] [security2:error] [pid 157386:tid 157552] [client 20.51.153.15:8771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/11.php"] [unique_id "aoSCoU1jzAhYHVVT1WfffwAAAS4"] [Tue Aug 18 13:04:49.419088 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.36.136:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffgAAAATI"] [Tue Aug 18 13:04:49.484776 2026] [security2:error] [pid 157386:tid 157639] [client 20.250.13.23:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/inputs.php"] [unique_id "aoSCoU1jzAhYHVVT1WffgwAAAYU"] [Tue Aug 18 13:04:49.498116 2026] [security2:error] [pid 157386:tid 157591] [client 20.226.36.136:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCoU1jzAhYHVVT1WffhAAAAVU"] [Tue Aug 18 13:04:49.527807 2026] [security2:error] [pid 157386:tid 157564] [client 20.251.48.93:38785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/inso.php"] [unique_id "aoSCoU1jzAhYHVVT1WffhgAAATo"] [Tue Aug 18 13:04:49.532185 2026] [security2:error] [pid 157386:tid 157642] [client 20.226.36.136:62197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCoU1jzAhYHVVT1WffiAAAAYg"] [Tue Aug 18 13:04:49.535590 2026] [authz_core:error] [pid 157386:tid 157507] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:49.535881 2026] [authz_core:error] [pid 157386:tid 157507] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:49.551635 2026] [security2:error] [pid 157386:tid 157521] [client 158.23.17.4:48446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/conn-test.php"] [unique_id "aoSCoU1jzAhYHVVT1WffiwAAAQ8"] [Tue Aug 18 13:04:49.555382 2026] [security2:error] [pid 157386:tid 157530] [client 20.1.169.243:10894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSCoU1jzAhYHVVT1WffjAAAARg"] [Tue Aug 18 13:04:49.562888 2026] [security2:error] [pid 157386:tid 157610] [client 20.151.109.219:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/qk.php"] [unique_id "aoSCoU1jzAhYHVVT1WffjQAAAWg"] [Tue Aug 18 13:04:49.593604 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.36.136:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffjgAAAXQ"] [Tue Aug 18 13:04:49.635028 2026] [security2:error] [pid 157386:tid 157629] [client 20.226.36.136:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffjwAAAXs"] [Tue Aug 18 13:04:49.649485 2026] [security2:error] [pid 157386:tid 157558] [client 40.85.222.29:17548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/lddxs.php"] [unique_id "aoSCoU1jzAhYHVVT1WffkQAAATQ"] [Tue Aug 18 13:04:49.653073 2026] [security2:error] [pid 157386:tid 157570] [client 20.51.153.15:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vm.php"] [unique_id "aoSCoU1jzAhYHVVT1WffkgAAAUA"] [Tue Aug 18 13:04:49.667422 2026] [security2:error] [pid 157386:tid 157588] [client 20.79.204.6:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WfflAAAAVI"] [Tue Aug 18 13:04:49.680904 2026] [security2:error] [pid 157386:tid 157626] [client 20.226.36.136:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/first.php"] [unique_id "aoSCoU1jzAhYHVVT1WfflQAAAXg"] [Tue Aug 18 13:04:49.690767 2026] [security2:error] [pid 157386:tid 157536] [client 20.215.241.237:19032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mudancasmb.com.br"] [uri "/ajax.php"] [unique_id "aoSCoU1jzAhYHVVT1WfflgAAAR4"] [Tue Aug 18 13:04:49.707076 2026] [security2:error] [pid 157386:tid 157546] [client 20.226.36.136:65302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffmAAAASg"] [Tue Aug 18 13:04:49.726862 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.36.136:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffmQAAAX0"] [Tue Aug 18 13:04:49.808701 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.36.136:62152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffnAAAAUM"] [Tue Aug 18 13:04:49.827523 2026] [security2:error] [pid 157386:tid 157528] [client 20.226.36.136:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCoU1jzAhYHVVT1WffngAAARY"] [Tue Aug 18 13:04:49.841408 2026] [authz_core:error] [pid 157386:tid 157512] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:49.841882 2026] [authz_core:error] [pid 157386:tid 157512] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:49.842804 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:62168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffoAAAARk"] [Tue Aug 18 13:04:49.870526 2026] [security2:error] [pid 157386:tid 157535] [client 20.25.139.174:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffoQAAAR0"] [Tue Aug 18 13:04:49.904685 2026] [security2:error] [pid 157386:tid 157628] [client 68.221.73.131:40855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/wsomini.php"] [unique_id "aoSCoU1jzAhYHVVT1WffogAAAXo"] [Tue Aug 18 13:04:49.908565 2026] [security2:error] [pid 157386:tid 157583] [client 20.91.215.254:20244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-configs.php"] [unique_id "aoSCoU1jzAhYHVVT1WffpAAAAU0"] [Tue Aug 18 13:04:49.908591 2026] [security2:error] [pid 157386:tid 157608] [client 132.196.30.78:20090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/as.php"] [unique_id "aoSCoU1jzAhYHVVT1WffpQAAAWY"] [Tue Aug 18 13:04:49.923710 2026] [authz_core:error] [pid 157386:tid 157497] [remote 57.141.22.52:37670] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:49.924090 2026] [authz_core:error] [pid 157386:tid 157497] [remote 57.141.22.52:37670] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:49.933551 2026] [security2:error] [pid 157386:tid 157516] [client 20.226.36.136:65307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffpwAAAQo"] [Tue Aug 18 13:04:49.940259 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.100.201:23916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/spadex.php"] [unique_id "aoSCoU1jzAhYHVVT1WffqAAAAVQ"] [Tue Aug 18 13:04:49.943368 2026] [security2:error] [pid 157386:tid 157627] [client 4.232.151.198:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/abcde.php"] [unique_id "aoSCoU1jzAhYHVVT1WffqQAAAXk"] [Tue Aug 18 13:04:49.958999 2026] [security2:error] [pid 157386:tid 157524] [client 40.85.222.29:17538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/zjggu.php"] [unique_id "aoSCoU1jzAhYHVVT1WffqgAAARI"] [Tue Aug 18 13:04:49.961411 2026] [security2:error] [pid 157386:tid 157637] [client 20.51.153.15:8772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/eg.php"] [unique_id "aoSCoU1jzAhYHVVT1WffqwAAAYM"] [Tue Aug 18 13:04:49.968101 2026] [security2:error] [pid 157386:tid 157550] [client 20.1.169.243:11084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSCoU1jzAhYHVVT1WffrAAAASw"] [Tue Aug 18 13:04:49.984413 2026] [security2:error] [pid 157386:tid 157635] [client 213.35.127.232:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCoU1jzAhYHVVT1WffrQAAAYE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:49.987406 2026] [security2:error] [pid 157386:tid 157633] [client 20.171.51.14:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pw.php"] [unique_id "aoSCoU1jzAhYHVVT1WffrgAAAX8"] [Tue Aug 18 13:04:49.992954 2026] [security2:error] [pid 157386:tid 157603] [client 68.155.154.236:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCoU1jzAhYHVVT1WffrwAAAWE"] [Tue Aug 18 13:04:50.008174 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.36.136:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rsmoto.com.br"] [uri "/images/security.php"] [unique_id "aoSCok1jzAhYHVVT1WffsAAAAVk"] [Tue Aug 18 13:04:50.137694 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:50.137971 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:50.141619 2026] [security2:error] [pid 157386:tid 157561] [client 4.223.113.180:39738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/sf.php"] [unique_id "aoSCok1jzAhYHVVT1WfftQAAATc"] [Tue Aug 18 13:04:50.152572 2026] [security2:error] [pid 157386:tid 157574] [client 20.65.98.162:20707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCok1jzAhYHVVT1WfftgAAAUQ"] [Tue Aug 18 13:04:50.170953 2026] [security2:error] [pid 157386:tid 157585] [client 20.206.73.37:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/av.php"] [unique_id "aoSCok1jzAhYHVVT1WfftwAAAU8"] [Tue Aug 18 13:04:50.185530 2026] [security2:error] [pid 157386:tid 157527] [client 103.82.26.211:59859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCok1jzAhYHVVT1WffuAAAARU"] [Tue Aug 18 13:04:50.199310 2026] [security2:error] [pid 157386:tid 157621] [client 86.120.159.145:19135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCok1jzAhYHVVT1WffuQAAAXM"] [Tue Aug 18 13:04:50.199509 2026] [security2:error] [pid 157386:tid 157621] [client 86.120.159.145:19135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCok1jzAhYHVVT1WffuQAAAXM"] [Tue Aug 18 13:04:50.208296 2026] [security2:error] [pid 157386:tid 157566] [client 158.23.17.4:48434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fg.php"] [unique_id "aoSCok1jzAhYHVVT1WffugAAATw"] [Tue Aug 18 13:04:50.208481 2026] [security2:error] [pid 157386:tid 157541] [client 20.51.153.15:8819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/uk.php"] [unique_id "aoSCok1jzAhYHVVT1WffuwAAASM"] [Tue Aug 18 13:04:50.258303 2026] [security2:error] [pid 157386:tid 157556] [client 40.85.222.29:17540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCok1jzAhYHVVT1WffvQAAATI"] [Tue Aug 18 13:04:50.321578 2026] [security2:error] [pid 157386:tid 157615] [client 20.250.13.23:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/elp.php"] [unique_id "aoSCok1jzAhYHVVT1WffwAAAAW0"] [Tue Aug 18 13:04:50.431449 2026] [security2:error] [pid 157386:tid 157568] [client 20.25.139.174:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/vx.php"] [unique_id "aoSCok1jzAhYHVVT1WffxgAAAT4"] [Tue Aug 18 13:04:50.436407 2026] [security2:error] [pid 157386:tid 157530] [client 68.221.73.131:63050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alyauto.com.br"] [uri "/vr.php"] [unique_id "aoSCok1jzAhYHVVT1WffyAAAARg"] [Tue Aug 18 13:04:50.440130 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:50.440483 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:50.462513 2026] [security2:error] [pid 157386:tid 157576] [client 20.1.169.243:11236] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSCok1jzAhYHVVT1WffyQAAAUY"] [Tue Aug 18 13:04:50.462628 2026] [security2:error] [pid 157386:tid 157576] [client 20.1.169.243:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSCok1jzAhYHVVT1WffyQAAAUY"] [Tue Aug 18 13:04:50.494714 2026] [security2:error] [pid 157386:tid 157578] [client 20.65.98.162:20712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCok1jzAhYHVVT1WffygAAAUg"] [Tue Aug 18 13:04:50.549975 2026] [security2:error] [pid 157386:tid 157591] [client 20.91.215.254:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-post.php"] [unique_id "aoSCok1jzAhYHVVT1WffzAAAAVU"] [Tue Aug 18 13:04:50.552475 2026] [security2:error] [pid 157386:tid 157629] [client 40.85.222.29:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCok1jzAhYHVVT1WffzQAAAXs"] [Tue Aug 18 13:04:50.560976 2026] [security2:error] [pid 157386:tid 157548] [client 20.51.153.15:9206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/creds.php"] [unique_id "aoSCok1jzAhYHVVT1WffzgAAASo"] [Tue Aug 18 13:04:50.583851 2026] [security2:error] [pid 157386:tid 157588] [client 20.91.215.254:24587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCok1jzAhYHVVT1Wff0AAAAVI"] [Tue Aug 18 13:04:50.588658 2026] [security2:error] [pid 157386:tid 157639] [client 132.196.30.78:28025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/min.php"] [unique_id "aoSCok1jzAhYHVVT1Wff0QAAAYU"] [Tue Aug 18 13:04:50.648275 2026] [security2:error] [pid 157386:tid 157642] [client 4.232.151.198:7740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/anjay.php"] [unique_id "aoSCok1jzAhYHVVT1Wff0wAAAYg"] [Tue Aug 18 13:04:50.665326 2026] [security2:error] [pid 157386:tid 157631] [client 20.206.73.37:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCok1jzAhYHVVT1Wff1QAAAX0"] [Tue Aug 18 13:04:50.708678 2026] [security2:error] [pid 157386:tid 157599] [client 20.104.100.201:23947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSCok1jzAhYHVVT1Wff2QAAAV0"] [Tue Aug 18 13:04:50.739237 2026] [authz_core:error] [pid 157386:tid 157394] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:50.739518 2026] [authz_core:error] [pid 157386:tid 157394] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:50.763397 2026] [security2:error] [pid 157386:tid 157602] [client 168.62.48.100:4194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/index/function.php"] [unique_id "aoSCok1jzAhYHVVT1Wff2wAAAWA"] [Tue Aug 18 13:04:50.807939 2026] [security2:error] [pid 157386:tid 157625] [client 20.65.98.162:20608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/domvf.php"] [unique_id "aoSCok1jzAhYHVVT1Wff3QAAAXc"] [Tue Aug 18 13:04:50.811453 2026] [security2:error] [pid 157386:tid 157535] [client 20.51.153.15:8433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ho.php"] [unique_id "aoSCok1jzAhYHVVT1Wff3gAAAR0"] [Tue Aug 18 13:04:50.835104 2026] [security2:error] [pid 157386:tid 157573] [client 20.1.169.243:11128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCok1jzAhYHVVT1Wff4AAAAUM"] [Tue Aug 18 13:04:50.861573 2026] [security2:error] [pid 157386:tid 157516] [client 20.206.73.37:24519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/bengi.php"] [unique_id "aoSCok1jzAhYHVVT1Wff4gAAAQo"] [Tue Aug 18 13:04:50.861703 2026] [security2:error] [pid 157386:tid 157579] [client 40.85.222.29:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/kopyw.php"] [unique_id "aoSCok1jzAhYHVVT1Wff4QAAAUk"] [Tue Aug 18 13:04:50.896695 2026] [security2:error] [pid 157386:tid 157524] [client 20.171.51.14:44875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fn.php"] [unique_id "aoSCok1jzAhYHVVT1Wff5AAAARI"] [Tue Aug 18 13:04:50.973125 2026] [security2:error] [pid 157386:tid 157577] [client 158.23.17.4:40407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ve.php"] [unique_id "aoSCok1jzAhYHVVT1Wff6QAAAUc"] [Tue Aug 18 13:04:50.997782 2026] [security2:error] [pid 157386:tid 157518] [client 213.35.127.232:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCok1jzAhYHVVT1Wff6gAAAQw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:51.041294 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:51.041574 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:51.048922 2026] [security2:error] [pid 157386:tid 157534] [client 20.65.98.162:20730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSCo01jzAhYHVVT1Wff7AAAARw"] [Tue Aug 18 13:04:51.065590 2026] [security2:error] [pid 157386:tid 157520] [client 20.124.247.79:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCo01jzAhYHVVT1Wff8AAAAQ4"] [Tue Aug 18 13:04:51.096826 2026] [security2:error] [pid 157386:tid 157574] [client 20.206.73.37:1662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/h.php"] [unique_id "aoSCo01jzAhYHVVT1Wff8QAAAUQ"] [Tue Aug 18 13:04:51.141434 2026] [security2:error] [pid 157386:tid 157527] [client 40.85.222.29:17577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/zznmg.php"] [unique_id "aoSCo01jzAhYHVVT1Wff8wAAARU"] [Tue Aug 18 13:04:51.161782 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/mandrill.php"] [unique_id "aoSCo01jzAhYHVVT1Wff9AAAASA"] [Tue Aug 18 13:04:51.176714 2026] [security2:error] [pid 157386:tid 157606] [client 20.51.153.15:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/of.php"] [unique_id "aoSCo01jzAhYHVVT1Wff9QAAAWQ"] [Tue Aug 18 13:04:51.198569 2026] [security2:error] [pid 157386:tid 157561] [client 20.1.169.243:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/api.php"] [unique_id "aoSCo01jzAhYHVVT1Wff9gAAATc"] [Tue Aug 18 13:04:51.231016 2026] [security2:error] [pid 157386:tid 157615] [client 168.62.48.100:5503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCo01jzAhYHVVT1Wff-QAAAW0"] [Tue Aug 18 13:04:51.259983 2026] [security2:error] [pid 157386:tid 157609] [client 20.91.215.254:30100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSCo01jzAhYHVVT1Wff_AAAAWc"] [Tue Aug 18 13:04:51.274420 2026] [security2:error] [pid 157386:tid 157584] [client 20.91.215.254:24614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/0x.php"] [unique_id "aoSCo01jzAhYHVVT1Wff_QAAAU4"] [Tue Aug 18 13:04:51.305381 2026] [security2:error] [pid 157386:tid 157521] [client 20.65.98.162:20684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/gec.php"] [unique_id "aoSCo01jzAhYHVVT1Wff_wAAAQ8"] [Tue Aug 18 13:04:51.329020 2026] [security2:error] [pid 157386:tid 157630] [client 4.223.113.180:39724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/file56.php"] [unique_id "aoSCo01jzAhYHVVT1WfgAgAAAXw"] [Tue Aug 18 13:04:51.341776 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:51.342040 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:51.372041 2026] [security2:error] [pid 157386:tid 157553] [client 20.250.13.23:21103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/admin.php"] [unique_id "aoSCo01jzAhYHVVT1WfgBAAAAS8"] [Tue Aug 18 13:04:51.459549 2026] [security2:error] [pid 157386:tid 157558] [client 40.85.222.29:17562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCo01jzAhYHVVT1WfgCQAAATQ"] [Tue Aug 18 13:04:51.504980 2026] [security2:error] [pid 157386:tid 157642] [client 68.155.154.236:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nasbeauty.com.br"] [uri "/images/security.php"] [unique_id "aoSCo01jzAhYHVVT1WfgDgAAAYg"] [Tue Aug 18 13:04:51.505020 2026] [security2:error] [pid 157386:tid 157565] [client 4.232.151.198:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "aoSCo01jzAhYHVVT1WfgDQAAATs"] [Tue Aug 18 13:04:51.515894 2026] [security2:error] [pid 157386:tid 157532] [client 103.82.26.211:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bjagricola.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCo01jzAhYHVVT1WfgDwAAARo"] [Tue Aug 18 13:04:51.556449 2026] [security2:error] [pid 157386:tid 157545] [client 20.65.98.162:20674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/sky.php"] [unique_id "aoSCo01jzAhYHVVT1WfgEwAAASc"] [Tue Aug 18 13:04:51.560918 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:10759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSCo01jzAhYHVVT1WfgFAAAARA"] [Tue Aug 18 13:04:51.562709 2026] [security2:error] [pid 157386:tid 157542] [client 20.51.153.15:8798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/bu.php"] [unique_id "aoSCo01jzAhYHVVT1WfgFQAAASQ"] [Tue Aug 18 13:04:51.587304 2026] [security2:error] [pid 157386:tid 157599] [client 132.196.30.78:19853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/php8.php"] [unique_id "aoSCo01jzAhYHVVT1WfgFwAAAV0"] [Tue Aug 18 13:04:51.615597 2026] [security2:error] [pid 157386:tid 157640] [client 20.25.139.174:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wap.php"] [unique_id "aoSCo01jzAhYHVVT1WfgGAAAAYY"] [Tue Aug 18 13:04:51.646737 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:51.647033 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:51.653675 2026] [security2:error] [pid 157386:tid 157604] [client 158.23.17.4:7203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ia.php"] [unique_id "aoSCo01jzAhYHVVT1WfgGgAAAWI"] [Tue Aug 18 13:04:51.659415 2026] [security2:error] [pid 157386:tid 157528] [client 20.171.51.14:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kf.php"] [unique_id "aoSCo01jzAhYHVVT1WfgGwAAARY"] [Tue Aug 18 13:04:51.671119 2026] [security2:error] [pid 157386:tid 157620] [client 20.104.100.201:23987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/srontol.php"] [unique_id "aoSCo01jzAhYHVVT1WfgHQAAAXI"] [Tue Aug 18 13:04:51.781265 2026] [security2:error] [pid 157386:tid 157549] [client 20.151.109.219:10564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCo01jzAhYHVVT1WfgIAAAASs"] [Tue Aug 18 13:04:51.809629 2026] [security2:error] [pid 157386:tid 157572] [client 40.85.222.29:17578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCo01jzAhYHVVT1WfgIgAAAUI"] [Tue Aug 18 13:04:51.832669 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:20825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/main.php"] [unique_id "aoSCo01jzAhYHVVT1WfgIwAAAWE"] [Tue Aug 18 13:04:51.851433 2026] [security2:error] [pid 157386:tid 157595] [client 20.65.98.162:20676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/sixxis.php"] [unique_id "aoSCo01jzAhYHVVT1WfgJQAAAVk"] [Tue Aug 18 13:04:51.897275 2026] [security2:error] [pid 157386:tid 157643] [client 4.232.151.198:11575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wpc.php"] [unique_id "aoSCo01jzAhYHVVT1WfgKAAAAYk"] [Tue Aug 18 13:04:51.928397 2026] [security2:error] [pid 157386:tid 157636] [client 20.1.169.243:11112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/db-status.php"] [unique_id "aoSCo01jzAhYHVVT1WfgKgAAAYI"] [Tue Aug 18 13:04:51.948504 2026] [authz_core:error] [pid 157386:tid 157398] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:51.948767 2026] [authz_core:error] [pid 157386:tid 157398] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:51.949963 2026] [security2:error] [pid 157386:tid 157537] [client 20.91.215.254:21463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/222.php"] [unique_id "aoSCo01jzAhYHVVT1WfgLQAAAR8"] [Tue Aug 18 13:04:51.956196 2026] [security2:error] [pid 157386:tid 157608] [client 20.91.215.254:20246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSCo01jzAhYHVVT1WfgLgAAAWY"] [Tue Aug 18 13:04:52.019486 2026] [security2:error] [pid 157386:tid 157625] [client 213.35.127.232:62366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgNQAAAXc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:52.104384 2026] [security2:error] [pid 157386:tid 157589] [client 20.65.98.162:20622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/yj09.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgOgAAAVM"] [Tue Aug 18 13:04:52.147304 2026] [security2:error] [pid 157386:tid 157621] [client 132.196.30.78:19890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgPQAAAXM"] [Tue Aug 18 13:04:52.155396 2026] [security2:error] [pid 157386:tid 157585] [client 40.85.222.29:6745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/oivcl.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgPgAAAU8"] [Tue Aug 18 13:04:52.167118 2026] [security2:error] [pid 157386:tid 157601] [client 4.232.151.198:22174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/publick.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgPwAAAV8"] [Tue Aug 18 13:04:52.215717 2026] [security2:error] [pid 157386:tid 157571] [client 20.25.139.174:4686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgQAAAAUE"] [Tue Aug 18 13:04:52.246800 2026] [authz_core:error] [pid 157386:tid 157434] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:52.247086 2026] [authz_core:error] [pid 157386:tid 157434] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:52.265866 2026] [security2:error] [pid 157386:tid 157586] [client 20.79.204.6:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ws83.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgQwAAAVA"] [Tue Aug 18 13:04:52.301380 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:11301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgRQAAATk"] [Tue Aug 18 13:04:52.393930 2026] [security2:error] [pid 157386:tid 157591] [client 20.104.100.201:23997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/file5.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgSwAAAVU"] [Tue Aug 18 13:04:52.425473 2026] [security2:error] [pid 157386:tid 157584] [client 4.223.113.180:41379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/2.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgTQAAAU4"] [Tue Aug 18 13:04:52.445078 2026] [security2:error] [pid 157386:tid 157611] [client 40.85.222.29:17589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/zugvi.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgUAAAAWk"] [Tue Aug 18 13:04:52.471864 2026] [security2:error] [pid 157386:tid 157622] [client 20.206.73.37:18965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/ano.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgUgAAAXQ"] [Tue Aug 18 13:04:52.481060 2026] [security2:error] [pid 157386:tid 157532] [client 20.51.153.15:8765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/rn.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgUwAAARo"] [Tue Aug 18 13:04:52.512774 2026] [security2:error] [pid 157386:tid 157583] [client 49.13.130.29:44968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSCo01jzAhYHVVT1WfgLwAAAU0"], referer: http://www.webeb.com.br [Tue Aug 18 13:04:52.544648 2026] [security2:error] [pid 157386:tid 157599] [client 20.65.98.162:20678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/k.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgWAAAAV0"] [Tue Aug 18 13:04:52.592252 2026] [security2:error] [pid 157386:tid 157613] [client 20.91.215.254:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/aa.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgWgAAAWs"] [Tue Aug 18 13:04:52.593434 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:27772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/payout.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgWwAAAXY"] [Tue Aug 18 13:04:52.604566 2026] [security2:error] [pid 157386:tid 157620] [client 20.171.51.14:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/su.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgXAAAAXI"] [Tue Aug 18 13:04:52.610139 2026] [security2:error] [pid 157386:tid 157628] [client 49.37.150.8:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgTwAAAXo"] [Tue Aug 18 13:04:52.610299 2026] [security2:error] [pid 157386:tid 157628] [client 49.37.150.8:60971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgTwAAAXo"] [Tue Aug 18 13:04:52.610435 2026] [security2:error] [pid 157386:tid 157569] [client 158.23.17.4:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kn.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgXQAAAT8"] [Tue Aug 18 13:04:52.641871 2026] [security2:error] [pid 157386:tid 157516] [client 168.62.48.100:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgYAAAAQo"] [Tue Aug 18 13:04:52.664048 2026] [security2:error] [pid 157386:tid 157587] [client 20.1.169.243:11119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jomaconstrutora.com.br"] [uri "/wp-content/home.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgYQAAAVE"] [Tue Aug 18 13:04:52.676919 2026] [security2:error] [pid 157386:tid 157557] [client 20.91.215.254:15633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgYgAAATM"] [Tue Aug 18 13:04:52.676948 2026] [security2:error] [pid 157386:tid 157642] [client 132.196.30.78:28020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/222.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgYwAAAYg"] [Tue Aug 18 13:04:52.717552 2026] [security2:error] [pid 157386:tid 157603] [client 20.51.153.15:8440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ut.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgZwAAAWE"] [Tue Aug 18 13:04:52.757733 2026] [security2:error] [pid 157386:tid 157595] [client 68.221.73.131:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/images.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgaQAAAVk"] [Tue Aug 18 13:04:52.769022 2026] [security2:error] [pid 157386:tid 157643] [client 40.85.222.29:17598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wsrer.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgbAAAAYk"] [Tue Aug 18 13:04:52.782999 2026] [security2:error] [pid 157386:tid 157547] [client 20.25.139.174:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/bgymj.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgbQAAASk"] [Tue Aug 18 13:04:52.832556 2026] [security2:error] [pid 157386:tid 157535] [client 4.232.151.198:24235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/cs.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgbwAAAR0"] [Tue Aug 18 13:04:52.837242 2026] [security2:error] [pid 157386:tid 157631] [client 20.65.98.162:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/w.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgcAAAAX0"] [Tue Aug 18 13:04:52.853324 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:52.853782 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:52.871515 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fs.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgcgAAAVc"] [Tue Aug 18 13:04:52.942908 2026] [security2:error] [pid 157386:tid 157564] [client 20.171.51.14:18643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-key.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgeQAAATo"] [Tue Aug 18 13:04:52.981681 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:23828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/yup.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgewAAARg"] [Tue Aug 18 13:04:52.988847 2026] [security2:error] [pid 157386:tid 157563] [client 20.124.247.79:16414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCpE1jzAhYHVVT1WfgfAAAATk"] [Tue Aug 18 13:04:53.029764 2026] [security2:error] [pid 157386:tid 157612] [client 20.51.153.15:8728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/eh.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgiAAAAWo"] [Tue Aug 18 13:04:53.032935 2026] [security2:error] [pid 157386:tid 157562] [client 213.35.127.232:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgiQAAATg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:53.057218 2026] [security2:error] [pid 157386:tid 157597] [client 40.85.222.29:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgjAAAAVs"] [Tue Aug 18 13:04:53.083706 2026] [security2:error] [pid 157386:tid 157536] [client 20.65.98.162:20708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/fpwch.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgmAAAAR4"] [Tue Aug 18 13:04:53.137254 2026] [security2:error] [pid 157386:tid 157609] [client 20.79.204.6:10151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/atex1.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgwwAAAWc"] [Tue Aug 18 13:04:53.234993 2026] [security2:error] [pid 157386:tid 157549] [client 40.74.65.169:16282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/sf.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgywAAASs"] [Tue Aug 18 13:04:53.266950 2026] [security2:error] [pid 157386:tid 157558] [client 20.91.215.254:21453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/abcd.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgzgAAATQ"] [Tue Aug 18 13:04:53.280121 2026] [security2:error] [pid 157386:tid 157550] [client 20.51.153.15:8407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ad.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg0AAAASw"] [Tue Aug 18 13:04:53.315751 2026] [security2:error] [pid 157386:tid 157617] [client 132.196.30.78:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg0gAAAW8"] [Tue Aug 18 13:04:53.339966 2026] [security2:error] [pid 157386:tid 157643] [client 20.65.98.162:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg1AAAAYk"] [Tue Aug 18 13:04:53.360481 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:56020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/Mailgun.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg1QAAAVY"] [Tue Aug 18 13:04:53.364460 2026] [security2:error] [pid 157386:tid 157622] [client 74.7.244.41:55996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lavobrasil.com.br"] [uri "/index.php"] [unique_id "aoSCpU1jzAhYHVVT1WfgygABdAc"] [Tue Aug 18 13:04:53.367309 2026] [security2:error] [pid 157386:tid 157582] [client 20.91.215.254:15662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/cjfuns.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg1gAAAUw"] [Tue Aug 18 13:04:53.382053 2026] [security2:error] [pid 157386:tid 157600] [client 40.85.222.29:17574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/yxijx.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg1wAAAV4"] [Tue Aug 18 13:04:53.385069 2026] [security2:error] [pid 157386:tid 157516] [client 20.25.139.174:4647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/aa.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg2AAAAQo"] [Tue Aug 18 13:04:53.457301 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:53.457737 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:53.477219 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.100.201:23878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg3QAAAWA"] [Tue Aug 18 13:04:53.490642 2026] [security2:error] [pid 157386:tid 157541] [client 4.232.151.198:42972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/1nt3pqdk.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg3wAAASM"] [Tue Aug 18 13:04:53.534758 2026] [security2:error] [pid 157386:tid 157635] [client 4.232.151.198:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/fone1.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg4gAAAYE"] [Tue Aug 18 13:04:53.544362 2026] [security2:error] [pid 157386:tid 157539] [client 20.251.48.93:46287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/aa.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg4wAAASE"] [Tue Aug 18 13:04:53.576389 2026] [security2:error] [pid 157386:tid 157565] [client 149.34.210.141:55317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg5AAAATs"] [Tue Aug 18 13:04:53.576483 2026] [security2:error] [pid 157386:tid 157565] [client 149.34.210.141:55317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg5AAAATs"] [Tue Aug 18 13:04:53.583962 2026] [security2:error] [pid 157386:tid 157560] [client 20.65.98.162:20693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/blurbs.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg7QAAATY"] [Tue Aug 18 13:04:53.602054 2026] [security2:error] [pid 157386:tid 157416] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCpU1jzAhYHVVT1Wfg7gABMB0"] [Tue Aug 18 13:04:53.615113 2026] [security2:error] [pid 157386:tid 157586] [client 20.51.153.15:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/vd.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg8AAAAVA"] [Tue Aug 18 13:04:53.616472 2026] [security2:error] [pid 157386:tid 157568] [client 20.171.51.14:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gg.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg8QAAAT4"] [Tue Aug 18 13:04:53.634204 2026] [security2:error] [pid 157386:tid 157444] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCpU1jzAhYHVVT1Wfg8gABSzk"] [Tue Aug 18 13:04:53.641869 2026] [security2:error] [pid 157386:tid 157519] [client 158.23.17.4:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wm.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg8wAAAQ0"] [Tue Aug 18 13:04:53.672278 2026] [security2:error] [pid 157386:tid 157570] [client 40.85.222.29:17570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCpU1jzAhYHVVT1Wfg_QAAAUA"] [Tue Aug 18 13:04:53.803778 2026] [security2:error] [pid 157386:tid 157448] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/config/.env.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhDgABFj0"] [Tue Aug 18 13:04:53.846452 2026] [security2:error] [pid 157386:tid 157465] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCpU1jzAhYHVVT1WfhDwABFU4"] [Tue Aug 18 13:04:53.891534 2026] [security2:error] [pid 157386:tid 157550] [client 20.65.98.162:20714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/100.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhIAAAASw"] [Tue Aug 18 13:04:53.898876 2026] [security2:error] [pid 157386:tid 157531] [client 20.91.215.254:24603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/admin.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhIQAAARk"] [Tue Aug 18 13:04:53.917588 2026] [security2:error] [pid 157386:tid 157583] [client 20.25.139.174:4524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhIgAAAU0"] [Tue Aug 18 13:04:53.937341 2026] [security2:error] [pid 157386:tid 157617] [client 20.51.153.15:9106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/56.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhJwAAAW8"] [Tue Aug 18 13:04:53.950942 2026] [security2:error] [pid 157386:tid 157595] [client 168.62.48.100:5587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pousadaemarraialdocabo.net.br"] [uri "/images/security.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhLQAAAVk"] [Tue Aug 18 13:04:53.976692 2026] [security2:error] [pid 157386:tid 157612] [client 20.250.13.23:48561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/classwithtostring.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhLgAAAWo"] [Tue Aug 18 13:04:53.976779 2026] [security2:error] [pid 157386:tid 157559] [client 20.79.204.6:9292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/class-t.api.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhLwAAATU"] [Tue Aug 18 13:04:53.981507 2026] [security2:error] [pid 157386:tid 157520] [client 40.85.222.29:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/jrpga.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhMQAAAQ4"] [Tue Aug 18 13:04:53.985642 2026] [security2:error] [pid 157386:tid 157624] [client 132.196.30.78:28028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/info.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhMgAAAXY"] [Tue Aug 18 13:04:53.994789 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:27760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/rb.php"] [unique_id "aoSCpU1jzAhYHVVT1WfhMwAAAVY"] [Tue Aug 18 13:04:54.002227 2026] [security2:error] [pid 157386:tid 157603] [client 102.213.179.104:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhNgAAAWE"] [Tue Aug 18 13:04:54.002352 2026] [security2:error] [pid 157386:tid 157603] [client 102.213.179.104:62413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhNgAAAWE"] [Tue Aug 18 13:04:54.008037 2026] [security2:error] [pid 157386:tid 157622] [client 20.104.100.201:24062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-the.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhNwAAAXQ"] [Tue Aug 18 13:04:54.040088 2026] [security2:error] [pid 157386:tid 157502] [remote 185.6.9.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.9.6.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhOQABK3M"] [Tue Aug 18 13:04:54.060423 2026] [security2:error] [pid 157386:tid 157638] [client 213.35.127.232:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhOgAAAYQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:54.096748 2026] [security2:error] [pid 157386:tid 157558] [client 20.91.215.254:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhPQAAATQ"] [Tue Aug 18 13:04:54.130630 2026] [security2:error] [pid 157386:tid 157572] [client 4.232.151.198:22153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/unknown.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhPwAAAUI"] [Tue Aug 18 13:04:54.197958 2026] [security2:error] [pid 157386:tid 157594] [client 20.171.51.14:18636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gi.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhQQAAAVg"] [Tue Aug 18 13:04:54.212879 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.98.162:20627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/ccc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhRQAAASM"] [Tue Aug 18 13:04:54.212973 2026] [security2:error] [pid 157386:tid 157391] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/config.php.bak"] [unique_id "aoSCpk1jzAhYHVVT1WfhRAABcAQ"] [Tue Aug 18 13:04:54.222682 2026] [security2:error] [pid 157386:tid 157485] [remote 136.110.27.48:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.predilletoparquedez.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCpk1jzAhYHVVT1WfhRwABc2I"] [Tue Aug 18 13:04:54.226122 2026] [authz_core:error] [pid 157386:tid 157484] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:54.226397 2026] [authz_core:error] [pid 157386:tid 157484] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:54.321253 2026] [autoindex:error] [pid 157386:tid 157610] [client 20.119.58.187:2048] AH01276: Cannot serve directory /home1/hotelvip/public_html/www.pousadaclassea.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:04:54.347120 2026] [security2:error] [pid 157386:tid 157563] [client 158.23.17.4:56550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ac.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhUAAAATk"] [Tue Aug 18 13:04:54.394800 2026] [security2:error] [pid 157386:tid 157607] [client 40.85.222.29:17594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhUgAAAWU"] [Tue Aug 18 13:04:54.411990 2026] [security2:error] [pid 157386:tid 157512] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhUwABOH0"] [Tue Aug 18 13:04:54.412145 2026] [security2:error] [pid 157386:tid 157562] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhUwABOH0"] [Tue Aug 18 13:04:54.425249 2026] [security2:error] [pid 157386:tid 157570] [client 20.104.100.201:23859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhVAAAAUA"] [Tue Aug 18 13:04:54.478556 2026] [security2:error] [pid 157386:tid 157524] [client 20.65.98.162:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/get.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhVgAAARI"] [Tue Aug 18 13:04:54.496700 2026] [security2:error] [pid 157386:tid 157521] [client 20.25.139.174:4608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/bolt.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhVwAAAQ8"] [Tue Aug 18 13:04:54.519040 2026] [security2:error] [pid 157386:tid 157545] [client 157.20.138.62:59887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhWAAAASc"] [Tue Aug 18 13:04:54.519159 2026] [security2:error] [pid 157386:tid 157545] [client 157.20.138.62:59887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhWAAAASc"] [Tue Aug 18 13:04:54.595775 2026] [security2:error] [pid 157386:tid 157599] [client 213.202.253.4:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/txets.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhXwAAAV0"], referer: www.google.com [Tue Aug 18 13:04:54.679963 2026] [security2:error] [pid 157386:tid 157542] [client 40.85.222.29:17550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/nwwha.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhZQAAASQ"] [Tue Aug 18 13:04:54.745058 2026] [security2:error] [pid 157386:tid 157614] [client 20.65.98.162:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/images.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhaAAAAWw"] [Tue Aug 18 13:04:54.761312 2026] [security2:error] [pid 157386:tid 157561] [client 20.171.51.14:13432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pz.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhagAAATc"] [Tue Aug 18 13:04:54.764664 2026] [security2:error] [pid 157386:tid 157635] [client 4.232.151.198:37064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ncx.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhawAAAYE"] [Tue Aug 18 13:04:54.769271 2026] [security2:error] [pid 157386:tid 157531] [client 20.91.215.254:24632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhbAAAARk"] [Tue Aug 18 13:04:54.775100 2026] [security2:error] [pid 157386:tid 157566] [client 20.91.215.254:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhbQAAATw"] [Tue Aug 18 13:04:54.792282 2026] [security2:error] [pid 157386:tid 157604] [client 132.196.30.78:28002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/a.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhbwAAAWI"] [Tue Aug 18 13:04:54.832440 2026] [authz_core:error] [pid 157386:tid 157418] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:54.832705 2026] [authz_core:error] [pid 157386:tid 157418] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:54.863349 2026] [security2:error] [pid 157386:tid 157534] [client 20.124.247.79:16498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhdQAAARw"] [Tue Aug 18 13:04:54.904457 2026] [security2:error] [pid 157386:tid 157535] [client 68.221.73.131:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/ops.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhegAAAR0"] [Tue Aug 18 13:04:54.982198 2026] [security2:error] [pid 157386:tid 157637] [client 40.85.222.29:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/opsqt.php"] [unique_id "aoSCpk1jzAhYHVVT1WfhgAAAAYM"] [Tue Aug 18 13:04:55.056732 2026] [security2:error] [pid 157386:tid 157540] [client 178.153.171.161:54838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhhgAAASI"] [Tue Aug 18 13:04:55.056872 2026] [security2:error] [pid 157386:tid 157540] [client 178.153.171.161:54838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhhgAAASI"] [Tue Aug 18 13:04:55.072074 2026] [security2:error] [pid 157386:tid 157642] [client 213.35.127.232:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCp01jzAhYHVVT1WfhiAAAAYg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:55.117936 2026] [security2:error] [pid 157386:tid 157615] [client 20.25.139.174:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/bthil.php"] [unique_id "aoSCp01jzAhYHVVT1WfhkgAAAW0"] [Tue Aug 18 13:04:55.126922 2026] [security2:error] [pid 157386:tid 157563] [client 20.151.109.219:17632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/37.php"] [unique_id "aoSCp01jzAhYHVVT1WfhlAAAATk"] [Tue Aug 18 13:04:55.135620 2026] [authz_core:error] [pid 157386:tid 157438] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:55.136117 2026] [authz_core:error] [pid 157386:tid 157438] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:55.146526 2026] [security2:error] [pid 157386:tid 157407] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env"] [unique_id "aoSCp01jzAhYHVVT1WfhmQABcRQ"] [Tue Aug 18 13:04:55.168532 2026] [security2:error] [pid 157386:tid 157587] [client 20.65.98.162:20621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/alls.php"] [unique_id "aoSCp01jzAhYHVVT1WfhngAAAVE"] [Tue Aug 18 13:04:55.223634 2026] [security2:error] [pid 157386:tid 157553] [client 20.251.48.93:42710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/img.php"] [unique_id "aoSCp01jzAhYHVVT1WfhoAAAAS8"] [Tue Aug 18 13:04:55.243863 2026] [security2:error] [pid 157386:tid 157519] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhnwABDTE"] [Tue Aug 18 13:04:55.261647 2026] [security2:error] [pid 157386:tid 157588] [client 40.85.222.29:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCp01jzAhYHVVT1WfhowAAAVI"] [Tue Aug 18 13:04:55.283505 2026] [security2:error] [pid 157386:tid 157521] [client 4.232.151.198:7686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-json-ajax-session.php"] [unique_id "aoSCp01jzAhYHVVT1WfhpQAAAQ8"] [Tue Aug 18 13:04:55.305290 2026] [security2:error] [pid 157386:tid 157584] [client 20.104.100.201:24006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/xwpg.php"] [unique_id "aoSCp01jzAhYHVVT1WfhpwAAAU4"] [Tue Aug 18 13:04:55.309297 2026] [security2:error] [pid 157386:tid 157538] [client 114.119.140.102:41141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "telesaopedro.com.br"] [uri "/centro-educacional-tia-leninha-tile"] [unique_id "aoSCp01jzAhYHVVT1WfhqQAAASA"], referer: https://telesaopedro.com.br/centro-educacional-tia-leninha-tile/ [Tue Aug 18 13:04:55.350536 2026] [security2:error] [pid 157386:tid 157639] [client 20.151.109.219:10599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/oauth.php"] [unique_id "aoSCp01jzAhYHVVT1WfhrgAAAYU"] [Tue Aug 18 13:04:55.401947 2026] [security2:error] [pid 157386:tid 157586] [client 20.91.215.254:24594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/akc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhsAAAAVA"] [Tue Aug 18 13:04:55.403517 2026] [security2:error] [pid 157386:tid 157620] [client 20.206.73.37:24546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/file2.php"] [unique_id "aoSCp01jzAhYHVVT1WfhsQAAAXI"] [Tue Aug 18 13:04:55.434997 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:55.435462 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:55.452698 2026] [security2:error] [pid 157386:tid 157516] [client 20.91.215.254:15641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/import.php"] [unique_id "aoSCp01jzAhYHVVT1WfhtAAAAQo"] [Tue Aug 18 13:04:55.454907 2026] [security2:error] [pid 157386:tid 157562] [client 132.196.30.78:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/chosen.php"] [unique_id "aoSCp01jzAhYHVVT1WfhtQAAATg"] [Tue Aug 18 13:04:55.484864 2026] [security2:error] [pid 157386:tid 157632] [client 20.65.98.162:20699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/coffexium.php"] [unique_id "aoSCp01jzAhYHVVT1WfhtwAAAX4"] [Tue Aug 18 13:04:55.505537 2026] [security2:error] [pid 157386:tid 157566] [client 20.171.51.14:38727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kk.php"] [unique_id "aoSCp01jzAhYHVVT1WfhuAAAATw"] [Tue Aug 18 13:04:55.551244 2026] [security2:error] [pid 157386:tid 157577] [client 158.23.17.4:25354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/yz.php"] [unique_id "aoSCp01jzAhYHVVT1WfhuwAAAUc"] [Tue Aug 18 13:04:55.561456 2026] [security2:error] [pid 157386:tid 157643] [client 40.85.222.29:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCp01jzAhYHVVT1WfhvAAAAYk"] [Tue Aug 18 13:04:55.567009 2026] [security2:error] [pid 157386:tid 157580] [client 138.36.100.162:41750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhvQAAAUo"] [Tue Aug 18 13:04:55.628028 2026] [security2:error] [pid 157386:tid 157592] [client 20.206.73.37:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/media.php"] [unique_id "aoSCp01jzAhYHVVT1WfhxAAAAVY"] [Tue Aug 18 13:04:55.674656 2026] [lsapi:warn] [pid 157386:tid 157451] [remote 57.141.22.120:43928] [host rafaelgallassini.com.br] Backend log: PHP Warning: file_put_contents(): Only 65536 of 88951 bytes written, possibly out of free disk space in /home4/rafaelgalla/public_html/wp-content/plugins/tenweb-speed-optimizer/includes/WebPageCache/OptimizerWebPageCache.php on line 205\n [Tue Aug 18 13:04:55.728958 2026] [security2:error] [pid 157386:tid 157631] [client 20.151.109.219:45847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/md.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh1AAAAX0"] [Tue Aug 18 13:04:55.732752 2026] [security2:error] [pid 157386:tid 157535] [client 40.74.65.169:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/k.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh1QAAAR0"] [Tue Aug 18 13:04:55.733430 2026] [security2:error] [pid 157386:tid 157627] [client 20.250.13.23:48540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/666.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh1gAAAXk"] [Tue Aug 18 13:04:55.735353 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:55.735833 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:55.768596 2026] [security2:error] [pid 157386:tid 157590] [client 20.65.98.162:20613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/red.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh2AAAAVQ"] [Tue Aug 18 13:04:55.786420 2026] [security2:error] [pid 157386:tid 157557] [client 4.223.113.180:41375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh2QAAATM"] [Tue Aug 18 13:04:55.876068 2026] [security2:error] [pid 157386:tid 157621] [client 40.85.222.29:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh4AAAAXM"] [Tue Aug 18 13:04:55.877351 2026] [security2:error] [pid 157386:tid 157617] [client 20.79.204.6:9666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/w.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh4QAAAW8"] [Tue Aug 18 13:04:55.924694 2026] [security2:error] [pid 157386:tid 157626] [client 103.120.71.157:64624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh5AAAAXg"] [Tue Aug 18 13:04:55.924846 2026] [security2:error] [pid 157386:tid 157626] [client 103.120.71.157:64624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh5AAAAXg"] [Tue Aug 18 13:04:55.967795 2026] [security2:error] [pid 157386:tid 157540] [client 20.206.73.37:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/admin.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh5wAAASI"] [Tue Aug 18 13:04:55.984220 2026] [security2:error] [pid 157386:tid 157572] [client 4.232.151.198:25233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/litespeed.php"] [unique_id "aoSCp01jzAhYHVVT1Wfh6QAAAUI"] [Tue Aug 18 13:04:56.003844 2026] [security2:error] [pid 157386:tid 157580] [client 138.36.100.162:41750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCp01jzAhYHVVT1WfhvQAAAUo"] [Tue Aug 18 13:04:56.031269 2026] [security2:error] [pid 157386:tid 157602] [client 20.91.215.254:24628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/buy.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh6wAAAWA"] [Tue Aug 18 13:04:56.034041 2026] [authz_core:error] [pid 157386:tid 157498] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:56.034325 2026] [authz_core:error] [pid 157386:tid 157498] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:56.089258 2026] [security2:error] [pid 157386:tid 157605] [client 20.171.51.14:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh8QAAAWM"] [Tue Aug 18 13:04:56.089261 2026] [security2:error] [pid 157386:tid 157623] [client 213.35.127.232:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh8gAAAXU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:56.177620 2026] [security2:error] [pid 157386:tid 157539] [client 20.91.215.254:8117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/cropper.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh9AAAASE"] [Tue Aug 18 13:04:56.186756 2026] [security2:error] [pid 157386:tid 157591] [client 40.85.222.29:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh9QAAAVU"] [Tue Aug 18 13:04:56.205553 2026] [security2:error] [pid 157386:tid 157550] [client 158.23.17.4:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kj.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh9wAAASw"] [Tue Aug 18 13:04:56.225104 2026] [security2:error] [pid 157386:tid 157641] [client 132.196.30.78:28006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh-AAAAYc"] [Tue Aug 18 13:04:56.228645 2026] [security2:error] [pid 157386:tid 157584] [client 20.104.100.201:23937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/dex.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh-QAAAU4"] [Tue Aug 18 13:04:56.235567 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:51721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/timeclock.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh-gAAAXc"] [Tue Aug 18 13:04:56.263035 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/x.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh_AAAAQ0"] [Tue Aug 18 13:04:56.306104 2026] [security2:error] [pid 157386:tid 157639] [client 68.221.73.131:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/coffexium.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh_gAAAYU"] [Tue Aug 18 13:04:56.311886 2026] [security2:error] [pid 157386:tid 157463] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh_wABO0w"] [Tue Aug 18 13:04:56.312277 2026] [security2:error] [pid 157386:tid 157565] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqE1jzAhYHVVT1Wfh_wABO0w"] [Tue Aug 18 13:04:56.410432 2026] [security2:error] [pid 157386:tid 157492] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiBwABQ2k"], referer: https://transevang.com.br/login [Tue Aug 18 13:04:56.467588 2026] [security2:error] [pid 157386:tid 157583] [client 20.65.98.162:20691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiDgAAAU0"] [Tue Aug 18 13:04:56.474119 2026] [security2:error] [pid 157386:tid 157595] [client 40.85.222.29:17563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiEAAAAVk"] [Tue Aug 18 13:04:56.494068 2026] [security2:error] [pid 157386:tid 157503] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.backup"] [unique_id "aoSCqE1jzAhYHVVT1WfiEQABQ3Q"] [Tue Aug 18 13:04:56.502149 2026] [security2:error] [pid 157386:tid 157472] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.old"] [unique_id "aoSCqE1jzAhYHVVT1WfiEgABQ1U"] [Tue Aug 18 13:04:56.519422 2026] [security2:error] [pid 157386:tid 157509] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.bak"] [unique_id "aoSCqE1jzAhYHVVT1WfiFAABQ3o"] [Tue Aug 18 13:04:56.588008 2026] [security2:error] [pid 157386:tid 157613] [client 20.171.51.14:18663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/dg.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiGQAAAWs"] [Tue Aug 18 13:04:56.602019 2026] [security2:error] [pid 157386:tid 157547] [client 20.124.247.79:16466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/sky.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiGgAAASk"] [Tue Aug 18 13:04:56.614347 2026] [security2:error] [pid 157386:tid 157518] [client 4.232.151.198:25270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/un2.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiGwAAAQw"] [Tue Aug 18 13:04:56.638583 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:56.639077 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:56.673800 2026] [security2:error] [pid 157386:tid 157561] [client 20.206.73.37:30606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/ai.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiHwAAATc"] [Tue Aug 18 13:04:56.683584 2026] [security2:error] [pid 157386:tid 157577] [client 20.91.215.254:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/cong.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiIAAAAUc"] [Tue Aug 18 13:04:56.791701 2026] [security2:error] [pid 157386:tid 157564] [client 40.85.222.29:17544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiIwAAATo"] [Tue Aug 18 13:04:56.797507 2026] [security2:error] [pid 157386:tid 157541] [client 168.62.48.100:4151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiJAAAASM"] [Tue Aug 18 13:04:56.816114 2026] [security2:error] [pid 157386:tid 157624] [client 132.196.30.78:19894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/vx.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiKAAAAXY"] [Tue Aug 18 13:04:56.830475 2026] [security2:error] [pid 157386:tid 157603] [client 20.91.215.254:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiKQAAAWE"] [Tue Aug 18 13:04:56.850637 2026] [security2:error] [pid 157386:tid 157574] [client 20.25.139.174:4652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/index/function.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiKgAAAUQ"] [Tue Aug 18 13:04:56.853782 2026] [security2:error] [pid 157386:tid 157494] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/api/.env"] [unique_id "aoSCqE1jzAhYHVVT1WfiLAABiGs"] [Tue Aug 18 13:04:56.883976 2026] [security2:error] [pid 157386:tid 157580] [client 20.65.98.162:20701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/admin.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiMAAAAUo"] [Tue Aug 18 13:04:56.916874 2026] [security2:error] [pid 157386:tid 157606] [client 20.151.109.219:10618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/iy.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiMgAAAWQ"] [Tue Aug 18 13:04:56.935386 2026] [security2:error] [pid 157386:tid 157615] [client 158.23.17.4:56742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vg.php"] [unique_id "aoSCqE1jzAhYHVVT1WfiNAAAAW0"] [Tue Aug 18 13:04:57.059695 2026] [security2:error] [pid 157386:tid 157587] [client 20.251.48.93:26073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/222.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiOAAAAVE"] [Tue Aug 18 13:04:57.086614 2026] [security2:error] [pid 157386:tid 157594] [client 40.85.222.29:6743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiOwAAAVg"] [Tue Aug 18 13:04:57.089967 2026] [security2:error] [pid 157386:tid 157395] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/config/.env"] [unique_id "aoSCqU1jzAhYHVVT1WfiPAABUgg"] [Tue Aug 18 13:04:57.092338 2026] [security2:error] [pid 157386:tid 157591] [client 68.221.73.131:37440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiPQAAAVU"] [Tue Aug 18 13:04:57.104305 2026] [security2:error] [pid 157386:tid 157409] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/backend/.env"] [unique_id "aoSCqU1jzAhYHVVT1WfiPgABUhY"] [Tue Aug 18 13:04:57.107990 2026] [security2:error] [pid 157386:tid 157617] [client 213.35.127.232:63478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiPwAAAW8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:57.114414 2026] [security2:error] [pid 157386:tid 157452] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiQAABUkE"], referer: https://transevang.com.br/wp-admin/ [Tue Aug 18 13:04:57.157255 2026] [security2:error] [pid 157386:tid 157504] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/wp-login.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiQQABRXU"], referer: https://transevang.com.br/wp-admin/ [Tue Aug 18 13:04:57.232183 2026] [security2:error] [pid 157386:tid 157548] [client 20.65.98.162:20623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file52.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiRQAAASo"] [Tue Aug 18 13:04:57.237624 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:57.237916 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:57.282364 2026] [security2:error] [pid 157386:tid 157569] [client 20.250.13.23:22075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/ws54.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiRwAAAT8"] [Tue Aug 18 13:04:57.307774 2026] [security2:error] [pid 157386:tid 157527] [client 74.248.130.103:22373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/xiugai.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiSwAAARU"] [Tue Aug 18 13:04:57.346832 2026] [security2:error] [pid 157386:tid 157634] [client 20.171.51.14:57998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/bm.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiTwAAAYA"] [Tue Aug 18 13:04:57.380759 2026] [security2:error] [pid 157386:tid 157584] [client 4.232.151.198:25246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/po8sa.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiUgAAAU4"] [Tue Aug 18 13:04:57.383850 2026] [security2:error] [pid 157386:tid 157600] [client 4.232.151.198:41507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiUwAAAV4"] [Tue Aug 18 13:04:57.417559 2026] [security2:error] [pid 157386:tid 157635] [client 40.85.222.29:6729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiVAAAAYE"] [Tue Aug 18 13:04:57.427551 2026] [security2:error] [pid 157386:tid 157618] [client 103.184.169.37:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiVQAAAXA"] [Tue Aug 18 13:04:57.427714 2026] [security2:error] [pid 157386:tid 157618] [client 103.184.169.37:43917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiVQAAAXA"] [Tue Aug 18 13:04:57.428403 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/aaa.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiVgAAAQ0"] [Tue Aug 18 13:04:57.429864 2026] [security2:error] [pid 157386:tid 157550] [client 20.79.204.6:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/archive.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiVwAAASw"] [Tue Aug 18 13:04:57.447087 2026] [security2:error] [pid 157386:tid 157565] [client 20.91.215.254:24585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiWgAAATs"] [Tue Aug 18 13:04:57.449633 2026] [security2:error] [pid 157386:tid 157604] [client 20.151.109.219:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/email.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiWwAAAWI"] [Tue Aug 18 13:04:57.459338 2026] [security2:error] [pid 157386:tid 157559] [client 20.104.100.201:24061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/xyn.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiXAAAATU"] [Tue Aug 18 13:04:57.475266 2026] [security2:error] [pid 157386:tid 157609] [client 20.91.215.254:23680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiXQAAAWc"] [Tue Aug 18 13:04:57.540047 2026] [security2:error] [pid 157386:tid 157520] [client 20.65.98.162:20650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/geck.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiYgAAAQ4"] [Tue Aug 18 13:04:57.540914 2026] [authz_core:error] [pid 157386:tid 157511] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:57.541360 2026] [authz_core:error] [pid 157386:tid 157511] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:57.681150 2026] [security2:error] [pid 157386:tid 157557] [client 132.196.30.78:19869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wap.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiZgAAATM"] [Tue Aug 18 13:04:57.702658 2026] [security2:error] [pid 157386:tid 157570] [client 158.23.17.4:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sm.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiaQAAAUA"] [Tue Aug 18 13:04:57.719272 2026] [security2:error] [pid 157386:tid 157564] [client 40.85.222.29:6721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCqU1jzAhYHVVT1WfiawAAATo"] [Tue Aug 18 13:04:57.731027 2026] [security2:error] [pid 157386:tid 157626] [client 114.119.132.122:55113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ariatec.com.br"] [uri "/category/servicos"] [unique_id "aoSCqU1jzAhYHVVT1WfibAAAAXg"], referer: http://ariatec.com.br/category/servicos [Tue Aug 18 13:04:57.794916 2026] [security2:error] [pid 157386:tid 157531] [client 39.35.122.233:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.122.35.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "institutoferiani.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqU1jzAhYHVVT1WficAAAARk"] [Tue Aug 18 13:04:57.795065 2026] [security2:error] [pid 157386:tid 157531] [client 39.35.122.233:62476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "institutoferiani.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqU1jzAhYHVVT1WficAAAARk"] [Tue Aug 18 13:04:57.830755 2026] [security2:error] [pid 157386:tid 157580] [client 20.65.98.162:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/biufile.php"] [unique_id "aoSCqU1jzAhYHVVT1WficgAAAUo"] [Tue Aug 18 13:04:57.840807 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:57.841068 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:57.891220 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/og.php"] [unique_id "aoSCqU1jzAhYHVVT1WfieAAAAUw"] [Tue Aug 18 13:04:58.013697 2026] [security2:error] [pid 157386:tid 157574] [client 20.25.139.174:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/abcd.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiiAAAAUQ"] [Tue Aug 18 13:04:58.014437 2026] [security2:error] [pid 157386:tid 157619] [client 40.85.222.29:17536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiiQAAAXE"] [Tue Aug 18 13:04:58.032811 2026] [security2:error] [pid 157386:tid 157423] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.github/.env"] [unique_id "aoSCqk1jzAhYHVVT1WfiiwABISQ"] [Tue Aug 18 13:04:58.062876 2026] [security2:error] [pid 157386:tid 157591] [client 20.171.51.14:7878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vu.php"] [unique_id "aoSCqk1jzAhYHVVT1WfijQAAAVU"] [Tue Aug 18 13:04:58.074115 2026] [security2:error] [pid 157386:tid 157617] [client 20.151.109.219:45874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/profile.php"] [unique_id "aoSCqk1jzAhYHVVT1WfijgAAAW8"] [Tue Aug 18 13:04:58.085549 2026] [security2:error] [pid 157386:tid 157606] [client 20.91.215.254:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/db.php"] [unique_id "aoSCqk1jzAhYHVVT1WfikgAAAWQ"] [Tue Aug 18 13:04:58.089400 2026] [security2:error] [pid 157386:tid 157540] [client 4.232.151.198:25238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/lmfi.php"] [unique_id "aoSCqk1jzAhYHVVT1WfikwAAASI"] [Tue Aug 18 13:04:58.113925 2026] [security2:error] [pid 157386:tid 157625] [client 20.65.98.162:20632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/dejavu.php"] [unique_id "aoSCqk1jzAhYHVVT1WfilQAAAXc"] [Tue Aug 18 13:04:58.126743 2026] [security2:error] [pid 157386:tid 157622] [client 213.35.127.232:63728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCqk1jzAhYHVVT1WfilgAAAXQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:58.129495 2026] [security2:error] [pid 157386:tid 157636] [client 20.206.73.37:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/images.php"] [unique_id "aoSCqk1jzAhYHVVT1WfilwAAAYI"] [Tue Aug 18 13:04:58.139420 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:58.139686 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:58.143700 2026] [security2:error] [pid 157386:tid 157583] [client 197.184.64.235:42671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfimwAAAU0"] [Tue Aug 18 13:04:58.143855 2026] [security2:error] [pid 157386:tid 157583] [client 197.184.64.235:42671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfimwAAAU0"] [Tue Aug 18 13:04:58.200990 2026] [security2:error] [pid 157386:tid 157569] [client 158.23.17.4:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/28.php"] [unique_id "aoSCqk1jzAhYHVVT1WfingAAAT8"] [Tue Aug 18 13:04:58.285737 2026] [security2:error] [pid 157386:tid 157588] [client 132.196.30.78:19898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSCqk1jzAhYHVVT1WfipAAAAVI"] [Tue Aug 18 13:04:58.356110 2026] [security2:error] [pid 157386:tid 157595] [client 40.85.222.29:6744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiqwAAAVk"] [Tue Aug 18 13:04:58.378514 2026] [security2:error] [pid 157386:tid 157627] [client 37.40.227.74:56676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfirAAAAXk"] [Tue Aug 18 13:04:58.378637 2026] [security2:error] [pid 157386:tid 157627] [client 37.40.227.74:56676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfirAAAAXk"] [Tue Aug 18 13:04:58.442629 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:58.443073 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:58.443156 2026] [security2:error] [pid 157386:tid 157552] [client 20.65.98.162:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/aaf.php"] [unique_id "aoSCqk1jzAhYHVVT1WfisAAAAS4"] [Tue Aug 18 13:04:58.519610 2026] [security2:error] [pid 157386:tid 157535] [client 20.206.73.37:1841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/sf.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiswAAAR0"] [Tue Aug 18 13:04:58.550683 2026] [security2:error] [pid 157386:tid 157641] [client 20.91.215.254:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/goat.php"] [unique_id "aoSCqk1jzAhYHVVT1WfitQAAAYc"] [Tue Aug 18 13:04:58.573905 2026] [security2:error] [pid 157386:tid 157544] [client 20.25.139.174:4658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-good.php"] [unique_id "aoSCqk1jzAhYHVVT1WfitwAAASY"] [Tue Aug 18 13:04:58.596878 2026] [security2:error] [pid 157386:tid 157598] [client 196.12.128.158:53958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiuQAAAVw"] [Tue Aug 18 13:04:58.597004 2026] [security2:error] [pid 157386:tid 157598] [client 196.12.128.158:53958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiuQAAAVw"] [Tue Aug 18 13:04:58.656020 2026] [security2:error] [pid 157386:tid 157626] [client 40.85.222.29:17587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCqk1jzAhYHVVT1WfivAAAAXg"] [Tue Aug 18 13:04:58.663376 2026] [security2:error] [pid 157386:tid 157529] [client 20.124.247.79:16460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/file5.php"] [unique_id "aoSCqk1jzAhYHVVT1WfivQAAARc"] [Tue Aug 18 13:04:58.704457 2026] [security2:error] [pid 157386:tid 157531] [client 20.65.98.162:20620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSCqk1jzAhYHVVT1WfivwAAARk"] [Tue Aug 18 13:04:58.705028 2026] [authz_core:error] [pid 157386:tid 157447] [remote 34.62.54.143:43410] AH01630: client denied by server configuration: /home2/transevang/public_html/.htpasswd [Tue Aug 18 13:04:58.744640 2026] [authz_core:error] [pid 157386:tid 157405] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:58.745077 2026] [authz_core:error] [pid 157386:tid 157405] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:58.804584 2026] [security2:error] [pid 157386:tid 157621] [client 20.91.215.254:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/dropdown.php"] [unique_id "aoSCqk1jzAhYHVVT1WfixgAAAXM"] [Tue Aug 18 13:04:58.838496 2026] [security2:error] [pid 157386:tid 157526] [client 20.171.51.14:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ic.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiyAAAARQ"] [Tue Aug 18 13:04:58.844040 2026] [security2:error] [pid 157386:tid 157608] [client 4.232.151.198:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/wp-apxupx.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiyQAAAWY"] [Tue Aug 18 13:04:58.846781 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.100.201:24025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCqk1jzAhYHVVT1WfiygAAAS8"] [Tue Aug 18 13:04:58.945511 2026] [security2:error] [pid 157386:tid 157540] [client 158.23.17.4:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/m.php"] [unique_id "aoSCqk1jzAhYHVVT1WfizwAAASI"] [Tue Aug 18 13:04:58.955044 2026] [security2:error] [pid 157386:tid 157625] [client 20.65.98.162:20703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/155.php"] [unique_id "aoSCqk1jzAhYHVVT1Wfi0AAAAXc"] [Tue Aug 18 13:04:58.963807 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:17611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lp.php"] [unique_id "aoSCqk1jzAhYHVVT1Wfi0gAAATA"] [Tue Aug 18 13:04:58.966727 2026] [security2:error] [pid 157386:tid 157636] [client 40.85.222.29:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCqk1jzAhYHVVT1Wfi0wAAAYI"] [Tue Aug 18 13:04:58.992732 2026] [security2:error] [pid 157386:tid 157523] [client 132.196.30.78:27989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/bgymj.php"] [unique_id "aoSCqk1jzAhYHVVT1Wfi1gAAARE"] [Tue Aug 18 13:04:59.041677 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:59.041940 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:59.045615 2026] [security2:error] [pid 157386:tid 157463] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSCq01jzAhYHVVT1Wfi2QABf0w"] [Tue Aug 18 13:04:59.080448 2026] [security2:error] [pid 157386:tid 157637] [client 20.25.139.174:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/simple.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi3QAAAYM"] [Tue Aug 18 13:04:59.156206 2026] [security2:error] [pid 157386:tid 157585] [client 213.35.127.232:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi4QAAAU8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:04:59.160367 2026] [security2:error] [pid 157386:tid 157638] [client 20.250.13.23:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/deepseek_d.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi4gAAAYQ"] [Tue Aug 18 13:04:59.229022 2026] [security2:error] [pid 157386:tid 157579] [client 20.250.13.23:61070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/goods.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi5AAAAUk"] [Tue Aug 18 13:04:59.265798 2026] [security2:error] [pid 157386:tid 157561] [client 5.31.227.224:7858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi6AAAATc"] [Tue Aug 18 13:04:59.265921 2026] [security2:error] [pid 157386:tid 157561] [client 5.31.227.224:7858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi6AAAATc"] [Tue Aug 18 13:04:59.266068 2026] [security2:error] [pid 157386:tid 157628] [client 223.185.37.47:26643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi5wAAAXo"] [Tue Aug 18 13:04:59.266618 2026] [security2:error] [pid 157386:tid 157628] [client 223.185.37.47:26643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi5wAAAXo"] [Tue Aug 18 13:04:59.277348 2026] [security2:error] [pid 157386:tid 157552] [client 40.85.222.29:17551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi6QAAAS4"] [Tue Aug 18 13:04:59.332006 2026] [security2:error] [pid 157386:tid 157635] [client 20.91.215.254:15673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/Session.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi7AAAAYE"] [Tue Aug 18 13:04:59.350233 2026] [authz_core:error] [pid 157386:tid 157508] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:59.350659 2026] [authz_core:error] [pid 157386:tid 157508] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:59.359696 2026] [security2:error] [pid 157386:tid 157478] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSCq01jzAhYHVVT1Wfi7wABHVs"] [Tue Aug 18 13:04:59.363472 2026] [security2:error] [pid 157386:tid 157612] [client 20.65.98.162:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/ops.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi8AAAAWo"] [Tue Aug 18 13:04:59.417840 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/summary.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi8QAAAVQ"] [Tue Aug 18 13:04:59.460998 2026] [security2:error] [pid 157386:tid 157589] [client 20.206.73.37:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/biufile.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi9QAAAVM"] [Tue Aug 18 13:04:59.466477 2026] [security2:error] [pid 157386:tid 157610] [client 20.91.215.254:24615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/file.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi9gAAAWg"] [Tue Aug 18 13:04:59.529698 2026] [security2:error] [pid 157386:tid 157626] [client 20.124.247.79:16506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/xyn.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi-QAAAXg"] [Tue Aug 18 13:04:59.555501 2026] [security2:error] [pid 157386:tid 157601] [client 40.85.222.29:17547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi-wAAAV8"] [Tue Aug 18 13:04:59.556166 2026] [security2:error] [pid 157386:tid 157580] [client 158.23.17.4:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nl.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi_AAAAUo"] [Tue Aug 18 13:04:59.564079 2026] [security2:error] [pid 157386:tid 157391] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/id_rsa"] [unique_id "aoSCq01jzAhYHVVT1Wfi_QABVwQ"] [Tue Aug 18 13:04:59.570476 2026] [security2:error] [pid 157386:tid 157631] [client 132.196.30.78:27996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/aa.php"] [unique_id "aoSCq01jzAhYHVVT1Wfi_gAAAX0"] [Tue Aug 18 13:04:59.578313 2026] [authz_core:error] [pid 157386:tid 157544] [client 192.178.4.133:52910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:59.578598 2026] [authz_core:error] [pid 157386:tid 157544] [client 192.178.4.133:52910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:59.604842 2026] [security2:error] [pid 157386:tid 157620] [client 4.232.151.198:44613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wso.php"] [unique_id "aoSCq01jzAhYHVVT1WfjAAAAAXI"] [Tue Aug 18 13:04:59.615953 2026] [security2:error] [pid 157386:tid 157615] [client 20.171.51.14:58027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ue.php"] [unique_id "aoSCq01jzAhYHVVT1WfjAgAAAW0"] [Tue Aug 18 13:04:59.625282 2026] [security2:error] [pid 157386:tid 157642] [client 20.65.98.162:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/mac.php"] [unique_id "aoSCq01jzAhYHVVT1WfjBAAAAYg"] [Tue Aug 18 13:04:59.633342 2026] [security2:error] [pid 157386:tid 157641] [client 20.25.139.174:4638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/edit-tags.php"] [unique_id "aoSCq01jzAhYHVVT1WfjBQAAAYc"] [Tue Aug 18 13:04:59.648544 2026] [authz_core:error] [pid 157386:tid 157500] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:59.648996 2026] [authz_core:error] [pid 157386:tid 157500] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:04:59.743228 2026] [security2:error] [pid 157386:tid 157521] [client 4.223.113.180:19258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCq01jzAhYHVVT1WfjCQAAAQ8"] [Tue Aug 18 13:04:59.802430 2026] [security2:error] [pid 157386:tid 157594] [client 20.151.109.219:53544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ey.php"] [unique_id "aoSCq01jzAhYHVVT1WfjCgAAAVg"] [Tue Aug 18 13:04:59.822459 2026] [security2:error] [pid 157386:tid 157486] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/id_dsa"] [unique_id "aoSCq01jzAhYHVVT1WfjDAABb2M"] [Tue Aug 18 13:04:59.843366 2026] [security2:error] [pid 157386:tid 157555] [client 168.62.48.100:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/Cachex.php"] [unique_id "aoSCq01jzAhYHVVT1WfjDgAAATE"] [Tue Aug 18 13:04:59.903967 2026] [security2:error] [pid 157386:tid 157548] [client 40.85.222.29:6727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCq01jzAhYHVVT1WfjEwAAASo"] [Tue Aug 18 13:04:59.945483 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:04:59.945750 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:00.004467 2026] [security2:error] [pid 157386:tid 157623] [client 4.232.151.198:25242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/504.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjGQAAAXU"] [Tue Aug 18 13:05:00.018672 2026] [security2:error] [pid 157386:tid 157550] [client 74.248.130.103:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/adminner.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjGgAAASw"] [Tue Aug 18 13:05:00.035271 2026] [security2:error] [pid 157386:tid 157587] [client 20.91.215.254:15626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjHAAAAVE"] [Tue Aug 18 13:05:00.073035 2026] [security2:error] [pid 157386:tid 157609] [client 20.38.3.247:39107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjHgAAAWc"] [Tue Aug 18 13:05:00.100640 2026] [security2:error] [pid 157386:tid 157583] [client 20.91.215.254:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/goods.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjIQAAAU0"] [Tue Aug 18 13:05:00.121427 2026] [security2:error] [pid 157386:tid 157614] [client 68.221.73.131:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/BDKR28WP.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjIgAAAWw"] [Tue Aug 18 13:05:00.143969 2026] [security2:error] [pid 157386:tid 157545] [client 132.196.30.78:20046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-mail.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjIwAAASc"] [Tue Aug 18 13:05:00.178778 2026] [security2:error] [pid 157386:tid 157554] [client 213.35.127.232:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjJQAAATA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:00.183354 2026] [security2:error] [pid 157386:tid 157561] [client 158.23.17.4:56730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/68.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjJgAAATc"] [Tue Aug 18 13:05:00.193373 2026] [security2:error] [pid 157386:tid 157628] [client 20.65.98.162:20720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjJwAAAXo"] [Tue Aug 18 13:05:00.207985 2026] [security2:error] [pid 157386:tid 157409] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/key.pem"] [unique_id "aoSCrE1jzAhYHVVT1WfjKAABLhY"] [Tue Aug 18 13:05:00.215731 2026] [security2:error] [pid 157386:tid 157595] [client 20.25.139.174:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/u.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjKQAAAVk"] [Tue Aug 18 13:05:00.224676 2026] [security2:error] [pid 157386:tid 157592] [client 40.85.222.29:17539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjKgAAAVY"] [Tue Aug 18 13:05:00.229600 2026] [security2:error] [pid 157386:tid 157547] [client 68.221.73.131:30241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/gec.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjKwAAASk"] [Tue Aug 18 13:05:00.232040 2026] [security2:error] [pid 157386:tid 157569] [client 20.151.109.219:13800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/conf.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjLAAAAT8"] [Tue Aug 18 13:05:00.246011 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:00.246270 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:00.255066 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.100.201:24033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-good.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjLgAAAUI"] [Tue Aug 18 13:05:00.296819 2026] [security2:error] [pid 157386:tid 157504] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/privatekey.key"] [unique_id "aoSCrE1jzAhYHVVT1WfjMQABVHU"] [Tue Aug 18 13:05:00.307845 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lv.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjMgAAAW4"] [Tue Aug 18 13:05:00.328066 2026] [security2:error] [pid 157386:tid 157611] [client 20.171.51.14:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lr.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjMwAAAWk"] [Tue Aug 18 13:05:00.353959 2026] [authz_core:error] [pid 157386:tid 157487] [remote 57.141.22.53:29472] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:00.354218 2026] [authz_core:error] [pid 157386:tid 157487] [remote 57.141.22.53:29472] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:00.384701 2026] [security2:error] [pid 157386:tid 157575] [client 20.79.204.6:9338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/bless.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjNgAAAUU"] [Tue Aug 18 13:05:00.424410 2026] [security2:error] [pid 157386:tid 157529] [client 40.74.65.169:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/82.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjNwAAARc"] [Tue Aug 18 13:05:00.512011 2026] [security2:error] [pid 157386:tid 157571] [client 20.65.98.162:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjOwAAAUE"] [Tue Aug 18 13:05:00.579881 2026] [security2:error] [pid 157386:tid 157602] [client 40.85.222.29:17583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjQAAAAWA"] [Tue Aug 18 13:05:00.600289 2026] [security2:error] [pid 157386:tid 157613] [client 20.124.247.79:16415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/inso.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjQQAAAWs"] [Tue Aug 18 13:05:00.630288 2026] [authz_core:error] [pid 157386:tid 157596] [client 192.178.4.133:52910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:00.630556 2026] [authz_core:error] [pid 157386:tid 157596] [client 192.178.4.133:52910] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:00.686068 2026] [security2:error] [pid 157386:tid 157574] [client 20.251.48.93:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/key.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjRgAAAUQ"] [Tue Aug 18 13:05:00.757692 2026] [security2:error] [pid 157386:tid 157591] [client 168.62.48.100:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjSwAAAVU"] [Tue Aug 18 13:05:00.784473 2026] [security2:error] [pid 157386:tid 157615] [client 4.232.151.198:25274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/tiny.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjTQAAAW0"] [Tue Aug 18 13:05:00.786285 2026] [security2:error] [pid 157386:tid 157606] [client 20.65.98.162:20637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/system_log.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjTgAAAWQ"] [Tue Aug 18 13:05:00.790533 2026] [security2:error] [pid 157386:tid 157642] [client 20.91.215.254:18368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/hplfuns.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjTwAAAYg"] [Tue Aug 18 13:05:00.816988 2026] [security2:error] [pid 157386:tid 157542] [client 86.120.159.145:19397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjUQAAASQ"] [Tue Aug 18 13:05:00.817118 2026] [security2:error] [pid 157386:tid 157542] [client 86.120.159.145:19397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjUQAAASQ"] [Tue Aug 18 13:05:00.829896 2026] [security2:error] [pid 157386:tid 157599] [client 20.91.215.254:15622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/abcd.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjUgAAAV0"] [Tue Aug 18 13:05:00.835949 2026] [security2:error] [pid 157386:tid 157636] [client 158.23.17.4:14057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/jl.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjVAAAAYI"] [Tue Aug 18 13:05:00.844929 2026] [security2:error] [pid 157386:tid 157621] [client 20.25.139.174:4557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjVgAAAXM"] [Tue Aug 18 13:05:00.848981 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:00.849245 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:00.854354 2026] [security2:error] [pid 157386:tid 157624] [client 20.171.51.14:7915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ka.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjVwAAAXY"] [Tue Aug 18 13:05:00.863746 2026] [security2:error] [pid 157386:tid 157528] [client 213.202.253.4:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjWAAAARY"], referer: www.google.com [Tue Aug 18 13:05:00.869491 2026] [security2:error] [pid 157386:tid 157620] [client 132.196.30.78:19846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/bolt.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjWQAAAXI"] [Tue Aug 18 13:05:00.906940 2026] [security2:error] [pid 157386:tid 157637] [client 40.85.222.29:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjXAAAAYM"] [Tue Aug 18 13:05:00.964643 2026] [security2:error] [pid 157386:tid 157444] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSCrE1jzAhYHVVT1WfjYAABhDk"] [Tue Aug 18 13:05:00.969497 2026] [security2:error] [pid 157386:tid 157627] [client 20.104.100.201:23887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wmore1.php"] [unique_id "aoSCrE1jzAhYHVVT1WfjYQAAAXk"] [Tue Aug 18 13:05:01.039428 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:05:01.039456 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:05:01.153125 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:01.153433 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:01.197626 2026] [security2:error] [pid 157386:tid 157518] [client 74.248.130.103:7707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file1221.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjbgAAAQw"] [Tue Aug 18 13:05:01.211291 2026] [security2:error] [pid 157386:tid 157534] [client 213.35.127.232:64545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjcAAAARw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:01.226297 2026] [security2:error] [pid 157386:tid 157612] [client 40.85.222.29:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjcgAAAWo"] [Tue Aug 18 13:05:01.255601 2026] [security2:error] [pid 157386:tid 157537] [client 68.221.73.131:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/sky.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjdAAAAR8"] [Tue Aug 18 13:05:01.316929 2026] [security2:error] [pid 157386:tid 157577] [client 20.151.109.219:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/51.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjeAAAAUc"] [Tue Aug 18 13:05:01.326344 2026] [security2:error] [pid 157386:tid 157616] [client 20.206.73.37:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/coffexium.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjegAAAW4"] [Tue Aug 18 13:05:01.348530 2026] [security2:error] [pid 157386:tid 157397] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.hermes/.env"] [unique_id "aoSCrU1jzAhYHVVT1WfjfAABHQo"] [Tue Aug 18 13:05:01.355353 2026] [security2:error] [pid 157386:tid 157611] [client 20.171.51.14:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ot.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjfgAAAWk"] [Tue Aug 18 13:05:01.413097 2026] [security2:error] [pid 157386:tid 157570] [client 20.65.98.162:20615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/pucci.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjgQAAAUA"] [Tue Aug 18 13:05:01.420707 2026] [security2:error] [pid 157386:tid 157573] [client 20.91.215.254:21472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/htaccess.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjgwAAAUM"] [Tue Aug 18 13:05:01.431528 2026] [security2:error] [pid 157386:tid 157567] [client 4.232.151.198:7789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/atomlib.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjhAAAAT0"] [Tue Aug 18 13:05:01.445212 2026] [security2:error] [pid 157386:tid 157590] [client 20.25.139.174:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/h.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjhwAAAVQ"] [Tue Aug 18 13:05:01.497747 2026] [security2:error] [pid 157386:tid 157531] [client 20.151.109.219:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/bala.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjiQAAARk"] [Tue Aug 18 13:05:01.502534 2026] [security2:error] [pid 157386:tid 157555] [client 49.37.150.8:61535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjigAAATE"] [Tue Aug 18 13:05:01.502690 2026] [security2:error] [pid 157386:tid 157555] [client 49.37.150.8:61535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjigAAATE"] [Tue Aug 18 13:05:01.565773 2026] [security2:error] [pid 157386:tid 157519] [client 20.104.100.201:23890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/special.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjjQAAAQ0"] [Tue Aug 18 13:05:01.577785 2026] [security2:error] [pid 157386:tid 157633] [client 20.79.204.6:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/sagax1.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjjgAAAX8"] [Tue Aug 18 13:05:01.592228 2026] [security2:error] [pid 157386:tid 157576] [client 40.85.222.29:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjjwAAAUY"] [Tue Aug 18 13:05:01.593889 2026] [security2:error] [pid 157386:tid 157533] [client 4.223.113.180:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/dav.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjkAAAARs"] [Tue Aug 18 13:05:01.610130 2026] [security2:error] [pid 157386:tid 157575] [client 20.91.215.254:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/kj.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjkQAAAUU"] [Tue Aug 18 13:05:01.690534 2026] [security2:error] [pid 157386:tid 157626] [client 132.196.30.78:27980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/bthil.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjlAAAAXg"] [Tue Aug 18 13:05:01.692953 2026] [security2:error] [pid 157386:tid 157600] [client 20.250.13.23:38295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/function/function.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjlQAAAV4"] [Tue Aug 18 13:05:01.756887 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:01.757327 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:01.819936 2026] [security2:error] [pid 157386:tid 157642] [client 20.206.73.37:2142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/sky.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjmwAAAYg"] [Tue Aug 18 13:05:01.911267 2026] [security2:error] [pid 157386:tid 157618] [client 20.124.247.79:16458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/puc.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjnwAAAXA"] [Tue Aug 18 13:05:01.944748 2026] [security2:error] [pid 157386:tid 157538] [client 68.221.73.131:37915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/sixxis.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjoAAAASA"] [Tue Aug 18 13:05:01.961254 2026] [security2:error] [pid 157386:tid 157638] [client 40.85.222.29:6593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCrU1jzAhYHVVT1WfjpAAAAYQ"] [Tue Aug 18 13:05:02.010547 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.100.201:24059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjqQAAAX4"] [Tue Aug 18 13:05:02.038026 2026] [security2:error] [pid 157386:tid 157614] [client 20.65.98.162:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjqgAAAWw"] [Tue Aug 18 13:05:02.052041 2026] [security2:error] [pid 157386:tid 157528] [client 20.25.139.174:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjrgAAARY"] [Tue Aug 18 13:05:02.052195 2026] [security2:error] [pid 157386:tid 157621] [client 20.91.215.254:3756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/images/wso.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjrQAAAXM"] [Tue Aug 18 13:05:02.058678 2026] [authz_core:error] [pid 157386:tid 157457] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:02.059123 2026] [authz_core:error] [pid 157386:tid 157457] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:02.063131 2026] [security2:error] [pid 157386:tid 157607] [client 20.151.109.219:56063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ew.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjrwAAAWU"] [Tue Aug 18 13:05:02.085130 2026] [security2:error] [pid 157386:tid 157586] [client 20.171.51.14:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ih.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjswAAAVA"] [Tue Aug 18 13:05:02.157956 2026] [security2:error] [pid 157386:tid 157550] [client 4.232.151.198:7188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/12.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjtQAAASw"] [Tue Aug 18 13:05:02.220693 2026] [security2:error] [pid 157386:tid 157534] [client 20.251.48.93:40847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/chosen.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjtgAAARw"] [Tue Aug 18 13:05:02.223749 2026] [security2:error] [pid 157386:tid 157634] [client 213.35.127.232:64810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjuAAAAYA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:02.313412 2026] [security2:error] [pid 157386:tid 157609] [client 20.91.215.254:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/languages.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjuQAAAWc"] [Tue Aug 18 13:05:02.357523 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:02.357821 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:02.382985 2026] [security2:error] [pid 157386:tid 157610] [client 40.85.222.29:6772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjvAAAAWg"] [Tue Aug 18 13:05:02.431159 2026] [security2:error] [pid 157386:tid 157529] [client 20.65.98.162:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjvgAAARc"] [Tue Aug 18 13:05:02.465336 2026] [security2:error] [pid 157386:tid 157524] [client 20.104.100.201:23875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/thoms.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjwAAAARI"] [Tue Aug 18 13:05:02.481596 2026] [security2:error] [pid 157386:tid 157489] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "transevang.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSCrk1jzAhYHVVT1WfjwgABemY"] [Tue Aug 18 13:05:02.482107 2026] [security2:error] [pid 157386:tid 157459] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "transevang.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSCrk1jzAhYHVVT1WfjwwABekg"] [Tue Aug 18 13:05:02.488061 2026] [security2:error] [pid 157386:tid 157531] [client 20.151.109.219:10621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/222.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjxAAAARk"] [Tue Aug 18 13:05:02.550540 2026] [security2:error] [pid 157386:tid 157573] [client 20.25.139.174:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/a7.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjxgAAAUM"] [Tue Aug 18 13:05:02.620425 2026] [http2:warn] [pid 139043:tid 139191] [client 201.32.74.208:57070] h2_stream(139043-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:05:02.657338 2026] [authz_core:error] [pid 157386:tid 157470] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:02.657732 2026] [authz_core:error] [pid 157386:tid 157470] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:02.658283 2026] [security2:error] [pid 157386:tid 157582] [client 40.85.222.29:17537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjzQAAAUw"] [Tue Aug 18 13:05:02.669632 2026] [security2:error] [pid 157386:tid 157575] [client 168.62.48.100:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCrk1jzAhYHVVT1WfjzgAAAUU"] [Tue Aug 18 13:05:02.687175 2026] [security2:error] [pid 157386:tid 157540] [client 158.23.17.4:20479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/tq.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj0AAAASI"] [Tue Aug 18 13:05:02.701086 2026] [security2:error] [pid 157386:tid 157601] [client 20.91.215.254:3862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/index/function.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj0QAAAV8"] [Tue Aug 18 13:05:02.706902 2026] [security2:error] [pid 157386:tid 157525] [client 20.65.98.162:7117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/puc.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj0gAAARM"] [Tue Aug 18 13:05:02.711788 2026] [security2:error] [pid 157386:tid 157546] [client 20.171.51.14:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/k.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj0wAAASg"] [Tue Aug 18 13:05:02.730691 2026] [security2:error] [pid 157386:tid 157461] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/laravel/.env"] [unique_id "aoSCrk1jzAhYHVVT1Wfj1AABeEo"] [Tue Aug 18 13:05:02.758713 2026] [security2:error] [pid 157386:tid 157600] [client 68.221.73.131:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/sf.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj1QAAAV4"] [Tue Aug 18 13:05:02.775169 2026] [lsapi:warn] [pid 157386:tid 157476] [remote 57.141.22.22:54452] [host rafaelgallassini.com.br] Backend log: PHP Warning: mkdir(): Disk quota exceeded in /home4/rafaelgalla/public_html/wp-content/plugins/tenweb-speed-optimizer/includes/WebPageCache/OptimizerWebPageCache.php on line 190\n [Tue Aug 18 13:05:02.778854 2026] [security2:error] [pid 157386:tid 157593] [client 4.223.113.180:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/wp_wol.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj1gAAAVc"] [Tue Aug 18 13:05:02.781973 2026] [security2:error] [pid 157386:tid 157554] [client 20.79.204.6:9698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wpc.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj1wAAATA"] [Tue Aug 18 13:05:02.787290 2026] [security2:error] [pid 157386:tid 157591] [client 132.196.30.78:28012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/x.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj2QAAAVU"] [Tue Aug 18 13:05:02.787337 2026] [security2:error] [pid 157386:tid 157641] [client 4.232.151.198:22165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/sck.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj2AAAAYc"] [Tue Aug 18 13:05:02.822157 2026] [security2:error] [pid 157386:tid 157539] [client 20.104.100.201:23814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj2gAAASE"] [Tue Aug 18 13:05:02.850664 2026] [security2:error] [pid 157386:tid 157625] [client 20.38.3.247:6239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj2wAAAXc"] [Tue Aug 18 13:05:02.903192 2026] [security2:error] [pid 157386:tid 157453] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/config.php.bak"] [unique_id "aoSCrk1jzAhYHVVT1Wfj3gABdkI"] [Tue Aug 18 13:05:02.913217 2026] [security2:error] [pid 157386:tid 157643] [client 20.124.247.79:16396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/19.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj3wAAAYk"] [Tue Aug 18 13:05:02.936163 2026] [security2:error] [pid 157386:tid 157477] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/config/.env.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj4QABe1o"] [Tue Aug 18 13:05:02.973532 2026] [security2:error] [pid 157386:tid 157587] [client 40.85.222.29:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCrk1jzAhYHVVT1Wfj4wAAAVE"] [Tue Aug 18 13:05:03.081841 2026] [security2:error] [pid 157386:tid 157642] [client 20.25.139.174:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/manager.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj6QAAAYg"] [Tue Aug 18 13:05:03.101067 2026] [security2:error] [pid 157386:tid 157561] [client 40.74.65.169:16344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/dex.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj6gAAATc"] [Tue Aug 18 13:05:03.139088 2026] [security2:error] [pid 157386:tid 157596] [client 20.65.98.162:20648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/8.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj6wAAAVo"] [Tue Aug 18 13:05:03.143110 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/routes.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj7AAAARo"] [Tue Aug 18 13:05:03.143127 2026] [security2:error] [pid 157386:tid 157448] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/.env.php.bak"] [unique_id "aoSCr01jzAhYHVVT1Wfj7QABSD0"] [Tue Aug 18 13:05:03.163996 2026] [security2:error] [pid 157386:tid 157387] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/core/.env"] [unique_id "aoSCr01jzAhYHVVT1Wfj7wABgAA"] [Tue Aug 18 13:05:03.192171 2026] [authz_core:error] [pid 157386:tid 157502] [remote 57.141.22.121:45632] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:03.192432 2026] [authz_core:error] [pid 157386:tid 157502] [remote 57.141.22.121:45632] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:03.218596 2026] [security2:error] [pid 157386:tid 157559] [client 68.221.73.131:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/yj09.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj8QAAATU"] [Tue Aug 18 13:05:03.235764 2026] [security2:error] [pid 157386:tid 157569] [client 20.104.100.201:23984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/root.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj8gAAAT8"] [Tue Aug 18 13:05:03.240666 2026] [security2:error] [pid 157386:tid 157556] [client 213.35.127.232:65103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj8wAAATI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:03.258444 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:03.258708 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:03.336643 2026] [security2:error] [pid 157386:tid 157579] [client 20.91.215.254:3884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/info.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj9gAAAUk"] [Tue Aug 18 13:05:03.347572 2026] [security2:error] [pid 157386:tid 157467] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.62.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transevang.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSCr01jzAhYHVVT1Wfj9wABaFA"] [Tue Aug 18 13:05:03.380740 2026] [security2:error] [pid 157386:tid 157524] [client 40.85.222.29:17572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj-gAAARI"] [Tue Aug 18 13:05:03.449918 2026] [security2:error] [pid 157386:tid 157628] [client 20.65.98.162:20629] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.ergoclinica.com.br"] [uri "/1.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj-wAAAXo"] [Tue Aug 18 13:05:03.450026 2026] [security2:error] [pid 157386:tid 157628] [client 20.65.98.162:20629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/1.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj-wAAAXo"] [Tue Aug 18 13:05:03.490653 2026] [security2:error] [pid 157386:tid 157630] [client 132.196.30.78:20037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/index/function.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj_AAAAXw"] [Tue Aug 18 13:05:03.500140 2026] [security2:error] [pid 157386:tid 157609] [client 4.232.151.198:25218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/1945.php"] [unique_id "aoSCr01jzAhYHVVT1Wfj_QAAAWc"] [Tue Aug 18 13:05:03.554461 2026] [security2:error] [pid 157386:tid 157492] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/.env.swp"] [unique_id "aoSCr01jzAhYHVVT1WfkAQABPWk"] [Tue Aug 18 13:05:03.558604 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:03.558865 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:03.571137 2026] [security2:error] [pid 157386:tid 157622] [client 20.206.73.37:27677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/xx.php"] [unique_id "aoSCr01jzAhYHVVT1WfkAgAAAXQ"] [Tue Aug 18 13:05:03.577527 2026] [security2:error] [pid 157386:tid 157546] [client 20.206.73.37:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/admin.php"] [unique_id "aoSCr01jzAhYHVVT1WfkAwAAASg"] [Tue Aug 18 13:05:03.624988 2026] [security2:error] [pid 157386:tid 157594] [client 20.124.247.79:16436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/133.php"] [unique_id "aoSCr01jzAhYHVVT1WfkBAAAAVg"] [Tue Aug 18 13:05:03.639486 2026] [security2:error] [pid 157386:tid 157591] [client 158.23.17.4:48389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/cv.php"] [unique_id "aoSCr01jzAhYHVVT1WfkBgAAAVU"] [Tue Aug 18 13:05:03.647069 2026] [security2:error] [pid 157386:tid 157565] [client 20.25.139.174:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/w1.php"] [unique_id "aoSCr01jzAhYHVVT1WfkBwAAATs"] [Tue Aug 18 13:05:03.660105 2026] [security2:error] [pid 157386:tid 157641] [client 20.206.73.37:46972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/dex.php"] [unique_id "aoSCr01jzAhYHVVT1WfkCQAAAYc"] [Tue Aug 18 13:05:03.677918 2026] [security2:error] [pid 157386:tid 157617] [client 40.85.222.29:17592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCr01jzAhYHVVT1WfkCwAAAW8"] [Tue Aug 18 13:05:03.693414 2026] [security2:error] [pid 157386:tid 157625] [client 20.91.215.254:15666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/nw.php"] [unique_id "aoSCr01jzAhYHVVT1WfkDQAAAXc"] [Tue Aug 18 13:05:03.695247 2026] [security2:error] [pid 157386:tid 157606] [client 20.104.100.201:23922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/fpwch.php"] [unique_id "aoSCr01jzAhYHVVT1WfkDgAAAWQ"] [Tue Aug 18 13:05:03.721634 2026] [security2:error] [pid 157386:tid 157542] [client 20.65.98.162:20625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/about.php"] [unique_id "aoSCr01jzAhYHVVT1WfkEAAAASQ"] [Tue Aug 18 13:05:03.733685 2026] [security2:error] [pid 157386:tid 157483] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/web/.env"] [unique_id "aoSCr01jzAhYHVVT1WfkEQABdmA"] [Tue Aug 18 13:05:03.821599 2026] [security2:error] [pid 157386:tid 157503] [remote 34.62.54.143:43410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transevang.com.br"] [uri "/public/.env"] [unique_id "aoSCr01jzAhYHVVT1WfkFgABg3Q"] [Tue Aug 18 13:05:03.847699 2026] [security2:error] [pid 157386:tid 157533] [client 20.250.13.23:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/file.php"] [unique_id "aoSCr01jzAhYHVVT1WfkJAAAARs"] [Tue Aug 18 13:05:03.860375 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:03.860843 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:03.909614 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pqr.php"] [unique_id "aoSCr01jzAhYHVVT1WfkVQAAAXk"] [Tue Aug 18 13:05:03.958956 2026] [security2:error] [pid 157386:tid 157581] [client 20.171.51.14:38747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/iu.php"] [unique_id "aoSCr01jzAhYHVVT1WfkVgAAAUs"] [Tue Aug 18 13:05:03.976116 2026] [security2:error] [pid 157386:tid 157523] [client 20.91.215.254:3767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/profile.php"] [unique_id "aoSCr01jzAhYHVVT1WfkWgAAARE"] [Tue Aug 18 13:05:03.995099 2026] [security2:error] [pid 157386:tid 157632] [client 20.65.98.162:20642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/admin.php"] [unique_id "aoSCr01jzAhYHVVT1WfkWwAAAX4"] [Tue Aug 18 13:05:04.011339 2026] [security2:error] [pid 157386:tid 157595] [client 20.104.100.201:23866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/mg.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkZwAAAVk"] [Tue Aug 18 13:05:04.051278 2026] [security2:error] [pid 157386:tid 157578] [client 40.85.222.29:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkcAAAAUg"] [Tue Aug 18 13:05:04.067220 2026] [security2:error] [pid 157386:tid 157554] [client 149.34.210.141:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkcgAAATA"] [Tue Aug 18 13:05:04.134429 2026] [security2:error] [pid 157386:tid 157597] [client 4.232.151.198:22191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/homeadmin.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkdgAAAVs"] [Tue Aug 18 13:05:04.162177 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:04.162450 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:04.224692 2026] [security2:error] [pid 157386:tid 157631] [client 20.124.247.79:16416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkfAAAAX0"] [Tue Aug 18 13:05:04.253048 2026] [security2:error] [pid 157386:tid 157548] [client 213.35.127.232:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkfgAAASo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:04.286681 2026] [security2:error] [pid 157386:tid 157568] [client 20.65.98.162:20705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/edit.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkgwAAAT4"] [Tue Aug 18 13:05:04.334300 2026] [security2:error] [pid 157386:tid 157554] [client 149.34.210.141:56027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkcgAAATA"] [Tue Aug 18 13:05:04.340499 2026] [security2:error] [pid 157386:tid 157546] [client 20.251.48.93:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/wpxml.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkiAAAASg"] [Tue Aug 18 13:05:04.352152 2026] [security2:error] [pid 157386:tid 157594] [client 20.104.100.201:23927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/reop3.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkiQAAAVg"] [Tue Aug 18 13:05:04.367486 2026] [security2:error] [pid 157386:tid 157570] [client 20.79.204.6:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/fone1.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkigAAAUA"] [Tue Aug 18 13:05:04.369527 2026] [security2:error] [pid 157386:tid 157610] [client 20.91.215.254:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkiwAAAWg"] [Tue Aug 18 13:05:04.381501 2026] [security2:error] [pid 157386:tid 157625] [client 40.85.222.29:17588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkjAAAAXc"] [Tue Aug 18 13:05:04.419782 2026] [security2:error] [pid 157386:tid 157640] [client 68.221.73.131:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/k.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkjQAAAYY"] [Tue Aug 18 13:05:04.426210 2026] [security2:error] [pid 157386:tid 157519] [client 4.223.113.180:41067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/fm2.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkjgAAAQ0"] [Tue Aug 18 13:05:04.475005 2026] [security2:error] [pid 157386:tid 157588] [client 40.85.222.29:6765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkkwAAAVI"] [Tue Aug 18 13:05:04.498964 2026] [security2:error] [pid 157386:tid 157618] [client 74.248.130.103:22352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/inx.php"] [unique_id "aoSCsE1jzAhYHVVT1WfklAAAAXA"] [Tue Aug 18 13:05:04.506666 2026] [security2:error] [pid 157386:tid 157574] [client 132.196.30.78:28018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/aaa.php"] [unique_id "aoSCsE1jzAhYHVVT1WfklQAAAUQ"] [Tue Aug 18 13:05:04.506927 2026] [security2:error] [pid 157386:tid 157629] [client 158.23.17.4:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/un.php"] [unique_id "aoSCsE1jzAhYHVVT1WfklgAAAXs"] [Tue Aug 18 13:05:04.535625 2026] [security2:error] [pid 157386:tid 157533] [client 20.151.109.219:17628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/php5.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkmQAAARs"] [Tue Aug 18 13:05:04.547914 2026] [security2:error] [pid 157386:tid 157530] [client 20.171.51.14:14121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pk.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkmgAAARg"] [Tue Aug 18 13:05:04.560860 2026] [security2:error] [pid 157386:tid 157521] [client 20.65.98.162:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkmwAAAQ8"] [Tue Aug 18 13:05:04.599574 2026] [security2:error] [pid 157386:tid 157518] [client 20.250.13.23:48880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/nw.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkngAAAQw"] [Tue Aug 18 13:05:04.605805 2026] [security2:error] [pid 157386:tid 157564] [client 20.91.215.254:3891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/sx.php"] [unique_id "aoSCsE1jzAhYHVVT1WfknwAAATo"] [Tue Aug 18 13:05:04.674987 2026] [security2:error] [pid 157386:tid 157545] [client 20.38.3.247:22999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkogAAASc"] [Tue Aug 18 13:05:04.723453 2026] [security2:error] [pid 157386:tid 157638] [client 20.25.139.174:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-login.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkpgAAAYQ"] [Tue Aug 18 13:05:04.743735 2026] [security2:error] [pid 157386:tid 157550] [client 20.104.100.201:23920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/php5.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkpwAAASw"] [Tue Aug 18 13:05:04.761364 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:04.761632 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:04.767888 2026] [security2:error] [pid 157386:tid 157558] [client 40.74.65.169:60252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkqwAAATQ"] [Tue Aug 18 13:05:04.815080 2026] [security2:error] [pid 157386:tid 157634] [client 40.85.222.29:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCsE1jzAhYHVVT1WfkrgAAAYA"] [Tue Aug 18 13:05:04.829111 2026] [security2:error] [pid 157386:tid 157539] [client 20.65.98.162:20624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/inputs.php"] [unique_id "aoSCsE1jzAhYHVVT1WfksQAAASE"] [Tue Aug 18 13:05:04.847302 2026] [security2:error] [pid 157386:tid 157537] [client 4.232.151.198:40550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/zup.php73"] [unique_id "aoSCsE1jzAhYHVVT1WfksgAAAR8"] [Tue Aug 18 13:05:04.893016 2026] [security2:error] [pid 157386:tid 157605] [client 41.209.14.92:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.14.209.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "institutocamaleao.org"] [uri "/xmlrpc.php"] [unique_id "aoSCsE1jzAhYHVVT1WfktAAAAWM"] [Tue Aug 18 13:05:04.893138 2026] [security2:error] [pid 157386:tid 157605] [client 41.209.14.92:58387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "institutocamaleao.org"] [uri "/xmlrpc.php"] [unique_id "aoSCsE1jzAhYHVVT1WfktAAAAWM"] [Tue Aug 18 13:05:05.001737 2026] [security2:error] [pid 157386:tid 157595] [client 4.232.151.198:19287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/theme-insynwr.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkuAAAAVk"] [Tue Aug 18 13:05:05.009351 2026] [security2:error] [pid 157386:tid 157630] [client 74.248.130.103:42233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/reviall.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkugAAAXw"] [Tue Aug 18 13:05:05.061069 2026] [security2:error] [pid 157386:tid 157575] [client 20.104.100.201:23879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/acp.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkvgAAAUU"] [Tue Aug 18 13:05:05.067269 2026] [authz_core:error] [pid 157386:tid 157445] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:05.067678 2026] [authz_core:error] [pid 157386:tid 157445] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:05.080997 2026] [security2:error] [pid 157386:tid 157568] [client 20.65.98.162:20652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/av.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkvwAAAT4"] [Tue Aug 18 13:05:05.085559 2026] [security2:error] [pid 157386:tid 157601] [client 157.20.138.62:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkwAAAAV8"] [Tue Aug 18 13:05:05.085662 2026] [security2:error] [pid 157386:tid 157601] [client 157.20.138.62:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkwAAAAV8"] [Tue Aug 18 13:05:05.119941 2026] [security2:error] [pid 157386:tid 157598] [client 40.85.222.29:6619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/weozh.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkwQAAAVw"] [Tue Aug 18 13:05:05.155874 2026] [security2:error] [pid 157386:tid 157603] [client 158.23.17.4:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/evil.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkwwAAAWE"] [Tue Aug 18 13:05:05.157527 2026] [autoindex:error] [pid 157386:tid 157556] [client 20.91.215.254:20245] AH01276: Cannot serve directory /home3/pletud/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:05.196045 2026] [security2:error] [pid 157386:tid 157626] [client 132.196.30.78:28011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/abcd.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkxAAAAXg"] [Tue Aug 18 13:05:05.233353 2026] [security2:error] [pid 157386:tid 157624] [client 20.124.247.79:16467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/mosty.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkxwAAAXY"] [Tue Aug 18 13:05:05.233656 2026] [security2:error] [pid 157386:tid 157548] [client 20.91.215.254:3157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkyAAAASo"] [Tue Aug 18 13:05:05.270877 2026] [security2:error] [pid 157386:tid 157557] [client 213.35.127.232:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkygAAATM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:05.288188 2026] [security2:error] [pid 157386:tid 157600] [client 20.25.139.174:4552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/default.php"] [unique_id "aoSCsU1jzAhYHVVT1WfkzAAAAV4"] [Tue Aug 18 13:05:05.352021 2026] [security2:error] [pid 157386:tid 157618] [client 20.65.98.162:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk0AAAAXA"] [Tue Aug 18 13:05:05.367258 2026] [security2:error] [pid 157386:tid 157629] [client 20.91.215.254:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk0gAAAXs"] [Tue Aug 18 13:05:05.368692 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:05.369128 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:05.381132 2026] [security2:error] [pid 157386:tid 157538] [client 20.104.100.201:23980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/yas.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk0wAAASA"] [Tue Aug 18 13:05:05.395963 2026] [security2:error] [pid 157386:tid 157533] [client 20.151.109.219:21902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/an.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk1AAAARs"] [Tue Aug 18 13:05:05.413099 2026] [security2:error] [pid 157386:tid 157599] [client 68.221.73.131:37482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/w.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk1QAAAV0"] [Tue Aug 18 13:05:05.433679 2026] [security2:error] [pid 157386:tid 157584] [client 40.85.222.29:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/rymmm.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk1gAAAU4"] [Tue Aug 18 13:05:05.447743 2026] [security2:error] [pid 157386:tid 157567] [client 40.74.65.169:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk1wAAAT0"] [Tue Aug 18 13:05:05.449748 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:21943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/Black.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk2AAAAVE"] [Tue Aug 18 13:05:05.461302 2026] [security2:error] [pid 157386:tid 157563] [client 20.171.51.14:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ge.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk6AAAATk"] [Tue Aug 18 13:05:05.496367 2026] [security2:error] [pid 157386:tid 157545] [client 40.85.222.29:6751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk6QAAASc"] [Tue Aug 18 13:05:05.588581 2026] [security2:error] [pid 157386:tid 157580] [client 178.153.171.161:62254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk7QAAAUo"] [Tue Aug 18 13:05:05.588704 2026] [security2:error] [pid 157386:tid 157580] [client 178.153.171.161:62254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk7QAAAUo"] [Tue Aug 18 13:05:05.619628 2026] [security2:error] [pid 157386:tid 157613] [client 20.250.13.23:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/xleet.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk8AAAAWs"] [Tue Aug 18 13:05:05.666074 2026] [security2:error] [pid 157386:tid 157523] [client 20.250.13.23:22824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk8gAAARE"] [Tue Aug 18 13:05:05.672883 2026] [security2:error] [pid 157386:tid 157528] [client 102.213.179.104:63079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk8wAAARY"] [Tue Aug 18 13:05:05.672959 2026] [security2:error] [pid 157386:tid 157528] [client 102.213.179.104:63079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk8wAAARY"] [Tue Aug 18 13:05:05.705662 2026] [security2:error] [pid 157386:tid 157498] [remote 216.38.28.47:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worldportas.com.br"] [uri "/wp-login.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk9AABT28"] [Tue Aug 18 13:05:05.708137 2026] [security2:error] [pid 157386:tid 157527] [client 4.232.151.198:7666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ovazeuaxq.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk9QAAARU"] [Tue Aug 18 13:05:05.726103 2026] [security2:error] [pid 157386:tid 157628] [client 40.85.222.29:6783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/lddxs.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk9gAAAXo"] [Tue Aug 18 13:05:05.737574 2026] [security2:error] [pid 157386:tid 157611] [client 20.65.98.162:20639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCsU1jzAhYHVVT1Wfk9wAAAWk"] [Tue Aug 18 13:05:05.776664 2026] [security2:error] [pid 157386:tid 157641] [client 20.25.139.174:4645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/i.php"] [unique_id "aoSCsU1jzAhYHVVT1WflAQAAAYc"] [Tue Aug 18 13:05:05.798157 2026] [security2:error] [pid 157386:tid 157572] [client 20.79.204.6:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ncx.php"] [unique_id "aoSCsU1jzAhYHVVT1WflAwAAAUI"] [Tue Aug 18 13:05:05.828710 2026] [security2:error] [pid 157386:tid 157594] [client 20.124.247.79:16390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/blurbs.php"] [unique_id "aoSCsU1jzAhYHVVT1WflCAAAAVg"] [Tue Aug 18 13:05:05.832591 2026] [security2:error] [pid 157386:tid 157591] [client 20.206.73.37:35299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/gm.php"] [unique_id "aoSCsU1jzAhYHVVT1WflCQAAAVU"] [Tue Aug 18 13:05:05.888529 2026] [security2:error] [pid 157386:tid 157605] [client 20.91.215.254:3147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSCsU1jzAhYHVVT1WflDgAAAWM"] [Tue Aug 18 13:05:05.918349 2026] [security2:error] [pid 157386:tid 157640] [client 158.23.17.4:15799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pw.php"] [unique_id "aoSCsU1jzAhYHVVT1WflEAAAAYY"] [Tue Aug 18 13:05:05.925678 2026] [security2:error] [pid 157386:tid 157604] [client 68.221.73.131:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/k.php"] [unique_id "aoSCsU1jzAhYHVVT1WflEgAAAWI"] [Tue Aug 18 13:05:06.021770 2026] [security2:error] [pid 157386:tid 157529] [client 40.85.222.29:17542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/zjggu.php"] [unique_id "aoSCsk1jzAhYHVVT1WflFwAAARc"] [Tue Aug 18 13:05:06.022741 2026] [security2:error] [pid 157386:tid 157538] [client 20.65.98.162:20631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-blog.php"] [unique_id "aoSCsk1jzAhYHVVT1WflGAAAASA"] [Tue Aug 18 13:05:06.035258 2026] [security2:error] [pid 157386:tid 157525] [client 20.91.215.254:30080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSCsk1jzAhYHVVT1WflGQAAARM"] [Tue Aug 18 13:05:06.091478 2026] [security2:error] [pid 157386:tid 157599] [client 20.206.73.37:46937] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "maganmotors.com.br"] [uri "/1.php"] [unique_id "aoSCsk1jzAhYHVVT1WflGgAAAV0"] [Tue Aug 18 13:05:06.091582 2026] [security2:error] [pid 157386:tid 157599] [client 20.206.73.37:46937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/1.php"] [unique_id "aoSCsk1jzAhYHVVT1WflGgAAAV0"] [Tue Aug 18 13:05:06.101409 2026] [security2:error] [pid 157386:tid 157622] [client 132.196.30.78:27976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-good.php"] [unique_id "aoSCsk1jzAhYHVVT1WflGwAAAXQ"] [Tue Aug 18 13:05:06.121607 2026] [security2:error] [pid 157386:tid 157627] [client 40.74.65.169:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/media.php"] [unique_id "aoSCsk1jzAhYHVVT1WflHQAAAXk"] [Tue Aug 18 13:05:06.148601 2026] [security2:error] [pid 157386:tid 157510] [remote 82.165.89.134:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.89.165.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/wp-login.php"] [unique_id "aoSCsk1jzAhYHVVT1WflHgABW3s"] [Tue Aug 18 13:05:06.150570 2026] [security2:error] [pid 157386:tid 157632] [client 20.206.73.37:65171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/222.php"] [unique_id "aoSCsk1jzAhYHVVT1WflIAAAAX4"] [Tue Aug 18 13:05:06.156242 2026] [security2:error] [pid 157386:tid 157621] [client 74.248.130.103:48978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/11.php"] [unique_id "aoSCsk1jzAhYHVVT1WflIQAAAXM"] [Tue Aug 18 13:05:06.164908 2026] [security2:error] [pid 157386:tid 157545] [client 20.124.247.79:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/bajah.php"] [unique_id "aoSCsk1jzAhYHVVT1WflIgAAASc"] [Tue Aug 18 13:05:06.214498 2026] [security2:error] [pid 157386:tid 157564] [client 20.38.3.247:16919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/av.php"] [unique_id "aoSCsk1jzAhYHVVT1WflJQAAATo"] [Tue Aug 18 13:05:06.232451 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.100.201:23996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ah25.php"] [unique_id "aoSCsk1jzAhYHVVT1WflJgAAAS8"] [Tue Aug 18 13:05:06.233036 2026] [security2:error] [pid 157386:tid 157586] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsk1jzAhYHVVT1WflJAABUEM"] [Tue Aug 18 13:05:06.268035 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:06.268288 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:06.300665 2026] [security2:error] [pid 157386:tid 157524] [client 213.35.127.232:49551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCsk1jzAhYHVVT1WflKQAAARI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:06.331379 2026] [security2:error] [pid 157386:tid 157643] [client 18.192.166.72:3092] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSCsk1jzAhYHVVT1WflHwAAAYk"], referer: https://www.institutoferiani.com.br [Tue Aug 18 13:05:06.340539 2026] [security2:error] [pid 157386:tid 157523] [client 68.221.73.131:47394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/fpwch.php"] [unique_id "aoSCsk1jzAhYHVVT1WflLQAAARE"] [Tue Aug 18 13:05:06.344332 2026] [security2:error] [pid 157386:tid 157542] [client 4.223.113.180:40473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSCsk1jzAhYHVVT1WflIwAAASQ"] [Tue Aug 18 13:05:06.350748 2026] [security2:error] [pid 157386:tid 157585] [client 40.85.222.29:6607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/dlvqo.php"] [unique_id "aoSCsk1jzAhYHVVT1WflLwAAAU8"] [Tue Aug 18 13:05:06.380931 2026] [security2:error] [pid 157386:tid 157546] [client 20.171.51.14:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kl.php"] [unique_id "aoSCsk1jzAhYHVVT1WflMwAAASg"] [Tue Aug 18 13:05:06.410029 2026] [security2:error] [pid 157386:tid 157563] [client 4.232.151.198:25271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/wp-load.php"] [unique_id "aoSCsk1jzAhYHVVT1WflNQAAATk"] [Tue Aug 18 13:05:06.433145 2026] [security2:error] [pid 157386:tid 157641] [client 158.23.17.4:40384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fn.php"] [unique_id "aoSCsk1jzAhYHVVT1WflNgAAAYc"] [Tue Aug 18 13:05:06.558166 2026] [security2:error] [pid 157386:tid 157598] [client 20.65.98.162:7118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCsk1jzAhYHVVT1WflOgAAAVw"] [Tue Aug 18 13:05:06.660813 2026] [security2:error] [pid 157386:tid 157617] [client 40.85.222.29:17560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCsk1jzAhYHVVT1WflPQAAAW8"] [Tue Aug 18 13:05:06.676403 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sy.php"] [unique_id "aoSCsk1jzAhYHVVT1WflQAAAAYY"] [Tue Aug 18 13:05:06.683449 2026] [security2:error] [pid 157386:tid 157609] [client 20.91.215.254:23715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/f7.php"] [unique_id "aoSCsk1jzAhYHVVT1WflQQAAAWc"] [Tue Aug 18 13:05:06.697622 2026] [security2:error] [pid 157386:tid 157600] [client 40.85.222.29:17595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/pkmoj.php"] [unique_id "aoSCsk1jzAhYHVVT1WflQgAAAV4"] [Tue Aug 18 13:05:06.708767 2026] [security2:error] [pid 157386:tid 157552] [client 20.124.247.79:16503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/h.php"] [unique_id "aoSCsk1jzAhYHVVT1WflQwAAAS4"] [Tue Aug 18 13:05:06.732905 2026] [security2:error] [pid 157386:tid 157567] [client 20.250.13.23:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/404.php"] [unique_id "aoSCsk1jzAhYHVVT1WflRAAAAT0"] [Tue Aug 18 13:05:06.735251 2026] [security2:error] [pid 157386:tid 157602] [client 20.91.215.254:45317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCsk1jzAhYHVVT1WflRQAAAWA"] [Tue Aug 18 13:05:06.747374 2026] [security2:error] [pid 157386:tid 157575] [client 213.202.253.4:56017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSCsk1jzAhYHVVT1WflRgAAAUU"], referer: www.google.com [Tue Aug 18 13:05:06.752254 2026] [security2:error] [pid 157386:tid 157588] [client 20.151.109.219:21938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/filesystems.php"] [unique_id "aoSCsk1jzAhYHVVT1WflSAAAAVI"] [Tue Aug 18 13:05:06.768298 2026] [security2:error] [pid 157386:tid 157587] [client 20.250.13.23:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp.php"] [unique_id "aoSCsk1jzAhYHVVT1WflSQAAAVE"] [Tue Aug 18 13:05:06.805800 2026] [security2:error] [pid 157386:tid 157538] [client 20.65.98.162:20611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCsk1jzAhYHVVT1WflSwAAASA"] [Tue Aug 18 13:05:06.811283 2026] [security2:error] [pid 157386:tid 157525] [client 40.74.65.169:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/admin.php"] [unique_id "aoSCsk1jzAhYHVVT1WflTAAAARM"] [Tue Aug 18 13:05:06.832213 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:24042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/ano.php"] [unique_id "aoSCsk1jzAhYHVVT1WflTQAAARg"] [Tue Aug 18 13:05:06.848458 2026] [security2:error] [pid 157386:tid 157604] [client 20.25.139.174:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCsk1jzAhYHVVT1WflTgAAAWI"] [Tue Aug 18 13:05:06.875474 2026] [security2:error] [pid 157386:tid 157568] [client 132.196.30.78:19878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/simple.php"] [unique_id "aoSCsk1jzAhYHVVT1WflUAAAAT4"] [Tue Aug 18 13:05:06.974661 2026] [security2:error] [pid 157386:tid 157493] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsk1jzAhYHVVT1WflUwABVmo"] [Tue Aug 18 13:05:06.974820 2026] [security2:error] [pid 157386:tid 157592] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCsk1jzAhYHVVT1WflUwABVmo"] [Tue Aug 18 13:05:06.980820 2026] [security2:error] [pid 157386:tid 157564] [client 40.74.65.169:16263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/puc.php"] [unique_id "aoSCsk1jzAhYHVVT1WflVAAAATo"] [Tue Aug 18 13:05:06.981343 2026] [security2:error] [pid 157386:tid 157553] [client 40.85.222.29:6731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/kopyw.php"] [unique_id "aoSCsk1jzAhYHVVT1WflVQAAAS8"] [Tue Aug 18 13:05:07.006548 2026] [security2:error] [pid 157386:tid 157550] [client 40.85.222.29:6776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCs01jzAhYHVVT1WflVwAAASw"] [Tue Aug 18 13:05:07.081108 2026] [security2:error] [pid 157386:tid 157643] [client 20.65.98.162:20710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/222.php"] [unique_id "aoSCs01jzAhYHVVT1WflYAAAAYk"] [Tue Aug 18 13:05:07.127134 2026] [security2:error] [pid 157386:tid 157581] [client 20.251.48.93:8556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/file1221.php"] [unique_id "aoSCs01jzAhYHVVT1WflaAAAAUs"] [Tue Aug 18 13:05:07.129937 2026] [security2:error] [pid 157386:tid 157584] [client 4.232.151.198:25265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/alfa-v4.php"] [unique_id "aoSCs01jzAhYHVVT1WflaQAAAU4"] [Tue Aug 18 13:05:07.146344 2026] [security2:error] [pid 157386:tid 157608] [client 68.221.73.131:35254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCs01jzAhYHVVT1WflagAAAWY"] [Tue Aug 18 13:05:07.169116 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:07.169377 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:07.219700 2026] [security2:error] [pid 157386:tid 157641] [client 20.171.51.14:13390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gs.php"] [unique_id "aoSCs01jzAhYHVVT1WflcgAAAYc"] [Tue Aug 18 13:05:07.228393 2026] [security2:error] [pid 157386:tid 157577] [client 20.206.73.37:43219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/uwu.php"] [unique_id "aoSCs01jzAhYHVVT1WfldAAAAUc"] [Tue Aug 18 13:05:07.279239 2026] [security2:error] [pid 157386:tid 157427] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCs01jzAhYHVVT1WfldgABQyg"] [Tue Aug 18 13:05:07.279382 2026] [security2:error] [pid 157386:tid 157573] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCs01jzAhYHVVT1WfldgABQyg"] [Tue Aug 18 13:05:07.294168 2026] [security2:error] [pid 157386:tid 157611] [client 40.85.222.29:6756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCs01jzAhYHVVT1WfldwAAAWk"] [Tue Aug 18 13:05:07.298214 2026] [security2:error] [pid 157386:tid 157601] [client 20.124.247.79:16472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/ano.php"] [unique_id "aoSCs01jzAhYHVVT1WfleAAAAV8"] [Tue Aug 18 13:05:07.317946 2026] [security2:error] [pid 157386:tid 157612] [client 213.35.127.232:49791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCs01jzAhYHVVT1WfleQAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:07.323497 2026] [security2:error] [pid 157386:tid 157596] [client 40.85.222.29:6778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/zznmg.php"] [unique_id "aoSCs01jzAhYHVVT1WflegAAAVo"] [Tue Aug 18 13:05:07.340710 2026] [security2:error] [pid 157386:tid 157598] [client 20.206.73.37:16843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/file5.php"] [unique_id "aoSCs01jzAhYHVVT1WflfAAAAVw"] [Tue Aug 18 13:05:07.351418 2026] [security2:error] [pid 157386:tid 157563] [client 20.25.139.174:4567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCs01jzAhYHVVT1WflfwAAATk"] [Tue Aug 18 13:05:07.383635 2026] [security2:error] [pid 157386:tid 157610] [client 158.23.17.4:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kf.php"] [unique_id "aoSCs01jzAhYHVVT1WflgQAAAWg"] [Tue Aug 18 13:05:07.385956 2026] [security2:error] [pid 157386:tid 157549] [client 20.91.215.254:30098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/photo.php"] [unique_id "aoSCs01jzAhYHVVT1WflhAAAASs"] [Tue Aug 18 13:05:07.429509 2026] [security2:error] [pid 157386:tid 157639] [client 20.104.100.201:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/nwflm.php"] [unique_id "aoSCs01jzAhYHVVT1WflhQAAAYU"] [Tue Aug 18 13:05:07.459525 2026] [security2:error] [pid 157386:tid 157616] [client 20.65.98.162:20667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSCs01jzAhYHVVT1WflhgAAAW4"] [Tue Aug 18 13:05:07.471889 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:07.472157 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:07.494417 2026] [security2:error] [pid 157386:tid 157602] [client 40.74.65.169:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/mac.php"] [unique_id "aoSCs01jzAhYHVVT1WfliQAAAWA"] [Tue Aug 18 13:05:07.498584 2026] [security2:error] [pid 157386:tid 157535] [client 4.223.113.180:17908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/gebase.php69"] [unique_id "aoSCs01jzAhYHVVT1WfligAAAR0"] [Tue Aug 18 13:05:07.508930 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:21935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSCs01jzAhYHVVT1WfljAAAAVE"] [Tue Aug 18 13:05:07.568948 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:61299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/82.php"] [unique_id "aoSCs01jzAhYHVVT1WfljgAAARM"] [Tue Aug 18 13:05:07.598862 2026] [security2:error] [pid 157386:tid 157590] [client 20.91.215.254:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSCs01jzAhYHVVT1WfljwAAAVQ"] [Tue Aug 18 13:05:07.626098 2026] [security2:error] [pid 157386:tid 157589] [client 40.85.222.29:17593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCs01jzAhYHVVT1WflmQAAAVM"] [Tue Aug 18 13:05:07.643138 2026] [security2:error] [pid 157386:tid 157642] [client 40.85.222.29:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/bhfnd.php"] [unique_id "aoSCs01jzAhYHVVT1WflnAAAAYg"] [Tue Aug 18 13:05:07.750104 2026] [security2:error] [pid 157386:tid 157580] [client 20.65.98.162:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCs01jzAhYHVVT1WflogAAAUo"] [Tue Aug 18 13:05:07.772956 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:07.773221 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:07.836438 2026] [security2:error] [pid 157386:tid 157568] [client 4.232.151.198:42743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/abby.php"] [unique_id "aoSCs01jzAhYHVVT1WflpgAAAT4"] [Tue Aug 18 13:05:07.898131 2026] [security2:error] [pid 157386:tid 157519] [client 20.250.13.23:40406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/155.php"] [unique_id "aoSCs01jzAhYHVVT1WflqAAAAQ0"] [Tue Aug 18 13:05:07.902494 2026] [security2:error] [pid 157386:tid 157537] [client 20.206.73.37:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/coffee.php"] [unique_id "aoSCs01jzAhYHVVT1WflqQAAAR8"] [Tue Aug 18 13:05:07.909689 2026] [security2:error] [pid 157386:tid 157541] [client 20.124.247.79:16490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/ai.php"] [unique_id "aoSCs01jzAhYHVVT1WflqgAAASM"] [Tue Aug 18 13:05:07.914628 2026] [security2:error] [pid 157386:tid 157643] [client 168.62.48.100:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCs01jzAhYHVVT1WflqwAAAYk"] [Tue Aug 18 13:05:07.928545 2026] [security2:error] [pid 157386:tid 157586] [client 20.25.139.174:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCs01jzAhYHVVT1WflrAAAAVA"] [Tue Aug 18 13:05:07.939328 2026] [security2:error] [pid 157386:tid 157614] [client 40.85.222.29:17559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/qfvqu.php"] [unique_id "aoSCs01jzAhYHVVT1WflrQAAAWw"] [Tue Aug 18 13:05:07.969737 2026] [security2:error] [pid 157386:tid 157528] [client 68.221.73.131:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/blurbs.php"] [unique_id "aoSCs01jzAhYHVVT1WflrgAAARY"] [Tue Aug 18 13:05:08.039646 2026] [security2:error] [pid 157386:tid 157620] [client 20.91.215.254:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-aa.php"] [unique_id "aoSCtE1jzAhYHVVT1WflrwAAAXI"] [Tue Aug 18 13:05:08.074062 2026] [authz_core:error] [pid 157386:tid 157453] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:08.074338 2026] [authz_core:error] [pid 157386:tid 157453] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:08.133580 2026] [security2:error] [pid 157386:tid 157571] [client 20.171.51.14:38723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lw.php"] [unique_id "aoSCtE1jzAhYHVVT1WflswAAAUE"] [Tue Aug 18 13:05:08.140424 2026] [security2:error] [pid 157386:tid 157557] [client 103.184.169.37:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.169.184.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1WfltAAAATM"] [Tue Aug 18 13:05:08.140524 2026] [security2:error] [pid 157386:tid 157557] [client 103.184.169.37:43954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mudancassilvano.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1WfltAAAATM"] [Tue Aug 18 13:05:08.145367 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.100.201:23874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/wp-load.php"] [unique_id "aoSCtE1jzAhYHVVT1WfltQAAAWk"] [Tue Aug 18 13:05:08.186584 2026] [security2:error] [pid 157386:tid 157554] [client 20.251.48.93:50399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/nox.php"] [unique_id "aoSCtE1jzAhYHVVT1WfltwAAATA"] [Tue Aug 18 13:05:08.187433 2026] [security2:error] [pid 157386:tid 157547] [client 132.196.30.78:28027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/edit-tags.php"] [unique_id "aoSCtE1jzAhYHVVT1WfluAAAASk"] [Tue Aug 18 13:05:08.189307 2026] [security2:error] [pid 157386:tid 157565] [client 40.74.65.169:60165] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/1.php"] [unique_id "aoSCtE1jzAhYHVVT1WflugAAATs"] [Tue Aug 18 13:05:08.189391 2026] [security2:error] [pid 157386:tid 157565] [client 40.74.65.169:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/1.php"] [unique_id "aoSCtE1jzAhYHVVT1WflugAAATs"] [Tue Aug 18 13:05:08.212166 2026] [security2:error] [pid 157386:tid 157572] [client 40.85.222.29:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCtE1jzAhYHVVT1WfluwAAAUI"] [Tue Aug 18 13:05:08.226697 2026] [security2:error] [pid 157386:tid 157598] [client 20.65.98.162:20670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp.php"] [unique_id "aoSCtE1jzAhYHVVT1WflvAAAAVw"] [Tue Aug 18 13:05:08.256941 2026] [security2:error] [pid 157386:tid 157597] [client 40.85.222.29:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/oivcl.php"] [unique_id "aoSCtE1jzAhYHVVT1WflvgAAAVs"] [Tue Aug 18 13:05:08.291140 2026] [security2:error] [pid 157386:tid 157595] [client 20.91.215.254:3196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSCtE1jzAhYHVVT1WflvwAAAVk"] [Tue Aug 18 13:05:08.299778 2026] [security2:error] [pid 157386:tid 157578] [client 20.250.13.23:17146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/wk/index.php"] [unique_id "aoSCtE1jzAhYHVVT1WflwAAAAUg"] [Tue Aug 18 13:05:08.307173 2026] [security2:error] [pid 157386:tid 157566] [client 20.79.204.6:9696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCtE1jzAhYHVVT1WflwQAAATw"] [Tue Aug 18 13:05:08.320961 2026] [security2:error] [pid 157386:tid 157634] [client 4.223.113.180:46489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/akcc.php"] [unique_id "aoSCtE1jzAhYHVVT1WflwgAAAYA"] [Tue Aug 18 13:05:08.346769 2026] [security2:error] [pid 157386:tid 157526] [client 213.35.127.232:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCtE1jzAhYHVVT1WflwwAAARQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:08.374809 2026] [authz_core:error] [pid 157386:tid 157443] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:08.375065 2026] [authz_core:error] [pid 157386:tid 157443] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:08.485179 2026] [security2:error] [pid 157386:tid 157527] [client 4.232.151.198:24199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/Mhbgf.php"] [unique_id "aoSCtE1jzAhYHVVT1WflzAAAARU"] [Tue Aug 18 13:05:08.485976 2026] [security2:error] [pid 157386:tid 157536] [client 20.65.98.162:20643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/i.php"] [unique_id "aoSCtE1jzAhYHVVT1WflzQAAAR4"] [Tue Aug 18 13:05:08.497475 2026] [security2:error] [pid 157386:tid 157555] [client 20.104.100.201:23861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/jj.php"] [unique_id "aoSCtE1jzAhYHVVT1WflzgAAATE"] [Tue Aug 18 13:05:08.500179 2026] [security2:error] [pid 157386:tid 157642] [client 40.85.222.29:6759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCtE1jzAhYHVVT1WflzwAAAYg"] [Tue Aug 18 13:05:08.545316 2026] [security2:error] [pid 157386:tid 157567] [client 20.25.139.174:4485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/NewFile.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl0AAAAT0"] [Tue Aug 18 13:05:08.605399 2026] [security2:error] [pid 157386:tid 157606] [client 103.120.71.157:65242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl0QAAAWQ"] [Tue Aug 18 13:05:08.605516 2026] [security2:error] [pid 157386:tid 157606] [client 103.120.71.157:65242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl0QAAAWQ"] [Tue Aug 18 13:05:08.638946 2026] [security2:error] [pid 157386:tid 157524] [client 40.85.222.29:6723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/zugvi.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl0wAAARI"] [Tue Aug 18 13:05:08.660757 2026] [autoindex:error] [pid 157386:tid 157399] [remote 20.79.204.6:0] AH01276: Cannot serve directory /home3/cp39imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:08.664387 2026] [security2:error] [pid 157386:tid 157523] [client 197.184.64.235:42674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl1QAAARE"] [Tue Aug 18 13:05:08.664525 2026] [security2:error] [pid 157386:tid 157523] [client 197.184.64.235:42674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl1QAAARE"] [Tue Aug 18 13:05:08.687537 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:08.687814 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:08.692674 2026] [security2:error] [pid 157386:tid 157584] [client 5.31.227.224:1408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl1wAAAU4"] [Tue Aug 18 13:05:08.692853 2026] [security2:error] [pid 157386:tid 157584] [client 5.31.227.224:1408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl1wAAAU4"] [Tue Aug 18 13:05:08.697851 2026] [security2:error] [pid 157386:tid 157588] [client 158.23.17.4:14046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/su.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl2AAAAVI"] [Tue Aug 18 13:05:08.732152 2026] [security2:error] [pid 157386:tid 157621] [client 20.91.215.254:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/d.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl2QAAAXM"] [Tue Aug 18 13:05:08.735778 2026] [security2:error] [pid 157386:tid 157581] [client 4.232.151.198:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/k.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl2gAAAUs"] [Tue Aug 18 13:05:08.739424 2026] [security2:error] [pid 157386:tid 157528] [client 20.65.98.162:20673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/abcd.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl2wAAARY"] [Tue Aug 18 13:05:08.781539 2026] [security2:error] [pid 157386:tid 157614] [client 138.36.100.162:42328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl3AAAAWw"] [Tue Aug 18 13:05:08.781895 2026] [security2:error] [pid 157386:tid 157614] [client 138.36.100.162:42328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl3AAAAWw"] [Tue Aug 18 13:05:08.784945 2026] [security2:error] [pid 157386:tid 157624] [client 20.171.51.14:13388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vj.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl3QAAAXY"] [Tue Aug 18 13:05:08.789734 2026] [security2:error] [pid 157386:tid 157543] [client 68.221.73.131:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/100.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl3gAAASU"] [Tue Aug 18 13:05:08.833227 2026] [security2:error] [pid 157386:tid 157620] [client 20.151.109.219:13784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/57.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl4QAAAXI"] [Tue Aug 18 13:05:08.846345 2026] [security2:error] [pid 157386:tid 157600] [client 20.151.109.219:58715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/phpstatus.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl4gAAAV4"] [Tue Aug 18 13:05:08.848098 2026] [security2:error] [pid 157386:tid 157635] [client 40.85.222.29:17599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl4wAAAYE"] [Tue Aug 18 13:05:08.887001 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/coffee.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl5AAAAS8"] [Tue Aug 18 13:05:08.896268 2026] [security2:error] [pid 157386:tid 157573] [client 20.124.247.79:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/sf.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl5QAAAUM"] [Tue Aug 18 13:05:08.948141 2026] [security2:error] [pid 157386:tid 157603] [client 20.91.215.254:3198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl5gAAAWE"] [Tue Aug 18 13:05:08.962173 2026] [security2:error] [pid 157386:tid 157472] [remote 115.146.125.52:44276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl5wABd1U"] [Tue Aug 18 13:05:08.978185 2026] [security2:error] [pid 157386:tid 157547] [client 40.85.222.29:6594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wsrer.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl6QAAASk"] [Tue Aug 18 13:05:08.991282 2026] [security2:error] [pid 157386:tid 157572] [client 20.65.98.162:20666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCtE1jzAhYHVVT1Wfl6gAAAUI"] [Tue Aug 18 13:05:09.065053 2026] [security2:error] [pid 157386:tid 157579] [client 196.12.128.158:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl6wAAAUk"] [Tue Aug 18 13:05:09.065187 2026] [security2:error] [pid 157386:tid 157579] [client 196.12.128.158:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl6wAAAUk"] [Tue Aug 18 13:05:09.072337 2026] [security2:error] [pid 157386:tid 157531] [client 20.250.13.23:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/about.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl7QAAARk"] [Tue Aug 18 13:05:09.074396 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.100.201:23821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/img.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl7gAAATY"] [Tue Aug 18 13:05:09.122785 2026] [security2:error] [pid 157386:tid 157601] [client 20.25.139.174:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl7wAAAV8"] [Tue Aug 18 13:05:09.161875 2026] [security2:error] [pid 157386:tid 157582] [client 4.232.151.198:39578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl8AAAAUw"] [Tue Aug 18 13:05:09.164285 2026] [security2:error] [pid 157386:tid 157634] [client 40.85.222.29:17545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl8QAAAYA"] [Tue Aug 18 13:05:09.204252 2026] [security2:error] [pid 157386:tid 157639] [client 20.206.73.37:3510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl8wAAAYU"] [Tue Aug 18 13:05:09.239579 2026] [security2:error] [pid 157386:tid 157552] [client 20.251.48.93:8562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/akismet.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl9AAAAS4"] [Tue Aug 18 13:05:09.278655 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:09.278922 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:09.287175 2026] [security2:error] [pid 157386:tid 157529] [client 40.85.222.29:6758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/ucpfr.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl9wAAARc"] [Tue Aug 18 13:05:09.346134 2026] [security2:error] [pid 157386:tid 157590] [client 20.65.98.162:20645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl-AAAAVQ"] [Tue Aug 18 13:05:09.356331 2026] [security2:error] [pid 157386:tid 157627] [client 20.124.247.79:16403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/xx.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl-gAAAXk"] [Tue Aug 18 13:05:09.363521 2026] [security2:error] [pid 157386:tid 157626] [client 213.35.127.232:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl-wAAAXg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:09.388749 2026] [security2:error] [pid 157386:tid 157527] [client 20.171.51.14:12065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mimes.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl_AAAARU"] [Tue Aug 18 13:05:09.443933 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:17034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ah.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl_QAAARo"] [Tue Aug 18 13:05:09.445480 2026] [security2:error] [pid 157386:tid 157520] [client 20.151.109.219:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/del.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl_gAAAQ4"] [Tue Aug 18 13:05:09.496546 2026] [security2:error] [pid 157386:tid 157578] [client 132.196.30.78:19882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/u.php"] [unique_id "aoSCtU1jzAhYHVVT1Wfl_wAAAUg"] [Tue Aug 18 13:05:09.501283 2026] [security2:error] [pid 157386:tid 157539] [client 40.85.222.29:6622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmAAAAASE"] [Tue Aug 18 13:05:09.530817 2026] [security2:error] [pid 157386:tid 157616] [client 20.91.215.254:15648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmAgAAAW4"] [Tue Aug 18 13:05:09.536499 2026] [security2:error] [pid 157386:tid 157533] [client 20.250.13.23:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/96i.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmAwAAARs"] [Tue Aug 18 13:05:09.556587 2026] [security2:error] [pid 157386:tid 157605] [client 223.185.37.47:19090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmBQAAAWM"] [Tue Aug 18 13:05:09.556737 2026] [security2:error] [pid 157386:tid 157605] [client 223.185.37.47:19090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmBQAAAWM"] [Tue Aug 18 13:05:09.566143 2026] [security2:error] [pid 157386:tid 157618] [client 40.74.65.169:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmBgAAAXA"] [Tue Aug 18 13:05:09.580604 2026] [authz_core:error] [pid 157386:tid 157471] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:09.580870 2026] [authz_core:error] [pid 157386:tid 157471] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:09.584975 2026] [security2:error] [pid 157386:tid 157540] [client 20.91.215.254:3136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmCAAAASI"] [Tue Aug 18 13:05:09.639303 2026] [security2:error] [pid 157386:tid 157581] [client 20.65.98.162:20633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmDQAAAUs"] [Tue Aug 18 13:05:09.677688 2026] [security2:error] [pid 157386:tid 157613] [client 20.104.100.201:23983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tentacledigital.com.br"] [uri "/we.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmEQAAAWs"] [Tue Aug 18 13:05:09.751444 2026] [security2:error] [pid 157386:tid 157553] [client 40.85.222.29:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/yxijx.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmFAAAAS8"] [Tue Aug 18 13:05:09.759512 2026] [security2:error] [pid 157386:tid 157580] [client 4.223.113.180:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmFQAAAUo"] [Tue Aug 18 13:05:09.801777 2026] [cgid:error] [pid 157386:tid 157603] [client 169.58.72.248:61272] AH01265: stderr from /home2/tecnomorcom/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:05:09.828573 2026] [security2:error] [pid 157386:tid 157535] [client 40.85.222.29:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/rezor.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmGAAAAR0"] [Tue Aug 18 13:05:09.832293 2026] [security2:error] [pid 157386:tid 157628] [client 74.248.130.103:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/File.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmGQAAAXo"] [Tue Aug 18 13:05:09.870512 2026] [security2:error] [pid 157386:tid 157612] [client 158.23.17.4:48976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wp-key.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmGwAAAWo"] [Tue Aug 18 13:05:09.883221 2026] [authz_core:error] [pid 157386:tid 157512] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:09.883631 2026] [authz_core:error] [pid 157386:tid 157512] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:09.894066 2026] [security2:error] [pid 157386:tid 157638] [client 4.232.151.198:25250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/mimetypes.inc.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmHwAAAYQ"] [Tue Aug 18 13:05:09.908233 2026] [security2:error] [pid 157386:tid 157643] [client 20.25.139.174:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmIAAAAYk"] [Tue Aug 18 13:05:09.966500 2026] [security2:error] [pid 157386:tid 157579] [client 20.171.51.14:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ni.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmIQAAAUk"] [Tue Aug 18 13:05:09.987765 2026] [security2:error] [pid 157386:tid 157560] [client 168.62.48.100:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCtU1jzAhYHVVT1WfmIwAAATY"] [Tue Aug 18 13:05:10.017918 2026] [security2:error] [pid 157386:tid 157566] [client 68.221.73.131:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/ccc.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmJQAAATw"] [Tue Aug 18 13:05:10.019195 2026] [security2:error] [pid 157386:tid 157582] [client 20.65.98.162:7124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/simple.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmJgAAAUw"] [Tue Aug 18 13:05:10.172827 2026] [security2:error] [pid 157386:tid 157597] [client 20.91.215.254:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmKQAAAVs"] [Tue Aug 18 13:05:10.179705 2026] [security2:error] [pid 157386:tid 157631] [client 20.124.247.79:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/uwu.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmKwAAAX0"] [Tue Aug 18 13:05:10.182142 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:10.182432 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:10.188052 2026] [security2:error] [pid 157386:tid 157626] [client 40.85.222.29:6600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmLAAAAXg"] [Tue Aug 18 13:05:10.221298 2026] [security2:error] [pid 157386:tid 157527] [client 40.85.222.29:17591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/zwlsv.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmLQAAARU"] [Tue Aug 18 13:05:10.223942 2026] [security2:error] [pid 157386:tid 157601] [client 20.91.215.254:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmLgAAAV8"] [Tue Aug 18 13:05:10.262798 2026] [security2:error] [pid 157386:tid 157551] [client 40.74.65.169:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmNQAAAS0"] [Tue Aug 18 13:05:10.367097 2026] [security2:error] [pid 157386:tid 157640] [client 20.206.73.37:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmOQAAAYY"] [Tue Aug 18 13:05:10.378821 2026] [security2:error] [pid 157386:tid 157639] [client 213.35.127.232:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmOgAAAYU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:10.398511 2026] [security2:error] [pid 157386:tid 157538] [client 20.206.73.37:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/mac.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmOwAAASA"] [Tue Aug 18 13:05:10.416984 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vw.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmPAAAAVc"] [Tue Aug 18 13:05:10.425661 2026] [security2:error] [pid 157386:tid 157532] [client 20.25.139.174:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/themes.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmPwAAARo"] [Tue Aug 18 13:05:10.462076 2026] [security2:error] [pid 157386:tid 157621] [client 40.85.222.29:6604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmQQAAAXM"] [Tue Aug 18 13:05:10.485458 2026] [security2:error] [pid 157386:tid 157624] [client 20.65.98.162:20715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/chosen.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmRAAAAXY"] [Tue Aug 18 13:05:10.510907 2026] [security2:error] [pid 157386:tid 157543] [client 158.23.17.4:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gg.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmRgAAASU"] [Tue Aug 18 13:05:10.610233 2026] [security2:error] [pid 157386:tid 157523] [client 4.232.151.198:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/banners/autoload_classmap.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmRwAAARE"] [Tue Aug 18 13:05:10.617035 2026] [security2:error] [pid 157386:tid 157522] [client 74.248.130.103:48983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/fi22.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmSAAAARA"] [Tue Aug 18 13:05:10.655186 2026] [security2:error] [pid 157386:tid 157530] [client 20.171.51.14:13380] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cubangovidros.com.br"] [uri "/1.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmSQAAARg"] [Tue Aug 18 13:05:10.655281 2026] [security2:error] [pid 157386:tid 157530] [client 20.171.51.14:13380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/1.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmSQAAARg"] [Tue Aug 18 13:05:10.656432 2026] [security2:error] [pid 157386:tid 157553] [client 40.85.222.29:6651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/jrpga.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmSgAAAS8"] [Tue Aug 18 13:05:10.703671 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:43228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/signon.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmSwAAAU4"] [Tue Aug 18 13:05:10.726925 2026] [security2:error] [pid 157386:tid 157548] [client 132.196.30.78:27969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmTAAAASo"] [Tue Aug 18 13:05:10.783892 2026] [security2:error] [pid 157386:tid 157547] [client 68.221.73.131:47377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/get.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmUAAAASk"] [Tue Aug 18 13:05:10.784689 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:10.784945 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:10.811568 2026] [security2:error] [pid 157386:tid 157630] [client 20.91.215.254:30093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmUQAAAXw"] [Tue Aug 18 13:05:10.879144 2026] [security2:error] [pid 157386:tid 157643] [client 40.85.222.29:6736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/index/function.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmUwAAAYk"] [Tue Aug 18 13:05:10.880018 2026] [security2:error] [pid 157386:tid 157556] [client 20.65.98.162:7143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/als.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmVAAAATI"] [Tue Aug 18 13:05:10.881574 2026] [security2:error] [pid 157386:tid 157632] [client 20.91.215.254:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSCtk1jzAhYHVVT1WfmVQAAAX4"] [Tue Aug 18 13:05:10.948285 2026] [security2:error] [pid 157386:tid 157595] [client 40.74.65.169:60189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/yj09.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmVwAAAVk"] [Tue Aug 18 13:05:10.949645 2026] [security2:error] [pid 157386:tid 157628] [client 20.25.139.174:4678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/cv.php"] [unique_id "aoSCtk1jzAhYHVVT1WfmWAAAAXo"] [Tue Aug 18 13:05:11.035417 2026] [security2:error] [pid 157386:tid 157602] [client 20.151.109.219:21909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/moderator.php"] [unique_id "aoSCt01jzAhYHVVT1WfmXAAAAWA"] [Tue Aug 18 13:05:11.077156 2026] [security2:error] [pid 157386:tid 157637] [client 20.38.3.247:40047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/images.php"] [unique_id "aoSCt01jzAhYHVVT1WfmXQAAAYM"] [Tue Aug 18 13:05:11.129160 2026] [security2:error] [pid 157386:tid 157620] [client 20.206.73.37:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/xyn.php"] [unique_id "aoSCt01jzAhYHVVT1WfmYQAAAXI"] [Tue Aug 18 13:05:11.149959 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/88.php"] [unique_id "aoSCt01jzAhYHVVT1WfmYwAAATU"] [Tue Aug 18 13:05:11.190108 2026] [security2:error] [pid 157386:tid 157536] [client 40.85.222.29:17543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSCt01jzAhYHVVT1WfmZAAAAR4"] [Tue Aug 18 13:05:11.192665 2026] [security2:error] [pid 157386:tid 157525] [client 20.65.98.162:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/nox.php"] [unique_id "aoSCt01jzAhYHVVT1WfmZQAAARM"] [Tue Aug 18 13:05:11.302969 2026] [security2:error] [pid 157386:tid 157629] [client 132.196.30.78:19855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/h.php"] [unique_id "aoSCt01jzAhYHVVT1WfmZwAAAXs"] [Tue Aug 18 13:05:11.311793 2026] [security2:error] [pid 157386:tid 157567] [client 20.251.48.93:46272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/admin.php"] [unique_id "aoSCt01jzAhYHVVT1WfmaAAAAT0"] [Tue Aug 18 13:05:11.326152 2026] [security2:error] [pid 157386:tid 157585] [client 4.232.151.198:26733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/qfunctions.php"] [unique_id "aoSCt01jzAhYHVVT1WfmaQAAAU8"] [Tue Aug 18 13:05:11.337621 2026] [security2:error] [pid 157386:tid 157539] [client 40.85.222.29:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCt01jzAhYHVVT1WfmagAAASE"] [Tue Aug 18 13:05:11.351798 2026] [security2:error] [pid 157386:tid 157610] [client 86.120.159.145:19647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCt01jzAhYHVVT1WfmawAAAWg"] [Tue Aug 18 13:05:11.351894 2026] [security2:error] [pid 157386:tid 157610] [client 86.120.159.145:19647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCt01jzAhYHVVT1WfmawAAAWg"] [Tue Aug 18 13:05:11.392796 2026] [security2:error] [pid 157386:tid 157526] [client 213.35.127.232:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCt01jzAhYHVVT1WfmbQAAARQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:11.393439 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:11.393843 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:11.413356 2026] [security2:error] [pid 157386:tid 157538] [client 158.23.17.4:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gi.php"] [unique_id "aoSCt01jzAhYHVVT1WfmcAAAASA"] [Tue Aug 18 13:05:11.448095 2026] [security2:error] [pid 157386:tid 157578] [client 20.124.247.79:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/signon.php"] [unique_id "aoSCt01jzAhYHVVT1WfmcgAAAUg"] [Tue Aug 18 13:05:11.453611 2026] [security2:error] [pid 157386:tid 157588] [client 20.65.98.162:7147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file59.php"] [unique_id "aoSCt01jzAhYHVVT1WfmcwAAAVI"] [Tue Aug 18 13:05:11.497464 2026] [security2:error] [pid 157386:tid 157551] [client 20.91.215.254:30083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCt01jzAhYHVVT1WfmdgAAAS0"] [Tue Aug 18 13:05:11.550554 2026] [security2:error] [pid 157386:tid 157616] [client 20.91.215.254:24269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSCt01jzAhYHVVT1WfmeQAAAW4"] [Tue Aug 18 13:05:11.567985 2026] [security2:error] [pid 157386:tid 157523] [client 20.151.109.219:21913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lj.php"] [unique_id "aoSCt01jzAhYHVVT1WfmfQAAARE"] [Tue Aug 18 13:05:11.588971 2026] [security2:error] [pid 157386:tid 157530] [client 68.221.73.131:47418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/images.php"] [unique_id "aoSCt01jzAhYHVVT1WfmfwAAARg"] [Tue Aug 18 13:05:11.611047 2026] [security2:error] [pid 157386:tid 157580] [client 40.74.65.169:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/inso.php"] [unique_id "aoSCt01jzAhYHVVT1WfmhgAAAUo"] [Tue Aug 18 13:05:11.625599 2026] [security2:error] [pid 157386:tid 157571] [client 40.74.65.169:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/scxy.php"] [unique_id "aoSCt01jzAhYHVVT1WfmhwAAAUE"] [Tue Aug 18 13:05:11.634382 2026] [security2:error] [pid 157386:tid 157636] [client 20.79.204.6:9328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wso.php"] [unique_id "aoSCt01jzAhYHVVT1WfmiAAAAYI"] [Tue Aug 18 13:05:11.673984 2026] [authz_core:error] [pid 157386:tid 157486] [remote 57.141.22.121:60148] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:11.674255 2026] [authz_core:error] [pid 157386:tid 157486] [remote 57.141.22.121:60148] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:11.689646 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:11.689957 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:11.696195 2026] [security2:error] [pid 157386:tid 157625] [client 40.85.222.29:6738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/Cachex.php"] [unique_id "aoSCt01jzAhYHVVT1WfmjAAAAXc"] [Tue Aug 18 13:05:11.702301 2026] [security2:error] [pid 157386:tid 157524] [client 20.206.73.37:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/mgrr.php"] [unique_id "aoSCt01jzAhYHVVT1WfmjwAAARI"] [Tue Aug 18 13:05:11.723376 2026] [security2:error] [pid 157386:tid 157614] [client 68.221.73.131:61288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/dex.php"] [unique_id "aoSCt01jzAhYHVVT1WfmkgAAAWw"] [Tue Aug 18 13:05:11.770045 2026] [security2:error] [pid 157386:tid 157643] [client 20.65.98.162:7146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/admin.php"] [unique_id "aoSCt01jzAhYHVVT1WfmkwAAAYk"] [Tue Aug 18 13:05:11.775231 2026] [security2:error] [pid 157386:tid 157556] [client 20.171.51.14:41673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/hj.php"] [unique_id "aoSCt01jzAhYHVVT1WfmlAAAATI"] [Tue Aug 18 13:05:11.802784 2026] [security2:error] [pid 157386:tid 157599] [client 40.85.222.29:6633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/nwwha.php"] [unique_id "aoSCt01jzAhYHVVT1WfmlgAAAV0"] [Tue Aug 18 13:05:11.917055 2026] [security2:error] [pid 157386:tid 157577] [client 132.196.30.78:27979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ms-edit.php"] [unique_id "aoSCt01jzAhYHVVT1WfmmAAAAUc"] [Tue Aug 18 13:05:11.974038 2026] [security2:error] [pid 157386:tid 157542] [client 4.232.151.198:25252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/hehehehe.php"] [unique_id "aoSCt01jzAhYHVVT1WfmmwAAASQ"] [Tue Aug 18 13:05:11.980013 2026] [security2:error] [pid 157386:tid 157576] [client 4.232.151.198:11868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCt01jzAhYHVVT1WfmngAAAUY"] [Tue Aug 18 13:05:11.991041 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:11.991311 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:12.018960 2026] [security2:error] [pid 157386:tid 157544] [client 49.37.150.8:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmoAAAASY"] [Tue Aug 18 13:05:12.019103 2026] [security2:error] [pid 157386:tid 157544] [client 49.37.150.8:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmoAAAASY"] [Tue Aug 18 13:05:12.062267 2026] [security2:error] [pid 157386:tid 157569] [client 40.85.222.29:17555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmogAAAT8"] [Tue Aug 18 13:05:12.071036 2026] [security2:error] [pid 157386:tid 157527] [client 20.65.98.162:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/aa2.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmpAAAARU"] [Tue Aug 18 13:05:12.077918 2026] [security2:error] [pid 157386:tid 157611] [client 20.250.13.23:24730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/term.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmpQAAAWk"] [Tue Aug 18 13:05:12.089338 2026] [security2:error] [pid 157386:tid 157601] [client 216.244.66.243:42342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/coroalove+plataforma-1/"] [unique_id "aoSCuE1jzAhYHVVT1WfmqAAAAV8"] [Tue Aug 18 13:05:12.089404 2026] [security2:error] [pid 157386:tid 157601] [client 216.244.66.243:42342] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/coroalove+plataforma-1/"] [unique_id "aoSCuE1jzAhYHVVT1WfmqAAAAV8"] [Tue Aug 18 13:05:12.108650 2026] [security2:error] [pid 157386:tid 157591] [client 20.25.139.174:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmqQAAAVU"] [Tue Aug 18 13:05:12.163291 2026] [security2:error] [pid 157386:tid 157529] [client 20.91.215.254:30096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmqwAAARc"] [Tue Aug 18 13:05:12.263799 2026] [security2:error] [pid 157386:tid 157564] [client 20.250.13.23:28251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/as.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmsgAAATo"] [Tue Aug 18 13:05:12.288215 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:17629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kh.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmtAAAASU"] [Tue Aug 18 13:05:12.294760 2026] [authz_core:error] [pid 157386:tid 157425] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:12.295024 2026] [authz_core:error] [pid 157386:tid 157425] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:12.299801 2026] [security2:error] [pid 157386:tid 157623] [client 40.74.65.169:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmtQAAAXU"] [Tue Aug 18 13:05:12.319003 2026] [security2:error] [pid 157386:tid 157596] [client 20.65.98.162:20682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/xamp.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmtgAAAVo"] [Tue Aug 18 13:05:12.358090 2026] [security2:error] [pid 157386:tid 157594] [client 40.85.222.29:6774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/opsqt.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmtwAAAVg"] [Tue Aug 18 13:05:12.366555 2026] [security2:error] [pid 157386:tid 157567] [client 20.91.215.254:45337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmuAAAAT0"] [Tue Aug 18 13:05:12.376940 2026] [security2:error] [pid 157386:tid 157516] [client 168.62.48.100:12271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmuQAAAQo"] [Tue Aug 18 13:05:12.377242 2026] [security2:error] [pid 157386:tid 157616] [client 20.171.51.14:38756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ij.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmugAAAW4"] [Tue Aug 18 13:05:12.397821 2026] [security2:error] [pid 157386:tid 157523] [client 158.23.17.4:40413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pz.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmvAAAARE"] [Tue Aug 18 13:05:12.409122 2026] [security2:error] [pid 157386:tid 157536] [client 213.35.127.232:50923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmvgAAAR4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:12.416451 2026] [security2:error] [pid 157386:tid 157639] [client 20.79.204.6:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/zup.php73"] [unique_id "aoSCuE1jzAhYHVVT1WfmvwAAAYU"] [Tue Aug 18 13:05:12.430987 2026] [security2:error] [pid 157386:tid 157583] [client 68.221.73.131:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/alls.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmwQAAAU0"] [Tue Aug 18 13:05:12.439202 2026] [security2:error] [pid 157386:tid 157618] [client 40.85.222.29:17552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmwgAAAXA"] [Tue Aug 18 13:05:12.544116 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/infoinfo.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmxgAAAXw"] [Tue Aug 18 13:05:12.560648 2026] [security2:error] [pid 157386:tid 157565] [client 20.65.98.162:20683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/bless.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmxwAAATs"] [Tue Aug 18 13:05:12.593740 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:12.594006 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:12.608838 2026] [security2:error] [pid 157386:tid 157571] [client 132.196.30.78:27983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/a7.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmywAAAUE"] [Tue Aug 18 13:05:12.615487 2026] [security2:error] [pid 157386:tid 157521] [client 4.232.151.198:7760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/delpaths.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmzAAAAQ8"] [Tue Aug 18 13:05:12.679855 2026] [security2:error] [pid 157386:tid 157635] [client 20.25.139.174:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ws83.php"] [unique_id "aoSCuE1jzAhYHVVT1WfmzQAAAYE"] [Tue Aug 18 13:05:12.798232 2026] [security2:error] [pid 157386:tid 157572] [client 20.91.215.254:30113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/abc.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm0QAAAUI"] [Tue Aug 18 13:05:12.818349 2026] [security2:error] [pid 157386:tid 157559] [client 40.85.222.29:17580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/jvcpa.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm0gAAATU"] [Tue Aug 18 13:05:12.822768 2026] [security2:error] [pid 157386:tid 157590] [client 40.85.222.29:6754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm0wAAAVQ"] [Tue Aug 18 13:05:12.831840 2026] [security2:error] [pid 157386:tid 157563] [client 20.65.98.162:20718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file25.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm1AAAATk"] [Tue Aug 18 13:05:12.832598 2026] [security2:error] [pid 157386:tid 157527] [client 74.248.130.103:50113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm1QAAARU"] [Tue Aug 18 13:05:12.871033 2026] [security2:error] [pid 157386:tid 157611] [client 20.206.73.37:3457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/55.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm1wAAAWk"] [Tue Aug 18 13:05:12.896505 2026] [authz_core:error] [pid 157386:tid 157427] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:12.896919 2026] [authz_core:error] [pid 157386:tid 157427] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:12.902007 2026] [security2:error] [pid 157386:tid 157626] [client 20.171.51.14:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ud.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm2QAAAXg"] [Tue Aug 18 13:05:12.987109 2026] [security2:error] [pid 157386:tid 157584] [client 40.74.65.169:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm2gAAAU4"] [Tue Aug 18 13:05:12.987968 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/c99shell.php"] [unique_id "aoSCuE1jzAhYHVVT1Wfm2wAAASE"] [Tue Aug 18 13:05:13.028943 2026] [security2:error] [pid 157386:tid 157566] [client 20.91.215.254:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm3AAAATw"] [Tue Aug 18 13:05:13.095816 2026] [security2:error] [pid 157386:tid 157605] [client 20.65.98.162:20657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file15.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm3gAAAWM"] [Tue Aug 18 13:05:13.115585 2026] [security2:error] [pid 157386:tid 157588] [client 68.155.154.236:14301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm3wAAAVI"] [Tue Aug 18 13:05:13.196251 2026] [authz_core:error] [pid 157386:tid 157491] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:13.196605 2026] [authz_core:error] [pid 157386:tid 157491] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:13.224355 2026] [security2:error] [pid 157386:tid 157557] [client 40.85.222.29:7131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm4gAAATM"] [Tue Aug 18 13:05:13.247148 2026] [security2:error] [pid 157386:tid 157574] [client 40.85.222.29:6722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm5AAAAUQ"] [Tue Aug 18 13:05:13.256049 2026] [security2:error] [pid 157386:tid 157640] [client 132.196.30.78:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/manager.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm5wAAAYY"] [Tue Aug 18 13:05:13.259106 2026] [security2:error] [pid 157386:tid 157531] [client 4.232.151.198:7698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/sindicat.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm6AAAARk"] [Tue Aug 18 13:05:13.262448 2026] [security2:error] [pid 157386:tid 157567] [client 158.23.17.4:46816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kk.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm6QAAAT0"] [Tue Aug 18 13:05:13.272977 2026] [security2:error] [pid 157386:tid 157538] [client 20.25.139.174:4618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/atex1.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm6gAAASA"] [Tue Aug 18 13:05:13.285661 2026] [security2:error] [pid 157386:tid 157516] [client 20.151.109.219:17608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/jb.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm6wAAAQo"] [Tue Aug 18 13:05:13.351166 2026] [security2:error] [pid 157386:tid 157613] [client 20.65.98.162:20616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/f35.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm7QAAAWs"] [Tue Aug 18 13:05:13.381896 2026] [security2:error] [pid 157386:tid 157621] [client 74.7.175.135:41028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.gabrielabrandao.adv.br"] [uri "/index.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm5QABcz4"] [Tue Aug 18 13:05:13.421484 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm7wAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:13.437128 2026] [security2:error] [pid 157386:tid 157619] [client 20.171.51.14:47115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ip.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm8AAAAXE"] [Tue Aug 18 13:05:13.443922 2026] [security2:error] [pid 157386:tid 157610] [client 20.91.215.254:16586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/sf.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm8QAAAWg"] [Tue Aug 18 13:05:13.449467 2026] [security2:error] [pid 157386:tid 157524] [client 20.124.247.79:16507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/file61.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm8gAAARI"] [Tue Aug 18 13:05:13.495871 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:13.496116 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:13.527344 2026] [security2:error] [pid 157386:tid 157565] [client 40.85.222.29:6742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm9QAAATs"] [Tue Aug 18 13:05:13.527488 2026] [security2:error] [pid 157386:tid 157615] [client 40.85.222.29:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm9gAAAW0"] [Tue Aug 18 13:05:13.571940 2026] [security2:error] [pid 157386:tid 157532] [client 20.206.73.37:15720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/inso.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm9wAAARo"] [Tue Aug 18 13:05:13.594367 2026] [security2:error] [pid 157386:tid 157632] [client 20.65.98.162:20636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-load.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm-gAAAX4"] [Tue Aug 18 13:05:13.617859 2026] [security2:error] [pid 157386:tid 157489] [remote 162.214.205.212:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-login.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm_AABKmY"] [Tue Aug 18 13:05:13.656899 2026] [security2:error] [pid 157386:tid 157642] [client 20.91.215.254:45371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm_QAAAYg"] [Tue Aug 18 13:05:13.671385 2026] [security2:error] [pid 157386:tid 157638] [client 40.74.65.169:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/blurbs.php"] [unique_id "aoSCuU1jzAhYHVVT1Wfm_gAAAYQ"] [Tue Aug 18 13:05:13.774859 2026] [security2:error] [pid 157386:tid 157627] [client 20.250.13.23:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnAQAAAXk"] [Tue Aug 18 13:05:13.807517 2026] [security2:error] [pid 157386:tid 157517] [client 40.85.222.29:6775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnBAAAAQs"] [Tue Aug 18 13:05:13.838445 2026] [security2:error] [pid 157386:tid 157555] [client 20.171.51.14:58012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/99.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnBQAAATE"] [Tue Aug 18 13:05:13.841300 2026] [security2:error] [pid 157386:tid 157628] [client 20.25.139.174:4583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnBgAAAXo"] [Tue Aug 18 13:05:13.868755 2026] [security2:error] [pid 157386:tid 157591] [client 20.251.48.93:50428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.rgmadvogados.adv.br"] [uri "/ajax.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnBwAAAVU"] [Tue Aug 18 13:05:13.883486 2026] [security2:error] [pid 157386:tid 157635] [client 132.196.30.78:19873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/w1.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnCAAAAYE"] [Tue Aug 18 13:05:13.929093 2026] [security2:error] [pid 157386:tid 157550] [client 20.206.73.37:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/ajax.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnDQAAASw"] [Tue Aug 18 13:05:13.944904 2026] [security2:error] [pid 157386:tid 157576] [client 4.232.151.198:18527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/user/flower.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnDwAAAUY"] [Tue Aug 18 13:05:13.959978 2026] [security2:error] [pid 157386:tid 157533] [client 68.221.73.131:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/coffexium.php"] [unique_id "aoSCuU1jzAhYHVVT1WfnEAAAARs"] [Tue Aug 18 13:05:14.001250 2026] [security2:error] [pid 157386:tid 157602] [client 20.206.73.37:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/ws55.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnEQAAAWA"] [Tue Aug 18 13:05:14.005672 2026] [security2:error] [pid 157386:tid 157604] [client 40.85.222.29:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnEgAAAWI"] [Tue Aug 18 13:05:14.036089 2026] [security2:error] [pid 157386:tid 157534] [client 68.155.154.236:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnGQAAARw"] [Tue Aug 18 13:05:14.070206 2026] [security2:error] [pid 157386:tid 157557] [client 20.151.109.219:56000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/do.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnGgAAATM"] [Tue Aug 18 13:05:14.126953 2026] [security2:error] [pid 157386:tid 157640] [client 40.85.222.29:6609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnHAAAAYY"] [Tue Aug 18 13:05:14.142354 2026] [security2:error] [pid 157386:tid 157531] [client 20.206.73.37:43201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/file61.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnHQAAARk"] [Tue Aug 18 13:05:14.156591 2026] [security2:error] [pid 157386:tid 157629] [client 20.91.215.254:7913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/chosen.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnHgAAAXs"] [Tue Aug 18 13:05:14.183516 2026] [security2:error] [pid 157386:tid 157554] [client 20.65.98.162:7127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnIAAAATA"] [Tue Aug 18 13:05:14.201645 2026] [security2:error] [pid 157386:tid 157625] [client 20.79.204.6:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/k.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnIQAAAXc"] [Tue Aug 18 13:05:14.267145 2026] [security2:error] [pid 157386:tid 157465] [remote 95.111.251.70:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cropman.com.br"] [uri "/wp-login.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnIgABOU4"] [Tue Aug 18 13:05:14.275983 2026] [security2:error] [pid 157386:tid 157593] [client 213.202.253.4:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/filefuns.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnJAAAAVc"], referer: www.google.com [Tue Aug 18 13:05:14.296454 2026] [security2:error] [pid 157386:tid 157585] [client 20.151.109.219:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/profiler.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnJQAAAU8"] [Tue Aug 18 13:05:14.306766 2026] [security2:error] [pid 157386:tid 157623] [client 20.91.215.254:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnJgAAAXU"] [Tue Aug 18 13:05:14.328303 2026] [security2:error] [pid 157386:tid 157536] [client 20.171.51.14:6595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/er.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnJwAAAR4"] [Tue Aug 18 13:05:14.355407 2026] [security2:error] [pid 157386:tid 157519] [client 40.74.65.169:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/bajah.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnKAAAAQ0"] [Tue Aug 18 13:05:14.363822 2026] [security2:error] [pid 157386:tid 157637] [client 4.223.113.180:43829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/updates.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnKQAAAYM"] [Tue Aug 18 13:05:14.406175 2026] [security2:error] [pid 157386:tid 157549] [client 40.85.222.29:17558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnLAAAASs"] [Tue Aug 18 13:05:14.417545 2026] [security2:error] [pid 157386:tid 157616] [client 20.25.139.174:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/w.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnLgAAAW4"] [Tue Aug 18 13:05:14.438715 2026] [security2:error] [pid 157386:tid 157596] [client 213.35.127.232:51355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnLwAAAVo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:14.462561 2026] [security2:error] [pid 157386:tid 157547] [client 40.85.222.29:6750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnMQAAASk"] [Tue Aug 18 13:05:14.512501 2026] [security2:error] [pid 157386:tid 157518] [client 20.206.73.37:33721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/yj09.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnMwAAAQw"] [Tue Aug 18 13:05:14.520317 2026] [security2:error] [pid 157386:tid 157542] [client 20.206.73.37:35275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/m.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnNQAAASQ"] [Tue Aug 18 13:05:14.523952 2026] [security2:error] [pid 157386:tid 157571] [client 20.65.98.162:20685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/aaa.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnNwAAAUE"] [Tue Aug 18 13:05:14.533875 2026] [security2:error] [pid 157386:tid 157543] [client 149.34.210.141:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnPQAAASU"] [Tue Aug 18 13:05:14.573023 2026] [security2:error] [pid 157386:tid 157592] [client 68.221.73.131:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/puc.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnQQAAAVY"] [Tue Aug 18 13:05:14.626474 2026] [security2:error] [pid 157386:tid 157608] [client 132.196.30.78:20050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-login.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnRAAAAWY"] [Tue Aug 18 13:05:14.667778 2026] [security2:error] [pid 157386:tid 157524] [client 4.232.151.198:7971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/Diff/Renderer/about.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnRQAAARI"] [Tue Aug 18 13:05:14.675692 2026] [security2:error] [pid 157386:tid 157540] [client 20.250.13.23:33628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/min.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnRgAAASI"] [Tue Aug 18 13:05:14.699248 2026] [authz_core:error] [pid 157386:tid 157481] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:14.699569 2026] [authz_core:error] [pid 157386:tid 157481] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:14.716337 2026] [security2:error] [pid 157386:tid 157527] [client 20.171.51.14:18666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/qk.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnSgAAARU"] [Tue Aug 18 13:05:14.724914 2026] [security2:error] [pid 157386:tid 157611] [client 168.62.48.100:4098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnSwAAAWk"] [Tue Aug 18 13:05:14.731363 2026] [security2:error] [pid 157386:tid 157628] [client 40.85.222.29:6779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnTAAAAXo"] [Tue Aug 18 13:05:14.743913 2026] [security2:error] [pid 157386:tid 157635] [client 68.221.73.131:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/red.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnTQAAAYE"] [Tue Aug 18 13:05:14.770057 2026] [security2:error] [pid 157386:tid 157626] [client 20.65.98.162:20728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/gecko.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnTwAAAXg"] [Tue Aug 18 13:05:14.797078 2026] [security2:error] [pid 157386:tid 157584] [client 40.85.222.29:6753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnUQAAAU4"] [Tue Aug 18 13:05:14.799016 2026] [security2:error] [pid 157386:tid 157543] [client 149.34.210.141:56738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnPQAAASU"] [Tue Aug 18 13:05:14.866613 2026] [security2:error] [pid 157386:tid 157620] [client 20.91.215.254:15668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/u.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnWgAAAXI"] [Tue Aug 18 13:05:14.885870 2026] [security2:error] [pid 157386:tid 157575] [client 40.74.65.169:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/aa.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnWwAAAUU"] [Tue Aug 18 13:05:14.892876 2026] [security2:error] [pid 157386:tid 157574] [client 20.151.109.219:13786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/findes.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnXAAAAUQ"] [Tue Aug 18 13:05:14.943124 2026] [security2:error] [pid 157386:tid 157555] [client 20.91.215.254:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnYAAAATE"] [Tue Aug 18 13:05:14.983549 2026] [security2:error] [pid 157386:tid 157554] [client 68.155.154.236:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/weozh.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnYgAAATA"] [Tue Aug 18 13:05:14.996076 2026] [security2:error] [pid 157386:tid 157568] [client 20.25.139.174:4666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/archive.php"] [unique_id "aoSCuk1jzAhYHVVT1WfnZAAAAT4"] [Tue Aug 18 13:05:15.002161 2026] [authz_core:error] [pid 157386:tid 157506] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:15.002488 2026] [authz_core:error] [pid 157386:tid 157506] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:15.029150 2026] [security2:error] [pid 157386:tid 157603] [client 20.65.98.162:20677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/xiugai.php"] [unique_id "aoSCu01jzAhYHVVT1WfnZgAAAWE"] [Tue Aug 18 13:05:15.051675 2026] [security2:error] [pid 157386:tid 157593] [client 40.74.65.169:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/domvf.php"] [unique_id "aoSCu01jzAhYHVVT1WfnaAAAAVc"] [Tue Aug 18 13:05:15.066533 2026] [security2:error] [pid 157386:tid 157523] [client 40.85.222.29:7110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCu01jzAhYHVVT1WfnagAAARE"] [Tue Aug 18 13:05:15.071160 2026] [security2:error] [pid 157386:tid 157551] [client 40.85.222.29:17564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCu01jzAhYHVVT1WfnawAAAS0"] [Tue Aug 18 13:05:15.117485 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:58742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/yw.php"] [unique_id "aoSCu01jzAhYHVVT1WfnbgAAAXM"] [Tue Aug 18 13:05:15.223963 2026] [security2:error] [pid 157386:tid 157566] [client 20.79.204.6:9282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-blink.php"] [unique_id "aoSCu01jzAhYHVVT1WfndQAAATw"] [Tue Aug 18 13:05:15.229931 2026] [security2:error] [pid 157386:tid 157538] [client 20.250.13.23:16036] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSCu01jzAhYHVVT1WfndgAAASA"] [Tue Aug 18 13:05:15.230036 2026] [security2:error] [pid 157386:tid 157538] [client 20.250.13.23:16036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/1.php"] [unique_id "aoSCu01jzAhYHVVT1WfndgAAASA"] [Tue Aug 18 13:05:15.262403 2026] [security2:error] [pid 157386:tid 157589] [client 132.196.30.78:19849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/default.php"] [unique_id "aoSCu01jzAhYHVVT1WfneQAAAVM"] [Tue Aug 18 13:05:15.275264 2026] [security2:error] [pid 157386:tid 157532] [client 20.171.51.14:38749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSCu01jzAhYHVVT1WfnegAAARo"] [Tue Aug 18 13:05:15.283473 2026] [security2:error] [pid 157386:tid 157570] [client 158.23.17.4:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/phpcheck.php"] [unique_id "aoSCu01jzAhYHVVT1WfnewAAAUA"] [Tue Aug 18 13:05:15.303471 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:15.303734 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:15.313269 2026] [security2:error] [pid 157386:tid 157518] [client 20.65.98.162:7158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/adminner.php"] [unique_id "aoSCu01jzAhYHVVT1WfnfQAAAQw"] [Tue Aug 18 13:05:15.348865 2026] [security2:error] [pid 157386:tid 157556] [client 40.85.222.29:7116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCu01jzAhYHVVT1WfngAAAATI"] [Tue Aug 18 13:05:15.363244 2026] [security2:error] [pid 157386:tid 157623] [client 4.232.151.198:22184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-setting.php"] [unique_id "aoSCu01jzAhYHVVT1WfnggAAAXU"] [Tue Aug 18 13:05:15.414457 2026] [security2:error] [pid 157386:tid 157548] [client 40.85.222.29:6592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCu01jzAhYHVVT1WfnhAAAASo"] [Tue Aug 18 13:05:15.456183 2026] [security2:error] [pid 157386:tid 157519] [client 213.35.127.232:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCu01jzAhYHVVT1WfniAAAAQ0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:15.493190 2026] [security2:error] [pid 157386:tid 157580] [client 20.206.73.37:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/scxy.php"] [unique_id "aoSCu01jzAhYHVVT1WfniQAAAUo"] [Tue Aug 18 13:05:15.568838 2026] [security2:error] [pid 157386:tid 157571] [client 20.25.139.174:4487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/bless.php"] [unique_id "aoSCu01jzAhYHVVT1WfnjgAAAUE"] [Tue Aug 18 13:05:15.596835 2026] [security2:error] [pid 157386:tid 157632] [client 20.91.215.254:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSCu01jzAhYHVVT1WfnkAAAAX4"] [Tue Aug 18 13:05:15.608543 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:15.608977 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:15.616317 2026] [security2:error] [pid 157386:tid 157635] [client 20.65.98.162:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file1221.php"] [unique_id "aoSCu01jzAhYHVVT1WfnkgAAAYE"] [Tue Aug 18 13:05:15.641997 2026] [autoindex:error] [pid 157386:tid 157542] [client 20.91.215.254:16582] AH01276: Cannot serve directory /home3/pletud/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:15.651079 2026] [security2:error] [pid 157386:tid 157604] [client 157.20.138.62:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCu01jzAhYHVVT1WfnlAAAAWI"] [Tue Aug 18 13:05:15.651202 2026] [security2:error] [pid 157386:tid 157604] [client 157.20.138.62:61218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCu01jzAhYHVVT1WfnlAAAAWI"] [Tue Aug 18 13:05:15.670452 2026] [security2:error] [pid 157386:tid 157558] [client 40.85.222.29:6740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCu01jzAhYHVVT1WfnlgAAATQ"] [Tue Aug 18 13:05:15.718192 2026] [security2:error] [pid 157386:tid 157577] [client 40.85.222.29:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCu01jzAhYHVVT1WfnmgAAAUc"] [Tue Aug 18 13:05:15.735378 2026] [security2:error] [pid 157386:tid 157598] [client 40.74.65.169:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/fpwch.php"] [unique_id "aoSCu01jzAhYHVVT1WfnmwAAAVw"] [Tue Aug 18 13:05:15.775263 2026] [security2:error] [pid 157386:tid 157579] [client 20.206.73.37:65164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ops.php"] [unique_id "aoSCu01jzAhYHVVT1WfnnAAAAUk"] [Tue Aug 18 13:05:15.821116 2026] [security2:error] [pid 157386:tid 157602] [client 68.155.154.236:14260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/rymmm.php"] [unique_id "aoSCu01jzAhYHVVT1WfnngAAAWA"] [Tue Aug 18 13:05:15.851335 2026] [security2:error] [pid 157386:tid 157624] [client 20.171.51.14:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fs.php"] [unique_id "aoSCu01jzAhYHVVT1WfnnwAAAXY"] [Tue Aug 18 13:05:15.858868 2026] [security2:error] [pid 157386:tid 157534] [client 168.62.48.100:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCu01jzAhYHVVT1WfnoAAAARw"] [Tue Aug 18 13:05:15.859836 2026] [security2:error] [pid 157386:tid 157575] [client 20.91.215.254:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/customize.php"] [unique_id "aoSCu01jzAhYHVVT1WfnoQAAAUU"] [Tue Aug 18 13:05:15.878389 2026] [security2:error] [pid 157386:tid 157552] [client 158.23.17.4:40419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/dg.php"] [unique_id "aoSCu01jzAhYHVVT1WfnowAAAS4"] [Tue Aug 18 13:05:15.886697 2026] [security2:error] [pid 157386:tid 157574] [client 20.124.247.79:16497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/copypaths.php"] [unique_id "aoSCu01jzAhYHVVT1WfnpAAAAUQ"] [Tue Aug 18 13:05:15.897410 2026] [security2:error] [pid 157386:tid 157531] [client 20.65.98.162:20669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/inx.php"] [unique_id "aoSCu01jzAhYHVVT1WfnpQAAARk"] [Tue Aug 18 13:05:15.905108 2026] [authz_core:error] [pid 157386:tid 157487] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:15.905393 2026] [authz_core:error] [pid 157386:tid 157487] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:15.992124 2026] [security2:error] [pid 157386:tid 157546] [client 40.85.222.29:7139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCu01jzAhYHVVT1WfnqwAAASg"] [Tue Aug 18 13:05:16.016085 2026] [security2:error] [pid 157386:tid 157607] [client 132.196.30.78:27981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/i.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnrAAAAWU"] [Tue Aug 18 13:05:16.053611 2026] [security2:error] [pid 157386:tid 157631] [client 4.232.151.198:18529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnrQAAAX0"] [Tue Aug 18 13:05:16.099440 2026] [security2:error] [pid 157386:tid 157522] [client 20.151.109.219:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/fedora.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnsAAAARA"] [Tue Aug 18 13:05:16.100628 2026] [security2:error] [pid 157386:tid 157600] [client 20.151.109.219:13765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/qh.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnsQAAAV4"] [Tue Aug 18 13:05:16.101600 2026] [security2:error] [pid 157386:tid 157621] [client 40.85.222.29:6746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnsgAAAXM"] [Tue Aug 18 13:05:16.168826 2026] [security2:error] [pid 157386:tid 157540] [client 178.153.171.161:48026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvE1jzAhYHVVT1WfntwAAASI"] [Tue Aug 18 13:05:16.168937 2026] [security2:error] [pid 157386:tid 157540] [client 178.153.171.161:48026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvE1jzAhYHVVT1WfntwAAASI"] [Tue Aug 18 13:05:16.175555 2026] [security2:error] [pid 157386:tid 157555] [client 20.25.139.174:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/sagax1.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnugAAATE"] [Tue Aug 18 13:05:16.179302 2026] [security2:error] [pid 157386:tid 157616] [client 20.65.98.162:20672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/reviall.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnuwAAAW4"] [Tue Aug 18 13:05:16.208953 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:16.209375 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:16.346379 2026] [security2:error] [pid 157386:tid 157532] [client 40.85.222.29:6632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnyQAAARo"] [Tue Aug 18 13:05:16.395283 2026] [security2:error] [pid 157386:tid 157583] [client 40.85.222.29:6767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCvE1jzAhYHVVT1WfnzgAAAU0"] [Tue Aug 18 13:05:16.430681 2026] [security2:error] [pid 157386:tid 157599] [client 40.74.65.169:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/adminner.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn0gAAAV0"] [Tue Aug 18 13:05:16.471571 2026] [security2:error] [pid 157386:tid 157637] [client 213.35.127.232:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn2QAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:16.487501 2026] [security2:error] [pid 157386:tid 157580] [client 20.65.98.162:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/11.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn2gAAAUo"] [Tue Aug 18 13:05:16.620949 2026] [security2:error] [pid 157386:tid 157558] [client 20.206.73.37:16837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/puc.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn5AAAATQ"] [Tue Aug 18 13:05:16.645049 2026] [security2:error] [pid 157386:tid 157577] [client 20.91.215.254:4060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn5gAAAUc"] [Tue Aug 18 13:05:16.645992 2026] [security2:error] [pid 157386:tid 157585] [client 40.85.222.29:6599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn5wAAAU8"] [Tue Aug 18 13:05:16.690244 2026] [autoindex:error] [pid 157386:tid 157591] [client 169.58.72.248:53190] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:16.696281 2026] [security2:error] [pid 157386:tid 157533] [client 20.250.13.23:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/php8.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn7QAAARs"] [Tue Aug 18 13:05:16.716210 2026] [security2:error] [pid 157386:tid 157582] [client 40.85.222.29:6617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn7gAAAUw"] [Tue Aug 18 13:05:16.730501 2026] [security2:error] [pid 157386:tid 157611] [client 4.232.151.198:19827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/maint/ajax-actions.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn8QAAAWk"] [Tue Aug 18 13:05:16.740310 2026] [security2:error] [pid 157386:tid 157528] [client 68.155.154.236:14212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/lddxs.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn8gAAARY"] [Tue Aug 18 13:05:16.744209 2026] [security2:error] [pid 157386:tid 157588] [client 158.23.17.4:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/bm.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn9AAAAVI"] [Tue Aug 18 13:05:16.761162 2026] [security2:error] [pid 157386:tid 157598] [client 138.36.100.162:41587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn9QAAAVw"] [Tue Aug 18 13:05:16.761289 2026] [security2:error] [pid 157386:tid 157598] [client 138.36.100.162:41587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn9QAAAVw"] [Tue Aug 18 13:05:16.763749 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wpc.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn9gAAAX4"] [Tue Aug 18 13:05:16.770849 2026] [security2:error] [pid 157386:tid 157597] [client 20.65.98.162:20618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/File.php"] [unique_id "aoSCvE1jzAhYHVVT1Wfn9wAAAVs"] [Tue Aug 18 13:05:16.807134 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:16.807399 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:16.861162 2026] [security2:error] [pid 157386:tid 157554] [client 20.124.247.79:16509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/bless6.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoAAAAATA"] [Tue Aug 18 13:05:16.872817 2026] [security2:error] [pid 157386:tid 157617] [client 132.196.30.78:28017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoAQAAAW8"] [Tue Aug 18 13:05:16.879575 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:10572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/path.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoAgAAAXc"] [Tue Aug 18 13:05:16.883438 2026] [security2:error] [pid 157386:tid 157564] [client 68.221.73.131:61287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/inso.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoAwAAATo"] [Tue Aug 18 13:05:16.895233 2026] [security2:error] [pid 157386:tid 157631] [client 20.151.109.219:21907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/r.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoBAAAAX0"] [Tue Aug 18 13:05:16.942845 2026] [security2:error] [pid 157386:tid 157600] [client 40.85.222.29:17566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCvE1jzAhYHVVT1WfoBwAAAV4"] [Tue Aug 18 13:05:16.950617 2026] [autoindex:error] [pid 157386:tid 157576] [client 198.235.24.173:58076] AH01276: Cannot serve directory /home4/varandasgp/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:17.028531 2026] [security2:error] [pid 157386:tid 157549] [client 20.79.204.6:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/ww5.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoDAAAASs"] [Tue Aug 18 13:05:17.038997 2026] [security2:error] [pid 157386:tid 157540] [client 68.221.73.131:38651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoDQAAASI"] [Tue Aug 18 13:05:17.054650 2026] [security2:error] [pid 157386:tid 157567] [client 20.1.169.243:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoDgAAAT0"] [Tue Aug 18 13:05:17.067587 2026] [security2:error] [pid 157386:tid 157541] [client 40.85.222.29:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoDwAAASM"] [Tue Aug 18 13:05:17.077873 2026] [security2:error] [pid 157386:tid 157630] [client 20.65.98.162:20660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/fi22.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoEAAAAXw"] [Tue Aug 18 13:05:17.078116 2026] [security2:error] [pid 157386:tid 157615] [client 20.38.3.247:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/ops.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoEQAAAW0"] [Tue Aug 18 13:05:17.110712 2026] [security2:error] [pid 157386:tid 157518] [client 40.74.65.169:60284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/abcd.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoFQAAAQw"] [Tue Aug 18 13:05:17.142168 2026] [security2:error] [pid 157386:tid 157583] [client 68.155.154.236:14274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/zjggu.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoGQAAAU0"] [Tue Aug 18 13:05:17.142275 2026] [security2:error] [pid 157386:tid 157530] [client 20.206.73.37:1897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/copypaths.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoGgAAARg"] [Tue Aug 18 13:05:17.156091 2026] [security2:error] [pid 157386:tid 157525] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoFgABE0U"] [Tue Aug 18 13:05:17.165692 2026] [security2:error] [pid 157386:tid 157537] [client 20.206.73.37:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/33.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoHQAAAR8"] [Tue Aug 18 13:05:17.184042 2026] [security2:error] [pid 157386:tid 157637] [client 168.62.48.100:4223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoHgAAAYM"] [Tue Aug 18 13:05:17.250201 2026] [security2:error] [pid 157386:tid 157606] [client 20.91.215.254:16579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/mah/function.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoIgAAAWQ"] [Tue Aug 18 13:05:17.250778 2026] [security2:error] [pid 157386:tid 157559] [client 40.85.222.29:6612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoIwAAATU"] [Tue Aug 18 13:05:17.277024 2026] [security2:error] [pid 157386:tid 157461] [remote 84.205.178.135:52995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.178.205.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faganelli.com.br.bergoninf.com"] [uri "/wp-login.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoJQABNko"] [Tue Aug 18 13:05:17.277070 2026] [security2:error] [pid 157386:tid 157547] [client 20.91.215.254:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoJgAAASk"] [Tue Aug 18 13:05:17.320048 2026] [security2:error] [pid 157386:tid 157520] [client 20.171.51.14:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/rb.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoKQAAAQ4"] [Tue Aug 18 13:05:17.364616 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/fone1.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoKgAAAQ0"] [Tue Aug 18 13:05:17.371982 2026] [security2:error] [pid 157386:tid 157599] [client 4.232.151.198:18513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-lock.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoLAAAAV0"] [Tue Aug 18 13:05:17.408561 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:17.408836 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:17.435351 2026] [security2:error] [pid 157386:tid 157579] [client 40.85.222.29:6782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoNAAAAUk"] [Tue Aug 18 13:05:17.459999 2026] [security2:error] [pid 157386:tid 157582] [client 20.65.98.162:20697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoNgAAAUw"] [Tue Aug 18 13:05:17.481431 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.130.103:22396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoOAAAAWk"] [Tue Aug 18 13:05:17.496533 2026] [security2:error] [pid 157386:tid 157593] [client 213.35.127.232:52040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoOQAAAVc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:17.505501 2026] [security2:error] [pid 157386:tid 157534] [client 102.213.179.104:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoOwAAARw"] [Tue Aug 18 13:05:17.505613 2026] [security2:error] [pid 157386:tid 157534] [client 102.213.179.104:63770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoOwAAARw"] [Tue Aug 18 13:05:17.535046 2026] [security2:error] [pid 157386:tid 157597] [client 40.85.222.29:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoPAAAAVs"] [Tue Aug 18 13:05:17.539763 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/456.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoPQAAAS4"] [Tue Aug 18 13:05:17.558951 2026] [security2:error] [pid 157386:tid 157605] [client 20.1.169.243:15557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/admin.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoQQAAAWM"] [Tue Aug 18 13:05:17.609477 2026] [security2:error] [pid 157386:tid 157526] [client 158.23.17.4:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vu.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoRAAAARQ"] [Tue Aug 18 13:05:17.609917 2026] [security2:error] [pid 157386:tid 157627] [client 132.196.30.78:19850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoRQAAAXk"] [Tue Aug 18 13:05:17.664453 2026] [security2:error] [pid 157386:tid 157428] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoTAABLCk"] [Tue Aug 18 13:05:17.664614 2026] [security2:error] [pid 157386:tid 157550] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoTAABLCk"] [Tue Aug 18 13:05:17.681588 2026] [security2:error] [pid 157386:tid 157607] [client 20.215.241.237:62992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoTQAAAWU"] [Tue Aug 18 13:05:17.708924 2026] [security2:error] [pid 157386:tid 157524] [client 68.155.154.236:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/dlvqo.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoUAAAARI"] [Tue Aug 18 13:05:17.710940 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:17.711192 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:17.718847 2026] [security2:error] [pid 157386:tid 157542] [client 20.206.73.37:3501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/ws13.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoUQAAASQ"] [Tue Aug 18 13:05:17.726695 2026] [security2:error] [pid 157386:tid 157600] [client 20.65.98.162:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoUwAAAV4"] [Tue Aug 18 13:05:17.734367 2026] [security2:error] [pid 157386:tid 157576] [client 40.85.222.29:6655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoVQAAAUY"] [Tue Aug 18 13:05:17.783200 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:58195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/f.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoWAAAASI"] [Tue Aug 18 13:05:17.783559 2026] [security2:error] [pid 157386:tid 157543] [client 40.74.65.169:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/simple.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoWQAAASU"] [Tue Aug 18 13:05:17.875472 2026] [security2:error] [pid 157386:tid 157578] [client 40.85.222.29:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoXQAAAUg"] [Tue Aug 18 13:05:17.927902 2026] [security2:error] [pid 157386:tid 157567] [client 20.1.169.243:15719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/api.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoYAAAAT0"] [Tue Aug 18 13:05:17.944068 2026] [security2:error] [pid 157386:tid 157549] [client 20.25.139.174:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ncx.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoYgAAASs"] [Tue Aug 18 13:05:17.962140 2026] [security2:error] [pid 157386:tid 157642] [client 68.221.73.131:16234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/admin.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoYwAAAYg"] [Tue Aug 18 13:05:17.996142 2026] [security2:error] [pid 157386:tid 157641] [client 20.65.98.162:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCvU1jzAhYHVVT1WfoZAAAAYc"] [Tue Aug 18 13:05:18.011769 2026] [authz_core:error] [pid 157386:tid 157485] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:18.012026 2026] [authz_core:error] [pid 157386:tid 157485] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:18.049815 2026] [security2:error] [pid 157386:tid 157566] [client 4.232.151.198:24195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/qw.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoaQAAATw"] [Tue Aug 18 13:05:18.062069 2026] [security2:error] [pid 157386:tid 157572] [client 40.85.222.29:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoagAAAUI"] [Tue Aug 18 13:05:18.062766 2026] [security2:error] [pid 157386:tid 157538] [client 20.91.215.254:30082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/filter.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoawAAASA"] [Tue Aug 18 13:05:18.069924 2026] [security2:error] [pid 157386:tid 157606] [client 20.171.51.14:6604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/37.php"] [unique_id "aoSCvk1jzAhYHVVT1WfobAAAAWQ"] [Tue Aug 18 13:05:18.080623 2026] [security2:error] [pid 157386:tid 157559] [client 20.151.109.219:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/17.php"] [unique_id "aoSCvk1jzAhYHVVT1WfobQAAATU"] [Tue Aug 18 13:05:18.140363 2026] [security2:error] [pid 157386:tid 157604] [client 20.124.247.79:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/special.php"] [unique_id "aoSCvk1jzAhYHVVT1WfocQAAAWI"] [Tue Aug 18 13:05:18.207909 2026] [security2:error] [pid 157386:tid 157591] [client 20.151.109.219:21906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/SMTP.php"] [unique_id "aoSCvk1jzAhYHVVT1WfodAAAAVU"] [Tue Aug 18 13:05:18.211906 2026] [autoindex:error] [pid 157386:tid 157539] [client 5.133.192.128:51011] AH01276: Cannot serve directory /home1/deliciacom/public_html/: No matching DirectoryIndex (public/index.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:18.216264 2026] [security2:error] [pid 157386:tid 157595] [client 20.215.241.237:11388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoeAAAAVk"] [Tue Aug 18 13:05:18.218921 2026] [security2:error] [pid 157386:tid 157626] [client 4.232.151.198:41493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/ww5.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoeQAAAXg"] [Tue Aug 18 13:05:18.224011 2026] [security2:error] [pid 157386:tid 157638] [client 132.196.30.78:19851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/gecko-new.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoegAAAYQ"] [Tue Aug 18 13:05:18.235955 2026] [security2:error] [pid 157386:tid 157553] [client 20.65.98.162:20671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoewAAAS8"] [Tue Aug 18 13:05:18.248089 2026] [security2:error] [pid 157386:tid 157582] [client 40.85.222.29:6734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCvk1jzAhYHVVT1WfofAAAAUw"] [Tue Aug 18 13:05:18.293570 2026] [security2:error] [pid 157386:tid 157599] [client 20.1.169.243:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/ms-files.php"] [unique_id "aoSCvk1jzAhYHVVT1WfofgAAAV0"] [Tue Aug 18 13:05:18.294602 2026] [security2:error] [pid 157386:tid 157534] [client 68.155.154.236:14273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/pkmoj.php"] [unique_id "aoSCvk1jzAhYHVVT1WfofwAAARw"] [Tue Aug 18 13:05:18.359574 2026] [security2:error] [pid 157386:tid 157574] [client 20.91.215.254:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoggAAAUQ"] [Tue Aug 18 13:05:18.440007 2026] [security2:error] [pid 157386:tid 157629] [client 40.85.222.29:6780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCvk1jzAhYHVVT1WfohgAAAXs"] [Tue Aug 18 13:05:18.442764 2026] [security2:error] [pid 157386:tid 157602] [client 20.25.139.174:4665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCvk1jzAhYHVVT1WfohwAAAWA"] [Tue Aug 18 13:05:18.474488 2026] [security2:error] [pid 157386:tid 157563] [client 158.23.17.4:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ic.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoigAAATk"] [Tue Aug 18 13:05:18.480978 2026] [security2:error] [pid 157386:tid 157523] [client 40.74.65.169:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/wp-manager.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoiwAAARE"] [Tue Aug 18 13:05:18.511867 2026] [security2:error] [pid 157386:tid 157542] [client 20.65.98.162:7123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSCvk1jzAhYHVVT1WfojQAAASQ"] [Tue Aug 18 13:05:18.518135 2026] [security2:error] [pid 157386:tid 157577] [client 213.35.127.232:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCvk1jzAhYHVVT1WfojgAAAUc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:18.546982 2026] [security2:error] [pid 157386:tid 157621] [client 40.85.222.29:6643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCvk1jzAhYHVVT1WfojwAAAXM"] [Tue Aug 18 13:05:18.613031 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:18.613301 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:18.646265 2026] [security2:error] [pid 157386:tid 157555] [client 20.171.51.14:38776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/md.php"] [unique_id "aoSCvk1jzAhYHVVT1WfolAAAATE"] [Tue Aug 18 13:05:18.658103 2026] [security2:error] [pid 157386:tid 157600] [client 20.1.169.243:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/plugin-install.php"] [unique_id "aoSCvk1jzAhYHVVT1WfolgAAAV4"] [Tue Aug 18 13:05:18.697710 2026] [security2:error] [pid 157386:tid 157610] [client 20.151.109.219:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/vbseo.php"] [unique_id "aoSCvk1jzAhYHVVT1WfolwAAAWg"] [Tue Aug 18 13:05:18.703897 2026] [security2:error] [pid 157386:tid 157541] [client 20.215.241.237:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCvk1jzAhYHVVT1WfomAAAASM"] [Tue Aug 18 13:05:18.721977 2026] [security2:error] [pid 157386:tid 157573] [client 20.91.215.254:22542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/input.php"] [unique_id "aoSCvk1jzAhYHVVT1WfomQAAAUM"] [Tue Aug 18 13:05:18.722958 2026] [security2:error] [pid 157386:tid 157565] [client 20.124.247.79:16484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/fz.php"] [unique_id "aoSCvk1jzAhYHVVT1WfomgAAATs"] [Tue Aug 18 13:05:18.752332 2026] [security2:error] [pid 157386:tid 157522] [client 4.232.151.198:19137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-sitemas-user.php"] [unique_id "aoSCvk1jzAhYHVVT1WfonAAAARA"] [Tue Aug 18 13:05:18.752558 2026] [security2:error] [pid 157386:tid 157630] [client 20.65.98.162:20696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSCvk1jzAhYHVVT1WfonQAAAXw"] [Tue Aug 18 13:05:18.787760 2026] [security2:error] [pid 157386:tid 157589] [client 68.155.154.236:14266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/kopyw.php"] [unique_id "aoSCvk1jzAhYHVVT1WfonwAAAVM"] [Tue Aug 18 13:05:18.790611 2026] [security2:error] [pid 157386:tid 157518] [client 40.85.222.29:6618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCvk1jzAhYHVVT1WfooAAAAQw"] [Tue Aug 18 13:05:18.806286 2026] [security2:error] [pid 157386:tid 157624] [client 40.74.65.169:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/img.php"] [unique_id "aoSCvk1jzAhYHVVT1WfooQAAAXY"] [Tue Aug 18 13:05:18.885890 2026] [security2:error] [pid 157386:tid 157637] [client 40.85.222.29:6610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCvk1jzAhYHVVT1WfopwAAAYM"] [Tue Aug 18 13:05:18.915603 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:18.915870 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:18.940071 2026] [security2:error] [pid 157386:tid 157572] [client 68.221.73.131:38036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file52.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoqgAAAUI"] [Tue Aug 18 13:05:18.994402 2026] [security2:error] [pid 157386:tid 157615] [client 20.91.215.254:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSCvk1jzAhYHVVT1WfoqwAAAW0"] [Tue Aug 18 13:05:18.998533 2026] [security2:error] [pid 157386:tid 157548] [client 20.65.98.162:7076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/media.php"] [unique_id "aoSCvk1jzAhYHVVT1WforAAAASo"] [Tue Aug 18 13:05:19.001356 2026] [security2:error] [pid 157386:tid 157551] [client 20.25.139.174:4693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wso.php"] [unique_id "aoSCvk1jzAhYHVVT1WforQAAAS0"] [Tue Aug 18 13:05:19.005401 2026] [security2:error] [pid 157386:tid 157635] [client 20.206.73.37:2876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/19.php"] [unique_id "aoSCv01jzAhYHVVT1WforgAAAYE"] [Tue Aug 18 13:05:19.074559 2026] [security2:error] [pid 157386:tid 157609] [client 132.196.30.78:28005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/NewFile.php"] [unique_id "aoSCv01jzAhYHVVT1WfosQAAAWc"] [Tue Aug 18 13:05:19.080558 2026] [security2:error] [pid 157386:tid 157591] [client 20.38.3.247:35611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/coffexium.php"] [unique_id "aoSCv01jzAhYHVVT1WfosgAAAVU"] [Tue Aug 18 13:05:19.080658 2026] [security2:error] [pid 157386:tid 157620] [client 20.79.204.6:9323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/2.php"] [unique_id "aoSCv01jzAhYHVVT1WfoswAAAXI"] [Tue Aug 18 13:05:19.097261 2026] [security2:error] [pid 157386:tid 157560] [client 20.1.169.243:15720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/wp-activate.php"] [unique_id "aoSCv01jzAhYHVVT1WfotAAAATY"] [Tue Aug 18 13:05:19.130636 2026] [security2:error] [pid 157386:tid 157597] [client 20.250.13.23:16040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/alfa.php"] [unique_id "aoSCv01jzAhYHVVT1WfotwAAAVs"] [Tue Aug 18 13:05:19.161941 2026] [security2:error] [pid 157386:tid 157528] [client 20.215.241.237:12166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/av.php"] [unique_id "aoSCv01jzAhYHVVT1WfouQAAARY"] [Tue Aug 18 13:05:19.162808 2026] [security2:error] [pid 157386:tid 157545] [client 5.31.227.224:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfougAAASc"] [Tue Aug 18 13:05:19.162908 2026] [security2:error] [pid 157386:tid 157545] [client 5.31.227.224:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfougAAASc"] [Tue Aug 18 13:05:19.163716 2026] [security2:error] [pid 157386:tid 157598] [client 40.85.222.29:6748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCv01jzAhYHVVT1WfouwAAAVw"] [Tue Aug 18 13:05:19.167154 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/xiugai.php"] [unique_id "aoSCv01jzAhYHVVT1WfovAAAARw"] [Tue Aug 18 13:05:19.170006 2026] [security2:error] [pid 157386:tid 157633] [client 40.85.222.29:6773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCv01jzAhYHVVT1WfovQAAAX8"] [Tue Aug 18 13:05:19.178536 2026] [security2:error] [pid 157386:tid 157632] [client 74.248.130.103:50142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCv01jzAhYHVVT1WfovgAAAX4"] [Tue Aug 18 13:05:19.215022 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:19.215285 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:19.224182 2026] [security2:error] [pid 157386:tid 157564] [client 197.184.64.235:42675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfowQAAATo"] [Tue Aug 18 13:05:19.224354 2026] [security2:error] [pid 157386:tid 157564] [client 197.184.64.235:42675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfowQAAATo"] [Tue Aug 18 13:05:19.327589 2026] [security2:error] [pid 157386:tid 157602] [client 20.65.98.162:7055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/inso.php"] [unique_id "aoSCv01jzAhYHVVT1WfoxAAAAWA"] [Tue Aug 18 13:05:19.349989 2026] [security2:error] [pid 157386:tid 157563] [client 20.171.51.14:38750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/iy.php"] [unique_id "aoSCv01jzAhYHVVT1WfoxQAAATk"] [Tue Aug 18 13:05:19.353131 2026] [security2:error] [pid 157386:tid 157411] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfoxgABERg"] [Tue Aug 18 13:05:19.353332 2026] [security2:error] [pid 157386:tid 157523] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1WfoxgABERg"] [Tue Aug 18 13:05:19.372014 2026] [security2:error] [pid 157386:tid 157542] [client 158.23.17.4:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ue.php"] [unique_id "aoSCv01jzAhYHVVT1WfoyAAAASQ"] [Tue Aug 18 13:05:19.410281 2026] [security2:error] [pid 157386:tid 157552] [client 20.91.215.254:22564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/jquery.php"] [unique_id "aoSCv01jzAhYHVVT1WfoygAAAS4"] [Tue Aug 18 13:05:19.443748 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/sysinfo.php"] [unique_id "aoSCv01jzAhYHVVT1WfoywAAAXM"] [Tue Aug 18 13:05:19.460901 2026] [security2:error] [pid 157386:tid 157568] [client 20.1.169.243:15730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/plugins/wp-load.php"] [unique_id "aoSCv01jzAhYHVVT1WfozQAAAT4"] [Tue Aug 18 13:05:19.473828 2026] [security2:error] [pid 157386:tid 157612] [client 40.85.222.29:17573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCv01jzAhYHVVT1WfozwAAAWo"] [Tue Aug 18 13:05:19.484705 2026] [security2:error] [pid 157386:tid 157636] [client 4.232.151.198:42960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo0AAAAYI"] [Tue Aug 18 13:05:19.485312 2026] [security2:error] [pid 157386:tid 157540] [client 68.155.154.236:14333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/zznmg.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo0QAAASI"] [Tue Aug 18 13:05:19.489496 2026] [security2:error] [pid 157386:tid 157629] [client 20.25.139.174:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/zup.php73"] [unique_id "aoSCv01jzAhYHVVT1Wfo0gAAAXs"] [Tue Aug 18 13:05:19.514793 2026] [security2:error] [pid 157386:tid 157600] [client 40.85.222.29:6720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo1AAAAV4"] [Tue Aug 18 13:05:19.536126 2026] [security2:error] [pid 157386:tid 157601] [client 103.120.71.157:39393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo1QAAAV8"] [Tue Aug 18 13:05:19.536254 2026] [security2:error] [pid 157386:tid 157601] [client 103.120.71.157:39393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo1QAAAV8"] [Tue Aug 18 13:05:19.548168 2026] [security2:error] [pid 157386:tid 157605] [client 213.35.127.232:52442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo1gAAAWM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:19.582298 2026] [security2:error] [pid 157386:tid 157581] [client 196.12.128.158:55461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo2gAAAUs"] [Tue Aug 18 13:05:19.582398 2026] [security2:error] [pid 157386:tid 157581] [client 196.12.128.158:55461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo2gAAAUs"] [Tue Aug 18 13:05:19.603360 2026] [security2:error] [pid 157386:tid 157567] [client 20.65.98.162:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/shiny.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo2wAAAT0"] [Tue Aug 18 13:05:19.679508 2026] [security2:error] [pid 157386:tid 157637] [client 74.248.130.103:34997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo6gAAAYM"] [Tue Aug 18 13:05:19.688248 2026] [security2:error] [pid 157386:tid 157641] [client 20.215.241.237:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/images.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo7AAAAYc"] [Tue Aug 18 13:05:19.735122 2026] [security2:error] [pid 157386:tid 157549] [client 20.250.13.23:7488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-content/admin.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo7wAAASs"] [Tue Aug 18 13:05:19.768639 2026] [security2:error] [pid 157386:tid 157615] [client 40.85.222.29:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo9AAAAW0"] [Tue Aug 18 13:05:19.813979 2026] [security2:error] [pid 157386:tid 157604] [client 20.124.247.79:16492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/clque.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo9gAAAWI"] [Tue Aug 18 13:05:19.815156 2026] [security2:error] [pid 157386:tid 157519] [client 20.151.109.219:27735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ev.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo9wAAAQ0"] [Tue Aug 18 13:05:19.821886 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:19.822139 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:19.824502 2026] [security2:error] [pid 157386:tid 157608] [client 20.1.169.243:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/themes/api.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo-QAAAWY"] [Tue Aug 18 13:05:19.844431 2026] [security2:error] [pid 157386:tid 157639] [client 20.65.98.162:20634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/403dd.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo-wAAAYU"] [Tue Aug 18 13:05:19.863755 2026] [security2:error] [pid 157386:tid 157616] [client 40.74.65.169:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/wp-load.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo_QAAAW4"] [Tue Aug 18 13:05:19.864168 2026] [security2:error] [pid 157386:tid 157638] [client 37.40.227.74:57194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo_gAAAYQ"] [Tue Aug 18 13:05:19.868644 2026] [security2:error] [pid 157386:tid 157638] [client 37.40.227.74:57194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCv01jzAhYHVVT1Wfo_gAAAYQ"] [Tue Aug 18 13:05:19.905076 2026] [security2:error] [pid 157386:tid 157521] [client 68.221.73.131:61261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/aa.php"] [unique_id "aoSCv01jzAhYHVVT1WfpEgAAAQ8"] [Tue Aug 18 13:05:19.921620 2026] [security2:error] [pid 157386:tid 157527] [client 40.85.222.29:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSCv01jzAhYHVVT1WfpEwAAARU"] [Tue Aug 18 13:05:19.954527 2026] [security2:error] [pid 157386:tid 157632] [client 20.91.215.254:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSCv01jzAhYHVVT1WfpFgAAAX4"] [Tue Aug 18 13:05:19.975807 2026] [security2:error] [pid 157386:tid 157596] [client 52.173.121.69:47458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCv01jzAhYHVVT1WfpGQAAAVo"] [Tue Aug 18 13:05:20.015837 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/30.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpHQAAATo"] [Tue Aug 18 13:05:20.048445 2026] [security2:error] [pid 157386:tid 157628] [client 20.25.139.174:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/k.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpIgAAAXo"] [Tue Aug 18 13:05:20.048463 2026] [security2:error] [pid 157386:tid 157585] [client 40.85.222.29:17579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpIwAAAU8"] [Tue Aug 18 13:05:20.051105 2026] [security2:error] [pid 157386:tid 157523] [client 20.171.51.14:47133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/og.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpJAAAARE"] [Tue Aug 18 13:05:20.096544 2026] [security2:error] [pid 157386:tid 157548] [client 132.196.30.78:27972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpKAAAASo"] [Tue Aug 18 13:05:20.125134 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:20.125580 2026] [authz_core:error] [pid 157386:tid 157440] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:20.141518 2026] [security2:error] [pid 157386:tid 157593] [client 20.91.215.254:16607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/media-new.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpLQAAAVc"] [Tue Aug 18 13:05:20.145601 2026] [security2:error] [pid 157386:tid 157588] [client 20.65.98.162:20656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/baba.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpLgAAAVI"] [Tue Aug 18 13:05:20.177550 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.154.236:14313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/bhfnd.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpLwAAAV4"] [Tue Aug 18 13:05:20.184939 2026] [security2:error] [pid 157386:tid 157601] [client 74.248.130.103:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpMAAAAV8"] [Tue Aug 18 13:05:20.199149 2026] [security2:error] [pid 157386:tid 157542] [client 20.1.169.243:15682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/themes/db-status.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpMQAAASQ"] [Tue Aug 18 13:05:20.201618 2026] [security2:error] [pid 157386:tid 157573] [client 20.215.241.237:45390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/ops.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpMwAAAUM"] [Tue Aug 18 13:05:20.247213 2026] [security2:error] [pid 157386:tid 157544] [client 223.185.37.47:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpNAAAASY"] [Tue Aug 18 13:05:20.247292 2026] [security2:error] [pid 157386:tid 157544] [client 223.185.37.47:23141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpNAAAASY"] [Tue Aug 18 13:05:20.251081 2026] [security2:error] [pid 157386:tid 157643] [client 20.206.73.37:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/8.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpNgAAAYk"] [Tue Aug 18 13:05:20.273344 2026] [autoindex:error] [pid 157386:tid 157526] [client 4.232.151.198:25264] AH01276: Cannot serve directory /home2/pixmid70/public_html/wp-includes/blocks/comment-template/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:20.311045 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xs.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpOAAAAXA"] [Tue Aug 18 13:05:20.358755 2026] [security2:error] [pid 157386:tid 157535] [client 40.85.222.29:7161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpOwAAAR0"] [Tue Aug 18 13:05:20.369277 2026] [security2:error] [pid 157386:tid 157543] [client 40.85.222.29:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpPAAAASU"] [Tue Aug 18 13:05:20.373280 2026] [security2:error] [pid 157386:tid 157549] [client 20.151.109.219:20850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/ppinfo.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpPQAAASs"] [Tue Aug 18 13:05:20.386464 2026] [security2:error] [pid 157386:tid 157547] [client 20.38.3.247:24266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpPwAAASk"] [Tue Aug 18 13:05:20.421638 2026] [security2:error] [pid 157386:tid 157558] [client 20.65.98.162:20609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/site.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpQQAAATQ"] [Tue Aug 18 13:05:20.423507 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:20.423766 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:20.452941 2026] [security2:error] [pid 157386:tid 157608] [client 158.23.17.4:40395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lr.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpQwAAAWY"] [Tue Aug 18 13:05:20.536864 2026] [security2:error] [pid 157386:tid 157572] [client 20.25.139.174:4636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpRgAAAUI"] [Tue Aug 18 13:05:20.554330 2026] [security2:error] [pid 157386:tid 157640] [client 4.232.151.198:11782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/2.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpRwAAAYY"] [Tue Aug 18 13:05:20.559545 2026] [security2:error] [pid 157386:tid 157579] [client 40.74.65.169:41411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/155.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpSAAAAUk"] [Tue Aug 18 13:05:20.560701 2026] [security2:error] [pid 157386:tid 157620] [client 68.221.73.131:53566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/geck.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpSQAAAXI"] [Tue Aug 18 13:05:20.564973 2026] [security2:error] [pid 157386:tid 157624] [client 213.35.127.232:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpSwAAAXY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:20.572958 2026] [security2:error] [pid 157386:tid 157619] [client 20.151.109.219:5345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pu.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpTQAAAXE"] [Tue Aug 18 13:05:20.574005 2026] [security2:error] [pid 157386:tid 157519] [client 20.1.169.243:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/themes/module.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpTgAAAQ0"] [Tue Aug 18 13:05:20.595662 2026] [security2:error] [pid 157386:tid 157533] [client 213.202.253.4:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/filefuns.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpUQAAARs"], referer: www.google.com [Tue Aug 18 13:05:20.695993 2026] [security2:error] [pid 157386:tid 157517] [client 40.85.222.29:7134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpVwAAAQs"] [Tue Aug 18 13:05:20.705142 2026] [security2:error] [pid 157386:tid 157626] [client 20.171.51.14:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lp.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpWAAAAXg"] [Tue Aug 18 13:05:20.711046 2026] [security2:error] [pid 157386:tid 157596] [client 20.65.98.162:7112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpWQAAAVo"] [Tue Aug 18 13:05:20.734753 2026] [security2:error] [pid 157386:tid 157639] [client 132.196.30.78:20263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpWwAAAYU"] [Tue Aug 18 13:05:20.775550 2026] [security2:error] [pid 157386:tid 157564] [client 68.155.154.236:14307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/qfvqu.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpXQAAATo"] [Tue Aug 18 13:05:20.793243 2026] [security2:error] [pid 157386:tid 157623] [client 20.91.215.254:3867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpXgAAAXU"] [Tue Aug 18 13:05:20.796664 2026] [security2:error] [pid 157386:tid 157529] [client 40.85.222.29:6635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpXwAAARc"] [Tue Aug 18 13:05:20.800311 2026] [security2:error] [pid 157386:tid 157602] [client 20.215.241.237:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/coffexium.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpYAAAAWA"] [Tue Aug 18 13:05:20.806186 2026] [security2:error] [pid 157386:tid 157524] [client 20.206.73.37:34769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoverona.com.br"] [uri "/packed.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpYQAAARI"] [Tue Aug 18 13:05:20.822766 2026] [security2:error] [pid 157386:tid 157528] [client 20.91.215.254:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpYwAAARY"] [Tue Aug 18 13:05:20.839668 2026] [security2:error] [pid 157386:tid 157615] [client 20.250.13.23:7544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/222.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpZQAAAW0"] [Tue Aug 18 13:05:20.952313 2026] [security2:error] [pid 157386:tid 157631] [client 20.65.98.162:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/cabs.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpawAAAX0"] [Tue Aug 18 13:05:20.957082 2026] [security2:error] [pid 157386:tid 157625] [client 20.1.169.243:15715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/languages/themes/wp-activate.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpbAAAAXc"] [Tue Aug 18 13:05:20.966264 2026] [security2:error] [pid 157386:tid 157548] [client 4.232.151.198:25264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-site-query-pic.php"] [unique_id "aoSCwE1jzAhYHVVT1WfpbQAAASo"] [Tue Aug 18 13:05:21.007658 2026] [security2:error] [pid 157386:tid 157621] [client 40.85.222.29:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpbgAAAXM"] [Tue Aug 18 13:05:21.012105 2026] [security2:error] [pid 157386:tid 157636] [client 52.173.121.69:60570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpbwAAAYI"] [Tue Aug 18 13:05:21.018050 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:39833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ry.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpcAAAASI"] [Tue Aug 18 13:05:21.022992 2026] [security2:error] [pid 157386:tid 157587] [client 20.124.247.79:16453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/nano.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpcwAAAVE"] [Tue Aug 18 13:05:21.025913 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:21.026197 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:21.092354 2026] [security2:error] [pid 157386:tid 157634] [client 4.223.113.180:46479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpdwAAAYA"] [Tue Aug 18 13:05:21.094586 2026] [security2:error] [pid 157386:tid 157605] [client 158.23.17.4:47660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ka.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpeAAAAWM"] [Tue Aug 18 13:05:21.097852 2026] [access_compat:error] [pid 157386:tid 157601] [client 69.63.184.22:38964] AH01797: client denied by server configuration: /home1/produtosmaisrs/public_html/robots.txt [Tue Aug 18 13:05:21.132185 2026] [security2:error] [pid 157386:tid 157629] [client 20.79.204.6:9724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpfQAAAXs"] [Tue Aug 18 13:05:21.136817 2026] [security2:error] [pid 157386:tid 157569] [client 74.7.230.27:58080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpdgABP3M"] [Tue Aug 18 13:05:21.138361 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:19733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/globals.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpfgAAAXw"] [Tue Aug 18 13:05:21.166142 2026] [security2:error] [pid 157386:tid 157550] [client 40.85.222.29:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpfwAAASw"] [Tue Aug 18 13:05:21.228516 2026] [security2:error] [pid 157386:tid 157546] [client 20.65.98.162:20681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/insc.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpggAAASg"] [Tue Aug 18 13:05:21.255151 2026] [security2:error] [pid 157386:tid 157586] [client 40.74.65.169:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpgwAAAVA"] [Tue Aug 18 13:05:21.284296 2026] [security2:error] [pid 157386:tid 157543] [client 40.85.222.29:17575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfphQAAASU"] [Tue Aug 18 13:05:21.322308 2026] [security2:error] [pid 157386:tid 157526] [client 20.1.169.243:15576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpiQAAARQ"] [Tue Aug 18 13:05:21.342144 2026] [security2:error] [pid 157386:tid 157520] [client 20.151.109.219:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpigAAAQ4"] [Tue Aug 18 13:05:21.387056 2026] [security2:error] [pid 157386:tid 157608] [client 20.151.109.219:49976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pm.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpjQAAAWY"] [Tue Aug 18 13:05:21.390847 2026] [security2:error] [pid 157386:tid 157604] [client 74.7.230.27:57346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpjAAAAWI"] [Tue Aug 18 13:05:21.419194 2026] [security2:error] [pid 157386:tid 157603] [client 68.155.154.236:14276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/oivcl.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpjwAAAWE"] [Tue Aug 18 13:05:21.424124 2026] [security2:error] [pid 157386:tid 157556] [client 20.91.215.254:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpkAAAATI"] [Tue Aug 18 13:05:21.466578 2026] [security2:error] [pid 157386:tid 157537] [client 132.196.30.78:27991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/themes.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpkQAAAR8"] [Tue Aug 18 13:05:21.475843 2026] [security2:error] [pid 157386:tid 157591] [client 168.62.48.100:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpkwAAAVU"] [Tue Aug 18 13:05:21.476131 2026] [security2:error] [pid 157386:tid 157539] [client 20.65.98.162:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/file.php"] [unique_id "aoSCwU1jzAhYHVVT1WfplAAAASE"] [Tue Aug 18 13:05:21.495551 2026] [security2:error] [pid 157386:tid 157620] [client 20.215.241.237:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCwU1jzAhYHVVT1WfplQAAAXI"] [Tue Aug 18 13:05:21.506328 2026] [security2:error] [pid 157386:tid 157624] [client 20.171.51.14:38745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ey.php"] [unique_id "aoSCwU1jzAhYHVVT1WfplgAAAXY"] [Tue Aug 18 13:05:21.514887 2026] [security2:error] [pid 157386:tid 157553] [client 40.85.222.29:6596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSCwU1jzAhYHVVT1WfplwAAAS8"] [Tue Aug 18 13:05:21.578020 2026] [security2:error] [pid 157386:tid 157637] [client 213.35.127.232:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpmQAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:21.627529 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:21.627808 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:21.659426 2026] [security2:error] [pid 157386:tid 157638] [client 4.232.151.198:18551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/about.php7"] [unique_id "aoSCwU1jzAhYHVVT1WfpnwAAAYQ"] [Tue Aug 18 13:05:21.665432 2026] [security2:error] [pid 157386:tid 157582] [client 68.221.73.131:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/biufile.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpoAAAAUw"] [Tue Aug 18 13:05:21.682569 2026] [security2:error] [pid 157386:tid 157589] [client 74.7.230.27:57346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpoQAAAVM"] [Tue Aug 18 13:05:21.683302 2026] [security2:error] [pid 157386:tid 157557] [client 40.85.222.29:6606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/first.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpogAAATM"] [Tue Aug 18 13:05:21.718830 2026] [security2:error] [pid 157386:tid 157529] [client 20.151.109.219:49965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/dr.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpowAAARc"] [Tue Aug 18 13:05:21.727479 2026] [security2:error] [pid 157386:tid 157602] [client 20.65.98.162:20725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/dex.php"] [unique_id "aoSCwU1jzAhYHVVT1WfppQAAAWA"] [Tue Aug 18 13:05:21.794272 2026] [security2:error] [pid 157386:tid 157519] [client 20.91.215.254:22568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpqQAAAQ0"] [Tue Aug 18 13:05:21.811224 2026] [security2:error] [pid 157386:tid 157617] [client 74.7.230.27:57346] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpqwAAAW8"], referer: http://idealplast.ind.br/robots.txt [Tue Aug 18 13:05:21.848569 2026] [security2:error] [pid 157386:tid 157531] [client 20.1.169.243:15702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/panel.php"] [unique_id "aoSCwU1jzAhYHVVT1WfprQAAARk"] [Tue Aug 18 13:05:21.888391 2026] [security2:error] [pid 157386:tid 157584] [client 52.173.121.69:10005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpsAAAAU4"] [Tue Aug 18 13:05:21.897315 2026] [security2:error] [pid 157386:tid 157609] [client 86.120.159.145:19903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpsgAAAWc"] [Tue Aug 18 13:05:21.897414 2026] [security2:error] [pid 157386:tid 157609] [client 86.120.159.145:19903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpsgAAAWc"] [Tue Aug 18 13:05:21.903113 2026] [security2:error] [pid 157386:tid 157548] [client 40.85.222.29:7111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpswAAASo"] [Tue Aug 18 13:05:21.911564 2026] [security2:error] [pid 157386:tid 157568] [client 20.206.73.37:40267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/btx25.php"] [unique_id "aoSCwU1jzAhYHVVT1WfptAAAAT4"] [Tue Aug 18 13:05:21.929746 2026] [authz_core:error] [pid 157386:tid 157420] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:21.930164 2026] [authz_core:error] [pid 157386:tid 157420] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:21.953386 2026] [security2:error] [pid 157386:tid 157587] [client 40.74.65.169:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/aaa.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpuAAAAVE"] [Tue Aug 18 13:05:21.963756 2026] [security2:error] [pid 157386:tid 157588] [client 20.151.109.219:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/yindu.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpugAAAVI"] [Tue Aug 18 13:05:21.971162 2026] [security2:error] [pid 157386:tid 157570] [client 20.65.98.162:20635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/key.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpuwAAAUA"] [Tue Aug 18 13:05:21.971296 2026] [security2:error] [pid 157386:tid 157593] [client 20.215.241.237:60656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/sf.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpvAAAAVc"] [Tue Aug 18 13:05:21.986795 2026] [security2:error] [pid 157386:tid 157634] [client 40.85.222.29:6764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpvgAAAYA"] [Tue Aug 18 13:05:21.994690 2026] [security2:error] [pid 157386:tid 157605] [client 20.151.109.219:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ts.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpwAAAAWM"] [Tue Aug 18 13:05:21.999302 2026] [security2:error] [pid 157386:tid 157601] [client 68.155.154.236:14286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/zugvi.php"] [unique_id "aoSCwU1jzAhYHVVT1WfpwQAAAV8"] [Tue Aug 18 13:05:22.053201 2026] [security2:error] [pid 157386:tid 157627] [client 132.196.30.78:19858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/cv.php"] [unique_id "aoSCwk1jzAhYHVVT1WfpzwAAAXk"] [Tue Aug 18 13:05:22.058960 2026] [security2:error] [pid 157386:tid 157563] [client 20.91.215.254:3140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp0AAAATk"] [Tue Aug 18 13:05:22.108203 2026] [security2:error] [pid 157386:tid 157566] [client 20.206.73.37:21074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/133.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp0wAAATw"] [Tue Aug 18 13:05:22.148562 2026] [security2:error] [pid 157386:tid 157535] [client 20.124.247.79:16406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/.mopj.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp1gAAAR0"] [Tue Aug 18 13:05:22.199980 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:42262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lv.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp2gAAATU"] [Tue Aug 18 13:05:22.212996 2026] [security2:error] [pid 157386:tid 157552] [client 20.1.169.243:15731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins//about.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp3AAAAS4"] [Tue Aug 18 13:05:22.230358 2026] [security2:error] [pid 157386:tid 157610] [client 20.65.98.162:20695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/kir.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp4AAAAWg"] [Tue Aug 18 13:05:22.231244 2026] [security2:error] [pid 157386:tid 157572] [client 20.250.13.23:21177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/edit.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp4QAAAUI"] [Tue Aug 18 13:05:22.248589 2026] [security2:error] [pid 157386:tid 157576] [client 20.38.3.247:7171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/sf.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp4wAAAUY"] [Tue Aug 18 13:05:22.261273 2026] [security2:error] [pid 157386:tid 157591] [client 40.85.222.29:6638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp5QAAAVU"] [Tue Aug 18 13:05:22.265071 2026] [security2:error] [pid 157386:tid 157579] [client 45.131.195.56:62297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "chicodareia.com.br"] [uri "/"] [unique_id "aoSCwk1jzAhYHVVT1Wfp5gAAAUk"] [Tue Aug 18 13:05:22.279141 2026] [security2:error] [pid 157386:tid 157553] [client 40.85.222.29:6749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp5wAAAS8"] [Tue Aug 18 13:05:22.287918 2026] [security2:error] [pid 157386:tid 157521] [client 20.151.109.219:56007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fd.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp6AAAAQ8"] [Tue Aug 18 13:05:22.324826 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/53.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp7AAAAXg"] [Tue Aug 18 13:05:22.380473 2026] [security2:error] [pid 157386:tid 157555] [client 4.223.113.180:40859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp8wAAATE"] [Tue Aug 18 13:05:22.382150 2026] [security2:error] [pid 157386:tid 157590] [client 4.232.151.198:11802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp9AAAAVQ"] [Tue Aug 18 13:05:22.431656 2026] [security2:error] [pid 157386:tid 157525] [client 20.91.215.254:22535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp-wAAARM"] [Tue Aug 18 13:05:22.437132 2026] [security2:error] [pid 157386:tid 157617] [client 68.155.154.236:14239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wsrer.php"] [unique_id "aoSCwk1jzAhYHVVT1Wfp_AAAAW8"] [Tue Aug 18 13:05:22.457312 2026] [security2:error] [pid 157386:tid 157628] [client 68.221.73.131:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/dejavu.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqAAAAAXo"] [Tue Aug 18 13:05:22.503311 2026] [security2:error] [pid 157386:tid 157568] [client 20.65.98.162:20709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/nofile.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqBgAAAT4"] [Tue Aug 18 13:05:22.513485 2026] [security2:error] [pid 157386:tid 157528] [client 49.37.150.8:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqBwAAARY"] [Tue Aug 18 13:05:22.513580 2026] [security2:error] [pid 157386:tid 157528] [client 49.37.150.8:62628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqBwAAARY"] [Tue Aug 18 13:05:22.531132 2026] [authz_core:error] [pid 157386:tid 157511] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:22.531420 2026] [authz_core:error] [pid 157386:tid 157511] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:22.532569 2026] [security2:error] [pid 157386:tid 157540] [client 20.206.73.37:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/biufile.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqCgAAASI"] [Tue Aug 18 13:05:22.537116 2026] [security2:error] [pid 157386:tid 157558] [client 20.124.247.79:16431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/bengi.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqCwAAATQ"] [Tue Aug 18 13:05:22.537566 2026] [security2:error] [pid 157386:tid 157587] [client 20.215.241.237:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/k.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqDAAAAVE"] [Tue Aug 18 13:05:22.537954 2026] [security2:error] [pid 157386:tid 157588] [client 40.85.222.29:6763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqDQAAAVI"] [Tue Aug 18 13:05:22.551945 2026] [security2:error] [pid 157386:tid 157593] [client 68.221.73.131:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/img.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqEAAAAVc"] [Tue Aug 18 13:05:22.577172 2026] [security2:error] [pid 157386:tid 157585] [client 20.1.169.243:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins//index.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqEgAAAU8"] [Tue Aug 18 13:05:22.585801 2026] [security2:error] [pid 157386:tid 157600] [client 158.23.17.4:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ot.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqEwAAAV4"] [Tue Aug 18 13:05:22.598115 2026] [security2:error] [pid 157386:tid 157539] [client 213.35.127.232:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqFAAAASE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:22.638111 2026] [security2:error] [pid 157386:tid 157630] [client 40.74.65.169:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/FWAZ.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqGAAAAXw"] [Tue Aug 18 13:05:22.640844 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:39831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lq.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqGQAAASY"] [Tue Aug 18 13:05:22.674935 2026] [security2:error] [pid 157386:tid 157642] [client 40.85.222.29:6637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqGwAAAYg"] [Tue Aug 18 13:05:22.770628 2026] [security2:error] [pid 157386:tid 157571] [client 20.65.98.162:20644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/fling.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqJAAAAUE"] [Tue Aug 18 13:05:22.786579 2026] [security2:error] [pid 157386:tid 157518] [client 20.25.139.174:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/ww5.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqJwAAAQw"] [Tue Aug 18 13:05:22.836810 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:22.837234 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:22.845065 2026] [security2:error] [pid 157386:tid 157591] [client 40.85.222.29:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/blog/byp.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqKwAAAVU"] [Tue Aug 18 13:05:22.864091 2026] [security2:error] [pid 157386:tid 157579] [client 4.232.151.198:7918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/dedi1.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqLQAAAUk"] [Tue Aug 18 13:05:22.913085 2026] [security2:error] [pid 157386:tid 157521] [client 20.151.109.219:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/sxx.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqLgAAAQ8"] [Tue Aug 18 13:05:22.932629 2026] [security2:error] [pid 157386:tid 157517] [client 132.196.30.78:19865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqLwAAAQs"] [Tue Aug 18 13:05:22.936857 2026] [security2:error] [pid 157386:tid 157626] [client 52.173.121.69:10033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqMAAAAXg"] [Tue Aug 18 13:05:22.940433 2026] [security2:error] [pid 157386:tid 157582] [client 45.131.195.248:24815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "chicodareia.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "aoSCwk1jzAhYHVVT1WfqMgAAAUw"] [Tue Aug 18 13:05:22.952555 2026] [security2:error] [pid 157386:tid 157557] [client 20.151.109.219:49929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/you.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqNAAAATM"] [Tue Aug 18 13:05:22.976566 2026] [security2:error] [pid 157386:tid 157620] [client 20.1.169.243:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins//min.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqNgAAAXI"] [Tue Aug 18 13:05:22.977140 2026] [security2:error] [pid 157386:tid 157581] [client 40.74.65.169:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/222.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqNwAAAUs"] [Tue Aug 18 13:05:23.024038 2026] [security2:error] [pid 157386:tid 157623] [client 20.65.98.162:7160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/zoo1.php"] [unique_id "aoSCw01jzAhYHVVT1WfqOQAAAXU"] [Tue Aug 18 13:05:23.069570 2026] [security2:error] [pid 157386:tid 157613] [client 40.85.222.29:6724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSCw01jzAhYHVVT1WfqPAAAAWs"] [Tue Aug 18 13:05:23.081934 2026] [security2:error] [pid 157386:tid 157596] [client 158.23.17.4:63014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ih.php"] [unique_id "aoSCw01jzAhYHVVT1WfqPgAAAVo"] [Tue Aug 18 13:05:23.105718 2026] [security2:error] [pid 157386:tid 157628] [client 20.124.247.79:16454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/file2.php"] [unique_id "aoSCw01jzAhYHVVT1WfqPwAAAXo"] [Tue Aug 18 13:05:23.107123 2026] [security2:error] [pid 157386:tid 157603] [client 185.191.171.8:31230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752094179/1753920000/"] [unique_id "aoSCw01jzAhYHVVT1WfqQAAAAWE"] [Tue Aug 18 13:05:23.107278 2026] [security2:error] [pid 157386:tid 157603] [client 185.191.171.8:31230] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752094179/1753920000/"] [unique_id "aoSCw01jzAhYHVVT1WfqQAAAAWE"] [Tue Aug 18 13:05:23.119866 2026] [security2:error] [pid 157386:tid 157578] [client 20.215.241.237:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/82.php"] [unique_id "aoSCw01jzAhYHVVT1WfqQgAAAUg"] [Tue Aug 18 13:05:23.129070 2026] [security2:error] [pid 157386:tid 157524] [client 74.7.175.151:54948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCw01jzAhYHVVT1WfqQwAAARI"] [Tue Aug 18 13:05:23.134478 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:23.134767 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:23.153410 2026] [security2:error] [pid 157386:tid 157568] [client 20.91.215.254:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSCw01jzAhYHVVT1WfqSAAAAT4"] [Tue Aug 18 13:05:23.167792 2026] [security2:error] [pid 157386:tid 157528] [client 40.85.222.29:7120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSCw01jzAhYHVVT1WfqSQAAARY"] [Tue Aug 18 13:05:23.209412 2026] [security2:error] [pid 157386:tid 157555] [client 20.91.215.254:22565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSCw01jzAhYHVVT1WfqTQAAATE"] [Tue Aug 18 13:05:23.235274 2026] [security2:error] [pid 157386:tid 157441] [remote 162.214.205.212:38180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boscoagriturismo.com"] [uri "/wp-login.php"] [unique_id "aoSCw01jzAhYHVVT1WfqUAABdjY"] [Tue Aug 18 13:05:23.242241 2026] [security2:error] [pid 157386:tid 157634] [client 68.155.154.236:14226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/ucpfr.php"] [unique_id "aoSCw01jzAhYHVVT1WfqUQAAAYA"] [Tue Aug 18 13:05:23.257613 2026] [security2:error] [pid 157386:tid 157605] [client 74.7.175.151:54948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealplast.ind.br"] [uri "/index.php"] [unique_id "aoSCw01jzAhYHVVT1WfqUgAAAWM"], referer: http://www.idealplast.ind.br/robots.txt [Tue Aug 18 13:05:23.323143 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ez.php"] [unique_id "aoSCw01jzAhYHVVT1WfqewAAAVY"] [Tue Aug 18 13:05:23.324865 2026] [security2:error] [pid 157386:tid 157530] [client 40.74.65.169:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/site.php"] [unique_id "aoSCw01jzAhYHVVT1WfqfAAAARg"] [Tue Aug 18 13:05:23.340547 2026] [security2:error] [pid 157386:tid 157540] [client 20.25.139.174:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/2.php"] [unique_id "aoSCw01jzAhYHVVT1WfqfQAAASI"] [Tue Aug 18 13:05:23.343888 2026] [security2:error] [pid 157386:tid 157516] [client 20.65.98.162:20724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/zoo2.php"] [unique_id "aoSCw01jzAhYHVVT1WfqfwAAAQo"] [Tue Aug 18 13:05:23.344392 2026] [security2:error] [pid 157386:tid 157588] [client 20.1.169.243:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/111/wp-polls/tinymce/plugins/security.php"] [unique_id "aoSCw01jzAhYHVVT1WfqfgAAAVI"] [Tue Aug 18 13:05:23.361552 2026] [security2:error] [pid 157386:tid 157607] [client 20.151.109.219:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/info2.php"] [unique_id "aoSCw01jzAhYHVVT1WfqgQAAAWU"] [Tue Aug 18 13:05:23.403377 2026] [security2:error] [pid 157386:tid 157546] [client 20.171.51.14:13439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/51.php"] [unique_id "aoSCw01jzAhYHVVT1WfqgwAAASg"] [Tue Aug 18 13:05:23.444434 2026] [security2:error] [pid 157386:tid 157535] [client 40.85.222.29:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSCw01jzAhYHVVT1WfqiAAAAR0"] [Tue Aug 18 13:05:23.507821 2026] [security2:error] [pid 157386:tid 157559] [client 40.85.222.29:6777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSCw01jzAhYHVVT1WfqiwAAATU"] [Tue Aug 18 13:05:23.594886 2026] [security2:error] [pid 157386:tid 157626] [client 45.131.195.78:51079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "chicodareia.com.br"] [uri "/media/system/js/core.js"] [unique_id "aoSCw01jzAhYHVVT1WfqjgAAAXg"] [Tue Aug 18 13:05:23.595088 2026] [security2:error] [pid 157386:tid 157517] [client 20.215.241.237:57360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/dex.php"] [unique_id "aoSCw01jzAhYHVVT1WfqjQAAAQs"] [Tue Aug 18 13:05:23.609546 2026] [security2:error] [pid 157386:tid 157545] [client 4.232.151.198:7747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-admin/maint/maint/flower.php"] [unique_id "aoSCw01jzAhYHVVT1WfqkAAAASc"] [Tue Aug 18 13:05:23.610472 2026] [security2:error] [pid 157386:tid 157582] [client 20.65.98.162:20711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/org.php"] [unique_id "aoSCw01jzAhYHVVT1WfqkQAAAUw"] [Tue Aug 18 13:05:23.611335 2026] [security2:error] [pid 157386:tid 157539] [client 213.35.127.232:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCw01jzAhYHVVT1WfqkgAAASE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:23.628655 2026] [security2:error] [pid 157386:tid 157639] [client 158.23.17.4:56559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/k.php"] [unique_id "aoSCw01jzAhYHVVT1WfqkwAAAYU"] [Tue Aug 18 13:05:23.629574 2026] [security2:error] [pid 157386:tid 157638] [client 68.221.73.131:16230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/aaf.php"] [unique_id "aoSCw01jzAhYHVVT1WfqlAAAAYQ"] [Tue Aug 18 13:05:23.657277 2026] [security2:error] [pid 157386:tid 157620] [client 20.124.247.79:16475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/gm.php"] [unique_id "aoSCw01jzAhYHVVT1WfqlQAAAXI"] [Tue Aug 18 13:05:23.674747 2026] [security2:error] [pid 157386:tid 157590] [client 157.90.155.240:9296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSCw01jzAhYHVVT1WfqTAAAAVQ"], referer: https://www.saojudas.com.br/ [Tue Aug 18 13:05:23.675019 2026] [security2:error] [pid 157386:tid 157547] [client 78.47.98.55:61862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSCwk1jzAhYHVVT1WfqNQAAASk"], referer: https://www.saojudas.com.br [Tue Aug 18 13:05:23.710396 2026] [security2:error] [pid 157386:tid 157596] [client 20.151.109.219:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/asus.php"] [unique_id "aoSCw01jzAhYHVVT1WfqnAAAAVo"] [Tue Aug 18 13:05:23.713996 2026] [security2:error] [pid 157386:tid 157598] [client 74.248.130.103:22353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSCw01jzAhYHVVT1WfqnQAAAVw"] [Tue Aug 18 13:05:23.715068 2026] [security2:error] [pid 157386:tid 157527] [client 20.1.169.243:15718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSCw01jzAhYHVVT1WfqngAAARU"] [Tue Aug 18 13:05:23.736637 2026] [security2:error] [pid 157386:tid 157603] [client 40.85.222.29:7145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.advogadocriminalgoiania.com.br"] [uri "/images/security.php"] [unique_id "aoSCw01jzAhYHVVT1WfqnwAAAWE"] [Tue Aug 18 13:05:23.769931 2026] [security2:error] [pid 157386:tid 157584] [client 68.155.154.236:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/yxijx.php"] [unique_id "aoSCw01jzAhYHVVT1WfqoAAAAU4"] [Tue Aug 18 13:05:23.807034 2026] [security2:error] [pid 157386:tid 157533] [client 4.232.151.198:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/atomlib.php"] [unique_id "aoSCw01jzAhYHVVT1WfqpAAAARs"] [Tue Aug 18 13:05:23.822015 2026] [security2:error] [pid 157386:tid 157609] [client 40.85.222.29:7153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSCw01jzAhYHVVT1WfqpQAAAWc"] [Tue Aug 18 13:05:23.851702 2026] [security2:error] [pid 157386:tid 157611] [client 20.65.98.162:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/imageskir.php"] [unique_id "aoSCw01jzAhYHVVT1WfqqAAAAWk"] [Tue Aug 18 13:05:23.866238 2026] [security2:error] [pid 157386:tid 157557] [client 20.91.215.254:16611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/ebs.php7"] [unique_id "aoSCw01jzAhYHVVT1WfqqQAAATM"] [Tue Aug 18 13:05:23.902367 2026] [security2:error] [pid 157386:tid 157601] [client 20.171.51.14:7884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ew.php"] [unique_id "aoSCw01jzAhYHVVT1WfqrAAAAV8"] [Tue Aug 18 13:05:23.907789 2026] [security2:error] [pid 157386:tid 157566] [client 132.196.30.78:19889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ws83.php"] [unique_id "aoSCw01jzAhYHVVT1WfqrQAAATw"] [Tue Aug 18 13:05:24.002760 2026] [security2:error] [pid 157386:tid 157546] [client 20.91.215.254:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqsgAAASg"] [Tue Aug 18 13:05:24.013897 2026] [security2:error] [pid 157386:tid 157618] [client 40.74.65.169:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/ccc.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqswAAAXA"] [Tue Aug 18 13:05:24.051490 2026] [security2:error] [pid 157386:tid 157571] [client 52.173.121.69:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSCxE1jzAhYHVVT1WfquAAAAUE"] [Tue Aug 18 13:05:24.097856 2026] [security2:error] [pid 157386:tid 157579] [client 20.65.98.162:7136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/indexo.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqvQAAAUk"] [Tue Aug 18 13:05:24.099469 2026] [security2:error] [pid 157386:tid 157588] [client 20.1.169.243:15692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/bolvo-features/inc/plugins/data.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqvgAAAVI"] [Tue Aug 18 13:05:24.104204 2026] [security2:error] [pid 157386:tid 157534] [client 20.215.241.237:11343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/puc.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqvwAAARw"] [Tue Aug 18 13:05:24.117171 2026] [security2:error] [pid 157386:tid 157537] [client 40.85.222.29:6755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqwAAAAR8"] [Tue Aug 18 13:05:24.144058 2026] [security2:error] [pid 157386:tid 157521] [client 20.151.109.219:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/22.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqwgAAAQ8"] [Tue Aug 18 13:05:24.144327 2026] [security2:error] [pid 157386:tid 157585] [client 20.25.139.174:4561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqwwAAAU8"] [Tue Aug 18 13:05:24.188253 2026] [security2:error] [pid 157386:tid 157575] [client 103.82.26.211:59892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fokuss.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqxwAAAUU"] [Tue Aug 18 13:05:24.247940 2026] [security2:error] [pid 157386:tid 157599] [client 4.232.151.198:24217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/module.audio-video.matroska-meta.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqygAAAV0"] [Tue Aug 18 13:05:24.254685 2026] [security2:error] [pid 157386:tid 157629] [client 68.155.154.236:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/zwlsv.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqywAAAXs"] [Tue Aug 18 13:05:24.262089 2026] [security2:error] [pid 157386:tid 157529] [client 20.206.73.37:65174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/coffexium.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqzQAAARc"] [Tue Aug 18 13:05:24.288749 2026] [security2:error] [pid 157386:tid 157577] [client 158.23.17.4:46828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/iu.php"] [unique_id "aoSCxE1jzAhYHVVT1WfqzwAAAUc"] [Tue Aug 18 13:05:24.361825 2026] [security2:error] [pid 157386:tid 157628] [client 20.65.98.162:20690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq0wAAAXo"] [Tue Aug 18 13:05:24.429476 2026] [security2:error] [pid 157386:tid 157528] [client 40.85.222.29:6726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq2gAAARY"] [Tue Aug 18 13:05:24.469672 2026] [security2:error] [pid 157386:tid 157586] [client 20.1.169.243:15732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/about.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq3QAAAVA"] [Tue Aug 18 13:05:24.509685 2026] [security2:error] [pid 157386:tid 157541] [client 20.151.109.219:46401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/zs.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq3wAAASM"] [Tue Aug 18 13:05:24.515880 2026] [security2:error] [pid 157386:tid 157606] [client 20.124.247.79:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/ws55.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq4AAAAWQ"] [Tue Aug 18 13:05:24.548504 2026] [authz_core:error] [pid 157386:tid 157483] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:24.548781 2026] [authz_core:error] [pid 157386:tid 157483] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:24.574068 2026] [security2:error] [pid 157386:tid 157619] [client 20.171.51.14:18661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pqr.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq5AAAAXE"] [Tue Aug 18 13:05:24.616889 2026] [security2:error] [pid 157386:tid 157548] [client 20.91.215.254:22576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq5QAAASo"] [Tue Aug 18 13:05:24.619132 2026] [security2:error] [pid 157386:tid 157592] [client 20.38.3.247:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/k.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq5gAAAVY"] [Tue Aug 18 13:05:24.630564 2026] [security2:error] [pid 157386:tid 157595] [client 213.35.127.232:53485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq5wAAAVk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:24.631848 2026] [security2:error] [pid 157386:tid 157531] [client 20.91.215.254:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq6AAAARk"] [Tue Aug 18 13:05:24.641506 2026] [security2:error] [pid 157386:tid 157516] [client 20.65.98.162:20717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq6gAAAQo"] [Tue Aug 18 13:05:24.645312 2026] [security2:error] [pid 157386:tid 157624] [client 20.25.139.174:4465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/atomlib.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq6wAAAXY"] [Tue Aug 18 13:05:24.660561 2026] [security2:error] [pid 157386:tid 157600] [client 20.215.241.237:11378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/inso.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq7QAAAV4"] [Tue Aug 18 13:05:24.709498 2026] [security2:error] [pid 157386:tid 157625] [client 40.74.65.169:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/admin.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq8AAAAXc"] [Tue Aug 18 13:05:24.719318 2026] [security2:error] [pid 157386:tid 157538] [client 40.85.222.29:6613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq8QAAASA"] [Tue Aug 18 13:05:24.726863 2026] [security2:error] [pid 157386:tid 157526] [client 68.221.73.131:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq8gAAARQ"] [Tue Aug 18 13:05:24.784586 2026] [security2:error] [pid 157386:tid 157611] [client 4.232.151.198:11778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.mabelini.com.br"] [uri "/rip.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq-AAAAWk"] [Tue Aug 18 13:05:24.833642 2026] [security2:error] [pid 157386:tid 157549] [client 20.1.169.243:15552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/admin.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq-wAAASs"] [Tue Aug 18 13:05:24.842425 2026] [security2:error] [pid 157386:tid 157642] [client 20.250.13.23:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq_AAAAYg"] [Tue Aug 18 13:05:24.849135 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:24.849454 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:24.855406 2026] [security2:error] [pid 157386:tid 157537] [client 20.151.109.219:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/iz.php"] [unique_id "aoSCxE1jzAhYHVVT1Wfq_wAAAR8"] [Tue Aug 18 13:05:24.887051 2026] [security2:error] [pid 157386:tid 157607] [client 132.196.30.78:20282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/atex1.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrIAAAAWU"] [Tue Aug 18 13:05:24.903489 2026] [security2:error] [pid 157386:tid 157575] [client 20.65.98.162:20726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/.admin.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrJwAAAUU"] [Tue Aug 18 13:05:24.903569 2026] [security2:error] [pid 157386:tid 157638] [client 74.248.130.103:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/media.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrKAAAAYQ"] [Tue Aug 18 13:05:24.909655 2026] [access_compat:error] [pid 157386:tid 157543] [client 5.255.231.185:54342] AH01797: client denied by server configuration: /home1/novamatronfer/public_html/robots.txt [Tue Aug 18 13:05:24.926310 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:21918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/settings.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrKwAAAUw"] [Tue Aug 18 13:05:24.932746 2026] [security2:error] [pid 157386:tid 157564] [client 20.171.51.14:44870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/an.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrLAAAATo"] [Tue Aug 18 13:05:24.950037 2026] [security2:error] [pid 157386:tid 157635] [client 4.232.151.198:24203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/assets/autoload_classmap.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrLgAAAYE"] [Tue Aug 18 13:05:24.974238 2026] [security2:error] [pid 157386:tid 157590] [client 20.206.73.37:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/bless6.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrLwAAAVQ"] [Tue Aug 18 13:05:25.000145 2026] [security2:error] [pid 157386:tid 157578] [client 20.79.204.6:10123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/atomlib.php"] [unique_id "aoSCxE1jzAhYHVVT1WfrMQAAAUg"] [Tue Aug 18 13:05:25.008314 2026] [security2:error] [pid 157386:tid 157567] [client 149.34.210.141:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrMgAAAT0"] [Tue Aug 18 13:05:25.028212 2026] [security2:error] [pid 157386:tid 157580] [client 40.85.222.29:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrMwAAAUo"] [Tue Aug 18 13:05:25.048237 2026] [security2:error] [pid 157386:tid 157628] [client 68.155.154.236:14227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/jrpga.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrNgAAAXo"] [Tue Aug 18 13:05:25.104294 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sx.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrOQAAAVc"] [Tue Aug 18 13:05:25.140478 2026] [security2:error] [pid 157386:tid 157606] [client 20.151.109.219:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/se.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrOwAAAWQ"] [Tue Aug 18 13:05:25.140907 2026] [security2:error] [pid 157386:tid 157605] [client 68.221.73.131:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/222.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrPAAAAWM"] [Tue Aug 18 13:05:25.152802 2026] [security2:error] [pid 157386:tid 157522] [client 20.65.98.162:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/wsomini.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrPgAAARA"] [Tue Aug 18 13:05:25.154504 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:25.154926 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:25.190007 2026] [security2:error] [pid 157386:tid 157613] [client 20.25.139.174:4646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/rip.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrQAAAAWs"] [Tue Aug 18 13:05:25.198790 2026] [security2:error] [pid 157386:tid 157587] [client 20.1.169.243:15573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrQQAAAVE"] [Tue Aug 18 13:05:25.234160 2026] [security2:error] [pid 157386:tid 157548] [client 20.215.241.237:60665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/aa.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrQwAAASo"] [Tue Aug 18 13:05:25.251294 2026] [security2:error] [pid 157386:tid 157595] [client 68.221.73.131:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/155.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrRQAAAVk"] [Tue Aug 18 13:05:25.275438 2026] [security2:error] [pid 157386:tid 157567] [client 149.34.210.141:57444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrMgAAAT0"] [Tue Aug 18 13:05:25.283772 2026] [security2:error] [pid 157386:tid 157603] [client 20.91.215.254:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrRgAAAWE"] [Tue Aug 18 13:05:25.295666 2026] [security2:error] [pid 157386:tid 157624] [client 158.23.17.4:11441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pk.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrRwAAAXY"] [Tue Aug 18 13:05:25.308012 2026] [security2:error] [pid 157386:tid 157555] [client 40.85.222.29:17582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrSAAAATE"] [Tue Aug 18 13:05:25.322859 2026] [security2:error] [pid 157386:tid 157560] [client 52.173.121.69:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrSwAAATY"] [Tue Aug 18 13:05:25.339259 2026] [security2:error] [pid 157386:tid 157634] [client 20.91.215.254:7882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrTQAAAYA"] [Tue Aug 18 13:05:25.362045 2026] [security2:error] [pid 157386:tid 157526] [client 20.171.51.14:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sy.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrTgAAARQ"] [Tue Aug 18 13:05:25.386256 2026] [security2:error] [pid 157386:tid 157571] [client 40.74.65.169:41439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/reviall.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrUAAAAUE"] [Tue Aug 18 13:05:25.417421 2026] [security2:error] [pid 157386:tid 157565] [client 40.74.65.169:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/key.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrZQAAATs"] [Tue Aug 18 13:05:25.433317 2026] [security2:error] [pid 157386:tid 157579] [client 20.65.98.162:7050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ergoclinica.com.br"] [uri "/vr.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrbAAAAUk"] [Tue Aug 18 13:05:25.445771 2026] [security2:error] [pid 157386:tid 157534] [client 68.155.154.236:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/museu/yhweq.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrcAAAARw"] [Tue Aug 18 13:05:25.461597 2026] [security2:error] [pid 157386:tid 157405] [remote 20.54.134.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.134.54.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrcQABChI"] [Tue Aug 18 13:05:25.465239 2026] [security2:error] [pid 157386:tid 157551] [client 103.82.26.211:61874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.82.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fokuss.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrcgAAAS0"] [Tue Aug 18 13:05:25.465255 2026] [security2:error] [pid 157386:tid 157517] [client 20.124.247.79:16393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/m.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrcwAAAQs"] [Tue Aug 18 13:05:25.474172 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:58187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vp.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrdAAAASE"] [Tue Aug 18 13:05:25.477259 2026] [security2:error] [pid 157386:tid 157531] [client 20.250.13.23:17422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrdgAAARk"] [Tue Aug 18 13:05:25.543089 2026] [security2:error] [pid 157386:tid 157623] [client 20.206.73.37:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrgQAAAXU"] [Tue Aug 18 13:05:25.562866 2026] [security2:error] [pid 157386:tid 157616] [client 20.1.169.243:15558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/db-status.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrgwAAAW4"] [Tue Aug 18 13:05:25.607011 2026] [security2:error] [pid 157386:tid 157612] [client 40.85.222.29:6770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrjAAAAWo"] [Tue Aug 18 13:05:25.609776 2026] [security2:error] [pid 157386:tid 157604] [client 4.232.151.198:25247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ncx.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrjQAAAWI"] [Tue Aug 18 13:05:25.634747 2026] [security2:error] [pid 157386:tid 157524] [client 168.62.48.100:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrjgAAARI"] [Tue Aug 18 13:05:25.651143 2026] [security2:error] [pid 157386:tid 157602] [client 213.35.127.232:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrkAAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:25.695399 2026] [security2:error] [pid 157386:tid 157620] [client 20.25.139.174:4509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/p.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrkgAAAXI"] [Tue Aug 18 13:05:25.750375 2026] [security2:error] [pid 157386:tid 157559] [client 20.215.241.237:61638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/img.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrlgAAATU"] [Tue Aug 18 13:05:25.756678 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:25.756956 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:25.781158 2026] [security2:error] [pid 157386:tid 157522] [client 20.151.109.219:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nu.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrlwAAARA"] [Tue Aug 18 13:05:25.794634 2026] [security2:error] [pid 157386:tid 157613] [client 20.151.109.219:46451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ph.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrmQAAAWs"] [Tue Aug 18 13:05:25.806760 2026] [security2:error] [pid 157386:tid 157587] [client 20.171.51.14:13389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/57.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrmwAAAVE"] [Tue Aug 18 13:05:25.807697 2026] [security2:error] [pid 157386:tid 157635] [client 20.79.204.6:9309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/rip.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrnAAAAYE"] [Tue Aug 18 13:05:25.834657 2026] [security2:error] [pid 157386:tid 157530] [client 68.155.154.236:14167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/nwwha.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrnQAAARg"] [Tue Aug 18 13:05:25.869055 2026] [security2:error] [pid 157386:tid 157568] [client 4.223.113.180:11738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/Casper.php"] [unique_id "aoSCxU1jzAhYHVVT1WfroQAAAT4"] [Tue Aug 18 13:05:25.892907 2026] [security2:error] [pid 157386:tid 157636] [client 20.25.139.174:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/inputs.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrpAAAAYI"] [Tue Aug 18 13:05:25.926787 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:58356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mx.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrpwAAASI"] [Tue Aug 18 13:05:25.945228 2026] [security2:error] [pid 157386:tid 157603] [client 40.85.222.29:6602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrqQAAAWE"] [Tue Aug 18 13:05:25.995708 2026] [security2:error] [pid 157386:tid 157562] [client 20.124.247.79:16386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/33.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrrAAAATg"] [Tue Aug 18 13:05:25.998297 2026] [security2:error] [pid 157386:tid 157605] [client 20.91.215.254:22532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/lite.php"] [unique_id "aoSCxU1jzAhYHVVT1WfrrQAAAWM"] [Tue Aug 18 13:05:26.053868 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:26.054148 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:26.056615 2026] [security2:error] [pid 157386:tid 157600] [client 132.196.30.78:20276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/class-t.api.php"] [unique_id "aoSCxk1jzAhYHVVT1WfruQAAAV4"] [Tue Aug 18 13:05:26.057647 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:15939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/elementor/core/admin/ui/components/min.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrugAAAYc"] [Tue Aug 18 13:05:26.091850 2026] [security2:error] [pid 157386:tid 157579] [client 40.74.65.169:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/nope.php"] [unique_id "aoSCxk1jzAhYHVVT1WfruwAAAUk"] [Tue Aug 18 13:05:26.128655 2026] [security2:error] [pid 157386:tid 157551] [client 20.91.215.254:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/wp-themes.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrvgAAAS0"] [Tue Aug 18 13:05:26.139631 2026] [security2:error] [pid 157386:tid 157594] [client 20.250.13.23:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrvwAAAVg"] [Tue Aug 18 13:05:26.177341 2026] [security2:error] [pid 157386:tid 157608] [client 157.20.138.62:61892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrwgAAAWY"] [Tue Aug 18 13:05:26.177464 2026] [security2:error] [pid 157386:tid 157608] [client 157.20.138.62:61892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrwgAAAWY"] [Tue Aug 18 13:05:26.181007 2026] [security2:error] [pid 157386:tid 157598] [client 68.221.73.131:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/key.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrwwAAAVw"] [Tue Aug 18 13:05:26.185944 2026] [security2:error] [pid 157386:tid 157552] [client 68.155.154.236:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/opsqt.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrxQAAAS4"] [Tue Aug 18 13:05:26.203514 2026] [security2:error] [pid 157386:tid 157573] [client 158.23.17.4:14037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ge.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrxgAAAUM"] [Tue Aug 18 13:05:26.228685 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/s.php"] [unique_id "aoSCxk1jzAhYHVVT1WfryQAAASk"] [Tue Aug 18 13:05:26.264055 2026] [security2:error] [pid 157386:tid 157526] [client 4.232.151.198:7744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/plugins/autoload_classmap.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrygAAARQ"] [Tue Aug 18 13:05:26.264897 2026] [security2:error] [pid 157386:tid 157527] [client 40.85.222.29:6762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrywAAARU"] [Tue Aug 18 13:05:26.291954 2026] [security2:error] [pid 157386:tid 157516] [client 20.25.139.174:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duthiveiculos.com.br"] [uri "/php.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrzgAAAQo"] [Tue Aug 18 13:05:26.292844 2026] [security2:error] [pid 157386:tid 157604] [client 52.173.121.69:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSCxk1jzAhYHVVT1WfrzwAAAWI"] [Tue Aug 18 13:05:26.301032 2026] [security2:error] [pid 157386:tid 157628] [client 68.221.73.131:46557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/ops.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr0AAAAXo"] [Tue Aug 18 13:05:26.322095 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:10573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/spip.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr0QAAARo"] [Tue Aug 18 13:05:26.413525 2026] [security2:error] [pid 157386:tid 157522] [client 20.171.51.14:7908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ah.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr1wAAARA"] [Tue Aug 18 13:05:26.428966 2026] [security2:error] [pid 157386:tid 157521] [client 20.25.139.174:4637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/admin.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr2gAAAQ8"] [Tue Aug 18 13:05:26.491716 2026] [security2:error] [pid 157386:tid 157640] [client 20.250.13.23:28865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr3QAAAYY"] [Tue Aug 18 13:05:26.528788 2026] [security2:error] [pid 157386:tid 157540] [client 20.215.241.237:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/222.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr4AAAASI"] [Tue Aug 18 13:05:26.595216 2026] [security2:error] [pid 157386:tid 157625] [client 20.1.169.243:15560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr4gAAAXc"] [Tue Aug 18 13:05:26.598172 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:46436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/uo.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr4wAAASA"] [Tue Aug 18 13:05:26.599218 2026] [security2:error] [pid 157386:tid 157542] [client 40.85.222.29:7124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/rezor.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr5AAAASQ"] [Tue Aug 18 13:05:26.602613 2026] [security2:error] [pid 157386:tid 157560] [client 178.153.171.161:19677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr5gAAATY"] [Tue Aug 18 13:05:26.602741 2026] [security2:error] [pid 157386:tid 157560] [client 178.153.171.161:19677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr5gAAATY"] [Tue Aug 18 13:05:26.656512 2026] [authz_core:error] [pid 157386:tid 157410] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:26.656802 2026] [authz_core:error] [pid 157386:tid 157410] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:26.662872 2026] [security2:error] [pid 157386:tid 157602] [client 213.35.127.232:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr6wAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:26.695116 2026] [security2:error] [pid 157386:tid 157554] [client 68.155.154.236:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/jvcpa.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr7QAAATA"] [Tue Aug 18 13:05:26.708123 2026] [security2:error] [pid 157386:tid 157627] [client 213.202.253.4:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr7gAAAXk"], referer: www.google.com [Tue Aug 18 13:05:26.738514 2026] [security2:error] [pid 157386:tid 157568] [client 132.196.30.78:27982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/w.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr8AAAAT4"] [Tue Aug 18 13:05:26.760547 2026] [security2:error] [pid 157386:tid 157555] [client 20.91.215.254:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.capitalcaminhonetes.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr8QAAATE"] [Tue Aug 18 13:05:26.769602 2026] [security2:error] [pid 157386:tid 157601] [client 20.250.13.23:43783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/st.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr8gAAAV8"] [Tue Aug 18 13:05:26.770257 2026] [security2:error] [pid 157386:tid 157624] [client 20.91.215.254:16599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSCxk1jzAhYHVVT1Wfr8wAAAXY"] [Tue Aug 18 13:05:26.783087 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/nope.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr9QAAAS8"] [Tue Aug 18 13:05:26.914423 2026] [security2:error] [pid 157386:tid 157547] [client 20.124.247.79:16437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "casamentos.gramadoboutiqueeventos.com.br"] [uri "/packed.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr-gAAASk"] [Tue Aug 18 13:05:26.921906 2026] [security2:error] [pid 157386:tid 157616] [client 40.85.222.29:6769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr-wAAAW4"] [Tue Aug 18 13:05:26.944509 2026] [security2:error] [pid 157386:tid 157626] [client 20.25.139.174:4489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/goods.php"] [unique_id "aoSCxk1jzAhYHVVT1Wfr_QAAAXg"] [Tue Aug 18 13:05:26.996317 2026] [security2:error] [pid 157386:tid 157526] [client 20.38.3.247:35053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/82.php"] [unique_id "aoSCxk1jzAhYHVVT1WfsAwAAARQ"] [Tue Aug 18 13:05:27.006979 2026] [security2:error] [pid 157386:tid 157534] [client 4.232.151.198:25216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/litanies.php"] [unique_id "aoSCx01jzAhYHVVT1WfsBAAAARw"] [Tue Aug 18 13:05:27.046154 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kx.php"] [unique_id "aoSCx01jzAhYHVVT1WfsBgAAAU4"] [Tue Aug 18 13:05:27.090187 2026] [security2:error] [pid 157386:tid 157620] [client 20.1.169.243:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/post-types-order/compatibility/themes/db-status.php"] [unique_id "aoSCx01jzAhYHVVT1WfsCQAAAXI"] [Tue Aug 18 13:05:27.135697 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.85:33874] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:27.136031 2026] [security2:error] [pid 157386:tid 157642] [client 20.215.241.237:40029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/key.php"] [unique_id "aoSCx01jzAhYHVVT1WfsDAAAAYg"] [Tue Aug 18 13:05:27.136133 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.85:33874] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:27.191883 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/search.php"] [unique_id "aoSCx01jzAhYHVVT1WfsEAAAATw"] [Tue Aug 18 13:05:27.201778 2026] [security2:error] [pid 157386:tid 157613] [client 20.171.51.14:7875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vw.php"] [unique_id "aoSCx01jzAhYHVVT1WfsEQAAAWs"] [Tue Aug 18 13:05:27.263405 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:27.263829 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:27.273826 2026] [security2:error] [pid 157386:tid 157592] [client 68.221.73.131:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/mac.php"] [unique_id "aoSCx01jzAhYHVVT1WfsFAAAAVY"] [Tue Aug 18 13:05:27.296581 2026] [security2:error] [pid 157386:tid 157585] [client 68.155.154.236:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSCx01jzAhYHVVT1WfsFgAAAU8"] [Tue Aug 18 13:05:27.329606 2026] [security2:error] [pid 157386:tid 157640] [client 158.23.17.4:20436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kl.php"] [unique_id "aoSCx01jzAhYHVVT1WfsFwAAAYY"] [Tue Aug 18 13:05:27.348669 2026] [security2:error] [pid 157386:tid 157631] [client 45.131.195.101:26469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.chicodareia.com.br"] [uri "/"] [unique_id "aoSCx01jzAhYHVVT1WfsGQAAAX0"] [Tue Aug 18 13:05:27.358702 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:21922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ko.php"] [unique_id "aoSCx01jzAhYHVVT1WfsGgAAASY"] [Tue Aug 18 13:05:27.359475 2026] [security2:error] [pid 157386:tid 157618] [client 40.85.222.29:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSCx01jzAhYHVVT1WfsGwAAAXA"] [Tue Aug 18 13:05:27.368448 2026] [security2:error] [pid 157386:tid 157595] [client 138.36.100.162:43097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCx01jzAhYHVVT1WfsHAAAAVk"] [Tue Aug 18 13:05:27.368554 2026] [security2:error] [pid 157386:tid 157595] [client 138.36.100.162:43097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCx01jzAhYHVVT1WfsHAAAAVk"] [Tue Aug 18 13:05:27.383571 2026] [security2:error] [pid 157386:tid 157434] [remote 162.214.205.212:38186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoSCx01jzAhYHVVT1WfsHQABGi8"] [Tue Aug 18 13:05:27.407276 2026] [security2:error] [pid 157386:tid 157562] [client 20.151.109.219:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/va.php"] [unique_id "aoSCx01jzAhYHVVT1WfsHgAAATg"] [Tue Aug 18 13:05:27.409787 2026] [security2:error] [pid 157386:tid 157619] [client 132.196.30.78:19876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/archive.php"] [unique_id "aoSCx01jzAhYHVVT1WfsHwAAAXE"] [Tue Aug 18 13:05:27.409901 2026] [security2:error] [pid 157386:tid 157612] [client 20.250.13.23:35571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSCx01jzAhYHVVT1WfsIAAAAWo"] [Tue Aug 18 13:05:27.446130 2026] [security2:error] [pid 157386:tid 157636] [client 20.79.204.6:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/p.php"] [unique_id "aoSCx01jzAhYHVVT1WfsIgAAAYI"] [Tue Aug 18 13:05:27.454389 2026] [security2:error] [pid 157386:tid 157525] [client 20.1.169.243:15726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/post.php"] [unique_id "aoSCx01jzAhYHVVT1WfsIwAAARM"] [Tue Aug 18 13:05:27.455690 2026] [security2:error] [pid 157386:tid 157529] [client 20.91.215.254:7564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSCx01jzAhYHVVT1WfsJAAAARc"] [Tue Aug 18 13:05:27.458246 2026] [security2:error] [pid 157386:tid 157625] [client 40.74.65.169:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/new.php"] [unique_id "aoSCx01jzAhYHVVT1WfsJQAAAXc"] [Tue Aug 18 13:05:27.493866 2026] [security2:error] [pid 157386:tid 157630] [client 20.25.139.174:4596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/file.php"] [unique_id "aoSCx01jzAhYHVVT1WfsJgAAAXw"] [Tue Aug 18 13:05:27.564618 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:27.565020 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:27.648056 2026] [security2:error] [pid 157386:tid 157524] [client 20.250.13.23:7509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/info.php"] [unique_id "aoSCx01jzAhYHVVT1WfsLQAAARI"] [Tue Aug 18 13:05:27.654104 2026] [security2:error] [pid 157386:tid 157535] [client 4.232.151.198:25224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/notifications.php"] [unique_id "aoSCx01jzAhYHVVT1WfsLgAAAR0"] [Tue Aug 18 13:05:27.679337 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:54136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCx01jzAhYHVVT1WfsMQAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:27.687578 2026] [security2:error] [pid 157386:tid 157543] [client 20.171.51.14:31139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCx01jzAhYHVVT1WfsMgAAASU"] [Tue Aug 18 13:05:27.691900 2026] [security2:error] [pid 157386:tid 157554] [client 74.7.228.4:38074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rstcomercio.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSCx01jzAhYHVVT1WfsMwABMCI"] [Tue Aug 18 13:05:27.695207 2026] [security2:error] [pid 157386:tid 157564] [client 20.171.51.14:47122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lj.php"] [unique_id "aoSCx01jzAhYHVVT1WfsNQAAATo"] [Tue Aug 18 13:05:27.704588 2026] [security2:error] [pid 157386:tid 157574] [client 40.85.222.29:6625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/index/function.php"] [unique_id "aoSCx01jzAhYHVVT1WfsNwAAAUQ"] [Tue Aug 18 13:05:27.745534 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fo.php"] [unique_id "aoSCx01jzAhYHVVT1WfsOwAAAVQ"] [Tue Aug 18 13:05:27.759775 2026] [security2:error] [pid 157386:tid 157603] [client 20.215.241.237:40015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/chosen.php"] [unique_id "aoSCx01jzAhYHVVT1WfsPAAAAWE"] [Tue Aug 18 13:05:27.814199 2026] [security2:error] [pid 157386:tid 157527] [client 68.221.73.131:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/chosen.php"] [unique_id "aoSCx01jzAhYHVVT1WfsPwAAARU"] [Tue Aug 18 13:05:27.857172 2026] [security2:error] [pid 157386:tid 157610] [client 68.155.154.236:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSCx01jzAhYHVVT1WfsQQAAAWg"] [Tue Aug 18 13:05:27.898073 2026] [security2:error] [pid 157386:tid 157608] [client 20.1.169.243:15686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/simply-gallery-block/plugins/ms-files.php"] [unique_id "aoSCx01jzAhYHVVT1WfsRQAAAWY"] [Tue Aug 18 13:05:27.902019 2026] [security2:error] [pid 157386:tid 157635] [client 103.120.71.157:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCx01jzAhYHVVT1WfsRAAAAYE"] [Tue Aug 18 13:05:27.902144 2026] [security2:error] [pid 157386:tid 157635] [client 103.120.71.157:40025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCx01jzAhYHVVT1WfsRAAAAYE"] [Tue Aug 18 13:05:27.994277 2026] [security2:error] [pid 157386:tid 157541] [client 45.131.195.55:60555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.chicodareia.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "aoSCx01jzAhYHVVT1WfsSQAAASM"] [Tue Aug 18 13:05:28.007130 2026] [security2:error] [pid 157386:tid 157522] [client 158.23.17.4:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gs.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsSgAAARA"] [Tue Aug 18 13:05:28.014581 2026] [security2:error] [pid 157386:tid 157583] [client 40.85.222.29:6747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsTAAAAU0"] [Tue Aug 18 13:05:28.033798 2026] [security2:error] [pid 157386:tid 157534] [client 20.250.13.23:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-configs.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsTQAAARw"] [Tue Aug 18 13:05:28.071371 2026] [security2:error] [pid 157386:tid 157558] [client 20.25.139.174:4597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/adminfuns.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsTwAAATQ"] [Tue Aug 18 13:05:28.103163 2026] [security2:error] [pid 157386:tid 157622] [client 52.173.121.69:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsUgAAAXQ"] [Tue Aug 18 13:05:28.112049 2026] [security2:error] [pid 157386:tid 157573] [client 200.145.216.228:36098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "memo.ind.br"] [uri "/index.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsSwAAAUM"], referer: https://memo.ind.br/politica-de-privacidade-e-cookies [Tue Aug 18 13:05:28.145046 2026] [security2:error] [pid 157386:tid 157631] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsUwABfUU"] [Tue Aug 18 13:05:28.155525 2026] [security2:error] [pid 157386:tid 157577] [client 40.74.65.169:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/new.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsWAAAAUc"] [Tue Aug 18 13:05:28.162303 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:28.162573 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:28.167671 2026] [security2:error] [pid 157386:tid 157612] [client 20.151.109.219:49948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/loading.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsWgAAAWo"] [Tue Aug 18 13:05:28.186987 2026] [security2:error] [pid 157386:tid 157636] [client 20.151.109.219:21937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/pl.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsWwAAAYI"] [Tue Aug 18 13:05:28.191958 2026] [security2:error] [pid 157386:tid 157614] [client 20.91.215.254:7897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsXAAAAWw"] [Tue Aug 18 13:05:28.216501 2026] [security2:error] [pid 157386:tid 157525] [client 20.206.73.37:16458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/special.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsXQAAARM"] [Tue Aug 18 13:05:28.238522 2026] [security2:error] [pid 157386:tid 157625] [client 68.155.154.236:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsXgAAAXc"] [Tue Aug 18 13:05:28.267127 2026] [security2:error] [pid 157386:tid 157537] [client 20.1.169.243:15716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/softaculous-pro/assets/images/plugins/plugin-install.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsYgAAAR8"] [Tue Aug 18 13:05:28.299224 2026] [security2:error] [pid 157386:tid 157530] [client 40.85.222.29:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/Cachex.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsZAAAARg"] [Tue Aug 18 13:05:28.338171 2026] [security2:error] [pid 157386:tid 157611] [client 20.215.241.237:57177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/wpxml.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsZQAAAWk"] [Tue Aug 18 13:05:28.348817 2026] [security2:error] [pid 157386:tid 157433] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsZwABSi4"] [Tue Aug 18 13:05:28.348962 2026] [security2:error] [pid 157386:tid 157580] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsZwABSi4"] [Tue Aug 18 13:05:28.369228 2026] [security2:error] [pid 157386:tid 157549] [client 20.151.109.219:27340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/build.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsaAAAASs"] [Tue Aug 18 13:05:28.419196 2026] [security2:error] [pid 157386:tid 157550] [client 4.232.151.198:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/Requests/Exception/content.php.suspected"] [unique_id "aoSCyE1jzAhYHVVT1WfsbAAAASw"] [Tue Aug 18 13:05:28.463348 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:28.463618 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:28.491792 2026] [security2:error] [pid 157386:tid 157535] [client 20.171.51.14:38775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kh.php"] [unique_id "aoSCyE1jzAhYHVVT1WfscAAAAR0"] [Tue Aug 18 13:05:28.519108 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:63272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ke.php"] [unique_id "aoSCyE1jzAhYHVVT1WfscgAAASU"] [Tue Aug 18 13:05:28.582205 2026] [security2:error] [pid 157386:tid 157589] [client 20.250.13.23:22431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/elp.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsdQAAAVM"] [Tue Aug 18 13:05:28.597710 2026] [security2:error] [pid 157386:tid 157599] [client 68.221.73.131:31130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsdgAAAV0"] [Tue Aug 18 13:05:28.604251 2026] [security2:error] [pid 157386:tid 157627] [client 45.131.195.71:60093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.chicodareia.com.br"] [uri "/media/system/js/core.js"] [unique_id "aoSCyE1jzAhYHVVT1WfsdwAAAXk"] [Tue Aug 18 13:05:28.611940 2026] [access_compat:error] [pid 157386:tid 157616] [client 173.252.87.115:33440] AH01797: client denied by server configuration: /home2/anmultimarcas/public_html/meta.json [Tue Aug 18 13:05:28.636361 2026] [security2:error] [pid 157386:tid 157552] [client 20.1.169.243:15723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/updraftplus/templates/wp-admin/options.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsewAAAS4"] [Tue Aug 18 13:05:28.638130 2026] [security2:error] [pid 157386:tid 157524] [client 20.25.139.174:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/404.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsfAAAARI"] [Tue Aug 18 13:05:28.643917 2026] [security2:error] [pid 157386:tid 157626] [client 40.85.222.29:6624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsfQAAAXg"] [Tue Aug 18 13:05:28.650625 2026] [security2:error] [pid 157386:tid 157598] [client 132.196.30.78:20066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/bless.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsfgAAAVw"] [Tue Aug 18 13:05:28.676807 2026] [security2:error] [pid 157386:tid 157630] [client 20.79.204.6:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.advocaciasc.com"] [uri "/php.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsgAAAAXw"] [Tue Aug 18 13:05:28.680017 2026] [security2:error] [pid 157386:tid 157571] [client 20.250.13.23:8125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/a.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsgQAAAUE"] [Tue Aug 18 13:05:28.700363 2026] [security2:error] [pid 157386:tid 157605] [client 20.250.13.23:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-post.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsggAAAWM"] [Tue Aug 18 13:05:28.709425 2026] [security2:error] [pid 157386:tid 157588] [client 213.35.127.232:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCyE1jzAhYHVVT1WfshAAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:28.714215 2026] [security2:error] [pid 157386:tid 157528] [client 158.23.17.4:49189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lw.php"] [unique_id "aoSCyE1jzAhYHVVT1WfshQAAARY"] [Tue Aug 18 13:05:28.728113 2026] [security2:error] [pid 157386:tid 157608] [client 20.206.73.37:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/1xmomo.php"] [unique_id "aoSCyE1jzAhYHVVT1WfshgAAAWY"] [Tue Aug 18 13:05:28.763282 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:28.763548 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:28.842528 2026] [security2:error] [pid 157386:tid 157613] [client 20.215.241.237:60096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/file1221.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsjAAAAWs"] [Tue Aug 18 13:05:28.857734 2026] [security2:error] [pid 157386:tid 157587] [client 40.74.65.169:60283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/apreset.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsjQAAAVE"] [Tue Aug 18 13:05:28.872141 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nh.php"] [unique_id "aoSCyE1jzAhYHVVT1WfsjwAAAT0"] [Tue Aug 18 13:05:28.896098 2026] [security2:error] [pid 157386:tid 157615] [client 74.248.130.103:22383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/inso.php"] [unique_id "aoSCyE1jzAhYHVVT1WfskQAAAW0"] [Tue Aug 18 13:05:28.900900 2026] [security2:error] [pid 157386:tid 157519] [client 20.91.215.254:16614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSCyE1jzAhYHVVT1WfskgAAAQ0"] [Tue Aug 18 13:05:28.962092 2026] [security2:error] [pid 157386:tid 157619] [client 40.85.222.29:6621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCyE1jzAhYHVVT1WfslAAAAXE"] [Tue Aug 18 13:05:29.003477 2026] [security2:error] [pid 157386:tid 157557] [client 20.1.169.243:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/admin.php"] [unique_id "aoSCyU1jzAhYHVVT1WfslgAAATM"] [Tue Aug 18 13:05:29.020032 2026] [authz_core:error] [pid 157386:tid 157640] [client 192.178.4.133:36792] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:29.020302 2026] [authz_core:error] [pid 157386:tid 157640] [client 192.178.4.133:36792] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:29.043969 2026] [security2:error] [pid 157386:tid 157625] [client 68.155.154.236:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsmQAAAXc"] [Tue Aug 18 13:05:29.063305 2026] [security2:error] [pid 157386:tid 157560] [client 20.206.73.37:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/dex.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsmwAAATY"] [Tue Aug 18 13:05:29.068433 2026] [security2:error] [pid 157386:tid 157537] [client 20.171.51.14:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/jb.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsnAAAAR8"] [Tue Aug 18 13:05:29.119872 2026] [security2:error] [pid 157386:tid 157622] [client 4.232.151.198:41602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/makesmtp.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsoAAAAXQ"] [Tue Aug 18 13:05:29.194681 2026] [security2:error] [pid 157386:tid 157517] [client 165.227.157.145:59976] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "infoprodutores.com"] [uri "/"] [unique_id "aoSCyU1jzAhYHVVT1WfsogAAAQs"] [Tue Aug 18 13:05:29.219115 2026] [security2:error] [pid 157386:tid 157550] [client 20.151.109.219:21264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/env.php"] [unique_id "aoSCyU1jzAhYHVVT1WfspAAAASw"] [Tue Aug 18 13:05:29.234776 2026] [security2:error] [pid 157386:tid 157516] [client 20.25.139.174:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wk/index.php"] [unique_id "aoSCyU1jzAhYHVVT1WfspgAAAQo"] [Tue Aug 18 13:05:29.253561 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:5356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/oo.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsqAAAAR0"] [Tue Aug 18 13:05:29.267819 2026] [security2:error] [pid 157386:tid 157561] [client 45.92.229.89:34181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsnwAAATc"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:05:29.269478 2026] [security2:error] [pid 157386:tid 157539] [client 20.171.51.14:11820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsqQAAASE"] [Tue Aug 18 13:05:29.302876 2026] [security2:error] [pid 157386:tid 157599] [client 40.85.222.29:6781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsqwAAAV0"] [Tue Aug 18 13:05:29.315558 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:58707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/defaul.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsrAAAAXk"] [Tue Aug 18 13:05:29.321577 2026] [security2:error] [pid 157386:tid 157611] [client 20.250.13.23:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsrQAAAWk"] [Tue Aug 18 13:05:29.329454 2026] [security2:error] [pid 157386:tid 157438] [remote 203.99.146.53:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsrgABdTM"] [Tue Aug 18 13:05:29.370128 2026] [security2:error] [pid 157386:tid 157568] [client 20.1.169.243:15711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/maintenance.php"] [unique_id "aoSCyU1jzAhYHVVT1WfssgAAAT4"] [Tue Aug 18 13:05:29.402234 2026] [security2:error] [pid 157386:tid 157526] [client 20.215.241.237:60157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/nox.php"] [unique_id "aoSCyU1jzAhYHVVT1WfstAAAARQ"] [Tue Aug 18 13:05:29.410006 2026] [security2:error] [pid 157386:tid 157635] [client 102.213.179.104:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfstgAAAYE"] [Tue Aug 18 13:05:29.410367 2026] [security2:error] [pid 157386:tid 157635] [client 102.213.179.104:64435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfstgAAAYE"] [Tue Aug 18 13:05:29.427605 2026] [security2:error] [pid 157386:tid 157581] [client 197.184.64.235:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfstwAAAUs"] [Tue Aug 18 13:05:29.427752 2026] [security2:error] [pid 157386:tid 157581] [client 197.184.64.235:42676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfstwAAAUs"] [Tue Aug 18 13:05:29.497675 2026] [security2:error] [pid 157386:tid 157541] [client 52.173.121.69:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsuwAAASM"] [Tue Aug 18 13:05:29.533511 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/1mage.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsvgAAARw"] [Tue Aug 18 13:05:29.534442 2026] [security2:error] [pid 157386:tid 157547] [client 37.40.227.74:56537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsvwAAASk"] [Tue Aug 18 13:05:29.544136 2026] [security2:error] [pid 157386:tid 157547] [client 37.40.227.74:56537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsvwAAASk"] [Tue Aug 18 13:05:29.547798 2026] [security2:error] [pid 157386:tid 157596] [client 168.62.48.100:4144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCyU1jzAhYHVVT1WfswQAAAVo"] [Tue Aug 18 13:05:29.556797 2026] [security2:error] [pid 157386:tid 157603] [client 20.250.13.23:34102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCyU1jzAhYHVVT1WfswgAAAWE"] [Tue Aug 18 13:05:29.599345 2026] [security2:error] [pid 157386:tid 157585] [client 40.85.222.29:6636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/.cache/x.php"] [unique_id "aoSCyU1jzAhYHVVT1WfswwAAAU8"] [Tue Aug 18 13:05:29.620389 2026] [security2:error] [pid 157386:tid 157638] [client 74.248.130.103:54856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/shiny.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsxAAAAYQ"] [Tue Aug 18 13:05:29.640140 2026] [security2:error] [pid 157386:tid 157562] [client 20.171.51.14:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/do.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsxwAAATg"] [Tue Aug 18 13:05:29.663176 2026] [security2:error] [pid 157386:tid 157532] [client 40.74.65.169:16257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/chosen.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsyQAAARo"] [Tue Aug 18 13:05:29.667153 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:29.667421 2026] [authz_core:error] [pid 157386:tid 157431] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:29.676611 2026] [security2:error] [pid 157386:tid 157518] [client 68.155.154.236:14323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsywAAAQw"] [Tue Aug 18 13:05:29.716823 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:62930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ja.php"] [unique_id "aoSCyU1jzAhYHVVT1WfszgAAAVY"] [Tue Aug 18 13:05:29.733714 2026] [security2:error] [pid 157386:tid 157565] [client 5.31.227.224:59050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs0QAAATs"] [Tue Aug 18 13:05:29.735432 2026] [security2:error] [pid 157386:tid 157595] [client 20.1.169.243:15735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/module.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs0gAAAVk"] [Tue Aug 18 13:05:29.740062 2026] [security2:error] [pid 157386:tid 157593] [client 20.91.215.254:7890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs0wAAAVc"] [Tue Aug 18 13:05:29.740644 2026] [security2:error] [pid 157386:tid 157565] [client 5.31.227.224:59050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs0QAAATs"] [Tue Aug 18 13:05:29.745080 2026] [security2:error] [pid 157386:tid 157545] [client 213.35.127.232:54551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs1AAAASc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:29.755658 2026] [fcgid:warn] [pid 157386:tid 157537] (70014)End of file found: [client 199.45.155.71:33656] mod_fcgid: can't get data from http client [Tue Aug 18 13:05:29.765221 2026] [security2:error] [pid 157386:tid 157567] [client 4.232.151.198:18526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/img/class-wp-http-client.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs1wAAAT0"] [Tue Aug 18 13:05:29.766887 2026] [security2:error] [pid 157386:tid 157573] [client 20.25.139.174:4517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/about.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs2AAAAUM"] [Tue Aug 18 13:05:29.782694 2026] [security2:error] [pid 157386:tid 157552] [client 132.196.30.78:20234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/sagax1.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs2QAAAS4"] [Tue Aug 18 13:05:29.818742 2026] [security2:error] [pid 157386:tid 157589] [client 34.198.201.66:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSCyU1jzAhYHVVT1WfsuAABU1M"], referer: https://thatianysantana.com.br/ [Tue Aug 18 13:05:29.875612 2026] [security2:error] [pid 157386:tid 157561] [client 20.215.241.237:11893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/akismet.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs4AAAATc"] [Tue Aug 18 13:05:29.895792 2026] [security2:error] [pid 157386:tid 157618] [client 158.23.17.4:46805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vj.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs4gAAAXA"] [Tue Aug 18 13:05:29.916575 2026] [security2:error] [pid 157386:tid 157599] [client 40.85.222.29:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs5AAAAV0"] [Tue Aug 18 13:05:29.968496 2026] [authz_core:error] [pid 157386:tid 157454] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:29.968855 2026] [authz_core:error] [pid 157386:tid 157454] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:29.981201 2026] [security2:error] [pid 157386:tid 157600] [client 114.119.135.158:29111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ateliedoautomovel.com.br"] [uri "/images/carrossel/m13.jpg"] [unique_id "aoSCyU1jzAhYHVVT1Wfs6wAAAV4"], referer: http://ateliedoautomovel.com.br/images/carrossel/m13.jpg [Tue Aug 18 13:05:29.990833 2026] [security2:error] [pid 157386:tid 157598] [client 68.221.73.131:41871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs7AAAAVw"] [Tue Aug 18 13:05:29.994213 2026] [security2:error] [pid 157386:tid 157564] [client 20.118.133.132:40975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/h.php"] [unique_id "aoSCyU1jzAhYHVVT1Wfs7gAAATo"] [Tue Aug 18 13:05:30.036824 2026] [security2:error] [pid 157386:tid 157517] [client 20.250.13.23:35523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs8QAAAQs"] [Tue Aug 18 13:05:30.040935 2026] [security2:error] [pid 157386:tid 157588] [client 68.155.154.236:14210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs8gAAAVI"] [Tue Aug 18 13:05:30.082977 2026] [security2:error] [pid 157386:tid 157571] [client 196.12.128.158:56215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs9QAAAUE"] [Tue Aug 18 13:05:30.083124 2026] [security2:error] [pid 157386:tid 157571] [client 196.12.128.158:56215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs9QAAAUE"] [Tue Aug 18 13:05:30.097210 2026] [security2:error] [pid 157386:tid 157639] [client 20.151.109.219:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xx.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs9gAAAYU"] [Tue Aug 18 13:05:30.108429 2026] [security2:error] [pid 157386:tid 157636] [client 20.1.169.243:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-super-cache/plugins/index.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs9wAAAYI"] [Tue Aug 18 13:05:30.119800 2026] [security2:error] [pid 157386:tid 157531] [client 68.221.73.131:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/wpxml.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs-AAAARk"] [Tue Aug 18 13:05:30.130957 2026] [security2:error] [pid 157386:tid 157640] [client 20.104.100.201:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs-gAAAYY"] [Tue Aug 18 13:05:30.169421 2026] [security2:error] [pid 157386:tid 157558] [client 20.151.109.219:53538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mz.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs_AAAATQ"] [Tue Aug 18 13:05:30.183145 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:17649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/twin.php"] [unique_id "aoSCyk1jzAhYHVVT1Wfs_wAAAWE"] [Tue Aug 18 13:05:30.196868 2026] [security2:error] [pid 157386:tid 157480] [remote 162.214.205.212:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSCyk1jzAhYHVVT1WftAAABIV0"] [Tue Aug 18 13:05:30.209170 2026] [security2:error] [pid 157386:tid 157583] [client 40.85.222.29:6598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSCyk1jzAhYHVVT1WftAQAAAU0"] [Tue Aug 18 13:05:30.233522 2026] [security2:error] [pid 157386:tid 157546] [client 40.74.65.169:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/imsc.php"] [unique_id "aoSCyk1jzAhYHVVT1WftAwAAASg"] [Tue Aug 18 13:05:30.274631 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:30.275079 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:30.311424 2026] [security2:error] [pid 157386:tid 157592] [client 20.215.241.237:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/admin.php"] [unique_id "aoSCyk1jzAhYHVVT1WftCAAAAVY"] [Tue Aug 18 13:05:30.311857 2026] [security2:error] [pid 157386:tid 157533] [client 20.25.139.174:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/term.php"] [unique_id "aoSCyk1jzAhYHVVT1WftCQAAARs"] [Tue Aug 18 13:05:30.378027 2026] [security2:error] [pid 157386:tid 157612] [client 132.196.30.78:20275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wpc.php"] [unique_id "aoSCyk1jzAhYHVVT1WftDgAAAWo"] [Tue Aug 18 13:05:30.397841 2026] [security2:error] [pid 157386:tid 157641] [client 168.62.48.100:4157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCyk1jzAhYHVVT1WftEAAAAYc"] [Tue Aug 18 13:05:30.412062 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/conn-test.php"] [unique_id "aoSCyk1jzAhYHVVT1WftEQAAAT0"] [Tue Aug 18 13:05:30.488565 2026] [security2:error] [pid 157386:tid 157589] [client 40.85.222.29:7113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCyk1jzAhYHVVT1WftFwAAAVM"] [Tue Aug 18 13:05:30.506350 2026] [security2:error] [pid 157386:tid 157601] [client 20.171.51.14:47161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/yw.php"] [unique_id "aoSCyk1jzAhYHVVT1WftGAAAAV8"] [Tue Aug 18 13:05:30.537205 2026] [autoindex:error] [pid 157386:tid 157518] [client 20.91.215.254:16630] AH01276: Cannot serve directory /home3/pletud/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:30.578830 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.49.167:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCyk1jzAhYHVVT1WftIAAAAWA"] [Tue Aug 18 13:05:30.634625 2026] [security2:error] [pid 157386:tid 157568] [client 68.155.154.236:14150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSCyk1jzAhYHVVT1WftIwAAAT4"] [Tue Aug 18 13:05:30.649653 2026] [security2:error] [pid 157386:tid 157615] [client 20.1.169.243:15604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/style-engine/style-engine/ixr/plugins/wp-mail.php"] [unique_id "aoSCyk1jzAhYHVVT1WftJQAAAW0"] [Tue Aug 18 13:05:30.668069 2026] [security2:error] [pid 157386:tid 157635] [client 158.23.17.4:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mimes.php"] [unique_id "aoSCyk1jzAhYHVVT1WftJgAAAYE"] [Tue Aug 18 13:05:30.671843 2026] [security2:error] [pid 157386:tid 157622] [client 20.250.13.23:44092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-2019.php"] [unique_id "aoSCyk1jzAhYHVVT1WftJwAAAXQ"] [Tue Aug 18 13:05:30.725179 2026] [security2:error] [pid 157386:tid 157609] [client 74.248.130.103:7924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/403dd.php"] [unique_id "aoSCyk1jzAhYHVVT1WftKgAAAWc"] [Tue Aug 18 13:05:30.746253 2026] [security2:error] [pid 157386:tid 157571] [client 20.91.215.254:16630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/ku.php"] [unique_id "aoSCyk1jzAhYHVVT1WftKwAAAUE"] [Tue Aug 18 13:05:30.762527 2026] [security2:error] [pid 157386:tid 157525] [client 20.215.241.237:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fipe.multiveicular.org.br"] [uri "/ajax.php"] [unique_id "aoSCyk1jzAhYHVVT1WftLAAAARM"] [Tue Aug 18 13:05:30.765249 2026] [security2:error] [pid 157386:tid 157552] [client 213.35.127.232:54765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCyk1jzAhYHVVT1WftLQAAAS4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:30.787777 2026] [security2:error] [pid 157386:tid 157541] [client 40.85.222.29:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSCyk1jzAhYHVVT1WftLwAAASM"] [Tue Aug 18 13:05:30.790388 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fg.php"] [unique_id "aoSCyk1jzAhYHVVT1WftMAAAAX8"] [Tue Aug 18 13:05:30.816767 2026] [security2:error] [pid 157386:tid 157527] [client 223.185.37.47:16987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCyk1jzAhYHVVT1WftSAAAARU"] [Tue Aug 18 13:05:30.816871 2026] [security2:error] [pid 157386:tid 157527] [client 223.185.37.47:16987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSCyk1jzAhYHVVT1WftSAAAARU"] [Tue Aug 18 13:05:30.834442 2026] [security2:error] [pid 157386:tid 157517] [client 20.25.139.174:4523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSCyk1jzAhYHVVT1WftSQAAAQs"] [Tue Aug 18 13:05:30.872535 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:30.872906 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:30.909555 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/imscjpg.php"] [unique_id "aoSCyk1jzAhYHVVT1WftUQAAATM"] [Tue Aug 18 13:05:30.985404 2026] [security2:error] [pid 157386:tid 157565] [client 20.151.109.219:56017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ft.php"] [unique_id "aoSCyk1jzAhYHVVT1WftXQAAATs"] [Tue Aug 18 13:05:30.989408 2026] [security2:error] [pid 157386:tid 157595] [client 20.104.49.167:26395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCyk1jzAhYHVVT1WftXgAAAVk"] [Tue Aug 18 13:05:31.014216 2026] [security2:error] [pid 157386:tid 157556] [client 20.1.169.243:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/test.php"] [unique_id "aoSCy01jzAhYHVVT1WftYgAAATI"] [Tue Aug 18 13:05:31.014740 2026] [autoindex:error] [pid 157386:tid 157612] [client 4.232.151.198:25259] AH01276: Cannot serve directory /home2/pixmid70/public_html/wp-includes/js/tinymce/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:31.109804 2026] [security2:error] [pid 157386:tid 157581] [client 40.85.222.29:6639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSCy01jzAhYHVVT1WftaAAAAUs"] [Tue Aug 18 13:05:31.117898 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/45.php"] [unique_id "aoSCy01jzAhYHVVT1WftaQAAAUM"] [Tue Aug 18 13:05:31.154637 2026] [security2:error] [pid 157386:tid 157548] [client 20.151.109.219:49335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ve.php"] [unique_id "aoSCy01jzAhYHVVT1WftagAAASo"] [Tue Aug 18 13:05:31.174129 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:31.174363 2026] [security2:error] [pid 157386:tid 157601] [client 68.155.154.236:14228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSCy01jzAhYHVVT1WftbAAAAV8"] [Tue Aug 18 13:05:31.174377 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:31.179452 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:13787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/new2.php"] [unique_id "aoSCy01jzAhYHVVT1WftbQAAAXM"] [Tue Aug 18 13:05:31.184587 2026] [security2:error] [pid 157386:tid 157503] [remote 47.128.31.155:11366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSCy01jzAhYHVVT1WftbwABWHQ"] [Tue Aug 18 13:05:31.200994 2026] [security2:error] [pid 157386:tid 157642] [client 158.23.17.4:20418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ni.php"] [unique_id "aoSCy01jzAhYHVVT1WftcAAAAYg"] [Tue Aug 18 13:05:31.222739 2026] [security2:error] [pid 157386:tid 157586] [client 4.232.151.198:25259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/linkpreview/alfa.php"] [unique_id "aoSCy01jzAhYHVVT1WftcgAAAVA"] [Tue Aug 18 13:05:31.227647 2026] [security2:error] [pid 157386:tid 157610] [client 74.248.130.103:54869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/baba.php"] [unique_id "aoSCy01jzAhYHVVT1WftcwAAAWg"] [Tue Aug 18 13:05:31.238451 2026] [security2:error] [pid 157386:tid 157550] [client 168.62.48.100:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCy01jzAhYHVVT1WftdAAAASw"] [Tue Aug 18 13:05:31.357495 2026] [security2:error] [pid 157386:tid 157607] [client 20.25.139.174:4501] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.acassiocorretor.com.br"] [uri "/1.php"] [unique_id "aoSCy01jzAhYHVVT1WftdgAAAWU"] [Tue Aug 18 13:05:31.357625 2026] [security2:error] [pid 157386:tid 157607] [client 20.25.139.174:4501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/1.php"] [unique_id "aoSCy01jzAhYHVVT1WftdgAAAWU"] [Tue Aug 18 13:05:31.379147 2026] [security2:error] [pid 157386:tid 157521] [client 20.1.169.243:15728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSCy01jzAhYHVVT1WfteAAAAQ8"] [Tue Aug 18 13:05:31.399644 2026] [security2:error] [pid 157386:tid 157623] [client 20.171.51.14:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/qh.php"] [unique_id "aoSCy01jzAhYHVVT1WfteQAAAXU"] [Tue Aug 18 13:05:31.421555 2026] [security2:error] [pid 157386:tid 157626] [client 40.85.222.29:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSCy01jzAhYHVVT1WftegAAAXg"] [Tue Aug 18 13:05:31.446961 2026] [security2:error] [pid 157386:tid 157604] [client 20.203.183.135:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCy01jzAhYHVVT1WftewAAAWI"] [Tue Aug 18 13:05:31.448499 2026] [security2:error] [pid 157386:tid 157518] [client 20.250.13.23:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/cjfuns.php"] [unique_id "aoSCy01jzAhYHVVT1WftfAAAAQw"] [Tue Aug 18 13:05:31.448864 2026] [security2:error] [pid 157386:tid 157635] [client 20.151.109.219:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ia.php"] [unique_id "aoSCy01jzAhYHVVT1WftfQAAAYE"] [Tue Aug 18 13:05:31.477355 2026] [security2:error] [pid 157386:tid 157582] [client 20.206.73.37:33685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCy01jzAhYHVVT1WftggAAAUw"] [Tue Aug 18 13:05:31.478898 2026] [security2:error] [pid 157386:tid 157566] [client 132.196.30.78:20255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/fone1.php"] [unique_id "aoSCy01jzAhYHVVT1WftgwAAATw"] [Tue Aug 18 13:05:31.528994 2026] [security2:error] [pid 157386:tid 157639] [client 20.104.49.167:21909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/media.php"] [unique_id "aoSCy01jzAhYHVVT1WfthgAAAYU"] [Tue Aug 18 13:05:31.575493 2026] [security2:error] [pid 157386:tid 157613] [client 68.155.154.236:14148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSCy01jzAhYHVVT1WftiQAAAWs"] [Tue Aug 18 13:05:31.597044 2026] [security2:error] [pid 157386:tid 157597] [client 20.250.13.23:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/chosen.php"] [unique_id "aoSCy01jzAhYHVVT1WftjAAAAVs"] [Tue Aug 18 13:05:31.603173 2026] [security2:error] [pid 157386:tid 157527] [client 40.74.65.169:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/qlex1.php"] [unique_id "aoSCy01jzAhYHVVT1WftjQAAARU"] [Tue Aug 18 13:05:31.609452 2026] [security2:error] [pid 157386:tid 157558] [client 20.151.109.219:17037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/h.php"] [unique_id "aoSCy01jzAhYHVVT1WftjgAAATQ"] [Tue Aug 18 13:05:31.636144 2026] [autoindex:error] [pid 157386:tid 157578] [client 20.91.215.254:16577] AH01276: Cannot serve directory /home3/pletud/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:31.662641 2026] [security2:error] [pid 157386:tid 157638] [client 40.74.65.169:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/wpxml.php"] [unique_id "aoSCy01jzAhYHVVT1WftkAAAAYQ"] [Tue Aug 18 13:05:31.664432 2026] [security2:error] [pid 157386:tid 157562] [client 20.206.73.37:2828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/mosty.php"] [unique_id "aoSCy01jzAhYHVVT1WftkQAAATg"] [Tue Aug 18 13:05:31.682298 2026] [security2:error] [pid 157386:tid 157577] [client 68.221.73.131:40716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/system_log.php"] [unique_id "aoSCy01jzAhYHVVT1WftkgAAAUc"] [Tue Aug 18 13:05:31.687534 2026] [security2:error] [pid 157386:tid 157534] [client 20.250.13.23:20141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/666.php"] [unique_id "aoSCy01jzAhYHVVT1WftkwAAARw"] [Tue Aug 18 13:05:31.710624 2026] [security2:error] [pid 157386:tid 157414] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCy01jzAhYHVVT1WftlAABaRs"] [Tue Aug 18 13:05:31.710797 2026] [security2:error] [pid 157386:tid 157611] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCy01jzAhYHVVT1WftlAABaRs"] [Tue Aug 18 13:05:31.749278 2026] [security2:error] [pid 157386:tid 157585] [client 20.1.169.243:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/elementra/skins/politics/plugins/security.php"] [unique_id "aoSCy01jzAhYHVVT1WftlgAAAU8"] [Tue Aug 18 13:05:31.775548 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:31.775821 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:31.778382 2026] [security2:error] [pid 157386:tid 157564] [client 213.35.127.232:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSCy01jzAhYHVVT1WftmAAAATo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:31.802574 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kn.php"] [unique_id "aoSCy01jzAhYHVVT1WftnQAAAVk"] [Tue Aug 18 13:05:31.814109 2026] [security2:error] [pid 157386:tid 157603] [client 112.209.77.43:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.77.209.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/xmlrpc.php"] [unique_id "aoSCy01jzAhYHVVT1WfthAAAAWE"] [Tue Aug 18 13:05:31.814212 2026] [security2:error] [pid 157386:tid 157603] [client 112.209.77.43:25474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "immobili.adm.br"] [uri "/xmlrpc.php"] [unique_id "aoSCy01jzAhYHVVT1WfthAAAAWE"] [Tue Aug 18 13:05:31.845780 2026] [security2:error] [pid 157386:tid 157556] [client 20.91.215.254:16577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/chosen.php"] [unique_id "aoSCy01jzAhYHVVT1WftnwAAATI"] [Tue Aug 18 13:05:31.851883 2026] [authz_core:error] [pid 157386:tid 157492] [remote 57.141.22.98:33774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:31.852140 2026] [authz_core:error] [pid 157386:tid 157492] [remote 57.141.22.98:33774] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:31.858813 2026] [security2:error] [pid 157386:tid 157426] [remote 208.122.213.225:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projectcs.com.au"] [uri "/wp-login.php"] [unique_id "aoSCy01jzAhYHVVT1WftoQABeSc"] [Tue Aug 18 13:05:31.884110 2026] [security2:error] [pid 157386:tid 157539] [client 4.232.151.198:24229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-font-utils.php"] [unique_id "aoSCy01jzAhYHVVT1WftogAAASE"] [Tue Aug 18 13:05:31.884903 2026] [security2:error] [pid 157386:tid 157567] [client 40.85.222.29:6629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSCy01jzAhYHVVT1WftowAAAT0"] [Tue Aug 18 13:05:31.904164 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.49.167:26386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/admin.php"] [unique_id "aoSCy01jzAhYHVVT1WftpAAAAUo"] [Tue Aug 18 13:05:31.926152 2026] [security2:error] [pid 157386:tid 157592] [client 20.25.139.174:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/alfa.php"] [unique_id "aoSCy01jzAhYHVVT1WftpwAAAVY"] [Tue Aug 18 13:05:31.961192 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/r.php"] [unique_id "aoSCy01jzAhYHVVT1WftqgAAATU"] [Tue Aug 18 13:05:32.057340 2026] [security2:error] [pid 157386:tid 157550] [client 20.203.183.135:44379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCzE1jzAhYHVVT1WftrgAAASw"] [Tue Aug 18 13:05:32.076552 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:32.076837 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:32.097382 2026] [security2:error] [pid 157386:tid 157612] [client 20.250.13.23:35545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSCzE1jzAhYHVVT1WftsAAAAWo"] [Tue Aug 18 13:05:32.116371 2026] [security2:error] [pid 157386:tid 157642] [client 20.1.169.243:15722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSCzE1jzAhYHVVT1WftsgAAAYg"] [Tue Aug 18 13:05:32.121667 2026] [security2:error] [pid 157386:tid 157560] [client 3.79.134.69:24834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSCzE1jzAhYHVVT1WftrQAAATY"], referer: https://www.saojudas.com.br [Tue Aug 18 13:05:32.139778 2026] [security2:error] [pid 157386:tid 157602] [client 68.155.154.236:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSCzE1jzAhYHVVT1WftswAAAWA"] [Tue Aug 18 13:05:32.182568 2026] [security2:error] [pid 157386:tid 157599] [client 20.151.109.219:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/rex.php"] [unique_id "aoSCzE1jzAhYHVVT1WfttQAAAV0"] [Tue Aug 18 13:05:32.196617 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wm.php"] [unique_id "aoSCzE1jzAhYHVVT1WftuAAAAW4"] [Tue Aug 18 13:05:32.202009 2026] [security2:error] [pid 157386:tid 157524] [client 158.23.17.4:46800] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/1.php"] [unique_id "aoSCzE1jzAhYHVVT1WftuQAAARI"] [Tue Aug 18 13:05:32.202088 2026] [security2:error] [pid 157386:tid 157524] [client 158.23.17.4:46800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/1.php"] [unique_id "aoSCzE1jzAhYHVVT1WftuQAAARI"] [Tue Aug 18 13:05:32.212072 2026] [security2:error] [pid 157386:tid 157568] [client 168.62.48.100:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCzE1jzAhYHVVT1WftugAAAT4"] [Tue Aug 18 13:05:32.218667 2026] [security2:error] [pid 157386:tid 157626] [client 40.85.222.29:6760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSCzE1jzAhYHVVT1WftuwAAAXg"] [Tue Aug 18 13:05:32.268757 2026] [security2:error] [pid 157386:tid 157618] [client 213.202.253.4:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSCzE1jzAhYHVVT1WftvwAAAXA"], referer: www.google.com [Tue Aug 18 13:05:32.281356 2026] [security2:error] [pid 157386:tid 157528] [client 40.74.65.169:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/mariju.php"] [unique_id "aoSCzE1jzAhYHVVT1WftwAAAARY"] [Tue Aug 18 13:05:32.292076 2026] [security2:error] [pid 157386:tid 157566] [client 20.104.49.167:2747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/mac.php"] [unique_id "aoSCzE1jzAhYHVVT1WftwgAAATw"] [Tue Aug 18 13:05:32.304752 2026] [security2:error] [pid 157386:tid 157593] [client 4.223.113.180:21060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/beence.php"] [unique_id "aoSCzE1jzAhYHVVT1WftwwAAAVc"] [Tue Aug 18 13:05:32.305918 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/40.php"] [unique_id "aoSCzE1jzAhYHVVT1WftxAAAAUE"] [Tue Aug 18 13:05:32.376995 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:32.377262 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:32.447211 2026] [security2:error] [pid 157386:tid 157554] [client 132.196.30.78:19844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ncx.php"] [unique_id "aoSCzE1jzAhYHVVT1WftxwAAATA"] [Tue Aug 18 13:05:32.454187 2026] [security2:error] [pid 157386:tid 157605] [client 20.25.139.174:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/edit.php"] [unique_id "aoSCzE1jzAhYHVVT1WftyAAAAWM"] [Tue Aug 18 13:05:32.468360 2026] [security2:error] [pid 157386:tid 157547] [client 20.104.100.201:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCzE1jzAhYHVVT1WftywAAASk"] [Tue Aug 18 13:05:32.479204 2026] [security2:error] [pid 157386:tid 157636] [client 20.1.169.243:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/login.php"] [unique_id "aoSCzE1jzAhYHVVT1WftzAAAAYI"] [Tue Aug 18 13:05:32.486731 2026] [security2:error] [pid 157386:tid 157549] [client 86.120.159.145:20159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCzE1jzAhYHVVT1WftzQAAASs"] [Tue Aug 18 13:05:32.486988 2026] [security2:error] [pid 157386:tid 157549] [client 86.120.159.145:20159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCzE1jzAhYHVVT1WftzQAAASs"] [Tue Aug 18 13:05:32.489093 2026] [security2:error] [pid 157386:tid 157579] [client 68.155.154.236:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSCzE1jzAhYHVVT1WftzgAAAUk"] [Tue Aug 18 13:05:32.514590 2026] [security2:error] [pid 157386:tid 157558] [client 40.85.222.29:7166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSCzE1jzAhYHVVT1WftzwAAATQ"] [Tue Aug 18 13:05:32.523894 2026] [security2:error] [pid 157386:tid 157574] [client 4.232.151.198:25273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/admin_panel.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft0QAAAUQ"] [Tue Aug 18 13:05:32.543628 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ac.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft0gAAAUY"] [Tue Aug 18 13:05:32.567343 2026] [security2:error] [pid 157386:tid 157569] [client 20.91.215.254:7925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/asd.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft1AAAAT8"] [Tue Aug 18 13:05:32.580119 2026] [security2:error] [pid 157386:tid 157638] [client 20.104.49.167:12780] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/1.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft1gAAAYQ"] [Tue Aug 18 13:05:32.580225 2026] [security2:error] [pid 157386:tid 157638] [client 20.104.49.167:12780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/1.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft1gAAAYQ"] [Tue Aug 18 13:05:32.740890 2026] [security2:error] [pid 157386:tid 157540] [client 20.250.13.23:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft3wAAASI"] [Tue Aug 18 13:05:32.766492 2026] [security2:error] [pid 157386:tid 157539] [client 40.74.65.169:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/file1221.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft4AAAASE"] [Tue Aug 18 13:05:32.790426 2026] [security2:error] [pid 157386:tid 157580] [client 20.171.51.14:58032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/17.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft4gAAAUo"] [Tue Aug 18 13:05:32.814578 2026] [security2:error] [pid 157386:tid 157640] [client 213.35.127.232:55147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft6AAAAYY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:32.829943 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/yz.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft6wAAAXM"] [Tue Aug 18 13:05:32.845084 2026] [security2:error] [pid 157386:tid 157641] [client 40.85.222.29:7106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft7AAAAYc"] [Tue Aug 18 13:05:32.849125 2026] [security2:error] [pid 157386:tid 157627] [client 20.1.169.243:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/plugin-install.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft7QAAAXk"] [Tue Aug 18 13:05:32.884647 2026] [security2:error] [pid 157386:tid 157550] [client 68.155.154.236:14289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft7wAAASw"] [Tue Aug 18 13:05:32.894690 2026] [security2:error] [pid 157386:tid 157619] [client 158.23.17.4:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/88.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft8AAAAXE"] [Tue Aug 18 13:05:32.948091 2026] [security2:error] [pid 157386:tid 157612] [client 20.104.49.167:41789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/coffee.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft8gAAAWo"] [Tue Aug 18 13:05:32.960823 2026] [security2:error] [pid 157386:tid 157600] [client 49.37.150.8:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft8wAAAV4"] [Tue Aug 18 13:05:32.963150 2026] [security2:error] [pid 157386:tid 157600] [client 49.37.150.8:63171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft8wAAAV4"] [Tue Aug 18 13:05:32.966840 2026] [security2:error] [pid 157386:tid 157560] [client 40.74.65.169:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft9AAAATY"] [Tue Aug 18 13:05:32.976804 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/elp.php"] [unique_id "aoSCzE1jzAhYHVVT1Wft9gAAAQ0"] [Tue Aug 18 13:05:32.980009 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:32.980268 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:33.024681 2026] [security2:error] [pid 157386:tid 157632] [client 20.171.51.14:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/st.php"] [unique_id "aoSCzU1jzAhYHVVT1Wft-QAAAX4"] [Tue Aug 18 13:05:33.043114 2026] [security2:error] [pid 157386:tid 157626] [client 20.203.183.135:30374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCzU1jzAhYHVVT1Wft_gAAAXg"] [Tue Aug 18 13:05:33.045108 2026] [security2:error] [pid 157386:tid 157598] [client 20.38.3.247:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/dex.php"] [unique_id "aoSCzU1jzAhYHVVT1Wft_wAAAVw"] [Tue Aug 18 13:05:33.067458 2026] [security2:error] [pid 157386:tid 157592] [client 132.196.30.78:27994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuAwAAAVY"] [Tue Aug 18 13:05:33.112963 2026] [security2:error] [pid 157386:tid 157582] [client 68.221.73.131:61286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/file1221.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuBwAAAUw"] [Tue Aug 18 13:05:33.180015 2026] [security2:error] [pid 157386:tid 157587] [client 40.85.222.29:7119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuCQAAAVE"] [Tue Aug 18 13:05:33.200156 2026] [security2:error] [pid 157386:tid 157551] [client 20.91.215.254:7896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/akc.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuDAAAAS0"] [Tue Aug 18 13:05:33.229635 2026] [security2:error] [pid 157386:tid 157642] [client 4.232.151.198:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/customize/about.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuDwAAAYg"] [Tue Aug 18 13:05:33.231174 2026] [security2:error] [pid 157386:tid 157609] [client 20.1.169.243:15700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/test.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuEAAAAWc"] [Tue Aug 18 13:05:33.243281 2026] [security2:error] [pid 157386:tid 157554] [client 68.155.154.236:14314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuEQAAATA"] [Tue Aug 18 13:05:33.246410 2026] [security2:error] [pid 157386:tid 157643] [client 20.151.109.219:45885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ee.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuEgAAAYk"] [Tue Aug 18 13:05:33.250437 2026] [security2:error] [pid 157386:tid 157605] [client 20.104.49.167:2568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuEwAAAWM"] [Tue Aug 18 13:05:33.279931 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:33.280201 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:33.311786 2026] [security2:error] [pid 157386:tid 157549] [client 52.173.121.69:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuFwAAASs"] [Tue Aug 18 13:05:33.358570 2026] [security2:error] [pid 157386:tid 157593] [client 20.250.13.23:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/import.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuGAAAAVc"] [Tue Aug 18 13:05:33.384147 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:62964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kj.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuGgAAAUY"] [Tue Aug 18 13:05:33.419411 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:19730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/verification.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuHAAAAXQ"] [Tue Aug 18 13:05:33.489131 2026] [security2:error] [pid 157386:tid 157628] [client 68.221.73.131:46538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/pucci.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuIAAAAXo"] [Tue Aug 18 13:05:33.513868 2026] [security2:error] [pid 157386:tid 157603] [client 40.85.222.29:7118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuIQAAAWE"] [Tue Aug 18 13:05:33.520803 2026] [security2:error] [pid 157386:tid 157578] [client 20.25.139.174:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuIgAAAUg"] [Tue Aug 18 13:05:33.575538 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:52883] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cvwebdesigner.com.br"] [uri "/1.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuJgAAAU4"] [Tue Aug 18 13:05:33.575632 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:52883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/1.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuJgAAAU4"] [Tue Aug 18 13:05:33.581067 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:33.581341 2026] [authz_core:error] [pid 157386:tid 157407] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:33.583257 2026] [security2:error] [pid 157386:tid 157540] [client 168.62.48.100:12166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuJwAAASI"] [Tue Aug 18 13:05:33.584374 2026] [security2:error] [pid 157386:tid 157633] [client 20.250.13.23:47444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-content/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuKAAAAX8"] [Tue Aug 18 13:05:33.597607 2026] [security2:error] [pid 157386:tid 157538] [client 20.1.169.243:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuKgAAASA"] [Tue Aug 18 13:05:33.610527 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.49.167:21944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuKwAAAT0"] [Tue Aug 18 13:05:33.623501 2026] [security2:error] [pid 157386:tid 157573] [client 20.203.183.135:38111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/av.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuLAAAAUM"] [Tue Aug 18 13:05:33.638277 2026] [security2:error] [pid 157386:tid 157601] [client 68.155.154.236:14217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuLwAAAV8"] [Tue Aug 18 13:05:33.653035 2026] [security2:error] [pid 157386:tid 157624] [client 40.74.65.169:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/contacto.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuMwAAAXY"] [Tue Aug 18 13:05:33.700267 2026] [security2:error] [pid 157386:tid 157627] [client 20.171.51.14:18635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ev.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuNgAAAXk"] [Tue Aug 18 13:05:33.721158 2026] [security2:error] [pid 157386:tid 157619] [client 40.74.65.169:16266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/nox.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuNwAAAXE"] [Tue Aug 18 13:05:33.785008 2026] [security2:error] [pid 157386:tid 157595] [client 132.196.30.78:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wso.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuOQAAAVk"] [Tue Aug 18 13:05:33.802578 2026] [security2:error] [pid 157386:tid 157612] [client 20.206.73.37:21331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/fz.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuOgAAAWo"] [Tue Aug 18 13:05:33.812269 2026] [security2:error] [pid 157386:tid 157560] [client 40.85.222.29:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuOwAAATY"] [Tue Aug 18 13:05:33.816967 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vg.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuPAAAATo"] [Tue Aug 18 13:05:33.845262 2026] [security2:error] [pid 157386:tid 157544] [client 213.35.127.232:55365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuPwAAASY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:33.909000 2026] [security2:error] [pid 157386:tid 157568] [client 20.51.153.15:8752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/mandrill.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuQQAAAT4"] [Tue Aug 18 13:05:33.915457 2026] [security2:error] [pid 157386:tid 157546] [client 4.232.151.198:7801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuQgAAASg"] [Tue Aug 18 13:05:33.934403 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.49.167:41787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/yj09.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuRAAAAQw"] [Tue Aug 18 13:05:33.940261 2026] [security2:error] [pid 157386:tid 157592] [client 158.23.17.4:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/hj.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuRQAAAVY"] [Tue Aug 18 13:05:33.944270 2026] [security2:error] [pid 157386:tid 157580] [client 20.91.215.254:7931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/maintenance.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuRgAAAUo"] [Tue Aug 18 13:05:33.966998 2026] [security2:error] [pid 157386:tid 157555] [client 20.1.169.243:15734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/themes/index.php"] [unique_id "aoSCzU1jzAhYHVVT1WfuSAAAATE"] [Tue Aug 18 13:05:34.037393 2026] [security2:error] [pid 157386:tid 157607] [client 20.25.139.174:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/666.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuSwAAAWU"] [Tue Aug 18 13:05:34.040197 2026] [security2:error] [pid 157386:tid 157519] [client 20.250.13.23:35564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/cropper.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuTAAAAQ0"] [Tue Aug 18 13:05:34.133896 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:63287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sm.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuTgAAATA"] [Tue Aug 18 13:05:34.136763 2026] [security2:error] [pid 157386:tid 157605] [client 40.85.222.29:6647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuTwAAAWM"] [Tue Aug 18 13:05:34.147542 2026] [security2:error] [pid 157386:tid 157629] [client 20.79.222.117:18003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuUAAAAXs"] [Tue Aug 18 13:05:34.172855 2026] [security2:error] [pid 157386:tid 157597] [client 20.171.51.14:47163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xs.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuUQAAAVs"] [Tue Aug 18 13:05:34.180764 2026] [security2:error] [pid 157386:tid 157579] [client 20.203.183.135:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/images.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuVQAAAUk"] [Tue Aug 18 13:05:34.182917 2026] [authz_core:error] [pid 157386:tid 157457] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:34.183229 2026] [authz_core:error] [pid 157386:tid 157457] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:34.209412 2026] [security2:error] [pid 157386:tid 157593] [client 68.155.154.236:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuWAAAAVc"] [Tue Aug 18 13:05:34.257153 2026] [security2:error] [pid 157386:tid 157634] [client 20.104.49.167:2642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/scxy.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuWgAAAYA"] [Tue Aug 18 13:05:34.280632 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ak.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuWwAAAWk"] [Tue Aug 18 13:05:34.337307 2026] [security2:error] [pid 157386:tid 157603] [client 40.74.65.169:60185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/image2.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuXQAAAWE"] [Tue Aug 18 13:05:34.359580 2026] [security2:error] [pid 157386:tid 157584] [client 52.173.121.69:29828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuYQAAAU4"] [Tue Aug 18 13:05:34.405457 2026] [security2:error] [pid 157386:tid 157565] [client 20.250.13.23:28258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/vx.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuZAAAATs"] [Tue Aug 18 13:05:34.431376 2026] [security2:error] [pid 157386:tid 157588] [client 40.85.222.29:6631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/well-known/index.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuZQAAAVI"] [Tue Aug 18 13:05:34.454372 2026] [security2:error] [pid 157386:tid 157589] [client 20.151.109.219:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/28.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuZgAAAVM"] [Tue Aug 18 13:05:34.468686 2026] [security2:error] [pid 157386:tid 157621] [client 20.1.169.243:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/alfa-rex.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuZwAAAXM"] [Tue Aug 18 13:05:34.483863 2026] [authz_core:error] [pid 157386:tid 157455] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:34.484129 2026] [authz_core:error] [pid 157386:tid 157455] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:34.547108 2026] [security2:error] [pid 157386:tid 157562] [client 132.196.30.78:20236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/zup.php73"] [unique_id "aoSCzk1jzAhYHVVT1WfuawAAATg"] [Tue Aug 18 13:05:34.556567 2026] [security2:error] [pid 157386:tid 157627] [client 20.79.222.117:18012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCzk1jzAhYHVVT1WfubQAAAXk"] [Tue Aug 18 13:05:34.569872 2026] [security2:error] [pid 157386:tid 157527] [client 40.74.65.169:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/akismet.php"] [unique_id "aoSCzk1jzAhYHVVT1WfubwAAARU"] [Tue Aug 18 13:05:34.577166 2026] [security2:error] [pid 157386:tid 157542] [client 20.91.215.254:16600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/options-writing.php"] [unique_id "aoSCzk1jzAhYHVVT1WfucAAAASQ"] [Tue Aug 18 13:05:34.655577 2026] [security2:error] [pid 157386:tid 157526] [client 4.232.151.198:25272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/add-venue-ru.php"] [unique_id "aoSCzk1jzAhYHVVT1WfudQAAARQ"] [Tue Aug 18 13:05:34.658047 2026] [security2:error] [pid 157386:tid 157601] [client 20.250.13.23:44067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSCzk1jzAhYHVVT1WfudgAAAV8"] [Tue Aug 18 13:05:34.684815 2026] [security2:error] [pid 157386:tid 157560] [client 68.155.154.236:14300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSCzk1jzAhYHVVT1WfueAAAATY"] [Tue Aug 18 13:05:34.733395 2026] [security2:error] [pid 157386:tid 157537] [client 20.104.49.167:48564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSCzk1jzAhYHVVT1WfueQAAAR8"] [Tue Aug 18 13:05:34.739004 2026] [security2:error] [pid 157386:tid 157521] [client 168.62.48.100:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuegAAAQ8"] [Tue Aug 18 13:05:34.740870 2026] [security2:error] [pid 157386:tid 157568] [client 20.25.139.174:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ws54.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuewAAAT4"] [Tue Aug 18 13:05:34.768441 2026] [security2:error] [pid 157386:tid 157594] [client 40.85.222.29:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSCzk1jzAhYHVVT1WfufgAAAVg"] [Tue Aug 18 13:05:34.786263 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:34.786707 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:34.794671 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/m.php"] [unique_id "aoSCzk1jzAhYHVVT1WfugQAAAUo"] [Tue Aug 18 13:05:34.799519 2026] [security2:error] [pid 157386:tid 157618] [client 20.171.51.14:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/lmfi2.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuggAAAXA"] [Tue Aug 18 13:05:34.859438 2026] [security2:error] [pid 157386:tid 157586] [client 213.35.127.232:55559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuhgAAAVA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:34.917269 2026] [security2:error] [pid 157386:tid 157587] [client 20.203.183.135:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/ops.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuiAAAAVE"] [Tue Aug 18 13:05:34.959562 2026] [security2:error] [pid 157386:tid 157520] [client 20.79.222.117:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSCzk1jzAhYHVVT1WfuigAAAQ4"] [Tue Aug 18 13:05:34.966926 2026] [security2:error] [pid 157386:tid 157643] [client 20.1.169.243:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "aoSCzk1jzAhYHVVT1WfujAAAAYk"] [Tue Aug 18 13:05:34.984204 2026] [security2:error] [pid 157386:tid 157554] [client 20.206.73.37:46947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSCzk1jzAhYHVVT1WfujQAAATA"] [Tue Aug 18 13:05:34.999589 2026] [security2:error] [pid 157386:tid 157547] [client 20.206.73.37:15882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/blurbs.php"] [unique_id "aoSCzk1jzAhYHVVT1WfujwAAASk"] [Tue Aug 18 13:05:35.013700 2026] [security2:error] [pid 157386:tid 157558] [client 40.74.65.169:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/fb.php"] [unique_id "aoSCz01jzAhYHVVT1WfukAAAATQ"] [Tue Aug 18 13:05:35.088177 2026] [authz_core:error] [pid 157386:tid 157486] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:35.088485 2026] [authz_core:error] [pid 157386:tid 157486] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:35.127243 2026] [security2:error] [pid 157386:tid 157626] [client 20.104.49.167:12762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSCz01jzAhYHVVT1WfulQAAAXg"] [Tue Aug 18 13:05:35.148608 2026] [security2:error] [pid 157386:tid 157576] [client 40.85.222.29:7126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSCz01jzAhYHVVT1WfulwAAAUY"] [Tue Aug 18 13:05:35.158285 2026] [security2:error] [pid 157386:tid 157605] [client 132.196.30.78:27974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/k.php"] [unique_id "aoSCz01jzAhYHVVT1WfumAAAAWM"] [Tue Aug 18 13:05:35.163918 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:5367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nl.php"] [unique_id "aoSCz01jzAhYHVVT1WfumQAAAU4"] [Tue Aug 18 13:05:35.183313 2026] [security2:error] [pid 157386:tid 157538] [client 68.155.154.236:14284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSCz01jzAhYHVVT1WfumgAAASA"] [Tue Aug 18 13:05:35.223928 2026] [security2:error] [pid 157386:tid 157588] [client 20.118.133.132:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/ano.php"] [unique_id "aoSCz01jzAhYHVVT1WfunQAAAVI"] [Tue Aug 18 13:05:35.268353 2026] [security2:error] [pid 157386:tid 157541] [client 20.25.139.174:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSCz01jzAhYHVVT1WfunwAAASM"] [Tue Aug 18 13:05:35.272468 2026] [security2:error] [pid 157386:tid 157593] [client 20.250.13.23:35521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSCz01jzAhYHVVT1WfuoQAAAVc"] [Tue Aug 18 13:05:35.295195 2026] [security2:error] [pid 157386:tid 157634] [client 4.232.151.198:25267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/rishi/db.php"] [unique_id "aoSCz01jzAhYHVVT1WfupAAAAYA"] [Tue Aug 18 13:05:35.302331 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/smtp.php"] [unique_id "aoSCz01jzAhYHVVT1WfupQAAARU"] [Tue Aug 18 13:05:35.329052 2026] [security2:error] [pid 157386:tid 157545] [client 52.173.121.69:56020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/first.php"] [unique_id "aoSCz01jzAhYHVVT1WfupgAAASc"] [Tue Aug 18 13:05:35.340004 2026] [security2:error] [pid 157386:tid 157565] [client 20.1.169.243:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/wp-pridmag/layout.php"] [unique_id "aoSCz01jzAhYHVVT1WfupwAAATs"] [Tue Aug 18 13:05:35.362195 2026] [authz_core:error] [pid 157386:tid 157624] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:35.362472 2026] [authz_core:error] [pid 157386:tid 157624] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:35.364750 2026] [security2:error] [pid 157386:tid 157597] [client 20.91.215.254:7924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSCz01jzAhYHVVT1WfuqQAAAVs"] [Tue Aug 18 13:05:35.371992 2026] [security2:error] [pid 157386:tid 157601] [client 20.171.51.14:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fd.php"] [unique_id "aoSCz01jzAhYHVVT1WfuqwAAAV8"] [Tue Aug 18 13:05:35.391176 2026] [security2:error] [pid 157386:tid 157612] [client 158.23.17.4:56549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ij.php"] [unique_id "aoSCz01jzAhYHVVT1WfurgAAAWo"] [Tue Aug 18 13:05:35.393481 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:35.393931 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:35.404184 2026] [security2:error] [pid 157386:tid 157600] [client 20.79.222.117:18013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/av.php"] [unique_id "aoSCz01jzAhYHVVT1WfurwAAAV4"] [Tue Aug 18 13:05:35.411074 2026] [security2:error] [pid 157386:tid 157556] [client 4.223.113.180:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/configs.php"] [unique_id "aoSCz01jzAhYHVVT1WfusAAAATI"] [Tue Aug 18 13:05:35.445409 2026] [security2:error] [pid 157386:tid 157537] [client 20.203.183.135:38094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/coffexium.php"] [unique_id "aoSCz01jzAhYHVVT1WfusgAAAR8"] [Tue Aug 18 13:05:35.456118 2026] [security2:error] [pid 157386:tid 157642] [client 216.244.66.243:49786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/gay+telegran-0/"] [unique_id "aoSCz01jzAhYHVVT1WfuswAAAYg"] [Tue Aug 18 13:05:35.456223 2026] [security2:error] [pid 157386:tid 157642] [client 216.244.66.243:49786] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/gay+telegran-0/"] [unique_id "aoSCz01jzAhYHVVT1WfuswAAAYg"] [Tue Aug 18 13:05:35.487383 2026] [security2:error] [pid 157386:tid 157530] [client 40.85.222.29:7107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSCz01jzAhYHVVT1WfutQAAARg"] [Tue Aug 18 13:05:35.509894 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/68.php"] [unique_id "aoSCz01jzAhYHVVT1WfutgAAAXA"] [Tue Aug 18 13:05:35.512224 2026] [security2:error] [pid 157386:tid 157616] [client 20.116.17.175:45292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSCz01jzAhYHVVT1WfutwAAAW4"] [Tue Aug 18 13:05:35.540289 2026] [security2:error] [pid 157386:tid 157582] [client 68.155.154.236:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSCz01jzAhYHVVT1WfuugAAAUw"] [Tue Aug 18 13:05:35.552001 2026] [security2:error] [pid 157386:tid 157543] [client 149.34.210.141:58151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCz01jzAhYHVVT1WfuuwAAASU"] [Tue Aug 18 13:05:35.558636 2026] [security2:error] [pid 157386:tid 157566] [client 20.206.73.37:17067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/bajah.php"] [unique_id "aoSCz01jzAhYHVVT1WfuvAAAATw"] [Tue Aug 18 13:05:35.586220 2026] [security2:error] [pid 157386:tid 157617] [client 40.74.65.169:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/admin.php"] [unique_id "aoSCz01jzAhYHVVT1WfuvQAAAW8"] [Tue Aug 18 13:05:35.597865 2026] [security2:error] [pid 157386:tid 157632] [client 20.250.13.23:7524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wap.php"] [unique_id "aoSCz01jzAhYHVVT1WfuvgAAAX4"] [Tue Aug 18 13:05:35.632590 2026] [security2:error] [pid 157386:tid 157551] [client 20.104.100.201:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/makeasmtp.php"] [unique_id "aoSCz01jzAhYHVVT1WfuwQAAAS0"] [Tue Aug 18 13:05:35.671913 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:27375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/test_info.php"] [unique_id "aoSCz01jzAhYHVVT1WfuwwAAATA"] [Tue Aug 18 13:05:35.690673 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:35.690938 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:35.709059 2026] [security2:error] [pid 157386:tid 157517] [client 40.74.65.169:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/gi.php"] [unique_id "aoSCz01jzAhYHVVT1WfuxQAAAQs"] [Tue Aug 18 13:05:35.720984 2026] [security2:error] [pid 157386:tid 157608] [client 20.1.169.243:15564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "aoSCz01jzAhYHVVT1WfuxgAAAWY"] [Tue Aug 18 13:05:35.731823 2026] [security2:error] [pid 157386:tid 157619] [client 68.221.73.131:17431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-temp.php"] [unique_id "aoSCz01jzAhYHVVT1WfuxwAAAXE"] [Tue Aug 18 13:05:35.796491 2026] [security2:error] [pid 157386:tid 157603] [client 40.85.222.29:7148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/mt/byp.php"] [unique_id "aoSCz01jzAhYHVVT1WfuygAAAWE"] [Tue Aug 18 13:05:35.817926 2026] [security2:error] [pid 157386:tid 157585] [client 20.79.222.117:18025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/images.php"] [unique_id "aoSCz01jzAhYHVVT1WfuywAAAU8"] [Tue Aug 18 13:05:35.818120 2026] [security2:error] [pid 157386:tid 157543] [client 149.34.210.141:58151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSCz01jzAhYHVVT1WfuuwAAASU"] [Tue Aug 18 13:05:35.831917 2026] [security2:error] [pid 157386:tid 157525] [client 132.196.30.78:19877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-blink.php"] [unique_id "aoSCz01jzAhYHVVT1WfuzAAAARM"] [Tue Aug 18 13:05:35.844376 2026] [security2:error] [pid 157386:tid 157579] [client 20.25.139.174:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/function/function.php"] [unique_id "aoSCz01jzAhYHVVT1WfuzQAAAUk"] [Tue Aug 18 13:05:35.845366 2026] [security2:error] [pid 157386:tid 157538] [client 20.116.17.175:22636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSCz01jzAhYHVVT1WfuzgAAASA"] [Tue Aug 18 13:05:35.857620 2026] [security2:error] [pid 157386:tid 157567] [client 20.171.51.14:38754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/info2.php"] [unique_id "aoSCz01jzAhYHVVT1WfuzwAAAT0"] [Tue Aug 18 13:05:35.885969 2026] [security2:error] [pid 157386:tid 157533] [client 213.35.127.232:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSCz01jzAhYHVVT1Wfu0QAAARs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:35.895614 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:46448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/jl.php"] [unique_id "aoSCz01jzAhYHVVT1Wfu0gAAAXM"] [Tue Aug 18 13:05:35.907784 2026] [security2:error] [pid 157386:tid 157558] [client 20.250.13.23:44065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/goat.php"] [unique_id "aoSCz01jzAhYHVVT1Wfu1AAAATQ"] [Tue Aug 18 13:05:35.933534 2026] [security2:error] [pid 157386:tid 157562] [client 68.155.154.236:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSCz01jzAhYHVVT1Wfu1gAAATg"] [Tue Aug 18 13:05:35.959011 2026] [security2:error] [pid 157386:tid 157638] [client 4.232.151.198:24205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "aoSCz01jzAhYHVVT1Wfu1wAAAYQ"] [Tue Aug 18 13:05:35.991383 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:35.991664 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:36.009354 2026] [security2:error] [pid 157386:tid 157532] [client 68.221.73.131:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/nox.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu2QAAARo"] [Tue Aug 18 13:05:36.080654 2026] [security2:error] [pid 157386:tid 157561] [client 40.85.222.29:17556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu2gAAATc"] [Tue Aug 18 13:05:36.096918 2026] [security2:error] [pid 157386:tid 157581] [client 20.91.215.254:7922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/maint.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu2wAAAUs"] [Tue Aug 18 13:05:36.102138 2026] [security2:error] [pid 157386:tid 157590] [client 20.203.183.135:30372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu3AAAAVQ"] [Tue Aug 18 13:05:36.106484 2026] [security2:error] [pid 157386:tid 157630] [client 20.1.169.243:15734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/updraft/plugins-old/updraftplus/templates/wp-admin/data.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu3QAAAXw"] [Tue Aug 18 13:05:36.190870 2026] [security2:error] [pid 157386:tid 157564] [client 20.116.17.175:22616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu3gAAATo"] [Tue Aug 18 13:05:36.232146 2026] [security2:error] [pid 157386:tid 157537] [client 20.79.222.117:17986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/ops.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu3wAAAR8"] [Tue Aug 18 13:05:36.291614 2026] [security2:error] [pid 157386:tid 157568] [client 20.206.73.37:24424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/clque.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu4QAAAT4"] [Tue Aug 18 13:05:36.293688 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:36.293961 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:36.325057 2026] [security2:error] [pid 157386:tid 157615] [client 52.173.121.69:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu4gAAAW0"] [Tue Aug 18 13:05:36.337651 2026] [security2:error] [pid 157386:tid 157618] [client 20.171.51.14:13437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sx.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu5AAAAXA"] [Tue Aug 18 13:05:36.342900 2026] [authz_core:error] [pid 157386:tid 157616] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:36.343149 2026] [authz_core:error] [pid 157386:tid 157616] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:36.349677 2026] [security2:error] [pid 157386:tid 157560] [client 20.25.139.174:4500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/nw.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu5QAAATY"] [Tue Aug 18 13:05:36.385513 2026] [security2:error] [pid 157386:tid 157599] [client 40.85.222.29:6493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu5gAAAV0"] [Tue Aug 18 13:05:36.397677 2026] [security2:error] [pid 157386:tid 157566] [client 40.74.65.169:41430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/video.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu5wAAATw"] [Tue Aug 18 13:05:36.398254 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:65078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/tq.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu6AAAAUE"] [Tue Aug 18 13:05:36.410234 2026] [security2:error] [pid 157386:tid 157617] [client 20.104.49.167:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/blurbs.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu6QAAAW8"] [Tue Aug 18 13:05:36.503997 2026] [security2:error] [pid 157386:tid 157551] [client 20.171.51.14:23236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/le.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu7gAAAS0"] [Tue Aug 18 13:05:36.540963 2026] [security2:error] [pid 157386:tid 157623] [client 68.155.154.236:14262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu7wAAAXU"] [Tue Aug 18 13:05:36.553592 2026] [security2:error] [pid 157386:tid 157614] [client 20.250.13.23:35575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/Session.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu8AAAAWw"] [Tue Aug 18 13:05:36.572619 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:22640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/cok.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu8QAAAWE"] [Tue Aug 18 13:05:36.591993 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:36.592259 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:36.599267 2026] [security2:error] [pid 157386:tid 157543] [client 20.1.169.243:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu9gAAASU"] [Tue Aug 18 13:05:36.604957 2026] [security2:error] [pid 157386:tid 157640] [client 4.232.151.198:7749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-includes/customize/autoload_classmap.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu9wAAAYY"] [Tue Aug 18 13:05:36.654133 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/teste.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu-QAAARM"] [Tue Aug 18 13:05:36.671246 2026] [security2:error] [pid 157386:tid 157588] [client 157.20.138.62:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu-gAAAVI"] [Tue Aug 18 13:05:36.671377 2026] [security2:error] [pid 157386:tid 157588] [client 157.20.138.62:62552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu-gAAAVI"] [Tue Aug 18 13:05:36.677240 2026] [security2:error] [pid 157386:tid 157557] [client 20.79.222.117:18037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/coffexium.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu-wAAATM"] [Tue Aug 18 13:05:36.709100 2026] [security2:error] [pid 157386:tid 157549] [client 20.171.51.14:9942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nu.php"] [unique_id "aoSC0E1jzAhYHVVT1Wfu_wAAASs"] [Tue Aug 18 13:05:36.710013 2026] [security2:error] [pid 157386:tid 157624] [client 40.85.222.29:7109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvAAAAAXY"] [Tue Aug 18 13:05:36.779828 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:58697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/14.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvAwAAAXg"] [Tue Aug 18 13:05:36.792379 2026] [security2:error] [pid 157386:tid 157620] [client 20.91.215.254:7902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/phpMailer.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvBAAAAXI"] [Tue Aug 18 13:05:36.810943 2026] [security2:error] [pid 157386:tid 157541] [client 20.203.183.135:34583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/sf.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvBQAAASM"] [Tue Aug 18 13:05:36.815264 2026] [security2:error] [pid 157386:tid 157593] [client 68.221.73.131:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/akismet.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvBgAAAVc"] [Tue Aug 18 13:05:36.836369 2026] [security2:error] [pid 157386:tid 157586] [client 20.250.13.23:48851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-admin/wp.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvBwAAAVA"] [Tue Aug 18 13:05:36.838739 2026] [security2:error] [pid 157386:tid 157540] [client 20.25.139.174:4305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/xleet.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvCAAAASI"] [Tue Aug 18 13:05:36.855630 2026] [security2:error] [pid 157386:tid 157638] [client 20.116.17.175:45279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/accesson.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvCQAAAYQ"] [Tue Aug 18 13:05:36.884230 2026] [security2:error] [pid 157386:tid 157565] [client 68.155.154.236:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvCwAAATs"] [Tue Aug 18 13:05:36.893628 2026] [authz_core:error] [pid 157386:tid 157405] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:36.893907 2026] [authz_core:error] [pid 157386:tid 157405] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:36.901177 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/cv.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvDQAAAR0"] [Tue Aug 18 13:05:36.910647 2026] [security2:error] [pid 157386:tid 157611] [client 213.35.127.232:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvDgAAAWk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:36.918517 2026] [security2:error] [pid 157386:tid 157534] [client 168.62.48.100:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvEAAAARw"] [Tue Aug 18 13:05:36.951418 2026] [security2:error] [pid 157386:tid 157597] [client 20.250.13.23:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/ws54.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvEgAAAVs"] [Tue Aug 18 13:05:36.989011 2026] [security2:error] [pid 157386:tid 157610] [client 68.221.73.131:30992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSC0E1jzAhYHVVT1WfvEwAAAWg"] [Tue Aug 18 13:05:37.031449 2026] [security2:error] [pid 157386:tid 157527] [client 20.1.169.243:15727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvFAAAARU"] [Tue Aug 18 13:05:37.041842 2026] [security2:error] [pid 157386:tid 157564] [client 40.85.222.29:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvFQAAATo"] [Tue Aug 18 13:05:37.064834 2026] [security2:error] [pid 157386:tid 157628] [client 40.74.65.169:16310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.h6.com.br"] [uri "/ajax.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvFwAAAXo"] [Tue Aug 18 13:05:37.086554 2026] [security2:error] [pid 157386:tid 157642] [client 20.79.222.117:18041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvGAAAAYg"] [Tue Aug 18 13:05:37.091541 2026] [security2:error] [pid 157386:tid 157568] [client 40.74.65.169:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/hel.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvGQAAAT4"] [Tue Aug 18 13:05:37.102494 2026] [security2:error] [pid 157386:tid 157531] [client 178.153.171.161:41511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvGwAAARk"] [Tue Aug 18 13:05:37.102597 2026] [security2:error] [pid 157386:tid 157531] [client 178.153.171.161:41511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvGwAAARk"] [Tue Aug 18 13:05:37.135674 2026] [security2:error] [pid 157386:tid 157530] [client 20.171.51.14:7895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ko.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvHQAAARg"] [Tue Aug 18 13:05:37.168754 2026] [security2:error] [pid 157386:tid 157560] [client 20.116.17.175:45253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/av.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvHgAAATY"] [Tue Aug 18 13:05:37.184453 2026] [security2:error] [pid 157386:tid 157601] [client 20.250.13.23:35533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvHwAAAV8"] [Tue Aug 18 13:05:37.214272 2026] [security2:error] [pid 157386:tid 157617] [client 132.196.30.78:20228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/ww5.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvIgAAAW8"] [Tue Aug 18 13:05:37.242439 2026] [security2:error] [pid 157386:tid 157575] [client 20.104.49.167:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/bajah.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvJQAAAUU"] [Tue Aug 18 13:05:37.300737 2026] [security2:error] [pid 157386:tid 157544] [client 4.232.151.198:25254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/text/autoload_classmap.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvJwAAASY"] [Tue Aug 18 13:05:37.304740 2026] [security2:error] [pid 157386:tid 157518] [client 68.155.154.236:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvKAAAAQw"] [Tue Aug 18 13:05:37.314308 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.100.201:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/cok.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvKQAAAUI"] [Tue Aug 18 13:05:37.342204 2026] [security2:error] [pid 157386:tid 157574] [client 20.151.109.219:46430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/un.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvKwAAAUQ"] [Tue Aug 18 13:05:37.342732 2026] [security2:error] [pid 157386:tid 157599] [client 20.25.139.174:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvLAAAAV0"] [Tue Aug 18 13:05:37.379097 2026] [security2:error] [pid 157386:tid 157583] [client 40.85.222.29:6597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvLQAAAU0"] [Tue Aug 18 13:05:37.399022 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/api.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvLgAAARA"] [Tue Aug 18 13:05:37.495620 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:37.497237 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:37.499955 2026] [security2:error] [pid 157386:tid 157624] [client 20.116.17.175:22560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/kj.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvNAAAAXY"] [Tue Aug 18 13:05:37.503426 2026] [security2:error] [pid 157386:tid 157573] [client 20.79.222.117:17960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/sf.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvNQAAAUM"] [Tue Aug 18 13:05:37.514917 2026] [security2:error] [pid 157386:tid 157622] [client 20.51.153.15:8418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/main.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvNgAAAXQ"] [Tue Aug 18 13:05:37.523517 2026] [security2:error] [pid 157386:tid 157626] [client 20.203.183.135:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/k.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvNwAAAXg"] [Tue Aug 18 13:05:37.561894 2026] [security2:error] [pid 157386:tid 157591] [client 20.91.215.254:15138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvOAAAAVU"] [Tue Aug 18 13:05:37.690343 2026] [security2:error] [pid 157386:tid 157611] [client 40.85.222.29:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvPQAAAWk"] [Tue Aug 18 13:05:37.698734 2026] [security2:error] [pid 157386:tid 157620] [client 138.36.100.162:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvPgAAAXI"] [Tue Aug 18 13:05:37.698839 2026] [security2:error] [pid 157386:tid 157620] [client 138.36.100.162:42780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvPgAAAXI"] [Tue Aug 18 13:05:37.724983 2026] [security2:error] [pid 157386:tid 157625] [client 20.171.51.14:6624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/pl.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvQQAAAXc"] [Tue Aug 18 13:05:37.729862 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.49.167:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/domvf.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvQgAAAVs"] [Tue Aug 18 13:05:37.739328 2026] [security2:error] [pid 157386:tid 157610] [client 20.151.109.219:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/evil.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvQwAAAWg"] [Tue Aug 18 13:05:37.769295 2026] [security2:error] [pid 157386:tid 157545] [client 20.1.169.243:15707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/core.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvRQAAASc"] [Tue Aug 18 13:05:37.774843 2026] [security2:error] [pid 157386:tid 157630] [client 40.74.65.169:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/grok.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvRgAAAXw"] [Tue Aug 18 13:05:37.796464 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:37.796716 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:37.814104 2026] [security2:error] [pid 157386:tid 157609] [client 20.250.13.23:44055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/abcd.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvSQAAAWc"] [Tue Aug 18 13:05:37.835564 2026] [security2:error] [pid 157386:tid 157535] [client 132.196.30.78:19862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/2.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvSgAAAR0"] [Tue Aug 18 13:05:37.861325 2026] [security2:error] [pid 157386:tid 157600] [client 20.116.17.175:22565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvSwAAAV4"] [Tue Aug 18 13:05:37.864967 2026] [security2:error] [pid 157386:tid 157556] [client 68.155.154.236:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvTAAAATI"] [Tue Aug 18 13:05:37.910388 2026] [security2:error] [pid 157386:tid 157550] [client 20.79.222.117:17924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/k.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvTQAAASw"] [Tue Aug 18 13:05:37.919636 2026] [security2:error] [pid 157386:tid 157561] [client 20.25.139.174:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/155.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvTgAAATc"] [Tue Aug 18 13:05:37.925028 2026] [security2:error] [pid 157386:tid 157593] [client 213.35.127.232:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvTwAAAVc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:37.997791 2026] [security2:error] [pid 157386:tid 157568] [client 40.85.222.29:7159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvUQAAAT4"] [Tue Aug 18 13:05:38.023943 2026] [security2:error] [pid 157386:tid 157618] [client 52.173.121.69:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvUgAAAXA"] [Tue Aug 18 13:05:38.059363 2026] [security2:error] [pid 157386:tid 157527] [client 4.232.151.198:25261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/form.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvVAAAARU"] [Tue Aug 18 13:05:38.127445 2026] [security2:error] [pid 157386:tid 157612] [client 20.250.13.23:21735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvWAAAAWo"] [Tue Aug 18 13:05:38.138612 2026] [security2:error] [pid 157386:tid 157594] [client 20.1.169.243:15708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/data.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvWgAAAVg"] [Tue Aug 18 13:05:38.139636 2026] [security2:error] [pid 157386:tid 157607] [client 20.203.183.135:30347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/82.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvWwAAAWU"] [Tue Aug 18 13:05:38.140024 2026] [security2:error] [pid 157386:tid 157575] [client 20.104.49.167:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/fpwch.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvXAAAAUU"] [Tue Aug 18 13:05:38.153952 2026] [security2:error] [pid 157386:tid 157613] [client 20.116.17.175:22573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/png.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvXgAAAWs"] [Tue Aug 18 13:05:38.183691 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvYAAAAQw"] [Tue Aug 18 13:05:38.209975 2026] [security2:error] [pid 157386:tid 157642] [client 20.91.215.254:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/al.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvYgAAAYg"] [Tue Aug 18 13:05:38.218764 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.100.201:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvYwAAAUI"] [Tue Aug 18 13:05:38.248850 2026] [security2:error] [pid 157386:tid 157599] [client 68.221.73.131:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/admin.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvZAAAAV0"] [Tue Aug 18 13:05:38.275294 2026] [security2:error] [pid 157386:tid 157623] [client 168.62.48.100:4207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvZQAAAXU"] [Tue Aug 18 13:05:38.278658 2026] [security2:error] [pid 157386:tid 157543] [client 213.202.253.4:56807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/postnews.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvZgAAASU"], referer: www.google.com [Tue Aug 18 13:05:38.307900 2026] [security2:error] [pid 157386:tid 157641] [client 68.155.154.236:14271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvZwAAAYc"] [Tue Aug 18 13:05:38.323678 2026] [security2:error] [pid 157386:tid 157640] [client 20.171.51.14:7933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/env.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvaAAAAYY"] [Tue Aug 18 13:05:38.325672 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/puc.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvaQAAARM"] [Tue Aug 18 13:05:38.330173 2026] [security2:error] [pid 157386:tid 157524] [client 20.79.222.117:18029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/82.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvagAAARI"] [Tue Aug 18 13:05:38.335066 2026] [security2:error] [pid 157386:tid 157538] [client 20.51.153.15:8830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/ga.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvawAAASA"] [Tue Aug 18 13:05:38.338509 2026] [security2:error] [pid 157386:tid 157578] [client 40.85.222.29:6505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/first.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvbAAAAUg"] [Tue Aug 18 13:05:38.359209 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.100.201:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/accesson.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvbgAAAQ8"] [Tue Aug 18 13:05:38.359238 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pw.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvbQAAAUM"] [Tue Aug 18 13:05:38.400065 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:38.400327 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:38.429615 2026] [security2:error] [pid 157386:tid 157546] [client 20.250.13.23:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/bgymj.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvcAAAASg"] [Tue Aug 18 13:05:38.444891 2026] [security2:error] [pid 157386:tid 157554] [client 20.250.13.23:44095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/kj.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvcQAAATA"] [Tue Aug 18 13:05:38.469200 2026] [security2:error] [pid 157386:tid 157540] [client 20.116.17.175:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ab.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvcwAAASI"] [Tue Aug 18 13:05:38.470840 2026] [security2:error] [pid 157386:tid 157638] [client 40.74.65.169:41469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/indes.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvdAAAAYQ"] [Tue Aug 18 13:05:38.483024 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvdQAAAWk"] [Tue Aug 18 13:05:38.505161 2026] [security2:error] [pid 157386:tid 157583] [client 20.25.139.174:4609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/96i.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvdwAAAU0"] [Tue Aug 18 13:05:38.506591 2026] [autoindex:error] [pid 157386:tid 157512] [remote 4.232.151.198:0] AH01276: Cannot serve directory /home1/w32lie55icas3ua4/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:38.506934 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:27328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/local.php"] [unique_id "aoSC0k1jzAhYHVVT1WfveAAAAVk"] [Tue Aug 18 13:05:38.562426 2026] [security2:error] [pid 157386:tid 157591] [client 20.1.169.243:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/db-status.php"] [unique_id "aoSC0k1jzAhYHVVT1WfveQAAAVU"] [Tue Aug 18 13:05:38.584818 2026] [security2:error] [pid 157386:tid 157630] [client 20.51.153.15:9215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/wb.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvegAAAXw"] [Tue Aug 18 13:05:38.647541 2026] [security2:error] [pid 157386:tid 157552] [client 40.85.222.29:7141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvfQAAAS4"] [Tue Aug 18 13:05:38.649415 2026] [security2:error] [pid 157386:tid 157533] [client 20.104.49.167:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/adminner.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvfgAAARs"] [Tue Aug 18 13:05:38.656629 2026] [security2:error] [pid 157386:tid 157632] [client 5.161.61.238:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSC0U1jzAhYHVVT1WfvIwABfkc"], referer: https://tecpolorefrigeracaosp.com.br/ [Tue Aug 18 13:05:38.657125 2026] [security2:error] [pid 157386:tid 157589] [client 20.151.109.219:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/tk.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvfwAAAVM"] [Tue Aug 18 13:05:38.691624 2026] [security2:error] [pid 157386:tid 157565] [client 4.232.151.198:42971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/class-wp-font-face-resolver.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvgAAAATs"] [Tue Aug 18 13:05:38.705335 2026] [authz_core:error] [pid 157386:tid 157471] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:38.705740 2026] [authz_core:error] [pid 157386:tid 157471] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:38.734354 2026] [security2:error] [pid 157386:tid 157639] [client 132.196.30.78:20244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvgwAAAYU"] [Tue Aug 18 13:05:38.765306 2026] [security2:error] [pid 157386:tid 157532] [client 74.248.130.103:54895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/site.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvhQAAARo"] [Tue Aug 18 13:05:38.769212 2026] [security2:error] [pid 157386:tid 157527] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/admin.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvhgAAARU"] [Tue Aug 18 13:05:38.773121 2026] [security2:error] [pid 157386:tid 157547] [client 20.79.222.117:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/dex.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvhwAAASk"] [Tue Aug 18 13:05:38.797665 2026] [security2:error] [pid 157386:tid 157571] [client 68.155.154.236:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvjQAAAUE"] [Tue Aug 18 13:05:38.847709 2026] [security2:error] [pid 157386:tid 157594] [client 20.51.153.15:8820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/xn.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvjgAAAVg"] [Tue Aug 18 13:05:38.849410 2026] [security2:error] [pid 157386:tid 157607] [client 20.151.109.219:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fn.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvjwAAAWU"] [Tue Aug 18 13:05:38.880784 2026] [security2:error] [pid 157386:tid 157613] [client 20.171.51.14:44925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mz.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvkQAAAWs"] [Tue Aug 18 13:05:38.928282 2026] [security2:error] [pid 157386:tid 157559] [client 20.1.169.243:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvkwAAATU"] [Tue Aug 18 13:05:38.945275 2026] [security2:error] [pid 157386:tid 157609] [client 213.35.127.232:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvlAAAAWc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:38.957448 2026] [security2:error] [pid 157386:tid 157577] [client 20.250.13.23:25589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/function/function.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvlgAAAUc"] [Tue Aug 18 13:05:38.959069 2026] [security2:error] [pid 157386:tid 157530] [client 20.91.215.254:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvlwAAARg"] [Tue Aug 18 13:05:38.959866 2026] [security2:error] [pid 157386:tid 157413] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvlQABcRo"] [Tue Aug 18 13:05:38.960063 2026] [security2:error] [pid 157386:tid 157619] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvlQABcRo"] [Tue Aug 18 13:05:38.991415 2026] [security2:error] [pid 157386:tid 157614] [client 40.85.222.29:6494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvmAAAAWw"] [Tue Aug 18 13:05:39.002249 2026] [authz_core:error] [pid 157386:tid 157411] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:39.002515 2026] [authz_core:error] [pid 157386:tid 157411] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:39.072811 2026] [security2:error] [pid 157386:tid 157528] [client 20.25.139.174:4445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/as.php"] [unique_id "aoSC001jzAhYHVVT1WfvngAAARY"] [Tue Aug 18 13:05:39.079139 2026] [security2:error] [pid 157386:tid 157578] [client 158.23.17.4:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ud.php"] [unique_id "aoSC001jzAhYHVVT1WfvnwAAAUg"] [Tue Aug 18 13:05:39.081710 2026] [security2:error] [pid 157386:tid 157555] [client 20.250.13.23:44057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/languages.php"] [unique_id "aoSC001jzAhYHVVT1WfvoAAAATE"] [Tue Aug 18 13:05:39.088135 2026] [security2:error] [pid 157386:tid 157588] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC001jzAhYHVVT1WfvnQABUgg"] [Tue Aug 18 13:05:39.097961 2026] [security2:error] [pid 157386:tid 157549] [client 20.203.183.135:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/dex.php"] [unique_id "aoSC001jzAhYHVVT1WfvoQAAASs"] [Tue Aug 18 13:05:39.148830 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/public/css.php"] [unique_id "aoSC001jzAhYHVVT1WfvogAAARk"] [Tue Aug 18 13:05:39.164129 2026] [security2:error] [pid 157386:tid 157562] [client 40.74.65.169:41418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/tTPcH.php"] [unique_id "aoSC001jzAhYHVVT1WfvowAAATg"] [Tue Aug 18 13:05:39.176932 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.49.167:12791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/abcd.php"] [unique_id "aoSC001jzAhYHVVT1WfvpAAAAT0"] [Tue Aug 18 13:05:39.178254 2026] [security2:error] [pid 157386:tid 157598] [client 20.51.153.15:8716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/47.php"] [unique_id "aoSC001jzAhYHVVT1WfvpQAAAVw"] [Tue Aug 18 13:05:39.185464 2026] [security2:error] [pid 157386:tid 157546] [client 20.79.222.117:17995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/puc.php"] [unique_id "aoSC001jzAhYHVVT1WfvpgAAASg"] [Tue Aug 18 13:05:39.200709 2026] [security2:error] [pid 157386:tid 157519] [client 20.151.109.219:50436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kf.php"] [unique_id "aoSC001jzAhYHVVT1WfvpwAAAQ0"] [Tue Aug 18 13:05:39.225422 2026] [security2:error] [pid 157386:tid 157406] [remote 208.122.213.225:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stremma.com.br"] [uri "/wp-login.php"] [unique_id "aoSC001jzAhYHVVT1WfvqAABIRM"] [Tue Aug 18 13:05:39.288789 2026] [security2:error] [pid 157386:tid 157627] [client 40.85.222.29:6652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSC001jzAhYHVVT1WfvqwAAAXk"] [Tue Aug 18 13:05:39.289650 2026] [security2:error] [pid 157386:tid 157611] [client 68.155.154.236:14252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSC001jzAhYHVVT1WfvrAAAAWk"] [Tue Aug 18 13:05:39.300595 2026] [security2:error] [pid 157386:tid 157580] [client 20.1.169.243:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/load.php"] [unique_id "aoSC001jzAhYHVVT1WfvrgAAAUo"] [Tue Aug 18 13:05:39.302704 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:39.302979 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:39.352687 2026] [security2:error] [pid 157386:tid 157610] [client 20.206.73.37:18010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/nano.php"] [unique_id "aoSC001jzAhYHVVT1WfvsQAAAWg"] [Tue Aug 18 13:05:39.400800 2026] [security2:error] [pid 157386:tid 157558] [client 132.196.30.78:18953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/atomlib.php"] [unique_id "aoSC001jzAhYHVVT1WfvsgAAATQ"] [Tue Aug 18 13:05:39.437220 2026] [security2:error] [pid 157386:tid 157600] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC001jzAhYHVVT1WfvtQAAAV4"] [Tue Aug 18 13:05:39.462501 2026] [security2:error] [pid 157386:tid 157533] [client 20.118.133.132:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/ai.php"] [unique_id "aoSC001jzAhYHVVT1WfvtgAAARs"] [Tue Aug 18 13:05:39.480851 2026] [security2:error] [pid 157386:tid 157632] [client 20.51.153.15:8719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/payout.php"] [unique_id "aoSC001jzAhYHVVT1WfvuAAAAX4"] [Tue Aug 18 13:05:39.514488 2026] [security2:error] [pid 157386:tid 157561] [client 20.116.17.175:22604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/12.php"] [unique_id "aoSC001jzAhYHVVT1WfvugAAATc"] [Tue Aug 18 13:05:39.537208 2026] [authz_core:error] [pid 157386:tid 157628] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:39.537537 2026] [authz_core:error] [pid 157386:tid 157628] [client 192.178.4.133:62664] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:39.559657 2026] [security2:error] [pid 157386:tid 157604] [client 157.90.156.63:57200] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSC0k1jzAhYHVVT1WfvUwAAAWI"], referer: https://www.parquefazendadasflores.com.br [Tue Aug 18 13:05:39.581619 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:49340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/su.php"] [unique_id "aoSC001jzAhYHVVT1WfvvgAAASk"] [Tue Aug 18 13:05:39.589586 2026] [security2:error] [pid 157386:tid 157571] [client 20.79.222.117:18039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/inso.php"] [unique_id "aoSC001jzAhYHVVT1WfvwAAAAUE"] [Tue Aug 18 13:05:39.603379 2026] [authz_core:error] [pid 157386:tid 157453] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:39.603633 2026] [authz_core:error] [pid 157386:tid 157453] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:39.621084 2026] [security2:error] [pid 157386:tid 157612] [client 40.85.222.29:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/blog/byp.php"] [unique_id "aoSC001jzAhYHVVT1WfvxAAAAWo"] [Tue Aug 18 13:05:39.622333 2026] [security2:error] [pid 157386:tid 157618] [client 20.206.73.37:33723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/sky.php"] [unique_id "aoSC001jzAhYHVVT1WfvxQAAAXA"] [Tue Aug 18 13:05:39.643265 2026] [security2:error] [pid 157386:tid 157564] [client 20.25.139.174:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/min.php"] [unique_id "aoSC001jzAhYHVVT1WfvxgAAATo"] [Tue Aug 18 13:05:39.657938 2026] [security2:error] [pid 157386:tid 157643] [client 20.91.215.254:15142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-activat.php"] [unique_id "aoSC001jzAhYHVVT1WfvxwAAAYk"] [Tue Aug 18 13:05:39.667343 2026] [security2:error] [pid 157386:tid 157629] [client 20.1.169.243:15695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/maintenance.php"] [unique_id "aoSC001jzAhYHVVT1WfvyQAAAXs"] [Tue Aug 18 13:05:39.687779 2026] [security2:error] [pid 157386:tid 157553] [client 20.250.13.23:52883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/aa.php"] [unique_id "aoSC001jzAhYHVVT1WfvzAAAAS8"] [Tue Aug 18 13:05:39.735274 2026] [security2:error] [pid 157386:tid 157623] [client 20.51.153.15:9093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/te.php"] [unique_id "aoSC001jzAhYHVVT1Wfv0QAAAXU"] [Tue Aug 18 13:05:39.781343 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:21899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/hp.php"] [unique_id "aoSC001jzAhYHVVT1Wfv0wAAAYY"] [Tue Aug 18 13:05:39.782348 2026] [security2:error] [pid 157386:tid 157524] [client 20.171.51.14:38748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ft.php"] [unique_id "aoSC001jzAhYHVVT1Wfv1AAAARI"] [Tue Aug 18 13:05:39.839525 2026] [security2:error] [pid 157386:tid 157521] [client 40.74.65.169:41456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/bs1.php"] [unique_id "aoSC001jzAhYHVVT1Wfv2wAAAQ8"] [Tue Aug 18 13:05:39.848181 2026] [security2:error] [pid 157386:tid 157621] [client 20.171.51.14:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/hr.php"] [unique_id "aoSC001jzAhYHVVT1Wfv3AAAAXM"] [Tue Aug 18 13:05:39.873389 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:17606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSC001jzAhYHVVT1Wfv3gAAAT0"] [Tue Aug 18 13:05:39.883616 2026] [security2:error] [pid 157386:tid 157597] [client 197.184.64.235:42677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC001jzAhYHVVT1Wfv3wAAAVs"] [Tue Aug 18 13:05:39.888483 2026] [security2:error] [pid 157386:tid 157597] [client 197.184.64.235:42677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC001jzAhYHVVT1Wfv3wAAAVs"] [Tue Aug 18 13:05:39.895065 2026] [security2:error] [pid 157386:tid 157544] [client 40.85.222.29:6757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSC001jzAhYHVVT1Wfv4AAAASY"] [Tue Aug 18 13:05:39.907808 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:39.908086 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:39.914751 2026] [security2:error] [pid 157386:tid 157537] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC001jzAhYHVVT1Wfv4wAAAR8"] [Tue Aug 18 13:05:39.916929 2026] [security2:error] [pid 157386:tid 157517] [client 20.116.17.175:22600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/x1da.php"] [unique_id "aoSC001jzAhYHVVT1Wfv5AAAAQs"] [Tue Aug 18 13:05:39.930358 2026] [security2:error] [pid 157386:tid 157616] [client 4.232.151.198:24209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/6pf6swoe.php"] [unique_id "aoSC001jzAhYHVVT1Wfv5QAAAW4"] [Tue Aug 18 13:05:39.960204 2026] [security2:error] [pid 157386:tid 157580] [client 20.250.13.23:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/nw.php"] [unique_id "aoSC001jzAhYHVVT1Wfv5wAAAUo"] [Tue Aug 18 13:05:39.970072 2026] [security2:error] [pid 157386:tid 157613] [client 213.35.127.232:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSC001jzAhYHVVT1Wfv6gAAAWs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:39.971549 2026] [security2:error] [pid 157386:tid 157583] [client 74.7.230.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.imoveiseimoveisltda.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSC001jzAhYHVVT1Wfv6QABTVc"] [Tue Aug 18 13:05:39.972261 2026] [security2:error] [pid 157386:tid 157595] [client 20.104.49.167:41780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/simple.php"] [unique_id "aoSC001jzAhYHVVT1Wfv6wAAAVk"] [Tue Aug 18 13:05:39.995999 2026] [security2:error] [pid 157386:tid 157558] [client 20.79.222.117:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/aa.php"] [unique_id "aoSC001jzAhYHVVT1Wfv7gAAATQ"] [Tue Aug 18 13:05:40.008345 2026] [security2:error] [pid 157386:tid 157592] [client 20.51.153.15:8358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/kc.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv7wAAAVY"] [Tue Aug 18 13:05:40.032312 2026] [autoindex:error] [pid 157386:tid 157546] [client 205.210.31.44:64700] AH01276: Cannot serve directory /home3/luzpatchworkcom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:40.032333 2026] [security2:error] [pid 157386:tid 157519] [client 20.1.169.243:15555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/min.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv8wAAAQ0"] [Tue Aug 18 13:05:40.036311 2026] [security2:error] [pid 157386:tid 157632] [client 68.155.154.236:14278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv9AAAAX4"] [Tue Aug 18 13:05:40.038549 2026] [security2:error] [pid 157386:tid 157589] [client 20.104.100.201:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv9QAAAVM"] [Tue Aug 18 13:05:40.050662 2026] [security2:error] [pid 157386:tid 157561] [client 52.173.121.69:9971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv9gAAATc"] [Tue Aug 18 13:05:40.074866 2026] [security2:error] [pid 157386:tid 157635] [client 49.13.24.81:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSC001jzAhYHVVT1WfvrwAAAYE"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:05:40.139104 2026] [security2:error] [pid 157386:tid 157532] [client 68.221.73.131:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.miruku.co.mz"] [uri "/ajax.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv-QAAARo"] [Tue Aug 18 13:05:40.195404 2026] [security2:error] [pid 157386:tid 157572] [client 20.203.183.135:28334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/puc.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv-wAAAUI"] [Tue Aug 18 13:05:40.203274 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/gelay.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv_gAAAYk"] [Tue Aug 18 13:05:40.210761 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:40.211169 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:40.212711 2026] [autoindex:error] [pid 157386:tid 157600] [client 20.25.139.174:4546] AH01276: Cannot serve directory /home3/cp39imobibrasil/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:40.241816 2026] [security2:error] [pid 157386:tid 157560] [client 40.85.222.29:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSC1E1jzAhYHVVT1Wfv_wAAATY"] [Tue Aug 18 13:05:40.246327 2026] [security2:error] [pid 157386:tid 157615] [client 4.223.113.180:35651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/delpaths.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwAAAAAW0"] [Tue Aug 18 13:05:40.300690 2026] [security2:error] [pid 157386:tid 157636] [client 20.51.153.15:8753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "regaf.noise2.com.br"] [uri "/bf.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwAwAAAYI"] [Tue Aug 18 13:05:40.339568 2026] [security2:error] [pid 157386:tid 157604] [client 20.91.215.254:15106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwBQAAAWI"] [Tue Aug 18 13:05:40.352565 2026] [security2:error] [pid 157386:tid 157559] [client 5.31.227.224:1451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwBwAAATU"] [Tue Aug 18 13:05:40.360081 2026] [security2:error] [pid 157386:tid 157559] [client 5.31.227.224:1451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwBwAAATU"] [Tue Aug 18 13:05:40.378786 2026] [security2:error] [pid 157386:tid 157529] [client 20.25.139.174:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/php8.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwCQAAARc"] [Tue Aug 18 13:05:40.390840 2026] [security2:error] [pid 157386:tid 157562] [client 68.155.154.236:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwCgAAATg"] [Tue Aug 18 13:05:40.397041 2026] [security2:error] [pid 157386:tid 157597] [client 20.79.222.117:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/img.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwCwAAAVs"] [Tue Aug 18 13:05:40.400636 2026] [security2:error] [pid 157386:tid 157614] [client 20.1.169.243:15565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/ms-files.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwDAAAAWw"] [Tue Aug 18 13:05:40.406178 2026] [security2:error] [pid 157386:tid 157544] [client 20.116.17.175:45269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/mcs.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwDgAAASY"] [Tue Aug 18 13:05:40.426074 2026] [security2:error] [pid 157386:tid 157638] [client 20.151.109.219:39978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wx.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwEAAAAYQ"] [Tue Aug 18 13:05:40.453198 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:45831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/ninja.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwEwAAAUM"] [Tue Aug 18 13:05:40.478932 2026] [security2:error] [pid 157386:tid 157550] [client 20.25.139.174:4624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/inputs.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwFAAAASw"] [Tue Aug 18 13:05:40.484280 2026] [security2:error] [pid 157386:tid 157627] [client 49.13.24.81:18222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwEgAAAXk"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:05:40.485163 2026] [security2:error] [pid 157386:tid 157588] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwFQAAAVI"] [Tue Aug 18 13:05:40.509153 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:40.509591 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:40.523936 2026] [security2:error] [pid 157386:tid 157630] [client 20.171.51.14:7906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/h.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwHwAAAXw"] [Tue Aug 18 13:05:40.525219 2026] [security2:error] [pid 157386:tid 157552] [client 40.74.65.169:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/hp2.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwIAAAAS4"] [Tue Aug 18 13:05:40.538671 2026] [security2:error] [pid 157386:tid 157623] [client 20.250.13.23:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-mail.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwIgAAAXU"] [Tue Aug 18 13:05:40.565038 2026] [security2:error] [pid 157386:tid 157632] [client 40.85.222.29:6640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.zilempreendimentos.com.br"] [uri "/images/security.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwIwAAAX4"] [Tue Aug 18 13:05:40.583753 2026] [security2:error] [pid 157386:tid 157549] [client 20.250.13.23:44090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwJQAAASs"] [Tue Aug 18 13:05:40.596794 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wp-key.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwJgAAAU4"] [Tue Aug 18 13:05:40.601693 2026] [security2:error] [pid 157386:tid 157556] [client 20.104.49.167:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/wp-manager.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwJwAAATI"] [Tue Aug 18 13:05:40.605153 2026] [security2:error] [pid 157386:tid 157582] [client 196.12.128.158:56967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwKAAAAUw"] [Tue Aug 18 13:05:40.605279 2026] [security2:error] [pid 157386:tid 157582] [client 196.12.128.158:56967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwKAAAAUw"] [Tue Aug 18 13:05:40.611682 2026] [security2:error] [pid 157386:tid 157520] [client 103.120.71.157:40665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwKgAAAQ4"] [Tue Aug 18 13:05:40.611823 2026] [security2:error] [pid 157386:tid 157520] [client 103.120.71.157:40665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwKgAAAQ4"] [Tue Aug 18 13:05:40.644449 2026] [security2:error] [pid 157386:tid 157543] [client 68.221.73.131:46939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/8.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwLAAAASU"] [Tue Aug 18 13:05:40.666916 2026] [security2:error] [pid 157386:tid 157580] [client 4.232.151.198:24214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/gvy6f.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwLQAAAUo"] [Tue Aug 18 13:05:40.678229 2026] [security2:error] [pid 157386:tid 157612] [client 158.23.17.4:48962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ip.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwLgAAAWo"] [Tue Aug 18 13:05:40.704043 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.100.201:54079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/makeasmtp.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwLwAAAWA"] [Tue Aug 18 13:05:40.753496 2026] [security2:error] [pid 157386:tid 157605] [client 20.206.73.37:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/coffee.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwMQAAAWM"] [Tue Aug 18 13:05:40.761076 2026] [security2:error] [pid 157386:tid 157525] [client 49.13.24.81:18214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSC001jzAhYHVVT1WfvnAAAARM"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:05:40.764892 2026] [security2:error] [pid 157386:tid 157532] [client 20.1.169.243:15587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/options.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwMwAAARo"] [Tue Aug 18 13:05:40.765809 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/adminfuns.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwNAAAAUI"] [Tue Aug 18 13:05:40.783777 2026] [security2:error] [pid 157386:tid 157643] [client 68.155.154.236:14216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwNQAAAYk"] [Tue Aug 18 13:05:40.792078 2026] [security2:error] [pid 157386:tid 157629] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwNgAAAXs"] [Tue Aug 18 13:05:40.808234 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:40.808501 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:40.811762 2026] [security2:error] [pid 157386:tid 157577] [client 20.79.222.117:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/222.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwOAAAAUc"] [Tue Aug 18 13:05:40.831520 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:22599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/adminner.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwOQAAAXE"] [Tue Aug 18 13:05:40.833951 2026] [security2:error] [pid 157386:tid 157615] [client 20.38.3.247:36753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/puc.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwOgAAAW0"] [Tue Aug 18 13:05:40.942869 2026] [security2:error] [pid 157386:tid 157518] [client 20.25.139.174:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwPAAAAQw"] [Tue Aug 18 13:05:40.966641 2026] [security2:error] [pid 157386:tid 157560] [client 20.25.139.174:4607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/admin.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwPQAAATY"] [Tue Aug 18 13:05:40.991755 2026] [security2:error] [pid 157386:tid 157576] [client 213.35.127.232:57120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwQQAAAUY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:40.995715 2026] [security2:error] [pid 157386:tid 157542] [client 20.91.215.254:16635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/past1.php"] [unique_id "aoSC1E1jzAhYHVVT1WfwQgAAASQ"] [Tue Aug 18 13:05:41.007894 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:49926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gg.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwRAAAAUM"] [Tue Aug 18 13:05:41.065562 2026] [security2:error] [pid 157386:tid 157624] [client 102.213.179.104:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwSgAAAXY"] [Tue Aug 18 13:05:41.065717 2026] [security2:error] [pid 157386:tid 157624] [client 102.213.179.104:65101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwSgAAAXY"] [Tue Aug 18 13:05:41.067532 2026] [security2:error] [pid 157386:tid 157535] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwSwAAAR0"] [Tue Aug 18 13:05:41.076038 2026] [authz_core:error] [pid 157386:tid 157421] [remote 57.141.22.11:60306] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:41.076505 2026] [authz_core:error] [pid 157386:tid 157421] [remote 57.141.22.11:60306] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:41.114687 2026] [authz_core:error] [pid 157386:tid 157441] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:41.115167 2026] [authz_core:error] [pid 157386:tid 157441] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:41.136301 2026] [security2:error] [pid 157386:tid 157634] [client 68.155.154.236:14215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwUQAAAYA"] [Tue Aug 18 13:05:41.145305 2026] [security2:error] [pid 157386:tid 157550] [client 20.1.169.243:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/security.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwUgAAASw"] [Tue Aug 18 13:05:41.147263 2026] [security2:error] [pid 157386:tid 157620] [client 52.173.121.69:63596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/blog/byp.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwUwAAAXI"] [Tue Aug 18 13:05:41.152287 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:22567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/dragonshell.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwVAAAAYg"] [Tue Aug 18 13:05:41.165128 2026] [security2:error] [pid 157386:tid 157549] [client 20.171.51.14:18651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/40.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwVgAAASs"] [Tue Aug 18 13:05:41.194478 2026] [security2:error] [pid 157386:tid 157574] [client 20.203.183.135:19077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/inso.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwVwAAAUQ"] [Tue Aug 18 13:05:41.211066 2026] [security2:error] [pid 157386:tid 157635] [client 40.74.65.169:41431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/yb.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwWAAAAYE"] [Tue Aug 18 13:05:41.222657 2026] [autoindex:error] [pid 157386:tid 157554] [client 20.250.13.23:44089] AH01276: Cannot serve directory /home4/oleoebaterias/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:41.226380 2026] [security2:error] [pid 157386:tid 157582] [client 20.79.222.117:18021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/key.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwWgAAAUw"] [Tue Aug 18 13:05:41.238705 2026] [security2:error] [pid 157386:tid 157520] [client 20.104.100.201:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/cok.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwWwAAAQ4"] [Tue Aug 18 13:05:41.241169 2026] [security2:error] [pid 157386:tid 157548] [client 20.171.51.14:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kt.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwXAAAASo"] [Tue Aug 18 13:05:41.242587 2026] [security2:error] [pid 157386:tid 157625] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwXQAAAXc"] [Tue Aug 18 13:05:41.261974 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:21251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/dj.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwXgAAAVA"] [Tue Aug 18 13:05:41.283080 2026] [security2:error] [pid 157386:tid 157543] [client 40.74.65.169:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwYAAAASU"] [Tue Aug 18 13:05:41.301911 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:39821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gi.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwZAAAATw"] [Tue Aug 18 13:05:41.315785 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:27730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/phpprobe.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwZQAAAXA"] [Tue Aug 18 13:05:41.326469 2026] [security2:error] [pid 157386:tid 157630] [client 4.232.151.198:24210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/index22.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwZwAAAXw"] [Tue Aug 18 13:05:41.349044 2026] [security2:error] [pid 157386:tid 157607] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/dirs.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwagAAAWU"] [Tue Aug 18 13:05:41.349069 2026] [security2:error] [pid 157386:tid 157605] [client 20.104.100.201:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/av.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwaQAAAWM"] [Tue Aug 18 13:05:41.362985 2026] [security2:error] [pid 157386:tid 157532] [client 20.38.3.247:35608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/inso.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwbAAAARo"] [Tue Aug 18 13:05:41.370840 2026] [security2:error] [pid 157386:tid 157632] [client 49.13.24.81:1076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwawAAAX4"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:05:41.411270 2026] [authz_core:error] [pid 157386:tid 157505] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:41.411551 2026] [authz_core:error] [pid 157386:tid 157505] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:41.426457 2026] [security2:error] [pid 157386:tid 157619] [client 20.250.13.23:44089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwcAAAAXE"] [Tue Aug 18 13:05:41.494180 2026] [security2:error] [pid 157386:tid 157633] [client 49.13.167.123:4356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSC001jzAhYHVVT1Wfv6AAAAX8"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:05:41.496463 2026] [security2:error] [pid 157386:tid 157612] [client 20.25.139.174:4563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/222.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwdAAAAWo"] [Tue Aug 18 13:05:41.498809 2026] [security2:error] [pid 157386:tid 157580] [client 20.25.139.174:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/goods.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwdQAAAUo"] [Tue Aug 18 13:05:41.510394 2026] [security2:error] [pid 157386:tid 157629] [client 20.1.169.243:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwdgAAAXs"] [Tue Aug 18 13:05:41.515666 2026] [security2:error] [pid 157386:tid 157568] [client 68.155.154.236:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwdwAAAT4"] [Tue Aug 18 13:05:41.527406 2026] [security2:error] [pid 157386:tid 157640] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/about.php"] [unique_id "aoSC1U1jzAhYHVVT1WfweAAAAYY"] [Tue Aug 18 13:05:41.528577 2026] [security2:error] [pid 157386:tid 157604] [client 20.206.73.37:22351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "manoelmotosecarros.com.br"] [uri "/.mopj.php"] [unique_id "aoSC1U1jzAhYHVVT1WfweQAAAWI"] [Tue Aug 18 13:05:41.589360 2026] [security2:error] [pid 157386:tid 157564] [client 20.250.13.23:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/bolt.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwegAAATo"] [Tue Aug 18 13:05:41.589638 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.49.167:2750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/xiugai.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwewAAAUY"] [Tue Aug 18 13:05:41.610761 2026] [security2:error] [pid 157386:tid 157573] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/fresh.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwfQAAAUM"] [Tue Aug 18 13:05:41.626606 2026] [security2:error] [pid 157386:tid 157578] [client 20.79.222.117:17932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/chosen.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwfwAAAUg"] [Tue Aug 18 13:05:41.631797 2026] [security2:error] [pid 157386:tid 157538] [client 132.196.30.78:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/rip.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwgAAAASA"] [Tue Aug 18 13:05:41.665070 2026] [security2:error] [pid 157386:tid 157533] [client 20.116.17.175:22536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/setup-config.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwggAAARs"] [Tue Aug 18 13:05:41.680608 2026] [security2:error] [pid 157386:tid 157628] [client 20.203.183.135:19130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/aa.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwgwAAAXo"] [Tue Aug 18 13:05:41.684133 2026] [security2:error] [pid 157386:tid 157615] [client 20.91.215.254:15120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/file61.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwhAAAAW0"] [Tue Aug 18 13:05:41.738397 2026] [security2:error] [pid 157386:tid 157587] [client 20.104.100.201:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/accesson.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwhwAAAVE"] [Tue Aug 18 13:05:41.745928 2026] [security2:error] [pid 157386:tid 157574] [client 68.221.73.131:30976] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/1.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwiAAAAUQ"] [Tue Aug 18 13:05:41.746035 2026] [security2:error] [pid 157386:tid 157574] [client 68.221.73.131:30976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/1.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwiAAAAUQ"] [Tue Aug 18 13:05:41.747242 2026] [security2:error] [pid 157386:tid 157635] [client 68.155.156.252:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwiQAAAYE"] [Tue Aug 18 13:05:41.787963 2026] [security2:error] [pid 157386:tid 157636] [client 49.13.24.81:1062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwTQAAAYI"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:05:41.805600 2026] [security2:error] [pid 157386:tid 157520] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwigAAAQ4"] [Tue Aug 18 13:05:41.871578 2026] [security2:error] [pid 157386:tid 157528] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/admin404.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwiwAAARY"] [Tue Aug 18 13:05:41.872143 2026] [security2:error] [pid 157386:tid 157556] [client 20.1.169.243:15568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwjAAAATI"] [Tue Aug 18 13:05:41.889475 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pz.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwjQAAAXA"] [Tue Aug 18 13:05:41.896892 2026] [security2:error] [pid 157386:tid 157602] [client 40.74.65.169:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/vc.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwjgAAAWA"] [Tue Aug 18 13:05:41.943512 2026] [security2:error] [pid 157386:tid 157525] [client 20.171.51.14:58035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ee.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwkAAAARM"] [Tue Aug 18 13:05:41.971898 2026] [security2:error] [pid 157386:tid 157532] [client 68.155.154.236:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwkgAAARo"] [Tue Aug 18 13:05:41.980358 2026] [security2:error] [pid 157386:tid 157637] [client 40.74.65.169:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwkwAAAYM"] [Tue Aug 18 13:05:41.982606 2026] [security2:error] [pid 157386:tid 157554] [client 4.232.151.198:29662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/theme/gr.php"] [unique_id "aoSC1U1jzAhYHVVT1WfwlAAAATA"] [Tue Aug 18 13:05:42.007799 2026] [security2:error] [pid 157386:tid 157610] [client 213.35.127.232:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwlwAAAWg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:42.010917 2026] [security2:error] [pid 157386:tid 157547] [client 20.25.139.174:4598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwmAAAASk"] [Tue Aug 18 13:05:42.011425 2026] [security2:error] [pid 157386:tid 157543] [client 20.25.139.174:4542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/file.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwmQAAASU"] [Tue Aug 18 13:05:42.039354 2026] [security2:error] [pid 157386:tid 157534] [client 20.79.222.117:18024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/wpxml.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwmwAAARw"] [Tue Aug 18 13:05:42.041417 2026] [security2:error] [pid 157386:tid 157639] [client 20.250.13.23:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwnAAAAYU"] [Tue Aug 18 13:05:42.089411 2026] [security2:error] [pid 157386:tid 157540] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/f35.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwngAAASI"] [Tue Aug 18 13:05:42.101642 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:22597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/f35.update.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwoQAAAXk"] [Tue Aug 18 13:05:42.104305 2026] [security2:error] [pid 157386:tid 157614] [client 223.185.37.47:3779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwogAAAWw"] [Tue Aug 18 13:05:42.104479 2026] [security2:error] [pid 157386:tid 157614] [client 223.185.37.47:3779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwogAAAWw"] [Tue Aug 18 13:05:42.152792 2026] [security2:error] [pid 157386:tid 157633] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/loading.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwpwAAAX8"] [Tue Aug 18 13:05:42.170037 2026] [security2:error] [pid 157386:tid 157585] [client 20.250.13.23:27854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/nw.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwqAAAAU8"] [Tue Aug 18 13:05:42.175935 2026] [security2:error] [pid 157386:tid 157629] [client 20.151.109.219:56001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/wp-title.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwqgAAAXs"] [Tue Aug 18 13:05:42.205943 2026] [security2:error] [pid 157386:tid 157598] [client 4.223.113.180:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/NewFile.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwrQAAAVw"] [Tue Aug 18 13:05:42.215757 2026] [security2:error] [pid 157386:tid 157566] [client 49.13.167.123:61982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwnQAAATw"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:05:42.253546 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/wp-blog-header.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwrgAAAYc"] [Tue Aug 18 13:05:42.299293 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kk.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwrwAAAUY"] [Tue Aug 18 13:05:42.313496 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:42.313756 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:42.321377 2026] [security2:error] [pid 157386:tid 157611] [client 68.155.154.236:14208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwsgAAAWk"] [Tue Aug 18 13:05:42.385974 2026] [security2:error] [pid 157386:tid 157643] [client 20.171.51.14:38724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ak.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwtAAAAYk"] [Tue Aug 18 13:05:42.394700 2026] [security2:error] [pid 157386:tid 157616] [client 20.116.17.175:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/bdroot.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwtQAAAW4"] [Tue Aug 18 13:05:42.399423 2026] [security2:error] [pid 157386:tid 157578] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/conn-test.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwtgAAAUg"] [Tue Aug 18 13:05:42.420396 2026] [security2:error] [pid 157386:tid 157519] [client 68.155.156.252:16690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwugAAAQ0"] [Tue Aug 18 13:05:42.447946 2026] [security2:error] [pid 157386:tid 157550] [client 20.79.222.117:17939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/file1221.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwuwAAASw"] [Tue Aug 18 13:05:42.518559 2026] [security2:error] [pid 157386:tid 157636] [client 20.206.73.37:39619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/file5.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwvQAAAYI"] [Tue Aug 18 13:05:42.519101 2026] [security2:error] [pid 157386:tid 157548] [client 20.104.100.201:54068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/av.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwvgAAASo"] [Tue Aug 18 13:05:42.562472 2026] [security2:error] [pid 157386:tid 157517] [client 20.25.139.174:4603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwwgAAAQs"] [Tue Aug 18 13:05:42.562546 2026] [security2:error] [pid 157386:tid 157588] [client 20.25.139.174:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/info.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwwQAAAVI"] [Tue Aug 18 13:05:42.563340 2026] [security2:error] [pid 157386:tid 157594] [client 158.23.17.4:40405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/99.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwwwAAAVg"] [Tue Aug 18 13:05:42.568182 2026] [security2:error] [pid 157386:tid 157607] [client 20.104.49.167:21939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/wp-load.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwxAAAAWU"] [Tue Aug 18 13:05:42.586244 2026] [security2:error] [pid 157386:tid 157525] [client 40.74.65.169:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/pema.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwxgAAARM"] [Tue Aug 18 13:05:42.600357 2026] [autoindex:error] [pid 157386:tid 157518] [client 20.91.215.254:7879] AH01276: Cannot serve directory /home3/pletud/public_html/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:42.620355 2026] [security2:error] [pid 157386:tid 157635] [client 20.1.169.243:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/wp-mail.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwyAAAAYE"] [Tue Aug 18 13:05:42.635455 2026] [security2:error] [pid 157386:tid 157600] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/inputs.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwyQAAAV4"] [Tue Aug 18 13:05:42.642707 2026] [security2:error] [pid 157386:tid 157599] [client 20.203.183.135:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/img.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwzAAAAV0"] [Tue Aug 18 13:05:42.652547 2026] [security2:error] [pid 157386:tid 157589] [client 20.250.13.23:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/f7.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwzgAAAVM"] [Tue Aug 18 13:05:42.663474 2026] [security2:error] [pid 157386:tid 157543] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/evil.php"] [unique_id "aoSC1k1jzAhYHVVT1WfwzwAAASU"] [Tue Aug 18 13:05:42.669741 2026] [security2:error] [pid 157386:tid 157534] [client 20.116.17.175:22633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-temp.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw0AAAARw"] [Tue Aug 18 13:05:42.673271 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/aa.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw0gAAAS8"] [Tue Aug 18 13:05:42.699398 2026] [security2:error] [pid 157386:tid 157614] [client 68.155.154.236:14277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw1AAAAWw"] [Tue Aug 18 13:05:42.713854 2026] [security2:error] [pid 157386:tid 157538] [client 132.196.30.78:20272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/p.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw1wAAASA"] [Tue Aug 18 13:05:42.755176 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/phpcheck.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw2QAAAVk"] [Tue Aug 18 13:05:42.768501 2026] [security2:error] [pid 157386:tid 157571] [client 68.221.73.131:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/about.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw2wAAAUE"] [Tue Aug 18 13:05:42.783017 2026] [security2:error] [pid 157386:tid 157597] [client 52.173.121.69:63595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw3gAAAVs"] [Tue Aug 18 13:05:42.785373 2026] [security2:error] [pid 157386:tid 157560] [client 20.250.13.23:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/bthil.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw3wAAATY"] [Tue Aug 18 13:05:42.798843 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:17616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fa.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw4AAAAXQ"] [Tue Aug 18 13:05:42.810119 2026] [security2:error] [pid 157386:tid 157579] [client 20.91.215.254:7879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plenitude.com.br"] [uri "/license.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw4gAAAUk"] [Tue Aug 18 13:05:42.859086 2026] [fcgid:warn] [pid 157386:tid 157613] (70014)End of file found: [client 66.132.172.184:17298] mod_fcgid: can't get data from http client [Tue Aug 18 13:05:42.866198 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:20845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/styles.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw5wAAAW4"] [Tue Aug 18 13:05:42.880413 2026] [security2:error] [pid 157386:tid 157566] [client 49.13.134.145:31580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw2gAAATw"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:05:42.897006 2026] [security2:error] [pid 157386:tid 157609] [client 20.79.222.117:17966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/nox.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw6AAAAWc"] [Tue Aug 18 13:05:42.914061 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:42.914330 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:42.936272 2026] [security2:error] [pid 157386:tid 157623] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/wp-key.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw6wAAAXU"] [Tue Aug 18 13:05:42.986878 2026] [security2:error] [pid 157386:tid 157617] [client 20.206.73.37:2145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/h.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw8QAAAW8"] [Tue Aug 18 13:05:42.988510 2026] [security2:error] [pid 157386:tid 157608] [client 20.1.169.243:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/wp-signup.php"] [unique_id "aoSC1k1jzAhYHVVT1Wfw8gAAAWY"] [Tue Aug 18 13:05:43.030397 2026] [security2:error] [pid 157386:tid 157627] [client 213.35.127.232:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSC101jzAhYHVVT1Wfw9gAAAXk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:43.047520 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:45270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-css.php"] [unique_id "aoSC101jzAhYHVVT1Wfw9wAAASs"] [Tue Aug 18 13:05:43.066193 2026] [security2:error] [pid 157386:tid 157637] [client 86.120.159.145:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1Wfw-AAAAYM"] [Tue Aug 18 13:05:43.066366 2026] [security2:error] [pid 157386:tid 157637] [client 86.120.159.145:20411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1Wfw-AAAAYM"] [Tue Aug 18 13:05:43.077772 2026] [security2:error] [pid 157386:tid 157582] [client 68.155.156.252:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/media.php"] [unique_id "aoSC101jzAhYHVVT1Wfw-QAAAUw"] [Tue Aug 18 13:05:43.118218 2026] [security2:error] [pid 157386:tid 157537] [client 4.223.113.180:44138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/system.php"] [unique_id "aoSC101jzAhYHVVT1Wfw-wAAAR8"] [Tue Aug 18 13:05:43.163689 2026] [security2:error] [pid 157386:tid 157588] [client 20.171.51.14:18650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/test_info.php"] [unique_id "aoSC101jzAhYHVVT1Wfw_AAAAVI"] [Tue Aug 18 13:05:43.173668 2026] [security2:error] [pid 157386:tid 157607] [client 68.155.154.236:14232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSC101jzAhYHVVT1Wfw_QAAAWU"] [Tue Aug 18 13:05:43.176835 2026] [security2:error] [pid 157386:tid 157539] [client 168.62.48.100:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/well-known/index.php"] [unique_id "aoSC101jzAhYHVVT1Wfw_gAAASE"] [Tue Aug 18 13:05:43.176995 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:5368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/dg.php"] [unique_id "aoSC101jzAhYHVVT1Wfw_wAAAR0"] [Tue Aug 18 13:05:43.183284 2026] [security2:error] [pid 157386:tid 157527] [client 20.104.100.201:54071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/kj.php"] [unique_id "aoSC101jzAhYHVVT1WfxAAAAARU"] [Tue Aug 18 13:05:43.196931 2026] [security2:error] [pid 157386:tid 157532] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/phpcheck.php"] [unique_id "aoSC101jzAhYHVVT1WfxAQAAARo"] [Tue Aug 18 13:05:43.203473 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.49.167:2588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/155.php"] [unique_id "aoSC101jzAhYHVVT1WfxAgAAAX4"] [Tue Aug 18 13:05:43.215452 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:43.215717 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:43.221217 2026] [security2:error] [pid 157386:tid 157610] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/alfa.php"] [unique_id "aoSC101jzAhYHVVT1WfxBwAAAWg"] [Tue Aug 18 13:05:43.268512 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:60227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/sh.php"] [unique_id "aoSC101jzAhYHVVT1WfxDAAAAS8"] [Tue Aug 18 13:05:43.269119 2026] [security2:error] [pid 157386:tid 157540] [client 4.232.151.198:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/pwnd/pwnd.php"] [unique_id "aoSC101jzAhYHVVT1WfxDQAAASI"] [Tue Aug 18 13:05:43.270276 2026] [security2:error] [pid 157386:tid 157561] [client 20.250.13.23:43795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/photo.php"] [unique_id "aoSC101jzAhYHVVT1WfxDgAAATc"] [Tue Aug 18 13:05:43.287773 2026] [security2:error] [pid 157386:tid 157548] [client 20.25.139.174:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/a.php"] [unique_id "aoSC101jzAhYHVVT1WfxEAAAASo"] [Tue Aug 18 13:05:43.290126 2026] [security2:error] [pid 157386:tid 157528] [client 20.25.139.174:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/404.php"] [unique_id "aoSC101jzAhYHVVT1WfxEQAAARY"] [Tue Aug 18 13:05:43.297621 2026] [security2:error] [pid 157386:tid 157517] [client 132.196.30.78:20231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brasiltocantins.com.br"] [uri "/php.php"] [unique_id "aoSC101jzAhYHVVT1WfxEgAAAQs"] [Tue Aug 18 13:05:43.317774 2026] [security2:error] [pid 157386:tid 157602] [client 20.79.222.117:17922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/akismet.php"] [unique_id "aoSC101jzAhYHVVT1WfxEwAAAWA"] [Tue Aug 18 13:05:43.353145 2026] [security2:error] [pid 157386:tid 157604] [client 40.74.65.169:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/av.php"] [unique_id "aoSC101jzAhYHVVT1WfxFQAAAWI"] [Tue Aug 18 13:05:43.408122 2026] [security2:error] [pid 157386:tid 157562] [client 20.203.183.135:19077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/222.php"] [unique_id "aoSC101jzAhYHVVT1WfxGQAAATg"] [Tue Aug 18 13:05:43.460057 2026] [security2:error] [pid 157386:tid 157641] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/mimes.php"] [unique_id "aoSC101jzAhYHVVT1WfxGgAAAYc"] [Tue Aug 18 13:05:43.515531 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:43.515798 2026] [authz_core:error] [pid 157386:tid 157475] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:43.519142 2026] [security2:error] [pid 157386:tid 157559] [client 20.250.13.23:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/xleet.php"] [unique_id "aoSC101jzAhYHVVT1WfxHgAAATU"] [Tue Aug 18 13:05:43.519157 2026] [security2:error] [pid 157386:tid 157547] [client 20.1.169.243:15739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1WfxFAAAASk"] [Tue Aug 18 13:05:43.522249 2026] [security2:error] [pid 157386:tid 157521] [client 49.37.150.8:63724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1WfxHwAAAQ8"] [Tue Aug 18 13:05:43.522901 2026] [security2:error] [pid 157386:tid 157521] [client 49.37.150.8:63724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1WfxHwAAAQ8"] [Tue Aug 18 13:05:43.534570 2026] [security2:error] [pid 157386:tid 157557] [client 20.118.133.132:57584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/sf.php"] [unique_id "aoSC101jzAhYHVVT1WfxIAAAATM"] [Tue Aug 18 13:05:43.551356 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:39844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/bm.php"] [unique_id "aoSC101jzAhYHVVT1WfxIQAAAUM"] [Tue Aug 18 13:05:43.567628 2026] [security2:error] [pid 157386:tid 157430] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1WfxIgABdys"] [Tue Aug 18 13:05:43.567793 2026] [security2:error] [pid 157386:tid 157625] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC101jzAhYHVVT1WfxIgABdys"] [Tue Aug 18 13:05:43.573542 2026] [security2:error] [pid 157386:tid 157630] [client 68.155.154.236:14214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSC101jzAhYHVVT1WfxIwAAAXw"] [Tue Aug 18 13:05:43.575931 2026] [security2:error] [pid 157386:tid 157639] [client 49.13.134.145:9926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSC101jzAhYHVVT1WfxGwAAAYU"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:05:43.581578 2026] [security2:error] [pid 157386:tid 157613] [client 68.221.73.131:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/admin.php"] [unique_id "aoSC101jzAhYHVVT1WfxJAAAAWs"] [Tue Aug 18 13:05:43.619306 2026] [security2:error] [pid 157386:tid 157643] [client 52.173.121.69:47530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSC101jzAhYHVVT1WfxJgAAAYk"] [Tue Aug 18 13:05:43.623303 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:27740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/fb.php"] [unique_id "aoSC101jzAhYHVVT1WfxJwAAATw"] [Tue Aug 18 13:05:43.639216 2026] [security2:error] [pid 157386:tid 157552] [client 20.104.49.167:41415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/index.php"] [unique_id "aoSC101jzAhYHVVT1WfxKAAAAS4"] [Tue Aug 18 13:05:43.647167 2026] [security2:error] [pid 157386:tid 157533] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/lock360.php"] [unique_id "aoSC101jzAhYHVVT1WfxKQAAARs"] [Tue Aug 18 13:05:43.723436 2026] [security2:error] [pid 157386:tid 157519] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSC101jzAhYHVVT1WfxKgAAAQ0"] [Tue Aug 18 13:05:43.761577 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/flox.php"] [unique_id "aoSC101jzAhYHVVT1WfxKwAAAWE"] [Tue Aug 18 13:05:43.778746 2026] [security2:error] [pid 157386:tid 157584] [client 20.79.222.117:17987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/admin.php"] [unique_id "aoSC101jzAhYHVVT1WfxLgAAAU4"] [Tue Aug 18 13:05:43.816210 2026] [authz_core:error] [pid 157386:tid 157438] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:43.816475 2026] [authz_core:error] [pid 157386:tid 157438] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:43.825930 2026] [security2:error] [pid 157386:tid 157624] [client 20.25.139.174:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/chosen.php"] [unique_id "aoSC101jzAhYHVVT1WfxMgAAAXY"] [Tue Aug 18 13:05:43.827749 2026] [security2:error] [pid 157386:tid 157596] [client 20.25.139.174:4333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wk/index.php"] [unique_id "aoSC101jzAhYHVVT1WfxMwAAAVo"] [Tue Aug 18 13:05:43.845439 2026] [security2:error] [pid 157386:tid 157588] [client 20.171.51.14:18628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/14.php"] [unique_id "aoSC101jzAhYHVVT1WfxNAAAAVI"] [Tue Aug 18 13:05:43.899127 2026] [security2:error] [pid 157386:tid 157541] [client 20.1.169.243:15710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/wp-cron.php"] [unique_id "aoSC101jzAhYHVVT1WfxNQAAASM"] [Tue Aug 18 13:05:43.905501 2026] [security2:error] [pid 157386:tid 157527] [client 158.23.17.4:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/er.php"] [unique_id "aoSC101jzAhYHVVT1WfxNwAAARU"] [Tue Aug 18 13:05:43.905735 2026] [security2:error] [pid 157386:tid 157621] [client 20.250.13.23:35573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-aa.php"] [unique_id "aoSC101jzAhYHVVT1WfxOAAAAXM"] [Tue Aug 18 13:05:43.916842 2026] [security2:error] [pid 157386:tid 157532] [client 20.104.100.201:53883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSC101jzAhYHVVT1WfxOQAAARo"] [Tue Aug 18 13:05:43.932358 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/flower.php"] [unique_id "aoSC101jzAhYHVVT1WfxOgAAAX4"] [Tue Aug 18 13:05:43.949341 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.154.236:14213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSC101jzAhYHVVT1WfxOwAAAV4"] [Tue Aug 18 13:05:43.952420 2026] [security2:error] [pid 157386:tid 157544] [client 40.74.65.169:41452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/button.php"] [unique_id "aoSC101jzAhYHVVT1WfxPAAAASY"] [Tue Aug 18 13:05:43.955638 2026] [security2:error] [pid 157386:tid 157620] [client 4.223.113.180:35701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSC101jzAhYHVVT1WfxPQAAAXI"] [Tue Aug 18 13:05:43.975907 2026] [security2:error] [pid 157386:tid 157572] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/pqr.php"] [unique_id "aoSC101jzAhYHVVT1WfxQAAAAUI"] [Tue Aug 18 13:05:44.014571 2026] [security2:error] [pid 157386:tid 157593] [client 4.232.151.198:24216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-we.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxQwAAAVc"] [Tue Aug 18 13:05:44.022247 2026] [security2:error] [pid 157386:tid 157534] [client 20.104.49.167:48537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/aaa.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxRAAAARw"] [Tue Aug 18 13:05:44.045113 2026] [security2:error] [pid 157386:tid 157548] [client 40.74.65.169:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/media.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxRQAAASo"] [Tue Aug 18 13:05:44.048257 2026] [security2:error] [pid 157386:tid 157528] [client 20.206.73.37:21843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/bengi.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxRgAAARY"] [Tue Aug 18 13:05:44.049942 2026] [security2:error] [pid 157386:tid 157576] [client 213.35.127.232:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxRwAAAUY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:44.072497 2026] [security2:error] [pid 157386:tid 157602] [client 68.155.156.252:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/admin.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxSAAAAWA"] [Tue Aug 18 13:05:44.102055 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:10583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/server.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxSgAAAVk"] [Tue Aug 18 13:05:44.109348 2026] [security2:error] [pid 157386:tid 157571] [client 20.38.3.247:25157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/aa.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxSwAAAUE"] [Tue Aug 18 13:05:44.113083 2026] [security2:error] [pid 157386:tid 157597] [client 20.151.109.219:39861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vu.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxTQAAAVs"] [Tue Aug 18 13:05:44.127775 2026] [security2:error] [pid 157386:tid 157635] [client 213.202.253.4:57169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/postnews.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxTgAAAYE"], referer: www.google.com [Tue Aug 18 13:05:44.173053 2026] [security2:error] [pid 157386:tid 157564] [client 20.116.17.175:22544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/op.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxUAAAATo"] [Tue Aug 18 13:05:44.175778 2026] [security2:error] [pid 157386:tid 157641] [client 20.226.36.136:63841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxUQAAAYc"] [Tue Aug 18 13:05:44.216163 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/13.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxUwAAARk"] [Tue Aug 18 13:05:44.230374 2026] [security2:error] [pid 157386:tid 157521] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/lmfi2.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxVQAAAQ8"] [Tue Aug 18 13:05:44.251627 2026] [security2:error] [pid 157386:tid 157614] [client 20.79.222.117:17996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.222.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.tecnomor.com.br"] [uri "/ajax.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxVgAAAWw"] [Tue Aug 18 13:05:44.264333 2026] [security2:error] [pid 157386:tid 157622] [client 20.1.169.243:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/wp-mail.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxVwAAAXQ"] [Tue Aug 18 13:05:44.288531 2026] [security2:error] [pid 157386:tid 157578] [client 68.155.154.236:14236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxWQAAAUg"] [Tue Aug 18 13:05:44.401936 2026] [security2:error] [pid 157386:tid 157638] [client 20.25.139.174:4459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxWgAAAYQ"] [Tue Aug 18 13:05:44.402450 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.49.167:41757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/FWAZ.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxWwAAAWk"] [Tue Aug 18 13:05:44.419524 2026] [security2:error] [pid 157386:tid 157625] [client 20.25.139.174:4582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/about.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxXwAAAXc"] [Tue Aug 18 13:05:44.442788 2026] [security2:error] [pid 157386:tid 157615] [client 20.206.73.37:3505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/xyn.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxYQAAAW0"] [Tue Aug 18 13:05:44.492804 2026] [security2:error] [pid 157386:tid 157633] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/info2.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxYgAAAX8"] [Tue Aug 18 13:05:44.530084 2026] [security2:error] [pid 157386:tid 157554] [client 20.250.13.23:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/d.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxZwAAATA"] [Tue Aug 18 13:05:44.533593 2026] [security2:error] [pid 157386:tid 157584] [client 20.171.51.14:6630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/tk.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxaQAAAU4"] [Tue Aug 18 13:05:44.546655 2026] [security2:error] [pid 157386:tid 157520] [client 20.116.17.175:45275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/1xmomo.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxawAAAQ4"] [Tue Aug 18 13:05:44.561774 2026] [security2:error] [pid 157386:tid 157568] [client 20.171.51.14:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ww.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxbAAAAT4"] [Tue Aug 18 13:05:44.567207 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ic.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxbQAAAXY"] [Tue Aug 18 13:05:44.606352 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/cc.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxcQAAAXA"] [Tue Aug 18 13:05:44.616553 2026] [security2:error] [pid 157386:tid 157594] [client 52.173.121.69:9966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/images/security.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxcwAAAVg"] [Tue Aug 18 13:05:44.622313 2026] [security2:error] [pid 157386:tid 157607] [client 68.155.154.236:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/rezor.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxdAAAAWU"] [Tue Aug 18 13:05:44.626275 2026] [security2:error] [pid 157386:tid 157539] [client 20.250.13.23:35759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/x.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxdgAAASE"] [Tue Aug 18 13:05:44.628554 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gw.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxdwAAAR0"] [Tue Aug 18 13:05:44.630731 2026] [security2:error] [pid 157386:tid 157587] [client 20.1.169.243:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/xmlrpc.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxeAAAAVE"] [Tue Aug 18 13:05:44.636839 2026] [security2:error] [pid 157386:tid 157541] [client 40.74.65.169:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/wlc.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxeQAAASM"] [Tue Aug 18 13:05:44.651612 2026] [security2:error] [pid 157386:tid 157621] [client 20.226.36.136:63847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxewAAAXM"] [Tue Aug 18 13:05:44.658664 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:19745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/xinfo.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxfgAAARo"] [Tue Aug 18 13:05:44.724057 2026] [authz_core:error] [pid 157386:tid 157470] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:44.724296 2026] [authz_core:error] [pid 157386:tid 157470] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:44.741982 2026] [security2:error] [pid 157386:tid 157586] [client 68.221.73.131:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/edit.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxgAAAAVA"] [Tue Aug 18 13:05:44.742651 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/images.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxgQAAARw"] [Tue Aug 18 13:05:44.765244 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.49.167:2712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/site.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxggAAAVQ"] [Tue Aug 18 13:05:44.770869 2026] [security2:error] [pid 157386:tid 157538] [client 68.155.156.252:47328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/mac.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxgwAAASA"] [Tue Aug 18 13:05:44.771665 2026] [security2:error] [pid 157386:tid 157546] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/test_info.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxhAAAASg"] [Tue Aug 18 13:05:44.799824 2026] [security2:error] [pid 157386:tid 157530] [client 20.226.36.136:41488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/weozh.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxhgAAARg"] [Tue Aug 18 13:05:44.896463 2026] [security2:error] [pid 157386:tid 157562] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/gecko-new.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxiQAAATg"] [Tue Aug 18 13:05:44.948268 2026] [security2:error] [pid 157386:tid 157593] [client 20.25.139.174:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/vx.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxjAAAAVc"] [Tue Aug 18 13:05:44.960454 2026] [security2:error] [pid 157386:tid 157559] [client 68.155.154.236:14184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/uploads/bypass.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxjQAAATU"] [Tue Aug 18 13:05:44.971685 2026] [security2:error] [pid 157386:tid 157550] [client 20.25.139.174:4502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/term.php"] [unique_id "aoSC2E1jzAhYHVVT1WfxjgAAASw"] [Tue Aug 18 13:05:45.004027 2026] [security2:error] [pid 157386:tid 157597] [client 20.1.169.243:15942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/api.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxjwAAAVs"] [Tue Aug 18 13:05:45.019712 2026] [security2:error] [pid 157386:tid 157630] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/xynz1.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxkQAAAXw"] [Tue Aug 18 13:05:45.023286 2026] [authz_core:error] [pid 157386:tid 157395] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:45.023534 2026] [authz_core:error] [pid 157386:tid 157395] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:45.068016 2026] [security2:error] [pid 157386:tid 157561] [client 213.35.127.232:58169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxkgAAATc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:45.071205 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:5371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ue.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxlAAAASU"] [Tue Aug 18 13:05:45.072299 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.49.167:12772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/ccc.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxlQAAAYk"] [Tue Aug 18 13:05:45.073194 2026] [security2:error] [pid 157386:tid 157634] [client 20.116.17.175:22624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/txets.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxlgAAAYA"] [Tue Aug 18 13:05:45.136896 2026] [security2:error] [pid 157386:tid 157525] [client 4.232.151.198:18505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxngAAARM"] [Tue Aug 18 13:05:45.143667 2026] [security2:error] [pid 157386:tid 157564] [client 20.250.13.23:44059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxoAAAATo"] [Tue Aug 18 13:05:45.166030 2026] [security2:error] [pid 157386:tid 157633] [client 20.171.51.14:58045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/hp.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxoQAAAX8"] [Tue Aug 18 13:05:45.207633 2026] [security2:error] [pid 157386:tid 157545] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxowAAASc"] [Tue Aug 18 13:05:45.267527 2026] [security2:error] [pid 157386:tid 157568] [client 20.203.183.135:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/key.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxpQAAAT4"] [Tue Aug 18 13:05:45.268483 2026] [security2:error] [pid 157386:tid 157612] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/album.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxpgAAAWo"] [Tue Aug 18 13:05:45.285917 2026] [security2:error] [pid 157386:tid 157628] [client 74.7.228.37:54866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sistemas.numem.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSC2U1jzAhYHVVT1WfxqAABens"] [Tue Aug 18 13:05:45.310091 2026] [security2:error] [pid 157386:tid 157556] [client 40.74.65.169:41419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/fi.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxqgAAATI"] [Tue Aug 18 13:05:45.321609 2026] [authz_core:error] [pid 157386:tid 157452] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:45.321875 2026] [authz_core:error] [pid 157386:tid 157452] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:45.331604 2026] [security2:error] [pid 157386:tid 157577] [client 68.155.154.236:14233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxrAAAAUc"] [Tue Aug 18 13:05:45.334708 2026] [security2:error] [pid 157386:tid 157567] [client 4.223.113.180:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxrgAAAT0"] [Tue Aug 18 13:05:45.334736 2026] [security2:error] [pid 157386:tid 157618] [client 158.23.17.4:20415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/qk.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxrQAAAXA"] [Tue Aug 18 13:05:45.366518 2026] [security2:error] [pid 157386:tid 157536] [client 20.206.73.37:17069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/ano.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxrwAAAR4"] [Tue Aug 18 13:05:45.372912 2026] [security2:error] [pid 157386:tid 157637] [client 20.1.169.243:15614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/assets/script-loader.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxsAAAAYM"] [Tue Aug 18 13:05:45.402492 2026] [security2:error] [pid 157386:tid 157518] [client 20.151.109.219:21285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/sw.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxsQAAAQw"] [Tue Aug 18 13:05:45.422333 2026] [security2:error] [pid 157386:tid 157600] [client 40.74.65.169:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/admin.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxsgAAAV4"] [Tue Aug 18 13:05:45.426899 2026] [security2:error] [pid 157386:tid 157544] [client 20.118.133.132:59358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/xx.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxswAAASY"] [Tue Aug 18 13:05:45.450786 2026] [security2:error] [pid 157386:tid 157620] [client 20.151.109.219:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lr.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxtAAAAXI"] [Tue Aug 18 13:05:45.496672 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/01.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxtgAAAS8"] [Tue Aug 18 13:05:45.496688 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/sym.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxtwAAASI"] [Tue Aug 18 13:05:45.517604 2026] [security2:error] [pid 157386:tid 157594] [client 20.25.139.174:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxuQAAAVg"] [Tue Aug 18 13:05:45.523019 2026] [security2:error] [pid 157386:tid 157534] [client 20.104.49.167:12778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/admin.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxugAAARw"] [Tue Aug 18 13:05:45.526246 2026] [security2:error] [pid 157386:tid 157528] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/creds.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxuwAAARY"] [Tue Aug 18 13:05:45.623672 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:45.623933 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:45.669983 2026] [security2:error] [pid 157386:tid 157521] [client 20.25.139.174:4298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wap.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxxgAAAQ8"] [Tue Aug 18 13:05:45.717628 2026] [security2:error] [pid 157386:tid 157542] [client 68.155.154.236:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/index/function.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxygAAASQ"] [Tue Aug 18 13:05:45.737008 2026] [security2:error] [pid 157386:tid 157517] [client 20.226.36.136:25899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/rymmm.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxzAAAAQs"] [Tue Aug 18 13:05:45.741273 2026] [security2:error] [pid 157386:tid 157519] [client 20.104.100.201:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/kj.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxzgAAAQ0"] [Tue Aug 18 13:05:45.744812 2026] [security2:error] [pid 157386:tid 157622] [client 20.171.51.14:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wx.php"] [unique_id "aoSC2U1jzAhYHVVT1WfxzwAAAXQ"] [Tue Aug 18 13:05:45.754889 2026] [security2:error] [pid 157386:tid 157538] [client 20.250.13.23:43797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx0AAAASA"] [Tue Aug 18 13:05:45.795826 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ka.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx0wAAAVY"] [Tue Aug 18 13:05:45.796716 2026] [security2:error] [pid 157386:tid 157605] [client 68.155.156.252:13448] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "julio.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx1AAAAWM"] [Tue Aug 18 13:05:45.796839 2026] [security2:error] [pid 157386:tid 157605] [client 68.155.156.252:13448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/1.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx1AAAAWM"] [Tue Aug 18 13:05:45.807276 2026] [security2:error] [pid 157386:tid 157611] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/mandrill.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx1gAAAWk"] [Tue Aug 18 13:05:45.847342 2026] [security2:error] [pid 157386:tid 157560] [client 4.232.151.198:7721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/ulc2.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx3wAAATY"] [Tue Aug 18 13:05:45.873524 2026] [security2:error] [pid 157386:tid 157564] [client 68.221.73.131:30998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx4wAAATo"] [Tue Aug 18 13:05:45.881151 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/lv.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx5AAAAXU"] [Tue Aug 18 13:05:45.888647 2026] [security2:error] [pid 157386:tid 157627] [client 20.206.73.37:65180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx7AAAAXk"] [Tue Aug 18 13:05:45.928068 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:45.928353 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:45.993569 2026] [security2:error] [pid 157386:tid 157628] [client 20.1.169.243:15736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/blocks/heading/min.php"] [unique_id "aoSC2U1jzAhYHVVT1Wfx9QAAAXo"] [Tue Aug 18 13:05:46.006638 2026] [security2:error] [pid 157386:tid 157563] [client 40.74.65.169:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/chris.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx9wAAATk"] [Tue Aug 18 13:05:46.015553 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.43:28330] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:46.016043 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.43:28330] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:46.036781 2026] [security2:error] [pid 157386:tid 157567] [client 20.171.51.14:53883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/mo.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx-QAAAT0"] [Tue Aug 18 13:05:46.038565 2026] [security2:error] [pid 157386:tid 157588] [client 20.104.49.167:41759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/reviall.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx-gAAAVI"] [Tue Aug 18 13:05:46.044471 2026] [security2:error] [pid 157386:tid 157522] [client 20.25.139.174:4727] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx-wAAARA"] [Tue Aug 18 13:05:46.044585 2026] [security2:error] [pid 157386:tid 157522] [client 20.25.139.174:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/1.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx-wAAARA"] [Tue Aug 18 13:05:46.058364 2026] [security2:error] [pid 157386:tid 157536] [client 20.116.17.175:22561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/img.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx_AAAAR4"] [Tue Aug 18 13:05:46.063238 2026] [security2:error] [pid 157386:tid 157587] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/main.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx_QAAAVE"] [Tue Aug 18 13:05:46.067999 2026] [security2:error] [pid 157386:tid 157637] [client 68.155.154.236:14316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSC2k1jzAhYHVVT1Wfx_wAAAYM"] [Tue Aug 18 13:05:46.084383 2026] [security2:error] [pid 157386:tid 157561] [client 213.35.127.232:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyAgAAATc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:46.099713 2026] [security2:error] [pid 157386:tid 157632] [client 40.74.65.169:55175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/222.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyDQAAAX4"] [Tue Aug 18 13:05:46.123021 2026] [security2:error] [pid 157386:tid 157579] [client 149.34.210.141:58865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyDgAAAUk"] [Tue Aug 18 13:05:46.127077 2026] [security2:error] [pid 157386:tid 157600] [client 20.151.109.219:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ot.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyDwAAAV4"] [Tue Aug 18 13:05:46.156518 2026] [security2:error] [pid 157386:tid 157524] [client 20.151.109.219:13798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyEgAAARI"] [Tue Aug 18 13:05:46.226534 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:46.226809 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:46.231384 2026] [security2:error] [pid 157386:tid 157539] [client 20.25.139.174:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyGQAAASE"] [Tue Aug 18 13:05:46.277979 2026] [security2:error] [pid 157386:tid 157570] [client 20.104.100.201:53842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/png.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyHAAAAUA"] [Tue Aug 18 13:05:46.279038 2026] [security2:error] [pid 157386:tid 157582] [client 4.223.113.180:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/akc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyHQAAAUw"] [Tue Aug 18 13:05:46.282005 2026] [security2:error] [pid 157386:tid 157546] [client 68.155.156.252:13483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/coffee.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyHgAAASg"] [Tue Aug 18 13:05:46.340022 2026] [security2:error] [pid 157386:tid 157573] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/payout.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyHwAAAUM"] [Tue Aug 18 13:05:46.357593 2026] [security2:error] [pid 157386:tid 157591] [client 20.171.51.14:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/dj.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyIgAAAVU"] [Tue Aug 18 13:05:46.368145 2026] [security2:error] [pid 157386:tid 157540] [client 20.250.13.23:43825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyIwAAASI"] [Tue Aug 18 13:05:46.369525 2026] [security2:error] [pid 157386:tid 157526] [client 20.1.169.243:15958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/config.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyJAAAARQ"] [Tue Aug 18 13:05:46.387870 2026] [security2:error] [pid 157386:tid 157519] [client 74.248.130.103:34950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyJwAAAQ0"] [Tue Aug 18 13:05:46.388080 2026] [security2:error] [pid 157386:tid 157571] [client 47.128.25.77:47610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sortis.com.br"] [uri "/robots.txt"] [unique_id "aoSC2k1jzAhYHVVT1WfyKAAAAUE"] [Tue Aug 18 13:05:46.398706 2026] [security2:error] [pid 157386:tid 157579] [client 149.34.210.141:58865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyDgAAAUk"] [Tue Aug 18 13:05:46.403210 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:49982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ih.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyLgAAATw"] [Tue Aug 18 13:05:46.404993 2026] [security2:error] [pid 157386:tid 157537] [client 20.250.13.23:15396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/wp.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyLwAAAR8"] [Tue Aug 18 13:05:46.435562 2026] [security2:error] [pid 157386:tid 157569] [client 20.116.17.175:45280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyMgAAAT8"] [Tue Aug 18 13:05:46.467467 2026] [security2:error] [pid 157386:tid 157608] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/new.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyNwAAAWY"] [Tue Aug 18 13:05:46.502574 2026] [security2:error] [pid 157386:tid 157558] [client 4.232.151.198:7785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/RxR_uvhya.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyOAAAATQ"] [Tue Aug 18 13:05:46.529716 2026] [security2:error] [pid 157386:tid 157568] [client 20.151.109.219:27378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "galchurras.com.br"] [uri "/ye.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyPAAAAT4"] [Tue Aug 18 13:05:46.529941 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:46.530245 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:46.539978 2026] [security2:error] [pid 157386:tid 157612] [client 68.155.154.236:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/Cachex.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyPgAAAWo"] [Tue Aug 18 13:05:46.605576 2026] [security2:error] [pid 157386:tid 157618] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/Mailgun.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyPwAAAXA"] [Tue Aug 18 13:05:46.618670 2026] [security2:error] [pid 157386:tid 157525] [client 20.25.139.174:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/alfa.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyQQAAARM"] [Tue Aug 18 13:05:46.702525 2026] [security2:error] [pid 157386:tid 157532] [client 40.74.65.169:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/doc.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyRQAAARo"] [Tue Aug 18 13:05:46.741233 2026] [security2:error] [pid 157386:tid 157544] [client 20.203.183.135:44360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/chosen.php"] [unique_id "aoSC2k1jzAhYHVVT1WfySgAAASY"] [Tue Aug 18 13:05:46.766477 2026] [security2:error] [pid 157386:tid 157577] [client 20.25.139.174:4435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/bgymj.php"] [unique_id "aoSC2k1jzAhYHVVT1WfySwAAAUc"] [Tue Aug 18 13:05:46.768756 2026] [security2:error] [pid 157386:tid 157617] [client 20.151.109.219:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/k.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyTQAAAW8"] [Tue Aug 18 13:05:46.801177 2026] [security2:error] [pid 157386:tid 157599] [client 40.74.65.169:1828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/mac.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyTwAAAV0"] [Tue Aug 18 13:05:46.825207 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/222.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyVAAAAWA"] [Tue Aug 18 13:05:46.828683 2026] [authz_core:error] [pid 157386:tid 157426] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:46.828978 2026] [authz_core:error] [pid 157386:tid 157426] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:46.846779 2026] [security2:error] [pid 157386:tid 157539] [client 20.38.3.247:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/img.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyVQAAASE"] [Tue Aug 18 13:05:46.847922 2026] [security2:error] [pid 157386:tid 157529] [client 158.23.17.4:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyVgAAARc"] [Tue Aug 18 13:05:46.870744 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.49.167:41745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/nope.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyWAAAAUo"] [Tue Aug 18 13:05:46.878772 2026] [security2:error] [pid 157386:tid 157562] [client 20.116.17.175:1611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyWQAAATg"] [Tue Aug 18 13:05:46.881365 2026] [security2:error] [pid 157386:tid 157593] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/oauth.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyWgAAAVc"] [Tue Aug 18 13:05:46.906513 2026] [security2:error] [pid 157386:tid 157521] [client 68.155.156.252:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/classwithtostring.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyXQAAAQ8"] [Tue Aug 18 13:05:46.912244 2026] [security2:error] [pid 157386:tid 157573] [client 20.1.169.243:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyXgAAAUM"] [Tue Aug 18 13:05:46.919065 2026] [security2:error] [pid 157386:tid 157575] [client 20.171.51.14:17164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/qr.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyXwAAAUU"] [Tue Aug 18 13:05:46.943601 2026] [security2:error] [pid 157386:tid 157517] [client 20.226.36.136:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/lddxs.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyYQAAAQs"] [Tue Aug 18 13:05:46.984262 2026] [security2:error] [pid 157386:tid 157620] [client 20.250.13.23:44049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC2k1jzAhYHVVT1WfyZAAAAXI"] [Tue Aug 18 13:05:47.018234 2026] [security2:error] [pid 157386:tid 157601] [client 20.206.73.37:24508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/inso.php"] [unique_id "aoSC201jzAhYHVVT1WfyZgAAAV8"] [Tue Aug 18 13:05:47.100463 2026] [security2:error] [pid 157386:tid 157553] [client 213.35.127.232:58689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC201jzAhYHVVT1WfybQAAAS8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:47.113368 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/chosen.php"] [unique_id "aoSC201jzAhYHVVT1WfybgAAAUs"] [Tue Aug 18 13:05:47.122550 2026] [security2:error] [pid 157386:tid 157564] [client 68.155.154.236:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSC201jzAhYHVVT1WfybwAAATo"] [Tue Aug 18 13:05:47.128029 2026] [security2:error] [pid 157386:tid 157546] [client 4.223.113.180:35668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/flower.php"] [unique_id "aoSC201jzAhYHVVT1WfycQAAASg"] [Tue Aug 18 13:05:47.131075 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:47.131178 2026] [security2:error] [pid 157386:tid 157547] [client 20.250.13.23:19342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/155.php"] [unique_id "aoSC201jzAhYHVVT1WfydAAAASk"] [Tue Aug 18 13:05:47.131223 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:39868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/iu.php"] [unique_id "aoSC201jzAhYHVVT1WfycwAAAXU"] [Tue Aug 18 13:05:47.131359 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:47.137126 2026] [security2:error] [pid 157386:tid 157608] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/timeclock.php"] [unique_id "aoSC201jzAhYHVVT1WfydQAAAWY"] [Tue Aug 18 13:05:47.145823 2026] [security2:error] [pid 157386:tid 157540] [client 20.25.139.174:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/edit.php"] [unique_id "aoSC201jzAhYHVVT1WfydgAAASI"] [Tue Aug 18 13:05:47.180479 2026] [security2:error] [pid 157386:tid 157639] [client 4.232.151.198:7683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/storage/upload/bypass.php"] [unique_id "aoSC201jzAhYHVVT1WfyeAAAAYU"] [Tue Aug 18 13:05:47.204120 2026] [security2:error] [pid 157386:tid 157636] [client 68.221.73.131:17408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/inputs.php"] [unique_id "aoSC201jzAhYHVVT1WfyegAAAYI"] [Tue Aug 18 13:05:47.256170 2026] [security2:error] [pid 157386:tid 157557] [client 157.20.138.62:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC201jzAhYHVVT1WfyfAAAATM"] [Tue Aug 18 13:05:47.256278 2026] [security2:error] [pid 157386:tid 157557] [client 157.20.138.62:63210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC201jzAhYHVVT1WfyfAAAATM"] [Tue Aug 18 13:05:47.272762 2026] [security2:error] [pid 157386:tid 157603] [client 20.104.100.201:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ab.php"] [unique_id "aoSC201jzAhYHVVT1WfyfgAAAWE"] [Tue Aug 18 13:05:47.273448 2026] [security2:error] [pid 157386:tid 157556] [client 20.104.49.167:41749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/nope.php"] [unique_id "aoSC201jzAhYHVVT1WfyfwAAATI"] [Tue Aug 18 13:05:47.308942 2026] [security2:error] [pid 157386:tid 157627] [client 20.25.139.174:4593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/aa.php"] [unique_id "aoSC201jzAhYHVVT1WfygQAAAXk"] [Tue Aug 18 13:05:47.315417 2026] [security2:error] [pid 157386:tid 157596] [client 20.1.169.243:15945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css/min.php"] [unique_id "aoSC201jzAhYHVVT1WfyggAAAVo"] [Tue Aug 18 13:05:47.315667 2026] [security2:error] [pid 157386:tid 157563] [client 170.81.43.147:36984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.43.81.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agatrend.com.br"] [uri "/include/plugin/payment/alipay/pay.php"] [unique_id "aoSC201jzAhYHVVT1WfygwAAATk"] [Tue Aug 18 13:05:47.326063 2026] [security2:error] [pid 157386:tid 157516] [client 20.116.17.175:22588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSC201jzAhYHVVT1WfyhAAAAQo"] [Tue Aug 18 13:05:47.393956 2026] [security2:error] [pid 157386:tid 157610] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/email.php"] [unique_id "aoSC201jzAhYHVVT1WfyigAAAWg"] [Tue Aug 18 13:05:47.398309 2026] [security2:error] [pid 157386:tid 157541] [client 40.74.65.169:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/1337.php"] [unique_id "aoSC201jzAhYHVVT1WfyiwAAASM"] [Tue Aug 18 13:05:47.406215 2026] [security2:error] [pid 157386:tid 157625] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/info.php"] [unique_id "aoSC201jzAhYHVVT1WfyjAAAAXc"] [Tue Aug 18 13:05:47.406547 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pk.php"] [unique_id "aoSC201jzAhYHVVT1WfyjQAAAXg"] [Tue Aug 18 13:05:47.438343 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:47.438607 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:47.487176 2026] [security2:error] [pid 157386:tid 157535] [client 40.74.65.169:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/ops.php"] [unique_id "aoSC201jzAhYHVVT1WfykgAAAR0"] [Tue Aug 18 13:05:47.554438 2026] [security2:error] [pid 157386:tid 157526] [client 178.153.171.161:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC201jzAhYHVVT1WfylgAAARQ"] [Tue Aug 18 13:05:47.554594 2026] [security2:error] [pid 157386:tid 157526] [client 178.153.171.161:62610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC201jzAhYHVVT1WfylgAAARQ"] [Tue Aug 18 13:05:47.563412 2026] [security2:error] [pid 157386:tid 157529] [client 68.155.156.252:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/wp-ws68.php"] [unique_id "aoSC201jzAhYHVVT1WfylwAAARc"] [Tue Aug 18 13:05:47.593941 2026] [security2:error] [pid 157386:tid 157637] [client 20.104.49.167:12764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/new.php"] [unique_id "aoSC201jzAhYHVVT1WfymAAAAYM"] [Tue Aug 18 13:05:47.618081 2026] [security2:error] [pid 157386:tid 157542] [client 34.38.184.238:49804] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC201jzAhYHVVT1WfyoQAAASQ"] [Tue Aug 18 13:05:47.619526 2026] [security2:error] [pid 157386:tid 157548] [client 34.38.184.238:49810] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC201jzAhYHVVT1WfypQAAASo"] [Tue Aug 18 13:05:47.620316 2026] [security2:error] [pid 157386:tid 157550] [client 34.38.184.238:49788] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/media../.env"] [unique_id "aoSC201jzAhYHVVT1WfyqAAAASw"] [Tue Aug 18 13:05:47.620423 2026] [security2:error] [pid 157386:tid 157538] [client 34.38.184.238:49758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/static../.env"] [unique_id "aoSC201jzAhYHVVT1WfyqQAAASA"] [Tue Aug 18 13:05:47.621053 2026] [security2:error] [pid 157386:tid 157597] [client 34.38.184.238:49858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env"] [unique_id "aoSC201jzAhYHVVT1WfynwAAAVs"] [Tue Aug 18 13:05:47.621063 2026] [security2:error] [pid 157386:tid 157517] [client 34.38.184.238:49816] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/proc/1/environ"] [unique_id "aoSC201jzAhYHVVT1WfyqwAAAQs"] [Tue Aug 18 13:05:47.625386 2026] [security2:error] [pid 157386:tid 157620] [client 20.171.51.14:13436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fa.php"] [unique_id "aoSC201jzAhYHVVT1WfyrAAAAXI"] [Tue Aug 18 13:05:47.633833 2026] [security2:error] [pid 157386:tid 157522] [client 20.116.17.175:1628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSC201jzAhYHVVT1WfyrQAAARA"] [Tue Aug 18 13:05:47.636169 2026] [security2:error] [pid 157386:tid 157544] [client 20.250.13.23:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/adminfuns.php"] [unique_id "aoSC201jzAhYHVVT1WfyrgAAASY"] [Tue Aug 18 13:05:47.642603 2026] [security2:error] [pid 157386:tid 157537] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/profile.php"] [unique_id "aoSC201jzAhYHVVT1WfysAAAAR8"] [Tue Aug 18 13:05:47.645316 2026] [security2:error] [pid 157386:tid 157598] [client 68.155.154.236:14229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-2019.php"] [unique_id "aoSC201jzAhYHVVT1WfysQAAAVw"] [Tue Aug 18 13:05:47.647026 2026] [security2:error] [pid 157386:tid 157616] [client 20.250.13.23:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/index/function.php"] [unique_id "aoSC201jzAhYHVVT1WfysgAAAW4"] [Tue Aug 18 13:05:47.654171 2026] [security2:error] [pid 157386:tid 157622] [client 20.25.139.174:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/elp.php"] [unique_id "aoSC201jzAhYHVVT1WfyswAAAXQ"] [Tue Aug 18 13:05:47.670312 2026] [security2:error] [pid 157386:tid 157415] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSC201jzAhYHVVT1WfytQABexw"] [Tue Aug 18 13:05:47.670601 2026] [security2:error] [pid 157386:tid 157504] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSC201jzAhYHVVT1WfytgABe3U"] [Tue Aug 18 13:05:47.692871 2026] [security2:error] [pid 157386:tid 157582] [client 20.1.169.243:15755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/css/wp-login.php"] [unique_id "aoSC201jzAhYHVVT1WfyuQAAAUw"] [Tue Aug 18 13:05:47.694394 2026] [security2:error] [pid 157386:tid 157440] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/config/.env.php"] [unique_id "aoSC201jzAhYHVVT1WfyugABOzU"] [Tue Aug 18 13:05:47.700824 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:50022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/"] [unique_id "aoSC201jzAhYHVVT1WfyuwAAARs"] [Tue Aug 18 13:05:47.708243 2026] [security2:error] [pid 157386:tid 157607] [client 34.38.184.238:50104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/graphql"] [unique_id "aoSC201jzAhYHVVT1WfywQAAAWU"], referer: http://mail.meneghel.com [Tue Aug 18 13:05:47.714288 2026] [security2:error] [pid 157386:tid 157552] [client 34.38.184.238:50124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/graphql/console"] [unique_id "aoSC201jzAhYHVVT1WfywwAAAS4"], referer: http://mail.meneghel.com [Tue Aug 18 13:05:47.720150 2026] [security2:error] [pid 157386:tid 157608] [client 34.38.184.238:49946] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/proc/self/environ"] [unique_id "aoSC201jzAhYHVVT1WfyxwAAAWY"] [Tue Aug 18 13:05:47.720651 2026] [security2:error] [pid 157386:tid 157623] [client 34.38.184.238:50038] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/read"] [unique_id "aoSC201jzAhYHVVT1WfyxgAAAXU"] [Tue Aug 18 13:05:47.721770 2026] [security2:error] [pid 157386:tid 157642] [client 52.173.121.69:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSC201jzAhYHVVT1WfyyQAAAYg"] [Tue Aug 18 13:05:47.723660 2026] [security2:error] [pid 157386:tid 157639] [client 34.38.184.238:49890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/media../etc/passwd"] [unique_id "aoSC201jzAhYHVVT1WfyzAAAAYU"] [Tue Aug 18 13:05:47.726258 2026] [security2:error] [pid 157386:tid 157574] [client 34.38.184.238:49910] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env"] [unique_id "aoSC201jzAhYHVVT1Wfy0QAAAUQ"] [Tue Aug 18 13:05:47.726387 2026] [security2:error] [pid 157386:tid 157636] [client 34.38.184.238:50010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/download"] [unique_id "aoSC201jzAhYHVVT1WfyzgAAAYI"] [Tue Aug 18 13:05:47.727154 2026] [security2:error] [pid 157386:tid 157611] [client 34.38.184.238:49898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/files../etc/passwd"] [unique_id "aoSC201jzAhYHVVT1Wfy0gAAAWk"] [Tue Aug 18 13:05:47.728765 2026] [security2:error] [pid 157386:tid 157612] [client 34.38.184.238:50008] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/@vite/env"] [unique_id "aoSC201jzAhYHVVT1Wfy1AAAAWo"] [Tue Aug 18 13:05:47.729365 2026] [core:error] [pid 157386:tid 157557] [client 34.38.184.238:49892] AH10244: invalid URI path (/assets../../../etc/passwd) [Tue Aug 18 13:05:47.729910 2026] [security2:error] [pid 157386:tid 157549] [client 34.38.184.238:49978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.git-credentials"] [unique_id "aoSC201jzAhYHVVT1Wfy2AAAASs"] [Tue Aug 18 13:05:47.730804 2026] [security2:error] [pid 157386:tid 157554] [client 34.38.184.238:49888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/static../etc/passwd"] [unique_id "aoSC201jzAhYHVVT1Wfy1QAAATA"] [Tue Aug 18 13:05:47.732095 2026] [security2:error] [pid 157386:tid 157635] [client 34.38.184.238:49932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/app/.env"] [unique_id "aoSC201jzAhYHVVT1Wfy2QAAAYE"] [Tue Aug 18 13:05:47.749867 2026] [security2:error] [pid 157386:tid 157618] [client 20.171.51.14:23269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/dirs.php"] [unique_id "aoSC201jzAhYHVVT1Wfy2gAAAXA"] [Tue Aug 18 13:05:47.796225 2026] [security2:error] [pid 157386:tid 157431] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/.env.php.bak"] [unique_id "aoSC201jzAhYHVVT1Wfy2wABHiw"] [Tue Aug 18 13:05:47.805629 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ge.php"] [unique_id "aoSC201jzAhYHVVT1Wfy3AAAARM"] [Tue Aug 18 13:05:47.836840 2026] [security2:error] [pid 157386:tid 157640] [client 20.25.139.174:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-mail.php"] [unique_id "aoSC201jzAhYHVVT1Wfy3gAAAYY"] [Tue Aug 18 13:05:47.845364 2026] [security2:error] [pid 157386:tid 157570] [client 4.232.151.198:25278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pixmidias.com.br"] [uri "/alfav4-1-0.php"] [unique_id "aoSC201jzAhYHVVT1Wfy3wAAAUA"] [Tue Aug 18 13:05:47.882196 2026] [security2:error] [pid 157386:tid 157600] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSC201jzAhYHVVT1Wfy4QAAAV4"] [Tue Aug 18 13:05:47.891225 2026] [security2:error] [pid 157386:tid 157527] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/summary.php"] [unique_id "aoSC201jzAhYHVVT1Wfy4gAAARU"] [Tue Aug 18 13:05:47.898272 2026] [security2:error] [pid 157386:tid 157604] [client 20.104.49.167:41755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/new.php"] [unique_id "aoSC201jzAhYHVVT1Wfy4wAAAWI"] [Tue Aug 18 13:05:47.931755 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.36.136:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/zjggu.php"] [unique_id "aoSC201jzAhYHVVT1Wfy5QAAAVM"] [Tue Aug 18 13:05:47.969956 2026] [security2:error] [pid 157386:tid 157580] [client 20.250.13.23:22892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/96i.php"] [unique_id "aoSC201jzAhYHVVT1Wfy5gAAAUo"] [Tue Aug 18 13:05:47.985672 2026] [security2:error] [pid 157386:tid 157535] [client 20.116.17.175:45250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/term.php"] [unique_id "aoSC201jzAhYHVVT1Wfy5wAAAR0"] [Tue Aug 18 13:05:48.034007 2026] [authz_core:error] [pid 157386:tid 157411] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:48.034301 2026] [authz_core:error] [pid 157386:tid 157411] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:48.058174 2026] [security2:error] [pid 157386:tid 157595] [client 20.1.169.243:15948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/id3/about.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy6wAAAVk"] [Tue Aug 18 13:05:48.080027 2026] [security2:error] [pid 157386:tid 157529] [client 68.155.154.236:14297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy7AAAARc"] [Tue Aug 18 13:05:48.081487 2026] [security2:error] [pid 157386:tid 157637] [client 20.171.51.14:44909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/fb.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy7QAAAYM"] [Tue Aug 18 13:05:48.084122 2026] [security2:error] [pid 157386:tid 157550] [client 40.74.65.169:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/Njima.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy7wAAASw"] [Tue Aug 18 13:05:48.113308 2026] [security2:error] [pid 157386:tid 157548] [client 20.104.100.201:54034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/12.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy8gAAASo"] [Tue Aug 18 13:05:48.118758 2026] [security2:error] [pid 157386:tid 157563] [client 213.35.127.232:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy8wAAATk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:48.144157 2026] [security2:error] [pid 157386:tid 157584] [client 5.161.113.195:45474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.autocred360.com.br"] [uri "/index.php"] [unique_id "aoSC201jzAhYHVVT1WfygAAAAU4"], referer: https://www.autocred360.com.br [Tue Aug 18 13:05:48.144826 2026] [security2:error] [pid 157386:tid 157575] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/conf.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy9AAAAUU"] [Tue Aug 18 13:05:48.167301 2026] [security2:error] [pid 157386:tid 157517] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy9gAAAQs"] [Tue Aug 18 13:05:48.191751 2026] [security2:error] [pid 157386:tid 157638] [client 40.74.65.169:1818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/8.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy-QAAAYQ"] [Tue Aug 18 13:05:48.192652 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.49.167:2686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/apreset.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy-gAAAQ8"] [Tue Aug 18 13:05:48.204350 2026] [security2:error] [pid 157386:tid 157578] [client 20.25.139.174:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy_AAAAUg"] [Tue Aug 18 13:05:48.233258 2026] [security2:error] [pid 157386:tid 157537] [client 158.23.17.4:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fs.php"] [unique_id "aoSC3E1jzAhYHVVT1Wfy_gAAAR8"] [Tue Aug 18 13:05:48.238472 2026] [security2:error] [pid 157386:tid 157493] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSC3E1jzAhYHVVT1Wfy_wABXGo"] [Tue Aug 18 13:05:48.251549 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kl.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzAAAAAXY"] [Tue Aug 18 13:05:48.262854 2026] [security2:error] [pid 157386:tid 157526] [client 20.250.13.23:43779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/abc.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzAQAAARQ"] [Tue Aug 18 13:05:48.268972 2026] [security2:error] [pid 157386:tid 157435] [remote 136.110.27.48:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.weishaupt.com.br"] [uri "/config.php.bak"] [unique_id "aoSC3E1jzAhYHVVT1WfzAgABazA"] [Tue Aug 18 13:05:48.348804 2026] [security2:error] [pid 157386:tid 157581] [client 20.151.109.219:21305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/uq.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzCAAAAUs"] [Tue Aug 18 13:05:48.349302 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:48.349573 2026] [authz_core:error] [pid 157386:tid 157509] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:48.371219 2026] [security2:error] [pid 157386:tid 157560] [client 20.203.183.135:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/wpxml.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzCgAAATY"] [Tue Aug 18 13:05:48.381259 2026] [security2:error] [pid 157386:tid 157552] [client 20.116.17.175:45283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/black.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzCwAAAS4"] [Tue Aug 18 13:05:48.388427 2026] [security2:error] [pid 157386:tid 157643] [client 20.25.139.174:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/bolt.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzDQAAAYk"] [Tue Aug 18 13:05:48.413255 2026] [security2:error] [pid 157386:tid 157623] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/bala.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzDwAAAXU"] [Tue Aug 18 13:05:48.415533 2026] [security2:error] [pid 157386:tid 157547] [client 68.155.154.236:14249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/.cache/x.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzEAAAASk"] [Tue Aug 18 13:05:48.428454 2026] [security2:error] [pid 157386:tid 157565] [client 20.1.169.243:15567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/id3/index.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzEQAAATs"] [Tue Aug 18 13:05:48.439733 2026] [security2:error] [pid 157386:tid 157591] [client 20.250.13.23:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/aaa.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzEgAAAVU"] [Tue Aug 18 13:05:48.479214 2026] [security2:error] [pid 157386:tid 157636] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/k.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzFQAAAYI"] [Tue Aug 18 13:05:48.540795 2026] [security2:error] [pid 157386:tid 157635] [client 20.118.133.132:48561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/uwu.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzFgAAAYE"] [Tue Aug 18 13:05:48.544317 2026] [security2:error] [pid 157386:tid 157568] [client 20.104.49.167:21889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/1mage.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzFwAAAT4"] [Tue Aug 18 13:05:48.608164 2026] [security2:error] [pid 157386:tid 157536] [client 20.104.100.201:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzHAAAAR4"] [Tue Aug 18 13:05:48.634348 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:48.634604 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:48.646531 2026] [security2:error] [pid 157386:tid 157621] [client 20.171.51.14:6652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gw.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzIAAAAXM"] [Tue Aug 18 13:05:48.660859 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:22572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/as.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzIQAAAXE"] [Tue Aug 18 13:05:48.666568 2026] [security2:error] [pid 157386:tid 157572] [client 20.151.109.219:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gs.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzIgAAAUI"] [Tue Aug 18 13:05:48.680564 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/222.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzJAAAASM"] [Tue Aug 18 13:05:48.736479 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.156.252:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/yj09.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzJwAAAV4"] [Tue Aug 18 13:05:48.755305 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/666.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzKAAAAX4"] [Tue Aug 18 13:05:48.781452 2026] [security2:error] [pid 157386:tid 157589] [client 40.74.65.169:41415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/BIBIL.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzKgAAAVM"] [Tue Aug 18 13:05:48.794123 2026] [security2:error] [pid 157386:tid 157640] [client 20.1.169.243:15946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/id3/min.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzLgAAAYY"] [Tue Aug 18 13:05:48.811712 2026] [security2:error] [pid 157386:tid 157599] [client 68.221.73.131:48253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/av.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzLwAAAV0"] [Tue Aug 18 13:05:48.813828 2026] [security2:error] [pid 157386:tid 157588] [client 168.62.48.100:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzMAAAAVI"] [Tue Aug 18 13:05:48.885682 2026] [security2:error] [pid 157386:tid 157538] [client 40.74.65.169:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/biufile.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzMwAAASA"] [Tue Aug 18 13:05:48.905247 2026] [security2:error] [pid 157386:tid 157574] [client 138.36.100.162:42826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzNQAAAUQ"] [Tue Aug 18 13:05:48.905390 2026] [security2:error] [pid 157386:tid 157574] [client 138.36.100.162:42826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzNQAAAUQ"] [Tue Aug 18 13:05:48.936100 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:48.936390 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:48.938965 2026] [security2:error] [pid 157386:tid 157527] [client 20.25.139.174:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/bthil.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzOQAAARU"] [Tue Aug 18 13:05:48.945792 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:17080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/ai.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzOgAAAU4"] [Tue Aug 18 13:05:48.946334 2026] [security2:error] [pid 157386:tid 157575] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/routes.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzOwAAAUU"] [Tue Aug 18 13:05:48.977425 2026] [security2:error] [pid 157386:tid 157521] [client 20.116.17.175:22586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/pucci.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzPwAAAQ8"] [Tue Aug 18 13:05:48.991163 2026] [security2:error] [pid 157386:tid 157604] [client 20.250.13.23:35549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/sf.php"] [unique_id "aoSC3E1jzAhYHVVT1WfzQgAAAWI"] [Tue Aug 18 13:05:49.024618 2026] [security2:error] [pid 157386:tid 157583] [client 20.104.100.201:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/x1da.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzRQAAAU0"] [Tue Aug 18 13:05:49.066210 2026] [security2:error] [pid 157386:tid 157622] [client 20.171.51.14:13417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/sw.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzRwAAAXQ"] [Tue Aug 18 13:05:49.075484 2026] [security2:error] [pid 157386:tid 157531] [client 52.173.121.69:56977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzSgAAARk"] [Tue Aug 18 13:05:49.116688 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/403.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzTgAAAVQ"] [Tue Aug 18 13:05:49.136621 2026] [security2:error] [pid 157386:tid 157580] [client 213.35.127.232:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzTwAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:49.149532 2026] [security2:error] [pid 157386:tid 157544] [client 20.127.136.245:28254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/inputs.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzUQAAASY"] [Tue Aug 18 13:05:49.154501 2026] [security2:error] [pid 157386:tid 157519] [client 20.250.13.23:42888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/as.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzUgAAAQ0"] [Tue Aug 18 13:05:49.195273 2026] [security2:error] [pid 157386:tid 157547] [client 68.155.156.252:49728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/scxy.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzVgAAASk"] [Tue Aug 18 13:05:49.210168 2026] [security2:error] [pid 157386:tid 157609] [client 20.104.49.167:26384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/imsc.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzVwAAAWc"] [Tue Aug 18 13:05:49.214366 2026] [security2:error] [pid 157386:tid 157585] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/php5.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzWAAAAU8"] [Tue Aug 18 13:05:49.242754 2026] [authz_core:error] [pid 157386:tid 157422] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:49.243218 2026] [authz_core:error] [pid 157386:tid 157422] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:49.258334 2026] [security2:error] [pid 157386:tid 157612] [client 158.23.17.4:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/rb.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzWwAAAWo"] [Tue Aug 18 13:05:49.289640 2026] [security2:error] [pid 157386:tid 157635] [client 20.1.169.243:15613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzXgAAAYE"] [Tue Aug 18 13:05:49.318624 2026] [security2:error] [pid 157386:tid 157642] [client 20.151.109.219:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/32.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzXwAAAYg"] [Tue Aug 18 13:05:49.382344 2026] [security2:error] [pid 157386:tid 157525] [client 20.203.183.135:56560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/file1221.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzYQAAARM"] [Tue Aug 18 13:05:49.404390 2026] [security2:error] [pid 157386:tid 157619] [client 20.171.51.14:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/sn.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzYwAAAXE"] [Tue Aug 18 13:05:49.410768 2026] [security2:error] [pid 157386:tid 157639] [client 20.104.100.201:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/mcs.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzZQAAAYU"] [Tue Aug 18 13:05:49.413778 2026] [security2:error] [pid 157386:tid 157626] [client 20.116.17.175:22631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wicked.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzZgAAAXg"] [Tue Aug 18 13:05:49.425583 2026] [security2:error] [pid 157386:tid 157526] [client 20.250.13.23:33555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/abcd.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzZwAAARQ"] [Tue Aug 18 13:05:49.428989 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.36.136:25113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/dlvqo.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzaAAAAXw"] [Tue Aug 18 13:05:49.474194 2026] [security2:error] [pid 157386:tid 157524] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/Black.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzbQAAARI"] [Tue Aug 18 13:05:49.483038 2026] [security2:error] [pid 157386:tid 157518] [client 40.74.65.169:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/too.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzbwAAAQw"] [Tue Aug 18 13:05:49.484963 2026] [security2:error] [pid 157386:tid 157599] [client 20.25.139.174:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/ws54.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzcAAAAV0"] [Tue Aug 18 13:05:49.490760 2026] [security2:error] [pid 157386:tid 157588] [client 20.206.73.37:31065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/file2.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzcQAAAVI"] [Tue Aug 18 13:05:49.538919 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:49.539181 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:49.560930 2026] [security2:error] [pid 157386:tid 157637] [client 40.74.65.169:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/coffexium.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzegAAAYM"] [Tue Aug 18 13:05:49.571055 2026] [cgid:error] [pid 157386:tid 157534] [client 20.25.139.174:4605] AH01265: stderr from /home3/cp39imobibrasil/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:05:49.616514 2026] [security2:error] [pid 157386:tid 157621] [client 20.250.13.23:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/chosen.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzfQAAAXM"] [Tue Aug 18 13:05:49.635453 2026] [security2:error] [pid 157386:tid 157521] [client 20.206.73.37:17075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/sf.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzfgAAAQ8"] [Tue Aug 18 13:05:49.635593 2026] [security2:error] [pid 157386:tid 157601] [client 4.223.113.180:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzgAAAAV8"] [Tue Aug 18 13:05:49.637766 2026] [security2:error] [pid 157386:tid 157408] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzfwABeRU"] [Tue Aug 18 13:05:49.637915 2026] [security2:error] [pid 157386:tid 157627] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzfwABeRU"] [Tue Aug 18 13:05:49.650342 2026] [security2:error] [pid 157386:tid 157620] [client 52.173.121.69:37693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzggAAAXI"] [Tue Aug 18 13:05:49.663570 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ixr/min.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzhQAAAYA"] [Tue Aug 18 13:05:49.671831 2026] [security2:error] [pid 157386:tid 157631] [client 20.104.49.167:2668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/imscjpg.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzhwAAAX0"] [Tue Aug 18 13:05:49.721801 2026] [security2:error] [pid 157386:tid 157562] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/gecko.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzigAAATg"] [Tue Aug 18 13:05:49.729980 2026] [security2:error] [pid 157386:tid 157622] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/filesystems.php"] [unique_id "aoSC3U1jzAhYHVVT1WfziwAAAXQ"] [Tue Aug 18 13:05:49.733056 2026] [security2:error] [pid 157386:tid 157629] [client 20.25.139.174:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/x.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzjQAAAXs"] [Tue Aug 18 13:05:49.740939 2026] [security2:error] [pid 157386:tid 157530] [client 68.155.156.252:5203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzjgAAARg"] [Tue Aug 18 13:05:49.743514 2026] [security2:error] [pid 157386:tid 157548] [client 20.116.17.175:22601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/water.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzjwAAASo"] [Tue Aug 18 13:05:49.752640 2026] [security2:error] [pid 157386:tid 157531] [client 20.206.73.37:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/puc.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzkAAAARk"] [Tue Aug 18 13:05:49.754298 2026] [security2:error] [pid 157386:tid 157595] [client 20.127.136.245:28109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/admin.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzkQAAAVk"] [Tue Aug 18 13:05:49.783928 2026] [security2:error] [pid 157386:tid 157628] [client 34.38.184.238:50004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC3U1jzAhYHVVT1WfzlAAAAXo"] [Tue Aug 18 13:05:49.783929 2026] [security2:error] [pid 157386:tid 157553] [client 34.38.184.238:49942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC3U1jzAhYHVVT1WfzlQAAAS8"] [Tue Aug 18 13:05:49.784286 2026] [security2:error] [pid 157386:tid 157624] [client 34.38.184.238:50048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/iam/security-credentials/"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC3U1jzAhYHVVT1WfzkwAAAXY"] [Tue Aug 18 13:05:49.785486 2026] [security2:error] [pid 157386:tid 157590] [client 20.171.51.14:47131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gc.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzlwAAAVQ"] [Tue Aug 18 13:05:49.840529 2026] [authz_core:error] [pid 157386:tid 157391] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:49.840835 2026] [authz_core:error] [pid 157386:tid 157391] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:49.937428 2026] [security2:error] [pid 157386:tid 157633] [client 74.248.130.103:35007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/cabs.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzoQAAAX8"] [Tue Aug 18 13:05:49.967951 2026] [security2:error] [pid 157386:tid 157532] [client 20.226.36.136:23223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/pkmoj.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzpAAAARo"] [Tue Aug 18 13:05:49.986570 2026] [security2:error] [pid 157386:tid 157534] [client 20.151.109.219:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lw.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzpgAAARw"] [Tue Aug 18 13:05:49.989848 2026] [security2:error] [pid 157386:tid 157538] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSC3U1jzAhYHVVT1WfzpwAAASA"] [Tue Aug 18 13:05:50.036605 2026] [security2:error] [pid 157386:tid 157577] [client 20.1.169.243:15593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ixr/wp-login.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzrAAAAUc"] [Tue Aug 18 13:05:50.056864 2026] [security2:error] [pid 157386:tid 157611] [client 20.25.139.174:4671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzrQAAAWk"] [Tue Aug 18 13:05:50.065783 2026] [security2:error] [pid 157386:tid 157575] [client 20.118.133.132:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/signon.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzrgAAAUU"] [Tue Aug 18 13:05:50.073704 2026] [security2:error] [pid 157386:tid 157517] [client 20.203.183.135:61304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/nox.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzrwAAAQs"] [Tue Aug 18 13:05:50.087454 2026] [security2:error] [pid 157386:tid 157549] [client 103.120.71.157:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzsQAAASs"] [Tue Aug 18 13:05:50.087569 2026] [security2:error] [pid 157386:tid 157549] [client 103.120.71.157:51342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzsQAAASs"] [Tue Aug 18 13:05:50.092886 2026] [security2:error] [pid 157386:tid 157601] [client 20.104.49.167:41773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/qlex1.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzsgAAAV8"] [Tue Aug 18 13:05:50.099178 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:45261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fine.php"] [unique_id "aoSC3k1jzAhYHVVT1WfztAAAAXk"] [Tue Aug 18 13:05:50.102211 2026] [security2:error] [pid 157386:tid 157521] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzsAABDxI"] [Tue Aug 18 13:05:50.126234 2026] [security2:error] [pid 157386:tid 157620] [client 52.173.121.69:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSC3k1jzAhYHVVT1WfztgAAAXI"] [Tue Aug 18 13:05:50.157840 2026] [security2:error] [pid 157386:tid 157544] [client 213.35.127.232:59444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzugAAASY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:50.176299 2026] [security2:error] [pid 157386:tid 157625] [client 40.74.65.169:41451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.nacionalautomoveissc.com.br"] [uri "/g3.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzuwAAAXc"] [Tue Aug 18 13:05:50.177169 2026] [security2:error] [pid 157386:tid 157540] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/aa.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzvAAAASI"] [Tue Aug 18 13:05:50.188252 2026] [security2:error] [pid 157386:tid 157543] [client 20.127.136.245:28102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/goods.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzvgAAASU"] [Tue Aug 18 13:05:50.255517 2026] [security2:error] [pid 157386:tid 157565] [client 213.202.253.4:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/userfuns.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzwAAAATs"], referer: www.google.com [Tue Aug 18 13:05:50.256270 2026] [security2:error] [pid 157386:tid 157531] [client 40.74.65.169:55176] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.marthaimenes.com"] [uri "/1.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzwQAAARk"] [Tue Aug 18 13:05:50.256402 2026] [security2:error] [pid 157386:tid 157531] [client 40.74.65.169:55176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/1.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzwQAAARk"] [Tue Aug 18 13:05:50.256467 2026] [security2:error] [pid 157386:tid 157595] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/phpstatus.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzwgAAAVk"] [Tue Aug 18 13:05:50.260747 2026] [security2:error] [pid 157386:tid 157528] [client 20.25.139.174:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/index/function.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzwwAAARY"] [Tue Aug 18 13:05:50.261648 2026] [security2:error] [pid 157386:tid 157584] [client 20.250.13.23:44071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/u.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzxAAAAU4"] [Tue Aug 18 13:05:50.276817 2026] [security2:error] [pid 157386:tid 157641] [client 158.23.17.4:48447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/37.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzxQAAAYc"] [Tue Aug 18 13:05:50.296248 2026] [security2:error] [pid 157386:tid 157553] [client 20.171.51.14:6600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/uq.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzyAAAAS8"] [Tue Aug 18 13:05:50.305003 2026] [authz_core:error] [pid 157386:tid 157394] [remote 57.141.22.42:59600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:50.305430 2026] [authz_core:error] [pid 157386:tid 157394] [remote 57.141.22.42:59600] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:50.308000 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vj.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzyQAAAXY"] [Tue Aug 18 13:05:50.337136 2026] [security2:error] [pid 157386:tid 157614] [client 20.171.51.14:30232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/43.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzygAAAWw"] [Tue Aug 18 13:05:50.387444 2026] [security2:error] [pid 157386:tid 157560] [client 68.155.156.252:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzzAAAATY"] [Tue Aug 18 13:05:50.409366 2026] [security2:error] [pid 157386:tid 157562] [client 20.250.13.23:40415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-good.php"] [unique_id "aoSC3k1jzAhYHVVT1WfzzgAAATg"] [Tue Aug 18 13:05:50.444107 2026] [security2:error] [pid 157386:tid 157630] [client 197.184.64.235:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz0AAAAXw"] [Tue Aug 18 13:05:50.444231 2026] [security2:error] [pid 157386:tid 157630] [client 197.184.64.235:42678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz0AAAAXw"] [Tue Aug 18 13:05:50.444570 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:50.444827 2026] [authz_core:error] [pid 157386:tid 157462] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:50.464404 2026] [security2:error] [pid 157386:tid 157547] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/0x.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz0gAAASk"] [Tue Aug 18 13:05:50.521597 2026] [security2:error] [pid 157386:tid 157554] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/del.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz0wAAATA"] [Tue Aug 18 13:05:50.530517 2026] [security2:error] [pid 157386:tid 157533] [client 20.1.169.243:15944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/min.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz1QAAARs"] [Tue Aug 18 13:05:50.560734 2026] [security2:error] [pid 157386:tid 157536] [client 20.226.36.136:23190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/kopyw.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz2AAAAR4"] [Tue Aug 18 13:05:50.560945 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/73.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz2QAAAVE"] [Tue Aug 18 13:05:50.574093 2026] [security2:error] [pid 157386:tid 157571] [client 74.248.130.103:42010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/insc.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz2gAAAUE"] [Tue Aug 18 13:05:50.619595 2026] [security2:error] [pid 157386:tid 157609] [client 20.25.139.174:4732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/function/function.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz2wAAAWc"] [Tue Aug 18 13:05:50.642160 2026] [security2:error] [pid 157386:tid 157639] [client 52.173.121.69:53213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz3AAAAYU"] [Tue Aug 18 13:05:50.681786 2026] [security2:error] [pid 157386:tid 157535] [client 20.104.49.167:12797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/mariju.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz3gAAAR0"] [Tue Aug 18 13:05:50.717098 2026] [security2:error] [pid 157386:tid 157518] [client 68.155.156.252:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/blurbs.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz4AAAAQw"] [Tue Aug 18 13:05:50.744933 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:50.745207 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:50.763051 2026] [security2:error] [pid 157386:tid 157602] [client 20.151.109.219:5336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mimes.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz5QAAAWA"] [Tue Aug 18 13:05:50.767332 2026] [security2:error] [pid 157386:tid 157550] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/zxz.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz5gAAASw"] [Tue Aug 18 13:05:50.771928 2026] [security2:error] [pid 157386:tid 157534] [client 20.116.17.175:22646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/loader.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz5wAAARw"] [Tue Aug 18 13:05:50.783434 2026] [security2:error] [pid 157386:tid 157573] [client 20.206.73.37:46916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/19.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz6AAAAUM"] [Tue Aug 18 13:05:50.785937 2026] [security2:error] [pid 157386:tid 157527] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/moderator.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz6QAAARU"] [Tue Aug 18 13:05:50.798039 2026] [security2:error] [pid 157386:tid 157611] [client 68.221.73.131:55913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz6gAAAWk"] [Tue Aug 18 13:05:50.816136 2026] [security2:error] [pid 157386:tid 157626] [client 20.25.139.174:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/aaa.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz6wAAAXg"] [Tue Aug 18 13:05:50.853946 2026] [security2:error] [pid 157386:tid 157539] [client 20.171.51.14:18659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/32.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz8AAAASE"] [Tue Aug 18 13:05:50.867783 2026] [security2:error] [pid 157386:tid 157596] [client 20.127.136.245:28276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/file.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz8gAAAVo"] [Tue Aug 18 13:05:50.898868 2026] [security2:error] [pid 157386:tid 157561] [client 20.1.169.243:15703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/plugins/data.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz9QAAATc"] [Tue Aug 18 13:05:50.916632 2026] [security2:error] [pid 157386:tid 157540] [client 34.38.184.238:50220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/backend/.env"] [unique_id "aoSC3k1jzAhYHVVT1Wfz9wAAASI"] [Tue Aug 18 13:05:50.919009 2026] [security2:error] [pid 157386:tid 157583] [client 34.38.184.238:50208] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env.swp"] [unique_id "aoSC3k1jzAhYHVVT1Wfz-gAAAU0"] [Tue Aug 18 13:05:50.942226 2026] [security2:error] [pid 157386:tid 157543] [client 34.38.184.238:50178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env.old"] [unique_id "aoSC3k1jzAhYHVVT1Wfz_AAAASU"] [Tue Aug 18 13:05:50.943702 2026] [security2:error] [pid 157386:tid 157629] [client 34.38.184.238:50172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env.backup"] [unique_id "aoSC3k1jzAhYHVVT1Wfz_QAAAXs"] [Tue Aug 18 13:05:50.944038 2026] [security2:error] [pid 157386:tid 157570] [client 40.74.65.169:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/coffee.php"] [unique_id "aoSC3k1jzAhYHVVT1Wfz_gAAAUA"] [Tue Aug 18 13:05:50.960076 2026] [security2:error] [pid 157386:tid 157566] [client 5.31.227.224:30427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1Wf0AAAAATw"] [Tue Aug 18 13:05:50.960171 2026] [security2:error] [pid 157386:tid 157566] [client 5.31.227.224:30427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC3k1jzAhYHVVT1Wf0AAAAATw"] [Tue Aug 18 13:05:50.972923 2026] [security2:error] [pid 157386:tid 157528] [client 34.38.184.238:50170] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env.bak"] [unique_id "aoSC3k1jzAhYHVVT1Wf0AQAAARY"] [Tue Aug 18 13:05:51.033048 2026] [security2:error] [pid 157386:tid 157590] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/infoinfo.php"] [unique_id "aoSC301jzAhYHVVT1Wf0AwAAAVQ"] [Tue Aug 18 13:05:51.047238 2026] [security2:error] [pid 157386:tid 157614] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/www.php"] [unique_id "aoSC301jzAhYHVVT1Wf0BQAAAWw"] [Tue Aug 18 13:05:51.056269 2026] [security2:error] [pid 157386:tid 157592] [client 68.155.156.252:42310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/bajah.php"] [unique_id "aoSC301jzAhYHVVT1Wf0BgAAAVY"] [Tue Aug 18 13:05:51.077886 2026] [security2:error] [pid 157386:tid 157643] [client 196.12.128.158:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC301jzAhYHVVT1Wf0CAAAAYk"] [Tue Aug 18 13:05:51.078014 2026] [security2:error] [pid 157386:tid 157643] [client 196.12.128.158:57726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC301jzAhYHVVT1Wf0CAAAAYk"] [Tue Aug 18 13:05:51.096654 2026] [security2:error] [pid 157386:tid 157608] [client 20.206.73.37:55354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSC301jzAhYHVVT1Wf0CgAAAWY"] [Tue Aug 18 13:05:51.139256 2026] [security2:error] [pid 157386:tid 157564] [client 34.38.184.238:49942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/api/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0DQAAATo"] [Tue Aug 18 13:05:51.157836 2026] [security2:error] [pid 157386:tid 157613] [client 20.25.139.174:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/nw.php"] [unique_id "aoSC301jzAhYHVVT1Wf0EwAAAWs"] [Tue Aug 18 13:05:51.161969 2026] [security2:error] [pid 157386:tid 157632] [client 20.250.13.23:35527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/customize.php"] [unique_id "aoSC301jzAhYHVVT1Wf0FAAAAX4"] [Tue Aug 18 13:05:51.167400 2026] [security2:error] [pid 157386:tid 157568] [client 20.203.183.135:56555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/akismet.php"] [unique_id "aoSC301jzAhYHVVT1Wf0FQAAAT4"] [Tue Aug 18 13:05:51.175747 2026] [security2:error] [pid 157386:tid 157517] [client 213.35.127.232:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSC301jzAhYHVVT1Wf0FgAAAQs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:51.190026 2026] [security2:error] [pid 157386:tid 157556] [client 20.151.109.219:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ni.php"] [unique_id "aoSC301jzAhYHVVT1Wf0GAAAATI"] [Tue Aug 18 13:05:51.196950 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.49.167:41729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSC301jzAhYHVVT1Wf0GQAAAXA"] [Tue Aug 18 13:05:51.214948 2026] [security2:error] [pid 157386:tid 157516] [client 74.248.130.103:40755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/file.php"] [unique_id "aoSC301jzAhYHVVT1Wf0GgAAAQo"] [Tue Aug 18 13:05:51.248349 2026] [security2:error] [pid 157386:tid 157536] [client 34.38.184.238:50148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/src/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0GwAAAR4"] [Tue Aug 18 13:05:51.251882 2026] [security2:error] [pid 157386:tid 157587] [client 52.173.121.69:37648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSC301jzAhYHVVT1Wf0HAAAAVE"] [Tue Aug 18 13:05:51.254500 2026] [security2:error] [pid 157386:tid 157571] [client 74.249.206.207:64559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC301jzAhYHVVT1Wf0HQAAAUE"] [Tue Aug 18 13:05:51.256037 2026] [security2:error] [pid 157386:tid 157525] [client 34.38.184.238:50232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/server/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0HgAAARM"] [Tue Aug 18 13:05:51.260473 2026] [security2:error] [pid 157386:tid 157582] [client 20.206.73.37:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/133.php"] [unique_id "aoSC301jzAhYHVVT1Wf0HwAAAUw"] [Tue Aug 18 13:05:51.271917 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/plugins/plugin-install.php"] [unique_id "aoSC301jzAhYHVVT1Wf0IAAAAYA"] [Tue Aug 18 13:05:51.279919 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/c99shell.php"] [unique_id "aoSC301jzAhYHVVT1Wf0IwAAASM"] [Tue Aug 18 13:05:51.307429 2026] [security2:error] [pid 157386:tid 157572] [client 168.62.48.100:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSC301jzAhYHVVT1Wf0JAAAAUI"] [Tue Aug 18 13:05:51.331860 2026] [security2:error] [pid 157386:tid 157633] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wicked.php"] [unique_id "aoSC301jzAhYHVVT1Wf0JQAAAX8"] [Tue Aug 18 13:05:51.335385 2026] [security2:error] [pid 157386:tid 157554] [client 20.25.139.174:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/abcd.php"] [unique_id "aoSC301jzAhYHVVT1Wf0JgAAATA"] [Tue Aug 18 13:05:51.338970 2026] [security2:error] [pid 157386:tid 157612] [client 20.127.136.245:28252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/adminfuns.php"] [unique_id "aoSC301jzAhYHVVT1Wf0JwAAAWo"] [Tue Aug 18 13:05:51.363558 2026] [security2:error] [pid 157386:tid 157594] [client 20.151.109.219:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ib.php"] [unique_id "aoSC301jzAhYHVVT1Wf0KQAAAVg"] [Tue Aug 18 13:05:51.526711 2026] [security2:error] [pid 157386:tid 157596] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/profiler.php"] [unique_id "aoSC301jzAhYHVVT1Wf0LwAAAVo"] [Tue Aug 18 13:05:51.585921 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:5347] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "app.hospitalhacos.org.br"] [uri "/1.php"] [unique_id "aoSC301jzAhYHVVT1Wf0MgAAATc"] [Tue Aug 18 13:05:51.586047 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:5347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/1.php"] [unique_id "aoSC301jzAhYHVVT1Wf0MgAAATc"] [Tue Aug 18 13:05:51.591533 2026] [security2:error] [pid 157386:tid 157557] [client 68.155.156.252:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/domvf.php"] [unique_id "aoSC301jzAhYHVVT1Wf0MwAAATM"] [Tue Aug 18 13:05:51.594688 2026] [security2:error] [pid 157386:tid 157598] [client 20.104.49.167:41781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/contacto.php"] [unique_id "aoSC301jzAhYHVVT1Wf0NAAAAVw"] [Tue Aug 18 13:05:51.619742 2026] [security2:error] [pid 157386:tid 157625] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSC301jzAhYHVVT1Wf0NQAAAXc"] [Tue Aug 18 13:05:51.628699 2026] [security2:error] [pid 157386:tid 157583] [client 40.74.65.169:51639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/classwithtostring.php"] [unique_id "aoSC301jzAhYHVVT1Wf0NgAAAU0"] [Tue Aug 18 13:05:51.641401 2026] [security2:error] [pid 157386:tid 157638] [client 20.1.169.243:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/plugins/users.php"] [unique_id "aoSC301jzAhYHVVT1Wf0NwAAAYQ"] [Tue Aug 18 13:05:51.646594 2026] [security2:error] [pid 157386:tid 157530] [client 52.173.121.69:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSC301jzAhYHVVT1Wf0OwAAARg"] [Tue Aug 18 13:05:51.650640 2026] [authz_core:error] [pid 157386:tid 157500] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:51.650900 2026] [authz_core:error] [pid 157386:tid 157500] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:51.686415 2026] [security2:error] [pid 157386:tid 157528] [client 20.116.17.175:22591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/zero.php"] [unique_id "aoSC301jzAhYHVVT1Wf0PgAAARY"] [Tue Aug 18 13:05:51.691201 2026] [security2:error] [pid 157386:tid 157584] [client 34.38.184.238:50248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/config/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0PwAAAU4"] [Tue Aug 18 13:05:51.704220 2026] [security2:error] [pid 157386:tid 157522] [client 20.25.139.174:4709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/xleet.php"] [unique_id "aoSC301jzAhYHVVT1Wf0QAAAARA"] [Tue Aug 18 13:05:51.717186 2026] [security2:error] [pid 157386:tid 157641] [client 74.249.206.207:45009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC301jzAhYHVVT1Wf0QQAAAYc"] [Tue Aug 18 13:05:51.774563 2026] [security2:error] [pid 157386:tid 157643] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/findes.php"] [unique_id "aoSC301jzAhYHVVT1Wf0QwAAAYk"] [Tue Aug 18 13:05:51.818875 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC301jzAhYHVVT1Wf0RwAAATo"] [Tue Aug 18 13:05:51.819796 2026] [security2:error] [pid 157386:tid 157532] [client 34.38.184.238:50282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/web/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0RgAAARo"] [Tue Aug 18 13:05:51.823895 2026] [security2:error] [pid 157386:tid 157545] [client 20.171.51.14:13426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/73.php"] [unique_id "aoSC301jzAhYHVVT1Wf0SAAAASc"] [Tue Aug 18 13:05:51.828011 2026] [security2:error] [pid 157386:tid 157585] [client 20.206.73.37:21065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/xx.php"] [unique_id "aoSC301jzAhYHVVT1Wf0SgAAAU8"] [Tue Aug 18 13:05:51.856136 2026] [security2:error] [pid 157386:tid 157640] [client 20.25.139.174:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-good.php"] [unique_id "aoSC301jzAhYHVVT1Wf0TAAAAYY"] [Tue Aug 18 13:05:51.858770 2026] [security2:error] [pid 157386:tid 157568] [client 34.38.184.238:50172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/back/.env"] [unique_id "aoSC301jzAhYHVVT1Wf0TQAAAT4"] [Tue Aug 18 13:05:51.874642 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/88.php"] [unique_id "aoSC301jzAhYHVVT1Wf0TgAAAXA"] [Tue Aug 18 13:05:51.883620 2026] [security2:error] [pid 157386:tid 157516] [client 74.248.130.103:7886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/dex.php"] [unique_id "aoSC301jzAhYHVVT1Wf0TwAAAQo"] [Tue Aug 18 13:05:51.905433 2026] [security2:error] [pid 157386:tid 157634] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSC301jzAhYHVVT1Wf0UQAAAYA"] [Tue Aug 18 13:05:51.928717 2026] [security2:error] [pid 157386:tid 157541] [client 68.155.156.252:21739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/fpwch.php"] [unique_id "aoSC301jzAhYHVVT1Wf0VQAAASM"] [Tue Aug 18 13:05:51.953510 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:51.953985 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:51.982610 2026] [security2:error] [pid 157386:tid 157546] [client 85.208.98.23:49212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSC301jzAhYHVVT1Wf0WgAAASg"] [Tue Aug 18 13:05:51.982674 2026] [security2:error] [pid 157386:tid 157588] [client 20.104.49.167:2657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/image2.php"] [unique_id "aoSC301jzAhYHVVT1Wf0WQAAAVI"] [Tue Aug 18 13:05:51.982700 2026] [security2:error] [pid 157386:tid 157546] [client 85.208.98.23:49212] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSC301jzAhYHVVT1Wf0WgAAASg"] [Tue Aug 18 13:05:51.986306 2026] [security2:error] [pid 157386:tid 157550] [client 20.104.100.201:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/png.php"] [unique_id "aoSC301jzAhYHVVT1Wf0WwAAASw"] [Tue Aug 18 13:05:51.995429 2026] [security2:error] [pid 157386:tid 157534] [client 20.250.13.23:43828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/mah/function.php"] [unique_id "aoSC301jzAhYHVVT1Wf0XQAAARw"] [Tue Aug 18 13:05:52.001749 2026] [security2:error] [pid 157386:tid 157573] [client 20.203.183.135:34577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/admin.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0YQAAAUM"] [Tue Aug 18 13:05:52.026318 2026] [security2:error] [pid 157386:tid 157575] [client 34.38.184.238:50250] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/public/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ZAAAAUU"] [Tue Aug 18 13:05:52.029855 2026] [security2:error] [pid 157386:tid 157621] [client 34.38.184.238:50266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.aws/credentials.old"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ZQAAAXM"] [Tue Aug 18 13:05:52.037688 2026] [security2:error] [pid 157386:tid 157549] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/fedora.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ZgAAASs"] [Tue Aug 18 13:05:52.071530 2026] [security2:error] [pid 157386:tid 157578] [client 68.221.73.131:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ZwAAAUg"] [Tue Aug 18 13:05:52.075955 2026] [security2:error] [pid 157386:tid 157620] [client 34.38.184.238:50314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.aws/credentials.bak"] [unique_id "aoSC4E1jzAhYHVVT1Wf0aQAAAXI"] [Tue Aug 18 13:05:52.109110 2026] [security2:error] [pid 157386:tid 157625] [client 74.249.206.207:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/media.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0bwAAAXc"] [Tue Aug 18 13:05:52.129966 2026] [security2:error] [pid 157386:tid 157530] [client 34.38.184.238:50536] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/@fs/root/.aws/config"] [unique_id "aoSC4E1jzAhYHVVT1Wf0cQAAARg"] [Tue Aug 18 13:05:52.131134 2026] [security2:error] [pid 157386:tid 157589] [client 34.38.184.238:50430] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/home/ec2-user/.aws/credentials"] [unique_id "aoSC4E1jzAhYHVVT1Wf0dQAAAVM"] [Tue Aug 18 13:05:52.133464 2026] [security2:error] [pid 157386:tid 157629] [client 34.38.184.238:50498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/files../.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0cgAAAXs"] [Tue Aug 18 13:05:52.134149 2026] [security2:error] [pid 157386:tid 157529] [client 34.38.184.238:50450] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/_next/../.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0fgAAARc"] [Tue Aug 18 13:05:52.134598 2026] [core:error] [pid 157386:tid 157624] [client 34.38.184.238:50456] AH10244: invalid URI path (/assets../../../.env) [Tue Aug 18 13:05:52.135066 2026] [security2:error] [pid 157386:tid 157590] [client 34.38.184.238:50444] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC4E1jzAhYHVVT1Wf0gQAAAVQ"] [Tue Aug 18 13:05:52.135690 2026] [security2:error] [pid 157386:tid 157580] [client 34.38.184.238:50354] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.vercel/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0hAAAAUo"] [Tue Aug 18 13:05:52.136419 2026] [security2:error] [pid 157386:tid 157581] [client 34.38.184.238:50286] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/apps/api/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0hwAAAUs"] [Tue Aug 18 13:05:52.136646 2026] [security2:error] [pid 157386:tid 157553] [client 34.38.184.238:50406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/_next/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0fwAAAS8"] [Tue Aug 18 13:05:52.137355 2026] [security2:error] [pid 157386:tid 157608] [client 34.38.184.238:50368] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4E1jzAhYHVVT1Wf0igAAAWY"] [Tue Aug 18 13:05:52.137614 2026] [security2:error] [pid 157386:tid 157592] [client 34.38.184.238:50460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/@fs/root/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0gwAAAVY"] [Tue Aug 18 13:05:52.138156 2026] [security2:error] [pid 157386:tid 157544] [client 34.38.184.238:50338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/core/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0iQAAASY"] [Tue Aug 18 13:05:52.138542 2026] [security2:error] [pid 157386:tid 157519] [client 34.38.184.238:50404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/@fs/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0hgAAAQ0"] [Tue Aug 18 13:05:52.138815 2026] [security2:error] [pid 157386:tid 157560] [client 34.38.184.238:50386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/@fs/app/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0hQAAATY"] [Tue Aug 18 13:05:52.145988 2026] [security2:error] [pid 157386:tid 157569] [client 20.1.169.243:15960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/config.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0iwAAAT8"] [Tue Aug 18 13:05:52.157312 2026] [security2:error] [pid 157386:tid 157623] [client 158.23.17.4:46791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/md.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0jAAAAXU"] [Tue Aug 18 13:05:52.169487 2026] [security2:error] [pid 157386:tid 157611] [client 37.40.227.74:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0jwAAAWk"] [Tue Aug 18 13:05:52.169591 2026] [security2:error] [pid 157386:tid 157611] [client 37.40.227.74:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0jwAAAWk"] [Tue Aug 18 13:05:52.170831 2026] [security2:error] [pid 157386:tid 157554] [client 51.68.107.141:33747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vindimo.com.br"] [uri "/robots.txt"] [unique_id "aoSC4E1jzAhYHVVT1Wf0kAAAATA"] [Tue Aug 18 13:05:52.170980 2026] [security2:error] [pid 157386:tid 157554] [client 51.68.107.141:33747] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vindimo.com.br"] [uri "/robots.txt"] [unique_id "aoSC4E1jzAhYHVVT1Wf0kAAAATA"] [Tue Aug 18 13:05:52.188584 2026] [security2:error] [pid 157386:tid 157547] [client 34.38.184.238:50004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.github/.env"] [unique_id "aoSC4E1jzAhYHVVT1Wf0kwAAASk"] [Tue Aug 18 13:05:52.200018 2026] [security2:error] [pid 157386:tid 157538] [client 20.226.36.136:25110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/zznmg.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0lwAAASA"] [Tue Aug 18 13:05:52.200886 2026] [security2:error] [pid 157386:tid 157537] [client 213.35.127.232:59929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0mAAAAR8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:52.207589 2026] [security2:error] [pid 157386:tid 157601] [client 20.25.139.174:4296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0mQAAAV8"] [Tue Aug 18 13:05:52.216789 2026] [security2:error] [pid 157386:tid 157526] [client 20.127.136.245:28106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/404.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0mgAAARQ"] [Tue Aug 18 13:05:52.253159 2026] [security2:error] [pid 157386:tid 157618] [client 34.38.184.238:50220] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4E1jzAhYHVVT1Wf0oQAAAXA"] [Tue Aug 18 13:05:52.255653 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:52.256095 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:52.264105 2026] [security2:error] [pid 157386:tid 157571] [client 20.104.100.201:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/adminner.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0owAAAUE"] [Tue Aug 18 13:05:52.264191 2026] [security2:error] [pid 157386:tid 157587] [client 52.173.121.69:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ogAAAVE"] [Tue Aug 18 13:05:52.299057 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/path.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0pQAAASM"] [Tue Aug 18 13:05:52.299855 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/cah.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0pgAAAUI"] [Tue Aug 18 13:05:52.301829 2026] [security2:error] [pid 157386:tid 157599] [client 20.151.109.219:46431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/hj.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0pwAAAV0"] [Tue Aug 18 13:05:52.311807 2026] [security2:error] [pid 157386:tid 157535] [client 40.74.65.169:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/wp-ws68.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0qAAAAR0"] [Tue Aug 18 13:05:52.314971 2026] [security2:error] [pid 157386:tid 157612] [client 34.38.184.238:50186] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.cursor/mcp.json"] [unique_id "aoSC4E1jzAhYHVVT1Wf0qQAAAWo"] [Tue Aug 18 13:05:52.316999 2026] [security2:error] [pid 157386:tid 157543] [client 20.38.3.247:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/222.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0rAAAASU"] [Tue Aug 18 13:05:52.331213 2026] [security2:error] [pid 157386:tid 157588] [client 34.38.184.238:50208] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4E1jzAhYHVVT1Wf0rgAAAVI"] [Tue Aug 18 13:05:52.373574 2026] [security2:error] [pid 157386:tid 157577] [client 34.38.184.238:50562] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4E1jzAhYHVVT1Wf0sQAAAUc"] [Tue Aug 18 13:05:52.378600 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/simple.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0swAAAX4"] [Tue Aug 18 13:05:52.399425 2026] [security2:error] [pid 157386:tid 157621] [client 68.155.156.252:5243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/adminner.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0tQAAAXM"] [Tue Aug 18 13:05:52.418353 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.49.167:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/fb.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0twAAAVs"] [Tue Aug 18 13:05:52.475044 2026] [security2:error] [pid 157386:tid 157596] [client 20.171.51.14:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ib.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ugAAAVo"] [Tue Aug 18 13:05:52.490525 2026] [security2:error] [pid 157386:tid 157524] [client 4.223.113.180:42747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/OK.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0vAAAARI"] [Tue Aug 18 13:05:52.498150 2026] [security2:error] [pid 157386:tid 157539] [client 20.206.73.37:2175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/uwu.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0vQAAASE"] [Tue Aug 18 13:05:52.501006 2026] [security2:error] [pid 157386:tid 157566] [client 223.185.37.47:23645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0vgAAATw"] [Tue Aug 18 13:05:52.501101 2026] [security2:error] [pid 157386:tid 157566] [client 223.185.37.47:23645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0vgAAATw"] [Tue Aug 18 13:05:52.513588 2026] [security2:error] [pid 157386:tid 157582] [client 20.1.169.243:15615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/db-status.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0vwAAAUw"] [Tue Aug 18 13:05:52.540787 2026] [security2:error] [pid 157386:tid 157629] [client 20.203.183.135:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uni.numem.com.br"] [uri "/ajax.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0wAAAAXs"] [Tue Aug 18 13:05:52.541527 2026] [security2:error] [pid 157386:tid 157636] [client 102.213.179.104:49388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0wQAAAYI"] [Tue Aug 18 13:05:52.541636 2026] [security2:error] [pid 157386:tid 157636] [client 102.213.179.104:49388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0wQAAAYI"] [Tue Aug 18 13:05:52.546788 2026] [security2:error] [pid 157386:tid 157608] [client 20.118.133.132:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/file61.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0wwAAAWY"] [Tue Aug 18 13:05:52.551347 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:52.551631 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:52.567651 2026] [security2:error] [pid 157386:tid 157565] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/456.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0xQAAATs"] [Tue Aug 18 13:05:52.587399 2026] [security2:error] [pid 157386:tid 157560] [client 74.249.206.207:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/admin.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0xwAAATY"] [Tue Aug 18 13:05:52.651099 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.36.136:41536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/bhfnd.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0ywAAAX0"] [Tue Aug 18 13:05:52.702801 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:49291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ij.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0zAAAAXQ"] [Tue Aug 18 13:05:52.722898 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0zgAAASA"] [Tue Aug 18 13:05:52.726406 2026] [security2:error] [pid 157386:tid 157563] [client 20.250.13.23:44046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/filter.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf0zwAAATk"] [Tue Aug 18 13:05:52.726825 2026] [security2:error] [pid 157386:tid 157530] [client 20.127.136.245:28099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wk/index.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf00AAAARg"] [Tue Aug 18 13:05:52.742031 2026] [security2:error] [pid 157386:tid 157519] [client 20.25.139.174:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/155.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf00wAAAQ0"] [Tue Aug 18 13:05:52.763795 2026] [security2:error] [pid 157386:tid 157533] [client 20.215.241.237:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf01gAAARs"] [Tue Aug 18 13:05:52.767634 2026] [security2:error] [pid 157386:tid 157516] [client 158.23.17.4:20466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/iy.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf01wAAAQo"] [Tue Aug 18 13:05:52.768427 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/system_log.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf02AAAAXA"] [Tue Aug 18 13:05:52.811882 2026] [security2:error] [pid 157386:tid 157619] [client 20.206.73.37:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/1xmomo.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf02wAAAXE"] [Tue Aug 18 13:05:52.812462 2026] [security2:error] [pid 157386:tid 157576] [client 68.155.156.252:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/abcd.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf03AAAAUY"] [Tue Aug 18 13:05:52.831531 2026] [security2:error] [pid 157386:tid 157615] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/SMTP.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf03gAAAW0"] [Tue Aug 18 13:05:52.838993 2026] [security2:error] [pid 157386:tid 157567] [client 20.226.36.136:25106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/qfvqu.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf03wAAAT0"] [Tue Aug 18 13:05:52.839578 2026] [security2:error] [pid 157386:tid 157564] [client 20.116.17.175:22532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/002.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf04AAAATo"] [Tue Aug 18 13:05:52.851617 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:52.851902 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:52.861234 2026] [security2:error] [pid 157386:tid 157535] [client 20.104.100.201:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/dragonshell.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf04gAAAR0"] [Tue Aug 18 13:05:52.891509 2026] [security2:error] [pid 157386:tid 157545] [client 20.25.139.174:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/edit-tags.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf04wAAASc"] [Tue Aug 18 13:05:52.926042 2026] [security2:error] [pid 157386:tid 157588] [client 20.104.49.167:48575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/gi.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf05wAAAVI"] [Tue Aug 18 13:05:52.960695 2026] [security2:error] [pid 157386:tid 157633] [client 20.206.73.37:15734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/signon.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf06AAAAX8"] [Tue Aug 18 13:05:52.981190 2026] [security2:error] [pid 157386:tid 157632] [client 74.249.206.207:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/mac.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf06QAAAX4"] [Tue Aug 18 13:05:52.989199 2026] [security2:error] [pid 157386:tid 157559] [client 40.74.65.169:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/yj09.php"] [unique_id "aoSC4E1jzAhYHVVT1Wf06gAAATU"] [Tue Aug 18 13:05:53.035082 2026] [security2:error] [pid 157386:tid 157617] [client 20.1.169.243:15969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf07AAAAW8"] [Tue Aug 18 13:05:53.090932 2026] [security2:error] [pid 157386:tid 157638] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/vbseo.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf07wAAAYQ"] [Tue Aug 18 13:05:53.113198 2026] [security2:error] [pid 157386:tid 157589] [client 20.171.51.14:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/fresh.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf09AAAAVM"] [Tue Aug 18 13:05:53.139814 2026] [security2:error] [pid 157386:tid 157629] [client 20.226.36.136:41486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/oivcl.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf09QAAAXs"] [Tue Aug 18 13:05:53.153384 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:53.153663 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:53.153698 2026] [security2:error] [pid 157386:tid 157553] [client 20.151.109.219:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ud.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf09wAAAS8"] [Tue Aug 18 13:05:53.180994 2026] [security2:error] [pid 157386:tid 157565] [client 20.171.51.14:33194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xm.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf0-gAAATs"] [Tue Aug 18 13:05:53.226169 2026] [security2:error] [pid 157386:tid 157623] [client 34.38.184.238:50414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/download"] [unique_id "aoSC4U1jzAhYHVVT1Wf1AAAAAXU"] [Tue Aug 18 13:05:53.227193 2026] [security2:error] [pid 157386:tid 157552] [client 34.38.184.238:50488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/read"] [unique_id "aoSC4U1jzAhYHVVT1Wf1AwAAAS4"] [Tue Aug 18 13:05:53.227687 2026] [security2:error] [pid 157386:tid 157598] [client 34.38.184.238:50472] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/file"] [unique_id "aoSC4U1jzAhYHVVT1Wf1BgAAAVw"] [Tue Aug 18 13:05:53.228041 2026] [security2:error] [pid 157386:tid 157554] [client 34.38.184.238:50332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/"] [unique_id "aoSC4U1jzAhYHVVT1Wf1BQAAATA"] [Tue Aug 18 13:05:53.228238 2026] [security2:error] [pid 157386:tid 157613] [client 213.35.127.232:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1CAAAAWs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:53.228363 2026] [security2:error] [pid 157386:tid 157574] [client 34.38.184.238:50316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/download"] [unique_id "aoSC4U1jzAhYHVVT1Wf1AQAAAUQ"] [Tue Aug 18 13:05:53.229218 2026] [security2:error] [pid 157386:tid 157622] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1CQAAAXQ"] [Tue Aug 18 13:05:53.229796 2026] [security2:error] [pid 157386:tid 157611] [client 34.38.184.238:50508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/read?url=file:///proc/1/environ"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/read"] [unique_id "aoSC4U1jzAhYHVVT1Wf1BAAAAWk"] [Tue Aug 18 13:05:53.229805 2026] [security2:error] [pid 157386:tid 157600] [client 20.25.139.174:4712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/96i.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1CgAAAV4"] [Tue Aug 18 13:05:53.230191 2026] [security2:error] [pid 157386:tid 157547] [client 34.38.184.238:50404] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4U1jzAhYHVVT1Wf1BwAAASk"] [Tue Aug 18 13:05:53.252813 2026] [security2:error] [pid 157386:tid 157563] [client 68.155.156.252:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/simple.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1DAAAATk"] [Tue Aug 18 13:05:53.273384 2026] [security2:error] [pid 157386:tid 157530] [client 20.151.109.219:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/dirs.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1DQAAARg"] [Tue Aug 18 13:05:53.276672 2026] [security2:error] [pid 157386:tid 157537] [client 20.104.49.167:48528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/video.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1DgAAAR8"] [Tue Aug 18 13:05:53.286767 2026] [security2:error] [pid 157386:tid 157579] [client 34.38.184.238:50460] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4U1jzAhYHVVT1Wf1EAAAAUk"] [Tue Aug 18 13:05:53.293065 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:50498] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/actuator/logfile"] [unique_id "aoSC4U1jzAhYHVVT1Wf1EQAAARs"] [Tue Aug 18 13:05:53.307363 2026] [security2:error] [pid 157386:tid 157536] [client 34.38.184.238:50048] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC4U1jzAhYHVVT1Wf1EwAAAR4"] [Tue Aug 18 13:05:53.308898 2026] [security2:error] [pid 157386:tid 157618] [client 34.38.184.238:49942] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC4U1jzAhYHVVT1Wf1EgAAAXA"] [Tue Aug 18 13:05:53.340533 2026] [security2:error] [pid 157386:tid 157615] [client 52.173.121.69:57728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1FAAAAW0"] [Tue Aug 18 13:05:53.341429 2026] [security2:error] [pid 157386:tid 157590] [client 20.250.13.23:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/input.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1FQAAAVQ"] [Tue Aug 18 13:05:53.362201 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xm.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1FwAAAT0"] [Tue Aug 18 13:05:53.366630 2026] [security2:error] [pid 157386:tid 157520] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/sysinfo.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1GAAAAQ4"] [Tue Aug 18 13:05:53.375170 2026] [security2:error] [pid 157386:tid 157639] [client 20.226.36.136:41590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/zugvi.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1GwAAAYU"] [Tue Aug 18 13:05:53.379039 2026] [security2:error] [pid 157386:tid 157569] [client 20.25.139.174:4297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/u.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1HAAAAT8"] [Tue Aug 18 13:05:53.399960 2026] [security2:error] [pid 157386:tid 157604] [client 20.1.169.243:15724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1HgAAAWI"] [Tue Aug 18 13:05:53.417692 2026] [security2:error] [pid 157386:tid 157577] [client 68.221.73.131:26487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-blog.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1IQAAAUc"] [Tue Aug 18 13:05:53.445229 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:50441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ip.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1IgAAAWE"] [Tue Aug 18 13:05:53.455787 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:53.456059 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:53.493081 2026] [security2:error] [pid 157386:tid 157593] [client 20.104.100.201:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/setup-config.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1JQAAAVc"] [Tue Aug 18 13:05:53.529538 2026] [security2:error] [pid 157386:tid 157638] [client 20.215.241.237:18461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1KAAAAYQ"] [Tue Aug 18 13:05:53.555014 2026] [security2:error] [pid 157386:tid 157546] [client 34.38.184.238:50562] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/redirect"] [unique_id "aoSC4U1jzAhYHVVT1Wf1KQAAASg"] [Tue Aug 18 13:05:53.555317 2026] [security2:error] [pid 157386:tid 157539] [client 4.223.113.180:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/config.php7"] [unique_id "aoSC4U1jzAhYHVVT1Wf1KgAAASE"] [Tue Aug 18 13:05:53.586758 2026] [security2:error] [pid 157386:tid 157566] [client 20.104.49.167:2731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/hel.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1LQAAATw"] [Tue Aug 18 13:05:53.591115 2026] [security2:error] [pid 157386:tid 157580] [client 68.155.156.252:26914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/wp-manager.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1LgAAAUo"] [Tue Aug 18 13:05:53.598178 2026] [security2:error] [pid 157386:tid 157629] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1LwAAAXs"] [Tue Aug 18 13:05:53.617282 2026] [security2:error] [pid 157386:tid 157553] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/ppinfo.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1MQAAAS8"] [Tue Aug 18 13:05:53.644119 2026] [security2:error] [pid 157386:tid 157592] [client 74.249.206.207:64569] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/1.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1MgAAAVY"] [Tue Aug 18 13:05:53.644279 2026] [security2:error] [pid 157386:tid 157592] [client 74.249.206.207:64569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/1.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1MgAAAVY"] [Tue Aug 18 13:05:53.664602 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wsrer.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1NQAAARk"] [Tue Aug 18 13:05:53.669471 2026] [security2:error] [pid 157386:tid 157528] [client 86.120.159.145:20667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1NAAAARY"] [Tue Aug 18 13:05:53.669605 2026] [security2:error] [pid 157386:tid 157528] [client 86.120.159.145:20667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1NAAAARY"] [Tue Aug 18 13:05:53.683799 2026] [security2:error] [pid 157386:tid 157560] [client 40.74.65.169:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/scxy.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1NgAAATY"] [Tue Aug 18 13:05:53.694955 2026] [security2:error] [pid 157386:tid 157598] [client 74.248.130.103:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/key.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1NwAAAVw"] [Tue Aug 18 13:05:53.733343 2026] [security2:error] [pid 157386:tid 157613] [client 20.226.36.136:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/ucpfr.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1OgAAAWs"] [Tue Aug 18 13:05:53.755634 2026] [security2:error] [pid 157386:tid 157624] [client 20.25.139.174:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/as.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1PAAAAXY"] [Tue Aug 18 13:05:53.775766 2026] [security2:error] [pid 157386:tid 157565] [client 20.1.169.243:15681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/tinymce/themes/xmlrpc.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1PQAAATs"] [Tue Aug 18 13:05:53.780343 2026] [security2:error] [pid 157386:tid 157597] [client 20.127.136.245:28116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/about.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1PgAAAVs"] [Tue Aug 18 13:05:53.817064 2026] [security2:error] [pid 157386:tid 157576] [client 158.23.17.4:20379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/og.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1QAAAAUY"] [Tue Aug 18 13:05:53.842867 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/zy.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1QgAAAYA"] [Tue Aug 18 13:05:53.848297 2026] [security2:error] [pid 157386:tid 157615] [client 20.151.109.219:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/99.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1QwAAAW0"] [Tue Aug 18 13:05:53.872400 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/globals.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1RAAAASM"] [Tue Aug 18 13:05:53.882607 2026] [security2:error] [pid 157386:tid 157599] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/abc.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1RQAAAV0"] [Tue Aug 18 13:05:53.903121 2026] [security2:error] [pid 157386:tid 157600] [client 20.25.139.174:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1RwAAAV4"] [Tue Aug 18 13:05:53.904951 2026] [security2:error] [pid 157386:tid 157600] [client 20.226.36.136:25146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/yxijx.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1SAAAAV4"] [Tue Aug 18 13:05:53.940150 2026] [security2:error] [pid 157386:tid 157641] [client 20.104.49.167:41748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/grok.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1TAAAAYc"] [Tue Aug 18 13:05:53.968624 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:53.968950 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:53.971335 2026] [security2:error] [pid 157386:tid 157631] [client 20.171.51.14:6594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/zy.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1TwAAAX0"] [Tue Aug 18 13:05:53.995269 2026] [security2:error] [pid 157386:tid 157533] [client 20.250.13.23:23702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/jquery.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1UAAAARs"] [Tue Aug 18 13:05:53.996191 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:22559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/zxz.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1UQAAAXk"] [Tue Aug 18 13:05:54.000980 2026] [security2:error] [pid 157386:tid 157601] [client 49.37.150.8:64274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1UgAAAV8"] [Tue Aug 18 13:05:54.001095 2026] [security2:error] [pid 157386:tid 157601] [client 49.37.150.8:64274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1UgAAAV8"] [Tue Aug 18 13:05:54.017643 2026] [security2:error] [pid 157386:tid 157620] [client 74.249.206.207:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/coffee.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1VAAAAXI"] [Tue Aug 18 13:05:54.128022 2026] [security2:error] [pid 157386:tid 157589] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/yindu.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1WAAAAVM"] [Tue Aug 18 13:05:54.140097 2026] [security2:error] [pid 157386:tid 157418] [remote 89.185.225.24:34902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1WQABFx8"] [Tue Aug 18 13:05:54.164386 2026] [security2:error] [pid 157386:tid 157636] [client 68.155.156.252:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/xiugai.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1XAAAAYI"] [Tue Aug 18 13:05:54.168569 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/akcc.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1XQAAAUs"] [Tue Aug 18 13:05:54.220903 2026] [security2:error] [pid 157386:tid 157466] [remote 115.146.125.52:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertacoelhopsicologa.com.br"] [uri "/wp-login.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1YAABWU8"] [Tue Aug 18 13:05:54.252814 2026] [security2:error] [pid 157386:tid 157524] [client 20.25.139.174:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/min.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1YQAAARI"] [Tue Aug 18 13:05:54.263708 2026] [security2:error] [pid 157386:tid 157587] [client 213.35.127.232:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1YgAAAVE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:54.266458 2026] [security2:error] [pid 157386:tid 157528] [client 20.1.169.243:15943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/load.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1ZAAAARY"] [Tue Aug 18 13:05:54.269748 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/er.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1ZQAAAU4"] [Tue Aug 18 13:05:54.271004 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:54.271264 2026] [authz_core:error] [pid 157386:tid 157463] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:54.300941 2026] [security2:error] [pid 157386:tid 157614] [client 20.151.109.219:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/q.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1ZwAAAWw"] [Tue Aug 18 13:05:54.334733 2026] [security2:error] [pid 157386:tid 157630] [client 20.250.13.23:48879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/simple.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1agAAAXw"] [Tue Aug 18 13:05:54.349412 2026] [security2:error] [pid 157386:tid 157540] [client 74.249.206.207:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1awAAASI"] [Tue Aug 18 13:05:54.365096 2026] [security2:error] [pid 157386:tid 157574] [client 20.116.17.175:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/memberfuns.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1bAAAAUQ"] [Tue Aug 18 13:05:54.371226 2026] [security2:error] [pid 157386:tid 157518] [client 40.74.65.169:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1bQAAAQw"] [Tue Aug 18 13:05:54.383450 2026] [security2:error] [pid 157386:tid 157592] [client 20.127.136.245:28110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/term.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1bwAAAVY"] [Tue Aug 18 13:05:54.387126 2026] [security2:error] [pid 157386:tid 157613] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/sxx.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1cAAAAWs"] [Tue Aug 18 13:05:54.398086 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.36.136:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/zwlsv.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1cQAAAXQ"] [Tue Aug 18 13:05:54.399913 2026] [security2:error] [pid 157386:tid 157531] [client 20.25.139.174:4625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/h.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1cgAAARk"] [Tue Aug 18 13:05:54.401397 2026] [security2:error] [pid 157386:tid 157611] [client 168.62.48.100:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1cwAAAWk"] [Tue Aug 18 13:05:54.419069 2026] [security2:error] [pid 157386:tid 157526] [client 34.38.184.238:50404] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/redirect"] [unique_id "aoSC4k1jzAhYHVVT1Wf1dAAAARQ"] [Tue Aug 18 13:05:54.469768 2026] [security2:error] [pid 157386:tid 157565] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wk/index.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1dwAAATs"] [Tue Aug 18 13:05:54.474759 2026] [security2:error] [pid 157386:tid 157597] [client 34.38.184.238:50460] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/fetch"] [unique_id "aoSC4k1jzAhYHVVT1Wf1eAAAAVs"] [Tue Aug 18 13:05:54.485738 2026] [security2:error] [pid 157386:tid 157546] [client 4.223.113.180:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1eQAAASg"] [Tue Aug 18 13:05:54.510742 2026] [security2:error] [pid 157386:tid 157541] [client 34.38.184.238:50630] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC4k1jzAhYHVVT1Wf1fAAAASM"] [Tue Aug 18 13:05:54.515917 2026] [security2:error] [pid 157386:tid 157520] [client 20.104.49.167:23948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/indes.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1fQAAAQ4"] [Tue Aug 18 13:05:54.564363 2026] [authz_core:error] [pid 157386:tid 157479] [remote 85.204.70.116:0] AH01630: client denied by server configuration: /home2/hg1tdc82/public_html/wp-content/uploads/index.php [Tue Aug 18 13:05:54.570284 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:54.570548 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:54.583455 2026] [security2:error] [pid 157386:tid 157571] [client 20.171.51.14:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/q.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1hQAAAUE"] [Tue Aug 18 13:05:54.603982 2026] [security2:error] [pid 157386:tid 157534] [client 20.215.241.237:31561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1hgAAARw"] [Tue Aug 18 13:05:54.613464 2026] [security2:error] [pid 157386:tid 157633] [client 20.104.100.201:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ab.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1hwAAAX8"] [Tue Aug 18 13:05:54.628499 2026] [security2:error] [pid 157386:tid 157624] [client 20.250.13.23:18519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/media-new.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1iAAAAXY"] [Tue Aug 18 13:05:54.632402 2026] [security2:error] [pid 157386:tid 157590] [client 20.1.169.243:15688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/login.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1iQAAAVQ"] [Tue Aug 18 13:05:54.634600 2026] [security2:error] [pid 157386:tid 157559] [client 68.155.156.252:49729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/wp-load.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1igAAATU"] [Tue Aug 18 13:05:54.645134 2026] [security2:error] [pid 157386:tid 157525] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/settings.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1iwAAARM"] [Tue Aug 18 13:05:54.668203 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:50208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/proxy"] [unique_id "aoSC4k1jzAhYHVVT1Wf1jgAAARs"] [Tue Aug 18 13:05:54.699490 2026] [security2:error] [pid 157386:tid 157596] [client 20.151.109.219:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/qk.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1jwAAAVo"] [Tue Aug 18 13:05:54.701843 2026] [security2:error] [pid 157386:tid 157625] [client 34.38.184.238:50406] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/v1/fetch"] [unique_id "aoSC4k1jzAhYHVVT1Wf1kAAAAXc"] [Tue Aug 18 13:05:54.722600 2026] [security2:error] [pid 157386:tid 157583] [client 158.23.17.4:48439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lp.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1kgAAAU0"] [Tue Aug 18 13:05:54.772810 2026] [security2:error] [pid 157386:tid 157593] [client 20.171.51.14:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/gj.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1lgAAAVc"] [Tue Aug 18 13:05:54.788485 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.100.201:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/f35.update.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1lwAAAUo"] [Tue Aug 18 13:05:54.797798 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.85.180:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.joanagaspar.com.br"] [uri "/1.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1mAAAAS8"] [Tue Aug 18 13:05:54.797894 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/1.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1mAAAAS8"] [Tue Aug 18 13:05:54.823073 2026] [security2:error] [pid 157386:tid 157595] [client 74.249.206.207:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1mQAAAVk"] [Tue Aug 18 13:05:54.850227 2026] [security2:error] [pid 157386:tid 157605] [client 20.127.136.245:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1nAAAAWM"] [Tue Aug 18 13:05:54.865417 2026] [security2:error] [pid 157386:tid 157578] [client 168.62.48.100:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/mt/byp.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1ngAAAUg"] [Tue Aug 18 13:05:54.873103 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:54.873414 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:54.907102 2026] [security2:error] [pid 157386:tid 157598] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/spip.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1oQAAAVw"] [Tue Aug 18 13:05:54.922373 2026] [security2:error] [pid 157386:tid 157594] [client 20.116.17.175:22607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/aa.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1owAAAVg"] [Tue Aug 18 13:05:54.926456 2026] [security2:error] [pid 157386:tid 157619] [client 20.25.139.174:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ms-edit.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1pAAAAXE"] [Tue Aug 18 13:05:54.927371 2026] [security2:error] [pid 157386:tid 157554] [client 20.25.139.174:4839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/php8.php"] [unique_id "aoSC4k1jzAhYHVVT1Wf1pQAAATA"] [Tue Aug 18 13:05:55.009762 2026] [security2:error] [pid 157386:tid 157519] [client 68.155.156.252:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/155.php"] [unique_id "aoSC401jzAhYHVVT1Wf1qQAAAQ0"] [Tue Aug 18 13:05:55.047503 2026] [security2:error] [pid 157386:tid 157517] [client 68.221.73.131:24493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/adminfuns.php"] [unique_id "aoSC401jzAhYHVVT1Wf1rQAAAQs"] [Tue Aug 18 13:05:55.092253 2026] [security2:error] [pid 157386:tid 157541] [client 40.74.65.169:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/BDKR28WP.php"] [unique_id "aoSC401jzAhYHVVT1Wf1rgAAASM"] [Tue Aug 18 13:05:55.102046 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fraie1p4.php"] [unique_id "aoSC401jzAhYHVVT1Wf1rwAAAT0"] [Tue Aug 18 13:05:55.110130 2026] [security2:error] [pid 157386:tid 157535] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSC401jzAhYHVVT1Wf1sQAAAR0"] [Tue Aug 18 13:05:55.131143 2026] [security2:error] [pid 157386:tid 157543] [client 20.206.73.37:2170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/file61.php"] [unique_id "aoSC401jzAhYHVVT1Wf1sgAAASU"] [Tue Aug 18 13:05:55.173302 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:55.173593 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:55.174852 2026] [security2:error] [pid 157386:tid 157545] [client 74.249.206.207:32604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/yj09.php"] [unique_id "aoSC401jzAhYHVVT1Wf1tAAAASc"] [Tue Aug 18 13:05:55.189176 2026] [security2:error] [pid 157386:tid 157569] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/search.php"] [unique_id "aoSC401jzAhYHVVT1Wf1tgAAAT8"] [Tue Aug 18 13:05:55.220709 2026] [security2:error] [pid 157386:tid 157623] [client 20.1.169.243:15607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/min.php"] [unique_id "aoSC401jzAhYHVVT1Wf1uQAAAXU"] [Tue Aug 18 13:05:55.235076 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:21690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/fresh.php"] [unique_id "aoSC401jzAhYHVVT1Wf1ugAAAXg"] [Tue Aug 18 13:05:55.251179 2026] [security2:error] [pid 157386:tid 157550] [client 20.226.36.136:41579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/jrpga.php"] [unique_id "aoSC401jzAhYHVVT1Wf1uwAAASw"] [Tue Aug 18 13:05:55.270045 2026] [security2:error] [pid 157386:tid 157546] [client 20.250.13.23:23701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSC401jzAhYHVVT1Wf1vAAAASg"] [Tue Aug 18 13:05:55.289006 2026] [security2:error] [pid 157386:tid 157557] [client 20.151.109.219:21910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xf.php"] [unique_id "aoSC401jzAhYHVVT1Wf1vgAAATM"] [Tue Aug 18 13:05:55.314281 2026] [security2:error] [pid 157386:tid 157609] [client 213.35.127.232:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSC401jzAhYHVVT1Wf1vwAAAWc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:55.364890 2026] [security2:error] [pid 157386:tid 157430] [remote 162.241.153.188:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.153.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tivinalili.com.br"] [uri "/wp-login.php"] [unique_id "aoSC401jzAhYHVVT1Wf1wAABDys"] [Tue Aug 18 13:05:55.431092 2026] [security2:error] [pid 157386:tid 157627] [client 68.155.156.252:20313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/index.php"] [unique_id "aoSC401jzAhYHVVT1Wf1wwAAAXk"] [Tue Aug 18 13:05:55.433649 2026] [security2:error] [pid 157386:tid 157633] [client 20.25.139.174:4614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC401jzAhYHVVT1Wf1xAAAAX8"] [Tue Aug 18 13:05:55.435782 2026] [security2:error] [pid 157386:tid 157617] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/build.php"] [unique_id "aoSC401jzAhYHVVT1Wf1xQAAAW8"] [Tue Aug 18 13:05:55.436874 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/a7.php"] [unique_id "aoSC401jzAhYHVVT1Wf1xgAAAX4"] [Tue Aug 18 13:05:55.511290 2026] [security2:error] [pid 157386:tid 157642] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSC401jzAhYHVVT1Wf1xwAAAYg"] [Tue Aug 18 13:05:55.533797 2026] [security2:error] [pid 157386:tid 157643] [client 20.151.109.219:65057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fs.php"] [unique_id "aoSC401jzAhYHVVT1Wf1yAAAAYk"] [Tue Aug 18 13:05:55.543769 2026] [security2:error] [pid 157386:tid 157527] [client 74.249.206.207:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/scxy.php"] [unique_id "aoSC401jzAhYHVVT1Wf1yQAAARU"] [Tue Aug 18 13:05:55.684064 2026] [security2:error] [pid 157386:tid 157629] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/defaul.php"] [unique_id "aoSC401jzAhYHVVT1Wf1ywAAAXs"] [Tue Aug 18 13:05:55.744858 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.49.167:48553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/tTPcH.php"] [unique_id "aoSC401jzAhYHVVT1Wf1zAAAAXo"] [Tue Aug 18 13:05:55.768616 2026] [security2:error] [pid 157386:tid 157522] [client 20.38.3.247:7175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/key.php"] [unique_id "aoSC401jzAhYHVVT1Wf1zgAAARA"] [Tue Aug 18 13:05:55.790243 2026] [security2:error] [pid 157386:tid 157595] [client 68.155.156.252:53927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/aaa.php"] [unique_id "aoSC401jzAhYHVVT1Wf1zwAAAVk"] [Tue Aug 18 13:05:55.850443 2026] [security2:error] [pid 157386:tid 157528] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/as.php"] [unique_id "aoSC401jzAhYHVVT1Wf10AAAARY"] [Tue Aug 18 13:05:55.859068 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:55.859339 2026] [authz_core:error] [pid 157386:tid 157397] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:55.922884 2026] [security2:error] [pid 157386:tid 157562] [client 5.161.215.244:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "yycc.com.br"] [uri "/index.php"] [unique_id "aoSC4U1jzAhYHVVT1Wf1FgABOEE"], referer: https://yycc.com.br/ [Tue Aug 18 13:05:55.938169 2026] [security2:error] [pid 157386:tid 157605] [client 52.173.121.69:40900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSC401jzAhYHVVT1Wf10gAAAWM"] [Tue Aug 18 13:05:55.946095 2026] [security2:error] [pid 157386:tid 157578] [client 20.171.51.14:31135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pd.php"] [unique_id "aoSC401jzAhYHVVT1Wf10wAAAUg"] [Tue Aug 18 13:05:55.979362 2026] [security2:error] [pid 157386:tid 157593] [client 20.127.136.245:28123] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.luvhost.com.br"] [uri "/1.php"] [unique_id "aoSC401jzAhYHVVT1Wf11QAAAVc"] [Tue Aug 18 13:05:55.979461 2026] [security2:error] [pid 157386:tid 157593] [client 20.127.136.245:28123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/1.php"] [unique_id "aoSC401jzAhYHVVT1Wf11QAAAVc"] [Tue Aug 18 13:05:56.007395 2026] [security2:error] [pid 157386:tid 157540] [client 20.171.51.14:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xf.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf11gAAASI"] [Tue Aug 18 13:05:56.027346 2026] [security2:error] [pid 157386:tid 157554] [client 20.116.17.175:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/echkm.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf12AAAATA"] [Tue Aug 18 13:05:56.027850 2026] [security2:error] [pid 157386:tid 157548] [client 20.151.109.219:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/rb.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf12QAAASo"] [Tue Aug 18 13:05:56.086152 2026] [security2:error] [pid 157386:tid 157582] [client 20.250.13.23:52869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/edit-tags.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf12gAAAUw"] [Tue Aug 18 13:05:56.153650 2026] [security2:error] [pid 157386:tid 157537] [client 20.104.100.201:54058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/bdroot.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf13QAAAR8"] [Tue Aug 18 13:05:56.188008 2026] [security2:error] [pid 157386:tid 157519] [client 158.23.17.4:20431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ey.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf13gAAAQ0"] [Tue Aug 18 13:05:56.245733 2026] [security2:error] [pid 157386:tid 157637] [client 20.206.73.37:31070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/gm.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf13wAAAYM"] [Tue Aug 18 13:05:56.273751 2026] [security2:error] [pid 157386:tid 157587] [client 20.25.139.174:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/manager.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf14AAAAVE"] [Tue Aug 18 13:05:56.330352 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf14gAAATY"] [Tue Aug 18 13:05:56.449842 2026] [security2:error] [pid 157386:tid 157456] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf14wABDkU"] [Tue Aug 18 13:05:56.449981 2026] [security2:error] [pid 157386:tid 157520] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf14wABDkU"] [Tue Aug 18 13:05:56.468770 2026] [security2:error] [pid 157386:tid 157535] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/twin.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf15AAAAR0"] [Tue Aug 18 13:05:56.513349 2026] [security2:error] [pid 157386:tid 157579] [client 40.74.65.169:55204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf15QAAAUk"] [Tue Aug 18 13:05:56.575594 2026] [autoindex:error] [pid 157386:tid 157394] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:56.630161 2026] [security2:error] [pid 157386:tid 157641] [client 20.171.51.14:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gb.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf15wAAAYc"] [Tue Aug 18 13:05:56.706923 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:56.707205 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:56.733204 2026] [security2:error] [pid 157386:tid 157638] [client 149.34.210.141:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf16gAAAYQ"] [Tue Aug 18 13:05:56.773014 2026] [security2:error] [pid 157386:tid 157546] [client 20.151.109.219:46439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/37.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf16wAAASg"] [Tue Aug 18 13:05:56.792014 2026] [security2:error] [pid 157386:tid 157590] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/new2.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf17AAAAVQ"] [Tue Aug 18 13:05:56.887285 2026] [security2:error] [pid 157386:tid 157525] [client 20.206.73.37:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/copypaths.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf17QAAARM"] [Tue Aug 18 13:05:56.975011 2026] [security2:error] [pid 157386:tid 157529] [client 20.215.241.237:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf17wAAARc"] [Tue Aug 18 13:05:56.997811 2026] [security2:error] [pid 157386:tid 157620] [client 20.171.51.14:21284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/th.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf18AAAAXI"] [Tue Aug 18 13:05:57.034628 2026] [security2:error] [pid 157386:tid 157424] [remote 129.121.103.155:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalinox.pt.cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf11wABXCU"] [Tue Aug 18 13:05:57.146301 2026] [security2:error] [pid 157386:tid 157626] [client 20.250.13.23:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/u.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf18gAAAXg"] [Tue Aug 18 13:05:57.154023 2026] [security2:error] [pid 157386:tid 157603] [client 68.155.156.252:13453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/FWAZ.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf18wAAAWE"] [Tue Aug 18 13:05:57.163501 2026] [security2:error] [pid 157386:tid 157643] [client 34.38.184.238:50220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/v1/fetch"] [unique_id "aoSC5U1jzAhYHVVT1Wf19AAAAYk"] [Tue Aug 18 13:05:57.181923 2026] [security2:error] [pid 157386:tid 157532] [client 20.1.169.243:15559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/options.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf19QAAARo"] [Tue Aug 18 13:05:57.250977 2026] [security2:error] [pid 157386:tid 157566] [client 40.74.65.169:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/1xmomo.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf19wAAATw"] [Tue Aug 18 13:05:57.258699 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:5345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/md.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf1-AAAAW4"] [Tue Aug 18 13:05:57.265319 2026] [security2:error] [pid 157386:tid 157636] [client 74.249.206.207:64556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf1-QAAAYI"] [Tue Aug 18 13:05:57.282679 2026] [security2:error] [pid 157386:tid 157631] [client 20.250.13.23:44033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf1-gAAAX0"] [Tue Aug 18 13:05:57.371986 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:57.372260 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:57.469536 2026] [security2:error] [pid 157386:tid 157562] [client 168.62.48.100:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf1_gAAATg"] [Tue Aug 18 13:05:57.506311 2026] [security2:error] [pid 157386:tid 157578] [client 34.38.184.238:47790] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC5U1jzAhYHVVT1Wf1_wAAAUg"] [Tue Aug 18 13:05:57.583914 2026] [security2:error] [pid 157386:tid 157594] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/rex.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2AgAAAVg"] [Tue Aug 18 13:05:57.622224 2026] [autoindex:error] [pid 157386:tid 157492] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:57.636134 2026] [security2:error] [pid 157386:tid 157592] [client 68.155.156.252:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/site.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2BQAAAVY"] [Tue Aug 18 13:05:57.706232 2026] [security2:error] [pid 157386:tid 157613] [client 74.249.206.207:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2BwAAAWs"] [Tue Aug 18 13:05:57.709583 2026] [security2:error] [pid 157386:tid 157589] [client 4.223.113.180:43313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/randkeyword.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2CAAAAVM"] [Tue Aug 18 13:05:57.721443 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:65087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/iy.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2CgAAAXQ"] [Tue Aug 18 13:05:57.784622 2026] [security2:error] [pid 157386:tid 157638] [client 149.34.210.141:59572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC5E1jzAhYHVVT1Wf16gAAAYQ"] [Tue Aug 18 13:05:57.827361 2026] [security2:error] [pid 157386:tid 157533] [client 157.20.138.62:63864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2DAAAARs"] [Tue Aug 18 13:05:57.872823 2026] [security2:error] [pid 157386:tid 157637] [client 20.104.100.201:53828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-temp.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2DgAAAYM"] [Tue Aug 18 13:05:57.874940 2026] [security2:error] [pid 157386:tid 157601] [client 20.25.139.174:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/222.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2DwAAAV8"] [Tue Aug 18 13:05:57.900179 2026] [security2:error] [pid 157386:tid 157611] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/verification.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2EwAAAWk"] [Tue Aug 18 13:05:57.909280 2026] [security2:error] [pid 157386:tid 157602] [client 216.73.161.218:53977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2CQAAAWA"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:05:58.041476 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.100.201:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/12.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2FQAAAUY"] [Tue Aug 18 13:05:58.042198 2026] [authz_core:error] [pid 157386:tid 157465] [remote 57.141.22.102:34484] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:58.042470 2026] [authz_core:error] [pid 157386:tid 157465] [remote 57.141.22.102:34484] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:58.091974 2026] [security2:error] [pid 157386:tid 157567] [client 68.155.156.252:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/ccc.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2FwAAAT0"] [Tue Aug 18 13:05:58.106278 2026] [security2:error] [pid 157386:tid 157547] [client 158.23.17.4:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lv.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2GAAAASk"] [Tue Aug 18 13:05:58.140334 2026] [security2:error] [pid 157386:tid 157535] [client 52.173.121.69:37667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2GgAAAR0"] [Tue Aug 18 13:05:58.173213 2026] [security2:error] [pid 157386:tid 157543] [client 74.249.206.207:32517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/blurbs.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2GwAAASU"] [Tue Aug 18 13:05:58.215899 2026] [security2:error] [pid 157386:tid 157569] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/smtp.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2HQAAAT8"] [Tue Aug 18 13:05:58.322888 2026] [security2:error] [pid 157386:tid 157534] [client 20.104.100.201:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-css.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2IAAAARw"] [Tue Aug 18 13:05:58.386019 2026] [security2:error] [pid 157386:tid 157559] [client 20.151.109.219:27358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gb.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2IgAAATU"] [Tue Aug 18 13:05:58.421956 2026] [security2:error] [pid 157386:tid 157565] [client 20.206.73.37:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/mosty.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2IwAAATs"] [Tue Aug 18 13:05:58.450987 2026] [security2:error] [pid 157386:tid 157521] [client 20.215.241.237:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/xx.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2JAAAAQ8"] [Tue Aug 18 13:05:58.484388 2026] [security2:error] [pid 157386:tid 157627] [client 68.155.156.252:34567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/admin.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2JgAAAXk"] [Tue Aug 18 13:05:58.525750 2026] [security2:error] [pid 157386:tid 157632] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/teste.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2JwAAAX4"] [Tue Aug 18 13:05:58.539242 2026] [autoindex:error] [pid 157386:tid 157481] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:05:58.564093 2026] [security2:error] [pid 157386:tid 157642] [client 40.74.65.169:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2KgAAAYg"] [Tue Aug 18 13:05:58.587011 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/og.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2KwAAAXg"] [Tue Aug 18 13:05:58.601110 2026] [security2:error] [pid 157386:tid 157643] [client 74.249.206.207:64568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/bajah.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2LAAAAYk"] [Tue Aug 18 13:05:58.631782 2026] [security2:error] [pid 157386:tid 157526] [client 20.25.139.174:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/w1.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2LQAAARQ"] [Tue Aug 18 13:05:58.701032 2026] [security2:error] [pid 157386:tid 157553] [client 20.151.109.219:59727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/admin404.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2MAAAAS8"] [Tue Aug 18 13:05:58.775444 2026] [security2:error] [pid 157386:tid 157524] [client 20.171.51.14:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/jp.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2OAAAARI"] [Tue Aug 18 13:05:58.805033 2026] [security2:error] [pid 157386:tid 157525] [client 114.119.136.76:54167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifetreemarketing.com"] [uri "/fim-da-loja-virtual-conheca-o-botao-de-compra-do-chatgpt/"] [unique_id "aoSC5k1jzAhYHVVT1Wf2OgAAARM"], referer: https://lifetreemarketing.com/author/carlosedu73/ [Tue Aug 18 13:05:58.831830 2026] [security2:error] [pid 157386:tid 157562] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2OwAAATg"] [Tue Aug 18 13:05:58.893740 2026] [security2:error] [pid 157386:tid 157609] [client 4.223.113.180:35315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2PAAAAWc"] [Tue Aug 18 13:05:58.904013 2026] [security2:error] [pid 157386:tid 157542] [client 20.104.100.201:54027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/flox.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2PgAAASQ"] [Tue Aug 18 13:05:58.906681 2026] [security2:error] [pid 157386:tid 157552] [client 34.38.184.238:47824] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/preview"] [unique_id "aoSC5k1jzAhYHVVT1Wf2PwAAAS4"] [Tue Aug 18 13:05:58.912667 2026] [security2:error] [pid 157386:tid 157527] [client 20.226.36.136:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2QAAAARU"] [Tue Aug 18 13:05:58.922925 2026] [security2:error] [pid 157386:tid 157593] [client 216.244.66.243:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mail.jclareteimoveis.com.br"] [uri "/uuu+bet-2/"] [unique_id "aoSC5k1jzAhYHVVT1Wf2QQAAAVc"] [Tue Aug 18 13:05:58.922983 2026] [security2:error] [pid 157386:tid 157593] [client 216.244.66.243:57502] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.jclareteimoveis.com.br"] [uri "/uuu+bet-2/"] [unique_id "aoSC5k1jzAhYHVVT1Wf2QQAAAVc"] [Tue Aug 18 13:05:58.949050 2026] [security2:error] [pid 157386:tid 157614] [client 74.249.206.207:32568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/domvf.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2QgAAAWw"] [Tue Aug 18 13:05:58.956703 2026] [security2:error] [pid 157386:tid 157624] [client 213.202.253.4:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/userfuns.php"] [unique_id "aoSC5k1jzAhYHVVT1Wf2RAAAAXY"], referer: www.google.com [Tue Aug 18 13:05:59.099439 2026] [security2:error] [pid 157386:tid 157533] [client 157.20.138.62:63864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC5U1jzAhYHVVT1Wf2DAAAARs"] [Tue Aug 18 13:05:59.118612 2026] [security2:error] [pid 157386:tid 157610] [client 213.35.127.232:60862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSC501jzAhYHVVT1Wf2SAAAAWg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:05:59.143171 2026] [security2:error] [pid 157386:tid 157638] [client 34.38.184.238:47784] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC501jzAhYHVVT1Wf2SQAAAYQ"] [Tue Aug 18 13:05:59.252289 2026] [security2:error] [pid 157386:tid 157637] [client 20.116.17.175:22590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/domvf.php"] [unique_id "aoSC501jzAhYHVVT1Wf2TQAAAYM"] [Tue Aug 18 13:05:59.297208 2026] [security2:error] [pid 157386:tid 157595] [client 20.250.13.23:23726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSC501jzAhYHVVT1Wf2TwAAAVk"] [Tue Aug 18 13:05:59.311931 2026] [security2:error] [pid 157386:tid 157587] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/local.php"] [unique_id "aoSC501jzAhYHVVT1Wf2UAAAAVE"] [Tue Aug 18 13:05:59.376194 2026] [security2:error] [pid 157386:tid 157615] [client 20.171.51.14:47136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/eq.php"] [unique_id "aoSC501jzAhYHVVT1Wf2UgAAAW0"] [Tue Aug 18 13:05:59.405966 2026] [security2:error] [pid 157386:tid 157567] [client 20.25.139.174:4602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-login.php"] [unique_id "aoSC501jzAhYHVVT1Wf2VAAAAT0"] [Tue Aug 18 13:05:59.409134 2026] [security2:error] [pid 157386:tid 157599] [client 20.151.109.219:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lp.php"] [unique_id "aoSC501jzAhYHVVT1Wf2VQAAAV0"] [Tue Aug 18 13:05:59.411954 2026] [security2:error] [pid 157386:tid 157518] [client 20.250.13.23:39062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSC501jzAhYHVVT1Wf2VgAAAQw"] [Tue Aug 18 13:05:59.485664 2026] [security2:error] [pid 157386:tid 157572] [client 20.151.109.219:12869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/loading.php"] [unique_id "aoSC501jzAhYHVVT1Wf2WwAAAUI"] [Tue Aug 18 13:05:59.496964 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:13777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/jp.php"] [unique_id "aoSC501jzAhYHVVT1Wf2XAAAAYY"] [Tue Aug 18 13:05:59.554608 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:05:59.554888 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:05:59.564204 2026] [security2:error] [pid 157386:tid 157634] [client 138.36.100.162:42332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC501jzAhYHVVT1Wf2YAAAAYA"] [Tue Aug 18 13:05:59.564308 2026] [security2:error] [pid 157386:tid 157634] [client 138.36.100.162:42332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC501jzAhYHVVT1Wf2YAAAAYA"] [Tue Aug 18 13:05:59.623544 2026] [security2:error] [pid 157386:tid 157633] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSC501jzAhYHVVT1Wf2YgAAAX8"] [Tue Aug 18 13:05:59.698502 2026] [security2:error] [pid 157386:tid 157600] [client 20.206.73.37:15873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/bless6.php"] [unique_id "aoSC501jzAhYHVVT1Wf2ZQAAAV4"] [Tue Aug 18 13:05:59.713639 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.100.201:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/op.php"] [unique_id "aoSC501jzAhYHVVT1Wf2ZwAAAYk"] [Tue Aug 18 13:05:59.767897 2026] [security2:error] [pid 157386:tid 157561] [client 178.128.23.175:64820] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "zanoniautomoveis.com.br"] [uri "/"] [unique_id "aoSC501jzAhYHVVT1Wf2aAAAATc"] [Tue Aug 18 13:05:59.829338 2026] [security2:error] [pid 157386:tid 157566] [client 74.249.206.207:32551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/fpwch.php"] [unique_id "aoSC501jzAhYHVVT1Wf2aQAAATw"] [Tue Aug 18 13:05:59.831343 2026] [security2:error] [pid 157386:tid 157636] [client 20.171.51.14:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/admin404.php"] [unique_id "aoSC501jzAhYHVVT1Wf2agAAAYI"] [Tue Aug 18 13:05:59.856020 2026] [security2:error] [pid 157386:tid 157629] [client 40.74.65.169:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/blurbs.php"] [unique_id "aoSC501jzAhYHVVT1Wf2awAAAXs"] [Tue Aug 18 13:05:59.926431 2026] [security2:error] [pid 157386:tid 157558] [client 52.173.121.69:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSC501jzAhYHVVT1Wf2dAAAATQ"] [Tue Aug 18 13:06:00.045443 2026] [security2:error] [pid 157386:tid 157528] [client 20.118.133.132:48540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/copypaths.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2eAAAARY"] [Tue Aug 18 13:06:00.047171 2026] [security2:error] [pid 157386:tid 157593] [client 34.38.184.238:47880] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC6E1jzAhYHVVT1Wf2eQAAAVc"] [Tue Aug 18 13:06:00.084822 2026] [security2:error] [pid 157386:tid 157594] [client 68.155.156.252:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/reviall.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2fAAAAVg"] [Tue Aug 18 13:06:00.122500 2026] [security2:error] [pid 157386:tid 157539] [client 20.25.139.174:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2fQAAASE"] [Tue Aug 18 13:06:00.181972 2026] [security2:error] [pid 157386:tid 157581] [client 74.248.130.103:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/kir.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2gwAAAUs"] [Tue Aug 18 13:06:00.204228 2026] [security2:error] [pid 157386:tid 157589] [client 158.23.17.4:47631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/51.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2hAAAAVM"] [Tue Aug 18 13:06:00.244441 2026] [security2:error] [pid 157386:tid 157538] [client 20.38.3.247:36771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/chosen.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2hwAAASA"] [Tue Aug 18 13:06:00.352628 2026] [security2:error] [pid 157386:tid 157560] [client 20.151.109.219:10582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/eq.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2jwAAATY"] [Tue Aug 18 13:06:00.354075 2026] [security2:error] [pid 157386:tid 157615] [client 74.249.206.207:32550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/adminner.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2kAAAAW0"] [Tue Aug 18 13:06:00.363567 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.36.136:23221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/nwwha.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2kQAAATI"] [Tue Aug 18 13:06:00.440630 2026] [security2:error] [pid 157386:tid 157619] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/ninja.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2kwAAAXE"] [Tue Aug 18 13:06:00.476891 2026] [security2:error] [pid 157386:tid 157569] [client 20.151.109.219:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/conn-test.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2lAAAAT8"] [Tue Aug 18 13:06:00.554572 2026] [autoindex:error] [pid 157386:tid 157429] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:00.601473 2026] [security2:error] [pid 157386:tid 157520] [client 68.155.156.252:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/nope.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2ngAAAQ4"] [Tue Aug 18 13:06:00.604689 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/bajah.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2nwAAARw"] [Tue Aug 18 13:06:00.725223 2026] [security2:error] [pid 157386:tid 157521] [client 52.173.121.69:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2oAAAAQ8"] [Tue Aug 18 13:06:00.859460 2026] [security2:error] [pid 157386:tid 157620] [client 20.151.109.219:39823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ey.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2pgAAAXI"] [Tue Aug 18 13:06:00.910857 2026] [security2:error] [pid 157386:tid 157543] [client 20.25.139.174:4809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/info.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2pwAAASU"] [Tue Aug 18 13:06:00.955974 2026] [security2:error] [pid 157386:tid 157643] [client 20.206.73.37:31091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/ws55.php"] [unique_id "aoSC6E1jzAhYHVVT1Wf2qQAAAYk"] [Tue Aug 18 13:06:01.004795 2026] [authz_core:error] [pid 157386:tid 157482] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:01.005056 2026] [authz_core:error] [pid 157386:tid 157482] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:01.039525 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:06:01.039554 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:06:01.054600 2026] [security2:error] [pid 157386:tid 157631] [client 68.155.156.252:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/nope.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2rAAAAX0"] [Tue Aug 18 13:06:01.059376 2026] [security2:error] [pid 157386:tid 157629] [client 34.38.184.238:47836] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/preview"] [unique_id "aoSC6U1jzAhYHVVT1Wf2rgAAAXs"] [Tue Aug 18 13:06:01.084911 2026] [security2:error] [pid 157386:tid 157525] [client 34.38.184.238:47902] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC6U1jzAhYHVVT1Wf2rwAAARM"] [Tue Aug 18 13:06:01.149380 2026] [security2:error] [pid 157386:tid 157585] [client 20.171.51.14:38735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ep.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2sAAAAU8"] [Tue Aug 18 13:06:01.165819 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/evil.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2sgAAAUo"] [Tue Aug 18 13:06:01.205300 2026] [security2:error] [pid 157386:tid 157526] [client 20.25.139.174:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/default.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2tAAAARQ"] [Tue Aug 18 13:06:01.301495 2026] [security2:error] [pid 157386:tid 157563] [client 20.250.13.23:7514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/h.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2uAAAATk"] [Tue Aug 18 13:06:01.601522 2026] [security2:error] [pid 157386:tid 157606] [client 103.120.71.157:41903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2vgAAAWQ"] [Tue Aug 18 13:06:01.601631 2026] [security2:error] [pid 157386:tid 157606] [client 103.120.71.157:41903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2vgAAAWQ"] [Tue Aug 18 13:06:01.603675 2026] [security2:error] [pid 157386:tid 157548] [client 158.23.17.4:15798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ew.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2vwAAASo"] [Tue Aug 18 13:06:01.655537 2026] [security2:error] [pid 157386:tid 157610] [client 20.116.17.175:45281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/red.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2wgAAAWg"] [Tue Aug 18 13:06:01.832086 2026] [security2:error] [pid 157386:tid 157578] [client 20.171.51.14:47140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/rf.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2xgAAAUg"] [Tue Aug 18 13:06:01.858351 2026] [security2:error] [pid 157386:tid 157641] [client 20.127.136.245:28255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/alfa.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2xwAAAYc"] [Tue Aug 18 13:06:01.907661 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.100.201:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/1xmomo.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2yAAAAVQ"] [Tue Aug 18 13:06:01.957542 2026] [security2:error] [pid 157386:tid 157517] [client 20.151.109.219:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lv.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2yQAAAQs"] [Tue Aug 18 13:06:02.017000 2026] [security2:error] [pid 157386:tid 157587] [client 20.250.13.23:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2zQAAAVE"] [Tue Aug 18 13:06:02.042809 2026] [security2:error] [pid 157386:tid 157597] [client 20.25.139.174:4431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/i.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2zgAAAVs"] [Tue Aug 18 13:06:02.141088 2026] [security2:error] [pid 157386:tid 157583] [client 74.248.130.103:42014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/nofile.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2zwAAAU0"] [Tue Aug 18 13:06:02.156045 2026] [security2:error] [pid 157386:tid 157543] [client 104.222.31.70:33603] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "fbenevides.com.br"] [uri "/node/1"] [unique_id "aoSC6k1jzAhYHVVT1Wf20AAAASU"] [Tue Aug 18 13:06:02.218880 2026] [security2:error] [pid 157386:tid 157614] [client 20.25.139.174:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/a.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf20wAAAWw"] [Tue Aug 18 13:06:02.228532 2026] [security2:error] [pid 157386:tid 157626] [client 34.38.184.238:48234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/var/www/html/.env"] [unique_id "aoSC6k1jzAhYHVVT1Wf21AAAAXg"] [Tue Aug 18 13:06:02.239840 2026] [security2:error] [pid 157386:tid 157631] [client 68.155.156.252:20313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/new.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf21gAAAX0"] [Tue Aug 18 13:06:02.254110 2026] [security2:error] [pid 157386:tid 157564] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/phpprobe.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf21wAAATo"] [Tue Aug 18 13:06:02.278418 2026] [security2:error] [pid 157386:tid 157623] [client 34.38.184.238:48164] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config/jenkins.xml"] [unique_id "aoSC6k1jzAhYHVVT1Wf22AAAAXU"] [Tue Aug 18 13:06:02.300844 2026] [security2:error] [pid 157386:tid 157558] [client 20.151.109.219:65013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/wp-key.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf23AAAATQ"] [Tue Aug 18 13:06:02.307046 2026] [security2:error] [pid 157386:tid 157562] [client 20.151.109.219:5349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/51.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf23QAAATg"] [Tue Aug 18 13:06:02.312543 2026] [security2:error] [pid 157386:tid 157609] [client 34.38.184.238:48224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env.prod.bak"] [unique_id "aoSC6k1jzAhYHVVT1Wf23gAAAWc"] [Tue Aug 18 13:06:02.317764 2026] [security2:error] [pid 157386:tid 157593] [client 158.23.17.4:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pqr.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf24wAAAVc"] [Tue Aug 18 13:06:02.339933 2026] [security2:error] [pid 157386:tid 157601] [client 34.38.184.238:47910] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/@fs/proc/self/environ"] [unique_id "aoSC6k1jzAhYHVVT1Wf25wAAAV8"] [Tue Aug 18 13:06:02.360650 2026] [security2:error] [pid 157386:tid 157582] [client 20.226.36.136:41532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/opsqt.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf26gAAAUw"] [Tue Aug 18 13:06:02.476317 2026] [security2:error] [pid 157386:tid 157573] [client 20.1.169.243:15938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/plugin-install.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf27QAAAUM"] [Tue Aug 18 13:06:02.516073 2026] [security2:error] [pid 157386:tid 157416] [remote 203.99.146.53:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf27wABLx0"] [Tue Aug 18 13:06:02.556205 2026] [security2:error] [pid 157386:tid 157637] [client 52.173.121.69:49555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf28wAAAYM"] [Tue Aug 18 13:06:02.580636 2026] [autoindex:error] [pid 157386:tid 157418] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:02.591838 2026] [authz_core:error] [pid 157386:tid 157486] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:02.592093 2026] [authz_core:error] [pid 157386:tid 157486] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:02.620515 2026] [http2:warn] [pid 139043:tid 139191] [client 201.32.74.208:57070] h2_stream(139043-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:06:02.658266 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.100.201:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/x1da.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2-AAAAQw"] [Tue Aug 18 13:06:02.692560 2026] [security2:error] [pid 157386:tid 157453] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2-gABcUI"] [Tue Aug 18 13:06:02.692743 2026] [security2:error] [pid 157386:tid 157619] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2-gABcUI"] [Tue Aug 18 13:06:02.723774 2026] [security2:error] [pid 157386:tid 157578] [client 20.206.73.37:20523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/m.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2_QAAAUg"] [Tue Aug 18 13:06:02.755744 2026] [security2:error] [pid 157386:tid 157574] [client 20.118.133.132:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/bless6.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf2_wAAAUQ"] [Tue Aug 18 13:06:02.768874 2026] [security2:error] [pid 157386:tid 157604] [client 4.223.113.180:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf3AAAAAWI"] [Tue Aug 18 13:06:02.771383 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:42251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xynz1.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf3AQAAATU"] [Tue Aug 18 13:06:02.797754 2026] [security2:error] [pid 157386:tid 157611] [client 213.35.127.232:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf3AgAAAWk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:02.799493 2026] [security2:error] [pid 157386:tid 157595] [client 20.127.136.245:28258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/edit.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf3AwAAAVk"] [Tue Aug 18 13:06:02.878676 2026] [security2:error] [pid 157386:tid 157586] [client 20.116.17.175:45278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSC6k1jzAhYHVVT1Wf3BgAAAVA"] [Tue Aug 18 13:06:02.985746 2026] [security2:error] [pid 157386:tid 157529] [client 34.38.184.238:48248] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env.anthropic"] [unique_id "aoSC6k1jzAhYHVVT1Wf3DgAAARc"] [Tue Aug 18 13:06:02.986415 2026] [security2:error] [pid 157386:tid 157577] [client 34.38.184.238:47988] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/jenkins/credentials.xml"] [unique_id "aoSC6k1jzAhYHVVT1Wf3DwAAAUc"] [Tue Aug 18 13:06:03.033710 2026] [authz_core:error] [pid 157386:tid 157400] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:03.034167 2026] [authz_core:error] [pid 157386:tid 157400] [remote 216.73.216.206:61623] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:03.052637 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/phpcheck.php"] [unique_id "aoSC601jzAhYHVVT1Wf3EQAAAXU"] [Tue Aug 18 13:06:03.059675 2026] [security2:error] [pid 157386:tid 157524] [client 20.116.17.175:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC601jzAhYHVVT1Wf3EgAAARI"] [Tue Aug 18 13:06:03.123655 2026] [security2:error] [pid 157386:tid 157463] [remote 203.99.146.53:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "themenstyle.com.br"] [uri "/wp-login.php"] [unique_id "aoSC601jzAhYHVVT1Wf3FQABSkw"], referer: https://themenstyle.com.br/wp-login.php [Tue Aug 18 13:06:03.132761 2026] [security2:error] [pid 157386:tid 157585] [client 68.221.73.131:27384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/ms-edit.php"] [unique_id "aoSC601jzAhYHVVT1Wf3FgAAAU8"] [Tue Aug 18 13:06:03.160096 2026] [security2:error] [pid 157386:tid 157617] [client 178.153.171.161:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3FwAAAW8"] [Tue Aug 18 13:06:03.166656 2026] [security2:error] [pid 157386:tid 157539] [client 20.215.241.237:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/av.php"] [unique_id "aoSC601jzAhYHVVT1Wf3GAAAASE"] [Tue Aug 18 13:06:03.190780 2026] [security2:error] [pid 157386:tid 157552] [client 34.38.184.238:48234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/jenkins/config.xml.bak"] [unique_id "aoSC601jzAhYHVVT1Wf3GQAAAS4"] [Tue Aug 18 13:06:03.244778 2026] [security2:error] [pid 157386:tid 157592] [client 34.38.184.238:48232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/var/www/.env"] [unique_id "aoSC601jzAhYHVVT1Wf3IwAAAVY"] [Tue Aug 18 13:06:03.245615 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:48222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env.production.bak"] [unique_id "aoSC601jzAhYHVVT1Wf3IgAAARs"] [Tue Aug 18 13:06:03.266581 2026] [security2:error] [pid 157386:tid 157531] [client 20.25.139.174:4319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSC601jzAhYHVVT1Wf3JQAAARk"] [Tue Aug 18 13:06:03.274481 2026] [security2:error] [pid 157386:tid 157553] [client 20.226.36.136:25879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/jvcpa.php"] [unique_id "aoSC601jzAhYHVVT1Wf3KgAAAS8"] [Tue Aug 18 13:06:03.292198 2026] [security2:error] [pid 157386:tid 157548] [client 34.38.184.238:47916] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/Jenkinsfile"] [unique_id "aoSC601jzAhYHVVT1Wf3LAAAASo"] [Tue Aug 18 13:06:03.320486 2026] [security2:error] [pid 157386:tid 157606] [client 168.62.48.100:18075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC601jzAhYHVVT1Wf3LgAAAWQ"] [Tue Aug 18 13:06:03.329881 2026] [security2:error] [pid 157386:tid 157575] [client 223.185.37.47:24576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3LwAAAUU"] [Tue Aug 18 13:06:03.369791 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:4462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC601jzAhYHVVT1Wf3MAAAATM"] [Tue Aug 18 13:06:03.372022 2026] [security2:error] [pid 157386:tid 157607] [client 20.1.169.243:15572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/radio.php"] [unique_id "aoSC601jzAhYHVVT1Wf3MQAAAWU"] [Tue Aug 18 13:06:03.411024 2026] [security2:error] [pid 157386:tid 157561] [client 34.38.184.238:47926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/job/.env"] [unique_id "aoSC601jzAhYHVVT1Wf3MwAAATc"] [Tue Aug 18 13:06:03.468403 2026] [security2:error] [pid 157386:tid 157581] [client 34.38.184.238:48258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/.env.php"] [unique_id "aoSC601jzAhYHVVT1Wf3KQAAAUs"] [Tue Aug 18 13:06:03.485067 2026] [security2:error] [pid 157386:tid 157643] [client 20.206.73.37:26541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/blurbs.php"] [unique_id "aoSC601jzAhYHVVT1Wf3OAAAAYk"] [Tue Aug 18 13:06:03.495443 2026] [security2:error] [pid 157386:tid 157560] [client 34.38.184.238:47808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/.env.local.php"] [unique_id "aoSC601jzAhYHVVT1Wf3NgAAATY"] [Tue Aug 18 13:06:03.499530 2026] [security2:error] [pid 157386:tid 157571] [client 5.31.227.224:29950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3OgAAAUE"] [Tue Aug 18 13:06:03.499669 2026] [security2:error] [pid 157386:tid 157571] [client 5.31.227.224:29950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3OgAAAUE"] [Tue Aug 18 13:06:03.504465 2026] [autoindex:error] [pid 157386:tid 157401] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:03.510936 2026] [security2:error] [pid 157386:tid 157538] [client 20.25.139.174:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/chosen.php"] [unique_id "aoSC601jzAhYHVVT1Wf3OwAAASA"] [Tue Aug 18 13:06:03.540204 2026] [security2:error] [pid 157386:tid 157619] [client 158.23.17.4:14051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/an.php"] [unique_id "aoSC601jzAhYHVVT1Wf3PAAAAXE"] [Tue Aug 18 13:06:03.598830 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:2864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/special.php"] [unique_id "aoSC601jzAhYHVVT1Wf3QgAAAU4"] [Tue Aug 18 13:06:03.642233 2026] [security2:error] [pid 157386:tid 157599] [client 168.62.48.100:18136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC601jzAhYHVVT1Wf3RAAAAV0"] [Tue Aug 18 13:06:03.651972 2026] [security2:error] [pid 157386:tid 157565] [client 74.248.130.103:56980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/fling.php"] [unique_id "aoSC601jzAhYHVVT1Wf3RQAAATs"] [Tue Aug 18 13:06:03.668409 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ew.php"] [unique_id "aoSC601jzAhYHVVT1Wf3RgAAAWk"] [Tue Aug 18 13:06:03.686195 2026] [security2:error] [pid 157386:tid 157547] [client 34.38.184.238:48138] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.github/workflows/publish.yml"] [unique_id "aoSC601jzAhYHVVT1Wf3SQAAASk"] [Tue Aug 18 13:06:03.687342 2026] [security2:error] [pid 157386:tid 157517] [client 52.173.121.69:35129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/rezor.php"] [unique_id "aoSC601jzAhYHVVT1Wf3SgAAAQs"] [Tue Aug 18 13:06:03.730296 2026] [security2:error] [pid 157386:tid 157550] [client 34.38.184.238:48192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/www/.env"] [unique_id "aoSC601jzAhYHVVT1Wf3TQAAASw"] [Tue Aug 18 13:06:03.765853 2026] [security2:error] [pid 157386:tid 157612] [client 20.250.13.23:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/ebs.php7"] [unique_id "aoSC601jzAhYHVVT1Wf3TwAAAWo"] [Tue Aug 18 13:06:03.846872 2026] [security2:error] [pid 157386:tid 157609] [client 102.213.179.104:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3VAAAAWc"] [Tue Aug 18 13:06:03.859245 2026] [security2:error] [pid 157386:tid 157631] [client 68.155.156.252:65404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/new.php"] [unique_id "aoSC601jzAhYHVVT1Wf3VQAAAX0"] [Tue Aug 18 13:06:03.916768 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.49.167:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/bs1.php"] [unique_id "aoSC601jzAhYHVVT1Wf3VgAAAXU"] [Tue Aug 18 13:06:03.926565 2026] [security2:error] [pid 157386:tid 157629] [client 34.38.184.238:48080] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.vercel/.env.development.local"] [unique_id "aoSC601jzAhYHVVT1Wf3VwAAAXs"] [Tue Aug 18 13:06:03.938371 2026] [security2:error] [pid 157386:tid 157632] [client 34.38.184.238:48096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.travis.yml"] [unique_id "aoSC601jzAhYHVVT1Wf3WgAAAX4"] [Tue Aug 18 13:06:03.944185 2026] [security2:error] [pid 157386:tid 157558] [client 20.171.51.14:38773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vo.php"] [unique_id "aoSC601jzAhYHVVT1Wf3XAAAATQ"] [Tue Aug 18 13:06:04.032337 2026] [security2:error] [pid 157386:tid 157603] [client 168.62.48.100:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/weozh.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3XQAAAWE"] [Tue Aug 18 13:06:04.075786 2026] [security2:error] [pid 157386:tid 157585] [client 20.151.109.219:65020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/mimes.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3XgAAAU8"] [Tue Aug 18 13:06:04.088515 2026] [security2:error] [pid 157386:tid 157569] [client 20.25.139.174:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3XwAAAT8"] [Tue Aug 18 13:06:04.133412 2026] [security2:error] [pid 157386:tid 157520] [client 20.215.241.237:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/media.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3YQAAAQ4"] [Tue Aug 18 13:06:04.168296 2026] [security2:error] [pid 157386:tid 157593] [client 20.116.17.175:1640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3YgAAAVc"] [Tue Aug 18 13:06:04.177911 2026] [security2:error] [pid 157386:tid 157582] [client 20.38.3.247:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/wpxml.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3YwAAAUw"] [Tue Aug 18 13:06:04.192858 2026] [security2:error] [pid 157386:tid 157530] [client 20.250.13.23:26466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/min.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3ZAAAARg"] [Tue Aug 18 13:06:04.316606 2026] [autoindex:error] [pid 157386:tid 157456] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:04.361095 2026] [security2:error] [pid 157386:tid 157610] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3aAAAAWg"] [Tue Aug 18 13:06:04.433961 2026] [security2:error] [pid 157386:tid 157643] [client 20.171.51.14:7889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wu.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3awAAAYk"] [Tue Aug 18 13:06:04.452135 2026] [autoindex:error] [pid 157386:tid 157532] [client 66.132.195.35:32092] AH01276: Cannot serve directory /home4/vaicercom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:04.524369 2026] [security2:error] [pid 157386:tid 157516] [client 20.206.73.37:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/mgrr.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3cgAAAQo"] [Tue Aug 18 13:06:04.526390 2026] [security2:error] [pid 157386:tid 157619] [client 34.38.184.238:48126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.netlify/.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3cwAAAXE"] [Tue Aug 18 13:06:04.588822 2026] [security2:error] [pid 157386:tid 157542] [client 49.37.150.8:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3dAAAASQ"] [Tue Aug 18 13:06:04.588939 2026] [security2:error] [pid 157386:tid 157542] [client 49.37.150.8:64845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3dAAAASQ"] [Tue Aug 18 13:06:04.609932 2026] [security2:error] [pid 157386:tid 157617] [client 178.153.171.161:28127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "400"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3FwAAAW8"] [Tue Aug 18 13:06:04.617513 2026] [security2:error] [pid 157386:tid 157565] [client 20.171.51.14:30227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/qo.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3dQAAATs"] [Tue Aug 18 13:06:04.636917 2026] [security2:error] [pid 157386:tid 157595] [client 158.23.17.4:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sy.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3dgAAAVk"] [Tue Aug 18 13:06:04.643027 2026] [security2:error] [pid 157386:tid 157547] [client 168.62.48.100:4191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3dwAAASk"] [Tue Aug 18 13:06:04.706701 2026] [security2:error] [pid 157386:tid 157586] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3gQAAAVA"] [Tue Aug 18 13:06:04.749457 2026] [security2:error] [pid 157386:tid 157529] [client 20.116.17.175:20422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3hAAAARc"] [Tue Aug 18 13:06:04.772470 2026] [security2:error] [pid 157386:tid 157626] [client 20.104.49.167:48569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/hp2.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3hwAAAXg"] [Tue Aug 18 13:06:04.786064 2026] [security2:error] [pid 157386:tid 157631] [client 34.38.184.238:48142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/supabase/.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3iAAAAX0"] [Tue Aug 18 13:06:04.786799 2026] [security2:error] [pid 157386:tid 157577] [client 34.38.184.238:34522] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC7E1jzAhYHVVT1Wf3iQAAAUc"] [Tue Aug 18 13:06:04.798910 2026] [security2:error] [pid 157386:tid 157629] [client 34.38.184.238:48098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.supabase/.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3igAAAXs"] [Tue Aug 18 13:06:04.799613 2026] [core:error] [pid 157386:tid 157632] [client 34.38.184.238:34580] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../.env) [Tue Aug 18 13:06:04.832922 2026] [security2:error] [pid 157386:tid 157587] [client 20.1.169.243:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/random_compat/bala.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3jAAAAVE"] [Tue Aug 18 13:06:04.857064 2026] [security2:error] [pid 157386:tid 157534] [client 68.221.73.131:37554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/222.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3jQAAARw"] [Tue Aug 18 13:06:04.859167 2026] [security2:error] [pid 157386:tid 157641] [client 40.74.65.169:4568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/media.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3jgAAAYc"] [Tue Aug 18 13:06:04.860300 2026] [security2:error] [pid 157386:tid 157606] [client 86.120.159.145:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3jwAAAWQ"] [Tue Aug 18 13:06:04.945259 2026] [security2:error] [pid 157386:tid 157601] [client 34.38.184.238:48060] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSC7E1jzAhYHVVT1Wf3lQAAAV8"] [Tue Aug 18 13:06:04.947658 2026] [core:error] [pid 157386:tid 157540] [client 34.38.184.238:48048] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:06:04.947658 2026] [core:error] [pid 157386:tid 157573] [client 34.38.184.238:48100] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 13:06:04.947734 2026] [security2:error] [pid 157386:tid 157628] [client 34.38.184.238:48066] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC7E1jzAhYHVVT1Wf3mQAAAXo"] [Tue Aug 18 13:06:04.948900 2026] [security2:error] [pid 157386:tid 157592] [client 34.38.184.238:48202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/..;/.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3mAAAAVY"] [Tue Aug 18 13:06:04.948930 2026] [security2:error] [pid 157386:tid 157530] [client 34.38.184.238:48224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/static/..;/.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3mgAAARg"] [Tue Aug 18 13:06:04.950059 2026] [security2:error] [pid 157386:tid 157589] [client 34.38.184.238:48128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/..%2F..%2F..%2F..%2F..%2F.env"] [unique_id "aoSC7E1jzAhYHVVT1Wf3mwAAAVM"] [Tue Aug 18 13:06:04.968151 2026] [security2:error] [pid 157386:tid 157561] [client 4.223.113.180:40917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/manager.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3nwAAATc"] [Tue Aug 18 13:06:05.014253 2026] [security2:error] [pid 157386:tid 157609] [client 102.213.179.104:50055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3VAAAAWc"] [Tue Aug 18 13:06:05.140159 2026] [security2:error] [pid 157386:tid 157580] [client 196.12.128.158:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3ogAAAUo"] [Tue Aug 18 13:06:05.140288 2026] [security2:error] [pid 157386:tid 157580] [client 196.12.128.158:58479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3ogAAAUo"] [Tue Aug 18 13:06:05.154041 2026] [security2:error] [pid 157386:tid 157548] [client 20.25.139.174:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/vx.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3pAAAASo"] [Tue Aug 18 13:06:05.339864 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:12906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/fraie1p4.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3rAAAAVk"] [Tue Aug 18 13:06:05.351965 2026] [security2:error] [pid 157386:tid 157517] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3rwAAAQs"] [Tue Aug 18 13:06:05.486640 2026] [security2:error] [pid 157386:tid 157542] [client 20.250.13.23:18541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3swAAASQ"] [Tue Aug 18 13:06:05.549667 2026] [security2:error] [pid 157386:tid 157599] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/wp-title.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3uAAAAV0"] [Tue Aug 18 13:06:05.561635 2026] [security2:error] [pid 157386:tid 157593] [client 34.38.184.238:48142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env.orig"] [unique_id "aoSC7U1jzAhYHVVT1Wf3uQAAAVc"] [Tue Aug 18 13:06:05.569498 2026] [security2:error] [pid 157386:tid 157594] [client 20.250.13.23:40411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/ms-edit.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3ugAAAVg"] [Tue Aug 18 13:06:05.586195 2026] [security2:error] [pid 157386:tid 157527] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC6U1jzAhYHVVT1Wf2tQABFW8"] [Tue Aug 18 13:06:05.602512 2026] [core:error] [pid 157386:tid 157573] [client 34.38.184.238:48148] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:06:05.621912 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:53839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/txets.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3vAAAARg"] [Tue Aug 18 13:06:05.672818 2026] [security2:error] [pid 157386:tid 157536] [client 20.171.51.14:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/sd.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3wAAAAR4"] [Tue Aug 18 13:06:05.719214 2026] [security2:error] [pid 157386:tid 157575] [client 223.185.37.47:24576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC601jzAhYHVVT1Wf3LwAAAUU"] [Tue Aug 18 13:06:05.719975 2026] [security2:error] [pid 157386:tid 157607] [client 34.38.184.238:48234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env"] [unique_id "aoSC7U1jzAhYHVVT1Wf3xQAAAWU"] [Tue Aug 18 13:06:05.730434 2026] [security2:error] [pid 157386:tid 157581] [client 20.118.133.132:61353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/special.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3yAAAAUs"] [Tue Aug 18 13:06:05.732070 2026] [security2:error] [pid 157386:tid 157606] [client 86.120.159.145:20922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7E1jzAhYHVVT1Wf3jwAAAWQ"] [Tue Aug 18 13:06:05.791879 2026] [security2:error] [pid 157386:tid 157567] [client 158.158.74.177:20503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3yQAAAT0"] [Tue Aug 18 13:06:05.834511 2026] [security2:error] [pid 157386:tid 157548] [client 68.221.73.131:37558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3zQAAASo"] [Tue Aug 18 13:06:06.129529 2026] [security2:error] [pid 157386:tid 157550] [client 20.151.109.219:39871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pqr.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf31AAAASw"] [Tue Aug 18 13:06:06.179933 2026] [security2:error] [pid 157386:tid 157529] [client 20.116.17.175:22650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf32AAAARc"] [Tue Aug 18 13:06:06.187429 2026] [security2:error] [pid 157386:tid 157577] [client 168.62.48.100:18149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/rymmm.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf32QAAAUc"] [Tue Aug 18 13:06:06.256647 2026] [security2:error] [pid 157386:tid 157587] [client 20.104.49.167:12755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/yb.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf32wAAAVE"] [Tue Aug 18 13:06:06.262023 2026] [security2:error] [pid 157386:tid 157519] [client 20.215.241.237:34432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/images.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf33QAAAQ0"] [Tue Aug 18 13:06:06.331026 2026] [security2:error] [pid 157386:tid 157539] [client 20.171.51.14:47135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/de.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf33wAAASE"] [Tue Aug 18 13:06:06.348700 2026] [security2:error] [pid 157386:tid 157552] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/styles.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf34AAAAS4"] [Tue Aug 18 13:06:06.424588 2026] [security2:error] [pid 157386:tid 157573] [client 20.116.17.175:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf35QAAAUM"] [Tue Aug 18 13:06:06.431180 2026] [security2:error] [pid 157386:tid 157592] [client 34.38.184.238:48020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/client/.env"] [unique_id "aoSC7k1jzAhYHVVT1Wf35gAAAVY"] [Tue Aug 18 13:06:06.485951 2026] [security2:error] [pid 157386:tid 157613] [client 168.62.48.100:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf36AAAAWs"] [Tue Aug 18 13:06:06.519249 2026] [security2:error] [pid 157386:tid 157581] [client 168.62.48.100:18126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/lddxs.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf37AAAAUs"] [Tue Aug 18 13:06:06.521350 2026] [security2:error] [pid 157386:tid 157623] [client 18.192.166.72:58438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3vQAAAXU"], referer: https://www.meucrescer.com.br [Tue Aug 18 13:06:06.567748 2026] [security2:error] [pid 157386:tid 157547] [client 34.38.184.238:48274] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env.yml"] [unique_id "aoSC7k1jzAhYHVVT1Wf37gAAASk"] [Tue Aug 18 13:06:06.624531 2026] [security2:error] [pid 157386:tid 157569] [client 213.202.253.4:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/gdftps.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf38AAAAT8"], referer: www.google.com [Tue Aug 18 13:06:06.625679 2026] [security2:error] [pid 157386:tid 157580] [client 40.74.65.169:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/admin.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf38wAAAUo"] [Tue Aug 18 13:06:06.627365 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.49.167:12747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/vc.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf39AAAAYk"] [Tue Aug 18 13:06:06.643806 2026] [security2:error] [pid 157386:tid 157584] [client 20.104.100.201:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/mcs.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf39gAAAU4"] [Tue Aug 18 13:06:06.646491 2026] [security2:error] [pid 157386:tid 157578] [client 34.38.184.238:48016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/backend/api/.env"] [unique_id "aoSC7k1jzAhYHVVT1Wf39wAAAUg"] [Tue Aug 18 13:06:06.650449 2026] [security2:error] [pid 157386:tid 157574] [client 20.104.100.201:54039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/img.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf3-AAAAUQ"] [Tue Aug 18 13:06:06.664595 2026] [security2:error] [pid 157386:tid 157563] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/server.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf3-QAAATk"] [Tue Aug 18 13:06:06.685690 2026] [security2:error] [pid 157386:tid 157526] [client 37.40.227.74:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3vwAAARQ"] [Tue Aug 18 13:06:06.711520 2026] [security2:error] [pid 157386:tid 157604] [client 34.38.184.238:48192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/app/api/.env"] [unique_id "aoSC7k1jzAhYHVVT1Wf3-wAAAWI"] [Tue Aug 18 13:06:06.770349 2026] [security2:error] [pid 157386:tid 157564] [client 68.155.156.252:49760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/apreset.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf3_QAAATo"] [Tue Aug 18 13:06:06.772496 2026] [security2:error] [pid 157386:tid 157517] [client 20.1.169.243:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/simplepie/library/simplepie/about.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf3_gAAAQs"] [Tue Aug 18 13:06:06.772597 2026] [security2:error] [pid 157386:tid 157568] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/an.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf3_wAAAT4"] [Tue Aug 18 13:06:06.806009 2026] [security2:error] [pid 157386:tid 157586] [client 20.171.51.14:13412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/album.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4AQAAAVA"] [Tue Aug 18 13:06:06.854265 2026] [security2:error] [pid 157386:tid 157411] [remote 103.56.163.133:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3zAABJxg"] [Tue Aug 18 13:06:06.855402 2026] [core:notice] [pid 157386:tid 157496] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:06:06.855599 2026] [security2:error] [pid 157386:tid 157632] [client 34.38.184.238:48126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/laravel/.env"] [unique_id "aoSC7k1jzAhYHVVT1Wf4AgAAAX4"] [Tue Aug 18 13:06:06.865295 2026] [security2:error] [pid 157386:tid 157583] [client 20.25.139.174:4823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4BgAAAU0"] [Tue Aug 18 13:06:06.869497 2026] [security2:error] [pid 157386:tid 157542] [client 4.223.113.180:35229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/csv.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4BwAAASQ"] [Tue Aug 18 13:06:06.881607 2026] [security2:error] [pid 157386:tid 157519] [client 20.206.73.37:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/bajah.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4CAAAAQ0"] [Tue Aug 18 13:06:06.921496 2026] [autoindex:error] [pid 157386:tid 157558] [client 20.250.13.23:30074] AH01276: Cannot serve directory /home2/luceanjocom/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:06.939079 2026] [security2:error] [pid 157386:tid 157603] [client 168.62.48.100:18168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/zjggu.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4DgAAAWE"] [Tue Aug 18 13:06:06.949257 2026] [security2:error] [pid 157386:tid 157634] [client 34.38.184.238:48222] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSC7k1jzAhYHVVT1Wf4DwAAAYA"] [Tue Aug 18 13:06:06.950832 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/xinfo.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf4EAAAASM"] [Tue Aug 18 13:06:06.971052 2026] [security2:error] [pid 157386:tid 157552] [client 34.38.184.238:48098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config/.env.production"] [unique_id "aoSC7k1jzAhYHVVT1Wf4EQAAAS4"] [Tue Aug 18 13:06:07.013597 2026] [security2:error] [pid 157386:tid 157540] [client 158.23.17.4:63035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/57.php"] [unique_id "aoSC701jzAhYHVVT1Wf4FQAAASI"] [Tue Aug 18 13:06:07.032922 2026] [security2:error] [pid 157386:tid 157573] [client 34.38.184.238:49942] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/proxy"] [unique_id "aoSC701jzAhYHVVT1Wf4FgAAAUM"] [Tue Aug 18 13:06:07.037104 2026] [security2:error] [pid 157386:tid 157592] [client 34.38.184.238:48224] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC701jzAhYHVVT1Wf4FwAAAVY"] [Tue Aug 18 13:06:07.055965 2026] [security2:error] [pid 157386:tid 157613] [client 20.206.73.37:15783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/fz.php"] [unique_id "aoSC701jzAhYHVVT1Wf4GgAAAWs"] [Tue Aug 18 13:06:07.059894 2026] [security2:error] [pid 157386:tid 157607] [client 74.248.130.103:7933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/zoo1.php"] [unique_id "aoSC701jzAhYHVVT1Wf4GwAAAWU"] [Tue Aug 18 13:06:07.062745 2026] [security2:error] [pid 157386:tid 157635] [client 20.250.13.23:18516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSC701jzAhYHVVT1Wf4HAAAAYE"] [Tue Aug 18 13:06:07.066812 2026] [security2:error] [pid 157386:tid 157610] [client 20.25.139.174:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wap.php"] [unique_id "aoSC701jzAhYHVVT1Wf4HQAAAWg"] [Tue Aug 18 13:06:07.092079 2026] [security2:error] [pid 157386:tid 157554] [client 34.38.184.238:47952] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.env.sample"] [unique_id "aoSC701jzAhYHVVT1Wf4HwAAATA"] [Tue Aug 18 13:06:07.147255 2026] [security2:error] [pid 157386:tid 157557] [client 34.38.184.238:34530] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/application.env"] [unique_id "aoSC701jzAhYHVVT1Wf4IgAAATM"] [Tue Aug 18 13:06:07.148346 2026] [security2:error] [pid 157386:tid 157546] [client 34.38.184.238:34540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/frontend/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4IQAAASg"] [Tue Aug 18 13:06:07.177117 2026] [security2:error] [pid 157386:tid 157580] [client 51.75.236.138:21734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hmanyhands.com.br"] [uri "/robots.txt"] [unique_id "aoSC701jzAhYHVVT1Wf4JAAAAUo"] [Tue Aug 18 13:06:07.177928 2026] [security2:error] [pid 157386:tid 157580] [client 51.75.236.138:21734] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hmanyhands.com.br"] [uri "/robots.txt"] [unique_id "aoSC701jzAhYHVVT1Wf4JAAAAUo"] [Tue Aug 18 13:06:07.199910 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.100.201:53848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/admin.php"] [unique_id "aoSC701jzAhYHVVT1Wf4JwAAAYk"] [Tue Aug 18 13:06:07.251857 2026] [security2:error] [pid 157386:tid 157578] [client 168.62.48.100:18054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/dlvqo.php"] [unique_id "aoSC701jzAhYHVVT1Wf4KQAAAUg"] [Tue Aug 18 13:06:07.265426 2026] [security2:error] [pid 157386:tid 157556] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/sym.php"] [unique_id "aoSC701jzAhYHVVT1Wf4KgAAATI"] [Tue Aug 18 13:06:07.297329 2026] [security2:error] [pid 157386:tid 157559] [client 34.38.184.238:47958] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/development/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4LQAAATU"] [Tue Aug 18 13:06:07.300662 2026] [security2:error] [pid 157386:tid 157617] [client 34.38.184.238:48234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/prod/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4LwAAAW8"] [Tue Aug 18 13:06:07.333646 2026] [security2:error] [pid 157386:tid 157611] [client 20.171.51.14:20409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/km.php"] [unique_id "aoSC701jzAhYHVVT1Wf4MAAAAWk"] [Tue Aug 18 13:06:07.375605 2026] [security2:error] [pid 157386:tid 157568] [client 40.74.65.169:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/mac.php"] [unique_id "aoSC701jzAhYHVVT1Wf4MgAAAT4"] [Tue Aug 18 13:06:07.410552 2026] [security2:error] [pid 157386:tid 157626] [client 34.38.184.238:48016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/ci/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4MwAAAXg"] [Tue Aug 18 13:06:07.423574 2026] [security2:error] [pid 157386:tid 157529] [client 34.38.184.238:48142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/internal/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4NAAAARc"] [Tue Aug 18 13:06:07.434595 2026] [security2:error] [pid 157386:tid 157545] [client 34.38.184.238:47966] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/staging/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4NgAAASc"] [Tue Aug 18 13:06:07.435904 2026] [security2:error] [pid 157386:tid 157577] [client 34.38.184.238:48178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/production/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4NQAAAUc"] [Tue Aug 18 13:06:07.493992 2026] [security2:error] [pid 157386:tid 157583] [client 34.38.184.238:48126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/html/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4OAAAAU0"] [Tue Aug 18 13:06:07.499251 2026] [security2:error] [pid 157386:tid 157542] [client 20.226.36.136:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSC701jzAhYHVVT1Wf4OgAAASQ"] [Tue Aug 18 13:06:07.506115 2026] [security2:error] [pid 157386:tid 157620] [client 20.25.139.174:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/gecko-new.php"] [unique_id "aoSC701jzAhYHVVT1Wf4OwAAAXI"] [Tue Aug 18 13:06:07.554064 2026] [security2:error] [pid 157386:tid 157633] [client 168.62.48.100:18067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/pkmoj.php"] [unique_id "aoSC701jzAhYHVVT1Wf4PAAAAX8"] [Tue Aug 18 13:06:07.575740 2026] [security2:error] [pid 157386:tid 157603] [client 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foxalpha.com.br"] [uri "/ye.php"] [unique_id "aoSC701jzAhYHVVT1Wf4PQAAAWE"] [Tue Aug 18 13:06:07.627346 2026] [security2:error] [pid 157386:tid 157634] [client 34.38.184.238:48192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/services/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4QAAAAYA"] [Tue Aug 18 13:06:07.703567 2026] [security2:error] [pid 157386:tid 157599] [client 34.38.184.238:48128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.env~"] [unique_id "aoSC701jzAhYHVVT1Wf4QgAAAV0"] [Tue Aug 18 13:06:07.741799 2026] [security2:error] [pid 157386:tid 157573] [client 34.38.184.238:48002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/old/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4RQAAAUM"] [Tue Aug 18 13:06:07.790924 2026] [security2:error] [pid 157386:tid 157561] [client 78.47.173.76:57312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.meucrescer.com.br"] [uri "/index.php"] [unique_id "aoSC701jzAhYHVVT1Wf4QwAAATc"], referer: https://www.meucrescer.com.br [Tue Aug 18 13:06:07.791567 2026] [security2:error] [pid 157386:tid 157600] [client 20.127.136.245:28279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/elp.php"] [unique_id "aoSC701jzAhYHVVT1Wf4RgAAAV4"] [Tue Aug 18 13:06:07.835943 2026] [security2:error] [pid 157386:tid 157635] [client 34.38.184.238:34528] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC701jzAhYHVVT1Wf4SAAAAYE"] [Tue Aug 18 13:06:07.841925 2026] [security2:error] [pid 157386:tid 157536] [client 34.38.184.238:47850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/private/.env"] [unique_id "aoSC701jzAhYHVVT1Wf4SQAAAR4"] [Tue Aug 18 13:06:07.843688 2026] [security2:error] [pid 157386:tid 157581] [client 168.62.48.100:18086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/kopyw.php"] [unique_id "aoSC701jzAhYHVVT1Wf4SgAAAUs"] [Tue Aug 18 13:06:07.854961 2026] [security2:error] [pid 157386:tid 157582] [client 158.158.74.177:20484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSC701jzAhYHVVT1Wf4SwAAAUw"] [Tue Aug 18 13:06:07.880328 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:15698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/simplepie/library/simplepie/min.php"] [unique_id "aoSC701jzAhYHVVT1Wf4TAAAAYc"] [Tue Aug 18 13:06:08.100449 2026] [security2:error] [pid 157386:tid 157605] [client 20.116.17.175:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/cok.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4WQAAAWM"] [Tue Aug 18 13:06:08.135630 2026] [security2:error] [pid 157386:tid 157569] [client 40.74.65.169:4860] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/1.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4XAAAAT8"] [Tue Aug 18 13:06:08.135711 2026] [security2:error] [pid 157386:tid 157569] [client 40.74.65.169:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/1.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4XAAAAT8"] [Tue Aug 18 13:06:08.176376 2026] [security2:error] [pid 157386:tid 157611] [client 168.62.48.100:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4XQAAAWk"] [Tue Aug 18 13:06:08.200065 2026] [security2:error] [pid 157386:tid 157576] [client 68.221.73.131:27361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4XgAAAUY"] [Tue Aug 18 13:06:08.258350 2026] [security2:error] [pid 157386:tid 157525] [client 20.250.13.23:30074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/php8.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4XwAAARM"] [Tue Aug 18 13:06:08.296757 2026] [security2:error] [pid 157386:tid 157507] [remote 188.164.197.230:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSC7k1jzAhYHVVT1Wf32gABeng"] [Tue Aug 18 13:06:08.296836 2026] [security2:error] [pid 157386:tid 157529] [client 74.249.206.207:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/abcd.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4YQAAARc"] [Tue Aug 18 13:06:08.304189 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4YgAAAX4"] [Tue Aug 18 13:06:08.340077 2026] [security2:error] [pid 157386:tid 157642] [client 34.38.184.238:34752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC8E1jzAhYHVVT1Wf4ZAAAAYg"] [Tue Aug 18 13:06:08.367046 2026] [security2:error] [pid 157386:tid 157620] [client 34.38.184.238:34722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/crm/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4ZgAAAXI"] [Tue Aug 18 13:06:08.397712 2026] [security2:error] [pid 157386:tid 157549] [client 34.38.184.238:34788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/application/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4ZwAAASs"] [Tue Aug 18 13:06:08.400995 2026] [security2:error] [pid 157386:tid 157558] [client 157.20.138.62:64526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4aAAAATQ"] [Tue Aug 18 13:06:08.401210 2026] [security2:error] [pid 157386:tid 157558] [client 157.20.138.62:64526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4aAAAATQ"] [Tue Aug 18 13:06:08.462739 2026] [security2:error] [pid 157386:tid 157544] [client 34.38.184.238:48032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/proxy?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/proxy"] [unique_id "aoSC8E1jzAhYHVVT1Wf4awAAASY"] [Tue Aug 18 13:06:08.462808 2026] [security2:error] [pid 157386:tid 157564] [client 104.222.31.70:33328] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "fbenevides.com"] [uri "/node/1"] [unique_id "aoSC8E1jzAhYHVVT1Wf4bAAAATo"] [Tue Aug 18 13:06:08.477775 2026] [security2:error] [pid 157386:tid 157634] [client 34.38.184.238:34540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/backup/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4bgAAAYA"] [Tue Aug 18 13:06:08.479488 2026] [security2:error] [pid 157386:tid 157541] [client 34.38.184.238:48026] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/app/.env.production"] [unique_id "aoSC8E1jzAhYHVVT1Wf4bwAAASM"] [Tue Aug 18 13:06:08.562392 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:34798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/v2/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4cgAAARs"] [Tue Aug 18 13:06:08.585284 2026] [security2:error] [pid 157386:tid 157528] [client 34.38.184.238:34576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/conf/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4cwAAARY"] [Tue Aug 18 13:06:08.603907 2026] [security2:error] [pid 157386:tid 157530] [client 34.38.184.238:34560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/backend/.env.local"] [unique_id "aoSC8E1jzAhYHVVT1Wf4dQAAARg"] [Tue Aug 18 13:06:08.607928 2026] [security2:error] [pid 157386:tid 157573] [client 34.38.184.238:47940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/phpinfo.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4dwAAAUM"] [Tue Aug 18 13:06:08.662244 2026] [security2:error] [pid 157386:tid 157561] [client 15.235.98.183:26976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hmanyhands.com.br"] [uri "/"] [unique_id "aoSC8E1jzAhYHVVT1Wf4egAAATc"] [Tue Aug 18 13:06:08.662342 2026] [security2:error] [pid 157386:tid 157561] [client 15.235.98.183:26976] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hmanyhands.com.br"] [uri "/"] [unique_id "aoSC8E1jzAhYHVVT1Wf4egAAATc"] [Tue Aug 18 13:06:08.736412 2026] [security2:error] [pid 157386:tid 157536] [client 34.38.184.238:48020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/docker/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4gQAAAR4"] [Tue Aug 18 13:06:08.809817 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:1649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4hwAAAYc"] [Tue Aug 18 13:06:08.886997 2026] [security2:error] [pid 157386:tid 157553] [client 20.1.169.243:15976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/text/diff/renderer/install.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4igAAAS8"] [Tue Aug 18 13:06:08.892548 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/coffee.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4jAAAARw"] [Tue Aug 18 13:06:08.897058 2026] [security2:error] [pid 157386:tid 157580] [client 34.38.184.238:34602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.docker/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4jQAAAUo"] [Tue Aug 18 13:06:08.905890 2026] [security2:error] [pid 157386:tid 157584] [client 20.206.73.37:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/h.php"] [unique_id "aoSC8E1jzAhYHVVT1Wf4kAAAAU4"] [Tue Aug 18 13:06:08.905950 2026] [security2:error] [pid 157386:tid 157560] [client 34.38.184.238:34612] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSC8E1jzAhYHVVT1Wf4kQAAATY"] [Tue Aug 18 13:06:08.947118 2026] [security2:error] [pid 157386:tid 157547] [client 34.38.184.238:34616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/apps/.env"] [unique_id "aoSC8E1jzAhYHVVT1Wf4kwAAASk"] [Tue Aug 18 13:06:09.030702 2026] [security2:error] [pid 157386:tid 157585] [client 34.38.184.238:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "aoSC8U1jzAhYHVVT1Wf4lgAAAU8"] [Tue Aug 18 13:06:09.048677 2026] [security2:error] [pid 157386:tid 157569] [client 34.38.184.238:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/config/.env.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4lwAAAT8"] [Tue Aug 18 13:06:09.084212 2026] [security2:error] [pid 157386:tid 157619] [client 74.248.130.103:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/zoo2.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4mQAAAXE"] [Tue Aug 18 13:06:09.127849 2026] [security2:error] [pid 157386:tid 157588] [client 158.158.74.177:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4nAAAAVI"] [Tue Aug 18 13:06:09.242985 2026] [security2:error] [pid 157386:tid 157426] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4ngABiCc"] [Tue Aug 18 13:06:09.243231 2026] [security2:error] [pid 157386:tid 157642] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4ngABiCc"] [Tue Aug 18 13:06:09.254652 2026] [security2:error] [pid 157386:tid 157542] [client 34.38.184.238:48178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/v1/.env"] [unique_id "aoSC8U1jzAhYHVVT1Wf4nwAAASQ"] [Tue Aug 18 13:06:09.256077 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:20356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/accesson.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4oAAAAUk"] [Tue Aug 18 13:06:09.340372 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:12888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/pqr.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4pAAAAX8"] [Tue Aug 18 13:06:09.342280 2026] [security2:error] [pid 157386:tid 157545] [client 20.1.169.243:15612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/themes.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4pQAAASc"] [Tue Aug 18 13:06:09.384367 2026] [security2:error] [pid 157386:tid 157577] [client 34.38.184.238:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/twilio/.env.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4pgAAAUc"] [Tue Aug 18 13:06:09.407009 2026] [security2:error] [pid 157386:tid 157564] [client 20.171.51.14:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/mf.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4pwAAATo"] [Tue Aug 18 13:06:09.417627 2026] [security2:error] [pid 157386:tid 157634] [client 20.104.100.201:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/index.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4qAAAAYA"] [Tue Aug 18 13:06:09.427081 2026] [security2:error] [pid 157386:tid 157615] [client 20.127.136.245:28100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4qQAAAW0"] [Tue Aug 18 13:06:09.489367 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.100.201:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/adminner.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4qgAAAQ8"] [Tue Aug 18 13:06:09.510362 2026] [security2:error] [pid 157386:tid 157601] [client 34.38.184.238:48234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/_profiler/phpinfo.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4qwAAAV8"] [Tue Aug 18 13:06:09.563688 2026] [security2:error] [pid 157386:tid 157614] [client 20.171.51.14:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kv.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4rgAAAWw"] [Tue Aug 18 13:06:09.571674 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.36.136:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4rwAAAVQ"] [Tue Aug 18 13:06:09.572505 2026] [security2:error] [pid 157386:tid 157562] [client 34.38.184.238:47958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/sendgrid/.env.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4sAAAATg"] [Tue Aug 18 13:06:09.609681 2026] [security2:error] [pid 157386:tid 157548] [client 20.25.139.174:4843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/NewFile.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4sQAAASo"] [Tue Aug 18 13:06:09.638396 2026] [security2:error] [pid 157386:tid 157536] [client 34.38.184.238:34638] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/app_dev.php/_profiler/.env"] [unique_id "aoSC8U1jzAhYHVVT1Wf4sgAAAR4"] [Tue Aug 18 13:06:09.639958 2026] [security2:error] [pid 157386:tid 157635] [client 34.38.184.238:34652] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC8U1jzAhYHVVT1Wf4swAAAYE"] [Tue Aug 18 13:06:09.723315 2026] [autoindex:error] [pid 157386:tid 157475] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:09.751405 2026] [security2:error] [pid 157386:tid 157566] [client 34.38.184.238:48142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.openclaw/.env"] [unique_id "aoSC8U1jzAhYHVVT1Wf4uQAAATw"] [Tue Aug 18 13:06:09.854994 2026] [security2:error] [pid 157386:tid 157604] [client 20.116.17.175:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/av.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4uwAAAWI"] [Tue Aug 18 13:06:09.859107 2026] [security2:error] [pid 157386:tid 157597] [client 158.23.17.4:47647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ah.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4vAAAAVs"] [Tue Aug 18 13:06:09.926963 2026] [security2:error] [pid 157386:tid 157559] [client 20.118.133.132:8180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/fz.php"] [unique_id "aoSC8U1jzAhYHVVT1Wf4vwAAATU"] [Tue Aug 18 13:06:10.067326 2026] [authz_core:error] [pid 157386:tid 157428] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:10.067629 2026] [authz_core:error] [pid 157386:tid 157428] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:10.123862 2026] [security2:error] [pid 157386:tid 157598] [client 20.250.13.23:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/a7.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf4xQAAAVw"] [Tue Aug 18 13:06:10.139458 2026] [autoindex:error] [pid 157386:tid 157554] [client 169.58.72.248:52418] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:10.149361 2026] [security2:error] [pid 157386:tid 157577] [client 20.251.48.93:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf4ygAAAUc"] [Tue Aug 18 13:06:10.312012 2026] [security2:error] [pid 157386:tid 157533] [client 20.171.51.14:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ie.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf4zgAAARs"] [Tue Aug 18 13:06:10.422341 2026] [security2:error] [pid 157386:tid 157617] [client 168.62.48.100:18088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/zznmg.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf42AAAAW8"] [Tue Aug 18 13:06:10.455841 2026] [security2:error] [pid 157386:tid 157525] [client 20.25.139.174:4803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf42QAAARM"] [Tue Aug 18 13:06:10.482492 2026] [security2:error] [pid 157386:tid 157614] [client 20.116.17.175:20304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/kj.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf43AAAAWw"] [Tue Aug 18 13:06:10.499516 2026] [security2:error] [pid 157386:tid 157576] [client 178.153.171.161:45173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf43QAAAUY"] [Tue Aug 18 13:06:10.499661 2026] [security2:error] [pid 157386:tid 157576] [client 178.153.171.161:45173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf43QAAAUY"] [Tue Aug 18 13:06:10.517056 2026] [autoindex:error] [pid 157386:tid 157451] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:10.533556 2026] [security2:error] [pid 157386:tid 157575] [client 34.38.184.238:34752] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC8k1jzAhYHVVT1Wf43wAAAUU"] [Tue Aug 18 13:06:10.699258 2026] [security2:error] [pid 157386:tid 157641] [client 34.38.184.238:34704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/jenkins/.env"] [unique_id "aoSC8k1jzAhYHVVT1Wf45QAAAYc"] [Tue Aug 18 13:06:10.700980 2026] [security2:error] [pid 157386:tid 157561] [client 68.155.156.252:63186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/1mage.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf45gAAATc"] [Tue Aug 18 13:06:10.712110 2026] [security2:error] [pid 157386:tid 157524] [client 34.38.184.238:48192] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC8k1jzAhYHVVT1Wf45wAAARI"] [Tue Aug 18 13:06:10.822976 2026] [security2:error] [pid 157386:tid 157553] [client 74.248.130.103:54880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/org.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf47AAAAS8"] [Tue Aug 18 13:06:10.877997 2026] [security2:error] [pid 157386:tid 157587] [client 158.23.17.4:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vw.php"] [unique_id "aoSC8k1jzAhYHVVT1Wf47QAAAVE"] [Tue Aug 18 13:06:10.915293 2026] [security2:error] [pid 157386:tid 157550] [client 34.38.184.238:48002] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/aws/ecs/task-credentials"] [unique_id "aoSC8k1jzAhYHVVT1Wf47gAAASw"] [Tue Aug 18 13:06:11.100342 2026] [security2:error] [pid 157386:tid 157559] [client 20.38.3.247:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/file1221.php"] [unique_id "aoSC801jzAhYHVVT1Wf48AAAATU"] [Tue Aug 18 13:06:11.108294 2026] [security2:error] [pid 157386:tid 157517] [client 34.38.184.238:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/.env.php.bak"] [unique_id "aoSC801jzAhYHVVT1Wf48gAAAQs"] [Tue Aug 18 13:06:11.200067 2026] [security2:error] [pid 157386:tid 157534] [client 20.127.136.245:27990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/666.php"] [unique_id "aoSC801jzAhYHVVT1Wf49QAAARw"] [Tue Aug 18 13:06:11.300194 2026] [security2:error] [pid 157386:tid 157577] [client 142.132.180.39:56232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSC801jzAhYHVVT1Wf49wAAAUc"], referer: http://www.pinceisroma.com.br [Tue Aug 18 13:06:11.309694 2026] [security2:error] [pid 157386:tid 157615] [client 68.221.73.131:24494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp.php"] [unique_id "aoSC801jzAhYHVVT1Wf4-QAAAW0"] [Tue Aug 18 13:06:11.439818 2026] [security2:error] [pid 157386:tid 157630] [client 20.116.17.175:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSC801jzAhYHVVT1Wf4_QAAAXw"] [Tue Aug 18 13:06:11.481936 2026] [security2:error] [pid 157386:tid 157628] [client 34.38.184.238:34616] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSC801jzAhYHVVT1Wf5AAAAAXo"] [Tue Aug 18 13:06:11.492983 2026] [security2:error] [pid 157386:tid 157614] [client 34.38.184.238:48178] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/management/env"] [unique_id "aoSC801jzAhYHVVT1Wf5AQAAAWw"] [Tue Aug 18 13:06:11.500620 2026] [security2:error] [pid 157386:tid 157570] [client 20.206.73.37:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/55.php"] [unique_id "aoSC801jzAhYHVVT1Wf5AgAAAUA"] [Tue Aug 18 13:06:11.565350 2026] [security2:error] [pid 157386:tid 157582] [client 20.104.100.201:54033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSC801jzAhYHVVT1Wf5BAAAAUw"] [Tue Aug 18 13:06:11.594313 2026] [security2:error] [pid 157386:tid 157558] [client 34.38.184.238:34544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/dev/.env"] [unique_id "aoSC801jzAhYHVVT1Wf5BgAAATQ"] [Tue Aug 18 13:06:11.618296 2026] [security2:error] [pid 157386:tid 157625] [client 34.38.184.238:34670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC801jzAhYHVVT1Wf5CAAAAXc"] [Tue Aug 18 13:06:11.618764 2026] [security2:error] [pid 157386:tid 157584] [client 34.38.184.238:34952] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/root/.aws/config"] [unique_id "aoSC801jzAhYHVVT1Wf5CQAAAU4"] [Tue Aug 18 13:06:11.646650 2026] [security2:error] [pid 157386:tid 157635] [client 20.251.48.93:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC801jzAhYHVVT1Wf5CwAAAYE"] [Tue Aug 18 13:06:11.675628 2026] [security2:error] [pid 157386:tid 157532] [client 20.25.139.174:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/bgymj.php"] [unique_id "aoSC801jzAhYHVVT1Wf5DQAAARo"] [Tue Aug 18 13:06:11.696400 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:21663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/lmfi2.php"] [unique_id "aoSC801jzAhYHVVT1Wf5DgAAASY"] [Tue Aug 18 13:06:11.706267 2026] [security2:error] [pid 157386:tid 157574] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/404.php"] [unique_id "aoSC801jzAhYHVVT1Wf5DwAAAUQ"] [Tue Aug 18 13:06:11.714475 2026] [security2:error] [pid 157386:tid 157612] [client 34.38.184.238:34602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.hermes/.env"] [unique_id "aoSC801jzAhYHVVT1Wf5EAAAAWo"] [Tue Aug 18 13:06:11.728504 2026] [security2:error] [pid 157386:tid 157600] [client 213.35.127.232:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSC801jzAhYHVVT1Wf5EQAAAV4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:11.758580 2026] [security2:error] [pid 157386:tid 157566] [client 168.62.48.100:18120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/bhfnd.php"] [unique_id "aoSC801jzAhYHVVT1Wf5EwAAATw"] [Tue Aug 18 13:06:11.789207 2026] [security2:error] [pid 157386:tid 157580] [client 142.132.180.39:56238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pinceisroma.com.br"] [uri "/server.php"] [unique_id "aoSC801jzAhYHVVT1Wf5EgAAAUo"], referer: http://www.pinceisroma.com.br [Tue Aug 18 13:06:11.889147 2026] [security2:error] [pid 157386:tid 157517] [client 34.38.184.238:48016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/s3-credentials.bak"] [unique_id "aoSC801jzAhYHVVT1Wf5GAAAAQs"] [Tue Aug 18 13:06:11.965667 2026] [security2:error] [pid 157386:tid 157579] [client 34.38.184.238:34960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/aws/metadata/iam/security-credentials/"] [unique_id "aoSC801jzAhYHVVT1Wf5HgAAAUk"] [Tue Aug 18 13:06:11.984059 2026] [security2:error] [pid 157386:tid 157626] [client 34.38.184.238:35088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/aws/s3/credentials.bak"] [unique_id "aoSC801jzAhYHVVT1Wf5HwAAAXg"] [Tue Aug 18 13:06:11.991383 2026] [security2:error] [pid 157386:tid 157516] [client 103.120.71.157:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC801jzAhYHVVT1Wf5IQAAAQo"] [Tue Aug 18 13:06:11.991483 2026] [security2:error] [pid 157386:tid 157516] [client 103.120.71.157:52568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC801jzAhYHVVT1Wf5IQAAAQo"] [Tue Aug 18 13:06:12.036565 2026] [security2:error] [pid 157386:tid 157549] [client 20.206.73.37:40282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/ano.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5IgAAASs"] [Tue Aug 18 13:06:12.063195 2026] [security2:error] [pid 157386:tid 157633] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5IwAAAX8"] [Tue Aug 18 13:06:12.108603 2026] [security2:error] [pid 157386:tid 157541] [client 168.62.48.100:4206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5JQAAASM"] [Tue Aug 18 13:06:12.119500 2026] [autoindex:error] [pid 157386:tid 157518] [client 205.210.31.163:64962] AH01276: Cannot serve directory /home2/luceanjocom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:12.143462 2026] [security2:error] [pid 157386:tid 157552] [client 74.249.206.207:32638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/simple.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5JwAAAS4"] [Tue Aug 18 13:06:12.168533 2026] [security2:error] [pid 157386:tid 157533] [client 20.251.48.93:17032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/domvf.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5KAAAARs"] [Tue Aug 18 13:06:12.273696 2026] [security2:error] [pid 157386:tid 157558] [client 34.38.184.238:48202] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC9E1jzAhYHVVT1Wf5LAAAATQ"] [Tue Aug 18 13:06:12.305771 2026] [proxy:error] [pid 157386:tid 157638] (70007)The timeout specified has expired: [client 74.244.185.64:23774] AH01095: prefetch request body failed to 127.0.0.1:2095 (127.0.0.1) from 74.244.185.64 (), referer: http://webmail.esteticarvca.com.br/cpsess7158735704/3rdparty/roundcube/?_task=mail&_mbox=INBOX [Tue Aug 18 13:06:12.369634 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:15963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/themes/plugin-install.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5MgAAAYA"] [Tue Aug 18 13:06:12.370843 2026] [security2:error] [pid 157386:tid 157532] [client 20.116.17.175:45311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/output.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5MwAAARo"] [Tue Aug 18 13:06:12.389097 2026] [security2:error] [pid 157386:tid 157561] [client 34.38.184.238:34650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC9E1jzAhYHVVT1Wf5NAAAATc"] [Tue Aug 18 13:06:12.439946 2026] [security2:error] [pid 157386:tid 157587] [client 20.104.100.201:53850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/cong.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5NwAAAVE"] [Tue Aug 18 13:06:12.460027 2026] [security2:error] [pid 157386:tid 157548] [client 20.250.13.23:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/manager.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5OgAAASo"] [Tue Aug 18 13:06:12.547159 2026] [security2:error] [pid 157386:tid 157543] [client 34.38.184.238:34602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/pms"] [unique_id "aoSC9E1jzAhYHVVT1Wf5PgAAASU"] [Tue Aug 18 13:06:12.581139 2026] [security2:error] [pid 157386:tid 157535] [client 34.38.184.238:34596] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSC9E1jzAhYHVVT1Wf5QgAAAR0"] [Tue Aug 18 13:06:12.584092 2026] [security2:error] [pid 157386:tid 157529] [client 20.1.169.243:4997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/bthil.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5QwAAARc"] [Tue Aug 18 13:06:12.590593 2026] [security2:error] [pid 157386:tid 157404] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5RAABdRE"] [Tue Aug 18 13:06:12.590756 2026] [security2:error] [pid 157386:tid 157627] [client 74.249.206.207:64520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-manager.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5RQAAAXk"] [Tue Aug 18 13:06:12.590760 2026] [security2:error] [pid 157386:tid 157623] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5RAABdRE"] [Tue Aug 18 13:06:12.728981 2026] [security2:error] [pid 157386:tid 157517] [client 20.1.169.243:4501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/index/function.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5TQAAAQs"] [Tue Aug 18 13:06:12.776456 2026] [security2:error] [pid 157386:tid 157615] [client 20.127.136.245:27969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ws54.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5TgAAAW0"] [Tue Aug 18 13:06:12.776768 2026] [security2:error] [pid 157386:tid 157577] [client 68.155.156.252:35418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/imsc.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5TwAAAUc"] [Tue Aug 18 13:06:12.788492 2026] [security2:error] [pid 157386:tid 157630] [client 20.250.13.23:60969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5UAAAAXw"] [Tue Aug 18 13:06:12.924182 2026] [core:error] [pid 157386:tid 157570] [client 34.38.184.238:35224] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../root/.aws/credentials) [Tue Aug 18 13:06:12.933737 2026] [security2:error] [pid 157386:tid 157568] [client 34.38.184.238:35162] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/tmp/.aws/credentials"] [unique_id "aoSC9E1jzAhYHVVT1Wf5VwAAAT4"] [Tue Aug 18 13:06:12.974455 2026] [security2:error] [pid 157386:tid 157598] [client 20.25.139.174:4668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/aa.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5XQAAAVw"] [Tue Aug 18 13:06:12.976681 2026] [security2:error] [pid 157386:tid 157632] [client 34.38.184.238:35242] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Froot/.aws/credentials"] [unique_id "aoSC9E1jzAhYHVVT1Wf5XgAAAX4"] [Tue Aug 18 13:06:12.989846 2026] [core:error] [pid 157386:tid 157631] [client 34.38.184.238:35238] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/root/.aws/credentials) [Tue Aug 18 13:06:12.994882 2026] [security2:error] [pid 157386:tid 157540] [client 138.36.100.162:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5YAAAASI"] [Tue Aug 18 13:06:13.011290 2026] [security2:error] [pid 157386:tid 157588] [client 74.249.206.207:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/xiugai.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5YQAAAVI"] [Tue Aug 18 13:06:13.019028 2026] [security2:error] [pid 157386:tid 157620] [client 20.1.169.243:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/index.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5YgAAAXI"] [Tue Aug 18 13:06:13.021545 2026] [security2:error] [pid 157386:tid 157537] [client 34.38.184.238:35248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/pms"] [unique_id "aoSC9U1jzAhYHVVT1Wf5YwAAAR8"] [Tue Aug 18 13:06:13.060825 2026] [security2:error] [pid 157386:tid 157540] [client 138.36.100.162:41976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9E1jzAhYHVVT1Wf5YAAAASI"] [Tue Aug 18 13:06:13.063078 2026] [security2:error] [pid 157386:tid 157635] [client 34.38.184.238:34670] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC9U1jzAhYHVVT1Wf5ZAAAAYE"] [Tue Aug 18 13:06:13.144937 2026] [security2:error] [pid 157386:tid 157562] [client 4.223.113.180:11437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/404.php123123"] [unique_id "aoSC9U1jzAhYHVVT1Wf5aQAAATg"] [Tue Aug 18 13:06:13.152073 2026] [security2:error] [pid 157386:tid 157621] [client 34.38.184.238:35274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/aws/.env"] [unique_id "aoSC9U1jzAhYHVVT1Wf5agAAAXM"] [Tue Aug 18 13:06:13.161018 2026] [security2:error] [pid 157386:tid 157553] [client 34.38.184.238:34818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/proxy"] [unique_id "aoSC9U1jzAhYHVVT1Wf5awAAAS8"] [Tue Aug 18 13:06:13.166748 2026] [security2:error] [pid 157386:tid 157611] [client 20.116.17.175:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/png.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5bAAAAWk"] [Tue Aug 18 13:06:13.195632 2026] [security2:error] [pid 157386:tid 157603] [client 197.184.64.235:42680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5bQAAAWE"] [Tue Aug 18 13:06:13.195752 2026] [security2:error] [pid 157386:tid 157603] [client 197.184.64.235:42680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5bQAAAWE"] [Tue Aug 18 13:06:13.199315 2026] [security2:error] [pid 157386:tid 157601] [client 20.251.48.93:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5bgAAAV8"] [Tue Aug 18 13:06:13.221582 2026] [security2:error] [pid 157386:tid 157566] [client 68.221.73.131:7816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/i.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5bwAAATw"] [Tue Aug 18 13:06:13.271177 2026] [security2:error] [pid 157386:tid 157547] [client 20.25.139.174:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5cgAAASk"] [Tue Aug 18 13:06:13.289112 2026] [security2:error] [pid 157386:tid 157563] [client 213.35.127.232:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5dQAAATk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:13.333803 2026] [security2:error] [pid 157386:tid 157589] [client 20.151.109.219:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/info2.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5dwAAAVM"] [Tue Aug 18 13:06:13.361972 2026] [security2:error] [pid 157386:tid 157619] [client 85.208.98.31:38372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bjagricola.com.br"] [uri "/camperized-vans-for-sale-k.html"] [unique_id "aoSC9U1jzAhYHVVT1Wf5ewAAAXE"] [Tue Aug 18 13:06:13.362086 2026] [security2:error] [pid 157386:tid 157619] [client 85.208.98.31:38372] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/camperized-vans-for-sale-k.html"] [unique_id "aoSC9U1jzAhYHVVT1Wf5ewAAAXE"] [Tue Aug 18 13:06:13.372306 2026] [security2:error] [pid 157386:tid 157559] [client 74.7.175.133:60600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lecarveiculospira.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSC9U1jzAhYHVVT1Wf5fAABNSA"] [Tue Aug 18 13:06:13.375163 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:13.375291 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:13.375427 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:13.375547 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:13.376175 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:13.376451 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:13.386418 2026] [security2:error] [pid 157386:tid 157627] [client 34.38.184.238:34954] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/secrets/aws.json"] [unique_id "aoSC9U1jzAhYHVVT1Wf5gAAAAXk"] [Tue Aug 18 13:06:13.424059 2026] [security2:error] [pid 157386:tid 157586] [client 74.249.206.207:45006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wp-load.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5ggAAAVA"] [Tue Aug 18 13:06:13.429221 2026] [core:error] [pid 157386:tid 157618] [client 34.38.184.238:34992] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../root/.aws/credentials) [Tue Aug 18 13:06:13.503743 2026] [autoindex:error] [pid 157386:tid 157400] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:13.525650 2026] [security2:error] [pid 157386:tid 157584] [client 20.250.13.23:23714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/lite.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5hwAAAU4"] [Tue Aug 18 13:06:13.532593 2026] [security2:error] [pid 157386:tid 157615] [client 34.38.184.238:34978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/ecs/task-credentials.json"] [unique_id "aoSC9U1jzAhYHVVT1Wf5iQAAAW0"] [Tue Aug 18 13:06:13.591335 2026] [security2:error] [pid 157386:tid 157572] [client 213.202.253.4:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/gdftps.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5iwAAAUI"], referer: www.google.com [Tue Aug 18 13:06:13.607281 2026] [security2:error] [pid 157386:tid 157565] [client 20.151.109.219:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/an.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5jQAAATs"] [Tue Aug 18 13:06:13.610673 2026] [security2:error] [pid 157386:tid 157410] [remote 203.99.146.53:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5jgABKxc"] [Tue Aug 18 13:06:13.715087 2026] [security2:error] [pid 157386:tid 157449] [remote 194.39.148.170:60144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.148.39.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5jwABbj4"] [Tue Aug 18 13:06:13.724185 2026] [security2:error] [pid 157386:tid 157558] [client 20.38.3.247:31324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/nox.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5kgAAATQ"] [Tue Aug 18 13:06:13.757396 2026] [security2:error] [pid 157386:tid 157536] [client 68.155.156.252:23771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/imscjpg.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5lQAAAR4"] [Tue Aug 18 13:06:13.790653 2026] [security2:error] [pid 157386:tid 157418] [remote 47.89.174.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "beca.3xsolutions.com.br"] [uri "/.env"] [unique_id "aoSC9U1jzAhYHVVT1Wf5lgABCx8"] [Tue Aug 18 13:06:13.857437 2026] [security2:error] [pid 157386:tid 157620] [client 34.38.184.238:35098] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/proxy"] [unique_id "aoSC9U1jzAhYHVVT1Wf5mAAAAXI"] [Tue Aug 18 13:06:13.866079 2026] [security2:error] [pid 157386:tid 157537] [client 20.79.204.6:11690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5mQAAAR8"] [Tue Aug 18 13:06:13.869798 2026] [security2:error] [pid 157386:tid 157575] [client 196.12.128.158:59231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5mgAAAUU"] [Tue Aug 18 13:06:13.879472 2026] [security2:error] [pid 157386:tid 157592] [client 20.116.17.175:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ab.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5mwAAAVY"] [Tue Aug 18 13:06:13.895205 2026] [security2:error] [pid 157386:tid 157540] [client 74.249.206.207:39119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/155.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5nAAAASI"] [Tue Aug 18 13:06:13.925335 2026] [security2:error] [pid 157386:tid 157582] [client 34.38.184.238:34630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/public/.aws/credentials"] [unique_id "aoSC9U1jzAhYHVVT1Wf5nQAAAUw"] [Tue Aug 18 13:06:13.927860 2026] [security2:error] [pid 157386:tid 157557] [client 20.206.73.37:3480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/ai.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5ngAAATM"] [Tue Aug 18 13:06:13.987752 2026] [security2:error] [pid 157386:tid 157564] [client 5.31.227.224:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5oAAAATo"] [Tue Aug 18 13:06:13.987861 2026] [security2:error] [pid 157386:tid 157564] [client 5.31.227.224:7869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5oAAAATo"] [Tue Aug 18 13:06:13.997502 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/test_info.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5owAAAT0"] [Tue Aug 18 13:06:14.106677 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:14.106948 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:14.205588 2026] [security2:error] [pid 157386:tid 157627] [client 20.104.100.201:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/term.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5sQAAAXk"] [Tue Aug 18 13:06:14.245114 2026] [security2:error] [pid 157386:tid 157639] [client 34.38.184.238:35034] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/service-account.json"] [unique_id "aoSC9k1jzAhYHVVT1Wf5swAAAYU"] [Tue Aug 18 13:06:14.268235 2026] [security2:error] [pid 157386:tid 157585] [client 34.38.184.238:34946] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSC9k1jzAhYHVVT1Wf5tgAAAU8"] [Tue Aug 18 13:06:14.304038 2026] [security2:error] [pid 157386:tid 157518] [client 20.116.17.175:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/12.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5uAAAAQw"] [Tue Aug 18 13:06:14.320542 2026] [security2:error] [pid 157386:tid 157508] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5ugABeHk"] [Tue Aug 18 13:06:14.320789 2026] [security2:error] [pid 157386:tid 157626] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5ugABeHk"] [Tue Aug 18 13:06:14.341335 2026] [security2:error] [pid 157386:tid 157593] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-login.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5aAAAAVc"] [Tue Aug 18 13:06:14.346558 2026] [security2:error] [pid 157386:tid 157571] [client 34.38.184.238:34818] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSC9k1jzAhYHVVT1Wf5vAAAAUE"] [Tue Aug 18 13:06:14.422146 2026] [security2:error] [pid 157386:tid 157533] [client 74.249.206.207:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/index.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5vgAAARs"] [Tue Aug 18 13:06:14.427252 2026] [security2:error] [pid 157386:tid 157628] [client 34.38.184.238:48126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.gcloud/credentials.json"] [unique_id "aoSC9k1jzAhYHVVT1Wf5wAAAAXo"] [Tue Aug 18 13:06:14.462006 2026] [security2:error] [pid 157386:tid 157637] [client 20.116.17.175:45266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/tiny2.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5wwAAAYM"] [Tue Aug 18 13:06:14.501537 2026] [security2:error] [pid 157386:tid 157525] [client 20.25.139.174:4841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/themes.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5xgAAARM"] [Tue Aug 18 13:06:14.539158 2026] [security2:error] [pid 157386:tid 157527] [client 34.38.184.238:34650] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "mail.meneghel.com"] [uri "/fetch"] [unique_id "aoSC9k1jzAhYHVVT1Wf5yAAAARU"] [Tue Aug 18 13:06:14.633295 2026] [security2:error] [pid 157386:tid 157643] [client 37.40.227.74:57130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5zQAAAYk"] [Tue Aug 18 13:06:14.633419 2026] [security2:error] [pid 157386:tid 157643] [client 37.40.227.74:57130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf5zQAAAYk"] [Tue Aug 18 13:06:14.706081 2026] [security2:error] [pid 157386:tid 157520] [client 20.127.136.245:28103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf50AAAAQ4"] [Tue Aug 18 13:06:14.730001 2026] [security2:error] [pid 157386:tid 157557] [client 34.38.184.238:34962] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/firebase-service-account.json"] [unique_id "aoSC9k1jzAhYHVVT1Wf50gAAATM"] [Tue Aug 18 13:06:14.738710 2026] [security2:error] [pid 157386:tid 157554] [client 20.171.51.14:42240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/z.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf51gAAATA"] [Tue Aug 18 13:06:14.758041 2026] [security2:error] [pid 157386:tid 157562] [client 34.38.184.238:34766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/gcp-service-account.json"] [unique_id "aoSC9k1jzAhYHVVT1Wf51wAAATg"] [Tue Aug 18 13:06:14.758613 2026] [security2:error] [pid 157386:tid 157612] [client 34.38.184.238:35122] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.openai/config.json"] [unique_id "aoSC9k1jzAhYHVVT1Wf52AAAAWo"] [Tue Aug 18 13:06:14.821026 2026] [security2:error] [pid 157386:tid 157548] [client 74.249.206.207:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/aaa.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf53QAAASo"] [Tue Aug 18 13:06:14.904281 2026] [security2:error] [pid 157386:tid 157606] [client 5.29.54.176:49273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.54.29.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "instrumedcalibracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC801jzAhYHVVT1Wf5FAAAAWQ"] [Tue Aug 18 13:06:14.904391 2026] [security2:error] [pid 157386:tid 157606] [client 5.29.54.176:49273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "instrumedcalibracao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC801jzAhYHVVT1Wf5FAAAAWQ"] [Tue Aug 18 13:06:14.915518 2026] [security2:error] [pid 157386:tid 157623] [client 74.248.130.103:40761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/imageskir.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf55wAAAXU"] [Tue Aug 18 13:06:14.965086 2026] [security2:error] [pid 157386:tid 157618] [client 20.116.17.175:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/x1da.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf56gAAAXA"] [Tue Aug 18 13:06:14.979070 2026] [security2:error] [pid 157386:tid 157600] [client 20.25.139.174:4617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-mail.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf56wAAAV4"] [Tue Aug 18 13:06:14.996233 2026] [security2:error] [pid 157386:tid 157522] [client 102.213.179.104:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf57AAAARA"] [Tue Aug 18 13:06:14.996381 2026] [security2:error] [pid 157386:tid 157522] [client 102.213.179.104:50711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf57AAAARA"] [Tue Aug 18 13:06:14.997310 2026] [security2:error] [pid 157386:tid 157575] [client 196.12.128.158:59231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSC9U1jzAhYHVVT1Wf5mgAAAUU"] [Tue Aug 18 13:06:14.998488 2026] [security2:error] [pid 157386:tid 157626] [client 20.151.109.219:7326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sy.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf57QAAAXg"] [Tue Aug 18 13:06:14.998836 2026] [security2:error] [pid 157386:tid 157593] [client 20.116.17.175:22577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wpxml.php"] [unique_id "aoSC9k1jzAhYHVVT1Wf57gAAAVc"] [Tue Aug 18 13:06:15.068160 2026] [security2:error] [pid 157386:tid 157577] [client 20.1.169.243:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSC901jzAhYHVVT1Wf59AAAAUc"] [Tue Aug 18 13:06:15.082283 2026] [security2:error] [pid 157386:tid 157589] [client 20.25.139.174:4844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/cv.php"] [unique_id "aoSC901jzAhYHVVT1Wf59wAAAVM"] [Tue Aug 18 13:06:15.085290 2026] [security2:error] [pid 157386:tid 157533] [client 168.62.48.100:18034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/qfvqu.php"] [unique_id "aoSC901jzAhYHVVT1Wf5-AAAARs"] [Tue Aug 18 13:06:15.114371 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:15.114637 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:15.119962 2026] [security2:error] [pid 157386:tid 157628] [client 34.38.184.238:35108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/anthropic.json"] [unique_id "aoSC901jzAhYHVVT1Wf5-gAAAXo"] [Tue Aug 18 13:06:15.211185 2026] [security2:error] [pid 157386:tid 157536] [client 158.23.17.4:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lj.php"] [unique_id "aoSC901jzAhYHVVT1Wf5_AAAAR4"] [Tue Aug 18 13:06:15.254646 2026] [security2:error] [pid 157386:tid 157478] [remote 203.99.146.53:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.146.99.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelbuzatto.com.br"] [uri "/wp-login.php"] [unique_id "aoSC901jzAhYHVVT1Wf5_QABfVs"], referer: https://rafaelbuzatto.com.br/wp-login.php [Tue Aug 18 13:06:15.255894 2026] [security2:error] [pid 157386:tid 157625] [client 74.249.206.207:32526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/FWAZ.php"] [unique_id "aoSC901jzAhYHVVT1Wf5_gAAAXc"] [Tue Aug 18 13:06:15.267917 2026] [security2:error] [pid 157386:tid 157588] [client 34.38.184.238:35126] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config/anthropic.json"] [unique_id "aoSC901jzAhYHVVT1Wf6AQAAAVI"] [Tue Aug 18 13:06:15.330641 2026] [security2:error] [pid 157386:tid 157573] [client 223.185.37.47:18249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC901jzAhYHVVT1Wf6AwAAAUM"] [Tue Aug 18 13:06:15.330769 2026] [security2:error] [pid 157386:tid 157573] [client 223.185.37.47:18249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSC901jzAhYHVVT1Wf6AwAAAUM"] [Tue Aug 18 13:06:15.389066 2026] [security2:error] [pid 157386:tid 157519] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSC901jzAhYHVVT1Wf6BgAAAQ0"] [Tue Aug 18 13:06:15.481200 2026] [security2:error] [pid 157386:tid 157524] [client 213.35.127.232:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSC901jzAhYHVVT1Wf6DQAAARI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:15.509345 2026] [autoindex:error] [pid 157386:tid 157512] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:15.520686 2026] [security2:error] [pid 157386:tid 157584] [client 20.250.13.23:18559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSC901jzAhYHVVT1Wf6DwAAAU4"] [Tue Aug 18 13:06:15.528643 2026] [security2:error] [pid 157386:tid 157612] [client 20.1.169.243:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/file5.php"] [unique_id "aoSC901jzAhYHVVT1Wf6EAAAAWo"] [Tue Aug 18 13:06:15.551580 2026] [security2:error] [pid 157386:tid 157406] [remote 162.214.205.212:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSC901jzAhYHVVT1Wf6EQABIhM"] [Tue Aug 18 13:06:15.554407 2026] [security2:error] [pid 157386:tid 157623] [client 68.155.156.252:35401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/qlex1.php"] [unique_id "aoSC901jzAhYHVVT1Wf6EgAAAXU"] [Tue Aug 18 13:06:15.586568 2026] [authz_core:error] [pid 157386:tid 157485] [remote 57.141.22.47:55358] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:15.586836 2026] [authz_core:error] [pid 157386:tid 157485] [remote 57.141.22.47:55358] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:15.588401 2026] [core:error] [pid 157386:tid 157488] [remote 172.182.217.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:06:15.588415 2026] [core:error] [pid 157386:tid 157488] [remote 172.182.217.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:06:15.672476 2026] [security2:error] [pid 157386:tid 157600] [client 74.249.206.207:32610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/site.php"] [unique_id "aoSC901jzAhYHVVT1Wf6FwAAAV4"] [Tue Aug 18 13:06:15.728946 2026] [security2:error] [pid 157386:tid 157594] [client 158.158.74.177:9332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/st.php"] [unique_id "aoSC901jzAhYHVVT1Wf6GQAAAVg"] [Tue Aug 18 13:06:15.749835 2026] [autoindex:error] [pid 157386:tid 157388] [remote 20.205.121.237:0] AH01276: Cannot serve directory /home3/cp37imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:15.835899 2026] [security2:error] [pid 157386:tid 157521] [client 4.223.113.180:45647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esteticarvca.com.br"] [uri "/log.php"] [unique_id "aoSC901jzAhYHVVT1Wf6HgAAAQ8"] [Tue Aug 18 13:06:15.842670 2026] [security2:error] [pid 157386:tid 157589] [client 34.38.184.238:34722] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config/env.js"] [unique_id "aoSC901jzAhYHVVT1Wf6HwAAAVM"] [Tue Aug 18 13:06:15.871036 2026] [security2:error] [pid 157386:tid 157563] [client 20.118.133.132:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/clque.php"] [unique_id "aoSC901jzAhYHVVT1Wf6IAAAATk"] [Tue Aug 18 13:06:15.929643 2026] [security2:error] [pid 157386:tid 157547] [client 20.127.136.245:28115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/function/function.php"] [unique_id "aoSC901jzAhYHVVT1Wf6IgAAASk"] [Tue Aug 18 13:06:15.954407 2026] [security2:error] [pid 157386:tid 157558] [client 34.38.184.238:35190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/app-config.json"] [unique_id "aoSC901jzAhYHVVT1Wf6IwAAATQ"] [Tue Aug 18 13:06:16.075677 2026] [security2:error] [pid 157386:tid 157539] [client 20.116.17.175:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6KgAAASE"] [Tue Aug 18 13:06:16.123310 2026] [security2:error] [pid 157386:tid 157557] [client 74.249.206.207:45055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/ccc.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6MgAAATM"] [Tue Aug 18 13:06:16.141629 2026] [security2:error] [pid 157386:tid 157629] [client 20.1.169.243:5040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6MwAAAXs"] [Tue Aug 18 13:06:16.184924 2026] [security2:error] [pid 157386:tid 157544] [client 34.38.184.238:35248] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.kube/config"] [unique_id "aoSC-E1jzAhYHVVT1Wf6NgAAASY"] [Tue Aug 18 13:06:16.281101 2026] [autoindex:error] [pid 157386:tid 157393] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:16.304840 2026] [security2:error] [pid 157386:tid 157548] [client 68.221.73.131:52758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/abcd.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6QAAAASo"] [Tue Aug 18 13:06:16.427304 2026] [security2:error] [pid 157386:tid 157606] [client 168.62.48.100:18146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/oivcl.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6QwAAAWQ"] [Tue Aug 18 13:06:16.440256 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.49.167:2695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/pema.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6RAAAAQw"] [Tue Aug 18 13:06:16.470570 2026] [security2:error] [pid 157386:tid 157542] [client 20.1.169.243:15979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/widgets/min.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6RQAAASQ"] [Tue Aug 18 13:06:16.489130 2026] [security2:error] [pid 157386:tid 157540] [client 74.249.206.207:32606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/admin.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6RgAAASI"] [Tue Aug 18 13:06:16.509548 2026] [security2:error] [pid 157386:tid 157623] [client 20.25.139.174:4822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6RwAAAXU"] [Tue Aug 18 13:06:16.553058 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.156.252:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/mariju.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6SQAAAV4"] [Tue Aug 18 13:06:16.575725 2026] [security2:error] [pid 157386:tid 157630] [client 49.37.150.8:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6SAAAAXw"] [Tue Aug 18 13:06:16.575836 2026] [security2:error] [pid 157386:tid 157630] [client 49.37.150.8:65416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6SAAAAXw"] [Tue Aug 18 13:06:16.583261 2026] [security2:error] [pid 157386:tid 157538] [client 34.38.184.238:25810] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/api/openapi.json"] [unique_id "aoSC-E1jzAhYHVVT1Wf6TAAAASA"] [Tue Aug 18 13:06:16.585541 2026] [security2:error] [pid 157386:tid 157619] [client 20.1.169.243:5049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-includes/blocks/search/index.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6TgAAAXE"] [Tue Aug 18 13:06:16.595286 2026] [security2:error] [pid 157386:tid 157565] [client 20.250.13.23:28873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/w1.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6TwAAATs"] [Tue Aug 18 13:06:16.630525 2026] [security2:error] [pid 157386:tid 157579] [client 34.38.184.238:25836] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/public/env.js"] [unique_id "aoSC-E1jzAhYHVVT1Wf6UQAAAUk"] [Tue Aug 18 13:06:16.640817 2026] [security2:error] [pid 157386:tid 157593] [client 20.206.73.37:24509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/sf.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6UwAAAVc"] [Tue Aug 18 13:06:16.691122 2026] [security2:error] [pid 157386:tid 157580] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6VQAAAUo"] [Tue Aug 18 13:06:16.694182 2026] [security2:error] [pid 157386:tid 157641] [client 40.74.65.169:4825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6VgAAAYc"] [Tue Aug 18 13:06:16.707826 2026] [security2:error] [pid 157386:tid 157521] [client 20.251.48.93:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/gec.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6WAAAAQ8"] [Tue Aug 18 13:06:16.751681 2026] [security2:error] [pid 157386:tid 157585] [client 86.120.159.145:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6WQAAAU8"] [Tue Aug 18 13:06:16.751787 2026] [security2:error] [pid 157386:tid 157585] [client 86.120.159.145:51034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6WQAAAU8"] [Tue Aug 18 13:06:16.762521 2026] [security2:error] [pid 157386:tid 157533] [client 20.116.17.175:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/mcs.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6XAAAARs"] [Tue Aug 18 13:06:16.763664 2026] [security2:error] [pid 157386:tid 157516] [client 20.250.13.23:44043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6XQAAAQo"] [Tue Aug 18 13:06:16.843790 2026] [security2:error] [pid 157386:tid 157568] [client 74.249.206.207:32593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/reviall.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6YgAAAT4"] [Tue Aug 18 13:06:16.892690 2026] [security2:error] [pid 157386:tid 157534] [client 74.248.130.103:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/indexo.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6ZQAAARw"] [Tue Aug 18 13:06:16.918612 2026] [security2:error] [pid 157386:tid 157551] [client 20.215.241.237:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/mac.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6ZwAAAS0"] [Tue Aug 18 13:06:17.133244 2026] [security2:error] [pid 157386:tid 157576] [client 49.13.164.148:27838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSC-E1jzAhYHVVT1Wf6aAAAAUY"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 13:06:17.149428 2026] [security2:error] [pid 157386:tid 157557] [client 68.155.156.252:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/cofbgxlk.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6aQAAATM"] [Tue Aug 18 13:06:17.212911 2026] [security2:error] [pid 157386:tid 157552] [client 20.1.169.243:5039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/edit.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6bAAAAS4"] [Tue Aug 18 13:06:17.301366 2026] [security2:error] [pid 157386:tid 157564] [client 20.171.51.14:44910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xg.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6cAAAATo"] [Tue Aug 18 13:06:17.391981 2026] [security2:error] [pid 157386:tid 157634] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6cwAAAYA"] [Tue Aug 18 13:06:17.421885 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:17.422138 2026] [authz_core:error] [pid 157386:tid 157513] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:17.463295 2026] [security2:error] [pid 157386:tid 157588] [client 20.250.13.23:18529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6dwAAAVI"] [Tue Aug 18 13:06:17.480684 2026] [security2:error] [pid 157386:tid 157587] [client 20.127.136.245:28272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/nw.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6eAAAAVE"] [Tue Aug 18 13:06:17.482801 2026] [security2:error] [pid 157386:tid 157553] [client 20.116.17.175:22643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ccou.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6eQAAAS8"] [Tue Aug 18 13:06:17.493861 2026] [security2:error] [pid 157386:tid 157639] [client 157.90.155.240:34866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSC-U1jzAhYHVVT1Wf6egAAAYU"], referer: http://rakhomed.com.br [Tue Aug 18 13:06:17.510442 2026] [security2:error] [pid 157386:tid 157600] [client 74.248.130.103:49633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6ewAAAV4"] [Tue Aug 18 13:06:17.841716 2026] [security2:error] [pid 157386:tid 157581] [client 158.158.74.177:9859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSC-U1jzAhYHVVT1Wf6iQAAAUs"] [Tue Aug 18 13:06:17.901615 2026] [security2:error] [pid 157386:tid 157569] [client 34.38.184.238:25740] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/deploy/service-account.json"] [unique_id "aoSC-U1jzAhYHVVT1Wf6jAAAAT8"] [Tue Aug 18 13:06:17.984200 2026] [autoindex:error] [pid 157386:tid 157438] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:18.006261 2026] [security2:error] [pid 157386:tid 157539] [client 20.215.241.237:37688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/ops.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6kgAAASE"] [Tue Aug 18 13:06:18.075615 2026] [security2:error] [pid 157386:tid 157642] [client 34.38.184.238:48128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/config.php.bak"] [unique_id "aoSC-k1jzAhYHVVT1Wf6lwAAAYg"] [Tue Aug 18 13:06:18.091589 2026] [security2:error] [pid 157386:tid 157528] [client 20.25.139.174:4526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ws83.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6mAAAARY"] [Tue Aug 18 13:06:18.129250 2026] [security2:error] [pid 157386:tid 157582] [client 34.38.184.238:25820] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/application.properties"] [unique_id "aoSC-k1jzAhYHVVT1Wf6mQAAAUw"] [Tue Aug 18 13:06:18.131618 2026] [security2:error] [pid 157386:tid 157632] [client 20.250.13.23:23704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6mgAAAX4"] [Tue Aug 18 13:06:18.156510 2026] [security2:error] [pid 157386:tid 157544] [client 158.23.17.4:14069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kh.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6nAAAASY"] [Tue Aug 18 13:06:18.274658 2026] [authz_core:error] [pid 157386:tid 157441] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:18.274943 2026] [authz_core:error] [pid 157386:tid 157441] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:18.372879 2026] [security2:error] [pid 157386:tid 157519] [client 20.1.169.243:15585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-cron.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6owAAAQ0"] [Tue Aug 18 13:06:18.426056 2026] [autoindex:error] [pid 157386:tid 157511] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:18.451649 2026] [security2:error] [pid 157386:tid 157611] [client 74.249.206.207:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/nope.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6pgAAAWk"] [Tue Aug 18 13:06:18.598537 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.100.201:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/black.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6qwAAATY"] [Tue Aug 18 13:06:18.668319 2026] [security2:error] [pid 157386:tid 157600] [client 20.25.139.174:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/atex1.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6rgAAAV4"] [Tue Aug 18 13:06:18.679470 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/f.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6sAAAAXM"] [Tue Aug 18 13:06:18.701140 2026] [security2:error] [pid 157386:tid 157641] [client 168.62.48.100:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6sgAAAYc"] [Tue Aug 18 13:06:18.771282 2026] [security2:error] [pid 157386:tid 157533] [client 20.151.109.219:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/57.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6tQAAARs"] [Tue Aug 18 13:06:18.835567 2026] [security2:error] [pid 157386:tid 157580] [client 20.1.169.243:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/wp-links-opml.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6ugAAAUo"] [Tue Aug 18 13:06:18.889001 2026] [security2:error] [pid 157386:tid 157593] [client 20.250.13.23:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6vAAAAVc"] [Tue Aug 18 13:06:18.985372 2026] [security2:error] [pid 157386:tid 157609] [client 114.119.133.87:55387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brindesoxente.com"] [uri "/index.php/product-category/chaveiros/page/2"] [unique_id "aoSC-k1jzAhYHVVT1Wf6wAAAAWc"], referer: https://www.brindesoxente.com/index.php/product-category/chaveiros/page/1 [Tue Aug 18 13:06:19.104538 2026] [security2:error] [pid 157386:tid 157618] [client 20.250.13.23:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-login.php"] [unique_id "aoSC-k1jzAhYHVVT1Wf6uwAAAXA"] [Tue Aug 18 13:06:19.139039 2026] [security2:error] [pid 157386:tid 157599] [client 20.206.73.37:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ajax.php"] [unique_id "aoSC-01jzAhYHVVT1Wf6xwAAAV0"] [Tue Aug 18 13:06:19.366445 2026] [security2:error] [pid 157386:tid 157588] [client 20.116.17.175:20441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/adminner.php"] [unique_id "aoSC-01jzAhYHVVT1Wf6zQAAAVI"] [Tue Aug 18 13:06:19.408857 2026] [security2:error] [pid 157386:tid 157524] [client 74.248.130.103:22329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSC-01jzAhYHVVT1Wf6zwAAARI"] [Tue Aug 18 13:06:19.432536 2026] [security2:error] [pid 157386:tid 157535] [client 20.1.169.243:4995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/a.php"] [unique_id "aoSC-01jzAhYHVVT1Wf60QAAAR0"] [Tue Aug 18 13:06:19.438256 2026] [security2:error] [pid 157386:tid 157579] [client 34.38.184.238:25850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.meneghel.com"] [uri "/wp-config.php.swp"] [unique_id "aoSC-01jzAhYHVVT1Wf60wAAAUk"] [Tue Aug 18 13:06:19.440151 2026] [security2:error] [pid 157386:tid 157560] [client 3.79.134.69:42960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rakhomed.com.br"] [uri "/"] [unique_id "aoSC-01jzAhYHVVT1Wf61AAAATY"], referer: http://rakhomed.com.br [Tue Aug 18 13:06:19.440386 2026] [security2:error] [pid 157386:tid 157619] [client 34.38.184.238:35150] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.npmrc"] [unique_id "aoSC-01jzAhYHVVT1Wf61QAAAXE"] [Tue Aug 18 13:06:19.451288 2026] [security2:error] [pid 157386:tid 157626] [client 34.38.184.238:25752] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.terraform/terraform.tfstate"] [unique_id "aoSC-01jzAhYHVVT1Wf61wAAAXg"] [Tue Aug 18 13:06:19.681871 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:19.682177 2026] [authz_core:error] [pid 157386:tid 157442] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:19.750888 2026] [security2:error] [pid 157386:tid 157545] [client 34.38.184.238:25840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.meneghel.com"] [uri "/wp-config.php~"] [unique_id "aoSC-01jzAhYHVVT1Wf63AAAASc"] [Tue Aug 18 13:06:19.775278 2026] [security2:error] [pid 157386:tid 157601] [client 168.62.48.100:18116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/zugvi.php"] [unique_id "aoSC-01jzAhYHVVT1Wf63QAAAV8"] [Tue Aug 18 13:06:20.029779 2026] [security2:error] [pid 157386:tid 157542] [client 178.153.171.161:23908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf66wAAASQ"] [Tue Aug 18 13:06:20.038830 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.100.201:54067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/as.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf67AAAAVs"] [Tue Aug 18 13:06:20.052920 2026] [security2:error] [pid 157386:tid 157517] [client 20.1.169.243:5044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/w.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf67QAAAQs"] [Tue Aug 18 13:06:20.081035 2026] [security2:error] [pid 157386:tid 157531] [client 20.206.73.37:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/xx.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf68gAAARk"] [Tue Aug 18 13:06:20.110043 2026] [security2:error] [pid 157386:tid 157546] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wso.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf68wAAASg"] [Tue Aug 18 13:06:20.126005 2026] [security2:error] [pid 157386:tid 157623] [client 20.79.204.6:11664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/0x.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf69AAAAXU"] [Tue Aug 18 13:06:20.129576 2026] [security2:error] [pid 157386:tid 157519] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/av.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf69QAAAQ0"] [Tue Aug 18 13:06:20.246570 2026] [security2:error] [pid 157386:tid 157548] [client 20.151.109.219:28739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/30.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf6-gAAASo"] [Tue Aug 18 13:06:20.253688 2026] [security2:error] [pid 157386:tid 157576] [client 20.25.139.174:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/class-t.api.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf6_AAAAUY"] [Tue Aug 18 13:06:20.296166 2026] [security2:error] [pid 157386:tid 157527] [client 20.127.136.245:28274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/xleet.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf6_QAAARU"] [Tue Aug 18 13:06:20.297846 2026] [security2:error] [pid 157386:tid 157526] [client 37.40.227.74:56873] ModSecurity: Warning. String match "408" at RESPONSE_STATUS. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "35"] [id "343434"] [rev "1"] [msg "Atomicorp.com WAF Rules: Client Connection dropped by Apache due to slow connection, possible Slowaris attack"] [severity "WARNING"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3vwAAARQ"] [Tue Aug 18 13:06:20.297903 2026] [security2:error] [pid 157386:tid 157526] [client 37.40.227.74:56873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "408"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC7U1jzAhYHVVT1Wf3vwAAARQ"] [Tue Aug 18 13:06:20.367997 2026] [security2:error] [pid 157386:tid 157629] [client 114.119.149.2:32575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rhemahost.com.br"] [uri "/comercial/wp-content/uploads/2015/11/Empilhadeira-Combust%C3%A3o-GTS25_2-300x300.png"] [unique_id "aoSC_E1jzAhYHVVT1Wf7AgAAAXs"], referer: https://rhemahost.com.br/comercial/wp-content/uploads/2015/11/Empilhadeira-Combust%C3%A3o-GTS25_2-300x300.png [Tue Aug 18 13:06:20.431955 2026] [security2:error] [pid 157386:tid 157621] [client 158.23.17.4:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/jb.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7BAAAAXM"] [Tue Aug 18 13:06:20.454055 2026] [security2:error] [pid 157386:tid 157514] [remote 185.37.231.189:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.231.37.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guinchomarquette.com.br"] [uri "/wp-login.php"] [unique_id "aoSC-01jzAhYHVVT1Wf6zgABOH8"] [Tue Aug 18 13:06:20.482920 2026] [security2:error] [pid 157386:tid 157547] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/sf.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7BwAAASk"] [Tue Aug 18 13:06:20.542662 2026] [security2:error] [pid 157386:tid 157521] [client 168.62.48.100:18059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wsrer.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7CwAAAQ8"] [Tue Aug 18 13:06:20.548443 2026] [security2:error] [pid 157386:tid 157594] [client 20.215.241.237:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/coffexium.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7DQAAAVg"] [Tue Aug 18 13:06:20.560435 2026] [security2:error] [pid 157386:tid 157582] [client 20.116.17.175:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7DgAAAUw"] [Tue Aug 18 13:06:20.636559 2026] [security2:error] [pid 157386:tid 157606] [client 34.38.184.238:34602] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/WEB-INF/web.xml"] [unique_id "aoSC_E1jzAhYHVVT1Wf7EQAAAWQ"] [Tue Aug 18 13:06:20.727089 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.49.167:21937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/sh.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7FgAAAUs"] [Tue Aug 18 13:06:20.781501 2026] [security2:error] [pid 157386:tid 157570] [client 3.77.67.4:43416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.portaltomazzi.com.br"] [uri "/index.php"] [unique_id "aoSC-01jzAhYHVVT1Wf62QAAAUA"], referer: https://www.portaltomazzi.com.br/ [Tue Aug 18 13:06:20.819446 2026] [security2:error] [pid 157386:tid 157573] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/images.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7GwAAAUM"] [Tue Aug 18 13:06:20.827132 2026] [security2:error] [pid 157386:tid 157616] [client 20.251.48.93:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/sky.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7HAAAAW4"] [Tue Aug 18 13:06:20.844249 2026] [security2:error] [pid 157386:tid 157544] [client 34.38.184.238:35146] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/local.settings.json"] [unique_id "aoSC_E1jzAhYHVVT1Wf7HwAAASY"] [Tue Aug 18 13:06:20.880495 2026] [security2:error] [pid 157386:tid 157552] [client 20.171.51.14:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/nd.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7IAAAAS4"] [Tue Aug 18 13:06:20.904333 2026] [security2:error] [pid 157386:tid 157597] [client 34.38.184.238:25726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/web.config"] [unique_id "aoSC_E1jzAhYHVVT1Wf7IQAAAVs"] [Tue Aug 18 13:06:20.925027 2026] [security2:error] [pid 157386:tid 157517] [client 168.62.48.100:18131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/ucpfr.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7IgAAAQs"] [Tue Aug 18 13:06:20.940575 2026] [security2:error] [pid 157386:tid 157556] [client 20.151.109.219:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ah.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf7IwAAATI"] [Tue Aug 18 13:06:21.057435 2026] [security2:error] [pid 157386:tid 157584] [client 68.155.156.252:13768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/contacto.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7JQAAAU4"] [Tue Aug 18 13:06:21.129536 2026] [security2:error] [pid 157386:tid 157542] [client 178.153.171.161:23908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_E1jzAhYHVVT1Wf66wAAASQ"] [Tue Aug 18 13:06:21.223962 2026] [security2:error] [pid 157386:tid 157591] [client 34.38.184.238:35264] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config.json"] [unique_id "aoSC_U1jzAhYHVVT1Wf7KwAAAVU"] [Tue Aug 18 13:06:21.232797 2026] [security2:error] [pid 157386:tid 157541] [client 149.34.210.141:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7KQAAASM"] [Tue Aug 18 13:06:21.259826 2026] [security2:error] [pid 157386:tid 157607] [client 157.90.155.240:54944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7LQAAAWU"], referer: http://rakhomed.com.br [Tue Aug 18 13:06:21.306402 2026] [security2:error] [pid 157386:tid 157562] [client 168.62.48.100:18070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/yxijx.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7MAAAATg"] [Tue Aug 18 13:06:21.340745 2026] [security2:error] [pid 157386:tid 157639] [client 20.127.136.245:28226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7MQAAAYU"] [Tue Aug 18 13:06:21.357268 2026] [security2:error] [pid 157386:tid 157603] [client 20.25.139.174:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/w.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7MgAAAWE"] [Tue Aug 18 13:06:21.503294 2026] [security2:error] [pid 157386:tid 157521] [client 34.38.184.238:25732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/backup.sql"] [unique_id "aoSC_U1jzAhYHVVT1Wf7OAAAAQ8"] [Tue Aug 18 13:06:21.507915 2026] [security2:error] [pid 157386:tid 157594] [client 52.173.121.69:35119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7OQAAAVg"] [Tue Aug 18 13:06:21.533914 2026] [security2:error] [pid 157386:tid 157610] [client 20.25.139.174:4463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/bolt.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7OgAAAWg"] [Tue Aug 18 13:06:21.543679 2026] [security2:error] [pid 157386:tid 157533] [client 34.38.184.238:25690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/dump.sql"] [unique_id "aoSC_U1jzAhYHVVT1Wf7PAAAARs"] [Tue Aug 18 13:06:21.557700 2026] [security2:error] [pid 157386:tid 157563] [client 34.38.184.238:35066] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/.azure/accessTokens.json"] [unique_id "aoSC_U1jzAhYHVVT1Wf7PQAAATk"] [Tue Aug 18 13:06:21.609313 2026] [security2:error] [pid 157386:tid 157580] [client 40.74.65.169:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7RAAAAUo"] [Tue Aug 18 13:06:21.665915 2026] [security2:error] [pid 157386:tid 157534] [client 20.251.48.93:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/sixxis.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7RgAAARw"] [Tue Aug 18 13:06:21.699302 2026] [security2:error] [pid 157386:tid 157445] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7RwABiTo"] [Tue Aug 18 13:06:21.699476 2026] [security2:error] [pid 157386:tid 157643] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7RwABiTo"] [Tue Aug 18 13:06:21.852550 2026] [security2:error] [pid 157386:tid 157597] [client 168.62.48.100:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7UQAAAVs"] [Tue Aug 18 13:06:21.873690 2026] [security2:error] [pid 157386:tid 157561] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/index/function.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7UgAAATc"] [Tue Aug 18 13:06:21.878685 2026] [security2:error] [pid 157386:tid 157570] [client 20.118.133.132:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/nano.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7UwAAAUA"] [Tue Aug 18 13:06:21.907630 2026] [security2:error] [pid 157386:tid 157599] [client 158.23.17.4:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/do.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7VQAAAV0"] [Tue Aug 18 13:06:22.021138 2026] [security2:error] [pid 157386:tid 157518] [client 74.249.206.207:45038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/nope.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7WQAAAQw"] [Tue Aug 18 13:06:22.067044 2026] [security2:error] [pid 157386:tid 157559] [client 34.38.184.238:25862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/config/application.properties"] [unique_id "aoSC_k1jzAhYHVVT1Wf7YQAAATU"] [Tue Aug 18 13:06:22.126827 2026] [security2:error] [pid 157386:tid 157564] [client 34.38.184.238:34660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.meneghel.com"] [uri "/wp-config.php.bak"] [unique_id "aoSC_k1jzAhYHVVT1Wf7ZQAAATo"] [Tue Aug 18 13:06:22.151606 2026] [security2:error] [pid 157386:tid 157524] [client 40.74.65.169:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/fpwch.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7ZwAAARI"] [Tue Aug 18 13:06:22.226634 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:24853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/xynz1.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7bAAAAVA"] [Tue Aug 18 13:06:22.277226 2026] [security2:error] [pid 157386:tid 157600] [client 34.38.184.238:25772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/actuator/httptrace"] [unique_id "aoSC_k1jzAhYHVVT1Wf7cAAAAV4"] [Tue Aug 18 13:06:22.312952 2026] [security2:error] [pid 157386:tid 157550] [client 20.1.169.243:15936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7cQAAASw"] [Tue Aug 18 13:06:22.323459 2026] [security2:error] [pid 157386:tid 157620] [client 20.104.49.167:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/button.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7cgAAAXI"] [Tue Aug 18 13:06:22.382764 2026] [security2:error] [pid 157386:tid 157547] [client 52.173.121.69:52932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/index/function.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7dAAAASk"] [Tue Aug 18 13:06:22.388550 2026] [security2:error] [pid 157386:tid 157539] [client 20.127.136.245:28097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/155.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7dQAAASE"] [Tue Aug 18 13:06:22.422734 2026] [proxy:error] [pid 157386:tid 157638] (70007)The timeout specified has expired: [client 74.244.185.64:23774] AH02608: read request body failed to 127.0.0.1:2095 (127.0.0.1) from 74.244.185.64 (), referer: http://webmail.esteticarvca.com.br/cpsess7158735704/3rdparty/roundcube/?_task=mail&_mbox=INBOX [Tue Aug 18 13:06:22.422754 2026] [proxy_http:error] [pid 157386:tid 157638] [client 74.244.185.64:23774] AH01097: pass request body failed to 127.0.0.1:2095 (127.0.0.1) from 74.244.185.64 (), referer: http://webmail.esteticarvca.com.br/cpsess7158735704/3rdparty/roundcube/?_task=mail&_mbox=INBOX [Tue Aug 18 13:06:22.422853 2026] [security2:error] [pid 157386:tid 157638] [client 74.244.185.64:23774] ModSecurity: Warning. String match "408" at RESPONSE_STATUS. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "35"] [id "343434"] [rev "1"] [msg "Atomicorp.com WAF Rules: Client Connection dropped by Apache due to slow connection, possible Slowaris attack"] [severity "WARNING"] [hostname "webmail.esteticarvca.com.br"] [uri "/___proxy_subdomain_webmail/cpsess7158735704/3rdparty/roundcube/"] [unique_id "aoSC6U1jzAhYHVVT1Wf2vQAAAYQ"], referer: http://webmail.esteticarvca.com.br/cpsess7158735704/3rdparty/roundcube/?_task=mail&_mbox=INBOX [Tue Aug 18 13:06:22.435227 2026] [security2:error] [pid 157386:tid 157630] [client 3.79.134.69:22858] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rakhomed.com.br"] [uri "/index.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7dgAAAXw"], referer: http://rakhomed.com.br [Tue Aug 18 13:06:22.473254 2026] [security2:error] [pid 157386:tid 157531] [client 68.155.156.252:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/image2.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7dwAAARk"] [Tue Aug 18 13:06:22.544785 2026] [security2:error] [pid 157386:tid 157534] [client 168.62.48.100:18166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/zwlsv.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7ewAAARw"] [Tue Aug 18 13:06:22.558058 2026] [security2:error] [pid 157386:tid 157543] [client 34.38.184.238:25706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/db.sql"] [unique_id "aoSC_k1jzAhYHVVT1Wf7fAAAASU"] [Tue Aug 18 13:06:22.600815 2026] [security2:error] [pid 157386:tid 157596] [client 213.35.127.232:65362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7fQAAAVo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:22.612761 2026] [security2:error] [pid 157386:tid 157643] [client 20.151.109.219:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vw.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7fwAAAYk"] [Tue Aug 18 13:06:22.655919 2026] [lsapi:error] [pid 157386:tid 157395] [remote 52.167.144.159:16884] [host mresquadrias.com.br] Backend fatal error: PHP Fatal error: Uncaught Error: Call to a member function set() on null in /home2/mresquadrias/public_html/wp-includes/l10n.php:856\nStack trace:\n#0 /home2/mresquadrias/public_html/wp-includes/l10n.php(959): load_textdomain('default', '/home2/mresquad...', 'pt_BR')\n#1 /home2/mresquadrias/public_html/wp-includes/class-wp-fatal-error-handler.php(49): load_default_textdomain()\n#2 [internal function]: WP_Fatal_Error_Handler->handle()\n#3 {main}\n thrown in /home2/mresquadrias/public_html/wp-includes/l10n.php on line 856\n [Tue Aug 18 13:06:22.708588 2026] [lsapi:error] [pid 157386:tid 157509] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:22.708605 2026] [lsapi:error] [pid 157386:tid 157509] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:22.708610 2026] [lsapi:error] [pid 157386:tid 157509] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] Client error on sending request(POST /agenda/painel/paginas/agendamentos/listar-horarios.php HTTP/2.0); uri(/agenda/painel/paginas/agendamentos/listar-horarios.php) content-length(74): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:22.794150 2026] [security2:error] [pid 157386:tid 157579] [client 52.87.72.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atekrefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7aAABSSc"], referer: https://atekrefrigeracao.com.br/ [Tue Aug 18 13:06:22.816656 2026] [security2:error] [pid 157386:tid 157535] [client 20.250.13.23:33629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/default.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7jgAAAR0"] [Tue Aug 18 13:06:22.873745 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:20960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pu.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7kAAAAYA"] [Tue Aug 18 13:06:22.876374 2026] [security2:error] [pid 157386:tid 157546] [client 34.38.184.238:35212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/database.sql"] [unique_id "aoSC_k1jzAhYHVVT1Wf7kQAAASg"] [Tue Aug 18 13:06:22.884695 2026] [security2:error] [pid 157386:tid 157472] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/hplfuns.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7UAABQVU"] [Tue Aug 18 13:06:22.886180 2026] [security2:error] [pid 157386:tid 157518] [client 34.38.184.238:25784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.meneghel.com"] [uri "/wp-config.php.old"] [unique_id "aoSC_k1jzAhYHVVT1Wf7kgAAAQw"] [Tue Aug 18 13:06:22.891207 2026] [security2:error] [pid 157386:tid 157552] [client 168.62.48.100:17996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/jrpga.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7kwAAAS4"] [Tue Aug 18 13:06:22.917238 2026] [autoindex:error] [pid 157386:tid 157622] [client 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:22.918100 2026] [security2:error] [pid 157386:tid 157572] [client 158.158.74.177:9311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-configs.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7lQAAAUI"] [Tue Aug 18 13:06:23.032009 2026] [security2:error] [pid 157386:tid 157577] [client 74.249.206.207:64526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/new.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7mgAAAUc"] [Tue Aug 18 13:06:23.079704 2026] [security2:error] [pid 157386:tid 157527] [client 20.250.13.23:23742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/ku.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7nAAAARU"] [Tue Aug 18 13:06:23.122226 2026] [security2:error] [pid 157386:tid 157583] [client 20.127.136.245:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/96i.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7nQAAAU0"] [Tue Aug 18 13:06:23.125417 2026] [lsapi:error] [pid 157386:tid 157419] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:23.125431 2026] [lsapi:error] [pid 157386:tid 157419] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:23.125435 2026] [lsapi:error] [pid 157386:tid 157419] [remote 168.181.166.128:64672] [host riobrancoconsultorios.com.br] Client error on sending request(POST /agenda/painel/paginas/agendamentos/listar-horarios.php HTTP/2.0); uri(/agenda/painel/paginas/agendamentos/listar-horarios.php) content-length(74): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29751 [Tue Aug 18 13:06:23.128556 2026] [security2:error] [pid 157386:tid 157400] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/hosty.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7oAABUA0"] [Tue Aug 18 13:06:23.128936 2026] [security2:error] [pid 157386:tid 157569] [client 222.124.191.185:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7YAAAAT8"] [Tue Aug 18 13:06:23.129002 2026] [security2:error] [pid 157386:tid 157569] [client 222.124.191.185:58892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_k1jzAhYHVVT1Wf7YAAAAT8"] [Tue Aug 18 13:06:23.146130 2026] [security2:error] [pid 157386:tid 157548] [client 20.215.241.237:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7oQAAASo"] [Tue Aug 18 13:06:23.151059 2026] [security2:error] [pid 157386:tid 157582] [client 20.250.13.23:42853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/222.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7ogAAAUw"] [Tue Aug 18 13:06:23.171326 2026] [security2:error] [pid 157386:tid 157591] [client 158.23.17.4:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/yw.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7owAAAVU"] [Tue Aug 18 13:06:23.201097 2026] [security2:error] [pid 157386:tid 157588] [client 20.25.139.174:4840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/bthil.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7pQAAAVI"] [Tue Aug 18 13:06:23.248944 2026] [security2:error] [pid 157386:tid 157562] [client 74.248.130.103:46998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/.admin.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7qAAAATg"] [Tue Aug 18 13:06:23.284186 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/edit.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7qQAAAWk"] [Tue Aug 18 13:06:23.373858 2026] [security2:error] [pid 157386:tid 157531] [client 40.74.65.169:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/yj09.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7qwAAARk"] [Tue Aug 18 13:06:23.391252 2026] [security2:error] [pid 157386:tid 157627] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/ops.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7rAAAAXk"] [Tue Aug 18 13:06:23.398412 2026] [security2:error] [pid 157386:tid 157606] [client 20.151.109.219:59769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/album.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7rQAAAWQ"] [Tue Aug 18 13:06:23.402119 2026] [security2:error] [pid 157386:tid 157601] [client 68.221.73.131:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-manager.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7rgAAAV8"] [Tue Aug 18 13:06:23.405089 2026] [core:crit] [pid 157386:tid 157534] (13)Permission denied: [client 85.204.70.116:0] AH00529: /home2/hg1tdc82/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/hg1tdc82/public_html/cgi-bin/' is executable [Tue Aug 18 13:06:23.448285 2026] [security2:error] [pid 157386:tid 157566] [client 68.155.156.252:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/fb.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7swAAATw"] [Tue Aug 18 13:06:23.466449 2026] [security2:error] [pid 157386:tid 157575] [client 34.38.184.238:25918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/storage/logs/lumen.log"] [unique_id "aoSC_01jzAhYHVVT1Wf7tAAAAUU"] [Tue Aug 18 13:06:23.478542 2026] [security2:error] [pid 157386:tid 157557] [client 34.38.184.238:35204] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/logs/app.log"] [unique_id "aoSC_01jzAhYHVVT1Wf7tgAAATM"] [Tue Aug 18 13:06:23.501825 2026] [security2:error] [pid 157386:tid 157597] [client 74.249.206.207:64540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/new.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7uQAAAVs"] [Tue Aug 18 13:06:23.552570 2026] [security2:error] [pid 157386:tid 157495] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/t.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7vAABQ2w"] [Tue Aug 18 13:06:23.618648 2026] [security2:error] [pid 157386:tid 157584] [client 34.38.184.238:25992] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/server-info"] [unique_id "aoSC_01jzAhYHVVT1Wf7wwAAAU4"] [Tue Aug 18 13:06:23.633208 2026] [security2:error] [pid 157386:tid 157622] [client 34.38.184.238:25732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/docker-compose.yaml"] [unique_id "aoSC_01jzAhYHVVT1Wf7xgAAAXQ"] [Tue Aug 18 13:06:23.635437 2026] [security2:error] [pid 157386:tid 157592] [client 20.1.169.243:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7xwAAAVY"] [Tue Aug 18 13:06:23.636737 2026] [security2:error] [pid 157386:tid 157572] [client 34.38.184.238:25690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.ssh/id_rsa"] [unique_id "aoSC_01jzAhYHVVT1Wf7yAAAAUI"] [Tue Aug 18 13:06:23.643429 2026] [security2:error] [pid 157386:tid 157556] [client 20.25.139.174:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/archive.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7yQAAATI"] [Tue Aug 18 13:06:23.667698 2026] [security2:error] [pid 157386:tid 157641] [client 138.36.100.162:43197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7zQAAAYc"] [Tue Aug 18 13:06:23.667784 2026] [security2:error] [pid 157386:tid 157641] [client 138.36.100.162:43197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7zQAAAYc"] [Tue Aug 18 13:06:23.719757 2026] [security2:error] [pid 157386:tid 157553] [client 213.35.127.232:50627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSC_01jzAhYHVVT1Wf7zwAAAS8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:23.730543 2026] [security2:error] [pid 157386:tid 157435] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf70AABgzA"] [Tue Aug 18 13:06:23.730794 2026] [security2:error] [pid 157386:tid 157637] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf70AABgzA"] [Tue Aug 18 13:06:23.762286 2026] [authz_core:error] [pid 157386:tid 157489] [remote 57.141.22.122:24628] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:23.762623 2026] [authz_core:error] [pid 157386:tid 157489] [remote 57.141.22.122:24628] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:23.915580 2026] [security2:error] [pid 157386:tid 157629] [client 5.31.227.224:29907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf73gAAAXs"] [Tue Aug 18 13:06:23.915757 2026] [security2:error] [pid 157386:tid 157629] [client 5.31.227.224:29907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf73gAAAXs"] [Tue Aug 18 13:06:23.957134 2026] [security2:error] [pid 157386:tid 157642] [client 34.38.184.238:26176] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/database.yml"] [unique_id "aoSC_01jzAhYHVVT1Wf74AAAAYg"] [Tue Aug 18 13:06:23.970028 2026] [security2:error] [pid 157386:tid 157601] [client 20.151.109.219:5771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lj.php"] [unique_id "aoSC_01jzAhYHVVT1Wf74QAAAV8"] [Tue Aug 18 13:06:23.981903 2026] [security2:error] [pid 157386:tid 157540] [client 20.251.48.93:31266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/yj09.php"] [unique_id "aoSC_01jzAhYHVVT1Wf74wAAASI"] [Tue Aug 18 13:06:23.987519 2026] [authz_core:error] [pid 157386:tid 157543] [client 34.38.184.238:25706] AH01630: client denied by server configuration: /home4/meneghel/public_html/error_log [Tue Aug 18 13:06:23.997433 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.49.167:2728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/wlc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf75QAAAYk"] [Tue Aug 18 13:06:24.016874 2026] [security2:error] [pid 157386:tid 157598] [client 20.1.169.243:15937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-rss.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf75wAAAVw"] [Tue Aug 18 13:06:24.016893 2026] [security2:error] [pid 157386:tid 157575] [client 52.173.121.69:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf76QAAAUU"] [Tue Aug 18 13:06:24.042510 2026] [security2:error] [pid 157386:tid 157557] [client 34.38.184.238:34934] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/kubernetes.yml"] [unique_id "aoSDAE1jzAhYHVVT1Wf76gAAATM"] [Tue Aug 18 13:06:24.057151 2026] [security2:error] [pid 157386:tid 157605] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/coffexium.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf76wAAAWM"] [Tue Aug 18 13:06:24.110837 2026] [security2:error] [pid 157386:tid 157535] [client 158.23.17.4:40421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/qh.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf77QAAAR0"] [Tue Aug 18 13:06:24.125486 2026] [security2:error] [pid 157386:tid 157517] [client 34.38.184.238:26094] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/trace.axd"] [unique_id "aoSDAE1jzAhYHVVT1Wf77wAAAQs"] [Tue Aug 18 13:06:24.137735 2026] [security2:error] [pid 157386:tid 157522] [client 40.74.65.169:4585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/scxy.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf78QAAARA"] [Tue Aug 18 13:06:24.156055 2026] [security2:error] [pid 157386:tid 157421] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSC_01jzAhYHVVT1Wf73wABWCI"] [Tue Aug 18 13:06:24.175625 2026] [security2:error] [pid 157386:tid 157518] [client 20.206.73.37:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/uwu.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf78wAAAQw"] [Tue Aug 18 13:06:24.292400 2026] [security2:error] [pid 157386:tid 157559] [client 34.38.184.238:25946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.184.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.meneghel.com"] [uri "/info.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf7-AAAATU"] [Tue Aug 18 13:06:24.311361 2026] [security2:error] [pid 157386:tid 157577] [client 20.116.17.175:58417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf7-gAAAUc"] [Tue Aug 18 13:06:24.358903 2026] [security2:error] [pid 157386:tid 157553] [client 34.38.184.238:25930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "mail.meneghel.com"] [uri "/.bash_history"] [unique_id "aoSDAE1jzAhYHVVT1Wf7_AAAAS8"] [Tue Aug 18 13:06:24.360899 2026] [security2:error] [pid 157386:tid 157607] [client 185.191.171.10:59400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752167229/1753920000/"] [unique_id "aoSDAE1jzAhYHVVT1Wf7_QAAAWU"] [Tue Aug 18 13:06:24.361047 2026] [security2:error] [pid 157386:tid 157607] [client 185.191.171.10:59400] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752167229/1753920000/"] [unique_id "aoSDAE1jzAhYHVVT1Wf7_QAAAWU"] [Tue Aug 18 13:06:24.452444 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:22927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ry.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8AgAAASE"] [Tue Aug 18 13:06:24.466306 2026] [security2:error] [pid 157386:tid 157526] [client 20.1.169.243:15974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-setting.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8AwAAARQ"] [Tue Aug 18 13:06:24.479488 2026] [security2:error] [pid 157386:tid 157623] [client 20.171.51.14:18675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ri.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8BAAAAXU"] [Tue Aug 18 13:06:24.543553 2026] [security2:error] [pid 157386:tid 157550] [client 34.38.184.238:26014] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.meneghel.com"] [uri "/_ignition/health-check"] [unique_id "aoSDAE1jzAhYHVVT1Wf8BwAAASw"] [Tue Aug 18 13:06:24.581317 2026] [security2:error] [pid 157386:tid 157562] [client 20.1.169.243:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/0x.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8CwAAATg"] [Tue Aug 18 13:06:24.583667 2026] [security2:error] [pid 157386:tid 157611] [client 168.62.48.100:18133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8DAAAAWk"] [Tue Aug 18 13:06:24.617921 2026] [authz_core:error] [pid 157386:tid 157416] [remote 57.141.22.120:34240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:24.618205 2026] [authz_core:error] [pid 157386:tid 157416] [remote 57.141.22.120:34240] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:24.647170 2026] [security2:error] [pid 157386:tid 157589] [client 20.206.73.37:21073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/nano.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8DwAAAVM"] [Tue Aug 18 13:06:24.685628 2026] [security2:error] [pid 157386:tid 157619] [client 20.79.204.6:11693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8EAAAAXE"] [Tue Aug 18 13:06:24.707254 2026] [security2:error] [pid 157386:tid 157541] [client 149.34.210.141:60987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSC_U1jzAhYHVVT1Wf7KQAAASM"] [Tue Aug 18 13:06:24.734504 2026] [security2:error] [pid 157386:tid 157486] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/xx.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8EwABF2M"] [Tue Aug 18 13:06:24.743733 2026] [security2:error] [pid 157386:tid 157631] [client 158.23.17.4:20431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/r.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8FAAAAX0"] [Tue Aug 18 13:06:24.750141 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:10617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/rf.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8FQAAAUM"] [Tue Aug 18 13:06:24.777941 2026] [security2:error] [pid 157386:tid 157585] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8FwAAAU8"] [Tue Aug 18 13:06:24.790477 2026] [security2:error] [pid 157386:tid 157590] [client 74.248.130.103:7513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/wsomini.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8GAAAAVQ"] [Tue Aug 18 13:06:24.837654 2026] [security2:error] [pid 157386:tid 157599] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8GwAAAV0"] [Tue Aug 18 13:06:24.845041 2026] [security2:error] [pid 157386:tid 157433] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8HAABEi4"] [Tue Aug 18 13:06:24.845246 2026] [security2:error] [pid 157386:tid 157524] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8HAABEi4"] [Tue Aug 18 13:06:24.942310 2026] [security2:error] [pid 157386:tid 157536] [client 20.250.13.23:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/chosen.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8IQAAAR4"] [Tue Aug 18 13:06:24.969776 2026] [security2:error] [pid 157386:tid 157507] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/zwso.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8IgABTHg"] [Tue Aug 18 13:06:24.999780 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.100.201:54077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/pucci.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8JQAAAXU"] [Tue Aug 18 13:06:25.026073 2026] [security2:error] [pid 157386:tid 157592] [client 20.1.169.243:4992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/file.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8JwAAAVY"] [Tue Aug 18 13:06:25.032909 2026] [security2:error] [pid 157386:tid 157548] [client 20.251.48.93:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/k.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8KAAAASo"] [Tue Aug 18 13:06:25.047611 2026] [security2:error] [pid 157386:tid 157579] [client 20.171.51.14:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/tp.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8LAAAAUk"] [Tue Aug 18 13:06:25.151864 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:21664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/creds.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8NwAAASU"] [Tue Aug 18 13:06:25.165600 2026] [security2:error] [pid 157386:tid 157626] [client 223.185.37.47:17556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8OQAAAXg"] [Tue Aug 18 13:06:25.165765 2026] [security2:error] [pid 157386:tid 157626] [client 223.185.37.47:17556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8OQAAAXg"] [Tue Aug 18 13:06:25.205793 2026] [security2:error] [pid 157386:tid 157605] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8OwAAAWM"] [Tue Aug 18 13:06:25.244020 2026] [security2:error] [pid 157386:tid 157586] [client 20.116.17.175:45282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/crgio.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8PgAAAVA"] [Tue Aug 18 13:06:25.249078 2026] [access_compat:error] [pid 157386:tid 157610] [client 34.38.184.238:26076] AH01797: client denied by server configuration: /home4/meneghel/public_html/server-status [Tue Aug 18 13:06:25.251479 2026] [security2:error] [pid 157386:tid 157632] [client 68.155.156.252:22132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/gi.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8PwAAAX4"] [Tue Aug 18 13:06:25.271311 2026] [security2:error] [pid 157386:tid 157576] [client 37.40.227.74:56817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8QAAAAUY"] [Tue Aug 18 13:06:25.275469 2026] [security2:error] [pid 157386:tid 157576] [client 37.40.227.74:56817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8QAAAAUY"] [Tue Aug 18 13:06:25.289005 2026] [security2:error] [pid 157386:tid 157537] [client 20.25.139.174:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/bless.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8QwAAAR8"] [Tue Aug 18 13:06:25.301057 2026] [security2:error] [pid 157386:tid 157621] [client 20.250.13.23:24930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luceanjo.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8RAAAAXM"] [Tue Aug 18 13:06:25.330839 2026] [security2:error] [pid 157386:tid 157552] [client 52.173.121.69:35084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/Cachex.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8RgAAAS4"] [Tue Aug 18 13:06:25.353101 2026] [security2:error] [pid 157386:tid 157601] [client 20.79.204.6:11668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8RwAAAV8"] [Tue Aug 18 13:06:25.369174 2026] [security2:error] [pid 157386:tid 157569] [client 20.104.49.167:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/fi.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8SAAAAT8"] [Tue Aug 18 13:06:25.375107 2026] [security2:error] [pid 157386:tid 157542] [client 74.249.206.207:64539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/apreset.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8SQAAASQ"] [Tue Aug 18 13:06:25.375251 2026] [security2:error] [pid 157386:tid 157391] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/x.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8SgABfAQ"] [Tue Aug 18 13:06:25.439027 2026] [security2:error] [pid 157386:tid 157616] [client 197.184.64.235:42681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8SwAAAW4"] [Tue Aug 18 13:06:25.439148 2026] [security2:error] [pid 157386:tid 157616] [client 197.184.64.235:42681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8SwAAAW4"] [Tue Aug 18 13:06:25.457053 2026] [security2:error] [pid 157386:tid 157592] [client 20.206.73.37:15784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "levalixo.com.br"] [uri "/.mopj.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8TgAAAVY"] [Tue Aug 18 13:06:25.479399 2026] [security2:error] [pid 157386:tid 157614] [client 20.1.169.243:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8TwAAAWw"] [Tue Aug 18 13:06:25.550610 2026] [security2:error] [pid 157386:tid 157484] [remote 52.139.47.57:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8UAABWmE"] [Tue Aug 18 13:06:25.550710 2026] [security2:error] [pid 157386:tid 157484] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/1.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8UAABWmE"] [Tue Aug 18 13:06:25.578824 2026] [security2:error] [pid 157386:tid 157534] [client 68.221.73.131:61513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8UwAAARw"] [Tue Aug 18 13:06:25.637864 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:21695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/mandrill.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8VgAAASU"] [Tue Aug 18 13:06:25.644716 2026] [security2:error] [pid 157386:tid 157629] [client 68.155.156.252:23746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/video.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8VwAAAXs"] [Tue Aug 18 13:06:25.648894 2026] [security2:error] [pid 157386:tid 157517] [client 20.250.13.23:44079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/asd.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8WAAAAQs"] [Tue Aug 18 13:06:25.675785 2026] [security2:error] [pid 157386:tid 157544] [client 20.116.17.175:58199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8WgAAASY"] [Tue Aug 18 13:06:25.745138 2026] [security2:error] [pid 157386:tid 157628] [client 74.249.206.207:32599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/1mage.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8XQAAAXo"] [Tue Aug 18 13:06:25.857516 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.49.167:2570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/chris.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8ZAAAAUo"] [Tue Aug 18 13:06:25.883545 2026] [security2:error] [pid 157386:tid 157552] [client 74.248.130.103:21219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.cf7616030820.reinertimoveis.com.br"] [uri "/vr.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8ZQAAAS4"] [Tue Aug 18 13:06:25.886546 2026] [security2:error] [pid 157386:tid 157607] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8ZgAAAWU"] [Tue Aug 18 13:06:25.910986 2026] [security2:error] [pid 157386:tid 157583] [client 158.23.17.4:14052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/17.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8ZwAAAU0"] [Tue Aug 18 13:06:25.926180 2026] [security2:error] [pid 157386:tid 157591] [client 213.35.127.232:50893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8aAAAAVU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:25.936194 2026] [security2:error] [pid 157386:tid 157536] [client 20.116.17.175:22651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDAU1jzAhYHVVT1Wf8agAAAR4"] [Tue Aug 18 13:06:26.018508 2026] [security2:error] [pid 157386:tid 157475] [remote 209.42.21.221:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSDAE1jzAhYHVVT1Wf8JAABFFg"] [Tue Aug 18 13:06:26.031191 2026] [security2:error] [pid 157386:tid 157576] [client 20.79.204.6:11697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/abcd.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8cAAAAUY"] [Tue Aug 18 13:06:26.040831 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:36690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pm.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8cQAAAUk"] [Tue Aug 18 13:06:26.071613 2026] [security2:error] [pid 157386:tid 157521] [client 20.250.13.23:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/i.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8dQAAAQ8"] [Tue Aug 18 13:06:26.100290 2026] [security2:error] [pid 157386:tid 157596] [client 20.251.48.93:17071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/w.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8eQAAAVo"] [Tue Aug 18 13:06:26.108203 2026] [security2:error] [pid 157386:tid 157454] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/z.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8egABE0M"] [Tue Aug 18 13:06:26.116987 2026] [security2:error] [pid 157386:tid 157631] [client 20.25.139.174:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/sagax1.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8ewAAAX0"] [Tue Aug 18 13:06:26.231040 2026] [security2:error] [pid 157386:tid 157575] [client 20.25.139.174:4362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/x.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8gAAAAUU"] [Tue Aug 18 13:06:26.283370 2026] [security2:error] [pid 157386:tid 157517] [client 20.226.36.136:38501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8gwAAAQs"] [Tue Aug 18 13:06:26.285710 2026] [security2:error] [pid 157386:tid 157509] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/ee.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8hAABd3o"] [Tue Aug 18 13:06:26.299116 2026] [security2:error] [pid 157386:tid 157605] [client 74.248.130.103:27584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8hQAAAWM"] [Tue Aug 18 13:06:26.361702 2026] [security2:error] [pid 157386:tid 157598] [client 158.158.74.177:9900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-post.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8kAAAAVw"] [Tue Aug 18 13:06:26.407440 2026] [autoindex:error] [pid 157386:tid 157524] [client 169.58.72.248:54381] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:26.410285 2026] [security2:error] [pid 157386:tid 157569] [client 86.120.159.145:21423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8mgAAAT8"] [Tue Aug 18 13:06:26.410402 2026] [security2:error] [pid 157386:tid 157569] [client 86.120.159.145:21423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8mgAAAT8"] [Tue Aug 18 13:06:26.422163 2026] [security2:error] [pid 157386:tid 157580] [client 52.173.121.69:31217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8mwAAAUo"] [Tue Aug 18 13:06:26.459563 2026] [security2:error] [pid 157386:tid 157442] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/we.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8ngABZTc"] [Tue Aug 18 13:06:26.471082 2026] [security2:error] [pid 157386:tid 157568] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/sf.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8nwAAAT4"] [Tue Aug 18 13:06:26.551522 2026] [security2:error] [pid 157386:tid 157529] [client 68.155.156.252:23755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/hel.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8pgAAARc"] [Tue Aug 18 13:06:26.567628 2026] [security2:error] [pid 157386:tid 157411] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/f5.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8qAABMBg"] [Tue Aug 18 13:06:26.582333 2026] [security2:error] [pid 157386:tid 157518] [client 20.116.17.175:22574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/css.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8rwAAAQw"] [Tue Aug 18 13:06:26.586881 2026] [security2:error] [pid 157386:tid 157526] [client 20.171.51.14:6615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/zj.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8sAAAARQ"] [Tue Aug 18 13:06:26.594771 2026] [security2:error] [pid 157386:tid 157577] [client 127.0.0.1:56426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "aoSDAk1jzAhYHVVT1Wf8nQAAAUc"] [Tue Aug 18 13:06:26.594853 2026] [security2:error] [pid 157386:tid 157553] [client 74.7.244.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "autodiscover.grupoi9x.com.br"] [uri "/robots.txt"] [unique_id "aoSDAk1jzAhYHVVT1Wf8nAAAAS8"] [Tue Aug 18 13:06:26.604055 2026] [security2:error] [pid 157386:tid 157530] [client 20.251.48.93:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/fpwch.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8sgAAARg"] [Tue Aug 18 13:06:26.612581 2026] [security2:error] [pid 157386:tid 157621] [client 102.213.179.104:51373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8rgAAAXM"] [Tue Aug 18 13:06:26.612687 2026] [security2:error] [pid 157386:tid 157621] [client 102.213.179.104:51373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8rgAAAXM"] [Tue Aug 18 13:06:26.632108 2026] [security2:error] [pid 157386:tid 157413] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/to.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8tAABaRo"] [Tue Aug 18 13:06:26.635294 2026] [security2:error] [pid 157386:tid 157620] [client 20.104.100.201:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wicked.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8tQAAAXI"] [Tue Aug 18 13:06:26.644131 2026] [security2:error] [pid 157386:tid 157525] [client 68.221.73.131:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8tgAAARM"] [Tue Aug 18 13:06:26.710425 2026] [security2:error] [pid 157386:tid 157619] [client 20.1.169.243:15981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wpr-addons/forms/b1ack.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8uwAAAXE"] [Tue Aug 18 13:06:26.722389 2026] [security2:error] [pid 157386:tid 157626] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-good.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8vAAAAXg"] [Tue Aug 18 13:06:26.838848 2026] [security2:error] [pid 157386:tid 157638] [client 40.74.65.169:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8xAAAAYQ"] [Tue Aug 18 13:06:26.851364 2026] [security2:error] [pid 157386:tid 157452] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/ty.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf8xQABXEE"] [Tue Aug 18 13:06:26.893744 2026] [authz_core:error] [pid 157386:tid 157408] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:26.894069 2026] [authz_core:error] [pid 157386:tid 157408] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:26.972050 2026] [security2:error] [pid 157386:tid 157633] [client 74.248.130.103:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf80wAAAX8"] [Tue Aug 18 13:06:26.999446 2026] [security2:error] [pid 157386:tid 157563] [client 20.25.139.174:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/index/function.php"] [unique_id "aoSDAk1jzAhYHVVT1Wf81gAAATk"] [Tue Aug 18 13:06:27.033730 2026] [security2:error] [pid 157386:tid 157558] [client 20.116.17.175:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/cok.php"] [unique_id "aoSDA01jzAhYHVVT1Wf81wAAATQ"] [Tue Aug 18 13:06:27.049853 2026] [security2:error] [pid 157386:tid 157535] [client 20.116.17.175:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDA01jzAhYHVVT1Wf82QAAAR0"] [Tue Aug 18 13:06:27.090085 2026] [security2:error] [pid 157386:tid 157554] [client 20.104.49.167:21896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/doc.php"] [unique_id "aoSDA01jzAhYHVVT1Wf83AAAATA"] [Tue Aug 18 13:06:27.099093 2026] [security2:error] [pid 157386:tid 157592] [client 20.251.48.93:3828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDA01jzAhYHVVT1Wf83gAAAVY"] [Tue Aug 18 13:06:27.157186 2026] [security2:error] [pid 157386:tid 157577] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/k.php"] [unique_id "aoSDA01jzAhYHVVT1Wf84gAAAUc"] [Tue Aug 18 13:06:27.166254 2026] [security2:error] [pid 157386:tid 157566] [client 20.1.169.243:15991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/x.php"] [unique_id "aoSDA01jzAhYHVVT1Wf84wAAATw"] [Tue Aug 18 13:06:27.260630 2026] [security2:error] [pid 157386:tid 157639] [client 68.155.154.236:14151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDA01jzAhYHVVT1Wf85gAAAYU"] [Tue Aug 18 13:06:27.273449 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/dr.php"] [unique_id "aoSDA01jzAhYHVVT1Wf85wAAAXQ"] [Tue Aug 18 13:06:27.306222 2026] [security2:error] [pid 157386:tid 157600] [client 74.249.206.207:32566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/imsc.php"] [unique_id "aoSDA01jzAhYHVVT1Wf86AAAAV4"] [Tue Aug 18 13:06:27.352583 2026] [lsapi:error] [pid 157386:tid 157404] [remote 168.181.166.128:1731] [host riobrancoconsultorios.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29308 [Tue Aug 18 13:06:27.352615 2026] [lsapi:error] [pid 157386:tid 157404] [remote 168.181.166.128:1731] [host riobrancoconsultorios.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29308 [Tue Aug 18 13:06:27.352620 2026] [lsapi:error] [pid 157386:tid 157404] [remote 168.181.166.128:1731] [host riobrancoconsultorios.com.br] Client error on sending request(POST /agenda/painel/paginas/agendamentos/listar-horarios.php HTTP/2.0); uri(/agenda/painel/paginas/agendamentos/listar-horarios.php) content-length(74): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://riobrancoconsultorios.com.br/agenda/painel/index.php?pagina=agendamentos_form&editar_id=29308 [Tue Aug 18 13:06:27.388907 2026] [security2:error] [pid 157386:tid 157618] [client 20.250.13.23:44053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/akc.php"] [unique_id "aoSDA01jzAhYHVVT1Wf87wAAAXA"] [Tue Aug 18 13:06:27.406375 2026] [security2:error] [pid 157386:tid 157428] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/ak.php"] [unique_id "aoSDA01jzAhYHVVT1Wf88AABeSk"] [Tue Aug 18 13:06:27.423264 2026] [security2:error] [pid 157386:tid 157528] [client 158.23.17.4:56704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ev.php"] [unique_id "aoSDA01jzAhYHVVT1Wf88QAAARY"] [Tue Aug 18 13:06:27.466160 2026] [security2:error] [pid 157386:tid 157598] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/media.php"] [unique_id "aoSDA01jzAhYHVVT1Wf88gAAAVw"] [Tue Aug 18 13:06:27.474969 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/dragonshell.php"] [unique_id "aoSDA01jzAhYHVVT1Wf88wAAAYc"] [Tue Aug 18 13:06:27.481451 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:22589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/epinyins.php"] [unique_id "aoSDA01jzAhYHVVT1Wf89AAAAX4"] [Tue Aug 18 13:06:27.488570 2026] [security2:error] [pid 157386:tid 157556] [client 68.155.156.252:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/grok.php"] [unique_id "aoSDA01jzAhYHVVT1Wf89QAAATI"] [Tue Aug 18 13:06:27.532638 2026] [security2:error] [pid 157386:tid 157601] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/tes.php"] [unique_id "aoSDA01jzAhYHVVT1Wf89wAAAV8"] [Tue Aug 18 13:06:27.551815 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/accesson.php"] [unique_id "aoSDA01jzAhYHVVT1Wf8-AAAAYg"] [Tue Aug 18 13:06:27.569361 2026] [security2:error] [pid 157386:tid 157633] [client 20.251.48.93:55349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/blurbs.php"] [unique_id "aoSDA01jzAhYHVVT1Wf8-QAAAX8"] [Tue Aug 18 13:06:27.586843 2026] [security2:error] [pid 157386:tid 157589] [client 20.1.169.243:15592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/yellow.php"] [unique_id "aoSDA01jzAhYHVVT1Wf8-wAAAVM"] [Tue Aug 18 13:06:27.668357 2026] [security2:error] [pid 157386:tid 157522] [client 74.249.206.207:32582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDA01jzAhYHVVT1Wf8_wAAARA"] [Tue Aug 18 13:06:27.668939 2026] [security2:error] [pid 157386:tid 157554] [client 20.1.169.243:4484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9AAAAATA"] [Tue Aug 18 13:06:27.678608 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:29321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/main.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9AQAAAVY"] [Tue Aug 18 13:06:27.721919 2026] [security2:error] [pid 157386:tid 157548] [client 20.151.109.219:39812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kh.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9AwAAASo"] [Tue Aug 18 13:06:27.732449 2026] [security2:error] [pid 157386:tid 157625] [client 20.79.204.6:11711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9BAAAAXc"] [Tue Aug 18 13:06:27.761635 2026] [security2:error] [pid 157386:tid 157553] [client 52.173.121.69:31888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9CAAAAS8"] [Tue Aug 18 13:06:27.800454 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:27.800888 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:27.865616 2026] [security2:error] [pid 157386:tid 157631] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/files/index.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9CwAAAX0"] [Tue Aug 18 13:06:27.913320 2026] [security2:error] [pid 157386:tid 157549] [client 222.124.191.185:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9DgAAASs"] [Tue Aug 18 13:06:27.913423 2026] [security2:error] [pid 157386:tid 157549] [client 222.124.191.185:58906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9DgAAASs"] [Tue Aug 18 13:06:27.959271 2026] [security2:error] [pid 157386:tid 157459] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/fm.php"] [unique_id "aoSDA01jzAhYHVVT1Wf9DwABNUg"] [Tue Aug 18 13:06:28.011357 2026] [security2:error] [pid 157386:tid 157517] [client 20.127.136.245:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/as.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9FAAAAQs"] [Tue Aug 18 13:06:28.022378 2026] [security2:error] [pid 157386:tid 157567] [client 20.171.51.14:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/x.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9FQAAAT0"] [Tue Aug 18 13:06:28.052942 2026] [security2:error] [pid 157386:tid 157605] [client 68.155.156.252:33691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/indes.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9GAAAAWM"] [Tue Aug 18 13:06:28.064505 2026] [security2:error] [pid 157386:tid 157573] [client 20.116.17.175:22594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/load.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9GQAAAUM"] [Tue Aug 18 13:06:28.082208 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:63283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/jb.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9GgAAAXk"] [Tue Aug 18 13:06:28.126111 2026] [security2:error] [pid 157386:tid 157638] [client 20.151.109.219:24842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/payout.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9HQAAAYQ"] [Tue Aug 18 13:06:28.134216 2026] [security2:error] [pid 157386:tid 157436] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/wp.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9HgABTDE"] [Tue Aug 18 13:06:28.152865 2026] [security2:error] [pid 157386:tid 157437] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/al.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9IAABWDI"] [Tue Aug 18 13:06:28.180471 2026] [security2:error] [pid 157386:tid 157556] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9IQAAATI"] [Tue Aug 18 13:06:28.194195 2026] [security2:error] [pid 157386:tid 157557] [client 20.116.17.175:20377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/setup-config.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9IwAAATM"] [Tue Aug 18 13:06:28.260200 2026] [security2:error] [pid 157386:tid 157626] [client 20.1.169.243:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9JQAAAXg"] [Tue Aug 18 13:06:28.308483 2026] [security2:error] [pid 157386:tid 157430] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/33.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9JwABJCs"] [Tue Aug 18 13:06:28.341319 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.100.201:53843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/water.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9KQAAAXU"] [Tue Aug 18 13:06:28.460083 2026] [security2:error] [pid 157386:tid 157607] [client 20.226.36.136:63845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9LwAAAWU"] [Tue Aug 18 13:06:28.483613 2026] [security2:error] [pid 157386:tid 157431] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/az.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9MAABVSw"] [Tue Aug 18 13:06:28.498150 2026] [security2:error] [pid 157386:tid 157621] [client 20.171.51.14:47113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/yn.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9MgAAAXM"] [Tue Aug 18 13:06:28.515215 2026] [security2:error] [pid 157386:tid 157527] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/images/images/about.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9MwAAARU"] [Tue Aug 18 13:06:28.526001 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.49.167:21943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/1337.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9NAAAAWk"] [Tue Aug 18 13:06:28.601336 2026] [security2:error] [pid 157386:tid 157631] [client 74.249.206.207:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/qlex1.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9NwAAAX0"] [Tue Aug 18 13:06:28.601661 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:39824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/do.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9OAAAAW4"] [Tue Aug 18 13:06:28.638442 2026] [security2:error] [pid 157386:tid 157541] [client 20.250.13.23:44039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/maintenance.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9OgAAASM"] [Tue Aug 18 13:06:28.683893 2026] [security2:error] [pid 157386:tid 157518] [client 20.116.17.175:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/f35.update.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9QgAAAQw"] [Tue Aug 18 13:06:28.705412 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.156.252:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/tTPcH.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9RwAAAV4"] [Tue Aug 18 13:06:28.859820 2026] [security2:error] [pid 157386:tid 157573] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9SwAAAUM"] [Tue Aug 18 13:06:28.864541 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:17556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/Mailgun.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9TAAAAVA"] [Tue Aug 18 13:06:28.887474 2026] [security2:error] [pid 157386:tid 157461] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/inc.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9TwABhEo"] [Tue Aug 18 13:06:28.919689 2026] [security2:error] [pid 157386:tid 157598] [client 52.173.121.69:10663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9VgAAAVw"] [Tue Aug 18 13:06:28.924830 2026] [security2:error] [pid 157386:tid 157594] [client 20.215.241.237:26642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/sf.php"] [unique_id "aoSDBE1jzAhYHVVT1Wf9VwAAAVg"] [Tue Aug 18 13:06:29.035508 2026] [security2:error] [pid 157386:tid 157419] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/sx.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9YAABJCA"] [Tue Aug 18 13:06:29.076470 2026] [security2:error] [pid 157386:tid 157569] [client 20.250.13.23:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9YQAAAT8"] [Tue Aug 18 13:06:29.081156 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:58189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/yw.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9ZAAAAXU"] [Tue Aug 18 13:06:29.092422 2026] [security2:error] [pid 157386:tid 157561] [client 213.35.127.232:51427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9ZQAAATc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:29.099465 2026] [security2:error] [pid 157386:tid 157531] [client 74.249.206.207:64537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/mariju.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9ZgAAARk"] [Tue Aug 18 13:06:29.105086 2026] [security2:error] [pid 157386:tid 157589] [client 20.104.100.201:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/fine.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9ZwAAAVM"] [Tue Aug 18 13:06:29.107103 2026] [security2:error] [pid 157386:tid 157585] [client 20.206.73.37:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/signon.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9aAAAAU8"] [Tue Aug 18 13:06:29.116304 2026] [security2:error] [pid 157386:tid 157566] [client 20.127.136.245:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/min.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9aQAAATw"] [Tue Aug 18 13:06:29.139464 2026] [security2:error] [pid 157386:tid 157544] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/admin.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9awAAASY"] [Tue Aug 18 13:06:29.147793 2026] [security2:error] [pid 157386:tid 157547] [client 149.34.210.141:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9bAAAASk"] [Tue Aug 18 13:06:29.217119 2026] [security2:error] [pid 157386:tid 157602] [client 20.25.139.174:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/aaa.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9bwAAAWA"] [Tue Aug 18 13:06:29.325735 2026] [security2:error] [pid 157386:tid 157630] [client 68.155.156.252:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/bs1.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9cAAAAXw"] [Tue Aug 18 13:06:29.328123 2026] [security2:error] [pid 157386:tid 157635] [client 20.1.169.243:5038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/3.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9cQAAAYE"] [Tue Aug 18 13:06:29.349970 2026] [security2:error] [pid 157386:tid 157592] [client 20.250.13.23:23690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/options-writing.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9cgAAAVY"] [Tue Aug 18 13:06:29.406931 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.49.167:48563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/Njima.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9cwAAAQw"] [Tue Aug 18 13:06:29.416867 2026] [security2:error] [pid 157386:tid 157575] [client 20.116.17.175:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/bdroot.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9dAAAAUU"] [Tue Aug 18 13:06:29.429861 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/qh.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9dgAAAUk"] [Tue Aug 18 13:06:29.480716 2026] [security2:error] [pid 157386:tid 157597] [client 40.74.65.169:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9egAAAVs"] [Tue Aug 18 13:06:29.510217 2026] [security2:error] [pid 157386:tid 157605] [client 68.155.154.236:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9fAAAAWM"] [Tue Aug 18 13:06:29.571299 2026] [security2:error] [pid 157386:tid 157618] [client 20.116.17.175:22605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9hAAAAXA"] [Tue Aug 18 13:06:29.582424 2026] [security2:error] [pid 157386:tid 157478] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/tfm.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9hQABhFs"] [Tue Aug 18 13:06:29.615461 2026] [security2:error] [pid 157386:tid 157598] [client 52.173.121.69:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9hgAAAVw"] [Tue Aug 18 13:06:29.630477 2026] [security2:error] [pid 157386:tid 157594] [client 158.23.17.4:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xs.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9hwAAAVg"] [Tue Aug 18 13:06:29.672057 2026] [security2:error] [pid 157386:tid 157556] [client 74.249.206.207:64521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9iAAAATI"] [Tue Aug 18 13:06:29.772344 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/r.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9jgAAAS4"] [Tue Aug 18 13:06:29.773178 2026] [security2:error] [pid 157386:tid 157568] [client 20.25.139.174:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wpc.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9jwAAAT4"] [Tue Aug 18 13:06:29.781565 2026] [security2:error] [pid 157386:tid 157601] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/82.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9kAAAAV8"] [Tue Aug 18 13:06:29.793509 2026] [security2:error] [pid 157386:tid 157554] [client 178.153.171.161:24661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9jQAAATA"] [Tue Aug 18 13:06:29.793625 2026] [security2:error] [pid 157386:tid 157554] [client 178.153.171.161:24661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9jQAAATA"] [Tue Aug 18 13:06:29.810051 2026] [security2:error] [pid 157386:tid 157633] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/mac.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9kQAAAX8"] [Tue Aug 18 13:06:29.845737 2026] [security2:error] [pid 157386:tid 157632] [client 20.25.139.174:4830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/abcd.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9kwAAAX4"] [Tue Aug 18 13:06:29.855959 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.100.201:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/loader.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9lAAAAQ8"] [Tue Aug 18 13:06:29.866497 2026] [security2:error] [pid 157386:tid 157510] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9lQABN3s"] [Tue Aug 18 13:06:29.942624 2026] [security2:error] [pid 157386:tid 157591] [client 20.171.51.14:58007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/11.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9lgAAAVU"] [Tue Aug 18 13:06:30.049339 2026] [security2:error] [pid 157386:tid 157527] [client 68.155.156.252:15304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/hp2.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9nQAAARU"] [Tue Aug 18 13:06:30.102465 2026] [security2:error] [pid 157386:tid 157433] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/x.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9ngABRi4"] [Tue Aug 18 13:06:30.117256 2026] [security2:error] [pid 157386:tid 157393] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/asd.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9nwABewY"] [Tue Aug 18 13:06:30.118176 2026] [security2:error] [pid 157386:tid 157584] [client 20.226.36.136:38473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9oAAAAU4"] [Tue Aug 18 13:06:30.137681 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:65045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/17.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9oQAAAXw"] [Tue Aug 18 13:06:30.137703 2026] [security2:error] [pid 157386:tid 157635] [client 20.116.17.175:22543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ty.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9ogAAAYE"] [Tue Aug 18 13:06:30.143221 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:17567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/oauth.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9owAAAVY"] [Tue Aug 18 13:06:30.159411 2026] [security2:error] [pid 157386:tid 157438] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.env"] [unique_id "aoSDBk1jzAhYHVVT1Wf9pQABOjM"] [Tue Aug 18 13:06:30.189335 2026] [security2:error] [pid 157386:tid 157543] [client 20.1.169.243:5312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/as.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9qwAAASU"] [Tue Aug 18 13:06:30.206585 2026] [security2:error] [pid 157386:tid 157518] [client 40.74.65.169:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/blurbs.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9rQAAAQw"] [Tue Aug 18 13:06:30.219100 2026] [security2:error] [pid 157386:tid 157627] [client 20.1.169.243:5028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/config.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9rwAAAXk"] [Tue Aug 18 13:06:30.232749 2026] [security2:error] [pid 157386:tid 157579] [client 68.155.154.236:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9sAAAAUk"] [Tue Aug 18 13:06:30.250436 2026] [security2:error] [pid 157386:tid 157526] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/rip.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9sgAAARQ"] [Tue Aug 18 13:06:30.279594 2026] [security2:error] [pid 157386:tid 157417] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/nij.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9tAABYR4"] [Tue Aug 18 13:06:30.338128 2026] [security2:error] [pid 157386:tid 157428] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/filemanager.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9vQABCyk"] [Tue Aug 18 13:06:30.344812 2026] [security2:error] [pid 157386:tid 157617] [client 213.202.253.4:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9vgAAAW8"], referer: www.google.com [Tue Aug 18 13:06:30.371032 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.36.136:48841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9vwAAAWM"] [Tue Aug 18 13:06:30.426997 2026] [security2:error] [pid 157386:tid 157585] [client 158.158.74.177:20486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9wgAAAU8"] [Tue Aug 18 13:06:30.433065 2026] [security2:error] [pid 157386:tid 157641] [client 52.173.121.69:49546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9wwAAAYc"] [Tue Aug 18 13:06:30.464920 2026] [security2:error] [pid 157386:tid 157524] [client 40.80.82.167:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "grupoi9x.com.br"] [uri "/1.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9ywAAARI"] [Tue Aug 18 13:06:30.465024 2026] [security2:error] [pid 157386:tid 157524] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/1.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9ywAAARI"] [Tue Aug 18 13:06:30.489613 2026] [security2:error] [pid 157386:tid 157578] [client 68.155.156.252:23292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/yb.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9zAAAAUg"] [Tue Aug 18 13:06:30.500472 2026] [security2:error] [pid 157386:tid 157568] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/dex.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9zQAAAT4"] [Tue Aug 18 13:06:30.504790 2026] [security2:error] [pid 157386:tid 157601] [client 20.171.51.14:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vm.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9zgAAAV8"] [Tue Aug 18 13:06:30.516749 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/timeclock.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9zwAAAX8"] [Tue Aug 18 13:06:30.532402 2026] [security2:error] [pid 157386:tid 157623] [client 74.248.130.103:10723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf90QAAAXU"] [Tue Aug 18 13:06:30.541374 2026] [security2:error] [pid 157386:tid 157531] [client 157.90.155.240:49208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.chicodareia.com.br"] [uri "/index.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9wAAAARk"], referer: https://www.chicodareia.com.br/ [Tue Aug 18 13:06:30.623526 2026] [security2:error] [pid 157386:tid 157557] [client 20.1.169.243:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/simple.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf92wAAATM"] [Tue Aug 18 13:06:30.634269 2026] [security2:error] [pid 157386:tid 157583] [client 158.23.17.4:63020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/lmfi2.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf93AAAAU0"] [Tue Aug 18 13:06:30.642353 2026] [security2:error] [pid 157386:tid 157591] [client 68.221.73.131:7859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/simple.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf93QAAAVU"] [Tue Aug 18 13:06:30.734350 2026] [security2:error] [pid 157386:tid 157602] [client 20.116.17.175:1644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf94AAAAWA"] [Tue Aug 18 13:06:30.746012 2026] [security2:error] [pid 157386:tid 157436] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/wp-login.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf90AABNDE"], referer: https://brasipaodequeijo.com.br/login [Tue Aug 18 13:06:30.776421 2026] [security2:error] [pid 157386:tid 157540] [client 20.127.136.245:28104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/php8.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf94wAAASI"] [Tue Aug 18 13:06:30.784468 2026] [security2:error] [pid 157386:tid 157628] [client 74.249.206.207:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/contacto.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf95AAAAXo"] [Tue Aug 18 13:06:30.811234 2026] [security2:error] [pid 157386:tid 157434] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/404.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf95QABfC8"] [Tue Aug 18 13:06:30.818072 2026] [security2:error] [pid 157386:tid 157621] [client 138.36.100.162:42148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf95gAAAXM"] [Tue Aug 18 13:06:30.837741 2026] [security2:error] [pid 157386:tid 157590] [client 20.250.13.23:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf95wAAAVQ"] [Tue Aug 18 13:06:30.844997 2026] [security2:error] [pid 157386:tid 157551] [client 40.74.65.169:1823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/sf.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf96AAAAS0"] [Tue Aug 18 13:06:30.848492 2026] [security2:error] [pid 157386:tid 157621] [client 138.36.100.162:42148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf95gAAAXM"] [Tue Aug 18 13:06:30.863054 2026] [security2:error] [pid 157386:tid 157563] [client 20.151.109.219:17560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/email.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf96QAAATk"] [Tue Aug 18 13:06:30.967357 2026] [security2:error] [pid 157386:tid 157475] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.env.backup"] [unique_id "aoSDBk1jzAhYHVVT1Wf99AABGFg"] [Tue Aug 18 13:06:30.967367 2026] [security2:error] [pid 157386:tid 157501] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.env.bak"] [unique_id "aoSDBk1jzAhYHVVT1Wf99QABGHI"] [Tue Aug 18 13:06:30.967372 2026] [security2:error] [pid 157386:tid 157405] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.env.old"] [unique_id "aoSDBk1jzAhYHVVT1Wf9-AABGBI"] [Tue Aug 18 13:06:30.980026 2026] [security2:error] [pid 157386:tid 157616] [client 157.20.138.62:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9-QAAAW4"] [Tue Aug 18 13:06:30.980170 2026] [security2:error] [pid 157386:tid 157616] [client 157.20.138.62:49444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDBk1jzAhYHVVT1Wf9-QAAAW4"] [Tue Aug 18 13:06:31.004447 2026] [security2:error] [pid 157386:tid 157547] [client 149.34.210.141:61695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDBU1jzAhYHVVT1Wf9bAAAASk"] [Tue Aug 18 13:06:31.056923 2026] [security2:error] [pid 157386:tid 157399] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/mah.php"] [unique_id "aoSDB01jzAhYHVVT1Wf9_wABcgw"] [Tue Aug 18 13:06:31.065568 2026] [security2:error] [pid 157386:tid 157582] [client 20.116.17.175:20413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-AAAAAUw"] [Tue Aug 18 13:06:31.076415 2026] [security2:error] [pid 157386:tid 157526] [client 20.1.169.243:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/storage/index.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-AQAAARQ"] [Tue Aug 18 13:06:31.149366 2026] [security2:error] [pid 157386:tid 157552] [client 20.251.48.93:17033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/100.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-BAAAAS4"] [Tue Aug 18 13:06:31.192046 2026] [security2:error] [pid 157386:tid 157634] [client 213.35.127.232:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-BwAAAYA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:31.200552 2026] [security2:error] [pid 157386:tid 157443] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-CQABJDg"] [Tue Aug 18 13:06:31.214741 2026] [security2:error] [pid 157386:tid 157619] [client 68.155.156.252:23248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/vc.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-CgAAAXE"] [Tue Aug 18 13:06:31.228115 2026] [security2:error] [pid 157386:tid 157566] [client 20.104.100.201:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/zero.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-CwAAATw"] [Tue Aug 18 13:06:31.236590 2026] [security2:error] [pid 157386:tid 157556] [client 20.116.17.175:22593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/dot.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-DAAAATI"] [Tue Aug 18 13:06:31.271600 2026] [security2:error] [pid 157386:tid 157591] [client 20.226.36.136:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-DgAAAVU"] [Tue Aug 18 13:06:31.325282 2026] [security2:error] [pid 157386:tid 157415] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/api/.env"] [unique_id "aoSDB01jzAhYHVVT1Wf-EAABGBw"] [Tue Aug 18 13:06:31.325446 2026] [security2:error] [pid 157386:tid 157474] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/backend/.env"] [unique_id "aoSDB01jzAhYHVVT1Wf-EwABGFc"] [Tue Aug 18 13:06:31.325550 2026] [security2:error] [pid 157386:tid 157578] [client 20.127.136.245:28118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-FAAAAUg"] [Tue Aug 18 13:06:31.405884 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:31.406148 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:31.425080 2026] [security2:error] [pid 157386:tid 157410] [remote 162.214.96.231:38224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-FQABVhc"] [Tue Aug 18 13:06:31.430727 2026] [security2:error] [pid 157386:tid 157497] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-FwABVG4"] [Tue Aug 18 13:06:31.434219 2026] [security2:error] [pid 157386:tid 157551] [client 20.226.36.136:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/weozh.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-GAAAAS0"] [Tue Aug 18 13:06:31.440156 2026] [security2:error] [pid 157386:tid 157472] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/config/.env"] [unique_id "aoSDB01jzAhYHVVT1Wf-GgABGFU"] [Tue Aug 18 13:06:31.448196 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:64621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/profile.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-HQAAAXM"] [Tue Aug 18 13:06:31.461714 2026] [security2:error] [pid 157386:tid 157612] [client 20.226.36.136:38503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-HgAAAWo"] [Tue Aug 18 13:06:31.487467 2026] [security2:error] [pid 157386:tid 157627] [client 20.171.51.14:42272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/eg.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-IAAAAXk"] [Tue Aug 18 13:06:31.498347 2026] [security2:error] [pid 157386:tid 157529] [client 20.116.17.175:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-css.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-IQAAARc"] [Tue Aug 18 13:06:31.547698 2026] [security2:error] [pid 157386:tid 157597] [client 20.116.17.175:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/av.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-JwAAAVs"] [Tue Aug 18 13:06:31.580977 2026] [security2:error] [pid 157386:tid 157547] [client 40.74.65.169:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/xx.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-KAAAASk"] [Tue Aug 18 13:06:31.588655 2026] [security2:error] [pid 157386:tid 157464] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/ws.php7"] [unique_id "aoSDB01jzAhYHVVT1Wf-KQABb00"] [Tue Aug 18 13:06:31.662499 2026] [security2:error] [pid 157386:tid 157573] [client 40.74.65.169:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/bajah.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-LgAAAUM"] [Tue Aug 18 13:06:31.665658 2026] [security2:error] [pid 157386:tid 157531] [client 20.1.169.243:15941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/post.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-LwAAARk"] [Tue Aug 18 13:06:31.690102 2026] [security2:error] [pid 157386:tid 157563] [client 158.158.74.177:20487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-MAAAATk"] [Tue Aug 18 13:06:31.699201 2026] [security2:error] [pid 157386:tid 157594] [client 20.116.17.175:22596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/005.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-MgAAAVg"] [Tue Aug 18 13:06:31.712283 2026] [security2:error] [pid 157386:tid 157550] [client 20.25.139.174:4453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.secretplaceangradosreis.com.br"] [uri "/wp-good.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-MwAAASw"] [Tue Aug 18 13:06:31.735733 2026] [security2:error] [pid 157386:tid 157570] [client 20.251.48.93:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/ccc.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-NAAAAUA"] [Tue Aug 18 13:06:31.756003 2026] [security2:error] [pid 157386:tid 157414] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/jga.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-NgABPRs"] [Tue Aug 18 13:06:31.759957 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.36.136:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/rymmm.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-NwAAAS4"] [Tue Aug 18 13:06:31.769275 2026] [security2:error] [pid 157386:tid 157532] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-OAAAARo"] [Tue Aug 18 13:06:31.807353 2026] [security2:error] [pid 157386:tid 157498] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/.__info.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-OQABiG8"] [Tue Aug 18 13:06:31.826142 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ev.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-PAAAATw"] [Tue Aug 18 13:06:31.867446 2026] [security2:error] [pid 157386:tid 157632] [client 68.155.156.252:47092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/pema.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-PgAAAX4"] [Tue Aug 18 13:06:31.888950 2026] [security2:error] [pid 157386:tid 157631] [client 20.215.241.237:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/k.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-QAAAAX0"] [Tue Aug 18 13:06:31.905826 2026] [security2:error] [pid 157386:tid 157611] [client 68.221.73.131:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/chosen.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-QQAAAWk"] [Tue Aug 18 13:06:31.914101 2026] [security2:error] [pid 157386:tid 157517] [client 168.62.48.100:18174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/nwwha.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-QgAAAQs"] [Tue Aug 18 13:06:31.914771 2026] [security2:error] [pid 157386:tid 157559] [client 168.62.48.100:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/first.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-QwAAATU"] [Tue Aug 18 13:06:31.916200 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/themes.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-RAAAAYA"] [Tue Aug 18 13:06:31.924494 2026] [security2:error] [pid 157386:tid 157456] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/166.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-RwABL0U"] [Tue Aug 18 13:06:31.934307 2026] [security2:error] [pid 157386:tid 157581] [client 20.226.36.136:62184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/lddxs.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-SAAAAUs"] [Tue Aug 18 13:06:31.966542 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:17558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/summary.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-SgAAASY"] [Tue Aug 18 13:06:31.996940 2026] [security2:error] [pid 157386:tid 157389] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/access.php"] [unique_id "aoSDB01jzAhYHVVT1Wf-SwABLQI"] [Tue Aug 18 13:06:32.014517 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:20942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ts.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-TAAAASU"] [Tue Aug 18 13:06:32.033612 2026] [security2:error] [pid 157386:tid 157539] [client 52.173.121.69:41664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-TgAAASE"] [Tue Aug 18 13:06:32.045632 2026] [security2:error] [pid 157386:tid 157525] [client 74.248.130.103:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/av.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-TwAAARM"] [Tue Aug 18 13:06:32.084443 2026] [security2:error] [pid 157386:tid 157516] [client 20.226.36.136:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/zjggu.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-UgAAAQo"] [Tue Aug 18 13:06:32.085041 2026] [security2:error] [pid 157386:tid 157490] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/wp-login.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-VAABGGc"], referer: https://brasipaodequeijo.com.br/wp-admin/ [Tue Aug 18 13:06:32.102539 2026] [security2:error] [pid 157386:tid 157620] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/moon.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-VgAAAXI"] [Tue Aug 18 13:06:32.149623 2026] [security2:error] [pid 157386:tid 157563] [client 20.79.204.6:11691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-VwAAATk"] [Tue Aug 18 13:06:32.159683 2026] [security2:error] [pid 157386:tid 157594] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/coffee.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-WAAAAVg"] [Tue Aug 18 13:06:32.202943 2026] [security2:error] [pid 157386:tid 157641] [client 20.151.109.219:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xs.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-WQAAAYc"] [Tue Aug 18 13:06:32.203579 2026] [security2:error] [pid 157386:tid 157585] [client 20.226.36.136:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/dlvqo.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-WgAAAU8"] [Tue Aug 18 13:06:32.210783 2026] [security2:error] [pid 157386:tid 157622] [client 20.118.133.132:61276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "bateriasexpress.aju.br"] [uri "/.mopj.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-WwAAAXQ"] [Tue Aug 18 13:06:32.212749 2026] [security2:error] [pid 157386:tid 157579] [client 20.1.169.243:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/atex1.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-XAAAAUk"] [Tue Aug 18 13:06:32.270612 2026] [security2:error] [pid 157386:tid 157421] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/log.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-YgABJCI"] [Tue Aug 18 13:06:32.275468 2026] [security2:error] [pid 157386:tid 157522] [client 20.250.13.23:44094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/maint.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-YwAAARA"] [Tue Aug 18 13:06:32.296139 2026] [security2:error] [pid 157386:tid 157574] [client 213.35.127.232:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-ZAAAAUQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:32.296160 2026] [security2:error] [pid 157386:tid 157557] [client 20.226.36.136:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/pkmoj.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-ZQAAATM"] [Tue Aug 18 13:06:32.308161 2026] [security2:error] [pid 157386:tid 157583] [client 168.62.48.100:18145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/opsqt.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-ZgAAAU0"] [Tue Aug 18 13:06:32.334169 2026] [security2:error] [pid 157386:tid 157631] [client 40.74.65.169:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/adminner.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-aQAAAX0"] [Tue Aug 18 13:06:32.350671 2026] [security2:error] [pid 157386:tid 157545] [client 68.155.154.236:14155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-awAAASc"] [Tue Aug 18 13:06:32.355694 2026] [security2:error] [pid 157386:tid 157611] [client 20.251.48.93:58715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/get.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-bAAAAWk"] [Tue Aug 18 13:06:32.357089 2026] [security2:error] [pid 157386:tid 157611] [client 20.116.17.175:22647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/v2.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-bQAAAWk"] [Tue Aug 18 13:06:32.366448 2026] [security2:error] [pid 157386:tid 157559] [client 20.226.36.136:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/kopyw.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-bgAAATU"] [Tue Aug 18 13:06:32.422275 2026] [security2:error] [pid 157386:tid 157496] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/wp-login.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-cgABZG0"], referer: https://brasipaodequeijo.com.br/wp-admin/ [Tue Aug 18 13:06:32.423916 2026] [security2:error] [pid 157386:tid 157393] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-cwABIgY"] [Tue Aug 18 13:06:32.424085 2026] [security2:error] [pid 157386:tid 157540] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-cwABIgY"] [Tue Aug 18 13:06:32.427402 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:20427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/flox.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-dQAAAUs"] [Tue Aug 18 13:06:32.434621 2026] [security2:error] [pid 157386:tid 157615] [client 74.249.206.207:32540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/image2.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-dgAAAW0"] [Tue Aug 18 13:06:32.443527 2026] [security2:error] [pid 157386:tid 157544] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/cache.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-dwAAASY"] [Tue Aug 18 13:06:32.460178 2026] [security2:error] [pid 157386:tid 157438] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/file.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-eQABczM"] [Tue Aug 18 13:06:32.497027 2026] [security2:error] [pid 157386:tid 157543] [client 20.226.36.136:25089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-egAAASU"] [Tue Aug 18 13:06:32.546262 2026] [security2:error] [pid 157386:tid 157476] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-fAABZVk"] [Tue Aug 18 13:06:32.546504 2026] [security2:error] [pid 157386:tid 157607] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-fAABZVk"] [Tue Aug 18 13:06:32.570763 2026] [security2:error] [pid 157386:tid 157403] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/02.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-gQABFxA"] [Tue Aug 18 13:06:32.571105 2026] [security2:error] [pid 157386:tid 157451] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.github/.env"] [unique_id "aoSDCE1jzAhYHVVT1Wf-fgABUUA"] [Tue Aug 18 13:06:32.639104 2026] [security2:error] [pid 157386:tid 157623] [client 103.120.71.157:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-ggAAAXU"] [Tue Aug 18 13:06:32.639262 2026] [security2:error] [pid 157386:tid 157623] [client 103.120.71.157:53796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-ggAAAXU"] [Tue Aug 18 13:06:32.670016 2026] [security2:error] [pid 157386:tid 157620] [client 20.226.36.136:62173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/zznmg.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-hAAAAXI"] [Tue Aug 18 13:06:32.690706 2026] [security2:error] [pid 157386:tid 157590] [client 168.62.48.100:18063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-hgAAAVQ"] [Tue Aug 18 13:06:32.712387 2026] [security2:error] [pid 157386:tid 157528] [client 197.184.64.235:42682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-hwAAARY"] [Tue Aug 18 13:06:32.712529 2026] [security2:error] [pid 157386:tid 157528] [client 197.184.64.235:42682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-hwAAARY"] [Tue Aug 18 13:06:32.729290 2026] [security2:error] [pid 157386:tid 157641] [client 74.248.130.103:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/images.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-iAAAAYc"] [Tue Aug 18 13:06:32.751103 2026] [security2:error] [pid 157386:tid 157591] [client 20.226.36.136:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/bhfnd.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-iQAAAVU"] [Tue Aug 18 13:06:32.752809 2026] [security2:error] [pid 157386:tid 157404] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/menu.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-igABEhE"] [Tue Aug 18 13:06:32.839031 2026] [security2:error] [pid 157386:tid 157564] [client 20.79.204.6:11563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/akc.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-jAAAATo"] [Tue Aug 18 13:06:32.892990 2026] [security2:error] [pid 157386:tid 157583] [client 20.116.17.175:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/op.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-jwAAAU0"] [Tue Aug 18 13:06:32.896799 2026] [security2:error] [pid 157386:tid 157538] [client 20.171.51.14:6593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/uk.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-kAAAASA"] [Tue Aug 18 13:06:32.938250 2026] [security2:error] [pid 157386:tid 157450] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/spip.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-kgABYT8"] [Tue Aug 18 13:06:32.948366 2026] [security2:error] [pid 157386:tid 157561] [client 20.116.17.175:1617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wkl.php"] [unique_id "aoSDCE1jzAhYHVVT1Wf-lAAAATc"] [Tue Aug 18 13:06:33.003024 2026] [security2:error] [pid 157386:tid 157559] [client 168.62.48.100:18074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-lwAAATU"] [Tue Aug 18 13:06:33.031679 2026] [security2:error] [pid 157386:tid 157605] [client 74.248.18.37:40346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/catalogbypass.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-mQAAAWM"] [Tue Aug 18 13:06:33.041623 2026] [security2:error] [pid 157386:tid 157544] [client 168.62.48.100:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-mwAAASY"] [Tue Aug 18 13:06:33.107703 2026] [security2:error] [pid 157386:tid 157571] [client 20.206.73.37:25092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manoelmotosecarros.com.br"] [uri "/packed.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-ogAAAUE"] [Tue Aug 18 13:06:33.109071 2026] [security2:error] [pid 157386:tid 157606] [client 20.226.36.136:33460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-owAAAWQ"] [Tue Aug 18 13:06:33.120218 2026] [security2:error] [pid 157386:tid 157485] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-pQABMmI"] [Tue Aug 18 13:06:33.130923 2026] [authz_core:error] [pid 157386:tid 157408] [remote 57.141.22.56:58480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:33.131207 2026] [authz_core:error] [pid 157386:tid 157408] [remote 57.141.22.56:58480] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:33.163388 2026] [security2:error] [pid 157386:tid 157529] [client 20.151.109.219:42767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/53.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-pwAAARc"] [Tue Aug 18 13:06:33.164406 2026] [security2:error] [pid 157386:tid 157635] [client 20.104.100.201:53837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/002.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-qAAAAYE"] [Tue Aug 18 13:06:33.178778 2026] [authz_core:error] [pid 157386:tid 157401] [remote 34.73.137.196:38704] AH01630: client denied by server configuration: /home1/agencialkx/brasipaodequeijo.com.br/.htpasswd [Tue Aug 18 13:06:33.195244 2026] [security2:error] [pid 157386:tid 157548] [client 20.1.169.243:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-sAAAASo"] [Tue Aug 18 13:06:33.216103 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:33.216361 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:33.246086 2026] [security2:error] [pid 157386:tid 157516] [client 74.248.130.103:33116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/ops.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-tgAAAQo"] [Tue Aug 18 13:06:33.247042 2026] [security2:error] [pid 157386:tid 157620] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/puc.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-twAAAXI"] [Tue Aug 18 13:06:33.288487 2026] [security2:error] [pid 157386:tid 157526] [client 20.127.136.245:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/222.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-uAAAARQ"] [Tue Aug 18 13:06:33.307957 2026] [security2:error] [pid 157386:tid 157390] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/aksinet.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-ugABOQM"] [Tue Aug 18 13:06:33.363145 2026] [security2:error] [pid 157386:tid 157641] [client 74.249.206.207:32588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/fb.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-vgAAAYc"] [Tue Aug 18 13:06:33.370519 2026] [security2:error] [pid 157386:tid 157475] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/bolt.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-wAABElg"] [Tue Aug 18 13:06:33.379427 2026] [security2:error] [pid 157386:tid 157633] [client 213.35.127.232:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-wQAAAX8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:33.386151 2026] [security2:error] [pid 157386:tid 157607] [client 74.248.18.37:40534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/fitnessbase/dev.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-wwAAAWU"] [Tue Aug 18 13:06:33.392485 2026] [security2:error] [pid 157386:tid 157622] [client 20.206.73.37:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/file61.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-xAAAAXQ"] [Tue Aug 18 13:06:33.398819 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:1632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-xQAAAUk"] [Tue Aug 18 13:06:33.411223 2026] [security2:error] [pid 157386:tid 157639] [client 40.74.65.169:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/domvf.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-xgAAAYU"] [Tue Aug 18 13:06:33.427075 2026] [security2:error] [pid 157386:tid 157531] [client 168.62.48.100:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-yAAAARk"] [Tue Aug 18 13:06:33.445770 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/conf.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-yQAAAWE"] [Tue Aug 18 13:06:33.522436 2026] [security2:error] [pid 157386:tid 157468] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDCU1jzAhYHVVT1Wf-zgABK1E"] [Tue Aug 18 13:06:33.522507 2026] [security2:error] [pid 157386:tid 157469] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDCU1jzAhYHVVT1Wf-zAABK1I"] [Tue Aug 18 13:06:33.548456 2026] [security2:error] [pid 157386:tid 157458] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/item.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-0wABY0c"] [Tue Aug 18 13:06:33.561205 2026] [security2:error] [pid 157386:tid 157551] [client 20.171.51.14:47109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/creds.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-1QAAAS0"] [Tue Aug 18 13:06:33.691434 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-3gAAAVs"] [Tue Aug 18 13:06:33.695566 2026] [security2:error] [pid 157386:tid 157473] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/id_rsa"] [unique_id "aoSDCU1jzAhYHVVT1Wf-3wABKlY"] [Tue Aug 18 13:06:33.724041 2026] [security2:error] [pid 157386:tid 157432] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/sid3.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-4gABUS0"] [Tue Aug 18 13:06:33.734256 2026] [security2:error] [pid 157386:tid 157620] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-4wAAAXI"] [Tue Aug 18 13:06:33.794909 2026] [security2:error] [pid 157386:tid 157544] [client 158.158.74.177:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-5QAAASY"] [Tue Aug 18 13:06:33.851504 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:1627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/az.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-5wAAAYc"] [Tue Aug 18 13:06:33.855620 2026] [security2:error] [pid 157386:tid 157558] [client 168.62.48.100:18058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-6AAAATQ"] [Tue Aug 18 13:06:33.871318 2026] [security2:error] [pid 157386:tid 157588] [client 20.151.109.219:59765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/bala.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-6gAAAVI"] [Tue Aug 18 13:06:33.878063 2026] [security2:error] [pid 157386:tid 157622] [client 68.155.156.252:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/sh.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-6wAAAXQ"] [Tue Aug 18 13:06:33.894290 2026] [security2:error] [pid 157386:tid 157552] [client 52.173.121.69:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-7AAAAS4"] [Tue Aug 18 13:06:33.897135 2026] [security2:error] [pid 157386:tid 157453] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/size.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-7QABcEI"] [Tue Aug 18 13:06:33.977286 2026] [security2:error] [pid 157386:tid 157536] [client 20.250.13.23:23709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/phpMailer.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-7wAAAR4"] [Tue Aug 18 13:06:34.001106 2026] [security2:error] [pid 157386:tid 157639] [client 20.251.48.93:61595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/images.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf-8AAAAYU"] [Tue Aug 18 13:06:34.003001 2026] [security2:error] [pid 157386:tid 157564] [client 20.1.169.243:5043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-content/packed.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf-8QAAATo"] [Tue Aug 18 13:06:34.080858 2026] [security2:error] [pid 157386:tid 157447] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/tgrs.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf-8gABWTw"] [Tue Aug 18 13:06:34.084888 2026] [security2:error] [pid 157386:tid 157619] [client 20.151.109.219:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xynz1.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf-8wAAAXE"] [Tue Aug 18 13:06:34.117136 2026] [authz_core:error] [pid 157386:tid 157398] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:34.117579 2026] [authz_core:error] [pid 157386:tid 157398] [remote 216.73.216.206:20343] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:34.121203 2026] [security2:error] [pid 157386:tid 157534] [client 45.131.195.59:20417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "formeskin.com.br"] [uri "/wp-login.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-7gAAARw"] [Tue Aug 18 13:06:34.127819 2026] [security2:error] [pid 157386:tid 157448] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/privatekey.key"] [unique_id "aoSDCk1jzAhYHVVT1Wf--gABXD0"] [Tue Aug 18 13:06:34.127823 2026] [security2:error] [pid 157386:tid 157427] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/id_dsa"] [unique_id "aoSDCk1jzAhYHVVT1Wf-9wABXCg"] [Tue Aug 18 13:06:34.127827 2026] [security2:error] [pid 157386:tid 157446] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/key.pem"] [unique_id "aoSDCk1jzAhYHVVT1Wf-9gABXDs"] [Tue Aug 18 13:06:34.143632 2026] [security2:error] [pid 157386:tid 157577] [client 40.74.65.169:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/fpwch.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf-_gAAAUc"] [Tue Aug 18 13:06:34.250900 2026] [security2:error] [pid 157386:tid 157414] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/simple.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_BAABRhs"] [Tue Aug 18 13:06:34.273851 2026] [security2:error] [pid 157386:tid 157574] [client 20.116.17.175:20416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_BQAAAUQ"] [Tue Aug 18 13:06:34.319355 2026] [security2:error] [pid 157386:tid 157549] [client 74.249.206.207:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/gi.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_CgAAASs"] [Tue Aug 18 13:06:34.328235 2026] [security2:error] [pid 157386:tid 157630] [client 168.62.48.100:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_CwAAAXw"] [Tue Aug 18 13:06:34.350277 2026] [security2:error] [pid 157386:tid 157635] [client 68.221.73.131:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/als.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_DAAAAYE"] [Tue Aug 18 13:06:34.354306 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.36.136:65294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/qfvqu.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_DQAAAVs"] [Tue Aug 18 13:06:34.407259 2026] [security2:error] [pid 157386:tid 157517] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_EAAAAQs"] [Tue Aug 18 13:06:34.414211 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.100.201:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/zxz.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_EQAAAUs"] [Tue Aug 18 13:06:34.493297 2026] [security2:error] [pid 157386:tid 157455] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/berax.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_FwABF0Q"] [Tue Aug 18 13:06:34.562475 2026] [security2:error] [pid 157386:tid 157556] [client 20.79.204.6:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/buy.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_GgAAATI"] [Tue Aug 18 13:06:34.569605 2026] [security2:error] [pid 157386:tid 157580] [client 20.251.48.93:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/alls.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_GwAAAUo"] [Tue Aug 18 13:06:34.586817 2026] [security2:error] [pid 157386:tid 157584] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_HAAAAU4"] [Tue Aug 18 13:06:34.603364 2026] [security2:error] [pid 157386:tid 157525] [client 5.31.227.224:1447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_HQAAARM"] [Tue Aug 18 13:06:34.608077 2026] [security2:error] [pid 157386:tid 157525] [client 5.31.227.224:1447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_HQAAARM"] [Tue Aug 18 13:06:34.611102 2026] [security2:error] [pid 157386:tid 157613] [client 173.239.254.5:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atriempresarial.com.br"] [uri "/wp-login.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-1wAAAWs"] [Tue Aug 18 13:06:34.685136 2026] [security2:error] [pid 157386:tid 157633] [client 74.249.206.207:45051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/video.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_HgAAAX8"] [Tue Aug 18 13:06:34.687992 2026] [security2:error] [pid 157386:tid 157435] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/fi2.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_HwABUjA"] [Tue Aug 18 13:06:34.695617 2026] [security2:error] [pid 157386:tid 157624] [client 20.118.133.132:7794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/bengi.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_JAAAAXY"] [Tue Aug 18 13:06:34.711199 2026] [security2:error] [pid 157386:tid 157507] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/ws83.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_JQABcHg"] [Tue Aug 18 13:06:34.716346 2026] [security2:error] [pid 157386:tid 157536] [client 20.116.17.175:45288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/z43agz.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_JwAAAR4"] [Tue Aug 18 13:06:34.758617 2026] [security2:error] [pid 157386:tid 157642] [client 20.206.73.37:15910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/bengi.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_KQAAAYg"] [Tue Aug 18 13:06:34.806707 2026] [security2:error] [pid 157386:tid 157531] [client 20.171.51.14:7914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ho.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_KwAAARk"] [Tue Aug 18 13:06:34.815226 2026] [security2:error] [pid 157386:tid 157538] [client 168.62.48.100:18142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_LAAAASA"] [Tue Aug 18 13:06:34.833168 2026] [security2:error] [pid 157386:tid 157557] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/inso.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_LQAAATM"] [Tue Aug 18 13:06:34.876811 2026] [security2:error] [pid 157386:tid 157387] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/feeds.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_LwABcQA"] [Tue Aug 18 13:06:34.895977 2026] [security2:error] [pid 157386:tid 157522] [client 40.74.65.169:4923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/adminner.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_MwAAARA"] [Tue Aug 18 13:06:34.904734 2026] [security2:error] [pid 157386:tid 157542] [client 20.151.109.219:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lq.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_NAAAASQ"] [Tue Aug 18 13:06:34.920047 2026] [security2:error] [pid 157386:tid 157605] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/o.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_NQAAAWM"] [Tue Aug 18 13:06:34.926015 2026] [security2:error] [pid 157386:tid 157615] [client 20.226.36.136:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/oivcl.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_NgAAAW0"] [Tue Aug 18 13:06:34.929752 2026] [security2:error] [pid 157386:tid 157430] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/style.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_NwABLSs"] [Tue Aug 18 13:06:34.959478 2026] [security2:error] [pid 157386:tid 157574] [client 40.74.65.169:55252] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.marthaimenes.com"] [uri "/wp-content/uploads/"] [unique_id "aoSDCk1jzAhYHVVT1Wf_OAAAAUQ"] [Tue Aug 18 13:06:34.966132 2026] [security2:error] [pid 157386:tid 157589] [client 20.1.169.243:5000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_OQAAAVM"] [Tue Aug 18 13:06:34.973197 2026] [security2:error] [pid 157386:tid 157513] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDCk1jzAhYHVVT1Wf_OgABJ34"] [Tue Aug 18 13:06:34.991368 2026] [security2:error] [pid 157386:tid 157393] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDCk1jzAhYHVVT1Wf_PwABJwY"] [Tue Aug 18 13:06:35.015122 2026] [security2:error] [pid 157386:tid 157638] [client 68.155.154.236:14238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_QgAAAYQ"] [Tue Aug 18 13:06:35.041381 2026] [security2:error] [pid 157386:tid 157625] [client 195.2.67.184:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petstopclinicaveterinaria.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-mAAAAXc"], referer: https://petstopclinicaveterinaria.com.br/ [Tue Aug 18 13:06:35.092317 2026] [security2:error] [pid 157386:tid 157462] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/wp-the.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_RgABc0s"] [Tue Aug 18 13:06:35.116680 2026] [security2:error] [pid 157386:tid 157529] [client 20.226.36.136:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/zugvi.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_SAAAARc"] [Tue Aug 18 13:06:35.194436 2026] [security2:error] [pid 157386:tid 157553] [client 37.40.227.74:56736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_TwAAAS8"] [Tue Aug 18 13:06:35.194576 2026] [security2:error] [pid 157386:tid 157553] [client 37.40.227.74:56736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_TwAAAS8"] [Tue Aug 18 13:06:35.216033 2026] [security2:error] [pid 157386:tid 157540] [client 74.248.18.37:32502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/libs.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_UQAAASI"] [Tue Aug 18 13:06:35.242297 2026] [security2:error] [pid 157386:tid 157558] [client 20.1.169.243:15984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/about.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_UgAAATQ"] [Tue Aug 18 13:06:35.252669 2026] [security2:error] [pid 157386:tid 157510] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/plugin.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_UwABZXs"] [Tue Aug 18 13:06:35.278262 2026] [security2:error] [pid 157386:tid 157566] [client 193.19.109.78:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.109.19.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atriempresarial.com.br"] [uri "/wp-login.php"] [unique_id "aoSDCk1jzAhYHVVT1Wf_AwAAATw"] [Tue Aug 18 13:06:35.281558 2026] [security2:error] [pid 157386:tid 157543] [client 158.158.74.177:20526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/cjfuns.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_VQAAASU"] [Tue Aug 18 13:06:35.351633 2026] [security2:error] [pid 157386:tid 157557] [client 20.251.48.93:3780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/coffexium.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_XQAAATM"] [Tue Aug 18 13:06:35.396428 2026] [security2:error] [pid 157386:tid 157619] [client 20.226.36.136:62188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wsrer.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_XwAAAXE"] [Tue Aug 18 13:06:35.397975 2026] [security2:error] [pid 157386:tid 157542] [client 20.116.17.175:58215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/kj.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_YAAAASQ"] [Tue Aug 18 13:06:35.419525 2026] [security2:error] [pid 157386:tid 157489] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/readme.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_YQABLWY"] [Tue Aug 18 13:06:35.430586 2026] [security2:error] [pid 157386:tid 157623] [client 68.155.154.236:14171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_YwAAAXU"] [Tue Aug 18 13:06:35.440042 2026] [security2:error] [pid 157386:tid 157606] [client 20.127.136.245:28098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_ZAAAAWQ"] [Tue Aug 18 13:06:35.460489 2026] [security2:error] [pid 157386:tid 157499] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/curl.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_ZQABU3A"] [Tue Aug 18 13:06:35.465868 2026] [security2:error] [pid 157386:tid 157630] [client 20.171.51.14:7888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/97.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_ZgAAAXw"] [Tue Aug 18 13:06:35.473855 2026] [security2:error] [pid 157386:tid 157620] [client 213.35.127.232:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_ZwAAAXI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:35.541253 2026] [security2:error] [pid 157386:tid 157485] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_awABC2I"] [Tue Aug 18 13:06:35.541450 2026] [security2:error] [pid 157386:tid 157517] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_awABC2I"] [Tue Aug 18 13:06:35.548010 2026] [security2:error] [pid 157386:tid 157581] [client 68.155.156.252:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/button.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_bAAAAUs"] [Tue Aug 18 13:06:35.558961 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vo.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_bgAAAUk"] [Tue Aug 18 13:06:35.575143 2026] [security2:error] [pid 157386:tid 157529] [client 20.226.36.136:61469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/ucpfr.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_cQAAARc"] [Tue Aug 18 13:06:35.579046 2026] [security2:error] [pid 157386:tid 157492] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/chosen.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_cgABXGk"] [Tue Aug 18 13:06:35.580193 2026] [security2:error] [pid 157386:tid 157587] [client 20.206.73.37:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/yj09.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_cwAAAVE"] [Tue Aug 18 13:06:35.598671 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/lmfi2.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_dQAAAXk"] [Tue Aug 18 13:06:35.610825 2026] [security2:error] [pid 157386:tid 157556] [client 40.74.65.169:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/abcd.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_dgAAATI"] [Tue Aug 18 13:06:35.660541 2026] [security2:error] [pid 157386:tid 157553] [client 20.151.109.219:28766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/you.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_eAAAAS8"] [Tue Aug 18 13:06:35.696667 2026] [security2:error] [pid 157386:tid 157480] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "brasipaodequeijo.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSDC01jzAhYHVVT1Wf_egABNF0"] [Tue Aug 18 13:06:35.696670 2026] [security2:error] [pid 157386:tid 157390] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "brasipaodequeijo.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSDC01jzAhYHVVT1Wf_fAABNAM"] [Tue Aug 18 13:06:35.697028 2026] [security2:error] [pid 157386:tid 157535] [client 20.250.13.23:18556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_eQAAAR0"] [Tue Aug 18 13:06:35.707591 2026] [security2:error] [pid 157386:tid 157607] [client 40.74.65.169:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/abcd.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_fgAAAWU"] [Tue Aug 18 13:06:35.730894 2026] [security2:error] [pid 157386:tid 157591] [client 196.12.128.158:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_fwAAAVU"] [Tue Aug 18 13:06:35.731003 2026] [security2:error] [pid 157386:tid 157591] [client 196.12.128.158:60786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_fwAAAVU"] [Tue Aug 18 13:06:35.771855 2026] [security2:error] [pid 157386:tid 157622] [client 20.116.17.175:20429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/txets.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_gQAAAXQ"] [Tue Aug 18 13:06:35.784799 2026] [security2:error] [pid 157386:tid 157395] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/system.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_ggABGAg"] [Tue Aug 18 13:06:35.806479 2026] [security2:error] [pid 157386:tid 157635] [client 20.79.204.6:11675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/cong.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_gwAAAYE"] [Tue Aug 18 13:06:35.822478 2026] [security2:error] [pid 157386:tid 157578] [client 52.173.121.69:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_hAAAAUg"] [Tue Aug 18 13:06:35.840111 2026] [security2:error] [pid 157386:tid 157548] [client 20.1.169.243:15961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/post.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_hQAAASo"] [Tue Aug 18 13:06:35.854118 2026] [security2:error] [pid 157386:tid 157534] [client 20.226.36.136:65341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/yxijx.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_hgAAARw"] [Tue Aug 18 13:06:35.896816 2026] [security2:error] [pid 157386:tid 157412] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDC01jzAhYHVVT1Wf_iQABcRk"] [Tue Aug 18 13:06:35.903623 2026] [security2:error] [pid 157386:tid 157542] [client 68.155.154.236:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_igAAASQ"] [Tue Aug 18 13:06:35.943762 2026] [security2:error] [pid 157386:tid 157615] [client 20.104.100.201:53849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/memberfuns.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_iwAAAW0"] [Tue Aug 18 13:06:35.966825 2026] [security2:error] [pid 157386:tid 157633] [client 158.158.74.177:9889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_jQAAAX8"] [Tue Aug 18 13:06:35.977780 2026] [security2:error] [pid 157386:tid 157405] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/config/.env.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_jwABfBI"] [Tue Aug 18 13:06:35.978362 2026] [security2:error] [pid 157386:tid 157465] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/laravel/.env"] [unique_id "aoSDC01jzAhYHVVT1Wf_kAABfE4"] [Tue Aug 18 13:06:36.014284 2026] [security2:error] [pid 157386:tid 157518] [client 74.7.230.2:59658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ctamcursos.com.br"] [uri "/index.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-rwABDB8"] [Tue Aug 18 13:06:36.022226 2026] [security2:error] [pid 157386:tid 157458] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/wp-load.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_lAABhEc"] [Tue Aug 18 13:06:36.027488 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.36.136:62182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/zwlsv.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_lQAAAVs"] [Tue Aug 18 13:06:36.046983 2026] [security2:error] [pid 157386:tid 157454] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/Njima.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_lgABC0M"] [Tue Aug 18 13:06:36.050666 2026] [security2:error] [pid 157386:tid 157621] [client 20.151.109.219:46446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fd.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_lwAAAXM"] [Tue Aug 18 13:06:36.082411 2026] [security2:error] [pid 157386:tid 157581] [client 20.206.73.37:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/copypaths.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_mAAAAUs"] [Tue Aug 18 13:06:36.098996 2026] [security2:error] [pid 157386:tid 157516] [client 20.226.36.136:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_mQAAAQo"] [Tue Aug 18 13:06:36.099234 2026] [security2:error] [pid 157386:tid 157603] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/yj09.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_mgAAAWE"] [Tue Aug 18 13:06:36.118559 2026] [security2:error] [pid 157386:tid 157576] [client 20.171.51.14:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/rh.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_nAAAAUY"] [Tue Aug 18 13:06:36.185306 2026] [security2:error] [pid 157386:tid 157473] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/config.php.bak"] [unique_id "aoSDDE1jzAhYHVVT1Wf_nwABMlY"] [Tue Aug 18 13:06:36.187257 2026] [security2:error] [pid 157386:tid 157399] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/core/.env"] [unique_id "aoSDDE1jzAhYHVVT1Wf_oAABMgw"] [Tue Aug 18 13:06:36.226167 2026] [security2:error] [pid 157386:tid 157592] [client 5.161.61.238:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracao.com.br"] [uri "/index.php"] [unique_id "aoSDCU1jzAhYHVVT1Wf-1gABVlQ"], referer: https://tecpolorefrigeracao.com.br/ [Tue Aug 18 13:06:36.271938 2026] [security2:error] [pid 157386:tid 157408] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasipaodequeijo.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSDDE1jzAhYHVVT1Wf_pAABQhU"] [Tue Aug 18 13:06:36.273276 2026] [security2:error] [pid 157386:tid 157503] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/.env.swp"] [unique_id "aoSDDE1jzAhYHVVT1Wf_owABQnQ"] [Tue Aug 18 13:06:36.280211 2026] [security2:error] [pid 157386:tid 157493] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/colors.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_pgABUmo"] [Tue Aug 18 13:06:36.286872 2026] [security2:error] [pid 157386:tid 157566] [client 20.118.133.132:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/file2.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_pwAAATw"] [Tue Aug 18 13:06:36.291735 2026] [security2:error] [pid 157386:tid 157598] [client 20.1.169.243:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/flower.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_qAAAAVw"] [Tue Aug 18 13:06:36.312404 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:36.312655 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:36.313158 2026] [security2:error] [pid 157386:tid 157622] [client 222.124.191.185:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_qwAAAXQ"] [Tue Aug 18 13:06:36.313237 2026] [security2:error] [pid 157386:tid 157622] [client 222.124.191.185:54766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_qwAAAXQ"] [Tue Aug 18 13:06:36.346363 2026] [security2:error] [pid 157386:tid 157569] [client 68.155.156.252:22129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/wlc.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_rQAAAT8"] [Tue Aug 18 13:06:36.353606 2026] [security2:error] [pid 157386:tid 157635] [client 68.155.154.236:14146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/update/wpupex.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_rgAAAYE"] [Tue Aug 18 13:06:36.359428 2026] [security2:error] [pid 157386:tid 157504] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/public/.env"] [unique_id "aoSDDE1jzAhYHVVT1Wf_rwABSHU"] [Tue Aug 18 13:06:36.359726 2026] [security2:error] [pid 157386:tid 157642] [client 40.74.65.169:4809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/simple.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_sQAAAYg"] [Tue Aug 18 13:06:36.366770 2026] [security2:error] [pid 157386:tid 157587] [client 20.250.13.23:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/al.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_sgAAAVE"] [Tue Aug 18 13:06:36.417988 2026] [security2:error] [pid 157386:tid 157601] [client 158.23.17.4:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fd.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_swAAAV8"] [Tue Aug 18 13:06:36.425251 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marthaimenes.com"] [uri "/wpxml.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_tAAAATM"] [Tue Aug 18 13:06:36.440349 2026] [security2:error] [pid 157386:tid 157582] [client 20.116.17.175:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_tQAAAUw"] [Tue Aug 18 13:06:36.443772 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/info2.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_tgAAATc"] [Tue Aug 18 13:06:36.452796 2026] [security2:error] [pid 157386:tid 157542] [client 168.62.48.100:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_ugAAASQ"] [Tue Aug 18 13:06:36.478040 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.36.136:48868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/jrpga.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_vAAAAWM"] [Tue Aug 18 13:06:36.507698 2026] [security2:error] [pid 157386:tid 157543] [client 74.249.206.207:64562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/hel.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_vQAAASU"] [Tue Aug 18 13:06:36.518702 2026] [security2:error] [pid 157386:tid 157577] [client 20.127.136.245:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/info.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_vgAAAUc"] [Tue Aug 18 13:06:36.560207 2026] [security2:error] [pid 157386:tid 157427] [remote 52.139.47.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dtbbrasil.com.br"] [uri "/files/8.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_vwABNSg"] [Tue Aug 18 13:06:36.560244 2026] [security2:error] [pid 157386:tid 157606] [client 68.221.73.131:7358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/nox.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_wAAAAWQ"] [Tue Aug 18 13:06:36.609133 2026] [security2:error] [pid 157386:tid 157552] [client 223.185.37.47:25784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_xQAAAS4"] [Tue Aug 18 13:06:36.609245 2026] [security2:error] [pid 157386:tid 157552] [client 223.185.37.47:25784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_xQAAAS4"] [Tue Aug 18 13:06:36.682087 2026] [security2:error] [pid 157386:tid 157631] [client 20.206.73.37:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/file2.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_xwAAAX0"] [Tue Aug 18 13:06:36.725246 2026] [security2:error] [pid 157386:tid 157613] [client 20.79.204.6:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_yAAAAWs"] [Tue Aug 18 13:06:36.736170 2026] [security2:error] [pid 157386:tid 157579] [client 20.104.100.201:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/aa.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_yQAAAUk"] [Tue Aug 18 13:06:36.748866 2026] [security2:error] [pid 157386:tid 157629] [client 158.158.74.177:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_ygAAAXs"] [Tue Aug 18 13:06:36.801514 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sx.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_0AAAAVk"] [Tue Aug 18 13:06:36.835364 2026] [security2:error] [pid 157386:tid 157593] [client 20.250.13.23:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_0QAAAVc"] [Tue Aug 18 13:06:36.851783 2026] [security2:error] [pid 157386:tid 157612] [client 52.173.121.69:52915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_0gAAAWo"] [Tue Aug 18 13:06:36.867782 2026] [security2:error] [pid 157386:tid 157616] [client 20.251.48.93:53397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/red.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_0wAAAW4"] [Tue Aug 18 13:06:36.891620 2026] [security2:error] [pid 157386:tid 157420] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_1AABViE"] [Tue Aug 18 13:06:36.894780 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:20682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ez.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_1QAAASE"] [Tue Aug 18 13:06:36.940606 2026] [security2:error] [pid 157386:tid 157571] [client 74.248.18.37:6625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_1wAAAUE"] [Tue Aug 18 13:06:36.985482 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.49.167:48538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_2gAAARg"] [Tue Aug 18 13:06:36.998543 2026] [security2:error] [pid 157386:tid 157569] [client 68.155.154.236:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-admin/install.php"] [unique_id "aoSDDE1jzAhYHVVT1Wf_2wAAAT8"] [Tue Aug 18 13:06:37.027192 2026] [security2:error] [pid 157386:tid 157642] [client 20.171.51.14:13428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/yg.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_3AAAAYg"] [Tue Aug 18 13:06:37.034672 2026] [security2:error] [pid 157386:tid 157535] [client 49.37.150.8:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_3QAAAR0"] [Tue Aug 18 13:06:37.034800 2026] [security2:error] [pid 157386:tid 157535] [client 49.37.150.8:50169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_3QAAAR0"] [Tue Aug 18 13:06:37.037290 2026] [security2:error] [pid 157386:tid 157541] [client 86.120.159.145:21709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_3gAAASM"] [Tue Aug 18 13:06:37.037381 2026] [security2:error] [pid 157386:tid 157541] [client 86.120.159.145:21709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_3gAAASM"] [Tue Aug 18 13:06:37.080947 2026] [security2:error] [pid 157386:tid 157498] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/radio.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_4QABMG8"] [Tue Aug 18 13:06:37.086045 2026] [security2:error] [pid 157386:tid 157482] [remote 34.73.137.196:38704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brasipaodequeijo.com.br"] [uri "/web/.env"] [unique_id "aoSDDU1jzAhYHVVT1Wf_4gABM18"] [Tue Aug 18 13:06:37.092223 2026] [security2:error] [pid 157386:tid 157570] [client 20.1.169.243:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_6QAAAUA"] [Tue Aug 18 13:06:37.093153 2026] [security2:error] [pid 157386:tid 157556] [client 20.1.169.243:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/black.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_6gAAATI"] [Tue Aug 18 13:06:37.113559 2026] [security2:error] [pid 157386:tid 157582] [client 40.74.65.169:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_6wAAAUw"] [Tue Aug 18 13:06:37.147019 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.36.136:53507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/museu/yhweq.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_7AAAAVA"] [Tue Aug 18 13:06:37.165812 2026] [security2:error] [pid 157386:tid 157543] [client 20.38.3.247:38551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/admin.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_7QAAASU"] [Tue Aug 18 13:06:37.175260 2026] [security2:error] [pid 157386:tid 157403] [remote 85.204.70.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1td.com.br"] [uri "/wp-login.php"] [unique_id "aoSDC01jzAhYHVVT1Wf_SQABVBA"] [Tue Aug 18 13:06:37.265296 2026] [security2:error] [pid 157386:tid 157470] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_8QABLlM"] [Tue Aug 18 13:06:37.310710 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/bb.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_9AAAARk"] [Tue Aug 18 13:06:37.352590 2026] [security2:error] [pid 157386:tid 157621] [client 20.206.73.37:26557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/bless6.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_9QAAAXM"] [Tue Aug 18 13:06:37.369108 2026] [security2:error] [pid 157386:tid 157581] [client 20.151.109.219:24858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/222.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_9gAAAUs"] [Tue Aug 18 13:06:37.418441 2026] [security2:error] [pid 157386:tid 157620] [client 20.25.139.174:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/fone1.php"] [unique_id "aoSDDU1jzAhYHVVT1Wf_-QAAAXI"] [Tue Aug 18 13:06:37.480117 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:20436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/img.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAAQAAAXk"] [Tue Aug 18 13:06:37.482524 2026] [security2:error] [pid 157386:tid 157545] [client 20.215.241.237:28855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/82.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAAgAAASc"] [Tue Aug 18 13:06:37.492259 2026] [security2:error] [pid 157386:tid 157589] [client 158.158.74.177:24643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/import.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAAwAAAVM"] [Tue Aug 18 13:06:37.494002 2026] [security2:error] [pid 157386:tid 157612] [client 52.173.121.69:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDDU1jzAhYHVVT1WcABAAAAWo"] [Tue Aug 18 13:06:37.536967 2026] [security2:error] [pid 157386:tid 157616] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/aa.php"] [unique_id "aoSDDU1jzAhYHVVT1WcABgAAAW4"] [Tue Aug 18 13:06:37.561808 2026] [security2:error] [pid 157386:tid 157539] [client 20.116.17.175:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/3.php"] [unique_id "aoSDDU1jzAhYHVVT1WcACAAAASE"] [Tue Aug 18 13:06:37.619509 2026] [security2:error] [pid 157386:tid 157622] [client 68.155.156.252:53177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/fi.php"] [unique_id "aoSDDU1jzAhYHVVT1WcACwAAAXQ"] [Tue Aug 18 13:06:37.624071 2026] [security2:error] [pid 157386:tid 157558] [client 68.221.73.131:29403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file59.php"] [unique_id "aoSDDU1jzAhYHVVT1WcADAAAATQ"] [Tue Aug 18 13:06:37.630651 2026] [security2:error] [pid 157386:tid 157532] [client 38.246.32.104:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.32.246.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1WcACgAAARo"] [Tue Aug 18 13:06:37.631067 2026] [security2:error] [pid 157386:tid 157624] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDDU1jzAhYHVVT1WcADQAAAXY"] [Tue Aug 18 13:06:37.636152 2026] [security2:error] [pid 157386:tid 157639] [client 20.127.136.245:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/a.php"] [unique_id "aoSDDU1jzAhYHVVT1WcADgAAAYU"] [Tue Aug 18 13:06:37.752493 2026] [security2:error] [pid 157386:tid 157636] [client 20.151.109.219:21654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/routes.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAEQAAAYI"] [Tue Aug 18 13:06:37.757212 2026] [security2:error] [pid 157386:tid 157524] [client 20.1.169.243:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAEgAAARI"] [Tue Aug 18 13:06:37.794597 2026] [security2:error] [pid 157386:tid 157544] [client 20.226.36.136:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/nwwha.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAEwAAASY"] [Tue Aug 18 13:06:37.862063 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:21941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wu.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAFgAAAU4"] [Tue Aug 18 13:06:37.865100 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/xiugai.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAFwAAATM"] [Tue Aug 18 13:06:37.866226 2026] [security2:error] [pid 157386:tid 157532] [client 38.246.32.104:62523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSDDU1jzAhYHVVT1WcACgAAARo"] [Tue Aug 18 13:06:37.866923 2026] [security2:error] [pid 157386:tid 157486] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAGAABf2M"] [Tue Aug 18 13:06:37.983894 2026] [security2:error] [pid 157386:tid 157625] [client 74.249.206.207:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/grok.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAGwAAAXc"] [Tue Aug 18 13:06:37.984461 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:20473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDDU1jzAhYHVVT1WcAHAAAAX4"] [Tue Aug 18 13:06:38.060596 2026] [security2:error] [pid 157386:tid 157605] [client 20.79.204.6:11684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/db.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAIAAAAWM"] [Tue Aug 18 13:06:38.137013 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:49296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nu.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAIgAAASc"] [Tue Aug 18 13:06:38.151290 2026] [security2:error] [pid 157386:tid 157612] [client 20.151.109.219:24843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/php5.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAJAAAAWo"] [Tue Aug 18 13:06:38.161955 2026] [security2:error] [pid 157386:tid 157547] [client 68.155.154.236:14181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAJQAAASk"] [Tue Aug 18 13:06:38.190997 2026] [security2:error] [pid 157386:tid 157539] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAKAAAASE"] [Tue Aug 18 13:06:38.201556 2026] [security2:error] [pid 157386:tid 157525] [client 20.206.73.37:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/gm.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAKgAAARM"] [Tue Aug 18 13:06:38.222238 2026] [security2:error] [pid 157386:tid 157642] [client 74.248.18.37:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins//about.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAKwAAAYg"] [Tue Aug 18 13:06:38.226394 2026] [security2:error] [pid 157386:tid 157563] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/img.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAMgAAATk"] [Tue Aug 18 13:06:38.293251 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.122:42688] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:38.293600 2026] [authz_core:error] [pid 157386:tid 157396] [remote 57.141.22.122:42688] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:38.364657 2026] [security2:error] [pid 157386:tid 157541] [client 20.38.3.247:59975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.espacosvilaolimpia.com.br"] [uri "/ajax.php"] [unique_id "aoSDDk1jzAhYHVVT1WcANwAAASM"] [Tue Aug 18 13:06:38.372099 2026] [security2:error] [pid 157386:tid 157635] [client 20.1.169.243:15967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAOAAAAYE"] [Tue Aug 18 13:06:38.388582 2026] [security2:error] [pid 157386:tid 157585] [client 20.250.13.23:23738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAOgAAAU8"] [Tue Aug 18 13:06:38.399271 2026] [security2:error] [pid 157386:tid 157561] [client 52.173.121.69:10680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAOwAAATc"] [Tue Aug 18 13:06:38.415134 2026] [security2:error] [pid 157386:tid 157636] [client 20.226.36.136:38505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAPAAAAYI"] [Tue Aug 18 13:06:38.540128 2026] [security2:error] [pid 157386:tid 157534] [client 20.1.169.243:5822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/bs1.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAPgAAARw"] [Tue Aug 18 13:06:38.552351 2026] [security2:error] [pid 157386:tid 157615] [client 168.62.48.100:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAPwAAAW0"] [Tue Aug 18 13:06:38.590423 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/wp-load.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAQAAAATM"] [Tue Aug 18 13:06:38.618898 2026] [security2:error] [pid 157386:tid 157413] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/u.php"] [unique_id "aoSDDk1jzAhYHVVT1WcARwABLho"] [Tue Aug 18 13:06:38.699126 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:22552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/log.php"] [unique_id "aoSDDk1jzAhYHVVT1WcASwAAAX4"] [Tue Aug 18 13:06:38.729811 2026] [security2:error] [pid 157386:tid 157638] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/scxy.php"] [unique_id "aoSDDk1jzAhYHVVT1WcATQAAAYQ"] [Tue Aug 18 13:06:38.736965 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:53689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDDk1jzAhYHVVT1WcATgAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:38.837665 2026] [security2:error] [pid 157386:tid 157620] [client 158.23.17.4:47649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/info2.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAUQAAAXI"] [Tue Aug 18 13:06:38.915946 2026] [security2:error] [pid 157386:tid 157589] [client 20.104.100.201:17387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/echkm.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAUgAAAVM"] [Tue Aug 18 13:06:38.916687 2026] [security2:error] [pid 157386:tid 157600] [client 102.213.179.104:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAUwAAAV4"] [Tue Aug 18 13:06:38.916798 2026] [security2:error] [pid 157386:tid 157600] [client 102.213.179.104:52043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAUwAAAV4"] [Tue Aug 18 13:06:38.939906 2026] [security2:error] [pid 157386:tid 157592] [client 68.155.156.252:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/chris.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAVQAAAVY"] [Tue Aug 18 13:06:38.944699 2026] [security2:error] [pid 157386:tid 157538] [client 38.246.32.104:62727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.32.246.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAVgAAASA"] [Tue Aug 18 13:06:38.976089 2026] [security2:error] [pid 157386:tid 157539] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/222.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAVwAAASE"] [Tue Aug 18 13:06:38.983629 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ko.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAWAAAARM"] [Tue Aug 18 13:06:39.027777 2026] [security2:error] [pid 157386:tid 157598] [client 20.79.204.6:11694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/dropdown.php"] [unique_id "aoSDD01jzAhYHVVT1WcAWgAAAVw"] [Tue Aug 18 13:06:39.040833 2026] [security2:error] [pid 157386:tid 157617] [client 158.158.74.177:9869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/cropper.php"] [unique_id "aoSDD01jzAhYHVVT1WcAWwAAAW8"] [Tue Aug 18 13:06:39.046229 2026] [security2:error] [pid 157386:tid 157520] [client 20.25.139.174:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ncx.php"] [unique_id "aoSDD01jzAhYHVVT1WcAXAAAAQ4"] [Tue Aug 18 13:06:39.204269 2026] [security2:error] [pid 157386:tid 157538] [client 38.246.32.104:62727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bioarquitetar.com"] [uri "/xmlrpc.php"] [unique_id "aoSDDk1jzAhYHVVT1WcAVgAAASA"] [Tue Aug 18 13:06:39.214549 2026] [security2:error] [pid 157386:tid 157611] [client 20.127.136.245:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/chosen.php"] [unique_id "aoSDD01jzAhYHVVT1WcAYwAAAWk"] [Tue Aug 18 13:06:39.225553 2026] [security2:error] [pid 157386:tid 157541] [client 20.118.133.132:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/gm.php"] [unique_id "aoSDD01jzAhYHVVT1WcAZAAAASM"] [Tue Aug 18 13:06:39.242929 2026] [security2:error] [pid 157386:tid 157603] [client 20.1.169.243:15980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/jp.php"] [unique_id "aoSDD01jzAhYHVVT1WcAZQAAAWE"] [Tue Aug 18 13:06:39.334931 2026] [security2:error] [pid 157386:tid 157524] [client 40.74.65.169:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/155.php"] [unique_id "aoSDD01jzAhYHVVT1WcAaAAAARI"] [Tue Aug 18 13:06:39.345783 2026] [security2:error] [pid 157386:tid 157554] [client 68.155.154.236:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDD01jzAhYHVVT1WcAaQAAATA"] [Tue Aug 18 13:06:39.380638 2026] [security2:error] [pid 157386:tid 157423] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/k.php"] [unique_id "aoSDD01jzAhYHVVT1WcAagABJiQ"] [Tue Aug 18 13:06:39.405659 2026] [security2:error] [pid 157386:tid 157586] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDD01jzAhYHVVT1WcAawAAAVA"] [Tue Aug 18 13:06:39.439282 2026] [security2:error] [pid 157386:tid 157522] [client 20.226.36.136:41572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDD01jzAhYHVVT1WcAbAAAARA"] [Tue Aug 18 13:06:39.536948 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:22580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ohct.php"] [unique_id "aoSDD01jzAhYHVVT1WcAcQAAAXE"] [Tue Aug 18 13:06:39.555022 2026] [security2:error] [pid 157386:tid 157567] [client 20.151.109.219:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/asus.php"] [unique_id "aoSDD01jzAhYHVVT1WcAcwAAAT0"] [Tue Aug 18 13:06:39.570637 2026] [authz_core:error] [pid 157386:tid 157480] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:39.570924 2026] [authz_core:error] [pid 157386:tid 157480] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:39.597821 2026] [security2:error] [pid 157386:tid 157535] [client 222.124.191.185:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSDD01jzAhYHVVT1WcAdgAAAR0"] [Tue Aug 18 13:06:39.597902 2026] [security2:error] [pid 157386:tid 157535] [client 222.124.191.185:57052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "aoSDD01jzAhYHVVT1WcAdgAAAR0"] [Tue Aug 18 13:06:39.597961 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:53217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/Black.php"] [unique_id "aoSDD01jzAhYHVVT1WcAdQAAAYA"] [Tue Aug 18 13:06:39.645401 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:17081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/de.php"] [unique_id "aoSDD01jzAhYHVVT1WcAdwAAAXU"] [Tue Aug 18 13:06:39.700113 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:20361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDD01jzAhYHVVT1WcAeAAAAUs"] [Tue Aug 18 13:06:39.856861 2026] [security2:error] [pid 157386:tid 157571] [client 149.34.210.141:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDD01jzAhYHVVT1WcAegAAAUE"] [Tue Aug 18 13:06:39.857587 2026] [security2:error] [pid 157386:tid 157618] [client 68.221.73.131:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/admin.php"] [unique_id "aoSDD01jzAhYHVVT1WcAewAAAXA"] [Tue Aug 18 13:06:39.862457 2026] [security2:error] [pid 157386:tid 157534] [client 20.25.139.174:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDD01jzAhYHVVT1WcAfAAAARw"] [Tue Aug 18 13:06:39.905329 2026] [security2:error] [pid 157386:tid 157595] [client 74.248.18.37:40539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/colors/coffee/autoload_classmap.php"] [unique_id "aoSDD01jzAhYHVVT1WcAfgAAAVk"] [Tue Aug 18 13:06:39.927529 2026] [security2:error] [pid 157386:tid 157593] [client 20.226.36.136:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDD01jzAhYHVVT1WcAgAAAAVc"] [Tue Aug 18 13:06:39.947169 2026] [security2:error] [pid 157386:tid 157539] [client 168.62.48.100:18128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDD01jzAhYHVVT1WcAgwAAASE"] [Tue Aug 18 13:06:40.004791 2026] [security2:error] [pid 157386:tid 157598] [client 68.155.156.252:22069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/doc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAhAAAAVw"] [Tue Aug 18 13:06:40.019580 2026] [security2:error] [pid 157386:tid 157526] [client 20.116.17.175:58188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/png.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAhwAAARQ"] [Tue Aug 18 13:06:40.036788 2026] [security2:error] [pid 157386:tid 157574] [client 158.23.17.4:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/sx.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAiQAAAUQ"] [Tue Aug 18 13:06:40.078369 2026] [security2:error] [pid 157386:tid 157576] [client 40.74.65.169:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/index.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAigAAAUY"] [Tue Aug 18 13:06:40.088858 2026] [security2:error] [pid 157386:tid 157635] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAiwAAAYE"] [Tue Aug 18 13:06:40.089467 2026] [security2:error] [pid 157386:tid 157613] [client 20.206.73.37:2879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/ws55.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAjAAAAWs"] [Tue Aug 18 13:06:40.119274 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:15983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAjQAAATk"] [Tue Aug 18 13:06:40.149999 2026] [security2:error] [pid 157386:tid 157571] [client 149.34.210.141:62403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDD01jzAhYHVVT1WcAegAAAUE"] [Tue Aug 18 13:06:40.203340 2026] [security2:error] [pid 157386:tid 157597] [client 168.62.48.100:18125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAjgAAAVs"] [Tue Aug 18 13:06:40.208377 2026] [security2:error] [pid 157386:tid 157521] [client 52.173.121.69:35097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAjwAAAQ8"] [Tue Aug 18 13:06:40.339457 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:58743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/album.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAkwAAAVE"] [Tue Aug 18 13:06:40.353013 2026] [security2:error] [pid 157386:tid 157552] [client 20.104.49.167:2664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/too.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAlgAAAS4"] [Tue Aug 18 13:06:40.398119 2026] [security2:error] [pid 157386:tid 157588] [client 168.62.48.100:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAlwAAAVI"] [Tue Aug 18 13:06:40.441438 2026] [security2:error] [pid 157386:tid 157517] [client 20.215.241.237:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/dex.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAmQAAAQs"] [Tue Aug 18 13:06:40.483728 2026] [security2:error] [pid 157386:tid 157543] [client 168.62.48.100:18065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAmwAAASU"] [Tue Aug 18 13:06:40.490257 2026] [security2:error] [pid 157386:tid 157542] [client 20.1.169.243:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAnQAAASQ"] [Tue Aug 18 13:06:40.519698 2026] [security2:error] [pid 157386:tid 157589] [client 20.1.169.243:5322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/colors/blue/about.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAnwAAAVM"] [Tue Aug 18 13:06:40.531227 2026] [security2:error] [pid 157386:tid 157590] [client 20.171.51.14:44891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/et.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAoAAAAVQ"] [Tue Aug 18 13:06:40.572411 2026] [security2:error] [pid 157386:tid 157594] [client 20.1.169.243:4500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/xda.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAogAAAVg"] [Tue Aug 18 13:06:40.579484 2026] [security2:error] [pid 157386:tid 157545] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/key.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAowAAASc"] [Tue Aug 18 13:06:40.588925 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcApAAAAXA"] [Tue Aug 18 13:06:40.611941 2026] [security2:error] [pid 157386:tid 157633] [client 51.15.217.215:40970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.217.15.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDEE1jzAhYHVVT1WcApQAAAX8"] [Tue Aug 18 13:06:40.626032 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDEE1jzAhYHVVT1WcApgAAAVw"] [Tue Aug 18 13:06:40.676133 2026] [security2:error] [pid 157386:tid 157540] [client 20.79.204.6:11705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/file.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAqAAAASI"] [Tue Aug 18 13:06:40.688922 2026] [security2:error] [pid 157386:tid 157562] [client 68.155.156.252:33715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/1337.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAqQAAATg"] [Tue Aug 18 13:06:40.689772 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.100.201:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/domvf.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAqgAAAUY"] [Tue Aug 18 13:06:40.695192 2026] [security2:error] [pid 157386:tid 157605] [client 158.158.74.177:20492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcArAAAAWM"] [Tue Aug 18 13:06:40.710801 2026] [security2:error] [pid 157386:tid 157538] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/blurbs.php"] [unique_id "aoSDEE1jzAhYHVVT1WcArQAAASA"] [Tue Aug 18 13:06:40.722281 2026] [security2:error] [pid 157386:tid 157635] [client 68.221.73.131:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/aa2.php"] [unique_id "aoSDEE1jzAhYHVVT1WcArwAAAYE"] [Tue Aug 18 13:06:40.757078 2026] [security2:error] [pid 157386:tid 157579] [client 157.20.138.62:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAsAAAAUk"] [Tue Aug 18 13:06:40.757194 2026] [security2:error] [pid 157386:tid 157579] [client 157.20.138.62:50254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAsAAAAUk"] [Tue Aug 18 13:06:40.764060 2026] [security2:error] [pid 157386:tid 157571] [client 20.104.49.167:26396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hotelvipempresas.com.br"] [uri "/g3.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAswAAAUE"] [Tue Aug 18 13:06:40.781804 2026] [security2:error] [pid 157386:tid 157569] [client 168.62.48.100:18165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAtQAAAT8"] [Tue Aug 18 13:06:40.781819 2026] [security2:error] [pid 157386:tid 157524] [client 40.74.65.169:4457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/aaa.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAtAAAARI"] [Tue Aug 18 13:06:40.785378 2026] [security2:error] [pid 157386:tid 157554] [client 20.206.73.37:15911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/m.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAtgAAATA"] [Tue Aug 18 13:06:40.812071 2026] [security2:error] [pid 157386:tid 157525] [client 20.127.136.245:28142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAuAAAARM"] [Tue Aug 18 13:06:40.834133 2026] [security2:error] [pid 157386:tid 157557] [client 222.124.191.185:57056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAuQAAATM"] [Tue Aug 18 13:06:40.834211 2026] [security2:error] [pid 157386:tid 157557] [client 222.124.191.185:57056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAuQAAATM"] [Tue Aug 18 13:06:40.840113 2026] [security2:error] [pid 157386:tid 157615] [client 74.248.130.103:53677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/coffexium.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAuwAAAW0"] [Tue Aug 18 13:06:40.852657 2026] [security2:error] [pid 157386:tid 157619] [client 20.206.73.37:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/special.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAvgAAAXE"] [Tue Aug 18 13:06:40.853468 2026] [security2:error] [pid 157386:tid 157532] [client 20.226.36.136:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAvwAAARo"] [Tue Aug 18 13:06:40.855572 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:15790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAwQAAATk"] [Tue Aug 18 13:06:40.869603 2026] [security2:error] [pid 157386:tid 157634] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/file.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAwwAAAYA"] [Tue Aug 18 13:06:40.873874 2026] [security2:error] [pid 157386:tid 157518] [client 5.161.117.52:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlypiscinas.com.br"] [uri "/index.php"] [unique_id "aoSDDk1jzAhYHVVT1WcASAABDFk"], referer: https://jlypiscinas.com.br/ [Tue Aug 18 13:06:40.885830 2026] [security2:error] [pid 157386:tid 157637] [client 213.35.127.232:54409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAxQAAAYM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:40.902414 2026] [security2:error] [pid 157386:tid 157560] [client 20.124.247.79:16719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAxwAAATY"] [Tue Aug 18 13:06:40.978438 2026] [security2:error] [pid 157386:tid 157620] [client 52.173.121.69:57766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDEE1jzAhYHVVT1WcAzAAAAXI"] [Tue Aug 18 13:06:41.001357 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/filesystems.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA0QAAASc"] [Tue Aug 18 13:06:41.006886 2026] [security2:error] [pid 157386:tid 157600] [client 68.155.154.236:14220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA0gAAAV4"] [Tue Aug 18 13:06:41.044342 2026] [security2:error] [pid 157386:tid 157520] [client 20.171.51.14:41715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/of.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA1wAAAQ4"] [Tue Aug 18 13:06:41.064511 2026] [security2:error] [pid 157386:tid 157578] [client 168.62.48.100:18118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA2AAAAUg"] [Tue Aug 18 13:06:41.073532 2026] [security2:error] [pid 157386:tid 157597] [client 74.248.18.37:32467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/Core-Econ/index.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA2gAAAVs"] [Tue Aug 18 13:06:41.090650 2026] [security2:error] [pid 157386:tid 157611] [client 20.226.36.136:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/opsqt.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA3AAAAWk"] [Tue Aug 18 13:06:41.101857 2026] [security2:error] [pid 157386:tid 157453] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/elp.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA3gABYUI"] [Tue Aug 18 13:06:41.156593 2026] [security2:error] [pid 157386:tid 157614] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/epinyins.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA4QAAAWw"] [Tue Aug 18 13:06:41.175217 2026] [security2:error] [pid 157386:tid 157557] [client 20.215.241.237:59258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/puc.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA4gAAATM"] [Tue Aug 18 13:06:41.178041 2026] [security2:error] [pid 157386:tid 157577] [client 20.124.247.79:16723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA4wAAAUc"] [Tue Aug 18 13:06:41.192109 2026] [security2:error] [pid 157386:tid 157610] [client 202.150.75.89:24677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.75.150.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marioneto.com.br"] [uri "/site/wp-login.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA5AAAAWg"] [Tue Aug 18 13:06:41.216712 2026] [security2:error] [pid 157386:tid 157534] [client 178.153.171.161:5145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA6QAAARw"] [Tue Aug 18 13:06:41.216835 2026] [security2:error] [pid 157386:tid 157534] [client 178.153.171.161:5145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA6QAAARw"] [Tue Aug 18 13:06:41.223403 2026] [security2:error] [pid 157386:tid 157617] [client 20.1.169.243:15955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA6gAAAW8"] [Tue Aug 18 13:06:41.226470 2026] [security2:error] [pid 157386:tid 157637] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/chosen.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA7AAAAYM"] [Tue Aug 18 13:06:41.266933 2026] [security2:error] [pid 157386:tid 157643] [client 158.23.17.4:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nu.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA8AAAAYk"] [Tue Aug 18 13:06:41.270031 2026] [security2:error] [pid 157386:tid 157420] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA8QABJCE"] [Tue Aug 18 13:06:41.272243 2026] [security2:error] [pid 157386:tid 157631] [client 74.248.130.103:37557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/BDKR28WP.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA8gAAAX0"] [Tue Aug 18 13:06:41.281804 2026] [security2:error] [pid 157386:tid 157576] [client 20.79.204.6:11648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/goods.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA9QAAAUY"] [Tue Aug 18 13:06:41.285260 2026] [security2:error] [pid 157386:tid 157585] [client 20.127.136.245:28122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/vx.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA9gAAAU8"] [Tue Aug 18 13:06:41.292283 2026] [security2:error] [pid 157386:tid 157620] [client 20.116.17.175:20457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA9wAAAXI"] [Tue Aug 18 13:06:41.299960 2026] [security2:error] [pid 157386:tid 157559] [client 20.226.36.136:63861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA-AAAATU"] [Tue Aug 18 13:06:41.309198 2026] [security2:error] [pid 157386:tid 157583] [client 20.151.109.219:59744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/showphpinfo.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA-QAAAU0"] [Tue Aug 18 13:06:41.326672 2026] [security2:error] [pid 157386:tid 157531] [client 168.62.48.100:18119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA-wAAARk"] [Tue Aug 18 13:06:41.332126 2026] [security2:error] [pid 157386:tid 157552] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/bajah.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA_AAAAS4"] [Tue Aug 18 13:06:41.332145 2026] [security2:error] [pid 157386:tid 157536] [client 74.249.206.207:32525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/indes.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA_QAAAR4"] [Tue Aug 18 13:06:41.345873 2026] [security2:error] [pid 157386:tid 157548] [client 158.158.74.177:20535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSDEU1jzAhYHVVT1WcA_gAAASo"] [Tue Aug 18 13:06:41.393246 2026] [security2:error] [pid 157386:tid 157574] [client 68.155.156.252:33449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/Njima.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBAAAAAUQ"] [Tue Aug 18 13:06:41.424138 2026] [security2:error] [pid 157386:tid 157597] [client 68.155.154.236:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/well-known/index.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBAgAAAVs"] [Tue Aug 18 13:06:41.434277 2026] [security2:error] [pid 157386:tid 157540] [client 20.251.48.93:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBAwAAASI"] [Tue Aug 18 13:06:41.436362 2026] [security2:error] [pid 157386:tid 157549] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBBQAAASs"] [Tue Aug 18 13:06:41.455582 2026] [security2:error] [pid 157386:tid 157571] [client 40.74.65.169:4866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBCAAAAUE"] [Tue Aug 18 13:06:41.475758 2026] [security2:error] [pid 157386:tid 157522] [client 20.116.17.175:22614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ot.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBDQAAARA"] [Tue Aug 18 13:06:41.535427 2026] [security2:error] [pid 157386:tid 157490] [remote 129.121.103.155:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impactads.com.br"] [uri "/wp-login.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBEAABhmc"] [Tue Aug 18 13:06:41.539968 2026] [security2:error] [pid 157386:tid 157594] [client 20.25.139.174:4837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wso.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBEQAAAVg"] [Tue Aug 18 13:06:41.543357 2026] [security2:error] [pid 157386:tid 157615] [client 20.124.247.79:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/av.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBEgAAAW0"] [Tue Aug 18 13:06:41.560974 2026] [security2:error] [pid 157386:tid 157610] [client 68.221.73.131:53651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/xamp.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBFAAAAWg"] [Tue Aug 18 13:06:41.576510 2026] [security2:error] [pid 157386:tid 157534] [client 52.173.121.69:35117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBFgAAARw"] [Tue Aug 18 13:06:41.587885 2026] [security2:error] [pid 157386:tid 157601] [client 20.1.169.243:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/abe.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBFwAAAV8"] [Tue Aug 18 13:06:41.589314 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/22.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBGAAAAXY"] [Tue Aug 18 13:06:41.649749 2026] [security2:error] [pid 157386:tid 157470] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/o.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBIAABRlM"] [Tue Aug 18 13:06:41.654088 2026] [security2:error] [pid 157386:tid 157530] [client 20.151.109.219:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/phpstatus.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBIgAAARg"] [Tue Aug 18 13:06:41.664394 2026] [security2:error] [pid 157386:tid 157558] [client 20.171.51.14:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/bu.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBIwAAATQ"] [Tue Aug 18 13:06:41.670097 2026] [security2:error] [pid 157386:tid 157516] [client 20.151.109.219:17654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kv.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBJgAAAQo"] [Tue Aug 18 13:06:41.673614 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.36.136:61466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/jvcpa.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBJwAAAVQ"] [Tue Aug 18 13:06:41.692072 2026] [security2:error] [pid 157386:tid 157536] [client 168.62.48.100:18171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBKwAAAR4"] [Tue Aug 18 13:06:41.713421 2026] [security2:error] [pid 157386:tid 157600] [client 74.249.206.207:45045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBLAAAAV4"] [Tue Aug 18 13:06:41.753797 2026] [security2:error] [pid 157386:tid 157539] [client 20.116.17.175:20479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBLwAAASE"] [Tue Aug 18 13:06:41.789932 2026] [security2:error] [pid 157386:tid 157630] [client 68.155.154.236:14254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBMQAAAXw"] [Tue Aug 18 13:06:41.811296 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:41.811662 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:41.816918 2026] [security2:error] [pid 157386:tid 157391] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/theme.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBNgABgQQ"] [Tue Aug 18 13:06:41.821475 2026] [security2:error] [pid 157386:tid 157527] [client 74.248.130.103:10462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/sf.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBNwAAARU"] [Tue Aug 18 13:06:41.823319 2026] [security2:error] [pid 157386:tid 157518] [client 74.248.18.37:32449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/120f9.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBOAAAAQw"] [Tue Aug 18 13:06:41.826962 2026] [security2:error] [pid 157386:tid 157571] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/wpxml.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBOQAAAUE"] [Tue Aug 18 13:06:41.863291 2026] [security2:error] [pid 157386:tid 157522] [client 20.251.48.93:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/admin.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBPAAAARA"] [Tue Aug 18 13:06:41.869842 2026] [security2:error] [pid 157386:tid 157589] [client 20.124.247.79:16740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/images.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBPQAAAVM"] [Tue Aug 18 13:06:41.887539 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:5326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/con7.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBPgAAAYc"] [Tue Aug 18 13:06:41.887982 2026] [security2:error] [pid 157386:tid 157531] [client 20.79.204.6:11670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBPwAAARk"] [Tue Aug 18 13:06:41.902896 2026] [security2:error] [pid 157386:tid 157588] [client 213.35.127.232:54878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBQQAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:41.905923 2026] [security2:error] [pid 157386:tid 157529] [client 158.23.17.4:25358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ko.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBQgAAARc"] [Tue Aug 18 13:06:41.934637 2026] [security2:error] [pid 157386:tid 157557] [client 20.226.36.136:25123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBQwAAATM"] [Tue Aug 18 13:06:41.950291 2026] [security2:error] [pid 157386:tid 157572] [client 20.1.169.243:4493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBRAAAAUI"] [Tue Aug 18 13:06:41.951495 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBRQAAAUs"] [Tue Aug 18 13:06:41.959648 2026] [security2:error] [pid 157386:tid 157520] [client 43.164.196.244:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.196.164.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.turialaluminio.com.br"] [uri "/rss.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBMwAAAQ4"] [Tue Aug 18 13:06:41.963525 2026] [security2:error] [pid 157386:tid 157569] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/domvf.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBRgAAAT8"] [Tue Aug 18 13:06:41.968469 2026] [security2:error] [pid 157386:tid 157564] [client 158.158.74.177:20518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/goat.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBSAAAATo"] [Tue Aug 18 13:06:41.987308 2026] [security2:error] [pid 157386:tid 157538] [client 47.128.58.253:18910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "goedertcertificacaodigital.com.br"] [uri "/robots.txt"] [unique_id "aoSDEU1jzAhYHVVT1WcBTQAAASA"] [Tue Aug 18 13:06:41.990094 2026] [security2:error] [pid 157386:tid 157554] [client 20.1.169.243:15574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin/index_upload.php"] [unique_id "aoSDEU1jzAhYHVVT1WcBTgAAATA"] [Tue Aug 18 13:06:42.001192 2026] [security2:error] [pid 157386:tid 157563] [client 20.151.109.219:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/del.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBTwAAATk"] [Tue Aug 18 13:06:42.003015 2026] [security2:error] [pid 157386:tid 157556] [client 20.127.136.245:28277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wap.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBUAAAATI"] [Tue Aug 18 13:06:42.018962 2026] [security2:error] [pid 157386:tid 157610] [client 168.62.48.100:18150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBUQAAAWg"] [Tue Aug 18 13:06:42.050390 2026] [security2:error] [pid 157386:tid 157603] [client 20.250.13.23:18509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-activat.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBUgAAAWE"] [Tue Aug 18 13:06:42.064255 2026] [security2:error] [pid 157386:tid 157601] [client 20.118.133.132:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/ws55.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBVQAAAV8"] [Tue Aug 18 13:06:42.079451 2026] [security2:error] [pid 157386:tid 157559] [client 222.124.191.185:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBVgAAATU"] [Tue Aug 18 13:06:42.079565 2026] [security2:error] [pid 157386:tid 157559] [client 222.124.191.185:57060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/site/xmlrpc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBVgAAATU"] [Tue Aug 18 13:06:42.084906 2026] [security2:error] [pid 157386:tid 157591] [client 74.249.206.207:32605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/bs1.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBWAAAAVU"] [Tue Aug 18 13:06:42.097369 2026] [security2:error] [pid 157386:tid 157553] [client 20.25.139.174:4644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/zup.php73"] [unique_id "aoSDEk1jzAhYHVVT1WcBXAAAAS8"] [Tue Aug 18 13:06:42.120909 2026] [security2:error] [pid 157386:tid 157590] [client 68.155.156.252:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/BIBIL.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBXgAAAVQ"] [Tue Aug 18 13:06:42.130356 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ab.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBYAAAAV0"] [Tue Aug 18 13:06:42.133176 2026] [security2:error] [pid 157386:tid 157600] [client 20.151.109.219:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/zs.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBYQAAAV4"] [Tue Aug 18 13:06:42.137083 2026] [security2:error] [pid 157386:tid 157542] [client 68.155.154.236:14258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBYgAAASQ"] [Tue Aug 18 13:06:42.154288 2026] [security2:error] [pid 157386:tid 157567] [client 40.74.65.169:4819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/site.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBYwAAAT0"] [Tue Aug 18 13:06:42.209758 2026] [security2:error] [pid 157386:tid 157478] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBZwABFFs"] [Tue Aug 18 13:06:42.210456 2026] [security2:error] [pid 157386:tid 157539] [client 52.173.121.69:52977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBaAAAASE"] [Tue Aug 18 13:06:42.243910 2026] [security2:error] [pid 157386:tid 157630] [client 20.171.51.14:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/rn.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBcAAAAXw"] [Tue Aug 18 13:06:42.244854 2026] [security2:error] [pid 157386:tid 157562] [client 20.226.36.136:41523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBcQAAATg"] [Tue Aug 18 13:06:42.253684 2026] [security2:error] [pid 157386:tid 157629] [client 20.1.169.243:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBdAAAAXs"] [Tue Aug 18 13:06:42.271427 2026] [security2:error] [pid 157386:tid 157527] [client 20.104.100.201:53847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/red.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBdgAAARU"] [Tue Aug 18 13:06:42.274373 2026] [security2:error] [pid 157386:tid 157518] [client 20.116.17.175:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/term.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBdwAAAQw"] [Tue Aug 18 13:06:42.286506 2026] [security2:error] [pid 157386:tid 157560] [client 20.124.247.79:16757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/ops.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBeAAAATY"] [Tue Aug 18 13:06:42.303631 2026] [security2:error] [pid 157386:tid 157531] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env"] [unique_id "aoSDEk1jzAhYHVVT1WcBfAAAARk"] [Tue Aug 18 13:06:42.317031 2026] [security2:error] [pid 157386:tid 157585] [client 20.1.169.243:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/15.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBfQAAAU8"] [Tue Aug 18 13:06:42.327635 2026] [security2:error] [pid 157386:tid 157588] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBfgAAAVI"] [Tue Aug 18 13:06:42.335152 2026] [security2:error] [pid 157386:tid 157572] [client 20.251.48.93:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file52.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBfwAAAUI"] [Tue Aug 18 13:06:42.355305 2026] [security2:error] [pid 157386:tid 157583] [client 20.1.169.243:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin/upload/css.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBgAAAAU0"] [Tue Aug 18 13:06:42.356014 2026] [security2:error] [pid 157386:tid 157584] [client 202.150.75.89:24714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.75.150.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marioneto.com.br"] [uri "/site/wp-login.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBgQAAAU4"] [Tue Aug 18 13:06:42.366225 2026] [security2:error] [pid 157386:tid 157577] [client 20.151.109.219:49928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/pl.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBggAAAUc"] [Tue Aug 18 13:06:42.375443 2026] [security2:error] [pid 157386:tid 157422] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/bi.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBgwABOiM"] [Tue Aug 18 13:06:42.395462 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/moderator.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBhAAAAYY"] [Tue Aug 18 13:06:42.426755 2026] [security2:error] [pid 157386:tid 157524] [client 74.249.206.207:32628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/hp2.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBhQAAARI"] [Tue Aug 18 13:06:42.434947 2026] [security2:error] [pid 157386:tid 157587] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/file1221.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBhgAAAVE"] [Tue Aug 18 13:06:42.498548 2026] [security2:error] [pid 157386:tid 157609] [client 20.79.204.6:11534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/htaccess.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBhwAAAWc"] [Tue Aug 18 13:06:42.500435 2026] [security2:error] [pid 157386:tid 157601] [client 74.248.130.103:42386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/k.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBiAAAAV8"] [Tue Aug 18 13:06:42.544249 2026] [security2:error] [pid 157386:tid 157389] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBiQABLgI"] [Tue Aug 18 13:06:42.549924 2026] [security2:error] [pid 157386:tid 157617] [client 168.62.48.100:18163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBigAAAW8"] [Tue Aug 18 13:06:42.560157 2026] [security2:error] [pid 157386:tid 157602] [client 68.221.73.131:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/bless.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBiwAAAWA"] [Tue Aug 18 13:06:42.591097 2026] [security2:error] [pid 157386:tid 157631] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/fpwch.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBjAAAAX0"] [Tue Aug 18 13:06:42.594127 2026] [security2:error] [pid 157386:tid 157623] [client 20.127.136.245:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBjgAAAXU"] [Tue Aug 18 13:06:42.604145 2026] [security2:error] [pid 157386:tid 157620] [client 68.155.154.236:14235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBjwAAAXI"] [Tue Aug 18 13:06:42.616695 2026] [security2:error] [pid 157386:tid 157603] [client 20.1.169.243:5336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/dist/alfa-rex.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBkAAAAWE"] [Tue Aug 18 13:06:42.640080 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBkQAAAVY"] [Tue Aug 18 13:06:42.642891 2026] [security2:error] [pid 157386:tid 157619] [client 20.124.247.79:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/coffexium.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBkgAAAXE"] [Tue Aug 18 13:06:42.660402 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:62966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/env.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBkwAAAVQ"] [Tue Aug 18 13:06:42.661181 2026] [security2:error] [pid 157386:tid 157618] [client 20.25.139.174:4495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/k.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBlAAAAXA"] [Tue Aug 18 13:06:42.665014 2026] [security2:error] [pid 157386:tid 157532] [client 158.158.74.177:24674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/Session.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBlQAAARo"] [Tue Aug 18 13:06:42.680565 2026] [security2:error] [pid 157386:tid 157559] [client 20.1.169.243:4535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/403.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBlwAAATU"] [Tue Aug 18 13:06:42.691621 2026] [fcgid:warn] [pid 157386:tid 157567] (70014)End of file found: [client 199.45.155.83:43290] mod_fcgid: can't get data from http client [Tue Aug 18 13:06:42.710950 2026] [security2:error] [pid 157386:tid 157624] [client 20.250.13.23:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBnAAAAXY"] [Tue Aug 18 13:06:42.718743 2026] [security2:error] [pid 157386:tid 157530] [client 20.1.169.243:15987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/al.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBnQAAARg"] [Tue Aug 18 13:06:42.720289 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:17584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/infoinfo.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBngAAASE"] [Tue Aug 18 13:06:42.739066 2026] [security2:error] [pid 157386:tid 157518] [client 74.249.206.207:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/yb.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBowAAAQw"] [Tue Aug 18 13:06:42.750620 2026] [security2:error] [pid 157386:tid 157628] [client 20.151.109.219:45841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/z.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBpwAAAXo"] [Tue Aug 18 13:06:42.756529 2026] [security2:error] [pid 157386:tid 157506] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/24.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBqAABUnc"] [Tue Aug 18 13:06:42.775706 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:20938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/iz.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBqgAAAWk"] [Tue Aug 18 13:06:42.781017 2026] [security2:error] [pid 157386:tid 157584] [client 20.251.48.93:3784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/geck.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBqwAAAU4"] [Tue Aug 18 13:06:42.802371 2026] [security2:error] [pid 157386:tid 157558] [client 138.36.100.162:41371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBrQAAATQ"] [Tue Aug 18 13:06:42.802486 2026] [security2:error] [pid 157386:tid 157558] [client 138.36.100.162:41371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBrQAAATQ"] [Tue Aug 18 13:06:42.820891 2026] [security2:error] [pid 157386:tid 157634] [client 74.248.18.37:32491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/providers/ultra.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBsQAAAYA"] [Tue Aug 18 13:06:42.822469 2026] [security2:error] [pid 157386:tid 157636] [client 20.171.51.14:44927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ut.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBsgAAAYI"] [Tue Aug 18 13:06:42.836176 2026] [security2:error] [pid 157386:tid 157615] [client 158.23.17.4:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/pl.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBswAAAW0"] [Tue Aug 18 13:06:42.850924 2026] [security2:error] [pid 157386:tid 157541] [client 40.74.65.169:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/ccc.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBtAAAASM"] [Tue Aug 18 13:06:42.852585 2026] [security2:error] [pid 157386:tid 157538] [client 168.62.48.100:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBtgAAASA"] [Tue Aug 18 13:06:42.876909 2026] [security2:error] [pid 157386:tid 157586] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env.backup"] [unique_id "aoSDEk1jzAhYHVVT1WcBuwAAAVA"] [Tue Aug 18 13:06:42.887758 2026] [security2:error] [pid 157386:tid 157521] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env.bak"] [unique_id "aoSDEk1jzAhYHVVT1WcBvAAAAQ8"] [Tue Aug 18 13:06:42.890666 2026] [security2:error] [pid 157386:tid 157536] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env.old"] [unique_id "aoSDEk1jzAhYHVVT1WcBvQAAAR4"] [Tue Aug 18 13:06:42.907000 2026] [security2:error] [pid 157386:tid 157602] [client 52.173.121.69:57765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBvwAAAWA"] [Tue Aug 18 13:06:42.916395 2026] [security2:error] [pid 157386:tid 157620] [client 20.116.17.175:45263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/v5.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBwgAAAXI"] [Tue Aug 18 13:06:42.917182 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.36.136:41508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBwwAAAWE"] [Tue Aug 18 13:06:42.922491 2026] [security2:error] [pid 157386:tid 157547] [client 213.35.127.232:55136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBxAAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:42.935539 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/black.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBxgAAASs"] [Tue Aug 18 13:06:42.981309 2026] [security2:error] [pid 157386:tid 157543] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/function/function.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBywAAASU"] [Tue Aug 18 13:06:42.981752 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:5343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/elementor/wp-login.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBzAAAATk"] [Tue Aug 18 13:06:42.985167 2026] [security2:error] [pid 157386:tid 157595] [client 74.248.130.103:10520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/82.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBzQAAAVk"] [Tue Aug 18 13:06:42.990417 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mz.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBzgAAAUk"] [Tue Aug 18 13:06:43.002851 2026] [security2:error] [pid 157386:tid 157570] [client 20.151.109.219:12902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/c99shell.php"] [unique_id "aoSDE01jzAhYHVVT1WcBzwAAAUA"] [Tue Aug 18 13:06:43.006516 2026] [security2:error] [pid 157386:tid 157580] [client 20.124.247.79:16762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDE01jzAhYHVVT1WcB0AAAAUo"] [Tue Aug 18 13:06:43.041799 2026] [security2:error] [pid 157386:tid 157632] [client 20.206.73.37:24480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/fz.php"] [unique_id "aoSDE01jzAhYHVVT1WcB0QAAAX4"] [Tue Aug 18 13:06:43.050027 2026] [security2:error] [pid 157386:tid 157592] [client 20.1.169.243:4998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/404webshell.php"] [unique_id "aoSDE01jzAhYHVVT1WcB0gAAAVY"] [Tue Aug 18 13:06:43.053463 2026] [security2:error] [pid 157386:tid 157550] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/nox.php"] [unique_id "aoSDE01jzAhYHVVT1WcB0wAAASw"] [Tue Aug 18 13:06:43.059031 2026] [security2:error] [pid 157386:tid 157539] [client 20.206.73.37:15890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/33.php"] [unique_id "aoSDE01jzAhYHVVT1WcB1AAAASE"] [Tue Aug 18 13:06:43.082226 2026] [security2:error] [pid 157386:tid 157599] [client 20.1.169.243:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/baxa1.php"] [unique_id "aoSDE01jzAhYHVVT1WcB1gAAAV0"] [Tue Aug 18 13:06:43.083188 2026] [security2:error] [pid 157386:tid 157496] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB1QABfG0"] [Tue Aug 18 13:06:43.083331 2026] [security2:error] [pid 157386:tid 157630] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB1QABfG0"] [Tue Aug 18 13:06:43.088203 2026] [security2:error] [pid 157386:tid 157566] [client 68.155.154.236:14246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/mt/byp.php"] [unique_id "aoSDE01jzAhYHVVT1WcB1wAAATw"] [Tue Aug 18 13:06:43.094069 2026] [security2:error] [pid 157386:tid 157604] [client 74.249.206.207:32343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/vc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB2AAAAWI"] [Tue Aug 18 13:06:43.104948 2026] [security2:error] [pid 157386:tid 157590] [client 37.139.53.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.53.139.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.tinna.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBxwAAAVQ"], referer: http://blog.tinna.com.br/2016/09/19/primavera-verao-2017-4-tendencias/ [Tue Aug 18 13:06:43.105064 2026] [security2:error] [pid 157386:tid 157590] [client 37.139.53.7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "blog.tinna.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDEk1jzAhYHVVT1WcBxwAAAVQ"], referer: http://blog.tinna.com.br/2016/09/19/primavera-verao-2017-4-tendencias/ [Tue Aug 18 13:06:43.128495 2026] [security2:error] [pid 157386:tid 157516] [client 20.79.204.6:11530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/images/wso.php"] [unique_id "aoSDE01jzAhYHVVT1WcB2wAAAQo"] [Tue Aug 18 13:06:43.147094 2026] [security2:error] [pid 157386:tid 157591] [client 197.184.64.235:42683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB3wAAAVU"] [Tue Aug 18 13:06:43.147184 2026] [security2:error] [pid 157386:tid 157591] [client 197.184.64.235:42683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB3wAAAVU"] [Tue Aug 18 13:06:43.179511 2026] [security2:error] [pid 157386:tid 157597] [client 68.221.73.131:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file25.php"] [unique_id "aoSDE01jzAhYHVVT1WcB4gAAAVs"] [Tue Aug 18 13:06:43.194313 2026] [security2:error] [pid 157386:tid 157614] [client 20.25.139.174:4448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDE01jzAhYHVVT1WcB4wAAAWw"] [Tue Aug 18 13:06:43.209292 2026] [security2:error] [pid 157386:tid 157564] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/adminner.php"] [unique_id "aoSDE01jzAhYHVVT1WcB5QAAATo"] [Tue Aug 18 13:06:43.225477 2026] [security2:error] [pid 157386:tid 157558] [client 168.62.48.100:18056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDE01jzAhYHVVT1WcB5gAAATQ"] [Tue Aug 18 13:06:43.236742 2026] [security2:error] [pid 157386:tid 157582] [client 20.251.48.93:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/biufile.php"] [unique_id "aoSDE01jzAhYHVVT1WcB5wAAAUw"] [Tue Aug 18 13:06:43.238005 2026] [security2:error] [pid 157386:tid 157542] [client 20.127.136.245:28147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/bgymj.php"] [unique_id "aoSDE01jzAhYHVVT1WcB6AAAASQ"] [Tue Aug 18 13:06:43.262591 2026] [security2:error] [pid 157386:tid 157641] [client 222.124.191.185:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB6QAAAYc"] [Tue Aug 18 13:06:43.262671 2026] [security2:error] [pid 157386:tid 157641] [client 222.124.191.185:57070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/news/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcB6QAAAYc"] [Tue Aug 18 13:06:43.268412 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ft.php"] [unique_id "aoSDE01jzAhYHVVT1WcB6gAAAYA"] [Tue Aug 18 13:06:43.274620 2026] [security2:error] [pid 157386:tid 157594] [client 20.171.51.14:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/eh.php"] [unique_id "aoSDE01jzAhYHVVT1WcB6wAAAVg"] [Tue Aug 18 13:06:43.286429 2026] [security2:error] [pid 157386:tid 157636] [client 20.124.247.79:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/sf.php"] [unique_id "aoSDE01jzAhYHVVT1WcB7AAAAYI"] [Tue Aug 18 13:06:43.303423 2026] [security2:error] [pid 157386:tid 157629] [client 158.158.74.177:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSDE01jzAhYHVVT1WcB7QAAAXs"] [Tue Aug 18 13:06:43.345880 2026] [security2:error] [pid 157386:tid 157568] [client 20.151.109.219:17542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/profiler.php"] [unique_id "aoSDE01jzAhYHVVT1WcB8gAAAT4"] [Tue Aug 18 13:06:43.351013 2026] [security2:error] [pid 157386:tid 157553] [client 20.250.13.23:44038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/past1.php"] [unique_id "aoSDE01jzAhYHVVT1WcB8wAAAS8"] [Tue Aug 18 13:06:43.383981 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:56031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xg.php"] [unique_id "aoSDE01jzAhYHVVT1WcB9QAAAS4"] [Tue Aug 18 13:06:43.395861 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDE01jzAhYHVVT1WcB9gAAAWA"] [Tue Aug 18 13:06:43.402742 2026] [security2:error] [pid 157386:tid 157623] [client 74.249.206.207:32636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/pema.php"] [unique_id "aoSDE01jzAhYHVVT1WcB9wAAAXU"] [Tue Aug 18 13:06:43.405686 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.36.136:23193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDE01jzAhYHVVT1WcB-AAAAWE"] [Tue Aug 18 13:06:43.413260 2026] [security2:error] [pid 157386:tid 157615] [client 20.1.169.243:5014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/666.php"] [unique_id "aoSDE01jzAhYHVVT1WcB-QAAAW0"] [Tue Aug 18 13:06:43.417810 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:20424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/as.php"] [unique_id "aoSDE01jzAhYHVVT1WcB-gAAAYg"] [Tue Aug 18 13:06:43.447278 2026] [security2:error] [pid 157386:tid 157538] [client 20.1.169.243:15766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSDE01jzAhYHVVT1WcB-wAAASA"] [Tue Aug 18 13:06:43.467008 2026] [security2:error] [pid 157386:tid 157601] [client 74.248.130.103:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/dex.php"] [unique_id "aoSDE01jzAhYHVVT1WcB_AAAAV8"] [Tue Aug 18 13:06:43.468856 2026] [security2:error] [pid 157386:tid 157548] [client 20.1.169.243:5793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/goat1.php"] [unique_id "aoSDE01jzAhYHVVT1WcB_QAAASo"] [Tue Aug 18 13:06:43.500639 2026] [security2:error] [pid 157386:tid 157567] [client 20.226.36.136:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDE01jzAhYHVVT1WcB_gAAAT0"] [Tue Aug 18 13:06:43.503174 2026] [security2:error] [pid 157386:tid 157402] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-block.php"] [unique_id "aoSDE01jzAhYHVVT1WcB_wABSQ8"] [Tue Aug 18 13:06:43.511787 2026] [security2:error] [pid 157386:tid 157570] [client 20.151.109.219:22974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/se.php"] [unique_id "aoSDE01jzAhYHVVT1WcCAQAAAUA"] [Tue Aug 18 13:06:43.515813 2026] [security2:error] [pid 157386:tid 157606] [client 168.62.48.100:18010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDE01jzAhYHVVT1WcCAgAAAWQ"] [Tue Aug 18 13:06:43.525718 2026] [security2:error] [pid 157386:tid 157526] [client 158.23.17.4:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/env.php"] [unique_id "aoSDE01jzAhYHVVT1WcCAwAAARQ"] [Tue Aug 18 13:06:43.529693 2026] [security2:error] [pid 157386:tid 157510] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env"] [unique_id "aoSDE01jzAhYHVVT1WcCBAABVns"] [Tue Aug 18 13:06:43.535871 2026] [security2:error] [pid 157386:tid 157599] [client 68.155.154.236:14269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/MTOS/byp.php"] [unique_id "aoSDE01jzAhYHVVT1WcCBQAAAV0"] [Tue Aug 18 13:06:43.536249 2026] [security2:error] [pid 157386:tid 157630] [client 40.74.65.169:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/admin.php"] [unique_id "aoSDE01jzAhYHVVT1WcCBgAAAXw"] [Tue Aug 18 13:06:43.544687 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:65025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/h.php"] [unique_id "aoSDE01jzAhYHVVT1WcCBwAAATw"] [Tue Aug 18 13:06:43.608188 2026] [security2:error] [pid 157386:tid 157585] [client 135.225.75.187:31853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDE01jzAhYHVVT1WcCDgAAAU8"] [Tue Aug 18 13:06:43.614638 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:43.614949 2026] [authz_core:error] [pid 157386:tid 157430] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:43.619550 2026] [security2:error] [pid 157386:tid 157516] [client 20.124.247.79:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/k.php"] [unique_id "aoSDE01jzAhYHVVT1WcCDwAAAQo"] [Tue Aug 18 13:06:43.623240 2026] [security2:error] [pid 157386:tid 157633] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/api/.env"] [unique_id "aoSDE01jzAhYHVVT1WcCEAAAAX8"] [Tue Aug 18 13:06:43.634125 2026] [security2:error] [pid 157386:tid 157573] [client 20.206.73.37:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/scxy.php"] [unique_id "aoSDE01jzAhYHVVT1WcCFgAAAUM"] [Tue Aug 18 13:06:43.653259 2026] [security2:error] [pid 157386:tid 157583] [client 20.151.109.219:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/findes.php"] [unique_id "aoSDE01jzAhYHVVT1WcCGQAAAU0"] [Tue Aug 18 13:06:43.654284 2026] [security2:error] [pid 157386:tid 157619] [client 74.248.18.37:32486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-edit.php"] [unique_id "aoSDE01jzAhYHVVT1WcCGgAAAXE"] [Tue Aug 18 13:06:43.670237 2026] [security2:error] [pid 157386:tid 157581] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/akismet.php"] [unique_id "aoSDE01jzAhYHVVT1WcCGwAAAUs"] [Tue Aug 18 13:06:43.671427 2026] [security2:error] [pid 157386:tid 157445] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wk/index.php"] [unique_id "aoSDE01jzAhYHVVT1WcCHAABgTo"] [Tue Aug 18 13:06:43.681098 2026] [security2:error] [pid 157386:tid 157558] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDE01jzAhYHVVT1WcCHgAAATQ"] [Tue Aug 18 13:06:43.702257 2026] [security2:error] [pid 157386:tid 157640] [client 74.249.206.207:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/sh.php"] [unique_id "aoSDE01jzAhYHVVT1WcCIwAAAYY"] [Tue Aug 18 13:06:43.718058 2026] [security2:error] [pid 157386:tid 157589] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/backend/.env"] [unique_id "aoSDE01jzAhYHVVT1WcCJQAAAVM"] [Tue Aug 18 13:06:43.722280 2026] [security2:error] [pid 157386:tid 157594] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/config/.env"] [unique_id "aoSDE01jzAhYHVVT1WcCJgAAAVg"] [Tue Aug 18 13:06:43.729088 2026] [security2:error] [pid 157386:tid 157530] [client 20.79.204.6:11651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/index/function.php"] [unique_id "aoSDE01jzAhYHVVT1WcCKAAAARg"] [Tue Aug 18 13:06:43.736785 2026] [security2:error] [pid 157386:tid 157625] [client 20.251.48.93:17082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/dejavu.php"] [unique_id "aoSDE01jzAhYHVVT1WcCKQAAAXc"] [Tue Aug 18 13:06:43.740996 2026] [security2:error] [pid 157386:tid 157525] [client 20.116.17.175:22642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSDE01jzAhYHVVT1WcCKwAAARM"] [Tue Aug 18 13:06:43.756601 2026] [security2:error] [pid 157386:tid 157561] [client 196.12.128.158:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcCLAAAATc"] [Tue Aug 18 13:06:43.756732 2026] [security2:error] [pid 157386:tid 157561] [client 196.12.128.158:61636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDE01jzAhYHVVT1WcCLAAAATc"] [Tue Aug 18 13:06:43.774634 2026] [security2:error] [pid 157386:tid 157584] [client 20.1.169.243:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/7.php"] [unique_id "aoSDE01jzAhYHVVT1WcCMAAAAU4"] [Tue Aug 18 13:06:43.789951 2026] [security2:error] [pid 157386:tid 157550] [client 20.127.136.245:28126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/aa.php"] [unique_id "aoSDE01jzAhYHVVT1WcCMgAAASw"] [Tue Aug 18 13:06:43.804975 2026] [security2:error] [pid 157386:tid 157575] [client 213.202.253.4:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDE01jzAhYHVVT1WcCMwAAAUU"], referer: www.google.com [Tue Aug 18 13:06:43.812437 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSDE01jzAhYHVVT1WcCNAAAARA"] [Tue Aug 18 13:06:43.822666 2026] [security2:error] [pid 157386:tid 157549] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/abcd.php"] [unique_id "aoSDE01jzAhYHVVT1WcCNQAAASs"] [Tue Aug 18 13:06:43.830166 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/google-seo-rank/module.php"] [unique_id "aoSDE01jzAhYHVVT1WcCNgAAAYA"] [Tue Aug 18 13:06:43.874622 2026] [security2:error] [pid 157386:tid 157601] [client 168.62.48.100:18109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDE01jzAhYHVVT1WcCOAAAAV8"] [Tue Aug 18 13:06:43.901538 2026] [security2:error] [pid 157386:tid 157580] [client 68.155.154.236:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDE01jzAhYHVVT1WcCOQAAAUo"] [Tue Aug 18 13:06:43.910630 2026] [security2:error] [pid 157386:tid 157624] [client 20.124.247.79:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/82.php"] [unique_id "aoSDE01jzAhYHVVT1WcCPAAAAXY"] [Tue Aug 18 13:06:43.910936 2026] [security2:error] [pid 157386:tid 157390] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/w.php"] [unique_id "aoSDE01jzAhYHVVT1WcCPQABHAM"] [Tue Aug 18 13:06:43.930038 2026] [security2:error] [pid 157386:tid 157526] [client 52.173.121.69:52981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDE01jzAhYHVVT1WcCPwAAARQ"] [Tue Aug 18 13:06:43.936020 2026] [security2:error] [pid 157386:tid 157566] [client 20.116.17.175:20428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/pucci.php"] [unique_id "aoSDE01jzAhYHVVT1WcCQwAAATw"] [Tue Aug 18 13:06:43.936764 2026] [security2:error] [pid 157386:tid 157621] [client 20.116.17.175:58201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/12.php"] [unique_id "aoSDE01jzAhYHVVT1WcCRAAAAXM"] [Tue Aug 18 13:06:43.950553 2026] [security2:error] [pid 157386:tid 157588] [client 213.35.127.232:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDE01jzAhYHVVT1WcCRQAAAVI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:43.963161 2026] [security2:error] [pid 157386:tid 157544] [client 20.250.13.23:18534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/file61.php"] [unique_id "aoSDE01jzAhYHVVT1WcCSAAAASY"] [Tue Aug 18 13:06:43.965423 2026] [security2:error] [pid 157386:tid 157568] [client 158.158.74.177:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/abcd.php"] [unique_id "aoSDE01jzAhYHVVT1WcCSQAAAT4"] [Tue Aug 18 13:06:43.966771 2026] [security2:error] [pid 157386:tid 157585] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/ok.php"] [unique_id "aoSDE01jzAhYHVVT1WcCSgAAAU8"] [Tue Aug 18 13:06:43.969079 2026] [security2:error] [pid 157386:tid 157516] [client 20.151.109.219:5327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/40.php"] [unique_id "aoSDE01jzAhYHVVT1WcCSwAAAQo"] [Tue Aug 18 13:06:43.969803 2026] [security2:error] [pid 157386:tid 157633] [client 74.248.130.103:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/puc.php"] [unique_id "aoSDE01jzAhYHVVT1WcCTAAAAX8"] [Tue Aug 18 13:06:43.987821 2026] [security2:error] [pid 157386:tid 157404] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.bak"] [unique_id "aoSDE01jzAhYHVVT1WcCTgABQxE"] [Tue Aug 18 13:06:43.990136 2026] [security2:error] [pid 157386:tid 157491] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.backup"] [unique_id "aoSDE01jzAhYHVVT1WcCTwABQ2g"] [Tue Aug 18 13:06:44.024585 2026] [security2:error] [pid 157386:tid 157614] [client 135.225.75.187:57487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCUQAAAWw"] [Tue Aug 18 13:06:44.028480 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:21643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/fedora.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCUwAAATo"] [Tue Aug 18 13:06:44.047481 2026] [security2:error] [pid 157386:tid 157558] [client 74.249.206.207:32583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/button.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCVAAAATQ"] [Tue Aug 18 13:06:44.060080 2026] [security2:error] [pid 157386:tid 157640] [client 20.104.100.201:54072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/JawirGenk.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCVgAAAYY"] [Tue Aug 18 13:06:44.083421 2026] [security2:error] [pid 157386:tid 157524] [client 68.221.73.131:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file15.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCWAAAARI"] [Tue Aug 18 13:06:44.139701 2026] [security2:error] [pid 157386:tid 157619] [client 20.1.169.243:5047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/a7.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCWwAAAXE"] [Tue Aug 18 13:06:44.148493 2026] [security2:error] [pid 157386:tid 157547] [client 20.250.13.23:35173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/gecko-new.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCXgAAASk"] [Tue Aug 18 13:06:44.155063 2026] [security2:error] [pid 157386:tid 157631] [client 168.62.48.100:18155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCXwAAAX0"] [Tue Aug 18 13:06:44.160679 2026] [security2:error] [pid 157386:tid 157641] [client 20.251.48.93:17063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/aaf.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCYAAAAYc"] [Tue Aug 18 13:06:44.175729 2026] [security2:error] [pid 157386:tid 157602] [client 20.171.51.14:7899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ad.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCYQAAAWA"] [Tue Aug 18 13:06:44.176660 2026] [security2:error] [pid 157386:tid 157532] [client 20.1.169.243:15596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/contact.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCYwAAARo"] [Tue Aug 18 13:06:44.193088 2026] [security2:error] [pid 157386:tid 157612] [client 20.1.169.243:5771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/h.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCZAAAAWo"] [Tue Aug 18 13:06:44.211708 2026] [security2:error] [pid 157386:tid 157495] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/config/.env"] [unique_id "aoSDFE1jzAhYHVVT1WcCZQABH2w"] [Tue Aug 18 13:06:44.219902 2026] [security2:error] [pid 157386:tid 157603] [client 40.74.65.169:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/reviall.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCZwAAAWE"] [Tue Aug 18 13:06:44.239489 2026] [security2:error] [pid 157386:tid 157561] [client 20.127.136.245:28112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCagAAATc"] [Tue Aug 18 13:06:44.267564 2026] [security2:error] [pid 157386:tid 157553] [client 20.124.247.79:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/dex.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCbAAAAS8"] [Tue Aug 18 13:06:44.270258 2026] [security2:error] [pid 157386:tid 157639] [client 20.151.109.219:49936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ee.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCbQAAAYU"] [Tue Aug 18 13:06:44.281964 2026] [security2:error] [pid 157386:tid 157548] [client 68.155.154.236:14158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCbgAAASo"] [Tue Aug 18 13:06:44.288120 2026] [security2:error] [pid 157386:tid 157598] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/admin.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCbwAAAVw"] [Tue Aug 18 13:06:44.305141 2026] [security2:error] [pid 157386:tid 157570] [client 20.25.139.174:4802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/ww5.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCcQAAAUA"] [Tue Aug 18 13:06:44.310200 2026] [security2:error] [pid 157386:tid 157511] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCXAABLnw"] [Tue Aug 18 13:06:44.324830 2026] [security2:error] [pid 157386:tid 157624] [client 20.151.109.219:17551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/path.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCcgAAAXY"] [Tue Aug 18 13:06:44.328318 2026] [security2:error] [pid 157386:tid 157551] [client 20.79.204.6:11531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/info.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCcwAAAS0"] [Tue Aug 18 13:06:44.336904 2026] [security2:error] [pid 157386:tid 157483] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.env.old"] [unique_id "aoSDFE1jzAhYHVVT1WcCdAABHGA"] [Tue Aug 18 13:06:44.345298 2026] [security2:error] [pid 157386:tid 157477] [remote 185.118.190.176:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viniciushartl.com.br"] [uri "/wp-login.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCeAABIlo"] [Tue Aug 18 13:06:44.354534 2026] [security2:error] [pid 157386:tid 157621] [client 20.104.85.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.joanagaspar.com.br"] [uri "/item.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCfgAAAXM"] [Tue Aug 18 13:06:44.370520 2026] [security2:error] [pid 157386:tid 157588] [client 20.116.17.175:20451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wicked.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCgQAAAVI"] [Tue Aug 18 13:06:44.372682 2026] [security2:error] [pid 157386:tid 157590] [client 104.209.144.33:31247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCgAAAAVQ"] [Tue Aug 18 13:06:44.382010 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:17623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/nd.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCggAAASY"] [Tue Aug 18 13:06:44.400787 2026] [security2:error] [pid 157386:tid 157516] [client 20.226.36.136:53513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCgwAAAQo"] [Tue Aug 18 13:06:44.407426 2026] [security2:error] [pid 157386:tid 157604] [client 74.248.130.103:49433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/inso.php"] [unique_id "aoSDFE1jzAhYHVVT1WcChAAAAWI"] [Tue Aug 18 13:06:44.412962 2026] [security2:error] [pid 157386:tid 157616] [client 68.155.156.252:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/too.php"] [unique_id "aoSDFE1jzAhYHVVT1WcChQAAAW4"] [Tue Aug 18 13:06:44.419057 2026] [security2:error] [pid 157386:tid 157522] [client 74.248.18.37:24112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/twentytwentyfour/functions.php"] [unique_id "aoSDFE1jzAhYHVVT1WcChgAAARA"] [Tue Aug 18 13:06:44.442020 2026] [security2:error] [pid 157386:tid 157560] [client 222.124.191.185:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/web/xmlrpc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCiAAAATY"] [Tue Aug 18 13:06:44.442111 2026] [security2:error] [pid 157386:tid 157560] [client 222.124.191.185:57074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/web/xmlrpc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCiAAAATY"] [Tue Aug 18 13:06:44.445709 2026] [security2:error] [pid 157386:tid 157521] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/simple.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCiQAAAQ8"] [Tue Aug 18 13:06:44.449794 2026] [security2:error] [pid 157386:tid 157597] [client 135.225.75.187:11357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ws61.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCigAAAVs"] [Tue Aug 18 13:06:44.488419 2026] [security2:error] [pid 157386:tid 157428] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCkAABNCk"] [Tue Aug 18 13:06:44.489393 2026] [security2:error] [pid 157386:tid 157571] [client 168.62.48.100:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCkQAAAUE"] [Tue Aug 18 13:06:44.503278 2026] [security2:error] [pid 157386:tid 157607] [client 20.1.169.243:5027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/alfadheat.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCkgAAAWU"] [Tue Aug 18 13:06:44.511605 2026] [authz_core:error] [pid 157386:tid 157418] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:44.511866 2026] [authz_core:error] [pid 157386:tid 157418] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:44.520605 2026] [security2:error] [pid 157386:tid 157554] [client 5.31.227.224:7862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcClAAAATA"] [Tue Aug 18 13:06:44.534211 2026] [security2:error] [pid 157386:tid 157554] [client 5.31.227.224:7862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcClAAAATA"] [Tue Aug 18 13:06:44.545889 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vp.php"] [unique_id "aoSDFE1jzAhYHVVT1WcClgAAARM"] [Tue Aug 18 13:06:44.547059 2026] [security2:error] [pid 157386:tid 157531] [client 20.151.109.219:49299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ak.php"] [unique_id "aoSDFE1jzAhYHVVT1WcClwAAARk"] [Tue Aug 18 13:06:44.556465 2026] [security2:error] [pid 157386:tid 157572] [client 20.1.169.243:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/import/csv1.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCmAAAAUI"] [Tue Aug 18 13:06:44.561766 2026] [security2:error] [pid 157386:tid 157609] [client 20.1.169.243:15589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cux.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCmQAAAWc"] [Tue Aug 18 13:06:44.566946 2026] [security2:error] [pid 157386:tid 157619] [client 168.62.48.100:12235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCmwAAAXE"] [Tue Aug 18 13:06:44.585833 2026] [security2:error] [pid 157386:tid 157503] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/api/.env"] [unique_id "aoSDFE1jzAhYHVVT1WcCnQABKXQ"] [Tue Aug 18 13:06:44.588349 2026] [security2:error] [pid 157386:tid 157631] [client 74.249.206.207:32621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/wlc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCngAAAX0"] [Tue Aug 18 13:06:44.600046 2026] [security2:error] [pid 157386:tid 157542] [client 20.124.247.79:16756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/puc.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCnwAAASQ"] [Tue Aug 18 13:06:44.603174 2026] [security2:error] [pid 157386:tid 157585] [client 158.158.74.177:20483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/kj.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCoAAAAU8"] [Tue Aug 18 13:06:44.604104 2026] [security2:error] [pid 157386:tid 157550] [client 20.251.48.93:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCoQAAASw"] [Tue Aug 18 13:06:44.631216 2026] [security2:error] [pid 157386:tid 157537] [client 20.226.36.136:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCpAAAAR8"] [Tue Aug 18 13:06:44.637169 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:22619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCpQAAAYg"] [Tue Aug 18 13:06:44.652739 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:24871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/456.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCpwAAAUY"] [Tue Aug 18 13:06:44.654485 2026] [security2:error] [pid 157386:tid 157493] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/file5.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCqAABN2o"] [Tue Aug 18 13:06:44.660511 2026] [security2:error] [pid 157386:tid 157538] [client 20.206.73.37:17058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "levalixo.com.br"] [uri "/packed.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCqQAAASA"] [Tue Aug 18 13:06:44.734782 2026] [security2:error] [pid 157386:tid 157587] [client 20.127.136.245:28230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/bolt.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCrAAAAVE"] [Tue Aug 18 13:06:44.773994 2026] [security2:error] [pid 157386:tid 157540] [client 52.173.121.69:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCsQAAASI"] [Tue Aug 18 13:06:44.821345 2026] [security2:error] [pid 157386:tid 157500] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/new.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCtAABJnE"] [Tue Aug 18 13:06:44.833444 2026] [security2:error] [pid 157386:tid 157437] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/backend/.env"] [unique_id "aoSDFE1jzAhYHVVT1WcCtQABTDI"] [Tue Aug 18 13:06:44.857792 2026] [security2:error] [pid 157386:tid 157604] [client 20.250.13.23:23693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oleoebaterias.com.br"] [uri "/license.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCuQAAAWI"] [Tue Aug 18 13:06:44.864947 2026] [security2:error] [pid 157386:tid 157522] [client 74.248.130.103:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/aa.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCugAAARA"] [Tue Aug 18 13:06:44.865414 2026] [security2:error] [pid 157386:tid 157526] [client 135.225.75.187:11627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/rum.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCuwAAARQ"] [Tue Aug 18 13:06:44.868339 2026] [security2:error] [pid 157386:tid 157624] [client 20.1.169.243:5020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/apikey/mar.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCvAAAAXY"] [Tue Aug 18 13:06:44.883581 2026] [security2:error] [pid 157386:tid 157632] [client 168.62.48.100:18009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCvgAAAX4"] [Tue Aug 18 13:06:44.886529 2026] [security2:error] [pid 157386:tid 157548] [client 20.25.139.174:4838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/2.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCvwAAASo"] [Tue Aug 18 13:06:44.887007 2026] [security2:error] [pid 157386:tid 157599] [client 74.249.206.207:32351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/fi.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCwAAAAV0"] [Tue Aug 18 13:06:44.889459 2026] [security2:error] [pid 157386:tid 157566] [client 20.124.247.79:16642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/inso.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCwQAAATw"] [Tue Aug 18 13:06:44.894505 2026] [security2:error] [pid 157386:tid 157578] [client 40.74.65.169:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/nope.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCwwAAAUg"] [Tue Aug 18 13:06:44.912454 2026] [security2:error] [pid 157386:tid 157597] [client 20.196.200.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.200.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.1ba.com.br"] [uri "/ajax.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCxQAAAVs"] [Tue Aug 18 13:06:44.921376 2026] [security2:error] [pid 157386:tid 157527] [client 20.1.169.243:5339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/index.bak.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCxgAAARU"] [Tue Aug 18 13:06:44.927133 2026] [security2:error] [pid 157386:tid 157545] [client 20.1.169.243:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/favicon.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCxwAAASc"] [Tue Aug 18 13:06:44.933160 2026] [security2:error] [pid 157386:tid 157556] [client 20.116.17.175:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/x1da.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCyAAAATI"] [Tue Aug 18 13:06:44.940119 2026] [security2:error] [pid 157386:tid 157635] [client 20.151.109.219:49954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/test_info.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCyQAAAYE"] [Tue Aug 18 13:06:44.941015 2026] [security2:error] [pid 157386:tid 157539] [client 20.79.204.6:11671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/profile.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCygAAASE"] [Tue Aug 18 13:06:44.965334 2026] [security2:error] [pid 157386:tid 157575] [client 213.35.127.232:55599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCzAAAAUU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:44.981191 2026] [security2:error] [pid 157386:tid 157607] [client 68.221.73.131:45085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/f35.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCzQAAAWU"] [Tue Aug 18 13:06:44.985462 2026] [security2:error] [pid 157386:tid 157530] [client 68.155.154.236:14254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDFE1jzAhYHVVT1WcCzwAAARg"] [Tue Aug 18 13:06:44.994343 2026] [security2:error] [pid 157386:tid 157395] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/fm.php"] [unique_id "aoSDFE1jzAhYHVVT1WcC0QABHQg"] [Tue Aug 18 13:06:45.006670 2026] [security2:error] [pid 157386:tid 157614] [client 20.151.109.219:21692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/SMTP.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC0wAAAWw"] [Tue Aug 18 13:06:45.018156 2026] [security2:error] [pid 157386:tid 157432] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC1AABJS0"] [Tue Aug 18 13:06:45.018391 2026] [security2:error] [pid 157386:tid 157543] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC1AABJS0"] [Tue Aug 18 13:06:45.041859 2026] [security2:error] [pid 157386:tid 157536] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.github/.env"] [unique_id "aoSDFU1jzAhYHVVT1WcC1QAAAR4"] [Tue Aug 18 13:06:45.053745 2026] [security2:error] [pid 157386:tid 157565] [client 20.226.36.136:52659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC2wAAATs"] [Tue Aug 18 13:06:45.056219 2026] [security2:error] [pid 157386:tid 157631] [client 20.116.17.175:20444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/water.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC3AAAAX0"] [Tue Aug 18 13:06:45.070385 2026] [security2:error] [pid 157386:tid 157602] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC3QAAAWA"] [Tue Aug 18 13:06:45.109712 2026] [security2:error] [pid 157386:tid 157576] [client 20.251.48.93:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/155.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC4wAAAUY"] [Tue Aug 18 13:06:45.138753 2026] [security2:error] [pid 157386:tid 157639] [client 168.62.48.100:18060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC5wAAAYU"] [Tue Aug 18 13:06:45.150742 2026] [security2:error] [pid 157386:tid 157598] [client 20.171.51.14:47111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/vd.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC6AAAAVw"] [Tue Aug 18 13:06:45.190362 2026] [security2:error] [pid 157386:tid 157587] [client 74.249.206.207:64552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/chris.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC6gAAAVE"] [Tue Aug 18 13:06:45.210942 2026] [security2:error] [pid 157386:tid 157498] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/bolt.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC6wABHG8"] [Tue Aug 18 13:06:45.221622 2026] [security2:error] [pid 157386:tid 157540] [client 20.124.247.79:16759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/aa.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC7AAAASI"] [Tue Aug 18 13:06:45.231808 2026] [security2:error] [pid 157386:tid 157638] [client 20.151.109.219:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ph.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC7QAAAYQ"] [Tue Aug 18 13:06:45.236570 2026] [security2:error] [pid 157386:tid 157538] [client 20.1.169.243:5003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/assetsalfa.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC7gAAASA"] [Tue Aug 18 13:06:45.275992 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/14.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC8wAAASY"] [Tue Aug 18 13:06:45.285999 2026] [security2:error] [pid 157386:tid 157582] [client 135.225.75.187:11609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ze.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC9AAAAUw"] [Tue Aug 18 13:06:45.292580 2026] [security2:error] [pid 157386:tid 157580] [client 20.1.169.243:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/randkeyword.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC9QAAAUo"] [Tue Aug 18 13:06:45.295554 2026] [security2:error] [pid 157386:tid 157570] [client 20.1.169.243:5340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/lite.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC9gAAAUA"] [Tue Aug 18 13:06:45.301361 2026] [security2:error] [pid 157386:tid 157604] [client 20.151.109.219:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/vbseo.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC9wAAAWI"] [Tue Aug 18 13:06:45.310669 2026] [security2:error] [pid 157386:tid 157537] [client 20.127.136.245:28284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/bthil.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC-AAAAR8"] [Tue Aug 18 13:06:45.318405 2026] [security2:error] [pid 157386:tid 157526] [client 74.248.130.103:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/img.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC-gAAARQ"] [Tue Aug 18 13:06:45.319856 2026] [security2:error] [pid 157386:tid 157642] [client 74.248.18.37:32460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-oembed.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC_AAAAYg"] [Tue Aug 18 13:06:45.361064 2026] [security2:error] [pid 157386:tid 157585] [client 158.158.74.177:9873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/languages.php"] [unique_id "aoSDFU1jzAhYHVVT1WcC_gAAAU8"] [Tue Aug 18 13:06:45.370748 2026] [security2:error] [pid 157386:tid 157557] [client 114.119.149.91:32419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bergoninf.com"] [uri "/lista/informatica/portateis-acessorios/pecas-partes-notebooks"] [unique_id "aoSDFU1jzAhYHVVT1WcC_wAAATM"], referer: https://www.bergoninf.com/lista/informatica/portateis-acessorios/pecas-partes-notebooks [Tue Aug 18 13:06:45.386199 2026] [security2:error] [pid 157386:tid 157539] [client 168.62.48.100:18161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDAAAAASE"] [Tue Aug 18 13:06:45.435688 2026] [security2:error] [pid 157386:tid 157455] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDAwABNEQ"] [Tue Aug 18 13:06:45.470058 2026] [security2:error] [pid 157386:tid 157551] [client 223.185.37.47:5208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDCQAAAS0"] [Tue Aug 18 13:06:45.470156 2026] [security2:error] [pid 157386:tid 157551] [client 223.185.37.47:5208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDCQAAAS0"] [Tue Aug 18 13:06:45.490605 2026] [security2:error] [pid 157386:tid 157628] [client 68.155.154.236:14296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDCgAAAXo"] [Tue Aug 18 13:06:45.501213 2026] [security2:error] [pid 157386:tid 157630] [client 20.25.139.174:4540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDCwAAAXw"] [Tue Aug 18 13:06:45.532071 2026] [security2:error] [pid 157386:tid 157531] [client 74.249.206.207:45029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/doc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDDQAAARk"] [Tue Aug 18 13:06:45.541554 2026] [security2:error] [pid 157386:tid 157609] [client 68.155.156.252:33495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.156.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "julio.multiveicular.org.br"] [uri "/g3.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDDgAAAWc"] [Tue Aug 18 13:06:45.545189 2026] [security2:error] [pid 157386:tid 157548] [client 20.79.204.6:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/sx.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDDwAAASo"] [Tue Aug 18 13:06:45.564291 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/mcs.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDEgAAAYc"] [Tue Aug 18 13:06:45.581359 2026] [security2:error] [pid 157386:tid 157542] [client 40.74.65.169:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/nope.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDEwAAASQ"] [Tue Aug 18 13:06:45.585940 2026] [security2:error] [pid 157386:tid 157602] [client 104.209.144.33:32643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDFAAAAWA"] [Tue Aug 18 13:06:45.602145 2026] [security2:error] [pid 157386:tid 157535] [client 20.1.169.243:5045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/init.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDFQAAAR0"] [Tue Aug 18 13:06:45.604372 2026] [security2:error] [pid 157386:tid 157407] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDFgABGhQ"] [Tue Aug 18 13:06:45.604576 2026] [security2:error] [pid 157386:tid 157532] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDFgABGhQ"] [Tue Aug 18 13:06:45.605047 2026] [security2:error] [pid 157386:tid 157424] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/php.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDFwABdSU"] [Tue Aug 18 13:06:45.608892 2026] [security2:error] [pid 157386:tid 157612] [client 20.251.48.93:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/ops.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDGQAAAWo"] [Tue Aug 18 13:06:45.619051 2026] [security2:error] [pid 157386:tid 157643] [client 20.151.109.219:21682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/sysinfo.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDHAAAAYk"] [Tue Aug 18 13:06:45.631798 2026] [security2:error] [pid 157386:tid 157639] [client 20.171.51.14:7886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/56.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDIQAAAYU"] [Tue Aug 18 13:06:45.648435 2026] [security2:error] [pid 157386:tid 157601] [client 168.62.48.100:18117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDIgAAAV8"] [Tue Aug 18 13:06:45.659080 2026] [security2:error] [pid 157386:tid 157536] [client 20.1.169.243:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/live.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDJgAAAR4"] [Tue Aug 18 13:06:45.660471 2026] [security2:error] [pid 157386:tid 157637] [client 20.124.247.79:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/img.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDJwAAAYM"] [Tue Aug 18 13:06:45.673892 2026] [security2:error] [pid 157386:tid 157581] [client 20.1.169.243:15911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/gebase.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDLAAAAUs"] [Tue Aug 18 13:06:45.685463 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/tk.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDLQAAATc"] [Tue Aug 18 13:06:45.688858 2026] [security2:error] [pid 157386:tid 157549] [client 20.226.36.136:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDLgAAASs"] [Tue Aug 18 13:06:45.694123 2026] [security2:error] [pid 157386:tid 157577] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/xiugai.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDMQAAAUc"] [Tue Aug 18 13:06:45.703196 2026] [security2:error] [pid 157386:tid 157540] [client 135.225.75.187:41256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/gjm.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDMgAAASI"] [Tue Aug 18 13:06:45.710512 2026] [security2:error] [pid 157386:tid 157629] [client 20.116.17.175:63553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/dk.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDNAAAAXs"] [Tue Aug 18 13:06:45.790387 2026] [security2:error] [pid 157386:tid 157522] [client 74.248.130.103:45642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/222.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDNwAAARA"] [Tue Aug 18 13:06:45.824097 2026] [security2:error] [pid 157386:tid 157599] [client 20.226.36.136:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDOQAAAV0"] [Tue Aug 18 13:06:45.841217 2026] [security2:error] [pid 157386:tid 157585] [client 20.116.17.175:20458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/fine.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDOwAAAU8"] [Tue Aug 18 13:06:45.913060 2026] [security2:error] [pid 157386:tid 157607] [client 20.151.109.219:21675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/ppinfo.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDPwAAAWU"] [Tue Aug 18 13:06:45.943684 2026] [security2:error] [pid 157386:tid 157614] [client 168.62.48.100:18144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDQQAAAWw"] [Tue Aug 18 13:06:45.963289 2026] [security2:error] [pid 157386:tid 157597] [client 20.1.169.243:5032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/bak.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDQgAAAVs"] [Tue Aug 18 13:06:45.966513 2026] [security2:error] [pid 157386:tid 157640] [client 20.124.247.79:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/222.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDRAAAAYY"] [Tue Aug 18 13:06:45.972561 2026] [security2:error] [pid 157386:tid 157627] [client 68.155.154.236:14308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDRQAAAXk"] [Tue Aug 18 13:06:45.987942 2026] [security2:error] [pid 157386:tid 157547] [client 213.35.127.232:55842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDFU1jzAhYHVVT1WcDRwAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:46.003375 2026] [security2:error] [pid 157386:tid 157449] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDSwABJD4"] [Tue Aug 18 13:06:46.015038 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:62958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/hp.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDTAAAATA"] [Tue Aug 18 13:06:46.016794 2026] [security2:error] [pid 157386:tid 157535] [client 74.249.206.207:32603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/1337.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDTQAAAR0"] [Tue Aug 18 13:06:46.021530 2026] [security2:error] [pid 157386:tid 157579] [client 20.1.169.243:5777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/bypass.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDTgAAAUk"] [Tue Aug 18 13:06:46.036280 2026] [security2:error] [pid 157386:tid 157532] [client 20.251.48.93:55333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/mac.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDUAAAARo"] [Tue Aug 18 13:06:46.039113 2026] [security2:error] [pid 157386:tid 157557] [client 20.25.139.174:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/atomlib.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDUQAAATM"] [Tue Aug 18 13:06:46.044899 2026] [security2:error] [pid 157386:tid 157625] [client 20.1.169.243:15970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/2008.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDUgAAAXc"] [Tue Aug 18 13:06:46.094336 2026] [security2:error] [pid 157386:tid 157595] [client 20.127.136.245:28016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/x.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDVQAAAVk"] [Tue Aug 18 13:06:46.121433 2026] [security2:error] [pid 157386:tid 157639] [client 135.225.75.187:31834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/new4.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDVgAAAYU"] [Tue Aug 18 13:06:46.132886 2026] [security2:error] [pid 157386:tid 157565] [client 20.171.51.14:33185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/rx.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDVwAAATs"] [Tue Aug 18 13:06:46.150629 2026] [security2:error] [pid 157386:tid 157525] [client 20.79.204.6:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDWAAAARM"] [Tue Aug 18 13:06:46.155356 2026] [security2:error] [pid 157386:tid 157603] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDFk1jzAhYHVVT1WcDWQAAAWE"] [Tue Aug 18 13:06:46.170269 2026] [security2:error] [pid 157386:tid 157389] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDWwABPwI"] [Tue Aug 18 13:06:46.180422 2026] [authz_core:error] [pid 157386:tid 157623] [client 192.178.4.134:47338] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:46.180885 2026] [authz_core:error] [pid 157386:tid 157623] [client 192.178.4.134:47338] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:46.186505 2026] [security2:error] [pid 157386:tid 157576] [client 52.173.121.69:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDXQAAAUY"] [Tue Aug 18 13:06:46.206667 2026] [security2:error] [pid 157386:tid 157553] [client 20.226.36.136:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDXgAAAS8"] [Tue Aug 18 13:06:46.208514 2026] [security2:error] [pid 157386:tid 157538] [client 20.104.100.201:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/options.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDXwAAASA"] [Tue Aug 18 13:06:46.236049 2026] [security2:error] [pid 157386:tid 157606] [client 158.158.74.177:20519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/nw.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDYAAAAWQ"] [Tue Aug 18 13:06:46.238701 2026] [security2:error] [pid 157386:tid 157544] [client 20.151.109.219:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/s.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDYQAAASY"] [Tue Aug 18 13:06:46.244997 2026] [security2:error] [pid 157386:tid 157615] [client 20.116.17.175:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/adminner.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDYgAAAW0"] [Tue Aug 18 13:06:46.251954 2026] [security2:error] [pid 157386:tid 157583] [client 20.215.241.237:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/inso.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDYwAAAU0"] [Tue Aug 18 13:06:46.266388 2026] [security2:error] [pid 157386:tid 157541] [client 40.74.65.169:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/new.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDZQAAASM"] [Tue Aug 18 13:06:46.271230 2026] [security2:error] [pid 157386:tid 157580] [client 74.248.130.103:57055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/key.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDZgAAAUo"] [Tue Aug 18 13:06:46.289869 2026] [security2:error] [pid 157386:tid 157562] [client 168.62.48.100:18140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDaQAAATg"] [Tue Aug 18 13:06:46.312246 2026] [security2:error] [pid 157386:tid 157387] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.github/.env"] [unique_id "aoSDFk1jzAhYHVVT1WcDawABPAA"] [Tue Aug 18 13:06:46.315714 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:46.316012 2026] [authz_core:error] [pid 157386:tid 157514] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:46.319616 2026] [security2:error] [pid 157386:tid 157521] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/wp-load.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDbAAAAQ8"] [Tue Aug 18 13:06:46.324489 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wx.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDbgAAARU"] [Tue Aug 18 13:06:46.326931 2026] [security2:error] [pid 157386:tid 157600] [client 20.1.169.243:4489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/bgymj.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDbwAAAV4"] [Tue Aug 18 13:06:46.327988 2026] [security2:error] [pid 157386:tid 157556] [client 68.155.154.236:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDcAAAATI"] [Tue Aug 18 13:06:46.332409 2026] [security2:error] [pid 157386:tid 157508] [remote 37.59.204.134:26074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSDFk1jzAhYHVVT1WcDdAABQnk"] [Tue Aug 18 13:06:46.332553 2026] [security2:error] [pid 157386:tid 157572] [client 37.59.204.134:26074] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/robots.txt"] [unique_id "aoSDFk1jzAhYHVVT1WcDdAABQnk"] [Tue Aug 18 13:06:46.337013 2026] [security2:error] [pid 157386:tid 157487] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/go.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDeAABLWQ"] [Tue Aug 18 13:06:46.357879 2026] [security2:error] [pid 157386:tid 157531] [client 74.248.18.37:32459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/allez.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDegAAARk"] [Tue Aug 18 13:06:46.363312 2026] [security2:error] [pid 157386:tid 157636] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDFk1jzAhYHVVT1WcDewAAAYI"] [Tue Aug 18 13:06:46.365805 2026] [security2:error] [pid 157386:tid 157628] [client 168.62.48.100:4183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDfAAAAXo"] [Tue Aug 18 13:06:46.369085 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:21680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/globals.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDfQAAAVA"] [Tue Aug 18 13:06:46.397951 2026] [security2:error] [pid 157386:tid 157613] [client 103.120.71.157:44429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDgQAAAWs"] [Tue Aug 18 13:06:46.398132 2026] [security2:error] [pid 157386:tid 157613] [client 103.120.71.157:44429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDgQAAAWs"] [Tue Aug 18 13:06:46.410143 2026] [security2:error] [pid 157386:tid 157624] [client 20.1.169.243:15583] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/c99.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDggAAAXY"] [Tue Aug 18 13:06:46.445756 2026] [security2:error] [pid 157386:tid 157554] [client 74.249.206.207:45012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/Njima.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDhQAAATA"] [Tue Aug 18 13:06:46.458887 2026] [security2:error] [pid 157386:tid 157590] [client 49.37.150.8:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDhwAAAVQ"] [Tue Aug 18 13:06:46.458996 2026] [security2:error] [pid 157386:tid 157590] [client 49.37.150.8:50739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDhwAAAVQ"] [Tue Aug 18 13:06:46.481954 2026] [security2:error] [pid 157386:tid 157539] [client 20.124.247.79:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/key.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDiAAAASE"] [Tue Aug 18 13:06:46.510961 2026] [security2:error] [pid 157386:tid 157639] [client 20.1.169.243:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/lock360.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDiwAAAYU"] [Tue Aug 18 13:06:46.551984 2026] [security2:error] [pid 157386:tid 157552] [client 20.116.17.175:45251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/bal.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDjgAAAS4"] [Tue Aug 18 13:06:46.555397 2026] [security2:error] [pid 157386:tid 157587] [client 135.225.75.187:31840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-act.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDjwAAAVE"] [Tue Aug 18 13:06:46.556951 2026] [security2:error] [pid 157386:tid 157603] [client 68.221.73.131:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-load.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDkQAAAWE"] [Tue Aug 18 13:06:46.586526 2026] [security2:error] [pid 157386:tid 157518] [client 168.62.48.100:18114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDkwAAAQw"] [Tue Aug 18 13:06:46.588830 2026] [security2:error] [pid 157386:tid 157564] [client 20.25.139.174:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/rip.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDlAAAATo"] [Tue Aug 18 13:06:46.591887 2026] [security2:error] [pid 157386:tid 157549] [client 20.226.36.136:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDlQAAASs"] [Tue Aug 18 13:06:46.624626 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:7410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/dj.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDmQAAASA"] [Tue Aug 18 13:06:46.691438 2026] [security2:error] [pid 157386:tid 157583] [client 20.116.17.175:20354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/loader.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDngAAAU0"] [Tue Aug 18 13:06:46.697254 2026] [security2:error] [pid 157386:tid 157570] [client 20.151.109.219:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/yindu.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDnwAAAUA"] [Tue Aug 18 13:06:46.717463 2026] [security2:error] [pid 157386:tid 157426] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/atomlib.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDogABOCc"] [Tue Aug 18 13:06:46.745256 2026] [security2:error] [pid 157386:tid 157576] [client 20.127.136.245:28244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/index/function.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDowAAAUY"] [Tue Aug 18 13:06:46.755248 2026] [security2:error] [pid 157386:tid 157600] [client 20.116.17.175:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/dragonshell.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDpQAAAV4"] [Tue Aug 18 13:06:46.781925 2026] [security2:error] [pid 157386:tid 157606] [client 20.1.169.243:15957] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/c99.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDqAAAAWQ"] [Tue Aug 18 13:06:46.802960 2026] [security2:error] [pid 157386:tid 157636] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/id_rsa"] [unique_id "aoSDFk1jzAhYHVVT1WcDqgAAAYI"] [Tue Aug 18 13:06:46.812095 2026] [security2:error] [pid 157386:tid 157592] [client 20.1.169.243:4502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDrAAAAVY"] [Tue Aug 18 13:06:46.816390 2026] [security2:error] [pid 157386:tid 157614] [client 68.155.154.236:14207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/first.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDrQAAAWw"] [Tue Aug 18 13:06:46.821891 2026] [security2:error] [pid 157386:tid 157613] [client 20.171.51.14:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mandrill.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDrgAAAWs"] [Tue Aug 18 13:06:46.840624 2026] [security2:error] [pid 157386:tid 157616] [client 104.209.144.33:32647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/weozh.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDrwAAAW4"] [Tue Aug 18 13:06:46.854333 2026] [security2:error] [pid 157386:tid 157547] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/id_dsa"] [unique_id "aoSDFk1jzAhYHVVT1WcDsAAAASk"] [Tue Aug 18 13:06:46.863438 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.36.136:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDsQAAAWc"] [Tue Aug 18 13:06:46.864491 2026] [security2:error] [pid 157386:tid 157568] [client 158.158.74.177:9303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDsgAAAT4"] [Tue Aug 18 13:06:46.865001 2026] [security2:error] [pid 157386:tid 157591] [client 52.173.121.69:38363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDswAAAVU"] [Tue Aug 18 13:06:46.867520 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ri.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDtAAAAUE"] [Tue Aug 18 13:06:46.873295 2026] [security2:error] [pid 157386:tid 157589] [client 74.248.130.103:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/chosen.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDtQAAAVM"] [Tue Aug 18 13:06:46.887528 2026] [security2:error] [pid 157386:tid 157615] [client 20.79.204.6:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDuAAAAW0"] [Tue Aug 18 13:06:46.888758 2026] [security2:error] [pid 157386:tid 157602] [client 20.151.109.219:20988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/uo.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDuQAAAWA"] [Tue Aug 18 13:06:46.919776 2026] [security2:error] [pid 157386:tid 157565] [client 222.124.191.185:57078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDvAAAATs"] [Tue Aug 18 13:06:46.919856 2026] [security2:error] [pid 157386:tid 157565] [client 222.124.191.185:57078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/main/xmlrpc.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDvAAAATs"] [Tue Aug 18 13:06:46.931742 2026] [security2:error] [pid 157386:tid 157590] [client 168.62.48.100:18052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDwAAAAVQ"] [Tue Aug 18 13:06:46.934179 2026] [security2:error] [pid 157386:tid 157543] [client 74.249.206.207:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDwQAAASU"] [Tue Aug 18 13:06:46.943641 2026] [security2:error] [pid 157386:tid 157642] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/155.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDwgAAAYg"] [Tue Aug 18 13:06:46.954286 2026] [security2:error] [pid 157386:tid 157625] [client 40.74.65.169:4292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/new.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDwwAAAXc"] [Tue Aug 18 13:06:46.973798 2026] [security2:error] [pid 157386:tid 157612] [client 20.124.247.79:16713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/chosen.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDxAAAAWo"] [Tue Aug 18 13:06:46.982545 2026] [security2:error] [pid 157386:tid 157548] [client 135.225.75.187:18664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/grsiuk.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDyAAAASo"] [Tue Aug 18 13:06:46.996683 2026] [security2:error] [pid 157386:tid 157601] [client 20.1.169.243:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSDFk1jzAhYHVVT1WcDzAAAAV8"] [Tue Aug 18 13:06:47.011413 2026] [security2:error] [pid 157386:tid 157544] [client 213.35.127.232:56101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDF01jzAhYHVVT1WcDzgAAASY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:47.024927 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:53196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/sxx.php"] [unique_id "aoSDF01jzAhYHVVT1WcDzwAAAS4"] [Tue Aug 18 13:06:47.029254 2026] [security2:error] [pid 157386:tid 157587] [client 20.251.48.93:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDF01jzAhYHVVT1WcD0AAAAVE"] [Tue Aug 18 13:06:47.048094 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:63283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fa.php"] [unique_id "aoSDF01jzAhYHVVT1WcD0gAAARM"] [Tue Aug 18 13:06:47.107952 2026] [security2:error] [pid 157386:tid 157463] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcD1wABNUw"] [Tue Aug 18 13:06:47.146767 2026] [security2:error] [pid 157386:tid 157637] [client 20.1.169.243:15993] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/c99.php"] [unique_id "aoSDF01jzAhYHVVT1WcD2wAAAYM"] [Tue Aug 18 13:06:47.164596 2026] [security2:error] [pid 157386:tid 157618] [client 20.226.36.136:62193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDF01jzAhYHVVT1WcD3AAAAXA"] [Tue Aug 18 13:06:47.167792 2026] [security2:error] [pid 157386:tid 157639] [client 20.25.139.174:4474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/p.php"] [unique_id "aoSDF01jzAhYHVVT1WcD3QAAAYU"] [Tue Aug 18 13:06:47.170453 2026] [security2:error] [pid 157386:tid 157522] [client 20.104.49.167:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDF01jzAhYHVVT1WcD3wAAARA"] [Tue Aug 18 13:06:47.178092 2026] [security2:error] [pid 157386:tid 157518] [client 20.1.169.243:5029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.caminhosdaregiao.com.br"] [uri "/class.php"] [unique_id "aoSDF01jzAhYHVVT1WcD4AAAAQw"] [Tue Aug 18 13:06:47.199676 2026] [security2:error] [pid 157386:tid 157632] [client 68.155.154.236:14200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcD4QAAAX4"] [Tue Aug 18 13:06:47.210972 2026] [security2:error] [pid 157386:tid 157521] [client 168.62.48.100:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDF01jzAhYHVVT1WcD4wAAAQ8"] [Tue Aug 18 13:06:47.215861 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:47.216111 2026] [authz_core:error] [pid 157386:tid 157466] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:47.239967 2026] [security2:error] [pid 157386:tid 157561] [client 51.116.232.28:2988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDF01jzAhYHVVT1WcD5QAAATc"] [Tue Aug 18 13:06:47.259267 2026] [security2:error] [pid 157386:tid 157524] [client 20.127.136.245:28275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/aaa.php"] [unique_id "aoSDF01jzAhYHVVT1WcD5gAAARI"] [Tue Aug 18 13:06:47.275058 2026] [security2:error] [pid 157386:tid 157450] [remote 4.223.113.180:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.foxalpha.com.br"] [uri "/1.php"] [unique_id "aoSDF01jzAhYHVVT1WcD6AABZT8"] [Tue Aug 18 13:06:47.275151 2026] [security2:error] [pid 157386:tid 157450] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/1.php"] [unique_id "aoSDF01jzAhYHVVT1WcD6AABZT8"] [Tue Aug 18 13:06:47.280998 2026] [security2:error] [pid 157386:tid 157558] [client 20.171.51.14:18645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/main.php"] [unique_id "aoSDF01jzAhYHVVT1WcD6QAAATQ"] [Tue Aug 18 13:06:47.319179 2026] [authz_core:error] [pid 157386:tid 157474] [remote 34.62.54.143:44828] AH01630: client denied by server configuration: /home2/natbrw01/uhequeimado.com.br/.htpasswd [Tue Aug 18 13:06:47.323748 2026] [security2:error] [pid 157386:tid 157520] [client 74.248.130.103:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/wpxml.php"] [unique_id "aoSDF01jzAhYHVVT1WcD7AAAAQ4"] [Tue Aug 18 13:06:47.349237 2026] [security2:error] [pid 157386:tid 157568] [client 74.249.206.207:64548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/too.php"] [unique_id "aoSDF01jzAhYHVVT1WcD7wAAAT4"] [Tue Aug 18 13:06:47.354277 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/fb.php"] [unique_id "aoSDF01jzAhYHVVT1WcD8wAAAWk"] [Tue Aug 18 13:06:47.354283 2026] [security2:error] [pid 157386:tid 157623] [client 74.248.18.37:32494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/colors/coffee/mailer.php"] [unique_id "aoSDF01jzAhYHVVT1WcD8gAAAXU"] [Tue Aug 18 13:06:47.358797 2026] [security2:error] [pid 157386:tid 157527] [client 20.1.169.243:5317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/pwnd/as.php"] [unique_id "aoSDF01jzAhYHVVT1WcD9AAAARU"] [Tue Aug 18 13:06:47.363892 2026] [security2:error] [pid 157386:tid 157589] [client 20.116.17.175:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/zero.php"] [unique_id "aoSDF01jzAhYHVVT1WcD9QAAAVM"] [Tue Aug 18 13:06:47.399119 2026] [security2:error] [pid 157386:tid 157590] [client 135.225.75.187:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/h.php"] [unique_id "aoSDF01jzAhYHVVT1WcD-gAAAVQ"] [Tue Aug 18 13:06:47.421658 2026] [security2:error] [pid 157386:tid 157625] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/key.pem"] [unique_id "aoSDF01jzAhYHVVT1WcD_AAAAXc"] [Tue Aug 18 13:06:47.444228 2026] [security2:error] [pid 157386:tid 157468] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSDF01jzAhYHVVT1WcEAAABZFE"] [Tue Aug 18 13:06:47.445068 2026] [security2:error] [pid 157386:tid 157516] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/privatekey.key"] [unique_id "aoSDF01jzAhYHVVT1WcD_wAAAQo"] [Tue Aug 18 13:06:47.465117 2026] [security2:error] [pid 157386:tid 157601] [client 20.151.109.219:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kx.php"] [unique_id "aoSDF01jzAhYHVVT1WcEAgAAAV8"] [Tue Aug 18 13:06:47.470201 2026] [security2:error] [pid 157386:tid 157585] [client 20.251.48.93:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSDF01jzAhYHVVT1WcEBAAAAU8"] [Tue Aug 18 13:06:47.473378 2026] [security2:error] [pid 157386:tid 157552] [client 168.62.48.100:18152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDF01jzAhYHVVT1WcEBQAAAS4"] [Tue Aug 18 13:06:47.501457 2026] [autoindex:error] [pid 157386:tid 157594] [client 158.158.74.177:9877] AH01276: Cannot serve directory /home1/llservicosnet/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:47.511156 2026] [security2:error] [pid 157386:tid 157565] [client 20.1.169.243:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/g3.php"] [unique_id "aoSDF01jzAhYHVVT1WcECgAAATs"] [Tue Aug 18 13:06:47.519294 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/settings.php"] [unique_id "aoSDF01jzAhYHVVT1WcECwAAAYA"] [Tue Aug 18 13:06:47.523084 2026] [security2:error] [pid 157386:tid 157540] [client 20.104.49.167:8664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDF01jzAhYHVVT1WcEDAAAASI"] [Tue Aug 18 13:06:47.537672 2026] [autoindex:error] [pid 157386:tid 157551] [client 20.79.204.6:12225] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:47.573922 2026] [security2:error] [pid 157386:tid 157541] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcEFAAAASM"] [Tue Aug 18 13:06:47.583034 2026] [security2:error] [pid 157386:tid 157580] [client 20.116.17.175:45268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/yawa.php"] [unique_id "aoSDF01jzAhYHVVT1WcEFgAAAUo"] [Tue Aug 18 13:06:47.610416 2026] [security2:error] [pid 157386:tid 157433] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSDF01jzAhYHVVT1WcEGAABFC4"] [Tue Aug 18 13:06:47.615391 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.36.136:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDF01jzAhYHVVT1WcEGQAAAQw"] [Tue Aug 18 13:06:47.626256 2026] [security2:error] [pid 157386:tid 157619] [client 20.124.247.79:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/wpxml.php"] [unique_id "aoSDF01jzAhYHVVT1WcEGwAAAXE"] [Tue Aug 18 13:06:47.644799 2026] [security2:error] [pid 157386:tid 157632] [client 51.116.232.28:2994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDF01jzAhYHVVT1WcEHAAAAX4"] [Tue Aug 18 13:06:47.651035 2026] [security2:error] [pid 157386:tid 157629] [client 20.151.109.219:39817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gw.php"] [unique_id "aoSDF01jzAhYHVVT1WcEHQAAAXs"] [Tue Aug 18 13:06:47.654390 2026] [security2:error] [pid 157386:tid 157578] [client 40.74.65.169:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/apreset.php"] [unique_id "aoSDF01jzAhYHVVT1WcEHgAAAUg"] [Tue Aug 18 13:06:47.683778 2026] [security2:error] [pid 157386:tid 157569] [client 68.155.154.236:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcEIAAAAT8"] [Tue Aug 18 13:06:47.695954 2026] [security2:error] [pid 157386:tid 157607] [client 20.104.85.180:5986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDF01jzAhYHVVT1WcEIQAAAWU"] [Tue Aug 18 13:06:47.706655 2026] [security2:error] [pid 157386:tid 157628] [client 20.226.36.136:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDF01jzAhYHVVT1WcEIwAAAXo"] [Tue Aug 18 13:06:47.707599 2026] [security2:error] [pid 157386:tid 157592] [client 20.171.51.14:9971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ga.php"] [unique_id "aoSDF01jzAhYHVVT1WcEJAAAAVY"] [Tue Aug 18 13:06:47.716480 2026] [security2:error] [pid 157386:tid 157621] [client 20.25.139.174:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.acassiocorretor.com.br"] [uri "/php.php"] [unique_id "aoSDF01jzAhYHVVT1WcEKAAAAXM"] [Tue Aug 18 13:06:47.717474 2026] [security2:error] [pid 157386:tid 157640] [client 158.158.74.177:9877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDF01jzAhYHVVT1WcEKQAAAYY"] [Tue Aug 18 13:06:47.722901 2026] [security2:error] [pid 157386:tid 157639] [client 20.1.169.243:5323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/rk2.php"] [unique_id "aoSDF01jzAhYHVVT1WcEKgAAAYU"] [Tue Aug 18 13:06:47.738551 2026] [security2:error] [pid 157386:tid 157573] [client 20.79.204.6:12225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcELAAAAUM"] [Tue Aug 18 13:06:47.761728 2026] [security2:error] [pid 157386:tid 157570] [client 74.248.130.103:40560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/file1221.php"] [unique_id "aoSDF01jzAhYHVVT1WcELQAAAUA"] [Tue Aug 18 13:06:47.765222 2026] [security2:error] [pid 157386:tid 157527] [client 74.249.206.207:44992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gramadoboutiqueeventos.com.br"] [uri "/g3.php"] [unique_id "aoSDF01jzAhYHVVT1WcELgAAARU"] [Tue Aug 18 13:06:47.778486 2026] [security2:error] [pid 157386:tid 157493] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/aaa.php"] [unique_id "aoSDF01jzAhYHVVT1WcEMAABYGo"] [Tue Aug 18 13:06:47.792360 2026] [security2:error] [pid 157386:tid 157547] [client 168.62.48.100:18008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDF01jzAhYHVVT1WcENwAAASk"] [Tue Aug 18 13:06:47.828596 2026] [security2:error] [pid 157386:tid 157617] [client 20.116.17.175:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/setup-config.php"] [unique_id "aoSDF01jzAhYHVVT1WcEOgAAAW8"] [Tue Aug 18 13:06:47.829620 2026] [security2:error] [pid 157386:tid 157617] [client 135.225.75.187:21456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/koiy.php"] [unique_id "aoSDF01jzAhYHVVT1WcEOwAAAW8"] [Tue Aug 18 13:06:47.870593 2026] [security2:error] [pid 157386:tid 157600] [client 20.127.136.245:28117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/abcd.php"] [unique_id "aoSDF01jzAhYHVVT1WcEPgAAAV4"] [Tue Aug 18 13:06:47.879351 2026] [security2:error] [pid 157386:tid 157597] [client 20.1.169.243:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/img/omar.php.png"] [unique_id "aoSDF01jzAhYHVVT1WcEPwAAAVs"] [Tue Aug 18 13:06:47.882320 2026] [security2:error] [pid 157386:tid 157610] [client 52.173.121.69:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDF01jzAhYHVVT1WcEQAAAAWg"] [Tue Aug 18 13:06:47.882820 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDF01jzAhYHVVT1WcEQQAAARk"] [Tue Aug 18 13:06:47.893488 2026] [security2:error] [pid 157386:tid 157606] [client 20.124.247.79:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/file1221.php"] [unique_id "aoSDF01jzAhYHVVT1WcEQgAAAWQ"] [Tue Aug 18 13:06:47.898580 2026] [security2:error] [pid 157386:tid 157516] [client 20.251.48.93:17061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/system_log.php"] [unique_id "aoSDF01jzAhYHVVT1WcERAAAAQo"] [Tue Aug 18 13:06:47.899394 2026] [security2:error] [pid 157386:tid 157604] [client 37.40.227.74:56853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDF01jzAhYHVVT1WcERQAAAWI"] [Tue Aug 18 13:06:47.899487 2026] [security2:error] [pid 157386:tid 157604] [client 37.40.227.74:56853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDF01jzAhYHVVT1WcERQAAAWI"] [Tue Aug 18 13:06:47.908481 2026] [security2:error] [pid 157386:tid 157484] [remote 142.44.228.69:56228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bjagricola.com.br"] [uri "/"] [unique_id "aoSDF01jzAhYHVVT1WcERgABU2E"] [Tue Aug 18 13:06:47.908596 2026] [security2:error] [pid 157386:tid 157589] [client 142.44.228.69:56228] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bjagricola.com.br"] [uri "/"] [unique_id "aoSDF01jzAhYHVVT1WcERgABU2E"] [Tue Aug 18 13:06:47.935422 2026] [security2:error] [pid 157386:tid 157453] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDF01jzAhYHVVT1WcESAABUUI"] [Tue Aug 18 13:06:47.940083 2026] [security2:error] [pid 157386:tid 157581] [client 68.221.73.131:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSDF01jzAhYHVVT1WcESQAAAUs"] [Tue Aug 18 13:06:47.977384 2026] [security2:error] [pid 157386:tid 157479] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/alfa.php"] [unique_id "aoSDF01jzAhYHVVT1WcESwABRFw"] [Tue Aug 18 13:06:47.987828 2026] [security2:error] [pid 157386:tid 157624] [client 20.226.36.136:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDF01jzAhYHVVT1WcETgAAAXY"] [Tue Aug 18 13:06:47.989092 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:46402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/sw.php"] [unique_id "aoSDF01jzAhYHVVT1WcETwAAASA"] [Tue Aug 18 13:06:48.003797 2026] [security2:error] [pid 157386:tid 157541] [client 20.118.133.132:61347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/m.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEVQAAASM"] [Tue Aug 18 13:06:48.031299 2026] [security2:error] [pid 157386:tid 157524] [client 213.35.127.232:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEWAAAARI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:48.047503 2026] [security2:error] [pid 157386:tid 157586] [client 51.116.232.28:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/media.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEXAAAAVA"] [Tue Aug 18 13:06:48.061973 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.85.180:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEXQAAAX4"] [Tue Aug 18 13:06:48.085275 2026] [security2:error] [pid 157386:tid 157521] [client 168.62.48.100:18028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEYAAAAQ8"] [Tue Aug 18 13:06:48.085731 2026] [security2:error] [pid 157386:tid 157620] [client 20.1.169.243:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEYQAAAXI"] [Tue Aug 18 13:06:48.096871 2026] [security2:error] [pid 157386:tid 157578] [client 20.151.109.219:17564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/spip.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEYgAAAUg"] [Tue Aug 18 13:06:48.131214 2026] [security2:error] [pid 157386:tid 157561] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDGE1jzAhYHVVT1WcEZQAAATc"] [Tue Aug 18 13:06:48.134493 2026] [security2:error] [pid 157386:tid 157584] [client 20.171.51.14:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wb.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEZgAAAU4"] [Tue Aug 18 13:06:48.137591 2026] [security2:error] [pid 157386:tid 157568] [client 222.124.191.185:36096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEZwAAAT4"] [Tue Aug 18 13:06:48.137678 2026] [security2:error] [pid 157386:tid 157568] [client 222.124.191.185:36096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEZwAAAT4"] [Tue Aug 18 13:06:48.144683 2026] [security2:error] [pid 157386:tid 157418] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEaAABQh8"] [Tue Aug 18 13:06:48.149543 2026] [security2:error] [pid 157386:tid 157607] [client 68.155.154.236:14244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEaQAAAWU"] [Tue Aug 18 13:06:48.162972 2026] [security2:error] [pid 157386:tid 157592] [client 20.124.247.79:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/nox.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEawAAAVY"] [Tue Aug 18 13:06:48.165508 2026] [security2:error] [pid 157386:tid 157558] [client 20.226.36.136:52617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEbAAAATQ"] [Tue Aug 18 13:06:48.178462 2026] [security2:error] [pid 157386:tid 157614] [client 20.104.49.167:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEbgAAAWw"] [Tue Aug 18 13:06:48.198073 2026] [security2:error] [pid 157386:tid 157640] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/aaa.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEbwAAAYY"] [Tue Aug 18 13:06:48.205896 2026] [security2:error] [pid 157386:tid 157591] [client 20.116.17.175:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/002.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEcwAAAVU"] [Tue Aug 18 13:06:48.209098 2026] [security2:error] [pid 157386:tid 157570] [client 20.215.241.237:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/aa.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEdAAAAUA"] [Tue Aug 18 13:06:48.240952 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:20725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/va.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEdQAAAWk"] [Tue Aug 18 13:06:48.249111 2026] [security2:error] [pid 157386:tid 157567] [client 135.225.75.187:11338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fff.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEdgAAAT0"] [Tue Aug 18 13:06:48.249358 2026] [security2:error] [pid 157386:tid 157602] [client 74.248.130.103:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/nox.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEdwAAAWA"] [Tue Aug 18 13:06:48.266824 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:21901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/tp.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEeQAAATA"] [Tue Aug 18 13:06:48.276267 2026] [security2:error] [pid 157386:tid 157575] [client 20.1.169.243:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEegAAAUU"] [Tue Aug 18 13:06:48.276346 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.36.136:61500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEewAAAVQ"] [Tue Aug 18 13:06:48.282518 2026] [security2:error] [pid 157386:tid 157617] [client 20.151.109.219:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gc.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEfAAAAW8"] [Tue Aug 18 13:06:48.312804 2026] [security2:error] [pid 157386:tid 157461] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/sf.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEfgABPEo"] [Tue Aug 18 13:06:48.339287 2026] [security2:error] [pid 157386:tid 157622] [client 158.158.74.177:20515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEfwAAAXQ"] [Tue Aug 18 13:06:48.348929 2026] [security2:error] [pid 157386:tid 157610] [client 40.74.65.169:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/1mage.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEgQAAAWg"] [Tue Aug 18 13:06:48.363507 2026] [security2:error] [pid 157386:tid 157531] [client 168.62.48.100:18057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEhAAAARk"] [Tue Aug 18 13:06:48.378476 2026] [security2:error] [pid 157386:tid 157527] [client 20.127.136.245:28224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-good.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEhwAAARU"] [Tue Aug 18 13:06:48.389109 2026] [autoindex:error] [pid 157386:tid 157569] [client 20.79.204.6:11525] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:48.396837 2026] [security2:error] [pid 157386:tid 157633] [client 20.226.36.136:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEiQAAAX8"] [Tue Aug 18 13:06:48.418014 2026] [security2:error] [pid 157386:tid 157587] [client 20.104.85.180:5955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/admin.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEiwAAAVE"] [Tue Aug 18 13:06:48.449262 2026] [security2:error] [pid 157386:tid 157600] [client 20.1.169.243:5813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/tool.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEjwAAAV4"] [Tue Aug 18 13:06:48.449960 2026] [security2:error] [pid 157386:tid 157549] [client 51.116.232.28:2653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/admin.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEkAAAASs"] [Tue Aug 18 13:06:48.460687 2026] [security2:error] [pid 157386:tid 157551] [client 20.116.17.175:22603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEkQAAAS0"] [Tue Aug 18 13:06:48.462223 2026] [security2:error] [pid 157386:tid 157559] [client 20.226.36.136:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEkgAAATU"] [Tue Aug 18 13:06:48.488830 2026] [security2:error] [pid 157386:tid 157580] [client 20.124.247.79:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/akismet.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEkwAAAUo"] [Tue Aug 18 13:06:48.497240 2026] [security2:error] [pid 157386:tid 157618] [client 104.209.144.33:31281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/rymmm.php"] [unique_id "aoSDGE1jzAhYHVVT1WcElAAAAXA"] [Tue Aug 18 13:06:48.503460 2026] [security2:error] [pid 157386:tid 157470] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/file56.php"] [unique_id "aoSDGE1jzAhYHVVT1WcElgABEFM"] [Tue Aug 18 13:06:48.536620 2026] [security2:error] [pid 157386:tid 157635] [client 74.248.18.37:40335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/teslav.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEmgAAAYE"] [Tue Aug 18 13:06:48.542504 2026] [security2:error] [pid 157386:tid 157634] [client 20.226.36.136:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEmwAAAYA"] [Tue Aug 18 13:06:48.569126 2026] [security2:error] [pid 157386:tid 157576] [client 20.226.36.136:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEoAAAAUY"] [Tue Aug 18 13:06:48.589684 2026] [security2:error] [pid 157386:tid 157536] [client 20.79.204.6:11525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEpAAAAR4"] [Tue Aug 18 13:06:48.596386 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:49319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/uq.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEpQAAATc"] [Tue Aug 18 13:06:48.626220 2026] [security2:error] [pid 157386:tid 157572] [client 20.171.51.14:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/xn.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEpwAAAUI"] [Tue Aug 18 13:06:48.630758 2026] [security2:error] [pid 157386:tid 157588] [client 20.226.36.136:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEqgAAAVI"] [Tue Aug 18 13:06:48.631339 2026] [security2:error] [pid 157386:tid 157391] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDGE1jzAhYHVVT1WcEqQABegQ"] [Tue Aug 18 13:06:48.640395 2026] [security2:error] [pid 157386:tid 157614] [client 168.62.48.100:18096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEqwAAAWw"] [Tue Aug 18 13:06:48.643599 2026] [security2:error] [pid 157386:tid 157579] [client 20.1.169.243:15704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/inputs.php"] [unique_id "aoSDGE1jzAhYHVVT1WcErAAAAUk"] [Tue Aug 18 13:06:48.644179 2026] [security2:error] [pid 157386:tid 157640] [client 20.116.17.175:20475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/zxz.php"] [unique_id "aoSDGE1jzAhYHVVT1WcErQAAAYY"] [Tue Aug 18 13:06:48.660332 2026] [security2:error] [pid 157386:tid 157609] [client 68.155.154.236:14330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/blog/byp.php"] [unique_id "aoSDGE1jzAhYHVVT1WcErwAAAWc"] [Tue Aug 18 13:06:48.664860 2026] [security2:error] [pid 157386:tid 157591] [client 135.225.75.187:41233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/pouhg.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEsQAAAVU"] [Tue Aug 18 13:06:48.668231 2026] [authz_core:error] [pid 157386:tid 157427] [remote 57.141.22.48:36526] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:48.668488 2026] [authz_core:error] [pid 157386:tid 157427] [remote 57.141.22.48:36526] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:48.675474 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:21689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/search.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEsgAAAXU"] [Tue Aug 18 13:06:48.683797 2026] [security2:error] [pid 157386:tid 157567] [client 20.226.36.136:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEswAAAT0"] [Tue Aug 18 13:06:48.696740 2026] [security2:error] [pid 157386:tid 157554] [client 74.248.130.103:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/akismet.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEtAAAATA"] [Tue Aug 18 13:06:48.712404 2026] [security2:error] [pid 157386:tid 157617] [client 20.226.36.136:61450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEtgAAAW8"] [Tue Aug 18 13:06:48.716901 2026] [security2:error] [pid 157386:tid 157612] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDGE1jzAhYHVVT1WcEuAAAAWo"] [Tue Aug 18 13:06:48.727753 2026] [security2:error] [pid 157386:tid 157435] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/2.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEugABPDA"] [Tue Aug 18 13:06:48.738099 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.85.180:5989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/public/css.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEuwAAAVs"] [Tue Aug 18 13:06:48.743424 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEvQAAARk"] [Tue Aug 18 13:06:48.762441 2026] [security2:error] [pid 157386:tid 157527] [client 20.124.247.79:16650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/admin.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEvgAAARU"] [Tue Aug 18 13:06:48.798454 2026] [security2:error] [pid 157386:tid 157627] [client 20.226.36.136:52655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEvwAAAXk"] [Tue Aug 18 13:06:48.817413 2026] [security2:error] [pid 157386:tid 157587] [client 20.251.48.93:26363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/pucci.php"] [unique_id "aoSDGE1jzAhYHVVT1WcExAAAAVE"] [Tue Aug 18 13:06:48.820381 2026] [security2:error] [pid 157386:tid 157590] [client 20.1.169.243:5359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/twentytwenty/functions.php"] [unique_id "aoSDGE1jzAhYHVVT1WcExwAAAVQ"] [Tue Aug 18 13:06:48.824701 2026] [security2:error] [pid 157386:tid 157544] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEyAAAASY"] [Tue Aug 18 13:06:48.840305 2026] [security2:error] [pid 157386:tid 157600] [client 20.226.36.136:62195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEywAAAV4"] [Tue Aug 18 13:06:48.852933 2026] [security2:error] [pid 157386:tid 157624] [client 51.116.232.28:2975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/mac.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEzQAAAXY"] [Tue Aug 18 13:06:48.855775 2026] [security2:error] [pid 157386:tid 157538] [client 20.226.36.136:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEzgAAASA"] [Tue Aug 18 13:06:48.864591 2026] [security2:error] [pid 157386:tid 157559] [client 20.116.17.175:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/f35.update.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEzwAAATU"] [Tue Aug 18 13:06:48.871139 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.36.136:52609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE0AAAAWM"] [Tue Aug 18 13:06:48.894852 2026] [security2:error] [pid 157386:tid 157449] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE0QABLD4"] [Tue Aug 18 13:06:48.899188 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.36.136:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE0gAAAVA"] [Tue Aug 18 13:06:48.912499 2026] [security2:error] [pid 157386:tid 157642] [client 168.62.48.100:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE1AAAAYg"] [Tue Aug 18 13:06:48.922077 2026] [security2:error] [pid 157386:tid 157540] [client 20.116.17.175:20417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE1QAAASI"] [Tue Aug 18 13:06:48.925759 2026] [security2:error] [pid 157386:tid 157629] [client 52.173.121.69:58192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE1gAAAXs"] [Tue Aug 18 13:06:48.928080 2026] [security2:error] [pid 157386:tid 157521] [client 20.226.36.136:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE1wAAAQ8"] [Tue Aug 18 13:06:48.934014 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/32.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE2AAAAWE"] [Tue Aug 18 13:06:48.955096 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.36.136:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE2QAAAS4"] [Tue Aug 18 13:06:48.969099 2026] [security2:error] [pid 157386:tid 157539] [client 158.158.74.177:20505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/f7.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE2gAAASE"] [Tue Aug 18 13:06:48.996792 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/build.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE3AAAATc"] [Tue Aug 18 13:06:48.998732 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.36.136:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDGE1jzAhYHVVT1WcE3QAAAQw"] [Tue Aug 18 13:06:49.009454 2026] [security2:error] [pid 157386:tid 157618] [client 20.1.169.243:15964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/layout.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE3wAAAXA"] [Tue Aug 18 13:06:49.013672 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:5966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE4AAAAVY"] [Tue Aug 18 13:06:49.028948 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:49.029215 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:49.046097 2026] [security2:error] [pid 157386:tid 157520] [client 20.124.247.79:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/ajax.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE5QAAAQ4"] [Tue Aug 18 13:06:49.046906 2026] [security2:error] [pid 157386:tid 157641] [client 20.226.36.136:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE5gAAAYc"] [Tue Aug 18 13:06:49.047770 2026] [security2:error] [pid 157386:tid 157534] [client 213.35.127.232:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE5wAAARw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:49.049570 2026] [security2:error] [pid 157386:tid 157639] [client 40.74.65.169:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/imsc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE6AAAAYU"] [Tue Aug 18 13:06:49.049683 2026] [security2:error] [pid 157386:tid 157573] [client 20.116.17.175:45248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/7.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE6QAAAUM"] [Tue Aug 18 13:06:49.050290 2026] [security2:error] [pid 157386:tid 157609] [client 158.23.17.4:63006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mz.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE6gAAAWc"] [Tue Aug 18 13:06:49.063412 2026] [security2:error] [pid 157386:tid 157456] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE6wABdUU"] [Tue Aug 18 13:06:49.080497 2026] [security2:error] [pid 157386:tid 157630] [client 135.225.75.187:41250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/moon3.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE-wAAAXw"] [Tue Aug 18 13:06:49.086891 2026] [security2:error] [pid 157386:tid 157547] [client 20.226.36.136:62200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDGU1jzAhYHVVT1WcE_wAAASk"] [Tue Aug 18 13:06:49.087750 2026] [security2:error] [pid 157386:tid 157575] [client 20.104.49.167:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFAAAAAUU"] [Tue Aug 18 13:06:49.105364 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.36.136:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFBAAAAXQ"] [Tue Aug 18 13:06:49.117000 2026] [security2:error] [pid 157386:tid 157606] [client 68.155.154.236:14083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFBwAAAWQ"] [Tue Aug 18 13:06:49.117015 2026] [security2:error] [pid 157386:tid 157604] [client 74.248.130.103:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/admin.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFCQAAAWI"] [Tue Aug 18 13:06:49.117062 2026] [security2:error] [pid 157386:tid 157610] [client 68.221.73.131:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/aaa.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFCAAAAWg"] [Tue Aug 18 13:06:49.165922 2026] [security2:error] [pid 157386:tid 157631] [client 168.62.48.100:18132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFHAAAAX0"] [Tue Aug 18 13:06:49.179782 2026] [security2:error] [pid 157386:tid 157530] [client 102.213.179.104:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFIgAAARg"] [Tue Aug 18 13:06:49.179866 2026] [security2:error] [pid 157386:tid 157530] [client 102.213.179.104:52703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFIgAAARg"] [Tue Aug 18 13:06:49.182135 2026] [security2:error] [pid 157386:tid 157538] [client 20.226.36.136:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFIwAAASA"] [Tue Aug 18 13:06:49.183550 2026] [security2:error] [pid 157386:tid 157591] [client 20.1.169.243:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-admin.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFJQAAAVU"] [Tue Aug 18 13:06:49.187651 2026] [security2:error] [pid 157386:tid 157615] [client 20.151.109.219:27773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/zj.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFJwAAAW0"] [Tue Aug 18 13:06:49.198763 2026] [security2:error] [pid 157386:tid 157583] [client 20.79.204.6:11574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFKQAAAU0"] [Tue Aug 18 13:06:49.228988 2026] [security2:error] [pid 157386:tid 157430] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/dav.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFMgABiCs"] [Tue Aug 18 13:06:49.243644 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/73.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFNAAAATo"] [Tue Aug 18 13:06:49.256244 2026] [security2:error] [pid 157386:tid 157576] [client 51.116.232.28:2991] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/1.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFNwAAAUY"] [Tue Aug 18 13:06:49.256340 2026] [security2:error] [pid 157386:tid 157576] [client 51.116.232.28:2991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/1.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFNwAAAUY"] [Tue Aug 18 13:06:49.264625 2026] [security2:error] [pid 157386:tid 157539] [client 20.116.17.175:20317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/aa.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFOgAAASE"] [Tue Aug 18 13:06:49.301460 2026] [security2:error] [pid 157386:tid 157518] [client 20.104.85.180:6014] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/block-supports/"] [unique_id "aoSDGU1jzAhYHVVT1WcFPQAAAQw"] [Tue Aug 18 13:06:49.315421 2026] [security2:error] [pid 157386:tid 157621] [client 78.46.215.1:2438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alcorseguros.com.br"] [uri "/index.php"] [unique_id "aoSDGE1jzAhYHVVT1WcEhQAAAXM"], referer: https://www.alcorseguros.com.br [Tue Aug 18 13:06:49.315959 2026] [security2:error] [pid 157386:tid 157592] [client 20.171.51.14:38729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/47.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFPgAAAVY"] [Tue Aug 18 13:06:49.316463 2026] [security2:error] [pid 157386:tid 157581] [client 149.34.210.141:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFPwAAAUs"] [Tue Aug 18 13:06:49.318756 2026] [security2:error] [pid 157386:tid 157553] [client 104.209.144.33:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/lddxs.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFQAAAAS8"] [Tue Aug 18 13:06:49.335664 2026] [security2:error] [pid 157386:tid 157641] [client 20.124.247.79:16648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/abe.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFQgAAAYc"] [Tue Aug 18 13:06:49.365185 2026] [security2:error] [pid 157386:tid 157525] [client 222.124.191.185:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFRAAAARM"] [Tue Aug 18 13:06:49.365294 2026] [security2:error] [pid 157386:tid 157525] [client 222.124.191.185:36112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFRAAAARM"] [Tue Aug 18 13:06:49.405010 2026] [security2:error] [pid 157386:tid 157542] [client 20.151.109.219:53244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/defaul.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFSQAAASQ"] [Tue Aug 18 13:06:49.407222 2026] [security2:error] [pid 157386:tid 157547] [client 168.62.48.100:18048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFSgAAASk"] [Tue Aug 18 13:06:49.420786 2026] [security2:error] [pid 157386:tid 157628] [client 20.127.136.245:28120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/simple.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFTAAAAXo"] [Tue Aug 18 13:06:49.443799 2026] [security2:error] [pid 157386:tid 157436] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/wp_wol.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFTgABPDE"] [Tue Aug 18 13:06:49.453576 2026] [security2:error] [pid 157386:tid 157531] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/site.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFUAAAARk"] [Tue Aug 18 13:06:49.495372 2026] [security2:error] [pid 157386:tid 157578] [client 20.226.36.136:65315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFUgAAAUg"] [Tue Aug 18 13:06:49.498284 2026] [security2:error] [pid 157386:tid 157527] [client 135.225.75.187:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/opts.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFUwAAARU"] [Tue Aug 18 13:06:49.525819 2026] [security2:error] [pid 157386:tid 157611] [client 20.250.13.23:33141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/NewFile.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFVwAAAWk"] [Tue Aug 18 13:06:49.538210 2026] [security2:error] [pid 157386:tid 157631] [client 20.1.169.243:15608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/text.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFWAAAAX0"] [Tue Aug 18 13:06:49.546625 2026] [security2:error] [pid 157386:tid 157543] [client 20.1.169.243:5786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFWgAAASU"] [Tue Aug 18 13:06:49.573690 2026] [security2:error] [pid 157386:tid 157624] [client 68.155.154.236:14178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFXgAAAXY"] [Tue Aug 18 13:06:49.580316 2026] [security2:error] [pid 157386:tid 157469] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_rsa"] [unique_id "aoSDGU1jzAhYHVVT1WcFXwABXlI"] [Tue Aug 18 13:06:49.583225 2026] [security2:error] [pid 157386:tid 157465] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/id_dsa"] [unique_id "aoSDGU1jzAhYHVVT1WcFYAABGE4"] [Tue Aug 18 13:06:49.594475 2026] [security2:error] [pid 157386:tid 157581] [client 149.34.210.141:63106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFPwAAAUs"] [Tue Aug 18 13:06:49.608278 2026] [security2:error] [pid 157386:tid 157551] [client 20.151.109.219:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ib.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFYwAAAS0"] [Tue Aug 18 13:06:49.621239 2026] [security2:error] [pid 157386:tid 157605] [client 20.124.247.79:16764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/bs1.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFZAAAAWM"] [Tue Aug 18 13:06:49.621699 2026] [security2:error] [pid 157386:tid 157615] [client 74.248.130.103:42415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.hostlig.solutions"] [uri "/ajax.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFZQAAAW0"] [Tue Aug 18 13:06:49.635806 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.85.180:6020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFaQAAAWA"] [Tue Aug 18 13:06:49.636715 2026] [security2:error] [pid 157386:tid 157532] [client 158.158.74.177:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/photo.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFagAAARo"] [Tue Aug 18 13:06:49.647056 2026] [security2:error] [pid 157386:tid 157522] [client 168.62.48.100:18071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/rezor.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFawAAARA"] [Tue Aug 18 13:06:49.654189 2026] [security2:error] [pid 157386:tid 157601] [client 20.116.17.175:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/echkm.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFbAAAAV8"] [Tue Aug 18 13:06:49.665901 2026] [security2:error] [pid 157386:tid 157580] [client 51.116.232.28:3000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/coffee.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFbQAAAUo"] [Tue Aug 18 13:06:49.675606 2026] [security2:error] [pid 157386:tid 157475] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/fm2.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFbgABLFg"] [Tue Aug 18 13:06:49.719188 2026] [security2:error] [pid 157386:tid 157594] [client 168.62.48.100:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFcQAAAVg"] [Tue Aug 18 13:06:49.721249 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/bdroot.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFcwAAAXE"] [Tue Aug 18 13:06:49.732179 2026] [security2:error] [pid 157386:tid 157564] [client 20.251.48.93:53417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFdAAAATo"] [Tue Aug 18 13:06:49.749778 2026] [security2:error] [pid 157386:tid 157616] [client 40.74.65.169:4858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFeAAAAW4"] [Tue Aug 18 13:06:49.751661 2026] [security2:error] [pid 157386:tid 157599] [client 213.202.253.4:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFeQAAAV0"], referer: www.google.com [Tue Aug 18 13:06:49.781176 2026] [security2:error] [pid 157386:tid 157621] [client 20.226.36.136:65317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFfAAAAXM"] [Tue Aug 18 13:06:49.781541 2026] [security2:error] [pid 157386:tid 157592] [client 20.171.51.14:9935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/payout.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFfQAAAVY"] [Tue Aug 18 13:06:49.791814 2026] [security2:error] [pid 157386:tid 157562] [client 20.116.17.175:22550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ws77.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFfgAAATg"] [Tue Aug 18 13:06:49.805840 2026] [security2:error] [pid 157386:tid 157535] [client 20.79.204.6:11653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFgAAAAR0"] [Tue Aug 18 13:06:49.822708 2026] [security2:error] [pid 157386:tid 157591] [client 74.248.18.37:40349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/plugin.js.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFggAAAVU"] [Tue Aug 18 13:06:49.823681 2026] [security2:error] [pid 157386:tid 157525] [client 104.209.144.33:32663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/zjggu.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFgwAAARM"] [Tue Aug 18 13:06:49.826683 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:12866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/twin.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFhAAAAUM"] [Tue Aug 18 13:06:49.872019 2026] [security2:error] [pid 157386:tid 157504] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSDGU1jzAhYHVVT1WcFhQABdXU"] [Tue Aug 18 13:06:49.899847 2026] [security2:error] [pid 157386:tid 157618] [client 20.1.169.243:15798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/tmp/.phpEsretb_zablokowane"] [unique_id "aoSDGU1jzAhYHVVT1WcFiAAAAXA"] [Tue Aug 18 13:06:49.899945 2026] [security2:error] [pid 157386:tid 157595] [client 168.62.48.100:18061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFiQAAAVk"] [Tue Aug 18 13:06:49.908917 2026] [authz_core:error] [pid 157386:tid 157466] [remote 57.141.22.6:60218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:49.909159 2026] [authz_core:error] [pid 157386:tid 157466] [remote 57.141.22.6:60218] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:49.909793 2026] [security2:error] [pid 157386:tid 157628] [client 20.151.109.219:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fo.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFjwAAAXo"] [Tue Aug 18 13:06:49.920517 2026] [security2:error] [pid 157386:tid 157566] [client 135.225.75.187:18661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/zwq13.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFkAAAATw"] [Tue Aug 18 13:06:49.929347 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:49.929624 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:49.943953 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.85.180:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/gelay.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFkgAAARk"] [Tue Aug 18 13:06:49.987598 2026] [security2:error] [pid 157386:tid 157627] [client 68.155.154.236:14322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vooo.3xsolutions.com"] [uri "/images/security.php"] [unique_id "aoSDGU1jzAhYHVVT1WcFlwAAAXk"] [Tue Aug 18 13:06:50.015532 2026] [security2:error] [pid 157386:tid 157637] [client 20.151.109.219:63255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xm.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFmgAAAYM"] [Tue Aug 18 13:06:50.017824 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:10596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/x.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFnAAAAVE"] [Tue Aug 18 13:06:50.025756 2026] [security2:error] [pid 157386:tid 157620] [client 20.124.247.79:16767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/yes.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFnQAAAXI"] [Tue Aug 18 13:06:50.068387 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFnwAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:50.075180 2026] [security2:error] [pid 157386:tid 157534] [client 51.116.232.28:2668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFoQAAARw"] [Tue Aug 18 13:06:50.075841 2026] [security2:error] [pid 157386:tid 157412] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/key.pem"] [unique_id "aoSDGk1jzAhYHVVT1WcFoAABJRk"] [Tue Aug 18 13:06:50.078899 2026] [security2:error] [pid 157386:tid 157614] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/ccc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFogAAAWw"] [Tue Aug 18 13:06:50.114073 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/domvf.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFpgAAAUs"] [Tue Aug 18 13:06:50.131746 2026] [security2:error] [pid 157386:tid 157569] [client 20.127.136.245:28280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/edit-tags.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFpwAAAT8"] [Tue Aug 18 13:06:50.142361 2026] [security2:error] [pid 157386:tid 157583] [client 168.62.48.100:17985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFqAAAAU0"] [Tue Aug 18 13:06:50.151938 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFqQAAARA"] [Tue Aug 18 13:06:50.202654 2026] [security2:error] [pid 157386:tid 157550] [client 104.209.144.33:32701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/dlvqo.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFqwAAASw"] [Tue Aug 18 13:06:50.215704 2026] [security2:error] [pid 157386:tid 157607] [client 68.221.73.131:50477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/gecko.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFrAAAAWU"] [Tue Aug 18 13:06:50.216391 2026] [security2:error] [pid 157386:tid 157520] [client 52.173.121.69:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFrQAAAQ4"] [Tue Aug 18 13:06:50.219442 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/new2.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFrgAAAYA"] [Tue Aug 18 13:06:50.249845 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.85.180:6001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFsQAAAQ8"] [Tue Aug 18 13:06:50.254545 2026] [security2:error] [pid 157386:tid 157564] [client 20.251.48.93:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFsgAAATo"] [Tue Aug 18 13:06:50.266707 2026] [security2:error] [pid 157386:tid 157602] [client 20.1.169.243:15968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/upload.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFtgAAAWA"] [Tue Aug 18 13:06:50.275878 2026] [security2:error] [pid 157386:tid 157584] [client 20.171.51.14:12082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/bh.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFtwAAAU4"] [Tue Aug 18 13:06:50.287423 2026] [security2:error] [pid 157386:tid 157545] [client 158.158.74.177:24970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-aa.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFuwAAASc"] [Tue Aug 18 13:06:50.301985 2026] [security2:error] [pid 157386:tid 157642] [client 20.226.36.136:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/rezor.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFvAAAAYg"] [Tue Aug 18 13:06:50.315853 2026] [security2:error] [pid 157386:tid 157399] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/privatekey.key"] [unique_id "aoSDGk1jzAhYHVVT1WcFvgABhww"] [Tue Aug 18 13:06:50.338872 2026] [security2:error] [pid 157386:tid 157461] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/gebase.php69"] [unique_id "aoSDGk1jzAhYHVVT1WcFvwABRko"] [Tue Aug 18 13:06:50.345900 2026] [security2:error] [pid 157386:tid 157549] [client 157.20.138.62:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFwQAAASs"] [Tue Aug 18 13:06:50.346015 2026] [security2:error] [pid 157386:tid 157549] [client 157.20.138.62:51037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFwQAAASs"] [Tue Aug 18 13:06:50.363404 2026] [security2:error] [pid 157386:tid 157609] [client 135.225.75.187:41224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/Okxob.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFxAAAAWc"] [Tue Aug 18 13:06:50.373742 2026] [security2:error] [pid 157386:tid 157561] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/laravel/.env"] [unique_id "aoSDGk1jzAhYHVVT1WcFxgAAATc"] [Tue Aug 18 13:06:50.379138 2026] [security2:error] [pid 157386:tid 157539] [client 20.124.247.79:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/go.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFxwAAASE"] [Tue Aug 18 13:06:50.386359 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/zy.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFywAAAXU"] [Tue Aug 18 13:06:50.395637 2026] [security2:error] [pid 157386:tid 157618] [client 20.226.36.136:62206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/uploads/bypass.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFzAAAAXA"] [Tue Aug 18 13:06:50.400210 2026] [security2:error] [pid 157386:tid 157628] [client 20.116.17.175:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFzQAAAXo"] [Tue Aug 18 13:06:50.411448 2026] [security2:error] [pid 157386:tid 157571] [client 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/config/.env.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFzgAAAUE"] [Tue Aug 18 13:06:50.414784 2026] [security2:error] [pid 157386:tid 157625] [client 20.79.204.6:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSDGk1jzAhYHVVT1WcFzwAAAXc"] [Tue Aug 18 13:06:50.415442 2026] [security2:error] [pid 157386:tid 157597] [client 168.62.48.100:18079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/index/function.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF0AAAAVs"] [Tue Aug 18 13:06:50.415913 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.36.136:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF0QAAARk"] [Tue Aug 18 13:06:50.428870 2026] [security2:error] [pid 157386:tid 157610] [client 40.74.65.169:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/qlex1.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF0gAAAWg"] [Tue Aug 18 13:06:50.433263 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.49.167:14166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/xx.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF0wAAAYk"] [Tue Aug 18 13:06:50.472999 2026] [security2:error] [pid 157386:tid 157606] [client 20.226.36.136:62157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/index/function.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF1QAAAWQ"] [Tue Aug 18 13:06:50.478457 2026] [security2:error] [pid 157386:tid 157554] [client 51.116.232.28:2967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF1gAAATA"] [Tue Aug 18 13:06:50.502835 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.36.136:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF1wAAATI"] [Tue Aug 18 13:06:50.508144 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:59716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/rex.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF2AAAAWk"] [Tue Aug 18 13:06:50.542631 2026] [security2:error] [pid 157386:tid 157636] [client 20.226.36.136:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF3AAAAYI"] [Tue Aug 18 13:06:50.548168 2026] [security2:error] [pid 157386:tid 157543] [client 20.104.85.180:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF3gAAASU"] [Tue Aug 18 13:06:50.550717 2026] [security2:error] [pid 157386:tid 157410] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/akcc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF3wABhRc"] [Tue Aug 18 13:06:50.559906 2026] [security2:error] [pid 157386:tid 157624] [client 20.116.17.175:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/red.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF4AAAAXY"] [Tue Aug 18 13:06:50.626669 2026] [security2:error] [pid 157386:tid 157601] [client 20.226.36.136:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/Cachex.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF5AAAAV8"] [Tue Aug 18 13:06:50.627555 2026] [security2:error] [pid 157386:tid 157522] [client 104.209.144.33:31262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/pkmoj.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF5QAAARA"] [Tue Aug 18 13:06:50.632198 2026] [security2:error] [pid 157386:tid 157590] [client 20.1.169.243:15953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/upload/upload_cert.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF5wAAAVQ"] [Tue Aug 18 13:06:50.654845 2026] [security2:error] [pid 157386:tid 157591] [client 74.248.18.37:32448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/analytics.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF6gAAAVU"] [Tue Aug 18 13:06:50.660525 2026] [security2:error] [pid 157386:tid 157520] [client 20.171.51.14:7903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/ct.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF6wAAAQ4"] [Tue Aug 18 13:06:50.677699 2026] [security2:error] [pid 157386:tid 157619] [client 168.62.48.100:18072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF7AAAAXE"] [Tue Aug 18 13:06:50.689333 2026] [security2:error] [pid 157386:tid 157530] [client 158.23.17.4:62989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ft.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF7QAAARg"] [Tue Aug 18 13:06:50.692559 2026] [security2:error] [pid 157386:tid 157602] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/admin.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF7gAAAWA"] [Tue Aug 18 13:06:50.718554 2026] [security2:error] [pid 157386:tid 157584] [client 20.116.17.175:22654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/read.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF7wAAAU4"] [Tue Aug 18 13:06:50.719888 2026] [security2:error] [pid 157386:tid 157538] [client 178.153.171.161:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF8AAAASA"] [Tue Aug 18 13:06:50.719995 2026] [security2:error] [pid 157386:tid 157538] [client 178.153.171.161:26377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF8AAAASA"] [Tue Aug 18 13:06:50.722096 2026] [security2:error] [pid 157386:tid 157391] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF8QABDAQ"] [Tue Aug 18 13:06:50.722611 2026] [security2:error] [pid 157386:tid 157633] [client 20.127.136.245:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/u.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF8wAAAX8"] [Tue Aug 18 13:06:50.728749 2026] [security2:error] [pid 157386:tid 157621] [client 20.226.36.136:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF9AAAAXM"] [Tue Aug 18 13:06:50.786401 2026] [security2:error] [pid 157386:tid 157525] [client 135.225.75.187:11596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/file59.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF-AAAARM"] [Tue Aug 18 13:06:50.817129 2026] [security2:error] [pid 157386:tid 157609] [client 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDGk1jzAhYHVVT1WcF-wAAAWc"] [Tue Aug 18 13:06:50.823522 2026] [security2:error] [pid 157386:tid 157557] [client 20.251.48.93:31271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/puc.php"] [unique_id "aoSDGk1jzAhYHVVT1WcF_QAAATM"] [Tue Aug 18 13:06:50.829838 2026] [security2:error] [pid 157386:tid 157630] [client 20.124.247.79:16649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/cof.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGAQAAAXw"] [Tue Aug 18 13:06:50.833990 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:50.834458 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:50.837290 2026] [security2:error] [pid 157386:tid 157542] [client 20.226.36.136:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-2019.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGAgAAASQ"] [Tue Aug 18 13:06:50.841376 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:21661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/verification.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGBAAAAXU"] [Tue Aug 18 13:06:50.842350 2026] [security2:error] [pid 157386:tid 157575] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/core/.env"] [unique_id "aoSDGk1jzAhYHVVT1WcGAwAAAUU"] [Tue Aug 18 13:06:50.885414 2026] [security2:error] [pid 157386:tid 157643] [client 20.1.169.243:5817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGCQAAAYk"] [Tue Aug 18 13:06:50.890280 2026] [security2:error] [pid 157386:tid 157488] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/updates.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGCgABXGU"] [Tue Aug 18 13:06:50.903108 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.85.180:6019] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/css/"] [unique_id "aoSDGk1jzAhYHVVT1WcGCwAAAT0"] [Tue Aug 18 13:06:50.905513 2026] [security2:error] [pid 157386:tid 157529] [client 158.158.74.177:24976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/d.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGDQAAARc"] [Tue Aug 18 13:06:50.930971 2026] [security2:error] [pid 157386:tid 157578] [client 51.116.232.28:2626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/yj09.php"] [unique_id "aoSDGk1jzAhYHVVT1WcGDwAAAUg"] [Tue Aug 18 13:06:50.997068 2026] [security2:error] [pid 157386:tid 157592] [client 20.1.169.243:15940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/uploads/683584ibal.php.xxxjpg"] [unique_id "aoSDGk1jzAhYHVVT1WcGEwAAAVY"] [Tue Aug 18 13:06:51.013688 2026] [security2:error] [pid 157386:tid 157537] [client 20.226.36.136:61501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDG01jzAhYHVVT1WcGFAAAAR8"] [Tue Aug 18 13:06:51.048864 2026] [security2:error] [pid 157386:tid 157573] [client 20.79.204.6:11657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDG01jzAhYHVVT1WcGFQAAAUM"] [Tue Aug 18 13:06:51.062872 2026] [security2:error] [pid 157386:tid 157634] [client 222.124.191.185:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSDG01jzAhYHVVT1WcGFgAAAYA"] [Tue Aug 18 13:06:51.062981 2026] [security2:error] [pid 157386:tid 157634] [client 222.124.191.185:36118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "aoSDG01jzAhYHVVT1WcGFgAAAYA"] [Tue Aug 18 13:06:51.092714 2026] [security2:error] [pid 157386:tid 157562] [client 213.35.127.232:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDG01jzAhYHVVT1WcGGAAAATg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:51.095529 2026] [security2:error] [pid 157386:tid 157424] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSDG01jzAhYHVVT1WcGGQABLSU"] [Tue Aug 18 13:06:51.099019 2026] [security2:error] [pid 157386:tid 157585] [client 168.62.48.100:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/Cachex.php"] [unique_id "aoSDG01jzAhYHVVT1WcGGgAAAU8"] [Tue Aug 18 13:06:51.124329 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:27726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/yn.php"] [unique_id "aoSDG01jzAhYHVVT1WcGHwAAARU"] [Tue Aug 18 13:06:51.124587 2026] [security2:error] [pid 157386:tid 157516] [client 40.74.65.169:4431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/mariju.php"] [unique_id "aoSDG01jzAhYHVVT1WcGIAAAAQo"] [Tue Aug 18 13:06:51.136780 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.36.136:65293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/.cache/x.php"] [unique_id "aoSDG01jzAhYHVVT1WcGIQAAAXQ"] [Tue Aug 18 13:06:51.176331 2026] [security2:error] [pid 157386:tid 157520] [client 20.171.51.14:7920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/gy.php"] [unique_id "aoSDG01jzAhYHVVT1WcGIwAAAQ4"] [Tue Aug 18 13:06:51.184284 2026] [security2:error] [pid 157386:tid 157619] [client 20.104.85.180:5995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDG01jzAhYHVVT1WcGJgAAAXE"] [Tue Aug 18 13:06:51.193812 2026] [security2:error] [pid 157386:tid 157565] [client 20.116.17.175:20374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSDG01jzAhYHVVT1WcGJwAAATs"] [Tue Aug 18 13:06:51.205588 2026] [security2:error] [pid 157386:tid 157602] [client 135.225.75.187:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/eauu.php"] [unique_id "aoSDG01jzAhYHVVT1WcGKQAAAWA"] [Tue Aug 18 13:06:51.260728 2026] [security2:error] [pid 157386:tid 157518] [client 68.221.73.131:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/xiugai.php"] [unique_id "aoSDG01jzAhYHVVT1WcGTwAAAQw"] [Tue Aug 18 13:06:51.261472 2026] [security2:error] [pid 157386:tid 157430] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSDG01jzAhYHVVT1WcGUAABfys"] [Tue Aug 18 13:06:51.273158 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/smtp.php"] [unique_id "aoSDG01jzAhYHVVT1WcGUgAAAUk"] [Tue Aug 18 13:06:51.311973 2026] [security2:error] [pid 157386:tid 157641] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/reviall.php"] [unique_id "aoSDG01jzAhYHVVT1WcGVwAAAYc"] [Tue Aug 18 13:06:51.335996 2026] [security2:error] [pid 157386:tid 157525] [client 51.116.232.28:2992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/scxy.php"] [unique_id "aoSDG01jzAhYHVVT1WcGWgAAARM"] [Tue Aug 18 13:06:51.360071 2026] [security2:error] [pid 157386:tid 157401] [remote 162.55.89.48:36412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deliciasdaisa.com.br"] [uri "/wp-login.php"] [unique_id "aoSDG01jzAhYHVVT1WcGWwABGg4"] [Tue Aug 18 13:06:51.362759 2026] [security2:error] [pid 157386:tid 157574] [client 20.1.169.243:15795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/uploads/angulu.php"] [unique_id "aoSDG01jzAhYHVVT1WcGXgAAAUQ"] [Tue Aug 18 13:06:51.366615 2026] [security2:error] [pid 157386:tid 157513] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDG01jzAhYHVVT1WcGXwABV34"] [Tue Aug 18 13:06:51.367627 2026] [security2:error] [pid 157386:tid 157635] [client 20.250.13.23:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-Blogs.php"] [unique_id "aoSDG01jzAhYHVVT1WcGYgAAAYE"] [Tue Aug 18 13:06:51.381121 2026] [security2:error] [pid 157386:tid 157572] [client 20.124.247.79:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/Engine.php"] [unique_id "aoSDG01jzAhYHVVT1WcGZAAAAUI"] [Tue Aug 18 13:06:51.390475 2026] [security2:error] [pid 157386:tid 157557] [client 168.62.48.100:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDG01jzAhYHVVT1WcGZQAAATM"] [Tue Aug 18 13:06:51.415277 2026] [security2:error] [pid 157386:tid 157591] [client 74.248.18.37:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/awesome-coming-soon/flower.php"] [unique_id "aoSDG01jzAhYHVVT1WcGaQAAAVU"] [Tue Aug 18 13:06:51.428078 2026] [security2:error] [pid 157386:tid 157414] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/Casper.php"] [unique_id "aoSDG01jzAhYHVVT1WcGagABcBs"] [Tue Aug 18 13:06:51.435070 2026] [security2:error] [pid 157386:tid 157628] [client 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/config.php.bak"] [unique_id "aoSDG01jzAhYHVVT1WcGbQAAAXo"] [Tue Aug 18 13:06:51.458832 2026] [security2:error] [pid 157386:tid 157643] [client 104.209.144.33:32672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/kopyw.php"] [unique_id "aoSDG01jzAhYHVVT1WcGcwAAAYk"] [Tue Aug 18 13:06:51.467412 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.85.180:6002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/about.php"] [unique_id "aoSDG01jzAhYHVVT1WcGdQAAAT0"] [Tue Aug 18 13:06:51.483144 2026] [security2:error] [pid 157386:tid 157539] [client 34.83.187.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.187.83.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSDG01jzAhYHVVT1WcGewAAASE"] [Tue Aug 18 13:06:51.488631 2026] [security2:error] [pid 157386:tid 157578] [client 20.151.109.219:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/q.php"] [unique_id "aoSDG01jzAhYHVVT1WcGfwAAAUg"] [Tue Aug 18 13:06:51.497745 2026] [security2:error] [pid 157386:tid 157611] [client 20.251.48.93:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/8.php"] [unique_id "aoSDG01jzAhYHVVT1WcGhAAAAWk"] [Tue Aug 18 13:06:51.501922 2026] [security2:error] [pid 157386:tid 157582] [client 20.104.100.201:54035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDG01jzAhYHVVT1WcGhQAAAUw"] [Tue Aug 18 13:06:51.524376 2026] [security2:error] [pid 157386:tid 157568] [client 20.116.17.175:45271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/albin.php"] [unique_id "aoSDG01jzAhYHVVT1WcGjwAAAT4"] [Tue Aug 18 13:06:51.524895 2026] [security2:error] [pid 157386:tid 157594] [client 158.158.74.177:24985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSDG01jzAhYHVVT1WcGkAAAAVg"] [Tue Aug 18 13:06:51.560660 2026] [security2:error] [pid 157386:tid 157543] [client 20.226.36.136:61472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDG01jzAhYHVVT1WcGmgAAASU"] [Tue Aug 18 13:06:51.617976 2026] [security2:error] [pid 157386:tid 157553] [client 20.1.169.243:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDG01jzAhYHVVT1WcGnQAAAS8"] [Tue Aug 18 13:06:51.622491 2026] [security2:error] [pid 157386:tid 157551] [client 52.173.121.69:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDG01jzAhYHVVT1WcGnwAAAS0"] [Tue Aug 18 13:06:51.625667 2026] [security2:error] [pid 157386:tid 157569] [client 135.225.75.187:31816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/dsd.php"] [unique_id "aoSDG01jzAhYHVVT1WcGpQAAAT8"] [Tue Aug 18 13:06:51.641297 2026] [security2:error] [pid 157386:tid 157522] [client 168.62.48.100:18158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDG01jzAhYHVVT1WcGpwAAARA"] [Tue Aug 18 13:06:51.641355 2026] [security2:error] [pid 157386:tid 157500] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/beence.php"] [unique_id "aoSDG01jzAhYHVVT1WcGqAABFXE"] [Tue Aug 18 13:06:51.647957 2026] [security2:error] [pid 157386:tid 157571] [client 20.79.204.6:11654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSDG01jzAhYHVVT1WcGqQAAAUE"] [Tue Aug 18 13:06:51.654487 2026] [security2:error] [pid 157386:tid 157622] [client 20.104.49.167:8683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/av.php"] [unique_id "aoSDG01jzAhYHVVT1WcGrAAAAXQ"] [Tue Aug 18 13:06:51.668994 2026] [security2:error] [pid 157386:tid 157520] [client 20.151.109.219:24890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/teste.php"] [unique_id "aoSDG01jzAhYHVVT1WcGsAAAAQ4"] [Tue Aug 18 13:06:51.720687 2026] [security2:error] [pid 157386:tid 157584] [client 158.23.17.4:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/h.php"] [unique_id "aoSDG01jzAhYHVVT1WcGsQAAAU4"] [Tue Aug 18 13:06:51.727945 2026] [security2:error] [pid 157386:tid 157634] [client 20.1.169.243:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/uploads/phUploader.php"] [unique_id "aoSDG01jzAhYHVVT1WcGtAAAAYA"] [Tue Aug 18 13:06:51.732875 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:51.733135 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:51.741961 2026] [security2:error] [pid 157386:tid 157633] [client 51.116.232.28:2646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDG01jzAhYHVVT1WcGtgAAAX8"] [Tue Aug 18 13:06:51.757136 2026] [security2:error] [pid 157386:tid 157579] [client 20.104.85.180:5984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDG01jzAhYHVVT1WcGuAAAAUk"] [Tue Aug 18 13:06:51.807889 2026] [security2:error] [pid 157386:tid 157457] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/configs.php"] [unique_id "aoSDG01jzAhYHVVT1WcGvgABV0Y"] [Tue Aug 18 13:06:51.812067 2026] [security2:error] [pid 157386:tid 157588] [client 40.74.65.169:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDG01jzAhYHVVT1WcGvwAAAVI"] [Tue Aug 18 13:06:51.837940 2026] [security2:error] [pid 157386:tid 157599] [client 20.127.136.245:27978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDG01jzAhYHVVT1WcGwgAAAV0"] [Tue Aug 18 13:06:51.873569 2026] [security2:error] [pid 157386:tid 157618] [client 104.209.144.33:32679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/zznmg.php"] [unique_id "aoSDG01jzAhYHVVT1WcGwwAAAXA"] [Tue Aug 18 13:06:51.887886 2026] [security2:error] [pid 157386:tid 157628] [client 68.221.73.131:25433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/adminner.php"] [unique_id "aoSDG01jzAhYHVVT1WcGxQAAAXo"] [Tue Aug 18 13:06:51.895618 2026] [security2:error] [pid 157386:tid 157566] [client 20.151.109.219:46461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xf.php"] [unique_id "aoSDG01jzAhYHVVT1WcGxgAAATw"] [Tue Aug 18 13:06:51.925549 2026] [security2:error] [pid 157386:tid 157625] [client 20.124.247.79:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/hehe.php"] [unique_id "aoSDG01jzAhYHVVT1WcGyAAAAXc"] [Tue Aug 18 13:06:51.925752 2026] [security2:error] [pid 157386:tid 157597] [client 20.251.48.93:50292] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.ellevadomall.com.br"] [uri "/1.php"] [unique_id "aoSDG01jzAhYHVVT1WcGyQAAAVs"] [Tue Aug 18 13:06:51.925824 2026] [security2:error] [pid 157386:tid 157597] [client 20.251.48.93:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/1.php"] [unique_id "aoSDG01jzAhYHVVT1WcGyQAAAVs"] [Tue Aug 18 13:06:51.930770 2026] [security2:error] [pid 157386:tid 157610] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/nope.php"] [unique_id "aoSDG01jzAhYHVVT1WcGygAAAWg"] [Tue Aug 18 13:06:51.933415 2026] [security2:error] [pid 157386:tid 157598] [client 20.118.133.132:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/33.php"] [unique_id "aoSDG01jzAhYHVVT1WcGzAAAAVw"] [Tue Aug 18 13:06:51.951794 2026] [security2:error] [pid 157386:tid 157558] [client 168.62.48.100:18069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDG01jzAhYHVVT1WcGzQAAATQ"] [Tue Aug 18 13:06:51.957344 2026] [security2:error] [pid 157386:tid 157578] [client 20.116.17.175:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-css.php"] [unique_id "aoSDG01jzAhYHVVT1WcGzgAAAUg"] [Tue Aug 18 13:06:51.962681 2026] [security2:error] [pid 157386:tid 157581] [client 20.171.51.14:38765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/tt.php"] [unique_id "aoSDG01jzAhYHVVT1WcGzwAAAUs"] [Tue Aug 18 13:06:51.980403 2026] [security2:error] [pid 157386:tid 157575] [client 20.1.169.243:16290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-the.php"] [unique_id "aoSDG01jzAhYHVVT1WcG0AAAAUU"] [Tue Aug 18 13:06:52.032824 2026] [security2:error] [pid 157386:tid 157556] [client 20.151.109.219:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/local.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG0gAAATI"] [Tue Aug 18 13:06:52.033977 2026] [security2:error] [pid 157386:tid 157421] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/delpaths.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG0wABgyI"] [Tue Aug 18 13:06:52.039344 2026] [security2:error] [pid 157386:tid 157582] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/.env.swp"] [unique_id "aoSDHE1jzAhYHVVT1WcG1AAAAUw"] [Tue Aug 18 13:06:52.042458 2026] [security2:error] [pid 157386:tid 157620] [client 135.225.75.187:18637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/c4.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG1QAAAXI"] [Tue Aug 18 13:06:52.047611 2026] [security2:error] [pid 157386:tid 157526] [client 20.104.85.180:5892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/f35.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG1gAAARQ"] [Tue Aug 18 13:06:52.082169 2026] [security2:error] [pid 157386:tid 157542] [client 20.151.109.219:27752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/11.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG2QAAASQ"] [Tue Aug 18 13:06:52.086349 2026] [autoindex:error] [pid 157386:tid 157612] [client 169.58.72.248:57303] AH01276: Cannot serve directory /home3/adobankcom/public_html/wp-content/plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:52.098393 2026] [security2:error] [pid 157386:tid 157537] [client 20.116.17.175:1616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fw/34.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG2wAAAR8"] [Tue Aug 18 13:06:52.105128 2026] [security2:error] [pid 157386:tid 157534] [client 20.226.36.136:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/index.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG3AAAARw"] [Tue Aug 18 13:06:52.117909 2026] [security2:error] [pid 157386:tid 157617] [client 20.1.169.243:15975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/woh.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG3gAAAW8"] [Tue Aug 18 13:06:52.122078 2026] [security2:error] [pid 157386:tid 157614] [client 213.35.127.232:57292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG3wAAAWw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:52.135884 2026] [security2:error] [pid 157386:tid 157541] [client 20.104.49.167:14184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/media.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG4AAAASM"] [Tue Aug 18 13:06:52.142319 2026] [security2:error] [pid 157386:tid 157587] [client 158.158.74.177:9863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG4QAAAVE"] [Tue Aug 18 13:06:52.159271 2026] [security2:error] [pid 157386:tid 157407] [remote 34.62.54.143:44828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uhequeimado.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDHE1jzAhYHVVT1WcG4gABGRQ"] [Tue Aug 18 13:06:52.170453 2026] [security2:error] [pid 157386:tid 157553] [client 51.116.232.28:3005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG4wAAAS8"] [Tue Aug 18 13:06:52.204001 2026] [security2:error] [pid 157386:tid 157517] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/public/.env"] [unique_id "aoSDHE1jzAhYHVVT1WcG5wAAAQs"] [Tue Aug 18 13:06:52.214962 2026] [security2:error] [pid 157386:tid 157601] [client 168.62.48.100:18175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG6gAAAV8"] [Tue Aug 18 13:06:52.226986 2026] [security2:error] [pid 157386:tid 157516] [client 104.209.144.33:32681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/bhfnd.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG6wAAAQo"] [Tue Aug 18 13:06:52.235588 2026] [security2:error] [pid 157386:tid 157424] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/NewFile.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG7AABLCU"] [Tue Aug 18 13:06:52.246173 2026] [security2:error] [pid 157386:tid 157619] [client 20.124.247.79:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/dkSUq.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG7wAAAXE"] [Tue Aug 18 13:06:52.266440 2026] [security2:error] [pid 157386:tid 157549] [client 20.79.204.6:11698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG8AAAASs"] [Tue Aug 18 13:06:52.284157 2026] [security2:error] [pid 157386:tid 157584] [client 34.83.187.233:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.pontadaareiaimoveis.com.br"] [uri "/web/.env"] [unique_id "aoSDHE1jzAhYHVVT1WcG8gAAAU4"] [Tue Aug 18 13:06:52.292791 2026] [security2:error] [pid 157386:tid 157634] [client 168.62.48.100:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.megalustresrs.com.br"] [uri "/images/security.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG8wAAAYA"] [Tue Aug 18 13:06:52.327163 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:20454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG9QAAAUk"] [Tue Aug 18 13:06:52.343751 2026] [security2:error] [pid 157386:tid 157571] [client 20.1.169.243:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG9gAAAUE"] [Tue Aug 18 13:06:52.403752 2026] [security2:error] [pid 157386:tid 157389] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/system.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG_AABfAI"] [Tue Aug 18 13:06:52.412888 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:20695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/loading.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG_QAAAVA"] [Tue Aug 18 13:06:52.416140 2026] [security2:error] [pid 157386:tid 157604] [client 20.104.85.180:5965] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/js/"] [unique_id "aoSDHE1jzAhYHVVT1WcG_gAAAWI"] [Tue Aug 18 13:06:52.426348 2026] [security2:error] [pid 157386:tid 157591] [client 158.23.17.4:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/40.php"] [unique_id "aoSDHE1jzAhYHVVT1WcG_wAAAVU"] [Tue Aug 18 13:06:52.460845 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gb.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHAQAAAXc"] [Tue Aug 18 13:06:52.464608 2026] [security2:error] [pid 157386:tid 157598] [client 135.225.75.187:31856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/an7.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHAgAAAVw"] [Tue Aug 18 13:06:52.469696 2026] [security2:error] [pid 157386:tid 157643] [client 20.251.48.93:17074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/about.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHAwAAAYk"] [Tue Aug 18 13:06:52.476129 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/wp_sitting.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHBAAAAYY"] [Tue Aug 18 13:06:52.485931 2026] [security2:error] [pid 157386:tid 157570] [client 168.62.48.100:18023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHBgAAAUA"] [Tue Aug 18 13:06:52.507927 2026] [security2:error] [pid 157386:tid 157642] [client 40.74.65.169:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/contacto.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHCAAAAYg"] [Tue Aug 18 13:06:52.509799 2026] [security2:error] [pid 157386:tid 157623] [client 20.124.247.79:16646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/qwas.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHCQAAAXU"] [Tue Aug 18 13:06:52.519025 2026] [security2:error] [pid 157386:tid 157530] [client 74.248.18.37:23260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/BDKR28_nfbxj7ov.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHDAAAARg"] [Tue Aug 18 13:06:52.554077 2026] [security2:error] [pid 157386:tid 157620] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/nope.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHDgAAAXI"] [Tue Aug 18 13:06:52.559054 2026] [security2:error] [pid 157386:tid 157561] [client 20.127.136.245:27983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/h.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHDwAAATc"] [Tue Aug 18 13:06:52.575176 2026] [security2:error] [pid 157386:tid 157521] [client 51.116.232.28:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/blurbs.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHEAAAAQ8"] [Tue Aug 18 13:06:52.577629 2026] [security2:error] [pid 157386:tid 157387] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHEQABJAA"] [Tue Aug 18 13:06:52.612392 2026] [security2:error] [pid 157386:tid 157636] [client 20.1.169.243:15990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHEgAAAYI"] [Tue Aug 18 13:06:52.631091 2026] [security2:error] [pid 157386:tid 157639] [client 20.226.36.136:52608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHFAAAAYU"] [Tue Aug 18 13:06:52.634937 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:52.635209 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:52.682271 2026] [security2:error] [pid 157386:tid 157540] [client 68.221.73.131:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file1221.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHGgAAASI"] [Tue Aug 18 13:06:52.705855 2026] [security2:error] [pid 157386:tid 157603] [client 222.124.191.185:36124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHGwAAAWE"] [Tue Aug 18 13:06:52.705967 2026] [security2:error] [pid 157386:tid 157603] [client 222.124.191.185:36124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/old/xmlrpc.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHGwAAAWE"] [Tue Aug 18 13:06:52.708294 2026] [security2:error] [pid 157386:tid 157554] [client 20.1.169.243:5353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wso.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHHAAAATA"] [Tue Aug 18 13:06:52.729345 2026] [security2:error] [pid 157386:tid 157543] [client 104.209.144.33:31232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/qfvqu.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHIAAAASU"] [Tue Aug 18 13:06:52.730010 2026] [security2:error] [pid 157386:tid 157517] [client 20.116.17.175:58213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/flox.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHIQAAAQs"] [Tue Aug 18 13:06:52.743616 2026] [security2:error] [pid 157386:tid 157516] [client 20.104.85.180:5891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/inputs.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHIwAAAQo"] [Tue Aug 18 13:06:52.744384 2026] [security2:error] [pid 157386:tid 157438] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHJQABSjM"] [Tue Aug 18 13:06:52.764768 2026] [security2:error] [pid 157386:tid 157594] [client 158.158.74.177:20537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHKwAAAVg"] [Tue Aug 18 13:06:52.774479 2026] [security2:error] [pid 157386:tid 157549] [client 168.62.48.100:17933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHLAAAASs"] [Tue Aug 18 13:06:52.778532 2026] [security2:error] [pid 157386:tid 157629] [client 20.171.51.14:58015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/mq.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHLgAAAXs"] [Tue Aug 18 13:06:52.832630 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:64578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/ninja.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHMgAAAX8"] [Tue Aug 18 13:06:52.853482 2026] [security2:error] [pid 157386:tid 157606] [client 20.104.49.167:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/images.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHMwAAAWQ"] [Tue Aug 18 13:06:52.873764 2026] [security2:error] [pid 157386:tid 157402] [remote 216.194.122.158:50032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHNAABFA8"] [Tue Aug 18 13:06:52.882447 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:17043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vm.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHNQAAAUE"] [Tue Aug 18 13:06:52.889691 2026] [security2:error] [pid 157386:tid 157574] [client 135.225.75.187:18675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHNwAAAUQ"] [Tue Aug 18 13:06:52.892944 2026] [security2:error] [pid 157386:tid 157538] [client 20.124.247.79:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/OK.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHOAAAASA"] [Tue Aug 18 13:06:52.921892 2026] [security2:error] [pid 157386:tid 157508] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/akc.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHOgABM3k"] [Tue Aug 18 13:06:52.941875 2026] [security2:error] [pid 157386:tid 157572] [client 20.151.109.219:7340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/jp.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHOwAAAUI"] [Tue Aug 18 13:06:52.976937 2026] [security2:error] [pid 157386:tid 157618] [client 51.116.232.28:2995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/bajah.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHPgAAAXA"] [Tue Aug 18 13:06:52.977369 2026] [security2:error] [pid 157386:tid 157579] [client 20.1.169.243:15951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHPwAAAUk"] [Tue Aug 18 13:06:52.990715 2026] [security2:error] [pid 157386:tid 157552] [client 20.79.204.6:11536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHQQAAAS4"] [Tue Aug 18 13:06:52.997348 2026] [security2:error] [pid 157386:tid 157598] [client 20.116.17.175:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDHE1jzAhYHVVT1WcHQgAAAVw"] [Tue Aug 18 13:06:53.028608 2026] [security2:error] [pid 157386:tid 157539] [client 20.104.85.180:5997] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/css/colors/"] [unique_id "aoSDHU1jzAhYHVVT1WcHRAAAASE"] [Tue Aug 18 13:06:53.074071 2026] [security2:error] [pid 157386:tid 157586] [client 20.1.169.243:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/www.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHRQAAAVA"] [Tue Aug 18 13:06:53.083369 2026] [authz_core:error] [pid 157386:tid 157396] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:53.083634 2026] [authz_core:error] [pid 157386:tid 157396] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:53.099284 2026] [security2:error] [pid 157386:tid 157530] [client 168.62.48.100:18050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHSgAAARg"] [Tue Aug 18 13:06:53.105371 2026] [security2:error] [pid 157386:tid 157564] [client 20.116.17.175:1642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp9.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHSwAAATo"] [Tue Aug 18 13:06:53.114663 2026] [security2:error] [pid 157386:tid 157628] [client 103.120.71.157:45091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHTAAAAXo"] [Tue Aug 18 13:06:53.115795 2026] [security2:error] [pid 157386:tid 157628] [client 103.120.71.157:45091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHTAAAAXo"] [Tue Aug 18 13:06:53.119277 2026] [security2:error] [pid 157386:tid 157631] [client 104.209.144.33:31260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/oivcl.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHTgAAAX0"] [Tue Aug 18 13:06:53.140039 2026] [security2:error] [pid 157386:tid 157447] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/flower.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHTwABDzw"] [Tue Aug 18 13:06:53.150873 2026] [security2:error] [pid 157386:tid 157584] [client 213.35.127.232:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHUAAAAU4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:53.184951 2026] [security2:error] [pid 157386:tid 157575] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/new.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHUgAAAUU"] [Tue Aug 18 13:06:53.187776 2026] [security2:error] [pid 157386:tid 157627] [client 40.74.65.169:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/image2.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHVAAAAXk"] [Tue Aug 18 13:06:53.203332 2026] [security2:error] [pid 157386:tid 157614] [client 20.151.109.219:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/phpprobe.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHVgAAAWw"] [Tue Aug 18 13:06:53.204929 2026] [security2:error] [pid 157386:tid 157639] [client 20.251.48.93:17054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/admin.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHVwAAAYU"] [Tue Aug 18 13:06:53.211012 2026] [security2:error] [pid 157386:tid 157593] [client 20.127.136.245:28151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHWAAAAVc"] [Tue Aug 18 13:06:53.221504 2026] [security2:error] [pid 157386:tid 157559] [client 20.250.13.23:35164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.journeyxperience.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHWgAAATU"] [Tue Aug 18 13:06:53.270106 2026] [security2:error] [pid 157386:tid 157540] [client 52.173.121.69:36573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHWwAAASI"] [Tue Aug 18 13:06:53.285538 2026] [security2:error] [pid 157386:tid 157546] [client 20.151.109.219:20674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ke.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHXQAAASg"] [Tue Aug 18 13:06:53.289480 2026] [security2:error] [pid 157386:tid 157607] [client 20.124.247.79:15303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/13.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHXgAAAWU"] [Tue Aug 18 13:06:53.305477 2026] [security2:error] [pid 157386:tid 157603] [client 135.225.75.187:31865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/byp8.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHXwAAAWE"] [Tue Aug 18 13:06:53.308676 2026] [security2:error] [pid 157386:tid 157554] [client 20.104.85.180:5993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/alfa.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHYAAAATA"] [Tue Aug 18 13:06:53.336776 2026] [security2:error] [pid 157386:tid 157611] [client 138.36.100.162:41959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHYQAAAWk"] [Tue Aug 18 13:06:53.338569 2026] [security2:error] [pid 157386:tid 157517] [client 20.151.109.219:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/eq.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHYgAAAQs"] [Tue Aug 18 13:06:53.351931 2026] [security2:error] [pid 157386:tid 157544] [client 20.1.169.243:15999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/wp-login.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHZAAAASY"] [Tue Aug 18 13:06:53.352033 2026] [security2:error] [pid 157386:tid 157516] [client 52.173.121.69:38380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHZwAAAQo"] [Tue Aug 18 13:06:53.360292 2026] [security2:error] [pid 157386:tid 157594] [client 168.62.48.100:18085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHagAAAVg"] [Tue Aug 18 13:06:53.386068 2026] [security2:error] [pid 157386:tid 157615] [client 51.116.232.28:2955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/domvf.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHdQAAAW0"] [Tue Aug 18 13:06:53.392175 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.100.201:54052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHeAAAAVQ"] [Tue Aug 18 13:06:53.393871 2026] [security2:error] [pid 157386:tid 157583] [client 20.116.17.175:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHeQAAAU0"] [Tue Aug 18 13:06:53.404902 2026] [security2:error] [pid 157386:tid 157636] [client 158.158.74.177:9337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHfQAAAYI"] [Tue Aug 18 13:06:53.414039 2026] [security2:error] [pid 157386:tid 157510] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/class-IXR-encryption.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHfwABf3s"] [Tue Aug 18 13:06:53.438308 2026] [security2:error] [pid 157386:tid 157551] [client 20.1.169.243:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/x.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHgwAAAS0"] [Tue Aug 18 13:06:53.465287 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/eg.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHhgAAASc"] [Tue Aug 18 13:06:53.465996 2026] [security2:error] [pid 157386:tid 157535] [client 20.116.17.175:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/op.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHhwAAAR0"] [Tue Aug 18 13:06:53.484685 2026] [security2:error] [pid 157386:tid 157538] [client 20.151.109.219:17550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/wp-title.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHiQAAASA"] [Tue Aug 18 13:06:53.490964 2026] [security2:error] [pid 157386:tid 157604] [client 104.209.144.33:32668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/zugvi.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHiwAAAWI"] [Tue Aug 18 13:06:53.498166 2026] [security2:error] [pid 157386:tid 157618] [client 68.221.73.131:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/inx.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHjQAAAXA"] [Tue Aug 18 13:06:53.524333 2026] [security2:error] [pid 157386:tid 157610] [client 20.104.49.167:61920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/mac.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHkAAAAWg"] [Tue Aug 18 13:06:53.534506 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:53.534908 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:53.539034 2026] [security2:error] [pid 157386:tid 157598] [client 158.23.17.4:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ee.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHkwAAAVw"] [Tue Aug 18 13:06:53.565626 2026] [security2:error] [pid 157386:tid 157640] [client 20.124.247.79:16662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/file.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHlwAAAYY"] [Tue Aug 18 13:06:53.582097 2026] [security2:error] [pid 157386:tid 157477] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/OK.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHmwABR1o"] [Tue Aug 18 13:06:53.587206 2026] [security2:error] [pid 157386:tid 157616] [client 20.104.85.180:6012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/lock360.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHnQAAAW4"] [Tue Aug 18 13:06:53.623697 2026] [security2:error] [pid 157386:tid 157578] [client 197.184.64.235:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHowAAAUg"] [Tue Aug 18 13:06:53.628358 2026] [security2:error] [pid 157386:tid 157578] [client 197.184.64.235:42684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHowAAAUg"] [Tue Aug 18 13:06:53.656469 2026] [security2:error] [pid 157386:tid 157575] [client 20.151.109.219:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ep.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHqAAAAUU"] [Tue Aug 18 13:06:53.657866 2026] [security2:error] [pid 157386:tid 157522] [client 168.62.48.100:18170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHqQAAARA"] [Tue Aug 18 13:06:53.663280 2026] [security2:error] [pid 157386:tid 157614] [client 20.251.48.93:58704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/edit.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHrAAAAWw"] [Tue Aug 18 13:06:53.708469 2026] [security2:error] [pid 157386:tid 157552] [client 20.127.136.245:27998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/a7.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHrwAAAS4"] [Tue Aug 18 13:06:53.716267 2026] [security2:error] [pid 157386:tid 157642] [client 20.1.169.243:15981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHsAAAAYg"] [Tue Aug 18 13:06:53.722888 2026] [security2:error] [pid 157386:tid 157553] [client 135.225.75.187:21441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/plugins.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHtAAAAS8"] [Tue Aug 18 13:06:53.733062 2026] [security2:error] [pid 157386:tid 157611] [client 138.36.100.162:41959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHYQAAAWk"] [Tue Aug 18 13:06:53.762841 2026] [security2:error] [pid 157386:tid 157603] [client 20.171.51.14:9941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/13.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH0AAAAWE"] [Tue Aug 18 13:06:53.770231 2026] [security2:error] [pid 157386:tid 157641] [client 20.79.204.6:11677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSDHU1jzAhYHVVT1WcHoAAAAYc"] [Tue Aug 18 13:06:53.770813 2026] [security2:error] [pid 157386:tid 157543] [client 104.209.144.33:32702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wsrer.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH4QAAASU"] [Tue Aug 18 13:06:53.784988 2026] [security2:error] [pid 157386:tid 157537] [client 51.116.232.28:3006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/fpwch.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH5wAAAR8"] [Tue Aug 18 13:06:53.787331 2026] [security2:error] [pid 157386:tid 157459] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH6AABM0g"] [Tue Aug 18 13:06:53.787455 2026] [security2:error] [pid 157386:tid 157557] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH6AABM0g"] [Tue Aug 18 13:06:53.792225 2026] [security2:error] [pid 157386:tid 157393] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/config.php7"] [unique_id "aoSDHU1jzAhYHVVT1WcH6gABJgY"] [Tue Aug 18 13:06:53.801262 2026] [security2:error] [pid 157386:tid 157593] [client 20.1.169.243:5763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH7QAAAVc"] [Tue Aug 18 13:06:53.803123 2026] [security2:error] [pid 157386:tid 157580] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/new.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH7gAAAUo"] [Tue Aug 18 13:06:53.804958 2026] [security2:error] [pid 157386:tid 157549] [client 20.151.109.219:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/styles.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH7wAAASs"] [Tue Aug 18 13:06:53.832760 2026] [security2:error] [pid 157386:tid 157562] [client 20.124.247.79:16668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/rezor.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH_gAAATg"] [Tue Aug 18 13:06:53.867743 2026] [security2:error] [pid 157386:tid 157622] [client 20.104.85.180:5953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/flower.php"] [unique_id "aoSDHU1jzAhYHVVT1WcH_wAAAXQ"] [Tue Aug 18 13:06:53.881286 2026] [security2:error] [pid 157386:tid 157551] [client 20.116.17.175:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/output.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIDAAAAS0"] [Tue Aug 18 13:06:53.887918 2026] [security2:error] [pid 157386:tid 157565] [client 40.74.65.169:4461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/fb.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIDQAAATs"] [Tue Aug 18 13:06:53.893395 2026] [security2:error] [pid 157386:tid 157550] [client 20.104.49.167:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ops.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIDgAAASw"] [Tue Aug 18 13:06:53.971231 2026] [security2:error] [pid 157386:tid 157566] [client 20.118.133.132:51203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bateriasexpress.aju.br"] [uri "/packed.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIFQAAATw"] [Tue Aug 18 13:06:53.971255 2026] [security2:error] [pid 157386:tid 157572] [client 168.62.48.100:18139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIFAAAAUI"] [Tue Aug 18 13:06:53.984524 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:53.984793 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:53.993886 2026] [security2:error] [pid 157386:tid 157423] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/hyIPpxWDQ.php"] [unique_id "aoSDHU1jzAhYHVVT1WcIHAABXiQ"] [Tue Aug 18 13:06:54.044967 2026] [security2:error] [pid 157386:tid 157590] [client 158.158.74.177:20529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIKAAAAVQ"] [Tue Aug 18 13:06:54.060668 2026] [security2:error] [pid 157386:tid 157564] [client 20.226.36.136:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIKQAAATo"] [Tue Aug 18 13:06:54.078425 2026] [security2:error] [pid 157386:tid 157588] [client 20.151.109.219:33520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/nh.php"] [unique_id "aoSDHk1jzAhYHVVT1WcILAAAAVI"] [Tue Aug 18 13:06:54.084584 2026] [security2:error] [pid 157386:tid 157561] [client 20.151.109.219:24852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/server.php"] [unique_id "aoSDHk1jzAhYHVVT1WcILwAAATc"] [Tue Aug 18 13:06:54.092760 2026] [security2:error] [pid 157386:tid 157591] [client 20.1.169.243:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/admin-header.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIMgAAAVU"] [Tue Aug 18 13:06:54.095641 2026] [security2:error] [pid 157386:tid 157612] [client 104.209.144.33:25285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/ucpfr.php"] [unique_id "aoSDHk1jzAhYHVVT1WcINAAAAWo"] [Tue Aug 18 13:06:54.095682 2026] [security2:error] [pid 157386:tid 157563] [client 20.124.247.79:16712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/3p8jj8r.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIMwAAATk"] [Tue Aug 18 13:06:54.115774 2026] [security2:error] [pid 157386:tid 157522] [client 20.116.17.175:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDHk1jzAhYHVVT1WcINQAAARA"] [Tue Aug 18 13:06:54.119706 2026] [security2:error] [pid 157386:tid 157614] [client 20.116.17.175:22615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/save.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIOgAAAWw"] [Tue Aug 18 13:06:54.120024 2026] [security2:error] [pid 157386:tid 157534] [client 20.251.48.93:31273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIOwAAARw"] [Tue Aug 18 13:06:54.145100 2026] [security2:error] [pid 157386:tid 157639] [client 135.225.75.187:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/100.kb.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIQwAAAYU"] [Tue Aug 18 13:06:54.146497 2026] [security2:error] [pid 157386:tid 157541] [client 20.104.85.180:5961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/13.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIRQAAASM"] [Tue Aug 18 13:06:54.161482 2026] [security2:error] [pid 157386:tid 157493] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/randkeyword.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIRgABUWo"] [Tue Aug 18 13:06:54.162964 2026] [security2:error] [pid 157386:tid 157637] [client 20.1.169.243:5333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIRwAAAYM"] [Tue Aug 18 13:06:54.171210 2026] [security2:error] [pid 157386:tid 157636] [client 213.35.127.232:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDHk1jzAhYHVVT1WcISQAAAYI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:54.191122 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:20408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/tiny2.php"] [unique_id "aoSDHk1jzAhYHVVT1WcISgAAAYg"] [Tue Aug 18 13:06:54.200140 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:27742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/uk.php"] [unique_id "aoSDHk1jzAhYHVVT1WcITQAAAWk"] [Tue Aug 18 13:06:54.210682 2026] [security2:error] [pid 157386:tid 157546] [client 51.116.232.28:2983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/adminner.php"] [unique_id "aoSDHk1jzAhYHVVT1WcITwAAASg"] [Tue Aug 18 13:06:54.252566 2026] [security2:error] [pid 157386:tid 157558] [client 16.22.108.225:57703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.108.22.16.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gustavofrison.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIUAAAATQ"] [Tue Aug 18 13:06:54.259607 2026] [security2:error] [pid 157386:tid 157593] [client 168.62.48.100:18169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIUQAAAVc"] [Tue Aug 18 13:06:54.289518 2026] [security2:error] [pid 157386:tid 157625] [client 158.23.17.4:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ak.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIUwAAAXc"] [Tue Aug 18 13:06:54.308612 2026] [security2:error] [pid 157386:tid 157539] [client 74.248.18.37:40341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/upload/upload_cert.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIWgAAASE"] [Tue Aug 18 13:06:54.323988 2026] [security2:error] [pid 157386:tid 157527] [client 68.221.73.131:31321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/reviall.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIWwAAARU"] [Tue Aug 18 13:06:54.329627 2026] [security2:error] [pid 157386:tid 157432] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/ewywe1dg.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIXQABcS0"] [Tue Aug 18 13:06:54.374388 2026] [security2:error] [pid 157386:tid 157613] [client 20.79.204.6:11685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIYgAAAWs"] [Tue Aug 18 13:06:54.383758 2026] [security2:error] [pid 157386:tid 157598] [client 222.124.191.185:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIZAAAAVw"] [Tue Aug 18 13:06:54.383835 2026] [security2:error] [pid 157386:tid 157598] [client 222.124.191.185:36138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sitemw.com.br"] [uri "/new/xmlrpc.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIZAAAAVw"] [Tue Aug 18 13:06:54.398638 2026] [security2:error] [pid 157386:tid 157574] [client 20.151.109.219:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/xinfo.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIaQAAAUQ"] [Tue Aug 18 13:06:54.426055 2026] [security2:error] [pid 157386:tid 157618] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/apreset.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIbwAAAXA"] [Tue Aug 18 13:06:54.434470 2026] [security2:error] [pid 157386:tid 157572] [client 20.151.109.219:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/rf.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIcQAAAUI"] [Tue Aug 18 13:06:54.455748 2026] [security2:error] [pid 157386:tid 157610] [client 20.104.85.180:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/cc.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIdAAAAWg"] [Tue Aug 18 13:06:54.484651 2026] [security2:error] [pid 157386:tid 157571] [client 104.209.144.33:31258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/yxijx.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIeAAAAUE"] [Tue Aug 18 13:06:54.496273 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wpxml.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIeQAAAXk"] [Tue Aug 18 13:06:54.501631 2026] [security2:error] [pid 157386:tid 157412] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIegABNhk"] [Tue Aug 18 13:06:54.506599 2026] [security2:error] [pid 157386:tid 157526] [client 20.1.169.243:15971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/logs.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIewAAARQ"] [Tue Aug 18 13:06:54.526189 2026] [security2:error] [pid 157386:tid 157609] [client 20.1.169.243:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finissimamoveis.com.br"] [uri "/fpwch.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIfAAAAWc"] [Tue Aug 18 13:06:54.541764 2026] [security2:error] [pid 157386:tid 157581] [client 20.65.98.162:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIgQAAAUs"] [Tue Aug 18 13:06:54.563386 2026] [security2:error] [pid 157386:tid 157556] [client 135.225.75.187:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/mamzi.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIhAAAATI"] [Tue Aug 18 13:06:54.564380 2026] [security2:error] [pid 157386:tid 157584] [client 20.251.48.93:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/inputs.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIhQAAAU4"] [Tue Aug 18 13:06:54.584121 2026] [security2:error] [pid 157386:tid 157563] [client 40.74.65.169:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/gi.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIhwAAATk"] [Tue Aug 18 13:06:54.603962 2026] [security2:error] [pid 157386:tid 157567] [client 168.62.48.100:18143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIigAAAT0"] [Tue Aug 18 13:06:54.616485 2026] [security2:error] [pid 157386:tid 157639] [client 51.116.232.28:2966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/abcd.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIiwAAAYU"] [Tue Aug 18 13:06:54.619287 2026] [security2:error] [pid 157386:tid 157541] [client 20.124.247.79:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/dapa.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIjQAAASM"] [Tue Aug 18 13:06:54.636199 2026] [security2:error] [pid 157386:tid 157524] [client 20.127.136.245:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/manager.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIkQAAARI"] [Tue Aug 18 13:06:54.642274 2026] [security2:error] [pid 157386:tid 157540] [client 20.104.49.167:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/coffexium.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIkgAAASI"] [Tue Aug 18 13:06:54.668508 2026] [security2:error] [pid 157386:tid 157452] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/manager.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIlQABbkE"] [Tue Aug 18 13:06:54.692970 2026] [security2:error] [pid 157386:tid 157529] [client 158.158.74.177:20509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/abc.php"] [unique_id "aoSDHk1jzAhYHVVT1WcImQAAARc"] [Tue Aug 18 13:06:54.700217 2026] [security2:error] [pid 157386:tid 157536] [client 20.151.109.219:24835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/sym.php"] [unique_id "aoSDHk1jzAhYHVVT1WcImgAAAR4"] [Tue Aug 18 13:06:54.712021 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/txets.php"] [unique_id "aoSDHk1jzAhYHVVT1WcInAAAAYc"] [Tue Aug 18 13:06:54.714248 2026] [security2:error] [pid 157386:tid 157543] [client 20.116.17.175:22648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSDHk1jzAhYHVVT1WcInQAAASU"] [Tue Aug 18 13:06:54.714852 2026] [security2:error] [pid 157386:tid 157577] [client 20.151.109.219:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xynz1.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIngAAAUc"] [Tue Aug 18 13:06:54.738227 2026] [security2:error] [pid 157386:tid 157558] [client 20.104.85.180:5889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIoAAAATQ"] [Tue Aug 18 13:06:54.752510 2026] [security2:error] [pid 157386:tid 157599] [client 52.173.121.69:55384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIoQAAAV0"] [Tue Aug 18 13:06:54.772859 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.100.201:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/output.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIpQAAAUo"] [Tue Aug 18 13:06:54.822785 2026] [security2:error] [pid 157386:tid 157622] [client 20.215.241.237:47127] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.smaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIpwAAAXQ"] [Tue Aug 18 13:06:54.822888 2026] [security2:error] [pid 157386:tid 157622] [client 20.215.241.237:47127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/1.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIpwAAAXQ"] [Tue Aug 18 13:06:54.836353 2026] [security2:error] [pid 157386:tid 157459] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/csv.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIqQABO0g"] [Tue Aug 18 13:06:54.855479 2026] [security2:error] [pid 157386:tid 157535] [client 52.173.121.69:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIrQAAAR0"] [Tue Aug 18 13:06:54.858871 2026] [security2:error] [pid 157386:tid 157531] [client 20.116.17.175:20466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIrgAAARk"] [Tue Aug 18 13:06:54.867099 2026] [security2:error] [pid 157386:tid 157594] [client 20.124.247.79:16701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/Ipv6.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIrwAAAVg"] [Tue Aug 18 13:06:54.873205 2026] [security2:error] [pid 157386:tid 157621] [client 20.1.169.243:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/media.php.INFECTED.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIsAAAAXM"] [Tue Aug 18 13:06:54.876240 2026] [security2:error] [pid 157386:tid 157532] [client 20.171.51.14:18683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/so.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIsQAAARo"] [Tue Aug 18 13:06:54.881510 2026] [security2:error] [pid 157386:tid 157574] [client 168.62.48.100:17993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIsgAAAUQ"] [Tue Aug 18 13:06:54.888103 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:54.888364 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:54.906451 2026] [security2:error] [pid 157386:tid 157551] [client 104.209.144.33:31238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/zwlsv.php"] [unique_id "aoSDHk1jzAhYHVVT1WcItgAAAS0"] [Tue Aug 18 13:06:54.963245 2026] [security2:error] [pid 157386:tid 157537] [client 16.22.108.225:57733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.108.22.16.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gustavofrison.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIuQAAAR8"] [Tue Aug 18 13:06:54.986847 2026] [security2:error] [pid 157386:tid 157586] [client 135.225.75.187:21484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ms.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIugAAAVA"] [Tue Aug 18 13:06:54.999571 2026] [security2:error] [pid 157386:tid 157609] [client 20.151.109.219:21646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tokmotos.filialweb.com"] [uri "/ye.php"] [unique_id "aoSDHk1jzAhYHVVT1WcIuwAAAWc"] [Tue Aug 18 13:06:55.007862 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/oo.php"] [unique_id "aoSDH01jzAhYHVVT1WcIvAAAAVQ"] [Tue Aug 18 13:06:55.009489 2026] [security2:error] [pid 157386:tid 157527] [client 20.79.204.6:11520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDH01jzAhYHVVT1WcIvQAAARU"] [Tue Aug 18 13:06:55.016153 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vo.php"] [unique_id "aoSDH01jzAhYHVVT1WcIvgAAATo"] [Tue Aug 18 13:06:55.017383 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.85.180:6003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSDH01jzAhYHVVT1WcIvwAAARg"] [Tue Aug 18 13:06:55.037039 2026] [security2:error] [pid 157386:tid 157581] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/1mage.php"] [unique_id "aoSDH01jzAhYHVVT1WcIwgAAAUs"] [Tue Aug 18 13:06:55.048403 2026] [security2:error] [pid 157386:tid 157487] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/404.php123123"] [unique_id "aoSDH01jzAhYHVVT1WcIwwABSGQ"] [Tue Aug 18 13:06:55.051523 2026] [security2:error] [pid 157386:tid 157547] [client 51.116.232.28:2649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/simple.php"] [unique_id "aoSDH01jzAhYHVVT1WcIxAAAASk"] [Tue Aug 18 13:06:55.127409 2026] [security2:error] [pid 157386:tid 157522] [client 20.124.247.79:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/first.php"] [unique_id "aoSDH01jzAhYHVVT1WcIxgAAARA"] [Tue Aug 18 13:06:55.152865 2026] [security2:error] [pid 157386:tid 157614] [client 20.65.69.59:1789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDH01jzAhYHVVT1WcIxwAAAWw"] [Tue Aug 18 13:06:55.186200 2026] [security2:error] [pid 157386:tid 157552] [client 168.62.48.100:18017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDH01jzAhYHVVT1WcIygAAAS4"] [Tue Aug 18 13:06:55.190492 2026] [security2:error] [pid 157386:tid 157613] [client 213.35.127.232:58025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDH01jzAhYHVVT1WcIywAAAWs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:55.195413 2026] [security2:error] [pid 157386:tid 157585] [client 20.251.48.93:19753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/av.php"] [unique_id "aoSDH01jzAhYHVVT1WcIzAAAAU8"] [Tue Aug 18 13:06:55.222328 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ccou.php"] [unique_id "aoSDH01jzAhYHVVT1WcIzgAAAX4"] [Tue Aug 18 13:06:55.230407 2026] [security2:error] [pid 157386:tid 157627] [client 20.127.136.245:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/w1.php"] [unique_id "aoSDH01jzAhYHVVT1WcIzwAAAXk"] [Tue Aug 18 13:06:55.240678 2026] [security2:error] [pid 157386:tid 157553] [client 20.1.169.243:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDH01jzAhYHVVT1WcI0AAAAS8"] [Tue Aug 18 13:06:55.266235 2026] [security2:error] [pid 157386:tid 157391] [remote 4.223.113.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.113.223.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.foxalpha.com.br"] [uri "/log.php"] [unique_id "aoSDH01jzAhYHVVT1WcI0QABKAQ"] [Tue Aug 18 13:06:55.270913 2026] [security2:error] [pid 157386:tid 157534] [client 5.31.227.224:7858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDH01jzAhYHVVT1WcI0gAAARw"] [Tue Aug 18 13:06:55.272039 2026] [security2:error] [pid 157386:tid 157529] [client 40.74.65.169:4451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/video.php"] [unique_id "aoSDH01jzAhYHVVT1WcI0wAAARc"] [Tue Aug 18 13:06:55.275844 2026] [security2:error] [pid 157386:tid 157534] [client 5.31.227.224:7858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDH01jzAhYHVVT1WcI0gAAARw"] [Tue Aug 18 13:06:55.288099 2026] [security2:error] [pid 157386:tid 157536] [client 20.151.109.219:13768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/creds.php"] [unique_id "aoSDH01jzAhYHVVT1WcI1AAAAR4"] [Tue Aug 18 13:06:55.301694 2026] [security2:error] [pid 157386:tid 157603] [client 20.104.85.180:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/01.php"] [unique_id "aoSDH01jzAhYHVVT1WcI1QAAAWE"] [Tue Aug 18 13:06:55.344689 2026] [security2:error] [pid 157386:tid 157568] [client 158.158.74.177:20530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/sf.php"] [unique_id "aoSDH01jzAhYHVVT1WcI2AAAAT4"] [Tue Aug 18 13:06:55.350154 2026] [security2:error] [pid 157386:tid 157517] [client 104.209.144.33:32667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/jrpga.php"] [unique_id "aoSDH01jzAhYHVVT1WcI2QAAAQs"] [Tue Aug 18 13:06:55.377145 2026] [security2:error] [pid 157386:tid 157557] [client 20.124.247.79:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/wpupex.php"] [unique_id "aoSDH01jzAhYHVVT1WcI2gAAATM"] [Tue Aug 18 13:06:55.392634 2026] [security2:error] [pid 157386:tid 157558] [client 20.116.17.175:63567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDH01jzAhYHVVT1WcI2wAAATQ"] [Tue Aug 18 13:06:55.399606 2026] [security2:error] [pid 157386:tid 157563] [client 74.248.18.37:32478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/aquxkprm.php"] [unique_id "aoSDH01jzAhYHVVT1WcI3QAAATk"] [Tue Aug 18 13:06:55.401005 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:58189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/img.php"] [unique_id "aoSDH01jzAhYHVVT1WcI3gAAAV0"] [Tue Aug 18 13:06:55.406172 2026] [security2:error] [pid 157386:tid 157629] [client 135.225.75.187:11647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/gfile.php"] [unique_id "aoSDH01jzAhYHVVT1WcI4AAAAXs"] [Tue Aug 18 13:06:55.407281 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.49.167:14203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDH01jzAhYHVVT1WcI4QAAAUo"] [Tue Aug 18 13:06:55.445334 2026] [security2:error] [pid 157386:tid 157622] [client 168.62.48.100:18055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDH01jzAhYHVVT1WcI4wAAAXQ"] [Tue Aug 18 13:06:55.452629 2026] [security2:error] [pid 157386:tid 157518] [client 51.116.232.28:2642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDH01jzAhYHVVT1WcI5AAAAQw"] [Tue Aug 18 13:06:55.474501 2026] [security2:error] [pid 157386:tid 157559] [client 20.151.109.219:20711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ja.php"] [unique_id "aoSDH01jzAhYHVVT1WcI5QAAATU"] [Tue Aug 18 13:06:55.485232 2026] [security2:error] [pid 157386:tid 157592] [client 4.232.151.198:5394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/uploads/backwpup-restore/uploads/users.php"] [unique_id "aoSDH01jzAhYHVVT1WcI5gAAAVY"] [Tue Aug 18 13:06:55.498924 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wu.php"] [unique_id "aoSDH01jzAhYHVVT1WcI5wAAAR0"] [Tue Aug 18 13:06:55.504953 2026] [security2:error] [pid 157386:tid 157520] [client 37.40.227.74:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDH01jzAhYHVVT1WcI6QAAAQ4"] [Tue Aug 18 13:06:55.505034 2026] [security2:error] [pid 157386:tid 157520] [client 37.40.227.74:56987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDH01jzAhYHVVT1WcI6QAAAQ4"] [Tue Aug 18 13:06:55.547249 2026] [security2:error] [pid 157386:tid 157532] [client 20.226.36.136:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDH01jzAhYHVVT1WcI7AAAARo"] [Tue Aug 18 13:06:55.593245 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.85.180:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/lv.php"] [unique_id "aoSDH01jzAhYHVVT1WcI7gAAAVs"] [Tue Aug 18 13:06:55.617760 2026] [security2:error] [pid 157386:tid 157583] [client 20.79.204.6:11701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDH01jzAhYHVVT1WcI9QAAAU0"] [Tue Aug 18 13:06:55.628559 2026] [security2:error] [pid 157386:tid 157560] [client 20.251.48.93:26348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDH01jzAhYHVVT1WcI9gAAATY"] [Tue Aug 18 13:06:55.640312 2026] [security2:error] [pid 157386:tid 157623] [client 20.124.247.79:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/bibil.php"] [unique_id "aoSDH01jzAhYHVVT1WcI9wAAAXU"] [Tue Aug 18 13:06:55.644780 2026] [security2:error] [pid 157386:tid 157606] [client 20.1.169.243:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "aoSDH01jzAhYHVVT1WcI-AAAAWQ"] [Tue Aug 18 13:06:55.648794 2026] [security2:error] [pid 157386:tid 157609] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/imsc.php"] [unique_id "aoSDH01jzAhYHVVT1WcI-QAAAWc"] [Tue Aug 18 13:06:55.707962 2026] [security2:error] [pid 157386:tid 157584] [client 168.62.48.100:18064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDH01jzAhYHVVT1WcJAAAAAU4"] [Tue Aug 18 13:06:55.766583 2026] [security2:error] [pid 157386:tid 157522] [client 20.104.49.167:61946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/sf.php"] [unique_id "aoSDH01jzAhYHVVT1WcJAwAAARA"] [Tue Aug 18 13:06:55.790333 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:55.790588 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:55.803634 2026] [security2:error] [pid 157386:tid 157614] [client 158.23.17.4:42609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/test_info.php"] [unique_id "aoSDH01jzAhYHVVT1WcJBgAAAWw"] [Tue Aug 18 13:06:55.811700 2026] [security2:error] [pid 157386:tid 157554] [client 20.151.109.219:46409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/de.php"] [unique_id "aoSDH01jzAhYHVVT1WcJBwAAATA"] [Tue Aug 18 13:06:55.812402 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:20440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/crgio.php"] [unique_id "aoSDH01jzAhYHVVT1WcJCAAAAYU"] [Tue Aug 18 13:06:55.813509 2026] [security2:error] [pid 157386:tid 157541] [client 20.171.51.14:7251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/10.php"] [unique_id "aoSDH01jzAhYHVVT1WcJCQAAASM"] [Tue Aug 18 13:06:55.822251 2026] [security2:error] [pid 157386:tid 157636] [client 135.225.75.187:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSDH01jzAhYHVVT1WcJCgAAAYI"] [Tue Aug 18 13:06:55.829694 2026] [security2:error] [pid 157386:tid 157552] [client 20.127.136.245:28249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSDH01jzAhYHVVT1WcJCwAAAS4"] [Tue Aug 18 13:06:55.837124 2026] [security2:error] [pid 157386:tid 157631] [client 104.209.144.33:32646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDH01jzAhYHVVT1WcJDAAAAX0"] [Tue Aug 18 13:06:55.845753 2026] [security2:error] [pid 157386:tid 157642] [client 20.116.17.175:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDH01jzAhYHVVT1WcJDQAAAYg"] [Tue Aug 18 13:06:55.853257 2026] [security2:error] [pid 157386:tid 157524] [client 51.116.232.28:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/xiugai.php"] [unique_id "aoSDH01jzAhYHVVT1WcJDgAAARI"] [Tue Aug 18 13:06:55.856793 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ho.php"] [unique_id "aoSDH01jzAhYHVVT1WcJDwAAASI"] [Tue Aug 18 13:06:55.863975 2026] [security2:error] [pid 157386:tid 157632] [client 20.226.112.14:61738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDH01jzAhYHVVT1WcJEQAAAX4"] [Tue Aug 18 13:06:55.882058 2026] [security2:error] [pid 157386:tid 157616] [client 20.226.112.14:61707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDH01jzAhYHVVT1WcJEgAAAW4"] [Tue Aug 18 13:06:55.882660 2026] [security2:error] [pid 157386:tid 157546] [client 20.104.85.180:5967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/new.php"] [unique_id "aoSDH01jzAhYHVVT1WcJEwAAASg"] [Tue Aug 18 13:06:55.893115 2026] [security2:error] [pid 157386:tid 157641] [client 20.226.112.14:38250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ws61.php"] [unique_id "aoSDH01jzAhYHVVT1WcJFQAAAYc"] [Tue Aug 18 13:06:55.902185 2026] [security2:error] [pid 157386:tid 157572] [client 20.215.241.237:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/img.php"] [unique_id "aoSDH01jzAhYHVVT1WcJFgAAAUI"] [Tue Aug 18 13:06:55.912746 2026] [security2:error] [pid 157386:tid 157543] [client 20.226.36.136:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDH01jzAhYHVVT1WcJFwAAASU"] [Tue Aug 18 13:06:55.923020 2026] [security2:error] [pid 157386:tid 157517] [client 20.124.247.79:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/halo.php"] [unique_id "aoSDH01jzAhYHVVT1WcJGAAAAQs"] [Tue Aug 18 13:06:55.931182 2026] [security2:error] [pid 157386:tid 157601] [client 20.226.112.14:61734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/rum.php"] [unique_id "aoSDH01jzAhYHVVT1WcJGQAAAV8"] [Tue Aug 18 13:06:55.948010 2026] [security2:error] [pid 157386:tid 157563] [client 40.74.65.169:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/hel.php"] [unique_id "aoSDH01jzAhYHVVT1WcJGgAAATk"] [Tue Aug 18 13:06:55.949965 2026] [security2:error] [pid 157386:tid 157542] [client 20.226.112.14:38229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ze.php"] [unique_id "aoSDH01jzAhYHVVT1WcJGwAAASQ"] [Tue Aug 18 13:06:55.971551 2026] [security2:error] [pid 157386:tid 157629] [client 68.221.73.131:41394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/11.php"] [unique_id "aoSDH01jzAhYHVVT1WcJHgAAAXs"] [Tue Aug 18 13:06:55.972936 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.112.14:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/gjm.php"] [unique_id "aoSDH01jzAhYHVVT1WcJHwAAAUo"] [Tue Aug 18 13:06:55.988744 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.112.14:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/new4.php"] [unique_id "aoSDH01jzAhYHVVT1WcJIAAAAQw"] [Tue Aug 18 13:06:55.996365 2026] [security2:error] [pid 157386:tid 157567] [client 158.158.74.177:20501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/chosen.php"] [unique_id "aoSDH01jzAhYHVVT1WcJIQAAAT0"] [Tue Aug 18 13:06:56.008059 2026] [security2:error] [pid 157386:tid 157535] [client 20.226.112.14:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-act.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJIwAAAR0"] [Tue Aug 18 13:06:56.008746 2026] [security2:error] [pid 157386:tid 157611] [client 74.7.228.31:57114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.brazcoengenharia.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDIE1jzAhYHVVT1WcJIgABaSQ"] [Tue Aug 18 13:06:56.011313 2026] [security2:error] [pid 157386:tid 157643] [client 20.1.169.243:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJJAAAAYk"] [Tue Aug 18 13:06:56.031671 2026] [security2:error] [pid 157386:tid 157516] [client 20.226.112.14:61348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/grsiuk.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJJgAAAQo"] [Tue Aug 18 13:06:56.045549 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.112.14:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/h.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJJwAAAXw"] [Tue Aug 18 13:06:56.056879 2026] [security2:error] [pid 157386:tid 157537] [client 20.226.112.14:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/koiy.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJKgAAAR8"] [Tue Aug 18 13:06:56.073269 2026] [security2:error] [pid 157386:tid 157526] [client 20.226.112.14:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fff.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJLAAAARQ"] [Tue Aug 18 13:06:56.074859 2026] [security2:error] [pid 157386:tid 157570] [client 20.65.69.59:29245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJLQAAAUA"] [Tue Aug 18 13:06:56.089268 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:56.089535 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:56.099784 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.112.14:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/pouhg.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJNQAAAVQ"] [Tue Aug 18 13:06:56.107273 2026] [security2:error] [pid 157386:tid 157582] [client 4.232.151.198:5400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/gxirhnercs.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJOAAAAUw"] [Tue Aug 18 13:06:56.110078 2026] [security2:error] [pid 157386:tid 157579] [client 74.248.18.37:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ice.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJOQAAAUk"] [Tue Aug 18 13:06:56.122804 2026] [security2:error] [pid 157386:tid 157628] [client 20.226.112.14:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/moon3.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJPAAAAXo"] [Tue Aug 18 13:06:56.138353 2026] [security2:error] [pid 157386:tid 157584] [client 20.151.109.219:7351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/album.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJPgAAAU4"] [Tue Aug 18 13:06:56.148523 2026] [security2:error] [pid 157386:tid 157578] [client 168.62.48.100:18087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJPwAAAUg"] [Tue Aug 18 13:06:56.151152 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.112.14:61728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/opts.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJQQAAAVk"] [Tue Aug 18 13:06:56.158557 2026] [security2:error] [pid 157386:tid 157614] [client 20.251.48.93:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJRAAAAWw"] [Tue Aug 18 13:06:56.159263 2026] [security2:error] [pid 157386:tid 157554] [client 20.104.85.180:5972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/222.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJRQAAATA"] [Tue Aug 18 13:06:56.167048 2026] [security2:error] [pid 157386:tid 157541] [client 20.226.112.14:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/zwq13.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJRgAAASM"] [Tue Aug 18 13:06:56.185648 2026] [security2:error] [pid 157386:tid 157636] [client 20.226.112.14:61368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/Okxob.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJSAAAAYI"] [Tue Aug 18 13:06:56.188202 2026] [security2:error] [pid 157386:tid 157634] [client 20.116.17.175:22618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/df.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJSQAAAYA"] [Tue Aug 18 13:06:56.200050 2026] [security2:error] [pid 157386:tid 157585] [client 20.226.112.14:38215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/file59.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJSgAAAU8"] [Tue Aug 18 13:06:56.213756 2026] [security2:error] [pid 157386:tid 157553] [client 213.35.127.232:58255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJTQAAAS8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:56.213790 2026] [security2:error] [pid 157386:tid 157642] [client 104.209.144.33:31239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/nwwha.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJTAAAAYg"] [Tue Aug 18 13:06:56.217927 2026] [security2:error] [pid 157386:tid 157524] [client 20.226.112.14:37519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/eauu.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJTgAAARI"] [Tue Aug 18 13:06:56.233814 2026] [security2:error] [pid 157386:tid 157616] [client 20.226.112.14:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/dsd.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJUAAAAW4"] [Tue Aug 18 13:06:56.239444 2026] [security2:error] [pid 157386:tid 157529] [client 135.225.75.187:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/cu.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJUQAAARc"] [Tue Aug 18 13:06:56.254254 2026] [security2:error] [pid 157386:tid 157539] [client 20.79.204.6:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJUgAAASE"] [Tue Aug 18 13:06:56.270144 2026] [security2:error] [pid 157386:tid 157591] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJUwAAAVU"] [Tue Aug 18 13:06:56.277307 2026] [security2:error] [pid 157386:tid 157568] [client 20.226.112.14:38262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/c4.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJVAAAAT4"] [Tue Aug 18 13:06:56.288787 2026] [security2:error] [pid 157386:tid 157601] [client 51.116.232.28:3002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/wp-load.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJVQAAAV8"] [Tue Aug 18 13:06:56.299858 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.112.14:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/an7.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJWAAAATk"] [Tue Aug 18 13:06:56.302984 2026] [security2:error] [pid 157386:tid 157599] [client 20.124.247.79:16687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/ajq1s.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJWQAAAV0"] [Tue Aug 18 13:06:56.311151 2026] [security2:error] [pid 157386:tid 157615] [client 20.206.73.37:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ws13.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJWgAAAW0"] [Tue Aug 18 13:06:56.329858 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.112.14:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJXAAAAUo"] [Tue Aug 18 13:06:56.357392 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.112.14:61314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/byp8.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJXwAAAXQ"] [Tue Aug 18 13:06:56.367255 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.112.14:61334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/plugins.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJYAAAAVM"] [Tue Aug 18 13:06:56.377523 2026] [security2:error] [pid 157386:tid 157536] [client 20.1.169.243:15743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJYQAAAR4"] [Tue Aug 18 13:06:56.385380 2026] [security2:error] [pid 157386:tid 157611] [client 20.226.112.14:38224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/100.kb.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJYgAAAWk"] [Tue Aug 18 13:06:56.392894 2026] [security2:error] [pid 157386:tid 157520] [client 20.116.17.175:58411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJZAAAAQ4"] [Tue Aug 18 13:06:56.408166 2026] [security2:error] [pid 157386:tid 157598] [client 158.23.17.4:20413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/14.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJZQAAAVw"] [Tue Aug 18 13:06:56.411806 2026] [security2:error] [pid 157386:tid 157592] [client 20.226.112.14:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/mamzi.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJZwAAAVY"] [Tue Aug 18 13:06:56.419453 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.100.201:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/tiny2.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJaQAAAUY"] [Tue Aug 18 13:06:56.434099 2026] [security2:error] [pid 157386:tid 157574] [client 20.104.49.167:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/k.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJawAAAUQ"] [Tue Aug 18 13:06:56.437268 2026] [security2:error] [pid 157386:tid 157604] [client 20.226.112.14:61748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ms.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJbQAAAWI"] [Tue Aug 18 13:06:56.440191 2026] [security2:error] [pid 157386:tid 157572] [client 20.127.136.245:28003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/default.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJbgAAAUI"] [Tue Aug 18 13:06:56.441588 2026] [security2:error] [pid 157386:tid 157630] [client 20.104.85.180:6009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/chosen.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJbwAAAXw"] [Tue Aug 18 13:06:56.447048 2026] [security2:error] [pid 157386:tid 157537] [client 20.151.109.219:49332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kv.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJcAAAAR8"] [Tue Aug 18 13:06:56.452110 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.112.14:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/gfile.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJcQAAAVA"] [Tue Aug 18 13:06:56.463598 2026] [security2:error] [pid 157386:tid 157570] [client 20.171.51.14:13420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/te.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJcgAAAUA"] [Tue Aug 18 13:06:56.475881 2026] [security2:error] [pid 157386:tid 157469] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJcwABTFI"] [Tue Aug 18 13:06:56.476017 2026] [security2:error] [pid 157386:tid 157582] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJcwABTFI"] [Tue Aug 18 13:06:56.482874 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.112.14:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJdAAAAUk"] [Tue Aug 18 13:06:56.483553 2026] [security2:error] [pid 157386:tid 157530] [client 168.62.48.100:18011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJdQAAARg"] [Tue Aug 18 13:06:56.484885 2026] [security2:error] [pid 157386:tid 157581] [client 20.206.73.37:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/clque.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJdgAAAUs"] [Tue Aug 18 13:06:56.490298 2026] [security2:error] [pid 157386:tid 157607] [client 20.65.98.162:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJdwAAAWU"] [Tue Aug 18 13:06:56.501203 2026] [security2:error] [pid 157386:tid 157610] [client 20.116.17.175:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJeAAAAWg"] [Tue Aug 18 13:06:56.512275 2026] [security2:error] [pid 157386:tid 157578] [client 20.226.112.14:38264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/cu.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJegAAAUg"] [Tue Aug 18 13:06:56.540293 2026] [security2:error] [pid 157386:tid 157634] [client 20.226.112.14:37510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/X57.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJiwAAAYA"] [Tue Aug 18 13:06:56.582146 2026] [security2:error] [pid 157386:tid 157540] [client 20.226.112.14:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/forbidals.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJkgAAASI"] [Tue Aug 18 13:06:56.607743 2026] [security2:error] [pid 157386:tid 157539] [client 20.226.112.14:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/edit.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJlwAAASE"] [Tue Aug 18 13:06:56.616627 2026] [security2:error] [pid 157386:tid 157591] [client 52.173.121.69:36587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/weozh.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJmAAAAVU"] [Tue Aug 18 13:06:56.620431 2026] [security2:error] [pid 157386:tid 157543] [client 20.226.112.14:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/kj.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJmQAAASU"] [Tue Aug 18 13:06:56.621296 2026] [security2:error] [pid 157386:tid 157568] [client 40.74.65.169:4887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/grok.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJmgAAAT4"] [Tue Aug 18 13:06:56.623184 2026] [security2:error] [pid 157386:tid 157577] [client 20.124.247.79:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/spip.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJmwAAAUc"] [Tue Aug 18 13:06:56.637109 2026] [security2:error] [pid 157386:tid 157516] [client 158.158.74.177:9864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/u.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJnQAAAQo"] [Tue Aug 18 13:06:56.637238 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.112.14:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/bes.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJngAAATk"] [Tue Aug 18 13:06:56.653017 2026] [security2:error] [pid 157386:tid 157593] [client 20.226.112.14:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ws60.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJoQAAAVc"] [Tue Aug 18 13:06:56.665476 2026] [security2:error] [pid 157386:tid 157622] [client 135.225.75.187:12071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/X57.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJqAAAAXQ"] [Tue Aug 18 13:06:56.679859 2026] [security2:error] [pid 157386:tid 157520] [client 20.226.36.136:53531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJqQAAAQ4"] [Tue Aug 18 13:06:56.689035 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.112.14:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/olfclass.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJqwAAAXw"] [Tue Aug 18 13:06:56.690206 2026] [security2:error] [pid 157386:tid 157594] [client 51.116.232.28:2949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/155.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJrAAAAVg"] [Tue Aug 18 13:06:56.692188 2026] [security2:error] [pid 157386:tid 157640] [client 104.209.144.33:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/opsqt.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJrQAAAYY"] [Tue Aug 18 13:06:56.693733 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:56.694170 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:56.716297 2026] [autoindex:error] [pid 157386:tid 157512] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:56.729445 2026] [security2:error] [pid 157386:tid 157582] [client 20.104.85.180:5978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/info.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJsQAAAUw"] [Tue Aug 18 13:06:56.735992 2026] [security2:error] [pid 157386:tid 157530] [client 20.116.17.175:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJsgAAARg"] [Tue Aug 18 13:06:56.736925 2026] [security2:error] [pid 157386:tid 157522] [client 4.232.151.198:5385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/plugins/data.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJswAAARA"] [Tue Aug 18 13:06:56.742482 2026] [security2:error] [pid 157386:tid 157607] [client 20.226.112.14:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wpver.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJtAAAAWU"] [Tue Aug 18 13:06:56.750525 2026] [security2:error] [pid 157386:tid 157595] [client 168.62.48.100:18112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJtQAAAVk"] [Tue Aug 18 13:06:56.751021 2026] [security2:error] [pid 157386:tid 157601] [client 20.1.169.243:15741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/wp-login.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJtgAAAV8"] [Tue Aug 18 13:06:56.758728 2026] [security2:error] [pid 157386:tid 157584] [client 20.226.112.14:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/thui.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJtwAAAU4"] [Tue Aug 18 13:06:56.760298 2026] [security2:error] [pid 157386:tid 157569] [client 167.235.143.113:15244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJRwAAAT8"], referer: https://dadicamotors.com.br/ [Tue Aug 18 13:06:56.773115 2026] [security2:error] [pid 157386:tid 157634] [client 20.151.109.219:7393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/z.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJuAAAAYA"] [Tue Aug 18 13:06:56.780043 2026] [security2:error] [pid 157386:tid 157575] [client 20.226.112.14:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/tmpls.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJuQAAAUU"] [Tue Aug 18 13:06:56.786395 2026] [security2:error] [pid 157386:tid 157585] [client 52.173.121.69:52949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJugAAAU8"] [Tue Aug 18 13:06:56.798348 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.112.14:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/nzv.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJvAAAAS4"] [Tue Aug 18 13:06:56.837276 2026] [security2:error] [pid 157386:tid 157553] [client 20.226.112.14:61414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/error1.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJvgAAAS8"] [Tue Aug 18 13:06:56.838957 2026] [security2:error] [pid 157386:tid 157476] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.git/HEAD"] [unique_id "aoSDIE1jzAhYHVVT1WcJvwABcVk"] [Tue Aug 18 13:06:56.846560 2026] [security2:error] [pid 157386:tid 157452] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDIE1jzAhYHVVT1WcJwgABPUE"] [Tue Aug 18 13:06:56.854955 2026] [security2:error] [pid 157386:tid 157529] [client 20.226.112.14:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/155.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJxQAAARc"] [Tue Aug 18 13:06:56.865000 2026] [security2:error] [pid 157386:tid 157504] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/files../etc/passwd"] [unique_id "aoSDIE1jzAhYHVVT1WcJyAABiXU"] [Tue Aug 18 13:06:56.868131 2026] [security2:error] [pid 157386:tid 157490] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config.js"] [unique_id "aoSDIE1jzAhYHVVT1WcJywABVmc"] [Tue Aug 18 13:06:56.868393 2026] [access_compat:error] [pid 157386:tid 157580] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/index.php4 [Tue Aug 18 13:06:56.868753 2026] [access_compat:error] [pid 157386:tid 157580] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/index.php3 [Tue Aug 18 13:06:56.869124 2026] [access_compat:error] [pid 157386:tid 157580] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/index.php [Tue Aug 18 13:06:56.869642 2026] [access_compat:error] [pid 157386:tid 157580] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/index.phtml [Tue Aug 18 13:06:56.870531 2026] [security2:error] [pid 157386:tid 157557] [client 20.116.17.175:22549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJzgAAATM"] [Tue Aug 18 13:06:56.871201 2026] [access_compat:error] [pid 157386:tid 157580] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/index.php5 [Tue Aug 18 13:06:56.872618 2026] [security2:error] [pid 157386:tid 157387] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/"] [unique_id "aoSDIE1jzAhYHVVT1WcJzwABCgA"] [Tue Aug 18 13:06:56.877798 2026] [security2:error] [pid 157386:tid 157413] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env"] [unique_id "aoSDIE1jzAhYHVVT1WcJ0gABVxo"] [Tue Aug 18 13:06:56.879620 2026] [security2:error] [pid 157386:tid 157460] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/static../.env"] [unique_id "aoSDIE1jzAhYHVVT1WcJ0wABK0k"] [Tue Aug 18 13:06:56.879639 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.112.14:37567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fasx.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ1QAAAXQ"] [Tue Aug 18 13:06:56.881745 2026] [security2:error] [pid 157386:tid 157389] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/static../etc/passwd"] [unique_id "aoSDIE1jzAhYHVVT1WcJ1wABUwI"] [Tue Aug 18 13:06:56.885172 2026] [security2:error] [pid 157386:tid 157407] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/app/.env"] [unique_id "aoSDIE1jzAhYHVVT1WcJ2gABLBQ"] [Tue Aug 18 13:06:56.889925 2026] [security2:error] [pid 157386:tid 157500] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/proc/self/environ"] [unique_id "aoSDIE1jzAhYHVVT1WcJ3AABWHE"] [Tue Aug 18 13:06:56.893976 2026] [security2:error] [pid 157386:tid 157590] [client 20.226.112.14:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-good.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ3QAAAVQ"] [Tue Aug 18 13:06:56.896938 2026] [security2:error] [pid 157386:tid 157449] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/media../.env"] [unique_id "aoSDIE1jzAhYHVVT1WcJ3wABGD4"] [Tue Aug 18 13:06:56.898519 2026] [security2:error] [pid 157386:tid 157391] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/read"] [unique_id "aoSDIE1jzAhYHVVT1WcJ4AABEAQ"] [Tue Aug 18 13:06:56.899538 2026] [security2:error] [pid 157386:tid 157578] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/qlex1.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ4gAAAUg"] [Tue Aug 18 13:06:56.903568 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.112.14:61335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/zxin.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ5AAAAVk"] [Tue Aug 18 13:06:56.912994 2026] [security2:error] [pid 157386:tid 157584] [client 20.226.112.14:38209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/pass4.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ5gAAAU4"] [Tue Aug 18 13:06:56.914556 2026] [security2:error] [pid 157386:tid 157441] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env"] [unique_id "aoSDIE1jzAhYHVVT1WcJ5wABPzY"] [Tue Aug 18 13:06:56.923883 2026] [security2:error] [pid 157386:tid 157581] [client 20.127.136.245:28240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/i.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ6AAAAUs"] [Tue Aug 18 13:06:56.928237 2026] [security2:error] [pid 157386:tid 157575] [client 20.226.112.14:38209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ6QAAAUU"] [Tue Aug 18 13:06:56.930154 2026] [security2:error] [pid 157386:tid 157635] [client 20.226.36.136:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ6wAAAYE"] [Tue Aug 18 13:06:56.937805 2026] [security2:error] [pid 157386:tid 157508] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/download"] [unique_id "aoSDIE1jzAhYHVVT1WcJ7AABcHk"] [Tue Aug 18 13:06:56.938055 2026] [security2:error] [pid 157386:tid 157464] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/proc/1/environ"] [unique_id "aoSDIE1jzAhYHVVT1WcJ7QABKU0"] [Tue Aug 18 13:06:56.944956 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.112.14:61712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/z.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ7gAAAX0"] [Tue Aug 18 13:06:56.947980 2026] [security2:error] [pid 157386:tid 157494] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDIE1jzAhYHVVT1WcJ7wABaGs"] [Tue Aug 18 13:06:56.951557 2026] [security2:error] [pid 157386:tid 157492] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/media../etc/passwd"] [unique_id "aoSDIE1jzAhYHVVT1WcJ8AABhWk"] [Tue Aug 18 13:06:56.952286 2026] [security2:error] [pid 157386:tid 157419] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDIE1jzAhYHVVT1WcJ8QABLyA"] [Tue Aug 18 13:06:56.963421 2026] [security2:error] [pid 157386:tid 157463] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ8wABDEw"] [Tue Aug 18 13:06:56.963630 2026] [security2:error] [pid 157386:tid 157518] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ8wABDEw"] [Tue Aug 18 13:06:56.963786 2026] [security2:error] [pid 157386:tid 157627] [client 49.37.150.8:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ9AAAAXk"] [Tue Aug 18 13:06:56.963907 2026] [security2:error] [pid 157386:tid 157627] [client 49.37.150.8:51319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ9AAAAXk"] [Tue Aug 18 13:06:56.967285 2026] [security2:error] [pid 157386:tid 157559] [client 20.226.112.14:37566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/222.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ9QAAATU"] [Tue Aug 18 13:06:56.989973 2026] [security2:error] [pid 157386:tid 157641] [client 20.226.112.14:37549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/G-in.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ-AAAAYc"] [Tue Aug 18 13:06:56.999532 2026] [authz_core:error] [pid 157386:tid 157450] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:56.999571 2026] [security2:error] [pid 157386:tid 157603] [client 20.124.247.79:16658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/wpup.php"] [unique_id "aoSDIE1jzAhYHVVT1WcJ-QAAAWE"] [Tue Aug 18 13:06:57.000025 2026] [authz_core:error] [pid 157386:tid 157450] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:57.007635 2026] [security2:error] [pid 157386:tid 157643] [client 20.226.112.14:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xxx.php"] [unique_id "aoSDIU1jzAhYHVVT1WcJ-wAAAYk"] [Tue Aug 18 13:06:57.009422 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/97.php"] [unique_id "aoSDIU1jzAhYHVVT1WcJ_AAAASU"] [Tue Aug 18 13:06:57.010056 2026] [security2:error] [pid 157386:tid 157573] [client 74.248.18.37:32493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/js-settings.php"] [unique_id "aoSDIU1jzAhYHVVT1WcJ_QAAAUM"] [Tue Aug 18 13:06:57.013835 2026] [security2:error] [pid 157386:tid 157621] [client 20.104.85.180:5904] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/html-api/"] [unique_id "aoSDIU1jzAhYHVVT1WcJ_gAAAXM"] [Tue Aug 18 13:06:57.016729 2026] [security2:error] [pid 157386:tid 157557] [client 20.116.17.175:20383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/css.php"] [unique_id "aoSDIU1jzAhYHVVT1WcJ_wAAATM"] [Tue Aug 18 13:06:57.024809 2026] [security2:error] [pid 157386:tid 157451] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDIU1jzAhYHVVT1WcKAAABUkA"] [Tue Aug 18 13:06:57.026495 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.112.14:61705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/un.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKAQAAATk"] [Tue Aug 18 13:06:57.035877 2026] [security2:error] [pid 157386:tid 157514] [remote 162.214.205.212:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKAgABOn8"] [Tue Aug 18 13:06:57.059236 2026] [security2:error] [pid 157386:tid 157525] [client 20.226.112.14:61733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/autogooey.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKBAAAARM"] [Tue Aug 18 13:06:57.073148 2026] [security2:error] [pid 157386:tid 157589] [client 20.215.241.237:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/222.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKBgAAAVM"] [Tue Aug 18 13:06:57.073960 2026] [security2:error] [pid 157386:tid 157542] [client 168.62.48.100:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKBwAAASQ"] [Tue Aug 18 13:06:57.076797 2026] [security2:error] [pid 157386:tid 157572] [client 20.226.112.14:55326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sty.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKCQAAAUI"] [Tue Aug 18 13:06:57.082434 2026] [security2:error] [pid 157386:tid 157594] [client 135.225.75.187:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/forbidals.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKCgAAAVg"] [Tue Aug 18 13:06:57.085070 2026] [access_compat:error] [pid 157386:tid 157550] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/2025/index.php4 [Tue Aug 18 13:06:57.085504 2026] [access_compat:error] [pid 157386:tid 157550] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/2025/index.php3 [Tue Aug 18 13:06:57.085938 2026] [access_compat:error] [pid 157386:tid 157550] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/2025/index.php [Tue Aug 18 13:06:57.086509 2026] [access_compat:error] [pid 157386:tid 157550] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/2025/index.phtml [Tue Aug 18 13:06:57.088134 2026] [access_compat:error] [pid 157386:tid 157550] [client 20.79.204.6:11700] AH01797: client denied by server configuration: /home1/caboclotaperoa/public_html/wp-content/uploads/2025/index.php5 [Tue Aug 18 13:06:57.089954 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.112.14:61317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wio.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKCwAAAVs"] [Tue Aug 18 13:06:57.103798 2026] [security2:error] [pid 157386:tid 157623] [client 20.226.112.14:61340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/1061.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKDQAAAXU"] [Tue Aug 18 13:06:57.127209 2026] [security2:error] [pid 157386:tid 157601] [client 20.251.48.93:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKDgAAAV8"] [Tue Aug 18 13:06:57.127582 2026] [security2:error] [pid 157386:tid 157554] [client 51.116.232.28:2965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKDwAAATA"] [Tue Aug 18 13:06:57.128427 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.112.14:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/gec.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKEAAAAUk"] [Tue Aug 18 13:06:57.148849 2026] [security2:error] [pid 157386:tid 157575] [client 20.226.112.14:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/scx.php7"] [unique_id "aoSDIU1jzAhYHVVT1WcKEgAAAUU"] [Tue Aug 18 13:06:57.162697 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.112.14:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKFgAAAX0"] [Tue Aug 18 13:06:57.172291 2026] [security2:error] [pid 157386:tid 157560] [client 20.151.109.219:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xg.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKFwAAATY"] [Tue Aug 18 13:06:57.173454 2026] [security2:error] [pid 157386:tid 157587] [client 104.209.144.33:25328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKGAAAAVE"] [Tue Aug 18 13:06:57.174228 2026] [security2:error] [pid 157386:tid 157516] [client 20.1.169.243:15799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKGgAAAQo"] [Tue Aug 18 13:06:57.198021 2026] [security2:error] [pid 157386:tid 157553] [client 20.226.112.14:37529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp5.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKHAAAAS8"] [Tue Aug 18 13:06:57.214629 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.112.14:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/a2.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKHgAAAQw"] [Tue Aug 18 13:06:57.230816 2026] [security2:error] [pid 157386:tid 157526] [client 213.35.127.232:58505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKHwAAARQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:57.243905 2026] [security2:error] [pid 157386:tid 157641] [client 20.151.109.219:38603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xx.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKIAAAAYc"] [Tue Aug 18 13:06:57.247391 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.112.14:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/app.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKIQAAAWM"] [Tue Aug 18 13:06:57.248344 2026] [security2:error] [pid 157386:tid 157576] [client 20.171.51.14:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/kc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKIwAAAUY"] [Tue Aug 18 13:06:57.290698 2026] [security2:error] [pid 157386:tid 157604] [client 20.79.204.6:11700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKKQAAAWI"] [Tue Aug 18 13:06:57.291929 2026] [autoindex:error] [pid 157386:tid 157573] [client 20.226.112.14:61438] AH01276: Cannot serve directory /home2/combrazilcoa/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:57.293495 2026] [security2:error] [pid 157386:tid 157621] [client 20.104.85.180:5987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKKwAAAXM"] [Tue Aug 18 13:06:57.295398 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:57.295656 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:57.300878 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.112.14:61438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKLAAAAUo"] [Tue Aug 18 13:06:57.320141 2026] [security2:error] [pid 157386:tid 157622] [client 20.226.112.14:37539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/cxc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKLgAAAXQ"] [Tue Aug 18 13:06:57.320162 2026] [security2:error] [pid 157386:tid 157593] [client 40.74.65.169:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/indes.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKLQAAAVc"] [Tue Aug 18 13:06:57.324879 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKLwAAASs"] [Tue Aug 18 13:06:57.329316 2026] [security2:error] [pid 157386:tid 157609] [client 223.185.37.47:2651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKMAAAAWc"] [Tue Aug 18 13:06:57.329492 2026] [security2:error] [pid 157386:tid 157609] [client 223.185.37.47:2651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKMAAAAWc"] [Tue Aug 18 13:06:57.335293 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.112.14:37539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDIU1jzAhYHVVT1WcKMQAAAVM"] [Tue Aug 18 13:06:57.346712 2026] [security2:error] [pid 157386:tid 157630] [client 20.116.17.175:45276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/usr.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKNAAAAXw"] [Tue Aug 18 13:06:57.355602 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.112.14:38222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/0.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKNgAAAVs"] [Tue Aug 18 13:06:57.358406 2026] [security2:error] [pid 157386:tid 157606] [client 20.124.247.79:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/myy.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKNwAAAWQ"] [Tue Aug 18 13:06:57.362493 2026] [security2:error] [pid 157386:tid 157582] [client 168.62.48.100:18095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKOQAAAUw"] [Tue Aug 18 13:06:57.368886 2026] [security2:error] [pid 157386:tid 157625] [client 4.232.151.198:5422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/options.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKOgAAAXc"] [Tue Aug 18 13:06:57.376831 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.112.14:37514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/dom.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKOwAAATI"] [Tue Aug 18 13:06:57.392829 2026] [security2:error] [pid 157386:tid 157522] [client 20.226.112.14:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/bb.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKPAAAARA"] [Tue Aug 18 13:06:57.409825 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.112.14:51543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ok.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKPgAAAUk"] [Tue Aug 18 13:06:57.424454 2026] [security2:error] [pid 157386:tid 157637] [client 20.116.17.175:20426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKPwAAAYM"] [Tue Aug 18 13:06:57.428191 2026] [security2:error] [pid 157386:tid 157636] [client 20.226.112.14:55315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp9.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKQAAAAYI"] [Tue Aug 18 13:06:57.438309 2026] [security2:error] [pid 157386:tid 157562] [client 213.202.253.4:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKQgAAATg"], referer: www.google.com [Tue Aug 18 13:06:57.442540 2026] [security2:error] [pid 157386:tid 157585] [client 20.226.112.14:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ws59.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKQwAAAU8"] [Tue Aug 18 13:06:57.456490 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.112.14:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKRAAAAS4"] [Tue Aug 18 13:06:57.469090 2026] [security2:error] [pid 157386:tid 157529] [client 20.226.112.14:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKRQAAARc"] [Tue Aug 18 13:06:57.483660 2026] [security2:error] [pid 157386:tid 157566] [client 20.226.112.14:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/vx.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKRgAAATw"] [Tue Aug 18 13:06:57.493313 2026] [security2:error] [pid 157386:tid 157559] [client 158.158.74.177:25012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/customize.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKSAAAATU"] [Tue Aug 18 13:06:57.495488 2026] [security2:error] [pid 157386:tid 157623] [client 74.7.244.48:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.jetherostembergimoveis.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDIU1jzAhYHVVT1WcKRwABdUU"] [Tue Aug 18 13:06:57.499869 2026] [security2:error] [pid 157386:tid 157567] [client 135.225.75.187:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/edit.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKSQAAAT0"] [Tue Aug 18 13:06:57.502662 2026] [security2:error] [pid 157386:tid 157605] [client 20.226.112.14:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ah25.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKSgAAAWM"] [Tue Aug 18 13:06:57.508744 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:5795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/nd.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKTAAAASU"] [Tue Aug 18 13:06:57.509500 2026] [security2:error] [pid 157386:tid 157611] [client 20.104.49.167:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/82.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKTQAAAWk"] [Tue Aug 18 13:06:57.516185 2026] [security2:error] [pid 157386:tid 157629] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/mariju.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKTwAAAXs"] [Tue Aug 18 13:06:57.523064 2026] [security2:error] [pid 157386:tid 157635] [client 20.226.112.14:61723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/tt.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKUAAAAYE"] [Tue Aug 18 13:06:57.525771 2026] [security2:error] [pid 157386:tid 157545] [client 51.116.232.28:2957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/aaa.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKUgAAASc"] [Tue Aug 18 13:06:57.537482 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.112.14:51414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xqq.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKVQAAAUM"] [Tue Aug 18 13:06:57.544616 2026] [security2:error] [pid 157386:tid 157574] [client 158.23.17.4:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/tk.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKVgAAAUQ"] [Tue Aug 18 13:06:57.558579 2026] [security2:error] [pid 157386:tid 157599] [client 20.226.112.14:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/06.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKVwAAAV0"] [Tue Aug 18 13:06:57.565646 2026] [security2:error] [pid 157386:tid 157547] [client 20.1.169.243:15913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKWAAAASk"] [Tue Aug 18 13:06:57.575238 2026] [security2:error] [pid 157386:tid 157593] [client 20.104.85.180:5937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKWwAAAVc"] [Tue Aug 18 13:06:57.586865 2026] [security2:error] [pid 157386:tid 157549] [client 20.226.112.14:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/166.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKXAAAASs"] [Tue Aug 18 13:06:57.597348 2026] [authz_core:error] [pid 157386:tid 157401] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:57.597651 2026] [authz_core:error] [pid 157386:tid 157401] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:57.606140 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.112.14:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/snq.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKXgAAAWc"] [Tue Aug 18 13:06:57.622599 2026] [security2:error] [pid 157386:tid 157590] [client 20.171.51.14:33013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/sb.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKYgAAAVQ"] [Tue Aug 18 13:06:57.625092 2026] [security2:error] [pid 157386:tid 157597] [client 20.226.112.14:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-access.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKYwAAAVs"] [Tue Aug 18 13:06:57.643732 2026] [security2:error] [pid 157386:tid 157594] [client 168.62.48.100:18066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKZAAAAVg"] [Tue Aug 18 13:06:57.649402 2026] [security2:error] [pid 157386:tid 157582] [client 20.226.112.14:61317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/nw.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKZQAAAUw"] [Tue Aug 18 13:06:57.654223 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.36.136:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKZgAAATI"] [Tue Aug 18 13:06:57.677814 2026] [security2:error] [pid 157386:tid 157637] [client 20.226.112.14:61759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ws62.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKaAAAAYM"] [Tue Aug 18 13:06:57.712954 2026] [security2:error] [pid 157386:tid 157618] [client 20.104.100.201:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/setup-config.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKbAAAAXA"] [Tue Aug 18 13:06:57.724348 2026] [security2:error] [pid 157386:tid 157587] [client 20.226.112.14:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/public/vx.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKbgAAAVE"] [Tue Aug 18 13:06:57.744244 2026] [security2:error] [pid 157386:tid 157518] [client 20.124.247.79:15331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/geido.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKcQAAAQw"] [Tue Aug 18 13:06:57.752337 2026] [security2:error] [pid 157386:tid 157591] [client 20.226.112.14:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/loxi-o.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKigAAAVU"] [Tue Aug 18 13:06:57.761051 2026] [security2:error] [pid 157386:tid 157643] [client 104.209.144.33:32671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKkwAAAYk"] [Tue Aug 18 13:06:57.767855 2026] [security2:error] [pid 157386:tid 157635] [client 20.226.112.14:61696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sdsa.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKlAAAAYE"] [Tue Aug 18 13:06:57.773126 2026] [security2:error] [pid 157386:tid 157526] [client 74.248.18.37:40352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ad24f.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKlgAAARQ"] [Tue Aug 18 13:06:57.786361 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.112.14:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-freya.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKmQAAAUM"] [Tue Aug 18 13:06:57.787121 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/term.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKmgAAATk"] [Tue Aug 18 13:06:57.798983 2026] [security2:error] [pid 157386:tid 157532] [client 20.251.48.93:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKnAAAARo"] [Tue Aug 18 13:06:57.802679 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:50453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ri.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKnQAAAUo"] [Tue Aug 18 13:06:57.805294 2026] [security2:error] [pid 157386:tid 157615] [client 20.226.112.14:38218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fleen.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKngAAAW0"] [Tue Aug 18 13:06:57.814754 2026] [security2:error] [pid 157386:tid 157547] [client 20.127.136.245:28119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKsgAAASk"] [Tue Aug 18 13:06:57.822013 2026] [security2:error] [pid 157386:tid 157557] [client 20.226.112.14:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/e.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKswAAATM"] [Tue Aug 18 13:06:57.840883 2026] [security2:error] [pid 157386:tid 157520] [client 20.226.112.14:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/hello.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKtgAAAQ4"] [Tue Aug 18 13:06:57.845651 2026] [security2:error] [pid 157386:tid 157542] [client 20.65.69.59:24691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/dirs.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKtwAAASQ"] [Tue Aug 18 13:06:57.857242 2026] [security2:error] [pid 157386:tid 157606] [client 20.226.112.14:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/brc.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKuAAAAWQ"] [Tue Aug 18 13:06:57.859285 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.85.180:5921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/k.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKuQAAAUI"] [Tue Aug 18 13:06:57.860516 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/rh.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKugAAAXw"] [Tue Aug 18 13:06:57.874294 2026] [security2:error] [pid 157386:tid 157522] [client 20.226.112.14:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/file52.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKwgAAARA"] [Tue Aug 18 13:06:57.882590 2026] [security2:error] [pid 157386:tid 157595] [client 20.226.112.14:38271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKxAAAAVk"] [Tue Aug 18 13:06:57.890263 2026] [security2:error] [pid 157386:tid 157581] [client 20.79.204.6:11523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKxgAAAUs"] [Tue Aug 18 13:06:57.893148 2026] [security2:error] [pid 157386:tid 157636] [client 20.226.112.14:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/path.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKyAAAAYI"] [Tue Aug 18 13:06:57.896341 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:57.896607 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:57.903245 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/conn-test.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKzQAAAS4"] [Tue Aug 18 13:06:57.905425 2026] [security2:error] [pid 157386:tid 157618] [client 20.226.112.14:61740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wpo.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKzgAAAXA"] [Tue Aug 18 13:06:57.911968 2026] [security2:error] [pid 157386:tid 157587] [client 168.62.48.100:18106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDIU1jzAhYHVVT1WcKzwAAAVE"] [Tue Aug 18 13:06:57.919644 2026] [security2:error] [pid 157386:tid 157613] [client 20.116.17.175:20330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/epinyins.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK0AAAAWs"] [Tue Aug 18 13:06:57.920244 2026] [security2:error] [pid 157386:tid 157639] [client 135.225.75.187:18684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/kj.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK0QAAAYU"] [Tue Aug 18 13:06:57.924032 2026] [security2:error] [pid 157386:tid 157623] [client 51.116.232.28:2648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK0wAAAXU"] [Tue Aug 18 13:06:57.924046 2026] [security2:error] [pid 157386:tid 157559] [client 20.226.112.14:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/a1vx.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK0gAAATU"] [Tue Aug 18 13:06:57.939353 2026] [security2:error] [pid 157386:tid 157525] [client 20.1.169.243:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/index.php.suspected"] [unique_id "aoSDIU1jzAhYHVVT1WcK1AAAARM"] [Tue Aug 18 13:06:57.942923 2026] [security2:error] [pid 157386:tid 157619] [client 20.226.112.14:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ty.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK1QAAAXE"] [Tue Aug 18 13:06:57.953860 2026] [security2:error] [pid 157386:tid 157551] [client 20.226.112.14:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/vgtyu.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK1gAAAS0"] [Tue Aug 18 13:06:57.956635 2026] [security2:error] [pid 157386:tid 157591] [client 20.171.51.14:44884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/jn.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK1wAAAVU"] [Tue Aug 18 13:06:57.966302 2026] [security2:error] [pid 157386:tid 157629] [client 20.226.112.14:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/mans.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK2AAAAXs"] [Tue Aug 18 13:06:57.986205 2026] [security2:error] [pid 157386:tid 157635] [client 20.226.112.14:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/co.php"] [unique_id "aoSDIU1jzAhYHVVT1WcK2gAAAYE"] [Tue Aug 18 13:06:58.002999 2026] [security2:error] [pid 157386:tid 157573] [client 20.226.112.14:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/btx25.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK3QAAAUM"] [Tue Aug 18 13:06:58.007269 2026] [security2:error] [pid 157386:tid 157563] [client 40.74.65.169:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK4AAAATk"] [Tue Aug 18 13:06:58.008662 2026] [security2:error] [pid 157386:tid 157621] [client 20.124.247.79:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/gelay.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK4wAAAXM"] [Tue Aug 18 13:06:58.018589 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.112.14:38257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/avim.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK5wAAAUo"] [Tue Aug 18 13:06:58.034082 2026] [security2:error] [pid 157386:tid 157557] [client 20.226.112.14:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/myfile.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK6AAAATM"] [Tue Aug 18 13:06:58.035525 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:1655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK6QAAASs"] [Tue Aug 18 13:06:58.040659 2026] [security2:error] [pid 157386:tid 157593] [client 78.46.215.1:7202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.stampi.ind.br"] [uri "/index.html"] [unique_id "aoSDIk1jzAhYHVVT1WcK6gAAAVc"], referer: http://www.stampi.ind.br/ [Tue Aug 18 13:06:58.049612 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.112.14:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xmy.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK7gAAAVM"] [Tue Aug 18 13:06:58.063412 2026] [security2:error] [pid 157386:tid 157582] [client 20.226.112.14:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xda.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK8QAAAUw"] [Tue Aug 18 13:06:58.072426 2026] [security2:error] [pid 157386:tid 157597] [client 4.232.151.198:22272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/js/new.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK9AAAAVs"] [Tue Aug 18 13:06:58.078432 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.112.14:61749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/zz.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK9wAAAWE"] [Tue Aug 18 13:06:58.084897 2026] [security2:error] [pid 157386:tid 157556] [client 20.151.109.219:5322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/tp.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK-AAAATI"] [Tue Aug 18 13:06:58.095075 2026] [security2:error] [pid 157386:tid 157581] [client 20.226.112.14:61350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xa.php"] [unique_id "aoSDIk1jzAhYHVVT1WcK-QAAAUs"] [Tue Aug 18 13:06:58.109408 2026] [security2:error] [pid 157386:tid 157535] [client 20.226.112.14:37554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/f6.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLAAAAAR0"] [Tue Aug 18 13:06:58.124573 2026] [security2:error] [pid 157386:tid 157562] [client 20.226.112.14:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/mcs.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLAgAAATg"] [Tue Aug 18 13:06:58.138502 2026] [security2:error] [pid 157386:tid 157639] [client 20.104.85.180:5932] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSDIk1jzAhYHVVT1WcLAwAAAYU"] [Tue Aug 18 13:06:58.138585 2026] [security2:error] [pid 157386:tid 157559] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLBAAAATU"] [Tue Aug 18 13:06:58.152538 2026] [security2:error] [pid 157386:tid 157571] [client 20.226.112.14:37557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/xleet.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLBQAAAUE"] [Tue Aug 18 13:06:58.168144 2026] [security2:error] [pid 157386:tid 157525] [client 20.226.112.14:51583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fr/ms.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLCAAAARM"] [Tue Aug 18 13:06:58.199862 2026] [security2:error] [pid 157386:tid 157550] [client 20.226.112.14:38223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/gool.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLCwAAASw"] [Tue Aug 18 13:06:58.219166 2026] [security2:error] [pid 157386:tid 157635] [client 168.62.48.100:18073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLEQAAAYE"] [Tue Aug 18 13:06:58.234115 2026] [security2:error] [pid 157386:tid 157526] [client 20.226.112.14:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/maxro.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLEwAAARQ"] [Tue Aug 18 13:06:58.249822 2026] [security2:error] [pid 157386:tid 157632] [client 213.35.127.232:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLFAAAAX4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:58.250603 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.112.14:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wdf.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLFQAAATk"] [Tue Aug 18 13:06:58.255065 2026] [security2:error] [pid 157386:tid 157532] [client 20.104.49.167:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/dex.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLFwAAARo"] [Tue Aug 18 13:06:58.262110 2026] [security2:error] [pid 157386:tid 157575] [client 20.124.247.79:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/atomlib.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLGAAAAUU"] [Tue Aug 18 13:06:58.264633 2026] [security2:error] [pid 157386:tid 157564] [client 20.226.112.14:51449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ff1.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLGQAAATo"] [Tue Aug 18 13:06:58.280484 2026] [security2:error] [pid 157386:tid 157598] [client 20.226.112.14:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/guk.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLGgAAAVw"] [Tue Aug 18 13:06:58.282953 2026] [security2:error] [pid 157386:tid 157576] [client 20.251.48.93:61623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLGwAAAUY"] [Tue Aug 18 13:06:58.296741 2026] [security2:error] [pid 157386:tid 157520] [client 20.226.112.14:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-the.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLHAAAAQ4"] [Tue Aug 18 13:06:58.302345 2026] [security2:error] [pid 157386:tid 157589] [client 20.116.17.175:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/black.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLHQAAAVM"] [Tue Aug 18 13:06:58.310646 2026] [security2:error] [pid 157386:tid 157551] [client 20.1.169.243:15768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/layout.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLHwAAAS0"] [Tue Aug 18 13:06:58.313171 2026] [security2:error] [pid 157386:tid 157572] [client 20.226.112.14:38236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sbhu.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLIAAAAUI"] [Tue Aug 18 13:06:58.322573 2026] [security2:error] [pid 157386:tid 157524] [client 20.226.112.14:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/zc-318.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLIgAAARI"] [Tue Aug 18 13:06:58.335983 2026] [security2:error] [pid 157386:tid 157594] [client 20.226.112.14:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ccou.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLIwAAAVg"] [Tue Aug 18 13:06:58.336480 2026] [security2:error] [pid 157386:tid 157597] [client 135.225.75.187:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/bes.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLJAAAAVs"] [Tue Aug 18 13:06:58.349218 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.112.14:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/txets.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLJgAAAXw"] [Tue Aug 18 13:06:58.352955 2026] [security2:error] [pid 157386:tid 157578] [client 158.158.74.177:25018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/mah/function.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLJwAAAUg"] [Tue Aug 18 13:06:58.360593 2026] [security2:error] [pid 157386:tid 157556] [client 20.226.112.14:61317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fun.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLKAAAATI"] [Tue Aug 18 13:06:58.361581 2026] [security2:error] [pid 157386:tid 157531] [client 51.116.232.28:2977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/site.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLKQAAARk"] [Tue Aug 18 13:06:58.373804 2026] [security2:error] [pid 157386:tid 157612] [client 20.226.112.14:61355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/jq.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLKgAAAWo"] [Tue Aug 18 13:06:58.377090 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/load.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLKwAAAUk"] [Tue Aug 18 13:06:58.385282 2026] [security2:error] [pid 157386:tid 157535] [client 20.226.112.14:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sys.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLLQAAAR0"] [Tue Aug 18 13:06:58.400477 2026] [security2:error] [pid 157386:tid 157585] [client 20.226.112.14:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/pp.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLLwAAAU8"] [Tue Aug 18 13:06:58.409109 2026] [security2:error] [pid 157386:tid 157605] [client 20.127.136.245:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLMQAAAWM"] [Tue Aug 18 13:06:58.419096 2026] [security2:error] [pid 157386:tid 157587] [client 20.226.112.14:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wqqs.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLMwAAAVE"] [Tue Aug 18 13:06:58.424971 2026] [authz_core:error] [pid 157386:tid 157453] [remote 57.141.22.115:47088] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:58.425433 2026] [authz_core:error] [pid 157386:tid 157453] [remote 57.141.22.115:47088] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:58.431849 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.85.180:5916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/403.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLNAAAAXU"] [Tue Aug 18 13:06:58.442750 2026] [security2:error] [pid 157386:tid 157553] [client 20.226.112.14:44185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/clasa99.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLNgAAAS8"] [Tue Aug 18 13:06:58.455967 2026] [security2:error] [pid 157386:tid 157566] [client 20.226.112.14:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/666.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLNwAAATw"] [Tue Aug 18 13:06:58.470954 2026] [security2:error] [pid 157386:tid 157611] [client 20.226.112.14:38230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/thui.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLOwAAAWk"] [Tue Aug 18 13:06:58.490169 2026] [security2:error] [pid 157386:tid 157635] [client 20.226.112.14:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/agg.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLQQAAAYE"] [Tue Aug 18 13:06:58.492872 2026] [security2:error] [pid 157386:tid 157592] [client 20.65.98.162:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/img.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLQgAAAVY"] [Tue Aug 18 13:06:58.505646 2026] [security2:error] [pid 157386:tid 157574] [client 20.226.112.14:51501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/erty.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLRQAAAUQ"] [Tue Aug 18 13:06:58.507679 2026] [autoindex:error] [pid 157386:tid 157593] [client 20.79.204.6:11553] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:58.517827 2026] [security2:error] [pid 157386:tid 157575] [client 168.62.48.100:18047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLRwAAAUU"] [Tue Aug 18 13:06:58.520321 2026] [security2:error] [pid 157386:tid 157637] [client 20.226.112.14:61346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/mini.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLSAAAAYM"] [Tue Aug 18 13:06:58.530296 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:16738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/ee.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLSgAAAVw"] [Tue Aug 18 13:06:58.535945 2026] [security2:error] [pid 157386:tid 157576] [client 20.226.112.14:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sid3.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLSwAAAUY"] [Tue Aug 18 13:06:58.549883 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.112.14:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/moon.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLTAAAAWc"] [Tue Aug 18 13:06:58.563096 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.112.14:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ms.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLTgAAAVM"] [Tue Aug 18 13:06:58.577081 2026] [security2:error] [pid 157386:tid 157542] [client 20.226.36.136:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/update/wpupex.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLTwAAASQ"] [Tue Aug 18 13:06:58.577875 2026] [security2:error] [pid 157386:tid 157537] [client 20.226.112.14:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wsws.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLUAAAAR8"] [Tue Aug 18 13:06:58.594824 2026] [security2:error] [pid 157386:tid 157597] [client 158.23.17.4:56735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/hp.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLUgAAAVs"] [Tue Aug 18 13:06:58.603344 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.112.14:61754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/motu.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLUwAAAWE"] [Tue Aug 18 13:06:58.614506 2026] [security2:error] [pid 157386:tid 157578] [client 20.226.112.14:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fff.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLVAAAAUg"] [Tue Aug 18 13:06:58.626001 2026] [security2:error] [pid 157386:tid 157531] [client 20.226.112.14:38213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/66.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLVgAAARk"] [Tue Aug 18 13:06:58.626440 2026] [security2:error] [pid 157386:tid 157595] [client 20.65.69.59:1283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/fresh.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLVwAAAVk"] [Tue Aug 18 13:06:58.642309 2026] [security2:error] [pid 157386:tid 157581] [client 20.226.112.14:61754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/g.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLWAAAAUs"] [Tue Aug 18 13:06:58.673750 2026] [security2:error] [pid 157386:tid 157584] [client 20.226.112.14:44204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/x7.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLWgAAAU4"] [Tue Aug 18 13:06:58.678172 2026] [security2:error] [pid 157386:tid 157636] [client 20.116.17.175:22540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/css/database.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLWwAAAYI"] [Tue Aug 18 13:06:58.683499 2026] [security2:error] [pid 157386:tid 157586] [client 20.1.169.243:15992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/0Rhsgxs8WrSRpDwUIbgQrf/src/ui/index.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLXAAAAVA"] [Tue Aug 18 13:06:58.692184 2026] [security2:error] [pid 157386:tid 157618] [client 20.226.112.14:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/god.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLXQAAAXA"] [Tue Aug 18 13:06:58.693484 2026] [security2:error] [pid 157386:tid 157529] [client 40.74.65.169:4551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/bs1.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLXgAAARc"] [Tue Aug 18 13:06:58.712489 2026] [security2:error] [pid 157386:tid 157613] [client 20.226.112.14:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLYAAAAWs"] [Tue Aug 18 13:06:58.713681 2026] [security2:error] [pid 157386:tid 157623] [client 20.104.85.180:6007] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/images/"] [unique_id "aoSDIk1jzAhYHVVT1WcLYgAAAXU"] [Tue Aug 18 13:06:58.720067 2026] [security2:error] [pid 157386:tid 157559] [client 20.171.51.14:6616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/bf.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLYwAAATU"] [Tue Aug 18 13:06:58.728396 2026] [autoindex:error] [pid 157386:tid 157587] [client 20.79.204.6:11553] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:58.731005 2026] [security2:error] [pid 157386:tid 157564] [client 4.232.151.198:22293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/petz/inc/plugins/wp-links-opml.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLZAAAATo"] [Tue Aug 18 13:06:58.742022 2026] [security2:error] [pid 157386:tid 157641] [client 104.209.144.33:31236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLZQAAAYc"] [Tue Aug 18 13:06:58.743333 2026] [security2:error] [pid 157386:tid 157562] [client 74.248.18.37:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/images/class-config.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLaQAAATg"] [Tue Aug 18 13:06:58.753814 2026] [security2:error] [pid 157386:tid 157541] [client 135.225.75.187:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ws60.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLbgAAASM"] [Tue Aug 18 13:06:58.760884 2026] [security2:error] [pid 157386:tid 157571] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/contacto.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLbwAAAUE"] [Tue Aug 18 13:06:58.763031 2026] [security2:error] [pid 157386:tid 157525] [client 20.226.112.14:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/8.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLcAAAARM"] [Tue Aug 18 13:06:58.763061 2026] [security2:error] [pid 157386:tid 157619] [client 51.116.232.28:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/ccc.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLcQAAAXE"] [Tue Aug 18 13:06:58.791690 2026] [security2:error] [pid 157386:tid 157526] [client 20.116.17.175:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLdAAAARQ"] [Tue Aug 18 13:06:58.807227 2026] [security2:error] [pid 157386:tid 157592] [client 20.226.112.14:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/koiy.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLdgAAAVY"] [Tue Aug 18 13:06:58.833514 2026] [security2:error] [pid 157386:tid 157621] [client 168.62.48.100:18053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLeQAAAXM"] [Tue Aug 18 13:06:58.838556 2026] [security2:error] [pid 157386:tid 157599] [client 20.226.112.14:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/iko.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLegAAAV0"] [Tue Aug 18 13:06:58.859995 2026] [security2:error] [pid 157386:tid 157598] [client 20.226.112.14:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/raw.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLfAAAAVw"] [Tue Aug 18 13:06:58.868091 2026] [security2:error] [pid 157386:tid 157628] [client 20.151.109.219:20978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fg.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLfQAAAXo"] [Tue Aug 18 13:06:58.875442 2026] [security2:error] [pid 157386:tid 157553] [client 20.127.136.245:28154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLfgAAAS8"] [Tue Aug 18 13:06:58.877870 2026] [security2:error] [pid 157386:tid 157549] [client 20.104.100.201:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wpxml.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLfwAAASs"] [Tue Aug 18 13:06:58.897423 2026] [security2:error] [pid 157386:tid 157602] [client 20.124.247.79:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/tfm.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLggAAAWA"] [Tue Aug 18 13:06:58.911728 2026] [security2:error] [pid 157386:tid 157551] [client 52.173.121.69:11050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLhAAAAS0"] [Tue Aug 18 13:06:58.918296 2026] [security2:error] [pid 157386:tid 157572] [client 20.251.48.93:26350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/222.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLhQAAAUI"] [Tue Aug 18 13:06:58.928103 2026] [security2:error] [pid 157386:tid 157537] [client 20.79.204.6:11553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLhgAAAR8"] [Tue Aug 18 13:06:58.938926 2026] [security2:error] [pid 157386:tid 157531] [client 20.116.17.175:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/as.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLhwAAARk"] [Tue Aug 18 13:06:58.971085 2026] [authz_core:error] [pid 157386:tid 157387] [remote 57.141.22.10:57574] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:58.971538 2026] [authz_core:error] [pid 157386:tid 157387] [remote 57.141.22.10:57574] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:58.974918 2026] [security2:error] [pid 157386:tid 157566] [client 158.158.74.177:25011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/filter.php"] [unique_id "aoSDIk1jzAhYHVVT1WcLjwAAATw"] [Tue Aug 18 13:06:59.008414 2026] [security2:error] [pid 157386:tid 157605] [client 20.104.85.180:5982] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/cache/"] [unique_id "aoSDI01jzAhYHVVT1WcLkgAAAWM"] [Tue Aug 18 13:06:59.049639 2026] [security2:error] [pid 157386:tid 157542] [client 20.1.169.243:15917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/0x5oFSRBaxEEW4WLAIJz80/src/ui/index.php"] [unique_id "aoSDI01jzAhYHVVT1WcLlQAAASQ"] [Tue Aug 18 13:06:59.101437 2026] [authz_core:error] [pid 157386:tid 157449] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:59.101693 2026] [authz_core:error] [pid 157386:tid 157449] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:59.151242 2026] [security2:error] [pid 157386:tid 157532] [client 20.215.241.237:10691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/key.php"] [unique_id "aoSDI01jzAhYHVVT1WcLnAAAARo"] [Tue Aug 18 13:06:59.169945 2026] [security2:error] [pid 157386:tid 157628] [client 135.225.75.187:21451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/olfclass.php"] [unique_id "aoSDI01jzAhYHVVT1WcLoQAAAXo"] [Tue Aug 18 13:06:59.202258 2026] [security2:error] [pid 157386:tid 157554] [client 168.62.48.100:18090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDI01jzAhYHVVT1WcLpAAAATA"] [Tue Aug 18 13:06:59.212583 2026] [security2:error] [pid 157386:tid 157602] [client 51.116.232.28:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/admin.php"] [unique_id "aoSDI01jzAhYHVVT1WcLpQAAAWA"] [Tue Aug 18 13:06:59.244885 2026] [security2:error] [pid 157386:tid 157572] [client 20.124.247.79:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/tool.php"] [unique_id "aoSDI01jzAhYHVVT1WcLpgAAAUI"] [Tue Aug 18 13:06:59.252437 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:10579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/yg.php"] [unique_id "aoSDI01jzAhYHVVT1WcLpwAAAUw"] [Tue Aug 18 13:06:59.258034 2026] [security2:error] [pid 157386:tid 157594] [client 20.116.17.175:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ty.php"] [unique_id "aoSDI01jzAhYHVVT1WcLqAAAAVg"] [Tue Aug 18 13:06:59.270005 2026] [security2:error] [pid 157386:tid 157631] [client 20.116.17.175:22542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/privdayz.php"] [unique_id "aoSDI01jzAhYHVVT1WcLrAAAAX0"] [Tue Aug 18 13:06:59.288172 2026] [security2:error] [pid 157386:tid 157522] [client 20.104.85.180:5994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/gecko.php"] [unique_id "aoSDI01jzAhYHVVT1WcLrQAAARA"] [Tue Aug 18 13:06:59.292114 2026] [security2:error] [pid 157386:tid 157535] [client 213.35.127.232:58983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDI01jzAhYHVVT1WcLrgAAAR0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:06:59.330795 2026] [security2:error] [pid 157386:tid 157612] [client 20.104.49.167:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/puc.php"] [unique_id "aoSDI01jzAhYHVVT1WcLrwAAAWo"] [Tue Aug 18 13:06:59.330842 2026] [autoindex:error] [pid 157386:tid 157461] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:06:59.370752 2026] [security2:error] [pid 157386:tid 157552] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/image2.php"] [unique_id "aoSDI01jzAhYHVVT1WcLtwAAAS4"] [Tue Aug 18 13:06:59.373971 2026] [security2:error] [pid 157386:tid 157537] [client 20.127.136.245:28130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/NewFile.php"] [unique_id "aoSDI01jzAhYHVVT1WcLuAAAAR8"] [Tue Aug 18 13:06:59.389996 2026] [security2:error] [pid 157386:tid 157566] [client 40.74.65.169:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/hp2.php"] [unique_id "aoSDI01jzAhYHVVT1WcLuQAAATw"] [Tue Aug 18 13:06:59.407792 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:59.408216 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:59.420856 2026] [security2:error] [pid 157386:tid 157578] [client 20.1.169.243:15996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/duplicator/assets/about.php"] [unique_id "aoSDI01jzAhYHVVT1WcLvAAAAUg"] [Tue Aug 18 13:06:59.431142 2026] [lsapi:warn] [pid 157386:tid 157615] [client 62.197.45.179:58156] [host terrassis.com.br] Backend log: PHP Warning: Failed to set memory limit to 512 bytes (Current memory usage is 2097152 bytes) in Unknown on line 0\n, referer: https://terrassis.com.br/ [Tue Aug 18 13:06:59.477304 2026] [security2:error] [pid 157386:tid 157587] [client 168.62.48.100:18124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDI01jzAhYHVVT1WcLvwAAAVE"] [Tue Aug 18 13:06:59.505400 2026] [security2:error] [pid 157386:tid 157530] [client 20.251.48.93:26343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDI01jzAhYHVVT1WcLwAAAARg"] [Tue Aug 18 13:06:59.515654 2026] [security2:error] [pid 157386:tid 157518] [client 158.23.17.4:40425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wx.php"] [unique_id "aoSDI01jzAhYHVVT1WcLwgAAAQw"] [Tue Aug 18 13:06:59.533045 2026] [security2:error] [pid 157386:tid 157531] [client 20.79.204.6:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSDI01jzAhYHVVT1WcLxAAAARk"] [Tue Aug 18 13:06:59.538134 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:15296] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/1.php"] [unique_id "aoSDI01jzAhYHVVT1WcLxgAAAVw"] [Tue Aug 18 13:06:59.538178 2026] [security2:error] [pid 157386:tid 157580] [client 104.209.144.33:31276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDI01jzAhYHVVT1WcLxQAAAUo"] [Tue Aug 18 13:06:59.538230 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:15296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/1.php"] [unique_id "aoSDI01jzAhYHVVT1WcLxgAAAVw"] [Tue Aug 18 13:06:59.580219 2026] [security2:error] [pid 157386:tid 157572] [client 4.232.151.198:18952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/Cap.php"] [unique_id "aoSDI01jzAhYHVVT1WcLywAAAUI"] [Tue Aug 18 13:06:59.588758 2026] [security2:error] [pid 157386:tid 157582] [client 135.225.75.187:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wpver.php"] [unique_id "aoSDI01jzAhYHVVT1WcLzwAAAUw"] [Tue Aug 18 13:06:59.599126 2026] [security2:error] [pid 157386:tid 157597] [client 20.104.85.180:6000] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/"] [unique_id "aoSDI01jzAhYHVVT1WcL0QAAAVs"] [Tue Aug 18 13:06:59.617885 2026] [security2:error] [pid 157386:tid 157601] [client 51.116.232.28:2961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/reviall.php"] [unique_id "aoSDI01jzAhYHVVT1WcL0wAAAV8"] [Tue Aug 18 13:06:59.627710 2026] [security2:error] [pid 157386:tid 157584] [client 158.158.74.177:24975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/input.php"] [unique_id "aoSDI01jzAhYHVVT1WcL1AAAAU4"] [Tue Aug 18 13:06:59.662845 2026] [security2:error] [pid 157386:tid 157579] [client 20.171.51.14:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/xj.php"] [unique_id "aoSDI01jzAhYHVVT1WcL1gAAAUk"] [Tue Aug 18 13:06:59.674246 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDI01jzAhYHVVT1WcL2wAAAUs"] [Tue Aug 18 13:06:59.678609 2026] [security2:error] [pid 157386:tid 157556] [client 222.124.191.185:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.191.124.222.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sitemw.com.br"] [uri "/wp-login.php"] [unique_id "aoSDI01jzAhYHVVT1WcL3AAAATI"] [Tue Aug 18 13:06:59.705811 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:06:59.706261 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:06:59.722624 2026] [security2:error] [pid 157386:tid 157591] [client 20.116.17.175:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/pucci.php"] [unique_id "aoSDI01jzAhYHVVT1WcL4wAAAVU"] [Tue Aug 18 13:06:59.722644 2026] [security2:error] [pid 157386:tid 157430] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.env"] [unique_id "aoSDI01jzAhYHVVT1WcL4gABDCs"] [Tue Aug 18 13:06:59.746893 2026] [security2:error] [pid 157386:tid 157635] [client 20.151.109.219:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/zj.php"] [unique_id "aoSDI01jzAhYHVVT1WcL5gAAAYE"] [Tue Aug 18 13:06:59.748363 2026] [security2:error] [pid 157386:tid 157592] [client 168.62.48.100:18105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDI01jzAhYHVVT1WcL5wAAAVY"] [Tue Aug 18 13:06:59.761958 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:1653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wg459o.php"] [unique_id "aoSDI01jzAhYHVVT1WcL6wAAAV0"] [Tue Aug 18 13:06:59.770388 2026] [security2:error] [pid 157386:tid 157632] [client 74.248.18.37:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ranger.php"] [unique_id "aoSDI01jzAhYHVVT1WcL7AAAAX4"] [Tue Aug 18 13:06:59.783073 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.49.167:8620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/inso.php"] [unique_id "aoSDI01jzAhYHVVT1WcL7QAAARk"] [Tue Aug 18 13:06:59.787832 2026] [security2:error] [pid 157386:tid 157643] [client 149.34.210.141:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDI01jzAhYHVVT1WcL7gAAAYk"] [Tue Aug 18 13:06:59.804028 2026] [security2:error] [pid 157386:tid 157598] [client 20.124.247.79:15326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/dev1s.php"] [unique_id "aoSDI01jzAhYHVVT1WcL8AAAAVw"] [Tue Aug 18 13:06:59.871525 2026] [security2:error] [pid 157386:tid 157573] [client 20.1.169.243:15966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aoSDI01jzAhYHVVT1WcL9QAAAUM"] [Tue Aug 18 13:06:59.871661 2026] [security2:error] [pid 157386:tid 157535] [client 20.104.100.201:54061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/min.php"] [unique_id "aoSDI01jzAhYHVVT1WcL9gAAAR0"] [Tue Aug 18 13:06:59.880612 2026] [security2:error] [pid 157386:tid 157584] [client 20.104.85.180:5998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/aa.php"] [unique_id "aoSDI01jzAhYHVVT1WcL9wAAAU4"] [Tue Aug 18 13:06:59.939301 2026] [security2:error] [pid 157386:tid 157446] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.env.backup"] [unique_id "aoSDI01jzAhYHVVT1WcL-gABYzs"] [Tue Aug 18 13:06:59.981351 2026] [security2:error] [pid 157386:tid 157613] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/fb.php"] [unique_id "aoSDI01jzAhYHVVT1WcMAwAAAWs"] [Tue Aug 18 13:06:59.989400 2026] [security2:error] [pid 157386:tid 157623] [client 20.251.48.93:50245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDI01jzAhYHVVT1WcMBAAAAXU"] [Tue Aug 18 13:06:59.999925 2026] [security2:error] [pid 157386:tid 157614] [client 20.127.136.245:28283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSDI01jzAhYHVVT1WcMBwAAAWw"] [Tue Aug 18 13:07:00.008644 2026] [security2:error] [pid 157386:tid 157564] [client 20.226.36.136:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-admin/install.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMCAAAATo"] [Tue Aug 18 13:07:00.013618 2026] [security2:error] [pid 157386:tid 157641] [client 135.225.75.187:11329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/thui.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMCQAAAYc"] [Tue Aug 18 13:07:00.028133 2026] [security2:error] [pid 157386:tid 157466] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.env.bak"] [unique_id "aoSDJE1jzAhYHVVT1WcMCwABY08"] [Tue Aug 18 13:07:00.028133 2026] [security2:error] [pid 157386:tid 157470] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.env.old"] [unique_id "aoSDJE1jzAhYHVVT1WcMCgABY1M"] [Tue Aug 18 13:07:00.028523 2026] [security2:error] [pid 157386:tid 157571] [client 51.116.232.28:2996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/nope.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMDAAAAUE"] [Tue Aug 18 13:07:00.053475 2026] [security2:error] [pid 157386:tid 157643] [client 149.34.210.141:63816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDI01jzAhYHVVT1WcL7gAAAYk"] [Tue Aug 18 13:07:00.055473 2026] [security2:error] [pid 157386:tid 157611] [client 47.128.45.209:14860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "plenitude.com.br"] [uri "/robots.txt"] [unique_id "aoSDJE1jzAhYHVVT1WcMDQAAAWk"] [Tue Aug 18 13:07:00.064125 2026] [security2:error] [pid 157386:tid 157455] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/api/.env"] [unique_id "aoSDJE1jzAhYHVVT1WcMEQABI0Q"] [Tue Aug 18 13:07:00.090271 2026] [security2:error] [pid 157386:tid 157635] [client 40.74.65.169:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/yb.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMEwAAAYE"] [Tue Aug 18 13:07:00.095267 2026] [security2:error] [pid 157386:tid 157574] [client 20.151.109.219:46441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/x.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMFAAAAUQ"] [Tue Aug 18 13:07:00.101587 2026] [security2:error] [pid 157386:tid 157550] [client 20.116.17.175:20435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/dot.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMFQAAASw"] [Tue Aug 18 13:07:00.107560 2026] [security2:error] [pid 157386:tid 157592] [client 168.62.48.100:18122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMFwAAAVY"] [Tue Aug 18 13:07:00.118319 2026] [security2:error] [pid 157386:tid 157547] [client 20.124.247.79:16645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/we.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMGAAAASk"] [Tue Aug 18 13:07:00.149143 2026] [autoindex:error] [pid 157386:tid 157618] [client 20.79.204.6:11555] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/Requests/src/Cookie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:00.166995 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.85.180:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/0x.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMGgAAARk"] [Tue Aug 18 13:07:00.174191 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.49.167:8673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/aa.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMHAAAAXo"] [Tue Aug 18 13:07:00.186751 2026] [security2:error] [pid 157386:tid 157625] [client 20.215.241.237:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/chosen.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMHgAAAXc"] [Tue Aug 18 13:07:00.210648 2026] [security2:error] [pid 157386:tid 157567] [client 4.232.151.198:5383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMIgAAAT0"] [Tue Aug 18 13:07:00.245994 2026] [security2:error] [pid 157386:tid 157630] [client 104.209.144.33:31263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMJgAAAXw"] [Tue Aug 18 13:07:00.248359 2026] [security2:error] [pid 157386:tid 157502] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/config/.env"] [unique_id "aoSDJE1jzAhYHVVT1WcMKQABSnM"] [Tue Aug 18 13:07:00.248443 2026] [security2:error] [pid 157386:tid 157421] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/backend/.env"] [unique_id "aoSDJE1jzAhYHVVT1WcMJwABSiI"] [Tue Aug 18 13:07:00.250516 2026] [security2:error] [pid 157386:tid 157619] [client 158.158.74.177:25009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/jquery.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMKgAAAXE"] [Tue Aug 18 13:07:00.259804 2026] [security2:error] [pid 157386:tid 157637] [client 20.1.169.243:15986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/pwnd/gecko.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMKwAAAYM"] [Tue Aug 18 13:07:00.311147 2026] [security2:error] [pid 157386:tid 157516] [client 213.35.127.232:59235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMMQAAAQo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:00.350566 2026] [security2:error] [pid 157386:tid 157595] [client 20.79.204.6:11555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMMgAAAVk"] [Tue Aug 18 13:07:00.353200 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:22569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/mifta.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMNAAAAUk"] [Tue Aug 18 13:07:00.384680 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/yn.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMNgAAASc"] [Tue Aug 18 13:07:00.434953 2026] [security2:error] [pid 157386:tid 157607] [client 135.225.75.187:21493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/tmpls.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMOgAAAWU"] [Tue Aug 18 13:07:00.445485 2026] [security2:error] [pid 157386:tid 157520] [client 168.62.48.100:18160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/first.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMOwAAAQ4"] [Tue Aug 18 13:07:00.446987 2026] [security2:error] [pid 157386:tid 157590] [client 20.104.85.180:6005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/zxz.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMPAAAAVQ"] [Tue Aug 18 13:07:00.456741 2026] [security2:error] [pid 157386:tid 157639] [client 51.116.232.28:2956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/nope.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMPwAAAYU"] [Tue Aug 18 13:07:00.469521 2026] [security2:error] [pid 157386:tid 157614] [client 20.124.247.79:16765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/gdn.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMQQAAAWw"] [Tue Aug 18 13:07:00.493836 2026] [security2:error] [pid 157386:tid 157605] [client 20.116.17.175:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wicked.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMSAAAAWM"] [Tue Aug 18 13:07:00.500601 2026] [authz_core:error] [pid 157386:tid 157400] [remote 57.141.22.50:36540] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:00.501052 2026] [authz_core:error] [pid 157386:tid 157400] [remote 57.141.22.50:36540] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:00.547850 2026] [security2:error] [pid 157386:tid 157551] [client 20.127.136.245:27999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMUQAAAS0"] [Tue Aug 18 13:07:00.583241 2026] [security2:error] [pid 157386:tid 157635] [client 20.116.17.175:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/005.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMUwAAAYE"] [Tue Aug 18 13:07:00.598521 2026] [security2:error] [pid 157386:tid 157627] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/gi.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMVQAAAXk"] [Tue Aug 18 13:07:00.648976 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.49.167:8648] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMXgAAAXo"] [Tue Aug 18 13:07:00.649107 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.49.167:8648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/1.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMXgAAAXo"] [Tue Aug 18 13:07:00.653850 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:13818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/et.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMXwAAAXc"] [Tue Aug 18 13:07:00.665607 2026] [security2:error] [pid 157386:tid 157602] [client 20.104.100.201:53886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ccou.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMYQAAAWA"] [Tue Aug 18 13:07:00.707524 2026] [security2:error] [pid 157386:tid 157557] [client 20.251.48.93:61611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMZQAAATM"] [Tue Aug 18 13:07:00.709737 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/11.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMZgAAAUw"] [Tue Aug 18 13:07:00.710652 2026] [security2:error] [pid 157386:tid 157594] [client 158.23.17.4:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/dj.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMZwAAAVg"] [Tue Aug 18 13:07:00.713227 2026] [autoindex:error] [pid 157386:tid 157442] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:00.752483 2026] [security2:error] [pid 157386:tid 157606] [client 20.104.85.180:6015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/www.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMawAAAWQ"] [Tue Aug 18 13:07:00.755641 2026] [security2:error] [pid 157386:tid 157560] [client 20.116.17.175:22563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMbQAAATY"] [Tue Aug 18 13:07:00.770040 2026] [security2:error] [pid 157386:tid 157579] [client 40.74.65.169:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/vc.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMcgAAAUk"] [Tue Aug 18 13:07:00.773105 2026] [security2:error] [pid 157386:tid 157581] [client 168.62.48.100:18013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMcwAAAUs"] [Tue Aug 18 13:07:00.791270 2026] [security2:error] [pid 157386:tid 157575] [client 74.7.241.140:34486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "petstopclinicaveterinaria.com.br"] [uri "/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMMAABRS0"] [Tue Aug 18 13:07:00.833295 2026] [security2:error] [pid 157386:tid 157525] [client 157.20.138.62:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMfAAAARM"] [Tue Aug 18 13:07:00.833493 2026] [security2:error] [pid 157386:tid 157525] [client 157.20.138.62:51702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMfAAAARM"] [Tue Aug 18 13:07:00.851565 2026] [security2:error] [pid 157386:tid 157578] [client 135.225.75.187:11613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/nzv.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMfQAAAUg"] [Tue Aug 18 13:07:00.858518 2026] [security2:error] [pid 157386:tid 157605] [client 20.1.169.243:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/wp-help/index.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMgAAAAWM"] [Tue Aug 18 13:07:00.863891 2026] [security2:error] [pid 157386:tid 157539] [client 51.116.232.28:2631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/new.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMgwAAASE"] [Tue Aug 18 13:07:00.868577 2026] [security2:error] [pid 157386:tid 157518] [client 52.173.121.69:36583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/rymmm.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMiAAAAQw"] [Tue Aug 18 13:07:00.869008 2026] [security2:error] [pid 157386:tid 157591] [client 20.124.247.79:16696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/166.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMigAAAVU"] [Tue Aug 18 13:07:00.890097 2026] [security2:error] [pid 157386:tid 157426] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.github/.env"] [unique_id "aoSDJE1jzAhYHVVT1WcMiwABaSc"] [Tue Aug 18 13:07:00.914158 2026] [security2:error] [pid 157386:tid 157549] [client 158.158.74.177:20511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/media-new.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMlQAAASs"] [Tue Aug 18 13:07:00.979945 2026] [security2:error] [pid 157386:tid 157553] [client 104.209.144.33:31275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDJE1jzAhYHVVT1WcMnQAAAS8"] [Tue Aug 18 13:07:01.001231 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vm.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMogAAATo"] [Tue Aug 18 13:07:01.002573 2026] [security2:error] [pid 157386:tid 157557] [client 20.104.49.167:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/img.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMowAAATM"] [Tue Aug 18 13:07:01.033704 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.85.180:6008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wicked.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMpgAAAUI"] [Tue Aug 18 13:07:01.036240 2026] [security2:error] [pid 157386:tid 157566] [client 20.127.136.245:28136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/themes.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMpwAAATw"] [Tue Aug 18 13:07:01.039809 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:07:01.039841 2026] [http2:warn] [pid 139043:tid 139189] [client 201.32.74.208:56981] h2_stream(139043-532-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:07:01.052492 2026] [security2:error] [pid 157386:tid 157567] [client 20.65.98.162:43939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/aa.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMqgAAAT0"] [Tue Aug 18 13:07:01.055167 2026] [authz_core:error] [pid 157386:tid 157457] [remote 34.38.94.143:51990] AH01630: client denied by server configuration: /home4/filial35/public_html/josysantos/.htpasswd [Tue Aug 18 13:07:01.058254 2026] [autoindex:error] [pid 157386:tid 157559] [client 20.79.204.6:11562] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:01.069712 2026] [security2:error] [pid 157386:tid 157639] [client 4.232.151.198:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/.tmb/dropdown.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMrQAAAYU"] [Tue Aug 18 13:07:01.084578 2026] [security2:error] [pid 157386:tid 157619] [client 168.62.48.100:18113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMrgAAAXE"] [Tue Aug 18 13:07:01.158551 2026] [security2:error] [pid 157386:tid 157537] [client 20.124.247.79:16671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/file3.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMswAAAR8"] [Tue Aug 18 13:07:01.161251 2026] [security2:error] [pid 157386:tid 157586] [client 20.116.17.175:22576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/index2.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMtQAAAVA"] [Tue Aug 18 13:07:01.190801 2026] [autoindex:error] [pid 157386:tid 157410] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:01.204770 2026] [security2:error] [pid 157386:tid 157623] [client 20.226.36.136:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMuQAAAXU"] [Tue Aug 18 13:07:01.212207 2026] [security2:error] [pid 157386:tid 157422] [remote 47.128.35.22:52714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.autochampsveiculos.com.br"] [uri "/veiculo/616875/ecosport-se-1-5-12v-flex-5p-aut"] [unique_id "aoSDJU1jzAhYHVVT1WcMugABhyM"] [Tue Aug 18 13:07:01.215568 2026] [security2:error] [pid 157386:tid 157539] [client 20.151.109.219:36720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ve.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMuwAAASE"] [Tue Aug 18 13:07:01.217353 2026] [security2:error] [pid 157386:tid 157585] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/video.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMvAAAAU8"] [Tue Aug 18 13:07:01.228831 2026] [security2:error] [pid 157386:tid 157592] [client 178.153.171.161:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMvwAAAVY"] [Tue Aug 18 13:07:01.228952 2026] [security2:error] [pid 157386:tid 157592] [client 178.153.171.161:53608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMvwAAAVY"] [Tue Aug 18 13:07:01.251154 2026] [lsapi:warn] [pid 157386:tid 157621] [client 162.241.203.17:25516] [host terrassis.com.br] Backend log: PHP Warning: Failed to set memory limit to 512 bytes (Current memory usage is 2097152 bytes) in Unknown on line 0\n [Tue Aug 18 13:07:01.257714 2026] [security2:error] [pid 157386:tid 157574] [client 20.79.204.6:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMwwAAAUQ"] [Tue Aug 18 13:07:01.257893 2026] [security2:error] [pid 157386:tid 157640] [client 20.116.17.175:20474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/v2.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMxAAAAYY"] [Tue Aug 18 13:07:01.259220 2026] [security2:error] [pid 157386:tid 157642] [client 20.1.169.243:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMxQAAAYg"] [Tue Aug 18 13:07:01.270394 2026] [security2:error] [pid 157386:tid 157627] [client 135.225.75.187:12065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/error1.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMxwAAAXk"] [Tue Aug 18 13:07:01.281782 2026] [security2:error] [pid 157386:tid 157562] [client 20.151.109.219:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/eg.php"] [unique_id "aoSDJU1jzAhYHVVT1WcMygAAATg"] [Tue Aug 18 13:07:01.299603 2026] [security2:error] [pid 157386:tid 157503] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.ssh/id_rsa"] [unique_id "aoSDJU1jzAhYHVVT1WcMzgABVXQ"] [Tue Aug 18 13:07:01.300023 2026] [security2:error] [pid 157386:tid 157628] [client 51.116.232.28:2990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/new.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM0AAAAXo"] [Tue Aug 18 13:07:01.305665 2026] [security2:error] [pid 157386:tid 157589] [client 52.173.121.69:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM0QAAAVM"] [Tue Aug 18 13:07:01.326046 2026] [security2:error] [pid 157386:tid 157604] [client 20.251.48.93:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/i.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM1AAAAWI"] [Tue Aug 18 13:07:01.327495 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.85.180:5996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM1QAAAS8"] [Tue Aug 18 13:07:01.338527 2026] [security2:error] [pid 157386:tid 157541] [client 213.35.127.232:59507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM2wAAASM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:01.340547 2026] [security2:error] [pid 157386:tid 157541] [client 52.173.121.69:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/lddxs.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM4gAAASM"] [Tue Aug 18 13:07:01.342010 2026] [security2:error] [pid 157386:tid 157557] [client 20.116.17.175:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/water.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM5AAAATM"] [Tue Aug 18 13:07:01.350882 2026] [security2:error] [pid 157386:tid 157582] [client 168.62.48.100:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM5QAAAUw"] [Tue Aug 18 13:07:01.365404 2026] [security2:error] [pid 157386:tid 157603] [client 20.104.49.167:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/222.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM5wAAAWE"] [Tue Aug 18 13:07:01.387274 2026] [security2:error] [pid 157386:tid 157558] [client 20.65.69.59:35397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/admin404.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM6QAAATQ"] [Tue Aug 18 13:07:01.405918 2026] [security2:error] [pid 157386:tid 157559] [client 20.124.247.79:15335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/y.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM7AAAATU"] [Tue Aug 18 13:07:01.438550 2026] [security2:error] [pid 157386:tid 157601] [client 102.213.179.104:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM7gAAAV8"] [Tue Aug 18 13:07:01.438787 2026] [security2:error] [pid 157386:tid 157601] [client 102.213.179.104:53370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM7gAAAV8"] [Tue Aug 18 13:07:01.452015 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:17063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/of.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM7wAAAXw"] [Tue Aug 18 13:07:01.467555 2026] [security2:error] [pid 157386:tid 157606] [client 40.74.65.169:4598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/pema.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM8QAAAWQ"] [Tue Aug 18 13:07:01.470088 2026] [security2:error] [pid 157386:tid 157584] [client 20.226.36.136:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM8gAAAU4"] [Tue Aug 18 13:07:01.510600 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:01.510918 2026] [authz_core:error] [pid 157386:tid 157404] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:01.522131 2026] [security2:error] [pid 157386:tid 157614] [client 20.215.241.237:17809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/thoms.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM9QAAAWw"] [Tue Aug 18 13:07:01.530599 2026] [security2:error] [pid 157386:tid 157489] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.ssh/id_dsa"] [unique_id "aoSDJU1jzAhYHVVT1WcM9gABGGY"] [Tue Aug 18 13:07:01.540030 2026] [fcgid:warn] [pid 157386:tid 157539] (70014)End of file found: [client 199.45.154.123:50434] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:01.557169 2026] [lsapi:warn] [pid 157386:tid 157621] [client 162.241.203.17:25532] [host terrassis.com.br] Backend log: PHP Warning: Failed to set memory limit to 512 bytes (Current memory usage is 10485760 bytes) in Unknown on line 0\n [Tue Aug 18 13:07:01.558259 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ia.php"] [unique_id "aoSDJU1jzAhYHVVT1WcM_QAAAUE"] [Tue Aug 18 13:07:01.575592 2026] [security2:error] [pid 157386:tid 157640] [client 20.151.109.219:5342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/uk.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNAAAAAYY"] [Tue Aug 18 13:07:01.584423 2026] [security2:error] [pid 157386:tid 157627] [client 20.116.17.175:1116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/8.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNAgAAAXk"] [Tue Aug 18 13:07:01.610728 2026] [security2:error] [pid 157386:tid 157542] [client 20.104.85.180:6006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNBQAAASQ"] [Tue Aug 18 13:07:01.622683 2026] [security2:error] [pid 157386:tid 157562] [client 168.62.48.100:18098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNBgAAATg"] [Tue Aug 18 13:07:01.633877 2026] [security2:error] [pid 157386:tid 157525] [client 20.1.169.243:15595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNBwAAARM"] [Tue Aug 18 13:07:01.648839 2026] [security2:error] [pid 157386:tid 157619] [client 158.158.74.177:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNCgAAAXE"] [Tue Aug 18 13:07:01.666702 2026] [security2:error] [pid 157386:tid 157589] [client 52.173.121.69:36605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/zjggu.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNCwAAAVM"] [Tue Aug 18 13:07:01.686380 2026] [security2:error] [pid 157386:tid 157543] [client 74.248.18.37:32464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/indexmat_crea.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNDwAAASU"] [Tue Aug 18 13:07:01.692276 2026] [security2:error] [pid 157386:tid 157463] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/id_rsa"] [unique_id "aoSDJU1jzAhYHVVT1WcNEQABM0w"] [Tue Aug 18 13:07:01.692293 2026] [security2:error] [pid 157386:tid 157554] [client 135.225.75.187:31836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/155.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNEgAAATA"] [Tue Aug 18 13:07:01.706809 2026] [security2:error] [pid 157386:tid 157600] [client 20.124.247.79:16692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/modric8QWQCC.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNEwAAAV4"] [Tue Aug 18 13:07:01.716910 2026] [security2:error] [pid 157386:tid 157550] [client 51.89.129.28:16460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gramadoboutiqueeventos.com.br"] [uri "/robots.txt"] [unique_id "aoSDJU1jzAhYHVVT1WcNFAAAASw"] [Tue Aug 18 13:07:01.716985 2026] [security2:error] [pid 157386:tid 157550] [client 51.89.129.28:16460] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gramadoboutiqueeventos.com.br"] [uri "/robots.txt"] [unique_id "aoSDJU1jzAhYHVVT1WcNFAAAASw"] [Tue Aug 18 13:07:01.722749 2026] [security2:error] [pid 157386:tid 157567] [client 51.116.232.28:2647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/apreset.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNFQAAAT0"] [Tue Aug 18 13:07:01.749025 2026] [security2:error] [pid 157386:tid 157392] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/id_dsa"] [unique_id "aoSDJU1jzAhYHVVT1WcNFwABXwU"] [Tue Aug 18 13:07:01.772237 2026] [security2:error] [pid 157386:tid 157613] [client 20.127.136.245:28260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/cv.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNGgAAAWs"] [Tue Aug 18 13:07:01.784177 2026] [security2:error] [pid 157386:tid 157535] [client 20.251.48.93:14698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/abcd.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNHAAAAR0"] [Tue Aug 18 13:07:01.789525 2026] [security2:error] [pid 157386:tid 157580] [client 158.23.17.4:42568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fa.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNHQAAAUo"] [Tue Aug 18 13:07:01.791985 2026] [security2:error] [pid 157386:tid 157576] [client 20.104.49.167:16023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/key.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNHgAAAUY"] [Tue Aug 18 13:07:01.811511 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:01.811794 2026] [authz_core:error] [pid 157386:tid 157474] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:01.832426 2026] [autoindex:error] [pid 157386:tid 157468] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:01.842469 2026] [security2:error] [pid 157386:tid 157637] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/hel.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNJAAAAYM"] [Tue Aug 18 13:07:01.859444 2026] [security2:error] [pid 157386:tid 157628] [client 20.79.204.6:11669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNJQAAAXo"] [Tue Aug 18 13:07:01.868069 2026] [security2:error] [pid 157386:tid 157623] [client 168.62.48.100:17957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNJgAAAXU"] [Tue Aug 18 13:07:01.874936 2026] [security2:error] [pid 157386:tid 157605] [client 68.221.73.131:41356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/File.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNJwAAAWM"] [Tue Aug 18 13:07:01.891390 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:5936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/cah.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNKQAAAVY"] [Tue Aug 18 13:07:01.911085 2026] [security2:error] [pid 157386:tid 157524] [client 20.171.51.14:20870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ns.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNLAAAARI"] [Tue Aug 18 13:07:01.979623 2026] [security2:error] [pid 157386:tid 157551] [client 20.151.109.219:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/creds.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNMwAAAS0"] [Tue Aug 18 13:07:01.997848 2026] [security2:error] [pid 157386:tid 157641] [client 20.1.169.243:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "aoSDJU1jzAhYHVVT1WcNNwAAAYc"] [Tue Aug 18 13:07:02.013567 2026] [security2:error] [pid 157386:tid 157530] [client 20.116.17.175:1600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/images.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNPQAAARg"] [Tue Aug 18 13:07:02.108296 2026] [security2:error] [pid 157386:tid 157584] [client 135.225.75.187:11608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fasx.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNSQAAAU4"] [Tue Aug 18 13:07:02.117115 2026] [security2:error] [pid 157386:tid 157541] [client 20.104.49.167:14159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/chosen.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNSgAAASM"] [Tue Aug 18 13:07:02.122049 2026] [security2:error] [pid 157386:tid 157581] [client 51.116.232.28:2636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/1mage.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNSwAAAUs"] [Tue Aug 18 13:07:02.129510 2026] [security2:error] [pid 157386:tid 157521] [client 20.151.109.219:40507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kn.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNTAAAAQ8"] [Tue Aug 18 13:07:02.133292 2026] [security2:error] [pid 157386:tid 157537] [client 4.232.151.198:22290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNTQAAAR8"] [Tue Aug 18 13:07:02.133352 2026] [security2:error] [pid 157386:tid 157516] [client 20.104.100.201:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/crgio.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNTgAAAQo"] [Tue Aug 18 13:07:02.141687 2026] [security2:error] [pid 157386:tid 157520] [client 20.124.247.79:15332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/modric7Z7J2X.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNUgAAAQ4"] [Tue Aug 18 13:07:02.157672 2026] [security2:error] [pid 157386:tid 157573] [client 168.62.48.100:18001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNUwAAAUM"] [Tue Aug 18 13:07:02.161054 2026] [security2:error] [pid 157386:tid 157618] [client 20.116.17.175:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wkl.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNVAAAAXA"] [Tue Aug 18 13:07:02.166788 2026] [security2:error] [pid 157386:tid 157628] [client 20.226.36.136:62175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNVQAAAXo"] [Tue Aug 18 13:07:02.170007 2026] [security2:error] [pid 157386:tid 157590] [client 40.74.65.169:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/sh.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNVgAAAVQ"] [Tue Aug 18 13:07:02.183518 2026] [security2:error] [pid 157386:tid 157587] [client 20.116.17.175:58427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/fine.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNWAAAAVE"] [Tue Aug 18 13:07:02.193558 2026] [security2:error] [pid 157386:tid 157605] [client 20.104.85.180:5952] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aoSDJk1jzAhYHVVT1WcNWgAAAWM"] [Tue Aug 18 13:07:02.237756 2026] [security2:error] [pid 157386:tid 157635] [client 20.65.69.59:21175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/loading.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNXwAAAYE"] [Tue Aug 18 13:07:02.244435 2026] [security2:error] [pid 157386:tid 157532] [client 104.209.144.33:32673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNYAAAARo"] [Tue Aug 18 13:07:02.292007 2026] [autoindex:error] [pid 157386:tid 157496] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:02.296028 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:39809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ho.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNZwAAAWE"] [Tue Aug 18 13:07:02.305959 2026] [security2:error] [pid 157386:tid 157529] [client 158.158.74.177:9331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNaQAAARc"] [Tue Aug 18 13:07:02.321109 2026] [security2:error] [pid 157386:tid 157607] [client 20.251.48.93:44356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNawAAAWU"] [Tue Aug 18 13:07:02.347431 2026] [security2:error] [pid 157386:tid 157629] [client 158.23.17.4:63022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/fb.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNbgAAAXs"] [Tue Aug 18 13:07:02.357471 2026] [security2:error] [pid 157386:tid 157387] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/key.pem"] [unique_id "aoSDJk1jzAhYHVVT1WcNbwABMAA"] [Tue Aug 18 13:07:02.358169 2026] [security2:error] [pid 157386:tid 157602] [client 213.35.127.232:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNcAAAAWA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:02.367748 2026] [security2:error] [pid 157386:tid 157571] [client 20.1.169.243:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/414.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNcwAAAUE"] [Tue Aug 18 13:07:02.369087 2026] [security2:error] [pid 157386:tid 157457] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/privatekey.key"] [unique_id "aoSDJk1jzAhYHVVT1WcNcgABMEY"] [Tue Aug 18 13:07:02.405261 2026] [security2:error] [pid 157386:tid 157606] [client 20.127.136.245:27968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNdgAAAWQ"] [Tue Aug 18 13:07:02.411230 2026] [security2:error] [pid 157386:tid 157535] [client 52.173.121.69:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNeAAAAR0"] [Tue Aug 18 13:07:02.411858 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.100.201:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/f35.update.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNeQAAATY"] [Tue Aug 18 13:07:02.421409 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:02.421705 2026] [authz_core:error] [pid 157386:tid 157448] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:02.433868 2026] [security2:error] [pid 157386:tid 157580] [client 168.62.48.100:18089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.autocarmult.com.br"] [uri "/images/security.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNewAAAUo"] [Tue Aug 18 13:07:02.454518 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:22608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/a.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNfQAAAUs"] [Tue Aug 18 13:07:02.465145 2026] [security2:error] [pid 157386:tid 157526] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/grok.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNfgAAARQ"] [Tue Aug 18 13:07:02.471355 2026] [security2:error] [pid 157386:tid 157531] [client 20.124.247.79:16678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/modricXP4D68.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNgAAAARk"] [Tue Aug 18 13:07:02.484935 2026] [security2:error] [pid 157386:tid 157619] [client 20.79.204.6:11676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNgQAAAXE"] [Tue Aug 18 13:07:02.523854 2026] [security2:error] [pid 157386:tid 157521] [client 138.36.100.162:41853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNhgAAAQ8"] [Tue Aug 18 13:07:02.523983 2026] [security2:error] [pid 157386:tid 157521] [client 138.36.100.162:41853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNhgAAAQ8"] [Tue Aug 18 13:07:02.529252 2026] [security2:error] [pid 157386:tid 157563] [client 135.225.75.187:35738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-good.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNhwAAATk"] [Tue Aug 18 13:07:02.534125 2026] [security2:error] [pid 157386:tid 157628] [client 51.116.232.28:3043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/imsc.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNiAAAAXo"] [Tue Aug 18 13:07:02.539535 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:36707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wm.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNiQAAAVQ"] [Tue Aug 18 13:07:02.576432 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:6021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/system_log.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNjAAAAVY"] [Tue Aug 18 13:07:02.604370 2026] [security2:error] [pid 157386:tid 157634] [client 20.104.100.201:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNjwAAAYA"] [Tue Aug 18 13:07:02.620607 2026] [http2:warn] [pid 139043:tid 139191] [client 201.32.74.208:57070] h2_stream(139043-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:07:02.631080 2026] [security2:error] [pid 157386:tid 157642] [client 20.151.109.219:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/97.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNkQAAAYg"] [Tue Aug 18 13:07:02.652730 2026] [http2:warn] [pid 157386:tid 157608] [client 201.32.74.208:57204] h2_stream(157386-520-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:07:02.688115 2026] [autoindex:error] [pid 157386:tid 157458] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:02.714204 2026] [security2:error] [pid 157386:tid 157525] [client 20.206.73.37:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/nano.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNmAAAARM"] [Tue Aug 18 13:07:02.735139 2026] [security2:error] [pid 157386:tid 157394] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.openclaw/.env"] [unique_id "aoSDJk1jzAhYHVVT1WcNmgABTwc"] [Tue Aug 18 13:07:02.738040 2026] [security2:error] [pid 157386:tid 157589] [client 20.171.51.14:36287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/gk.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNmwAAAVM"] [Tue Aug 18 13:07:02.750465 2026] [security2:error] [pid 157386:tid 157551] [client 20.1.169.243:15754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/gbaun.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNnAAAAS0"] [Tue Aug 18 13:07:02.789588 2026] [security2:error] [pid 157386:tid 157607] [client 20.215.241.237:63839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/wpxml.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNnQAAAWU"] [Tue Aug 18 13:07:02.820921 2026] [security2:error] [pid 157386:tid 157532] [client 4.232.151.198:5390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/network/file.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNoQAAARo"] [Tue Aug 18 13:07:02.841397 2026] [security2:error] [pid 157386:tid 157520] [client 74.248.18.37:24973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/geju.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNowAAAQ4"] [Tue Aug 18 13:07:02.842321 2026] [security2:error] [pid 157386:tid 157601] [client 20.65.69.59:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/conn-test.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNpAAAAV8"] [Tue Aug 18 13:07:02.847319 2026] [security2:error] [pid 157386:tid 157602] [client 40.74.65.169:4425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/button.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNpgAAAWA"] [Tue Aug 18 13:07:02.849870 2026] [security2:error] [pid 157386:tid 157584] [client 20.116.17.175:45259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNpwAAAU4"] [Tue Aug 18 13:07:02.857284 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:21911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bu.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNqQAAAR0"] [Tue Aug 18 13:07:02.863632 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.36.136:62191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/well-known/index.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNqwAAAUo"] [Tue Aug 18 13:07:02.864035 2026] [security2:error] [pid 157386:tid 157576] [client 20.116.17.175:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNrAAAAUY"] [Tue Aug 18 13:07:02.902783 2026] [security2:error] [pid 157386:tid 157567] [client 20.127.136.245:28125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ws83.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNtQAAAT0"] [Tue Aug 18 13:07:02.905762 2026] [security2:error] [pid 157386:tid 157556] [client 104.209.144.33:31244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNtgAAATI"] [Tue Aug 18 13:07:02.912003 2026] [security2:error] [pid 157386:tid 157554] [client 20.124.247.79:16711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.patiojardinsma.com.br"] [uri "/clara.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNuAAAATA"] [Tue Aug 18 13:07:02.934337 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/loader.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNuwAAATk"] [Tue Aug 18 13:07:02.938535 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.85.180:5964] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-includes/pomo/"] [unique_id "aoSDJk1jzAhYHVVT1WcNvAAAAXo"] [Tue Aug 18 13:07:02.939111 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:5801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/rh.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNvQAAAVQ"] [Tue Aug 18 13:07:02.948168 2026] [security2:error] [pid 157386:tid 157587] [client 135.225.75.187:23851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/zxin.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNvgAAAVE"] [Tue Aug 18 13:07:02.949181 2026] [security2:error] [pid 157386:tid 157636] [client 51.116.232.28:2686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNvwAAAYI"] [Tue Aug 18 13:07:02.954418 2026] [security2:error] [pid 157386:tid 157419] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/core/.env"] [unique_id "aoSDJk1jzAhYHVVT1WcNwAABZCA"] [Tue Aug 18 13:07:02.968898 2026] [security2:error] [pid 157386:tid 157586] [client 20.104.49.167:8651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/thoms.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNxQAAAVA"] [Tue Aug 18 13:07:02.969831 2026] [security2:error] [pid 157386:tid 157582] [client 158.158.74.177:25002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSDJk1jzAhYHVVT1WcNxgAAAUw"] [Tue Aug 18 13:07:02.986093 2026] [lsapi:warn] [pid 157386:tid 157545] [client 62.197.45.179:58565] [host terrassis.com.br] Backend log: PHP Warning: Failed to set memory limit to 512 bytes (Current memory usage is 23068672 bytes) in Unknown on line 0\n, referer: https://terrassis.com.br/ [Tue Aug 18 13:07:03.010696 2026] [security2:error] [pid 157386:tid 157508] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/config.php.bak"] [unique_id "aoSDJ01jzAhYHVVT1WcNyQABZHk"] [Tue Aug 18 13:07:03.013432 2026] [authz_core:error] [pid 157386:tid 157484] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:03.013683 2026] [authz_core:error] [pid 157386:tid 157484] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:03.022044 2026] [security2:error] [pid 157386:tid 157643] [client 20.251.48.93:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDJ01jzAhYHVVT1WcNywAAAYk"] [Tue Aug 18 13:07:03.079991 2026] [security2:error] [pid 157386:tid 157642] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/indes.php"] [unique_id "aoSDJ01jzAhYHVVT1WcNzAAAAYg"] [Tue Aug 18 13:07:03.122201 2026] [security2:error] [pid 157386:tid 157597] [client 20.1.169.243:15947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/themes.php"] [unique_id "aoSDJ01jzAhYHVVT1WcNzwAAAVs"] [Tue Aug 18 13:07:03.130988 2026] [autoindex:error] [pid 157386:tid 157521] [client 20.79.204.6:11689] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:03.140100 2026] [security2:error] [pid 157386:tid 157609] [client 20.104.100.201:54059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/css.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN0gAAAWc"] [Tue Aug 18 13:07:03.140556 2026] [security2:error] [pid 157386:tid 157561] [client 54.39.203.197:42132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gramadoboutiqueeventos.com.br"] [uri "/"] [unique_id "aoSDJ01jzAhYHVVT1WcN0wAAATc"] [Tue Aug 18 13:07:03.140627 2026] [security2:error] [pid 157386:tid 157561] [client 54.39.203.197:42132] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gramadoboutiqueeventos.com.br"] [uri "/"] [unique_id "aoSDJ01jzAhYHVVT1WcN0wAAATc"] [Tue Aug 18 13:07:03.255859 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:46421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/yg.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN1gAAAUo"] [Tue Aug 18 13:07:03.272095 2026] [autoindex:error] [pid 157386:tid 157461] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:03.275739 2026] [security2:error] [pid 157386:tid 157531] [client 20.104.49.167:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/wpxml.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN2QAAARk"] [Tue Aug 18 13:07:03.298278 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.85.180:5888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN3AAAAUs"] [Tue Aug 18 13:07:03.315531 2026] [security2:error] [pid 157386:tid 157554] [client 20.116.17.175:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/99.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN3gAAATA"] [Tue Aug 18 13:07:03.317778 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:03.318216 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:03.337242 2026] [security2:error] [pid 157386:tid 157435] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.hermes/.env"] [unique_id "aoSDJ01jzAhYHVVT1WcN4QABdDA"] [Tue Aug 18 13:07:03.343337 2026] [security2:error] [pid 157386:tid 157438] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/configuration.php.bak"] [unique_id "aoSDJ01jzAhYHVVT1WcN4gABdDM"] [Tue Aug 18 13:07:03.345932 2026] [security2:error] [pid 157386:tid 157441] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/.env.swp"] [unique_id "aoSDJ01jzAhYHVVT1WcN4wABdDY"] [Tue Aug 18 13:07:03.367897 2026] [security2:error] [pid 157386:tid 157628] [client 135.225.75.187:23864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/pass4.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN5gAAAXo"] [Tue Aug 18 13:07:03.371093 2026] [security2:error] [pid 157386:tid 157611] [client 213.35.127.232:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN5wAAAWk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:03.382602 2026] [security2:error] [pid 157386:tid 157593] [client 51.116.232.28:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/qlex1.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN6gAAAVc"] [Tue Aug 18 13:07:03.449357 2026] [security2:error] [pid 157386:tid 157635] [client 52.173.121.69:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/first.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN7AAAAYE"] [Tue Aug 18 13:07:03.495650 2026] [security2:error] [pid 157386:tid 157590] [client 20.1.169.243:15774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/wpr-addons/forms/RxRzhwix.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN7wAAAVQ"] [Tue Aug 18 13:07:03.519757 2026] [security2:error] [pid 157386:tid 157542] [client 20.151.109.219:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ac.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN8AAAASQ"] [Tue Aug 18 13:07:03.523601 2026] [security2:error] [pid 157386:tid 157643] [client 40.74.65.169:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/wlc.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN8QAAAYk"] [Tue Aug 18 13:07:03.544510 2026] [security2:error] [pid 157386:tid 157630] [client 20.127.136.245:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/atex1.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN8wAAAXw"] [Tue Aug 18 13:07:03.552513 2026] [security2:error] [pid 157386:tid 157640] [client 20.79.204.6:11689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN9gAAAYY"] [Tue Aug 18 13:07:03.563222 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/et.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN-AAAAXk"] [Tue Aug 18 13:07:03.580039 2026] [security2:error] [pid 157386:tid 157561] [client 20.104.85.180:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDJ01jzAhYHVVT1WcN-QAAATc"] [Tue Aug 18 13:07:03.593785 2026] [security2:error] [pid 157386:tid 157473] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/public/.env"] [unique_id "aoSDJ01jzAhYHVVT1WcN_AABGFY"] [Tue Aug 18 13:07:03.613159 2026] [security2:error] [pid 157386:tid 157453] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/web/.env"] [unique_id "aoSDJ01jzAhYHVVT1WcN_wABGEI"] [Tue Aug 18 13:07:03.616919 2026] [security2:error] [pid 157386:tid 157587] [client 158.158.74.177:20488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOAAAAAVE"] [Tue Aug 18 13:07:03.641756 2026] [security2:error] [pid 157386:tid 157543] [client 20.116.17.175:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/zero.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOAwAAASU"] [Tue Aug 18 13:07:03.686500 2026] [autoindex:error] [pid 157386:tid 157455] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:03.698382 2026] [security2:error] [pid 157386:tid 157589] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOBgAAAVM"] [Tue Aug 18 13:07:03.703833 2026] [security2:error] [pid 157386:tid 157551] [client 20.116.17.175:22602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/yup.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOBwAAAS0"] [Tue Aug 18 13:07:03.704578 2026] [security2:error] [pid 157386:tid 157574] [client 4.232.151.198:18960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/upgrade/alfa.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOCAAAAUQ"] [Tue Aug 18 13:07:03.704712 2026] [security2:error] [pid 157386:tid 157600] [client 20.151.109.219:27744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/rn.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOCQAAAV4"] [Tue Aug 18 13:07:03.730366 2026] [security2:error] [pid 157386:tid 157591] [client 20.104.49.167:13598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/file1221.php"] [unique_id "aoSDJ01jzAhYHVVT1WcODgAAAVU"] [Tue Aug 18 13:07:03.742069 2026] [security2:error] [pid 157386:tid 157532] [client 20.251.48.93:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDJ01jzAhYHVVT1WcODwAAARo"] [Tue Aug 18 13:07:03.742440 2026] [security2:error] [pid 157386:tid 157629] [client 20.65.69.59:1728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/evil.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOEAAAAXs"] [Tue Aug 18 13:07:03.786605 2026] [security2:error] [pid 157386:tid 157575] [client 213.202.253.4:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/delpaths.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOEQAAAUU"], referer: www.google.com [Tue Aug 18 13:07:03.788993 2026] [security2:error] [pid 157386:tid 157613] [client 51.116.232.28:2980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/mariju.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOEgAAAWs"] [Tue Aug 18 13:07:03.789154 2026] [security2:error] [pid 157386:tid 157547] [client 135.225.75.187:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOEwAAASk"] [Tue Aug 18 13:07:03.816584 2026] [security2:error] [pid 157386:tid 157580] [client 20.116.17.175:20440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/az.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOFwAAAUo"] [Tue Aug 18 13:07:03.830765 2026] [security2:error] [pid 157386:tid 157562] [client 103.120.71.157:55630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOGQAAATg"] [Tue Aug 18 13:07:03.830951 2026] [security2:error] [pid 157386:tid 157562] [client 103.120.71.157:55630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOGQAAATg"] [Tue Aug 18 13:07:03.843241 2026] [security2:error] [pid 157386:tid 157516] [client 104.209.144.33:31273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOGwAAAQo"] [Tue Aug 18 13:07:03.867341 2026] [security2:error] [pid 157386:tid 157553] [client 20.104.100.201:53832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOHQAAAS8"] [Tue Aug 18 13:07:03.879126 2026] [security2:error] [pid 157386:tid 157628] [client 20.104.85.180:5898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/abc.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOIAAAAXo"] [Tue Aug 18 13:07:03.918685 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.36.136:48885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOJgAAAVA"] [Tue Aug 18 13:07:03.922539 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:03.922990 2026] [authz_core:error] [pid 157386:tid 157406] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:03.927131 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:7346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/of.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOJwAAAUw"] [Tue Aug 18 13:07:03.967021 2026] [security2:error] [pid 157386:tid 157531] [client 20.1.169.243:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/wpr-addons/forms/b1ack.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOKQAAARk"] [Tue Aug 18 13:07:04.000940 2026] [security2:error] [pid 157386:tid 157542] [client 20.65.98.162:37688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/av.php"] [unique_id "aoSDJ01jzAhYHVVT1WcOKgAAASQ"] [Tue Aug 18 13:07:04.028476 2026] [security2:error] [pid 157386:tid 157554] [client 20.127.136.245:28231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOLAAAATA"] [Tue Aug 18 13:07:04.061685 2026] [security2:error] [pid 157386:tid 157612] [client 20.226.36.136:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOLwAAAWo"] [Tue Aug 18 13:07:04.079035 2026] [security2:error] [pid 157386:tid 157606] [client 197.184.64.235:42685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOMQAAAWQ"] [Tue Aug 18 13:07:04.079135 2026] [security2:error] [pid 157386:tid 157606] [client 197.184.64.235:42685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOMQAAAWQ"] [Tue Aug 18 13:07:04.088335 2026] [autoindex:error] [pid 157386:tid 157403] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:04.111704 2026] [security2:error] [pid 157386:tid 157491] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "josysantos.filialweb.com"] [uri "/wp-config.php.bak"] [unique_id "aoSDKE1jzAhYHVVT1WcOMgABXGg"] [Tue Aug 18 13:07:04.138168 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.18.37:32451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/maro.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOMwAAAWk"] [Tue Aug 18 13:07:04.154630 2026] [security2:error] [pid 157386:tid 157449] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "josysantos.filialweb.com"] [uri "/wp-config.php.old"] [unique_id "aoSDKE1jzAhYHVVT1WcONAABLj4"] [Tue Aug 18 13:07:04.169823 2026] [autoindex:error] [pid 157386:tid 157539] [client 20.79.204.6:11706] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:04.186919 2026] [security2:error] [pid 157386:tid 157522] [client 52.173.121.69:36603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/dlvqo.php"] [unique_id "aoSDKE1jzAhYHVVT1WcONgAAARA"] [Tue Aug 18 13:07:04.188118 2026] [security2:error] [pid 157386:tid 157537] [client 51.116.232.28:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDKE1jzAhYHVVT1WcONwAAAR8"] [Tue Aug 18 13:07:04.188132 2026] [security2:error] [pid 157386:tid 157516] [client 20.104.85.180:5980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/akcc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOOAAAAQo"] [Tue Aug 18 13:07:04.190021 2026] [security2:error] [pid 157386:tid 157623] [client 20.116.17.175:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/002.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOOQAAAXU"] [Tue Aug 18 13:07:04.190472 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.49.167:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/nox.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOOgAAATY"] [Tue Aug 18 13:07:04.200110 2026] [security2:error] [pid 157386:tid 157545] [client 20.151.109.219:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ut.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOOwAAASc"] [Tue Aug 18 13:07:04.208459 2026] [security2:error] [pid 157386:tid 157631] [client 135.225.75.187:23818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/z.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOPQAAAX0"] [Tue Aug 18 13:07:04.211824 2026] [security2:error] [pid 157386:tid 157628] [client 40.74.65.169:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/fi.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOPgAAAXo"] [Tue Aug 18 13:07:04.215675 2026] [security2:error] [pid 157386:tid 157593] [client 20.116.17.175:20376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/z43agz.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOQAAAAVc"] [Tue Aug 18 13:07:04.228411 2026] [security2:error] [pid 157386:tid 157511] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/.env.php.bak"] [unique_id "aoSDKE1jzAhYHVVT1WcOQgABUHw"] [Tue Aug 18 13:07:04.233496 2026] [security2:error] [pid 157386:tid 157400] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/config/.env.php"] [unique_id "aoSDKE1jzAhYHVVT1WcORAABdA0"] [Tue Aug 18 13:07:04.233813 2026] [security2:error] [pid 157386:tid 157640] [client 158.158.74.177:20516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/ebs.php7"] [unique_id "aoSDKE1jzAhYHVVT1WcORQAAAYY"] [Tue Aug 18 13:07:04.237771 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/bu.php"] [unique_id "aoSDKE1jzAhYHVVT1WcORgAAAUw"] [Tue Aug 18 13:07:04.250565 2026] [security2:error] [pid 157386:tid 157387] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/laravel/.env"] [unique_id "aoSDKE1jzAhYHVVT1WcORwABdAA"] [Tue Aug 18 13:07:04.327673 2026] [security2:error] [pid 157386:tid 157524] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/bs1.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOTQAAARI"] [Tue Aug 18 13:07:04.335403 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:15959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOTgAAATk"] [Tue Aug 18 13:07:04.339420 2026] [security2:error] [pid 157386:tid 157639] [client 20.215.241.237:16950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/file1221.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOUAAAAYU"] [Tue Aug 18 13:07:04.371118 2026] [security2:error] [pid 157386:tid 157549] [client 20.79.204.6:11706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOUgAAASs"] [Tue Aug 18 13:07:04.389688 2026] [security2:error] [pid 157386:tid 157529] [client 213.35.127.232:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOVAAAARc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:04.396003 2026] [security2:error] [pid 157386:tid 157530] [client 4.232.151.198:18996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOUwAAARg"] [Tue Aug 18 13:07:04.403884 2026] [security2:error] [pid 157386:tid 157535] [client 20.116.17.175:22535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/222.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOVQAAAR0"] [Tue Aug 18 13:07:04.436042 2026] [security2:error] [pid 157386:tid 157564] [client 52.173.121.69:11020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOVgAAATo"] [Tue Aug 18 13:07:04.455375 2026] [security2:error] [pid 157386:tid 157603] [client 20.171.51.14:23149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wn.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOVwAAAWE"] [Tue Aug 18 13:07:04.465018 2026] [security2:error] [pid 157386:tid 157585] [client 20.104.85.180:5898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wk/index.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOWAAAAU8"] [Tue Aug 18 13:07:04.469056 2026] [security2:error] [pid 157386:tid 157589] [client 20.226.36.136:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOWQAAAVM"] [Tue Aug 18 13:07:04.523657 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:04.523965 2026] [authz_core:error] [pid 157386:tid 157433] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:04.556661 2026] [security2:error] [pid 157386:tid 157554] [client 20.127.136.245:28132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/w.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOYgAAATA"] [Tue Aug 18 13:07:04.574343 2026] [security2:error] [pid 157386:tid 157613] [client 20.151.109.219:7378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/rn.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOZAAAAWs"] [Tue Aug 18 13:07:04.589196 2026] [security2:error] [pid 157386:tid 157547] [client 20.65.69.59:1316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/wp-key.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOZwAAASk"] [Tue Aug 18 13:07:04.609857 2026] [security2:error] [pid 157386:tid 157522] [client 20.116.17.175:58198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/zxz.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOagAAARA"] [Tue Aug 18 13:07:04.618782 2026] [security2:error] [pid 157386:tid 157516] [client 51.116.232.28:2654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/contacto.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOawAAAQo"] [Tue Aug 18 13:07:04.629376 2026] [security2:error] [pid 157386:tid 157560] [client 135.225.75.187:11626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/222.php"] [unique_id "aoSDKE1jzAhYHVVT1WcObAAAATY"] [Tue Aug 18 13:07:04.644488 2026] [security2:error] [pid 157386:tid 157631] [client 20.116.17.175:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/3.php"] [unique_id "aoSDKE1jzAhYHVVT1WcObQAAAX0"] [Tue Aug 18 13:07:04.654638 2026] [security2:error] [pid 157386:tid 157410] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDKE1jzAhYHVVT1WcObwABPRc"] [Tue Aug 18 13:07:04.712959 2026] [security2:error] [pid 157386:tid 157580] [client 20.1.169.243:15783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOcgAAAUo"] [Tue Aug 18 13:07:04.715420 2026] [security2:error] [pid 157386:tid 157401] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOcwABhg4"] [Tue Aug 18 13:07:04.715573 2026] [security2:error] [pid 157386:tid 157640] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOcwABhg4"] [Tue Aug 18 13:07:04.720342 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/yz.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOdAAAAUw"] [Tue Aug 18 13:07:04.747238 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:5968] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/1.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOdQAAAVY"] [Tue Aug 18 13:07:04.747389 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.85.180:5968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/1.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOdQAAAVY"] [Tue Aug 18 13:07:04.753374 2026] [security2:error] [pid 157386:tid 157618] [client 20.251.48.93:23274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/simple.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOdgAAAXA"] [Tue Aug 18 13:07:04.755236 2026] [security2:error] [pid 157386:tid 157635] [client 49.145.211.146:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOZQAAAYE"] [Tue Aug 18 13:07:04.755380 2026] [security2:error] [pid 157386:tid 157635] [client 49.145.211.146:10479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOZQAAAYE"] [Tue Aug 18 13:07:04.778026 2026] [security2:error] [pid 157386:tid 157524] [client 20.104.100.201:53831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/epinyins.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOdwAAARI"] [Tue Aug 18 13:07:04.785160 2026] [security2:error] [pid 157386:tid 157563] [client 52.173.121.69:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/pkmoj.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOeAAAATk"] [Tue Aug 18 13:07:04.811445 2026] [security2:error] [pid 157386:tid 157591] [client 196.12.128.158:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOeQAAAVU"] [Tue Aug 18 13:07:04.811560 2026] [security2:error] [pid 157386:tid 157591] [client 196.12.128.158:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOeQAAAVU"] [Tue Aug 18 13:07:04.822495 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:04.822893 2026] [authz_core:error] [pid 157386:tid 157458] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:04.854213 2026] [security2:error] [pid 157386:tid 157585] [client 20.116.17.175:63607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOgQAAAU8"] [Tue Aug 18 13:07:04.863859 2026] [security2:error] [pid 157386:tid 157551] [client 20.151.109.219:49343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ut.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOgwAAAS0"] [Tue Aug 18 13:07:04.871603 2026] [security2:error] [pid 157386:tid 157556] [client 158.158.74.177:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOhQAAATI"] [Tue Aug 18 13:07:04.883135 2026] [security2:error] [pid 157386:tid 157443] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOhwABaTg"] [Tue Aug 18 13:07:04.910776 2026] [security2:error] [pid 157386:tid 157629] [client 40.74.65.169:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/chris.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOiQAAAXs"] [Tue Aug 18 13:07:04.936521 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/eh.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOiwAAASk"] [Tue Aug 18 13:07:04.960625 2026] [security2:error] [pid 157386:tid 157572] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/hp2.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOjQAAAUI"] [Tue Aug 18 13:07:04.973757 2026] [security2:error] [pid 157386:tid 157614] [client 74.248.18.37:32450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/smilies/about.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOjgAAAWw"] [Tue Aug 18 13:07:04.975758 2026] [security2:error] [pid 157386:tid 157623] [client 20.226.36.136:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/mt/byp.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOjwAAAXU"] [Tue Aug 18 13:07:04.977946 2026] [security2:error] [pid 157386:tid 157634] [client 20.79.204.6:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSDKE1jzAhYHVVT1WcOkAAAAYA"] [Tue Aug 18 13:07:05.020597 2026] [security2:error] [pid 157386:tid 157600] [client 51.116.232.28:2643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/image2.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOkgAAAV4"] [Tue Aug 18 13:07:05.028879 2026] [security2:error] [pid 157386:tid 157532] [client 20.127.136.245:28096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/archive.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOkwAAARo"] [Tue Aug 18 13:07:05.049983 2026] [security2:error] [pid 157386:tid 157593] [client 135.225.75.187:12089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/G-in.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOlAAAAVc"] [Tue Aug 18 13:07:05.063039 2026] [security2:error] [pid 157386:tid 157606] [client 20.104.49.167:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/akismet.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOlgAAAWQ"] [Tue Aug 18 13:07:05.065626 2026] [security2:error] [pid 157386:tid 157580] [client 20.104.85.180:5829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOlwAAAUo"] [Tue Aug 18 13:07:05.079247 2026] [security2:error] [pid 157386:tid 157582] [client 20.116.17.175:58205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOmAAAAUw"] [Tue Aug 18 13:07:05.086379 2026] [security2:error] [pid 157386:tid 157522] [client 20.1.169.243:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOmQAAARA"] [Tue Aug 18 13:07:05.122844 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:05.123119 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:05.131140 2026] [security2:error] [pid 157386:tid 157601] [client 4.232.151.198:22307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/.tmb/cloud.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOnAAAAV8"] [Tue Aug 18 13:07:05.134444 2026] [security2:error] [pid 157386:tid 157542] [client 20.116.17.175:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/log.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOngAAASQ"] [Tue Aug 18 13:07:05.199884 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/eh.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOowAAAXw"] [Tue Aug 18 13:07:05.254277 2026] [security2:error] [pid 157386:tid 157627] [client 74.7.244.24:54966] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.maxxbox.com.br.maxxbox.ind.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDKU1jzAhYHVVT1WcOqwABeWY"] [Tue Aug 18 13:07:05.265523 2026] [security2:error] [pid 157386:tid 157609] [client 20.226.36.136:53538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/MTOS/byp.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOrAAAAWc"] [Tue Aug 18 13:07:05.268868 2026] [security2:error] [pid 157386:tid 157579] [client 20.116.17.175:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/spadex.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOrQAAAUk"] [Tue Aug 18 13:07:05.272150 2026] [security2:error] [pid 157386:tid 157598] [client 52.173.121.69:10683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOrgAAAVw"] [Tue Aug 18 13:07:05.315901 2026] [security2:error] [pid 157386:tid 157604] [client 20.65.69.59:21174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/phpcheck.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOsAAAAWI"] [Tue Aug 18 13:07:05.352459 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.85.180:5926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.85.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jcveiculosutilitarios.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOsgAAARg"] [Tue Aug 18 13:07:05.375249 2026] [security2:error] [pid 157386:tid 157602] [client 20.116.17.175:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/aa.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOtAAAAWA"] [Tue Aug 18 13:07:05.378570 2026] [security2:error] [pid 157386:tid 157575] [client 20.151.109.219:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kj.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOtQAAAUU"] [Tue Aug 18 13:07:05.392360 2026] [security2:error] [pid 157386:tid 157613] [client 20.104.100.201:17367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/load.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOtwAAAWs"] [Tue Aug 18 13:07:05.393232 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ad.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOuAAAASk"] [Tue Aug 18 13:07:05.409628 2026] [security2:error] [pid 157386:tid 157617] [client 104.209.144.33:32687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOuwAAAW8"] [Tue Aug 18 13:07:05.411705 2026] [security2:error] [pid 157386:tid 157640] [client 213.35.127.232:60502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOvAAAAYY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:05.419392 2026] [security2:error] [pid 157386:tid 157572] [client 52.173.121.69:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/kopyw.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOvQAAAUI"] [Tue Aug 18 13:07:05.421183 2026] [security2:error] [pid 157386:tid 157556] [client 20.127.136.245:28286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/bless.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOvgAAATI"] [Tue Aug 18 13:07:05.423934 2026] [security2:error] [pid 157386:tid 157641] [client 20.104.49.167:8839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/admin.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOwAAAAYc"] [Tue Aug 18 13:07:05.463200 2026] [security2:error] [pid 157386:tid 157550] [client 20.1.169.243:15978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOwgAAASw"] [Tue Aug 18 13:07:05.464748 2026] [security2:error] [pid 157386:tid 157516] [client 51.116.232.28:2632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/fb.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOwQAAAQo"] [Tue Aug 18 13:07:05.470052 2026] [security2:error] [pid 157386:tid 157623] [client 135.225.75.187:31860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xxx.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOxAAAAXU"] [Tue Aug 18 13:07:05.477286 2026] [security2:error] [pid 157386:tid 157435] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/admin.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOxgABNjA"] [Tue Aug 18 13:07:05.559591 2026] [security2:error] [pid 157386:tid 157629] [client 158.158.74.177:9327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSDKU1jzAhYHVVT1WcOywAAAXs"] [Tue Aug 18 13:07:05.585453 2026] [security2:error] [pid 157386:tid 157549] [client 40.74.65.169:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/doc.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO0gAAASs"] [Tue Aug 18 13:07:05.586242 2026] [security2:error] [pid 157386:tid 157612] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/yb.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO0wAAAWo"] [Tue Aug 18 13:07:05.618815 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:05.619075 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:05.625029 2026] [security2:error] [pid 157386:tid 157597] [client 20.251.48.93:62721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/chosen.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO5gAAAVs"] [Tue Aug 18 13:07:05.628999 2026] [security2:error] [pid 157386:tid 157595] [client 45.92.229.105:24855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO5wAAAVk"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:07:05.639400 2026] [security2:error] [pid 157386:tid 157637] [client 20.116.17.175:63554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO6AAAAYM"] [Tue Aug 18 13:07:05.651910 2026] [security2:error] [pid 157386:tid 157627] [client 20.151.109.219:46433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ad.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO6gAAAXk"] [Tue Aug 18 13:07:05.661473 2026] [security2:error] [pid 157386:tid 157564] [client 20.226.36.136:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO6wAAATo"] [Tue Aug 18 13:07:05.675272 2026] [autoindex:error] [pid 157386:tid 157432] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:05.703000 2026] [security2:error] [pid 157386:tid 157499] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/public/css.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO7wABYnA"] [Tue Aug 18 13:07:05.718860 2026] [security2:error] [pid 157386:tid 157600] [client 20.79.204.6:11665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO9gAAAV4"] [Tue Aug 18 13:07:05.734651 2026] [security2:error] [pid 157386:tid 157631] [client 74.248.18.37:6449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/gCdfg/autoload_classmap.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO9wAAAX0"] [Tue Aug 18 13:07:05.750683 2026] [security2:error] [pid 157386:tid 157559] [client 158.23.17.4:56537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gw.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO-gAAATU"] [Tue Aug 18 13:07:05.773437 2026] [security2:error] [pid 157386:tid 157426] [remote 162.55.89.48:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ofertas.vidracariafroesbox.com.br"] [uri "/wp-login.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO_AABVyc"] [Tue Aug 18 13:07:05.773518 2026] [security2:error] [pid 157386:tid 157580] [client 4.232.151.198:5393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "aoSDKU1jzAhYHVVT1WcO-wAAAUo"] [Tue Aug 18 13:07:05.822430 2026] [security2:error] [pid 157386:tid 157387] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDKU1jzAhYHVVT1WcO_wABfwA"] [Tue Aug 18 13:07:05.832153 2026] [security2:error] [pid 157386:tid 157625] [client 52.173.121.69:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/zznmg.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPAAAAAXc"] [Tue Aug 18 13:07:05.841334 2026] [security2:error] [pid 157386:tid 157611] [client 20.1.169.243:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPAwAAAWk"] [Tue Aug 18 13:07:05.851440 2026] [security2:error] [pid 157386:tid 157457] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/@fs/root/.aws/config"] [unique_id "aoSDKU1jzAhYHVVT1WcPBAABFUY"] [Tue Aug 18 13:07:05.868347 2026] [security2:error] [pid 157386:tid 157562] [client 51.116.232.28:2667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/gi.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPBwAAATg"] [Tue Aug 18 13:07:05.883036 2026] [security2:error] [pid 157386:tid 157492] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/@fs/.env"] [unique_id "aoSDKU1jzAhYHVVT1WcPCAABQGk"] [Tue Aug 18 13:07:05.886821 2026] [security2:error] [pid 157386:tid 157614] [client 20.116.17.175:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ohct.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPCQAAAWw"] [Tue Aug 18 13:07:05.888086 2026] [security2:error] [pid 157386:tid 157474] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/@fs/app/.env"] [unique_id "aoSDKU1jzAhYHVVT1WcPCgABH1c"] [Tue Aug 18 13:07:05.891758 2026] [security2:error] [pid 157386:tid 157550] [client 135.225.75.187:11643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/un.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPCwAAASw"] [Tue Aug 18 13:07:05.900655 2026] [security2:error] [pid 157386:tid 157623] [client 20.116.17.175:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/echkm.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPDQAAAXU"] [Tue Aug 18 13:07:05.912356 2026] [security2:error] [pid 157386:tid 157634] [client 52.173.121.69:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPDwAAAYA"] [Tue Aug 18 13:07:05.915974 2026] [security2:error] [pid 157386:tid 157560] [client 20.151.109.219:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/vd.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPEAAAATY"] [Tue Aug 18 13:07:05.916039 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.100.201:54043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPEQAAAT0"] [Tue Aug 18 13:07:05.924785 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:05.925248 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:05.933232 2026] [security2:error] [pid 157386:tid 157406] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPGAABcBM"] [Tue Aug 18 13:07:05.997692 2026] [security2:error] [pid 157386:tid 157522] [client 20.151.109.219:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/vd.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPGQAAARA"] [Tue Aug 18 13:07:05.999582 2026] [security2:error] [pid 157386:tid 157640] [client 20.127.136.245:28238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/sagax1.php"] [unique_id "aoSDKU1jzAhYHVVT1WcPGgAAAYY"] [Tue Aug 18 13:07:06.006405 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:45308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/srontol.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPGwAAAV0"] [Tue Aug 18 13:07:06.023691 2026] [security2:error] [pid 157386:tid 157396] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDKk1jzAhYHVVT1WcPLQABQAk"] [Tue Aug 18 13:07:06.103957 2026] [security2:error] [pid 157386:tid 157503] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/phpinfo.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPNwABiHQ"] [Tue Aug 18 13:07:06.108681 2026] [autoindex:error] [pid 157386:tid 157480] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:06.175483 2026] [security2:error] [pid 157386:tid 157470] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/@fs/app/.aws/credentials"] [unique_id "aoSDKk1jzAhYHVVT1WcPPAABaFM"] [Tue Aug 18 13:07:06.197613 2026] [security2:error] [pid 157386:tid 157605] [client 158.158.74.177:9283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/lite.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPPQAAAWM"] [Tue Aug 18 13:07:06.206162 2026] [security2:error] [pid 157386:tid 157643] [client 20.104.49.167:51840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/bajah.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPPgAAAYk"] [Tue Aug 18 13:07:06.208679 2026] [security2:error] [pid 157386:tid 157604] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/vc.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPPwAAAWI"] [Tue Aug 18 13:07:06.214115 2026] [security2:error] [pid 157386:tid 157563] [client 20.1.169.243:15982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/cY5ipC.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPQAAAATk"] [Tue Aug 18 13:07:06.220025 2026] [security2:error] [pid 157386:tid 157477] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDKk1jzAhYHVVT1WcPQgABO1o"] [Tue Aug 18 13:07:06.222860 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:06.223127 2026] [authz_core:error] [pid 157386:tid 157419] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:06.237794 2026] [security2:error] [pid 157386:tid 157631] [client 20.226.36.136:62162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPRAAAAX0"] [Tue Aug 18 13:07:06.237822 2026] [security2:error] [pid 157386:tid 157615] [client 104.209.144.33:31286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPRQAAAW0"] [Tue Aug 18 13:07:06.243394 2026] [security2:error] [pid 157386:tid 157520] [client 20.116.17.175:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/domvf.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPRwAAAQ4"] [Tue Aug 18 13:07:06.269021 2026] [security2:error] [pid 157386:tid 157641] [client 51.116.232.28:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/video.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPSQAAAYc"] [Tue Aug 18 13:07:06.269985 2026] [security2:error] [pid 157386:tid 157614] [client 40.74.65.169:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/1337.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPSgAAAWw"] [Tue Aug 18 13:07:06.285009 2026] [security2:error] [pid 157386:tid 157516] [client 20.151.109.219:22942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vg.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPTAAAAQo"] [Tue Aug 18 13:07:06.292815 2026] [security2:error] [pid 157386:tid 157550] [client 20.151.109.219:5321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/56.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPTQAAASw"] [Tue Aug 18 13:07:06.296073 2026] [security2:error] [pid 157386:tid 157435] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/info.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPTgABMjA"] [Tue Aug 18 13:07:06.315358 2026] [security2:error] [pid 157386:tid 157461] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/pi.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPTwABMko"] [Tue Aug 18 13:07:06.328741 2026] [security2:error] [pid 157386:tid 157551] [client 74.248.18.37:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/lock360.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPUQAAAS0"] [Tue Aug 18 13:07:06.335680 2026] [security2:error] [pid 157386:tid 157545] [client 135.225.75.187:31845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/autogooey.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPUgAAASc"] [Tue Aug 18 13:07:06.339363 2026] [security2:error] [pid 157386:tid 157576] [client 20.251.48.93:62769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/als.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPUwAAAUY"] [Tue Aug 18 13:07:06.339393 2026] [security2:error] [pid 157386:tid 157389] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/test.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPVAABPQI"] [Tue Aug 18 13:07:06.347557 2026] [security2:error] [pid 157386:tid 157622] [client 52.173.121.69:36581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/bhfnd.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPVQAAAXQ"] [Tue Aug 18 13:07:06.356283 2026] [autoindex:error] [pid 157386:tid 157637] [client 20.79.204.6:11528] AH01276: Cannot serve directory /home1/caboclotaperoa/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:06.391749 2026] [security2:error] [pid 157386:tid 157586] [client 20.116.17.175:22655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/file5.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPWgAAAVA"] [Tue Aug 18 13:07:06.410672 2026] [security2:error] [pid 157386:tid 157452] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDKk1jzAhYHVVT1WcPXQABREE"] [Tue Aug 18 13:07:06.415498 2026] [security2:error] [pid 157386:tid 157621] [client 20.116.17.175:20316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ot.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPXgAAAXM"] [Tue Aug 18 13:07:06.420815 2026] [security2:error] [pid 157386:tid 157466] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDKk1jzAhYHVVT1WcPXwABJE8"] [Tue Aug 18 13:07:06.437702 2026] [security2:error] [pid 157386:tid 157612] [client 213.35.127.232:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPYAAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:06.454424 2026] [security2:error] [pid 157386:tid 157607] [client 4.232.151.198:18982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/gettest.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPYQAAAWU"] [Tue Aug 18 13:07:06.459933 2026] [security2:error] [pid 157386:tid 157592] [client 20.104.100.201:54036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ty.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPYgAAAVY"] [Tue Aug 18 13:07:06.525552 2026] [security2:error] [pid 157386:tid 157537] [client 74.248.18.37:25022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/backup-backup/includes/1a895fa06f.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPawAAAR8"] [Tue Aug 18 13:07:06.556157 2026] [security2:error] [pid 157386:tid 157543] [client 20.79.204.6:11528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPbgAAASU"] [Tue Aug 18 13:07:06.558995 2026] [security2:error] [pid 157386:tid 157463] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/i.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPbwABfkw"] [Tue Aug 18 13:07:06.559080 2026] [security2:error] [pid 157386:tid 157604] [client 20.226.36.136:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPcAAAAWI"] [Tue Aug 18 13:07:06.576748 2026] [security2:error] [pid 157386:tid 157563] [client 20.151.109.219:10615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/56.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPcwAAATk"] [Tue Aug 18 13:07:06.582867 2026] [security2:error] [pid 157386:tid 157518] [client 114.119.142.197:32117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zyoninformatica.com.br"] [uri "/ecotank-l1800/"] [unique_id "aoSDKk1jzAhYHVVT1WcPdAAAAQw"], referer: https://zyoninformatica.com.br/ecotank-l1800/ [Tue Aug 18 13:07:06.585571 2026] [security2:error] [pid 157386:tid 157581] [client 20.116.17.175:58185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/red.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPdQAAAUs"] [Tue Aug 18 13:07:06.606589 2026] [security2:error] [pid 157386:tid 157483] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPeAABGGA"] [Tue Aug 18 13:07:06.610453 2026] [autoindex:error] [pid 157386:tid 157428] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:06.637980 2026] [security2:error] [pid 157386:tid 157541] [client 20.1.169.243:15794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPegAAASM"] [Tue Aug 18 13:07:06.680269 2026] [security2:error] [pid 157386:tid 157551] [client 20.104.49.167:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/ajax.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPfQAAAS0"] [Tue Aug 18 13:07:06.691801 2026] [security2:error] [pid 157386:tid 157545] [client 20.116.17.175:63557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/yup.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPfgAAASc"] [Tue Aug 18 13:07:06.698136 2026] [security2:error] [pid 157386:tid 157576] [client 51.116.232.28:2630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/hel.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPfwAAAUY"] [Tue Aug 18 13:07:06.713113 2026] [security2:error] [pid 157386:tid 157529] [client 5.31.227.224:1423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPgQAAARc"] [Tue Aug 18 13:07:06.713288 2026] [security2:error] [pid 157386:tid 157529] [client 5.31.227.224:1423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPgQAAARc"] [Tue Aug 18 13:07:06.754132 2026] [security2:error] [pid 157386:tid 157629] [client 135.225.75.187:23035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sty.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPgwAAAXs"] [Tue Aug 18 13:07:06.796876 2026] [security2:error] [pid 157386:tid 157526] [client 20.151.109.219:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/rx.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPiAAAARQ"] [Tue Aug 18 13:07:06.822232 2026] [security2:error] [pid 157386:tid 157497] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/app_dev.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPiwABh24"] [Tue Aug 18 13:07:06.825520 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:06.825833 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:06.836118 2026] [security2:error] [pid 157386:tid 157571] [client 158.158.74.177:24645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSDKk1jzAhYHVVT1WcPjgAAAUE"] [Tue Aug 18 13:07:06.836508 2026] [security2:error] [pid 157386:tid 157603] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/pema.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPjwAAAWE"] [Tue Aug 18 13:07:06.838047 2026] [security2:error] [pid 157386:tid 157413] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/gelay.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPkAABTho"] [Tue Aug 18 13:07:06.928435 2026] [security2:error] [pid 157386:tid 157627] [client 20.226.36.136:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPlwAAAXk"] [Tue Aug 18 13:07:06.948064 2026] [security2:error] [pid 157386:tid 157609] [client 20.151.109.219:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/rx.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPmQAAAWc"] [Tue Aug 18 13:07:06.964768 2026] [security2:error] [pid 157386:tid 157635] [client 74.248.18.37:21331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/log.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPmwAAAYE"] [Tue Aug 18 13:07:06.966484 2026] [security2:error] [pid 157386:tid 157554] [client 40.74.65.169:4587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/Njima.php"] [unique_id "aoSDKk1jzAhYHVVT1WcPnAAAATA"] [Tue Aug 18 13:07:07.008965 2026] [security2:error] [pid 157386:tid 157580] [client 20.251.48.93:16273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/nox.php"] [unique_id "aoSDK01jzAhYHVVT1WcPoQAAAUo"] [Tue Aug 18 13:07:07.025231 2026] [security2:error] [pid 157386:tid 157597] [client 20.116.17.175:64904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSDK01jzAhYHVVT1WcPogAAAVs"] [Tue Aug 18 13:07:07.025301 2026] [autoindex:error] [pid 157386:tid 157456] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:07.026091 2026] [security2:error] [pid 157386:tid 157541] [client 20.116.17.175:22635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDK01jzAhYHVVT1WcPowAAASM"] [Tue Aug 18 13:07:07.033344 2026] [security2:error] [pid 157386:tid 157426] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.94.38.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "josysantos.filialweb.com"] [uri "/app_dev.php/_profiler"] [unique_id "aoSDK01jzAhYHVVT1WcPpAABVCc"] [Tue Aug 18 13:07:07.043363 2026] [security2:error] [pid 157386:tid 157524] [client 20.1.169.243:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/about.php"] [unique_id "aoSDK01jzAhYHVVT1WcPpQAAARI"] [Tue Aug 18 13:07:07.066347 2026] [security2:error] [pid 157386:tid 157449] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDK01jzAhYHVVT1WcPpwABCj4"] [Tue Aug 18 13:07:07.097424 2026] [security2:error] [pid 157386:tid 157553] [client 20.151.109.219:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mandrill.php"] [unique_id "aoSDK01jzAhYHVVT1WcPqgAAAS8"] [Tue Aug 18 13:07:07.100624 2026] [security2:error] [pid 157386:tid 157531] [client 51.116.232.28:2627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/grok.php"] [unique_id "aoSDK01jzAhYHVVT1WcPqwAAARk"] [Tue Aug 18 13:07:07.105410 2026] [security2:error] [pid 157386:tid 157578] [client 4.232.151.198:22304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/void.php"] [unique_id "aoSDK01jzAhYHVVT1WcPrAAAAUg"] [Tue Aug 18 13:07:07.126794 2026] [security2:error] [pid 157386:tid 157623] [client 20.127.136.245:27975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcPsQAAAXU"] [Tue Aug 18 13:07:07.127285 2026] [authz_core:error] [pid 157386:tid 157492] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:07.127710 2026] [authz_core:error] [pid 157386:tid 157492] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:07.129163 2026] [security2:error] [pid 157386:tid 157621] [client 20.104.49.167:52418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.caboclotaperoa.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDK01jzAhYHVVT1WcPsgAAAXM"] [Tue Aug 18 13:07:07.134173 2026] [security2:error] [pid 157386:tid 157636] [client 52.173.121.69:28319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/qfvqu.php"] [unique_id "aoSDK01jzAhYHVVT1WcPswAAAYI"] [Tue Aug 18 13:07:07.168676 2026] [security2:error] [pid 157386:tid 157543] [client 20.79.204.6:11544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "caboclotaperoa.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcPtQAAASU"] [Tue Aug 18 13:07:07.171030 2026] [security2:error] [pid 157386:tid 157584] [client 135.225.75.187:31832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wio.php"] [unique_id "aoSDK01jzAhYHVVT1WcPtgAAAU4"] [Tue Aug 18 13:07:07.223149 2026] [security2:error] [pid 157386:tid 157579] [client 20.226.36.136:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcPugAAAUk"] [Tue Aug 18 13:07:07.256205 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:20234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/v5.php"] [unique_id "aoSDK01jzAhYHVVT1WcPvgAAATk"] [Tue Aug 18 13:07:07.283114 2026] [security2:error] [pid 157386:tid 157559] [client 52.173.121.69:38351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDK01jzAhYHVVT1WcPwAAAATU"] [Tue Aug 18 13:07:07.291477 2026] [security2:error] [pid 157386:tid 157420] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDK01jzAhYHVVT1WcPwQABMyE"] [Tue Aug 18 13:07:07.301519 2026] [security2:error] [pid 157386:tid 157551] [client 74.248.18.37:24993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/locks.php"] [unique_id "aoSDK01jzAhYHVVT1WcPxAAAAS0"] [Tue Aug 18 13:07:07.335628 2026] [security2:error] [pid 157386:tid 157617] [client 158.158.74.177:17131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/lock360.php"] [unique_id "aoSDK01jzAhYHVVT1WcPxgAAAW8"] [Tue Aug 18 13:07:07.340151 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:20683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sm.php"] [unique_id "aoSDK01jzAhYHVVT1WcPxwAAAXc"] [Tue Aug 18 13:07:07.400007 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/main.php"] [unique_id "aoSDK01jzAhYHVVT1WcPygAAAUY"] [Tue Aug 18 13:07:07.412588 2026] [security2:error] [pid 157386:tid 157560] [client 20.116.17.175:22579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-the.php"] [unique_id "aoSDK01jzAhYHVVT1WcPywAAATY"] [Tue Aug 18 13:07:07.416824 2026] [security2:error] [pid 157386:tid 157469] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcPzQABPVI"] [Tue Aug 18 13:07:07.416991 2026] [security2:error] [pid 157386:tid 157567] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcPzQABPVI"] [Tue Aug 18 13:07:07.429848 2026] [security2:error] [pid 157386:tid 157629] [client 20.171.51.14:21930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/app.php"] [unique_id "aoSDK01jzAhYHVVT1WcP0AAAAXs"] [Tue Aug 18 13:07:07.433621 2026] [security2:error] [pid 157386:tid 157613] [client 20.1.169.243:15761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "aoSDK01jzAhYHVVT1WcP0QAAAWs"] [Tue Aug 18 13:07:07.448665 2026] [security2:error] [pid 157386:tid 157585] [client 20.65.69.59:22023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/mimes.php"] [unique_id "aoSDK01jzAhYHVVT1WcP0wAAAU8"] [Tue Aug 18 13:07:07.457096 2026] [security2:error] [pid 157386:tid 157574] [client 213.35.127.232:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDK01jzAhYHVVT1WcP1AAAAUQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:07.463864 2026] [security2:error] [pid 157386:tid 157623] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/sh.php"] [unique_id "aoSDK01jzAhYHVVT1WcP1QAAAXU"] [Tue Aug 18 13:07:07.467107 2026] [security2:error] [pid 157386:tid 157526] [client 20.116.17.175:64988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSDK01jzAhYHVVT1WcP1gAAARQ"] [Tue Aug 18 13:07:07.497804 2026] [security2:error] [pid 157386:tid 157572] [client 49.37.150.8:51902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcP3QAAAUI"] [Tue Aug 18 13:07:07.497922 2026] [security2:error] [pid 157386:tid 157572] [client 49.37.150.8:51902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcP3QAAAUI"] [Tue Aug 18 13:07:07.500355 2026] [security2:error] [pid 157386:tid 157607] [client 20.226.36.136:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcP3gAAAWU"] [Tue Aug 18 13:07:07.500556 2026] [security2:error] [pid 157386:tid 157571] [client 20.151.109.219:21925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mandrill.php"] [unique_id "aoSDK01jzAhYHVVT1WcP3wAAAUE"] [Tue Aug 18 13:07:07.511219 2026] [autoindex:error] [pid 157386:tid 157445] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:07.547900 2026] [security2:error] [pid 157386:tid 157640] [client 51.116.232.28:3026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/indes.php"] [unique_id "aoSDK01jzAhYHVVT1WcP4gAAAYY"] [Tue Aug 18 13:07:07.562051 2026] [security2:error] [pid 157386:tid 157586] [client 86.120.159.145:22189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcP4wAAAVA"] [Tue Aug 18 13:07:07.562171 2026] [security2:error] [pid 157386:tid 157586] [client 86.120.159.145:22189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcP4wAAAVA"] [Tue Aug 18 13:07:07.570223 2026] [security2:error] [pid 157386:tid 157600] [client 158.158.74.177:9907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSDK01jzAhYHVVT1WcP5AAAAV4"] [Tue Aug 18 13:07:07.580637 2026] [security2:error] [pid 157386:tid 157641] [client 20.251.48.93:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file59.php"] [unique_id "aoSDK01jzAhYHVVT1WcP5QAAAYc"] [Tue Aug 18 13:07:07.590197 2026] [security2:error] [pid 157386:tid 157592] [client 135.225.75.187:35740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/1061.php"] [unique_id "aoSDK01jzAhYHVVT1WcP5gAAAVY"] [Tue Aug 18 13:07:07.595186 2026] [security2:error] [pid 157386:tid 157643] [client 104.209.144.33:31242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDK01jzAhYHVVT1WcP6gAAAYk"] [Tue Aug 18 13:07:07.595742 2026] [security2:error] [pid 157386:tid 157437] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/files../.env"] [unique_id "aoSDK01jzAhYHVVT1WcP6QABVTI"] [Tue Aug 18 13:07:07.596274 2026] [security2:error] [pid 157386:tid 157448] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.aws/credentials.old"] [unique_id "aoSDK01jzAhYHVVT1WcP6AABYz0"] [Tue Aug 18 13:07:07.598457 2026] [security2:error] [pid 157386:tid 157614] [client 74.248.18.37:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/lv.php"] [unique_id "aoSDK01jzAhYHVVT1WcP6wAAAWw"] [Tue Aug 18 13:07:07.620563 2026] [security2:error] [pid 157386:tid 157582] [client 20.127.136.245:28262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/fone1.php"] [unique_id "aoSDK01jzAhYHVVT1WcP7QAAAUw"] [Tue Aug 18 13:07:07.631897 2026] [security2:error] [pid 157386:tid 157581] [client 20.226.36.136:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/first.php"] [unique_id "aoSDK01jzAhYHVVT1WcP8AAAAUs"] [Tue Aug 18 13:07:07.646851 2026] [security2:error] [pid 157386:tid 157514] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.backup"] [unique_id "aoSDK01jzAhYHVVT1WcP8QABNX8"] [Tue Aug 18 13:07:07.647785 2026] [security2:error] [pid 157386:tid 157390] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.env.development"] [unique_id "aoSDK01jzAhYHVVT1WcP8wABLgM"] [Tue Aug 18 13:07:07.654963 2026] [security2:error] [pid 157386:tid 157557] [client 40.74.65.169:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDK01jzAhYHVVT1WcP9AAAATM"] [Tue Aug 18 13:07:07.691276 2026] [security2:error] [pid 157386:tid 157631] [client 52.173.121.69:28313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/oivcl.php"] [unique_id "aoSDK01jzAhYHVVT1WcP-AAAAX0"] [Tue Aug 18 13:07:07.709413 2026] [security2:error] [pid 157386:tid 157632] [client 20.151.109.219:39867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ga.php"] [unique_id "aoSDK01jzAhYHVVT1WcP-gAAAX4"] [Tue Aug 18 13:07:07.730992 2026] [security2:error] [pid 157386:tid 157584] [client 4.232.151.198:18995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wpsml-sys.php"] [unique_id "aoSDK01jzAhYHVVT1WcP_gAAAU4"] [Tue Aug 18 13:07:07.765811 2026] [security2:error] [pid 157386:tid 157576] [client 20.116.17.175:63556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDK01jzAhYHVVT1WcQAQAAAUY"] [Tue Aug 18 13:07:07.772045 2026] [security2:error] [pid 157386:tid 157477] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/core/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQBAABfFo"] [Tue Aug 18 13:07:07.773309 2026] [security2:error] [pid 157386:tid 157435] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/public/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQBQABfDA"] [Tue Aug 18 13:07:07.774165 2026] [security2:error] [pid 157386:tid 157567] [client 20.226.36.136:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcQBgAAAT0"] [Tue Aug 18 13:07:07.799123 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:28782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/28.php"] [unique_id "aoSDK01jzAhYHVVT1WcQCAAAAR0"] [Tue Aug 18 13:07:07.823649 2026] [security2:error] [pid 157386:tid 157389] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/config/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQCgABJAI"] [Tue Aug 18 13:07:07.824654 2026] [security2:error] [pid 157386:tid 157458] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/back/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQCwABPEc"] [Tue Aug 18 13:07:07.827649 2026] [security2:error] [pid 157386:tid 157575] [client 20.1.169.243:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/block-supports/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcQDAAAAUU"] [Tue Aug 18 13:07:07.829157 2026] [security2:error] [pid 157386:tid 157452] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/.aws/credentials"] [unique_id "aoSDK01jzAhYHVVT1WcQDQABQkE"] [Tue Aug 18 13:07:07.843578 2026] [security2:error] [pid 157386:tid 157603] [client 20.226.36.136:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcQEAAAAWE"] [Tue Aug 18 13:07:07.847497 2026] [security2:error] [pid 157386:tid 157494] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/server/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQEQABJWs"] [Tue Aug 18 13:07:07.847762 2026] [security2:error] [pid 157386:tid 157547] [client 223.185.37.47:26733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcQEgAAASk"] [Tue Aug 18 13:07:07.856739 2026] [security2:error] [pid 157386:tid 157547] [client 223.185.37.47:26733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDK01jzAhYHVVT1WcQEgAAASk"] [Tue Aug 18 13:07:07.863004 2026] [security2:error] [pid 157386:tid 157463] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/backend/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQEwABakw"] [Tue Aug 18 13:07:07.876675 2026] [access_compat:error] [pid 157386:tid 157421] [remote 34.38.94.143:51990] AH01797: client denied by server configuration: /home4/filial35/public_html/josysantos/server-status [Tue Aug 18 13:07:07.903932 2026] [security2:error] [pid 157386:tid 157418] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/@fs/home/ec2-user/.aws/credentials"] [unique_id "aoSDK01jzAhYHVVT1WcQFwABTR8"] [Tue Aug 18 13:07:07.911554 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.36.136:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDK01jzAhYHVVT1WcQGAAAAVA"] [Tue Aug 18 13:07:07.934870 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.100.201:53857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDK01jzAhYHVVT1WcQGQAAAQ8"] [Tue Aug 18 13:07:07.954379 2026] [security2:error] [pid 157386:tid 157609] [client 20.116.17.175:20460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSDK01jzAhYHVVT1WcQHAAAAWc"] [Tue Aug 18 13:07:07.955923 2026] [security2:error] [pid 157386:tid 157592] [client 51.116.232.28:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDK01jzAhYHVVT1WcQHQAAAVY"] [Tue Aug 18 13:07:07.971235 2026] [security2:error] [pid 157386:tid 157392] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDK01jzAhYHVVT1WcQIAABDgU"] [Tue Aug 18 13:07:07.972094 2026] [security2:error] [pid 157386:tid 157416] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/web/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQHwABeh0"] [Tue Aug 18 13:07:07.973839 2026] [security2:error] [pid 157386:tid 157446] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.aws/credentials.bak"] [unique_id "aoSDK01jzAhYHVVT1WcQIQABNTs"] [Tue Aug 18 13:07:07.977027 2026] [security2:error] [pid 157386:tid 157460] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env"] [unique_id "aoSDK01jzAhYHVVT1WcQIgABLkk"] [Tue Aug 18 13:07:07.981735 2026] [security2:error] [pid 157386:tid 157557] [client 20.65.98.162:45090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/media.php"] [unique_id "aoSDK01jzAhYHVVT1WcQJQAAATM"] [Tue Aug 18 13:07:07.982586 2026] [security2:error] [pid 157386:tid 157409] [remote 34.38.94.143:51990] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "josysantos.filialweb.com"] [uri "/server-info"] [unique_id "aoSDK01jzAhYHVVT1WcQJAABGBY"] [Tue Aug 18 13:07:07.988358 2026] [security2:error] [pid 157386:tid 157553] [client 158.158.74.177:4773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/log.php"] [unique_id "aoSDK01jzAhYHVVT1WcQKAAAAS8"] [Tue Aug 18 13:07:08.008578 2026] [security2:error] [pid 157386:tid 157537] [client 135.225.75.187:31812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/gec.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQKQAAAR8"] [Tue Aug 18 13:07:08.018251 2026] [security2:error] [pid 157386:tid 157471] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/apps/api/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQKgABblQ"] [Tue Aug 18 13:07:08.018419 2026] [security2:error] [pid 157386:tid 157563] [client 20.226.36.136:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/blog/byp.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQKwAAATk"] [Tue Aug 18 13:07:08.029892 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:08.030149 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:08.041919 2026] [security2:error] [pid 157386:tid 157590] [client 20.116.17.175:65018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQLQAAAVQ"] [Tue Aug 18 13:07:08.061257 2026] [security2:error] [pid 157386:tid 157637] [client 20.226.36.136:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQLwAAAYM"] [Tue Aug 18 13:07:08.071142 2026] [security2:error] [pid 157386:tid 157633] [client 20.116.17.175:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/xwpg.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQMQAAAX8"] [Tue Aug 18 13:07:08.071994 2026] [security2:error] [pid 157386:tid 157413] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.swp"] [unique_id "aoSDLE1jzAhYHVVT1WcQMAABhho"] [Tue Aug 18 13:07:08.073201 2026] [autoindex:error] [pid 157386:tid 157404] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:08.074798 2026] [security2:error] [pid 157386:tid 157527] [client 20.151.109.219:49959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/wb.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQMgAAARU"] [Tue Aug 18 13:07:08.078704 2026] [security2:error] [pid 157386:tid 157568] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/button.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQNQAAAT4"] [Tue Aug 18 13:07:08.081139 2026] [security2:error] [pid 157386:tid 157441] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQNgABajY"] [Tue Aug 18 13:07:08.083395 2026] [security2:error] [pid 157386:tid 157419] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/src/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQNwABhyA"] [Tue Aug 18 13:07:08.083881 2026] [security2:error] [pid 157386:tid 157620] [client 20.226.36.136:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQOAAAAXI"] [Tue Aug 18 13:07:08.086649 2026] [security2:error] [pid 157386:tid 157453] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQOgABJkI"] [Tue Aug 18 13:07:08.087227 2026] [security2:error] [pid 157386:tid 157456] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.old"] [unique_id "aoSDLE1jzAhYHVVT1WcQPAABakU"] [Tue Aug 18 13:07:08.129157 2026] [security2:error] [pid 157386:tid 157576] [client 20.226.36.136:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.filialweb.com"] [uri "/images/security.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQPwAAAUY"] [Tue Aug 18 13:07:08.177922 2026] [security2:error] [pid 157386:tid 157531] [client 20.251.48.93:3480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/admin.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQQwAAARk"] [Tue Aug 18 13:07:08.187067 2026] [security2:error] [pid 157386:tid 157578] [client 20.151.109.219:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/main.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQRQAAAUg"] [Tue Aug 18 13:07:08.195166 2026] [security2:error] [pid 157386:tid 157481] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/about.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQRwABV14"] [Tue Aug 18 13:07:08.197369 2026] [security2:error] [pid 157386:tid 157412] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/_next/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQSAABhhk"] [Tue Aug 18 13:07:08.201100 2026] [security2:error] [pid 157386:tid 157535] [client 20.65.69.59:21156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/fraie1p4.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQSQAAAR0"] [Tue Aug 18 13:07:08.207512 2026] [security2:error] [pid 157386:tid 157511] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDLE1jzAhYHVVT1WcQSwABanw"] [Tue Aug 18 13:07:08.215576 2026] [security2:error] [pid 157386:tid 157631] [client 158.158.74.177:20527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQTAAAAX0"] [Tue Aug 18 13:07:08.220644 2026] [security2:error] [pid 157386:tid 157587] [client 20.1.169.243:15904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQTQAAAVE"] [Tue Aug 18 13:07:08.236282 2026] [security2:error] [pid 157386:tid 157595] [client 20.127.136.245:28129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ncx.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQTwAAAVk"] [Tue Aug 18 13:07:08.246245 2026] [security2:error] [pid 157386:tid 157597] [client 74.248.18.37:11304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/mah/function.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQUAAAAVs"] [Tue Aug 18 13:07:08.259753 2026] [security2:error] [pid 157386:tid 157457] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDLE1jzAhYHVVT1WcQUgABhkY"] [Tue Aug 18 13:07:08.291090 2026] [security2:error] [pid 157386:tid 157508] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDLE1jzAhYHVVT1WcQVgABank"] [Tue Aug 18 13:07:08.292629 2026] [security2:error] [pid 157386:tid 157496] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.github/.env"] [unique_id "aoSDLE1jzAhYHVVT1WcQVwABam0"] [Tue Aug 18 13:07:08.305299 2026] [security2:error] [pid 157386:tid 157506] [remote 188.164.197.230:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQWAABYHc"] [Tue Aug 18 13:07:08.334033 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:08.334476 2026] [authz_core:error] [pid 157386:tid 157472] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:08.338899 2026] [security2:error] [pid 157386:tid 157642] [client 20.215.241.237:16937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/nox.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQWwAAAYg"] [Tue Aug 18 13:07:08.364199 2026] [security2:error] [pid 157386:tid 157589] [client 52.173.121.69:28305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/zugvi.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQXQAAAVM"] [Tue Aug 18 13:07:08.369532 2026] [security2:error] [pid 157386:tid 157583] [client 51.116.232.28:2972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/bs1.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQXgAAAU0"] [Tue Aug 18 13:07:08.371314 2026] [security2:error] [pid 157386:tid 157551] [client 40.74.65.169:4145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/too.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQYAAAAS0"] [Tue Aug 18 13:07:08.391101 2026] [security2:error] [pid 157386:tid 157622] [client 4.232.151.198:18976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/l.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQYwAAAXQ"] [Tue Aug 18 13:07:08.419614 2026] [security2:error] [pid 157386:tid 157442] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQZAABOjc"] [Tue Aug 18 13:07:08.420624 2026] [security2:error] [pid 157386:tid 157600] [client 20.116.17.175:22587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/dex.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQZQAAAV4"] [Tue Aug 18 13:07:08.423473 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/xn.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQZwAAAVY"] [Tue Aug 18 13:07:08.426675 2026] [security2:error] [pid 157386:tid 157462] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.bak"] [unique_id "aoSDLE1jzAhYHVVT1WcQaAABhks"] [Tue Aug 18 13:07:08.429207 2026] [security2:error] [pid 157386:tid 157635] [client 135.225.75.187:41261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/scx.php7"] [unique_id "aoSDLE1jzAhYHVVT1WcQaQAAAYE"] [Tue Aug 18 13:07:08.451634 2026] [security2:error] [pid 157386:tid 157591] [client 104.209.144.33:32641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQawAAAVU"] [Tue Aug 18 13:07:08.483164 2026] [security2:error] [pid 157386:tid 157594] [client 20.116.17.175:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQbgAAAVg"] [Tue Aug 18 13:07:08.484089 2026] [security2:error] [pid 157386:tid 157606] [client 20.206.73.37:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/btx25.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQbwAAAWQ"] [Tue Aug 18 13:07:08.485232 2026] [security2:error] [pid 157386:tid 157614] [client 167.235.143.113:37588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/"] [unique_id "aoSDLE1jzAhYHVVT1WcQbQAAAWw"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 13:07:08.509159 2026] [security2:error] [pid 157386:tid 157567] [client 213.35.127.232:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQcgAAAT0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:08.525526 2026] [security2:error] [pid 157386:tid 157520] [client 52.173.121.69:52969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQdAAAAQ4"] [Tue Aug 18 13:07:08.596755 2026] [security2:error] [pid 157386:tid 157549] [client 20.1.169.243:15949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQeQAAASs"] [Tue Aug 18 13:07:08.597547 2026] [security2:error] [pid 157386:tid 157625] [client 74.248.18.37:61289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/js/wp-login.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQYgAAAXc"] [Tue Aug 18 13:07:08.607201 2026] [security2:error] [pid 157386:tid 157569] [client 68.221.73.131:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/fi22.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQegAAAT8"] [Tue Aug 18 13:07:08.619279 2026] [security2:error] [pid 157386:tid 157601] [client 158.158.74.177:17091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/lv.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQfwAAAV8"] [Tue Aug 18 13:07:08.632407 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:08.632666 2026] [authz_core:error] [pid 157386:tid 157388] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:08.648263 2026] [security2:error] [pid 157386:tid 157610] [client 20.251.48.93:35721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/aa2.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQggAAAWg"] [Tue Aug 18 13:07:08.653432 2026] [security2:error] [pid 157386:tid 157507] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/f35.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQhAABXXg"] [Tue Aug 18 13:07:08.661807 2026] [authz_core:error] [pid 157386:tid 157408] [remote 57.141.22.107:49686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:08.662251 2026] [authz_core:error] [pid 157386:tid 157408] [remote 57.141.22.107:49686] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:08.680089 2026] [autoindex:error] [pid 157386:tid 157459] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:08.692466 2026] [security2:error] [pid 157386:tid 157561] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/wlc.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQhgAAATc"] [Tue Aug 18 13:07:08.722971 2026] [security2:error] [pid 157386:tid 157584] [client 20.127.136.245:28145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQiQAAAU4"] [Tue Aug 18 13:07:08.724222 2026] [security2:error] [pid 157386:tid 157630] [client 20.116.17.175:45298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/xyn.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQigAAAXw"] [Tue Aug 18 13:07:08.743964 2026] [security2:error] [pid 157386:tid 157618] [client 20.171.51.14:2258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/87.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQiwAAAXA"] [Tue Aug 18 13:07:08.747317 2026] [security2:error] [pid 157386:tid 157531] [client 20.151.109.219:6023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/47.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQjAAAARk"] [Tue Aug 18 13:07:08.848596 2026] [security2:error] [pid 157386:tid 157538] [client 158.158.74.177:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQlQAAASA"] [Tue Aug 18 13:07:08.857104 2026] [security2:error] [pid 157386:tid 157542] [client 51.116.232.28:3038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/hp2.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQlgAAASQ"] [Tue Aug 18 13:07:08.859265 2026] [security2:error] [pid 157386:tid 157597] [client 135.225.75.187:35719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQlwAAAVs"] [Tue Aug 18 13:07:08.884075 2026] [security2:error] [pid 157386:tid 157510] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQmQABYXs"] [Tue Aug 18 13:07:08.884260 2026] [security2:error] [pid 157386:tid 157603] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQmQABYXs"] [Tue Aug 18 13:07:08.936086 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:08.936372 2026] [authz_core:error] [pid 157386:tid 157451] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:08.936837 2026] [security2:error] [pid 157386:tid 157546] [client 20.116.17.175:58383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/output.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQnwAAASg"] [Tue Aug 18 13:07:08.962528 2026] [security2:error] [pid 157386:tid 157541] [client 20.1.169.243:15775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/customize/about.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQoQAAASM"] [Tue Aug 18 13:07:08.971861 2026] [security2:error] [pid 157386:tid 157629] [client 74.248.18.37:21363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQowAAAXs"] [Tue Aug 18 13:07:08.980499 2026] [security2:error] [pid 157386:tid 157536] [client 20.104.100.201:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/dot.php"] [unique_id "aoSDLE1jzAhYHVVT1WcQpAAAAR4"] [Tue Aug 18 13:07:09.016505 2026] [security2:error] [pid 157386:tid 157551] [client 20.65.69.59:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/pqr.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQqQAAAS0"] [Tue Aug 18 13:07:09.023279 2026] [security2:error] [pid 157386:tid 157583] [client 20.151.109.219:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/payout.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQqwAAAU0"] [Tue Aug 18 13:07:09.026749 2026] [security2:error] [pid 157386:tid 157593] [client 4.232.151.198:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/file.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQrAAAAVc"] [Tue Aug 18 13:07:09.067081 2026] [security2:error] [pid 157386:tid 157592] [client 40.74.65.169:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.srasaneamento.com.br"] [uri "/g3.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQrQAAAVY"] [Tue Aug 18 13:07:09.079888 2026] [security2:error] [pid 157386:tid 157556] [client 20.251.48.93:44373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/xamp.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQrwAAATI"] [Tue Aug 18 13:07:09.080957 2026] [security2:error] [pid 157386:tid 157591] [client 20.116.17.175:1601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQsQAAAVU"] [Tue Aug 18 13:07:09.106144 2026] [security2:error] [pid 157386:tid 157394] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/inputs.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQswABHAc"] [Tue Aug 18 13:07:09.132137 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:49723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/m.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQtAAAARM"] [Tue Aug 18 13:07:09.133995 2026] [autoindex:error] [pid 157386:tid 157491] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:09.151665 2026] [security2:error] [pid 157386:tid 157566] [client 167.235.143.113:49026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.melocorretordeimoveis.com.br"] [uri "/index.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQrgAAATw"], referer: http://www.melocorretordeimoveis.com.br [Tue Aug 18 13:07:09.163198 2026] [security2:error] [pid 157386:tid 157521] [client 20.127.136.245:28143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wso.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQtgAAAQ8"] [Tue Aug 18 13:07:09.236750 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:09.237006 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:09.255914 2026] [security2:error] [pid 157386:tid 157524] [client 51.116.232.28:2655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/yb.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQxwAAARI"] [Tue Aug 18 13:07:09.276840 2026] [security2:error] [pid 157386:tid 157540] [client 135.225.75.187:11640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp5.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQyQAAASI"] [Tue Aug 18 13:07:09.292137 2026] [security2:error] [pid 157386:tid 157633] [client 104.209.144.33:25330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQygAAAX8"] [Tue Aug 18 13:07:09.303365 2026] [security2:error] [pid 157386:tid 157606] [client 158.158.74.177:4746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/mah/function.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQywAAAWQ"] [Tue Aug 18 13:07:09.315086 2026] [security2:error] [pid 157386:tid 157539] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/fi.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQzgAAASE"] [Tue Aug 18 13:07:09.334055 2026] [security2:error] [pid 157386:tid 157573] [client 20.1.169.243:15753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/about.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ0AAAAUM"] [Tue Aug 18 13:07:09.403688 2026] [security2:error] [pid 157386:tid 157581] [client 74.248.18.37:40326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/maint/xleet.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ1AAAAUs"] [Tue Aug 18 13:07:09.411922 2026] [security2:error] [pid 157386:tid 157618] [client 20.151.109.219:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/bh.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ1gAAAXA"] [Tue Aug 18 13:07:09.414789 2026] [security2:error] [pid 157386:tid 157588] [client 20.116.17.175:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ1wAAAVI"] [Tue Aug 18 13:07:09.478414 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:13764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ga.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ2wAAAXU"] [Tue Aug 18 13:07:09.479631 2026] [security2:error] [pid 157386:tid 157569] [client 158.158.74.177:16246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ3AAAAT8"] [Tue Aug 18 13:07:09.488172 2026] [autoindex:error] [pid 157386:tid 157526] [client 31.58.51.57:33258] AH01276: Cannot serve directory /home2/atlasi11/Map.atlas-ia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:09.520187 2026] [security2:error] [pid 157386:tid 157616] [client 20.116.17.175:45258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-good.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ3gAAAW4"] [Tue Aug 18 13:07:09.523895 2026] [security2:error] [pid 157386:tid 157543] [client 20.251.48.93:31233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/bless.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ3wAAASU"] [Tue Aug 18 13:07:09.529768 2026] [security2:error] [pid 157386:tid 157580] [client 213.35.127.232:61466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ4QAAAUo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:09.537242 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:09.537522 2026] [authz_core:error] [pid 157386:tid 157421] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:09.545506 2026] [security2:error] [pid 157386:tid 157602] [client 20.116.17.175:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/tiny2.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ4wAAAWA"] [Tue Aug 18 13:07:09.566240 2026] [security2:error] [pid 157386:tid 157541] [client 20.65.69.59:35395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/lmfi2.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ5QAAASM"] [Tue Aug 18 13:07:09.571886 2026] [security2:error] [pid 157386:tid 157532] [client 20.171.51.14:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/zi.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ5gAAARo"] [Tue Aug 18 13:07:09.602545 2026] [security2:error] [pid 157386:tid 157576] [client 74.248.18.37:18193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/mass.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ5wAAAUY"] [Tue Aug 18 13:07:09.658642 2026] [security2:error] [pid 157386:tid 157529] [client 51.116.232.28:2950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/vc.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ7AAAARc"] [Tue Aug 18 13:07:09.668801 2026] [security2:error] [pid 157386:tid 157631] [client 4.232.151.198:5410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ7QAAAX0"] [Tue Aug 18 13:07:09.683200 2026] [security2:error] [pid 157386:tid 157622] [client 20.151.109.219:40498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/nl.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ7gAAAXQ"] [Tue Aug 18 13:07:09.702998 2026] [security2:error] [pid 157386:tid 157592] [client 135.225.75.187:23039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/a2.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ7wAAAVY"] [Tue Aug 18 13:07:09.718426 2026] [security2:error] [pid 157386:tid 157591] [client 20.151.109.219:7320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/ct.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ8gAAAVU"] [Tue Aug 18 13:07:09.726303 2026] [security2:error] [pid 157386:tid 157460] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/firebase-config.json"] [unique_id "aoSDLU1jzAhYHVVT1WcQ8wABY0k"] [Tue Aug 18 13:07:09.735122 2026] [security2:error] [pid 157386:tid 157409] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSDLU1jzAhYHVVT1WcQ9AABHBY"] [Tue Aug 18 13:07:09.756587 2026] [security2:error] [pid 157386:tid 157518] [client 52.173.121.69:36606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wsrer.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ9QAAAQw"] [Tue Aug 18 13:07:09.772156 2026] [security2:error] [pid 157386:tid 157567] [client 20.104.100.201:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/005.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ9wAAAT0"] [Tue Aug 18 13:07:09.776841 2026] [security2:error] [pid 157386:tid 157471] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/alfa.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ-QABYlQ"] [Tue Aug 18 13:07:09.842343 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:09.842807 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:09.860346 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wmore1.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ_AAAAX4"] [Tue Aug 18 13:07:09.923056 2026] [security2:error] [pid 157386:tid 157643] [client 158.158.74.177:4736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/makeasmtp.php"] [unique_id "aoSDLU1jzAhYHVVT1WcQ_wAAAYk"] [Tue Aug 18 13:07:09.967183 2026] [security2:error] [pid 157386:tid 157539] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/chris.php"] [unique_id "aoSDLU1jzAhYHVVT1WcRAwAAASE"] [Tue Aug 18 13:07:09.994475 2026] [security2:error] [pid 157386:tid 157568] [client 20.151.109.219:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/gy.php"] [unique_id "aoSDLU1jzAhYHVVT1WcRBgAAAT4"] [Tue Aug 18 13:07:09.997674 2026] [security2:error] [pid 157386:tid 157481] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/lock360.php"] [unique_id "aoSDLU1jzAhYHVVT1WcRBwABN14"] [Tue Aug 18 13:07:10.066024 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wpxml.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRDAAAATk"] [Tue Aug 18 13:07:10.066686 2026] [security2:error] [pid 157386:tid 157560] [client 51.116.232.28:3035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/pema.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRDQAAATY"] [Tue Aug 18 13:07:10.086048 2026] [security2:error] [pid 157386:tid 157581] [client 20.251.48.93:44385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file25.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRDwAAAUs"] [Tue Aug 18 13:07:10.089893 2026] [access_compat:error] [pid 157386:tid 157531] [client 69.171.234.24:46678] AH01797: client denied by server configuration: /home2/wwwasjveiculos/public_html/meta.json [Tue Aug 18 13:07:10.123562 2026] [security2:error] [pid 157386:tid 157621] [client 20.65.69.59:1787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/info2.php"] [unique_id "aoSDLk1jzAhYHVVT1WcREwAAAXM"] [Tue Aug 18 13:07:10.124649 2026] [security2:error] [pid 157386:tid 157610] [client 135.225.75.187:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/app.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRFAAAAWg"] [Tue Aug 18 13:07:10.135970 2026] [security2:error] [pid 157386:tid 157542] [client 20.127.136.245:27994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/zup.php73"] [unique_id "aoSDLk1jzAhYHVVT1WcRFgAAASQ"] [Tue Aug 18 13:07:10.140304 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:10.140605 2026] [authz_core:error] [pid 157386:tid 157501] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:10.142973 2026] [security2:error] [pid 157386:tid 157538] [client 20.116.17.175:45285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/special.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRGAAAASA"] [Tue Aug 18 13:07:10.217411 2026] [security2:error] [pid 157386:tid 157572] [client 52.173.121.69:38340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRGwAAAUI"] [Tue Aug 18 13:07:10.261384 2026] [security2:error] [pid 157386:tid 157639] [client 149.34.210.141:64520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRIAAAAYU"] [Tue Aug 18 13:07:10.261545 2026] [security2:error] [pid 157386:tid 157639] [client 149.34.210.141:64520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRIAAAAYU"] [Tue Aug 18 13:07:10.269757 2026] [security2:error] [pid 157386:tid 157611] [client 20.151.109.219:49339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/tt.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRIgAAAWk"] [Tue Aug 18 13:07:10.314639 2026] [security2:error] [pid 157386:tid 157618] [client 74.248.18.37:21365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRJwAAAXA"] [Tue Aug 18 13:07:10.328284 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/68.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRKQAAAUk"] [Tue Aug 18 13:07:10.337765 2026] [security2:error] [pid 157386:tid 157583] [client 158.23.17.4:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRKwAAAU0"] [Tue Aug 18 13:07:10.349743 2026] [security2:error] [pid 157386:tid 157529] [client 158.158.74.177:24962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/ku.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRLwAAARc"] [Tue Aug 18 13:07:10.367842 2026] [security2:error] [pid 157386:tid 157615] [client 20.151.109.219:13790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/wb.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRMgAAAW0"] [Tue Aug 18 13:07:10.372656 2026] [security2:error] [pid 157386:tid 157614] [client 4.232.151.198:5417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/xmrlpc.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRNAAAAWw"] [Tue Aug 18 13:07:10.407288 2026] [security2:error] [pid 157386:tid 157609] [client 104.209.144.33:31266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRNwAAAWc"] [Tue Aug 18 13:07:10.440411 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:10.440706 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:10.448807 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:22637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDLk1jzAhYHVVT1WcROgAAAXE"] [Tue Aug 18 13:07:10.470013 2026] [security2:error] [pid 157386:tid 157620] [client 51.116.232.28:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/sh.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRPAAAAXI"] [Tue Aug 18 13:07:10.544127 2026] [security2:error] [pid 157386:tid 157553] [client 20.251.48.93:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file15.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRQgAAAS8"] [Tue Aug 18 13:07:10.553838 2026] [security2:error] [pid 157386:tid 157589] [client 158.158.74.177:17134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/mass.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRRQAAAVM"] [Tue Aug 18 13:07:10.554860 2026] [security2:error] [pid 157386:tid 157556] [client 20.104.100.201:17360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/v2.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRRgAAATI"] [Tue Aug 18 13:07:10.560462 2026] [security2:error] [pid 157386:tid 157575] [client 213.35.127.232:61719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRSAAAAUU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:10.576418 2026] [security2:error] [pid 157386:tid 157625] [client 20.116.17.175:58209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRSwAAAXc"] [Tue Aug 18 13:07:10.578183 2026] [security2:error] [pid 157386:tid 157447] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.vercel/.env"] [unique_id "aoSDLk1jzAhYHVVT1WcRTAABDjw"] [Tue Aug 18 13:07:10.605823 2026] [security2:error] [pid 157386:tid 157565] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/doc.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRTgAAATs"] [Tue Aug 18 13:07:10.606425 2026] [security2:error] [pid 157386:tid 157597] [client 20.151.109.219:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/mq.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRTwAAAVs"] [Tue Aug 18 13:07:10.649103 2026] [security2:error] [pid 157386:tid 157567] [client 20.127.136.245:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/k.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRUQAAAT0"] [Tue Aug 18 13:07:10.666359 2026] [security2:error] [pid 157386:tid 157633] [client 74.248.18.37:6438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-signdown.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRVAAAAX8"] [Tue Aug 18 13:07:10.693403 2026] [security2:error] [pid 157386:tid 157617] [client 158.23.17.4:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRWQAAAW8"] [Tue Aug 18 13:07:10.705137 2026] [security2:error] [pid 157386:tid 157641] [client 20.116.17.175:20309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/dk.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRWgAAAYc"] [Tue Aug 18 13:07:10.708981 2026] [security2:error] [pid 157386:tid 157607] [client 20.215.241.237:36244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/akismet.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRWwAAAWU"] [Tue Aug 18 13:07:10.717014 2026] [security2:error] [pid 157386:tid 157427] [remote 115.146.125.52:40590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "humanitics.com.br"] [uri "/wp-login.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRXAABJyg"] [Tue Aug 18 13:07:10.732410 2026] [security2:error] [pid 157386:tid 157402] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/flower.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRXgABGQ8"] [Tue Aug 18 13:07:10.740671 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:10.740950 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:10.770632 2026] [autoindex:error] [pid 157386:tid 157600] [client 135.225.75.187:23855] AH01276: Cannot serve directory /home2/mentevitta/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:10.793138 2026] [security2:error] [pid 157386:tid 157587] [client 20.116.17.175:63570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/thoms.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRYgAAAVE"] [Tue Aug 18 13:07:10.794961 2026] [security2:error] [pid 157386:tid 157570] [client 20.151.109.219:42805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/jl.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRYwAAAUA"] [Tue Aug 18 13:07:10.809952 2026] [autoindex:error] [pid 157386:tid 157585] [client 31.58.51.57:38238] AH01276: Cannot serve directory /home2/atlasi11/Map.atlas-ia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:10.826164 2026] [security2:error] [pid 157386:tid 157516] [client 20.65.69.59:29239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/test_info.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRZwAAAQo"] [Tue Aug 18 13:07:10.840223 2026] [security2:error] [pid 157386:tid 157582] [client 213.202.253.4:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/delpaths.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRaAAAAUw"], referer: www.google.com [Tue Aug 18 13:07:10.880135 2026] [security2:error] [pid 157386:tid 157639] [client 51.116.232.28:2974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/button.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRaQAAAYU"] [Tue Aug 18 13:07:10.957609 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:49317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/13.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRbAAAAUk"] [Tue Aug 18 13:07:10.958873 2026] [security2:error] [pid 157386:tid 157576] [client 20.151.109.219:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/xn.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRbQAAAUY"] [Tue Aug 18 13:07:10.976568 2026] [security2:error] [pid 157386:tid 157573] [client 74.248.18.37:11314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/meta.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRbgAAAUM"] [Tue Aug 18 13:07:10.996496 2026] [security2:error] [pid 157386:tid 157615] [client 20.251.48.93:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/f35.php"] [unique_id "aoSDLk1jzAhYHVVT1WcRcgAAAW0"] [Tue Aug 18 13:07:11.004760 2026] [security2:error] [pid 157386:tid 157538] [client 4.232.151.198:5387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/aj.php"] [unique_id "aoSDL01jzAhYHVVT1WcRcwAAASA"] [Tue Aug 18 13:07:11.042503 2026] [authz_core:error] [pid 157386:tid 157485] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:11.042772 2026] [authz_core:error] [pid 157386:tid 157485] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:11.057308 2026] [security2:error] [pid 157386:tid 157394] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/"] [unique_id "aoSDL01jzAhYHVVT1WcRdgABawc"] [Tue Aug 18 13:07:11.058917 2026] [security2:error] [pid 157386:tid 157491] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/download"] [unique_id "aoSDL01jzAhYHVVT1WcRdwABa2g"] [Tue Aug 18 13:07:11.062608 2026] [security2:error] [pid 157386:tid 157437] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcReAABVjI"] [Tue Aug 18 13:07:11.064002 2026] [security2:error] [pid 157386:tid 157609] [client 158.23.17.4:38366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/st.php"] [unique_id "aoSDL01jzAhYHVVT1WcReQAAAWc"] [Tue Aug 18 13:07:11.067152 2026] [security2:error] [pid 157386:tid 157591] [client 20.116.17.175:1098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDL01jzAhYHVVT1WcRegAAAVU"] [Tue Aug 18 13:07:11.088616 2026] [security2:error] [pid 157386:tid 157465] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/read"] [unique_id "aoSDL01jzAhYHVVT1WcRfAABHE4"] [Tue Aug 18 13:07:11.101585 2026] [security2:error] [pid 157386:tid 157422] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/read"] [unique_id "aoSDL01jzAhYHVVT1WcRfgABUiM"] [Tue Aug 18 13:07:11.102805 2026] [security2:error] [pid 157386:tid 157445] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/api/file"] [unique_id "aoSDL01jzAhYHVVT1WcRfQABUjo"] [Tue Aug 18 13:07:11.187781 2026] [security2:error] [pid 157386:tid 157583] [client 158.158.74.177:17106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/memberfuns.php"] [unique_id "aoSDL01jzAhYHVVT1WcRhQAAAU0"] [Tue Aug 18 13:07:11.187916 2026] [security2:error] [pid 157386:tid 157557] [client 158.158.74.177:9330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/chosen.php"] [unique_id "aoSDL01jzAhYHVVT1WcRhAAAATM"] [Tue Aug 18 13:07:11.189370 2026] [security2:error] [pid 157386:tid 157632] [client 135.225.75.187:23855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDL01jzAhYHVVT1WcRhgAAAX4"] [Tue Aug 18 13:07:11.232400 2026] [security2:error] [pid 157386:tid 157625] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/1337.php"] [unique_id "aoSDL01jzAhYHVVT1WcRiQAAAXc"] [Tue Aug 18 13:07:11.236839 2026] [security2:error] [pid 157386:tid 157544] [client 20.104.100.201:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wkl.php"] [unique_id "aoSDL01jzAhYHVVT1WcRigAAASY"] [Tue Aug 18 13:07:11.241950 2026] [security2:error] [pid 157386:tid 157500] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcRjAABDnE"] [Tue Aug 18 13:07:11.243796 2026] [security2:error] [pid 157386:tid 157540] [client 20.65.69.59:29208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/xynz1.php"] [unique_id "aoSDL01jzAhYHVVT1WcRjQAAASI"] [Tue Aug 18 13:07:11.253831 2026] [security2:error] [pid 157386:tid 157396] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcRjgABegk"] [Tue Aug 18 13:07:11.286192 2026] [security2:error] [pid 157386:tid 157443] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcRkQABPTg"] [Tue Aug 18 13:07:11.288543 2026] [security2:error] [pid 157386:tid 157601] [client 51.116.232.28:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/wlc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRkgAAAV8"] [Tue Aug 18 13:07:11.298499 2026] [security2:error] [pid 157386:tid 157640] [client 20.116.17.175:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ccou.php"] [unique_id "aoSDL01jzAhYHVVT1WcRkwAAAYY"] [Tue Aug 18 13:07:11.317668 2026] [security2:error] [pid 157386:tid 157525] [client 20.151.109.219:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/so.php"] [unique_id "aoSDL01jzAhYHVVT1WcRlQAAARM"] [Tue Aug 18 13:07:11.324108 2026] [autoindex:error] [pid 157386:tid 157599] [client 169.58.72.248:53167] AH01276: Cannot serve directory /home3/adobankcom/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:11.334695 2026] [security2:error] [pid 157386:tid 157617] [client 20.151.109.219:40480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/tq.php"] [unique_id "aoSDL01jzAhYHVVT1WcRlwAAAW8"] [Tue Aug 18 13:07:11.341228 2026] [security2:error] [pid 157386:tid 157537] [client 157.20.138.62:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRmQAAAR8"] [Tue Aug 18 13:07:11.341392 2026] [security2:error] [pid 157386:tid 157537] [client 157.20.138.62:52360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRmQAAAR8"] [Tue Aug 18 13:07:11.343632 2026] [security2:error] [pid 157386:tid 157527] [client 74.248.130.103:28056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDL01jzAhYHVVT1WcRmgAAARU"] [Tue Aug 18 13:07:11.343665 2026] [authz_core:error] [pid 157386:tid 157391] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:11.343950 2026] [authz_core:error] [pid 157386:tid 157391] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:11.382181 2026] [security2:error] [pid 157386:tid 157467] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/13.php"] [unique_id "aoSDL01jzAhYHVVT1WcRnwABNlA"] [Tue Aug 18 13:07:11.418877 2026] [security2:error] [pid 157386:tid 157542] [client 20.116.17.175:1120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/root.php"] [unique_id "aoSDL01jzAhYHVVT1WcRowAAASQ"] [Tue Aug 18 13:07:11.438881 2026] [security2:error] [pid 157386:tid 157464] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcRpQABWE0"] [Tue Aug 18 13:07:11.457737 2026] [security2:error] [pid 157386:tid 157572] [client 20.251.48.93:14672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-load.php"] [unique_id "aoSDL01jzAhYHVVT1WcRqwAAAUI"] [Tue Aug 18 13:07:11.460770 2026] [security2:error] [pid 157386:tid 157582] [client 52.173.121.69:52311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tinoequipamentos.com.br"] [uri "/images/security.php"] [unique_id "aoSDL01jzAhYHVVT1WcRrAAAAUw"] [Tue Aug 18 13:07:11.477843 2026] [security2:error] [pid 157386:tid 157558] [client 158.23.17.4:7301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/le.php"] [unique_id "aoSDL01jzAhYHVVT1WcRrQAAATQ"] [Tue Aug 18 13:07:11.508716 2026] [security2:error] [pid 157386:tid 157606] [client 74.248.18.37:32465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/pki-validation/flower.php"] [unique_id "aoSDL01jzAhYHVVT1WcRsAAAAWQ"] [Tue Aug 18 13:07:11.525936 2026] [security2:error] [pid 157386:tid 157444] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDL01jzAhYHVVT1WcRsQABTjk"] [Tue Aug 18 13:07:11.569471 2026] [security2:error] [pid 157386:tid 157610] [client 20.65.69.59:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/album.php"] [unique_id "aoSDL01jzAhYHVVT1WcRtAAAAWg"] [Tue Aug 18 13:07:11.582912 2026] [security2:error] [pid 157386:tid 157565] [client 213.35.127.232:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDL01jzAhYHVVT1WcRtgAAATs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:11.587741 2026] [security2:error] [pid 157386:tid 157579] [client 68.221.73.131:17536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDL01jzAhYHVVT1WcRtwAAAUk"] [Tue Aug 18 13:07:11.610109 2026] [security2:error] [pid 157386:tid 157577] [client 74.248.18.37:11277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/mini.php"] [unique_id "aoSDL01jzAhYHVVT1WcRuwAAAUc"] [Tue Aug 18 13:07:11.610991 2026] [security2:error] [pid 157386:tid 157642] [client 101.53.230.88:49043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.230.53.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRugAAAYg"] [Tue Aug 18 13:07:11.611135 2026] [security2:error] [pid 157386:tid 157642] [client 101.53.230.88:49043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRugAAAYg"] [Tue Aug 18 13:07:11.612627 2026] [security2:error] [pid 157386:tid 157631] [client 135.225.75.187:35769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/cxc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRvAAAAX0"] [Tue Aug 18 13:07:11.615686 2026] [security2:error] [pid 157386:tid 157495] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/cc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRvQABF2w"] [Tue Aug 18 13:07:11.629123 2026] [security2:error] [pid 157386:tid 157573] [client 20.151.109.219:39837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/10.php"] [unique_id "aoSDL01jzAhYHVVT1WcRvwAAAUM"] [Tue Aug 18 13:07:11.647940 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:11.648389 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:11.714274 2026] [security2:error] [pid 157386:tid 157504] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/claude_desktop_config.json"] [unique_id "aoSDL01jzAhYHVVT1WcRxAABC3U"] [Tue Aug 18 13:07:11.721137 2026] [security2:error] [pid 157386:tid 157518] [client 178.153.171.161:27911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRxgAAAQw"] [Tue Aug 18 13:07:11.721300 2026] [security2:error] [pid 157386:tid 157518] [client 178.153.171.161:27911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRxgAAAQw"] [Tue Aug 18 13:07:11.728197 2026] [security2:error] [pid 157386:tid 157619] [client 20.116.17.175:1608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fpwch.php"] [unique_id "aoSDL01jzAhYHVVT1WcRxwAAAXE"] [Tue Aug 18 13:07:11.730974 2026] [security2:error] [pid 157386:tid 157588] [client 51.116.232.28:2986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/fi.php"] [unique_id "aoSDL01jzAhYHVVT1WcRyAAAAVI"] [Tue Aug 18 13:07:11.733277 2026] [security2:error] [pid 157386:tid 157586] [client 20.127.136.245:28002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDL01jzAhYHVVT1WcRyQAAAVA"] [Tue Aug 18 13:07:11.770031 2026] [security2:error] [pid 157386:tid 157611] [client 4.232.151.198:18963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "aoSDL01jzAhYHVVT1WcRygAAAWk"] [Tue Aug 18 13:07:11.781360 2026] [security2:error] [pid 157386:tid 157620] [client 102.213.179.104:54034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRywAAAXI"] [Tue Aug 18 13:07:11.781544 2026] [security2:error] [pid 157386:tid 157620] [client 102.213.179.104:54034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDL01jzAhYHVVT1WcRywAAAXI"] [Tue Aug 18 13:07:11.839923 2026] [security2:error] [pid 157386:tid 157460] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDL01jzAhYHVVT1WcRzwABd0k"] [Tue Aug 18 13:07:11.852339 2026] [security2:error] [pid 157386:tid 157540] [client 74.248.130.103:28075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDL01jzAhYHVVT1WcR0QAAASI"] [Tue Aug 18 13:07:11.860150 2026] [security2:error] [pid 157386:tid 157597] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/Njima.php"] [unique_id "aoSDL01jzAhYHVVT1WcR0gAAAVs"] [Tue Aug 18 13:07:11.871604 2026] [security2:error] [pid 157386:tid 157614] [client 158.158.74.177:17112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/meta.php"] [unique_id "aoSDL01jzAhYHVVT1WcR0wAAAWw"] [Tue Aug 18 13:07:11.885805 2026] [security2:error] [pid 157386:tid 157567] [client 158.23.17.4:39586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/hr.php"] [unique_id "aoSDL01jzAhYHVVT1WcR1AAAAT0"] [Tue Aug 18 13:07:11.888909 2026] [security2:error] [pid 157386:tid 157564] [client 158.158.74.177:9324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/asd.php"] [unique_id "aoSDL01jzAhYHVVT1WcR1QAAATo"] [Tue Aug 18 13:07:11.903642 2026] [security2:error] [pid 157386:tid 157601] [client 20.116.17.175:20365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/bal.php"] [unique_id "aoSDL01jzAhYHVVT1WcR1gAAAV8"] [Tue Aug 18 13:07:11.933677 2026] [security2:error] [pid 157386:tid 157617] [client 20.116.17.175:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/crgio.php"] [unique_id "aoSDL01jzAhYHVVT1WcR2QAAAW8"] [Tue Aug 18 13:07:11.945855 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:11.946187 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:11.958692 2026] [security2:error] [pid 157386:tid 157560] [client 20.151.109.219:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/te.php"] [unique_id "aoSDL01jzAhYHVVT1WcR3QAAATY"] [Tue Aug 18 13:07:12.029166 2026] [security2:error] [pid 157386:tid 157603] [client 135.225.75.187:11630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDME1jzAhYHVVT1WcR4QAAAWE"] [Tue Aug 18 13:07:12.032256 2026] [security2:error] [pid 157386:tid 157582] [client 20.65.69.59:29242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/creds.php"] [unique_id "aoSDME1jzAhYHVVT1WcR4gAAAUw"] [Tue Aug 18 13:07:12.082529 2026] [security2:error] [pid 157386:tid 157418] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDME1jzAhYHVVT1WcR4wABHR8"] [Tue Aug 18 13:07:12.083596 2026] [security2:error] [pid 157386:tid 157416] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSDME1jzAhYHVVT1WcR5AABYB0"] [Tue Aug 18 13:07:12.084239 2026] [security2:error] [pid 157386:tid 157549] [client 20.151.109.219:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/47.php"] [unique_id "aoSDME1jzAhYHVVT1WcR5QAAASs"] [Tue Aug 18 13:07:12.093937 2026] [security2:error] [pid 157386:tid 157606] [client 20.116.17.175:45277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/mg.php"] [unique_id "aoSDME1jzAhYHVVT1WcR5wAAAWQ"] [Tue Aug 18 13:07:12.139039 2026] [security2:error] [pid 157386:tid 157563] [client 51.116.232.28:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/chris.php"] [unique_id "aoSDME1jzAhYHVVT1WcR6wAAATk"] [Tue Aug 18 13:07:12.146287 2026] [security2:error] [pid 157386:tid 157527] [client 52.28.162.93:1384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dadicamotors.com.br"] [uri "/index.php"] [unique_id "aoSDME1jzAhYHVVT1WcR6gAAARU"], referer: https://dadicamotors.com.br/ [Tue Aug 18 13:07:12.154387 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:17395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-asudo.php"] [unique_id "aoSDME1jzAhYHVVT1WcR7AAAARg"] [Tue Aug 18 13:07:12.190225 2026] [security2:error] [pid 157386:tid 157587] [client 20.151.109.219:46538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/cv.php"] [unique_id "aoSDME1jzAhYHVVT1WcR8AAAAVE"] [Tue Aug 18 13:07:12.222156 2026] [security2:error] [pid 157386:tid 157636] [client 20.104.100.201:53344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDME1jzAhYHVVT1WcR8wAAAYI"] [Tue Aug 18 13:07:12.233317 2026] [security2:error] [pid 157386:tid 157518] [client 20.151.109.219:39822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/kc.php"] [unique_id "aoSDME1jzAhYHVVT1WcR9gAAAQw"] [Tue Aug 18 13:07:12.235434 2026] [security2:error] [pid 157386:tid 157419] [remote 129.121.103.155:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSDME1jzAhYHVVT1WcR9QABcSA"] [Tue Aug 18 13:07:12.246706 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:12.247054 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:12.272580 2026] [security2:error] [pid 157386:tid 157572] [client 74.248.18.37:21321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/mm.php"] [unique_id "aoSDME1jzAhYHVVT1WcR-QAAAUI"] [Tue Aug 18 13:07:12.310245 2026] [security2:error] [pid 157386:tid 157620] [client 74.248.130.103:11084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDME1jzAhYHVVT1WcR-wAAAXI"] [Tue Aug 18 13:07:12.327539 2026] [security2:error] [pid 157386:tid 157557] [client 158.23.17.4:20625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kt.php"] [unique_id "aoSDME1jzAhYHVVT1WcR_AAAATM"] [Tue Aug 18 13:07:12.396712 2026] [security2:error] [pid 157386:tid 157567] [client 20.251.48.93:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSDME1jzAhYHVVT1WcSAQAAAT0"] [Tue Aug 18 13:07:12.424379 2026] [security2:error] [pid 157386:tid 157577] [client 74.248.18.37:32511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/.dj/index.php"] [unique_id "aoSDME1jzAhYHVVT1WcSAgAAAUc"] [Tue Aug 18 13:07:12.453969 2026] [security2:error] [pid 157386:tid 157607] [client 135.225.75.187:23621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/0.php"] [unique_id "aoSDME1jzAhYHVVT1WcSCwAAAWU"] [Tue Aug 18 13:07:12.455110 2026] [security2:error] [pid 157386:tid 157624] [client 104.209.144.33:31241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDME1jzAhYHVVT1WcSEgAAAXY"] [Tue Aug 18 13:07:12.469688 2026] [security2:error] [pid 157386:tid 157574] [client 20.116.17.175:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/reop3.php"] [unique_id "aoSDME1jzAhYHVVT1WcSFQAAAUQ"] [Tue Aug 18 13:07:12.470364 2026] [security2:error] [pid 157386:tid 157562] [client 20.65.69.59:19540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/mandrill.php"] [unique_id "aoSDME1jzAhYHVVT1WcSFgAAATg"] [Tue Aug 18 13:07:12.494791 2026] [security2:error] [pid 157386:tid 157578] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDME1jzAhYHVVT1WcSGQAAAUg"] [Tue Aug 18 13:07:12.506274 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/jn.php"] [unique_id "aoSDME1jzAhYHVVT1WcSGwAAAWE"] [Tue Aug 18 13:07:12.514190 2026] [security2:error] [pid 157386:tid 157611] [client 158.158.74.177:16207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/akc.php"] [unique_id "aoSDME1jzAhYHVVT1WcSHgAAAWk"] [Tue Aug 18 13:07:12.517672 2026] [security2:error] [pid 157386:tid 157521] [client 158.158.74.177:4752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/mini.php"] [unique_id "aoSDME1jzAhYHVVT1WcSHwAAAQ8"] [Tue Aug 18 13:07:12.520116 2026] [security2:error] [pid 157386:tid 157638] [client 46.102.21.132:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDME1jzAhYHVVT1WcR_wAAAYQ"] [Tue Aug 18 13:07:12.520222 2026] [security2:error] [pid 157386:tid 157638] [client 46.102.21.132:58518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDME1jzAhYHVVT1WcR_wAAAYQ"] [Tue Aug 18 13:07:12.533400 2026] [security2:error] [pid 157386:tid 157616] [client 20.116.17.175:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDME1jzAhYHVVT1WcSIAAAAW4"] [Tue Aug 18 13:07:12.533716 2026] [security2:error] [pid 157386:tid 157558] [client 20.151.109.219:17659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/payout.php"] [unique_id "aoSDME1jzAhYHVVT1WcSIQAAATQ"] [Tue Aug 18 13:07:12.539102 2026] [security2:error] [pid 157386:tid 157627] [client 51.116.232.28:3021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/doc.php"] [unique_id "aoSDME1jzAhYHVVT1WcSIgAAAXk"] [Tue Aug 18 13:07:12.550015 2026] [authz_core:error] [pid 157386:tid 157417] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:12.550432 2026] [authz_core:error] [pid 157386:tid 157417] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:12.600429 2026] [security2:error] [pid 157386:tid 157547] [client 213.35.127.232:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDME1jzAhYHVVT1WcSLgAAASk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:12.656445 2026] [security2:error] [pid 157386:tid 157593] [client 20.65.98.162:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/images.php"] [unique_id "aoSDME1jzAhYHVVT1WcSNQAAAVc"] [Tue Aug 18 13:07:12.656476 2026] [security2:error] [pid 157386:tid 157527] [client 20.127.136.245:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/ww5.php"] [unique_id "aoSDME1jzAhYHVVT1WcSNgAAARU"] [Tue Aug 18 13:07:12.680290 2026] [security2:error] [pid 157386:tid 157573] [client 20.116.17.175:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/yawa.php"] [unique_id "aoSDME1jzAhYHVVT1WcSOAAAAUM"] [Tue Aug 18 13:07:12.708871 2026] [security2:error] [pid 157386:tid 157592] [client 4.232.151.198:5398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/images/Mhbgf.php"] [unique_id "aoSDME1jzAhYHVVT1WcSOgAAAVY"] [Tue Aug 18 13:07:12.709048 2026] [security2:error] [pid 157386:tid 157629] [client 20.151.109.219:20981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/un.php"] [unique_id "aoSDME1jzAhYHVVT1WcSOwAAAXs"] [Tue Aug 18 13:07:12.734475 2026] [security2:error] [pid 157386:tid 157407] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/01.php"] [unique_id "aoSDME1jzAhYHVVT1WcSPgABTxQ"] [Tue Aug 18 13:07:12.755292 2026] [security2:error] [pid 157386:tid 157635] [client 20.116.17.175:1612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/php5.php"] [unique_id "aoSDME1jzAhYHVVT1WcSPwAAAYE"] [Tue Aug 18 13:07:12.834972 2026] [security2:error] [pid 157386:tid 157590] [client 20.151.109.219:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.hospitalhacos.org.br"] [uri "/bf.php"] [unique_id "aoSDME1jzAhYHVVT1WcSQwAAAVQ"] [Tue Aug 18 13:07:12.844999 2026] [security2:error] [pid 157386:tid 157552] [client 158.23.17.4:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ww.php"] [unique_id "aoSDME1jzAhYHVVT1WcSRQAAAS4"] [Tue Aug 18 13:07:12.848471 2026] [authz_core:error] [pid 157386:tid 157502] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:12.848770 2026] [authz_core:error] [pid 157386:tid 157502] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:12.852049 2026] [security2:error] [pid 157386:tid 157554] [client 74.248.130.103:28080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/av.php"] [unique_id "aoSDME1jzAhYHVVT1WcSRgAAATA"] [Tue Aug 18 13:07:12.873774 2026] [security2:error] [pid 157386:tid 157540] [client 135.225.75.187:23861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/dom.php"] [unique_id "aoSDME1jzAhYHVVT1WcSRwAAASI"] [Tue Aug 18 13:07:12.904567 2026] [security2:error] [pid 157386:tid 157613] [client 74.248.18.37:21327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSDME1jzAhYHVVT1WcSYAAAAWs"] [Tue Aug 18 13:07:12.910950 2026] [security2:error] [pid 157386:tid 157567] [client 20.251.48.93:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/aaa.php"] [unique_id "aoSDME1jzAhYHVVT1WcSYQAAAT0"] [Tue Aug 18 13:07:12.935665 2026] [security2:error] [pid 157386:tid 157537] [client 20.215.241.237:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/admin.php"] [unique_id "aoSDME1jzAhYHVVT1WcSZQAAAR8"] [Tue Aug 18 13:07:12.959931 2026] [security2:error] [pid 157386:tid 157607] [client 51.116.232.28:2658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/1337.php"] [unique_id "aoSDME1jzAhYHVVT1WcSbAAAAWU"] [Tue Aug 18 13:07:12.964233 2026] [security2:error] [pid 157386:tid 157408] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/lv.php"] [unique_id "aoSDME1jzAhYHVVT1WcSbQABGRU"] [Tue Aug 18 13:07:12.981712 2026] [security2:error] [pid 157386:tid 157562] [client 20.116.17.175:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/css.php"] [unique_id "aoSDME1jzAhYHVVT1WcSbgAAATg"] [Tue Aug 18 13:07:13.002568 2026] [security2:error] [pid 157386:tid 157467] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/download"] [unique_id "aoSDMU1jzAhYHVVT1WcScAABXlA"] [Tue Aug 18 13:07:13.056459 2026] [security2:error] [pid 157386:tid 157603] [client 20.151.109.219:56009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bh.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSeQAAAWE"] [Tue Aug 18 13:07:13.091657 2026] [security2:error] [pid 157386:tid 157525] [client 172.182.217.32:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/index.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSfAAAARM"] [Tue Aug 18 13:07:13.098127 2026] [security2:error] [pid 157386:tid 157618] [client 20.65.69.59:29207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/main.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSfwAAAXA"] [Tue Aug 18 13:07:13.101282 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSgAAAAYU"] [Tue Aug 18 13:07:13.110786 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:22568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/acp.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSgQAAASs"] [Tue Aug 18 13:07:13.119421 2026] [security2:error] [pid 157386:tid 157536] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/too.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSgwAAAR4"] [Tue Aug 18 13:07:13.125089 2026] [security2:error] [pid 157386:tid 157595] [client 20.127.136.245:28114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/2.php"] [unique_id "aoSDMU1jzAhYHVVT1WcShAAAAVk"] [Tue Aug 18 13:07:13.141729 2026] [security2:error] [pid 157386:tid 157599] [client 158.158.74.177:4759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/mm.php"] [unique_id "aoSDMU1jzAhYHVVT1WcShgAAAV0"] [Tue Aug 18 13:07:13.148824 2026] [security2:error] [pid 157386:tid 157632] [client 20.206.73.37:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSigAAAX4"] [Tue Aug 18 13:07:13.154489 2026] [authz_core:error] [pid 157386:tid 157400] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:13.154772 2026] [authz_core:error] [pid 157386:tid 157400] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:13.160744 2026] [security2:error] [pid 157386:tid 157535] [client 138.36.100.162:42540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSjAAAAR0"] [Tue Aug 18 13:07:13.160837 2026] [security2:error] [pid 157386:tid 157535] [client 138.36.100.162:42540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSjAAAAR0"] [Tue Aug 18 13:07:13.185571 2026] [fcgid:warn] [pid 157386:tid 157631] (70014)End of file found: [client 195.170.172.216:39318] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:13.189090 2026] [security2:error] [pid 157386:tid 157450] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/new.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSkgABiT8"] [Tue Aug 18 13:07:13.224349 2026] [security2:error] [pid 157386:tid 157517] [client 20.151.109.219:20720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/evil.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSlgAAAQs"] [Tue Aug 18 13:07:13.228516 2026] [security2:error] [pid 157386:tid 157576] [client 158.158.74.177:25013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/maintenance.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSmQAAAUY"] [Tue Aug 18 13:07:13.238144 2026] [autoindex:error] [pid 157386:tid 157539] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:13.239601 2026] [security2:error] [pid 157386:tid 157585] [client 20.104.100.201:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/az.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSmwAAAU8"] [Tue Aug 18 13:07:13.267332 2026] [autoindex:error] [pid 157386:tid 157610] [client 172.182.217.32:4051] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:13.320944 2026] [security2:error] [pid 157386:tid 157526] [client 135.225.75.187:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/bb.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSpgAAARQ"] [Tue Aug 18 13:07:13.327787 2026] [security2:error] [pid 157386:tid 157627] [client 74.248.18.37:32453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/moduleswp.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSpwAAAXk"] [Tue Aug 18 13:07:13.364412 2026] [security2:error] [pid 157386:tid 157544] [client 51.116.232.28:2680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/Njima.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSqQAAASY"] [Tue Aug 18 13:07:13.397183 2026] [security2:error] [pid 157386:tid 157614] [client 20.116.17.175:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSugAAAWw"] [Tue Aug 18 13:07:13.421932 2026] [security2:error] [pid 157386:tid 157397] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/222.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSvgABago"] [Tue Aug 18 13:07:13.430374 2026] [security2:error] [pid 157386:tid 157551] [client 172.182.217.32:4051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/admin.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSvwAAAS0"] [Tue Aug 18 13:07:13.454348 2026] [security2:error] [pid 157386:tid 157623] [client 74.248.130.103:11094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/images.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSwwAAAXU"] [Tue Aug 18 13:07:13.469213 2026] [security2:error] [pid 157386:tid 157580] [client 20.251.48.93:14664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/gecko.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSyQAAAUo"] [Tue Aug 18 13:07:13.470114 2026] [security2:error] [pid 157386:tid 157600] [client 20.116.17.175:22529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/yas.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSygAAAV4"] [Tue Aug 18 13:07:13.509310 2026] [security2:error] [pid 157386:tid 157611] [client 20.116.17.175:20393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/7.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSzgAAAWk"] [Tue Aug 18 13:07:13.536282 2026] [security2:error] [pid 157386:tid 157604] [client 74.248.18.37:11298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/moon.php"] [unique_id "aoSDMU1jzAhYHVVT1WcSzwAAAWI"] [Tue Aug 18 13:07:13.579434 2026] [fcgid:warn] [pid 157386:tid 157639] (70014)End of file found: [client 195.170.172.216:39334] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:13.589500 2026] [autoindex:error] [pid 157386:tid 157606] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:13.606905 2026] [security2:error] [pid 157386:tid 157641] [client 20.127.136.245:28237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS1QAAAYc"] [Tue Aug 18 13:07:13.609497 2026] [security2:error] [pid 157386:tid 157505] [remote 66.102.134.13:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tomiogroup.com.br"] [uri "/wp-login.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS1gABLHY"] [Tue Aug 18 13:07:13.619134 2026] [security2:error] [pid 157386:tid 157554] [client 213.35.127.232:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS1wAAATA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:13.676830 2026] [security2:error] [pid 157386:tid 157595] [client 20.151.109.219:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/ct.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS2wAAAVk"] [Tue Aug 18 13:07:13.679523 2026] [security2:error] [pid 157386:tid 157566] [client 4.232.151.198:5392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/images/cloud.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS3QAAATw"] [Tue Aug 18 13:07:13.733209 2026] [security2:error] [pid 157386:tid 157527] [client 40.80.82.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.82.80.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupoi9x.com.br"] [uri "/g3.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS4wAAARU"] [Tue Aug 18 13:07:13.739877 2026] [security2:error] [pid 157386:tid 157446] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/chosen.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS5AABTTs"] [Tue Aug 18 13:07:13.742748 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:54017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/z43agz.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS5QAAARg"] [Tue Aug 18 13:07:13.749462 2026] [security2:error] [pid 157386:tid 157615] [client 135.225.75.187:35756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ok.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS6AAAAW0"] [Tue Aug 18 13:07:13.751315 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:13.751573 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:13.798787 2026] [security2:error] [pid 157386:tid 157622] [client 20.116.17.175:20402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ws77.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS6QAAAXQ"] [Tue Aug 18 13:07:13.806594 2026] [security2:error] [pid 157386:tid 157592] [client 51.116.232.28:2635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS6gAAAVY"] [Tue Aug 18 13:07:13.828894 2026] [security2:error] [pid 157386:tid 157534] [client 20.116.17.175:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ah25.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS7AAAARw"] [Tue Aug 18 13:07:13.847600 2026] [security2:error] [pid 157386:tid 157545] [client 158.158.74.177:24981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/options-writing.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS7QAAASc"] [Tue Aug 18 13:07:13.868888 2026] [security2:error] [pid 157386:tid 157558] [client 158.158.74.177:17114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/modules/mod_footer.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS7wAAATQ"] [Tue Aug 18 13:07:13.914614 2026] [security2:error] [pid 157386:tid 157503] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDMU1jzAhYHVVT1WcS8gABL3Q"] [Tue Aug 18 13:07:13.915407 2026] [security2:error] [pid 157386:tid 157524] [client 20.226.112.14:61318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/public/hi.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS9AAAARI"] [Tue Aug 18 13:07:13.916598 2026] [autoindex:error] [pid 157386:tid 157575] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:13.924224 2026] [security2:error] [pid 157386:tid 157643] [client 172.182.217.32:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/api.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS9gAAAYk"] [Tue Aug 18 13:07:13.926802 2026] [security2:error] [pid 157386:tid 157557] [client 20.226.112.14:61747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/get.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS9wAAATM"] [Tue Aug 18 13:07:13.940192 2026] [security2:error] [pid 157386:tid 157552] [client 20.226.112.14:38269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/rpk.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS-AAAAS4"] [Tue Aug 18 13:07:13.950536 2026] [security2:error] [pid 157386:tid 157630] [client 20.226.112.14:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS-gAAAXw"] [Tue Aug 18 13:07:13.960422 2026] [security2:error] [pid 157386:tid 157627] [client 20.226.112.14:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/mga.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS-wAAAXk"] [Tue Aug 18 13:07:13.970893 2026] [security2:error] [pid 157386:tid 157544] [client 20.226.112.14:61312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/fs.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS_QAAASY"] [Tue Aug 18 13:07:13.976595 2026] [security2:error] [pid 157386:tid 157427] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/info.php"] [unique_id "aoSDMU1jzAhYHVVT1WcS_gABPSg"] [Tue Aug 18 13:07:13.978530 2026] [fcgid:warn] [pid 157386:tid 157628] (70014)End of file found: [client 195.170.172.216:39352] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:13.979441 2026] [security2:error] [pid 157386:tid 157601] [client 20.226.112.14:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/wp-tem.php"] [unique_id "aoSDMU1jzAhYHVVT1WcTAAAAAV8"] [Tue Aug 18 13:07:13.987853 2026] [security2:error] [pid 157386:tid 157439] [remote 115.146.125.52:40600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSDMU1jzAhYHVVT1WcTAQABazQ"] [Tue Aug 18 13:07:13.988533 2026] [security2:error] [pid 157386:tid 157614] [client 20.226.112.14:61750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/sadd.php"] [unique_id "aoSDMU1jzAhYHVVT1WcTAgAAAWw"] [Tue Aug 18 13:07:13.999062 2026] [security2:error] [pid 157386:tid 157537] [client 20.226.112.14:51545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ex.php"] [unique_id "aoSDMU1jzAhYHVVT1WcTAwAAAR8"] [Tue Aug 18 13:07:14.009918 2026] [security2:error] [pid 157386:tid 157607] [client 20.226.112.14:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/tax.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTBQAAAWU"] [Tue Aug 18 13:07:14.014613 2026] [security2:error] [pid 157386:tid 157584] [client 20.116.17.175:58197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/epinyins.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTBgAAAU4"] [Tue Aug 18 13:07:14.019829 2026] [security2:error] [pid 157386:tid 157574] [client 20.226.112.14:55319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/X7x.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTBwAAAUQ"] [Tue Aug 18 13:07:14.029672 2026] [security2:error] [pid 157386:tid 157580] [client 20.226.112.14:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ocxla.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTCAAAAUo"] [Tue Aug 18 13:07:14.038587 2026] [security2:error] [pid 157386:tid 157586] [client 20.226.112.14:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/post.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTCQAAAVA"] [Tue Aug 18 13:07:14.049239 2026] [security2:error] [pid 157386:tid 157611] [client 20.226.112.14:61737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/nhr.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTCwAAAWk"] [Tue Aug 18 13:07:14.051357 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:14.051618 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:14.052658 2026] [security2:error] [pid 157386:tid 157638] [client 20.251.48.93:16810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/xiugai.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTDAAAAYQ"] [Tue Aug 18 13:07:14.067442 2026] [security2:error] [pid 157386:tid 157604] [client 20.226.112.14:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTDQAAAWI"] [Tue Aug 18 13:07:14.077514 2026] [security2:error] [pid 157386:tid 157639] [client 20.226.112.14:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ws79.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTDgAAAYU"] [Tue Aug 18 13:07:14.087840 2026] [security2:error] [pid 157386:tid 157641] [client 20.226.112.14:61312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/rtx.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTEAAAAYc"] [Tue Aug 18 13:07:14.098231 2026] [security2:error] [pid 157386:tid 157554] [client 20.226.112.14:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/end.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTEQAAATA"] [Tue Aug 18 13:07:14.107176 2026] [security2:error] [pid 157386:tid 157536] [client 20.226.112.14:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.112.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brazilcoa.com.br"] [uri "/ae.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTEwAAAR4"] [Tue Aug 18 13:07:14.120422 2026] [security2:error] [pid 157386:tid 157565] [client 20.65.69.59:1457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/payout.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTFQAAATs"] [Tue Aug 18 13:07:14.138959 2026] [security2:error] [pid 157386:tid 157570] [client 74.248.130.103:11131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/ops.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTFwAAAUA"] [Tue Aug 18 13:07:14.151989 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/read.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTGAAAAWE"] [Tue Aug 18 13:07:14.167376 2026] [security2:error] [pid 157386:tid 157520] [client 74.248.18.37:11266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/n.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTGQAAAQ4"] [Tue Aug 18 13:07:14.173294 2026] [security2:error] [pid 157386:tid 157591] [client 135.225.75.187:41263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp9.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTGwAAAVU"] [Tue Aug 18 13:07:14.204875 2026] [security2:error] [pid 157386:tid 157642] [client 51.116.232.28:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/too.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTHwAAAYg"] [Tue Aug 18 13:07:14.220437 2026] [security2:error] [pid 157386:tid 157631] [client 20.104.100.201:54075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/3.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTIAAAAX0"] [Tue Aug 18 13:07:14.248856 2026] [security2:error] [pid 157386:tid 157617] [client 20.116.17.175:22581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ano.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTIgAAAW8"] [Tue Aug 18 13:07:14.318592 2026] [autoindex:error] [pid 157386:tid 157632] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:14.355220 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:14.355478 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:14.360149 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:33836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pw.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTJwAAAUw"] [Tue Aug 18 13:07:14.367494 2026] [security2:error] [pid 157386:tid 157532] [client 74.248.18.37:32484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-tinymce.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTKAAAARo"] [Tue Aug 18 13:07:14.372789 2026] [fcgid:warn] [pid 157386:tid 157553] (70014)End of file found: [client 195.170.172.216:39368] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:14.379547 2026] [security2:error] [pid 157386:tid 157538] [client 20.116.17.175:64963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/load.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTKwAAASA"] [Tue Aug 18 13:07:14.385479 2026] [security2:error] [pid 157386:tid 157552] [client 20.151.109.219:27733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/gy.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTLAAAAS4"] [Tue Aug 18 13:07:14.428221 2026] [security2:error] [pid 157386:tid 157630] [client 158.23.17.4:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mo.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTLwAAAXw"] [Tue Aug 18 13:07:14.436087 2026] [security2:error] [pid 157386:tid 157622] [client 172.182.217.32:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/ms-files.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTMAAAAXQ"] [Tue Aug 18 13:07:14.444695 2026] [security2:error] [pid 157386:tid 157526] [client 40.74.65.169:7145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTMQAAARQ"] [Tue Aug 18 13:07:14.493528 2026] [security2:error] [pid 157386:tid 157592] [client 158.158.74.177:17132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/moon.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTMwAAAVY"] [Tue Aug 18 13:07:14.537808 2026] [security2:error] [pid 157386:tid 157640] [client 20.215.241.237:62243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/bajah.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTNQAAAYY"] [Tue Aug 18 13:07:14.554004 2026] [security2:error] [pid 157386:tid 157612] [client 20.116.17.175:1627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/nwflm.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTNwAAAWo"] [Tue Aug 18 13:07:14.554179 2026] [security2:error] [pid 157386:tid 157585] [client 158.158.74.177:24988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTNgAAAU8"] [Tue Aug 18 13:07:14.556335 2026] [security2:error] [pid 157386:tid 157445] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTOAABYzo"] [Tue Aug 18 13:07:14.595780 2026] [security2:error] [pid 157386:tid 157600] [client 135.225.75.187:23809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ws59.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTOwAAAV4"] [Tue Aug 18 13:07:14.601192 2026] [security2:error] [pid 157386:tid 157564] [client 20.116.17.175:20359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/albin.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTPAAAATo"] [Tue Aug 18 13:07:14.605666 2026] [security2:error] [pid 157386:tid 157586] [client 51.116.232.28:2682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.232.116.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sprintlimp.com.br"] [uri "/g3.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTPQAAAVA"] [Tue Aug 18 13:07:14.617572 2026] [security2:error] [pid 157386:tid 157638] [client 20.104.100.201:53875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/log.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTPgAAAYQ"] [Tue Aug 18 13:07:14.632899 2026] [security2:error] [pid 157386:tid 157516] [client 20.251.48.93:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/adminner.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTPwAAAQo"] [Tue Aug 18 13:07:14.638623 2026] [security2:error] [pid 157386:tid 157534] [client 213.35.127.232:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTQQAAARw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:14.639238 2026] [security2:error] [pid 157386:tid 157616] [client 20.65.98.162:37655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/admin.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTQgAAAW4"] [Tue Aug 18 13:07:14.697370 2026] [security2:error] [pid 157386:tid 157589] [client 20.127.136.245:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/atomlib.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTRwAAAVM"] [Tue Aug 18 13:07:14.708369 2026] [security2:error] [pid 157386:tid 157597] [client 4.232.151.198:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/router.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTSgAAAVs"] [Tue Aug 18 13:07:14.711018 2026] [autoindex:error] [pid 157386:tid 157595] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:14.730557 2026] [security2:error] [pid 157386:tid 157565] [client 74.248.130.103:54050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/coffexium.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTTAAAATs"] [Tue Aug 18 13:07:14.740184 2026] [security2:error] [pid 157386:tid 157578] [client 20.116.17.175:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTTQAAAUg"] [Tue Aug 18 13:07:14.761640 2026] [security2:error] [pid 157386:tid 157591] [client 158.23.17.4:5039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/qr.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTUQAAAVU"] [Tue Aug 18 13:07:14.764945 2026] [fcgid:warn] [pid 157386:tid 157517] (70014)End of file found: [client 195.170.172.216:39380] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:14.785286 2026] [security2:error] [pid 157386:tid 157486] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTVgABe2M"] [Tue Aug 18 13:07:14.803206 2026] [security2:error] [pid 157386:tid 157635] [client 20.65.69.59:22018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/Mailgun.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTWQAAAYE"] [Tue Aug 18 13:07:14.817288 2026] [security2:error] [pid 157386:tid 157521] [client 74.248.18.37:11276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/nc4.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTWwAAAQ8"] [Tue Aug 18 13:07:14.818775 2026] [security2:error] [pid 157386:tid 157624] [client 197.184.64.235:42686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTXAAAAXY"] [Tue Aug 18 13:07:14.828610 2026] [security2:error] [pid 157386:tid 157624] [client 197.184.64.235:42686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTXAAAAXY"] [Tue Aug 18 13:07:14.829243 2026] [security2:error] [pid 157386:tid 157532] [client 20.116.17.175:22625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-load.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTXQAAARo"] [Tue Aug 18 13:07:14.862427 2026] [security2:error] [pid 157386:tid 157620] [client 20.151.109.219:27729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/tt.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTYAAAAXI"] [Tue Aug 18 13:07:14.930330 2026] [security2:error] [pid 157386:tid 157642] [client 172.182.217.32:4159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/plugin-install.php"] [unique_id "aoSDMk1jzAhYHVVT1WcTYwAAAYg"] [Tue Aug 18 13:07:14.957396 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:14.957647 2026] [authz_core:error] [pid 157386:tid 157464] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:15.005847 2026] [security2:error] [pid 157386:tid 157605] [client 68.221.73.131:8183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSDM01jzAhYHVVT1WcTdQAAAWM"] [Tue Aug 18 13:07:15.012076 2026] [security2:error] [pid 157386:tid 157537] [client 135.225.75.187:35714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSDM01jzAhYHVVT1WcTdgAAAR8"] [Tue Aug 18 13:07:15.012381 2026] [security2:error] [pid 157386:tid 157623] [client 20.151.109.219:33524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fn.php"] [unique_id "aoSDM01jzAhYHVVT1WcTdwAAAXU"] [Tue Aug 18 13:07:15.055295 2026] [security2:error] [pid 157386:tid 157460] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDM01jzAhYHVVT1WcTfAABXkk"] [Tue Aug 18 13:07:15.064004 2026] [security2:error] [pid 157386:tid 157542] [client 20.171.51.14:55893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/92.php"] [unique_id "aoSDM01jzAhYHVVT1WcTfQAAASQ"] [Tue Aug 18 13:07:15.072937 2026] [security2:error] [pid 157386:tid 157432] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin.php"] [unique_id "aoSDM01jzAhYHVVT1WcTgQABhC0"] [Tue Aug 18 13:07:15.112707 2026] [security2:error] [pid 157386:tid 157581] [client 158.158.74.177:17144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/n.php"] [unique_id "aoSDM01jzAhYHVVT1WcTgwAAAUs"] [Tue Aug 18 13:07:15.119401 2026] [security2:error] [pid 157386:tid 157544] [client 20.116.17.175:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/jj.php"] [unique_id "aoSDM01jzAhYHVVT1WcThAAAASY"] [Tue Aug 18 13:07:15.138274 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/fw/34.php"] [unique_id "aoSDM01jzAhYHVVT1WcThQAAAYU"] [Tue Aug 18 13:07:15.162466 2026] [security2:error] [pid 157386:tid 157540] [client 74.248.18.37:25012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/base.php"] [unique_id "aoSDM01jzAhYHVVT1WcTiAAAASI"] [Tue Aug 18 13:07:15.183064 2026] [security2:error] [pid 157386:tid 157614] [client 158.158.74.177:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/maint.php"] [unique_id "aoSDM01jzAhYHVVT1WcTigAAAWw"] [Tue Aug 18 13:07:15.199779 2026] [security2:error] [pid 157386:tid 157554] [client 158.23.17.4:44710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/dirs.php"] [unique_id "aoSDM01jzAhYHVVT1WcTjAAAATA"] [Tue Aug 18 13:07:15.200536 2026] [security2:error] [pid 157386:tid 157559] [client 74.248.130.103:43072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDM01jzAhYHVVT1WcTjQAAATU"] [Tue Aug 18 13:07:15.217385 2026] [security2:error] [pid 157386:tid 157452] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTkAABI0E"] [Tue Aug 18 13:07:15.217538 2026] [security2:error] [pid 157386:tid 157541] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTkAABI0E"] [Tue Aug 18 13:07:15.231889 2026] [security2:error] [pid 157386:tid 157595] [client 40.74.65.169:7104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDM01jzAhYHVVT1WcTkgAAAVk"] [Tue Aug 18 13:07:15.240432 2026] [security2:error] [pid 157386:tid 157565] [client 20.151.109.219:23163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/mq.php"] [unique_id "aoSDM01jzAhYHVVT1WcTkwAAATs"] [Tue Aug 18 13:07:15.269438 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ty.php"] [unique_id "aoSDM01jzAhYHVVT1WcTlgAAAWE"] [Tue Aug 18 13:07:15.282585 2026] [security2:error] [pid 157386:tid 157419] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDM01jzAhYHVVT1WcTlwABOSA"] [Tue Aug 18 13:07:15.289183 2026] [security2:error] [pid 157386:tid 157636] [client 20.215.241.237:62722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/ajax.php"] [unique_id "aoSDM01jzAhYHVVT1WcTmgAAAYI"] [Tue Aug 18 13:07:15.295831 2026] [security2:error] [pid 157386:tid 157591] [client 20.206.73.37:55332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDM01jzAhYHVVT1WcTmwAAAVU"] [Tue Aug 18 13:07:15.341654 2026] [security2:error] [pid 157386:tid 157641] [client 196.12.128.158:63907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTnQAAAYc"] [Tue Aug 18 13:07:15.341779 2026] [security2:error] [pid 157386:tid 157641] [client 196.12.128.158:63907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTnQAAAYc"] [Tue Aug 18 13:07:15.343366 2026] [security2:error] [pid 157386:tid 157618] [client 4.232.151.198:18991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/shop.php"] [unique_id "aoSDM01jzAhYHVVT1WcTngAAAXA"] [Tue Aug 18 13:07:15.349440 2026] [security2:error] [pid 157386:tid 157534] [client 20.127.136.245:28257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/rip.php"] [unique_id "aoSDM01jzAhYHVVT1WcTnwAAARw"] [Tue Aug 18 13:07:15.368398 2026] [security2:error] [pid 157386:tid 157632] [client 20.251.48.93:3513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file1221.php"] [unique_id "aoSDM01jzAhYHVVT1WcToQAAAX4"] [Tue Aug 18 13:07:15.412715 2026] [security2:error] [pid 157386:tid 157524] [client 20.65.69.59:1294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/oauth.php"] [unique_id "aoSDM01jzAhYHVVT1WcTpAAAARI"] [Tue Aug 18 13:07:15.419078 2026] [security2:error] [pid 157386:tid 157570] [client 172.182.217.32:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/wp-activate.php"] [unique_id "aoSDM01jzAhYHVVT1WcTpgAAAUA"] [Tue Aug 18 13:07:15.432949 2026] [security2:error] [pid 157386:tid 157620] [client 135.225.75.187:11638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSDM01jzAhYHVVT1WcTpwAAAXI"] [Tue Aug 18 13:07:15.448858 2026] [security2:error] [pid 157386:tid 157557] [client 20.104.100.201:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ohct.php"] [unique_id "aoSDM01jzAhYHVVT1WcTqQAAATM"] [Tue Aug 18 13:07:15.448896 2026] [security2:error] [pid 157386:tid 157566] [client 74.248.18.37:18207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/new.php"] [unique_id "aoSDM01jzAhYHVVT1WcTqAAAATw"] [Tue Aug 18 13:07:15.450981 2026] [security2:error] [pid 157386:tid 157567] [client 49.145.211.146:10970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTmQAAAT0"] [Tue Aug 18 13:07:15.451074 2026] [security2:error] [pid 157386:tid 157567] [client 49.145.211.146:10970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDM01jzAhYHVVT1WcTmQAAAT0"] [Tue Aug 18 13:07:15.476047 2026] [security2:error] [pid 157386:tid 157552] [client 20.116.17.175:63558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/img.php"] [unique_id "aoSDM01jzAhYHVVT1WcTrAAAAS4"] [Tue Aug 18 13:07:15.502854 2026] [security2:error] [pid 157386:tid 157457] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/k.php"] [unique_id "aoSDM01jzAhYHVVT1WcTrwABiEY"] [Tue Aug 18 13:07:15.540295 2026] [authz_core:error] [pid 157386:tid 157409] [remote 57.141.22.35:49188] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:15.540774 2026] [authz_core:error] [pid 157386:tid 157409] [remote 57.141.22.35:49188] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:15.560420 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:15.560876 2026] [authz_core:error] [pid 157386:tid 157424] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:15.580261 2026] [security2:error] [pid 157386:tid 157627] [client 158.23.17.4:39569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sn.php"] [unique_id "aoSDM01jzAhYHVVT1WcTwAAAAXk"] [Tue Aug 18 13:07:15.638229 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.130.103:58269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/sf.php"] [unique_id "aoSDM01jzAhYHVVT1WcTxwAAAWk"] [Tue Aug 18 13:07:15.665075 2026] [security2:error] [pid 157386:tid 157615] [client 213.35.127.232:63008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDM01jzAhYHVVT1WcTyQAAAW0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:15.702766 2026] [security2:error] [pid 157386:tid 157616] [client 20.151.109.219:42785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kf.php"] [unique_id "aoSDM01jzAhYHVVT1WcTzAAAAW4"] [Tue Aug 18 13:07:15.729643 2026] [security2:error] [pid 157386:tid 157587] [client 158.158.74.177:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/nc4.php"] [unique_id "aoSDM01jzAhYHVVT1WcT4gAAAVE"] [Tue Aug 18 13:07:15.739281 2026] [security2:error] [pid 157386:tid 157414] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/public/css.php"] [unique_id "aoSDM01jzAhYHVVT1WcT5AABIhs"] [Tue Aug 18 13:07:15.806842 2026] [security2:error] [pid 157386:tid 157565] [client 20.251.48.93:16809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/inx.php"] [unique_id "aoSDM01jzAhYHVVT1WcT6AAAATs"] [Tue Aug 18 13:07:15.817356 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:45302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/we.php"] [unique_id "aoSDM01jzAhYHVVT1WcT6QAAAV0"] [Tue Aug 18 13:07:15.854650 2026] [security2:error] [pid 157386:tid 157571] [client 135.225.75.187:31821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/vx.php"] [unique_id "aoSDM01jzAhYHVVT1WcT7gAAAUE"] [Tue Aug 18 13:07:15.859782 2026] [authz_core:error] [pid 157386:tid 157415] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:15.860080 2026] [authz_core:error] [pid 157386:tid 157415] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:15.898899 2026] [security2:error] [pid 157386:tid 157581] [client 158.158.74.177:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/phpMailer.php"] [unique_id "aoSDM01jzAhYHVVT1WcT8AAAAUs"] [Tue Aug 18 13:07:15.899533 2026] [security2:error] [pid 157386:tid 157549] [client 20.127.136.245:28282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/p.php"] [unique_id "aoSDM01jzAhYHVVT1WcT8QAAASs"] [Tue Aug 18 13:07:15.911336 2026] [security2:error] [pid 157386:tid 157591] [client 52.173.121.69:28321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/ucpfr.php"] [unique_id "aoSDM01jzAhYHVVT1WcT8gAAAVU"] [Tue Aug 18 13:07:15.911471 2026] [security2:error] [pid 157386:tid 157614] [client 172.182.217.32:4060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/plugins/wp-load.php"] [unique_id "aoSDM01jzAhYHVVT1WcT8wAAAWw"] [Tue Aug 18 13:07:15.912250 2026] [security2:error] [pid 157386:tid 157517] [client 20.116.17.175:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp9.php"] [unique_id "aoSDM01jzAhYHVVT1WcT9AAAAQs"] [Tue Aug 18 13:07:15.915943 2026] [security2:error] [pid 157386:tid 157604] [client 158.23.17.4:4641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/43.php"] [unique_id "aoSDM01jzAhYHVVT1WcT9QAAAWI"] [Tue Aug 18 13:07:15.946212 2026] [security2:error] [pid 157386:tid 157518] [client 40.74.65.169:21352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/domvf.php"] [unique_id "aoSDM01jzAhYHVVT1WcT9wAAAQw"] [Tue Aug 18 13:07:15.969883 2026] [security2:error] [pid 157386:tid 157497] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/403.php"] [unique_id "aoSDM01jzAhYHVVT1WcT-QABe24"] [Tue Aug 18 13:07:15.977074 2026] [security2:error] [pid 157386:tid 157394] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/classwithtostring.php"] [unique_id "aoSDM01jzAhYHVVT1WcT-gABcAc"] [Tue Aug 18 13:07:16.016180 2026] [security2:error] [pid 157386:tid 157576] [client 20.171.51.14:55924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/jm.php"] [unique_id "aoSDNE1jzAhYHVVT1WcT_QAAAUY"] [Tue Aug 18 13:07:16.034165 2026] [security2:error] [pid 157386:tid 157578] [client 4.232.151.198:22303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-info.php"] [unique_id "aoSDNE1jzAhYHVVT1WcT_wAAAUg"] [Tue Aug 18 13:07:16.051173 2026] [security2:error] [pid 157386:tid 157573] [client 74.248.18.37:40342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/dichku.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUAAAAAUM"] [Tue Aug 18 13:07:16.097577 2026] [security2:error] [pid 157386:tid 157620] [client 20.151.109.219:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/13.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUAwAAAXI"] [Tue Aug 18 13:07:16.120442 2026] [autoindex:error] [pid 157386:tid 157580] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:16.120832 2026] [security2:error] [pid 157386:tid 157610] [client 20.215.241.237:37237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.smaveiculos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUCAAAAWg"] [Tue Aug 18 13:07:16.127679 2026] [security2:error] [pid 157386:tid 157530] [client 74.248.18.37:11273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/packed.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUCgAAARg"] [Tue Aug 18 13:07:16.160855 2026] [authz_core:error] [pid 157386:tid 157491] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:16.161143 2026] [authz_core:error] [pid 157386:tid 157491] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:16.198281 2026] [security2:error] [pid 157386:tid 157592] [client 20.65.69.59:21171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/timeclock.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUDgAAAVY"] [Tue Aug 18 13:07:16.266975 2026] [security2:error] [pid 157386:tid 157640] [client 158.23.17.4:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fresh.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUEQAAAYY"] [Tue Aug 18 13:07:16.270861 2026] [security2:error] [pid 157386:tid 157556] [client 20.151.109.219:36290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/su.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUEgAAATI"] [Tue Aug 18 13:07:16.271190 2026] [security2:error] [pid 157386:tid 157521] [client 135.225.75.187:11605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ah25.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUEwAAAQ8"] [Tue Aug 18 13:07:16.311402 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.130.103:64530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/k.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUFgAAAWk"] [Tue Aug 18 13:07:16.344811 2026] [security2:error] [pid 157386:tid 157486] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-supports/"] [unique_id "aoSDNE1jzAhYHVVT1WcUGQABcWM"] [Tue Aug 18 13:07:16.344821 2026] [security2:error] [pid 157386:tid 157538] [client 20.104.100.201:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ot.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUGAAAASA"] [Tue Aug 18 13:07:16.349815 2026] [security2:error] [pid 157386:tid 157569] [client 158.158.74.177:17108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/new.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUGgAAAT8"] [Tue Aug 18 13:07:16.355806 2026] [security2:error] [pid 157386:tid 157586] [client 20.251.48.93:26350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/reviall.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUGwAAAVA"] [Tue Aug 18 13:07:16.367320 2026] [security2:error] [pid 157386:tid 157544] [client 20.116.17.175:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUHQAAASY"] [Tue Aug 18 13:07:16.379372 2026] [security2:error] [pid 157386:tid 157598] [client 20.65.98.162:63510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/222.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUIAAAAVw"] [Tue Aug 18 13:07:16.383486 2026] [security2:error] [pid 157386:tid 157582] [client 24.77.77.1:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.77.77.24.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imagination.net.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUHgAAAUw"] [Tue Aug 18 13:07:16.383614 2026] [security2:error] [pid 157386:tid 157582] [client 24.77.77.1:13210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "imagination.net.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUHgAAAUw"] [Tue Aug 18 13:07:16.391136 2026] [security2:error] [pid 157386:tid 157475] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDNE1jzAhYHVVT1WcUIQABd1g"] [Tue Aug 18 13:07:16.400341 2026] [security2:error] [pid 157386:tid 157623] [client 20.127.136.245:28008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.luvhost.com.br"] [uri "/php.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUIgAAAXU"] [Tue Aug 18 13:07:16.403249 2026] [security2:error] [pid 157386:tid 157529] [client 172.182.217.32:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/themes/api.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUIwAAARc"] [Tue Aug 18 13:07:16.446313 2026] [security2:error] [pid 157386:tid 157638] [client 20.116.17.175:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/save.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUJgAAAYQ"] [Tue Aug 18 13:07:16.462654 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:16.462938 2026] [authz_core:error] [pid 157386:tid 157429] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:16.504308 2026] [autoindex:error] [pid 157386:tid 157589] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:16.515791 2026] [security2:error] [pid 157386:tid 157574] [client 158.158.74.177:25023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUKgAAAUQ"] [Tue Aug 18 13:07:16.552817 2026] [security2:error] [pid 157386:tid 157563] [client 5.31.227.224:30438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNE1jzAhYHVVT1WcULAAAATk"] [Tue Aug 18 13:07:16.553006 2026] [security2:error] [pid 157386:tid 157563] [client 5.31.227.224:30438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNE1jzAhYHVVT1WcULAAAATk"] [Tue Aug 18 13:07:16.609805 2026] [security2:error] [pid 157386:tid 157401] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/admin.php"] [unique_id "aoSDNE1jzAhYHVVT1WcULQABCw4"] [Tue Aug 18 13:07:16.689753 2026] [security2:error] [pid 157386:tid 157615] [client 213.35.127.232:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUMgAAAW0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:16.689811 2026] [security2:error] [pid 157386:tid 157632] [client 135.225.75.187:11611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/tt.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUMwAAAX4"] [Tue Aug 18 13:07:16.694169 2026] [security2:error] [pid 157386:tid 157547] [client 4.232.151.198:5437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/public_html/wp-content/uploads/users.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUNAAAASk"] [Tue Aug 18 13:07:16.728751 2026] [security2:error] [pid 157386:tid 157575] [client 20.206.73.37:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUNQAAAUU"] [Tue Aug 18 13:07:16.763210 2026] [security2:error] [pid 157386:tid 157631] [client 40.74.65.169:21319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUOQAAAX0"] [Tue Aug 18 13:07:16.765409 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:16.765650 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:16.805404 2026] [security2:error] [pid 157386:tid 157524] [client 158.23.17.4:7324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gj.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUPQAAARI"] [Tue Aug 18 13:07:16.814455 2026] [autoindex:error] [pid 157386:tid 157609] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:16.858107 2026] [security2:error] [pid 157386:tid 157474] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gelay.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUQAABPVc"] [Tue Aug 18 13:07:16.865916 2026] [security2:error] [pid 157386:tid 157580] [client 74.248.130.103:51520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/82.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUQQAAAUo"] [Tue Aug 18 13:07:16.888915 2026] [security2:error] [pid 157386:tid 157485] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/gecko.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUQgABGGI"] [Tue Aug 18 13:07:16.892170 2026] [security2:error] [pid 157386:tid 157578] [client 172.182.217.32:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/themes/db-status.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUQwAAAUg"] [Tue Aug 18 13:07:16.930886 2026] [security2:error] [pid 157386:tid 157592] [client 20.116.17.175:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/dot.php"] [unique_id "aoSDNE1jzAhYHVVT1WcURAAAAVY"] [Tue Aug 18 13:07:16.938305 2026] [security2:error] [pid 157386:tid 157628] [client 20.65.69.59:19530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/email.php"] [unique_id "aoSDNE1jzAhYHVVT1WcURQAAAXo"] [Tue Aug 18 13:07:16.945860 2026] [security2:error] [pid 157386:tid 157613] [client 20.151.109.219:27713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/so.php"] [unique_id "aoSDNE1jzAhYHVVT1WcURgAAAWs"] [Tue Aug 18 13:07:16.968018 2026] [security2:error] [pid 157386:tid 157612] [client 158.158.74.177:4417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/packed.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUSAAAAWo"] [Tue Aug 18 13:07:16.975119 2026] [security2:error] [pid 157386:tid 157627] [client 74.248.18.37:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/image.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUSQAAAXk"] [Tue Aug 18 13:07:16.980452 2026] [security2:error] [pid 157386:tid 157521] [client 74.248.18.37:11285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/plugin.php"] [unique_id "aoSDNE1jzAhYHVVT1WcUSgAAAQ8"] [Tue Aug 18 13:07:17.000860 2026] [security2:error] [pid 157386:tid 157531] [client 20.116.17.175:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUTgAAARk"] [Tue Aug 18 13:07:17.022225 2026] [security2:error] [pid 157386:tid 157542] [client 20.251.48.93:52435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/11.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUUAAAASQ"] [Tue Aug 18 13:07:17.070076 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:17.070401 2026] [authz_core:error] [pid 157386:tid 157495] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:17.086172 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:46562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wp-key.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUUgAAAVc"] [Tue Aug 18 13:07:17.107600 2026] [security2:error] [pid 157386:tid 157625] [client 135.225.75.187:11631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xqq.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUUwAAAXc"] [Tue Aug 18 13:07:17.152707 2026] [security2:error] [pid 157386:tid 157543] [client 158.23.17.4:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pd.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUVgAAASU"] [Tue Aug 18 13:07:17.231018 2026] [security2:error] [pid 157386:tid 157607] [client 158.158.74.177:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/al.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUWgAAAWU"] [Tue Aug 18 13:07:17.277444 2026] [autoindex:error] [pid 157386:tid 157603] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:17.324363 2026] [security2:error] [pid 157386:tid 157435] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUXQABFDA"] [Tue Aug 18 13:07:17.327349 2026] [security2:error] [pid 157386:tid 157537] [client 4.232.151.198:5423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/x.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUXgAAAR8"] [Tue Aug 18 13:07:17.385565 2026] [security2:error] [pid 157386:tid 157601] [client 172.182.217.32:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/themes/module.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUYQAAAV8"] [Tue Aug 18 13:07:17.404740 2026] [security2:error] [pid 157386:tid 157629] [client 20.251.48.93:16830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/File.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUZQAAAXs"] [Tue Aug 18 13:07:17.425365 2026] [security2:error] [pid 157386:tid 157396] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/.env.local.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUZgABcAk"] [Tue Aug 18 13:07:17.427487 2026] [security2:error] [pid 157386:tid 157451] [remote 47.128.18.73:44402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vipshopps.com.br"] [uri "/"] [unique_id "aoSDNU1jzAhYHVVT1WcUZwABT0A"] [Tue Aug 18 13:07:17.438935 2026] [security2:error] [pid 157386:tid 157615] [client 74.248.130.103:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/dex.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUaAAAAW0"] [Tue Aug 18 13:07:17.447892 2026] [security2:error] [pid 157386:tid 157573] [client 20.250.13.23:8252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/inputs.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUawAAAUM"] [Tue Aug 18 13:07:17.492525 2026] [security2:error] [pid 157386:tid 157568] [client 158.23.17.4:20642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/th.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUbAAAAT4"] [Tue Aug 18 13:07:17.529935 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:20587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gec.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUbQAAAS8"] [Tue Aug 18 13:07:17.530675 2026] [security2:error] [pid 157386:tid 157624] [client 135.225.75.187:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/06.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUbgAAAXY"] [Tue Aug 18 13:07:17.539046 2026] [security2:error] [pid 157386:tid 157609] [client 20.116.17.175:20379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUcAAAAWc"] [Tue Aug 18 13:07:17.547109 2026] [autoindex:error] [pid 157386:tid 157620] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:17.548667 2026] [security2:error] [pid 157386:tid 157566] [client 20.79.204.6:5748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/g.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUcwAAATw"] [Tue Aug 18 13:07:17.589829 2026] [security2:error] [pid 157386:tid 157513] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/aa.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUeAABSn4"] [Tue Aug 18 13:07:17.589900 2026] [security2:error] [pid 157386:tid 157467] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/adminfuns.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUdwABOlA"] [Tue Aug 18 13:07:17.604706 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:17294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/v5.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUegAAARg"] [Tue Aug 18 13:07:17.666239 2026] [security2:error] [pid 157386:tid 157628] [client 20.151.109.219:38643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gg.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUfwAAAXo"] [Tue Aug 18 13:07:17.668205 2026] [authz_core:error] [pid 157386:tid 157408] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:17.668474 2026] [authz_core:error] [pid 157386:tid 157408] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:17.727368 2026] [security2:error] [pid 157386:tid 157518] [client 213.35.127.232:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUgQAAAQw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:17.735423 2026] [security2:error] [pid 157386:tid 157577] [client 20.151.109.219:21942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/10.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUggAAAUc"] [Tue Aug 18 13:07:17.795669 2026] [security2:error] [pid 157386:tid 157538] [client 158.158.74.177:17150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/plugin.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUhQAAASA"] [Tue Aug 18 13:07:17.798889 2026] [security2:error] [pid 157386:tid 157569] [client 20.116.17.175:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/005.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUhwAAAT8"] [Tue Aug 18 13:07:17.807526 2026] [security2:error] [pid 157386:tid 157567] [client 20.79.204.6:5759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/gecko.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUiQAAAT0"] [Tue Aug 18 13:07:17.813255 2026] [security2:error] [pid 157386:tid 157418] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/0x.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUigABJh8"] [Tue Aug 18 13:07:17.823511 2026] [security2:error] [pid 157386:tid 157593] [client 20.251.48.93:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/fi22.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUiwAAAVc"] [Tue Aug 18 13:07:17.830775 2026] [security2:error] [pid 157386:tid 157599] [client 104.209.144.33:32644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUjAAAAV0"] [Tue Aug 18 13:07:17.841198 2026] [security2:error] [pid 157386:tid 157625] [client 74.248.18.37:21336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/public/moon.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUjQAAAXc"] [Tue Aug 18 13:07:17.855699 2026] [security2:error] [pid 157386:tid 157641] [client 223.185.37.47:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUjgAAAYc"] [Tue Aug 18 13:07:17.855849 2026] [security2:error] [pid 157386:tid 157641] [client 223.185.37.47:11311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUjgAAAYc"] [Tue Aug 18 13:07:17.885288 2026] [security2:error] [pid 157386:tid 157630] [client 158.158.74.177:9310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUkQAAAXw"] [Tue Aug 18 13:07:17.889002 2026] [security2:error] [pid 157386:tid 157640] [client 172.182.217.32:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/languages/themes/wp-activate.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUkgAAAYY"] [Tue Aug 18 13:07:17.923927 2026] [security2:error] [pid 157386:tid 157565] [client 49.37.150.8:52485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUlQAAATs"] [Tue Aug 18 13:07:17.924046 2026] [security2:error] [pid 157386:tid 157565] [client 49.37.150.8:52485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUlQAAATs"] [Tue Aug 18 13:07:17.936612 2026] [security2:error] [pid 157386:tid 157471] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/"] [unique_id "aoSDNU1jzAhYHVVT1WcUlgABNVQ"] [Tue Aug 18 13:07:17.951433 2026] [fcgid:warn] [pid 157386:tid 157589] (70014)End of file found: [client 195.170.172.216:39460] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:17.954418 2026] [security2:error] [pid 157386:tid 157579] [client 135.225.75.187:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/166.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUmQAAAUk"] [Tue Aug 18 13:07:17.956190 2026] [autoindex:error] [pid 157386:tid 157536] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:17.966786 2026] [security2:error] [pid 157386:tid 157638] [client 20.116.17.175:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/df.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUmwAAAYQ"] [Tue Aug 18 13:07:17.982990 2026] [security2:error] [pid 157386:tid 157516] [client 74.248.130.103:43102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/puc.php"] [unique_id "aoSDNU1jzAhYHVVT1WcUnQAAAQo"] [Tue Aug 18 13:07:18.034013 2026] [security2:error] [pid 157386:tid 157517] [client 158.23.17.4:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/admin404.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUnwAAAQs"] [Tue Aug 18 13:07:18.043216 2026] [security2:error] [pid 157386:tid 157450] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/zxz.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUoAABRD8"] [Tue Aug 18 13:07:18.054176 2026] [security2:error] [pid 157386:tid 157611] [client 4.232.151.198:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/stem.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUoQAAAWk"] [Tue Aug 18 13:07:18.091081 2026] [security2:error] [pid 157386:tid 157531] [client 74.248.18.37:32485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/RxR_cbpre.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUogAAARk"] [Tue Aug 18 13:07:18.178075 2026] [security2:error] [pid 157386:tid 157631] [client 20.104.100.201:53867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/replace.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUpgAAAX0"] [Tue Aug 18 13:07:18.188204 2026] [security2:error] [pid 157386:tid 157398] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUpwABKQs"] [Tue Aug 18 13:07:18.239084 2026] [security2:error] [pid 157386:tid 157590] [client 40.74.65.169:21327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/sky.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUqgAAAVQ"] [Tue Aug 18 13:07:18.272674 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:18.273118 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:18.273453 2026] [security2:error] [pid 157386:tid 157527] [client 20.251.48.93:16793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUrQAAARU"] [Tue Aug 18 13:07:18.274005 2026] [security2:error] [pid 157386:tid 157393] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/www.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUrgABWAY"] [Tue Aug 18 13:07:18.329653 2026] [security2:error] [pid 157386:tid 157577] [client 20.65.98.162:55015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/mac.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUswAAAUc"] [Tue Aug 18 13:07:18.334490 2026] [autoindex:error] [pid 157386:tid 157518] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:18.362415 2026] [security2:error] [pid 157386:tid 157587] [client 68.221.73.131:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUtgAAAVE"] [Tue Aug 18 13:07:18.364270 2026] [security2:error] [pid 157386:tid 157602] [client 20.151.109.219:58736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/te.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUtwAAAWA"] [Tue Aug 18 13:07:18.372076 2026] [security2:error] [pid 157386:tid 157569] [client 135.225.75.187:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/snq.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUuQAAAT8"] [Tue Aug 18 13:07:18.373664 2026] [security2:error] [pid 157386:tid 157567] [client 158.23.17.4:4637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/qo.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUugAAAT0"] [Tue Aug 18 13:07:18.376364 2026] [security2:error] [pid 157386:tid 157511] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/home/runner/.aws/credentials"] [unique_id "aoSDNk1jzAhYHVVT1WcUvAABE3w"] [Tue Aug 18 13:07:18.382336 2026] [security2:error] [pid 157386:tid 157620] [client 172.182.217.32:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/min.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUvQAAAXI"] [Tue Aug 18 13:07:18.421139 2026] [security2:error] [pid 157386:tid 157557] [client 20.79.204.6:5755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/gettest.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUwgAAATM"] [Tue Aug 18 13:07:18.444339 2026] [security2:error] [pid 157386:tid 157397] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/about.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUwwABdwo"] [Tue Aug 18 13:07:18.452402 2026] [security2:error] [pid 157386:tid 157405] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUxAABFxI"] [Tue Aug 18 13:07:18.452612 2026] [security2:error] [pid 157386:tid 157529] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUxAABFxI"] [Tue Aug 18 13:07:18.472118 2026] [security2:error] [pid 157386:tid 157564] [client 74.248.18.37:11318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/public/storage.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUxQAAATo"] [Tue Aug 18 13:07:18.511798 2026] [security2:error] [pid 157386:tid 157496] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wicked.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUxwABhm0"] [Tue Aug 18 13:07:18.526499 2026] [security2:error] [pid 157386:tid 157554] [client 20.116.17.175:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/v2.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUyAAAATA"] [Tue Aug 18 13:07:18.535993 2026] [security2:error] [pid 157386:tid 157633] [client 158.158.74.177:9322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-activat.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUyQAAAX8"] [Tue Aug 18 13:07:18.540733 2026] [security2:error] [pid 157386:tid 157643] [client 20.65.69.59:35408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/profile.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUywAAAYk"] [Tue Aug 18 13:07:18.557526 2026] [security2:error] [pid 157386:tid 157597] [client 20.151.109.219:33521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gi.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUzAAAAVs"] [Tue Aug 18 13:07:18.569166 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:18.569432 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:18.598950 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:20343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDNk1jzAhYHVVT1WcUzgAAAWE"] [Tue Aug 18 13:07:18.626128 2026] [security2:error] [pid 157386:tid 157539] [client 158.158.74.177:4140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/public/moon.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU0AAAASE"] [Tue Aug 18 13:07:18.684025 2026] [security2:error] [pid 157386:tid 157606] [client 4.232.151.198:18967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/UomnmTO0r9.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU0gAAAWQ"] [Tue Aug 18 13:07:18.750672 2026] [security2:error] [pid 157386:tid 157599] [client 213.35.127.232:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU1QAAAV0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:18.755454 2026] [security2:error] [pid 157386:tid 157403] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU1wABHBA"] [Tue Aug 18 13:07:18.764350 2026] [security2:error] [pid 157386:tid 157635] [client 20.251.48.93:3504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU2AAAAYE"] [Tue Aug 18 13:07:18.767306 2026] [security2:error] [pid 157386:tid 157462] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU2QABUks"] [Tue Aug 18 13:07:18.784689 2026] [security2:error] [pid 157386:tid 157542] [client 74.248.18.37:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ciis.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU2gAAASQ"] [Tue Aug 18 13:07:18.789150 2026] [security2:error] [pid 157386:tid 157521] [client 135.225.75.187:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-access.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU2wAAAQ8"] [Tue Aug 18 13:07:18.804113 2026] [security2:error] [pid 157386:tid 157631] [client 158.23.17.4:44691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sd.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU3AAAAX0"] [Tue Aug 18 13:07:18.823414 2026] [autoindex:error] [pid 157386:tid 157547] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:18.870388 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:18.870650 2026] [authz_core:error] [pid 157386:tid 157436] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:18.910336 2026] [security2:error] [pid 157386:tid 157572] [client 103.120.71.157:46475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU4wAAAUI"] [Tue Aug 18 13:07:18.910524 2026] [security2:error] [pid 157386:tid 157572] [client 103.120.71.157:46475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU4wAAAUI"] [Tue Aug 18 13:07:18.985815 2026] [security2:error] [pid 157386:tid 157566] [client 40.74.65.169:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/sixxis.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU5QAAATw"] [Tue Aug 18 13:07:18.996476 2026] [security2:error] [pid 157386:tid 157508] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDNk1jzAhYHVVT1WcU5gABiHk"] [Tue Aug 18 13:07:19.010778 2026] [security2:error] [pid 157386:tid 157560] [client 74.248.130.103:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/inso.php"] [unique_id "aoSDN01jzAhYHVVT1WcU5wAAATY"] [Tue Aug 18 13:07:19.043683 2026] [security2:error] [pid 157386:tid 157493] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/f35.php"] [unique_id "aoSDN01jzAhYHVVT1WcU6gABE2o"] [Tue Aug 18 13:07:19.060701 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.100.201:17374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/fw/faiyy.php"] [unique_id "aoSDN01jzAhYHVVT1WcU7QAAAX4"] [Tue Aug 18 13:07:19.106164 2026] [security2:error] [pid 157386:tid 157594] [client 74.248.18.37:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/radio.php"] [unique_id "aoSDN01jzAhYHVVT1WcU8AAAAVg"] [Tue Aug 18 13:07:19.150928 2026] [security2:error] [pid 157386:tid 157630] [client 20.151.109.219:58331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pz.php"] [unique_id "aoSDN01jzAhYHVVT1WcU8wAAAXw"] [Tue Aug 18 13:07:19.159071 2026] [autoindex:error] [pid 157386:tid 157619] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:19.164286 2026] [security2:error] [pid 157386:tid 157634] [client 158.23.17.4:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/km.php"] [unique_id "aoSDN01jzAhYHVVT1WcU9AAAAYA"] [Tue Aug 18 13:07:19.171667 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:19.171927 2026] [security2:error] [pid 157386:tid 157628] [client 20.79.204.6:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/goods.php"] [unique_id "aoSDN01jzAhYHVVT1WcU9gAAAXo"] [Tue Aug 18 13:07:19.171953 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:19.205961 2026] [security2:error] [pid 157386:tid 157643] [client 135.225.75.187:23840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/nw.php"] [unique_id "aoSDN01jzAhYHVVT1WcU-AAAAYk"] [Tue Aug 18 13:07:19.208424 2026] [security2:error] [pid 157386:tid 157617] [client 20.250.13.23:8837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/admin.php"] [unique_id "aoSDN01jzAhYHVVT1WcU-QAAAW8"] [Tue Aug 18 13:07:19.217792 2026] [autoindex:error] [pid 157386:tid 157483] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:19.244506 2026] [security2:error] [pid 157386:tid 157569] [client 158.158.74.177:4749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/public/storage.php"] [unique_id "aoSDN01jzAhYHVVT1WcU-wAAAT8"] [Tue Aug 18 13:07:19.254538 2026] [security2:error] [pid 157386:tid 157427] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/cah.php"] [unique_id "aoSDN01jzAhYHVVT1WcU_AABUyg"] [Tue Aug 18 13:07:19.265409 2026] [security2:error] [pid 157386:tid 157536] [client 20.151.109.219:53529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/kc.php"] [unique_id "aoSDN01jzAhYHVVT1WcU_QAAAR4"] [Tue Aug 18 13:07:19.276116 2026] [security2:error] [pid 157386:tid 157509] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/proxy"] [unique_id "aoSDN01jzAhYHVVT1WcU_gABY3o"] [Tue Aug 18 13:07:19.285926 2026] [security2:error] [pid 157386:tid 157577] [client 158.158.74.177:20511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSDN01jzAhYHVVT1WcVAAAAAUc"] [Tue Aug 18 13:07:19.285965 2026] [security2:error] [pid 157386:tid 157624] [client 20.116.17.175:58180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wkl.php"] [unique_id "aoSDN01jzAhYHVVT1WcVAQAAAXY"] [Tue Aug 18 13:07:19.298294 2026] [security2:error] [pid 157386:tid 157516] [client 20.251.48.93:17859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDN01jzAhYHVVT1WcVAwAAAQo"] [Tue Aug 18 13:07:19.318367 2026] [security2:error] [pid 157386:tid 157459] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/"] [unique_id "aoSDN01jzAhYHVVT1WcVBAABIUg"] [Tue Aug 18 13:07:19.364330 2026] [security2:error] [pid 157386:tid 157604] [client 20.116.17.175:20298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/usr.php"] [unique_id "aoSDN01jzAhYHVVT1WcVBwAAAWI"] [Tue Aug 18 13:07:19.399450 2026] [security2:error] [pid 157386:tid 157641] [client 4.232.151.198:18959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/New.php"] [unique_id "aoSDN01jzAhYHVVT1WcVCgAAAYc"] [Tue Aug 18 13:07:19.411261 2026] [security2:error] [pid 157386:tid 157545] [client 20.65.69.59:24680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/summary.php"] [unique_id "aoSDN01jzAhYHVVT1WcVCwAAASc"] [Tue Aug 18 13:07:19.451026 2026] [security2:error] [pid 157386:tid 157556] [client 23.94.148.16:18962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.148.94.23.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDN01jzAhYHVVT1WcU8QAAATI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:07:19.451145 2026] [security2:error] [pid 157386:tid 157556] [client 23.94.148.16:18962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDN01jzAhYHVVT1WcU8QAAATI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:07:19.472393 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:19.472653 2026] [authz_core:error] [pid 157386:tid 157413] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:19.478750 2026] [security2:error] [pid 157386:tid 157570] [client 74.248.18.37:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/envato-market/inc/class-envato-market-github.php"] [unique_id "aoSDN01jzAhYHVVT1WcVDwAAAUA"] [Tue Aug 18 13:07:19.556117 2026] [security2:error] [pid 157386:tid 157498] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/inputs.php"] [unique_id "aoSDN01jzAhYHVVT1WcVEQABPm8"] [Tue Aug 18 13:07:19.564054 2026] [security2:error] [pid 157386:tid 157521] [client 74.248.130.103:41197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/aa.php"] [unique_id "aoSDN01jzAhYHVVT1WcVEgAAAQ8"] [Tue Aug 18 13:07:19.623258 2026] [security2:error] [pid 157386:tid 157524] [client 135.225.75.187:21470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ws62.php"] [unique_id "aoSDN01jzAhYHVVT1WcVFAAAARI"] [Tue Aug 18 13:07:19.633699 2026] [autoindex:error] [pid 157386:tid 157395] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:19.653157 2026] [security2:error] [pid 157386:tid 157578] [client 158.23.17.4:7329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mf.php"] [unique_id "aoSDN01jzAhYHVVT1WcVFgAAAUg"] [Tue Aug 18 13:07:19.733518 2026] [security2:error] [pid 157386:tid 157560] [client 104.209.144.33:32682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDN01jzAhYHVVT1WcVHQAAATY"] [Tue Aug 18 13:07:19.742990 2026] [security2:error] [pid 157386:tid 157520] [client 74.248.18.37:11326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/root.php"] [unique_id "aoSDN01jzAhYHVVT1WcVHgAAAQ4"] [Tue Aug 18 13:07:19.744687 2026] [security2:error] [pid 157386:tid 157620] [client 20.251.48.93:14398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSDN01jzAhYHVVT1WcVHwAAAXI"] [Tue Aug 18 13:07:19.748293 2026] [security2:error] [pid 157386:tid 157632] [client 20.104.100.201:17370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/dk.php"] [unique_id "aoSDN01jzAhYHVVT1WcVIQAAAX4"] [Tue Aug 18 13:07:19.765558 2026] [security2:error] [pid 157386:tid 157532] [client 213.35.127.232:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDN01jzAhYHVVT1WcVIgAAARo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:19.776782 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:19.777197 2026] [authz_core:error] [pid 157386:tid 157387] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:19.831391 2026] [security2:error] [pid 157386:tid 157586] [client 20.151.109.219:20717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kk.php"] [unique_id "aoSDN01jzAhYHVVT1WcVJwAAAVA"] [Tue Aug 18 13:07:19.839411 2026] [security2:error] [pid 157386:tid 157512] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/"] [unique_id "aoSDN01jzAhYHVVT1WcVKAABL30"] [Tue Aug 18 13:07:19.880805 2026] [security2:error] [pid 157386:tid 157584] [client 158.158.74.177:4757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/radio.php"] [unique_id "aoSDN01jzAhYHVVT1WcVKgAAAU4"] [Tue Aug 18 13:07:19.893688 2026] [security2:error] [pid 157386:tid 157538] [client 20.116.17.175:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDN01jzAhYHVVT1WcVKwAAASA"] [Tue Aug 18 13:07:19.915748 2026] [lsapi:error] [pid 123784:tid 123981] [client 201.32.74.208:56971] [host pensamentosimperfeitos.com.br] Error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(15337): ReceiveAckHdr: timeout 300 is exceeded [Tue Aug 18 13:07:19.941275 2026] [security2:error] [pid 157386:tid 157602] [client 20.79.204.6:5952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/gulu.php"] [unique_id "aoSDN01jzAhYHVVT1WcVLQAAAWA"] [Tue Aug 18 13:07:19.942760 2026] [security2:error] [pid 157386:tid 157587] [client 158.158.74.177:24964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/past1.php"] [unique_id "aoSDN01jzAhYHVVT1WcVLgAAAVE"] [Tue Aug 18 13:07:19.946077 2026] [security2:error] [pid 157386:tid 157400] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/system_log.php"] [unique_id "aoSDN01jzAhYHVVT1WcVLwABbA0"] [Tue Aug 18 13:07:19.965524 2026] [security2:error] [pid 157386:tid 157412] [remote 129.121.123.168:50030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSDN01jzAhYHVVT1WcVMAABIxk"] [Tue Aug 18 13:07:19.982957 2026] [security2:error] [pid 157386:tid 157637] [client 40.74.65.169:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/yj09.php"] [unique_id "aoSDN01jzAhYHVVT1WcVMgAAAYM"] [Tue Aug 18 13:07:20.012823 2026] [security2:error] [pid 157386:tid 157539] [client 68.221.73.131:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVMwAAASE"] [Tue Aug 18 13:07:20.016414 2026] [security2:error] [pid 157386:tid 157592] [client 20.116.17.175:64997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVNAAAAVY"] [Tue Aug 18 13:07:20.043203 2026] [security2:error] [pid 157386:tid 157636] [client 135.225.75.187:11588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/public/vx.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVNgAAAYI"] [Tue Aug 18 13:07:20.049214 2026] [security2:error] [pid 157386:tid 157601] [client 20.151.109.219:58709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/jn.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVOAAAAV8"] [Tue Aug 18 13:07:20.066689 2026] [security2:error] [pid 157386:tid 157643] [client 4.232.151.198:22332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/panel.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVOgAAAYk"] [Tue Aug 18 13:07:20.078468 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:20.078738 2026] [authz_core:error] [pid 157386:tid 157402] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:20.084270 2026] [security2:error] [pid 157386:tid 157545] [client 158.23.17.4:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ie.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVPQAAASc"] [Tue Aug 18 13:07:20.113865 2026] [security2:error] [pid 157386:tid 157569] [client 20.250.13.23:8213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/goods.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVPgAAAT8"] [Tue Aug 18 13:07:20.118190 2026] [security2:error] [pid 157386:tid 157618] [client 20.65.69.59:22066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/conf.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVPwAAAXA"] [Tue Aug 18 13:07:20.129727 2026] [security2:error] [pid 157386:tid 157497] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/alfa.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVQQABXW4"] [Tue Aug 18 13:07:20.157959 2026] [security2:error] [pid 157386:tid 157585] [client 20.206.73.37:46933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "maganmotors.com.br"] [uri "/.mopj.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVQgAAAU8"] [Tue Aug 18 13:07:20.173369 2026] [security2:error] [pid 157386:tid 157518] [client 86.120.159.145:22409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVQwAAAQw"] [Tue Aug 18 13:07:20.173802 2026] [security2:error] [pid 157386:tid 157518] [client 86.120.159.145:22409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVQwAAAQw"] [Tue Aug 18 13:07:20.196882 2026] [security2:error] [pid 157386:tid 157568] [client 74.248.130.103:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/img.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVRQAAAT4"] [Tue Aug 18 13:07:20.296025 2026] [security2:error] [pid 157386:tid 157578] [client 20.206.73.37:65163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/sky.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVSgAAAUg"] [Tue Aug 18 13:07:20.327736 2026] [autoindex:error] [pid 157386:tid 157612] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:20.331644 2026] [security2:error] [pid 157386:tid 157556] [client 74.248.18.37:40344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-rest-true-meta-fields.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVTAAAATI"] [Tue Aug 18 13:07:20.346777 2026] [authz_core:error] [pid 157386:tid 157521] [client 192.178.4.135:44979] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:20.347035 2026] [authz_core:error] [pid 157386:tid 157521] [client 192.178.4.135:44979] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:20.361795 2026] [security2:error] [pid 157386:tid 157620] [client 20.251.48.93:54036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVTwAAAXI"] [Tue Aug 18 13:07:20.373740 2026] [security2:error] [pid 157386:tid 157576] [client 74.248.18.37:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/server.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVUQAAAUY"] [Tue Aug 18 13:07:20.375911 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:20.376169 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:20.376473 2026] [security2:error] [pid 157386:tid 157582] [client 20.151.109.219:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/phpcheck.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVUgAAAUw"] [Tue Aug 18 13:07:20.414768 2026] [security2:error] [pid 157386:tid 157564] [client 104.209.144.33:31251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVVgAAATo"] [Tue Aug 18 13:07:20.449626 2026] [security2:error] [pid 157386:tid 157553] [client 20.116.17.175:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/css/database.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVWAAAAS8"] [Tue Aug 18 13:07:20.459238 2026] [security2:error] [pid 157386:tid 157565] [client 135.225.75.187:21452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/loxi-o.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVWQAAATs"] [Tue Aug 18 13:07:20.465509 2026] [security2:error] [pid 157386:tid 157501] [remote 95.111.251.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.251.111.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVWgABK3I"] [Tue Aug 18 13:07:20.481047 2026] [security2:error] [pid 157386:tid 157642] [client 3.12.251.153:21450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ealoggroup.com.br"] [uri "/index.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVWwAAAYg"], referer: https://ealoggroup.com.br/ [Tue Aug 18 13:07:20.482926 2026] [security2:error] [pid 157386:tid 157554] [client 20.116.17.175:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/az.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVXAAAATA"] [Tue Aug 18 13:07:20.485318 2026] [security2:error] [pid 157386:tid 157507] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lock360.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVXQABW3g"] [Tue Aug 18 13:07:20.498214 2026] [security2:error] [pid 157386:tid 157544] [client 158.23.17.4:5030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nw.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVXwAAASY"] [Tue Aug 18 13:07:20.499543 2026] [security2:error] [pid 157386:tid 157572] [client 158.158.74.177:17130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/root.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVYAAAAUI"] [Tue Aug 18 13:07:20.520976 2026] [security2:error] [pid 157386:tid 157543] [client 20.151.109.219:21889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfunnelcrm.com.br"] [uri "/bf.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVYQAAASU"] [Tue Aug 18 13:07:20.536096 2026] [security2:error] [pid 157386:tid 157602] [client 172.182.217.32:4146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/panel.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVYgAAAWA"] [Tue Aug 18 13:07:20.553969 2026] [security2:error] [pid 157386:tid 157623] [client 20.65.98.162:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ops.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVYwAAAXU"] [Tue Aug 18 13:07:20.566121 2026] [autoindex:error] [pid 157386:tid 157587] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:20.568549 2026] [security2:error] [pid 157386:tid 157558] [client 20.79.204.6:5758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/h.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVZwAAATQ"] [Tue Aug 18 13:07:20.569061 2026] [security2:error] [pid 157386:tid 157637] [client 20.104.100.201:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/bal.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVaAAAAYM"] [Tue Aug 18 13:07:20.603776 2026] [security2:error] [pid 157386:tid 157557] [client 158.158.74.177:9297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/file61.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVaQAAATM"] [Tue Aug 18 13:07:20.618401 2026] [security2:error] [pid 157386:tid 157437] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVagABOTI"] [Tue Aug 18 13:07:20.706815 2026] [security2:error] [pid 157386:tid 157619] [client 74.248.130.103:28032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/222.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVbQAAAXE"] [Tue Aug 18 13:07:20.718536 2026] [security2:error] [pid 157386:tid 157562] [client 4.232.151.198:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/ID/module.audio.flac.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVbgAAATg"] [Tue Aug 18 13:07:20.739888 2026] [security2:error] [pid 157386:tid 157571] [client 40.74.65.169:37419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/k.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVbwAAAUE"] [Tue Aug 18 13:07:20.755142 2026] [security2:error] [pid 157386:tid 157487] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVcQABe2Q"] [Tue Aug 18 13:07:20.755293 2026] [security2:error] [pid 157386:tid 157629] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVcQABe2Q"] [Tue Aug 18 13:07:20.788280 2026] [security2:error] [pid 157386:tid 157586] [client 213.35.127.232:59557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVdAAAAVA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:20.796403 2026] [security2:error] [pid 157386:tid 157559] [client 104.209.144.33:31233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVdQAAATU"] [Tue Aug 18 13:07:20.796527 2026] [security2:error] [pid 157386:tid 157486] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/flower.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVdgABUmM"] [Tue Aug 18 13:07:20.824074 2026] [autoindex:error] [pid 157386:tid 157639] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:20.824975 2026] [security2:error] [pid 157386:tid 157567] [client 149.34.210.141:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVeAAAAT0"] [Tue Aug 18 13:07:20.842363 2026] [security2:error] [pid 157386:tid 157445] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVeQABVDo"] [Tue Aug 18 13:07:20.863374 2026] [security2:error] [pid 157386:tid 157547] [client 158.23.17.4:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sb.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVewAAASk"] [Tue Aug 18 13:07:20.879746 2026] [security2:error] [pid 157386:tid 157527] [client 135.225.75.187:23811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sdsa.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVfAAAARU"] [Tue Aug 18 13:07:20.894912 2026] [security2:error] [pid 157386:tid 157583] [client 20.151.109.219:28774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/dg.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVfQAAAU0"] [Tue Aug 18 13:07:20.916763 2026] [security2:error] [pid 157386:tid 157422] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.env.json"] [unique_id "aoSDOE1jzAhYHVVT1WcVfwABSyM"] [Tue Aug 18 13:07:20.967212 2026] [security2:error] [pid 157386:tid 157556] [client 20.116.17.175:20455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/privdayz.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVgwAAATI"] [Tue Aug 18 13:07:20.978070 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:20.978338 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:21.019114 2026] [autoindex:error] [pid 157386:tid 157620] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:21.020301 2026] [security2:error] [pid 157386:tid 157632] [client 20.251.48.93:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSDOU1jzAhYHVVT1WcViAAAAX4"] [Tue Aug 18 13:07:21.025265 2026] [security2:error] [pid 157386:tid 157579] [client 172.182.217.32:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins//about.php"] [unique_id "aoSDOU1jzAhYHVVT1WcViQAAAUk"] [Tue Aug 18 13:07:21.070013 2026] [security2:error] [pid 157386:tid 157500] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/abc.php"] [unique_id "aoSDOU1jzAhYHVVT1WcViwABOnE"] [Tue Aug 18 13:07:21.070803 2026] [security2:error] [pid 157386:tid 157469] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/13.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVjAABF1I"] [Tue Aug 18 13:07:21.097883 2026] [security2:error] [pid 157386:tid 157567] [client 149.34.210.141:65229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDOE1jzAhYHVVT1WcVeAAAAT0"] [Tue Aug 18 13:07:21.114447 2026] [security2:error] [pid 157386:tid 157580] [client 74.248.18.37:21314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVjgAAAUo"] [Tue Aug 18 13:07:21.175922 2026] [security2:error] [pid 157386:tid 157572] [client 20.65.69.59:39477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/bala.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVkAAAAUI"] [Tue Aug 18 13:07:21.179415 2026] [security2:error] [pid 157386:tid 157552] [client 158.158.74.177:17088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/server.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVkQAAAS4"] [Tue Aug 18 13:07:21.191852 2026] [security2:error] [pid 157386:tid 157613] [client 20.79.204.6:5972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/hello.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVkgAAAWs"] [Tue Aug 18 13:07:21.223548 2026] [security2:error] [pid 157386:tid 157543] [client 104.209.144.33:25324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVkwAAASU"] [Tue Aug 18 13:07:21.240213 2026] [autoindex:error] [pid 157386:tid 157589] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:21.251663 2026] [security2:error] [pid 157386:tid 157602] [client 158.23.17.4:39154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xj.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVlwAAAWA"] [Tue Aug 18 13:07:21.267279 2026] [security2:error] [pid 157386:tid 157536] [client 74.248.130.103:41195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/key.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVmQAAAR4"] [Tue Aug 18 13:07:21.282859 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:21.283112 2026] [authz_core:error] [pid 157386:tid 157488] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:21.293439 2026] [security2:error] [pid 157386:tid 157514] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/akcc.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVnAABY38"] [Tue Aug 18 13:07:21.297023 2026] [security2:error] [pid 157386:tid 157624] [client 135.225.75.187:31825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-freya.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVnQAAAXY"] [Tue Aug 18 13:07:21.346550 2026] [security2:error] [pid 157386:tid 157598] [client 4.232.151.198:22313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/gallery.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVoAAAAVw"] [Tue Aug 18 13:07:21.381356 2026] [security2:error] [pid 157386:tid 157526] [client 20.116.17.175:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/z43agz.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVoQAAARQ"] [Tue Aug 18 13:07:21.385279 2026] [security2:error] [pid 157386:tid 157537] [client 20.151.109.219:36309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/bm.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVogAAAR8"] [Tue Aug 18 13:07:21.421807 2026] [security2:error] [pid 157386:tid 157601] [client 107.189.27.226:60702] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "elitepaintball.com.br"] [uri "/"] [unique_id "aoSDOU1jzAhYHVVT1WcVpAAAAV8"] [Tue Aug 18 13:07:21.428393 2026] [security2:error] [pid 157386:tid 157542] [client 74.248.18.37:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVpgAAASQ"] [Tue Aug 18 13:07:21.449660 2026] [security2:error] [pid 157386:tid 157641] [client 158.158.74.177:24982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.llservicosnet.com.br"] [uri "/license.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVpwAAAYc"] [Tue Aug 18 13:07:21.458601 2026] [autoindex:error] [pid 157386:tid 157643] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:21.507090 2026] [security2:error] [pid 157386:tid 157577] [client 20.116.17.175:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wg459o.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVrAAAAUc"] [Tue Aug 18 13:07:21.512111 2026] [security2:error] [pid 157386:tid 157546] [client 40.74.65.169:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/w.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVrQAAASg"] [Tue Aug 18 13:07:21.513984 2026] [security2:error] [pid 157386:tid 157539] [client 172.182.217.32:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins//index.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVrgAAASE"] [Tue Aug 18 13:07:21.532208 2026] [security2:error] [pid 157386:tid 157484] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wk/index.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVrwABP2E"] [Tue Aug 18 13:07:21.566271 2026] [security2:error] [pid 157386:tid 157559] [client 20.251.48.93:16775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/media.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVsQAAATU"] [Tue Aug 18 13:07:21.580940 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:21.581203 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:21.587688 2026] [security2:error] [pid 157386:tid 157458] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cc.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVswABUkc"] [Tue Aug 18 13:07:21.592044 2026] [security2:error] [pid 157386:tid 157568] [client 104.209.144.33:32678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVtAAAAT4"] [Tue Aug 18 13:07:21.623954 2026] [security2:error] [pid 157386:tid 157521] [client 20.104.100.201:54065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/yawa.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVugAAAQ8"] [Tue Aug 18 13:07:21.630132 2026] [security2:error] [pid 157386:tid 157524] [client 195.170.172.216:39564] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "162.241.203.17"] [uri "/"] [unique_id "aoSDOU1jzAhYHVVT1WcVvAAAARI"] [Tue Aug 18 13:07:21.635223 2026] [security2:error] [pid 157386:tid 157547] [client 20.65.69.59:29234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/222.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVvQAAASk"] [Tue Aug 18 13:07:21.635373 2026] [security2:error] [pid 157386:tid 157447] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/azure-pipelines.yml"] [unique_id "aoSDOU1jzAhYHVVT1WcVvgABaDw"] [Tue Aug 18 13:07:21.653731 2026] [security2:error] [pid 157386:tid 157578] [client 107.189.27.226:60702] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "elitepaintball.com.br"] [uri "/"] [unique_id "aoSDOU1jzAhYHVVT1WcVwAAAAUg"] [Tue Aug 18 13:07:21.655090 2026] [security2:error] [pid 157386:tid 157622] [client 158.23.17.4:20671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ns.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVwQAAAXQ"] [Tue Aug 18 13:07:21.668067 2026] [security2:error] [pid 157386:tid 157478] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/var/www/.env"] [unique_id "aoSDOU1jzAhYHVVT1WcVwwABHFs"] [Tue Aug 18 13:07:21.670637 2026] [security2:error] [pid 157386:tid 157513] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/job/.env"] [unique_id "aoSDOU1jzAhYHVVT1WcVxAABVH4"] [Tue Aug 18 13:07:21.685482 2026] [security2:error] [pid 157386:tid 157432] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/.env.php"] [unique_id "aoSDOU1jzAhYHVVT1WcVxgABaS0"] [Tue Aug 18 13:07:21.701925 2026] [security2:error] [pid 157386:tid 157471] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.env.openai"] [unique_id "aoSDOU1jzAhYHVVT1WcVzAABJ1Q"] [Tue Aug 18 13:07:21.702588 2026] [security2:error] [pid 157386:tid 157460] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.production.bak"] [unique_id "aoSDOU1jzAhYHVVT1WcVywABVEk"] [Tue Aug 18 13:07:21.704928 2026] [security2:error] [pid 157386:tid 157442] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSDOU1jzAhYHVVT1WcVzQABJzc"] [Tue Aug 18 13:07:21.716373 2026] [security2:error] [pid 157386:tid 157632] [client 135.225.75.187:31824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fleen.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV0QAAAX4"] [Tue Aug 18 13:07:21.719554 2026] [security2:error] [pid 157386:tid 157433] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.github/workflows/publish.yml"] [unique_id "aoSDOU1jzAhYHVVT1WcV0gABTS4"] [Tue Aug 18 13:07:21.767310 2026] [security2:error] [pid 157386:tid 157629] [client 74.248.18.37:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/shell.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV2AAAAXs"] [Tue Aug 18 13:07:21.772396 2026] [security2:error] [pid 157386:tid 157393] [remote 20.163.43.14:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.novosares.com.br"] [uri "/1.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV2QABbQY"] [Tue Aug 18 13:07:21.772511 2026] [security2:error] [pid 157386:tid 157393] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/1.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV2QABbQY"] [Tue Aug 18 13:07:21.796144 2026] [security2:error] [pid 157386:tid 157564] [client 20.151.109.219:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vu.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV2gAAATo"] [Tue Aug 18 13:07:21.796928 2026] [security2:error] [pid 157386:tid 157595] [client 158.158.74.177:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV2wAAAVk"] [Tue Aug 18 13:07:21.805156 2026] [security2:error] [pid 157386:tid 157619] [client 213.35.127.232:64930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV3AAAAXE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:21.821735 2026] [security2:error] [pid 157386:tid 157633] [client 20.79.204.6:5725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/images/index.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV3QAAAX8"] [Tue Aug 18 13:07:21.828008 2026] [security2:error] [pid 157386:tid 157455] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko-new.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV3gABF0Q"] [Tue Aug 18 13:07:21.863175 2026] [security2:error] [pid 157386:tid 157567] [client 74.248.130.103:58266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/chosen.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV4AAAAT0"] [Tue Aug 18 13:07:21.863262 2026] [security2:error] [pid 157386:tid 157617] [client 104.209.144.33:32703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV3wAAAW8"] [Tue Aug 18 13:07:21.871308 2026] [autoindex:error] [pid 157386:tid 157570] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:21.878950 2026] [security2:error] [pid 157386:tid 157553] [client 157.20.138.62:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV4wAAAS8"] [Tue Aug 18 13:07:21.879052 2026] [security2:error] [pid 157386:tid 157553] [client 157.20.138.62:53015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV4wAAAS8"] [Tue Aug 18 13:07:21.879882 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:21.880138 2026] [authz_core:error] [pid 157386:tid 157416] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:21.998355 2026] [security2:error] [pid 157386:tid 157397] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV6gABLAo"] [Tue Aug 18 13:07:22.000599 2026] [security2:error] [pid 157386:tid 157582] [client 172.182.217.32:4032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins//min.php"] [unique_id "aoSDOU1jzAhYHVVT1WcV6wAAAUw"] [Tue Aug 18 13:07:22.029730 2026] [security2:error] [pid 157386:tid 157480] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/jenkins/config.xml.bak"] [unique_id "aoSDOk1jzAhYHVVT1WcV7QABVF0"] [Tue Aug 18 13:07:22.042366 2026] [security2:error] [pid 157386:tid 157636] [client 20.251.48.93:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/inso.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV8AAAAYI"] [Tue Aug 18 13:07:22.063902 2026] [security2:error] [pid 157386:tid 157457] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content.php.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV8wABg0Y"] [Tue Aug 18 13:07:22.067662 2026] [security2:error] [pid 157386:tid 157557] [client 158.23.17.4:7307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gk.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV9AAAATM"] [Tue Aug 18 13:07:22.067678 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/3.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV9QAAATk"] [Tue Aug 18 13:07:22.130438 2026] [security2:error] [pid 157386:tid 157576] [client 4.232.151.198:5389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/Cache.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV_AAAAUY"] [Tue Aug 18 13:07:22.132147 2026] [security2:error] [pid 157386:tid 157601] [client 135.225.75.187:35673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/e.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV_QAAAV8"] [Tue Aug 18 13:07:22.180756 2026] [authz_core:error] [pid 157386:tid 157508] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:22.181023 2026] [authz_core:error] [pid 157386:tid 157508] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:22.194050 2026] [autoindex:error] [pid 157386:tid 157571] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:22.214577 2026] [security2:error] [pid 157386:tid 157496] [remote 20.84.23.222:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.23.84.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tersaudefitness.com.br.elizangelabrito.com.br"] [uri "/wp-login.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV7wABGG0"] [Tue Aug 18 13:07:22.223575 2026] [security2:error] [pid 157386:tid 157607] [client 74.248.18.37:40321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/rss.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWBgAAAWU"] [Tue Aug 18 13:07:22.225454 2026] [security2:error] [pid 157386:tid 157540] [client 40.74.65.169:21320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/fpwch.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWBwAAASI"] [Tue Aug 18 13:07:22.226215 2026] [security2:error] [pid 157386:tid 157489] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWCAABPGY"] [Tue Aug 18 13:07:22.272645 2026] [security2:error] [pid 157386:tid 157568] [client 20.151.109.219:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ic.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWCgAAAT4"] [Tue Aug 18 13:07:22.297237 2026] [security2:error] [pid 157386:tid 157581] [client 178.153.171.161:3165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWCwAAAUs"] [Tue Aug 18 13:07:22.297395 2026] [security2:error] [pid 157386:tid 157581] [client 178.153.171.161:3165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWCwAAAUs"] [Tue Aug 18 13:07:22.306437 2026] [security2:error] [pid 157386:tid 157463] [remote 46.250.228.132:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.228.250.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWDAABKUw"] [Tue Aug 18 13:07:22.329485 2026] [security2:error] [pid 157386:tid 157578] [client 104.209.144.33:25284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWDQAAAUg"] [Tue Aug 18 13:07:22.345503 2026] [security2:error] [pid 157386:tid 157632] [client 74.248.130.103:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/wpxml.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWDwAAAX4"] [Tue Aug 18 13:07:22.346564 2026] [security2:error] [pid 157386:tid 157631] [client 20.65.69.59:1455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/routes.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWEAAAAX0"] [Tue Aug 18 13:07:22.356278 2026] [security2:error] [pid 157386:tid 157427] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/01.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWEQABeyg"] [Tue Aug 18 13:07:22.399728 2026] [security2:error] [pid 157386:tid 157541] [client 74.248.18.37:21351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/sim.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWEgAAASM"] [Tue Aug 18 13:07:22.437942 2026] [security2:error] [pid 157386:tid 157599] [client 20.79.204.6:5747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/index.bak.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWEwAAAV0"] [Tue Aug 18 13:07:22.441386 2026] [security2:error] [pid 157386:tid 157628] [client 158.158.74.177:17090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/shell.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWFAAAAXo"] [Tue Aug 18 13:07:22.442174 2026] [security2:error] [pid 157386:tid 157615] [client 158.23.17.4:39105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wn.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWFQAAAW0"] [Tue Aug 18 13:07:22.451075 2026] [security2:error] [pid 157386:tid 157575] [client 45.84.107.54:13525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV-gAAAUU"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:07:22.451164 2026] [security2:error] [pid 157386:tid 157575] [client 45.84.107.54:13525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDOk1jzAhYHVVT1WcV-gAAAUU"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:07:22.455320 2026] [security2:error] [pid 157386:tid 157509] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/as.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWFgABWXo"] [Tue Aug 18 13:07:22.482368 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:22.482622 2026] [authz_core:error] [pid 157386:tid 157459] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:22.487387 2026] [security2:error] [pid 157386:tid 157527] [client 172.182.217.32:25588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/111/wp-polls/tinymce/plugins/security.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWGQAAARU"] [Tue Aug 18 13:07:22.487461 2026] [autoindex:error] [pid 157386:tid 157619] [client 31.58.51.57:42582] AH01276: Cannot serve directory /home2/atlasi11/Map.atlas-ia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:22.495206 2026] [security2:error] [pid 157386:tid 157633] [client 20.251.48.93:3505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/shiny.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWGgAAAX8"] [Tue Aug 18 13:07:22.518500 2026] [security2:error] [pid 157386:tid 157481] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/jenkins/.env"] [unique_id "aoSDOk1jzAhYHVVT1WcWHAABVF4"] [Tue Aug 18 13:07:22.548342 2026] [security2:error] [pid 157386:tid 157570] [client 20.116.17.175:64996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/log.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWHgAAAUA"] [Tue Aug 18 13:07:22.553993 2026] [security2:error] [pid 157386:tid 157553] [client 135.225.75.187:23024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/hello.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWIAAAAS8"] [Tue Aug 18 13:07:22.561061 2026] [security2:error] [pid 157386:tid 157565] [client 68.221.73.131:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWIQAAATs"] [Tue Aug 18 13:07:22.574814 2026] [autoindex:error] [pid 157386:tid 157586] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:22.623455 2026] [security2:error] [pid 157386:tid 157407] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/lv.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWJAABaxQ"] [Tue Aug 18 13:07:22.633676 2026] [security2:error] [pid 157386:tid 157472] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/var/www/html/.env"] [unique_id "aoSDOk1jzAhYHVVT1WcWJQABVFU"] [Tue Aug 18 13:07:22.647851 2026] [security2:error] [pid 157386:tid 157498] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/jenkins.conf"] [unique_id "aoSDOk1jzAhYHVVT1WcWJgABTW8"] [Tue Aug 18 13:07:22.690422 2026] [security2:error] [pid 157386:tid 157436] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWJwABdTE"] [Tue Aug 18 13:07:22.713735 2026] [security2:error] [pid 157386:tid 157614] [client 20.151.109.219:28753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ue.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWKAAAAWw"] [Tue Aug 18 13:07:22.736274 2026] [security2:error] [pid 157386:tid 157636] [client 20.116.17.175:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/mifta.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWKQAAAYI"] [Tue Aug 18 13:07:22.748995 2026] [security2:error] [pid 157386:tid 157567] [client 4.232.151.198:19005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-add.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWLAAAAT0"] [Tue Aug 18 13:07:22.765900 2026] [security2:error] [pid 157386:tid 157637] [client 104.209.144.33:32654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWLwAAAYM"] [Tue Aug 18 13:07:22.769442 2026] [autoindex:error] [pid 157386:tid 157642] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:22.782585 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:22.782847 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:22.819263 2026] [security2:error] [pid 157386:tid 157438] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/www/.env"] [unique_id "aoSDOk1jzAhYHVVT1WcWMwABHDM"] [Tue Aug 18 13:07:22.832644 2026] [security2:error] [pid 157386:tid 157612] [client 213.35.127.232:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWNAAAAWo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:22.840166 2026] [security2:error] [pid 157386:tid 157593] [client 158.23.17.4:53193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/app.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWNQAAAVc"] [Tue Aug 18 13:07:22.869694 2026] [security2:error] [pid 157386:tid 157414] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/new.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWOAABZBs"] [Tue Aug 18 13:07:22.912279 2026] [security2:error] [pid 157386:tid 157540] [client 40.74.65.169:7112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWOwAAASI"] [Tue Aug 18 13:07:22.922578 2026] [security2:error] [pid 157386:tid 157512] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWPAABPH0"] [Tue Aug 18 13:07:22.952029 2026] [security2:error] [pid 157386:tid 157635] [client 20.206.73.37:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/file5.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWPgAAAYE"] [Tue Aug 18 13:07:22.957868 2026] [security2:error] [pid 157386:tid 157639] [client 74.248.130.103:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/file1221.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWPwAAAYU"] [Tue Aug 18 13:07:22.975612 2026] [security2:error] [pid 157386:tid 157601] [client 172.182.217.32:4034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWQAAAAV8"] [Tue Aug 18 13:07:22.989487 2026] [security2:error] [pid 157386:tid 157556] [client 135.225.75.187:31811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/brc.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWQQAAATI"] [Tue Aug 18 13:07:22.996480 2026] [security2:error] [pid 157386:tid 157581] [client 20.65.69.59:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/php5.php"] [unique_id "aoSDOk1jzAhYHVVT1WcWQgAAAUs"] [Tue Aug 18 13:07:23.011487 2026] [autoindex:error] [pid 157386:tid 157547] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:23.044525 2026] [security2:error] [pid 157386:tid 157560] [client 20.104.100.201:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDO01jzAhYHVVT1WcWRgAAATY"] [Tue Aug 18 13:07:23.063355 2026] [security2:error] [pid 157386:tid 157604] [client 158.158.74.177:17115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/sim.php"] [unique_id "aoSDO01jzAhYHVVT1WcWRwAAAWI"] [Tue Aug 18 13:07:23.066506 2026] [security2:error] [pid 157386:tid 157641] [client 20.79.204.6:5962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/index/function.php"] [unique_id "aoSDO01jzAhYHVVT1WcWSAAAAYc"] [Tue Aug 18 13:07:23.070057 2026] [security2:error] [pid 157386:tid 157620] [client 20.251.48.93:29739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/403dd.php"] [unique_id "aoSDO01jzAhYHVVT1WcWTwAAAXI"] [Tue Aug 18 13:07:23.083500 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:23.083781 2026] [authz_core:error] [pid 157386:tid 157439] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:23.105128 2026] [security2:error] [pid 157386:tid 157387] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/222.php"] [unique_id "aoSDO01jzAhYHVVT1WcWVgABSQA"] [Tue Aug 18 13:07:23.105174 2026] [security2:error] [pid 157386:tid 157541] [client 74.248.18.37:25011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-pluging.php"] [unique_id "aoSDO01jzAhYHVVT1WcWVQAAASM"] [Tue Aug 18 13:07:23.114925 2026] [security2:error] [pid 157386:tid 157532] [client 20.151.109.219:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lr.php"] [unique_id "aoSDO01jzAhYHVVT1WcWVwAAARo"] [Tue Aug 18 13:07:23.123380 2026] [security2:error] [pid 157386:tid 157572] [client 74.248.18.37:21337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/simple.php"] [unique_id "aoSDO01jzAhYHVVT1WcWWQAAAUI"] [Tue Aug 18 13:07:23.152441 2026] [security2:error] [pid 157386:tid 157507] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDO01jzAhYHVVT1WcWXAABcXg"] [Tue Aug 18 13:07:23.156691 2026] [security2:error] [pid 157386:tid 157576] [client 46.102.21.132:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWXQAAAUY"] [Tue Aug 18 13:07:23.156791 2026] [security2:error] [pid 157386:tid 157576] [client 46.102.21.132:59048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWXQAAAUY"] [Tue Aug 18 13:07:23.157104 2026] [security2:error] [pid 157386:tid 157633] [client 20.65.98.162:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/8.php"] [unique_id "aoSDO01jzAhYHVVT1WcWXgAAAX8"] [Tue Aug 18 13:07:23.171959 2026] [security2:error] [pid 157386:tid 157580] [client 20.116.17.175:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ohct.php"] [unique_id "aoSDO01jzAhYHVVT1WcWYQAAAUo"] [Tue Aug 18 13:07:23.232204 2026] [security2:error] [pid 157386:tid 157613] [client 158.23.17.4:5044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/87.php"] [unique_id "aoSDO01jzAhYHVVT1WcWZwAAAWs"] [Tue Aug 18 13:07:23.282230 2026] [autoindex:error] [pid 157386:tid 157582] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:23.391035 2026] [authz_core:error] [pid 157386:tid 157487] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:23.391498 2026] [authz_core:error] [pid 157386:tid 157487] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:23.392086 2026] [security2:error] [pid 157386:tid 157529] [client 4.232.151.198:18958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/cgi-bin/cloud.php"] [unique_id "aoSDO01jzAhYHVVT1WcWbgAAARc"] [Tue Aug 18 13:07:23.395450 2026] [security2:error] [pid 157386:tid 157445] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDO01jzAhYHVVT1WcWbwABiDo"] [Tue Aug 18 13:07:23.396928 2026] [security2:error] [pid 157386:tid 157526] [client 74.248.130.103:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/nox.php"] [unique_id "aoSDO01jzAhYHVVT1WcWcAAAARQ"] [Tue Aug 18 13:07:23.413085 2026] [security2:error] [pid 157386:tid 157542] [client 135.225.75.187:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/file52.php"] [unique_id "aoSDO01jzAhYHVVT1WcWcQAAASQ"] [Tue Aug 18 13:07:23.440986 2026] [security2:error] [pid 157386:tid 157638] [client 102.213.179.104:54705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWcwAAAYQ"] [Tue Aug 18 13:07:23.441138 2026] [security2:error] [pid 157386:tid 157638] [client 102.213.179.104:54705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWcwAAAYQ"] [Tue Aug 18 13:07:23.447531 2026] [security2:error] [pid 157386:tid 157574] [client 104.209.144.33:25325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDO01jzAhYHVVT1WcWdQAAAUQ"] [Tue Aug 18 13:07:23.463900 2026] [security2:error] [pid 157386:tid 157623] [client 172.182.217.32:4157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/bolvo-features/inc/plugins/data.php"] [unique_id "aoSDO01jzAhYHVVT1WcWdgAAAXU"] [Tue Aug 18 13:07:23.474364 2026] [security2:error] [pid 157386:tid 157475] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/chosen.php"] [unique_id "aoSDO01jzAhYHVVT1WcWeAABIVg"] [Tue Aug 18 13:07:23.569967 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ot.php"] [unique_id "aoSDO01jzAhYHVVT1WcWeQAAAYU"] [Tue Aug 18 13:07:23.586438 2026] [security2:error] [pid 157386:tid 157573] [client 158.23.17.4:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/zi.php"] [unique_id "aoSDO01jzAhYHVVT1WcWfAAAAUM"] [Tue Aug 18 13:07:23.589584 2026] [security2:error] [pid 157386:tid 157581] [client 40.74.65.169:37429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/blurbs.php"] [unique_id "aoSDO01jzAhYHVVT1WcWfQAAAUs"] [Tue Aug 18 13:07:23.631434 2026] [autoindex:error] [pid 157386:tid 157618] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:23.687906 2026] [authz_core:error] [pid 157386:tid 157401] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:23.688173 2026] [authz_core:error] [pid 157386:tid 157401] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:23.689766 2026] [security2:error] [pid 157386:tid 157607] [client 158.158.74.177:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/simple.php"] [unique_id "aoSDO01jzAhYHVVT1WcWgwAAAWU"] [Tue Aug 18 13:07:23.694066 2026] [security2:error] [pid 157386:tid 157589] [client 20.79.204.6:5961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/info.php"] [unique_id "aoSDO01jzAhYHVVT1WcWhAAAAVM"] [Tue Aug 18 13:07:23.714744 2026] [security2:error] [pid 157386:tid 157514] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/%2eenv"] [unique_id "aoSDO01jzAhYHVVT1WcWhwABVH8"] [Tue Aug 18 13:07:23.718817 2026] [security2:error] [pid 157386:tid 157532] [client 20.251.48.93:29700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/baba.php"] [unique_id "aoSDO01jzAhYHVVT1WcWiAAAARo"] [Tue Aug 18 13:07:23.743874 2026] [security2:error] [pid 157386:tid 157615] [client 104.209.144.33:25302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDO01jzAhYHVVT1WcWiQAAAW0"] [Tue Aug 18 13:07:23.772318 2026] [security2:error] [pid 157386:tid 157470] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/download"] [unique_id "aoSDO01jzAhYHVVT1WcWiwABHFM"] [Tue Aug 18 13:07:23.774769 2026] [security2:error] [pid 157386:tid 157563] [client 74.248.18.37:21349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/st.php"] [unique_id "aoSDO01jzAhYHVVT1WcWjAAAATk"] [Tue Aug 18 13:07:23.787502 2026] [security2:error] [pid 157386:tid 157424] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.netlify/.env"] [unique_id "aoSDO01jzAhYHVVT1WcWjQABVCU"] [Tue Aug 18 13:07:23.800906 2026] [security2:error] [pid 157386:tid 157537] [client 74.248.18.37:24972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/mah.php"] [unique_id "aoSDO01jzAhYHVVT1WcWkAAAAR8"] [Tue Aug 18 13:07:23.828518 2026] [security2:error] [pid 157386:tid 157485] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/supabase/.env"] [unique_id "aoSDO01jzAhYHVVT1WcWkwABJ2I"] [Tue Aug 18 13:07:23.840321 2026] [security2:error] [pid 157386:tid 157576] [client 135.225.75.187:35708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSDO01jzAhYHVVT1WcWlAAAAUY"] [Tue Aug 18 13:07:23.853361 2026] [security2:error] [pid 157386:tid 157540] [client 213.35.127.232:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDO01jzAhYHVVT1WcWlQAAASI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:23.854864 2026] [security2:error] [pid 157386:tid 157484] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDO01jzAhYHVVT1WcWlgABL2E"] [Tue Aug 18 13:07:23.863495 2026] [security2:error] [pid 157386:tid 157565] [client 20.116.17.175:58235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/v5.php"] [unique_id "aoSDO01jzAhYHVVT1WcWlwAAATs"] [Tue Aug 18 13:07:23.876885 2026] [security2:error] [pid 157386:tid 157458] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.supabase/.env"] [unique_id "aoSDO01jzAhYHVVT1WcWmAABTUc"] [Tue Aug 18 13:07:23.898176 2026] [security2:error] [pid 157386:tid 157633] [client 138.36.100.162:42019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWmQAAAX8"] [Tue Aug 18 13:07:23.898286 2026] [security2:error] [pid 157386:tid 157633] [client 138.36.100.162:42019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDO01jzAhYHVVT1WcWmQAAAX8"] [Tue Aug 18 13:07:23.951110 2026] [security2:error] [pid 157386:tid 157595] [client 172.182.217.32:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/about.php"] [unique_id "aoSDO01jzAhYHVVT1WcWmwAAAVk"] [Tue Aug 18 13:07:23.956575 2026] [autoindex:error] [pid 157386:tid 157592] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:23.980149 2026] [security2:error] [pid 157386:tid 157447] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/info.php"] [unique_id "aoSDO01jzAhYHVVT1WcWngABazw"] [Tue Aug 18 13:07:23.987739 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:23.987996 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:24.000305 2026] [fcgid:warn] [pid 157386:tid 157569] (70014)End of file found: [client 66.132.195.75:16000] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:24.011103 2026] [security2:error] [pid 157386:tid 157584] [client 20.116.17.175:20339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWoQAAAU4"] [Tue Aug 18 13:07:24.049194 2026] [security2:error] [pid 157386:tid 157582] [client 20.65.69.59:19567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/Black.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWowAAAUw"] [Tue Aug 18 13:07:24.067231 2026] [security2:error] [pid 157386:tid 157636] [client 158.23.17.4:4663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/92.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWpAAAAYI"] [Tue Aug 18 13:07:24.071141 2026] [security2:error] [pid 157386:tid 157549] [client 4.232.151.198:18945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/moddofuns.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWpQAAASs"] [Tue Aug 18 13:07:24.079898 2026] [security2:error] [pid 157386:tid 157432] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/an.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWpgABYy0"] [Tue Aug 18 13:07:24.128785 2026] [security2:error] [pid 157386:tid 157625] [client 104.209.144.33:31246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWpwAAAXc"] [Tue Aug 18 13:07:24.164281 2026] [security2:error] [pid 157386:tid 157529] [client 68.221.73.131:8145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWqAAAARc"] [Tue Aug 18 13:07:24.167426 2026] [security2:error] [pid 157386:tid 157598] [client 74.248.130.103:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/akismet.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWqQAAAVw"] [Tue Aug 18 13:07:24.186681 2026] [security2:error] [pid 157386:tid 157526] [client 20.151.109.219:38613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ka.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWqgAAARQ"] [Tue Aug 18 13:07:24.215942 2026] [security2:error] [pid 157386:tid 157471] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/html-api/"] [unique_id "aoSDPE1jzAhYHVVT1WcWqwABJFQ"] [Tue Aug 18 13:07:24.223008 2026] [security2:error] [pid 157386:tid 157612] [client 20.104.100.201:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/7.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWrAAAAWo"] [Tue Aug 18 13:07:24.261075 2026] [security2:error] [pid 157386:tid 157574] [client 135.225.75.187:11597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/path.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWrQAAAUQ"] [Tue Aug 18 13:07:24.289632 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:24.289903 2026] [authz_core:error] [pid 157386:tid 157460] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:24.294404 2026] [security2:error] [pid 157386:tid 157535] [client 40.74.65.169:20760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/100.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWsAAAAR0"] [Tue Aug 18 13:07:24.302546 2026] [security2:error] [pid 157386:tid 157433] [remote 85.204.70.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1td.com.br"] [uri "/wp-login.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWsQABPC4"] [Tue Aug 18 13:07:24.308552 2026] [security2:error] [pid 157386:tid 157561] [client 20.79.204.6:5965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/inputs.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWsgAAATc"] [Tue Aug 18 13:07:24.315025 2026] [security2:error] [pid 157386:tid 157536] [client 158.158.74.177:17101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/st.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWtAAAAR4"] [Tue Aug 18 13:07:24.321139 2026] [security2:error] [pid 157386:tid 157585] [client 20.116.17.175:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWtQAAAU8"] [Tue Aug 18 13:07:24.355157 2026] [security2:error] [pid 157386:tid 157455] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/client/.env"] [unique_id "aoSDPE1jzAhYHVVT1WcWuAABVEQ"] [Tue Aug 18 13:07:24.390062 2026] [security2:error] [pid 157386:tid 157640] [client 20.206.73.37:26615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/xyn.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWuQAAAYY"] [Tue Aug 18 13:07:24.408824 2026] [security2:error] [pid 157386:tid 157573] [client 20.251.48.93:3575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/site.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWuwAAAUM"] [Tue Aug 18 13:07:24.418362 2026] [security2:error] [pid 157386:tid 157517] [client 74.248.18.37:11267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWvAAAAQs"] [Tue Aug 18 13:07:24.435246 2026] [security2:error] [pid 157386:tid 157606] [client 172.182.217.32:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/coming-soon/app/backwards/themes/admin.php"] [unique_id "aoSDPE1jzAhYHVVT1WcWvQAAAWQ"] [Tue Aug 18 13:07:24.465411 2026] [autoindex:error] [pid 157386:tid 157525] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:24.545272 2026] [security2:error] [pid 157386:tid 157477] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/404.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW0QABH1o"] [Tue Aug 18 13:07:24.572799 2026] [security2:error] [pid 157386:tid 157506] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW0gABInc"] [Tue Aug 18 13:07:24.596465 2026] [authz_core:error] [pid 157386:tid 157483] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:24.596885 2026] [authz_core:error] [pid 157386:tid 157483] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:24.597131 2026] [security2:error] [pid 157386:tid 157427] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/..%2F..%2F..%2F..%2F..%2F.env"] [unique_id "aoSDPE1jzAhYHVVT1WcW1gABgCg"] [Tue Aug 18 13:07:24.603783 2026] [security2:error] [pid 157386:tid 157597] [client 158.23.17.4:38393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/jm.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW2AAAAVs"] [Tue Aug 18 13:07:24.610762 2026] [security2:error] [pid 157386:tid 157396] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSDPE1jzAhYHVVT1WcW2gABfwk"] [Tue Aug 18 13:07:24.676237 2026] [security2:error] [pid 157386:tid 157560] [client 74.248.18.37:18582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/myshell.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW4gAAATY"] [Tue Aug 18 13:07:24.678410 2026] [security2:error] [pid 157386:tid 157543] [client 135.225.75.187:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wpo.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW4wAAASU"] [Tue Aug 18 13:07:24.686715 2026] [security2:error] [pid 157386:tid 157584] [client 74.248.130.103:49499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/admin.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW5AAAAU4"] [Tue Aug 18 13:07:24.688376 2026] [security2:error] [pid 157386:tid 157602] [client 20.151.109.219:36681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ot.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW5gAAAWA"] [Tue Aug 18 13:07:24.718915 2026] [autoindex:error] [pid 157386:tid 157551] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:24.809496 2026] [security2:error] [pid 157386:tid 157589] [client 4.232.151.198:5405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/system_log.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW7QAAAVM"] [Tue Aug 18 13:07:24.821129 2026] [security2:error] [pid 157386:tid 157436] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW7gABdzE"] [Tue Aug 18 13:07:24.821981 2026] [security2:error] [pid 157386:tid 157624] [client 20.116.17.175:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW7wAAAXY"] [Tue Aug 18 13:07:24.869104 2026] [security2:error] [pid 157386:tid 157556] [client 213.35.127.232:49271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW8gAAATI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:24.891395 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:24.891669 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:24.909376 2026] [security2:error] [pid 157386:tid 157638] [client 20.65.69.59:1469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/filesystems.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW9gAAAYQ"] [Tue Aug 18 13:07:24.924894 2026] [security2:error] [pid 157386:tid 157567] [client 172.182.217.32:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/config.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW9wAAAT0"] [Tue Aug 18 13:07:24.926861 2026] [security2:error] [pid 157386:tid 157562] [client 20.79.204.6:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/install.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW-AAAATg"] [Tue Aug 18 13:07:24.932886 2026] [security2:error] [pid 157386:tid 157574] [client 104.209.144.33:32660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW-QAAAUQ"] [Tue Aug 18 13:07:24.945284 2026] [security2:error] [pid 157386:tid 157636] [client 158.158.74.177:17121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW-wAAAYI"] [Tue Aug 18 13:07:24.946503 2026] [security2:error] [pid 157386:tid 157508] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-login.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW7AABe3k"] [Tue Aug 18 13:07:24.976903 2026] [autoindex:error] [pid 157386:tid 157600] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:24.983617 2026] [security2:error] [pid 157386:tid 157536] [client 20.251.48.93:14361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDPE1jzAhYHVVT1WcW_gAAAR4"] [Tue Aug 18 13:07:24.984294 2026] [security2:error] [pid 157386:tid 157395] [remote 47.128.35.215:48096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.autochampsveiculos.com.br"] [uri "/veiculo/616875/ecosport-se-1-5-12v-flex-5p-aut"] [unique_id "aoSDPE1jzAhYHVVT1WcW_wABGQg"] [Tue Aug 18 13:07:24.991928 2026] [security2:error] [pid 157386:tid 157585] [client 40.74.65.169:7120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ccc.php"] [unique_id "aoSDPE1jzAhYHVVT1WcXAAAAAU8"] [Tue Aug 18 13:07:25.039230 2026] [security2:error] [pid 157386:tid 157599] [client 197.184.64.235:42687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXAQAAAV0"] [Tue Aug 18 13:07:25.043211 2026] [security2:error] [pid 157386:tid 157599] [client 197.184.64.235:42687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXAQAAAV0"] [Tue Aug 18 13:07:25.052741 2026] [security2:error] [pid 157386:tid 157529] [client 74.248.18.37:11727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/system.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXAgAAARc"] [Tue Aug 18 13:07:25.065030 2026] [security2:error] [pid 157386:tid 157534] [client 158.23.17.4:53220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wj.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXAwAAARw"] [Tue Aug 18 13:07:25.082270 2026] [security2:error] [pid 157386:tid 157459] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/login/..;/actuator/env"] [unique_id "aoSDPU1jzAhYHVVT1WcXBQABQ0g"] [Tue Aug 18 13:07:25.089704 2026] [security2:error] [pid 157386:tid 157431] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/..;/actuator/env"] [unique_id "aoSDPU1jzAhYHVVT1WcXBgABCyw"] [Tue Aug 18 13:07:25.095263 2026] [security2:error] [pid 157386:tid 157606] [client 135.225.75.187:22994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/a1vx.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXBwAAAWQ"] [Tue Aug 18 13:07:25.124635 2026] [security2:error] [pid 157386:tid 157632] [client 103.120.71.157:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXCAAAAX4"] [Tue Aug 18 13:07:25.124773 2026] [security2:error] [pid 157386:tid 157632] [client 103.120.71.157:56852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXCAAAAX4"] [Tue Aug 18 13:07:25.125397 2026] [security2:error] [pid 157386:tid 157390] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/k.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXCQABSAM"] [Tue Aug 18 13:07:25.163074 2026] [security2:error] [pid 157386:tid 157563] [client 74.248.130.103:49495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.goedertcertificacaodigital.com.br"] [uri "/ajax.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXCwAAATk"] [Tue Aug 18 13:07:25.170717 2026] [autoindex:error] [pid 157386:tid 157575] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:25.188157 2026] [security2:error] [pid 157386:tid 157579] [client 20.151.109.219:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ih.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXDQAAAUk"] [Tue Aug 18 13:07:25.195319 2026] [security2:error] [pid 157386:tid 157611] [client 20.116.17.175:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/dk.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXDgAAAWk"] [Tue Aug 18 13:07:25.196229 2026] [security2:error] [pid 157386:tid 157389] [remote 85.204.70.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1td.com.br"] [uri "/wp-login.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXDwABGAI"] [Tue Aug 18 13:07:25.197221 2026] [security2:error] [pid 157386:tid 157497] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXEAABH24"] [Tue Aug 18 13:07:25.271135 2026] [security2:error] [pid 157386:tid 157554] [client 104.209.144.33:25295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXEgAAATA"] [Tue Aug 18 13:07:25.354705 2026] [security2:error] [pid 157386:tid 157387] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSDPU1jzAhYHVVT1WcXGAABbQA"] [Tue Aug 18 13:07:25.356593 2026] [security2:error] [pid 157386:tid 157428] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/..;/.env"] [unique_id "aoSDPU1jzAhYHVVT1WcXFwABQik"] [Tue Aug 18 13:07:25.363812 2026] [security2:error] [pid 157386:tid 157569] [client 52.173.121.69:28320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/yxijx.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXGQAAAT8"] [Tue Aug 18 13:07:25.372417 2026] [security2:error] [pid 157386:tid 157507] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/static/..;/.env"] [unique_id "aoSDPU1jzAhYHVVT1WcXHQABWHg"] [Tue Aug 18 13:07:25.381993 2026] [security2:error] [pid 157386:tid 157590] [client 74.248.18.37:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/filemanagerk.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXHgAAAVQ"] [Tue Aug 18 13:07:25.410798 2026] [security2:error] [pid 157386:tid 157540] [client 172.182.217.32:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/db-status.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXJQAAASI"] [Tue Aug 18 13:07:25.457026 2026] [security2:error] [pid 157386:tid 157583] [client 4.232.151.198:5408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/motu.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXKQAAAU0"] [Tue Aug 18 13:07:25.463321 2026] [security2:error] [pid 157386:tid 157423] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/"] [unique_id "aoSDPU1jzAhYHVVT1WcXKgABKyQ"] [Tue Aug 18 13:07:25.471992 2026] [security2:error] [pid 157386:tid 157525] [client 185.191.171.7:58100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752865496/1753920000/"] [unique_id "aoSDPU1jzAhYHVVT1WcXLAAAARM"] [Tue Aug 18 13:07:25.472919 2026] [security2:error] [pid 157386:tid 157525] [client 185.191.171.7:58100] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752865496/1753920000/"] [unique_id "aoSDPU1jzAhYHVVT1WcXLAAAARM"] [Tue Aug 18 13:07:25.477377 2026] [autoindex:error] [pid 157386:tid 157605] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:25.496294 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:25.496689 2026] [authz_core:error] [pid 157386:tid 157446] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:25.515617 2026] [security2:error] [pid 157386:tid 157616] [client 135.225.75.187:23025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ty.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXLgAAAW4"] [Tue Aug 18 13:07:25.562702 2026] [security2:error] [pid 157386:tid 157542] [client 20.116.17.175:64913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/bal.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXLwAAASQ"] [Tue Aug 18 13:07:25.568113 2026] [security2:error] [pid 157386:tid 157543] [client 158.158.74.177:4760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/system.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXMAAAASU"] [Tue Aug 18 13:07:25.589960 2026] [security2:error] [pid 157386:tid 157562] [client 104.209.144.33:31285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXMgAAATg"] [Tue Aug 18 13:07:25.592174 2026] [security2:error] [pid 157386:tid 157577] [client 20.251.48.93:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/cabs.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXMwAAAUc"] [Tue Aug 18 13:07:25.595579 2026] [security2:error] [pid 157386:tid 157581] [client 49.145.211.146:11369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXKAAAAUs"] [Tue Aug 18 13:07:25.595671 2026] [security2:error] [pid 157386:tid 157581] [client 49.145.211.146:11369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXKAAAAUs"] [Tue Aug 18 13:07:25.636214 2026] [security2:error] [pid 157386:tid 157602] [client 20.79.204.6:5740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXNQAAAWA"] [Tue Aug 18 13:07:25.685047 2026] [security2:error] [pid 157386:tid 157589] [client 74.248.18.37:11268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/system_log.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXOAAAAVM"] [Tue Aug 18 13:07:25.703739 2026] [security2:error] [pid 157386:tid 157585] [client 20.65.69.59:22053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/showphpinfo.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXOQAAAU8"] [Tue Aug 18 13:07:25.712082 2026] [security2:error] [pid 157386:tid 157640] [client 158.23.17.4:20656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/74.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXOgAAAYY"] [Tue Aug 18 13:07:25.722793 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/index2.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXPAAAAV0"] [Tue Aug 18 13:07:25.768217 2026] [security2:error] [pid 157386:tid 157445] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/403.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXPgABHDo"] [Tue Aug 18 13:07:25.776336 2026] [security2:error] [pid 157386:tid 157417] [remote 72.167.40.62:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cesarinox.com"] [uri "/wp-login.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXPwABTB4"] [Tue Aug 18 13:07:25.794336 2026] [security2:error] [pid 157386:tid 157622] [client 40.74.65.169:36969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/get.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXQQAAAXQ"] [Tue Aug 18 13:07:25.815117 2026] [autoindex:error] [pid 157386:tid 157641] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:25.820935 2026] [security2:error] [pid 157386:tid 157620] [client 20.65.98.162:45087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/biufile.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXQwAAAXI"] [Tue Aug 18 13:07:25.870593 2026] [security2:error] [pid 157386:tid 157619] [client 196.12.128.158:64658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXRgAAAXE"] [Tue Aug 18 13:07:25.870692 2026] [security2:error] [pid 157386:tid 157619] [client 196.12.128.158:64658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXRgAAAXE"] [Tue Aug 18 13:07:25.893250 2026] [security2:error] [pid 157386:tid 157558] [client 213.35.127.232:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXRwAAATQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:25.917092 2026] [security2:error] [pid 157386:tid 157485] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXTwABL2I"] [Tue Aug 18 13:07:25.917257 2026] [security2:error] [pid 157386:tid 157553] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXTwABL2I"] [Tue Aug 18 13:07:25.936374 2026] [security2:error] [pid 157386:tid 157597] [client 135.225.75.187:23848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/vgtyu.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXUAAAAVs"] [Tue Aug 18 13:07:25.947650 2026] [autoindex:error] [pid 157386:tid 157529] [client 172.182.217.32:4128] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-content/plugins/elementor/core/admin/ui/components/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.009733 2026] [security2:error] [pid 157386:tid 157580] [client 104.209.144.33:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXVQAAAUo"] [Tue Aug 18 13:07:26.034121 2026] [security2:error] [pid 157386:tid 157487] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/production/.env"] [unique_id "aoSDPk1jzAhYHVVT1WcXWAABQmQ"] [Tue Aug 18 13:07:26.034379 2026] [security2:error] [pid 157386:tid 157447] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/internal/.env"] [unique_id "aoSDPk1jzAhYHVVT1WcXWQABPzw"] [Tue Aug 18 13:07:26.047799 2026] [security2:error] [pid 157386:tid 157432] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/"] [unique_id "aoSDPk1jzAhYHVVT1WcXWgABVC0"] [Tue Aug 18 13:07:26.093453 2026] [security2:error] [pid 157386:tid 157540] [client 20.251.48.93:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/insc.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXXgAAASI"] [Tue Aug 18 13:07:26.109532 2026] [security2:error] [pid 157386:tid 157614] [client 172.182.217.32:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/elementor/core/admin/ui/components/min.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXXwAAAWw"] [Tue Aug 18 13:07:26.175642 2026] [security2:error] [pid 157386:tid 157537] [client 74.248.18.37:24102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/luf.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXYgAAAR8"] [Tue Aug 18 13:07:26.176411 2026] [security2:error] [pid 157386:tid 157565] [client 4.232.151.198:22311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/uploads/2024//chosen.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXYwAAATs"] [Tue Aug 18 13:07:26.191597 2026] [security2:error] [pid 157386:tid 157637] [client 158.158.74.177:17693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/system_log.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXZAAAAYM"] [Tue Aug 18 13:07:26.213251 2026] [autoindex:error] [pid 157386:tid 157598] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.232084 2026] [security2:error] [pid 157386:tid 157605] [client 158.23.17.4:20634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/av.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXZgAAAWM"] [Tue Aug 18 13:07:26.271367 2026] [security2:error] [pid 157386:tid 157471] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/cache/"] [unique_id "aoSDPk1jzAhYHVVT1WcXZwABiFQ"] [Tue Aug 18 13:07:26.283385 2026] [security2:error] [pid 157386:tid 157594] [client 20.79.204.6:5712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/item.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXagAAAVg"] [Tue Aug 18 13:07:26.300527 2026] [security2:error] [pid 157386:tid 157613] [client 104.209.144.33:32651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXawAAAWs"] [Tue Aug 18 13:07:26.308995 2026] [autoindex:error] [pid 157386:tid 157433] [remote 20.163.43.14:0] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.317501 2026] [security2:error] [pid 157386:tid 157551] [client 74.248.18.37:21369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXbQAAAS0"] [Tue Aug 18 13:07:26.343312 2026] [security2:error] [pid 157386:tid 157581] [client 20.104.100.201:53881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ws77.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXbwAAAUs"] [Tue Aug 18 13:07:26.349292 2026] [security2:error] [pid 157386:tid 157574] [client 20.116.17.175:64929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/yawa.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXcAAAAUQ"] [Tue Aug 18 13:07:26.356569 2026] [security2:error] [pid 157386:tid 157623] [client 135.225.75.187:35712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/mans.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXcgAAAXU"] [Tue Aug 18 13:07:26.397263 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:26.397527 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:26.414163 2026] [security2:error] [pid 157386:tid 157589] [client 20.65.69.59:24677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/phpstatus.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXdAAAAVM"] [Tue Aug 18 13:07:26.478017 2026] [security2:error] [pid 157386:tid 157601] [client 20.116.17.175:20418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/8.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXdgAAAV8"] [Tue Aug 18 13:07:26.494266 2026] [security2:error] [pid 157386:tid 157534] [client 40.74.65.169:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/images.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXeAAAARw"] [Tue Aug 18 13:07:26.540251 2026] [security2:error] [pid 157386:tid 157491] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wso.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXfQABSGg"] [Tue Aug 18 13:07:26.551375 2026] [authz_core:error] [pid 157386:tid 157450] [remote 57.141.22.2:59152] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:26.551639 2026] [authz_core:error] [pid 157386:tid 157450] [remote 57.141.22.2:59152] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:26.579171 2026] [autoindex:error] [pid 157386:tid 157641] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.638316 2026] [autoindex:error] [pid 157386:tid 157539] [client 205.210.31.219:60990] AH01276: Cannot serve directory /home1/xsolutions/vfarm.3xsolutions.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.646892 2026] [security2:error] [pid 157386:tid 157629] [client 52.173.121.69:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/zwlsv.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXhQAAAXs"] [Tue Aug 18 13:07:26.658704 2026] [security2:error] [pid 157386:tid 157634] [client 20.251.48.93:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/file.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXhwAAAYA"] [Tue Aug 18 13:07:26.703549 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:26.704007 2026] [authz_core:error] [pid 157386:tid 157503] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:26.707349 2026] [security2:error] [pid 157386:tid 157504] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/gecko.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXjAABSnU"] [Tue Aug 18 13:07:26.724646 2026] [security2:error] [pid 157386:tid 157572] [client 20.104.100.201:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-temp.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXjQAAAUI"] [Tue Aug 18 13:07:26.757458 2026] [security2:error] [pid 157386:tid 157588] [client 20.116.17.175:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXjgAAAVI"] [Tue Aug 18 13:07:26.765658 2026] [security2:error] [pid 157386:tid 157590] [client 20.206.73.37:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXjwAAAVQ"] [Tue Aug 18 13:07:26.772819 2026] [security2:error] [pid 157386:tid 157630] [client 135.225.75.187:35735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/co.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXkAAAAXw"] [Tue Aug 18 13:07:26.773641 2026] [security2:error] [pid 157386:tid 157430] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/sf.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXkQABRis"] [Tue Aug 18 13:07:26.801250 2026] [security2:error] [pid 157386:tid 157639] [client 4.232.151.198:5429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/help.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXkgAAAYU"] [Tue Aug 18 13:07:26.809842 2026] [security2:error] [pid 157386:tid 157579] [client 158.158.74.177:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/templates/beez3/error.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXlAAAAUk"] [Tue Aug 18 13:07:26.822209 2026] [security2:error] [pid 157386:tid 157614] [client 68.221.73.131:54594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/media.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXlQAAAWw"] [Tue Aug 18 13:07:26.824706 2026] [security2:error] [pid 157386:tid 157583] [client 104.209.144.33:31233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXlgAAAU0"] [Tue Aug 18 13:07:26.832795 2026] [security2:error] [pid 157386:tid 157633] [client 20.104.100.201:53369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXlwAAAX8"] [Tue Aug 18 13:07:26.920154 2026] [security2:error] [pid 157386:tid 157593] [client 20.79.204.6:5734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/js.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXnAAAAVc"] [Tue Aug 18 13:07:26.920245 2026] [security2:error] [pid 157386:tid 157620] [client 213.35.127.232:49711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXnQAAAXI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:26.933584 2026] [autoindex:error] [pid 157386:tid 157607] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:26.953881 2026] [security2:error] [pid 157386:tid 157605] [client 20.65.69.59:21139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/del.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXoAAAAWM"] [Tue Aug 18 13:07:26.963410 2026] [security2:error] [pid 157386:tid 157615] [client 74.248.18.37:21374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/test.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXogAAAW0"] [Tue Aug 18 13:07:26.979145 2026] [security2:error] [pid 157386:tid 157451] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/staging/.env"] [unique_id "aoSDPk1jzAhYHVVT1WcXowABbkA"] [Tue Aug 18 13:07:26.990923 2026] [security2:error] [pid 157386:tid 157584] [client 74.248.18.37:33267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/wsoyanzfv3.php"] [unique_id "aoSDPk1jzAhYHVVT1WcXpAAAAU4"] [Tue Aug 18 13:07:27.012616 2026] [security2:error] [pid 157386:tid 157480] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/index/function.php"] [unique_id "aoSDP01jzAhYHVVT1WcXpwABFF0"] [Tue Aug 18 13:07:27.021284 2026] [security2:error] [pid 157386:tid 157482] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/"] [unique_id "aoSDP01jzAhYHVVT1WcXqQABMl8"] [Tue Aug 18 13:07:27.083554 2026] [security2:error] [pid 157386:tid 157609] [client 158.23.17.4:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ag.php"] [unique_id "aoSDP01jzAhYHVVT1WcXqwAAAWc"] [Tue Aug 18 13:07:27.091853 2026] [security2:error] [pid 157386:tid 157527] [client 20.205.121.237:11535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/tmp/index.php"] [unique_id "aoSDP01jzAhYHVVT1WcXrAAAARU"] [Tue Aug 18 13:07:27.100220 2026] [security2:error] [pid 157386:tid 157562] [client 20.151.109.219:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/k.php"] [unique_id "aoSDP01jzAhYHVVT1WcXrQAAATg"] [Tue Aug 18 13:07:27.125753 2026] [security2:error] [pid 157386:tid 157421] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/prod/.env"] [unique_id "aoSDP01jzAhYHVVT1WcXsQABHSI"] [Tue Aug 18 13:07:27.136732 2026] [autoindex:error] [pid 157386:tid 157403] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:27.186371 2026] [security2:error] [pid 157386:tid 157606] [client 5.31.227.224:1436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDP01jzAhYHVVT1WcXtAAAAWQ"] [Tue Aug 18 13:07:27.186542 2026] [security2:error] [pid 157386:tid 157606] [client 5.31.227.224:1436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDP01jzAhYHVVT1WcXtAAAAWQ"] [Tue Aug 18 13:07:27.189074 2026] [security2:error] [pid 157386:tid 157589] [client 40.74.65.169:21355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/alls.php"] [unique_id "aoSDP01jzAhYHVVT1WcXtQAAAVM"] [Tue Aug 18 13:07:27.193941 2026] [security2:error] [pid 157386:tid 157592] [client 20.250.13.23:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/file.php"] [unique_id "aoSDP01jzAhYHVVT1WcXtgAAAVY"] [Tue Aug 18 13:07:27.201316 2026] [security2:error] [pid 157386:tid 157599] [client 135.225.75.187:23836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/btx25.php"] [unique_id "aoSDP01jzAhYHVVT1WcXuAAAAV0"] [Tue Aug 18 13:07:27.205881 2026] [security2:error] [pid 157386:tid 157601] [client 104.209.144.33:31245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDP01jzAhYHVVT1WcXuQAAAV8"] [Tue Aug 18 13:07:27.210813 2026] [security2:error] [pid 157386:tid 157457] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/services/.env"] [unique_id "aoSDP01jzAhYHVVT1WcXugABGUY"] [Tue Aug 18 13:07:27.224529 2026] [security2:error] [pid 157386:tid 157496] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/dev/.env"] [unique_id "aoSDP01jzAhYHVVT1WcXuwABQ20"] [Tue Aug 18 13:07:27.234557 2026] [security2:error] [pid 157386:tid 157582] [client 20.116.17.175:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/7.php"] [unique_id "aoSDP01jzAhYHVVT1WcXvAAAAUw"] [Tue Aug 18 13:07:27.246378 2026] [security2:error] [pid 157386:tid 157422] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.env~"] [unique_id "aoSDP01jzAhYHVVT1WcXvgABYCM"] [Tue Aug 18 13:07:27.258217 2026] [security2:error] [pid 157386:tid 157461] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/edit.php"] [unique_id "aoSDP01jzAhYHVVT1WcXwAABJ0o"] [Tue Aug 18 13:07:27.267610 2026] [autoindex:error] [pid 157386:tid 157641] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:27.279385 2026] [security2:error] [pid 157386:tid 157530] [client 20.104.100.201:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/read.php"] [unique_id "aoSDP01jzAhYHVVT1WcXwgAAARg"] [Tue Aug 18 13:07:27.295332 2026] [security2:error] [pid 157386:tid 157477] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/aa.php"] [unique_id "aoSDP01jzAhYHVVT1WcXxQABIVo"] [Tue Aug 18 13:07:27.300434 2026] [authz_core:error] [pid 157386:tid 157490] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:27.300695 2026] [authz_core:error] [pid 157386:tid 157490] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:27.403315 2026] [security2:error] [pid 157386:tid 157597] [client 20.251.48.93:14371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/dex.php"] [unique_id "aoSDP01jzAhYHVVT1WcX0AAAAVs"] [Tue Aug 18 13:07:27.421866 2026] [security2:error] [pid 157386:tid 157569] [client 20.116.17.175:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/images.php"] [unique_id "aoSDP01jzAhYHVVT1WcX0QAAAT8"] [Tue Aug 18 13:07:27.433547 2026] [security2:error] [pid 157386:tid 157534] [client 158.158.74.177:4788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/test.php"] [unique_id "aoSDP01jzAhYHVVT1WcX0gAAARw"] [Tue Aug 18 13:07:27.460542 2026] [security2:error] [pid 157386:tid 157636] [client 4.232.151.198:18985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDP01jzAhYHVVT1WcX1AAAAYI"] [Tue Aug 18 13:07:27.503260 2026] [security2:error] [pid 157386:tid 157587] [client 104.209.144.33:25306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDP01jzAhYHVVT1WcX2AAAAVE"] [Tue Aug 18 13:07:27.507560 2026] [security2:error] [pid 157386:tid 157579] [client 20.65.69.59:1432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/moderator.php"] [unique_id "aoSDP01jzAhYHVVT1WcX2gAAAUk"] [Tue Aug 18 13:07:27.524468 2026] [autoindex:error] [pid 157386:tid 157635] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:27.531067 2026] [security2:error] [pid 157386:tid 157406] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/0x.php"] [unique_id "aoSDP01jzAhYHVVT1WcX3gABKBM"] [Tue Aug 18 13:07:27.533661 2026] [security2:error] [pid 157386:tid 157575] [client 74.7.230.54:35920] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.grols.com.br"] [uri "/index.php"] [unique_id "aoSDPU1jzAhYHVVT1WcXVAABRWE"] [Tue Aug 18 13:07:27.552872 2026] [security2:error] [pid 157386:tid 157549] [client 20.116.17.175:58224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ws77.php"] [unique_id "aoSDP01jzAhYHVVT1WcX3wAAASs"] [Tue Aug 18 13:07:27.574161 2026] [security2:error] [pid 157386:tid 157559] [client 20.205.121.237:11564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/tmpls.php"] [unique_id "aoSDP01jzAhYHVVT1WcX4gAAATU"] [Tue Aug 18 13:07:27.597667 2026] [security2:error] [pid 157386:tid 157553] [client 20.79.204.6:5721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/k.php"] [unique_id "aoSDP01jzAhYHVVT1WcX5QAAAS8"] [Tue Aug 18 13:07:27.597690 2026] [security2:error] [pid 157386:tid 157570] [client 74.248.18.37:21367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/test1.php"] [unique_id "aoSDP01jzAhYHVVT1WcX5gAAAUA"] [Tue Aug 18 13:07:27.604429 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:27.604699 2026] [authz_core:error] [pid 157386:tid 157499] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:27.607822 2026] [security2:error] [pid 157386:tid 157508] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.env.orig"] [unique_id "aoSDP01jzAhYHVVT1WcX5wABcnk"] [Tue Aug 18 13:07:27.620981 2026] [security2:error] [pid 157386:tid 157605] [client 135.225.75.187:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/avim.php"] [unique_id "aoSDP01jzAhYHVVT1WcX6AAAAWM"] [Tue Aug 18 13:07:27.676631 2026] [security2:error] [pid 157386:tid 157473] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/ci/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX7AABFFY"] [Tue Aug 18 13:07:27.676766 2026] [security2:error] [pid 157386:tid 157594] [client 158.23.17.4:44733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ig.php"] [unique_id "aoSDP01jzAhYHVVT1WcX7QAAAVg"] [Tue Aug 18 13:07:27.682484 2026] [security2:error] [pid 157386:tid 157459] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/conf/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX7gABJEg"] [Tue Aug 18 13:07:27.691592 2026] [security2:error] [pid 157386:tid 157390] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/old/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX8AABUgM"] [Tue Aug 18 13:07:27.711030 2026] [security2:error] [pid 157386:tid 157497] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/html/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX8gABZ24"] [Tue Aug 18 13:07:27.725679 2026] [security2:error] [pid 157386:tid 157590] [client 74.248.18.37:18563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/imageadmin.php"] [unique_id "aoSDP01jzAhYHVVT1WcX9QAAAVQ"] [Tue Aug 18 13:07:27.759007 2026] [autoindex:error] [pid 157386:tid 157586] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:27.764415 2026] [security2:error] [pid 157386:tid 157551] [client 20.151.109.219:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/iu.php"] [unique_id "aoSDP01jzAhYHVVT1WcX-QAAAS0"] [Tue Aug 18 13:07:27.766291 2026] [security2:error] [pid 157386:tid 157404] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/application/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX-gABPBE"] [Tue Aug 18 13:07:27.767484 2026] [security2:error] [pid 157386:tid 157454] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/crm/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX-wABd0M"] [Tue Aug 18 13:07:27.777628 2026] [security2:error] [pid 157386:tid 157438] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/apps/.env"] [unique_id "aoSDP01jzAhYHVVT1WcX_QABHjM"] [Tue Aug 18 13:07:27.794542 2026] [security2:error] [pid 157386:tid 157589] [client 52.173.121.69:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/jrpga.php"] [unique_id "aoSDP01jzAhYHVVT1WcX_wAAAVM"] [Tue Aug 18 13:07:27.857174 2026] [security2:error] [pid 157386:tid 157632] [client 20.116.17.175:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/read.php"] [unique_id "aoSDP01jzAhYHVVT1WcYBgAAAX4"] [Tue Aug 18 13:07:27.889255 2026] [security2:error] [pid 157386:tid 157622] [client 40.74.65.169:36939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/coffexium.php"] [unique_id "aoSDP01jzAhYHVVT1WcYCAAAAXQ"] [Tue Aug 18 13:07:27.905770 2026] [authz_core:error] [pid 157386:tid 157420] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:27.906182 2026] [authz_core:error] [pid 157386:tid 157420] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:27.934696 2026] [security2:error] [pid 157386:tid 157539] [client 20.251.48.93:3531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/key.php"] [unique_id "aoSDP01jzAhYHVVT1WcYCwAAASE"] [Tue Aug 18 13:07:27.936003 2026] [security2:error] [pid 157386:tid 157593] [client 213.35.127.232:49930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDP01jzAhYHVVT1WcYDAAAAVc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:27.973305 2026] [security2:error] [pid 157386:tid 157392] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/v1/.env"] [unique_id "aoSDP01jzAhYHVVT1WcYDwABYQU"] [Tue Aug 18 13:07:27.975019 2026] [security2:error] [pid 157386:tid 157629] [client 52.22.236.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "amigosdoronron.com.br"] [uri "/index.php"] [unique_id "aoSDP01jzAhYHVVT1WcXxwABezc"], referer: https://amigosdoronron.com.br/ [Tue Aug 18 13:07:28.003237 2026] [security2:error] [pid 157386:tid 157466] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYEAABQk8"] [Tue Aug 18 13:07:28.012991 2026] [autoindex:error] [pid 157386:tid 157569] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:28.039078 2026] [security2:error] [pid 157386:tid 157543] [client 135.225.75.187:23002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/myfile.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYFAAAASU"] [Tue Aug 18 13:07:28.060956 2026] [security2:error] [pid 157386:tid 157518] [client 158.158.74.177:17128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/test1.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYFQAAAQw"] [Tue Aug 18 13:07:28.061010 2026] [security2:error] [pid 157386:tid 157636] [client 104.209.144.33:31280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYFgAAAYI"] [Tue Aug 18 13:07:28.067413 2026] [security2:error] [pid 157386:tid 157630] [client 20.116.17.175:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/a.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYFwAAAXw"] [Tue Aug 18 13:07:28.082139 2026] [security2:error] [pid 157386:tid 157563] [client 4.232.151.198:22286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/hplfuns.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYGAAAATk"] [Tue Aug 18 13:07:28.123645 2026] [security2:error] [pid 157386:tid 157587] [client 20.104.100.201:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/albin.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYGgAAAVE"] [Tue Aug 18 13:07:28.144105 2026] [security2:error] [pid 157386:tid 157591] [client 216.73.161.202:34223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYGwAAAVU"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:07:28.163643 2026] [security2:error] [pid 157386:tid 157583] [client 20.116.17.175:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/albin.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYHQAAAU0"] [Tue Aug 18 13:07:28.170049 2026] [security2:error] [pid 157386:tid 157464] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/private/.env"] [unique_id "aoSDQE1jzAhYHVVT1WcYHgABgU0"] [Tue Aug 18 13:07:28.178003 2026] [security2:error] [pid 157386:tid 157601] [client 20.250.13.23:29543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYHwAAAV8"] [Tue Aug 18 13:07:28.187312 2026] [security2:error] [pid 157386:tid 157394] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/frontend/.env"] [unique_id "aoSDQE1jzAhYHVVT1WcYIAABKAc"] [Tue Aug 18 13:07:28.190058 2026] [security2:error] [pid 157386:tid 157575] [client 52.173.121.69:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYIQAAAUU"] [Tue Aug 18 13:07:28.212062 2026] [security2:error] [pid 157386:tid 157597] [client 20.79.204.6:5745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/media/index.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYJQAAAVs"] [Tue Aug 18 13:07:28.228187 2026] [security2:error] [pid 157386:tid 157400] [remote 85.204.70.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1td.com.br"] [uri "/wp-login.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYJwABXA0"] [Tue Aug 18 13:07:28.240788 2026] [security2:error] [pid 157386:tid 157435] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-good.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYKQABbTA"] [Tue Aug 18 13:07:28.245039 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.18.37:21360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/text.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYKgAAAWk"] [Tue Aug 18 13:07:28.266320 2026] [security2:error] [pid 157386:tid 157411] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/backup/.env"] [unique_id "aoSDQE1jzAhYHVVT1WcYLAABWBg"] [Tue Aug 18 13:07:28.268803 2026] [security2:error] [pid 157386:tid 157445] [remote 100.25.120.246:13928] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cainelli.com.br"] [uri "/uploads/plctncc/restaurants-columbus-ravine,-scarborough"] [unique_id "aoSDQE1jzAhYHVVT1WcYLQABbDo"] [Tue Aug 18 13:07:28.274388 2026] [autoindex:error] [pid 157386:tid 157642] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:28.277315 2026] [security2:error] [pid 157386:tid 157542] [client 158.23.17.4:39594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ta.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYLgAAASQ"] [Tue Aug 18 13:07:28.343260 2026] [security2:error] [pid 157386:tid 157588] [client 172.182.217.32:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYMwAAAVI"] [Tue Aug 18 13:07:28.405437 2026] [security2:error] [pid 157386:tid 157535] [client 20.151.109.219:40459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pk.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYNwAAAR0"] [Tue Aug 18 13:07:28.410584 2026] [security2:error] [pid 157386:tid 157557] [client 74.248.18.37:18602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/webwp.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYOAAAATM"] [Tue Aug 18 13:07:28.411634 2026] [security2:error] [pid 157386:tid 157476] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/zxz.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYOQABdlk"] [Tue Aug 18 13:07:28.417203 2026] [security2:error] [pid 157386:tid 157446] [remote 47.128.32.201:57102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vipshopps.com.br"] [uri "/robots.txt"] [unique_id "aoSDQE1jzAhYHVVT1WcYOgABPDs"] [Tue Aug 18 13:07:28.433732 2026] [security2:error] [pid 157386:tid 157638] [client 49.37.150.8:53065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYPAAAAYQ"] [Tue Aug 18 13:07:28.433819 2026] [security2:error] [pid 157386:tid 157638] [client 49.37.150.8:53065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYPAAAAYQ"] [Tue Aug 18 13:07:28.440480 2026] [security2:error] [pid 157386:tid 157527] [client 223.185.37.47:11993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYPQAAARU"] [Tue Aug 18 13:07:28.442074 2026] [security2:error] [pid 157386:tid 157527] [client 223.185.37.47:11993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYPQAAARU"] [Tue Aug 18 13:07:28.457639 2026] [security2:error] [pid 157386:tid 157585] [client 135.225.75.187:35748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xmy.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYPwAAAU8"] [Tue Aug 18 13:07:28.458996 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:20329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYQAAAAV0"] [Tue Aug 18 13:07:28.505232 2026] [security2:error] [pid 157386:tid 157547] [client 104.209.144.33:31291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYRgAAASk"] [Tue Aug 18 13:07:28.507531 2026] [security2:error] [pid 157386:tid 157622] [client 20.251.48.93:54061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/kir.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYRwAAAXQ"] [Tue Aug 18 13:07:28.515880 2026] [security2:error] [pid 157386:tid 157618] [client 20.116.17.175:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/fw/34.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYSAAAAXA"] [Tue Aug 18 13:07:28.607269 2026] [security2:error] [pid 157386:tid 157584] [client 20.205.121.237:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/tool.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYTwAAAU4"] [Tue Aug 18 13:07:28.657388 2026] [security2:error] [pid 157386:tid 157543] [client 40.74.65.169:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/red.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYVgAAASU"] [Tue Aug 18 13:07:28.713855 2026] [security2:error] [pid 157386:tid 157643] [client 78.47.98.55:23522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agrimotor.com.br"] [uri "/index.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYSQAAAYk"], referer: https://agrimotor.com.br [Tue Aug 18 13:07:28.714289 2026] [security2:error] [pid 157386:tid 157530] [client 4.232.151.198:18962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/02.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYWAAAARg"] [Tue Aug 18 13:07:28.753898 2026] [security2:error] [pid 157386:tid 157604] [client 68.221.73.131:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/inso.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYWgAAAWI"] [Tue Aug 18 13:07:28.778579 2026] [security2:error] [pid 157386:tid 157541] [client 158.158.74.177:4742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/text.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYWwAAASM"] [Tue Aug 18 13:07:28.805649 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:28.805930 2026] [authz_core:error] [pid 157386:tid 157393] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:28.833535 2026] [security2:error] [pid 157386:tid 157580] [client 20.79.204.6:5724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYXQAAAUo"] [Tue Aug 18 13:07:28.869923 2026] [security2:error] [pid 157386:tid 157574] [client 104.209.144.33:32653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYYwAAAUQ"] [Tue Aug 18 13:07:28.874032 2026] [security2:error] [pid 157386:tid 157605] [client 135.225.75.187:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xda.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYZQAAAWM"] [Tue Aug 18 13:07:28.876908 2026] [security2:error] [pid 157386:tid 157636] [client 74.248.18.37:11721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYZwAAAYI"] [Tue Aug 18 13:07:28.878095 2026] [security2:error] [pid 157386:tid 157615] [client 20.116.17.175:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/99.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYaAAAAW0"] [Tue Aug 18 13:07:28.884713 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:64973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp9.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYaQAAAYU"] [Tue Aug 18 13:07:28.884874 2026] [autoindex:error] [pid 157386:tid 157391] [remote 85.204.70.116:0] AH01276: Cannot serve directory /home2/hg1tdc82/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:28.886735 2026] [autoindex:error] [pid 157386:tid 157598] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:28.893049 2026] [security2:error] [pid 157386:tid 157504] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/www.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYbAABWHU"] [Tue Aug 18 13:07:28.897534 2026] [security2:error] [pid 157386:tid 157576] [client 37.40.227.74:57237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYbQAAAUY"] [Tue Aug 18 13:07:28.897636 2026] [security2:error] [pid 157386:tid 157576] [client 37.40.227.74:57237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYbQAAAUY"] [Tue Aug 18 13:07:28.936384 2026] [security2:error] [pid 157386:tid 157567] [client 45.8.19.247:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "memorialpax.com.br"] [uri "/wp-login.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYcQAAAT0"] [Tue Aug 18 13:07:28.961275 2026] [security2:error] [pid 157386:tid 157538] [client 213.35.127.232:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDQE1jzAhYHVVT1WcYdAAAASA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:28.994847 2026] [security2:error] [pid 157386:tid 157455] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/backend/api/.env"] [unique_id "aoSDQE1jzAhYHVVT1WcYdQABZUQ"] [Tue Aug 18 13:07:29.035247 2026] [security2:error] [pid 157386:tid 157495] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/v2/.env"] [unique_id "aoSDQU1jzAhYHVVT1WcYdwABPGw"] [Tue Aug 18 13:07:29.039296 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:46573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ge.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYeAAAAXc"] [Tue Aug 18 13:07:29.043207 2026] [security2:error] [pid 157386:tid 157444] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/app/api/.env"] [unique_id "aoSDQU1jzAhYHVVT1WcYeQABZDk"] [Tue Aug 18 13:07:29.102505 2026] [security2:error] [pid 157386:tid 157609] [client 20.65.69.59:24697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/infoinfo.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYewAAAWc"] [Tue Aug 18 13:07:29.110645 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:29.111076 2026] [authz_core:error] [pid 157386:tid 157467] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:29.131645 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.18.37:18617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wordpress/wp-content/themes/as/flower.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYfgAAAWk"] [Tue Aug 18 13:07:29.132159 2026] [security2:error] [pid 157386:tid 157531] [client 158.23.17.4:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/34.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYfwAAARk"] [Tue Aug 18 13:07:29.155212 2026] [security2:error] [pid 157386:tid 157511] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wicked.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYgAABhnw"] [Tue Aug 18 13:07:29.179118 2026] [security2:error] [pid 157386:tid 157622] [client 20.251.48.93:29709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/nofile.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYggAAAXQ"] [Tue Aug 18 13:07:29.192186 2026] [security2:error] [pid 157386:tid 157602] [client 20.116.17.175:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/save.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYgwAAAWA"] [Tue Aug 18 13:07:29.203796 2026] [security2:error] [pid 157386:tid 157532] [client 104.209.144.33:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/rezor.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYhQAAARo"] [Tue Aug 18 13:07:29.268997 2026] [autoindex:error] [pid 157386:tid 157564] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:29.286212 2026] [security2:error] [pid 157386:tid 157630] [client 20.116.17.175:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/yup.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYiAAAAXw"] [Tue Aug 18 13:07:29.292460 2026] [security2:error] [pid 157386:tid 157637] [client 135.225.75.187:22996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/zz.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYiQAAAYM"] [Tue Aug 18 13:07:29.296577 2026] [security2:error] [pid 157386:tid 157418] [remote 129.121.123.168:58274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/wp-login.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYiwABNx8"] [Tue Aug 18 13:07:29.337238 2026] [security2:error] [pid 157386:tid 157517] [client 4.232.151.198:18949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/upgrade/alfanew.php7"] [unique_id "aoSDQU1jzAhYHVVT1WcYjAAAAQs"] [Tue Aug 18 13:07:29.369953 2026] [security2:error] [pid 157386:tid 157456] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYjwABI0U"] [Tue Aug 18 13:07:29.370092 2026] [security2:error] [pid 157386:tid 157541] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYjwABI0U"] [Tue Aug 18 13:07:29.396214 2026] [security2:error] [pid 157386:tid 157618] [client 158.158.74.177:17719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYkgAAAXA"] [Tue Aug 18 13:07:29.407510 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:29.407792 2026] [authz_core:error] [pid 157386:tid 157403] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:29.413154 2026] [security2:error] [pid 157386:tid 157503] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/HLA-dd.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYlQABQHQ"] [Tue Aug 18 13:07:29.420430 2026] [security2:error] [pid 157386:tid 157457] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/tes.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYlwABSkY"] [Tue Aug 18 13:07:29.468735 2026] [security2:error] [pid 157386:tid 157636] [client 104.209.144.33:32686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYmAAAAYI"] [Tue Aug 18 13:07:29.477134 2026] [security2:error] [pid 157386:tid 157615] [client 52.173.121.69:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/nwwha.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYmgAAAW0"] [Tue Aug 18 13:07:29.496232 2026] [security2:error] [pid 157386:tid 157563] [client 20.79.204.6:5963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/mgrr.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYmwAAATk"] [Tue Aug 18 13:07:29.516404 2026] [security2:error] [pid 157386:tid 157631] [client 20.171.51.14:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wj.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYnAAAAX0"] [Tue Aug 18 13:07:29.540735 2026] [autoindex:error] [pid 157386:tid 157594] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:29.573140 2026] [security2:error] [pid 157386:tid 157526] [client 20.116.17.175:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYogAAARQ"] [Tue Aug 18 13:07:29.585145 2026] [security2:error] [pid 157386:tid 157613] [client 20.65.69.59:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/c99shell.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYowAAAWs"] [Tue Aug 18 13:07:29.612374 2026] [security2:error] [pid 157386:tid 157567] [client 158.23.17.4:4664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/he.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYpAAAAT0"] [Tue Aug 18 13:07:29.613584 2026] [security2:error] [pid 157386:tid 157542] [client 20.151.109.219:31701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kl.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYpQAAASQ"] [Tue Aug 18 13:07:29.640515 2026] [security2:error] [pid 157386:tid 157641] [client 20.205.121.237:11556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/txets.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYpgAAAYc"] [Tue Aug 18 13:07:29.656815 2026] [security2:error] [pid 157386:tid 157461] [remote 194.116.184.179:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.184.116.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYpwABNUo"] [Tue Aug 18 13:07:29.658747 2026] [security2:error] [pid 157386:tid 157477] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/files/index.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYqgABS1o"] [Tue Aug 18 13:07:29.661666 2026] [security2:error] [pid 157386:tid 157574] [client 74.248.18.37:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/u.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYqwAAAUQ"] [Tue Aug 18 13:07:29.669506 2026] [security2:error] [pid 157386:tid 157396] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYrgABUgk"] [Tue Aug 18 13:07:29.681126 2026] [security2:error] [pid 157386:tid 157577] [client 20.116.17.175:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/222.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYrwAAAUc"] [Tue Aug 18 13:07:29.708158 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:29.708428 2026] [authz_core:error] [pid 157386:tid 157409] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:29.709553 2026] [security2:error] [pid 157386:tid 157551] [client 135.225.75.187:12054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xa.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYtgAAAS0"] [Tue Aug 18 13:07:29.731211 2026] [autoindex:error] [pid 157386:tid 157566] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:29.782421 2026] [security2:error] [pid 157386:tid 157589] [client 104.209.144.33:32669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYvwAAAVM"] [Tue Aug 18 13:07:29.784777 2026] [autoindex:error] [pid 157386:tid 157527] [client 82.102.18.182:59640] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:29.829574 2026] [security2:error] [pid 157386:tid 157405] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/phpinfo.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYwgABXRI"] [Tue Aug 18 13:07:29.841048 2026] [security2:error] [pid 157386:tid 157583] [client 20.250.13.23:55558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/404.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYxQAAAU0"] [Tue Aug 18 13:07:29.877217 2026] [security2:error] [pid 157386:tid 157575] [client 20.251.48.93:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/fling.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYxgAAAUU"] [Tue Aug 18 13:07:29.879497 2026] [security2:error] [pid 157386:tid 157627] [client 74.248.18.37:19702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/module.tag.id3v3.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYxwAAAXk"] [Tue Aug 18 13:07:29.886508 2026] [security2:error] [pid 157386:tid 157498] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYyAABdG8"] [Tue Aug 18 13:07:29.941346 2026] [security2:error] [pid 157386:tid 157544] [client 20.65.69.59:21182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/profiler.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYzAAAASY"] [Tue Aug 18 13:07:29.958780 2026] [security2:error] [pid 157386:tid 157484] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cah.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYzgABOmE"] [Tue Aug 18 13:07:29.961135 2026] [autoindex:error] [pid 157386:tid 157592] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:29.978119 2026] [security2:error] [pid 157386:tid 157518] [client 20.65.98.162:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/coffexium.php"] [unique_id "aoSDQU1jzAhYHVVT1WcYzwAAAQw"] [Tue Aug 18 13:07:29.980895 2026] [security2:error] [pid 157386:tid 157582] [client 4.232.151.198:23068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "aoSDQU1jzAhYHVVT1WcY0AAAAUw"] [Tue Aug 18 13:07:29.981656 2026] [security2:error] [pid 157386:tid 157534] [client 213.35.127.232:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDQU1jzAhYHVVT1WcY0QAAARw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:30.009475 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:30.009754 2026] [authz_core:error] [pid 157386:tid 157468] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:30.018873 2026] [security2:error] [pid 157386:tid 157587] [client 52.173.121.69:28306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/opsqt.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY1AAAAVE"] [Tue Aug 18 13:07:30.037483 2026] [security2:error] [pid 157386:tid 157611] [client 158.158.74.177:4738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/u.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY3QAAAWk"] [Tue Aug 18 13:07:30.050140 2026] [security2:error] [pid 157386:tid 157591] [client 104.209.144.33:25283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/index/function.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY3wAAAVU"] [Tue Aug 18 13:07:30.068670 2026] [security2:error] [pid 157386:tid 157545] [client 20.116.17.175:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY4QAAASc"] [Tue Aug 18 13:07:30.072803 2026] [security2:error] [pid 157386:tid 157595] [client 20.116.17.175:20478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY4gAAAVk"] [Tue Aug 18 13:07:30.088927 2026] [security2:error] [pid 157386:tid 157541] [client 68.221.73.131:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/shiny.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY4wAAASM"] [Tue Aug 18 13:07:30.091658 2026] [security2:error] [pid 157386:tid 157497] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/development/.env"] [unique_id "aoSDQk1jzAhYHVVT1WcY5AABaG4"] [Tue Aug 18 13:07:30.125936 2026] [security2:error] [pid 157386:tid 157436] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/images/images/about.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY5wABSjE"] [Tue Aug 18 13:07:30.126384 2026] [security2:error] [pid 157386:tid 157570] [client 135.225.75.187:35659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/f6.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY6AAAAUA"] [Tue Aug 18 13:07:30.157153 2026] [security2:error] [pid 157386:tid 157636] [client 20.151.109.219:20933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gs.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY6wAAAYI"] [Tue Aug 18 13:07:30.183692 2026] [security2:error] [pid 157386:tid 157563] [client 20.104.100.201:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/fw/34.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY7QAAATk"] [Tue Aug 18 13:07:30.184965 2026] [autoindex:error] [pid 157386:tid 157615] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:30.211640 2026] [security2:error] [pid 157386:tid 157472] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/laravel/.env"] [unique_id "aoSDQk1jzAhYHVVT1WcY7wABXFU"] [Tue Aug 18 13:07:30.237264 2026] [security2:error] [pid 157386:tid 157407] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/docker/.env"] [unique_id "aoSDQk1jzAhYHVVT1WcY9AABFBQ"] [Tue Aug 18 13:07:30.246881 2026] [security2:error] [pid 157386:tid 157438] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/"] [unique_id "aoSDQk1jzAhYHVVT1WcY9QABazM"] [Tue Aug 18 13:07:30.277146 2026] [security2:error] [pid 157386:tid 157571] [client 158.23.17.4:5038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gz.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY9gAAAUE"] [Tue Aug 18 13:07:30.285728 2026] [security2:error] [pid 157386:tid 157479] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/_profiler/phpinfo.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY9wABPVw"] [Tue Aug 18 13:07:30.292971 2026] [security2:error] [pid 157386:tid 157520] [client 74.248.18.37:11323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/updates.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY-AAAAQ4"] [Tue Aug 18 13:07:30.315095 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:30.315359 2026] [authz_core:error] [pid 157386:tid 157493] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:30.335746 2026] [security2:error] [pid 157386:tid 157574] [client 20.65.69.59:19534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/findes.php"] [unique_id "aoSDQk1jzAhYHVVT1WcY_AAAAUQ"] [Tue Aug 18 13:07:30.406864 2026] [security2:error] [pid 157386:tid 157624] [client 104.209.144.33:32677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZAQAAAXY"] [Tue Aug 18 13:07:30.424464 2026] [autoindex:error] [pid 157386:tid 157551] [client 104.209.144.33:29876] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:30.433187 2026] [security2:error] [pid 157386:tid 157566] [client 20.79.204.6:5749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/mini.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZBAAAATw"] [Tue Aug 18 13:07:30.476052 2026] [security2:error] [pid 157386:tid 157536] [client 172.182.217.32:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/post-types-order/compatibility/themes/db-status.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZBgAAAR4"] [Tue Aug 18 13:07:30.487372 2026] [security2:error] [pid 157386:tid 157609] [client 40.74.65.169:37418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZBwAAAWc"] [Tue Aug 18 13:07:30.500089 2026] [security2:error] [pid 157386:tid 157466] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/system_log.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZCAABFU8"] [Tue Aug 18 13:07:30.521241 2026] [security2:error] [pid 157386:tid 157501] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZCQABT3I"] [Tue Aug 18 13:07:30.542879 2026] [security2:error] [pid 157386:tid 157599] [client 135.225.75.187:11584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/mcs.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZDAAAAV0"] [Tue Aug 18 13:07:30.545110 2026] [security2:error] [pid 157386:tid 157583] [client 20.116.17.175:58407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/df.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZDgAAAU0"] [Tue Aug 18 13:07:30.566570 2026] [security2:error] [pid 157386:tid 157453] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/twilio/.env.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZEwABfkI"] [Tue Aug 18 13:07:30.569919 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:46543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lw.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZFgAAASk"] [Tue Aug 18 13:07:30.613126 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:30.613400 2026] [authz_core:error] [pid 157386:tid 157435] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:30.616121 2026] [security2:error] [pid 157386:tid 157557] [client 4.232.151.198:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZGwAAATM"] [Tue Aug 18 13:07:30.656189 2026] [security2:error] [pid 157386:tid 157603] [client 104.209.144.33:31237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/Cachex.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZHgAAAWE"] [Tue Aug 18 13:07:30.678275 2026] [security2:error] [pid 157386:tid 157559] [client 20.205.121.237:11527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/u.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZIgAAATU"] [Tue Aug 18 13:07:30.691162 2026] [security2:error] [pid 157386:tid 157642] [client 158.158.74.177:4456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/updates.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZIwAAAYg"] [Tue Aug 18 13:07:30.718514 2026] [security2:error] [pid 157386:tid 157582] [client 20.104.100.201:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp9.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZJQAAAUw"] [Tue Aug 18 13:07:30.722780 2026] [security2:error] [pid 157386:tid 157521] [client 74.248.18.37:24984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/wp-db-ajax-made/wp-ajax.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZJgAAAQ8"] [Tue Aug 18 13:07:30.731006 2026] [security2:error] [pid 157386:tid 157630] [client 20.251.48.93:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/zoo1.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZJwAAAXw"] [Tue Aug 18 13:07:30.731967 2026] [security2:error] [pid 157386:tid 157413] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/pomo/"] [unique_id "aoSDQk1jzAhYHVVT1WcZKAABgxo"] [Tue Aug 18 13:07:30.738899 2026] [security2:error] [pid 157386:tid 157561] [client 20.116.17.175:20345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/spadex.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZKQAAATc"] [Tue Aug 18 13:07:30.749643 2026] [security2:error] [pid 157386:tid 157423] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/rip.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZKwABSSQ"] [Tue Aug 18 13:07:30.874067 2026] [security2:error] [pid 157386:tid 157414] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/.env.local"] [unique_id "aoSDQk1jzAhYHVVT1WcZLwABLhs"] [Tue Aug 18 13:07:30.880359 2026] [security2:error] [pid 157386:tid 157488] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDQk1jzAhYHVVT1WcZMQABI2U"] [Tue Aug 18 13:07:30.885870 2026] [security2:error] [pid 157386:tid 157569] [client 20.65.69.59:22039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/fedora.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZMwAAAT8"] [Tue Aug 18 13:07:30.924804 2026] [security2:error] [pid 157386:tid 157529] [client 52.173.121.69:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZOAAAARc"] [Tue Aug 18 13:07:30.933140 2026] [security2:error] [pid 157386:tid 157534] [client 74.248.18.37:11309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZOgAAARw"] [Tue Aug 18 13:07:30.957990 2026] [security2:error] [pid 157386:tid 157576] [client 158.23.17.4:20629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nf.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZOwAAAUY"] [Tue Aug 18 13:07:30.958491 2026] [security2:error] [pid 157386:tid 157594] [client 104.209.144.33:31277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZPAAAAVg"] [Tue Aug 18 13:07:30.960300 2026] [security2:error] [pid 157386:tid 157553] [client 135.225.75.187:41243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/xleet.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZPQAAAS8"] [Tue Aug 18 13:07:30.969568 2026] [security2:error] [pid 157386:tid 157517] [client 172.182.217.32:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/post.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZPwAAAQs"] [Tue Aug 18 13:07:30.970175 2026] [security2:error] [pid 157386:tid 157471] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.docker/.env"] [unique_id "aoSDQk1jzAhYHVVT1WcZPgABMFQ"] [Tue Aug 18 13:07:30.991877 2026] [security2:error] [pid 157386:tid 157426] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZQAABbCc"] [Tue Aug 18 13:07:30.994916 2026] [security2:error] [pid 157386:tid 157532] [client 213.35.127.232:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDQk1jzAhYHVVT1WcZQQAAARo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:31.013354 2026] [security2:error] [pid 157386:tid 157613] [client 20.116.17.175:64978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZQwAAAWs"] [Tue Aug 18 13:07:31.105896 2026] [security2:error] [pid 157386:tid 157504] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/sendgrid/.env.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZTAABR3U"] [Tue Aug 18 13:07:31.175601 2026] [security2:error] [pid 157386:tid 157598] [client 20.79.204.6:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/minishell.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZVAAAAVw"] [Tue Aug 18 13:07:31.207107 2026] [security2:error] [pid 157386:tid 157495] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/.env.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZVwABXWw"] [Tue Aug 18 13:07:31.213881 2026] [security2:error] [pid 157386:tid 157469] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDQ01jzAhYHVVT1WcZWQABclI"] [Tue Aug 18 13:07:31.214524 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:31.214879 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:31.225514 2026] [security2:error] [pid 157386:tid 157458] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.aws_creds.json"] [unique_id "aoSDQ01jzAhYHVVT1WcZYAABIUc"] [Tue Aug 18 13:07:31.225888 2026] [security2:error] [pid 157386:tid 157578] [client 20.251.48.93:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/zoo2.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZXwAAAUg"] [Tue Aug 18 13:07:31.229224 2026] [security2:error] [pid 157386:tid 157544] [client 40.74.65.169:37420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZYgAAASY"] [Tue Aug 18 13:07:31.276867 2026] [security2:error] [pid 157386:tid 157642] [client 20.206.73.37:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/inso.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZZwAAAYg"] [Tue Aug 18 13:07:31.277452 2026] [security2:error] [pid 157386:tid 157629] [client 20.104.100.201:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/save.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZaAAAAXs"] [Tue Aug 18 13:07:31.283922 2026] [security2:error] [pid 157386:tid 157470] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/aws/ecs/task-credentials"] [unique_id "aoSDQ01jzAhYHVVT1WcZaQABNFM"] [Tue Aug 18 13:07:31.296417 2026] [security2:error] [pid 157386:tid 157542] [client 4.232.151.198:18986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/json.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZawAAASQ"] [Tue Aug 18 13:07:31.300598 2026] [security2:error] [pid 157386:tid 157388] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/aws/ecs/task-credentials.json"] [unique_id "aoSDQ01jzAhYHVVT1WcZbQABDAE"] [Tue Aug 18 13:07:31.311794 2026] [security2:error] [pid 157386:tid 157623] [client 158.158.74.177:18482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZbwAAAXU"] [Tue Aug 18 13:07:31.358057 2026] [security2:error] [pid 157386:tid 157457] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/app_dev.php/_profiler/.env"] [unique_id "aoSDQ01jzAhYHVVT1WcZdAABUUY"] [Tue Aug 18 13:07:31.365275 2026] [security2:error] [pid 157386:tid 157527] [client 74.248.18.37:19704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/comments.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZdgAAARU"] [Tue Aug 18 13:07:31.376699 2026] [security2:error] [pid 157386:tid 157604] [client 135.225.75.187:35743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fr/ms.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZegAAAWI"] [Tue Aug 18 13:07:31.405112 2026] [security2:error] [pid 157386:tid 157467] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ioxi-o.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZfAABGFA"] [Tue Aug 18 13:07:31.436032 2026] [security2:error] [pid 157386:tid 157541] [client 20.116.17.175:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/usr.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZfwAAASM"] [Tue Aug 18 13:07:31.438764 2026] [security2:error] [pid 157386:tid 157461] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/g.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZgAABKEo"] [Tue Aug 18 13:07:31.452098 2026] [security2:error] [pid 157386:tid 157526] [client 149.34.210.141:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZggAAARQ"] [Tue Aug 18 13:07:31.455636 2026] [security2:error] [pid 157386:tid 157633] [client 68.221.73.131:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/403dd.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZgwAAAX8"] [Tue Aug 18 13:07:31.474935 2026] [security2:error] [pid 157386:tid 157572] [client 158.23.17.4:44715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xv.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZhQAAAUI"] [Tue Aug 18 13:07:31.478045 2026] [security2:error] [pid 157386:tid 157397] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZhgABggo"] [Tue Aug 18 13:07:31.481741 2026] [security2:error] [pid 157386:tid 157640] [client 172.182.217.32:4147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/simply-gallery-block/plugins/ms-files.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZiAAAAYY"] [Tue Aug 18 13:07:31.519379 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:31.519661 2026] [authz_core:error] [pid 157386:tid 157510] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:31.522027 2026] [security2:error] [pid 157386:tid 157506] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "aoSDQ01jzAhYHVVT1WcZiwABdHc"] [Tue Aug 18 13:07:31.554792 2026] [security2:error] [pid 157386:tid 157615] [client 20.65.98.162:5319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/dex.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZjQAAAW0"] [Tue Aug 18 13:07:31.572092 2026] [security2:error] [pid 157386:tid 157624] [client 86.120.159.145:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZjwAAAXY"] [Tue Aug 18 13:07:31.572202 2026] [security2:error] [pid 157386:tid 157624] [client 86.120.159.145:54116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZjwAAAXY"] [Tue Aug 18 13:07:31.602339 2026] [security2:error] [pid 157386:tid 157496] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/abc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZkAABL20"] [Tue Aug 18 13:07:31.624840 2026] [security2:error] [pid 157386:tid 157502] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/gecko.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZkgABiXM"] [Tue Aug 18 13:07:31.641267 2026] [security2:error] [pid 157386:tid 157611] [client 74.248.18.37:11310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.financeiro.fabioweb.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZlAAAAWk"] [Tue Aug 18 13:07:31.643490 2026] [security2:error] [pid 157386:tid 157540] [client 20.65.69.59:29526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/path.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZlQAAASI"] [Tue Aug 18 13:07:31.647582 2026] [security2:error] [pid 157386:tid 157520] [client 20.151.109.219:22918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vj.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZlgAAAQ4"] [Tue Aug 18 13:07:31.683000 2026] [security2:error] [pid 157386:tid 157586] [client 20.251.48.93:3537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/org.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZmQAAAVA"] [Tue Aug 18 13:07:31.714941 2026] [security2:error] [pid 157386:tid 157606] [client 20.116.17.175:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZnQAAAWQ"] [Tue Aug 18 13:07:31.720088 2026] [security2:error] [pid 157386:tid 157579] [client 20.205.121.237:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/up.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZngAAAUk"] [Tue Aug 18 13:07:31.724572 2026] [security2:error] [pid 157386:tid 157489] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/moon.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZoAABHmY"] [Tue Aug 18 13:07:31.729890 2026] [security2:error] [pid 157386:tid 157526] [client 149.34.210.141:49556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZggAAARQ"] [Tue Aug 18 13:07:31.793969 2026] [security2:error] [pid 157386:tid 157598] [client 135.225.75.187:23835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/gool.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZpAAAAVw"] [Tue Aug 18 13:07:31.798432 2026] [security2:error] [pid 157386:tid 157405] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/gettest.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZpQABJxI"] [Tue Aug 18 13:07:31.817114 2026] [security2:error] [pid 157386:tid 157557] [client 20.116.17.175:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZpwAAATM"] [Tue Aug 18 13:07:31.817461 2026] [authz_core:error] [pid 157386:tid 157434] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:31.817703 2026] [authz_core:error] [pid 157386:tid 157434] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:31.860465 2026] [security2:error] [pid 157386:tid 157619] [client 20.104.100.201:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-rrtx.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZqwAAAXE"] [Tue Aug 18 13:07:31.877078 2026] [security2:error] [pid 157386:tid 157460] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/akcc.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZrAABSkk"] [Tue Aug 18 13:07:31.887000 2026] [security2:error] [pid 157386:tid 157592] [client 104.209.144.33:31256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZrgAAAVY"] [Tue Aug 18 13:07:31.928995 2026] [security2:error] [pid 157386:tid 157623] [client 40.74.65.169:21340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file52.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZsQAAAXU"] [Tue Aug 18 13:07:31.950232 2026] [security2:error] [pid 157386:tid 157568] [client 4.232.151.198:18990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/css/index.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZtAAAAT4"] [Tue Aug 18 13:07:31.960651 2026] [security2:error] [pid 157386:tid 157609] [client 20.79.204.6:5969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/mm.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZtQAAAWc"] [Tue Aug 18 13:07:31.966795 2026] [security2:error] [pid 157386:tid 157424] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/cache.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZtgABDyU"] [Tue Aug 18 13:07:31.972850 2026] [security2:error] [pid 157386:tid 157390] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/goods.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZtwABgwM"] [Tue Aug 18 13:07:31.980278 2026] [security2:error] [pid 157386:tid 157547] [client 172.182.217.32:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/softaculous-pro/assets/images/plugins/plugin-install.php"] [unique_id "aoSDQ01jzAhYHVVT1WcZuAAAASk"] [Tue Aug 18 13:07:32.012136 2026] [security2:error] [pid 157386:tid 157612] [client 158.158.74.177:17139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.plataformazap.filialweb.com"] [uri "/uploads/admin.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZvQAAAWo"] [Tue Aug 18 13:07:32.012245 2026] [security2:error] [pid 157386:tid 157581] [client 213.35.127.232:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZvAAAAUs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:32.050545 2026] [fcgid:warn] [pid 157386:tid 157559] (70014)End of file found: [client 195.170.172.216:39686] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:32.058352 2026] [security2:error] [pid 157386:tid 157543] [client 158.23.17.4:38396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mx.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZwQAAASU"] [Tue Aug 18 13:07:32.094632 2026] [security2:error] [pid 157386:tid 157633] [client 68.221.73.131:54582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/baba.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZwwAAAX8"] [Tue Aug 18 13:07:32.117045 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:32.117306 2026] [authz_core:error] [pid 157386:tid 157497] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:32.140288 2026] [security2:error] [pid 157386:tid 157610] [client 52.173.121.69:28339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZyQAAAWg"] [Tue Aug 18 13:07:32.151763 2026] [security2:error] [pid 157386:tid 157406] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/gulu.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZywABFxM"] [Tue Aug 18 13:07:32.164532 2026] [security2:error] [pid 157386:tid 157615] [client 20.116.17.175:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/css/database.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZzAAAAW0"] [Tue Aug 18 13:07:32.177026 2026] [security2:error] [pid 157386:tid 157472] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wk/index.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZzQABTVU"] [Tue Aug 18 13:07:32.189101 2026] [security2:error] [pid 157386:tid 157549] [client 20.251.48.93:35765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/imageskir.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZzwAAASs"] [Tue Aug 18 13:07:32.218293 2026] [security2:error] [pid 157386:tid 157517] [client 135.225.75.187:23842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/maxro.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ0gAAAQs"] [Tue Aug 18 13:07:32.274216 2026] [security2:error] [pid 157386:tid 157540] [client 74.248.18.37:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/blogs.dir/about.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ1QAAASI"] [Tue Aug 18 13:07:32.281838 2026] [security2:error] [pid 157386:tid 157593] [client 20.151.109.219:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mimes.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ1gAAAVc"] [Tue Aug 18 13:07:32.303878 2026] [security2:error] [pid 157386:tid 157524] [client 20.116.17.175:20425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/srontol.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ2QAAARI"] [Tue Aug 18 13:07:32.326002 2026] [security2:error] [pid 157386:tid 157389] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/h.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ2wABIQI"] [Tue Aug 18 13:07:32.370575 2026] [security2:error] [pid 157386:tid 157442] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDRE1jzAhYHVVT1WcZ3gABHTc"] [Tue Aug 18 13:07:32.425858 2026] [security2:error] [pid 157386:tid 157589] [client 20.250.13.23:47269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wk/index.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ4wAAAVM"] [Tue Aug 18 13:07:32.444898 2026] [security2:error] [pid 157386:tid 157545] [client 195.170.172.216:39688] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "162.241.203.17"] [uri "/"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5AAAASc"] [Tue Aug 18 13:07:32.445629 2026] [security2:error] [pid 157386:tid 157613] [client 157.20.138.62:53670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5QAAAWs"] [Tue Aug 18 13:07:32.445757 2026] [security2:error] [pid 157386:tid 157613] [client 157.20.138.62:53670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5QAAAWs"] [Tue Aug 18 13:07:32.465702 2026] [security2:error] [pid 157386:tid 157509] [remote 172.202.39.151:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5gABM3o"] [Tue Aug 18 13:07:32.465793 2026] [security2:error] [pid 157386:tid 157509] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5gABM3o"] [Tue Aug 18 13:07:32.476378 2026] [security2:error] [pid 157386:tid 157590] [client 172.182.217.32:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/updraftplus/templates/wp-admin/options.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ5wAAAVQ"] [Tue Aug 18 13:07:32.510440 2026] [security2:error] [pid 157386:tid 157459] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/hello.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ7AABe0g"] [Tue Aug 18 13:07:32.565521 2026] [security2:error] [pid 157386:tid 157419] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/preview"] [unique_id "aoSDRE1jzAhYHVVT1WcZ8AABTCA"] [Tue Aug 18 13:07:32.634066 2026] [security2:error] [pid 157386:tid 157625] [client 135.225.75.187:22980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wdf.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ9wAAAXc"] [Tue Aug 18 13:07:32.636448 2026] [security2:error] [pid 157386:tid 157579] [client 4.232.151.198:5427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/assets/images/tinyimg.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ-AAAAUk"] [Tue Aug 18 13:07:32.682340 2026] [security2:error] [pid 157386:tid 157541] [client 20.104.100.201:17353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/gecko-new.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ_AAAASM"] [Tue Aug 18 13:07:32.688064 2026] [security2:error] [pid 157386:tid 157490] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/images/index.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ_QABSGc"] [Tue Aug 18 13:07:32.692707 2026] [security2:error] [pid 157386:tid 157569] [client 20.151.109.219:40493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ni.php"] [unique_id "aoSDRE1jzAhYHVVT1WcZ_wAAAT8"] [Tue Aug 18 13:07:32.705333 2026] [security2:error] [pid 157386:tid 157411] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaAQABQBg"] [Tue Aug 18 13:07:32.706731 2026] [security2:error] [pid 157386:tid 157640] [client 20.116.17.175:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/privdayz.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaAgAAAYY"] [Tue Aug 18 13:07:32.707357 2026] [security2:error] [pid 157386:tid 157636] [client 104.209.144.33:32695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaAwAAAYI"] [Tue Aug 18 13:07:32.709394 2026] [security2:error] [pid 157386:tid 157610] [client 20.65.69.59:1315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/456.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaBAAAAWg"] [Tue Aug 18 13:07:32.711681 2026] [security2:error] [pid 157386:tid 157619] [client 20.79.204.6:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaBQAAAXE"] [Tue Aug 18 13:07:32.727343 2026] [security2:error] [pid 157386:tid 157631] [client 158.23.17.4:53239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/45.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaCAAAAX0"] [Tue Aug 18 13:07:32.752298 2026] [security2:error] [pid 157386:tid 157597] [client 20.205.121.237:11520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/upload.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaCwAAAVs"] [Tue Aug 18 13:07:32.773975 2026] [security2:error] [pid 157386:tid 157615] [client 20.251.48.93:14362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/indexo.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaDwAAAW0"] [Tue Aug 18 13:07:32.822837 2026] [security2:error] [pid 157386:tid 157639] [client 178.153.171.161:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaEwAAAYU"] [Tue Aug 18 13:07:32.822954 2026] [security2:error] [pid 157386:tid 157639] [client 178.153.171.161:59943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaEwAAAYU"] [Tue Aug 18 13:07:32.959792 2026] [security2:error] [pid 157386:tid 157599] [client 68.221.73.131:60322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/site.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaHwAAAV0"] [Tue Aug 18 13:07:32.968487 2026] [security2:error] [pid 157386:tid 157624] [client 172.182.217.32:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/admin.php"] [unique_id "aoSDRE1jzAhYHVVT1WcaIAAAAXY"] [Tue Aug 18 13:07:33.010792 2026] [security2:error] [pid 157386:tid 157606] [client 20.116.17.175:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wg459o.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaIQAAAWQ"] [Tue Aug 18 13:07:33.020547 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:33.020830 2026] [authz_core:error] [pid 157386:tid 157414] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:33.027742 2026] [security2:error] [pid 157386:tid 157534] [client 74.248.18.37:19711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/abcde.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaJAAAARw"] [Tue Aug 18 13:07:33.032126 2026] [security2:error] [pid 157386:tid 157516] [client 213.35.127.232:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaJQAAAQo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:33.033701 2026] [security2:error] [pid 157386:tid 157488] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/index.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaJgABHmU"] [Tue Aug 18 13:07:33.050697 2026] [security2:error] [pid 157386:tid 157635] [client 135.225.75.187:23844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ff1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaKQAAAYE"] [Tue Aug 18 13:07:33.059262 2026] [security2:error] [pid 157386:tid 157531] [client 40.74.65.169:7111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/geck.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaKgAAARk"] [Tue Aug 18 13:07:33.112627 2026] [lsapi:error] [pid 139043:tid 139057] [remote 201.32.74.208:56981] [host pensamentosimperfeitos.com.br] Error on sending request(GET /2026/07/07/destruiram-minha-casa/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: timeout 300 is exceeded, referer: https://pensamentosimperfeitos.com.br/ [Tue Aug 18 13:07:33.140576 2026] [security2:error] [pid 157386:tid 157560] [client 85.11.167.5:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.brunocunhaimoveis.com.br"] [uri "/"] [unique_id "aoSDRU1jzAhYHVVT1WcaLwAAATY"] [Tue Aug 18 13:07:33.174342 2026] [security2:error] [pid 157386:tid 157485] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/index.bak.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaMAABJGI"] [Tue Aug 18 13:07:33.220731 2026] [security2:error] [pid 157386:tid 157582] [client 20.251.48.93:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaNAAAAUw"] [Tue Aug 18 13:07:33.265812 2026] [security2:error] [pid 157386:tid 157561] [client 20.65.69.59:21173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/SMTP.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaNQAAATc"] [Tue Aug 18 13:07:33.269564 2026] [security2:error] [pid 157386:tid 157607] [client 4.232.151.198:18970] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaNgAAAWU"] [Tue Aug 18 13:07:33.269648 2026] [security2:error] [pid 157386:tid 157607] [client 4.232.151.198:18970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/twentytwentyfour/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaNgAAAWU"] [Tue Aug 18 13:07:33.309909 2026] [security2:error] [pid 157386:tid 157601] [client 52.173.121.69:28338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaOAAAAV8"] [Tue Aug 18 13:07:33.321419 2026] [security2:error] [pid 157386:tid 157603] [client 20.79.204.6:5991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ms-themes.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaTQAAAWE"] [Tue Aug 18 13:07:33.321808 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:33.322196 2026] [authz_core:error] [pid 157386:tid 157469] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:33.347369 2026] [security2:error] [pid 157386:tid 157390] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/index/function.php"] [unique_id "aoSDRU1jzAhYHVVT1WcadQABSQM"] [Tue Aug 18 13:07:33.348964 2026] [security2:error] [pid 157386:tid 157448] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/as.php"] [unique_id "aoSDRU1jzAhYHVVT1WcadgABQT0"] [Tue Aug 18 13:07:33.354799 2026] [ssl:error] [pid 157386:tid 157564] [client 54.86.115.253:43221] AH02032: Hostname srv254.prodns.com.br (default host as no SNI was provided) and hostname autoconfig.sortis.net provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 13:07:33.360952 2026] [security2:error] [pid 157386:tid 157612] [client 20.116.17.175:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/file5.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaeAAAAWo"] [Tue Aug 18 13:07:33.410251 2026] [security2:error] [pid 157386:tid 157575] [client 20.116.17.175:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/mifta.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaiQAAAUU"] [Tue Aug 18 13:07:33.418383 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:31684] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hmanyhands.com.br"] [uri "/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaigAAAX8"] [Tue Aug 18 13:07:33.418500 2026] [security2:error] [pid 157386:tid 157633] [client 20.151.109.219:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaigAAAX8"] [Tue Aug 18 13:07:33.430760 2026] [security2:error] [pid 157386:tid 157570] [client 20.65.98.162:59138] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaiwAAAUA"] [Tue Aug 18 13:07:33.430850 2026] [security2:error] [pid 157386:tid 157570] [client 20.65.98.162:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/1.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaiwAAAUA"] [Tue Aug 18 13:07:33.454108 2026] [security2:error] [pid 157386:tid 157529] [client 158.23.17.4:4993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wy.php"] [unique_id "aoSDRU1jzAhYHVVT1WcajgAAARc"] [Tue Aug 18 13:07:33.464974 2026] [security2:error] [pid 157386:tid 157576] [client 172.182.217.32:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/maintenance.php"] [unique_id "aoSDRU1jzAhYHVVT1WcajwAAAUY"] [Tue Aug 18 13:07:33.466920 2026] [security2:error] [pid 157386:tid 157642] [client 135.225.75.187:24622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/guk.php"] [unique_id "aoSDRU1jzAhYHVVT1WcakAAAAYg"] [Tue Aug 18 13:07:33.476807 2026] [fcgid:warn] [pid 157386:tid 157597] (70014)End of file found: [client 66.132.195.91:38280] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:33.522378 2026] [security2:error] [pid 157386:tid 157434] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/info.php"] [unique_id "aoSDRU1jzAhYHVVT1WcalQABfi8"] [Tue Aug 18 13:07:33.602212 2026] [security2:error] [pid 157386:tid 157438] [remote 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRU1jzAhYHVVT1WcamgABEjM"] [Tue Aug 18 13:07:33.602382 2026] [security2:error] [pid 157386:tid 157524] [client 2401:4900:881a:c57f:412:ae2b:202e:a2b7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adobank.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRU1jzAhYHVVT1WcamgABEjM"] [Tue Aug 18 13:07:33.620909 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:33.621166 2026] [authz_core:error] [pid 157386:tid 157494] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:33.658910 2026] [security2:error] [pid 157386:tid 157535] [client 20.251.48.93:3513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaoAAAAR0"] [Tue Aug 18 13:07:33.672357 2026] [security2:error] [pid 157386:tid 157459] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaoQABHEg"] [Tue Aug 18 13:07:33.688074 2026] [security2:error] [pid 157386:tid 157474] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaowABGVc"] [Tue Aug 18 13:07:33.699575 2026] [security2:error] [pid 157386:tid 157481] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/inputs.php"] [unique_id "aoSDRU1jzAhYHVVT1WcapAABcl4"] [Tue Aug 18 13:07:33.736529 2026] [security2:error] [pid 157386:tid 157557] [client 20.206.73.37:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/puc.php"] [unique_id "aoSDRU1jzAhYHVVT1WcapgAAATM"] [Tue Aug 18 13:07:33.767086 2026] [security2:error] [pid 157386:tid 157584] [client 20.65.69.59:50181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/vbseo.php"] [unique_id "aoSDRU1jzAhYHVVT1WcaqgAAAU4"] [Tue Aug 18 13:07:33.785346 2026] [security2:error] [pid 157386:tid 157614] [client 74.248.18.37:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/anjay.php"] [unique_id "aoSDRU1jzAhYHVVT1WcarAAAAWw"] [Tue Aug 18 13:07:33.788438 2026] [security2:error] [pid 157386:tid 157580] [client 20.116.17.175:58230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSDRU1jzAhYHVVT1WcarQAAAUo"] [Tue Aug 18 13:07:33.811376 2026] [security2:error] [pid 157386:tid 157592] [client 20.250.13.23:34795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/about.php"] [unique_id "aoSDRU1jzAhYHVVT1WcarwAAAVY"] [Tue Aug 18 13:07:33.822957 2026] [security2:error] [pid 157386:tid 157568] [client 20.151.109.219:28799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/88.php"] [unique_id "aoSDRU1jzAhYHVVT1WcasQAAAT4"] [Tue Aug 18 13:07:33.874542 2026] [security2:error] [pid 157386:tid 157399] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/install.php"] [unique_id "aoSDRU1jzAhYHVVT1WcatAABNww"] [Tue Aug 18 13:07:33.886463 2026] [security2:error] [pid 157386:tid 157547] [client 135.225.75.187:35757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-the.php"] [unique_id "aoSDRU1jzAhYHVVT1WcatgAAASk"] [Tue Aug 18 13:07:33.934240 2026] [security2:error] [pid 157386:tid 157490] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-config-sample.php"] [unique_id "aoSDRU1jzAhYHVVT1WcauwABQWc"] [Tue Aug 18 13:07:33.976628 2026] [security2:error] [pid 157386:tid 157629] [client 172.182.217.32:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/wp-polls/tinymce/plugins/module.php"] [unique_id "aoSDRU1jzAhYHVVT1WcawAAAAXs"] [Tue Aug 18 13:07:33.983211 2026] [security2:error] [pid 157386:tid 157591] [client 20.104.100.201:53375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDRU1jzAhYHVVT1WcawgAAAVU"] [Tue Aug 18 13:07:34.010388 2026] [security2:error] [pid 157386:tid 157575] [client 68.221.73.131:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDRk1jzAhYHVVT1WcaxAAAAUU"] [Tue Aug 18 13:07:34.016117 2026] [security2:error] [pid 157386:tid 157640] [client 158.23.17.4:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/f.php"] [unique_id "aoSDRk1jzAhYHVVT1WcaxgAAAYY"] [Tue Aug 18 13:07:34.048302 2026] [security2:error] [pid 157386:tid 157479] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDRk1jzAhYHVVT1WcayAABcVw"] [Tue Aug 18 13:07:34.051131 2026] [security2:error] [pid 157386:tid 157598] [client 213.35.127.232:51329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDRk1jzAhYHVVT1WcayQAAAVw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:34.089899 2026] [security2:error] [pid 157386:tid 157609] [client 20.79.204.6:5741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/my1.php"] [unique_id "aoSDRk1jzAhYHVVT1WcazAAAAWc"] [Tue Aug 18 13:07:34.150244 2026] [security2:error] [pid 157386:tid 157597] [client 40.74.65.169:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/biufile.php"] [unique_id "aoSDRk1jzAhYHVVT1WcazwAAAVs"] [Tue Aug 18 13:07:34.151392 2026] [security2:error] [pid 157386:tid 157543] [client 20.205.121.237:11568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca0AAAASU"] [Tue Aug 18 13:07:34.155883 2026] [security2:error] [pid 157386:tid 157394] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca0QABTQc"] [Tue Aug 18 13:07:34.167568 2026] [security2:error] [pid 157386:tid 157553] [client 4.232.151.198:23064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/filefuns.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca0wAAAS8"] [Tue Aug 18 13:07:34.169818 2026] [security2:error] [pid 157386:tid 157639] [client 20.251.48.93:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/.admin.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca1AAAAYU"] [Tue Aug 18 13:07:34.222848 2026] [security2:error] [pid 157386:tid 157453] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/item.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca2QABgEI"] [Tue Aug 18 13:07:34.246456 2026] [security2:error] [pid 157386:tid 157540] [client 20.116.17.175:58195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/index2.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca2wAAASI"] [Tue Aug 18 13:07:34.281214 2026] [security2:error] [pid 157386:tid 157642] [client 132.196.30.78:20315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/inputs.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca3AAAAYg"] [Tue Aug 18 13:07:34.298106 2026] [security2:error] [pid 157386:tid 157599] [client 20.116.17.175:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/yup.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca3gAAAV0"] [Tue Aug 18 13:07:34.300590 2026] [security2:error] [pid 157386:tid 157577] [client 20.171.51.14:39799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/74.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca3wAAAUc"] [Tue Aug 18 13:07:34.301186 2026] [security2:error] [pid 157386:tid 157624] [client 135.225.75.187:35675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sbhu.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca4AAAAXY"] [Tue Aug 18 13:07:34.360416 2026] [security2:error] [pid 157386:tid 157558] [client 138.36.100.162:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca4wAAATQ"] [Tue Aug 18 13:07:34.360539 2026] [security2:error] [pid 157386:tid 157558] [client 138.36.100.162:43252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca4wAAATQ"] [Tue Aug 18 13:07:34.398143 2026] [security2:error] [pid 157386:tid 157400] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/js.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca5QABHg0"] [Tue Aug 18 13:07:34.424021 2026] [security2:error] [pid 157386:tid 157485] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca6gABM2I"] [Tue Aug 18 13:07:34.424789 2026] [security2:error] [pid 157386:tid 157423] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca6wABayQ"] [Tue Aug 18 13:07:34.435470 2026] [security2:error] [pid 157386:tid 157602] [client 20.65.69.59:1281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/sysinfo.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca7AAAAWA"] [Tue Aug 18 13:07:34.441383 2026] [security2:error] [pid 157386:tid 157590] [client 158.23.17.4:53236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/30.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca7gAAAVQ"] [Tue Aug 18 13:07:34.454257 2026] [security2:error] [pid 157386:tid 157560] [client 20.151.109.219:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/hj.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca7wAAATY"] [Tue Aug 18 13:07:34.461730 2026] [security2:error] [pid 157386:tid 157524] [client 172.182.217.32:25547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/wp-super-cache/plugins/index.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca8AAAARI"] [Tue Aug 18 13:07:34.486271 2026] [security2:error] [pid 157386:tid 157445] [remote 103.56.163.133:41666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serviplascomercio.com.br"] [uri "/wp-login.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca8gABDDo"] [Tue Aug 18 13:07:34.529052 2026] [authz_core:error] [pid 157386:tid 157443] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:34.529506 2026] [authz_core:error] [pid 157386:tid 157443] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:34.531173 2026] [security2:error] [pid 157386:tid 157562] [client 74.248.18.37:19689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca9QAAATg"] [Tue Aug 18 13:07:34.571788 2026] [security2:error] [pid 157386:tid 157392] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/k.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca-QABIAU"] [Tue Aug 18 13:07:34.661190 2026] [security2:error] [pid 157386:tid 157563] [client 20.116.17.175:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/8.php"] [unique_id "aoSDRk1jzAhYHVVT1Wca_wAAATk"] [Tue Aug 18 13:07:34.685779 2026] [security2:error] [pid 157386:tid 157429] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/o.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbAgABOio"] [Tue Aug 18 13:07:34.711030 2026] [security2:error] [pid 157386:tid 157635] [client 20.104.100.201:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/df.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbBgAAAYE"] [Tue Aug 18 13:07:34.717668 2026] [security2:error] [pid 157386:tid 157595] [client 135.225.75.187:23822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/zc-318.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbBwAAAVk"] [Tue Aug 18 13:07:34.721233 2026] [security2:error] [pid 157386:tid 157589] [client 20.79.204.6:5971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/new.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbCAAAAVM"] [Tue Aug 18 13:07:34.739148 2026] [security2:error] [pid 157386:tid 157495] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/"] [unique_id "aoSDRk1jzAhYHVVT1WcbCQABVWw"] [Tue Aug 18 13:07:34.749790 2026] [security2:error] [pid 157386:tid 157415] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/media/index.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbCgABSBw"] [Tue Aug 18 13:07:34.789182 2026] [security2:error] [pid 157386:tid 157522] [client 4.232.151.198:22283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/h.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbDAAAARA"] [Tue Aug 18 13:07:34.791161 2026] [security2:error] [pid 157386:tid 157640] [client 20.251.48.93:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/wsomini.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbDQAAAYY"] [Tue Aug 18 13:07:34.858201 2026] [security2:error] [pid 157386:tid 157631] [client 40.74.65.169:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/dejavu.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbEQAAAX0"] [Tue Aug 18 13:07:34.866815 2026] [security2:error] [pid 157386:tid 157529] [client 20.104.100.201:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-css.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbEgAAARc"] [Tue Aug 18 13:07:34.877519 2026] [security2:error] [pid 157386:tid 157579] [client 132.196.30.78:13590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/admin.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbFQAAAUk"] [Tue Aug 18 13:07:34.908033 2026] [security2:error] [pid 157386:tid 157475] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/aws/s3/credentials.bak"] [unique_id "aoSDRk1jzAhYHVVT1WcbFgABQlg"] [Tue Aug 18 13:07:34.918961 2026] [security2:error] [pid 157386:tid 157388] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/bb.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbGAABLwE"] [Tue Aug 18 13:07:34.922120 2026] [security2:error] [pid 157386:tid 157430] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbGQABfis"] [Tue Aug 18 13:07:34.937762 2026] [security2:error] [pid 157386:tid 157540] [client 20.151.109.219:42763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ij.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbGgAAASI"] [Tue Aug 18 13:07:34.943652 2026] [security2:error] [pid 157386:tid 157435] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/pms"] [unique_id "aoSDRk1jzAhYHVVT1WcbGwABiDA"] [Tue Aug 18 13:07:34.944375 2026] [security2:error] [pid 157386:tid 157593] [client 102.213.179.104:55371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbHQAAAVc"] [Tue Aug 18 13:07:34.944951 2026] [security2:error] [pid 157386:tid 157593] [client 102.213.179.104:55371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDRk1jzAhYHVVT1WcbHQAAAVc"] [Tue Aug 18 13:07:34.956057 2026] [security2:error] [pid 157386:tid 157513] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDRk1jzAhYHVVT1WcbHwABb34"] [Tue Aug 18 13:07:34.982907 2026] [security2:error] [pid 157386:tid 157447] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/pms"] [unique_id "aoSDRk1jzAhYHVVT1WcbIQABZzw"] [Tue Aug 18 13:07:35.012682 2026] [security2:error] [pid 157386:tid 157506] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSDR01jzAhYHVVT1WcbIgABR3c"] [Tue Aug 18 13:07:35.029832 2026] [security2:error] [pid 157386:tid 157428] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/admin/config"] [unique_id "aoSDR01jzAhYHVVT1WcbIwABNCk"] [Tue Aug 18 13:07:35.061986 2026] [security2:error] [pid 157386:tid 157467] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/aws/s3/credentials.json"] [unique_id "aoSDR01jzAhYHVVT1WcbJwABHVA"] [Tue Aug 18 13:07:35.066702 2026] [security2:error] [pid 157386:tid 157629] [client 213.35.127.232:51555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDR01jzAhYHVVT1WcbKAAAAXs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:35.098889 2026] [security2:error] [pid 157386:tid 157460] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/mgrr.php"] [unique_id "aoSDR01jzAhYHVVT1WcbKwABM0k"] [Tue Aug 18 13:07:35.128858 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:35.129129 2026] [authz_core:error] [pid 157386:tid 157444] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:35.134794 2026] [security2:error] [pid 157386:tid 157584] [client 135.225.75.187:35718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ccou.php"] [unique_id "aoSDR01jzAhYHVVT1WcbLgAAAU4"] [Tue Aug 18 13:07:35.172475 2026] [security2:error] [pid 157386:tid 157565] [client 20.226.36.136:41599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDR01jzAhYHVVT1WcbMAAAATs"] [Tue Aug 18 13:07:35.175093 2026] [security2:error] [pid 157386:tid 157489] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDR01jzAhYHVVT1WcbMQABEmY"] [Tue Aug 18 13:07:35.204800 2026] [security2:error] [pid 157386:tid 157594] [client 20.65.69.59:1418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/ppinfo.php"] [unique_id "aoSDR01jzAhYHVVT1WcbNwAAAVg"] [Tue Aug 18 13:07:35.214745 2026] [security2:error] [pid 157386:tid 157477] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/aws/.env"] [unique_id "aoSDR01jzAhYHVVT1WcbOQABClo"] [Tue Aug 18 13:07:35.218951 2026] [security2:error] [pid 157386:tid 157607] [client 20.116.17.175:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/images.php"] [unique_id "aoSDR01jzAhYHVVT1WcbOwAAAWU"] [Tue Aug 18 13:07:35.232184 2026] [security2:error] [pid 157386:tid 157592] [client 104.209.144.33:25304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDR01jzAhYHVVT1WcbPAAAAVY"] [Tue Aug 18 13:07:35.262644 2026] [security2:error] [pid 157386:tid 157562] [client 158.23.17.4:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pu.php"] [unique_id "aoSDR01jzAhYHVVT1WcbQAAAATg"] [Tue Aug 18 13:07:35.284310 2026] [security2:error] [pid 157386:tid 157582] [client 68.221.73.131:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/cabs.php"] [unique_id "aoSDR01jzAhYHVVT1WcbQQAAAUw"] [Tue Aug 18 13:07:35.294609 2026] [security2:error] [pid 157386:tid 157498] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/an.php"] [unique_id "aoSDR01jzAhYHVVT1WcbQwABKW8"] [Tue Aug 18 13:07:35.298548 2026] [security2:error] [pid 157386:tid 157536] [client 74.248.18.37:36844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/publick.php"] [unique_id "aoSDR01jzAhYHVVT1WcbRAAAAR4"] [Tue Aug 18 13:07:35.309177 2026] [security2:error] [pid 157386:tid 157637] [client 20.251.48.93:35139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.48.251.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ellevadomall.com.br"] [uri "/vr.php"] [unique_id "aoSDR01jzAhYHVVT1WcbRQAAAYM"] [Tue Aug 18 13:07:35.363997 2026] [security2:error] [pid 157386:tid 157625] [client 20.151.109.219:28790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ud.php"] [unique_id "aoSDR01jzAhYHVVT1WcbSAAAAXc"] [Tue Aug 18 13:07:35.405064 2026] [security2:error] [pid 157386:tid 157571] [client 20.226.36.136:23192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDR01jzAhYHVVT1WcbSQAAAUE"] [Tue Aug 18 13:07:35.429619 2026] [security2:error] [pid 157386:tid 157580] [client 20.79.204.6:6010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/norn.php"] [unique_id "aoSDR01jzAhYHVVT1WcbTAAAAUo"] [Tue Aug 18 13:07:35.434961 2026] [security2:error] [pid 157386:tid 157480] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/hidden/.aws/credentials"] [unique_id "aoSDR01jzAhYHVVT1WcbUAABNV0"] [Tue Aug 18 13:07:35.437563 2026] [security2:error] [pid 157386:tid 157539] [client 4.232.151.198:18977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/plugins/link.php"] [unique_id "aoSDR01jzAhYHVVT1WcbUgAAASE"] [Tue Aug 18 13:07:35.490274 2026] [security2:error] [pid 157386:tid 157550] [client 132.196.30.78:3015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/goods.php"] [unique_id "aoSDR01jzAhYHVVT1WcbVQAAASw"] [Tue Aug 18 13:07:35.546446 2026] [security2:error] [pid 157386:tid 157486] [remote 35.247.121.182:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDR01jzAhYHVVT1WcbWQABcmM"] [Tue Aug 18 13:07:35.554290 2026] [security2:error] [pid 157386:tid 157502] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/images/"] [unique_id "aoSDR01jzAhYHVVT1WcbWgABcXM"] [Tue Aug 18 13:07:35.557137 2026] [security2:error] [pid 157386:tid 157588] [client 135.225.75.187:22997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/txets.php"] [unique_id "aoSDR01jzAhYHVVT1WcbWwAAAVI"] [Tue Aug 18 13:07:35.558677 2026] [security2:error] [pid 157386:tid 157527] [client 52.173.121.69:28333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDR01jzAhYHVVT1WcbXAAAARU"] [Tue Aug 18 13:07:35.563743 2026] [security2:error] [pid 157386:tid 157624] [client 197.184.64.235:42688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDR01jzAhYHVVT1WcbXQAAAXY"] [Tue Aug 18 13:07:35.568342 2026] [security2:error] [pid 157386:tid 157624] [client 197.184.64.235:42688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDR01jzAhYHVVT1WcbXQAAAXY"] [Tue Aug 18 13:07:35.648469 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:35.648922 2026] [authz_core:error] [pid 157386:tid 157390] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:35.650494 2026] [security2:error] [pid 157386:tid 157448] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/mini.php"] [unique_id "aoSDR01jzAhYHVVT1WcbYgABTT0"] [Tue Aug 18 13:07:35.689177 2026] [security2:error] [pid 157386:tid 157639] [client 20.116.17.175:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/a.php"] [unique_id "aoSDR01jzAhYHVVT1WcbZQAAAYU"] [Tue Aug 18 13:07:35.713549 2026] [security2:error] [pid 157386:tid 157549] [client 40.74.65.169:37413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/aaf.php"] [unique_id "aoSDR01jzAhYHVVT1WcbZwAAASs"] [Tue Aug 18 13:07:35.789190 2026] [security2:error] [pid 157386:tid 157558] [client 20.171.51.14:28283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/av.php"] [unique_id "aoSDR01jzAhYHVVT1WcbawAAATQ"] [Tue Aug 18 13:07:35.801034 2026] [security2:error] [pid 157386:tid 157590] [client 103.120.71.157:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDR01jzAhYHVVT1WcbbAAAAVQ"] [Tue Aug 18 13:07:35.801127 2026] [security2:error] [pid 157386:tid 157590] [client 103.120.71.157:57462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDR01jzAhYHVVT1WcbbAAAAVQ"] [Tue Aug 18 13:07:35.810923 2026] [security2:error] [pid 157386:tid 157586] [client 158.23.17.4:38397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ry.php"] [unique_id "aoSDR01jzAhYHVVT1WcbbQAAAVA"] [Tue Aug 18 13:07:35.831436 2026] [security2:error] [pid 157386:tid 157510] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/minishell.php"] [unique_id "aoSDR01jzAhYHVVT1WcbbgABHHs"] [Tue Aug 18 13:07:35.833336 2026] [security2:error] [pid 157386:tid 157629] [client 20.151.109.219:20941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ip.php"] [unique_id "aoSDR01jzAhYHVVT1WcbbwAAAXs"] [Tue Aug 18 13:07:35.845511 2026] [security2:error] [pid 157386:tid 157408] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/404.php"] [unique_id "aoSDR01jzAhYHVVT1WcbcQABaxU"] [Tue Aug 18 13:07:35.858470 2026] [security2:error] [pid 157386:tid 157387] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/credentials"] [unique_id "aoSDR01jzAhYHVVT1WcbcgABLQA"] [Tue Aug 18 13:07:35.905793 2026] [security2:error] [pid 157386:tid 157454] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDR01jzAhYHVVT1WcbdgABNkM"] [Tue Aug 18 13:07:35.943149 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:35.943425 2026] [authz_core:error] [pid 157386:tid 157389] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:35.973958 2026] [security2:error] [pid 157386:tid 157568] [client 135.225.75.187:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fun.php"] [unique_id "aoSDR01jzAhYHVVT1WcbewAAAT4"] [Tue Aug 18 13:07:35.992670 2026] [security2:error] [pid 157386:tid 157638] [client 74.248.18.37:36830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/cs.php"] [unique_id "aoSDR01jzAhYHVVT1WcbfgAAAYQ"] [Tue Aug 18 13:07:36.016507 2026] [security2:error] [pid 157386:tid 157426] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/mm.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbgQABgyc"] [Tue Aug 18 13:07:36.039070 2026] [security2:error] [pid 157386:tid 157603] [client 20.116.17.175:20362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbgwAAAWE"] [Tue Aug 18 13:07:36.083774 2026] [security2:error] [pid 157386:tid 157642] [client 213.35.127.232:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbhwAAAYg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:36.093761 2026] [security2:error] [pid 157386:tid 157584] [client 20.79.204.6:5720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/num.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbigAAAU4"] [Tue Aug 18 13:07:36.100890 2026] [security2:error] [pid 157386:tid 157520] [client 132.196.30.78:13623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/file.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbiwAAAQ4"] [Tue Aug 18 13:07:36.139099 2026] [security2:error] [pid 157386:tid 157591] [client 20.104.100.201:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDSE1jzAhYHVVT1WcblgAAAVU"] [Tue Aug 18 13:07:36.143667 2026] [security2:error] [pid 157386:tid 157481] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDSE1jzAhYHVVT1WcblwABP14"] [Tue Aug 18 13:07:36.182693 2026] [security2:error] [pid 157386:tid 157522] [client 20.116.17.175:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbmgAAARA"] [Tue Aug 18 13:07:36.192403 2026] [security2:error] [pid 157386:tid 157466] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbmwABME8"] [Tue Aug 18 13:07:36.213740 2026] [security2:error] [pid 157386:tid 157542] [client 20.226.36.136:34141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbnQAAASQ"] [Tue Aug 18 13:07:36.218832 2026] [security2:error] [pid 157386:tid 157619] [client 20.151.109.219:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/99.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbngAAAXE"] [Tue Aug 18 13:07:36.239607 2026] [security2:error] [pid 157386:tid 157631] [client 20.205.121.237:11553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/wp-admin/css/colors/modern/admin.php"] [unique_id "aoSDSE1jzAhYHVVT1WcboAAAAX0"] [Tue Aug 18 13:07:36.240597 2026] [security2:error] [pid 157386:tid 157624] [client 158.23.17.4:5041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pm.php"] [unique_id "aoSDSE1jzAhYHVVT1WcboQAAAXY"] [Tue Aug 18 13:07:36.245189 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:36.245459 2026] [authz_core:error] [pid 157386:tid 157399] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:36.293741 2026] [security2:error] [pid 157386:tid 157599] [client 49.145.211.146:11779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbkgAAAV0"] [Tue Aug 18 13:07:36.293886 2026] [security2:error] [pid 157386:tid 157599] [client 49.145.211.146:11779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbkgAAAV0"] [Tue Aug 18 13:07:36.313970 2026] [security2:error] [pid 157386:tid 157436] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-login.php"] [unique_id "aoSDSE1jzAhYHVVT1WcblAABITE"] [Tue Aug 18 13:07:36.361792 2026] [security2:error] [pid 157386:tid 157508] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/s3-credentials.bak"] [unique_id "aoSDSE1jzAhYHVVT1WcbqwABVHk"] [Tue Aug 18 13:07:36.365212 2026] [security2:error] [pid 157386:tid 157497] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ms-themes.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbrAABUG4"] [Tue Aug 18 13:07:36.384850 2026] [security2:error] [pid 157386:tid 157479] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/file.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbrQABZFw"] [Tue Aug 18 13:07:36.390577 2026] [security2:error] [pid 157386:tid 157567] [client 135.225.75.187:23832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/jq.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbrgAAAT0"] [Tue Aug 18 13:07:36.444094 2026] [security2:error] [pid 157386:tid 157598] [client 20.171.51.14:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ag.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbsQAAAVw"] [Tue Aug 18 13:07:36.482933 2026] [security2:error] [pid 157386:tid 157607] [client 4.232.151.198:22302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/class-t.api.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbtAAAAWU"] [Tue Aug 18 13:07:36.539794 2026] [security2:error] [pid 157386:tid 157468] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/my1.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbtwABOFE"] [Tue Aug 18 13:07:36.545961 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:36.546233 2026] [authz_core:error] [pid 157386:tid 157473] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:36.576192 2026] [security2:error] [pid 157386:tid 157494] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbuQABD2s"] [Tue Aug 18 13:07:36.622173 2026] [security2:error] [pid 157386:tid 157501] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/api/v1/credentials"] [unique_id "aoSDSE1jzAhYHVVT1WcbugABg3I"] [Tue Aug 18 13:07:36.623259 2026] [security2:error] [pid 157386:tid 157553] [client 40.74.65.169:21318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbuwAAAS8"] [Tue Aug 18 13:07:36.623497 2026] [security2:error] [pid 157386:tid 157536] [client 172.182.217.32:4107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/style-engine/style-engine/ixr/plugins/wp-mail.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbvAAAAR4"] [Tue Aug 18 13:07:36.637315 2026] [security2:error] [pid 157386:tid 157400] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/epinyins.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbvQABKA0"] [Tue Aug 18 13:07:36.660413 2026] [security2:error] [pid 157386:tid 157602] [client 158.23.17.4:53201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/dr.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbvwAAAWA"] [Tue Aug 18 13:07:36.669749 2026] [security2:error] [pid 157386:tid 157642] [client 20.226.36.136:51909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbwAAAAYg"] [Tue Aug 18 13:07:36.678823 2026] [security2:error] [pid 157386:tid 157610] [client 132.196.30.78:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbwQAAAWg"] [Tue Aug 18 13:07:36.687713 2026] [security2:error] [pid 157386:tid 157584] [client 20.116.17.175:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/99.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbwgAAAU4"] [Tue Aug 18 13:07:36.709809 2026] [security2:error] [pid 157386:tid 157445] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbxwABHDo"] [Tue Aug 18 13:07:36.709969 2026] [security2:error] [pid 157386:tid 157534] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbxwABHDo"] [Tue Aug 18 13:07:36.716610 2026] [security2:error] [pid 157386:tid 157476] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/new.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbyQABDlk"] [Tue Aug 18 13:07:36.774196 2026] [security2:error] [pid 157386:tid 157580] [client 20.151.109.219:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/er.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbygAAAUo"] [Tue Aug 18 13:07:36.806549 2026] [security2:error] [pid 157386:tid 157569] [client 135.225.75.187:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sys.php"] [unique_id "aoSDSE1jzAhYHVVT1WcbzwAAAT8"] [Tue Aug 18 13:07:36.810192 2026] [security2:error] [pid 157386:tid 157547] [client 74.248.18.37:58013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/1nt3pqdk.php"] [unique_id "aoSDSE1jzAhYHVVT1Wcb0AAAASk"] [Tue Aug 18 13:07:36.811061 2026] [security2:error] [pid 157386:tid 157437] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDSE1jzAhYHVVT1Wcb0QABGDI"] [Tue Aug 18 13:07:36.839125 2026] [security2:error] [pid 157386:tid 157471] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/ID3/"] [unique_id "aoSDSE1jzAhYHVVT1Wcb0wABEFQ"] [Tue Aug 18 13:07:36.846656 2026] [authz_core:error] [pid 157386:tid 157417] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:36.846935 2026] [authz_core:error] [pid 157386:tid 157417] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:36.886250 2026] [security2:error] [pid 157386:tid 157429] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDSE1jzAhYHVVT1Wcb1wABQCo"] [Tue Aug 18 13:07:36.927624 2026] [security2:error] [pid 157386:tid 157495] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/norn.php"] [unique_id "aoSDSE1jzAhYHVVT1Wcb2AABf2w"] [Tue Aug 18 13:07:36.983380 2026] [security2:error] [pid 157386:tid 157568] [client 20.79.204.6:5738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/options-reading.php"] [unique_id "aoSDSE1jzAhYHVVT1Wcb2gAAAT4"] [Tue Aug 18 13:07:37.018303 2026] [security2:error] [pid 157386:tid 157559] [client 20.104.100.201:53278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/cok.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb3AAAATU"] [Tue Aug 18 13:07:37.045878 2026] [security2:error] [pid 157386:tid 157532] [client 20.116.17.175:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/yup.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb4AAAARo"] [Tue Aug 18 13:07:37.083366 2026] [security2:error] [pid 157386:tid 157612] [client 20.116.17.175:20320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-the.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb4gAAAWo"] [Tue Aug 18 13:07:37.102806 2026] [security2:error] [pid 157386:tid 157487] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/num.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb4wABH2Q"] [Tue Aug 18 13:07:37.103806 2026] [security2:error] [pid 157386:tid 157643] [client 213.35.127.232:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb5AAAAYk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:37.112841 2026] [security2:error] [pid 157386:tid 157588] [client 172.182.217.32:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/test.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb5gAAAVI"] [Tue Aug 18 13:07:37.115083 2026] [security2:error] [pid 157386:tid 157573] [client 4.232.151.198:22278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb5wAAAUM"] [Tue Aug 18 13:07:37.147272 2026] [authz_core:error] [pid 157386:tid 157412] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:37.147594 2026] [authz_core:error] [pid 157386:tid 157412] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:37.191928 2026] [security2:error] [pid 157386:tid 157388] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/.well-known/"] [unique_id "aoSDSU1jzAhYHVVT1Wcb7QABJQE"] [Tue Aug 18 13:07:37.212361 2026] [security2:error] [pid 157386:tid 157617] [client 20.65.69.59:1119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/globals.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb7wAAAW8"] [Tue Aug 18 13:07:37.223494 2026] [security2:error] [pid 157386:tid 157577] [client 135.225.75.187:35655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/pp.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb8QAAAUc"] [Tue Aug 18 13:07:37.225687 2026] [security2:error] [pid 157386:tid 157622] [client 20.104.100.201:62620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/flox.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb8gAAAXQ"] [Tue Aug 18 13:07:37.250371 2026] [security2:error] [pid 157386:tid 157391] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/application_default_credentials.json"] [unique_id "aoSDSU1jzAhYHVVT1Wcb9QABHQQ"] [Tue Aug 18 13:07:37.275457 2026] [security2:error] [pid 157386:tid 157511] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/s3/public/credentials"] [unique_id "aoSDSU1jzAhYHVVT1Wcb9wABIXw"] [Tue Aug 18 13:07:37.276204 2026] [security2:error] [pid 157386:tid 157506] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/options-reading.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb-AABYnc"] [Tue Aug 18 13:07:37.311522 2026] [security2:error] [pid 157386:tid 157527] [client 20.205.121.237:11538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb-wAAARU"] [Tue Aug 18 13:07:37.338611 2026] [security2:error] [pid 157386:tid 157598] [client 68.221.73.131:30213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/insc.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb_gAAAVw"] [Tue Aug 18 13:07:37.343735 2026] [security2:error] [pid 157386:tid 157560] [client 20.171.51.14:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ig.php"] [unique_id "aoSDSU1jzAhYHVVT1Wcb_wAAATY"] [Tue Aug 18 13:07:37.392758 2026] [security2:error] [pid 157386:tid 157581] [client 132.196.30.78:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/404.php"] [unique_id "aoSDSU1jzAhYHVVT1WccAQAAAUs"] [Tue Aug 18 13:07:37.410468 2026] [security2:error] [pid 157386:tid 157571] [client 196.12.128.158:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDSU1jzAhYHVVT1WccAwAAAUE"] [Tue Aug 18 13:07:37.410606 2026] [security2:error] [pid 157386:tid 157571] [client 196.12.128.158:65410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDSU1jzAhYHVVT1WccAwAAAUE"] [Tue Aug 18 13:07:37.423301 2026] [security2:error] [pid 157386:tid 157521] [client 20.106.102.5:45219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDSU1jzAhYHVVT1WccBQAAAQ8"] [Tue Aug 18 13:07:37.429704 2026] [security2:error] [pid 157386:tid 157460] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wso.php"] [unique_id "aoSDSU1jzAhYHVVT1WccBwABMkk"] [Tue Aug 18 13:07:37.447995 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:37.448248 2026] [authz_core:error] [pid 157386:tid 157489] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:37.451552 2026] [security2:error] [pid 157386:tid 157590] [client 74.248.18.37:58029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/unknown.php"] [unique_id "aoSDSU1jzAhYHVVT1WccCgAAAVQ"] [Tue Aug 18 13:07:37.455740 2026] [lsapi:error] [pid 139043:tid 139069] [remote 201.32.74.208:56981] [host pensamentosimperfeitos.com.br] Error on sending request(GET /2026/07/07/destruiram-minha-casa/ HTTP/2.0); uri(/index.php) content-length(0): ReceiveAckHdr: timeout 300 is exceeded, referer: https://pensamentosimperfeitos.com.br/ [Tue Aug 18 13:07:37.469404 2026] [security2:error] [pid 157386:tid 157443] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ors32envu.php"] [unique_id "aoSDSU1jzAhYHVVT1WccCwABUTg"] [Tue Aug 18 13:07:37.480564 2026] [security2:error] [pid 157386:tid 157546] [client 20.116.17.175:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/222.php"] [unique_id "aoSDSU1jzAhYHVVT1WccDAAAASg"] [Tue Aug 18 13:07:37.590898 2026] [security2:error] [pid 157386:tid 157547] [client 20.151.109.219:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/qk.php"] [unique_id "aoSDSU1jzAhYHVVT1WccEAAAASk"] [Tue Aug 18 13:07:37.613047 2026] [security2:error] [pid 157386:tid 157449] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDSU1jzAhYHVVT1WccEgABXj4"] [Tue Aug 18 13:07:37.629654 2026] [security2:error] [pid 157386:tid 157625] [client 158.23.17.4:39160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ts.php"] [unique_id "aoSDSU1jzAhYHVVT1WccFQAAAXc"] [Tue Aug 18 13:07:37.635668 2026] [security2:error] [pid 157386:tid 157603] [client 172.182.217.32:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDSU1jzAhYHVVT1WccFgAAAWE"] [Tue Aug 18 13:07:37.643970 2026] [security2:error] [pid 157386:tid 157544] [client 135.225.75.187:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wqqs.php"] [unique_id "aoSDSU1jzAhYHVVT1WccGAAAASY"] [Tue Aug 18 13:07:37.645553 2026] [security2:error] [pid 157386:tid 157637] [client 20.79.204.6:5746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ors32envu.php"] [unique_id "aoSDSU1jzAhYHVVT1WccGQAAAYM"] [Tue Aug 18 13:07:37.653152 2026] [security2:error] [pid 157386:tid 157496] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/sf.php"] [unique_id "aoSDSU1jzAhYHVVT1WccGgABVW0"] [Tue Aug 18 13:07:37.680175 2026] [security2:error] [pid 157386:tid 157504] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDSU1jzAhYHVVT1WccGwABSXU"] [Tue Aug 18 13:07:37.684024 2026] [security2:error] [pid 157386:tid 157624] [client 20.226.36.136:34513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDSU1jzAhYHVVT1WccHAAAAXY"] [Tue Aug 18 13:07:37.730005 2026] [security2:error] [pid 157386:tid 157582] [client 4.232.151.198:41439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/inputs.php"] [unique_id "aoSDSU1jzAhYHVVT1WccIAAAAUw"] [Tue Aug 18 13:07:37.748207 2026] [security2:error] [pid 157386:tid 157620] [client 20.106.102.5:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDSU1jzAhYHVVT1WccIwAAAXI"] [Tue Aug 18 13:07:37.748353 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:37.748609 2026] [authz_core:error] [pid 157386:tid 157465] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:37.759256 2026] [security2:error] [pid 157386:tid 157534] [client 4.232.151.198:22284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/vx.php"] [unique_id "aoSDSU1jzAhYHVVT1WccJAAAARw"] [Tue Aug 18 13:07:37.789936 2026] [security2:error] [pid 157386:tid 157537] [client 20.116.17.175:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDSU1jzAhYHVVT1WccJQAAAR8"] [Tue Aug 18 13:07:37.808347 2026] [security2:error] [pid 157386:tid 157433] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDSU1jzAhYHVVT1WccKQABUi4"] [Tue Aug 18 13:07:37.862369 2026] [security2:error] [pid 157386:tid 157615] [client 20.250.13.23:43673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/term.php"] [unique_id "aoSDSU1jzAhYHVVT1WccLgAAAW0"] [Tue Aug 18 13:07:37.868772 2026] [security2:error] [pid 157386:tid 157422] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDSU1jzAhYHVVT1WccLwABJSM"] [Tue Aug 18 13:07:37.885743 2026] [security2:error] [pid 157386:tid 157480] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSDSU1jzAhYHVVT1WccMQABR10"] [Tue Aug 18 13:07:37.907418 2026] [security2:error] [pid 157386:tid 157456] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/index/function.php"] [unique_id "aoSDSU1jzAhYHVVT1WccMwABNEU"] [Tue Aug 18 13:07:37.912147 2026] [security2:error] [pid 157386:tid 157541] [client 5.31.227.224:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSU1jzAhYHVVT1WccNAAAASM"] [Tue Aug 18 13:07:37.916987 2026] [security2:error] [pid 157386:tid 157541] [client 5.31.227.224:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSU1jzAhYHVVT1WccNAAAASM"] [Tue Aug 18 13:07:37.939984 2026] [security2:error] [pid 157386:tid 157557] [client 20.65.69.59:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/yindu.php"] [unique_id "aoSDSU1jzAhYHVVT1WccNgAAATM"] [Tue Aug 18 13:07:37.942172 2026] [security2:error] [pid 157386:tid 157613] [client 20.65.98.162:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/coffee.php"] [unique_id "aoSDSU1jzAhYHVVT1WccNwAAAWs"] [Tue Aug 18 13:07:37.979352 2026] [security2:error] [pid 157386:tid 157424] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/aws.json"] [unique_id "aoSDSU1jzAhYHVVT1WccOQABFSU"] [Tue Aug 18 13:07:38.061810 2026] [security2:error] [pid 157386:tid 157482] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ova.php"] [unique_id "aoSDSk1jzAhYHVVT1WccQQABOF8"] [Tue Aug 18 13:07:38.062580 2026] [security2:error] [pid 157386:tid 157518] [client 135.225.75.187:24991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/clasa99.php"] [unique_id "aoSDSk1jzAhYHVVT1WccQgAAAQw"] [Tue Aug 18 13:07:38.072017 2026] [security2:error] [pid 157386:tid 157571] [client 20.106.102.5:45255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ws61.php"] [unique_id "aoSDSk1jzAhYHVVT1WccQwAAAUE"] [Tue Aug 18 13:07:38.103852 2026] [security2:error] [pid 157386:tid 157517] [client 20.116.17.175:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDSk1jzAhYHVVT1WccSQAAAQs"] [Tue Aug 18 13:07:38.108299 2026] [security2:error] [pid 157386:tid 157492] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp.php"] [unique_id "aoSDSk1jzAhYHVVT1WccSgABMmk"] [Tue Aug 18 13:07:38.118197 2026] [security2:error] [pid 157386:tid 157566] [client 213.35.127.232:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDSk1jzAhYHVVT1WccTAAAATw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:38.121278 2026] [security2:error] [pid 157386:tid 157636] [client 20.151.109.219:38628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSDSk1jzAhYHVVT1WccTQAAAYI"] [Tue Aug 18 13:07:38.126120 2026] [security2:error] [pid 157386:tid 157574] [client 172.182.217.32:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/elementra/skins/politics/plugins/security.php"] [unique_id "aoSDSk1jzAhYHVVT1WccTgAAAUQ"] [Tue Aug 18 13:07:38.136147 2026] [security2:error] [pid 157386:tid 157587] [client 20.116.17.175:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/spadex.php"] [unique_id "aoSDSk1jzAhYHVVT1WccUAAAAVE"] [Tue Aug 18 13:07:38.156552 2026] [security2:error] [pid 157386:tid 157451] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDSk1jzAhYHVVT1WccUQABcEA"] [Tue Aug 18 13:07:38.165101 2026] [security2:error] [pid 157386:tid 157441] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/edit.php"] [unique_id "aoSDSk1jzAhYHVVT1WccUwABCjY"] [Tue Aug 18 13:07:38.176127 2026] [security2:error] [pid 157386:tid 157612] [client 132.196.30.78:13610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wk/index.php"] [unique_id "aoSDSk1jzAhYHVVT1WccVQAAAWo"] [Tue Aug 18 13:07:38.235982 2026] [security2:error] [pid 157386:tid 157510] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/p.php"] [unique_id "aoSDSk1jzAhYHVVT1WccWAABOXs"] [Tue Aug 18 13:07:38.255512 2026] [security2:error] [pid 157386:tid 157600] [client 20.104.100.201:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/usr.php"] [unique_id "aoSDSk1jzAhYHVVT1WccWgAAAV4"] [Tue Aug 18 13:07:38.305520 2026] [security2:error] [pid 157386:tid 157565] [client 68.221.73.131:43481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/file.php"] [unique_id "aoSDSk1jzAhYHVVT1WccXgAAATs"] [Tue Aug 18 13:07:38.344289 2026] [security2:error] [pid 157386:tid 157560] [client 20.205.121.237:11548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.consultacomadvogado.com.br"] [uri "/wp-admin/css/mghnhykio.php"] [unique_id "aoSDSk1jzAhYHVVT1WccYgAAATY"] [Tue Aug 18 13:07:38.350828 2026] [security2:error] [pid 157386:tid 157540] [client 20.79.204.6:5709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSDSk1jzAhYHVVT1WccZAAAASI"] [Tue Aug 18 13:07:38.353846 2026] [security2:error] [pid 157386:tid 157426] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/function/function.php"] [unique_id "aoSDSk1jzAhYHVVT1WccZgABJCc"] [Tue Aug 18 13:07:38.398512 2026] [security2:error] [pid 157386:tid 157643] [client 20.106.102.5:45243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/rum.php"] [unique_id "aoSDSk1jzAhYHVVT1WccaAAAAYk"] [Tue Aug 18 13:07:38.412166 2026] [security2:error] [pid 157386:tid 157432] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/pages.php"] [unique_id "aoSDSk1jzAhYHVVT1WccagABWy0"] [Tue Aug 18 13:07:38.415770 2026] [security2:error] [pid 157386:tid 157402] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/rest-api/"] [unique_id "aoSDSk1jzAhYHVVT1WccawABbQ8"] [Tue Aug 18 13:07:38.422652 2026] [security2:error] [pid 157386:tid 157564] [client 4.232.151.198:23077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/mjq.php"] [unique_id "aoSDSk1jzAhYHVVT1WccbAAAATo"] [Tue Aug 18 13:07:38.479373 2026] [security2:error] [pid 157386:tid 157606] [client 135.225.75.187:24599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/666.php"] [unique_id "aoSDSk1jzAhYHVVT1WcccQAAAWQ"] [Tue Aug 18 13:07:38.483649 2026] [security2:error] [pid 157386:tid 157541] [client 158.23.17.4:39557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/53.php"] [unique_id "aoSDSk1jzAhYHVVT1WcccgAAASM"] [Tue Aug 18 13:07:38.491150 2026] [security2:error] [pid 157386:tid 157567] [client 20.116.17.175:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDSk1jzAhYHVVT1WcccwAAAT0"] [Tue Aug 18 13:07:38.492986 2026] [security2:error] [pid 157386:tid 157474] [remote 47.128.51.34:12130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "geracaoenergia.eng.br"] [uri "/geradores-para-casamento/"] [unique_id "aoSDSk1jzAhYHVVT1WccdAABTVc"] [Tue Aug 18 13:07:38.570322 2026] [security2:error] [pid 157386:tid 157605] [client 20.206.73.37:52897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/19.php"] [unique_id "aoSDSk1jzAhYHVVT1WccfAAAAWM"] [Tue Aug 18 13:07:38.586928 2026] [security2:error] [pid 157386:tid 157466] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/past.php"] [unique_id "aoSDSk1jzAhYHVVT1WccfQABXE8"] [Tue Aug 18 13:07:38.604321 2026] [security2:error] [pid 157386:tid 157526] [client 37.40.227.74:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSk1jzAhYHVVT1WccfgAAARQ"] [Tue Aug 18 13:07:38.605616 2026] [security2:error] [pid 157386:tid 157427] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDSk1jzAhYHVVT1WccfwABQig"] [Tue Aug 18 13:07:38.613934 2026] [security2:error] [pid 157386:tid 157526] [client 37.40.227.74:56836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSk1jzAhYHVVT1WccfgAAARQ"] [Tue Aug 18 13:07:38.620295 2026] [security2:error] [pid 157386:tid 157577] [client 172.182.217.32:25585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDSk1jzAhYHVVT1WccgAAAAUc"] [Tue Aug 18 13:07:38.639810 2026] [security2:error] [pid 157386:tid 157518] [client 20.226.36.136:25860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDSk1jzAhYHVVT1WccgQAAAQw"] [Tue Aug 18 13:07:38.652858 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:38.653108 2026] [authz_core:error] [pid 157386:tid 157478] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:38.684557 2026] [security2:error] [pid 157386:tid 157484] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDSk1jzAhYHVVT1WcchwABMmE"] [Tue Aug 18 13:07:38.722913 2026] [security2:error] [pid 157386:tid 157539] [client 20.106.102.5:45266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ze.php"] [unique_id "aoSDSk1jzAhYHVVT1WcciwAAASE"] [Tue Aug 18 13:07:38.728947 2026] [security2:error] [pid 157386:tid 157633] [client 74.248.18.37:58039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-json-ajax-session.php"] [unique_id "aoSDSk1jzAhYHVVT1WccjQAAAX8"] [Tue Aug 18 13:07:38.729261 2026] [security2:error] [pid 157386:tid 157610] [client 20.171.51.14:30358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ta.php"] [unique_id "aoSDSk1jzAhYHVVT1WccjgAAAWg"] [Tue Aug 18 13:07:38.776904 2026] [security2:error] [pid 157386:tid 157557] [client 132.196.30.78:20296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/about.php"] [unique_id "aoSDSk1jzAhYHVVT1WcckgAAATM"] [Tue Aug 18 13:07:38.787087 2026] [security2:error] [pid 157386:tid 157514] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/php.php"] [unique_id "aoSDSk1jzAhYHVVT1WcckwABgX8"] [Tue Aug 18 13:07:38.819080 2026] [security2:error] [pid 157386:tid 157580] [client 20.116.17.175:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/srontol.php"] [unique_id "aoSDSk1jzAhYHVVT1WcclAAAAUo"] [Tue Aug 18 13:07:38.859271 2026] [security2:error] [pid 157386:tid 157404] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDSk1jzAhYHVVT1WccmAABZxE"] [Tue Aug 18 13:07:38.894642 2026] [security2:error] [pid 157386:tid 157592] [client 20.151.109.219:31376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fs.php"] [unique_id "aoSDSk1jzAhYHVVT1WccmwAAAVY"] [Tue Aug 18 13:07:38.901334 2026] [security2:error] [pid 157386:tid 157554] [client 135.225.75.187:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/thui.php"] [unique_id "aoSDSk1jzAhYHVVT1WccnAAAATA"] [Tue Aug 18 13:07:38.904178 2026] [security2:error] [pid 157386:tid 157561] [client 49.37.150.8:53646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSk1jzAhYHVVT1WccnQAAATc"] [Tue Aug 18 13:07:38.904305 2026] [security2:error] [pid 157386:tid 157561] [client 49.37.150.8:53646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDSk1jzAhYHVVT1WccnQAAATc"] [Tue Aug 18 13:07:38.946027 2026] [security2:error] [pid 157386:tid 157497] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-good.php"] [unique_id "aoSDSk1jzAhYHVVT1WccngABU24"] [Tue Aug 18 13:07:38.955405 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:38.955673 2026] [authz_core:error] [pid 157386:tid 157479] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:39.001980 2026] [security2:error] [pid 157386:tid 157612] [client 20.79.204.6:5997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ova.php"] [unique_id "aoSDS01jzAhYHVVT1WccogAAAWo"] [Tue Aug 18 13:07:39.013050 2026] [security2:error] [pid 157386:tid 157576] [client 20.65.69.59:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/sxx.php"] [unique_id "aoSDS01jzAhYHVVT1WccpAAAAUY"] [Tue Aug 18 13:07:39.022236 2026] [security2:error] [pid 157386:tid 157414] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDS01jzAhYHVVT1WccpQABHBs"] [Tue Aug 18 13:07:39.028513 2026] [security2:error] [pid 157386:tid 157614] [client 20.226.36.136:41555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDS01jzAhYHVVT1WccpgAAAWw"] [Tue Aug 18 13:07:39.031803 2026] [security2:error] [pid 157386:tid 157624] [client 223.185.37.47:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDS01jzAhYHVVT1WccpwAAAXY"] [Tue Aug 18 13:07:39.031913 2026] [security2:error] [pid 157386:tid 157624] [client 223.185.37.47:17285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDS01jzAhYHVVT1WccpwAAAXY"] [Tue Aug 18 13:07:39.040524 2026] [security2:error] [pid 157386:tid 157542] [client 20.104.100.201:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDS01jzAhYHVVT1WccqAAAASQ"] [Tue Aug 18 13:07:39.050301 2026] [security2:error] [pid 157386:tid 157531] [client 20.106.102.5:45208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/gjm.php"] [unique_id "aoSDS01jzAhYHVVT1WccqgAAARk"] [Tue Aug 18 13:07:39.060598 2026] [security2:error] [pid 157386:tid 157643] [client 52.173.121.69:28290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDS01jzAhYHVVT1WccqwAAAYk"] [Tue Aug 18 13:07:39.060629 2026] [security2:error] [pid 157386:tid 157394] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/php8.php"] [unique_id "aoSDS01jzAhYHVVT1WccrAABHwc"] [Tue Aug 18 13:07:39.068006 2026] [security2:error] [pid 157386:tid 157585] [client 158.23.17.4:20619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lq.php"] [unique_id "aoSDS01jzAhYHVVT1WccrQAAAU8"] [Tue Aug 18 13:07:39.076754 2026] [security2:error] [pid 157386:tid 157597] [client 20.116.17.175:20386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/xwpg.php"] [unique_id "aoSDS01jzAhYHVVT1WccrgAAAVs"] [Tue Aug 18 13:07:39.078736 2026] [security2:error] [pid 157386:tid 157569] [client 4.232.151.198:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-includes/PHPMailer/about.php"] [unique_id "aoSDS01jzAhYHVVT1WccrwAAAT8"] [Tue Aug 18 13:07:39.106577 2026] [security2:error] [pid 157386:tid 157490] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/ok.php"] [unique_id "aoSDS01jzAhYHVVT1WccsgABJWc"] [Tue Aug 18 13:07:39.111800 2026] [security2:error] [pid 157386:tid 157568] [client 172.182.217.32:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/login.php"] [unique_id "aoSDS01jzAhYHVVT1WcctAAAAT4"] [Tue Aug 18 13:07:39.112553 2026] [security2:error] [pid 157386:tid 157521] [client 86.120.159.145:22923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDS01jzAhYHVVT1WcctQAAAQ8"] [Tue Aug 18 13:07:39.112639 2026] [security2:error] [pid 157386:tid 157521] [client 86.120.159.145:22923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDS01jzAhYHVVT1WcctQAAAQ8"] [Tue Aug 18 13:07:39.146213 2026] [security2:error] [pid 157386:tid 157581] [client 213.35.127.232:52473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDS01jzAhYHVVT1WcctwAAAUs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:39.226297 2026] [security2:error] [pid 157386:tid 157501] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/js/widgets/"] [unique_id "aoSDS01jzAhYHVVT1WccuwABXHI"] [Tue Aug 18 13:07:39.237677 2026] [security2:error] [pid 157386:tid 157445] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/plugins.php"] [unique_id "aoSDS01jzAhYHVVT1WccvQABQjo"] [Tue Aug 18 13:07:39.242683 2026] [security2:error] [pid 157386:tid 157526] [client 68.221.73.131:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/dex.php"] [unique_id "aoSDS01jzAhYHVVT1WccvgAAARQ"] [Tue Aug 18 13:07:39.258346 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:39.258786 2026] [authz_core:error] [pid 157386:tid 157476] [remote 216.73.216.206:31023] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:39.318237 2026] [security2:error] [pid 157386:tid 157556] [client 135.225.75.187:23856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/agg.php"] [unique_id "aoSDS01jzAhYHVVT1WccxAAAATI"] [Tue Aug 18 13:07:39.319548 2026] [security2:error] [pid 157386:tid 157636] [client 20.171.51.14:19659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/34.php"] [unique_id "aoSDS01jzAhYHVVT1WccxQAAAYI"] [Tue Aug 18 13:07:39.320701 2026] [security2:error] [pid 157386:tid 157553] [client 20.116.17.175:64970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/file5.php"] [unique_id "aoSDS01jzAhYHVVT1WccxgAAAS8"] [Tue Aug 18 13:07:39.347976 2026] [security2:error] [pid 157386:tid 157551] [client 132.196.30.78:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/term.php"] [unique_id "aoSDS01jzAhYHVVT1WccyQAAAS0"] [Tue Aug 18 13:07:39.412027 2026] [security2:error] [pid 157386:tid 157532] [client 74.248.18.37:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/litespeed.php"] [unique_id "aoSDS01jzAhYHVVT1WccywAAARo"] [Tue Aug 18 13:07:39.594644 2026] [http2:info] [pid 167459:tid 167459] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 13:07:39.617594 2026] [security2:error] [pid 167459:tid 167589] [client 20.106.102.5:45268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/new4.php"] [unique_id "aoSDS2r_JutbFb-8svrsDgAAAY8"] [Tue Aug 18 13:07:39.617591 2026] [security2:error] [pid 167459:tid 167591] [client 20.226.36.136:34137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDS2r_JutbFb-8svrsDwAAAZE"] [Tue Aug 18 13:07:39.619689 2026] [security2:error] [pid 167459:tid 167593] [client 158.23.17.4:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/you.php"] [unique_id "aoSDS2r_JutbFb-8svrsEAAAAZM"] [Tue Aug 18 13:07:39.619696 2026] [security2:error] [pid 167459:tid 167595] [client 20.116.17.175:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/dex.php"] [unique_id "aoSDS2r_JutbFb-8svrsEQAAAZU"] [Tue Aug 18 13:07:39.638597 2026] [security2:error] [pid 167459:tid 167606] [client 20.151.109.219:58353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/rb.php"] [unique_id "aoSDS2r_JutbFb-8svrsEwAAAaA"] [Tue Aug 18 13:07:39.679258 2026] [security2:error] [pid 167459:tid 167614] [client 20.116.17.175:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/yup.php"] [unique_id "aoSDS2r_JutbFb-8svrsFwAAAag"] [Tue Aug 18 13:07:39.739245 2026] [security2:error] [pid 167459:tid 167620] [client 135.225.75.187:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/erty.php"] [unique_id "aoSDS2r_JutbFb-8svrsGgAAAa4"] [Tue Aug 18 13:07:39.762558 2026] [security2:error] [pid 167459:tid 167464] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "aoSDS2r_JutbFb-8svrsGwABsQQ"] [Tue Aug 18 13:07:39.811335 2026] [security2:error] [pid 167459:tid 167592] [client 172.182.217.32:4144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/plugin-install.php"] [unique_id "aoSDS2r_JutbFb-8svrsHQAAAZI"] [Tue Aug 18 13:07:39.811466 2026] [security2:error] [pid 167459:tid 167465] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/post.php"] [unique_id "aoSDS2r_JutbFb-8svrsHgABpQU"] [Tue Aug 18 13:07:39.823322 2026] [security2:error] [pid 167459:tid 167594] [client 20.79.204.6:5752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/p.php"] [unique_id "aoSDS2r_JutbFb-8svrsIAAAAZQ"] [Tue Aug 18 13:07:39.837624 2026] [security2:error] [pid 167459:tid 167599] [client 4.232.151.198:5895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/twentytwelve/inc/.php"] [unique_id "aoSDS2r_JutbFb-8svrsJQAAAZk"] [Tue Aug 18 13:07:39.886779 2026] [security2:error] [pid 167459:tid 167639] [client 20.104.100.201:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/op.php"] [unique_id "aoSDS2r_JutbFb-8svrsKQAAAcE"] [Tue Aug 18 13:07:39.940632 2026] [security2:error] [pid 167459:tid 167643] [client 20.106.102.5:45201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-act.php"] [unique_id "aoSDS2r_JutbFb-8svrsMAAAAcU"] [Tue Aug 18 13:07:39.957782 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDS2r_JutbFb-8svrsMQAAAcc"] [Tue Aug 18 13:07:39.984245 2026] [security2:error] [pid 167459:tid 167480] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/r.php"] [unique_id "aoSDS2r_JutbFb-8svrsNAABzRQ"] [Tue Aug 18 13:07:39.990217 2026] [security2:error] [pid 167459:tid 167652] [client 20.104.100.201:17400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/css/database.php"] [unique_id "aoSDS2r_JutbFb-8svrsNQAAAc4"] [Tue Aug 18 13:07:39.992937 2026] [security2:error] [pid 167459:tid 167653] [client 158.23.17.4:38339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ez.php"] [unique_id "aoSDS2r_JutbFb-8svrsNwAAAc8"] [Tue Aug 18 13:07:40.002038 2026] [security2:error] [pid 167459:tid 167655] [client 20.116.17.175:58227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDTGr_JutbFb-8svrsOAAAAdE"] [Tue Aug 18 13:07:40.025008 2026] [security2:error] [pid 167459:tid 167619] [client 132.196.30.78:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDTGr_JutbFb-8svrsOwAAAa0"] [Tue Aug 18 13:07:40.025220 2026] [security2:error] [pid 167459:tid 167483] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/tes.php"] [unique_id "aoSDTGr_JutbFb-8svrsPAAB1Rc"] [Tue Aug 18 13:07:40.158945 2026] [security2:error] [pid 167459:tid 167490] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/radio.php"] [unique_id "aoSDTGr_JutbFb-8svrsRQAB6h4"] [Tue Aug 18 13:07:40.161771 2026] [authz_core:error] [pid 167459:tid 167489] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:40.162043 2026] [authz_core:error] [pid 167459:tid 167489] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:40.165518 2026] [security2:error] [pid 167459:tid 167682] [client 135.225.75.187:24613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/mini.php"] [unique_id "aoSDTGr_JutbFb-8svrsRgAAAew"] [Tue Aug 18 13:07:40.169248 2026] [security2:error] [pid 167459:tid 167635] [client 213.35.127.232:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDTGr_JutbFb-8svrsRwAAAb0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:40.189525 2026] [security2:error] [pid 167459:tid 167492] [remote 20.163.43.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.novosares.com.br"] [uri "/item.php"] [unique_id "aoSDTGr_JutbFb-8svrsSgABsCA"] [Tue Aug 18 13:07:40.195864 2026] [security2:error] [pid 167459:tid 167650] [client 74.248.18.37:27891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/un2.php"] [unique_id "aoSDTGr_JutbFb-8svrsTAAAAcw"] [Tue Aug 18 13:07:40.235258 2026] [security2:error] [pid 167459:tid 167495] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/app-config.json"] [unique_id "aoSDTGr_JutbFb-8svrsTwAB8iM"] [Tue Aug 18 13:07:40.254046 2026] [security2:error] [pid 167459:tid 167496] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/files/index.php"] [unique_id "aoSDTGr_JutbFb-8svrsUAAB8yQ"] [Tue Aug 18 13:07:40.254531 2026] [security2:error] [pid 167459:tid 167497] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDTGr_JutbFb-8svrsUQAB3CU"] [Tue Aug 18 13:07:40.256145 2026] [security2:error] [pid 167459:tid 167494] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDTGr_JutbFb-8svrsTgAB8SI"] [Tue Aug 18 13:07:40.256347 2026] [security2:error] [pid 167459:tid 167687] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDTGr_JutbFb-8svrsTgAB8SI"] [Tue Aug 18 13:07:40.267433 2026] [security2:error] [pid 167459:tid 167693] [client 20.106.102.5:45193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/grsiuk.php"] [unique_id "aoSDTGr_JutbFb-8svrsVAAAAfc"] [Tue Aug 18 13:07:40.300066 2026] [security2:error] [pid 167459:tid 167697] [client 68.221.73.131:8155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/key.php"] [unique_id "aoSDTGr_JutbFb-8svrsWAAAAfs"] [Tue Aug 18 13:07:40.301490 2026] [security2:error] [pid 167459:tid 167674] [client 172.182.217.32:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/test.php"] [unique_id "aoSDTGr_JutbFb-8svrsWgAAAeQ"] [Tue Aug 18 13:07:40.333611 2026] [security2:error] [pid 167459:tid 167699] [client 20.116.17.175:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-the.php"] [unique_id "aoSDTGr_JutbFb-8svrsXQAAAf0"] [Tue Aug 18 13:07:40.335686 2026] [security2:error] [pid 167459:tid 167701] [client 20.65.69.59:1763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/settings.php"] [unique_id "aoSDTGr_JutbFb-8svrsXgAAAf8"] [Tue Aug 18 13:07:40.337745 2026] [security2:error] [pid 167459:tid 167505] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSDTGr_JutbFb-8svrsXwACAC0"] [Tue Aug 18 13:07:40.348394 2026] [security2:error] [pid 167459:tid 167703] [client 20.65.98.162:59153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDTGr_JutbFb-8svrsYAAAAgE"] [Tue Aug 18 13:07:40.459164 2026] [security2:error] [pid 167459:tid 167604] [client 20.116.17.175:20276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/xyn.php"] [unique_id "aoSDTGr_JutbFb-8svrsbgAAAZ4"] [Tue Aug 18 13:07:40.462651 2026] [security2:error] [pid 167459:tid 167691] [client 4.232.151.198:23047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wsa.php"] [unique_id "aoSDTGr_JutbFb-8svrsbwAAAfU"] [Tue Aug 18 13:07:40.495895 2026] [security2:error] [pid 167459:tid 167518] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDTGr_JutbFb-8svrscwABqzo"] [Tue Aug 18 13:07:40.496699 2026] [security2:error] [pid 167459:tid 167620] [client 20.151.109.219:42788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/37.php"] [unique_id "aoSDTGr_JutbFb-8svrsdAAAAa4"] [Tue Aug 18 13:07:40.515965 2026] [security2:error] [pid 167459:tid 167626] [client 20.226.36.136:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDTGr_JutbFb-8svrsdwAAAbQ"] [Tue Aug 18 13:07:40.537831 2026] [security2:error] [pid 167459:tid 167520] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/red.php"] [unique_id "aoSDTGr_JutbFb-8svrseAABtjw"] [Tue Aug 18 13:07:40.573306 2026] [security2:error] [pid 167459:tid 167707] [client 20.79.204.6:5702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/pages.php"] [unique_id "aoSDTGr_JutbFb-8svrsewAAAgU"] [Tue Aug 18 13:07:40.581869 2026] [security2:error] [pid 167459:tid 167631] [client 135.225.75.187:24597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sid3.php"] [unique_id "aoSDTGr_JutbFb-8svrsfQAAAbk"] [Tue Aug 18 13:07:40.584138 2026] [security2:error] [pid 167459:tid 167612] [client 20.250.13.23:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDTGr_JutbFb-8svrsfwAAAaY"] [Tue Aug 18 13:07:40.594952 2026] [security2:error] [pid 167459:tid 167599] [client 20.106.102.5:45185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/h.php"] [unique_id "aoSDTGr_JutbFb-8svrshAAAAZk"] [Tue Aug 18 13:07:40.615611 2026] [security2:error] [pid 167459:tid 167639] [client 158.23.17.4:39122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/asus.php"] [unique_id "aoSDTGr_JutbFb-8svrshwAAAcE"] [Tue Aug 18 13:07:40.621074 2026] [security2:error] [pid 167459:tid 167529] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.openai/config.json"] [unique_id "aoSDTGr_JutbFb-8svrsiAABj0U"] [Tue Aug 18 13:07:40.698702 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:53347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/accesson.php"] [unique_id "aoSDTGr_JutbFb-8svrsjwAAAcc"] [Tue Aug 18 13:07:40.702421 2026] [security2:error] [pid 167459:tid 167597] [client 132.196.30.78:13097] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "anmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSDTGr_JutbFb-8svrskAAAAZc"] [Tue Aug 18 13:07:40.702511 2026] [security2:error] [pid 167459:tid 167597] [client 132.196.30.78:13097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/1.php"] [unique_id "aoSDTGr_JutbFb-8svrskAAAAZc"] [Tue Aug 18 13:07:40.726313 2026] [security2:error] [pid 167459:tid 167539] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/release.php"] [unique_id "aoSDTGr_JutbFb-8svrslQABzk8"] [Tue Aug 18 13:07:40.729424 2026] [security2:error] [pid 167459:tid 167653] [client 20.116.17.175:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDTGr_JutbFb-8svrslgAAAc8"] [Tue Aug 18 13:07:40.753180 2026] [security2:error] [pid 167459:tid 167540] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/images/images/about.php"] [unique_id "aoSDTGr_JutbFb-8svrslwABwFA"] [Tue Aug 18 13:07:40.792601 2026] [security2:error] [pid 167459:tid 167627] [client 172.182.217.32:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "aoSDTGr_JutbFb-8svrsnAAAAbU"] [Tue Aug 18 13:07:40.847747 2026] [security2:error] [pid 167459:tid 167675] [client 20.151.109.219:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/md.php"] [unique_id "aoSDTGr_JutbFb-8svrsoAAAAeU"] [Tue Aug 18 13:07:40.898854 2026] [security2:error] [pid 167459:tid 167546] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/reop3.php"] [unique_id "aoSDTGr_JutbFb-8svrspQAB7lY"] [Tue Aug 18 13:07:40.903736 2026] [security2:error] [pid 167459:tid 167667] [client 18.192.166.72:26066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.petceu.com.br"] [uri "/index.php"] [unique_id "aoSDTGr_JutbFb-8svrsVgAAAd0"], referer: https://www.petceu.com.br [Tue Aug 18 13:07:40.920607 2026] [security2:error] [pid 167459:tid 167688] [client 20.106.102.5:45276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/koiy.php"] [unique_id "aoSDTGr_JutbFb-8svrsrQAAAfI"] [Tue Aug 18 13:07:40.972386 2026] [security2:error] [pid 167459:tid 167658] [client 74.248.18.37:19660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/po8sa.php"] [unique_id "aoSDTGr_JutbFb-8svrssAAAAdQ"] [Tue Aug 18 13:07:40.997483 2026] [security2:error] [pid 167459:tid 167674] [client 135.225.75.187:23824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/moon.php"] [unique_id "aoSDTGr_JutbFb-8svrstQAAAeQ"] [Tue Aug 18 13:07:41.025262 2026] [security2:error] [pid 167459:tid 167701] [client 20.116.17.175:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/xwpg.php"] [unique_id "aoSDTWr_JutbFb-8svrsuAAAAf8"] [Tue Aug 18 13:07:41.044701 2026] [security2:error] [pid 167459:tid 167700] [client 20.171.51.14:39784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/he.php"] [unique_id "aoSDTWr_JutbFb-8svrsuQAAAf4"] [Tue Aug 18 13:07:41.047244 2026] [security2:error] [pid 167459:tid 167703] [client 52.173.121.69:28344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDTWr_JutbFb-8svrsuwAAAgE"] [Tue Aug 18 13:07:41.073916 2026] [security2:error] [pid 167459:tid 167558] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/robots.php"] [unique_id "aoSDTWr_JutbFb-8svrsvgACCGI"] [Tue Aug 18 13:07:41.083999 2026] [security2:error] [pid 167459:tid 167709] [client 20.104.100.201:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/1xmomo.php"] [unique_id "aoSDTWr_JutbFb-8svrswQAAAgc"] [Tue Aug 18 13:07:41.091888 2026] [security2:error] [pid 167459:tid 167561] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ms-edit.php"] [unique_id "aoSDTWr_JutbFb-8svrswwACC2U"] [Tue Aug 18 13:07:41.104005 2026] [security2:error] [pid 167459:tid 167683] [client 4.232.151.198:23090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/add.php"] [unique_id "aoSDTWr_JutbFb-8svrsxAAAAe0"] [Tue Aug 18 13:07:41.123056 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:38391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/22.php"] [unique_id "aoSDTWr_JutbFb-8svrsxQAAAg4"] [Tue Aug 18 13:07:41.152926 2026] [security2:error] [pid 167459:tid 167593] [client 68.221.73.131:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/kir.php"] [unique_id "aoSDTWr_JutbFb-8svrsyAAAAZM"] [Tue Aug 18 13:07:41.181711 2026] [security2:error] [pid 167459:tid 167673] [client 213.35.127.232:52907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDTWr_JutbFb-8svrsygAAAeM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:41.218876 2026] [security2:error] [pid 167459:tid 167614] [client 20.151.109.219:36297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/iy.php"] [unique_id "aoSDTWr_JutbFb-8svrszQAAAag"] [Tue Aug 18 13:07:41.246702 2026] [security2:error] [pid 167459:tid 167565] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/root.php"] [unique_id "aoSDTWr_JutbFb-8svrszgABm2k"] [Tue Aug 18 13:07:41.246782 2026] [security2:error] [pid 167459:tid 167620] [client 20.106.102.5:45271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fff.php"] [unique_id "aoSDTWr_JutbFb-8svrszwAAAa4"] [Tue Aug 18 13:07:41.283364 2026] [security2:error] [pid 167459:tid 167715] [client 132.196.30.78:13076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/alfa.php"] [unique_id "aoSDTWr_JutbFb-8svrs0QAAAg0"] [Tue Aug 18 13:07:41.288133 2026] [security2:error] [pid 167459:tid 167624] [client 20.65.69.59:1333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/spip.php"] [unique_id "aoSDTWr_JutbFb-8svrs0gAAAbI"] [Tue Aug 18 13:07:41.288238 2026] [security2:error] [pid 167459:tid 167591] [client 172.182.217.32:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/themes/index.php"] [unique_id "aoSDTWr_JutbFb-8svrs0wAAAZE"] [Tue Aug 18 13:07:41.330585 2026] [security2:error] [pid 167459:tid 167567] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/rip.php"] [unique_id "aoSDTWr_JutbFb-8svrs1QABpWs"] [Tue Aug 18 13:07:41.337615 2026] [security2:error] [pid 167459:tid 167615] [client 20.116.17.175:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/dex.php"] [unique_id "aoSDTWr_JutbFb-8svrs1gAAAak"] [Tue Aug 18 13:07:41.381812 2026] [security2:error] [pid 167459:tid 167606] [client 20.79.204.6:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/past.php"] [unique_id "aoSDTWr_JutbFb-8svrs2gAAAaA"] [Tue Aug 18 13:07:41.413941 2026] [security2:error] [pid 167459:tid 167644] [client 135.225.75.187:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ms.php"] [unique_id "aoSDTWr_JutbFb-8svrs3QAAAcY"] [Tue Aug 18 13:07:41.416136 2026] [security2:error] [pid 167459:tid 167632] [client 3.79.134.69:55606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.capecodcleaningservice.com"] [uri "/index.php"] [unique_id "aoSDTGr_JutbFb-8svrsmgAAAbo"], referer: https://www.capecodcleaningservice.com [Tue Aug 18 13:07:41.419522 2026] [security2:error] [pid 167459:tid 167625] [client 104.209.144.33:31282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDTWr_JutbFb-8svrs3gAAAbM"] [Tue Aug 18 13:07:41.424694 2026] [security2:error] [pid 167459:tid 167572] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/rrr.php"] [unique_id "aoSDTWr_JutbFb-8svrs3wABl3A"] [Tue Aug 18 13:07:41.564886 2026] [security2:error] [pid 167459:tid 167582] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/uploads/"] [unique_id "aoSDTWr_JutbFb-8svrs6QABtXo"] [Tue Aug 18 13:07:41.577236 2026] [security2:error] [pid 167459:tid 167664] [client 20.106.102.5:45206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/pouhg.php"] [unique_id "aoSDTWr_JutbFb-8svrs6gAAAdo"] [Tue Aug 18 13:07:41.584040 2026] [security2:error] [pid 167459:tid 167662] [client 158.23.17.4:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/zs.php"] [unique_id "aoSDTWr_JutbFb-8svrs6wAAAdg"] [Tue Aug 18 13:07:41.597853 2026] [security2:error] [pid 167459:tid 167583] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/s.php"] [unique_id "aoSDTWr_JutbFb-8svrs7AAB23s"] [Tue Aug 18 13:07:41.615447 2026] [security2:error] [pid 167459:tid 167671] [client 20.104.100.201:53352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/av.php"] [unique_id "aoSDTWr_JutbFb-8svrs7gAAAeE"] [Tue Aug 18 13:07:41.674365 2026] [security2:error] [pid 167459:tid 167684] [client 20.116.17.175:20318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDTWr_JutbFb-8svrs8gAAAe4"] [Tue Aug 18 13:07:41.725133 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.18.37:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/lmfi.php"] [unique_id "aoSDTWr_JutbFb-8svrs9QAAAc4"] [Tue Aug 18 13:07:41.754490 2026] [security2:error] [pid 167459:tid 167666] [client 20.226.36.136:37199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDTWr_JutbFb-8svrs9wAAAdw"] [Tue Aug 18 13:07:41.758477 2026] [security2:error] [pid 167459:tid 167689] [client 20.151.109.219:22932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/og.php"] [unique_id "aoSDTWr_JutbFb-8svrs-AAAAfM"] [Tue Aug 18 13:07:41.777837 2026] [security2:error] [pid 167459:tid 167600] [client 4.232.151.198:22310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/cron.php"] [unique_id "aoSDTWr_JutbFb-8svrs_gAAAZo"] [Tue Aug 18 13:07:41.795987 2026] [autoindex:error] [pid 167459:tid 167672] [client 172.182.217.32:4130] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:41.796292 2026] [security2:error] [pid 167459:tid 167700] [client 20.171.51.14:2127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/gz.php"] [unique_id "aoSDTWr_JutbFb-8svrtAQAAAf4"] [Tue Aug 18 13:07:41.804444 2026] [security2:error] [pid 167459:tid 167475] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmlrpc.php"] [unique_id "aoSDTWr_JutbFb-8svrtAwACAQ8"] [Tue Aug 18 13:07:41.807652 2026] [security2:error] [pid 167459:tid 167476] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/s93.php"] [unique_id "aoSDTWr_JutbFb-8svrtBAAB9BA"] [Tue Aug 18 13:07:41.831871 2026] [security2:error] [pid 167459:tid 167642] [client 135.225.75.187:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wsws.php"] [unique_id "aoSDTWr_JutbFb-8svrtBgAAAcQ"] [Tue Aug 18 13:07:41.901172 2026] [security2:error] [pid 167459:tid 167683] [client 20.106.102.5:45236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/moon3.php"] [unique_id "aoSDTWr_JutbFb-8svrtCgAAAe0"] [Tue Aug 18 13:07:41.923838 2026] [security2:error] [pid 167459:tid 167651] [client 149.34.210.141:50271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDTWr_JutbFb-8svrtDAAAAc0"] [Tue Aug 18 13:07:41.932687 2026] [security2:error] [pid 167459:tid 167595] [client 20.116.17.175:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/xyn.php"] [unique_id "aoSDTWr_JutbFb-8svrtDQAAAZU"] [Tue Aug 18 13:07:41.943942 2026] [security2:error] [pid 167459:tid 167667] [client 132.196.30.78:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/edit.php"] [unique_id "aoSDTWr_JutbFb-8svrtDgAAAd0"] [Tue Aug 18 13:07:41.957551 2026] [security2:error] [pid 167459:tid 167604] [client 20.206.73.37:52877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/133.php"] [unique_id "aoSDTWr_JutbFb-8svrtDwAAAZ4"] [Tue Aug 18 13:07:41.958599 2026] [security2:error] [pid 167459:tid 167598] [client 172.182.217.32:4130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/twentytwentyfour/patterns/alfa-rex.php"] [unique_id "aoSDTWr_JutbFb-8svrtEAAAAZg"] [Tue Aug 18 13:07:41.984256 2026] [security2:error] [pid 167459:tid 167462] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/server.php"] [unique_id "aoSDTWr_JutbFb-8svrtEgAB-wI"] [Tue Aug 18 13:07:41.989597 2026] [security2:error] [pid 167459:tid 167691] [client 68.221.73.131:21040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/nofile.php"] [unique_id "aoSDTWr_JutbFb-8svrtEwAAAfU"] [Tue Aug 18 13:07:42.009775 2026] [security2:error] [pid 167459:tid 167608] [client 20.104.100.201:54022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/privdayz.php"] [unique_id "aoSDTmr_JutbFb-8svrtFgAAAaI"] [Tue Aug 18 13:07:42.034950 2026] [security2:error] [pid 167459:tid 167482] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/moon.php"] [unique_id "aoSDTmr_JutbFb-8svrtGAABqBY"] [Tue Aug 18 13:07:42.039301 2026] [security2:error] [pid 167459:tid 167670] [client 52.28.162.93:63728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rhsolucionar.com.br"] [uri "/index.php"] [unique_id "aoSDTWr_JutbFb-8svrstwAAAeA"], referer: https://www.rhsolucionar.com.br/ [Tue Aug 18 13:07:42.074971 2026] [security2:error] [pid 167459:tid 167699] [client 158.23.17.4:4615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/iz.php"] [unique_id "aoSDTmr_JutbFb-8svrtGQAAAf0"] [Tue Aug 18 13:07:42.156266 2026] [security2:error] [pid 167459:tid 167484] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/settings.php"] [unique_id "aoSDTmr_JutbFb-8svrtHAABpRg"] [Tue Aug 18 13:07:42.186906 2026] [security2:error] [pid 167459:tid 167651] [client 149.34.210.141:50271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDTWr_JutbFb-8svrtDAAAAc0"] [Tue Aug 18 13:07:42.197531 2026] [security2:error] [pid 167459:tid 167709] [client 213.35.127.232:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDTmr_JutbFb-8svrtHwAAAgc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:42.231684 2026] [security2:error] [pid 167459:tid 167606] [client 20.106.102.5:45227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/opts.php"] [unique_id "aoSDTmr_JutbFb-8svrtIQAAAaA"] [Tue Aug 18 13:07:42.250233 2026] [security2:error] [pid 167459:tid 167640] [client 135.225.75.187:35653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/motu.php"] [unique_id "aoSDTmr_JutbFb-8svrtIwAAAcI"] [Tue Aug 18 13:07:42.266475 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:42.266774 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:42.268129 2026] [security2:error] [pid 167459:tid 167469] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/cache.php"] [unique_id "aoSDTmr_JutbFb-8svrtJQABugk"] [Tue Aug 18 13:07:42.302296 2026] [security2:error] [pid 167459:tid 167593] [client 20.79.204.6:5966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/php.php"] [unique_id "aoSDTmr_JutbFb-8svrtKAAAAZM"] [Tue Aug 18 13:07:42.319023 2026] [fcgid:warn] [pid 167459:tid 167649] (70014)End of file found: [client 66.132.172.184:52834] mod_fcgid: can't get data from http client [Tue Aug 18 13:07:42.319795 2026] [security2:error] [pid 167459:tid 167623] [client 20.116.17.175:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDTmr_JutbFb-8svrtKgAAAbE"] [Tue Aug 18 13:07:42.328693 2026] [security2:error] [pid 167459:tid 167471] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/sf.php"] [unique_id "aoSDTmr_JutbFb-8svrtKwAB3ws"] [Tue Aug 18 13:07:42.348303 2026] [security2:error] [pid 167459:tid 167599] [client 20.206.73.37:46955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/file2.php"] [unique_id "aoSDTmr_JutbFb-8svrtLQAAAZk"] [Tue Aug 18 13:07:42.368536 2026] [security2:error] [pid 167459:tid 167631] [client 74.248.18.37:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/wp-apxupx.php"] [unique_id "aoSDTmr_JutbFb-8svrtMQAAAbk"] [Tue Aug 18 13:07:42.395891 2026] [security2:error] [pid 167459:tid 167613] [client 20.104.100.201:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/txets.php"] [unique_id "aoSDTmr_JutbFb-8svrtNgAAAac"] [Tue Aug 18 13:07:42.482498 2026] [security2:error] [pid 167459:tid 167639] [client 4.232.151.198:5891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/we.php"] [unique_id "aoSDTmr_JutbFb-8svrtPAAAAcE"] [Tue Aug 18 13:07:42.497864 2026] [security2:error] [pid 167459:tid 167648] [client 132.196.30.78:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/elp.php"] [unique_id "aoSDTmr_JutbFb-8svrtPgAAAco"] [Tue Aug 18 13:07:42.501366 2026] [security2:error] [pid 167459:tid 167487] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/shell.php"] [unique_id "aoSDTmr_JutbFb-8svrtPwABzhs"] [Tue Aug 18 13:07:42.515958 2026] [security2:error] [pid 167459:tid 167466] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSDTmr_JutbFb-8svrtQAAB8AY"] [Tue Aug 18 13:07:42.526068 2026] [security2:error] [pid 167459:tid 167688] [client 20.226.36.136:38471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDTmr_JutbFb-8svrtQQAAAfI"] [Tue Aug 18 13:07:42.558825 2026] [security2:error] [pid 167459:tid 167696] [client 20.106.102.5:45213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/zwq13.php"] [unique_id "aoSDTmr_JutbFb-8svrtRgAAAfo"] [Tue Aug 18 13:07:42.570284 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:42.570559 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:42.590656 2026] [security2:error] [pid 167459:tid 167700] [client 158.23.17.4:39595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/se.php"] [unique_id "aoSDTmr_JutbFb-8svrtSwAAAf4"] [Tue Aug 18 13:07:42.615797 2026] [security2:error] [pid 167459:tid 167703] [client 20.116.17.175:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-good.php"] [unique_id "aoSDTmr_JutbFb-8svrtTAAAAgE"] [Tue Aug 18 13:07:42.671464 2026] [security2:error] [pid 167459:tid 167714] [client 135.225.75.187:23000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fff.php"] [unique_id "aoSDTmr_JutbFb-8svrtUgAAAgw"] [Tue Aug 18 13:07:42.674839 2026] [security2:error] [pid 167459:tid 167501] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/shiny.php"] [unique_id "aoSDTmr_JutbFb-8svrtUwABtCk"] [Tue Aug 18 13:07:42.740526 2026] [security2:error] [pid 167459:tid 167509] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/vendor/"] [unique_id "aoSDTmr_JutbFb-8svrtWQAB5DE"] [Tue Aug 18 13:07:42.823407 2026] [security2:error] [pid 167459:tid 167691] [client 20.104.100.201:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/kj.php"] [unique_id "aoSDTmr_JutbFb-8svrtYAAAAfU"] [Tue Aug 18 13:07:42.848043 2026] [security2:error] [pid 167459:tid 167513] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/sid3.php"] [unique_id "aoSDTmr_JutbFb-8svrtYQABozU"] [Tue Aug 18 13:07:42.885102 2026] [security2:error] [pid 167459:tid 167601] [client 20.106.102.5:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/Okxob.php"] [unique_id "aoSDTmr_JutbFb-8svrtZQAAAZs"] [Tue Aug 18 13:07:42.945012 2026] [security2:error] [pid 167459:tid 167595] [client 20.79.204.6:5727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/php8.php"] [unique_id "aoSDTmr_JutbFb-8svrtaQAAAZU"] [Tue Aug 18 13:07:42.980027 2026] [security2:error] [pid 167459:tid 167715] [client 20.116.17.175:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wmore1.php"] [unique_id "aoSDTmr_JutbFb-8svrtawAAAg0"] [Tue Aug 18 13:07:42.982768 2026] [security2:error] [pid 167459:tid 167612] [client 157.20.138.62:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDTmr_JutbFb-8svrtbAAAAaY"] [Tue Aug 18 13:07:42.982893 2026] [security2:error] [pid 167459:tid 167612] [client 157.20.138.62:54330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDTmr_JutbFb-8svrtbAAAAaY"] [Tue Aug 18 13:07:42.983077 2026] [security2:error] [pid 167459:tid 167506] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-content/themes/"] [unique_id "aoSDTmr_JutbFb-8svrtbQAB_C4"] [Tue Aug 18 13:07:43.021503 2026] [security2:error] [pid 167459:tid 167523] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/sid4.php"] [unique_id "aoSDT2r_JutbFb-8svrtcAABlD8"] [Tue Aug 18 13:07:43.028200 2026] [security2:error] [pid 167459:tid 167651] [client 158.23.17.4:20671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vp.php"] [unique_id "aoSDT2r_JutbFb-8svrtcQAAAc0"] [Tue Aug 18 13:07:43.088538 2026] [security2:error] [pid 167459:tid 167603] [client 135.225.75.187:35755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/66.php"] [unique_id "aoSDT2r_JutbFb-8svrtdAAAAZ0"] [Tue Aug 18 13:07:43.091866 2026] [security2:error] [pid 167459:tid 167526] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDT2r_JutbFb-8svrtdgABq0I"] [Tue Aug 18 13:07:43.110067 2026] [security2:error] [pid 167459:tid 167621] [client 4.232.151.198:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/themes/newsfeed-theme/bbh.php"] [unique_id "aoSDT2r_JutbFb-8svrtegAAAa8"] [Tue Aug 18 13:07:43.163966 2026] [security2:error] [pid 167459:tid 167702] [client 68.221.73.131:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/fling.php"] [unique_id "aoSDT2r_JutbFb-8svrtfwAAAgA"] [Tue Aug 18 13:07:43.177064 2026] [authz_core:error] [pid 167459:tid 167507] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:43.177515 2026] [authz_core:error] [pid 167459:tid 167507] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:43.181349 2026] [security2:error] [pid 167459:tid 167611] [client 132.196.30.78:20330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDT2r_JutbFb-8svrtgwAAAaU"] [Tue Aug 18 13:07:43.182468 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-good.php"] [unique_id "aoSDT2r_JutbFb-8svrthAAAAZI"] [Tue Aug 18 13:07:43.211369 2026] [security2:error] [pid 167459:tid 167664] [client 20.106.102.5:45218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/file59.php"] [unique_id "aoSDT2r_JutbFb-8svrthwAAAdo"] [Tue Aug 18 13:07:43.218852 2026] [security2:error] [pid 167459:tid 167706] [client 20.151.109.219:42791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lp.php"] [unique_id "aoSDT2r_JutbFb-8svrtiAAAAgQ"] [Tue Aug 18 13:07:43.225912 2026] [security2:error] [pid 167459:tid 167534] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDT2r_JutbFb-8svrtiwAB20o"] [Tue Aug 18 13:07:43.225930 2026] [security2:error] [pid 167459:tid 167679] [client 213.35.127.232:53377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDT2r_JutbFb-8svrtigAAAek"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:43.287013 2026] [security2:error] [pid 167459:tid 167668] [client 20.116.17.175:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/special.php"] [unique_id "aoSDT2r_JutbFb-8svrtjwAAAd4"] [Tue Aug 18 13:07:43.348961 2026] [security2:error] [pid 167459:tid 167694] [client 178.153.171.161:30318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDT2r_JutbFb-8svrtkgAAAfg"] [Tue Aug 18 13:07:43.349113 2026] [security2:error] [pid 167459:tid 167694] [client 178.153.171.161:30318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDT2r_JutbFb-8svrtkgAAAfg"] [Tue Aug 18 13:07:43.350371 2026] [security2:error] [pid 167459:tid 167537] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/configuration.js"] [unique_id "aoSDT2r_JutbFb-8svrtlAACBk0"] [Tue Aug 18 13:07:43.379962 2026] [security2:error] [pid 167459:tid 167539] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/size.php"] [unique_id "aoSDT2r_JutbFb-8svrtlwAB7E8"] [Tue Aug 18 13:07:43.381946 2026] [security2:error] [pid 167459:tid 167648] [client 158.23.17.4:44726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ph.php"] [unique_id "aoSDT2r_JutbFb-8svrtmAAAAco"] [Tue Aug 18 13:07:43.402866 2026] [security2:error] [pid 167459:tid 167662] [client 20.65.69.59:29211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/search.php"] [unique_id "aoSDT2r_JutbFb-8svrtmwAAAdg"] [Tue Aug 18 13:07:43.406652 2026] [security2:error] [pid 167459:tid 167541] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/js/crop/"] [unique_id "aoSDT2r_JutbFb-8svrtnAAB8lE"] [Tue Aug 18 13:07:43.451007 2026] [security2:error] [pid 167459:tid 167666] [client 74.248.18.37:19698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/504.php"] [unique_id "aoSDT2r_JutbFb-8svrtnwAAAdw"] [Tue Aug 18 13:07:43.475067 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:43.475515 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:43.477791 2026] [security2:error] [pid 167459:tid 167600] [client 20.104.100.201:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/img.php"] [unique_id "aoSDT2r_JutbFb-8svrtpQAAAZo"] [Tue Aug 18 13:07:43.505382 2026] [security2:error] [pid 167459:tid 167672] [client 20.104.100.201:53356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSDT2r_JutbFb-8svrtpwAAAeI"] [Tue Aug 18 13:07:43.506502 2026] [security2:error] [pid 167459:tid 167602] [client 135.225.75.187:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/g.php"] [unique_id "aoSDT2r_JutbFb-8svrtqAAAAZw"] [Tue Aug 18 13:07:43.538896 2026] [security2:error] [pid 167459:tid 167646] [client 20.106.102.5:45221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/eauu.php"] [unique_id "aoSDT2r_JutbFb-8svrtqgAAAcg"] [Tue Aug 18 13:07:43.552274 2026] [security2:error] [pid 167459:tid 167548] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/special.php"] [unique_id "aoSDT2r_JutbFb-8svrtrAABtFg"] [Tue Aug 18 13:07:43.641363 2026] [security2:error] [pid 167459:tid 167629] [client 20.116.17.175:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDT2r_JutbFb-8svrtswAAAbc"] [Tue Aug 18 13:07:43.642750 2026] [security2:error] [pid 167459:tid 167701] [client 20.65.98.162:54662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDT2r_JutbFb-8svrttAAAAf8"] [Tue Aug 18 13:07:43.654775 2026] [security2:error] [pid 167459:tid 167552] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-mail.php"] [unique_id "aoSDT2r_JutbFb-8svrttQAB91w"] [Tue Aug 18 13:07:43.659758 2026] [security2:error] [pid 167459:tid 167711] [client 20.79.204.6:5701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/plugins.php"] [unique_id "aoSDT2r_JutbFb-8svrttgAAAgk"] [Tue Aug 18 13:07:43.708577 2026] [security2:error] [pid 167459:tid 167698] [client 20.151.109.219:20673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ey.php"] [unique_id "aoSDT2r_JutbFb-8svrtuQAAAfw"] [Tue Aug 18 13:07:43.735154 2026] [security2:error] [pid 167459:tid 167561] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSDT2r_JutbFb-8svrtvQABpGU"] [Tue Aug 18 13:07:43.769884 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/s.php"] [unique_id "aoSDT2r_JutbFb-8svrtwAAAAaE"] [Tue Aug 18 13:07:43.773880 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:43.774157 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:43.785307 2026] [security2:error] [pid 167459:tid 167640] [client 20.226.36.136:25093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDT2r_JutbFb-8svrtwQAAAcI"] [Tue Aug 18 13:07:43.789485 2026] [security2:error] [pid 167459:tid 167656] [client 4.232.151.198:23055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/network/xleet.php"] [unique_id "aoSDT2r_JutbFb-8svrtwgAAAdI"] [Tue Aug 18 13:07:43.867894 2026] [security2:error] [pid 167459:tid 167649] [client 20.106.102.5:45279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/dsd.php"] [unique_id "aoSDT2r_JutbFb-8svrtygAAAcs"] [Tue Aug 18 13:07:43.869940 2026] [security2:error] [pid 167459:tid 167564] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/o.php"] [unique_id "aoSDT2r_JutbFb-8svrtywABtmg"] [Tue Aug 18 13:07:43.915080 2026] [security2:error] [pid 167459:tid 167555] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/storage/index.php"] [unique_id "aoSDT2r_JutbFb-8svrtzwABpV8"] [Tue Aug 18 13:07:43.925218 2026] [security2:error] [pid 167459:tid 167655] [client 135.225.75.187:24961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/x7.php"] [unique_id "aoSDT2r_JutbFb-8svrt0gAAAdE"] [Tue Aug 18 13:07:43.986800 2026] [security2:error] [pid 167459:tid 167603] [client 132.196.30.78:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/666.php"] [unique_id "aoSDT2r_JutbFb-8svrt3AAAAZ0"] [Tue Aug 18 13:07:44.002064 2026] [security2:error] [pid 167459:tid 167694] [client 20.116.17.175:58183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/thoms.php"] [unique_id "aoSDUGr_JutbFb-8svrt4AAAAfg"] [Tue Aug 18 13:07:44.026581 2026] [security2:error] [pid 167459:tid 167704] [client 20.104.100.201:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDUGr_JutbFb-8svrt7AAAAgI"] [Tue Aug 18 13:07:44.076209 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:44.076675 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:44.087562 2026] [security2:error] [pid 167459:tid 167575] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDUGr_JutbFb-8svrt8QAB8HM"] [Tue Aug 18 13:07:44.089403 2026] [security2:error] [pid 167459:tid 167662] [client 20.104.100.201:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/png.php"] [unique_id "aoSDUGr_JutbFb-8svrt8wAAAdg"] [Tue Aug 18 13:07:44.107432 2026] [security2:error] [pid 167459:tid 167475] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/bb.php"] [unique_id "aoSDUGr_JutbFb-8svrt9QAB1A8"] [Tue Aug 18 13:07:44.120020 2026] [security2:error] [pid 167459:tid 167666] [client 20.206.73.37:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDUGr_JutbFb-8svrt9wAAAdw"] [Tue Aug 18 13:07:44.144837 2026] [security2:error] [pid 167459:tid 167580] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/proxy"] [unique_id "aoSDUGr_JutbFb-8svrt-AAB13g"] [Tue Aug 18 13:07:44.164833 2026] [security2:error] [pid 167459:tid 167602] [client 172.182.217.32:4150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "aoSDUGr_JutbFb-8svrt-gAAAZw"] [Tue Aug 18 13:07:44.197365 2026] [security2:error] [pid 167459:tid 167627] [client 20.106.102.5:45220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/c4.php"] [unique_id "aoSDUGr_JutbFb-8svrt_gAAAbU"] [Tue Aug 18 13:07:44.233959 2026] [security2:error] [pid 167459:tid 167636] [client 52.139.47.57:30280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/666.php"] [unique_id "aoSDUGr_JutbFb-8svruAgAAAb4"] [Tue Aug 18 13:07:44.241810 2026] [security2:error] [pid 167459:tid 167669] [client 213.35.127.232:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDUGr_JutbFb-8svruAwAAAd8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:44.263645 2026] [security2:error] [pid 167459:tid 167472] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/sts.php"] [unique_id "aoSDUGr_JutbFb-8svruBgABvQw"] [Tue Aug 18 13:07:44.292250 2026] [security2:error] [pid 167459:tid 167676] [client 74.248.18.37:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/tiny.php"] [unique_id "aoSDUGr_JutbFb-8svruCAAAAeY"] [Tue Aug 18 13:07:44.326142 2026] [security2:error] [pid 167459:tid 167683] [client 158.23.17.4:36416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/uo.php"] [unique_id "aoSDUGr_JutbFb-8svruCgAAAe0"] [Tue Aug 18 13:07:44.348582 2026] [security2:error] [pid 167459:tid 167614] [client 135.225.75.187:22999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/god.php"] [unique_id "aoSDUGr_JutbFb-8svruDAAAAag"] [Tue Aug 18 13:07:44.353252 2026] [security2:error] [pid 167459:tid 167460] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDUGr_JutbFb-8svruDQABrgA"] [Tue Aug 18 13:07:44.377399 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:44.377638 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:44.380399 2026] [security2:error] [pid 167459:tid 167647] [client 52.139.47.57:3011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/bgymj.php"] [unique_id "aoSDUGr_JutbFb-8svruEQAAAck"] [Tue Aug 18 13:07:44.383624 2026] [security2:error] [pid 167459:tid 167680] [client 20.250.13.23:26733] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/1.php"] [unique_id "aoSDUGr_JutbFb-8svruEgAAAeo"] [Tue Aug 18 13:07:44.383751 2026] [security2:error] [pid 167459:tid 167680] [client 20.250.13.23:26733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/1.php"] [unique_id "aoSDUGr_JutbFb-8svruEgAAAeo"] [Tue Aug 18 13:07:44.404793 2026] [security2:error] [pid 167459:tid 167687] [client 20.116.17.175:58379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDUGr_JutbFb-8svruFAAAAfE"] [Tue Aug 18 13:07:44.436195 2026] [security2:error] [pid 167459:tid 167573] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/system_log.php"] [unique_id "aoSDUGr_JutbFb-8svruFwAB5HE"] [Tue Aug 18 13:07:44.496052 2026] [security2:error] [pid 167459:tid 167681] [client 4.232.151.198:23048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-content/plugins/Cache/Cache.php"] [unique_id "aoSDUGr_JutbFb-8svruGgAAAes"] [Tue Aug 18 13:07:44.525115 2026] [security2:error] [pid 167459:tid 167663] [client 20.106.102.5:45192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/an7.php"] [unique_id "aoSDUGr_JutbFb-8svruHAAAAdk"] [Tue Aug 18 13:07:44.558037 2026] [security2:error] [pid 167459:tid 167625] [client 20.151.109.219:28763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lv.php"] [unique_id "aoSDUGr_JutbFb-8svruHwAAAbM"] [Tue Aug 18 13:07:44.570701 2026] [security2:error] [pid 167459:tid 167471] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/network/"] [unique_id "aoSDUGr_JutbFb-8svruIgAB3Qs"] [Tue Aug 18 13:07:44.604127 2026] [security2:error] [pid 167459:tid 167611] [client 20.104.100.201:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/index.php"] [unique_id "aoSDUGr_JutbFb-8svruJAAAAaU"] [Tue Aug 18 13:07:44.608239 2026] [security2:error] [pid 167459:tid 167490] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/t.php"] [unique_id "aoSDUGr_JutbFb-8svruJQAB0R4"] [Tue Aug 18 13:07:44.619673 2026] [security2:error] [pid 167459:tid 167659] [client 20.226.36.136:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDUGr_JutbFb-8svruJgAAAdU"] [Tue Aug 18 13:07:44.632526 2026] [security2:error] [pid 167459:tid 167706] [client 20.116.17.175:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wmore1.php"] [unique_id "aoSDUGr_JutbFb-8svruJwAAAgQ"] [Tue Aug 18 13:07:44.653682 2026] [security2:error] [pid 167459:tid 167592] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDUGr_JutbFb-8svruKQAAAZI"] [Tue Aug 18 13:07:44.670368 2026] [security2:error] [pid 167459:tid 167606] [client 172.182.217.32:4143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/wp-pridmag/layout.php"] [unique_id "aoSDUGr_JutbFb-8svruLQAAAaA"] [Tue Aug 18 13:07:44.674484 2026] [security2:error] [pid 167459:tid 167631] [client 20.104.100.201:53343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ab.php"] [unique_id "aoSDUGr_JutbFb-8svruMAAAAbk"] [Tue Aug 18 13:07:44.678968 2026] [authz_core:error] [pid 167459:tid 167485] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:44.679401 2026] [authz_core:error] [pid 167459:tid 167485] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:44.700119 2026] [security2:error] [pid 167459:tid 167677] [client 20.171.51.14:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/nf.php"] [unique_id "aoSDUGr_JutbFb-8svruMQAAAec"] [Tue Aug 18 13:07:44.728478 2026] [security2:error] [pid 167459:tid 167619] [client 20.79.204.6:5958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/post.php"] [unique_id "aoSDUGr_JutbFb-8svruOAAAAa0"] [Tue Aug 18 13:07:44.740520 2026] [security2:error] [pid 167459:tid 167595] [client 46.102.21.132:59669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUGr_JutbFb-8svruOQAAAZU"] [Tue Aug 18 13:07:44.740653 2026] [security2:error] [pid 167459:tid 167595] [client 46.102.21.132:59669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUGr_JutbFb-8svruOQAAAZU"] [Tue Aug 18 13:07:44.742407 2026] [security2:error] [pid 167459:tid 167707] [client 158.23.17.4:20638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kx.php"] [unique_id "aoSDUGr_JutbFb-8svruOgAAAgU"] [Tue Aug 18 13:07:44.765760 2026] [security2:error] [pid 167459:tid 167708] [client 135.225.75.187:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSDUGr_JutbFb-8svruPAAAAgY"] [Tue Aug 18 13:07:44.768492 2026] [security2:error] [pid 167459:tid 167704] [client 132.196.30.78:13101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ws54.php"] [unique_id "aoSDUGr_JutbFb-8svruPQAAAgI"] [Tue Aug 18 13:07:44.782417 2026] [security2:error] [pid 167459:tid 167492] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/templates.php"] [unique_id "aoSDUGr_JutbFb-8svruPwABwSA"] [Tue Aug 18 13:07:44.792416 2026] [security2:error] [pid 167459:tid 167501] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDUGr_JutbFb-8svruQQACACk"] [Tue Aug 18 13:07:44.799537 2026] [security2:error] [pid 167459:tid 167679] [client 52.139.47.57:10112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/bthil.php"] [unique_id "aoSDUGr_JutbFb-8svruQgAAAek"] [Tue Aug 18 13:07:44.856973 2026] [security2:error] [pid 167459:tid 167686] [client 20.106.102.5:45225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/bsg-management/php.php"] [unique_id "aoSDUGr_JutbFb-8svruRgAAAfA"] [Tue Aug 18 13:07:44.858520 2026] [security2:error] [pid 167459:tid 167662] [client 68.221.73.131:8135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/zoo1.php"] [unique_id "aoSDUGr_JutbFb-8svruRwAAAdg"] [Tue Aug 18 13:07:44.899582 2026] [security2:error] [pid 167459:tid 167666] [client 20.116.17.175:58232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/root.php"] [unique_id "aoSDUGr_JutbFb-8svruSAAAAdw"] [Tue Aug 18 13:07:44.902989 2026] [security2:error] [pid 167459:tid 167613] [client 20.226.36.136:34551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDUGr_JutbFb-8svruSQAAAac"] [Tue Aug 18 13:07:44.957279 2026] [security2:error] [pid 167459:tid 167497] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/term.php"] [unique_id "aoSDUGr_JutbFb-8svruTQABviU"] [Tue Aug 18 13:07:44.967184 2026] [security2:error] [pid 167459:tid 167690] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDUGr_JutbFb-8svruTgAAAfQ"] [Tue Aug 18 13:07:45.006226 2026] [security2:error] [pid 167459:tid 167624] [client 20.151.109.219:33501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/51.php"] [unique_id "aoSDUWr_JutbFb-8svruUgAAAbI"] [Tue Aug 18 13:07:45.013981 2026] [security2:error] [pid 167459:tid 167515] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/xmrlpc.php"] [unique_id "aoSDUWr_JutbFb-8svruUwABnjc"] [Tue Aug 18 13:07:45.016532 2026] [security2:error] [pid 167459:tid 167701] [client 20.104.100.201:17229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wg459o.php"] [unique_id "aoSDUWr_JutbFb-8svruVAAAAf8"] [Tue Aug 18 13:07:45.123553 2026] [security2:error] [pid 167459:tid 167597] [client 4.232.151.198:23073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/num.php"] [unique_id "aoSDUWr_JutbFb-8svruVwAAAZc"] [Tue Aug 18 13:07:45.129946 2026] [security2:error] [pid 167459:tid 167500] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/test.php"] [unique_id "aoSDUWr_JutbFb-8svruWAABoig"] [Tue Aug 18 13:07:45.150162 2026] [security2:error] [pid 167459:tid 167614] [client 20.104.100.201:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/12.php"] [unique_id "aoSDUWr_JutbFb-8svruWgAAAag"] [Tue Aug 18 13:07:45.172176 2026] [security2:error] [pid 167459:tid 167676] [client 172.182.217.32:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "aoSDUWr_JutbFb-8svruXAAAAeY"] [Tue Aug 18 13:07:45.181868 2026] [security2:error] [pid 167459:tid 167601] [client 20.106.102.5:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/byp8.php"] [unique_id "aoSDUWr_JutbFb-8svruXgAAAZs"] [Tue Aug 18 13:07:45.188844 2026] [security2:error] [pid 167459:tid 167680] [client 135.225.75.187:18671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/8.php"] [unique_id "aoSDUWr_JutbFb-8svruYAAAAeo"] [Tue Aug 18 13:07:45.204293 2026] [security2:error] [pid 167459:tid 167650] [client 20.116.17.175:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/fpwch.php"] [unique_id "aoSDUWr_JutbFb-8svruYQAAAcw"] [Tue Aug 18 13:07:45.206713 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.18.37:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/atomlib.php"] [unique_id "aoSDUWr_JutbFb-8svruYgAAAd8"] [Tue Aug 18 13:07:45.220634 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:10122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/xp.php"] [unique_id "aoSDUWr_JutbFb-8svruZAAAAe0"] [Tue Aug 18 13:07:45.233770 2026] [security2:error] [pid 167459:tid 167502] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/file.php"] [unique_id "aoSDUWr_JutbFb-8svruZgAB-So"] [Tue Aug 18 13:07:45.252779 2026] [security2:error] [pid 167459:tid 167633] [client 158.23.17.4:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/va.php"] [unique_id "aoSDUWr_JutbFb-8svruZwAAAbs"] [Tue Aug 18 13:07:45.271313 2026] [security2:error] [pid 167459:tid 167642] [client 213.35.127.232:53824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDUWr_JutbFb-8svruaAAAAcQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:45.280211 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:45.280484 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:45.302475 2026] [security2:error] [pid 167459:tid 167498] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/test1.php"] [unique_id "aoSDUWr_JutbFb-8svruawABmiY"] [Tue Aug 18 13:07:45.322252 2026] [security2:error] [pid 167459:tid 167594] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/admin.php"] [unique_id "aoSDUWr_JutbFb-8svrubAAAAZQ"] [Tue Aug 18 13:07:45.388657 2026] [security2:error] [pid 167459:tid 167674] [client 138.36.100.162:41845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUWr_JutbFb-8svrucgAAAeQ"] [Tue Aug 18 13:07:45.388770 2026] [security2:error] [pid 167459:tid 167674] [client 138.36.100.162:41845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUWr_JutbFb-8svrucgAAAeQ"] [Tue Aug 18 13:07:45.415426 2026] [security2:error] [pid 167459:tid 167670] [client 20.79.204.6:5742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/r.php"] [unique_id "aoSDUWr_JutbFb-8svrucwAAAeA"] [Tue Aug 18 13:07:45.454240 2026] [security2:error] [pid 167459:tid 167656] [client 132.196.30.78:20288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDUWr_JutbFb-8svrudQAAAdI"] [Tue Aug 18 13:07:45.472944 2026] [security2:error] [pid 167459:tid 167520] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/epinyins.php"] [unique_id "aoSDUWr_JutbFb-8svrueAAB3jw"] [Tue Aug 18 13:07:45.476755 2026] [security2:error] [pid 167459:tid 167516] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/thoms.php"] [unique_id "aoSDUWr_JutbFb-8svrueQAB0Dg"] [Tue Aug 18 13:07:45.487316 2026] [security2:error] [pid 167459:tid 167703] [client 51.79.230.178:61672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "caminhosdaregiao.com.br"] [uri "/"] [unique_id "aoSDUWr_JutbFb-8svruegAAAgE"] [Tue Aug 18 13:07:45.508483 2026] [security2:error] [pid 167459:tid 167653] [client 20.106.102.5:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/plugins.php"] [unique_id "aoSDUWr_JutbFb-8svruewAAAc8"] [Tue Aug 18 13:07:45.533982 2026] [security2:error] [pid 167459:tid 167638] [client 20.116.17.175:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/mg.php"] [unique_id "aoSDUWr_JutbFb-8svrufgAAAcA"] [Tue Aug 18 13:07:45.581422 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:45.581694 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:45.612342 2026] [security2:error] [pid 167459:tid 167679] [client 135.225.75.187:23829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/koiy.php"] [unique_id "aoSDUWr_JutbFb-8svrugwAAAek"] [Tue Aug 18 13:07:45.620457 2026] [security2:error] [pid 167459:tid 167712] [client 104.209.144.33:32661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDUWr_JutbFb-8svruhAAAAgo"] [Tue Aug 18 13:07:45.636916 2026] [security2:error] [pid 167459:tid 167622] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/public/css.php"] [unique_id "aoSDUWr_JutbFb-8svruhQAAAbA"] [Tue Aug 18 13:07:45.639022 2026] [security2:error] [pid 167459:tid 167707] [client 52.139.47.57:37955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/reze.php"] [unique_id "aoSDUWr_JutbFb-8svruiAAAAgU"] [Tue Aug 18 13:07:45.659320 2026] [security2:error] [pid 167459:tid 167688] [client 20.104.100.201:53355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/x1da.php"] [unique_id "aoSDUWr_JutbFb-8svruiQAAAfI"] [Tue Aug 18 13:07:45.661338 2026] [security2:error] [pid 167459:tid 167595] [client 172.182.217.32:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/updraft/plugins-old/updraftplus/templates/wp-admin/data.php"] [unique_id "aoSDUWr_JutbFb-8svruigAAAZU"] [Tue Aug 18 13:07:45.676715 2026] [security2:error] [pid 167459:tid 167525] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/tool.php"] [unique_id "aoSDUWr_JutbFb-8svrujAABp0E"] [Tue Aug 18 13:07:45.693388 2026] [security2:error] [pid 167459:tid 167672] [client 20.226.36.136:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDUWr_JutbFb-8svrujgAAAeI"] [Tue Aug 18 13:07:45.705762 2026] [security2:error] [pid 167459:tid 167627] [client 20.151.109.219:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ew.php"] [unique_id "aoSDUWr_JutbFb-8svrukAAAAbU"] [Tue Aug 18 13:07:45.729542 2026] [security2:error] [pid 167459:tid 167491] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDUWr_JutbFb-8svrulQABvh8"] [Tue Aug 18 13:07:45.773740 2026] [security2:error] [pid 167459:tid 167604] [client 158.23.17.4:4655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fo.php"] [unique_id "aoSDUWr_JutbFb-8svrulgAAAZ4"] [Tue Aug 18 13:07:45.775339 2026] [security2:error] [pid 167459:tid 167598] [client 20.65.98.162:55595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/mgrr.php"] [unique_id "aoSDUWr_JutbFb-8svrulwAAAZg"] [Tue Aug 18 13:07:45.785859 2026] [security2:error] [pid 167459:tid 167693] [client 20.116.17.175:20338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/special.php"] [unique_id "aoSDUWr_JutbFb-8svrumAAAAfc"] [Tue Aug 18 13:07:45.829333 2026] [security2:error] [pid 167459:tid 167620] [client 20.116.17.175:64941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/reop3.php"] [unique_id "aoSDUWr_JutbFb-8svrumwAAAa4"] [Tue Aug 18 13:07:45.851960 2026] [security2:error] [pid 167459:tid 167676] [client 20.106.102.5:45233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/100.kb.php"] [unique_id "aoSDUWr_JutbFb-8svrunQAAAeY"] [Tue Aug 18 13:07:45.864153 2026] [security2:error] [pid 167459:tid 167536] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/tools.php"] [unique_id "aoSDUWr_JutbFb-8svrunwABm0w"] [Tue Aug 18 13:07:45.959667 2026] [security2:error] [pid 167459:tid 167716] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/classwithtostring.php"] [unique_id "aoSDUWr_JutbFb-8svrupQAAAg4"] [Tue Aug 18 13:07:45.965868 2026] [security2:error] [pid 167459:tid 167686] [client 20.250.13.23:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/alfa.php"] [unique_id "aoSDUWr_JutbFb-8svrupgAAAfA"] [Tue Aug 18 13:07:45.968034 2026] [security2:error] [pid 167459:tid 167589] [client 132.196.30.78:13115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/function/function.php"] [unique_id "aoSDUWr_JutbFb-8svrupwAAAY8"] [Tue Aug 18 13:07:45.968183 2026] [security2:error] [pid 167459:tid 167531] [remote 172.202.39.151:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/php-compat/"] [unique_id "aoSDUWr_JutbFb-8svruqAABwkc"] [Tue Aug 18 13:07:45.994649 2026] [security2:error] [pid 167459:tid 167552] [remote 162.55.89.48:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "historiasparadormir.top"] [uri "/wp-login.php"] [unique_id "aoSDUWr_JutbFb-8svruqgAB_lw"] [Tue Aug 18 13:07:46.034824 2026] [security2:error] [pid 167459:tid 167628] [client 68.221.73.131:64396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/zoo2.php"] [unique_id "aoSDUmr_JutbFb-8svrurAAAAbY"] [Tue Aug 18 13:07:46.035713 2026] [security2:error] [pid 167459:tid 167612] [client 135.225.75.187:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/iko.php"] [unique_id "aoSDUmr_JutbFb-8svrurQAAAaY"] [Tue Aug 18 13:07:46.037445 2026] [security2:error] [pid 167459:tid 167685] [client 20.79.204.6:5726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/radio.php"] [unique_id "aoSDUmr_JutbFb-8svrurgAAAe8"] [Tue Aug 18 13:07:46.052223 2026] [security2:error] [pid 167459:tid 167669] [client 52.139.47.57:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/2026w.php"] [unique_id "aoSDUmr_JutbFb-8svrusAAAAd8"] [Tue Aug 18 13:07:46.066872 2026] [security2:error] [pid 167459:tid 167535] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/txets.php"] [unique_id "aoSDUmr_JutbFb-8svrusgABpUs"] [Tue Aug 18 13:07:46.106190 2026] [security2:error] [pid 167459:tid 167674] [client 4.232.151.198:18969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/xmlrpc.php0"] [unique_id "aoSDUmr_JutbFb-8svrutwAAAeQ"] [Tue Aug 18 13:07:46.106704 2026] [security2:error] [pid 167459:tid 167706] [client 20.206.73.37:3513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/gm.php"] [unique_id "aoSDUmr_JutbFb-8svruuAAAAgQ"] [Tue Aug 18 13:07:46.108152 2026] [security2:error] [pid 167459:tid 167665] [client 20.206.73.37:26568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/mosty.php"] [unique_id "aoSDUmr_JutbFb-8svruuQAAAds"] [Tue Aug 18 13:07:46.166848 2026] [autoindex:error] [pid 167459:tid 167594] [client 172.182.217.32:4151] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-content/uploads/2023/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:46.175568 2026] [security2:error] [pid 167459:tid 167664] [client 20.106.102.5:45147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/mamzi.php"] [unique_id "aoSDUmr_JutbFb-8svruvQAAAdo"] [Tue Aug 18 13:07:46.187037 2026] [security2:error] [pid 167459:tid 167697] [client 20.151.109.219:36323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pqr.php"] [unique_id "aoSDUmr_JutbFb-8svruwQAAAfs"] [Tue Aug 18 13:07:46.213281 2026] [security2:error] [pid 167459:tid 167546] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDUmr_JutbFb-8svruxAAB1lY"] [Tue Aug 18 13:07:46.218425 2026] [security2:error] [pid 167459:tid 167703] [client 20.226.36.136:32651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/rezor.php"] [unique_id "aoSDUmr_JutbFb-8svruxQAAAgE"] [Tue Aug 18 13:07:46.235003 2026] [security2:error] [pid 167459:tid 167643] [client 158.23.17.4:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/loading.php"] [unique_id "aoSDUmr_JutbFb-8svruxwAAAcU"] [Tue Aug 18 13:07:46.240904 2026] [security2:error] [pid 167459:tid 167538] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/u.php"] [unique_id "aoSDUmr_JutbFb-8svruyAACAE4"] [Tue Aug 18 13:07:46.249488 2026] [security2:error] [pid 167459:tid 167704] [client 102.213.179.104:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svruygAAAgI"] [Tue Aug 18 13:07:46.249655 2026] [security2:error] [pid 167459:tid 167704] [client 102.213.179.104:56027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svruygAAAgI"] [Tue Aug 18 13:07:46.277998 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/12.php"] [unique_id "aoSDUmr_JutbFb-8svruzAAAAdk"] [Tue Aug 18 13:07:46.289167 2026] [security2:error] [pid 167459:tid 167681] [client 213.35.127.232:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDUmr_JutbFb-8svruzQAAAes"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:46.329972 2026] [security2:error] [pid 167459:tid 167689] [client 172.182.217.32:4151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/about.php"] [unique_id "aoSDUmr_JutbFb-8svru0AAAAfM"] [Tue Aug 18 13:07:46.361033 2026] [security2:error] [pid 167459:tid 167671] [client 20.104.100.201:53264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/mcs.php"] [unique_id "aoSDUmr_JutbFb-8svru0wAAAeE"] [Tue Aug 18 13:07:46.409891 2026] [security2:error] [pid 167459:tid 167604] [client 20.116.17.175:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDUmr_JutbFb-8svru1wAAAZ4"] [Tue Aug 18 13:07:46.412021 2026] [security2:error] [pid 167459:tid 167598] [client 20.116.17.175:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/php5.php"] [unique_id "aoSDUmr_JutbFb-8svru2AAAAZg"] [Tue Aug 18 13:07:46.416450 2026] [security2:error] [pid 167459:tid 167568] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/ultra.php"] [unique_id "aoSDUmr_JutbFb-8svru2QAB_2w"] [Tue Aug 18 13:07:46.430616 2026] [security2:error] [pid 167459:tid 167635] [client 103.120.71.157:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svru2gAAAb0"] [Tue Aug 18 13:07:46.430716 2026] [security2:error] [pid 167459:tid 167635] [client 103.120.71.157:48523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svru2gAAAb0"] [Tue Aug 18 13:07:46.444049 2026] [security2:error] [pid 167459:tid 167714] [client 197.184.64.235:42689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svru2wAAAgw"] [Tue Aug 18 13:07:46.444145 2026] [security2:error] [pid 167459:tid 167714] [client 197.184.64.235:42689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svru2wAAAgw"] [Tue Aug 18 13:07:46.445955 2026] [security2:error] [pid 167459:tid 167559] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDUmr_JutbFb-8svru3AAB9WM"] [Tue Aug 18 13:07:46.453395 2026] [security2:error] [pid 167459:tid 167563] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/web.config"] [unique_id "aoSDUmr_JutbFb-8svru3QACB2c"] [Tue Aug 18 13:07:46.453498 2026] [security2:error] [pid 167459:tid 167705] [client 135.225.75.187:35736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/raw.php"] [unique_id "aoSDUmr_JutbFb-8svru3gAAAgM"] [Tue Aug 18 13:07:46.468854 2026] [security2:error] [pid 167459:tid 167715] [client 52.139.47.57:64741] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "iguabagreen.com.br"] [uri "/1.php"] [unique_id "aoSDUmr_JutbFb-8svru4QAAAg0"] [Tue Aug 18 13:07:46.468973 2026] [security2:error] [pid 167459:tid 167715] [client 52.139.47.57:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/1.php"] [unique_id "aoSDUmr_JutbFb-8svru4QAAAg0"] [Tue Aug 18 13:07:46.493962 2026] [security2:error] [pid 167459:tid 167696] [client 20.104.100.201:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDUmr_JutbFb-8svru4wAAAfo"] [Tue Aug 18 13:07:46.495317 2026] [security2:error] [pid 167459:tid 167576] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/config.php.bak"] [unique_id "aoSDUmr_JutbFb-8svru5QAB_HQ"] [Tue Aug 18 13:07:46.500305 2026] [security2:error] [pid 167459:tid 167630] [client 20.106.102.5:45298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ms.php"] [unique_id "aoSDUmr_JutbFb-8svru5wAAAbg"] [Tue Aug 18 13:07:46.511244 2026] [security2:error] [pid 167459:tid 167508] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/settings.py"] [unique_id "aoSDUmr_JutbFb-8svru6QABxzA"] [Tue Aug 18 13:07:46.512123 2026] [security2:error] [pid 167459:tid 167683] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/admin.php"] [unique_id "aoSDUmr_JutbFb-8svru6gAAAe0"] [Tue Aug 18 13:07:46.515417 2026] [security2:error] [pid 167459:tid 167605] [client 51.79.230.178:61746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSDUmr_JutbFb-8svru6wAAAZ8"] [Tue Aug 18 13:07:46.515853 2026] [security2:error] [pid 167459:tid 167558] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/fetch"] [unique_id "aoSDUmr_JutbFb-8svru7AABzGI"] [Tue Aug 18 13:07:46.600971 2026] [security2:error] [pid 167459:tid 167625] [client 20.151.109.219:40501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/an.php"] [unique_id "aoSDUmr_JutbFb-8svru9QAAAbM"] [Tue Aug 18 13:07:46.619028 2026] [security2:error] [pid 167459:tid 167578] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/un.php"] [unique_id "aoSDUmr_JutbFb-8svru9gABpnY"] [Tue Aug 18 13:07:46.619511 2026] [security2:error] [pid 167459:tid 167628] [client 20.226.36.136:37225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDUmr_JutbFb-8svru9wAAAbY"] [Tue Aug 18 13:07:46.634832 2026] [security2:error] [pid 167459:tid 167613] [client 132.196.30.78:20340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/nw.php"] [unique_id "aoSDUmr_JutbFb-8svru-QAAAac"] [Tue Aug 18 13:07:46.665267 2026] [security2:error] [pid 167459:tid 167574] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp.php"] [unique_id "aoSDUmr_JutbFb-8svru-gABknI"] [Tue Aug 18 13:07:46.692049 2026] [security2:error] [pid 167459:tid 167610] [client 158.23.17.4:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ke.php"] [unique_id "aoSDUmr_JutbFb-8svru-wAAAaQ"] [Tue Aug 18 13:07:46.729889 2026] [security2:error] [pid 167459:tid 167617] [client 4.232.151.198:23052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.maxxbox.ind.br"] [uri "/wp-admin/maint/item.php"] [unique_id "aoSDUmr_JutbFb-8svru_wAAAas"] [Tue Aug 18 13:07:46.755510 2026] [authz_core:error] [pid 167459:tid 167616] [client 192.178.4.135:65005] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:46.755828 2026] [authz_core:error] [pid 167459:tid 167616] [client 192.178.4.135:65005] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:46.763293 2026] [security2:error] [pid 167459:tid 167642] [client 20.79.204.6:5968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSDUmr_JutbFb-8svrvAwAAAcQ"] [Tue Aug 18 13:07:46.788531 2026] [authz_core:error] [pid 167459:tid 167554] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:46.788978 2026] [authz_core:error] [pid 167459:tid 167554] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:46.791986 2026] [security2:error] [pid 167459:tid 167475] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/up.php"] [unique_id "aoSDUmr_JutbFb-8svrvBQABuQ8"] [Tue Aug 18 13:07:46.830796 2026] [security2:error] [pid 167459:tid 167638] [client 20.106.102.5:45257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/public/wp-blog.php"] [unique_id "aoSDUmr_JutbFb-8svrvBwAAAcA"] [Tue Aug 18 13:07:46.841604 2026] [security2:error] [pid 167459:tid 167665] [client 172.182.217.32:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSDUmr_JutbFb-8svrvCgAAAds"] [Tue Aug 18 13:07:46.851641 2026] [security2:error] [pid 167459:tid 167687] [client 49.145.211.146:12187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svrvCwAAAfE"] [Tue Aug 18 13:07:46.851779 2026] [security2:error] [pid 167459:tid 167687] [client 49.145.211.146:12187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svrvCwAAAfE"] [Tue Aug 18 13:07:46.853220 2026] [security2:error] [pid 167459:tid 167551] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/function/function.php"] [unique_id "aoSDUmr_JutbFb-8svrvDAABzls"] [Tue Aug 18 13:07:46.869043 2026] [security2:error] [pid 167459:tid 167615] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/gelay.php"] [unique_id "aoSDUmr_JutbFb-8svrvDQAAAak"] [Tue Aug 18 13:07:46.870367 2026] [security2:error] [pid 167459:tid 167712] [client 135.225.75.187:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/05.php"] [unique_id "aoSDUmr_JutbFb-8svrvDgAAAgo"] [Tue Aug 18 13:07:46.882478 2026] [security2:error] [pid 167459:tid 167678] [client 52.139.47.57:64713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/2.php"] [unique_id "aoSDUmr_JutbFb-8svrvDwAAAeg"] [Tue Aug 18 13:07:46.889976 2026] [security2:error] [pid 167459:tid 167663] [client 20.104.100.201:53367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/adminner.php"] [unique_id "aoSDUmr_JutbFb-8svrvEAAAAdk"] [Tue Aug 18 13:07:46.900317 2026] [security2:error] [pid 167459:tid 167710] [client 20.116.17.175:20420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDUmr_JutbFb-8svrvFQAAAgg"] [Tue Aug 18 13:07:46.916260 2026] [security2:error] [pid 167459:tid 167464] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/local.settings.json"] [unique_id "aoSDUmr_JutbFb-8svrvFwACBQQ"] [Tue Aug 18 13:07:46.921274 2026] [security2:error] [pid 167459:tid 167542] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDUmr_JutbFb-8svrvGAABrFI"] [Tue Aug 18 13:07:46.943199 2026] [security2:error] [pid 167459:tid 167577] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSDUmr_JutbFb-8svrvGwAB4nU"] [Tue Aug 18 13:07:46.952450 2026] [security2:error] [pid 167459:tid 167684] [client 4.232.151.198:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/admin.php"] [unique_id "aoSDUmr_JutbFb-8svrvHAAAAe4"] [Tue Aug 18 13:07:46.979917 2026] [security2:error] [pid 167459:tid 167593] [client 74.248.18.37:58045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/sck.php"] [unique_id "aoSDUmr_JutbFb-8svrvIAAAAZM"] [Tue Aug 18 13:07:46.982898 2026] [security2:error] [pid 167459:tid 167661] [client 20.171.51.14:19682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/xv.php"] [unique_id "aoSDUmr_JutbFb-8svrvIgAAAdc"] [Tue Aug 18 13:07:46.984739 2026] [security2:error] [pid 167459:tid 167648] [client 196.12.128.158:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svrvIwAAAco"] [Tue Aug 18 13:07:46.984898 2026] [security2:error] [pid 167459:tid 167648] [client 196.12.128.158:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDUmr_JutbFb-8svrvIwAAAco"] [Tue Aug 18 13:07:47.056781 2026] [security2:error] [pid 167459:tid 167573] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/settings.json"] [unique_id "aoSDU2r_JutbFb-8svrvJAACA3E"] [Tue Aug 18 13:07:47.096701 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:47.097160 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:47.106056 2026] [security2:error] [pid 167459:tid 167482] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDU2r_JutbFb-8svrvLgABtRY"] [Tue Aug 18 13:07:47.129756 2026] [security2:error] [pid 167459:tid 167676] [client 20.151.109.219:40454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sy.php"] [unique_id "aoSDU2r_JutbFb-8svrvMAAAAeY"] [Tue Aug 18 13:07:47.157011 2026] [security2:error] [pid 167459:tid 167680] [client 20.106.102.5:45254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/cu.php"] [unique_id "aoSDU2r_JutbFb-8svrvMgAAAeo"] [Tue Aug 18 13:07:47.158001 2026] [security2:error] [pid 167459:tid 167467] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/users.php"] [unique_id "aoSDU2r_JutbFb-8svrvNAABuAc"] [Tue Aug 18 13:07:47.194889 2026] [security2:error] [pid 167459:tid 167645] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDU2r_JutbFb-8svrvOAAAAcc"] [Tue Aug 18 13:07:47.212622 2026] [security2:error] [pid 167459:tid 167480] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDU2r_JutbFb-8svrvOQABwhQ"] [Tue Aug 18 13:07:47.218144 2026] [security2:error] [pid 167459:tid 167477] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/.docker/config.json"] [unique_id "aoSDU2r_JutbFb-8svrvOgABrhE"] [Tue Aug 18 13:07:47.231307 2026] [security2:error] [pid 167459:tid 167625] [client 20.116.17.175:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDU2r_JutbFb-8svrvOwAAAbM"] [Tue Aug 18 13:07:47.242311 2026] [security2:error] [pid 167459:tid 167612] [client 68.221.73.131:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/org.php"] [unique_id "aoSDU2r_JutbFb-8svrvPQAAAaY"] [Tue Aug 18 13:07:47.254831 2026] [security2:error] [pid 167459:tid 167628] [client 20.104.100.201:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dragonshell.php"] [unique_id "aoSDU2r_JutbFb-8svrvQAAAAbY"] [Tue Aug 18 13:07:47.287226 2026] [security2:error] [pid 167459:tid 167655] [client 135.225.75.187:24972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/public/hi.php"] [unique_id "aoSDU2r_JutbFb-8svrvQgAAAdE"] [Tue Aug 18 13:07:47.303992 2026] [security2:error] [pid 167459:tid 167613] [client 158.23.17.4:53223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nh.php"] [unique_id "aoSDU2r_JutbFb-8svrvQwAAAac"] [Tue Aug 18 13:07:47.310007 2026] [security2:error] [pid 167459:tid 167623] [client 213.35.127.232:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDU2r_JutbFb-8svrvRAAAAbE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:47.326505 2026] [security2:error] [pid 167459:tid 167698] [client 52.139.47.57:10162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/7.php"] [unique_id "aoSDU2r_JutbFb-8svrvRQAAAfw"] [Tue Aug 18 13:07:47.329414 2026] [security2:error] [pid 167459:tid 167641] [client 20.250.13.23:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/edit.php"] [unique_id "aoSDU2r_JutbFb-8svrvRwAAAcM"] [Tue Aug 18 13:07:47.332150 2026] [security2:error] [pid 167459:tid 167651] [client 172.182.217.32:4046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/api.php"] [unique_id "aoSDU2r_JutbFb-8svrvSAAAAc0"] [Tue Aug 18 13:07:47.333035 2026] [security2:error] [pid 167459:tid 167487] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/v.php"] [unique_id "aoSDU2r_JutbFb-8svrvSQACDhs"] [Tue Aug 18 13:07:47.344205 2026] [security2:error] [pid 167459:tid 167586] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDU2r_JutbFb-8svrvSwABq34"] [Tue Aug 18 13:07:47.344358 2026] [security2:error] [pid 167459:tid 167617] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDU2r_JutbFb-8svrvSwABq34"] [Tue Aug 18 13:07:47.345421 2026] [security2:error] [pid 167459:tid 167509] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDU2r_JutbFb-8svrvTAAB2jE"] [Tue Aug 18 13:07:47.355322 2026] [security2:error] [pid 167459:tid 167677] [client 20.116.17.175:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/acp.php"] [unique_id "aoSDU2r_JutbFb-8svrvTgAAAec"] [Tue Aug 18 13:07:47.386151 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:47.386471 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:47.428316 2026] [security2:error] [pid 167459:tid 167600] [client 20.79.204.6:5739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/red.php"] [unique_id "aoSDU2r_JutbFb-8svrvUwAAAZo"] [Tue Aug 18 13:07:47.480551 2026] [security2:error] [pid 167459:tid 167643] [client 20.106.102.5:45295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/X57.php"] [unique_id "aoSDU2r_JutbFb-8svrvVgAAAcU"] [Tue Aug 18 13:07:47.494787 2026] [security2:error] [pid 167459:tid 167494] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/g.php"] [unique_id "aoSDU2r_JutbFb-8svrvVwABziI"] [Tue Aug 18 13:07:47.499777 2026] [security2:error] [pid 167459:tid 167704] [client 20.151.109.219:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/57.php"] [unique_id "aoSDU2r_JutbFb-8svrvWAAAAgI"] [Tue Aug 18 13:07:47.502826 2026] [security2:error] [pid 167459:tid 167496] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/domvf.php"] [unique_id "aoSDU2r_JutbFb-8svrvWQABmSQ"] [Tue Aug 18 13:07:47.506861 2026] [security2:error] [pid 167459:tid 167515] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/v5.php"] [unique_id "aoSDU2r_JutbFb-8svrvWgABozc"] [Tue Aug 18 13:07:47.578471 2026] [security2:error] [pid 167459:tid 167591] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/adminfuns.php"] [unique_id "aoSDU2r_JutbFb-8svrvXgAAAZE"] [Tue Aug 18 13:07:47.589014 2026] [security2:error] [pid 167459:tid 167669] [client 132.196.30.78:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/xleet.php"] [unique_id "aoSDU2r_JutbFb-8svrvYAAAAd8"] [Tue Aug 18 13:07:47.594682 2026] [security2:error] [pid 167459:tid 167473] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/ok.php"] [unique_id "aoSDU2r_JutbFb-8svrvYgABrA0"] [Tue Aug 18 13:07:47.681681 2026] [security2:error] [pid 167459:tid 167511] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/we.php"] [unique_id "aoSDU2r_JutbFb-8svrvaQABrzM"] [Tue Aug 18 13:07:47.686777 2026] [authz_core:error] [pid 167459:tid 167485] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:47.687042 2026] [authz_core:error] [pid 167459:tid 167485] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:47.688296 2026] [security2:error] [pid 167459:tid 167688] [client 114.119.144.127:43067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "petceu.com.br"] [uri "/2017/03/page/2"] [unique_id "aoSDU2r_JutbFb-8svrvagAAAfI"], referer: https://petceu.com.br/2017/03 [Tue Aug 18 13:07:47.699896 2026] [security2:error] [pid 167459:tid 167604] [client 20.206.73.37:21572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/blurbs.php"] [unique_id "aoSDU2r_JutbFb-8svrvawAAAZ4"] [Tue Aug 18 13:07:47.706491 2026] [security2:error] [pid 167459:tid 167598] [client 135.225.75.187:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/get.php"] [unique_id "aoSDU2r_JutbFb-8svrvbAAAAZg"] [Tue Aug 18 13:07:47.715687 2026] [security2:error] [pid 167459:tid 167653] [client 20.104.100.201:53280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/setup-config.php"] [unique_id "aoSDU2r_JutbFb-8svrvbQAAAc8"] [Tue Aug 18 13:07:47.741124 2026] [security2:error] [pid 167459:tid 167694] [client 52.139.47.57:20188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/10.php"] [unique_id "aoSDU2r_JutbFb-8svrvbwAAAfg"] [Tue Aug 18 13:07:47.748505 2026] [security2:error] [pid 167459:tid 167691] [client 52.173.121.69:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDU2r_JutbFb-8svrvcAAAAfU"] [Tue Aug 18 13:07:47.794975 2026] [security2:error] [pid 167459:tid 167502] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSDU2r_JutbFb-8svrvcQACByo"] [Tue Aug 18 13:07:47.804227 2026] [security2:error] [pid 167459:tid 167705] [client 20.106.102.5:45235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/forbidals.php"] [unique_id "aoSDU2r_JutbFb-8svrvcgAAAgM"] [Tue Aug 18 13:07:47.821221 2026] [security2:error] [pid 167459:tid 167661] [client 172.182.217.32:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/core.php"] [unique_id "aoSDU2r_JutbFb-8svrvdQAAAdc"] [Tue Aug 18 13:07:47.828164 2026] [security2:error] [pid 167459:tid 167658] [client 158.23.17.4:39592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/oo.php"] [unique_id "aoSDU2r_JutbFb-8svrvdgAAAdQ"] [Tue Aug 18 13:07:47.846869 2026] [security2:error] [pid 167459:tid 167597] [client 20.151.109.219:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ah.php"] [unique_id "aoSDU2r_JutbFb-8svrvdwAAAZc"] [Tue Aug 18 13:07:47.858649 2026] [security2:error] [pid 167459:tid 167510] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wkl.php"] [unique_id "aoSDU2r_JutbFb-8svrveAABtTI"] [Tue Aug 18 13:07:47.868850 2026] [security2:error] [pid 167459:tid 167503] [remote 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mrvprojetos.com"] [uri "/item.php"] [unique_id "aoSDU2r_JutbFb-8svrveQABmys"] [Tue Aug 18 13:07:47.873091 2026] [security2:error] [pid 167459:tid 167666] [client 74.248.18.37:27853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/1945.php"] [unique_id "aoSDU2r_JutbFb-8svrvewAAAdw"] [Tue Aug 18 13:07:47.953056 2026] [security2:error] [pid 167459:tid 167683] [client 20.116.17.175:20231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/thoms.php"] [unique_id "aoSDU2r_JutbFb-8svrvfgAAAe0"] [Tue Aug 18 13:07:47.989303 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:47.989575 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:48.028941 2026] [security2:error] [pid 167459:tid 167533] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/gecko.php"] [unique_id "aoSDVGr_JutbFb-8svrvhgACBEk"] [Tue Aug 18 13:07:48.045020 2026] [security2:error] [pid 167459:tid 167488] [remote 162.214.205.212:53790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoSDVGr_JutbFb-8svrviAABwRw"] [Tue Aug 18 13:07:48.054090 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/yas.php"] [unique_id "aoSDVGr_JutbFb-8svrviQAAAZI"] [Tue Aug 18 13:07:48.070599 2026] [security2:error] [pid 167459:tid 167689] [client 20.79.204.6:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/release.php"] [unique_id "aoSDVGr_JutbFb-8svrvigAAAfM"] [Tue Aug 18 13:07:48.086730 2026] [security2:error] [pid 167459:tid 167526] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/gec.php"] [unique_id "aoSDVGr_JutbFb-8svrvjQABw0I"] [Tue Aug 18 13:07:48.099320 2026] [security2:error] [pid 167459:tid 167716] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDVGr_JutbFb-8svrvjwAAAg4"] [Tue Aug 18 13:07:48.120234 2026] [security2:error] [pid 167459:tid 167541] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/log-viewer"] [unique_id "aoSDVGr_JutbFb-8svrvkQAB41E"] [Tue Aug 18 13:07:48.124915 2026] [security2:error] [pid 167459:tid 167714] [client 135.225.75.187:24603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/rpk.php"] [unique_id "aoSDVGr_JutbFb-8svrvkgAAAgw"] [Tue Aug 18 13:07:48.135047 2026] [security2:error] [pid 167459:tid 167606] [client 20.106.102.5:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/edit.php"] [unique_id "aoSDVGr_JutbFb-8svrvkwAAAaA"] [Tue Aug 18 13:07:48.138256 2026] [security2:error] [pid 167459:tid 167617] [client 20.226.36.136:33435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDVGr_JutbFb-8svrvlAAAAas"] [Tue Aug 18 13:07:48.150959 2026] [security2:error] [pid 167459:tid 167534] [remote 34.239.85.139:34486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cainelli.com.br"] [uri "/uploads/plctncc/mini-and-micro-hydro-power-plant-pdf"] [unique_id "aoSDVGr_JutbFb-8svrvlQAB-ko"] [Tue Aug 18 13:07:48.153302 2026] [security2:error] [pid 167459:tid 167611] [client 52.139.47.57:3062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/13.php"] [unique_id "aoSDVGr_JutbFb-8svrvlgAAAaU"] [Tue Aug 18 13:07:48.165706 2026] [security2:error] [pid 167459:tid 167624] [client 132.196.30.78:13572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp.php"] [unique_id "aoSDVGr_JutbFb-8svrvlwAAAbI"] [Tue Aug 18 13:07:48.213960 2026] [security2:error] [pid 167459:tid 167468] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/gettest.php"] [unique_id "aoSDVGr_JutbFb-8svrvnAABrQg"] [Tue Aug 18 13:07:48.254991 2026] [security2:error] [pid 167459:tid 167517] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/work.php"] [unique_id "aoSDVGr_JutbFb-8svrvnwABvjk"] [Tue Aug 18 13:07:48.278567 2026] [security2:error] [pid 167459:tid 167687] [client 20.116.17.175:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/makeasmtp.php"] [unique_id "aoSDVGr_JutbFb-8svrvoQAAAfE"] [Tue Aug 18 13:07:48.291613 2026] [security2:error] [pid 167459:tid 167599] [client 20.151.109.219:33522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vw.php"] [unique_id "aoSDVGr_JutbFb-8svrvpAAAAZk"] [Tue Aug 18 13:07:48.293391 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:48.293869 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:48.314527 2026] [security2:error] [pid 167459:tid 167678] [client 68.221.73.131:39674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/imageskir.php"] [unique_id "aoSDVGr_JutbFb-8svrvpgAAAeg"] [Tue Aug 18 13:07:48.328995 2026] [security2:error] [pid 167459:tid 167649] [client 213.35.127.232:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDVGr_JutbFb-8svrvpwAAAcs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:48.340348 2026] [security2:error] [pid 167459:tid 167677] [client 172.182.217.32:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/data.php"] [unique_id "aoSDVGr_JutbFb-8svrvqAAAAec"] [Tue Aug 18 13:07:48.370471 2026] [security2:error] [pid 167459:tid 167657] [client 114.119.130.91:38093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "queroficarnanet.com"] [uri "/wp-login.php"] [unique_id "aoSDVGr_JutbFb-8svrvmwAAAdM"], referer: https://queroficarnanet.com/wp-login.php?action=register [Tue Aug 18 13:07:48.377084 2026] [security2:error] [pid 167459:tid 167512] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/sky.php"] [unique_id "aoSDVGr_JutbFb-8svrvrgABlTQ"] [Tue Aug 18 13:07:48.395295 2026] [security2:error] [pid 167459:tid 167521] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/goods.php"] [unique_id "aoSDVGr_JutbFb-8svrvsAAB4j0"] [Tue Aug 18 13:07:48.416861 2026] [security2:error] [pid 167459:tid 167684] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/about.php"] [unique_id "aoSDVGr_JutbFb-8svrvsQAAAe4"] [Tue Aug 18 13:07:48.456672 2026] [security2:error] [pid 167459:tid 167593] [client 20.106.102.5:45309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/kj.php"] [unique_id "aoSDVGr_JutbFb-8svrvtQAAAZM"] [Tue Aug 18 13:07:48.457425 2026] [security2:error] [pid 167459:tid 167481] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/worksec.php"] [unique_id "aoSDVGr_JutbFb-8svrvtwABrxU"] [Tue Aug 18 13:07:48.479761 2026] [security2:error] [pid 167459:tid 167699] [client 20.226.36.136:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/index/function.php"] [unique_id "aoSDVGr_JutbFb-8svrvuQAAAf0"] [Tue Aug 18 13:07:48.545510 2026] [security2:error] [pid 167459:tid 167627] [client 135.225.75.187:24631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDVGr_JutbFb-8svrvvQAAAbU"] [Tue Aug 18 13:07:48.593827 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:48.594242 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:48.600235 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/100.php"] [unique_id "aoSDVGr_JutbFb-8svrvwAAAAfQ"] [Tue Aug 18 13:07:48.603927 2026] [security2:error] [pid 167459:tid 167645] [client 5.31.227.224:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVGr_JutbFb-8svrvwQAAAcc"] [Tue Aug 18 13:07:48.616270 2026] [security2:error] [pid 167459:tid 167529] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/gulu.php"] [unique_id "aoSDVGr_JutbFb-8svrvwgAB7UU"] [Tue Aug 18 13:07:48.616464 2026] [security2:error] [pid 167459:tid 167645] [client 5.31.227.224:30417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVGr_JutbFb-8svrvwQAAAcc"] [Tue Aug 18 13:07:48.625208 2026] [security2:error] [pid 167459:tid 167524] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/dump.sql"] [unique_id "aoSDVGr_JutbFb-8svrvwwABwkA"] [Tue Aug 18 13:07:48.648338 2026] [security2:error] [pid 167459:tid 167550] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-activate.php"] [unique_id "aoSDVGr_JutbFb-8svrvxgABs1o"] [Tue Aug 18 13:07:48.654575 2026] [security2:error] [pid 167459:tid 167545] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/db.sql"] [unique_id "aoSDVGr_JutbFb-8svrvxwABnVU"] [Tue Aug 18 13:07:48.665223 2026] [security2:error] [pid 167459:tid 167556] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/database.sql"] [unique_id "aoSDVGr_JutbFb-8svrvyQABqmA"] [Tue Aug 18 13:07:48.698202 2026] [security2:error] [pid 167459:tid 167507] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/sixxis.php"] [unique_id "aoSDVGr_JutbFb-8svrvywABsS8"] [Tue Aug 18 13:07:48.703378 2026] [security2:error] [pid 167459:tid 167676] [client 20.104.100.201:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/f35.update.php"] [unique_id "aoSDVGr_JutbFb-8svrvzAAAAeY"] [Tue Aug 18 13:07:48.711352 2026] [security2:error] [pid 167459:tid 167650] [client 20.250.13.23:26740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/elp.php"] [unique_id "aoSDVGr_JutbFb-8svrvzQAAAcw"] [Tue Aug 18 13:07:48.723291 2026] [security2:error] [pid 167459:tid 167713] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDVGr_JutbFb-8svrvzgAAAgs"] [Tue Aug 18 13:07:48.780920 2026] [security2:error] [pid 167459:tid 167716] [client 20.106.102.5:45289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/bes.php"] [unique_id "aoSDVGr_JutbFb-8svrv0gAAAg4"] [Tue Aug 18 13:07:48.785025 2026] [security2:error] [pid 167459:tid 167658] [client 20.79.204.6:5722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/reop3.php"] [unique_id "aoSDVGr_JutbFb-8svrv1QAAAdQ"] [Tue Aug 18 13:07:48.787938 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ah25.php"] [unique_id "aoSDVGr_JutbFb-8svrv1gAAAeM"] [Tue Aug 18 13:07:48.821096 2026] [security2:error] [pid 167459:tid 167532] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin.php"] [unique_id "aoSDVGr_JutbFb-8svrv2AACDEg"] [Tue Aug 18 13:07:48.829289 2026] [security2:error] [pid 167459:tid 167628] [client 172.182.217.32:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/db-status.php"] [unique_id "aoSDVGr_JutbFb-8svrv2QAAAbY"] [Tue Aug 18 13:07:48.853370 2026] [security2:error] [pid 167459:tid 167617] [client 20.151.109.219:31710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lj.php"] [unique_id "aoSDVGr_JutbFb-8svrv2gAAAas"] [Tue Aug 18 13:07:48.877968 2026] [security2:error] [pid 167459:tid 167592] [client 132.196.30.78:20321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/155.php"] [unique_id "aoSDVGr_JutbFb-8svrv2wAAAZI"] [Tue Aug 18 13:07:48.885525 2026] [security2:error] [pid 167459:tid 167568] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/h.php"] [unique_id "aoSDVGr_JutbFb-8svrv3QABsmw"] [Tue Aug 18 13:07:48.886684 2026] [security2:error] [pid 167459:tid 167611] [client 20.116.17.175:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDVGr_JutbFb-8svrv3gAAAaU"] [Tue Aug 18 13:07:48.892345 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:48.892614 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:48.904917 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:37414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/homeadmin.php"] [unique_id "aoSDVGr_JutbFb-8svrv3wAAAfY"] [Tue Aug 18 13:07:48.933979 2026] [security2:error] [pid 167459:tid 167660] [client 20.104.100.201:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/mifta.php"] [unique_id "aoSDVGr_JutbFb-8svrv4gAAAdY"] [Tue Aug 18 13:07:48.970650 2026] [security2:error] [pid 167459:tid 167702] [client 135.225.75.187:12073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/mga.php"] [unique_id "aoSDVGr_JutbFb-8svrv5AAAAgA"] [Tue Aug 18 13:07:48.989718 2026] [security2:error] [pid 167459:tid 167559] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/yj09.php"] [unique_id "aoSDVGr_JutbFb-8svrv5QAB6WM"] [Tue Aug 18 13:07:49.013821 2026] [security2:error] [pid 167459:tid 167652] [client 20.104.100.201:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDVWr_JutbFb-8svrv6AAAAc4"] [Tue Aug 18 13:07:49.018069 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:3010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/222.php"] [unique_id "aoSDVWr_JutbFb-8svrv6QAAAfo"] [Tue Aug 18 13:07:49.022281 2026] [security2:error] [pid 167459:tid 167678] [client 20.206.73.37:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/bajah.php"] [unique_id "aoSDVWr_JutbFb-8svrv6wAAAeg"] [Tue Aug 18 13:07:49.026171 2026] [security2:error] [pid 167459:tid 167649] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/f35.php"] [unique_id "aoSDVWr_JutbFb-8svrv7AAAAcs"] [Tue Aug 18 13:07:49.068887 2026] [security2:error] [pid 167459:tid 167544] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/hello.php"] [unique_id "aoSDVWr_JutbFb-8svrv7QABsFQ"] [Tue Aug 18 13:07:49.090761 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:53201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ja.php"] [unique_id "aoSDVWr_JutbFb-8svrv8AAAAdM"] [Tue Aug 18 13:07:49.105062 2026] [security2:error] [pid 167459:tid 167595] [client 20.106.102.5:45297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ws60.php"] [unique_id "aoSDVWr_JutbFb-8svrv8gAAAZU"] [Tue Aug 18 13:07:49.152289 2026] [security2:error] [pid 167459:tid 167651] [client 4.232.151.198:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/goods.php"] [unique_id "aoSDVWr_JutbFb-8svrv9AAAAc0"] [Tue Aug 18 13:07:49.162222 2026] [security2:error] [pid 167459:tid 167600] [client 74.7.244.13:41154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "polomasculina.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDVWr_JutbFb-8svrv9QABmmI"] [Tue Aug 18 13:07:49.182377 2026] [security2:error] [pid 167459:tid 167564] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSDVWr_JutbFb-8svrv9gABz2g"] [Tue Aug 18 13:07:49.187477 2026] [security2:error] [pid 167459:tid 167701] [client 20.104.100.201:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/bdroot.php"] [unique_id "aoSDVWr_JutbFb-8svrv-QAAAf8"] [Tue Aug 18 13:07:49.193485 2026] [authz_core:error] [pid 167459:tid 167578] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:49.193736 2026] [authz_core:error] [pid 167459:tid 167578] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:49.210688 2026] [security2:error] [pid 167459:tid 167691] [client 20.151.109.219:46587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kh.php"] [unique_id "aoSDVWr_JutbFb-8svrv-wAAAfU"] [Tue Aug 18 13:07:49.248932 2026] [security2:error] [pid 167459:tid 167567] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/images/index.php"] [unique_id "aoSDVWr_JutbFb-8svrv_QAB12s"] [Tue Aug 18 13:07:49.279457 2026] [security2:error] [pid 167459:tid 167574] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/k.php"] [unique_id "aoSDVWr_JutbFb-8svrv_wABtXI"] [Tue Aug 18 13:07:49.290366 2026] [security2:error] [pid 167459:tid 167666] [client 68.221.73.131:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/indexo.php"] [unique_id "aoSDVWr_JutbFb-8svrwAAAAAdw"] [Tue Aug 18 13:07:49.293250 2026] [security2:error] [pid 167459:tid 167680] [client 20.226.36.136:34112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDVWr_JutbFb-8svrwAQAAAeo"] [Tue Aug 18 13:07:49.321593 2026] [security2:error] [pid 167459:tid 167626] [client 172.182.217.32:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDVWr_JutbFb-8svrwAwAAAbQ"] [Tue Aug 18 13:07:49.346955 2026] [security2:error] [pid 167459:tid 167711] [client 213.35.127.232:54687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDVWr_JutbFb-8svrwBAAAAgk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:49.356160 2026] [security2:error] [pid 167459:tid 167571] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDVWr_JutbFb-8svrwBQABwm8"] [Tue Aug 18 13:07:49.358824 2026] [security2:error] [pid 167459:tid 167700] [client 20.116.17.175:52586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/cok.php"] [unique_id "aoSDVWr_JutbFb-8svrwBgAAAf4"] [Tue Aug 18 13:07:49.384004 2026] [security2:error] [pid 167459:tid 167693] [client 47.128.16.209:13962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mcvans.com.br"] [uri "/robots.txt"] [unique_id "aoSDVWr_JutbFb-8svrwCQAAAfc"] [Tue Aug 18 13:07:49.392515 2026] [security2:error] [pid 167459:tid 167616] [client 135.225.75.187:24993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/fs.php"] [unique_id "aoSDVWr_JutbFb-8svrwCgAAAao"] [Tue Aug 18 13:07:49.404434 2026] [security2:error] [pid 167459:tid 167699] [client 20.79.204.6:5955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/robots.php"] [unique_id "aoSDVWr_JutbFb-8svrwCwAAAf0"] [Tue Aug 18 13:07:49.428523 2026] [security2:error] [pid 167459:tid 167706] [client 20.116.17.175:64911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/ano.php"] [unique_id "aoSDVWr_JutbFb-8svrwDQAAAgQ"] [Tue Aug 18 13:07:49.432482 2026] [security2:error] [pid 167459:tid 167654] [client 52.139.47.57:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDVWr_JutbFb-8svrwDgAAAdA"] [Tue Aug 18 13:07:49.432504 2026] [security2:error] [pid 167459:tid 167584] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/index.bak.php"] [unique_id "aoSDVWr_JutbFb-8svrwDwABwXw"] [Tue Aug 18 13:07:49.434109 2026] [security2:error] [pid 167459:tid 167650] [client 20.106.102.5:45223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/olfclass.php"] [unique_id "aoSDVWr_JutbFb-8svrwEAAAAcw"] [Tue Aug 18 13:07:49.441388 2026] [security2:error] [pid 167459:tid 167674] [client 49.37.150.8:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVWr_JutbFb-8svrwEQAAAeQ"] [Tue Aug 18 13:07:49.441495 2026] [security2:error] [pid 167459:tid 167674] [client 49.37.150.8:54229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVWr_JutbFb-8svrwEQAAAeQ"] [Tue Aug 18 13:07:49.496060 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:49.496358 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:49.498563 2026] [security2:error] [pid 167459:tid 167673] [client 20.65.98.162:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/55.php"] [unique_id "aoSDVWr_JutbFb-8svrwFwAAAeM"] [Tue Aug 18 13:07:49.530552 2026] [security2:error] [pid 167459:tid 167582] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSDVWr_JutbFb-8svrwGgAB2no"] [Tue Aug 18 13:07:49.536650 2026] [security2:error] [pid 167459:tid 167647] [client 132.196.30.78:20335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/96i.php"] [unique_id "aoSDVWr_JutbFb-8svrwHAAAAck"] [Tue Aug 18 13:07:49.544746 2026] [security2:error] [pid 167459:tid 167624] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/inputs.php"] [unique_id "aoSDVWr_JutbFb-8svrwHQAAAbI"] [Tue Aug 18 13:07:49.578078 2026] [security2:error] [pid 167459:tid 167547] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/w.php"] [unique_id "aoSDVWr_JutbFb-8svrwHwABuVc"] [Tue Aug 18 13:07:49.612271 2026] [security2:error] [pid 167459:tid 167575] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/index/function.php"] [unique_id "aoSDVWr_JutbFb-8svrwJAACAnM"] [Tue Aug 18 13:07:49.617422 2026] [security2:error] [pid 167459:tid 167599] [client 20.116.17.175:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/root.php"] [unique_id "aoSDVWr_JutbFb-8svrwJgAAAZk"] [Tue Aug 18 13:07:49.636307 2026] [security2:error] [pid 167459:tid 167598] [client 86.120.159.145:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVWr_JutbFb-8svrwJwAAAZg"] [Tue Aug 18 13:07:49.636426 2026] [security2:error] [pid 167459:tid 167598] [client 86.120.159.145:55174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDVWr_JutbFb-8svrwJwAAAZg"] [Tue Aug 18 13:07:49.669411 2026] [security2:error] [pid 167459:tid 167542] [remote 35.247.121.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.121.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inovartararas.com.br"] [uri "/info.php"] [unique_id "aoSDVWr_JutbFb-8svrwKQABolI"] [Tue Aug 18 13:07:49.689503 2026] [security2:error] [pid 167459:tid 167613] [client 74.248.18.37:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/theme-insynwr.php"] [unique_id "aoSDVWr_JutbFb-8svrwLQAAAac"] [Tue Aug 18 13:07:49.703874 2026] [security2:error] [pid 167459:tid 167579] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDVWr_JutbFb-8svrwLgAB53c"] [Tue Aug 18 13:07:49.736234 2026] [security2:error] [pid 167459:tid 167472] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/gcp.json"] [unique_id "aoSDVWr_JutbFb-8svrwMQABjww"] [Tue Aug 18 13:07:49.743090 2026] [security2:error] [pid 167459:tid 167460] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.bash_history"] [unique_id "aoSDVWr_JutbFb-8svrwNAABzgA"] [Tue Aug 18 13:07:49.758246 2026] [security2:error] [pid 167459:tid 167618] [client 20.106.102.5:45139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wpver.php"] [unique_id "aoSDVWr_JutbFb-8svrwNQAAAaw"] [Tue Aug 18 13:07:49.785223 2026] [security2:error] [pid 167459:tid 167643] [client 20.116.17.175:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/nwflm.php"] [unique_id "aoSDVWr_JutbFb-8svrwNwAAAcU"] [Tue Aug 18 13:07:49.801215 2026] [authz_core:error] [pid 167459:tid 167587] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:49.801690 2026] [authz_core:error] [pid 167459:tid 167587] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:49.808763 2026] [security2:error] [pid 167459:tid 167629] [client 172.182.217.32:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/load.php"] [unique_id "aoSDVWr_JutbFb-8svrwOwAAAbc"] [Tue Aug 18 13:07:49.810135 2026] [security2:error] [pid 167459:tid 167553] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/info.php"] [unique_id "aoSDVWr_JutbFb-8svrwPAACDV0"] [Tue Aug 18 13:07:49.817184 2026] [security2:error] [pid 167459:tid 167671] [client 135.225.75.187:24962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/wp-tem.php"] [unique_id "aoSDVWr_JutbFb-8svrwPgAAAeE"] [Tue Aug 18 13:07:49.826985 2026] [security2:error] [pid 167459:tid 167649] [client 74.7.241.159:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.imparavelimob.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDVWr_JutbFb-8svrwQAABy3g"] [Tue Aug 18 13:07:49.854019 2026] [security2:error] [pid 167459:tid 167710] [client 52.139.47.57:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/abcd.php"] [unique_id "aoSDVWr_JutbFb-8svrwRAAAAgg"] [Tue Aug 18 13:07:49.856843 2026] [security2:error] [pid 167459:tid 167600] [client 20.116.17.175:52574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/accesson.php"] [unique_id "aoSDVWr_JutbFb-8svrwRQAAAZo"] [Tue Aug 18 13:07:49.867436 2026] [security2:error] [pid 167459:tid 167480] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fpwch.php"] [unique_id "aoSDVWr_JutbFb-8svrwRgABvRQ"] [Tue Aug 18 13:07:49.873694 2026] [security2:error] [pid 167459:tid 167477] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/master.key"] [unique_id "aoSDVWr_JutbFb-8svrwRwABzxE"] [Tue Aug 18 13:07:49.889238 2026] [security2:error] [pid 167459:tid 167476] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/config/credentials.yml.enc"] [unique_id "aoSDVWr_JutbFb-8svrwSQABlRA"] [Tue Aug 18 13:07:49.892048 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:53349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDVWr_JutbFb-8svrwSgAAAgU"] [Tue Aug 18 13:07:49.894105 2026] [security2:error] [pid 167459:tid 167691] [client 20.206.73.37:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/h.php"] [unique_id "aoSDVWr_JutbFb-8svrwTAAAAfU"] [Tue Aug 18 13:07:49.953000 2026] [security2:error] [pid 167459:tid 167627] [client 20.151.109.219:42777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/jb.php"] [unique_id "aoSDVWr_JutbFb-8svrwUAAAAbU"] [Tue Aug 18 13:07:50.005554 2026] [security2:error] [pid 167459:tid 167462] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/inputs.php"] [unique_id "aoSDVmr_JutbFb-8svrwUwABxwI"] [Tue Aug 18 13:07:50.067888 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/alfa.php"] [unique_id "aoSDVmr_JutbFb-8svrwVQAAAbw"] [Tue Aug 18 13:07:50.074309 2026] [security2:error] [pid 167459:tid 167509] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSDVmr_JutbFb-8svrwVgAB3TE"] [Tue Aug 18 13:07:50.083561 2026] [security2:error] [pid 167459:tid 167603] [client 20.106.102.5:45184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/thui.php"] [unique_id "aoSDVmr_JutbFb-8svrwVwAAAZ0"] [Tue Aug 18 13:07:50.098587 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:50.098847 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:50.130027 2026] [security2:error] [pid 167459:tid 167644] [client 132.196.30.78:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/as.php"] [unique_id "aoSDVmr_JutbFb-8svrwXAAAAcY"] [Tue Aug 18 13:07:50.157242 2026] [security2:error] [pid 167459:tid 167494] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDVmr_JutbFb-8svrwXgABwSI"] [Tue Aug 18 13:07:50.171050 2026] [security2:error] [pid 167459:tid 167674] [client 20.116.17.175:50146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/wp-load.php"] [unique_id "aoSDVmr_JutbFb-8svrwXwAAAeQ"] [Tue Aug 18 13:07:50.202659 2026] [security2:error] [pid 167459:tid 167689] [client 68.221.73.131:59218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSDVmr_JutbFb-8svrwYgAAAfM"] [Tue Aug 18 13:07:50.234629 2026] [security2:error] [pid 167459:tid 167714] [client 135.225.75.187:23843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/sadd.php"] [unique_id "aoSDVmr_JutbFb-8svrwYwAAAgw"] [Tue Aug 18 13:07:50.239492 2026] [security2:error] [pid 167459:tid 167673] [client 20.104.100.201:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-css.php"] [unique_id "aoSDVmr_JutbFb-8svrwZAAAAeM"] [Tue Aug 18 13:07:50.246008 2026] [security2:error] [pid 167459:tid 167501] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/install.php"] [unique_id "aoSDVmr_JutbFb-8svrwZQABtik"] [Tue Aug 18 13:07:50.249591 2026] [security2:error] [pid 167459:tid 167483] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDVmr_JutbFb-8svrwZwAByRc"] [Tue Aug 18 13:07:50.251574 2026] [security2:error] [pid 167459:tid 167626] [client 20.79.204.6:5970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/root.php"] [unique_id "aoSDVmr_JutbFb-8svrwaAAAAbQ"] [Tue Aug 18 13:07:50.268611 2026] [security2:error] [pid 167459:tid 167699] [client 52.139.47.57:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/al.php"] [unique_id "aoSDVmr_JutbFb-8svrwagAAAf0"] [Tue Aug 18 13:07:50.295866 2026] [security2:error] [pid 167459:tid 167620] [client 20.206.73.37:65197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ano.php"] [unique_id "aoSDVmr_JutbFb-8svrwbAAAAa4"] [Tue Aug 18 13:07:50.295937 2026] [security2:error] [pid 167459:tid 167596] [client 172.182.217.32:4145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/maintenance.php"] [unique_id "aoSDVmr_JutbFb-8svrwbQAAAZY"] [Tue Aug 18 13:07:50.299942 2026] [security2:error] [pid 167459:tid 167703] [client 20.116.17.175:20300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/fpwch.php"] [unique_id "aoSDVmr_JutbFb-8svrwbgAAAgE"] [Tue Aug 18 13:07:50.330528 2026] [security2:error] [pid 167459:tid 167695] [client 20.250.13.23:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDVmr_JutbFb-8svrwcQAAAfk"] [Tue Aug 18 13:07:50.371785 2026] [security2:error] [pid 167459:tid 167711] [client 213.35.127.232:54911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDVmr_JutbFb-8svrwdQAAAgk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:50.397949 2026] [security2:error] [pid 167459:tid 167608] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/lock360.php"] [unique_id "aoSDVmr_JutbFb-8svrwdwAAAaI"] [Tue Aug 18 13:07:50.403712 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:50.403973 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:50.411800 2026] [security2:error] [pid 167459:tid 167712] [client 20.106.102.5:45229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/tmpls.php"] [unique_id "aoSDVmr_JutbFb-8svrwewAAAgo"] [Tue Aug 18 13:07:50.427098 2026] [security2:error] [pid 167459:tid 167469] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDVmr_JutbFb-8svrwfQABkQk"] [Tue Aug 18 13:07:50.436946 2026] [security2:error] [pid 167459:tid 167510] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSDVmr_JutbFb-8svrwfgABsDI"] [Tue Aug 18 13:07:50.441929 2026] [security2:error] [pid 167459:tid 167641] [client 74.248.18.37:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ovazeuaxq.php"] [unique_id "aoSDVmr_JutbFb-8svrwfwAAAcM"] [Tue Aug 18 13:07:50.447111 2026] [security2:error] [pid 167459:tid 167505] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/blurbs.php"] [unique_id "aoSDVmr_JutbFb-8svrwgQAB2C0"] [Tue Aug 18 13:07:50.464134 2026] [security2:error] [pid 167459:tid 167672] [client 20.151.109.219:58362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/do.php"] [unique_id "aoSDVmr_JutbFb-8svrwhAAAAeI"] [Tue Aug 18 13:07:50.502220 2026] [security2:error] [pid 167459:tid 167671] [client 20.116.17.175:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/jj.php"] [unique_id "aoSDVmr_JutbFb-8svrwhgAAAeE"] [Tue Aug 18 13:07:50.560286 2026] [security2:error] [pid 167459:tid 167705] [client 4.232.151.198:44684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/file.php"] [unique_id "aoSDVmr_JutbFb-8svrwiQAAAgM"] [Tue Aug 18 13:07:50.565100 2026] [security2:error] [pid 167459:tid 167593] [client 20.116.17.175:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/av.php"] [unique_id "aoSDVmr_JutbFb-8svrwigAAAZM"] [Tue Aug 18 13:07:50.614221 2026] [security2:error] [pid 167459:tid 167488] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/item.php"] [unique_id "aoSDVmr_JutbFb-8svrwjAACBxw"] [Tue Aug 18 13:07:50.623506 2026] [security2:error] [pid 167459:tid 167661] [client 20.206.73.37:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/ws55.php"] [unique_id "aoSDVmr_JutbFb-8svrwjgAAAdc"] [Tue Aug 18 13:07:50.654008 2026] [security2:error] [pid 167459:tid 167690] [client 135.225.75.187:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ex.php"] [unique_id "aoSDVmr_JutbFb-8svrwkgAAAfQ"] [Tue Aug 18 13:07:50.671892 2026] [security2:error] [pid 167459:tid 167684] [client 132.196.30.78:13090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/min.php"] [unique_id "aoSDVmr_JutbFb-8svrwlAAAAe4"] [Tue Aug 18 13:07:50.684180 2026] [security2:error] [pid 167459:tid 167600] [client 52.139.47.57:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/alfa.php"] [unique_id "aoSDVmr_JutbFb-8svrwlQAAAZo"] [Tue Aug 18 13:07:50.689919 2026] [security2:error] [pid 167459:tid 167645] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/flower.php"] [unique_id "aoSDVmr_JutbFb-8svrwlgAAAcc"] [Tue Aug 18 13:07:50.701244 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:50.701706 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:50.749577 2026] [security2:error] [pid 167459:tid 167685] [client 20.106.102.5:45305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/nzv.php"] [unique_id "aoSDVmr_JutbFb-8svrwmwAAAe8"] [Tue Aug 18 13:07:50.758026 2026] [security2:error] [pid 167459:tid 167485] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/100.php"] [unique_id "aoSDVmr_JutbFb-8svrwnAABpBk"] [Tue Aug 18 13:07:50.798445 2026] [security2:error] [pid 167459:tid 167516] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/js.php"] [unique_id "aoSDVmr_JutbFb-8svrwnwAB0Dg"] [Tue Aug 18 13:07:50.799367 2026] [security2:error] [pid 167459:tid 167652] [client 172.182.217.32:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/min.php"] [unique_id "aoSDVmr_JutbFb-8svrwoAAAAc4"] [Tue Aug 18 13:07:50.804379 2026] [security2:error] [pid 167459:tid 167630] [client 20.171.51.14:39790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/mx.php"] [unique_id "aoSDVmr_JutbFb-8svrwoQAAAbg"] [Tue Aug 18 13:07:50.840095 2026] [security2:error] [pid 167459:tid 167674] [client 20.116.17.175:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/mg.php"] [unique_id "aoSDVmr_JutbFb-8svrwowAAAeQ"] [Tue Aug 18 13:07:50.847606 2026] [security2:error] [pid 167459:tid 167713] [client 20.116.17.175:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/img.php"] [unique_id "aoSDVmr_JutbFb-8svrwpAAAAgs"] [Tue Aug 18 13:07:50.848774 2026] [security2:error] [pid 167459:tid 167525] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDVmr_JutbFb-8svrwpQAB80E"] [Tue Aug 18 13:07:50.941098 2026] [security2:error] [pid 167459:tid 167680] [client 20.79.204.6:5995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/rrr.php"] [unique_id "aoSDVmr_JutbFb-8svrwqQAAAeo"] [Tue Aug 18 13:07:50.941743 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/flox.php"] [unique_id "aoSDVmr_JutbFb-8svrwqgAAAZU"] [Tue Aug 18 13:07:50.956337 2026] [security2:error] [pid 167459:tid 167703] [client 20.226.36.136:34163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/Cachex.php"] [unique_id "aoSDVmr_JutbFb-8svrwqwAAAgE"] [Tue Aug 18 13:07:50.982541 2026] [security2:error] [pid 167459:tid 167481] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/k.php"] [unique_id "aoSDVmr_JutbFb-8svrwrgABwBU"] [Tue Aug 18 13:07:50.987448 2026] [security2:error] [pid 167459:tid 167611] [client 223.185.37.47:31089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDVmr_JutbFb-8svrwrwAAAaU"] [Tue Aug 18 13:07:50.987562 2026] [security2:error] [pid 167459:tid 167611] [client 223.185.37.47:31089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDVmr_JutbFb-8svrwrwAAAaU"] [Tue Aug 18 13:07:51.006462 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:51.006952 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:51.022402 2026] [security2:error] [pid 167459:tid 167609] [client 20.104.100.201:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/term.php"] [unique_id "aoSDV2r_JutbFb-8svrwsgAAAaM"] [Tue Aug 18 13:07:51.023182 2026] [access_compat:error] [pid 167459:tid 167521] [remote 35.247.121.182:0] AH01797: client denied by server configuration: /home3/inovartararas/public_html/server-status [Tue Aug 18 13:07:51.025977 2026] [security2:error] [pid 167459:tid 167529] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSDV2r_JutbFb-8svrwswACBkU"] [Tue Aug 18 13:07:51.037108 2026] [security2:error] [pid 167459:tid 167604] [client 68.221.73.131:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSDV2r_JutbFb-8svrwtAAAAZ4"] [Tue Aug 18 13:07:51.041223 2026] [security2:error] [pid 167459:tid 167608] [client 20.151.109.219:20963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/yw.php"] [unique_id "aoSDV2r_JutbFb-8svrwtQAAAaI"] [Tue Aug 18 13:07:51.048710 2026] [security2:error] [pid 167459:tid 167524] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ccc.php"] [unique_id "aoSDV2r_JutbFb-8svrwtgABrUA"] [Tue Aug 18 13:07:51.063713 2026] [security2:error] [pid 167459:tid 167676] [client 20.250.13.23:26125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/666.php"] [unique_id "aoSDV2r_JutbFb-8svrwuAAAAeY"] [Tue Aug 18 13:07:51.070205 2026] [security2:error] [pid 167459:tid 167613] [client 135.225.75.187:35751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/tax.php"] [unique_id "aoSDV2r_JutbFb-8svrwuQAAAac"] [Tue Aug 18 13:07:51.071125 2026] [security2:error] [pid 167459:tid 167712] [client 20.106.102.5:45253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/error1.php"] [unique_id "aoSDV2r_JutbFb-8svrwugAAAgo"] [Tue Aug 18 13:07:51.102069 2026] [security2:error] [pid 167459:tid 167702] [client 52.139.47.57:30276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/as.php"] [unique_id "aoSDV2r_JutbFb-8svrwvgAAAgA"] [Tue Aug 18 13:07:51.114645 2026] [security2:error] [pid 167459:tid 167591] [client 20.116.17.175:52593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/kj.php"] [unique_id "aoSDV2r_JutbFb-8svrwvwAAAZE"] [Tue Aug 18 13:07:51.155752 2026] [security2:error] [pid 167459:tid 167641] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/13.php"] [unique_id "aoSDV2r_JutbFb-8svrwwgAAAcM"] [Tue Aug 18 13:07:51.191807 2026] [security2:error] [pid 167459:tid 167528] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/media/index.php"] [unique_id "aoSDV2r_JutbFb-8svrwxgAB8UQ"] [Tue Aug 18 13:07:51.212182 2026] [security2:error] [pid 167459:tid 167532] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSDV2r_JutbFb-8svrwxwABqEg"] [Tue Aug 18 13:07:51.232636 2026] [security2:error] [pid 167459:tid 167599] [client 74.248.18.37:45601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/wp-load.php"] [unique_id "aoSDV2r_JutbFb-8svrwyAAAAZk"] [Tue Aug 18 13:07:51.241418 2026] [security2:error] [pid 167459:tid 167688] [client 20.116.17.175:58237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "designstonego.com.br"] [uri "/we.php"] [unique_id "aoSDV2r_JutbFb-8svrwyQAAAfI"] [Tue Aug 18 13:07:51.268025 2026] [security2:error] [pid 167459:tid 167663] [client 20.104.100.201:53374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/op.php"] [unique_id "aoSDV2r_JutbFb-8svrwygAAAdk"] [Tue Aug 18 13:07:51.278804 2026] [security2:error] [pid 167459:tid 167519] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDV2r_JutbFb-8svrwywAB_zs"] [Tue Aug 18 13:07:51.279008 2026] [security2:error] [pid 167459:tid 167701] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDV2r_JutbFb-8svrwywAB_zs"] [Tue Aug 18 13:07:51.287512 2026] [security2:error] [pid 167459:tid 167589] [client 172.182.217.32:25564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/ms-files.php"] [unique_id "aoSDV2r_JutbFb-8svrwzQAAAY8"] [Tue Aug 18 13:07:51.301558 2026] [security2:error] [pid 167459:tid 167597] [client 20.65.98.162:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ajax.php"] [unique_id "aoSDV2r_JutbFb-8svrwzwAAAZc"] [Tue Aug 18 13:07:51.304589 2026] [authz_core:error] [pid 167459:tid 167548] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:51.305063 2026] [authz_core:error] [pid 167459:tid 167548] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:51.338763 2026] [security2:error] [pid 167459:tid 167559] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/get.php"] [unique_id "aoSDV2r_JutbFb-8svrw0AABn2M"] [Tue Aug 18 13:07:51.371148 2026] [security2:error] [pid 167459:tid 167555] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDV2r_JutbFb-8svrw0gABpF8"] [Tue Aug 18 13:07:51.392907 2026] [security2:error] [pid 167459:tid 167678] [client 213.35.127.232:55156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDV2r_JutbFb-8svrw2wAAAeg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:51.395479 2026] [security2:error] [pid 167459:tid 167647] [client 20.106.102.5:45277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/155.php"] [unique_id "aoSDV2r_JutbFb-8svrw3AAAAck"] [Tue Aug 18 13:07:51.452011 2026] [security2:error] [pid 167459:tid 167649] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/cc.php"] [unique_id "aoSDV2r_JutbFb-8svrw4gAAAcs"] [Tue Aug 18 13:07:51.455046 2026] [security2:error] [pid 167459:tid 167677] [client 4.232.151.198:35822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDV2r_JutbFb-8svrw4wAAAec"] [Tue Aug 18 13:07:51.478793 2026] [security2:error] [pid 167459:tid 167543] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/backup.sql"] [unique_id "aoSDV2r_JutbFb-8svrw6gAB4FM"] [Tue Aug 18 13:07:51.489534 2026] [security2:error] [pid 167459:tid 167601] [client 135.225.75.187:24636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/X7x.php"] [unique_id "aoSDV2r_JutbFb-8svrw8gAAAZs"] [Tue Aug 18 13:07:51.514339 2026] [security2:error] [pid 167459:tid 167657] [client 52.139.47.57:10132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/aa.php"] [unique_id "aoSDV2r_JutbFb-8svrxAQAAAdM"] [Tue Aug 18 13:07:51.554885 2026] [security2:error] [pid 167459:tid 167587] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/mgrr.php"] [unique_id "aoSDV2r_JutbFb-8svrxGwAB7n8"] [Tue Aug 18 13:07:51.572024 2026] [security2:error] [pid 167459:tid 167489] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDV2r_JutbFb-8svrxIgABlx0"] [Tue Aug 18 13:07:51.602233 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:51.602535 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:51.612004 2026] [autoindex:error] [pid 167459:tid 167599] [client 132.196.30.78:13109] AH01276: Cannot serve directory /home2/anmultimarcas/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:51.629390 2026] [security2:error] [pid 167459:tid 167488] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/images.php"] [unique_id "aoSDV2r_JutbFb-8svrxLgAB0Rw"] [Tue Aug 18 13:07:51.665920 2026] [security2:error] [pid 167459:tid 167688] [client 20.79.204.6:5956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/s.php"] [unique_id "aoSDV2r_JutbFb-8svrxMQAAAfI"] [Tue Aug 18 13:07:51.698670 2026] [security2:error] [pid 167459:tid 167677] [client 40.74.65.169:20770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/155.php"] [unique_id "aoSDV2r_JutbFb-8svrxMgAAAec"] [Tue Aug 18 13:07:51.719390 2026] [security2:error] [pid 167459:tid 167593] [client 20.106.102.5:45260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fasx.php"] [unique_id "aoSDV2r_JutbFb-8svrxMwAAAZM"] [Tue Aug 18 13:07:51.738054 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:20308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/reop3.php"] [unique_id "aoSDV2r_JutbFb-8svrxNQAAAdI"] [Tue Aug 18 13:07:51.752401 2026] [security2:error] [pid 167459:tid 167498] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSDV2r_JutbFb-8svrxOAAB1SY"] [Tue Aug 18 13:07:51.752484 2026] [security2:error] [pid 167459:tid 167600] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/gecko-new.php"] [unique_id "aoSDV2r_JutbFb-8svrxOQAAAZo"] [Tue Aug 18 13:07:51.756786 2026] [security2:error] [pid 167459:tid 167622] [client 132.196.30.78:13109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/php8.php"] [unique_id "aoSDV2r_JutbFb-8svrxOgAAAbA"] [Tue Aug 18 13:07:51.774124 2026] [security2:error] [pid 167459:tid 167630] [client 172.182.217.32:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/options.php"] [unique_id "aoSDV2r_JutbFb-8svrxOwAAAbg"] [Tue Aug 18 13:07:51.845755 2026] [security2:error] [pid 167459:tid 167664] [client 52.87.72.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jlyclimatizacao.com.br"] [uri "/index.php"] [unique_id "aoSDVmr_JutbFb-8svrwZgAB2iA"], referer: https://jlyclimatizacao.com.br/ [Tue Aug 18 13:07:51.906969 2026] [security2:error] [pid 167459:tid 167614] [client 135.225.75.187:23825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ocxla.php"] [unique_id "aoSDV2r_JutbFb-8svrxPwAAAag"] [Tue Aug 18 13:07:51.920492 2026] [security2:error] [pid 167459:tid 167486] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/alls.php"] [unique_id "aoSDV2r_JutbFb-8svrxQQABxRo"] [Tue Aug 18 13:07:51.925032 2026] [security2:error] [pid 167459:tid 167701] [client 52.139.47.57:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/abc.php"] [unique_id "aoSDV2r_JutbFb-8svrxQgAAAf8"] [Tue Aug 18 13:07:51.926522 2026] [security2:error] [pid 167459:tid 167525] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/mini.php"] [unique_id "aoSDV2r_JutbFb-8svrxQwAB-0E"] [Tue Aug 18 13:07:51.935079 2026] [security2:error] [pid 167459:tid 167513] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDV2r_JutbFb-8svrxRQABlDU"] [Tue Aug 18 13:07:51.977952 2026] [security2:error] [pid 167459:tid 167623] [client 172.202.39.151:39228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDV2r_JutbFb-8svrxSAAAAbE"] [Tue Aug 18 13:07:52.020354 2026] [security2:error] [pid 167459:tid 167675] [client 37.40.227.74:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWGr_JutbFb-8svrxSgAAAeU"] [Tue Aug 18 13:07:52.020538 2026] [security2:error] [pid 167459:tid 167675] [client 37.40.227.74:56885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWGr_JutbFb-8svrxSgAAAeU"] [Tue Aug 18 13:07:52.042835 2026] [security2:error] [pid 167459:tid 167669] [client 20.106.102.5:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-good.php"] [unique_id "aoSDWGr_JutbFb-8svrxTAAAAd8"] [Tue Aug 18 13:07:52.043922 2026] [security2:error] [pid 167459:tid 167676] [client 74.248.18.37:37394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/alfa-v4.php"] [unique_id "aoSDWGr_JutbFb-8svrxTQAAAeY"] [Tue Aug 18 13:07:52.067633 2026] [security2:error] [pid 167459:tid 167707] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content.php.php"] [unique_id "aoSDWGr_JutbFb-8svrxVAAAAgU"] [Tue Aug 18 13:07:52.110694 2026] [security2:error] [pid 167459:tid 167527] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/minishell.php"] [unique_id "aoSDWGr_JutbFb-8svrxVwAB6EM"] [Tue Aug 18 13:07:52.114706 2026] [security2:error] [pid 167459:tid 167541] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSDWGr_JutbFb-8svrxWAABzFE"] [Tue Aug 18 13:07:52.174513 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.100.201:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDWGr_JutbFb-8svrxWgAAAY8"] [Tue Aug 18 13:07:52.176449 2026] [security2:error] [pid 167459:tid 167627] [client 20.151.109.219:28772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/qh.php"] [unique_id "aoSDWGr_JutbFb-8svrxWwAAAbU"] [Tue Aug 18 13:07:52.193712 2026] [security2:error] [pid 167459:tid 167708] [client 20.116.17.175:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSDWGr_JutbFb-8svrxYAAAAgY"] [Tue Aug 18 13:07:52.201147 2026] [security2:error] [pid 167459:tid 167671] [client 20.226.36.136:23218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDWGr_JutbFb-8svrxZgAAAeE"] [Tue Aug 18 13:07:52.204954 2026] [authz_core:error] [pid 167459:tid 167470] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:52.205248 2026] [authz_core:error] [pid 167459:tid 167470] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:52.212107 2026] [security2:error] [pid 167459:tid 167561] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/coffexium.php"] [unique_id "aoSDWGr_JutbFb-8svrxbAAB52U"] [Tue Aug 18 13:07:52.247766 2026] [security2:error] [pid 167459:tid 167661] [client 20.116.17.175:20342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/php5.php"] [unique_id "aoSDWGr_JutbFb-8svrxcwAAAdc"] [Tue Aug 18 13:07:52.263882 2026] [security2:error] [pid 167459:tid 167655] [client 172.182.217.32:25556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/security.php"] [unique_id "aoSDWGr_JutbFb-8svrxegAAAdE"] [Tue Aug 18 13:07:52.294627 2026] [security2:error] [pid 167459:tid 167582] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/mm.php"] [unique_id "aoSDWGr_JutbFb-8svrxgAABxXo"] [Tue Aug 18 13:07:52.327866 2026] [security2:error] [pid 167459:tid 167662] [client 172.202.39.151:39181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDWGr_JutbFb-8svrxkAAAAdg"] [Tue Aug 18 13:07:52.333853 2026] [security2:error] [pid 167459:tid 167653] [client 135.225.75.187:11594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/post.php"] [unique_id "aoSDWGr_JutbFb-8svrxkgAAAc8"] [Tue Aug 18 13:07:52.336470 2026] [security2:error] [pid 167459:tid 167608] [client 52.139.47.57:10167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/av.php"] [unique_id "aoSDWGr_JutbFb-8svrxkwAAAaI"] [Tue Aug 18 13:07:52.354873 2026] [security2:error] [pid 167459:tid 167595] [client 20.79.204.6:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/s93.php"] [unique_id "aoSDWGr_JutbFb-8svrxlgAAAZU"] [Tue Aug 18 13:07:52.368141 2026] [security2:error] [pid 167459:tid 167621] [client 20.106.102.5:45190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/zxin.php"] [unique_id "aoSDWGr_JutbFb-8svrxmQAAAa8"] [Tue Aug 18 13:07:52.369796 2026] [security2:error] [pid 167459:tid 167607] [client 132.196.30.78:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDWGr_JutbFb-8svrxmgAAAaE"] [Tue Aug 18 13:07:52.379805 2026] [security2:error] [pid 167459:tid 167712] [client 20.250.13.23:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/ws54.php"] [unique_id "aoSDWGr_JutbFb-8svrxnQAAAgo"] [Tue Aug 18 13:07:52.402686 2026] [security2:error] [pid 167459:tid 167710] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/01.php"] [unique_id "aoSDWGr_JutbFb-8svrxowAAAgg"] [Tue Aug 18 13:07:52.418295 2026] [security2:error] [pid 167459:tid 167689] [client 213.35.127.232:55391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDWGr_JutbFb-8svrxpAAAAfM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:52.469067 2026] [security2:error] [pid 167459:tid 167667] [client 149.34.210.141:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDWGr_JutbFb-8svrxqwAAAd0"] [Tue Aug 18 13:07:52.497375 2026] [security2:error] [pid 167459:tid 167570] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDWGr_JutbFb-8svrxrgACAm4"] [Tue Aug 18 13:07:52.498917 2026] [security2:error] [pid 167459:tid 167618] [client 40.74.65.169:21364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ops.php"] [unique_id "aoSDWGr_JutbFb-8svrxrwAAAaw"] [Tue Aug 18 13:07:52.502654 2026] [security2:error] [pid 167459:tid 167494] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/red.php"] [unique_id "aoSDWGr_JutbFb-8svrxsgAB8SI"] [Tue Aug 18 13:07:52.634022 2026] [security2:error] [pid 167459:tid 167496] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDWGr_JutbFb-8svrxvAABwiQ"] [Tue Aug 18 13:07:52.691614 2026] [security2:error] [pid 167459:tid 167629] [client 20.106.102.5:45194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/pass4.php"] [unique_id "aoSDWGr_JutbFb-8svrxvwAAAbc"] [Tue Aug 18 13:07:52.726092 2026] [security2:error] [pid 167459:tid 167671] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/lv.php"] [unique_id "aoSDWGr_JutbFb-8svrxwAAAAeE"] [Tue Aug 18 13:07:52.740345 2026] [security2:error] [pid 167459:tid 167667] [client 149.34.210.141:50980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDWGr_JutbFb-8svrxqwAAAd0"] [Tue Aug 18 13:07:52.743755 2026] [security2:error] [pid 167459:tid 167490] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ms-themes.php"] [unique_id "aoSDWGr_JutbFb-8svrxwgAB5B4"] [Tue Aug 18 13:07:52.750861 2026] [security2:error] [pid 167459:tid 167630] [client 135.225.75.187:31828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/nhr.php"] [unique_id "aoSDWGr_JutbFb-8svrxxAAAAbg"] [Tue Aug 18 13:07:52.751660 2026] [security2:error] [pid 167459:tid 167633] [client 20.171.51.14:45585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/45.php"] [unique_id "aoSDWGr_JutbFb-8svrxxQAAAbs"] [Tue Aug 18 13:07:52.755148 2026] [security2:error] [pid 167459:tid 167650] [client 172.182.217.32:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/test.php"] [unique_id "aoSDWGr_JutbFb-8svrxxwAAAcw"] [Tue Aug 18 13:07:52.758246 2026] [security2:error] [pid 167459:tid 167608] [client 52.139.47.57:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSDWGr_JutbFb-8svrxyAAAAaI"] [Tue Aug 18 13:07:52.809650 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:52.810050 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:52.810623 2026] [security2:error] [pid 167459:tid 167515] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/sodium_compat/"] [unique_id "aoSDWGr_JutbFb-8svrxzQABlzc"] [Tue Aug 18 13:07:52.812963 2026] [security2:error] [pid 167459:tid 167651] [client 68.221.73.131:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/.admin.php"] [unique_id "aoSDWGr_JutbFb-8svrxzgAAAc0"] [Tue Aug 18 13:07:52.859373 2026] [security2:error] [pid 167459:tid 167591] [client 74.248.18.37:6772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/abby.php"] [unique_id "aoSDWGr_JutbFb-8svrx0gAAAZE"] [Tue Aug 18 13:07:52.884068 2026] [security2:error] [pid 167459:tid 167628] [client 20.104.100.201:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/xyn.php"] [unique_id "aoSDWGr_JutbFb-8svrx0wAAAbY"] [Tue Aug 18 13:07:52.885134 2026] [security2:error] [pid 167459:tid 167657] [client 172.202.39.151:39196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/admin.php"] [unique_id "aoSDWGr_JutbFb-8svrx1AAAAdM"] [Tue Aug 18 13:07:52.888229 2026] [security2:error] [pid 167459:tid 167607] [client 132.196.30.78:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/222.php"] [unique_id "aoSDWGr_JutbFb-8svrx1QAAAaE"] [Tue Aug 18 13:07:52.927782 2026] [security2:error] [pid 167459:tid 167506] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/my1.php"] [unique_id "aoSDWGr_JutbFb-8svrx2wABnS4"] [Tue Aug 18 13:07:52.928527 2026] [security2:error] [pid 167459:tid 167676] [client 20.206.73.37:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ai.php"] [unique_id "aoSDWGr_JutbFb-8svrx3AAAAeY"] [Tue Aug 18 13:07:52.968643 2026] [security2:error] [pid 167459:tid 167536] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDWGr_JutbFb-8svrx5AAB8Uw"] [Tue Aug 18 13:07:52.976707 2026] [security2:error] [pid 167459:tid 167696] [client 128.140.106.114:57816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSDV2r_JutbFb-8svrxRAAAAfo"], referer: https://www.idealquimica.com [Tue Aug 18 13:07:52.991077 2026] [security2:error] [pid 167459:tid 167712] [client 20.79.204.6:5719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/server.php"] [unique_id "aoSDWGr_JutbFb-8svrx5gAAAgo"] [Tue Aug 18 13:07:52.995847 2026] [security2:error] [pid 167459:tid 167639] [client 4.232.151.198:16545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/g.php"] [unique_id "aoSDWGr_JutbFb-8svrx5wAAAcE"] [Tue Aug 18 13:07:53.005216 2026] [security2:error] [pid 167459:tid 167679] [client 20.116.17.175:20248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/acp.php"] [unique_id "aoSDWWr_JutbFb-8svrx6AAAAek"] [Tue Aug 18 13:07:53.013187 2026] [security2:error] [pid 167459:tid 167703] [client 20.106.102.5:45241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDWWr_JutbFb-8svrx6gAAAgE"] [Tue Aug 18 13:07:53.014669 2026] [security2:error] [pid 167459:tid 167636] [client 20.104.100.201:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/black.php"] [unique_id "aoSDWWr_JutbFb-8svrx6wAAAb4"] [Tue Aug 18 13:07:53.024093 2026] [security2:error] [pid 167459:tid 167675] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/new.php"] [unique_id "aoSDWWr_JutbFb-8svrx7AAAAeU"] [Tue Aug 18 13:07:53.094485 2026] [security2:error] [pid 167459:tid 167495] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "inovartararas.com.br"] [uri "/trace.axd"] [unique_id "aoSDWWr_JutbFb-8svrx8AABkCM"] [Tue Aug 18 13:07:53.100854 2026] [security2:error] [pid 167459:tid 167492] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/Text/"] [unique_id "aoSDWWr_JutbFb-8svrx8QACBSA"] [Tue Aug 18 13:07:53.112185 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:53.112617 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:53.113474 2026] [security2:error] [pid 167459:tid 167641] [client 20.116.17.175:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/png.php"] [unique_id "aoSDWWr_JutbFb-8svrx9AAAAcM"] [Tue Aug 18 13:07:53.142164 2026] [security2:error] [pid 167459:tid 167698] [client 4.232.151.198:11430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/404.php"] [unique_id "aoSDWWr_JutbFb-8svrx9QAAAfw"] [Tue Aug 18 13:07:53.163003 2026] [security2:error] [pid 167459:tid 167497] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/new.php"] [unique_id "aoSDWWr_JutbFb-8svrx-QABtSU"] [Tue Aug 18 13:07:53.168706 2026] [security2:error] [pid 167459:tid 167708] [client 135.225.75.187:24607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDWWr_JutbFb-8svrx-gAAAgY"] [Tue Aug 18 13:07:53.174982 2026] [security2:error] [pid 167459:tid 167623] [client 52.139.47.57:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/asus.php"] [unique_id "aoSDWWr_JutbFb-8svrx-wAAAbE"] [Tue Aug 18 13:07:53.215457 2026] [security2:error] [pid 167459:tid 167659] [client 20.151.109.219:36292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/r.php"] [unique_id "aoSDWWr_JutbFb-8svrx_wAAAdU"] [Tue Aug 18 13:07:53.228769 2026] [security2:error] [pid 167459:tid 167517] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSDWWr_JutbFb-8svryAAAB3Tk"] [Tue Aug 18 13:07:53.251736 2026] [security2:error] [pid 167459:tid 167715] [client 172.182.217.32:25579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDWWr_JutbFb-8svryAQAAAg0"] [Tue Aug 18 13:07:53.282437 2026] [security2:error] [pid 167459:tid 167706] [client 40.74.65.169:20553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/mac.php"] [unique_id "aoSDWWr_JutbFb-8svryAgAAAgQ"] [Tue Aug 18 13:07:53.307588 2026] [authz_core:error] [pid 167459:tid 167527] [remote 35.247.121.182:0] AH01630: client denied by server configuration: /home3/inovartararas/public_html/error_log [Tue Aug 18 13:07:53.334811 2026] [security2:error] [pid 167459:tid 167640] [client 172.202.39.151:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/public/css.php"] [unique_id "aoSDWWr_JutbFb-8svryBgAAAcI"] [Tue Aug 18 13:07:53.343740 2026] [security2:error] [pid 167459:tid 167677] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/222.php"] [unique_id "aoSDWWr_JutbFb-8svryCAAAAec"] [Tue Aug 18 13:07:53.344158 2026] [security2:error] [pid 167459:tid 167634] [client 20.106.102.5:45264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/z.php"] [unique_id "aoSDWWr_JutbFb-8svryCQAAAbw"] [Tue Aug 18 13:07:53.349366 2026] [security2:error] [pid 167459:tid 167523] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/norn.php"] [unique_id "aoSDWWr_JutbFb-8svryCwAB4D8"] [Tue Aug 18 13:07:53.390964 2026] [security2:error] [pid 167459:tid 167559] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/uploads/"] [unique_id "aoSDWWr_JutbFb-8svryEQABkWM"] [Tue Aug 18 13:07:53.402163 2026] [security2:error] [pid 167459:tid 167556] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSDWWr_JutbFb-8svryEgABmmA"] [Tue Aug 18 13:07:53.410157 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:53.410451 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:53.434083 2026] [security2:error] [pid 167459:tid 167705] [client 213.35.127.232:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDWWr_JutbFb-8svryFAAAAgM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:53.448441 2026] [security2:error] [pid 167459:tid 167661] [client 20.226.36.136:41475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDWWr_JutbFb-8svryFQAAAdc"] [Tue Aug 18 13:07:53.454155 2026] [security2:error] [pid 167459:tid 167561] [remote 103.56.163.133:54872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.163.56.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "castroeferres.com.br"] [uri "/wp-login.php"] [unique_id "aoSDWWr_JutbFb-8svryFgABp2U"] [Tue Aug 18 13:07:53.470989 2026] [security2:error] [pid 167459:tid 167684] [client 157.20.138.62:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWWr_JutbFb-8svryGAAAAe4"] [Tue Aug 18 13:07:53.471127 2026] [security2:error] [pid 167459:tid 167684] [client 157.20.138.62:54982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWWr_JutbFb-8svryGAAAAe4"] [Tue Aug 18 13:07:53.518093 2026] [security2:error] [pid 167459:tid 167649] [client 132.196.30.78:13068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDWWr_JutbFb-8svryGQAAAcs"] [Tue Aug 18 13:07:53.543082 2026] [security2:error] [pid 167459:tid 167555] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/num.php"] [unique_id "aoSDWWr_JutbFb-8svryGgAB5l8"] [Tue Aug 18 13:07:53.574668 2026] [security2:error] [pid 167459:tid 167508] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSDWWr_JutbFb-8svryHQABtDA"] [Tue Aug 18 13:07:53.586304 2026] [security2:error] [pid 167459:tid 167699] [client 135.225.75.187:21457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ws79.php"] [unique_id "aoSDWWr_JutbFb-8svryHgAAAf0"] [Tue Aug 18 13:07:53.628118 2026] [security2:error] [pid 167459:tid 167616] [client 52.139.47.57:20163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/about.php"] [unique_id "aoSDWWr_JutbFb-8svryIAAAAao"] [Tue Aug 18 13:07:53.634669 2026] [security2:error] [pid 167459:tid 167624] [client 20.104.100.201:9575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/txets.php"] [unique_id "aoSDWWr_JutbFb-8svryIQAAAbI"] [Tue Aug 18 13:07:53.636867 2026] [security2:error] [pid 167459:tid 167620] [client 74.248.18.37:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/Mhbgf.php"] [unique_id "aoSDWWr_JutbFb-8svryIgAAAa4"] [Tue Aug 18 13:07:53.646502 2026] [security2:error] [pid 167459:tid 167704] [client 172.202.39.151:39178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDWWr_JutbFb-8svryJAAAAgI"] [Tue Aug 18 13:07:53.649489 2026] [security2:error] [pid 167459:tid 167688] [client 20.127.136.245:9491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDWWr_JutbFb-8svryJQAAAfI"] [Tue Aug 18 13:07:53.650020 2026] [security2:error] [pid 167459:tid 167697] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/chosen.php"] [unique_id "aoSDWWr_JutbFb-8svryJgAAAfs"] [Tue Aug 18 13:07:53.668475 2026] [security2:error] [pid 167459:tid 167687] [client 20.106.102.5:45191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/222.php"] [unique_id "aoSDWWr_JutbFb-8svryKAAAAfE"] [Tue Aug 18 13:07:53.684481 2026] [security2:error] [pid 167459:tid 167535] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDWWr_JutbFb-8svryKQAB-ks"] [Tue Aug 18 13:07:53.702342 2026] [security2:error] [pid 167459:tid 167709] [client 4.232.151.198:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/gecko.php"] [unique_id "aoSDWWr_JutbFb-8svryKgAAAgc"] [Tue Aug 18 13:07:53.712232 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:53.712492 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:53.718562 2026] [security2:error] [pid 167459:tid 167712] [client 20.116.17.175:52885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ab.php"] [unique_id "aoSDWWr_JutbFb-8svryLAAAAgo"] [Tue Aug 18 13:07:53.724264 2026] [security2:error] [pid 167459:tid 167647] [client 20.79.204.6:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/settings.php"] [unique_id "aoSDWWr_JutbFb-8svryLQAAAck"] [Tue Aug 18 13:07:53.735785 2026] [security2:error] [pid 167459:tid 167538] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/options-reading.php"] [unique_id "aoSDWWr_JutbFb-8svryLgAB_04"] [Tue Aug 18 13:07:53.746659 2026] [security2:error] [pid 167459:tid 167643] [client 172.182.217.32:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/wp-blog-header.php"] [unique_id "aoSDWWr_JutbFb-8svryMQAAAcU"] [Tue Aug 18 13:07:53.762785 2026] [security2:error] [pid 167459:tid 167675] [client 68.221.73.131:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/wsomini.php"] [unique_id "aoSDWWr_JutbFb-8svryNAAAAeU"] [Tue Aug 18 13:07:53.793314 2026] [security2:error] [pid 167459:tid 167663] [client 20.116.17.175:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/yas.php"] [unique_id "aoSDWWr_JutbFb-8svryNQAAAdk"] [Tue Aug 18 13:07:53.827805 2026] [security2:error] [pid 167459:tid 167645] [client 65.21.237.14:58922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.cadema.com.br"] [uri "/index.php"] [unique_id "aoSDWGr_JutbFb-8svrxkQAAAcc"] [Tue Aug 18 13:07:53.851098 2026] [security2:error] [pid 167459:tid 167621] [client 88.99.80.227:56926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSDWWr_JutbFb-8svryNgAAAa8"], referer: http://www.idealquimica.com [Tue Aug 18 13:07:53.888849 2026] [security2:error] [pid 167459:tid 167673] [client 20.65.98.162:52993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/yj09.php"] [unique_id "aoSDWWr_JutbFb-8svryOwAAAeM"] [Tue Aug 18 13:07:53.915297 2026] [security2:error] [pid 167459:tid 167659] [client 20.127.136.245:1531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDWWr_JutbFb-8svryPAAAAdU"] [Tue Aug 18 13:07:53.916173 2026] [security2:error] [pid 167459:tid 167669] [client 20.206.73.37:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/m.php"] [unique_id "aoSDWWr_JutbFb-8svryPQAAAd8"] [Tue Aug 18 13:07:53.924422 2026] [security2:error] [pid 167459:tid 167491] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ors32envu.php"] [unique_id "aoSDWWr_JutbFb-8svryPwAB1h8"] [Tue Aug 18 13:07:53.929030 2026] [security2:error] [pid 167459:tid 167543] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDWWr_JutbFb-8svryQAAB3VM"] [Tue Aug 18 13:07:53.954028 2026] [security2:error] [pid 167459:tid 167710] [client 20.226.36.136:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDWWr_JutbFb-8svryRAAAAgg"] [Tue Aug 18 13:07:53.974899 2026] [security2:error] [pid 167459:tid 167566] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/admin.php"] [unique_id "aoSDWWr_JutbFb-8svryRQABuGo"] [Tue Aug 18 13:07:53.985927 2026] [security2:error] [pid 167459:tid 167691] [client 178.153.171.161:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWWr_JutbFb-8svryRwAAAfU"] [Tue Aug 18 13:07:53.986061 2026] [security2:error] [pid 167459:tid 167691] [client 178.153.171.161:45396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDWWr_JutbFb-8svryRwAAAfU"] [Tue Aug 18 13:07:53.992800 2026] [security2:error] [pid 167459:tid 167652] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/info.php"] [unique_id "aoSDWWr_JutbFb-8svrySQAAAc4"] [Tue Aug 18 13:07:53.993686 2026] [security2:error] [pid 167459:tid 167640] [client 20.106.102.5:45250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/G-in.php"] [unique_id "aoSDWWr_JutbFb-8svrySgAAAcI"] [Tue Aug 18 13:07:54.002149 2026] [security2:error] [pid 167459:tid 167702] [client 135.225.75.187:23003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/rtx.php"] [unique_id "aoSDWmr_JutbFb-8svrySwAAAgA"] [Tue Aug 18 13:07:54.048709 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:27815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/atomlib.php"] [unique_id "aoSDWmr_JutbFb-8svryTwAAAbc"] [Tue Aug 18 13:07:54.049554 2026] [security2:error] [pid 167459:tid 167589] [client 4.232.151.198:26126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wk/index.php"] [unique_id "aoSDWmr_JutbFb-8svryUAAAAY8"] [Tue Aug 18 13:07:54.102932 2026] [security2:error] [pid 167459:tid 167560] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDWmr_JutbFb-8svryUgABkWQ"] [Tue Aug 18 13:07:54.104154 2026] [security2:error] [pid 167459:tid 167504] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ov-simple1.php"] [unique_id "aoSDWmr_JutbFb-8svryUwABmiw"] [Tue Aug 18 13:07:54.163182 2026] [security2:error] [pid 167459:tid 167579] [remote 35.247.121.182:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "inovartararas.com.br"] [uri "/server-info"] [unique_id "aoSDWmr_JutbFb-8svryVwAB7nc"] [Tue Aug 18 13:07:54.237665 2026] [security2:error] [pid 167459:tid 167693] [client 172.182.217.32:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/wp-mail.php"] [unique_id "aoSDWmr_JutbFb-8svryWwAAAfc"] [Tue Aug 18 13:07:54.266093 2026] [security2:error] [pid 167459:tid 167581] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file52.php"] [unique_id "aoSDWmr_JutbFb-8svryXQABl3k"] [Tue Aug 18 13:07:54.279456 2026] [security2:error] [pid 167459:tid 167644] [client 132.196.30.78:20313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/info.php"] [unique_id "aoSDWmr_JutbFb-8svryXwAAAcY"] [Tue Aug 18 13:07:54.285142 2026] [security2:error] [pid 167459:tid 167521] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ova.php"] [unique_id "aoSDWmr_JutbFb-8svryYAAB5j0"] [Tue Aug 18 13:07:54.299576 2026] [security2:error] [pid 167459:tid 167635] [client 20.151.109.219:58359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/17.php"] [unique_id "aoSDWmr_JutbFb-8svryYgAAAb0"] [Tue Aug 18 13:07:54.306663 2026] [security2:error] [pid 167459:tid 167716] [client 172.202.39.151:27841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDWmr_JutbFb-8svryYwAAAg4"] [Tue Aug 18 13:07:54.310238 2026] [security2:error] [pid 167459:tid 167528] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDWmr_JutbFb-8svryZgABskQ"] [Tue Aug 18 13:07:54.316481 2026] [authz_core:error] [pid 167459:tid 167553] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:54.316910 2026] [authz_core:error] [pid 167459:tid 167553] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:54.321840 2026] [security2:error] [pid 167459:tid 167619] [client 20.106.102.5:45214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xxx.php"] [unique_id "aoSDWmr_JutbFb-8svryaAAAAa0"] [Tue Aug 18 13:07:54.325413 2026] [security2:error] [pid 167459:tid 167628] [client 4.232.151.198:16525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/gettest.php"] [unique_id "aoSDWmr_JutbFb-8svryaQAAAbY"] [Tue Aug 18 13:07:54.354127 2026] [security2:error] [pid 167459:tid 167671] [client 20.250.13.23:45217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDWmr_JutbFb-8svryagAAAeE"] [Tue Aug 18 13:07:54.355032 2026] [security2:error] [pid 167459:tid 167705] [client 74.248.18.37:7028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/endpoints/class-wp-rest-attachment-controller.php"] [unique_id "aoSDWmr_JutbFb-8svryawAAAgM"] [Tue Aug 18 13:07:54.420712 2026] [security2:error] [pid 167459:tid 167713] [client 20.104.100.201:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/as.php"] [unique_id "aoSDWmr_JutbFb-8svrycAAAAgs"] [Tue Aug 18 13:07:54.425708 2026] [security2:error] [pid 167459:tid 167643] [client 135.225.75.187:24592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/end.php"] [unique_id "aoSDWmr_JutbFb-8svrycQAAAcU"] [Tue Aug 18 13:07:54.433426 2026] [security2:error] [pid 167459:tid 167675] [client 20.226.36.136:34128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDWmr_JutbFb-8svrycgAAAeU"] [Tue Aug 18 13:07:54.435316 2026] [security2:error] [pid 167459:tid 167666] [client 207.175.174.249:23162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "aoSDWmr_JutbFb-8svrycwAAAdw"] [Tue Aug 18 13:07:54.435636 2026] [security2:error] [pid 167459:tid 167700] [client 207.175.174.249:23112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDWmr_JutbFb-8svryegAAAf4"] [Tue Aug 18 13:07:54.436145 2026] [security2:error] [pid 167459:tid 167654] [client 207.175.174.249:23102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDWmr_JutbFb-8svryfAAAAdA"] [Tue Aug 18 13:07:54.436556 2026] [security2:error] [pid 167459:tid 167698] [client 207.175.174.249:23002] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/config"] [unique_id "aoSDWmr_JutbFb-8svryfgAAAfw"] [Tue Aug 18 13:07:54.438288 2026] [security2:error] [pid 167459:tid 167621] [client 207.175.174.249:23064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "aoSDWmr_JutbFb-8svrygwAAAa8"] [Tue Aug 18 13:07:54.438415 2026] [security2:error] [pid 167459:tid 167592] [client 207.175.174.249:23048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/download"] [unique_id "aoSDWmr_JutbFb-8svryggAAAZI"] [Tue Aug 18 13:07:54.438686 2026] [security2:error] [pid 167459:tid 167653] [client 207.175.174.249:22952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aoSDWmr_JutbFb-8svryhQAAAc8"] [Tue Aug 18 13:07:54.439083 2026] [security2:error] [pid 167459:tid 167673] [client 207.175.174.249:23024] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.git-credentials"] [unique_id "aoSDWmr_JutbFb-8svryiQAAAeM"] [Tue Aug 18 13:07:54.439181 2026] [security2:error] [pid 167459:tid 167708] [client 207.175.174.249:22948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/files../etc/passwd"] [unique_id "aoSDWmr_JutbFb-8svryhwAAAgY"] [Tue Aug 18 13:07:54.439339 2026] [security2:error] [pid 167459:tid 167623] [client 207.175.174.249:22988] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proc/self/environ"] [unique_id "aoSDWmr_JutbFb-8svryigAAAbE"] [Tue Aug 18 13:07:54.439682 2026] [security2:error] [pid 167459:tid 167656] [client 207.175.174.249:22916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/static../etc/passwd"] [unique_id "aoSDWmr_JutbFb-8svryiAAAAdI"] [Tue Aug 18 13:07:54.440062 2026] [security2:error] [pid 167459:tid 167681] [client 207.175.174.249:22936] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/assets../../../etc/passwd"] [unique_id "aoSDWmr_JutbFb-8svryjgAAAes"] [Tue Aug 18 13:07:54.441275 2026] [security2:error] [pid 167459:tid 167662] [client 207.175.174.249:22846] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDWmr_JutbFb-8svrylAAAAdg"] [Tue Aug 18 13:07:54.441885 2026] [security2:error] [pid 167459:tid 167683] [client 207.175.174.249:22836] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDWmr_JutbFb-8svrylwAAAe0"] [Tue Aug 18 13:07:54.442020 2026] [security2:error] [pid 167459:tid 167710] [client 207.175.174.249:22926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/media../etc/passwd"] [unique_id "aoSDWmr_JutbFb-8svrylQAAAgg"] [Tue Aug 18 13:07:54.442792 2026] [security2:error] [pid 167459:tid 167715] [client 207.175.174.249:22782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aoSDWmr_JutbFb-8svrymAAAAg0"] [Tue Aug 18 13:07:54.442822 2026] [security2:error] [pid 167459:tid 167706] [client 207.175.174.249:22784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/static../.env"] [unique_id "aoSDWmr_JutbFb-8svrymQAAAgQ"] [Tue Aug 18 13:07:54.443524 2026] [security2:error] [pid 167459:tid 167633] [client 207.175.174.249:23072] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/read"] [unique_id "aoSDWmr_JutbFb-8svrynQAAAbs"] [Tue Aug 18 13:07:54.443683 2026] [proxy_http:error] [pid 167459:tid 167658] (20014)Internal error (specific information not available): [client 207.175.174.249:22986] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.443695 2026] [proxy:error] [pid 167459:tid 167658] [client 207.175.174.249:22986] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws/credentials [Tue Aug 18 13:07:54.444042 2026] [security2:error] [pid 167459:tid 167640] [client 207.175.174.249:23182] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/static../.aws/credentials"] [unique_id "aoSDWmr_JutbFb-8svryoAAAAcI"] [Tue Aug 18 13:07:54.444191 2026] [security2:error] [pid 167459:tid 167652] [client 207.175.174.249:22826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/media../.env"] [unique_id "aoSDWmr_JutbFb-8svrynwAAAc4"] [Tue Aug 18 13:07:54.449549 2026] [security2:error] [pid 167459:tid 167646] [client 213.35.127.232:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDWmr_JutbFb-8svryoQAAAcg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:54.450279 2026] [proxy_http:error] [pid 167459:tid 167707] (20014)Internal error (specific information not available): [client 207.175.174.249:23030] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.450291 2026] [proxy:error] [pid 167459:tid 167707] [client 207.175.174.249:23030] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.mcp.json [Tue Aug 18 13:07:54.456522 2026] [proxy_http:error] [pid 167459:tid 167663] (20014)Internal error (specific information not available): [client 207.175.174.249:23146] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: http://cpanel.vindimo.com.br [Tue Aug 18 13:07:54.456539 2026] [proxy:error] [pid 167459:tid 167663] [client 207.175.174.249:23146] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/graphql/console, referer: http://cpanel.vindimo.com.br [Tue Aug 18 13:07:54.461225 2026] [security2:error] [pid 167459:tid 167688] [client 52.139.47.57:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDWmr_JutbFb-8svryogAAAfI"] [Tue Aug 18 13:07:54.463217 2026] [proxy_http:error] [pid 167459:tid 167645] (20014)Internal error (specific information not available): [client 207.175.174.249:23108] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.463230 2026] [proxy:error] [pid 167459:tid 167645] [client 207.175.174.249:23108] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/fetch [Tue Aug 18 13:07:54.468685 2026] [proxy_http:error] [pid 167459:tid 167622] (20014)Internal error (specific information not available): [client 207.175.174.249:22898] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.468695 2026] [proxy:error] [pid 167459:tid 167622] [client 207.175.174.249:22898] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/etc/passwd [Tue Aug 18 13:07:54.474291 2026] [proxy_http:error] [pid 167459:tid 167623] (20014)Internal error (specific information not available): [client 207.175.174.249:22988] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.474310 2026] [proxy:error] [pid 167459:tid 167623] [client 207.175.174.249:22988] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html [Tue Aug 18 13:07:54.480334 2026] [proxy_http:error] [pid 167459:tid 167595] (20014)Internal error (specific information not available): [client 207.175.174.249:22964] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.480348 2026] [proxy:error] [pid 167459:tid 167595] [client 207.175.174.249:22964] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.local [Tue Aug 18 13:07:54.485855 2026] [proxy_http:error] [pid 167459:tid 167667] (20014)Internal error (specific information not available): [client 207.175.174.249:23008] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.485878 2026] [proxy:error] [pid 167459:tid 167667] [client 207.175.174.249:23008] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.git/HEAD [Tue Aug 18 13:07:54.493159 2026] [security2:error] [pid 167459:tid 167651] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDWmr_JutbFb-8svryqAAAAc0"] [Tue Aug 18 13:07:54.524652 2026] [security2:error] [pid 167459:tid 167704] [client 20.79.204.6:5953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/sf.php"] [unique_id "aoSDWmr_JutbFb-8svryrAAAAgI"] [Tue Aug 18 13:07:54.557691 2026] [security2:error] [pid 167459:tid 167462] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/geck.php"] [unique_id "aoSDWmr_JutbFb-8svryrwAB-AI"] [Tue Aug 18 13:07:54.574604 2026] [security2:error] [pid 167459:tid 167686] [client 20.171.51.14:22201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wy.php"] [unique_id "aoSDWmr_JutbFb-8svrytAAAAfA"] [Tue Aug 18 13:07:54.601116 2026] [proxy_http:error] [pid 167459:tid 167692] (20014)Internal error (specific information not available): [client 207.175.174.249:22850] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.601132 2026] [proxy:error] [pid 167459:tid 167692] [client 207.175.174.249:22850] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/proc/1/environ [Tue Aug 18 13:07:54.607734 2026] [proxy_http:error] [pid 167459:tid 167711] (20014)Internal error (specific information not available): [client 207.175.174.249:22868] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.607747 2026] [proxy:error] [pid 167459:tid 167711] [client 207.175.174.249:22868] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/credentials [Tue Aug 18 13:07:54.608101 2026] [security2:error] [pid 167459:tid 167676] [client 20.206.73.37:26520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/33.php"] [unique_id "aoSDWmr_JutbFb-8svryuAAAAeY"] [Tue Aug 18 13:07:54.614073 2026] [proxy_http:error] [pid 167459:tid 167633] (20014)Internal error (specific information not available): [client 207.175.174.249:23072] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.614092 2026] [proxy:error] [pid 167459:tid 167633] [client 207.175.174.249:23072] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html [Tue Aug 18 13:07:54.614867 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:54.615132 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:54.616826 2026] [security2:error] [pid 167459:tid 167619] [client 20.116.17.175:20288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ah25.php"] [unique_id "aoSDWmr_JutbFb-8svryuwAAAa0"] [Tue Aug 18 13:07:54.622757 2026] [security2:error] [pid 167459:tid 167628] [client 20.127.136.245:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/admin.php"] [unique_id "aoSDWmr_JutbFb-8svryvQAAAbY"] [Tue Aug 18 13:07:54.643101 2026] [security2:error] [pid 167459:tid 167494] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/p.php"] [unique_id "aoSDWmr_JutbFb-8svrywAACCiI"] [Tue Aug 18 13:07:54.644964 2026] [security2:error] [pid 167459:tid 167638] [client 88.99.80.227:48006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.idealquimica.com"] [uri "/index.php"] [unique_id "aoSDWmr_JutbFb-8svrykQAAAcA"], referer: http://www.idealquimica.com [Tue Aug 18 13:07:54.645844 2026] [security2:error] [pid 167459:tid 167639] [client 20.106.102.5:45191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/un.php"] [unique_id "aoSDWmr_JutbFb-8svrywgAAAcE"] [Tue Aug 18 13:07:54.707090 2026] [security2:error] [pid 167459:tid 167675] [client 104.209.144.33:32680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDWmr_JutbFb-8svryxwAAAeU"] [Tue Aug 18 13:07:54.716992 2026] [security2:error] [pid 167459:tid 167666] [client 68.221.73.131:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.doriccatransportes.com.br"] [uri "/vr.php"] [unique_id "aoSDWmr_JutbFb-8svryyAAAAdw"] [Tue Aug 18 13:07:54.723930 2026] [authz_core:error] [pid 167459:tid 167580] [remote 57.141.22.91:21490] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:54.724191 2026] [authz_core:error] [pid 167459:tid 167580] [remote 57.141.22.91:21490] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:54.726425 2026] [security2:error] [pid 167459:tid 167664] [client 172.182.217.32:25555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/wp-signup.php"] [unique_id "aoSDWmr_JutbFb-8svryygAAAdo"] [Tue Aug 18 13:07:54.734491 2026] [proxy_http:error] [pid 167459:tid 167707] (20014)Internal error (specific information not available): [client 207.175.174.249:23030] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:54.734499 2026] [proxy:error] [pid 167459:tid 167707] [client 207.175.174.249:23030] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Tue Aug 18 13:07:54.803942 2026] [security2:error] [pid 167459:tid 167710] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDWmr_JutbFb-8svry0QAAAgg"] [Tue Aug 18 13:07:54.826567 2026] [security2:error] [pid 167459:tid 167537] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/pages.php"] [unique_id "aoSDWmr_JutbFb-8svry0gABwk0"] [Tue Aug 18 13:07:54.835974 2026] [security2:error] [pid 167459:tid 167650] [client 172.202.39.151:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/gelay.php"] [unique_id "aoSDWmr_JutbFb-8svry1AAAAcw"] [Tue Aug 18 13:07:54.842900 2026] [security2:error] [pid 167459:tid 167702] [client 135.225.75.187:24986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.75.225.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "institutomentevitta.com.br"] [uri "/ae.php"] [unique_id "aoSDWmr_JutbFb-8svry1QAAAgA"] [Tue Aug 18 13:07:54.851547 2026] [security2:error] [pid 167459:tid 167470] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDWmr_JutbFb-8svry1gAByAo"] [Tue Aug 18 13:07:54.874257 2026] [security2:error] [pid 167459:tid 167465] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/biufile.php"] [unique_id "aoSDWmr_JutbFb-8svry2AAB7wU"] [Tue Aug 18 13:07:54.879773 2026] [security2:error] [pid 167459:tid 167688] [client 20.151.109.219:20710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ev.php"] [unique_id "aoSDWmr_JutbFb-8svry2QAAAfI"] [Tue Aug 18 13:07:54.910597 2026] [security2:error] [pid 167459:tid 167657] [client 20.116.17.175:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/12.php"] [unique_id "aoSDWmr_JutbFb-8svry3AAAAdM"] [Tue Aug 18 13:07:54.945394 2026] [security2:error] [pid 167459:tid 167623] [client 40.74.65.169:7144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDWmr_JutbFb-8svry3wAAAbE"] [Tue Aug 18 13:07:54.945406 2026] [security2:error] [pid 167459:tid 167605] [client 52.139.47.57:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/b.php"] [unique_id "aoSDWmr_JutbFb-8svry3gAAAZ8"] [Tue Aug 18 13:07:54.957940 2026] [security2:error] [pid 167459:tid 167592] [client 4.232.151.198:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/goods.php"] [unique_id "aoSDWmr_JutbFb-8svry4AAAAZI"] [Tue Aug 18 13:07:54.967816 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/autogooey.php"] [unique_id "aoSDWmr_JutbFb-8svry4QAAAc0"] [Tue Aug 18 13:07:54.969785 2026] [security2:error] [pid 167459:tid 167700] [client 4.232.151.198:42641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/about.php"] [unique_id "aoSDWmr_JutbFb-8svry4gAAAf4"] [Tue Aug 18 13:07:54.991432 2026] [security2:error] [pid 167459:tid 167616] [client 132.196.30.78:20290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/a.php"] [unique_id "aoSDWmr_JutbFb-8svry4wAAAao"] [Tue Aug 18 13:07:55.014280 2026] [security2:error] [pid 167459:tid 167615] [client 20.127.136.245:14485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/edit.php"] [unique_id "aoSDW2r_JutbFb-8svry5QAAAak"] [Tue Aug 18 13:07:55.025207 2026] [security2:error] [pid 167459:tid 167489] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSDW2r_JutbFb-8svry5wAB-B0"] [Tue Aug 18 13:07:55.066845 2026] [security2:error] [pid 167459:tid 167625] [client 65.21.237.14:48034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cadema.com.br"] [uri "/index.php"] [unique_id "aoSDWmr_JutbFb-8svryzgAAAbM"] [Tue Aug 18 13:07:55.113342 2026] [security2:error] [pid 167459:tid 167610] [client 74.248.18.37:20887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/mimetypes.inc.php"] [unique_id "aoSDW2r_JutbFb-8svry6gAAAaQ"] [Tue Aug 18 13:07:55.129563 2026] [security2:error] [pid 167459:tid 167649] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/k.php"] [unique_id "aoSDW2r_JutbFb-8svry6wAAAcs"] [Tue Aug 18 13:07:55.138154 2026] [security2:error] [pid 167459:tid 167501] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/past.php"] [unique_id "aoSDW2r_JutbFb-8svry7AABuSk"] [Tue Aug 18 13:07:55.164010 2026] [security2:error] [pid 167459:tid 167676] [client 172.202.39.151:39209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDW2r_JutbFb-8svry7gAAAeY"] [Tue Aug 18 13:07:55.170639 2026] [security2:error] [pid 167459:tid 167469] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/dejavu.php"] [unique_id "aoSDW2r_JutbFb-8svry7wABvQk"] [Tue Aug 18 13:07:55.175824 2026] [security2:error] [pid 167459:tid 167591] [client 20.79.204.6:5998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/shell.php"] [unique_id "aoSDW2r_JutbFb-8svry8AAAAZE"] [Tue Aug 18 13:07:55.189140 2026] [security2:error] [pid 167459:tid 167699] [client 20.151.109.219:40463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xs.php"] [unique_id "aoSDW2r_JutbFb-8svry8QAAAf0"] [Tue Aug 18 13:07:55.219314 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:55.219604 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:55.238115 2026] [security2:error] [pid 167459:tid 167619] [client 20.104.100.201:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/index2.php"] [unique_id "aoSDW2r_JutbFb-8svry-AAAAa0"] [Tue Aug 18 13:07:55.241917 2026] [security2:error] [pid 167459:tid 167684] [client 172.182.217.32:4072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/xmlrpc.php"] [unique_id "aoSDW2r_JutbFb-8svry9wAAAe4"] [Tue Aug 18 13:07:55.278562 2026] [security2:error] [pid 167459:tid 167697] [client 20.65.98.162:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/scxy.php"] [unique_id "aoSDW2r_JutbFb-8svry-QAAAfs"] [Tue Aug 18 13:07:55.281729 2026] [security2:error] [pid 167459:tid 167600] [client 20.250.13.23:51346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/function/function.php"] [unique_id "aoSDW2r_JutbFb-8svry-gAAAZo"] [Tue Aug 18 13:07:55.295778 2026] [security2:error] [pid 167459:tid 167609] [client 20.106.102.5:45127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sty.php"] [unique_id "aoSDW2r_JutbFb-8svry_AAAAaM"] [Tue Aug 18 13:07:55.343523 2026] [security2:error] [pid 167459:tid 167495] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/php.php"] [unique_id "aoSDW2r_JutbFb-8svry_QABrCM"] [Tue Aug 18 13:07:55.348852 2026] [security2:error] [pid 167459:tid 167712] [client 20.226.36.136:34504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDW2r_JutbFb-8svry_gAAAgo"] [Tue Aug 18 13:07:55.364579 2026] [security2:error] [pid 167459:tid 167633] [client 52.139.47.57:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/buy.php"] [unique_id "aoSDW2r_JutbFb-8svry_wAAAbs"] [Tue Aug 18 13:07:55.384418 2026] [security2:error] [pid 167459:tid 167557] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDW2r_JutbFb-8svrzAQABwWE"] [Tue Aug 18 13:07:55.432378 2026] [security2:error] [pid 167459:tid 167658] [client 20.116.17.175:20238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/ano.php"] [unique_id "aoSDW2r_JutbFb-8svrzAwAAAdQ"] [Tue Aug 18 13:07:55.432422 2026] [security2:error] [pid 167459:tid 167664] [client 104.209.144.33:24867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDW2r_JutbFb-8svrzAgAAAdo"] [Tue Aug 18 13:07:55.460994 2026] [security2:error] [pid 167459:tid 167562] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/aaf.php"] [unique_id "aoSDW2r_JutbFb-8svrzBAABz2Y"] [Tue Aug 18 13:07:55.477544 2026] [security2:error] [pid 167459:tid 167597] [client 213.35.127.232:56059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDW2r_JutbFb-8svrzBwAAAZc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:55.503588 2026] [security2:error] [pid 167459:tid 167652] [client 20.127.136.245:16594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/w.php"] [unique_id "aoSDW2r_JutbFb-8svrzCQAAAc4"] [Tue Aug 18 13:07:55.518548 2026] [security2:error] [pid 167459:tid 167650] [client 172.202.39.151:39201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDW2r_JutbFb-8svrzCwAAAcw"] [Tue Aug 18 13:07:55.519010 2026] [authz_core:error] [pid 167459:tid 167466] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:55.519260 2026] [authz_core:error] [pid 167459:tid 167466] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:55.526356 2026] [security2:error] [pid 167459:tid 167463] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/php8.php"] [unique_id "aoSDW2r_JutbFb-8svrzDAABkwM"] [Tue Aug 18 13:07:55.546482 2026] [security2:error] [pid 167459:tid 167646] [client 52.173.121.69:28328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDW2r_JutbFb-8svrzDQAAAcg"] [Tue Aug 18 13:07:55.557090 2026] [security2:error] [pid 167459:tid 167574] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDW2r_JutbFb-8svrzDgAB43I"] [Tue Aug 18 13:07:55.569701 2026] [security2:error] [pid 167459:tid 167657] [client 20.104.100.201:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/img.php"] [unique_id "aoSDW2r_JutbFb-8svrzEQAAAdM"] [Tue Aug 18 13:07:55.569848 2026] [security2:error] [pid 167459:tid 167715] [client 65.21.237.14:58922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.cadema.com.br"] [uri "/index.php"] [unique_id "aoSDW2r_JutbFb-8svrzCAAAAg0"] [Tue Aug 18 13:07:55.589705 2026] [security2:error] [pid 167459:tid 167714] [client 20.116.17.175:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/x1da.php"] [unique_id "aoSDW2r_JutbFb-8svrzGAAAAgw"] [Tue Aug 18 13:07:55.607464 2026] [security2:error] [pid 167459:tid 167666] [client 132.196.30.78:13111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/chosen.php"] [unique_id "aoSDW2r_JutbFb-8svrzGQAAAdw"] [Tue Aug 18 13:07:55.619056 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wio.php"] [unique_id "aoSDW2r_JutbFb-8svrzGgAAAc0"] [Tue Aug 18 13:07:55.647385 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.100.201:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/pucci.php"] [unique_id "aoSDW2r_JutbFb-8svrzGwAAAY8"] [Tue Aug 18 13:07:55.651683 2026] [security2:error] [pid 167459:tid 167616] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/403.php"] [unique_id "aoSDW2r_JutbFb-8svrzHAAAAao"] [Tue Aug 18 13:07:55.665650 2026] [security2:error] [pid 167459:tid 167601] [client 40.74.65.169:36975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSDW2r_JutbFb-8svrzHgAAAZs"] [Tue Aug 18 13:07:55.669825 2026] [security2:error] [pid 167459:tid 167694] [client 207.175.174.249:22992] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDW2r_JutbFb-8svrzHwAAAfg"] [Tue Aug 18 13:07:55.691575 2026] [security2:error] [pid 167459:tid 167695] [client 4.232.151.198:48471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/gulu.php"] [unique_id "aoSDW2r_JutbFb-8svrzIQAAAfk"] [Tue Aug 18 13:07:55.702293 2026] [security2:error] [pid 167459:tid 167688] [client 3.20.63.178:44144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rota85motorshop.com.br"] [uri "/index.php"] [unique_id "aoSDW2r_JutbFb-8svrzIAAAAfI"], referer: https://rota85motorshop.com.br/ [Tue Aug 18 13:07:55.710109 2026] [security2:error] [pid 167459:tid 167488] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/plugins.php"] [unique_id "aoSDW2r_JutbFb-8svrzIgAB1xw"] [Tue Aug 18 13:07:55.716090 2026] [security2:error] [pid 167459:tid 167610] [client 20.206.73.37:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/w1px.php"] [unique_id "aoSDW2r_JutbFb-8svrzIwAAAaQ"] [Tue Aug 18 13:07:55.720646 2026] [security2:error] [pid 167459:tid 167649] [client 207.175.174.249:23108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDW2r_JutbFb-8svrzJgAAAcs"] [Tue Aug 18 13:07:55.739037 2026] [security2:error] [pid 167459:tid 167677] [client 172.182.217.32:25543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/wp-cron.php"] [unique_id "aoSDW2r_JutbFb-8svrzKAAAAec"] [Tue Aug 18 13:07:55.750455 2026] [security2:error] [pid 167459:tid 167548] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/h02ugyh.php"] [unique_id "aoSDW2r_JutbFb-8svrzKgAB1lg"] [Tue Aug 18 13:07:55.781729 2026] [security2:error] [pid 167459:tid 167591] [client 20.116.17.175:20469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/nwflm.php"] [unique_id "aoSDW2r_JutbFb-8svrzLAAAAZE"] [Tue Aug 18 13:07:55.803514 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:3008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/bless.php"] [unique_id "aoSDW2r_JutbFb-8svrzLQAAAbc"] [Tue Aug 18 13:07:55.821837 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:55.822101 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:55.875287 2026] [security2:error] [pid 167459:tid 167615] [client 74.248.18.37:7008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/banners/autoload_classmap.php"] [unique_id "aoSDW2r_JutbFb-8svrzMQAAAak"] [Tue Aug 18 13:07:55.877764 2026] [security2:error] [pid 167459:tid 167697] [client 20.127.136.245:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/file.php"] [unique_id "aoSDW2r_JutbFb-8svrzMgAAAfs"] [Tue Aug 18 13:07:55.877868 2026] [security2:error] [pid 167459:tid 167620] [client 20.163.43.14:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDW2r_JutbFb-8svrzMwAAAa4"] [Tue Aug 18 13:07:55.889427 2026] [security2:error] [pid 167459:tid 167541] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/post.php"] [unique_id "aoSDW2r_JutbFb-8svrzNQAB9FE"] [Tue Aug 18 13:07:55.911413 2026] [security2:error] [pid 167459:tid 167680] [client 20.79.204.6:6000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/shiny.php"] [unique_id "aoSDW2r_JutbFb-8svrzNgAAAeo"] [Tue Aug 18 13:07:55.941847 2026] [security2:error] [pid 167459:tid 167614] [client 20.106.102.5:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/1061.php"] [unique_id "aoSDW2r_JutbFb-8svrzOAAAAag"] [Tue Aug 18 13:07:55.970572 2026] [security2:error] [pid 167459:tid 167638] [client 207.175.174.249:22868] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.prod"] [unique_id "aoSDW2r_JutbFb-8svrzPwAAAcA"] [Tue Aug 18 13:07:55.970990 2026] [security2:error] [pid 167459:tid 167658] [client 207.175.174.249:22784] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/core/.env"] [unique_id "aoSDW2r_JutbFb-8svrzTgAAAdQ"] [Tue Aug 18 13:07:55.971446 2026] [security2:error] [pid 167459:tid 167658] [client 207.175.174.249:22948] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/.aws/credentials"] [unique_id "aoSDW2r_JutbFb-8svrzUgAAAdQ"] [Tue Aug 18 13:07:55.971765 2026] [security2:error] [pid 167459:tid 167674] [client 207.175.174.249:23146] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.swp"] [unique_id "aoSDW2r_JutbFb-8svrzRgAAAeQ"] [Tue Aug 18 13:07:55.971797 2026] [security2:error] [pid 167459:tid 167670] [client 207.175.174.249:22856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "aoSDW2r_JutbFb-8svrzPgAAAeA"] [Tue Aug 18 13:07:55.972119 2026] [security2:error] [pid 167459:tid 167667] [client 207.175.174.249:23092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/back/.env"] [unique_id "aoSDW2r_JutbFb-8svrzTAAAAd0"] [Tue Aug 18 13:07:55.972165 2026] [security2:error] [pid 167459:tid 167664] [client 207.175.174.249:22970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "aoSDW2r_JutbFb-8svrzQgAAAdo"] [Tue Aug 18 13:07:55.972198 2026] [security2:error] [pid 167459:tid 167622] [client 207.175.174.249:22810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "aoSDW2r_JutbFb-8svrzSAAAAbA"] [Tue Aug 18 13:07:55.972286 2026] [security2:error] [pid 167459:tid 167692] [client 207.175.174.249:23132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/apps/api/.env"] [unique_id "aoSDW2r_JutbFb-8svrzTQAAAfY"] [Tue Aug 18 13:07:55.972370 2026] [security2:error] [pid 167459:tid 167595] [client 207.175.174.249:23084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "aoSDW2r_JutbFb-8svrzSQAAAZU"] [Tue Aug 18 13:07:55.972426 2026] [security2:error] [pid 167459:tid 167653] [client 207.175.174.249:23042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "aoSDW2r_JutbFb-8svrzSgAAAc8"] [Tue Aug 18 13:07:55.972803 2026] [security2:error] [pid 167459:tid 167639] [client 207.175.174.249:22850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "aoSDW2r_JutbFb-8svrzRwAAAcE"] [Tue Aug 18 13:07:55.972812 2026] [security2:error] [pid 167459:tid 167599] [client 207.175.174.249:23008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "aoSDW2r_JutbFb-8svrzRAAAAZk"] [Tue Aug 18 13:07:55.972813 2026] [security2:error] [pid 167459:tid 167606] [client 207.175.174.249:22964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "aoSDW2r_JutbFb-8svrzPAAAAaA"] [Tue Aug 18 13:07:55.972901 2026] [security2:error] [pid 167459:tid 167630] [client 207.175.174.249:22908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "aoSDW2r_JutbFb-8svrzQQAAAbg"] [Tue Aug 18 13:07:55.972914 2026] [security2:error] [pid 167459:tid 167696] [client 207.175.174.249:23162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.aws/credentials.old"] [unique_id "aoSDW2r_JutbFb-8svrzSwAAAfo"] [Tue Aug 18 13:07:55.973277 2026] [security2:error] [pid 167459:tid 167658] [client 207.175.174.249:23048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.aws/credentials.bak"] [unique_id "aoSDW2r_JutbFb-8svrzUwAAAdQ"] [Tue Aug 18 13:07:55.973459 2026] [security2:error] [pid 167459:tid 167652] [client 207.175.174.249:22826] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/web/.env"] [unique_id "aoSDW2r_JutbFb-8svrzWAAAAc4"] [Tue Aug 18 13:07:55.974439 2026] [proxy_http:error] [pid 167459:tid 167645] (20014)Internal error (specific information not available): [client 207.175.174.249:22916] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:55.980638 2026] [proxy_http:error] [pid 167459:tid 167678] (20014)Internal error (specific information not available): [client 207.175.174.249:22898] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:55.986790 2026] [proxy_http:error] [pid 167459:tid 167675] (20014)Internal error (specific information not available): [client 207.175.174.249:22986] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:55.993621 2026] [proxy_http:error] [pid 167459:tid 167708] (20014)Internal error (specific information not available): [client 207.175.174.249:22926] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:55.999821 2026] [proxy_http:error] [pid 167459:tid 167638] (20014)Internal error (specific information not available): [client 207.175.174.249:22952] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.005601 2026] [proxy_http:error] [pid 167459:tid 167706] (20014)Internal error (specific information not available): [client 207.175.174.249:22782] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.024245 2026] [security2:error] [pid 167459:tid 167673] [client 172.202.39.151:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDXGr_JutbFb-8svrzXgAAAeM"] [Tue Aug 18 13:07:56.041213 2026] [security2:error] [pid 167459:tid 167576] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/155.php"] [unique_id "aoSDXGr_JutbFb-8svrzXwACDXQ"] [Tue Aug 18 13:07:56.070295 2026] [security2:error] [pid 167459:tid 167561] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/r.php"] [unique_id "aoSDXGr_JutbFb-8svrzYQABsWU"] [Tue Aug 18 13:07:56.097417 2026] [security2:error] [pid 167459:tid 167612] [client 20.104.100.201:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/8.php"] [unique_id "aoSDXGr_JutbFb-8svrzYgAAAaY"] [Tue Aug 18 13:07:56.110261 2026] [authz_core:error] [pid 167459:tid 167529] [remote 57.141.22.89:56988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:56.110526 2026] [authz_core:error] [pid 167459:tid 167529] [remote 57.141.22.89:56988] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:56.114512 2026] [security2:error] [pid 167459:tid 167659] [client 104.209.144.33:31261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDXGr_JutbFb-8svrzZQAAAdU"] [Tue Aug 18 13:07:56.123136 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:56.123406 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:56.133885 2026] [security2:error] [pid 167459:tid 167651] [client 20.151.109.219:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/lmfi2.php"] [unique_id "aoSDXGr_JutbFb-8svrzaAAAAc0"] [Tue Aug 18 13:07:56.143752 2026] [security2:error] [pid 167459:tid 167519] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSDXGr_JutbFb-8svrzaQAB_js"] [Tue Aug 18 13:07:56.186900 2026] [security2:error] [pid 167459:tid 167650] [client 132.196.30.78:13107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDXGr_JutbFb-8svrzawAAAcw"] [Tue Aug 18 13:07:56.227764 2026] [security2:error] [pid 167459:tid 167627] [client 52.139.47.57:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDXGr_JutbFb-8svrzbgAAAbU"] [Tue Aug 18 13:07:56.234111 2026] [security2:error] [pid 167459:tid 167621] [client 172.182.217.32:4048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/wp-mail.php"] [unique_id "aoSDXGr_JutbFb-8svrzcQAAAa8"] [Tue Aug 18 13:07:56.234141 2026] [security2:error] [pid 167459:tid 167649] [client 207.175.174.249:23030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/@fs/.env"] [unique_id "aoSDXGr_JutbFb-8svrzbwAAAcs"] [Tue Aug 18 13:07:56.234648 2026] [security2:error] [pid 167459:tid 167596] [client 207.175.174.249:23120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/@fs/app/.env"] [unique_id "aoSDXGr_JutbFb-8svrzcAAAAZY"] [Tue Aug 18 13:07:56.235525 2026] [security2:error] [pid 167459:tid 167672] [client 207.175.174.249:23048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/@fs/root/.env"] [unique_id "aoSDXGr_JutbFb-8svrzcgAAAeI"] [Tue Aug 18 13:07:56.236707 2026] [security2:error] [pid 167459:tid 167703] [client 207.175.174.249:22850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.vercel/.env"] [unique_id "aoSDXGr_JutbFb-8svrzcwAAAgE"] [Tue Aug 18 13:07:56.238311 2026] [security2:error] [pid 167459:tid 167669] [client 207.175.174.249:23256] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/files../.env"] [unique_id "aoSDXGr_JutbFb-8svrzdwAAAd8"] [Tue Aug 18 13:07:56.238918 2026] [security2:error] [pid 167459:tid 167619] [client 207.175.174.249:23172] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/_next/static/../.env"] [unique_id "aoSDXGr_JutbFb-8svrzeAAAAa0"] [Tue Aug 18 13:07:56.238922 2026] [security2:error] [pid 167459:tid 167615] [client 207.175.174.249:22964] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSDXGr_JutbFb-8svrzegAAAak"] [Tue Aug 18 13:07:56.239176 2026] [core:error] [pid 167459:tid 167697] [client 207.175.174.249:23092] AH10244: invalid URI path (/assets../../../.env) [Tue Aug 18 13:07:56.239798 2026] [security2:error] [pid 167459:tid 167680] [client 207.175.174.249:22810] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.github/workflows/ci.yml"] [unique_id "aoSDXGr_JutbFb-8svrzggAAAeo"] [Tue Aug 18 13:07:56.239810 2026] [security2:error] [pid 167459:tid 167684] [client 207.175.174.249:22908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aoSDXGr_JutbFb-8svrzeQAAAe4"] [Tue Aug 18 13:07:56.240008 2026] [security2:error] [pid 167459:tid 167690] [client 207.175.174.249:23008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.github/.env"] [unique_id "aoSDXGr_JutbFb-8svrzfgAAAfQ"] [Tue Aug 18 13:07:56.240475 2026] [security2:error] [pid 167459:tid 167591] [client 207.175.174.249:23310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/root/.aws/config"] [unique_id "aoSDXGr_JutbFb-8svrzhQAAAZE"] [Tue Aug 18 13:07:56.240934 2026] [security2:error] [pid 167459:tid 167716] [client 207.175.174.249:23276] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDXGr_JutbFb-8svrzhgAAAg4"] [Tue Aug 18 13:07:56.241923 2026] [security2:error] [pid 167459:tid 167626] [client 207.175.174.249:23284] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/1/environ"] [unique_id "aoSDXGr_JutbFb-8svrzigAAAbQ"] [Tue Aug 18 13:07:56.242663 2026] [security2:error] [pid 167459:tid 167614] [client 20.116.17.175:20271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/wp-load.php"] [unique_id "aoSDXGr_JutbFb-8svrziwAAAag"] [Tue Aug 18 13:07:56.246013 2026] [proxy_http:error] [pid 167459:tid 167677] (20014)Internal error (specific information not available): [client 207.175.174.249:23246] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.246025 2026] [proxy:error] [pid 167459:tid 167677] [client 207.175.174.249:23246] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ubuntu/.aws/credentials [Tue Aug 18 13:07:56.253116 2026] [proxy_http:error] [pid 167459:tid 167609] (20014)Internal error (specific information not available): [client 207.175.174.249:22970] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.258173 2026] [security2:error] [pid 167459:tid 167691] [client 20.206.73.37:39631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maganmotors.com.br"] [uri "/packed.php"] [unique_id "aoSDXGr_JutbFb-8svrzjgAAAfU"] [Tue Aug 18 13:07:56.258571 2026] [security2:error] [pid 167459:tid 167681] [client 207.175.174.249:22882] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/runtime-config.js"] [unique_id "aoSDXGr_JutbFb-8svrzjwAAAes"] [Tue Aug 18 13:07:56.259373 2026] [proxy_http:error] [pid 167459:tid 167671] (20014)Internal error (specific information not available): [client 207.175.174.249:23042] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.266668 2026] [proxy_http:error] [pid 167459:tid 167635] (20014)Internal error (specific information not available): [client 207.175.174.249:23222] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.266686 2026] [proxy:error] [pid 167459:tid 167635] [client 207.175.174.249:23222] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/fetch [Tue Aug 18 13:07:56.267112 2026] [security2:error] [pid 167459:tid 167674] [client 20.127.136.245:9500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDXGr_JutbFb-8svrzkQAAAeQ"] [Tue Aug 18 13:07:56.270603 2026] [security2:error] [pid 167459:tid 167667] [client 20.163.43.14:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDXGr_JutbFb-8svrzkgAAAd0"] [Tue Aug 18 13:07:56.272040 2026] [security2:error] [pid 167459:tid 167664] [client 20.106.102.5:45209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/gec.php"] [unique_id "aoSDXGr_JutbFb-8svrzkwAAAdo"] [Tue Aug 18 13:07:56.273651 2026] [proxy_http:error] [pid 167459:tid 167716] (20014)Internal error (specific information not available): [client 207.175.174.249:23276] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.273668 2026] [proxy:error] [pid 167459:tid 167716] [client 207.175.174.249:23276] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html [Tue Aug 18 13:07:56.279997 2026] [proxy_http:error] [pid 167459:tid 167665] (20014)Internal error (specific information not available): [client 207.175.174.249:23272] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.280015 2026] [proxy:error] [pid 167459:tid 167665] [client 207.175.174.249:23272] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/credentials [Tue Aug 18 13:07:56.286608 2026] [proxy_http:error] [pid 167459:tid 167701] (20014)Internal error (specific information not available): [client 207.175.174.249:23296] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.286625 2026] [proxy:error] [pid 167459:tid 167701] [client 207.175.174.249:23296] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/.aws/credentials [Tue Aug 18 13:07:56.293022 2026] [proxy_http:error] [pid 167459:tid 167709] (20014)Internal error (specific information not available): [client 207.175.174.249:23044] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.319759 2026] [security2:error] [pid 167459:tid 167511] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSDXGr_JutbFb-8svrzlgABsDM"] [Tue Aug 18 13:07:56.332048 2026] [security2:error] [pid 167459:tid 167499] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ops.php"] [unique_id "aoSDXGr_JutbFb-8svrzlwAB-ic"] [Tue Aug 18 13:07:56.342357 2026] [security2:error] [pid 167459:tid 167618] [client 207.175.174.249:22796] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/aws-exports.js"] [unique_id "aoSDXGr_JutbFb-8svrzmgAAAaw"] [Tue Aug 18 13:07:56.342579 2026] [security2:error] [pid 167459:tid 167645] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/gecko.php"] [unique_id "aoSDXGr_JutbFb-8svrzmQAAAcc"] [Tue Aug 18 13:07:56.351260 2026] [security2:error] [pid 167459:tid 167514] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/radio.php"] [unique_id "aoSDXGr_JutbFb-8svrzmwAB6DY"] [Tue Aug 18 13:07:56.377542 2026] [security2:error] [pid 167459:tid 167589] [client 4.232.151.198:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/h.php"] [unique_id "aoSDXGr_JutbFb-8svrznQAAAY8"] [Tue Aug 18 13:07:56.412662 2026] [security2:error] [pid 167459:tid 167634] [client 65.21.237.14:59752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cadema.com.br"] [uri "/index.php"] [unique_id "aoSDXGr_JutbFb-8svrzjQAAAbw"] [Tue Aug 18 13:07:56.415742 2026] [security2:error] [pid 167459:tid 167605] [client 20.250.13.23:45235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/nw.php"] [unique_id "aoSDXGr_JutbFb-8svrzoAAAAZ8"] [Tue Aug 18 13:07:56.424165 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:56.424429 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:56.437286 2026] [security2:error] [pid 167459:tid 167656] [client 40.74.65.169:20740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/system_log.php"] [unique_id "aoSDXGr_JutbFb-8svrzpAAAAdI"] [Tue Aug 18 13:07:56.502412 2026] [security2:error] [pid 167459:tid 167601] [client 213.35.127.232:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDXGr_JutbFb-8svrzqQAAAZs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:56.510394 2026] [proxy_http:error] [pid 167459:tid 167651] (20014)Internal error (specific information not available): [client 207.175.174.249:23354] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.510408 2026] [proxy:error] [pid 167459:tid 167651] [client 207.175.174.249:23354] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/_profiler/phpinfo [Tue Aug 18 13:07:56.524370 2026] [security2:error] [pid 167459:tid 167628] [client 20.104.100.201:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDXGr_JutbFb-8svrzrQAAAbY"] [Tue Aug 18 13:07:56.535826 2026] [security2:error] [pid 167459:tid 167679] [client 207.175.174.249:22850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/read"] [unique_id "aoSDXGr_JutbFb-8svrzrwAAAek"] [Tue Aug 18 13:07:56.537513 2026] [security2:error] [pid 167459:tid 167610] [client 207.175.174.249:23120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/api/file"] [unique_id "aoSDXGr_JutbFb-8svrzsgAAAaQ"] [Tue Aug 18 13:07:56.537874 2026] [security2:error] [pid 167459:tid 167688] [client 207.175.174.249:23048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/read?url=file:///proc/1/environ"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/read"] [unique_id "aoSDXGr_JutbFb-8svrzsAAAAfI"] [Tue Aug 18 13:07:56.537989 2026] [security2:error] [pid 167459:tid 167689] [client 207.175.174.249:23030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?dest=http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDXGr_JutbFb-8svrzsQAAAfM"] [Tue Aug 18 13:07:56.543889 2026] [security2:error] [pid 167459:tid 167627] [client 172.202.39.151:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/about.php"] [unique_id "aoSDXGr_JutbFb-8svrzswAAAbU"] [Tue Aug 18 13:07:56.549737 2026] [security2:error] [pid 167459:tid 167621] [client 207.175.174.249:23514] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/actuator/logfile"] [unique_id "aoSDXGr_JutbFb-8svrztwAAAa8"] [Tue Aug 18 13:07:56.558009 2026] [security2:error] [pid 167459:tid 167703] [client 207.175.174.249:23484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "aoSDXGr_JutbFb-8svrzuQAAAgE"] [Tue Aug 18 13:07:56.558308 2026] [proxy_http:error] [pid 167459:tid 167631] (20014)Internal error (specific information not available): [client 207.175.174.249:23518] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.558322 2026] [proxy:error] [pid 167459:tid 167631] [client 207.175.174.249:23518] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.save [Tue Aug 18 13:07:56.564806 2026] [security2:error] [pid 167459:tid 167633] [client 20.79.204.6:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/sid3.php"] [unique_id "aoSDXGr_JutbFb-8svrzugAAAbs"] [Tue Aug 18 13:07:56.564821 2026] [proxy_http:error] [pid 167459:tid 167672] (20014)Internal error (specific information not available): [client 207.175.174.249:23504] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.564834 2026] [proxy:error] [pid 167459:tid 167672] [client 207.175.174.249:23504] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/home/ec2-user/.aws/credentials [Tue Aug 18 13:07:56.588282 2026] [security2:error] [pid 167459:tid 167630] [client 74.248.18.37:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/qfunctions.php"] [unique_id "aoSDXGr_JutbFb-8svrzvAAAAbg"] [Tue Aug 18 13:07:56.597694 2026] [security2:error] [pid 167459:tid 167700] [client 138.36.100.162:42257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXGr_JutbFb-8svrzvQAAAf4"] [Tue Aug 18 13:07:56.597855 2026] [security2:error] [pid 167459:tid 167700] [client 138.36.100.162:42257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXGr_JutbFb-8svrzvQAAAf4"] [Tue Aug 18 13:07:56.599922 2026] [security2:error] [pid 167459:tid 167697] [client 20.106.102.5:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/scx.php7"] [unique_id "aoSDXGr_JutbFb-8svrzvgAAAfs"] [Tue Aug 18 13:07:56.611105 2026] [security2:error] [pid 167459:tid 167611] [client 197.184.64.235:42690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXGr_JutbFb-8svrzvwAAAaU"] [Tue Aug 18 13:07:56.611244 2026] [security2:error] [pid 167459:tid 167611] [client 197.184.64.235:42690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXGr_JutbFb-8svrzvwAAAaU"] [Tue Aug 18 13:07:56.623503 2026] [security2:error] [pid 167459:tid 167491] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/mac.php"] [unique_id "aoSDXGr_JutbFb-8svrzwgABvR8"] [Tue Aug 18 13:07:56.633833 2026] [proxy_http:error] [pid 167459:tid 167645] (20014)Internal error (specific information not available): [client 207.175.174.249:23162] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.640682 2026] [security2:error] [pid 167459:tid 167675] [client 20.116.17.175:20415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/jj.php"] [unique_id "aoSDXGr_JutbFb-8svrzxgAAAeU"] [Tue Aug 18 13:07:56.641680 2026] [security2:error] [pid 167459:tid 167659] [client 52.139.47.57:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/cache.php"] [unique_id "aoSDXGr_JutbFb-8svrzxwAAAdU"] [Tue Aug 18 13:07:56.648661 2026] [security2:error] [pid 167459:tid 167715] [client 207.175.174.249:23194] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDXGr_JutbFb-8svrzyQAAAg0"] [Tue Aug 18 13:07:56.649885 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wicked.php"] [unique_id "aoSDXGr_JutbFb-8svrzygAAAgU"] [Tue Aug 18 13:07:56.654169 2026] [proxy_http:error] [pid 167459:tid 167715] (20014)Internal error (specific information not available): [client 207.175.174.249:23194] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.657059 2026] [security2:error] [pid 167459:tid 167648] [client 20.163.43.14:15710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/admin.php"] [unique_id "aoSDXGr_JutbFb-8svrzzAAAAco"] [Tue Aug 18 13:07:56.664418 2026] [security2:error] [pid 167459:tid 167688] [client 207.175.174.249:23534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/download"] [unique_id "aoSDXGr_JutbFb-8svrzzwAAAfI"] [Tue Aug 18 13:07:56.664952 2026] [security2:error] [pid 167459:tid 167689] [client 20.151.109.219:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fd.php"] [unique_id "aoSDXGr_JutbFb-8svrz0AAAAfM"] [Tue Aug 18 13:07:56.667937 2026] [security2:error] [pid 167459:tid 167627] [client 207.175.174.249:23546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/download"] [unique_id "aoSDXGr_JutbFb-8svrz0QAAAbU"] [Tue Aug 18 13:07:56.673316 2026] [proxy_http:error] [pid 167459:tid 167596] (20014)Internal error (specific information not available): [client 207.175.174.249:23342] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:56.673334 2026] [proxy:error] [pid 167459:tid 167596] [client 207.175.174.249:23342] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/__env.js [Tue Aug 18 13:07:56.679929 2026] [security2:error] [pid 167459:tid 167563] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDXGr_JutbFb-8svrz1wABtGc"] [Tue Aug 18 13:07:56.724267 2026] [security2:error] [pid 167459:tid 167560] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/randkeyword.php7"] [unique_id "aoSDXGr_JutbFb-8svrz3gABoGQ"] [Tue Aug 18 13:07:56.725713 2026] [security2:error] [pid 167459:tid 167665] [client 207.175.174.249:23238] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDXGr_JutbFb-8svrz3QAAAds"] [Tue Aug 18 13:07:56.734649 2026] [security2:error] [pid 167459:tid 167652] [client 20.127.136.245:20709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/aa.php"] [unique_id "aoSDXGr_JutbFb-8svrz3wAAAc4"] [Tue Aug 18 13:07:56.738182 2026] [security2:error] [pid 167459:tid 167684] [client 172.182.217.32:25574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/xmlrpc.php"] [unique_id "aoSDXGr_JutbFb-8svrz4AAAAe4"] [Tue Aug 18 13:07:56.771919 2026] [security2:error] [pid 167459:tid 167690] [client 132.196.30.78:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/vx.php"] [unique_id "aoSDXGr_JutbFb-8svrz4QAAAfQ"] [Tue Aug 18 13:07:56.854971 2026] [security2:error] [pid 167459:tid 167546] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDXGr_JutbFb-8svrz4gAB11Y"] [Tue Aug 18 13:07:56.859889 2026] [security2:error] [pid 167459:tid 167617] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/aa.php"] [unique_id "aoSDXGr_JutbFb-8svrz4wAAAas"] [Tue Aug 18 13:07:56.890859 2026] [security2:error] [pid 167459:tid 167607] [client 74.248.18.37:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/inputs.php"] [unique_id "aoSDXGr_JutbFb-8svrz5AAAAaE"] [Tue Aug 18 13:07:56.893614 2026] [security2:error] [pid 167459:tid 167675] [client 20.116.17.175:52553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/mcs.php"] [unique_id "aoSDXGr_JutbFb-8svrz5QAAAeU"] [Tue Aug 18 13:07:56.908024 2026] [security2:error] [pid 167459:tid 167504] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/red.php"] [unique_id "aoSDXGr_JutbFb-8svrz5gACBCw"] [Tue Aug 18 13:07:56.914694 2026] [security2:error] [pid 167459:tid 167542] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "aoSDXGr_JutbFb-8svrz5wABvFI"] [Tue Aug 18 13:07:56.924923 2026] [security2:error] [pid 167459:tid 167711] [client 20.106.102.5:45130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-admin/sc.php"] [unique_id "aoSDXGr_JutbFb-8svrz6AAAAgk"] [Tue Aug 18 13:07:57.003449 2026] [security2:error] [pid 167459:tid 167614] [client 4.232.151.198:48468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/hello.php"] [unique_id "aoSDXWr_JutbFb-8svrz6wAAAag"] [Tue Aug 18 13:07:57.011617 2026] [security2:error] [pid 167459:tid 167714] [client 20.104.100.201:17394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/images.php"] [unique_id "aoSDXWr_JutbFb-8svrz7AAAAgw"] [Tue Aug 18 13:07:57.023133 2026] [security2:error] [pid 167459:tid 167605] [client 20.163.43.14:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/public/css.php"] [unique_id "aoSDXWr_JutbFb-8svrz7gAAAZ8"] [Tue Aug 18 13:07:57.027790 2026] [security2:error] [pid 167459:tid 167593] [client 20.65.98.162:57765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ws13.php"] [unique_id "aoSDXWr_JutbFb-8svrz7wAAAZM"] [Tue Aug 18 13:07:57.053648 2026] [security2:error] [pid 167459:tid 167646] [client 52.139.47.57:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/content.php"] [unique_id "aoSDXWr_JutbFb-8svrz8QAAAcg"] [Tue Aug 18 13:07:57.053802 2026] [security2:error] [pid 167459:tid 167648] [client 20.116.17.175:20307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/img.php"] [unique_id "aoSDXWr_JutbFb-8svrz8gAAAco"] [Tue Aug 18 13:07:57.053905 2026] [security2:error] [pid 167459:tid 167650] [client 52.173.121.69:28330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDXWr_JutbFb-8svrz8wAAAcw"] [Tue Aug 18 13:07:57.060040 2026] [security2:error] [pid 167459:tid 167522] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSDXWr_JutbFb-8svrz9QAB9D4"] [Tue Aug 18 13:07:57.107119 2026] [security2:error] [pid 167459:tid 167500] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/release.php"] [unique_id "aoSDXWr_JutbFb-8svrz-gAB8ig"] [Tue Aug 18 13:07:57.131379 2026] [security2:error] [pid 167459:tid 167669] [client 20.127.136.245:5571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDXWr_JutbFb-8svrz-wAAAd8"] [Tue Aug 18 13:07:57.154426 2026] [security2:error] [pid 167459:tid 167703] [client 172.202.39.151:39224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDXWr_JutbFb-8svrz_gAAAgE"] [Tue Aug 18 13:07:57.174673 2026] [security2:error] [pid 167459:tid 167619] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/0x.php"] [unique_id "aoSDXWr_JutbFb-8svrz_wAAAa0"] [Tue Aug 18 13:07:57.202735 2026] [security2:error] [pid 167459:tid 167601] [client 20.79.204.6:5733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/sid4.php"] [unique_id "aoSDXWr_JutbFb-8svr0AQAAAZs"] [Tue Aug 18 13:07:57.205475 2026] [security2:error] [pid 167459:tid 167473] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/js/"] [unique_id "aoSDXWr_JutbFb-8svr0AgABuA0"] [Tue Aug 18 13:07:57.227005 2026] [security2:error] [pid 167459:tid 167625] [client 172.182.217.32:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/api.php"] [unique_id "aoSDXWr_JutbFb-8svr0BAAAAbM"] [Tue Aug 18 13:07:57.235593 2026] [security2:error] [pid 167459:tid 167578] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSDXWr_JutbFb-8svr0BQAB-3Y"] [Tue Aug 18 13:07:57.249874 2026] [security2:error] [pid 167459:tid 167671] [client 20.106.102.5:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp5.php"] [unique_id "aoSDXWr_JutbFb-8svr0BwAAAeE"] [Tue Aug 18 13:07:57.286498 2026] [security2:error] [pid 167459:tid 167545] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/reop3.php"] [unique_id "aoSDXWr_JutbFb-8svr0CgAB7VU"] [Tue Aug 18 13:07:57.327843 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:57.328112 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:57.331654 2026] [security2:error] [pid 167459:tid 167551] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/tmp/index.php"] [unique_id "aoSDXWr_JutbFb-8svr0DQABt1s"] [Tue Aug 18 13:07:57.395945 2026] [security2:error] [pid 167459:tid 167617] [client 207.175.174.249:23292] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDXWr_JutbFb-8svr0EAAAAas"] [Tue Aug 18 13:07:57.399615 2026] [security2:error] [pid 167459:tid 167654] [client 207.175.174.249:23132] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDXWr_JutbFb-8svr0EQAAAdA"] [Tue Aug 18 13:07:57.421298 2026] [security2:error] [pid 167459:tid 167673] [client 207.175.174.249:23208] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDXWr_JutbFb-8svr0EwAAAeM"] [Tue Aug 18 13:07:57.423071 2026] [security2:error] [pid 167459:tid 167592] [client 20.104.100.201:53364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDXWr_JutbFb-8svr0FAAAAZI"] [Tue Aug 18 13:07:57.427378 2026] [security2:error] [pid 167459:tid 167614] [client 207.175.174.249:23296] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDXWr_JutbFb-8svr0FQAAAag"] [Tue Aug 18 13:07:57.437183 2026] [security2:error] [pid 167459:tid 167715] [client 207.175.174.249:23030] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDXWr_JutbFb-8svr0FgAAAg0"] [Tue Aug 18 13:07:57.455045 2026] [security2:error] [pid 167459:tid 167624] [client 207.175.174.249:23272] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDXWr_JutbFb-8svr0GAAAAbI"] [Tue Aug 18 13:07:57.458665 2026] [security2:error] [pid 167459:tid 167667] [client 196.12.128.158:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0GQAAAd0"] [Tue Aug 18 13:07:57.458773 2026] [security2:error] [pid 167459:tid 167667] [client 196.12.128.158:50544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0GQAAAd0"] [Tue Aug 18 13:07:57.486284 2026] [security2:error] [pid 167459:tid 167705] [client 172.202.39.151:39203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/f35.php"] [unique_id "aoSDXWr_JutbFb-8svr0GwAAAgM"] [Tue Aug 18 13:07:57.496441 2026] [security2:error] [pid 167459:tid 167577] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDXWr_JutbFb-8svr0HAABqXU"] [Tue Aug 18 13:07:57.500659 2026] [security2:error] [pid 167459:tid 167712] [client 52.139.47.57:10144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDXWr_JutbFb-8svr0HQAAAgo"] [Tue Aug 18 13:07:57.506350 2026] [security2:error] [pid 167459:tid 167671] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/zxz.php"] [unique_id "aoSDXWr_JutbFb-8svr0HgAAAeE"] [Tue Aug 18 13:07:57.507087 2026] [security2:error] [pid 167459:tid 167640] [client 20.163.43.14:15630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDXWr_JutbFb-8svr0HwAAAcI"] [Tue Aug 18 13:07:57.518448 2026] [security2:error] [pid 167459:tid 167595] [client 20.151.109.219:28778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/info2.php"] [unique_id "aoSDXWr_JutbFb-8svr0IwAAAZU"] [Tue Aug 18 13:07:57.521080 2026] [security2:error] [pid 167459:tid 167597] [client 20.127.136.245:23824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/about.php"] [unique_id "aoSDXWr_JutbFb-8svr0JAAAAZc"] [Tue Aug 18 13:07:57.528100 2026] [security2:error] [pid 167459:tid 167591] [client 213.35.127.232:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDXWr_JutbFb-8svr0JgAAAZE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:57.540978 2026] [security2:error] [pid 167459:tid 167570] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/robots.php"] [unique_id "aoSDXWr_JutbFb-8svr0JwAB-m4"] [Tue Aug 18 13:07:57.570044 2026] [security2:error] [pid 167459:tid 167618] [client 102.213.179.104:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0KgAAAaw"] [Tue Aug 18 13:07:57.570165 2026] [security2:error] [pid 167459:tid 167618] [client 102.213.179.104:56693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0KgAAAaw"] [Tue Aug 18 13:07:57.574850 2026] [security2:error] [pid 167459:tid 167634] [client 20.106.102.5:45244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/a2.php"] [unique_id "aoSDXWr_JutbFb-8svr0KwAAAbw"] [Tue Aug 18 13:07:57.575747 2026] [security2:error] [pid 167459:tid 167657] [client 132.196.30.78:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wap.php"] [unique_id "aoSDXWr_JutbFb-8svr0LAAAAdM"] [Tue Aug 18 13:07:57.581303 2026] [security2:error] [pid 167459:tid 167678] [client 74.248.18.37:7011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/hehehehe.php"] [unique_id "aoSDXWr_JutbFb-8svr0LQAAAeg"] [Tue Aug 18 13:07:57.609981 2026] [security2:error] [pid 167459:tid 167693] [client 20.226.36.136:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDXWr_JutbFb-8svr0LgAAAfc"] [Tue Aug 18 13:07:57.625708 2026] [security2:error] [pid 167459:tid 167494] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDXWr_JutbFb-8svr0MAAByiI"] [Tue Aug 18 13:07:57.642554 2026] [security2:error] [pid 167459:tid 167475] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/tmpls.php"] [unique_id "aoSDXWr_JutbFb-8svr0MwACAQ8"] [Tue Aug 18 13:07:57.645851 2026] [security2:error] [pid 167459:tid 167619] [client 20.104.100.201:54019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/a.php"] [unique_id "aoSDXWr_JutbFb-8svr0NAAAAa0"] [Tue Aug 18 13:07:57.678619 2026] [security2:error] [pid 167459:tid 167633] [client 20.116.17.175:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/adminner.php"] [unique_id "aoSDXWr_JutbFb-8svr0NQAAAbs"] [Tue Aug 18 13:07:57.721753 2026] [security2:error] [pid 167459:tid 167700] [client 49.145.211.146:12604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0KAAAAf4"] [Tue Aug 18 13:07:57.721911 2026] [security2:error] [pid 167459:tid 167700] [client 49.145.211.146:12604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0KAAAAf4"] [Tue Aug 18 13:07:57.724787 2026] [security2:error] [pid 167459:tid 167714] [client 4.232.151.198:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/images/index.php"] [unique_id "aoSDXWr_JutbFb-8svr0OAAAAgw"] [Tue Aug 18 13:07:57.729682 2026] [security2:error] [pid 167459:tid 167675] [client 172.182.217.32:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/assets/script-loader.php"] [unique_id "aoSDXWr_JutbFb-8svr0OQAAAeU"] [Tue Aug 18 13:07:57.729700 2026] [security2:error] [pid 167459:tid 167584] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/root.php"] [unique_id "aoSDXWr_JutbFb-8svr0OgAB2nw"] [Tue Aug 18 13:07:57.754359 2026] [authz_core:error] [pid 167459:tid 167690] [client 192.178.4.133:63971] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:57.754635 2026] [authz_core:error] [pid 167459:tid 167690] [client 192.178.4.133:63971] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:57.792086 2026] [security2:error] [pid 167459:tid 167558] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSDXWr_JutbFb-8svr0QAAB3mI"] [Tue Aug 18 13:07:57.798707 2026] [security2:error] [pid 167459:tid 167549] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDXWr_JutbFb-8svr0QQABx1k"] [Tue Aug 18 13:07:57.803517 2026] [security2:error] [pid 167459:tid 167684] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/www.php"] [unique_id "aoSDXWr_JutbFb-8svr0QgAAAe4"] [Tue Aug 18 13:07:57.897806 2026] [security2:error] [pid 167459:tid 167715] [client 20.106.102.5:45146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/app.php"] [unique_id "aoSDXWr_JutbFb-8svr0RgAAAg0"] [Tue Aug 18 13:07:57.913880 2026] [security2:error] [pid 167459:tid 167622] [client 52.139.47.57:10152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/css.php"] [unique_id "aoSDXWr_JutbFb-8svr0RwAAAbA"] [Tue Aug 18 13:07:57.927105 2026] [security2:error] [pid 167459:tid 167669] [client 40.74.65.169:21365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/pucci.php"] [unique_id "aoSDXWr_JutbFb-8svr0SAAAAd8"] [Tue Aug 18 13:07:57.954621 2026] [security2:error] [pid 167459:tid 167484] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/tool.php"] [unique_id "aoSDXWr_JutbFb-8svr0TAABnRg"] [Tue Aug 18 13:07:57.961994 2026] [security2:error] [pid 167459:tid 167610] [client 207.175.174.249:23108] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDXWr_JutbFb-8svr0TwAAAaQ"] [Tue Aug 18 13:07:57.965177 2026] [proxy_http:error] [pid 167459:tid 167619] (20014)Internal error (specific information not available): [client 207.175.174.249:23296] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:57.972773 2026] [security2:error] [pid 167459:tid 167476] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSDXWr_JutbFb-8svr0UQABuxA"] [Tue Aug 18 13:07:57.980471 2026] [security2:error] [pid 167459:tid 167553] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0UgABqV0"] [Tue Aug 18 13:07:57.981420 2026] [security2:error] [pid 167459:tid 167615] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDXWr_JutbFb-8svr0UgABqV0"] [Tue Aug 18 13:07:57.995845 2026] [security2:error] [pid 167459:tid 167467] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/rrr.php"] [unique_id "aoSDXWr_JutbFb-8svr0VQABrgc"] [Tue Aug 18 13:07:58.000874 2026] [security2:error] [pid 167459:tid 167671] [client 20.163.43.14:15637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDXmr_JutbFb-8svr0VgAAAeE"] [Tue Aug 18 13:07:58.039375 2026] [security2:error] [pid 167459:tid 167664] [client 20.104.100.201:53255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDXmr_JutbFb-8svr0WwAAAdo"] [Tue Aug 18 13:07:58.083408 2026] [security2:error] [pid 167459:tid 167496] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/system_log.php"] [unique_id "aoSDXmr_JutbFb-8svr0XgABkCQ"] [Tue Aug 18 13:07:58.083931 2026] [security2:error] [pid 167459:tid 167665] [client 20.151.109.219:40464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sx.php"] [unique_id "aoSDXmr_JutbFb-8svr0XwAAAds"] [Tue Aug 18 13:07:58.111597 2026] [security2:error] [pid 167459:tid 167696] [client 104.209.144.33:31249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDXmr_JutbFb-8svr0YgAAAfo"] [Tue Aug 18 13:07:58.193787 2026] [security2:error] [pid 167459:tid 167661] [client 20.79.204.6:5735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/size.php"] [unique_id "aoSDXmr_JutbFb-8svr0ZgAAAdc"] [Tue Aug 18 13:07:58.200833 2026] [security2:error] [pid 167459:tid 167477] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/s.php"] [unique_id "aoSDXmr_JutbFb-8svr0ZwABqxE"] [Tue Aug 18 13:07:58.208894 2026] [security2:error] [pid 167459:tid 167530] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSDXmr_JutbFb-8svr0aAAB1UY"] [Tue Aug 18 13:07:58.236573 2026] [autoindex:error] [pid 167459:tid 167699] [client 172.182.217.32:4073] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/blocks/comment-template/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:58.245431 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:39212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/inputs.php"] [unique_id "aoSDXmr_JutbFb-8svr0bgAAAbw"] [Tue Aug 18 13:07:58.246957 2026] [security2:error] [pid 167459:tid 167657] [client 52.173.121.69:28292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDXmr_JutbFb-8svr0bwAAAdM"] [Tue Aug 18 13:07:58.266610 2026] [security2:error] [pid 167459:tid 167469] [remote 47.128.124.126:40606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caetesturismo.com.br"] [uri "/galeria/apa-pequenos-lencois/"] [unique_id "aoSDXmr_JutbFb-8svr0cAACCAk"] [Tue Aug 18 13:07:58.267398 2026] [security2:error] [pid 167459:tid 167490] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/txets.php"] [unique_id "aoSDXmr_JutbFb-8svr0cQABsR4"] [Tue Aug 18 13:07:58.269749 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/water.php"] [unique_id "aoSDXmr_JutbFb-8svr0cgAAAgU"] [Tue Aug 18 13:07:58.297044 2026] [security2:error] [pid 167459:tid 167715] [client 207.175.174.249:23030] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/v1/fetch"] [unique_id "aoSDXmr_JutbFb-8svr0dAAAAg0"] [Tue Aug 18 13:07:58.307127 2026] [security2:error] [pid 167459:tid 167651] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wicked.php"] [unique_id "aoSDXmr_JutbFb-8svr0dgAAAc0"] [Tue Aug 18 13:07:58.319975 2026] [security2:error] [pid 167459:tid 167646] [client 20.116.17.175:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dragonshell.php"] [unique_id "aoSDXmr_JutbFb-8svr0dwAAAcg"] [Tue Aug 18 13:07:58.323066 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:28255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/admin.php"] [unique_id "aoSDXmr_JutbFb-8svr0eAAAAec"] [Tue Aug 18 13:07:58.326151 2026] [security2:error] [pid 167459:tid 167666] [client 207.175.174.249:22856] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDXmr_JutbFb-8svr0eQAAAdw"] [Tue Aug 18 13:07:58.327620 2026] [security2:error] [pid 167459:tid 167648] [client 20.163.43.14:15717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/gelay.php"] [unique_id "aoSDXmr_JutbFb-8svr0egAAAco"] [Tue Aug 18 13:07:58.331919 2026] [security2:error] [pid 167459:tid 167684] [client 52.139.47.57:31566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/chosen.php"] [unique_id "aoSDXmr_JutbFb-8svr0ewAAAe4"] [Tue Aug 18 13:07:58.340622 2026] [security2:error] [pid 167459:tid 167695] [client 20.116.17.175:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "recantodaserra.hoteisecovip.com.br"] [uri "/we.php"] [unique_id "aoSDXmr_JutbFb-8svr0fAAAAfk"] [Tue Aug 18 13:07:58.342049 2026] [security2:error] [pid 167459:tid 167594] [client 20.127.136.245:18909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/goods.php"] [unique_id "aoSDXmr_JutbFb-8svr0fQAAAZQ"] [Tue Aug 18 13:07:58.345496 2026] [security2:error] [pid 167459:tid 167689] [client 20.104.100.201:17371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDXmr_JutbFb-8svr0fgAAAfM"] [Tue Aug 18 13:07:58.355035 2026] [security2:error] [pid 167459:tid 167713] [client 4.232.151.198:16574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/index.bak.php"] [unique_id "aoSDXmr_JutbFb-8svr0gQAAAgs"] [Tue Aug 18 13:07:58.373820 2026] [security2:error] [pid 167459:tid 167587] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/css/"] [unique_id "aoSDXmr_JutbFb-8svr0gwABr38"] [Tue Aug 18 13:07:58.382109 2026] [security2:error] [pid 167459:tid 167505] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/s93.php"] [unique_id "aoSDXmr_JutbFb-8svr0hAACDi0"] [Tue Aug 18 13:07:58.384696 2026] [security2:error] [pid 167459:tid 167681] [client 20.106.102.5:45232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDXmr_JutbFb-8svr0hQAAAes"] [Tue Aug 18 13:07:58.396739 2026] [security2:error] [pid 167459:tid 167674] [client 132.196.30.78:13091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDXmr_JutbFb-8svr0hgAAAeQ"] [Tue Aug 18 13:07:58.412703 2026] [security2:error] [pid 167459:tid 167495] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSDXmr_JutbFb-8svr0iAAB3SM"] [Tue Aug 18 13:07:58.421240 2026] [autoindex:error] [pid 167459:tid 167694] [client 172.182.217.32:4073] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/blocks/heading/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:58.485875 2026] [security2:error] [pid 167459:tid 167599] [client 74.248.18.37:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/delpaths.php"] [unique_id "aoSDXmr_JutbFb-8svr0iwAAAZk"] [Tue Aug 18 13:07:58.537240 2026] [authz_core:error] [pid 167459:tid 167483] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:58.537496 2026] [authz_core:error] [pid 167459:tid 167483] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:58.548820 2026] [security2:error] [pid 167459:tid 167607] [client 213.35.127.232:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDXmr_JutbFb-8svr0jQAAAaE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:58.563032 2026] [security2:error] [pid 167459:tid 167557] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/server.php"] [unique_id "aoSDXmr_JutbFb-8svr0jgACCmE"] [Tue Aug 18 13:07:58.583146 2026] [security2:error] [pid 167459:tid 167562] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/ty.php"] [unique_id "aoSDXmr_JutbFb-8svr0jwABuGY"] [Tue Aug 18 13:07:58.585154 2026] [security2:error] [pid 167459:tid 167510] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSDXmr_JutbFb-8svr0kQAB1jI"] [Tue Aug 18 13:07:58.585167 2026] [security2:error] [pid 167459:tid 167620] [client 172.182.217.32:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/blocks/heading/min.php"] [unique_id "aoSDXmr_JutbFb-8svr0kAAAAa4"] [Tue Aug 18 13:07:58.621955 2026] [security2:error] [pid 167459:tid 167595] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/HLA-dd.php"] [unique_id "aoSDXmr_JutbFb-8svr0lQAAAZU"] [Tue Aug 18 13:07:58.666352 2026] [security2:error] [pid 167459:tid 167554] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aoSDXmr_JutbFb-8svr0mAAB_14"] [Tue Aug 18 13:07:58.670906 2026] [security2:error] [pid 167459:tid 167590] [client 20.163.43.14:15718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDXmr_JutbFb-8svr0mQAAAZA"] [Tue Aug 18 13:07:58.712912 2026] [security2:error] [pid 167459:tid 167668] [client 20.106.102.5:45263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/cxc.php"] [unique_id "aoSDXmr_JutbFb-8svr0mgAAAd4"] [Tue Aug 18 13:07:58.743322 2026] [security2:error] [pid 167459:tid 167533] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/settings.php"] [unique_id "aoSDXmr_JutbFb-8svr0nQABj0k"] [Tue Aug 18 13:07:58.750456 2026] [security2:error] [pid 167459:tid 167685] [client 52.139.47.57:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/doc.php"] [unique_id "aoSDXmr_JutbFb-8svr0ngAAAe8"] [Tue Aug 18 13:07:58.752702 2026] [security2:error] [pid 167459:tid 167659] [client 52.173.121.69:28320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDXmr_JutbFb-8svr0nwAAAdU"] [Tue Aug 18 13:07:58.759129 2026] [security2:error] [pid 167459:tid 167478] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSDXmr_JutbFb-8svr0oAABmxI"] [Tue Aug 18 13:07:58.769912 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDXmr_JutbFb-8svr0oQAAAgQ"] [Tue Aug 18 13:07:58.783119 2026] [security2:error] [pid 167459:tid 167691] [client 20.127.136.245:23810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/php8.php"] [unique_id "aoSDXmr_JutbFb-8svr0ogAAAfU"] [Tue Aug 18 13:07:58.792661 2026] [security2:error] [pid 167459:tid 167678] [client 20.171.51.14:33539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/f.php"] [unique_id "aoSDXmr_JutbFb-8svr0pAAAAeg"] [Tue Aug 18 13:07:58.874046 2026] [security2:error] [pid 167459:tid 167655] [client 20.79.204.6:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/special.php"] [unique_id "aoSDXmr_JutbFb-8svr0pwAAAdE"] [Tue Aug 18 13:07:58.878943 2026] [security2:error] [pid 167459:tid 167600] [client 20.65.98.162:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/btx25.php"] [unique_id "aoSDXmr_JutbFb-8svr0qAAAAZo"] [Tue Aug 18 13:07:58.887867 2026] [security2:error] [pid 167459:tid 167646] [client 172.202.39.151:27852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/alfa.php"] [unique_id "aoSDXmr_JutbFb-8svr0qQAAAcg"] [Tue Aug 18 13:07:58.896560 2026] [security2:error] [pid 167459:tid 167524] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/u.php"] [unique_id "aoSDXmr_JutbFb-8svr0qgAB7kA"] [Tue Aug 18 13:07:58.945067 2026] [security2:error] [pid 167459:tid 167497] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/sf.php"] [unique_id "aoSDXmr_JutbFb-8svr0qwABlCU"] [Tue Aug 18 13:07:58.947378 2026] [security2:error] [pid 167459:tid 167502] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSDXmr_JutbFb-8svr0rAAB6So"] [Tue Aug 18 13:07:58.967389 2026] [security2:error] [pid 167459:tid 167688] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDXmr_JutbFb-8svr0rQAAAfI"] [Tue Aug 18 13:07:58.976587 2026] [security2:error] [pid 167459:tid 167492] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/pucci.php"] [unique_id "aoSDXmr_JutbFb-8svr0rwAB3yA"] [Tue Aug 18 13:07:58.985830 2026] [security2:error] [pid 167459:tid 167699] [client 4.232.151.198:48451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/index/function.php"] [unique_id "aoSDXmr_JutbFb-8svr0swAAAf0"] [Tue Aug 18 13:07:58.992605 2026] [proxy_http:error] [pid 167459:tid 167650] (20014)Internal error (specific information not available): [client 207.175.174.249:23562] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:58.997041 2026] [security2:error] [pid 167459:tid 167591] [client 20.163.43.14:15278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDXmr_JutbFb-8svr0tAAAAZE"] [Tue Aug 18 13:07:58.998711 2026] [security2:error] [pid 167459:tid 167693] [client 132.196.30.78:20319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/bgymj.php"] [unique_id "aoSDXmr_JutbFb-8svr0tQAAAfc"] [Tue Aug 18 13:07:59.036309 2026] [security2:error] [pid 167459:tid 167631] [client 20.106.102.5:45146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDX2r_JutbFb-8svr0twAAAbk"] [Tue Aug 18 13:07:59.080832 2026] [security2:error] [pid 167459:tid 167695] [client 172.182.217.32:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/config.php"] [unique_id "aoSDX2r_JutbFb-8svr0uQAAAfk"] [Tue Aug 18 13:07:59.085577 2026] [security2:error] [pid 167459:tid 167683] [client 20.250.13.23:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/xleet.php"] [unique_id "aoSDX2r_JutbFb-8svr0ugAAAe0"] [Tue Aug 18 13:07:59.101291 2026] [security2:error] [pid 167459:tid 167632] [client 45.92.229.97:41475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSDX2r_JutbFb-8svr0uwAAAbo"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:07:59.126047 2026] [security2:error] [pid 167459:tid 167585] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDX2r_JutbFb-8svr0vQABw30"] [Tue Aug 18 13:07:59.126090 2026] [security2:error] [pid 167459:tid 167488] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/shell.php"] [unique_id "aoSDX2r_JutbFb-8svr0vAACAxw"] [Tue Aug 18 13:07:59.140058 2026] [security2:error] [pid 167459:tid 167625] [client 52.173.121.69:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDX2r_JutbFb-8svr0wAAAAbM"] [Tue Aug 18 13:07:59.141014 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:59.141256 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:59.159439 2026] [security2:error] [pid 167459:tid 167697] [client 207.175.174.249:23582] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/webhook"] [unique_id "aoSDX2r_JutbFb-8svr0wQAAAfs"] [Tue Aug 18 13:07:59.168426 2026] [security2:error] [pid 167459:tid 167702] [client 52.139.47.57:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/elp.php"] [unique_id "aoSDX2r_JutbFb-8svr0wwAAAgA"] [Tue Aug 18 13:07:59.186107 2026] [security2:error] [pid 167459:tid 167660] [client 20.226.36.136:25910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDX2r_JutbFb-8svr0xAAAAdY"] [Tue Aug 18 13:07:59.209711 2026] [security2:error] [pid 167459:tid 167548] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/ultra.php"] [unique_id "aoSDX2r_JutbFb-8svr0xQABrFg"] [Tue Aug 18 13:07:59.214185 2026] [security2:error] [pid 167459:tid 167667] [client 74.248.18.37:7002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/sindicat.php"] [unique_id "aoSDX2r_JutbFb-8svr0xgAAAd0"] [Tue Aug 18 13:07:59.242963 2026] [security2:error] [pid 167459:tid 167613] [client 74.248.18.37:34965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/goods.php"] [unique_id "aoSDX2r_JutbFb-8svr0xwAAAac"] [Tue Aug 18 13:07:59.266819 2026] [security2:error] [pid 167459:tid 167461] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "aoSDX2r_JutbFb-8svr0yAABngE"] [Tue Aug 18 13:07:59.270393 2026] [security2:error] [pid 167459:tid 167668] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/cah.php"] [unique_id "aoSDX2r_JutbFb-8svr0yQAAAd4"] [Tue Aug 18 13:07:59.311283 2026] [security2:error] [pid 167459:tid 167541] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/shiny.php"] [unique_id "aoSDX2r_JutbFb-8svr0ywAB1VE"] [Tue Aug 18 13:07:59.311283 2026] [security2:error] [pid 167459:tid 167654] [client 20.151.109.219:42769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/nu.php"] [unique_id "aoSDX2r_JutbFb-8svr0ygAAAdA"] [Tue Aug 18 13:07:59.311494 2026] [security2:error] [pid 167459:tid 167474] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDX2r_JutbFb-8svr0zAAB7w4"] [Tue Aug 18 13:07:59.320816 2026] [security2:error] [pid 167459:tid 167601] [client 172.202.39.151:39179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/lock360.php"] [unique_id "aoSDX2r_JutbFb-8svr0zQAAAZs"] [Tue Aug 18 13:07:59.327035 2026] [security2:error] [pid 167459:tid 167634] [client 40.74.65.169:36942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDX2r_JutbFb-8svr0zgAAAbw"] [Tue Aug 18 13:07:59.340155 2026] [security2:error] [pid 167459:tid 167690] [client 20.206.73.37:55315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/zi-936.php"] [unique_id "aoSDX2r_JutbFb-8svr00AAAAfQ"] [Tue Aug 18 13:07:59.348084 2026] [http2:warn] [pid 157386:tid 157626] [client 17.246.19.48:44418] h2_stream(157386-1082-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:07:59.377377 2026] [security2:error] [pid 167459:tid 167593] [client 20.106.102.5:45204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/0.php"] [unique_id "aoSDX2r_JutbFb-8svr00gAAAZM"] [Tue Aug 18 13:07:59.385203 2026] [security2:error] [pid 167459:tid 167673] [client 207.175.174.249:23238] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDX2r_JutbFb-8svr01AAAAeM"] [Tue Aug 18 13:07:59.385209 2026] [security2:error] [pid 167459:tid 167715] [client 20.127.136.245:19335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/info.php"] [unique_id "aoSDX2r_JutbFb-8svr00wAAAg0"] [Tue Aug 18 13:07:59.439230 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:59.439500 2026] [security2:error] [pid 167459:tid 167638] [client 5.31.227.224:1419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr01wAAAcA"] [Tue Aug 18 13:07:59.439599 2026] [security2:error] [pid 167459:tid 167638] [client 5.31.227.224:1419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr01wAAAcA"] [Tue Aug 18 13:07:59.439601 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:59.492462 2026] [security2:error] [pid 167459:tid 167576] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/sid3.php"] [unique_id "aoSDX2r_JutbFb-8svr02wACC3Q"] [Tue Aug 18 13:07:59.494043 2026] [security2:error] [pid 167459:tid 167513] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDX2r_JutbFb-8svr03AABsDU"] [Tue Aug 18 13:07:59.500389 2026] [proxy_http:error] [pid 167459:tid 167646] (20014)Internal error (specific information not available): [client 207.175.174.249:23584] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:59.500408 2026] [proxy:error] [pid 167459:tid 167646] [client 207.175.174.249:23584] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/download [Tue Aug 18 13:07:59.506685 2026] [security2:error] [pid 167459:tid 167700] [client 20.163.43.14:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDX2r_JutbFb-8svr03QAAAf4"] [Tue Aug 18 13:07:59.521642 2026] [security2:error] [pid 167459:tid 167561] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/up.php"] [unique_id "aoSDX2r_JutbFb-8svr03gAB5GU"] [Tue Aug 18 13:07:59.554902 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.100.201:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/fine.php"] [unique_id "aoSDX2r_JutbFb-8svr03wAAAfc"] [Tue Aug 18 13:07:59.566148 2026] [security2:error] [pid 167459:tid 167701] [client 213.35.127.232:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDX2r_JutbFb-8svr04AAAAf8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:07:59.569336 2026] [security2:error] [pid 167459:tid 167527] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "aoSDX2r_JutbFb-8svr04QAB3EM"] [Tue Aug 18 13:07:59.585503 2026] [autoindex:error] [pid 167459:tid 167655] [client 172.182.217.32:4134] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:07:59.590263 2026] [security2:error] [pid 167459:tid 167684] [client 52.139.47.57:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/Exception-class.php"] [unique_id "aoSDX2r_JutbFb-8svr05AAAAe4"] [Tue Aug 18 13:07:59.652118 2026] [security2:error] [pid 167459:tid 167633] [client 4.232.151.198:48495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/info.php"] [unique_id "aoSDX2r_JutbFb-8svr06QAAAbs"] [Tue Aug 18 13:07:59.659805 2026] [security2:error] [pid 167459:tid 167648] [client 20.79.204.6:5704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSDX2r_JutbFb-8svr06gAAAco"] [Tue Aug 18 13:07:59.669092 2026] [security2:error] [pid 167459:tid 167486] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSDX2r_JutbFb-8svr07gABoBo"] [Tue Aug 18 13:07:59.674421 2026] [security2:error] [pid 167459:tid 167559] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/sid4.php"] [unique_id "aoSDX2r_JutbFb-8svr07wAB-2M"] [Tue Aug 18 13:07:59.684669 2026] [security2:error] [pid 167459:tid 167592] [client 132.196.30.78:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/aa.php"] [unique_id "aoSDX2r_JutbFb-8svr08AAAAZI"] [Tue Aug 18 13:07:59.704264 2026] [security2:error] [pid 167459:tid 167681] [client 20.106.102.5:45226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/dom.php"] [unique_id "aoSDX2r_JutbFb-8svr08QAAAes"] [Tue Aug 18 13:07:59.704834 2026] [security2:error] [pid 167459:tid 167702] [client 20.151.109.219:40448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ko.php"] [unique_id "aoSDX2r_JutbFb-8svr08gAAAgA"] [Tue Aug 18 13:07:59.736290 2026] [security2:error] [pid 167459:tid 167675] [client 172.202.39.151:39207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/flower.php"] [unique_id "aoSDX2r_JutbFb-8svr09AAAAeU"] [Tue Aug 18 13:07:59.739880 2026] [security2:error] [pid 167459:tid 167603] [client 37.40.227.74:57078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr09QAAAZ0"] [Tue Aug 18 13:07:59.743703 2026] [security2:error] [pid 167459:tid 167603] [client 37.40.227.74:57078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr09QAAAZ0"] [Tue Aug 18 13:07:59.744906 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:07:59.745320 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:07:59.748950 2026] [security2:error] [pid 167459:tid 167687] [client 172.182.217.32:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/css/index.php"] [unique_id "aoSDX2r_JutbFb-8svr09gAAAfE"] [Tue Aug 18 13:07:59.770249 2026] [security2:error] [pid 167459:tid 167610] [client 20.127.136.245:10792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/chosen.php"] [unique_id "aoSDX2r_JutbFb-8svr0-AAAAaQ"] [Tue Aug 18 13:07:59.791663 2026] [security2:error] [pid 167459:tid 167590] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/system_log.php"] [unique_id "aoSDX2r_JutbFb-8svr0-QAAAZA"] [Tue Aug 18 13:07:59.832052 2026] [security2:error] [pid 167459:tid 167604] [client 20.163.43.14:15707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/about.php"] [unique_id "aoSDX2r_JutbFb-8svr0-wAAAZ4"] [Tue Aug 18 13:07:59.835007 2026] [security2:error] [pid 167459:tid 167514] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/upload.php"] [unique_id "aoSDX2r_JutbFb-8svr0_AAB3jY"] [Tue Aug 18 13:07:59.851152 2026] [security2:error] [pid 167459:tid 167503] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDX2r_JutbFb-8svr0_QABjys"] [Tue Aug 18 13:07:59.854117 2026] [security2:error] [pid 167459:tid 167609] [client 49.37.150.8:54808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr0_gAAAaM"] [Tue Aug 18 13:07:59.854205 2026] [security2:error] [pid 167459:tid 167609] [client 49.37.150.8:54808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDX2r_JutbFb-8svr0_gAAAaM"] [Tue Aug 18 13:07:59.859592 2026] [security2:error] [pid 167459:tid 167555] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDX2r_JutbFb-8svr1AAABm18"] [Tue Aug 18 13:07:59.888977 2026] [proxy_http:error] [pid 167459:tid 167678] (20014)Internal error (specific information not available): [client 207.175.174.249:23600] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:07:59.925144 2026] [security2:error] [pid 167459:tid 167712] [client 74.248.18.37:20872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/user/flower.php"] [unique_id "aoSDX2r_JutbFb-8svr1BgAAAgo"] [Tue Aug 18 13:07:59.933755 2026] [security2:error] [pid 167459:tid 167638] [client 20.116.17.175:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/setup-config.php"] [unique_id "aoSDX2r_JutbFb-8svr1CAAAAcA"] [Tue Aug 18 13:07:59.944606 2026] [security2:error] [pid 167459:tid 167662] [client 207.175.174.249:23606] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/preview"] [unique_id "aoSDX2r_JutbFb-8svr1CQAAAdg"] [Tue Aug 18 13:07:59.978052 2026] [security2:error] [pid 167459:tid 167713] [client 52.173.121.69:36607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDX2r_JutbFb-8svr1CgAAAgs"] [Tue Aug 18 13:08:00.006146 2026] [security2:error] [pid 167459:tid 167677] [client 207.175.174.249:23292] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYGr_JutbFb-8svr1EgAAAec"] [Tue Aug 18 13:08:00.018428 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:63542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ee.php"] [unique_id "aoSDYGr_JutbFb-8svr1FQAAAfQ"] [Tue Aug 18 13:08:00.023262 2026] [security2:error] [pid 167459:tid 167563] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-content.php"] [unique_id "aoSDYGr_JutbFb-8svr1FgACBmc"] [Tue Aug 18 13:08:00.026118 2026] [security2:error] [pid 167459:tid 167699] [client 20.106.102.5:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/bb.php"] [unique_id "aoSDYGr_JutbFb-8svr1FwAAAf0"] [Tue Aug 18 13:08:00.045113 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:00.045584 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:00.051490 2026] [security2:error] [pid 167459:tid 167516] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/size.php"] [unique_id "aoSDYGr_JutbFb-8svr1HQABzDg"] [Tue Aug 18 13:08:00.056386 2026] [security2:error] [pid 167459:tid 167591] [client 40.74.65.169:20564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1HgAAAZE"] [Tue Aug 18 13:08:00.081390 2026] [security2:error] [pid 167459:tid 167683] [client 86.120.159.145:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDYGr_JutbFb-8svr1IgAAAe0"] [Tue Aug 18 13:08:00.081728 2026] [security2:error] [pid 167459:tid 167683] [client 86.120.159.145:23451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDYGr_JutbFb-8svr1IgAAAe0"] [Tue Aug 18 13:08:00.117756 2026] [security2:error] [pid 167459:tid 167607] [client 20.151.109.219:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/pl.php"] [unique_id "aoSDYGr_JutbFb-8svr1JQAAAaE"] [Tue Aug 18 13:08:00.137860 2026] [security2:error] [pid 167459:tid 167504] [remote 162.214.205.212:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/wp-login.php"] [unique_id "aoSDYGr_JutbFb-8svr1JgAB-iw"] [Tue Aug 18 13:08:00.146532 2026] [security2:error] [pid 167459:tid 167606] [client 172.202.39.151:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/13.php"] [unique_id "aoSDYGr_JutbFb-8svr1JwAAAaA"] [Tue Aug 18 13:08:00.147869 2026] [security2:error] [pid 167459:tid 167672] [client 20.250.13.23:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp.php"] [unique_id "aoSDYGr_JutbFb-8svr1KAAAAeI"] [Tue Aug 18 13:08:00.150278 2026] [security2:error] [pid 167459:tid 167583] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1KgACA3s"] [Tue Aug 18 13:08:00.155805 2026] [security2:error] [pid 167459:tid 167592] [client 20.163.43.14:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1KwAAAZI"] [Tue Aug 18 13:08:00.184687 2026] [security2:error] [pid 167459:tid 167646] [client 132.196.30.78:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDYGr_JutbFb-8svr1LAAAAcg"] [Tue Aug 18 13:08:00.185776 2026] [security2:error] [pid 167459:tid 167670] [client 20.127.136.245:10275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/simple.php"] [unique_id "aoSDYGr_JutbFb-8svr1LQAAAeA"] [Tue Aug 18 13:08:00.243544 2026] [security2:error] [pid 167459:tid 167666] [client 172.182.217.32:25592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/css/min.php"] [unique_id "aoSDYGr_JutbFb-8svr1MAAAAdw"] [Tue Aug 18 13:08:00.247803 2026] [security2:error] [pid 167459:tid 167629] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1MQAAAbc"] [Tue Aug 18 13:08:00.271022 2026] [security2:error] [pid 167459:tid 167686] [client 20.104.100.201:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/term.php"] [unique_id "aoSDYGr_JutbFb-8svr1MwAAAfA"] [Tue Aug 18 13:08:00.297845 2026] [security2:error] [pid 167459:tid 167522] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/special.php"] [unique_id "aoSDYGr_JutbFb-8svr1NAABvT4"] [Tue Aug 18 13:08:00.305099 2026] [security2:error] [pid 167459:tid 167684] [client 20.79.204.6:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/storage/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1NQAAAe4"] [Tue Aug 18 13:08:00.317021 2026] [security2:error] [pid 167459:tid 167641] [client 158.158.74.177:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSDYGr_JutbFb-8svr1NwAAAcM"] [Tue Aug 18 13:08:00.341293 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:00.341566 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:00.348529 2026] [security2:error] [pid 167459:tid 167659] [client 20.106.102.5:45297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ok.php"] [unique_id "aoSDYGr_JutbFb-8svr1OwAAAdU"] [Tue Aug 18 13:08:00.355307 2026] [security2:error] [pid 167459:tid 167601] [client 207.175.174.249:23642] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/image"] [unique_id "aoSDYGr_JutbFb-8svr1PAAAAZs"] [Tue Aug 18 13:08:00.392527 2026] [security2:error] [pid 167459:tid 167544] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDYGr_JutbFb-8svr1PgACCFQ"] [Tue Aug 18 13:08:00.393418 2026] [security2:error] [pid 167459:tid 167702] [client 4.232.151.198:16543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/inputs.php"] [unique_id "aoSDYGr_JutbFb-8svr1PwAAAgA"] [Tue Aug 18 13:08:00.439925 2026] [security2:error] [pid 167459:tid 167500] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/puc.php"] [unique_id "aoSDYGr_JutbFb-8svr1QQACDSg"] [Tue Aug 18 13:08:00.444369 2026] [security2:error] [pid 167459:tid 167653] [client 52.139.47.57:63514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/edit.php"] [unique_id "aoSDYGr_JutbFb-8svr1QgAAAc8"] [Tue Aug 18 13:08:00.467599 2026] [security2:error] [pid 167459:tid 167473] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/v5.php"] [unique_id "aoSDYGr_JutbFb-8svr1RAABmg0"] [Tue Aug 18 13:08:00.479673 2026] [security2:error] [pid 167459:tid 167579] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ssjpxze.php"] [unique_id "aoSDYGr_JutbFb-8svr1RQABwHc"] [Tue Aug 18 13:08:00.499909 2026] [security2:error] [pid 167459:tid 167594] [client 20.163.43.14:15641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/f35.php"] [unique_id "aoSDYGr_JutbFb-8svr1RgAAAZQ"] [Tue Aug 18 13:08:00.537199 2026] [security2:error] [pid 167459:tid 167673] [client 20.127.136.245:16588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDYGr_JutbFb-8svr1SAAAAeM"] [Tue Aug 18 13:08:00.541251 2026] [security2:error] [pid 167459:tid 167622] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/ioxi-o.php"] [unique_id "aoSDYGr_JutbFb-8svr1SQAAAbA"] [Tue Aug 18 13:08:00.565919 2026] [security2:error] [pid 167459:tid 167512] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSDYGr_JutbFb-8svr1SgAB9DQ"] [Tue Aug 18 13:08:00.580302 2026] [security2:error] [pid 167459:tid 167667] [client 213.35.127.232:57210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1SwAAAd0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:00.583626 2026] [security2:error] [pid 167459:tid 167627] [client 172.202.39.151:27844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/cc.php"] [unique_id "aoSDYGr_JutbFb-8svr1TAAAAbU"] [Tue Aug 18 13:08:00.590739 2026] [security2:error] [pid 167459:tid 167658] [client 223.185.37.47:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDYGr_JutbFb-8svr1TQAAAdQ"] [Tue Aug 18 13:08:00.590858 2026] [security2:error] [pid 167459:tid 167658] [client 223.185.37.47:19277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDYGr_JutbFb-8svr1TQAAAdQ"] [Tue Aug 18 13:08:00.618095 2026] [security2:error] [pid 167459:tid 167591] [client 20.104.100.201:17404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/99.php"] [unique_id "aoSDYGr_JutbFb-8svr1UgAAAZE"] [Tue Aug 18 13:08:00.644641 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:00.644942 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:00.667358 2026] [security2:error] [pid 167459:tid 167631] [client 52.173.121.69:36556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDYGr_JutbFb-8svr1VQAAAbk"] [Tue Aug 18 13:08:00.668507 2026] [security2:error] [pid 167459:tid 167493] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/storage/index.php"] [unique_id "aoSDYGr_JutbFb-8svr1VgAB-CE"] [Tue Aug 18 13:08:00.674171 2026] [security2:error] [pid 167459:tid 167614] [client 74.248.18.37:34978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/file.php"] [unique_id "aoSDYGr_JutbFb-8svr1VwAAAag"] [Tue Aug 18 13:08:00.675940 2026] [security2:error] [pid 167459:tid 167692] [client 20.106.102.5:45132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp9.php"] [unique_id "aoSDYGr_JutbFb-8svr1WAAAAfY"] [Tue Aug 18 13:08:00.685504 2026] [security2:error] [pid 167459:tid 167680] [client 158.158.74.177:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSDYGr_JutbFb-8svr1WQAAAeo"] [Tue Aug 18 13:08:00.731976 2026] [security2:error] [pid 167459:tid 167531] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/Requests/"] [unique_id "aoSDYGr_JutbFb-8svr1WwABu0c"] [Tue Aug 18 13:08:00.732825 2026] [security2:error] [pid 167459:tid 167688] [client 132.196.30.78:13077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/bolt.php"] [unique_id "aoSDYGr_JutbFb-8svr1XAAAAfI"] [Tue Aug 18 13:08:00.737243 2026] [security2:error] [pid 167459:tid 167699] [client 172.182.217.32:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/css/wp-login.php"] [unique_id "aoSDYGr_JutbFb-8svr1XQAAAf0"] [Tue Aug 18 13:08:00.738455 2026] [security2:error] [pid 167459:tid 167577] [remote 20.91.215.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.aceleradigital.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDYGr_JutbFb-8svr1XwAB0XU"] [Tue Aug 18 13:08:00.750353 2026] [security2:error] [pid 167459:tid 167651] [client 74.248.18.37:30765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/Diff/Renderer/about.php"] [unique_id "aoSDYGr_JutbFb-8svr1YAAAAc0"] [Tue Aug 18 13:08:00.759225 2026] [security2:error] [pid 167459:tid 167605] [client 40.74.65.169:20557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/puc.php"] [unique_id "aoSDYGr_JutbFb-8svr1YQAAAZ8"] [Tue Aug 18 13:08:00.778558 2026] [security2:error] [pid 167459:tid 167462] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/w.php"] [unique_id "aoSDYGr_JutbFb-8svr1YgABygI"] [Tue Aug 18 13:08:00.789646 2026] [security2:error] [pid 167459:tid 167677] [client 207.175.174.249:23336] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/image"] [unique_id "aoSDYGr_JutbFb-8svr1ZAAAAec"] [Tue Aug 18 13:08:00.840648 2026] [security2:error] [pid 167459:tid 167697] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/abc.php"] [unique_id "aoSDYGr_JutbFb-8svr1aAAAAfs"] [Tue Aug 18 13:08:00.846091 2026] [security2:error] [pid 167459:tid 167681] [client 20.151.109.219:28744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/env.php"] [unique_id "aoSDYGr_JutbFb-8svr1aQAAAes"] [Tue Aug 18 13:08:00.848557 2026] [security2:error] [pid 167459:tid 167630] [client 20.127.136.245:18912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/av.php"] [unique_id "aoSDYGr_JutbFb-8svr1agAAAbg"] [Tue Aug 18 13:08:00.850378 2026] [security2:error] [pid 167459:tid 167570] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDYGr_JutbFb-8svr1awAB1m4"] [Tue Aug 18 13:08:00.875024 2026] [security2:error] [pid 167459:tid 167599] [client 52.139.47.57:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/f35.php"] [unique_id "aoSDYGr_JutbFb-8svr1bQAAAZk"] [Tue Aug 18 13:08:00.878448 2026] [security2:error] [pid 167459:tid 167671] [client 20.104.100.201:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/loader.php"] [unique_id "aoSDYGr_JutbFb-8svr1bgAAAeE"] [Tue Aug 18 13:08:00.882407 2026] [security2:error] [pid 167459:tid 167646] [client 207.175.174.249:23628] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYGr_JutbFb-8svr1bwAAAcg"] [Tue Aug 18 13:08:00.940529 2026] [security2:error] [pid 167459:tid 167676] [client 158.158.74.177:13712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSDYGr_JutbFb-8svr1cgAAAeY"] [Tue Aug 18 13:08:00.969791 2026] [security2:error] [pid 167459:tid 167645] [client 4.232.151.198:48617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/term.php"] [unique_id "aoSDYGr_JutbFb-8svr1dAAAAcc"] [Tue Aug 18 13:08:00.996245 2026] [security2:error] [pid 167459:tid 167684] [client 20.163.43.14:15733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/inputs.php"] [unique_id "aoSDYGr_JutbFb-8svr1dQAAAe4"] [Tue Aug 18 13:08:00.999168 2026] [security2:error] [pid 167459:tid 167661] [client 20.106.102.5:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ws59.php"] [unique_id "aoSDYGr_JutbFb-8svr1dwAAAdc"] [Tue Aug 18 13:08:01.023258 2026] [security2:error] [pid 167459:tid 167575] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/8.php"] [unique_id "aoSDYWr_JutbFb-8svr1eAABj3M"] [Tue Aug 18 13:08:01.039131 2026] [security2:error] [pid 167459:tid 167659] [client 207.175.174.249:23612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1eQAAAdU"] [Tue Aug 18 13:08:01.090559 2026] [security2:error] [pid 167459:tid 167705] [client 20.79.204.6:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDYWr_JutbFb-8svr1ewAAAgM"] [Tue Aug 18 13:08:01.090929 2026] [security2:error] [pid 167459:tid 167507] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/we.php"] [unique_id "aoSDYWr_JutbFb-8svr1fAABmy8"] [Tue Aug 18 13:08:01.091741 2026] [security2:error] [pid 167459:tid 167586] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/sts.php"] [unique_id "aoSDYWr_JutbFb-8svr1fQABqn4"] [Tue Aug 18 13:08:01.122366 2026] [security2:error] [pid 167459:tid 167617] [client 20.171.51.14:30562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/30.php"] [unique_id "aoSDYWr_JutbFb-8svr1fgAAAas"] [Tue Aug 18 13:08:01.130487 2026] [security2:error] [pid 167459:tid 167698] [client 52.173.121.69:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDYWr_JutbFb-8svr1fwAAAfw"] [Tue Aug 18 13:08:01.146285 2026] [security2:error] [pid 167459:tid 167702] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/akcc.php"] [unique_id "aoSDYWr_JutbFb-8svr1ggAAAgA"] [Tue Aug 18 13:08:01.154076 2026] [security2:error] [pid 167459:tid 167629] [client 4.232.151.198:2963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/install.php"] [unique_id "aoSDYWr_JutbFb-8svr1hAAAAbc"] [Tue Aug 18 13:08:01.170993 2026] [security2:error] [pid 167459:tid 167707] [client 172.202.39.151:27897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDYWr_JutbFb-8svr1hQAAAgU"] [Tue Aug 18 13:08:01.224630 2026] [security2:error] [pid 167459:tid 167594] [client 207.175.174.249:23648] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDYWr_JutbFb-8svr1iAAAAZQ"] [Tue Aug 18 13:08:01.235024 2026] [security2:error] [pid 167459:tid 167654] [client 172.182.217.32:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/id3/about.php"] [unique_id "aoSDYWr_JutbFb-8svr1iQAAAdA"] [Tue Aug 18 13:08:01.242503 2026] [security2:error] [pid 167459:tid 167689] [client 207.175.174.249:23712] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1jAAAAfM"] [Tue Aug 18 13:08:01.245438 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:01.245694 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:01.252376 2026] [security2:error] [pid 167459:tid 167662] [client 20.226.36.136:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDYWr_JutbFb-8svr1jQAAAdg"] [Tue Aug 18 13:08:01.257863 2026] [security2:error] [pid 167459:tid 167673] [client 20.104.100.201:53373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/black.php"] [unique_id "aoSDYWr_JutbFb-8svr1jwAAAeM"] [Tue Aug 18 13:08:01.257960 2026] [security2:error] [pid 167459:tid 167706] [client 132.196.30.78:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/bthil.php"] [unique_id "aoSDYWr_JutbFb-8svr1jgAAAgQ"] [Tue Aug 18 13:08:01.272703 2026] [security2:error] [pid 167459:tid 167476] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/system_log.php"] [unique_id "aoSDYWr_JutbFb-8svr1kAABsBA"] [Tue Aug 18 13:08:01.278257 2026] [security2:error] [pid 167459:tid 167690] [client 207.175.174.249:23664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/fetch?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDYWr_JutbFb-8svr1kQAAAfQ"] [Tue Aug 18 13:08:01.287522 2026] [security2:error] [pid 167459:tid 167708] [client 207.175.174.249:23584] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYWr_JutbFb-8svr1kgAAAgY"] [Tue Aug 18 13:08:01.314374 2026] [security2:error] [pid 167459:tid 167553] [remote 40.74.65.169:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSDYWr_JutbFb-8svr1kwABr10"] [Tue Aug 18 13:08:01.314462 2026] [security2:error] [pid 167459:tid 167553] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/1.php"] [unique_id "aoSDYWr_JutbFb-8svr1kwABr10"] [Tue Aug 18 13:08:01.322282 2026] [security2:error] [pid 167459:tid 167650] [client 20.106.102.5:45215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/Ov-Simple1.php"] [unique_id "aoSDYWr_JutbFb-8svr1lQAAAcw"] [Tue Aug 18 13:08:01.364227 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/fff.php"] [unique_id "aoSDYWr_JutbFb-8svr1mgAAAdk"] [Tue Aug 18 13:08:01.402706 2026] [security2:error] [pid 167459:tid 167465] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wk/index.php"] [unique_id "aoSDYWr_JutbFb-8svr1nAAB7QU"] [Tue Aug 18 13:08:01.447809 2026] [security2:error] [pid 167459:tid 167614] [client 207.175.174.249:23686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "=(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?)://" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "517"] [id "340165"] [rev "291"] [msg "Atomicorp.com WAF Rules: Uniencoded possible Remote File Injection attempt in URI (AE)"] [data "/proxy?url=file:///root/.aws/credentials"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1ngAAAag"] [Tue Aug 18 13:08:01.453260 2026] [security2:error] [pid 167459:tid 167639] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wk/index.php"] [unique_id "aoSDYWr_JutbFb-8svr1nwAAAcE"] [Tue Aug 18 13:08:01.455103 2026] [security2:error] [pid 167459:tid 167477] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/t.php"] [unique_id "aoSDYWr_JutbFb-8svr1oAAB6hE"] [Tue Aug 18 13:08:01.460027 2026] [security2:error] [pid 167459:tid 167709] [client 207.175.174.249:23644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDYWr_JutbFb-8svr1oQAAAgc"] [Tue Aug 18 13:08:01.482069 2026] [security2:error] [pid 167459:tid 167655] [client 172.202.39.151:27846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSDYWr_JutbFb-8svr1pAAAAdE"] [Tue Aug 18 13:08:01.482536 2026] [security2:error] [pid 167459:tid 167685] [client 207.175.174.249:23716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1owAAAe8"] [Tue Aug 18 13:08:01.517951 2026] [security2:error] [pid 167459:tid 167682] [client 20.127.136.245:24795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp.php"] [unique_id "aoSDYWr_JutbFb-8svr1pQAAAew"] [Tue Aug 18 13:08:01.518017 2026] [security2:error] [pid 167459:tid 167677] [client 207.175.174.249:23646] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1pgAAAec"] [Tue Aug 18 13:08:01.519227 2026] [security2:error] [pid 167459:tid 167679] [client 74.248.18.37:30744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-setting.php"] [unique_id "aoSDYWr_JutbFb-8svr1pwAAAek"] [Tue Aug 18 13:08:01.531878 2026] [security2:error] [pid 167459:tid 167606] [client 207.175.174.249:23664] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/fetch"] [unique_id "aoSDYWr_JutbFb-8svr1qAAAAaA"] [Tue Aug 18 13:08:01.537777 2026] [security2:error] [pid 167459:tid 167615] [client 20.104.100.201:13911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/zero.php"] [unique_id "aoSDYWr_JutbFb-8svr1qQAAAak"] [Tue Aug 18 13:08:01.547469 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:01.547918 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:01.551359 2026] [security2:error] [pid 167459:tid 167592] [client 207.175.174.249:23702] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDYWr_JutbFb-8svr1qwAAAZI"] [Tue Aug 18 13:08:01.555624 2026] [proxy_http:error] [pid 167459:tid 167677] (20014)Internal error (specific information not available): [client 207.175.174.249:23646] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:01.555635 2026] [proxy:error] [pid 167459:tid 167677] [client 207.175.174.249:23646] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html [Tue Aug 18 13:08:01.556193 2026] [security2:error] [pid 167459:tid 167681] [client 20.206.73.37:21612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSDYWr_JutbFb-8svr1rAAAAes"] [Tue Aug 18 13:08:01.564337 2026] [security2:error] [pid 167459:tid 167653] [client 178.128.23.175:50777] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "paulinhoveiculos.com"] [uri "/"] [unique_id "aoSDYWr_JutbFb-8svr1rQAAAc8"] [Tue Aug 18 13:08:01.570437 2026] [security2:error] [pid 167459:tid 167627] [client 85.208.96.201:51202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bergoninf.com"] [uri "/robots.txt"] [unique_id "aoSDYWr_JutbFb-8svr1rgAAAbU"] [Tue Aug 18 13:08:01.570553 2026] [security2:error] [pid 167459:tid 167627] [client 85.208.96.201:51202] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bergoninf.com"] [uri "/robots.txt"] [unique_id "aoSDYWr_JutbFb-8svr1rgAAAbU"] [Tue Aug 18 13:08:01.573113 2026] [security2:error] [pid 167459:tid 167701] [client 158.158.74.177:13809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/st.php"] [unique_id "aoSDYWr_JutbFb-8svr1rwAAAf8"] [Tue Aug 18 13:08:01.573517 2026] [security2:error] [pid 167459:tid 167599] [client 207.175.174.249:23670] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYWr_JutbFb-8svr1sAAAAZk"] [Tue Aug 18 13:08:01.595601 2026] [security2:error] [pid 167459:tid 167713] [client 213.35.127.232:57439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDYWr_JutbFb-8svr1sgAAAgs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:01.605608 2026] [security2:error] [pid 167459:tid 167469] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/about.php"] [unique_id "aoSDYWr_JutbFb-8svr1swABnAk"] [Tue Aug 18 13:08:01.647335 2026] [security2:error] [pid 167459:tid 167603] [client 20.106.102.5:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSDYWr_JutbFb-8svr1tQAAAZ0"] [Tue Aug 18 13:08:01.650461 2026] [security2:error] [pid 167459:tid 167490] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/templates.php"] [unique_id "aoSDYWr_JutbFb-8svr1tgABpR4"] [Tue Aug 18 13:08:01.677500 2026] [security2:error] [pid 167459:tid 167610] [client 20.65.98.162:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSDYWr_JutbFb-8svr1uQAAAaQ"] [Tue Aug 18 13:08:01.693494 2026] [security2:error] [pid 167459:tid 167694] [client 74.248.18.37:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDYWr_JutbFb-8svr1uwAAAfg"] [Tue Aug 18 13:08:01.716911 2026] [security2:error] [pid 167459:tid 167613] [client 20.163.43.14:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/alfa.php"] [unique_id "aoSDYWr_JutbFb-8svr1vQAAAac"] [Tue Aug 18 13:08:01.719775 2026] [security2:error] [pid 167459:tid 167672] [client 172.182.217.32:4035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/id3/index.php"] [unique_id "aoSDYWr_JutbFb-8svr1vgAAAeI"] [Tue Aug 18 13:08:01.726859 2026] [security2:error] [pid 167459:tid 167646] [client 52.173.121.69:28340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDYWr_JutbFb-8svr1vwAAAcg"] [Tue Aug 18 13:08:01.730050 2026] [security2:error] [pid 167459:tid 167604] [client 207.175.174.249:23686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:url. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1wAAAAZ4"] [Tue Aug 18 13:08:01.740089 2026] [security2:error] [pid 167459:tid 167696] [client 20.79.204.6:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/sts.php"] [unique_id "aoSDYWr_JutbFb-8svr1wQAAAfo"] [Tue Aug 18 13:08:01.764878 2026] [security2:error] [pid 167459:tid 167697] [client 20.250.13.23:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/155.php"] [unique_id "aoSDYWr_JutbFb-8svr1wwAAAfs"] [Tue Aug 18 13:08:01.774186 2026] [security2:error] [pid 167459:tid 167505] [remote 185.118.190.176:50988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.190.118.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoSDYWr_JutbFb-8svr1xAABuy0"] [Tue Aug 18 13:08:01.781366 2026] [security2:error] [pid 167459:tid 167675] [client 52.139.47.57:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ff1.php"] [unique_id "aoSDYWr_JutbFb-8svr1xQAAAeU"] [Tue Aug 18 13:08:01.784608 2026] [security2:error] [pid 167459:tid 167641] [client 172.202.39.151:27876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/01.php"] [unique_id "aoSDYWr_JutbFb-8svr1xgAAAcM"] [Tue Aug 18 13:08:01.787201 2026] [security2:error] [pid 167459:tid 167695] [client 172.202.39.151:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSDYWr_JutbFb-8svr1xwAAAfk"] [Tue Aug 18 13:08:01.787288 2026] [security2:error] [pid 167459:tid 167695] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/1.php"] [unique_id "aoSDYWr_JutbFb-8svr1xwAAAfk"] [Tue Aug 18 13:08:01.806446 2026] [security2:error] [pid 167459:tid 167601] [client 207.175.174.249:23716] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYWr_JutbFb-8svr1yAAAAZs"] [Tue Aug 18 13:08:01.827393 2026] [security2:error] [pid 167459:tid 167702] [client 207.175.174.249:23644] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYWr_JutbFb-8svr1yQAAAgA"] [Tue Aug 18 13:08:01.829599 2026] [security2:error] [pid 167459:tid 167626] [client 20.151.109.219:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mz.php"] [unique_id "aoSDYWr_JutbFb-8svr1ygAAAbQ"] [Tue Aug 18 13:08:01.831410 2026] [security2:error] [pid 167459:tid 167487] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/term.php"] [unique_id "aoSDYWr_JutbFb-8svr1ywABtxs"] [Tue Aug 18 13:08:01.847243 2026] [authz_core:error] [pid 167459:tid 167539] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:01.847505 2026] [authz_core:error] [pid 167459:tid 167539] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:01.853405 2026] [security2:error] [pid 167459:tid 167660] [client 4.232.151.198:2986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ioxi-o.php"] [unique_id "aoSDYWr_JutbFb-8svr1zQAAAdY"] [Tue Aug 18 13:08:01.887707 2026] [security2:error] [pid 167459:tid 167712] [client 40.74.65.169:21332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/8.php"] [unique_id "aoSDYWr_JutbFb-8svr10AAAAgo"] [Tue Aug 18 13:08:01.894981 2026] [security2:error] [pid 167459:tid 167557] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/admin.php"] [unique_id "aoSDYWr_JutbFb-8svr10QACDGE"] [Tue Aug 18 13:08:01.973160 2026] [security2:error] [pid 167459:tid 167658] [client 20.106.102.5:45205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/vx.php"] [unique_id "aoSDYWr_JutbFb-8svr10wAAAdQ"] [Tue Aug 18 13:08:01.991228 2026] [cgid:error] [pid 167459:tid 167668] [client 132.196.30.78:20298] AH01265: stderr from /home2/anmultimarcas/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:08:02.042914 2026] [security2:error] [pid 167459:tid 167580] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/test.php"] [unique_id "aoSDYmr_JutbFb-8svr12QABlHg"] [Tue Aug 18 13:08:02.044658 2026] [security2:error] [pid 167459:tid 167554] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/worksec.php"] [unique_id "aoSDYmr_JutbFb-8svr12gABwl4"] [Tue Aug 18 13:08:02.063161 2026] [security2:error] [pid 167459:tid 167703] [client 20.163.43.14:15700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/lock360.php"] [unique_id "aoSDYmr_JutbFb-8svr13AAAAgE"] [Tue Aug 18 13:08:02.081476 2026] [security2:error] [pid 167459:tid 167710] [client 213.202.253.4:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/schallfuns.php"] [unique_id "aoSDYmr_JutbFb-8svr13QAAAgg"], referer: www.google.com [Tue Aug 18 13:08:02.083096 2026] [security2:error] [pid 167459:tid 167631] [client 172.202.39.151:27883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/lv.php"] [unique_id "aoSDYmr_JutbFb-8svr13gAAAbk"] [Tue Aug 18 13:08:02.107291 2026] [security2:error] [pid 167459:tid 167614] [client 207.175.174.249:23664] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDYmr_JutbFb-8svr13wAAAag"] [Tue Aug 18 13:08:02.111833 2026] [security2:error] [pid 167459:tid 167639] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSDYmr_JutbFb-8svr14AAAAcE"] [Tue Aug 18 13:08:02.116895 2026] [security2:error] [pid 167459:tid 167680] [client 20.226.36.136:41584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDYmr_JutbFb-8svr14QAAAeo"] [Tue Aug 18 13:08:02.134334 2026] [security2:error] [pid 167459:tid 167655] [client 132.196.30.78:20298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/x.php"] [unique_id "aoSDYmr_JutbFb-8svr14wAAAdE"] [Tue Aug 18 13:08:02.149181 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:02.149447 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:02.185512 2026] [security2:error] [pid 167459:tid 167515] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/edit.php"] [unique_id "aoSDYmr_JutbFb-8svr15QABtjc"] [Tue Aug 18 13:08:02.194816 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:17379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/flower.php"] [unique_id "aoSDYmr_JutbFb-8svr15gAAAdk"] [Tue Aug 18 13:08:02.207820 2026] [security2:error] [pid 167459:tid 167656] [client 158.158.74.177:13774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSDYmr_JutbFb-8svr15wAAAdI"] [Tue Aug 18 13:08:02.208112 2026] [security2:error] [pid 167459:tid 167620] [client 172.182.217.32:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/id3/min.php"] [unique_id "aoSDYmr_JutbFb-8svr16AAAAa4"] [Tue Aug 18 13:08:02.285521 2026] [security2:error] [pid 167459:tid 167683] [client 74.248.18.37:30760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "aoSDYmr_JutbFb-8svr17AAAAe0"] [Tue Aug 18 13:08:02.289574 2026] [security2:error] [pid 167459:tid 167463] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDYmr_JutbFb-8svr17QACCwM"] [Tue Aug 18 13:08:02.289760 2026] [security2:error] [pid 167459:tid 167713] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDYmr_JutbFb-8svr17QACCwM"] [Tue Aug 18 13:08:02.307413 2026] [security2:error] [pid 167459:tid 167602] [client 20.106.102.5:45212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ah25.php"] [unique_id "aoSDYmr_JutbFb-8svr17gAAAZw"] [Tue Aug 18 13:08:02.312172 2026] [security2:error] [pid 167459:tid 167664] [client 20.104.100.201:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/yup.php"] [unique_id "aoSDYmr_JutbFb-8svr17wAAAdo"] [Tue Aug 18 13:08:02.323251 2026] [security2:error] [pid 167459:tid 167619] [client 20.104.100.201:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/as.php"] [unique_id "aoSDYmr_JutbFb-8svr18QAAAa0"] [Tue Aug 18 13:08:02.364805 2026] [security2:error] [pid 167459:tid 167666] [client 20.116.17.175:52563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/f35.update.php"] [unique_id "aoSDYmr_JutbFb-8svr19AAAAdw"] [Tue Aug 18 13:08:02.431111 2026] [security2:error] [pid 167459:tid 167704] [client 20.79.204.6:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/system_log.php"] [unique_id "aoSDYmr_JutbFb-8svr19gAAAgI"] [Tue Aug 18 13:08:02.431542 2026] [security2:error] [pid 167459:tid 167596] [client 20.104.100.201:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/002.php"] [unique_id "aoSDYmr_JutbFb-8svr19wAAAZY"] [Tue Aug 18 13:08:02.447931 2026] [security2:error] [pid 167459:tid 167585] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/test1.php"] [unique_id "aoSDYmr_JutbFb-8svr1-QAB-H0"] [Tue Aug 18 13:08:02.449438 2026] [security2:error] [pid 167459:tid 167635] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/index.php"] [unique_id "aoSDYmr_JutbFb-8svr1-gAAAb0"] [Tue Aug 18 13:08:02.453541 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:02.453981 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:02.474474 2026] [security2:error] [pid 167459:tid 167646] [client 20.163.43.14:15624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/flower.php"] [unique_id "aoSDYmr_JutbFb-8svr1-wAAAcg"] [Tue Aug 18 13:08:02.477801 2026] [security2:error] [pid 167459:tid 167488] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDYmr_JutbFb-8svr1_AABnhw"] [Tue Aug 18 13:08:02.478356 2026] [security2:error] [pid 167459:tid 167677] [client 4.232.151.198:30085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/item.php"] [unique_id "aoSDYmr_JutbFb-8svr1_QAAAec"] [Tue Aug 18 13:08:02.482476 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDYmr_JutbFb-8svr1_gAAAcc"] [Tue Aug 18 13:08:02.501612 2026] [security2:error] [pid 167459:tid 167608] [client 207.175.174.249:23686] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYmr_JutbFb-8svr2AAAAAaI"] [Tue Aug 18 13:08:02.509569 2026] [security2:error] [pid 167459:tid 167633] [client 52.173.121.69:36592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDYmr_JutbFb-8svr2AgAAAbs"] [Tue Aug 18 13:08:02.509631 2026] [security2:error] [pid 167459:tid 167599] [client 172.202.39.151:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/new.php"] [unique_id "aoSDYmr_JutbFb-8svr2AQAAAZk"] [Tue Aug 18 13:08:02.594503 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:35405] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSDYmr_JutbFb-8svr2BQAAAgk"] [Tue Aug 18 13:08:02.594597 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:35405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1.php"] [unique_id "aoSDYmr_JutbFb-8svr2BQAAAgk"] [Tue Aug 18 13:08:02.608423 2026] [security2:error] [pid 167459:tid 167681] [client 213.35.127.232:57669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDYmr_JutbFb-8svr2BgAAAes"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:02.609997 2026] [security2:error] [pid 167459:tid 167672] [client 52.139.47.57:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/file.php"] [unique_id "aoSDYmr_JutbFb-8svr2BwAAAeI"] [Tue Aug 18 13:08:02.620712 2026] [http2:warn] [pid 139043:tid 139191] [client 201.32.74.208:57070] h2_stream(139043-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:08:02.631439 2026] [security2:error] [pid 167459:tid 167548] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/thoms.php"] [unique_id "aoSDYmr_JutbFb-8svr2CAABtFg"] [Tue Aug 18 13:08:02.631649 2026] [security2:error] [pid 167459:tid 167691] [client 20.106.102.5:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/tt.php"] [unique_id "aoSDYmr_JutbFb-8svr2CQAAAfU"] [Tue Aug 18 13:08:02.647059 2026] [security2:error] [pid 167459:tid 167461] [remote 47.128.51.47:51844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "geracaoenergia.eng.br"] [uri "/geradores-para-casamento/"] [unique_id "aoSDYmr_JutbFb-8svr2CgABsQE"] [Tue Aug 18 13:08:02.652811 2026] [http2:warn] [pid 157386:tid 157608] [client 201.32.74.208:57204] h2_stream(157386-520-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:08:02.666301 2026] [security2:error] [pid 167459:tid 167684] [client 132.196.30.78:13095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/index/function.php"] [unique_id "aoSDYmr_JutbFb-8svr2CwAAAe4"] [Tue Aug 18 13:08:02.677014 2026] [security2:error] [pid 167459:tid 167541] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-access.php"] [unique_id "aoSDYmr_JutbFb-8svr2DAABlVE"] [Tue Aug 18 13:08:02.691611 2026] [security2:error] [pid 167459:tid 167610] [client 20.250.13.23:28032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/96i.php"] [unique_id "aoSDYmr_JutbFb-8svr2DgAAAaQ"] [Tue Aug 18 13:08:02.713815 2026] [autoindex:error] [pid 167459:tid 167641] [client 172.182.217.32:4078] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:02.731879 2026] [security2:error] [pid 167459:tid 167712] [client 207.175.174.249:23720] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDYmr_JutbFb-8svr2EAAAAgo"] [Tue Aug 18 13:08:02.752588 2026] [authz_core:error] [pid 167459:tid 167517] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:02.752891 2026] [authz_core:error] [pid 167459:tid 167517] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:02.768897 2026] [security2:error] [pid 167459:tid 167513] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/inputs.php"] [unique_id "aoSDYmr_JutbFb-8svr2EwAB0DU"] [Tue Aug 18 13:08:02.770147 2026] [security2:error] [pid 167459:tid 167661] [client 4.232.151.198:48582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDYmr_JutbFb-8svr2FAAAAdc"] [Tue Aug 18 13:08:02.785106 2026] [security2:error] [pid 167459:tid 167601] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/as.php"] [unique_id "aoSDYmr_JutbFb-8svr2FQAAAZs"] [Tue Aug 18 13:08:02.804530 2026] [security2:error] [pid 167459:tid 167690] [client 20.163.43.14:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/13.php"] [unique_id "aoSDYmr_JutbFb-8svr2FgAAAfQ"] [Tue Aug 18 13:08:02.808772 2026] [security2:error] [pid 167459:tid 167667] [client 207.175.174.249:23722] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/fetch"] [unique_id "aoSDYmr_JutbFb-8svr2FwAAAd0"] [Tue Aug 18 13:08:02.812199 2026] [security2:error] [pid 167459:tid 167561] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/tool.php"] [unique_id "aoSDYmr_JutbFb-8svr2GAABumU"] [Tue Aug 18 13:08:02.827353 2026] [security2:error] [pid 167459:tid 167698] [client 158.158.74.177:13819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-configs.php"] [unique_id "aoSDYmr_JutbFb-8svr2GQAAAfw"] [Tue Aug 18 13:08:02.830137 2026] [security2:error] [pid 167459:tid 167658] [client 104.209.144.33:31248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDYmr_JutbFb-8svr2GgAAAdQ"] [Tue Aug 18 13:08:02.837118 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:27861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/222.php"] [unique_id "aoSDYmr_JutbFb-8svr2GwAAAbw"] [Tue Aug 18 13:08:02.855544 2026] [security2:error] [pid 167459:tid 167589] [client 85.208.96.210:25906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bergoninf.com"] [uri "/"] [unique_id "aoSDYmr_JutbFb-8svr2HAAAAY8"] [Tue Aug 18 13:08:02.855619 2026] [security2:error] [pid 167459:tid 167589] [client 85.208.96.210:25906] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bergoninf.com"] [uri "/"] [unique_id "aoSDYmr_JutbFb-8svr2HAAAAY8"] [Tue Aug 18 13:08:02.877248 2026] [security2:error] [pid 167459:tid 167716] [client 172.182.217.32:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDYmr_JutbFb-8svr2HwAAAg4"] [Tue Aug 18 13:08:02.891542 2026] [security2:error] [pid 167459:tid 167649] [client 20.226.36.136:25148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDYmr_JutbFb-8svr2IAAAAcs"] [Tue Aug 18 13:08:02.949644 2026] [security2:error] [pid 167459:tid 167655] [client 207.175.174.249:23732] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/proxy"] [unique_id "aoSDYmr_JutbFb-8svr2IgAAAdE"] [Tue Aug 18 13:08:02.954511 2026] [security2:error] [pid 167459:tid 167605] [client 20.127.136.245:14724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/file2.php"] [unique_id "aoSDYmr_JutbFb-8svr2IwAAAZ8"] [Tue Aug 18 13:08:02.955395 2026] [security2:error] [pid 167459:tid 167628] [client 20.106.102.5:45222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xqq.php"] [unique_id "aoSDYmr_JutbFb-8svr2JAAAAbY"] [Tue Aug 18 13:08:02.962218 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:30756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/maint/ajax-actions.php"] [unique_id "aoSDYmr_JutbFb-8svr2JQAAAfY"] [Tue Aug 18 13:08:02.993973 2026] [autoindex:error] [pid 167459:tid 167674] [client 20.91.215.254:22835] AH01276: Cannot serve directory /home3/cp37imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:02.998894 2026] [security2:error] [pid 167459:tid 167559] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin.php"] [unique_id "aoSDYmr_JutbFb-8svr2JwACBmM"] [Tue Aug 18 13:08:03.001228 2026] [security2:error] [pid 167459:tid 167526] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/tools.php"] [unique_id "aoSDY2r_JutbFb-8svr2KAABkUI"] [Tue Aug 18 13:08:03.024643 2026] [security2:error] [pid 167459:tid 167703] [client 52.139.47.57:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/goods.php"] [unique_id "aoSDY2r_JutbFb-8svr2KQAAAgE"] [Tue Aug 18 13:08:03.042998 2026] [security2:error] [pid 167459:tid 167659] [client 149.34.210.141:51686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDY2r_JutbFb-8svr2KwAAAdU"] [Tue Aug 18 13:08:03.052604 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:03.052879 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:03.068117 2026] [security2:error] [pid 167459:tid 167514] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/av.php"] [unique_id "aoSDY2r_JutbFb-8svr2LQAB2zY"] [Tue Aug 18 13:08:03.084946 2026] [security2:error] [pid 167459:tid 167652] [client 20.79.204.6:5714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/t.php"] [unique_id "aoSDY2r_JutbFb-8svr2LgAAAc4"] [Tue Aug 18 13:08:03.117061 2026] [security2:error] [pid 167459:tid 167602] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDY2r_JutbFb-8svr2MAAAAZw"] [Tue Aug 18 13:08:03.122376 2026] [security2:error] [pid 167459:tid 167689] [client 4.232.151.198:48499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/js.php"] [unique_id "aoSDY2r_JutbFb-8svr2MQAAAfM"] [Tue Aug 18 13:08:03.143503 2026] [security2:error] [pid 167459:tid 167619] [client 20.163.43.14:15652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/cc.php"] [unique_id "aoSDY2r_JutbFb-8svr2MwAAAa0"] [Tue Aug 18 13:08:03.151929 2026] [security2:error] [pid 167459:tid 167687] [client 20.104.100.201:53267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/pucci.php"] [unique_id "aoSDY2r_JutbFb-8svr2NAAAAfE"] [Tue Aug 18 13:08:03.154881 2026] [security2:error] [pid 167459:tid 167609] [client 207.175.174.249:24048] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.production.bak"] [unique_id "aoSDY2r_JutbFb-8svr2NgAAAaM"] [Tue Aug 18 13:08:03.156352 2026] [security2:error] [pid 167459:tid 167670] [client 207.175.174.249:23932] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.github/workflows/main.yml"] [unique_id "aoSDY2r_JutbFb-8svr2OgAAAeA"] [Tue Aug 18 13:08:03.157018 2026] [security2:error] [pid 167459:tid 167704] [client 207.175.174.249:24086] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/var/www/html/.env"] [unique_id "aoSDY2r_JutbFb-8svr2OwAAAgI"] [Tue Aug 18 13:08:03.163911 2026] [proxy_http:error] [pid 167459:tid 167676] (20014)Internal error (specific information not available): [client 207.175.174.249:23988] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.163930 2026] [proxy:error] [pid 167459:tid 167676] [client 207.175.174.249:23988] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/jenkins.xml [Tue Aug 18 13:08:03.169407 2026] [security2:error] [pid 167459:tid 167694] [client 172.202.39.151:27868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/chosen.php"] [unique_id "aoSDY2r_JutbFb-8svr2PAAAAfg"] [Tue Aug 18 13:08:03.169645 2026] [proxy_http:error] [pid 167459:tid 167666] (20014)Internal error (specific information not available): [client 207.175.174.249:24012] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.169652 2026] [proxy:error] [pid 167459:tid 167666] [client 207.175.174.249:24012] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.example [Tue Aug 18 13:08:03.173921 2026] [security2:error] [pid 167459:tid 167604] [client 207.175.174.249:23812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/jenkins/config.xml.bak"] [unique_id "aoSDY2r_JutbFb-8svr2QQAAAZ4"] [Tue Aug 18 13:08:03.174146 2026] [security2:error] [pid 167459:tid 167697] [client 207.175.174.249:23822] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.jenkins/config.xml"] [unique_id "aoSDY2r_JutbFb-8svr2RQAAAfs"] [Tue Aug 18 13:08:03.175082 2026] [security2:error] [pid 167459:tid 167624] [client 207.175.174.249:23748] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/home/circleci/.aws/credentials"] [unique_id "aoSDY2r_JutbFb-8svr2SgAAAbI"] [Tue Aug 18 13:08:03.175533 2026] [security2:error] [pid 167459:tid 167645] [client 207.175.174.249:24060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env.prod.bak"] [unique_id "aoSDY2r_JutbFb-8svr2QwAAAcc"] [Tue Aug 18 13:08:03.176899 2026] [security2:error] [pid 167459:tid 167711] [client 207.175.174.249:23832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/job/.env"] [unique_id "aoSDY2r_JutbFb-8svr2TwAAAgk"] [Tue Aug 18 13:08:03.176910 2026] [security2:error] [pid 167459:tid 167608] [client 207.175.174.249:23762] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/Jenkinsfile"] [unique_id "aoSDY2r_JutbFb-8svr2UgAAAaI"] [Tue Aug 18 13:08:03.178090 2026] [security2:error] [pid 167459:tid 167599] [client 207.175.174.249:24120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.174.175.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.php"] [unique_id "aoSDY2r_JutbFb-8svr2SAAAAZk"] [Tue Aug 18 13:08:03.178315 2026] [security2:error] [pid 167459:tid 167691] [client 207.175.174.249:23792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/jenkins/.env"] [unique_id "aoSDY2r_JutbFb-8svr2VQAAAfU"] [Tue Aug 18 13:08:03.178467 2026] [security2:error] [pid 167459:tid 167623] [client 207.175.174.249:23968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.github/workflows/docker.yml"] [unique_id "aoSDY2r_JutbFb-8svr2WQAAAbE"] [Tue Aug 18 13:08:03.182461 2026] [security2:error] [pid 167459:tid 167593] [client 20.151.109.219:38612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ft.php"] [unique_id "aoSDY2r_JutbFb-8svr2WgAAAZM"] [Tue Aug 18 13:08:03.185519 2026] [proxy_http:error] [pid 167459:tid 167677] (20014)Internal error (specific information not available): [client 207.175.174.249:24108] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.185533 2026] [proxy:error] [pid 167459:tid 167677] [client 207.175.174.249:24108] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.anthropic [Tue Aug 18 13:08:03.191273 2026] [proxy_http:error] [pid 167459:tid 167625] (20014)Internal error (specific information not available): [client 207.175.174.249:23854] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.191295 2026] [proxy:error] [pid 167459:tid 167625] [client 207.175.174.249:23854] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.github [Tue Aug 18 13:08:03.196946 2026] [proxy_http:error] [pid 167459:tid 167633] (20014)Internal error (specific information not available): [client 207.175.174.249:23786] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.196964 2026] [proxy:error] [pid 167459:tid 167633] [client 207.175.174.249:23786] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/jenkins/credentials.xml [Tue Aug 18 13:08:03.201994 2026] [proxy_http:error] [pid 167459:tid 167695] (20014)Internal error (specific information not available): [client 207.175.174.249:23996] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.202010 2026] [proxy:error] [pid 167459:tid 167695] [client 207.175.174.249:23996] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/jenkins.conf [Tue Aug 18 13:08:03.202205 2026] [security2:error] [pid 167459:tid 167556] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/txets.php"] [unique_id "aoSDY2r_JutbFb-8svr2XAAB7mA"] [Tue Aug 18 13:08:03.206417 2026] [security2:error] [pid 167459:tid 167610] [client 207.175.174.249:24152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.yml"] [unique_id "aoSDY2r_JutbFb-8svr2XgAAAaQ"] [Tue Aug 18 13:08:03.209100 2026] [proxy_http:error] [pid 167459:tid 167590] (20014)Internal error (specific information not available): [client 207.175.174.249:23960] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.209113 2026] [proxy:error] [pid 167459:tid 167590] [client 207.175.174.249:23960] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.github/workflows/test.yml [Tue Aug 18 13:08:03.215883 2026] [proxy_http:error] [pid 167459:tid 167617] (20014)Internal error (specific information not available): [client 207.175.174.249:23858] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.215895 2026] [proxy:error] [pid 167459:tid 167617] [client 207.175.174.249:23858] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.vercel/.env.production.local [Tue Aug 18 13:08:03.222206 2026] [proxy_http:error] [pid 167459:tid 167672] (20014)Internal error (specific information not available): [client 207.175.174.249:23776] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.222222 2026] [proxy:error] [pid 167459:tid 167672] [client 207.175.174.249:23776] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/azure-pipelines.yml [Tue Aug 18 13:08:03.228375 2026] [proxy_http:error] [pid 167459:tid 167660] (20014)Internal error (specific information not available): [client 207.175.174.249:23986] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.228390 2026] [proxy:error] [pid 167459:tid 167660] [client 207.175.174.249:23986] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.github/secrets.env [Tue Aug 18 13:08:03.235068 2026] [proxy_http:error] [pid 167459:tid 167678] (20014)Internal error (specific information not available): [client 207.175.174.249:23916] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.235089 2026] [proxy:error] [pid 167459:tid 167678] [client 207.175.174.249:23916] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cloudbuild.yaml [Tue Aug 18 13:08:03.257741 2026] [security2:error] [pid 167459:tid 167654] [client 207.175.174.249:24076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "aoSDY2r_JutbFb-8svr2YgAAAdA"] [Tue Aug 18 13:08:03.267811 2026] [proxy_http:error] [pid 167459:tid 167688] (20014)Internal error (specific information not available): [client 207.175.174.249:23908] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.267827 2026] [proxy:error] [pid 167459:tid 167688] [client 207.175.174.249:23908] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.drone.yml [Tue Aug 18 13:08:03.274497 2026] [proxy_http:error] [pid 167459:tid 167688] (20014)Internal error (specific information not available): [client 207.175.174.249:23908] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.274513 2026] [proxy:error] [pid 167459:tid 167688] [client 207.175.174.249:23908] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml [Tue Aug 18 13:08:03.282831 2026] [security2:error] [pid 167459:tid 167669] [client 20.106.102.5:45311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/06.php"] [unique_id "aoSDY2r_JutbFb-8svr2ZwAAAd8"] [Tue Aug 18 13:08:03.302775 2026] [security2:error] [pid 167459:tid 167671] [client 132.196.30.78:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/aaa.php"] [unique_id "aoSDY2r_JutbFb-8svr2aAAAAeE"] [Tue Aug 18 13:08:03.308595 2026] [security2:error] [pid 167459:tid 167659] [client 149.34.210.141:51686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDY2r_JutbFb-8svr2KwAAAdU"] [Tue Aug 18 13:08:03.362595 2026] [security2:error] [pid 167459:tid 167525] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDY2r_JutbFb-8svr2bAABy0E"] [Tue Aug 18 13:08:03.368452 2026] [security2:error] [pid 167459:tid 167595] [client 172.182.217.32:4155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/ixr/min.php"] [unique_id "aoSDY2r_JutbFb-8svr2bQAAAZU"] [Tue Aug 18 13:08:03.383265 2026] [security2:error] [pid 167459:tid 167639] [client 40.74.65.169:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/about.php"] [unique_id "aoSDY2r_JutbFb-8svr2bwAAAcE"] [Tue Aug 18 13:08:03.398308 2026] [security2:error] [pid 167459:tid 167543] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/u.php"] [unique_id "aoSDY2r_JutbFb-8svr2cAABzFM"] [Tue Aug 18 13:08:03.424050 2026] [security2:error] [pid 167459:tid 167680] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-config-sample.php"] [unique_id "aoSDY2r_JutbFb-8svr2cwAAAeo"] [Tue Aug 18 13:08:03.457080 2026] [security2:error] [pid 167459:tid 167714] [client 158.158.74.177:13763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-post.php"] [unique_id "aoSDY2r_JutbFb-8svr2dgAAAgw"] [Tue Aug 18 13:08:03.469750 2026] [security2:error] [pid 167459:tid 167712] [client 52.139.47.57:17053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/g.php"] [unique_id "aoSDY2r_JutbFb-8svr2dwAAAgo"] [Tue Aug 18 13:08:03.477545 2026] [security2:error] [pid 167459:tid 167663] [client 20.116.17.175:44682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/bdroot.php"] [unique_id "aoSDY2r_JutbFb-8svr2eAAAAdk"] [Tue Aug 18 13:08:03.495237 2026] [security2:error] [pid 167459:tid 167656] [client 20.163.43.14:15698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDY2r_JutbFb-8svr2eQAAAdI"] [Tue Aug 18 13:08:03.553389 2026] [security2:error] [pid 167459:tid 167708] [client 20.226.36.136:2868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDY2r_JutbFb-8svr2ewAAAgY"] [Tue Aug 18 13:08:03.578111 2026] [security2:error] [pid 167459:tid 167479] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/ultra.php"] [unique_id "aoSDY2r_JutbFb-8svr2fQABrBM"] [Tue Aug 18 13:08:03.609688 2026] [security2:error] [pid 167459:tid 167638] [client 20.106.102.5:45211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/166.php"] [unique_id "aoSDY2r_JutbFb-8svr2gQAAAcA"] [Tue Aug 18 13:08:03.626961 2026] [security2:error] [pid 167459:tid 167698] [client 213.35.127.232:57929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDY2r_JutbFb-8svr2ggAAAfw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:03.630977 2026] [security2:error] [pid 167459:tid 167516] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/advanced1.php"] [unique_id "aoSDY2r_JutbFb-8svr2hAABozg"] [Tue Aug 18 13:08:03.636038 2026] [security2:error] [pid 167459:tid 167704] [client 207.175.174.249:24028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.supabase/.env"] [unique_id "aoSDY2r_JutbFb-8svr2hgAAAgI"] [Tue Aug 18 13:08:03.637301 2026] [security2:error] [pid 167459:tid 167596] [client 207.175.174.249:23888] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/supabase/.env"] [unique_id "aoSDY2r_JutbFb-8svr2hwAAAZY"] [Tue Aug 18 13:08:03.653178 2026] [security2:error] [pid 167459:tid 167550] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDY2r_JutbFb-8svr2igABpVo"] [Tue Aug 18 13:08:03.655224 2026] [security2:error] [pid 167459:tid 167694] [client 20.104.100.201:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/zxz.php"] [unique_id "aoSDY2r_JutbFb-8svr2iwAAAfg"] [Tue Aug 18 13:08:03.668825 2026] [core:error] [pid 167459:tid 167645] [client 207.175.174.249:24002] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 13:08:03.672433 2026] [proxy_http:error] [pid 167459:tid 167645] (20014)Internal error (specific information not available): [client 207.175.174.249:24002] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.698070 2026] [core:error] [pid 167459:tid 167599] [client 207.175.174.249:23846] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../.env) [Tue Aug 18 13:08:03.699869 2026] [core:error] [pid 167459:tid 167691] [client 207.175.174.249:23902] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:08:03.706466 2026] [proxy_http:error] [pid 167459:tid 167691] (20014)Internal error (specific information not available): [client 207.175.174.249:23902] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.719682 2026] [security2:error] [pid 167459:tid 167635] [client 20.104.100.201:53314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wicked.php"] [unique_id "aoSDY2r_JutbFb-8svr2kgAAAb0"] [Tue Aug 18 13:08:03.720388 2026] [core:error] [pid 167459:tid 167593] [client 207.175.174.249:24102] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:08:03.720907 2026] [security2:error] [pid 167459:tid 167613] [client 207.175.174.249:23916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.174.175.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.vindimo.com.br"] [uri "/.env.local.php"] [unique_id "aoSDY2r_JutbFb-8svr2lAAAAac"] [Tue Aug 18 13:08:03.721413 2026] [security2:error] [pid 167459:tid 167657] [client 207.175.174.249:23986] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/..%252F..%252F..%252F..%252F..%252Fproc/self/environ"] [unique_id "aoSDY2r_JutbFb-8svr2lQAAAdM"] [Tue Aug 18 13:08:03.721633 2026] [security2:error] [pid 167459:tid 167696] [client 207.175.174.249:23858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/static/..;/.env"] [unique_id "aoSDY2r_JutbFb-8svr2lwAAAfo"] [Tue Aug 18 13:08:03.721678 2026] [security2:error] [pid 167459:tid 167715] [client 207.175.174.249:23776] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/..;/.env"] [unique_id "aoSDY2r_JutbFb-8svr2mAAAAg0"] [Tue Aug 18 13:08:03.721820 2026] [security2:error] [pid 167459:tid 167646] [client 207.175.174.249:24076] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSDY2r_JutbFb-8svr2lgAAAcg"] [Tue Aug 18 13:08:03.722589 2026] [security2:error] [pid 167459:tid 167607] [client 20.79.204.6:5984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/templates.php"] [unique_id "aoSDY2r_JutbFb-8svr2mgAAAaE"] [Tue Aug 18 13:08:03.722604 2026] [security2:error] [pid 167459:tid 167684] [client 207.175.174.249:24136] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/debug.log"] [unique_id "aoSDY2r_JutbFb-8svr2mwAAAe4"] [Tue Aug 18 13:08:03.723944 2026] [security2:error] [pid 167459:tid 167620] [client 74.248.18.37:30763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-lock.php"] [unique_id "aoSDY2r_JutbFb-8svr2nAAAAa4"] [Tue Aug 18 13:08:03.729044 2026] [proxy_http:error] [pid 167459:tid 167646] (20014)Internal error (specific information not available): [client 207.175.174.249:24076] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.729476 2026] [security2:error] [pid 167459:tid 167630] [client 207.175.174.249:23880] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ"] [unique_id "aoSDY2r_JutbFb-8svr2nQAAAbg"] [Tue Aug 18 13:08:03.731123 2026] [security2:error] [pid 167459:tid 167610] [client 207.175.174.249:24108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/..%2F..%2F..%2F..%2F..%2F.env"] [unique_id "aoSDY2r_JutbFb-8svr2ngAAAaQ"] [Tue Aug 18 13:08:03.731490 2026] [security2:error] [pid 167459:tid 167681] [client 207.175.174.249:23908] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/api/env"] [unique_id "aoSDY2r_JutbFb-8svr2oAAAAes"] [Tue Aug 18 13:08:03.734984 2026] [security2:error] [pid 167459:tid 167677] [client 207.175.174.249:23792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "aoSDY2r_JutbFb-8svr2owAAAec"] [Tue Aug 18 13:08:03.736178 2026] [security2:error] [pid 167459:tid 167695] [client 207.175.174.249:23832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "aoSDY2r_JutbFb-8svr2pgAAAfk"] [Tue Aug 18 13:08:03.736212 2026] [security2:error] [pid 167459:tid 167633] [client 207.175.174.249:23988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.netlify/.env"] [unique_id "aoSDY2r_JutbFb-8svr2pQAAAbs"] [Tue Aug 18 13:08:03.736811 2026] [proxy_http:error] [pid 167459:tid 167705] (20014)Internal error (specific information not available): [client 207.175.174.249:23976] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.743628 2026] [proxy_http:error] [pid 167459:tid 167625] (20014)Internal error (specific information not available): [client 207.175.174.249:24012] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.752100 2026] [security2:error] [pid 167459:tid 167674] [client 4.232.151.198:30087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/k.php"] [unique_id "aoSDY2r_JutbFb-8svr2pwAAAeQ"] [Tue Aug 18 13:08:03.752561 2026] [security2:error] [pid 167459:tid 167654] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDY2r_JutbFb-8svr2qAAAAdA"] [Tue Aug 18 13:08:03.759625 2026] [security2:error] [pid 167459:tid 167466] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/un.php"] [unique_id "aoSDY2r_JutbFb-8svr2qQAB4gY"] [Tue Aug 18 13:08:03.794579 2026] [security2:error] [pid 167459:tid 167693] [client 20.151.109.219:46584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/h.php"] [unique_id "aoSDY2r_JutbFb-8svr2rAAAAfc"] [Tue Aug 18 13:08:03.831371 2026] [security2:error] [pid 167459:tid 167634] [client 20.163.43.14:15713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSDY2r_JutbFb-8svr2rwAAAbw"] [Tue Aug 18 13:08:03.834473 2026] [security2:error] [pid 167459:tid 167671] [client 207.175.174.249:23786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "aoSDY2r_JutbFb-8svr2sQAAAeE"] [Tue Aug 18 13:08:03.838306 2026] [proxy_http:error] [pid 167459:tid 167621] (20014)Internal error (specific information not available): [client 207.175.174.249:23854] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:03.850924 2026] [security2:error] [pid 167459:tid 167649] [client 207.175.174.249:24060] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/internal/.env"] [unique_id "aoSDY2r_JutbFb-8svr2swAAAcs"] [Tue Aug 18 13:08:03.856869 2026] [security2:error] [pid 167459:tid 167608] [client 172.182.217.32:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/ixr/wp-login.php"] [unique_id "aoSDY2r_JutbFb-8svr2tAAAAaI"] [Tue Aug 18 13:08:03.860841 2026] [security2:error] [pid 167459:tid 167710] [client 207.175.174.249:23812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "aoSDY2r_JutbFb-8svr2tQAAAgg"] [Tue Aug 18 13:08:03.881254 2026] [security2:error] [pid 167459:tid 167617] [client 52.139.47.57:25756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDY2r_JutbFb-8svr2twAAAas"] [Tue Aug 18 13:08:03.897883 2026] [security2:error] [pid 167459:tid 167641] [client 172.202.39.151:27890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/info.php"] [unique_id "aoSDY2r_JutbFb-8svr2uAAAAcM"] [Tue Aug 18 13:08:03.903689 2026] [security2:error] [pid 167459:tid 167628] [client 207.175.174.249:23808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "aoSDY2r_JutbFb-8svr2uQAAAbY"] [Tue Aug 18 13:08:03.908396 2026] [security2:error] [pid 167459:tid 167714] [client 52.173.121.69:28318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDY2r_JutbFb-8svr2uwAAAgw"] [Tue Aug 18 13:08:03.920986 2026] [security2:error] [pid 167459:tid 167676] [client 132.196.30.78:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/abcd.php"] [unique_id "aoSDY2r_JutbFb-8svr2vAAAAeY"] [Tue Aug 18 13:08:03.932664 2026] [security2:error] [pid 167459:tid 167616] [client 207.175.174.249:23742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "aoSDY2r_JutbFb-8svr2vQAAAao"] [Tue Aug 18 13:08:03.933460 2026] [security2:error] [pid 167459:tid 167606] [client 20.106.102.5:45287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/snq.php"] [unique_id "aoSDY2r_JutbFb-8svr2wAAAAaA"] [Tue Aug 18 13:08:03.939925 2026] [security2:error] [pid 167459:tid 167535] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/up.php"] [unique_id "aoSDY2r_JutbFb-8svr2wQACAUs"] [Tue Aug 18 13:08:03.942995 2026] [security2:error] [pid 167459:tid 167508] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/class-wp-http-client.php"] [unique_id "aoSDY2r_JutbFb-8svr2wgABzzA"] [Tue Aug 18 13:08:03.943012 2026] [security2:error] [pid 167459:tid 167522] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDY2r_JutbFb-8svr2wwAB7z4"] [Tue Aug 18 13:08:03.956464 2026] [security2:error] [pid 167459:tid 167602] [client 207.175.174.249:23874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "aoSDY2r_JutbFb-8svr2xQAAAZw"] [Tue Aug 18 13:08:03.981641 2026] [security2:error] [pid 167459:tid 167704] [client 207.175.174.249:23738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "aoSDY2r_JutbFb-8svr2xwAAAgI"] [Tue Aug 18 13:08:03.990536 2026] [security2:error] [pid 167459:tid 167596] [client 207.175.174.249:23948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "aoSDY2r_JutbFb-8svr2yAAAAZY"] [Tue Aug 18 13:08:04.004251 2026] [security2:error] [pid 167459:tid 167592] [client 207.175.174.249:23782] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/production/.env"] [unique_id "aoSDZGr_JutbFb-8svr2ywAAAZI"] [Tue Aug 18 13:08:04.006315 2026] [security2:error] [pid 167459:tid 167673] [client 157.20.138.62:55639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZGr_JutbFb-8svr2zAAAAeM"] [Tue Aug 18 13:08:04.006444 2026] [security2:error] [pid 167459:tid 167673] [client 157.20.138.62:55639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZGr_JutbFb-8svr2zAAAAeM"] [Tue Aug 18 13:08:04.011611 2026] [security2:error] [pid 167459:tid 167604] [client 207.175.174.249:23988] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/application.env"] [unique_id "aoSDZGr_JutbFb-8svr2zQAAAZ4"] [Tue Aug 18 13:08:04.012855 2026] [security2:error] [pid 167459:tid 167648] [client 207.175.174.249:23792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/app/api/.env"] [unique_id "aoSDZGr_JutbFb-8svr2zgAAAco"] [Tue Aug 18 13:08:04.013398 2026] [security2:error] [pid 167459:tid 167697] [client 207.175.174.249:23832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/backend/api/.env"] [unique_id "aoSDZGr_JutbFb-8svr2zwAAAfs"] [Tue Aug 18 13:08:04.048886 2026] [core:error] [pid 167459:tid 167666] [client 207.175.174.249:24032] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.env) [Tue Aug 18 13:08:04.077405 2026] [security2:error] [pid 167459:tid 167680] [client 158.158.74.177:13768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSDZGr_JutbFb-8svr20wAAAeo"] [Tue Aug 18 13:08:04.084581 2026] [security2:error] [pid 167459:tid 167620] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDZGr_JutbFb-8svr21gAAAa4"] [Tue Aug 18 13:08:04.085292 2026] [security2:error] [pid 167459:tid 167620] [client 207.175.174.249:23786] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.vindimo.com.br"] [uri "/public/plugins/alertlist/../../../../../../../../proc/self/environ"] [unique_id "aoSDZGr_JutbFb-8svr21wAAAa4"] [Tue Aug 18 13:08:04.086858 2026] [proxy_http:error] [pid 167459:tid 167715] (20014)Internal error (specific information not available): [client 207.175.174.249:24028] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:04.123058 2026] [security2:error] [pid 167459:tid 167610] [client 40.74.65.169:7076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin.php"] [unique_id "aoSDZGr_JutbFb-8svr22wAAAaQ"] [Tue Aug 18 13:08:04.123091 2026] [security2:error] [pid 167459:tid 167614] [client 20.104.100.201:17366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/222.php"] [unique_id "aoSDZGr_JutbFb-8svr22gAAAag"] [Tue Aug 18 13:08:04.126792 2026] [security2:error] [pid 167459:tid 167709] [client 144.76.22.172:48588] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSDY2r_JutbFb-8svr2dAAAAgc"] [Tue Aug 18 13:08:04.141789 2026] [security2:error] [pid 167459:tid 167677] [client 207.175.174.249:23808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "aoSDZGr_JutbFb-8svr23gAAAec"] [Tue Aug 18 13:08:04.145353 2026] [security2:error] [pid 167459:tid 167512] [remote 72.167.40.62:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maxhost.com.br"] [uri "/wp-login.php"] [unique_id "aoSDZGr_JutbFb-8svr23wACCTQ"] [Tue Aug 18 13:08:04.182925 2026] [security2:error] [pid 167459:tid 167594] [client 20.163.43.14:15617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/01.php"] [unique_id "aoSDZGr_JutbFb-8svr24gAAAZQ"] [Tue Aug 18 13:08:04.200509 2026] [proxy_http:error] [pid 167459:tid 167629] (20014)Internal error (specific information not available): [client 207.175.174.249:23742] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:04.204049 2026] [security2:error] [pid 167459:tid 167672] [client 20.151.109.219:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/40.php"] [unique_id "aoSDZGr_JutbFb-8svr25AAAAeI"] [Tue Aug 18 13:08:04.213263 2026] [security2:error] [pid 167459:tid 167678] [client 20.104.100.201:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/water.php"] [unique_id "aoSDZGr_JutbFb-8svr25QAAAeg"] [Tue Aug 18 13:08:04.232594 2026] [security2:error] [pid 167459:tid 167531] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/js/jquery/"] [unique_id "aoSDZGr_JutbFb-8svr26QABukc"] [Tue Aug 18 13:08:04.241455 2026] [security2:error] [pid 167459:tid 167669] [client 207.175.174.249:23960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/services/.env"] [unique_id "aoSDZGr_JutbFb-8svr26gAAAd8"] [Tue Aug 18 13:08:04.254868 2026] [proxy_http:error] [pid 167459:tid 167659] (20014)Internal error (specific information not available): [client 207.175.174.249:23832] AH01102: error reading status line from remote server 127.0.0.1:2082 [Tue Aug 18 13:08:04.256001 2026] [security2:error] [pid 167459:tid 167577] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDZGr_JutbFb-8svr27gACDnU"] [Tue Aug 18 13:08:04.259499 2026] [security2:error] [pid 167459:tid 167595] [client 20.106.102.5:45187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-access.php"] [unique_id "aoSDZGr_JutbFb-8svr28AAAAZU"] [Tue Aug 18 13:08:04.268314 2026] [security2:error] [pid 167459:tid 167649] [client 207.175.174.249:24108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.174.175.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.vindimo.com.br"] [uri "/phpinfo.php"] [unique_id "aoSDZGr_JutbFb-8svr28gAAAcs"] [Tue Aug 18 13:08:04.292318 2026] [security2:error] [pid 167459:tid 167695] [client 52.139.47.57:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDZGr_JutbFb-8svr28wAAAfk"] [Tue Aug 18 13:08:04.313442 2026] [security2:error] [pid 167459:tid 167545] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/users.php"] [unique_id "aoSDZGr_JutbFb-8svr29QABzFU"] [Tue Aug 18 13:08:04.316782 2026] [security2:error] [pid 167459:tid 167667] [client 207.175.174.249:23996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/ci/.env"] [unique_id "aoSDZGr_JutbFb-8svr29wAAAd0"] [Tue Aug 18 13:08:04.360678 2026] [security2:error] [pid 167459:tid 167605] [client 20.116.17.175:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-temp.php"] [unique_id "aoSDZGr_JutbFb-8svr2-QAAAZ8"] [Tue Aug 18 13:08:04.360806 2026] [autoindex:error] [pid 167459:tid 167590] [client 172.182.217.32:4063] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:04.362350 2026] [security2:error] [pid 167459:tid 167633] [client 20.79.204.6:5989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/term.php"] [unique_id "aoSDZGr_JutbFb-8svr2-gAAAbs"] [Tue Aug 18 13:08:04.372951 2026] [security2:error] [pid 167459:tid 167712] [client 207.175.174.249:23808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/old/.env"] [unique_id "aoSDZGr_JutbFb-8svr2_AAAAgo"] [Tue Aug 18 13:08:04.403588 2026] [security2:error] [pid 167459:tid 167618] [client 207.175.174.249:23812] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/conf/.env"] [unique_id "aoSDZGr_JutbFb-8svr2_gAAAaw"] [Tue Aug 18 13:08:04.453128 2026] [security2:error] [pid 167459:tid 167654] [client 74.248.18.37:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/qw.php"] [unique_id "aoSDZGr_JutbFb-8svr3AwAAAdA"] [Tue Aug 18 13:08:04.459108 2026] [security2:error] [pid 167459:tid 167619] [client 207.175.174.249:23738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "aoSDZGr_JutbFb-8svr3BgAAAa0"] [Tue Aug 18 13:08:04.463025 2026] [security2:error] [pid 167459:tid 167589] [client 20.250.13.23:38613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/as.php"] [unique_id "aoSDZGr_JutbFb-8svr3BwAAAY8"] [Tue Aug 18 13:08:04.473904 2026] [security2:error] [pid 167459:tid 167626] [client 4.232.151.198:2967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/media/index.php"] [unique_id "aoSDZGr_JutbFb-8svr3CAAAAbQ"] [Tue Aug 18 13:08:04.478625 2026] [security2:error] [pid 167459:tid 167670] [client 207.175.174.249:23874] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/crm/.env"] [unique_id "aoSDZGr_JutbFb-8svr3CQAAAeA"] [Tue Aug 18 13:08:04.494360 2026] [security2:error] [pid 167459:tid 167460] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/v.php"] [unique_id "aoSDZGr_JutbFb-8svr3CgABpQA"] [Tue Aug 18 13:08:04.497646 2026] [security2:error] [pid 167459:tid 167713] [client 207.175.174.249:23792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.vindimo.com.br"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "aoSDZGr_JutbFb-8svr3CwAAAgs"] [Tue Aug 18 13:08:04.502357 2026] [security2:error] [pid 167459:tid 167692] [client 178.153.171.161:28323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZGr_JutbFb-8svr3DQAAAfY"] [Tue Aug 18 13:08:04.502479 2026] [security2:error] [pid 167459:tid 167692] [client 178.153.171.161:28323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZGr_JutbFb-8svr3DQAAAfY"] [Tue Aug 18 13:08:04.523163 2026] [security2:error] [pid 167459:tid 167648] [client 172.182.217.32:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css/min.php"] [unique_id "aoSDZGr_JutbFb-8svr3DwAAAco"] [Tue Aug 18 13:08:04.530591 2026] [security2:error] [pid 167459:tid 167586] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDZGr_JutbFb-8svr3EAAB-34"] [Tue Aug 18 13:08:04.531431 2026] [security2:error] [pid 167459:tid 167639] [client 132.196.30.78:13067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-good.php"] [unique_id "aoSDZGr_JutbFb-8svr3EQAAAcE"] [Tue Aug 18 13:08:04.542407 2026] [security2:error] [pid 167459:tid 167599] [client 20.163.43.14:15654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/lv.php"] [unique_id "aoSDZGr_JutbFb-8svr3EgAAAZk"] [Tue Aug 18 13:08:04.567868 2026] [security2:error] [pid 167459:tid 167494] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/contrjibus.php"] [unique_id "aoSDZGr_JutbFb-8svr3FAAB0SI"] [Tue Aug 18 13:08:04.568152 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:04.568413 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:04.570911 2026] [security2:error] [pid 167459:tid 167635] [client 207.175.174.249:23996] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/development/.env"] [unique_id "aoSDZGr_JutbFb-8svr3FQAAAb0"] [Tue Aug 18 13:08:04.589919 2026] [security2:error] [pid 167459:tid 167666] [client 20.106.102.5:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/nw.php"] [unique_id "aoSDZGr_JutbFb-8svr3FwAAAdw"] [Tue Aug 18 13:08:04.594808 2026] [security2:error] [pid 167459:tid 167657] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSDZGr_JutbFb-8svr3GAAAAdM"] [Tue Aug 18 13:08:04.596588 2026] [security2:error] [pid 167459:tid 167706] [client 20.151.109.219:40494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ee.php"] [unique_id "aoSDZGr_JutbFb-8svr3GQAAAgQ"] [Tue Aug 18 13:08:04.607636 2026] [core:error] [pid 167459:tid 167679] [client 207.175.174.249:23808] AH10244: invalid URI path (/public/plugins/grafana-clock-panel/../../../../../../../../.env) [Tue Aug 18 13:08:04.611807 2026] [security2:error] [pid 167459:tid 167684] [client 20.127.136.245:16614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/images/class-config.php"] [unique_id "aoSDZGr_JutbFb-8svr3GwAAAe4"] [Tue Aug 18 13:08:04.652609 2026] [security2:error] [pid 167459:tid 167617] [client 213.35.127.232:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDZGr_JutbFb-8svr3HgAAAas"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:04.675941 2026] [security2:error] [pid 167459:tid 167476] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/v5.php"] [unique_id "aoSDZGr_JutbFb-8svr3HwABqBA"] [Tue Aug 18 13:08:04.696882 2026] [security2:error] [pid 167459:tid 167596] [client 158.158.74.177:13794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSDZGr_JutbFb-8svr3IQAAAZY"] [Tue Aug 18 13:08:04.724836 2026] [security2:error] [pid 167459:tid 167675] [client 4.232.151.198:37517] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lucascamargosadv.com.br"] [uri "/1.php"] [unique_id "aoSDZGr_JutbFb-8svr3IgAAAeU"] [Tue Aug 18 13:08:04.724952 2026] [security2:error] [pid 167459:tid 167675] [client 4.232.151.198:37517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/1.php"] [unique_id "aoSDZGr_JutbFb-8svr3IgAAAeU"] [Tue Aug 18 13:08:04.748593 2026] [security2:error] [pid 167459:tid 167620] [client 20.226.36.136:25135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDZGr_JutbFb-8svr3IwAAAa4"] [Tue Aug 18 13:08:04.768970 2026] [security2:error] [pid 167459:tid 167672] [client 172.202.39.151:27895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDZGr_JutbFb-8svr3JAAAAeI"] [Tue Aug 18 13:08:04.771070 2026] [security2:error] [pid 167459:tid 167678] [client 207.175.174.249:23738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/v1/.env"] [unique_id "aoSDZGr_JutbFb-8svr3JQAAAeg"] [Tue Aug 18 13:08:04.771816 2026] [security2:error] [pid 167459:tid 167707] [client 52.139.47.57:31575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/in.php"] [unique_id "aoSDZGr_JutbFb-8svr3JwAAAgU"] [Tue Aug 18 13:08:04.800484 2026] [security2:error] [pid 167459:tid 167669] [client 20.104.100.201:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fine.php"] [unique_id "aoSDZGr_JutbFb-8svr3KgAAAd8"] [Tue Aug 18 13:08:04.819508 2026] [security2:error] [pid 167459:tid 167659] [client 40.74.65.169:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/edit.php"] [unique_id "aoSDZGr_JutbFb-8svr3KwAAAdU"] [Tue Aug 18 13:08:04.823974 2026] [security2:error] [pid 167459:tid 167465] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDZGr_JutbFb-8svr3LAABlQU"] [Tue Aug 18 13:08:04.857966 2026] [security2:error] [pid 167459:tid 167549] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/we.php"] [unique_id "aoSDZGr_JutbFb-8svr3LQAB-Vk"] [Tue Aug 18 13:08:04.869641 2026] [security2:error] [pid 167459:tid 167650] [client 20.163.43.14:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/new.php"] [unique_id "aoSDZGr_JutbFb-8svr3MAAAAcw"] [Tue Aug 18 13:08:04.879641 2026] [security2:error] [pid 167459:tid 167484] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/contrjibuscsxcds.php"] [unique_id "aoSDZGr_JutbFb-8svr3MQAB3Rg"] [Tue Aug 18 13:08:04.884589 2026] [security2:error] [pid 167459:tid 167651] [client 207.175.174.249:23792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.vindimo.com.br"] [uri "/.docker/.env"] [unique_id "aoSDZGr_JutbFb-8svr3MgAAAc0"] [Tue Aug 18 13:08:04.912564 2026] [security2:error] [pid 167459:tid 167628] [client 20.106.102.5:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ws62.php"] [unique_id "aoSDZGr_JutbFb-8svr3MwAAAbY"] [Tue Aug 18 13:08:04.918131 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/an.php"] [unique_id "aoSDZGr_JutbFb-8svr3NAAAAbw"] [Tue Aug 18 13:08:05.012903 2026] [security2:error] [pid 167459:tid 167621] [client 172.182.217.32:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/plugins/data.php"] [unique_id "aoSDZWr_JutbFb-8svr3NgAAAa8"] [Tue Aug 18 13:08:05.024192 2026] [security2:error] [pid 167459:tid 167658] [client 20.79.204.6:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/test.php"] [unique_id "aoSDZWr_JutbFb-8svr3OAAAAdQ"] [Tue Aug 18 13:08:05.029584 2026] [security2:error] [pid 167459:tid 167683] [client 20.151.109.219:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ak.php"] [unique_id "aoSDZWr_JutbFb-8svr3OQAAAe0"] [Tue Aug 18 13:08:05.040054 2026] [security2:error] [pid 167459:tid 167475] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wkl.php"] [unique_id "aoSDZWr_JutbFb-8svr3OwABzg8"] [Tue Aug 18 13:08:05.124891 2026] [security2:error] [pid 167459:tid 167490] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/222.php"] [unique_id "aoSDZWr_JutbFb-8svr3PgABpR4"] [Tue Aug 18 13:08:05.135759 2026] [security2:error] [pid 167459:tid 167603] [client 132.196.30.78:13094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/simple.php"] [unique_id "aoSDZWr_JutbFb-8svr3QAAAAZ0"] [Tue Aug 18 13:08:05.168976 2026] [security2:error] [pid 167459:tid 167616] [client 4.232.151.198:16544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/memberfuns.php"] [unique_id "aoSDZWr_JutbFb-8svr3QgAAAao"] [Tue Aug 18 13:08:05.169666 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:05.169953 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:05.180809 2026] [security2:error] [pid 167459:tid 167673] [client 20.104.100.201:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/memberfuns.php"] [unique_id "aoSDZWr_JutbFb-8svr3QwAAAeM"] [Tue Aug 18 13:08:05.184875 2026] [security2:error] [pid 167459:tid 167654] [client 52.139.47.57:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/info.php"] [unique_id "aoSDZWr_JutbFb-8svr3RAAAAdA"] [Tue Aug 18 13:08:05.193253 2026] [security2:error] [pid 167459:tid 167697] [client 20.163.43.14:15678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/222.php"] [unique_id "aoSDZWr_JutbFb-8svr3RQAAAfs"] [Tue Aug 18 13:08:05.235247 2026] [security2:error] [pid 167459:tid 167505] [remote 97.74.87.194:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriarfood.com"] [uri "/wp-login.php"] [unique_id "aoSDZWr_JutbFb-8svr3SQABpi0"] [Tue Aug 18 13:08:05.238542 2026] [security2:error] [pid 167459:tid 167655] [client 20.106.102.5:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/public/vx.php"] [unique_id "aoSDZWr_JutbFb-8svr3SgAAAdE"] [Tue Aug 18 13:08:05.239684 2026] [security2:error] [pid 167459:tid 167635] [client 20.226.36.136:43573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDZWr_JutbFb-8svr3SwAAAb0"] [Tue Aug 18 13:08:05.263652 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/loader.php"] [unique_id "aoSDZWr_JutbFb-8svr3TQAAAgQ"] [Tue Aug 18 13:08:05.263696 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.18.37:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-sitemas-user.php"] [unique_id "aoSDZWr_JutbFb-8svr3TAAAAdI"] [Tue Aug 18 13:08:05.333455 2026] [security2:error] [pid 167459:tid 167670] [client 158.158.74.177:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDZWr_JutbFb-8svr3UwAAAeA"] [Tue Aug 18 13:08:05.334807 2026] [security2:error] [pid 167459:tid 167701] [client 47.128.50.207:54482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.eccellenzaconsultoria.com.br"] [uri "/robots.txt"] [unique_id "aoSDZWr_JutbFb-8svr3VAAAAf8"] [Tue Aug 18 13:08:05.388062 2026] [security2:error] [pid 167459:tid 167681] [client 207.175.174.249:23948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.174.175.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.vindimo.com.br"] [uri "/sendgrid/.env.php"] [unique_id "aoSDZWr_JutbFb-8svr3VQAAAes"] [Tue Aug 18 13:08:05.415077 2026] [security2:error] [pid 167459:tid 167565] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDZWr_JutbFb-8svr3VwAB-Gk"] [Tue Aug 18 13:08:05.457867 2026] [security2:error] [pid 167459:tid 167675] [client 172.202.39.151:27859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDZWr_JutbFb-8svr3WQAAAeU"] [Tue Aug 18 13:08:05.471289 2026] [security2:error] [pid 167459:tid 167594] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/404.php"] [unique_id "aoSDZWr_JutbFb-8svr3WgAAAZQ"] [Tue Aug 18 13:08:05.486993 2026] [security2:error] [pid 167459:tid 167580] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/work.php"] [unique_id "aoSDZWr_JutbFb-8svr3XAAB5Hg"] [Tue Aug 18 13:08:05.499861 2026] [security2:error] [pid 167459:tid 167646] [client 172.182.217.32:25536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/plugins/plugin-install.php"] [unique_id "aoSDZWr_JutbFb-8svr3XgAAAcg"] [Tue Aug 18 13:08:05.515663 2026] [security2:error] [pid 167459:tid 167672] [client 52.173.121.69:28304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDZWr_JutbFb-8svr3YAAAAeI"] [Tue Aug 18 13:08:05.518908 2026] [security2:error] [pid 167459:tid 167678] [client 20.163.43.14:15691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/chosen.php"] [unique_id "aoSDZWr_JutbFb-8svr3YQAAAeg"] [Tue Aug 18 13:08:05.521467 2026] [security2:error] [pid 167459:tid 167530] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSDZWr_JutbFb-8svr3YgACBUY"] [Tue Aug 18 13:08:05.551838 2026] [security2:error] [pid 167459:tid 167601] [client 128.140.41.193:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.pousadadoreiarthur.com.br"] [uri "/index.php"] [unique_id "aoSDY2r_JutbFb-8svr2vwABm1I"], referer: https://www.pousadadoreiarthur.com.br/ [Tue Aug 18 13:08:05.568919 2026] [security2:error] [pid 167459:tid 167693] [client 20.106.102.5:45135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/loxi-o.php"] [unique_id "aoSDZWr_JutbFb-8svr3YwAAAfc"] [Tue Aug 18 13:08:05.600976 2026] [security2:error] [pid 167459:tid 167688] [client 52.139.47.57:31606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/inputs.php"] [unique_id "aoSDZWr_JutbFb-8svr3ZgAAAfI"] [Tue Aug 18 13:08:05.605490 2026] [security2:error] [pid 167459:tid 167668] [client 20.226.36.136:41564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDZWr_JutbFb-8svr3ZwAAAd4"] [Tue Aug 18 13:08:05.610493 2026] [security2:error] [pid 167459:tid 167702] [client 40.74.65.169:20576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDZWr_JutbFb-8svr3aAAAAgA"] [Tue Aug 18 13:08:05.635957 2026] [security2:error] [pid 167459:tid 167705] [client 20.79.204.6:5978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/test1.php"] [unique_id "aoSDZWr_JutbFb-8svr3aQAAAgM"] [Tue Aug 18 13:08:05.664680 2026] [security2:error] [pid 167459:tid 167651] [client 20.127.136.245:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/alfa.php"] [unique_id "aoSDZWr_JutbFb-8svr3bQAAAc0"] [Tue Aug 18 13:08:05.665696 2026] [security2:error] [pid 167459:tid 167593] [client 213.35.127.232:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDZWr_JutbFb-8svr3bgAAAZM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:05.669177 2026] [security2:error] [pid 167459:tid 167463] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/worksec.php"] [unique_id "aoSDZWr_JutbFb-8svr3bwABwwM"] [Tue Aug 18 13:08:05.669249 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:05.669639 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:05.705663 2026] [security2:error] [pid 167459:tid 167497] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDZWr_JutbFb-8svr3cgABtiU"] [Tue Aug 18 13:08:05.750182 2026] [security2:error] [pid 167459:tid 167591] [client 104.209.144.33:25323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDZWr_JutbFb-8svr3cwAAAZE"] [Tue Aug 18 13:08:05.753068 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-temp.php"] [unique_id "aoSDZWr_JutbFb-8svr3dAAAAcc"] [Tue Aug 18 13:08:05.758525 2026] [security2:error] [pid 167459:tid 167607] [client 20.250.13.23:45204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/min.php"] [unique_id "aoSDZWr_JutbFb-8svr3dQAAAaE"] [Tue Aug 18 13:08:05.786836 2026] [security2:error] [pid 167459:tid 167658] [client 20.151.109.219:20982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/test_info.php"] [unique_id "aoSDZWr_JutbFb-8svr3dwAAAdQ"] [Tue Aug 18 13:08:05.787913 2026] [security2:error] [pid 167459:tid 167627] [client 172.202.39.151:39205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/k.php"] [unique_id "aoSDZWr_JutbFb-8svr3eAAAAbU"] [Tue Aug 18 13:08:05.804686 2026] [security2:error] [pid 167459:tid 167683] [client 20.104.100.201:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/zero.php"] [unique_id "aoSDZWr_JutbFb-8svr3eQAAAe0"] [Tue Aug 18 13:08:05.825540 2026] [security2:error] [pid 167459:tid 167652] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-login.php"] [unique_id "aoSDZWr_JutbFb-8svr3egAAAc4"] [Tue Aug 18 13:08:05.833892 2026] [security2:error] [pid 167459:tid 167585] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDZWr_JutbFb-8svr3ewAB_H0"] [Tue Aug 18 13:08:05.850997 2026] [security2:error] [pid 167459:tid 167488] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-activate.php"] [unique_id "aoSDZWr_JutbFb-8svr3fAABjxw"] [Tue Aug 18 13:08:05.851513 2026] [security2:error] [pid 167459:tid 167613] [client 20.163.43.14:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/info.php"] [unique_id "aoSDZWr_JutbFb-8svr3fQAAAac"] [Tue Aug 18 13:08:05.881158 2026] [security2:error] [pid 167459:tid 167630] [client 132.196.30.78:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/edit-tags.php"] [unique_id "aoSDZWr_JutbFb-8svr3fwAAAbg"] [Tue Aug 18 13:08:05.894469 2026] [security2:error] [pid 167459:tid 167603] [client 20.106.102.5:45224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sdsa.php"] [unique_id "aoSDZWr_JutbFb-8svr3gAAAAZ0"] [Tue Aug 18 13:08:05.923601 2026] [security2:error] [pid 167459:tid 167640] [client 4.232.151.198:48475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/mgrr.php"] [unique_id "aoSDZWr_JutbFb-8svr3ggAAAcI"] [Tue Aug 18 13:08:05.969693 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:05.969958 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:05.980961 2026] [security2:error] [pid 167459:tid 167621] [client 158.158.74.177:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/cjfuns.php"] [unique_id "aoSDZWr_JutbFb-8svr3hQAAAa8"] [Tue Aug 18 13:08:05.996808 2026] [security2:error] [pid 167459:tid 167510] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/l10n/"] [unique_id "aoSDZWr_JutbFb-8svr3hgAB-zI"] [Tue Aug 18 13:08:06.035596 2026] [security2:error] [pid 167459:tid 167611] [client 52.139.47.57:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/item.php"] [unique_id "aoSDZmr_JutbFb-8svr3hwAAAaU"] [Tue Aug 18 13:08:06.037490 2026] [security2:error] [pid 167459:tid 167704] [client 172.182.217.32:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/plugins/users.php"] [unique_id "aoSDZmr_JutbFb-8svr3iAAAAgI"] [Tue Aug 18 13:08:06.038979 2026] [security2:error] [pid 167459:tid 167524] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin.php"] [unique_id "aoSDZmr_JutbFb-8svr3iQABpkA"] [Tue Aug 18 13:08:06.126690 2026] [security2:error] [pid 167459:tid 167680] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDZmr_JutbFb-8svr3iwAAAeo"] [Tue Aug 18 13:08:06.173054 2026] [security2:error] [pid 167459:tid 167624] [client 74.248.18.37:30751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/.well-known/pki-validation/wp-login.php"] [unique_id "aoSDZmr_JutbFb-8svr3jgAAAbI"] [Tue Aug 18 13:08:06.224312 2026] [security2:error] [pid 167459:tid 167701] [client 20.106.102.5:45153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-freya.php"] [unique_id "aoSDZmr_JutbFb-8svr3kQAAAf8"] [Tue Aug 18 13:08:06.260905 2026] [security2:error] [pid 167459:tid 167679] [client 138.36.100.162:42725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZmr_JutbFb-8svr3lgAAAek"] [Tue Aug 18 13:08:06.261027 2026] [security2:error] [pid 167459:tid 167679] [client 138.36.100.162:42725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZmr_JutbFb-8svr3lgAAAek"] [Tue Aug 18 13:08:06.274331 2026] [security2:error] [pid 167459:tid 167609] [client 20.104.100.201:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/002.php"] [unique_id "aoSDZmr_JutbFb-8svr3mQAAAaM"] [Tue Aug 18 13:08:06.275059 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:06.275505 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:06.287967 2026] [security2:error] [pid 167459:tid 167483] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp.php"] [unique_id "aoSDZmr_JutbFb-8svr3mgAB-hc"] [Tue Aug 18 13:08:06.354660 2026] [security2:error] [pid 167459:tid 167655] [client 20.79.204.6:5987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/thoms.php"] [unique_id "aoSDZmr_JutbFb-8svr3nQAAAdE"] [Tue Aug 18 13:08:06.392271 2026] [security2:error] [pid 167459:tid 167678] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDZmr_JutbFb-8svr3ngAAAeg"] [Tue Aug 18 13:08:06.408262 2026] [security2:error] [pid 167459:tid 167661] [client 20.163.43.14:15642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDZmr_JutbFb-8svr3oQAAAdc"] [Tue Aug 18 13:08:06.417484 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.100.201:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/aa.php"] [unique_id "aoSDZmr_JutbFb-8svr3owAAAfc"] [Tue Aug 18 13:08:06.419797 2026] [security2:error] [pid 167459:tid 167659] [client 20.127.136.245:13011] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/1.php"] [unique_id "aoSDZmr_JutbFb-8svr3pAAAAdU"] [Tue Aug 18 13:08:06.419888 2026] [security2:error] [pid 167459:tid 167659] [client 20.127.136.245:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/1.php"] [unique_id "aoSDZmr_JutbFb-8svr3pAAAAdU"] [Tue Aug 18 13:08:06.423079 2026] [security2:error] [pid 167459:tid 167716] [client 20.151.109.219:20967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/14.php"] [unique_id "aoSDZmr_JutbFb-8svr3pQAAAg4"] [Tue Aug 18 13:08:06.458503 2026] [security2:error] [pid 167459:tid 167576] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSDZmr_JutbFb-8svr3qAACAHQ"] [Tue Aug 18 13:08:06.472391 2026] [security2:error] [pid 167459:tid 167514] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDZmr_JutbFb-8svr3qQABojY"] [Tue Aug 18 13:08:06.483710 2026] [security2:error] [pid 167459:tid 167631] [client 20.226.36.136:33439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDZmr_JutbFb-8svr3qgAAAbk"] [Tue Aug 18 13:08:06.514551 2026] [security2:error] [pid 167459:tid 167620] [client 52.139.47.57:10132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/k.php"] [unique_id "aoSDZmr_JutbFb-8svr3rAAAAa4"] [Tue Aug 18 13:08:06.543406 2026] [autoindex:error] [pid 167459:tid 167594] [client 172.182.217.32:4079] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/js/tinymce/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:06.557447 2026] [security2:error] [pid 167459:tid 167628] [client 172.202.39.151:39231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/403.php"] [unique_id "aoSDZmr_JutbFb-8svr3sAAAAbY"] [Tue Aug 18 13:08:06.570024 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:06.570278 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:06.575439 2026] [security2:error] [pid 167459:tid 167596] [client 132.196.30.78:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/u.php"] [unique_id "aoSDZmr_JutbFb-8svr3tAAAAZY"] [Tue Aug 18 13:08:06.577963 2026] [security2:error] [pid 167459:tid 167534] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/i.php"] [unique_id "aoSDZmr_JutbFb-8svr3tQAB5ko"] [Tue Aug 18 13:08:06.587499 2026] [security2:error] [pid 167459:tid 167708] [client 20.106.102.5:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fleen.php"] [unique_id "aoSDZmr_JutbFb-8svr3tgAAAgY"] [Tue Aug 18 13:08:06.612408 2026] [security2:error] [pid 167459:tid 167591] [client 40.74.65.169:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/inputs.php"] [unique_id "aoSDZmr_JutbFb-8svr3uAAAAZE"] [Tue Aug 18 13:08:06.650811 2026] [security2:error] [pid 167459:tid 167592] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDZmr_JutbFb-8svr3uwAAAZI"] [Tue Aug 18 13:08:06.679933 2026] [security2:error] [pid 167459:tid 167675] [client 213.35.127.232:58673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDZmr_JutbFb-8svr3vAAAAeU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:06.699614 2026] [security2:error] [pid 167459:tid 167658] [client 20.104.100.201:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/zxz.php"] [unique_id "aoSDZmr_JutbFb-8svr3vgAAAdQ"] [Tue Aug 18 13:08:06.705241 2026] [security2:error] [pid 167459:tid 167627] [client 172.182.217.32:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/themes/config.php"] [unique_id "aoSDZmr_JutbFb-8svr3vwAAAbU"] [Tue Aug 18 13:08:06.714690 2026] [security2:error] [pid 167459:tid 167517] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDZmr_JutbFb-8svr3wAAB7Tk"] [Tue Aug 18 13:08:06.746757 2026] [security2:error] [pid 167459:tid 167520] [remote 178.156.200.16:38792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabyfranco.com.br"] [uri "/wp-login.php"] [unique_id "aoSDZmr_JutbFb-8svr3wQABzDw"] [Tue Aug 18 13:08:06.756008 2026] [security2:error] [pid 167459:tid 167593] [client 158.158.74.177:13802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSDZmr_JutbFb-8svr3wwAAAZM"] [Tue Aug 18 13:08:06.769923 2026] [security2:error] [pid 167459:tid 167613] [client 20.163.43.14:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDZmr_JutbFb-8svr3xAAAAac"] [Tue Aug 18 13:08:06.790673 2026] [security2:error] [pid 167459:tid 167630] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wso.php"] [unique_id "aoSDZmr_JutbFb-8svr3xwAAAbg"] [Tue Aug 18 13:08:06.806495 2026] [security2:error] [pid 167459:tid 167713] [client 20.151.109.219:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/tk.php"] [unique_id "aoSDZmr_JutbFb-8svr3yAAAAgs"] [Tue Aug 18 13:08:06.849993 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/mini.php"] [unique_id "aoSDZmr_JutbFb-8svr3yQAAAfY"] [Tue Aug 18 13:08:06.868587 2026] [security2:error] [pid 167459:tid 167564] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/abcd.php"] [unique_id "aoSDZmr_JutbFb-8svr3zAABr2g"] [Tue Aug 18 13:08:06.873544 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:06.873876 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:06.895646 2026] [security2:error] [pid 167459:tid 167516] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSDZmr_JutbFb-8svr3zgABmTg"] [Tue Aug 18 13:08:06.906708 2026] [security2:error] [pid 167459:tid 167691] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/admin.php"] [unique_id "aoSDZmr_JutbFb-8svr3zwAAAfU"] [Tue Aug 18 13:08:06.909215 2026] [security2:error] [pid 167459:tid 167623] [client 20.106.102.5:45216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/e.php"] [unique_id "aoSDZmr_JutbFb-8svr30AAAAbE"] [Tue Aug 18 13:08:06.931377 2026] [security2:error] [pid 167459:tid 167704] [client 20.215.241.237:22379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDZmr_JutbFb-8svr30QAAAgI"] [Tue Aug 18 13:08:06.936663 2026] [security2:error] [pid 167459:tid 167603] [client 52.139.47.57:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/license.php"] [unique_id "aoSDZmr_JutbFb-8svr30gAAAZ0"] [Tue Aug 18 13:08:06.974297 2026] [security2:error] [pid 167459:tid 167715] [client 20.250.13.23:45237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/php8.php"] [unique_id "aoSDZmr_JutbFb-8svr31QAAAg0"] [Tue Aug 18 13:08:06.987977 2026] [security2:error] [pid 167459:tid 167604] [client 20.79.204.6:5737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/tool.php"] [unique_id "aoSDZmr_JutbFb-8svr31wAAAZ4"] [Tue Aug 18 13:08:07.068562 2026] [security2:error] [pid 167459:tid 167681] [client 20.104.100.201:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDZ2r_JutbFb-8svr32QAAAes"] [Tue Aug 18 13:08:07.075819 2026] [security2:error] [pid 167459:tid 167499] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDZ2r_JutbFb-8svr32gAB-Cc"] [Tue Aug 18 13:08:07.108880 2026] [security2:error] [pid 167459:tid 167649] [client 20.163.43.14:15632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/k.php"] [unique_id "aoSDZ2r_JutbFb-8svr34AAAAcs"] [Tue Aug 18 13:08:07.109140 2026] [security2:error] [pid 167459:tid 167641] [client 197.184.64.235:42691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZ2r_JutbFb-8svr34QAAAcM"] [Tue Aug 18 13:08:07.109283 2026] [security2:error] [pid 167459:tid 167641] [client 197.184.64.235:42691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDZ2r_JutbFb-8svr34QAAAcM"] [Tue Aug 18 13:08:07.161512 2026] [security2:error] [pid 167459:tid 167688] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/public/css.php"] [unique_id "aoSDZ2r_JutbFb-8svr35QAAAfI"] [Tue Aug 18 13:08:07.174772 2026] [security2:error] [pid 167459:tid 167538] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDZ2r_JutbFb-8svr35wABuU4"] [Tue Aug 18 13:08:07.176681 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:07.177124 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:07.179124 2026] [security2:error] [pid 167459:tid 167638] [client 132.196.30.78:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDZ2r_JutbFb-8svr36AAAAcA"] [Tue Aug 18 13:08:07.185518 2026] [security2:error] [pid 167459:tid 167615] [client 20.127.136.245:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/222.php"] [unique_id "aoSDZ2r_JutbFb-8svr36wAAAak"] [Tue Aug 18 13:08:07.195034 2026] [security2:error] [pid 167459:tid 167614] [client 172.182.217.32:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/themes/db-status.php"] [unique_id "aoSDZ2r_JutbFb-8svr37AAAAag"] [Tue Aug 18 13:08:07.232565 2026] [security2:error] [pid 167459:tid 167619] [client 20.226.36.136:25889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDZ2r_JutbFb-8svr37wAAAa0"] [Tue Aug 18 13:08:07.232577 2026] [security2:error] [pid 167459:tid 167667] [client 20.106.102.5:45258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/hello.php"] [unique_id "aoSDZ2r_JutbFb-8svr38AAAAd0"] [Tue Aug 18 13:08:07.241333 2026] [security2:error] [pid 167459:tid 167594] [client 20.151.109.219:32545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/hp.php"] [unique_id "aoSDZ2r_JutbFb-8svr38QAAAZQ"] [Tue Aug 18 13:08:07.312189 2026] [security2:error] [pid 167459:tid 167645] [client 74.248.18.37:30737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-site-query-pic.php"] [unique_id "aoSDZ2r_JutbFb-8svr39AAAAcc"] [Tue Aug 18 13:08:07.320955 2026] [security2:error] [pid 167459:tid 167601] [client 40.74.65.169:7087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/av.php"] [unique_id "aoSDZ2r_JutbFb-8svr39QAAAZs"] [Tue Aug 18 13:08:07.346086 2026] [security2:error] [pid 167459:tid 167671] [client 20.116.17.175:52564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-css.php"] [unique_id "aoSDZ2r_JutbFb-8svr39wAAAeE"] [Tue Aug 18 13:08:07.362370 2026] [security2:error] [pid 167459:tid 167651] [client 52.139.47.57:38362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/load.php"] [unique_id "aoSDZ2r_JutbFb-8svr3-AAAAc0"] [Tue Aug 18 13:08:07.377194 2026] [security2:error] [pid 167459:tid 167608] [client 158.158.74.177:13716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSDZ2r_JutbFb-8svr3-QAAAaI"] [Tue Aug 18 13:08:07.411875 2026] [security2:error] [pid 167459:tid 167593] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDZ2r_JutbFb-8svr3_AAAAZM"] [Tue Aug 18 13:08:07.448444 2026] [security2:error] [pid 167459:tid 167504] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSDZ2r_JutbFb-8svr3_wACCCw"] [Tue Aug 18 13:08:07.469208 2026] [security2:error] [pid 167459:tid 167583] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDZ2r_JutbFb-8svr4AQABp3s"] [Tue Aug 18 13:08:07.498124 2026] [security2:error] [pid 167459:tid 167596] [client 4.232.151.198:48480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/minishell.php"] [unique_id "aoSDZ2r_JutbFb-8svr4AwAAAZY"] [Tue Aug 18 13:08:07.557416 2026] [security2:error] [pid 167459:tid 167607] [client 20.106.102.5:45231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/brc.php"] [unique_id "aoSDZ2r_JutbFb-8svr4BgAAAaE"] [Tue Aug 18 13:08:07.558576 2026] [security2:error] [pid 167459:tid 167599] [client 104.209.144.33:31278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDZ2r_JutbFb-8svr4BwAAAZk"] [Tue Aug 18 13:08:07.581587 2026] [security2:error] [pid 167459:tid 167611] [client 20.65.98.162:39676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDZ2r_JutbFb-8svr4CAAAAaU"] [Tue Aug 18 13:08:07.591366 2026] [security2:error] [pid 167459:tid 167704] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/sf.php"] [unique_id "aoSDZ2r_JutbFb-8svr4CQAAAgI"] [Tue Aug 18 13:08:07.600236 2026] [security2:error] [pid 167459:tid 167635] [client 20.215.241.237:51367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDZ2r_JutbFb-8svr4CwAAAb0"] [Tue Aug 18 13:08:07.613754 2026] [security2:error] [pid 167459:tid 167680] [client 20.163.43.14:15621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/403.php"] [unique_id "aoSDZ2r_JutbFb-8svr4DAAAAeo"] [Tue Aug 18 13:08:07.629538 2026] [security2:error] [pid 167459:tid 167462] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDZ2r_JutbFb-8svr4DQAB7gI"] [Tue Aug 18 13:08:07.630627 2026] [security2:error] [pid 167459:tid 167698] [client 20.79.204.6:5981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/tools.php"] [unique_id "aoSDZ2r_JutbFb-8svr4DgAAAfw"] [Tue Aug 18 13:08:07.700645 2026] [autoindex:error] [pid 167459:tid 167692] [client 172.182.217.32:25559] AH01276: Cannot serve directory /home3/qriarq24/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:07.710168 2026] [security2:error] [pid 167459:tid 167683] [client 213.35.127.232:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDZ2r_JutbFb-8svr4FAAAAe0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:07.751974 2026] [security2:error] [pid 167459:tid 167511] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/colors/modern/admin.php"] [unique_id "aoSDZ2r_JutbFb-8svr4FQAB6DM"] [Tue Aug 18 13:08:07.757585 2026] [security2:error] [pid 167459:tid 167691] [client 20.25.139.174:4499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/inputs.php"] [unique_id "aoSDZ2r_JutbFb-8svr4FgAAAfU"] [Tue Aug 18 13:08:07.760222 2026] [security2:error] [pid 167459:tid 167500] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDZ2r_JutbFb-8svr4FwAB4ig"] [Tue Aug 18 13:08:07.776067 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:07.776408 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:07.796375 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:31558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/manager.php"] [unique_id "aoSDZ2r_JutbFb-8svr4GwAAAfA"] [Tue Aug 18 13:08:07.802351 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.100.201:13942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/echkm.php"] [unique_id "aoSDZ2r_JutbFb-8svr4HAAAAfc"] [Tue Aug 18 13:08:07.804697 2026] [security2:error] [pid 167459:tid 167669] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDZ2r_JutbFb-8svr4HQAAAd8"] [Tue Aug 18 13:08:07.812998 2026] [security2:error] [pid 167459:tid 167695] [client 172.202.39.151:27848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/gecko.php"] [unique_id "aoSDZ2r_JutbFb-8svr4HgAAAfk"] [Tue Aug 18 13:08:07.827438 2026] [security2:error] [pid 167459:tid 167528] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSDZ2r_JutbFb-8svr4IAAB8kQ"] [Tue Aug 18 13:08:07.863640 2026] [security2:error] [pid 167459:tid 167705] [client 172.182.217.32:25559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSDZ2r_JutbFb-8svr4IgAAAgM"] [Tue Aug 18 13:08:07.881135 2026] [security2:error] [pid 167459:tid 167638] [client 20.106.102.5:45308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/file52.php"] [unique_id "aoSDZ2r_JutbFb-8svr4JAAAAcA"] [Tue Aug 18 13:08:07.908064 2026] [security2:error] [pid 167459:tid 167615] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/index/function.php"] [unique_id "aoSDZ2r_JutbFb-8svr4JgAAAak"] [Tue Aug 18 13:08:07.919950 2026] [security2:error] [pid 167459:tid 167619] [client 20.104.100.201:53261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/aa.php"] [unique_id "aoSDZ2r_JutbFb-8svr4JwAAAa0"] [Tue Aug 18 13:08:07.985575 2026] [security2:error] [pid 167459:tid 167618] [client 196.12.128.158:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDZ2r_JutbFb-8svr4KwAAAaw"] [Tue Aug 18 13:08:07.985698 2026] [security2:error] [pid 167459:tid 167618] [client 196.12.128.158:51291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDZ2r_JutbFb-8svr4KwAAAaw"] [Tue Aug 18 13:08:07.999130 2026] [security2:error] [pid 167459:tid 167712] [client 20.65.98.162:46978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDZ2r_JutbFb-8svr4LAAAAgo"] [Tue Aug 18 13:08:08.006026 2026] [security2:error] [pid 167459:tid 167707] [client 158.158.74.177:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/import.php"] [unique_id "aoSDaGr_JutbFb-8svr4LQAAAgU"] [Tue Aug 18 13:08:08.021941 2026] [security2:error] [pid 167459:tid 167617] [client 74.7.175.154:51612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nstransportes.gruposchopan.com.br"] [uri "/index.php"] [unique_id "aoSDZmr_JutbFb-8svr3nAABqyA"] [Tue Aug 18 13:08:08.037481 2026] [security2:error] [pid 167459:tid 167601] [client 40.74.65.169:20750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDaGr_JutbFb-8svr4LwAAAZs"] [Tue Aug 18 13:08:08.050980 2026] [security2:error] [pid 167459:tid 167460] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/"] [unique_id "aoSDaGr_JutbFb-8svr4MQABzQA"] [Tue Aug 18 13:08:08.054942 2026] [security2:error] [pid 167459:tid 167702] [client 74.248.18.37:35432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/about.php7"] [unique_id "aoSDaGr_JutbFb-8svr4MwAAAgA"] [Tue Aug 18 13:08:08.060990 2026] [security2:error] [pid 167459:tid 167677] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/gelay.php"] [unique_id "aoSDaGr_JutbFb-8svr4NAAAAec"] [Tue Aug 18 13:08:08.078470 2026] [authz_core:error] [pid 167459:tid 167586] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:08.078739 2026] [authz_core:error] [pid 167459:tid 167586] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:08.106299 2026] [security2:error] [pid 167459:tid 167593] [client 20.127.136.245:1343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/asasx.php"] [unique_id "aoSDaGr_JutbFb-8svr4NwAAAZM"] [Tue Aug 18 13:08:08.133656 2026] [security2:error] [pid 167459:tid 167710] [client 20.226.36.136:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDaGr_JutbFb-8svr4OgAAAgg"] [Tue Aug 18 13:08:08.152414 2026] [security2:error] [pid 167459:tid 167594] [client 4.232.151.198:48474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/mm.php"] [unique_id "aoSDaGr_JutbFb-8svr4PAAAAZQ"] [Tue Aug 18 13:08:08.167006 2026] [security2:error] [pid 167459:tid 167631] [client 132.196.30.78:20304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/h.php"] [unique_id "aoSDaGr_JutbFb-8svr4PgAAAbk"] [Tue Aug 18 13:08:08.215161 2026] [security2:error] [pid 167459:tid 167648] [client 20.215.241.237:39790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDaGr_JutbFb-8svr4QgAAAco"] [Tue Aug 18 13:08:08.215193 2026] [security2:error] [pid 167459:tid 167668] [client 20.106.102.5:45247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sxdfrt.php"] [unique_id "aoSDaGr_JutbFb-8svr4QQAAAd4"] [Tue Aug 18 13:08:08.220813 2026] [security2:error] [pid 167459:tid 167653] [client 52.139.47.57:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/media.php"] [unique_id "aoSDaGr_JutbFb-8svr4QwAAAc8"] [Tue Aug 18 13:08:08.222468 2026] [security2:error] [pid 167459:tid 167673] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/edit.php"] [unique_id "aoSDaGr_JutbFb-8svr4RAAAAeM"] [Tue Aug 18 13:08:08.232080 2026] [security2:error] [pid 167459:tid 167592] [client 213.202.253.4:61088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/schallfuns.php"] [unique_id "aoSDaGr_JutbFb-8svr4RgAAAZI"], referer: www.google.com [Tue Aug 18 13:08:08.292123 2026] [security2:error] [pid 167459:tid 167599] [client 20.163.43.14:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/gecko.php"] [unique_id "aoSDaGr_JutbFb-8svr4UQAAAZk"] [Tue Aug 18 13:08:08.301461 2026] [security2:error] [pid 167459:tid 167521] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDaGr_JutbFb-8svr4UgABsT0"] [Tue Aug 18 13:08:08.310396 2026] [security2:error] [pid 167459:tid 167682] [client 20.25.139.174:4826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/admin.php"] [unique_id "aoSDaGr_JutbFb-8svr4VAAAAew"] [Tue Aug 18 13:08:08.325682 2026] [security2:error] [pid 167459:tid 167635] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDaGr_JutbFb-8svr4WAAAAb0"] [Tue Aug 18 13:08:08.342250 2026] [security2:error] [pid 167459:tid 167470] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/simple.php"] [unique_id "aoSDaGr_JutbFb-8svr4WQAB7go"] [Tue Aug 18 13:08:08.360090 2026] [security2:error] [pid 167459:tid 167616] [client 172.182.217.32:25544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "aoSDaGr_JutbFb-8svr4WwAAAao"] [Tue Aug 18 13:08:08.387598 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:08.388058 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:08.404309 2026] [security2:error] [pid 167459:tid 167589] [client 20.79.204.6:6003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/txets.php"] [unique_id "aoSDaGr_JutbFb-8svr4YgAAAY8"] [Tue Aug 18 13:08:08.404345 2026] [security2:error] [pid 167459:tid 167467] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDaGr_JutbFb-8svr4YQAB6Ac"] [Tue Aug 18 13:08:08.435862 2026] [security2:error] [pid 167459:tid 167662] [client 74.248.18.37:34953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/404.php"] [unique_id "aoSDaGr_JutbFb-8svr4ZAAAAdg"] [Tue Aug 18 13:08:08.452331 2026] [security2:error] [pid 167459:tid 167686] [client 20.104.100.201:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/echkm.php"] [unique_id "aoSDaGr_JutbFb-8svr4ZQAAAfA"] [Tue Aug 18 13:08:08.472181 2026] [security2:error] [pid 167459:tid 167687] [client 49.145.211.146:13029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaGr_JutbFb-8svr4UwAAAfE"] [Tue Aug 18 13:08:08.472425 2026] [security2:error] [pid 167459:tid 167687] [client 49.145.211.146:13029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaGr_JutbFb-8svr4UwAAAfE"] [Tue Aug 18 13:08:08.483137 2026] [security2:error] [pid 167459:tid 167565] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSDaGr_JutbFb-8svr4ZwAB8mk"] [Tue Aug 18 13:08:08.538243 2026] [security2:error] [pid 167459:tid 167619] [client 20.106.102.5:45234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/path.php"] [unique_id "aoSDaGr_JutbFb-8svr4aQAAAa0"] [Tue Aug 18 13:08:08.545987 2026] [security2:error] [pid 167459:tid 167633] [client 4.232.151.198:12103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/alfa.php"] [unique_id "aoSDaGr_JutbFb-8svr4awAAAbs"] [Tue Aug 18 13:08:08.552185 2026] [security2:error] [pid 167459:tid 167624] [client 20.127.136.245:4372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/filemanager.php"] [unique_id "aoSDaGr_JutbFb-8svr4bAAAAbI"] [Tue Aug 18 13:08:08.580859 2026] [security2:error] [pid 167459:tid 167634] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDaGr_JutbFb-8svr4cAAAAbw"] [Tue Aug 18 13:08:08.632338 2026] [security2:error] [pid 167459:tid 167542] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "aoSDaGr_JutbFb-8svr4cwABkVI"] [Tue Aug 18 13:08:08.648922 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/mar.php"] [unique_id "aoSDaGr_JutbFb-8svr4dQAAAcA"] [Tue Aug 18 13:08:08.665433 2026] [security2:error] [pid 167459:tid 167480] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSDaGr_JutbFb-8svr4dwABwxQ"] [Tue Aug 18 13:08:08.667647 2026] [security2:error] [pid 167459:tid 167572] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaGr_JutbFb-8svr4dgAB1HA"] [Tue Aug 18 13:08:08.667854 2026] [security2:error] [pid 167459:tid 167658] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaGr_JutbFb-8svr4dgAB1HA"] [Tue Aug 18 13:08:08.669272 2026] [security2:error] [pid 167459:tid 167659] [client 158.158.74.177:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/cropper.php"] [unique_id "aoSDaGr_JutbFb-8svr4eAAAAdU"] [Tue Aug 18 13:08:08.683474 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:08.683787 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:08.691314 2026] [security2:error] [pid 167459:tid 167650] [client 20.215.241.237:20557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/av.php"] [unique_id "aoSDaGr_JutbFb-8svr4ewAAAcw"] [Tue Aug 18 13:08:08.710677 2026] [security2:error] [pid 167459:tid 167694] [client 20.65.98.162:43353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/sky.php"] [unique_id "aoSDaGr_JutbFb-8svr4fQAAAfg"] [Tue Aug 18 13:08:08.715434 2026] [security2:error] [pid 167459:tid 167557] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/css/mghnhykio.php"] [unique_id "aoSDaGr_JutbFb-8svr4fwABmmE"] [Tue Aug 18 13:08:08.722984 2026] [security2:error] [pid 167459:tid 167681] [client 213.35.127.232:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDaGr_JutbFb-8svr4gAAAAes"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:08.759006 2026] [security2:error] [pid 167459:tid 167713] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDaGr_JutbFb-8svr4gQAAAgs"] [Tue Aug 18 13:08:08.801021 2026] [security2:error] [pid 167459:tid 167601] [client 20.25.139.174:4626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/goods.php"] [unique_id "aoSDaGr_JutbFb-8svr4hwAAAZs"] [Tue Aug 18 13:08:08.821705 2026] [security2:error] [pid 167459:tid 167603] [client 4.232.151.198:16542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ms-edit.php"] [unique_id "aoSDaGr_JutbFb-8svr4iAAAAZ0"] [Tue Aug 18 13:08:08.846243 2026] [security2:error] [pid 167459:tid 167608] [client 172.182.217.32:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/js/tinymce/themes/xmlrpc.php"] [unique_id "aoSDaGr_JutbFb-8svr4iwAAAaI"] [Tue Aug 18 13:08:08.846716 2026] [security2:error] [pid 167459:tid 167668] [client 20.163.43.14:15725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/aa.php"] [unique_id "aoSDaGr_JutbFb-8svr4jAAAAd4"] [Tue Aug 18 13:08:08.851087 2026] [security2:error] [pid 167459:tid 167677] [client 132.196.30.78:20311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDaGr_JutbFb-8svr4jQAAAec"] [Tue Aug 18 13:08:08.864613 2026] [security2:error] [pid 167459:tid 167654] [client 20.106.102.5:45245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wpo.php"] [unique_id "aoSDaGr_JutbFb-8svr4jwAAAdA"] [Tue Aug 18 13:08:08.889079 2026] [security2:error] [pid 167459:tid 167599] [client 20.151.109.219:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wx.php"] [unique_id "aoSDaGr_JutbFb-8svr4kQAAAZk"] [Tue Aug 18 13:08:08.910580 2026] [security2:error] [pid 167459:tid 167602] [client 172.202.39.151:39218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/aa.php"] [unique_id "aoSDaGr_JutbFb-8svr4kgAAAZw"] [Tue Aug 18 13:08:08.915379 2026] [security2:error] [pid 167459:tid 167612] [client 20.104.100.201:53263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/domvf.php"] [unique_id "aoSDaGr_JutbFb-8svr4kwAAAaY"] [Tue Aug 18 13:08:08.915871 2026] [security2:error] [pid 167459:tid 167611] [client 40.74.65.169:20598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDaGr_JutbFb-8svr4lAAAAaU"] [Tue Aug 18 13:08:08.921639 2026] [security2:error] [pid 167459:tid 167495] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/chosen.php"] [unique_id "aoSDaGr_JutbFb-8svr4lQAB7CM"] [Tue Aug 18 13:08:08.947113 2026] [security2:error] [pid 167459:tid 167680] [client 20.127.136.245:22058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/themes.php"] [unique_id "aoSDaGr_JutbFb-8svr4lgAAAeo"] [Tue Aug 18 13:08:08.973064 2026] [security2:error] [pid 167459:tid 167715] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDaGr_JutbFb-8svr4mAAAAg0"] [Tue Aug 18 13:08:08.985782 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:08.986112 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:09.005972 2026] [security2:error] [pid 167459:tid 167616] [client 158.23.17.4:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/conn-test.php"] [unique_id "aoSDaWr_JutbFb-8svr4mgAAAao"] [Tue Aug 18 13:08:09.014153 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:35395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/dedi1.php"] [unique_id "aoSDaWr_JutbFb-8svr4mwAAAfY"] [Tue Aug 18 13:08:09.026860 2026] [security2:error] [pid 167459:tid 167510] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/file-admin.php"] [unique_id "aoSDaWr_JutbFb-8svr4nAAB7TI"] [Tue Aug 18 13:08:09.036035 2026] [security2:error] [pid 167459:tid 167524] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDaWr_JutbFb-8svr4nQAB9UA"] [Tue Aug 18 13:08:09.048076 2026] [security2:error] [pid 167459:tid 167597] [client 20.79.204.6:5708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/u.php"] [unique_id "aoSDaWr_JutbFb-8svr4nwAAAZc"] [Tue Aug 18 13:08:09.067473 2026] [security2:error] [pid 167459:tid 167625] [client 52.139.47.57:24085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/my1.php"] [unique_id "aoSDaWr_JutbFb-8svr4oQAAAbM"] [Tue Aug 18 13:08:09.075485 2026] [security2:error] [pid 167459:tid 167662] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-good.php"] [unique_id "aoSDaWr_JutbFb-8svr4pAAAAdg"] [Tue Aug 18 13:08:09.144867 2026] [security2:error] [pid 167459:tid 167706] [client 104.209.144.33:25297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDaWr_JutbFb-8svr4pwAAAgQ"] [Tue Aug 18 13:08:09.180186 2026] [security2:error] [pid 167459:tid 167711] [client 20.163.43.14:15724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/0x.php"] [unique_id "aoSDaWr_JutbFb-8svr4qQAAAgk"] [Tue Aug 18 13:08:09.189300 2026] [security2:error] [pid 167459:tid 167657] [client 20.106.102.5:45302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/a1vx.php"] [unique_id "aoSDaWr_JutbFb-8svr4qgAAAdM"] [Tue Aug 18 13:08:09.230418 2026] [security2:error] [pid 167459:tid 167628] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/about.php"] [unique_id "aoSDaWr_JutbFb-8svr4qwAAAbY"] [Tue Aug 18 13:08:09.243214 2026] [security2:error] [pid 167459:tid 167513] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSDaWr_JutbFb-8svr4rAAB7zU"] [Tue Aug 18 13:08:09.256670 2026] [security2:error] [pid 167459:tid 167548] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "aoSDaWr_JutbFb-8svr4rgABn1g"] [Tue Aug 18 13:08:09.283219 2026] [security2:error] [pid 167459:tid 167708] [client 20.215.241.237:47824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/images.php"] [unique_id "aoSDaWr_JutbFb-8svr4sAAAAgY"] [Tue Aug 18 13:08:09.286812 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:09.287069 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:09.294200 2026] [security2:error] [pid 167459:tid 167609] [client 74.248.18.37:34990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wk/index.php"] [unique_id "aoSDaWr_JutbFb-8svr4sQAAAaM"] [Tue Aug 18 13:08:09.312644 2026] [security2:error] [pid 167459:tid 167714] [client 158.158.74.177:13823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSDaWr_JutbFb-8svr4sgAAAgw"] [Tue Aug 18 13:08:09.315058 2026] [security2:error] [pid 167459:tid 167688] [client 20.25.139.174:4713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/file.php"] [unique_id "aoSDaWr_JutbFb-8svr4swAAAfI"] [Tue Aug 18 13:08:09.325112 2026] [security2:error] [pid 167459:tid 167675] [client 20.226.36.136:25140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDaWr_JutbFb-8svr4tAAAAeU"] [Tue Aug 18 13:08:09.339589 2026] [security2:error] [pid 167459:tid 167502] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/file.php"] [unique_id "aoSDaWr_JutbFb-8svr4uQABwCo"] [Tue Aug 18 13:08:09.345346 2026] [security2:error] [pid 167459:tid 167658] [client 20.151.109.219:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/dj.php"] [unique_id "aoSDaWr_JutbFb-8svr4ugAAAdQ"] [Tue Aug 18 13:08:09.404044 2026] [authz_core:error] [pid 167459:tid 167663] [client 192.178.4.134:60375] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:09.404295 2026] [authz_core:error] [pid 167459:tid 167663] [client 192.178.4.134:60375] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:09.404369 2026] [security2:error] [pid 167459:tid 167694] [client 20.104.100.201:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/domvf.php"] [unique_id "aoSDaWr_JutbFb-8svr4vgAAAfg"] [Tue Aug 18 13:08:09.418714 2026] [security2:error] [pid 167459:tid 167600] [client 20.104.100.201:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/red.php"] [unique_id "aoSDaWr_JutbFb-8svr4vwAAAZo"] [Tue Aug 18 13:08:09.427082 2026] [security2:error] [pid 167459:tid 167509] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDaWr_JutbFb-8svr4wQABqDE"] [Tue Aug 18 13:08:09.453416 2026] [security2:error] [pid 167459:tid 167617] [client 132.196.30.78:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/a7.php"] [unique_id "aoSDaWr_JutbFb-8svr4wwAAAas"] [Tue Aug 18 13:08:09.470880 2026] [security2:error] [pid 167459:tid 167707] [client 4.232.151.198:16566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ms-themes.php"] [unique_id "aoSDaWr_JutbFb-8svr4xAAAAgU"] [Tue Aug 18 13:08:09.486134 2026] [security2:error] [pid 167459:tid 167659] [client 52.139.47.57:31980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/mm.php"] [unique_id "aoSDaWr_JutbFb-8svr4xQAAAdU"] [Tue Aug 18 13:08:09.493740 2026] [security2:error] [pid 167459:tid 167630] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDaWr_JutbFb-8svr4xgAAAbg"] [Tue Aug 18 13:08:09.495310 2026] [security2:error] [pid 167459:tid 167713] [client 74.249.206.207:8487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDaWr_JutbFb-8svr4xwAAAgs"] [Tue Aug 18 13:08:09.511830 2026] [security2:error] [pid 167459:tid 167631] [client 20.106.102.5:45299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ty.php"] [unique_id "aoSDaWr_JutbFb-8svr4yAAAAbk"] [Tue Aug 18 13:08:09.524641 2026] [security2:error] [pid 167459:tid 167618] [client 20.163.43.14:15266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/zxz.php"] [unique_id "aoSDaWr_JutbFb-8svr4ygAAAaw"] [Tue Aug 18 13:08:09.535630 2026] [security2:error] [pid 167459:tid 167639] [client 102.213.179.104:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaWr_JutbFb-8svr4ywAAAcE"] [Tue Aug 18 13:08:09.535794 2026] [security2:error] [pid 167459:tid 167639] [client 102.213.179.104:57385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDaWr_JutbFb-8svr4ywAAAcE"] [Tue Aug 18 13:08:09.542283 2026] [security2:error] [pid 167459:tid 167699] [client 20.127.136.245:12998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDaWr_JutbFb-8svr4zAAAAf0"] [Tue Aug 18 13:08:09.545610 2026] [security2:error] [pid 167459:tid 167517] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/als.php"] [unique_id "aoSDaWr_JutbFb-8svr4zQABnTk"] [Tue Aug 18 13:08:09.555584 2026] [security2:error] [pid 167459:tid 167608] [client 172.202.39.151:2001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/0x.php"] [unique_id "aoSDaWr_JutbFb-8svr4zwAAAaI"] [Tue Aug 18 13:08:09.591870 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:09.592194 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:09.611461 2026] [security2:error] [pid 167459:tid 167464] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSDaWr_JutbFb-8svr40gABwgQ"] [Tue Aug 18 13:08:09.617139 2026] [security2:error] [pid 167459:tid 167654] [client 40.74.65.169:21321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDaWr_JutbFb-8svr40wAAAdA"] [Tue Aug 18 13:08:09.724256 2026] [security2:error] [pid 167459:tid 167601] [client 20.79.204.6:5977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/ultra.php"] [unique_id "aoSDaWr_JutbFb-8svr5DAAAAZs"] [Tue Aug 18 13:08:09.738240 2026] [security2:error] [pid 167459:tid 167655] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/tes.php"] [unique_id "aoSDaWr_JutbFb-8svr5DQAAAdE"] [Tue Aug 18 13:08:09.743218 2026] [security2:error] [pid 167459:tid 167593] [client 213.35.127.232:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDaWr_JutbFb-8svr5DgAAAZM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:09.748772 2026] [security2:error] [pid 167459:tid 167678] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/f35.php"] [unique_id "aoSDaWr_JutbFb-8svr5DwAAAeg"] [Tue Aug 18 13:08:09.758063 2026] [security2:error] [pid 167459:tid 167613] [client 74.248.18.37:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-admin/maint/maint/flower.php"] [unique_id "aoSDaWr_JutbFb-8svr5EAAAAac"] [Tue Aug 18 13:08:09.836493 2026] [security2:error] [pid 167459:tid 167475] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/nox.php"] [unique_id "aoSDaWr_JutbFb-8svr5FAACBw8"] [Tue Aug 18 13:08:09.837617 2026] [security2:error] [pid 167459:tid 167625] [client 20.106.102.5:45198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/vgtyu.php"] [unique_id "aoSDaWr_JutbFb-8svr5FQAAAbM"] [Tue Aug 18 13:08:09.846353 2026] [security2:error] [pid 167459:tid 167662] [client 20.215.241.237:18069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/ops.php"] [unique_id "aoSDaWr_JutbFb-8svr5FgAAAdg"] [Tue Aug 18 13:08:09.851002 2026] [security2:error] [pid 167459:tid 167673] [client 85.208.96.198:54782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bergoninf.com"] [uri "/sitemap.xml"] [unique_id "aoSDaWr_JutbFb-8svr5FwAAAeM"] [Tue Aug 18 13:08:09.851094 2026] [security2:error] [pid 167459:tid 167673] [client 85.208.96.198:54782] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bergoninf.com"] [uri "/sitemap.xml"] [unique_id "aoSDaWr_JutbFb-8svr5FwAAAeM"] [Tue Aug 18 13:08:09.856186 2026] [security2:error] [pid 167459:tid 167693] [client 20.163.43.14:15711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/www.php"] [unique_id "aoSDaWr_JutbFb-8svr5GAAAAfc"] [Tue Aug 18 13:08:09.889014 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:53277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSDaWr_JutbFb-8svr5HAAAAZU"] [Tue Aug 18 13:08:09.931773 2026] [security2:error] [pid 167459:tid 167692] [client 158.158.74.177:13771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSDaWr_JutbFb-8svr5HgAAAfY"] [Tue Aug 18 13:08:09.963556 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:27468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/network.php"] [unique_id "aoSDaWr_JutbFb-8svr5HwAAAe0"] [Tue Aug 18 13:08:09.986044 2026] [security2:error] [pid 167459:tid 167490] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDaWr_JutbFb-8svr5IQABth4"] [Tue Aug 18 13:08:10.002816 2026] [security2:error] [pid 167459:tid 167712] [client 74.249.206.207:15325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDamr_JutbFb-8svr5JAAAAgo"] [Tue Aug 18 13:08:10.035366 2026] [security2:error] [pid 167459:tid 167653] [client 20.25.139.174:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/adminfuns.php"] [unique_id "aoSDamr_JutbFb-8svr5JgAAAc8"] [Tue Aug 18 13:08:10.043641 2026] [security2:error] [pid 167459:tid 167688] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/files/index.php"] [unique_id "aoSDamr_JutbFb-8svr5JwAAAfI"] [Tue Aug 18 13:08:10.051643 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:13901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/red.php"] [unique_id "aoSDamr_JutbFb-8svr5KAAAAcc"] [Tue Aug 18 13:08:10.063291 2026] [security2:error] [pid 167459:tid 167675] [client 20.127.136.245:1100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/buy.php"] [unique_id "aoSDamr_JutbFb-8svr5KQAAAeU"] [Tue Aug 18 13:08:10.126548 2026] [security2:error] [pid 167459:tid 167565] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file59.php"] [unique_id "aoSDamr_JutbFb-8svr5MQABzmk"] [Tue Aug 18 13:08:10.145270 2026] [security2:error] [pid 167459:tid 167614] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/inputs.php"] [unique_id "aoSDamr_JutbFb-8svr5MwAAAag"] [Tue Aug 18 13:08:10.153180 2026] [security2:error] [pid 167459:tid 167681] [client 172.202.39.151:39180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/zxz.php"] [unique_id "aoSDamr_JutbFb-8svr5NQAAAes"] [Tue Aug 18 13:08:10.162511 2026] [security2:error] [pid 167459:tid 167671] [client 20.106.102.5:45150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/mans.php"] [unique_id "aoSDamr_JutbFb-8svr5NwAAAeE"] [Tue Aug 18 13:08:10.187323 2026] [security2:error] [pid 167459:tid 167665] [client 20.163.43.14:15694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wicked.php"] [unique_id "aoSDamr_JutbFb-8svr5OwAAAds"] [Tue Aug 18 13:08:10.187687 2026] [security2:error] [pid 167459:tid 167619] [client 132.196.30.78:20318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/manager.php"] [unique_id "aoSDamr_JutbFb-8svr5PAAAAa0"] [Tue Aug 18 13:08:10.202181 2026] [security2:error] [pid 167459:tid 167603] [client 20.116.17.175:52605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/flox.php"] [unique_id "aoSDamr_JutbFb-8svr5PwAAAZ0"] [Tue Aug 18 13:08:10.237555 2026] [security2:error] [pid 167459:tid 167657] [client 4.232.151.198:30112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/my1.php"] [unique_id "aoSDamr_JutbFb-8svr5SAAAAdM"] [Tue Aug 18 13:08:10.254832 2026] [security2:error] [pid 167459:tid 167710] [client 158.23.17.4:20609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fg.php"] [unique_id "aoSDamr_JutbFb-8svr5TQAAAgg"] [Tue Aug 18 13:08:10.297033 2026] [security2:error] [pid 167459:tid 167621] [client 20.104.100.201:53339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSDamr_JutbFb-8svr5TwAAAa8"] [Tue Aug 18 13:08:10.298650 2026] [security2:error] [pid 167459:tid 167495] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDamr_JutbFb-8svr5UAABsSM"] [Tue Aug 18 13:08:10.359744 2026] [security2:error] [pid 167459:tid 167669] [client 4.232.151.198:42634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/edit.php"] [unique_id "aoSDamr_JutbFb-8svr5UgAAAd8"] [Tue Aug 18 13:08:10.365738 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:55395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5UwAAAZw"] [Tue Aug 18 13:08:10.365836 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:55395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5UwAAAZw"] [Tue Aug 18 13:08:10.368801 2026] [security2:error] [pid 167459:tid 167679] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDamr_JutbFb-8svr5VAAAAek"] [Tue Aug 18 13:08:10.380538 2026] [security2:error] [pid 167459:tid 167658] [client 74.248.18.37:39360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/about.php"] [unique_id "aoSDamr_JutbFb-8svr5VwAAAdQ"] [Tue Aug 18 13:08:10.384101 2026] [security2:error] [pid 167459:tid 167608] [client 52.139.47.57:31957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/new.php"] [unique_id "aoSDamr_JutbFb-8svr5WgAAAaI"] [Tue Aug 18 13:08:10.411228 2026] [security2:error] [pid 167459:tid 167659] [client 20.79.204.6:5753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/un.php"] [unique_id "aoSDamr_JutbFb-8svr5XgAAAdU"] [Tue Aug 18 13:08:10.417241 2026] [security2:error] [pid 167459:tid 167541] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/admin.php"] [unique_id "aoSDamr_JutbFb-8svr5XwABl1E"] [Tue Aug 18 13:08:10.437988 2026] [security2:error] [pid 167459:tid 167625] [client 20.206.73.37:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/php.php"] [unique_id "aoSDamr_JutbFb-8svr5YwAAAbM"] [Tue Aug 18 13:08:10.451483 2026] [security2:error] [pid 167459:tid 167532] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDamr_JutbFb-8svr5ZAAB90g"] [Tue Aug 18 13:08:10.489978 2026] [security2:error] [pid 167459:tid 167686] [client 20.106.102.5:45291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/co.php"] [unique_id "aoSDamr_JutbFb-8svr5ZgAAAfA"] [Tue Aug 18 13:08:10.491955 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:10.492224 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:10.514310 2026] [security2:error] [pid 167459:tid 167687] [client 20.163.43.14:15722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSDamr_JutbFb-8svr5ZwAAAfE"] [Tue Aug 18 13:08:10.545858 2026] [security2:error] [pid 167459:tid 167633] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/alfa.php"] [unique_id "aoSDamr_JutbFb-8svr5agAAAbs"] [Tue Aug 18 13:08:10.560598 2026] [security2:error] [pid 167459:tid 167613] [client 20.25.139.174:4862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/404.php"] [unique_id "aoSDamr_JutbFb-8svr5awAAAac"] [Tue Aug 18 13:08:10.564364 2026] [security2:error] [pid 167459:tid 167704] [client 158.158.74.177:13777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/goat.php"] [unique_id "aoSDamr_JutbFb-8svr5bAAAAgI"] [Tue Aug 18 13:08:10.582623 2026] [security2:error] [pid 167459:tid 167612] [client 74.248.18.37:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/module.audio-video.matroska-meta.php"] [unique_id "aoSDamr_JutbFb-8svr5bQAAAaY"] [Tue Aug 18 13:08:10.605553 2026] [security2:error] [pid 167459:tid 167634] [client 20.127.136.245:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/dropdown.php"] [unique_id "aoSDamr_JutbFb-8svr5bgAAAbw"] [Tue Aug 18 13:08:10.617978 2026] [security2:error] [pid 167459:tid 167596] [client 86.120.159.145:23753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5cAAAAZY"] [Tue Aug 18 13:08:10.618303 2026] [security2:error] [pid 167459:tid 167596] [client 86.120.159.145:23753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5cAAAAZY"] [Tue Aug 18 13:08:10.622611 2026] [security2:error] [pid 167459:tid 167627] [client 5.31.227.224:29902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5cQAAAbU"] [Tue Aug 18 13:08:10.627571 2026] [security2:error] [pid 167459:tid 167627] [client 5.31.227.224:29902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDamr_JutbFb-8svr5cQAAAbU"] [Tue Aug 18 13:08:10.633264 2026] [security2:error] [pid 167459:tid 167482] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSDamr_JutbFb-8svr5cgAB7xY"] [Tue Aug 18 13:08:10.661047 2026] [security2:error] [pid 167459:tid 167609] [client 20.226.36.136:37195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDamr_JutbFb-8svr5cwAAAaM"] [Tue Aug 18 13:08:10.667502 2026] [security2:error] [pid 167459:tid 167645] [client 20.215.241.237:25859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/coffexium.php"] [unique_id "aoSDamr_JutbFb-8svr5dAAAAcc"] [Tue Aug 18 13:08:10.684287 2026] [security2:error] [pid 167459:tid 167675] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/images/images/about.php"] [unique_id "aoSDamr_JutbFb-8svr5dQAAAeU"] [Tue Aug 18 13:08:10.706913 2026] [security2:error] [pid 167459:tid 167533] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/aa2.php"] [unique_id "aoSDamr_JutbFb-8svr5dwABzUk"] [Tue Aug 18 13:08:10.743281 2026] [security2:error] [pid 167459:tid 167600] [client 40.74.65.169:37391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDamr_JutbFb-8svr5eAAAAZo"] [Tue Aug 18 13:08:10.752835 2026] [security2:error] [pid 167459:tid 167614] [client 20.151.109.219:20733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fa.php"] [unique_id "aoSDamr_JutbFb-8svr5eQAAAag"] [Tue Aug 18 13:08:10.762050 2026] [security2:error] [pid 167459:tid 167617] [client 20.104.100.201:9540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDamr_JutbFb-8svr5egAAAas"] [Tue Aug 18 13:08:10.762598 2026] [security2:error] [pid 167459:tid 167632] [client 213.35.127.232:59629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDamr_JutbFb-8svr5ewAAAbo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:10.791356 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:10.791622 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:10.801263 2026] [security2:error] [pid 167459:tid 167714] [client 52.139.47.57:24000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/0x.php"] [unique_id "aoSDamr_JutbFb-8svr5fgAAAgw"] [Tue Aug 18 13:08:10.801878 2026] [security2:error] [pid 167459:tid 167594] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/lock360.php"] [unique_id "aoSDamr_JutbFb-8svr5fwAAAZQ"] [Tue Aug 18 13:08:10.814270 2026] [security2:error] [pid 167459:tid 167548] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSDamr_JutbFb-8svr5gQAB21g"] [Tue Aug 18 13:08:10.816096 2026] [security2:error] [pid 167459:tid 167619] [client 20.106.102.5:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/btx25.php"] [unique_id "aoSDamr_JutbFb-8svr5ggAAAa0"] [Tue Aug 18 13:08:10.820873 2026] [autoindex:error] [pid 167459:tid 167618] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:10.842700 2026] [security2:error] [pid 167459:tid 167590] [client 132.196.30.78:20336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/w1.php"] [unique_id "aoSDamr_JutbFb-8svr5gwAAAZA"] [Tue Aug 18 13:08:10.859223 2026] [security2:error] [pid 167459:tid 167668] [client 20.163.43.14:15709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDamr_JutbFb-8svr5hAAAAd4"] [Tue Aug 18 13:08:10.864787 2026] [security2:error] [pid 167459:tid 167708] [client 4.232.151.198:48488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/new.php"] [unique_id "aoSDamr_JutbFb-8svr5hQAAAgY"] [Tue Aug 18 13:08:10.933584 2026] [security2:error] [pid 167459:tid 167587] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDamr_JutbFb-8svr5hgABmX8"] [Tue Aug 18 13:08:10.999083 2026] [security2:error] [pid 167459:tid 167656] [client 172.182.217.32:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/load.php"] [unique_id "aoSDamr_JutbFb-8svr5hwAAAdI"] [Tue Aug 18 13:08:11.007193 2026] [security2:error] [pid 167459:tid 167502] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/xamp.php"] [unique_id "aoSDa2r_JutbFb-8svr5iAAB3yo"] [Tue Aug 18 13:08:11.009337 2026] [security2:error] [pid 167459:tid 167602] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/ms-edit.php"] [unique_id "aoSDa2r_JutbFb-8svr5iQAAAZw"] [Tue Aug 18 13:08:11.038599 2026] [security2:error] [pid 167459:tid 167514] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSDa2r_JutbFb-8svr5igABoTY"] [Tue Aug 18 13:08:11.040106 2026] [security2:error] [pid 167459:tid 167610] [client 172.202.39.151:39213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/www.php"] [unique_id "aoSDa2r_JutbFb-8svr5iwAAAaQ"] [Tue Aug 18 13:08:11.066123 2026] [security2:error] [pid 167459:tid 167655] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/flower.php"] [unique_id "aoSDa2r_JutbFb-8svr5jAAAAdE"] [Tue Aug 18 13:08:11.091083 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:11.091379 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:11.096172 2026] [security2:error] [pid 167459:tid 167648] [client 20.25.139.174:4805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wk/index.php"] [unique_id "aoSDa2r_JutbFb-8svr5jgAAAco"] [Tue Aug 18 13:08:11.098905 2026] [security2:error] [pid 167459:tid 167710] [client 20.79.204.6:5964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/up.php"] [unique_id "aoSDa2r_JutbFb-8svr5jwAAAgg"] [Tue Aug 18 13:08:11.134995 2026] [security2:error] [pid 167459:tid 167635] [client 223.185.37.47:18373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDa2r_JutbFb-8svr5kQAAAb0"] [Tue Aug 18 13:08:11.135082 2026] [security2:error] [pid 167459:tid 167635] [client 223.185.37.47:18373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDa2r_JutbFb-8svr5kQAAAb0"] [Tue Aug 18 13:08:11.138922 2026] [security2:error] [pid 167459:tid 167597] [client 20.106.102.5:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/avim.php"] [unique_id "aoSDa2r_JutbFb-8svr5kgAAAZc"] [Tue Aug 18 13:08:11.140763 2026] [security2:error] [pid 167459:tid 167615] [client 20.127.136.245:22361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/inputs.php"] [unique_id "aoSDa2r_JutbFb-8svr5kwAAAak"] [Tue Aug 18 13:08:11.154210 2026] [security2:error] [pid 167459:tid 167672] [client 20.215.241.237:21876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/BDKR28WP.php"] [unique_id "aoSDa2r_JutbFb-8svr5lAAAAeI"] [Tue Aug 18 13:08:11.170920 2026] [autoindex:error] [pid 167459:tid 167678] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:11.187652 2026] [security2:error] [pid 167459:tid 167703] [client 168.119.53.160:51820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pan.com.br"] [uri "/server.php"] [unique_id "aoSDZ2r_JutbFb-8svr4HwAAAgE"], referer: https://pan.com.br/?lang=pt-br [Tue Aug 18 13:08:11.194002 2026] [security2:error] [pid 167459:tid 167631] [client 158.158.74.177:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/Session.php"] [unique_id "aoSDa2r_JutbFb-8svr5lwAAAbk"] [Tue Aug 18 13:08:11.239164 2026] [security2:error] [pid 167459:tid 167692] [client 52.173.121.69:36589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDa2r_JutbFb-8svr5nAAAAfY"] [Tue Aug 18 13:08:11.245093 2026] [security2:error] [pid 167459:tid 167683] [client 20.163.43.14:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/cah.php"] [unique_id "aoSDa2r_JutbFb-8svr5nQAAAe0"] [Tue Aug 18 13:08:11.247031 2026] [security2:error] [pid 167459:tid 167534] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/includes/colour.php"] [unique_id "aoSDa2r_JutbFb-8svr5ngABp0o"] [Tue Aug 18 13:08:11.266086 2026] [security2:error] [pid 167459:tid 167626] [client 52.139.47.57:36044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/0.php"] [unique_id "aoSDa2r_JutbFb-8svr5nwAAAbQ"] [Tue Aug 18 13:08:11.304233 2026] [authz_core:error] [pid 167459:tid 167517] [remote 57.141.22.52:64818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:11.304499 2026] [authz_core:error] [pid 167459:tid 167517] [remote 57.141.22.52:64818] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:11.305941 2026] [security2:error] [pid 167459:tid 167464] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/bless.php"] [unique_id "aoSDa2r_JutbFb-8svr5ogABtQQ"] [Tue Aug 18 13:08:11.313507 2026] [security2:error] [pid 167459:tid 167705] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/rip.php"] [unique_id "aoSDa2r_JutbFb-8svr5owAAAgM"] [Tue Aug 18 13:08:11.313525 2026] [security2:error] [pid 167459:tid 167674] [client 20.104.100.201:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/JawirGenk.php"] [unique_id "aoSDa2r_JutbFb-8svr5pAAAAeQ"] [Tue Aug 18 13:08:11.328372 2026] [security2:error] [pid 167459:tid 167605] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/13.php"] [unique_id "aoSDa2r_JutbFb-8svr5pQAAAZ8"] [Tue Aug 18 13:08:11.362678 2026] [security2:error] [pid 167459:tid 167696] [client 74.248.18.37:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/assets/autoload_classmap.php"] [unique_id "aoSDa2r_JutbFb-8svr5pgAAAfo"] [Tue Aug 18 13:08:11.376008 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:39584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ve.php"] [unique_id "aoSDa2r_JutbFb-8svr5pwAAAcc"] [Tue Aug 18 13:08:11.393395 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:11.393658 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:11.398619 2026] [security2:error] [pid 167459:tid 167651] [client 20.104.100.201:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDa2r_JutbFb-8svr5qQAAAc0"] [Tue Aug 18 13:08:11.404395 2026] [security2:error] [pid 167459:tid 167695] [client 20.250.13.23:23195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDa2r_JutbFb-8svr5qgAAAfk"] [Tue Aug 18 13:08:11.410840 2026] [security2:error] [pid 167459:tid 167471] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDa2r_JutbFb-8svr5qwABqAs"] [Tue Aug 18 13:08:11.462851 2026] [security2:error] [pid 167459:tid 167594] [client 20.106.102.5:45125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/myfile.php"] [unique_id "aoSDa2r_JutbFb-8svr5rgAAAZQ"] [Tue Aug 18 13:08:11.464528 2026] [autoindex:error] [pid 167459:tid 167671] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:11.499251 2026] [security2:error] [pid 167459:tid 167592] [client 4.232.151.198:16439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/norn.php"] [unique_id "aoSDa2r_JutbFb-8svr5sQAAAZI"] [Tue Aug 18 13:08:11.558343 2026] [security2:error] [pid 167459:tid 167497] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/includes/xmrlpc.php"] [unique_id "aoSDa2r_JutbFb-8svr5sgABtyU"] [Tue Aug 18 13:08:11.562909 2026] [security2:error] [pid 167459:tid 167664] [client 172.182.217.32:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/login.php"] [unique_id "aoSDa2r_JutbFb-8svr5swAAAdo"] [Tue Aug 18 13:08:11.576995 2026] [security2:error] [pid 167459:tid 167599] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/cc.php"] [unique_id "aoSDa2r_JutbFb-8svr5twAAAZk"] [Tue Aug 18 13:08:11.584437 2026] [security2:error] [pid 167459:tid 167681] [client 20.25.139.174:4813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/about.php"] [unique_id "aoSDa2r_JutbFb-8svr5uAAAAes"] [Tue Aug 18 13:08:11.592865 2026] [security2:error] [pid 167459:tid 167555] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDa2r_JutbFb-8svr5ugABr18"] [Tue Aug 18 13:08:11.596236 2026] [security2:error] [pid 167459:tid 167543] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file25.php"] [unique_id "aoSDa2r_JutbFb-8svr5uwABsVM"] [Tue Aug 18 13:08:11.602535 2026] [security2:error] [pid 167459:tid 167611] [client 40.74.65.169:36973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDa2r_JutbFb-8svr5vAAAAaU"] [Tue Aug 18 13:08:11.687641 2026] [security2:error] [pid 167459:tid 167593] [client 74.249.206.207:15924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDa2r_JutbFb-8svr5wAAAAZM"] [Tue Aug 18 13:08:11.691341 2026] [security2:error] [pid 167459:tid 167708] [client 52.139.47.57:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/oxshell.php"] [unique_id "aoSDa2r_JutbFb-8svr5wgAAAgY"] [Tue Aug 18 13:08:11.724923 2026] [autoindex:error] [pid 167459:tid 167608] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:11.740932 2026] [security2:error] [pid 167459:tid 167666] [client 20.163.43.14:15635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/system_log.php"] [unique_id "aoSDa2r_JutbFb-8svr5xgAAAdw"] [Tue Aug 18 13:08:11.744352 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.100.201:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/options.php"] [unique_id "aoSDa2r_JutbFb-8svr5xwAAAfw"] [Tue Aug 18 13:08:11.772112 2026] [security2:error] [pid 167459:tid 167615] [client 132.196.30.78:20337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-login.php"] [unique_id "aoSDa2r_JutbFb-8svr5yAAAAak"] [Tue Aug 18 13:08:11.774984 2026] [security2:error] [pid 167459:tid 167630] [client 213.35.127.232:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDa2r_JutbFb-8svr5yQAAAbg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:11.779529 2026] [security2:error] [pid 167459:tid 167486] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDa2r_JutbFb-8svr5ygAByBo"] [Tue Aug 18 13:08:11.789742 2026] [security2:error] [pid 167459:tid 167672] [client 20.106.102.5:45259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xmy.php"] [unique_id "aoSDa2r_JutbFb-8svr5ywAAAeI"] [Tue Aug 18 13:08:11.815301 2026] [security2:error] [pid 167459:tid 167662] [client 114.119.152.167:29557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vavaturismo.com.br"] [uri "/site/conteudo/imagens/noticias/09-04-2014-23-03-29.jpg"] [unique_id "aoSDa2r_JutbFb-8svr50QAAAdg"], referer: http://www.vavaturismo.com.br/site/conteudo/imagens/noticias/09-04-2014-23-03-29.jpg [Tue Aug 18 13:08:11.823791 2026] [security2:error] [pid 167459:tid 167602] [client 158.158.74.177:13720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSDa2r_JutbFb-8svr50wAAAZw"] [Tue Aug 18 13:08:11.824810 2026] [security2:error] [pid 167459:tid 167701] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDa2r_JutbFb-8svr51AAAAf8"] [Tue Aug 18 13:08:11.827590 2026] [security2:error] [pid 167459:tid 167687] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/xmlrpc.php"] [unique_id "aoSDa2r_JutbFb-8svr51QAAAfE"] [Tue Aug 18 13:08:11.845174 2026] [security2:error] [pid 167459:tid 167595] [client 20.215.241.237:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/sf.php"] [unique_id "aoSDa2r_JutbFb-8svr51gAAAZU"] [Tue Aug 18 13:08:11.871193 2026] [security2:error] [pid 167459:tid 167518] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDa2r_JutbFb-8svr52AAB9jo"] [Tue Aug 18 13:08:11.874202 2026] [security2:error] [pid 167459:tid 167683] [client 20.127.136.245:9270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/100.php"] [unique_id "aoSDa2r_JutbFb-8svr52QAAAe0"] [Tue Aug 18 13:08:11.886859 2026] [security2:error] [pid 167459:tid 167550] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file15.php"] [unique_id "aoSDa2r_JutbFb-8svr52gAB9Vo"] [Tue Aug 18 13:08:11.933878 2026] [security2:error] [pid 167459:tid 167596] [client 172.202.39.151:27850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wicked.php"] [unique_id "aoSDa2r_JutbFb-8svr52wAAAZY"] [Tue Aug 18 13:08:11.997197 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:11.997455 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:12.008006 2026] [autoindex:error] [pid 167459:tid 167696] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:12.025185 2026] [security2:error] [pid 167459:tid 167716] [client 20.79.204.6:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/users.php"] [unique_id "aoSDbGr_JutbFb-8svr54AAAAg4"] [Tue Aug 18 13:08:12.058053 2026] [security2:error] [pid 167459:tid 167704] [client 172.182.217.32:4117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/min.php"] [unique_id "aoSDbGr_JutbFb-8svr56QAAAgI"] [Tue Aug 18 13:08:12.069315 2026] [security2:error] [pid 167459:tid 167694] [client 158.23.17.4:7322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ia.php"] [unique_id "aoSDbGr_JutbFb-8svr56gAAAfg"] [Tue Aug 18 13:08:12.075000 2026] [security2:error] [pid 167459:tid 167641] [client 20.206.73.37:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/sf.php"] [unique_id "aoSDbGr_JutbFb-8svr57AAAAcM"] [Tue Aug 18 13:08:12.077405 2026] [security2:error] [pid 167459:tid 167626] [client 20.25.139.174:4846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/term.php"] [unique_id "aoSDbGr_JutbFb-8svr57QAAAbQ"] [Tue Aug 18 13:08:12.080305 2026] [security2:error] [pid 167459:tid 167707] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content.php.php"] [unique_id "aoSDbGr_JutbFb-8svr57gAAAgU"] [Tue Aug 18 13:08:12.100964 2026] [security2:error] [pid 167459:tid 167625] [client 74.248.18.37:14916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/term.php"] [unique_id "aoSDbGr_JutbFb-8svr59gAAAbM"] [Tue Aug 18 13:08:12.111867 2026] [security2:error] [pid 167459:tid 167594] [client 20.151.109.219:36735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/fb.php"] [unique_id "aoSDbGr_JutbFb-8svr59wAAAZQ"] [Tue Aug 18 13:08:12.112069 2026] [security2:error] [pid 167459:tid 167705] [client 52.139.47.57:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/php8.php"] [unique_id "aoSDbGr_JutbFb-8svr5-AAAAgM"] [Tue Aug 18 13:08:12.115208 2026] [security2:error] [pid 167459:tid 167633] [client 3.219.81.66:47288] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "jthaveiculos.com.br"] [uri "/"] [unique_id "aoSDbGr_JutbFb-8svr5-QAAAbs"] [Tue Aug 18 13:08:12.116093 2026] [security2:error] [pid 167459:tid 167619] [client 20.106.102.5:45237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xda.php"] [unique_id "aoSDbGr_JutbFb-8svr5-gAAAa0"] [Tue Aug 18 13:08:12.116744 2026] [security2:error] [pid 167459:tid 167622] [client 74.248.18.37:35392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ncx.php"] [unique_id "aoSDbGr_JutbFb-8svr5-wAAAbA"] [Tue Aug 18 13:08:12.143450 2026] [security2:error] [pid 167459:tid 167634] [client 4.232.151.198:30123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/num.php"] [unique_id "aoSDbGr_JutbFb-8svr5_AAAAbw"] [Tue Aug 18 13:08:12.149493 2026] [security2:error] [pid 167459:tid 167603] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/moon.php"] [unique_id "aoSDbGr_JutbFb-8svr5_QAAAZ0"] [Tue Aug 18 13:08:12.180071 2026] [security2:error] [pid 167459:tid 167544] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/f35.php"] [unique_id "aoSDbGr_JutbFb-8svr5_wABkFQ"] [Tue Aug 18 13:08:12.199402 2026] [autoindex:error] [pid 167459:tid 167629] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:12.239441 2026] [security2:error] [pid 167459:tid 167621] [client 20.163.43.14:15620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDbGr_JutbFb-8svr6BQAAAa8"] [Tue Aug 18 13:08:12.281836 2026] [security2:error] [pid 167459:tid 167685] [client 158.23.17.4:7168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDbGr_JutbFb-8svr6CAAAAe8"] [Tue Aug 18 13:08:12.297300 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:12.297584 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:12.327464 2026] [security2:error] [pid 167459:tid 167592] [client 132.196.30.78:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/default.php"] [unique_id "aoSDbGr_JutbFb-8svr6DgAAAZI"] [Tue Aug 18 13:08:12.334916 2026] [security2:error] [pid 167459:tid 167654] [client 20.215.241.237:47866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/k.php"] [unique_id "aoSDbGr_JutbFb-8svr6DwAAAdA"] [Tue Aug 18 13:08:12.338564 2026] [security2:error] [pid 167459:tid 167698] [client 20.226.36.136:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDbGr_JutbFb-8svr6EQAAAfw"] [Tue Aug 18 13:08:12.342316 2026] [security2:error] [pid 167459:tid 167635] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/01.php"] [unique_id "aoSDbGr_JutbFb-8svr6EgAAAb0"] [Tue Aug 18 13:08:12.363376 2026] [security2:error] [pid 167459:tid 167715] [client 20.116.17.175:52883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/op.php"] [unique_id "aoSDbGr_JutbFb-8svr6EwAAAg0"] [Tue Aug 18 13:08:12.426546 2026] [security2:error] [pid 167459:tid 167540] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDbGr_JutbFb-8svr6FQABnFA"] [Tue Aug 18 13:08:12.441432 2026] [security2:error] [pid 167459:tid 167687] [client 20.106.102.5:45699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/zz.php"] [unique_id "aoSDbGr_JutbFb-8svr6FwAAAfE"] [Tue Aug 18 13:08:12.452157 2026] [security2:error] [pid 167459:tid 167595] [client 40.74.65.169:36987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/222.php"] [unique_id "aoSDbGr_JutbFb-8svr6GQAAAZU"] [Tue Aug 18 13:08:12.458999 2026] [security2:error] [pid 167459:tid 167692] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/cache.php"] [unique_id "aoSDbGr_JutbFb-8svr6GwAAAfY"] [Tue Aug 18 13:08:12.461614 2026] [security2:error] [pid 167459:tid 167656] [client 158.158.74.177:13772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/abcd.php"] [unique_id "aoSDbGr_JutbFb-8svr6HAAAAdI"] [Tue Aug 18 13:08:12.470375 2026] [security2:error] [pid 167459:tid 167512] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-load.php"] [unique_id "aoSDbGr_JutbFb-8svr6HgABpzQ"] [Tue Aug 18 13:08:12.478878 2026] [autoindex:error] [pid 167459:tid 167659] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:12.485777 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/output.php"] [unique_id "aoSDbGr_JutbFb-8svr6IQAAAbU"] [Tue Aug 18 13:08:12.486839 2026] [security2:error] [pid 167459:tid 167673] [client 20.151.109.219:22913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gw.php"] [unique_id "aoSDbGr_JutbFb-8svr6IgAAAeM"] [Tue Aug 18 13:08:12.502619 2026] [security2:error] [pid 167459:tid 167559] [remote 20.205.121.237:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.121.205.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.1td.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDbGr_JutbFb-8svr6KQABo2M"] [Tue Aug 18 13:08:12.523015 2026] [security2:error] [pid 167459:tid 167682] [client 20.250.13.23:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/222.php"] [unique_id "aoSDbGr_JutbFb-8svr6LgAAAew"] [Tue Aug 18 13:08:12.540163 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/p.php"] [unique_id "aoSDbGr_JutbFb-8svr6MAAAAfA"] [Tue Aug 18 13:08:12.543568 2026] [security2:error] [pid 167459:tid 167672] [client 172.182.217.32:25575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/options.php"] [unique_id "aoSDbGr_JutbFb-8svr6MQAAAeI"] [Tue Aug 18 13:08:12.566026 2026] [security2:error] [pid 167459:tid 167606] [client 20.163.43.14:15675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDbGr_JutbFb-8svr6PAAAAaA"] [Tue Aug 18 13:08:12.603230 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:12.603683 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:12.604814 2026] [security2:error] [pid 167459:tid 167704] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/lv.php"] [unique_id "aoSDbGr_JutbFb-8svr6QAAAAgI"] [Tue Aug 18 13:08:12.607850 2026] [security2:error] [pid 167459:tid 167573] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSDbGr_JutbFb-8svr6QQAB-HE"] [Tue Aug 18 13:08:12.639255 2026] [security2:error] [pid 167459:tid 167700] [client 20.25.139.174:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ioxi-o.php"] [unique_id "aoSDbGr_JutbFb-8svr6QgAAAf4"] [Tue Aug 18 13:08:12.640781 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDbGr_JutbFb-8svr6QwAAAgU"] [Tue Aug 18 13:08:12.692484 2026] [autoindex:error] [pid 167459:tid 167594] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:12.717793 2026] [security2:error] [pid 167459:tid 167633] [client 20.127.136.245:12931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/akc.php"] [unique_id "aoSDbGr_JutbFb-8svr6RgAAAbs"] [Tue Aug 18 13:08:12.750161 2026] [security2:error] [pid 167459:tid 167645] [client 20.79.204.6:5715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/v.php"] [unique_id "aoSDbGr_JutbFb-8svr6SAAAAcc"] [Tue Aug 18 13:08:12.763612 2026] [security2:error] [pid 167459:tid 167586] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-includes/assets/"] [unique_id "aoSDbGr_JutbFb-8svr6SQABkH4"] [Tue Aug 18 13:08:12.777800 2026] [security2:error] [pid 167459:tid 167629] [client 20.106.102.5:45269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xa.php"] [unique_id "aoSDbGr_JutbFb-8svr6TQAAAbc"] [Tue Aug 18 13:08:12.786844 2026] [security2:error] [pid 167459:tid 167663] [client 213.35.127.232:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDbGr_JutbFb-8svr6UAAAAdk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:12.817996 2026] [security2:error] [pid 167459:tid 167604] [client 4.232.151.198:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/options-reading.php"] [unique_id "aoSDbGr_JutbFb-8svr6UwAAAZ4"] [Tue Aug 18 13:08:12.864292 2026] [security2:error] [pid 167459:tid 167638] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/new.php"] [unique_id "aoSDbGr_JutbFb-8svr6VAAAAcA"] [Tue Aug 18 13:08:12.898694 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:12.898958 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:12.940753 2026] [security2:error] [pid 167459:tid 167628] [client 20.215.241.237:22396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/82.php"] [unique_id "aoSDbGr_JutbFb-8svr6WQAAAbY"] [Tue Aug 18 13:08:12.954401 2026] [autoindex:error] [pid 167459:tid 167592] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:12.955228 2026] [security2:error] [pid 167459:tid 167669] [client 52.139.47.57:24509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/php.php"] [unique_id "aoSDbGr_JutbFb-8svr6XAAAAd8"] [Tue Aug 18 13:08:12.957906 2026] [security2:error] [pid 167459:tid 167666] [client 20.163.43.14:15623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/abc.php"] [unique_id "aoSDbGr_JutbFb-8svr6XQAAAdw"] [Tue Aug 18 13:08:12.986678 2026] [authz_core:error] [pid 167459:tid 167601] [client 192.178.4.135:60985] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:12.986965 2026] [authz_core:error] [pid 167459:tid 167601] [client 192.178.4.135:60985] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:12.995915 2026] [security2:error] [pid 167459:tid 167585] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDbGr_JutbFb-8svr6YAAB2H0"] [Tue Aug 18 13:08:13.031915 2026] [security2:error] [pid 167459:tid 167684] [client 4.232.151.198:12105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/elp.php"] [unique_id "aoSDbWr_JutbFb-8svr6YQAAAe4"] [Tue Aug 18 13:08:13.040451 2026] [security2:error] [pid 167459:tid 167621] [client 74.248.18.37:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/plugins/autoload_classmap.php"] [unique_id "aoSDbWr_JutbFb-8svr6YgAAAa8"] [Tue Aug 18 13:08:13.054267 2026] [security2:error] [pid 167459:tid 167495] [remote 40.74.65.169:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "aoSDbWr_JutbFb-8svr6ZQAB8SM"] [Tue Aug 18 13:08:13.060605 2026] [security2:error] [pid 167459:tid 167593] [client 172.182.217.32:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/plugin-install.php"] [unique_id "aoSDbWr_JutbFb-8svr6ZgAAAZM"] [Tue Aug 18 13:08:13.082278 2026] [security2:error] [pid 167459:tid 167661] [client 20.206.73.37:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/xx.php"] [unique_id "aoSDbWr_JutbFb-8svr6ZwAAAdc"] [Tue Aug 18 13:08:13.085010 2026] [security2:error] [pid 167459:tid 167595] [client 52.173.121.69:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDbWr_JutbFb-8svr6aQAAAZU"] [Tue Aug 18 13:08:13.085041 2026] [security2:error] [pid 167459:tid 167690] [client 132.196.30.78:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/i.php"] [unique_id "aoSDbWr_JutbFb-8svr6aAAAAfQ"] [Tue Aug 18 13:08:13.102265 2026] [security2:error] [pid 167459:tid 167613] [client 20.106.102.5:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/f6.php"] [unique_id "aoSDbWr_JutbFb-8svr6agAAAac"] [Tue Aug 18 13:08:13.113458 2026] [security2:error] [pid 167459:tid 167691] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/222.php"] [unique_id "aoSDbWr_JutbFb-8svr6bAAAAfU"] [Tue Aug 18 13:08:13.113493 2026] [security2:error] [pid 167459:tid 167709] [client 158.23.17.4:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDbWr_JutbFb-8svr6awAAAgc"] [Tue Aug 18 13:08:13.122302 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kn.php"] [unique_id "aoSDbWr_JutbFb-8svr6bQAAAfs"] [Tue Aug 18 13:08:13.138902 2026] [security2:error] [pid 167459:tid 167658] [client 158.158.74.177:13821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/kj.php"] [unique_id "aoSDbWr_JutbFb-8svr6bwAAAdQ"] [Tue Aug 18 13:08:13.142217 2026] [security2:error] [pid 167459:tid 167597] [client 20.25.139.174:4496] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/1.php"] [unique_id "aoSDbWr_JutbFb-8svr6cQAAAZc"] [Tue Aug 18 13:08:13.142305 2026] [security2:error] [pid 167459:tid 167597] [client 20.25.139.174:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/1.php"] [unique_id "aoSDbWr_JutbFb-8svr6cQAAAZc"] [Tue Aug 18 13:08:13.176264 2026] [security2:error] [pid 167459:tid 167472] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6cgABzww"] [Tue Aug 18 13:08:13.182410 2026] [security2:error] [pid 167459:tid 167696] [client 40.74.65.169:7103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6cwAAAfo"] [Tue Aug 18 13:08:13.227299 2026] [core:notice] [pid 167459:tid 167524] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:08:13.234653 2026] [security2:error] [pid 167459:tid 167702] [client 172.202.39.151:27860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSDbWr_JutbFb-8svr6eAAAAgA"] [Tue Aug 18 13:08:13.243605 2026] [autoindex:error] [pid 167459:tid 167651] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:13.303833 2026] [security2:error] [pid 167459:tid 167626] [client 20.104.100.201:9537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/tiny2.php"] [unique_id "aoSDbWr_JutbFb-8svr6fAAAAbQ"] [Tue Aug 18 13:08:13.314487 2026] [security2:error] [pid 167459:tid 167670] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDbWr_JutbFb-8svr6fQAAAeA"] [Tue Aug 18 13:08:13.336680 2026] [security2:error] [pid 167459:tid 167671] [client 20.163.43.14:15640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/akcc.php"] [unique_id "aoSDbWr_JutbFb-8svr6gAAAAeE"] [Tue Aug 18 13:08:13.351389 2026] [security2:error] [pid 167459:tid 167532] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSDbWr_JutbFb-8svr6gQABkUg"] [Tue Aug 18 13:08:13.362579 2026] [security2:error] [pid 167459:tid 167716] [client 52.139.47.57:25739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/past.php"] [unique_id "aoSDbWr_JutbFb-8svr6hAAAAg4"] [Tue Aug 18 13:08:13.369369 2026] [security2:error] [pid 167459:tid 167618] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/chosen.php"] [unique_id "aoSDbWr_JutbFb-8svr6hQAAAaw"] [Tue Aug 18 13:08:13.414316 2026] [security2:error] [pid 167459:tid 167686] [client 20.79.204.6:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/v5.php"] [unique_id "aoSDbWr_JutbFb-8svr6hwAAAfA"] [Tue Aug 18 13:08:13.428889 2026] [security2:error] [pid 167459:tid 167640] [client 20.106.102.5:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/mcs.php"] [unique_id "aoSDbWr_JutbFb-8svr6iAAAAcI"] [Tue Aug 18 13:08:13.469391 2026] [security2:error] [pid 167459:tid 167530] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDbWr_JutbFb-8svr6igABmUY"] [Tue Aug 18 13:08:13.469655 2026] [security2:error] [pid 167459:tid 167599] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDbWr_JutbFb-8svr6igABmUY"] [Tue Aug 18 13:08:13.470305 2026] [security2:error] [pid 167459:tid 167663] [client 20.151.109.219:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/sw.php"] [unique_id "aoSDbWr_JutbFb-8svr6iwAAAdk"] [Tue Aug 18 13:08:13.511879 2026] [authz_core:error] [pid 167459:tid 167488] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:13.512154 2026] [authz_core:error] [pid 167459:tid 167488] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:13.518933 2026] [security2:error] [pid 167459:tid 167614] [client 4.232.151.198:16410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ors32envu.php"] [unique_id "aoSDbWr_JutbFb-8svr6kAAAAag"] [Tue Aug 18 13:08:13.530906 2026] [autoindex:error] [pid 167459:tid 167638] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:13.537248 2026] [security2:error] [pid 167459:tid 167648] [client 20.127.136.245:5553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSDbWr_JutbFb-8svr6kgAAAco"] [Tue Aug 18 13:08:13.548566 2026] [security2:error] [pid 167459:tid 167645] [client 172.182.217.32:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/radio.php"] [unique_id "aoSDbWr_JutbFb-8svr6kwAAAcc"] [Tue Aug 18 13:08:13.576767 2026] [security2:error] [pid 167459:tid 167635] [client 20.171.51.14:22170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pu.php"] [unique_id "aoSDbWr_JutbFb-8svr6lAAAAb0"] [Tue Aug 18 13:08:13.596127 2026] [security2:error] [pid 167459:tid 167659] [client 149.34.210.141:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDbWr_JutbFb-8svr6lQAAAdU"] [Tue Aug 18 13:08:13.626976 2026] [security2:error] [pid 167459:tid 167631] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/info.php"] [unique_id "aoSDbWr_JutbFb-8svr6lwAAAbk"] [Tue Aug 18 13:08:13.641873 2026] [security2:error] [pid 167459:tid 167487] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/aaa.php"] [unique_id "aoSDbWr_JutbFb-8svr6mQAB_xs"] [Tue Aug 18 13:08:13.670835 2026] [security2:error] [pid 167459:tid 167593] [client 20.163.43.14:15732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wk/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6mgAAAZM"] [Tue Aug 18 13:08:13.744745 2026] [security2:error] [pid 167459:tid 167669] [client 20.25.139.174:4827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/alfa.php"] [unique_id "aoSDbWr_JutbFb-8svr6oAAAAd8"] [Tue Aug 18 13:08:13.745291 2026] [security2:error] [pid 167459:tid 167697] [client 20.215.241.237:22394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/dex.php"] [unique_id "aoSDbWr_JutbFb-8svr6oQAAAfs"] [Tue Aug 18 13:08:13.753669 2026] [security2:error] [pid 167459:tid 167658] [client 20.106.102.5:45133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/xleet.php"] [unique_id "aoSDbWr_JutbFb-8svr6ogAAAdQ"] [Tue Aug 18 13:08:13.763069 2026] [security2:error] [pid 167459:tid 167654] [client 158.158.74.177:13706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/languages.php"] [unique_id "aoSDbWr_JutbFb-8svr6owAAAdA"] [Tue Aug 18 13:08:13.784927 2026] [security2:error] [pid 167459:tid 167621] [client 52.139.47.57:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/root.php"] [unique_id "aoSDbWr_JutbFb-8svr6pQAAAa8"] [Tue Aug 18 13:08:13.798809 2026] [security2:error] [pid 167459:tid 167676] [client 20.226.36.136:23215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDbWr_JutbFb-8svr6pgAAAeY"] [Tue Aug 18 13:08:13.821160 2026] [security2:error] [pid 167459:tid 167623] [client 213.35.127.232:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDbWr_JutbFb-8svr6qQAAAbE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:13.823481 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:13.823852 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:13.828438 2026] [security2:error] [pid 167459:tid 167653] [client 20.104.100.201:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDbWr_JutbFb-8svr6qgAAAc8"] [Tue Aug 18 13:08:13.837128 2026] [autoindex:error] [pid 167459:tid 167696] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:13.841286 2026] [security2:error] [pid 167459:tid 167620] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-mail.php"] [unique_id "aoSDbWr_JutbFb-8svr6rAAAAa4"] [Tue Aug 18 13:08:13.867529 2026] [security2:error] [pid 167459:tid 167659] [client 149.34.210.141:52444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDbWr_JutbFb-8svr6lQAAAdU"] [Tue Aug 18 13:08:13.872803 2026] [security2:error] [pid 167459:tid 167702] [client 158.23.17.4:44672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wm.php"] [unique_id "aoSDbWr_JutbFb-8svr6rgAAAgA"] [Tue Aug 18 13:08:13.882009 2026] [security2:error] [pid 167459:tid 167706] [client 132.196.30.78:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6sQAAAgQ"] [Tue Aug 18 13:08:13.887626 2026] [security2:error] [pid 167459:tid 167694] [client 172.202.39.151:27864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6swAAAfg"] [Tue Aug 18 13:08:13.903831 2026] [security2:error] [pid 167459:tid 167600] [client 20.151.109.219:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gc.php"] [unique_id "aoSDbWr_JutbFb-8svr6tgAAAZo"] [Tue Aug 18 13:08:13.911468 2026] [security2:error] [pid 167459:tid 167626] [client 20.116.17.175:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/1xmomo.php"] [unique_id "aoSDbWr_JutbFb-8svr6uAAAAbQ"] [Tue Aug 18 13:08:13.918660 2026] [security2:error] [pid 167459:tid 167700] [client 40.74.65.169:7122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDbWr_JutbFb-8svr6ugAAAf4"] [Tue Aug 18 13:08:13.923087 2026] [security2:error] [pid 167459:tid 167612] [client 49.13.167.123:50788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6nAAAAaY"], referer: https://siderurgiabrasil.com.br [Tue Aug 18 13:08:13.923672 2026] [security2:error] [pid 167459:tid 167670] [client 20.186.30.159:9829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDbWr_JutbFb-8svr6uwAAAeA"] [Tue Aug 18 13:08:13.933735 2026] [security2:error] [pid 167459:tid 167483] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/gecko.php"] [unique_id "aoSDbWr_JutbFb-8svr6vAAB4Rc"] [Tue Aug 18 13:08:13.943600 2026] [security2:error] [pid 167459:tid 167672] [client 20.104.100.201:17386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/spadex.php"] [unique_id "aoSDbWr_JutbFb-8svr6vgAAAeI"] [Tue Aug 18 13:08:13.965775 2026] [security2:error] [pid 167459:tid 167464] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSDbWr_JutbFb-8svr6vwABnwQ"] [Tue Aug 18 13:08:13.985674 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.18.37:6319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/litanies.php"] [unique_id "aoSDbWr_JutbFb-8svr6wAAAAdI"] [Tue Aug 18 13:08:14.005514 2026] [security2:error] [pid 167459:tid 167618] [client 20.163.43.14:15715] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/1.php"] [unique_id "aoSDbmr_JutbFb-8svr6wgAAAaw"] [Tue Aug 18 13:08:14.005667 2026] [security2:error] [pid 167459:tid 167618] [client 20.163.43.14:15715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/1.php"] [unique_id "aoSDbmr_JutbFb-8svr6wgAAAaw"] [Tue Aug 18 13:08:14.030335 2026] [autoindex:error] [pid 167459:tid 167686] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:14.033465 2026] [security2:error] [pid 167459:tid 167640] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDbmr_JutbFb-8svr6xAAAAcI"] [Tue Aug 18 13:08:14.038559 2026] [security2:error] [pid 167459:tid 167704] [client 172.182.217.32:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/random_compat/bala.php"] [unique_id "aoSDbmr_JutbFb-8svr6xQAAAgI"] [Tue Aug 18 13:08:14.046374 2026] [security2:error] [pid 167459:tid 167677] [client 20.65.98.162:46990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/file5.php"] [unique_id "aoSDbmr_JutbFb-8svr6xgAAAec"] [Tue Aug 18 13:08:14.053711 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:53366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wpxml.php"] [unique_id "aoSDbmr_JutbFb-8svr6xwAAAZs"] [Tue Aug 18 13:08:14.062474 2026] [security2:error] [pid 167459:tid 167688] [client 20.79.204.6:6002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/we.php"] [unique_id "aoSDbmr_JutbFb-8svr6yAAAAfI"] [Tue Aug 18 13:08:14.079408 2026] [security2:error] [pid 167459:tid 167611] [client 20.106.102.5:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fr/ms.php"] [unique_id "aoSDbmr_JutbFb-8svr6ygAAAaU"] [Tue Aug 18 13:08:14.120496 2026] [authz_core:error] [pid 167459:tid 167497] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:14.120964 2026] [authz_core:error] [pid 167459:tid 167497] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:14.148198 2026] [security2:error] [pid 167459:tid 167506] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSDbmr_JutbFb-8svr6zQABqC4"] [Tue Aug 18 13:08:14.179838 2026] [security2:error] [pid 167459:tid 167698] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/o.php"] [unique_id "aoSDbmr_JutbFb-8svr60AAAAfw"] [Tue Aug 18 13:08:14.207263 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:32875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/r.php"] [unique_id "aoSDbmr_JutbFb-8svr60QAAAdk"] [Tue Aug 18 13:08:14.207898 2026] [security2:error] [pid 167459:tid 167646] [client 74.249.206.207:8510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/av.php"] [unique_id "aoSDbmr_JutbFb-8svr60gAAAcg"] [Tue Aug 18 13:08:14.225282 2026] [security2:error] [pid 167459:tid 167523] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/xiugai.php"] [unique_id "aoSDbmr_JutbFb-8svr60wAB2D8"] [Tue Aug 18 13:08:14.239028 2026] [security2:error] [pid 167459:tid 167631] [client 52.173.121.69:28308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDbmr_JutbFb-8svr61AAAAbk"] [Tue Aug 18 13:08:14.251080 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:42593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/st.php"] [unique_id "aoSDbmr_JutbFb-8svr61QAAAc4"] [Tue Aug 18 13:08:14.256246 2026] [security2:error] [pid 167459:tid 167604] [client 20.25.139.174:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/edit.php"] [unique_id "aoSDbmr_JutbFb-8svr61gAAAZ4"] [Tue Aug 18 13:08:14.258017 2026] [security2:error] [pid 167459:tid 167657] [client 4.232.151.198:30098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ov-simple1.php"] [unique_id "aoSDbmr_JutbFb-8svr61wAAAdM"] [Tue Aug 18 13:08:14.266810 2026] [security2:error] [pid 167459:tid 167624] [client 78.46.215.1:1844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.anzenblindados.com.br"] [uri "/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6ewAAAbI"], referer: https://www.anzenblindados.com.br/ [Tue Aug 18 13:08:14.296493 2026] [security2:error] [pid 167459:tid 167691] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDbmr_JutbFb-8svr62gAAAfU"] [Tue Aug 18 13:08:14.340559 2026] [security2:error] [pid 167459:tid 167489] [remote 162.214.96.231:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cubangovidros.com.br"] [uri "/wp-login.php"] [unique_id "aoSDbmr_JutbFb-8svr63AAB-x0"] [Tue Aug 18 13:08:14.358151 2026] [autoindex:error] [pid 167459:tid 167710] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:14.359874 2026] [security2:error] [pid 167459:tid 167654] [client 20.163.43.14:15739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSDbmr_JutbFb-8svr64AAAAdA"] [Tue Aug 18 13:08:14.406458 2026] [security2:error] [pid 167459:tid 167589] [client 20.106.102.5:45124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/gool.php"] [unique_id "aoSDbmr_JutbFb-8svr64wAAAY8"] [Tue Aug 18 13:08:14.415385 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:14.415669 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:14.443799 2026] [security2:error] [pid 167459:tid 167701] [client 132.196.30.78:20300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDbmr_JutbFb-8svr65gAAAf8"] [Tue Aug 18 13:08:14.477783 2026] [security2:error] [pid 167459:tid 167590] [client 213.202.253.4:55846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSDbmr_JutbFb-8svr66AAAAZA"], referer: www.google.com [Tue Aug 18 13:08:14.481899 2026] [security2:error] [pid 167459:tid 167651] [client 20.104.100.201:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSDbmr_JutbFb-8svr66QAAAc0"] [Tue Aug 18 13:08:14.492130 2026] [security2:error] [pid 167459:tid 167682] [client 20.250.13.23:51361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDbmr_JutbFb-8svr66gAAAew"] [Tue Aug 18 13:08:14.495523 2026] [security2:error] [pid 167459:tid 167632] [client 20.151.109.219:28738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/uq.php"] [unique_id "aoSDbmr_JutbFb-8svr66wAAAbo"] [Tue Aug 18 13:08:14.503885 2026] [security2:error] [pid 167459:tid 167700] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/bb.php"] [unique_id "aoSDbmr_JutbFb-8svr67gAAAf4"] [Tue Aug 18 13:08:14.503910 2026] [security2:error] [pid 167459:tid 167707] [client 172.202.39.151:39176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/cah.php"] [unique_id "aoSDbmr_JutbFb-8svr67QAAAgU"] [Tue Aug 18 13:08:14.517365 2026] [security2:error] [pid 167459:tid 167535] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/adminner.php"] [unique_id "aoSDbmr_JutbFb-8svr67wAB4Es"] [Tue Aug 18 13:08:14.519922 2026] [security2:error] [pid 167459:tid 167613] [client 157.20.138.62:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDbmr_JutbFb-8svr68AAAAac"] [Tue Aug 18 13:08:14.520031 2026] [security2:error] [pid 167459:tid 167613] [client 157.20.138.62:56294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDbmr_JutbFb-8svr68AAAAac"] [Tue Aug 18 13:08:14.526216 2026] [security2:error] [pid 167459:tid 167460] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDbmr_JutbFb-8svr68QAB6gA"] [Tue Aug 18 13:08:14.551640 2026] [security2:error] [pid 167459:tid 167591] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/k.php"] [unique_id "aoSDbmr_JutbFb-8svr69AAAAZE"] [Tue Aug 18 13:08:14.562047 2026] [security2:error] [pid 167459:tid 167605] [client 20.104.100.201:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDbmr_JutbFb-8svr69QAAAZ8"] [Tue Aug 18 13:08:14.603159 2026] [security2:error] [pid 167459:tid 167656] [client 158.158.74.177:13813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/nw.php"] [unique_id "aoSDbmr_JutbFb-8svr69wAAAdI"] [Tue Aug 18 13:08:14.631989 2026] [security2:error] [pid 167459:tid 167617] [client 52.139.47.57:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/sid3.php"] [unique_id "aoSDbmr_JutbFb-8svr6-gAAAas"] [Tue Aug 18 13:08:14.683477 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ac.php"] [unique_id "aoSDbmr_JutbFb-8svr6_QAAAd4"] [Tue Aug 18 13:08:14.700485 2026] [security2:error] [pid 167459:tid 167607] [client 20.163.43.14:15728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDbmr_JutbFb-8svr6_gAAAaE"] [Tue Aug 18 13:08:14.707024 2026] [security2:error] [pid 167459:tid 167529] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDbmr_JutbFb-8svr7AAAB70U"] [Tue Aug 18 13:08:14.713834 2026] [security2:error] [pid 167459:tid 167612] [client 20.79.204.6:6004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wkl.php"] [unique_id "aoSDbmr_JutbFb-8svr7AwAAAaY"] [Tue Aug 18 13:08:14.720509 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:14.720962 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:14.735412 2026] [security2:error] [pid 167459:tid 167633] [client 20.106.102.5:45280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/maxro.php"] [unique_id "aoSDbmr_JutbFb-8svr7BAAAAbs"] [Tue Aug 18 13:08:14.783344 2026] [security2:error] [pid 167459:tid 167618] [client 20.25.139.174:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/elp.php"] [unique_id "aoSDbmr_JutbFb-8svr7BwAAAaw"] [Tue Aug 18 13:08:14.807597 2026] [security2:error] [pid 167459:tid 167574] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file1221.php"] [unique_id "aoSDbmr_JutbFb-8svr7CgACDXI"] [Tue Aug 18 13:08:14.814575 2026] [security2:error] [pid 167459:tid 167716] [client 74.248.18.37:6335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/notifications.php"] [unique_id "aoSDbmr_JutbFb-8svr7CwAAAg4"] [Tue Aug 18 13:08:14.822597 2026] [security2:error] [pid 167459:tid 167602] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDbmr_JutbFb-8svr7DgAAAZw"] [Tue Aug 18 13:08:14.830481 2026] [autoindex:error] [pid 167459:tid 167631] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:14.837532 2026] [security2:error] [pid 167459:tid 167628] [client 213.35.127.232:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDbmr_JutbFb-8svr7EAAAAbY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:14.888716 2026] [security2:error] [pid 167459:tid 167500] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSDbmr_JutbFb-8svr7FAABsig"] [Tue Aug 18 13:08:14.912286 2026] [security2:error] [pid 167459:tid 167611] [client 4.232.151.198:16402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ova.php"] [unique_id "aoSDbmr_JutbFb-8svr7FwAAAaU"] [Tue Aug 18 13:08:14.947364 2026] [cgid:error] [pid 167459:tid 167627] [client 169.58.72.248:54132] AH01265: stderr from /home3/adobankcom/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:08:14.951839 2026] [security2:error] [pid 167459:tid 167596] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/403.php"] [unique_id "aoSDbmr_JutbFb-8svr7GQAAAZY"] [Tue Aug 18 13:08:15.015555 2026] [security2:error] [pid 167459:tid 167654] [client 20.215.241.237:22397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/puc.php"] [unique_id "aoSDb2r_JutbFb-8svr7HAAAAdA"] [Tue Aug 18 13:08:15.015950 2026] [security2:error] [pid 167459:tid 167676] [client 20.171.51.14:22158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ry.php"] [unique_id "aoSDb2r_JutbFb-8svr7HQAAAeY"] [Tue Aug 18 13:08:15.029342 2026] [security2:error] [pid 167459:tid 167696] [client 20.104.100.201:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/output.php"] [unique_id "aoSDb2r_JutbFb-8svr7HwAAAfo"] [Tue Aug 18 13:08:15.037440 2026] [security2:error] [pid 167459:tid 167703] [client 20.104.100.201:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ccou.php"] [unique_id "aoSDb2r_JutbFb-8svr7IQAAAgE"] [Tue Aug 18 13:08:15.038014 2026] [security2:error] [pid 167459:tid 167673] [client 52.173.121.69:36593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDb2r_JutbFb-8svr7IgAAAeM"] [Tue Aug 18 13:08:15.040113 2026] [authz_core:error] [pid 167459:tid 167547] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:15.040381 2026] [authz_core:error] [pid 167459:tid 167547] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:15.059620 2026] [security2:error] [pid 167459:tid 167693] [client 20.106.102.5:45249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wdf.php"] [unique_id "aoSDb2r_JutbFb-8svr7JAAAAfc"] [Tue Aug 18 13:08:15.061567 2026] [security2:error] [pid 167459:tid 167604] [client 132.196.30.78:13620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDb2r_JutbFb-8svr7JQAAAZ4"] [Tue Aug 18 13:08:15.064085 2026] [security2:error] [pid 167459:tid 167697] [client 52.139.47.57:38370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ss.php"] [unique_id "aoSDb2r_JutbFb-8svr7JgAAAfs"] [Tue Aug 18 13:08:15.076839 2026] [security2:error] [pid 167459:tid 167659] [client 40.74.65.169:20604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp.php"] [unique_id "aoSDb2r_JutbFb-8svr7JwAAAdU"] [Tue Aug 18 13:08:15.088621 2026] [security2:error] [pid 167459:tid 167478] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSDb2r_JutbFb-8svr7KQAB6xI"] [Tue Aug 18 13:08:15.099362 2026] [security2:error] [pid 167459:tid 167492] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/inx.php"] [unique_id "aoSDb2r_JutbFb-8svr7KwABzSA"] [Tue Aug 18 13:08:15.111371 2026] [autoindex:error] [pid 167459:tid 167590] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:15.113296 2026] [security2:error] [pid 167459:tid 167678] [client 178.153.171.161:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDb2r_JutbFb-8svr7LQAAAeg"] [Tue Aug 18 13:08:15.113419 2026] [security2:error] [pid 167459:tid 167678] [client 178.153.171.161:59594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDb2r_JutbFb-8svr7LQAAAeg"] [Tue Aug 18 13:08:15.129984 2026] [security2:error] [pid 167459:tid 167615] [client 20.163.43.14:15737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/as.php"] [unique_id "aoSDb2r_JutbFb-8svr7LgAAAak"] [Tue Aug 18 13:08:15.145677 2026] [security2:error] [pid 167459:tid 167705] [client 74.248.18.37:27599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDb2r_JutbFb-8svr7MAAAAgM"] [Tue Aug 18 13:08:15.158513 2026] [security2:error] [pid 167459:tid 167655] [client 74.7.228.16:45632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.brioniimoveis.com.br"] [uri "/index.php"] [unique_id "aoSDbWr_JutbFb-8svr6nQAB0Vg"] [Tue Aug 18 13:08:15.210616 2026] [security2:error] [pid 167459:tid 167622] [client 172.202.39.151:39185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/system_log.php"] [unique_id "aoSDb2r_JutbFb-8svr7NQAAAbA"] [Tue Aug 18 13:08:15.284621 2026] [security2:error] [pid 167459:tid 167706] [client 158.158.74.177:13810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSDb2r_JutbFb-8svr7OAAAAgQ"] [Tue Aug 18 13:08:15.316579 2026] [security2:error] [pid 167459:tid 167668] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDb2r_JutbFb-8svr7OwAAAd4"] [Tue Aug 18 13:08:15.319012 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:15.319303 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:15.324808 2026] [security2:error] [pid 167459:tid 167670] [client 20.25.139.174:4811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/classwithtostring.php"] [unique_id "aoSDb2r_JutbFb-8svr7PAAAAeA"] [Tue Aug 18 13:08:15.325578 2026] [security2:error] [pid 167459:tid 167688] [client 20.151.109.219:40499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/32.php"] [unique_id "aoSDb2r_JutbFb-8svr7PQAAAfI"] [Tue Aug 18 13:08:15.348357 2026] [security2:error] [pid 167459:tid 167685] [client 158.23.17.4:5033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/yz.php"] [unique_id "aoSDb2r_JutbFb-8svr7PwAAAe8"] [Tue Aug 18 13:08:15.365163 2026] [security2:error] [pid 167459:tid 167713] [client 74.7.244.30:58244] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.adepol.com.br"] [uri "/index.php"] [unique_id "aoSDb2r_JutbFb-8svr7QgACCzQ"] [Tue Aug 18 13:08:15.386190 2026] [security2:error] [pid 167459:tid 167645] [client 20.106.102.5:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ff1.php"] [unique_id "aoSDb2r_JutbFb-8svr7QwAAAcc"] [Tue Aug 18 13:08:15.388508 2026] [security2:error] [pid 167459:tid 167618] [client 20.226.36.136:41517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDb2r_JutbFb-8svr7RAAAAaw"] [Tue Aug 18 13:08:15.401653 2026] [security2:error] [pid 167459:tid 167522] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/reviall.php"] [unique_id "aoSDb2r_JutbFb-8svr7RQAB3D4"] [Tue Aug 18 13:08:15.419944 2026] [autoindex:error] [pid 167459:tid 167630] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:15.437727 2026] [security2:error] [pid 167459:tid 167716] [client 20.104.100.201:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/crgio.php"] [unique_id "aoSDb2r_JutbFb-8svr7SAAAAg4"] [Tue Aug 18 13:08:15.460929 2026] [security2:error] [pid 167459:tid 167584] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDb2r_JutbFb-8svr7SgABvXw"] [Tue Aug 18 13:08:15.476287 2026] [security2:error] [pid 167459:tid 167628] [client 20.163.43.14:15673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDb2r_JutbFb-8svr7SwAAAbY"] [Tue Aug 18 13:08:15.478520 2026] [security2:error] [pid 167459:tid 167607] [client 52.139.47.57:32841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/sts.php"] [unique_id "aoSDb2r_JutbFb-8svr7TAAAAaE"] [Tue Aug 18 13:08:15.510687 2026] [security2:error] [pid 167459:tid 167683] [client 20.186.30.159:9764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDb2r_JutbFb-8svr7TwAAAe0"] [Tue Aug 18 13:08:15.510735 2026] [security2:error] [pid 167459:tid 167624] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/gecko.php"] [unique_id "aoSDb2r_JutbFb-8svr7TgAAAbI"] [Tue Aug 18 13:08:15.569989 2026] [security2:error] [pid 167459:tid 167669] [client 20.206.73.37:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/uwu.php"] [unique_id "aoSDb2r_JutbFb-8svr7UgAAAd8"] [Tue Aug 18 13:08:15.572039 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/tiny2.php"] [unique_id "aoSDb2r_JutbFb-8svr7UwAAAbU"] [Tue Aug 18 13:08:15.623749 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:15.624171 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:15.632129 2026] [security2:error] [pid 167459:tid 167623] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/xmrlpc.php"] [unique_id "aoSDb2r_JutbFb-8svr7VQAAAbE"] [Tue Aug 18 13:08:15.636279 2026] [security2:error] [pid 167459:tid 167663] [client 132.196.30.78:13099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/NewFile.php"] [unique_id "aoSDb2r_JutbFb-8svr7VwAAAdk"] [Tue Aug 18 13:08:15.641179 2026] [security2:error] [pid 167459:tid 167559] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDb2r_JutbFb-8svr7WAAB-mM"] [Tue Aug 18 13:08:15.645862 2026] [security2:error] [pid 167459:tid 167610] [client 20.79.204.6:5732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/work.php"] [unique_id "aoSDb2r_JutbFb-8svr7WQAAAaQ"] [Tue Aug 18 13:08:15.695366 2026] [security2:error] [pid 167459:tid 167511] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/11.php"] [unique_id "aoSDb2r_JutbFb-8svr7WgABlTM"] [Tue Aug 18 13:08:15.713994 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:6334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/Requests/Exception/content.php.suspected"] [unique_id "aoSDb2r_JutbFb-8svr7WwAAAec"] [Tue Aug 18 13:08:15.733530 2026] [security2:error] [pid 167459:tid 167681] [client 20.106.102.5:45181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/guk.php"] [unique_id "aoSDb2r_JutbFb-8svr7XgAAAes"] [Tue Aug 18 13:08:15.735465 2026] [autoindex:error] [pid 167459:tid 167641] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:15.741809 2026] [security2:error] [pid 167459:tid 167592] [client 20.250.13.23:28093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/info.php"] [unique_id "aoSDb2r_JutbFb-8svr7XwAAAZI"] [Tue Aug 18 13:08:15.758763 2026] [security2:error] [pid 167459:tid 167590] [client 20.127.136.245:9267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/php.php"] [unique_id "aoSDb2r_JutbFb-8svr7YAAAAZA"] [Tue Aug 18 13:08:15.759035 2026] [security2:error] [pid 167459:tid 167638] [client 4.232.151.198:16416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/p.php"] [unique_id "aoSDb2r_JutbFb-8svr7YQAAAcA"] [Tue Aug 18 13:08:15.824055 2026] [security2:error] [pid 167459:tid 167467] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSDb2r_JutbFb-8svr7ZQAB7Ac"] [Tue Aug 18 13:08:15.824677 2026] [security2:error] [pid 167459:tid 167671] [client 20.151.109.219:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/73.php"] [unique_id "aoSDb2r_JutbFb-8svr7ZgAAAeE"] [Tue Aug 18 13:08:15.830287 2026] [security2:error] [pid 167459:tid 167655] [client 20.226.36.136:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDb2r_JutbFb-8svr7ZwAAAdE"] [Tue Aug 18 13:08:15.839162 2026] [security2:error] [pid 167459:tid 167594] [client 20.116.17.175:44689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/txets.php"] [unique_id "aoSDb2r_JutbFb-8svr7agAAAZQ"] [Tue Aug 18 13:08:15.852511 2026] [security2:error] [pid 167459:tid 167650] [client 20.163.43.14:15666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSDb2r_JutbFb-8svr7awAAAcw"] [Tue Aug 18 13:08:15.853884 2026] [security2:error] [pid 167459:tid 167699] [client 52.139.47.57:30919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/hel.php"] [unique_id "aoSDb2r_JutbFb-8svr7bAAAAf0"] [Tue Aug 18 13:08:15.860910 2026] [security2:error] [pid 167459:tid 167683] [client 213.35.127.232:60811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDb2r_JutbFb-8svr7bQAAAe0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:15.862989 2026] [security2:error] [pid 167459:tid 167702] [client 20.25.139.174:4858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/666.php"] [unique_id "aoSDb2r_JutbFb-8svr7bgAAAgA"] [Tue Aug 18 13:08:15.885992 2026] [security2:error] [pid 167459:tid 167665] [client 40.74.65.169:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/i.php"] [unique_id "aoSDb2r_JutbFb-8svr7bwAAAds"] [Tue Aug 18 13:08:15.891442 2026] [security2:error] [pid 167459:tid 167664] [client 20.104.100.201:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDb2r_JutbFb-8svr7cAAAAdo"] [Tue Aug 18 13:08:15.907346 2026] [security2:error] [pid 167459:tid 167678] [client 52.139.47.57:24506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/shell.php"] [unique_id "aoSDb2r_JutbFb-8svr7cgAAAeg"] [Tue Aug 18 13:08:15.908694 2026] [security2:error] [pid 167459:tid 167706] [client 52.173.121.69:36571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDb2r_JutbFb-8svr7cwAAAgQ"] [Tue Aug 18 13:08:15.913160 2026] [security2:error] [pid 167459:tid 167629] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/aa.php"] [unique_id "aoSDb2r_JutbFb-8svr7dAAAAbc"] [Tue Aug 18 13:08:15.925673 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:15.926105 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:15.941469 2026] [security2:error] [pid 167459:tid 167711] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/file.php"] [unique_id "aoSDb2r_JutbFb-8svr7dgAAAgk"] [Tue Aug 18 13:08:15.974056 2026] [autoindex:error] [pid 167459:tid 167600] [client 158.158.74.177:13782] AH01276: Cannot serve directory /home3/guiad071/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:15.987643 2026] [security2:error] [pid 167459:tid 167484] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/File.php"] [unique_id "aoSDb2r_JutbFb-8svr7egABwhg"] [Tue Aug 18 13:08:16.005447 2026] [security2:error] [pid 167459:tid 167578] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSDcGr_JutbFb-8svr7fAABxHY"] [Tue Aug 18 13:08:16.061948 2026] [security2:error] [pid 167459:tid 167635] [client 20.106.102.5:45265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-the.php"] [unique_id "aoSDcGr_JutbFb-8svr7fwAAAb0"] [Tue Aug 18 13:08:16.062759 2026] [autoindex:error] [pid 167459:tid 167716] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:16.071269 2026] [security2:error] [pid 167459:tid 167628] [client 20.226.36.136:43552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDcGr_JutbFb-8svr7gQAAAbY"] [Tue Aug 18 13:08:16.131885 2026] [security2:error] [pid 167459:tid 167593] [client 158.23.17.4:46815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/le.php"] [unique_id "aoSDcGr_JutbFb-8svr7hAAAAZM"] [Tue Aug 18 13:08:16.160089 2026] [security2:error] [pid 167459:tid 167624] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/0x.php"] [unique_id "aoSDcGr_JutbFb-8svr7hQAAAbI"] [Tue Aug 18 13:08:16.178461 2026] [security2:error] [pid 167459:tid 167675] [client 20.163.43.14:15735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7hgAAAeU"] [Tue Aug 18 13:08:16.181135 2026] [security2:error] [pid 167459:tid 167611] [client 158.158.74.177:13782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDcGr_JutbFb-8svr7iAAAAaU"] [Tue Aug 18 13:08:16.190161 2026] [security2:error] [pid 167459:tid 167653] [client 132.196.30.78:13088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSDcGr_JutbFb-8svr7iQAAAc8"] [Tue Aug 18 13:08:16.191825 2026] [security2:error] [pid 167459:tid 167573] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSDcGr_JutbFb-8svr7igACBnE"] [Tue Aug 18 13:08:16.235870 2026] [security2:error] [pid 167459:tid 167676] [client 20.215.241.237:51182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/inso.php"] [unique_id "aoSDcGr_JutbFb-8svr7jQAAAeY"] [Tue Aug 18 13:08:16.254110 2026] [security2:error] [pid 167459:tid 167608] [client 172.202.39.151:27902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7jgAAAaI"] [Tue Aug 18 13:08:16.257481 2026] [security2:error] [pid 167459:tid 167589] [client 20.226.36.136:33462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7jwAAAY8"] [Tue Aug 18 13:08:16.261022 2026] [security2:error] [pid 167459:tid 167663] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/epinyins.php"] [unique_id "aoSDcGr_JutbFb-8svr7kAAAAdk"] [Tue Aug 18 13:08:16.263164 2026] [security2:error] [pid 167459:tid 167632] [client 20.79.204.6:5751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/worksec.php"] [unique_id "aoSDcGr_JutbFb-8svr7kQAAAbo"] [Tue Aug 18 13:08:16.272542 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:45803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/red.php"] [unique_id "aoSDcGr_JutbFb-8svr7lAAAAfQ"] [Tue Aug 18 13:08:16.277554 2026] [security2:error] [pid 167459:tid 167531] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fi22.php"] [unique_id "aoSDcGr_JutbFb-8svr7lgAB40c"] [Tue Aug 18 13:08:16.289677 2026] [security2:error] [pid 167459:tid 167693] [client 172.182.217.32:25621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/simplepie/library/simplepie/about.php"] [unique_id "aoSDcGr_JutbFb-8svr7lwAAAfc"] [Tue Aug 18 13:08:16.342390 2026] [security2:error] [pid 167459:tid 167661] [client 20.151.109.219:36331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ib.php"] [unique_id "aoSDcGr_JutbFb-8svr7mQAAAdc"] [Tue Aug 18 13:08:16.346730 2026] [security2:error] [pid 167459:tid 167599] [client 158.23.17.4:5047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kj.php"] [unique_id "aoSDcGr_JutbFb-8svr7mgAAAZk"] [Tue Aug 18 13:08:16.390740 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sbhu.php"] [unique_id "aoSDcGr_JutbFb-8svr7ngAAAc0"] [Tue Aug 18 13:08:16.392544 2026] [security2:error] [pid 167459:tid 167581] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSDcGr_JutbFb-8svr7nwABkHk"] [Tue Aug 18 13:08:16.414760 2026] [security2:error] [pid 167459:tid 167692] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/zxz.php"] [unique_id "aoSDcGr_JutbFb-8svr7oQAAAfY"] [Tue Aug 18 13:08:16.429141 2026] [security2:error] [pid 167459:tid 167707] [client 104.209.144.33:32642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDcGr_JutbFb-8svr7pQAAAgU"] [Tue Aug 18 13:08:16.445089 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.100.201:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/css.php"] [unique_id "aoSDcGr_JutbFb-8svr7qAAAAfw"] [Tue Aug 18 13:08:16.487922 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:19511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/setup-config.php"] [unique_id "aoSDcGr_JutbFb-8svr7qgAAAec"] [Tue Aug 18 13:08:16.504243 2026] [security2:error] [pid 167459:tid 167604] [client 4.232.151.198:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/pages.php"] [unique_id "aoSDcGr_JutbFb-8svr7rAAAAZ4"] [Tue Aug 18 13:08:16.525428 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:16.525692 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:16.533732 2026] [autoindex:error] [pid 167459:tid 167695] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:16.563128 2026] [security2:error] [pid 167459:tid 167683] [client 20.163.43.14:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7sAAAAe0"] [Tue Aug 18 13:08:16.567775 2026] [security2:error] [pid 167459:tid 167569] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDcGr_JutbFb-8svr7sQABsG0"] [Tue Aug 18 13:08:16.573280 2026] [security2:error] [pid 167459:tid 167580] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSDcGr_JutbFb-8svr7sgAByng"] [Tue Aug 18 13:08:16.577609 2026] [security2:error] [pid 167459:tid 167606] [client 20.226.36.136:33436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDcGr_JutbFb-8svr7swAAAaA"] [Tue Aug 18 13:08:16.581688 2026] [security2:error] [pid 167459:tid 167665] [client 20.25.139.174:4807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ws54.php"] [unique_id "aoSDcGr_JutbFb-8svr7tAAAAds"] [Tue Aug 18 13:08:16.608321 2026] [security2:error] [pid 167459:tid 167664] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7tQAAAdo"] [Tue Aug 18 13:08:16.610213 2026] [security2:error] [pid 167459:tid 167623] [client 74.248.18.37:49491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/makesmtp.php"] [unique_id "aoSDcGr_JutbFb-8svr7tgAAAbE"] [Tue Aug 18 13:08:16.626207 2026] [security2:error] [pid 167459:tid 167668] [client 143.244.57.82:52610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSDcGr_JutbFb-8svr7uQAAAd4"] [Tue Aug 18 13:08:16.629800 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:7165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/abcd.php"] [unique_id "aoSDcGr_JutbFb-8svr7ugAAAgk"] [Tue Aug 18 13:08:16.629857 2026] [security2:error] [pid 167459:tid 167700] [client 20.104.100.201:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wpxml.php"] [unique_id "aoSDcGr_JutbFb-8svr7uwAAAf4"] [Tue Aug 18 13:08:16.667472 2026] [security2:error] [pid 167459:tid 167600] [client 172.202.39.151:39198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDcGr_JutbFb-8svr7vQAAAZo"] [Tue Aug 18 13:08:16.681057 2026] [security2:error] [pid 167459:tid 167642] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/www.php"] [unique_id "aoSDcGr_JutbFb-8svr7vgAAAcQ"] [Tue Aug 18 13:08:16.688597 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:25395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/hr.php"] [unique_id "aoSDcGr_JutbFb-8svr7vwAAAcc"] [Tue Aug 18 13:08:16.689127 2026] [security2:error] [pid 167459:tid 167699] [client 52.139.47.57:30946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/sys.php"] [unique_id "aoSDcGr_JutbFb-8svr7wAAAAf0"] [Tue Aug 18 13:08:16.718025 2026] [security2:error] [pid 167459:tid 167666] [client 20.106.102.5:45716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/zc-318.php"] [unique_id "aoSDcGr_JutbFb-8svr7wQAAAdw"] [Tue Aug 18 13:08:16.732735 2026] [security2:error] [pid 167459:tid 167715] [client 20.151.109.219:49713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xm.php"] [unique_id "aoSDcGr_JutbFb-8svr7xAAAAg0"] [Tue Aug 18 13:08:16.781945 2026] [security2:error] [pid 167459:tid 167678] [client 172.182.217.32:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/simplepie/library/simplepie/min.php"] [unique_id "aoSDcGr_JutbFb-8svr7ywAAAeg"] [Tue Aug 18 13:08:16.783944 2026] [security2:error] [pid 167459:tid 167660] [client 132.196.30.78:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDcGr_JutbFb-8svr7zAAAAdY"] [Tue Aug 18 13:08:16.790706 2026] [security2:error] [pid 167459:tid 167532] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSDcGr_JutbFb-8svr7zQABk0g"] [Tue Aug 18 13:08:16.803429 2026] [security2:error] [pid 167459:tid 167624] [client 52.173.121.69:28311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDcGr_JutbFb-8svr7zgAAAbI"] [Tue Aug 18 13:08:16.824701 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:16.824992 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:16.858968 2026] [security2:error] [pid 167459:tid 167541] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSDcGr_JutbFb-8svr70wABl1E"] [Tue Aug 18 13:08:16.877909 2026] [security2:error] [pid 167459:tid 167712] [client 20.79.204.6:5754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-activate.php"] [unique_id "aoSDcGr_JutbFb-8svr71AAAAgo"] [Tue Aug 18 13:08:16.880513 2026] [security2:error] [pid 167459:tid 167625] [client 213.35.127.232:61047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDcGr_JutbFb-8svr71QAAAbM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:16.893091 2026] [security2:error] [pid 167459:tid 167607] [client 74.248.18.37:43471] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.portalosol.com.br"] [uri "/1.php"] [unique_id "aoSDcGr_JutbFb-8svr71gAAAaE"] [Tue Aug 18 13:08:16.893183 2026] [security2:error] [pid 167459:tid 167607] [client 74.248.18.37:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/1.php"] [unique_id "aoSDcGr_JutbFb-8svr71gAAAaE"] [Tue Aug 18 13:08:16.901837 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:38345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/t.php"] [unique_id "aoSDcGr_JutbFb-8svr72AAAAfA"] [Tue Aug 18 13:08:16.926399 2026] [autoindex:error] [pid 167459:tid 167663] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:16.931847 2026] [security2:error] [pid 167459:tid 167630] [client 158.158.74.177:13735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSDcGr_JutbFb-8svr74AAAAbg"] [Tue Aug 18 13:08:16.935852 2026] [security2:error] [pid 167459:tid 167673] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wicked.php"] [unique_id "aoSDcGr_JutbFb-8svr74QAAAeM"] [Tue Aug 18 13:08:16.955809 2026] [security2:error] [pid 167459:tid 167601] [client 158.23.17.4:39585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vg.php"] [unique_id "aoSDcGr_JutbFb-8svr74gAAAZs"] [Tue Aug 18 13:08:16.970449 2026] [security2:error] [pid 167459:tid 167508] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDcGr_JutbFb-8svr75AAB1zA"] [Tue Aug 18 13:08:17.037049 2026] [security2:error] [pid 167459:tid 167638] [client 143.244.57.82:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riovacinas.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcWr_JutbFb-8svr76QAAAcA"] [Tue Aug 18 13:08:17.044192 2026] [security2:error] [pid 167459:tid 167615] [client 20.106.102.5:45711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ccou.php"] [unique_id "aoSDcWr_JutbFb-8svr77AAAAak"] [Tue Aug 18 13:08:17.062493 2026] [security2:error] [pid 167459:tid 167667] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDcWr_JutbFb-8svr77QAAAd0"] [Tue Aug 18 13:08:17.062507 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDcWr_JutbFb-8svr77gAAAbU"] [Tue Aug 18 13:08:17.073321 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:53834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/srontol.php"] [unique_id "aoSDcWr_JutbFb-8svr77wAAAgU"] [Tue Aug 18 13:08:17.075200 2026] [security2:error] [pid 167459:tid 167689] [client 172.202.39.151:27851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/abc.php"] [unique_id "aoSDcWr_JutbFb-8svr78AAAAfM"] [Tue Aug 18 13:08:17.126435 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:17.126698 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:17.133188 2026] [security2:error] [pid 167459:tid 167599] [client 52.139.47.57:15929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/uploads/product.php"] [unique_id "aoSDcWr_JutbFb-8svr79AAAAZk"] [Tue Aug 18 13:08:17.138545 2026] [security2:error] [pid 167459:tid 167697] [client 20.250.13.23:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/a.php"] [unique_id "aoSDcWr_JutbFb-8svr79QAAAfs"] [Tue Aug 18 13:08:17.149745 2026] [security2:error] [pid 167459:tid 167483] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDcWr_JutbFb-8svr79gAB5xc"] [Tue Aug 18 13:08:17.149762 2026] [security2:error] [pid 167459:tid 167681] [client 20.25.139.174:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/deepseek_d.php"] [unique_id "aoSDcWr_JutbFb-8svr79wAAAes"] [Tue Aug 18 13:08:17.149821 2026] [security2:error] [pid 167459:tid 167464] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDcWr_JutbFb-8svr7-AABngQ"] [Tue Aug 18 13:08:17.153786 2026] [security2:error] [pid 167459:tid 167672] [client 20.226.36.136:28464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDcWr_JutbFb-8svr7-gAAAeI"] [Tue Aug 18 13:08:17.163923 2026] [autoindex:error] [pid 167459:tid 167591] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:17.177601 2026] [security2:error] [pid 167459:tid 167610] [client 20.163.43.14:15643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDcWr_JutbFb-8svr7_AAAAaQ"] [Tue Aug 18 13:08:17.189824 2026] [security2:error] [pid 167459:tid 167648] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/HLA-dd.php"] [unique_id "aoSDcWr_JutbFb-8svr7_gAAAco"] [Tue Aug 18 13:08:17.192652 2026] [security2:error] [pid 167459:tid 167606] [client 20.151.109.219:38615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/zy.php"] [unique_id "aoSDcWr_JutbFb-8svr7_wAAAaA"] [Tue Aug 18 13:08:17.200014 2026] [security2:error] [pid 167459:tid 167587] [remote 212.29.237.5:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.237.29.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ezycolor.com.br"] [uri "/wp-login.php"] [unique_id "aoSDcWr_JutbFb-8svr8AAAB-H8"] [Tue Aug 18 13:08:17.206878 2026] [security2:error] [pid 167459:tid 167632] [client 4.232.151.198:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/past.php"] [unique_id "aoSDcWr_JutbFb-8svr8AQAAAbo"] [Tue Aug 18 13:08:17.301322 2026] [security2:error] [pid 167459:tid 167713] [client 20.116.17.175:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/img.php"] [unique_id "aoSDcWr_JutbFb-8svr8BQAAAgs"] [Tue Aug 18 13:08:17.370543 2026] [security2:error] [pid 167459:tid 167592] [client 20.106.102.5:45303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/txets.php"] [unique_id "aoSDcWr_JutbFb-8svr8EAAAAZI"] [Tue Aug 18 13:08:17.390493 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:24497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/up.php"] [unique_id "aoSDcWr_JutbFb-8svr8EQAAAe0"] [Tue Aug 18 13:08:17.399417 2026] [security2:error] [pid 167459:tid 167714] [client 68.221.73.131:33177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDcWr_JutbFb-8svr8EwAAAgw"] [Tue Aug 18 13:08:17.406032 2026] [security2:error] [pid 167459:tid 167502] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDcWr_JutbFb-8svr8FAABkyo"] [Tue Aug 18 13:08:17.407197 2026] [security2:error] [pid 167459:tid 167624] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDcWr_JutbFb-8svr8FQAAAbI"] [Tue Aug 18 13:08:17.429145 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:17.429405 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:17.438323 2026] [security2:error] [pid 167459:tid 167706] [client 132.196.30.78:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/themes.php"] [unique_id "aoSDcWr_JutbFb-8svr8GQAAAgQ"] [Tue Aug 18 13:08:17.441798 2026] [security2:error] [pid 167459:tid 167460] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSDcWr_JutbFb-8svr8GgABlgA"] [Tue Aug 18 13:08:17.452970 2026] [security2:error] [pid 167459:tid 167597] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDcWr_JutbFb-8svr8HAAAAZc"] [Tue Aug 18 13:08:17.505988 2026] [autoindex:error] [pid 167459:tid 167652] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:17.513612 2026] [security2:error] [pid 167459:tid 167612] [client 20.79.204.6:6006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin.php"] [unique_id "aoSDcWr_JutbFb-8svr8KQAAAaY"] [Tue Aug 18 13:08:17.513955 2026] [security2:error] [pid 167459:tid 167658] [client 74.248.18.37:30747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/img/class-wp-http-client.php"] [unique_id "aoSDcWr_JutbFb-8svr8KgAAAdQ"] [Tue Aug 18 13:08:17.552676 2026] [security2:error] [pid 167459:tid 167663] [client 104.209.144.33:31284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDcWr_JutbFb-8svr8LAAAAdk"] [Tue Aug 18 13:08:17.557540 2026] [security2:error] [pid 167459:tid 167603] [client 52.139.47.57:30955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/11.php"] [unique_id "aoSDcWr_JutbFb-8svr8LQAAAZ0"] [Tue Aug 18 13:08:17.568732 2026] [security2:error] [pid 167459:tid 167690] [client 20.163.43.14:15743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/an.php"] [unique_id "aoSDcWr_JutbFb-8svr8LgAAAfQ"] [Tue Aug 18 13:08:17.575192 2026] [security2:error] [pid 167459:tid 167621] [client 20.104.100.201:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/epinyins.php"] [unique_id "aoSDcWr_JutbFb-8svr8LwAAAa8"] [Tue Aug 18 13:08:17.587244 2026] [security2:error] [pid 167459:tid 167503] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSDcWr_JutbFb-8svr8MAABwys"] [Tue Aug 18 13:08:17.597040 2026] [security2:error] [pid 167459:tid 167651] [client 172.202.39.151:27853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/akcc.php"] [unique_id "aoSDcWr_JutbFb-8svr8MQAAAc0"] [Tue Aug 18 13:08:17.611129 2026] [security2:error] [pid 167459:tid 167696] [client 40.74.65.169:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDcWr_JutbFb-8svr8MgAAAfo"] [Tue Aug 18 13:08:17.629999 2026] [security2:error] [pid 167459:tid 167709] [client 158.158.74.177:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/f7.php"] [unique_id "aoSDcWr_JutbFb-8svr8NAAAAgc"] [Tue Aug 18 13:08:17.642755 2026] [security2:error] [pid 167459:tid 167619] [client 20.226.36.136:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDcWr_JutbFb-8svr8NQAAAa0"] [Tue Aug 18 13:08:17.650405 2026] [security2:error] [pid 167459:tid 167638] [client 143.244.57.82:52628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSDcWr_JutbFb-8svr8NwAAAcA"] [Tue Aug 18 13:08:17.700747 2026] [security2:error] [pid 167459:tid 167613] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp.php"] [unique_id "aoSDcWr_JutbFb-8svr8OQAAAac"] [Tue Aug 18 13:08:17.701399 2026] [security2:error] [pid 167459:tid 167692] [client 20.106.102.5:45301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fun.php"] [unique_id "aoSDcWr_JutbFb-8svr8OgAAAfY"] [Tue Aug 18 13:08:17.707579 2026] [security2:error] [pid 167459:tid 167653] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/cah.php"] [unique_id "aoSDcWr_JutbFb-8svr8OwAAAc8"] [Tue Aug 18 13:08:17.712996 2026] [security2:error] [pid 167459:tid 167608] [client 20.25.139.174:4835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/function/function.php"] [unique_id "aoSDcWr_JutbFb-8svr8PAAAAaI"] [Tue Aug 18 13:08:17.730544 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:17.730833 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:17.732840 2026] [security2:error] [pid 167459:tid 167468] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSDcWr_JutbFb-8svr8PgAB0Qg"] [Tue Aug 18 13:08:17.787147 2026] [security2:error] [pid 167459:tid 167526] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDcWr_JutbFb-8svr8QAABn0I"] [Tue Aug 18 13:08:17.797403 2026] [autoindex:error] [pid 167459:tid 167695] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:17.815839 2026] [security2:error] [pid 167459:tid 167627] [client 52.139.47.57:24505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ultra.php"] [unique_id "aoSDcWr_JutbFb-8svr8QgAAAbU"] [Tue Aug 18 13:08:17.838751 2026] [security2:error] [pid 167459:tid 167691] [client 20.215.241.237:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/aa.php"] [unique_id "aoSDcWr_JutbFb-8svr8RAAAAfU"] [Tue Aug 18 13:08:17.842952 2026] [security2:error] [pid 167459:tid 167622] [client 158.23.17.4:44723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sm.php"] [unique_id "aoSDcWr_JutbFb-8svr8RQAAAbA"] [Tue Aug 18 13:08:17.874202 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:52909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/admin.php"] [unique_id "aoSDcWr_JutbFb-8svr8RgAAAdI"] [Tue Aug 18 13:08:17.883927 2026] [security2:error] [pid 167459:tid 167609] [client 197.184.64.235:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcWr_JutbFb-8svr8RwAAAaM"] [Tue Aug 18 13:08:17.884048 2026] [security2:error] [pid 167459:tid 167609] [client 197.184.64.235:42692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcWr_JutbFb-8svr8RwAAAaM"] [Tue Aug 18 13:08:17.901741 2026] [security2:error] [pid 167459:tid 167630] [client 213.35.127.232:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDcWr_JutbFb-8svr8SAAAAbg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:17.904517 2026] [security2:error] [pid 167459:tid 167623] [client 52.173.121.69:28303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDcWr_JutbFb-8svr8SQAAAbE"] [Tue Aug 18 13:08:17.923809 2026] [security2:error] [pid 167459:tid 167617] [client 4.232.151.198:16429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/php.php"] [unique_id "aoSDcWr_JutbFb-8svr8TAAAAas"] [Tue Aug 18 13:08:17.928038 2026] [security2:error] [pid 167459:tid 167704] [client 20.151.109.219:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/q.php"] [unique_id "aoSDcWr_JutbFb-8svr8TgAAAgI"] [Tue Aug 18 13:08:17.960525 2026] [security2:error] [pid 167459:tid 167688] [client 20.104.100.201:62678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/min.php"] [unique_id "aoSDcWr_JutbFb-8svr8TwAAAfI"] [Tue Aug 18 13:08:17.963311 2026] [security2:error] [pid 167459:tid 167681] [client 138.36.100.162:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcWr_JutbFb-8svr8UQAAAes"] [Tue Aug 18 13:08:17.963401 2026] [security2:error] [pid 167459:tid 167681] [client 138.36.100.162:43238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcWr_JutbFb-8svr8UQAAAes"] [Tue Aug 18 13:08:17.969630 2026] [security2:error] [pid 167459:tid 167492] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-content.php"] [unique_id "aoSDcWr_JutbFb-8svr8UgABmiA"] [Tue Aug 18 13:08:17.973071 2026] [security2:error] [pid 167459:tid 167671] [client 52.139.47.57:45779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/v9.php"] [unique_id "aoSDcWr_JutbFb-8svr8UwAAAeE"] [Tue Aug 18 13:08:17.985654 2026] [security2:error] [pid 167459:tid 167642] [client 172.202.39.151:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wk/index.php"] [unique_id "aoSDcWr_JutbFb-8svr8VQAAAcQ"] [Tue Aug 18 13:08:18.023574 2026] [security2:error] [pid 167459:tid 167525] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSDcmr_JutbFb-8svr8WAABtEE"] [Tue Aug 18 13:08:18.029250 2026] [security2:error] [pid 167459:tid 167662] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/function/function.php"] [unique_id "aoSDcmr_JutbFb-8svr8WQAAAdg"] [Tue Aug 18 13:08:18.029566 2026] [security2:error] [pid 167459:tid 167716] [client 20.106.102.5:45703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/jq.php"] [unique_id "aoSDcmr_JutbFb-8svr8WgAAAg4"] [Tue Aug 18 13:08:18.041433 2026] [security2:error] [pid 167459:tid 167628] [client 143.244.57.82:52644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSDcmr_JutbFb-8svr8WwAAAbY"] [Tue Aug 18 13:08:18.061610 2026] [autoindex:error] [pid 167459:tid 167635] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:18.088234 2026] [security2:error] [pid 167459:tid 167624] [client 20.163.43.14:15655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/404.php"] [unique_id "aoSDcmr_JutbFb-8svr8XQAAAbI"] [Tue Aug 18 13:08:18.090794 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/chosen.php"] [unique_id "aoSDcmr_JutbFb-8svr8XgAAAgU"] [Tue Aug 18 13:08:18.110881 2026] [security2:error] [pid 167459:tid 167710] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/system_log.php"] [unique_id "aoSDcmr_JutbFb-8svr8ZAAAAgg"] [Tue Aug 18 13:08:18.113966 2026] [security2:error] [pid 167459:tid 167629] [client 132.196.30.78:13093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/cv.php"] [unique_id "aoSDcmr_JutbFb-8svr8ZQAAAbc"] [Tue Aug 18 13:08:18.242443 2026] [security2:error] [pid 167459:tid 167706] [client 52.139.47.57:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/vv.php"] [unique_id "aoSDcmr_JutbFb-8svr8dAAAAgQ"] [Tue Aug 18 13:08:18.277879 2026] [security2:error] [pid 167459:tid 167660] [client 20.25.139.174:4819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/nw.php"] [unique_id "aoSDcmr_JutbFb-8svr8dQAAAdY"] [Tue Aug 18 13:08:18.315207 2026] [security2:error] [pid 167459:tid 167547] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/media.php"] [unique_id "aoSDcmr_JutbFb-8svr8eAAB-lc"] [Tue Aug 18 13:08:18.316294 2026] [security2:error] [pid 167459:tid 167668] [client 20.151.109.219:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xf.php"] [unique_id "aoSDcmr_JutbFb-8svr8eQAAAd4"] [Tue Aug 18 13:08:18.331493 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:18.331769 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:18.339632 2026] [security2:error] [pid 167459:tid 167678] [client 158.158.74.177:13811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/photo.php"] [unique_id "aoSDcmr_JutbFb-8svr8fAAAAeg"] [Tue Aug 18 13:08:18.352920 2026] [security2:error] [pid 167459:tid 167619] [client 20.106.102.5:45306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sys.php"] [unique_id "aoSDcmr_JutbFb-8svr8fgAAAa0"] [Tue Aug 18 13:08:18.363021 2026] [security2:error] [pid 167459:tid 167705] [client 172.202.39.151:39211] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/1.php"] [unique_id "aoSDcmr_JutbFb-8svr8fwAAAgM"] [Tue Aug 18 13:08:18.363123 2026] [security2:error] [pid 167459:tid 167705] [client 172.202.39.151:39211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/1.php"] [unique_id "aoSDcmr_JutbFb-8svr8fwAAAgM"] [Tue Aug 18 13:08:18.391507 2026] [security2:error] [pid 167459:tid 167692] [client 104.209.144.33:32691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8gwAAAfY"] [Tue Aug 18 13:08:18.394748 2026] [security2:error] [pid 167459:tid 167608] [client 40.74.65.169:37422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDcmr_JutbFb-8svr8hQAAAaI"] [Tue Aug 18 13:08:18.394876 2026] [security2:error] [pid 167459:tid 167682] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDcmr_JutbFb-8svr8hgAAAew"] [Tue Aug 18 13:08:18.395516 2026] [security2:error] [pid 167459:tid 167599] [client 20.104.100.201:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/load.php"] [unique_id "aoSDcmr_JutbFb-8svr8hwAAAZk"] [Tue Aug 18 13:08:18.400339 2026] [autoindex:error] [pid 167459:tid 167653] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:18.403599 2026] [security2:error] [pid 167459:tid 167641] [client 52.139.47.57:45806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/aaa.php"] [unique_id "aoSDcmr_JutbFb-8svr8iAAAAcM"] [Tue Aug 18 13:08:18.425611 2026] [security2:error] [pid 167459:tid 167655] [client 143.244.57.82:52660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSDcmr_JutbFb-8svr8igAAAdE"] [Tue Aug 18 13:08:18.444734 2026] [security2:error] [pid 167459:tid 167467] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDcmr_JutbFb-8svr8jAAB4gc"] [Tue Aug 18 13:08:18.466392 2026] [security2:error] [pid 167459:tid 167591] [client 20.163.43.14:15250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-login.php"] [unique_id "aoSDcmr_JutbFb-8svr8kwAAAZE"] [Tue Aug 18 13:08:18.508169 2026] [security2:error] [pid 167459:tid 167665] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8lQAAAds"] [Tue Aug 18 13:08:18.512347 2026] [security2:error] [pid 167459:tid 167648] [client 196.12.128.158:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDcmr_JutbFb-8svr8lwAAAco"] [Tue Aug 18 13:08:18.512528 2026] [security2:error] [pid 167459:tid 167648] [client 196.12.128.158:52043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDcmr_JutbFb-8svr8lwAAAco"] [Tue Aug 18 13:08:18.557583 2026] [security2:error] [pid 167459:tid 167631] [client 20.116.17.175:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8mgAAAbk"] [Tue Aug 18 13:08:18.573601 2026] [security2:error] [pid 167459:tid 167709] [client 4.232.151.198:30082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/php8.php"] [unique_id "aoSDcmr_JutbFb-8svr8nQAAAgc"] [Tue Aug 18 13:08:18.581459 2026] [security2:error] [pid 167459:tid 167620] [client 20.79.204.6:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSDcmr_JutbFb-8svr8ngAAAa4"] [Tue Aug 18 13:08:18.595955 2026] [autoindex:error] [pid 167459:tid 167642] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:18.605578 2026] [security2:error] [pid 167459:tid 167470] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/inso.php"] [unique_id "aoSDcmr_JutbFb-8svr8oAABrAo"] [Tue Aug 18 13:08:18.615481 2026] [security2:error] [pid 167459:tid 167626] [client 20.186.30.159:9850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDcmr_JutbFb-8svr8oQAAAbQ"] [Tue Aug 18 13:08:18.617431 2026] [security2:error] [pid 167459:tid 167659] [client 46.102.21.132:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcmr_JutbFb-8svr8ogAAAdU"] [Tue Aug 18 13:08:18.617568 2026] [security2:error] [pid 167459:tid 167659] [client 46.102.21.132:60981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDcmr_JutbFb-8svr8ogAAAdU"] [Tue Aug 18 13:08:18.628771 2026] [security2:error] [pid 167459:tid 167474] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSDcmr_JutbFb-8svr8pAACDg4"] [Tue Aug 18 13:08:18.680368 2026] [security2:error] [pid 167459:tid 167624] [client 20.106.102.5:45281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/pp.php"] [unique_id "aoSDcmr_JutbFb-8svr8pwAAAbI"] [Tue Aug 18 13:08:18.693031 2026] [security2:error] [pid 167459:tid 167597] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDcmr_JutbFb-8svr8qAAAAZc"] [Tue Aug 18 13:08:18.695889 2026] [security2:error] [pid 167459:tid 167676] [client 52.139.47.57:26656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/V5.php"] [unique_id "aoSDcmr_JutbFb-8svr8qQAAAeY"] [Tue Aug 18 13:08:18.717937 2026] [security2:error] [pid 167459:tid 167712] [client 20.226.36.136:25905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8rAAAAgo"] [Tue Aug 18 13:08:18.765257 2026] [security2:error] [pid 167459:tid 167646] [client 3.12.251.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "joanagaspar.com.br"] [uri "/"] [unique_id "aoSDcmr_JutbFb-8svr8rgAByGk"], referer: https://joanagaspar.com.br/ [Tue Aug 18 13:08:18.766465 2026] [security2:error] [pid 167459:tid 167625] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDcmr_JutbFb-8svr8rwAAAbM"] [Tue Aug 18 13:08:18.780525 2026] [security2:error] [pid 167459:tid 167633] [client 172.202.39.151:27862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8sgAAAbs"] [Tue Aug 18 13:08:18.783656 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:6312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/linkpreview/alfa.php"] [unique_id "aoSDcmr_JutbFb-8svr8swAAAdk"] [Tue Aug 18 13:08:18.785913 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:18.786169 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:18.806972 2026] [security2:error] [pid 167459:tid 167621] [client 20.163.43.14:15619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDcmr_JutbFb-8svr8tAAAAa8"] [Tue Aug 18 13:08:18.808533 2026] [security2:error] [pid 167459:tid 167561] [remote 20.100.169.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.aceleradigital.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDcmr_JutbFb-8svr8tQAB8WU"] [Tue Aug 18 13:08:18.809366 2026] [security2:error] [pid 167459:tid 167628] [client 20.25.139.174:4615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/xleet.php"] [unique_id "aoSDcmr_JutbFb-8svr8twAAAbY"] [Tue Aug 18 13:08:18.814374 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:6073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/rk2.php"] [unique_id "aoSDcmr_JutbFb-8svr8uAAAAe0"] [Tue Aug 18 13:08:18.821586 2026] [security2:error] [pid 167459:tid 167706] [client 143.244.57.82:52662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSDcmr_JutbFb-8svr8uQAAAgQ"] [Tue Aug 18 13:08:18.875051 2026] [security2:error] [pid 167459:tid 167619] [client 172.182.217.32:25616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/text/diff/renderer/install.php"] [unique_id "aoSDcmr_JutbFb-8svr8vQAAAa0"] [Tue Aug 18 13:08:18.878314 2026] [security2:error] [pid 167459:tid 167638] [client 132.196.30.78:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDcmr_JutbFb-8svr8vgAAAcA"] [Tue Aug 18 13:08:18.895827 2026] [security2:error] [pid 167459:tid 167498] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/shiny.php"] [unique_id "aoSDcmr_JutbFb-8svr8wAABqCY"] [Tue Aug 18 13:08:18.900473 2026] [security2:error] [pid 167459:tid 167689] [client 158.23.17.4:39167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/28.php"] [unique_id "aoSDcmr_JutbFb-8svr8wQAAAfM"] [Tue Aug 18 13:08:18.921943 2026] [security2:error] [pid 167459:tid 167608] [client 104.209.144.33:32670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDcmr_JutbFb-8svr8wwAAAaI"] [Tue Aug 18 13:08:18.922516 2026] [security2:error] [pid 167459:tid 167640] [client 213.35.127.232:61499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDcmr_JutbFb-8svr8xAAAAcI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:18.952511 2026] [autoindex:error] [pid 167459:tid 167653] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:18.961830 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.100.201:53306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDcmr_JutbFb-8svr80QAAAdE"] [Tue Aug 18 13:08:18.963744 2026] [security2:error] [pid 167459:tid 167666] [client 74.248.18.37:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/alfa.php"] [unique_id "aoSDcmr_JutbFb-8svr80wAAAdw"] [Tue Aug 18 13:08:18.976485 2026] [security2:error] [pid 167459:tid 167599] [client 3.12.251.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joanagaspar.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSDcmr_JutbFb-8svr8xQABmQY"], referer: https://joanagaspar.com.br/ [Tue Aug 18 13:08:18.995019 2026] [security2:error] [pid 167459:tid 167594] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/ok.php"] [unique_id "aoSDcmr_JutbFb-8svr82QAAAZQ"] [Tue Aug 18 13:08:19.007001 2026] [security2:error] [pid 167459:tid 167634] [client 20.106.102.5:45197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wqqs.php"] [unique_id "aoSDc2r_JutbFb-8svr82gAAAbw"] [Tue Aug 18 13:08:19.030115 2026] [security2:error] [pid 167459:tid 167665] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/abc.php"] [unique_id "aoSDc2r_JutbFb-8svr83gAAAds"] [Tue Aug 18 13:08:19.073507 2026] [security2:error] [pid 167459:tid 167678] [client 158.158.74.177:13789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-aa.php"] [unique_id "aoSDc2r_JutbFb-8svr9AgAAAeg"] [Tue Aug 18 13:08:19.120816 2026] [security2:error] [pid 167459:tid 167672] [client 52.139.47.57:32895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp-user.php"] [unique_id "aoSDc2r_JutbFb-8svr9EAAAAeI"] [Tue Aug 18 13:08:19.186561 2026] [security2:error] [pid 167459:tid 167492] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/403dd.php"] [unique_id "aoSDc2r_JutbFb-8svr9EQABriA"] [Tue Aug 18 13:08:19.214001 2026] [security2:error] [pid 167459:tid 167626] [client 20.226.36.136:34498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/first.php"] [unique_id "aoSDc2r_JutbFb-8svr9FAAAAbQ"] [Tue Aug 18 13:08:19.233239 2026] [security2:error] [pid 167459:tid 167704] [client 143.244.57.82:50506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSDc2r_JutbFb-8svr9FgAAAgI"] [Tue Aug 18 13:08:19.233821 2026] [security2:error] [pid 167459:tid 167617] [client 52.139.47.57:31697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/nux.php"] [unique_id "aoSDc2r_JutbFb-8svr9FwAAAas"] [Tue Aug 18 13:08:19.236228 2026] [security2:error] [pid 167459:tid 167659] [client 20.206.73.37:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/signon.php"] [unique_id "aoSDc2r_JutbFb-8svr9GAAAAdU"] [Tue Aug 18 13:08:19.237064 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:19.237304 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:19.252042 2026] [security2:error] [pid 167459:tid 167716] [client 104.209.144.33:32649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9GgAAAg4"] [Tue Aug 18 13:08:19.260849 2026] [autoindex:error] [pid 167459:tid 167662] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:19.269031 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ccou.php"] [unique_id "aoSDc2r_JutbFb-8svr9HQAAAgU"] [Tue Aug 18 13:08:19.281441 2026] [security2:error] [pid 167459:tid 167645] [client 49.145.211.146:9355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9DwAAAcc"] [Tue Aug 18 13:08:19.281563 2026] [security2:error] [pid 167459:tid 167645] [client 49.145.211.146:9355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9DwAAAcc"] [Tue Aug 18 13:08:19.285279 2026] [security2:error] [pid 167459:tid 167606] [client 4.232.151.198:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/plugins.php"] [unique_id "aoSDc2r_JutbFb-8svr9HwAAAaA"] [Tue Aug 18 13:08:19.287390 2026] [security2:error] [pid 167459:tid 167629] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/akcc.php"] [unique_id "aoSDc2r_JutbFb-8svr9IAAAAbc"] [Tue Aug 18 13:08:19.294656 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:48632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDc2r_JutbFb-8svr9IQAAAcw"] [Tue Aug 18 13:08:19.312306 2026] [security2:error] [pid 167459:tid 167632] [client 20.79.204.6:6008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDc2r_JutbFb-8svr9IgAAAbo"] [Tue Aug 18 13:08:19.331313 2026] [security2:error] [pid 167459:tid 167676] [client 20.106.102.5:45717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/clasa99.php"] [unique_id "aoSDc2r_JutbFb-8svr9JAAAAeY"] [Tue Aug 18 13:08:19.344444 2026] [security2:error] [pid 167459:tid 167630] [client 74.249.206.207:50535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/images.php"] [unique_id "aoSDc2r_JutbFb-8svr9JQAAAbg"] [Tue Aug 18 13:08:19.345204 2026] [security2:error] [pid 167459:tid 167712] [client 172.202.39.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cnascimentoassessoria.com"] [uri "/item.php"] [unique_id "aoSDc2r_JutbFb-8svr9JgAAAgo"] [Tue Aug 18 13:08:19.360195 2026] [security2:error] [pid 167459:tid 167642] [client 172.182.217.32:25540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/themes.php"] [unique_id "aoSDc2r_JutbFb-8svr9JwAAAcQ"] [Tue Aug 18 13:08:19.368644 2026] [security2:error] [pid 167459:tid 167652] [client 20.127.136.245:9273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/t.php"] [unique_id "aoSDc2r_JutbFb-8svr9KQAAAc4"] [Tue Aug 18 13:08:19.371182 2026] [security2:error] [pid 167459:tid 167611] [client 20.25.139.174:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp.php"] [unique_id "aoSDc2r_JutbFb-8svr9KgAAAaU"] [Tue Aug 18 13:08:19.385678 2026] [security2:error] [pid 167459:tid 167556] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9LQABsWA"] [Tue Aug 18 13:08:19.385849 2026] [security2:error] [pid 167459:tid 167623] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9LQABsWA"] [Tue Aug 18 13:08:19.394002 2026] [security2:error] [pid 167459:tid 167685] [client 52.173.121.69:50026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDc2r_JutbFb-8svr9LgAAAe8"] [Tue Aug 18 13:08:19.437446 2026] [security2:error] [pid 167459:tid 167663] [client 68.221.73.131:11085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDc2r_JutbFb-8svr9MwAAAdk"] [Tue Aug 18 13:08:19.462830 2026] [security2:error] [pid 167459:tid 167708] [client 132.196.30.78:13594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ws83.php"] [unique_id "aoSDc2r_JutbFb-8svr9NAAAAgY"] [Tue Aug 18 13:08:19.467198 2026] [security2:error] [pid 167459:tid 167690] [client 20.215.241.237:22362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/img.php"] [unique_id "aoSDc2r_JutbFb-8svr9NgAAAfQ"] [Tue Aug 18 13:08:19.478227 2026] [security2:error] [pid 167459:tid 167494] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/baba.php"] [unique_id "aoSDc2r_JutbFb-8svr9OAABryI"] [Tue Aug 18 13:08:19.522495 2026] [security2:error] [pid 167459:tid 167619] [client 20.116.17.175:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDc2r_JutbFb-8svr9RQAAAa0"] [Tue Aug 18 13:08:19.535470 2026] [authz_core:error] [pid 167459:tid 167504] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:19.535715 2026] [authz_core:error] [pid 167459:tid 167504] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:19.540636 2026] [security2:error] [pid 167459:tid 167625] [client 52.139.47.57:31555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDc2r_JutbFb-8svr9UAAAAbM"] [Tue Aug 18 13:08:19.548668 2026] [security2:error] [pid 167459:tid 167682] [client 20.163.43.14:15647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wso.php"] [unique_id "aoSDc2r_JutbFb-8svr9UgAAAew"] [Tue Aug 18 13:08:19.549018 2026] [security2:error] [pid 167459:tid 167608] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wk/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9UwAAAaI"] [Tue Aug 18 13:08:19.559316 2026] [security2:error] [pid 167459:tid 167655] [client 158.23.17.4:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/m.php"] [unique_id "aoSDc2r_JutbFb-8svr9VQAAAdE"] [Tue Aug 18 13:08:19.592872 2026] [autoindex:error] [pid 167459:tid 167602] [client 52.141.58.175:4314] AH01276: Cannot serve directory /home4/l6ghyuw9/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:19.608907 2026] [security2:error] [pid 167459:tid 167610] [client 40.74.65.169:36984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDc2r_JutbFb-8svr9YwAAAaQ"] [Tue Aug 18 13:08:19.635281 2026] [ssl:error] [pid 167459:tid 167714] [client 13.219.121.241:27510] AH02032: Hostname srv254.prodns.com.br (default host as no SNI was provided) and hostname cpcalendars.boavista.acecdlunai.com.br provided via HTTP have no compatible SSL setup for policy 'secure' [Tue Aug 18 13:08:19.644678 2026] [security2:error] [pid 167459:tid 167609] [client 20.226.36.136:51939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9ZgAAAaM"] [Tue Aug 18 13:08:19.648342 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:15170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/info.php"] [unique_id "aoSDc2r_JutbFb-8svr9aAAAAfo"] [Tue Aug 18 13:08:19.649555 2026] [security2:error] [pid 167459:tid 167648] [client 104.209.144.33:31264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDc2r_JutbFb-8svr9aQAAAco"] [Tue Aug 18 13:08:19.650128 2026] [security2:error] [pid 167459:tid 167656] [client 143.244.57.82:50508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSDc2r_JutbFb-8svr9agAAAdI"] [Tue Aug 18 13:08:19.659307 2026] [security2:error] [pid 167459:tid 167615] [client 20.106.102.5:45158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/666.php"] [unique_id "aoSDc2r_JutbFb-8svr9awAAAak"] [Tue Aug 18 13:08:19.716370 2026] [security2:error] [pid 167459:tid 167706] [client 158.158.74.177:13792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/d.php"] [unique_id "aoSDc2r_JutbFb-8svr9bgAAAgQ"] [Tue Aug 18 13:08:19.717269 2026] [security2:error] [pid 167459:tid 167681] [client 172.202.39.151:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9bwAAAes"] [Tue Aug 18 13:08:19.725707 2026] [security2:error] [pid 167459:tid 167620] [client 20.104.100.201:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ty.php"] [unique_id "aoSDc2r_JutbFb-8svr9cAAAAa4"] [Tue Aug 18 13:08:19.738416 2026] [security2:error] [pid 167459:tid 167626] [client 20.65.69.59:22022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/defaul.php"] [unique_id "aoSDc2r_JutbFb-8svr9cgAAAbQ"] [Tue Aug 18 13:08:19.765626 2026] [autoindex:error] [pid 167459:tid 167659] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:19.767617 2026] [security2:error] [pid 167459:tid 167524] [remote 119.13.212.254:41391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "infoprodutores.com"] [uri "/wp-json/pys-facebook/v1/event"] [unique_id "aoSDc2r_JutbFb-8svr9dwABtUA"], referer: https://infoprodutores.com/ [Tue Aug 18 13:08:19.770184 2026] [security2:error] [pid 167459:tid 167579] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/site.php"] [unique_id "aoSDc2r_JutbFb-8svr9eAACBXc"] [Tue Aug 18 13:08:19.773767 2026] [security2:error] [pid 167459:tid 167698] [client 20.250.13.23:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9eQAAAfw"] [Tue Aug 18 13:08:19.803436 2026] [security2:error] [pid 167459:tid 167664] [client 103.120.71.157:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9fwAAAdo"] [Tue Aug 18 13:08:19.803583 2026] [security2:error] [pid 167459:tid 167664] [client 103.120.71.157:59906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDc2r_JutbFb-8svr9fwAAAdo"] [Tue Aug 18 13:08:19.804315 2026] [security2:error] [pid 167459:tid 167606] [client 20.7.73.61:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.1td.com.br"] [uri "/1.php"] [unique_id "aoSDc2r_JutbFb-8svr9gAAAAaA"] [Tue Aug 18 13:08:19.804385 2026] [security2:error] [pid 167459:tid 167606] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/1.php"] [unique_id "aoSDc2r_JutbFb-8svr9gAAAAaA"] [Tue Aug 18 13:08:19.813580 2026] [security2:error] [pid 167459:tid 167640] [client 74.248.18.37:30769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-font-utils.php"] [unique_id "aoSDc2r_JutbFb-8svr9ggAAAcI"] [Tue Aug 18 13:08:19.851318 2026] [security2:error] [pid 167459:tid 167597] [client 20.104.100.201:62607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/crgio.php"] [unique_id "aoSDc2r_JutbFb-8svr9hgAAAZc"] [Tue Aug 18 13:08:19.876630 2026] [security2:error] [pid 167459:tid 167703] [client 172.182.217.32:4087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/themes/plugin-install.php"] [unique_id "aoSDc2r_JutbFb-8svr9iQAAAgE"] [Tue Aug 18 13:08:19.912802 2026] [security2:error] [pid 167459:tid 167688] [client 20.25.139.174:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/155.php"] [unique_id "aoSDc2r_JutbFb-8svr9igAAAfI"] [Tue Aug 18 13:08:19.927415 2026] [security2:error] [pid 167459:tid 167685] [client 20.163.43.14:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/sf.php"] [unique_id "aoSDc2r_JutbFb-8svr9jAAAAe8"] [Tue Aug 18 13:08:19.934207 2026] [security2:error] [pid 167459:tid 167613] [client 213.35.127.232:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDc2r_JutbFb-8svr9jQAAAac"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:19.950402 2026] [security2:error] [pid 167459:tid 167618] [client 20.79.204.6:5710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSDc2r_JutbFb-8svr9jgAAAaw"] [Tue Aug 18 13:08:19.957172 2026] [security2:error] [pid 167459:tid 167650] [client 52.139.47.57:19498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp.php"] [unique_id "aoSDc2r_JutbFb-8svr9jwAAAcw"] [Tue Aug 18 13:08:19.957875 2026] [security2:error] [pid 167459:tid 167633] [client 104.209.144.33:25303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDc2r_JutbFb-8svr9kAAAAbs"] [Tue Aug 18 13:08:19.961941 2026] [security2:error] [pid 167459:tid 167589] [client 52.173.121.69:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDc2r_JutbFb-8svr9kQAAAY8"] [Tue Aug 18 13:08:19.966033 2026] [security2:error] [pid 167459:tid 167704] [client 4.232.151.198:48497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/post.php"] [unique_id "aoSDc2r_JutbFb-8svr9kgAAAgI"] [Tue Aug 18 13:08:20.000308 2026] [security2:error] [pid 167459:tid 167621] [client 20.106.102.5:45275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/thui.php"] [unique_id "aoSDc2r_JutbFb-8svr9lAAAAa8"] [Tue Aug 18 13:08:20.036730 2026] [security2:error] [pid 167459:tid 167693] [client 20.151.109.219:33475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gb.php"] [unique_id "aoSDdGr_JutbFb-8svr9oQAAAfc"] [Tue Aug 18 13:08:20.053986 2026] [security2:error] [pid 167459:tid 167661] [client 143.244.57.82:50512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdGr_JutbFb-8svr9owAAAdc"] [Tue Aug 18 13:08:20.059850 2026] [security2:error] [pid 167459:tid 167593] [client 52.139.47.57:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/uploads/phpimage.php"] [unique_id "aoSDdGr_JutbFb-8svr9pAAAAZM"] [Tue Aug 18 13:08:20.060291 2026] [security2:error] [pid 167459:tid 167701] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/x/index.php"] [unique_id "aoSDdGr_JutbFb-8svr9pQAAAf8"] [Tue Aug 18 13:08:20.061508 2026] [security2:error] [pid 167459:tid 167533] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDdGr_JutbFb-8svr9pgABkEk"] [Tue Aug 18 13:08:20.106511 2026] [autoindex:error] [pid 167459:tid 167682] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:20.126221 2026] [security2:error] [pid 167459:tid 167677] [client 158.23.17.4:44732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nl.php"] [unique_id "aoSDdGr_JutbFb-8svr9qgAAAec"] [Tue Aug 18 13:08:20.140674 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:20.140945 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:20.191700 2026] [security2:error] [pid 167459:tid 167652] [client 132.196.30.78:20455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/atex1.php"] [unique_id "aoSDdGr_JutbFb-8svr9rwAAAc4"] [Tue Aug 18 13:08:20.238844 2026] [security2:error] [pid 167459:tid 167678] [client 20.104.100.201:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDdGr_JutbFb-8svr9sQAAAeg"] [Tue Aug 18 13:08:20.241014 2026] [security2:error] [pid 167459:tid 167612] [client 20.215.241.237:42638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/222.php"] [unique_id "aoSDdGr_JutbFb-8svr9sgAAAaY"] [Tue Aug 18 13:08:20.310811 2026] [security2:error] [pid 167459:tid 167626] [client 20.163.43.14:15650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/index/function.php"] [unique_id "aoSDdGr_JutbFb-8svr9twAAAbQ"] [Tue Aug 18 13:08:20.321518 2026] [security2:error] [pid 167459:tid 167617] [client 20.171.51.14:26019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pm.php"] [unique_id "aoSDdGr_JutbFb-8svr9uAAAAas"] [Tue Aug 18 13:08:20.324396 2026] [security2:error] [pid 167459:tid 167670] [client 20.106.102.5:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/agg.php"] [unique_id "aoSDdGr_JutbFb-8svr9uQAAAeA"] [Tue Aug 18 13:08:20.324952 2026] [security2:error] [pid 167459:tid 167659] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDdGr_JutbFb-8svr9ugAAAdU"] [Tue Aug 18 13:08:20.326666 2026] [security2:error] [pid 167459:tid 167683] [client 213.202.253.4:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sdmultimarcaspe.com.br"] [uri "/wp-content/schallfuns.php"] [unique_id "aoSDdGr_JutbFb-8svr9uwAAAe0"], referer: www.google.com [Tue Aug 18 13:08:20.341567 2026] [security2:error] [pid 167459:tid 167599] [client 158.158.74.177:13779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSDdGr_JutbFb-8svr9vAAAAZk"] [Tue Aug 18 13:08:20.352499 2026] [security2:error] [pid 167459:tid 167502] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/cabs.php"] [unique_id "aoSDdGr_JutbFb-8svr9vQABsio"] [Tue Aug 18 13:08:20.361883 2026] [security2:error] [pid 167459:tid 167698] [client 158.23.17.4:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kt.php"] [unique_id "aoSDdGr_JutbFb-8svr9vgAAAfw"] [Tue Aug 18 13:08:20.362817 2026] [security2:error] [pid 167459:tid 167714] [client 172.182.217.32:4098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "aoSDdGr_JutbFb-8svr9vwAAAgw"] [Tue Aug 18 13:08:20.374812 2026] [security2:error] [pid 167459:tid 167642] [client 204.8.96.106:33382] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDc2r_JutbFb-8svr9iAAAAcQ"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:08:20.379711 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:17370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/worksec.php"] [unique_id "aoSDdGr_JutbFb-8svr9wQAAAak"] [Tue Aug 18 13:08:20.392939 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.18.37:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/edit.php"] [unique_id "aoSDdGr_JutbFb-8svr9wgAAAd8"] [Tue Aug 18 13:08:20.408227 2026] [security2:error] [pid 167459:tid 167692] [client 104.209.144.33:25301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDdGr_JutbFb-8svr9xAAAAfY"] [Tue Aug 18 13:08:20.440406 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:20.440672 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:20.442118 2026] [security2:error] [pid 167459:tid 167632] [client 143.244.57.82:50524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdGr_JutbFb-8svr9yAAAAbo"] [Tue Aug 18 13:08:20.478301 2026] [security2:error] [pid 167459:tid 167620] [client 20.25.139.174:4486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/96i.php"] [unique_id "aoSDdGr_JutbFb-8svr9ywAAAa4"] [Tue Aug 18 13:08:20.487731 2026] [autoindex:error] [pid 167459:tid 167703] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:20.491536 2026] [security2:error] [pid 167459:tid 167707] [client 52.139.47.57:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/s.php"] [unique_id "aoSDdGr_JutbFb-8svr9zQAAAgU"] [Tue Aug 18 13:08:20.491699 2026] [security2:error] [pid 167459:tid 167671] [client 4.232.151.198:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/666.php"] [unique_id "aoSDdGr_JutbFb-8svr9zgAAAeE"] [Tue Aug 18 13:08:20.495220 2026] [security2:error] [pid 167459:tid 167623] [client 20.104.100.201:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDdGr_JutbFb-8svr9zwAAAbE"] [Tue Aug 18 13:08:20.523786 2026] [security2:error] [pid 167459:tid 167613] [client 20.116.17.175:52895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/cong.php"] [unique_id "aoSDdGr_JutbFb-8svr90AAAAac"] [Tue Aug 18 13:08:20.585594 2026] [security2:error] [pid 167459:tid 167704] [client 52.173.121.69:28336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDdGr_JutbFb-8svr90gAAAgI"] [Tue Aug 18 13:08:20.586259 2026] [security2:error] [pid 167459:tid 167663] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/as.php"] [unique_id "aoSDdGr_JutbFb-8svr90wAAAdk"] [Tue Aug 18 13:08:20.594225 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:30089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/r.php"] [unique_id "aoSDdGr_JutbFb-8svr91AAAAgg"] [Tue Aug 18 13:08:20.599137 2026] [security2:error] [pid 167459:tid 167606] [client 20.79.204.6:5697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDdGr_JutbFb-8svr91QAAAaA"] [Tue Aug 18 13:08:20.613207 2026] [security2:error] [pid 167459:tid 167673] [client 20.186.30.159:9849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/av.php"] [unique_id "aoSDdGr_JutbFb-8svr91gAAAeM"] [Tue Aug 18 13:08:20.638224 2026] [security2:error] [pid 167459:tid 167645] [client 20.250.13.23:26111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/vx.php"] [unique_id "aoSDdGr_JutbFb-8svr91wAAAcc"] [Tue Aug 18 13:08:20.641823 2026] [security2:error] [pid 167459:tid 167549] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/insc.php"] [unique_id "aoSDdGr_JutbFb-8svr92AABlVk"] [Tue Aug 18 13:08:20.645907 2026] [security2:error] [pid 167459:tid 167661] [client 20.163.43.14:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/edit.php"] [unique_id "aoSDdGr_JutbFb-8svr92gAAAdc"] [Tue Aug 18 13:08:20.656438 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/erty.php"] [unique_id "aoSDdGr_JutbFb-8svr92wAAAc0"] [Tue Aug 18 13:08:20.701368 2026] [autoindex:error] [pid 167459:tid 167705] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:20.704825 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dot.php"] [unique_id "aoSDdGr_JutbFb-8svr93gAAAbU"] [Tue Aug 18 13:08:20.741333 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:20.741604 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:20.784690 2026] [security2:error] [pid 167459:tid 167591] [client 20.226.36.136:63837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDdGr_JutbFb-8svr94wAAAZE"] [Tue Aug 18 13:08:20.787822 2026] [security2:error] [pid 167459:tid 167679] [client 5.31.227.224:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdGr_JutbFb-8svr95AAAAek"] [Tue Aug 18 13:08:20.787900 2026] [security2:error] [pid 167459:tid 167679] [client 5.31.227.224:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdGr_JutbFb-8svr95AAAAek"] [Tue Aug 18 13:08:20.801099 2026] [security2:error] [pid 167459:tid 167605] [client 104.209.144.33:32684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDdGr_JutbFb-8svr95QAAAZ8"] [Tue Aug 18 13:08:20.804814 2026] [security2:error] [pid 167459:tid 167590] [client 52.139.47.57:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDdGr_JutbFb-8svr95gAAAZA"] [Tue Aug 18 13:08:20.829508 2026] [security2:error] [pid 167459:tid 167694] [client 40.74.65.169:7155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/simple.php"] [unique_id "aoSDdGr_JutbFb-8svr96AAAAfg"] [Tue Aug 18 13:08:20.842582 2026] [security2:error] [pid 167459:tid 167654] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDdGr_JutbFb-8svr96QAAAdA"] [Tue Aug 18 13:08:20.853285 2026] [security2:error] [pid 167459:tid 167678] [client 143.244.57.82:50530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdGr_JutbFb-8svr96gAAAeg"] [Tue Aug 18 13:08:20.878716 2026] [security2:error] [pid 167459:tid 167625] [client 172.182.217.32:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/widgets/min.php"] [unique_id "aoSDdGr_JutbFb-8svr96wAAAbM"] [Tue Aug 18 13:08:20.901494 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdGr_JutbFb-8svr97QAAAZw"] [Tue Aug 18 13:08:20.901668 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:55984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdGr_JutbFb-8svr97QAAAZw"] [Tue Aug 18 13:08:20.905239 2026] [security2:error] [pid 167459:tid 167709] [client 20.215.241.237:47839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/key.php"] [unique_id "aoSDdGr_JutbFb-8svr97gAAAgc"] [Tue Aug 18 13:08:20.906907 2026] [security2:error] [pid 167459:tid 167682] [client 52.139.47.57:15898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/test.php"] [unique_id "aoSDdGr_JutbFb-8svr97wAAAew"] [Tue Aug 18 13:08:20.932424 2026] [security2:error] [pid 167459:tid 167543] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/file.php"] [unique_id "aoSDdGr_JutbFb-8svr98QAB4FM"] [Tue Aug 18 13:08:20.946813 2026] [security2:error] [pid 167459:tid 167621] [client 213.35.127.232:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDdGr_JutbFb-8svr99AAAAa8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:20.952482 2026] [security2:error] [pid 167459:tid 167668] [client 132.196.30.78:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDdGr_JutbFb-8svr99QAAAd4"] [Tue Aug 18 13:08:20.971206 2026] [autoindex:error] [pid 167459:tid 167711] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:20.987249 2026] [security2:error] [pid 167459:tid 167641] [client 20.106.102.5:45734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/mini.php"] [unique_id "aoSDdGr_JutbFb-8svr99wAAAcM"] [Tue Aug 18 13:08:20.994902 2026] [authz_core:error] [pid 167459:tid 167691] [client 192.178.4.134:37309] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:20.995152 2026] [authz_core:error] [pid 167459:tid 167691] [client 192.178.4.134:37309] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:21.005514 2026] [security2:error] [pid 167459:tid 167666] [client 158.158.74.177:13718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSDdWr_JutbFb-8svr9-QAAAdw"] [Tue Aug 18 13:08:21.006835 2026] [security2:error] [pid 167459:tid 167642] [client 204.8.96.106:33382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDc2r_JutbFb-8svr9iAAAAcQ"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:08:21.015869 2026] [security2:error] [pid 167459:tid 167608] [client 74.248.18.37:6308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/admin_panel.php"] [unique_id "aoSDdWr_JutbFb-8svr9-wAAAaI"] [Tue Aug 18 13:08:21.018175 2026] [security2:error] [pid 167459:tid 167639] [client 102.213.179.104:58108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr9_AAAAcE"] [Tue Aug 18 13:08:21.018297 2026] [security2:error] [pid 167459:tid 167639] [client 102.213.179.104:58108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr9_AAAAcE"] [Tue Aug 18 13:08:21.098621 2026] [security2:error] [pid 167459:tid 167712] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSDdWr_JutbFb-8svr9_wAAAgo"] [Tue Aug 18 13:08:21.119978 2026] [security2:error] [pid 167459:tid 167658] [client 104.209.144.33:32690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDdWr_JutbFb-8svr-AQAAAdQ"] [Tue Aug 18 13:08:21.125092 2026] [security2:error] [pid 167459:tid 167611] [client 20.104.100.201:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/005.php"] [unique_id "aoSDdWr_JutbFb-8svr-AgAAAaU"] [Tue Aug 18 13:08:21.127167 2026] [security2:error] [pid 167459:tid 167706] [client 20.25.139.174:4801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/as.php"] [unique_id "aoSDdWr_JutbFb-8svr-AwAAAgQ"] [Tue Aug 18 13:08:21.153120 2026] [security2:error] [pid 167459:tid 167600] [client 74.248.18.37:36685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/elp.php"] [unique_id "aoSDdWr_JutbFb-8svr-BAAAAZo"] [Tue Aug 18 13:08:21.161346 2026] [security2:error] [pid 167459:tid 167614] [client 86.120.159.145:24031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-BQAAAag"] [Tue Aug 18 13:08:21.161542 2026] [security2:error] [pid 167459:tid 167614] [client 86.120.159.145:24031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-BQAAAag"] [Tue Aug 18 13:08:21.183401 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/68.php"] [unique_id "aoSDdWr_JutbFb-8svr-BgAAAaE"] [Tue Aug 18 13:08:21.188617 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.36.136:43562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDdWr_JutbFb-8svr-BwAAAc8"] [Tue Aug 18 13:08:21.224805 2026] [security2:error] [pid 167459:tid 167630] [client 52.139.47.57:17059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp-signin.php"] [unique_id "aoSDdWr_JutbFb-8svr-CQAAAbg"] [Tue Aug 18 13:08:21.227016 2026] [security2:error] [pid 167459:tid 167606] [client 20.163.43.14:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDdWr_JutbFb-8svr-CgAAAaA"] [Tue Aug 18 13:08:21.236155 2026] [security2:error] [pid 167459:tid 167491] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/dex.php"] [unique_id "aoSDdWr_JutbFb-8svr-CwAB-R8"] [Tue Aug 18 13:08:21.260975 2026] [security2:error] [pid 167459:tid 167673] [client 52.173.121.69:36565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDdWr_JutbFb-8svr-DgAAAeM"] [Tue Aug 18 13:08:21.265302 2026] [security2:error] [pid 167459:tid 167675] [client 143.244.57.82:50544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdWr_JutbFb-8svr-DwAAAeU"] [Tue Aug 18 13:08:21.272395 2026] [security2:error] [pid 167459:tid 167664] [client 4.232.151.198:16443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/radio.php"] [unique_id "aoSDdWr_JutbFb-8svr-EAAAAdo"] [Tue Aug 18 13:08:21.301502 2026] [autoindex:error] [pid 167459:tid 167714] [client 20.79.204.6:6082] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:21.314260 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sid3.php"] [unique_id "aoSDdWr_JutbFb-8svr-EwAAAc0"] [Tue Aug 18 13:08:21.319507 2026] [security2:error] [pid 167459:tid 167618] [client 52.139.47.57:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/5.php"] [unique_id "aoSDdWr_JutbFb-8svr-FAAAAaw"] [Tue Aug 18 13:08:21.341924 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:21.342187 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:21.362413 2026] [security2:error] [pid 167459:tid 167705] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDdWr_JutbFb-8svr-FwAAAgM"] [Tue Aug 18 13:08:21.374341 2026] [security2:error] [pid 167459:tid 167589] [client 172.182.217.32:4140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/wp-cron.php"] [unique_id "aoSDdWr_JutbFb-8svr-GAAAAY8"] [Tue Aug 18 13:08:21.390262 2026] [security2:error] [pid 167459:tid 167655] [client 20.171.51.14:15990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/dr.php"] [unique_id "aoSDdWr_JutbFb-8svr-GwAAAdE"] [Tue Aug 18 13:08:21.418780 2026] [security2:error] [pid 167459:tid 167604] [client 104.209.144.33:32676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDdWr_JutbFb-8svr-HAAAAZ4"] [Tue Aug 18 13:08:21.503089 2026] [security2:error] [pid 167459:tid 167656] [client 20.79.204.6:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/about.php"] [unique_id "aoSDdWr_JutbFb-8svr-IgAAAdI"] [Tue Aug 18 13:08:21.531985 2026] [security2:error] [pid 167459:tid 167493] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/key.php"] [unique_id "aoSDdWr_JutbFb-8svr-JAAB1iE"] [Tue Aug 18 13:08:21.532995 2026] [security2:error] [pid 167459:tid 167612] [client 20.104.100.201:9539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/v2.php"] [unique_id "aoSDdWr_JutbFb-8svr-JQAAAaY"] [Tue Aug 18 13:08:21.570856 2026] [security2:error] [pid 167459:tid 167681] [client 4.232.151.198:36502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/ws54.php"] [unique_id "aoSDdWr_JutbFb-8svr-JgAAAes"] [Tue Aug 18 13:08:21.576012 2026] [security2:error] [pid 167459:tid 167696] [client 20.104.100.201:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/css.php"] [unique_id "aoSDdWr_JutbFb-8svr-JwAAAfo"] [Tue Aug 18 13:08:21.577926 2026] [security2:error] [pid 167459:tid 167682] [client 20.163.43.14:15622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-good.php"] [unique_id "aoSDdWr_JutbFb-8svr-KAAAAew"] [Tue Aug 18 13:08:21.578760 2026] [security2:error] [pid 167459:tid 167626] [client 20.226.36.136:41477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDdWr_JutbFb-8svr-KQAAAbQ"] [Tue Aug 18 13:08:21.641102 2026] [security2:error] [pid 167459:tid 167668] [client 20.106.102.5:45173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/moon.php"] [unique_id "aoSDdWr_JutbFb-8svr-KwAAAd4"] [Tue Aug 18 13:08:21.642475 2026] [security2:error] [pid 167459:tid 167648] [client 52.139.47.57:32869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDdWr_JutbFb-8svr-LAAAAco"] [Tue Aug 18 13:08:21.642756 2026] [security2:error] [pid 167459:tid 167599] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDdWr_JutbFb-8svr-LQAAAZk"] [Tue Aug 18 13:08:21.645337 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:21.645586 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:21.660965 2026] [security2:error] [pid 167459:tid 167605] [client 158.158.74.177:13765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSDdWr_JutbFb-8svr-LwAAAZ8"] [Tue Aug 18 13:08:21.676765 2026] [security2:error] [pid 167459:tid 167680] [client 20.250.13.23:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wap.php"] [unique_id "aoSDdWr_JutbFb-8svr-MAAAAeo"] [Tue Aug 18 13:08:21.680471 2026] [security2:error] [pid 167459:tid 167641] [client 143.244.57.82:50546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdWr_JutbFb-8svr-MQAAAcM"] [Tue Aug 18 13:08:21.689225 2026] [security2:error] [pid 167459:tid 167654] [client 20.25.139.174:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/min.php"] [unique_id "aoSDdWr_JutbFb-8svr-MgAAAdA"] [Tue Aug 18 13:08:21.717244 2026] [security2:error] [pid 167459:tid 167615] [client 158.23.17.4:40445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gc.php"] [unique_id "aoSDdWr_JutbFb-8svr-MwAAAak"] [Tue Aug 18 13:08:21.742613 2026] [security2:error] [pid 167459:tid 167670] [client 52.139.47.57:15219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/meta.php"] [unique_id "aoSDdWr_JutbFb-8svr-NQAAAeA"] [Tue Aug 18 13:08:21.797699 2026] [security2:error] [pid 167459:tid 167709] [client 74.248.18.37:30782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/customize/about.php"] [unique_id "aoSDdWr_JutbFb-8svr-NwAAAgc"] [Tue Aug 18 13:08:21.809893 2026] [security2:error] [pid 167459:tid 167671] [client 37.40.227.74:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-OAAAAeE"] [Tue Aug 18 13:08:21.810020 2026] [security2:error] [pid 167459:tid 167671] [client 37.40.227.74:56885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-OAAAAeE"] [Tue Aug 18 13:08:21.815253 2026] [security2:error] [pid 167459:tid 167688] [client 20.226.36.136:37218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDdWr_JutbFb-8svr-OQAAAfI"] [Tue Aug 18 13:08:21.818977 2026] [security2:error] [pid 167459:tid 167659] [client 132.196.30.78:13628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/w.php"] [unique_id "aoSDdWr_JutbFb-8svr-OgAAAdU"] [Tue Aug 18 13:08:21.822936 2026] [security2:error] [pid 167459:tid 167481] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/kir.php"] [unique_id "aoSDdWr_JutbFb-8svr-OwAB1BU"] [Tue Aug 18 13:08:21.833854 2026] [security2:error] [pid 167459:tid 167592] [client 20.215.241.237:51143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/chosen.php"] [unique_id "aoSDdWr_JutbFb-8svr-PAAAAZI"] [Tue Aug 18 13:08:21.863432 2026] [security2:error] [pid 167459:tid 167698] [client 172.182.217.32:25639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/wp-links-opml.php"] [unique_id "aoSDdWr_JutbFb-8svr-PQAAAfw"] [Tue Aug 18 13:08:21.868046 2026] [security2:error] [pid 167459:tid 167707] [client 223.185.37.47:1308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-PgAAAgU"] [Tue Aug 18 13:08:21.868156 2026] [security2:error] [pid 167459:tid 167707] [client 223.185.37.47:1308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDdWr_JutbFb-8svr-PgAAAgU"] [Tue Aug 18 13:08:21.883360 2026] [security2:error] [pid 167459:tid 167646] [client 104.209.144.33:24886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDdWr_JutbFb-8svr-QAAAAcg"] [Tue Aug 18 13:08:21.893151 2026] [security2:error] [pid 167459:tid 167613] [client 68.221.73.131:10673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDdWr_JutbFb-8svr-QQAAAac"] [Tue Aug 18 13:08:21.898407 2026] [security2:error] [pid 167459:tid 167715] [client 20.104.100.201:53371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wkl.php"] [unique_id "aoSDdWr_JutbFb-8svr-QgAAAg0"] [Tue Aug 18 13:08:21.909503 2026] [autoindex:error] [pid 167459:tid 167607] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:21.937617 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:2448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/randkeyword.php7"] [unique_id "aoSDdWr_JutbFb-8svr-RwAAAfY"] [Tue Aug 18 13:08:21.939746 2026] [security2:error] [pid 167459:tid 167606] [client 52.173.121.69:28341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDdWr_JutbFb-8svr-SQAAAaA"] [Tue Aug 18 13:08:21.946138 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:21.946412 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:21.962216 2026] [security2:error] [pid 167459:tid 167621] [client 213.35.127.232:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDdWr_JutbFb-8svr-SgAAAa8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:21.962487 2026] [security2:error] [pid 167459:tid 167673] [client 20.106.102.5:45759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ms.php"] [unique_id "aoSDdWr_JutbFb-8svr-SwAAAeM"] [Tue Aug 18 13:08:22.004037 2026] [security2:error] [pid 167459:tid 167714] [client 40.74.65.169:7082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/chosen.php"] [unique_id "aoSDdmr_JutbFb-8svr-TgAAAgw"] [Tue Aug 18 13:08:22.012770 2026] [security2:error] [pid 167459:tid 167651] [client 20.116.17.175:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/term.php"] [unique_id "aoSDdmr_JutbFb-8svr-TwAAAc0"] [Tue Aug 18 13:08:22.057348 2026] [security2:error] [pid 167459:tid 167627] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDdmr_JutbFb-8svr-UQAAAbU"] [Tue Aug 18 13:08:22.089223 2026] [security2:error] [pid 167459:tid 167679] [client 143.244.57.82:50552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdmr_JutbFb-8svr-VQAAAek"] [Tue Aug 18 13:08:22.114429 2026] [security2:error] [pid 167459:tid 167575] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/nofile.php"] [unique_id "aoSDdmr_JutbFb-8svr-WAAB_XM"] [Tue Aug 18 13:08:22.119362 2026] [security2:error] [pid 167459:tid 167687] [client 74.7.228.42:48232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.unicorh-pametrizacao.3xsolutions.com"] [uri "/cgi-sys/404.html"] [unique_id "aoSDdmr_JutbFb-8svr-VwAB8UQ"] [Tue Aug 18 13:08:22.125354 2026] [security2:error] [pid 167459:tid 167694] [client 158.23.17.4:5017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/jl.php"] [unique_id "aoSDdmr_JutbFb-8svr-WQAAAfg"] [Tue Aug 18 13:08:22.148237 2026] [security2:error] [pid 167459:tid 167633] [client 20.79.204.6:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDdmr_JutbFb-8svr-WgAAAbs"] [Tue Aug 18 13:08:22.163882 2026] [security2:error] [pid 167459:tid 167700] [client 52.139.47.57:15888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/files/add_evento.php"] [unique_id "aoSDdmr_JutbFb-8svr-WwAAAf4"] [Tue Aug 18 13:08:22.247131 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:22.247558 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:22.248841 2026] [autoindex:error] [pid 167459:tid 167681] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:22.269940 2026] [security2:error] [pid 167459:tid 167617] [client 20.163.43.14:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/tes.php"] [unique_id "aoSDdmr_JutbFb-8svr-YQAAAas"] [Tue Aug 18 13:08:22.284407 2026] [security2:error] [pid 167459:tid 167668] [client 20.106.102.5:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wsws.php"] [unique_id "aoSDdmr_JutbFb-8svr-YwAAAd4"] [Tue Aug 18 13:08:22.315715 2026] [security2:error] [pid 167459:tid 167711] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/an.php"] [unique_id "aoSDdmr_JutbFb-8svr-ZQAAAgk"] [Tue Aug 18 13:08:22.318936 2026] [security2:error] [pid 167459:tid 167591] [client 158.158.74.177:13709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDdmr_JutbFb-8svr-ZgAAAZE"] [Tue Aug 18 13:08:22.338974 2026] [security2:error] [pid 167459:tid 167641] [client 20.104.100.201:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSDdmr_JutbFb-8svr-ZwAAAcM"] [Tue Aug 18 13:08:22.367455 2026] [security2:error] [pid 167459:tid 167666] [client 52.139.47.57:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/ws.php"] [unique_id "aoSDdmr_JutbFb-8svr-aQAAAdw"] [Tue Aug 18 13:08:22.369173 2026] [security2:error] [pid 167459:tid 167612] [client 132.196.30.78:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/archive.php"] [unique_id "aoSDdmr_JutbFb-8svr-awAAAaY"] [Tue Aug 18 13:08:22.370641 2026] [security2:error] [pid 167459:tid 167674] [client 172.182.217.32:4136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSDdmr_JutbFb-8svr-bAAAAeQ"] [Tue Aug 18 13:08:22.403323 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDdmr_JutbFb-8svr-bQAAAcw"] [Tue Aug 18 13:08:22.408624 2026] [security2:error] [pid 167459:tid 167559] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fling.php"] [unique_id "aoSDdmr_JutbFb-8svr-bgABwWM"] [Tue Aug 18 13:08:22.442461 2026] [security2:error] [pid 167459:tid 167629] [client 20.25.139.174:4599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/php8.php"] [unique_id "aoSDdmr_JutbFb-8svr-bwAAAbc"] [Tue Aug 18 13:08:22.444185 2026] [security2:error] [pid 167459:tid 167670] [client 104.209.144.33:32694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDdmr_JutbFb-8svr-cAAAAeA"] [Tue Aug 18 13:08:22.483072 2026] [security2:error] [pid 167459:tid 167620] [client 143.244.57.82:50568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdmr_JutbFb-8svr-cQAAAa4"] [Tue Aug 18 13:08:22.532021 2026] [autoindex:error] [pid 167459:tid 167611] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:22.532357 2026] [security2:error] [pid 167459:tid 167637] [client 20.65.69.59:21160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/twin.php"] [unique_id "aoSDdmr_JutbFb-8svr-cwAAAb8"] [Tue Aug 18 13:08:22.546517 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:22.546838 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:22.556023 2026] [security2:error] [pid 167459:tid 167703] [client 20.215.241.237:16564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/wpxml.php"] [unique_id "aoSDdmr_JutbFb-8svr-dQAAAgE"] [Tue Aug 18 13:08:22.586312 2026] [security2:error] [pid 167459:tid 167646] [client 20.151.109.219:36335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/jp.php"] [unique_id "aoSDdmr_JutbFb-8svr-eQAAAcg"] [Tue Aug 18 13:08:22.587710 2026] [security2:error] [pid 167459:tid 167596] [client 52.139.47.57:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/upandsize.php"] [unique_id "aoSDdmr_JutbFb-8svr-egAAAZY"] [Tue Aug 18 13:08:22.587762 2026] [security2:error] [pid 167459:tid 167613] [client 52.173.121.69:36597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDdmr_JutbFb-8svr-ewAAAac"] [Tue Aug 18 13:08:22.591145 2026] [security2:error] [pid 167459:tid 167607] [client 20.116.17.175:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/black.php"] [unique_id "aoSDdmr_JutbFb-8svr-fAAAAaE"] [Tue Aug 18 13:08:22.605459 2026] [security2:error] [pid 167459:tid 167692] [client 20.106.102.5:45143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/motu.php"] [unique_id "aoSDdmr_JutbFb-8svr-fgAAAfY"] [Tue Aug 18 13:08:22.624825 2026] [security2:error] [pid 167459:tid 167621] [client 20.186.30.159:9818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/images.php"] [unique_id "aoSDdmr_JutbFb-8svr-fwAAAa8"] [Tue Aug 18 13:08:22.632149 2026] [security2:error] [pid 167459:tid 167628] [client 158.23.17.4:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/uq.php"] [unique_id "aoSDdmr_JutbFb-8svr-gAAAAbY"] [Tue Aug 18 13:08:22.632149 2026] [security2:error] [pid 167459:tid 167590] [client 4.232.151.198:48448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/red.php"] [unique_id "aoSDdmr_JutbFb-8svr-gQAAAZA"] [Tue Aug 18 13:08:22.651158 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDdmr_JutbFb-8svr-ggAAAcc"] [Tue Aug 18 13:08:22.653267 2026] [security2:error] [pid 167459:tid 167595] [client 20.163.43.14:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/files/index.php"] [unique_id "aoSDdmr_JutbFb-8svr-gwAAAZU"] [Tue Aug 18 13:08:22.698710 2026] [security2:error] [pid 167459:tid 167547] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/zoo1.php"] [unique_id "aoSDdmr_JutbFb-8svr-hAABrVc"] [Tue Aug 18 13:08:22.705317 2026] [security2:error] [pid 167459:tid 167603] [client 20.206.73.37:65161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/file61.php"] [unique_id "aoSDdmr_JutbFb-8svr-hQAAAZ0"] [Tue Aug 18 13:08:22.719592 2026] [security2:error] [pid 167459:tid 167705] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/404.php"] [unique_id "aoSDdmr_JutbFb-8svr-hgAAAgM"] [Tue Aug 18 13:08:22.789085 2026] [security2:error] [pid 167459:tid 167693] [client 52.139.47.57:26624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/wsa.php"] [unique_id "aoSDdmr_JutbFb-8svr-jAAAAfc"] [Tue Aug 18 13:08:22.803438 2026] [autoindex:error] [pid 167459:tid 167694] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:22.817658 2026] [security2:error] [pid 167459:tid 167659] [client 74.248.18.37:6331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSDdmr_JutbFb-8svr-jgAAAdU"] [Tue Aug 18 13:08:22.836057 2026] [security2:error] [pid 167459:tid 167690] [client 20.79.204.6:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSDdmr_JutbFb-8svr-kAAAAfQ"] [Tue Aug 18 13:08:22.845900 2026] [authz_core:error] [pid 167459:tid 167490] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:22.846155 2026] [authz_core:error] [pid 167459:tid 167490] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:22.851518 2026] [authz_core:error] [pid 167459:tid 167484] [remote 57.141.22.113:33878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:22.851795 2026] [authz_core:error] [pid 167459:tid 167484] [remote 57.141.22.113:33878] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:22.857211 2026] [security2:error] [pid 167459:tid 167651] [client 172.182.217.32:25578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-rss.php"] [unique_id "aoSDdmr_JutbFb-8svr-lQAAAc0"] [Tue Aug 18 13:08:22.867119 2026] [security2:error] [pid 167459:tid 167681] [client 20.104.100.201:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/az.php"] [unique_id "aoSDdmr_JutbFb-8svr-lgAAAes"] [Tue Aug 18 13:08:22.872279 2026] [security2:error] [pid 167459:tid 167626] [client 104.209.144.33:25291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDdmr_JutbFb-8svr-lwAAAbQ"] [Tue Aug 18 13:08:22.877168 2026] [security2:error] [pid 167459:tid 167615] [client 20.250.13.23:51377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDdmr_JutbFb-8svr-mAAAAak"] [Tue Aug 18 13:08:22.886598 2026] [security2:error] [pid 167459:tid 167617] [client 143.244.57.82:50576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "riovacinas.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSDdmr_JutbFb-8svr-mgAAAas"] [Tue Aug 18 13:08:22.939064 2026] [security2:error] [pid 167459:tid 167668] [client 172.202.39.151:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/as.php"] [unique_id "aoSDdmr_JutbFb-8svr-nAAAAd4"] [Tue Aug 18 13:08:22.941226 2026] [security2:error] [pid 167459:tid 167648] [client 20.106.102.5:45144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fff.php"] [unique_id "aoSDdmr_JutbFb-8svr-nQAAAco"] [Tue Aug 18 13:08:22.945990 2026] [security2:error] [pid 167459:tid 167599] [client 20.186.30.159:9730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ops.php"] [unique_id "aoSDdmr_JutbFb-8svr-ngAAAZk"] [Tue Aug 18 13:08:22.975526 2026] [security2:error] [pid 167459:tid 167669] [client 158.158.74.177:13703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDdmr_JutbFb-8svr-oAAAAd8"] [Tue Aug 18 13:08:22.982851 2026] [security2:error] [pid 167459:tid 167664] [client 213.35.127.232:62370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDdmr_JutbFb-8svr-ogAAAdo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:22.989065 2026] [security2:error] [pid 167459:tid 167570] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/zoo2.php"] [unique_id "aoSDdmr_JutbFb-8svr-owABn24"] [Tue Aug 18 13:08:23.009601 2026] [security2:error] [pid 167459:tid 167682] [client 52.139.47.57:38071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/cong.php"] [unique_id "aoSDd2r_JutbFb-8svr-pAAAAew"] [Tue Aug 18 13:08:23.020361 2026] [security2:error] [pid 167459:tid 167609] [client 20.25.139.174:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDd2r_JutbFb-8svr-pwAAAaM"] [Tue Aug 18 13:08:23.037792 2026] [security2:error] [pid 167459:tid 167612] [client 20.226.36.136:41571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDd2r_JutbFb-8svr-qAAAAaY"] [Tue Aug 18 13:08:23.067650 2026] [security2:error] [pid 167459:tid 167639] [client 20.163.43.14:15741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDd2r_JutbFb-8svr-qQAAAcE"] [Tue Aug 18 13:08:23.106995 2026] [autoindex:error] [pid 167459:tid 167671] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:23.115883 2026] [security2:error] [pid 167459:tid 167592] [client 51.68.107.156:34595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSDd2r_JutbFb-8svr-rAAAAZI"] [Tue Aug 18 13:08:23.116003 2026] [security2:error] [pid 167459:tid 167592] [client 51.68.107.156:34595] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "natupedras.com.br"] [uri "/robots.txt"] [unique_id "aoSDd2r_JutbFb-8svr-rAAAAZI"] [Tue Aug 18 13:08:23.143010 2026] [security2:error] [pid 167459:tid 167624] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-login.php"] [unique_id "aoSDdmr_JutbFb-8svr-oQAAAbI"] [Tue Aug 18 13:08:23.143311 2026] [security2:error] [pid 167459:tid 167698] [client 52.173.121.69:36594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDd2r_JutbFb-8svr-rgAAAfw"] [Tue Aug 18 13:08:23.149500 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:23.149766 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:23.187729 2026] [security2:error] [pid 167459:tid 167646] [client 20.65.98.162:50759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/xyn.php"] [unique_id "aoSDd2r_JutbFb-8svr-swAAAcg"] [Tue Aug 18 13:08:23.194496 2026] [security2:error] [pid 167459:tid 167596] [client 20.215.241.237:21843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/file1221.php"] [unique_id "aoSDd2r_JutbFb-8svr-tgAAAZY"] [Tue Aug 18 13:08:23.209795 2026] [security2:error] [pid 167459:tid 167616] [client 52.139.47.57:19512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/w.php"] [unique_id "aoSDd2r_JutbFb-8svr-uQAAAao"] [Tue Aug 18 13:08:23.265995 2026] [security2:error] [pid 167459:tid 167590] [client 20.106.102.5:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/66.php"] [unique_id "aoSDd2r_JutbFb-8svr-vAAAAZA"] [Tue Aug 18 13:08:23.271219 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:16411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/release.php"] [unique_id "aoSDd2r_JutbFb-8svr-vQAAAcw"] [Tue Aug 18 13:08:23.291017 2026] [security2:error] [pid 167459:tid 167473] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/org.php"] [unique_id "aoSDd2r_JutbFb-8svr-vgAB5Q0"] [Tue Aug 18 13:08:23.300066 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/tq.php"] [unique_id "aoSDd2r_JutbFb-8svr-wAAAAcc"] [Tue Aug 18 13:08:23.324115 2026] [security2:error] [pid 167459:tid 167638] [client 104.209.144.33:31272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDd2r_JutbFb-8svr-wQAAAcA"] [Tue Aug 18 13:08:23.353652 2026] [security2:error] [pid 167459:tid 167623] [client 172.182.217.32:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-setting.php"] [unique_id "aoSDd2r_JutbFb-8svr-wwAAAbE"] [Tue Aug 18 13:08:23.374299 2026] [security2:error] [pid 167459:tid 167679] [client 40.74.65.169:7128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/als.php"] [unique_id "aoSDd2r_JutbFb-8svr-xAAAAek"] [Tue Aug 18 13:08:23.399501 2026] [security2:error] [pid 167459:tid 167713] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDd2r_JutbFb-8svr-xwAAAgs"] [Tue Aug 18 13:08:23.402041 2026] [security2:error] [pid 167459:tid 167632] [client 20.104.100.201:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/z43agz.php"] [unique_id "aoSDd2r_JutbFb-8svr-yAAAAbo"] [Tue Aug 18 13:08:23.415102 2026] [security2:error] [pid 167459:tid 167694] [client 20.163.43.14:15239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/images/images/about.php"] [unique_id "aoSDd2r_JutbFb-8svr-ygAAAfg"] [Tue Aug 18 13:08:23.433646 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/file.php"] [unique_id "aoSDd2r_JutbFb-8svr-ywAAAfo"] [Tue Aug 18 13:08:23.449170 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:23.449436 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:23.479194 2026] [security2:error] [pid 167459:tid 167700] [client 158.23.17.4:20409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ww.php"] [unique_id "aoSDd2r_JutbFb-8svr-zwAAAf4"] [Tue Aug 18 13:08:23.498932 2026] [autoindex:error] [pid 167459:tid 167621] [client 20.79.204.6:5960] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:23.501504 2026] [security2:error] [pid 167459:tid 167614] [client 132.196.30.78:2900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/bless.php"] [unique_id "aoSDd2r_JutbFb-8svr-0gAAAag"] [Tue Aug 18 13:08:23.577685 2026] [security2:error] [pid 167459:tid 167707] [client 74.248.18.37:28406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDd2r_JutbFb-8svr-1QAAAgU"] [Tue Aug 18 13:08:23.579082 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:35430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/add-venue-ru.php"] [unique_id "aoSDd2r_JutbFb-8svr-1gAAAec"] [Tue Aug 18 13:08:23.581110 2026] [security2:error] [pid 167459:tid 167599] [client 20.116.17.175:52882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/as.php"] [unique_id "aoSDd2r_JutbFb-8svr-2AAAAZk"] [Tue Aug 18 13:08:23.582257 2026] [autoindex:error] [pid 167459:tid 167668] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:23.586837 2026] [security2:error] [pid 167459:tid 167693] [client 20.25.139.174:4831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/222.php"] [unique_id "aoSDd2r_JutbFb-8svr-2QAAAfc"] [Tue Aug 18 13:08:23.587341 2026] [security2:error] [pid 167459:tid 167522] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/imageskir.php"] [unique_id "aoSDd2r_JutbFb-8svr-2gAB3z4"] [Tue Aug 18 13:08:23.594009 2026] [security2:error] [pid 167459:tid 167605] [client 20.106.102.5:45284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/g.php"] [unique_id "aoSDd2r_JutbFb-8svr-2wAAAZ8"] [Tue Aug 18 13:08:23.603058 2026] [security2:error] [pid 167459:tid 167711] [client 20.226.36.136:41581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tiagoveiculos91.com.br"] [uri "/images/security.php"] [unique_id "aoSDd2r_JutbFb-8svr-3AAAAgk"] [Tue Aug 18 13:08:23.606959 2026] [security2:error] [pid 167459:tid 167594] [client 158.158.74.177:13800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/abc.php"] [unique_id "aoSDd2r_JutbFb-8svr-3QAAAZQ"] [Tue Aug 18 13:08:23.624512 2026] [security2:error] [pid 167459:tid 167682] [client 104.209.144.33:31254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDd2r_JutbFb-8svr-3gAAAew"] [Tue Aug 18 13:08:23.656830 2026] [security2:error] [pid 167459:tid 167665] [client 52.139.47.57:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/x.php"] [unique_id "aoSDd2r_JutbFb-8svr-3wAAAds"] [Tue Aug 18 13:08:23.682779 2026] [security2:error] [pid 167459:tid 167662] [client 62.101.160.240:58285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.160.101.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ledline.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDd2r_JutbFb-8svr-0wAAAdg"], referer: http://ledline.net.br/contato/ [Tue Aug 18 13:08:23.697633 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:38351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/cv.php"] [unique_id "aoSDd2r_JutbFb-8svr-5AAAAcQ"] [Tue Aug 18 13:08:23.702617 2026] [security2:error] [pid 167459:tid 167639] [client 20.79.204.6:5960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDd2r_JutbFb-8svr-5gAAAcE"] [Tue Aug 18 13:08:23.752820 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:23.753085 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:23.753227 2026] [security2:error] [pid 167459:tid 167631] [client 20.163.43.14:15264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDd2r_JutbFb-8svr-6QAAAbk"] [Tue Aug 18 13:08:23.795259 2026] [security2:error] [pid 167459:tid 167678] [client 20.104.100.201:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/epinyins.php"] [unique_id "aoSDd2r_JutbFb-8svr-8QAAAeg"] [Tue Aug 18 13:08:23.852412 2026] [security2:error] [pid 167459:tid 167670] [client 52.139.47.57:5932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/mail.php"] [unique_id "aoSDd2r_JutbFb-8svr-9QAAAeA"] [Tue Aug 18 13:08:23.877875 2026] [security2:error] [pid 167459:tid 167525] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/indexo.php"] [unique_id "aoSDd2r_JutbFb-8svr-9wAB_0E"] [Tue Aug 18 13:08:23.891438 2026] [security2:error] [pid 167459:tid 167672] [client 4.232.151.198:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/function/function.php"] [unique_id "aoSDd2r_JutbFb-8svr--QAAAeI"] [Tue Aug 18 13:08:23.894297 2026] [autoindex:error] [pid 167459:tid 167628] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:23.926770 2026] [security2:error] [pid 167459:tid 167645] [client 20.215.241.237:31937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/nox.php"] [unique_id "aoSDd2r_JutbFb-8svr--gAAAcc"] [Tue Aug 18 13:08:23.931818 2026] [security2:error] [pid 167459:tid 167703] [client 20.106.102.5:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/x7.php"] [unique_id "aoSDd2r_JutbFb-8svr-_AAAAgE"] [Tue Aug 18 13:08:23.933359 2026] [security2:error] [pid 167459:tid 167611] [client 20.127.136.245:1330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/index/function.php"] [unique_id "aoSDd2r_JutbFb-8svr-_QAAAaU"] [Tue Aug 18 13:08:23.945212 2026] [security2:error] [pid 167459:tid 167705] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wso.php"] [unique_id "aoSDd2r_JutbFb-8svr-_gAAAgM"] [Tue Aug 18 13:08:23.965365 2026] [security2:error] [pid 167459:tid 167655] [client 20.215.241.237:39359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDd2r_JutbFb-8svr_AAAAAdE"] [Tue Aug 18 13:08:23.981229 2026] [security2:error] [pid 167459:tid 167685] [client 4.232.151.198:16392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/reop3.php"] [unique_id "aoSDd2r_JutbFb-8svr_AQAAAe8"] [Tue Aug 18 13:08:24.000763 2026] [security2:error] [pid 167459:tid 167591] [client 213.35.127.232:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDd2r_JutbFb-8svr_AwAAAZE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:24.040938 2026] [security2:error] [pid 167459:tid 167694] [client 104.209.144.33:31267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/first.php"] [unique_id "aoSDeGr_JutbFb-8svr_BgAAAfg"] [Tue Aug 18 13:08:24.073595 2026] [security2:error] [pid 167459:tid 167673] [client 149.34.210.141:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_CQAAAeM"] [Tue Aug 18 13:08:24.085260 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/xx.php"] [unique_id "aoSDeGr_JutbFb-8svr_CgAAAaQ"] [Tue Aug 18 13:08:24.086018 2026] [security2:error] [pid 167459:tid 167657] [client 20.206.73.37:65169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/copypaths.php"] [unique_id "aoSDeGr_JutbFb-8svr_CwAAAdM"] [Tue Aug 18 13:08:24.089717 2026] [security2:error] [pid 167459:tid 167690] [client 20.163.43.14:15731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/rip.php"] [unique_id "aoSDeGr_JutbFb-8svr_DAAAAfQ"] [Tue Aug 18 13:08:24.117210 2026] [security2:error] [pid 167459:tid 167710] [client 40.74.65.169:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/nox.php"] [unique_id "aoSDeGr_JutbFb-8svr_DQAAAgg"] [Tue Aug 18 13:08:24.149887 2026] [security2:error] [pid 167459:tid 167627] [client 20.25.139.174:4497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDeGr_JutbFb-8svr_EAAAAbU"] [Tue Aug 18 13:08:24.168572 2026] [security2:error] [pid 167459:tid 167485] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSDeGr_JutbFb-8svr_EgACBRk"] [Tue Aug 18 13:08:24.170504 2026] [autoindex:error] [pid 167459:tid 167648] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:24.200046 2026] [security2:error] [pid 167459:tid 167659] [client 132.196.30.78:13116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/sagax1.php"] [unique_id "aoSDeGr_JutbFb-8svr_FQAAAdU"] [Tue Aug 18 13:08:24.201460 2026] [security2:error] [pid 167459:tid 167605] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/sf.php"] [unique_id "aoSDeGr_JutbFb-8svr_FgAAAZ8"] [Tue Aug 18 13:08:24.203936 2026] [security2:error] [pid 167459:tid 167594] [client 20.104.100.201:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/3.php"] [unique_id "aoSDeGr_JutbFb-8svr_FwAAAZQ"] [Tue Aug 18 13:08:24.248604 2026] [security2:error] [pid 167459:tid 167632] [client 158.158.74.177:13696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/sf.php"] [unique_id "aoSDeGr_JutbFb-8svr_JAAAAbo"] [Tue Aug 18 13:08:24.257126 2026] [security2:error] [pid 167459:tid 167709] [client 20.106.102.5:45283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/god.php"] [unique_id "aoSDeGr_JutbFb-8svr_QAAAAgc"] [Tue Aug 18 13:08:24.258762 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.18.37:30768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/rishi/db.php"] [unique_id "aoSDeGr_JutbFb-8svr_QQAAAc4"] [Tue Aug 18 13:08:24.269941 2026] [security2:error] [pid 167459:tid 167626] [client 52.139.47.57:38055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/angstroms.php"] [unique_id "aoSDeGr_JutbFb-8svr_QgAAAbQ"] [Tue Aug 18 13:08:24.310168 2026] [security2:error] [pid 167459:tid 167696] [client 74.248.18.37:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/666.php"] [unique_id "aoSDeGr_JutbFb-8svr_QwAAAfo"] [Tue Aug 18 13:08:24.340184 2026] [security2:error] [pid 167459:tid 167673] [client 149.34.210.141:53274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_CQAAAeM"] [Tue Aug 18 13:08:24.353938 2026] [security2:error] [pid 167459:tid 167592] [client 20.186.30.159:9795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/coffexium.php"] [unique_id "aoSDeGr_JutbFb-8svr_RgAAAZI"] [Tue Aug 18 13:08:24.356258 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:24.356546 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:24.386703 2026] [security2:error] [pid 167459:tid 167698] [client 20.215.241.237:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDeGr_JutbFb-8svr_SAAAAfw"] [Tue Aug 18 13:08:24.387863 2026] [security2:error] [pid 167459:tid 167629] [client 158.23.17.4:7351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/un.php"] [unique_id "aoSDeGr_JutbFb-8svr_SQAAAbc"] [Tue Aug 18 13:08:24.404703 2026] [security2:error] [pid 167459:tid 167711] [client 20.79.204.6:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSDeGr_JutbFb-8svr_SgAAAgk"] [Tue Aug 18 13:08:24.422589 2026] [autoindex:error] [pid 167459:tid 167674] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:24.454687 2026] [security2:error] [pid 167459:tid 167667] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/index/function.php"] [unique_id "aoSDeGr_JutbFb-8svr_TQAAAd0"] [Tue Aug 18 13:08:24.458278 2026] [security2:error] [pid 167459:tid 167606] [client 172.213.243.2:48345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDeGr_JutbFb-8svr_TgAAAaA"] [Tue Aug 18 13:08:24.460703 2026] [security2:error] [pid 167459:tid 167513] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSDeGr_JutbFb-8svr_UAAB_zU"] [Tue Aug 18 13:08:24.476590 2026] [security2:error] [pid 167459:tid 167661] [client 20.116.17.175:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/pucci.php"] [unique_id "aoSDeGr_JutbFb-8svr_UwAAAdc"] [Tue Aug 18 13:08:24.482045 2026] [lsapi:error] [pid 123784:tid 124044] [client 201.32.74.208:57062] [host pensamentosimperfeitos.com.br] Error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(15337): ReceiveAckHdr: timeout 300 is exceeded [Tue Aug 18 13:08:24.508342 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:20557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_VgAAAe0"] [Tue Aug 18 13:08:24.508869 2026] [security2:error] [pid 167459:tid 167526] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_XgAB5UI"] [Tue Aug 18 13:08:24.508988 2026] [security2:error] [pid 167459:tid 167675] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_XgAB5UI"] [Tue Aug 18 13:08:24.520963 2026] [security2:error] [pid 167459:tid 167611] [client 172.202.39.151:39229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDeGr_JutbFb-8svr_XwAAAaU"] [Tue Aug 18 13:08:24.569784 2026] [security2:error] [pid 167459:tid 167679] [client 20.206.73.37:65160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/bless6.php"] [unique_id "aoSDeGr_JutbFb-8svr_fQAAAek"] [Tue Aug 18 13:08:24.583998 2026] [security2:error] [pid 167459:tid 167593] [client 20.106.102.5:45148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ebahvhhh.php"] [unique_id "aoSDeGr_JutbFb-8svr_fgAAAZM"] [Tue Aug 18 13:08:24.616756 2026] [security2:error] [pid 167459:tid 167621] [client 20.215.241.237:16550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/akismet.php"] [unique_id "aoSDeGr_JutbFb-8svr_gQAAAa8"] [Tue Aug 18 13:08:24.647576 2026] [security2:error] [pid 167459:tid 167615] [client 20.163.43.14:15703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_hgAAAak"] [Tue Aug 18 13:08:24.655970 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:24.656212 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:24.661245 2026] [security2:error] [pid 167459:tid 167715] [client 4.232.151.198:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/robots.php"] [unique_id "aoSDeGr_JutbFb-8svr_iQAAAg0"] [Tue Aug 18 13:08:24.685926 2026] [security2:error] [pid 167459:tid 167589] [client 52.139.47.57:5643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/architect.php"] [unique_id "aoSDeGr_JutbFb-8svr_jAAAAY8"] [Tue Aug 18 13:08:24.709267 2026] [security2:error] [pid 167459:tid 167594] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/edit.php"] [unique_id "aoSDeGr_JutbFb-8svr_owAAAZQ"] [Tue Aug 18 13:08:24.710364 2026] [security2:error] [pid 167459:tid 167692] [client 20.250.13.23:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/bgymj.php"] [unique_id "aoSDeGr_JutbFb-8svr_pAAAAfY"] [Tue Aug 18 13:08:24.714122 2026] [security2:error] [pid 167459:tid 167638] [client 20.25.139.174:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/info.php"] [unique_id "aoSDeGr_JutbFb-8svr_pQAAAcA"] [Tue Aug 18 13:08:24.723350 2026] [security2:error] [pid 167459:tid 167699] [client 20.65.69.59:1295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/new2.php"] [unique_id "aoSDeGr_JutbFb-8svr_pgAAAf0"] [Tue Aug 18 13:08:24.750850 2026] [security2:error] [pid 167459:tid 167477] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/.admin.php"] [unique_id "aoSDeGr_JutbFb-8svr_qAABmhE"] [Tue Aug 18 13:08:24.785861 2026] [autoindex:error] [pid 167459:tid 167604] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:24.875297 2026] [security2:error] [pid 167459:tid 167666] [client 20.104.100.201:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/load.php"] [unique_id "aoSDeGr_JutbFb-8svr_sQAAAdw"] [Tue Aug 18 13:08:24.875330 2026] [security2:error] [pid 167459:tid 167702] [client 132.196.30.78:20417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wpc.php"] [unique_id "aoSDeGr_JutbFb-8svr_sAAAAgA"] [Tue Aug 18 13:08:24.891396 2026] [security2:error] [pid 167459:tid 167676] [client 2602:ffe4:8:1001::4:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/pe/camaragibe/alto-da-boa-vista/img/rua-do-panama-alto-da-boa-vista-camaragibe-pe.webp"] [unique_id "aoSDeGr_JutbFb-8svr_swAAAeY"], referer: https://www.icep.com.br/livrocep/pe/camaragibe/alto-da-boa-vista/rua-do-panama-cep-54759197/ [Tue Aug 18 13:08:24.892210 2026] [security2:error] [pid 167459:tid 167696] [client 158.23.17.4:20365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/32.php"] [unique_id "aoSDeGr_JutbFb-8svr_tAAAAfo"] [Tue Aug 18 13:08:24.898928 2026] [security2:error] [pid 167459:tid 167640] [client 158.158.74.177:14228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/chosen.php"] [unique_id "aoSDeGr_JutbFb-8svr_tQAAAcI"] [Tue Aug 18 13:08:24.905120 2026] [security2:error] [pid 167459:tid 167597] [client 20.106.102.5:45149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/8.php"] [unique_id "aoSDeGr_JutbFb-8svr_tgAAAZc"] [Tue Aug 18 13:08:24.929834 2026] [security2:error] [pid 167459:tid 167658] [client 172.213.243.2:14410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDeGr_JutbFb-8svr_uQAAAdQ"] [Tue Aug 18 13:08:24.951461 2026] [security2:error] [pid 167459:tid 167680] [client 52.139.47.57:19500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iguabagreen.com.br"] [uri "/y.php"] [unique_id "aoSDeGr_JutbFb-8svr_0gAAAeo"] [Tue Aug 18 13:08:24.957117 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:24.957416 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:24.968520 2026] [security2:error] [pid 167459:tid 167592] [client 20.215.241.237:59732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/media.php"] [unique_id "aoSDeGr_JutbFb-8svr_3QAAAZI"] [Tue Aug 18 13:08:24.980662 2026] [security2:error] [pid 167459:tid 167460] [remote 178.156.200.16:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marqimagem.com.br"] [uri "/wp-login.php"] [unique_id "aoSDeGr_JutbFb-8svr_3gABvwA"] [Tue Aug 18 13:08:24.986350 2026] [security2:error] [pid 167459:tid 167634] [client 74.248.18.37:6291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/seoo/wsoyanz1.php"] [unique_id "aoSDeGr_JutbFb-8svr_3wAAAbw"] [Tue Aug 18 13:08:24.987765 2026] [security2:error] [pid 167459:tid 167678] [client 20.163.43.14:15690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/moon.php"] [unique_id "aoSDeGr_JutbFb-8svr_4AAAAeg"] [Tue Aug 18 13:08:24.988159 2026] [security2:error] [pid 167459:tid 167663] [client 20.104.100.201:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/log.php"] [unique_id "aoSDeGr_JutbFb-8svr_4QAAAdk"] [Tue Aug 18 13:08:25.013364 2026] [security2:error] [pid 167459:tid 167668] [client 213.35.127.232:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDeWr_JutbFb-8svr_5QAAAd4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:25.014740 2026] [security2:error] [pid 167459:tid 167607] [client 52.173.121.69:36551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDeWr_JutbFb-8svr_5gAAAaE"] [Tue Aug 18 13:08:25.032257 2026] [security2:error] [pid 167459:tid 167609] [client 157.20.138.62:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svr_6QAAAaM"] [Tue Aug 18 13:08:25.033390 2026] [security2:error] [pid 167459:tid 167609] [client 157.20.138.62:56953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svr_6QAAAaM"] [Tue Aug 18 13:08:25.042052 2026] [security2:error] [pid 167459:tid 167509] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wsomini.php"] [unique_id "aoSDeWr_JutbFb-8svr_6gAB4DE"] [Tue Aug 18 13:08:25.051835 2026] [security2:error] [pid 167459:tid 167667] [client 40.74.65.169:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file59.php"] [unique_id "aoSDeWr_JutbFb-8svr_7AAAAd0"] [Tue Aug 18 13:08:25.067147 2026] [autoindex:error] [pid 167459:tid 167606] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:25.096100 2026] [security2:error] [pid 167459:tid 167590] [client 158.23.17.4:7315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/evil.php"] [unique_id "aoSDeWr_JutbFb-8svr_8QAAAZA"] [Tue Aug 18 13:08:25.104797 2026] [security2:error] [pid 167459:tid 167645] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDeWr_JutbFb-8svr_8wAAAcc"] [Tue Aug 18 13:08:25.115079 2026] [security2:error] [pid 167459:tid 167618] [client 52.139.47.57:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/subirfoto.php"] [unique_id "aoSDeWr_JutbFb-8svr_9AAAAaw"] [Tue Aug 18 13:08:25.115870 2026] [security2:error] [pid 167459:tid 167630] [client 20.79.204.6:6013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSDeWr_JutbFb-8svr_9QAAAbg"] [Tue Aug 18 13:08:25.118877 2026] [security2:error] [pid 167459:tid 167683] [client 104.209.144.33:32665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDeWr_JutbFb-8svr_9gAAAe0"] [Tue Aug 18 13:08:25.186441 2026] [security2:error] [pid 167459:tid 167591] [client 158.23.17.4:15807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/mo.php"] [unique_id "aoSDeWr_JutbFb-8svr_-QAAAZE"] [Tue Aug 18 13:08:25.228269 2026] [security2:error] [pid 167459:tid 167610] [client 20.106.102.5:45239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/koiy.php"] [unique_id "aoSDeWr_JutbFb-8svr_-gAAAaQ"] [Tue Aug 18 13:08:25.246813 2026] [security2:error] [pid 167459:tid 167669] [client 4.232.151.198:41189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/nw.php"] [unique_id "aoSDeWr_JutbFb-8svr__AAAAd8"] [Tue Aug 18 13:08:25.257651 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:25.257926 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:25.282933 2026] [security2:error] [pid 167459:tid 167675] [client 20.25.139.174:4850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/a.php"] [unique_id "aoSDeWr_JutbFb-8svr__gAAAeU"] [Tue Aug 18 13:08:25.291482 2026] [autoindex:error] [pid 167459:tid 167603] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:25.318419 2026] [security2:error] [pid 167459:tid 167617] [client 20.116.17.175:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wicked.php"] [unique_id "aoSDeWr_JutbFb-8svoABgAAAas"] [Tue Aug 18 13:08:25.323033 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:30142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/root.php"] [unique_id "aoSDeWr_JutbFb-8svoACAAAAcw"] [Tue Aug 18 13:08:25.334820 2026] [security2:error] [pid 167459:tid 167481] [remote 40.74.65.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/vr.php"] [unique_id "aoSDeWr_JutbFb-8svoACQAB1RU"] [Tue Aug 18 13:08:25.361667 2026] [security2:error] [pid 167459:tid 167692] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-good.php"] [unique_id "aoSDeWr_JutbFb-8svoACwAAAfY"] [Tue Aug 18 13:08:25.376148 2026] [security2:error] [pid 167459:tid 167699] [client 20.163.43.14:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/cache.php"] [unique_id "aoSDeWr_JutbFb-8svoAEAAAAf0"] [Tue Aug 18 13:08:25.421129 2026] [security2:error] [pid 167459:tid 167652] [client 20.215.241.237:30461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/admin.php"] [unique_id "aoSDeWr_JutbFb-8svoAFAAAAc4"] [Tue Aug 18 13:08:25.442204 2026] [security2:error] [pid 167459:tid 167654] [client 20.215.241.237:16520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/admin.php"] [unique_id "aoSDeWr_JutbFb-8svoAFwAAAdA"] [Tue Aug 18 13:08:25.515492 2026] [security2:error] [pid 167459:tid 167655] [client 114.5.214.109:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svoAGQAAAdE"] [Tue Aug 18 13:08:25.515605 2026] [security2:error] [pid 167459:tid 167655] [client 114.5.214.109:50417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svoAGQAAAdE"] [Tue Aug 18 13:08:25.525124 2026] [security2:error] [pid 167459:tid 167665] [client 52.139.47.57:5645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/166.php"] [unique_id "aoSDeWr_JutbFb-8svoAHAAAAds"] [Tue Aug 18 13:08:25.535887 2026] [security2:error] [pid 167459:tid 167662] [client 132.196.30.78:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/fone1.php"] [unique_id "aoSDeWr_JutbFb-8svoAHQAAAdg"] [Tue Aug 18 13:08:25.553617 2026] [security2:error] [pid 167459:tid 167631] [client 20.106.102.5:45732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/iko.php"] [unique_id "aoSDeWr_JutbFb-8svoAHwAAAbk"] [Tue Aug 18 13:08:25.563235 2026] [authz_core:error] [pid 167459:tid 167575] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:25.563683 2026] [authz_core:error] [pid 167459:tid 167575] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:25.567585 2026] [security2:error] [pid 167459:tid 167596] [client 178.153.171.161:45539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svoAIwAAAZY"] [Tue Aug 18 13:08:25.567691 2026] [security2:error] [pid 167459:tid 167596] [client 178.153.171.161:45539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDeWr_JutbFb-8svoAIwAAAZY"] [Tue Aug 18 13:08:25.579641 2026] [security2:error] [pid 167459:tid 167680] [client 104.209.144.33:31255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDeWr_JutbFb-8svoAJQAAAeo"] [Tue Aug 18 13:08:25.623336 2026] [security2:error] [pid 167459:tid 167622] [client 158.158.74.177:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/u.php"] [unique_id "aoSDeWr_JutbFb-8svoAKAAAAbA"] [Tue Aug 18 13:08:25.623453 2026] [security2:error] [pid 167459:tid 167714] [client 20.104.100.201:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDeWr_JutbFb-8svoAKQAAAgw"] [Tue Aug 18 13:08:25.635332 2026] [security2:error] [pid 167459:tid 167629] [client 172.202.39.151:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-config-sample.php"] [unique_id "aoSDeWr_JutbFb-8svoAKgAAAbc"] [Tue Aug 18 13:08:25.638664 2026] [security2:error] [pid 167459:tid 167601] [client 20.171.51.14:2365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ts.php"] [unique_id "aoSDeWr_JutbFb-8svoAKwAAAZs"] [Tue Aug 18 13:08:25.640244 2026] [security2:error] [pid 167459:tid 167637] [client 20.65.69.59:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/rex.php"] [unique_id "aoSDeWr_JutbFb-8svoALAAAAb8"] [Tue Aug 18 13:08:25.683903 2026] [security2:error] [pid 167459:tid 167633] [client 20.104.100.201:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ohct.php"] [unique_id "aoSDeWr_JutbFb-8svoALQAAAbs"] [Tue Aug 18 13:08:25.706214 2026] [security2:error] [pid 167459:tid 167607] [client 172.213.243.2:19866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ws61.php"] [unique_id "aoSDeWr_JutbFb-8svoALwAAAaE"] [Tue Aug 18 13:08:25.737407 2026] [security2:error] [pid 167459:tid 167616] [client 20.186.30.159:9807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDeWr_JutbFb-8svoANgAAAao"] [Tue Aug 18 13:08:25.755379 2026] [security2:error] [pid 167459:tid 167667] [client 40.74.65.169:20582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/admin.php"] [unique_id "aoSDeWr_JutbFb-8svoANwAAAd0"] [Tue Aug 18 13:08:25.816056 2026] [autoindex:error] [pid 167459:tid 167628] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:25.848144 2026] [security2:error] [pid 167459:tid 167703] [client 20.215.241.237:30434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/mac.php"] [unique_id "aoSDeWr_JutbFb-8svoAPAAAAgE"] [Tue Aug 18 13:08:25.852286 2026] [security2:error] [pid 167459:tid 167673] [client 74.248.18.37:35398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-includes/customize/autoload_classmap.php"] [unique_id "aoSDeWr_JutbFb-8svoAPQAAAeM"] [Tue Aug 18 13:08:25.863693 2026] [security2:error] [pid 167459:tid 167711] [client 20.25.139.174:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/chosen.php"] [unique_id "aoSDeWr_JutbFb-8svoAPgAAAgk"] [Tue Aug 18 13:08:25.869475 2026] [autoindex:error] [pid 167459:tid 167660] [client 20.79.204.6:6081] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:25.870053 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:25.870309 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:25.878225 2026] [security2:error] [pid 167459:tid 167620] [client 20.106.102.5:45286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/raw.php"] [unique_id "aoSDeWr_JutbFb-8svoAQQAAAa4"] [Tue Aug 18 13:08:25.904714 2026] [security2:error] [pid 167459:tid 167685] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/tes.php"] [unique_id "aoSDeWr_JutbFb-8svoAQgAAAe8"] [Tue Aug 18 13:08:25.944234 2026] [security2:error] [pid 167459:tid 167688] [client 52.139.47.57:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/222.php"] [unique_id "aoSDeWr_JutbFb-8svoARAAAAfI"] [Tue Aug 18 13:08:25.953896 2026] [security2:error] [pid 167459:tid 167610] [client 158.23.17.4:39567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pw.php"] [unique_id "aoSDeWr_JutbFb-8svoARQAAAaQ"] [Tue Aug 18 13:08:25.954707 2026] [security2:error] [pid 167459:tid 167670] [client 4.232.151.198:2440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/rrr.php"] [unique_id "aoSDeWr_JutbFb-8svoARgAAAeA"] [Tue Aug 18 13:08:25.992286 2026] [security2:error] [pid 167459:tid 167621] [client 158.23.17.4:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/qr.php"] [unique_id "aoSDeWr_JutbFb-8svoASAAAAa8"] [Tue Aug 18 13:08:26.014305 2026] [autoindex:error] [pid 167459:tid 167651] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:26.034334 2026] [security2:error] [pid 167459:tid 167614] [client 213.35.127.232:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDemr_JutbFb-8svoATAAAAag"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:26.069057 2026] [security2:error] [pid 167459:tid 167617] [client 20.79.204.6:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDemr_JutbFb-8svoAUAAAAas"] [Tue Aug 18 13:08:26.092554 2026] [authz_core:error] [pid 167459:tid 167567] [remote 57.141.22.13:36522] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:26.092805 2026] [authz_core:error] [pid 167459:tid 167567] [remote 57.141.22.13:36522] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:26.160984 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:26.161255 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:26.163755 2026] [security2:error] [pid 167459:tid 167600] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/files/index.php"] [unique_id "aoSDemr_JutbFb-8svoAXAAAAZo"] [Tue Aug 18 13:08:26.180377 2026] [security2:error] [pid 167459:tid 167669] [client 132.196.30.78:20469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ncx.php"] [unique_id "aoSDemr_JutbFb-8svoAXQAAAd8"] [Tue Aug 18 13:08:26.182643 2026] [security2:error] [pid 167459:tid 167624] [client 172.213.243.2:38405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/rum.php"] [unique_id "aoSDemr_JutbFb-8svoAXgAAAbI"] [Tue Aug 18 13:08:26.187223 2026] [security2:error] [pid 167459:tid 167657] [client 20.250.13.23:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/aa.php"] [unique_id "aoSDemr_JutbFb-8svoAXwAAAdM"] [Tue Aug 18 13:08:26.203565 2026] [security2:error] [pid 167459:tid 167642] [client 20.106.102.5:45270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/05.php"] [unique_id "aoSDemr_JutbFb-8svoAYAAAAcQ"] [Tue Aug 18 13:08:26.221755 2026] [autoindex:error] [pid 167459:tid 167625] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:26.225349 2026] [security2:error] [pid 167459:tid 167666] [client 104.209.144.33:32652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDemr_JutbFb-8svoAZAAAAdw"] [Tue Aug 18 13:08:26.232392 2026] [security2:error] [pid 167459:tid 167612] [client 158.23.17.4:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/73.php"] [unique_id "aoSDemr_JutbFb-8svoAZQAAAaY"] [Tue Aug 18 13:08:26.239547 2026] [security2:error] [pid 167459:tid 167704] [client 20.116.17.175:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/water.php"] [unique_id "aoSDemr_JutbFb-8svoAZwAAAgI"] [Tue Aug 18 13:08:26.246603 2026] [security2:error] [pid 167459:tid 167665] [client 20.104.100.201:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ot.php"] [unique_id "aoSDemr_JutbFb-8svoAaQAAAds"] [Tue Aug 18 13:08:26.247638 2026] [security2:error] [pid 167459:tid 167712] [client 172.202.39.151:39223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDemr_JutbFb-8svoAagAAAgo"] [Tue Aug 18 13:08:26.268481 2026] [security2:error] [pid 167459:tid 167640] [client 20.163.43.14:15241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDemr_JutbFb-8svoAbQAAAcI"] [Tue Aug 18 13:08:26.327621 2026] [security2:error] [pid 167459:tid 167680] [client 20.215.241.237:46356] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.circuitofechado.tv"] [uri "/1.php"] [unique_id "aoSDemr_JutbFb-8svoAcQAAAeo"] [Tue Aug 18 13:08:26.327747 2026] [security2:error] [pid 167459:tid 167680] [client 20.215.241.237:46356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/1.php"] [unique_id "aoSDemr_JutbFb-8svoAcQAAAeo"] [Tue Aug 18 13:08:26.379786 2026] [security2:error] [pid 167459:tid 167702] [client 52.139.47.57:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/ws66.php"] [unique_id "aoSDemr_JutbFb-8svoAcgAAAgA"] [Tue Aug 18 13:08:26.387883 2026] [security2:error] [pid 167459:tid 167699] [client 85.208.96.211:48842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752448461/1753920000/"] [unique_id "aoSDemr_JutbFb-8svoAcwAAAf0"] [Tue Aug 18 13:08:26.388048 2026] [security2:error] [pid 167459:tid 167699] [client 85.208.96.211:48842] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1752448461/1753920000/"] [unique_id "aoSDemr_JutbFb-8svoAcwAAAf0"] [Tue Aug 18 13:08:26.417022 2026] [security2:error] [pid 167459:tid 167637] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDemr_JutbFb-8svoAeAAAAb8"] [Tue Aug 18 13:08:26.420356 2026] [security2:error] [pid 167459:tid 167656] [client 20.25.139.174:4484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/index.php"] [unique_id "aoSDemr_JutbFb-8svoAegAAAdI"] [Tue Aug 18 13:08:26.426906 2026] [autoindex:error] [pid 167459:tid 167678] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:26.428193 2026] [security2:error] [pid 167459:tid 167599] [client 20.186.30.159:9855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/sf.php"] [unique_id "aoSDemr_JutbFb-8svoAewAAAZk"] [Tue Aug 18 13:08:26.429641 2026] [security2:error] [pid 167459:tid 167633] [client 20.215.241.237:8746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3xsolutions.com"] [uri "/ajax.php"] [unique_id "aoSDemr_JutbFb-8svoAfAAAAbs"] [Tue Aug 18 13:08:26.460235 2026] [security2:error] [pid 167459:tid 167648] [client 158.158.74.177:13793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/customize.php"] [unique_id "aoSDemr_JutbFb-8svoAgAAAAco"] [Tue Aug 18 13:08:26.461525 2026] [authz_core:error] [pid 167459:tid 167501] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:26.461808 2026] [authz_core:error] [pid 167459:tid 167501] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:26.510848 2026] [security2:error] [pid 167459:tid 167609] [client 40.74.65.169:21375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/aa2.php"] [unique_id "aoSDemr_JutbFb-8svoAgwAAAaM"] [Tue Aug 18 13:08:26.531343 2026] [security2:error] [pid 167459:tid 167672] [client 20.106.102.5:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/public/hi.php"] [unique_id "aoSDemr_JutbFb-8svoAhAAAAeI"] [Tue Aug 18 13:08:26.623505 2026] [security2:error] [pid 167459:tid 167705] [client 158.23.17.4:60671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fn.php"] [unique_id "aoSDemr_JutbFb-8svoAiQAAAgM"] [Tue Aug 18 13:08:26.625619 2026] [autoindex:error] [pid 167459:tid 167673] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:26.628603 2026] [security2:error] [pid 167459:tid 167711] [client 52.173.121.69:28301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDemr_JutbFb-8svoAiwAAAgk"] [Tue Aug 18 13:08:26.656371 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/text/autoload_classmap.php"] [unique_id "aoSDemr_JutbFb-8svoAjQAAAdk"] [Tue Aug 18 13:08:26.665157 2026] [security2:error] [pid 167459:tid 167685] [client 172.202.39.151:39194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDemr_JutbFb-8svoAjgAAAe8"] [Tue Aug 18 13:08:26.668866 2026] [security2:error] [pid 167459:tid 167679] [client 172.182.217.32:4154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wpr-addons/forms/b1ack.php"] [unique_id "aoSDemr_JutbFb-8svoAjwAAAek"] [Tue Aug 18 13:08:26.673475 2026] [security2:error] [pid 167459:tid 167713] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/images/images/about.php"] [unique_id "aoSDemr_JutbFb-8svoAkAAAAgs"] [Tue Aug 18 13:08:26.676830 2026] [security2:error] [pid 167459:tid 167641] [client 4.232.151.198:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/s.php"] [unique_id "aoSDemr_JutbFb-8svoAkQAAAcM"] [Tue Aug 18 13:08:26.692124 2026] [lsapi:error] [pid 139043:tid 139278] [client 201.32.74.208:57139] [host pensamentosimperfeitos.com.br] Connect to backend failed with CONNECTION_RESET on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 12915 with UID 12915 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html [Tue Aug 18 13:08:26.692119 2026] [lsapi:error] [pid 139043:tid 139062] [remote 201.32.74.208:57070] [host pensamentosimperfeitos.com.br] Connect to backend failed with CONNECTION_RESET on sending request(POST /wp-admin/admin-ajax.php HTTP/2.0); uri(/wp-admin/admin-ajax.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 12915 with UID 12915 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://pensamentosimperfeitos.com.br/wp-admin/import.php?import=blogger [Tue Aug 18 13:08:26.692132 2026] [lsapi:error] [pid 157386:tid 157555] [client 201.32.74.208:57207] [host pensamentosimperfeitos.com.br] Backend error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(134301) (lsphp is killed?): SendRequest: write to backend socket failed: errno 32 [Tue Aug 18 13:08:26.692131 2026] [lsapi:error] [pid 157386:tid 157425] [remote 201.32.74.208:57204] [host pensamentosimperfeitos.com.br] Connect to backend failed with CONNECTION_RESET on sending request(POST /wp-admin/admin-ajax.php HTTP/2.0); uri(/wp-admin/admin-ajax.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 12915 with UID 12915 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://pensamentosimperfeitos.com.br/wp-admin/import.php?import=blogger [Tue Aug 18 13:08:26.692177 2026] [lsapi:error] [pid 157386:tid 157548] [client 201.32.74.208:57233] [host pensamentosimperfeitos.com.br] Backend error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(134301) (lsphp is killed?): SendRequest: write to backend socket failed: errno 32 [Tue Aug 18 13:08:26.692211 2026] [lsapi:error] [pid 157386:tid 157395] [remote 201.32.74.208:57246] [host pensamentosimperfeitos.com.br] Connect to backend failed with CONNECTION_RESET on sending request(POST /wp-admin/admin-ajax.php HTTP/2.0); uri(/wp-admin/admin-ajax.php): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 12915 with UID 12915 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://pensamentosimperfeitos.com.br/wp-admin/import.php?import=blogger [Tue Aug 18 13:08:26.692222 2026] [lsapi:error] [pid 167459:tid 167644] [client 201.32.74.208:57263] [host pensamentosimperfeitos.com.br] Backend error on sending request(POST /wp-json/wp/v2/media HTTP/1.1); uri(/index.php) content-length(134301) (lsphp is killed?): SendRequest: write to backend socket failed: errno 32 [Tue Aug 18 13:08:26.692265 2026] [lsapi:error] [pid 167459:tid 167700] [client 162.241.203.17:23080] [host pensamentosimperfeitos.com.br] Connect to backend failed with CONNECTION_RESET on sending request(POST /wp-cron.php?doing_wp_cron=1787069304.5999009609222412109375 HTTP/1.1); uri(/wp-cron.php?doing_wp_cron=1787069304.5999009609222412109375): ReceiveAckHdr: backend reset connection: errno 104 (possibly memlimit for LVE ID 12915 with UID 12915 too small), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html [Tue Aug 18 13:08:26.727522 2026] [security2:error] [pid 167459:tid 167710] [client 172.213.243.2:5259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ze.php"] [unique_id "aoSDemr_JutbFb-8svoAlQAAAgg"] [Tue Aug 18 13:08:26.767561 2026] [security2:error] [pid 167459:tid 167675] [client 20.163.43.14:15716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDemr_JutbFb-8svoAlgAAAeU"] [Tue Aug 18 13:08:26.785562 2026] [security2:error] [pid 167459:tid 167674] [client 20.215.241.237:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/coffee.php"] [unique_id "aoSDemr_JutbFb-8svoAmQAAAeQ"] [Tue Aug 18 13:08:26.792069 2026] [security2:error] [pid 167459:tid 167660] [client 52.139.47.57:31736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/admin.php"] [unique_id "aoSDemr_JutbFb-8svoAmgAAAdY"] [Tue Aug 18 13:08:26.816089 2026] [security2:error] [pid 167459:tid 167617] [client 20.104.100.201:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/v5.php"] [unique_id "aoSDemr_JutbFb-8svoAmwAAAas"] [Tue Aug 18 13:08:26.830980 2026] [security2:error] [pid 167459:tid 167650] [client 104.209.144.33:31253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDemr_JutbFb-8svoAnQAAAcw"] [Tue Aug 18 13:08:26.832510 2026] [autoindex:error] [pid 167459:tid 167647] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:26.852487 2026] [security2:error] [pid 167459:tid 167620] [client 132.196.30.78:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDemr_JutbFb-8svoAnwAAAa4"] [Tue Aug 18 13:08:26.858618 2026] [security2:error] [pid 167459:tid 167692] [client 20.106.102.5:45176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/get.php"] [unique_id "aoSDemr_JutbFb-8svoAoAAAAfY"] [Tue Aug 18 13:08:26.868799 2026] [security2:error] [pid 167459:tid 167608] [client 20.79.204.6:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSDemr_JutbFb-8svoAlAAAAaI"] [Tue Aug 18 13:08:26.901614 2026] [security2:error] [pid 167459:tid 167639] [client 20.104.100.201:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ty.php"] [unique_id "aoSDemr_JutbFb-8svoApAAAAcE"] [Tue Aug 18 13:08:26.930704 2026] [security2:error] [pid 167459:tid 167666] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDemr_JutbFb-8svoApwAAAdw"] [Tue Aug 18 13:08:26.945758 2026] [security2:error] [pid 167459:tid 167614] [client 20.25.139.174:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/vx.php"] [unique_id "aoSDemr_JutbFb-8svoAqAAAAag"] [Tue Aug 18 13:08:26.968003 2026] [security2:error] [pid 167459:tid 167615] [client 4.232.151.198:38143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/xleet.php"] [unique_id "aoSDemr_JutbFb-8svoAqgAAAak"] [Tue Aug 18 13:08:27.005146 2026] [security2:error] [pid 167459:tid 167596] [client 20.116.17.175:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/fine.php"] [unique_id "aoSDe2r_JutbFb-8svoArAAAAZY"] [Tue Aug 18 13:08:27.047335 2026] [security2:error] [pid 167459:tid 167621] [client 213.35.127.232:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDe2r_JutbFb-8svoArgAAAa8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:27.050217 2026] [autoindex:error] [pid 167459:tid 167622] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:27.098534 2026] [security2:error] [pid 167459:tid 167678] [client 20.163.43.14:15697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/o.php"] [unique_id "aoSDe2r_JutbFb-8svoAsQAAAeg"] [Tue Aug 18 13:08:27.167141 2026] [security2:error] [pid 167459:tid 167658] [client 172.182.217.32:4141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/x.php"] [unique_id "aoSDe2r_JutbFb-8svoAtAAAAdQ"] [Tue Aug 18 13:08:27.169111 2026] [security2:error] [pid 167459:tid 167648] [client 172.213.243.2:5302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/gjm.php"] [unique_id "aoSDe2r_JutbFb-8svoAtQAAAco"] [Tue Aug 18 13:08:27.183435 2026] [security2:error] [pid 167459:tid 167677] [client 20.106.102.5:45157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/rpk.php"] [unique_id "aoSDe2r_JutbFb-8svoAtwAAAec"] [Tue Aug 18 13:08:27.184228 2026] [security2:error] [pid 167459:tid 167616] [client 172.202.39.151:39219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDe2r_JutbFb-8svoAuAAAAao"] [Tue Aug 18 13:08:27.194531 2026] [security2:error] [pid 167459:tid 167606] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/rip.php"] [unique_id "aoSDe2r_JutbFb-8svoAugAAAaA"] [Tue Aug 18 13:08:27.209757 2026] [security2:error] [pid 167459:tid 167709] [client 20.104.100.201:53311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSDe2r_JutbFb-8svoAvAAAAgc"] [Tue Aug 18 13:08:27.209836 2026] [security2:error] [pid 167459:tid 167694] [client 20.250.13.23:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDe2r_JutbFb-8svoAvQAAAfg"] [Tue Aug 18 13:08:27.213387 2026] [security2:error] [pid 167459:tid 167590] [client 213.202.253.4:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/txets.php"] [unique_id "aoSDe2r_JutbFb-8svoAvgAAAZA"], referer: www.google.com [Tue Aug 18 13:08:27.213586 2026] [security2:error] [pid 167459:tid 167637] [client 52.139.47.57:52365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/admin.php"] [unique_id "aoSDe2r_JutbFb-8svoAvwAAAb8"] [Tue Aug 18 13:08:27.228216 2026] [security2:error] [pid 167459:tid 167628] [client 20.215.241.237:46397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/classwithtostring.php"] [unique_id "aoSDe2r_JutbFb-8svoAwAAAAbY"] [Tue Aug 18 13:08:27.243381 2026] [autoindex:error] [pid 167459:tid 167645] [client 104.209.144.33:34161] AH01276: Cannot serve directory /home2/eletrosa/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:27.251685 2026] [security2:error] [pid 167459:tid 167630] [client 158.23.17.4:4662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kf.php"] [unique_id "aoSDe2r_JutbFb-8svoAwwAAAbg"] [Tue Aug 18 13:08:27.266173 2026] [security2:error] [pid 167459:tid 167619] [client 40.74.65.169:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xamp.php"] [unique_id "aoSDe2r_JutbFb-8svoAxAAAAa0"] [Tue Aug 18 13:08:27.351020 2026] [security2:error] [pid 167459:tid 167656] [client 4.232.151.198:2467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/s93.php"] [unique_id "aoSDe2r_JutbFb-8svoAyAAAAdI"] [Tue Aug 18 13:08:27.358630 2026] [security2:error] [pid 167459:tid 167697] [client 74.248.18.37:35403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/form.php"] [unique_id "aoSDe2r_JutbFb-8svoAyQAAAfs"] [Tue Aug 18 13:08:27.367267 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:27.367569 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:27.394968 2026] [security2:error] [pid 167459:tid 167636] [client 104.209.144.33:24835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDe2r_JutbFb-8svoAywAAAb4"] [Tue Aug 18 13:08:27.428402 2026] [security2:error] [pid 167459:tid 167691] [client 132.196.30.78:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wso.php"] [unique_id "aoSDe2r_JutbFb-8svoAzQAAAfU"] [Tue Aug 18 13:08:27.500421 2026] [security2:error] [pid 167459:tid 167707] [client 20.163.43.14:15245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/bb.php"] [unique_id "aoSDe2r_JutbFb-8svoAzwAAAgU"] [Tue Aug 18 13:08:27.509008 2026] [security2:error] [pid 167459:tid 167635] [client 20.106.102.5:45709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDe2r_JutbFb-8svoA0QAAAb0"] [Tue Aug 18 13:08:27.580814 2026] [security2:error] [pid 167459:tid 167595] [client 172.213.243.2:5305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/new4.php"] [unique_id "aoSDe2r_JutbFb-8svoA1gAAAZU"] [Tue Aug 18 13:08:27.596859 2026] [security2:error] [pid 167459:tid 167620] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDe2r_JutbFb-8svoA1wAAAa4"] [Tue Aug 18 13:08:27.605633 2026] [security2:error] [pid 167459:tid 167692] [client 20.116.17.175:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/loader.php"] [unique_id "aoSDe2r_JutbFb-8svoA2QAAAfY"] [Tue Aug 18 13:08:27.632403 2026] [security2:error] [pid 167459:tid 167716] [client 172.202.39.151:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/an.php"] [unique_id "aoSDe2r_JutbFb-8svoA2wAAAg4"] [Tue Aug 18 13:08:27.634262 2026] [security2:error] [pid 167459:tid 167603] [client 20.79.204.6:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDe2r_JutbFb-8svoA3AAAAZ0"] [Tue Aug 18 13:08:27.641354 2026] [security2:error] [pid 167459:tid 167650] [client 52.139.47.57:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSDe2r_JutbFb-8svoA3QAAAcw"] [Tue Aug 18 13:08:27.652257 2026] [security2:error] [pid 167459:tid 167617] [client 172.182.217.32:4153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/yellow.php"] [unique_id "aoSDe2r_JutbFb-8svoA3gAAAas"] [Tue Aug 18 13:08:27.661059 2026] [security2:error] [pid 167459:tid 167600] [client 20.186.30.159:9729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/k.php"] [unique_id "aoSDe2r_JutbFb-8svoA3wAAAZo"] [Tue Aug 18 13:08:27.662531 2026] [security2:error] [pid 167459:tid 167669] [client 20.215.241.237:39333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/wp-ws68.php"] [unique_id "aoSDe2r_JutbFb-8svoA4AAAAd8"] [Tue Aug 18 13:08:27.668886 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:27.669148 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:27.708893 2026] [security2:error] [pid 167459:tid 167652] [client 20.25.139.174:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wap.php"] [unique_id "aoSDe2r_JutbFb-8svoA5AAAAc4"] [Tue Aug 18 13:08:27.760121 2026] [security2:error] [pid 167459:tid 167696] [client 158.158.74.177:13700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/mah/function.php"] [unique_id "aoSDe2r_JutbFb-8svoA5QAAAfo"] [Tue Aug 18 13:08:27.829699 2026] [security2:error] [pid 167459:tid 167680] [client 20.163.43.14:15201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDe2r_JutbFb-8svoA6AAAAeo"] [Tue Aug 18 13:08:27.831666 2026] [security2:error] [pid 167459:tid 167632] [client 20.106.102.5:45203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/mga.php"] [unique_id "aoSDe2r_JutbFb-8svoA6QAAAbo"] [Tue Aug 18 13:08:27.852414 2026] [security2:error] [pid 167459:tid 167671] [client 104.209.144.33:25286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDe2r_JutbFb-8svoA7AAAAeE"] [Tue Aug 18 13:08:27.856533 2026] [security2:error] [pid 167459:tid 167624] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/moon.php"] [unique_id "aoSDe2r_JutbFb-8svoA7QAAAbI"] [Tue Aug 18 13:08:27.872527 2026] [security2:error] [pid 167459:tid 167622] [client 158.23.17.4:42584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ib.php"] [unique_id "aoSDe2r_JutbFb-8svoA9AAAAbA"] [Tue Aug 18 13:08:27.885799 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSDe2r_JutbFb-8svoA9gAAAZs"] [Tue Aug 18 13:08:27.894958 2026] [security2:error] [pid 167459:tid 167605] [client 158.23.17.4:11401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/dirs.php"] [unique_id "aoSDe2r_JutbFb-8svoA9wAAAZ8"] [Tue Aug 18 13:08:27.929541 2026] [security2:error] [pid 167459:tid 167646] [client 20.127.136.245:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wk/index.php"] [unique_id "aoSDe2r_JutbFb-8svoA-AAAAcg"] [Tue Aug 18 13:08:28.019692 2026] [security2:error] [pid 167459:tid 167694] [client 172.213.243.2:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-act.php"] [unique_id "aoSDfGr_JutbFb-8svoBAAAAAfg"] [Tue Aug 18 13:08:28.024049 2026] [security2:error] [pid 167459:tid 167640] [client 4.232.151.198:2457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/server.php"] [unique_id "aoSDfGr_JutbFb-8svoBAQAAAcI"] [Tue Aug 18 13:08:28.039982 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:28.040227 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:28.057165 2026] [security2:error] [pid 167459:tid 167599] [client 52.139.47.57:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDfGr_JutbFb-8svoBBAAAAZk"] [Tue Aug 18 13:08:28.062056 2026] [security2:error] [pid 167459:tid 167655] [client 213.35.127.232:63565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDfGr_JutbFb-8svoBBQAAAdE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:28.076228 2026] [security2:error] [pid 167459:tid 167621] [client 132.196.30.78:20432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/zup.php73"] [unique_id "aoSDfGr_JutbFb-8svoBBwAAAa8"] [Tue Aug 18 13:08:28.092133 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:20556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/bless.php"] [unique_id "aoSDfGr_JutbFb-8svoBCAAAAgk"] [Tue Aug 18 13:08:28.112753 2026] [security2:error] [pid 167459:tid 167613] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/cache.php"] [unique_id "aoSDfGr_JutbFb-8svoBCgAAAac"] [Tue Aug 18 13:08:28.117178 2026] [security2:error] [pid 167459:tid 167713] [client 20.215.241.237:59715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/yj09.php"] [unique_id "aoSDfGr_JutbFb-8svoBCwAAAgs"] [Tue Aug 18 13:08:28.139888 2026] [security2:error] [pid 167459:tid 167698] [client 172.182.217.32:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/.well-known/acme-challenge/post.php"] [unique_id "aoSDfGr_JutbFb-8svoBDAAAAfw"] [Tue Aug 18 13:08:28.155405 2026] [security2:error] [pid 167459:tid 167656] [client 20.106.102.5:45285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/fs.php"] [unique_id "aoSDfGr_JutbFb-8svoBDQAAAdI"] [Tue Aug 18 13:08:28.160223 2026] [security2:error] [pid 167459:tid 167700] [client 104.209.144.33:25343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.144.209.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.estudiohibrido.com.br"] [uri "/images/security.php"] [unique_id "aoSDfGr_JutbFb-8svoBDgAAAf4"] [Tue Aug 18 13:08:28.198097 2026] [security2:error] [pid 167459:tid 167675] [client 172.202.39.151:27866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/404.php"] [unique_id "aoSDfGr_JutbFb-8svoBEgAAAeU"] [Tue Aug 18 13:08:28.227102 2026] [security2:error] [pid 167459:tid 167648] [client 74.248.18.37:30724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/class-wp-font-face-resolver.php"] [unique_id "aoSDfGr_JutbFb-8svoBFgAAAco"] [Tue Aug 18 13:08:28.247890 2026] [security2:error] [pid 167459:tid 167635] [client 52.173.121.69:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDfGr_JutbFb-8svoBFwAAAb0"] [Tue Aug 18 13:08:28.248900 2026] [security2:error] [pid 167459:tid 167668] [client 20.104.100.201:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDfGr_JutbFb-8svoBGAAAAd4"] [Tue Aug 18 13:08:28.272177 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:28.272453 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:28.278840 2026] [security2:error] [pid 167459:tid 167705] [client 20.25.139.174:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDfGr_JutbFb-8svoBGwAAAgM"] [Tue Aug 18 13:08:28.304989 2026] [security2:error] [pid 167459:tid 167673] [client 20.79.204.6:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSDfGr_JutbFb-8svoBHAAAAeM"] [Tue Aug 18 13:08:28.326535 2026] [security2:error] [pid 167459:tid 167611] [client 4.232.151.198:40550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp.php"] [unique_id "aoSDfGr_JutbFb-8svoBHQAAAaU"] [Tue Aug 18 13:08:28.357892 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:38369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/su.php"] [unique_id "aoSDfGr_JutbFb-8svoBJQAAAg4"] [Tue Aug 18 13:08:28.365610 2026] [security2:error] [pid 167459:tid 167650] [client 20.163.43.14:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDfGr_JutbFb-8svoBJgAAAcw"] [Tue Aug 18 13:08:28.385717 2026] [security2:error] [pid 167459:tid 167679] [client 20.186.30.159:9761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/82.php"] [unique_id "aoSDfGr_JutbFb-8svoBKgAAAek"] [Tue Aug 18 13:08:28.386019 2026] [security2:error] [pid 167459:tid 167670] [client 158.158.74.177:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/filter.php"] [unique_id "aoSDfGr_JutbFb-8svoBKwAAAeA"] [Tue Aug 18 13:08:28.451894 2026] [security2:error] [pid 167459:tid 167689] [client 172.213.243.2:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/grsiuk.php"] [unique_id "aoSDfGr_JutbFb-8svoBLQAAAfM"] [Tue Aug 18 13:08:28.469231 2026] [security2:error] [pid 167459:tid 167654] [client 197.184.64.235:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfGr_JutbFb-8svoBLgAAAdA"] [Tue Aug 18 13:08:28.469358 2026] [security2:error] [pid 167459:tid 167654] [client 197.184.64.235:42693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfGr_JutbFb-8svoBLgAAAdA"] [Tue Aug 18 13:08:28.481451 2026] [security2:error] [pid 167459:tid 167598] [client 20.106.102.5:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/wp-tem.php"] [unique_id "aoSDfGr_JutbFb-8svoBLwAAAZg"] [Tue Aug 18 13:08:28.483830 2026] [security2:error] [pid 167459:tid 167634] [client 20.116.17.175:44715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/zero.php"] [unique_id "aoSDfGr_JutbFb-8svoBMAAAAbw"] [Tue Aug 18 13:08:28.509274 2026] [security2:error] [pid 167459:tid 167715] [client 52.139.47.57:52353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/gk.php"] [unique_id "aoSDfGr_JutbFb-8svoBMQAAAg0"] [Tue Aug 18 13:08:28.538758 2026] [authz_core:error] [pid 167459:tid 167701] [client 192.178.4.133:55410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:28.539019 2026] [authz_core:error] [pid 167459:tid 167701] [client 192.178.4.133:55410] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:28.591216 2026] [authz_core:error] [pid 167459:tid 167466] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:28.591482 2026] [authz_core:error] [pid 167459:tid 167466] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:28.620979 2026] [security2:error] [pid 167459:tid 167601] [client 20.171.51.14:23149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/53.php"] [unique_id "aoSDfGr_JutbFb-8svoBOgAAAZs"] [Tue Aug 18 13:08:28.621753 2026] [security2:error] [pid 167459:tid 167664] [client 138.36.100.162:41825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfGr_JutbFb-8svoBOwAAAdo"] [Tue Aug 18 13:08:28.621864 2026] [security2:error] [pid 167459:tid 167664] [client 138.36.100.162:41825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfGr_JutbFb-8svoBOwAAAdo"] [Tue Aug 18 13:08:28.633586 2026] [security2:error] [pid 167459:tid 167605] [client 20.215.241.237:30412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/scxy.php"] [unique_id "aoSDfGr_JutbFb-8svoBPQAAAZ8"] [Tue Aug 18 13:08:28.643008 2026] [security2:error] [pid 167459:tid 167642] [client 172.202.39.151:39192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-login.php"] [unique_id "aoSDfGr_JutbFb-8svoBPgAAAcQ"] [Tue Aug 18 13:08:28.656208 2026] [security2:error] [pid 167459:tid 167643] [client 4.232.151.198:2631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/settings.php"] [unique_id "aoSDfGr_JutbFb-8svoBPwAAAcU"] [Tue Aug 18 13:08:28.675901 2026] [security2:error] [pid 167459:tid 167647] [client 20.250.13.23:8493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/bolt.php"] [unique_id "aoSDfGr_JutbFb-8svoBQAAAAck"] [Tue Aug 18 13:08:28.713508 2026] [security2:error] [pid 167459:tid 167606] [client 20.163.43.14:15727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDfGr_JutbFb-8svoBQwAAAaA"] [Tue Aug 18 13:08:28.733579 2026] [security2:error] [pid 167459:tid 167702] [client 132.196.30.78:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/k.php"] [unique_id "aoSDfGr_JutbFb-8svoBRQAAAgA"] [Tue Aug 18 13:08:28.758660 2026] [security2:error] [pid 167459:tid 167640] [client 20.104.100.201:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dk.php"] [unique_id "aoSDfGr_JutbFb-8svoBRgAAAcI"] [Tue Aug 18 13:08:28.804588 2026] [security2:error] [pid 167459:tid 167630] [client 20.106.102.5:44997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/sadd.php"] [unique_id "aoSDfGr_JutbFb-8svoBSAAAAbg"] [Tue Aug 18 13:08:28.825180 2026] [security2:error] [pid 167459:tid 167655] [client 40.74.65.169:7105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file25.php"] [unique_id "aoSDfGr_JutbFb-8svoBSgAAAdE"] [Tue Aug 18 13:08:28.828143 2026] [security2:error] [pid 167459:tid 167621] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDfGr_JutbFb-8svoBSwAAAa8"] [Tue Aug 18 13:08:28.846127 2026] [security2:error] [pid 167459:tid 167663] [client 20.65.69.59:1745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/verification.php"] [unique_id "aoSDfGr_JutbFb-8svoBTAAAAdk"] [Tue Aug 18 13:08:28.856088 2026] [security2:error] [pid 167459:tid 167690] [client 20.25.139.174:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/bgymj.php"] [unique_id "aoSDfGr_JutbFb-8svoBTQAAAfQ"] [Tue Aug 18 13:08:28.881462 2026] [security2:error] [pid 167459:tid 167641] [client 172.213.243.2:36136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/h.php"] [unique_id "aoSDfGr_JutbFb-8svoBUAAAAcM"] [Tue Aug 18 13:08:28.886079 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:28.886351 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:28.928387 2026] [security2:error] [pid 167459:tid 167481] [remote 190.6.176.90:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michelepamela.com.br"] [uri "/wp-login.php"] [unique_id "aoSDfGr_JutbFb-8svoBUgABtRU"] [Tue Aug 18 13:08:28.960767 2026] [security2:error] [pid 167459:tid 167599] [client 52.139.47.57:31686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/fonts.php"] [unique_id "aoSDfGr_JutbFb-8svoBVAAAAZk"] [Tue Aug 18 13:08:29.000709 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:38349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wp-key.php"] [unique_id "aoSDfGr_JutbFb-8svoBVgAAAaE"] [Tue Aug 18 13:08:29.003415 2026] [security2:error] [pid 167459:tid 167636] [client 74.249.206.207:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/ops.php"] [unique_id "aoSDfWr_JutbFb-8svoBVwAAAb4"] [Tue Aug 18 13:08:29.009591 2026] [security2:error] [pid 167459:tid 167645] [client 158.158.74.177:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/input.php"] [unique_id "aoSDfWr_JutbFb-8svoBWAAAAcc"] [Tue Aug 18 13:08:29.011957 2026] [security2:error] [pid 167459:tid 167660] [client 172.202.39.151:27900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDfWr_JutbFb-8svoBWQAAAdY"] [Tue Aug 18 13:08:29.014934 2026] [autoindex:error] [pid 167459:tid 167694] [client 20.79.204.6:5894] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:29.050848 2026] [security2:error] [pid 167459:tid 167668] [client 20.163.43.14:15235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/file.php"] [unique_id "aoSDfWr_JutbFb-8svoBWwAAAd4"] [Tue Aug 18 13:08:29.081132 2026] [security2:error] [pid 167459:tid 167709] [client 213.35.127.232:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDfWr_JutbFb-8svoBXAAAAgc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:29.082680 2026] [security2:error] [pid 167459:tid 167614] [client 196.12.128.158:52794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBXQAAAag"] [Tue Aug 18 13:08:29.082801 2026] [security2:error] [pid 167459:tid 167614] [client 196.12.128.158:52794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBXQAAAag"] [Tue Aug 18 13:08:29.110069 2026] [security2:error] [pid 167459:tid 167659] [client 20.215.241.237:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDfWr_JutbFb-8svoBYQAAAdU"] [Tue Aug 18 13:08:29.127931 2026] [security2:error] [pid 167459:tid 167620] [client 20.106.102.5:45163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ex.php"] [unique_id "aoSDfWr_JutbFb-8svoBYwAAAa4"] [Tue Aug 18 13:08:29.147894 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:15770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xm.php"] [unique_id "aoSDfWr_JutbFb-8svoBZAAAAaU"] [Tue Aug 18 13:08:29.185791 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:29.186097 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:29.190674 2026] [security2:error] [pid 167459:tid 167632] [client 103.120.71.157:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBZwAAAbo"] [Tue Aug 18 13:08:29.190861 2026] [security2:error] [pid 167459:tid 167632] [client 103.120.71.157:60590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBZwAAAbo"] [Tue Aug 18 13:08:29.195814 2026] [security2:error] [pid 167459:tid 167669] [client 20.186.30.159:9813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/dex.php"] [unique_id "aoSDfWr_JutbFb-8svoBaQAAAd8"] [Tue Aug 18 13:08:29.215242 2026] [security2:error] [pid 167459:tid 167679] [client 20.206.73.37:55314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/special.php"] [unique_id "aoSDfWr_JutbFb-8svoBagAAAek"] [Tue Aug 18 13:08:29.240499 2026] [security2:error] [pid 167459:tid 167665] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDfWr_JutbFb-8svoBbAAAAds"] [Tue Aug 18 13:08:29.254683 2026] [security2:error] [pid 167459:tid 167673] [client 132.196.30.78:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDfWr_JutbFb-8svoBbgAAAeM"] [Tue Aug 18 13:08:29.259960 2026] [security2:error] [pid 167459:tid 167683] [client 74.248.18.37:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/6pf6swoe.php"] [unique_id "aoSDfWr_JutbFb-8svoBcAAAAe0"] [Tue Aug 18 13:08:29.263989 2026] [autoindex:error] [pid 167459:tid 167670] [client 20.79.204.6:5894] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:29.332142 2026] [security2:error] [pid 167459:tid 167596] [client 172.213.243.2:14548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/koiy.php"] [unique_id "aoSDfWr_JutbFb-8svoBcwAAAZY"] [Tue Aug 18 13:08:29.338732 2026] [security2:error] [pid 167459:tid 167631] [client 4.232.151.198:2449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/sf.php"] [unique_id "aoSDfWr_JutbFb-8svoBdAAAAbk"] [Tue Aug 18 13:08:29.351767 2026] [security2:error] [pid 167459:tid 167591] [client 158.23.17.4:25383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/sn.php"] [unique_id "aoSDfWr_JutbFb-8svoBdQAAAZE"] [Tue Aug 18 13:08:29.383741 2026] [security2:error] [pid 167459:tid 167714] [client 20.65.69.59:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/smtp.php"] [unique_id "aoSDfWr_JutbFb-8svoBeAAAAgw"] [Tue Aug 18 13:08:29.392671 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:5660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/chris.php"] [unique_id "aoSDfWr_JutbFb-8svoBegAAAfo"] [Tue Aug 18 13:08:29.393032 2026] [security2:error] [pid 167459:tid 167671] [client 20.151.109.219:20944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/eq.php"] [unique_id "aoSDfWr_JutbFb-8svoBewAAAeE"] [Tue Aug 18 13:08:29.412481 2026] [security2:error] [pid 167459:tid 167601] [client 52.173.121.69:36596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDfWr_JutbFb-8svoBfAAAAZs"] [Tue Aug 18 13:08:29.419386 2026] [security2:error] [pid 167459:tid 167625] [client 20.25.139.174:4859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/aa.php"] [unique_id "aoSDfWr_JutbFb-8svoBfQAAAbM"] [Tue Aug 18 13:08:29.437230 2026] [security2:error] [pid 167459:tid 167605] [client 20.104.100.201:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/bal.php"] [unique_id "aoSDfWr_JutbFb-8svoBfgAAAZ8"] [Tue Aug 18 13:08:29.450821 2026] [security2:error] [pid 167459:tid 167651] [client 20.106.102.5:45252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/tax.php"] [unique_id "aoSDfWr_JutbFb-8svoBfwAAAc0"] [Tue Aug 18 13:08:29.451458 2026] [security2:error] [pid 167459:tid 167642] [client 20.163.43.14:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/epinyins.php"] [unique_id "aoSDfWr_JutbFb-8svoBgQAAAcQ"] [Tue Aug 18 13:08:29.489386 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:29.489796 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:29.500313 2026] [security2:error] [pid 167459:tid 167703] [client 20.171.51.14:26026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/lq.php"] [unique_id "aoSDfWr_JutbFb-8svoBhAAAAgE"] [Tue Aug 18 13:08:29.501684 2026] [security2:error] [pid 167459:tid 167647] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/o.php"] [unique_id "aoSDfWr_JutbFb-8svoBhQAAAck"] [Tue Aug 18 13:08:29.516280 2026] [autoindex:error] [pid 167459:tid 167676] [client 20.79.204.6:5894] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:29.555092 2026] [security2:error] [pid 167459:tid 167590] [client 20.127.136.245:10606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDfWr_JutbFb-8svoBiAAAAZA"] [Tue Aug 18 13:08:29.575789 2026] [security2:error] [pid 167459:tid 167655] [client 20.215.241.237:46353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDfWr_JutbFb-8svoBiwAAAdE"] [Tue Aug 18 13:08:29.607784 2026] [security2:error] [pid 167459:tid 167690] [client 40.74.65.169:7164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file15.php"] [unique_id "aoSDfWr_JutbFb-8svoBjAAAAfQ"] [Tue Aug 18 13:08:29.645296 2026] [security2:error] [pid 167459:tid 167646] [client 158.158.74.177:13795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/jquery.php"] [unique_id "aoSDfWr_JutbFb-8svoBjwAAAcg"] [Tue Aug 18 13:08:29.648180 2026] [security2:error] [pid 167459:tid 167698] [client 158.23.17.4:60621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gg.php"] [unique_id "aoSDfWr_JutbFb-8svoBkAAAAfw"] [Tue Aug 18 13:08:29.717462 2026] [security2:error] [pid 167459:tid 167708] [client 20.79.204.6:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDfWr_JutbFb-8svoBkQAAAgY"] [Tue Aug 18 13:08:29.762798 2026] [security2:error] [pid 167459:tid 167660] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/bb.php"] [unique_id "aoSDfWr_JutbFb-8svoBlQAAAdY"] [Tue Aug 18 13:08:29.775665 2026] [security2:error] [pid 167459:tid 167707] [client 20.106.102.5:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/X7x.php"] [unique_id "aoSDfWr_JutbFb-8svoBlgAAAgU"] [Tue Aug 18 13:08:29.776082 2026] [security2:error] [pid 167459:tid 167635] [client 172.213.243.2:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fff.php"] [unique_id "aoSDfWr_JutbFb-8svoBlwAAAb0"] [Tue Aug 18 13:08:29.791184 2026] [authz_core:error] [pid 167459:tid 167514] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:29.791486 2026] [authz_core:error] [pid 167459:tid 167514] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:29.800246 2026] [security2:error] [pid 167459:tid 167709] [client 20.116.17.175:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/002.php"] [unique_id "aoSDfWr_JutbFb-8svoBmwAAAgc"] [Tue Aug 18 13:08:29.818283 2026] [security2:error] [pid 167459:tid 167705] [client 20.163.43.14:15645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDfWr_JutbFb-8svoBnAAAAgM"] [Tue Aug 18 13:08:29.823728 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:31733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/about.php"] [unique_id "aoSDfWr_JutbFb-8svoBngAAAcA"] [Tue Aug 18 13:08:29.885464 2026] [security2:error] [pid 167459:tid 167640] [client 49.145.211.146:9781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBoQAAAcI"] [Tue Aug 18 13:08:29.885575 2026] [security2:error] [pid 167459:tid 167640] [client 49.145.211.146:9781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfWr_JutbFb-8svoBoQAAAcI"] [Tue Aug 18 13:08:29.929172 2026] [security2:error] [pid 167459:tid 167679] [client 158.23.17.4:25352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/zy.php"] [unique_id "aoSDfWr_JutbFb-8svoBpgAAAek"] [Tue Aug 18 13:08:29.982062 2026] [security2:error] [pid 167459:tid 167670] [client 20.65.69.59:1749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/teste.php"] [unique_id "aoSDfWr_JutbFb-8svoBpwAAAeA"] [Tue Aug 18 13:08:30.016605 2026] [security2:error] [pid 167459:tid 167634] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDfmr_JutbFb-8svoBqgAAAbw"] [Tue Aug 18 13:08:30.018599 2026] [security2:error] [pid 167459:tid 167614] [client 4.232.151.198:30125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/shell.php"] [unique_id "aoSDfmr_JutbFb-8svoBqwAAAag"] [Tue Aug 18 13:08:30.028024 2026] [security2:error] [pid 167459:tid 167528] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfmr_JutbFb-8svoBrAAB8UQ"] [Tue Aug 18 13:08:30.028162 2026] [security2:error] [pid 167459:tid 167687] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDfmr_JutbFb-8svoBrAAB8UQ"] [Tue Aug 18 13:08:30.063966 2026] [security2:error] [pid 167459:tid 167631] [client 20.104.100.201:9583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/yawa.php"] [unique_id "aoSDfmr_JutbFb-8svoBrQAAAbk"] [Tue Aug 18 13:08:30.089229 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:30.089487 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:30.090101 2026] [security2:error] [pid 167459:tid 167672] [client 172.202.39.151:39227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wso.php"] [unique_id "aoSDfmr_JutbFb-8svoBsQAAAeI"] [Tue Aug 18 13:08:30.094372 2026] [security2:error] [pid 167459:tid 167645] [client 213.35.127.232:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDfmr_JutbFb-8svoBswAAAcc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:30.095984 2026] [security2:error] [pid 167459:tid 167611] [client 74.248.18.37:6847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/gvy6f.php"] [unique_id "aoSDfmr_JutbFb-8svoBtAAAAaU"] [Tue Aug 18 13:08:30.099055 2026] [security2:error] [pid 167459:tid 167617] [client 20.106.102.5:45744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ocxla.php"] [unique_id "aoSDfmr_JutbFb-8svoBtQAAAas"] [Tue Aug 18 13:08:30.107072 2026] [security2:error] [pid 167459:tid 167714] [client 20.215.241.237:30449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/blurbs.php"] [unique_id "aoSDfmr_JutbFb-8svoBtgAAAgw"] [Tue Aug 18 13:08:30.122451 2026] [security2:error] [pid 167459:tid 167682] [client 4.232.151.198:43574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/155.php"] [unique_id "aoSDfmr_JutbFb-8svoBtwAAAew"] [Tue Aug 18 13:08:30.167268 2026] [security2:error] [pid 167459:tid 167692] [client 20.25.139.174:4829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-mail.php"] [unique_id "aoSDfmr_JutbFb-8svoBuQAAAfY"] [Tue Aug 18 13:08:30.196654 2026] [security2:error] [pid 167459:tid 167648] [client 172.213.243.2:5252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/pouhg.php"] [unique_id "aoSDfmr_JutbFb-8svoBuwAAAco"] [Tue Aug 18 13:08:30.235460 2026] [security2:error] [pid 167459:tid 167643] [client 172.182.217.32:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/.well-known/pki-validation/about.php"] [unique_id "aoSDfmr_JutbFb-8svoBvQAAAcU"] [Tue Aug 18 13:08:30.238059 2026] [security2:error] [pid 167459:tid 167592] [client 52.139.47.57:5912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/http1.php"] [unique_id "aoSDfmr_JutbFb-8svoBvgAAAZI"] [Tue Aug 18 13:08:30.288161 2026] [security2:error] [pid 167459:tid 167596] [client 158.158.74.177:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/media-new.php"] [unique_id "aoSDfmr_JutbFb-8svoBwwAAAZY"] [Tue Aug 18 13:08:30.318836 2026] [security2:error] [pid 167459:tid 167608] [client 158.23.17.4:39605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gi.php"] [unique_id "aoSDfmr_JutbFb-8svoBxAAAAaI"] [Tue Aug 18 13:08:30.319499 2026] [security2:error] [pid 167459:tid 167693] [client 20.163.43.14:15704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDfmr_JutbFb-8svoBxQAAAfc"] [Tue Aug 18 13:08:30.368355 2026] [security2:error] [pid 167459:tid 167663] [client 40.74.65.169:36983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/f35.php"] [unique_id "aoSDfmr_JutbFb-8svoBxwAAAdk"] [Tue Aug 18 13:08:30.405018 2026] [security2:error] [pid 167459:tid 167712] [client 132.196.30.78:20339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/ww5.php"] [unique_id "aoSDfmr_JutbFb-8svoBywAAAgo"] [Tue Aug 18 13:08:30.424965 2026] [security2:error] [pid 167459:tid 167688] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDfmr_JutbFb-8svoBzAAAAfI"] [Tue Aug 18 13:08:30.437419 2026] [security2:error] [pid 167459:tid 167646] [client 20.106.102.5:45721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/post.php"] [unique_id "aoSDfmr_JutbFb-8svoBzgAAAcg"] [Tue Aug 18 13:08:30.453491 2026] [security2:error] [pid 167459:tid 167677] [client 20.186.30.159:9753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/puc.php"] [unique_id "aoSDfmr_JutbFb-8svoBzwAAAec"] [Tue Aug 18 13:08:30.518941 2026] [security2:error] [pid 167459:tid 167633] [client 20.79.204.6:5656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSDfmr_JutbFb-8svoB0wAAAbs"] [Tue Aug 18 13:08:30.530999 2026] [security2:error] [pid 167459:tid 167707] [client 20.151.109.219:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ep.php"] [unique_id "aoSDfmr_JutbFb-8svoB1AAAAgU"] [Tue Aug 18 13:08:30.535572 2026] [security2:error] [pid 167459:tid 167635] [client 20.127.136.245:5148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/xfun.php"] [unique_id "aoSDfmr_JutbFb-8svoB1QAAAb0"] [Tue Aug 18 13:08:30.580951 2026] [security2:error] [pid 167459:tid 167595] [client 158.23.17.4:47628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/q.php"] [unique_id "aoSDfmr_JutbFb-8svoB1wAAAZU"] [Tue Aug 18 13:08:30.585382 2026] [security2:error] [pid 167459:tid 167674] [client 20.215.241.237:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/bajah.php"] [unique_id "aoSDfmr_JutbFb-8svoB2AAAAeQ"] [Tue Aug 18 13:08:30.649676 2026] [security2:error] [pid 167459:tid 167716] [client 20.163.43.14:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDfmr_JutbFb-8svoB3QAAAg4"] [Tue Aug 18 13:08:30.656100 2026] [security2:error] [pid 167459:tid 167660] [client 52.139.47.57:5917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/uploadform.php"] [unique_id "aoSDfmr_JutbFb-8svoB3gAAAdY"] [Tue Aug 18 13:08:30.666190 2026] [security2:error] [pid 167459:tid 167600] [client 172.213.243.2:5269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/moon3.php"] [unique_id "aoSDfmr_JutbFb-8svoB3wAAAZo"] [Tue Aug 18 13:08:30.670595 2026] [security2:error] [pid 167459:tid 167706] [client 20.25.139.174:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/bolt.php"] [unique_id "aoSDfmr_JutbFb-8svoB4QAAAgQ"] [Tue Aug 18 13:08:30.687648 2026] [security2:error] [pid 167459:tid 167626] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDfmr_JutbFb-8svoB4wAAAbQ"] [Tue Aug 18 13:08:30.693318 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:30.693592 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:30.730757 2026] [security2:error] [pid 167459:tid 167638] [client 172.182.217.32:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/post.php"] [unique_id "aoSDfmr_JutbFb-8svoB5AAAAcA"] [Tue Aug 18 13:08:30.735953 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:2646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/shiny.php"] [unique_id "aoSDfmr_JutbFb-8svoB5QAAAgg"] [Tue Aug 18 13:08:30.762051 2026] [security2:error] [pid 167459:tid 167612] [client 20.106.102.5:45141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/nhr.php"] [unique_id "aoSDfmr_JutbFb-8svoB6AAAAaY"] [Tue Aug 18 13:08:30.768951 2026] [security2:error] [pid 167459:tid 167670] [client 20.104.100.201:53301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDfmr_JutbFb-8svoB6QAAAeA"] [Tue Aug 18 13:08:30.802157 2026] [security2:error] [pid 167459:tid 167662] [client 158.23.17.4:7215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/43.php"] [unique_id "aoSDfmr_JutbFb-8svoB7AAAAdg"] [Tue Aug 18 13:08:30.809381 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/dot.php"] [unique_id "aoSDfmr_JutbFb-8svoB7QAAAcc"] [Tue Aug 18 13:08:30.809674 2026] [security2:error] [pid 167459:tid 167611] [client 20.65.69.59:19565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/local.php"] [unique_id "aoSDfmr_JutbFb-8svoB7gAAAaU"] [Tue Aug 18 13:08:30.815681 2026] [security2:error] [pid 167459:tid 167682] [client 172.202.39.151:27855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/sf.php"] [unique_id "aoSDfmr_JutbFb-8svoB7wAAAew"] [Tue Aug 18 13:08:30.884173 2026] [security2:error] [pid 167459:tid 167704] [client 74.248.18.37:30730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/index22.php"] [unique_id "aoSDfmr_JutbFb-8svoB9gAAAgI"] [Tue Aug 18 13:08:30.908775 2026] [security2:error] [pid 167459:tid 167652] [client 158.158.74.177:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSDfmr_JutbFb-8svoB-gAAAc4"] [Tue Aug 18 13:08:30.943267 2026] [security2:error] [pid 167459:tid 167596] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/file.php"] [unique_id "aoSDfmr_JutbFb-8svoB_gAAAZY"] [Tue Aug 18 13:08:30.952706 2026] [security2:error] [pid 167459:tid 167610] [client 4.232.151.198:42411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/96i.php"] [unique_id "aoSDfmr_JutbFb-8svoB_wAAAaQ"] [Tue Aug 18 13:08:30.959321 2026] [security2:error] [pid 167459:tid 167590] [client 158.23.17.4:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pz.php"] [unique_id "aoSDfmr_JutbFb-8svoCAAAAAZA"] [Tue Aug 18 13:08:30.980087 2026] [security2:error] [pid 167459:tid 167630] [client 20.163.43.14:15634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp.php"] [unique_id "aoSDfmr_JutbFb-8svoCAgAAAbg"] [Tue Aug 18 13:08:30.994140 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:30.994403 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:31.007988 2026] [security2:error] [pid 167459:tid 167692] [client 132.196.30.78:13102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/2.php"] [unique_id "aoSDf2r_JutbFb-8svoCBAAAAfY"] [Tue Aug 18 13:08:31.051504 2026] [security2:error] [pid 167459:tid 167593] [client 20.215.241.237:46365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/domvf.php"] [unique_id "aoSDf2r_JutbFb-8svoCBwAAAZM"] [Tue Aug 18 13:08:31.071534 2026] [security2:error] [pid 167459:tid 167676] [client 52.139.47.57:29453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/uploads/frmUpload.php"] [unique_id "aoSDf2r_JutbFb-8svoCCAAAAeY"] [Tue Aug 18 13:08:31.076992 2026] [security2:error] [pid 167459:tid 167602] [client 40.74.65.169:7157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-load.php"] [unique_id "aoSDf2r_JutbFb-8svoCCQAAAZw"] [Tue Aug 18 13:08:31.085278 2026] [security2:error] [pid 167459:tid 167641] [client 20.106.102.5:45708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDf2r_JutbFb-8svoCCgAAAcM"] [Tue Aug 18 13:08:31.088319 2026] [security2:error] [pid 167459:tid 167661] [client 172.213.243.2:19871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/opts.php"] [unique_id "aoSDf2r_JutbFb-8svoCCwAAAdc"] [Tue Aug 18 13:08:31.113441 2026] [security2:error] [pid 167459:tid 167597] [client 213.35.127.232:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDf2r_JutbFb-8svoCDQAAAZc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:31.140065 2026] [security2:error] [pid 167459:tid 167700] [client 20.151.109.219:46531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/rf.php"] [unique_id "aoSDf2r_JutbFb-8svoCDwAAAf4"] [Tue Aug 18 13:08:31.170402 2026] [security2:error] [pid 167459:tid 167709] [client 20.186.30.159:12533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/inso.php"] [unique_id "aoSDf2r_JutbFb-8svoCEwAAAgc"] [Tue Aug 18 13:08:31.195712 2026] [security2:error] [pid 167459:tid 167663] [client 20.25.139.174:4815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/bthil.php"] [unique_id "aoSDf2r_JutbFb-8svoCFgAAAdk"] [Tue Aug 18 13:08:31.200401 2026] [security2:error] [pid 167459:tid 167657] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/epinyins.php"] [unique_id "aoSDf2r_JutbFb-8svoCFwAAAdM"] [Tue Aug 18 13:08:31.225685 2026] [security2:error] [pid 167459:tid 167591] [client 172.182.217.32:25541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/flower.php"] [unique_id "aoSDf2r_JutbFb-8svoCGAAAAZE"] [Tue Aug 18 13:08:31.299879 2026] [security2:error] [pid 167459:tid 167668] [client 20.127.136.245:21703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/p.php"] [unique_id "aoSDf2r_JutbFb-8svoCHQAAAd4"] [Tue Aug 18 13:08:31.305156 2026] [security2:error] [pid 167459:tid 167632] [client 20.163.43.14:15280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/function/function.php"] [unique_id "aoSDf2r_JutbFb-8svoCHgAAAbo"] [Tue Aug 18 13:08:31.333009 2026] [security2:error] [pid 167459:tid 167640] [client 49.37.150.8:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCIAAAAcI"] [Tue Aug 18 13:08:31.333115 2026] [security2:error] [pid 167459:tid 167640] [client 49.37.150.8:56570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCIAAAAcI"] [Tue Aug 18 13:08:31.352955 2026] [security2:error] [pid 167459:tid 167598] [client 20.79.204.6:6005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSDf2r_JutbFb-8svoCIQAAAZg"] [Tue Aug 18 13:08:31.377607 2026] [security2:error] [pid 167459:tid 167665] [client 5.31.227.224:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCIgAAAds"] [Tue Aug 18 13:08:31.377736 2026] [security2:error] [pid 167459:tid 167665] [client 5.31.227.224:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCIgAAAds"] [Tue Aug 18 13:08:31.387120 2026] [security2:error] [pid 167459:tid 167689] [client 20.104.100.201:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/7.php"] [unique_id "aoSDf2r_JutbFb-8svoCJAAAAfM"] [Tue Aug 18 13:08:31.394612 2026] [security2:error] [pid 167459:tid 167644] [client 20.65.69.59:35401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/wp_sitting.php"] [unique_id "aoSDf2r_JutbFb-8svoCJQAAAcY"] [Tue Aug 18 13:08:31.409982 2026] [security2:error] [pid 167459:tid 167634] [client 20.106.102.5:45707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ws79.php"] [unique_id "aoSDf2r_JutbFb-8svoCJgAAAbw"] [Tue Aug 18 13:08:31.432445 2026] [security2:error] [pid 167459:tid 167659] [client 4.232.151.198:16407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/sid3.php"] [unique_id "aoSDf2r_JutbFb-8svoCJwAAAdU"] [Tue Aug 18 13:08:31.439549 2026] [security2:error] [pid 167459:tid 167645] [client 20.116.17.175:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/zxz.php"] [unique_id "aoSDf2r_JutbFb-8svoCKAAAAcc"] [Tue Aug 18 13:08:31.449873 2026] [security2:error] [pid 167459:tid 167617] [client 20.186.30.159:9851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/aa.php"] [unique_id "aoSDf2r_JutbFb-8svoCKQAAAas"] [Tue Aug 18 13:08:31.463919 2026] [security2:error] [pid 167459:tid 167682] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDf2r_JutbFb-8svoCKgAAAew"] [Tue Aug 18 13:08:31.484846 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:29503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/uploads/pulldowns.php"] [unique_id "aoSDf2r_JutbFb-8svoCLAAAAbc"] [Tue Aug 18 13:08:31.517252 2026] [security2:error] [pid 167459:tid 167651] [client 172.213.243.2:14461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/zwq13.php"] [unique_id "aoSDf2r_JutbFb-8svoCLQAAAc0"] [Tue Aug 18 13:08:31.534115 2026] [security2:error] [pid 167459:tid 167703] [client 172.202.39.151:27894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/index/function.php"] [unique_id "aoSDf2r_JutbFb-8svoCLgAAAgE"] [Tue Aug 18 13:08:31.583814 2026] [security2:error] [pid 167459:tid 167596] [client 20.215.241.237:2980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/fpwch.php"] [unique_id "aoSDf2r_JutbFb-8svoCMAAAAZY"] [Tue Aug 18 13:08:31.585558 2026] [security2:error] [pid 167459:tid 167675] [client 132.196.30.78:13075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDf2r_JutbFb-8svoCMQAAAeU"] [Tue Aug 18 13:08:31.595047 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:31.595309 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:31.622753 2026] [security2:error] [pid 167459:tid 167710] [client 158.158.74.177:13769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSDf2r_JutbFb-8svoCNQAAAgg"] [Tue Aug 18 13:08:31.648798 2026] [security2:error] [pid 167459:tid 167608] [client 20.163.43.14:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDf2r_JutbFb-8svoCNwAAAaI"] [Tue Aug 18 13:08:31.658599 2026] [security2:error] [pid 167459:tid 167611] [client 74.248.18.37:35436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/theme/gr.php"] [unique_id "aoSDf2r_JutbFb-8svoCOAAAAaU"] [Tue Aug 18 13:08:31.721191 2026] [security2:error] [pid 167459:tid 167620] [client 86.120.159.145:24299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCPQAAAa4"] [Tue Aug 18 13:08:31.721519 2026] [security2:error] [pid 167459:tid 167620] [client 86.120.159.145:24299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDf2r_JutbFb-8svoCPQAAAa4"] [Tue Aug 18 13:08:31.721538 2026] [security2:error] [pid 167459:tid 167647] [client 172.182.217.32:4075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/autoload_classmap.php"] [unique_id "aoSDf2r_JutbFb-8svoCPAAAAck"] [Tue Aug 18 13:08:31.732177 2026] [security2:error] [pid 167459:tid 167713] [client 20.151.109.219:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xynz1.php"] [unique_id "aoSDf2r_JutbFb-8svoCPwAAAgs"] [Tue Aug 18 13:08:31.732788 2026] [security2:error] [pid 167459:tid 167676] [client 158.23.17.4:47618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xf.php"] [unique_id "aoSDf2r_JutbFb-8svoCQAAAAeY"] [Tue Aug 18 13:08:31.735177 2026] [security2:error] [pid 167459:tid 167685] [client 20.186.30.159:9830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/img.php"] [unique_id "aoSDf2r_JutbFb-8svoCQQAAAe8"] [Tue Aug 18 13:08:31.737397 2026] [security2:error] [pid 167459:tid 167641] [client 20.106.102.5:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/rtx.php"] [unique_id "aoSDf2r_JutbFb-8svoCQgAAAcM"] [Tue Aug 18 13:08:31.752523 2026] [security2:error] [pid 167459:tid 167605] [client 4.232.151.198:38577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/as.php"] [unique_id "aoSDf2r_JutbFb-8svoCQwAAAZ8"] [Tue Aug 18 13:08:31.778820 2026] [security2:error] [pid 167459:tid 167646] [client 158.23.17.4:40204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kk.php"] [unique_id "aoSDf2r_JutbFb-8svoCRgAAAcg"] [Tue Aug 18 13:08:31.875386 2026] [security2:error] [pid 167459:tid 167635] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDf2r_JutbFb-8svoCSgAAAb0"] [Tue Aug 18 13:08:31.891627 2026] [security2:error] [pid 167459:tid 167709] [client 20.25.139.174:4604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/x.php"] [unique_id "aoSDf2r_JutbFb-8svoCSwAAAgc"] [Tue Aug 18 13:08:31.900251 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:12469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/data.php"] [unique_id "aoSDf2r_JutbFb-8svoCTQAAAak"] [Tue Aug 18 13:08:31.901907 2026] [security2:error] [pid 167459:tid 167715] [client 20.65.69.59:19580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/ninja.php"] [unique_id "aoSDf2r_JutbFb-8svoCTgAAAg0"] [Tue Aug 18 13:08:31.930408 2026] [security2:error] [pid 167459:tid 167595] [client 172.213.243.2:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/Okxob.php"] [unique_id "aoSDf2r_JutbFb-8svoCUQAAAZU"] [Tue Aug 18 13:08:31.934460 2026] [security2:error] [pid 167459:tid 167667] [client 20.250.13.23:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/bthil.php"] [unique_id "aoSDf2r_JutbFb-8svoCUgAAAd0"] [Tue Aug 18 13:08:31.976020 2026] [security2:error] [pid 167459:tid 167604] [client 20.104.100.201:53323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ws77.php"] [unique_id "aoSDf2r_JutbFb-8svoCVQAAAZ4"] [Tue Aug 18 13:08:31.985341 2026] [security2:error] [pid 167459:tid 167664] [client 158.23.17.4:40387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/fresh.php"] [unique_id "aoSDf2r_JutbFb-8svoCVgAAAdo"] [Tue Aug 18 13:08:31.995460 2026] [security2:error] [pid 167459:tid 167716] [client 20.163.43.14:15720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDf2r_JutbFb-8svoCVwAAAg4"] [Tue Aug 18 13:08:32.013105 2026] [security2:error] [pid 167459:tid 167632] [client 20.215.241.237:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/adminner.php"] [unique_id "aoSDgGr_JutbFb-8svoCWQAAAbo"] [Tue Aug 18 13:08:32.035245 2026] [security2:error] [pid 167459:tid 167600] [client 20.65.98.162:47024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDgGr_JutbFb-8svoCWgAAAZo"] [Tue Aug 18 13:08:32.044942 2026] [security2:error] [pid 167459:tid 167697] [client 20.79.204.6:5744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSDgGr_JutbFb-8svoCXAAAAfs"] [Tue Aug 18 13:08:32.059440 2026] [security2:error] [pid 167459:tid 167650] [client 20.106.102.5:45705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/end.php"] [unique_id "aoSDgGr_JutbFb-8svoCXgAAAcw"] [Tue Aug 18 13:08:32.102054 2026] [security2:error] [pid 167459:tid 167662] [client 102.213.179.104:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDgGr_JutbFb-8svoCYQAAAdg"] [Tue Aug 18 13:08:32.102170 2026] [security2:error] [pid 167459:tid 167662] [client 102.213.179.104:58879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDgGr_JutbFb-8svoCYQAAAdg"] [Tue Aug 18 13:08:32.125889 2026] [security2:error] [pid 167459:tid 167597] [client 213.35.127.232:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDgGr_JutbFb-8svoCYwAAAZc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:32.126412 2026] [security2:error] [pid 167459:tid 167607] [client 4.232.151.198:2640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/sid4.php"] [unique_id "aoSDgGr_JutbFb-8svoCZAAAAaE"] [Tue Aug 18 13:08:32.137273 2026] [security2:error] [pid 167459:tid 167631] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDgGr_JutbFb-8svoCZQAAAbk"] [Tue Aug 18 13:08:32.159364 2026] [security2:error] [pid 167459:tid 167645] [client 20.151.109.219:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vo.php"] [unique_id "aoSDgGr_JutbFb-8svoCZgAAAcc"] [Tue Aug 18 13:08:32.212410 2026] [security2:error] [pid 167459:tid 167594] [client 172.182.217.32:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/classwithtostring.php"] [unique_id "aoSDgGr_JutbFb-8svoCaAAAAZQ"] [Tue Aug 18 13:08:32.270427 2026] [security2:error] [pid 167459:tid 167669] [client 132.196.30.78:20460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/atomlib.php"] [unique_id "aoSDgGr_JutbFb-8svoCawAAAd8"] [Tue Aug 18 13:08:32.289363 2026] [security2:error] [pid 167459:tid 167535] [remote 135.236.141.99:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.141.236.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.capecodcleaningservice.com"] [uri "/wp-login.php"] [unique_id "aoSDgGr_JutbFb-8svoCbAABmEs"] [Tue Aug 18 13:08:32.311033 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/phpcheck.php"] [unique_id "aoSDgGr_JutbFb-8svoCbgAAAc4"] [Tue Aug 18 13:08:32.314472 2026] [security2:error] [pid 167459:tid 167617] [client 52.139.47.57:32948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/bk.php"] [unique_id "aoSDgGr_JutbFb-8svoCbwAAAas"] [Tue Aug 18 13:08:32.322918 2026] [security2:error] [pid 167459:tid 167614] [client 158.158.74.177:13764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSDgGr_JutbFb-8svoCcAAAAag"] [Tue Aug 18 13:08:32.332203 2026] [security2:error] [pid 167459:tid 167609] [client 20.163.43.14:15736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/ok.php"] [unique_id "aoSDgGr_JutbFb-8svoCcQAAAaM"] [Tue Aug 18 13:08:32.349892 2026] [security2:error] [pid 167459:tid 167596] [client 20.116.17.175:52571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/memberfuns.php"] [unique_id "aoSDgGr_JutbFb-8svoCcgAAAZY"] [Tue Aug 18 13:08:32.368360 2026] [security2:error] [pid 167459:tid 167619] [client 20.171.51.14:19859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/you.php"] [unique_id "aoSDgGr_JutbFb-8svoCdAAAAa0"] [Tue Aug 18 13:08:32.370973 2026] [security2:error] [pid 167459:tid 167637] [client 20.127.136.245:13007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDgGr_JutbFb-8svoCdgAAAb8"] [Tue Aug 18 13:08:32.377475 2026] [security2:error] [pid 167459:tid 167710] [client 172.213.243.2:11592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/file59.php"] [unique_id "aoSDgGr_JutbFb-8svoCdwAAAgg"] [Tue Aug 18 13:08:32.383432 2026] [security2:error] [pid 167459:tid 167610] [client 20.106.102.5:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.102.106.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "supersegcorretora.com.br"] [uri "/ae.php"] [unique_id "aoSDgGr_JutbFb-8svoCeAAAAaQ"] [Tue Aug 18 13:08:32.396365 2026] [security2:error] [pid 167459:tid 167611] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp.php"] [unique_id "aoSDgGr_JutbFb-8svoCeQAAAaU"] [Tue Aug 18 13:08:32.422727 2026] [security2:error] [pid 167459:tid 167703] [client 20.25.139.174:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/index/function.php"] [unique_id "aoSDgGr_JutbFb-8svoCfAAAAgE"] [Tue Aug 18 13:08:32.436445 2026] [security2:error] [pid 167459:tid 167692] [client 20.215.241.237:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/abcd.php"] [unique_id "aoSDgGr_JutbFb-8svoCfQAAAfY"] [Tue Aug 18 13:08:32.502869 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:32.502903 2026] [security2:error] [pid 167459:tid 167661] [client 52.173.121.69:28332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDgGr_JutbFb-8svoCgwAAAdc"] [Tue Aug 18 13:08:32.503264 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:32.514262 2026] [security2:error] [pid 167459:tid 167622] [client 20.226.36.136:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDgGr_JutbFb-8svoChQAAAbA"] [Tue Aug 18 13:08:32.514748 2026] [security2:error] [pid 167459:tid 167655] [client 223.185.37.47:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDgGr_JutbFb-8svoChgAAAdE"] [Tue Aug 18 13:08:32.514843 2026] [security2:error] [pid 167459:tid 167655] [client 223.185.37.47:2126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDgGr_JutbFb-8svoChgAAAdE"] [Tue Aug 18 13:08:32.610088 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:53365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/read.php"] [unique_id "aoSDgGr_JutbFb-8svoChwAAAgU"] [Tue Aug 18 13:08:32.645645 2026] [security2:error] [pid 167459:tid 167621] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/function/function.php"] [unique_id "aoSDgGr_JutbFb-8svoCiAAAAa8"] [Tue Aug 18 13:08:32.676658 2026] [security2:error] [pid 167459:tid 167657] [client 20.186.30.159:9809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/222.php"] [unique_id "aoSDgGr_JutbFb-8svoCigAAAdM"] [Tue Aug 18 13:08:32.678272 2026] [security2:error] [pid 167459:tid 167663] [client 20.163.43.14:15168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.43.163.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelrotadosolmg.com.br"] [uri "/item.php"] [unique_id "aoSDgGr_JutbFb-8svoCiwAAAdk"] [Tue Aug 18 13:08:32.682896 2026] [security2:error] [pid 167459:tid 167595] [client 74.248.18.37:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/pwnd/pwnd.php"] [unique_id "aoSDgGr_JutbFb-8svoCjAAAAZU"] [Tue Aug 18 13:08:32.685747 2026] [security2:error] [pid 167459:tid 167667] [client 20.65.69.59:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/phpprobe.php"] [unique_id "aoSDgGr_JutbFb-8svoCjQAAAd0"] [Tue Aug 18 13:08:32.706890 2026] [security2:error] [pid 167459:tid 167671] [client 172.182.217.32:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/jp.php"] [unique_id "aoSDgGr_JutbFb-8svoCjwAAAeE"] [Tue Aug 18 13:08:32.735369 2026] [security2:error] [pid 167459:tid 167635] [client 52.139.47.57:29470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/x6.php"] [unique_id "aoSDgGr_JutbFb-8svoCkQAAAb0"] [Tue Aug 18 13:08:32.758885 2026] [security2:error] [pid 167459:tid 167627] [client 20.151.109.219:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wu.php"] [unique_id "aoSDgGr_JutbFb-8svoCkgAAAbU"] [Tue Aug 18 13:08:32.766231 2026] [security2:error] [pid 167459:tid 167604] [client 20.226.36.136:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDgGr_JutbFb-8svoClAAAAZ4"] [Tue Aug 18 13:08:32.772359 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/gj.php"] [unique_id "aoSDgGr_JutbFb-8svoClQAAAg4"] [Tue Aug 18 13:08:32.772576 2026] [autoindex:error] [pid 167459:tid 167646] [client 20.79.204.6:6142] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:32.796477 2026] [security2:error] [pid 167459:tid 167632] [client 40.74.65.169:20559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "aoSDgGr_JutbFb-8svoClwAAAbo"] [Tue Aug 18 13:08:32.822268 2026] [security2:error] [pid 167459:tid 167679] [client 158.23.17.4:4644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/dg.php"] [unique_id "aoSDgGr_JutbFb-8svoCmQAAAek"] [Tue Aug 18 13:08:32.837077 2026] [security2:error] [pid 167459:tid 167615] [client 132.196.30.78:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/rip.php"] [unique_id "aoSDgGr_JutbFb-8svoCmgAAAak"] [Tue Aug 18 13:08:32.841888 2026] [security2:error] [pid 167459:tid 167626] [client 172.213.243.2:14447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/eauu.php"] [unique_id "aoSDgGr_JutbFb-8svoCmwAAAbQ"] [Tue Aug 18 13:08:32.865868 2026] [security2:error] [pid 167459:tid 167665] [client 20.215.241.237:55202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/simple.php"] [unique_id "aoSDgGr_JutbFb-8svoCnQAAAds"] [Tue Aug 18 13:08:32.893782 2026] [security2:error] [pid 167459:tid 167662] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDgGr_JutbFb-8svoCngAAAdg"] [Tue Aug 18 13:08:32.908983 2026] [security2:error] [pid 167459:tid 167648] [client 20.25.139.174:4848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/aaa.php"] [unique_id "aoSDgGr_JutbFb-8svoCoAAAAco"] [Tue Aug 18 13:08:32.955006 2026] [security2:error] [pid 167459:tid 167607] [client 20.104.100.201:17348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/yup.php"] [unique_id "aoSDgGr_JutbFb-8svoCogAAAaE"] [Tue Aug 18 13:08:32.982346 2026] [security2:error] [pid 167459:tid 167601] [client 20.79.204.6:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDgGr_JutbFb-8svoCpAAAAZs"] [Tue Aug 18 13:08:33.013991 2026] [security2:error] [pid 167459:tid 167630] [client 158.158.74.177:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSDgWr_JutbFb-8svoCpgAAAbg"] [Tue Aug 18 13:08:33.035737 2026] [security2:error] [pid 167459:tid 167704] [client 20.104.100.201:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/005.php"] [unique_id "aoSDgWr_JutbFb-8svoCpwAAAgI"] [Tue Aug 18 13:08:33.055473 2026] [security2:error] [pid 167459:tid 167598] [client 4.232.151.198:2466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/size.php"] [unique_id "aoSDgWr_JutbFb-8svoCqAAAAZg"] [Tue Aug 18 13:08:33.075248 2026] [autoindex:error] [pid 167459:tid 167616] [client 82.102.18.182:33804] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:33.090855 2026] [security2:error] [pid 167459:tid 167614] [client 68.155.154.236:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDgWr_JutbFb-8svoCqgAAAag"] [Tue Aug 18 13:08:33.100228 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:33.100491 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:33.136289 2026] [security2:error] [pid 167459:tid 167706] [client 213.35.127.232:64559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDgWr_JutbFb-8svoCrQAAAgQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:33.142446 2026] [security2:error] [pid 167459:tid 167596] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDgWr_JutbFb-8svoCrgAAAZY"] [Tue Aug 18 13:08:33.152734 2026] [security2:error] [pid 167459:tid 167628] [client 20.104.100.201:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/albin.php"] [unique_id "aoSDgWr_JutbFb-8svoCrwAAAbY"] [Tue Aug 18 13:08:33.158528 2026] [security2:error] [pid 167459:tid 167625] [client 52.139.47.57:56216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/120f9.php"] [unique_id "aoSDgWr_JutbFb-8svoCsAAAAbM"] [Tue Aug 18 13:08:33.165445 2026] [security2:error] [pid 167459:tid 167710] [client 172.202.39.151:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/edit.php"] [unique_id "aoSDgWr_JutbFb-8svoCsgAAAgg"] [Tue Aug 18 13:08:33.196375 2026] [security2:error] [pid 167459:tid 167651] [client 172.182.217.32:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSDgWr_JutbFb-8svoCswAAAc0"] [Tue Aug 18 13:08:33.250462 2026] [security2:error] [pid 167459:tid 167562] [remote 57.141.22.86:38156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/public/index.php/en/news"] [unique_id "aoSDgWr_JutbFb-8svoCuAABo2Y"] [Tue Aug 18 13:08:33.278252 2026] [security2:error] [pid 167459:tid 167622] [client 20.151.109.219:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/de.php"] [unique_id "aoSDgWr_JutbFb-8svoCuwAAAbA"] [Tue Aug 18 13:08:33.302868 2026] [security2:error] [pid 167459:tid 167677] [client 172.213.243.2:11602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/dsd.php"] [unique_id "aoSDgWr_JutbFb-8svoCvgAAAec"] [Tue Aug 18 13:08:33.303541 2026] [security2:error] [pid 167459:tid 167636] [client 20.215.241.237:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/wp-manager.php"] [unique_id "aoSDgWr_JutbFb-8svoCvwAAAb4"] [Tue Aug 18 13:08:33.355894 2026] [security2:error] [pid 167459:tid 167680] [client 158.23.17.4:39137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/bm.php"] [unique_id "aoSDgWr_JutbFb-8svoCwAAAAeo"] [Tue Aug 18 13:08:33.360525 2026] [security2:error] [pid 167459:tid 167619] [client 74.248.18.37:6275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-we.php"] [unique_id "aoSDgWr_JutbFb-8svoCwQAAAa0"] [Tue Aug 18 13:08:33.392929 2026] [security2:error] [pid 167459:tid 167643] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/ok.php"] [unique_id "aoSDgWr_JutbFb-8svoCwgAAAcU"] [Tue Aug 18 13:08:33.408627 2026] [security2:error] [pid 167459:tid 167657] [client 20.171.51.14:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ez.php"] [unique_id "aoSDgWr_JutbFb-8svoCxgAAAdM"] [Tue Aug 18 13:08:33.427400 2026] [security2:error] [pid 167459:tid 167513] [remote 220.181.108.105:40241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gustavofrison.com.br"] [uri "/wp-login.php"] [unique_id "aoSDgWr_JutbFb-8svoCuQABkzU"] [Tue Aug 18 13:08:33.428953 2026] [security2:error] [pid 167459:tid 167705] [client 20.127.136.245:10273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/aaa.php"] [unique_id "aoSDgWr_JutbFb-8svoCyQAAAgM"] [Tue Aug 18 13:08:33.447422 2026] [security2:error] [pid 167459:tid 167641] [client 20.25.139.174:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/abcd.php"] [unique_id "aoSDgWr_JutbFb-8svoCygAAAcM"] [Tue Aug 18 13:08:33.466421 2026] [security2:error] [pid 167459:tid 167674] [client 158.23.17.4:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/pd.php"] [unique_id "aoSDgWr_JutbFb-8svoCzAAAAeQ"] [Tue Aug 18 13:08:33.491556 2026] [security2:error] [pid 167459:tid 167664] [client 20.250.13.23:39331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/x.php"] [unique_id "aoSDgWr_JutbFb-8svoC0QAAAdo"] [Tue Aug 18 13:08:33.498491 2026] [security2:error] [pid 167459:tid 167716] [client 20.226.36.136:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/weozh.php"] [unique_id "aoSDgWr_JutbFb-8svoC0gAAAg4"] [Tue Aug 18 13:08:33.573111 2026] [security2:error] [pid 167459:tid 167671] [client 52.139.47.57:52369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/IXR/d.php"] [unique_id "aoSDgWr_JutbFb-8svoC1AAAAeE"] [Tue Aug 18 13:08:33.573632 2026] [security2:error] [pid 167459:tid 167666] [client 132.196.30.78:13063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/p.php"] [unique_id "aoSDgWr_JutbFb-8svoC1QAAAdw"] [Tue Aug 18 13:08:33.601954 2026] [security2:error] [pid 167459:tid 167688] [client 213.202.253.4:60386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/txets.php"] [unique_id "aoSDgWr_JutbFb-8svoC1gAAAfI"], referer: www.google.com [Tue Aug 18 13:08:33.612237 2026] [security2:error] [pid 167459:tid 167612] [client 40.74.65.169:20762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/aaa.php"] [unique_id "aoSDgWr_JutbFb-8svoC1wAAAaY"] [Tue Aug 18 13:08:33.627049 2026] [security2:error] [pid 167459:tid 167670] [client 20.186.30.159:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/key.php"] [unique_id "aoSDgWr_JutbFb-8svoC2AAAAeA"] [Tue Aug 18 13:08:33.653124 2026] [security2:error] [pid 167459:tid 167631] [client 20.7.73.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.73.7.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.1td.com.br"] [uri "/item.php"] [unique_id "aoSDgWr_JutbFb-8svoC2gAAAbk"] [Tue Aug 18 13:08:33.679776 2026] [security2:error] [pid 167459:tid 167690] [client 20.79.204.6:6007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDgWr_JutbFb-8svoC2wAAAfQ"] [Tue Aug 18 13:08:33.686712 2026] [security2:error] [pid 167459:tid 167687] [client 172.182.217.32:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDgWr_JutbFb-8svoC3QAAAfE"] [Tue Aug 18 13:08:33.739110 2026] [security2:error] [pid 167459:tid 167682] [client 172.213.243.2:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/c4.php"] [unique_id "aoSDgWr_JutbFb-8svoC4QAAAew"] [Tue Aug 18 13:08:33.740073 2026] [security2:error] [pid 167459:tid 167603] [client 52.173.121.69:36569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDgWr_JutbFb-8svoC4gAAAZ0"] [Tue Aug 18 13:08:33.746883 2026] [security2:error] [pid 167459:tid 167650] [client 158.158.74.177:13724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/ebs.php7"] [unique_id "aoSDgWr_JutbFb-8svoC4wAAAcw"] [Tue Aug 18 13:08:33.755563 2026] [security2:error] [pid 167459:tid 167673] [client 20.215.241.237:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/xiugai.php"] [unique_id "aoSDgWr_JutbFb-8svoC5gAAAeM"] [Tue Aug 18 13:08:33.757401 2026] [security2:error] [pid 167459:tid 167679] [client 4.232.151.198:30100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/special.php"] [unique_id "aoSDgWr_JutbFb-8svoC5wAAAek"] [Tue Aug 18 13:08:33.760199 2026] [security2:error] [pid 167459:tid 167669] [client 158.23.17.4:4627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vu.php"] [unique_id "aoSDgWr_JutbFb-8svoC6AAAAd8"] [Tue Aug 18 13:08:33.768745 2026] [security2:error] [pid 167459:tid 167606] [client 20.226.36.136:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/rymmm.php"] [unique_id "aoSDgWr_JutbFb-8svoC6QAAAaA"] [Tue Aug 18 13:08:33.826553 2026] [security2:error] [pid 167459:tid 167613] [client 4.232.151.198:41202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/min.php"] [unique_id "aoSDgWr_JutbFb-8svoC7AAAAac"] [Tue Aug 18 13:08:33.868980 2026] [security2:error] [pid 167459:tid 167651] [client 20.151.109.219:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/album.php"] [unique_id "aoSDgWr_JutbFb-8svoC7wAAAc0"] [Tue Aug 18 13:08:33.939115 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gb.php"] [unique_id "aoSDgWr_JutbFb-8svoC9QAAAZQ"] [Tue Aug 18 13:08:33.995129 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:32905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-includes/error.php"] [unique_id "aoSDgWr_JutbFb-8svoC9gAAAaQ"] [Tue Aug 18 13:08:33.999685 2026] [security2:error] [pid 167459:tid 167619] [client 20.226.36.136:47953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/lddxs.php"] [unique_id "aoSDgWr_JutbFb-8svoC9wAAAa0"] [Tue Aug 18 13:08:34.014888 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:34.015159 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:34.063052 2026] [security2:error] [pid 167459:tid 167628] [client 20.25.139.174:4521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-good.php"] [unique_id "aoSDgmr_JutbFb-8svoC-wAAAbY"] [Tue Aug 18 13:08:34.153435 2026] [security2:error] [pid 167459:tid 167637] [client 213.35.127.232:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDgmr_JutbFb-8svoDAAAAAb8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:34.171908 2026] [security2:error] [pid 167459:tid 167654] [client 20.226.36.136:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/zjggu.php"] [unique_id "aoSDgmr_JutbFb-8svoDAQAAAdA"] [Tue Aug 18 13:08:34.191641 2026] [security2:error] [pid 167459:tid 167699] [client 20.215.241.237:30428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/wp-load.php"] [unique_id "aoSDgmr_JutbFb-8svoDAwAAAf0"] [Tue Aug 18 13:08:34.195541 2026] [security2:error] [pid 167459:tid 167712] [client 172.182.217.32:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDgmr_JutbFb-8svoDBQAAAgo"] [Tue Aug 18 13:08:34.211194 2026] [security2:error] [pid 167459:tid 167671] [client 172.213.243.2:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/an7.php"] [unique_id "aoSDgmr_JutbFb-8svoDBgAAAeE"] [Tue Aug 18 13:08:34.218509 2026] [security2:error] [pid 167459:tid 167705] [client 132.196.30.78:20299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.30.196.132.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anmultimarcas.com.br"] [uri "/php.php"] [unique_id "aoSDgmr_JutbFb-8svoDBwAAAgM"] [Tue Aug 18 13:08:34.223746 2026] [security2:error] [pid 167459:tid 167620] [client 74.248.133.44:12821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/f5.php"] [unique_id "aoSDgmr_JutbFb-8svoDCAAAAa4"] [Tue Aug 18 13:08:34.253887 2026] [autoindex:error] [pid 167459:tid 167711] [client 52.6.24.224:7066] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:34.257443 2026] [autoindex:error] [pid 167459:tid 167595] [client 52.6.24.224:39982] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodoaco.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:34.262049 2026] [security2:error] [pid 167459:tid 167644] [client 20.104.100.201:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fw/34.php"] [unique_id "aoSDgmr_JutbFb-8svoDDQAAAcY"] [Tue Aug 18 13:08:34.262447 2026] [security2:error] [pid 167459:tid 167611] [client 20.116.17.175:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/aa.php"] [unique_id "aoSDgmr_JutbFb-8svoDDgAAAaU"] [Tue Aug 18 13:08:34.313447 2026] [security2:error] [pid 167459:tid 167641] [client 20.79.204.6:5728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDgmr_JutbFb-8svoDFgAAAcM"] [Tue Aug 18 13:08:34.314454 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:34.314750 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:34.337840 2026] [security2:error] [pid 167459:tid 167682] [client 158.23.17.4:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ic.php"] [unique_id "aoSDgmr_JutbFb-8svoDGgAAAew"] [Tue Aug 18 13:08:34.359046 2026] [security2:error] [pid 167459:tid 167669] [client 20.226.36.136:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/dlvqo.php"] [unique_id "aoSDgmr_JutbFb-8svoDHQAAAd8"] [Tue Aug 18 13:08:34.392352 2026] [security2:error] [pid 167459:tid 167681] [client 20.226.36.136:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/pkmoj.php"] [unique_id "aoSDgmr_JutbFb-8svoDIgAAAes"] [Tue Aug 18 13:08:34.400908 2026] [security2:error] [pid 167459:tid 167590] [client 158.158.74.177:13790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSDgmr_JutbFb-8svoDIwAAAZA"] [Tue Aug 18 13:08:34.408551 2026] [security2:error] [pid 167459:tid 167512] [remote 162.241.152.27:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-login.php"] [unique_id "aoSDgmr_JutbFb-8svoDJAAB5DQ"] [Tue Aug 18 13:08:34.410731 2026] [security2:error] [pid 167459:tid 167683] [client 4.232.151.198:2445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ssjpxze.php"] [unique_id "aoSDgmr_JutbFb-8svoDJQAAAe0"] [Tue Aug 18 13:08:34.423465 2026] [security2:error] [pid 167459:tid 167648] [client 52.139.47.57:32942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/error.php"] [unique_id "aoSDgmr_JutbFb-8svoDJgAAAco"] [Tue Aug 18 13:08:34.432105 2026] [security2:error] [pid 167459:tid 167672] [client 20.151.109.219:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kv.php"] [unique_id "aoSDgmr_JutbFb-8svoDKAAAAeI"] [Tue Aug 18 13:08:34.445973 2026] [security2:error] [pid 167459:tid 167653] [client 40.74.65.169:20547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gecko.php"] [unique_id "aoSDgmr_JutbFb-8svoDKQAAAc8"] [Tue Aug 18 13:08:34.452358 2026] [security2:error] [pid 167459:tid 167678] [client 20.226.36.136:61449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/kopyw.php"] [unique_id "aoSDgmr_JutbFb-8svoDKgAAAeg"] [Tue Aug 18 13:08:34.454272 2026] [security2:error] [pid 167459:tid 167647] [client 74.248.18.37:6317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDgmr_JutbFb-8svoDKwAAAck"] [Tue Aug 18 13:08:34.471859 2026] [security2:error] [pid 167459:tid 167602] [client 20.65.69.59:1312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/wp-title.php"] [unique_id "aoSDgmr_JutbFb-8svoDLwAAAZw"] [Tue Aug 18 13:08:34.546300 2026] [security2:error] [pid 167459:tid 167622] [client 20.226.36.136:53529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/zznmg.php"] [unique_id "aoSDgmr_JutbFb-8svoDMgAAAbA"] [Tue Aug 18 13:08:34.579113 2026] [security2:error] [pid 167459:tid 167709] [client 20.226.36.136:65296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/bhfnd.php"] [unique_id "aoSDgmr_JutbFb-8svoDNAAAAgc"] [Tue Aug 18 13:08:34.597393 2026] [security2:error] [pid 167459:tid 167610] [client 20.127.136.245:4413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/term.php"] [unique_id "aoSDgmr_JutbFb-8svoDNQAAAaQ"] [Tue Aug 18 13:08:34.618138 2026] [authz_core:error] [pid 167459:tid 167584] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:34.618414 2026] [authz_core:error] [pid 167459:tid 167584] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:34.619308 2026] [security2:error] [pid 167459:tid 167600] [client 149.34.210.141:54027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDgmr_JutbFb-8svoDOQAAAZo"] [Tue Aug 18 13:08:34.626907 2026] [security2:error] [pid 167459:tid 167593] [client 172.213.243.2:19538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/bsg-management/php.php"] [unique_id "aoSDgmr_JutbFb-8svoDOgAAAZM"] [Tue Aug 18 13:08:34.627507 2026] [security2:error] [pid 167459:tid 167651] [client 20.25.139.174:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/simple.php"] [unique_id "aoSDgmr_JutbFb-8svoDOwAAAc0"] [Tue Aug 18 13:08:34.630670 2026] [security2:error] [pid 167459:tid 167628] [client 20.215.241.237:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/155.php"] [unique_id "aoSDgmr_JutbFb-8svoDPAAAAbY"] [Tue Aug 18 13:08:34.631812 2026] [security2:error] [pid 167459:tid 167627] [client 20.226.36.136:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/qfvqu.php"] [unique_id "aoSDgmr_JutbFb-8svoDPQAAAbU"] [Tue Aug 18 13:08:34.680702 2026] [security2:error] [pid 167459:tid 167654] [client 20.226.36.136:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/oivcl.php"] [unique_id "aoSDgmr_JutbFb-8svoDPwAAAdA"] [Tue Aug 18 13:08:34.687503 2026] [security2:error] [pid 167459:tid 167685] [client 172.182.217.32:25630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-mail.php"] [unique_id "aoSDgmr_JutbFb-8svoDQAAAAe8"] [Tue Aug 18 13:08:34.701162 2026] [autoindex:error] [pid 167459:tid 167699] [client 3.210.118.109:55151] AH01276: Cannot serve directory /home2/siderurgiabrasil/anuariodasiderurgia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:34.705477 2026] [security2:error] [pid 167459:tid 167712] [client 20.226.36.136:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/zugvi.php"] [unique_id "aoSDgmr_JutbFb-8svoDQgAAAgo"] [Tue Aug 18 13:08:34.737296 2026] [security2:error] [pid 167459:tid 167666] [client 20.104.100.201:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/classwithtostring.php"] [unique_id "aoSDgmr_JutbFb-8svoDQwAAAdw"] [Tue Aug 18 13:08:34.748799 2026] [security2:error] [pid 167459:tid 167711] [client 20.186.30.159:9844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/chosen.php"] [unique_id "aoSDgmr_JutbFb-8svoDRwAAAgk"] [Tue Aug 18 13:08:34.749633 2026] [security2:error] [pid 167459:tid 167664] [client 216.73.160.240:29849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ruanautomoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSDgmr_JutbFb-8svoDRQAAAdo"] [Tue Aug 18 13:08:34.761877 2026] [security2:error] [pid 167459:tid 167644] [client 20.151.109.219:40508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/z.php"] [unique_id "aoSDgmr_JutbFb-8svoDSAAAAcY"] [Tue Aug 18 13:08:34.786504 2026] [security2:error] [pid 167459:tid 167688] [client 20.226.36.136:52660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wsrer.php"] [unique_id "aoSDgmr_JutbFb-8svoDSgAAAfI"] [Tue Aug 18 13:08:34.845870 2026] [security2:error] [pid 167459:tid 167671] [client 52.139.47.57:38039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/zogy1.php"] [unique_id "aoSDgmr_JutbFb-8svoDTgAAAeE"] [Tue Aug 18 13:08:34.877632 2026] [security2:error] [pid 167459:tid 167650] [client 52.173.121.69:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/rezor.php"] [unique_id "aoSDgmr_JutbFb-8svoDTwAAAcw"] [Tue Aug 18 13:08:34.890738 2026] [security2:error] [pid 167459:tid 167600] [client 149.34.210.141:54027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDgmr_JutbFb-8svoDOQAAAZo"] [Tue Aug 18 13:08:34.921065 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:34.921469 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:34.928046 2026] [security2:error] [pid 167459:tid 167614] [client 20.226.36.136:47948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/ucpfr.php"] [unique_id "aoSDgmr_JutbFb-8svoDVAAAAag"] [Tue Aug 18 13:08:34.936181 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:25391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/th.php"] [unique_id "aoSDgmr_JutbFb-8svoDVQAAAc4"] [Tue Aug 18 13:08:34.940377 2026] [security2:error] [pid 167459:tid 167706] [client 158.23.17.4:40245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ue.php"] [unique_id "aoSDgmr_JutbFb-8svoDVgAAAgQ"] [Tue Aug 18 13:08:35.012027 2026] [security2:error] [pid 167459:tid 167625] [client 158.23.17.4:48398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/jp.php"] [unique_id "aoSDg2r_JutbFb-8svoDWwAAAbM"] [Tue Aug 18 13:08:35.013538 2026] [security2:error] [pid 167459:tid 167674] [client 20.226.36.136:48855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/yxijx.php"] [unique_id "aoSDg2r_JutbFb-8svoDXAAAAeQ"] [Tue Aug 18 13:08:35.024389 2026] [security2:error] [pid 167459:tid 167690] [client 158.158.74.177:14246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSDg2r_JutbFb-8svoDXgAAAfQ"] [Tue Aug 18 13:08:35.045005 2026] [security2:error] [pid 167459:tid 167687] [client 172.213.243.2:11805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/byp8.php"] [unique_id "aoSDg2r_JutbFb-8svoDXwAAAfE"] [Tue Aug 18 13:08:35.050647 2026] [security2:error] [pid 167459:tid 167601] [client 4.232.151.198:2624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/storage/index.php"] [unique_id "aoSDg2r_JutbFb-8svoDYAAAAZs"] [Tue Aug 18 13:08:35.053893 2026] [security2:error] [pid 167459:tid 167672] [client 20.65.69.59:22048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/styles.php"] [unique_id "aoSDg2r_JutbFb-8svoDYQAAAeI"] [Tue Aug 18 13:08:35.058753 2026] [security2:error] [pid 167459:tid 167678] [client 20.104.100.201:53293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp9.php"] [unique_id "aoSDg2r_JutbFb-8svoDYgAAAeg"] [Tue Aug 18 13:08:35.080783 2026] [security2:error] [pid 167459:tid 167638] [client 20.104.100.201:62603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/v2.php"] [unique_id "aoSDg2r_JutbFb-8svoDZgAAAcA"] [Tue Aug 18 13:08:35.081079 2026] [security2:error] [pid 167459:tid 167602] [client 20.226.36.136:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/zwlsv.php"] [unique_id "aoSDg2r_JutbFb-8svoDZQAAAZw"] [Tue Aug 18 13:08:35.086111 2026] [security2:error] [pid 167459:tid 167656] [client 20.215.241.237:59728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/index.php"] [unique_id "aoSDg2r_JutbFb-8svoDaQAAAdI"] [Tue Aug 18 13:08:35.120559 2026] [security2:error] [pid 167459:tid 167649] [client 20.151.109.219:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xg.php"] [unique_id "aoSDg2r_JutbFb-8svoDbQAAAcs"] [Tue Aug 18 13:08:35.133662 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.100.201:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-the.php"] [unique_id "aoSDg2r_JutbFb-8svoDbwAAAdE"] [Tue Aug 18 13:08:35.141767 2026] [security2:error] [pid 167459:tid 167660] [client 20.250.13.23:27384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/index/function.php"] [unique_id "aoSDg2r_JutbFb-8svoDcQAAAdY"] [Tue Aug 18 13:08:35.173091 2026] [security2:error] [pid 167459:tid 167668] [client 68.155.154.236:25345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDg2r_JutbFb-8svoDdQAAAd4"] [Tue Aug 18 13:08:35.173926 2026] [security2:error] [pid 167459:tid 167708] [client 213.35.127.232:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDg2r_JutbFb-8svoDdgAAAgY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:35.184338 2026] [security2:error] [pid 167459:tid 167657] [client 40.74.65.169:36931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/xiugai.php"] [unique_id "aoSDg2r_JutbFb-8svoDdwAAAdM"] [Tue Aug 18 13:08:35.189417 2026] [security2:error] [pid 167459:tid 167703] [client 172.182.217.32:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/abe.php"] [unique_id "aoSDg2r_JutbFb-8svoDegAAAgE"] [Tue Aug 18 13:08:35.197715 2026] [security2:error] [pid 167459:tid 167665] [client 74.248.18.37:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/ulc2.php"] [unique_id "aoSDg2r_JutbFb-8svoDfAAAAds"] [Tue Aug 18 13:08:35.214781 2026] [security2:error] [pid 167459:tid 167710] [client 20.25.139.174:4511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/edit-tags.php"] [unique_id "aoSDg2r_JutbFb-8svoDgAAAAgg"] [Tue Aug 18 13:08:35.221655 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:35.222125 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:35.261449 2026] [security2:error] [pid 167459:tid 167594] [client 52.139.47.57:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDg2r_JutbFb-8svoDigAAAZQ"] [Tue Aug 18 13:08:35.280264 2026] [autoindex:error] [pid 167459:tid 167637] [client 4.232.151.198:40837] AH01276: Cannot serve directory /home3/lucascamargosadv/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:35.331520 2026] [security2:error] [pid 167459:tid 167636] [client 20.116.17.175:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/echkm.php"] [unique_id "aoSDg2r_JutbFb-8svoDjgAAAb4"] [Tue Aug 18 13:08:35.350459 2026] [autoindex:error] [pid 167459:tid 167699] [client 20.79.204.6:5967] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:35.363702 2026] [security2:error] [pid 167459:tid 167688] [client 20.206.73.37:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/fz.php"] [unique_id "aoSDg2r_JutbFb-8svoDlQAAAfI"] [Tue Aug 18 13:08:35.375056 2026] [security2:error] [pid 167459:tid 167696] [client 20.226.36.136:52633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/jrpga.php"] [unique_id "aoSDg2r_JutbFb-8svoDlgAAAfo"] [Tue Aug 18 13:08:35.387860 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:37748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/ws54.php"] [unique_id "aoSDg2r_JutbFb-8svoDmAAAAfY"] [Tue Aug 18 13:08:35.444232 2026] [security2:error] [pid 167459:tid 167524] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDg2r_JutbFb-8svoDnQABmkA"] [Tue Aug 18 13:08:35.444464 2026] [security2:error] [pid 167459:tid 167600] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDg2r_JutbFb-8svoDnQABmkA"] [Tue Aug 18 13:08:35.447135 2026] [security2:error] [pid 167459:tid 167629] [client 158.23.17.4:7300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lr.php"] [unique_id "aoSDg2r_JutbFb-8svoDngAAAbc"] [Tue Aug 18 13:08:35.468946 2026] [security2:error] [pid 167459:tid 167673] [client 172.213.243.2:14538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/plugins.php"] [unique_id "aoSDg2r_JutbFb-8svoDnwAAAeM"] [Tue Aug 18 13:08:35.504802 2026] [security2:error] [pid 167459:tid 167598] [client 20.215.241.237:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/aaa.php"] [unique_id "aoSDg2r_JutbFb-8svoDogAAAZg"] [Tue Aug 18 13:08:35.527537 2026] [security2:error] [pid 167459:tid 167596] [client 4.232.151.198:40837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/php8.php"] [unique_id "aoSDg2r_JutbFb-8svoDowAAAZY"] [Tue Aug 18 13:08:35.532299 2026] [security2:error] [pid 167459:tid 167681] [client 20.65.69.59:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/server.php"] [unique_id "aoSDg2r_JutbFb-8svoDpAAAAes"] [Tue Aug 18 13:08:35.533510 2026] [security2:error] [pid 167459:tid 167590] [client 20.171.51.14:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/asus.php"] [unique_id "aoSDg2r_JutbFb-8svoDpQAAAZA"] [Tue Aug 18 13:08:35.562269 2026] [security2:error] [pid 167459:tid 167674] [client 52.173.121.69:28310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDg2r_JutbFb-8svoDqAAAAeQ"] [Tue Aug 18 13:08:35.562359 2026] [security2:error] [pid 167459:tid 167675] [client 20.79.204.6:5967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDg2r_JutbFb-8svoDpwAAAeU"] [Tue Aug 18 13:08:35.639020 2026] [security2:error] [pid 167459:tid 167678] [client 172.202.39.151:27899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDg2r_JutbFb-8svoDqwAAAeg"] [Tue Aug 18 13:08:35.650443 2026] [security2:error] [pid 167459:tid 167689] [client 158.158.74.177:13796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/lite.php"] [unique_id "aoSDg2r_JutbFb-8svoDrQAAAfM"] [Tue Aug 18 13:08:35.663796 2026] [security2:error] [pid 167459:tid 167603] [client 157.20.138.62:57608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDg2r_JutbFb-8svoDrwAAAZ0"] [Tue Aug 18 13:08:35.663930 2026] [security2:error] [pid 167459:tid 167603] [client 157.20.138.62:57608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDg2r_JutbFb-8svoDrwAAAZ0"] [Tue Aug 18 13:08:35.676291 2026] [security2:error] [pid 167459:tid 167632] [client 52.139.47.57:32923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/news-admin.php"] [unique_id "aoSDg2r_JutbFb-8svoDsAAAAbo"] [Tue Aug 18 13:08:35.677990 2026] [security2:error] [pid 167459:tid 167652] [client 172.182.217.32:4095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/admin/index_upload.php"] [unique_id "aoSDg2r_JutbFb-8svoDsQAAAc4"] [Tue Aug 18 13:08:35.689155 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:35.689427 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:35.738250 2026] [security2:error] [pid 167459:tid 167679] [client 4.232.151.198:2550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/storage/rip.php"] [unique_id "aoSDg2r_JutbFb-8svoDtgAAAek"] [Tue Aug 18 13:08:35.747484 2026] [security2:error] [pid 167459:tid 167622] [client 20.151.109.219:22957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/nd.php"] [unique_id "aoSDg2r_JutbFb-8svoDtwAAAbA"] [Tue Aug 18 13:08:35.773501 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.100.201:53317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/save.php"] [unique_id "aoSDg2r_JutbFb-8svoDuQAAAdE"] [Tue Aug 18 13:08:35.790061 2026] [security2:error] [pid 167459:tid 167687] [client 20.25.139.174:4481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/u.php"] [unique_id "aoSDg2r_JutbFb-8svoDvAAAAfE"] [Tue Aug 18 13:08:35.844774 2026] [security2:error] [pid 167459:tid 167662] [client 20.226.36.136:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDg2r_JutbFb-8svoDvQAAAdg"] [Tue Aug 18 13:08:35.914690 2026] [security2:error] [pid 167459:tid 167685] [client 20.127.136.245:4375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/7.php"] [unique_id "aoSDg2r_JutbFb-8svoDwgAAAe8"] [Tue Aug 18 13:08:35.925672 2026] [security2:error] [pid 167459:tid 167635] [client 172.213.243.2:48325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/100.kb.php"] [unique_id "aoSDg2r_JutbFb-8svoDwwAAAb0"] [Tue Aug 18 13:08:35.943196 2026] [security2:error] [pid 167459:tid 167712] [client 20.215.241.237:40524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/FWAZ.php"] [unique_id "aoSDg2r_JutbFb-8svoDxQAAAgo"] [Tue Aug 18 13:08:35.991410 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:35.991697 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:36.017211 2026] [security2:error] [pid 167459:tid 167651] [client 158.23.17.4:39570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ka.php"] [unique_id "aoSDhGr_JutbFb-8svoDxwAAAc0"] [Tue Aug 18 13:08:36.067562 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:27892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-good.php"] [unique_id "aoSDhGr_JutbFb-8svoDygAAAbw"] [Tue Aug 18 13:08:36.093628 2026] [security2:error] [pid 167459:tid 167605] [client 74.248.18.37:6282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/RxR_uvhya.php"] [unique_id "aoSDhGr_JutbFb-8svoDzAAAAZ8"] [Tue Aug 18 13:08:36.095646 2026] [security2:error] [pid 167459:tid 167620] [client 52.139.47.57:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/css/root.php"] [unique_id "aoSDhGr_JutbFb-8svoDzQAAAa4"] [Tue Aug 18 13:08:36.097049 2026] [security2:error] [pid 167459:tid 167659] [client 20.186.30.159:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/wpxml.php"] [unique_id "aoSDhGr_JutbFb-8svoDzgAAAdU"] [Tue Aug 18 13:08:36.097888 2026] [security2:error] [pid 167459:tid 167615] [client 40.74.65.169:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/adminner.php"] [unique_id "aoSDhGr_JutbFb-8svoDzwAAAak"] [Tue Aug 18 13:08:36.133891 2026] [security2:error] [pid 167459:tid 167693] [client 20.226.36.136:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/nwwha.php"] [unique_id "aoSDhGr_JutbFb-8svoD0wAAAfc"] [Tue Aug 18 13:08:36.167962 2026] [security2:error] [pid 167459:tid 167642] [client 172.182.217.32:25620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/admin/upload/css.php"] [unique_id "aoSDhGr_JutbFb-8svoD1AAAAcQ"] [Tue Aug 18 13:08:36.180267 2026] [security2:error] [pid 167459:tid 167625] [client 178.153.171.161:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDhGr_JutbFb-8svoD1gAAAbM"] [Tue Aug 18 13:08:36.180404 2026] [security2:error] [pid 167459:tid 167625] [client 178.153.171.161:36936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDhGr_JutbFb-8svoD1gAAAbM"] [Tue Aug 18 13:08:36.188880 2026] [security2:error] [pid 167459:tid 167701] [client 20.65.69.59:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/xinfo.php"] [unique_id "aoSDhGr_JutbFb-8svoD1wAAAf8"] [Tue Aug 18 13:08:36.189518 2026] [security2:error] [pid 167459:tid 167657] [client 213.35.127.232:65214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDhGr_JutbFb-8svoD2AAAAdM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:36.192291 2026] [security2:error] [pid 167459:tid 167711] [client 20.79.204.6:5993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSDhGr_JutbFb-8svoD2QAAAgk"] [Tue Aug 18 13:08:36.219377 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSDhGr_JutbFb-8svoD3QAAAgU"] [Tue Aug 18 13:08:36.248432 2026] [security2:error] [pid 167459:tid 167672] [client 52.173.121.69:28351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDhGr_JutbFb-8svoD3wAAAeI"] [Tue Aug 18 13:08:36.260768 2026] [security2:error] [pid 167459:tid 167653] [client 20.151.109.219:20676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ri.php"] [unique_id "aoSDhGr_JutbFb-8svoD4AAAAc8"] [Tue Aug 18 13:08:36.273690 2026] [security2:error] [pid 167459:tid 167696] [client 158.158.74.177:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSDhGr_JutbFb-8svoD4gAAAfo"] [Tue Aug 18 13:08:36.293142 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:36.293457 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:36.343959 2026] [security2:error] [pid 167459:tid 167597] [client 20.250.13.23:50127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/aaa.php"] [unique_id "aoSDhGr_JutbFb-8svoD6AAAAZc"] [Tue Aug 18 13:08:36.359770 2026] [security2:error] [pid 167459:tid 167598] [client 20.25.139.174:4622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDhGr_JutbFb-8svoD6QAAAZg"] [Tue Aug 18 13:08:36.413383 2026] [security2:error] [pid 167459:tid 167630] [client 172.213.243.2:48324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/mamzi.php"] [unique_id "aoSDhGr_JutbFb-8svoD7gAAAbg"] [Tue Aug 18 13:08:36.415528 2026] [security2:error] [pid 167459:tid 167529] [remote 5.188.86.234:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bjagricola.com.br"] [uri "/wp-login.php"] [unique_id "aoSDhGr_JutbFb-8svoD7QAB60U"] [Tue Aug 18 13:08:36.460831 2026] [security2:error] [pid 167459:tid 167706] [client 4.232.151.198:2653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/sts.php"] [unique_id "aoSDhGr_JutbFb-8svoD7wAAAgQ"] [Tue Aug 18 13:08:36.466251 2026] [security2:error] [pid 167459:tid 167668] [client 20.215.241.237:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/site.php"] [unique_id "aoSDhGr_JutbFb-8svoD8AAAAd4"] [Tue Aug 18 13:08:36.513737 2026] [security2:error] [pid 167459:tid 167626] [client 20.104.100.201:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wkl.php"] [unique_id "aoSDhGr_JutbFb-8svoD9QAAAbQ"] [Tue Aug 18 13:08:36.514450 2026] [security2:error] [pid 167459:tid 167647] [client 52.139.47.57:56255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/js/goods.php"] [unique_id "aoSDhGr_JutbFb-8svoD9gAAAck"] [Tue Aug 18 13:08:36.542971 2026] [security2:error] [pid 167459:tid 167591] [client 20.226.36.136:47976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/opsqt.php"] [unique_id "aoSDhGr_JutbFb-8svoD-AAAAZE"] [Tue Aug 18 13:08:36.589303 2026] [security2:error] [pid 167459:tid 167589] [client 158.23.17.4:4630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ot.php"] [unique_id "aoSDhGr_JutbFb-8svoD-wAAAY8"] [Tue Aug 18 13:08:36.655186 2026] [security2:error] [pid 167459:tid 167665] [client 172.182.217.32:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/al.php"] [unique_id "aoSDhGr_JutbFb-8svoD_QAAAds"] [Tue Aug 18 13:08:36.685131 2026] [security2:error] [pid 167459:tid 167615] [client 20.104.100.201:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDhGr_JutbFb-8svoD_wAAAak"] [Tue Aug 18 13:08:36.734647 2026] [security2:error] [pid 167459:tid 167663] [client 20.127.136.245:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/file5.php"] [unique_id "aoSDhGr_JutbFb-8svoEAQAAAdk"] [Tue Aug 18 13:08:36.830522 2026] [security2:error] [pid 167459:tid 167702] [client 52.173.121.69:28329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/index/function.php"] [unique_id "aoSDhGr_JutbFb-8svoECAAAAgA"] [Tue Aug 18 13:08:36.848671 2026] [security2:error] [pid 167459:tid 167611] [client 20.25.139.174:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/h.php"] [unique_id "aoSDhGr_JutbFb-8svoECQAAAaU"] [Tue Aug 18 13:08:36.855020 2026] [security2:error] [pid 167459:tid 167596] [client 172.213.243.2:48333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ms.php"] [unique_id "aoSDhGr_JutbFb-8svoECwAAAZY"] [Tue Aug 18 13:08:36.859034 2026] [security2:error] [pid 167459:tid 167707] [client 40.74.65.169:21338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file1221.php"] [unique_id "aoSDhGr_JutbFb-8svoEDAAAAgU"] [Tue Aug 18 13:08:36.859847 2026] [security2:error] [pid 167459:tid 167634] [client 74.248.18.37:6589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/storage/upload/bypass.php"] [unique_id "aoSDhGr_JutbFb-8svoEDgAAAbw"] [Tue Aug 18 13:08:36.882009 2026] [autoindex:error] [pid 167459:tid 167619] [client 20.79.204.6:6102] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:36.891684 2026] [security2:error] [pid 167459:tid 167645] [client 158.158.74.177:14248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSDhGr_JutbFb-8svoEEgAAAcc"] [Tue Aug 18 13:08:36.901352 2026] [security2:error] [pid 167459:tid 167684] [client 20.215.241.237:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/ccc.php"] [unique_id "aoSDhGr_JutbFb-8svoEEwAAAe4"] [Tue Aug 18 13:08:36.921682 2026] [security2:error] [pid 167459:tid 167653] [client 158.23.17.4:20478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/eq.php"] [unique_id "aoSDhGr_JutbFb-8svoEFQAAAc8"] [Tue Aug 18 13:08:36.932618 2026] [security2:error] [pid 167459:tid 167642] [client 52.139.47.57:29449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/ak.php"] [unique_id "aoSDhGr_JutbFb-8svoEFgAAAcQ"] [Tue Aug 18 13:08:37.063608 2026] [security2:error] [pid 167459:tid 167497] [remote 121.200.216.188:40882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wrtech.com.br"] [uri "/wp-login.php"] [unique_id "aoSDhWr_JutbFb-8svoEKQAB8SU"] [Tue Aug 18 13:08:37.083059 2026] [security2:error] [pid 167459:tid 167626] [client 20.79.204.6:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDhWr_JutbFb-8svoELAAAAbQ"] [Tue Aug 18 13:08:37.087398 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:39148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ih.php"] [unique_id "aoSDhWr_JutbFb-8svoELQAAAZQ"] [Tue Aug 18 13:08:37.128931 2026] [security2:error] [pid 167459:tid 167601] [client 4.232.151.198:2543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/system_log.php"] [unique_id "aoSDhWr_JutbFb-8svoEMAAAAZs"] [Tue Aug 18 13:08:37.145059 2026] [security2:error] [pid 167459:tid 167623] [client 172.182.217.32:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/baxa1.php"] [unique_id "aoSDhWr_JutbFb-8svoENQAAAbE"] [Tue Aug 18 13:08:37.156051 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/df.php"] [unique_id "aoSDhWr_JutbFb-8svoENwAAAZU"] [Tue Aug 18 13:08:37.184781 2026] [security2:error] [pid 167459:tid 167699] [client 20.151.109.219:38148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/tp.php"] [unique_id "aoSDhWr_JutbFb-8svoEOwAAAf0"] [Tue Aug 18 13:08:37.189087 2026] [security2:error] [pid 167459:tid 167686] [client 52.173.121.69:49950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDhWr_JutbFb-8svoEPQAAAfA"] [Tue Aug 18 13:08:37.196145 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:37.196436 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:37.201066 2026] [security2:error] [pid 167459:tid 167675] [client 213.35.127.232:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDhWr_JutbFb-8svoEQAAAAeU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:37.302371 2026] [security2:error] [pid 167459:tid 167596] [client 172.202.39.151:27857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/tes.php"] [unique_id "aoSDhWr_JutbFb-8svoESAAAAZY"] [Tue Aug 18 13:08:37.303036 2026] [security2:error] [pid 167459:tid 167616] [client 172.213.243.2:48346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/gfile.php"] [unique_id "aoSDhWr_JutbFb-8svoESQAAAao"] [Tue Aug 18 13:08:37.340853 2026] [security2:error] [pid 167459:tid 167645] [client 20.186.30.159:12524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/file1221.php"] [unique_id "aoSDhWr_JutbFb-8svoEUQAAAcc"] [Tue Aug 18 13:08:37.355813 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/wp-admin/maint/vc.php"] [unique_id "aoSDhWr_JutbFb-8svoEUgAAAak"] [Tue Aug 18 13:08:37.396495 2026] [security2:error] [pid 167459:tid 167697] [client 20.215.241.237:3003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/admin.php"] [unique_id "aoSDhWr_JutbFb-8svoEUwAAAfs"] [Tue Aug 18 13:08:37.418379 2026] [security2:error] [pid 167459:tid 167603] [client 20.116.17.175:52580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/domvf.php"] [unique_id "aoSDhWr_JutbFb-8svoEVQAAAZ0"] [Tue Aug 18 13:08:37.443470 2026] [security2:error] [pid 167459:tid 167663] [client 20.25.139.174:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ms-edit.php"] [unique_id "aoSDhWr_JutbFb-8svoEVwAAAdk"] [Tue Aug 18 13:08:37.493709 2026] [security2:error] [pid 167459:tid 167598] [client 5.188.86.234:39320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.86.188.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bjagricola.com.br"] [uri "/wp-login.php"] [unique_id "aoSDhWr_JutbFb-8svoEXgAAAZg"] [Tue Aug 18 13:08:37.510567 2026] [security2:error] [pid 167459:tid 167674] [client 158.158.74.177:14210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSDhWr_JutbFb-8svoEXwAAAeQ"] [Tue Aug 18 13:08:37.563752 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:15779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/admin404.php"] [unique_id "aoSDhWr_JutbFb-8svoEYwAAAZI"] [Tue Aug 18 13:08:37.569111 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:7311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/k.php"] [unique_id "aoSDhWr_JutbFb-8svoEZAAAAeg"] [Tue Aug 18 13:08:37.579493 2026] [security2:error] [pid 167459:tid 167656] [client 20.226.36.136:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDhWr_JutbFb-8svoEZgAAAdI"] [Tue Aug 18 13:08:37.634565 2026] [security2:error] [pid 167459:tid 167597] [client 172.182.217.32:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/buy.php"] [unique_id "aoSDhWr_JutbFb-8svoEaQAAAZc"] [Tue Aug 18 13:08:37.641970 2026] [security2:error] [pid 167459:tid 167662] [client 20.127.136.245:7129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDhWr_JutbFb-8svoEagAAAdg"] [Tue Aug 18 13:08:37.677874 2026] [security2:error] [pid 167459:tid 167668] [client 20.116.17.175:22778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDhWr_JutbFb-8svoEbgAAAd4"] [Tue Aug 18 13:08:37.682829 2026] [security2:error] [pid 167459:tid 167714] [client 74.248.18.37:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.sobanheiras.com.br"] [uri "/alfav4-1-0.php"] [unique_id "aoSDhWr_JutbFb-8svoEcQAAAgw"] [Tue Aug 18 13:08:37.700642 2026] [security2:error] [pid 167459:tid 167608] [client 20.104.100.201:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDhWr_JutbFb-8svoEcgAAAaI"] [Tue Aug 18 13:08:37.715035 2026] [security2:error] [pid 167459:tid 167626] [client 20.104.100.201:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-asudo.php"] [unique_id "aoSDhWr_JutbFb-8svoEdQAAAbQ"] [Tue Aug 18 13:08:37.720193 2026] [security2:error] [pid 167459:tid 167594] [client 52.173.121.69:28299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/Cachex.php"] [unique_id "aoSDhWr_JutbFb-8svoEdgAAAZQ"] [Tue Aug 18 13:08:37.725657 2026] [security2:error] [pid 167459:tid 167693] [client 172.213.243.2:19863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/public/wp-blog.php"] [unique_id "aoSDhWr_JutbFb-8svoEdwAAAfc"] [Tue Aug 18 13:08:37.772304 2026] [security2:error] [pid 167459:tid 167706] [client 52.139.47.57:5683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/.well-known/nastar.php"] [unique_id "aoSDhWr_JutbFb-8svoEegAAAgQ"] [Tue Aug 18 13:08:37.778882 2026] [autoindex:error] [pid 167459:tid 167630] [client 20.100.169.31:11033] AH01276: Cannot serve directory /home4/cidadedemilao/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:37.795491 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:37.795760 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:37.799372 2026] [security2:error] [pid 167459:tid 167677] [client 4.232.151.198:2638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/t.php"] [unique_id "aoSDhWr_JutbFb-8svoEfQAAAec"] [Tue Aug 18 13:08:37.848975 2026] [security2:error] [pid 167459:tid 167675] [client 20.171.51.14:23550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/22.php"] [unique_id "aoSDhWr_JutbFb-8svoEfgAAAeU"] [Tue Aug 18 13:08:37.852182 2026] [security2:error] [pid 167459:tid 167610] [client 20.79.204.6:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDhWr_JutbFb-8svoEfwAAAaQ"] [Tue Aug 18 13:08:37.869493 2026] [security2:error] [pid 167459:tid 167671] [client 40.74.65.169:20549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/inx.php"] [unique_id "aoSDhWr_JutbFb-8svoEggAAAeE"] [Tue Aug 18 13:08:37.921503 2026] [security2:error] [pid 167459:tid 167669] [client 20.215.241.237:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/reviall.php"] [unique_id "aoSDhWr_JutbFb-8svoEhAAAAd8"] [Tue Aug 18 13:08:37.991905 2026] [security2:error] [pid 167459:tid 167686] [client 20.25.139.174:4537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/a7.php"] [unique_id "aoSDhWr_JutbFb-8svoEiwAAAfA"] [Tue Aug 18 13:08:37.994179 2026] [security2:error] [pid 167459:tid 167618] [client 74.248.18.37:31791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDhWr_JutbFb-8svoEjAAAAaw"] [Tue Aug 18 13:08:38.098200 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:38.098469 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:38.120687 2026] [security2:error] [pid 167459:tid 167698] [client 172.182.217.32:25584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/cong.php"] [unique_id "aoSDhmr_JutbFb-8svoEkgAAAfw"] [Tue Aug 18 13:08:38.142089 2026] [security2:error] [pid 167459:tid 167663] [client 52.173.121.69:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDhmr_JutbFb-8svoElQAAAdk"] [Tue Aug 18 13:08:38.154024 2026] [security2:error] [pid 167459:tid 167692] [client 20.104.100.201:9563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/usr.php"] [unique_id "aoSDhmr_JutbFb-8svoElwAAAfY"] [Tue Aug 18 13:08:38.186155 2026] [security2:error] [pid 167459:tid 167640] [client 158.158.74.177:13736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDhmr_JutbFb-8svoEmQAAAcI"] [Tue Aug 18 13:08:38.208549 2026] [security2:error] [pid 167459:tid 167645] [client 52.139.47.57:56251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "godmotors.com.br"] [uri "/images/upload-size.php"] [unique_id "aoSDhmr_JutbFb-8svoEmgAAAcc"] [Tue Aug 18 13:08:38.208994 2026] [security2:error] [pid 167459:tid 167661] [client 172.213.243.2:14354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/cu.php"] [unique_id "aoSDhmr_JutbFb-8svoEmwAAAdc"] [Tue Aug 18 13:08:38.211876 2026] [security2:error] [pid 167459:tid 167628] [client 213.35.127.232:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDhmr_JutbFb-8svoEnAAAAbY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:38.249296 2026] [security2:error] [pid 167459:tid 167679] [client 20.65.69.59:35431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/sym.php"] [unique_id "aoSDhmr_JutbFb-8svoEogAAAek"] [Tue Aug 18 13:08:38.309181 2026] [security2:error] [pid 167459:tid 167621] [client 158.23.17.4:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ep.php"] [unique_id "aoSDhmr_JutbFb-8svoEpAAAAa8"] [Tue Aug 18 13:08:38.388658 2026] [security2:error] [pid 167459:tid 167597] [client 158.23.17.4:38383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/iu.php"] [unique_id "aoSDhmr_JutbFb-8svoEpgAAAZc"] [Tue Aug 18 13:08:38.402546 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:38.402959 2026] [authz_core:error] [pid 167459:tid 167579] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:38.416199 2026] [security2:error] [pid 167459:tid 167659] [client 20.226.36.136:52641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDhmr_JutbFb-8svoErgAAAdU"] [Tue Aug 18 13:08:38.427937 2026] [security2:error] [pid 167459:tid 167598] [client 4.232.151.198:2537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/templates.php"] [unique_id "aoSDhmr_JutbFb-8svoEsAAAAZg"] [Tue Aug 18 13:08:38.430120 2026] [security2:error] [pid 167459:tid 167714] [client 52.173.121.69:36591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDhmr_JutbFb-8svoEsQAAAgw"] [Tue Aug 18 13:08:38.434596 2026] [security2:error] [pid 167459:tid 167710] [client 20.171.51.14:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/zs.php"] [unique_id "aoSDhmr_JutbFb-8svoEswAAAgg"] [Tue Aug 18 13:08:38.465741 2026] [security2:error] [pid 167459:tid 167608] [client 20.116.17.175:22693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDhmr_JutbFb-8svoEtQAAAaI"] [Tue Aug 18 13:08:38.471971 2026] [security2:error] [pid 167459:tid 167647] [client 20.215.241.237:46346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/nope.php"] [unique_id "aoSDhmr_JutbFb-8svoEtwAAAck"] [Tue Aug 18 13:08:38.483311 2026] [security2:error] [pid 167459:tid 167655] [client 20.25.139.174:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/manager.php"] [unique_id "aoSDhmr_JutbFb-8svoEuQAAAdE"] [Tue Aug 18 13:08:38.534831 2026] [security2:error] [pid 167459:tid 167624] [client 20.186.30.159:9787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/nox.php"] [unique_id "aoSDhmr_JutbFb-8svoEuwAAAbI"] [Tue Aug 18 13:08:38.573245 2026] [security2:error] [pid 167459:tid 167666] [client 40.74.65.169:20781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/reviall.php"] [unique_id "aoSDhmr_JutbFb-8svoEvAAAAdw"] [Tue Aug 18 13:08:38.605184 2026] [security2:error] [pid 167459:tid 167609] [client 20.151.109.219:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/zj.php"] [unique_id "aoSDhmr_JutbFb-8svoEvwAAAaM"] [Tue Aug 18 13:08:38.610184 2026] [security2:error] [pid 167459:tid 167593] [client 172.182.217.32:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/contact.php"] [unique_id "aoSDhmr_JutbFb-8svoEwgAAAZM"] [Tue Aug 18 13:08:38.610240 2026] [security2:error] [pid 167459:tid 167644] [client 20.104.100.201:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDhmr_JutbFb-8svoEwQAAAcY"] [Tue Aug 18 13:08:38.621090 2026] [security2:error] [pid 167459:tid 167652] [client 47.128.34.121:49814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.uninutri.ind.br"] [uri "/"] [unique_id "aoSDhmr_JutbFb-8svoExAAAAc4"] [Tue Aug 18 13:08:38.622798 2026] [security2:error] [pid 167459:tid 167610] [client 172.213.243.2:34394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/X57.php"] [unique_id "aoSDhmr_JutbFb-8svoExQAAAaQ"] [Tue Aug 18 13:08:38.693319 2026] [security2:error] [pid 167459:tid 167702] [client 20.65.69.59:1434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "antoniopericiacontabil.com"] [uri "/ye.php"] [unique_id "aoSDhmr_JutbFb-8svoEyQAAAgA"] [Tue Aug 18 13:08:38.739478 2026] [security2:error] [pid 167459:tid 167620] [client 68.155.154.236:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/weozh.php"] [unique_id "aoSDhmr_JutbFb-8svoEzQAAAa4"] [Tue Aug 18 13:08:38.765056 2026] [autoindex:error] [pid 167459:tid 167614] [client 20.79.204.6:6122] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:38.839646 2026] [security2:error] [pid 167459:tid 167676] [client 158.158.74.177:13715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSDhmr_JutbFb-8svoE2QAAAeY"] [Tue Aug 18 13:08:38.860978 2026] [security2:error] [pid 167459:tid 167703] [client 52.173.121.69:50011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDhmr_JutbFb-8svoE2gAAAgE"] [Tue Aug 18 13:08:38.904075 2026] [security2:error] [pid 167459:tid 167670] [client 197.184.64.235:42694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDhmr_JutbFb-8svoE3QAAAeA"] [Tue Aug 18 13:08:38.904173 2026] [security2:error] [pid 167459:tid 167670] [client 197.184.64.235:42694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDhmr_JutbFb-8svoE3QAAAeA"] [Tue Aug 18 13:08:38.953522 2026] [security2:error] [pid 167459:tid 167661] [client 20.104.100.201:17315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/cong.php"] [unique_id "aoSDhmr_JutbFb-8svoE4QAAAdc"] [Tue Aug 18 13:08:38.965998 2026] [security2:error] [pid 167459:tid 167682] [client 20.79.204.6:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSDhmr_JutbFb-8svoE4wAAAew"] [Tue Aug 18 13:08:38.980299 2026] [security2:error] [pid 167459:tid 167679] [client 20.215.241.237:39347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/nope.php"] [unique_id "aoSDhmr_JutbFb-8svoE5AAAAek"] [Tue Aug 18 13:08:39.003381 2026] [authz_core:error] [pid 167459:tid 167483] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:39.003846 2026] [authz_core:error] [pid 167459:tid 167483] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:39.021063 2026] [security2:error] [pid 167459:tid 167637] [client 20.25.139.174:4352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/w1.php"] [unique_id "aoSDh2r_JutbFb-8svoE5wAAAb8"] [Tue Aug 18 13:08:39.052902 2026] [security2:error] [pid 167459:tid 167596] [client 138.36.100.162:42269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDh2r_JutbFb-8svoE6QAAAZY"] [Tue Aug 18 13:08:39.053000 2026] [security2:error] [pid 167459:tid 167596] [client 138.36.100.162:42269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDh2r_JutbFb-8svoE6QAAAZY"] [Tue Aug 18 13:08:39.060804 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:56567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/qo.php"] [unique_id "aoSDh2r_JutbFb-8svoE6gAAAfs"] [Tue Aug 18 13:08:39.071314 2026] [security2:error] [pid 167459:tid 167681] [client 20.226.36.136:47937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDh2r_JutbFb-8svoE6wAAAes"] [Tue Aug 18 13:08:39.080804 2026] [security2:error] [pid 167459:tid 167662] [client 172.213.243.2:15042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/forbidals.php"] [unique_id "aoSDh2r_JutbFb-8svoE7AAAAdg"] [Tue Aug 18 13:08:39.087068 2026] [security2:error] [pid 167459:tid 167688] [client 20.116.17.175:52557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/red.php"] [unique_id "aoSDh2r_JutbFb-8svoE7QAAAfI"] [Tue Aug 18 13:08:39.097461 2026] [security2:error] [pid 167459:tid 167632] [client 172.182.217.32:25644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/cux.php"] [unique_id "aoSDh2r_JutbFb-8svoE7gAAAbo"] [Tue Aug 18 13:08:39.135591 2026] [security2:error] [pid 167459:tid 167611] [client 213.202.253.4:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSDh2r_JutbFb-8svoE7wAAAaU"], referer: www.google.com [Tue Aug 18 13:08:39.138418 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:53188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pk.php"] [unique_id "aoSDh2r_JutbFb-8svoE8AAAAd4"] [Tue Aug 18 13:08:39.159707 2026] [security2:error] [pid 167459:tid 167605] [client 4.232.151.198:2546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/term.php"] [unique_id "aoSDh2r_JutbFb-8svoE9QAAAZ8"] [Tue Aug 18 13:08:39.192300 2026] [security2:error] [pid 167459:tid 167674] [client 52.173.121.69:36575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDh2r_JutbFb-8svoE9gAAAeQ"] [Tue Aug 18 13:08:39.227778 2026] [authz_core:error] [pid 167459:tid 167535] [remote 57.141.22.126:44932] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:39.228041 2026] [authz_core:error] [pid 167459:tid 167535] [remote 57.141.22.126:44932] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:39.230151 2026] [security2:error] [pid 167459:tid 167650] [client 213.35.127.232:49513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDh2r_JutbFb-8svoE-QAAAcw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:39.250694 2026] [security2:error] [pid 167459:tid 167715] [client 66.249.77.96:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/robots.txt"] [unique_id "aoSDh2r_JutbFb-8svoE_AAAAg0"] [Tue Aug 18 13:08:39.302567 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:39.302832 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:39.343735 2026] [security2:error] [pid 167459:tid 167630] [client 66.249.77.98:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "buscacep.linkasites.com.br"] [uri "/livrocep/rn/natal/lagoa-azul/img/avenida-remador-clodoaldo-bakker-cj-n-horizonte-lagoa-azul-natal-rn.webp"] [unique_id "aoSDh2r_JutbFb-8svoFAAAAAbg"] [Tue Aug 18 13:08:39.384648 2026] [security2:error] [pid 167459:tid 167660] [client 20.116.17.175:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDh2r_JutbFb-8svoFAQAAAdY"] [Tue Aug 18 13:08:39.395781 2026] [security2:error] [pid 167459:tid 167694] [client 40.74.65.169:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/11.php"] [unique_id "aoSDh2r_JutbFb-8svoFAgAAAfg"] [Tue Aug 18 13:08:39.402203 2026] [security2:error] [pid 167459:tid 167677] [client 20.215.241.237:39310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/new.php"] [unique_id "aoSDh2r_JutbFb-8svoFBAAAAec"] [Tue Aug 18 13:08:39.422428 2026] [security2:error] [pid 167459:tid 167609] [client 20.104.100.201:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/css/database.php"] [unique_id "aoSDh2r_JutbFb-8svoFBgAAAaM"] [Tue Aug 18 13:08:39.497964 2026] [security2:error] [pid 167459:tid 167671] [client 172.213.243.2:19746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/edit.php"] [unique_id "aoSDh2r_JutbFb-8svoFCAAAAeE"] [Tue Aug 18 13:08:39.569147 2026] [security2:error] [pid 167459:tid 167657] [client 20.151.109.219:20688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/x.php"] [unique_id "aoSDh2r_JutbFb-8svoFCwAAAdM"] [Tue Aug 18 13:08:39.577643 2026] [security2:error] [pid 167459:tid 167666] [client 20.79.204.6:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSDh2r_JutbFb-8svoFDAAAAdw"] [Tue Aug 18 13:08:39.583933 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/favicon.php"] [unique_id "aoSDh2r_JutbFb-8svoFDQAAAb4"] [Tue Aug 18 13:08:39.601764 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:39.602020 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:39.612586 2026] [security2:error] [pid 167459:tid 167623] [client 52.173.121.69:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDh2r_JutbFb-8svoFEAAAAbE"] [Tue Aug 18 13:08:39.619599 2026] [security2:error] [pid 167459:tid 167628] [client 196.12.128.158:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDh2r_JutbFb-8svoFEgAAAbY"] [Tue Aug 18 13:08:39.619738 2026] [security2:error] [pid 167459:tid 167628] [client 196.12.128.158:53534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDh2r_JutbFb-8svoFEgAAAbY"] [Tue Aug 18 13:08:39.639617 2026] [security2:error] [pid 167459:tid 167614] [client 158.23.17.4:40438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/rf.php"] [unique_id "aoSDh2r_JutbFb-8svoFEwAAAag"] [Tue Aug 18 13:08:39.672695 2026] [security2:error] [pid 167459:tid 167653] [client 172.202.39.151:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/files/index.php"] [unique_id "aoSDh2r_JutbFb-8svoFFgAAAc8"] [Tue Aug 18 13:08:39.683349 2026] [security2:error] [pid 167459:tid 167672] [client 158.158.74.177:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/ku.php"] [unique_id "aoSDh2r_JutbFb-8svoFFwAAAeI"] [Tue Aug 18 13:08:39.698754 2026] [security2:error] [pid 167459:tid 167686] [client 158.23.17.4:47633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/sd.php"] [unique_id "aoSDh2r_JutbFb-8svoFGQAAAfA"] [Tue Aug 18 13:08:39.769267 2026] [security2:error] [pid 167459:tid 167590] [client 178.156.189.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "graices.com.br"] [uri "/"] [unique_id "aoSDh2r_JutbFb-8svoFHAABkCU"], referer: https://graices.com.br/ [Tue Aug 18 13:08:39.771829 2026] [security2:error] [pid 167459:tid 167692] [client 20.186.30.159:9848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/akismet.php"] [unique_id "aoSDh2r_JutbFb-8svoFHQAAAfY"] [Tue Aug 18 13:08:39.791581 2026] [security2:error] [pid 167459:tid 167617] [client 20.25.139.174:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-login.php"] [unique_id "aoSDh2r_JutbFb-8svoFHwAAAas"] [Tue Aug 18 13:08:39.833093 2026] [security2:error] [pid 167459:tid 167664] [client 20.215.241.237:46374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/new.php"] [unique_id "aoSDh2r_JutbFb-8svoFIAAAAdo"] [Tue Aug 18 13:08:39.834219 2026] [security2:error] [pid 167459:tid 167679] [client 20.226.36.136:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDh2r_JutbFb-8svoFIQAAAek"] [Tue Aug 18 13:08:39.853950 2026] [security2:error] [pid 167459:tid 167702] [client 4.232.151.198:2519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/test.php"] [unique_id "aoSDh2r_JutbFb-8svoFIgAAAgA"] [Tue Aug 18 13:08:39.854939 2026] [security2:error] [pid 167459:tid 167622] [client 20.104.100.201:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/xwpg.php"] [unique_id "aoSDh2r_JutbFb-8svoFIwAAAbA"] [Tue Aug 18 13:08:39.857517 2026] [security2:error] [pid 167459:tid 167678] [client 20.171.51.14:23533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/iz.php"] [unique_id "aoSDh2r_JutbFb-8svoFJQAAAeg"] [Tue Aug 18 13:08:39.917297 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:39.917569 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:39.940226 2026] [security2:error] [pid 167459:tid 167708] [client 172.213.243.2:36117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/kj.php"] [unique_id "aoSDh2r_JutbFb-8svoFKAAAAgY"] [Tue Aug 18 13:08:40.017596 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:7310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ge.php"] [unique_id "aoSDiGr_JutbFb-8svoFKgAAAZI"] [Tue Aug 18 13:08:40.072492 2026] [security2:error] [pid 167459:tid 167697] [client 172.182.217.32:25612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/randkeyword.php"] [unique_id "aoSDiGr_JutbFb-8svoFLAAAAfs"] [Tue Aug 18 13:08:40.098920 2026] [security2:error] [pid 167459:tid 167711] [client 20.104.100.201:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/privdayz.php"] [unique_id "aoSDiGr_JutbFb-8svoFLwAAAgk"] [Tue Aug 18 13:08:40.117257 2026] [security2:error] [pid 167459:tid 167667] [client 20.116.17.175:22764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/cok.php"] [unique_id "aoSDiGr_JutbFb-8svoFMAAAAd0"] [Tue Aug 18 13:08:40.123816 2026] [security2:error] [pid 167459:tid 167605] [client 20.226.36.136:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDiGr_JutbFb-8svoFMQAAAZ8"] [Tue Aug 18 13:08:40.154173 2026] [security2:error] [pid 167459:tid 167715] [client 40.74.65.169:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/File.php"] [unique_id "aoSDiGr_JutbFb-8svoFNAAAAg0"] [Tue Aug 18 13:08:40.162053 2026] [security2:error] [pid 167459:tid 167647] [client 20.151.109.219:40473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/yn.php"] [unique_id "aoSDiGr_JutbFb-8svoFNQAAAck"] [Tue Aug 18 13:08:40.176416 2026] [security2:error] [pid 167459:tid 167543] [remote 178.156.200.16:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.200.156.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtvsolucoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSDiGr_JutbFb-8svoFNgABylM"] [Tue Aug 18 13:08:40.192253 2026] [security2:error] [pid 167459:tid 167704] [client 52.173.121.69:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDiGr_JutbFb-8svoFOAAAAgI"] [Tue Aug 18 13:08:40.208886 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:40.209318 2026] [authz_core:error] [pid 167459:tid 167481] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:40.242491 2026] [security2:error] [pid 167459:tid 167696] [client 178.156.189.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "graices.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "aoSDiGr_JutbFb-8svoFNwAB-mw"], referer: https://graices.com.br/ [Tue Aug 18 13:08:40.247057 2026] [security2:error] [pid 167459:tid 167596] [client 213.35.127.232:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDiGr_JutbFb-8svoFOwAAAZY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:40.258508 2026] [security2:error] [pid 167459:tid 167630] [client 20.226.36.136:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDiGr_JutbFb-8svoFPAAAAbg"] [Tue Aug 18 13:08:40.265073 2026] [security2:error] [pid 167459:tid 167597] [client 20.215.241.237:30437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/apreset.php"] [unique_id "aoSDiGr_JutbFb-8svoFPQAAAZc"] [Tue Aug 18 13:08:40.293849 2026] [security2:error] [pid 167459:tid 167677] [client 20.186.30.159:9756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/admin.php"] [unique_id "aoSDiGr_JutbFb-8svoFQAAAAec"] [Tue Aug 18 13:08:40.328306 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.100.201:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/az.php"] [unique_id "aoSDiGr_JutbFb-8svoFRQAAAdE"] [Tue Aug 18 13:08:40.364651 2026] [security2:error] [pid 167459:tid 167669] [client 172.213.243.2:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/bes.php"] [unique_id "aoSDiGr_JutbFb-8svoFRwAAAd8"] [Tue Aug 18 13:08:40.388121 2026] [security2:error] [pid 167459:tid 167654] [client 20.25.139.174:4633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/default.php"] [unique_id "aoSDiGr_JutbFb-8svoFSQAAAdA"] [Tue Aug 18 13:08:40.414398 2026] [autoindex:error] [pid 167459:tid 167598] [client 20.79.204.6:5706] AH01276: Cannot serve directory /home4/eccellenzaconsul/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:40.512799 2026] [security2:error] [pid 167459:tid 167686] [client 20.226.36.136:48837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDiGr_JutbFb-8svoFTgAAAfA"] [Tue Aug 18 13:08:40.520924 2026] [security2:error] [pid 167459:tid 167608] [client 49.145.211.146:10400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFTwAAAaI"] [Tue Aug 18 13:08:40.521028 2026] [security2:error] [pid 167459:tid 167608] [client 49.145.211.146:10400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFTwAAAaI"] [Tue Aug 18 13:08:40.561953 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:25565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/gebase.php"] [unique_id "aoSDiGr_JutbFb-8svoFUQAAAb4"] [Tue Aug 18 13:08:40.578149 2026] [security2:error] [pid 167459:tid 167713] [client 4.232.151.198:2478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/test1.php"] [unique_id "aoSDiGr_JutbFb-8svoFUgAAAgs"] [Tue Aug 18 13:08:40.613456 2026] [security2:error] [pid 167459:tid 167603] [client 20.79.204.6:5706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDiGr_JutbFb-8svoFVAAAAZ0"] [Tue Aug 18 13:08:40.626765 2026] [security2:error] [pid 167459:tid 167559] [remote 162.55.89.48:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lavobotafogo.com"] [uri "/wp-login.php"] [unique_id "aoSDiGr_JutbFb-8svoFVQABxWM"] [Tue Aug 18 13:08:40.657920 2026] [security2:error] [pid 167459:tid 167640] [client 20.116.17.175:22679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/accesson.php"] [unique_id "aoSDiGr_JutbFb-8svoFVwAAAcI"] [Tue Aug 18 13:08:40.712227 2026] [security2:error] [pid 167459:tid 167661] [client 158.158.74.177:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/chosen.php"] [unique_id "aoSDiGr_JutbFb-8svoFWgAAAdc"] [Tue Aug 18 13:08:40.720143 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:5004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kl.php"] [unique_id "aoSDiGr_JutbFb-8svoFWwAAAcc"] [Tue Aug 18 13:08:40.731618 2026] [security2:error] [pid 167459:tid 167682] [client 158.23.17.4:56760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xynz1.php"] [unique_id "aoSDiGr_JutbFb-8svoFXAAAAew"] [Tue Aug 18 13:08:40.734996 2026] [security2:error] [pid 167459:tid 167664] [client 20.215.241.237:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/1mage.php"] [unique_id "aoSDiGr_JutbFb-8svoFXQAAAdo"] [Tue Aug 18 13:08:40.782766 2026] [security2:error] [pid 167459:tid 167679] [client 172.213.243.2:16873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ws60.php"] [unique_id "aoSDiGr_JutbFb-8svoFXgAAAek"] [Tue Aug 18 13:08:40.804065 2026] [security2:error] [pid 167459:tid 167678] [client 20.104.100.201:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wg459o.php"] [unique_id "aoSDiGr_JutbFb-8svoFYgAAAeg"] [Tue Aug 18 13:08:40.809594 2026] [security2:error] [pid 167459:tid 167534] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFYwAB4ko"] [Tue Aug 18 13:08:40.809801 2026] [security2:error] [pid 167459:tid 167672] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFYwAB4ko"] [Tue Aug 18 13:08:40.809898 2026] [security2:error] [pid 167459:tid 167674] [client 103.120.71.157:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFZAAAAeQ"] [Tue Aug 18 13:08:40.810000 2026] [security2:error] [pid 167459:tid 167674] [client 103.120.71.157:61420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiGr_JutbFb-8svoFZAAAAeQ"] [Tue Aug 18 13:08:40.816362 2026] [security2:error] [pid 167459:tid 167683] [client 74.248.133.44:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/al.php"] [unique_id "aoSDiGr_JutbFb-8svoFZQAAAe0"] [Tue Aug 18 13:08:40.868873 2026] [security2:error] [pid 167459:tid 167662] [client 20.127.136.245:16581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDiGr_JutbFb-8svoFZwAAAdg"] [Tue Aug 18 13:08:40.885668 2026] [security2:error] [pid 167459:tid 167592] [client 40.74.65.169:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/fi22.php"] [unique_id "aoSDiGr_JutbFb-8svoFaQAAAZI"] [Tue Aug 18 13:08:40.893032 2026] [security2:error] [pid 167459:tid 167693] [client 20.250.13.23:40716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/abcd.php"] [unique_id "aoSDiGr_JutbFb-8svoFagAAAfc"] [Tue Aug 18 13:08:40.907864 2026] [security2:error] [pid 167459:tid 167520] [remote 162.214.96.231:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faganelli.com.br.bergoninf.com"] [uri "/wp-login.php"] [unique_id "aoSDiGr_JutbFb-8svoFbAAB5jw"] [Tue Aug 18 13:08:40.957163 2026] [security2:error] [pid 167459:tid 167715] [client 20.116.17.175:52894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/JawirGenk.php"] [unique_id "aoSDiGr_JutbFb-8svoFbQAAAg0"] [Tue Aug 18 13:08:40.982382 2026] [security2:error] [pid 167459:tid 167685] [client 20.25.139.174:4528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/i.php"] [unique_id "aoSDiGr_JutbFb-8svoFcQAAAe8"] [Tue Aug 18 13:08:41.009240 2026] [security2:error] [pid 167459:tid 167706] [client 20.226.36.136:62194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDiWr_JutbFb-8svoFdAAAAgQ"] [Tue Aug 18 13:08:41.019740 2026] [security2:error] [pid 167459:tid 167602] [client 20.186.30.159:9759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.30.186.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eurotruckparts.com.br"] [uri "/ajax.php"] [unique_id "aoSDiWr_JutbFb-8svoFdQAAAZw"] [Tue Aug 18 13:08:41.129029 2026] [security2:error] [pid 167459:tid 167647] [client 172.182.217.32:25628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/images/2008.php"] [unique_id "aoSDiWr_JutbFb-8svoFegAAAck"] [Tue Aug 18 13:08:41.142016 2026] [security2:error] [pid 167459:tid 167669] [client 20.116.17.175:22750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/av.php"] [unique_id "aoSDiWr_JutbFb-8svoFfAAAAd8"] [Tue Aug 18 13:08:41.148017 2026] [security2:error] [pid 167459:tid 167657] [client 172.202.39.151:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFfQAAAdM"] [Tue Aug 18 13:08:41.161235 2026] [security2:error] [pid 167459:tid 167616] [client 20.215.241.237:59729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/imsc.php"] [unique_id "aoSDiWr_JutbFb-8svoFfwAAAao"] [Tue Aug 18 13:08:41.225508 2026] [security2:error] [pid 167459:tid 167628] [client 158.23.17.4:47637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/km.php"] [unique_id "aoSDiWr_JutbFb-8svoFgAAAAbY"] [Tue Aug 18 13:08:41.229154 2026] [security2:error] [pid 167459:tid 167651] [client 172.213.243.2:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/olfclass.php"] [unique_id "aoSDiWr_JutbFb-8svoFgQAAAc0"] [Tue Aug 18 13:08:41.256557 2026] [security2:error] [pid 167459:tid 167614] [client 20.104.100.201:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/mifta.php"] [unique_id "aoSDiWr_JutbFb-8svoFhQAAAag"] [Tue Aug 18 13:08:41.257456 2026] [security2:error] [pid 167459:tid 167709] [client 158.23.17.4:44675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gs.php"] [unique_id "aoSDiWr_JutbFb-8svoFhwAAAgc"] [Tue Aug 18 13:08:41.257744 2026] [security2:error] [pid 167459:tid 167605] [client 213.35.127.232:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFhgAAAZ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:41.277883 2026] [security2:error] [pid 167459:tid 167597] [client 20.79.204.6:5646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDiWr_JutbFb-8svoFigAAAZc"] [Tue Aug 18 13:08:41.310705 2026] [security2:error] [pid 167459:tid 167671] [client 4.232.151.198:2520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/thoms.php"] [unique_id "aoSDiWr_JutbFb-8svoFiwAAAeE"] [Tue Aug 18 13:08:41.317183 2026] [security2:error] [pid 167459:tid 167705] [client 52.173.121.69:36553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFjAAAAgM"] [Tue Aug 18 13:08:41.331673 2026] [security2:error] [pid 167459:tid 167636] [client 20.104.100.201:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/z43agz.php"] [unique_id "aoSDiWr_JutbFb-8svoFjgAAAb4"] [Tue Aug 18 13:08:41.354880 2026] [security2:error] [pid 167459:tid 167666] [client 158.158.74.177:13719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/asd.php"] [unique_id "aoSDiWr_JutbFb-8svoFkAAAAdw"] [Tue Aug 18 13:08:41.364650 2026] [security2:error] [pid 167459:tid 167684] [client 52.15.147.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alsconsultoria.com.br"] [uri "/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFiAAB7n0"], referer: https://alsconsultoria.com.br/ [Tue Aug 18 13:08:41.410395 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:41.410660 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:41.451702 2026] [security2:error] [pid 167459:tid 167640] [client 20.226.36.136:61462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDiWr_JutbFb-8svoFkwAAAcI"] [Tue Aug 18 13:08:41.585732 2026] [security2:error] [pid 167459:tid 167702] [client 20.215.241.237:59747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/imscjpg.php"] [unique_id "aoSDiWr_JutbFb-8svoFmgAAAgA"] [Tue Aug 18 13:08:41.595484 2026] [security2:error] [pid 167459:tid 167678] [client 20.151.109.219:38618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/11.php"] [unique_id "aoSDiWr_JutbFb-8svoFmwAAAeg"] [Tue Aug 18 13:08:41.620538 2026] [security2:error] [pid 167459:tid 167627] [client 172.182.217.32:4090] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "qriar.com"] [uri "/images/c99.php"] [unique_id "aoSDiWr_JutbFb-8svoFnQAAAbU"] [Tue Aug 18 13:08:41.622503 2026] [security2:error] [pid 167459:tid 167674] [client 158.23.17.4:40461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lw.php"] [unique_id "aoSDiWr_JutbFb-8svoFngAAAeQ"] [Tue Aug 18 13:08:41.682649 2026] [security2:error] [pid 167459:tid 167683] [client 40.74.65.169:35421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDiWr_JutbFb-8svoFnwAAAe0"] [Tue Aug 18 13:08:41.685822 2026] [security2:error] [pid 167459:tid 167635] [client 20.116.17.175:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/options.php"] [unique_id "aoSDiWr_JutbFb-8svoFoAAAAb0"] [Tue Aug 18 13:08:41.690162 2026] [security2:error] [pid 167459:tid 167621] [client 172.213.243.2:48342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wpver.php"] [unique_id "aoSDiWr_JutbFb-8svoFoQAAAa8"] [Tue Aug 18 13:08:41.691237 2026] [security2:error] [pid 167459:tid 167701] [client 68.155.154.236:27578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/rymmm.php"] [unique_id "aoSDiWr_JutbFb-8svoFogAAAf8"] [Tue Aug 18 13:08:41.709707 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:41.709980 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:41.749662 2026] [security2:error] [pid 167459:tid 167632] [client 158.23.17.4:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vo.php"] [unique_id "aoSDiWr_JutbFb-8svoFpgAAAbo"] [Tue Aug 18 13:08:41.760683 2026] [security2:error] [pid 167459:tid 167592] [client 20.25.139.174:4857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFpwAAAZI"] [Tue Aug 18 13:08:41.797430 2026] [security2:error] [pid 167459:tid 167660] [client 49.37.150.8:57162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiWr_JutbFb-8svoFqQAAAdY"] [Tue Aug 18 13:08:41.797549 2026] [security2:error] [pid 167459:tid 167660] [client 49.37.150.8:57162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiWr_JutbFb-8svoFqQAAAdY"] [Tue Aug 18 13:08:41.919124 2026] [security2:error] [pid 167459:tid 167629] [client 5.31.227.224:29940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiWr_JutbFb-8svoFrgAAAbc"] [Tue Aug 18 13:08:41.921093 2026] [security2:error] [pid 167459:tid 167629] [client 5.31.227.224:29940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDiWr_JutbFb-8svoFrgAAAbc"] [Tue Aug 18 13:08:41.949972 2026] [security2:error] [pid 167459:tid 167604] [client 20.79.204.6:5633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSDiWr_JutbFb-8svoFsAAAAZ4"] [Tue Aug 18 13:08:41.958260 2026] [security2:error] [pid 167459:tid 167706] [client 20.171.51.14:5396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/se.php"] [unique_id "aoSDiWr_JutbFb-8svoFsQAAAgQ"] [Tue Aug 18 13:08:41.968688 2026] [security2:error] [pid 167459:tid 167696] [client 20.116.17.175:41499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/kj.php"] [unique_id "aoSDiWr_JutbFb-8svoFsgAAAfo"] [Tue Aug 18 13:08:41.973406 2026] [security2:error] [pid 167459:tid 167595] [client 4.232.151.198:2529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/tool.php"] [unique_id "aoSDiWr_JutbFb-8svoFswAAAZU"] [Tue Aug 18 13:08:41.993195 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.100.201:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSDiWr_JutbFb-8svoFtgAAAY8"] [Tue Aug 18 13:08:41.994109 2026] [security2:error] [pid 167459:tid 167644] [client 158.158.74.177:13755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/akc.php"] [unique_id "aoSDiWr_JutbFb-8svoFtwAAAcY"] [Tue Aug 18 13:08:42.008255 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:42.008531 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:42.050916 2026] [security2:error] [pid 167459:tid 167694] [client 158.23.17.4:25391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/mf.php"] [unique_id "aoSDimr_JutbFb-8svoFuQAAAfg"] [Tue Aug 18 13:08:42.131715 2026] [security2:error] [pid 167459:tid 167596] [client 172.182.217.32:25610] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "qriar.com"] [uri "/images/c99.php"] [unique_id "aoSDimr_JutbFb-8svoFuwAAAZY"] [Tue Aug 18 13:08:42.140162 2026] [security2:error] [pid 167459:tid 167631] [client 172.213.243.2:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/thui.php"] [unique_id "aoSDimr_JutbFb-8svoFvAAAAbk"] [Tue Aug 18 13:08:42.156523 2026] [security2:error] [pid 167459:tid 167680] [client 172.202.39.151:39173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/images/images/about.php"] [unique_id "aoSDimr_JutbFb-8svoFvgAAAeo"] [Tue Aug 18 13:08:42.184483 2026] [security2:error] [pid 167459:tid 167619] [client 158.23.17.4:41869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vj.php"] [unique_id "aoSDimr_JutbFb-8svoFwAAAAa0"] [Tue Aug 18 13:08:42.186615 2026] [security2:error] [pid 167459:tid 167688] [client 86.120.159.145:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoFwgAAAfI"] [Tue Aug 18 13:08:42.186771 2026] [security2:error] [pid 167459:tid 167688] [client 86.120.159.145:57904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoFwgAAAfI"] [Tue Aug 18 13:08:42.206532 2026] [security2:error] [pid 167459:tid 167709] [client 20.215.241.237:30448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/qlex1.php"] [unique_id "aoSDimr_JutbFb-8svoFxAAAAgc"] [Tue Aug 18 13:08:42.210048 2026] [security2:error] [pid 167459:tid 167607] [client 20.116.17.175:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDimr_JutbFb-8svoFxQAAAaE"] [Tue Aug 18 13:08:42.272174 2026] [security2:error] [pid 167459:tid 167704] [client 213.35.127.232:50145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDimr_JutbFb-8svoFyAAAAgI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:42.294351 2026] [security2:error] [pid 167459:tid 167647] [client 20.25.139.174:4498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDimr_JutbFb-8svoFyQAAAck"] [Tue Aug 18 13:08:42.313071 2026] [authz_core:error] [pid 167459:tid 167552] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:42.313430 2026] [authz_core:error] [pid 167459:tid 167552] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:42.459523 2026] [security2:error] [pid 167459:tid 167622] [client 20.104.100.201:53319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/index2.php"] [unique_id "aoSDimr_JutbFb-8svoFzwAAAbA"] [Tue Aug 18 13:08:42.490111 2026] [security2:error] [pid 167459:tid 167656] [client 40.74.65.169:7061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "aoSDimr_JutbFb-8svoF0QAAAdI"] [Tue Aug 18 13:08:42.511676 2026] [security2:error] [pid 167459:tid 167674] [client 20.104.100.201:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/3.php"] [unique_id "aoSDimr_JutbFb-8svoF0gAAAeQ"] [Tue Aug 18 13:08:42.531157 2026] [security2:error] [pid 167459:tid 167494] [remote 50.6.6.8:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.6.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amp.adv.br"] [uri "/wp-login.php"] [unique_id "aoSDimr_JutbFb-8svoF0wABoiI"] [Tue Aug 18 13:08:42.532737 2026] [security2:error] [pid 167459:tid 167683] [client 20.151.109.219:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vm.php"] [unique_id "aoSDimr_JutbFb-8svoF1QAAAe0"] [Tue Aug 18 13:08:42.562031 2026] [security2:error] [pid 167459:tid 167621] [client 158.23.17.4:25381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wu.php"] [unique_id "aoSDimr_JutbFb-8svoF1wAAAa8"] [Tue Aug 18 13:08:42.579103 2026] [security2:error] [pid 167459:tid 167666] [client 20.79.204.6:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSDimr_JutbFb-8svoF2AAAAdw"] [Tue Aug 18 13:08:42.580163 2026] [security2:error] [pid 167459:tid 167600] [client 114.5.214.109:50418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoF2QAAAZo"] [Tue Aug 18 13:08:42.580249 2026] [security2:error] [pid 167459:tid 167600] [client 114.5.214.109:50418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoF2QAAAZo"] [Tue Aug 18 13:08:42.583682 2026] [security2:error] [pid 167459:tid 167701] [client 172.213.243.2:19745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/tmpls.php"] [unique_id "aoSDimr_JutbFb-8svoF2gAAAf8"] [Tue Aug 18 13:08:42.609446 2026] [security2:error] [pid 167459:tid 167713] [client 20.171.51.14:23521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/vp.php"] [unique_id "aoSDimr_JutbFb-8svoF3QAAAgs"] [Tue Aug 18 13:08:42.613373 2026] [authz_core:error] [pid 167459:tid 167470] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:42.613624 2026] [authz_core:error] [pid 167459:tid 167470] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:42.620765 2026] [security2:error] [pid 167459:tid 167689] [client 172.182.217.32:25538] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "qriar.com"] [uri "/images/c99.php"] [unique_id "aoSDimr_JutbFb-8svoF3gAAAfM"] [Tue Aug 18 13:08:42.639421 2026] [security2:error] [pid 167459:tid 167646] [client 4.232.151.198:2556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/tools.php"] [unique_id "aoSDimr_JutbFb-8svoF3wAAAcg"] [Tue Aug 18 13:08:42.645454 2026] [security2:error] [pid 167459:tid 167693] [client 20.226.36.136:61488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDimr_JutbFb-8svoF4AAAAfc"] [Tue Aug 18 13:08:42.648521 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:4619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mimes.php"] [unique_id "aoSDimr_JutbFb-8svoF4QAAAaU"] [Tue Aug 18 13:08:42.660894 2026] [security2:error] [pid 167459:tid 167645] [client 158.158.74.177:13702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/maintenance.php"] [unique_id "aoSDimr_JutbFb-8svoF5AAAAcc"] [Tue Aug 18 13:08:42.726025 2026] [security2:error] [pid 167459:tid 167599] [client 20.215.241.237:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/mariju.php"] [unique_id "aoSDimr_JutbFb-8svoF5wAAAZk"] [Tue Aug 18 13:08:42.774342 2026] [security2:error] [pid 167459:tid 167650] [client 20.116.17.175:22702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/images/acxx.php"] [unique_id "aoSDimr_JutbFb-8svoF6gAAAcw"] [Tue Aug 18 13:08:42.855951 2026] [security2:error] [pid 167459:tid 167662] [client 4.232.151.198:38588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDimr_JutbFb-8svoF7QAAAdg"] [Tue Aug 18 13:08:42.857299 2026] [security2:error] [pid 167459:tid 167716] [client 20.25.139.174:4514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/gecko-new.php"] [unique_id "aoSDimr_JutbFb-8svoF7wAAAg4"] [Tue Aug 18 13:08:42.914173 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:42.914487 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:42.948926 2026] [security2:error] [pid 167459:tid 167687] [client 20.116.17.175:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDimr_JutbFb-8svoF8wAAAfE"] [Tue Aug 18 13:08:42.965901 2026] [security2:error] [pid 167459:tid 167657] [client 172.202.39.151:39215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDimr_JutbFb-8svoF9AAAAdM"] [Tue Aug 18 13:08:42.993191 2026] [security2:error] [pid 167459:tid 167626] [client 37.40.227.74:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoF9QAAAbQ"] [Tue Aug 18 13:08:42.999022 2026] [security2:error] [pid 167459:tid 167626] [client 37.40.227.74:57104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDimr_JutbFb-8svoF9QAAAbQ"] [Tue Aug 18 13:08:43.028148 2026] [security2:error] [pid 167459:tid 167712] [client 172.213.243.2:19885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/nzv.php"] [unique_id "aoSDi2r_JutbFb-8svoF9wAAAgo"] [Tue Aug 18 13:08:43.065237 2026] [security2:error] [pid 167459:tid 167619] [client 158.23.17.4:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ie.php"] [unique_id "aoSDi2r_JutbFb-8svoF-AAAAa0"] [Tue Aug 18 13:08:43.096257 2026] [security2:error] [pid 167459:tid 167711] [client 68.221.73.131:22700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/images.php"] [unique_id "aoSDi2r_JutbFb-8svoF-gAAAgk"] [Tue Aug 18 13:08:43.111070 2026] [security2:error] [pid 167459:tid 167654] [client 172.182.217.32:4089] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "qriar.com"] [uri "/images/c99.php"] [unique_id "aoSDi2r_JutbFb-8svoF_AAAAdA"] [Tue Aug 18 13:08:43.164622 2026] [security2:error] [pid 167459:tid 167627] [client 102.213.179.104:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDi2r_JutbFb-8svoF_QAAAbU"] [Tue Aug 18 13:08:43.164738 2026] [security2:error] [pid 167459:tid 167627] [client 102.213.179.104:59608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDi2r_JutbFb-8svoF_QAAAbU"] [Tue Aug 18 13:08:43.189359 2026] [security2:error] [pid 167459:tid 167647] [client 40.74.65.169:64383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDi2r_JutbFb-8svoF_gAAAck"] [Tue Aug 18 13:08:43.190547 2026] [security2:error] [pid 167459:tid 167671] [client 20.104.100.201:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/8.php"] [unique_id "aoSDi2r_JutbFb-8svoF_wAAAeE"] [Tue Aug 18 13:08:43.192999 2026] [security2:error] [pid 167459:tid 167703] [client 20.151.109.219:33478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/eg.php"] [unique_id "aoSDi2r_JutbFb-8svoGAAAAAgE"] [Tue Aug 18 13:08:43.205467 2026] [security2:error] [pid 167459:tid 167663] [client 20.215.241.237:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/cofbgxlk.php"] [unique_id "aoSDi2r_JutbFb-8svoGAgAAAdk"] [Tue Aug 18 13:08:43.214255 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:43.214510 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:43.219005 2026] [security2:error] [pid 167459:tid 167692] [client 158.23.17.4:5055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ni.php"] [unique_id "aoSDi2r_JutbFb-8svoGBgAAAfY"] [Tue Aug 18 13:08:43.273301 2026] [security2:error] [pid 167459:tid 167651] [client 4.232.151.198:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/txets.php"] [unique_id "aoSDi2r_JutbFb-8svoGBwAAAc0"] [Tue Aug 18 13:08:43.276023 2026] [security2:error] [pid 167459:tid 167591] [client 20.250.13.23:33455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-good.php"] [unique_id "aoSDi2r_JutbFb-8svoGCAAAAZE"] [Tue Aug 18 13:08:43.287747 2026] [security2:error] [pid 167459:tid 167669] [client 213.35.127.232:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDi2r_JutbFb-8svoGCQAAAd8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:43.296323 2026] [security2:error] [pid 167459:tid 167605] [client 158.158.74.177:13787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/options-writing.php"] [unique_id "aoSDi2r_JutbFb-8svoGCwAAAZ8"] [Tue Aug 18 13:08:43.308659 2026] [security2:error] [pid 167459:tid 167622] [client 52.173.121.69:28289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDi2r_JutbFb-8svoGDQAAAbA"] [Tue Aug 18 13:08:43.385321 2026] [security2:error] [pid 167459:tid 167666] [client 20.116.17.175:22763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/png.php"] [unique_id "aoSDi2r_JutbFb-8svoGEQAAAdw"] [Tue Aug 18 13:08:43.391508 2026] [security2:error] [pid 167459:tid 167590] [client 20.25.139.174:4437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/NewFile.php"] [unique_id "aoSDi2r_JutbFb-8svoGEgAAAZA"] [Tue Aug 18 13:08:43.443245 2026] [security2:error] [pid 167459:tid 167592] [client 172.213.243.2:16846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/error1.php"] [unique_id "aoSDi2r_JutbFb-8svoGFQAAAZI"] [Tue Aug 18 13:08:43.493612 2026] [security2:error] [pid 167459:tid 167660] [client 20.79.204.6:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDi2r_JutbFb-8svoGFgAAAdY"] [Tue Aug 18 13:08:43.497012 2026] [security2:error] [pid 167459:tid 167693] [client 172.202.39.151:27901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/rip.php"] [unique_id "aoSDi2r_JutbFb-8svoGFwAAAfc"] [Tue Aug 18 13:08:43.517002 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:43.517251 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:43.517779 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:7184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/de.php"] [unique_id "aoSDi2r_JutbFb-8svoGGgAAAcc"] [Tue Aug 18 13:08:43.535491 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:10191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.info.php"] [unique_id "aoSDi2r_JutbFb-8svoGHAAAAeA"] [Tue Aug 18 13:08:43.559239 2026] [security2:error] [pid 167459:tid 167697] [client 34.198.201.66:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ba.com.br"] [uri "/index.php"] [unique_id "aoSDiWr_JutbFb-8svoFrQAB-xQ"], referer: https://1ba.com.br/ [Tue Aug 18 13:08:43.576988 2026] [security2:error] [pid 167459:tid 167699] [client 20.104.100.201:62615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/log.php"] [unique_id "aoSDi2r_JutbFb-8svoGHgAAAf0"] [Tue Aug 18 13:08:43.601860 2026] [security2:error] [pid 167459:tid 167632] [client 172.182.217.32:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/images/g3.php"] [unique_id "aoSDi2r_JutbFb-8svoGIAAAAbo"] [Tue Aug 18 13:08:43.639742 2026] [security2:error] [pid 167459:tid 167472] [remote 162.214.205.212:60526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhosdaregiao.com.br"] [uri "/wp-login.php"] [unique_id "aoSDi2r_JutbFb-8svoGIQABoww"] [Tue Aug 18 13:08:43.698590 2026] [security2:error] [pid 167459:tid 167630] [client 20.151.109.219:33499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/uk.php"] [unique_id "aoSDi2r_JutbFb-8svoGJQAAAbg"] [Tue Aug 18 13:08:43.719648 2026] [security2:error] [pid 167459:tid 167714] [client 20.116.17.175:52570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/output.php"] [unique_id "aoSDi2r_JutbFb-8svoGJwAAAgw"] [Tue Aug 18 13:08:43.737511 2026] [security2:error] [pid 167459:tid 167635] [client 20.104.100.201:53290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/images.php"] [unique_id "aoSDi2r_JutbFb-8svoGKAAAAb0"] [Tue Aug 18 13:08:43.748751 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:60622] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "comforthmg.3xsolutions.com"] [uri "/1.php"] [unique_id "aoSDi2r_JutbFb-8svoGKQAAAdM"] [Tue Aug 18 13:08:43.748852 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/1.php"] [unique_id "aoSDi2r_JutbFb-8svoGKQAAAdM"] [Tue Aug 18 13:08:43.766620 2026] [security2:error] [pid 167459:tid 167673] [client 20.215.241.237:46372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/contacto.php"] [unique_id "aoSDi2r_JutbFb-8svoGKgAAAeM"] [Tue Aug 18 13:08:43.865073 2026] [security2:error] [pid 167459:tid 167615] [client 172.213.243.2:19577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/155.php"] [unique_id "aoSDi2r_JutbFb-8svoGMQAAAak"] [Tue Aug 18 13:08:43.896828 2026] [security2:error] [pid 167459:tid 167704] [client 40.74.65.169:37427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "aoSDi2r_JutbFb-8svoGNwAAAgI"] [Tue Aug 18 13:08:43.901273 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/about.php"] [unique_id "aoSDi2r_JutbFb-8svoGOAAAAbQ"] [Tue Aug 18 13:08:43.904807 2026] [security2:error] [pid 167459:tid 167687] [client 20.25.139.174:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-Blogs.php"] [unique_id "aoSDi2r_JutbFb-8svoGOQAAAfE"] [Tue Aug 18 13:08:43.918559 2026] [security2:error] [pid 167459:tid 167634] [client 158.158.74.177:14242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSDi2r_JutbFb-8svoGOgAAAbw"] [Tue Aug 18 13:08:43.998617 2026] [security2:error] [pid 167459:tid 167669] [client 20.171.51.14:18236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ph.php"] [unique_id "aoSDi2r_JutbFb-8svoGPwAAAd8"] [Tue Aug 18 13:08:43.999667 2026] [security2:error] [pid 167459:tid 167505] [remote 72.167.40.62:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.40.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "i-databi.com.br"] [uri "/wp-login.php"] [unique_id "aoSDi2r_JutbFb-8svoGPAACDi0"] [Tue Aug 18 13:08:44.048776 2026] [security2:error] [pid 167459:tid 167619] [client 4.232.151.198:2442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/u.php"] [unique_id "aoSDjGr_JutbFb-8svoGQQAAAa0"] [Tue Aug 18 13:08:44.061231 2026] [autoindex:error] [pid 167459:tid 167678] [client 52.73.140.57:55804] AH01276: Cannot serve directory /home4/onsehemel/antonioteodoro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:44.088895 2026] [security2:error] [pid 167459:tid 167681] [client 172.182.217.32:25632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/img/omar.php.png"] [unique_id "aoSDjGr_JutbFb-8svoGRQAAAes"] [Tue Aug 18 13:08:44.119029 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:44.119314 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:44.133096 2026] [security2:error] [pid 167459:tid 167715] [client 20.79.204.6:5644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDjGr_JutbFb-8svoGRwAAAg0"] [Tue Aug 18 13:08:44.148622 2026] [security2:error] [pid 167459:tid 167683] [client 172.202.39.151:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjGr_JutbFb-8svoGSgAAAe0"] [Tue Aug 18 13:08:44.247121 2026] [security2:error] [pid 167459:tid 167689] [client 52.173.121.69:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDjGr_JutbFb-8svoGTQAAAfM"] [Tue Aug 18 13:08:44.247861 2026] [security2:error] [pid 167459:tid 167659] [client 20.116.17.175:22682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ab.php"] [unique_id "aoSDjGr_JutbFb-8svoGTgAAAdU"] [Tue Aug 18 13:08:44.267568 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.100.201:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/a.php"] [unique_id "aoSDjGr_JutbFb-8svoGTwAAAfc"] [Tue Aug 18 13:08:44.268729 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/nw.php"] [unique_id "aoSDjGr_JutbFb-8svoGUAAAAaU"] [Tue Aug 18 13:08:44.280501 2026] [security2:error] [pid 167459:tid 167672] [client 158.23.17.4:39142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/88.php"] [unique_id "aoSDjGr_JutbFb-8svoGUQAAAeI"] [Tue Aug 18 13:08:44.286609 2026] [security2:error] [pid 167459:tid 167645] [client 20.215.241.237:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/image2.php"] [unique_id "aoSDjGr_JutbFb-8svoGUwAAAcc"] [Tue Aug 18 13:08:44.293267 2026] [security2:error] [pid 167459:tid 167682] [client 172.213.243.2:16869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fasx.php"] [unique_id "aoSDjGr_JutbFb-8svoGVAAAAew"] [Tue Aug 18 13:08:44.299540 2026] [security2:error] [pid 167459:tid 167636] [client 213.35.127.232:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDjGr_JutbFb-8svoGVQAAAb4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:44.342690 2026] [security2:error] [pid 167459:tid 167629] [client 20.104.100.201:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ohct.php"] [unique_id "aoSDjGr_JutbFb-8svoGWAAAAbc"] [Tue Aug 18 13:08:44.423423 2026] [security2:error] [pid 167459:tid 167657] [client 20.1.169.243:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSDjGr_JutbFb-8svoGXgAAAdM"] [Tue Aug 18 13:08:44.433239 2026] [security2:error] [pid 167459:tid 167660] [client 20.25.139.174:4533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDjGr_JutbFb-8svoGYQAAAdY"] [Tue Aug 18 13:08:44.490541 2026] [security2:error] [pid 167459:tid 167711] [client 20.116.17.175:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/tiny2.php"] [unique_id "aoSDjGr_JutbFb-8svoGYwAAAgk"] [Tue Aug 18 13:08:44.494055 2026] [security2:error] [pid 167459:tid 167614] [client 20.226.36.136:62185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDjGr_JutbFb-8svoGZAAAAag"] [Tue Aug 18 13:08:44.544808 2026] [security2:error] [pid 167459:tid 167618] [client 158.158.74.177:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/maint.php"] [unique_id "aoSDjGr_JutbFb-8svoGZwAAAaw"] [Tue Aug 18 13:08:44.595730 2026] [security2:error] [pid 167459:tid 167675] [client 172.182.217.32:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/index/function.php"] [unique_id "aoSDjGr_JutbFb-8svoGaAAAAeU"] [Tue Aug 18 13:08:44.638611 2026] [security2:error] [pid 167459:tid 167625] [client 20.171.51.14:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/s.php"] [unique_id "aoSDjGr_JutbFb-8svoGbAAAAbM"] [Tue Aug 18 13:08:44.671027 2026] [security2:error] [pid 167459:tid 167669] [client 172.202.39.151:27843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/moon.php"] [unique_id "aoSDjGr_JutbFb-8svoGbQAAAd8"] [Tue Aug 18 13:08:44.672628 2026] [security2:error] [pid 167459:tid 167716] [client 40.74.65.169:21345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "aoSDjGr_JutbFb-8svoGbgAAAg4"] [Tue Aug 18 13:08:44.719234 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:44.719507 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:44.738458 2026] [security2:error] [pid 167459:tid 167605] [client 172.213.243.2:19536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-good.php"] [unique_id "aoSDjGr_JutbFb-8svoGcwAAAZ8"] [Tue Aug 18 13:08:44.752191 2026] [security2:error] [pid 167459:tid 167634] [client 20.79.204.6:5717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSDjGr_JutbFb-8svoGdAAAAbw"] [Tue Aug 18 13:08:44.757615 2026] [security2:error] [pid 167459:tid 167622] [client 158.23.17.4:5053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/hj.php"] [unique_id "aoSDjGr_JutbFb-8svoGdgAAAbA"] [Tue Aug 18 13:08:44.765322 2026] [security2:error] [pid 167459:tid 167665] [client 4.232.151.198:2465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/ultra.php"] [unique_id "aoSDjGr_JutbFb-8svoGdwAAAds"] [Tue Aug 18 13:08:44.771525 2026] [security2:error] [pid 167459:tid 167656] [client 20.215.241.237:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/fb.php"] [unique_id "aoSDjGr_JutbFb-8svoGeAAAAdI"] [Tue Aug 18 13:08:44.824078 2026] [security2:error] [pid 167459:tid 167594] [client 74.248.133.44:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/inc.php"] [unique_id "aoSDjGr_JutbFb-8svoGegAAAZQ"] [Tue Aug 18 13:08:44.830468 2026] [security2:error] [pid 167459:tid 167679] [client 20.1.169.243:10184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSDjGr_JutbFb-8svoGewAAAek"] [Tue Aug 18 13:08:44.866315 2026] [security2:error] [pid 167459:tid 167616] [client 20.104.100.201:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDjGr_JutbFb-8svoGfQAAAao"] [Tue Aug 18 13:08:44.903521 2026] [security2:error] [pid 167459:tid 167590] [client 20.116.17.175:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/12.php"] [unique_id "aoSDjGr_JutbFb-8svoGfgAAAZA"] [Tue Aug 18 13:08:44.922026 2026] [security2:error] [pid 167459:tid 167649] [client 4.232.151.198:38541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/222.php"] [unique_id "aoSDjGr_JutbFb-8svoGfwAAAcs"] [Tue Aug 18 13:08:44.960550 2026] [security2:error] [pid 167459:tid 167674] [client 20.25.139.174:4828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/themes.php"] [unique_id "aoSDjGr_JutbFb-8svoGgAAAAeQ"] [Tue Aug 18 13:08:45.021818 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:45.022085 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:45.072651 2026] [security2:error] [pid 167459:tid 167653] [client 223.185.37.47:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDjWr_JutbFb-8svoGhQAAAc8"] [Tue Aug 18 13:08:45.072804 2026] [security2:error] [pid 167459:tid 167653] [client 223.185.37.47:23141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDjWr_JutbFb-8svoGhQAAAc8"] [Tue Aug 18 13:08:45.083924 2026] [security2:error] [pid 167459:tid 167600] [client 172.182.217.32:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/inputs.php"] [unique_id "aoSDjWr_JutbFb-8svoGhwAAAZo"] [Tue Aug 18 13:08:45.089941 2026] [security2:error] [pid 167459:tid 167636] [client 52.173.121.69:36600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDjWr_JutbFb-8svoGiAAAAb4"] [Tue Aug 18 13:08:45.121833 2026] [security2:error] [pid 167459:tid 167642] [client 149.34.210.141:54731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDjWr_JutbFb-8svoGigAAAcQ"] [Tue Aug 18 13:08:45.128878 2026] [security2:error] [pid 167459:tid 167697] [client 20.226.36.136:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDjWr_JutbFb-8svoGiwAAAfs"] [Tue Aug 18 13:08:45.159906 2026] [security2:error] [pid 167459:tid 167629] [client 172.213.243.2:34400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/zxin.php"] [unique_id "aoSDjWr_JutbFb-8svoGjAAAAbc"] [Tue Aug 18 13:08:45.168570 2026] [security2:error] [pid 167459:tid 167659] [client 158.158.74.177:13766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/phpMailer.php"] [unique_id "aoSDjWr_JutbFb-8svoGjQAAAdU"] [Tue Aug 18 13:08:45.254345 2026] [security2:error] [pid 167459:tid 167609] [client 158.23.17.4:40439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/sb.php"] [unique_id "aoSDjWr_JutbFb-8svoGjwAAAaM"] [Tue Aug 18 13:08:45.275162 2026] [security2:error] [pid 167459:tid 167589] [client 158.23.17.4:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ij.php"] [unique_id "aoSDjWr_JutbFb-8svoGkAAAAY8"] [Tue Aug 18 13:08:45.290999 2026] [security2:error] [pid 167459:tid 167686] [client 20.116.17.175:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wpxml.php"] [unique_id "aoSDjWr_JutbFb-8svoGkQAAAfA"] [Tue Aug 18 13:08:45.291310 2026] [security2:error] [pid 167459:tid 167690] [client 20.104.100.201:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ot.php"] [unique_id "aoSDjWr_JutbFb-8svoGkgAAAfQ"] [Tue Aug 18 13:08:45.300292 2026] [security2:error] [pid 167459:tid 167597] [client 74.248.18.37:32284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/function/function.php"] [unique_id "aoSDjWr_JutbFb-8svoGkwAAAZc"] [Tue Aug 18 13:08:45.311800 2026] [security2:error] [pid 167459:tid 167658] [client 213.35.127.232:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDjWr_JutbFb-8svoGlAAAAdQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:45.319341 2026] [security2:error] [pid 167459:tid 167635] [client 20.1.169.243:10472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSDjWr_JutbFb-8svoGmQAAAb0"] [Tue Aug 18 13:08:45.326815 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:45.327185 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:45.381542 2026] [security2:error] [pid 167459:tid 167712] [client 20.116.17.175:41475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/x1da.php"] [unique_id "aoSDjWr_JutbFb-8svoGnwAAAgo"] [Tue Aug 18 13:08:45.392713 2026] [security2:error] [pid 167459:tid 167642] [client 149.34.210.141:54731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDjWr_JutbFb-8svoGigAAAcQ"] [Tue Aug 18 13:08:45.397379 2026] [security2:error] [pid 167459:tid 167660] [client 40.74.65.169:7135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "aoSDjWr_JutbFb-8svoGoAAAAdY"] [Tue Aug 18 13:08:45.413263 2026] [security2:error] [pid 167459:tid 167617] [client 20.79.204.6:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/options.php"] [unique_id "aoSDjWr_JutbFb-8svoGogAAAas"] [Tue Aug 18 13:08:45.437763 2026] [security2:error] [pid 167459:tid 167615] [client 20.215.241.237:39332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/gi.php"] [unique_id "aoSDjWr_JutbFb-8svoGowAAAak"] [Tue Aug 18 13:08:45.475783 2026] [security2:error] [pid 167459:tid 167687] [client 213.202.253.4:65205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/txets.php"] [unique_id "aoSDjWr_JutbFb-8svoGpQAAAfE"], referer: www.google.com [Tue Aug 18 13:08:45.527351 2026] [security2:error] [pid 167459:tid 167705] [client 20.226.36.136:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDjWr_JutbFb-8svoGqQAAAgM"] [Tue Aug 18 13:08:45.575903 2026] [security2:error] [pid 167459:tid 167625] [client 172.213.243.2:15061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/pass4.php"] [unique_id "aoSDjWr_JutbFb-8svoGqgAAAbM"] [Tue Aug 18 13:08:45.576411 2026] [security2:error] [pid 167459:tid 167641] [client 172.182.217.32:25576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/layout.php"] [unique_id "aoSDjWr_JutbFb-8svoGqwAAAcM"] [Tue Aug 18 13:08:45.616249 2026] [security2:error] [pid 167459:tid 167716] [client 20.151.109.219:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/creds.php"] [unique_id "aoSDjWr_JutbFb-8svoGrQAAAg4"] [Tue Aug 18 13:08:45.625981 2026] [security2:error] [pid 167459:tid 167676] [client 68.155.154.236:25365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/lddxs.php"] [unique_id "aoSDjWr_JutbFb-8svoGrwAAAeY"] [Tue Aug 18 13:08:45.705001 2026] [security2:error] [pid 167459:tid 167692] [client 20.1.169.243:10193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/admin.php"] [unique_id "aoSDjWr_JutbFb-8svoGuQAAAfY"] [Tue Aug 18 13:08:45.722632 2026] [security2:error] [pid 167459:tid 167614] [client 20.25.139.174:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/cv.php"] [unique_id "aoSDjWr_JutbFb-8svoGugAAAag"] [Tue Aug 18 13:08:45.734234 2026] [security2:error] [pid 167459:tid 167675] [client 4.232.151.198:2514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/un.php"] [unique_id "aoSDjWr_JutbFb-8svoGuwAAAeU"] [Tue Aug 18 13:08:45.784744 2026] [security2:error] [pid 167459:tid 167627] [client 49.51.52.250:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.52.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vhagenciadigital.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjWr_JutbFb-8svoGpAAAAbU"] [Tue Aug 18 13:08:45.785888 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.100.201:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/99.php"] [unique_id "aoSDjWr_JutbFb-8svoGvQAAAdE"] [Tue Aug 18 13:08:45.805062 2026] [security2:error] [pid 167459:tid 167708] [client 158.158.74.177:13894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSDjWr_JutbFb-8svoGvgAAAgY"] [Tue Aug 18 13:08:45.809047 2026] [security2:error] [pid 167459:tid 167683] [client 20.226.36.136:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDjWr_JutbFb-8svoGvwAAAe0"] [Tue Aug 18 13:08:45.820494 2026] [security2:error] [pid 167459:tid 167649] [client 158.23.17.4:14070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/album.php"] [unique_id "aoSDjWr_JutbFb-8svoGwAAAAcs"] [Tue Aug 18 13:08:45.843313 2026] [security2:error] [pid 167459:tid 167592] [client 52.173.121.69:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDjWr_JutbFb-8svoGwQAAAZI"] [Tue Aug 18 13:08:45.859981 2026] [security2:error] [pid 167459:tid 167674] [client 20.215.241.237:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/video.php"] [unique_id "aoSDjWr_JutbFb-8svoGwgAAAeQ"] [Tue Aug 18 13:08:45.890865 2026] [security2:error] [pid 167459:tid 167611] [client 20.116.17.175:22725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/mcs.php"] [unique_id "aoSDjWr_JutbFb-8svoGxAAAAaU"] [Tue Aug 18 13:08:45.892394 2026] [security2:error] [pid 167459:tid 167693] [client 20.226.36.136:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDjWr_JutbFb-8svoGxQAAAfc"] [Tue Aug 18 13:08:45.924501 2026] [security2:error] [pid 167459:tid 167672] [client 158.23.17.4:14055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/xj.php"] [unique_id "aoSDjWr_JutbFb-8svoGxwAAAeI"] [Tue Aug 18 13:08:45.927087 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:45.927349 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:45.958280 2026] [security2:error] [pid 167459:tid 167682] [client 172.202.39.151:39217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/cache.php"] [unique_id "aoSDjWr_JutbFb-8svoGyQAAAew"] [Tue Aug 18 13:08:45.960837 2026] [security2:error] [pid 167459:tid 167599] [client 20.226.36.136:62156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDjWr_JutbFb-8svoGygAAAZk"] [Tue Aug 18 13:08:45.997807 2026] [security2:error] [pid 167459:tid 167636] [client 172.213.243.2:14420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-conflg.php"] [unique_id "aoSDjWr_JutbFb-8svoGywAAAb4"] [Tue Aug 18 13:08:45.999386 2026] [security2:error] [pid 167459:tid 167620] [client 20.226.6.191:4154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDjWr_JutbFb-8svoGzAAAAa4"] [Tue Aug 18 13:08:46.019363 2026] [security2:error] [pid 167459:tid 167629] [client 158.23.17.4:20669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ud.php"] [unique_id "aoSDjmr_JutbFb-8svoGzQAAAbc"] [Tue Aug 18 13:08:46.029200 2026] [security2:error] [pid 167459:tid 167701] [client 20.79.204.6:5889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSDjmr_JutbFb-8svoGzgAAAf8"] [Tue Aug 18 13:08:46.094170 2026] [security2:error] [pid 167459:tid 167609] [client 20.151.109.219:36689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ho.php"] [unique_id "aoSDjmr_JutbFb-8svoG0AAAAaM"] [Tue Aug 18 13:08:46.094988 2026] [security2:error] [pid 167459:tid 167651] [client 20.226.6.191:4121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDjmr_JutbFb-8svoG0QAAAc0"] [Tue Aug 18 13:08:46.102802 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/core.php"] [unique_id "aoSDjmr_JutbFb-8svoG0gAAAeA"] [Tue Aug 18 13:08:46.114678 2026] [security2:error] [pid 167459:tid 167602] [client 68.221.73.131:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/ops.php"] [unique_id "aoSDjmr_JutbFb-8svoG0wAAAZw"] [Tue Aug 18 13:08:46.128772 2026] [security2:error] [pid 167459:tid 167623] [client 20.104.100.201:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/yup.php"] [unique_id "aoSDjmr_JutbFb-8svoG1AAAAbE"] [Tue Aug 18 13:08:46.133145 2026] [security2:error] [pid 167459:tid 167635] [client 20.226.36.136:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDjmr_JutbFb-8svoG1QAAAb0"] [Tue Aug 18 13:08:46.225475 2026] [security2:error] [pid 167459:tid 167688] [client 20.104.100.201:13916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/v5.php"] [unique_id "aoSDjmr_JutbFb-8svoG2gAAAfI"] [Tue Aug 18 13:08:46.231388 2026] [security2:error] [pid 167459:tid 167654] [client 20.226.36.136:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDjmr_JutbFb-8svoG2wAAAdA"] [Tue Aug 18 13:08:46.231681 2026] [security2:error] [pid 167459:tid 167615] [client 40.74.65.169:36932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/media.php"] [unique_id "aoSDjmr_JutbFb-8svoG3AAAAak"] [Tue Aug 18 13:08:46.238572 2026] [security2:error] [pid 167459:tid 167687] [client 20.226.6.191:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/admin.php"] [unique_id "aoSDjmr_JutbFb-8svoG3QAAAfE"] [Tue Aug 18 13:08:46.272656 2026] [security2:error] [pid 167459:tid 167663] [client 20.226.6.191:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/public/css.php"] [unique_id "aoSDjmr_JutbFb-8svoG3wAAAdk"] [Tue Aug 18 13:08:46.279960 2026] [security2:error] [pid 167459:tid 167625] [client 20.215.241.237:30408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/hel.php"] [unique_id "aoSDjmr_JutbFb-8svoG4QAAAbM"] [Tue Aug 18 13:08:46.287238 2026] [security2:error] [pid 167459:tid 167641] [client 20.116.17.175:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/min.php"] [unique_id "aoSDjmr_JutbFb-8svoG4gAAAcM"] [Tue Aug 18 13:08:46.293320 2026] [security2:error] [pid 167459:tid 167713] [client 157.20.138.62:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoG4wAAAgs"] [Tue Aug 18 13:08:46.293488 2026] [security2:error] [pid 167459:tid 167713] [client 157.20.138.62:58264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoG4wAAAgs"] [Tue Aug 18 13:08:46.316159 2026] [security2:error] [pid 167459:tid 167647] [client 20.226.6.191:4109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/classwithtostring.php"] [unique_id "aoSDjmr_JutbFb-8svoG5AAAAck"] [Tue Aug 18 13:08:46.331575 2026] [security2:error] [pid 167459:tid 167684] [client 52.173.121.69:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDjmr_JutbFb-8svoG5QAAAe4"] [Tue Aug 18 13:08:46.335969 2026] [security2:error] [pid 167459:tid 167697] [client 213.35.127.232:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDjmr_JutbFb-8svoG5gAAAfs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:46.355458 2026] [security2:error] [pid 167459:tid 167692] [client 20.171.51.14:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/uo.php"] [unique_id "aoSDjmr_JutbFb-8svoG6AAAAfY"] [Tue Aug 18 13:08:46.369494 2026] [security2:error] [pid 167459:tid 167678] [client 20.226.6.191:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/admin.php"] [unique_id "aoSDjmr_JutbFb-8svoG6gAAAeg"] [Tue Aug 18 13:08:46.377063 2026] [security2:error] [pid 167459:tid 167665] [client 158.23.17.4:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ns.php"] [unique_id "aoSDjmr_JutbFb-8svoG6wAAAds"] [Tue Aug 18 13:08:46.388642 2026] [security2:error] [pid 167459:tid 167675] [client 20.226.6.191:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/gelay.php"] [unique_id "aoSDjmr_JutbFb-8svoG7QAAAeU"] [Tue Aug 18 13:08:46.392254 2026] [security2:error] [pid 167459:tid 167601] [client 20.25.139.174:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDjmr_JutbFb-8svoG7wAAAZs"] [Tue Aug 18 13:08:46.404618 2026] [security2:error] [pid 167459:tid 167655] [client 20.226.36.136:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDjmr_JutbFb-8svoG8AAAAdE"] [Tue Aug 18 13:08:46.408348 2026] [security2:error] [pid 167459:tid 167673] [client 4.232.151.198:2464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/up.php"] [unique_id "aoSDjmr_JutbFb-8svoG8QAAAeM"] [Tue Aug 18 13:08:46.413496 2026] [security2:error] [pid 167459:tid 167616] [client 20.226.6.191:4100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDjmr_JutbFb-8svoG8gAAAao"] [Tue Aug 18 13:08:46.414169 2026] [security2:error] [pid 167459:tid 167715] [client 172.213.243.2:16838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/z.php"] [unique_id "aoSDjmr_JutbFb-8svoG8wAAAg0"] [Tue Aug 18 13:08:46.434898 2026] [security2:error] [pid 167459:tid 167706] [client 20.226.6.191:4159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/adminfuns.php"] [unique_id "aoSDjmr_JutbFb-8svoG9QAAAgQ"] [Tue Aug 18 13:08:46.439333 2026] [security2:error] [pid 167459:tid 167617] [client 158.158.74.177:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/al.php"] [unique_id "aoSDjmr_JutbFb-8svoG9gAAAas"] [Tue Aug 18 13:08:46.441517 2026] [autoindex:error] [pid 167459:tid 167589] [client 74.248.133.44:15116] AH01276: Cannot serve directory /home3/automotivapoa/public_html/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:46.466019 2026] [security2:error] [pid 167459:tid 167674] [client 20.226.6.191:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "aoSDjmr_JutbFb-8svoG-AAAAeQ"] [Tue Aug 18 13:08:46.489712 2026] [security2:error] [pid 167459:tid 167611] [client 20.104.100.201:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/222.php"] [unique_id "aoSDjmr_JutbFb-8svoG-QAAAaU"] [Tue Aug 18 13:08:46.496178 2026] [security2:error] [pid 167459:tid 167603] [client 20.1.169.243:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/db-status.php"] [unique_id "aoSDjmr_JutbFb-8svoG-gAAAZ0"] [Tue Aug 18 13:08:46.504667 2026] [security2:error] [pid 167459:tid 167702] [client 20.226.6.191:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/about.php"] [unique_id "aoSDjmr_JutbFb-8svoG-wAAAgA"] [Tue Aug 18 13:08:46.514058 2026] [security2:error] [pid 167459:tid 167585] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoG_AACCH0"] [Tue Aug 18 13:08:46.514266 2026] [security2:error] [pid 167459:tid 167710] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoG_AACCH0"] [Tue Aug 18 13:08:46.529742 2026] [security2:error] [pid 167459:tid 167682] [client 20.226.6.191:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDjmr_JutbFb-8svoG_gAAAew"] [Tue Aug 18 13:08:46.531047 2026] [authz_core:error] [pid 167459:tid 167565] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:46.531334 2026] [authz_core:error] [pid 167459:tid 167565] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:46.549609 2026] [security2:error] [pid 167459:tid 167600] [client 20.226.6.191:4167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/f35.php"] [unique_id "aoSDjmr_JutbFb-8svoHAAAAAZo"] [Tue Aug 18 13:08:46.591379 2026] [security2:error] [pid 167459:tid 167701] [client 20.226.6.191:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/inputs.php"] [unique_id "aoSDjmr_JutbFb-8svoHAwAAAf8"] [Tue Aug 18 13:08:46.610620 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:61464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDjmr_JutbFb-8svoHBAAAAcc"] [Tue Aug 18 13:08:46.638209 2026] [security2:error] [pid 167459:tid 167659] [client 178.153.171.161:14224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoHBQAAAdU"] [Tue Aug 18 13:08:46.638322 2026] [security2:error] [pid 167459:tid 167659] [client 178.153.171.161:14224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDjmr_JutbFb-8svoHBQAAAdU"] [Tue Aug 18 13:08:46.656013 2026] [security2:error] [pid 167459:tid 167703] [client 20.226.36.136:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDjmr_JutbFb-8svoHBgAAAgE"] [Tue Aug 18 13:08:46.666140 2026] [security2:error] [pid 167459:tid 167657] [client 20.1.169.243:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/666.php"] [unique_id "aoSDjmr_JutbFb-8svoHCAAAAdM"] [Tue Aug 18 13:08:46.669872 2026] [security2:error] [pid 167459:tid 167685] [client 74.248.133.44:15116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDjmr_JutbFb-8svoHCQAAAe8"] [Tue Aug 18 13:08:46.687995 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ip.php"] [unique_id "aoSDjmr_JutbFb-8svoHCwAAAcQ"] [Tue Aug 18 13:08:46.694357 2026] [security2:error] [pid 167459:tid 167648] [client 20.226.36.136:52629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDjmr_JutbFb-8svoHDAAAAco"] [Tue Aug 18 13:08:46.699177 2026] [security2:error] [pid 167459:tid 167694] [client 20.215.241.237:39320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/grok.php"] [unique_id "aoSDjmr_JutbFb-8svoHDgAAAfg"] [Tue Aug 18 13:08:46.711156 2026] [security2:error] [pid 167459:tid 167615] [client 20.226.6.191:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/alfa.php"] [unique_id "aoSDjmr_JutbFb-8svoHDwAAAak"] [Tue Aug 18 13:08:46.714597 2026] [security2:error] [pid 167459:tid 167667] [client 20.79.204.6:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSDjmr_JutbFb-8svoHEQAAAd0"] [Tue Aug 18 13:08:46.747267 2026] [security2:error] [pid 167459:tid 167598] [client 20.116.17.175:41498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/adminner.php"] [unique_id "aoSDjmr_JutbFb-8svoHEwAAAZg"] [Tue Aug 18 13:08:46.751576 2026] [security2:error] [pid 167459:tid 167705] [client 20.226.36.136:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDjmr_JutbFb-8svoHFAAAAgM"] [Tue Aug 18 13:08:46.769986 2026] [security2:error] [pid 167459:tid 167713] [client 20.226.6.191:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/lock360.php"] [unique_id "aoSDjmr_JutbFb-8svoHFQAAAgs"] [Tue Aug 18 13:08:46.783175 2026] [security2:error] [pid 167459:tid 167647] [client 20.116.17.175:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ccou.php"] [unique_id "aoSDjmr_JutbFb-8svoHFwAAAck"] [Tue Aug 18 13:08:46.826678 2026] [security2:error] [pid 167459:tid 167692] [client 172.213.243.2:16895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/222.php"] [unique_id "aoSDjmr_JutbFb-8svoHGwAAAfY"] [Tue Aug 18 13:08:46.829187 2026] [authz_core:error] [pid 167459:tid 167514] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:46.829546 2026] [authz_core:error] [pid 167459:tid 167514] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:46.863248 2026] [security2:error] [pid 167459:tid 167678] [client 20.226.6.191:4140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/flower.php"] [unique_id "aoSDjmr_JutbFb-8svoHHQAAAeg"] [Tue Aug 18 13:08:46.864035 2026] [security2:error] [pid 167459:tid 167618] [client 20.1.169.243:10484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSDjmr_JutbFb-8svoHHgAAAaw"] [Tue Aug 18 13:08:46.871949 2026] [security2:error] [pid 167459:tid 167619] [client 20.65.98.162:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/inso.php"] [unique_id "aoSDjmr_JutbFb-8svoHHwAAAa0"] [Tue Aug 18 13:08:46.891511 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDjmr_JutbFb-8svoHIQAAAZs"] [Tue Aug 18 13:08:46.944377 2026] [security2:error] [pid 167459:tid 167708] [client 20.226.36.136:47983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDjmr_JutbFb-8svoHIwAAAgY"] [Tue Aug 18 13:08:46.954782 2026] [security2:error] [pid 167459:tid 167625] [client 20.25.139.174:4506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ws83.php"] [unique_id "aoSDjmr_JutbFb-8svoHJQAAAbM"] [Tue Aug 18 13:08:46.976810 2026] [security2:error] [pid 167459:tid 167649] [client 40.74.65.169:37382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/inso.php"] [unique_id "aoSDjmr_JutbFb-8svoHJgAAAcs"] [Tue Aug 18 13:08:46.998778 2026] [security2:error] [pid 167459:tid 167589] [client 20.226.6.191:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/13.php"] [unique_id "aoSDjmr_JutbFb-8svoHKAAAAY8"] [Tue Aug 18 13:08:47.011040 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:56753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kv.php"] [unique_id "aoSDj2r_JutbFb-8svoHKgAAAaU"] [Tue Aug 18 13:08:47.032161 2026] [security2:error] [pid 167459:tid 167679] [client 20.1.169.243:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/bgymj.php"] [unique_id "aoSDj2r_JutbFb-8svoHKwAAAek"] [Tue Aug 18 13:08:47.036556 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.36.136:47967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDj2r_JutbFb-8svoHLAAAAc8"] [Tue Aug 18 13:08:47.083167 2026] [security2:error] [pid 167459:tid 167614] [client 158.158.74.177:13818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp.php"] [unique_id "aoSDj2r_JutbFb-8svoHLgAAAag"] [Tue Aug 18 13:08:47.101648 2026] [security2:error] [pid 167459:tid 167600] [client 158.23.17.4:15756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/gk.php"] [unique_id "aoSDj2r_JutbFb-8svoHLwAAAZo"] [Tue Aug 18 13:08:47.112134 2026] [security2:error] [pid 167459:tid 167714] [client 20.226.36.136:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDj2r_JutbFb-8svoHMAAAAgw"] [Tue Aug 18 13:08:47.128522 2026] [security2:error] [pid 167459:tid 167605] [client 20.226.6.191:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/cc.php"] [unique_id "aoSDj2r_JutbFb-8svoHMgAAAZ8"] [Tue Aug 18 13:08:47.131733 2026] [authz_core:error] [pid 167459:tid 167584] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:47.132010 2026] [authz_core:error] [pid 167459:tid 167584] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:47.139114 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:48867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDj2r_JutbFb-8svoHNQAAAcc"] [Tue Aug 18 13:08:47.143618 2026] [security2:error] [pid 167459:tid 167696] [client 20.215.241.237:30431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/indes.php"] [unique_id "aoSDj2r_JutbFb-8svoHNgAAAfo"] [Tue Aug 18 13:08:47.211613 2026] [security2:error] [pid 167459:tid 167632] [client 20.226.6.191:4153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/gecko-new.php"] [unique_id "aoSDj2r_JutbFb-8svoHOQAAAbo"] [Tue Aug 18 13:08:47.215577 2026] [security2:error] [pid 167459:tid 167658] [client 20.151.109.219:20976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/97.php"] [unique_id "aoSDj2r_JutbFb-8svoHOwAAAdQ"] [Tue Aug 18 13:08:47.227120 2026] [security2:error] [pid 167459:tid 167685] [client 158.23.17.4:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/99.php"] [unique_id "aoSDj2r_JutbFb-8svoHPQAAAe8"] [Tue Aug 18 13:08:47.244093 2026] [security2:error] [pid 167459:tid 167606] [client 20.1.169.243:10179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHPgAAAaA"] [Tue Aug 18 13:08:47.245749 2026] [security2:error] [pid 167459:tid 167650] [client 172.213.243.2:36103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/G-in.php"] [unique_id "aoSDj2r_JutbFb-8svoHPwAAAcw"] [Tue Aug 18 13:08:47.260458 2026] [security2:error] [pid 167459:tid 167630] [client 20.226.6.191:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content.php.php"] [unique_id "aoSDj2r_JutbFb-8svoHQAAAAbg"] [Tue Aug 18 13:08:47.315573 2026] [core:notice] [pid 167459:tid 167501] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:08:47.350627 2026] [security2:error] [pid 167459:tid 167603] [client 213.35.127.232:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDj2r_JutbFb-8svoHQgAAAZ0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:47.374061 2026] [security2:error] [pid 167459:tid 167669] [client 20.104.100.201:53353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/spadex.php"] [unique_id "aoSDj2r_JutbFb-8svoHRQAAAd8"] [Tue Aug 18 13:08:47.379368 2026] [security2:error] [pid 167459:tid 167668] [client 4.232.151.198:30094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/users.php"] [unique_id "aoSDj2r_JutbFb-8svoHRgAAAd4"] [Tue Aug 18 13:08:47.395405 2026] [security2:error] [pid 167459:tid 167648] [client 20.1.169.243:9547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/bthil.php"] [unique_id "aoSDj2r_JutbFb-8svoHRwAAAco"] [Tue Aug 18 13:08:47.436673 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:47.436948 2026] [authz_core:error] [pid 167459:tid 167478] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:47.438126 2026] [security2:error] [pid 167459:tid 167684] [client 20.226.6.191:4098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/01.php"] [unique_id "aoSDj2r_JutbFb-8svoHSQAAAe4"] [Tue Aug 18 13:08:47.486511 2026] [security2:error] [pid 167459:tid 167618] [client 52.173.121.69:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDj2r_JutbFb-8svoHSgAAAaw"] [Tue Aug 18 13:08:47.488003 2026] [security2:error] [pid 167459:tid 167619] [client 20.226.36.136:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDj2r_JutbFb-8svoHSwAAAa0"] [Tue Aug 18 13:08:47.502662 2026] [security2:error] [pid 167459:tid 167623] [client 74.248.133.44:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/x.php"] [unique_id "aoSDj2r_JutbFb-8svoHTAAAAbE"] [Tue Aug 18 13:08:47.503599 2026] [security2:error] [pid 167459:tid 167675] [client 20.116.17.175:22686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/dragonshell.php"] [unique_id "aoSDj2r_JutbFb-8svoHTQAAAeU"] [Tue Aug 18 13:08:47.508796 2026] [security2:error] [pid 167459:tid 167654] [client 20.25.139.174:4852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/atex1.php"] [unique_id "aoSDj2r_JutbFb-8svoHTgAAAdA"] [Tue Aug 18 13:08:47.526697 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/crgio.php"] [unique_id "aoSDj2r_JutbFb-8svoHTwAAAeM"] [Tue Aug 18 13:08:47.532196 2026] [security2:error] [pid 167459:tid 167715] [client 20.104.100.201:13922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/replace.php"] [unique_id "aoSDj2r_JutbFb-8svoHUQAAAg0"] [Tue Aug 18 13:08:47.559016 2026] [security2:error] [pid 167459:tid 167664] [client 20.226.36.136:47950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDj2r_JutbFb-8svoHVQAAAdo"] [Tue Aug 18 13:08:47.560223 2026] [security2:error] [pid 167459:tid 167597] [client 20.79.204.6:5672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSDj2r_JutbFb-8svoHVgAAAZc"] [Tue Aug 18 13:08:47.621202 2026] [security2:error] [pid 167459:tid 167693] [client 20.215.241.237:34401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/tTPcH.php"] [unique_id "aoSDj2r_JutbFb-8svoHWgAAAfc"] [Tue Aug 18 13:08:47.631229 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:10181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHWwAAAZs"] [Tue Aug 18 13:08:47.684302 2026] [security2:error] [pid 167459:tid 167599] [client 172.213.243.2:19567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xxx.php"] [unique_id "aoSDj2r_JutbFb-8svoHXQAAAZk"] [Tue Aug 18 13:08:47.684414 2026] [security2:error] [pid 167459:tid 167679] [client 20.226.6.191:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/lv.php"] [unique_id "aoSDj2r_JutbFb-8svoHXgAAAek"] [Tue Aug 18 13:08:47.713519 2026] [security2:error] [pid 167459:tid 167607] [client 158.158.74.177:13759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-activat.php"] [unique_id "aoSDj2r_JutbFb-8svoHYQAAAaE"] [Tue Aug 18 13:08:47.729272 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:5010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/er.php"] [unique_id "aoSDj2r_JutbFb-8svoHYwAAAZQ"] [Tue Aug 18 13:08:47.735274 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:47.735545 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:47.767705 2026] [security2:error] [pid 167459:tid 167629] [client 40.74.65.169:20752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/shiny.php"] [unique_id "aoSDj2r_JutbFb-8svoHZAAAAbc"] [Tue Aug 18 13:08:47.769358 2026] [security2:error] [pid 167459:tid 167613] [client 20.226.36.136:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDj2r_JutbFb-8svoHZQAAAac"] [Tue Aug 18 13:08:47.792527 2026] [security2:error] [pid 167459:tid 167595] [client 172.182.217.32:25577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/text.php"] [unique_id "aoSDj2r_JutbFb-8svoHZgAAAZU"] [Tue Aug 18 13:08:47.796516 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.6.191:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/new.php"] [unique_id "aoSDj2r_JutbFb-8svoHZwAAAcc"] [Tue Aug 18 13:08:47.815843 2026] [security2:error] [pid 167459:tid 167702] [client 20.1.169.243:8898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/xp.php"] [unique_id "aoSDj2r_JutbFb-8svoHaAAAAgA"] [Tue Aug 18 13:08:47.829265 2026] [security2:error] [pid 167459:tid 167696] [client 68.155.154.236:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/zjggu.php"] [unique_id "aoSDj2r_JutbFb-8svoHagAAAfo"] [Tue Aug 18 13:08:47.829898 2026] [security2:error] [pid 167459:tid 167611] [client 104.222.31.70:57285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fbenevides.com.br"] [uri "/pandora_console/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHawAAAaU"] [Tue Aug 18 13:08:47.833420 2026] [security2:error] [pid 167459:tid 167677] [client 104.222.31.70:57279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.31.222.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/pandora_console/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHbAAAAec"] [Tue Aug 18 13:08:47.851190 2026] [security2:error] [pid 167459:tid 167670] [client 20.226.6.191:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/222.php"] [unique_id "aoSDj2r_JutbFb-8svoHbwAAAeA"] [Tue Aug 18 13:08:47.885812 2026] [security2:error] [pid 167459:tid 167658] [client 172.202.39.151:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDj2r_JutbFb-8svoHcwAAAdQ"] [Tue Aug 18 13:08:47.905656 2026] [security2:error] [pid 167459:tid 167680] [client 20.226.6.191:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/chosen.php"] [unique_id "aoSDj2r_JutbFb-8svoHdAAAAeo"] [Tue Aug 18 13:08:47.946287 2026] [security2:error] [pid 167459:tid 167712] [client 20.104.100.201:53345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHdgAAAgo"] [Tue Aug 18 13:08:47.946313 2026] [security2:error] [pid 167459:tid 167596] [client 20.226.6.191:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/info.php"] [unique_id "aoSDj2r_JutbFb-8svoHdwAAAZY"] [Tue Aug 18 13:08:47.979091 2026] [security2:error] [pid 167459:tid 167705] [client 20.226.6.191:4151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDj2r_JutbFb-8svoHewAAAgM"] [Tue Aug 18 13:08:47.997183 2026] [security2:error] [pid 167459:tid 167632] [client 20.1.169.243:10219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSDj2r_JutbFb-8svoHfAAAAbo"] [Tue Aug 18 13:08:48.037048 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:48.037314 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:48.049969 2026] [security2:error] [pid 167459:tid 167684] [client 20.226.6.191:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDkGr_JutbFb-8svoHfwAAAe4"] [Tue Aug 18 13:08:48.050134 2026] [security2:error] [pid 167459:tid 167689] [client 4.232.151.198:2483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/v.php"] [unique_id "aoSDkGr_JutbFb-8svoHfgAAAfM"] [Tue Aug 18 13:08:48.070218 2026] [security2:error] [pid 167459:tid 167692] [client 52.173.121.69:28349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDkGr_JutbFb-8svoHgAAAAfY"] [Tue Aug 18 13:08:48.075104 2026] [security2:error] [pid 167459:tid 167606] [client 20.25.139.174:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/class-t.api.php"] [unique_id "aoSDkGr_JutbFb-8svoHgQAAAaA"] [Tue Aug 18 13:08:48.088801 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:48410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/z.php"] [unique_id "aoSDkGr_JutbFb-8svoHggAAAdM"] [Tue Aug 18 13:08:48.110521 2026] [security2:error] [pid 167459:tid 167654] [client 172.213.243.2:14441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/un.php"] [unique_id "aoSDkGr_JutbFb-8svoHgwAAAdA"] [Tue Aug 18 13:08:48.121156 2026] [security2:error] [pid 167459:tid 167644] [client 74.248.18.37:49755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/nw.php"] [unique_id "aoSDkGr_JutbFb-8svoHhAAAAcY"] [Tue Aug 18 13:08:48.147388 2026] [security2:error] [pid 167459:tid 167673] [client 20.226.6.191:4144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/k.php"] [unique_id "aoSDkGr_JutbFb-8svoHhQAAAeM"] [Tue Aug 18 13:08:48.179610 2026] [security2:error] [pid 167459:tid 167708] [client 20.215.241.237:2981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/bs1.php"] [unique_id "aoSDkGr_JutbFb-8svoHhwAAAgY"] [Tue Aug 18 13:08:48.179858 2026] [security2:error] [pid 167459:tid 167615] [client 20.1.169.243:8903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/reze.php"] [unique_id "aoSDkGr_JutbFb-8svoHiAAAAak"] [Tue Aug 18 13:08:48.194624 2026] [security2:error] [pid 167459:tid 167597] [client 20.226.6.191:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/403.php"] [unique_id "aoSDkGr_JutbFb-8svoHigAAAZc"] [Tue Aug 18 13:08:48.195176 2026] [security2:error] [pid 167459:tid 167625] [client 158.23.17.4:39575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/qk.php"] [unique_id "aoSDkGr_JutbFb-8svoHiwAAAbM"] [Tue Aug 18 13:08:48.202173 2026] [security2:error] [pid 167459:tid 167649] [client 20.226.36.136:47947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDkGr_JutbFb-8svoHjAAAAcs"] [Tue Aug 18 13:08:48.254763 2026] [security2:error] [pid 167459:tid 167672] [client 20.116.17.175:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDkGr_JutbFb-8svoHjQAAAeI"] [Tue Aug 18 13:08:48.261104 2026] [security2:error] [pid 167459:tid 167599] [client 20.116.17.175:22663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/setup-config.php"] [unique_id "aoSDkGr_JutbFb-8svoHjgAAAZk"] [Tue Aug 18 13:08:48.298644 2026] [security2:error] [pid 167459:tid 167655] [client 172.182.217.32:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/tmp/.phpEsretb_zablokowane"] [unique_id "aoSDkGr_JutbFb-8svoHkQAAAdE"] [Tue Aug 18 13:08:48.303984 2026] [security2:error] [pid 167459:tid 167614] [client 20.226.6.191:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/gecko.php"] [unique_id "aoSDkGr_JutbFb-8svoHkgAAAag"] [Tue Aug 18 13:08:48.316260 2026] [security2:error] [pid 167459:tid 167675] [client 20.79.204.6:5973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSDkGr_JutbFb-8svoHlAAAAeU"] [Tue Aug 18 13:08:48.317855 2026] [security2:error] [pid 167459:tid 167675] [client 20.226.36.136:48858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDkGr_JutbFb-8svoHlQAAAeU"] [Tue Aug 18 13:08:48.346861 2026] [authz_core:error] [pid 167459:tid 167470] [remote 57.141.22.122:50414] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:48.347273 2026] [authz_core:error] [pid 167459:tid 167470] [remote 57.141.22.122:50414] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:48.353095 2026] [security2:error] [pid 167459:tid 167627] [client 158.158.74.177:13762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSDkGr_JutbFb-8svoHmQAAAbU"] [Tue Aug 18 13:08:48.366888 2026] [security2:error] [pid 167459:tid 167697] [client 20.1.169.243:10460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/ms-files.php"] [unique_id "aoSDkGr_JutbFb-8svoHmgAAAfs"] [Tue Aug 18 13:08:48.368288 2026] [security2:error] [pid 167459:tid 167637] [client 213.35.127.232:51489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDkGr_JutbFb-8svoHnAAAAb8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:48.383673 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.6.191:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/aa.php"] [unique_id "aoSDkGr_JutbFb-8svoHngAAAcc"] [Tue Aug 18 13:08:48.438652 2026] [security2:error] [pid 167459:tid 167622] [client 74.248.133.44:60087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/filemanager.php"] [unique_id "aoSDkGr_JutbFb-8svoHnwAAAbA"] [Tue Aug 18 13:08:48.452314 2026] [security2:error] [pid 167459:tid 167602] [client 158.23.17.4:15796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wn.php"] [unique_id "aoSDkGr_JutbFb-8svoHoAAAAZw"] [Tue Aug 18 13:08:48.467481 2026] [security2:error] [pid 167459:tid 167636] [client 20.226.6.191:4150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/0x.php"] [unique_id "aoSDkGr_JutbFb-8svoHoQAAAb4"] [Tue Aug 18 13:08:48.504280 2026] [security2:error] [pid 167459:tid 167642] [client 40.74.65.169:36990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/403dd.php"] [unique_id "aoSDkGr_JutbFb-8svoHogAAAcQ"] [Tue Aug 18 13:08:48.538886 2026] [security2:error] [pid 167459:tid 167596] [client 172.213.243.2:15060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/autogooey.php"] [unique_id "aoSDkGr_JutbFb-8svoHowAAAZY"] [Tue Aug 18 13:08:48.542163 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:8918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/2026w.php"] [unique_id "aoSDkGr_JutbFb-8svoHpQAAAec"] [Tue Aug 18 13:08:48.559784 2026] [security2:error] [pid 167459:tid 167598] [client 20.226.36.136:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDkGr_JutbFb-8svoHpgAAAZg"] [Tue Aug 18 13:08:48.572378 2026] [security2:error] [pid 167459:tid 167705] [client 158.23.17.4:38373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fraie1p4.php"] [unique_id "aoSDkGr_JutbFb-8svoHpwAAAgM"] [Tue Aug 18 13:08:48.581466 2026] [security2:error] [pid 167459:tid 167590] [client 4.232.151.198:40864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDkGr_JutbFb-8svoHqAAAAZA"] [Tue Aug 18 13:08:48.589170 2026] [security2:error] [pid 167459:tid 167624] [client 20.127.136.245:14747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSDkGr_JutbFb-8svoHqQAAAbI"] [Tue Aug 18 13:08:48.591886 2026] [security2:error] [pid 167459:tid 167611] [client 20.25.139.174:4707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/w.php"] [unique_id "aoSDkGr_JutbFb-8svoHqgAAAaU"] [Tue Aug 18 13:08:48.594137 2026] [security2:error] [pid 167459:tid 167663] [client 20.226.6.191:4123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/zxz.php"] [unique_id "aoSDkGr_JutbFb-8svoHqwAAAdk"] [Tue Aug 18 13:08:48.638798 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:48.639058 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:48.643915 2026] [security2:error] [pid 167459:tid 167713] [client 20.226.6.191:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/www.php"] [unique_id "aoSDkGr_JutbFb-8svoHrgAAAgs"] [Tue Aug 18 13:08:48.698801 2026] [security2:error] [pid 167459:tid 167635] [client 4.232.151.198:21480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/v5.php"] [unique_id "aoSDkGr_JutbFb-8svoHuwAAAb0"] [Tue Aug 18 13:08:48.734853 2026] [security2:error] [pid 167459:tid 167589] [client 20.226.6.191:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wicked.php"] [unique_id "aoSDkGr_JutbFb-8svoHwAAAAY8"] [Tue Aug 18 13:08:48.749404 2026] [security2:error] [pid 167459:tid 167632] [client 20.1.169.243:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/options.php"] [unique_id "aoSDkGr_JutbFb-8svoHwQAAAbo"] [Tue Aug 18 13:08:48.752768 2026] [security2:error] [pid 167459:tid 167651] [client 20.226.6.191:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/HLA-dd.php"] [unique_id "aoSDkGr_JutbFb-8svoHwgAAAc0"] [Tue Aug 18 13:08:48.760353 2026] [security2:error] [pid 167459:tid 167667] [client 20.104.100.201:53291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/srontol.php"] [unique_id "aoSDkGr_JutbFb-8svoHwwAAAd0"] [Tue Aug 18 13:08:48.777429 2026] [security2:error] [pid 167459:tid 167679] [client 20.226.6.191:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDkGr_JutbFb-8svoHxgAAAek"] [Tue Aug 18 13:08:48.779895 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:5331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/as.php"] [unique_id "aoSDkGr_JutbFb-8svoHxwAAAcU"] [Tue Aug 18 13:08:48.787559 2026] [security2:error] [pid 167459:tid 167641] [client 172.182.217.32:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/upload.php"] [unique_id "aoSDkGr_JutbFb-8svoHyAAAAcM"] [Tue Aug 18 13:08:48.812109 2026] [security2:error] [pid 167459:tid 167655] [client 172.202.39.151:39208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDkGr_JutbFb-8svoHywAAAdE"] [Tue Aug 18 13:08:48.849976 2026] [security2:error] [pid 167459:tid 167600] [client 20.215.241.237:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/hp2.php"] [unique_id "aoSDkGr_JutbFb-8svoHzAAAAZo"] [Tue Aug 18 13:08:48.880611 2026] [security2:error] [pid 167459:tid 167613] [client 20.226.6.191:4155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/cah.php"] [unique_id "aoSDkGr_JutbFb-8svoHzwAAAac"] [Tue Aug 18 13:08:48.914209 2026] [security2:error] [pid 167459:tid 167670] [client 20.116.17.175:22731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/f35.update.php"] [unique_id "aoSDkGr_JutbFb-8svoH0AAAAeA"] [Tue Aug 18 13:08:48.941038 2026] [security2:error] [pid 167459:tid 167714] [client 20.226.36.136:47966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDkGr_JutbFb-8svoH0wAAAgw"] [Tue Aug 18 13:08:48.945756 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:48.946194 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:48.955578 2026] [security2:error] [pid 167459:tid 167605] [client 172.213.243.2:14355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sty.php"] [unique_id "aoSDkGr_JutbFb-8svoH1AAAAZ8"] [Tue Aug 18 13:08:48.956878 2026] [security2:error] [pid 167459:tid 167693] [client 20.79.204.6:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-blink.php"] [unique_id "aoSDkGr_JutbFb-8svoH1QAAAfc"] [Tue Aug 18 13:08:48.964273 2026] [security2:error] [pid 167459:tid 167630] [client 20.226.6.191:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/system_log.php"] [unique_id "aoSDkGr_JutbFb-8svoH1gAAAbg"] [Tue Aug 18 13:08:48.979646 2026] [security2:error] [pid 167459:tid 167596] [client 158.23.17.4:40447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xg.php"] [unique_id "aoSDkGr_JutbFb-8svoH1wAAAZY"] [Tue Aug 18 13:08:48.985086 2026] [security2:error] [pid 167459:tid 167690] [client 158.158.74.177:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/past1.php"] [unique_id "aoSDkGr_JutbFb-8svoH2AAAAfQ"] [Tue Aug 18 13:08:48.987801 2026] [security2:error] [pid 167459:tid 167480] [remote 162.214.96.231:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnomor.com.br"] [uri "/wp-login.php"] [unique_id "aoSDkGr_JutbFb-8svoH2QABwBQ"] [Tue Aug 18 13:08:48.989603 2026] [security2:error] [pid 167459:tid 167620] [client 20.1.169.243:8938] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/1.php"] [unique_id "aoSDkGr_JutbFb-8svoH2wAAAa4"] [Tue Aug 18 13:08:48.989669 2026] [security2:error] [pid 167459:tid 167620] [client 20.1.169.243:8938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/1.php"] [unique_id "aoSDkGr_JutbFb-8svoH2wAAAa4"] [Tue Aug 18 13:08:49.001097 2026] [security2:error] [pid 167459:tid 167688] [client 138.36.100.162:42027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoH3AAAAfI"] [Tue Aug 18 13:08:49.001199 2026] [security2:error] [pid 167459:tid 167688] [client 138.36.100.162:42027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoH3AAAAfI"] [Tue Aug 18 13:08:49.054706 2026] [security2:error] [pid 167459:tid 167663] [client 52.173.121.69:28297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDkWr_JutbFb-8svoH6wAAAdk"] [Tue Aug 18 13:08:49.062900 2026] [security2:error] [pid 167459:tid 167713] [client 20.116.17.175:52873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/css.php"] [unique_id "aoSDkWr_JutbFb-8svoH7AAAAgs"] [Tue Aug 18 13:08:49.067387 2026] [security2:error] [pid 167459:tid 167678] [client 20.226.6.191:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/user/index.php"] [unique_id "aoSDkWr_JutbFb-8svoH8QAAAeg"] [Tue Aug 18 13:08:49.097129 2026] [security2:error] [pid 167459:tid 167616] [client 158.23.17.4:20608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fs.php"] [unique_id "aoSDkWr_JutbFb-8svoH8gAAAao"] [Tue Aug 18 13:08:49.114230 2026] [security2:error] [pid 167459:tid 167618] [client 20.226.6.191:4143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/ioxi-o.php"] [unique_id "aoSDkWr_JutbFb-8svoH8wAAAaw"] [Tue Aug 18 13:08:49.125285 2026] [security2:error] [pid 167459:tid 167642] [client 104.222.31.70:57991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.31.222.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fioplastic.com.br"] [uri "/dashboard/uploadID.php"] [unique_id "aoSDkWr_JutbFb-8svoH9AAAAcQ"] [Tue Aug 18 13:08:49.141379 2026] [security2:error] [pid 167459:tid 167680] [client 20.25.139.174:4493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/archive.php"] [unique_id "aoSDkWr_JutbFb-8svoH9QAAAeo"] [Tue Aug 18 13:08:49.141387 2026] [security2:error] [pid 167459:tid 167589] [client 20.171.51.14:19898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kx.php"] [unique_id "aoSDkWr_JutbFb-8svoH9wAAAY8"] [Tue Aug 18 13:08:49.141414 2026] [security2:error] [pid 167459:tid 167625] [client 20.226.6.191:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/abc.php"] [unique_id "aoSDkWr_JutbFb-8svoH-AAAAbM"] [Tue Aug 18 13:08:49.144021 2026] [security2:error] [pid 167459:tid 167603] [client 20.1.169.243:16293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/atex1.php"] [unique_id "aoSDkWr_JutbFb-8svoH-QAAAZ0"] [Tue Aug 18 13:08:49.147754 2026] [security2:error] [pid 167459:tid 167694] [client 20.1.169.243:10464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/panel.php"] [unique_id "aoSDkWr_JutbFb-8svoH-gAAAfg"] [Tue Aug 18 13:08:49.156308 2026] [security2:error] [pid 167459:tid 167632] [client 20.226.6.191:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/akcc.php"] [unique_id "aoSDkWr_JutbFb-8svoH-wAAAbo"] [Tue Aug 18 13:08:49.172357 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.6.191:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wk/index.php"] [unique_id "aoSDkWr_JutbFb-8svoH_AAAAc8"] [Tue Aug 18 13:08:49.173693 2026] [security2:error] [pid 167459:tid 167591] [client 114.5.214.109:50419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoH_QAAAZE"] [Tue Aug 18 13:08:49.173809 2026] [security2:error] [pid 167459:tid 167591] [client 114.5.214.109:50419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoH_QAAAZE"] [Tue Aug 18 13:08:49.198712 2026] [security2:error] [pid 167459:tid 167641] [client 20.226.6.191:4220] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.classeamotel.com"] [uri "/1.php"] [unique_id "aoSDkWr_JutbFb-8svoH_gAAAcM"] [Tue Aug 18 13:08:49.198848 2026] [security2:error] [pid 167459:tid 167641] [client 20.226.6.191:4220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/1.php"] [unique_id "aoSDkWr_JutbFb-8svoH_gAAAcM"] [Tue Aug 18 13:08:49.217549 2026] [security2:error] [pid 167459:tid 167617] [client 20.104.100.201:62625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/fw/faiyy.php"] [unique_id "aoSDkWr_JutbFb-8svoH_wAAAas"] [Tue Aug 18 13:08:49.236163 2026] [security2:error] [pid 167459:tid 167631] [client 20.226.6.191:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/x/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIAgAAAbk"] [Tue Aug 18 13:08:49.240808 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:49.241095 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:49.256986 2026] [security2:error] [pid 167459:tid 167640] [client 172.202.39.151:39182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/o.php"] [unique_id "aoSDkWr_JutbFb-8svoIAwAAAcI"] [Tue Aug 18 13:08:49.259991 2026] [security2:error] [pid 167459:tid 167671] [client 20.226.6.191:4102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIBAAAAeE"] [Tue Aug 18 13:08:49.274503 2026] [security2:error] [pid 167459:tid 167689] [client 172.182.217.32:25623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/upload/upload_cert.php"] [unique_id "aoSDkWr_JutbFb-8svoIBgAAAfM"] [Tue Aug 18 13:08:49.276346 2026] [security2:error] [pid 167459:tid 167683] [client 20.226.6.191:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/as.php"] [unique_id "aoSDkWr_JutbFb-8svoIBwAAAe0"] [Tue Aug 18 13:08:49.290924 2026] [security2:error] [pid 167459:tid 167629] [client 20.226.6.191:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDkWr_JutbFb-8svoICAAAAbc"] [Tue Aug 18 13:08:49.300051 2026] [security2:error] [pid 167459:tid 167646] [client 20.215.241.237:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/yb.php"] [unique_id "aoSDkWr_JutbFb-8svoICQAAAcg"] [Tue Aug 18 13:08:49.339187 2026] [security2:error] [pid 167459:tid 167654] [client 40.74.65.169:7099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/baba.php"] [unique_id "aoSDkWr_JutbFb-8svoIHQAAAdA"] [Tue Aug 18 13:08:49.357587 2026] [security2:error] [pid 167459:tid 167614] [client 20.1.169.243:8951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/2.php"] [unique_id "aoSDkWr_JutbFb-8svoIHgAAAag"] [Tue Aug 18 13:08:49.360365 2026] [security2:error] [pid 167459:tid 167662] [client 20.226.6.191:4157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-config-sample.php"] [unique_id "aoSDkWr_JutbFb-8svoIIAAAAdg"] [Tue Aug 18 13:08:49.362840 2026] [security2:error] [pid 167459:tid 167652] [client 20.151.109.219:40506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/rh.php"] [unique_id "aoSDkWr_JutbFb-8svoIIQAAAc4"] [Tue Aug 18 13:08:49.380860 2026] [security2:error] [pid 167459:tid 167598] [client 213.35.127.232:51720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDkWr_JutbFb-8svoIIgAAAZg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:49.382244 2026] [security2:error] [pid 167459:tid 167707] [client 74.249.206.207:17536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDkWr_JutbFb-8svoIIwAAAgU"] [Tue Aug 18 13:08:49.390011 2026] [security2:error] [pid 167459:tid 167681] [client 20.250.13.23:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/simple.php"] [unique_id "aoSDkWr_JutbFb-8svoIJQAAAes"] [Tue Aug 18 13:08:49.393672 2026] [security2:error] [pid 167459:tid 167670] [client 172.213.243.2:14435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wio.php"] [unique_id "aoSDkWr_JutbFb-8svoIJgAAAeA"] [Tue Aug 18 13:08:49.401578 2026] [security2:error] [pid 167459:tid 167622] [client 20.226.6.191:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIJwAAAbA"] [Tue Aug 18 13:08:49.407093 2026] [security2:error] [pid 167459:tid 167658] [client 20.104.100.201:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/file5.php"] [unique_id "aoSDkWr_JutbFb-8svoIKAAAAdQ"] [Tue Aug 18 13:08:49.413206 2026] [security2:error] [pid 167459:tid 167709] [client 20.226.6.191:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIKgAAAgc"] [Tue Aug 18 13:08:49.437210 2026] [security2:error] [pid 167459:tid 167596] [client 20.116.17.175:22700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/bdroot.php"] [unique_id "aoSDkWr_JutbFb-8svoIKwAAAZY"] [Tue Aug 18 13:08:49.448538 2026] [security2:error] [pid 167459:tid 167716] [client 197.184.64.235:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoILAAAAg4"] [Tue Aug 18 13:08:49.448646 2026] [security2:error] [pid 167459:tid 167716] [client 197.184.64.235:42695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkWr_JutbFb-8svoILAAAAg4"] [Tue Aug 18 13:08:49.497359 2026] [security2:error] [pid 167459:tid 167624] [client 20.226.6.191:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIMAAAAbI"] [Tue Aug 18 13:08:49.506974 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:5782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/atomlib.php"] [unique_id "aoSDkWr_JutbFb-8svoIMgAAAfA"] [Tue Aug 18 13:08:49.543553 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:49.543829 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:49.549344 2026] [security2:error] [pid 167459:tid 167684] [client 20.226.6.191:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/an.php"] [unique_id "aoSDkWr_JutbFb-8svoINAAAAe4"] [Tue Aug 18 13:08:49.552841 2026] [security2:error] [pid 167459:tid 167692] [client 158.23.17.4:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/app.php"] [unique_id "aoSDkWr_JutbFb-8svoINQAAAfY"] [Tue Aug 18 13:08:49.553195 2026] [security2:error] [pid 167459:tid 167693] [client 20.1.169.243:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSDkWr_JutbFb-8svoINgAAAfc"] [Tue Aug 18 13:08:49.556405 2026] [security2:error] [pid 167459:tid 167627] [client 4.232.151.198:2492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/we.php"] [unique_id "aoSDkWr_JutbFb-8svoINwAAAbU"] [Tue Aug 18 13:08:49.593403 2026] [security2:error] [pid 167459:tid 167597] [client 20.116.17.175:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDkWr_JutbFb-8svoIOQAAAZc"] [Tue Aug 18 13:08:49.611044 2026] [security2:error] [pid 167459:tid 167592] [client 20.226.6.191:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/404.php"] [unique_id "aoSDkWr_JutbFb-8svoIOgAAAZI"] [Tue Aug 18 13:08:49.617928 2026] [security2:error] [pid 167459:tid 167685] [client 20.79.204.6:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDkWr_JutbFb-8svoIOwAAAe8"] [Tue Aug 18 13:08:49.634521 2026] [security2:error] [pid 167459:tid 167605] [client 158.158.74.177:13745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/file61.php"] [unique_id "aoSDkWr_JutbFb-8svoIPQAAAZ8"] [Tue Aug 18 13:08:49.685033 2026] [security2:error] [pid 167459:tid 167667] [client 158.23.17.4:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/rb.php"] [unique_id "aoSDkWr_JutbFb-8svoIPwAAAd0"] [Tue Aug 18 13:08:49.688835 2026] [security2:error] [pid 167459:tid 167647] [client 20.25.139.174:4700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/bless.php"] [unique_id "aoSDkWr_JutbFb-8svoIQAAAAck"] [Tue Aug 18 13:08:49.714268 2026] [security2:error] [pid 167459:tid 167591] [client 172.202.39.151:27885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/bb.php"] [unique_id "aoSDkWr_JutbFb-8svoIQgAAAZE"] [Tue Aug 18 13:08:49.721218 2026] [security2:error] [pid 167459:tid 167589] [client 20.1.169.243:9545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/7.php"] [unique_id "aoSDkWr_JutbFb-8svoIQwAAAY8"] [Tue Aug 18 13:08:49.759735 2026] [security2:error] [pid 167459:tid 167641] [client 20.215.241.237:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/vc.php"] [unique_id "aoSDkWr_JutbFb-8svoIRQAAAcM"] [Tue Aug 18 13:08:49.769616 2026] [security2:error] [pid 167459:tid 167680] [client 172.182.217.32:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/uploads/683584ibal.php.xxxjpg"] [unique_id "aoSDkWr_JutbFb-8svoIRgAAAeo"] [Tue Aug 18 13:08:49.829158 2026] [security2:error] [pid 167459:tid 167675] [client 20.104.100.201:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/yup.php"] [unique_id "aoSDkWr_JutbFb-8svoIRwAAAeU"] [Tue Aug 18 13:08:49.839066 2026] [security2:error] [pid 167459:tid 167665] [client 172.213.243.2:19565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/1061.php"] [unique_id "aoSDkWr_JutbFb-8svoISQAAAds"] [Tue Aug 18 13:08:49.847388 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:49.847790 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:49.865482 2026] [security2:error] [pid 167459:tid 167610] [client 158.23.17.4:40416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/nd.php"] [unique_id "aoSDkWr_JutbFb-8svoISgAAAaQ"] [Tue Aug 18 13:08:49.868196 2026] [security2:error] [pid 167459:tid 167613] [client 20.104.100.201:17390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/dex.php"] [unique_id "aoSDkWr_JutbFb-8svoISwAAAac"] [Tue Aug 18 13:08:49.871313 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:5799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/black.php"] [unique_id "aoSDkWr_JutbFb-8svoITAAAAcU"] [Tue Aug 18 13:08:49.889349 2026] [security2:error] [pid 167459:tid 167706] [client 20.226.6.191:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-login.php"] [unique_id "aoSDkWr_JutbFb-8svoIRAAAAgQ"] [Tue Aug 18 13:08:49.905845 2026] [security2:error] [pid 167459:tid 167715] [client 20.226.6.191:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/uploads/goods.php"] [unique_id "aoSDkWr_JutbFb-8svoITQAAAg0"] [Tue Aug 18 13:08:49.917807 2026] [security2:error] [pid 167459:tid 167631] [client 20.1.169.243:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSDkWr_JutbFb-8svoITgAAAbk"] [Tue Aug 18 13:08:50.009920 2026] [security2:error] [pid 167459:tid 167702] [client 20.226.36.136:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDkmr_JutbFb-8svoIUQAAAgA"] [Tue Aug 18 13:08:50.011952 2026] [security2:error] [pid 167459:tid 167598] [client 20.226.6.191:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wso.php"] [unique_id "aoSDkmr_JutbFb-8svoIUgAAAZg"] [Tue Aug 18 13:08:50.028320 2026] [security2:error] [pid 167459:tid 167622] [client 52.173.121.69:28288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIVAAAAbA"] [Tue Aug 18 13:08:50.038754 2026] [security2:error] [pid 167459:tid 167630] [client 40.74.65.169:21331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/site.php"] [unique_id "aoSDkmr_JutbFb-8svoIVgAAAbg"] [Tue Aug 18 13:08:50.071996 2026] [security2:error] [pid 167459:tid 167690] [client 20.226.6.191:4174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/sf.php"] [unique_id "aoSDkmr_JutbFb-8svoIVwAAAfQ"] [Tue Aug 18 13:08:50.098132 2026] [security2:error] [pid 167459:tid 167663] [client 172.202.39.151:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDkmr_JutbFb-8svoIWAAAAdk"] [Tue Aug 18 13:08:50.105776 2026] [security2:error] [pid 167459:tid 167614] [client 20.1.169.243:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/10.php"] [unique_id "aoSDkmr_JutbFb-8svoIWQAAAag"] [Tue Aug 18 13:08:50.132812 2026] [security2:error] [pid 167459:tid 167672] [client 4.232.151.198:11288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/info.php"] [unique_id "aoSDkmr_JutbFb-8svoIWgAAAeI"] [Tue Aug 18 13:08:50.143179 2026] [security2:error] [pid 167459:tid 167608] [client 196.12.128.158:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIXQAAAaI"] [Tue Aug 18 13:08:50.143333 2026] [security2:error] [pid 167459:tid 167608] [client 196.12.128.158:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIXQAAAaI"] [Tue Aug 18 13:08:50.143712 2026] [authz_core:error] [pid 167459:tid 167521] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:50.143964 2026] [authz_core:error] [pid 167459:tid 167521] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:50.167589 2026] [security2:error] [pid 167459:tid 167660] [client 20.104.100.201:53303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDkmr_JutbFb-8svoIXgAAAdY"] [Tue Aug 18 13:08:50.178753 2026] [security2:error] [pid 167459:tid 167684] [client 158.23.17.4:38365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/37.php"] [unique_id "aoSDkmr_JutbFb-8svoIXwAAAe4"] [Tue Aug 18 13:08:50.216986 2026] [security2:error] [pid 167459:tid 167648] [client 20.226.6.191:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/index/function.php"] [unique_id "aoSDkmr_JutbFb-8svoIYAAAAco"] [Tue Aug 18 13:08:50.223043 2026] [security2:error] [pid 167459:tid 167627] [client 20.215.241.237:59763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/pema.php"] [unique_id "aoSDkmr_JutbFb-8svoIYQAAAbU"] [Tue Aug 18 13:08:50.225596 2026] [security2:error] [pid 167459:tid 167596] [client 20.25.139.174:4518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/sagax1.php"] [unique_id "aoSDkmr_JutbFb-8svoIYgAAAZY"] [Tue Aug 18 13:08:50.234859 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/bs1.php"] [unique_id "aoSDkmr_JutbFb-8svoIYwAAAgI"] [Tue Aug 18 13:08:50.239869 2026] [security2:error] [pid 167459:tid 167657] [client 68.155.154.236:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/dlvqo.php"] [unique_id "aoSDkmr_JutbFb-8svoIZQAAAdM"] [Tue Aug 18 13:08:50.239925 2026] [security2:error] [pid 167459:tid 167636] [client 20.79.204.6:5757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDkmr_JutbFb-8svoIZAAAAb4"] [Tue Aug 18 13:08:50.281800 2026] [security2:error] [pid 167459:tid 167642] [client 20.226.6.191:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/edit.php"] [unique_id "aoSDkmr_JutbFb-8svoIZwAAAcQ"] [Tue Aug 18 13:08:50.282779 2026] [security2:error] [pid 167459:tid 167625] [client 20.151.109.219:31718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/yg.php"] [unique_id "aoSDkmr_JutbFb-8svoIaAAAAbM"] [Tue Aug 18 13:08:50.284611 2026] [security2:error] [pid 167459:tid 167590] [client 20.1.169.243:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSDkmr_JutbFb-8svoIaQAAAZA"] [Tue Aug 18 13:08:50.288346 2026] [security2:error] [pid 167459:tid 167624] [client 172.182.217.32:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/uploads/angulu.php"] [unique_id "aoSDkmr_JutbFb-8svoIagAAAbI"] [Tue Aug 18 13:08:50.289974 2026] [security2:error] [pid 167459:tid 167592] [client 172.213.243.2:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/gec.php"] [unique_id "aoSDkmr_JutbFb-8svoIawAAAZI"] [Tue Aug 18 13:08:50.316348 2026] [security2:error] [pid 167459:tid 167686] [client 4.232.151.198:2328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wkl.php"] [unique_id "aoSDkmr_JutbFb-8svoIbQAAAfA"] [Tue Aug 18 13:08:50.354564 2026] [security2:error] [pid 167459:tid 167694] [client 20.226.6.191:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "aoSDkmr_JutbFb-8svoIbwAAAfg"] [Tue Aug 18 13:08:50.388367 2026] [security2:error] [pid 167459:tid 167667] [client 20.116.17.175:41517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-temp.php"] [unique_id "aoSDkmr_JutbFb-8svoIcAAAAd0"] [Tue Aug 18 13:08:50.396249 2026] [security2:error] [pid 167459:tid 167716] [client 213.35.127.232:51925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDkmr_JutbFb-8svoIcgAAAg4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:50.418208 2026] [security2:error] [pid 167459:tid 167633] [client 20.116.17.175:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/epinyins.php"] [unique_id "aoSDkmr_JutbFb-8svoIcwAAAbs"] [Tue Aug 18 13:08:50.446120 2026] [security2:error] [pid 167459:tid 167600] [client 20.226.6.191:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-good.php"] [unique_id "aoSDkmr_JutbFb-8svoIdwAAAZo"] [Tue Aug 18 13:08:50.447927 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:50.448189 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:50.469772 2026] [security2:error] [pid 167459:tid 167713] [client 20.1.169.243:8935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/13.php"] [unique_id "aoSDkmr_JutbFb-8svoIeAAAAgs"] [Tue Aug 18 13:08:50.491917 2026] [security2:error] [pid 167459:tid 167675] [client 158.23.17.4:7201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ri.php"] [unique_id "aoSDkmr_JutbFb-8svoIeQAAAeU"] [Tue Aug 18 13:08:50.509040 2026] [security2:error] [pid 167459:tid 167629] [client 158.158.74.177:13738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.74.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guiadorossi.com.br"] [uri "/license.php"] [unique_id "aoSDkmr_JutbFb-8svoIegAAAbc"] [Tue Aug 18 13:08:50.578067 2026] [security2:error] [pid 167459:tid 167634] [client 172.202.39.151:27898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIfAAAAbw"] [Tue Aug 18 13:08:50.596768 2026] [security2:error] [pid 167459:tid 167701] [client 158.23.17.4:44674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/md.php"] [unique_id "aoSDkmr_JutbFb-8svoIfwAAAf8"] [Tue Aug 18 13:08:50.600016 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:16313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/colors/blue/about.php"] [unique_id "aoSDkmr_JutbFb-8svoIgAAAAeE"] [Tue Aug 18 13:08:50.624399 2026] [security2:error] [pid 167459:tid 167662] [client 20.104.100.201:9566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-the.php"] [unique_id "aoSDkmr_JutbFb-8svoIggAAAdg"] [Tue Aug 18 13:08:50.639554 2026] [security2:error] [pid 167459:tid 167623] [client 20.226.6.191:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/tes.php"] [unique_id "aoSDkmr_JutbFb-8svoIgwAAAbE"] [Tue Aug 18 13:08:50.656584 2026] [security2:error] [pid 167459:tid 167598] [client 68.221.73.131:35897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/coffexium.php"] [unique_id "aoSDkmr_JutbFb-8svoIhAAAAZg"] [Tue Aug 18 13:08:50.659098 2026] [security2:error] [pid 167459:tid 167613] [client 20.1.169.243:10495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/test.php"] [unique_id "aoSDkmr_JutbFb-8svoIhgAAAac"] [Tue Aug 18 13:08:50.659879 2026] [security2:error] [pid 167459:tid 167681] [client 20.226.6.191:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/files/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIhwAAAes"] [Tue Aug 18 13:08:50.674497 2026] [security2:error] [pid 167459:tid 167630] [client 20.226.6.191:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIiAAAAbg"] [Tue Aug 18 13:08:50.697788 2026] [security2:error] [pid 167459:tid 167620] [client 20.215.241.237:34390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/sh.php"] [unique_id "aoSDkmr_JutbFb-8svoIiQAAAa4"] [Tue Aug 18 13:08:50.702773 2026] [security2:error] [pid 167459:tid 167688] [client 20.226.6.191:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/images/images/about.php"] [unique_id "aoSDkmr_JutbFb-8svoIigAAAfI"] [Tue Aug 18 13:08:50.716540 2026] [security2:error] [pid 167459:tid 167614] [client 20.226.6.191:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/ms-edit.php"] [unique_id "aoSDkmr_JutbFb-8svoIiwAAAag"] [Tue Aug 18 13:08:50.717490 2026] [security2:error] [pid 167459:tid 167672] [client 172.213.243.2:19524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/scx.php7"] [unique_id "aoSDkmr_JutbFb-8svoIjAAAAeI"] [Tue Aug 18 13:08:50.731491 2026] [security2:error] [pid 167459:tid 167699] [client 47.128.53.31:58460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "plasmeg.com.br"] [uri "/robots.txt"] [unique_id "aoSDkmr_JutbFb-8svoIjQAAAf0"] [Tue Aug 18 13:08:50.737209 2026] [security2:error] [pid 167459:tid 167660] [client 20.226.6.191:4117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/rip.php"] [unique_id "aoSDkmr_JutbFb-8svoIjgAAAdY"] [Tue Aug 18 13:08:50.748989 2026] [security2:error] [pid 167459:tid 167601] [client 74.248.18.37:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/xleet.php"] [unique_id "aoSDkmr_JutbFb-8svoIkAAAAZs"] [Tue Aug 18 13:08:50.750090 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:50.750352 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:50.768904 2026] [security2:error] [pid 167459:tid 167649] [client 20.226.6.191:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/xmlrpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIkgAAAcs"] [Tue Aug 18 13:08:50.772825 2026] [security2:error] [pid 167459:tid 167616] [client 158.23.17.4:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/87.php"] [unique_id "aoSDkmr_JutbFb-8svoIkwAAAao"] [Tue Aug 18 13:08:50.779417 2026] [security2:error] [pid 167459:tid 167645] [client 172.182.217.32:25645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/uploads/phUploader.php"] [unique_id "aoSDkmr_JutbFb-8svoIlAAAAcc"] [Tue Aug 18 13:08:50.782236 2026] [security2:error] [pid 167459:tid 167656] [client 52.173.121.69:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIlgAAAdI"] [Tue Aug 18 13:08:50.785249 2026] [security2:error] [pid 167459:tid 167703] [client 20.25.139.174:4432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIlwAAAgE"] [Tue Aug 18 13:08:50.802924 2026] [security2:error] [pid 167459:tid 167618] [client 20.171.51.14:36126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/va.php"] [unique_id "aoSDkmr_JutbFb-8svoImAAAAaw"] [Tue Aug 18 13:08:50.815496 2026] [security2:error] [pid 167459:tid 167509] [remote 129.121.103.155:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/wp-login.php"] [unique_id "aoSDkmr_JutbFb-8svoImQAB-zE"] [Tue Aug 18 13:08:50.822827 2026] [security2:error] [pid 167459:tid 167642] [client 20.226.6.191:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/moon.php"] [unique_id "aoSDkmr_JutbFb-8svoImwAAAcQ"] [Tue Aug 18 13:08:50.834512 2026] [security2:error] [pid 167459:tid 167663] [client 20.1.169.243:8901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/100.php"] [unique_id "aoSDkmr_JutbFb-8svoInAAAAdk"] [Tue Aug 18 13:08:50.842604 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:37431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDkmr_JutbFb-8svoIngAAAbI"] [Tue Aug 18 13:08:50.857545 2026] [security2:error] [pid 167459:tid 167592] [client 20.226.36.136:65289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDkmr_JutbFb-8svoInwAAAZI"] [Tue Aug 18 13:08:50.864565 2026] [security2:error] [pid 167459:tid 167605] [client 20.226.6.191:4216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/cache.php"] [unique_id "aoSDkmr_JutbFb-8svoIoAAAAZ8"] [Tue Aug 18 13:08:50.887763 2026] [security2:error] [pid 167459:tid 167677] [client 20.79.204.6:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSDkmr_JutbFb-8svoIpAAAAec"] [Tue Aug 18 13:08:50.946028 2026] [security2:error] [pid 167459:tid 167679] [client 20.104.100.201:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/dk.php"] [unique_id "aoSDkmr_JutbFb-8svoIqQAAAek"] [Tue Aug 18 13:08:50.960940 2026] [security2:error] [pid 167459:tid 167609] [client 49.145.211.146:10911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIqgAAAaM"] [Tue Aug 18 13:08:50.961076 2026] [security2:error] [pid 167459:tid 167609] [client 49.145.211.146:10911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDkmr_JutbFb-8svoIqgAAAaM"] [Tue Aug 18 13:08:50.969642 2026] [security2:error] [pid 167459:tid 167674] [client 20.1.169.243:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/con7.php"] [unique_id "aoSDkmr_JutbFb-8svoIqwAAAeQ"] [Tue Aug 18 13:08:50.992030 2026] [security2:error] [pid 167459:tid 167655] [client 20.226.6.191:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDkmr_JutbFb-8svoIrAAAAdE"] [Tue Aug 18 13:08:51.029405 2026] [security2:error] [pid 167459:tid 167628] [client 20.151.109.219:20934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/et.php"] [unique_id "aoSDk2r_JutbFb-8svoIrQAAAbY"] [Tue Aug 18 13:08:51.031182 2026] [security2:error] [pid 167459:tid 167694] [client 20.1.169.243:10471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSDk2r_JutbFb-8svoIrgAAAfg"] [Tue Aug 18 13:08:51.040233 2026] [security2:error] [pid 167459:tid 167640] [client 20.116.17.175:41523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-css.php"] [unique_id "aoSDk2r_JutbFb-8svoIrwAAAcI"] [Tue Aug 18 13:08:51.047409 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:51.047669 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:51.094077 2026] [security2:error] [pid 167459:tid 167610] [client 158.23.17.4:5046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/iy.php"] [unique_id "aoSDk2r_JutbFb-8svoIswAAAaQ"] [Tue Aug 18 13:08:51.129192 2026] [security2:error] [pid 167459:tid 167637] [client 20.127.136.245:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/atomlib.php"] [unique_id "aoSDk2r_JutbFb-8svoItAAAAb8"] [Tue Aug 18 13:08:51.134350 2026] [security2:error] [pid 167459:tid 167634] [client 172.213.243.2:18586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-admin/sc.php"] [unique_id "aoSDk2r_JutbFb-8svoItgAAAbw"] [Tue Aug 18 13:08:51.151150 2026] [security2:error] [pid 167459:tid 167701] [client 20.226.6.191:4288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-mail.php"] [unique_id "aoSDk2r_JutbFb-8svoItwAAAf8"] [Tue Aug 18 13:08:51.190978 2026] [security2:error] [pid 167459:tid 167708] [client 20.215.241.237:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/button.php"] [unique_id "aoSDk2r_JutbFb-8svoIuQAAAgY"] [Tue Aug 18 13:08:51.213831 2026] [security2:error] [pid 167459:tid 167623] [client 20.226.6.191:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/o.php"] [unique_id "aoSDk2r_JutbFb-8svoIugAAAbE"] [Tue Aug 18 13:08:51.219703 2026] [security2:error] [pid 167459:tid 167638] [client 4.232.151.198:42130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/a.php"] [unique_id "aoSDk2r_JutbFb-8svoIuwAAAcA"] [Tue Aug 18 13:08:51.231575 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:8932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/222.php"] [unique_id "aoSDk2r_JutbFb-8svoIvAAAAgQ"] [Tue Aug 18 13:08:51.240131 2026] [security2:error] [pid 167459:tid 167594] [client 172.202.39.151:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDk2r_JutbFb-8svoIvgAAAZQ"] [Tue Aug 18 13:08:51.252108 2026] [security2:error] [pid 167459:tid 167707] [client 52.173.121.69:28300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDk2r_JutbFb-8svoIvwAAAgU"] [Tue Aug 18 13:08:51.257510 2026] [security2:error] [pid 167459:tid 167622] [client 4.232.151.198:2331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/work.php"] [unique_id "aoSDk2r_JutbFb-8svoIwAAAAbA"] [Tue Aug 18 13:08:51.267936 2026] [security2:error] [pid 167459:tid 167643] [client 172.182.217.32:4066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/woh.php"] [unique_id "aoSDk2r_JutbFb-8svoIwgAAAcU"] [Tue Aug 18 13:08:51.318133 2026] [security2:error] [pid 167459:tid 167696] [client 20.25.139.174:4325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/fone1.php"] [unique_id "aoSDk2r_JutbFb-8svoIwwAAAfo"] [Tue Aug 18 13:08:51.322945 2026] [security2:error] [pid 167459:tid 167615] [client 20.104.100.201:9590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDk2r_JutbFb-8svoIxAAAAak"] [Tue Aug 18 13:08:51.332552 2026] [security2:error] [pid 167459:tid 167700] [client 20.1.169.243:5814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/contact-form-7/includes/js/jquery-ui/themes/smoothness/RxRywmgzyK.php"] [unique_id "aoSDk2r_JutbFb-8svoIxQAAAf4"] [Tue Aug 18 13:08:51.352709 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:51.352977 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:51.380904 2026] [security2:error] [pid 167459:tid 167688] [client 158.23.17.4:15776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/tp.php"] [unique_id "aoSDk2r_JutbFb-8svoIxwAAAfI"] [Tue Aug 18 13:08:51.407919 2026] [security2:error] [pid 167459:tid 167714] [client 20.1.169.243:10461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSDk2r_JutbFb-8svoIyAAAAgw"] [Tue Aug 18 13:08:51.415374 2026] [security2:error] [pid 167459:tid 167675] [client 213.35.127.232:52171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDk2r_JutbFb-8svoIyQAAAeU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:51.489907 2026] [security2:error] [pid 167459:tid 167626] [client 20.250.13.23:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSDk2r_JutbFb-8svoIywAAAbQ"] [Tue Aug 18 13:08:51.507808 2026] [security2:error] [pid 167459:tid 167711] [client 20.79.204.6:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-config.php"] [unique_id "aoSDk2r_JutbFb-8svoIzQAAAgk"] [Tue Aug 18 13:08:51.509443 2026] [security2:error] [pid 167459:tid 167492] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDk2r_JutbFb-8svoIzAAB2CA"] [Tue Aug 18 13:08:51.509642 2026] [security2:error] [pid 167459:tid 167662] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDk2r_JutbFb-8svoIzAAB2CA"] [Tue Aug 18 13:08:51.553029 2026] [security2:error] [pid 167459:tid 167590] [client 20.226.6.191:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/bb.php"] [unique_id "aoSDk2r_JutbFb-8svoIzwAAAZA"] [Tue Aug 18 13:08:51.561452 2026] [security2:error] [pid 167459:tid 167687] [client 20.151.109.219:49682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/of.php"] [unique_id "aoSDk2r_JutbFb-8svoI0AAAAfE"] [Tue Aug 18 13:08:51.566804 2026] [security2:error] [pid 167459:tid 167685] [client 172.213.243.2:18594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp5.php"] [unique_id "aoSDk2r_JutbFb-8svoI0QAAAe8"] [Tue Aug 18 13:08:51.579347 2026] [security2:error] [pid 167459:tid 167605] [client 158.23.17.4:63021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/zi.php"] [unique_id "aoSDk2r_JutbFb-8svoI0gAAAZ8"] [Tue Aug 18 13:08:51.580823 2026] [security2:error] [pid 167459:tid 167603] [client 40.74.65.169:36949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/cabs.php"] [unique_id "aoSDk2r_JutbFb-8svoI0wAAAZ0"] [Tue Aug 18 13:08:51.595085 2026] [security2:error] [pid 167459:tid 167677] [client 191.237.254.161:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDk2r_JutbFb-8svoI1AAAAec"] [Tue Aug 18 13:08:51.595988 2026] [security2:error] [pid 167459:tid 167649] [client 20.1.169.243:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDk2r_JutbFb-8svoI1QAAAcs"] [Tue Aug 18 13:08:51.614442 2026] [security2:error] [pid 167459:tid 167625] [client 20.215.241.237:27687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/wlc.php"] [unique_id "aoSDk2r_JutbFb-8svoI1gAAAbM"] [Tue Aug 18 13:08:51.630510 2026] [security2:error] [pid 167459:tid 167710] [client 20.226.6.191:4209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "aoSDk2r_JutbFb-8svoI2AAAAgg"] [Tue Aug 18 13:08:51.642754 2026] [security2:error] [pid 167459:tid 167589] [client 52.173.121.69:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI2gAAAY8"] [Tue Aug 18 13:08:51.651162 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:51.651595 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:51.661250 2026] [security2:error] [pid 167459:tid 167670] [client 20.116.17.175:45343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/flox.php"] [unique_id "aoSDk2r_JutbFb-8svoI2wAAAeA"] [Tue Aug 18 13:08:51.697525 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/dist/alfa-rex.php"] [unique_id "aoSDk2r_JutbFb-8svoI3AAAAfA"] [Tue Aug 18 13:08:51.703975 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/load.php"] [unique_id "aoSDk2r_JutbFb-8svoI3QAAAeM"] [Tue Aug 18 13:08:51.725305 2026] [security2:error] [pid 167459:tid 167595] [client 20.226.6.191:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI3wAAAZU"] [Tue Aug 18 13:08:51.753758 2026] [security2:error] [pid 167459:tid 167689] [client 20.226.6.191:4141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/xmrlpc.php"] [unique_id "aoSDk2r_JutbFb-8svoI4AAAAfM"] [Tue Aug 18 13:08:51.765708 2026] [security2:error] [pid 167459:tid 167610] [client 20.104.100.201:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/xwpg.php"] [unique_id "aoSDk2r_JutbFb-8svoI4gAAAaQ"] [Tue Aug 18 13:08:51.767889 2026] [security2:error] [pid 167459:tid 167593] [client 20.226.6.191:4221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/file.php"] [unique_id "aoSDk2r_JutbFb-8svoI5AAAAZM"] [Tue Aug 18 13:08:51.803799 2026] [security2:error] [pid 167459:tid 167701] [client 20.226.6.191:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/epinyins.php"] [unique_id "aoSDk2r_JutbFb-8svoI5wAAAf8"] [Tue Aug 18 13:08:51.816465 2026] [security2:error] [pid 167459:tid 167667] [client 20.1.169.243:10479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSDk2r_JutbFb-8svoI6QAAAd0"] [Tue Aug 18 13:08:51.818520 2026] [security2:error] [pid 167459:tid 167671] [client 20.226.36.136:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDk2r_JutbFb-8svoI6gAAAeE"] [Tue Aug 18 13:08:51.830602 2026] [security2:error] [pid 167459:tid 167609] [client 104.222.31.70:58930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.31.222.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com.br"] [uri "/pandora_console/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI7AAAAaM"] [Tue Aug 18 13:08:51.838370 2026] [security2:error] [pid 167459:tid 167633] [client 104.222.31.70:58952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "fbenevides.com"] [uri "/pandora_console/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI7QAAAbs"] [Tue Aug 18 13:08:51.843203 2026] [security2:error] [pid 167459:tid 167661] [client 191.237.254.161:36376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDk2r_JutbFb-8svoI7gAAAdc"] [Tue Aug 18 13:08:51.847151 2026] [security2:error] [pid 167459:tid 167622] [client 172.202.39.151:39168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/file.php"] [unique_id "aoSDk2r_JutbFb-8svoI7wAAAbA"] [Tue Aug 18 13:08:51.869512 2026] [security2:error] [pid 167459:tid 167643] [client 158.23.17.4:20652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/og.php"] [unique_id "aoSDk2r_JutbFb-8svoI8AAAAcU"] [Tue Aug 18 13:08:51.876782 2026] [security2:error] [pid 167459:tid 167607] [client 20.226.6.191:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI8QAAAaE"] [Tue Aug 18 13:08:51.884666 2026] [security2:error] [pid 167459:tid 167641] [client 20.25.139.174:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ncx.php"] [unique_id "aoSDk2r_JutbFb-8svoI8gAAAcM"] [Tue Aug 18 13:08:51.910954 2026] [autoindex:error] [pid 167459:tid 167681] [client 189.5.11.234:39089] AH01276: Cannot serve directory /home4/lavora68/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:51.914860 2026] [security2:error] [pid 167459:tid 167628] [client 4.232.151.198:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/worksec.php"] [unique_id "aoSDk2r_JutbFb-8svoI-AAAAbY"] [Tue Aug 18 13:08:51.961791 2026] [security2:error] [pid 167459:tid 167598] [client 20.1.169.243:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/abcd.php"] [unique_id "aoSDk2r_JutbFb-8svoI-gAAAZg"] [Tue Aug 18 13:08:51.987057 2026] [security2:error] [pid 167459:tid 167709] [client 20.226.6.191:4198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDk2r_JutbFb-8svoI_AAAAgc"] [Tue Aug 18 13:08:51.998127 2026] [autoindex:error] [pid 167459:tid 167601] [client 189.5.11.234:34699] AH01276: Cannot serve directory /home4/lavora68/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:52.018383 2026] [security2:error] [pid 167459:tid 167645] [client 68.155.154.236:27536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/pkmoj.php"] [unique_id "aoSDlGr_JutbFb-8svoI_wAAAcc"] [Tue Aug 18 13:08:52.020459 2026] [security2:error] [pid 167459:tid 167657] [client 191.237.254.161:44728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/media.php"] [unique_id "aoSDlGr_JutbFb-8svoJAAAAAdM"] [Tue Aug 18 13:08:52.037110 2026] [security2:error] [pid 167459:tid 167618] [client 20.215.241.237:46343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/fi.php"] [unique_id "aoSDlGr_JutbFb-8svoJAQAAAaw"] [Tue Aug 18 13:08:52.051666 2026] [security2:error] [pid 167459:tid 167590] [client 74.248.133.44:28588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDlGr_JutbFb-8svoJBAAAAZA"] [Tue Aug 18 13:08:52.056042 2026] [security2:error] [pid 167459:tid 167624] [client 20.104.100.201:9477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/dex.php"] [unique_id "aoSDlGr_JutbFb-8svoJBQAAAbI"] [Tue Aug 18 13:08:52.056919 2026] [security2:error] [pid 167459:tid 167687] [client 20.226.6.191:4146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDlGr_JutbFb-8svoJBgAAAfE"] [Tue Aug 18 13:08:52.076983 2026] [security2:error] [pid 167459:tid 167714] [client 20.1.169.243:16260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/elementor/wp-login.php"] [unique_id "aoSDlGr_JutbFb-8svoJBwAAAgw"] [Tue Aug 18 13:08:52.107099 2026] [security2:error] [pid 167459:tid 167712] [client 20.250.13.23:23056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJCAAAAgo"] [Tue Aug 18 13:08:52.122716 2026] [security2:error] [pid 167459:tid 167670] [client 172.213.243.2:19772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/a2.php"] [unique_id "aoSDlGr_JutbFb-8svoJCQAAAeA"] [Tue Aug 18 13:08:52.147620 2026] [security2:error] [pid 167459:tid 167680] [client 20.226.6.191:4193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp.php"] [unique_id "aoSDlGr_JutbFb-8svoJCgAAAeo"] [Tue Aug 18 13:08:52.165225 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:22694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/op.php"] [unique_id "aoSDlGr_JutbFb-8svoJCwAAAeM"] [Tue Aug 18 13:08:52.174791 2026] [security2:error] [pid 167459:tid 167694] [client 20.226.6.191:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/function/function.php"] [unique_id "aoSDlGr_JutbFb-8svoJDAAAAfg"] [Tue Aug 18 13:08:52.191764 2026] [security2:error] [pid 167459:tid 167595] [client 52.173.121.69:50036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDlGr_JutbFb-8svoJDQAAAZU"] [Tue Aug 18 13:08:52.194530 2026] [security2:error] [pid 167459:tid 167649] [client 20.1.169.243:10470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-login.php"] [unique_id "aoSDlGr_JutbFb-8svoJDgAAAcs"] [Tue Aug 18 13:08:52.204108 2026] [security2:error] [pid 167459:tid 167684] [client 20.79.204.6:5663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDlGr_JutbFb-8svoJDwAAAe4"] [Tue Aug 18 13:08:52.204627 2026] [security2:error] [pid 167459:tid 167612] [client 43.172.194.204:54652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.194.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "siderurgiabrasil.com.br"] [uri "/wp-content/ajax-handler.php"] [unique_id "aoSDlGr_JutbFb-8svoJAgAAAaY"], referer: http://siderurgiabrasil.com.br/2022/06/10/projetos-de-reaproveitamento-de-agua-do-brasil/ [Tue Aug 18 13:08:52.251908 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:52.252156 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:52.253491 2026] [security2:error] [pid 167459:tid 167701] [client 158.23.17.4:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/zj.php"] [unique_id "aoSDlGr_JutbFb-8svoJEgAAAf8"] [Tue Aug 18 13:08:52.267082 2026] [autoindex:error] [pid 167459:tid 167610] [client 189.5.11.234:41389] AH01276: Cannot serve directory /home4/lavora68/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:52.274520 2026] [security2:error] [pid 167459:tid 167597] [client 49.37.150.8:23114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJFQAAAZc"] [Tue Aug 18 13:08:52.274612 2026] [security2:error] [pid 167459:tid 167597] [client 49.37.150.8:23114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJFQAAAZc"] [Tue Aug 18 13:08:52.280921 2026] [security2:error] [pid 167459:tid 167671] [client 20.226.6.191:4201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDlGr_JutbFb-8svoJFgAAAeE"] [Tue Aug 18 13:08:52.349605 2026] [autoindex:error] [pid 167459:tid 167661] [client 189.5.11.234:51335] AH01276: Cannot serve directory /home4/lavora68/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:08:52.358019 2026] [security2:error] [pid 167459:tid 167589] [client 74.248.18.37:48254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp.php"] [unique_id "aoSDlGr_JutbFb-8svoJHgAAAY8"] [Tue Aug 18 13:08:52.367370 2026] [security2:error] [pid 167459:tid 167593] [client 20.1.169.243:8906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/al.php"] [unique_id "aoSDlGr_JutbFb-8svoJHwAAAZM"] [Tue Aug 18 13:08:52.375779 2026] [security2:error] [pid 167459:tid 167702] [client 20.104.100.201:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/xyn.php"] [unique_id "aoSDlGr_JutbFb-8svoJIgAAAgA"] [Tue Aug 18 13:08:52.376845 2026] [security2:error] [pid 167459:tid 167658] [client 40.74.65.169:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/insc.php"] [unique_id "aoSDlGr_JutbFb-8svoJJAAAAdQ"] [Tue Aug 18 13:08:52.388621 2026] [security2:error] [pid 167459:tid 167700] [client 20.116.17.175:52871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDlGr_JutbFb-8svoJJQAAAf4"] [Tue Aug 18 13:08:52.399655 2026] [security2:error] [pid 167459:tid 167696] [client 158.23.17.4:38360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lp.php"] [unique_id "aoSDlGr_JutbFb-8svoJKAAAAfo"] [Tue Aug 18 13:08:52.433375 2026] [security2:error] [pid 167459:tid 167710] [client 213.35.127.232:52383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDlGr_JutbFb-8svoJKQAAAgg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:52.459194 2026] [security2:error] [pid 167459:tid 167631] [client 20.25.139.174:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDlGr_JutbFb-8svoJLAAAAbk"] [Tue Aug 18 13:08:52.467899 2026] [security2:error] [pid 167459:tid 167672] [client 20.215.241.237:2999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/chris.php"] [unique_id "aoSDlGr_JutbFb-8svoJLgAAAeI"] [Tue Aug 18 13:08:52.488345 2026] [security2:error] [pid 167459:tid 167676] [client 20.226.6.191:4284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDlGr_JutbFb-8svoJLwAAAeY"] [Tue Aug 18 13:08:52.490217 2026] [security2:error] [pid 167459:tid 167692] [client 20.104.100.201:13909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/bal.php"] [unique_id "aoSDlGr_JutbFb-8svoJMAAAAfY"] [Tue Aug 18 13:08:52.511253 2026] [security2:error] [pid 167459:tid 167601] [client 191.237.254.161:44723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/admin.php"] [unique_id "aoSDlGr_JutbFb-8svoJMQAAAZs"] [Tue Aug 18 13:08:52.514205 2026] [security2:error] [pid 167459:tid 167682] [client 213.202.253.4:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/filefuns.php"] [unique_id "aoSDlGr_JutbFb-8svoJMgAAAew"], referer: www.google.com [Tue Aug 18 13:08:52.530075 2026] [security2:error] [pid 167459:tid 167662] [client 20.226.6.191:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/ok.php"] [unique_id "aoSDlGr_JutbFb-8svoJMwAAAdg"] [Tue Aug 18 13:08:52.533975 2026] [security2:error] [pid 167459:tid 167704] [client 172.213.243.2:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/app.php"] [unique_id "aoSDlGr_JutbFb-8svoJNAAAAgI"] [Tue Aug 18 13:08:52.554124 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:52.554428 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:52.562517 2026] [security2:error] [pid 167459:tid 167590] [client 20.127.136.245:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/min.php"] [unique_id "aoSDlGr_JutbFb-8svoJNwAAAZA"] [Tue Aug 18 13:08:52.567956 2026] [security2:error] [pid 167459:tid 167624] [client 20.1.169.243:5801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/goat1.php"] [unique_id "aoSDlGr_JutbFb-8svoJOAAAAbI"] [Tue Aug 18 13:08:52.569433 2026] [security2:error] [pid 167459:tid 167687] [client 20.226.6.191:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.6.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.classeamotel.com"] [uri "/item.php"] [unique_id "aoSDlGr_JutbFb-8svoJOQAAAfE"] [Tue Aug 18 13:08:52.575460 2026] [security2:error] [pid 167459:tid 167675] [client 20.1.169.243:10467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSDlGr_JutbFb-8svoJOgAAAeU"] [Tue Aug 18 13:08:52.602058 2026] [security2:error] [pid 167459:tid 167603] [client 191.237.254.161:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/mac.php"] [unique_id "aoSDlGr_JutbFb-8svoJPAAAAZ0"] [Tue Aug 18 13:08:52.603802 2026] [security2:error] [pid 167459:tid 167603] [client 20.116.17.175:41474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDlGr_JutbFb-8svoJPQAAAZ0"] [Tue Aug 18 13:08:52.604145 2026] [security2:error] [pid 167459:tid 167580] [remote 162.214.205.212:58986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-login.php"] [unique_id "aoSDlGr_JutbFb-8svoJPgACAXg"] [Tue Aug 18 13:08:52.604638 2026] [security2:error] [pid 167459:tid 167615] [client 37.40.227.74:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.227.40.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJPwAAAak"] [Tue Aug 18 13:08:52.604752 2026] [security2:error] [pid 167459:tid 167615] [client 37.40.227.74:56938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scaclinic.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJPwAAAak"] [Tue Aug 18 13:08:52.607632 2026] [security2:error] [pid 167459:tid 167625] [client 20.226.36.136:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDlGr_JutbFb-8svoJQAAAAbM"] [Tue Aug 18 13:08:52.629916 2026] [security2:error] [pid 167459:tid 167681] [client 4.232.151.198:2349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-activate.php"] [unique_id "aoSDlGr_JutbFb-8svoJQQAAAes"] [Tue Aug 18 13:08:52.638322 2026] [security2:error] [pid 167459:tid 167660] [client 5.31.227.224:30419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJQwAAAdY"] [Tue Aug 18 13:08:52.640961 2026] [security2:error] [pid 167459:tid 167651] [client 172.202.39.151:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/epinyins.php"] [unique_id "aoSDlGr_JutbFb-8svoJRAAAAc0"] [Tue Aug 18 13:08:52.643363 2026] [security2:error] [pid 167459:tid 167660] [client 5.31.227.224:30419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJQwAAAdY"] [Tue Aug 18 13:08:52.698289 2026] [security2:error] [pid 167459:tid 167649] [client 74.249.206.207:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/sf.php"] [unique_id "aoSDlGr_JutbFb-8svoJRgAAAcs"] [Tue Aug 18 13:08:52.706255 2026] [security2:error] [pid 167459:tid 167678] [client 86.120.159.145:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJRwAAAeg"] [Tue Aug 18 13:08:52.706433 2026] [security2:error] [pid 167459:tid 167678] [client 86.120.159.145:24839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJRwAAAeg"] [Tue Aug 18 13:08:52.722874 2026] [security2:error] [pid 167459:tid 167650] [client 191.237.254.161:36396] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mhost.com.br"] [uri "/1.php"] [unique_id "aoSDlGr_JutbFb-8svoJSAAAAcw"] [Tue Aug 18 13:08:52.722992 2026] [security2:error] [pid 167459:tid 167650] [client 191.237.254.161:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/1.php"] [unique_id "aoSDlGr_JutbFb-8svoJSAAAAcw"] [Tue Aug 18 13:08:52.725463 2026] [security2:error] [pid 167459:tid 167711] [client 20.250.13.23:5677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSDlGr_JutbFb-8svoJSQAAAgk"] [Tue Aug 18 13:08:52.730509 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:9546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/alfa.php"] [unique_id "aoSDlGr_JutbFb-8svoJSgAAAgo"] [Tue Aug 18 13:08:52.762945 2026] [security2:error] [pid 167459:tid 167637] [client 191.237.254.161:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/coffee.php"] [unique_id "aoSDlGr_JutbFb-8svoJTAAAAb8"] [Tue Aug 18 13:08:52.838586 2026] [security2:error] [pid 167459:tid 167671] [client 52.173.121.69:28337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDlGr_JutbFb-8svoJTgAAAeE"] [Tue Aug 18 13:08:52.851806 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:52.852094 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:52.858228 2026] [security2:error] [pid 167459:tid 167617] [client 191.237.254.161:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDlGr_JutbFb-8svoJUAAAAas"] [Tue Aug 18 13:08:52.860734 2026] [security2:error] [pid 167459:tid 167604] [client 103.120.71.157:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJUQAAAZ4"] [Tue Aug 18 13:08:52.860844 2026] [security2:error] [pid 167459:tid 167604] [client 103.120.71.157:52364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlGr_JutbFb-8svoJUQAAAZ4"] [Tue Aug 18 13:08:52.877191 2026] [security2:error] [pid 167459:tid 167640] [client 20.79.204.6:5979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-content.php"] [unique_id "aoSDlGr_JutbFb-8svoJUgAAAcI"] [Tue Aug 18 13:08:52.891893 2026] [security2:error] [pid 167459:tid 167622] [client 191.237.254.161:6582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDlGr_JutbFb-8svoJUwAAAbA"] [Tue Aug 18 13:08:52.911172 2026] [security2:error] [pid 167459:tid 167658] [client 20.215.241.237:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/doc.php"] [unique_id "aoSDlGr_JutbFb-8svoJVAAAAdQ"] [Tue Aug 18 13:08:52.933422 2026] [security2:error] [pid 167459:tid 167636] [client 20.1.169.243:5315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/google-seo-rank/module.php"] [unique_id "aoSDlGr_JutbFb-8svoJVgAAAb4"] [Tue Aug 18 13:08:52.936269 2026] [security2:error] [pid 167459:tid 167696] [client 191.237.254.161:28176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/yj09.php"] [unique_id "aoSDlGr_JutbFb-8svoJVwAAAfo"] [Tue Aug 18 13:08:52.946273 2026] [security2:error] [pid 167459:tid 167674] [client 191.237.254.161:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/scxy.php"] [unique_id "aoSDlGr_JutbFb-8svoJWAAAAeQ"] [Tue Aug 18 13:08:52.976450 2026] [security2:error] [pid 167459:tid 167610] [client 20.1.169.243:10457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSDlGr_JutbFb-8svoJWgAAAaQ"] [Tue Aug 18 13:08:52.996335 2026] [security2:error] [pid 167459:tid 167633] [client 20.116.17.175:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/txets.php"] [unique_id "aoSDlGr_JutbFb-8svoJXAAAAbs"] [Tue Aug 18 13:08:53.038404 2026] [security2:error] [pid 167459:tid 167623] [client 20.25.139.174:4329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wso.php"] [unique_id "aoSDlWr_JutbFb-8svoJXwAAAbE"] [Tue Aug 18 13:08:53.043337 2026] [security2:error] [pid 167459:tid 167709] [client 20.100.169.31:17911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDlWr_JutbFb-8svoJYQAAAgc"] [Tue Aug 18 13:08:53.093644 2026] [security2:error] [pid 167459:tid 167669] [client 20.1.169.243:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/as.php"] [unique_id "aoSDlWr_JutbFb-8svoJYgAAAd8"] [Tue Aug 18 13:08:53.114107 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/92.php"] [unique_id "aoSDlWr_JutbFb-8svoJZAAAAcc"] [Tue Aug 18 13:08:53.154803 2026] [security2:error] [pid 167459:tid 167590] [client 158.23.17.4:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ey.php"] [unique_id "aoSDlWr_JutbFb-8svoJZgAAAZA"] [Tue Aug 18 13:08:53.157767 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:53.158219 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:53.158797 2026] [security2:error] [pid 167459:tid 167624] [client 191.237.254.161:36563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDlWr_JutbFb-8svoJZwAAAbI"] [Tue Aug 18 13:08:53.163481 2026] [security2:error] [pid 167459:tid 167641] [client 74.248.133.44:12655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/storage/rip.php"] [unique_id "aoSDlWr_JutbFb-8svoJaAAAAcM"] [Tue Aug 18 13:08:53.172550 2026] [security2:error] [pid 167459:tid 167687] [client 172.213.243.2:14451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-content/admin.php"] [unique_id "aoSDlWr_JutbFb-8svoJaQAAAfE"] [Tue Aug 18 13:08:53.193973 2026] [security2:error] [pid 167459:tid 167714] [client 20.104.100.201:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDlWr_JutbFb-8svoJagAAAgw"] [Tue Aug 18 13:08:53.196191 2026] [security2:error] [pid 167459:tid 167603] [client 191.237.254.161:2822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDlWr_JutbFb-8svoJbAAAAZ0"] [Tue Aug 18 13:08:53.232491 2026] [security2:error] [pid 167459:tid 167679] [client 40.74.65.169:7063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/file.php"] [unique_id "aoSDlWr_JutbFb-8svoJbQAAAek"] [Tue Aug 18 13:08:53.296016 2026] [security2:error] [pid 167459:tid 167675] [client 20.1.169.243:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/h.php"] [unique_id "aoSDlWr_JutbFb-8svoJcAAAAeU"] [Tue Aug 18 13:08:53.303299 2026] [security2:error] [pid 167459:tid 167635] [client 20.116.17.175:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ty.php"] [unique_id "aoSDlWr_JutbFb-8svoJcQAAAb0"] [Tue Aug 18 13:08:53.321941 2026] [security2:error] [pid 167459:tid 167600] [client 20.250.13.23:23087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSDlWr_JutbFb-8svoJdAAAAZo"] [Tue Aug 18 13:08:53.330040 2026] [security2:error] [pid 167459:tid 167595] [client 20.151.109.219:46533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/bu.php"] [unique_id "aoSDlWr_JutbFb-8svoJdgAAAZU"] [Tue Aug 18 13:08:53.331334 2026] [security2:error] [pid 167459:tid 167611] [client 191.237.254.161:23894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/blurbs.php"] [unique_id "aoSDlWr_JutbFb-8svoJdwAAAaU"] [Tue Aug 18 13:08:53.334297 2026] [security2:error] [pid 167459:tid 167649] [client 20.226.36.136:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDlWr_JutbFb-8svoJeAAAAcs"] [Tue Aug 18 13:08:53.347930 2026] [security2:error] [pid 167459:tid 167618] [client 20.250.13.23:23052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/st.php"] [unique_id "aoSDlWr_JutbFb-8svoJeQAAAaw"] [Tue Aug 18 13:08:53.367265 2026] [security2:error] [pid 167459:tid 167657] [client 4.232.151.198:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin.php"] [unique_id "aoSDlWr_JutbFb-8svoJewAAAdM"] [Tue Aug 18 13:08:53.395427 2026] [security2:error] [pid 167459:tid 167683] [client 191.237.254.161:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/bajah.php"] [unique_id "aoSDlWr_JutbFb-8svoJfQAAAe0"] [Tue Aug 18 13:08:53.412740 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:10469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/002.php"] [unique_id "aoSDlWr_JutbFb-8svoJfgAAAfA"] [Tue Aug 18 13:08:53.423355 2026] [security2:error] [pid 167459:tid 167627] [client 20.215.241.237:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/1337.php"] [unique_id "aoSDlWr_JutbFb-8svoJfwAAAbU"] [Tue Aug 18 13:08:53.428379 2026] [security2:error] [pid 167459:tid 167608] [client 191.237.254.161:2870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/domvf.php"] [unique_id "aoSDlWr_JutbFb-8svoJgAAAAaI"] [Tue Aug 18 13:08:53.445943 2026] [security2:error] [pid 167459:tid 167704] [client 213.35.127.232:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDlWr_JutbFb-8svoJggAAAgI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:53.459154 2026] [security2:error] [pid 167459:tid 167597] [client 191.237.254.161:6588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/fpwch.php"] [unique_id "aoSDlWr_JutbFb-8svoJhQAAAZc"] [Tue Aug 18 13:08:53.469088 2026] [security2:error] [pid 167459:tid 167654] [client 172.182.217.32:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDlWr_JutbFb-8svoJhwAAAdA"] [Tue Aug 18 13:08:53.475073 2026] [security2:error] [pid 167459:tid 167664] [client 45.92.229.94:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSDlWr_JutbFb-8svoJcgAAAdo"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:08:53.479048 2026] [security2:error] [pid 167459:tid 167708] [client 191.237.254.161:29853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/adminner.php"] [unique_id "aoSDlWr_JutbFb-8svoJiAAAAgY"] [Tue Aug 18 13:08:53.480822 2026] [security2:error] [pid 167459:tid 167609] [client 158.23.17.4:47679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/x.php"] [unique_id "aoSDlWr_JutbFb-8svoJiQAAAaM"] [Tue Aug 18 13:08:53.484932 2026] [security2:error] [pid 167459:tid 167706] [client 172.202.39.151:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDlWr_JutbFb-8svoJigAAAgQ"] [Tue Aug 18 13:08:53.489182 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:8841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/aa.php"] [unique_id "aoSDlWr_JutbFb-8svoJjAAAAgo"] [Tue Aug 18 13:08:53.497001 2026] [security2:error] [pid 167459:tid 167640] [client 191.237.254.161:2825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/abcd.php"] [unique_id "aoSDlWr_JutbFb-8svoJjQAAAcI"] [Tue Aug 18 13:08:53.519968 2026] [security2:error] [pid 167459:tid 167661] [client 191.237.254.161:2825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/simple.php"] [unique_id "aoSDlWr_JutbFb-8svoJjgAAAdc"] [Tue Aug 18 13:08:53.532479 2026] [security2:error] [pid 167459:tid 167658] [client 191.237.254.161:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDlWr_JutbFb-8svoJjwAAAdQ"] [Tue Aug 18 13:08:53.559396 2026] [security2:error] [pid 167459:tid 167663] [client 191.237.254.161:2845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/xiugai.php"] [unique_id "aoSDlWr_JutbFb-8svoJkQAAAdk"] [Tue Aug 18 13:08:53.589530 2026] [security2:error] [pid 167459:tid 167666] [client 172.213.243.2:14394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/cxc.php"] [unique_id "aoSDlWr_JutbFb-8svoJkwAAAdw"] [Tue Aug 18 13:08:53.597422 2026] [security2:error] [pid 167459:tid 167629] [client 20.25.139.174:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/zup.php73"] [unique_id "aoSDlWr_JutbFb-8svoJlAAAAbc"] [Tue Aug 18 13:08:53.603301 2026] [security2:error] [pid 167459:tid 167614] [client 191.237.254.161:36553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/wp-load.php"] [unique_id "aoSDlWr_JutbFb-8svoJlQAAAag"] [Tue Aug 18 13:08:53.609384 2026] [security2:error] [pid 167459:tid 167633] [client 20.104.100.201:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-good.php"] [unique_id "aoSDlWr_JutbFb-8svoJlgAAAbs"] [Tue Aug 18 13:08:53.624758 2026] [security2:error] [pid 167459:tid 167699] [client 191.237.254.161:23872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/155.php"] [unique_id "aoSDlWr_JutbFb-8svoJlwAAAf0"] [Tue Aug 18 13:08:53.659111 2026] [security2:error] [pid 167459:tid 167596] [client 4.232.151.198:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/chosen.php"] [unique_id "aoSDlWr_JutbFb-8svoJmQAAAZY"] [Tue Aug 18 13:08:53.660277 2026] [security2:error] [pid 167459:tid 167636] [client 20.1.169.243:16296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/import/csv1.php"] [unique_id "aoSDlWr_JutbFb-8svoJmgAAAb4"] [Tue Aug 18 13:08:53.660765 2026] [security2:error] [pid 167459:tid 167601] [client 191.237.254.161:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/index.php"] [unique_id "aoSDlWr_JutbFb-8svoJmwAAAZs"] [Tue Aug 18 13:08:53.674385 2026] [security2:error] [pid 167459:tid 167677] [client 20.100.169.31:2903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/0x.php"] [unique_id "aoSDlWr_JutbFb-8svoJnAAAAec"] [Tue Aug 18 13:08:53.684262 2026] [security2:error] [pid 167459:tid 167667] [client 191.237.254.161:13976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/aaa.php"] [unique_id "aoSDlWr_JutbFb-8svoJnQAAAd0"] [Tue Aug 18 13:08:53.694734 2026] [security2:error] [pid 167459:tid 167662] [client 191.237.254.161:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDlWr_JutbFb-8svoJngAAAdg"] [Tue Aug 18 13:08:53.718456 2026] [security2:error] [pid 167459:tid 167643] [client 191.237.254.161:28212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/site.php"] [unique_id "aoSDlWr_JutbFb-8svoJnwAAAcU"] [Tue Aug 18 13:08:53.728845 2026] [security2:error] [pid 167459:tid 167590] [client 191.237.254.161:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/ccc.php"] [unique_id "aoSDlWr_JutbFb-8svoJoAAAAZA"] [Tue Aug 18 13:08:53.742070 2026] [security2:error] [pid 167459:tid 167687] [client 191.237.254.161:14004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/admin.php"] [unique_id "aoSDlWr_JutbFb-8svoJoQAAAfE"] [Tue Aug 18 13:08:53.755300 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:53.755558 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:53.764197 2026] [security2:error] [pid 167459:tid 167603] [client 20.79.204.6:5696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDlWr_JutbFb-8svoJpQAAAZ0"] [Tue Aug 18 13:08:53.765068 2026] [security2:error] [pid 167459:tid 167714] [client 20.116.17.175:22754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/img.php"] [unique_id "aoSDlWr_JutbFb-8svoJpgAAAgw"] [Tue Aug 18 13:08:53.768133 2026] [security2:error] [pid 167459:tid 167713] [client 158.23.17.4:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lv.php"] [unique_id "aoSDlWr_JutbFb-8svoJpwAAAgs"] [Tue Aug 18 13:08:53.782781 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:9680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/0x.php"] [unique_id "aoSDlWr_JutbFb-8svoJqAAAAbQ"] [Tue Aug 18 13:08:53.804742 2026] [security2:error] [pid 167459:tid 167655] [client 20.151.109.219:33515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/rn.php"] [unique_id "aoSDlWr_JutbFb-8svoJqQAAAdE"] [Tue Aug 18 13:08:53.837929 2026] [security2:error] [pid 167459:tid 167635] [client 191.237.254.161:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/reviall.php"] [unique_id "aoSDlWr_JutbFb-8svoJrAAAAb0"] [Tue Aug 18 13:08:53.853888 2026] [security2:error] [pid 167459:tid 167641] [client 20.1.169.243:8943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/abc.php"] [unique_id "aoSDlWr_JutbFb-8svoJrgAAAcM"] [Tue Aug 18 13:08:53.859113 2026] [security2:error] [pid 167459:tid 167594] [client 223.185.37.47:19560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDlWr_JutbFb-8svoJrwAAAZQ"] [Tue Aug 18 13:08:53.859242 2026] [security2:error] [pid 167459:tid 167594] [client 223.185.37.47:19560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDlWr_JutbFb-8svoJrwAAAZQ"] [Tue Aug 18 13:08:53.866979 2026] [security2:error] [pid 167459:tid 167611] [client 20.215.241.237:39323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/Njima.php"] [unique_id "aoSDlWr_JutbFb-8svoJsAAAAaU"] [Tue Aug 18 13:08:53.919195 2026] [security2:error] [pid 167459:tid 167637] [client 191.237.254.161:2826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/nope.php"] [unique_id "aoSDlWr_JutbFb-8svoJswAAAb8"] [Tue Aug 18 13:08:53.919625 2026] [security2:error] [pid 167459:tid 167686] [client 52.173.121.69:28324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDlWr_JutbFb-8svoJtAAAAfA"] [Tue Aug 18 13:08:53.932520 2026] [security2:error] [pid 167459:tid 167624] [client 20.250.13.23:23095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSDlWr_JutbFb-8svoJtgAAAbI"] [Tue Aug 18 13:08:53.959409 2026] [security2:error] [pid 167459:tid 167606] [client 172.182.217.32:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDlWr_JutbFb-8svoJtwAAAaA"] [Tue Aug 18 13:08:53.962513 2026] [security2:error] [pid 167459:tid 167605] [client 20.250.13.23:23089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSDlWr_JutbFb-8svoJuAAAAZ8"] [Tue Aug 18 13:08:53.979459 2026] [security2:error] [pid 167459:tid 167597] [client 40.74.65.169:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/dex.php"] [unique_id "aoSDlWr_JutbFb-8svoJuQAAAZc"] [Tue Aug 18 13:08:54.008312 2026] [security2:error] [pid 167459:tid 167617] [client 172.213.243.2:19886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/alfa-rex.php7"] [unique_id "aoSDlmr_JutbFb-8svoJugAAAas"] [Tue Aug 18 13:08:54.016674 2026] [security2:error] [pid 167459:tid 167604] [client 158.23.17.4:56755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/jm.php"] [unique_id "aoSDlmr_JutbFb-8svoJuwAAAZ4"] [Tue Aug 18 13:08:54.016775 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:53329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wmore1.php"] [unique_id "aoSDlmr_JutbFb-8svoJvAAAAgQ"] [Tue Aug 18 13:08:54.025074 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:5363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/index.bak.php"] [unique_id "aoSDlmr_JutbFb-8svoJvgAAAfM"] [Tue Aug 18 13:08:54.055541 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:54.055795 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:54.065663 2026] [security2:error] [pid 167459:tid 167622] [client 191.237.254.161:22862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/nope.php"] [unique_id "aoSDlmr_JutbFb-8svoJwgAAAbA"] [Tue Aug 18 13:08:54.089843 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.100.201:13867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/yawa.php"] [unique_id "aoSDlmr_JutbFb-8svoJwwAAAY8"] [Tue Aug 18 13:08:54.095120 2026] [security2:error] [pid 167459:tid 167593] [client 191.237.254.161:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/new.php"] [unique_id "aoSDlmr_JutbFb-8svoJxAAAAZM"] [Tue Aug 18 13:08:54.114735 2026] [security2:error] [pid 167459:tid 167634] [client 191.237.254.161:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/new.php"] [unique_id "aoSDlmr_JutbFb-8svoJxwAAAbw"] [Tue Aug 18 13:08:54.131498 2026] [security2:error] [pid 167459:tid 167674] [client 191.237.254.161:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/apreset.php"] [unique_id "aoSDlmr_JutbFb-8svoJyAAAAeQ"] [Tue Aug 18 13:08:54.148190 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:10494] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSDlmr_JutbFb-8svoJyQAAAgo"] [Tue Aug 18 13:08:54.148287 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:10494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/1.php"] [unique_id "aoSDlmr_JutbFb-8svoJyQAAAgo"] [Tue Aug 18 13:08:54.149246 2026] [security2:error] [pid 167459:tid 167705] [client 191.237.254.161:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/1mage.php"] [unique_id "aoSDlmr_JutbFb-8svoJygAAAgM"] [Tue Aug 18 13:08:54.178521 2026] [security2:error] [pid 167459:tid 167671] [client 20.25.139.174:4450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/k.php"] [unique_id "aoSDlmr_JutbFb-8svoJywAAAeE"] [Tue Aug 18 13:08:54.180605 2026] [security2:error] [pid 167459:tid 167614] [client 172.202.39.151:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/style-engine/index.php"] [unique_id "aoSDlmr_JutbFb-8svoJzAAAAag"] [Tue Aug 18 13:08:54.203957 2026] [security2:error] [pid 167459:tid 167598] [client 191.237.254.161:61223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/imsc.php"] [unique_id "aoSDlmr_JutbFb-8svoJzgAAAZg"] [Tue Aug 18 13:08:54.218385 2026] [security2:error] [pid 167459:tid 167709] [client 191.237.254.161:28198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDlmr_JutbFb-8svoJzwAAAgc"] [Tue Aug 18 13:08:54.222140 2026] [security2:error] [pid 167459:tid 167652] [client 20.1.169.243:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/av.php"] [unique_id "aoSDlmr_JutbFb-8svoJ0AAAAc4"] [Tue Aug 18 13:08:54.231075 2026] [security2:error] [pid 167459:tid 167691] [client 20.226.36.136:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/rezor.php"] [unique_id "aoSDlmr_JutbFb-8svoJ0QAAAfU"] [Tue Aug 18 13:08:54.238763 2026] [security2:error] [pid 167459:tid 167636] [client 4.232.151.198:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/about.php"] [unique_id "aoSDlmr_JutbFb-8svoJ0gAAAb4"] [Tue Aug 18 13:08:54.239229 2026] [security2:error] [pid 167459:tid 167601] [client 191.237.254.161:14628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/qlex1.php"] [unique_id "aoSDlmr_JutbFb-8svoJ0wAAAZs"] [Tue Aug 18 13:08:54.241991 2026] [security2:error] [pid 167459:tid 167616] [client 20.116.17.175:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDlmr_JutbFb-8svoJ1AAAAao"] [Tue Aug 18 13:08:54.266111 2026] [security2:error] [pid 167459:tid 167667] [client 191.237.254.161:28181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/mariju.php"] [unique_id "aoSDlmr_JutbFb-8svoJ1QAAAd0"] [Tue Aug 18 13:08:54.283928 2026] [security2:error] [pid 167459:tid 167653] [client 191.237.254.161:13989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDlmr_JutbFb-8svoJ1gAAAc8"] [Tue Aug 18 13:08:54.294791 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:5020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/51.php"] [unique_id "aoSDlmr_JutbFb-8svoJ2AAAAZI"] [Tue Aug 18 13:08:54.296399 2026] [security2:error] [pid 167459:tid 167685] [client 191.237.254.161:2878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/contacto.php"] [unique_id "aoSDlmr_JutbFb-8svoJ2QAAAe8"] [Tue Aug 18 13:08:54.297023 2026] [security2:error] [pid 167459:tid 167661] [client 20.100.169.31:2570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/222.php"] [unique_id "aoSDlmr_JutbFb-8svoJ2gAAAdc"] [Tue Aug 18 13:08:54.299226 2026] [security2:error] [pid 167459:tid 167603] [client 20.215.241.237:30421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/BIBIL.php"] [unique_id "aoSDlmr_JutbFb-8svoJ2wAAAZ0"] [Tue Aug 18 13:08:54.320557 2026] [security2:error] [pid 167459:tid 167713] [client 20.171.51.14:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/fo.php"] [unique_id "aoSDlmr_JutbFb-8svoJ3AAAAgs"] [Tue Aug 18 13:08:54.337607 2026] [security2:error] [pid 167459:tid 167680] [client 191.237.254.161:13989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/image2.php"] [unique_id "aoSDlmr_JutbFb-8svoJ3QAAAeo"] [Tue Aug 18 13:08:54.354350 2026] [security2:error] [pid 167459:tid 167675] [client 20.127.136.245:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/mac.php"] [unique_id "aoSDlmr_JutbFb-8svoJ3gAAAeU"] [Tue Aug 18 13:08:54.356581 2026] [security2:error] [pid 167459:tid 167600] [client 20.116.17.175:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDlmr_JutbFb-8svoJ3wAAAZo"] [Tue Aug 18 13:08:54.388141 2026] [security2:error] [pid 167459:tid 167682] [client 20.1.169.243:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lite.php"] [unique_id "aoSDlmr_JutbFb-8svoJ4QAAAew"] [Tue Aug 18 13:08:54.396254 2026] [security2:error] [pid 167459:tid 167629] [client 20.79.204.6:5982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSDlmr_JutbFb-8svoJ4wAAAbc"] [Tue Aug 18 13:08:54.449171 2026] [security2:error] [pid 167459:tid 167697] [client 172.182.217.32:25617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/images/wp-login.php"] [unique_id "aoSDlmr_JutbFb-8svoJ5wAAAfs"] [Tue Aug 18 13:08:54.459591 2026] [security2:error] [pid 167459:tid 167630] [client 213.35.127.232:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDlmr_JutbFb-8svoJ6AAAAbg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:54.492426 2026] [security2:error] [pid 167459:tid 167627] [client 172.213.243.2:19529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/0.php"] [unique_id "aoSDlmr_JutbFb-8svoJ6gAAAbU"] [Tue Aug 18 13:08:54.522388 2026] [security2:error] [pid 167459:tid 167673] [client 20.104.100.201:9597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/special.php"] [unique_id "aoSDlmr_JutbFb-8svoJ7AAAAeM"] [Tue Aug 18 13:08:54.523531 2026] [security2:error] [pid 167459:tid 167594] [client 20.1.169.243:10459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/100.php"] [unique_id "aoSDlmr_JutbFb-8svoJ7QAAAZQ"] [Tue Aug 18 13:08:54.586376 2026] [security2:error] [pid 167459:tid 167706] [client 20.226.36.136:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDlmr_JutbFb-8svoJ8AAAAgQ"] [Tue Aug 18 13:08:54.590672 2026] [security2:error] [pid 167459:tid 167595] [client 20.250.13.23:5207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-configs.php"] [unique_id "aoSDlmr_JutbFb-8svoJ8QAAAZU"] [Tue Aug 18 13:08:54.591081 2026] [security2:error] [pid 167459:tid 167689] [client 74.248.130.103:45811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDlmr_JutbFb-8svoJ8gAAAfM"] [Tue Aug 18 13:08:54.594116 2026] [security2:error] [pid 167459:tid 167683] [client 102.213.179.104:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlmr_JutbFb-8svoJ7wAAAe0"] [Tue Aug 18 13:08:54.594213 2026] [security2:error] [pid 167459:tid 167683] [client 102.213.179.104:60290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlmr_JutbFb-8svoJ7wAAAe0"] [Tue Aug 18 13:08:54.601597 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:9537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSDlmr_JutbFb-8svoJ8wAAAfA"] [Tue Aug 18 13:08:54.602917 2026] [security2:error] [pid 167459:tid 167655] [client 20.250.13.23:5679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSDlmr_JutbFb-8svoJ9AAAAdE"] [Tue Aug 18 13:08:54.645112 2026] [security2:error] [pid 167459:tid 167593] [client 172.202.39.151:39225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDlmr_JutbFb-8svoJ9wAAAZM"] [Tue Aug 18 13:08:54.662418 2026] [authz_core:error] [pid 167459:tid 167523] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:54.662658 2026] [authz_core:error] [pid 167459:tid 167523] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:54.669210 2026] [security2:error] [pid 167459:tid 167663] [client 191.237.254.161:22871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/fb.php"] [unique_id "aoSDlmr_JutbFb-8svoJ-gAAAdk"] [Tue Aug 18 13:08:54.671109 2026] [security2:error] [pid 167459:tid 167674] [client 40.74.65.169:7053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/key.php"] [unique_id "aoSDlmr_JutbFb-8svoJ-wAAAeQ"] [Tue Aug 18 13:08:54.683771 2026] [security2:error] [pid 167459:tid 167628] [client 52.173.121.69:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDlmr_JutbFb-8svoJ_AAAAbY"] [Tue Aug 18 13:08:54.724389 2026] [security2:error] [pid 167459:tid 167614] [client 20.215.241.237:46381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/too.php"] [unique_id "aoSDlmr_JutbFb-8svoJ_gAAAag"] [Tue Aug 18 13:08:54.738480 2026] [security2:error] [pid 167459:tid 167609] [client 20.25.139.174:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-blink.php"] [unique_id "aoSDlmr_JutbFb-8svoKAQAAAaM"] [Tue Aug 18 13:08:54.752077 2026] [security2:error] [pid 167459:tid 167589] [client 20.1.169.243:5768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/live.php"] [unique_id "aoSDlmr_JutbFb-8svoKAwAAAY8"] [Tue Aug 18 13:08:54.859000 2026] [security2:error] [pid 167459:tid 167596] [client 191.237.254.161:2831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/gi.php"] [unique_id "aoSDlmr_JutbFb-8svoKBgAAAZY"] [Tue Aug 18 13:08:54.865883 2026] [security2:error] [pid 167459:tid 167636] [client 20.116.17.175:22773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDlmr_JutbFb-8svoKBwAAAb4"] [Tue Aug 18 13:08:54.872856 2026] [security2:error] [pid 167459:tid 167690] [client 4.232.151.198:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDlmr_JutbFb-8svoKCAAAAfQ"] [Tue Aug 18 13:08:54.883355 2026] [security2:error] [pid 167459:tid 167667] [client 20.104.100.201:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDlmr_JutbFb-8svoKCQAAAd0"] [Tue Aug 18 13:08:54.893639 2026] [security2:error] [pid 167459:tid 167647] [client 20.250.13.23:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/edit-tags.php"] [unique_id "aoSDlmr_JutbFb-8svoKCgAAAck"] [Tue Aug 18 13:08:54.893656 2026] [security2:error] [pid 167459:tid 167672] [client 20.1.169.243:10489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/2.php"] [unique_id "aoSDlmr_JutbFb-8svoKCwAAAeI"] [Tue Aug 18 13:08:54.922514 2026] [security2:error] [pid 167459:tid 167703] [client 20.100.169.31:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/aa.php"] [unique_id "aoSDlmr_JutbFb-8svoKDQAAAgE"] [Tue Aug 18 13:08:54.938211 2026] [security2:error] [pid 167459:tid 167633] [client 172.182.217.32:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDlmr_JutbFb-8svoKDwAAAbs"] [Tue Aug 18 13:08:54.957008 2026] [security2:error] [pid 167459:tid 167713] [client 172.213.243.2:19556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/dom.php"] [unique_id "aoSDlmr_JutbFb-8svoKEgAAAgs"] [Tue Aug 18 13:08:54.957440 2026] [security2:error] [pid 167459:tid 167615] [client 20.151.109.219:36341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ut.php"] [unique_id "aoSDlmr_JutbFb-8svoKEwAAAak"] [Tue Aug 18 13:08:54.960527 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:54.960787 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:54.967265 2026] [security2:error] [pid 167459:tid 167691] [client 20.1.169.243:8900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/asus.php"] [unique_id "aoSDlmr_JutbFb-8svoKFQAAAfU"] [Tue Aug 18 13:08:54.986352 2026] [security2:error] [pid 167459:tid 167599] [client 74.248.133.44:13234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/.__info.php"] [unique_id "aoSDlmr_JutbFb-8svoKFgAAAZk"] [Tue Aug 18 13:08:55.012973 2026] [security2:error] [pid 167459:tid 167709] [client 20.79.204.6:5707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.204.79.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eccellenzaconsultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDl2r_JutbFb-8svoKFwAAAgc"] [Tue Aug 18 13:08:55.013541 2026] [security2:error] [pid 167459:tid 167700] [client 20.104.100.201:9483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDl2r_JutbFb-8svoKGAAAAf4"] [Tue Aug 18 13:08:55.048061 2026] [security2:error] [pid 167459:tid 167682] [client 158.23.17.4:56527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wj.php"] [unique_id "aoSDl2r_JutbFb-8svoKHAAAAew"] [Tue Aug 18 13:08:55.050306 2026] [security2:error] [pid 167459:tid 167629] [client 74.248.130.103:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDl2r_JutbFb-8svoKHQAAAbc"] [Tue Aug 18 13:08:55.079654 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ew.php"] [unique_id "aoSDl2r_JutbFb-8svoKIQAAAeg"] [Tue Aug 18 13:08:55.117140 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:3182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/bypass.php"] [unique_id "aoSDl2r_JutbFb-8svoKJAAAAbQ"] [Tue Aug 18 13:08:55.169978 2026] [security2:error] [pid 167459:tid 167664] [client 20.171.51.14:10886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/loading.php"] [unique_id "aoSDl2r_JutbFb-8svoKJgAAAdo"] [Tue Aug 18 13:08:55.180625 2026] [security2:error] [pid 167459:tid 167617] [client 191.237.254.161:22869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/video.php"] [unique_id "aoSDl2r_JutbFb-8svoKKAAAAas"] [Tue Aug 18 13:08:55.198803 2026] [security2:error] [pid 167459:tid 167692] [client 5.161.194.92:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1td.com.br"] [uri "/index.php"] [unique_id "aoSDlmr_JutbFb-8svoKFAAB9is"], referer: https://1td.com.br [Tue Aug 18 13:08:55.206855 2026] [security2:error] [pid 167459:tid 167680] [client 20.250.13.23:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-post.php"] [unique_id "aoSDl2r_JutbFb-8svoKKQAAAeo"] [Tue Aug 18 13:08:55.222391 2026] [security2:error] [pid 167459:tid 167683] [client 172.202.39.151:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp.php"] [unique_id "aoSDl2r_JutbFb-8svoKLAAAAe0"] [Tue Aug 18 13:08:55.232034 2026] [security2:error] [pid 167459:tid 167655] [client 20.226.36.136:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDl2r_JutbFb-8svoKLgAAAdE"] [Tue Aug 18 13:08:55.235046 2026] [security2:error] [pid 167459:tid 167708] [client 20.250.13.23:23065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/st.php"] [unique_id "aoSDl2r_JutbFb-8svoKLwAAAgY"] [Tue Aug 18 13:08:55.239289 2026] [security2:error] [pid 167459:tid 167635] [client 158.23.17.4:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/yn.php"] [unique_id "aoSDl2r_JutbFb-8svoKMAAAAb0"] [Tue Aug 18 13:08:55.274674 2026] [security2:error] [pid 167459:tid 167606] [client 20.1.169.243:10456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/222.php"] [unique_id "aoSDl2r_JutbFb-8svoKMgAAAaA"] [Tue Aug 18 13:08:55.279351 2026] [security2:error] [pid 167459:tid 167628] [client 20.127.136.245:24826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/nc4.php"] [unique_id "aoSDl2r_JutbFb-8svoKMwAAAbY"] [Tue Aug 18 13:08:55.281540 2026] [security2:error] [pid 167459:tid 167566] [remote 162.214.96.231:42646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gvc.eng.br"] [uri "/wp-login.php"] [unique_id "aoSDl2r_JutbFb-8svoKNAACCmo"] [Tue Aug 18 13:08:55.332403 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:8924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/about.php"] [unique_id "aoSDl2r_JutbFb-8svoKNwAAAfM"] [Tue Aug 18 13:08:55.353235 2026] [security2:error] [pid 167459:tid 167609] [client 20.215.241.237:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.circuitofechado.tv"] [uri "/g3.php"] [unique_id "aoSDl2r_JutbFb-8svoKOAAAAaM"] [Tue Aug 18 13:08:55.368113 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.100.201:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/thoms.php"] [unique_id "aoSDl2r_JutbFb-8svoKOgAAAY8"] [Tue Aug 18 13:08:55.370014 2026] [security2:error] [pid 167459:tid 167707] [client 20.116.17.175:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dot.php"] [unique_id "aoSDl2r_JutbFb-8svoKOwAAAgU"] [Tue Aug 18 13:08:55.413340 2026] [security2:error] [pid 167459:tid 167636] [client 40.74.65.169:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/kir.php"] [unique_id "aoSDl2r_JutbFb-8svoKPwAAAb4"] [Tue Aug 18 13:08:55.425963 2026] [security2:error] [pid 167459:tid 167601] [client 191.237.254.161:2818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/hel.php"] [unique_id "aoSDl2r_JutbFb-8svoKQgAAAZs"] [Tue Aug 18 13:08:55.425992 2026] [security2:error] [pid 167459:tid 167688] [client 172.182.217.32:25558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/includes/admin-header.php"] [unique_id "aoSDl2r_JutbFb-8svoKQQAAAfI"] [Tue Aug 18 13:08:55.460581 2026] [security2:error] [pid 167459:tid 167672] [client 191.237.254.161:22879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/grok.php"] [unique_id "aoSDl2r_JutbFb-8svoKRAAAAeI"] [Tue Aug 18 13:08:55.466778 2026] [security2:error] [pid 167459:tid 167662] [client 172.213.243.2:19849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/bb.php"] [unique_id "aoSDl2r_JutbFb-8svoKRQAAAdg"] [Tue Aug 18 13:08:55.477063 2026] [security2:error] [pid 167459:tid 167608] [client 213.35.127.232:53021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDl2r_JutbFb-8svoKRgAAAaI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:55.486208 2026] [core:notice] [pid 167459:tid 167506] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:08:55.498606 2026] [security2:error] [pid 167459:tid 167592] [client 52.173.121.69:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDl2r_JutbFb-8svoKSgAAAZI"] [Tue Aug 18 13:08:55.520592 2026] [security2:error] [pid 167459:tid 167714] [client 4.232.151.198:11918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDl2r_JutbFb-8svoKSwAAAgw"] [Tue Aug 18 13:08:55.533446 2026] [security2:error] [pid 167459:tid 167642] [client 74.248.130.103:17741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDl2r_JutbFb-8svoKTAAAAcQ"] [Tue Aug 18 13:08:55.536909 2026] [security2:error] [pid 167459:tid 167651] [client 191.237.254.161:13981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/indes.php"] [unique_id "aoSDl2r_JutbFb-8svoKTQAAAc0"] [Tue Aug 18 13:08:55.549009 2026] [security2:error] [pid 167459:tid 167614] [client 20.100.169.31:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/abcd.php"] [unique_id "aoSDl2r_JutbFb-8svoKTgAAAag"] [Tue Aug 18 13:08:55.565812 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:55.566238 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:55.587298 2026] [security2:error] [pid 167459:tid 167705] [client 4.232.151.198:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/admin.php"] [unique_id "aoSDl2r_JutbFb-8svoKVAAAAgM"] [Tue Aug 18 13:08:55.589812 2026] [security2:error] [pid 167459:tid 167701] [client 149.34.210.141:55438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDl2r_JutbFb-8svoKUwAAAf8"] [Tue Aug 18 13:08:55.600078 2026] [security2:error] [pid 167459:tid 167665] [client 191.237.254.161:2873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDl2r_JutbFb-8svoKVgAAAds"] [Tue Aug 18 13:08:55.605564 2026] [security2:error] [pid 167459:tid 167612] [client 20.1.169.243:5805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/lock360.php"] [unique_id "aoSDl2r_JutbFb-8svoKWAAAAaY"] [Tue Aug 18 13:08:55.609798 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:39582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pqr.php"] [unique_id "aoSDl2r_JutbFb-8svoKWQAAAfs"] [Tue Aug 18 13:08:55.626373 2026] [security2:error] [pid 167459:tid 167657] [client 20.171.51.14:60376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ke.php"] [unique_id "aoSDl2r_JutbFb-8svoKWgAAAdM"] [Tue Aug 18 13:08:55.629059 2026] [security2:error] [pid 167459:tid 167591] [client 191.237.254.161:22893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/bs1.php"] [unique_id "aoSDl2r_JutbFb-8svoKWwAAAZE"] [Tue Aug 18 13:08:55.652681 2026] [security2:error] [pid 167459:tid 167610] [client 20.1.169.243:10490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSDl2r_JutbFb-8svoKXAAAAaQ"] [Tue Aug 18 13:08:55.659479 2026] [security2:error] [pid 167459:tid 167645] [client 191.237.254.161:24739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/hp2.php"] [unique_id "aoSDl2r_JutbFb-8svoKXQAAAcc"] [Tue Aug 18 13:08:55.671729 2026] [security2:error] [pid 167459:tid 167644] [client 20.226.36.136:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/index/function.php"] [unique_id "aoSDl2r_JutbFb-8svoKXwAAAcY"] [Tue Aug 18 13:08:55.701685 2026] [security2:error] [pid 167459:tid 167704] [client 172.202.39.151:27884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/function/function.php"] [unique_id "aoSDl2r_JutbFb-8svoKYAAAAgI"] [Tue Aug 18 13:08:55.713202 2026] [security2:error] [pid 167459:tid 167594] [client 191.237.254.161:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/yb.php"] [unique_id "aoSDl2r_JutbFb-8svoKYQAAAZQ"] [Tue Aug 18 13:08:55.770006 2026] [security2:error] [pid 167459:tid 167680] [client 20.25.139.174:4491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/ww5.php"] [unique_id "aoSDl2r_JutbFb-8svoKYwAAAeo"] [Tue Aug 18 13:08:55.770180 2026] [security2:error] [pid 167459:tid 167716] [client 20.1.169.243:8953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/atomlib.php"] [unique_id "aoSDl2r_JutbFb-8svoKZAAAAg4"] [Tue Aug 18 13:08:55.808670 2026] [security2:error] [pid 167459:tid 167660] [client 191.237.254.161:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/vc.php"] [unique_id "aoSDl2r_JutbFb-8svoKZQAAAdY"] [Tue Aug 18 13:08:55.810740 2026] [security2:error] [pid 167459:tid 167635] [client 20.151.109.219:31699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/eh.php"] [unique_id "aoSDl2r_JutbFb-8svoKZgAAAb0"] [Tue Aug 18 13:08:55.838871 2026] [security2:error] [pid 167459:tid 167684] [client 20.250.13.23:55106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSDl2r_JutbFb-8svoKaAAAAe4"] [Tue Aug 18 13:08:55.853002 2026] [security2:error] [pid 167459:tid 167701] [client 149.34.210.141:55438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDl2r_JutbFb-8svoKUwAAAf8"] [Tue Aug 18 13:08:55.856198 2026] [security2:error] [pid 167459:tid 167626] [client 20.250.13.23:5219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSDl2r_JutbFb-8svoKagAAAbQ"] [Tue Aug 18 13:08:55.864142 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:55.864422 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:55.897397 2026] [security2:error] [pid 167459:tid 167712] [client 172.213.243.2:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ok.php"] [unique_id "aoSDl2r_JutbFb-8svoKbAAAAgo"] [Tue Aug 18 13:08:55.912690 2026] [security2:error] [pid 167459:tid 167706] [client 172.182.217.32:25542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/includes/logs.php"] [unique_id "aoSDl2r_JutbFb-8svoKbQAAAgQ"] [Tue Aug 18 13:08:55.916442 2026] [security2:error] [pid 167459:tid 167685] [client 20.104.100.201:9473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDl2r_JutbFb-8svoKbwAAAe8"] [Tue Aug 18 13:08:55.922269 2026] [security2:error] [pid 167459:tid 167689] [client 191.237.254.161:11676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/pema.php"] [unique_id "aoSDl2r_JutbFb-8svoKcAAAAfM"] [Tue Aug 18 13:08:55.956575 2026] [security2:error] [pid 167459:tid 167707] [client 191.237.254.161:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/sh.php"] [unique_id "aoSDl2r_JutbFb-8svoKcgAAAgU"] [Tue Aug 18 13:08:56.022461 2026] [security2:error] [pid 167459:tid 167596] [client 191.237.254.161:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/button.php"] [unique_id "aoSDmGr_JutbFb-8svoKdAAAAZY"] [Tue Aug 18 13:08:56.031743 2026] [security2:error] [pid 167459:tid 167687] [client 74.248.133.44:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/access.php"] [unique_id "aoSDmGr_JutbFb-8svoKdgAAAfE"] [Tue Aug 18 13:08:56.034777 2026] [security2:error] [pid 167459:tid 167681] [client 20.1.169.243:10493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/403.php"] [unique_id "aoSDmGr_JutbFb-8svoKdwAAAes"] [Tue Aug 18 13:08:56.035692 2026] [security2:error] [pid 167459:tid 167616] [client 191.237.254.161:61220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/wlc.php"] [unique_id "aoSDmGr_JutbFb-8svoKeAAAAao"] [Tue Aug 18 13:08:56.036313 2026] [security2:error] [pid 167459:tid 167677] [client 20.116.17.175:41477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "aoSDmGr_JutbFb-8svoKeQAAAec"] [Tue Aug 18 13:08:56.058309 2026] [security2:error] [pid 167459:tid 167643] [client 74.248.130.103:45817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/av.php"] [unique_id "aoSDmGr_JutbFb-8svoKegAAAcU"] [Tue Aug 18 13:08:56.093121 2026] [security2:error] [pid 167459:tid 167674] [client 20.1.169.243:16285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/majalahpro-core/lib/index.php"] [unique_id "aoSDmGr_JutbFb-8svoKfAAAAeQ"] [Tue Aug 18 13:08:56.097585 2026] [security2:error] [pid 167459:tid 167713] [client 191.237.254.161:2834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/fi.php"] [unique_id "aoSDmGr_JutbFb-8svoKfQAAAgs"] [Tue Aug 18 13:08:56.108880 2026] [security2:error] [pid 167459:tid 167714] [client 191.237.254.161:11651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/chris.php"] [unique_id "aoSDmGr_JutbFb-8svoKfgAAAgw"] [Tue Aug 18 13:08:56.142920 2026] [security2:error] [pid 167459:tid 167676] [client 20.1.169.243:9592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDmGr_JutbFb-8svoKgAAAAeY"] [Tue Aug 18 13:08:56.151581 2026] [security2:error] [pid 167459:tid 167614] [client 40.74.65.169:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/nofile.php"] [unique_id "aoSDmGr_JutbFb-8svoKggAAAag"] [Tue Aug 18 13:08:56.164828 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:56.165079 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:56.165886 2026] [security2:error] [pid 167459:tid 167682] [client 191.237.254.161:13956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/doc.php"] [unique_id "aoSDmGr_JutbFb-8svoKhAAAAew"] [Tue Aug 18 13:08:56.184147 2026] [security2:error] [pid 167459:tid 167699] [client 20.100.169.31:2560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/admin.php"] [unique_id "aoSDmGr_JutbFb-8svoKhQAAAf0"] [Tue Aug 18 13:08:56.240125 2026] [security2:error] [pid 167459:tid 167618] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDlmr_JutbFb-8svoJ_wABrAw"] [Tue Aug 18 13:08:56.247841 2026] [security2:error] [pid 167459:tid 167603] [client 20.104.100.201:13849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/7.php"] [unique_id "aoSDmGr_JutbFb-8svoKigAAAZ0"] [Tue Aug 18 13:08:56.271037 2026] [security2:error] [pid 167459:tid 167644] [client 20.127.136.245:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/as.php"] [unique_id "aoSDmGr_JutbFb-8svoKiwAAAcY"] [Tue Aug 18 13:08:56.310418 2026] [security2:error] [pid 167459:tid 167594] [client 172.213.243.2:19894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp9.php"] [unique_id "aoSDmGr_JutbFb-8svoKjgAAAZQ"] [Tue Aug 18 13:08:56.320985 2026] [security2:error] [pid 167459:tid 167535] [remote 162.214.96.231:42644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tigre.tur.br.slweb.net.br"] [uri "/wp-login.php"] [unique_id "aoSDmGr_JutbFb-8svoKjwABoUs"] [Tue Aug 18 13:08:56.329870 2026] [security2:error] [pid 167459:tid 167670] [client 4.232.151.198:2335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDmGr_JutbFb-8svoKkAAAAeA"] [Tue Aug 18 13:08:56.341178 2026] [security2:error] [pid 167459:tid 167664] [client 191.237.254.161:24716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/1337.php"] [unique_id "aoSDmGr_JutbFb-8svoKkQAAAdo"] [Tue Aug 18 13:08:56.356160 2026] [security2:error] [pid 167459:tid 167602] [client 172.202.39.151:27882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "aoSDmGr_JutbFb-8svoKkwAAAZw"] [Tue Aug 18 13:08:56.370433 2026] [security2:error] [pid 167459:tid 167630] [client 20.250.13.23:31239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/u.php"] [unique_id "aoSDmGr_JutbFb-8svoKlAAAAbg"] [Tue Aug 18 13:08:56.391972 2026] [security2:error] [pid 167459:tid 167597] [client 191.237.254.161:11706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/Njima.php"] [unique_id "aoSDmGr_JutbFb-8svoKlgAAAZc"] [Tue Aug 18 13:08:56.409590 2026] [security2:error] [pid 167459:tid 167650] [client 20.1.169.243:10177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/404.php"] [unique_id "aoSDmGr_JutbFb-8svoKmAAAAcw"] [Tue Aug 18 13:08:56.410781 2026] [security2:error] [pid 167459:tid 167680] [client 20.226.36.136:62180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDmGr_JutbFb-8svoKmQAAAeo"] [Tue Aug 18 13:08:56.414435 2026] [security2:error] [pid 167459:tid 167716] [client 74.249.206.207:51563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/k.php"] [unique_id "aoSDmGr_JutbFb-8svoKmgAAAg4"] [Tue Aug 18 13:08:56.421180 2026] [security2:error] [pid 167459:tid 167657] [client 172.182.217.32:25732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/includes/media.php.INFECTED.php"] [unique_id "aoSDmGr_JutbFb-8svoKmwAAAdM"] [Tue Aug 18 13:08:56.450525 2026] [security2:error] [pid 167459:tid 167655] [client 52.173.121.69:49989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDmGr_JutbFb-8svoKnAAAAdE"] [Tue Aug 18 13:08:56.456860 2026] [security2:error] [pid 167459:tid 167708] [client 20.104.100.201:9598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/root.php"] [unique_id "aoSDmGr_JutbFb-8svoKnQAAAgY"] [Tue Aug 18 13:08:56.456880 2026] [security2:error] [pid 167459:tid 167632] [client 20.1.169.243:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/pwnd/as.php"] [unique_id "aoSDmGr_JutbFb-8svoKngAAAbo"] [Tue Aug 18 13:08:56.460839 2026] [security2:error] [pid 167459:tid 167704] [client 20.25.139.174:4733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/2.php"] [unique_id "aoSDmGr_JutbFb-8svoKoAAAAgI"] [Tue Aug 18 13:08:56.462178 2026] [security2:error] [pid 167459:tid 167591] [client 20.250.13.23:6072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSDmGr_JutbFb-8svoKoQAAAZE"] [Tue Aug 18 13:08:56.469467 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:56.469880 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:56.470016 2026] [security2:error] [pid 167459:tid 167645] [client 20.250.13.23:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-configs.php"] [unique_id "aoSDmGr_JutbFb-8svoKogAAAcc"] [Tue Aug 18 13:08:56.486916 2026] [security2:error] [pid 167459:tid 167693] [client 158.23.17.4:14020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/11.php"] [unique_id "aoSDmGr_JutbFb-8svoKpAAAAfc"] [Tue Aug 18 13:08:56.494626 2026] [security2:error] [pid 167459:tid 167700] [client 213.35.127.232:53215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDmGr_JutbFb-8svoKpgAAAf4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:56.501266 2026] [security2:error] [pid 167459:tid 167635] [client 158.23.17.4:7299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/an.php"] [unique_id "aoSDmGr_JutbFb-8svoKpwAAAb0"] [Tue Aug 18 13:08:56.507509 2026] [security2:error] [pid 167459:tid 167648] [client 20.1.169.243:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/b.php"] [unique_id "aoSDmGr_JutbFb-8svoKqQAAAco"] [Tue Aug 18 13:08:56.507677 2026] [security2:error] [pid 167459:tid 167593] [client 191.237.254.161:11702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/BIBIL.php"] [unique_id "aoSDmGr_JutbFb-8svoKqAAAAZM"] [Tue Aug 18 13:08:56.548637 2026] [security2:error] [pid 167459:tid 167703] [client 20.171.51.14:2361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/nh.php"] [unique_id "aoSDmGr_JutbFb-8svoKrAAAAgE"] [Tue Aug 18 13:08:56.576407 2026] [security2:error] [pid 167459:tid 167706] [client 191.237.254.161:13975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/too.php"] [unique_id "aoSDmGr_JutbFb-8svoKrQAAAgQ"] [Tue Aug 18 13:08:56.580842 2026] [security2:error] [pid 167459:tid 167671] [client 20.116.17.175:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDmGr_JutbFb-8svoKrwAAAeE"] [Tue Aug 18 13:08:56.582638 2026] [security2:error] [pid 167459:tid 167689] [client 74.248.130.103:17742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/images.php"] [unique_id "aoSDmGr_JutbFb-8svoKsAAAAfM"] [Tue Aug 18 13:08:56.589111 2026] [security2:error] [pid 167459:tid 167649] [client 20.151.109.219:40488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ad.php"] [unique_id "aoSDmGr_JutbFb-8svoKsQAAAcs"] [Tue Aug 18 13:08:56.600386 2026] [security2:error] [pid 167459:tid 167638] [client 191.237.254.161:23929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mhost.com.br"] [uri "/g3.php"] [unique_id "aoSDmGr_JutbFb-8svoKsgAAAcA"] [Tue Aug 18 13:08:56.737144 2026] [security2:error] [pid 167459:tid 167661] [client 172.213.243.2:14764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ws59.php"] [unique_id "aoSDmGr_JutbFb-8svoKtQAAAdc"] [Tue Aug 18 13:08:56.765213 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:56.765482 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:56.779786 2026] [security2:error] [pid 167459:tid 167616] [client 20.1.169.243:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/4mosan.php"] [unique_id "aoSDmGr_JutbFb-8svoKuQAAAao"] [Tue Aug 18 13:08:56.822625 2026] [security2:error] [pid 167459:tid 167646] [client 157.20.138.62:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmGr_JutbFb-8svoKugAAAcg"] [Tue Aug 18 13:08:56.822755 2026] [security2:error] [pid 167459:tid 167646] [client 157.20.138.62:58920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmGr_JutbFb-8svoKugAAAcg"] [Tue Aug 18 13:08:56.825989 2026] [security2:error] [pid 167459:tid 167647] [client 20.1.169.243:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/rk2.php"] [unique_id "aoSDmGr_JutbFb-8svoKuwAAAck"] [Tue Aug 18 13:08:56.863324 2026] [security2:error] [pid 167459:tid 167608] [client 74.7.241.191:48330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.rodrigodeboneimoveis.com.br"] [uri "/robots.txt"] [unique_id "aoSDmGr_JutbFb-8svoKvwAAAaI"] [Tue Aug 18 13:08:56.869404 2026] [security2:error] [pid 167459:tid 167709] [client 20.116.17.175:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/005.php"] [unique_id "aoSDmGr_JutbFb-8svoKwAAAAgc"] [Tue Aug 18 13:08:56.903849 2026] [security2:error] [pid 167459:tid 167678] [client 20.127.136.245:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/k.php"] [unique_id "aoSDmGr_JutbFb-8svoKwQAAAeg"] [Tue Aug 18 13:08:56.907177 2026] [security2:error] [pid 167459:tid 167615] [client 172.182.217.32:25662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/install.php"] [unique_id "aoSDmGr_JutbFb-8svoKwgAAAak"] [Tue Aug 18 13:08:56.945827 2026] [security2:error] [pid 167459:tid 167665] [client 20.116.17.175:22728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/term.php"] [unique_id "aoSDmGr_JutbFb-8svoKxAAAAds"] [Tue Aug 18 13:08:56.958234 2026] [security2:error] [pid 167459:tid 167656] [client 40.74.65.169:37383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/fling.php"] [unique_id "aoSDmGr_JutbFb-8svoKxQAAAdI"] [Tue Aug 18 13:08:56.973585 2026] [security2:error] [pid 167459:tid 167714] [client 20.25.139.174:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "aoSDmGr_JutbFb-8svoKxgAAAgw"] [Tue Aug 18 13:08:56.978447 2026] [security2:error] [pid 167459:tid 167651] [client 20.1.169.243:8955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/buy.php"] [unique_id "aoSDmGr_JutbFb-8svoKxwAAAc0"] [Tue Aug 18 13:08:56.990746 2026] [security2:error] [pid 167459:tid 167687] [client 74.248.133.44:56018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/02.php"] [unique_id "aoSDmGr_JutbFb-8svoKyAAAAfE"] [Tue Aug 18 13:08:57.063079 2026] [security2:error] [pid 167459:tid 167603] [client 158.23.17.4:40502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sy.php"] [unique_id "aoSDmWr_JutbFb-8svoKzAAAAZ0"] [Tue Aug 18 13:08:57.063675 2026] [security2:error] [pid 167459:tid 167624] [client 20.100.169.31:2619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDmWr_JutbFb-8svoKzQAAAbI"] [Tue Aug 18 13:08:57.066215 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:57.066505 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:57.074127 2026] [security2:error] [pid 167459:tid 167627] [client 172.202.39.151:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "aoSDmWr_JutbFb-8svoKzgAAAbU"] [Tue Aug 18 13:08:57.103625 2026] [security2:error] [pid 167459:tid 167676] [client 20.250.13.23:6026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDmWr_JutbFb-8svoK0QAAAeY"] [Tue Aug 18 13:08:57.148568 2026] [security2:error] [pid 167459:tid 167602] [client 52.173.121.69:28315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDmWr_JutbFb-8svoK0wAAAZw"] [Tue Aug 18 13:08:57.152835 2026] [security2:error] [pid 167459:tid 167629] [client 20.250.13.23:60373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-post.php"] [unique_id "aoSDmWr_JutbFb-8svoK1AAAAbc"] [Tue Aug 18 13:08:57.155944 2026] [security2:error] [pid 167459:tid 167628] [client 178.153.171.161:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmWr_JutbFb-8svoK1QAAAbY"] [Tue Aug 18 13:08:57.156082 2026] [security2:error] [pid 167459:tid 167628] [client 178.153.171.161:35037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmWr_JutbFb-8svoK1QAAAbY"] [Tue Aug 18 13:08:57.187169 2026] [security2:error] [pid 167459:tid 167716] [client 172.213.243.2:19742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/Ov-Simple1.php"] [unique_id "aoSDmWr_JutbFb-8svoK1gAAAg4"] [Tue Aug 18 13:08:57.188913 2026] [security2:error] [pid 167459:tid 167613] [client 20.1.169.243:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/storage/rip.php"] [unique_id "aoSDmWr_JutbFb-8svoK2AAAAac"] [Tue Aug 18 13:08:57.202972 2026] [security2:error] [pid 167459:tid 167683] [client 4.232.151.198:2310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/about.php"] [unique_id "aoSDmWr_JutbFb-8svoK2gAAAe0"] [Tue Aug 18 13:08:57.204152 2026] [security2:error] [pid 167459:tid 167655] [client 20.65.98.162:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/puc.php"] [unique_id "aoSDmWr_JutbFb-8svoK2wAAAdE"] [Tue Aug 18 13:08:57.206942 2026] [security2:error] [pid 167459:tid 167708] [client 20.104.100.201:13893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ws77.php"] [unique_id "aoSDmWr_JutbFb-8svoK3AAAAgY"] [Tue Aug 18 13:08:57.226969 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/504.php"] [unique_id "aoSDmWr_JutbFb-8svoK3gAAAeA"] [Tue Aug 18 13:08:57.241920 2026] [security2:error] [pid 167459:tid 167635] [client 74.248.130.103:31972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/ops.php"] [unique_id "aoSDmWr_JutbFb-8svoK3wAAAb0"] [Tue Aug 18 13:08:57.318574 2026] [security2:error] [pid 167459:tid 167606] [client 20.171.51.14:19594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/oo.php"] [unique_id "aoSDmWr_JutbFb-8svoK5AAAAaA"] [Tue Aug 18 13:08:57.346067 2026] [security2:error] [pid 167459:tid 167645] [client 20.1.169.243:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/bless.php"] [unique_id "aoSDmWr_JutbFb-8svoK5QAAAcc"] [Tue Aug 18 13:08:57.368371 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:57.368644 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:57.412036 2026] [security2:error] [pid 167459:tid 167679] [client 172.182.217.32:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/js/widgets/about.php7"] [unique_id "aoSDmWr_JutbFb-8svoK6QAAAek"] [Tue Aug 18 13:08:57.426002 2026] [security2:error] [pid 167459:tid 167623] [client 20.116.17.175:41512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/black.php"] [unique_id "aoSDmWr_JutbFb-8svoK6gAAAbE"] [Tue Aug 18 13:08:57.461293 2026] [security2:error] [pid 167459:tid 167702] [client 20.250.13.23:30293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDmWr_JutbFb-8svoK6wAAAgA"] [Tue Aug 18 13:08:57.488004 2026] [security2:error] [pid 167459:tid 167643] [client 20.104.100.201:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/fpwch.php"] [unique_id "aoSDmWr_JutbFb-8svoK7QAAAcU"] [Tue Aug 18 13:08:57.490937 2026] [security2:error] [pid 167459:tid 167500] [remote 162.241.152.27:57190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savvyoffshore.com.br"] [uri "/wp-login.php"] [unique_id "aoSDmWr_JutbFb-8svoK7gABpSg"] [Tue Aug 18 13:08:57.505743 2026] [security2:error] [pid 167459:tid 167650] [client 213.35.127.232:53419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDmWr_JutbFb-8svoK8AAAAcw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:57.523849 2026] [security2:error] [pid 167459:tid 167633] [client 20.226.36.136:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/Cachex.php"] [unique_id "aoSDmWr_JutbFb-8svoK8gAAAbs"] [Tue Aug 18 13:08:57.528567 2026] [security2:error] [pid 167459:tid 167585] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmWr_JutbFb-8svoK8wABqn0"] [Tue Aug 18 13:08:57.528754 2026] [security2:error] [pid 167459:tid 167616] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmWr_JutbFb-8svoK8wABqn0"] [Tue Aug 18 13:08:57.534981 2026] [security2:error] [pid 167459:tid 167712] [client 20.25.139.174:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/atomlib.php"] [unique_id "aoSDmWr_JutbFb-8svoK9AAAAgo"] [Tue Aug 18 13:08:57.552785 2026] [security2:error] [pid 167459:tid 167666] [client 20.1.169.243:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/tool.php"] [unique_id "aoSDmWr_JutbFb-8svoK9QAAAdw"] [Tue Aug 18 13:08:57.560529 2026] [security2:error] [pid 167459:tid 167647] [client 158.23.17.4:20635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/57.php"] [unique_id "aoSDmWr_JutbFb-8svoK9gAAAck"] [Tue Aug 18 13:08:57.563406 2026] [security2:error] [pid 167459:tid 167642] [client 68.155.154.236:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/kopyw.php"] [unique_id "aoSDmWr_JutbFb-8svoK9wAAAcQ"] [Tue Aug 18 13:08:57.563511 2026] [security2:error] [pid 167459:tid 167652] [client 172.202.39.151:27871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/ok.php"] [unique_id "aoSDmWr_JutbFb-8svoK-AAAAc4"] [Tue Aug 18 13:08:57.599662 2026] [security2:error] [pid 167459:tid 167662] [client 20.1.169.243:10486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/7.php"] [unique_id "aoSDmWr_JutbFb-8svoK_AAAAdg"] [Tue Aug 18 13:08:57.637673 2026] [security2:error] [pid 167459:tid 167705] [client 172.213.243.2:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSDmWr_JutbFb-8svoK_gAAAgM"] [Tue Aug 18 13:08:57.670098 2026] [authz_core:error] [pid 167459:tid 167507] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:57.670549 2026] [authz_core:error] [pid 167459:tid 167507] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:57.702242 2026] [security2:error] [pid 167459:tid 167620] [client 20.100.169.31:2916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/akc.php"] [unique_id "aoSDmWr_JutbFb-8svoLBAAAAa4"] [Tue Aug 18 13:08:57.708856 2026] [security2:error] [pid 167459:tid 167592] [client 20.1.169.243:8916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDmWr_JutbFb-8svoLBQAAAZI"] [Tue Aug 18 13:08:57.714694 2026] [security2:error] [pid 167459:tid 167713] [client 20.250.13.23:5893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/cjfuns.php"] [unique_id "aoSDmWr_JutbFb-8svoLBgAAAgs"] [Tue Aug 18 13:08:57.746163 2026] [security2:error] [pid 167459:tid 167654] [client 52.173.121.69:28309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDmWr_JutbFb-8svoLCAAAAdA"] [Tue Aug 18 13:08:57.754852 2026] [security2:error] [pid 167459:tid 167676] [client 40.74.65.169:36971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/zoo1.php"] [unique_id "aoSDmWr_JutbFb-8svoLCQAAAeY"] [Tue Aug 18 13:08:57.766484 2026] [security2:error] [pid 167459:tid 167595] [client 74.7.175.154:54064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sengerclimatizacao.com.br"] [uri "/index.php"] [unique_id "aoSDmWr_JutbFb-8svoK4QABlTQ"] [Tue Aug 18 13:08:57.769457 2026] [security2:error] [pid 167459:tid 167608] [client 20.250.13.23:5946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSDmWr_JutbFb-8svoLCwAAAaI"] [Tue Aug 18 13:08:57.788736 2026] [security2:error] [pid 167459:tid 167629] [client 158.23.17.4:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/74.php"] [unique_id "aoSDmWr_JutbFb-8svoLDQAAAbc"] [Tue Aug 18 13:08:57.831558 2026] [security2:error] [pid 167459:tid 167653] [client 4.232.151.198:2347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDmWr_JutbFb-8svoLDgAAAc8"] [Tue Aug 18 13:08:57.832149 2026] [security2:error] [pid 167459:tid 167657] [client 20.226.36.136:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDmWr_JutbFb-8svoLDwAAAdM"] [Tue Aug 18 13:08:57.833217 2026] [security2:error] [pid 167459:tid 167656] [client 185.246.188.73:59118] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 73.188.246.185.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDmWr_JutbFb-8svoLAQAAAdI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:08:57.833306 2026] [security2:error] [pid 167459:tid 167656] [client 185.246.188.73:59118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDmWr_JutbFb-8svoLAQAAAdI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:08:57.902420 2026] [security2:error] [pid 167459:tid 167607] [client 172.182.217.32:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "aoSDmWr_JutbFb-8svoLEwAAAaE"] [Tue Aug 18 13:08:57.921255 2026] [security2:error] [pid 167459:tid 167628] [client 20.1.169.243:5811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/twentytwenty/functions.php"] [unique_id "aoSDmWr_JutbFb-8svoLFQAAAbY"] [Tue Aug 18 13:08:57.950485 2026] [security2:error] [pid 167459:tid 167696] [client 20.116.17.175:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/v2.php"] [unique_id "aoSDmWr_JutbFb-8svoLFwAAAfo"] [Tue Aug 18 13:08:57.968647 2026] [security2:error] [pid 167459:tid 167632] [client 20.1.169.243:10487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/8.php"] [unique_id "aoSDmWr_JutbFb-8svoLGQAAAbo"] [Tue Aug 18 13:08:57.968747 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:57.969017 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:57.982652 2026] [security2:error] [pid 167459:tid 167663] [client 20.104.100.201:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/read.php"] [unique_id "aoSDmWr_JutbFb-8svoLGwAAAdk"] [Tue Aug 18 13:08:57.993901 2026] [security2:error] [pid 167459:tid 167685] [client 20.116.17.175:22675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/as.php"] [unique_id "aoSDmWr_JutbFb-8svoLHQAAAe8"] [Tue Aug 18 13:08:58.048258 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:44064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/vx.php"] [unique_id "aoSDmmr_JutbFb-8svoLHwAAAfY"] [Tue Aug 18 13:08:58.072741 2026] [security2:error] [pid 167459:tid 167660] [client 20.25.139.174:4694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/rip.php"] [unique_id "aoSDmmr_JutbFb-8svoLIAAAAdY"] [Tue Aug 18 13:08:58.081878 2026] [security2:error] [pid 167459:tid 167625] [client 172.213.243.2:19534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/vx.php"] [unique_id "aoSDmmr_JutbFb-8svoLIQAAAbM"] [Tue Aug 18 13:08:58.131134 2026] [security2:error] [pid 167459:tid 167623] [client 74.248.130.103:45802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/coffexium.php"] [unique_id "aoSDmmr_JutbFb-8svoLJAAAAbE"] [Tue Aug 18 13:08:58.141146 2026] [fcgid:warn] [pid 167459:tid 167596] (70014)End of file found: [client 66.132.195.60:49882] mod_fcgid: can't get data from http client [Tue Aug 18 13:08:58.144930 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:8921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/cache.php"] [unique_id "aoSDmmr_JutbFb-8svoLJgAAAgQ"] [Tue Aug 18 13:08:58.148315 2026] [security2:error] [pid 167459:tid 167681] [client 20.151.109.219:36207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/vd.php"] [unique_id "aoSDmmr_JutbFb-8svoLJwAAAes"] [Tue Aug 18 13:08:58.168478 2026] [security2:error] [pid 167459:tid 167672] [client 158.23.17.4:7357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ah.php"] [unique_id "aoSDmmr_JutbFb-8svoLKAAAAeI"] [Tue Aug 18 13:08:58.233008 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:25376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vm.php"] [unique_id "aoSDmmr_JutbFb-8svoLKgAAAaU"] [Tue Aug 18 13:08:58.271176 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:58.271454 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:58.285637 2026] [security2:error] [pid 167459:tid 167667] [client 20.1.169.243:5760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin.php"] [unique_id "aoSDmmr_JutbFb-8svoLLAAAAd0"] [Tue Aug 18 13:08:58.295541 2026] [security2:error] [pid 167459:tid 167666] [client 20.127.136.245:10804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSDmmr_JutbFb-8svoLLQAAAdw"] [Tue Aug 18 13:08:58.327005 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:14071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/av.php"] [unique_id "aoSDmmr_JutbFb-8svoLMAAAAc4"] [Tue Aug 18 13:08:58.340312 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:10176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/82.php"] [unique_id "aoSDmmr_JutbFb-8svoLMQAAAcU"] [Tue Aug 18 13:08:58.350178 2026] [security2:error] [pid 167459:tid 167686] [client 20.250.13.23:18195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSDmmr_JutbFb-8svoLMgAAAfA"] [Tue Aug 18 13:08:58.382256 2026] [security2:error] [pid 167459:tid 167715] [client 20.100.169.31:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/buy.php"] [unique_id "aoSDmmr_JutbFb-8svoLNAAAAg0"] [Tue Aug 18 13:08:58.385155 2026] [security2:error] [pid 167459:tid 167702] [client 20.250.13.23:18236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSDmmr_JutbFb-8svoLNgAAAgA"] [Tue Aug 18 13:08:58.385197 2026] [security2:error] [pid 167459:tid 167700] [client 20.116.17.175:22712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/pucci.php"] [unique_id "aoSDmmr_JutbFb-8svoLNQAAAf4"] [Tue Aug 18 13:08:58.396254 2026] [security2:error] [pid 167459:tid 167674] [client 172.182.217.32:25631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDmmr_JutbFb-8svoLNwAAAeQ"] [Tue Aug 18 13:08:58.417840 2026] [security2:error] [pid 167459:tid 167716] [client 114.5.214.109:50420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmmr_JutbFb-8svoLOgAAAg4"] [Tue Aug 18 13:08:58.424307 2026] [security2:error] [pid 167459:tid 167631] [client 20.226.36.136:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDmmr_JutbFb-8svoLOwAAAbk"] [Tue Aug 18 13:08:58.433567 2026] [security2:error] [pid 167459:tid 167716] [client 114.5.214.109:50420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDmmr_JutbFb-8svoLOgAAAg4"] [Tue Aug 18 13:08:58.472013 2026] [security2:error] [pid 167459:tid 167697] [client 52.173.121.69:36586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDmmr_JutbFb-8svoLPQAAAfs"] [Tue Aug 18 13:08:58.486521 2026] [security2:error] [pid 167459:tid 167641] [client 4.232.151.198:2352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors.php"] [unique_id "aoSDmmr_JutbFb-8svoLPgAAAcM"] [Tue Aug 18 13:08:58.490107 2026] [security2:error] [pid 167459:tid 167593] [client 20.171.51.14:21611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ja.php"] [unique_id "aoSDmmr_JutbFb-8svoLQAAAAZM"] [Tue Aug 18 13:08:58.495154 2026] [security2:error] [pid 167459:tid 167639] [client 40.74.65.169:37423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/zoo2.php"] [unique_id "aoSDmmr_JutbFb-8svoLQQAAAcE"] [Tue Aug 18 13:08:58.509948 2026] [security2:error] [pid 167459:tid 167640] [client 20.1.169.243:8927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/content.php"] [unique_id "aoSDmmr_JutbFb-8svoLQwAAAcI"] [Tue Aug 18 13:08:58.512280 2026] [security2:error] [pid 167459:tid 167603] [client 172.213.243.2:18589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ah25.php"] [unique_id "aoSDmmr_JutbFb-8svoLRAAAAZ0"] [Tue Aug 18 13:08:58.536780 2026] [security2:error] [pid 167459:tid 167605] [client 213.35.127.232:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDmmr_JutbFb-8svoLRQAAAZ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:58.578452 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:58.578710 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:58.594295 2026] [security2:error] [pid 167459:tid 167705] [client 20.25.139.174:4531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/p.php"] [unique_id "aoSDmmr_JutbFb-8svoLSAAAAgM"] [Tue Aug 18 13:08:58.649118 2026] [security2:error] [pid 167459:tid 167624] [client 20.1.169.243:5347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDmmr_JutbFb-8svoLSQAAAbI"] [Tue Aug 18 13:08:58.687833 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.36.136:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDmmr_JutbFb-8svoLSwAAAc8"] [Tue Aug 18 13:08:58.709695 2026] [security2:error] [pid 167459:tid 167708] [client 20.226.36.136:48871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDmmr_JutbFb-8svoLTAAAAgY"] [Tue Aug 18 13:08:58.727015 2026] [security2:error] [pid 167459:tid 167704] [client 20.226.36.136:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDmmr_JutbFb-8svoLTQAAAgI"] [Tue Aug 18 13:08:58.752676 2026] [security2:error] [pid 167459:tid 167607] [client 20.65.98.162:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/19.php"] [unique_id "aoSDmmr_JutbFb-8svoLTgAAAaE"] [Tue Aug 18 13:08:58.758397 2026] [security2:error] [pid 167459:tid 167688] [client 74.248.18.37:49734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/155.php"] [unique_id "aoSDmmr_JutbFb-8svoLTwAAAfI"] [Tue Aug 18 13:08:58.763955 2026] [security2:error] [pid 167459:tid 167669] [client 20.226.36.136:65336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDmmr_JutbFb-8svoLUgAAAd8"] [Tue Aug 18 13:08:58.770020 2026] [security2:error] [pid 167459:tid 167617] [client 20.1.169.243:10192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/a.php"] [unique_id "aoSDmmr_JutbFb-8svoLUwAAAas"] [Tue Aug 18 13:08:58.781909 2026] [security2:error] [pid 167459:tid 167632] [client 158.23.17.4:7321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vw.php"] [unique_id "aoSDmmr_JutbFb-8svoLVAAAAbo"] [Tue Aug 18 13:08:58.798508 2026] [security2:error] [pid 167459:tid 167703] [client 20.116.17.175:44706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wkl.php"] [unique_id "aoSDmmr_JutbFb-8svoLVgAAAgE"] [Tue Aug 18 13:08:58.818913 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/albin.php"] [unique_id "aoSDmmr_JutbFb-8svoLVwAAAcc"] [Tue Aug 18 13:08:58.825023 2026] [security2:error] [pid 167459:tid 167671] [client 20.226.36.136:65337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDmmr_JutbFb-8svoLWAAAAeE"] [Tue Aug 18 13:08:58.831913 2026] [security2:error] [pid 167459:tid 167595] [client 20.250.13.23:9200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/h.php"] [unique_id "aoSDmmr_JutbFb-8svoLWQAAAZU"] [Tue Aug 18 13:08:58.837190 2026] [security2:error] [pid 167459:tid 167599] [client 74.248.133.44:56005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/menu.php"] [unique_id "aoSDmmr_JutbFb-8svoLWwAAAZk"] [Tue Aug 18 13:08:58.850426 2026] [security2:error] [pid 167459:tid 167660] [client 20.151.109.219:38160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/56.php"] [unique_id "aoSDmmr_JutbFb-8svoLXAAAAdY"] [Tue Aug 18 13:08:58.873043 2026] [security2:error] [pid 167459:tid 167634] [client 20.116.17.175:41476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wicked.php"] [unique_id "aoSDmmr_JutbFb-8svoLYAAAAbw"] [Tue Aug 18 13:08:58.873344 2026] [authz_core:error] [pid 167459:tid 167575] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:58.873595 2026] [authz_core:error] [pid 167459:tid 167575] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:58.875027 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:8945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDmmr_JutbFb-8svoLYQAAAZs"] [Tue Aug 18 13:08:58.891429 2026] [security2:error] [pid 167459:tid 167670] [client 172.182.217.32:25648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "aoSDmmr_JutbFb-8svoLYgAAAeA"] [Tue Aug 18 13:08:58.927034 2026] [security2:error] [pid 167459:tid 167650] [client 172.213.243.2:15086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/tt.php"] [unique_id "aoSDmmr_JutbFb-8svoLZAAAAcw"] [Tue Aug 18 13:08:58.940342 2026] [security2:error] [pid 167459:tid 167616] [client 172.202.39.151:27840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.solucaoparapocos.com.br"] [uri "/item.php"] [unique_id "aoSDmmr_JutbFb-8svoLZgAAAao"] [Tue Aug 18 13:08:58.964799 2026] [security2:error] [pid 167459:tid 167658] [client 20.250.13.23:18216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSDmmr_JutbFb-8svoLaAAAAdQ"] [Tue Aug 18 13:08:59.004514 2026] [security2:error] [pid 167459:tid 167663] [client 20.100.169.31:2583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/cong.php"] [unique_id "aoSDm2r_JutbFb-8svoLagAAAdk"] [Tue Aug 18 13:08:59.005802 2026] [security2:error] [pid 167459:tid 167709] [client 20.226.36.136:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDm2r_JutbFb-8svoLawAAAgc"] [Tue Aug 18 13:08:59.007496 2026] [security2:error] [pid 167459:tid 167619] [client 20.250.13.23:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDm2r_JutbFb-8svoLbAAAAa0"] [Tue Aug 18 13:08:59.067317 2026] [security2:error] [pid 167459:tid 167678] [client 74.248.130.103:28954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDm2r_JutbFb-8svoLcAAAAeg"] [Tue Aug 18 13:08:59.084244 2026] [security2:error] [pid 167459:tid 167612] [client 20.226.36.136:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDm2r_JutbFb-8svoLcgAAAaY"] [Tue Aug 18 13:08:59.105380 2026] [security2:error] [pid 167459:tid 167687] [client 4.232.151.198:21758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wap.php"] [unique_id "aoSDm2r_JutbFb-8svoLcwAAAfE"] [Tue Aug 18 13:08:59.133792 2026] [security2:error] [pid 167459:tid 167675] [client 20.226.36.136:62154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDm2r_JutbFb-8svoLdwAAAeU"] [Tue Aug 18 13:08:59.137662 2026] [security2:error] [pid 167459:tid 167702] [client 20.1.169.243:10478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/aa.php"] [unique_id "aoSDm2r_JutbFb-8svoLeAAAAgA"] [Tue Aug 18 13:08:59.145523 2026] [security2:error] [pid 167459:tid 167712] [client 20.25.139.174:4649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.139.25.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mocarzel.eng.br"] [uri "/php.php"] [unique_id "aoSDm2r_JutbFb-8svoLegAAAgo"] [Tue Aug 18 13:08:59.173917 2026] [authz_core:error] [pid 167459:tid 167490] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:59.174163 2026] [authz_core:error] [pid 167459:tid 167490] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:59.181127 2026] [security2:error] [pid 167459:tid 167690] [client 20.226.36.136:47945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDm2r_JutbFb-8svoLfQAAAfQ"] [Tue Aug 18 13:08:59.191353 2026] [security2:error] [pid 167459:tid 167594] [client 40.74.65.169:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/org.php"] [unique_id "aoSDm2r_JutbFb-8svoLfgAAAZQ"] [Tue Aug 18 13:08:59.220363 2026] [security2:error] [pid 167459:tid 167684] [client 20.226.36.136:62196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDm2r_JutbFb-8svoLgAAAAe4"] [Tue Aug 18 13:08:59.261586 2026] [security2:error] [pid 167459:tid 167680] [client 20.1.169.243:5319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDm2r_JutbFb-8svoLhAAAAeo"] [Tue Aug 18 13:08:59.265691 2026] [security2:error] [pid 167459:tid 167713] [client 20.1.169.243:8929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/css.php"] [unique_id "aoSDm2r_JutbFb-8svoLiAAAAgs"] [Tue Aug 18 13:08:59.268055 2026] [security2:error] [pid 167459:tid 167600] [client 138.36.100.162:43244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDm2r_JutbFb-8svoLiQAAAZo"] [Tue Aug 18 13:08:59.268131 2026] [security2:error] [pid 167459:tid 167600] [client 138.36.100.162:43244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDm2r_JutbFb-8svoLiQAAAZo"] [Tue Aug 18 13:08:59.279526 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.36.136:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDm2r_JutbFb-8svoLiwAAAc8"] [Tue Aug 18 13:08:59.317314 2026] [security2:error] [pid 167459:tid 167655] [client 20.226.36.136:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDm2r_JutbFb-8svoLjgAAAdE"] [Tue Aug 18 13:08:59.342591 2026] [security2:error] [pid 167459:tid 167637] [client 172.213.243.2:14738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xqq.php"] [unique_id "aoSDm2r_JutbFb-8svoLjwAAAb8"] [Tue Aug 18 13:08:59.348203 2026] [http2:warn] [pid 157386:tid 157626] [client 17.246.19.48:44418] h2_stream(157386-1082-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:08:59.355122 2026] [security2:error] [pid 167459:tid 167704] [client 20.116.17.175:22701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/water.php"] [unique_id "aoSDm2r_JutbFb-8svoLkAAAAgI"] [Tue Aug 18 13:08:59.378707 2026] [security2:error] [pid 167459:tid 167705] [client 172.182.217.32:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/classwithtostring.php"] [unique_id "aoSDm2r_JutbFb-8svoLkQAAAgM"] [Tue Aug 18 13:08:59.389834 2026] [security2:error] [pid 167459:tid 167688] [client 4.232.151.198:2348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDm2r_JutbFb-8svoLkgAAAfI"] [Tue Aug 18 13:08:59.394447 2026] [security2:error] [pid 167459:tid 167613] [client 178.156.185.127:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bn2s.com.br"] [uri "/index.php"] [unique_id "aoSDm2r_JutbFb-8svoLhgAAAac"], referer: https://bn2s.com.br/ [Tue Aug 18 13:08:59.397015 2026] [security2:error] [pid 167459:tid 167628] [client 20.127.136.245:4965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/system_log.php"] [unique_id "aoSDm2r_JutbFb-8svoLkwAAAbY"] [Tue Aug 18 13:08:59.436221 2026] [security2:error] [pid 167459:tid 167710] [client 158.23.17.4:63000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ag.php"] [unique_id "aoSDm2r_JutbFb-8svoLlQAAAgg"] [Tue Aug 18 13:08:59.463558 2026] [security2:error] [pid 167459:tid 167714] [client 213.202.253.4:52112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/filefuns.php"] [unique_id "aoSDm2r_JutbFb-8svoLlgAAAgw"], referer: www.google.com [Tue Aug 18 13:08:59.476067 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:59.476342 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:59.507643 2026] [security2:error] [pid 167459:tid 167635] [client 20.1.169.243:10455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/aaa.php"] [unique_id "aoSDm2r_JutbFb-8svoLmQAAAb0"] [Tue Aug 18 13:08:59.551598 2026] [security2:error] [pid 167459:tid 167676] [client 213.35.127.232:53811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDm2r_JutbFb-8svoLnAAAAeY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:08:59.575688 2026] [security2:error] [pid 167459:tid 167649] [client 158.23.17.4:15763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/eg.php"] [unique_id "aoSDm2r_JutbFb-8svoLnQAAAcs"] [Tue Aug 18 13:08:59.613531 2026] [security2:error] [pid 167459:tid 167693] [client 20.250.13.23:5920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/import.php"] [unique_id "aoSDm2r_JutbFb-8svoLnwAAAfc"] [Tue Aug 18 13:08:59.633057 2026] [security2:error] [pid 167459:tid 167677] [client 20.226.36.136:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDm2r_JutbFb-8svoLoQAAAec"] [Tue Aug 18 13:08:59.635185 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:8899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/chosen.php"] [unique_id "aoSDm2r_JutbFb-8svoLogAAAfM"] [Tue Aug 18 13:08:59.643233 2026] [security2:error] [pid 167459:tid 167632] [client 20.250.13.23:18237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/cjfuns.php"] [unique_id "aoSDm2r_JutbFb-8svoLowAAAbo"] [Tue Aug 18 13:08:59.663841 2026] [security2:error] [pid 167459:tid 167641] [client 197.184.64.235:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDm2r_JutbFb-8svoLpAAAAcM"] [Tue Aug 18 13:08:59.663935 2026] [security2:error] [pid 167459:tid 167641] [client 197.184.64.235:42696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDm2r_JutbFb-8svoLpAAAAcM"] [Tue Aug 18 13:08:59.691773 2026] [security2:error] [pid 167459:tid 167669] [client 20.100.169.31:2942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSDm2r_JutbFb-8svoLpwAAAd8"] [Tue Aug 18 13:08:59.695207 2026] [security2:error] [pid 167459:tid 167667] [client 74.249.206.207:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/82.php"] [unique_id "aoSDm2r_JutbFb-8svoLqAAAAd0"] [Tue Aug 18 13:08:59.730650 2026] [security2:error] [pid 167459:tid 167666] [client 158.23.17.4:7304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lj.php"] [unique_id "aoSDm2r_JutbFb-8svoLqgAAAdw"] [Tue Aug 18 13:08:59.754412 2026] [security2:error] [pid 167459:tid 167715] [client 172.213.243.2:19560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/06.php"] [unique_id "aoSDm2r_JutbFb-8svoLrAAAAg0"] [Tue Aug 18 13:08:59.767827 2026] [security2:error] [pid 167459:tid 167674] [client 20.116.17.175:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-asudo.php"] [unique_id "aoSDm2r_JutbFb-8svoLrgAAAeQ"] [Tue Aug 18 13:08:59.774983 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:08:59.775259 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:08:59.794893 2026] [security2:error] [pid 167459:tid 167699] [client 20.116.17.175:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/fine.php"] [unique_id "aoSDm2r_JutbFb-8svoLsAAAAf0"] [Tue Aug 18 13:08:59.829619 2026] [security2:error] [pid 167459:tid 167644] [client 20.104.100.201:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/fw/34.php"] [unique_id "aoSDm2r_JutbFb-8svoLswAAAcY"] [Tue Aug 18 13:08:59.831487 2026] [security2:error] [pid 167459:tid 167645] [client 74.248.133.44:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/spip.php"] [unique_id "aoSDm2r_JutbFb-8svoLtAAAAcc"] [Tue Aug 18 13:08:59.866976 2026] [security2:error] [pid 167459:tid 167647] [client 172.182.217.32:25562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/cong.php"] [unique_id "aoSDm2r_JutbFb-8svoLtgAAAck"] [Tue Aug 18 13:08:59.878982 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/aar.php"] [unique_id "aoSDm2r_JutbFb-8svoLuQAAAfA"] [Tue Aug 18 13:08:59.893158 2026] [security2:error] [pid 167459:tid 167702] [client 20.151.109.219:20987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/rx.php"] [unique_id "aoSDm2r_JutbFb-8svoLugAAAgA"] [Tue Aug 18 13:08:59.905033 2026] [security2:error] [pid 167459:tid 167712] [client 74.248.130.103:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/sf.php"] [unique_id "aoSDm2r_JutbFb-8svoLuwAAAgo"] [Tue Aug 18 13:08:59.914078 2026] [security2:error] [pid 167459:tid 167656] [client 136.144.35.203:60673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "usebluelord.com"] [uri "/wp-login.php"] [unique_id "aoSDm2r_JutbFb-8svoLvAAAAdI"] [Tue Aug 18 13:08:59.914504 2026] [security2:error] [pid 167459:tid 167627] [client 40.74.65.169:37417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/imageskir.php"] [unique_id "aoSDm2r_JutbFb-8svoLvQAAAbU"] [Tue Aug 18 13:08:59.952699 2026] [security2:error] [pid 167459:tid 167618] [client 20.104.100.201:53289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/mg.php"] [unique_id "aoSDm2r_JutbFb-8svoLwAAAAaw"] [Tue Aug 18 13:08:59.972633 2026] [security2:error] [pid 167459:tid 167590] [client 40.74.65.169:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDm2r_JutbFb-8svoLwQAAAZA"] [Tue Aug 18 13:08:59.996868 2026] [security2:error] [pid 167459:tid 167636] [client 20.1.169.243:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/Text/Diff/Engine.php"] [unique_id "aoSDm2r_JutbFb-8svoLwgAAAb4"] [Tue Aug 18 13:08:59.999507 2026] [security2:error] [pid 167459:tid 167640] [client 20.1.169.243:9540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/doc.php"] [unique_id "aoSDm2r_JutbFb-8svoLwwAAAcI"] [Tue Aug 18 13:09:00.081970 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:00.082238 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:00.103954 2026] [security2:error] [pid 167459:tid 167593] [client 4.232.151.198:2340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/cloud.php"] [unique_id "aoSDnGr_JutbFb-8svoLxwAAAZM"] [Tue Aug 18 13:09:00.122306 2026] [fcgid:warn] [pid 167459:tid 167683] (70014)End of file found: [client 66.132.195.49:39142] mod_fcgid: can't get data from http client [Tue Aug 18 13:09:00.163211 2026] [security2:error] [pid 167459:tid 167682] [client 20.116.17.175:41532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/loader.php"] [unique_id "aoSDnGr_JutbFb-8svoLywAAAew"] [Tue Aug 18 13:09:00.188663 2026] [security2:error] [pid 167459:tid 167607] [client 172.213.243.2:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/166.php"] [unique_id "aoSDnGr_JutbFb-8svoLzAAAAaE"] [Tue Aug 18 13:09:00.228746 2026] [security2:error] [pid 167459:tid 167672] [client 20.250.13.23:5914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/cropper.php"] [unique_id "aoSDnGr_JutbFb-8svoLzwAAAeI"] [Tue Aug 18 13:09:00.246226 2026] [security2:error] [pid 167459:tid 167602] [client 20.1.169.243:9672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/ab.php"] [unique_id "aoSDnGr_JutbFb-8svoL0AAAAZw"] [Tue Aug 18 13:09:00.256802 2026] [security2:error] [pid 167459:tid 167642] [client 20.250.13.23:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSDnGr_JutbFb-8svoL0QAAAcQ"] [Tue Aug 18 13:09:00.317523 2026] [security2:error] [pid 167459:tid 167657] [client 20.100.169.31:49412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/db.php"] [unique_id "aoSDnGr_JutbFb-8svoL2AAAAdM"] [Tue Aug 18 13:09:00.358821 2026] [security2:error] [pid 167459:tid 167662] [client 172.182.217.32:4091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/index.php.suspected"] [unique_id "aoSDnGr_JutbFb-8svoL2gAAAdg"] [Tue Aug 18 13:09:00.378295 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:00.378561 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:00.404013 2026] [security2:error] [pid 167459:tid 167622] [client 20.1.169.243:8941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/elp.php"] [unique_id "aoSDnGr_JutbFb-8svoL4AAAAbA"] [Tue Aug 18 13:09:00.412830 2026] [security2:error] [pid 167459:tid 167667] [client 158.23.17.4:39145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kh.php"] [unique_id "aoSDnGr_JutbFb-8svoL4gAAAd0"] [Tue Aug 18 13:09:00.450963 2026] [security2:error] [pid 167459:tid 167643] [client 52.173.121.69:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDnGr_JutbFb-8svoL6AAAAcU"] [Tue Aug 18 13:09:00.459782 2026] [security2:error] [pid 167459:tid 167715] [client 158.23.17.4:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/uk.php"] [unique_id "aoSDnGr_JutbFb-8svoL7wAAAg0"] [Tue Aug 18 13:09:00.472683 2026] [security2:error] [pid 167459:tid 167615] [client 20.65.98.162:53571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/133.php"] [unique_id "aoSDnGr_JutbFb-8svoL8QAAAak"] [Tue Aug 18 13:09:00.540489 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDnGr_JutbFb-8svoL9wAAAcc"] [Tue Aug 18 13:09:00.568530 2026] [security2:error] [pid 167459:tid 167605] [client 213.35.127.232:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDnGr_JutbFb-8svoL-AAAAZ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:00.600752 2026] [security2:error] [pid 167459:tid 167686] [client 172.213.243.2:14723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/snq.php"] [unique_id "aoSDnGr_JutbFb-8svoL-wAAAfA"] [Tue Aug 18 13:09:00.623778 2026] [security2:error] [pid 167459:tid 167670] [client 74.248.18.37:14427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/96i.php"] [unique_id "aoSDnGr_JutbFb-8svoL_QAAAeA"] [Tue Aug 18 13:09:00.634275 2026] [security2:error] [pid 167459:tid 167696] [client 20.1.169.243:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/abc.php"] [unique_id "aoSDnGr_JutbFb-8svoL_gAAAfo"] [Tue Aug 18 13:09:00.654846 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/az.php"] [unique_id "aoSDnGr_JutbFb-8svoMAAAAAdI"] [Tue Aug 18 13:09:00.659517 2026] [security2:error] [pid 167459:tid 167627] [client 68.155.154.236:25368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/zznmg.php"] [unique_id "aoSDnGr_JutbFb-8svoMAQAAAbU"] [Tue Aug 18 13:09:00.684824 2026] [security2:error] [pid 167459:tid 167598] [client 196.12.128.158:55036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDnGr_JutbFb-8svoMBAAAAZg"] [Tue Aug 18 13:09:00.684938 2026] [security2:error] [pid 167459:tid 167598] [client 196.12.128.158:55036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDnGr_JutbFb-8svoMBAAAAZg"] [Tue Aug 18 13:09:00.685366 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:00.685636 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:00.731885 2026] [security2:error] [pid 167459:tid 167684] [client 40.74.65.169:20773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/indexo.php"] [unique_id "aoSDnGr_JutbFb-8svoMBwAAAe4"] [Tue Aug 18 13:09:00.734234 2026] [security2:error] [pid 167459:tid 167679] [client 74.248.133.44:48929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/ab1ux1ft.php"] [unique_id "aoSDnGr_JutbFb-8svoMCAAAAek"] [Tue Aug 18 13:09:00.738565 2026] [security2:error] [pid 167459:tid 167590] [client 20.1.169.243:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-mail.php"] [unique_id "aoSDnGr_JutbFb-8svoMCQAAAZA"] [Tue Aug 18 13:09:00.765323 2026] [security2:error] [pid 167459:tid 167597] [client 40.74.65.169:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDnGr_JutbFb-8svoMCwAAAZc"] [Tue Aug 18 13:09:00.768749 2026] [security2:error] [pid 167459:tid 167624] [client 20.116.17.175:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/zero.php"] [unique_id "aoSDnGr_JutbFb-8svoMDAAAAbI"] [Tue Aug 18 13:09:00.768832 2026] [security2:error] [pid 167459:tid 167698] [client 20.1.169.243:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/Exception-class.php"] [unique_id "aoSDnGr_JutbFb-8svoMDQAAAfw"] [Tue Aug 18 13:09:00.827395 2026] [security2:error] [pid 167459:tid 167592] [client 4.232.151.198:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "aoSDnGr_JutbFb-8svoMDwAAAZI"] [Tue Aug 18 13:09:00.829765 2026] [security2:error] [pid 167459:tid 167680] [client 168.62.48.100:16507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDnGr_JutbFb-8svoMEAAAAeo"] [Tue Aug 18 13:09:00.841748 2026] [security2:error] [pid 167459:tid 167600] [client 20.206.73.37:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/nano.php"] [unique_id "aoSDnGr_JutbFb-8svoMEQAAAZo"] [Tue Aug 18 13:09:00.847252 2026] [security2:error] [pid 167459:tid 167611] [client 20.250.13.23:18422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSDnGr_JutbFb-8svoMEgAAAaU"] [Tue Aug 18 13:09:00.853911 2026] [security2:error] [pid 167459:tid 167685] [client 172.182.217.32:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/layout.php"] [unique_id "aoSDnGr_JutbFb-8svoMEwAAAe8"] [Tue Aug 18 13:09:00.890045 2026] [security2:error] [pid 167459:tid 167594] [client 20.250.13.23:18202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSDnGr_JutbFb-8svoMFgAAAZQ"] [Tue Aug 18 13:09:00.945113 2026] [security2:error] [pid 167459:tid 167607] [client 74.248.130.103:31968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/k.php"] [unique_id "aoSDnGr_JutbFb-8svoMGAAAAaE"] [Tue Aug 18 13:09:00.981015 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:00.981296 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:00.981528 2026] [security2:error] [pid 167459:tid 167672] [client 185.246.188.73:59132] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 73.188.246.185.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDnGr_JutbFb-8svoMIwAAAeI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:00.981599 2026] [security2:error] [pid 167459:tid 167672] [client 185.246.188.73:59132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDnGr_JutbFb-8svoMIwAAAeI"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:01.000060 2026] [security2:error] [pid 167459:tid 167636] [client 20.100.169.31:2611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/dropdown.php"] [unique_id "aoSDnGr_JutbFb-8svoMJwAAAb4"] [Tue Aug 18 13:09:01.003432 2026] [security2:error] [pid 167459:tid 167593] [client 20.1.169.243:10462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/abcd.php"] [unique_id "aoSDnWr_JutbFb-8svoMKAAAAZM"] [Tue Aug 18 13:09:01.004644 2026] [authz_core:error] [pid 167459:tid 167530] [remote 57.141.22.99:55232] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:01.004904 2026] [authz_core:error] [pid 167459:tid 167530] [remote 57.141.22.99:55232] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:01.010585 2026] [security2:error] [pid 167459:tid 167701] [client 172.213.243.2:19757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-access.php"] [unique_id "aoSDnWr_JutbFb-8svoMKQAAAf8"] [Tue Aug 18 13:09:01.013001 2026] [security2:error] [pid 167459:tid 167676] [client 20.127.136.245:4987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/x.php"] [unique_id "aoSDnWr_JutbFb-8svoMKgAAAeY"] [Tue Aug 18 13:09:01.015167 2026] [security2:error] [pid 167459:tid 167634] [client 158.23.17.4:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/jb.php"] [unique_id "aoSDnWr_JutbFb-8svoMKwAAAbw"] [Tue Aug 18 13:09:01.033059 2026] [security2:error] [pid 167459:tid 167629] [client 20.104.100.201:13914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp9.php"] [unique_id "aoSDnWr_JutbFb-8svoMLwAAAbc"] [Tue Aug 18 13:09:01.080505 2026] [security2:error] [pid 167459:tid 167693] [client 168.62.48.100:16403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDnWr_JutbFb-8svoMMgAAAfc"] [Tue Aug 18 13:09:01.101285 2026] [security2:error] [pid 167459:tid 167635] [client 20.1.169.243:5370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-the.php"] [unique_id "aoSDnWr_JutbFb-8svoMMwAAAb0"] [Tue Aug 18 13:09:01.109457 2026] [security2:error] [pid 167459:tid 167650] [client 158.23.17.4:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ig.php"] [unique_id "aoSDnWr_JutbFb-8svoMNAAAAcw"] [Tue Aug 18 13:09:01.133503 2026] [security2:error] [pid 167459:tid 167660] [client 20.1.169.243:8904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ee.php"] [unique_id "aoSDnWr_JutbFb-8svoMNwAAAdY"] [Tue Aug 18 13:09:01.243396 2026] [security2:error] [pid 167459:tid 167665] [client 20.226.36.136:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDnWr_JutbFb-8svoMOgAAAds"] [Tue Aug 18 13:09:01.270651 2026] [security2:error] [pid 167459:tid 167644] [client 20.116.17.175:22768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/002.php"] [unique_id "aoSDnWr_JutbFb-8svoMOwAAAcY"] [Tue Aug 18 13:09:01.283808 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:01.284307 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:01.297838 2026] [security2:error] [pid 167459:tid 167639] [client 158.23.17.4:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/creds.php"] [unique_id "aoSDnWr_JutbFb-8svoMPQAAAcE"] [Tue Aug 18 13:09:01.314460 2026] [security2:error] [pid 167459:tid 167595] [client 20.250.13.23:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDnWr_JutbFb-8svoMPwAAAZU"] [Tue Aug 18 13:09:01.333895 2026] [security2:error] [pid 167459:tid 167603] [client 168.62.48.100:16410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/weozh.php"] [unique_id "aoSDnWr_JutbFb-8svoMQAAAAZ0"] [Tue Aug 18 13:09:01.343857 2026] [security2:error] [pid 167459:tid 167709] [client 172.182.217.32:25602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/0Rhsgxs8WrSRpDwUIbgQrf/src/ui/index.php"] [unique_id "aoSDnWr_JutbFb-8svoMQgAAAgc"] [Tue Aug 18 13:09:01.396145 2026] [security2:error] [pid 167459:tid 167687] [client 20.1.169.243:10207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/about.php"] [unique_id "aoSDnWr_JutbFb-8svoMRwAAAfE"] [Tue Aug 18 13:09:01.423641 2026] [security2:error] [pid 167459:tid 167689] [client 20.65.98.162:5747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/1xmomo.php"] [unique_id "aoSDnWr_JutbFb-8svoMSQAAAfM"] [Tue Aug 18 13:09:01.427890 2026] [security2:error] [pid 167459:tid 167618] [client 172.213.243.2:19883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/nw.php"] [unique_id "aoSDnWr_JutbFb-8svoMSgAAAaw"] [Tue Aug 18 13:09:01.466323 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:5346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp.php"] [unique_id "aoSDnWr_JutbFb-8svoMSwAAAeA"] [Tue Aug 18 13:09:01.480831 2026] [security2:error] [pid 167459:tid 167705] [client 52.173.121.69:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDnWr_JutbFb-8svoMTAAAAgM"] [Tue Aug 18 13:09:01.485517 2026] [security2:error] [pid 167459:tid 167700] [client 20.250.13.23:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSDnWr_JutbFb-8svoMTQAAAf4"] [Tue Aug 18 13:09:01.516046 2026] [security2:error] [pid 167459:tid 167647] [client 20.250.13.23:18219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/import.php"] [unique_id "aoSDnWr_JutbFb-8svoMTwAAAck"] [Tue Aug 18 13:09:01.520625 2026] [security2:error] [pid 167459:tid 167592] [client 40.74.65.169:36937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wp_motu_4r80b.php"] [unique_id "aoSDnWr_JutbFb-8svoMUAAAAZI"] [Tue Aug 18 13:09:01.534301 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:9328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/edit.php"] [unique_id "aoSDnWr_JutbFb-8svoMUgAAAbQ"] [Tue Aug 18 13:09:01.546414 2026] [security2:error] [pid 167459:tid 167643] [client 49.145.211.146:11361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnWr_JutbFb-8svoMVQAAAcU"] [Tue Aug 18 13:09:01.546591 2026] [security2:error] [pid 167459:tid 167643] [client 49.145.211.146:11361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnWr_JutbFb-8svoMVQAAAcU"] [Tue Aug 18 13:09:01.551015 2026] [security2:error] [pid 167459:tid 167633] [client 20.104.100.201:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/reop3.php"] [unique_id "aoSDnWr_JutbFb-8svoMVgAAAbs"] [Tue Aug 18 13:09:01.576731 2026] [security2:error] [pid 167459:tid 167637] [client 168.62.48.100:16448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/rymmm.php"] [unique_id "aoSDnWr_JutbFb-8svoMWAAAAb8"] [Tue Aug 18 13:09:01.584282 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:01.584550 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:01.587890 2026] [security2:error] [pid 167459:tid 167691] [client 40.74.65.169:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDnWr_JutbFb-8svoMWwAAAfU"] [Tue Aug 18 13:09:01.589071 2026] [security2:error] [pid 167459:tid 167619] [client 213.35.127.232:54198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDnWr_JutbFb-8svoMXAAAAa0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:01.624622 2026] [security2:error] [pid 167459:tid 167590] [client 20.100.169.31:2615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/file.php"] [unique_id "aoSDnWr_JutbFb-8svoMXwAAAZA"] [Tue Aug 18 13:09:01.657915 2026] [security2:error] [pid 167459:tid 167593] [client 20.226.36.136:62150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDnWr_JutbFb-8svoMYAAAAZM"] [Tue Aug 18 13:09:01.749944 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:2582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDnWr_JutbFb-8svoMawAAAfY"] [Tue Aug 18 13:09:01.756776 2026] [security2:error] [pid 167459:tid 167632] [client 20.116.17.175:45398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/zxz.php"] [unique_id "aoSDnWr_JutbFb-8svoMbAAAAbo"] [Tue Aug 18 13:09:01.763197 2026] [security2:error] [pid 167459:tid 167642] [client 20.1.169.243:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/about/function.php"] [unique_id "aoSDnWr_JutbFb-8svoMbQAAAcQ"] [Tue Aug 18 13:09:01.787582 2026] [security2:error] [pid 167459:tid 167658] [client 20.151.109.219:46571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mandrill.php"] [unique_id "aoSDnWr_JutbFb-8svoMcAAAAdQ"] [Tue Aug 18 13:09:01.814467 2026] [security2:error] [pid 167459:tid 167667] [client 168.62.48.100:16461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/lddxs.php"] [unique_id "aoSDnWr_JutbFb-8svoMcgAAAd0"] [Tue Aug 18 13:09:01.831299 2026] [security2:error] [pid 167459:tid 167602] [client 172.182.217.32:25590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/0x5oFSRBaxEEW4WLAIJz80/src/ui/index.php"] [unique_id "aoSDnWr_JutbFb-8svoMcwAAAZw"] [Tue Aug 18 13:09:01.831435 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:5764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wso.php"] [unique_id "aoSDnWr_JutbFb-8svoMdAAAAZs"] [Tue Aug 18 13:09:01.840347 2026] [security2:error] [pid 167459:tid 167674] [client 20.104.100.201:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/save.php"] [unique_id "aoSDnWr_JutbFb-8svoMdQAAAeQ"] [Tue Aug 18 13:09:01.845694 2026] [security2:error] [pid 167459:tid 167715] [client 172.213.243.2:11605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ws62.php"] [unique_id "aoSDnWr_JutbFb-8svoMdgAAAg0"] [Tue Aug 18 13:09:01.885996 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:01.886254 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:01.898600 2026] [security2:error] [pid 167459:tid 167641] [client 20.1.169.243:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/f35.php"] [unique_id "aoSDnWr_JutbFb-8svoMeQAAAcM"] [Tue Aug 18 13:09:02.059259 2026] [security2:error] [pid 167459:tid 167654] [client 20.116.17.175:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/z43agz.php"] [unique_id "aoSDnmr_JutbFb-8svoMhQAAAdA"] [Tue Aug 18 13:09:02.079384 2026] [security2:error] [pid 167459:tid 167705] [client 168.62.48.100:16469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/zjggu.php"] [unique_id "aoSDnmr_JutbFb-8svoMhgAAAgM"] [Tue Aug 18 13:09:02.099252 2026] [security2:error] [pid 167459:tid 167700] [client 158.23.17.4:25346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ho.php"] [unique_id "aoSDnmr_JutbFb-8svoMiAAAAf4"] [Tue Aug 18 13:09:02.137410 2026] [security2:error] [pid 167459:tid 167648] [client 20.250.13.23:18238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/cropper.php"] [unique_id "aoSDnmr_JutbFb-8svoMjQAAAco"] [Tue Aug 18 13:09:02.153164 2026] [security2:error] [pid 167459:tid 167627] [client 20.1.169.243:10208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/admin/admin.php"] [unique_id "aoSDnmr_JutbFb-8svoMjgAAAbU"] [Tue Aug 18 13:09:02.156921 2026] [security2:error] [pid 167459:tid 167595] [client 20.250.13.23:18176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/goat.php"] [unique_id "aoSDnmr_JutbFb-8svoMjwAAAZU"] [Tue Aug 18 13:09:02.168757 2026] [security2:error] [pid 167459:tid 167584] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnmr_JutbFb-8svoMkAABuXw"] [Tue Aug 18 13:09:02.168920 2026] [security2:error] [pid 167459:tid 167631] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnmr_JutbFb-8svoMkAABuXw"] [Tue Aug 18 13:09:02.187237 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:02.187510 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:02.194608 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:5330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/www.php"] [unique_id "aoSDnmr_JutbFb-8svoMkgAAAeA"] [Tue Aug 18 13:09:02.228234 2026] [security2:error] [pid 167459:tid 167653] [client 20.226.36.136:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDnmr_JutbFb-8svoMlgAAAc8"] [Tue Aug 18 13:09:02.242378 2026] [security2:error] [pid 167459:tid 167704] [client 20.116.17.175:22756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/memberfuns.php"] [unique_id "aoSDnmr_JutbFb-8svoMlwAAAgI"] [Tue Aug 18 13:09:02.258685 2026] [security2:error] [pid 167459:tid 167613] [client 172.213.243.2:15041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/public/vx.php"] [unique_id "aoSDnmr_JutbFb-8svoMmgAAAac"] [Tue Aug 18 13:09:02.259000 2026] [security2:error] [pid 167459:tid 167618] [client 20.100.169.31:2575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/goods.php"] [unique_id "aoSDnmr_JutbFb-8svoMmQAAAaw"] [Tue Aug 18 13:09:02.260000 2026] [security2:error] [pid 167459:tid 167594] [client 74.248.130.103:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/82.php"] [unique_id "aoSDnmr_JutbFb-8svoMmwAAAZQ"] [Tue Aug 18 13:09:02.265225 2026] [security2:error] [pid 167459:tid 167596] [client 20.1.169.243:8849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/fff.php"] [unique_id "aoSDnmr_JutbFb-8svoMnAAAAZY"] [Tue Aug 18 13:09:02.267568 2026] [security2:error] [pid 167459:tid 167608] [client 4.232.151.198:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDnmr_JutbFb-8svoMnQAAAaI"] [Tue Aug 18 13:09:02.288984 2026] [security2:error] [pid 167459:tid 167607] [client 20.104.100.201:9547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/php5.php"] [unique_id "aoSDnmr_JutbFb-8svoMnwAAAaE"] [Tue Aug 18 13:09:02.294108 2026] [security2:error] [pid 167459:tid 167682] [client 40.74.65.169:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/8pyceeo.php"] [unique_id "aoSDnmr_JutbFb-8svoMoAAAAew"] [Tue Aug 18 13:09:02.318069 2026] [security2:error] [pid 167459:tid 167661] [client 158.23.17.4:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/do.php"] [unique_id "aoSDnmr_JutbFb-8svoMpAAAAdc"] [Tue Aug 18 13:09:02.321530 2026] [security2:error] [pid 167459:tid 167589] [client 168.62.48.100:16390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/dlvqo.php"] [unique_id "aoSDnmr_JutbFb-8svoMpQAAAY8"] [Tue Aug 18 13:09:02.323366 2026] [security2:error] [pid 167459:tid 167592] [client 172.182.217.32:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/duplicator/assets/about.php"] [unique_id "aoSDnmr_JutbFb-8svoMpgAAAZI"] [Tue Aug 18 13:09:02.362394 2026] [security2:error] [pid 167459:tid 167593] [client 20.127.136.245:10781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSDnmr_JutbFb-8svoMqAAAAZM"] [Tue Aug 18 13:09:02.364877 2026] [security2:error] [pid 167459:tid 167599] [client 20.100.169.31:18976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/ioxi-o.php"] [unique_id "aoSDnmr_JutbFb-8svoMqQAAAZk"] [Tue Aug 18 13:09:02.381246 2026] [security2:error] [pid 167459:tid 167689] [client 108.165.238.6:29224] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDnmr_JutbFb-8svoMgwAAAfM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:09:02.412273 2026] [security2:error] [pid 167459:tid 167626] [client 4.232.151.198:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/ectoplasm/wp-login.php"] [unique_id "aoSDnmr_JutbFb-8svoMrQAAAbQ"] [Tue Aug 18 13:09:02.432698 2026] [security2:error] [pid 167459:tid 167614] [client 20.65.98.162:63300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/mosty.php"] [unique_id "aoSDnmr_JutbFb-8svoMsAAAAag"] [Tue Aug 18 13:09:02.451363 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.133.44:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/aksinet.php"] [unique_id "aoSDnmr_JutbFb-8svoMsQAAAdI"] [Tue Aug 18 13:09:02.493220 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:02.493679 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:02.519990 2026] [security2:error] [pid 167459:tid 167714] [client 20.1.169.243:10234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/admin/function.php"] [unique_id "aoSDnmr_JutbFb-8svoMtQAAAgw"] [Tue Aug 18 13:09:02.564898 2026] [security2:error] [pid 167459:tid 167693] [client 20.1.169.243:5767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/x.php"] [unique_id "aoSDnmr_JutbFb-8svoMuAAAAfc"] [Tue Aug 18 13:09:02.582457 2026] [security2:error] [pid 167459:tid 167681] [client 168.62.48.100:16508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/pkmoj.php"] [unique_id "aoSDnmr_JutbFb-8svoMuQAAAes"] [Tue Aug 18 13:09:02.590245 2026] [security2:error] [pid 167459:tid 167716] [client 20.104.100.201:54030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/xyn.php"] [unique_id "aoSDnmr_JutbFb-8svoMuwAAAg4"] [Tue Aug 18 13:09:02.595423 2026] [security2:error] [pid 167459:tid 167612] [client 158.23.17.4:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ta.php"] [unique_id "aoSDnmr_JutbFb-8svoMvAAAAaY"] [Tue Aug 18 13:09:02.599883 2026] [security2:error] [pid 167459:tid 167683] [client 213.35.127.232:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDnmr_JutbFb-8svoMvQAAAe0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:02.657144 2026] [security2:error] [pid 167459:tid 167669] [client 20.151.109.219:36319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/main.php"] [unique_id "aoSDnmr_JutbFb-8svoMvwAAAd8"] [Tue Aug 18 13:09:02.666955 2026] [security2:error] [pid 167459:tid 167603] [client 20.206.73.37:65168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cvwebdesigner.com.br"] [uri "/.mopj.php"] [unique_id "aoSDnmr_JutbFb-8svoMwAAAAZ0"] [Tue Aug 18 13:09:02.687617 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:41483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/aa.php"] [unique_id "aoSDnmr_JutbFb-8svoMxAAAAeM"] [Tue Aug 18 13:09:02.693955 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ff1.php"] [unique_id "aoSDnmr_JutbFb-8svoMxQAAAgQ"] [Tue Aug 18 13:09:02.716372 2026] [security2:error] [pid 167459:tid 167638] [client 172.213.243.2:18568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/loxi-o.php"] [unique_id "aoSDnmr_JutbFb-8svoMxgAAAcA"] [Tue Aug 18 13:09:02.725264 2026] [security2:error] [pid 167459:tid 167597] [client 20.226.36.136:62164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDnmr_JutbFb-8svoMxwAAAZc"] [Tue Aug 18 13:09:02.751089 2026] [security2:error] [pid 167459:tid 167698] [client 20.250.13.23:18370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSDnmr_JutbFb-8svoMygAAAfw"] [Tue Aug 18 13:09:02.751527 2026] [security2:error] [pid 167459:tid 167687] [client 49.37.150.8:58335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnmr_JutbFb-8svoMywAAAfE"] [Tue Aug 18 13:09:02.751616 2026] [security2:error] [pid 167459:tid 167687] [client 49.37.150.8:58335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDnmr_JutbFb-8svoMywAAAfE"] [Tue Aug 18 13:09:02.777698 2026] [security2:error] [pid 167459:tid 167609] [client 20.250.13.23:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/Session.php"] [unique_id "aoSDnmr_JutbFb-8svoMzQAAAaM"] [Tue Aug 18 13:09:02.791033 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-rrtx.php"] [unique_id "aoSDnmr_JutbFb-8svoMzwAAAZU"] [Tue Aug 18 13:09:02.809756 2026] [security2:error] [pid 167459:tid 167620] [client 172.182.217.32:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aoSDnmr_JutbFb-8svoM0QAAAa4"] [Tue Aug 18 13:09:02.844859 2026] [security2:error] [pid 167459:tid 167686] [client 158.23.17.4:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/97.php"] [unique_id "aoSDnmr_JutbFb-8svoM1AAAAfA"] [Tue Aug 18 13:09:02.852926 2026] [security2:error] [pid 167459:tid 167633] [client 168.62.48.100:16505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/kopyw.php"] [unique_id "aoSDnmr_JutbFb-8svoM1wAAAbs"] [Tue Aug 18 13:09:02.880907 2026] [security2:error] [pid 167459:tid 167704] [client 52.173.121.69:36545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/first.php"] [unique_id "aoSDnmr_JutbFb-8svoM2QAAAgI"] [Tue Aug 18 13:09:02.881218 2026] [security2:error] [pid 167459:tid 167690] [client 20.100.169.31:2918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDnmr_JutbFb-8svoM2gAAAfQ"] [Tue Aug 18 13:09:02.885016 2026] [security2:error] [pid 167459:tid 167640] [client 20.1.169.243:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/adminfuns.php"] [unique_id "aoSDnmr_JutbFb-8svoM2wAAAcI"] [Tue Aug 18 13:09:02.890663 2026] [security2:error] [pid 167459:tid 167613] [client 40.74.65.169:43740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/av.php"] [unique_id "aoSDnmr_JutbFb-8svoM3AAAAac"] [Tue Aug 18 13:09:02.902775 2026] [authz_core:error] [pid 167459:tid 167630] [client 192.178.4.134:55415] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:02.903027 2026] [authz_core:error] [pid 167459:tid 167630] [client 192.178.4.134:55415] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:02.927639 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:5800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSDnmr_JutbFb-8svoM3gAAAeE"] [Tue Aug 18 13:09:02.937137 2026] [security2:error] [pid 167459:tid 167682] [client 20.127.136.245:13812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/hosty.php"] [unique_id "aoSDnmr_JutbFb-8svoM3wAAAew"] [Tue Aug 18 13:09:02.987497 2026] [security2:error] [pid 167459:tid 167627] [client 20.100.169.31:18967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/0x.php"] [unique_id "aoSDnmr_JutbFb-8svoM4AAAAbU"] [Tue Aug 18 13:09:02.995624 2026] [security2:error] [pid 167459:tid 167590] [client 40.74.65.169:21312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/.admin.php"] [unique_id "aoSDnmr_JutbFb-8svoM4QAAAZA"] [Tue Aug 18 13:09:03.003735 2026] [security2:error] [pid 167459:tid 167707] [client 20.226.36.136:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDn2r_JutbFb-8svoM4gAAAgU"] [Tue Aug 18 13:09:03.018814 2026] [security2:error] [pid 167459:tid 167689] [client 108.165.238.6:29224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDnmr_JutbFb-8svoMgwAAAfM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:09:03.052301 2026] [security2:error] [pid 167459:tid 167600] [client 4.232.151.198:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDn2r_JutbFb-8svoM5AAAAZo"] [Tue Aug 18 13:09:03.057093 2026] [security2:error] [pid 167459:tid 167607] [client 20.1.169.243:8959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/flower.php"] [unique_id "aoSDn2r_JutbFb-8svoM5gAAAaE"] [Tue Aug 18 13:09:03.081480 2026] [security2:error] [pid 167459:tid 167657] [client 20.104.100.201:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/acp.php"] [unique_id "aoSDn2r_JutbFb-8svoM6gAAAdM"] [Tue Aug 18 13:09:03.090648 2026] [authz_core:error] [pid 167459:tid 167577] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:03.090959 2026] [authz_core:error] [pid 167459:tid 167577] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:03.107869 2026] [security2:error] [pid 167459:tid 167662] [client 168.62.48.100:16477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/zznmg.php"] [unique_id "aoSDn2r_JutbFb-8svoM7QAAAdg"] [Tue Aug 18 13:09:03.137262 2026] [security2:error] [pid 167459:tid 167632] [client 172.213.243.2:14421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sdsa.php"] [unique_id "aoSDn2r_JutbFb-8svoM7wAAAbo"] [Tue Aug 18 13:09:03.140727 2026] [security2:error] [pid 167459:tid 167642] [client 20.116.17.175:22746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/echkm.php"] [unique_id "aoSDn2r_JutbFb-8svoM8AAAAcQ"] [Tue Aug 18 13:09:03.182509 2026] [autoindex:error] [pid 167459:tid 167672] [client 66.132.195.49:39168] AH01276: Cannot serve directory /home1/cipodi60/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:03.240847 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:20618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/yw.php"] [unique_id "aoSDn2r_JutbFb-8svoM9AAAAg4"] [Tue Aug 18 13:09:03.258993 2026] [security2:error] [pid 167459:tid 167692] [client 20.1.169.243:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSDn2r_JutbFb-8svoM9QAAAfY"] [Tue Aug 18 13:09:03.272199 2026] [security2:error] [pid 167459:tid 167670] [client 86.120.159.145:25121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDn2r_JutbFb-8svoM9gAAAeA"] [Tue Aug 18 13:09:03.272462 2026] [security2:error] [pid 167459:tid 167670] [client 86.120.159.145:25121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDn2r_JutbFb-8svoM9gAAAeA"] [Tue Aug 18 13:09:03.289931 2026] [security2:error] [pid 167459:tid 167667] [client 20.1.169.243:5776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/aaa.php"] [unique_id "aoSDn2r_JutbFb-8svoM-AAAAd0"] [Tue Aug 18 13:09:03.296918 2026] [security2:error] [pid 167459:tid 167688] [client 172.182.217.32:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/pwnd/gecko.php"] [unique_id "aoSDn2r_JutbFb-8svoM-QAAAfI"] [Tue Aug 18 13:09:03.338903 2026] [security2:error] [pid 167459:tid 167610] [client 74.248.130.103:31974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/dex.php"] [unique_id "aoSDn2r_JutbFb-8svoM-wAAAaQ"] [Tue Aug 18 13:09:03.346653 2026] [security2:error] [pid 167459:tid 167669] [client 168.62.48.100:16441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/bhfnd.php"] [unique_id "aoSDn2r_JutbFb-8svoM_AAAAd8"] [Tue Aug 18 13:09:03.368012 2026] [security2:error] [pid 167459:tid 167622] [client 20.250.13.23:5934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSDn2r_JutbFb-8svoM_wAAAbA"] [Tue Aug 18 13:09:03.392207 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:03.392470 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:03.396044 2026] [security2:error] [pid 167459:tid 167601] [client 20.250.13.23:18418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSDn2r_JutbFb-8svoNAQAAAZs"] [Tue Aug 18 13:09:03.419315 2026] [security2:error] [pid 167459:tid 167639] [client 20.250.13.23:34211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/a7.php"] [unique_id "aoSDn2r_JutbFb-8svoNAwAAAcE"] [Tue Aug 18 13:09:03.423201 2026] [security2:error] [pid 167459:tid 167665] [client 20.1.169.243:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/file.php"] [unique_id "aoSDn2r_JutbFb-8svoNBQAAAds"] [Tue Aug 18 13:09:03.466593 2026] [security2:error] [pid 167459:tid 167700] [client 20.104.100.201:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/gecko-new.php"] [unique_id "aoSDn2r_JutbFb-8svoNBwAAAf4"] [Tue Aug 18 13:09:03.491313 2026] [security2:error] [pid 167459:tid 167648] [client 5.31.227.224:1441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDn2r_JutbFb-8svoNCAAAAco"] [Tue Aug 18 13:09:03.491433 2026] [security2:error] [pid 167459:tid 167648] [client 5.31.227.224:1441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDn2r_JutbFb-8svoNCAAAAco"] [Tue Aug 18 13:09:03.509448 2026] [security2:error] [pid 167459:tid 167651] [client 20.100.169.31:2914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/htaccess.php"] [unique_id "aoSDn2r_JutbFb-8svoNCQAAAc0"] [Tue Aug 18 13:09:03.513420 2026] [security2:error] [pid 167459:tid 167684] [client 74.249.206.207:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/dex.php"] [unique_id "aoSDn2r_JutbFb-8svoNCgAAAe4"] [Tue Aug 18 13:09:03.553082 2026] [security2:error] [pid 167459:tid 167631] [client 172.213.243.2:19882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-freya.php"] [unique_id "aoSDn2r_JutbFb-8svoNDAAAAbk"] [Tue Aug 18 13:09:03.584632 2026] [security2:error] [pid 167459:tid 167604] [client 168.62.48.100:16449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/qfvqu.php"] [unique_id "aoSDn2r_JutbFb-8svoNDgAAAZ4"] [Tue Aug 18 13:09:03.614384 2026] [security2:error] [pid 167459:tid 167645] [client 213.35.127.232:54637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDn2r_JutbFb-8svoNDwAAAcc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:03.632245 2026] [security2:error] [pid 167459:tid 167709] [client 20.100.169.31:3516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/222.php"] [unique_id "aoSDn2r_JutbFb-8svoNEAAAAgc"] [Tue Aug 18 13:09:03.653315 2026] [security2:error] [pid 167459:tid 167647] [client 20.1.169.243:16283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fichiers.queroficarnanet.com"] [uri "/fpwch.php"] [unique_id "aoSDn2r_JutbFb-8svoNEgAAAck"] [Tue Aug 18 13:09:03.658990 2026] [security2:error] [pid 167459:tid 167620] [client 20.1.169.243:9669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/ahax.php"] [unique_id "aoSDn2r_JutbFb-8svoNEwAAAa4"] [Tue Aug 18 13:09:03.694714 2026] [security2:error] [pid 167459:tid 167698] [client 4.232.151.198:2365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/colors/light/wp-login.php"] [unique_id "aoSDn2r_JutbFb-8svoNFgAAAfw"] [Tue Aug 18 13:09:03.719038 2026] [security2:error] [pid 167459:tid 167596] [client 20.226.36.136:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDn2r_JutbFb-8svoNFwAAAZY"] [Tue Aug 18 13:09:03.747019 2026] [security2:error] [pid 167459:tid 167628] [client 52.173.121.69:36560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDn2r_JutbFb-8svoNGQAAAbY"] [Tue Aug 18 13:09:03.766484 2026] [security2:error] [pid 167459:tid 167712] [client 20.116.17.175:52875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/3.php"] [unique_id "aoSDn2r_JutbFb-8svoNGgAAAgo"] [Tue Aug 18 13:09:03.806189 2026] [security2:error] [pid 167459:tid 167593] [client 40.74.65.169:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/wsomini.php"] [unique_id "aoSDn2r_JutbFb-8svoNHwAAAZM"] [Tue Aug 18 13:09:03.811824 2026] [security2:error] [pid 167459:tid 167599] [client 20.104.100.201:53281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/yas.php"] [unique_id "aoSDn2r_JutbFb-8svoNIAAAAZk"] [Tue Aug 18 13:09:03.822635 2026] [security2:error] [pid 167459:tid 167598] [client 20.151.109.219:20965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ga.php"] [unique_id "aoSDn2r_JutbFb-8svoNIQAAAZg"] [Tue Aug 18 13:09:03.845943 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:9559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/goods.php"] [unique_id "aoSDn2r_JutbFb-8svoNIgAAAeE"] [Tue Aug 18 13:09:03.851196 2026] [security2:error] [pid 167459:tid 167626] [client 168.62.48.100:16466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/oivcl.php"] [unique_id "aoSDn2r_JutbFb-8svoNIwAAAbQ"] [Tue Aug 18 13:09:03.882090 2026] [security2:error] [pid 167459:tid 167600] [client 20.65.98.162:63308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/blurbs.php"] [unique_id "aoSDn2r_JutbFb-8svoNJAAAAZo"] [Tue Aug 18 13:09:03.913542 2026] [security2:error] [pid 167459:tid 167650] [client 158.23.17.4:15802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/rh.php"] [unique_id "aoSDn2r_JutbFb-8svoNKAAAAcw"] [Tue Aug 18 13:09:03.970604 2026] [security2:error] [pid 167459:tid 167674] [client 158.23.17.4:39043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/qh.php"] [unique_id "aoSDn2r_JutbFb-8svoNKQAAAeQ"] [Tue Aug 18 13:09:03.985622 2026] [security2:error] [pid 167459:tid 167655] [client 172.213.243.2:15095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fleen.php"] [unique_id "aoSDn2r_JutbFb-8svoNKgAAAdE"] [Tue Aug 18 13:09:03.988347 2026] [security2:error] [pid 167459:tid 167592] [client 20.250.13.23:5904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/goat.php"] [unique_id "aoSDn2r_JutbFb-8svoNKwAAAZI"] [Tue Aug 18 13:09:03.996907 2026] [authz_core:error] [pid 167459:tid 167513] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:03.997170 2026] [authz_core:error] [pid 167459:tid 167513] [remote 216.73.216.206:61370] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:04.001740 2026] [security2:error] [pid 167459:tid 167678] [client 74.248.130.103:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/puc.php"] [unique_id "aoSDoGr_JutbFb-8svoNLQAAAeg"] [Tue Aug 18 13:09:04.003492 2026] [security2:error] [pid 167459:tid 167612] [client 20.127.136.245:19368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/test1.php"] [unique_id "aoSDoGr_JutbFb-8svoNLwAAAaY"] [Tue Aug 18 13:09:04.013575 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:18186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/abcd.php"] [unique_id "aoSDoGr_JutbFb-8svoNMAAAAgU"] [Tue Aug 18 13:09:04.016452 2026] [security2:error] [pid 167459:tid 167683] [client 20.116.17.175:22704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/domvf.php"] [unique_id "aoSDoGr_JutbFb-8svoNMQAAAe0"] [Tue Aug 18 13:09:04.073078 2026] [security2:error] [pid 167459:tid 167632] [client 20.1.169.243:10480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/alfa.php"] [unique_id "aoSDoGr_JutbFb-8svoNMgAAAbo"] [Tue Aug 18 13:09:04.173384 2026] [security2:error] [pid 167459:tid 167658] [client 20.100.169.31:2924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/images/wso.php"] [unique_id "aoSDoGr_JutbFb-8svoNNQAAAdQ"] [Tue Aug 18 13:09:04.188260 2026] [security2:error] [pid 167459:tid 167639] [client 168.62.48.100:16391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/zugvi.php"] [unique_id "aoSDoGr_JutbFb-8svoNNgAAAcE"] [Tue Aug 18 13:09:04.210989 2026] [security2:error] [pid 167459:tid 167646] [client 20.1.169.243:8946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/g.php"] [unique_id "aoSDoGr_JutbFb-8svoNOAAAAcg"] [Tue Aug 18 13:09:04.228339 2026] [security2:error] [pid 167459:tid 167713] [client 20.226.36.136:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDoGr_JutbFb-8svoNOQAAAgs"] [Tue Aug 18 13:09:04.238824 2026] [security2:error] [pid 167459:tid 167660] [client 40.74.65.169:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/images.php"] [unique_id "aoSDoGr_JutbFb-8svoNOgAAAdY"] [Tue Aug 18 13:09:04.246235 2026] [security2:error] [pid 167459:tid 167696] [client 52.173.121.69:28323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDoGr_JutbFb-8svoNOwAAAfo"] [Tue Aug 18 13:09:04.256296 2026] [security2:error] [pid 167459:tid 167686] [client 158.23.17.4:7180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/34.php"] [unique_id "aoSDoGr_JutbFb-8svoNPAAAAfA"] [Tue Aug 18 13:09:04.263614 2026] [security2:error] [pid 167459:tid 167688] [client 20.100.169.31:3464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/aa.php"] [unique_id "aoSDoGr_JutbFb-8svoNPQAAAfI"] [Tue Aug 18 13:09:04.397974 2026] [security2:error] [pid 167459:tid 167690] [client 223.185.37.47:16903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDoGr_JutbFb-8svoNRQAAAfQ"] [Tue Aug 18 13:09:04.398086 2026] [security2:error] [pid 167459:tid 167690] [client 223.185.37.47:16903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDoGr_JutbFb-8svoNRQAAAfQ"] [Tue Aug 18 13:09:04.442370 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:10206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/alfax.php"] [unique_id "aoSDoGr_JutbFb-8svoNTAAAAgI"] [Tue Aug 18 13:09:04.458270 2026] [security2:error] [pid 167459:tid 167689] [client 168.62.48.100:16480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wsrer.php"] [unique_id "aoSDoGr_JutbFb-8svoNTQAAAfM"] [Tue Aug 18 13:09:04.468515 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/as.php"] [unique_id "aoSDoGr_JutbFb-8svoNTgAAAdk"] [Tue Aug 18 13:09:04.481549 2026] [security2:error] [pid 167459:tid 167710] [client 172.213.243.2:18621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/e.php"] [unique_id "aoSDoGr_JutbFb-8svoNUAAAAgg"] [Tue Aug 18 13:09:04.541211 2026] [security2:error] [pid 167459:tid 167636] [client 20.116.17.175:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/log.php"] [unique_id "aoSDoGr_JutbFb-8svoNUgAAAb4"] [Tue Aug 18 13:09:04.571856 2026] [security2:error] [pid 167459:tid 167625] [client 20.104.100.201:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/df.php"] [unique_id "aoSDoGr_JutbFb-8svoNVAAAAbM"] [Tue Aug 18 13:09:04.575346 2026] [security2:error] [pid 167459:tid 167593] [client 20.1.169.243:8951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDoGr_JutbFb-8svoNVQAAAZM"] [Tue Aug 18 13:09:04.618421 2026] [security2:error] [pid 167459:tid 167629] [client 40.74.65.169:7056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.maronebrito.com.br"] [uri "/vr.php"] [unique_id "aoSDoGr_JutbFb-8svoNVwAAAbc"] [Tue Aug 18 13:09:04.620451 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:18372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/Session.php"] [unique_id "aoSDoGr_JutbFb-8svoNWAAAAbY"] [Tue Aug 18 13:09:04.630851 2026] [security2:error] [pid 167459:tid 167679] [client 213.35.127.232:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDoGr_JutbFb-8svoNWQAAAek"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:04.645227 2026] [security2:error] [pid 167459:tid 167590] [client 20.250.13.23:18215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/kj.php"] [unique_id "aoSDoGr_JutbFb-8svoNWwAAAZA"] [Tue Aug 18 13:09:04.700784 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.130.103:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/inso.php"] [unique_id "aoSDoGr_JutbFb-8svoNXQAAAfY"] [Tue Aug 18 13:09:04.702828 2026] [security2:error] [pid 167459:tid 167707] [client 168.62.48.100:16402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/ucpfr.php"] [unique_id "aoSDoGr_JutbFb-8svoNXgAAAgU"] [Tue Aug 18 13:09:04.748275 2026] [security2:error] [pid 167459:tid 167619] [client 213.202.253.4:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSDoGr_JutbFb-8svoNXwAAAa0"], referer: www.google.com [Tue Aug 18 13:09:04.785864 2026] [security2:error] [pid 167459:tid 167635] [client 52.173.121.69:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDoGr_JutbFb-8svoNYQAAAb0"] [Tue Aug 18 13:09:04.802960 2026] [security2:error] [pid 167459:tid 167595] [client 20.100.169.31:2933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/index/function.php"] [unique_id "aoSDoGr_JutbFb-8svoNYwAAAZU"] [Tue Aug 18 13:09:04.813883 2026] [security2:error] [pid 167459:tid 167592] [client 20.1.169.243:10231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/ant.php"] [unique_id "aoSDoGr_JutbFb-8svoNZAAAAZI"] [Tue Aug 18 13:09:04.825178 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:9522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ah25.php"] [unique_id "aoSDoGr_JutbFb-8svoNZgAAAZs"] [Tue Aug 18 13:09:04.899118 2026] [security2:error] [pid 167459:tid 167597] [client 172.213.243.2:37095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/hello.php"] [unique_id "aoSDoGr_JutbFb-8svoNagAAAZc"] [Tue Aug 18 13:09:04.941962 2026] [security2:error] [pid 167459:tid 167674] [client 20.100.169.31:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/abcd.php"] [unique_id "aoSDoGr_JutbFb-8svoNbAAAAeQ"] [Tue Aug 18 13:09:04.952545 2026] [security2:error] [pid 167459:tid 167646] [client 168.62.48.100:16497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/yxijx.php"] [unique_id "aoSDoGr_JutbFb-8svoNbQAAAcg"] [Tue Aug 18 13:09:04.953030 2026] [security2:error] [pid 167459:tid 167697] [client 74.248.133.44:32381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/simple.php"] [unique_id "aoSDoGr_JutbFb-8svoNbgAAAfs"] [Tue Aug 18 13:09:04.974976 2026] [security2:error] [pid 167459:tid 167702] [client 158.23.17.4:7188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/yg.php"] [unique_id "aoSDoGr_JutbFb-8svoNbwAAAgA"] [Tue Aug 18 13:09:04.975903 2026] [security2:error] [pid 167459:tid 167639] [client 20.1.169.243:9562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDoGr_JutbFb-8svoNcAAAAcE"] [Tue Aug 18 13:09:05.042113 2026] [security2:error] [pid 167459:tid 167673] [client 20.127.136.245:13809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/zwso.php"] [unique_id "aoSDoWr_JutbFb-8svoNcgAAAeM"] [Tue Aug 18 13:09:05.077079 2026] [security2:error] [pid 167459:tid 167698] [client 4.232.151.198:2318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDoWr_JutbFb-8svoNcwAAAfw"] [Tue Aug 18 13:09:05.080404 2026] [security2:error] [pid 167459:tid 167627] [client 144.76.22.179:33712] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siderurgiabrasil.com.br"] [uri "/index.php"] [unique_id "aoSDoGr_JutbFb-8svoNSwAAAbU"] [Tue Aug 18 13:09:05.097893 2026] [security2:error] [pid 167459:tid 167596] [client 20.116.17.175:22665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/red.php"] [unique_id "aoSDoWr_JutbFb-8svoNdQAAAZY"] [Tue Aug 18 13:09:05.099425 2026] [security2:error] [pid 167459:tid 167481] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/chosen.php"] [unique_id "aoSDoWr_JutbFb-8svoNdAABpxU"] [Tue Aug 18 13:09:05.157297 2026] [security2:error] [pid 167459:tid 167711] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDoWr_JutbFb-8svoNdgACCVc"] [Tue Aug 18 13:09:05.194182 2026] [security2:error] [pid 167459:tid 167591] [client 168.62.48.100:16397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/zwlsv.php"] [unique_id "aoSDoWr_JutbFb-8svoNdwAAAZE"] [Tue Aug 18 13:09:05.224891 2026] [security2:error] [pid 167459:tid 167710] [client 20.151.109.219:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/wb.php"] [unique_id "aoSDoWr_JutbFb-8svoNeQAAAgg"] [Tue Aug 18 13:09:05.238951 2026] [security2:error] [pid 167459:tid 167653] [client 20.250.13.23:5888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSDoWr_JutbFb-8svoNegAAAc8"] [Tue Aug 18 13:09:05.258822 2026] [security2:error] [pid 167459:tid 167676] [client 52.173.121.69:28326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDoWr_JutbFb-8svoNewAAAeY"] [Tue Aug 18 13:09:05.261008 2026] [security2:error] [pid 167459:tid 167620] [client 20.250.13.23:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/languages.php"] [unique_id "aoSDoWr_JutbFb-8svoNfAAAAa4"] [Tue Aug 18 13:09:05.277646 2026] [security2:error] [pid 167459:tid 167672] [client 20.1.169.243:10458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/app.php"] [unique_id "aoSDoWr_JutbFb-8svoNfgAAAeI"] [Tue Aug 18 13:09:05.281568 2026] [authz_core:error] [pid 167459:tid 167532] [remote 57.141.22.37:46430] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:05.281831 2026] [authz_core:error] [pid 167459:tid 167532] [remote 57.141.22.37:46430] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:05.288267 2026] [security2:error] [pid 167459:tid 167626] [client 158.23.17.4:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/he.php"] [unique_id "aoSDoWr_JutbFb-8svoNfwAAAbQ"] [Tue Aug 18 13:09:05.293845 2026] [security2:error] [pid 167459:tid 167636] [client 20.226.36.136:65306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDoWr_JutbFb-8svoNgAAAAb4"] [Tue Aug 18 13:09:05.340648 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/in.php"] [unique_id "aoSDoWr_JutbFb-8svoNgQAAAfM"] [Tue Aug 18 13:09:05.369420 2026] [security2:error] [pid 167459:tid 167607] [client 20.38.3.247:21265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDoWr_JutbFb-8svoNggAAAaE"] [Tue Aug 18 13:09:05.378014 2026] [security2:error] [pid 167459:tid 167593] [client 172.182.217.32:25573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/plugins/wp-help/index.php"] [unique_id "aoSDoWr_JutbFb-8svoNgwAAAZM"] [Tue Aug 18 13:09:05.389255 2026] [security2:error] [pid 167459:tid 167614] [client 172.213.243.2:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/brc.php"] [unique_id "aoSDoWr_JutbFb-8svoNhAAAAag"] [Tue Aug 18 13:09:05.432201 2026] [security2:error] [pid 167459:tid 167598] [client 20.100.169.31:2891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/info.php"] [unique_id "aoSDoWr_JutbFb-8svoNhwAAAZg"] [Tue Aug 18 13:09:05.448424 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.18.37:35011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/min.php"] [unique_id "aoSDoWr_JutbFb-8svoNiAAAAc4"] [Tue Aug 18 13:09:05.453511 2026] [security2:error] [pid 167459:tid 167693] [client 168.62.48.100:16435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/jrpga.php"] [unique_id "aoSDoWr_JutbFb-8svoNiQAAAfc"] [Tue Aug 18 13:09:05.458627 2026] [security2:error] [pid 167459:tid 167612] [client 20.104.100.201:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDoWr_JutbFb-8svoNigAAAaY"] [Tue Aug 18 13:09:05.526039 2026] [security2:error] [pid 167459:tid 167559] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/xleet.php"] [unique_id "aoSDoWr_JutbFb-8svoNjgABu2M"] [Tue Aug 18 13:09:05.543683 2026] [security2:error] [pid 167459:tid 167519] [remote 190.6.176.90:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.176.6.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifetreemarketing.com"] [uri "/wp-login.php"] [unique_id "aoSDoWr_JutbFb-8svoNjwAB8Ds"] [Tue Aug 18 13:09:05.559241 2026] [authz_core:error] [pid 167459:tid 167502] [remote 57.141.22.109:26320] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:05.559517 2026] [authz_core:error] [pid 167459:tid 167502] [remote 57.141.22.109:26320] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:05.579691 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:05.579950 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:05.582443 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:05.583165 2026] [authz_core:error] [pid 167459:tid 167556] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:05.602630 2026] [security2:error] [pid 167459:tid 167657] [client 20.100.169.31:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/admin.php"] [unique_id "aoSDoWr_JutbFb-8svoNlwAAAdM"] [Tue Aug 18 13:09:05.605578 2026] [security2:error] [pid 167459:tid 167681] [client 47.128.33.88:59782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.uninutri.ind.br"] [uri "/"] [unique_id "aoSDoWr_JutbFb-8svoNmAAAAes"] [Tue Aug 18 13:09:05.647188 2026] [security2:error] [pid 167459:tid 167670] [client 20.1.169.243:10200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/archive.php"] [unique_id "aoSDoWr_JutbFb-8svoNmQAAAeA"] [Tue Aug 18 13:09:05.648747 2026] [security2:error] [pid 167459:tid 167671] [client 213.35.127.232:55097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDoWr_JutbFb-8svoNmgAAAeE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:05.669262 2026] [security2:error] [pid 167459:tid 167500] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/ds.php"] [unique_id "aoSDoWr_JutbFb-8svoNmwACBCg"] [Tue Aug 18 13:09:05.704139 2026] [security2:error] [pid 167459:tid 167605] [client 20.1.169.243:9328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/info.php"] [unique_id "aoSDoWr_JutbFb-8svoNnAAAAZ8"] [Tue Aug 18 13:09:05.714543 2026] [security2:error] [pid 167459:tid 167597] [client 52.173.121.69:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDoWr_JutbFb-8svoNnQAAAZc"] [Tue Aug 18 13:09:05.748391 2026] [security2:error] [pid 167459:tid 167654] [client 20.151.109.219:46545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/xn.php"] [unique_id "aoSDoWr_JutbFb-8svoNngAAAdA"] [Tue Aug 18 13:09:05.762043 2026] [security2:error] [pid 167459:tid 167648] [client 74.248.130.103:28936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/aa.php"] [unique_id "aoSDoWr_JutbFb-8svoNoAAAAco"] [Tue Aug 18 13:09:05.767822 2026] [security2:error] [pid 167459:tid 167674] [client 168.62.48.100:16502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDoWr_JutbFb-8svoNoQAAAeQ"] [Tue Aug 18 13:09:05.773713 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:20630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/r.php"] [unique_id "aoSDoWr_JutbFb-8svoNogAAAfs"] [Tue Aug 18 13:09:05.793841 2026] [security2:error] [pid 167459:tid 167713] [client 20.38.3.247:16054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDoWr_JutbFb-8svoNpAAAAgs"] [Tue Aug 18 13:09:05.804566 2026] [security2:error] [pid 167459:tid 167631] [client 172.213.243.2:14346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/file52.php"] [unique_id "aoSDoWr_JutbFb-8svoNpQAAAbk"] [Tue Aug 18 13:09:05.813099 2026] [security2:error] [pid 167459:tid 167491] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/f5.php"] [unique_id "aoSDoWr_JutbFb-8svoNpgABwR8"] [Tue Aug 18 13:09:05.828484 2026] [security2:error] [pid 167459:tid 167675] [client 4.232.151.198:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/data.php"] [unique_id "aoSDoWr_JutbFb-8svoNqAAAAeU"] [Tue Aug 18 13:09:05.856104 2026] [security2:error] [pid 167459:tid 167673] [client 20.226.36.136:61496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDoWr_JutbFb-8svoNqQAAAeM"] [Tue Aug 18 13:09:05.859750 2026] [security2:error] [pid 167459:tid 167709] [client 20.127.136.245:19330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/Geforce.php"] [unique_id "aoSDoWr_JutbFb-8svoNqgAAAgc"] [Tue Aug 18 13:09:05.861288 2026] [security2:error] [pid 167459:tid 167601] [client 20.250.13.23:18412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/abcd.php"] [unique_id "aoSDoWr_JutbFb-8svoNqwAAAZs"] [Tue Aug 18 13:09:05.868381 2026] [security2:error] [pid 167459:tid 167623] [client 20.116.17.175:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/JawirGenk.php"] [unique_id "aoSDoWr_JutbFb-8svoNrAAAAbE"] [Tue Aug 18 13:09:05.870194 2026] [security2:error] [pid 167459:tid 167665] [client 172.182.217.32:25661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "aoSDoWr_JutbFb-8svoNrQAAAds"] [Tue Aug 18 13:09:05.898693 2026] [access_compat:error] [pid 167459:tid 167658] [client 20.250.13.23:18209] AH01797: client denied by server configuration: /home4/alltime/public_html/wp-content/uploads/2022/07/index.php [Tue Aug 18 13:09:05.957028 2026] [security2:error] [pid 167459:tid 167530] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/god4m.php"] [unique_id "aoSDoWr_JutbFb-8svoNrwACAkY"] [Tue Aug 18 13:09:05.987440 2026] [security2:error] [pid 167459:tid 167620] [client 40.74.65.169:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/ops.php"] [unique_id "aoSDoWr_JutbFb-8svoNsQAAAa4"] [Tue Aug 18 13:09:05.997804 2026] [security2:error] [pid 167459:tid 167701] [client 20.226.36.136:52665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDoWr_JutbFb-8svoNsgAAAf8"] [Tue Aug 18 13:09:06.006086 2026] [security2:error] [pid 167459:tid 167610] [client 20.250.13.23:34916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/manager.php"] [unique_id "aoSDomr_JutbFb-8svoNswAAAaQ"] [Tue Aug 18 13:09:06.009806 2026] [security2:error] [pid 167459:tid 167625] [client 168.62.48.100:16511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/nwwha.php"] [unique_id "aoSDomr_JutbFb-8svoNtAAAAbM"] [Tue Aug 18 13:09:06.018564 2026] [security2:error] [pid 167459:tid 167634] [client 20.1.169.243:10492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/as.php"] [unique_id "aoSDomr_JutbFb-8svoNtQAAAbw"] [Tue Aug 18 13:09:06.029862 2026] [security2:error] [pid 167459:tid 167613] [client 74.7.228.46:49922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "vitormotoslimeira.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDomr_JutbFb-8svoNtgABpyc"] [Tue Aug 18 13:09:06.062784 2026] [security2:error] [pid 167459:tid 167645] [client 20.100.169.31:2581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/profile.php"] [unique_id "aoSDomr_JutbFb-8svoNuQAAAcc"] [Tue Aug 18 13:09:06.072388 2026] [security2:error] [pid 167459:tid 167628] [client 20.116.17.175:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ohct.php"] [unique_id "aoSDomr_JutbFb-8svoNugAAAbY"] [Tue Aug 18 13:09:06.073805 2026] [security2:error] [pid 167459:tid 167629] [client 20.65.98.162:63354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/bajah.php"] [unique_id "aoSDomr_JutbFb-8svoNuwAAAbc"] [Tue Aug 18 13:09:06.081289 2026] [security2:error] [pid 167459:tid 167599] [client 20.1.169.243:8931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/inputs.php"] [unique_id "aoSDomr_JutbFb-8svoNvAAAAZk"] [Tue Aug 18 13:09:06.102152 2026] [security2:error] [pid 167459:tid 167508] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/info.php"] [unique_id "aoSDomr_JutbFb-8svoNvwABxDA"] [Tue Aug 18 13:09:06.105531 2026] [security2:error] [pid 167459:tid 167685] [client 20.250.13.23:18209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/nw.php"] [unique_id "aoSDomr_JutbFb-8svoNwAAAAe8"] [Tue Aug 18 13:09:06.145418 2026] [security2:error] [pid 167459:tid 167630] [client 149.34.210.141:56149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDomr_JutbFb-8svoNwQAAAbg"] [Tue Aug 18 13:09:06.149392 2026] [security2:error] [pid 167459:tid 167693] [client 158.23.17.4:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/et.php"] [unique_id "aoSDomr_JutbFb-8svoNwgAAAfc"] [Tue Aug 18 13:09:06.206456 2026] [security2:error] [pid 167459:tid 167615] [client 20.38.3.247:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/media.php"] [unique_id "aoSDomr_JutbFb-8svoNxAAAAak"] [Tue Aug 18 13:09:06.216370 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:06.216631 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:06.221933 2026] [security2:error] [pid 167459:tid 167633] [client 172.213.243.2:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sxdfrt.php"] [unique_id "aoSDomr_JutbFb-8svoNxgAAAbs"] [Tue Aug 18 13:09:06.244862 2026] [security2:error] [pid 167459:tid 167595] [client 102.213.179.104:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDomr_JutbFb-8svoNyAAAAZU"] [Tue Aug 18 13:09:06.244953 2026] [security2:error] [pid 167459:tid 167595] [client 102.213.179.104:60967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDomr_JutbFb-8svoNyAAAAZU"] [Tue Aug 18 13:09:06.262493 2026] [security2:error] [pid 167459:tid 167619] [client 52.173.121.69:49923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDomr_JutbFb-8svoNygAAAa0"] [Tue Aug 18 13:09:06.282559 2026] [security2:error] [pid 167459:tid 167657] [client 20.226.36.136:65305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDomr_JutbFb-8svoNzQAAAdM"] [Tue Aug 18 13:09:06.314779 2026] [security2:error] [pid 167459:tid 167622] [client 168.62.48.100:16455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/opsqt.php"] [unique_id "aoSDomr_JutbFb-8svoNzgAAAbA"] [Tue Aug 18 13:09:06.342315 2026] [security2:error] [pid 167459:tid 167656] [client 158.23.17.4:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/gz.php"] [unique_id "aoSDomr_JutbFb-8svoN0AAAAdI"] [Tue Aug 18 13:09:06.367865 2026] [security2:error] [pid 167459:tid 167692] [client 172.182.217.32:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "aoSDomr_JutbFb-8svoN0QAAAfY"] [Tue Aug 18 13:09:06.377844 2026] [security2:error] [pid 167459:tid 167654] [client 20.151.109.219:29380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/47.php"] [unique_id "aoSDomr_JutbFb-8svoN0gAAAdA"] [Tue Aug 18 13:09:06.384789 2026] [security2:error] [pid 167459:tid 167714] [client 20.1.169.243:10221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/assets/images/doc.php"] [unique_id "aoSDomr_JutbFb-8svoN1AAAAgw"] [Tue Aug 18 13:09:06.387215 2026] [security2:error] [pid 167459:tid 167708] [client 158.23.17.4:5016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/17.php"] [unique_id "aoSDomr_JutbFb-8svoN1QAAAgY"] [Tue Aug 18 13:09:06.424245 2026] [security2:error] [pid 167459:tid 167630] [client 149.34.210.141:56149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDomr_JutbFb-8svoNwQAAAbg"] [Tue Aug 18 13:09:06.446690 2026] [security2:error] [pid 167459:tid 167680] [client 20.1.169.243:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/item.php"] [unique_id "aoSDomr_JutbFb-8svoN1wAAAeo"] [Tue Aug 18 13:09:06.462514 2026] [security2:error] [pid 167459:tid 167684] [client 20.226.36.136:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDomr_JutbFb-8svoN2AAAAe4"] [Tue Aug 18 13:09:06.486788 2026] [security2:error] [pid 167459:tid 167592] [client 20.250.13.23:18192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/kj.php"] [unique_id "aoSDomr_JutbFb-8svoN2QAAAZI"] [Tue Aug 18 13:09:06.495294 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:06.495572 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:06.587746 2026] [security2:error] [pid 167459:tid 167709] [client 20.104.100.201:9479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/ano.php"] [unique_id "aoSDomr_JutbFb-8svoN3gAAAgc"] [Tue Aug 18 13:09:06.607124 2026] [security2:error] [pid 167459:tid 167601] [client 168.62.48.100:16396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDomr_JutbFb-8svoN3wAAAZs"] [Tue Aug 18 13:09:06.622550 2026] [security2:error] [pid 167459:tid 167647] [client 74.248.130.103:31983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/img.php"] [unique_id "aoSDomr_JutbFb-8svoN4AAAAck"] [Tue Aug 18 13:09:06.639825 2026] [security2:error] [pid 167459:tid 167694] [client 172.213.243.2:19877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/path.php"] [unique_id "aoSDomr_JutbFb-8svoN4QAAAfg"] [Tue Aug 18 13:09:06.643609 2026] [security2:error] [pid 167459:tid 167649] [client 4.232.151.198:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/bgymj.php"] [unique_id "aoSDomr_JutbFb-8svoN5AAAAcs"] [Tue Aug 18 13:09:06.662370 2026] [security2:error] [pid 167459:tid 167687] [client 4.232.151.198:2338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/disagrsxr.php"] [unique_id "aoSDomr_JutbFb-8svoN5QAAAfE"] [Tue Aug 18 13:09:06.675088 2026] [security2:error] [pid 167459:tid 167602] [client 213.35.127.232:55321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDomr_JutbFb-8svoN5gAAAZw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:06.686365 2026] [security2:error] [pid 167459:tid 167713] [client 20.100.169.31:2957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/sx.php"] [unique_id "aoSDomr_JutbFb-8svoN5wAAAgs"] [Tue Aug 18 13:09:06.695856 2026] [security2:error] [pid 167459:tid 167711] [client 20.226.36.136:53563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDomr_JutbFb-8svoN6AAAAgk"] [Tue Aug 18 13:09:06.720529 2026] [security2:error] [pid 167459:tid 167702] [client 20.250.13.23:18374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSDomr_JutbFb-8svoN6gAAAgA"] [Tue Aug 18 13:09:06.740185 2026] [security2:error] [pid 167459:tid 167636] [client 52.173.121.69:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/images/security.php"] [unique_id "aoSDomr_JutbFb-8svoN7gAAAb4"] [Tue Aug 18 13:09:06.771974 2026] [security2:error] [pid 167459:tid 167618] [client 20.1.169.243:10188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/atomlib.php"] [unique_id "aoSDomr_JutbFb-8svoN7wAAAaw"] [Tue Aug 18 13:09:06.819364 2026] [security2:error] [pid 167459:tid 167591] [client 20.1.169.243:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/k.php"] [unique_id "aoSDomr_JutbFb-8svoN8AAAAZE"] [Tue Aug 18 13:09:06.855958 2026] [security2:error] [pid 167459:tid 167690] [client 172.182.217.32:25742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "aoSDomr_JutbFb-8svoN8QAAAfQ"] [Tue Aug 18 13:09:06.857469 2026] [security2:error] [pid 167459:tid 167614] [client 168.62.48.100:16436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDomr_JutbFb-8svoN8gAAAag"] [Tue Aug 18 13:09:06.868725 2026] [security2:error] [pid 167459:tid 167589] [client 20.116.17.175:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/options.php"] [unique_id "aoSDomr_JutbFb-8svoN8wAAAY8"] [Tue Aug 18 13:09:06.887458 2026] [security2:error] [pid 167459:tid 167645] [client 20.226.36.136:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDomr_JutbFb-8svoN9QAAAcc"] [Tue Aug 18 13:09:06.899910 2026] [security2:error] [pid 167459:tid 167679] [client 158.23.17.4:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/nf.php"] [unique_id "aoSDomr_JutbFb-8svoN9gAAAek"] [Tue Aug 18 13:09:06.965016 2026] [security2:error] [pid 167459:tid 167615] [client 20.100.169.31:18986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/adminfuns.php"] [unique_id "aoSDomr_JutbFb-8svoN_AAAAak"] [Tue Aug 18 13:09:07.004266 2026] [security2:error] [pid 167459:tid 167518] [remote 162.241.152.27:39740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.152.241.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ondaparaty.com"] [uri "/wp-login.php"] [unique_id "aoSDo2r_JutbFb-8svoN_QABoDo"] [Tue Aug 18 13:09:07.028129 2026] [security2:error] [pid 167459:tid 167703] [client 158.23.17.4:5027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ev.php"] [unique_id "aoSDo2r_JutbFb-8svoN_gAAAgE"] [Tue Aug 18 13:09:07.057274 2026] [security2:error] [pid 167459:tid 167657] [client 172.213.243.2:19731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wpo.php"] [unique_id "aoSDo2r_JutbFb-8svoN_wAAAdM"] [Tue Aug 18 13:09:07.078836 2026] [security2:error] [pid 167459:tid 167594] [client 20.104.100.201:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/usr.php"] [unique_id "aoSDo2r_JutbFb-8svoOAAAAAZQ"] [Tue Aug 18 13:09:07.119405 2026] [security2:error] [pid 167459:tid 167671] [client 168.62.48.100:16498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDo2r_JutbFb-8svoOAQAAAeE"] [Tue Aug 18 13:09:07.124706 2026] [security2:error] [pid 167459:tid 167599] [client 20.250.13.23:17001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/languages.php"] [unique_id "aoSDo2r_JutbFb-8svoOAgAAAZk"] [Tue Aug 18 13:09:07.146386 2026] [security2:error] [pid 167459:tid 167644] [client 20.1.169.243:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/b.php"] [unique_id "aoSDo2r_JutbFb-8svoOBQAAAcY"] [Tue Aug 18 13:09:07.170445 2026] [security2:error] [pid 167459:tid 167714] [client 114.119.147.246:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bioclimaarcondicionado.com.br"] [uri "/manutencao-preventiva"] [unique_id "aoSDo2r_JutbFb-8svoOBwAAAgw"], referer: http://www.bioclimaarcondicionado.com.br/manutencao-preventiva [Tue Aug 18 13:09:07.195781 2026] [security2:error] [pid 167459:tid 167681] [client 20.1.169.243:8853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/license.php"] [unique_id "aoSDo2r_JutbFb-8svoOCQAAAes"] [Tue Aug 18 13:09:07.313832 2026] [security2:error] [pid 167459:tid 167670] [client 20.100.169.31:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDo2r_JutbFb-8svoOCwAAAeA"] [Tue Aug 18 13:09:07.319774 2026] [security2:error] [pid 167459:tid 167533] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/.__info.php"] [unique_id "aoSDo2r_JutbFb-8svoODAACBUk"] [Tue Aug 18 13:09:07.330560 2026] [security2:error] [pid 167459:tid 167673] [client 20.127.136.245:9510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/fpwch.php"] [unique_id "aoSDo2r_JutbFb-8svoODQAAAeM"] [Tue Aug 18 13:09:07.348534 2026] [autoindex:error] [pid 167459:tid 167664] [client 20.250.13.23:18227] AH01276: Cannot serve directory /home4/alltime/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:07.354124 2026] [security2:error] [pid 167459:tid 167630] [client 172.182.217.32:25637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/414.php"] [unique_id "aoSDo2r_JutbFb-8svoOEAAAAbg"] [Tue Aug 18 13:09:07.371410 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:2451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/dropdown.php"] [unique_id "aoSDo2r_JutbFb-8svoOEgAAAfY"] [Tue Aug 18 13:09:07.378448 2026] [security2:error] [pid 167459:tid 167623] [client 20.226.36.136:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/first.php"] [unique_id "aoSDo2r_JutbFb-8svoOFAAAAbE"] [Tue Aug 18 13:09:07.406622 2026] [security2:error] [pid 167459:tid 167649] [client 20.151.109.219:42804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/payout.php"] [unique_id "aoSDo2r_JutbFb-8svoOFQAAAcs"] [Tue Aug 18 13:09:07.407602 2026] [security2:error] [pid 167459:tid 167603] [client 74.248.130.103:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/222.php"] [unique_id "aoSDo2r_JutbFb-8svoOFgAAAZ0"] [Tue Aug 18 13:09:07.431176 2026] [security2:error] [pid 167459:tid 167687] [client 168.62.48.100:16388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDo2r_JutbFb-8svoOFwAAAfE"] [Tue Aug 18 13:09:07.465095 2026] [security2:error] [pid 167459:tid 167584] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/0.php"] [unique_id "aoSDo2r_JutbFb-8svoOGAACC3w"] [Tue Aug 18 13:09:07.470742 2026] [security2:error] [pid 167459:tid 167711] [client 172.213.243.2:19854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/a1vx.php"] [unique_id "aoSDo2r_JutbFb-8svoOGgAAAgk"] [Tue Aug 18 13:09:07.499156 2026] [security2:error] [pid 167459:tid 167682] [client 157.20.138.62:59575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDo2r_JutbFb-8svoOGwAAAew"] [Tue Aug 18 13:09:07.499271 2026] [security2:error] [pid 167459:tid 167682] [client 157.20.138.62:59575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDo2r_JutbFb-8svoOGwAAAew"] [Tue Aug 18 13:09:07.509439 2026] [security2:error] [pid 167459:tid 167698] [client 20.1.169.243:10239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/backup.php"] [unique_id "aoSDo2r_JutbFb-8svoOHgAAAfw"] [Tue Aug 18 13:09:07.545434 2026] [security2:error] [pid 167459:tid 167631] [client 4.232.151.198:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/aa.php"] [unique_id "aoSDo2r_JutbFb-8svoOIAAAAbk"] [Tue Aug 18 13:09:07.551385 2026] [security2:error] [pid 167459:tid 167689] [client 20.250.13.23:18227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDo2r_JutbFb-8svoOIQAAAfM"] [Tue Aug 18 13:09:07.559056 2026] [security2:error] [pid 167459:tid 167602] [client 20.1.169.243:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/load.php"] [unique_id "aoSDo2r_JutbFb-8svoOIwAAAZw"] [Tue Aug 18 13:09:07.605114 2026] [security2:error] [pid 167459:tid 167627] [client 20.100.169.31:3490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/akc.php"] [unique_id "aoSDo2r_JutbFb-8svoOJQAAAbU"] [Tue Aug 18 13:09:07.611283 2026] [security2:error] [pid 167459:tid 167479] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/07.php"] [unique_id "aoSDo2r_JutbFb-8svoOJgABqBM"] [Tue Aug 18 13:09:07.641264 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:07.641539 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:07.675027 2026] [security2:error] [pid 167459:tid 167642] [client 168.62.48.100:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDo2r_JutbFb-8svoOKAAAAcQ"] [Tue Aug 18 13:09:07.686996 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xs.php"] [unique_id "aoSDo2r_JutbFb-8svoOKgAAAeg"] [Tue Aug 18 13:09:07.690634 2026] [security2:error] [pid 167459:tid 167641] [client 213.35.127.232:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDo2r_JutbFb-8svoOKwAAAcM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:07.690737 2026] [security2:error] [pid 167459:tid 167691] [client 20.226.36.136:62168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDo2r_JutbFb-8svoOLAAAAfU"] [Tue Aug 18 13:09:07.692443 2026] [security2:error] [pid 167459:tid 167669] [client 178.153.171.161:40236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDo2r_JutbFb-8svoOLQAAAd8"] [Tue Aug 18 13:09:07.692555 2026] [security2:error] [pid 167459:tid 167669] [client 178.153.171.161:40236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDo2r_JutbFb-8svoOLQAAAd8"] [Tue Aug 18 13:09:07.707892 2026] [security2:error] [pid 167459:tid 167699] [client 20.38.3.247:2121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/admin.php"] [unique_id "aoSDo2r_JutbFb-8svoOLgAAAf0"] [Tue Aug 18 13:09:07.721554 2026] [security2:error] [pid 167459:tid 167638] [client 20.104.100.201:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/nwflm.php"] [unique_id "aoSDo2r_JutbFb-8svoOLwAAAcA"] [Tue Aug 18 13:09:07.750106 2026] [security2:error] [pid 167459:tid 167640] [client 20.116.17.175:52865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ot.php"] [unique_id "aoSDo2r_JutbFb-8svoOMgAAAcI"] [Tue Aug 18 13:09:07.754595 2026] [security2:error] [pid 167459:tid 167576] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/dropdown.php"] [unique_id "aoSDo2r_JutbFb-8svoOMwABoHQ"] [Tue Aug 18 13:09:07.808150 2026] [security2:error] [pid 167459:tid 167644] [client 40.74.65.169:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/coffexium.php"] [unique_id "aoSDo2r_JutbFb-8svoONQAAAcY"] [Tue Aug 18 13:09:07.816098 2026] [security2:error] [pid 167459:tid 167656] [client 74.249.206.207:8550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/puc.php"] [unique_id "aoSDo2r_JutbFb-8svoONgAAAdI"] [Tue Aug 18 13:09:07.848139 2026] [security2:error] [pid 167459:tid 167650] [client 172.182.217.32:25747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/gbaun.php"] [unique_id "aoSDo2r_JutbFb-8svoOOAAAAcw"] [Tue Aug 18 13:09:07.885120 2026] [security2:error] [pid 167459:tid 167681] [client 172.213.243.2:19537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ty.php"] [unique_id "aoSDo2r_JutbFb-8svoOOgAAAes"] [Tue Aug 18 13:09:07.897992 2026] [security2:error] [pid 167459:tid 167490] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSDo2r_JutbFb-8svoOOwAB6h4"] [Tue Aug 18 13:09:07.905867 2026] [security2:error] [pid 167459:tid 167624] [client 20.151.109.219:33827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/bh.php"] [unique_id "aoSDo2r_JutbFb-8svoOPAAAAbI"] [Tue Aug 18 13:09:07.912799 2026] [security2:error] [pid 167459:tid 167590] [client 20.1.169.243:10454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bak.php"] [unique_id "aoSDo2r_JutbFb-8svoOPgAAAZA"] [Tue Aug 18 13:09:07.919452 2026] [security2:error] [pid 167459:tid 167604] [client 168.62.48.100:16492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDo2r_JutbFb-8svoOPwAAAZ4"] [Tue Aug 18 13:09:07.922335 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/manager.php"] [unique_id "aoSDo2r_JutbFb-8svoOQAAAAeE"] [Tue Aug 18 13:09:07.954446 2026] [security2:error] [pid 167459:tid 167600] [client 20.100.169.31:2975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDo2r_JutbFb-8svoORwAAAZo"] [Tue Aug 18 13:09:07.955220 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/nw.php"] [unique_id "aoSDo2r_JutbFb-8svoOSAAAAgU"] [Tue Aug 18 13:09:07.993185 2026] [security2:error] [pid 167459:tid 167692] [client 20.65.98.162:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/h.php"] [unique_id "aoSDo2r_JutbFb-8svoOUQAAAfY"] [Tue Aug 18 13:09:08.042649 2026] [security2:error] [pid 167459:tid 167563] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-sigunq.php"] [unique_id "aoSDpGr_JutbFb-8svoOVwAB5mc"] [Tue Aug 18 13:09:08.044267 2026] [security2:error] [pid 167459:tid 167620] [client 158.23.17.4:48417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/of.php"] [unique_id "aoSDpGr_JutbFb-8svoOWQAAAa4"] [Tue Aug 18 13:09:08.103642 2026] [security2:error] [pid 167459:tid 167631] [client 158.23.17.4:39128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/lmfi2.php"] [unique_id "aoSDpGr_JutbFb-8svoOXQAAAbk"] [Tue Aug 18 13:09:08.122178 2026] [security2:error] [pid 167459:tid 167591] [client 130.89.144.171:50992] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "netfactory.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDpGr_JutbFb-8svoOXwAAAZE"] [Tue Aug 18 13:09:08.159128 2026] [security2:error] [pid 167459:tid 167627] [client 20.127.136.245:23869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDpGr_JutbFb-8svoOYQAAAbU"] [Tue Aug 18 13:09:08.178715 2026] [security2:error] [pid 167459:tid 167664] [client 20.250.13.23:18193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSDpGr_JutbFb-8svoOYgAAAdo"] [Tue Aug 18 13:09:08.186396 2026] [security2:error] [pid 167459:tid 167511] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wso112233.php"] [unique_id "aoSDpGr_JutbFb-8svoOYwABzjM"] [Tue Aug 18 13:09:08.187587 2026] [security2:error] [pid 167459:tid 167691] [client 74.248.130.103:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/key.php"] [unique_id "aoSDpGr_JutbFb-8svoOZAAAAfU"] [Tue Aug 18 13:09:08.196777 2026] [security2:error] [pid 167459:tid 167699] [client 168.62.48.100:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDpGr_JutbFb-8svoOZQAAAf0"] [Tue Aug 18 13:09:08.236453 2026] [security2:error] [pid 167459:tid 167711] [client 20.100.169.31:3489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/buy.php"] [unique_id "aoSDpGr_JutbFb-8svoOaQAAAgk"] [Tue Aug 18 13:09:08.251406 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:08.251684 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:08.265760 2026] [security2:error] [pid 167459:tid 167594] [client 20.226.36.136:62158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDpGr_JutbFb-8svoOawAAAZQ"] [Tue Aug 18 13:09:08.277772 2026] [security2:error] [pid 167459:tid 167613] [client 20.1.169.243:10258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bgymj.php"] [unique_id "aoSDpGr_JutbFb-8svoObQAAAac"] [Tue Aug 18 13:09:08.299938 2026] [security2:error] [pid 167459:tid 167714] [client 172.213.243.2:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/vgtyu.php"] [unique_id "aoSDpGr_JutbFb-8svoObgAAAgw"] [Tue Aug 18 13:09:08.318108 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:9566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/media.php"] [unique_id "aoSDpGr_JutbFb-8svoObwAAAcU"] [Tue Aug 18 13:09:08.340316 2026] [security2:error] [pid 167459:tid 167685] [client 172.182.217.32:25550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/themes.php"] [unique_id "aoSDpGr_JutbFb-8svoOcQAAAe8"] [Tue Aug 18 13:09:08.357147 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:3330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDpGr_JutbFb-8svoOcwAAAec"] [Tue Aug 18 13:09:08.368018 2026] [security2:error] [pid 167459:tid 167639] [client 4.232.151.198:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/images/about.php"] [unique_id "aoSDpGr_JutbFb-8svoOdAAAAcE"] [Tue Aug 18 13:09:08.377249 2026] [security2:error] [pid 167459:tid 167660] [client 20.104.100.201:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/wp-load.php"] [unique_id "aoSDpGr_JutbFb-8svoOdgAAAdY"] [Tue Aug 18 13:09:08.403557 2026] [security2:error] [pid 167459:tid 167601] [client 20.116.17.175:22743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "aoSDpGr_JutbFb-8svoOeAAAAZs"] [Tue Aug 18 13:09:08.404481 2026] [security2:error] [pid 167459:tid 167632] [client 20.226.36.136:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDpGr_JutbFb-8svoOeQAAAbo"] [Tue Aug 18 13:09:08.443021 2026] [security2:error] [pid 167459:tid 167608] [client 74.248.18.37:14493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/php8.php"] [unique_id "aoSDpGr_JutbFb-8svoOfAAAAaI"] [Tue Aug 18 13:09:08.450446 2026] [security2:error] [pid 167459:tid 167623] [client 168.62.48.100:16422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDpGr_JutbFb-8svoOfQAAAbE"] [Tue Aug 18 13:09:08.482202 2026] [security2:error] [pid 167459:tid 167586] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpGr_JutbFb-8svoOfgABln4"] [Tue Aug 18 13:09:08.482356 2026] [security2:error] [pid 167459:tid 167596] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpGr_JutbFb-8svoOfgABln4"] [Tue Aug 18 13:09:08.532559 2026] [autoindex:error] [pid 167459:tid 167676] [client 130.89.144.171:47750] AH01276: Cannot serve directory /home2/netfactory/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:08.533540 2026] [security2:error] [pid 167459:tid 167676] [client 130.89.144.171:47750] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "netfactory.com.br"] [uri "/cgi-sys/403.html"] [unique_id "aoSDpGr_JutbFb-8svoOfwAAAeY"] [Tue Aug 18 13:09:08.544112 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:08.544362 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:08.584623 2026] [security2:error] [pid 167459:tid 167604] [client 20.250.13.23:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSDpGr_JutbFb-8svoOigAAAZ4"] [Tue Aug 18 13:09:08.584892 2026] [security2:error] [pid 167459:tid 167599] [client 172.182.217.32:15563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/666.php"] [unique_id "aoSDpGr_JutbFb-8svoOiwAAAZk"] [Tue Aug 18 13:09:08.608712 2026] [security2:error] [pid 167459:tid 167535] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/alfanew.php"] [unique_id "aoSDpGr_JutbFb-8svoOjwAB-Es"] [Tue Aug 18 13:09:08.645065 2026] [security2:error] [pid 167459:tid 167675] [client 101.53.230.88:48597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.230.53.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpGr_JutbFb-8svoOkQAAAeU"] [Tue Aug 18 13:09:08.645218 2026] [security2:error] [pid 167459:tid 167675] [client 101.53.230.88:48597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpGr_JutbFb-8svoOkQAAAeU"] [Tue Aug 18 13:09:08.660181 2026] [security2:error] [pid 167459:tid 167686] [client 147.90.234.30:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.234.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDpGr_JutbFb-8svoOcAAAAfA"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:08.660274 2026] [security2:error] [pid 167459:tid 167686] [client 147.90.234.30:60092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDpGr_JutbFb-8svoOcAAAAfA"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:08.671064 2026] [security2:error] [pid 167459:tid 167593] [client 20.226.36.136:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDpGr_JutbFb-8svoOkgAAAZM"] [Tue Aug 18 13:09:08.679269 2026] [security2:error] [pid 167459:tid 167662] [client 20.1.169.243:8877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/mar.php"] [unique_id "aoSDpGr_JutbFb-8svoOlAAAAdg"] [Tue Aug 18 13:09:08.685681 2026] [security2:error] [pid 167459:tid 167614] [client 158.23.17.4:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fd.php"] [unique_id "aoSDpGr_JutbFb-8svoOlQAAAag"] [Tue Aug 18 13:09:08.689371 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:10228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bi.php"] [unique_id "aoSDpGr_JutbFb-8svoOlgAAAbQ"] [Tue Aug 18 13:09:08.707371 2026] [security2:error] [pid 167459:tid 167590] [client 213.35.127.232:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDpGr_JutbFb-8svoOnwAAAZA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:08.708113 2026] [security2:error] [pid 167459:tid 167627] [client 172.213.243.2:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/mans.php"] [unique_id "aoSDpGr_JutbFb-8svoOoAAAAbU"] [Tue Aug 18 13:09:08.708780 2026] [security2:error] [pid 167459:tid 167670] [client 168.62.48.100:16409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDpGr_JutbFb-8svoOoQAAAeA"] [Tue Aug 18 13:09:08.736865 2026] [security2:error] [pid 167459:tid 167652] [client 20.38.3.247:14998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/mac.php"] [unique_id "aoSDpGr_JutbFb-8svoOogAAAc4"] [Tue Aug 18 13:09:08.746256 2026] [security2:error] [pid 167459:tid 167625] [client 74.248.133.44:13125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/berax.php"] [unique_id "aoSDpGr_JutbFb-8svoOowAAAbM"] [Tue Aug 18 13:09:08.747998 2026] [security2:error] [pid 167459:tid 167709] [client 172.182.217.32:15757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/bgymj.php"] [unique_id "aoSDpGr_JutbFb-8svoOpAAAAgc"] [Tue Aug 18 13:09:08.749510 2026] [security2:error] [pid 167459:tid 167513] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/fw.php"] [unique_id "aoSDpGr_JutbFb-8svoOpQABwDU"] [Tue Aug 18 13:09:08.786177 2026] [security2:error] [pid 167459:tid 167710] [client 20.100.169.31:2620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDpGr_JutbFb-8svoOpwAAAgg"] [Tue Aug 18 13:09:08.797424 2026] [security2:error] [pid 167459:tid 167689] [client 20.250.13.23:18185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/f7.php"] [unique_id "aoSDpGr_JutbFb-8svoOqQAAAfM"] [Tue Aug 18 13:09:08.798774 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDpGr_JutbFb-8svoOqgAAAZU"] [Tue Aug 18 13:09:08.840807 2026] [security2:error] [pid 167459:tid 167646] [client 172.182.217.32:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/wpr-addons/forms/RxRzhwix.php"] [unique_id "aoSDpGr_JutbFb-8svoOrwAAAcg"] [Tue Aug 18 13:09:08.850059 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:08.850476 2026] [authz_core:error] [pid 167459:tid 167542] [remote 216.73.216.206:36366] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:08.856364 2026] [security2:error] [pid 167459:tid 167643] [client 20.104.100.201:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/jj.php"] [unique_id "aoSDpGr_JutbFb-8svoOtQAAAcU"] [Tue Aug 18 13:09:08.869227 2026] [security2:error] [pid 167459:tid 167605] [client 20.100.169.31:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/cong.php"] [unique_id "aoSDpGr_JutbFb-8svoOtwAAAZ8"] [Tue Aug 18 13:09:08.887522 2026] [security2:error] [pid 167459:tid 167685] [client 74.248.130.103:28945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/chosen.php"] [unique_id "aoSDpGr_JutbFb-8svoOuAAAAe8"] [Tue Aug 18 13:09:08.888075 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:18375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/v5.php"] [unique_id "aoSDpGr_JutbFb-8svoOuQAAAZI"] [Tue Aug 18 13:09:08.970713 2026] [security2:error] [pid 167459:tid 167596] [client 168.62.48.100:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDpGr_JutbFb-8svoOxAAAAZY"] [Tue Aug 18 13:09:08.994567 2026] [security2:error] [pid 167459:tid 167633] [client 74.248.18.37:25356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSDpGr_JutbFb-8svoOxwAAAbs"] [Tue Aug 18 13:09:09.044270 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/my1.php"] [unique_id "aoSDpWr_JutbFb-8svoOyQAAAZs"] [Tue Aug 18 13:09:09.044640 2026] [security2:error] [pid 167459:tid 167673] [client 20.151.109.219:36697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/ct.php"] [unique_id "aoSDpWr_JutbFb-8svoOygAAAeM"] [Tue Aug 18 13:09:09.052909 2026] [security2:error] [pid 167459:tid 167653] [client 20.1.169.243:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/blog.php"] [unique_id "aoSDpWr_JutbFb-8svoOzAAAAc8"] [Tue Aug 18 13:09:09.060587 2026] [security2:error] [pid 167459:tid 167703] [client 20.226.36.136:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDpWr_JutbFb-8svoOzQAAAgE"] [Tue Aug 18 13:09:09.075866 2026] [security2:error] [pid 167459:tid 167510] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-login.php"] [unique_id "aoSDpGr_JutbFb-8svoOuwABwTI"] [Tue Aug 18 13:09:09.114362 2026] [security2:error] [pid 167459:tid 167593] [client 40.74.65.169:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDpWr_JutbFb-8svoO0QAAAZM"] [Tue Aug 18 13:09:09.126872 2026] [security2:error] [pid 167459:tid 167690] [client 172.213.243.2:19853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/co.php"] [unique_id "aoSDpWr_JutbFb-8svoO0wAAAfQ"] [Tue Aug 18 13:09:09.129918 2026] [security2:error] [pid 167459:tid 167683] [client 4.232.151.198:2623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDpWr_JutbFb-8svoO1AAAAe0"] [Tue Aug 18 13:09:09.197842 2026] [security2:error] [pid 167459:tid 167652] [client 20.226.36.136:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDpWr_JutbFb-8svoO1QAAAc4"] [Tue Aug 18 13:09:09.213940 2026] [autoindex:error] [pid 167459:tid 167651] [client 20.250.13.23:5938] AH01276: Cannot serve directory /home2/sunlux/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:09.215194 2026] [security2:error] [pid 167459:tid 167589] [client 168.62.48.100:16468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDpWr_JutbFb-8svoO1wAAAY8"] [Tue Aug 18 13:09:09.219888 2026] [security2:error] [pid 167459:tid 167508] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/simple.php"] [unique_id "aoSDpWr_JutbFb-8svoO2AABwjA"] [Tue Aug 18 13:09:09.234234 2026] [security2:error] [pid 167459:tid 167624] [client 172.182.217.32:15596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/bthil.php"] [unique_id "aoSDpWr_JutbFb-8svoO2QAAAbI"] [Tue Aug 18 13:09:09.238901 2026] [security2:error] [pid 167459:tid 167710] [client 20.38.3.247:16012] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/1.php"] [unique_id "aoSDpWr_JutbFb-8svoO2gAAAgg"] [Tue Aug 18 13:09:09.238984 2026] [security2:error] [pid 167459:tid 167710] [client 20.38.3.247:16012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/1.php"] [unique_id "aoSDpWr_JutbFb-8svoO2gAAAgg"] [Tue Aug 18 13:09:09.333764 2026] [security2:error] [pid 167459:tid 167627] [client 172.182.217.32:25168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-content/uploads/wpr-addons/forms/b1ack.php"] [unique_id "aoSDpWr_JutbFb-8svoO4AAAAbU"] [Tue Aug 18 13:09:09.365085 2026] [security2:error] [pid 167459:tid 167585] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/classsmtps.php"] [unique_id "aoSDpWr_JutbFb-8svoO5QAB6X0"] [Tue Aug 18 13:09:09.419252 2026] [security2:error] [pid 167459:tid 167696] [client 20.226.36.136:65287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.36.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.webeb.com.br"] [uri "/images/security.php"] [unique_id "aoSDpWr_JutbFb-8svoO5wAAAfo"] [Tue Aug 18 13:09:09.421037 2026] [security2:error] [pid 167459:tid 167671] [client 20.250.13.23:5938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDpWr_JutbFb-8svoO6AAAAeE"] [Tue Aug 18 13:09:09.422702 2026] [security2:error] [pid 167459:tid 167613] [client 20.1.169.243:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bs1.php"] [unique_id "aoSDpWr_JutbFb-8svoO6gAAAac"] [Tue Aug 18 13:09:09.425957 2026] [security2:error] [pid 167459:tid 167700] [client 20.250.13.23:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/photo.php"] [unique_id "aoSDpWr_JutbFb-8svoO6wAAAf4"] [Tue Aug 18 13:09:09.428706 2026] [security2:error] [pid 167459:tid 167558] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDpWr_JutbFb-8svoO7AAB0mI"] [Tue Aug 18 13:09:09.450887 2026] [security2:error] [pid 167459:tid 167684] [client 20.1.169.243:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/mm.php"] [unique_id "aoSDpWr_JutbFb-8svoO7QAAAe4"] [Tue Aug 18 13:09:09.462703 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:7196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/bu.php"] [unique_id "aoSDpWr_JutbFb-8svoO7wAAAg4"] [Tue Aug 18 13:09:09.493926 2026] [security2:error] [pid 167459:tid 167595] [client 20.100.169.31:3462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/css/classwithtostring.php"] [unique_id "aoSDpWr_JutbFb-8svoO8wAAAZU"] [Tue Aug 18 13:09:09.512788 2026] [security2:error] [pid 167459:tid 167495] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDpWr_JutbFb-8svoO9AAByyM"] [Tue Aug 18 13:09:09.528307 2026] [security2:error] [pid 167459:tid 167619] [client 74.248.18.37:21186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDpWr_JutbFb-8svoO9QAAAa0"] [Tue Aug 18 13:09:09.541129 2026] [security2:error] [pid 167459:tid 167615] [client 74.248.133.44:18491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fi2.php"] [unique_id "aoSDpWr_JutbFb-8svoO9gAAAak"] [Tue Aug 18 13:09:09.560240 2026] [security2:error] [pid 167459:tid 167691] [client 4.232.151.198:42118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDpWr_JutbFb-8svoO-gAAAfU"] [Tue Aug 18 13:09:09.598396 2026] [security2:error] [pid 167459:tid 167673] [client 168.62.48.100:16414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDpWr_JutbFb-8svoO_QAAAeM"] [Tue Aug 18 13:09:09.623980 2026] [security2:error] [pid 167459:tid 167701] [client 172.213.243.2:14729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/btx25.php"] [unique_id "aoSDpWr_JutbFb-8svoO_wAAAf8"] [Tue Aug 18 13:09:09.632817 2026] [security2:error] [pid 167459:tid 167604] [client 20.100.169.31:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDpWr_JutbFb-8svoPAAAAAZ4"] [Tue Aug 18 13:09:09.642653 2026] [security2:error] [pid 167459:tid 167602] [client 20.116.17.175:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/uploads/users.php"] [unique_id "aoSDpWr_JutbFb-8svoPAgAAAZw"] [Tue Aug 18 13:09:09.652913 2026] [security2:error] [pid 167459:tid 167706] [client 74.248.18.37:3385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/222.php"] [unique_id "aoSDpWr_JutbFb-8svoPAwAAAgQ"] [Tue Aug 18 13:09:09.659100 2026] [security2:error] [pid 167459:tid 167533] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-trackback.php"] [unique_id "aoSDpWr_JutbFb-8svoPBAAB5Uk"] [Tue Aug 18 13:09:09.689988 2026] [security2:error] [pid 167459:tid 167690] [client 20.116.17.175:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/replace.php"] [unique_id "aoSDpWr_JutbFb-8svoPBQAAAfQ"] [Tue Aug 18 13:09:09.696347 2026] [security2:error] [pid 167459:tid 167507] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.env"] [unique_id "aoSDpWr_JutbFb-8svoPCAABqC8"] [Tue Aug 18 13:09:09.701989 2026] [security2:error] [pid 167459:tid 167688] [client 114.5.214.109:50421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpWr_JutbFb-8svoPCgAAAfI"] [Tue Aug 18 13:09:09.712634 2026] [security2:error] [pid 167459:tid 167688] [client 114.5.214.109:50421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpWr_JutbFb-8svoPCgAAAfI"] [Tue Aug 18 13:09:09.721987 2026] [security2:error] [pid 167459:tid 167698] [client 172.182.217.32:15585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/xp.php"] [unique_id "aoSDpWr_JutbFb-8svoPCwAAAfw"] [Tue Aug 18 13:09:09.724448 2026] [security2:error] [pid 167459:tid 167592] [client 213.35.127.232:55966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDpWr_JutbFb-8svoPDAAAAZI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:09.735889 2026] [security2:error] [pid 167459:tid 167637] [client 158.23.17.4:39574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/info2.php"] [unique_id "aoSDpWr_JutbFb-8svoPDQAAAb8"] [Tue Aug 18 13:09:09.742128 2026] [security2:error] [pid 167459:tid 167625] [client 20.104.100.201:9503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/img.php"] [unique_id "aoSDpWr_JutbFb-8svoPDgAAAbM"] [Tue Aug 18 13:09:09.792603 2026] [security2:error] [pid 167459:tid 167710] [client 74.248.130.103:28957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/wpxml.php"] [unique_id "aoSDpWr_JutbFb-8svoPDwAAAgg"] [Tue Aug 18 13:09:09.800904 2026] [security2:error] [pid 167459:tid 167713] [client 20.1.169.243:10466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bthil.php"] [unique_id "aoSDpWr_JutbFb-8svoPEAAAAgs"] [Tue Aug 18 13:09:09.803986 2026] [security2:error] [pid 167459:tid 167501] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-signup.php"] [unique_id "aoSDpWr_JutbFb-8svoPEQABoCk"] [Tue Aug 18 13:09:09.815336 2026] [security2:error] [pid 167459:tid 167683] [client 20.1.169.243:9290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/network.php"] [unique_id "aoSDpWr_JutbFb-8svoPEgAAAe0"] [Tue Aug 18 13:09:09.817619 2026] [security2:error] [pid 167459:tid 167584] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDpWr_JutbFb-8svoPEwAB0Xw"] [Tue Aug 18 13:09:09.825597 2026] [security2:error] [pid 167459:tid 167593] [client 172.182.217.32:25613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSDpWr_JutbFb-8svoPFAAAAZM"] [Tue Aug 18 13:09:09.845184 2026] [security2:error] [pid 167459:tid 167663] [client 20.127.136.245:9533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/about/function.php"] [unique_id "aoSDpWr_JutbFb-8svoPFQAAAdk"] [Tue Aug 18 13:09:09.853952 2026] [security2:error] [pid 167459:tid 167681] [client 168.62.48.100:16405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDpWr_JutbFb-8svoPFgAAAes"] [Tue Aug 18 13:09:09.895961 2026] [security2:error] [pid 167459:tid 167662] [client 4.232.151.198:2617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/images/index.php"] [unique_id "aoSDpWr_JutbFb-8svoPGAAAAdg"] [Tue Aug 18 13:09:09.948762 2026] [security2:error] [pid 167459:tid 167656] [client 20.38.3.247:14985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/coffee.php"] [unique_id "aoSDpWr_JutbFb-8svoPHQAAAdI"] [Tue Aug 18 13:09:09.948786 2026] [security2:error] [pid 167459:tid 167709] [client 20.151.109.219:42786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/gy.php"] [unique_id "aoSDpWr_JutbFb-8svoPHAAAAgc"] [Tue Aug 18 13:09:09.948949 2026] [security2:error] [pid 167459:tid 167538] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSDpWr_JutbFb-8svoPHgACBU4"] [Tue Aug 18 13:09:09.956911 2026] [security2:error] [pid 167459:tid 167576] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/dirs.php"] [unique_id "aoSDpWr_JutbFb-8svoPHwAB83Q"] [Tue Aug 18 13:09:09.998909 2026] [security2:error] [pid 167459:tid 167490] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.env.backup"] [unique_id "aoSDpWr_JutbFb-8svoPIwAB1h4"] [Tue Aug 18 13:09:10.036681 2026] [security2:error] [pid 167459:tid 167626] [client 20.250.13.23:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSDpmr_JutbFb-8svoPJAAAAbQ"] [Tue Aug 18 13:09:10.040120 2026] [security2:error] [pid 167459:tid 167645] [client 20.250.13.23:18385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-aa.php"] [unique_id "aoSDpmr_JutbFb-8svoPJQAAAcc"] [Tue Aug 18 13:09:10.046549 2026] [security2:error] [pid 167459:tid 167647] [client 40.74.65.169:10468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/sf.php"] [unique_id "aoSDpmr_JutbFb-8svoPJgAAAck"] [Tue Aug 18 13:09:10.061756 2026] [security2:error] [pid 167459:tid 167654] [client 172.213.243.2:14377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/avim.php"] [unique_id "aoSDpmr_JutbFb-8svoPJwAAAdA"] [Tue Aug 18 13:09:10.092664 2026] [security2:error] [pid 167459:tid 167480] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDpmr_JutbFb-8svoPKgABnxQ"] [Tue Aug 18 13:09:10.100447 2026] [security2:error] [pid 167459:tid 167527] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fresh.php"] [unique_id "aoSDpmr_JutbFb-8svoPKwABu0M"] [Tue Aug 18 13:09:10.113226 2026] [security2:error] [pid 167459:tid 167691] [client 168.62.48.100:16413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDpmr_JutbFb-8svoPLAAAAfU"] [Tue Aug 18 13:09:10.116656 2026] [security2:error] [pid 167459:tid 167628] [client 20.100.169.31:3503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/db.php"] [unique_id "aoSDpmr_JutbFb-8svoPLgAAAbY"] [Tue Aug 18 13:09:10.118354 2026] [security2:error] [pid 167459:tid 167478] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.env.bak"] [unique_id "aoSDpmr_JutbFb-8svoPLQAB1hI"] [Tue Aug 18 13:09:10.120935 2026] [security2:error] [pid 167459:tid 167462] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.env.old"] [unique_id "aoSDpmr_JutbFb-8svoPLwAB1gI"] [Tue Aug 18 13:09:10.166544 2026] [security2:error] [pid 167459:tid 167705] [client 20.1.169.243:10468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/bypass.php"] [unique_id "aoSDpmr_JutbFb-8svoPMQAAAgM"] [Tue Aug 18 13:09:10.178917 2026] [security2:error] [pid 167459:tid 167596] [client 20.1.169.243:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/new.php"] [unique_id "aoSDpmr_JutbFb-8svoPMgAAAZY"] [Tue Aug 18 13:09:10.210812 2026] [security2:error] [pid 167459:tid 167649] [client 172.182.217.32:15607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/reze.php"] [unique_id "aoSDpmr_JutbFb-8svoPMwAAAcs"] [Tue Aug 18 13:09:10.220991 2026] [security2:error] [pid 167459:tid 167623] [client 158.23.17.4:38380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sx.php"] [unique_id "aoSDpmr_JutbFb-8svoPNQAAAbE"] [Tue Aug 18 13:09:10.236977 2026] [security2:error] [pid 167459:tid 167536] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-activate.php"] [unique_id "aoSDpmr_JutbFb-8svoPNgACAUw"] [Tue Aug 18 13:09:10.245634 2026] [security2:error] [pid 167459:tid 167477] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/admin404.php"] [unique_id "aoSDpmr_JutbFb-8svoPNwABnhE"] [Tue Aug 18 13:09:10.251684 2026] [security2:error] [pid 167459:tid 167489] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/api/.env"] [unique_id "aoSDpmr_JutbFb-8svoPOAABwR0"] [Tue Aug 18 13:09:10.265688 2026] [security2:error] [pid 167459:tid 167619] [client 20.100.169.31:2896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSDpmr_JutbFb-8svoPOgAAAa0"] [Tue Aug 18 13:09:10.287071 2026] [security2:error] [pid 167459:tid 167658] [client 74.248.18.37:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSDpmr_JutbFb-8svoPPgAAAdQ"] [Tue Aug 18 13:09:10.305631 2026] [security2:error] [pid 167459:tid 167476] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/backend/.env"] [unique_id "aoSDpmr_JutbFb-8svoPQAABphA"] [Tue Aug 18 13:09:10.307065 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.133.44:13153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/feeds.php"] [unique_id "aoSDpmr_JutbFb-8svoPQQAAAd8"] [Tue Aug 18 13:09:10.314999 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "aoSDpmr_JutbFb-8svoPQwAAAb4"] [Tue Aug 18 13:09:10.340802 2026] [security2:error] [pid 167459:tid 167485] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/config/.env"] [unique_id "aoSDpmr_JutbFb-8svoPRAABphk"] [Tue Aug 18 13:09:10.380941 2026] [security2:error] [pid 167459:tid 167473] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/post.php"] [unique_id "aoSDpmr_JutbFb-8svoPRgABvw0"] [Tue Aug 18 13:09:10.394771 2026] [security2:error] [pid 167459:tid 167529] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/loading.php"] [unique_id "aoSDpmr_JutbFb-8svoPRwAB10U"] [Tue Aug 18 13:09:10.468653 2026] [security2:error] [pid 167459:tid 167617] [client 168.62.48.100:16490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDpmr_JutbFb-8svoPTgAAAas"] [Tue Aug 18 13:09:10.480216 2026] [security2:error] [pid 167459:tid 167646] [client 20.38.3.247:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDpmr_JutbFb-8svoPTwAAAcg"] [Tue Aug 18 13:09:10.496645 2026] [security2:error] [pid 167459:tid 167681] [client 20.151.109.219:33495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/tt.php"] [unique_id "aoSDpmr_JutbFb-8svoPUQAAAes"] [Tue Aug 18 13:09:10.508071 2026] [security2:error] [pid 167459:tid 167638] [client 197.184.64.235:42698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpmr_JutbFb-8svoPUgAAAcA"] [Tue Aug 18 13:09:10.508165 2026] [security2:error] [pid 167459:tid 167685] [client 74.248.130.103:45794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/file1221.php"] [unique_id "aoSDpmr_JutbFb-8svoPUwAAAe8"] [Tue Aug 18 13:09:10.508178 2026] [security2:error] [pid 167459:tid 167638] [client 197.184.64.235:42698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDpmr_JutbFb-8svoPUgAAAcA"] [Tue Aug 18 13:09:10.524666 2026] [security2:error] [pid 167459:tid 167474] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDpmr_JutbFb-8svoPVQAB2A4"] [Tue Aug 18 13:09:10.538102 2026] [security2:error] [pid 167459:tid 167541] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/conn-test.php"] [unique_id "aoSDpmr_JutbFb-8svoPWAAB4lE"] [Tue Aug 18 13:09:10.563650 2026] [security2:error] [pid 167459:tid 167700] [client 172.213.243.2:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/myfile.php"] [unique_id "aoSDpmr_JutbFb-8svoPXQAAAf4"] [Tue Aug 18 13:09:10.577358 2026] [security2:error] [pid 167459:tid 167683] [client 20.1.169.243:8872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/0x.php"] [unique_id "aoSDpmr_JutbFb-8svoPXgAAAe0"] [Tue Aug 18 13:09:10.649342 2026] [security2:error] [pid 167459:tid 167712] [client 20.250.13.23:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/w1.php"] [unique_id "aoSDpmr_JutbFb-8svoPYwAAAgo"] [Tue Aug 18 13:09:10.651514 2026] [security2:error] [pid 167459:tid 167713] [client 20.250.13.23:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/f7.php"] [unique_id "aoSDpmr_JutbFb-8svoPZAAAAgs"] [Tue Aug 18 13:09:10.656138 2026] [security2:error] [pid 167459:tid 167606] [client 20.250.13.23:18207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/d.php"] [unique_id "aoSDpmr_JutbFb-8svoPZQAAAaA"] [Tue Aug 18 13:09:10.660665 2026] [security2:error] [pid 167459:tid 167594] [client 20.1.169.243:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cc.php"] [unique_id "aoSDpmr_JutbFb-8svoPZgAAAZQ"] [Tue Aug 18 13:09:10.668973 2026] [security2:error] [pid 167459:tid 167566] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/hoot.php"] [unique_id "aoSDpmr_JutbFb-8svoPZwAB02o"] [Tue Aug 18 13:09:10.682727 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.100.201:53299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemdolarrs.com.br"] [uri "/we.php"] [unique_id "aoSDpmr_JutbFb-8svoPaAAAAZU"] [Tue Aug 18 13:09:10.690371 2026] [security2:error] [pid 167459:tid 167550] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/evil.php"] [unique_id "aoSDpmr_JutbFb-8svoPaQABolo"] [Tue Aug 18 13:09:10.707245 2026] [security2:error] [pid 167459:tid 167696] [client 172.182.217.32:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/2026w.php"] [unique_id "aoSDpmr_JutbFb-8svoPagAAAfo"] [Tue Aug 18 13:09:10.715469 2026] [security2:error] [pid 167459:tid 167598] [client 20.100.169.31:3468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/dropdown.php"] [unique_id "aoSDpmr_JutbFb-8svoPawAAAZg"] [Tue Aug 18 13:09:10.742111 2026] [security2:error] [pid 167459:tid 167605] [client 40.74.65.169:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/k.php"] [unique_id "aoSDpmr_JutbFb-8svoPbgAAAZ8"] [Tue Aug 18 13:09:10.744038 2026] [security2:error] [pid 167459:tid 167589] [client 213.35.127.232:56197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDpmr_JutbFb-8svoPbwAAAY8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:10.745711 2026] [security2:error] [pid 167459:tid 167611] [client 168.62.48.100:16412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDpmr_JutbFb-8svoPcAAAAaU"] [Tue Aug 18 13:09:10.754491 2026] [security2:error] [pid 167459:tid 167676] [client 20.104.100.201:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/css/database.php"] [unique_id "aoSDpmr_JutbFb-8svoPcgAAAeY"] [Tue Aug 18 13:09:10.806819 2026] [security2:error] [pid 167459:tid 167715] [client 172.182.217.32:25608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDpmr_JutbFb-8svoPcwAAAg0"] [Tue Aug 18 13:09:10.819059 2026] [security2:error] [pid 167459:tid 167496] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/log.php"] [unique_id "aoSDpmr_JutbFb-8svoPdQABliQ"] [Tue Aug 18 13:09:10.826985 2026] [security2:error] [pid 167459:tid 167601] [client 20.116.17.175:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/fw/faiyy.php"] [unique_id "aoSDpmr_JutbFb-8svoPeAAAAZs"] [Tue Aug 18 13:09:10.838669 2026] [security2:error] [pid 167459:tid 167497] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-key.php"] [unique_id "aoSDpmr_JutbFb-8svoPeQAB7CU"] [Tue Aug 18 13:09:10.887007 2026] [autoindex:error] [pid 167459:tid 167616] [client 20.100.169.31:36207] AH01276: Cannot serve directory /home1/t5n37y9g/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:10.901452 2026] [security2:error] [pid 167459:tid 167626] [client 20.100.169.31:2954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDpmr_JutbFb-8svoPfwAAAbQ"] [Tue Aug 18 13:09:10.925914 2026] [security2:error] [pid 167459:tid 167658] [client 158.23.17.4:39153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nu.php"] [unique_id "aoSDpmr_JutbFb-8svoPgQAAAdQ"] [Tue Aug 18 13:09:10.926508 2026] [security2:error] [pid 167459:tid 167673] [client 158.23.17.4:40437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/xv.php"] [unique_id "aoSDpmr_JutbFb-8svoPggAAAeM"] [Tue Aug 18 13:09:10.930594 2026] [security2:error] [pid 167459:tid 167665] [client 74.248.18.37:3336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSDpmr_JutbFb-8svoPhAAAAds"] [Tue Aug 18 13:09:10.941282 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:8839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/0.php"] [unique_id "aoSDpmr_JutbFb-8svoPhQAAAgI"] [Tue Aug 18 13:09:10.953205 2026] [security2:error] [pid 167459:tid 167466] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.github/.env"] [unique_id "aoSDpmr_JutbFb-8svoPhgAB_wY"] [Tue Aug 18 13:09:10.960737 2026] [security2:error] [pid 167459:tid 167634] [client 4.232.151.198:2360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/includes/about.php"] [unique_id "aoSDpmr_JutbFb-8svoPiAAAAbw"] [Tue Aug 18 13:09:10.962745 2026] [security2:error] [pid 167459:tid 167562] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/bak.php"] [unique_id "aoSDpmr_JutbFb-8svoPiQAB9GY"] [Tue Aug 18 13:09:10.978938 2026] [security2:error] [pid 167459:tid 167488] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/phpcheck.php"] [unique_id "aoSDpmr_JutbFb-8svoPiwACBhw"] [Tue Aug 18 13:09:11.011932 2026] [security2:error] [pid 167459:tid 167716] [client 74.248.130.103:28942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/nox.php"] [unique_id "aoSDp2r_JutbFb-8svoPjwAAAg4"] [Tue Aug 18 13:09:11.016470 2026] [security2:error] [pid 167459:tid 167597] [client 172.213.243.2:18609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xmy.php"] [unique_id "aoSDp2r_JutbFb-8svoPkAAAAZc"] [Tue Aug 18 13:09:11.029773 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:9676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDp2r_JutbFb-8svoPkQAAAgQ"] [Tue Aug 18 13:09:11.051015 2026] [security2:error] [pid 167459:tid 167637] [client 168.62.48.100:16445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDp2r_JutbFb-8svoPkgAAAb8"] [Tue Aug 18 13:09:11.071419 2026] [security2:error] [pid 167459:tid 167652] [client 20.65.98.162:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ano.php"] [unique_id "aoSDp2r_JutbFb-8svoPkwAAAc4"] [Tue Aug 18 13:09:11.109735 2026] [security2:error] [pid 167459:tid 167513] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/content.php"] [unique_id "aoSDp2r_JutbFb-8svoPlgABtTU"] [Tue Aug 18 13:09:11.116924 2026] [security2:error] [pid 167459:tid 167545] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/mimes.php"] [unique_id "aoSDp2r_JutbFb-8svoPlwAB3FU"] [Tue Aug 18 13:09:11.128188 2026] [security2:error] [pid 167459:tid 167663] [client 20.116.17.175:22714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/output.php"] [unique_id "aoSDp2r_JutbFb-8svoPmAAAAdk"] [Tue Aug 18 13:09:11.172406 2026] [security2:error] [pid 167459:tid 167631] [client 158.23.17.4:15793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/rn.php"] [unique_id "aoSDp2r_JutbFb-8svoPmQAAAbk"] [Tue Aug 18 13:09:11.189926 2026] [security2:error] [pid 167459:tid 167498] [remote 115.146.125.52:35694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.146.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natyou.com.br"] [uri "/wp-login.php"] [unique_id "aoSDp2r_JutbFb-8svoPmwAB7SY"] [Tue Aug 18 13:09:11.193421 2026] [security2:error] [pid 167459:tid 167602] [client 172.182.217.32:15599] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "acqualereformadepiscina.com.br"] [uri "/1.php"] [unique_id "aoSDp2r_JutbFb-8svoPnAAAAZw"] [Tue Aug 18 13:09:11.193510 2026] [security2:error] [pid 167459:tid 167602] [client 172.182.217.32:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/1.php"] [unique_id "aoSDp2r_JutbFb-8svoPnAAAAZw"] [Tue Aug 18 13:09:11.204681 2026] [security2:error] [pid 167459:tid 167656] [client 20.127.136.245:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/function/function.php"] [unique_id "aoSDp2r_JutbFb-8svoPngAAAdI"] [Tue Aug 18 13:09:11.206040 2026] [security2:error] [pid 167459:tid 167671] [client 196.12.128.158:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDp2r_JutbFb-8svoPnQAAAeE"] [Tue Aug 18 13:09:11.206188 2026] [security2:error] [pid 167459:tid 167671] [client 196.12.128.158:55790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDp2r_JutbFb-8svoPnQAAAeE"] [Tue Aug 18 13:09:11.254676 2026] [security2:error] [pid 167459:tid 167463] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/upfile.php"] [unique_id "aoSDp2r_JutbFb-8svoPowAB0wM"] [Tue Aug 18 13:09:11.267169 2026] [security2:error] [pid 167459:tid 167482] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSDp2r_JutbFb-8svoPpQABkhY"] [Tue Aug 18 13:09:11.276598 2026] [security2:error] [pid 167459:tid 167699] [client 20.250.13.23:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/photo.php"] [unique_id "aoSDp2r_JutbFb-8svoPpwAAAf0"] [Tue Aug 18 13:09:11.299387 2026] [security2:error] [pid 167459:tid 167714] [client 172.182.217.32:25728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/SimplePie/Content/Type/index.php"] [unique_id "aoSDp2r_JutbFb-8svoPqQAAAgw"] [Tue Aug 18 13:09:11.301640 2026] [security2:error] [pid 167459:tid 167599] [client 138.36.100.162:41855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDp2r_JutbFb-8svoPqAAAAZk"] [Tue Aug 18 13:09:11.301798 2026] [security2:error] [pid 167459:tid 167599] [client 138.36.100.162:41855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDp2r_JutbFb-8svoPqAAAAZk"] [Tue Aug 18 13:09:11.306433 2026] [security2:error] [pid 167459:tid 167700] [client 20.1.169.243:8952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/oxshell.php"] [unique_id "aoSDp2r_JutbFb-8svoPqgAAAf4"] [Tue Aug 18 13:09:11.306928 2026] [security2:error] [pid 167459:tid 167615] [client 168.62.48.100:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDp2r_JutbFb-8svoPqwAAAak"] [Tue Aug 18 13:09:11.326576 2026] [security2:error] [pid 167459:tid 167646] [client 20.100.169.31:3473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/file.php"] [unique_id "aoSDp2r_JutbFb-8svoPrQAAAcg"] [Tue Aug 18 13:09:11.340972 2026] [authz_core:error] [pid 167459:tid 167509] [remote 34.158.8.33:0] AH01630: client denied by server configuration: /home2/alsconsultoria/public_html/.htpasswd [Tue Aug 18 13:09:11.341527 2026] [security2:error] [pid 167459:tid 167618] [client 20.250.13.23:18420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSDp2r_JutbFb-8svoPsQAAAaw"] [Tue Aug 18 13:09:11.398322 2026] [cgid:error] [pid 167459:tid 167644] [client 20.1.169.243:9667] AH01264: stderr from /home1/querofi1/fichiers.queroficarnanet.com/cgi-bin/cgi-bin: script not found or unable to stat [Tue Aug 18 13:09:11.400283 2026] [security2:error] [pid 167459:tid 167553] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/bypass.php"] [unique_id "aoSDp2r_JutbFb-8svoPuAAB8V0"] [Tue Aug 18 13:09:11.408372 2026] [security2:error] [pid 167459:tid 167464] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/pqr.php"] [unique_id "aoSDp2r_JutbFb-8svoPuQACDQQ"] [Tue Aug 18 13:09:11.444503 2026] [security2:error] [pid 167459:tid 167610] [client 172.213.243.2:18565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xda.php"] [unique_id "aoSDp2r_JutbFb-8svoPugAAAaQ"] [Tue Aug 18 13:09:11.497827 2026] [security2:error] [pid 167459:tid 167679] [client 213.202.253.4:60284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/wp-content/postnews.php"] [unique_id "aoSDp2r_JutbFb-8svoPvwAAAek"], referer: www.google.com [Tue Aug 18 13:09:11.520437 2026] [security2:error] [pid 167459:tid 167686] [client 20.1.169.243:9667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDp2r_JutbFb-8svoPwgAAAfA"] [Tue Aug 18 13:09:11.521244 2026] [security2:error] [pid 167459:tid 167658] [client 74.249.206.207:9106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/inso.php"] [unique_id "aoSDp2r_JutbFb-8svoPwwAAAdQ"] [Tue Aug 18 13:09:11.537083 2026] [security2:error] [pid 167459:tid 167709] [client 20.100.169.31:49411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSDp2r_JutbFb-8svoPxAAAAgc"] [Tue Aug 18 13:09:11.543788 2026] [security2:error] [pid 167459:tid 167508] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/updates.php"] [unique_id "aoSDp2r_JutbFb-8svoPxgABvDA"] [Tue Aug 18 13:09:11.552012 2026] [security2:error] [pid 167459:tid 167570] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/lmfi2.php"] [unique_id "aoSDp2r_JutbFb-8svoPxwAB324"] [Tue Aug 18 13:09:11.555766 2026] [security2:error] [pid 167459:tid 167636] [client 158.23.17.4:4661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ko.php"] [unique_id "aoSDp2r_JutbFb-8svoPyAAAAb4"] [Tue Aug 18 13:09:11.580263 2026] [security2:error] [pid 167459:tid 167688] [client 74.248.133.44:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/curl.php"] [unique_id "aoSDp2r_JutbFb-8svoPyQAAAfI"] [Tue Aug 18 13:09:11.590012 2026] [security2:error] [pid 167459:tid 167628] [client 74.248.18.37:25400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin.php"] [unique_id "aoSDp2r_JutbFb-8svoPygAAAbY"] [Tue Aug 18 13:09:11.590383 2026] [security2:error] [pid 167459:tid 167597] [client 168.62.48.100:16465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDp2r_JutbFb-8svoPywAAAZc"] [Tue Aug 18 13:09:11.634909 2026] [security2:error] [pid 167459:tid 167620] [client 4.232.151.198:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDp2r_JutbFb-8svoPzwAAAa4"] [Tue Aug 18 13:09:11.672451 2026] [security2:error] [pid 167459:tid 167643] [client 40.74.65.169:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/82.php"] [unique_id "aoSDp2r_JutbFb-8svoP0AAAAcU"] [Tue Aug 18 13:09:11.680415 2026] [security2:error] [pid 167459:tid 167675] [client 172.182.217.32:15614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/2.php"] [unique_id "aoSDp2r_JutbFb-8svoP0QAAAeU"] [Tue Aug 18 13:09:11.681888 2026] [security2:error] [pid 167459:tid 167708] [client 20.1.169.243:8907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/php8.php"] [unique_id "aoSDp2r_JutbFb-8svoP0gAAAgY"] [Tue Aug 18 13:09:11.689633 2026] [security2:error] [pid 167459:tid 167556] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDp2r_JutbFb-8svoP0wABq2A"] [Tue Aug 18 13:09:11.693014 2026] [security2:error] [pid 167459:tid 167585] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/info2.php"] [unique_id "aoSDp2r_JutbFb-8svoP1AAB6H0"] [Tue Aug 18 13:09:11.756969 2026] [security2:error] [pid 167459:tid 167711] [client 20.116.17.175:44676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dk.php"] [unique_id "aoSDp2r_JutbFb-8svoP2gAAAgk"] [Tue Aug 18 13:09:11.766049 2026] [security2:error] [pid 167459:tid 167653] [client 213.35.127.232:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDp2r_JutbFb-8svoP2wAAAc8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:11.772221 2026] [security2:error] [pid 167459:tid 167683] [client 74.248.130.103:31939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/akismet.php"] [unique_id "aoSDp2r_JutbFb-8svoP3AAAAe0"] [Tue Aug 18 13:09:11.788469 2026] [security2:error] [pid 167459:tid 167612] [client 172.182.217.32:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/SimplePie/autoload_classmap.php"] [unique_id "aoSDp2r_JutbFb-8svoP3wAAAaY"] [Tue Aug 18 13:09:11.806184 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:11.806443 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:11.832174 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:48435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/mx.php"] [unique_id "aoSDp2r_JutbFb-8svoP4wAAAdM"] [Tue Aug 18 13:09:11.833734 2026] [security2:error] [pid 167459:tid 167580] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/test_info.php"] [unique_id "aoSDp2r_JutbFb-8svoP5AAB9ng"] [Tue Aug 18 13:09:11.834368 2026] [security2:error] [pid 167459:tid 167493] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/ae.php"] [unique_id "aoSDp2r_JutbFb-8svoP5QABkiE"] [Tue Aug 18 13:09:11.839892 2026] [security2:error] [pid 167459:tid 167696] [client 168.62.48.100:16478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDp2r_JutbFb-8svoP5wAAAfo"] [Tue Aug 18 13:09:11.888606 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDp2r_JutbFb-8svoP6AAAAec"] [Tue Aug 18 13:09:11.904672 2026] [security2:error] [pid 167459:tid 167615] [client 172.213.243.2:37112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/zz.php"] [unique_id "aoSDp2r_JutbFb-8svoP6QAAAak"] [Tue Aug 18 13:09:11.943422 2026] [autoindex:error] [pid 167459:tid 167514] [remote 20.219.2.203:0] AH01276: Cannot serve directory /home3/cp37imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:11.949168 2026] [security2:error] [pid 167459:tid 167638] [client 20.100.169.31:3340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/goods.php"] [unique_id "aoSDp2r_JutbFb-8svoP7wAAAcA"] [Tue Aug 18 13:09:11.952351 2026] [security2:error] [pid 167459:tid 167614] [client 20.127.136.245:8287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-signin.php"] [unique_id "aoSDp2r_JutbFb-8svoP8AAAAag"] [Tue Aug 18 13:09:11.972501 2026] [security2:error] [pid 167459:tid 167533] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDp2r_JutbFb-8svoP8wAB8Uk"] [Tue Aug 18 13:09:11.978018 2026] [security2:error] [pid 167459:tid 167507] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/moon.php"] [unique_id "aoSDp2r_JutbFb-8svoP9AAB7C8"] [Tue Aug 18 13:09:11.981411 2026] [security2:error] [pid 167459:tid 167575] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/xynz1.php"] [unique_id "aoSDp2r_JutbFb-8svoP9QAB7nM"] [Tue Aug 18 13:09:11.985415 2026] [security2:error] [pid 167459:tid 167609] [client 20.250.13.23:23068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-aa.php"] [unique_id "aoSDp2r_JutbFb-8svoP9wAAAaM"] [Tue Aug 18 13:09:11.991297 2026] [security2:error] [pid 167459:tid 167651] [client 20.250.13.23:6079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSDp2r_JutbFb-8svoP-AAAAc0"] [Tue Aug 18 13:09:12.007911 2026] [security2:error] [pid 167459:tid 167501] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDqGr_JutbFb-8svoP-gAB8Sk"] [Tue Aug 18 13:09:12.048302 2026] [security2:error] [pid 167459:tid 167646] [client 20.1.169.243:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/p.php"] [unique_id "aoSDqGr_JutbFb-8svoP_wAAAcg"] [Tue Aug 18 13:09:12.069656 2026] [security2:error] [pid 167459:tid 167598] [client 158.23.17.4:32430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/pl.php"] [unique_id "aoSDqGr_JutbFb-8svoQBQAAAZg"] [Tue Aug 18 13:09:12.092750 2026] [security2:error] [pid 167459:tid 167650] [client 20.38.3.247:15009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDqGr_JutbFb-8svoQBwAAAcw"] [Tue Aug 18 13:09:12.113701 2026] [security2:error] [pid 167459:tid 167658] [client 168.62.48.100:16483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDqGr_JutbFb-8svoQCgAAAdQ"] [Tue Aug 18 13:09:12.115642 2026] [security2:error] [pid 167459:tid 167672] [client 49.145.211.146:11785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqGr_JutbFb-8svoQCQAAAeI"] [Tue Aug 18 13:09:12.115909 2026] [security2:error] [pid 167459:tid 167672] [client 49.145.211.146:11785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqGr_JutbFb-8svoQCQAAAeI"] [Tue Aug 18 13:09:12.118944 2026] [security2:error] [pid 167459:tid 167589] [client 20.250.13.23:40141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-login.php"] [unique_id "aoSDp2r_JutbFb-8svoP7gAAAY8"] [Tue Aug 18 13:09:12.119908 2026] [security2:error] [pid 167459:tid 167527] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/album.php"] [unique_id "aoSDqGr_JutbFb-8svoQDAAB20M"] [Tue Aug 18 13:09:12.129423 2026] [security2:error] [pid 167459:tid 167478] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/blog.php"] [unique_id "aoSDqGr_JutbFb-8svoQDQAByxI"] [Tue Aug 18 13:09:12.169901 2026] [security2:error] [pid 167459:tid 167603] [client 172.182.217.32:15587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/7.php"] [unique_id "aoSDqGr_JutbFb-8svoQDgAAAZ0"] [Tue Aug 18 13:09:12.208985 2026] [security2:error] [pid 167459:tid 167610] [client 20.100.169.31:2563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDqGr_JutbFb-8svoQEAAAAaQ"] [Tue Aug 18 13:09:12.254364 2026] [security2:error] [pid 167459:tid 167691] [client 158.23.17.4:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ut.php"] [unique_id "aoSDqGr_JutbFb-8svoQEQAAAfU"] [Tue Aug 18 13:09:12.261892 2026] [security2:error] [pid 167459:tid 167654] [client 20.1.169.243:9694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSDqGr_JutbFb-8svoQEwAAAdA"] [Tue Aug 18 13:09:12.261906 2026] [security2:error] [pid 167459:tid 167484] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/creds.php"] [unique_id "aoSDqGr_JutbFb-8svoQFAABsxg"] [Tue Aug 18 13:09:12.273661 2026] [security2:error] [pid 167459:tid 167477] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/ini.php"] [unique_id "aoSDqGr_JutbFb-8svoQFgABshE"] [Tue Aug 18 13:09:12.278215 2026] [security2:error] [pid 167459:tid 167673] [client 172.182.217.32:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/SimplePie/cY5ipC.php"] [unique_id "aoSDqGr_JutbFb-8svoQGAAAAeM"] [Tue Aug 18 13:09:12.347030 2026] [security2:error] [pid 167459:tid 167670] [client 172.213.243.2:37111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xa.php"] [unique_id "aoSDqGr_JutbFb-8svoQHAAAAeA"] [Tue Aug 18 13:09:12.367022 2026] [security2:error] [pid 167459:tid 167662] [client 168.62.48.100:16491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDqGr_JutbFb-8svoQIAAAAdg"] [Tue Aug 18 13:09:12.392537 2026] [security2:error] [pid 167459:tid 167653] [client 40.74.65.169:11909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/dex.php"] [unique_id "aoSDqGr_JutbFb-8svoQJAAAAc8"] [Tue Aug 18 13:09:12.407619 2026] [security2:error] [pid 167459:tid 167565] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/mandrill.php"] [unique_id "aoSDqGr_JutbFb-8svoQJgACBGk"] [Tue Aug 18 13:09:12.407745 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:12.408136 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:12.412571 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/php.php"] [unique_id "aoSDqGr_JutbFb-8svoQKQAAAcU"] [Tue Aug 18 13:09:12.420710 2026] [security2:error] [pid 167459:tid 167554] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/admin-ajax.php"] [unique_id "aoSDqGr_JutbFb-8svoQKgABul4"] [Tue Aug 18 13:09:12.457966 2026] [security2:error] [pid 167459:tid 167671] [client 20.104.100.201:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/privdayz.php"] [unique_id "aoSDqGr_JutbFb-8svoQLQAAAeE"] [Tue Aug 18 13:09:12.477400 2026] [security2:error] [pid 167459:tid 167712] [client 74.248.130.103:17775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/admin.php"] [unique_id "aoSDqGr_JutbFb-8svoQLgAAAgo"] [Tue Aug 18 13:09:12.482372 2026] [security2:error] [pid 167459:tid 167657] [client 4.232.151.198:2577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/js/about.php"] [unique_id "aoSDqGr_JutbFb-8svoQLwAAAdM"] [Tue Aug 18 13:09:12.485224 2026] [security2:error] [pid 167459:tid 167595] [client 20.116.17.175:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/bal.php"] [unique_id "aoSDqGr_JutbFb-8svoQMAAAAZU"] [Tue Aug 18 13:09:12.547656 2026] [security2:error] [pid 167459:tid 167581] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSDqGr_JutbFb-8svoQIQACBnk"], referer: https://alsconsultoria.com.br/login [Tue Aug 18 13:09:12.551314 2026] [security2:error] [pid 167459:tid 167552] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/main.php"] [unique_id "aoSDqGr_JutbFb-8svoQNAABrFw"] [Tue Aug 18 13:09:12.559219 2026] [security2:error] [pid 167459:tid 167605] [client 74.248.18.37:3382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDqGr_JutbFb-8svoQNQAAAZ8"] [Tue Aug 18 13:09:12.565018 2026] [security2:error] [pid 167459:tid 167566] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/akc.php"] [unique_id "aoSDqGr_JutbFb-8svoQNwABwGo"] [Tue Aug 18 13:09:12.572486 2026] [security2:error] [pid 167459:tid 167648] [client 20.100.169.31:18963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/hplfuns.php"] [unique_id "aoSDqGr_JutbFb-8svoQOAAAAco"] [Tue Aug 18 13:09:12.600601 2026] [security2:error] [pid 167459:tid 167607] [client 20.250.13.23:18211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/d.php"] [unique_id "aoSDqGr_JutbFb-8svoQOgAAAaE"] [Tue Aug 18 13:09:12.610586 2026] [security2:error] [pid 167459:tid 167640] [client 20.250.13.23:18228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSDqGr_JutbFb-8svoQOwAAAcI"] [Tue Aug 18 13:09:12.620903 2026] [security2:error] [pid 167459:tid 167684] [client 158.23.17.4:7350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/env.php"] [unique_id "aoSDqGr_JutbFb-8svoQPAAAAe4"] [Tue Aug 18 13:09:12.627051 2026] [security2:error] [pid 167459:tid 167637] [client 20.1.169.243:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSDqGr_JutbFb-8svoQPQAAAb8"] [Tue Aug 18 13:09:12.659827 2026] [security2:error] [pid 167459:tid 167696] [client 172.182.217.32:15590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/10.php"] [unique_id "aoSDqGr_JutbFb-8svoQQQAAAfo"] [Tue Aug 18 13:09:12.688654 2026] [security2:error] [pid 167459:tid 167516] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/payout.php"] [unique_id "aoSDqGr_JutbFb-8svoQQgABqjg"] [Tue Aug 18 13:09:12.694228 2026] [security2:error] [pid 167459:tid 167702] [client 74.248.18.37:15089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/222.php"] [unique_id "aoSDqGr_JutbFb-8svoQQwAAAgA"] [Tue Aug 18 13:09:12.697510 2026] [security2:error] [pid 167459:tid 167612] [client 74.248.133.44:42637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/Njima.php"] [unique_id "aoSDqGr_JutbFb-8svoQRAAAAaY"] [Tue Aug 18 13:09:12.710477 2026] [security2:error] [pid 167459:tid 167503] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/akcc.php"] [unique_id "aoSDqGr_JutbFb-8svoQRgABlCs"] [Tue Aug 18 13:09:12.726964 2026] [security2:error] [pid 167459:tid 167686] [client 20.38.3.247:16059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/yj09.php"] [unique_id "aoSDqGr_JutbFb-8svoQSQAAAfA"] [Tue Aug 18 13:09:12.742512 2026] [security2:error] [pid 167459:tid 167589] [client 168.62.48.100:16488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDqGr_JutbFb-8svoQSgAAAY8"] [Tue Aug 18 13:09:12.767302 2026] [security2:error] [pid 167459:tid 167601] [client 172.182.217.32:25634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDqGr_JutbFb-8svoQSwAAAZs"] [Tue Aug 18 13:09:12.768985 2026] [security2:error] [pid 167459:tid 167697] [client 172.213.243.2:19573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/f6.php"] [unique_id "aoSDqGr_JutbFb-8svoQTAAAAfs"] [Tue Aug 18 13:09:12.778792 2026] [security2:error] [pid 167459:tid 167690] [client 158.23.17.4:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/45.php"] [unique_id "aoSDqGr_JutbFb-8svoQTgAAAfQ"] [Tue Aug 18 13:09:12.779949 2026] [security2:error] [pid 167459:tid 167635] [client 213.35.127.232:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDqGr_JutbFb-8svoQTwAAAb0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:12.787190 2026] [security2:error] [pid 167459:tid 167598] [client 20.1.169.243:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/past.php"] [unique_id "aoSDqGr_JutbFb-8svoQUgAAAZg"] [Tue Aug 18 13:09:12.801222 2026] [security2:error] [pid 167459:tid 167470] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/id_rsa"] [unique_id "aoSDqGr_JutbFb-8svoQUwACBwo"] [Tue Aug 18 13:09:12.832620 2026] [security2:error] [pid 167459:tid 167466] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/Mailgun.php"] [unique_id "aoSDqGr_JutbFb-8svoQVgAB_AY"] [Tue Aug 18 13:09:12.852305 2026] [security2:error] [pid 167459:tid 167604] [client 20.100.169.31:2591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSDqGr_JutbFb-8svoQWAAAAZ4"] [Tue Aug 18 13:09:12.855066 2026] [security2:error] [pid 167459:tid 167562] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/asasx.php"] [unique_id "aoSDqGr_JutbFb-8svoQWQACDmY"] [Tue Aug 18 13:09:12.863289 2026] [security2:error] [pid 167459:tid 167488] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/id_dsa"] [unique_id "aoSDqGr_JutbFb-8svoQWwACBxw"] [Tue Aug 18 13:09:12.887279 2026] [security2:error] [pid 167459:tid 167487] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSDqGr_JutbFb-8svoQYAACBxs"], referer: https://alsconsultoria.com.br/wp-admin/ [Tue Aug 18 13:09:12.972707 2026] [security2:error] [pid 167459:tid 167582] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "aoSDqGr_JutbFb-8svoQagACB3o"], referer: https://alsconsultoria.com.br/wp-admin/ [Tue Aug 18 13:09:12.992014 2026] [security2:error] [pid 167459:tid 167606] [client 20.1.169.243:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/config.php"] [unique_id "aoSDqGr_JutbFb-8svoQbQAAAaA"] [Tue Aug 18 13:09:12.999585 2026] [security2:error] [pid 167459:tid 167471] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/axx.php"] [unique_id "aoSDqGr_JutbFb-8svoQcAAB5As"] [Tue Aug 18 13:09:13.005890 2026] [security2:error] [pid 167459:tid 167515] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/oauth.php"] [unique_id "aoSDqWr_JutbFb-8svoQcQABuTc"] [Tue Aug 18 13:09:13.013861 2026] [security2:error] [pid 167459:tid 167544] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQcwAByFQ"] [Tue Aug 18 13:09:13.014058 2026] [security2:error] [pid 167459:tid 167646] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQcwAByFQ"] [Tue Aug 18 13:09:13.032014 2026] [security2:error] [pid 167459:tid 167653] [client 168.62.48.100:16481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDqWr_JutbFb-8svoQdQAAAc8"] [Tue Aug 18 13:09:13.073890 2026] [security2:error] [pid 167459:tid 167553] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/key.pem"] [unique_id "aoSDqWr_JutbFb-8svoQdgABul0"] [Tue Aug 18 13:09:13.115415 2026] [security2:error] [pid 167459:tid 167537] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/privatekey.key"] [unique_id "aoSDqWr_JutbFb-8svoQegABw00"] [Tue Aug 18 13:09:13.116194 2026] [security2:error] [pid 167459:tid 167712] [client 20.104.100.201:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDqWr_JutbFb-8svoQewAAAgo"] [Tue Aug 18 13:09:13.129576 2026] [security2:error] [pid 167459:tid 167647] [client 4.232.151.198:2653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDqWr_JutbFb-8svoQfAAAAck"] [Tue Aug 18 13:09:13.145743 2026] [security2:error] [pid 167459:tid 167520] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/berax.php"] [unique_id "aoSDqWr_JutbFb-8svoQfQABkjw"] [Tue Aug 18 13:09:13.145881 2026] [security2:error] [pid 167459:tid 167500] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/timeclock.php"] [unique_id "aoSDqWr_JutbFb-8svoQfgABlSg"] [Tue Aug 18 13:09:13.152078 2026] [security2:error] [pid 167459:tid 167683] [client 20.1.169.243:9543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/root.php"] [unique_id "aoSDqWr_JutbFb-8svoQgAAAAe0"] [Tue Aug 18 13:09:13.165746 2026] [security2:error] [pid 167459:tid 167625] [client 20.250.13.23:31256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/default.php"] [unique_id "aoSDqWr_JutbFb-8svoQggAAAbM"] [Tue Aug 18 13:09:13.166277 2026] [security2:error] [pid 167459:tid 167685] [client 172.182.217.32:15745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/13.php"] [unique_id "aoSDqWr_JutbFb-8svoQgwAAAe8"] [Tue Aug 18 13:09:13.166551 2026] [security2:error] [pid 167459:tid 167677] [client 20.116.17.175:22775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/tiny2.php"] [unique_id "aoSDqWr_JutbFb-8svoQhAAAAec"] [Tue Aug 18 13:09:13.172577 2026] [security2:error] [pid 167459:tid 167600] [client 74.248.130.103:60718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.130.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiliodecarvalho.com.br"] [uri "/ajax.php"] [unique_id "aoSDqWr_JutbFb-8svoQhQAAAZo"] [Tue Aug 18 13:09:13.202372 2026] [security2:error] [pid 167459:tid 167680] [client 20.100.169.31:3498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/htaccess.php"] [unique_id "aoSDqWr_JutbFb-8svoQhwAAAeo"] [Tue Aug 18 13:09:13.204401 2026] [security2:error] [pid 167459:tid 167605] [client 40.74.65.169:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/puc.php"] [unique_id "aoSDqWr_JutbFb-8svoQiAAAAZ8"] [Tue Aug 18 13:09:13.204442 2026] [security2:error] [pid 167459:tid 167692] [client 49.37.150.8:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQiQAAAfY"] [Tue Aug 18 13:09:13.204530 2026] [security2:error] [pid 167459:tid 167692] [client 49.37.150.8:58929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQiQAAAfY"] [Tue Aug 18 13:09:13.214031 2026] [security2:error] [pid 167459:tid 167630] [client 74.248.18.37:25376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/akc.php"] [unique_id "aoSDqWr_JutbFb-8svoQiwAAAbg"] [Tue Aug 18 13:09:13.233041 2026] [security2:error] [pid 167459:tid 167648] [client 172.213.243.2:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/mcs.php"] [unique_id "aoSDqWr_JutbFb-8svoQjQAAAco"] [Tue Aug 18 13:09:13.244682 2026] [security2:error] [pid 167459:tid 167626] [client 158.23.17.4:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/eh.php"] [unique_id "aoSDqWr_JutbFb-8svoQjgAAAbQ"] [Tue Aug 18 13:09:13.259778 2026] [security2:error] [pid 167459:tid 167613] [client 20.250.13.23:18231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDqWr_JutbFb-8svoQjwAAAac"] [Tue Aug 18 13:09:13.262164 2026] [security2:error] [pid 167459:tid 167629] [client 20.250.13.23:18416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-includes/widgets.php"] [unique_id "aoSDqWr_JutbFb-8svoQkAAAAbc"] [Tue Aug 18 13:09:13.263151 2026] [security2:error] [pid 167459:tid 167623] [client 172.182.217.32:25600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/Text/about.php"] [unique_id "aoSDqWr_JutbFb-8svoQkQAAAbE"] [Tue Aug 18 13:09:13.284532 2026] [security2:error] [pid 167459:tid 167705] [client 158.23.17.4:38353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mz.php"] [unique_id "aoSDqWr_JutbFb-8svoQkwAAAgM"] [Tue Aug 18 13:09:13.290139 2026] [security2:error] [pid 167459:tid 167570] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/build.php"] [unique_id "aoSDqWr_JutbFb-8svoQlAAB7G4"] [Tue Aug 18 13:09:13.294452 2026] [security2:error] [pid 167459:tid 167460] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/email.php"] [unique_id "aoSDqWr_JutbFb-8svoQlQABwgA"] [Tue Aug 18 13:09:13.340340 2026] [security2:error] [pid 167459:tid 167701] [client 168.62.48.100:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDqWr_JutbFb-8svoQmgAAAf8"] [Tue Aug 18 13:09:13.363415 2026] [security2:error] [pid 167459:tid 167676] [client 20.1.169.243:9679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSDqWr_JutbFb-8svoQmwAAAeY"] [Tue Aug 18 13:09:13.434364 2026] [security2:error] [pid 167459:tid 167542] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/buy.php"] [unique_id "aoSDqWr_JutbFb-8svoQogABvlI"] [Tue Aug 18 13:09:13.435702 2026] [security2:error] [pid 167459:tid 167512] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/profile.php"] [unique_id "aoSDqWr_JutbFb-8svoQowABxzQ"] [Tue Aug 18 13:09:13.470956 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/yawa.php"] [unique_id "aoSDqWr_JutbFb-8svoQpQAAAeM"] [Tue Aug 18 13:09:13.516884 2026] [security2:error] [pid 167459:tid 167651] [client 20.100.169.31:2463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDqWr_JutbFb-8svoQpgAAAc0"] [Tue Aug 18 13:09:13.524061 2026] [security2:error] [pid 167459:tid 167697] [client 20.1.169.243:8836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/r.php"] [unique_id "aoSDqWr_JutbFb-8svoQqAAAAfs"] [Tue Aug 18 13:09:13.543117 2026] [security2:error] [pid 167459:tid 167580] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDqWr_JutbFb-8svoQqQABtXg"] [Tue Aug 18 13:09:13.576899 2026] [security2:error] [pid 167459:tid 167555] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/summary.php"] [unique_id "aoSDqWr_JutbFb-8svoQqwAByF8"] [Tue Aug 18 13:09:13.578871 2026] [security2:error] [pid 167459:tid 167530] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/checkbox.php"] [unique_id "aoSDqWr_JutbFb-8svoQrAAB2UY"] [Tue Aug 18 13:09:13.620831 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:13.621087 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:13.650848 2026] [security2:error] [pid 167459:tid 167625] [client 52.139.47.57:35316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.info.php"] [unique_id "aoSDqWr_JutbFb-8svoQtgAAAbM"] [Tue Aug 18 13:09:13.658875 2026] [security2:error] [pid 167459:tid 167620] [client 172.182.217.32:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/100.php"] [unique_id "aoSDqWr_JutbFb-8svoQtwAAAa4"] [Tue Aug 18 13:09:13.684212 2026] [security2:error] [pid 167459:tid 167611] [client 168.62.48.100:16407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDqWr_JutbFb-8svoQugAAAaU"] [Tue Aug 18 13:09:13.688180 2026] [security2:error] [pid 167459:tid 167680] [client 172.213.243.2:15064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/xleet.php"] [unique_id "aoSDqWr_JutbFb-8svoQvgAAAeo"] [Tue Aug 18 13:09:13.720247 2026] [security2:error] [pid 167459:tid 167576] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/conf.php"] [unique_id "aoSDqWr_JutbFb-8svoQwwABqHQ"] [Tue Aug 18 13:09:13.724807 2026] [security2:error] [pid 167459:tid 167584] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/cong.php"] [unique_id "aoSDqWr_JutbFb-8svoQxAABtHw"] [Tue Aug 18 13:09:13.728197 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:9664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/module.php"] [unique_id "aoSDqWr_JutbFb-8svoQyQAAAfM"] [Tue Aug 18 13:09:13.754782 2026] [security2:error] [pid 167459:tid 167671] [client 172.182.217.32:25775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "aoSDqWr_JutbFb-8svoQzAAAAeE"] [Tue Aug 18 13:09:13.788828 2026] [security2:error] [pid 167459:tid 167696] [client 86.120.159.145:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQ0AAAAfo"] [Tue Aug 18 13:09:13.788988 2026] [security2:error] [pid 167459:tid 167696] [client 86.120.159.145:59474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqWr_JutbFb-8svoQ0AAAAfo"] [Tue Aug 18 13:09:13.799314 2026] [security2:error] [pid 167459:tid 167661] [client 213.35.127.232:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDqWr_JutbFb-8svoQ1wAAAdc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:13.816524 2026] [security2:error] [pid 167459:tid 167684] [client 158.23.17.4:40479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ft.php"] [unique_id "aoSDqWr_JutbFb-8svoQ2QAAAe4"] [Tue Aug 18 13:09:13.822346 2026] [security2:error] [pid 167459:tid 167657] [client 20.100.169.31:18952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/images/wso.php"] [unique_id "aoSDqWr_JutbFb-8svoQ2wAAAdM"] [Tue Aug 18 13:09:13.851159 2026] [security2:error] [pid 167459:tid 167592] [client 74.248.18.37:3358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/buy.php"] [unique_id "aoSDqWr_JutbFb-8svoQ3AAAAZI"] [Tue Aug 18 13:09:13.861395 2026] [security2:error] [pid 167459:tid 167531] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/bala.php"] [unique_id "aoSDqWr_JutbFb-8svoQ3gAB1Ec"] [Tue Aug 18 13:09:13.870505 2026] [security2:error] [pid 167459:tid 167548] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/file4.php"] [unique_id "aoSDqWr_JutbFb-8svoQ3wAB6Vg"] [Tue Aug 18 13:09:13.877090 2026] [security2:error] [pid 167459:tid 167700] [client 20.250.13.23:18402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSDqWr_JutbFb-8svoQ4QAAAf4"] [Tue Aug 18 13:09:13.881363 2026] [security2:error] [pid 167459:tid 167710] [client 20.250.13.23:5915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDqWr_JutbFb-8svoQ4gAAAgg"] [Tue Aug 18 13:09:13.888420 2026] [security2:error] [pid 167459:tid 167622] [client 20.1.169.243:9576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/sid3.php"] [unique_id "aoSDqWr_JutbFb-8svoQ5AAAAbA"] [Tue Aug 18 13:09:13.896373 2026] [security2:error] [pid 167459:tid 167473] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDqWr_JutbFb-8svoQ5gABmg0"] [Tue Aug 18 13:09:13.909095 2026] [security2:error] [pid 167459:tid 167605] [client 20.250.13.23:50098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/i.php"] [unique_id "aoSDqWr_JutbFb-8svoQ6QAAAZ8"] [Tue Aug 18 13:09:13.913062 2026] [security2:error] [pid 167459:tid 167703] [client 158.23.17.4:14059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ad.php"] [unique_id "aoSDqWr_JutbFb-8svoQ6wAAAgE"] [Tue Aug 18 13:09:13.914123 2026] [security2:error] [pid 167459:tid 167672] [client 40.74.65.169:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/inso.php"] [unique_id "aoSDqWr_JutbFb-8svoQ7AAAAeI"] [Tue Aug 18 13:09:13.936826 2026] [security2:error] [pid 167459:tid 167598] [client 20.127.136.245:22183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/f35.php"] [unique_id "aoSDqWr_JutbFb-8svoQ8gAAAZg"] [Tue Aug 18 13:09:14.004316 2026] [security2:error] [pid 167459:tid 167524] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/222.php"] [unique_id "aoSDqmr_JutbFb-8svoQ_QABtkA"] [Tue Aug 18 13:09:14.017309 2026] [security2:error] [pid 167459:tid 167583] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/flower.php"] [unique_id "aoSDqmr_JutbFb-8svoRAAABwXs"] [Tue Aug 18 13:09:14.070834 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:18542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/about.php"] [unique_id "aoSDqmr_JutbFb-8svoRAQAAAfQ"] [Tue Aug 18 13:09:14.104626 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:10226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/options.php"] [unique_id "aoSDqmr_JutbFb-8svoRBwAAAgQ"] [Tue Aug 18 13:09:14.109224 2026] [security2:error] [pid 167459:tid 167716] [client 5.31.227.224:7849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqmr_JutbFb-8svoRCAAAAg4"] [Tue Aug 18 13:09:14.109341 2026] [security2:error] [pid 167459:tid 167716] [client 5.31.227.224:7849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDqmr_JutbFb-8svoRCAAAAg4"] [Tue Aug 18 13:09:14.128782 2026] [security2:error] [pid 167459:tid 167707] [client 74.248.18.37:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/inputs.php"] [unique_id "aoSDqmr_JutbFb-8svoRCgAAAgU"] [Tue Aug 18 13:09:14.129009 2026] [security2:error] [pid 167459:tid 167641] [client 172.213.243.2:19727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fr/ms.php"] [unique_id "aoSDqmr_JutbFb-8svoRCwAAAcM"] [Tue Aug 18 13:09:14.136926 2026] [security2:error] [pid 167459:tid 167683] [client 20.206.73.37:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/bengi.php"] [unique_id "aoSDqmr_JutbFb-8svoRDAAAAe0"] [Tue Aug 18 13:09:14.142614 2026] [security2:error] [pid 167459:tid 167589] [client 20.100.169.31:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDqmr_JutbFb-8svoRDQAAAY8"] [Tue Aug 18 13:09:14.142872 2026] [security2:error] [pid 167459:tid 167599] [client 20.151.109.219:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/mq.php"] [unique_id "aoSDqmr_JutbFb-8svoRDgAAAZk"] [Tue Aug 18 13:09:14.147781 2026] [security2:error] [pid 167459:tid 167505] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/routes.php"] [unique_id "aoSDqmr_JutbFb-8svoREAACDC0"] [Tue Aug 18 13:09:14.147796 2026] [security2:error] [pid 167459:tid 167688] [client 172.182.217.32:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/222.php"] [unique_id "aoSDqmr_JutbFb-8svoRDwAAAfI"] [Tue Aug 18 13:09:14.162251 2026] [security2:error] [pid 167459:tid 167529] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/form.php"] [unique_id "aoSDqmr_JutbFb-8svoREwABpUU"] [Tue Aug 18 13:09:14.195264 2026] [security2:error] [pid 167459:tid 167626] [client 114.119.140.161:21821] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.agatrend.com.br"] [uri "/robots.txt"] [unique_id "aoSDqmr_JutbFb-8svoRFgAAAbQ"], referer: http://www.agatrend.com.br/robots.txt [Tue Aug 18 13:09:14.197203 2026] [security2:error] [pid 167459:tid 167617] [client 74.7.175.168:43924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.teste.advocaciacriminalgo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSDqmr_JutbFb-8svoRFQABqwM"] [Tue Aug 18 13:09:14.242401 2026] [security2:error] [pid 167459:tid 167596] [client 172.182.217.32:25786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/block-supports/index.php"] [unique_id "aoSDqmr_JutbFb-8svoRIgAAAZY"] [Tue Aug 18 13:09:14.252373 2026] [security2:error] [pid 167459:tid 167595] [client 20.1.169.243:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ss.php"] [unique_id "aoSDqmr_JutbFb-8svoRJgAAAZU"] [Tue Aug 18 13:09:14.287428 2026] [security2:error] [pid 167459:tid 167544] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/php5.php"] [unique_id "aoSDqmr_JutbFb-8svoRKQABplQ"] [Tue Aug 18 13:09:14.294876 2026] [security2:error] [pid 167459:tid 167702] [client 158.23.17.4:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wy.php"] [unique_id "aoSDqmr_JutbFb-8svoRKgAAAgA"] [Tue Aug 18 13:09:14.313021 2026] [security2:error] [pid 167459:tid 167464] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/gecko.php"] [unique_id "aoSDqmr_JutbFb-8svoRLAAB9gQ"] [Tue Aug 18 13:09:14.338983 2026] [security2:error] [pid 167459:tid 167603] [client 4.232.151.198:51045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/js/widgets/xmrlpc.php"] [unique_id "aoSDqmr_JutbFb-8svoRMwAAAZ0"] [Tue Aug 18 13:09:14.437157 2026] [security2:error] [pid 167459:tid 167460] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/Black.php"] [unique_id "aoSDqmr_JutbFb-8svoROgAB5QA"] [Tue Aug 18 13:09:14.440000 2026] [security2:error] [pid 167459:tid 167678] [client 168.62.48.100:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDqmr_JutbFb-8svoROwAAAeg"] [Tue Aug 18 13:09:14.441342 2026] [security2:error] [pid 167459:tid 167690] [client 158.23.17.4:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/vd.php"] [unique_id "aoSDqmr_JutbFb-8svoRPAAAAfQ"] [Tue Aug 18 13:09:14.444621 2026] [security2:error] [pid 167459:tid 167615] [client 20.100.169.31:18978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/index/function.php"] [unique_id "aoSDqmr_JutbFb-8svoRPQAAAak"] [Tue Aug 18 13:09:14.458146 2026] [security2:error] [pid 167459:tid 167497] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/kyami.php"] [unique_id "aoSDqmr_JutbFb-8svoRPwABzSU"] [Tue Aug 18 13:09:14.507486 2026] [security2:error] [pid 167459:tid 167660] [client 74.248.18.37:3378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cong.php"] [unique_id "aoSDqmr_JutbFb-8svoRRAAAAdY"] [Tue Aug 18 13:09:14.517309 2026] [security2:error] [pid 167459:tid 167604] [client 20.1.169.243:10463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/panel.php"] [unique_id "aoSDqmr_JutbFb-8svoRRQAAAZ4"] [Tue Aug 18 13:09:14.521601 2026] [security2:error] [pid 167459:tid 167704] [client 20.250.13.23:5917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/abc.php"] [unique_id "aoSDqmr_JutbFb-8svoRRwAAAgI"] [Tue Aug 18 13:09:14.538564 2026] [security2:error] [pid 167459:tid 167653] [client 20.65.98.162:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ai.php"] [unique_id "aoSDqmr_JutbFb-8svoRSQAAAc8"] [Tue Aug 18 13:09:14.547351 2026] [security2:error] [pid 167459:tid 167635] [client 20.250.13.23:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/abc.php"] [unique_id "aoSDqmr_JutbFb-8svoRSgAAAb0"] [Tue Aug 18 13:09:14.569700 2026] [security2:error] [pid 167459:tid 167683] [client 172.213.243.2:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/gool.php"] [unique_id "aoSDqmr_JutbFb-8svoRTQAAAe0"] [Tue Aug 18 13:09:14.577303 2026] [security2:error] [pid 167459:tid 167519] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/filesystems.php"] [unique_id "aoSDqmr_JutbFb-8svoRTgABmTs"] [Tue Aug 18 13:09:14.601953 2026] [security2:error] [pid 167459:tid 167521] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/manager.php"] [unique_id "aoSDqmr_JutbFb-8svoRUQABrD0"] [Tue Aug 18 13:09:14.616391 2026] [security2:error] [pid 167459:tid 167674] [client 20.1.169.243:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/sts.php"] [unique_id "aoSDqmr_JutbFb-8svoRVQAAAeQ"] [Tue Aug 18 13:09:14.624676 2026] [security2:error] [pid 167459:tid 167630] [client 158.23.17.4:39138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/h.php"] [unique_id "aoSDqmr_JutbFb-8svoRVgAAAbg"] [Tue Aug 18 13:09:14.635666 2026] [security2:error] [pid 167459:tid 167606] [client 172.182.217.32:15602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDqmr_JutbFb-8svoRWAAAAaA"] [Tue Aug 18 13:09:14.642377 2026] [security2:error] [pid 167459:tid 167614] [client 52.139.47.57:18544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSDqmr_JutbFb-8svoRWQAAAag"] [Tue Aug 18 13:09:14.660035 2026] [security2:error] [pid 167459:tid 167644] [client 40.74.65.169:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/aa.php"] [unique_id "aoSDqmr_JutbFb-8svoRWwAAAcY"] [Tue Aug 18 13:09:14.715207 2026] [security2:error] [pid 167459:tid 167708] [client 20.116.17.175:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wpxml.php"] [unique_id "aoSDqmr_JutbFb-8svoRXgAAAgY"] [Tue Aug 18 13:09:14.718201 2026] [security2:error] [pid 167459:tid 167530] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/showphpinfo.php"] [unique_id "aoSDqmr_JutbFb-8svoRXwABlkY"] [Tue Aug 18 13:09:14.746836 2026] [security2:error] [pid 167459:tid 167468] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/mari.php"] [unique_id "aoSDqmr_JutbFb-8svoRYQAB_wg"] [Tue Aug 18 13:09:14.747611 2026] [security2:error] [pid 167459:tid 167688] [client 172.182.217.32:25581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSDqmr_JutbFb-8svoRYgAAAfI"] [Tue Aug 18 13:09:14.779906 2026] [security2:error] [pid 167459:tid 167625] [client 20.100.169.31:2842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSDqmr_JutbFb-8svoRZAAAAbM"] [Tue Aug 18 13:09:14.812959 2026] [security2:error] [pid 167459:tid 167709] [client 213.35.127.232:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDqmr_JutbFb-8svoRZgAAAgc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:14.828397 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:14.828671 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:14.857907 2026] [security2:error] [pid 167459:tid 167518] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/phpstatus.php"] [unique_id "aoSDqmr_JutbFb-8svoRcQABxzo"] [Tue Aug 18 13:09:14.885939 2026] [security2:error] [pid 167459:tid 167490] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/laravel/.env"] [unique_id "aoSDqmr_JutbFb-8svoRdQABwh4"] [Tue Aug 18 13:09:14.891634 2026] [security2:error] [pid 167459:tid 167502] [remote 172.161.79.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.79.161.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amigosdoronron.com.br"] [uri "/nc4.php"] [unique_id "aoSDqmr_JutbFb-8svoRdgABsio"] [Tue Aug 18 13:09:14.912432 2026] [security2:error] [pid 167459:tid 167702] [client 20.1.169.243:10475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSDqmr_JutbFb-8svoRdwAAAgA"] [Tue Aug 18 13:09:14.981802 2026] [security2:error] [pid 167459:tid 167600] [client 20.1.169.243:9580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/shell.php"] [unique_id "aoSDqmr_JutbFb-8svoRfQAAAZo"] [Tue Aug 18 13:09:14.986920 2026] [security2:error] [pid 167459:tid 167569] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDqmr_JutbFb-8svoRfgABuW0"] [Tue Aug 18 13:09:14.986931 2026] [security2:error] [pid 167459:tid 167546] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/config/.env.php"] [unique_id "aoSDqmr_JutbFb-8svoRfwABuVY"] [Tue Aug 18 13:09:14.993761 2026] [security2:error] [pid 167459:tid 167716] [client 172.213.243.2:19532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/maxro.php"] [unique_id "aoSDqmr_JutbFb-8svoRgAAAAg4"] [Tue Aug 18 13:09:14.996342 2026] [security2:error] [pid 167459:tid 167560] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/del.php"] [unique_id "aoSDqmr_JutbFb-8svoRgQABnmQ"] [Tue Aug 18 13:09:15.022711 2026] [security2:error] [pid 167459:tid 167534] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/core/.env"] [unique_id "aoSDq2r_JutbFb-8svoRgwAByUo"] [Tue Aug 18 13:09:15.026233 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:2563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/link-add.php"] [unique_id "aoSDq2r_JutbFb-8svoRhAAAAcw"] [Tue Aug 18 13:09:15.046595 2026] [cgid:error] [pid 167459:tid 167565] [remote 172.161.79.158:0] AH01265: stderr from /home2/amigosdoronron/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:09:15.070967 2026] [security2:error] [pid 167459:tid 167649] [client 20.100.169.31:3338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/info.php"] [unique_id "aoSDq2r_JutbFb-8svoRigAAAcs"] [Tue Aug 18 13:09:15.076453 2026] [security2:error] [pid 167459:tid 167674] [client 68.155.154.236:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/bhfnd.php"] [unique_id "aoSDq2r_JutbFb-8svoRiwAAAeQ"] [Tue Aug 18 13:09:15.083561 2026] [security2:error] [pid 167459:tid 167646] [client 20.104.100.201:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wg459o.php"] [unique_id "aoSDq2r_JutbFb-8svoRjAAAAcg"] [Tue Aug 18 13:09:15.110594 2026] [security2:error] [pid 167459:tid 167698] [client 223.185.37.47:15576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoRjQAAAfw"] [Tue Aug 18 13:09:15.110706 2026] [security2:error] [pid 167459:tid 167698] [client 223.185.37.47:15576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoRjQAAAfw"] [Tue Aug 18 13:09:15.119410 2026] [security2:error] [pid 167459:tid 167531] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/config.php.bak"] [unique_id "aoSDq2r_JutbFb-8svoRjwABrkc"] [Tue Aug 18 13:09:15.122892 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:18522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSDq2r_JutbFb-8svoRkQAAAec"] [Tue Aug 18 13:09:15.123306 2026] [security2:error] [pid 167459:tid 167627] [client 172.182.217.32:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/abcd.php"] [unique_id "aoSDq2r_JutbFb-8svoRkgAAAbU"] [Tue Aug 18 13:09:15.124155 2026] [security2:error] [pid 167459:tid 167567] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSDq2r_JutbFb-8svoRkwABrms"] [Tue Aug 18 13:09:15.136079 2026] [security2:error] [pid 167459:tid 167693] [client 20.250.13.23:23070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/sf.php"] [unique_id "aoSDq2r_JutbFb-8svoRlQAAAfc"] [Tue Aug 18 13:09:15.139839 2026] [security2:error] [pid 167459:tid 167510] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/moderator.php"] [unique_id "aoSDq2r_JutbFb-8svoRlwAByjI"] [Tue Aug 18 13:09:15.149135 2026] [security2:error] [pid 167459:tid 167608] [client 168.62.48.100:16387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDq2r_JutbFb-8svoRmAAAAaI"] [Tue Aug 18 13:09:15.152881 2026] [security2:error] [pid 167459:tid 167615] [client 74.248.18.37:25368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSDq2r_JutbFb-8svoRmgAAAak"] [Tue Aug 18 13:09:15.153170 2026] [security2:error] [pid 167459:tid 167644] [client 158.23.17.4:53221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/40.php"] [unique_id "aoSDq2r_JutbFb-8svoRmwAAAcY"] [Tue Aug 18 13:09:15.160934 2026] [security2:error] [pid 167459:tid 167629] [client 158.23.17.4:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/f.php"] [unique_id "aoSDq2r_JutbFb-8svoRnAAAAbc"] [Tue Aug 18 13:09:15.166359 2026] [security2:error] [pid 167459:tid 167605] [client 20.250.13.23:18199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDq2r_JutbFb-8svoRnQAAAZ8"] [Tue Aug 18 13:09:15.223235 2026] [security2:error] [pid 167459:tid 167575] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/.env.swp"] [unique_id "aoSDq2r_JutbFb-8svoRoAAB6nM"] [Tue Aug 18 13:09:15.239360 2026] [security2:error] [pid 167459:tid 167699] [client 172.182.217.32:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "aoSDq2r_JutbFb-8svoRogAAAf0"] [Tue Aug 18 13:09:15.258689 2026] [security2:error] [pid 167459:tid 167517] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/public/.env"] [unique_id "aoSDq2r_JutbFb-8svoRpQABoTk"] [Tue Aug 18 13:09:15.287461 2026] [security2:error] [pid 167459:tid 167525] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/infoinfo.php"] [unique_id "aoSDq2r_JutbFb-8svoRpwAB_0E"] [Tue Aug 18 13:09:15.291102 2026] [security2:error] [pid 167459:tid 167666] [client 20.1.169.243:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSDq2r_JutbFb-8svoRqAAAAdw"] [Tue Aug 18 13:09:15.348630 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/setup-config.php"] [unique_id "aoSDq2r_JutbFb-8svoRqgAAAeE"] [Tue Aug 18 13:09:15.386635 2026] [security2:error] [pid 167459:tid 167522] [remote 34.158.8.33:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alsconsultoria.com.br"] [uri "/web/.env"] [unique_id "aoSDq2r_JutbFb-8svoRrAABpj4"] [Tue Aug 18 13:09:15.406562 2026] [security2:error] [pid 167459:tid 167705] [client 20.100.169.31:2599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSDq2r_JutbFb-8svoRrgAAAgM"] [Tue Aug 18 13:09:15.409956 2026] [security2:error] [pid 167459:tid 167633] [client 172.213.243.2:11607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wdf.php"] [unique_id "aoSDq2r_JutbFb-8svoRrwAAAbs"] [Tue Aug 18 13:09:15.425957 2026] [security2:error] [pid 167459:tid 167583] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/c99shell.php"] [unique_id "aoSDq2r_JutbFb-8svoRsgAB23s"] [Tue Aug 18 13:09:15.435007 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:15.435394 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:15.474822 2026] [security2:error] [pid 167459:tid 167638] [client 20.127.136.245:14500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/gg.php"] [unique_id "aoSDq2r_JutbFb-8svoRuwAAAcA"] [Tue Aug 18 13:09:15.548104 2026] [security2:error] [pid 167459:tid 167623] [client 46.102.21.132:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoR1AAAAbE"] [Tue Aug 18 13:09:15.548240 2026] [security2:error] [pid 167459:tid 167623] [client 46.102.21.132:62922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoR1AAAAbE"] [Tue Aug 18 13:09:15.555530 2026] [security2:error] [pid 167459:tid 167599] [client 74.249.206.207:21632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/aa.php"] [unique_id "aoSDq2r_JutbFb-8svoR3wAAAZk"] [Tue Aug 18 13:09:15.565069 2026] [security2:error] [pid 167459:tid 167500] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/profiler.php"] [unique_id "aoSDq2r_JutbFb-8svoR4AACDCg"] [Tue Aug 18 13:09:15.583841 2026] [security2:error] [pid 167459:tid 167674] [client 158.23.17.4:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/56.php"] [unique_id "aoSDq2r_JutbFb-8svoR4wAAAeQ"] [Tue Aug 18 13:09:15.609597 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/al.php"] [unique_id "aoSDq2r_JutbFb-8svoR5QAAAb4"] [Tue Aug 18 13:09:15.612006 2026] [security2:error] [pid 167459:tid 167678] [client 40.74.65.169:43713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/img.php"] [unique_id "aoSDq2r_JutbFb-8svoR5gAAAeg"] [Tue Aug 18 13:09:15.641581 2026] [security2:error] [pid 167459:tid 167626] [client 20.116.17.175:52581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSDq2r_JutbFb-8svoR6AAAAbQ"] [Tue Aug 18 13:09:15.655392 2026] [security2:error] [pid 167459:tid 167635] [client 20.1.169.243:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoR6QAAAb0"] [Tue Aug 18 13:09:15.695052 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSDq2r_JutbFb-8svoR7QAAAbc"] [Tue Aug 18 13:09:15.696215 2026] [security2:error] [pid 167459:tid 167631] [client 20.100.169.31:3336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/profile.php"] [unique_id "aoSDq2r_JutbFb-8svoR7gAAAbk"] [Tue Aug 18 13:09:15.702363 2026] [security2:error] [pid 167459:tid 167579] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/findes.php"] [unique_id "aoSDq2r_JutbFb-8svoR7wACCHc"] [Tue Aug 18 13:09:15.713793 2026] [security2:error] [pid 167459:tid 167606] [client 20.1.169.243:9328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/t.php"] [unique_id "aoSDq2r_JutbFb-8svoR8gAAAaA"] [Tue Aug 18 13:09:15.735213 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:15.735508 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:15.752692 2026] [security2:error] [pid 167459:tid 167630] [client 172.182.217.32:4085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/customize/about.php"] [unique_id "aoSDq2r_JutbFb-8svoR9gAAAbg"] [Tue Aug 18 13:09:15.754188 2026] [security2:error] [pid 167459:tid 167642] [client 20.250.13.23:5907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/chosen.php"] [unique_id "aoSDq2r_JutbFb-8svoR9wAAAcQ"] [Tue Aug 18 13:09:15.759531 2026] [security2:error] [pid 167459:tid 167595] [client 158.23.17.4:39565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ee.php"] [unique_id "aoSDq2r_JutbFb-8svoR-QAAAZU"] [Tue Aug 18 13:09:15.781981 2026] [security2:error] [pid 167459:tid 167653] [client 74.248.18.37:58915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/admin.php"] [unique_id "aoSDq2r_JutbFb-8svoR-wAAAc8"] [Tue Aug 18 13:09:15.789506 2026] [security2:error] [pid 167459:tid 167649] [client 20.250.13.23:18377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDq2r_JutbFb-8svoR_AAAAcs"] [Tue Aug 18 13:09:15.791765 2026] [security2:error] [pid 167459:tid 167589] [client 74.248.18.37:3383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/db.php"] [unique_id "aoSDq2r_JutbFb-8svoR_QAAAY8"] [Tue Aug 18 13:09:15.821596 2026] [security2:error] [pid 167459:tid 167658] [client 172.213.243.2:5723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ff1.php"] [unique_id "aoSDq2r_JutbFb-8svoR_gAAAdQ"] [Tue Aug 18 13:09:15.832516 2026] [security2:error] [pid 167459:tid 167604] [client 213.35.127.232:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDq2r_JutbFb-8svoR_wAAAZ4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:15.842140 2026] [security2:error] [pid 167459:tid 167549] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/fedora.php"] [unique_id "aoSDq2r_JutbFb-8svoSAQAB7lk"] [Tue Aug 18 13:09:15.848033 2026] [security2:error] [pid 167459:tid 167607] [client 68.221.73.131:28223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/sf.php"] [unique_id "aoSDq2r_JutbFb-8svoSAgAAAaE"] [Tue Aug 18 13:09:15.919654 2026] [security2:error] [pid 167459:tid 167592] [client 4.232.151.198:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/maint/index.php"] [unique_id "aoSDq2r_JutbFb-8svoSBAAAAZI"] [Tue Aug 18 13:09:15.942774 2026] [security2:error] [pid 167459:tid 167611] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDq2r_JutbFb-8svoSAwABpTQ"] [Tue Aug 18 13:09:15.980548 2026] [security2:error] [pid 167459:tid 167555] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/path.php"] [unique_id "aoSDq2r_JutbFb-8svoSCAAB218"] [Tue Aug 18 13:09:16.011824 2026] [security2:error] [pid 167459:tid 167669] [client 168.62.48.100:16408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDrGr_JutbFb-8svoSCgAAAd8"] [Tue Aug 18 13:09:16.035333 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:16.035601 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:16.044037 2026] [security2:error] [pid 167459:tid 167701] [client 20.100.169.31:52435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDrGr_JutbFb-8svoSDwAAAf8"] [Tue Aug 18 13:09:16.063492 2026] [security2:error] [pid 167459:tid 167637] [client 20.1.169.243:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/chosen.php"] [unique_id "aoSDrGr_JutbFb-8svoSEgAAAb8"] [Tue Aug 18 13:09:16.085360 2026] [security2:error] [pid 167459:tid 167513] [remote 162.55.89.48:41966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viniciushartl.com.br"] [uri "/wp-login.php"] [unique_id "aoSDrGr_JutbFb-8svoSFQAB2DU"] [Tue Aug 18 13:09:16.088952 2026] [security2:error] [pid 167459:tid 167641] [client 20.1.169.243:9544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/up.php"] [unique_id "aoSDrGr_JutbFb-8svoSFgAAAcM"] [Tue Aug 18 13:09:16.097795 2026] [security2:error] [pid 167459:tid 167705] [client 172.182.217.32:15582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/alfa.php"] [unique_id "aoSDrGr_JutbFb-8svoSFwAAAgM"] [Tue Aug 18 13:09:16.118674 2026] [security2:error] [pid 167459:tid 167703] [client 52.139.47.57:18509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/admin.php"] [unique_id "aoSDrGr_JutbFb-8svoSGQAAAgE"] [Tue Aug 18 13:09:16.118930 2026] [security2:error] [pid 167459:tid 167514] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/456.php"] [unique_id "aoSDrGr_JutbFb-8svoSGgAB5TY"] [Tue Aug 18 13:09:16.152223 2026] [security2:error] [pid 167459:tid 167713] [client 216.73.161.201:37619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.161.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSDq2r_JutbFb-8svoSCQAAAgs"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:09:16.215493 2026] [security2:error] [pid 167459:tid 167594] [client 20.127.136.245:21206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/class.php"] [unique_id "aoSDrGr_JutbFb-8svoSIAAAAZQ"] [Tue Aug 18 13:09:16.233186 2026] [security2:error] [pid 167459:tid 167628] [client 172.213.243.2:48418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/guk.php"] [unique_id "aoSDrGr_JutbFb-8svoSIwAAAbY"] [Tue Aug 18 13:09:16.246403 2026] [security2:error] [pid 167459:tid 167702] [client 172.182.217.32:25761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qriar.com"] [uri "/wp-includes/images/about.php"] [unique_id "aoSDrGr_JutbFb-8svoSJQAAAgA"] [Tue Aug 18 13:09:16.253680 2026] [security2:error] [pid 167459:tid 167677] [client 20.116.17.175:22732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/min.php"] [unique_id "aoSDrGr_JutbFb-8svoSJgAAAec"] [Tue Aug 18 13:09:16.266403 2026] [security2:error] [pid 167459:tid 167543] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/SMTP.php"] [unique_id "aoSDrGr_JutbFb-8svoSJwABylM"] [Tue Aug 18 13:09:16.286149 2026] [security2:error] [pid 167459:tid 167626] [client 158.23.17.4:39563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ak.php"] [unique_id "aoSDrGr_JutbFb-8svoSKAAAAbQ"] [Tue Aug 18 13:09:16.323159 2026] [security2:error] [pid 167459:tid 167690] [client 20.100.169.31:18947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/sx.php"] [unique_id "aoSDrGr_JutbFb-8svoSKgAAAfQ"] [Tue Aug 18 13:09:16.337926 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:16.338196 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:16.344821 2026] [security2:error] [pid 167459:tid 167620] [client 40.74.65.169:43739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/222.php"] [unique_id "aoSDrGr_JutbFb-8svoSLgAAAa4"] [Tue Aug 18 13:09:16.370566 2026] [security2:error] [pid 167459:tid 167643] [client 20.250.13.23:5924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/u.php"] [unique_id "aoSDrGr_JutbFb-8svoSLwAAAcU"] [Tue Aug 18 13:09:16.406088 2026] [security2:error] [pid 167459:tid 167584] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/vbseo.php"] [unique_id "aoSDrGr_JutbFb-8svoSMQABlnw"] [Tue Aug 18 13:09:16.410550 2026] [security2:error] [pid 167459:tid 167656] [client 20.250.13.23:23051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/abc.php"] [unique_id "aoSDrGr_JutbFb-8svoSNAAAAdI"] [Tue Aug 18 13:09:16.424398 2026] [security2:error] [pid 167459:tid 167599] [client 74.248.18.37:3369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSDrGr_JutbFb-8svoSNQAAAZk"] [Tue Aug 18 13:09:16.454374 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:9548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ultra.php"] [unique_id "aoSDrGr_JutbFb-8svoSNwAAAgI"] [Tue Aug 18 13:09:16.534693 2026] [security2:error] [pid 167459:tid 167606] [client 52.139.47.57:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/core.php"] [unique_id "aoSDrGr_JutbFb-8svoSOwAAAaA"] [Tue Aug 18 13:09:16.544113 2026] [security2:error] [pid 167459:tid 167528] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/sysinfo.php"] [unique_id "aoSDrGr_JutbFb-8svoSPAABwUQ"] [Tue Aug 18 13:09:16.553235 2026] [security2:error] [pid 167459:tid 167666] [client 20.151.109.219:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/13.php"] [unique_id "aoSDrGr_JutbFb-8svoSPQAAAdw"] [Tue Aug 18 13:09:16.554624 2026] [security2:error] [pid 167459:tid 167715] [client 20.1.169.243:9727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/class-protect-uploads.php"] [unique_id "aoSDrGr_JutbFb-8svoSPgAAAg0"] [Tue Aug 18 13:09:16.576798 2026] [security2:error] [pid 167459:tid 167679] [client 20.104.100.201:13843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/mifta.php"] [unique_id "aoSDrGr_JutbFb-8svoSQgAAAek"] [Tue Aug 18 13:09:16.585661 2026] [security2:error] [pid 167459:tid 167630] [client 172.182.217.32:15610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/as.php"] [unique_id "aoSDrGr_JutbFb-8svoSQwAAAbg"] [Tue Aug 18 13:09:16.608831 2026] [security2:error] [pid 167459:tid 167706] [client 149.34.210.141:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDrGr_JutbFb-8svoSRQAAAgQ"] [Tue Aug 18 13:09:16.611950 2026] [security2:error] [pid 167459:tid 167708] [client 4.232.151.198:2568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/maint/repair.php"] [unique_id "aoSDrGr_JutbFb-8svoSRgAAAgY"] [Tue Aug 18 13:09:16.639122 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:16.639388 2026] [authz_core:error] [pid 167459:tid 167563] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:16.648477 2026] [security2:error] [pid 167459:tid 167633] [client 172.213.243.2:37110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-the.php"] [unique_id "aoSDrGr_JutbFb-8svoSSQAAAbs"] [Tue Aug 18 13:09:16.669544 2026] [security2:error] [pid 167459:tid 167608] [client 20.100.169.31:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDrGr_JutbFb-8svoSTQAAAaI"] [Tue Aug 18 13:09:16.685969 2026] [security2:error] [pid 167459:tid 167499] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ppinfo.php"] [unique_id "aoSDrGr_JutbFb-8svoSTgAB3yc"] [Tue Aug 18 13:09:16.818889 2026] [security2:error] [pid 167459:tid 167603] [client 20.1.169.243:8843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/vv.php"] [unique_id "aoSDrGr_JutbFb-8svoSVQAAAZ0"] [Tue Aug 18 13:09:16.826630 2026] [security2:error] [pid 167459:tid 167510] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/globals.php"] [unique_id "aoSDrGr_JutbFb-8svoSVgABzTI"] [Tue Aug 18 13:09:16.836280 2026] [security2:error] [pid 167459:tid 167667] [client 168.62.48.100:16389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDrGr_JutbFb-8svoSVwAAAd0"] [Tue Aug 18 13:09:16.857093 2026] [security2:error] [pid 167459:tid 167589] [client 213.35.127.232:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDrGr_JutbFb-8svoSWgAAAY8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:16.875267 2026] [security2:error] [pid 167459:tid 167706] [client 149.34.210.141:56856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDrGr_JutbFb-8svoSRQAAAgQ"] [Tue Aug 18 13:09:16.920283 2026] [security2:error] [pid 167459:tid 167703] [client 20.1.169.243:10222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSDrGr_JutbFb-8svoSXQAAAgE"] [Tue Aug 18 13:09:16.941249 2026] [security2:error] [pid 167459:tid 167673] [client 158.23.17.4:4997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/test_info.php"] [unique_id "aoSDrGr_JutbFb-8svoSYQAAAeM"] [Tue Aug 18 13:09:16.947060 2026] [security2:error] [pid 167459:tid 167640] [client 20.100.169.31:18965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDrGr_JutbFb-8svoSYgAAAcI"] [Tue Aug 18 13:09:16.950809 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:18540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/db-status.php"] [unique_id "aoSDrGr_JutbFb-8svoSYwAAAcA"] [Tue Aug 18 13:09:16.969011 2026] [security2:error] [pid 167459:tid 167477] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/yindu.php"] [unique_id "aoSDrGr_JutbFb-8svoSZgABqBE"] [Tue Aug 18 13:09:16.994112 2026] [security2:error] [pid 167459:tid 167665] [client 149.118.59.225:56892] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "devaleobras.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSDrGr_JutbFb-8svoSZwAAAds"] [Tue Aug 18 13:09:17.056277 2026] [security2:error] [pid 167459:tid 167620] [client 172.213.243.2:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sbhu.php"] [unique_id "aoSDrWr_JutbFb-8svoSaQAAAa4"] [Tue Aug 18 13:09:17.075470 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:15763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/aa.php"] [unique_id "aoSDrWr_JutbFb-8svoSawAAAb4"] [Tue Aug 18 13:09:17.083583 2026] [security2:error] [pid 167459:tid 167594] [client 74.248.18.37:25360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/file.php"] [unique_id "aoSDrWr_JutbFb-8svoSbQAAAZQ"] [Tue Aug 18 13:09:17.101213 2026] [security2:error] [pid 167459:tid 167668] [client 20.250.13.23:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/sf.php"] [unique_id "aoSDrWr_JutbFb-8svoSbgAAAd4"] [Tue Aug 18 13:09:17.106283 2026] [security2:error] [pid 167459:tid 167522] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/sxx.php"] [unique_id "aoSDrWr_JutbFb-8svoScAAB5j4"] [Tue Aug 18 13:09:17.120566 2026] [autoindex:error] [pid 167459:tid 167650] [client 20.250.13.23:18428] AH01276: Cannot serve directory /home4/alltime/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:17.129373 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:22691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ccou.php"] [unique_id "aoSDrWr_JutbFb-8svoScwAAAdI"] [Tue Aug 18 13:09:17.130348 2026] [security2:error] [pid 167459:tid 167623] [client 213.202.253.4:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/postnews.php"] [unique_id "aoSDrWr_JutbFb-8svoSdAAAAbE"], referer: www.google.com [Tue Aug 18 13:09:17.165074 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.133.44:38793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/colors.php"] [unique_id "aoSDrWr_JutbFb-8svoSdwAAAdk"] [Tue Aug 18 13:09:17.197839 2026] [security2:error] [pid 167459:tid 167629] [client 20.1.169.243:8854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/V5.php"] [unique_id "aoSDrWr_JutbFb-8svoSeAAAAbc"] [Tue Aug 18 13:09:17.233909 2026] [security2:error] [pid 167459:tid 167616] [client 40.74.65.169:11699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/key.php"] [unique_id "aoSDrWr_JutbFb-8svoSewAAAao"] [Tue Aug 18 13:09:17.253252 2026] [security2:error] [pid 167459:tid 167505] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/settings.php"] [unique_id "aoSDrWr_JutbFb-8svoSfQABui0"] [Tue Aug 18 13:09:17.294538 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/content.php"] [unique_id "aoSDrWr_JutbFb-8svoSfgAAAgI"] [Tue Aug 18 13:09:17.311656 2026] [security2:error] [pid 167459:tid 167605] [client 20.100.169.31:2880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDrWr_JutbFb-8svoSgAAAAZ8"] [Tue Aug 18 13:09:17.323759 2026] [security2:error] [pid 167459:tid 167630] [client 20.250.13.23:18428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/customize.php"] [unique_id "aoSDrWr_JutbFb-8svoSgQAAAbg"] [Tue Aug 18 13:09:17.352380 2026] [security2:error] [pid 167459:tid 167708] [client 158.23.17.4:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/rx.php"] [unique_id "aoSDrWr_JutbFb-8svoSgwAAAgY"] [Tue Aug 18 13:09:17.392903 2026] [security2:error] [pid 167459:tid 167538] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/spip.php"] [unique_id "aoSDrWr_JutbFb-8svoShQABpU4"] [Tue Aug 18 13:09:17.421644 2026] [security2:error] [pid 167459:tid 167712] [client 52.139.47.57:35313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSDrWr_JutbFb-8svoSiAAAAgo"] [Tue Aug 18 13:09:17.422768 2026] [security2:error] [pid 167459:tid 167598] [client 158.23.17.4:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/14.php"] [unique_id "aoSDrWr_JutbFb-8svoSiQAAAZg"] [Tue Aug 18 13:09:17.461936 2026] [security2:error] [pid 167459:tid 167516] [remote 162.55.89.48:41970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.89.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centraldasvariedades.com.br"] [uri "/wp-login.php"] [unique_id "aoSDrWr_JutbFb-8svoSjAABozg"] [Tue Aug 18 13:09:17.472131 2026] [security2:error] [pid 167459:tid 167697] [client 102.213.179.104:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrWr_JutbFb-8svoSjgAAAfs"] [Tue Aug 18 13:09:17.472224 2026] [security2:error] [pid 167459:tid 167697] [client 102.213.179.104:61653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrWr_JutbFb-8svoSjgAAAfs"] [Tue Aug 18 13:09:17.503098 2026] [security2:error] [pid 167459:tid 167658] [client 172.213.243.2:14445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/zc-318.php"] [unique_id "aoSDrWr_JutbFb-8svoSkAAAAdQ"] [Tue Aug 18 13:09:17.530916 2026] [security2:error] [pid 167459:tid 167461] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/search.php"] [unique_id "aoSDrWr_JutbFb-8svoSkQAB8wE"] [Tue Aug 18 13:09:17.538842 2026] [security2:error] [pid 167459:tid 167682] [client 20.127.136.245:8315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/flower.php"] [unique_id "aoSDrWr_JutbFb-8svoSkgAAAew"] [Tue Aug 18 13:09:17.546935 2026] [security2:error] [pid 167459:tid 167660] [client 74.248.18.37:49731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDrWr_JutbFb-8svoSkwAAAdY"] [Tue Aug 18 13:09:17.559100 2026] [security2:error] [pid 167459:tid 167675] [client 20.116.17.175:41473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/crgio.php"] [unique_id "aoSDrWr_JutbFb-8svoSlAAAAeU"] [Tue Aug 18 13:09:17.564907 2026] [security2:error] [pid 167459:tid 167654] [client 20.1.169.243:8861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp-user.php"] [unique_id "aoSDrWr_JutbFb-8svoSlQAAAdA"] [Tue Aug 18 13:09:17.566688 2026] [security2:error] [pid 167459:tid 167601] [client 172.182.217.32:15606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/abc.php"] [unique_id "aoSDrWr_JutbFb-8svoSlgAAAZs"] [Tue Aug 18 13:09:17.569088 2026] [security2:error] [pid 167459:tid 167714] [client 20.100.169.31:3457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDrWr_JutbFb-8svoSlwAAAgw"] [Tue Aug 18 13:09:17.574862 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:17.575123 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:17.613192 2026] [security2:error] [pid 167459:tid 167628] [client 168.62.48.100:16437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDrWr_JutbFb-8svoSnAAAAbY"] [Tue Aug 18 13:09:17.618017 2026] [security2:error] [pid 167459:tid 167606] [client 4.232.151.198:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/maint/wpxml.php"] [unique_id "aoSDrWr_JutbFb-8svoSnQAAAaA"] [Tue Aug 18 13:09:17.663245 2026] [security2:error] [pid 167459:tid 167703] [client 20.104.100.201:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSDrWr_JutbFb-8svoSoQAAAgE"] [Tue Aug 18 13:09:17.663640 2026] [security2:error] [pid 167459:tid 167661] [client 20.1.169.243:10187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/database.php"] [unique_id "aoSDrWr_JutbFb-8svoSogAAAdc"] [Tue Aug 18 13:09:17.672486 2026] [security2:error] [pid 167459:tid 167568] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/build.php"] [unique_id "aoSDrWr_JutbFb-8svoSpAACAGw"] [Tue Aug 18 13:09:17.713753 2026] [security2:error] [pid 167459:tid 167597] [client 20.250.13.23:18213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/chosen.php"] [unique_id "aoSDrWr_JutbFb-8svoSpwAAAZc"] [Tue Aug 18 13:09:17.715972 2026] [security2:error] [pid 167459:tid 167696] [client 74.248.18.37:25345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSDrWr_JutbFb-8svoSqAAAAfo"] [Tue Aug 18 13:09:17.813394 2026] [security2:error] [pid 167459:tid 167535] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/defaul.php"] [unique_id "aoSDrWr_JutbFb-8svoSrQABmUs"] [Tue Aug 18 13:09:17.841510 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:13698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/index.php"] [unique_id "aoSDrWr_JutbFb-8svoSsAAAAec"] [Tue Aug 18 13:09:17.843276 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:17.843538 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:17.875844 2026] [security2:error] [pid 167459:tid 167691] [client 213.35.127.232:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDrWr_JutbFb-8svoSswAAAfU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:17.883852 2026] [security2:error] [pid 167459:tid 167616] [client 20.116.17.175:41527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/uploads/file1.php"] [unique_id "aoSDrWr_JutbFb-8svoStQAAAao"] [Tue Aug 18 13:09:17.893284 2026] [security2:error] [pid 167459:tid 167634] [client 20.65.98.162:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/w1px.php"] [unique_id "aoSDrWr_JutbFb-8svoStwAAAbw"] [Tue Aug 18 13:09:17.918858 2026] [security2:error] [pid 167459:tid 167684] [client 172.213.243.2:11638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ccou.php"] [unique_id "aoSDrWr_JutbFb-8svoSuAAAAe4"] [Tue Aug 18 13:09:17.936141 2026] [security2:error] [pid 167459:tid 167615] [client 20.1.169.243:8870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDrWr_JutbFb-8svoSvAAAAak"] [Tue Aug 18 13:09:17.954785 2026] [security2:error] [pid 167459:tid 167496] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/twin.php"] [unique_id "aoSDrWr_JutbFb-8svoSvQABnyQ"] [Tue Aug 18 13:09:17.959918 2026] [security2:error] [pid 167459:tid 167630] [client 168.62.48.100:16386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDrWr_JutbFb-8svoSvwAAAbg"] [Tue Aug 18 13:09:18.014051 2026] [security2:error] [pid 167459:tid 167673] [client 149.118.59.225:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.59.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devaleobras.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSDrmr_JutbFb-8svoSwwAAAeM"] [Tue Aug 18 13:09:18.022453 2026] [security2:error] [pid 167459:tid 167608] [client 20.151.109.219:58357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/so.php"] [unique_id "aoSDrmr_JutbFb-8svoSxAAAAaI"] [Tue Aug 18 13:09:18.027486 2026] [security2:error] [pid 167459:tid 167680] [client 158.23.17.4:40210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/tk.php"] [unique_id "aoSDrmr_JutbFb-8svoSywAAAeo"] [Tue Aug 18 13:09:18.030937 2026] [security2:error] [pid 167459:tid 167604] [client 20.1.169.243:10482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/db.php"] [unique_id "aoSDrmr_JutbFb-8svoSzAAAAZ4"] [Tue Aug 18 13:09:18.040169 2026] [security2:error] [pid 167459:tid 167639] [client 157.20.138.62:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrmr_JutbFb-8svoSzQAAAcE"] [Tue Aug 18 13:09:18.040516 2026] [security2:error] [pid 167459:tid 167639] [client 157.20.138.62:60244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrmr_JutbFb-8svoSzQAAAcE"] [Tue Aug 18 13:09:18.056671 2026] [security2:error] [pid 167459:tid 167715] [client 172.182.217.32:15560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/av.php"] [unique_id "aoSDrmr_JutbFb-8svoSzgAAAg0"] [Tue Aug 18 13:09:18.078789 2026] [security2:error] [pid 167459:tid 167637] [client 40.74.65.169:10486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/chosen.php"] [unique_id "aoSDrmr_JutbFb-8svoS0QAAAb8"] [Tue Aug 18 13:09:18.097212 2026] [security2:error] [pid 167459:tid 167619] [client 4.232.151.198:31342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/bolt.php"] [unique_id "aoSDrmr_JutbFb-8svoS0gAAAa0"] [Tue Aug 18 13:09:18.102736 2026] [security2:error] [pid 167459:tid 167579] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/new2.php"] [unique_id "aoSDrmr_JutbFb-8svoS0wAB_3c"] [Tue Aug 18 13:09:18.141354 2026] [security2:error] [pid 167459:tid 167660] [client 20.127.136.245:22195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/motu.php"] [unique_id "aoSDrmr_JutbFb-8svoS2gAAAdY"] [Tue Aug 18 13:09:18.213430 2026] [security2:error] [pid 167459:tid 167652] [client 20.116.17.175:22736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/css.php"] [unique_id "aoSDrmr_JutbFb-8svoS4gAAAc4"] [Tue Aug 18 13:09:18.234411 2026] [security2:error] [pid 167459:tid 167672] [client 20.250.13.23:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/mah/function.php"] [unique_id "aoSDrmr_JutbFb-8svoS4wAAAeI"] [Tue Aug 18 13:09:18.243801 2026] [security2:error] [pid 167459:tid 167674] [client 178.153.171.161:37590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrmr_JutbFb-8svoS5gAAAeQ"] [Tue Aug 18 13:09:18.243911 2026] [security2:error] [pid 167459:tid 167674] [client 178.153.171.161:37590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDrmr_JutbFb-8svoS5gAAAeQ"] [Tue Aug 18 13:09:18.250067 2026] [security2:error] [pid 167459:tid 167511] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/rex.php"] [unique_id "aoSDrmr_JutbFb-8svoS5wAB7zM"] [Tue Aug 18 13:09:18.254859 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:35319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSDrmr_JutbFb-8svoS6AAAAfA"] [Tue Aug 18 13:09:18.318053 2026] [security2:error] [pid 167459:tid 167625] [client 20.1.169.243:8869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp.php"] [unique_id "aoSDrmr_JutbFb-8svoS7gAAAbM"] [Tue Aug 18 13:09:18.329417 2026] [security2:error] [pid 167459:tid 167624] [client 172.213.243.2:19574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/txets.php"] [unique_id "aoSDrmr_JutbFb-8svoS8gAAAbI"] [Tue Aug 18 13:09:18.348700 2026] [security2:error] [pid 167459:tid 167709] [client 20.100.169.31:2945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSDrmr_JutbFb-8svoS9gAAAgc"] [Tue Aug 18 13:09:18.364887 2026] [security2:error] [pid 167459:tid 167600] [client 74.248.18.37:3357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDrmr_JutbFb-8svoS-AAAAZo"] [Tue Aug 18 13:09:18.386320 2026] [security2:error] [pid 167459:tid 167716] [client 74.248.133.44:18475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/interactivity-api/index.php"] [unique_id "aoSDrmr_JutbFb-8svoS_AAAAg4"] [Tue Aug 18 13:09:18.394416 2026] [security2:error] [pid 167459:tid 167523] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/verification.php"] [unique_id "aoSDrmr_JutbFb-8svoS_wAB0z8"] [Tue Aug 18 13:09:18.403361 2026] [security2:error] [pid 167459:tid 167698] [client 20.1.169.243:10212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/default.php"] [unique_id "aoSDrmr_JutbFb-8svoTAAAAAfw"] [Tue Aug 18 13:09:18.404786 2026] [security2:error] [pid 167459:tid 167667] [client 4.232.151.198:2714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/maintenance.php"] [unique_id "aoSDrmr_JutbFb-8svoTAQAAAd0"] [Tue Aug 18 13:09:18.421606 2026] [security2:error] [pid 167459:tid 167691] [client 168.62.48.100:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDrmr_JutbFb-8svoTBQAAAfU"] [Tue Aug 18 13:09:18.527623 2026] [security2:error] [pid 167459:tid 167597] [client 20.250.13.23:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/u.php"] [unique_id "aoSDrmr_JutbFb-8svoTDwAAAZc"] [Tue Aug 18 13:09:18.538027 2026] [security2:error] [pid 167459:tid 167526] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/smtp.php"] [unique_id "aoSDrmr_JutbFb-8svoTEQACCUI"] [Tue Aug 18 13:09:18.542558 2026] [security2:error] [pid 167459:tid 167642] [client 172.182.217.32:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSDrmr_JutbFb-8svoTEgAAAcQ"] [Tue Aug 18 13:09:18.670741 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:35302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSDrmr_JutbFb-8svoTFQAAAdk"] [Tue Aug 18 13:09:18.671382 2026] [security2:error] [pid 167459:tid 167692] [client 20.116.17.175:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/7.php"] [unique_id "aoSDrmr_JutbFb-8svoTFgAAAfY"] [Tue Aug 18 13:09:18.677227 2026] [security2:error] [pid 167459:tid 167560] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/teste.php"] [unique_id "aoSDrmr_JutbFb-8svoTGAABwWQ"] [Tue Aug 18 13:09:18.680731 2026] [security2:error] [pid 167459:tid 167609] [client 20.116.17.175:22708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "aoSDrmr_JutbFb-8svoTGQAAAaM"] [Tue Aug 18 13:09:18.683358 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/worksec.php"] [unique_id "aoSDrmr_JutbFb-8svoTGgAAAeE"] [Tue Aug 18 13:09:18.683806 2026] [security2:error] [pid 167459:tid 167715] [client 149.118.59.225:58572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "devaleobras.com.br"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSDrmr_JutbFb-8svoTGwAAAg0"] [Tue Aug 18 13:09:18.718597 2026] [security2:error] [pid 167459:tid 167637] [client 20.171.51.14:18234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/conn-test.php"] [unique_id "aoSDrmr_JutbFb-8svoTHAAAAb8"] [Tue Aug 18 13:09:18.736325 2026] [security2:error] [pid 167459:tid 167689] [client 20.250.13.23:43745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSDrmr_JutbFb-8svoTHgAAAfM"] [Tue Aug 18 13:09:18.747979 2026] [authz_core:error] [pid 167459:tid 167587] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:18.748249 2026] [authz_core:error] [pid 167459:tid 167587] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:18.770888 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/dex.php"] [unique_id "aoSDrmr_JutbFb-8svoTIQAAAgo"] [Tue Aug 18 13:09:18.777934 2026] [security2:error] [pid 167459:tid 167593] [client 158.23.17.4:48847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mandrill.php"] [unique_id "aoSDrmr_JutbFb-8svoTIgAAAZM"] [Tue Aug 18 13:09:18.788306 2026] [security2:error] [pid 167459:tid 167603] [client 172.213.243.2:18604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fun.php"] [unique_id "aoSDrmr_JutbFb-8svoTIwAAAZ0"] [Tue Aug 18 13:09:18.820285 2026] [security2:error] [pid 167459:tid 167507] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/local.php"] [unique_id "aoSDrmr_JutbFb-8svoTJgABti8"] [Tue Aug 18 13:09:18.848909 2026] [security2:error] [pid 167459:tid 167644] [client 168.62.48.100:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDrmr_JutbFb-8svoTKQAAAcY"] [Tue Aug 18 13:09:18.865504 2026] [security2:error] [pid 167459:tid 167608] [client 20.250.13.23:18194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/filter.php"] [unique_id "aoSDrmr_JutbFb-8svoTKgAAAaI"] [Tue Aug 18 13:09:18.871190 2026] [security2:error] [pid 167459:tid 167658] [client 158.101.5.31:59947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "docurso.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSDrmr_JutbFb-8svoTKwAAAdQ"] [Tue Aug 18 13:09:18.894618 2026] [security2:error] [pid 167459:tid 167700] [client 213.35.127.232:58094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDrmr_JutbFb-8svoTLAAAAf4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:18.920499 2026] [security2:error] [pid 167459:tid 167640] [client 20.100.169.31:18968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDrmr_JutbFb-8svoTLwAAAcI"] [Tue Aug 18 13:09:18.947578 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:20435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/30.php"] [unique_id "aoSDrmr_JutbFb-8svoTMQAAAcc"] [Tue Aug 18 13:09:18.961079 2026] [security2:error] [pid 167459:tid 167518] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp_sitting.php"] [unique_id "aoSDrmr_JutbFb-8svoTMgAB3zo"] [Tue Aug 18 13:09:18.996489 2026] [security2:error] [pid 167459:tid 167651] [client 20.100.169.31:2565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSDrmr_JutbFb-8svoTNgAAAc0"] [Tue Aug 18 13:09:18.996516 2026] [security2:error] [pid 167459:tid 167660] [client 74.248.18.37:3351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/htaccess.php"] [unique_id "aoSDrmr_JutbFb-8svoTNQAAAdY"] [Tue Aug 18 13:09:19.027007 2026] [security2:error] [pid 167459:tid 167674] [client 172.182.217.32:12251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/asus.php"] [unique_id "aoSDr2r_JutbFb-8svoTOAAAAeQ"] [Tue Aug 18 13:09:19.048565 2026] [security2:error] [pid 167459:tid 167614] [client 20.1.169.243:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDr2r_JutbFb-8svoTPAAAAag"] [Tue Aug 18 13:09:19.055751 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:19.056216 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:19.082544 2026] [security2:error] [pid 167459:tid 167624] [client 52.139.47.57:35267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/ms-files.php"] [unique_id "aoSDr2r_JutbFb-8svoTQAAAAbI"] [Tue Aug 18 13:09:19.084101 2026] [security2:error] [pid 167459:tid 167677] [client 40.74.65.169:10455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/wpxml.php"] [unique_id "aoSDr2r_JutbFb-8svoTQQAAAec"] [Tue Aug 18 13:09:19.099488 2026] [security2:error] [pid 167459:tid 167575] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ninja.php"] [unique_id "aoSDr2r_JutbFb-8svoTQgAB0XM"] [Tue Aug 18 13:09:19.126048 2026] [security2:error] [pid 167459:tid 167606] [client 168.62.48.100:16485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDr2r_JutbFb-8svoTRAAAAaA"] [Tue Aug 18 13:09:19.137423 2026] [security2:error] [pid 167459:tid 167650] [client 20.1.169.243:10217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/df.php"] [unique_id "aoSDr2r_JutbFb-8svoTRQAAAcw"] [Tue Aug 18 13:09:19.205857 2026] [security2:error] [pid 167459:tid 167629] [client 172.213.243.2:18613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/jq.php"] [unique_id "aoSDr2r_JutbFb-8svoTSQAAAbc"] [Tue Aug 18 13:09:19.238564 2026] [security2:error] [pid 167459:tid 167493] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/phpprobe.php"] [unique_id "aoSDr2r_JutbFb-8svoTSwABySE"] [Tue Aug 18 13:09:19.245536 2026] [security2:error] [pid 167459:tid 167607] [client 20.104.100.201:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/index2.php"] [unique_id "aoSDr2r_JutbFb-8svoTTAAAAaE"] [Tue Aug 18 13:09:19.266096 2026] [security2:error] [pid 167459:tid 167601] [client 74.248.18.37:49739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/info.php"] [unique_id "aoSDr2r_JutbFb-8svoTTQAAAZs"] [Tue Aug 18 13:09:19.277643 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/network/about.php"] [unique_id "aoSDr2r_JutbFb-8svoTWAAAAgg"] [Tue Aug 18 13:09:19.283430 2026] [security2:error] [pid 167459:tid 167627] [client 20.116.17.175:22717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/epinyins.php"] [unique_id "aoSDr2r_JutbFb-8svoTWQAAAbU"] [Tue Aug 18 13:09:19.327022 2026] [security2:error] [pid 167459:tid 167612] [client 68.155.154.236:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/qfvqu.php"] [unique_id "aoSDr2r_JutbFb-8svoTaAAAAaY"] [Tue Aug 18 13:09:19.353421 2026] [security2:error] [pid 167459:tid 167681] [client 149.118.59.225:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.59.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "devaleobras.com.br"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSDr2r_JutbFb-8svoTcQAAAes"] [Tue Aug 18 13:09:19.357593 2026] [security2:error] [pid 167459:tid 167663] [client 20.250.13.23:5398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/customize.php"] [unique_id "aoSDr2r_JutbFb-8svoTdgAAAdk"] [Tue Aug 18 13:09:19.358456 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:19.358850 2026] [authz_core:error] [pid 167459:tid 167469] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:19.375335 2026] [security2:error] [pid 167459:tid 167582] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/wp-title.php"] [unique_id "aoSDr2r_JutbFb-8svoTdwABwXo"] [Tue Aug 18 13:09:19.376055 2026] [security2:error] [pid 167459:tid 167577] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/info.php"] [unique_id "aoSDr2r_JutbFb-8svoTeAABrnU"] [Tue Aug 18 13:09:19.387256 2026] [security2:error] [pid 167459:tid 167613] [client 158.101.5.31:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.5.101.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSDr2r_JutbFb-8svoTeQAAAac"] [Tue Aug 18 13:09:19.395422 2026] [security2:error] [pid 167459:tid 167715] [client 158.23.17.4:20665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/hp.php"] [unique_id "aoSDr2r_JutbFb-8svoTewAAAg0"] [Tue Aug 18 13:09:19.415042 2026] [security2:error] [pid 167459:tid 167641] [client 20.1.169.243:8911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp-signin.php"] [unique_id "aoSDr2r_JutbFb-8svoTgwAAAcM"] [Tue Aug 18 13:09:19.418995 2026] [security2:error] [pid 167459:tid 167462] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDr2r_JutbFb-8svoThAAB_QI"] [Tue Aug 18 13:09:19.419095 2026] [security2:error] [pid 167459:tid 167699] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDr2r_JutbFb-8svoThAAB_QI"] [Tue Aug 18 13:09:19.434783 2026] [security2:error] [pid 167459:tid 167487] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/phpinfo.php"] [unique_id "aoSDr2r_JutbFb-8svoThgABvxs"] [Tue Aug 18 13:09:19.468208 2026] [security2:error] [pid 167459:tid 167595] [client 20.127.136.245:23832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/404.php"] [unique_id "aoSDr2r_JutbFb-8svoTiQAAAZU"] [Tue Aug 18 13:09:19.470887 2026] [security2:error] [pid 167459:tid 167603] [client 20.151.109.219:20950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/10.php"] [unique_id "aoSDr2r_JutbFb-8svoTiwAAAZ0"] [Tue Aug 18 13:09:19.494388 2026] [security2:error] [pid 167459:tid 167678] [client 20.250.13.23:5434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/input.php"] [unique_id "aoSDr2r_JutbFb-8svoTkAAAAeg"] [Tue Aug 18 13:09:19.502466 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:10477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/disagrsxr.php"] [unique_id "aoSDr2r_JutbFb-8svoTkwAAAeE"] [Tue Aug 18 13:09:19.507647 2026] [security2:error] [pid 167459:tid 167692] [client 52.139.47.57:35284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/options.php"] [unique_id "aoSDr2r_JutbFb-8svoTlAAAAfY"] [Tue Aug 18 13:09:19.510078 2026] [security2:error] [pid 167459:tid 167680] [client 172.182.217.32:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/about.php"] [unique_id "aoSDr2r_JutbFb-8svoTlQAAAeo"] [Tue Aug 18 13:09:19.510873 2026] [security2:error] [pid 167459:tid 167675] [client 168.62.48.100:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDr2r_JutbFb-8svoTlgAAAeU"] [Tue Aug 18 13:09:19.513845 2026] [security2:error] [pid 167459:tid 167497] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/styles.php"] [unique_id "aoSDr2r_JutbFb-8svoTlwABtiU"] [Tue Aug 18 13:09:19.519234 2026] [security2:error] [pid 167459:tid 167622] [client 185.223.152.199:28013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.152.223.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eezy.site"] [uri "/wp-login.php"] [unique_id "aoSDr2r_JutbFb-8svoTagAAAbA"] [Tue Aug 18 13:09:19.568441 2026] [security2:error] [pid 167459:tid 167549] [remote 34.158.8.33:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.8.158.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/pi.php"] [unique_id "aoSDr2r_JutbFb-8svoTmgABv1k"] [Tue Aug 18 13:09:19.647865 2026] [security2:error] [pid 167459:tid 167645] [client 172.213.243.2:14364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sys.php"] [unique_id "aoSDr2r_JutbFb-8svoTrgAAAcc"] [Tue Aug 18 13:09:19.652076 2026] [security2:error] [pid 167459:tid 167615] [client 74.248.18.37:3083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/wso.php"] [unique_id "aoSDr2r_JutbFb-8svoTrwAAAak"] [Tue Aug 18 13:09:19.652506 2026] [security2:error] [pid 167459:tid 167479] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/server.php"] [unique_id "aoSDr2r_JutbFb-8svoTsQAB3xM"] [Tue Aug 18 13:09:19.725909 2026] [security2:error] [pid 167459:tid 167614] [client 158.101.5.31:60387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "docurso.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "aoSDr2r_JutbFb-8svoTvQAAAag"] [Tue Aug 18 13:09:19.789239 2026] [security2:error] [pid 167459:tid 167576] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/xinfo.php"] [unique_id "aoSDr2r_JutbFb-8svoTwwABoHQ"] [Tue Aug 18 13:09:19.792516 2026] [security2:error] [pid 167459:tid 167691] [client 74.249.206.207:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/img.php"] [unique_id "aoSDr2r_JutbFb-8svoTxAAAAfU"] [Tue Aug 18 13:09:19.846564 2026] [security2:error] [pid 167459:tid 167674] [client 20.1.169.243:8845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDr2r_JutbFb-8svoTygAAAeQ"] [Tue Aug 18 13:09:19.851591 2026] [security2:error] [pid 167459:tid 167707] [client 158.23.17.4:46801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/pu.php"] [unique_id "aoSDr2r_JutbFb-8svoTzAAAAgU"] [Tue Aug 18 13:09:19.858247 2026] [security2:error] [pid 167459:tid 167704] [client 168.62.48.100:16406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSDr2r_JutbFb-8svoTzQAAAgI"] [Tue Aug 18 13:09:19.900876 2026] [security2:error] [pid 167459:tid 167655] [client 20.1.169.243:9687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/domvf.php"] [unique_id "aoSDr2r_JutbFb-8svoTzgAAAdE"] [Tue Aug 18 13:09:19.909944 2026] [security2:error] [pid 167459:tid 167608] [client 213.35.127.232:58314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDr2r_JutbFb-8svoTzwAAAaI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:19.925257 2026] [security2:error] [pid 167459:tid 167648] [client 52.139.47.57:13699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/panel.php"] [unique_id "aoSDr2r_JutbFb-8svoT0AAAAco"] [Tue Aug 18 13:09:19.928378 2026] [security2:error] [pid 167459:tid 167607] [client 20.116.17.175:22767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/load.php"] [unique_id "aoSDr2r_JutbFb-8svoT0QAAAaE"] [Tue Aug 18 13:09:19.929197 2026] [security2:error] [pid 167459:tid 167478] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/sym.php"] [unique_id "aoSDr2r_JutbFb-8svoT0gACCRI"] [Tue Aug 18 13:09:19.959795 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:19.960075 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:19.992965 2026] [security2:error] [pid 167459:tid 167676] [client 20.250.13.23:34002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDr2r_JutbFb-8svoT1gAAAeY"] [Tue Aug 18 13:09:19.994629 2026] [security2:error] [pid 167459:tid 167710] [client 40.74.65.169:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/file1221.php"] [unique_id "aoSDr2r_JutbFb-8svoT1wAAAgg"] [Tue Aug 18 13:09:20.015161 2026] [security2:error] [pid 167459:tid 167684] [client 172.182.217.32:15600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/atomlib.php"] [unique_id "aoSDsGr_JutbFb-8svoT2QAAAe4"] [Tue Aug 18 13:09:20.016355 2026] [security2:error] [pid 167459:tid 167672] [client 4.232.151.198:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSDsGr_JutbFb-8svoT2gAAAeI"] [Tue Aug 18 13:09:20.053911 2026] [security2:error] [pid 167459:tid 167611] [client 20.100.169.31:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDsGr_JutbFb-8svoT3QAAAaU"] [Tue Aug 18 13:09:20.064537 2026] [security2:error] [pid 167459:tid 167681] [client 158.101.5.31:60585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.5.101.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "docurso.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "aoSDsGr_JutbFb-8svoT3gAAAes"] [Tue Aug 18 13:09:20.066443 2026] [security2:error] [pid 167459:tid 167532] [remote 20.65.69.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.69.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.fonsecashop.com.br"] [uri "/ye.php"] [unique_id "aoSDsGr_JutbFb-8svoT3wAB2Ug"] [Tue Aug 18 13:09:20.081858 2026] [security2:error] [pid 167459:tid 167620] [client 172.213.243.2:19863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/pp.php"] [unique_id "aoSDsGr_JutbFb-8svoT4AAAAa4"] [Tue Aug 18 13:09:20.100600 2026] [security2:error] [pid 167459:tid 167716] [client 20.171.51.14:60377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/fg.php"] [unique_id "aoSDsGr_JutbFb-8svoT4wAAAg4"] [Tue Aug 18 13:09:20.108439 2026] [security2:error] [pid 167459:tid 167590] [client 20.250.13.23:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/jquery.php"] [unique_id "aoSDsGr_JutbFb-8svoT5AAAAZA"] [Tue Aug 18 13:09:20.126964 2026] [security2:error] [pid 167459:tid 167609] [client 4.232.151.198:44079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/bthil.php"] [unique_id "aoSDsGr_JutbFb-8svoT5wAAAaM"] [Tue Aug 18 13:09:20.158605 2026] [security2:error] [pid 167459:tid 167670] [client 20.65.98.162:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/zi-936.php"] [unique_id "aoSDsGr_JutbFb-8svoT6gAAAeA"] [Tue Aug 18 13:09:20.169513 2026] [security2:error] [pid 167459:tid 167689] [client 158.23.17.4:32440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wx.php"] [unique_id "aoSDsGr_JutbFb-8svoT6wAAAfM"] [Tue Aug 18 13:09:20.171394 2026] [security2:error] [pid 167459:tid 167596] [client 114.119.135.37:20677] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.pinceisroma.com.br"] [uri "/es/cat/productos/rodillos-de-lana/lana_de_poliester/"] [unique_id "aoSDsGr_JutbFb-8svoT7AAAAZY"], referer: https://www.pinceisroma.com.br/es/cat/productos/rodillos-de-lana [Tue Aug 18 13:09:20.177916 2026] [security2:error] [pid 167459:tid 167595] [client 20.116.17.175:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/ws77.php"] [unique_id "aoSDsGr_JutbFb-8svoT7QAAAZU"] [Tue Aug 18 13:09:20.194926 2026] [security2:error] [pid 167459:tid 167714] [client 20.250.13.23:5421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/mah/function.php"] [unique_id "aoSDsGr_JutbFb-8svoT7gAAAgw"] [Tue Aug 18 13:09:20.228730 2026] [security2:error] [pid 167459:tid 167597] [client 74.248.133.44:51947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/radio.php"] [unique_id "aoSDsGr_JutbFb-8svoT8QAAAZc"] [Tue Aug 18 13:09:20.265404 2026] [security2:error] [pid 167459:tid 167699] [client 20.1.169.243:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/dropdown.php"] [unique_id "aoSDsGr_JutbFb-8svoT8wAAAf0"] [Tue Aug 18 13:09:20.266899 2026] [security2:error] [pid 167459:tid 167675] [client 168.62.48.100:16440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSDsGr_JutbFb-8svoT9AAAAeU"] [Tue Aug 18 13:09:20.271446 2026] [security2:error] [pid 167459:tid 167682] [client 20.100.169.31:3364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/about.php"] [unique_id "aoSDsGr_JutbFb-8svoT9QAAAew"] [Tue Aug 18 13:09:20.287392 2026] [security2:error] [pid 167459:tid 167639] [client 74.248.18.37:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSDsGr_JutbFb-8svoT9gAAAcE"] [Tue Aug 18 13:09:20.324619 2026] [security2:error] [pid 167459:tid 167637] [client 20.38.3.247:2449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/scxy.php"] [unique_id "aoSDsGr_JutbFb-8svoT-AAAAb8"] [Tue Aug 18 13:09:20.338952 2026] [security2:error] [pid 167459:tid 167703] [client 20.1.169.243:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/ws.php"] [unique_id "aoSDsGr_JutbFb-8svoT-QAAAgE"] [Tue Aug 18 13:09:20.412270 2026] [security2:error] [pid 167459:tid 167628] [client 52.139.47.57:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSDsGr_JutbFb-8svoT_QAAAbY"] [Tue Aug 18 13:09:20.489179 2026] [security2:error] [pid 167459:tid 167614] [client 172.213.243.2:14375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wqqs.php"] [unique_id "aoSDsGr_JutbFb-8svoUAwAAAag"] [Tue Aug 18 13:09:20.504425 2026] [security2:error] [pid 167459:tid 167591] [client 172.182.217.32:15579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/alfa-rex.php7"] [unique_id "aoSDsGr_JutbFb-8svoUBAAAAZE"] [Tue Aug 18 13:09:20.606421 2026] [security2:error] [pid 167459:tid 167629] [client 168.62.48.100:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSDsGr_JutbFb-8svoUCwAAAbc"] [Tue Aug 18 13:09:20.611520 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:20.611796 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:20.630815 2026] [security2:error] [pid 167459:tid 167661] [client 20.1.169.243:10476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSDsGr_JutbFb-8svoUDQAAAdc"] [Tue Aug 18 13:09:20.668768 2026] [security2:error] [pid 167459:tid 167669] [client 4.232.151.198:2693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/options-privacy.php"] [unique_id "aoSDsGr_JutbFb-8svoUEQAAAd8"] [Tue Aug 18 13:09:20.672821 2026] [security2:error] [pid 167459:tid 167656] [client 68.221.73.131:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/k.php"] [unique_id "aoSDsGr_JutbFb-8svoUEgAAAdI"] [Tue Aug 18 13:09:20.687987 2026] [security2:error] [pid 167459:tid 167651] [client 20.100.169.31:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSDsGr_JutbFb-8svoUEwAAAc0"] [Tue Aug 18 13:09:20.691301 2026] [security2:error] [pid 167459:tid 167708] [client 197.184.64.235:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsGr_JutbFb-8svoUFQAAAgY"] [Tue Aug 18 13:09:20.691425 2026] [security2:error] [pid 167459:tid 167708] [client 197.184.64.235:42699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsGr_JutbFb-8svoUFQAAAgY"] [Tue Aug 18 13:09:20.723234 2026] [security2:error] [pid 167459:tid 167684] [client 158.23.17.4:44697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/dj.php"] [unique_id "aoSDsGr_JutbFb-8svoUFgAAAe4"] [Tue Aug 18 13:09:20.740077 2026] [security2:error] [pid 167459:tid 167705] [client 20.104.100.201:13920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/8.php"] [unique_id "aoSDsGr_JutbFb-8svoUGQAAAgM"] [Tue Aug 18 13:09:20.742213 2026] [security2:error] [pid 167459:tid 167707] [client 20.1.169.243:9585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/wsa.php"] [unique_id "aoSDsGr_JutbFb-8svoUGgAAAgU"] [Tue Aug 18 13:09:20.744425 2026] [security2:error] [pid 167459:tid 167691] [client 20.250.13.23:5401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/media-new.php"] [unique_id "aoSDsGr_JutbFb-8svoUGwAAAfU"] [Tue Aug 18 13:09:20.746920 2026] [security2:error] [pid 167459:tid 167668] [client 138.36.100.162:42549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsGr_JutbFb-8svoUHAAAAd4"] [Tue Aug 18 13:09:20.746993 2026] [security2:error] [pid 167459:tid 167668] [client 138.36.100.162:42549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsGr_JutbFb-8svoUHAAAAd4"] [Tue Aug 18 13:09:20.782950 2026] [security2:error] [pid 167459:tid 167698] [client 20.250.13.23:58075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/gecko-new.php"] [unique_id "aoSDsGr_JutbFb-8svoUHwAAAfw"] [Tue Aug 18 13:09:20.784000 2026] [security2:error] [pid 167459:tid 167673] [client 20.38.3.247:21254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDsGr_JutbFb-8svoUIAAAAeM"] [Tue Aug 18 13:09:20.833366 2026] [security2:error] [pid 167459:tid 167676] [client 52.139.47.57:35279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSDsGr_JutbFb-8svoUIQAAAeY"] [Tue Aug 18 13:09:20.838800 2026] [security2:error] [pid 167459:tid 167648] [client 20.250.13.23:5426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/filter.php"] [unique_id "aoSDsGr_JutbFb-8svoUIgAAAco"] [Tue Aug 18 13:09:20.863964 2026] [authz_core:error] [pid 167459:tid 167539] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:20.864219 2026] [authz_core:error] [pid 167459:tid 167539] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:20.891670 2026] [security2:error] [pid 167459:tid 167653] [client 20.100.169.31:3488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/admin-header.php"] [unique_id "aoSDsGr_JutbFb-8svoUJwAAAc8"] [Tue Aug 18 13:09:20.910785 2026] [security2:error] [pid 167459:tid 167596] [client 172.213.243.2:19730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/clasa99.php"] [unique_id "aoSDsGr_JutbFb-8svoUKQAAAZY"] [Tue Aug 18 13:09:20.914501 2026] [security2:error] [pid 167459:tid 167712] [client 40.74.65.169:11688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/nox.php"] [unique_id "aoSDsGr_JutbFb-8svoUKgAAAgo"] [Tue Aug 18 13:09:20.917700 2026] [security2:error] [pid 167459:tid 167630] [client 74.248.18.37:3082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/info.php"] [unique_id "aoSDsGr_JutbFb-8svoUKwAAAbg"] [Tue Aug 18 13:09:20.921368 2026] [security2:error] [pid 167459:tid 167603] [client 168.62.48.100:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/rezor.php"] [unique_id "aoSDsGr_JutbFb-8svoULAAAAZ0"] [Tue Aug 18 13:09:20.934419 2026] [security2:error] [pid 167459:tid 167618] [client 213.35.127.232:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDsGr_JutbFb-8svoULQAAAaw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:20.993057 2026] [security2:error] [pid 167459:tid 167663] [client 172.182.217.32:15591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/b.php"] [unique_id "aoSDsGr_JutbFb-8svoUMAAAAdk"] [Tue Aug 18 13:09:21.017044 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/edit.php"] [unique_id "aoSDsWr_JutbFb-8svoUMQAAAbQ"] [Tue Aug 18 13:09:21.107911 2026] [security2:error] [pid 167459:tid 167619] [client 20.1.169.243:8848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/w.php"] [unique_id "aoSDsWr_JutbFb-8svoUNgAAAa0"] [Tue Aug 18 13:09:21.116425 2026] [cgid:error] [pid 167459:tid 167677] [client 4.232.151.198:21723] AH01265: stderr from /home3/lucascamargosadv/public_html/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:09:21.133619 2026] [security2:error] [pid 167459:tid 167605] [client 20.127.136.245:22168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/lite.php"] [unique_id "aoSDsWr_JutbFb-8svoUOgAAAZ8"] [Tue Aug 18 13:09:21.236991 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:21.237261 2026] [authz_core:error] [pid 167459:tid 167467] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:21.254387 2026] [security2:error] [pid 167459:tid 167654] [client 52.139.47.57:35285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSDsWr_JutbFb-8svoUPgAAAdA"] [Tue Aug 18 13:09:21.265822 2026] [security2:error] [pid 167459:tid 167623] [client 20.171.51.14:18201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ve.php"] [unique_id "aoSDsWr_JutbFb-8svoUPwAAAbE"] [Tue Aug 18 13:09:21.267356 2026] [security2:error] [pid 167459:tid 167591] [client 168.62.48.100:16460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/uploads/bypass.php"] [unique_id "aoSDsWr_JutbFb-8svoUQAAAAZE"] [Tue Aug 18 13:09:21.334111 2026] [security2:error] [pid 167459:tid 167629] [client 172.213.243.2:37116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/666.php"] [unique_id "aoSDsWr_JutbFb-8svoURAAAAbc"] [Tue Aug 18 13:09:21.338619 2026] [security2:error] [pid 167459:tid 167661] [client 158.23.17.4:20631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fa.php"] [unique_id "aoSDsWr_JutbFb-8svoURQAAAdc"] [Tue Aug 18 13:09:21.357547 2026] [security2:error] [pid 167459:tid 167640] [client 20.250.13.23:5392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSDsWr_JutbFb-8svoURwAAAcI"] [Tue Aug 18 13:09:21.364960 2026] [security2:error] [pid 167459:tid 167601] [client 20.38.3.247:21269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDsWr_JutbFb-8svoUSAAAAZs"] [Tue Aug 18 13:09:21.383276 2026] [security2:error] [pid 167459:tid 167614] [client 20.1.169.243:9716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/elp.php"] [unique_id "aoSDsWr_JutbFb-8svoUSQAAAag"] [Tue Aug 18 13:09:21.388708 2026] [security2:error] [pid 167459:tid 167612] [client 5.161.73.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jgbdominiosolucoes.com.br"] [uri "/index.php"] [unique_id "aoSDsGr_JutbFb-8svoT3AABpmk"], referer: https://jgbdominiosolucoes.com.br/ [Tue Aug 18 13:09:21.396585 2026] [security2:error] [pid 167459:tid 167656] [client 4.232.151.198:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/x.php"] [unique_id "aoSDsWr_JutbFb-8svoUSgAAAdI"] [Tue Aug 18 13:09:21.460308 2026] [security2:error] [pid 167459:tid 167631] [client 20.250.13.23:5400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/input.php"] [unique_id "aoSDsWr_JutbFb-8svoUTAAAAbk"] [Tue Aug 18 13:09:21.472925 2026] [security2:error] [pid 167459:tid 167607] [client 20.1.169.243:9583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/x.php"] [unique_id "aoSDsWr_JutbFb-8svoUTwAAAaE"] [Tue Aug 18 13:09:21.479398 2026] [security2:error] [pid 167459:tid 167632] [client 172.182.217.32:15750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/buy.php"] [unique_id "aoSDsWr_JutbFb-8svoUUAAAAbo"] [Tue Aug 18 13:09:21.484582 2026] [security2:error] [pid 167459:tid 167606] [client 4.232.151.198:45442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/options.php"] [unique_id "aoSDsWr_JutbFb-8svoUUQAAAaA"] [Tue Aug 18 13:09:21.530027 2026] [security2:error] [pid 167459:tid 167698] [client 20.100.169.31:2453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSDsWr_JutbFb-8svoUUwAAAfw"] [Tue Aug 18 13:09:21.538267 2026] [security2:error] [pid 167459:tid 167673] [client 20.151.109.219:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/te.php"] [unique_id "aoSDsWr_JutbFb-8svoUVAAAAeM"] [Tue Aug 18 13:09:21.550026 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:3349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/profile.php"] [unique_id "aoSDsWr_JutbFb-8svoUVQAAAfY"] [Tue Aug 18 13:09:21.567523 2026] [security2:error] [pid 167459:tid 167616] [client 20.100.169.31:3487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/admin.php"] [unique_id "aoSDsWr_JutbFb-8svoUVwAAAao"] [Tue Aug 18 13:09:21.629216 2026] [security2:error] [pid 167459:tid 167657] [client 20.65.98.162:51221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/dcsgumnm.php"] [unique_id "aoSDsWr_JutbFb-8svoUWgAAAdM"] [Tue Aug 18 13:09:21.629958 2026] [security2:error] [pid 167459:tid 167596] [client 40.74.65.169:11652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/akismet.php"] [unique_id "aoSDsWr_JutbFb-8svoUWwAAAZY"] [Tue Aug 18 13:09:21.667658 2026] [security2:error] [pid 167459:tid 167649] [client 168.62.48.100:16495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSDsWr_JutbFb-8svoUXAAAAcs"] [Tue Aug 18 13:09:21.698426 2026] [security2:error] [pid 167459:tid 167620] [client 52.139.47.57:18520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/test.php"] [unique_id "aoSDsWr_JutbFb-8svoUXQAAAa4"] [Tue Aug 18 13:09:21.734061 2026] [security2:error] [pid 167459:tid 167713] [client 196.12.128.158:56537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDsWr_JutbFb-8svoUYAAAAgs"] [Tue Aug 18 13:09:21.734162 2026] [security2:error] [pid 167459:tid 167713] [client 196.12.128.158:56537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDsWr_JutbFb-8svoUYAAAAgs"] [Tue Aug 18 13:09:21.748185 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:10198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/email.php"] [unique_id "aoSDsWr_JutbFb-8svoUYgAAAfM"] [Tue Aug 18 13:09:21.752810 2026] [security2:error] [pid 167459:tid 167682] [client 172.213.243.2:14768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/thui.php"] [unique_id "aoSDsWr_JutbFb-8svoUYwAAAew"] [Tue Aug 18 13:09:21.765240 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:21.765517 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:21.793725 2026] [security2:error] [pid 167459:tid 167615] [client 97.74.89.162:41200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "maxhost.com.br"] [uri "/"] [unique_id "aoSDsWr_JutbFb-8svoUZgAAAak"] [Tue Aug 18 13:09:21.834815 2026] [security2:error] [pid 167459:tid 167605] [client 20.116.17.175:52589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/read.php"] [unique_id "aoSDsWr_JutbFb-8svoUZwAAAZ8"] [Tue Aug 18 13:09:21.843543 2026] [security2:error] [pid 167459:tid 167702] [client 158.23.17.4:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/main.php"] [unique_id "aoSDsWr_JutbFb-8svoUaAAAAgA"] [Tue Aug 18 13:09:21.843802 2026] [security2:error] [pid 167459:tid 167633] [client 20.104.100.201:13859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/images.php"] [unique_id "aoSDsWr_JutbFb-8svoUaQAAAbs"] [Tue Aug 18 13:09:21.859926 2026] [security2:error] [pid 167459:tid 167597] [client 20.1.169.243:8923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/xx.php"] [unique_id "aoSDsWr_JutbFb-8svoUagAAAZc"] [Tue Aug 18 13:09:21.924238 2026] [security2:error] [pid 167459:tid 167709] [client 20.38.3.247:16036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/blurbs.php"] [unique_id "aoSDsWr_JutbFb-8svoUcQAAAgc"] [Tue Aug 18 13:09:21.949353 2026] [security2:error] [pid 167459:tid 167670] [client 213.35.127.232:58764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDsWr_JutbFb-8svoUdAAAAeA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:21.968379 2026] [security2:error] [pid 167459:tid 167686] [client 172.182.217.32:15613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/bless.php"] [unique_id "aoSDsWr_JutbFb-8svoUdQAAAfA"] [Tue Aug 18 13:09:21.970703 2026] [security2:error] [pid 167459:tid 167622] [client 74.248.133.44:39233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSDsWr_JutbFb-8svoUdwAAAbA"] [Tue Aug 18 13:09:21.974772 2026] [security2:error] [pid 167459:tid 167662] [client 20.250.13.23:18196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSDsWr_JutbFb-8svoUeAAAAdg"] [Tue Aug 18 13:09:22.049023 2026] [security2:error] [pid 167459:tid 167629] [client 20.171.51.14:36107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ia.php"] [unique_id "aoSDsmr_JutbFb-8svoUewAAAbc"] [Tue Aug 18 13:09:22.066707 2026] [security2:error] [pid 167459:tid 167640] [client 68.155.154.236:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/oivcl.php"] [unique_id "aoSDsmr_JutbFb-8svoUfgAAAcI"] [Tue Aug 18 13:09:22.087785 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:44689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/fb.php"] [unique_id "aoSDsmr_JutbFb-8svoUfwAAAcQ"] [Tue Aug 18 13:09:22.106863 2026] [security2:error] [pid 167459:tid 167669] [client 168.62.48.100:16494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/index/function.php"] [unique_id "aoSDsmr_JutbFb-8svoUgAAAAd8"] [Tue Aug 18 13:09:22.111456 2026] [security2:error] [pid 167459:tid 167650] [client 52.139.47.57:18528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSDsmr_JutbFb-8svoUgQAAAcw"] [Tue Aug 18 13:09:22.116038 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:16862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/jquery.php"] [unique_id "aoSDsmr_JutbFb-8svoUggAAAbY"] [Tue Aug 18 13:09:22.128200 2026] [security2:error] [pid 167459:tid 167690] [client 4.232.151.198:45495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/plugin-install.php"] [unique_id "aoSDsmr_JutbFb-8svoUgwAAAfQ"] [Tue Aug 18 13:09:22.140310 2026] [security2:error] [pid 167459:tid 167634] [client 20.1.169.243:10218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/error.php"] [unique_id "aoSDsmr_JutbFb-8svoUhAAAAbw"] [Tue Aug 18 13:09:22.173973 2026] [security2:error] [pid 167459:tid 167631] [client 172.213.243.2:48324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/agg.php"] [unique_id "aoSDsmr_JutbFb-8svoUhgAAAbk"] [Tue Aug 18 13:09:22.188553 2026] [security2:error] [pid 167459:tid 167674] [client 20.100.169.31:18983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/content.php"] [unique_id "aoSDsmr_JutbFb-8svoUhwAAAeQ"] [Tue Aug 18 13:09:22.226305 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsmr_JutbFb-8svoUiQAAAZs"] [Tue Aug 18 13:09:22.244115 2026] [security2:error] [pid 167459:tid 167685] [client 20.250.13.23:50146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.giacomotors.com.br"] [uri "/NewFile.php"] [unique_id "aoSDsmr_JutbFb-8svoUigAAAe8"] [Tue Aug 18 13:09:22.371549 2026] [security2:error] [pid 167459:tid 167600] [client 74.248.18.37:3121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/sx.php"] [unique_id "aoSDsmr_JutbFb-8svoUkQAAAZo"] [Tue Aug 18 13:09:22.374849 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:22.375128 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:22.415054 2026] [security2:error] [pid 167459:tid 167596] [client 20.100.169.31:2907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSDsmr_JutbFb-8svoUlAAAAZY"] [Tue Aug 18 13:09:22.441870 2026] [security2:error] [pid 167459:tid 167630] [client 158.23.17.4:56544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ga.php"] [unique_id "aoSDsmr_JutbFb-8svoUlgAAAbg"] [Tue Aug 18 13:09:22.450288 2026] [security2:error] [pid 167459:tid 167618] [client 20.127.136.245:22148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/lock360.php"] [unique_id "aoSDsmr_JutbFb-8svoUlwAAAaw"] [Tue Aug 18 13:09:22.454760 2026] [security2:error] [pid 167459:tid 167691] [client 172.182.217.32:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDsmr_JutbFb-8svoUmAAAAfU"] [Tue Aug 18 13:09:22.458563 2026] [security2:error] [pid 167459:tid 167666] [client 40.74.65.169:11663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/admin.php"] [unique_id "aoSDsmr_JutbFb-8svoUmQAAAdw"] [Tue Aug 18 13:09:22.472248 2026] [security2:error] [pid 167459:tid 167714] [client 20.116.17.175:22664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_cdd9.php"] [unique_id "aoSDsmr_JutbFb-8svoUmgAAAgw"] [Tue Aug 18 13:09:22.504946 2026] [security2:error] [pid 167459:tid 167594] [client 20.1.169.243:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/f35.php"] [unique_id "aoSDsmr_JutbFb-8svoUmwAAAZQ"] [Tue Aug 18 13:09:22.513533 2026] [security2:error] [pid 167459:tid 167648] [client 168.62.48.100:16496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSDsmr_JutbFb-8svoUnAAAAco"] [Tue Aug 18 13:09:22.522215 2026] [security2:error] [pid 167459:tid 167716] [client 52.139.47.57:35264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSDsmr_JutbFb-8svoUngAAAg4"] [Tue Aug 18 13:09:22.592452 2026] [security2:error] [pid 167459:tid 167649] [client 20.1.169.243:8937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hotelfontanaunai.com.br"] [uri "/y.php"] [unique_id "aoSDsmr_JutbFb-8svoUoQAAAcs"] [Tue Aug 18 13:09:22.594108 2026] [security2:error] [pid 167459:tid 167687] [client 20.250.13.23:16878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSDsmr_JutbFb-8svoUogAAAfE"] [Tue Aug 18 13:09:22.603079 2026] [security2:error] [pid 167459:tid 167706] [client 172.213.243.2:14383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/erty.php"] [unique_id "aoSDsmr_JutbFb-8svoUowAAAgQ"] [Tue Aug 18 13:09:22.622561 2026] [security2:error] [pid 167459:tid 167616] [client 74.248.18.37:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/goods.php"] [unique_id "aoSDsmr_JutbFb-8svoUpQAAAao"] [Tue Aug 18 13:09:22.626232 2026] [security2:error] [pid 167459:tid 167540] [remote 47.89.174.181:47880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "belleimultimarcas.com.br"] [uri "/.env"] [unique_id "aoSDsmr_JutbFb-8svoUpgAB2VA"] [Tue Aug 18 13:09:22.647956 2026] [security2:error] [pid 167459:tid 167688] [client 49.145.211.146:12209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsmr_JutbFb-8svoUqAAAAfI"] [Tue Aug 18 13:09:22.648081 2026] [security2:error] [pid 167459:tid 167688] [client 49.145.211.146:12209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDsmr_JutbFb-8svoUqAAAAfI"] [Tue Aug 18 13:09:22.676605 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:22.677036 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:22.680578 2026] [security2:error] [pid 167459:tid 167665] [client 20.65.98.162:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/php.php"] [unique_id "aoSDsmr_JutbFb-8svoUqwAAAds"] [Tue Aug 18 13:09:22.729768 2026] [security2:error] [pid 167459:tid 167626] [client 20.250.13.23:5385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/media-new.php"] [unique_id "aoSDsmr_JutbFb-8svoUrgAAAbQ"] [Tue Aug 18 13:09:22.808522 2026] [security2:error] [pid 167459:tid 167599] [client 20.100.169.31:3496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/index.php"] [unique_id "aoSDsmr_JutbFb-8svoUsQAAAZk"] [Tue Aug 18 13:09:22.834073 2026] [security2:error] [pid 167459:tid 167710] [client 168.62.48.100:16451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/Cachex.php"] [unique_id "aoSDsmr_JutbFb-8svoUtQAAAgg"] [Tue Aug 18 13:09:22.868395 2026] [security2:error] [pid 167459:tid 167702] [client 4.232.151.198:45462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/wp-cron.php"] [unique_id "aoSDsmr_JutbFb-8svoUtgAAAgA"] [Tue Aug 18 13:09:22.870302 2026] [security2:error] [pid 167459:tid 167622] [client 20.1.169.243:10248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/f35.update.php"] [unique_id "aoSDsmr_JutbFb-8svoUtwAAAbA"] [Tue Aug 18 13:09:22.904153 2026] [security2:error] [pid 167459:tid 167592] [client 213.202.253.4:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/postnews.php"] [unique_id "aoSDsmr_JutbFb-8svoUuQAAAZI"], referer: www.google.com [Tue Aug 18 13:09:22.936864 2026] [security2:error] [pid 167459:tid 167627] [client 68.155.154.236:25370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/zugvi.php"] [unique_id "aoSDsmr_JutbFb-8svoUugAAAbU"] [Tue Aug 18 13:09:22.943276 2026] [security2:error] [pid 167459:tid 167636] [client 172.182.217.32:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/cache.php"] [unique_id "aoSDsmr_JutbFb-8svoUuwAAAb4"] [Tue Aug 18 13:09:22.954313 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:13700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSDsmr_JutbFb-8svoUvAAAAfQ"] [Tue Aug 18 13:09:22.966758 2026] [security2:error] [pid 167459:tid 167703] [client 213.35.127.232:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDsmr_JutbFb-8svoUvQAAAgE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:22.975623 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:22.975890 2026] [authz_core:error] [pid 167459:tid 167551] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:23.024023 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.18.37:3386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDs2r_JutbFb-8svoUwAAAAd8"] [Tue Aug 18 13:09:23.027398 2026] [security2:error] [pid 167459:tid 167604] [client 172.213.243.2:19581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/mini.php"] [unique_id "aoSDs2r_JutbFb-8svoUwQAAAZ4"] [Tue Aug 18 13:09:23.041637 2026] [security2:error] [pid 167459:tid 167651] [client 20.100.169.31:2923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSDs2r_JutbFb-8svoUwgAAAc0"] [Tue Aug 18 13:09:23.053074 2026] [security2:error] [pid 167459:tid 167692] [client 158.23.17.4:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ry.php"] [unique_id "aoSDs2r_JutbFb-8svoUwwAAAfY"] [Tue Aug 18 13:09:23.057199 2026] [security2:error] [pid 167459:tid 167662] [client 74.248.133.44:30078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSDs2r_JutbFb-8svoUxAAAAdg"] [Tue Aug 18 13:09:23.082120 2026] [security2:error] [pid 167459:tid 167613] [client 74.249.206.207:14958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/222.php"] [unique_id "aoSDs2r_JutbFb-8svoUxgAAAac"] [Tue Aug 18 13:09:23.112368 2026] [security2:error] [pid 167459:tid 167712] [client 4.232.151.198:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/index/function.php"] [unique_id "aoSDs2r_JutbFb-8svoUyAAAAgo"] [Tue Aug 18 13:09:23.163535 2026] [security2:error] [pid 167459:tid 167630] [client 20.104.100.201:13913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/a.php"] [unique_id "aoSDs2r_JutbFb-8svoUygAAAbg"] [Tue Aug 18 13:09:23.203998 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:16861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSDs2r_JutbFb-8svoU0QAAAgU"] [Tue Aug 18 13:09:23.224279 2026] [security2:error] [pid 167459:tid 167715] [client 158.23.17.4:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gw.php"] [unique_id "aoSDs2r_JutbFb-8svoU0gAAAg0"] [Tue Aug 18 13:09:23.236307 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:10237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/file.php"] [unique_id "aoSDs2r_JutbFb-8svoU0wAAAgI"] [Tue Aug 18 13:09:23.280184 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:23.280445 2026] [authz_core:error] [pid 167459:tid 167530] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:23.281635 2026] [security2:error] [pid 167459:tid 167667] [client 168.62.48.100:16462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSDs2r_JutbFb-8svoU1gAAAd0"] [Tue Aug 18 13:09:23.367526 2026] [security2:error] [pid 167459:tid 167612] [client 52.139.47.57:18500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-login.php"] [unique_id "aoSDs2r_JutbFb-8svoU3AAAAaY"] [Tue Aug 18 13:09:23.383449 2026] [security2:error] [pid 167459:tid 167620] [client 20.38.3.247:44380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/bajah.php"] [unique_id "aoSDs2r_JutbFb-8svoU3QAAAa4"] [Tue Aug 18 13:09:23.430566 2026] [security2:error] [pid 167459:tid 167658] [client 172.182.217.32:15608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/content.php"] [unique_id "aoSDs2r_JutbFb-8svoU4QAAAdQ"] [Tue Aug 18 13:09:23.439808 2026] [security2:error] [pid 167459:tid 167591] [client 172.213.243.2:18603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sid3.php"] [unique_id "aoSDs2r_JutbFb-8svoU4gAAAZE"] [Tue Aug 18 13:09:23.455809 2026] [security2:error] [pid 167459:tid 167648] [client 20.100.169.31:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSDs2r_JutbFb-8svoU4wAAAco"] [Tue Aug 18 13:09:23.460167 2026] [security2:error] [pid 167459:tid 167679] [client 40.74.65.169:11661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.clinicagastrolapa.com.br"] [uri "/ajax.php"] [unique_id "aoSDs2r_JutbFb-8svoU5QAAAek"] [Tue Aug 18 13:09:23.472942 2026] [security2:error] [pid 167459:tid 167706] [client 20.250.13.23:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSDs2r_JutbFb-8svoU5gAAAgQ"] [Tue Aug 18 13:09:23.546998 2026] [security2:error] [pid 167459:tid 167645] [client 4.232.151.198:45487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSDs2r_JutbFb-8svoU6AAAAcc"] [Tue Aug 18 13:09:23.558732 2026] [security2:error] [pid 167459:tid 167643] [client 68.155.154.236:25404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wsrer.php"] [unique_id "aoSDs2r_JutbFb-8svoU7QAAAcU"] [Tue Aug 18 13:09:23.563844 2026] [security2:error] [pid 167459:tid 167537] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDs2r_JutbFb-8svoU7gAB8U0"] [Tue Aug 18 13:09:23.563987 2026] [security2:error] [pid 167459:tid 167687] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDs2r_JutbFb-8svoU7gAB8U0"] [Tue Aug 18 13:09:23.576927 2026] [security2:error] [pid 167459:tid 167622] [client 20.65.98.162:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/sf.php"] [unique_id "aoSDs2r_JutbFb-8svoU8AAAAbA"] [Tue Aug 18 13:09:23.602355 2026] [security2:error] [pid 167459:tid 167700] [client 20.1.169.243:10238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/file2.php"] [unique_id "aoSDs2r_JutbFb-8svoU8QAAAf4"] [Tue Aug 18 13:09:23.654581 2026] [security2:error] [pid 167459:tid 167686] [client 74.248.18.37:25349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDs2r_JutbFb-8svoU9wAAAfA"] [Tue Aug 18 13:09:23.678127 2026] [security2:error] [pid 167459:tid 167673] [client 20.171.51.14:2617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kn.php"] [unique_id "aoSDs2r_JutbFb-8svoU-AAAAeM"] [Tue Aug 18 13:09:23.701547 2026] [security2:error] [pid 167459:tid 167593] [client 20.100.169.31:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSDs2r_JutbFb-8svoU-wAAAZM"] [Tue Aug 18 13:09:23.714247 2026] [security2:error] [pid 167459:tid 167637] [client 49.37.150.8:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDs2r_JutbFb-8svoU_AAAAb8"] [Tue Aug 18 13:09:23.716465 2026] [security2:error] [pid 167459:tid 167637] [client 49.37.150.8:59513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDs2r_JutbFb-8svoU_AAAAb8"] [Tue Aug 18 13:09:23.724878 2026] [security2:error] [pid 167459:tid 167604] [client 168.62.48.100:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-2019.php"] [unique_id "aoSDs2r_JutbFb-8svoU_QAAAZ4"] [Tue Aug 18 13:09:23.779796 2026] [security2:error] [pid 167459:tid 167703] [client 52.139.47.57:18527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSDs2r_JutbFb-8svoVAgAAAgE"] [Tue Aug 18 13:09:23.820762 2026] [security2:error] [pid 167459:tid 167632] [client 20.250.13.23:16860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/ebs.php7"] [unique_id "aoSDs2r_JutbFb-8svoVBAAAAbo"] [Tue Aug 18 13:09:23.836604 2026] [security2:error] [pid 167459:tid 167641] [client 158.23.17.4:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/wb.php"] [unique_id "aoSDs2r_JutbFb-8svoVBQAAAcM"] [Tue Aug 18 13:09:23.847270 2026] [security2:error] [pid 167459:tid 167636] [client 4.232.151.198:31347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/aaa.php"] [unique_id "aoSDs2r_JutbFb-8svoVBwAAAb4"] [Tue Aug 18 13:09:23.853578 2026] [security2:error] [pid 167459:tid 167693] [client 172.213.243.2:14445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/moon.php"] [unique_id "aoSDs2r_JutbFb-8svoVCQAAAfc"] [Tue Aug 18 13:09:23.856687 2026] [security2:error] [pid 167459:tid 167666] [client 20.104.100.201:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSDs2r_JutbFb-8svoVCgAAAdw"] [Tue Aug 18 13:09:23.874157 2026] [security2:error] [pid 167459:tid 167715] [client 20.116.17.175:52877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/albin.php"] [unique_id "aoSDs2r_JutbFb-8svoVCwAAAg0"] [Tue Aug 18 13:09:23.881969 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:23.882239 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:23.915612 2026] [security2:error] [pid 167459:tid 167662] [client 172.182.217.32:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDs2r_JutbFb-8svoVEgAAAdg"] [Tue Aug 18 13:09:23.970796 2026] [security2:error] [pid 167459:tid 167691] [client 20.1.169.243:9671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/files.php"] [unique_id "aoSDs2r_JutbFb-8svoVFAAAAfU"] [Tue Aug 18 13:09:23.979648 2026] [security2:error] [pid 167459:tid 167601] [client 213.35.127.232:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDs2r_JutbFb-8svoVFgAAAZs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:24.081786 2026] [security2:error] [pid 167459:tid 167713] [client 20.100.169.31:3506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDtGr_JutbFb-8svoVHAAAAgs"] [Tue Aug 18 13:09:24.087801 2026] [security2:error] [pid 167459:tid 167716] [client 20.250.13.23:18159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSDtGr_JutbFb-8svoVHQAAAg4"] [Tue Aug 18 13:09:24.093112 2026] [security2:error] [pid 167459:tid 167608] [client 158.23.17.4:38342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/sw.php"] [unique_id "aoSDtGr_JutbFb-8svoVIQAAAaI"] [Tue Aug 18 13:09:24.112153 2026] [security2:error] [pid 167459:tid 167642] [client 168.62.48.100:16454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSDtGr_JutbFb-8svoVIgAAAcQ"] [Tue Aug 18 13:09:24.131562 2026] [security2:error] [pid 167459:tid 167474] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.aws/config"] [unique_id "aoSDtGr_JutbFb-8svoVJAAB8Q4"] [Tue Aug 18 13:09:24.135386 2026] [security2:error] [pid 167459:tid 167499] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/z9x8c7v6b5-debug-trigger-cpcalendars.jotamotos.com.br"] [unique_id "aoSDtGr_JutbFb-8svoVJQABuSc"] [Tue Aug 18 13:09:24.135573 2026] [security2:error] [pid 167459:tid 167563] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/rclone.conf"] [unique_id "aoSDtGr_JutbFb-8svoVJgABuWc"] [Tue Aug 18 13:09:24.140191 2026] [security2:error] [pid 167459:tid 167567] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.git/config"] [unique_id "aoSDtGr_JutbFb-8svoVJwABoWs"] [Tue Aug 18 13:09:24.140295 2026] [security2:error] [pid 167459:tid 167583] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.aws/credentials"] [unique_id "aoSDtGr_JutbFb-8svoVKAABoXs"] [Tue Aug 18 13:09:24.149482 2026] [security2:error] [pid 167459:tid 167509] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/wp-json"] [unique_id "aoSDtGr_JutbFb-8svoVKQACADE"] [Tue Aug 18 13:09:24.187807 2026] [authz_core:error] [pid 167459:tid 167491] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:24.188266 2026] [authz_core:error] [pid 167459:tid 167491] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:24.209911 2026] [security2:error] [pid 167459:tid 167619] [client 52.139.47.57:35307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSDtGr_JutbFb-8svoVLQAAAa0"] [Tue Aug 18 13:09:24.238966 2026] [security2:error] [pid 167459:tid 167477] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.info.php"] [unique_id "aoSDtGr_JutbFb-8svoVMwABzBE"] [Tue Aug 18 13:09:24.262532 2026] [security2:error] [pid 167459:tid 167686] [client 172.213.243.2:18610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ms.php"] [unique_id "aoSDtGr_JutbFb-8svoVPwAAAfA"] [Tue Aug 18 13:09:24.277922 2026] [security2:error] [pid 167459:tid 167487] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.gitconfig"] [unique_id "aoSDtGr_JutbFb-8svoVWwAB_Bs"] [Tue Aug 18 13:09:24.281098 2026] [security2:error] [pid 167459:tid 167673] [client 20.127.136.245:13811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSDtGr_JutbFb-8svoVXAAAAeM"] [Tue Aug 18 13:09:24.292869 2026] [security2:error] [pid 167459:tid 167573] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.git/HEAD"] [unique_id "aoSDtGr_JutbFb-8svoVXQABk3E"] [Tue Aug 18 13:09:24.299506 2026] [security2:error] [pid 167459:tid 167462] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "aoSDtGr_JutbFb-8svoVXgAB6wI"] [Tue Aug 18 13:09:24.301955 2026] [security2:error] [pid 167459:tid 167488] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.git-credentials"] [unique_id "aoSDtGr_JutbFb-8svoVXwABvxw"] [Tue Aug 18 13:09:24.309793 2026] [security2:error] [pid 167459:tid 167500] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "aoSDtGr_JutbFb-8svoVYAAB3yg"] [Tue Aug 18 13:09:24.316348 2026] [security2:error] [pid 167459:tid 167460] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env"] [unique_id "aoSDtGr_JutbFb-8svoVYQAB9gA"] [Tue Aug 18 13:09:24.322740 2026] [security2:error] [pid 167459:tid 167661] [client 4.232.151.198:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-admin/wp-signup.php"] [unique_id "aoSDtGr_JutbFb-8svoVYwAAAdc"] [Tue Aug 18 13:09:24.356385 2026] [security2:error] [pid 167459:tid 167613] [client 68.155.154.236:25363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/ucpfr.php"] [unique_id "aoSDtGr_JutbFb-8svoVZgAAAac"] [Tue Aug 18 13:09:24.362775 2026] [security2:error] [pid 167459:tid 167653] [client 74.248.133.44:51942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/u.php"] [unique_id "aoSDtGr_JutbFb-8svoVZwAAAc8"] [Tue Aug 18 13:09:24.365125 2026] [security2:error] [pid 167459:tid 167606] [client 20.1.169.243:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/fix.php"] [unique_id "aoSDtGr_JutbFb-8svoVaAAAAaA"] [Tue Aug 18 13:09:24.373102 2026] [security2:error] [pid 167459:tid 167540] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/about.php"] [unique_id "aoSDtGr_JutbFb-8svoVaQABo1A"] [Tue Aug 18 13:09:24.403463 2026] [security2:error] [pid 167459:tid 167701] [client 172.182.217.32:15749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/css.php"] [unique_id "aoSDtGr_JutbFb-8svoVbQAAAf8"] [Tue Aug 18 13:09:24.404522 2026] [security2:error] [pid 167459:tid 167667] [client 86.120.159.145:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtGr_JutbFb-8svoVbgAAAd0"] [Tue Aug 18 13:09:24.404791 2026] [security2:error] [pid 167459:tid 167667] [client 86.120.159.145:60002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtGr_JutbFb-8svoVbgAAAd0"] [Tue Aug 18 13:09:24.417049 2026] [security2:error] [pid 167459:tid 167644] [client 168.62.48.100:16504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/.cache/x.php"] [unique_id "aoSDtGr_JutbFb-8svoVbwAAAcY"] [Tue Aug 18 13:09:24.434868 2026] [security2:error] [pid 167459:tid 167526] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.production"] [unique_id "aoSDtGr_JutbFb-8svoVlAACBUI"] [Tue Aug 18 13:09:24.439761 2026] [security2:error] [pid 167459:tid 167478] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.example"] [unique_id "aoSDtGr_JutbFb-8svoVlQACBRI"] [Tue Aug 18 13:09:24.444385 2026] [security2:error] [pid 167459:tid 167683] [client 20.250.13.23:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSDtGr_JutbFb-8svoVnQAAAe0"] [Tue Aug 18 13:09:24.445454 2026] [security2:error] [pid 167459:tid 167502] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.backup"] [unique_id "aoSDtGr_JutbFb-8svoVngAB6io"] [Tue Aug 18 13:09:24.458104 2026] [security2:error] [pid 167459:tid 167527] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.local"] [unique_id "aoSDtGr_JutbFb-8svoVqQAB4UM"] [Tue Aug 18 13:09:24.458867 2026] [security2:error] [pid 167459:tid 167532] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.bak"] [unique_id "aoSDtGr_JutbFb-8svoVqgAB7Eg"] [Tue Aug 18 13:09:24.476191 2026] [security2:error] [pid 167459:tid 167561] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.old"] [unique_id "aoSDtGr_JutbFb-8svoVswAB9WU"] [Tue Aug 18 13:09:24.483779 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:24.484060 2026] [authz_core:error] [pid 167459:tid 167509] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:24.507453 2026] [security2:error] [pid 167459:tid 167646] [client 20.38.3.247:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/domvf.php"] [unique_id "aoSDtGr_JutbFb-8svoVuAAAAcg"] [Tue Aug 18 13:09:24.542176 2026] [security2:error] [pid 167459:tid 167638] [client 74.248.18.37:25390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDtGr_JutbFb-8svoVuwAAAcA"] [Tue Aug 18 13:09:24.580346 2026] [authz_core:error] [pid 167459:tid 167538] [remote 57.141.22.8:41506] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:24.580602 2026] [authz_core:error] [pid 167459:tid 167538] [remote 57.141.22.8:41506] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:24.584210 2026] [security2:error] [pid 167459:tid 167477] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/admin/.env"] [unique_id "aoSDtGr_JutbFb-8svoVvwAB0RE"] [Tue Aug 18 13:09:24.591568 2026] [security2:error] [pid 167459:tid 167503] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/backend/.env"] [unique_id "aoSDtGr_JutbFb-8svoVwQAB0Ss"] [Tue Aug 18 13:09:24.595973 2026] [security2:error] [pid 167459:tid 167473] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/.env"] [unique_id "aoSDtGr_JutbFb-8svoVwwABlA0"] [Tue Aug 18 13:09:24.604608 2026] [security2:error] [pid 167459:tid 167591] [client 20.116.17.175:41491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ty.php"] [unique_id "aoSDtGr_JutbFb-8svoVxAAAAZE"] [Tue Aug 18 13:09:24.614620 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:49729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/a.php"] [unique_id "aoSDtGr_JutbFb-8svoVxgAAAec"] [Tue Aug 18 13:09:24.621528 2026] [security2:error] [pid 167459:tid 167601] [client 52.139.47.57:9895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/002.php"] [unique_id "aoSDtGr_JutbFb-8svoVxwAAAZs"] [Tue Aug 18 13:09:24.624682 2026] [security2:error] [pid 167459:tid 167554] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/.env"] [unique_id "aoSDtGr_JutbFb-8svoVyAAByl4"] [Tue Aug 18 13:09:24.624686 2026] [security2:error] [pid 167459:tid 167548] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/secrets.json"] [unique_id "aoSDtGr_JutbFb-8svoVyQABylg"] [Tue Aug 18 13:09:24.627443 2026] [security2:error] [pid 167459:tid 167578] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/secrets.yml"] [unique_id "aoSDtGr_JutbFb-8svoVygAB6XY"] [Tue Aug 18 13:09:24.651591 2026] [security2:error] [pid 167459:tid 167508] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "aoSDtGr_JutbFb-8svoVywACBDA"] [Tue Aug 18 13:09:24.675373 2026] [security2:error] [pid 167459:tid 167710] [client 172.213.243.2:37091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wsws.php"] [unique_id "aoSDtGr_JutbFb-8svoVzAAAAgg"] [Tue Aug 18 13:09:24.691548 2026] [security2:error] [pid 167459:tid 167687] [client 158.23.17.4:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gc.php"] [unique_id "aoSDtGr_JutbFb-8svoVzQAAAfE"] [Tue Aug 18 13:09:24.706637 2026] [security2:error] [pid 167459:tid 167712] [client 20.100.169.31:18982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDtGr_JutbFb-8svoVzwAAAgo"] [Tue Aug 18 13:09:24.733138 2026] [security2:error] [pid 167459:tid 167713] [client 20.1.169.243:10235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/fm.php"] [unique_id "aoSDtGr_JutbFb-8svoV0gAAAgs"] [Tue Aug 18 13:09:24.733499 2026] [security2:error] [pid 167459:tid 167711] [client 20.250.13.23:18144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/import.php"] [unique_id "aoSDtGr_JutbFb-8svoV0QAAAgk"] [Tue Aug 18 13:09:24.734926 2026] [security2:error] [pid 167459:tid 167602] [client 168.62.48.100:16401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSDtGr_JutbFb-8svoV0wAAAZw"] [Tue Aug 18 13:09:24.739666 2026] [security2:error] [pid 167459:tid 167580] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/staging/.env"] [unique_id "aoSDtGr_JutbFb-8svoV1QABkng"] [Tue Aug 18 13:09:24.744616 2026] [security2:error] [pid 167459:tid 167619] [client 20.100.169.31:2597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSDtGr_JutbFb-8svoV1gAAAa0"] [Tue Aug 18 13:09:24.748131 2026] [security2:error] [pid 167459:tid 167582] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/service-account.json"] [unique_id "aoSDtGr_JutbFb-8svoV1wACDHo"] [Tue Aug 18 13:09:24.760115 2026] [security2:error] [pid 167459:tid 167505] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/docker/.env"] [unique_id "aoSDtGr_JutbFb-8svoV2gABzC0"] [Tue Aug 18 13:09:24.769468 2026] [security2:error] [pid 167459:tid 167529] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/production/.env"] [unique_id "aoSDtGr_JutbFb-8svoV3QABqEU"] [Tue Aug 18 13:09:24.770868 2026] [security2:error] [pid 167459:tid 167565] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.production.bak"] [unique_id "aoSDtGr_JutbFb-8svoV3gAB42k"] [Tue Aug 18 13:09:24.771420 2026] [security2:error] [pid 167459:tid 167634] [client 5.31.227.224:1452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtGr_JutbFb-8svoV3wAAAbw"] [Tue Aug 18 13:09:24.772164 2026] [security2:error] [pid 167459:tid 167463] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.docker"] [unique_id "aoSDtGr_JutbFb-8svoV4AAByQM"] [Tue Aug 18 13:09:24.775814 2026] [security2:error] [pid 167459:tid 167634] [client 5.31.227.224:1452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtGr_JutbFb-8svoV3wAAAbw"] [Tue Aug 18 13:09:24.786646 2026] [security2:error] [pid 167459:tid 167558] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "aoSDtGr_JutbFb-8svoV4wACBmI"] [Tue Aug 18 13:09:24.899961 2026] [security2:error] [pid 167459:tid 167471] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fabispinazolapilates.com.br"] [uri "/wp-login.php"] [unique_id "aoSDtGr_JutbFb-8svoV7AABpws"] [Tue Aug 18 13:09:24.902854 2026] [security2:error] [pid 167459:tid 167498] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.prod.bak"] [unique_id "aoSDtGr_JutbFb-8svoV7QABzyY"] [Tue Aug 18 13:09:24.905103 2026] [security2:error] [pid 167459:tid 167461] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/key.json"] [unique_id "aoSDtGr_JutbFb-8svoV7gABoAE"] [Tue Aug 18 13:09:24.909979 2026] [security2:error] [pid 167459:tid 167524] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/credentials.json"] [unique_id "aoSDtGr_JutbFb-8svoV8AABw0A"] [Tue Aug 18 13:09:24.910001 2026] [security2:error] [pid 167459:tid 167690] [client 172.182.217.32:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/chosen.php"] [unique_id "aoSDtGr_JutbFb-8svoV7wAAAfQ"] [Tue Aug 18 13:09:24.913643 2026] [security2:error] [pid 167459:tid 167701] [client 20.151.109.219:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/kc.php"] [unique_id "aoSDtGr_JutbFb-8svoV8QAAAf8"] [Tue Aug 18 13:09:24.929808 2026] [security2:error] [pid 167459:tid 167530] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/@fs/.env"] [unique_id "aoSDtGr_JutbFb-8svoWIQAB-0Y"] [Tue Aug 18 13:09:24.933607 2026] [security2:error] [pid 167459:tid 167544] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/serviceAccountKey.json"] [unique_id "aoSDtGr_JutbFb-8svoWKgABnVQ"] [Tue Aug 18 13:09:24.934619 2026] [security2:error] [pid 167459:tid 167502] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/@fs/root/.env"] [unique_id "aoSDtGr_JutbFb-8svoWKwAB9yo"] [Tue Aug 18 13:09:24.949919 2026] [security2:error] [pid 167459:tid 167683] [client 68.155.154.236:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/yxijx.php"] [unique_id "aoSDtGr_JutbFb-8svoWLQAAAe0"] [Tue Aug 18 13:09:25.007015 2026] [security2:error] [pid 167459:tid 167642] [client 213.35.127.232:59440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDtWr_JutbFb-8svoWLwAAAcQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:25.018352 2026] [security2:error] [pid 167459:tid 167656] [client 4.232.151.198:2716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-blink.php"] [unique_id "aoSDtWr_JutbFb-8svoWMAAAAdI"] [Tue Aug 18 13:09:25.035993 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/0x.php"] [unique_id "aoSDtWr_JutbFb-8svoWMgAAAaQ"] [Tue Aug 18 13:09:25.037163 2026] [security2:error] [pid 167459:tid 167691] [client 158.23.17.4:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/xn.php"] [unique_id "aoSDtWr_JutbFb-8svoWMwAAAfU"] [Tue Aug 18 13:09:25.059051 2026] [security2:error] [pid 167459:tid 167507] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "aoSDtWr_JutbFb-8svoWNAAB6C8"] [Tue Aug 18 13:09:25.060963 2026] [security2:error] [pid 167459:tid 167661] [client 20.250.13.23:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSDtWr_JutbFb-8svoWNQAAAdc"] [Tue Aug 18 13:09:25.066129 2026] [security2:error] [pid 167459:tid 167585] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/acme-challenge/makeasmtp.php"] [unique_id "aoSDtWr_JutbFb-8svoWNgABwX0"] [Tue Aug 18 13:09:25.069230 2026] [security2:error] [pid 167459:tid 167550] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/service_account.json"] [unique_id "aoSDtWr_JutbFb-8svoWOAABqlo"] [Tue Aug 18 13:09:25.075710 2026] [security2:error] [pid 167459:tid 167469] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/@fs/proc/self/environ"] [unique_id "aoSDtWr_JutbFb-8svoWOQABpgk"] [Tue Aug 18 13:09:25.077629 2026] [security2:error] [pid 167459:tid 167638] [client 74.249.206.207:8536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/key.php"] [unique_id "aoSDtWr_JutbFb-8svoWOgAAAcA"] [Tue Aug 18 13:09:25.080096 2026] [security2:error] [pid 167459:tid 167657] [client 168.62.48.100:16453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDtWr_JutbFb-8svoWOwAAAdM"] [Tue Aug 18 13:09:25.083270 2026] [security2:error] [pid 167459:tid 167480] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/google-credentials.json"] [unique_id "aoSDtWr_JutbFb-8svoWPAAB2hQ"] [Tue Aug 18 13:09:25.085907 2026] [security2:error] [pid 167459:tid 167518] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/gcp-credentials.json"] [unique_id "aoSDtWr_JutbFb-8svoWPgABlzo"] [Tue Aug 18 13:09:25.087863 2026] [security2:error] [pid 167459:tid 167532] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/Dockerfile"] [unique_id "aoSDtWr_JutbFb-8svoWQAACA0g"] [Tue Aug 18 13:09:25.089309 2026] [security2:error] [pid 167459:tid 167665] [client 172.213.243.2:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/motu.php"] [unique_id "aoSDtWr_JutbFb-8svoWQQAAAds"] [Tue Aug 18 13:09:25.092827 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:25.093079 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:25.097892 2026] [security2:error] [pid 167459:tid 167662] [client 20.1.169.243:10223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/footer.php"] [unique_id "aoSDtWr_JutbFb-8svoWQgAAAdg"] [Tue Aug 18 13:09:25.102361 2026] [security2:error] [pid 167459:tid 167640] [client 74.248.18.37:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/file.php"] [unique_id "aoSDtWr_JutbFb-8svoWQwAAAcI"] [Tue Aug 18 13:09:25.113508 2026] [security2:error] [pid 167459:tid 167629] [client 103.120.71.157:54425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtWr_JutbFb-8svoWRAAAAbc"] [Tue Aug 18 13:09:25.113597 2026] [security2:error] [pid 167459:tid 167629] [client 103.120.71.157:54425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtWr_JutbFb-8svoWRAAAAbc"] [Tue Aug 18 13:09:25.184291 2026] [security2:error] [pid 167459:tid 167608] [client 20.104.100.201:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/99.php"] [unique_id "aoSDtWr_JutbFb-8svoWSAAAAaI"] [Tue Aug 18 13:09:25.199699 2026] [security2:error] [pid 167459:tid 167493] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/admin.php"] [unique_id "aoSDtWr_JutbFb-8svoWSQACCCE"] [Tue Aug 18 13:09:25.208459 2026] [security2:error] [pid 167459:tid 167499] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/keys/service-account.json"] [unique_id "aoSDtWr_JutbFb-8svoWTAAB8Sc"] [Tue Aug 18 13:09:25.220361 2026] [security2:error] [pid 167459:tid 167561] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/sa.json"] [unique_id "aoSDtWr_JutbFb-8svoWTgABmmU"] [Tue Aug 18 13:09:25.233587 2026] [security2:error] [pid 167459:tid 167492] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase-service-account.json"] [unique_id "aoSDtWr_JutbFb-8svoWUAAB-iA"] [Tue Aug 18 13:09:25.233771 2026] [security2:error] [pid 167459:tid 167489] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase-credentials.json"] [unique_id "aoSDtWr_JutbFb-8svoWUQAB-h0"] [Tue Aug 18 13:09:25.247205 2026] [security2:error] [pid 167459:tid 167622] [client 158.23.17.4:53243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/uq.php"] [unique_id "aoSDtWr_JutbFb-8svoWUwAAAbA"] [Tue Aug 18 13:09:25.247385 2026] [security2:error] [pid 167459:tid 167477] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase-admin.json"] [unique_id "aoSDtWr_JutbFb-8svoWVAABrRE"] [Tue Aug 18 13:09:25.247913 2026] [security2:error] [pid 167459:tid 167503] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.github/.env"] [unique_id "aoSDtWr_JutbFb-8svoWVQABrSs"] [Tue Aug 18 13:09:25.280402 2026] [security2:error] [pid 167459:tid 167627] [client 20.116.17.175:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/fw/34.php"] [unique_id "aoSDtWr_JutbFb-8svoWVwAAAbU"] [Tue Aug 18 13:09:25.334541 2026] [security2:error] [pid 167459:tid 167473] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/core.php"] [unique_id "aoSDtWr_JutbFb-8svoWWQAB3g0"] [Tue Aug 18 13:09:25.350981 2026] [security2:error] [pid 167459:tid 167624] [client 20.250.13.23:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSDtWr_JutbFb-8svoWWwAAAbI"] [Tue Aug 18 13:09:25.383247 2026] [security2:error] [pid 167459:tid 167508] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.docker/config.json"] [unique_id "aoSDtWr_JutbFb-8svoWYAAByTA"] [Tue Aug 18 13:09:25.396901 2026] [security2:error] [pid 167459:tid 167593] [client 168.62.48.100:16428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDtWr_JutbFb-8svoWYQAAAZM"] [Tue Aug 18 13:09:25.400775 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.18.37:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDtWr_JutbFb-8svoWYgAAAd8"] [Tue Aug 18 13:09:25.403323 2026] [security2:error] [pid 167459:tid 167632] [client 172.182.217.32:15782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/doc.php"] [unique_id "aoSDtWr_JutbFb-8svoWZAAAAbo"] [Tue Aug 18 13:09:25.404307 2026] [security2:error] [pid 167459:tid 167495] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.boto"] [unique_id "aoSDtWr_JutbFb-8svoWZQAB9iM"] [Tue Aug 18 13:09:25.404660 2026] [security2:error] [pid 167459:tid 167495] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.npmrc"] [unique_id "aoSDtWr_JutbFb-8svoWbQAB9iM"] [Tue Aug 18 13:09:25.404754 2026] [security2:error] [pid 167459:tid 167505] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.htpasswd"] [unique_id "aoSDtWr_JutbFb-8svoWbgAB9i0"] [Tue Aug 18 13:09:25.407142 2026] [security2:error] [pid 167459:tid 167466] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/gcp-key.json"] [unique_id "aoSDtWr_JutbFb-8svoWbwABzQY"] [Tue Aug 18 13:09:25.415379 2026] [security2:error] [pid 167459:tid 167604] [client 20.171.51.14:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wm.php"] [unique_id "aoSDtWr_JutbFb-8svoWcAAAAZ4"] [Tue Aug 18 13:09:25.426120 2026] [security2:error] [pid 167459:tid 167467] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.s3cfg"] [unique_id "aoSDtWr_JutbFb-8svoWcQAB1Ac"] [Tue Aug 18 13:09:25.466726 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:35289] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.zelareimoveis.com.br"] [uri "/1.php"] [unique_id "aoSDtWr_JutbFb-8svoWdQAAAfA"] [Tue Aug 18 13:09:25.466841 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:35289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/1.php"] [unique_id "aoSDtWr_JutbFb-8svoWdQAAAfA"] [Tue Aug 18 13:09:25.466861 2026] [security2:error] [pid 167459:tid 167673] [client 20.1.169.243:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/form.php"] [unique_id "aoSDtWr_JutbFb-8svoWdgAAAeM"] [Tue Aug 18 13:09:25.470397 2026] [security2:error] [pid 167459:tid 167463] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/db-status.php"] [unique_id "aoSDtWr_JutbFb-8svoWdwAB9AM"] [Tue Aug 18 13:09:25.496774 2026] [security2:error] [pid 167459:tid 167626] [client 20.100.169.31:18970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSDtWr_JutbFb-8svoWWAAAAbQ"] [Tue Aug 18 13:09:25.509420 2026] [security2:error] [pid 167459:tid 167701] [client 172.213.243.2:48391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fff.php"] [unique_id "aoSDtWr_JutbFb-8svoWeAAAAf8"] [Tue Aug 18 13:09:25.545794 2026] [security2:error] [pid 167459:tid 167539] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/openapi.json"] [unique_id "aoSDtWr_JutbFb-8svoWewABxk8"] [Tue Aug 18 13:09:25.547448 2026] [security2:error] [pid 167459:tid 167697] [client 20.104.100.201:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/yup.php"] [unique_id "aoSDtWr_JutbFb-8svoWfAAAAfs"] [Tue Aug 18 13:09:25.550906 2026] [security2:error] [pid 167459:tid 167482] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/public/admin.json"] [unique_id "aoSDtWr_JutbFb-8svoWfQABrBY"] [Tue Aug 18 13:09:25.560732 2026] [security2:error] [pid 167459:tid 167472] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/health"] [unique_id "aoSDtWr_JutbFb-8svoWfgAB9ww"] [Tue Aug 18 13:09:25.569730 2026] [security2:error] [pid 167459:tid 167506] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/account"] [unique_id "aoSDtWr_JutbFb-8svoWfwAB7S4"] [Tue Aug 18 13:09:25.570831 2026] [security2:error] [pid 167459:tid 167587] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.svn/entries"] [unique_id "aoSDtWr_JutbFb-8svoWgAABj38"] [Tue Aug 18 13:09:25.588761 2026] [security2:error] [pid 167459:tid 167704] [client 20.100.169.31:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDtWr_JutbFb-8svoWgQAAAgI"] [Tue Aug 18 13:09:25.594299 2026] [security2:error] [pid 167459:tid 167520] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/terraform.tfstate"] [unique_id "aoSDtWr_JutbFb-8svoWggABxDw"] [Tue Aug 18 13:09:25.602825 2026] [security2:error] [pid 167459:tid 167516] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSDtWr_JutbFb-8svoWhAAB0jg"] [Tue Aug 18 13:09:25.629366 2026] [security2:error] [pid 167459:tid 167610] [client 158.23.17.4:14022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/pm.php"] [unique_id "aoSDtWr_JutbFb-8svoWhgAAAaQ"] [Tue Aug 18 13:09:25.653115 2026] [security2:error] [pid 167459:tid 167691] [client 20.127.136.245:2116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSDtWr_JutbFb-8svoWiAAAAfU"] [Tue Aug 18 13:09:25.662527 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.133.44:38845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/k.php"] [unique_id "aoSDtWr_JutbFb-8svoWiQAAAc4"] [Tue Aug 18 13:09:25.674373 2026] [security2:error] [pid 167459:tid 167641] [client 20.250.13.23:23262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/lite.php"] [unique_id "aoSDtWr_JutbFb-8svoWigAAAcM"] [Tue Aug 18 13:09:25.688672 2026] [security2:error] [pid 167459:tid 167498] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/app-config.json"] [unique_id "aoSDtWr_JutbFb-8svoWiwABqiY"] [Tue Aug 18 13:09:25.690892 2026] [security2:error] [pid 167459:tid 167605] [client 20.65.98.162:53636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/xx.php"] [unique_id "aoSDtWr_JutbFb-8svoWjAAAAZ8"] [Tue Aug 18 13:09:25.703897 2026] [security2:error] [pid 167459:tid 167524] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/__env.js"] [unique_id "aoSDtWr_JutbFb-8svoWjwABwEA"] [Tue Aug 18 13:09:25.712951 2026] [security2:error] [pid 167459:tid 167606] [client 4.232.151.198:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-blog-header.php"] [unique_id "aoSDtWr_JutbFb-8svoWkQAAAaA"] [Tue Aug 18 13:09:25.714370 2026] [security2:error] [pid 167459:tid 167545] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/health"] [unique_id "aoSDtWr_JutbFb-8svoWkwAB2lU"] [Tue Aug 18 13:09:25.721082 2026] [security2:error] [pid 167459:tid 167504] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/v1/env"] [unique_id "aoSDtWr_JutbFb-8svoWlAABlyw"] [Tue Aug 18 13:09:25.734013 2026] [security2:error] [pid 167459:tid 167515] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/swagger.json"] [unique_id "aoSDtWr_JutbFb-8svoWlQAB2zc"] [Tue Aug 18 13:09:25.736146 2026] [security2:error] [pid 167459:tid 167479] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/index.php"] [unique_id "aoSDtWr_JutbFb-8svoWlgAB2BM"] [Tue Aug 18 13:09:25.761766 2026] [security2:error] [pid 167459:tid 167549] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/runtime.js"] [unique_id "aoSDtWr_JutbFb-8svoWmAAB0Vk"] [Tue Aug 18 13:09:25.782820 2026] [security2:error] [pid 167459:tid 167609] [client 223.185.37.47:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDtWr_JutbFb-8svoWmQAAAaM"] [Tue Aug 18 13:09:25.783015 2026] [security2:error] [pid 167459:tid 167609] [client 223.185.37.47:10182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDtWr_JutbFb-8svoWmQAAAaM"] [Tue Aug 18 13:09:25.789383 2026] [security2:error] [pid 167459:tid 167596] [client 74.248.18.37:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/chosen.php"] [unique_id "aoSDtWr_JutbFb-8svoWmwAAAZY"] [Tue Aug 18 13:09:25.821014 2026] [security2:error] [pid 167459:tid 167687] [client 168.62.48.100:16395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSDtWr_JutbFb-8svoWngAAAfE"] [Tue Aug 18 13:09:25.828575 2026] [security2:error] [pid 167459:tid 167511] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/configuration.js"] [unique_id "aoSDtWr_JutbFb-8svoWnwABmzM"] [Tue Aug 18 13:09:25.839530 2026] [security2:error] [pid 167459:tid 167657] [client 20.1.169.243:10483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/fpwch.php"] [unique_id "aoSDtWr_JutbFb-8svoWoAAAAdM"] [Tue Aug 18 13:09:25.869134 2026] [security2:error] [pid 167459:tid 167487] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/settings.js"] [unique_id "aoSDtWr_JutbFb-8svoWoQACChs"] [Tue Aug 18 13:09:25.872858 2026] [security2:error] [pid 167459:tid 167514] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/constants.js"] [unique_id "aoSDtWr_JutbFb-8svoWogAB0DY"] [Tue Aug 18 13:09:25.873385 2026] [security2:error] [pid 167459:tid 167553] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/environment.js"] [unique_id "aoSDtWr_JutbFb-8svoWowAB0F0"] [Tue Aug 18 13:09:25.876060 2026] [security2:error] [pid 167459:tid 167577] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSDtWr_JutbFb-8svoWpAABoXU"] [Tue Aug 18 13:09:25.887055 2026] [security2:error] [pid 167459:tid 167555] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/credentials.js"] [unique_id "aoSDtWr_JutbFb-8svoWpgAB-l8"] [Tue Aug 18 13:09:25.892897 2026] [security2:error] [pid 167459:tid 167705] [client 172.182.217.32:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/elp.php"] [unique_id "aoSDtWr_JutbFb-8svoWpwAAAgM"] [Tue Aug 18 13:09:25.895413 2026] [security2:error] [pid 167459:tid 167688] [client 52.139.47.57:35312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/100.php"] [unique_id "aoSDtWr_JutbFb-8svoWqAAAAfI"] [Tue Aug 18 13:09:25.928926 2026] [security2:error] [pid 167459:tid 167684] [client 172.213.243.2:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/66.php"] [unique_id "aoSDtWr_JutbFb-8svoWqQAAAe4"] [Tue Aug 18 13:09:25.978659 2026] [security2:error] [pid 167459:tid 167465] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.json.js"] [unique_id "aoSDtWr_JutbFb-8svoWrAAB8wU"] [Tue Aug 18 13:09:25.979023 2026] [security2:error] [pid 167459:tid 167594] [client 20.250.13.23:23246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/ebs.php7"] [unique_id "aoSDtWr_JutbFb-8svoWqwAAAZQ"] [Tue Aug 18 13:09:25.989839 2026] [security2:error] [pid 167459:tid 167531] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.js"] [unique_id "aoSDtWr_JutbFb-8svoWrwABykc"] [Tue Aug 18 13:09:26.011097 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/logs233/x.php"] [unique_id "aoSDtmr_JutbFb-8svoWsAAByRU"] [Tue Aug 18 13:09:26.018990 2026] [security2:error] [pid 167459:tid 167678] [client 213.35.127.232:59670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDtmr_JutbFb-8svoWsQAAAeg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:26.019655 2026] [security2:error] [pid 167459:tid 167568] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/public/env.js"] [unique_id "aoSDtmr_JutbFb-8svoWsgABk2w"] [Tue Aug 18 13:09:26.021477 2026] [security2:error] [pid 167459:tid 167485] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/sw.js"] [unique_id "aoSDtmr_JutbFb-8svoWswAB5Rk"] [Tue Aug 18 13:09:26.042162 2026] [security2:error] [pid 167459:tid 167573] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/service-worker.js"] [unique_id "aoSDtmr_JutbFb-8svoWtAABunE"] [Tue Aug 18 13:09:26.049803 2026] [security2:error] [pid 167459:tid 167551] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/ngsw.json"] [unique_id "aoSDtmr_JutbFb-8svoWtgAB9ls"] [Tue Aug 18 13:09:26.054895 2026] [security2:error] [pid 167459:tid 167643] [client 68.155.154.236:27562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/zwlsv.php"] [unique_id "aoSDtmr_JutbFb-8svoWtwAAAcU"] [Tue Aug 18 13:09:26.083425 2026] [security2:error] [pid 167459:tid 167703] [client 158.23.17.4:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/32.php"] [unique_id "aoSDtmr_JutbFb-8svoWuQAAAgE"] [Tue Aug 18 13:09:26.121633 2026] [security2:error] [pid 167459:tid 167714] [client 20.100.169.31:3386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSDtmr_JutbFb-8svoWuwAAAgw"] [Tue Aug 18 13:09:26.121781 2026] [security2:error] [pid 167459:tid 167622] [client 74.248.18.37:25353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSDtmr_JutbFb-8svoWvAAAAbA"] [Tue Aug 18 13:09:26.132163 2026] [security2:error] [pid 167459:tid 167571] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/graphql"] [unique_id "aoSDtmr_JutbFb-8svoWvQABp28"] [Tue Aug 18 13:09:26.138627 2026] [security2:error] [pid 167459:tid 167512] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/graphql"] [unique_id "aoSDtmr_JutbFb-8svoWvgAB4zQ"] [Tue Aug 18 13:09:26.147865 2026] [security2:error] [pid 167459:tid 167569] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/ms-files.php"] [unique_id "aoSDtmr_JutbFb-8svoWvwAB9G0"] [Tue Aug 18 13:09:26.163009 2026] [security2:error] [pid 167459:tid 167533] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/v1/graphql"] [unique_id "aoSDtmr_JutbFb-8svoWwQAB3Uk"] [Tue Aug 18 13:09:26.170656 2026] [security2:error] [pid 167459:tid 167564] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/graphql/console"] [unique_id "aoSDtmr_JutbFb-8svoWwgABvGg"] [Tue Aug 18 13:09:26.202989 2026] [security2:error] [pid 167459:tid 167575] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/actuator"] [unique_id "aoSDtmr_JutbFb-8svoWwwABnXM"] [Tue Aug 18 13:09:26.204841 2026] [security2:error] [pid 167459:tid 167693] [client 20.127.136.245:12209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/.alf.php"] [unique_id "aoSDtmr_JutbFb-8svoWxAAAAfc"] [Tue Aug 18 13:09:26.210810 2026] [security2:error] [pid 167459:tid 167636] [client 20.1.169.243:9712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/function.php"] [unique_id "aoSDtmr_JutbFb-8svoWxgAAAb4"] [Tue Aug 18 13:09:26.210918 2026] [security2:error] [pid 167459:tid 167715] [client 168.62.48.100:16392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSDtmr_JutbFb-8svoWxQAAAg0"] [Tue Aug 18 13:09:26.216986 2026] [security2:error] [pid 167459:tid 167500] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/actuator/configprops"] [unique_id "aoSDtmr_JutbFb-8svoWxwACACg"] [Tue Aug 18 13:09:26.219142 2026] [security2:error] [pid 167459:tid 167708] [client 20.100.169.31:17862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSDtmr_JutbFb-8svoWyAAAAgY"] [Tue Aug 18 13:09:26.253360 2026] [security2:error] [pid 167459:tid 167704] [client 20.104.100.201:13852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/222.php"] [unique_id "aoSDtmr_JutbFb-8svoWygAAAgI"] [Tue Aug 18 13:09:26.257150 2026] [security2:error] [pid 167459:tid 167671] [client 158.23.17.4:40404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/47.php"] [unique_id "aoSDtmr_JutbFb-8svoWywAAAeE"] [Tue Aug 18 13:09:26.275005 2026] [security2:error] [pid 167459:tid 167537] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/actuator/mappings"] [unique_id "aoSDtmr_JutbFb-8svoWzAAB7E0"] [Tue Aug 18 13:09:26.283129 2026] [security2:error] [pid 167459:tid 167526] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/options.php"] [unique_id "aoSDtmr_JutbFb-8svoWzQABsUI"] [Tue Aug 18 13:09:26.284916 2026] [security2:error] [pid 167459:tid 167658] [client 20.250.13.23:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSDtmr_JutbFb-8svoWzgAAAdQ"] [Tue Aug 18 13:09:26.289312 2026] [security2:error] [pid 167459:tid 167584] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/phpinfo.php"] [unique_id "aoSDtmr_JutbFb-8svoW0AABknw"] [Tue Aug 18 13:09:26.310629 2026] [security2:error] [pid 167459:tid 167644] [client 52.139.47.57:18525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/2.php"] [unique_id "aoSDtmr_JutbFb-8svoW0QAAAcY"] [Tue Aug 18 13:09:26.326931 2026] [security2:error] [pid 167459:tid 167490] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/info.php"] [unique_id "aoSDtmr_JutbFb-8svoW0gABwx4"] [Tue Aug 18 13:09:26.342400 2026] [security2:error] [pid 167459:tid 167612] [client 172.213.243.2:16398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/g.php"] [unique_id "aoSDtmr_JutbFb-8svoW0wAAAaY"] [Tue Aug 18 13:09:26.357401 2026] [security2:error] [pid 167459:tid 167576] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/pi.php"] [unique_id "aoSDtmr_JutbFb-8svoW1QAB2nQ"] [Tue Aug 18 13:09:26.367951 2026] [security2:error] [pid 167459:tid 167543] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/test.php"] [unique_id "aoSDtmr_JutbFb-8svoW1gABl1M"] [Tue Aug 18 13:09:26.379959 2026] [security2:error] [pid 167459:tid 167662] [client 20.38.3.247:30705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/fpwch.php"] [unique_id "aoSDtmr_JutbFb-8svoW2AAAAdg"] [Tue Aug 18 13:09:26.381607 2026] [security2:error] [pid 167459:tid 167468] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/i.php"] [unique_id "aoSDtmr_JutbFb-8svoW2QABwgg"] [Tue Aug 18 13:09:26.386021 2026] [security2:error] [pid 167459:tid 167683] [client 172.182.217.32:15787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/Exception-class.php"] [unique_id "aoSDtmr_JutbFb-8svoW2gAAAe0"] [Tue Aug 18 13:09:26.388817 2026] [security2:error] [pid 167459:tid 167540] [remote 162.214.205.212:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientalbrindes.com.br"] [uri "/wp-login.php"] [unique_id "aoSDtmr_JutbFb-8svoW2wAB5FA"] [Tue Aug 18 13:09:26.416829 2026] [security2:error] [pid 167459:tid 167513] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/panel.php"] [unique_id "aoSDtmr_JutbFb-8svoW3AABozU"] [Tue Aug 18 13:09:26.428998 2026] [security2:error] [pid 167459:tid 167523] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/_profiler/latest"] [unique_id "aoSDtmr_JutbFb-8svoW3QAB1z8"] [Tue Aug 18 13:09:26.445444 2026] [security2:error] [pid 167459:tid 167581] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/_profiler/open"] [unique_id "aoSDtmr_JutbFb-8svoW6AABmXk"] [Tue Aug 18 13:09:26.483827 2026] [security2:error] [pid 167459:tid 167507] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/app_dev.php"] [unique_id "aoSDtmr_JutbFb-8svoW6gABmy8"] [Tue Aug 18 13:09:26.509777 2026] [security2:error] [pid 167459:tid 167711] [client 168.62.48.100:16506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSDtmr_JutbFb-8svoW6wAAAgk"] [Tue Aug 18 13:09:26.516286 2026] [security2:error] [pid 167459:tid 167585] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/_ignition/health-check"] [unique_id "aoSDtmr_JutbFb-8svoW7AABnH0"] [Tue Aug 18 13:09:26.524416 2026] [security2:error] [pid 167459:tid 167697] [client 4.232.151.198:45449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-blog.php"] [unique_id "aoSDtmr_JutbFb-8svoW7wAAAfs"] [Tue Aug 18 13:09:26.525392 2026] [security2:error] [pid 167459:tid 167486] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSDtmr_JutbFb-8svoW8AACAxo"] [Tue Aug 18 13:09:26.542677 2026] [security2:error] [pid 167459:tid 167469] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/telescope/requests"] [unique_id "aoSDtmr_JutbFb-8svoW8QABtQk"] [Tue Aug 18 13:09:26.551265 2026] [security2:error] [pid 167459:tid 167480] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "aoSDtmr_JutbFb-8svoW8gABshQ"] [Tue Aug 18 13:09:26.578784 2026] [security2:error] [pid 167459:tid 167518] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/_debugbar/open"] [unique_id "aoSDtmr_JutbFb-8svoW8wABlDo"] [Tue Aug 18 13:09:26.583299 2026] [security2:error] [pid 167459:tid 167710] [client 20.1.169.243:9681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/g.php"] [unique_id "aoSDtmr_JutbFb-8svoW9AAAAgg"] [Tue Aug 18 13:09:26.589756 2026] [security2:error] [pid 167459:tid 167648] [client 74.249.206.207:50059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/chosen.php"] [unique_id "aoSDtmr_JutbFb-8svoW9gAAAco"] [Tue Aug 18 13:09:26.595771 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:26.596023 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:26.600636 2026] [security2:error] [pid 167459:tid 167629] [client 20.250.13.23:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/include/Lurd.class.php"] [unique_id "aoSDtmr_JutbFb-8svoW9wAAAbc"] [Tue Aug 18 13:09:26.601303 2026] [security2:error] [pid 167459:tid 167538] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/__debug__/"] [unique_id "aoSDtmr_JutbFb-8svoW-AABy04"] [Tue Aug 18 13:09:26.643288 2026] [security2:error] [pid 167459:tid 167563] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/elmah.axd"] [unique_id "aoSDtmr_JutbFb-8svoW_AABk2c"] [Tue Aug 18 13:09:26.661619 2026] [security2:error] [pid 167459:tid 167561] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/trace.axd"] [unique_id "aoSDtmr_JutbFb-8svoXAQABkWU"] [Tue Aug 18 13:09:26.665928 2026] [security2:error] [pid 167459:tid 167691] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDtmr_JutbFb-8svoW-QAB9Us"] [Tue Aug 18 13:09:26.685684 2026] [security2:error] [pid 167459:tid 167492] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/pki-validation/min.php"] [unique_id "aoSDtmr_JutbFb-8svoXAgABzSA"] [Tue Aug 18 13:09:26.690922 2026] [security2:error] [pid 167459:tid 167489] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/server-status"] [unique_id "aoSDtmr_JutbFb-8svoXAwABnh0"] [Tue Aug 18 13:09:26.693653 2026] [security2:error] [pid 167459:tid 167477] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/server-info"] [unique_id "aoSDtmr_JutbFb-8svoXBAABxRE"] [Tue Aug 18 13:09:26.696533 2026] [security2:error] [pid 167459:tid 167541] [remote 162.214.205.212:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orientalbrindes.com.br"] [uri "/wp-login.php"] [unique_id "aoSDtmr_JutbFb-8svoXBgACAVE"], referer: https://orientalbrindes.com.br/wp-login.php [Tue Aug 18 13:09:26.723644 2026] [security2:error] [pid 167459:tid 167560] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/nginx_status"] [unique_id "aoSDtmr_JutbFb-8svoXCQAB8GQ"] [Tue Aug 18 13:09:26.730314 2026] [security2:error] [pid 167459:tid 167673] [client 20.171.51.14:18215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ac.php"] [unique_id "aoSDtmr_JutbFb-8svoXCgAAAeM"] [Tue Aug 18 13:09:26.743607 2026] [security2:error] [pid 167459:tid 167619] [client 20.100.169.31:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDtmr_JutbFb-8svoXDAAAAa0"] [Tue Aug 18 13:09:26.750936 2026] [security2:error] [pid 167459:tid 167701] [client 172.213.243.2:18619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/x7.php"] [unique_id "aoSDtmr_JutbFb-8svoXDQAAAf8"] [Tue Aug 18 13:09:26.764984 2026] [security2:error] [pid 167459:tid 167611] [client 74.248.18.37:3367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDtmr_JutbFb-8svoXDgAAAaU"] [Tue Aug 18 13:09:26.770634 2026] [security2:error] [pid 167459:tid 167521] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/core/.env"] [unique_id "aoSDtmr_JutbFb-8svoXDwAB3T0"] [Tue Aug 18 13:09:26.781111 2026] [security2:error] [pid 167459:tid 167634] [client 168.62.48.100:16501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSDtmr_JutbFb-8svoXEAAAAbw"] [Tue Aug 18 13:09:26.801290 2026] [security2:error] [pid 167459:tid 167508] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDtmr_JutbFb-8svoXEgABnTA"] [Tue Aug 18 13:09:26.812523 2026] [security2:error] [pid 167459:tid 167464] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.vscode/launch.json"] [unique_id "aoSDtmr_JutbFb-8svoXEwAB9wQ"] [Tue Aug 18 13:09:26.819469 2026] [security2:error] [pid 167459:tid 167495] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/plugin-install.php"] [unique_id "aoSDtmr_JutbFb-8svoXFAABviM"] [Tue Aug 18 13:09:26.840423 2026] [security2:error] [pid 167459:tid 167505] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "aoSDtmr_JutbFb-8svoXFQACBi0"] [Tue Aug 18 13:09:26.843216 2026] [security2:error] [pid 167459:tid 167491] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "aoSDtmr_JutbFb-8svoXFgABjx8"] [Tue Aug 18 13:09:26.855171 2026] [security2:error] [pid 167459:tid 167642] [client 20.104.100.201:13906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-temp.php"] [unique_id "aoSDtmr_JutbFb-8svoXGAAAAcQ"] [Tue Aug 18 13:09:26.867995 2026] [security2:error] [pid 167459:tid 167623] [client 20.127.136.245:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSDtmr_JutbFb-8svoXGQAAAbE"] [Tue Aug 18 13:09:26.872674 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:18547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/222.php"] [unique_id "aoSDtmr_JutbFb-8svoXGgAAAdk"] [Tue Aug 18 13:09:26.874223 2026] [security2:error] [pid 167459:tid 167613] [client 172.182.217.32:15557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ee.php"] [unique_id "aoSDtmr_JutbFb-8svoXGwAAAac"] [Tue Aug 18 13:09:26.879695 2026] [security2:error] [pid 167459:tid 167669] [client 20.100.169.31:2885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSDtmr_JutbFb-8svoXHAAAAd8"] [Tue Aug 18 13:09:26.887588 2026] [security2:error] [pid 167459:tid 167583] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDtmr_JutbFb-8svoXHgABkns"] [Tue Aug 18 13:09:26.891101 2026] [security2:error] [pid 167459:tid 167610] [client 68.155.154.236:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/jrpga.php"] [unique_id "aoSDtmr_JutbFb-8svoXIAAAAaQ"] [Tue Aug 18 13:09:26.896550 2026] [security2:error] [pid 167459:tid 167632] [client 185.191.171.14:24322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754387842/1756598400/"] [unique_id "aoSDtmr_JutbFb-8svoXIQAAAbo"] [Tue Aug 18 13:09:26.896655 2026] [security2:error] [pid 167459:tid 167632] [client 185.191.171.14:24322] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754387842/1756598400/"] [unique_id "aoSDtmr_JutbFb-8svoXIQAAAbo"] [Tue Aug 18 13:09:26.901975 2026] [security2:error] [pid 167459:tid 167639] [client 20.116.17.175:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp9.php"] [unique_id "aoSDtmr_JutbFb-8svoXIwAAAcE"] [Tue Aug 18 13:09:26.904038 2026] [security2:error] [pid 167459:tid 167670] [client 20.250.13.23:23237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSDtmr_JutbFb-8svoXJAAAAeA"] [Tue Aug 18 13:09:26.905631 2026] [authz_core:error] [pid 167459:tid 167580] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:26.905906 2026] [authz_core:error] [pid 167459:tid 167580] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:26.913963 2026] [security2:error] [pid 167459:tid 167582] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/authorized_keys"] [unique_id "aoSDtmr_JutbFb-8svoXJQABqno"] [Tue Aug 18 13:09:26.943306 2026] [security2:error] [pid 167459:tid 167633] [client 158.23.17.4:14046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/payout.php"] [unique_id "aoSDtmr_JutbFb-8svoXJgAAAbs"] [Tue Aug 18 13:09:26.949518 2026] [security2:error] [pid 167459:tid 167702] [client 20.1.169.243:10273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/goods.php"] [unique_id "aoSDtmr_JutbFb-8svoXJwAAAgA"] [Tue Aug 18 13:09:26.953616 2026] [security2:error] [pid 167459:tid 167466] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/test.php"] [unique_id "aoSDtmr_JutbFb-8svoXKAABwAY"] [Tue Aug 18 13:09:26.968848 2026] [security2:error] [pid 167459:tid 167474] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/known_hosts"] [unique_id "aoSDtmr_JutbFb-8svoXKgABtg4"] [Tue Aug 18 13:09:26.970276 2026] [security2:error] [pid 167459:tid 167565] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.ssh/config"] [unique_id "aoSDtmr_JutbFb-8svoXKwAB22k"] [Tue Aug 18 13:09:26.992853 2026] [security2:error] [pid 167459:tid 167566] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/id_rsa"] [unique_id "aoSDtmr_JutbFb-8svoXLQAB7Wo"] [Tue Aug 18 13:09:27.004602 2026] [security2:error] [pid 167459:tid 167539] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/id_dsa"] [unique_id "aoSDt2r_JutbFb-8svoXLwAB6U8"] [Tue Aug 18 13:09:27.034215 2026] [security2:error] [pid 167459:tid 167615] [client 213.35.127.232:59884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDt2r_JutbFb-8svoXMgAAAak"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:27.043176 2026] [security2:error] [pid 167459:tid 167472] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/id_ed25519"] [unique_id "aoSDt2r_JutbFb-8svoXMwAB8Qw"] [Tue Aug 18 13:09:27.051287 2026] [security2:error] [pid 167459:tid 167713] [client 20.91.215.254:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDt2r_JutbFb-8svoXNAAAAgs"] [Tue Aug 18 13:09:27.054880 2026] [security2:error] [pid 167459:tid 167506] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/id_ecdsa"] [unique_id "aoSDt2r_JutbFb-8svoXNQABuC4"] [Tue Aug 18 13:09:27.059699 2026] [security2:error] [pid 167459:tid 167657] [client 168.62.48.100:16418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSDt2r_JutbFb-8svoXNgAAAdM"] [Tue Aug 18 13:09:27.071175 2026] [security2:error] [pid 167459:tid 167711] [client 158.23.17.4:20646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/73.php"] [unique_id "aoSDt2r_JutbFb-8svoXNwAAAgk"] [Tue Aug 18 13:09:27.076128 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.133.44:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/elp.php"] [unique_id "aoSDt2r_JutbFb-8svoXOQAAAdI"] [Tue Aug 18 13:09:27.085637 2026] [security2:error] [pid 167459:tid 167600] [client 158.23.17.4:40429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/dr.php"] [unique_id "aoSDt2r_JutbFb-8svoXOgAAAZo"] [Tue Aug 18 13:09:27.088296 2026] [security2:error] [pid 167459:tid 167520] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-blog-header.php"] [unique_id "aoSDt2r_JutbFb-8svoXOwABnDw"] [Tue Aug 18 13:09:27.117350 2026] [security2:error] [pid 167459:tid 167527] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/key.pem"] [unique_id "aoSDt2r_JutbFb-8svoXPQAB-0M"] [Tue Aug 18 13:09:27.118994 2026] [security2:error] [pid 167459:tid 167516] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/server.key"] [unique_id "aoSDt2r_JutbFb-8svoXPgACAzg"] [Tue Aug 18 13:09:27.148085 2026] [security2:error] [pid 167459:tid 167522] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/private-key"] [unique_id "aoSDt2r_JutbFb-8svoXQAAB7j4"] [Tue Aug 18 13:09:27.151068 2026] [security2:error] [pid 167459:tid 167548] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/privatekey.key"] [unique_id "aoSDt2r_JutbFb-8svoXQQABkFg"] [Tue Aug 18 13:09:27.160441 2026] [security2:error] [pid 167459:tid 167668] [client 172.213.243.2:11645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/god.php"] [unique_id "aoSDt2r_JutbFb-8svoXQgAAAd4"] [Tue Aug 18 13:09:27.190776 2026] [security2:error] [pid 167459:tid 167653] [client 149.34.210.141:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDt2r_JutbFb-8svoXRAAAAc8"] [Tue Aug 18 13:09:27.190940 2026] [security2:error] [pid 167459:tid 167653] [client 149.34.210.141:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDt2r_JutbFb-8svoXRAAAAc8"] [Tue Aug 18 13:09:27.211191 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:27.211243 2026] [security2:error] [pid 167459:tid 167529] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/localhost.key"] [unique_id "aoSDt2r_JutbFb-8svoXRgABt0U"] [Tue Aug 18 13:09:27.211631 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:27.215529 2026] [security2:error] [pid 167459:tid 167524] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/host.key"] [unique_id "aoSDt2r_JutbFb-8svoXRwABy0A"] [Tue Aug 18 13:09:27.222496 2026] [security2:error] [pid 167459:tid 167545] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-cron.php"] [unique_id "aoSDt2r_JutbFb-8svoXSQAB6FU"] [Tue Aug 18 13:09:27.237400 2026] [security2:error] [pid 167459:tid 167660] [client 20.250.13.23:23241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSDt2r_JutbFb-8svoXSgAAAdY"] [Tue Aug 18 13:09:27.272372 2026] [security2:error] [pid 167459:tid 167515] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/ssl/localhost.key"] [unique_id "aoSDt2r_JutbFb-8svoXTAAB9jc"] [Tue Aug 18 13:09:27.276454 2026] [security2:error] [pid 167459:tid 167479] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/ssl/server.key"] [unique_id "aoSDt2r_JutbFb-8svoXTQABzRM"] [Tue Aug 18 13:09:27.285448 2026] [security2:error] [pid 167459:tid 167627] [client 52.139.47.57:18538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSDt2r_JutbFb-8svoXTgAAAbU"] [Tue Aug 18 13:09:27.300541 2026] [security2:error] [pid 167459:tid 167549] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDt2r_JutbFb-8svoXTwABxVk"] [Tue Aug 18 13:09:27.305697 2026] [security2:error] [pid 167459:tid 167570] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "aoSDt2r_JutbFb-8svoXUAACDG4"] [Tue Aug 18 13:09:27.346699 2026] [security2:error] [pid 167459:tid 167619] [client 20.104.100.201:13786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/spadex.php"] [unique_id "aoSDt2r_JutbFb-8svoXUgAAAa0"] [Tue Aug 18 13:09:27.357437 2026] [security2:error] [pid 167459:tid 167511] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-links-opml.php"] [unique_id "aoSDt2r_JutbFb-8svoXUwAB_zM"] [Tue Aug 18 13:09:27.357900 2026] [security2:error] [pid 167459:tid 167487] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.continue/config.json"] [unique_id "aoSDt2r_JutbFb-8svoXVAABpRs"] [Tue Aug 18 13:09:27.360255 2026] [security2:error] [pid 167459:tid 167667] [client 168.62.48.100:16419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSDt2r_JutbFb-8svoXVQAAAd0"] [Tue Aug 18 13:09:27.360642 2026] [security2:error] [pid 167459:tid 167672] [client 172.182.217.32:15442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/edit.php"] [unique_id "aoSDt2r_JutbFb-8svoXVgAAAeI"] [Tue Aug 18 13:09:27.364919 2026] [security2:error] [pid 167459:tid 167514] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.cursor/mcp.json"] [unique_id "aoSDt2r_JutbFb-8svoXVwABrDY"] [Tue Aug 18 13:09:27.370187 2026] [security2:error] [pid 167459:tid 167624] [client 20.100.169.31:3354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDt2r_JutbFb-8svoXWAAAAbI"] [Tue Aug 18 13:09:27.380754 2026] [security2:error] [pid 167459:tid 167681] [client 20.1.169.243:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/gtt.php"] [unique_id "aoSDt2r_JutbFb-8svoXWgAAAes"] [Tue Aug 18 13:09:27.391144 2026] [security2:error] [pid 167459:tid 167693] [client 20.65.98.162:41589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/uwu.php"] [unique_id "aoSDt2r_JutbFb-8svoXWwAAAfc"] [Tue Aug 18 13:09:27.408183 2026] [security2:error] [pid 167459:tid 167596] [client 20.38.3.247:15038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/adminner.php"] [unique_id "aoSDt2r_JutbFb-8svoXXAAAAZY"] [Tue Aug 18 13:09:27.412438 2026] [security2:error] [pid 167459:tid 167648] [client 74.248.18.37:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSDt2r_JutbFb-8svoXXQAAAco"] [Tue Aug 18 13:09:27.418913 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:2584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-blogs.php"] [unique_id "aoSDt2r_JutbFb-8svoXXgAAAgg"] [Tue Aug 18 13:09:27.426392 2026] [security2:error] [pid 167459:tid 167577] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.codex/config.toml"] [unique_id "aoSDt2r_JutbFb-8svoXXwABj3U"] [Tue Aug 18 13:09:27.429644 2026] [security2:error] [pid 167459:tid 167525] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.aider.conf.yml"] [unique_id "aoSDt2r_JutbFb-8svoXYQABxEE"] [Tue Aug 18 13:09:27.429802 2026] [security2:error] [pid 167459:tid 167704] [client 68.155.154.236:25406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSDt2r_JutbFb-8svoXYAAAAgI"] [Tue Aug 18 13:09:27.462063 2026] [security2:error] [pid 167459:tid 167578] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDt2r_JutbFb-8svoXYwABsXY"] [Tue Aug 18 13:09:27.465942 2026] [security2:error] [pid 167459:tid 167574] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.hermes/config.yaml"] [unique_id "aoSDt2r_JutbFb-8svoXZAAB2XI"] [Tue Aug 18 13:09:27.468912 2026] [security2:error] [pid 167459:tid 167675] [client 20.91.215.254:16876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/0x.php"] [unique_id "aoSDt2r_JutbFb-8svoXZQAAAeU"] [Tue Aug 18 13:09:27.475438 2026] [security2:error] [pid 167459:tid 167613] [client 20.171.51.14:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/yz.php"] [unique_id "aoSDt2r_JutbFb-8svoXZgAAAac"] [Tue Aug 18 13:09:27.509404 2026] [security2:error] [pid 167459:tid 167481] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "aoSDt2r_JutbFb-8svoXawABpBU"] [Tue Aug 18 13:09:27.517068 2026] [security2:error] [pid 167459:tid 167483] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.hermes/auth.json"] [unique_id "aoSDt2r_JutbFb-8svoXbAABzBc"] [Tue Aug 18 13:09:27.522541 2026] [security2:error] [pid 167459:tid 167673] [client 20.250.13.23:23284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSDt2r_JutbFb-8svoXbQAAAeM"] [Tue Aug 18 13:09:27.569926 2026] [security2:error] [pid 167459:tid 167670] [client 172.213.243.2:37064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ebahvhhh.php"] [unique_id "aoSDt2r_JutbFb-8svoXcAAAAeA"] [Tue Aug 18 13:09:27.574975 2026] [security2:error] [pid 167459:tid 167485] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.claude.json"] [unique_id "aoSDt2r_JutbFb-8svoXcQABqhk"] [Tue Aug 18 13:09:27.582289 2026] [security2:error] [pid 167459:tid 167698] [client 4.232.151.198:44078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/abcd.php"] [unique_id "aoSDt2r_JutbFb-8svoXcgAAAfw"] [Tue Aug 18 13:09:27.588568 2026] [security2:error] [pid 167459:tid 167573] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.claude/settings.json"] [unique_id "aoSDt2r_JutbFb-8svoXcwABu3E"] [Tue Aug 18 13:09:27.593034 2026] [security2:error] [pid 167459:tid 167702] [client 20.116.17.175:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/save.php"] [unique_id "aoSDt2r_JutbFb-8svoXdAAAAgA"] [Tue Aug 18 13:09:27.616284 2026] [security2:error] [pid 167459:tid 167571] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.mcp.json"] [unique_id "aoSDt2r_JutbFb-8svoXeAABtm8"] [Tue Aug 18 13:09:27.616578 2026] [security2:error] [pid 167459:tid 167664] [client 168.62.48.100:16434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSDt2r_JutbFb-8svoXeQAAAdo"] [Tue Aug 18 13:09:27.624498 2026] [security2:error] [pid 167459:tid 167569] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.bashrc"] [unique_id "aoSDt2r_JutbFb-8svoXewABwm0"] [Tue Aug 18 13:09:27.658495 2026] [security2:error] [pid 167459:tid 167559] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.zshrc"] [unique_id "aoSDt2r_JutbFb-8svoXfAABomM"] [Tue Aug 18 13:09:27.666462 2026] [security2:error] [pid 167459:tid 167465] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-login.php"] [unique_id "aoSDt2r_JutbFb-8svoXZwABkgU"] [Tue Aug 18 13:09:27.675464 2026] [security2:error] [pid 167459:tid 167564] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.bash_profile"] [unique_id "aoSDt2r_JutbFb-8svoXfgABqWg"] [Tue Aug 18 13:09:27.696537 2026] [security2:error] [pid 167459:tid 167639] [client 52.139.47.57:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/403.php"] [unique_id "aoSDt2r_JutbFb-8svoXhgAAAcE"] [Tue Aug 18 13:09:27.712862 2026] [security2:error] [pid 167459:tid 167630] [client 20.100.169.31:2893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDt2r_JutbFb-8svoXiAAAAbg"] [Tue Aug 18 13:09:27.727259 2026] [security2:error] [pid 167459:tid 167497] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.profile"] [unique_id "aoSDt2r_JutbFb-8svoXiQABriU"] [Tue Aug 18 13:09:27.746852 2026] [security2:error] [pid 167459:tid 167490] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSDt2r_JutbFb-8svoXigABoR4"] [Tue Aug 18 13:09:27.765741 2026] [security2:error] [pid 167459:tid 167552] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSDt2r_JutbFb-8svoXiwABmlw"] [Tue Aug 18 13:09:27.781454 2026] [security2:error] [pid 167459:tid 167576] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "aoSDt2r_JutbFb-8svoXjAAB-nQ"] [Tue Aug 18 13:09:27.783176 2026] [security2:error] [pid 167459:tid 167595] [client 20.1.169.243:10182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/gulu.php"] [unique_id "aoSDt2r_JutbFb-8svoXjQAAAZU"] [Tue Aug 18 13:09:27.800491 2026] [security2:error] [pid 167459:tid 167543] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-settings.php"] [unique_id "aoSDt2r_JutbFb-8svoXjgAB-1M"] [Tue Aug 18 13:09:27.805951 2026] [security2:error] [pid 167459:tid 167540] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/laravel/.env"] [unique_id "aoSDt2r_JutbFb-8svoXkQACA1A"] [Tue Aug 18 13:09:27.819907 2026] [security2:error] [pid 167459:tid 167488] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/.env.php"] [unique_id "aoSDt2r_JutbFb-8svoXkgAB8hw"] [Tue Aug 18 13:09:27.836784 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:4614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ib.php"] [unique_id "aoSDt2r_JutbFb-8svoXkwAAAd4"] [Tue Aug 18 13:09:27.846842 2026] [security2:error] [pid 167459:tid 167713] [client 172.182.217.32:15758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/f35.php"] [unique_id "aoSDt2r_JutbFb-8svoXlAAAAgs"] [Tue Aug 18 13:09:27.851665 2026] [security2:error] [pid 167459:tid 167677] [client 20.250.13.23:5329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/lite.php"] [unique_id "aoSDt2r_JutbFb-8svoXlQAAAec"] [Tue Aug 18 13:09:27.869963 2026] [security2:error] [pid 167459:tid 167513] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDt2r_JutbFb-8svoXlgABzzU"] [Tue Aug 18 13:09:27.877113 2026] [security2:error] [pid 167459:tid 167674] [client 74.248.133.44:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDt2r_JutbFb-8svoXlwAAAeQ"] [Tue Aug 18 13:09:27.904244 2026] [security2:error] [pid 167459:tid 167544] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/database.yml"] [unique_id "aoSDt2r_JutbFb-8svoXmgAB6FQ"] [Tue Aug 18 13:09:27.912900 2026] [security2:error] [pid 167459:tid 167691] [client 20.38.3.247:37977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/abcd.php"] [unique_id "aoSDt2r_JutbFb-8svoXmwAAAfU"] [Tue Aug 18 13:09:27.913268 2026] [security2:error] [pid 167459:tid 167692] [client 20.116.17.175:22766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/uploads/panel.php"] [unique_id "aoSDt2r_JutbFb-8svoXnAAAAfY"] [Tue Aug 18 13:09:27.918102 2026] [security2:error] [pid 167459:tid 167557] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/auth.json"] [unique_id "aoSDt2r_JutbFb-8svoXnQABtWE"] [Tue Aug 18 13:09:27.924007 2026] [security2:error] [pid 167459:tid 167643] [client 168.62.48.100:16459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSDt2r_JutbFb-8svoXngAAAcU"] [Tue Aug 18 13:09:27.933805 2026] [security2:error] [pid 167459:tid 167478] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/.well-known/wp-signup.php"] [unique_id "aoSDt2r_JutbFb-8svoXnwABxxI"] [Tue Aug 18 13:09:27.942599 2026] [security2:error] [pid 167459:tid 167528] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.php.bak"] [unique_id "aoSDt2r_JutbFb-8svoXoQAB8EQ"] [Tue Aug 18 13:09:27.954107 2026] [security2:error] [pid 167459:tid 167510] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSDt2r_JutbFb-8svoXogABnzI"] [Tue Aug 18 13:09:27.974349 2026] [security2:error] [pid 167459:tid 167519] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.dev"] [unique_id "aoSDt2r_JutbFb-8svoXowAB9Ds"] [Tue Aug 18 13:09:27.978318 2026] [security2:error] [pid 167459:tid 167619] [client 172.213.243.2:14751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/8.php"] [unique_id "aoSDt2r_JutbFb-8svoXpAAAAa0"] [Tue Aug 18 13:09:27.994274 2026] [security2:error] [pid 167459:tid 167685] [client 20.100.169.31:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDt2r_JutbFb-8svoXpgAAAe8"] [Tue Aug 18 13:09:28.011133 2026] [security2:error] [pid 167459:tid 167509] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.swp"] [unique_id "aoSDuGr_JutbFb-8svoXpwABrDE"] [Tue Aug 18 13:09:28.019546 2026] [security2:error] [pid 167459:tid 167603] [client 158.23.17.4:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/bh.php"] [unique_id "aoSDuGr_JutbFb-8svoXqAAAAZ0"] [Tue Aug 18 13:09:28.051916 2026] [security2:error] [pid 167459:tid 167601] [client 213.35.127.232:60109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDuGr_JutbFb-8svoXqQAAAZs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:28.053706 2026] [security2:error] [pid 167459:tid 167581] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/public/.env"] [unique_id "aoSDuGr_JutbFb-8svoXqgACCHk"] [Tue Aug 18 13:09:28.055448 2026] [security2:error] [pid 167459:tid 167590] [client 74.248.18.37:3339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDuGr_JutbFb-8svoXqwAAAZA"] [Tue Aug 18 13:09:28.063386 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSDuGr_JutbFb-8svoXrAAAAgU"] [Tue Aug 18 13:09:28.065637 2026] [security2:error] [pid 167459:tid 167462] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/web/.env"] [unique_id "aoSDuGr_JutbFb-8svoXrQAB5gI"] [Tue Aug 18 13:09:28.066159 2026] [security2:error] [pid 167459:tid 167507] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/002.php"] [unique_id "aoSDuGr_JutbFb-8svoXrgABjy8"] [Tue Aug 18 13:09:28.073409 2026] [security2:error] [pid 167459:tid 167716] [client 4.232.151.198:29441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-config.php"] [unique_id "aoSDuGr_JutbFb-8svoXsAAAAg4"] [Tue Aug 18 13:09:28.074489 2026] [security2:error] [pid 167459:tid 167642] [client 74.249.206.207:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/wpxml.php"] [unique_id "aoSDuGr_JutbFb-8svoXsQAAAcQ"] [Tue Aug 18 13:09:28.083512 2026] [security2:error] [pid 167459:tid 167585] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/application.yml"] [unique_id "aoSDuGr_JutbFb-8svoXsgAB4X0"] [Tue Aug 18 13:09:28.104978 2026] [security2:error] [pid 167459:tid 167629] [client 20.91.215.254:16854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/222.php"] [unique_id "aoSDuGr_JutbFb-8svoXtQAAAbc"] [Tue Aug 18 13:09:28.122226 2026] [security2:error] [pid 167459:tid 167611] [client 52.139.47.57:18553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/404.php"] [unique_id "aoSDuGr_JutbFb-8svoXtgAAAaU"] [Tue Aug 18 13:09:28.122695 2026] [security2:error] [pid 167459:tid 167480] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/aws-config.js"] [unique_id "aoSDuGr_JutbFb-8svoXtwABpxQ"] [Tue Aug 18 13:09:28.125998 2026] [security2:error] [pid 167459:tid 167661] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.tinna.com.br"] [uri "/index.php"] [unique_id "aoSDt2r_JutbFb-8svoXMAAAAdc"], referer: http://blog.tinna.com.br [Tue Aug 18 13:09:28.128307 2026] [security2:error] [pid 167459:tid 167534] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/application.properties"] [unique_id "aoSDuGr_JutbFb-8svoXuAAB30o"] [Tue Aug 18 13:09:28.146844 2026] [security2:error] [pid 167459:tid 167686] [client 20.250.13.23:18123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDuGr_JutbFb-8svoXuQAAAfA"] [Tue Aug 18 13:09:28.160743 2026] [security2:error] [pid 167459:tid 167624] [client 20.1.169.243:9699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/hello.php"] [unique_id "aoSDuGr_JutbFb-8svoXuwAAAbI"] [Tue Aug 18 13:09:28.175939 2026] [security2:error] [pid 167459:tid 167646] [client 168.62.48.100:4035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSDuGr_JutbFb-8svoXvQAAAcg"] [Tue Aug 18 13:09:28.178055 2026] [security2:error] [pid 167459:tid 167476] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/application.properties"] [unique_id "aoSDuGr_JutbFb-8svoXvgABqhA"] [Tue Aug 18 13:09:28.195499 2026] [security2:error] [pid 167459:tid 167638] [client 68.155.154.236:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/nwwha.php"] [unique_id "aoSDuGr_JutbFb-8svoXvwAAAcA"] [Tue Aug 18 13:09:28.199552 2026] [security2:error] [pid 167459:tid 167538] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/0x.php"] [unique_id "aoSDuGr_JutbFb-8svoXwwABoE4"] [Tue Aug 18 13:09:28.228594 2026] [security2:error] [pid 167459:tid 167561] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/bootstrap.properties"] [unique_id "aoSDuGr_JutbFb-8svoXxwAB2GU"] [Tue Aug 18 13:09:28.229624 2026] [security2:error] [pid 167459:tid 167535] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/bootstrap.yml"] [unique_id "aoSDuGr_JutbFb-8svoXyAABwks"] [Tue Aug 18 13:09:28.249909 2026] [security2:error] [pid 167459:tid 167492] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/gcp-credentials.json"] [unique_id "aoSDuGr_JutbFb-8svoXyQABpiA"] [Tue Aug 18 13:09:28.254309 2026] [security2:error] [pid 167459:tid 167655] [client 20.127.136.245:28644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSDuGr_JutbFb-8svoXygAAAdE"] [Tue Aug 18 13:09:28.282962 2026] [security2:error] [pid 167459:tid 167477] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/secrets.yml"] [unique_id "aoSDuGr_JutbFb-8svoXzAAB1BE"] [Tue Aug 18 13:09:28.294863 2026] [security2:error] [pid 167459:tid 167541] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase.json"] [unique_id "aoSDuGr_JutbFb-8svoXzQAB0FE"] [Tue Aug 18 13:09:28.299291 2026] [security2:error] [pid 167459:tid 167656] [client 158.23.17.4:56553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ts.php"] [unique_id "aoSDuGr_JutbFb-8svoXzgAAAdI"] [Tue Aug 18 13:09:28.331099 2026] [security2:error] [pid 167459:tid 167503] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/actuator/env"] [unique_id "aoSDuGr_JutbFb-8svoXzwACDSs"] [Tue Aug 18 13:09:28.333264 2026] [security2:error] [pid 167459:tid 167586] [remote 20.119.58.187:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSDuGr_JutbFb-8svoX0AABnH4"] [Tue Aug 18 13:09:28.333380 2026] [security2:error] [pid 167459:tid 167586] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/1.php"] [unique_id "aoSDuGr_JutbFb-8svoX0AABnH4"] [Tue Aug 18 13:09:28.334898 2026] [security2:error] [pid 167459:tid 167670] [client 172.182.217.32:15575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/fff.php"] [unique_id "aoSDuGr_JutbFb-8svoX0QAAAeA"] [Tue Aug 18 13:09:28.366904 2026] [security2:error] [pid 167459:tid 167650] [client 20.100.169.31:52416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viacentroveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoX0wAAAcw"] [Tue Aug 18 13:09:28.373994 2026] [security2:error] [pid 167459:tid 167521] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/gradle.properties"] [unique_id "aoSDuGr_JutbFb-8svoX1AABlT0"] [Tue Aug 18 13:09:28.373997 2026] [security2:error] [pid 167459:tid 167550] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/google-service-account.json"] [unique_id "aoSDuGr_JutbFb-8svoX1QABlVo"] [Tue Aug 18 13:09:28.389904 2026] [security2:error] [pid 167459:tid 167688] [client 172.213.243.2:16883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/koiy.php"] [unique_id "aoSDuGr_JutbFb-8svoX1wAAAfI"] [Tue Aug 18 13:09:28.396290 2026] [security2:error] [pid 167459:tid 167713] [client 158.23.17.4:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xm.php"] [unique_id "aoSDuGr_JutbFb-8svoX2AAAAgs"] [Tue Aug 18 13:09:28.411906 2026] [security2:error] [pid 167459:tid 167495] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.gradle/gradle.properties"] [unique_id "aoSDuGr_JutbFb-8svoX2gABlCM"] [Tue Aug 18 13:09:28.426918 2026] [security2:error] [pid 167459:tid 167591] [client 40.74.65.169:5693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDuGr_JutbFb-8svoX2wAAAZE"] [Tue Aug 18 13:09:28.438785 2026] [security2:error] [pid 167459:tid 167644] [client 20.116.17.175:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-rrtx.php"] [unique_id "aoSDuGr_JutbFb-8svoX3AAAAcY"] [Tue Aug 18 13:09:28.447505 2026] [security2:error] [pid 167459:tid 167491] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/push_config.json"] [unique_id "aoSDuGr_JutbFb-8svoX3gABzx8"] [Tue Aug 18 13:09:28.456674 2026] [security2:error] [pid 167459:tid 167517] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/firebase-admin.json"] [unique_id "aoSDuGr_JutbFb-8svoX4AAB3Dk"] [Tue Aug 18 13:09:28.462199 2026] [security2:error] [pid 167459:tid 167674] [client 20.104.49.167:8621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDuGr_JutbFb-8svoX3wAAAeQ"] [Tue Aug 18 13:09:28.464376 2026] [security2:error] [pid 167459:tid 167678] [client 20.171.51.14:2606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kj.php"] [unique_id "aoSDuGr_JutbFb-8svoX4QAAAeg"] [Tue Aug 18 13:09:28.470788 2026] [security2:error] [pid 167459:tid 167493] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/100.php"] [unique_id "aoSDuGr_JutbFb-8svoX4gAB1iE"] [Tue Aug 18 13:09:28.472749 2026] [security2:error] [pid 167459:tid 167684] [client 102.213.179.104:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoX4wAAAe4"] [Tue Aug 18 13:09:28.472840 2026] [security2:error] [pid 167459:tid 167684] [client 102.213.179.104:62322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoX4wAAAe4"] [Tue Aug 18 13:09:28.478054 2026] [security2:error] [pid 167459:tid 167692] [client 168.62.48.100:4090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSDuGr_JutbFb-8svoX5AAAAfY"] [Tue Aug 18 13:09:28.481425 2026] [security2:error] [pid 167459:tid 167627] [client 20.38.3.247:24407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/simple.php"] [unique_id "aoSDuGr_JutbFb-8svoX5gAAAbU"] [Tue Aug 18 13:09:28.486423 2026] [security2:error] [pid 167459:tid 167582] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/gc-service.json"] [unique_id "aoSDuGr_JutbFb-8svoX5wABxXo"] [Tue Aug 18 13:09:28.491085 2026] [security2:error] [pid 167459:tid 167657] [client 20.250.13.23:23289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSDuGr_JutbFb-8svoX6AAAAdM"] [Tue Aug 18 13:09:28.492841 2026] [security2:error] [pid 167459:tid 167597] [client 20.65.98.162:36619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/signon.php"] [unique_id "aoSDuGr_JutbFb-8svoX6QAAAZc"] [Tue Aug 18 13:09:28.516927 2026] [security2:error] [pid 167459:tid 167683] [client 4.232.151.198:44141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-good.php"] [unique_id "aoSDuGr_JutbFb-8svoX6wAAAe0"] [Tue Aug 18 13:09:28.532698 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:10292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSDuGr_JutbFb-8svoX7gAAAfM"] [Tue Aug 18 13:09:28.534134 2026] [security2:error] [pid 167459:tid 167614] [client 52.139.47.57:18559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/4mosan.php"] [unique_id "aoSDuGr_JutbFb-8svoX7wAAAag"] [Tue Aug 18 13:09:28.540696 2026] [security2:error] [pid 167459:tid 167474] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/awsConfig.js"] [unique_id "aoSDuGr_JutbFb-8svoX8AAB4g4"] [Tue Aug 18 13:09:28.542953 2026] [security2:error] [pid 167459:tid 167496] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/gcp-service.json"] [unique_id "aoSDuGr_JutbFb-8svoX8QABvCQ"] [Tue Aug 18 13:09:28.559244 2026] [security2:error] [pid 167459:tid 167565] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/values.yaml"] [unique_id "aoSDuGr_JutbFb-8svoX8gABrGk"] [Tue Aug 18 13:09:28.570240 2026] [security2:error] [pid 167459:tid 167596] [client 158.23.17.4:20416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/ct.php"] [unique_id "aoSDuGr_JutbFb-8svoX8wAAAZY"] [Tue Aug 18 13:09:28.604259 2026] [security2:error] [pid 167459:tid 167539] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/google-services.json"] [unique_id "aoSDuGr_JutbFb-8svoX9AAB6k8"] [Tue Aug 18 13:09:28.605165 2026] [security2:error] [pid 167459:tid 167566] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/2.php"] [unique_id "aoSDuGr_JutbFb-8svoX9QACAmo"] [Tue Aug 18 13:09:28.615144 2026] [security2:error] [pid 167459:tid 167506] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/docker-compose.yaml"] [unique_id "aoSDuGr_JutbFb-8svoX9wABsS4"] [Tue Aug 18 13:09:28.626117 2026] [security2:error] [pid 167459:tid 167675] [client 68.155.154.236:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/opsqt.php"] [unique_id "aoSDuGr_JutbFb-8svoX-QAAAeU"] [Tue Aug 18 13:09:28.632577 2026] [security2:error] [pid 167459:tid 167637] [client 20.104.100.201:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/srontol.php"] [unique_id "aoSDuGr_JutbFb-8svoX-gAAAb8"] [Tue Aug 18 13:09:28.633550 2026] [security2:error] [pid 167459:tid 167467] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/__/firebase/init.json"] [unique_id "aoSDuGr_JutbFb-8svoX-wABtwc"] [Tue Aug 18 13:09:28.641679 2026] [security2:error] [pid 167459:tid 167554] [remote 188.164.197.230:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guelraott.com"] [uri "/wp-login.php"] [unique_id "aoSDuGr_JutbFb-8svoX_AAB-l4"] [Tue Aug 18 13:09:28.693014 2026] [security2:error] [pid 167459:tid 167703] [client 74.248.18.37:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSDuGr_JutbFb-8svoX_wAAAgE"] [Tue Aug 18 13:09:28.694929 2026] [security2:error] [pid 167459:tid 167527] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/debug/pprof/"] [unique_id "aoSDuGr_JutbFb-8svoYAAABukM"] [Tue Aug 18 13:09:28.702807 2026] [security2:error] [pid 167459:tid 167645] [client 4.232.151.198:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-conflg.php"] [unique_id "aoSDuGr_JutbFb-8svoYAQAAAcc"] [Tue Aug 18 13:09:28.704494 2026] [security2:error] [pid 167459:tid 167516] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/master.key"] [unique_id "aoSDuGr_JutbFb-8svoYAgAB4zg"] [Tue Aug 18 13:09:28.714811 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:28.715048 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:28.720708 2026] [security2:error] [pid 167459:tid 167593] [client 157.20.138.62:60898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoYBQAAAZM"] [Tue Aug 18 13:09:28.720818 2026] [security2:error] [pid 167459:tid 167593] [client 157.20.138.62:60898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoYBQAAAZM"] [Tue Aug 18 13:09:28.720990 2026] [security2:error] [pid 167459:tid 167522] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/debug/pprof/cmdline"] [unique_id "aoSDuGr_JutbFb-8svoYBwAByD4"] [Tue Aug 18 13:09:28.739138 2026] [security2:error] [pid 167459:tid 167548] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/222.php"] [unique_id "aoSDuGr_JutbFb-8svoYCQACAFg"] [Tue Aug 18 13:09:28.753765 2026] [security2:error] [pid 167459:tid 167610] [client 178.153.171.161:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoYCgAAAaQ"] [Tue Aug 18 13:09:28.753900 2026] [security2:error] [pid 167459:tid 167610] [client 178.153.171.161:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuGr_JutbFb-8svoYCgAAAaQ"] [Tue Aug 18 13:09:28.763791 2026] [security2:error] [pid 167459:tid 167603] [client 20.250.13.23:18116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSDuGr_JutbFb-8svoYCwAAAZ0"] [Tue Aug 18 13:09:28.765755 2026] [security2:error] [pid 167459:tid 167501] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/storage.yml"] [unique_id "aoSDuGr_JutbFb-8svoYDAABwCk"] [Tue Aug 18 13:09:28.773841 2026] [security2:error] [pid 167459:tid 167529] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.json"] [unique_id "aoSDuGr_JutbFb-8svoYDQAB2kU"] [Tue Aug 18 13:09:28.774834 2026] [security2:error] [pid 167459:tid 167524] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/debug/vars"] [unique_id "aoSDuGr_JutbFb-8svoYDgABoEA"] [Tue Aug 18 13:09:28.810581 2026] [security2:error] [pid 167459:tid 167682] [client 172.213.243.2:17918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/iko.php"] [unique_id "aoSDuGr_JutbFb-8svoYEQAAAew"] [Tue Aug 18 13:09:28.819310 2026] [security2:error] [pid 167459:tid 167613] [client 172.182.217.32:15788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ff1.php"] [unique_id "aoSDuGr_JutbFb-8svoYEgAAAac"] [Tue Aug 18 13:09:28.819883 2026] [security2:error] [pid 167459:tid 167671] [client 20.91.215.254:16884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/aa.php"] [unique_id "aoSDuGr_JutbFb-8svoYEwAAAeE"] [Tue Aug 18 13:09:28.827530 2026] [security2:error] [pid 167459:tid 167655] [client 168.62.48.100:3999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSDuGr_JutbFb-8svoYFAAAAdE"] [Tue Aug 18 13:09:28.851888 2026] [security2:error] [pid 167459:tid 167515] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/settings.py"] [unique_id "aoSDuGr_JutbFb-8svoYFQABojc"] [Tue Aug 18 13:09:28.859514 2026] [security2:error] [pid 167459:tid 167479] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.js"] [unique_id "aoSDuGr_JutbFb-8svoYFgABqRM"] [Tue Aug 18 13:09:28.881069 2026] [security2:error] [pid 167459:tid 167570] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/metrics"] [unique_id "aoSDuGr_JutbFb-8svoYFwABy24"] [Tue Aug 18 13:09:28.881905 2026] [security2:error] [pid 167459:tid 167549] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/3pjcpmfsd8b.php"] [unique_id "aoSDuGr_JutbFb-8svoYGAABrlk"] [Tue Aug 18 13:09:28.914437 2026] [security2:error] [pid 167459:tid 167662] [client 20.1.169.243:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/images/class-config.php"] [unique_id "aoSDuGr_JutbFb-8svoYGgAAAdg"] [Tue Aug 18 13:09:28.938119 2026] [security2:error] [pid 167459:tid 167587] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/config"] [unique_id "aoSDuGr_JutbFb-8svoYGwAB4H8"] [Tue Aug 18 13:09:28.942554 2026] [security2:error] [pid 167459:tid 167511] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.pypirc"] [unique_id "aoSDuGr_JutbFb-8svoYHQABzDM"] [Tue Aug 18 13:09:28.956822 2026] [security2:error] [pid 167459:tid 167487] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.yaml"] [unique_id "aoSDuGr_JutbFb-8svoYHgABlRs"] [Tue Aug 18 13:09:28.957409 2026] [security2:error] [pid 167459:tid 167612] [client 52.139.47.57:35323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/504.php"] [unique_id "aoSDuGr_JutbFb-8svoYHwAAAaY"] [Tue Aug 18 13:09:28.993293 2026] [security2:error] [pid 167459:tid 167594] [client 74.248.133.44:12953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/o.php"] [unique_id "aoSDuGr_JutbFb-8svoYIQAAAZQ"] [Tue Aug 18 13:09:29.014661 2026] [security2:error] [pid 167459:tid 167473] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/settings"] [unique_id "aoSDuWr_JutbFb-8svoYJAABkQ0"] [Tue Aug 18 13:09:29.016301 2026] [security2:error] [pid 167459:tid 167525] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/403.php"] [unique_id "aoSDuWr_JutbFb-8svoYJQABxkE"] [Tue Aug 18 13:09:29.023850 2026] [security2:error] [pid 167459:tid 167674] [client 158.23.17.4:42585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/53.php"] [unique_id "aoSDuWr_JutbFb-8svoYJgAAAeQ"] [Tue Aug 18 13:09:29.040916 2026] [security2:error] [pid 167459:tid 167542] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.streamlit/secrets.toml"] [unique_id "aoSDuWr_JutbFb-8svoYJwAB7lI"] [Tue Aug 18 13:09:29.055275 2026] [security2:error] [pid 167459:tid 167578] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.toml"] [unique_id "aoSDuWr_JutbFb-8svoYKAABzXY"] [Tue Aug 18 13:09:29.055675 2026] [security2:error] [pid 167459:tid 167692] [client 20.38.3.247:2457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDuWr_JutbFb-8svoYKQAAAfY"] [Tue Aug 18 13:09:29.074412 2026] [security2:error] [pid 167459:tid 167698] [client 213.35.127.232:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDuWr_JutbFb-8svoYKgAAAfw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:29.078620 2026] [security2:error] [pid 167459:tid 167481] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/v1/settings"] [unique_id "aoSDuWr_JutbFb-8svoYLAABxRU"] [Tue Aug 18 13:09:29.079935 2026] [security2:error] [pid 167459:tid 167657] [client 20.151.109.219:33848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/jn.php"] [unique_id "aoSDuWr_JutbFb-8svoYLQAAAdM"] [Tue Aug 18 13:09:29.081322 2026] [security2:error] [pid 167459:tid 167597] [client 20.127.136.245:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSDuWr_JutbFb-8svoYLgAAAZc"] [Tue Aug 18 13:09:29.093466 2026] [security2:error] [pid 167459:tid 167483] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/settings.py"] [unique_id "aoSDuWr_JutbFb-8svoYLwAB9Bc"] [Tue Aug 18 13:09:29.113263 2026] [security2:error] [pid 167459:tid 167504] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/dashboard"] [unique_id "aoSDuWr_JutbFb-8svoYMAAB8yw"] [Tue Aug 18 13:09:29.113686 2026] [security2:error] [pid 167459:tid 167631] [client 168.62.48.100:16479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/well-known/index.php"] [unique_id "aoSDuWr_JutbFb-8svoYMQAAAbk"] [Tue Aug 18 13:09:29.114013 2026] [security2:error] [pid 167459:tid 167693] [client 20.250.13.23:5352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSDuWr_JutbFb-8svoYMgAAAfc"] [Tue Aug 18 13:09:29.148667 2026] [security2:error] [pid 167459:tid 167601] [client 158.23.17.4:38359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/zy.php"] [unique_id "aoSDuWr_JutbFb-8svoYMwAAAZs"] [Tue Aug 18 13:09:29.150526 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/404.php"] [unique_id "aoSDuWr_JutbFb-8svoYNAAByhk"] [Tue Aug 18 13:09:29.160993 2026] [security2:error] [pid 167459:tid 167590] [client 68.155.154.236:25351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/jvcpa.php"] [unique_id "aoSDuWr_JutbFb-8svoYNgAAAZA"] [Tue Aug 18 13:09:29.161124 2026] [security2:error] [pid 167459:tid 167708] [client 20.116.17.175:52591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/gecko-new.php"] [unique_id "aoSDuWr_JutbFb-8svoYNwAAAgY"] [Tue Aug 18 13:09:29.168407 2026] [security2:error] [pid 167459:tid 167676] [client 20.203.183.135:64773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDuWr_JutbFb-8svoYOAAAAeY"] [Tue Aug 18 13:09:29.181610 2026] [security2:error] [pid 167459:tid 167642] [client 20.104.100.201:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/file5.php"] [unique_id "aoSDuWr_JutbFb-8svoYOgAAAcQ"] [Tue Aug 18 13:09:29.184097 2026] [security2:error] [pid 167459:tid 167558] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/settings.json"] [unique_id "aoSDuWr_JutbFb-8svoYOwAB6mI"] [Tue Aug 18 13:09:29.198024 2026] [security2:error] [pid 167459:tid 167562] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/core/settings.py"] [unique_id "aoSDuWr_JutbFb-8svoYPgABt2Y"] [Tue Aug 18 13:09:29.205594 2026] [security2:error] [pid 167459:tid 167630] [client 213.202.253.4:64716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/userfuns.php"] [unique_id "aoSDuWr_JutbFb-8svoYQAAAAbg"], referer: www.google.com [Tue Aug 18 13:09:29.223891 2026] [security2:error] [pid 167459:tid 167564] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/info"] [unique_id "aoSDuWr_JutbFb-8svoYQwAB8Gg"] [Tue Aug 18 13:09:29.225317 2026] [security2:error] [pid 167459:tid 167703] [client 172.213.243.2:37092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/raw.php"] [unique_id "aoSDuWr_JutbFb-8svoYRAAAAgE"] [Tue Aug 18 13:09:29.244546 2026] [security2:error] [pid 167459:tid 167471] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/env.js"] [unique_id "aoSDuWr_JutbFb-8svoYRQAB4ws"] [Tue Aug 18 13:09:29.247292 2026] [security2:error] [pid 167459:tid 167500] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/app/settings.py"] [unique_id "aoSDuWr_JutbFb-8svoYRgAB9Sg"] [Tue Aug 18 13:09:29.274376 2026] [security2:error] [pid 167459:tid 167461] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/_health"] [unique_id "aoSDuWr_JutbFb-8svoYSAABpAE"] [Tue Aug 18 13:09:29.286759 2026] [security2:error] [pid 167459:tid 167537] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/4mosan.php"] [unique_id "aoSDuWr_JutbFb-8svoYSQABwE0"] [Tue Aug 18 13:09:29.321578 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:29.321853 2026] [authz_core:error] [pid 167459:tid 167536] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:29.333260 2026] [security2:error] [pid 167459:tid 167575] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/runtime.exs"] [unique_id "aoSDuWr_JutbFb-8svoYTAABwnM"] [Tue Aug 18 13:09:29.335879 2026] [security2:error] [pid 167459:tid 167618] [client 172.182.217.32:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/flower.php"] [unique_id "aoSDuWr_JutbFb-8svoYTQAAAaw"] [Tue Aug 18 13:09:29.344899 2026] [security2:error] [pid 167459:tid 167614] [client 74.248.18.37:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDuWr_JutbFb-8svoYTgAAAag"] [Tue Aug 18 13:09:29.353980 2026] [security2:error] [pid 167459:tid 167498] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/appsettings.json"] [unique_id "aoSDuWr_JutbFb-8svoYUAAB4SY"] [Tue Aug 18 13:09:29.368265 2026] [security2:error] [pid 167459:tid 167655] [client 20.65.98.162:40218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/file61.php"] [unique_id "aoSDuWr_JutbFb-8svoYUQAAAdE"] [Tue Aug 18 13:09:29.372510 2026] [security2:error] [pid 167459:tid 167497] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config/prod.exs"] [unique_id "aoSDuWr_JutbFb-8svoYUgAB6SU"] [Tue Aug 18 13:09:29.379158 2026] [security2:error] [pid 167459:tid 167645] [client 52.139.47.57:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/7.php"] [unique_id "aoSDuWr_JutbFb-8svoYUwAAAcc"] [Tue Aug 18 13:09:29.392236 2026] [security2:error] [pid 167459:tid 167687] [client 168.62.48.100:16503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSDuWr_JutbFb-8svoYVgAAAfE"] [Tue Aug 18 13:09:29.406646 2026] [security2:error] [pid 167459:tid 167490] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/aws-exports.js"] [unique_id "aoSDuWr_JutbFb-8svoYWAAByx4"] [Tue Aug 18 13:09:29.412493 2026] [security2:error] [pid 167459:tid 167552] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/backend/settings.py"] [unique_id "aoSDuWr_JutbFb-8svoYWQABrlw"] [Tue Aug 18 13:09:29.416437 2026] [security2:error] [pid 167459:tid 167697] [client 20.1.169.243:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/images/index.php"] [unique_id "aoSDuWr_JutbFb-8svoYWgAAAfs"] [Tue Aug 18 13:09:29.420133 2026] [security2:error] [pid 167459:tid 167531] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/504.php"] [unique_id "aoSDuWr_JutbFb-8svoYWwABoUc"] [Tue Aug 18 13:09:29.429039 2026] [security2:error] [pid 167459:tid 167596] [client 4.232.151.198:47177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-content.php"] [unique_id "aoSDuWr_JutbFb-8svoYXAAAAZY"] [Tue Aug 18 13:09:29.429260 2026] [security2:error] [pid 167459:tid 167576] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/appsettings.Development.json"] [unique_id "aoSDuWr_JutbFb-8svoYXQABmnQ"] [Tue Aug 18 13:09:29.430092 2026] [autoindex:error] [pid 167459:tid 167716] [client 20.250.13.23:5335] AH01276: Cannot serve directory /home4/alltime/public_html/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:29.449471 2026] [security2:error] [pid 167459:tid 167632] [client 20.91.215.254:22321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/abcd.php"] [unique_id "aoSDuWr_JutbFb-8svoYXwAAAbo"] [Tue Aug 18 13:09:29.483107 2026] [security2:error] [pid 167459:tid 167650] [client 20.38.3.247:21261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/xiugai.php"] [unique_id "aoSDuWr_JutbFb-8svoYYAAAAcw"] [Tue Aug 18 13:09:29.499566 2026] [security2:error] [pid 167459:tid 167547] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/amplifyconfiguration.json"] [unique_id "aoSDuWr_JutbFb-8svoYYQAB3Vc"] [Tue Aug 18 13:09:29.515018 2026] [security2:error] [pid 167459:tid 167540] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/firebase-config.json"] [unique_id "aoSDuWr_JutbFb-8svoYYwAB3lA"] [Tue Aug 18 13:09:29.515494 2026] [security2:error] [pid 167459:tid 167488] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.py"] [unique_id "aoSDuWr_JutbFb-8svoYZAAB3hw"] [Tue Aug 18 13:09:29.554310 2026] [security2:error] [pid 167459:tid 167533] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/7.php"] [unique_id "aoSDuWr_JutbFb-8svoYbAAB7kk"] [Tue Aug 18 13:09:29.572391 2026] [security2:error] [pid 167459:tid 167478] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/env.json"] [unique_id "aoSDuWr_JutbFb-8svoYbgABzRI"] [Tue Aug 18 13:09:29.575967 2026] [security2:error] [pid 167459:tid 167692] [client 158.23.17.4:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/gy.php"] [unique_id "aoSDuWr_JutbFb-8svoYbwAAAfY"] [Tue Aug 18 13:09:29.577311 2026] [security2:error] [pid 167459:tid 167528] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/instance/config.py"] [unique_id "aoSDuWr_JutbFb-8svoYcAABtUQ"] [Tue Aug 18 13:09:29.601641 2026] [security2:error] [pid 167459:tid 167643] [client 20.203.183.135:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDuWr_JutbFb-8svoYcgAAAcU"] [Tue Aug 18 13:09:29.634028 2026] [security2:error] [pid 167459:tid 167657] [client 20.250.13.23:5335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/ku.php"] [unique_id "aoSDuWr_JutbFb-8svoYdAAAAdM"] [Tue Aug 18 13:09:29.636095 2026] [security2:error] [pid 167459:tid 167597] [client 20.171.51.14:2344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/vg.php"] [unique_id "aoSDuWr_JutbFb-8svoYdQAAAZc"] [Tue Aug 18 13:09:29.637132 2026] [security2:error] [pid 167459:tid 167605] [client 172.213.243.2:11603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/05.php"] [unique_id "aoSDuWr_JutbFb-8svoYdgAAAZ8"] [Tue Aug 18 13:09:29.649785 2026] [security2:error] [pid 167459:tid 167556] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.development"] [unique_id "aoSDuWr_JutbFb-8svoYeAABrWA"] [Tue Aug 18 13:09:29.659228 2026] [security2:error] [pid 167459:tid 167689] [client 158.23.17.4:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/lq.php"] [unique_id "aoSDuWr_JutbFb-8svoYegAAAfM"] [Tue Aug 18 13:09:29.662632 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.49.167:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDuWr_JutbFb-8svoYewAAAfc"] [Tue Aug 18 13:09:29.682431 2026] [security2:error] [pid 167459:tid 167581] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.well-known/jwks.json"] [unique_id "aoSDuWr_JutbFb-8svoYfAABm3k"] [Tue Aug 18 13:09:29.687348 2026] [security2:error] [pid 167459:tid 167530] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/8.php"] [unique_id "aoSDuWr_JutbFb-8svoYfQABykY"] [Tue Aug 18 13:09:29.700289 2026] [security2:error] [pid 167459:tid 167710] [client 40.74.65.169:5692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDuWr_JutbFb-8svoYfgAAAgg"] [Tue Aug 18 13:09:29.726057 2026] [security2:error] [pid 167459:tid 167507] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.staging"] [unique_id "aoSDuWr_JutbFb-8svoYgAAB5i8"] [Tue Aug 18 13:09:29.727651 2026] [security2:error] [pid 167459:tid 167591] [client 20.250.13.23:23234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSDuWr_JutbFb-8svoYgQAAAZE"] [Tue Aug 18 13:09:29.730021 2026] [security2:error] [pid 167459:tid 167642] [client 168.62.48.100:16411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDuWr_JutbFb-8svoYggAAAcQ"] [Tue Aug 18 13:09:29.752521 2026] [security2:error] [pid 167459:tid 167534] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/v2/config"] [unique_id "aoSDuWr_JutbFb-8svoYhQAB50o"] [Tue Aug 18 13:09:29.768056 2026] [security2:error] [pid 167459:tid 167523] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/.env.test"] [unique_id "aoSDuWr_JutbFb-8svoYhgAB5T8"] [Tue Aug 18 13:09:29.768672 2026] [security2:error] [pid 167459:tid 167476] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/v1/config"] [unique_id "aoSDuWr_JutbFb-8svoYhwABvxA"] [Tue Aug 18 13:09:29.783599 2026] [security2:error] [pid 167459:tid 167652] [client 68.155.154.236:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSDuWr_JutbFb-8svoYiQAAAc4"] [Tue Aug 18 13:09:29.787643 2026] [security2:error] [pid 167459:tid 167672] [client 20.1.169.243:9727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/index/function.php"] [unique_id "aoSDuWr_JutbFb-8svoYigAAAeI"] [Tue Aug 18 13:09:29.793705 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/8.php"] [unique_id "aoSDuWr_JutbFb-8svoYiwAAAe0"] [Tue Aug 18 13:09:29.796036 2026] [security2:error] [pid 167459:tid 167639] [client 74.248.18.37:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDuWr_JutbFb-8svoYjAAAAcE"] [Tue Aug 18 13:09:29.815587 2026] [security2:error] [pid 167459:tid 167499] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/env"] [unique_id "aoSDuWr_JutbFb-8svoYjQAB3yc"] [Tue Aug 18 13:09:29.819733 2026] [security2:error] [pid 167459:tid 167631] [client 172.182.217.32:15781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/file.php"] [unique_id "aoSDuWr_JutbFb-8svoYjgAAAbk"] [Tue Aug 18 13:09:29.820405 2026] [security2:error] [pid 167459:tid 167484] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/82.php"] [unique_id "aoSDuWr_JutbFb-8svoYjwAB8Bg"] [Tue Aug 18 13:09:29.831624 2026] [security2:error] [pid 167459:tid 167703] [client 20.116.17.175:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/df.php"] [unique_id "aoSDuWr_JutbFb-8svoYkQAAAgE"] [Tue Aug 18 13:09:29.851137 2026] [security2:error] [pid 167459:tid 167593] [client 20.127.136.245:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSDuWr_JutbFb-8svoYlAAAAZM"] [Tue Aug 18 13:09:29.871742 2026] [security2:error] [pid 167459:tid 167695] [client 74.248.133.44:35267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/theme.php"] [unique_id "aoSDuWr_JutbFb-8svoYnwAAAfk"] [Tue Aug 18 13:09:29.872127 2026] [security2:error] [pid 167459:tid 167503] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/config.env"] [unique_id "aoSDuWr_JutbFb-8svoYoAACACs"] [Tue Aug 18 13:09:29.879499 2026] [security2:error] [pid 167459:tid 167603] [client 20.38.3.247:24446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/wp-load.php"] [unique_id "aoSDuWr_JutbFb-8svoYowAAAZ0"] [Tue Aug 18 13:09:29.893499 2026] [security2:error] [pid 167459:tid 167517] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/runtime-config.js"] [unique_id "aoSDuWr_JutbFb-8svoYqQABoDk"] [Tue Aug 18 13:09:29.893514 2026] [security2:error] [pid 167459:tid 167491] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/sendgrid.env"] [unique_id "aoSDuWr_JutbFb-8svoYqgABoB8"] [Tue Aug 18 13:09:29.919667 2026] [security2:error] [pid 167459:tid 167496] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/api/v2/settings"] [unique_id "aoSDuWr_JutbFb-8svoYrwAB7CQ"] [Tue Aug 18 13:09:29.930072 2026] [authz_core:error] [pid 167459:tid 167565] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:29.930510 2026] [authz_core:error] [pid 167459:tid 167565] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:29.932110 2026] [security2:error] [pid 167459:tid 167469] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/app/.env"] [unique_id "aoSDuWr_JutbFb-8svoYsQABqAk"] [Tue Aug 18 13:09:29.942515 2026] [security2:error] [pid 167459:tid 167633] [client 101.53.230.88:49650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.230.53.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuWr_JutbFb-8svoYswAAAbs"] [Tue Aug 18 13:09:29.942630 2026] [security2:error] [pid 167459:tid 167633] [client 101.53.230.88:49650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDuWr_JutbFb-8svoYswAAAbs"] [Tue Aug 18 13:09:29.954306 2026] [security2:error] [pid 167459:tid 167539] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/a.php"] [unique_id "aoSDuWr_JutbFb-8svoYtAAB6U8"] [Tue Aug 18 13:09:29.975290 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:25363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDuWr_JutbFb-8svoYtgAAAdk"] [Tue Aug 18 13:09:29.996325 2026] [security2:error] [pid 167459:tid 167506] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/manifest.webmanifest"] [unique_id "aoSDuWr_JutbFb-8svoYtwABli4"] [Tue Aug 18 13:09:30.009093 2026] [security2:error] [pid 167459:tid 167715] [client 168.62.48.100:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSDumr_JutbFb-8svoYuQAAAg0"] [Tue Aug 18 13:09:30.019686 2026] [security2:error] [pid 167459:tid 167716] [client 20.203.183.135:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDumr_JutbFb-8svoYugAAAg4"] [Tue Aug 18 13:09:30.034431 2026] [security2:error] [pid 167459:tid 167467] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/openapi.json"] [unique_id "aoSDumr_JutbFb-8svoYuwAB2Ac"] [Tue Aug 18 13:09:30.035019 2026] [security2:error] [pid 167459:tid 167554] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/src/.env"] [unique_id "aoSDumr_JutbFb-8svoYvAABul4"] [Tue Aug 18 13:09:30.039228 2026] [security2:error] [pid 167459:tid 167527] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/frontend/.env"] [unique_id "aoSDumr_JutbFb-8svoYvgABzEM"] [Tue Aug 18 13:09:30.045208 2026] [authz_core:error] [pid 167459:tid 167505] [remote 57.141.22.48:46690] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:30.045468 2026] [authz_core:error] [pid 167459:tid 167505] [remote 57.141.22.48:46690] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:30.056161 2026] [security2:error] [pid 167459:tid 167595] [client 172.213.243.2:19733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/public/hi.php"] [unique_id "aoSDumr_JutbFb-8svoYvwAAAZU"] [Tue Aug 18 13:09:30.067769 2026] [security2:error] [pid 167459:tid 167516] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/server/.env"] [unique_id "aoSDumr_JutbFb-8svoYwAACAzg"] [Tue Aug 18 13:09:30.089004 2026] [security2:error] [pid 167459:tid 167522] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/aa.php"] [unique_id "aoSDumr_JutbFb-8svoYwQAB8j4"] [Tue Aug 18 13:09:30.089476 2026] [security2:error] [pid 167459:tid 167704] [client 213.35.127.232:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDumr_JutbFb-8svoYwgAAAgI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:30.093191 2026] [security2:error] [pid 167459:tid 167548] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/dev/.env"] [unique_id "aoSDumr_JutbFb-8svoYwwACC1g"] [Tue Aug 18 13:09:30.122697 2026] [security2:error] [pid 167459:tid 167666] [client 20.100.169.31:3362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSDumr_JutbFb-8svoYxgAAAdw"] [Tue Aug 18 13:09:30.128285 2026] [security2:error] [pid 167459:tid 167665] [client 20.91.215.254:3797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/admin.php"] [unique_id "aoSDumr_JutbFb-8svoYxwAAAds"] [Tue Aug 18 13:09:30.143873 2026] [security2:error] [pid 167459:tid 167684] [client 20.104.100.201:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/yup.php"] [unique_id "aoSDumr_JutbFb-8svoYyAAAAe4"] [Tue Aug 18 13:09:30.154739 2026] [security2:error] [pid 167459:tid 167602] [client 20.1.169.243:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/info.php"] [unique_id "aoSDumr_JutbFb-8svoYyQAAAZw"] [Tue Aug 18 13:09:30.165220 2026] [security2:error] [pid 167459:tid 167529] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/web.config"] [unique_id "aoSDumr_JutbFb-8svoYygABw0U"] [Tue Aug 18 13:09:30.189402 2026] [security2:error] [pid 167459:tid 167524] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/local.settings.json"] [unique_id "aoSDumr_JutbFb-8svoYywABl0A"] [Tue Aug 18 13:09:30.200125 2026] [security2:error] [pid 167459:tid 167515] [remote 35.192.155.163:41488] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.jotamotos.com.br"] [uri "/appsettings.Production.json"] [unique_id "aoSDumr_JutbFb-8svoYzQAB9Dc"] [Tue Aug 18 13:09:30.219303 2026] [security2:error] [pid 167459:tid 167668] [client 52.139.47.57:35265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/82.php"] [unique_id "aoSDumr_JutbFb-8svoYzgAAAd4"] [Tue Aug 18 13:09:30.223739 2026] [security2:error] [pid 167459:tid 167479] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/aaa.php"] [unique_id "aoSDumr_JutbFb-8svoYzwAB9xM"] [Tue Aug 18 13:09:30.239700 2026] [security2:error] [pid 167459:tid 167601] [client 74.249.206.207:14926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/file1221.php"] [unique_id "aoSDumr_JutbFb-8svoY0QAAAZs"] [Tue Aug 18 13:09:30.252807 2026] [security2:error] [pid 167459:tid 167710] [client 20.171.51.14:17751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/sm.php"] [unique_id "aoSDumr_JutbFb-8svoY0wAAAgg"] [Tue Aug 18 13:09:30.268176 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:54018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-good.php"] [unique_id "aoSDumr_JutbFb-8svoY1AAAAbU"] [Tue Aug 18 13:09:30.301044 2026] [autoindex:error] [pid 167459:tid 167636] [client 20.250.13.23:39241] AH01276: Cannot serve directory /home4/alltime/public_html/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:30.308460 2026] [security2:error] [pid 167459:tid 167651] [client 172.182.217.32:15754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/goods.php"] [unique_id "aoSDumr_JutbFb-8svoY1wAAAc0"] [Tue Aug 18 13:09:30.308943 2026] [security2:error] [pid 167459:tid 167623] [client 4.232.151.198:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-content/about.php"] [unique_id "aoSDumr_JutbFb-8svoY2AAAAbE"] [Tue Aug 18 13:09:30.354793 2026] [security2:error] [pid 167459:tid 167660] [client 20.250.13.23:5337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/xmrlpc.php"] [unique_id "aoSDumr_JutbFb-8svoY3AAAAdY"] [Tue Aug 18 13:09:30.358561 2026] [security2:error] [pid 167459:tid 167568] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/aar.php"] [unique_id "aoSDumr_JutbFb-8svoY3QAB7Ww"] [Tue Aug 18 13:09:30.379778 2026] [security2:error] [pid 167459:tid 167572] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDumr_JutbFb-8svoY3wABwXA"] [Tue Aug 18 13:09:30.379915 2026] [security2:error] [pid 167459:tid 167639] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDumr_JutbFb-8svoY3wABwXA"] [Tue Aug 18 13:09:30.388378 2026] [security2:error] [pid 167459:tid 167631] [client 168.62.48.100:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/mt/byp.php"] [unique_id "aoSDumr_JutbFb-8svoY4AAAAbk"] [Tue Aug 18 13:09:30.438484 2026] [security2:error] [pid 167459:tid 167695] [client 20.203.183.135:29427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/av.php"] [unique_id "aoSDumr_JutbFb-8svoY5wAAAfk"] [Tue Aug 18 13:09:30.467842 2026] [security2:error] [pid 167459:tid 167685] [client 172.213.243.2:32481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/get.php"] [unique_id "aoSDumr_JutbFb-8svoY6QAAAe8"] [Tue Aug 18 13:09:30.488128 2026] [security2:error] [pid 167459:tid 167629] [client 20.116.17.175:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSDumr_JutbFb-8svoY6wAAAbc"] [Tue Aug 18 13:09:30.489879 2026] [security2:error] [pid 167459:tid 167609] [client 68.155.154.236:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSDumr_JutbFb-8svoY7AAAAaM"] [Tue Aug 18 13:09:30.494050 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/ab.php"] [unique_id "aoSDumr_JutbFb-8svoY7QAB_hU"] [Tue Aug 18 13:09:30.506857 2026] [security2:error] [pid 167459:tid 167633] [client 20.151.109.219:46882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hmanyhands.com.br"] [uri "/bf.php"] [unique_id "aoSDumr_JutbFb-8svoY7gAAAbs"] [Tue Aug 18 13:09:30.522118 2026] [security2:error] [pid 167459:tid 167691] [client 20.1.169.243:9688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/install.php"] [unique_id "aoSDumr_JutbFb-8svoY7wAAAfU"] [Tue Aug 18 13:09:30.528626 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:30.528892 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:30.531385 2026] [security2:error] [pid 167459:tid 167714] [client 20.250.13.23:39241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/chosen.php"] [unique_id "aoSDumr_JutbFb-8svoY8gAAAgw"] [Tue Aug 18 13:09:30.538640 2026] [security2:error] [pid 167459:tid 167645] [client 158.23.17.4:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/you.php"] [unique_id "aoSDumr_JutbFb-8svoY8wAAAcc"] [Tue Aug 18 13:09:30.566171 2026] [security2:error] [pid 167459:tid 167715] [client 40.74.65.169:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDumr_JutbFb-8svoY9gAAAg0"] [Tue Aug 18 13:09:30.576470 2026] [security2:error] [pid 167459:tid 167716] [client 20.104.49.167:19609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDumr_JutbFb-8svoY9wAAAg4"] [Tue Aug 18 13:09:30.633579 2026] [security2:error] [pid 167459:tid 167667] [client 20.127.136.245:1526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSDumr_JutbFb-8svoY-wAAAd0"] [Tue Aug 18 13:09:30.637383 2026] [security2:error] [pid 167459:tid 167614] [client 52.139.47.57:18534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/a.php"] [unique_id "aoSDumr_JutbFb-8svoY_AAAAag"] [Tue Aug 18 13:09:30.649124 2026] [security2:error] [pid 167459:tid 167558] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/abc.php"] [unique_id "aoSDumr_JutbFb-8svoY_gACAmI"] [Tue Aug 18 13:09:30.690583 2026] [security2:error] [pid 167459:tid 167665] [client 158.23.17.4:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/tt.php"] [unique_id "aoSDumr_JutbFb-8svoZAAAAAds"] [Tue Aug 18 13:09:30.707308 2026] [security2:error] [pid 167459:tid 167520] [remote 152.39.227.250:37877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "infoprodutores.com"] [uri "/wp-json/pys-facebook/v1/event"] [unique_id "aoSDumr_JutbFb-8svoZAgABzzw"], referer: https://infoprodutores.com/depoimentos-codigo-da-autoridade/ [Tue Aug 18 13:09:30.726378 2026] [security2:error] [pid 167459:tid 167615] [client 20.100.169.31:18989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-fclass.php"] [unique_id "aoSDumr_JutbFb-8svoZBQAAAak"] [Tue Aug 18 13:09:30.738039 2026] [security2:error] [pid 167459:tid 167602] [client 20.171.51.14:2312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/28.php"] [unique_id "aoSDumr_JutbFb-8svoZBwAAAZw"] [Tue Aug 18 13:09:30.781383 2026] [security2:error] [pid 167459:tid 167690] [client 20.38.3.247:37982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/155.php"] [unique_id "aoSDumr_JutbFb-8svoZDgAAAfQ"] [Tue Aug 18 13:09:30.792640 2026] [security2:error] [pid 167459:tid 167465] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/abcd.php"] [unique_id "aoSDumr_JutbFb-8svoZDwAB3gU"] [Tue Aug 18 13:09:30.803340 2026] [security2:error] [pid 167459:tid 167705] [client 172.182.217.32:15589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/g.php"] [unique_id "aoSDumr_JutbFb-8svoZEAAAAgM"] [Tue Aug 18 13:09:30.805669 2026] [security2:error] [pid 167459:tid 167708] [client 74.248.18.37:25387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSDumr_JutbFb-8svoY-gAAAgY"] [Tue Aug 18 13:09:30.817016 2026] [security2:error] [pid 167459:tid 167601] [client 168.62.48.100:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSDumr_JutbFb-8svoZEQAAAZs"] [Tue Aug 18 13:09:30.822437 2026] [security2:error] [pid 167459:tid 167626] [client 20.104.100.201:13895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/classwithtostring.php"] [unique_id "aoSDumr_JutbFb-8svoZEgAAAbQ"] [Tue Aug 18 13:09:30.830107 2026] [authz_core:error] [pid 167459:tid 167580] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:30.830378 2026] [authz_core:error] [pid 167459:tid 167580] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:30.874588 2026] [security2:error] [pid 167459:tid 167676] [client 20.203.183.135:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/images.php"] [unique_id "aoSDumr_JutbFb-8svoZFgAAAeY"] [Tue Aug 18 13:09:30.879870 2026] [security2:error] [pid 167459:tid 167591] [client 172.213.243.2:48440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/rpk.php"] [unique_id "aoSDumr_JutbFb-8svoZFwAAAZE"] [Tue Aug 18 13:09:30.890174 2026] [security2:error] [pid 167459:tid 167643] [client 20.1.169.243:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/item.php"] [unique_id "aoSDumr_JutbFb-8svoZGwAAAcU"] [Tue Aug 18 13:09:30.909107 2026] [security2:error] [pid 167459:tid 167637] [client 20.65.98.162:5310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/copypaths.php"] [unique_id "aoSDumr_JutbFb-8svoZHQAAAb8"] [Tue Aug 18 13:09:30.926742 2026] [security2:error] [pid 167459:tid 167490] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/about.php"] [unique_id "aoSDumr_JutbFb-8svoZHwABpR4"] [Tue Aug 18 13:09:30.957018 2026] [security2:error] [pid 167459:tid 167598] [client 74.248.18.37:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDumr_JutbFb-8svoZIAAAAZg"] [Tue Aug 18 13:09:30.986913 2026] [security2:error] [pid 167459:tid 167605] [client 20.250.13.23:23263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/user/12.php"] [unique_id "aoSDumr_JutbFb-8svoZIQAAAZ8"] [Tue Aug 18 13:09:31.006937 2026] [security2:error] [pid 167459:tid 167669] [client 20.91.215.254:16859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDu2r_JutbFb-8svoZIgAAAd8"] [Tue Aug 18 13:09:31.042796 2026] [security2:error] [pid 167459:tid 167648] [client 4.232.151.198:29466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-content/ad4599c5/admin.php"] [unique_id "aoSDu2r_JutbFb-8svoZJAAAAco"] [Tue Aug 18 13:09:31.049957 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/aa.php"] [unique_id "aoSDu2r_JutbFb-8svoZJgAAAec"] [Tue Aug 18 13:09:31.059430 2026] [security2:error] [pid 167459:tid 167616] [client 68.155.154.236:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSDu2r_JutbFb-8svoZJwAAAao"] [Tue Aug 18 13:09:31.061918 2026] [security2:error] [pid 167459:tid 167531] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/about/function.php"] [unique_id "aoSDu2r_JutbFb-8svoZKAAB-Uc"] [Tue Aug 18 13:09:31.112541 2026] [security2:error] [pid 167459:tid 167657] [client 213.35.127.232:60804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDu2r_JutbFb-8svoZKgAAAdM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:31.116025 2026] [security2:error] [pid 167459:tid 167647] [client 138.36.100.162:41405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDu2r_JutbFb-8svoZKwAAAck"] [Tue Aug 18 13:09:31.116179 2026] [security2:error] [pid 167459:tid 167647] [client 138.36.100.162:41405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDu2r_JutbFb-8svoZKwAAAck"] [Tue Aug 18 13:09:31.131872 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:31.132131 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:31.147730 2026] [security2:error] [pid 167459:tid 167683] [client 20.250.13.23:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/asd.php"] [unique_id "aoSDu2r_JutbFb-8svoZLgAAAe0"] [Tue Aug 18 13:09:31.198849 2026] [security2:error] [pid 167459:tid 167488] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/admin/admin.php"] [unique_id "aoSDu2r_JutbFb-8svoZMgABwhw"] [Tue Aug 18 13:09:31.203140 2026] [security2:error] [pid 167459:tid 167628] [client 168.62.48.100:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDu2r_JutbFb-8svoZMwAAAbY"] [Tue Aug 18 13:09:31.239068 2026] [security2:error] [pid 167459:tid 167638] [client 197.184.64.235:42701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDu2r_JutbFb-8svoZNAAAAcA"] [Tue Aug 18 13:09:31.239157 2026] [security2:error] [pid 167459:tid 167638] [client 197.184.64.235:42701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDu2r_JutbFb-8svoZNAAAAcA"] [Tue Aug 18 13:09:31.258637 2026] [security2:error] [pid 167459:tid 167608] [client 74.248.133.44:35280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-conflg.php"] [unique_id "aoSDu2r_JutbFb-8svoZNQAAAaI"] [Tue Aug 18 13:09:31.292667 2026] [security2:error] [pid 167459:tid 167664] [client 172.182.217.32:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDu2r_JutbFb-8svoZOAAAAdo"] [Tue Aug 18 13:09:31.292684 2026] [security2:error] [pid 167459:tid 167691] [client 20.38.3.247:2157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/index.php"] [unique_id "aoSDu2r_JutbFb-8svoZNwAAAfU"] [Tue Aug 18 13:09:31.295544 2026] [security2:error] [pid 167459:tid 167649] [client 20.203.183.135:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/ops.php"] [unique_id "aoSDu2r_JutbFb-8svoZOQAAAcs"] [Tue Aug 18 13:09:31.296147 2026] [security2:error] [pid 167459:tid 167714] [client 172.213.243.2:20787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-blog.php"] [unique_id "aoSDu2r_JutbFb-8svoZOgAAAgw"] [Tue Aug 18 13:09:31.332787 2026] [security2:error] [pid 167459:tid 167551] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/admin/function.php"] [unique_id "aoSDu2r_JutbFb-8svoZOwAB2Vs"] [Tue Aug 18 13:09:31.336974 2026] [security2:error] [pid 167459:tid 167646] [client 20.1.169.243:10224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/kir.php"] [unique_id "aoSDu2r_JutbFb-8svoZPAAAAcg"] [Tue Aug 18 13:09:31.361412 2026] [security2:error] [pid 167459:tid 167681] [client 4.232.151.198:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/simple.php"] [unique_id "aoSDu2r_JutbFb-8svoZPQAAAes"] [Tue Aug 18 13:09:31.366588 2026] [security2:error] [pid 167459:tid 167711] [client 20.104.49.167:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/av.php"] [unique_id "aoSDu2r_JutbFb-8svoZPgAAAgk"] [Tue Aug 18 13:09:31.383364 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:40462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/q.php"] [unique_id "aoSDu2r_JutbFb-8svoZQAAAAg4"] [Tue Aug 18 13:09:31.431854 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:31.432132 2026] [authz_core:error] [pid 167459:tid 167512] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:31.438138 2026] [security2:error] [pid 167459:tid 167633] [client 74.248.18.37:3366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSDu2r_JutbFb-8svoZQgAAAbs"] [Tue Aug 18 13:09:31.442429 2026] [security2:error] [pid 167459:tid 167650] [client 40.74.65.169:5691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/av.php"] [unique_id "aoSDu2r_JutbFb-8svoZRAAAAcw"] [Tue Aug 18 13:09:31.467535 2026] [security2:error] [pid 167459:tid 167478] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/adminfuns.php"] [unique_id "aoSDu2r_JutbFb-8svoZRwAB8hI"] [Tue Aug 18 13:09:31.484462 2026] [security2:error] [pid 167459:tid 167697] [client 52.139.47.57:35306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/aaa.php"] [unique_id "aoSDu2r_JutbFb-8svoZSQAAAfs"] [Tue Aug 18 13:09:31.488997 2026] [security2:error] [pid 167459:tid 167666] [client 158.23.17.4:56533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/mq.php"] [unique_id "aoSDu2r_JutbFb-8svoZSgAAAdw"] [Tue Aug 18 13:09:31.523624 2026] [security2:error] [pid 167459:tid 167668] [client 168.62.48.100:16384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSDu2r_JutbFb-8svoZSwAAAd4"] [Tue Aug 18 13:09:31.526532 2026] [security2:error] [pid 167459:tid 167528] [remote 47.128.31.207:59666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maxxbox.ind.br"] [uri "/"] [unique_id "aoSDu2r_JutbFb-8svoZTAAB80Q"] [Tue Aug 18 13:09:31.602023 2026] [security2:error] [pid 167459:tid 167510] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSDu2r_JutbFb-8svoZUAACCDI"] [Tue Aug 18 13:09:31.604373 2026] [security2:error] [pid 167459:tid 167626] [client 20.171.51.14:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/m.php"] [unique_id "aoSDu2r_JutbFb-8svoZUQAAAbQ"] [Tue Aug 18 13:09:31.641122 2026] [security2:error] [pid 167459:tid 167662] [client 20.91.215.254:22274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/akc.php"] [unique_id "aoSDu2r_JutbFb-8svoZUgAAAdg"] [Tue Aug 18 13:09:31.645598 2026] [security2:error] [pid 167459:tid 167623] [client 20.127.136.245:18659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/xmr.php"] [unique_id "aoSDu2r_JutbFb-8svoZUwAAAbE"] [Tue Aug 18 13:09:31.703470 2026] [security2:error] [pid 167459:tid 167660] [client 172.213.243.2:17879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/mga.php"] [unique_id "aoSDu2r_JutbFb-8svoZXwAAAdY"] [Tue Aug 18 13:09:31.713675 2026] [security2:error] [pid 167459:tid 167706] [client 4.232.151.198:44409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "plataformazap.filialweb.com"] [uri "/wp-content/admin.php"] [unique_id "aoSDu2r_JutbFb-8svoZYgAAAgQ"] [Tue Aug 18 13:09:31.727424 2026] [security2:error] [pid 167459:tid 167598] [client 20.203.183.135:29270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/coffexium.php"] [unique_id "aoSDu2r_JutbFb-8svoZZAAAAZg"] [Tue Aug 18 13:09:31.730429 2026] [security2:error] [pid 167459:tid 167630] [client 20.104.100.201:13912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-the.php"] [unique_id "aoSDu2r_JutbFb-8svoZZgAAAbg"] [Tue Aug 18 13:09:31.736703 2026] [security2:error] [pid 167459:tid 167579] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/ahax.php"] [unique_id "aoSDu2r_JutbFb-8svoZaAABwXc"] [Tue Aug 18 13:09:31.778004 2026] [security2:error] [pid 167459:tid 167676] [client 172.182.217.32:15784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDu2r_JutbFb-8svoZbwAAAeY"] [Tue Aug 18 13:09:31.797160 2026] [security2:error] [pid 167459:tid 167624] [client 20.38.3.247:50893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDu2r_JutbFb-8svoZcAAAAbI"] [Tue Aug 18 13:09:31.802573 2026] [security2:error] [pid 167459:tid 167708] [client 20.250.13.23:5343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/akc.php"] [unique_id "aoSDu2r_JutbFb-8svoZcQAAAgY"] [Tue Aug 18 13:09:31.806672 2026] [security2:error] [pid 167459:tid 167673] [client 68.155.154.236:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSDu2r_JutbFb-8svoZcgAAAeM"] [Tue Aug 18 13:09:31.808221 2026] [security2:error] [pid 167459:tid 167648] [client 20.38.3.247:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/aaa.php"] [unique_id "aoSDu2r_JutbFb-8svoZcwAAAco"] [Tue Aug 18 13:09:31.819472 2026] [security2:error] [pid 167459:tid 167625] [client 20.65.98.162:62193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/bless6.php"] [unique_id "aoSDu2r_JutbFb-8svoZdAAAAbM"] [Tue Aug 18 13:09:31.820972 2026] [security2:error] [pid 167459:tid 167677] [client 20.250.13.23:5373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/ku.php"] [unique_id "aoSDu2r_JutbFb-8svoZdQAAAec"] [Tue Aug 18 13:09:31.826566 2026] [security2:error] [pid 167459:tid 167641] [client 20.1.169.243:10195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/log.php"] [unique_id "aoSDu2r_JutbFb-8svoZdgAAAcM"] [Tue Aug 18 13:09:31.876635 2026] [security2:error] [pid 167459:tid 167503] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/alfa.php"] [unique_id "aoSDu2r_JutbFb-8svoZeAAB-is"] [Tue Aug 18 13:09:31.876921 2026] [security2:error] [pid 167459:tid 167657] [client 168.62.48.100:16476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSDu2r_JutbFb-8svoZeQAAAdM"] [Tue Aug 18 13:09:31.904574 2026] [security2:error] [pid 167459:tid 167589] [client 52.139.47.57:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/aar.php"] [unique_id "aoSDu2r_JutbFb-8svoZewAAAY8"] [Tue Aug 18 13:09:31.979800 2026] [security2:error] [pid 167459:tid 167682] [client 20.116.17.175:52874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/usr.php"] [unique_id "aoSDu2r_JutbFb-8svoZfgAAAew"] [Tue Aug 18 13:09:32.011338 2026] [security2:error] [pid 167459:tid 167586] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/alfax.php"] [unique_id "aoSDvGr_JutbFb-8svoZfwAB0X4"] [Tue Aug 18 13:09:32.028433 2026] [core:notice] [pid 167459:tid 167691] AH00113: /home1/maxxtelecomcom/public_html/.htaccess:22 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:09:32.061839 2026] [security2:error] [pid 167459:tid 167663] [client 68.221.73.131:41329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/82.php"] [unique_id "aoSDvGr_JutbFb-8svoZhAAAAdk"] [Tue Aug 18 13:09:32.092678 2026] [security2:error] [pid 167459:tid 167647] [client 74.248.18.37:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDvGr_JutbFb-8svoZhQAAAck"] [Tue Aug 18 13:09:32.116606 2026] [security2:error] [pid 167459:tid 167596] [client 172.213.243.2:11599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/fs.php"] [unique_id "aoSDvGr_JutbFb-8svoZiQAAAZY"] [Tue Aug 18 13:09:32.128776 2026] [security2:error] [pid 167459:tid 167669] [client 213.35.127.232:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDvGr_JutbFb-8svoZiwAAAd8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:32.144962 2026] [security2:error] [pid 167459:tid 167518] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/ant.php"] [unique_id "aoSDvGr_JutbFb-8svoZjAACAjo"] [Tue Aug 18 13:09:32.163060 2026] [security2:error] [pid 167459:tid 167665] [client 20.38.3.247:35906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDvGr_JutbFb-8svoZjgAAAds"] [Tue Aug 18 13:09:32.169286 2026] [security2:error] [pid 167459:tid 167615] [client 20.203.183.135:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDvGr_JutbFb-8svoZkAAAAak"] [Tue Aug 18 13:09:32.169558 2026] [security2:error] [pid 167459:tid 167684] [client 168.62.48.100:16447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSDvGr_JutbFb-8svoZjwAAAe4"] [Tue Aug 18 13:09:32.189705 2026] [security2:error] [pid 167459:tid 167690] [client 20.104.100.201:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/cong.php"] [unique_id "aoSDvGr_JutbFb-8svoZkQAAAfQ"] [Tue Aug 18 13:09:32.195557 2026] [security2:error] [pid 167459:tid 167715] [client 20.1.169.243:9714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/logins.php"] [unique_id "aoSDvGr_JutbFb-8svoZkgAAAg0"] [Tue Aug 18 13:09:32.259255 2026] [security2:error] [pid 167459:tid 167627] [client 158.23.17.4:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xf.php"] [unique_id "aoSDvGr_JutbFb-8svoZmAAAAbU"] [Tue Aug 18 13:09:32.263730 2026] [security2:error] [pid 167459:tid 167653] [client 196.12.128.158:57287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDvGr_JutbFb-8svoZmgAAAc8"] [Tue Aug 18 13:09:32.263856 2026] [security2:error] [pid 167459:tid 167653] [client 196.12.128.158:57287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDvGr_JutbFb-8svoZmgAAAc8"] [Tue Aug 18 13:09:32.264921 2026] [security2:error] [pid 167459:tid 167613] [client 172.182.217.32:15581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/in.php"] [unique_id "aoSDvGr_JutbFb-8svoZmwAAAac"] [Tue Aug 18 13:09:32.278456 2026] [security2:error] [pid 167459:tid 167469] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/app.php"] [unique_id "aoSDvGr_JutbFb-8svoZnAABxQk"] [Tue Aug 18 13:09:32.312358 2026] [security2:error] [pid 167459:tid 167646] [client 20.91.215.254:16862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/buy.php"] [unique_id "aoSDvGr_JutbFb-8svoZnwAAAcg"] [Tue Aug 18 13:09:32.323982 2026] [security2:error] [pid 167459:tid 167703] [client 74.248.133.44:23034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/bi.php"] [unique_id "aoSDvGr_JutbFb-8svoZoAAAAgE"] [Tue Aug 18 13:09:32.324012 2026] [security2:error] [pid 167459:tid 167597] [client 52.139.47.57:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ab.php"] [unique_id "aoSDvGr_JutbFb-8svoZoQAAAZc"] [Tue Aug 18 13:09:32.359897 2026] [security2:error] [pid 167459:tid 167592] [client 20.38.3.247:30675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDvGr_JutbFb-8svoZowAAAZI"] [Tue Aug 18 13:09:32.362224 2026] [authz_core:error] [pid 167459:tid 167566] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:32.362666 2026] [authz_core:error] [pid 167459:tid 167566] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:32.377594 2026] [security2:error] [pid 167459:tid 167706] [client 158.23.17.4:63034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/13.php"] [unique_id "aoSDvGr_JutbFb-8svoZpAAAAgQ"] [Tue Aug 18 13:09:32.397197 2026] [security2:error] [pid 167459:tid 167630] [client 68.155.154.236:27570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSDvGr_JutbFb-8svoZpwAAAbg"] [Tue Aug 18 13:09:32.414484 2026] [security2:error] [pid 167459:tid 167602] [client 20.250.13.23:23242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/maintenance.php"] [unique_id "aoSDvGr_JutbFb-8svoZqAAAAZw"] [Tue Aug 18 13:09:32.427572 2026] [security2:error] [pid 167459:tid 167631] [client 168.62.48.100:16493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSDvGr_JutbFb-8svoZqQAAAbk"] [Tue Aug 18 13:09:32.527799 2026] [security2:error] [pid 167459:tid 167641] [client 172.213.243.2:11596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/wp-tem.php"] [unique_id "aoSDvGr_JutbFb-8svoZrgAAAcM"] [Tue Aug 18 13:09:32.559396 2026] [security2:error] [pid 167459:tid 167657] [client 20.127.136.245:2170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/about.php"] [unique_id "aoSDvGr_JutbFb-8svoZsAAAAdM"] [Tue Aug 18 13:09:32.605285 2026] [security2:error] [pid 167459:tid 167702] [client 20.203.183.135:29261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/sf.php"] [unique_id "aoSDvGr_JutbFb-8svoZswAAAgA"] [Tue Aug 18 13:09:32.608555 2026] [security2:error] [pid 167459:tid 167707] [client 20.38.3.247:35929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/media.php"] [unique_id "aoSDvGr_JutbFb-8svoZtAAAAgU"] [Tue Aug 18 13:09:32.617717 2026] [security2:error] [pid 167459:tid 167609] [client 40.74.65.169:5666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/images.php"] [unique_id "aoSDvGr_JutbFb-8svoZtQAAAaM"] [Tue Aug 18 13:09:32.617910 2026] [security2:error] [pid 167459:tid 167708] [client 20.1.169.243:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/mailer.php"] [unique_id "aoSDvGr_JutbFb-8svoZtgAAAgY"] [Tue Aug 18 13:09:32.647610 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:32.647909 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:32.649520 2026] [security2:error] [pid 167459:tid 167682] [client 20.104.100.201:62652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/xwpg.php"] [unique_id "aoSDvGr_JutbFb-8svoZuQAAAew"] [Tue Aug 18 13:09:32.664528 2026] [security2:error] [pid 167459:tid 167678] [client 20.250.13.23:39266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/chosen.php"] [unique_id "aoSDvGr_JutbFb-8svoZvAAAAeg"] [Tue Aug 18 13:09:32.673446 2026] [security2:error] [pid 167459:tid 167548] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/archive.php"] [unique_id "aoSDvGr_JutbFb-8svoZvQABvlg"] [Tue Aug 18 13:09:32.676455 2026] [security2:error] [pid 167459:tid 167672] [client 4.232.151.198:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/edit-tags.php"] [unique_id "aoSDvGr_JutbFb-8svoZvgAAAeI"] [Tue Aug 18 13:09:32.680156 2026] [security2:error] [pid 167459:tid 167680] [client 20.104.49.167:63708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/images.php"] [unique_id "aoSDvGr_JutbFb-8svoZvwAAAeo"] [Tue Aug 18 13:09:32.708434 2026] [security2:error] [pid 167459:tid 167655] [client 158.23.17.4:56738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ez.php"] [unique_id "aoSDvGr_JutbFb-8svoZwQAAAdE"] [Tue Aug 18 13:09:32.728768 2026] [security2:error] [pid 167459:tid 167625] [client 74.248.18.37:25358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDvGr_JutbFb-8svoZwgAAAbM"] [Tue Aug 18 13:09:32.741423 2026] [security2:error] [pid 167459:tid 167606] [client 52.139.47.57:35317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/abc.php"] [unique_id "aoSDvGr_JutbFb-8svoZwwAAAaA"] [Tue Aug 18 13:09:32.768500 2026] [security2:error] [pid 167459:tid 167647] [client 168.62.48.100:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSDvGr_JutbFb-8svoZxgAAAck"] [Tue Aug 18 13:09:32.773550 2026] [security2:error] [pid 167459:tid 167698] [client 172.182.217.32:15574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/info.php"] [unique_id "aoSDvGr_JutbFb-8svoZxwAAAfw"] [Tue Aug 18 13:09:32.805138 2026] [security2:error] [pid 167459:tid 167669] [client 74.249.206.207:21672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/nox.php"] [unique_id "aoSDvGr_JutbFb-8svoZyAAAAd8"] [Tue Aug 18 13:09:32.811838 2026] [security2:error] [pid 167459:tid 167529] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/as.php"] [unique_id "aoSDvGr_JutbFb-8svoZyQABlUU"] [Tue Aug 18 13:09:32.891460 2026] [core:error] [pid 167459:tid 167515] [remote 20.80.111.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:09:32.891486 2026] [core:error] [pid 167459:tid 167515] [remote 20.80.111.3:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace. [Tue Aug 18 13:09:32.893873 2026] [security2:error] [pid 167459:tid 167612] [client 114.5.214.109:50423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvGr_JutbFb-8svoZzgAAAaY"] [Tue Aug 18 13:09:32.901936 2026] [security2:error] [pid 167459:tid 167612] [client 114.5.214.109:50423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvGr_JutbFb-8svoZzgAAAaY"] [Tue Aug 18 13:09:32.936456 2026] [security2:error] [pid 167459:tid 167643] [client 172.213.243.2:11584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/sadd.php"] [unique_id "aoSDvGr_JutbFb-8svoZ0AAAAcU"] [Tue Aug 18 13:09:32.948043 2026] [security2:error] [pid 167459:tid 167462] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/assets/images/doc.php"] [unique_id "aoSDvGr_JutbFb-8svoZ0gABvwI"] [Tue Aug 18 13:09:32.948511 2026] [security2:error] [pid 167459:tid 167714] [client 20.91.215.254:22300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/cong.php"] [unique_id "aoSDvGr_JutbFb-8svoZ0wAAAgw"] [Tue Aug 18 13:09:32.954296 2026] [security2:error] [pid 167459:tid 167703] [client 20.38.3.247:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/admin.php"] [unique_id "aoSDvGr_JutbFb-8svoZ1AAAAgE"] [Tue Aug 18 13:09:32.969190 2026] [security2:error] [pid 167459:tid 167701] [client 20.100.169.31:3515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDvGr_JutbFb-8svoZ1QAAAf8"] [Tue Aug 18 13:09:32.982623 2026] [security2:error] [pid 167459:tid 167661] [client 68.155.154.236:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSDvGr_JutbFb-8svoZ1gAAAdc"] [Tue Aug 18 13:09:32.983913 2026] [security2:error] [pid 167459:tid 167651] [client 20.1.169.243:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/min.php"] [unique_id "aoSDvGr_JutbFb-8svoZ1wAAAc0"] [Tue Aug 18 13:09:33.000394 2026] [security2:error] [pid 167459:tid 167706] [client 158.23.17.4:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/so.php"] [unique_id "aoSDvGr_JutbFb-8svoZ2QAAAgQ"] [Tue Aug 18 13:09:33.027390 2026] [security2:error] [pid 167459:tid 167604] [client 20.203.183.135:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/k.php"] [unique_id "aoSDvWr_JutbFb-8svoZ2wAAAZ4"] [Tue Aug 18 13:09:33.038000 2026] [security2:error] [pid 167459:tid 167665] [client 20.250.13.23:5361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/options-writing.php"] [unique_id "aoSDvWr_JutbFb-8svoZ3QAAAds"] [Tue Aug 18 13:09:33.092583 2026] [security2:error] [pid 167459:tid 167572] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/atomlib.php"] [unique_id "aoSDvWr_JutbFb-8svoZ3wAB3HA"] [Tue Aug 18 13:09:33.130267 2026] [security2:error] [pid 167459:tid 167642] [client 168.62.48.100:16463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/first.php"] [unique_id "aoSDvWr_JutbFb-8svoZ4QAAAcQ"] [Tue Aug 18 13:09:33.142466 2026] [security2:error] [pid 167459:tid 167667] [client 213.35.127.232:61304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDvWr_JutbFb-8svoZ4gAAAd0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:33.149735 2026] [security2:error] [pid 167459:tid 167623] [client 74.248.133.44:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/disagraeosc.php"] [unique_id "aoSDvWr_JutbFb-8svoZ4wAAAbE"] [Tue Aug 18 13:09:33.164157 2026] [security2:error] [pid 167459:tid 167611] [client 52.139.47.57:18506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/abcd.php"] [unique_id "aoSDvWr_JutbFb-8svoZ5AAAAaU"] [Tue Aug 18 13:09:33.197348 2026] [security2:error] [pid 167459:tid 167684] [client 49.145.211.146:12644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvWr_JutbFb-8svoZ5gAAAe4"] [Tue Aug 18 13:09:33.197481 2026] [security2:error] [pid 167459:tid 167684] [client 49.145.211.146:12644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvWr_JutbFb-8svoZ5gAAAe4"] [Tue Aug 18 13:09:33.200902 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.18.37:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/vx.php"] [unique_id "aoSDvWr_JutbFb-8svoZ5wAAAfY"] [Tue Aug 18 13:09:33.229817 2026] [security2:error] [pid 167459:tid 167511] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/b.php"] [unique_id "aoSDvWr_JutbFb-8svoZ6QABjzM"] [Tue Aug 18 13:09:33.249142 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:33.249418 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:33.254675 2026] [security2:error] [pid 167459:tid 167609] [client 20.65.98.162:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/special.php"] [unique_id "aoSDvWr_JutbFb-8svoZ6wAAAaM"] [Tue Aug 18 13:09:33.260635 2026] [security2:error] [pid 167459:tid 167605] [client 172.182.217.32:15580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/inputs.php"] [unique_id "aoSDvWr_JutbFb-8svoZ7AAAAZ8"] [Tue Aug 18 13:09:33.290350 2026] [security2:error] [pid 167459:tid 167713] [client 20.38.3.247:46631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/mac.php"] [unique_id "aoSDvWr_JutbFb-8svoZ7wAAAgs"] [Tue Aug 18 13:09:33.351017 2026] [security2:error] [pid 167459:tid 167680] [client 172.213.243.2:19732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ex.php"] [unique_id "aoSDvWr_JutbFb-8svoZ8QAAAeo"] [Tue Aug 18 13:09:33.366980 2026] [security2:error] [pid 167459:tid 167466] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/backup.php"] [unique_id "aoSDvWr_JutbFb-8svoZ8wABogY"] [Tue Aug 18 13:09:33.368549 2026] [security2:error] [pid 167459:tid 167673] [client 74.248.18.37:3331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSDvWr_JutbFb-8svoZ9AAAAeM"] [Tue Aug 18 13:09:33.383459 2026] [security2:error] [pid 167459:tid 167696] [client 20.250.13.23:5315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/asd.php"] [unique_id "aoSDvWr_JutbFb-8svoZ9QAAAfo"] [Tue Aug 18 13:09:33.390650 2026] [security2:error] [pid 167459:tid 167649] [client 20.127.136.245:10025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/admin.php"] [unique_id "aoSDvWr_JutbFb-8svoZ9gAAAcs"] [Tue Aug 18 13:09:33.396936 2026] [security2:error] [pid 167459:tid 167606] [client 20.104.49.167:50541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/ops.php"] [unique_id "aoSDvWr_JutbFb-8svoZ9wAAAaA"] [Tue Aug 18 13:09:33.405389 2026] [security2:error] [pid 167459:tid 167591] [client 20.116.17.175:52600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/privacy.php"] [unique_id "aoSDvWr_JutbFb-8svoZ-AAAAZE"] [Tue Aug 18 13:09:33.418794 2026] [security2:error] [pid 167459:tid 167647] [client 158.23.17.4:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gb.php"] [unique_id "aoSDvWr_JutbFb-8svoZ-gAAAck"] [Tue Aug 18 13:09:33.443169 2026] [security2:error] [pid 167459:tid 167688] [client 20.203.183.135:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/82.php"] [unique_id "aoSDvWr_JutbFb-8svoZ-wAAAfI"] [Tue Aug 18 13:09:33.444759 2026] [security2:error] [pid 167459:tid 167704] [client 40.74.65.169:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/ops.php"] [unique_id "aoSDvWr_JutbFb-8svoZ_AAAAgI"] [Tue Aug 18 13:09:33.466207 2026] [security2:error] [pid 167459:tid 167690] [client 168.62.48.100:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSDvWr_JutbFb-8svoZ_QAAAfQ"] [Tue Aug 18 13:09:33.476630 2026] [security2:error] [pid 167459:tid 167715] [client 20.1.169.243:10204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/mini.php"] [unique_id "aoSDvWr_JutbFb-8svoZ_gAAAg0"] [Tue Aug 18 13:09:33.504803 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bak.php"] [unique_id "aoSDvWr_JutbFb-8svoaAQABphU"] [Tue Aug 18 13:09:33.557455 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:33.557710 2026] [authz_core:error] [pid 167459:tid 167463] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:33.575409 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:35271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/about.php"] [unique_id "aoSDvWr_JutbFb-8svoaBQAAAfA"] [Tue Aug 18 13:09:33.611275 2026] [security2:error] [pid 167459:tid 167625] [client 20.100.169.31:3466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSDvWr_JutbFb-8svoaCAAAAbM"] [Tue Aug 18 13:09:33.614792 2026] [security2:error] [pid 167459:tid 167664] [client 20.91.215.254:22320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSDvWr_JutbFb-8svoaCQAAAdo"] [Tue Aug 18 13:09:33.633440 2026] [security2:error] [pid 167459:tid 167701] [client 20.38.3.247:16172] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lp.advocaciapedroso.com.br"] [uri "/1.php"] [unique_id "aoSDvWr_JutbFb-8svoaCwAAAf8"] [Tue Aug 18 13:09:33.633560 2026] [security2:error] [pid 167459:tid 167701] [client 20.38.3.247:16172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/1.php"] [unique_id "aoSDvWr_JutbFb-8svoaCwAAAf8"] [Tue Aug 18 13:09:33.638697 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bgymj.php"] [unique_id "aoSDvWr_JutbFb-8svoaEgACBBk"] [Tue Aug 18 13:09:33.648938 2026] [security2:error] [pid 167459:tid 167604] [client 68.155.154.236:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSDvWr_JutbFb-8svoaEwAAAZ4"] [Tue Aug 18 13:09:33.652168 2026] [security2:error] [pid 167459:tid 167595] [client 20.250.13.23:23245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSDvWr_JutbFb-8svoaFAAAAZU"] [Tue Aug 18 13:09:33.696883 2026] [security2:error] [pid 167459:tid 167654] [client 178.156.189.249:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "markettohome.com.br"] [uri "/index.php"] [unique_id "aoSDvGr_JutbFb-8svoZngAB0E8"], referer: https://markettohome.com.br/ [Tue Aug 18 13:09:33.755053 2026] [security2:error] [pid 167459:tid 167646] [client 172.182.217.32:15583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/item.php"] [unique_id "aoSDvWr_JutbFb-8svoaGwAAAcg"] [Tue Aug 18 13:09:33.764974 2026] [security2:error] [pid 167459:tid 167692] [client 172.213.243.2:19840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/tax.php"] [unique_id "aoSDvWr_JutbFb-8svoaHAAAAfY"] [Tue Aug 18 13:09:33.765226 2026] [security2:error] [pid 167459:tid 167657] [client 20.38.3.247:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/site.php"] [unique_id "aoSDvWr_JutbFb-8svoaHQAAAdM"] [Tue Aug 18 13:09:33.775350 2026] [security2:error] [pid 167459:tid 167558] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bi.php"] [unique_id "aoSDvWr_JutbFb-8svoaHgABj2I"] [Tue Aug 18 13:09:33.797771 2026] [security2:error] [pid 167459:tid 167671] [client 158.23.17.4:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/asus.php"] [unique_id "aoSDvWr_JutbFb-8svoaHwAAAeE"] [Tue Aug 18 13:09:33.855198 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:33.855469 2026] [authz_core:error] [pid 167459:tid 167520] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:33.880323 2026] [security2:error] [pid 167459:tid 167593] [client 20.1.169.243:9723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/moddofuns.php"] [unique_id "aoSDvWr_JutbFb-8svoaIwAAAZM"] [Tue Aug 18 13:09:33.882167 2026] [security2:error] [pid 167459:tid 167682] [client 20.203.183.135:63874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/dex.php"] [unique_id "aoSDvWr_JutbFb-8svoaJAAAAew"] [Tue Aug 18 13:09:33.893430 2026] [security2:error] [pid 167459:tid 167658] [client 168.62.48.100:16456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSDvWr_JutbFb-8svoaJQAAAdQ"] [Tue Aug 18 13:09:33.912198 2026] [security2:error] [pid 167459:tid 167508] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/blog.php"] [unique_id "aoSDvWr_JutbFb-8svoaJgABwjA"] [Tue Aug 18 13:09:33.937879 2026] [security2:error] [pid 167459:tid 167672] [client 20.127.136.245:3728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDvWr_JutbFb-8svoaKAAAAeI"] [Tue Aug 18 13:09:33.970351 2026] [security2:error] [pid 167459:tid 167655] [client 158.23.17.4:7306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/jp.php"] [unique_id "aoSDvWr_JutbFb-8svoaKQAAAdE"] [Tue Aug 18 13:09:33.991647 2026] [security2:error] [pid 167459:tid 167699] [client 52.139.47.57:18556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/about/function.php"] [unique_id "aoSDvWr_JutbFb-8svoaKwAAAf0"] [Tue Aug 18 13:09:33.997488 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/akc.php"] [unique_id "aoSDvWr_JutbFb-8svoaLAAAAgU"] [Tue Aug 18 13:09:34.001952 2026] [security2:error] [pid 167459:tid 167691] [client 20.171.51.14:17786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/nl.php"] [unique_id "aoSDvmr_JutbFb-8svoaLgAAAfU"] [Tue Aug 18 13:09:34.006209 2026] [security2:error] [pid 167459:tid 167716] [client 20.38.3.247:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/coffee.php"] [unique_id "aoSDvmr_JutbFb-8svoaLwAAAg4"] [Tue Aug 18 13:09:34.008041 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.49.167:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/coffexium.php"] [unique_id "aoSDvmr_JutbFb-8svoaMAAAAfw"] [Tue Aug 18 13:09:34.046973 2026] [security2:error] [pid 167459:tid 167500] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bs1.php"] [unique_id "aoSDvmr_JutbFb-8svoaMgABwCg"] [Tue Aug 18 13:09:34.149652 2026] [security2:error] [pid 167459:tid 167596] [client 49.37.150.8:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoaNgAAAZY"] [Tue Aug 18 13:09:34.149777 2026] [security2:error] [pid 167459:tid 167596] [client 49.37.150.8:60158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoaNgAAAZY"] [Tue Aug 18 13:09:34.160449 2026] [security2:error] [pid 167459:tid 167605] [client 213.35.127.232:61571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDvmr_JutbFb-8svoaOAAAAZ8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:34.176706 2026] [security2:error] [pid 167459:tid 167714] [client 172.213.243.2:19768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/X7x.php"] [unique_id "aoSDvmr_JutbFb-8svoaOQAAAgw"] [Tue Aug 18 13:09:34.184344 2026] [security2:error] [pid 167459:tid 167514] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bthil.php"] [unique_id "aoSDvmr_JutbFb-8svoaOgABlzY"] [Tue Aug 18 13:09:34.193768 2026] [security2:error] [pid 167459:tid 167703] [client 168.62.48.100:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSDvmr_JutbFb-8svoaOwAAAgE"] [Tue Aug 18 13:09:34.245326 2026] [security2:error] [pid 167459:tid 167634] [client 172.182.217.32:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/k.php"] [unique_id "aoSDvmr_JutbFb-8svoaPwAAAbw"] [Tue Aug 18 13:09:34.250115 2026] [security2:error] [pid 167459:tid 167601] [client 20.1.169.243:10229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSDvmr_JutbFb-8svoaQAAAAZs"] [Tue Aug 18 13:09:34.261247 2026] [security2:error] [pid 167459:tid 167713] [client 74.248.133.44:15811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/24.php"] [unique_id "aoSDvmr_JutbFb-8svoaQQAAAgs"] [Tue Aug 18 13:09:34.264930 2026] [security2:error] [pid 167459:tid 167639] [client 40.74.65.169:5685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/coffexium.php"] [unique_id "aoSDvmr_JutbFb-8svoaQgAAAcE"] [Tue Aug 18 13:09:34.279627 2026] [security2:error] [pid 167459:tid 167689] [client 20.91.215.254:16895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/db.php"] [unique_id "aoSDvmr_JutbFb-8svoaQwAAAfM"] [Tue Aug 18 13:09:34.285251 2026] [security2:error] [pid 167459:tid 167715] [client 20.250.13.23:5331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/maint.php"] [unique_id "aoSDvmr_JutbFb-8svoaRAAAAg0"] [Tue Aug 18 13:09:34.292006 2026] [security2:error] [pid 167459:tid 167710] [client 20.203.183.135:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/puc.php"] [unique_id "aoSDvmr_JutbFb-8svoaRgAAAgg"] [Tue Aug 18 13:09:34.292958 2026] [security2:error] [pid 167459:tid 167465] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoaRQAB-QU"] [Tue Aug 18 13:09:34.293115 2026] [security2:error] [pid 167459:tid 167695] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoaRQAB-QU"] [Tue Aug 18 13:09:34.319337 2026] [security2:error] [pid 167459:tid 167651] [client 158.23.17.4:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/10.php"] [unique_id "aoSDvmr_JutbFb-8svoaRwAAAc0"] [Tue Aug 18 13:09:34.319978 2026] [security2:error] [pid 167459:tid 167472] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/bypass.php"] [unique_id "aoSDvmr_JutbFb-8svoaSAAB0Aw"] [Tue Aug 18 13:09:34.387066 2026] [security2:error] [pid 167459:tid 167656] [client 20.38.3.247:46613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSDvmr_JutbFb-8svoaSQAAAdI"] [Tue Aug 18 13:09:34.408125 2026] [security2:error] [pid 167459:tid 167620] [client 52.139.47.57:13696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin/admin.php"] [unique_id "aoSDvmr_JutbFb-8svoaSgAAAa4"] [Tue Aug 18 13:09:34.435000 2026] [security2:error] [pid 167459:tid 167611] [client 74.248.18.37:25383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSDvmr_JutbFb-8svoaSwAAAaU"] [Tue Aug 18 13:09:34.440533 2026] [security2:error] [pid 167459:tid 167692] [client 168.62.48.100:16398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/blog/byp.php"] [unique_id "aoSDvmr_JutbFb-8svoaTQAAAfY"] [Tue Aug 18 13:09:34.514268 2026] [security2:error] [pid 167459:tid 167628] [client 68.155.154.236:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSDvmr_JutbFb-8svoaUQAAAbY"] [Tue Aug 18 13:09:34.531005 2026] [security2:error] [pid 167459:tid 167632] [client 158.23.17.4:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/22.php"] [unique_id "aoSDvmr_JutbFb-8svoaUgAAAbo"] [Tue Aug 18 13:09:34.590965 2026] [security2:error] [pid 167459:tid 167699] [client 172.213.243.2:17910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ocxla.php"] [unique_id "aoSDvmr_JutbFb-8svoaVQAAAf0"] [Tue Aug 18 13:09:34.607942 2026] [security2:error] [pid 167459:tid 167645] [client 20.171.51.14:2737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/68.php"] [unique_id "aoSDvmr_JutbFb-8svoaVwAAAcc"] [Tue Aug 18 13:09:34.634849 2026] [security2:error] [pid 167459:tid 167682] [client 20.1.169.243:10213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/moduless.php"] [unique_id "aoSDvmr_JutbFb-8svoaYgAAAew"] [Tue Aug 18 13:09:34.666269 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:44686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/eq.php"] [unique_id "aoSDvmr_JutbFb-8svoaaAAAAd4"] [Tue Aug 18 13:09:34.676999 2026] [security2:error] [pid 167459:tid 167551] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cc.php"] [unique_id "aoSDvmr_JutbFb-8svoaaQAB8ls"] [Tue Aug 18 13:09:34.688108 2026] [security2:error] [pid 167459:tid 167697] [client 20.250.13.23:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/maintenance.php"] [unique_id "aoSDvmr_JutbFb-8svoaawAAAfs"] [Tue Aug 18 13:09:34.707362 2026] [security2:error] [pid 167459:tid 167690] [client 168.62.48.100:16425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSDvmr_JutbFb-8svoabAAAAfQ"] [Tue Aug 18 13:09:34.718712 2026] [security2:error] [pid 167459:tid 167590] [client 20.203.183.135:64825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/inso.php"] [unique_id "aoSDvmr_JutbFb-8svoabQAAAZA"] [Tue Aug 18 13:09:34.732823 2026] [security2:error] [pid 167459:tid 167649] [client 172.182.217.32:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/license.php"] [unique_id "aoSDvmr_JutbFb-8svoabgAAAcs"] [Tue Aug 18 13:09:34.757290 2026] [security2:error] [pid 167459:tid 167675] [client 20.38.3.247:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSDvmr_JutbFb-8svoacAAAAeU"] [Tue Aug 18 13:09:34.770600 2026] [security2:error] [pid 167459:tid 167686] [client 20.38.3.247:24437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/ccc.php"] [unique_id "aoSDvmr_JutbFb-8svoacgAAAfA"] [Tue Aug 18 13:09:34.811456 2026] [security2:error] [pid 167459:tid 167579] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDvmr_JutbFb-8svoahwABv3c"] [Tue Aug 18 13:09:34.812880 2026] [security2:error] [pid 167459:tid 167613] [client 20.104.100.201:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/dex.php"] [unique_id "aoSDvmr_JutbFb-8svoaiAAAAac"] [Tue Aug 18 13:09:34.819112 2026] [security2:error] [pid 167459:tid 167678] [client 4.232.151.198:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/u.php"] [unique_id "aoSDvmr_JutbFb-8svoaiQAAAeg"] [Tue Aug 18 13:09:34.827025 2026] [security2:error] [pid 167459:tid 167704] [client 52.139.47.57:35321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/admin/function.php"] [unique_id "aoSDvmr_JutbFb-8svoaiwAAAgI"] [Tue Aug 18 13:09:34.908625 2026] [security2:error] [pid 167459:tid 167657] [client 86.120.159.145:60528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoajQAAAdM"] [Tue Aug 18 13:09:34.909036 2026] [security2:error] [pid 167459:tid 167657] [client 86.120.159.145:60528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDvmr_JutbFb-8svoajQAAAdM"] [Tue Aug 18 13:09:34.909205 2026] [security2:error] [pid 167459:tid 167638] [client 20.250.13.23:39244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/phpMailer.php"] [unique_id "aoSDvmr_JutbFb-8svoajgAAAcA"] [Tue Aug 18 13:09:34.922356 2026] [security2:error] [pid 167459:tid 167601] [client 20.100.169.31:18949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSDvmr_JutbFb-8svoajwAAAZs"] [Tue Aug 18 13:09:34.940181 2026] [security2:error] [pid 167459:tid 167612] [client 20.91.215.254:3421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/dropdown.php"] [unique_id "aoSDvmr_JutbFb-8svoakQAAAaY"] [Tue Aug 18 13:09:34.972096 2026] [security2:error] [pid 167459:tid 167654] [client 20.124.247.79:16675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDvmr_JutbFb-8svoalgAAAdA"] [Tue Aug 18 13:09:35.004879 2026] [security2:error] [pid 167459:tid 167648] [client 172.213.243.2:32461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/post.php"] [unique_id "aoSDv2r_JutbFb-8svoalwAAAco"] [Tue Aug 18 13:09:35.029248 2026] [security2:error] [pid 167459:tid 167634] [client 20.1.169.243:9670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/ms-edit.php"] [unique_id "aoSDv2r_JutbFb-8svoamAAAAbw"] [Tue Aug 18 13:09:35.036303 2026] [security2:error] [pid 167459:tid 167626] [client 103.120.71.157:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDv2r_JutbFb-8svoamgAAAbQ"] [Tue Aug 18 13:09:35.036392 2026] [security2:error] [pid 167459:tid 167626] [client 103.120.71.157:64448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDv2r_JutbFb-8svoamgAAAbQ"] [Tue Aug 18 13:09:35.036711 2026] [security2:error] [pid 167459:tid 167631] [client 20.65.98.162:36207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/fz.php"] [unique_id "aoSDv2r_JutbFb-8svoamQAAAbk"] [Tue Aug 18 13:09:35.068938 2026] [security2:error] [pid 167459:tid 167627] [client 74.248.18.37:56960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSDv2r_JutbFb-8svoanQAAAbU"] [Tue Aug 18 13:09:35.068998 2026] [security2:error] [pid 167459:tid 167623] [client 168.62.48.100:16424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSDv2r_JutbFb-8svoangAAAbE"] [Tue Aug 18 13:09:35.074252 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:35.074512 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:35.078441 2026] [security2:error] [pid 167459:tid 167677] [client 158.23.17.4:39615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ep.php"] [unique_id "aoSDv2r_JutbFb-8svoaoAAAAec"] [Tue Aug 18 13:09:35.093614 2026] [security2:error] [pid 167459:tid 167563] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDv2r_JutbFb-8svoaogABpWc"] [Tue Aug 18 13:09:35.122459 2026] [security2:error] [pid 167459:tid 167708] [client 20.38.3.247:20624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/yj09.php"] [unique_id "aoSDv2r_JutbFb-8svoaowAAAgY"] [Tue Aug 18 13:09:35.133308 2026] [security2:error] [pid 167459:tid 167685] [client 20.203.183.135:38263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/aa.php"] [unique_id "aoSDv2r_JutbFb-8svoapAAAAe8"] [Tue Aug 18 13:09:35.135935 2026] [security2:error] [pid 167459:tid 167663] [client 68.155.154.236:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSDv2r_JutbFb-8svoapQAAAdk"] [Tue Aug 18 13:09:35.155831 2026] [security2:error] [pid 167459:tid 167629] [client 20.104.49.167:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDv2r_JutbFb-8svoapgAAAbc"] [Tue Aug 18 13:09:35.175591 2026] [security2:error] [pid 167459:tid 167703] [client 213.35.127.232:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDv2r_JutbFb-8svoapwAAAgE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:35.185846 2026] [security2:error] [pid 167459:tid 167628] [client 20.127.136.245:1654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/as.php"] [unique_id "aoSDv2r_JutbFb-8svoaqQAAAbY"] [Tue Aug 18 13:09:35.186518 2026] [security2:error] [pid 167459:tid 167546] [remote 57.141.22.24:39074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/public/index.php/locais/academia"] [unique_id "aoSDv2r_JutbFb-8svoaqAAB0lY"] [Tue Aug 18 13:09:35.199542 2026] [security2:error] [pid 167459:tid 167658] [client 40.74.65.169:5667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/BDKR28WP.php"] [unique_id "aoSDv2r_JutbFb-8svoaqgAAAdQ"] [Tue Aug 18 13:09:35.207683 2026] [security2:error] [pid 167459:tid 167664] [client 213.202.253.4:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/userfuns.php"] [unique_id "aoSDv2r_JutbFb-8svoarAAAAdo"], referer: www.google.com [Tue Aug 18 13:09:35.221017 2026] [security2:error] [pid 167459:tid 167712] [client 172.182.217.32:15588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/load.php"] [unique_id "aoSDv2r_JutbFb-8svoarQAAAgo"] [Tue Aug 18 13:09:35.227049 2026] [security2:error] [pid 167459:tid 167502] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDv2r_JutbFb-8svoargAB4io"] [Tue Aug 18 13:09:35.247956 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/adminfuns.php"] [unique_id "aoSDv2r_JutbFb-8svoasQAAAaQ"] [Tue Aug 18 13:09:35.277463 2026] [security2:error] [pid 167459:tid 167655] [client 20.38.3.247:2516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/admin.php"] [unique_id "aoSDv2r_JutbFb-8svoaswAAAdE"] [Tue Aug 18 13:09:35.310679 2026] [security2:error] [pid 167459:tid 167641] [client 20.250.13.23:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/options-writing.php"] [unique_id "aoSDv2r_JutbFb-8svoatgAAAcM"] [Tue Aug 18 13:09:35.314830 2026] [security2:error] [pid 167459:tid 167650] [client 20.124.247.79:16732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDv2r_JutbFb-8svoatwAAAcw"] [Tue Aug 18 13:09:35.362415 2026] [security2:error] [pid 167459:tid 167499] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSDv2r_JutbFb-8svoaugAByyc"] [Tue Aug 18 13:09:35.410807 2026] [security2:error] [pid 167459:tid 167645] [client 20.1.169.243:9666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/new.php"] [unique_id "aoSDv2r_JutbFb-8svoavQAAAcc"] [Tue Aug 18 13:09:35.417897 2026] [security2:error] [pid 167459:tid 167614] [client 172.213.243.2:37101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/nhr.php"] [unique_id "aoSDv2r_JutbFb-8svoavgAAAag"] [Tue Aug 18 13:09:35.424310 2026] [security2:error] [pid 167459:tid 167615] [client 5.31.227.224:1436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDv2r_JutbFb-8svoavwAAAak"] [Tue Aug 18 13:09:35.424420 2026] [security2:error] [pid 167459:tid 167615] [client 5.31.227.224:1436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDv2r_JutbFb-8svoavwAAAak"] [Tue Aug 18 13:09:35.455513 2026] [security2:error] [pid 167459:tid 167714] [client 20.38.3.247:44947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/scxy.php"] [unique_id "aoSDv2r_JutbFb-8svoawwAAAgw"] [Tue Aug 18 13:09:35.482373 2026] [security2:error] [pid 167459:tid 167594] [client 168.62.48.100:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.aad056a293a5.valorreformadepiscina.com.br"] [uri "/images/security.php"] [unique_id "aoSDv2r_JutbFb-8svoaxAAAAZQ"] [Tue Aug 18 13:09:35.498473 2026] [security2:error] [pid 167459:tid 167491] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSDv2r_JutbFb-8svoaxgABsx8"] [Tue Aug 18 13:09:35.521247 2026] [security2:error] [pid 167459:tid 167698] [client 20.250.13.23:39278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSDv2r_JutbFb-8svoaxwAAAfw"] [Tue Aug 18 13:09:35.567215 2026] [security2:error] [pid 167459:tid 167595] [client 20.203.183.135:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/img.php"] [unique_id "aoSDv2r_JutbFb-8svoayQAAAZU"] [Tue Aug 18 13:09:35.574863 2026] [security2:error] [pid 167459:tid 167619] [client 20.91.215.254:22324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/file.php"] [unique_id "aoSDv2r_JutbFb-8svoaygAAAa0"] [Tue Aug 18 13:09:35.593481 2026] [security2:error] [pid 167459:tid 167710] [client 20.124.247.79:16684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSDv2r_JutbFb-8svoazAAAAgg"] [Tue Aug 18 13:09:35.633202 2026] [security2:error] [pid 167459:tid 167550] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/config.php"] [unique_id "aoSDv2r_JutbFb-8svoazwABuVo"] [Tue Aug 18 13:09:35.661625 2026] [security2:error] [pid 167459:tid 167620] [client 20.171.51.14:19897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/jl.php"] [unique_id "aoSDv2r_JutbFb-8svoa0gAAAa4"] [Tue Aug 18 13:09:35.679350 2026] [security2:error] [pid 167459:tid 167604] [client 52.139.47.57:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/administrator/templates/hathor/html/layouts/plugins/db-status.php"] [unique_id "aoSDv2r_JutbFb-8svoa1AAAAZ4"] [Tue Aug 18 13:09:35.705228 2026] [security2:error] [pid 167459:tid 167691] [client 172.182.217.32:15570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/manager.php"] [unique_id "aoSDv2r_JutbFb-8svoa1gAAAfU"] [Tue Aug 18 13:09:35.738288 2026] [security2:error] [pid 167459:tid 167671] [client 20.38.3.247:2502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/reviall.php"] [unique_id "aoSDv2r_JutbFb-8svoa2AAAAeE"] [Tue Aug 18 13:09:35.767024 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.18.37:9852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/404.php"] [unique_id "aoSDv2r_JutbFb-8svoa2QAAAc4"] [Tue Aug 18 13:09:35.768538 2026] [security2:error] [pid 167459:tid 167585] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSDv2r_JutbFb-8svoa2gAB_n0"] [Tue Aug 18 13:09:35.775858 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSDv2r_JutbFb-8svoa3gAAAec"] [Tue Aug 18 13:09:35.783164 2026] [security2:error] [pid 167459:tid 167703] [client 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aoSDv2r_JutbFb-8svoa3wAAAgE"] [Tue Aug 18 13:09:35.785933 2026] [security2:error] [pid 167459:tid 167628] [client 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDv2r_JutbFb-8svoa4AAAAbY"], referer: www.google.com [Tue Aug 18 13:09:35.786220 2026] [security2:error] [pid 167459:tid 167656] [client 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-plain.php"] [unique_id "aoSDv2r_JutbFb-8svoa4QAAAdI"], referer: www.google.com [Tue Aug 18 13:09:35.797176 2026] [security2:error] [pid 167459:tid 167593] [client 20.38.3.247:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDv2r_JutbFb-8svoa4wAAAZM"] [Tue Aug 18 13:09:35.827428 2026] [security2:error] [pid 167459:tid 167607] [client 172.213.243.2:14767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ms-edit.php"] [unique_id "aoSDv2r_JutbFb-8svoa5gAAAaE"] [Tue Aug 18 13:09:35.838812 2026] [security2:error] [pid 167459:tid 167616] [client 68.155.154.236:27580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSDv2r_JutbFb-8svoa6AAAAao"] [Tue Aug 18 13:09:35.880954 2026] [security2:error] [pid 167459:tid 167618] [client 20.104.100.201:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/xyn.php"] [unique_id "aoSDv2r_JutbFb-8svoa6wAAAaw"] [Tue Aug 18 13:09:35.882904 2026] [security2:error] [pid 167459:tid 167655] [client 20.124.247.79:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/av.php"] [unique_id "aoSDv2r_JutbFb-8svoa7AAAAdE"] [Tue Aug 18 13:09:35.900574 2026] [security2:error] [pid 167459:tid 167707] [client 20.116.17.175:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/css/database.php"] [unique_id "aoSDv2r_JutbFb-8svoa7QAAAgU"] [Tue Aug 18 13:09:35.903765 2026] [security2:error] [pid 167459:tid 167548] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/module.php"] [unique_id "aoSDv2r_JutbFb-8svoa7gAB7Fg"] [Tue Aug 18 13:09:35.938412 2026] [security2:error] [pid 167459:tid 167622] [client 20.250.13.23:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSDv2r_JutbFb-8svoa8AAAAbA"] [Tue Aug 18 13:09:35.955521 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:4994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/rf.php"] [unique_id "aoSDv2r_JutbFb-8svoa8gAAAd4"] [Tue Aug 18 13:09:35.959651 2026] [security2:error] [pid 167459:tid 167681] [client 4.232.151.198:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDv2r_JutbFb-8svoa8wAAAes"] [Tue Aug 18 13:09:35.975718 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:35.975994 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:36.051489 2026] [security2:error] [pid 167459:tid 167645] [client 20.203.183.135:29430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/222.php"] [unique_id "aoSDwGr_JutbFb-8svoa9wAAAcc"] [Tue Aug 18 13:09:36.067009 2026] [security2:error] [pid 167459:tid 167506] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/options.php"] [unique_id "aoSDwGr_JutbFb-8svoa-AABqC4"] [Tue Aug 18 13:09:36.103382 2026] [security2:error] [pid 167459:tid 167713] [client 52.139.47.57:18554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ahax.php"] [unique_id "aoSDwGr_JutbFb-8svoa-QAAAgs"] [Tue Aug 18 13:09:36.107070 2026] [security2:error] [pid 167459:tid 167684] [client 74.248.133.44:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-block.php"] [unique_id "aoSDwGr_JutbFb-8svoa-gAAAe4"] [Tue Aug 18 13:09:36.123124 2026] [security2:error] [pid 167459:tid 167647] [client 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/iaudskae.php"] [unique_id "aoSDwGr_JutbFb-8svoa-wAAAck"], referer: www.google.com [Tue Aug 18 13:09:36.125690 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:49051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/te.php"] [unique_id "aoSDwGr_JutbFb-8svoa_AAAAZQ"] [Tue Aug 18 13:09:36.128229 2026] [security2:error] [pid 167459:tid 167679] [client 20.38.3.247:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDwGr_JutbFb-8svoa_QAAAek"] [Tue Aug 18 13:09:36.145069 2026] [security2:error] [pid 167459:tid 167690] [client 20.1.169.243:9707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/num.php"] [unique_id "aoSDwGr_JutbFb-8svoa_wAAAfQ"] [Tue Aug 18 13:09:36.146247 2026] [security2:error] [pid 167459:tid 167716] [client 20.250.13.23:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/al.php"] [unique_id "aoSDwGr_JutbFb-8svobAAAAAg4"] [Tue Aug 18 13:09:36.161538 2026] [security2:error] [pid 167459:tid 167683] [client 74.248.18.37:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDwGr_JutbFb-8svobAgAAAe0"] [Tue Aug 18 13:09:36.169912 2026] [security2:error] [pid 167459:tid 167701] [client 20.65.98.162:62191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/clque.php"] [unique_id "aoSDwGr_JutbFb-8svobBAAAAf8"] [Tue Aug 18 13:09:36.189362 2026] [security2:error] [pid 167459:tid 167672] [client 213.35.127.232:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDwGr_JutbFb-8svobBgAAAeI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:36.193544 2026] [security2:error] [pid 167459:tid 167633] [client 172.182.217.32:15611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/media.php"] [unique_id "aoSDwGr_JutbFb-8svobBwAAAbs"] [Tue Aug 18 13:09:36.203925 2026] [security2:error] [pid 167459:tid 167529] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/panel.php"] [unique_id "aoSDwGr_JutbFb-8svobCAABm0U"] [Tue Aug 18 13:09:36.228645 2026] [security2:error] [pid 167459:tid 167689] [client 20.124.247.79:16664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/images.php"] [unique_id "aoSDwGr_JutbFb-8svobCgAAAfM"] [Tue Aug 18 13:09:36.235236 2026] [security2:error] [pid 167459:tid 167715] [client 172.213.243.2:37086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ws79.php"] [unique_id "aoSDwGr_JutbFb-8svobCwAAAg0"] [Tue Aug 18 13:09:36.242016 2026] [security2:error] [pid 167459:tid 167653] [client 20.91.215.254:22318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/goods.php"] [unique_id "aoSDwGr_JutbFb-8svobDAAAAc8"] [Tue Aug 18 13:09:36.256078 2026] [security2:error] [pid 167459:tid 167696] [client 20.100.169.31:19003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSDwGr_JutbFb-8svobDQAAAfo"] [Tue Aug 18 13:09:36.277492 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:36.277798 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:36.283852 2026] [security2:error] [pid 167459:tid 167592] [client 40.74.65.169:5656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/sf.php"] [unique_id "aoSDwGr_JutbFb-8svobEQAAAZI"] [Tue Aug 18 13:09:36.302520 2026] [security2:error] [pid 167459:tid 167522] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-plain.php"] [unique_id "aoSDwGr_JutbFb-8svobEwACDD4"], referer: www.google.com [Tue Aug 18 13:09:36.311798 2026] [security2:error] [pid 167459:tid 167462] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSDwGr_JutbFb-8svobFAABuQI"], referer: www.google.com [Tue Aug 18 13:09:36.335938 2026] [security2:error] [pid 167459:tid 167660] [client 68.155.154.236:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSDwGr_JutbFb-8svobFQAAAdY"] [Tue Aug 18 13:09:36.340159 2026] [security2:error] [pid 167459:tid 167567] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSDwGr_JutbFb-8svobFgAB5Gs"] [Tue Aug 18 13:09:36.392339 2026] [security2:error] [pid 167459:tid 167651] [client 223.185.37.47:31782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDwGr_JutbFb-8svobFwAAAc0"] [Tue Aug 18 13:09:36.392434 2026] [security2:error] [pid 167459:tid 167651] [client 223.185.37.47:31782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDwGr_JutbFb-8svobFwAAAc0"] [Tue Aug 18 13:09:36.432781 2026] [security2:error] [pid 167459:tid 167646] [client 74.249.206.207:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/akismet.php"] [unique_id "aoSDwGr_JutbFb-8svobGAAAAcg"] [Tue Aug 18 13:09:36.463179 2026] [security2:error] [pid 167459:tid 167593] [client 20.203.183.135:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/key.php"] [unique_id "aoSDwGr_JutbFb-8svobGQAAAZM"] [Tue Aug 18 13:09:36.473772 2026] [security2:error] [pid 167459:tid 167572] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "aoSDwGr_JutbFb-8svobGgAB1HA"] [Tue Aug 18 13:09:36.474281 2026] [security2:error] [pid 167459:tid 167474] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSDwGr_JutbFb-8svobGwABug4"] [Tue Aug 18 13:09:36.482415 2026] [security2:error] [pid 167459:tid 167630] [client 20.38.3.247:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/blurbs.php"] [unique_id "aoSDwGr_JutbFb-8svobHAAAAbg"] [Tue Aug 18 13:09:36.499545 2026] [security2:error] [pid 167459:tid 167616] [client 20.124.247.79:15354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/ops.php"] [unique_id "aoSDwGr_JutbFb-8svobHQAAAao"] [Tue Aug 18 13:09:36.511983 2026] [security2:error] [pid 167459:tid 167652] [client 20.1.169.243:9717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/php.php"] [unique_id "aoSDwGr_JutbFb-8svobHgAAAc4"] [Tue Aug 18 13:09:36.514922 2026] [security2:error] [pid 167459:tid 167663] [client 52.139.47.57:18539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfa.php"] [unique_id "aoSDwGr_JutbFb-8svobHwAAAdk"] [Tue Aug 18 13:09:36.578318 2026] [security2:error] [pid 167459:tid 167699] [client 158.23.17.4:4610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xynz1.php"] [unique_id "aoSDwGr_JutbFb-8svobIQAAAf0"] [Tue Aug 18 13:09:36.590659 2026] [security2:error] [pid 167459:tid 167692] [client 20.250.13.23:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/maint.php"] [unique_id "aoSDwGr_JutbFb-8svobIgAAAfY"] [Tue Aug 18 13:09:36.611587 2026] [security2:error] [pid 167459:tid 167511] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSDwGr_JutbFb-8svobJAABkTM"] [Tue Aug 18 13:09:36.632597 2026] [security2:error] [pid 167459:tid 167587] [remote 46.62.208.238:39752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.208.62.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "immobili.adm.br"] [uri "/wp-login.php"] [unique_id "aoSDwGr_JutbFb-8svobJQABlX8"] [Tue Aug 18 13:09:36.646501 2026] [security2:error] [pid 167459:tid 167650] [client 172.213.243.2:37081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/rtx.php"] [unique_id "aoSDwGr_JutbFb-8svobJwAAAcw"] [Tue Aug 18 13:09:36.671113 2026] [security2:error] [pid 167459:tid 167671] [client 74.248.18.37:51403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wap.php"] [unique_id "aoSDwGr_JutbFb-8svobKAAAAeE"] [Tue Aug 18 13:09:36.680706 2026] [security2:error] [pid 167459:tid 167643] [client 172.182.217.32:15573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/mar.php"] [unique_id "aoSDwGr_JutbFb-8svobKgAAAcU"] [Tue Aug 18 13:09:36.691273 2026] [security2:error] [pid 167459:tid 167608] [client 20.127.136.245:6350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/bolt.php"] [unique_id "aoSDwGr_JutbFb-8svobKwAAAaI"] [Tue Aug 18 13:09:36.691524 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:56531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/kc.php"] [unique_id "aoSDwGr_JutbFb-8svobLQAAAcQ"] [Tue Aug 18 13:09:36.706120 2026] [security2:error] [pid 167459:tid 167675] [client 20.104.49.167:60891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/sf.php"] [unique_id "aoSDwGr_JutbFb-8svobLgAAAeU"] [Tue Aug 18 13:09:36.746271 2026] [security2:error] [pid 167459:tid 167516] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/chosen.php"] [unique_id "aoSDwGr_JutbFb-8svobLwABsjg"] [Tue Aug 18 13:09:36.769248 2026] [security2:error] [pid 167459:tid 167618] [client 20.250.13.23:5628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp.php"] [unique_id "aoSDwGr_JutbFb-8svobMAAAAaw"] [Tue Aug 18 13:09:36.778413 2026] [security2:error] [pid 167459:tid 167565] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/uccomjmr.php"] [unique_id "aoSDwGr_JutbFb-8svobMQAB5mk"], referer: www.google.com [Tue Aug 18 13:09:36.786954 2026] [security2:error] [pid 167459:tid 167636] [client 20.124.247.79:15340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/coffexium.php"] [unique_id "aoSDwGr_JutbFb-8svobMgAAAb4"] [Tue Aug 18 13:09:36.792629 2026] [security2:error] [pid 167459:tid 167606] [client 74.248.18.37:3376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSDwGr_JutbFb-8svobMwAAAaA"] [Tue Aug 18 13:09:36.825660 2026] [security2:error] [pid 167459:tid 167712] [client 4.232.151.198:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/h.php"] [unique_id "aoSDwGr_JutbFb-8svobPAAAAgo"] [Tue Aug 18 13:09:36.831648 2026] [security2:error] [pid 167459:tid 167679] [client 158.23.17.4:46794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/zs.php"] [unique_id "aoSDwGr_JutbFb-8svobPQAAAek"] [Tue Aug 18 13:09:36.842594 2026] [security2:error] [pid 167459:tid 167716] [client 20.38.3.247:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/bajah.php"] [unique_id "aoSDwGr_JutbFb-8svobPgAAAg4"] [Tue Aug 18 13:09:36.856494 2026] [security2:error] [pid 167459:tid 167701] [client 20.116.17.175:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/privdayz.php"] [unique_id "aoSDwGr_JutbFb-8svobPwAAAf8"] [Tue Aug 18 13:09:36.875760 2026] [security2:error] [pid 167459:tid 167681] [client 20.100.169.31:18997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSDwGr_JutbFb-8svobQQAAAes"] [Tue Aug 18 13:09:36.877159 2026] [authz_core:error] [pid 167459:tid 167464] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:36.877403 2026] [authz_core:error] [pid 167459:tid 167464] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:36.878024 2026] [security2:error] [pid 167459:tid 167645] [client 20.1.169.243:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/php/eval-stdin.php"] [unique_id "aoSDwGr_JutbFb-8svobQgAAAcc"] [Tue Aug 18 13:09:36.885869 2026] [security2:error] [pid 167459:tid 167670] [client 20.91.215.254:22329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/hplfuns.php"] [unique_id "aoSDwGr_JutbFb-8svobRAAAAeA"] [Tue Aug 18 13:09:36.902939 2026] [security2:error] [pid 167459:tid 167619] [client 20.203.183.135:38237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/chosen.php"] [unique_id "aoSDwGr_JutbFb-8svobRQAAAa0"] [Tue Aug 18 13:09:36.931117 2026] [security2:error] [pid 167459:tid 167612] [client 68.155.154.236:4064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSDwGr_JutbFb-8svobRgAAAaY"] [Tue Aug 18 13:09:36.934755 2026] [security2:error] [pid 167459:tid 167713] [client 52.139.47.57:18552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/alfax.php"] [unique_id "aoSDwGr_JutbFb-8svobRwAAAgs"] [Tue Aug 18 13:09:36.947755 2026] [security2:error] [pid 167459:tid 167470] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "aoSDwGr_JutbFb-8svobSAAB6Ao"] [Tue Aug 18 13:09:37.026786 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/class-protect-uploads.php"] [unique_id "aoSDwWr_JutbFb-8svobSwABpRk"] [Tue Aug 18 13:09:37.063347 2026] [security2:error] [pid 167459:tid 167651] [client 172.213.243.2:48417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/end.php"] [unique_id "aoSDwWr_JutbFb-8svobTAAAAc0"] [Tue Aug 18 13:09:37.073004 2026] [security2:error] [pid 167459:tid 167629] [client 20.124.247.79:16689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSDwWr_JutbFb-8svobTQAAAbc"] [Tue Aug 18 13:09:37.109766 2026] [security2:error] [pid 167459:tid 167570] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "aoSDwWr_JutbFb-8svobUwABnW4"] [Tue Aug 18 13:09:37.164605 2026] [security2:error] [pid 167459:tid 167525] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSDwWr_JutbFb-8svobVAABkUE"] [Tue Aug 18 13:09:37.170779 2026] [security2:error] [pid 167459:tid 167620] [client 172.182.217.32:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/my1.php"] [unique_id "aoSDwWr_JutbFb-8svobVQAAAa4"] [Tue Aug 18 13:09:37.211497 2026] [security2:error] [pid 167459:tid 167631] [client 20.250.13.23:39245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/phpMailer.php"] [unique_id "aoSDwWr_JutbFb-8svobVgAAAbk"] [Tue Aug 18 13:09:37.212209 2026] [security2:error] [pid 167459:tid 167641] [client 158.23.17.4:20641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vo.php"] [unique_id "aoSDwWr_JutbFb-8svobVwAAAcM"] [Tue Aug 18 13:09:37.220579 2026] [security2:error] [pid 167459:tid 167638] [client 213.35.127.232:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDwWr_JutbFb-8svobWAAAAcA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:37.243749 2026] [security2:error] [pid 167459:tid 167640] [client 20.38.3.247:35955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/domvf.php"] [unique_id "aoSDwWr_JutbFb-8svobWgAAAcI"] [Tue Aug 18 13:09:37.245378 2026] [security2:error] [pid 167459:tid 167655] [client 20.1.169.243:9702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/php8.php"] [unique_id "aoSDwWr_JutbFb-8svobWwAAAdE"] [Tue Aug 18 13:09:37.258551 2026] [security2:error] [pid 167459:tid 167608] [client 158.23.17.4:11435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/jn.php"] [unique_id "aoSDwWr_JutbFb-8svobXAAAAaI"] [Tue Aug 18 13:09:37.268172 2026] [security2:error] [pid 167459:tid 167675] [client 20.206.73.37:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/file2.php"] [unique_id "aoSDwWr_JutbFb-8svobXQAAAeU"] [Tue Aug 18 13:09:37.274152 2026] [security2:error] [pid 167459:tid 167519] [remote 45.141.215.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.215.141.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alsconsultoria.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "aoSDwWr_JutbFb-8svobXgABsjs"] [Tue Aug 18 13:09:37.300067 2026] [security2:error] [pid 167459:tid 167508] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/content.php"] [unique_id "aoSDwWr_JutbFb-8svobXwAB8jA"] [Tue Aug 18 13:09:37.312069 2026] [security2:error] [pid 167459:tid 167676] [client 20.203.183.135:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/wpxml.php"] [unique_id "aoSDwWr_JutbFb-8svobYAAAAeY"] [Tue Aug 18 13:09:37.338283 2026] [security2:error] [pid 167459:tid 167606] [client 20.124.247.79:16659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/sf.php"] [unique_id "aoSDwWr_JutbFb-8svobYQAAAaA"] [Tue Aug 18 13:09:37.353683 2026] [security2:error] [pid 167459:tid 167600] [client 52.139.47.57:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ant.php"] [unique_id "aoSDwWr_JutbFb-8svobYgAAAZo"] [Tue Aug 18 13:09:37.366760 2026] [security2:error] [pid 167459:tid 167684] [client 20.104.100.201:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDwWr_JutbFb-8svobYwAAAe4"] [Tue Aug 18 13:09:37.393467 2026] [security2:error] [pid 167459:tid 167682] [client 20.250.13.23:5318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-activat.php"] [unique_id "aoSDwWr_JutbFb-8svobZAAAAew"] [Tue Aug 18 13:09:37.422933 2026] [security2:error] [pid 167459:tid 167683] [client 40.74.65.169:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/k.php"] [unique_id "aoSDwWr_JutbFb-8svobcAAAAe0"] [Tue Aug 18 13:09:37.436088 2026] [security2:error] [pid 167459:tid 167562] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/database.php"] [unique_id "aoSDwWr_JutbFb-8svobcgABnGY"] [Tue Aug 18 13:09:37.464971 2026] [security2:error] [pid 167459:tid 167616] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDwWr_JutbFb-8svobbwABqnM"] [Tue Aug 18 13:09:37.478512 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:37.478786 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:37.480638 2026] [security2:error] [pid 167459:tid 167633] [client 172.213.243.2:19735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.243.213.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meupix.net"] [uri "/ae.php"] [unique_id "aoSDwWr_JutbFb-8svobdgAAAbs"] [Tue Aug 18 13:09:37.508057 2026] [security2:error] [pid 167459:tid 167697] [client 20.100.169.31:3471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSDwWr_JutbFb-8svobdwAAAfs"] [Tue Aug 18 13:09:37.524051 2026] [security2:error] [pid 167459:tid 167618] [client 20.91.215.254:16893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/htaccess.php"] [unique_id "aoSDwWr_JutbFb-8svobfQAAAaw"] [Tue Aug 18 13:09:37.544424 2026] [security2:error] [pid 167459:tid 167654] [client 20.65.98.162:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/nano.php"] [unique_id "aoSDwWr_JutbFb-8svobgAAAAdA"] [Tue Aug 18 13:09:37.570312 2026] [security2:error] [pid 167459:tid 167714] [client 20.38.3.247:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/fpwch.php"] [unique_id "aoSDwWr_JutbFb-8svobggAAAgw"] [Tue Aug 18 13:09:37.572068 2026] [security2:error] [pid 167459:tid 167537] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/db.php"] [unique_id "aoSDwWr_JutbFb-8svobgwABl00"] [Tue Aug 18 13:09:37.588708 2026] [security2:error] [pid 167459:tid 167596] [client 158.23.17.4:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/iz.php"] [unique_id "aoSDwWr_JutbFb-8svobhQAAAZY"] [Tue Aug 18 13:09:37.641590 2026] [security2:error] [pid 167459:tid 167685] [client 20.124.247.79:16690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/k.php"] [unique_id "aoSDwWr_JutbFb-8svobhwAAAe8"] [Tue Aug 18 13:09:37.644267 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.18.37:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSDwWr_JutbFb-8svobiQAAAec"] [Tue Aug 18 13:09:37.661268 2026] [security2:error] [pid 167459:tid 167680] [client 172.182.217.32:15578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/mm.php"] [unique_id "aoSDwWr_JutbFb-8svobiwAAAeo"] [Tue Aug 18 13:09:37.704994 2026] [security2:error] [pid 167459:tid 167686] [client 74.248.18.37:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wk/index.php"] [unique_id "aoSDwWr_JutbFb-8svobjgAAAfA"] [Tue Aug 18 13:09:37.708177 2026] [security2:error] [pid 167459:tid 167656] [client 158.23.17.4:40395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.serviplascomercio.com.br"] [uri "/bf.php"] [unique_id "aoSDwWr_JutbFb-8svobjwAAAdI"] [Tue Aug 18 13:09:37.712813 2026] [security2:error] [pid 167459:tid 167551] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/default.php"] [unique_id "aoSDwWr_JutbFb-8svobkwABk1s"] [Tue Aug 18 13:09:37.712852 2026] [security2:error] [pid 167459:tid 167639] [client 68.155.154.236:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSDwWr_JutbFb-8svobkgAAAcE"] [Tue Aug 18 13:09:37.720618 2026] [security2:error] [pid 167459:tid 167632] [client 20.203.183.135:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/file1221.php"] [unique_id "aoSDwWr_JutbFb-8svoblAAAAbo"] [Tue Aug 18 13:09:37.746452 2026] [security2:error] [pid 167459:tid 167642] [client 149.34.210.141:58257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDwWr_JutbFb-8svobqAAAAcQ"] [Tue Aug 18 13:09:37.766830 2026] [security2:error] [pid 167459:tid 167715] [client 52.139.47.57:13706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/app.php"] [unique_id "aoSDwWr_JutbFb-8svobqQAAAg0"] [Tue Aug 18 13:09:37.768362 2026] [security2:error] [pid 167459:tid 167610] [client 20.1.169.243:9686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/plugins.php"] [unique_id "aoSDwWr_JutbFb-8svobqgAAAaQ"] [Tue Aug 18 13:09:37.789110 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:37.789582 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:37.791641 2026] [security2:error] [pid 167459:tid 167591] [client 68.221.73.131:52399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/dex.php"] [unique_id "aoSDwWr_JutbFb-8svobrgAAAZE"] [Tue Aug 18 13:09:37.827364 2026] [security2:error] [pid 167459:tid 167611] [client 20.250.13.23:39274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSDwWr_JutbFb-8svobsgAAAaU"] [Tue Aug 18 13:09:37.842771 2026] [security2:error] [pid 167459:tid 167619] [client 4.232.151.198:12030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/ms-edit.php"] [unique_id "aoSDwWr_JutbFb-8svobswAAAa0"] [Tue Aug 18 13:09:37.848198 2026] [security2:error] [pid 167459:tid 167482] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/dex.php"] [unique_id "aoSDwWr_JutbFb-8svobtAACBhY"] [Tue Aug 18 13:09:37.874630 2026] [security2:error] [pid 167459:tid 167673] [client 20.104.49.167:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/k.php"] [unique_id "aoSDwWr_JutbFb-8svobtQAAAeM"] [Tue Aug 18 13:09:37.904828 2026] [security2:error] [pid 167459:tid 167671] [client 20.127.136.245:10032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/class-t.api.php"] [unique_id "aoSDwWr_JutbFb-8svobugAAAeE"] [Tue Aug 18 13:09:37.910790 2026] [security2:error] [pid 167459:tid 167608] [client 20.38.3.247:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/adminner.php"] [unique_id "aoSDwWr_JutbFb-8svobuwAAAaI"] [Tue Aug 18 13:09:37.951199 2026] [security2:error] [pid 167459:tid 167613] [client 20.124.247.79:16747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/82.php"] [unique_id "aoSDwWr_JutbFb-8svobvQAAAac"] [Tue Aug 18 13:09:37.985957 2026] [security2:error] [pid 167459:tid 167556] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/df.php"] [unique_id "aoSDwWr_JutbFb-8svobvwAB-WA"] [Tue Aug 18 13:09:38.026731 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSDwmr_JutbFb-8svobwQAAAgU"] [Tue Aug 18 13:09:38.026842 2026] [security2:error] [pid 167459:tid 167642] [client 149.34.210.141:58257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDwWr_JutbFb-8svobqAAAAcQ"] [Tue Aug 18 13:09:38.121774 2026] [security2:error] [pid 167459:tid 167586] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/disagrsxr.php"] [unique_id "aoSDwmr_JutbFb-8svobxQAB634"] [Tue Aug 18 13:09:38.133805 2026] [security2:error] [pid 167459:tid 167684] [client 20.1.169.243:9691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/radio.php"] [unique_id "aoSDwmr_JutbFb-8svobxgAAAe4"] [Tue Aug 18 13:09:38.135967 2026] [security2:error] [pid 167459:tid 167616] [client 20.203.183.135:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/nox.php"] [unique_id "aoSDwmr_JutbFb-8svobxwAAAao"] [Tue Aug 18 13:09:38.155948 2026] [security2:error] [pid 167459:tid 167606] [client 172.182.217.32:15795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/network.php"] [unique_id "aoSDwmr_JutbFb-8svobyAAAAaA"] [Tue Aug 18 13:09:38.188621 2026] [security2:error] [pid 167459:tid 167666] [client 158.23.17.4:41880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wu.php"] [unique_id "aoSDwmr_JutbFb-8svobywAAAdw"] [Tue Aug 18 13:09:38.188641 2026] [security2:error] [pid 167459:tid 167662] [client 52.139.47.57:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/archive.php"] [unique_id "aoSDwmr_JutbFb-8svobygAAAdg"] [Tue Aug 18 13:09:38.219917 2026] [security2:error] [pid 167459:tid 167612] [client 20.116.17.175:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wg459o.php"] [unique_id "aoSDwmr_JutbFb-8svobzAAAAaY"] [Tue Aug 18 13:09:38.223605 2026] [security2:error] [pid 167459:tid 167600] [client 20.91.215.254:16855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/images/wso.php"] [unique_id "aoSDwmr_JutbFb-8svobzQAAAZo"] [Tue Aug 18 13:09:38.239679 2026] [security2:error] [pid 167459:tid 167702] [client 213.35.127.232:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDwmr_JutbFb-8svobzgAAAgA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:38.258845 2026] [security2:error] [pid 167459:tid 167654] [client 20.38.3.247:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/abcd.php"] [unique_id "aoSDwmr_JutbFb-8svob0wAAAdA"] [Tue Aug 18 13:09:38.264449 2026] [security2:error] [pid 167459:tid 167503] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/domvf.php"] [unique_id "aoSDwmr_JutbFb-8svob1AACBys"] [Tue Aug 18 13:09:38.282476 2026] [security2:error] [pid 167459:tid 167714] [client 68.155.154.236:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSDwmr_JutbFb-8svob1QAAAgw"] [Tue Aug 18 13:09:38.284460 2026] [security2:error] [pid 167459:tid 167592] [client 20.124.247.79:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/dex.php"] [unique_id "aoSDwmr_JutbFb-8svob1gAAAZI"] [Tue Aug 18 13:09:38.400555 2026] [security2:error] [pid 167459:tid 167491] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/dropdown.php"] [unique_id "aoSDwmr_JutbFb-8svob3QAB8B8"] [Tue Aug 18 13:09:38.418861 2026] [security2:error] [pid 167459:tid 167665] [client 20.104.100.201:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-good.php"] [unique_id "aoSDwmr_JutbFb-8svob3gAAAds"] [Tue Aug 18 13:09:38.449545 2026] [security2:error] [pid 167459:tid 167672] [client 20.250.13.23:5612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/al.php"] [unique_id "aoSDwmr_JutbFb-8svob4AAAAeI"] [Tue Aug 18 13:09:38.499767 2026] [security2:error] [pid 167459:tid 167680] [client 20.1.169.243:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/rem.php"] [unique_id "aoSDwmr_JutbFb-8svob4wAAAeo"] [Tue Aug 18 13:09:38.534897 2026] [security2:error] [pid 167459:tid 167585] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSDwmr_JutbFb-8svob5QABtn0"] [Tue Aug 18 13:09:38.568645 2026] [security2:error] [pid 167459:tid 167627] [client 20.203.183.135:29386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/akismet.php"] [unique_id "aoSDwmr_JutbFb-8svob7QAAAbU"] [Tue Aug 18 13:09:38.593268 2026] [security2:error] [pid 167459:tid 167611] [client 20.38.3.247:39066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/simple.php"] [unique_id "aoSDwmr_JutbFb-8svob7gAAAaU"] [Tue Aug 18 13:09:38.607468 2026] [security2:error] [pid 167459:tid 167626] [client 20.124.247.79:16758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/puc.php"] [unique_id "aoSDwmr_JutbFb-8svob7wAAAbQ"] [Tue Aug 18 13:09:38.616838 2026] [security2:error] [pid 167459:tid 167599] [client 52.139.47.57:18511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/as.php"] [unique_id "aoSDwmr_JutbFb-8svob8AAAAZk"] [Tue Aug 18 13:09:38.640887 2026] [security2:error] [pid 167459:tid 167632] [client 20.250.13.23:5341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/past1.php"] [unique_id "aoSDwmr_JutbFb-8svob8gAAAbo"] [Tue Aug 18 13:09:38.642135 2026] [security2:error] [pid 167459:tid 167715] [client 172.182.217.32:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/new.php"] [unique_id "aoSDwmr_JutbFb-8svob8wAAAg0"] [Tue Aug 18 13:09:38.650769 2026] [security2:error] [pid 167459:tid 167673] [client 40.74.65.169:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/82.php"] [unique_id "aoSDwmr_JutbFb-8svob9AAAAeM"] [Tue Aug 18 13:09:38.669961 2026] [security2:error] [pid 167459:tid 167641] [client 74.248.18.37:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSDwmr_JutbFb-8svob9QAAAcM"] [Tue Aug 18 13:09:38.670055 2026] [security2:error] [pid 167459:tid 167489] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/edit.php"] [unique_id "aoSDwmr_JutbFb-8svob9gABrh0"] [Tue Aug 18 13:09:38.686418 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:38.686678 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:38.695053 2026] [security2:error] [pid 167459:tid 167643] [client 68.155.154.236:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSDwmr_JutbFb-8svob-AAAAcU"] [Tue Aug 18 13:09:38.806577 2026] [security2:error] [pid 167459:tid 167529] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/elp.php"] [unique_id "aoSDwmr_JutbFb-8svob_AABmEU"] [Tue Aug 18 13:09:38.880000 2026] [security2:error] [pid 167459:tid 167664] [client 4.232.151.198:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/a7.php"] [unique_id "aoSDwmr_JutbFb-8svob_wAAAdo"] [Tue Aug 18 13:09:38.906070 2026] [security2:error] [pid 167459:tid 167683] [client 20.65.98.162:47057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/.mopj.php"] [unique_id "aoSDwmr_JutbFb-8svocAQAAAe0"] [Tue Aug 18 13:09:38.910049 2026] [security2:error] [pid 167459:tid 167650] [client 20.124.247.79:16716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/inso.php"] [unique_id "aoSDwmr_JutbFb-8svocAgAAAcw"] [Tue Aug 18 13:09:38.926415 2026] [security2:error] [pid 167459:tid 167698] [client 20.38.3.247:35961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/wp-manager.php"] [unique_id "aoSDwmr_JutbFb-8svocAwAAAfw"] [Tue Aug 18 13:09:38.940669 2026] [security2:error] [pid 167459:tid 167462] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/email.php"] [unique_id "aoSDwmr_JutbFb-8svocBAAB6wI"] [Tue Aug 18 13:09:38.951505 2026] [security2:error] [pid 167459:tid 167705] [client 20.1.169.243:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/server.php"] [unique_id "aoSDwmr_JutbFb-8svocBQAAAgM"] [Tue Aug 18 13:09:38.978018 2026] [security2:error] [pid 167459:tid 167697] [client 20.127.136.245:22015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/edit.php"] [unique_id "aoSDwmr_JutbFb-8svocBgAAAfs"] [Tue Aug 18 13:09:38.996419 2026] [security2:error] [pid 167459:tid 167637] [client 20.203.183.135:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/admin.php"] [unique_id "aoSDwmr_JutbFb-8svocCgAAAb8"] [Tue Aug 18 13:09:39.031106 2026] [security2:error] [pid 167459:tid 167716] [client 52.139.47.57:18510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/assets/images/doc.php"] [unique_id "aoSDw2r_JutbFb-8svocDAAAAg4"] [Tue Aug 18 13:09:39.069250 2026] [security2:error] [pid 167459:tid 167679] [client 20.91.215.254:22273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/index/function.php"] [unique_id "aoSDw2r_JutbFb-8svocDgAAAek"] [Tue Aug 18 13:09:39.075031 2026] [security2:error] [pid 167459:tid 167642] [client 20.250.13.23:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp.php"] [unique_id "aoSDw2r_JutbFb-8svocDwAAAcQ"] [Tue Aug 18 13:09:39.075096 2026] [security2:error] [pid 167459:tid 167511] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/error.php"] [unique_id "aoSDw2r_JutbFb-8svocEAACBzM"] [Tue Aug 18 13:09:39.108059 2026] [authz_core:error] [pid 167459:tid 167692] [client 192.178.4.133:37241] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:39.108307 2026] [authz_core:error] [pid 167459:tid 167692] [client 192.178.4.133:37241] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:39.125261 2026] [security2:error] [pid 167459:tid 167606] [client 172.182.217.32:15559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/0x.php"] [unique_id "aoSDw2r_JutbFb-8svocFQAAAaA"] [Tue Aug 18 13:09:39.137413 2026] [security2:error] [pid 167459:tid 167646] [client 74.248.133.44:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wk/index.php"] [unique_id "aoSDw2r_JutbFb-8svocFgAAAcg"] [Tue Aug 18 13:09:39.181099 2026] [security2:error] [pid 167459:tid 167590] [client 74.248.18.37:23142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/about.php"] [unique_id "aoSDw2r_JutbFb-8svocGQAAAZA"] [Tue Aug 18 13:09:39.204043 2026] [security2:error] [pid 167459:tid 167651] [client 20.124.247.79:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/aa.php"] [unique_id "aoSDw2r_JutbFb-8svocGgAAAc0"] [Tue Aug 18 13:09:39.208904 2026] [security2:error] [pid 167459:tid 167515] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/f35.php"] [unique_id "aoSDw2r_JutbFb-8svocGwAB8Dc"] [Tue Aug 18 13:09:39.246235 2026] [security2:error] [pid 167459:tid 167656] [client 68.155.154.236:27574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSDw2r_JutbFb-8svocHgAAAdI"] [Tue Aug 18 13:09:39.254934 2026] [security2:error] [pid 167459:tid 167602] [client 213.35.127.232:62763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDw2r_JutbFb-8svocHwAAAZw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:39.258191 2026] [security2:error] [pid 167459:tid 167639] [client 20.38.3.247:18513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/xiugai.php"] [unique_id "aoSDw2r_JutbFb-8svocIAAAAcE"] [Tue Aug 18 13:09:39.266306 2026] [security2:error] [pid 167459:tid 167682] [client 20.250.13.23:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/file61.php"] [unique_id "aoSDw2r_JutbFb-8svocIwAAAew"] [Tue Aug 18 13:09:39.274946 2026] [security2:error] [pid 167459:tid 167684] [client 74.248.18.37:15041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSDw2r_JutbFb-8svocJgAAAe4"] [Tue Aug 18 13:09:39.305680 2026] [security2:error] [pid 167459:tid 167597] [client 74.248.18.37:3374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSDw2r_JutbFb-8svocKAAAAZc"] [Tue Aug 18 13:09:39.314822 2026] [security2:error] [pid 167459:tid 167604] [client 157.20.138.62:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocKQAAAZ4"] [Tue Aug 18 13:09:39.314952 2026] [security2:error] [pid 167459:tid 167604] [client 157.20.138.62:61562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocKQAAAZ4"] [Tue Aug 18 13:09:39.325388 2026] [security2:error] [pid 167459:tid 167711] [client 158.23.17.4:5045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/de.php"] [unique_id "aoSDw2r_JutbFb-8svocKgAAAgk"] [Tue Aug 18 13:09:39.329796 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:10491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/settings.php"] [unique_id "aoSDw2r_JutbFb-8svocKwAAAgQ"] [Tue Aug 18 13:09:39.348204 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/f35.update.php"] [unique_id "aoSDw2r_JutbFb-8svocLAACARk"] [Tue Aug 18 13:09:39.398988 2026] [security2:error] [pid 167459:tid 167613] [client 178.153.171.161:34391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocLwAAAac"] [Tue Aug 18 13:09:39.399119 2026] [security2:error] [pid 167459:tid 167613] [client 178.153.171.161:34391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocLwAAAac"] [Tue Aug 18 13:09:39.413824 2026] [security2:error] [pid 167459:tid 167633] [client 20.203.183.135:29288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.183.203.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/ajax.php"] [unique_id "aoSDw2r_JutbFb-8svocMAAAAbs"] [Tue Aug 18 13:09:39.458454 2026] [security2:error] [pid 167459:tid 167618] [client 52.139.47.57:18558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/atomlib.php"] [unique_id "aoSDw2r_JutbFb-8svocMwAAAaw"] [Tue Aug 18 13:09:39.482172 2026] [security2:error] [pid 167459:tid 167505] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/file.php"] [unique_id "aoSDw2r_JutbFb-8svocNAABtS0"] [Tue Aug 18 13:09:39.516677 2026] [security2:error] [pid 167459:tid 167599] [client 20.38.3.247:16025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/nope.php"] [unique_id "aoSDw2r_JutbFb-8svocNQAAAZk"] [Tue Aug 18 13:09:39.531371 2026] [fcgid:warn] [pid 167459:tid 167673] (70014)End of file found: [client 199.45.154.66:35942] mod_fcgid: can't get data from http client [Tue Aug 18 13:09:39.565309 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:13944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wmore1.php"] [unique_id "aoSDw2r_JutbFb-8svocOAAAAZs"] [Tue Aug 18 13:09:39.620601 2026] [security2:error] [pid 167459:tid 167578] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/file2.php"] [unique_id "aoSDw2r_JutbFb-8svocOgABvnY"] [Tue Aug 18 13:09:39.639082 2026] [security2:error] [pid 167459:tid 167603] [client 172.182.217.32:15806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/0.php"] [unique_id "aoSDw2r_JutbFb-8svocPQAAAZ0"] [Tue Aug 18 13:09:39.642694 2026] [security2:error] [pid 167459:tid 167676] [client 20.38.3.247:6789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/wp-load.php"] [unique_id "aoSDw2r_JutbFb-8svocPgAAAeY"] [Tue Aug 18 13:09:39.653049 2026] [security2:error] [pid 167459:tid 167688] [client 20.124.247.79:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/img.php"] [unique_id "aoSDw2r_JutbFb-8svocPwAAAfI"] [Tue Aug 18 13:09:39.690753 2026] [security2:error] [pid 167459:tid 167712] [client 20.116.17.175:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/mifta.php"] [unique_id "aoSDw2r_JutbFb-8svocQQAAAgo"] [Tue Aug 18 13:09:39.697655 2026] [authz_core:error] [pid 167459:tid 167519] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:39.697917 2026] [authz_core:error] [pid 167459:tid 167519] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:39.699276 2026] [security2:error] [pid 167459:tid 167668] [client 20.1.169.243:10253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/sf.php"] [unique_id "aoSDw2r_JutbFb-8svocRAAAAd4"] [Tue Aug 18 13:09:39.708831 2026] [security2:error] [pid 167459:tid 167611] [client 20.91.215.254:22276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/info.php"] [unique_id "aoSDw2r_JutbFb-8svocRQAAAaU"] [Tue Aug 18 13:09:39.714812 2026] [security2:error] [pid 167459:tid 167626] [client 20.250.13.23:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-activat.php"] [unique_id "aoSDw2r_JutbFb-8svocRwAAAbQ"] [Tue Aug 18 13:09:39.720168 2026] [security2:error] [pid 167459:tid 167698] [client 20.100.169.31:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSDw2r_JutbFb-8svocSAAAAfw"] [Tue Aug 18 13:09:39.729396 2026] [security2:error] [pid 167459:tid 167705] [client 40.74.65.169:5657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dex.php"] [unique_id "aoSDw2r_JutbFb-8svocSQAAAgM"] [Tue Aug 18 13:09:39.730941 2026] [security2:error] [pid 167459:tid 167620] [client 74.7.228.10:54784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.restaurantefeiticosdasogra.com.br"] [uri "/index.php"] [unique_id "aoSDw2r_JutbFb-8svocQAABrno"] [Tue Aug 18 13:09:39.756816 2026] [security2:error] [pid 167459:tid 167473] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/files.php"] [unique_id "aoSDw2r_JutbFb-8svocSgAB2A0"] [Tue Aug 18 13:09:39.790867 2026] [security2:error] [pid 167459:tid 167674] [client 102.213.179.104:62992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocSwAAAeQ"] [Tue Aug 18 13:09:39.790995 2026] [security2:error] [pid 167459:tid 167674] [client 102.213.179.104:62992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDw2r_JutbFb-8svocSwAAAeQ"] [Tue Aug 18 13:09:39.857346 2026] [security2:error] [pid 167459:tid 167709] [client 158.23.17.4:7200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/se.php"] [unique_id "aoSDw2r_JutbFb-8svocTgAAAgc"] [Tue Aug 18 13:09:39.864565 2026] [security2:error] [pid 167459:tid 167714] [client 68.155.154.236:25364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSDw2r_JutbFb-8svocUAAAAgw"] [Tue Aug 18 13:09:39.870876 2026] [security2:error] [pid 167459:tid 167657] [client 52.139.47.57:18504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/b.php"] [unique_id "aoSDw2r_JutbFb-8svocUQAAAdM"] [Tue Aug 18 13:09:39.891878 2026] [security2:error] [pid 167459:tid 167539] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/fix.php"] [unique_id "aoSDw2r_JutbFb-8svocUwAB-k8"] [Tue Aug 18 13:09:39.904636 2026] [autoindex:error] [pid 167459:tid 167687] [client 20.250.13.23:5569] AH01276: Cannot serve directory /home4/alltime/public_html/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:39.928957 2026] [security2:error] [pid 167459:tid 167609] [client 20.124.247.79:15306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/222.php"] [unique_id "aoSDw2r_JutbFb-8svocVQAAAaM"] [Tue Aug 18 13:09:39.945276 2026] [security2:error] [pid 167459:tid 167681] [client 74.248.18.37:3343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSDw2r_JutbFb-8svocVgAAAes"] [Tue Aug 18 13:09:39.983744 2026] [security2:error] [pid 167459:tid 167647] [client 74.248.133.44:42862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/w.php"] [unique_id "aoSDw2r_JutbFb-8svocVwAAAck"] [Tue Aug 18 13:09:39.988607 2026] [security2:error] [pid 167459:tid 167700] [client 20.38.3.247:18539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/155.php"] [unique_id "aoSDw2r_JutbFb-8svocWQAAAf4"] [Tue Aug 18 13:09:39.990770 2026] [security2:error] [pid 167459:tid 167656] [client 158.23.17.4:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/album.php"] [unique_id "aoSDw2r_JutbFb-8svocWgAAAdI"] [Tue Aug 18 13:09:40.027488 2026] [security2:error] [pid 167459:tid 167463] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/fm.php"] [unique_id "aoSDxGr_JutbFb-8svocXAABzgM"] [Tue Aug 18 13:09:40.064497 2026] [security2:error] [pid 167459:tid 167590] [client 20.1.169.243:9695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/size.php"] [unique_id "aoSDxGr_JutbFb-8svocXwAAAZA"] [Tue Aug 18 13:09:40.082225 2026] [security2:error] [pid 167459:tid 167613] [client 20.104.49.167:60873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/82.php"] [unique_id "aoSDxGr_JutbFb-8svocYQAAAac"] [Tue Aug 18 13:09:40.109097 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alltimeadm.com.br"] [uri "/license.php"] [unique_id "aoSDxGr_JutbFb-8svocYgAAAbY"] [Tue Aug 18 13:09:40.127126 2026] [security2:error] [pid 167459:tid 167670] [client 20.171.51.14:2598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/tq.php"] [unique_id "aoSDxGr_JutbFb-8svocYwAAAeA"] [Tue Aug 18 13:09:40.133275 2026] [security2:error] [pid 167459:tid 167607] [client 172.182.217.32:15592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/oxshell.php"] [unique_id "aoSDxGr_JutbFb-8svocZQAAAaE"] [Tue Aug 18 13:09:40.162451 2026] [security2:error] [pid 167459:tid 167562] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/footer.php"] [unique_id "aoSDxGr_JutbFb-8svocagAB3WY"] [Tue Aug 18 13:09:40.173951 2026] [security2:error] [pid 167459:tid 167632] [client 20.38.3.247:2150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/nope.php"] [unique_id "aoSDxGr_JutbFb-8svocbgAAAbo"] [Tue Aug 18 13:09:40.175784 2026] [authz_core:error] [pid 167459:tid 167569] [remote 57.141.22.56:45274] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:40.176039 2026] [authz_core:error] [pid 167459:tid 167569] [remote 57.141.22.56:45274] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:40.279877 2026] [security2:error] [pid 167459:tid 167653] [client 213.35.127.232:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDxGr_JutbFb-8svocdAAAAc8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:40.279888 2026] [security2:error] [pid 167459:tid 167591] [client 52.139.47.57:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/backup.php"] [unique_id "aoSDxGr_JutbFb-8svoccwAAAZE"] [Tue Aug 18 13:09:40.295337 2026] [security2:error] [pid 167459:tid 167641] [client 20.124.247.79:15318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/key.php"] [unique_id "aoSDxGr_JutbFb-8svocdgAAAcM"] [Tue Aug 18 13:09:40.298077 2026] [security2:error] [pid 167459:tid 167577] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/form.php"] [unique_id "aoSDxGr_JutbFb-8svocdwAB9HU"] [Tue Aug 18 13:09:40.299067 2026] [security2:error] [pid 167459:tid 167697] [client 4.232.151.198:48823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/manager.php"] [unique_id "aoSDxGr_JutbFb-8svoceAAAAfs"] [Tue Aug 18 13:09:40.300306 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:40.300583 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:40.313831 2026] [security2:error] [pid 167459:tid 167716] [client 74.248.18.37:26283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/bgymj.php"] [unique_id "aoSDxGr_JutbFb-8svoceQAAAg4"] [Tue Aug 18 13:09:40.343471 2026] [security2:error] [pid 167459:tid 167692] [client 20.38.3.247:3621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/index.php"] [unique_id "aoSDxGr_JutbFb-8svocfAAAAfY"] [Tue Aug 18 13:09:40.347013 2026] [security2:error] [pid 167459:tid 167669] [client 20.250.13.23:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSDxGr_JutbFb-8svocfQAAAd8"] [Tue Aug 18 13:09:40.351742 2026] [security2:error] [pid 167459:tid 167615] [client 20.91.215.254:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/profile.php"] [unique_id "aoSDxGr_JutbFb-8svocfgAAAak"] [Tue Aug 18 13:09:40.386097 2026] [security2:error] [pid 167459:tid 167713] [client 20.206.73.37:52903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/gm.php"] [unique_id "aoSDxGr_JutbFb-8svocgAAAAgs"] [Tue Aug 18 13:09:40.401651 2026] [security2:error] [pid 167459:tid 167661] [client 158.23.17.4:5007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/kv.php"] [unique_id "aoSDxGr_JutbFb-8svocggAAAdc"] [Tue Aug 18 13:09:40.434793 2026] [security2:error] [pid 167459:tid 167655] [client 20.1.169.243:9706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/staging/wp-content/test.php"] [unique_id "aoSDxGr_JutbFb-8svochAAAAdE"] [Tue Aug 18 13:09:40.435188 2026] [security2:error] [pid 167459:tid 167537] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/fpwch.php"] [unique_id "aoSDxGr_JutbFb-8svochQAB5k0"] [Tue Aug 18 13:09:40.475288 2026] [security2:error] [pid 167459:tid 167594] [client 40.74.65.169:5650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/puc.php"] [unique_id "aoSDxGr_JutbFb-8svociAAAAZQ"] [Tue Aug 18 13:09:40.493441 2026] [security2:error] [pid 167459:tid 167668] [client 20.104.100.201:62714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/special.php"] [unique_id "aoSDxGr_JutbFb-8svociQAAAd4"] [Tue Aug 18 13:09:40.545228 2026] [security2:error] [pid 167459:tid 167620] [client 68.155.154.236:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSDxGr_JutbFb-8svociwAAAa4"] [Tue Aug 18 13:09:40.569701 2026] [security2:error] [pid 167459:tid 167497] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/function.php"] [unique_id "aoSDxGr_JutbFb-8svocjAAB0CU"] [Tue Aug 18 13:09:40.601521 2026] [authz_core:error] [pid 167459:tid 167553] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:40.601804 2026] [authz_core:error] [pid 167459:tid 167553] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:40.621225 2026] [security2:error] [pid 167459:tid 167712] [client 172.182.217.32:15567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/php8.php"] [unique_id "aoSDxGr_JutbFb-8svockQAAAgo"] [Tue Aug 18 13:09:40.650590 2026] [security2:error] [pid 167459:tid 167596] [client 158.23.17.4:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/vp.php"] [unique_id "aoSDxGr_JutbFb-8svockwAAAZY"] [Tue Aug 18 13:09:40.668087 2026] [security2:error] [pid 167459:tid 167602] [client 101.53.230.88:48307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.230.53.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxGr_JutbFb-8svoclAAAAZw"] [Tue Aug 18 13:09:40.668191 2026] [security2:error] [pid 167459:tid 167602] [client 101.53.230.88:48307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxGr_JutbFb-8svoclAAAAZw"] [Tue Aug 18 13:09:40.695893 2026] [security2:error] [pid 167459:tid 167646] [client 20.38.3.247:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/aaa.php"] [unique_id "aoSDxGr_JutbFb-8svoclgAAAcg"] [Tue Aug 18 13:09:40.697159 2026] [security2:error] [pid 167459:tid 167637] [client 52.139.47.57:13755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bak.php"] [unique_id "aoSDxGr_JutbFb-8svoclwAAAb8"] [Tue Aug 18 13:09:40.701460 2026] [security2:error] [pid 167459:tid 167658] [client 20.38.3.247:24422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/new.php"] [unique_id "aoSDxGr_JutbFb-8svocmQAAAdQ"] [Tue Aug 18 13:09:40.705788 2026] [security2:error] [pid 167459:tid 167534] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/g.php"] [unique_id "aoSDxGr_JutbFb-8svocmgABo0o"] [Tue Aug 18 13:09:40.768525 2026] [security2:error] [pid 167459:tid 167651] [client 20.124.247.79:16763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/chosen.php"] [unique_id "aoSDxGr_JutbFb-8svocnAAAAc0"] [Tue Aug 18 13:09:40.789166 2026] [security2:error] [pid 167459:tid 167686] [client 201.32.74.208:57368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSDxGr_JutbFb-8svocnQAAAfA"] [Tue Aug 18 13:09:40.802701 2026] [security2:error] [pid 167459:tid 167685] [client 20.1.169.243:9673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/storage/index.php"] [unique_id "aoSDxGr_JutbFb-8svocngAAAe8"] [Tue Aug 18 13:09:40.840905 2026] [security2:error] [pid 167459:tid 167571] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/goods.php"] [unique_id "aoSDxGr_JutbFb-8svocoQAB5W8"] [Tue Aug 18 13:09:40.863342 2026] [security2:error] [pid 167459:tid 167612] [client 20.65.98.162:45772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/bengi.php"] [unique_id "aoSDxGr_JutbFb-8svocogAAAaY"] [Tue Aug 18 13:09:40.906183 2026] [security2:error] [pid 167459:tid 167607] [client 20.127.136.245:1620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/ff1.php"] [unique_id "aoSDxGr_JutbFb-8svocpQAAAaE"] [Tue Aug 18 13:09:40.969940 2026] [security2:error] [pid 167459:tid 167681] [client 20.250.13.23:18139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/past1.php"] [unique_id "aoSDxGr_JutbFb-8svocqAAAAes"] [Tue Aug 18 13:09:40.975635 2026] [security2:error] [pid 167459:tid 167478] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/gtt.php"] [unique_id "aoSDxGr_JutbFb-8svocqQACDRI"] [Tue Aug 18 13:09:41.000955 2026] [security2:error] [pid 167459:tid 167593] [client 20.91.215.254:16834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/sx.php"] [unique_id "aoSDxWr_JutbFb-8svocrQAAAZM"] [Tue Aug 18 13:09:41.043418 2026] [security2:error] [pid 167459:tid 167636] [client 74.248.18.37:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSDxWr_JutbFb-8svocsAAAAb4"] [Tue Aug 18 13:09:41.064974 2026] [security2:error] [pid 167459:tid 167624] [client 20.100.169.31:3476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDxWr_JutbFb-8svocsgAAAbI"] [Tue Aug 18 13:09:41.106474 2026] [security2:error] [pid 167459:tid 167643] [client 20.124.247.79:16643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/wpxml.php"] [unique_id "aoSDxWr_JutbFb-8svoctgAAAcU"] [Tue Aug 18 13:09:41.107524 2026] [security2:error] [pid 167459:tid 167625] [client 20.38.3.247:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/FWAZ.php"] [unique_id "aoSDxWr_JutbFb-8svoctwAAAbM"] [Tue Aug 18 13:09:41.111390 2026] [security2:error] [pid 167459:tid 167708] [client 172.182.217.32:15772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/p.php"] [unique_id "aoSDxWr_JutbFb-8svocuQAAAgY"] [Tue Aug 18 13:09:41.117926 2026] [security2:error] [pid 167459:tid 167591] [client 52.139.47.57:18513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bgymj.php"] [unique_id "aoSDxWr_JutbFb-8svocuwAAAZE"] [Tue Aug 18 13:09:41.127687 2026] [security2:error] [pid 167459:tid 167552] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/gulu.php"] [unique_id "aoSDxWr_JutbFb-8svocvAAB0Vw"] [Tue Aug 18 13:09:41.171235 2026] [security2:error] [pid 167459:tid 167629] [client 20.1.169.243:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/storage/min.php"] [unique_id "aoSDxWr_JutbFb-8svocvQAAAbc"] [Tue Aug 18 13:09:41.200030 2026] [security2:error] [pid 167459:tid 167668] [client 40.74.65.169:5638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/inso.php"] [unique_id "aoSDxWr_JutbFb-8svocwAAAAd4"] [Tue Aug 18 13:09:41.200393 2026] [security2:error] [pid 167459:tid 167649] [client 20.104.49.167:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/dex.php"] [unique_id "aoSDxWr_JutbFb-8svocwQAAAcs"] [Tue Aug 18 13:09:41.203841 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:41.204106 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:41.264085 2026] [security2:error] [pid 167459:tid 167580] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/hello.php"] [unique_id "aoSDxWr_JutbFb-8svocwwAB6Hg"] [Tue Aug 18 13:09:41.278849 2026] [security2:error] [pid 167459:tid 167626] [client 74.248.18.37:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/term.php"] [unique_id "aoSDxWr_JutbFb-8svocxAAAAbQ"] [Tue Aug 18 13:09:41.313078 2026] [security2:error] [pid 167459:tid 167711] [client 213.35.127.232:63204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDxWr_JutbFb-8svocxgAAAgk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:41.335154 2026] [security2:error] [pid 167459:tid 167714] [client 20.104.100.201:13927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDxWr_JutbFb-8svocxwAAAgw"] [Tue Aug 18 13:09:41.341237 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:18369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/xyn.php"] [unique_id "aoSDxWr_JutbFb-8svocyAAAAZI"] [Tue Aug 18 13:09:41.352991 2026] [security2:error] [pid 167459:tid 167712] [client 68.155.154.236:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSDxWr_JutbFb-8svocygAAAgo"] [Tue Aug 18 13:09:41.394626 2026] [security2:error] [pid 167459:tid 167650] [client 4.232.151.198:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/w1.php"] [unique_id "aoSDxWr_JutbFb-8svoczAAAAcw"] [Tue Aug 18 13:09:41.398446 2026] [security2:error] [pid 167459:tid 167490] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSDxWr_JutbFb-8svoczQAB-h4"] [Tue Aug 18 13:09:41.421393 2026] [security2:error] [pid 167459:tid 167586] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoczgABsX4"] [Tue Aug 18 13:09:41.422096 2026] [security2:error] [pid 167459:tid 167623] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoczgABsX4"] [Tue Aug 18 13:09:41.433588 2026] [security2:error] [pid 167459:tid 167687] [client 20.38.3.247:16028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/new.php"] [unique_id "aoSDxWr_JutbFb-8svoczwAAAfE"] [Tue Aug 18 13:09:41.441404 2026] [security2:error] [pid 167459:tid 167637] [client 20.38.3.247:3624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/site.php"] [unique_id "aoSDxWr_JutbFb-8svoc0QAAAb8"] [Tue Aug 18 13:09:41.470758 2026] [security2:error] [pid 167459:tid 167618] [client 20.124.247.79:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/file1221.php"] [unique_id "aoSDxWr_JutbFb-8svoc0wAAAaw"] [Tue Aug 18 13:09:41.533101 2026] [security2:error] [pid 167459:tid 167503] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/images/class-config.php"] [unique_id "aoSDxWr_JutbFb-8svoc1QAB7is"] [Tue Aug 18 13:09:41.562580 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:35291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bi.php"] [unique_id "aoSDxWr_JutbFb-8svoc1wAAAcA"] [Tue Aug 18 13:09:41.592794 2026] [security2:error] [pid 167459:tid 167662] [client 74.248.18.37:14400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/aa.php"] [unique_id "aoSDxWr_JutbFb-8svoc2QAAAdg"] [Tue Aug 18 13:09:41.597756 2026] [security2:error] [pid 167459:tid 167646] [client 172.182.217.32:15562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/php.php"] [unique_id "aoSDxWr_JutbFb-8svoc2gAAAcg"] [Tue Aug 18 13:09:41.633510 2026] [security2:error] [pid 167459:tid 167703] [client 20.91.215.254:16879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSDxWr_JutbFb-8svoc3AAAAgE"] [Tue Aug 18 13:09:41.665796 2026] [security2:error] [pid 167459:tid 167658] [client 20.250.13.23:5317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/file61.php"] [unique_id "aoSDxWr_JutbFb-8svoc3wAAAdQ"] [Tue Aug 18 13:09:41.694823 2026] [security2:error] [pid 167459:tid 167619] [client 20.206.73.37:26581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/ws55.php"] [unique_id "aoSDxWr_JutbFb-8svoc4wAAAa0"] [Tue Aug 18 13:09:41.698695 2026] [security2:error] [pid 167459:tid 167700] [client 20.100.169.31:3355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSDxWr_JutbFb-8svoc5AAAAf4"] [Tue Aug 18 13:09:41.709299 2026] [security2:error] [pid 167459:tid 167676] [client 197.184.64.235:42702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoc5QAAAeY"] [Tue Aug 18 13:09:41.709470 2026] [security2:error] [pid 167459:tid 167676] [client 197.184.64.235:42702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoc5QAAAeY"] [Tue Aug 18 13:09:41.710512 2026] [security2:error] [pid 167459:tid 167709] [client 20.1.169.243:10232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/test.php"] [unique_id "aoSDxWr_JutbFb-8svoc5gAAAgc"] [Tue Aug 18 13:09:41.715663 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.49.167:63711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/puc.php"] [unique_id "aoSDxWr_JutbFb-8svoc5wAAAZU"] [Tue Aug 18 13:09:41.734568 2026] [security2:error] [pid 167459:tid 167599] [client 20.116.17.175:22697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/dot.php"] [unique_id "aoSDxWr_JutbFb-8svoc6wAAAZk"] [Tue Aug 18 13:09:41.744263 2026] [security2:error] [pid 167459:tid 167632] [client 20.124.247.79:16652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/nox.php"] [unique_id "aoSDxWr_JutbFb-8svoc7AAAAbo"] [Tue Aug 18 13:09:41.781580 2026] [security2:error] [pid 167459:tid 167715] [client 20.171.51.14:23545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/cv.php"] [unique_id "aoSDxWr_JutbFb-8svoc7gAAAg0"] [Tue Aug 18 13:09:41.792088 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/z.php"] [unique_id "aoSDxWr_JutbFb-8svoc8AAAAfs"] [Tue Aug 18 13:09:41.805262 2026] [authz_core:error] [pid 167459:tid 167468] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:41.805547 2026] [authz_core:error] [pid 167459:tid 167468] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:41.807314 2026] [security2:error] [pid 167459:tid 167593] [client 20.38.3.247:33668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/ccc.php"] [unique_id "aoSDxWr_JutbFb-8svoc8wAAAZM"] [Tue Aug 18 13:09:41.810223 2026] [security2:error] [pid 167459:tid 167576] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/images/index.php"] [unique_id "aoSDxWr_JutbFb-8svoc9AABqXQ"] [Tue Aug 18 13:09:41.813757 2026] [security2:error] [pid 167459:tid 167690] [client 68.155.154.236:25366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSDxWr_JutbFb-8svoc9QAAAfQ"] [Tue Aug 18 13:09:41.899061 2026] [security2:error] [pid 167459:tid 167706] [client 138.36.100.162:43132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoc-wAAAgQ"] [Tue Aug 18 13:09:41.899164 2026] [security2:error] [pid 167459:tid 167706] [client 138.36.100.162:43132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDxWr_JutbFb-8svoc-wAAAgQ"] [Tue Aug 18 13:09:41.936274 2026] [security2:error] [pid 167459:tid 167692] [client 40.74.65.169:5677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/aa.php"] [unique_id "aoSDxWr_JutbFb-8svoc_QAAAfY"] [Tue Aug 18 13:09:41.936900 2026] [security2:error] [pid 167459:tid 167707] [client 74.248.18.37:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSDxWr_JutbFb-8svoc_gAAAgU"] [Tue Aug 18 13:09:41.943664 2026] [security2:error] [pid 167459:tid 167496] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/index/function.php"] [unique_id "aoSDxWr_JutbFb-8svoc_wAB_SQ"] [Tue Aug 18 13:09:41.989641 2026] [security2:error] [pid 167459:tid 167671] [client 52.139.47.57:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/blog.php"] [unique_id "aoSDxWr_JutbFb-8svodAgAAAeE"] [Tue Aug 18 13:09:42.015241 2026] [security2:error] [pid 167459:tid 167654] [client 20.104.100.201:13869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/thoms.php"] [unique_id "aoSDxmr_JutbFb-8svodBAAAAdA"] [Tue Aug 18 13:09:42.077543 2026] [security2:error] [pid 167459:tid 167518] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/info.php"] [unique_id "aoSDxmr_JutbFb-8svodCQAB-jo"] [Tue Aug 18 13:09:42.077714 2026] [security2:error] [pid 167459:tid 167661] [client 213.202.253.4:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/gdftps.php"] [unique_id "aoSDxmr_JutbFb-8svodCAAAAdc"], referer: www.google.com [Tue Aug 18 13:09:42.081883 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/test1.php"] [unique_id "aoSDxmr_JutbFb-8svodCgAAAec"] [Tue Aug 18 13:09:42.084388 2026] [security2:error] [pid 167459:tid 167589] [client 172.182.217.32:15568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/past.php"] [unique_id "aoSDxmr_JutbFb-8svodCwAAAY8"] [Tue Aug 18 13:09:42.087053 2026] [security2:error] [pid 167459:tid 167665] [client 20.124.247.79:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/akismet.php"] [unique_id "aoSDxmr_JutbFb-8svodDQAAAds"] [Tue Aug 18 13:09:42.180580 2026] [security2:error] [pid 167459:tid 167652] [client 20.38.3.247:44084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/admin.php"] [unique_id "aoSDxmr_JutbFb-8svodEQAAAc4"] [Tue Aug 18 13:09:42.196228 2026] [security2:error] [pid 167459:tid 167609] [client 20.104.49.167:8583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/inso.php"] [unique_id "aoSDxmr_JutbFb-8svodEgAAAaM"] [Tue Aug 18 13:09:42.198762 2026] [security2:error] [pid 167459:tid 167662] [client 74.249.206.207:50096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/admin.php"] [unique_id "aoSDxmr_JutbFb-8svodEwAAAdg"] [Tue Aug 18 13:09:42.213200 2026] [security2:error] [pid 167459:tid 167529] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/install.php"] [unique_id "aoSDxmr_JutbFb-8svodFAAByEU"] [Tue Aug 18 13:09:42.300547 2026] [security2:error] [pid 167459:tid 167702] [client 20.65.98.162:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/file2.php"] [unique_id "aoSDxmr_JutbFb-8svodGwAAAgA"] [Tue Aug 18 13:09:42.312344 2026] [security2:error] [pid 167459:tid 167597] [client 74.248.133.44:35475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/css/wp-login.php"] [unique_id "aoSDxmr_JutbFb-8svodHAAAAZc"] [Tue Aug 18 13:09:42.322202 2026] [security2:error] [pid 167459:tid 167632] [client 68.155.154.236:4048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSDxmr_JutbFb-8svodHQAAAbo"] [Tue Aug 18 13:09:42.322484 2026] [security2:error] [pid 167459:tid 167712] [client 20.91.215.254:16858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSDxmr_JutbFb-8svodHgAAAgo"] [Tue Aug 18 13:09:42.324165 2026] [security2:error] [pid 167459:tid 167647] [client 20.100.169.31:3346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSDxmr_JutbFb-8svodHwAAAck"] [Tue Aug 18 13:09:42.331252 2026] [security2:error] [pid 167459:tid 167678] [client 213.35.127.232:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDxmr_JutbFb-8svodIAAAAeg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:42.346682 2026] [security2:error] [pid 167459:tid 167536] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/item.php"] [unique_id "aoSDxmr_JutbFb-8svodIQABm0w"] [Tue Aug 18 13:09:42.379265 2026] [security2:error] [pid 167459:tid 167640] [client 20.127.136.245:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/fff.php"] [unique_id "aoSDxmr_JutbFb-8svodJQAAAcI"] [Tue Aug 18 13:09:42.403957 2026] [security2:error] [pid 167459:tid 167619] [client 52.139.47.57:35273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bs1.php"] [unique_id "aoSDxmr_JutbFb-8svodJwAAAa0"] [Tue Aug 18 13:09:42.450206 2026] [security2:error] [pid 167459:tid 167681] [client 20.1.169.243:10299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/thoms.php"] [unique_id "aoSDxmr_JutbFb-8svodKQAAAes"] [Tue Aug 18 13:09:42.468906 2026] [security2:error] [pid 167459:tid 167643] [client 20.124.247.79:15314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/admin.php"] [unique_id "aoSDxmr_JutbFb-8svodKgAAAcU"] [Tue Aug 18 13:09:42.482160 2026] [security2:error] [pid 167459:tid 167541] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/kir.php"] [unique_id "aoSDxmr_JutbFb-8svodKwABplE"] [Tue Aug 18 13:09:42.494473 2026] [security2:error] [pid 167459:tid 167688] [client 20.250.13.23:5623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sunlux.com.br"] [uri "/license.php"] [unique_id "aoSDxmr_JutbFb-8svodLQAAAfI"] [Tue Aug 18 13:09:42.498387 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-login.php"] [unique_id "aoSDxmr_JutbFb-8svodLwAAAfY"] [Tue Aug 18 13:09:42.506700 2026] [autoindex:error] [pid 167459:tid 167673] [client 199.45.154.66:40312] AH01276: Cannot serve directory /home1/copaibas/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:42.527149 2026] [security2:error] [pid 167459:tid 167707] [client 20.38.3.247:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/reviall.php"] [unique_id "aoSDxmr_JutbFb-8svodMAAAAgU"] [Tue Aug 18 13:09:42.572384 2026] [security2:error] [pid 167459:tid 167605] [client 172.182.217.32:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/root.php"] [unique_id "aoSDxmr_JutbFb-8svodMgAAAZ8"] [Tue Aug 18 13:09:42.575831 2026] [security2:error] [pid 167459:tid 167606] [client 74.248.18.37:25372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSDxmr_JutbFb-8svodMwAAAaA"] [Tue Aug 18 13:09:42.586762 2026] [security2:error] [pid 167459:tid 167649] [client 40.74.65.169:4420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDxmr_JutbFb-8svodNAAAAcs"] [Tue Aug 18 13:09:42.595626 2026] [access_compat:error] [pid 167459:tid 167524] [remote 74.7.228.202:45402] AH01797: client denied by server configuration: /home3/restaura/public_html/xmlrpc.php, referer: https://www.restaurantefeiticosdasogra.com.br/ [Tue Aug 18 13:09:42.706876 2026] [security2:error] [pid 167459:tid 167613] [client 40.74.65.169:6216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/img.php"] [unique_id "aoSDxmr_JutbFb-8svodOwAAAac"] [Tue Aug 18 13:09:42.715965 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:42.716377 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:42.756037 2026] [lsapi:error] [pid 167459:tid 167511] [remote 34.73.137.196:51954] [host csleducacional.com.br] Backend fatal error: PHP Fatal error: Uncaught TypeError: implode(): Argument #2 ($array) must be of type ?array, string given in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php:528\nStack trace:\n#0 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(528): implode(Array, '|')\n#1 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php(314): MatthiasMullie\\Minify\\CSS->shortenColors('.elementor-kit-...')\n#2 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/Minify.php(111): MatthiasMullie\\Minify\\CSS->execute(NULL)\n#3 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(175): MatthiasMullie\\Minify\\Minify->minify()\n#4 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(128): WP_Rocket\\Optimization\\CSS\\Minify->minify('/home3/csleduca...', '/home3/csleduca...')\n#5 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/optimization/CSS/class-minify.php(66): WP_Rocket\\Optimization\\CSS\\Minify->replace_url('https://csleduc...')\n#6 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-abstract-minify-subscriber.php(85): WP_Rocket\\Optimization\\CSS\\Minify->optimize('...')\n#7 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/subscriber/Optimization/class-minify-css-subscriber.php(44): WP_Rocket\\Subscriber\\Optimization\\Minify_Subscriber->optimize('...')\n#8 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): WP_Rocket\\Subscriber\\Optimization\\Minify_CSS_Subscriber->process('...')\n#9 /home3/csleduca/public_html/wp-includes/plugin.php(205): WP_Hook->apply_filters('...', Array)\n#10 /home3/csleduca/public_html/wp-content/plugins/wp-rocket/inc/classes/Buffer/class-optimization.php(104): apply_filters('rocket_buffer', '...')\n#11 [internal function]: WP_Rocket\\Buffer\\Optimization->maybe_process_buffer('...', 9)\n#12 /home3/csleduca/public_html/wp-includes/functions.php(5493): ob_end_flush()\n#13 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(341): wp_ob_end_flush_all('')\n#14 /home3/csleduca/public_html/wp-includes/class-wp-hook.php(365): WP_Hook->apply_filters(NULL, Array)\n#15 /home3/csleduca/public_html/wp-includes/plugin.php(522): WP_Hook->do_action(Array)\n#16 /home3/csleduca/public_html/wp-includes/load.php(1308): do_action('shutdown')\n#17 [internal function]: shutdown_action_hook()\n#18 {main}\n thrown in /home3/csleduca/public_html/wp-content/plugins/wp-rocket/vendor/matthiasmullie/minify/src/CSS.php on line 528\n [Tue Aug 18 13:09:42.773191 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/log.php"] [unique_id "aoSDxmr_JutbFb-8svodPgABrBk"] [Tue Aug 18 13:09:42.790364 2026] [security2:error] [pid 167459:tid 167685] [client 20.38.3.247:2122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/apreset.php"] [unique_id "aoSDxmr_JutbFb-8svodPwAAAe8"] [Tue Aug 18 13:09:42.801620 2026] [security2:error] [pid 167459:tid 167616] [client 20.104.100.201:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSDxmr_JutbFb-8svodQAAAAao"] [Tue Aug 18 13:09:42.803198 2026] [security2:error] [pid 167459:tid 167596] [client 20.124.247.79:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/ajax.php"] [unique_id "aoSDxmr_JutbFb-8svodQQAAAZY"] [Tue Aug 18 13:09:42.818164 2026] [security2:error] [pid 167459:tid 167598] [client 158.23.17.4:63008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ph.php"] [unique_id "aoSDxmr_JutbFb-8svodQgAAAZg"] [Tue Aug 18 13:09:42.834469 2026] [security2:error] [pid 167459:tid 167592] [client 52.139.47.57:35297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bthil.php"] [unique_id "aoSDxmr_JutbFb-8svodQwAAAZI"] [Tue Aug 18 13:09:42.866388 2026] [autoindex:error] [pid 167459:tid 167708] [client 172.182.217.32:15245] AH01276: Cannot serve directory /home3/ewao7iz2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:42.871916 2026] [security2:error] [pid 167459:tid 167623] [client 20.1.169.243:9724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/tiny.php"] [unique_id "aoSDxmr_JutbFb-8svodRgAAAbE"] [Tue Aug 18 13:09:42.899891 2026] [security2:error] [pid 167459:tid 167666] [client 68.155.154.236:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSDxmr_JutbFb-8svodRwAAAdw"] [Tue Aug 18 13:09:42.906607 2026] [security2:error] [pid 167459:tid 167522] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/logins.php"] [unique_id "aoSDxmr_JutbFb-8svodSAABkD4"] [Tue Aug 18 13:09:42.913185 2026] [security2:error] [pid 167459:tid 167663] [client 20.38.3.247:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/nope.php"] [unique_id "aoSDxmr_JutbFb-8svodSQAAAdk"] [Tue Aug 18 13:09:42.922886 2026] [security2:error] [pid 167459:tid 167675] [client 20.104.49.167:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/aa.php"] [unique_id "aoSDxmr_JutbFb-8svodSgAAAeU"] [Tue Aug 18 13:09:42.934183 2026] [security2:error] [pid 167459:tid 167680] [client 196.12.128.158:58040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDxmr_JutbFb-8svodSwAAAeo"] [Tue Aug 18 13:09:42.934287 2026] [security2:error] [pid 167459:tid 167680] [client 196.12.128.158:58040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSDxmr_JutbFb-8svodSwAAAeo"] [Tue Aug 18 13:09:42.936930 2026] [security2:error] [pid 167459:tid 167610] [client 167.235.143.113:39860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.connectformaturas.com.br"] [uri "/index.php"] [unique_id "aoSDxWr_JutbFb-8svoc7wAAAaQ"], referer: https://www.connectformaturas.com.br [Tue Aug 18 13:09:42.949042 2026] [security2:error] [pid 167459:tid 167651] [client 201.32.74.208:57370] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "image/bmp"] [severity "WARNING"] [hostname "pensamentosimperfeitos.com.br"] [uri "/wp-json/wp/v2/media"] [unique_id "aoSDxmr_JutbFb-8svodTQAAAc0"] [Tue Aug 18 13:09:43.021176 2026] [security2:error] [pid 167459:tid 167620] [client 195.2.67.184:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ealoggroup.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSDx2r_JutbFb-8svodUQAAAa4"], referer: https://ealoggroup.com.br/ [Tue Aug 18 13:09:43.039926 2026] [security2:error] [pid 167459:tid 167565] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/mailer.php"] [unique_id "aoSDx2r_JutbFb-8svodUwACC2k"] [Tue Aug 18 13:09:43.062468 2026] [security2:error] [pid 167459:tid 167662] [client 172.182.217.32:15805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/r.php"] [unique_id "aoSDx2r_JutbFb-8svodWAAAAdg"] [Tue Aug 18 13:09:43.082432 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.18.37:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDx2r_JutbFb-8svodWQAAAc4"] [Tue Aug 18 13:09:43.093426 2026] [security2:error] [pid 167459:tid 167639] [client 20.124.247.79:16704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/abe.php"] [unique_id "aoSDx2r_JutbFb-8svodWgAAAcE"] [Tue Aug 18 13:09:43.108145 2026] [security2:error] [pid 167459:tid 167697] [client 20.51.153.15:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDx2r_JutbFb-8svodXQAAAfs"] [Tue Aug 18 13:09:43.165284 2026] [security2:error] [pid 167459:tid 167557] [remote 20.87.239.85:15235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "konneqt.cloud"] [uri "/wp-login.php"] [unique_id "aoSDx2r_JutbFb-8svodZAAB9WE"] [Tue Aug 18 13:09:43.179789 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/min.php"] [unique_id "aoSDx2r_JutbFb-8svodZQABpRU"] [Tue Aug 18 13:09:43.196676 2026] [security2:error] [pid 167459:tid 167698] [client 158.23.17.4:7340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xg.php"] [unique_id "aoSDx2r_JutbFb-8svodZgAAAfw"] [Tue Aug 18 13:09:43.217228 2026] [security2:error] [pid 167459:tid 167606] [client 20.206.73.37:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/m.php"] [unique_id "aoSDx2r_JutbFb-8svodagAAAaA"] [Tue Aug 18 13:09:43.221507 2026] [security2:error] [pid 167459:tid 167649] [client 20.91.215.254:22330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSDx2r_JutbFb-8svodbwAAAcs"] [Tue Aug 18 13:09:43.239153 2026] [security2:error] [pid 167459:tid 167706] [client 20.1.169.243:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/tool.php"] [unique_id "aoSDx2r_JutbFb-8svoddwAAAgQ"] [Tue Aug 18 13:09:43.251212 2026] [security2:error] [pid 167459:tid 167562] [remote 66.116.199.98:36404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "site.supercarconsulting.com.br"] [uri "/wp-login.php"] [unique_id "aoSDx2r_JutbFb-8svodeAABomY"] [Tue Aug 18 13:09:43.251382 2026] [security2:error] [pid 167459:tid 167612] [client 52.139.47.57:18555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/bypass.php"] [unique_id "aoSDx2r_JutbFb-8svodewAAAaY"] [Tue Aug 18 13:09:43.263187 2026] [security2:error] [pid 167459:tid 167613] [client 20.38.3.247:41795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/nope.php"] [unique_id "aoSDx2r_JutbFb-8svodfQAAAac"] [Tue Aug 18 13:09:43.266891 2026] [security2:error] [pid 167459:tid 167641] [client 74.248.18.37:25386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSDx2r_JutbFb-8svodfgAAAcM"] [Tue Aug 18 13:09:43.289791 2026] [security2:error] [pid 167459:tid 167664] [client 40.74.65.169:4858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDx2r_JutbFb-8svodfwAAAdo"] [Tue Aug 18 13:09:43.350747 2026] [security2:error] [pid 167459:tid 167686] [client 20.124.247.79:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/bs1.php"] [unique_id "aoSDx2r_JutbFb-8svodhQAAAfA"] [Tue Aug 18 13:09:43.354808 2026] [security2:error] [pid 167459:tid 167616] [client 20.104.100.201:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wmore1.php"] [unique_id "aoSDx2r_JutbFb-8svodhgAAAao"] [Tue Aug 18 13:09:43.358004 2026] [security2:error] [pid 167459:tid 167599] [client 213.35.127.232:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDx2r_JutbFb-8svodiAAAAZk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:43.362781 2026] [security2:error] [pid 167459:tid 167687] [client 20.51.153.15:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDx2r_JutbFb-8svodiQAAAfE"] [Tue Aug 18 13:09:43.364427 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:43.364684 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:43.465158 2026] [security2:error] [pid 167459:tid 167633] [client 20.38.3.247:16051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/1mage.php"] [unique_id "aoSDx2r_JutbFb-8svodjwAAAbs"] [Tue Aug 18 13:09:43.479033 2026] [security2:error] [pid 167459:tid 167497] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/mini.php"] [unique_id "aoSDx2r_JutbFb-8svodkgAB1iU"] [Tue Aug 18 13:09:43.545403 2026] [security2:error] [pid 167459:tid 167532] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.env"] [unique_id "aoSDx2r_JutbFb-8svodlgABo0g"] [Tue Aug 18 13:09:43.547991 2026] [security2:error] [pid 167459:tid 167676] [client 68.155.154.236:27547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSDx2r_JutbFb-8svodlwAAAeY"] [Tue Aug 18 13:09:43.552297 2026] [security2:error] [pid 167459:tid 167628] [client 172.182.217.32:15801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/sid3.php"] [unique_id "aoSDx2r_JutbFb-8svodmAAAAbY"] [Tue Aug 18 13:09:43.560200 2026] [security2:error] [pid 167459:tid 167630] [client 20.104.49.167:19602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/img.php"] [unique_id "aoSDx2r_JutbFb-8svodmQAAAbg"] [Tue Aug 18 13:09:43.587405 2026] [security2:error] [pid 167459:tid 167620] [client 20.124.247.79:16663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/yes.php"] [unique_id "aoSDx2r_JutbFb-8svodnAAAAa4"] [Tue Aug 18 13:09:43.597341 2026] [security2:error] [pid 167459:tid 167632] [client 20.51.153.15:13428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/st.php"] [unique_id "aoSDx2r_JutbFb-8svodqgAAAbo"] [Tue Aug 18 13:09:43.605181 2026] [security2:error] [pid 167459:tid 167689] [client 20.1.169.243:10283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/top.php"] [unique_id "aoSDx2r_JutbFb-8svodsgAAAfM"] [Tue Aug 18 13:09:43.609891 2026] [security2:error] [pid 167459:tid 167667] [client 20.38.3.247:3628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/new.php"] [unique_id "aoSDx2r_JutbFb-8svodtAAAAd0"] [Tue Aug 18 13:09:43.624487 2026] [security2:error] [pid 167459:tid 167555] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/moddofuns.php"] [unique_id "aoSDx2r_JutbFb-8svodtgABz18"] [Tue Aug 18 13:09:43.683952 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:5669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/222.php"] [unique_id "aoSDx2r_JutbFb-8svodvAAAAbI"] [Tue Aug 18 13:09:43.721747 2026] [security2:error] [pid 167459:tid 167586] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.env.backup"] [unique_id "aoSDx2r_JutbFb-8svodvgABo34"] [Tue Aug 18 13:09:43.725764 2026] [security2:error] [pid 167459:tid 167688] [client 20.100.169.31:18998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/wp-themes.php"] [unique_id "aoSDx2r_JutbFb-8svodvwAAAfI"] [Tue Aug 18 13:09:43.743311 2026] [security2:error] [pid 167459:tid 167691] [client 20.127.136.245:1657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/inputs.php"] [unique_id "aoSDx2r_JutbFb-8svodwAAAAfU"] [Tue Aug 18 13:09:43.753615 2026] [security2:error] [pid 167459:tid 167528] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.env.bak"] [unique_id "aoSDx2r_JutbFb-8svodwgABo0Q"] [Tue Aug 18 13:09:43.760617 2026] [security2:error] [pid 167459:tid 167503] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSDx2r_JutbFb-8svodwwABpSs"] [Tue Aug 18 13:09:43.802123 2026] [security2:error] [pid 167459:tid 167649] [client 52.139.47.57:35309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cc.php"] [unique_id "aoSDx2r_JutbFb-8svodzgAAAcs"] [Tue Aug 18 13:09:43.805236 2026] [security2:error] [pid 167459:tid 167499] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.env.old"] [unique_id "aoSDx2r_JutbFb-8svodzwABoyc"] [Tue Aug 18 13:09:43.834039 2026] [security2:error] [pid 167459:tid 167642] [client 20.104.100.201:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/root.php"] [unique_id "aoSDx2r_JutbFb-8svod0AAAAcQ"] [Tue Aug 18 13:09:43.873048 2026] [security2:error] [pid 167459:tid 167703] [client 20.124.247.79:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/go.php"] [unique_id "aoSDx2r_JutbFb-8svod1wAAAgE"] [Tue Aug 18 13:09:43.873556 2026] [security2:error] [pid 167459:tid 167663] [client 114.5.214.109:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod1gAAAdk"] [Tue Aug 18 13:09:43.873655 2026] [security2:error] [pid 167459:tid 167663] [client 114.5.214.109:50424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod1gAAAdk"] [Tue Aug 18 13:09:43.883299 2026] [security2:error] [pid 167459:tid 167671] [client 103.120.71.157:65054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod2gAAAeE"] [Tue Aug 18 13:09:43.883399 2026] [security2:error] [pid 167459:tid 167671] [client 103.120.71.157:65054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod2gAAAeE"] [Tue Aug 18 13:09:43.883915 2026] [security2:error] [pid 167459:tid 167670] [client 49.145.211.146:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod2QAAAeA"] [Tue Aug 18 13:09:43.884014 2026] [security2:error] [pid 167459:tid 167670] [client 49.145.211.146:13087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDx2r_JutbFb-8svod2QAAAeA"] [Tue Aug 18 13:09:43.888038 2026] [security2:error] [pid 167459:tid 167533] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/api/.env"] [unique_id "aoSDx2r_JutbFb-8svod2wABo0k"] [Tue Aug 18 13:09:43.889728 2026] [security2:error] [pid 167459:tid 167692] [client 4.232.151.198:38047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/default.php"] [unique_id "aoSDx2r_JutbFb-8svod3AAAAfY"] [Tue Aug 18 13:09:43.895687 2026] [security2:error] [pid 167459:tid 167502] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/moduless.php"] [unique_id "aoSDx2r_JutbFb-8svod3QABoio"] [Tue Aug 18 13:09:43.896968 2026] [security2:error] [pid 167459:tid 167592] [client 74.248.133.44:20664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "aoSDx2r_JutbFb-8svod3wAAAZI"] [Tue Aug 18 13:09:43.898434 2026] [security2:error] [pid 167459:tid 167521] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/backend/.env"] [unique_id "aoSDx2r_JutbFb-8svod3gABoz0"] [Tue Aug 18 13:09:43.918288 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:43.918551 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:43.941858 2026] [security2:error] [pid 167459:tid 167673] [client 74.248.18.37:35094] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "jx2.com.br"] [uri "/1.php"] [unique_id "aoSDx2r_JutbFb-8svod6wAAAeM"] [Tue Aug 18 13:09:43.941973 2026] [security2:error] [pid 167459:tid 167673] [client 74.248.18.37:35094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/1.php"] [unique_id "aoSDx2r_JutbFb-8svod6wAAAeM"] [Tue Aug 18 13:09:43.945087 2026] [security2:error] [pid 167459:tid 167468] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/config/.env"] [unique_id "aoSDx2r_JutbFb-8svod7AABowg"] [Tue Aug 18 13:09:43.961653 2026] [security2:error] [pid 167459:tid 167657] [client 20.38.3.247:44082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/new.php"] [unique_id "aoSDx2r_JutbFb-8svod7gAAAdM"] [Tue Aug 18 13:09:43.964115 2026] [security2:error] [pid 167459:tid 167696] [client 158.23.17.4:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/nd.php"] [unique_id "aoSDx2r_JutbFb-8svod8AAAAfo"] [Tue Aug 18 13:09:43.971874 2026] [security2:error] [pid 167459:tid 167664] [client 20.38.3.247:21266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/imsc.php"] [unique_id "aoSDx2r_JutbFb-8svod8QAAAdo"] [Tue Aug 18 13:09:43.973080 2026] [security2:error] [pid 167459:tid 167704] [client 20.1.169.243:9709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/txets.php"] [unique_id "aoSDx2r_JutbFb-8svod8gAAAgI"] [Tue Aug 18 13:09:43.974315 2026] [security2:error] [pid 167459:tid 167684] [client 20.51.153.15:13419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/le.php"] [unique_id "aoSDx2r_JutbFb-8svod8wAAAe4"] [Tue Aug 18 13:09:43.975661 2026] [security2:error] [pid 167459:tid 167668] [client 40.74.65.169:4591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/media.php"] [unique_id "aoSDx2r_JutbFb-8svod9AAAAd4"] [Tue Aug 18 13:09:43.999069 2026] [security2:error] [pid 167459:tid 167618] [client 68.155.154.236:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSDx2r_JutbFb-8svod9QAAAaw"] [Tue Aug 18 13:09:44.030135 2026] [security2:error] [pid 167459:tid 167515] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/ms-edit.php"] [unique_id "aoSDyGr_JutbFb-8svod-gAB_Tc"] [Tue Aug 18 13:09:44.037446 2026] [security2:error] [pid 167459:tid 167626] [client 172.182.217.32:15571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ss.php"] [unique_id "aoSDyGr_JutbFb-8svod_AAAAbQ"] [Tue Aug 18 13:09:44.067190 2026] [security2:error] [pid 167459:tid 167616] [client 20.91.215.254:16865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/about.php"] [unique_id "aoSDyGr_JutbFb-8svod_wAAAao"] [Tue Aug 18 13:09:44.091362 2026] [security2:error] [pid 167459:tid 167596] [client 20.116.17.175:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/index2.php"] [unique_id "aoSDyGr_JutbFb-8svoeAAAAAZY"] [Tue Aug 18 13:09:44.121244 2026] [security2:error] [pid 167459:tid 167701] [client 74.248.18.37:3370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDyGr_JutbFb-8svoeAwAAAf8"] [Tue Aug 18 13:09:44.141508 2026] [security2:error] [pid 167459:tid 167623] [client 20.171.51.14:10890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/un.php"] [unique_id "aoSDyGr_JutbFb-8svoeBAAAAbE"] [Tue Aug 18 13:09:44.166530 2026] [security2:error] [pid 167459:tid 167509] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/new.php"] [unique_id "aoSDyGr_JutbFb-8svoeBwABmjE"] [Tue Aug 18 13:09:44.168954 2026] [security2:error] [pid 167459:tid 167680] [client 20.124.247.79:15300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/cof.php"] [unique_id "aoSDyGr_JutbFb-8svoeCAAAAeo"] [Tue Aug 18 13:09:44.232052 2026] [security2:error] [pid 167459:tid 167709] [client 20.51.153.15:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/hr.php"] [unique_id "aoSDyGr_JutbFb-8svoeDgAAAgc"] [Tue Aug 18 13:09:44.244574 2026] [security2:error] [pid 167459:tid 167687] [client 52.139.47.57:18517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "aoSDyGr_JutbFb-8svoeDwAAAfE"] [Tue Aug 18 13:09:44.288814 2026] [security2:error] [pid 167459:tid 167620] [client 20.65.98.162:6077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/gm.php"] [unique_id "aoSDyGr_JutbFb-8svoeEQAAAa4"] [Tue Aug 18 13:09:44.302017 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSDyGr_JutbFb-8svoeEwAB8xU"] [Tue Aug 18 13:09:44.310083 2026] [security2:error] [pid 167459:tid 167700] [client 20.38.3.247:3608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/apreset.php"] [unique_id "aoSDyGr_JutbFb-8svoeFwAAAf4"] [Tue Aug 18 13:09:44.327693 2026] [security2:error] [pid 167459:tid 167647] [client 20.206.73.37:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/33.php"] [unique_id "aoSDyGr_JutbFb-8svoeGAAAAck"] [Tue Aug 18 13:09:44.347885 2026] [security2:error] [pid 167459:tid 167708] [client 20.100.169.31:3378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patecnologia.com"] [uri "/xmlrpc.php"] [unique_id "aoSDyGr_JutbFb-8svoeGQAAAgY"] [Tue Aug 18 13:09:44.350452 2026] [security2:error] [pid 167459:tid 167676] [client 20.1.169.243:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/virus.php"] [unique_id "aoSDyGr_JutbFb-8svoeGgAAAeY"] [Tue Aug 18 13:09:44.361253 2026] [security2:error] [pid 167459:tid 167558] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.github/.env"] [unique_id "aoSDyGr_JutbFb-8svoeGwABo2I"] [Tue Aug 18 13:09:44.377086 2026] [security2:error] [pid 167459:tid 167640] [client 158.23.17.4:38364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ri.php"] [unique_id "aoSDyGr_JutbFb-8svoeHQAAAcI"] [Tue Aug 18 13:09:44.378447 2026] [security2:error] [pid 167459:tid 167685] [client 213.35.127.232:63843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDyGr_JutbFb-8svoeHgAAAe8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:44.418263 2026] [security2:error] [pid 167459:tid 167622] [client 20.38.3.247:2469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDyGr_JutbFb-8svoeIQAAAbA"] [Tue Aug 18 13:09:44.439853 2026] [security2:error] [pid 167459:tid 167525] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/num.php"] [unique_id "aoSDyGr_JutbFb-8svoeJAAB8kE"] [Tue Aug 18 13:09:44.445272 2026] [security2:error] [pid 167459:tid 167517] [remote 180.93.1.219:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.1.93.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mempel.com.br"] [uri "/wp-login.php"] [unique_id "aoSDyGr_JutbFb-8svoeIwACBDk"] [Tue Aug 18 13:09:44.497633 2026] [security2:error] [pid 167459:tid 167593] [client 68.155.154.236:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSDyGr_JutbFb-8svoeJgAAAZM"] [Tue Aug 18 13:09:44.513387 2026] [security2:error] [pid 167459:tid 167703] [client 20.51.153.15:13436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kt.php"] [unique_id "aoSDyGr_JutbFb-8svoeJwAAAgE"] [Tue Aug 18 13:09:44.518606 2026] [security2:error] [pid 167459:tid 167692] [client 20.124.247.79:15328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/Engine.php"] [unique_id "aoSDyGr_JutbFb-8svoeKAAAAfY"] [Tue Aug 18 13:09:44.527087 2026] [security2:error] [pid 167459:tid 167683] [client 172.182.217.32:15761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/sts.php"] [unique_id "aoSDyGr_JutbFb-8svoeKgAAAe0"] [Tue Aug 18 13:09:44.574017 2026] [security2:error] [pid 167459:tid 167519] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/php.php"] [unique_id "aoSDyGr_JutbFb-8svoeLgABzTs"] [Tue Aug 18 13:09:44.639435 2026] [security2:error] [pid 167459:tid 167598] [client 20.38.3.247:37541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/1mage.php"] [unique_id "aoSDyGr_JutbFb-8svoeMgAAAZg"] [Tue Aug 18 13:09:44.659553 2026] [security2:error] [pid 167459:tid 167625] [client 40.74.65.169:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/admin.php"] [unique_id "aoSDyGr_JutbFb-8svoeNQAAAbM"] [Tue Aug 18 13:09:44.664319 2026] [security2:error] [pid 167459:tid 167702] [client 158.23.17.4:15764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/s.php"] [unique_id "aoSDyGr_JutbFb-8svoeNgAAAgA"] [Tue Aug 18 13:09:44.668203 2026] [security2:error] [pid 167459:tid 167623] [client 40.74.65.169:5689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/key.php"] [unique_id "aoSDyGr_JutbFb-8svoeNwAAAbE"] [Tue Aug 18 13:09:44.687491 2026] [security2:error] [pid 167459:tid 167590] [client 20.104.49.167:8867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/222.php"] [unique_id "aoSDyGr_JutbFb-8svoeOQAAAZA"] [Tue Aug 18 13:09:44.693381 2026] [security2:error] [pid 167459:tid 167648] [client 49.37.150.8:60927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyGr_JutbFb-8svoeOgAAAco"] [Tue Aug 18 13:09:44.693546 2026] [security2:error] [pid 167459:tid 167648] [client 49.37.150.8:60927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyGr_JutbFb-8svoeOgAAAco"] [Tue Aug 18 13:09:44.703409 2026] [security2:error] [pid 167459:tid 167642] [client 20.91.215.254:16868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "aoSDyGr_JutbFb-8svoeOwAAAcQ"] [Tue Aug 18 13:09:44.708152 2026] [security2:error] [pid 167459:tid 167514] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/php/eval-stdin.php"] [unique_id "aoSDyGr_JutbFb-8svoePAABmjY"] [Tue Aug 18 13:09:44.727343 2026] [authz_core:error] [pid 167459:tid 167582] [remote 34.73.137.196:51954] AH01630: client denied by server configuration: /home3/csleduca/public_html/.htpasswd [Tue Aug 18 13:09:44.728305 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:10268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/we.php"] [unique_id "aoSDyGr_JutbFb-8svoeQwAAAbQ"] [Tue Aug 18 13:09:44.753528 2026] [security2:error] [pid 167459:tid 167716] [client 74.248.18.37:25373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyGr_JutbFb-8svoeRgAAAg4"] [Tue Aug 18 13:09:44.756868 2026] [security2:error] [pid 167459:tid 167631] [client 20.51.153.15:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ww.php"] [unique_id "aoSDyGr_JutbFb-8svoeRwAAAbk"] [Tue Aug 18 13:09:44.794841 2026] [security2:error] [pid 167459:tid 167660] [client 52.139.47.57:18551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDyGr_JutbFb-8svoeSAAAAdY"] [Tue Aug 18 13:09:44.825752 2026] [security2:error] [pid 167459:tid 167643] [client 74.248.133.44:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/file5.php"] [unique_id "aoSDyGr_JutbFb-8svoeSgAAAcU"] [Tue Aug 18 13:09:44.833183 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:13928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/fpwch.php"] [unique_id "aoSDyGr_JutbFb-8svoeTAAAAbU"] [Tue Aug 18 13:09:44.836199 2026] [security2:error] [pid 167459:tid 167595] [client 20.124.247.79:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/hehe.php"] [unique_id "aoSDyGr_JutbFb-8svoeTQAAAZU"] [Tue Aug 18 13:09:44.837711 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:44.838141 2026] [authz_core:error] [pid 167459:tid 167505] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:44.856906 2026] [security2:error] [pid 167459:tid 167572] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/php8.php"] [unique_id "aoSDyGr_JutbFb-8svoeTwAB8XA"] [Tue Aug 18 13:09:44.970269 2026] [security2:error] [pid 167459:tid 167676] [client 20.38.3.247:33630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/imsc.php"] [unique_id "aoSDyGr_JutbFb-8svoeVAAAAeY"] [Tue Aug 18 13:09:45.002864 2026] [security2:error] [pid 167459:tid 167516] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSDyWr_JutbFb-8svoeVgACCjg"] [Tue Aug 18 13:09:45.016774 2026] [security2:error] [pid 167459:tid 167498] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyWr_JutbFb-8svoeWgAB-CY"] [Tue Aug 18 13:09:45.016966 2026] [security2:error] [pid 167459:tid 167694] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyWr_JutbFb-8svoeWgAB-CY"] [Tue Aug 18 13:09:45.017614 2026] [security2:error] [pid 167459:tid 167669] [client 172.182.217.32:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/shell.php"] [unique_id "aoSDyWr_JutbFb-8svoeWwAAAd8"] [Tue Aug 18 13:09:45.040088 2026] [security2:error] [pid 167459:tid 167652] [client 20.51.153.15:13342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mo.php"] [unique_id "aoSDyWr_JutbFb-8svoeXQAAAc4"] [Tue Aug 18 13:09:45.171242 2026] [security2:error] [pid 167459:tid 167621] [client 68.155.154.236:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSDyWr_JutbFb-8svoeYwAAAa8"] [Tue Aug 18 13:09:45.197858 2026] [security2:error] [pid 167459:tid 167478] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSDyWr_JutbFb-8svoeZAABkxI"] [Tue Aug 18 13:09:45.200336 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.49.167:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/key.php"] [unique_id "aoSDyWr_JutbFb-8svoeZgAAAY8"] [Tue Aug 18 13:09:45.212497 2026] [security2:error] [pid 167459:tid 167697] [client 52.139.47.57:9884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "aoSDyWr_JutbFb-8svoeaAAAAfs"] [Tue Aug 18 13:09:45.253852 2026] [security2:error] [pid 167459:tid 167714] [client 158.23.17.4:47639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/uo.php"] [unique_id "aoSDyWr_JutbFb-8svoeagAAAgw"] [Tue Aug 18 13:09:45.257208 2026] [security2:error] [pid 167459:tid 167638] [client 20.124.247.79:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/dkSUq.php"] [unique_id "aoSDyWr_JutbFb-8svoeawAAAcA"] [Tue Aug 18 13:09:45.285178 2026] [security2:error] [pid 167459:tid 167657] [client 20.65.98.162:5264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/ws55.php"] [unique_id "aoSDyWr_JutbFb-8svoebQAAAdM"] [Tue Aug 18 13:09:45.324034 2026] [security2:error] [pid 167459:tid 167629] [client 20.51.153.15:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/qr.php"] [unique_id "aoSDyWr_JutbFb-8svoecwAAAbc"] [Tue Aug 18 13:09:45.324059 2026] [security2:error] [pid 167459:tid 167534] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/id_dsa"] [unique_id "aoSDyWr_JutbFb-8svoecAAB7ko"] [Tue Aug 18 13:09:45.324060 2026] [security2:error] [pid 167459:tid 167571] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/id_rsa"] [unique_id "aoSDyWr_JutbFb-8svoecQAB7m8"] [Tue Aug 18 13:09:45.324139 2026] [security2:error] [pid 167459:tid 167668] [client 158.23.17.4:20658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/tp.php"] [unique_id "aoSDyWr_JutbFb-8svoecgAAAd4"] [Tue Aug 18 13:09:45.335628 2026] [security2:error] [pid 167459:tid 167594] [client 20.38.3.247:46655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/imscjpg.php"] [unique_id "aoSDyWr_JutbFb-8svoedgAAAZQ"] [Tue Aug 18 13:09:45.355128 2026] [security2:error] [pid 167459:tid 167705] [client 20.206.73.37:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.73.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cvwebdesigner.com.br"] [uri "/packed.php"] [unique_id "aoSDyWr_JutbFb-8svoeeAAAAgM"] [Tue Aug 18 13:09:45.365692 2026] [security2:error] [pid 167459:tid 167663] [client 40.74.65.169:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/mac.php"] [unique_id "aoSDyWr_JutbFb-8svoegQAAAdk"] [Tue Aug 18 13:09:45.376620 2026] [security2:error] [pid 167459:tid 167614] [client 86.120.159.145:26165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyWr_JutbFb-8svoeggAAAag"] [Tue Aug 18 13:09:45.376816 2026] [security2:error] [pid 167459:tid 167614] [client 86.120.159.145:26165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDyWr_JutbFb-8svoeggAAAag"] [Tue Aug 18 13:09:45.390664 2026] [security2:error] [pid 167459:tid 167704] [client 74.248.18.37:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/alfa.php"] [unique_id "aoSDyWr_JutbFb-8svoehQAAAgI"] [Tue Aug 18 13:09:45.394338 2026] [security2:error] [pid 167459:tid 167693] [client 213.35.127.232:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDyWr_JutbFb-8svoehgAAAfc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:45.396319 2026] [security2:error] [pid 167459:tid 167560] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/plugins.php"] [unique_id "aoSDyWr_JutbFb-8svoehwACCGQ"] [Tue Aug 18 13:09:45.396633 2026] [security2:error] [pid 167459:tid 167634] [client 20.91.215.254:3401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSDyWr_JutbFb-8svoeiAAAAbw"] [Tue Aug 18 13:09:45.411511 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/work.php"] [unique_id "aoSDyWr_JutbFb-8svoeiQAAAec"] [Tue Aug 18 13:09:45.444138 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:45.444409 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:45.475890 2026] [security2:error] [pid 167459:tid 167468] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/key.pem"] [unique_id "aoSDyWr_JutbFb-8svoeqwABrAg"] [Tue Aug 18 13:09:45.503548 2026] [security2:error] [pid 167459:tid 167591] [client 172.182.217.32:15803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/setup-config.php"] [unique_id "aoSDyWr_JutbFb-8svoerQAAAZE"] [Tue Aug 18 13:09:45.520563 2026] [security2:error] [pid 167459:tid 167709] [client 20.124.247.79:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/qwas.php"] [unique_id "aoSDyWr_JutbFb-8svoergAAAgc"] [Tue Aug 18 13:09:45.531845 2026] [security2:error] [pid 167459:tid 167482] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/radio.php"] [unique_id "aoSDyWr_JutbFb-8svoerwABxRY"] [Tue Aug 18 13:09:45.559377 2026] [security2:error] [pid 167459:tid 167630] [client 20.51.153.15:13347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/dirs.php"] [unique_id "aoSDyWr_JutbFb-8svoesQAAAbg"] [Tue Aug 18 13:09:45.586132 2026] [security2:error] [pid 167459:tid 167544] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/privatekey.key"] [unique_id "aoSDyWr_JutbFb-8svoetQABrFQ"] [Tue Aug 18 13:09:45.629926 2026] [security2:error] [pid 167459:tid 167716] [client 52.139.47.57:35303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/wp-settings.php"] [unique_id "aoSDyWr_JutbFb-8svoeuwAAAg4"] [Tue Aug 18 13:09:45.641600 2026] [security2:error] [pid 167459:tid 167700] [client 20.104.100.201:13891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/mg.php"] [unique_id "aoSDyWr_JutbFb-8svoevQAAAf4"] [Tue Aug 18 13:09:45.674776 2026] [security2:error] [pid 167459:tid 167690] [client 20.104.49.167:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/chosen.php"] [unique_id "aoSDyWr_JutbFb-8svoewQAAAfQ"] [Tue Aug 18 13:09:45.680696 2026] [security2:error] [pid 167459:tid 167524] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/rem.php"] [unique_id "aoSDyWr_JutbFb-8svoexwACBkA"] [Tue Aug 18 13:09:45.728991 2026] [security2:error] [pid 167459:tid 167694] [client 20.38.3.247:33657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/qlex1.php"] [unique_id "aoSDyWr_JutbFb-8svoezAAAAfg"] [Tue Aug 18 13:09:45.747049 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:45.747313 2026] [authz_core:error] [pid 167459:tid 167558] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:45.751606 2026] [security2:error] [pid 167459:tid 167639] [client 68.155.154.236:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSDyWr_JutbFb-8svoezwAAAcE"] [Tue Aug 18 13:09:45.803058 2026] [security2:error] [pid 167459:tid 167633] [client 20.124.247.79:15307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/OK.php"] [unique_id "aoSDyWr_JutbFb-8svoe0QAAAbs"] [Tue Aug 18 13:09:45.815077 2026] [security2:error] [pid 167459:tid 167565] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/server.php"] [unique_id "aoSDyWr_JutbFb-8svoe0wABo2k"] [Tue Aug 18 13:09:45.821479 2026] [security2:error] [pid 167459:tid 167676] [client 20.1.169.243:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin.php"] [unique_id "aoSDyWr_JutbFb-8svoe1gAAAeY"] [Tue Aug 18 13:09:45.852937 2026] [security2:error] [pid 167459:tid 167615] [client 20.51.153.15:13385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sn.php"] [unique_id "aoSDyWr_JutbFb-8svoe2AAAAak"] [Tue Aug 18 13:09:45.890465 2026] [security2:error] [pid 167459:tid 167682] [client 74.248.133.44:30061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/new.php"] [unique_id "aoSDyWr_JutbFb-8svoe2QAAAew"] [Tue Aug 18 13:09:45.936565 2026] [security2:error] [pid 167459:tid 167487] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.openclaw/.env"] [unique_id "aoSDyWr_JutbFb-8svoe3AACBBs"] [Tue Aug 18 13:09:45.952415 2026] [security2:error] [pid 167459:tid 167474] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/settings.php"] [unique_id "aoSDyWr_JutbFb-8svoe3gAB-w4"] [Tue Aug 18 13:09:45.975735 2026] [security2:error] [pid 167459:tid 167692] [client 158.23.17.4:7348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/zj.php"] [unique_id "aoSDyWr_JutbFb-8svoe4AAAAfY"] [Tue Aug 18 13:09:45.990031 2026] [security2:error] [pid 167459:tid 167611] [client 172.182.217.32:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/t.php"] [unique_id "aoSDyWr_JutbFb-8svoe4QAAAaU"] [Tue Aug 18 13:09:45.993221 2026] [security2:error] [pid 167459:tid 167645] [client 40.74.65.169:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/chosen.php"] [unique_id "aoSDyWr_JutbFb-8svoe4gAAAcc"] [Tue Aug 18 13:09:46.035164 2026] [security2:error] [pid 167459:tid 167655] [client 20.91.215.254:22280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/content.php"] [unique_id "aoSDymr_JutbFb-8svoe5AAAAdE"] [Tue Aug 18 13:09:46.043435 2026] [security2:error] [pid 167459:tid 167621] [client 52.139.47.57:35298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "aoSDymr_JutbFb-8svoe5QAAAa8"] [Tue Aug 18 13:09:46.049955 2026] [security2:error] [pid 167459:tid 167605] [client 40.74.65.169:4596] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "maxxirent.pt"] [uri "/1.php"] [unique_id "aoSDymr_JutbFb-8svoe5gAAAZ8"] [Tue Aug 18 13:09:46.050031 2026] [security2:error] [pid 167459:tid 167605] [client 40.74.65.169:4596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/1.php"] [unique_id "aoSDymr_JutbFb-8svoe5gAAAZ8"] [Tue Aug 18 13:09:46.085673 2026] [security2:error] [pid 167459:tid 167691] [client 20.124.247.79:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/13.php"] [unique_id "aoSDymr_JutbFb-8svoe6QAAAfU"] [Tue Aug 18 13:09:46.086029 2026] [security2:error] [pid 167459:tid 167463] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/sf.php"] [unique_id "aoSDymr_JutbFb-8svoe6gABwAM"] [Tue Aug 18 13:09:46.092409 2026] [security2:error] [pid 167459:tid 167507] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.hermes/.env"] [unique_id "aoSDymr_JutbFb-8svoe7AACBC8"] [Tue Aug 18 13:09:46.132978 2026] [security2:error] [pid 167459:tid 167703] [client 158.23.17.4:47632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kx.php"] [unique_id "aoSDymr_JutbFb-8svoe8QAAAgE"] [Tue Aug 18 13:09:46.147467 2026] [security2:error] [pid 167459:tid 167629] [client 20.51.153.15:13438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/43.php"] [unique_id "aoSDymr_JutbFb-8svoe8gAAAbc"] [Tue Aug 18 13:09:46.162687 2026] [security2:error] [pid 167459:tid 167596] [client 20.104.49.167:19619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/wpxml.php"] [unique_id "aoSDymr_JutbFb-8svoe9AAAAZY"] [Tue Aug 18 13:09:46.185105 2026] [security2:error] [pid 167459:tid 167623] [client 68.155.154.236:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSDymr_JutbFb-8svoe9wAAAbE"] [Tue Aug 18 13:09:46.189527 2026] [security2:error] [pid 167459:tid 167693] [client 20.38.3.247:3173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/mariju.php"] [unique_id "aoSDymr_JutbFb-8svoe-gAAAfc"] [Tue Aug 18 13:09:46.220504 2026] [security2:error] [pid 167459:tid 167572] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/size.php"] [unique_id "aoSDymr_JutbFb-8svoe_AABkHA"] [Tue Aug 18 13:09:46.326203 2026] [security2:error] [pid 167459:tid 167591] [client 20.1.169.243:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/about.php"] [unique_id "aoSDymr_JutbFb-8svofAAAAAZE"] [Tue Aug 18 13:09:46.355097 2026] [security2:error] [pid 167459:tid 167537] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/staging/wp-content/test.php"] [unique_id "aoSDymr_JutbFb-8svofAQABxU0"] [Tue Aug 18 13:09:46.364797 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:46.365072 2026] [authz_core:error] [pid 167459:tid 167516] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:46.377096 2026] [security2:error] [pid 167459:tid 167658] [client 5.31.227.224:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDymr_JutbFb-8svofBAAAAdQ"] [Tue Aug 18 13:09:46.381629 2026] [security2:error] [pid 167459:tid 167658] [client 5.31.227.224:59058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDymr_JutbFb-8svofBAAAAdQ"] [Tue Aug 18 13:09:46.387456 2026] [security2:error] [pid 167459:tid 167625] [client 20.51.153.15:13425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fresh.php"] [unique_id "aoSDymr_JutbFb-8svofBQAAAbM"] [Tue Aug 18 13:09:46.409127 2026] [security2:error] [pid 167459:tid 167641] [client 213.35.127.232:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDymr_JutbFb-8svofCQAAAcM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:46.438935 2026] [security2:error] [pid 167459:tid 167715] [client 20.124.247.79:16700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/file.php"] [unique_id "aoSDymr_JutbFb-8svofCwAAAg0"] [Tue Aug 18 13:09:46.458591 2026] [security2:error] [pid 167459:tid 167708] [client 20.171.51.14:19857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/evil.php"] [unique_id "aoSDymr_JutbFb-8svofDwAAAgY"] [Tue Aug 18 13:09:46.459295 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:13712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/config.php"] [unique_id "aoSDymr_JutbFb-8svofEAAAAaQ"] [Tue Aug 18 13:09:46.474621 2026] [security2:error] [pid 167459:tid 167600] [client 172.182.217.32:15800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/up.php"] [unique_id "aoSDymr_JutbFb-8svofEgAAAZo"] [Tue Aug 18 13:09:46.492926 2026] [security2:error] [pid 167459:tid 167532] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/storage/index.php"] [unique_id "aoSDymr_JutbFb-8svofFAAB3Eg"] [Tue Aug 18 13:09:46.533124 2026] [security2:error] [pid 167459:tid 167617] [client 158.23.17.4:39161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/x.php"] [unique_id "aoSDymr_JutbFb-8svofFgAAAas"] [Tue Aug 18 13:09:46.535097 2026] [security2:error] [pid 167459:tid 167674] [client 20.38.3.247:37537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDymr_JutbFb-8svofFwAAAeQ"] [Tue Aug 18 13:09:46.626645 2026] [security2:error] [pid 167459:tid 167472] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/storage/min.php"] [unique_id "aoSDymr_JutbFb-8svofHAABwQw"] [Tue Aug 18 13:09:46.671213 2026] [security2:error] [pid 167459:tid 167689] [client 20.51.153.15:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gj.php"] [unique_id "aoSDymr_JutbFb-8svofHgAAAfM"] [Tue Aug 18 13:09:46.693399 2026] [security2:error] [pid 167459:tid 167597] [client 74.248.133.44:12340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fm.php"] [unique_id "aoSDymr_JutbFb-8svofIAAAAZc"] [Tue Aug 18 13:09:46.695227 2026] [security2:error] [pid 167459:tid 167685] [client 20.124.247.79:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/rezor.php"] [unique_id "aoSDymr_JutbFb-8svofIQAAAe8"] [Tue Aug 18 13:09:46.695758 2026] [security2:error] [pid 167459:tid 167624] [client 20.1.169.243:9718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/admin.php"] [unique_id "aoSDymr_JutbFb-8svofIgAAAbI"] [Tue Aug 18 13:09:46.703883 2026] [security2:error] [pid 167459:tid 167619] [client 20.91.215.254:22319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSDymr_JutbFb-8svofIwAAAa0"] [Tue Aug 18 13:09:46.712428 2026] [security2:error] [pid 167459:tid 167662] [client 40.74.65.169:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wpxml.php"] [unique_id "aoSDymr_JutbFb-8svofJAAAAdg"] [Tue Aug 18 13:09:46.743100 2026] [security2:error] [pid 167459:tid 167603] [client 40.74.65.169:4565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/coffee.php"] [unique_id "aoSDymr_JutbFb-8svofJQAAAZ0"] [Tue Aug 18 13:09:46.759006 2026] [security2:error] [pid 167459:tid 167540] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "csleducacional.com.br"] [uri "/wp-config.php.bak"] [unique_id "aoSDymr_JutbFb-8svofJgABj1A"] [Tue Aug 18 13:09:46.760508 2026] [security2:error] [pid 167459:tid 167697] [client 68.155.154.236:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSDymr_JutbFb-8svofKAAAAfs"] [Tue Aug 18 13:09:46.762771 2026] [security2:error] [pid 167459:tid 167670] [client 158.23.17.4:15767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/va.php"] [unique_id "aoSDymr_JutbFb-8svofKQAAAeA"] [Tue Aug 18 13:09:46.771715 2026] [security2:error] [pid 167459:tid 167571] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "csleducacional.com.br"] [uri "/wp-config.php.old"] [unique_id "aoSDymr_JutbFb-8svofKwAB7W8"] [Tue Aug 18 13:09:46.875771 2026] [security2:error] [pid 167459:tid 167592] [client 20.104.49.167:58689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/file1221.php"] [unique_id "aoSDymr_JutbFb-8svofMgAAAZI"] [Tue Aug 18 13:09:46.878742 2026] [security2:error] [pid 167459:tid 167523] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/.env.php.bak"] [unique_id "aoSDymr_JutbFb-8svofMwAB9j8"] [Tue Aug 18 13:09:46.879707 2026] [security2:error] [pid 167459:tid 167679] [client 20.104.100.201:13884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/reop3.php"] [unique_id "aoSDymr_JutbFb-8svofNAAAAek"] [Tue Aug 18 13:09:46.884259 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:9859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "aoSDymr_JutbFb-8svofNQAAAak"] [Tue Aug 18 13:09:46.887734 2026] [security2:error] [pid 167459:tid 167531] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/laravel/.env"] [unique_id "aoSDymr_JutbFb-8svofNgAB9kc"] [Tue Aug 18 13:09:46.895696 2026] [security2:error] [pid 167459:tid 167580] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/config/.env.php"] [unique_id "aoSDymr_JutbFb-8svofNwAB9ng"] [Tue Aug 18 13:09:46.900611 2026] [security2:error] [pid 167459:tid 167663] [client 223.185.37.47:1798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDymr_JutbFb-8svofOAAAAdk"] [Tue Aug 18 13:09:46.900688 2026] [security2:error] [pid 167459:tid 167663] [client 223.185.37.47:1798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSDymr_JutbFb-8svofOAAAAdk"] [Tue Aug 18 13:09:46.904193 2026] [security2:error] [pid 167459:tid 167555] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/test.php"] [unique_id "aoSDymr_JutbFb-8svofOQACAV8"] [Tue Aug 18 13:09:46.940378 2026] [security2:error] [pid 167459:tid 167705] [client 20.38.3.247:44092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/contacto.php"] [unique_id "aoSDymr_JutbFb-8svofOwAAAgM"] [Tue Aug 18 13:09:46.953770 2026] [security2:error] [pid 167459:tid 167551] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/core/.env"] [unique_id "aoSDymr_JutbFb-8svofPQABmFs"] [Tue Aug 18 13:09:46.965372 2026] [security2:error] [pid 167459:tid 167645] [client 172.182.217.32:15752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ultra.php"] [unique_id "aoSDymr_JutbFb-8svofQQAAAcc"] [Tue Aug 18 13:09:46.986394 2026] [security2:error] [pid 167459:tid 167623] [client 20.65.98.162:40223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/m.php"] [unique_id "aoSDymr_JutbFb-8svofQwAAAbE"] [Tue Aug 18 13:09:46.999035 2026] [security2:error] [pid 167459:tid 167714] [client 20.124.247.79:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/3p8jj8r.php"] [unique_id "aoSDymr_JutbFb-8svofRAAAAgw"] [Tue Aug 18 13:09:47.032071 2026] [security2:error] [pid 167459:tid 167579] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/config.php.bak"] [unique_id "aoSDy2r_JutbFb-8svofRQABlnc"] [Tue Aug 18 13:09:47.040428 2026] [security2:error] [pid 167459:tid 167461] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/test1.php"] [unique_id "aoSDy2r_JutbFb-8svofRgABygE"] [Tue Aug 18 13:09:47.062701 2026] [security2:error] [pid 167459:tid 167553] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/configuration.php.bak"] [unique_id "aoSDy2r_JutbFb-8svofSgABll0"] [Tue Aug 18 13:09:47.092625 2026] [security2:error] [pid 167459:tid 167586] [remote 208.122.213.225:42114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.213.122.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naorar.com.br"] [uri "/wp-login.php"] [unique_id "aoSDy2r_JutbFb-8svofSwABpX4"] [Tue Aug 18 13:09:47.114428 2026] [security2:error] [pid 167459:tid 167556] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/.env.swp"] [unique_id "aoSDy2r_JutbFb-8svofTAABlmA"] [Tue Aug 18 13:09:47.129252 2026] [security2:error] [pid 167459:tid 167492] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/public/.env"] [unique_id "aoSDy2r_JutbFb-8svofTgABliA"] [Tue Aug 18 13:09:47.168492 2026] [security2:error] [pid 167459:tid 167576] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/web/.env"] [unique_id "aoSDy2r_JutbFb-8svofVQABlnQ"] [Tue Aug 18 13:09:47.174972 2026] [security2:error] [pid 167459:tid 167563] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/thoms.php"] [unique_id "aoSDy2r_JutbFb-8svofVgABoWc"] [Tue Aug 18 13:09:47.258622 2026] [security2:error] [pid 167459:tid 167672] [client 20.1.169.243:10295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDy2r_JutbFb-8svofXwAAAeI"] [Tue Aug 18 13:09:47.280299 2026] [security2:error] [pid 167459:tid 167637] [client 20.38.3.247:3617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/image2.php"] [unique_id "aoSDy2r_JutbFb-8svofYgAAAb8"] [Tue Aug 18 13:09:47.298477 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/module.php"] [unique_id "aoSDy2r_JutbFb-8svofZAAAAaQ"] [Tue Aug 18 13:09:47.313975 2026] [security2:error] [pid 167459:tid 167465] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/tiny.php"] [unique_id "aoSDy2r_JutbFb-8svofZwABuwU"] [Tue Aug 18 13:09:47.342596 2026] [security2:error] [pid 167459:tid 167606] [client 20.91.215.254:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7"] [unique_id "aoSDy2r_JutbFb-8svofagAAAaA"] [Tue Aug 18 13:09:47.351482 2026] [security2:error] [pid 167459:tid 167609] [client 20.124.247.79:15342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/dapa.php"] [unique_id "aoSDy2r_JutbFb-8svofawAAAaM"] [Tue Aug 18 13:09:47.384018 2026] [security2:error] [pid 167459:tid 167676] [client 20.104.49.167:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/nox.php"] [unique_id "aoSDy2r_JutbFb-8svofbQAAAeY"] [Tue Aug 18 13:09:47.387755 2026] [security2:error] [pid 167459:tid 167706] [client 158.23.17.4:5050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/yn.php"] [unique_id "aoSDy2r_JutbFb-8svofbgAAAgQ"] [Tue Aug 18 13:09:47.425188 2026] [security2:error] [pid 167459:tid 167630] [client 213.35.127.232:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDy2r_JutbFb-8svofcQAAAbg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:47.437467 2026] [security2:error] [pid 167459:tid 167593] [client 40.74.65.169:4854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/classwithtostring.php"] [unique_id "aoSDy2r_JutbFb-8svofcwAAAZM"] [Tue Aug 18 13:09:47.444967 2026] [security2:error] [pid 167459:tid 167595] [client 40.74.65.169:5648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file1221.php"] [unique_id "aoSDy2r_JutbFb-8svofdAAAAZU"] [Tue Aug 18 13:09:47.449578 2026] [security2:error] [pid 167459:tid 167585] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/tool.php"] [unique_id "aoSDy2r_JutbFb-8svofdQAB0X0"] [Tue Aug 18 13:09:47.455153 2026] [security2:error] [pid 167459:tid 167640] [client 172.182.217.32:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/vv.php"] [unique_id "aoSDy2r_JutbFb-8svofdgAAAcI"] [Tue Aug 18 13:09:47.529932 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/8.php"] [unique_id "aoSDy2r_JutbFb-8svofegAAAZI"] [Tue Aug 18 13:09:47.584057 2026] [security2:error] [pid 167459:tid 167524] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/top.php"] [unique_id "aoSDy2r_JutbFb-8svoffAABzUA"] [Tue Aug 18 13:09:47.622708 2026] [security2:error] [pid 167459:tid 167656] [client 68.155.154.236:25369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSDy2r_JutbFb-8svofgAAAAdI"] [Tue Aug 18 13:09:47.628102 2026] [security2:error] [pid 167459:tid 167594] [client 20.124.247.79:15341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/Ipv6.php"] [unique_id "aoSDy2r_JutbFb-8svofggAAAZQ"] [Tue Aug 18 13:09:47.641080 2026] [security2:error] [pid 167459:tid 167632] [client 20.38.3.247:24748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/fb.php"] [unique_id "aoSDy2r_JutbFb-8svofhgAAAbo"] [Tue Aug 18 13:09:47.717583 2026] [security2:error] [pid 167459:tid 167667] [client 52.139.47.57:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/options.php"] [unique_id "aoSDy2r_JutbFb-8svofigAAAd0"] [Tue Aug 18 13:09:47.718498 2026] [security2:error] [pid 167459:tid 167469] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/txets.php"] [unique_id "aoSDy2r_JutbFb-8svofiwAB_wk"] [Tue Aug 18 13:09:47.751754 2026] [security2:error] [pid 167459:tid 167681] [client 20.1.169.243:9710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSDy2r_JutbFb-8svofkQAAAes"] [Tue Aug 18 13:09:47.789903 2026] [security2:error] [pid 167459:tid 167590] [client 45.131.195.149:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seguntabmenca.com.br"] [uri "/wp-login.php"] [unique_id "aoSDy2r_JutbFb-8svoffwAAAZA"] [Tue Aug 18 13:09:47.852565 2026] [security2:error] [pid 167459:tid 167477] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/virus.php"] [unique_id "aoSDy2r_JutbFb-8svoflwABwxE"] [Tue Aug 18 13:09:47.867168 2026] [security2:error] [pid 167459:tid 167603] [client 74.248.18.37:30007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/edit.php"] [unique_id "aoSDy2r_JutbFb-8svofmgAAAZ0"] [Tue Aug 18 13:09:47.883956 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:47.884274 2026] [authz_core:error] [pid 167459:tid 167515] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:47.908534 2026] [security2:error] [pid 167459:tid 167661] [client 20.38.3.247:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/qlex1.php"] [unique_id "aoSDy2r_JutbFb-8svofnwAAAdc"] [Tue Aug 18 13:09:47.922851 2026] [security2:error] [pid 167459:tid 167674] [client 20.124.247.79:16709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/first.php"] [unique_id "aoSDy2r_JutbFb-8svofoAAAAeQ"] [Tue Aug 18 13:09:47.943948 2026] [security2:error] [pid 167459:tid 167631] [client 172.182.217.32:15605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/V5.php"] [unique_id "aoSDy2r_JutbFb-8svofowAAAbk"] [Tue Aug 18 13:09:47.973221 2026] [security2:error] [pid 167459:tid 167669] [client 20.38.3.247:3629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/gi.php"] [unique_id "aoSDy2r_JutbFb-8svofpgAAAd8"] [Tue Aug 18 13:09:47.985674 2026] [security2:error] [pid 167459:tid 167566] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/we.php"] [unique_id "aoSDy2r_JutbFb-8svofpwAB_Wo"] [Tue Aug 18 13:09:48.003003 2026] [security2:error] [pid 167459:tid 167639] [client 74.248.133.44:12780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/bolt.php"] [unique_id "aoSDzGr_JutbFb-8svofqAAAAcE"] [Tue Aug 18 13:09:48.005978 2026] [security2:error] [pid 167459:tid 167643] [client 20.91.215.254:22294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "aoSDzGr_JutbFb-8svofqQAAAcU"] [Tue Aug 18 13:09:48.016196 2026] [security2:error] [pid 167459:tid 167665] [client 74.248.18.37:30633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-mail.php"] [unique_id "aoSDzGr_JutbFb-8svofqgAAAds"] [Tue Aug 18 13:09:48.017448 2026] [security2:error] [pid 167459:tid 167654] [client 213.202.253.4:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/gdftps.php"] [unique_id "aoSDzGr_JutbFb-8svofqwAAAdA"], referer: www.google.com [Tue Aug 18 13:09:48.025810 2026] [security2:error] [pid 167459:tid 167610] [client 20.104.100.201:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/special.php"] [unique_id "aoSDzGr_JutbFb-8svofsAAAAaQ"] [Tue Aug 18 13:09:48.091304 2026] [security2:error] [pid 167459:tid 167712] [client 158.23.17.4:4631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/11.php"] [unique_id "aoSDzGr_JutbFb-8svoftAAAAgo"] [Tue Aug 18 13:09:48.119265 2026] [security2:error] [pid 167459:tid 167622] [client 20.1.169.243:9704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSDzGr_JutbFb-8svoftgAAAbA"] [Tue Aug 18 13:09:48.127268 2026] [security2:error] [pid 167459:tid 167664] [client 40.74.65.169:5663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/nox.php"] [unique_id "aoSDzGr_JutbFb-8svoftwAAAdo"] [Tue Aug 18 13:09:48.133450 2026] [security2:error] [pid 167459:tid 167611] [client 45.66.35.46:57476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.35.66.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDy2r_JutbFb-8svoflAAAAaU"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:48.133556 2026] [security2:error] [pid 167459:tid 167611] [client 45.66.35.46:57476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fbenevides.com"] [uri "/wp-comments-post.php"] [unique_id "aoSDy2r_JutbFb-8svoflAAAAaU"], referer: http://fbenevides.com/wp-comments-post.php [Tue Aug 18 13:09:48.134897 2026] [security2:error] [pid 167459:tid 167698] [client 40.74.65.169:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/wp-ws68.php"] [unique_id "aoSDzGr_JutbFb-8svofuAAAAfw"] [Tue Aug 18 13:09:48.148304 2026] [security2:error] [pid 167459:tid 167589] [client 20.104.49.167:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/akismet.php"] [unique_id "aoSDzGr_JutbFb-8svofuwAAAY8"] [Tue Aug 18 13:09:48.178742 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:48.179134 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:48.179919 2026] [security2:error] [pid 167459:tid 167685] [client 52.139.47.57:35286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/panel.php"] [unique_id "aoSDzGr_JutbFb-8svofvgAAAe8"] [Tue Aug 18 13:09:48.217083 2026] [security2:error] [pid 167459:tid 167612] [client 149.34.210.141:58967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDzGr_JutbFb-8svofwQAAAaY"] [Tue Aug 18 13:09:48.268423 2026] [security2:error] [pid 167459:tid 167615] [client 20.116.17.175:44703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/images.php"] [unique_id "aoSDzGr_JutbFb-8svofyQAAAak"] [Tue Aug 18 13:09:48.285440 2026] [security2:error] [pid 167459:tid 167629] [client 20.124.247.79:15319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/wpupex.php"] [unique_id "aoSDzGr_JutbFb-8svofygAAAbc"] [Tue Aug 18 13:09:48.311726 2026] [security2:error] [pid 167459:tid 167634] [client 158.23.17.4:20420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/fo.php"] [unique_id "aoSDzGr_JutbFb-8svofywAAAbw"] [Tue Aug 18 13:09:48.347658 2026] [security2:error] [pid 167459:tid 167660] [client 20.38.3.247:15010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/mariju.php"] [unique_id "aoSDzGr_JutbFb-8svofzQAAAdY"] [Tue Aug 18 13:09:48.365621 2026] [security2:error] [pid 167459:tid 167598] [client 20.38.3.247:3345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/video.php"] [unique_id "aoSDzGr_JutbFb-8svofzgAAAZg"] [Tue Aug 18 13:09:48.412069 2026] [security2:error] [pid 167459:tid 167500] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/work.php"] [unique_id "aoSDzGr_JutbFb-8svof0QABsSg"] [Tue Aug 18 13:09:48.430417 2026] [security2:error] [pid 167459:tid 167651] [client 172.182.217.32:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp-user.php"] [unique_id "aoSDzGr_JutbFb-8svof0gAAAc0"] [Tue Aug 18 13:09:48.443521 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.100.201:62611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/php5.php"] [unique_id "aoSDzGr_JutbFb-8svof0wAAAfc"] [Tue Aug 18 13:09:48.455700 2026] [security2:error] [pid 167459:tid 167649] [client 213.35.127.232:64709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSDzGr_JutbFb-8svof1QAAAcs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:48.483311 2026] [security2:error] [pid 167459:tid 167612] [client 149.34.210.141:58967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSDzGr_JutbFb-8svofwQAAAaY"] [Tue Aug 18 13:09:48.509984 2026] [security2:error] [pid 167459:tid 167667] [client 20.1.169.243:10281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDzGr_JutbFb-8svof2wAAAd0"] [Tue Aug 18 13:09:48.537230 2026] [security2:error] [pid 167459:tid 167627] [client 4.232.151.198:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/i.php"] [unique_id "aoSDzGr_JutbFb-8svof3gAAAbU"] [Tue Aug 18 13:09:48.545574 2026] [security2:error] [pid 167459:tid 167520] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin.php"] [unique_id "aoSDzGr_JutbFb-8svof4AABrzw"] [Tue Aug 18 13:09:48.558035 2026] [security2:error] [pid 167459:tid 167641] [client 20.124.247.79:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/bibil.php"] [unique_id "aoSDzGr_JutbFb-8svof4gAAAcM"] [Tue Aug 18 13:09:48.611672 2026] [security2:error] [pid 167459:tid 167714] [client 52.139.47.57:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/wp-activate.php"] [unique_id "aoSDzGr_JutbFb-8svof5gAAAgw"] [Tue Aug 18 13:09:48.629291 2026] [security2:error] [pid 167459:tid 167678] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDzGr_JutbFb-8svof4QAB6HU"] [Tue Aug 18 13:09:48.660231 2026] [security2:error] [pid 167459:tid 167646] [client 20.91.215.254:16846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSDzGr_JutbFb-8svof6AAAAcg"] [Tue Aug 18 13:09:48.710759 2026] [security2:error] [pid 167459:tid 167631] [client 20.51.153.15:13426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pd.php"] [unique_id "aoSDzGr_JutbFb-8svof7QAAAbk"] [Tue Aug 18 13:09:48.721454 2026] [security2:error] [pid 167459:tid 167617] [client 20.250.13.23:37261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/inputs.php"] [unique_id "aoSDzGr_JutbFb-8svof7gAAAas"] [Tue Aug 18 13:09:48.729558 2026] [security2:error] [pid 167459:tid 167628] [client 20.65.98.162:40923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/33.php"] [unique_id "aoSDzGr_JutbFb-8svof7wAAAbY"] [Tue Aug 18 13:09:48.781608 2026] [security2:error] [pid 167459:tid 167696] [client 20.38.3.247:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/hel.php"] [unique_id "aoSDzGr_JutbFb-8svof8gAAAfo"] [Tue Aug 18 13:09:48.814401 2026] [security2:error] [pid 167459:tid 167712] [client 40.74.65.169:5639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/akismet.php"] [unique_id "aoSDzGr_JutbFb-8svof9QAAAgo"] [Tue Aug 18 13:09:48.816456 2026] [security2:error] [pid 167459:tid 167619] [client 40.74.65.169:4440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/yj09.php"] [unique_id "aoSDzGr_JutbFb-8svof9gAAAa0"] [Tue Aug 18 13:09:48.846711 2026] [security2:error] [pid 167459:tid 167571] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/about.php"] [unique_id "aoSDzGr_JutbFb-8svof-AACBG8"] [Tue Aug 18 13:09:48.905512 2026] [security2:error] [pid 167459:tid 167642] [client 68.155.154.236:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSDzGr_JutbFb-8svof_gAAAcQ"] [Tue Aug 18 13:09:48.906368 2026] [security2:error] [pid 167459:tid 167589] [client 20.124.247.79:16742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/halo.php"] [unique_id "aoSDzGr_JutbFb-8svof_wAAAY8"] [Tue Aug 18 13:09:48.908737 2026] [security2:error] [pid 167459:tid 167665] [client 20.1.169.243:10481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDzGr_JutbFb-8svogAAAAAds"] [Tue Aug 18 13:09:48.918689 2026] [security2:error] [pid 167459:tid 167672] [client 172.182.217.32:15564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp-blog.php"] [unique_id "aoSDzGr_JutbFb-8svogAQAAAeI"] [Tue Aug 18 13:09:48.958474 2026] [security2:error] [pid 167459:tid 167595] [client 158.23.17.4:38371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vm.php"] [unique_id "aoSDzGr_JutbFb-8svogBAAAAZU"] [Tue Aug 18 13:09:48.960256 2026] [security2:error] [pid 167459:tid 167624] [client 20.51.153.15:13341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/th.php"] [unique_id "aoSDzGr_JutbFb-8svogBQAAAbI"] [Tue Aug 18 13:09:48.980883 2026] [security2:error] [pid 167459:tid 167555] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/admin.php"] [unique_id "aoSDzGr_JutbFb-8svogBgABwl8"] [Tue Aug 18 13:09:49.030865 2026] [security2:error] [pid 167459:tid 167698] [client 52.139.47.57:18557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/wp-blog-header.php"] [unique_id "aoSDzWr_JutbFb-8svogBwAAAfw"] [Tue Aug 18 13:09:49.096113 2026] [security2:error] [pid 167459:tid 167629] [client 20.127.136.245:16790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSDzWr_JutbFb-8svogDAAAAbc"] [Tue Aug 18 13:09:49.115826 2026] [security2:error] [pid 167459:tid 167692] [client 20.38.3.247:37545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/grok.php"] [unique_id "aoSDzWr_JutbFb-8svogDgAAAfY"] [Tue Aug 18 13:09:49.117489 2026] [security2:error] [pid 167459:tid 167594] [client 20.104.49.167:50339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/admin.php"] [unique_id "aoSDzWr_JutbFb-8svogEAAAAZQ"] [Tue Aug 18 13:09:49.128972 2026] [security2:error] [pid 167459:tid 167604] [client 74.249.206.207:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.caminhosdoreiki.com.br"] [uri "/ajax.php"] [unique_id "aoSDzWr_JutbFb-8svogEQAAAZ4"] [Tue Aug 18 13:09:49.169965 2026] [security2:error] [pid 167459:tid 167713] [client 20.171.51.14:2334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pw.php"] [unique_id "aoSDzWr_JutbFb-8svogFAAAAgs"] [Tue Aug 18 13:09:49.196228 2026] [security2:error] [pid 167459:tid 167651] [client 20.51.153.15:13388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/admin404.php"] [unique_id "aoSDzWr_JutbFb-8svogGAAAAc0"] [Tue Aug 18 13:09:49.233135 2026] [security2:error] [pid 167459:tid 167663] [client 20.38.3.247:16019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSDzWr_JutbFb-8svogGwAAAdk"] [Tue Aug 18 13:09:49.261605 2026] [security2:error] [pid 167459:tid 167607] [client 20.124.247.79:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/ajq1s.php"] [unique_id "aoSDzWr_JutbFb-8svogHgAAAaE"] [Tue Aug 18 13:09:49.262459 2026] [security2:error] [pid 167459:tid 167556] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSDzWr_JutbFb-8svogHwAB52A"] [Tue Aug 18 13:09:49.279246 2026] [security2:error] [pid 167459:tid 167668] [client 20.1.169.243:9668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSDzWr_JutbFb-8svogIAAAAd4"] [Tue Aug 18 13:09:49.311049 2026] [security2:error] [pid 167459:tid 167679] [client 20.91.215.254:3783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/plugins/classic-editor/wp-login.php"] [unique_id "aoSDzWr_JutbFb-8svogIQAAAek"] [Tue Aug 18 13:09:49.388634 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:49.389082 2026] [authz_core:error] [pid 167459:tid 167503] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:49.439843 2026] [security2:error] [pid 167459:tid 167699] [client 74.248.18.37:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/bolt.php"] [unique_id "aoSDzWr_JutbFb-8svogKQAAAf0"] [Tue Aug 18 13:09:49.472128 2026] [security2:error] [pid 167459:tid 167646] [client 20.51.153.15:13322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/qo.php"] [unique_id "aoSDzWr_JutbFb-8svogKwAAAcg"] [Tue Aug 18 13:09:49.476931 2026] [security2:error] [pid 167459:tid 167686] [client 213.35.127.232:64934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSDzWr_JutbFb-8svogLAAAAfA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:49.500645 2026] [security2:error] [pid 167459:tid 167702] [client 172.182.217.32:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp.php"] [unique_id "aoSDzWr_JutbFb-8svogLgAAAgA"] [Tue Aug 18 13:09:49.506227 2026] [security2:error] [pid 167459:tid 167661] [client 20.38.3.247:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/indes.php"] [unique_id "aoSDzWr_JutbFb-8svogLwAAAdc"] [Tue Aug 18 13:09:49.513631 2026] [security2:error] [pid 167459:tid 167703] [client 40.74.65.169:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/admin.php"] [unique_id "aoSDzWr_JutbFb-8svogMQAAAgE"] [Tue Aug 18 13:09:49.513655 2026] [security2:error] [pid 167459:tid 167674] [client 40.74.65.169:4574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/scxy.php"] [unique_id "aoSDzWr_JutbFb-8svogMgAAAeQ"] [Tue Aug 18 13:09:49.528833 2026] [security2:error] [pid 167459:tid 167617] [client 20.124.247.79:15338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/spip.php"] [unique_id "aoSDzWr_JutbFb-8svogMwAAAas"] [Tue Aug 18 13:09:49.545447 2026] [security2:error] [pid 167459:tid 167533] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSDzWr_JutbFb-8svogNgAB9Ek"] [Tue Aug 18 13:09:49.630655 2026] [security2:error] [pid 167459:tid 167626] [client 52.139.47.57:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/cgi-bin/xmlrpc.php"] [unique_id "aoSDzWr_JutbFb-8svogKgAAAbQ"] [Tue Aug 18 13:09:49.650324 2026] [security2:error] [pid 167459:tid 167631] [client 20.1.169.243:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSDzWr_JutbFb-8svogPwAAAbk"] [Tue Aug 18 13:09:49.662672 2026] [security2:error] [pid 167459:tid 167622] [client 158.23.17.4:39134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/eg.php"] [unique_id "aoSDzWr_JutbFb-8svogQQAAAbA"] [Tue Aug 18 13:09:49.679686 2026] [security2:error] [pid 167459:tid 167468] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSDzWr_JutbFb-8svogQgABpwg"] [Tue Aug 18 13:09:49.699439 2026] [security2:error] [pid 167459:tid 167642] [client 20.38.3.247:2171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/contacto.php"] [unique_id "aoSDzWr_JutbFb-8svogRAAAAcQ"] [Tue Aug 18 13:09:49.714822 2026] [security2:error] [pid 167459:tid 167589] [client 20.51.153.15:13424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sd.php"] [unique_id "aoSDzWr_JutbFb-8svogRwAAAY8"] [Tue Aug 18 13:09:49.800864 2026] [security2:error] [pid 167459:tid 167624] [client 68.155.154.236:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSDzWr_JutbFb-8svogSgAAAbI"] [Tue Aug 18 13:09:49.813523 2026] [security2:error] [pid 167459:tid 167583] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSDzWr_JutbFb-8svogTAABwns"] [Tue Aug 18 13:09:49.855735 2026] [security2:error] [pid 167459:tid 167602] [client 20.38.3.247:33693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/tTPcH.php"] [unique_id "aoSDzWr_JutbFb-8svogTQAAAZw"] [Tue Aug 18 13:09:49.890481 2026] [security2:error] [pid 167459:tid 167594] [client 20.124.247.79:15299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/wpup.php"] [unique_id "aoSDzWr_JutbFb-8svogTgAAAZQ"] [Tue Aug 18 13:09:49.897026 2026] [security2:error] [pid 167459:tid 167543] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/info.php"] [unique_id "aoSDzWr_JutbFb-8svogTwABnlM"] [Tue Aug 18 13:09:49.903409 2026] [security2:error] [pid 167459:tid 167524] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/phpinfo.php"] [unique_id "aoSDzWr_JutbFb-8svogUQABmEA"] [Tue Aug 18 13:09:49.919418 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:48389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/loading.php"] [unique_id "aoSDzWr_JutbFb-8svogUgAAAZI"] [Tue Aug 18 13:09:49.920322 2026] [security2:error] [pid 167459:tid 167581] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/i.php"] [unique_id "aoSDzWr_JutbFb-8svogVAABzXk"] [Tue Aug 18 13:09:49.920498 2026] [security2:error] [pid 167459:tid 167482] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/pi.php"] [unique_id "aoSDzWr_JutbFb-8svogUwABzRY"] [Tue Aug 18 13:09:49.929864 2026] [security2:error] [pid 167459:tid 167545] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/test.php"] [unique_id "aoSDzWr_JutbFb-8svogVgAB3FU"] [Tue Aug 18 13:09:49.930938 2026] [security2:error] [pid 167459:tid 167632] [client 157.20.138.62:62221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDzWr_JutbFb-8svogVwAAAbo"] [Tue Aug 18 13:09:49.931061 2026] [security2:error] [pid 167459:tid 167632] [client 157.20.138.62:62221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDzWr_JutbFb-8svogVwAAAbo"] [Tue Aug 18 13:09:49.948099 2026] [security2:error] [pid 167459:tid 167530] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSDzWr_JutbFb-8svogWQAB2UY"] [Tue Aug 18 13:09:49.964305 2026] [security2:error] [pid 167459:tid 167635] [client 20.116.17.175:52923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/a.php"] [unique_id "aoSDzWr_JutbFb-8svogWgAAAb0"] [Tue Aug 18 13:09:49.965480 2026] [security2:error] [pid 167459:tid 167671] [client 20.51.153.15:13380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/km.php"] [unique_id "aoSDzWr_JutbFb-8svogWwAAAeE"] [Tue Aug 18 13:09:49.988988 2026] [security2:error] [pid 167459:tid 167627] [client 178.153.171.161:29324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDzWr_JutbFb-8svogYQAAAbU"] [Tue Aug 18 13:09:49.989120 2026] [security2:error] [pid 167459:tid 167627] [client 178.153.171.161:29324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDzWr_JutbFb-8svogYQAAAbU"] [Tue Aug 18 13:09:49.993428 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:49.993882 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:50.001920 2026] [security2:error] [pid 167459:tid 167697] [client 20.91.215.254:16889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/plugins/yanierin/akc.php"] [unique_id "aoSDzmr_JutbFb-8svogZAAAAfs"] [Tue Aug 18 13:09:50.013528 2026] [security2:error] [pid 167459:tid 167637] [client 172.182.217.32:15760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/worksec.php"] [unique_id "aoSDzmr_JutbFb-8svogZQAAAb8"] [Tue Aug 18 13:09:50.032098 2026] [security2:error] [pid 167459:tid 167701] [client 20.1.169.243:9682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSDzmr_JutbFb-8svogZwAAAf8"] [Tue Aug 18 13:09:50.039436 2026] [security2:error] [pid 167459:tid 167709] [client 20.104.100.201:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/acp.php"] [unique_id "aoSDzmr_JutbFb-8svogaAAAAgc"] [Tue Aug 18 13:09:50.048824 2026] [security2:error] [pid 167459:tid 167704] [client 52.139.47.57:9914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/chosen.php"] [unique_id "aoSDzmr_JutbFb-8svogaQAAAgI"] [Tue Aug 18 13:09:50.065891 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-content/themes/index.php"] [unique_id "aoSDzmr_JutbFb-8svogagAAAZs"] [Tue Aug 18 13:09:50.081917 2026] [security2:error] [pid 167459:tid 167489] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSDzmr_JutbFb-8svogbQAB4B0"] [Tue Aug 18 13:09:50.087557 2026] [security2:error] [pid 167459:tid 167481] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSDzmr_JutbFb-8svogbgAB7RU"] [Tue Aug 18 13:09:50.088753 2026] [security2:error] [pid 167459:tid 167477] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.137.73.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "csleducacional.com.br"] [uri "/app_dev.php"] [unique_id "aoSDzmr_JutbFb-8svogbwABlxE"] [Tue Aug 18 13:09:50.123514 2026] [security2:error] [pid 167459:tid 167715] [client 20.38.3.247:24397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/image2.php"] [unique_id "aoSDzmr_JutbFb-8svogdAAAAg0"] [Tue Aug 18 13:09:50.191509 2026] [security2:error] [pid 167459:tid 167678] [client 20.38.3.247:37557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/bs1.php"] [unique_id "aoSDzmr_JutbFb-8svogdgAAAeg"] [Tue Aug 18 13:09:50.211048 2026] [security2:error] [pid 167459:tid 167646] [client 20.104.49.167:58723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/ajax.php"] [unique_id "aoSDzmr_JutbFb-8svogeAAAAcg"] [Tue Aug 18 13:09:50.217823 2026] [security2:error] [pid 167459:tid 167539] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSDzmr_JutbFb-8svogeQABmk8"] [Tue Aug 18 13:09:50.223030 2026] [security2:error] [pid 167459:tid 167674] [client 20.51.153.15:13324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mf.php"] [unique_id "aoSDzmr_JutbFb-8svogegAAAeQ"] [Tue Aug 18 13:09:50.226849 2026] [security2:error] [pid 167459:tid 167703] [client 40.74.65.169:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/ajax.php"] [unique_id "aoSDzmr_JutbFb-8svogfAAAAgE"] [Tue Aug 18 13:09:50.228041 2026] [security2:error] [pid 167459:tid 167657] [client 40.74.65.169:4315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSDzmr_JutbFb-8svogfQAAAdM"] [Tue Aug 18 13:09:50.249999 2026] [security2:error] [pid 167459:tid 167617] [client 20.124.247.79:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/myy.php"] [unique_id "aoSDzmr_JutbFb-8svoggQAAAas"] [Tue Aug 18 13:09:50.272434 2026] [security2:error] [pid 167459:tid 167700] [client 20.65.98.162:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.98.65.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.veiculossaojose.com.br"] [uri "/packed.php"] [unique_id "aoSDzmr_JutbFb-8svoghAAAAf4"] [Tue Aug 18 13:09:50.352439 2026] [access_compat:error] [pid 167459:tid 167475] [remote 34.73.137.196:51954] AH01797: client denied by server configuration: /home3/csleduca/public_html/server-status [Tue Aug 18 13:09:50.352601 2026] [security2:error] [pid 167459:tid 167565] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSDzmr_JutbFb-8svoghgABuWk"] [Tue Aug 18 13:09:50.358236 2026] [security2:error] [pid 167459:tid 167509] [remote 34.73.137.196:51954] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "csleducacional.com.br"] [uri "/server-info"] [unique_id "aoSDzmr_JutbFb-8svogiAABlzE"] [Tue Aug 18 13:09:50.418833 2026] [security2:error] [pid 167459:tid 167595] [client 74.248.18.37:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/elp.php"] [unique_id "aoSDzmr_JutbFb-8svogiwAAAZU"] [Tue Aug 18 13:09:50.418896 2026] [security2:error] [pid 167459:tid 167690] [client 20.1.169.243:9674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/css/min.php"] [unique_id "aoSDzmr_JutbFb-8svogjAAAAfQ"] [Tue Aug 18 13:09:50.421231 2026] [security2:error] [pid 167459:tid 167625] [client 20.250.13.23:34281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/admin.php"] [unique_id "aoSDzmr_JutbFb-8svogjQAAAbM"] [Tue Aug 18 13:09:50.446686 2026] [security2:error] [pid 167459:tid 167648] [client 158.23.17.4:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/uk.php"] [unique_id "aoSDzmr_JutbFb-8svogjwAAAco"] [Tue Aug 18 13:09:50.452570 2026] [security2:error] [pid 167459:tid 167665] [client 20.215.241.237:30410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSDzmr_JutbFb-8svogkQAAAds"] [Tue Aug 18 13:09:50.490983 2026] [security2:error] [pid 167459:tid 167506] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/css/min.php"] [unique_id "aoSDzmr_JutbFb-8svoglAAB7y4"] [Tue Aug 18 13:09:50.492522 2026] [security2:error] [pid 167459:tid 167695] [client 20.51.153.15:13333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ie.php"] [unique_id "aoSDzmr_JutbFb-8svoglgAAAfk"] [Tue Aug 18 13:09:50.501256 2026] [security2:error] [pid 167459:tid 167621] [client 213.35.127.232:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSDzmr_JutbFb-8svoglwAAAa8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:50.508961 2026] [security2:error] [pid 167459:tid 167662] [client 172.182.217.32:15594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp-themes.php"] [unique_id "aoSDzmr_JutbFb-8svogmAAAAdg"] [Tue Aug 18 13:09:50.508980 2026] [security2:error] [pid 167459:tid 167655] [client 20.124.247.79:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/geido.php"] [unique_id "aoSDzmr_JutbFb-8svogmQAAAdE"] [Tue Aug 18 13:09:50.517101 2026] [security2:error] [pid 167459:tid 167624] [client 68.155.154.236:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSDzmr_JutbFb-8svogoQAAAbI"] [Tue Aug 18 13:09:50.518257 2026] [security2:error] [pid 167459:tid 167640] [client 20.38.3.247:44191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/hp2.php"] [unique_id "aoSDzmr_JutbFb-8svogpAAAAcI"] [Tue Aug 18 13:09:50.614650 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/class-protect-uploads.php"] [unique_id "aoSDzmr_JutbFb-8svogtwAAAbc"] [Tue Aug 18 13:09:50.626996 2026] [security2:error] [pid 167459:tid 167572] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/data.php"] [unique_id "aoSDzmr_JutbFb-8svoguAABlHA"] [Tue Aug 18 13:09:50.721683 2026] [security2:error] [pid 167459:tid 167591] [client 20.38.3.247:2487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/fb.php"] [unique_id "aoSDzmr_JutbFb-8svog0QAAAZE"] [Tue Aug 18 13:09:50.732925 2026] [security2:error] [pid 167459:tid 167675] [client 20.91.215.254:22307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "aoSDzmr_JutbFb-8svog0wAAAeU"] [Tue Aug 18 13:09:50.750380 2026] [security2:error] [pid 167459:tid 167682] [client 20.51.153.15:13431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nw.php"] [unique_id "aoSDzmr_JutbFb-8svog1AAAAew"] [Tue Aug 18 13:09:50.758632 2026] [security2:error] [pid 167459:tid 167643] [client 74.248.133.44:64234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/js/codemirror/about.php"] [unique_id "aoSDzmr_JutbFb-8svog1wAAAcU"] [Tue Aug 18 13:09:50.760477 2026] [security2:error] [pid 167459:tid 167553] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/home.php"] [unique_id "aoSDzmr_JutbFb-8svog2AABpl0"] [Tue Aug 18 13:09:50.791199 2026] [security2:error] [pid 167459:tid 167601] [client 20.124.247.79:15316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/gelay.php"] [unique_id "aoSDzmr_JutbFb-8svog2QAAAZs"] [Tue Aug 18 13:09:50.808384 2026] [security2:error] [pid 167459:tid 167635] [client 20.1.169.243:10264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/data.php"] [unique_id "aoSDzmr_JutbFb-8svog2wAAAb0"] [Tue Aug 18 13:09:50.873686 2026] [security2:error] [pid 167459:tid 167603] [client 20.215.241.237:2956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSDzmr_JutbFb-8svog3gAAAZ0"] [Tue Aug 18 13:09:50.877165 2026] [security2:error] [pid 167459:tid 167716] [client 20.38.3.247:44064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/yb.php"] [unique_id "aoSDzmr_JutbFb-8svog3wAAAg4"] [Tue Aug 18 13:09:50.897619 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:50.897888 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:50.913753 2026] [security2:error] [pid 167459:tid 167645] [client 40.74.65.169:4303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSDzmr_JutbFb-8svog4wAAAcc"] [Tue Aug 18 13:09:50.934234 2026] [security2:error] [pid 167459:tid 167688] [client 158.23.17.4:25367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ke.php"] [unique_id "aoSDzmr_JutbFb-8svog5AAAAfI"] [Tue Aug 18 13:09:50.941021 2026] [security2:error] [pid 167459:tid 167686] [client 40.74.65.169:5694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/abe.php"] [unique_id "aoSDzmr_JutbFb-8svog5gAAAfA"] [Tue Aug 18 13:09:50.995391 2026] [security2:error] [pid 167459:tid 167658] [client 172.182.217.32:12238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp-signin.php"] [unique_id "aoSDzmr_JutbFb-8svog6AAAAdQ"] [Tue Aug 18 13:09:51.021616 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:39125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/creds.php"] [unique_id "aoSDz2r_JutbFb-8svog6gAAAdM"] [Tue Aug 18 13:09:51.034985 2026] [security2:error] [pid 167459:tid 167628] [client 52.139.47.57:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/class.uncode-6wixr9.php"] [unique_id "aoSDz2r_JutbFb-8svog6wAAAbY"] [Tue Aug 18 13:09:51.040607 2026] [security2:error] [pid 167459:tid 167567] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/images/min.php"] [unique_id "aoSDz2r_JutbFb-8svog7AABq2s"] [Tue Aug 18 13:09:51.053853 2026] [security2:error] [pid 167459:tid 167700] [client 20.124.247.79:15297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/atomlib.php"] [unique_id "aoSDz2r_JutbFb-8svog7QAAAf4"] [Tue Aug 18 13:09:51.074580 2026] [security2:error] [pid 167459:tid 167652] [client 68.155.154.236:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSDz2r_JutbFb-8svog7gAAAc4"] [Tue Aug 18 13:09:51.182506 2026] [security2:error] [pid 167459:tid 167672] [client 102.213.179.104:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDz2r_JutbFb-8svog9QAAAeI"] [Tue Aug 18 13:09:51.182605 2026] [security2:error] [pid 167459:tid 167672] [client 102.213.179.104:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSDz2r_JutbFb-8svog9QAAAeI"] [Tue Aug 18 13:09:51.206142 2026] [security2:error] [pid 167459:tid 167630] [client 20.1.169.243:10303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/home.php"] [unique_id "aoSDz2r_JutbFb-8svog9wAAAbg"] [Tue Aug 18 13:09:51.206998 2026] [security2:error] [pid 167459:tid 167638] [client 20.38.3.247:2147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/gi.php"] [unique_id "aoSDz2r_JutbFb-8svog-AAAAcA"] [Tue Aug 18 13:09:51.215048 2026] [security2:error] [pid 167459:tid 167664] [client 20.38.3.247:3377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/vc.php"] [unique_id "aoSDz2r_JutbFb-8svog-QAAAdo"] [Tue Aug 18 13:09:51.234151 2026] [security2:error] [pid 167459:tid 167611] [client 68.221.73.131:17934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/puc.php"] [unique_id "aoSDz2r_JutbFb-8svog-wAAAaU"] [Tue Aug 18 13:09:51.342938 2026] [security2:error] [pid 167459:tid 167526] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSDz2r_JutbFb-8svohFAAB-UI"] [Tue Aug 18 13:09:51.375868 2026] [security2:error] [pid 167459:tid 167610] [client 20.91.215.254:22305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSDz2r_JutbFb-8svohHAAAAaQ"] [Tue Aug 18 13:09:51.396772 2026] [security2:error] [pid 167459:tid 167624] [client 20.104.49.167:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/abe.php"] [unique_id "aoSDz2r_JutbFb-8svohHQAAAbI"] [Tue Aug 18 13:09:51.400654 2026] [security2:error] [pid 167459:tid 167650] [client 20.215.241.237:39337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/media.php"] [unique_id "aoSDz2r_JutbFb-8svohHgAAAcw"] [Tue Aug 18 13:09:51.401664 2026] [security2:error] [pid 167459:tid 167676] [client 20.124.247.79:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/ee.php"] [unique_id "aoSDz2r_JutbFb-8svohHwAAAeY"] [Tue Aug 18 13:09:51.441478 2026] [security2:error] [pid 167459:tid 167698] [client 68.155.154.236:25354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSDz2r_JutbFb-8svohIAAAAfw"] [Tue Aug 18 13:09:51.449513 2026] [security2:error] [pid 167459:tid 167649] [client 52.139.47.57:9887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/content.php"] [unique_id "aoSDz2r_JutbFb-8svohIQAAAcs"] [Tue Aug 18 13:09:51.449882 2026] [security2:error] [pid 167459:tid 167599] [client 20.104.100.201:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/thoms.php"] [unique_id "aoSDz2r_JutbFb-8svohIgAAAZk"] [Tue Aug 18 13:09:51.459032 2026] [security2:error] [pid 167459:tid 167602] [client 158.23.17.4:36424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ho.php"] [unique_id "aoSDz2r_JutbFb-8svohJQAAAZw"] [Tue Aug 18 13:09:51.479445 2026] [security2:error] [pid 167459:tid 167512] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/index.php"] [unique_id "aoSDz2r_JutbFb-8svohJgAB4zQ"] [Tue Aug 18 13:09:51.484683 2026] [security2:error] [pid 167459:tid 167626] [client 172.182.217.32:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSDz2r_JutbFb-8svohKAAAAbQ"] [Tue Aug 18 13:09:51.518530 2026] [security2:error] [pid 167459:tid 167619] [client 213.35.127.232:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSDz2r_JutbFb-8svohLQAAAa0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:51.594189 2026] [security2:error] [pid 167459:tid 167627] [client 20.38.3.247:36625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/pema.php"] [unique_id "aoSDz2r_JutbFb-8svohMwAAAbU"] [Tue Aug 18 13:09:51.612013 2026] [security2:error] [pid 167459:tid 167675] [client 40.74.65.169:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/blurbs.php"] [unique_id "aoSDz2r_JutbFb-8svohNAAAAeU"] [Tue Aug 18 13:09:51.643967 2026] [security2:error] [pid 167459:tid 167636] [client 74.248.18.37:51423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/bthil.php"] [unique_id "aoSDz2r_JutbFb-8svohNwAAAb4"] [Tue Aug 18 13:09:51.662041 2026] [security2:error] [pid 167459:tid 167701] [client 20.124.247.79:15312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/tfm.php"] [unique_id "aoSDz2r_JutbFb-8svohOQAAAf8"] [Tue Aug 18 13:09:51.693265 2026] [security2:error] [pid 167459:tid 167612] [client 20.38.3.247:2472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/video.php"] [unique_id "aoSDz2r_JutbFb-8svohOwAAAaY"] [Tue Aug 18 13:09:51.695884 2026] [security2:error] [pid 167459:tid 167709] [client 20.1.169.243:9677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/images/min.php"] [unique_id "aoSDz2r_JutbFb-8svohPAAAAgc"] [Tue Aug 18 13:09:51.760615 2026] [security2:error] [pid 167459:tid 167716] [client 158.23.17.4:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/nh.php"] [unique_id "aoSDz2r_JutbFb-8svohQgAAAg4"] [Tue Aug 18 13:09:51.814965 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:51.815229 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:51.843998 2026] [security2:error] [pid 167459:tid 167678] [client 20.215.241.237:30451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/admin.php"] [unique_id "aoSDz2r_JutbFb-8svohRwAAAeg"] [Tue Aug 18 13:09:51.864920 2026] [security2:error] [pid 167459:tid 167694] [client 52.139.47.57:35315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/database.php"] [unique_id "aoSDz2r_JutbFb-8svohSAAAAfg"] [Tue Aug 18 13:09:51.913464 2026] [security2:error] [pid 167459:tid 167463] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/link-add.php"] [unique_id "aoSDz2r_JutbFb-8svohSwAB1AM"] [Tue Aug 18 13:09:51.916573 2026] [security2:error] [pid 167459:tid 167657] [client 20.124.247.79:15254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/tool.php"] [unique_id "aoSDz2r_JutbFb-8svohTAAAAdM"] [Tue Aug 18 13:09:51.919377 2026] [security2:error] [pid 167459:tid 167692] [client 20.250.13.23:10140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/goods.php"] [unique_id "aoSDz2r_JutbFb-8svohTQAAAfY"] [Tue Aug 18 13:09:51.921273 2026] [security2:error] [pid 167459:tid 167628] [client 40.74.65.169:6217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/bs1.php"] [unique_id "aoSDz2r_JutbFb-8svohTwAAAbY"] [Tue Aug 18 13:09:51.931778 2026] [security2:error] [pid 167459:tid 167617] [client 20.38.3.247:3631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/sh.php"] [unique_id "aoSDz2r_JutbFb-8svohUAAAAas"] [Tue Aug 18 13:09:52.009107 2026] [security2:error] [pid 167459:tid 167645] [client 20.91.215.254:16890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/upgrade/index.php"] [unique_id "aoSD0Gr_JutbFb-8svohUgAAAcc"] [Tue Aug 18 13:09:52.053455 2026] [security2:error] [pid 167459:tid 167485] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/login.php"] [unique_id "aoSD0Gr_JutbFb-8svohUwAB2hk"] [Tue Aug 18 13:09:52.083489 2026] [security2:error] [pid 167459:tid 167593] [client 158.23.17.4:53207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/97.php"] [unique_id "aoSD0Gr_JutbFb-8svohVQAAAZM"] [Tue Aug 18 13:09:52.115822 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:52.116249 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:52.188984 2026] [security2:error] [pid 167459:tid 167577] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/min.php"] [unique_id "aoSD0Gr_JutbFb-8svohXAABsnU"] [Tue Aug 18 13:09:52.196878 2026] [security2:error] [pid 167459:tid 167676] [client 20.38.3.247:2492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/hel.php"] [unique_id "aoSD0Gr_JutbFb-8svohXgAAAeY"] [Tue Aug 18 13:09:52.204224 2026] [security2:error] [pid 167459:tid 167649] [client 20.1.169.243:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSD0Gr_JutbFb-8svohYQAAAcs"] [Tue Aug 18 13:09:52.206673 2026] [security2:error] [pid 167459:tid 167599] [client 20.124.247.79:16726] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.rufinograf.com.br"] [uri "/1.php"] [unique_id "aoSD0Gr_JutbFb-8svohYgAAAZk"] [Tue Aug 18 13:09:52.206760 2026] [security2:error] [pid 167459:tid 167599] [client 20.124.247.79:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/1.php"] [unique_id "aoSD0Gr_JutbFb-8svohYgAAAZk"] [Tue Aug 18 13:09:52.253160 2026] [security2:error] [pid 167459:tid 167681] [client 74.248.133.44:51945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/php.php"] [unique_id "aoSD0Gr_JutbFb-8svohaAAAAes"] [Tue Aug 18 13:09:52.287454 2026] [security2:error] [pid 167459:tid 167651] [client 40.74.65.169:4837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/bajah.php"] [unique_id "aoSD0Gr_JutbFb-8svohbAAAAc0"] [Tue Aug 18 13:09:52.292060 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:18526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/db.php"] [unique_id "aoSD0Gr_JutbFb-8svohbQAAAaQ"] [Tue Aug 18 13:09:52.299419 2026] [security2:error] [pid 167459:tid 167623] [client 20.127.136.245:13234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/lite.php"] [unique_id "aoSD0Gr_JutbFb-8svohbgAAAbE"] [Tue Aug 18 13:09:52.302162 2026] [security2:error] [pid 167459:tid 167673] [client 138.36.100.162:43165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svohbwAAAeM"] [Tue Aug 18 13:09:52.302258 2026] [security2:error] [pid 167459:tid 167673] [client 138.36.100.162:43165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svohbwAAAeM"] [Tue Aug 18 13:09:52.308236 2026] [security2:error] [pid 167459:tid 167689] [client 20.38.3.247:41704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/button.php"] [unique_id "aoSD0Gr_JutbFb-8svohcAAAAfM"] [Tue Aug 18 13:09:52.318998 2026] [security2:error] [pid 167459:tid 167591] [client 20.215.241.237:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/mac.php"] [unique_id "aoSD0Gr_JutbFb-8svohcgAAAZE"] [Tue Aug 18 13:09:52.326320 2026] [security2:error] [pid 167459:tid 167519] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSD0Gr_JutbFb-8svohcwABvzs"] [Tue Aug 18 13:09:52.332870 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSD0Gr_JutbFb-8svohdAAAAgQ"] [Tue Aug 18 13:09:52.347513 2026] [security2:error] [pid 167459:tid 167682] [client 20.104.49.167:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/bs1.php"] [unique_id "aoSD0Gr_JutbFb-8svohdQAAAew"] [Tue Aug 18 13:09:52.361217 2026] [security2:error] [pid 167459:tid 167648] [client 20.116.17.175:22698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/005.php"] [unique_id "aoSD0Gr_JutbFb-8svohdgAAAco"] [Tue Aug 18 13:09:52.412525 2026] [security2:error] [pid 167459:tid 167571] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svohdwAB3G8"] [Tue Aug 18 13:09:52.412709 2026] [security2:error] [pid 167459:tid 167666] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svohdwAB3G8"] [Tue Aug 18 13:09:52.449337 2026] [security2:error] [pid 167459:tid 167635] [client 197.184.64.235:42703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svoheQAAAb0"] [Tue Aug 18 13:09:52.449519 2026] [security2:error] [pid 167459:tid 167635] [client 197.184.64.235:42703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0Gr_JutbFb-8svoheQAAAb0"] [Tue Aug 18 13:09:52.462337 2026] [security2:error] [pid 167459:tid 167472] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/network/post.php"] [unique_id "aoSD0Gr_JutbFb-8svohegABnQw"] [Tue Aug 18 13:09:52.537453 2026] [security2:error] [pid 167459:tid 167698] [client 213.35.127.232:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD0Gr_JutbFb-8svohfAAAAfw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:52.549383 2026] [security2:error] [pid 167459:tid 167686] [client 20.124.247.79:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/dev1s.php"] [unique_id "aoSD0Gr_JutbFb-8svohfQAAAfA"] [Tue Aug 18 13:09:52.550862 2026] [security2:error] [pid 167459:tid 167694] [client 172.182.217.32:15569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/ws.php"] [unique_id "aoSD0Gr_JutbFb-8svohfgAAAfg"] [Tue Aug 18 13:09:52.589252 2026] [security2:error] [pid 167459:tid 167600] [client 158.23.17.4:4665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/rh.php"] [unique_id "aoSD0Gr_JutbFb-8svohgAAAAZo"] [Tue Aug 18 13:09:52.592794 2026] [security2:error] [pid 167459:tid 167715] [client 20.1.169.243:10270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD0Gr_JutbFb-8svohhAAAAg0"] [Tue Aug 18 13:09:52.599271 2026] [security2:error] [pid 167459:tid 167513] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/test.php"] [unique_id "aoSD0Gr_JutbFb-8svohhgAB1DU"] [Tue Aug 18 13:09:52.661948 2026] [security2:error] [pid 167459:tid 167628] [client 20.38.3.247:37702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/wlc.php"] [unique_id "aoSD0Gr_JutbFb-8svohiwAAAbY"] [Tue Aug 18 13:09:52.690910 2026] [security2:error] [pid 167459:tid 167652] [client 20.104.100.201:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/yas.php"] [unique_id "aoSD0Gr_JutbFb-8svohjgAAAc4"] [Tue Aug 18 13:09:52.691362 2026] [security2:error] [pid 167459:tid 167614] [client 40.74.65.169:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/yes.php"] [unique_id "aoSD0Gr_JutbFb-8svohjwAAAag"] [Tue Aug 18 13:09:52.694249 2026] [security2:error] [pid 167459:tid 167703] [client 20.38.3.247:2438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/grok.php"] [unique_id "aoSD0Gr_JutbFb-8svohkAAAAgE"] [Tue Aug 18 13:09:52.714408 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:35287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/default.php"] [unique_id "aoSD0Gr_JutbFb-8svohkgAAAak"] [Tue Aug 18 13:09:52.733122 2026] [security2:error] [pid 167459:tid 167573] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSD0Gr_JutbFb-8svohlQABuHE"] [Tue Aug 18 13:09:52.739699 2026] [security2:error] [pid 167459:tid 167664] [client 20.215.241.237:30403] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/1.php"] [unique_id "aoSD0Gr_JutbFb-8svohlgAAAdo"] [Tue Aug 18 13:09:52.739802 2026] [security2:error] [pid 167459:tid 167664] [client 20.215.241.237:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/1.php"] [unique_id "aoSD0Gr_JutbFb-8svohlgAAAdo"] [Tue Aug 18 13:09:52.830135 2026] [security2:error] [pid 167459:tid 167595] [client 20.51.153.15:13358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sb.php"] [unique_id "aoSD0Gr_JutbFb-8svohmQAAAZU"] [Tue Aug 18 13:09:52.906955 2026] [security2:error] [pid 167459:tid 167602] [client 68.155.154.236:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/block-bindings/kXaPL5.php"] [unique_id "aoSD0Gr_JutbFb-8svohngAAAZw"] [Tue Aug 18 13:09:52.918699 2026] [security2:error] [pid 167459:tid 167606] [client 20.124.247.79:15270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/we.php"] [unique_id "aoSD0Gr_JutbFb-8svohnwAAAaA"] [Tue Aug 18 13:09:52.960845 2026] [security2:error] [pid 167459:tid 167619] [client 40.74.65.169:4820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/domvf.php"] [unique_id "aoSD0Gr_JutbFb-8svohogAAAa0"] [Tue Aug 18 13:09:52.986082 2026] [security2:error] [pid 167459:tid 167592] [client 20.38.3.247:3642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/fi.php"] [unique_id "aoSD0Gr_JutbFb-8svohpAAAAZI"] [Tue Aug 18 13:09:53.024029 2026] [security2:error] [pid 167459:tid 167480] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/user/min.php"] [unique_id "aoSD0Wr_JutbFb-8svohpwABsRQ"] [Tue Aug 18 13:09:53.038949 2026] [security2:error] [pid 167459:tid 167711] [client 172.182.217.32:15572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/wsa.php"] [unique_id "aoSD0Wr_JutbFb-8svohqAAAAgk"] [Tue Aug 18 13:09:53.073967 2026] [security2:error] [pid 167459:tid 167637] [client 20.38.3.247:37960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/indes.php"] [unique_id "aoSD0Wr_JutbFb-8svohqQAAAb8"] [Tue Aug 18 13:09:53.074680 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/root.php"] [unique_id "aoSD0Wr_JutbFb-8svohqgAAAgQ"] [Tue Aug 18 13:09:53.100765 2026] [security2:error] [pid 167459:tid 167682] [client 20.91.215.254:16892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSD0Wr_JutbFb-8svohrQAAAew"] [Tue Aug 18 13:09:53.132028 2026] [security2:error] [pid 167459:tid 167651] [client 52.139.47.57:13754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/dex.php"] [unique_id "aoSD0Wr_JutbFb-8svohsQAAAc0"] [Tue Aug 18 13:09:53.155968 2026] [security2:error] [pid 167459:tid 167612] [client 158.23.17.4:38336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/yg.php"] [unique_id "aoSD0Wr_JutbFb-8svohswAAAaY"] [Tue Aug 18 13:09:53.160294 2026] [security2:error] [pid 167459:tid 167709] [client 20.51.153.15:13404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xj.php"] [unique_id "aoSD0Wr_JutbFb-8svohtAAAAgc"] [Tue Aug 18 13:09:53.162354 2026] [security2:error] [pid 167459:tid 167484] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/users.php"] [unique_id "aoSD0Wr_JutbFb-8svohtQACAhg"] [Tue Aug 18 13:09:53.173290 2026] [security2:error] [pid 167459:tid 167601] [client 20.215.241.237:30436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/coffee.php"] [unique_id "aoSD0Wr_JutbFb-8svohtgAAAZs"] [Tue Aug 18 13:09:53.175475 2026] [security2:error] [pid 167459:tid 167670] [client 20.124.247.79:15322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/gdn.php"] [unique_id "aoSD0Wr_JutbFb-8svohtwAAAeA"] [Tue Aug 18 13:09:53.212645 2026] [security2:error] [pid 167459:tid 167603] [client 20.1.169.243:10211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/link-add.php"] [unique_id "aoSD0Wr_JutbFb-8svohugAAAZ0"] [Tue Aug 18 13:09:53.236612 2026] [security2:error] [pid 167459:tid 167699] [client 20.104.49.167:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/yes.php"] [unique_id "aoSD0Wr_JutbFb-8svohxAAAAf0"] [Tue Aug 18 13:09:53.260198 2026] [security2:error] [pid 167459:tid 167688] [client 158.23.17.4:56551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/oo.php"] [unique_id "aoSD0Wr_JutbFb-8svohxQAAAfI"] [Tue Aug 18 13:09:53.296478 2026] [security2:error] [pid 167459:tid 167534] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSD0Wr_JutbFb-8svohyAACAEo"] [Tue Aug 18 13:09:53.316936 2026] [security2:error] [pid 167459:tid 167694] [client 20.38.3.247:33713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/chris.php"] [unique_id "aoSD0Wr_JutbFb-8svohygAAAfg"] [Tue Aug 18 13:09:53.318050 2026] [security2:error] [pid 167459:tid 167668] [client 74.248.18.37:58933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD0Wr_JutbFb-8svohywAAAd4"] [Tue Aug 18 13:09:53.322239 2026] [authz_core:error] [pid 167459:tid 167567] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:53.322501 2026] [authz_core:error] [pid 167459:tid 167567] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:53.355992 2026] [security2:error] [pid 167459:tid 167590] [client 196.12.128.158:58785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD0Wr_JutbFb-8svohzQAAAZA"] [Tue Aug 18 13:09:53.356091 2026] [security2:error] [pid 167459:tid 167590] [client 196.12.128.158:58785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD0Wr_JutbFb-8svohzQAAAZA"] [Tue Aug 18 13:09:53.412660 2026] [security2:error] [pid 167459:tid 167692] [client 20.38.3.247:37999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/tTPcH.php"] [unique_id "aoSD0Wr_JutbFb-8svohzwAAAfY"] [Tue Aug 18 13:09:53.429496 2026] [security2:error] [pid 167459:tid 167645] [client 20.124.247.79:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/166.php"] [unique_id "aoSD0Wr_JutbFb-8svoh0AAAAcc"] [Tue Aug 18 13:09:53.430436 2026] [security2:error] [pid 167459:tid 167468] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSD0Wr_JutbFb-8svoh0QACCAg"] [Tue Aug 18 13:09:53.444182 2026] [security2:error] [pid 167459:tid 167653] [client 40.74.65.169:5632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/go.php"] [unique_id "aoSD0Wr_JutbFb-8svoh0gAAAc8"] [Tue Aug 18 13:09:53.468712 2026] [security2:error] [pid 167459:tid 167630] [client 20.51.153.15:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ns.php"] [unique_id "aoSD0Wr_JutbFb-8svoh1AAAAbg"] [Tue Aug 18 13:09:53.531963 2026] [security2:error] [pid 167459:tid 167617] [client 172.182.217.32:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/w.php"] [unique_id "aoSD0Wr_JutbFb-8svoh2QAAAas"] [Tue Aug 18 13:09:53.553485 2026] [security2:error] [pid 167459:tid 167707] [client 52.139.47.57:9864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/df.php"] [unique_id "aoSD0Wr_JutbFb-8svoh2gAAAgU"] [Tue Aug 18 13:09:53.553581 2026] [security2:error] [pid 167459:tid 167684] [client 213.35.127.232:49361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD0Wr_JutbFb-8svoh2wAAAe4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:53.565471 2026] [security2:error] [pid 167459:tid 167554] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSD0Wr_JutbFb-8svoh3QABy14"] [Tue Aug 18 13:09:53.598528 2026] [security2:error] [pid 167459:tid 167683] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.doroincorporacoes.com.br"] [uri "/index.php"] [unique_id "aoSD0Gr_JutbFb-8svohfwAB7QY"], referer: https://www.doroincorporacoes.com.br/ [Tue Aug 18 13:09:53.606066 2026] [security2:error] [pid 167459:tid 167589] [client 20.1.169.243:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/login.php"] [unique_id "aoSD0Wr_JutbFb-8svoh4AAAAY8"] [Tue Aug 18 13:09:53.647287 2026] [security2:error] [pid 167459:tid 167614] [client 74.248.18.37:30472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/x.php"] [unique_id "aoSD0Wr_JutbFb-8svoh4gAAAag"] [Tue Aug 18 13:09:53.649504 2026] [security2:error] [pid 167459:tid 167614] [client 40.74.65.169:4838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/fpwch.php"] [unique_id "aoSD0Wr_JutbFb-8svoh5AAAAag"] [Tue Aug 18 13:09:53.690749 2026] [security2:error] [pid 167459:tid 167680] [client 20.124.247.79:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/file3.php"] [unique_id "aoSD0Wr_JutbFb-8svoh5QAAAeo"] [Tue Aug 18 13:09:53.693793 2026] [security2:error] [pid 167459:tid 167619] [client 20.38.3.247:3721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/doc.php"] [unique_id "aoSD0Wr_JutbFb-8svoh5gAAAa0"] [Tue Aug 18 13:09:53.698222 2026] [security2:error] [pid 167459:tid 167613] [client 20.215.241.237:40535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD0Wr_JutbFb-8svoh5wAAAac"] [Tue Aug 18 13:09:53.702423 2026] [security2:error] [pid 167459:tid 167481] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSD0Wr_JutbFb-8svoh6AABkhU"] [Tue Aug 18 13:09:53.716092 2026] [security2:error] [pid 167459:tid 167593] [client 74.248.133.44:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/wp-class.php"] [unique_id "aoSD0Wr_JutbFb-8svoh6QAAAZM"] [Tue Aug 18 13:09:53.732287 2026] [security2:error] [pid 167459:tid 167662] [client 20.91.215.254:22299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-fclass.php"] [unique_id "aoSD0Wr_JutbFb-8svoh6gAAAdg"] [Tue Aug 18 13:09:53.782670 2026] [security2:error] [pid 167459:tid 167681] [client 20.51.153.15:13405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gk.php"] [unique_id "aoSD0Wr_JutbFb-8svoh7AAAAes"] [Tue Aug 18 13:09:53.793430 2026] [security2:error] [pid 167459:tid 167637] [client 158.23.17.4:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ja.php"] [unique_id "aoSD0Wr_JutbFb-8svoh7gAAAb8"] [Tue Aug 18 13:09:53.798270 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.100.201:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/fpwch.php"] [unique_id "aoSD0Wr_JutbFb-8svoh8AAAAgQ"] [Tue Aug 18 13:09:53.827747 2026] [security2:error] [pid 167459:tid 167651] [client 20.104.100.201:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ah25.php"] [unique_id "aoSD0Wr_JutbFb-8svoh8QAAAc0"] [Tue Aug 18 13:09:53.828611 2026] [security2:error] [pid 167459:tid 167708] [client 20.38.3.247:2480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/bs1.php"] [unique_id "aoSD0Wr_JutbFb-8svoh8gAAAgY"] [Tue Aug 18 13:09:53.837926 2026] [security2:error] [pid 167459:tid 167545] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSD0Wr_JutbFb-8svoh9AAB0lU"] [Tue Aug 18 13:09:53.861698 2026] [security2:error] [pid 167459:tid 167704] [client 158.23.17.4:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/et.php"] [unique_id "aoSD0Wr_JutbFb-8svoh9QAAAgI"] [Tue Aug 18 13:09:53.890510 2026] [autoindex:error] [pid 167459:tid 167635] [client 52.6.24.224:41841] AH01276: Cannot serve directory /home1/agencialkx/anuncienainternet.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:53.929437 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:53.929707 2026] [authz_core:error] [pid 167459:tid 167560] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:53.970417 2026] [security2:error] [pid 167459:tid 167648] [client 52.139.47.57:18497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/disagrsxr.php"] [unique_id "aoSD0Wr_JutbFb-8svoh_AAAAco"] [Tue Aug 18 13:09:53.971814 2026] [security2:error] [pid 167459:tid 167491] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-admin/x.php"] [unique_id "aoSD0Wr_JutbFb-8svoh_QAB-B8"] [Tue Aug 18 13:09:53.974557 2026] [security2:error] [pid 167459:tid 167668] [client 20.124.247.79:16702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/y.php"] [unique_id "aoSD0Wr_JutbFb-8svoh_gAAAd4"] [Tue Aug 18 13:09:53.994702 2026] [security2:error] [pid 167459:tid 167622] [client 68.155.154.236:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/PHPMailer/8bmaeS.php"] [unique_id "aoSD0Wr_JutbFb-8svoh_wAAAbA"] [Tue Aug 18 13:09:54.018237 2026] [security2:error] [pid 167459:tid 167716] [client 20.1.169.243:10230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/min.php"] [unique_id "aoSD0mr_JutbFb-8svoiAgAAAg4"] [Tue Aug 18 13:09:54.021523 2026] [security2:error] [pid 167459:tid 167709] [client 172.182.217.32:15437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/x.php"] [unique_id "aoSD0mr_JutbFb-8svoiAwAAAgc"] [Tue Aug 18 13:09:54.021601 2026] [security2:error] [pid 167459:tid 167700] [client 20.250.13.23:10124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/file.php"] [unique_id "aoSD0mr_JutbFb-8svoiBAAAAf4"] [Tue Aug 18 13:09:54.022414 2026] [security2:error] [pid 167459:tid 167643] [client 20.38.3.247:32478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/1337.php"] [unique_id "aoSD0mr_JutbFb-8svoiBQAAAcU"] [Tue Aug 18 13:09:54.030668 2026] [security2:error] [pid 167459:tid 167598] [client 20.51.153.15:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wn.php"] [unique_id "aoSD0mr_JutbFb-8svoiBgAAAZg"] [Tue Aug 18 13:09:54.042364 2026] [security2:error] [pid 167459:tid 167641] [client 20.171.51.14:2345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/fn.php"] [unique_id "aoSD0mr_JutbFb-8svoiCAAAAcM"] [Tue Aug 18 13:09:54.052148 2026] [security2:error] [pid 167459:tid 167652] [client 168.62.48.100:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD0mr_JutbFb-8svoiCQAAAc4"] [Tue Aug 18 13:09:54.086785 2026] [security2:error] [pid 167459:tid 167692] [client 20.104.49.167:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/go.php"] [unique_id "aoSD0mr_JutbFb-8svoiCgAAAfY"] [Tue Aug 18 13:09:54.105159 2026] [security2:error] [pid 167459:tid 167574] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-blogs.php"] [unique_id "aoSD0mr_JutbFb-8svoiCwACCnI"] [Tue Aug 18 13:09:54.121990 2026] [security2:error] [pid 167459:tid 167615] [client 20.215.241.237:46351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSD0mr_JutbFb-8svoiDQAAAak"] [Tue Aug 18 13:09:54.146929 2026] [security2:error] [pid 167459:tid 167672] [client 40.74.65.169:6235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/cof.php"] [unique_id "aoSD0mr_JutbFb-8svoiDwAAAeI"] [Tue Aug 18 13:09:54.239518 2026] [security2:error] [pid 167459:tid 167543] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSD0mr_JutbFb-8svoiEwAB1FM"] [Tue Aug 18 13:09:54.250324 2026] [security2:error] [pid 167459:tid 167605] [client 213.202.253.4:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/adminfuns.php"] [unique_id "aoSD0mr_JutbFb-8svoiFAAAAZ8"], referer: www.google.com [Tue Aug 18 13:09:54.272902 2026] [security2:error] [pid 167459:tid 167606] [client 158.23.17.4:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/of.php"] [unique_id "aoSD0mr_JutbFb-8svoiFQAAAaA"] [Tue Aug 18 13:09:54.311821 2026] [security2:error] [pid 167459:tid 167614] [client 20.124.247.79:15232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/modric8QWQCC.php"] [unique_id "aoSD0mr_JutbFb-8svoiFwAAAag"] [Tue Aug 18 13:09:54.326706 2026] [security2:error] [pid 167459:tid 167705] [client 20.51.153.15:13340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/app.php"] [unique_id "aoSD0mr_JutbFb-8svoiGQAAAgM"] [Tue Aug 18 13:09:54.341196 2026] [security2:error] [pid 167459:tid 167690] [client 20.38.3.247:2467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/hp2.php"] [unique_id "aoSD0mr_JutbFb-8svoiGgAAAfQ"] [Tue Aug 18 13:09:54.350956 2026] [security2:error] [pid 167459:tid 167592] [client 40.74.65.169:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/adminner.php"] [unique_id "aoSD0mr_JutbFb-8svoiGwAAAZI"] [Tue Aug 18 13:09:54.386013 2026] [security2:error] [pid 167459:tid 167683] [client 20.1.169.243:10473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/network/index.php"] [unique_id "aoSD0mr_JutbFb-8svoiHgAAAe0"] [Tue Aug 18 13:09:54.397197 2026] [security2:error] [pid 167459:tid 167602] [client 52.139.47.57:9879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/domvf.php"] [unique_id "aoSD0mr_JutbFb-8svoiHwAAAZw"] [Tue Aug 18 13:09:54.403017 2026] [security2:error] [pid 167459:tid 167593] [client 4.232.151.198:48701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSD0mr_JutbFb-8svoiIQAAAZM"] [Tue Aug 18 13:09:54.407060 2026] [security2:error] [pid 167459:tid 167610] [client 20.38.3.247:37703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/Njima.php"] [unique_id "aoSD0mr_JutbFb-8svoiIgAAAaQ"] [Tue Aug 18 13:09:54.499762 2026] [security2:error] [pid 167459:tid 167630] [client 49.145.211.146:9436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0mr_JutbFb-8svoiJQAAAbg"] [Tue Aug 18 13:09:54.499943 2026] [security2:error] [pid 167459:tid 167630] [client 49.145.211.146:9436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD0mr_JutbFb-8svoiJQAAAbg"] [Tue Aug 18 13:09:54.510541 2026] [security2:error] [pid 167459:tid 167619] [client 172.182.217.32:15807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/xx.php"] [unique_id "aoSD0mr_JutbFb-8svoiJgAAAa0"] [Tue Aug 18 13:09:54.519887 2026] [security2:error] [pid 167459:tid 167583] [remote 20.119.58.187:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/1.php"] [unique_id "aoSD0mr_JutbFb-8svoiJwAB-3s"] [Tue Aug 18 13:09:54.519997 2026] [security2:error] [pid 167459:tid 167583] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/1.php"] [unique_id "aoSD0mr_JutbFb-8svoiJwAB-3s"] [Tue Aug 18 13:09:54.562851 2026] [security2:error] [pid 167459:tid 167656] [client 20.215.241.237:2957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/yj09.php"] [unique_id "aoSD0mr_JutbFb-8svoiKQAAAdI"] [Tue Aug 18 13:09:54.575261 2026] [security2:error] [pid 167459:tid 167609] [client 213.35.127.232:49591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD0mr_JutbFb-8svoiKgAAAaM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:54.578252 2026] [security2:error] [pid 167459:tid 167603] [client 20.51.153.15:13389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/87.php"] [unique_id "aoSD0mr_JutbFb-8svoiLAAAAZ0"] [Tue Aug 18 13:09:54.588215 2026] [autoindex:error] [pid 167459:tid 167691] [client 82.108.212.5:60600] AH01276: Cannot serve directory /home4/meneghel/_wildcard_.meneghel.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:09:54.598106 2026] [security2:error] [pid 167459:tid 167699] [client 68.155.154.236:25393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/block-patterns/mkA9wN.php"] [unique_id "aoSD0mr_JutbFb-8svoiLwAAAf0"] [Tue Aug 18 13:09:54.655320 2026] [security2:error] [pid 167459:tid 167529] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/admin.php"] [unique_id "aoSD0mr_JutbFb-8svoiMgAB10U"] [Tue Aug 18 13:09:54.750049 2026] [security2:error] [pid 167459:tid 167698] [client 20.1.169.243:10278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/network/post.php"] [unique_id "aoSD0mr_JutbFb-8svoiMwAAAfw"] [Tue Aug 18 13:09:54.760748 2026] [security2:error] [pid 167459:tid 167633] [client 20.124.247.79:16660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/modric7Z7J2X.php"] [unique_id "aoSD0mr_JutbFb-8svoiNAAAAbs"] [Tue Aug 18 13:09:54.764040 2026] [security2:error] [pid 167459:tid 167700] [client 20.38.3.247:41724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/BIBIL.php"] [unique_id "aoSD0mr_JutbFb-8svoiNQAAAf4"] [Tue Aug 18 13:09:54.780009 2026] [security2:error] [pid 167459:tid 167641] [client 20.104.100.201:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/mg.php"] [unique_id "aoSD0mr_JutbFb-8svoiNgAAAcM"] [Tue Aug 18 13:09:54.789420 2026] [security2:error] [pid 167459:tid 167462] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/api.php"] [unique_id "aoSD0mr_JutbFb-8svoiNwACAQI"] [Tue Aug 18 13:09:54.796287 2026] [security2:error] [pid 167459:tid 167669] [client 20.116.17.175:44700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSD0mr_JutbFb-8svoiOgAAAd8"] [Tue Aug 18 13:09:54.817795 2026] [security2:error] [pid 167459:tid 167712] [client 20.91.215.254:16861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSD0mr_JutbFb-8svoiOwAAAgo"] [Tue Aug 18 13:09:54.825599 2026] [security2:error] [pid 167459:tid 167645] [client 20.104.100.201:13904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/ano.php"] [unique_id "aoSD0mr_JutbFb-8svoiPAAAAcc"] [Tue Aug 18 13:09:54.838621 2026] [security2:error] [pid 167459:tid 167704] [client 20.250.13.23:45607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/adminfuns.php"] [unique_id "aoSD0mr_JutbFb-8svoiPgAAAgI"] [Tue Aug 18 13:09:54.838894 2026] [security2:error] [pid 167459:tid 167622] [client 52.139.47.57:35277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSD0mr_JutbFb-8svoiPwAAAbA"] [Tue Aug 18 13:09:54.846319 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:54.846604 2026] [authz_core:error] [pid 167459:tid 167499] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:54.849754 2026] [security2:error] [pid 167459:tid 167672] [client 158.23.17.4:39572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/bu.php"] [unique_id "aoSD0mr_JutbFb-8svoiQQAAAeI"] [Tue Aug 18 13:09:54.868115 2026] [security2:error] [pid 167459:tid 167638] [client 20.38.3.247:2173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/yb.php"] [unique_id "aoSD0mr_JutbFb-8svoiQgAAAcA"] [Tue Aug 18 13:09:54.895630 2026] [security2:error] [pid 167459:tid 167640] [client 20.116.17.175:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/v2.php"] [unique_id "aoSD0mr_JutbFb-8svoiQwAAAcI"] [Tue Aug 18 13:09:54.898811 2026] [security2:error] [pid 167459:tid 167631] [client 74.248.133.44:29062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "aoSD0mr_JutbFb-8svoiRQAAAbk"] [Tue Aug 18 13:09:54.900400 2026] [security2:error] [pid 167459:tid 167621] [client 20.51.153.15:13420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/zi.php"] [unique_id "aoSD0mr_JutbFb-8svoiRgAAAa8"] [Tue Aug 18 13:09:54.923502 2026] [security2:error] [pid 167459:tid 167552] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSD0mr_JutbFb-8svoiRwABvFw"] [Tue Aug 18 13:09:54.924761 2026] [security2:error] [pid 167459:tid 167662] [client 74.248.18.37:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/666.php"] [unique_id "aoSD0mr_JutbFb-8svoiSAAAAdg"] [Tue Aug 18 13:09:54.992974 2026] [security2:error] [pid 167459:tid 167626] [client 20.215.241.237:46353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/scxy.php"] [unique_id "aoSD0mr_JutbFb-8svoiTQAAAbQ"] [Tue Aug 18 13:09:55.009377 2026] [security2:error] [pid 167459:tid 167510] [remote 129.121.103.155:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polimentodemarmore.com.br"] [uri "/wp-login.php"] [unique_id "aoSD02r_JutbFb-8svoiTwAB6jI"] [Tue Aug 18 13:09:55.046054 2026] [security2:error] [pid 167459:tid 167607] [client 172.182.217.32:15793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoiUQAAAaE"] [Tue Aug 18 13:09:55.048153 2026] [security2:error] [pid 167459:tid 167683] [client 20.124.247.79:15175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/modricXP4D68.php"] [unique_id "aoSD02r_JutbFb-8svoiUwAAAe0"] [Tue Aug 18 13:09:55.049107 2026] [authz_core:error] [pid 167459:tid 167496] [remote 57.141.22.55:32078] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:55.049372 2026] [authz_core:error] [pid 167459:tid 167496] [remote 57.141.22.55:32078] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:55.049609 2026] [security2:error] [pid 167459:tid 167664] [client 40.74.65.169:4900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxxirent.pt"] [uri "/abcd.php"] [unique_id "aoSD02r_JutbFb-8svoiVAAAAdo"] [Tue Aug 18 13:09:55.056821 2026] [security2:error] [pid 167459:tid 167539] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/db-status.php"] [unique_id "aoSD02r_JutbFb-8svoiVQAB5U8"] [Tue Aug 18 13:09:55.085150 2026] [security2:error] [pid 167459:tid 167673] [client 40.74.65.169:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/Engine.php"] [unique_id "aoSD02r_JutbFb-8svoiVwAAAeM"] [Tue Aug 18 13:09:55.102104 2026] [security2:error] [pid 167459:tid 167689] [client 158.23.17.4:11402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/xx.php"] [unique_id "aoSD02r_JutbFb-8svoiWAAAAfM"] [Tue Aug 18 13:09:55.111846 2026] [security2:error] [pid 167459:tid 167618] [client 20.38.3.247:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/too.php"] [unique_id "aoSD02r_JutbFb-8svoiWgAAAaw"] [Tue Aug 18 13:09:55.141117 2026] [security2:error] [pid 167459:tid 167671] [client 20.1.169.243:10242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/test.php"] [unique_id "aoSD02r_JutbFb-8svoiXQAAAeE"] [Tue Aug 18 13:09:55.169774 2026] [security2:error] [pid 167459:tid 167623] [client 49.37.150.8:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoiYAAAAbE"] [Tue Aug 18 13:09:55.169928 2026] [security2:error] [pid 167459:tid 167623] [client 49.37.150.8:61610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoiYAAAAbE"] [Tue Aug 18 13:09:55.193042 2026] [security2:error] [pid 167459:tid 167566] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSD02r_JutbFb-8svoiYQAB0mo"] [Tue Aug 18 13:09:55.209448 2026] [security2:error] [pid 167459:tid 167601] [client 20.51.153.15:13439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/92.php"] [unique_id "aoSD02r_JutbFb-8svoiYgAAAZs"] [Tue Aug 18 13:09:55.222345 2026] [security2:error] [pid 167459:tid 167635] [client 20.104.49.167:63737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/cof.php"] [unique_id "aoSD02r_JutbFb-8svoiYwAAAb0"] [Tue Aug 18 13:09:55.244871 2026] [security2:error] [pid 167459:tid 167646] [client 20.38.3.247:24409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/vc.php"] [unique_id "aoSD02r_JutbFb-8svoiZgAAAcg"] [Tue Aug 18 13:09:55.255358 2026] [security2:error] [pid 167459:tid 167630] [client 52.139.47.57:18529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/dxb/.well-known/options.php"] [unique_id "aoSD02r_JutbFb-8svoiaAAAAbg"] [Tue Aug 18 13:09:55.327545 2026] [security2:error] [pid 167459:tid 167565] [remote 20.119.58.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.58.119.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mrvprojetos.com"] [uri "/wp-content/home.php"] [unique_id "aoSD02r_JutbFb-8svoiawABxGk"] [Tue Aug 18 13:09:55.355732 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.100.201:13910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/nwflm.php"] [unique_id "aoSD02r_JutbFb-8svoibQAAAfw"] [Tue Aug 18 13:09:55.365131 2026] [security2:error] [pid 167459:tid 167633] [client 158.23.17.4:44716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/rn.php"] [unique_id "aoSD02r_JutbFb-8svoibgAAAbs"] [Tue Aug 18 13:09:55.366351 2026] [security2:error] [pid 167459:tid 167700] [client 20.124.247.79:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.247.124.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.rufinograf.com.br"] [uri "/clara.php"] [unique_id "aoSD02r_JutbFb-8svoibwAAAf4"] [Tue Aug 18 13:09:55.452037 2026] [security2:error] [pid 167459:tid 167710] [client 20.38.3.247:41721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.advocaciapedroso.com.br"] [uri "/g3.php"] [unique_id "aoSD02r_JutbFb-8svoidAAAAgg"] [Tue Aug 18 13:09:55.481015 2026] [security2:error] [pid 167459:tid 167704] [client 20.51.153.15:13346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/jm.php"] [unique_id "aoSD02r_JutbFb-8svoidwAAAgI"] [Tue Aug 18 13:09:55.507588 2026] [security2:error] [pid 167459:tid 167703] [client 20.1.169.243:10266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSD02r_JutbFb-8svoieAAAAgE"] [Tue Aug 18 13:09:55.513646 2026] [security2:error] [pid 167459:tid 167653] [client 20.215.241.237:40538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSD02r_JutbFb-8svoieQAAAc8"] [Tue Aug 18 13:09:55.533865 2026] [security2:error] [pid 167459:tid 167598] [client 172.182.217.32:12230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.217.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "acqualereformadepiscina.com.br"] [uri "/y.php"] [unique_id "aoSD02r_JutbFb-8svoiewAAAZg"] [Tue Aug 18 13:09:55.540078 2026] [security2:error] [pid 167459:tid 167715] [client 20.91.215.254:22285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/Requests/alfa-rex.php"] [unique_id "aoSD02r_JutbFb-8svoifAAAAg0"] [Tue Aug 18 13:09:55.542429 2026] [security2:error] [pid 167459:tid 167632] [client 20.104.100.201:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/reop3.php"] [unique_id "aoSD02r_JutbFb-8svoifQAAAbo"] [Tue Aug 18 13:09:55.591223 2026] [security2:error] [pid 167459:tid 167679] [client 213.35.127.232:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD02r_JutbFb-8svoifwAAAek"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:55.609738 2026] [security2:error] [pid 167459:tid 167520] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoigQABqzw"] [Tue Aug 18 13:09:55.609882 2026] [security2:error] [pid 167459:tid 167617] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoigQABqzw"] [Tue Aug 18 13:09:55.675604 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:9894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/edit.php"] [unique_id "aoSD02r_JutbFb-8svoihQAAAcA"] [Tue Aug 18 13:09:55.734350 2026] [security2:error] [pid 167459:tid 167624] [client 114.5.214.109:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoihwAAAbI"] [Tue Aug 18 13:09:55.734507 2026] [security2:error] [pid 167459:tid 167624] [client 114.5.214.109:50425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoihwAAAbI"] [Tue Aug 18 13:09:55.746473 2026] [security2:error] [pid 167459:tid 167680] [client 20.51.153.15:13352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wj.php"] [unique_id "aoSD02r_JutbFb-8svoiiQAAAeo"] [Tue Aug 18 13:09:55.801884 2026] [security2:error] [pid 167459:tid 167602] [client 158.23.17.4:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ut.php"] [unique_id "aoSD02r_JutbFb-8svoiigAAAZw"] [Tue Aug 18 13:09:55.846871 2026] [security2:error] [pid 167459:tid 167650] [client 40.74.65.169:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/hehe.php"] [unique_id "aoSD02r_JutbFb-8svoiiwAAAcw"] [Tue Aug 18 13:09:55.853370 2026] [security2:error] [pid 167459:tid 167673] [client 20.38.3.247:30695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/pema.php"] [unique_id "aoSD02r_JutbFb-8svoijAAAAeM"] [Tue Aug 18 13:09:55.950199 2026] [security2:error] [pid 167459:tid 167625] [client 158.23.17.4:15804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/conn-test.php"] [unique_id "aoSD02r_JutbFb-8svoikgAAAbM"] [Tue Aug 18 13:09:55.996506 2026] [security2:error] [pid 167459:tid 167611] [client 86.120.159.145:61594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoilAAAAaU"] [Tue Aug 18 13:09:55.996834 2026] [security2:error] [pid 167459:tid 167611] [client 86.120.159.145:61594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD02r_JutbFb-8svoilAAAAaU"] [Tue Aug 18 13:09:56.008857 2026] [security2:error] [pid 167459:tid 167601] [client 20.104.100.201:13951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/wp-load.php"] [unique_id "aoSD1Gr_JutbFb-8svoilQAAAZs"] [Tue Aug 18 13:09:56.031188 2026] [security2:error] [pid 167459:tid 167596] [client 20.1.169.243:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/user/min.php"] [unique_id "aoSD1Gr_JutbFb-8svoilwAAAZY"] [Tue Aug 18 13:09:56.038310 2026] [security2:error] [pid 167459:tid 167688] [client 20.51.153.15:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/74.php"] [unique_id "aoSD1Gr_JutbFb-8svoimAAAAfI"] [Tue Aug 18 13:09:56.048112 2026] [security2:error] [pid 167459:tid 167646] [client 20.215.241.237:59738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSD1Gr_JutbFb-8svoimgAAAcg"] [Tue Aug 18 13:09:56.053338 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:56.053601 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:56.073175 2026] [security2:error] [pid 167459:tid 167628] [client 20.116.17.175:41530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wkl.php"] [unique_id "aoSD1Gr_JutbFb-8svoimwAAAbY"] [Tue Aug 18 13:09:56.112119 2026] [security2:error] [pid 167459:tid 167692] [client 74.248.133.44:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/go.php"] [unique_id "aoSD1Gr_JutbFb-8svoinAAAAfY"] [Tue Aug 18 13:09:56.114038 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.49.167:50360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/Engine.php"] [unique_id "aoSD1Gr_JutbFb-8svoinQAAAdE"] [Tue Aug 18 13:09:56.114654 2026] [security2:error] [pid 167459:tid 167697] [client 52.139.47.57:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/elp.php"] [unique_id "aoSD1Gr_JutbFb-8svoingAAAfs"] [Tue Aug 18 13:09:56.156416 2026] [security2:error] [pid 167459:tid 167675] [client 46.102.21.132:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Gr_JutbFb-8svoioAAAAeU"] [Tue Aug 18 13:09:56.156535 2026] [security2:error] [pid 167459:tid 167675] [client 46.102.21.132:64410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Gr_JutbFb-8svoioAAAAeU"] [Tue Aug 18 13:09:56.181023 2026] [security2:error] [pid 167459:tid 167590] [client 158.23.17.4:53227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/eh.php"] [unique_id "aoSD1Gr_JutbFb-8svoioQAAAZA"] [Tue Aug 18 13:09:56.226074 2026] [security2:error] [pid 167459:tid 167698] [client 20.38.3.247:37992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/sh.php"] [unique_id "aoSD1Gr_JutbFb-8svoiowAAAfw"] [Tue Aug 18 13:09:56.234024 2026] [security2:error] [pid 167459:tid 167582] [remote 192.250.229.214:36180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sci.atlas-ia.com"] [uri "/wp-login.php"] [unique_id "aoSD1Gr_JutbFb-8svoipAAB0no"] [Tue Aug 18 13:09:56.273746 2026] [security2:error] [pid 167459:tid 167669] [client 20.127.136.245:23832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/ms-edit.php"] [unique_id "aoSD1Gr_JutbFb-8svoipQAAAd8"] [Tue Aug 18 13:09:56.278371 2026] [security2:error] [pid 167459:tid 167712] [client 20.51.153.15:13321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/av.php"] [unique_id "aoSD1Gr_JutbFb-8svoipgAAAgo"] [Tue Aug 18 13:09:56.291356 2026] [security2:error] [pid 167459:tid 167710] [client 20.104.100.201:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/php5.php"] [unique_id "aoSD1Gr_JutbFb-8svoipwAAAgg"] [Tue Aug 18 13:09:56.400651 2026] [security2:error] [pid 167459:tid 167665] [client 20.1.169.243:10244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/users.php"] [unique_id "aoSD1Gr_JutbFb-8svoiqgAAAds"] [Tue Aug 18 13:09:56.420062 2026] [security2:error] [pid 167459:tid 167597] [client 20.91.215.254:16866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/Requests/src/Response/about.php"] [unique_id "aoSD1Gr_JutbFb-8svoiqwAAAZc"] [Tue Aug 18 13:09:56.465474 2026] [security2:error] [pid 167459:tid 167631] [client 20.215.241.237:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/blurbs.php"] [unique_id "aoSD1Gr_JutbFb-8svoirAAAAbk"] [Tue Aug 18 13:09:56.512199 2026] [security2:error] [pid 167459:tid 167617] [client 68.155.154.236:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/rezor.php"] [unique_id "aoSD1Gr_JutbFb-8svoirwAAAas"] [Tue Aug 18 13:09:56.523323 2026] [security2:error] [pid 167459:tid 167672] [client 52.139.47.57:18501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/email.php"] [unique_id "aoSD1Gr_JutbFb-8svoisAAAAeI"] [Tue Aug 18 13:09:56.533765 2026] [security2:error] [pid 167459:tid 167649] [client 20.250.13.23:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/404.php"] [unique_id "aoSD1Gr_JutbFb-8svoisQAAAcs"] [Tue Aug 18 13:09:56.576885 2026] [security2:error] [pid 167459:tid 167638] [client 20.51.153.15:13317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ag.php"] [unique_id "aoSD1Gr_JutbFb-8svoiswAAAcA"] [Tue Aug 18 13:09:56.621126 2026] [security2:error] [pid 167459:tid 167645] [client 213.35.127.232:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD1Gr_JutbFb-8svoitQAAAcc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:56.643315 2026] [security2:error] [pid 167459:tid 167614] [client 158.23.17.4:7356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ad.php"] [unique_id "aoSD1Gr_JutbFb-8svoitgAAAag"] [Tue Aug 18 13:09:56.670676 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:5655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dkSUq.php"] [unique_id "aoSD1Gr_JutbFb-8svoiuAAAAbI"] [Tue Aug 18 13:09:56.687562 2026] [security2:error] [pid 167459:tid 167592] [client 20.38.3.247:44212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/button.php"] [unique_id "aoSD1Gr_JutbFb-8svoiugAAAZI"] [Tue Aug 18 13:09:56.770088 2026] [security2:error] [pid 167459:tid 167626] [client 20.1.169.243:10243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSD1Gr_JutbFb-8svoivwAAAbQ"] [Tue Aug 18 13:09:56.818601 2026] [security2:error] [pid 167459:tid 167619] [client 20.51.153.15:13339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ig.php"] [unique_id "aoSD1Gr_JutbFb-8svoiwQAAAa0"] [Tue Aug 18 13:09:56.897489 2026] [security2:error] [pid 167459:tid 167663] [client 20.215.241.237:2991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/bajah.php"] [unique_id "aoSD1Gr_JutbFb-8svoiwgAAAdk"] [Tue Aug 18 13:09:56.944172 2026] [security2:error] [pid 167459:tid 167609] [client 20.104.49.167:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/hehe.php"] [unique_id "aoSD1Gr_JutbFb-8svoixAAAAaM"] [Tue Aug 18 13:09:56.945153 2026] [security2:error] [pid 167459:tid 167671] [client 52.139.47.57:18537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/error.php"] [unique_id "aoSD1Gr_JutbFb-8svoixQAAAeE"] [Tue Aug 18 13:09:56.957822 2026] [security2:error] [pid 167459:tid 167591] [client 103.120.71.157:49274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Gr_JutbFb-8svoixwAAAZE"] [Tue Aug 18 13:09:56.957926 2026] [security2:error] [pid 167459:tid 167591] [client 103.120.71.157:49274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Gr_JutbFb-8svoixwAAAZE"] [Tue Aug 18 13:09:57.054278 2026] [security2:error] [pid 167459:tid 167711] [client 5.31.227.224:7817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Wr_JutbFb-8svoizAAAAgk"] [Tue Aug 18 13:09:57.054417 2026] [security2:error] [pid 167459:tid 167711] [client 5.31.227.224:7817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD1Wr_JutbFb-8svoizAAAAgk"] [Tue Aug 18 13:09:57.056137 2026] [security2:error] [pid 167459:tid 167606] [client 4.232.151.198:38893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSD1Wr_JutbFb-8svoizQAAAaA"] [Tue Aug 18 13:09:57.083637 2026] [security2:error] [pid 167459:tid 167686] [client 158.23.17.4:5035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/vd.php"] [unique_id "aoSD1Wr_JutbFb-8svoizwAAAfA"] [Tue Aug 18 13:09:57.115422 2026] [security2:error] [pid 167459:tid 167702] [client 20.51.153.15:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ta.php"] [unique_id "aoSD1Wr_JutbFb-8svoi0AAAAgA"] [Tue Aug 18 13:09:57.163506 2026] [security2:error] [pid 167459:tid 167677] [client 20.1.169.243:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSD1Wr_JutbFb-8svoi0QAAAec"] [Tue Aug 18 13:09:57.184686 2026] [security2:error] [pid 167459:tid 167675] [client 20.116.17.175:45418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-asudo.php"] [unique_id "aoSD1Wr_JutbFb-8svoi1AAAAeU"] [Tue Aug 18 13:09:57.274601 2026] [security2:error] [pid 167459:tid 167700] [client 20.91.215.254:22311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "aoSD1Wr_JutbFb-8svoi2QAAAf4"] [Tue Aug 18 13:09:57.301401 2026] [security2:error] [pid 167459:tid 167669] [client 74.248.133.44:63869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/atomlib.php"] [unique_id "aoSD1Wr_JutbFb-8svoi2gAAAd8"] [Tue Aug 18 13:09:57.318016 2026] [security2:error] [pid 167459:tid 167712] [client 20.215.241.237:39324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/domvf.php"] [unique_id "aoSD1Wr_JutbFb-8svoi2wAAAgo"] [Tue Aug 18 13:09:57.345056 2026] [security2:error] [pid 167459:tid 167696] [client 20.38.3.247:2153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/wlc.php"] [unique_id "aoSD1Wr_JutbFb-8svoi3QAAAfo"] [Tue Aug 18 13:09:57.345072 2026] [security2:error] [pid 167459:tid 167704] [client 68.221.73.131:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/inso.php"] [unique_id "aoSD1Wr_JutbFb-8svoi3AAAAgI"] [Tue Aug 18 13:09:57.363572 2026] [security2:error] [pid 167459:tid 167687] [client 52.139.47.57:18536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/f35.php"] [unique_id "aoSD1Wr_JutbFb-8svoi3gAAAfE"] [Tue Aug 18 13:09:57.399742 2026] [security2:error] [pid 167459:tid 167598] [client 40.74.65.169:5671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/qwas.php"] [unique_id "aoSD1Wr_JutbFb-8svoi3wAAAZg"] [Tue Aug 18 13:09:57.431210 2026] [security2:error] [pid 167459:tid 167707] [client 20.51.153.15:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/34.php"] [unique_id "aoSD1Wr_JutbFb-8svoi4AAAAgU"] [Tue Aug 18 13:09:57.442647 2026] [security2:error] [pid 167459:tid 167679] [client 20.104.100.201:17368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/acp.php"] [unique_id "aoSD1Wr_JutbFb-8svoi4gAAAek"] [Tue Aug 18 13:09:57.542886 2026] [security2:error] [pid 167459:tid 167595] [client 20.1.169.243:10259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSD1Wr_JutbFb-8svoi6gAAAZU"] [Tue Aug 18 13:09:57.607788 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:5001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/56.php"] [unique_id "aoSD1Wr_JutbFb-8svoi7gAAAeg"] [Tue Aug 18 13:09:57.624136 2026] [security2:error] [pid 167459:tid 167627] [client 20.104.100.201:13926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/jj.php"] [unique_id "aoSD1Wr_JutbFb-8svoi8AAAAbU"] [Tue Aug 18 13:09:57.634982 2026] [security2:error] [pid 167459:tid 167652] [client 213.35.127.232:50213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD1Wr_JutbFb-8svoi8QAAAc4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:57.704605 2026] [security2:error] [pid 167459:tid 167592] [client 20.51.153.15:13326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/he.php"] [unique_id "aoSD1Wr_JutbFb-8svoi8wAAAZI"] [Tue Aug 18 13:09:57.721242 2026] [security2:error] [pid 167459:tid 167613] [client 74.248.18.37:29986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/ws54.php"] [unique_id "aoSD1Wr_JutbFb-8svoi9AAAAac"] [Tue Aug 18 13:09:57.757199 2026] [security2:error] [pid 167459:tid 167590] [client 142.132.180.39:42538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.webeb.com.br"] [uri "/index.php"] [unique_id "aoSD1Wr_JutbFb-8svoi1QAAAZA"], referer: http://www.webeb.com.br [Tue Aug 18 13:09:57.773584 2026] [security2:error] [pid 167459:tid 167689] [client 158.23.17.4:11399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/fg.php"] [unique_id "aoSD1Wr_JutbFb-8svoi9gAAAfM"] [Tue Aug 18 13:09:57.777528 2026] [security2:error] [pid 167459:tid 167618] [client 168.62.48.100:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD1Wr_JutbFb-8svoi9wAAAaw"] [Tue Aug 18 13:09:57.781118 2026] [security2:error] [pid 167459:tid 167635] [client 223.185.37.47:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD1Wr_JutbFb-8svoi-AAAAb0"] [Tue Aug 18 13:09:57.781782 2026] [security2:error] [pid 167459:tid 167635] [client 223.185.37.47:22703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD1Wr_JutbFb-8svoi-AAAAb0"] [Tue Aug 18 13:09:57.795371 2026] [security2:error] [pid 167459:tid 167664] [client 20.116.17.175:41488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/az.php"] [unique_id "aoSD1Wr_JutbFb-8svoi-QAAAdo"] [Tue Aug 18 13:09:57.796363 2026] [security2:error] [pid 167459:tid 167640] [client 20.215.241.237:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/fpwch.php"] [unique_id "aoSD1Wr_JutbFb-8svoi-gAAAcI"] [Tue Aug 18 13:09:57.800587 2026] [security2:error] [pid 167459:tid 167716] [client 52.139.47.57:13722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/f35.update.php"] [unique_id "aoSD1Wr_JutbFb-8svoi-wAAAg4"] [Tue Aug 18 13:09:57.859269 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:57.859685 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:54035] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:57.860045 2026] [security2:error] [pid 167459:tid 167612] [client 20.38.3.247:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/fi.php"] [unique_id "aoSD1Wr_JutbFb-8svojAAAAAaY"] [Tue Aug 18 13:09:57.923606 2026] [security2:error] [pid 167459:tid 167619] [client 20.1.169.243:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSD1Wr_JutbFb-8svojAQAAAa0"] [Tue Aug 18 13:09:57.933623 2026] [security2:error] [pid 167459:tid 167660] [client 20.91.215.254:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/Text/xwx1.php"] [unique_id "aoSD1Wr_JutbFb-8svojAgAAAdY"] [Tue Aug 18 13:09:57.949001 2026] [security2:error] [pid 167459:tid 167699] [client 158.23.17.4:50559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/rx.php"] [unique_id "aoSD1Wr_JutbFb-8svojAwAAAf0"] [Tue Aug 18 13:09:57.994783 2026] [security2:error] [pid 167459:tid 167624] [client 4.232.151.198:38853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/gecko-new.php"] [unique_id "aoSD1Wr_JutbFb-8svojBwAAAbI"] [Tue Aug 18 13:09:58.005887 2026] [security2:error] [pid 167459:tid 167606] [client 20.51.153.15:13409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gz.php"] [unique_id "aoSD1mr_JutbFb-8svojCAAAAaA"] [Tue Aug 18 13:09:58.080011 2026] [security2:error] [pid 167459:tid 167702] [client 20.104.100.201:54068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/yas.php"] [unique_id "aoSD1mr_JutbFb-8svojDAAAAgA"] [Tue Aug 18 13:09:58.226805 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:13702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/file.php"] [unique_id "aoSD1mr_JutbFb-8svojDwAAAec"] [Tue Aug 18 13:09:58.271339 2026] [security2:error] [pid 167459:tid 167656] [client 20.104.49.167:64291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/dkSUq.php"] [unique_id "aoSD1mr_JutbFb-8svojEAAAAdI"] [Tue Aug 18 13:09:58.284130 2026] [security2:error] [pid 167459:tid 167643] [client 20.215.241.237:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/adminner.php"] [unique_id "aoSD1mr_JutbFb-8svojEQAAAcU"] [Tue Aug 18 13:09:58.290294 2026] [security2:error] [pid 167459:tid 167651] [client 20.1.169.243:9726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSD1mr_JutbFb-8svojEgAAAc0"] [Tue Aug 18 13:09:58.292379 2026] [security2:error] [pid 167459:tid 167669] [client 20.38.3.247:21252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/chris.php"] [unique_id "aoSD1mr_JutbFb-8svojEwAAAd8"] [Tue Aug 18 13:09:58.346757 2026] [security2:error] [pid 167459:tid 167661] [client 20.51.153.15:13434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nf.php"] [unique_id "aoSD1mr_JutbFb-8svojFAAAAdc"] [Tue Aug 18 13:09:58.365193 2026] [security2:error] [pid 167459:tid 167665] [client 74.248.133.44:30058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSD1mr_JutbFb-8svojFQAAAds"] [Tue Aug 18 13:09:58.492699 2026] [security2:error] [pid 167459:tid 167658] [client 20.102.65.165:8473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD1mr_JutbFb-8svojHwAAAdQ"] [Tue Aug 18 13:09:58.519441 2026] [security2:error] [pid 167459:tid 167678] [client 40.74.65.169:5659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/OK.php"] [unique_id "aoSD1mr_JutbFb-8svojIAAAAeg"] [Tue Aug 18 13:09:58.522058 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:7334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mandrill.php"] [unique_id "aoSD1mr_JutbFb-8svojIQAAAc4"] [Tue Aug 18 13:09:58.529970 2026] [security2:error] [pid 167459:tid 167680] [client 20.116.17.175:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/z43agz.php"] [unique_id "aoSD1mr_JutbFb-8svojIgAAAeo"] [Tue Aug 18 13:09:58.578008 2026] [security2:error] [pid 167459:tid 167598] [client 20.91.215.254:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "aoSD1mr_JutbFb-8svojJQAAAZg"] [Tue Aug 18 13:09:58.610716 2026] [security2:error] [pid 167459:tid 167589] [client 20.51.153.15:13423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xv.php"] [unique_id "aoSD1mr_JutbFb-8svojJwAAAY8"] [Tue Aug 18 13:09:58.638535 2026] [security2:error] [pid 167459:tid 167648] [client 20.250.13.23:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/wk/index.php"] [unique_id "aoSD1mr_JutbFb-8svojKAAAAco"] [Tue Aug 18 13:09:58.645152 2026] [security2:error] [pid 167459:tid 167644] [client 52.139.47.57:2690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/file2.php"] [unique_id "aoSD1mr_JutbFb-8svojKQAAAcY"] [Tue Aug 18 13:09:58.652454 2026] [security2:error] [pid 167459:tid 167633] [client 213.35.127.232:50431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD1mr_JutbFb-8svojKgAAAbs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:58.658786 2026] [security2:error] [pid 167459:tid 167690] [client 20.1.169.243:10252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-admin/x.php"] [unique_id "aoSD1mr_JutbFb-8svojKwAAAfQ"] [Tue Aug 18 13:09:58.698782 2026] [security2:error] [pid 167459:tid 167636] [client 20.38.3.247:2507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/doc.php"] [unique_id "aoSD1mr_JutbFb-8svojMgAAAb4"] [Tue Aug 18 13:09:58.724305 2026] [security2:error] [pid 167459:tid 167625] [client 20.104.100.201:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ah25.php"] [unique_id "aoSD1mr_JutbFb-8svojMwAAAbM"] [Tue Aug 18 13:09:58.746070 2026] [security2:error] [pid 167459:tid 167663] [client 20.215.241.237:40515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/abcd.php"] [unique_id "aoSD1mr_JutbFb-8svojNAAAAdk"] [Tue Aug 18 13:09:58.769405 2026] [security2:error] [pid 167459:tid 167667] [client 149.34.210.141:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD1mr_JutbFb-8svojNgAAAd0"] [Tue Aug 18 13:09:58.817307 2026] [security2:error] [pid 167459:tid 167591] [client 20.104.100.201:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/img.php"] [unique_id "aoSD1mr_JutbFb-8svojNwAAAZE"] [Tue Aug 18 13:09:58.848039 2026] [security2:error] [pid 167459:tid 167699] [client 20.102.65.165:8463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD1mr_JutbFb-8svojOAAAAf0"] [Tue Aug 18 13:09:58.855161 2026] [security2:error] [pid 167459:tid 167481] [remote 66.102.134.13:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.134.102.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holldyperfuracoes.com.br"] [uri "/wp-login.php"] [unique_id "aoSD1mr_JutbFb-8svojOQABrBU"] [Tue Aug 18 13:09:58.887788 2026] [security2:error] [pid 167459:tid 167666] [client 158.23.17.4:56728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ve.php"] [unique_id "aoSD1mr_JutbFb-8svojOgAAAdw"] [Tue Aug 18 13:09:58.892902 2026] [security2:error] [pid 167459:tid 167620] [client 20.51.153.15:13319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mx.php"] [unique_id "aoSD1mr_JutbFb-8svojOwAAAa4"] [Tue Aug 18 13:09:58.949404 2026] [security2:error] [pid 167459:tid 167697] [client 20.127.136.245:22599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/rip.php"] [unique_id "aoSD1mr_JutbFb-8svojPQAAAfs"] [Tue Aug 18 13:09:59.035891 2026] [security2:error] [pid 167459:tid 167667] [client 149.34.210.141:59677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD1mr_JutbFb-8svojNgAAAd0"] [Tue Aug 18 13:09:59.053883 2026] [security2:error] [pid 167459:tid 167711] [client 20.1.169.243:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-blogs.php"] [unique_id "aoSD12r_JutbFb-8svojRAAAAgk"] [Tue Aug 18 13:09:59.071393 2026] [security2:error] [pid 167459:tid 167692] [client 52.139.47.57:35288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/files.php"] [unique_id "aoSD12r_JutbFb-8svojRQAAAfY"] [Tue Aug 18 13:09:59.096647 2026] [security2:error] [pid 167459:tid 167637] [client 4.232.151.198:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/NewFile.php"] [unique_id "aoSD12r_JutbFb-8svojRgAAAb8"] [Tue Aug 18 13:09:59.151128 2026] [security2:error] [pid 167459:tid 167712] [client 20.102.65.165:8465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSD12r_JutbFb-8svojSAAAAgo"] [Tue Aug 18 13:09:59.184308 2026] [security2:error] [pid 167459:tid 167567] [remote 216.194.122.158:44620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.122.194.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSD12r_JutbFb-8svojSgABqms"] [Tue Aug 18 13:09:59.184883 2026] [security2:error] [pid 167459:tid 167715] [client 20.215.241.237:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/simple.php"] [unique_id "aoSD12r_JutbFb-8svojTAAAAg0"] [Tue Aug 18 13:09:59.189308 2026] [security2:error] [pid 167459:tid 167665] [client 20.38.3.247:2139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/1337.php"] [unique_id "aoSD12r_JutbFb-8svojTgAAAds"] [Tue Aug 18 13:09:59.201314 2026] [security2:error] [pid 167459:tid 167647] [client 20.51.153.15:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/45.php"] [unique_id "aoSD12r_JutbFb-8svojTwAAAck"] [Tue Aug 18 13:09:59.272920 2026] [security2:error] [pid 167459:tid 167599] [client 158.23.17.4:53185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/main.php"] [unique_id "aoSD12r_JutbFb-8svojVAAAAZk"] [Tue Aug 18 13:09:59.321876 2026] [security2:error] [pid 167459:tid 167657] [client 74.248.18.37:59006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSD12r_JutbFb-8svojVwAAAdM"] [Tue Aug 18 13:09:59.348307 2026] [http2:warn] [pid 157386:tid 157626] [client 17.246.19.48:44418] h2_stream(157386-1082-3,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0 [Tue Aug 18 13:09:59.388578 2026] [security2:error] [pid 167459:tid 167680] [client 20.104.100.201:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/ano.php"] [unique_id "aoSD12r_JutbFb-8svojXwAAAeo"] [Tue Aug 18 13:09:59.442392 2026] [security2:error] [pid 167459:tid 167595] [client 20.1.169.243:10197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSD12r_JutbFb-8svojYgAAAZU"] [Tue Aug 18 13:09:59.467218 2026] [security2:error] [pid 167459:tid 167681] [client 20.51.153.15:13392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wy.php"] [unique_id "aoSD12r_JutbFb-8svojZAAAAes"] [Tue Aug 18 13:09:59.469117 2026] [security2:error] [pid 167459:tid 167689] [client 20.116.17.175:41492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/3.php"] [unique_id "aoSD12r_JutbFb-8svojZgAAAfM"] [Tue Aug 18 13:09:59.488476 2026] [security2:error] [pid 167459:tid 167706] [client 20.104.49.167:8868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/qwas.php"] [unique_id "aoSD12r_JutbFb-8svojaAAAAgQ"] [Tue Aug 18 13:09:59.491012 2026] [security2:error] [pid 167459:tid 167608] [client 52.139.47.57:35299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/fix.php"] [unique_id "aoSD12r_JutbFb-8svojaQAAAaI"] [Tue Aug 18 13:09:59.527877 2026] [security2:error] [pid 167459:tid 167648] [client 20.102.65.165:8549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/av.php"] [unique_id "aoSD12r_JutbFb-8svojbAAAAco"] [Tue Aug 18 13:09:59.608274 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:59.608441 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:59.608573 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:59.608733 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:59.609524 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:09:59.609789 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:09:59.622854 2026] [security2:error] [pid 167459:tid 167612] [client 20.38.3.247:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/Njima.php"] [unique_id "aoSD12r_JutbFb-8svojdQAAAaY"] [Tue Aug 18 13:09:59.642367 2026] [security2:error] [pid 167459:tid 167619] [client 20.215.241.237:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSD12r_JutbFb-8svojdgAAAa0"] [Tue Aug 18 13:09:59.650451 2026] [security2:error] [pid 167459:tid 167660] [client 20.91.215.254:16845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/customize/class-wp-customize-cropped-image-control.php"] [unique_id "aoSD12r_JutbFb-8svojdwAAAdY"] [Tue Aug 18 13:09:59.665168 2026] [security2:error] [pid 167459:tid 167658] [client 213.35.127.232:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD12r_JutbFb-8svojeAAAAdQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:09:59.723820 2026] [security2:error] [pid 167459:tid 167596] [client 20.51.153.15:13314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/f.php"] [unique_id "aoSD12r_JutbFb-8svojfQAAAZY"] [Tue Aug 18 13:09:59.822370 2026] [security2:error] [pid 167459:tid 167670] [client 20.102.65.165:8512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/images.php"] [unique_id "aoSD12r_JutbFb-8svojhQAAAeA"] [Tue Aug 18 13:09:59.831247 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ga.php"] [unique_id "aoSD12r_JutbFb-8svojhgAAAaE"] [Tue Aug 18 13:09:59.868740 2026] [security2:error] [pid 167459:tid 167686] [client 20.104.100.201:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/nwflm.php"] [unique_id "aoSD12r_JutbFb-8svojigAAAfA"] [Tue Aug 18 13:09:59.911792 2026] [security2:error] [pid 167459:tid 167713] [client 52.139.47.57:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/fm.php"] [unique_id "aoSD12r_JutbFb-8svojjQAAAgs"] [Tue Aug 18 13:09:59.940508 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:10286] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/1.php"] [unique_id "aoSD12r_JutbFb-8svojkAAAAgo"] [Tue Aug 18 13:09:59.940636 2026] [security2:error] [pid 167459:tid 167712] [client 20.1.169.243:10286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/1.php"] [unique_id "aoSD12r_JutbFb-8svojkAAAAgo"] [Tue Aug 18 13:09:59.949835 2026] [security2:error] [pid 167459:tid 167633] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD12r_JutbFb-8svojhwABuzM"] [Tue Aug 18 13:09:59.953829 2026] [security2:error] [pid 167459:tid 167610] [client 20.250.13.23:51033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/about.php"] [unique_id "aoSD12r_JutbFb-8svojlAAAAaQ"] [Tue Aug 18 13:09:59.975067 2026] [security2:error] [pid 167459:tid 167707] [client 20.38.3.247:2447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/BIBIL.php"] [unique_id "aoSD12r_JutbFb-8svojlgAAAgU"] [Tue Aug 18 13:09:59.995784 2026] [security2:error] [pid 167459:tid 167679] [client 20.51.153.15:13334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/30.php"] [unique_id "aoSD12r_JutbFb-8svojmAAAAek"] [Tue Aug 18 13:10:00.065345 2026] [security2:error] [pid 167459:tid 167695] [client 20.104.100.201:13943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "slweb.net.br"] [uri "/we.php"] [unique_id "aoSD2Gr_JutbFb-8svojnQAAAfk"] [Tue Aug 18 13:10:00.079407 2026] [security2:error] [pid 167459:tid 167625] [client 4.232.151.198:38054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSD2Gr_JutbFb-8svojngAAAbM"] [Tue Aug 18 13:10:00.090659 2026] [security2:error] [pid 167459:tid 167669] [client 20.116.17.175:45376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/log.php"] [unique_id "aoSD2Gr_JutbFb-8svojnwAAAd8"] [Tue Aug 18 13:10:00.098957 2026] [security2:error] [pid 167459:tid 167654] [client 74.248.133.44:61976] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "automotivapoa.com.br"] [uri "/1.php"] [unique_id "aoSD2Gr_JutbFb-8svojoAAAAdA"] [Tue Aug 18 13:10:00.099115 2026] [security2:error] [pid 167459:tid 167654] [client 74.248.133.44:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/1.php"] [unique_id "aoSD2Gr_JutbFb-8svojoAAAAdA"] [Tue Aug 18 13:10:00.119495 2026] [security2:error] [pid 167459:tid 167632] [client 20.215.241.237:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/xiugai.php"] [unique_id "aoSD2Gr_JutbFb-8svojowAAAbo"] [Tue Aug 18 13:10:00.135076 2026] [security2:error] [pid 167459:tid 167500] [remote 129.121.103.155:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rhinteligente360.com.br"] [uri "/wp-login.php"] [unique_id "aoSD2Gr_JutbFb-8svojpgAB_Cg"] [Tue Aug 18 13:10:00.178652 2026] [security2:error] [pid 167459:tid 167684] [client 40.74.65.169:5643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/13.php"] [unique_id "aoSD2Gr_JutbFb-8svojqQAAAe4"] [Tue Aug 18 13:10:00.214925 2026] [security2:error] [pid 167459:tid 167681] [client 20.102.65.165:8466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/ops.php"] [unique_id "aoSD2Gr_JutbFb-8svojqgAAAes"] [Tue Aug 18 13:10:00.247040 2026] [security2:error] [pid 167459:tid 167703] [client 20.51.153.15:13427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pu.php"] [unique_id "aoSD2Gr_JutbFb-8svojrAAAAgE"] [Tue Aug 18 13:10:00.314157 2026] [security2:error] [pid 167459:tid 167590] [client 20.1.169.243:10276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/admin.php"] [unique_id "aoSD2Gr_JutbFb-8svojrwAAAZA"] [Tue Aug 18 13:10:00.321362 2026] [security2:error] [pid 167459:tid 167687] [client 213.202.253.4:59894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/adminfuns.php"] [unique_id "aoSD2Gr_JutbFb-8svojsQAAAfE"], referer: www.google.com [Tue Aug 18 13:10:00.328093 2026] [security2:error] [pid 167459:tid 167597] [client 52.139.47.57:9897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/footer.php"] [unique_id "aoSD2Gr_JutbFb-8svojsgAAAZc"] [Tue Aug 18 13:10:00.402358 2026] [security2:error] [pid 167459:tid 167520] [remote 129.121.103.155:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.103.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rhinteligente360.com.br"] [uri "/wp-login.php"] [unique_id "aoSD2Gr_JutbFb-8svojtAACAzw"], referer: https://rhinteligente360.com.br/wp-login.php [Tue Aug 18 13:10:00.427883 2026] [security2:error] [pid 167459:tid 167619] [client 20.38.3.247:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/too.php"] [unique_id "aoSD2Gr_JutbFb-8svojtgAAAa0"] [Tue Aug 18 13:10:00.454524 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:00.454790 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:00.465000 2026] [security2:error] [pid 167459:tid 167662] [client 168.62.48.100:5586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/weozh.php"] [unique_id "aoSD2Gr_JutbFb-8svojugAAAdg"] [Tue Aug 18 13:10:00.471904 2026] [security2:error] [pid 167459:tid 167639] [client 157.20.138.62:62870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2Gr_JutbFb-8svojuwAAAcE"] [Tue Aug 18 13:10:00.471985 2026] [security2:error] [pid 167459:tid 167639] [client 157.20.138.62:62870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2Gr_JutbFb-8svojuwAAAcE"] [Tue Aug 18 13:10:00.514342 2026] [security2:error] [pid 167459:tid 167596] [client 20.91.215.254:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "aoSD2Gr_JutbFb-8svojvwAAAZY"] [Tue Aug 18 13:10:00.522045 2026] [security2:error] [pid 167459:tid 167666] [client 20.102.65.165:8534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/coffexium.php"] [unique_id "aoSD2Gr_JutbFb-8svojwAAAAdw"] [Tue Aug 18 13:10:00.548565 2026] [security2:error] [pid 167459:tid 167600] [client 74.248.18.37:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/index/function.php"] [unique_id "aoSD2Gr_JutbFb-8svojwQAAAZo"] [Tue Aug 18 13:10:00.551873 2026] [security2:error] [pid 167459:tid 167643] [client 178.153.171.161:39567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2Gr_JutbFb-8svojwgAAAcU"] [Tue Aug 18 13:10:00.556247 2026] [security2:error] [pid 167459:tid 167643] [client 178.153.171.161:39567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2Gr_JutbFb-8svojwgAAAcU"] [Tue Aug 18 13:10:00.560637 2026] [security2:error] [pid 167459:tid 167628] [client 20.215.241.237:46362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/wp-load.php"] [unique_id "aoSD2Gr_JutbFb-8svojwwAAAbY"] [Tue Aug 18 13:10:00.567822 2026] [security2:error] [pid 167459:tid 167594] [client 20.51.153.15:13412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ry.php"] [unique_id "aoSD2Gr_JutbFb-8svojxAAAAZQ"] [Tue Aug 18 13:10:00.598060 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ia.php"] [unique_id "aoSD2Gr_JutbFb-8svojxgAAAaE"] [Tue Aug 18 13:10:00.688496 2026] [security2:error] [pid 167459:tid 167635] [client 213.35.127.232:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD2Gr_JutbFb-8svojyAAAAb0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:00.691256 2026] [security2:error] [pid 167459:tid 167708] [client 20.1.169.243:10274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/api.php"] [unique_id "aoSD2Gr_JutbFb-8svojyQAAAgY"] [Tue Aug 18 13:10:00.743728 2026] [security2:error] [pid 167459:tid 167683] [client 52.139.47.57:13744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/form.php"] [unique_id "aoSD2Gr_JutbFb-8svojywAAAe0"] [Tue Aug 18 13:10:00.776593 2026] [security2:error] [pid 167459:tid 167700] [client 20.104.49.167:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/OK.php"] [unique_id "aoSD2Gr_JutbFb-8svojzQAAAf4"] [Tue Aug 18 13:10:00.835099 2026] [security2:error] [pid 167459:tid 167696] [client 158.23.17.4:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/wb.php"] [unique_id "aoSD2Gr_JutbFb-8svoj0AAAAfo"] [Tue Aug 18 13:10:00.848187 2026] [security2:error] [pid 167459:tid 167695] [client 20.51.153.15:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pm.php"] [unique_id "aoSD2Gr_JutbFb-8svoj0QAAAfk"] [Tue Aug 18 13:10:00.849375 2026] [security2:error] [pid 167459:tid 167625] [client 20.116.17.175:41520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ohct.php"] [unique_id "aoSD2Gr_JutbFb-8svoj0gAAAbM"] [Tue Aug 18 13:10:00.854453 2026] [security2:error] [pid 167459:tid 167661] [client 20.171.51.14:36097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kf.php"] [unique_id "aoSD2Gr_JutbFb-8svoj0wAAAdc"] [Tue Aug 18 13:10:00.895613 2026] [security2:error] [pid 167459:tid 167652] [client 20.38.3.247:2149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.3.38.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.complexosaudeblindada.com.br"] [uri "/g3.php"] [unique_id "aoSD2Gr_JutbFb-8svoj1QAAAc4"] [Tue Aug 18 13:10:00.907831 2026] [security2:error] [pid 167459:tid 167575] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-plain.php"] [unique_id "aoSD2Gr_JutbFb-8svoj1gABw3M"], referer: www.google.com [Tue Aug 18 13:10:00.925474 2026] [security2:error] [pid 167459:tid 167523] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "aoSD2Gr_JutbFb-8svoj2QAB6T8"] [Tue Aug 18 13:10:00.934560 2026] [security2:error] [pid 167459:tid 167464] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSD2Gr_JutbFb-8svoj2gAB-AQ"], referer: www.google.com [Tue Aug 18 13:10:00.977849 2026] [security2:error] [pid 167459:tid 167598] [client 20.102.65.165:8522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSD2Gr_JutbFb-8svoj3AAAAZg"] [Tue Aug 18 13:10:00.994814 2026] [security2:error] [pid 167459:tid 167714] [client 74.248.133.44:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-includes/blocks/about.php"] [unique_id "aoSD2Gr_JutbFb-8svoj3QAAAgw"] [Tue Aug 18 13:10:01.057434 2026] [security2:error] [pid 167459:tid 167617] [client 20.1.169.243:10241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSD2Wr_JutbFb-8svoj3wAAAas"] [Tue Aug 18 13:10:01.068940 2026] [security2:error] [pid 167459:tid 167648] [client 20.215.241.237:3004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/155.php"] [unique_id "aoSD2Wr_JutbFb-8svoj4AAAAco"] [Tue Aug 18 13:10:01.117976 2026] [security2:error] [pid 167459:tid 167590] [client 20.51.153.15:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/dr.php"] [unique_id "aoSD2Wr_JutbFb-8svoj4QAAAZA"] [Tue Aug 18 13:10:01.154583 2026] [security2:error] [pid 167459:tid 167698] [client 20.91.215.254:22332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/images/wp-login.php"] [unique_id "aoSD2Wr_JutbFb-8svoj4wAAAfw"] [Tue Aug 18 13:10:01.163095 2026] [security2:error] [pid 167459:tid 167688] [client 52.139.47.57:35278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/fpwch.php"] [unique_id "aoSD2Wr_JutbFb-8svoj5QAAAfI"] [Tue Aug 18 13:10:01.301103 2026] [security2:error] [pid 167459:tid 167620] [client 20.102.65.165:8499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/sf.php"] [unique_id "aoSD2Wr_JutbFb-8svoj7wAAAa4"] [Tue Aug 18 13:10:01.328144 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:01.328413 2026] [authz_core:error] [pid 167459:tid 167538] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:01.338301 2026] [security2:error] [pid 167459:tid 167600] [client 158.23.17.4:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kn.php"] [unique_id "aoSD2Wr_JutbFb-8svoj8gAAAZo"] [Tue Aug 18 13:10:01.353234 2026] [security2:error] [pid 167459:tid 167643] [client 20.104.100.201:17304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/wp-load.php"] [unique_id "aoSD2Wr_JutbFb-8svoj8wAAAcU"] [Tue Aug 18 13:10:01.383860 2026] [security2:error] [pid 167459:tid 167607] [client 40.74.65.169:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file.php"] [unique_id "aoSD2Wr_JutbFb-8svoj9QAAAaE"] [Tue Aug 18 13:10:01.400864 2026] [security2:error] [pid 167459:tid 167470] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/ramutoau.php"] [unique_id "aoSD2Wr_JutbFb-8svoj9gACAAo"], referer: www.google.com [Tue Aug 18 13:10:01.417166 2026] [security2:error] [pid 167459:tid 167665] [client 74.248.18.37:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/function/function.php"] [unique_id "aoSD2Wr_JutbFb-8svoj-AAAAds"] [Tue Aug 18 13:10:01.424042 2026] [security2:error] [pid 167459:tid 167461] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSD2Wr_JutbFb-8svoj-QAB2AE"], referer: www.google.com [Tue Aug 18 13:10:01.430709 2026] [security2:error] [pid 167459:tid 167666] [client 20.1.169.243:9800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/db-status.php"] [unique_id "aoSD2Wr_JutbFb-8svoj-gAAAdw"] [Tue Aug 18 13:10:01.463112 2026] [security2:error] [pid 167459:tid 167711] [client 158.23.17.4:5051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/xn.php"] [unique_id "aoSD2Wr_JutbFb-8svoj-wAAAgk"] [Tue Aug 18 13:10:01.480940 2026] [security2:error] [pid 167459:tid 167710] [client 20.51.153.15:1993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ts.php"] [unique_id "aoSD2Wr_JutbFb-8svoj_AAAAgg"] [Tue Aug 18 13:10:01.510471 2026] [security2:error] [pid 167459:tid 167609] [client 74.248.18.37:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/aaa.php"] [unique_id "aoSD2Wr_JutbFb-8svokAAAAAaM"] [Tue Aug 18 13:10:01.564139 2026] [security2:error] [pid 167459:tid 167471] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "aoSD2Wr_JutbFb-8svokAgABmws"] [Tue Aug 18 13:10:01.580638 2026] [security2:error] [pid 167459:tid 167677] [client 52.139.47.57:18498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/function.php"] [unique_id "aoSD2Wr_JutbFb-8svokBAAAAec"] [Tue Aug 18 13:10:01.592118 2026] [security2:error] [pid 167459:tid 167664] [client 20.102.65.165:8538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/k.php"] [unique_id "aoSD2Wr_JutbFb-8svokBQAAAdo"] [Tue Aug 18 13:10:01.630525 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:01.630853 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:01.634350 2026] [security2:error] [pid 167459:tid 167631] [client 20.215.241.237:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/index.php"] [unique_id "aoSD2Wr_JutbFb-8svokCQAAAbk"] [Tue Aug 18 13:10:01.702016 2026] [security2:error] [pid 167459:tid 167594] [client 213.35.127.232:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD2Wr_JutbFb-8svokDQAAAZQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:01.726981 2026] [security2:error] [pid 167459:tid 167492] [remote 74.208.90.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.90.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "altostima.com.br"] [uri "/wp-login.php"] [unique_id "aoSD2Wr_JutbFb-8svokDgABvSA"] [Tue Aug 18 13:10:01.729292 2026] [security2:error] [pid 167459:tid 167547] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "aoSD2Wr_JutbFb-8svokDwAB9Fc"] [Tue Aug 18 13:10:01.786687 2026] [security2:error] [pid 167459:tid 167679] [client 20.51.153.15:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/53.php"] [unique_id "aoSD2Wr_JutbFb-8svokFAAAAek"] [Tue Aug 18 13:10:01.789761 2026] [security2:error] [pid 167459:tid 167610] [client 20.91.215.254:22315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-includes/js/dist/script-modules/block-library/search/about.php"] [unique_id "aoSD2Wr_JutbFb-8svokFQAAAaQ"] [Tue Aug 18 13:10:01.803159 2026] [security2:error] [pid 167459:tid 167605] [client 20.1.169.243:10241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSD2Wr_JutbFb-8svokFgAAAZ8"] [Tue Aug 18 13:10:01.851924 2026] [security2:error] [pid 167459:tid 167602] [client 20.102.65.165:8562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/82.php"] [unique_id "aoSD2Wr_JutbFb-8svokGQAAAZw"] [Tue Aug 18 13:10:01.877297 2026] [security2:error] [pid 167459:tid 167684] [client 20.104.49.167:50343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/13.php"] [unique_id "aoSD2Wr_JutbFb-8svokGwAAAe4"] [Tue Aug 18 13:10:01.898963 2026] [security2:error] [pid 167459:tid 167553] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "aoSD2Wr_JutbFb-8svokHQAB810"] [Tue Aug 18 13:10:01.916112 2026] [security2:error] [pid 167459:tid 167608] [client 20.116.17.175:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ot.php"] [unique_id "aoSD2Wr_JutbFb-8svokHwAAAaI"] [Tue Aug 18 13:10:01.930975 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:01.931260 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:01.957414 2026] [security2:error] [pid 167459:tid 167707] [client 20.104.100.201:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/jj.php"] [unique_id "aoSD2Wr_JutbFb-8svokIgAAAgU"] [Tue Aug 18 13:10:02.002917 2026] [security2:error] [pid 167459:tid 167714] [client 52.139.47.57:13715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/g.php"] [unique_id "aoSD2mr_JutbFb-8svokJQAAAgw"] [Tue Aug 18 13:10:02.010250 2026] [security2:error] [pid 167459:tid 167590] [client 20.91.215.254:12690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/backup.php"] [unique_id "aoSD2mr_JutbFb-8svokJgAAAZA"] [Tue Aug 18 13:10:02.029310 2026] [security2:error] [pid 167459:tid 167629] [client 20.51.153.15:13399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lq.php"] [unique_id "aoSD2mr_JutbFb-8svokKAAAAbc"] [Tue Aug 18 13:10:02.069824 2026] [security2:error] [pid 167459:tid 167570] [remote 45.138.16.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.16.138.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fabispinazolapilates.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "aoSD2mr_JutbFb-8svokKgAB2W4"] [Tue Aug 18 13:10:02.069942 2026] [security2:error] [pid 167459:tid 167612] [client 20.215.241.237:55190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/aaa.php"] [unique_id "aoSD2mr_JutbFb-8svokKwAAAaY"] [Tue Aug 18 13:10:02.161000 2026] [security2:error] [pid 167459:tid 167615] [client 20.102.65.165:8548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/dex.php"] [unique_id "aoSD2mr_JutbFb-8svokLgAAAak"] [Tue Aug 18 13:10:02.170414 2026] [security2:error] [pid 167459:tid 167716] [client 20.1.169.243:9690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.169.1.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fichiers.queroficarnanet.com"] [uri "/wp-content/home.php"] [unique_id "aoSD2mr_JutbFb-8svokLwAAAg4"] [Tue Aug 18 13:10:02.216986 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/47.php"] [unique_id "aoSD2mr_JutbFb-8svokMAAAAaU"] [Tue Aug 18 13:10:02.231832 2026] [authz_core:error] [pid 167459:tid 167586] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:02.232218 2026] [authz_core:error] [pid 167459:tid 167586] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:02.289510 2026] [security2:error] [pid 167459:tid 167619] [client 20.51.153.15:13359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/you.php"] [unique_id "aoSD2mr_JutbFb-8svokNAAAAa0"] [Tue Aug 18 13:10:02.333270 2026] [security2:error] [pid 167459:tid 167638] [client 74.248.18.37:39038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/abcd.php"] [unique_id "aoSD2mr_JutbFb-8svokNwAAAcA"] [Tue Aug 18 13:10:02.367630 2026] [security2:error] [pid 167459:tid 167710] [client 20.116.17.175:41480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/v5.php"] [unique_id "aoSD2mr_JutbFb-8svokOgAAAgg"] [Tue Aug 18 13:10:02.382070 2026] [security2:error] [pid 167459:tid 167656] [client 20.171.51.14:2734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/su.php"] [unique_id "aoSD2mr_JutbFb-8svokOwAAAdI"] [Tue Aug 18 13:10:02.429433 2026] [security2:error] [pid 167459:tid 167675] [client 52.139.47.57:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSD2mr_JutbFb-8svokPgAAAeU"] [Tue Aug 18 13:10:02.496709 2026] [security2:error] [pid 167459:tid 167664] [client 158.23.17.4:28608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wm.php"] [unique_id "aoSD2mr_JutbFb-8svokQQAAAdo"] [Tue Aug 18 13:10:02.517504 2026] [security2:error] [pid 167459:tid 167637] [client 20.102.65.165:8540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/puc.php"] [unique_id "aoSD2mr_JutbFb-8svokRAAAAb8"] [Tue Aug 18 13:10:02.532159 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:02.532636 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:02.542241 2026] [security2:error] [pid 167459:tid 167683] [client 20.51.153.15:13366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ez.php"] [unique_id "aoSD2mr_JutbFb-8svokRgAAAe0"] [Tue Aug 18 13:10:02.567452 2026] [security2:error] [pid 167459:tid 167623] [client 20.104.100.201:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/img.php"] [unique_id "aoSD2mr_JutbFb-8svokRwAAAbE"] [Tue Aug 18 13:10:02.578482 2026] [security2:error] [pid 167459:tid 167696] [client 20.215.241.237:46336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSD2mr_JutbFb-8svokSAAAAfo"] [Tue Aug 18 13:10:02.616242 2026] [security2:error] [pid 167459:tid 167592] [client 102.213.179.104:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokTAAAAZI"] [Tue Aug 18 13:10:02.616418 2026] [security2:error] [pid 167459:tid 167592] [client 102.213.179.104:64350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokTAAAAZI"] [Tue Aug 18 13:10:02.626582 2026] [security2:error] [pid 167459:tid 167591] [client 158.23.17.4:32409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/payout.php"] [unique_id "aoSD2mr_JutbFb-8svokTQAAAZE"] [Tue Aug 18 13:10:02.640622 2026] [security2:error] [pid 167459:tid 167682] [client 74.248.18.37:39875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/nw.php"] [unique_id "aoSD2mr_JutbFb-8svokTgAAAew"] [Tue Aug 18 13:10:02.642712 2026] [security2:error] [pid 167459:tid 167594] [client 20.91.215.254:22295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/wp-themes.php"] [unique_id "aoSD2mr_JutbFb-8svokTwAAAZQ"] [Tue Aug 18 13:10:02.654863 2026] [security2:error] [pid 167459:tid 167661] [client 40.74.65.169:5672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/rezor.php"] [unique_id "aoSD2mr_JutbFb-8svokUAAAAdc"] [Tue Aug 18 13:10:02.716138 2026] [security2:error] [pid 167459:tid 167713] [client 213.35.127.232:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD2mr_JutbFb-8svokUgAAAgs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:02.753162 2026] [security2:error] [pid 167459:tid 167652] [client 138.36.100.162:42133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokVAAAAc4"] [Tue Aug 18 13:10:02.753296 2026] [security2:error] [pid 167459:tid 167652] [client 138.36.100.162:42133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokVAAAAc4"] [Tue Aug 18 13:10:02.787427 2026] [security2:error] [pid 167459:tid 167631] [client 20.91.215.254:12682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSD2mr_JutbFb-8svokVgAAAbk"] [Tue Aug 18 13:10:02.820205 2026] [security2:error] [pid 167459:tid 167667] [client 20.51.153.15:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/asus.php"] [unique_id "aoSD2mr_JutbFb-8svokVwAAAd0"] [Tue Aug 18 13:10:02.835528 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:02.835820 2026] [authz_core:error] [pid 167459:tid 167574] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:02.856692 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:9903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/gtt.php"] [unique_id "aoSD2mr_JutbFb-8svokWgAAAfQ"] [Tue Aug 18 13:10:02.888006 2026] [security2:error] [pid 167459:tid 167705] [client 45.131.195.120:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elietelucasadv.com.br"] [uri "/wp-login.php"] [unique_id "aoSD2mr_JutbFb-8svokUwAAAgM"] [Tue Aug 18 13:10:02.924243 2026] [security2:error] [pid 167459:tid 167672] [client 197.184.64.235:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokXAAAAeI"] [Tue Aug 18 13:10:02.924388 2026] [security2:error] [pid 167459:tid 167672] [client 197.184.64.235:42704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD2mr_JutbFb-8svokXAAAAeI"] [Tue Aug 18 13:10:02.964550 2026] [security2:error] [pid 167459:tid 167689] [client 20.102.65.165:8491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/inso.php"] [unique_id "aoSD2mr_JutbFb-8svokXgAAAfM"] [Tue Aug 18 13:10:03.015112 2026] [security2:error] [pid 167459:tid 167645] [client 20.215.241.237:2961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/site.php"] [unique_id "aoSD22r_JutbFb-8svokYAAAAcc"] [Tue Aug 18 13:10:03.095305 2026] [security2:error] [pid 167459:tid 167687] [client 20.116.17.175:22677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/replace.php"] [unique_id "aoSD22r_JutbFb-8svokYgAAAfE"] [Tue Aug 18 13:10:03.129960 2026] [security2:error] [pid 167459:tid 167640] [client 20.104.100.201:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.100.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "doctor360.online"] [uri "/we.php"] [unique_id "aoSD22r_JutbFb-8svokZQAAAcI"] [Tue Aug 18 13:10:03.131078 2026] [security2:error] [pid 167459:tid 167704] [client 20.51.153.15:13332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/22.php"] [unique_id "aoSD22r_JutbFb-8svokZgAAAgI"] [Tue Aug 18 13:10:03.166548 2026] [security2:error] [pid 167459:tid 167612] [client 158.23.17.4:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/ac.php"] [unique_id "aoSD22r_JutbFb-8svokaQAAAaY"] [Tue Aug 18 13:10:03.208596 2026] [security2:error] [pid 167459:tid 167684] [client 20.250.13.23:27410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/term.php"] [unique_id "aoSD22r_JutbFb-8svokagAAAe4"] [Tue Aug 18 13:10:03.270134 2026] [security2:error] [pid 167459:tid 167709] [client 52.139.47.57:18545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/gulu.php"] [unique_id "aoSD22r_JutbFb-8svokbgAAAgc"] [Tue Aug 18 13:10:03.287695 2026] [security2:error] [pid 167459:tid 167590] [client 20.91.215.254:22296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ceussmedicina.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD22r_JutbFb-8svokbwAAAZA"] [Tue Aug 18 13:10:03.384880 2026] [security2:error] [pid 167459:tid 167618] [client 158.23.17.4:40509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/bh.php"] [unique_id "aoSD22r_JutbFb-8svokcQAAAaw"] [Tue Aug 18 13:10:03.398168 2026] [security2:error] [pid 167459:tid 167607] [client 40.74.65.169:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/3p8jj8r.php"] [unique_id "aoSD22r_JutbFb-8svokcgAAAaE"] [Tue Aug 18 13:10:03.399279 2026] [security2:error] [pid 167459:tid 167627] [client 20.51.153.15:13369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/zs.php"] [unique_id "aoSD22r_JutbFb-8svokcwAAAbU"] [Tue Aug 18 13:10:03.416163 2026] [security2:error] [pid 167459:tid 167488] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD22r_JutbFb-8svokdAACABw"] [Tue Aug 18 13:10:03.416307 2026] [security2:error] [pid 167459:tid 167702] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD22r_JutbFb-8svokdAACABw"] [Tue Aug 18 13:10:03.421573 2026] [security2:error] [pid 167459:tid 167666] [client 20.102.65.165:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/aa.php"] [unique_id "aoSD22r_JutbFb-8svokdgAAAdw"] [Tue Aug 18 13:10:03.454641 2026] [security2:error] [pid 167459:tid 167658] [client 20.91.215.254:12805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/sx.php"] [unique_id "aoSD22r_JutbFb-8svokeAAAAdQ"] [Tue Aug 18 13:10:03.518119 2026] [security2:error] [pid 167459:tid 167621] [client 20.215.241.237:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/ccc.php"] [unique_id "aoSD22r_JutbFb-8svokfAAAAa8"] [Tue Aug 18 13:10:03.685744 2026] [security2:error] [pid 167459:tid 167683] [client 20.51.153.15:2020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/iz.php"] [unique_id "aoSD22r_JutbFb-8svokggAAAe0"] [Tue Aug 18 13:10:03.713835 2026] [security2:error] [pid 167459:tid 167596] [client 52.139.47.57:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/hello.php"] [unique_id "aoSD22r_JutbFb-8svokhAAAAZY"] [Tue Aug 18 13:10:03.727872 2026] [security2:error] [pid 167459:tid 167670] [client 213.35.127.232:51532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD22r_JutbFb-8svokhQAAAeA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:03.746128 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:03.746468 2026] [authz_core:error] [pid 167459:tid 167583] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:03.775289 2026] [security2:error] [pid 167459:tid 167682] [client 20.102.65.165:8478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/img.php"] [unique_id "aoSD22r_JutbFb-8svokhwAAAew"] [Tue Aug 18 13:10:03.798870 2026] [security2:error] [pid 167459:tid 167594] [client 20.116.17.175:22758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/fw/faiyy.php"] [unique_id "aoSD22r_JutbFb-8svokigAAAZQ"] [Tue Aug 18 13:10:03.820204 2026] [security2:error] [pid 167459:tid 167654] [client 4.232.151.198:43491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSD22r_JutbFb-8svokjAAAAdA"] [Tue Aug 18 13:10:03.850484 2026] [security2:error] [pid 167459:tid 167713] [client 158.23.17.4:5019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/ct.php"] [unique_id "aoSD22r_JutbFb-8svokjQAAAgs"] [Tue Aug 18 13:10:03.896966 2026] [security2:error] [pid 167459:tid 167597] [client 196.12.128.158:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD22r_JutbFb-8svokjwAAAZc"] [Tue Aug 18 13:10:03.897110 2026] [security2:error] [pid 167459:tid 167597] [client 196.12.128.158:59535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD22r_JutbFb-8svokjwAAAZc"] [Tue Aug 18 13:10:03.941481 2026] [security2:error] [pid 167459:tid 167631] [client 158.23.17.4:48432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/yz.php"] [unique_id "aoSD22r_JutbFb-8svokkgAAAbk"] [Tue Aug 18 13:10:03.944816 2026] [security2:error] [pid 167459:tid 167628] [client 108.165.238.6:31464] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD22r_JutbFb-8svokkQAAAbY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:03.973833 2026] [security2:error] [pid 167459:tid 167699] [client 20.51.153.15:13348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/se.php"] [unique_id "aoSD22r_JutbFb-8svoklgAAAf0"] [Tue Aug 18 13:10:04.011621 2026] [security2:error] [pid 167459:tid 167688] [client 20.215.241.237:3002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/admin.php"] [unique_id "aoSD3Gr_JutbFb-8svoklwAAAfI"] [Tue Aug 18 13:10:04.048252 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:04.048567 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:04.117662 2026] [security2:error] [pid 167459:tid 167651] [client 20.91.215.254:12814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/st.php"] [unique_id "aoSD3Gr_JutbFb-8svokmwAAAc0"] [Tue Aug 18 13:10:04.130009 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:2719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/html/plugins/plugins/config.php"] [unique_id "aoSD3Gr_JutbFb-8svoknQAAAfQ"] [Tue Aug 18 13:10:04.164456 2026] [security2:error] [pid 167459:tid 167629] [client 20.104.49.167:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/file.php"] [unique_id "aoSD3Gr_JutbFb-8svokoAAAAbc"] [Tue Aug 18 13:10:04.174093 2026] [security2:error] [pid 167459:tid 167655] [client 20.102.65.165:8527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/222.php"] [unique_id "aoSD3Gr_JutbFb-8svokoQAAAdE"] [Tue Aug 18 13:10:04.203254 2026] [security2:error] [pid 167459:tid 167640] [client 40.74.65.169:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dapa.php"] [unique_id "aoSD3Gr_JutbFb-8svokogAAAcI"] [Tue Aug 18 13:10:04.246875 2026] [security2:error] [pid 167459:tid 167603] [client 20.116.17.175:22709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/dk.php"] [unique_id "aoSD3Gr_JutbFb-8svokpwAAAZ0"] [Tue Aug 18 13:10:04.271704 2026] [security2:error] [pid 167459:tid 167673] [client 20.51.153.15:2031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vp.php"] [unique_id "aoSD3Gr_JutbFb-8svokqAAAAeM"] [Tue Aug 18 13:10:04.334244 2026] [security2:error] [pid 167459:tid 167695] [client 74.248.18.37:30477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-good.php"] [unique_id "aoSD3Gr_JutbFb-8svokrAAAAfk"] [Tue Aug 18 13:10:04.345820 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:04.346095 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 Not Found: /visualizar-pedido/images/favicon.ico [Tue Aug 18 13:10:04.483600 2026] [security2:error] [pid 167459:tid 167680] [client 158.23.17.4:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/gy.php"] [unique_id "aoSD3Gr_JutbFb-8svokuwAAAeo"] [Tue Aug 18 13:10:04.511466 2026] [security2:error] [pid 167459:tid 167634] [client 20.250.13.23:28933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSD3Gr_JutbFb-8svokvgAAAbw"] [Tue Aug 18 13:10:04.549528 2026] [security2:error] [pid 167459:tid 167636] [client 52.139.47.57:35322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/class-config.php"] [unique_id "aoSD3Gr_JutbFb-8svokwAAAAb4"] [Tue Aug 18 13:10:04.557213 2026] [security2:error] [pid 167459:tid 167683] [client 20.51.153.15:13422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ph.php"] [unique_id "aoSD3Gr_JutbFb-8svokwgAAAe0"] [Tue Aug 18 13:10:04.561150 2026] [security2:error] [pid 167459:tid 167628] [client 108.165.238.6:31464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD22r_JutbFb-8svokkQAAAbY"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:04.574405 2026] [security2:error] [pid 167459:tid 167623] [client 20.215.241.237:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/reviall.php"] [unique_id "aoSD3Gr_JutbFb-8svokxQAAAbE"] [Tue Aug 18 13:10:04.624237 2026] [security2:error] [pid 167459:tid 167670] [client 158.23.17.4:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kj.php"] [unique_id "aoSD3Gr_JutbFb-8svokygAAAeA"] [Tue Aug 18 13:10:04.634771 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:41519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/bal.php"] [unique_id "aoSD3Gr_JutbFb-8svokywAAAZI"] [Tue Aug 18 13:10:04.648456 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:04.648902 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:04.674281 2026] [security2:error] [pid 167459:tid 167644] [client 74.248.18.37:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xleet.php"] [unique_id "aoSD3Gr_JutbFb-8svokzwAAAcY"] [Tue Aug 18 13:10:04.685026 2026] [security2:error] [pid 167459:tid 167710] [client 74.249.206.207:16166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD3Gr_JutbFb-8svok0gAAAgg"] [Tue Aug 18 13:10:04.708778 2026] [security2:error] [pid 167459:tid 167594] [client 20.102.65.165:8521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/key.php"] [unique_id "aoSD3Gr_JutbFb-8svok1AAAAZQ"] [Tue Aug 18 13:10:04.739908 2026] [security2:error] [pid 167459:tid 167638] [client 213.35.127.232:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD3Gr_JutbFb-8svok2AAAAcA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:04.750824 2026] [security2:error] [pid 167459:tid 167715] [client 20.91.215.254:13017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSD3Gr_JutbFb-8svok2QAAAg0"] [Tue Aug 18 13:10:04.817671 2026] [security2:error] [pid 167459:tid 167597] [client 20.51.153.15:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/s.php"] [unique_id "aoSD3Gr_JutbFb-8svok2wAAAZc"] [Tue Aug 18 13:10:04.997952 2026] [security2:error] [pid 167459:tid 167706] [client 158.23.17.4:32389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/tt.php"] [unique_id "aoSD3Gr_JutbFb-8svok5AAAAgQ"] [Tue Aug 18 13:10:05.040396 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:5514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/Ipv6.php"] [unique_id "aoSD3Wr_JutbFb-8svok5QAAAbI"] [Tue Aug 18 13:10:05.057341 2026] [security2:error] [pid 167459:tid 167666] [client 103.120.71.157:57305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svok5gAAAdw"] [Tue Aug 18 13:10:05.057481 2026] [security2:error] [pid 167459:tid 167666] [client 103.120.71.157:57305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svok5gAAAdw"] [Tue Aug 18 13:10:05.058681 2026] [security2:error] [pid 167459:tid 167626] [client 20.116.17.175:41535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/yawa.php"] [unique_id "aoSD3Wr_JutbFb-8svok5wAAAbQ"] [Tue Aug 18 13:10:05.071010 2026] [security2:error] [pid 167459:tid 167611] [client 94.229.214.255:51268] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD3Gr_JutbFb-8svok1wAAAaU"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:05.083653 2026] [security2:error] [pid 167459:tid 167701] [client 20.215.241.237:39330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/nope.php"] [unique_id "aoSD3Wr_JutbFb-8svok6QAAAf8"] [Tue Aug 18 13:10:05.110775 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:35305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/images/index.php"] [unique_id "aoSD3Wr_JutbFb-8svok6gAAAfQ"] [Tue Aug 18 13:10:05.135114 2026] [security2:error] [pid 167459:tid 167629] [client 20.51.153.15:13374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/uo.php"] [unique_id "aoSD3Wr_JutbFb-8svok7AAAAbc"] [Tue Aug 18 13:10:05.149904 2026] [security2:error] [pid 167459:tid 167639] [client 158.23.17.4:40411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/vg.php"] [unique_id "aoSD3Wr_JutbFb-8svok7gAAAcE"] [Tue Aug 18 13:10:05.161682 2026] [security2:error] [pid 167459:tid 167678] [client 49.145.211.146:9977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svok7wAAAeg"] [Tue Aug 18 13:10:05.161785 2026] [security2:error] [pid 167459:tid 167678] [client 49.145.211.146:9977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svok7wAAAeg"] [Tue Aug 18 13:10:05.246926 2026] [authz_core:error] [pid 167459:tid 167573] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:05.247326 2026] [authz_core:error] [pid 167459:tid 167573] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:05.258407 2026] [security2:error] [pid 167459:tid 167646] [client 20.102.65.165:8564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/chosen.php"] [unique_id "aoSD3Wr_JutbFb-8svok8gAAAcg"] [Tue Aug 18 13:10:05.268792 2026] [security2:error] [pid 167459:tid 167686] [client 20.171.51.14:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/wp-key.php"] [unique_id "aoSD3Wr_JutbFb-8svok8wAAAfA"] [Tue Aug 18 13:10:05.348796 2026] [security2:error] [pid 167459:tid 167632] [client 168.62.48.100:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/rymmm.php"] [unique_id "aoSD3Wr_JutbFb-8svok9wAAAbo"] [Tue Aug 18 13:10:05.404512 2026] [security2:error] [pid 167459:tid 167684] [client 20.91.215.254:12811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-configs.php"] [unique_id "aoSD3Wr_JutbFb-8svok-AAAAe4"] [Tue Aug 18 13:10:05.502785 2026] [security2:error] [pid 167459:tid 167683] [client 20.116.17.175:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/maint/max.php"] [unique_id "aoSD3Wr_JutbFb-8svok_gAAAe0"] [Tue Aug 18 13:10:05.526888 2026] [security2:error] [pid 167459:tid 167630] [client 20.51.153.15:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kx.php"] [unique_id "aoSD3Wr_JutbFb-8svolBQAAAbg"] [Tue Aug 18 13:10:05.533204 2026] [security2:error] [pid 167459:tid 167665] [client 52.139.47.57:9890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/index/function.php"] [unique_id "aoSD3Wr_JutbFb-8svolBgAAAds"] [Tue Aug 18 13:10:05.547251 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:05.547521 2026] [authz_core:error] [pid 167459:tid 167461] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:05.562154 2026] [security2:error] [pid 167459:tid 167682] [client 20.102.65.165:8544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/wpxml.php"] [unique_id "aoSD3Wr_JutbFb-8svolCwAAAew"] [Tue Aug 18 13:10:05.586183 2026] [security2:error] [pid 167459:tid 167650] [client 45.131.193.49:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrassis.com.br"] [uri "/wp-login.php"] [unique_id "aoSD3Wr_JutbFb-8svok-QAAAcw"] [Tue Aug 18 13:10:05.614139 2026] [security2:error] [pid 167459:tid 167661] [client 20.215.241.237:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/nope.php"] [unique_id "aoSD3Wr_JutbFb-8svolEAAAAdc"] [Tue Aug 18 13:10:05.616054 2026] [security2:error] [pid 167459:tid 167635] [client 4.232.151.198:47313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/themes.php"] [unique_id "aoSD3Wr_JutbFb-8svolEQAAAb0"] [Tue Aug 18 13:10:05.642130 2026] [security2:error] [pid 167459:tid 167711] [client 74.249.206.207:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD3Wr_JutbFb-8svolFAAAAgk"] [Tue Aug 18 13:10:05.669493 2026] [security2:error] [pid 167459:tid 167611] [client 94.229.214.255:51268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD3Gr_JutbFb-8svok1wAAAaU"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:05.670161 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:62242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svolFQAAAZw"] [Tue Aug 18 13:10:05.670284 2026] [security2:error] [pid 167459:tid 167602] [client 49.37.150.8:62242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3Wr_JutbFb-8svolFQAAAZw"] [Tue Aug 18 13:10:05.725145 2026] [security2:error] [pid 167459:tid 167707] [client 74.248.18.37:35124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp.php"] [unique_id "aoSD3Wr_JutbFb-8svolIgAAAgU"] [Tue Aug 18 13:10:05.756248 2026] [security2:error] [pid 167459:tid 167692] [client 213.35.127.232:51957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD3Wr_JutbFb-8svolJwAAAfY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:05.826909 2026] [security2:error] [pid 167459:tid 167706] [client 20.51.153.15:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/va.php"] [unique_id "aoSD3Wr_JutbFb-8svolLAAAAgQ"] [Tue Aug 18 13:10:05.837530 2026] [security2:error] [pid 167459:tid 167608] [client 40.74.65.169:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/first.php"] [unique_id "aoSD3Wr_JutbFb-8svolLQAAAaI"] [Tue Aug 18 13:10:05.848942 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:05.849272 2026] [authz_core:error] [pid 167459:tid 167531] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:05.893110 2026] [security2:error] [pid 167459:tid 167626] [client 20.102.65.165:8550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/file1221.php"] [unique_id "aoSD3Wr_JutbFb-8svolMQAAAbQ"] [Tue Aug 18 13:10:05.893115 2026] [security2:error] [pid 167459:tid 167651] [client 158.23.17.4:7337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/mq.php"] [unique_id "aoSD3Wr_JutbFb-8svolMAAAAc0"] [Tue Aug 18 13:10:05.947768 2026] [security2:error] [pid 167459:tid 167589] [client 52.139.47.57:35327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/info.php"] [unique_id "aoSD3Wr_JutbFb-8svolMwAAAY8"] [Tue Aug 18 13:10:05.970193 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:39543] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/1.php"] [unique_id "aoSD3Wr_JutbFb-8svolNgAAAbY"] [Tue Aug 18 13:10:05.970297 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:39543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/1.php"] [unique_id "aoSD3Wr_JutbFb-8svolNgAAAbY"] [Tue Aug 18 13:10:05.986076 2026] [security2:error] [pid 167459:tid 167640] [client 20.116.17.175:45363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/7.php"] [unique_id "aoSD3Wr_JutbFb-8svolNwAAAcI"] [Tue Aug 18 13:10:06.005056 2026] [security2:error] [pid 167459:tid 167714] [client 47.128.19.114:53814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mabelini.com.br"] [uri "/robots.txt"] [unique_id "aoSD3mr_JutbFb-8svolOAAAAgw"] [Tue Aug 18 13:10:06.026408 2026] [security2:error] [pid 167459:tid 167663] [client 74.248.18.37:26241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/simple.php"] [unique_id "aoSD3mr_JutbFb-8svolOQAAAdk"] [Tue Aug 18 13:10:06.079342 2026] [security2:error] [pid 167459:tid 167624] [client 20.91.215.254:12835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-post.php"] [unique_id "aoSD3mr_JutbFb-8svolPAAAAbI"] [Tue Aug 18 13:10:06.120558 2026] [security2:error] [pid 167459:tid 167600] [client 20.51.153.15:13416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fo.php"] [unique_id "aoSD3mr_JutbFb-8svolPwAAAZo"] [Tue Aug 18 13:10:06.149107 2026] [authz_core:error] [pid 167459:tid 167497] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:06.149381 2026] [authz_core:error] [pid 167459:tid 167497] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:06.157797 2026] [security2:error] [pid 167459:tid 167468] [remote 199.193.138.200:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.138.193.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandaoesa.com"] [uri "/wp-login.php"] [unique_id "aoSD3mr_JutbFb-8svolQwAB_Ag"] [Tue Aug 18 13:10:06.183924 2026] [security2:error] [pid 167459:tid 167618] [client 20.215.241.237:30432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/new.php"] [unique_id "aoSD3mr_JutbFb-8svolRwAAAaw"] [Tue Aug 18 13:10:06.191175 2026] [security2:error] [pid 167459:tid 167620] [client 20.102.65.165:8462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/nox.php"] [unique_id "aoSD3mr_JutbFb-8svolSAAAAa4"] [Tue Aug 18 13:10:06.301830 2026] [security2:error] [pid 167459:tid 167534] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolTAAB8Uo"] [Tue Aug 18 13:10:06.302080 2026] [security2:error] [pid 167459:tid 167687] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolTAAB8Uo"] [Tue Aug 18 13:10:06.323547 2026] [security2:error] [pid 167459:tid 167649] [client 213.202.253.4:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/memberfuns.php"] [unique_id "aoSD3mr_JutbFb-8svolTQAAAcs"], referer: www.google.com [Tue Aug 18 13:10:06.362588 2026] [security2:error] [pid 167459:tid 167671] [client 20.118.172.148:60431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD3mr_JutbFb-8svolUAAAAeE"] [Tue Aug 18 13:10:06.368075 2026] [security2:error] [pid 167459:tid 167625] [client 74.249.206.207:47742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSD3mr_JutbFb-8svolUQAAAbM"] [Tue Aug 18 13:10:06.373257 2026] [security2:error] [pid 167459:tid 167630] [client 20.51.153.15:13328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/loading.php"] [unique_id "aoSD3mr_JutbFb-8svolUgAAAbg"] [Tue Aug 18 13:10:06.405543 2026] [security2:error] [pid 167459:tid 167606] [client 52.139.47.57:13719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/install.php"] [unique_id "aoSD3mr_JutbFb-8svolUwAAAaA"] [Tue Aug 18 13:10:06.416982 2026] [security2:error] [pid 167459:tid 167616] [client 74.248.133.44:46633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "aoSD3mr_JutbFb-8svolVAAAAao"] [Tue Aug 18 13:10:06.449311 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:06.449584 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:06.520680 2026] [security2:error] [pid 167459:tid 167602] [client 20.102.65.165:8524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/akismet.php"] [unique_id "aoSD3mr_JutbFb-8svolWAAAAZw"] [Tue Aug 18 13:10:06.566411 2026] [security2:error] [pid 167459:tid 167643] [client 86.120.159.145:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolWQAAAcU"] [Tue Aug 18 13:10:06.566518 2026] [security2:error] [pid 167459:tid 167643] [client 86.120.159.145:62126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolWQAAAcU"] [Tue Aug 18 13:10:06.575825 2026] [security2:error] [pid 167459:tid 167597] [client 68.221.73.131:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/aa.php"] [unique_id "aoSD3mr_JutbFb-8svolWgAAAZc"] [Tue Aug 18 13:10:06.636974 2026] [security2:error] [pid 167459:tid 167692] [client 20.51.153.15:13329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ke.php"] [unique_id "aoSD3mr_JutbFb-8svolXQAAAfY"] [Tue Aug 18 13:10:06.664234 2026] [security2:error] [pid 167459:tid 167681] [client 20.215.241.237:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/new.php"] [unique_id "aoSD3mr_JutbFb-8svolYAAAAes"] [Tue Aug 18 13:10:06.688256 2026] [security2:error] [pid 167459:tid 167703] [client 20.118.172.148:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD3mr_JutbFb-8svolYwAAAgE"] [Tue Aug 18 13:10:06.707865 2026] [security2:error] [pid 167459:tid 167605] [client 20.116.17.175:45413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ws77.php"] [unique_id "aoSD3mr_JutbFb-8svolZQAAAZ8"] [Tue Aug 18 13:10:06.720180 2026] [security2:error] [pid 167459:tid 167651] [client 40.74.65.169:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wpupex.php"] [unique_id "aoSD3mr_JutbFb-8svolawAAAc0"] [Tue Aug 18 13:10:06.723510 2026] [security2:error] [pid 167459:tid 167599] [client 20.91.215.254:12813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp/images/my.php"] [unique_id "aoSD3mr_JutbFb-8svolbAAAAZk"] [Tue Aug 18 13:10:06.766576 2026] [security2:error] [pid 167459:tid 167683] [client 114.5.214.109:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolbgAAAe0"] [Tue Aug 18 13:10:06.766684 2026] [security2:error] [pid 167459:tid 167683] [client 114.5.214.109:50426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD3mr_JutbFb-8svolbgAAAe0"] [Tue Aug 18 13:10:06.769680 2026] [security2:error] [pid 167459:tid 167592] [client 74.248.18.37:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/155.php"] [unique_id "aoSD3mr_JutbFb-8svolbwAAAZI"] [Tue Aug 18 13:10:06.776067 2026] [security2:error] [pid 167459:tid 167710] [client 213.35.127.232:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD3mr_JutbFb-8svolcAAAAgg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:06.810786 2026] [security2:error] [pid 167459:tid 167661] [client 74.248.18.37:30526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/edit-tags.php"] [unique_id "aoSD3mr_JutbFb-8svolcgAAAdc"] [Tue Aug 18 13:10:06.841610 2026] [security2:error] [pid 167459:tid 167656] [client 52.139.47.57:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/item.php"] [unique_id "aoSD3mr_JutbFb-8svolcwAAAdI"] [Tue Aug 18 13:10:06.878898 2026] [security2:error] [pid 167459:tid 167612] [client 20.51.153.15:13357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nh.php"] [unique_id "aoSD3mr_JutbFb-8svoldQAAAaY"] [Tue Aug 18 13:10:06.919984 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.49.167:51983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/rezor.php"] [unique_id "aoSD3mr_JutbFb-8svoleAAAAfw"] [Tue Aug 18 13:10:06.950052 2026] [security2:error] [pid 167459:tid 167620] [client 20.102.65.165:8472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/admin.php"] [unique_id "aoSD3mr_JutbFb-8svolewAAAa4"] [Tue Aug 18 13:10:07.036661 2026] [security2:error] [pid 167459:tid 167666] [client 20.118.172.148:56971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/admin.php"] [unique_id "aoSD32r_JutbFb-8svolfgAAAdw"] [Tue Aug 18 13:10:07.069010 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:07.069302 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:07.152273 2026] [security2:error] [pid 167459:tid 167649] [client 20.51.153.15:13343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/oo.php"] [unique_id "aoSD32r_JutbFb-8svolggAAAcs"] [Tue Aug 18 13:10:07.214104 2026] [security2:error] [pid 167459:tid 167606] [client 20.215.241.237:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/apreset.php"] [unique_id "aoSD32r_JutbFb-8svolhgAAAaA"] [Tue Aug 18 13:10:07.233700 2026] [security2:error] [pid 167459:tid 167709] [client 158.23.17.4:48402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/sm.php"] [unique_id "aoSD32r_JutbFb-8svolhwAAAgc"] [Tue Aug 18 13:10:07.257077 2026] [security2:error] [pid 167459:tid 167636] [client 52.139.47.57:13717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/kir.php"] [unique_id "aoSD32r_JutbFb-8svoliQAAAb4"] [Tue Aug 18 13:10:07.259404 2026] [security2:error] [pid 167459:tid 167670] [client 20.102.65.165:8469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.65.102.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.automoveismn.com.br"] [uri "/ajax.php"] [unique_id "aoSD32r_JutbFb-8svoligAAAeA"] [Tue Aug 18 13:10:07.368613 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:07.368890 2026] [authz_core:error] [pid 167459:tid 167465] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:07.379590 2026] [security2:error] [pid 167459:tid 167602] [client 74.249.206.207:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/av.php"] [unique_id "aoSD32r_JutbFb-8svoljgAAAZw"] [Tue Aug 18 13:10:07.415754 2026] [security2:error] [pid 167459:tid 167625] [client 20.91.215.254:12994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/function.php"] [unique_id "aoSD32r_JutbFb-8svoljwAAAbM"] [Tue Aug 18 13:10:07.427568 2026] [security2:error] [pid 167459:tid 167597] [client 20.118.172.148:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/edit.php"] [unique_id "aoSD32r_JutbFb-8svolkAAAAZc"] [Tue Aug 18 13:10:07.431917 2026] [security2:error] [pid 167459:tid 167631] [client 20.51.153.15:13331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ja.php"] [unique_id "aoSD32r_JutbFb-8svolkgAAAbk"] [Tue Aug 18 13:10:07.466887 2026] [security2:error] [pid 167459:tid 167697] [client 74.248.133.44:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/aaa.php"] [unique_id "aoSD32r_JutbFb-8svollAAAAfs"] [Tue Aug 18 13:10:07.557104 2026] [security2:error] [pid 167459:tid 167599] [client 114.119.150.41:23631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shamardedetizadora.com.br"] [uri "/2018/12/22/"] [unique_id "aoSD32r_JutbFb-8svolmwAAAZk"], referer: http://shamardedetizadora.com.br/2018/12/18 [Tue Aug 18 13:10:07.627212 2026] [security2:error] [pid 167459:tid 167683] [client 40.74.65.169:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/bibil.php"] [unique_id "aoSD32r_JutbFb-8svolngAAAe0"] [Tue Aug 18 13:10:07.697142 2026] [security2:error] [pid 167459:tid 167682] [client 18.192.166.72:9108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "qriar.com"] [uri "/index.php"] [unique_id "aoSD32r_JutbFb-8svolkwAAAew"], referer: https://qriar.com/ [Tue Aug 18 13:10:07.698919 2026] [security2:error] [pid 167459:tid 167715] [client 20.51.153.15:13336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xx.php"] [unique_id "aoSD32r_JutbFb-8svologAAAg0"] [Tue Aug 18 13:10:07.724343 2026] [security2:error] [pid 167459:tid 167694] [client 20.116.17.175:45405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/read.php"] [unique_id "aoSD32r_JutbFb-8svolpAAAAfg"] [Tue Aug 18 13:10:07.758785 2026] [security2:error] [pid 167459:tid 167647] [client 5.31.227.224:30420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.227.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD32r_JutbFb-8svolpwAAAck"] [Tue Aug 18 13:10:07.766024 2026] [security2:error] [pid 167459:tid 167647] [client 5.31.227.224:30420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bravossgi.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD32r_JutbFb-8svolpwAAAck"] [Tue Aug 18 13:10:07.769091 2026] [authz_core:error] [pid 167459:tid 167512] [remote 57.141.22.50:29414] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:07.769526 2026] [authz_core:error] [pid 167459:tid 167512] [remote 57.141.22.50:29414] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:07.784931 2026] [security2:error] [pid 167459:tid 167655] [client 20.215.241.237:46380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/1mage.php"] [unique_id "aoSD32r_JutbFb-8svolqgAAAdE"] [Tue Aug 18 13:10:07.786343 2026] [security2:error] [pid 167459:tid 167675] [client 213.35.127.232:52377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD32r_JutbFb-8svolqwAAAeU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:07.794871 2026] [security2:error] [pid 167459:tid 167499] [remote 162.214.184.71:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.184.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mudancassilvano.com.br"] [uri "/wp-login.php"] [unique_id "aoSD32r_JutbFb-8svolrAABmic"] [Tue Aug 18 13:10:07.806919 2026] [security2:error] [pid 167459:tid 167646] [client 20.118.172.148:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/w.php"] [unique_id "aoSD32r_JutbFb-8svolrgAAAcg"] [Tue Aug 18 13:10:07.817991 2026] [security2:error] [pid 167459:tid 167698] [client 52.139.47.57:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/log.php"] [unique_id "aoSD32r_JutbFb-8svolrwAAAfw"] [Tue Aug 18 13:10:07.885261 2026] [security2:error] [pid 167459:tid 167667] [client 74.248.18.37:24900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/u.php"] [unique_id "aoSD32r_JutbFb-8svolsQAAAd0"] [Tue Aug 18 13:10:07.932527 2026] [security2:error] [pid 167459:tid 167658] [client 47.128.48.60:22156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gruponovaeuro.com.br"] [uri "/robots.txt"] [unique_id "aoSD32r_JutbFb-8svoltAAAAdQ"] [Tue Aug 18 13:10:07.981320 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:07.981581 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:07.981871 2026] [security2:error] [pid 167459:tid 167712] [client 20.51.153.15:13320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/conn-test.php"] [unique_id "aoSD32r_JutbFb-8svoluAAAAgo"] [Tue Aug 18 13:10:08.047162 2026] [security2:error] [pid 167459:tid 167695] [client 20.91.215.254:13016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-2019.php"] [unique_id "aoSD4Gr_JutbFb-8svoluwAAAfk"] [Tue Aug 18 13:10:08.074350 2026] [security2:error] [pid 167459:tid 167713] [client 74.248.18.37:9406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/96i.php"] [unique_id "aoSD4Gr_JutbFb-8svolvAAAAgs"] [Tue Aug 18 13:10:08.107958 2026] [security2:error] [pid 167459:tid 167687] [client 20.171.51.14:31061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/gg.php"] [unique_id "aoSD4Gr_JutbFb-8svolvgAAAfE"] [Tue Aug 18 13:10:08.176630 2026] [security2:error] [pid 167459:tid 167630] [client 20.118.172.148:57473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/file.php"] [unique_id "aoSD4Gr_JutbFb-8svolwAAAAbg"] [Tue Aug 18 13:10:08.234809 2026] [security2:error] [pid 167459:tid 167714] [client 20.51.153.15:13364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fg.php"] [unique_id "aoSD4Gr_JutbFb-8svolwgAAAgw"] [Tue Aug 18 13:10:08.236252 2026] [security2:error] [pid 167459:tid 167634] [client 52.139.47.57:18552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/logins.php"] [unique_id "aoSD4Gr_JutbFb-8svolwwAAAbw"] [Tue Aug 18 13:10:08.257845 2026] [security2:error] [pid 167459:tid 167692] [client 223.185.37.47:19431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD4Gr_JutbFb-8svolxQAAAfY"] [Tue Aug 18 13:10:08.261775 2026] [security2:error] [pid 167459:tid 167692] [client 223.185.37.47:19431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD4Gr_JutbFb-8svolxQAAAfY"] [Tue Aug 18 13:10:08.277499 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:08.277782 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:08.301862 2026] [security2:error] [pid 167459:tid 167660] [client 20.116.17.175:22759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/albin.php"] [unique_id "aoSD4Gr_JutbFb-8svolxwAAAdY"] [Tue Aug 18 13:10:08.331873 2026] [security2:error] [pid 167459:tid 167609] [client 158.23.17.4:47641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/28.php"] [unique_id "aoSD4Gr_JutbFb-8svolyQAAAaM"] [Tue Aug 18 13:10:08.356769 2026] [security2:error] [pid 167459:tid 167699] [client 20.215.241.237:40525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/imsc.php"] [unique_id "aoSD4Gr_JutbFb-8svolywAAAf0"] [Tue Aug 18 13:10:08.402406 2026] [security2:error] [pid 167459:tid 167691] [client 74.249.206.207:22930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/images.php"] [unique_id "aoSD4Gr_JutbFb-8svolzAAAAfU"] [Tue Aug 18 13:10:08.468708 2026] [security2:error] [pid 167459:tid 167639] [client 20.51.153.15:13323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ve.php"] [unique_id "aoSD4Gr_JutbFb-8svol0AAAAcE"] [Tue Aug 18 13:10:08.486639 2026] [security2:error] [pid 167459:tid 167688] [client 40.74.65.169:5686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/halo.php"] [unique_id "aoSD4Gr_JutbFb-8svol0gAAAfI"] [Tue Aug 18 13:10:08.579169 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:08.579519 2026] [authz_core:error] [pid 167459:tid 167529] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:08.621956 2026] [security2:error] [pid 167459:tid 167690] [client 20.118.172.148:60429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSD4Gr_JutbFb-8svol1gAAAfQ"] [Tue Aug 18 13:10:08.669517 2026] [security2:error] [pid 167459:tid 167641] [client 52.139.47.57:18505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/mailer.php"] [unique_id "aoSD4Gr_JutbFb-8svol2AAAAcM"] [Tue Aug 18 13:10:08.746870 2026] [security2:error] [pid 167459:tid 167661] [client 20.51.153.15:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ia.php"] [unique_id "aoSD4Gr_JutbFb-8svol2gAAAdc"] [Tue Aug 18 13:10:08.755610 2026] [security2:error] [pid 167459:tid 167598] [client 20.91.215.254:12729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cjfuns.php"] [unique_id "aoSD4Gr_JutbFb-8svol2wAAAZg"] [Tue Aug 18 13:10:08.777657 2026] [security2:error] [pid 167459:tid 167715] [client 20.116.17.175:22672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/fw/34.php"] [unique_id "aoSD4Gr_JutbFb-8svol3AAAAg0"] [Tue Aug 18 13:10:08.800673 2026] [security2:error] [pid 167459:tid 167708] [client 213.35.127.232:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD4Gr_JutbFb-8svol3QAAAgY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:08.850550 2026] [security2:error] [pid 167459:tid 167615] [client 20.215.241.237:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/imscjpg.php"] [unique_id "aoSD4Gr_JutbFb-8svol4AAAAak"] [Tue Aug 18 13:10:08.878034 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:08.878298 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:08.969023 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.18.37:29976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/as.php"] [unique_id "aoSD4Gr_JutbFb-8svol4wAAAdI"] [Tue Aug 18 13:10:08.981157 2026] [security2:error] [pid 167459:tid 167698] [client 40.74.65.169:52323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD4Gr_JutbFb-8svol5AAAAfw"] [Tue Aug 18 13:10:08.991493 2026] [security2:error] [pid 167459:tid 167618] [client 20.104.49.167:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/3p8jj8r.php"] [unique_id "aoSD4Gr_JutbFb-8svol5gAAAaw"] [Tue Aug 18 13:10:09.003648 2026] [security2:error] [pid 167459:tid 167620] [client 20.118.172.148:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/aa.php"] [unique_id "aoSD4Wr_JutbFb-8svol5wAAAa4"] [Tue Aug 18 13:10:09.086435 2026] [security2:error] [pid 167459:tid 167675] [client 52.139.47.57:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/min.php"] [unique_id "aoSD4Wr_JutbFb-8svol6QAAAeU"] [Tue Aug 18 13:10:09.098705 2026] [security2:error] [pid 167459:tid 167651] [client 74.248.133.44:12329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/alfa.php"] [unique_id "aoSD4Wr_JutbFb-8svol6gAAAc0"] [Tue Aug 18 13:10:09.133551 2026] [security2:error] [pid 167459:tid 167619] [client 158.23.17.4:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/m.php"] [unique_id "aoSD4Wr_JutbFb-8svol6wAAAa0"] [Tue Aug 18 13:10:09.163133 2026] [security2:error] [pid 167459:tid 167653] [client 20.116.17.175:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp9.php"] [unique_id "aoSD4Wr_JutbFb-8svol7gAAAc8"] [Tue Aug 18 13:10:09.255004 2026] [security2:error] [pid 167459:tid 167676] [client 20.51.153.15:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kn.php"] [unique_id "aoSD4Wr_JutbFb-8svol8wAAAeY"] [Tue Aug 18 13:10:09.329077 2026] [security2:error] [pid 167459:tid 167700] [client 149.34.210.141:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD4Wr_JutbFb-8svol9QAAAf4"] [Tue Aug 18 13:10:09.403431 2026] [security2:error] [pid 167459:tid 167714] [client 20.118.172.148:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD4Wr_JutbFb-8svol-gAAAgw"] [Tue Aug 18 13:10:09.405489 2026] [security2:error] [pid 167459:tid 167634] [client 74.249.206.207:40143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/ops.php"] [unique_id "aoSD4Wr_JutbFb-8svol-wAAAbw"] [Tue Aug 18 13:10:09.423539 2026] [security2:error] [pid 167459:tid 167628] [client 20.215.241.237:29140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/qlex1.php"] [unique_id "aoSD4Wr_JutbFb-8svol_AAAAbY"] [Tue Aug 18 13:10:09.427641 2026] [security2:error] [pid 167459:tid 167684] [client 20.91.215.254:12804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSD4Wr_JutbFb-8svol_QAAAe4"] [Tue Aug 18 13:10:09.481715 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:09.482006 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:09.526186 2026] [security2:error] [pid 167459:tid 167664] [client 20.51.153.15:13413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wm.php"] [unique_id "aoSD4Wr_JutbFb-8svomAgAAAdo"] [Tue Aug 18 13:10:09.569816 2026] [security2:error] [pid 167459:tid 167645] [client 45.92.229.86:50139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.229.92.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSD4Wr_JutbFb-8svol-QAAAcc"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:10:09.592836 2026] [security2:error] [pid 167459:tid 167700] [client 149.34.210.141:60383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD4Wr_JutbFb-8svol9QAAAf4"] [Tue Aug 18 13:10:09.649161 2026] [security2:error] [pid 167459:tid 167613] [client 52.139.47.57:18514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/mini.php"] [unique_id "aoSD4Wr_JutbFb-8svomAwAAAac"] [Tue Aug 18 13:10:09.657509 2026] [security2:error] [pid 167459:tid 167597] [client 40.74.65.169:5654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/ajq1s.php"] [unique_id "aoSD4Wr_JutbFb-8svomBAAAAZc"] [Tue Aug 18 13:10:09.743398 2026] [authz_core:error] [pid 167459:tid 167498] [remote 57.141.22.119:49108] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:09.743668 2026] [authz_core:error] [pid 167459:tid 167498] [remote 57.141.22.119:49108] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:09.746413 2026] [security2:error] [pid 167459:tid 167603] [client 40.74.65.169:25469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD4Wr_JutbFb-8svomBwAAAZ0"] [Tue Aug 18 13:10:09.780081 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:09.780344 2026] [authz_core:error] [pid 167459:tid 167532] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:09.817361 2026] [security2:error] [pid 167459:tid 167599] [client 20.51.153.15:13318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ac.php"] [unique_id "aoSD4Wr_JutbFb-8svomCgAAAZk"] [Tue Aug 18 13:10:09.821600 2026] [security2:error] [pid 167459:tid 167692] [client 213.35.127.232:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD4Wr_JutbFb-8svomCwAAAfY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:09.828387 2026] [security2:error] [pid 167459:tid 167683] [client 20.116.17.175:22685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/save.php"] [unique_id "aoSD4Wr_JutbFb-8svomDAAAAe0"] [Tue Aug 18 13:10:09.859669 2026] [security2:error] [pid 167459:tid 167617] [client 20.116.17.175:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/99.php"] [unique_id "aoSD4Wr_JutbFb-8svomEAAAAas"] [Tue Aug 18 13:10:09.866634 2026] [autoindex:error] [pid 167459:tid 167641] [client 198.235.24.226:60602] AH01276: Cannot serve directory /home2/netfactory/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:09.867882 2026] [autoindex:error] [pid 167459:tid 167640] [client 198.235.24.226:60618] AH01276: Cannot serve directory /home4/fabio468/fabioweb-clientes.fabioweb.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:09.872473 2026] [security2:error] [pid 167459:tid 167598] [client 20.104.49.167:58669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/dapa.php"] [unique_id "aoSD4Wr_JutbFb-8svomEgAAAZg"] [Tue Aug 18 13:10:09.879976 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD4Wr_JutbFb-8svomEwAAAeg"] [Tue Aug 18 13:10:09.881303 2026] [security2:error] [pid 167459:tid 167715] [client 20.215.241.237:55203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/mariju.php"] [unique_id "aoSD4Wr_JutbFb-8svomFAAAAg0"] [Tue Aug 18 13:10:09.887803 2026] [security2:error] [pid 167459:tid 167694] [client 20.118.172.148:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/about.php"] [unique_id "aoSD4Wr_JutbFb-8svomFQAAAfg"] [Tue Aug 18 13:10:10.064544 2026] [security2:error] [pid 167459:tid 167625] [client 52.139.47.57:9900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/moddofuns.php"] [unique_id "aoSD4mr_JutbFb-8svomHAAAAbM"] [Tue Aug 18 13:10:10.064675 2026] [security2:error] [pid 167459:tid 167618] [client 20.51.153.15:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/yz.php"] [unique_id "aoSD4mr_JutbFb-8svomHQAAAaw"] [Tue Aug 18 13:10:10.088827 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:10.089097 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:10.101739 2026] [security2:error] [pid 167459:tid 167671] [client 4.232.151.198:46160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/cv.php"] [unique_id "aoSD4mr_JutbFb-8svomIAAAAeE"] [Tue Aug 18 13:10:10.112369 2026] [security2:error] [pid 167459:tid 167663] [client 20.91.215.254:12839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSD4mr_JutbFb-8svomIgAAAdk"] [Tue Aug 18 13:10:10.160728 2026] [security2:error] [pid 167459:tid 167662] [client 158.23.17.4:48415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/nl.php"] [unique_id "aoSD4mr_JutbFb-8svomJQAAAdg"] [Tue Aug 18 13:10:10.164312 2026] [security2:error] [pid 167459:tid 167614] [client 20.250.13.23:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/alfa.php"] [unique_id "aoSD4mr_JutbFb-8svomJgAAAag"] [Tue Aug 18 13:10:10.184499 2026] [security2:error] [pid 167459:tid 167608] [client 74.248.18.37:14434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSD4mr_JutbFb-8svomJwAAAaI"] [Tue Aug 18 13:10:10.290769 2026] [security2:error] [pid 167459:tid 167632] [client 20.118.172.148:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/goods.php"] [unique_id "aoSD4mr_JutbFb-8svomKwAAAbo"] [Tue Aug 18 13:10:10.333444 2026] [security2:error] [pid 167459:tid 167652] [client 20.51.153.15:13335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kj.php"] [unique_id "aoSD4mr_JutbFb-8svomLAAAAc4"] [Tue Aug 18 13:10:10.379863 2026] [security2:error] [pid 167459:tid 167634] [client 20.104.49.167:16115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/Ipv6.php"] [unique_id "aoSD4mr_JutbFb-8svomLgAAAbw"] [Tue Aug 18 13:10:10.385067 2026] [authz_core:error] [pid 167459:tid 167480] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:10.385353 2026] [authz_core:error] [pid 167459:tid 167480] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:10.415244 2026] [security2:error] [pid 167459:tid 167593] [client 158.23.17.4:10945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD4mr_JutbFb-8svomMAAAAZM"] [Tue Aug 18 13:10:10.415868 2026] [security2:error] [pid 167459:tid 167657] [client 74.248.133.44:21134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "aoSD4mr_JutbFb-8svomMQAAAdM"] [Tue Aug 18 13:10:10.435541 2026] [security2:error] [pid 167459:tid 167595] [client 40.74.65.169:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/domvf.php"] [unique_id "aoSD4mr_JutbFb-8svomMwAAAZU"] [Tue Aug 18 13:10:10.503114 2026] [security2:error] [pid 167459:tid 167670] [client 40.74.65.169:5538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/spip.php"] [unique_id "aoSD4mr_JutbFb-8svomOgAAAeA"] [Tue Aug 18 13:10:10.544822 2026] [security2:error] [pid 167459:tid 167656] [client 74.248.18.37:30010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/min.php"] [unique_id "aoSD4mr_JutbFb-8svomPAAAAdI"] [Tue Aug 18 13:10:10.553874 2026] [security2:error] [pid 167459:tid 167666] [client 20.116.17.175:22722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-rrtx.php"] [unique_id "aoSD4mr_JutbFb-8svomPQAAAdw"] [Tue Aug 18 13:10:10.555284 2026] [security2:error] [pid 167459:tid 167684] [client 52.139.47.57:9917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/modules/hrm/assets/plugins/db-status.php"] [unique_id "aoSD4mr_JutbFb-8svomPgAAAe4"] [Tue Aug 18 13:10:10.570986 2026] [security2:error] [pid 167459:tid 167591] [client 20.51.153.15:13356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vg.php"] [unique_id "aoSD4mr_JutbFb-8svomQgAAAZE"] [Tue Aug 18 13:10:10.687228 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:10.687542 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:10.703646 2026] [security2:error] [pid 167459:tid 167677] [client 20.215.241.237:59724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSD4mr_JutbFb-8svomTAAAAec"] [Tue Aug 18 13:10:10.791000 2026] [security2:error] [pid 167459:tid 167690] [client 20.118.172.148:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/php8.php"] [unique_id "aoSD4mr_JutbFb-8svomVQAAAfQ"] [Tue Aug 18 13:10:10.793669 2026] [security2:error] [pid 167459:tid 167631] [client 20.91.215.254:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/import.php"] [unique_id "aoSD4mr_JutbFb-8svomVgAAAbk"] [Tue Aug 18 13:10:10.794987 2026] [security2:error] [pid 167459:tid 167658] [client 158.23.17.4:38887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/st.php"] [unique_id "aoSD4mr_JutbFb-8svomVwAAAdQ"] [Tue Aug 18 13:10:10.836120 2026] [security2:error] [pid 167459:tid 167711] [client 213.35.127.232:53009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD4mr_JutbFb-8svomWAAAAgk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:10.851857 2026] [security2:error] [pid 167459:tid 167715] [client 20.51.153.15:13373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sm.php"] [unique_id "aoSD4mr_JutbFb-8svomWQAAAg0"] [Tue Aug 18 13:10:10.919920 2026] [security2:error] [pid 167459:tid 167673] [client 74.249.206.207:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/coffexium.php"] [unique_id "aoSD4mr_JutbFb-8svomWwAAAeM"] [Tue Aug 18 13:10:10.974869 2026] [security2:error] [pid 167459:tid 167598] [client 52.139.47.57:9862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/moduless.php"] [unique_id "aoSD4mr_JutbFb-8svomYwAAAZg"] [Tue Aug 18 13:10:10.998239 2026] [security2:error] [pid 167459:tid 167639] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD4mr_JutbFb-8svomXAABwS8"] [Tue Aug 18 13:10:11.012911 2026] [security2:error] [pid 167459:tid 167621] [client 157.20.138.62:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD42r_JutbFb-8svomaAAAAa8"] [Tue Aug 18 13:10:11.012999 2026] [security2:error] [pid 167459:tid 167621] [client 157.20.138.62:63522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD42r_JutbFb-8svomaAAAAa8"] [Tue Aug 18 13:10:11.024451 2026] [security2:error] [pid 167459:tid 167628] [client 178.153.171.161:20264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD42r_JutbFb-8svomaQAAAbY"] [Tue Aug 18 13:10:11.024621 2026] [security2:error] [pid 167459:tid 167628] [client 178.153.171.161:20264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD42r_JutbFb-8svomaQAAAbY"] [Tue Aug 18 13:10:11.082479 2026] [security2:error] [pid 167459:tid 167653] [client 20.104.49.167:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/first.php"] [unique_id "aoSD42r_JutbFb-8svomagAAAc8"] [Tue Aug 18 13:10:11.121545 2026] [security2:error] [pid 167459:tid 167712] [client 20.51.153.15:2039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/28.php"] [unique_id "aoSD42r_JutbFb-8svombAAAAgo"] [Tue Aug 18 13:10:11.130768 2026] [security2:error] [pid 167459:tid 167646] [client 158.23.17.4:25361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/68.php"] [unique_id "aoSD42r_JutbFb-8svombQAAAcg"] [Tue Aug 18 13:10:11.142567 2026] [security2:error] [pid 167459:tid 167632] [client 20.116.17.175:22680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/gecko-new.php"] [unique_id "aoSD42r_JutbFb-8svombgAAAbo"] [Tue Aug 18 13:10:11.146994 2026] [security2:error] [pid 167459:tid 167637] [client 40.74.65.169:52345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "aoSD42r_JutbFb-8svombwAAAb8"] [Tue Aug 18 13:10:11.185988 2026] [security2:error] [pid 167459:tid 167652] [client 158.23.17.4:33472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/le.php"] [unique_id "aoSD42r_JutbFb-8svomcgAAAc4"] [Tue Aug 18 13:10:11.197905 2026] [security2:error] [pid 167459:tid 167610] [client 168.62.48.100:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/lddxs.php"] [unique_id "aoSD42r_JutbFb-8svomcwAAAaQ"] [Tue Aug 18 13:10:11.228886 2026] [security2:error] [pid 167459:tid 167630] [client 20.215.241.237:55183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/contacto.php"] [unique_id "aoSD42r_JutbFb-8svomeQAAAbg"] [Tue Aug 18 13:10:11.287917 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:11.288175 2026] [authz_core:error] [pid 167459:tid 167559] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:11.393770 2026] [security2:error] [pid 167459:tid 167714] [client 52.139.47.57:13740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/ms-edit.php"] [unique_id "aoSD42r_JutbFb-8svomewAAAgw"] [Tue Aug 18 13:10:11.441395 2026] [security2:error] [pid 167459:tid 167716] [client 20.51.153.15:13415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/m.php"] [unique_id "aoSD42r_JutbFb-8svomfAAAAg4"] [Tue Aug 18 13:10:11.468480 2026] [security2:error] [pid 167459:tid 167634] [client 20.91.215.254:12827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/cropper.php"] [unique_id "aoSD42r_JutbFb-8svomfQAAAbw"] [Tue Aug 18 13:10:11.558943 2026] [security2:error] [pid 167459:tid 167651] [client 74.248.133.44:21181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/sf.php"] [unique_id "aoSD42r_JutbFb-8svomfwAAAc0"] [Tue Aug 18 13:10:11.587546 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:11.587815 2026] [authz_core:error] [pid 167459:tid 167585] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:11.639440 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/hr.php"] [unique_id "aoSD42r_JutbFb-8svomhAAAAcQ"] [Tue Aug 18 13:10:11.646877 2026] [security2:error] [pid 167459:tid 167713] [client 40.74.65.169:5684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/wpup.php"] [unique_id "aoSD42r_JutbFb-8svomhQAAAgs"] [Tue Aug 18 13:10:11.713798 2026] [security2:error] [pid 167459:tid 167649] [client 4.232.151.198:43466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSD42r_JutbFb-8svomhgAAAcs"] [Tue Aug 18 13:10:11.714123 2026] [security2:error] [pid 167459:tid 167611] [client 20.51.153.15:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nl.php"] [unique_id "aoSD42r_JutbFb-8svomhwAAAaU"] [Tue Aug 18 13:10:11.745666 2026] [security2:error] [pid 167459:tid 167692] [client 20.118.172.148:60451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/info.php"] [unique_id "aoSD42r_JutbFb-8svomiQAAAfY"] [Tue Aug 18 13:10:11.794846 2026] [security2:error] [pid 167459:tid 167631] [client 20.215.241.237:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/image2.php"] [unique_id "aoSD42r_JutbFb-8svomigAAAbk"] [Tue Aug 18 13:10:11.819520 2026] [security2:error] [pid 167459:tid 167607] [client 52.139.47.57:35311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/new.php"] [unique_id "aoSD42r_JutbFb-8svomiwAAAaE"] [Tue Aug 18 13:10:11.830053 2026] [security2:error] [pid 167459:tid 167678] [client 20.116.17.175:22735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/df.php"] [unique_id "aoSD42r_JutbFb-8svomjAAAAeg"] [Tue Aug 18 13:10:11.830516 2026] [security2:error] [pid 167459:tid 167715] [client 40.74.65.169:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/gec.php"] [unique_id "aoSD42r_JutbFb-8svomjQAAAg0"] [Tue Aug 18 13:10:11.849848 2026] [security2:error] [pid 167459:tid 167638] [client 213.35.127.232:53213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD42r_JutbFb-8svomjwAAAcA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:11.881502 2026] [security2:error] [pid 167459:tid 167710] [client 20.104.49.167:10835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/wpupex.php"] [unique_id "aoSD42r_JutbFb-8svomkgAAAgg"] [Tue Aug 18 13:10:11.887247 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:11.887507 2026] [authz_core:error] [pid 167459:tid 167581] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:11.989279 2026] [security2:error] [pid 167459:tid 167635] [client 20.51.153.15:13365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/68.php"] [unique_id "aoSD42r_JutbFb-8svomlgAAAb0"] [Tue Aug 18 13:10:12.005479 2026] [security2:error] [pid 167459:tid 167697] [client 74.248.18.37:26279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/h.php"] [unique_id "aoSD5Gr_JutbFb-8svomlwAAAfs"] [Tue Aug 18 13:10:12.121051 2026] [security2:error] [pid 167459:tid 167706] [client 20.91.215.254:13021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/images/xmrlpc.php"] [unique_id "aoSD5Gr_JutbFb-8svommwAAAgQ"] [Tue Aug 18 13:10:12.186010 2026] [security2:error] [pid 167459:tid 167628] [client 158.23.17.4:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/kt.php"] [unique_id "aoSD5Gr_JutbFb-8svomnQAAAbY"] [Tue Aug 18 13:10:12.190181 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:12.190490 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:12.223603 2026] [security2:error] [pid 167459:tid 167615] [client 20.116.17.175:41511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-includes/Text/Diff/Engine/file_ed27.php"] [unique_id "aoSD5Gr_JutbFb-8svomoAAAAak"] [Tue Aug 18 13:10:12.227534 2026] [security2:error] [pid 167459:tid 167608] [client 20.51.153.15:13363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/jl.php"] [unique_id "aoSD5Gr_JutbFb-8svomoQAAAaI"] [Tue Aug 18 13:10:12.243716 2026] [security2:error] [pid 167459:tid 167609] [client 52.139.47.57:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/node_modules/@babel/preset-modules/lib/plugins/system.php"] [unique_id "aoSD5Gr_JutbFb-8svomogAAAaM"] [Tue Aug 18 13:10:12.341209 2026] [security2:error] [pid 167459:tid 167636] [client 20.118.172.148:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/chosen.php"] [unique_id "aoSD5Gr_JutbFb-8svompQAAAb4"] [Tue Aug 18 13:10:12.354221 2026] [security2:error] [pid 167459:tid 167629] [client 20.250.13.23:47529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/edit.php"] [unique_id "aoSD5Gr_JutbFb-8svompgAAAbc"] [Tue Aug 18 13:10:12.370959 2026] [security2:error] [pid 167459:tid 167646] [client 40.74.65.169:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/myy.php"] [unique_id "aoSD5Gr_JutbFb-8svompwAAAcg"] [Tue Aug 18 13:10:12.395208 2026] [security2:error] [pid 167459:tid 167696] [client 20.215.241.237:59731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/fb.php"] [unique_id "aoSD5Gr_JutbFb-8svomqQAAAfo"] [Tue Aug 18 13:10:12.446948 2026] [security2:error] [pid 167459:tid 167687] [client 74.249.206.207:40135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/BDKR28WP.php"] [unique_id "aoSD5Gr_JutbFb-8svomqgAAAfE"] [Tue Aug 18 13:10:12.491784 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:12.492065 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:12.529805 2026] [security2:error] [pid 167459:tid 167700] [client 40.74.65.169:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/sky.php"] [unique_id "aoSD5Gr_JutbFb-8svomsAAAAf4"] [Tue Aug 18 13:10:12.548377 2026] [security2:error] [pid 167459:tid 167616] [client 20.51.153.15:13437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tq.php"] [unique_id "aoSD5Gr_JutbFb-8svomsgAAAao"] [Tue Aug 18 13:10:12.581254 2026] [security2:error] [pid 167459:tid 167660] [client 158.23.17.4:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ww.php"] [unique_id "aoSD5Gr_JutbFb-8svomtgAAAdY"] [Tue Aug 18 13:10:12.661501 2026] [security2:error] [pid 167459:tid 167657] [client 52.139.47.57:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/num.php"] [unique_id "aoSD5Gr_JutbFb-8svomuwAAAdM"] [Tue Aug 18 13:10:12.686799 2026] [security2:error] [pid 167459:tid 167651] [client 20.116.17.175:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/usr.php"] [unique_id "aoSD5Gr_JutbFb-8svomvQAAAc0"] [Tue Aug 18 13:10:12.793988 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:12.794256 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:12.798100 2026] [security2:error] [pid 167459:tid 167677] [client 20.104.49.167:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/bibil.php"] [unique_id "aoSD5Gr_JutbFb-8svomwQAAAec"] [Tue Aug 18 13:10:12.859306 2026] [security2:error] [pid 167459:tid 167666] [client 20.91.215.254:13033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSD5Gr_JutbFb-8svomwwAAAdw"] [Tue Aug 18 13:10:12.866827 2026] [security2:error] [pid 167459:tid 167595] [client 213.35.127.232:53419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD5Gr_JutbFb-8svomxAAAAZU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:12.896202 2026] [security2:error] [pid 167459:tid 167611] [client 20.51.153.15:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/cv.php"] [unique_id "aoSD5Gr_JutbFb-8svomxgAAAaU"] [Tue Aug 18 13:10:12.902696 2026] [security2:error] [pid 167459:tid 167631] [client 20.171.51.14:19846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/gi.php"] [unique_id "aoSD5Gr_JutbFb-8svomxwAAAbk"] [Tue Aug 18 13:10:12.961781 2026] [security2:error] [pid 167459:tid 167705] [client 20.118.172.148:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/simple.php"] [unique_id "aoSD5Gr_JutbFb-8svomyQAAAgM"] [Tue Aug 18 13:10:12.979273 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/mo.php"] [unique_id "aoSD5Gr_JutbFb-8svomygAAAeg"] [Tue Aug 18 13:10:13.010890 2026] [security2:error] [pid 167459:tid 167626] [client 20.215.241.237:2997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/gi.php"] [unique_id "aoSD5Wr_JutbFb-8svomywAAAbQ"] [Tue Aug 18 13:10:13.022300 2026] [security2:error] [pid 167459:tid 167594] [client 213.202.253.4:63760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/memberfuns.php"] [unique_id "aoSD5Wr_JutbFb-8svomzQAAAZQ"], referer: www.google.com [Tue Aug 18 13:10:13.034295 2026] [security2:error] [pid 167459:tid 167652] [client 74.248.133.44:30679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/file56.php"] [unique_id "aoSD5Wr_JutbFb-8svomzgAAAc4"] [Tue Aug 18 13:10:13.087842 2026] [security2:error] [pid 167459:tid 167644] [client 52.139.47.57:18524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/php.php"] [unique_id "aoSD5Wr_JutbFb-8svom0QAAAcY"] [Tue Aug 18 13:10:13.092981 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:13.093246 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:13.181643 2026] [security2:error] [pid 167459:tid 167624] [client 20.51.153.15:13315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/un.php"] [unique_id "aoSD5Wr_JutbFb-8svom2AAAAbI"] [Tue Aug 18 13:10:13.187874 2026] [security2:error] [pid 167459:tid 167635] [client 40.74.65.169:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/geido.php"] [unique_id "aoSD5Wr_JutbFb-8svom2QAAAb0"] [Tue Aug 18 13:10:13.233948 2026] [security2:error] [pid 167459:tid 167613] [client 40.74.65.169:52343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/sixxis.php"] [unique_id "aoSD5Wr_JutbFb-8svom2wAAAac"] [Tue Aug 18 13:10:13.244164 2026] [security2:error] [pid 167459:tid 167589] [client 197.184.64.235:42705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svom3AAAAY8"] [Tue Aug 18 13:10:13.244299 2026] [security2:error] [pid 167459:tid 167589] [client 197.184.64.235:42705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svom3AAAAY8"] [Tue Aug 18 13:10:13.274852 2026] [security2:error] [pid 167459:tid 167663] [client 168.62.48.100:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/zjggu.php"] [unique_id "aoSD5Wr_JutbFb-8svom3gAAAdk"] [Tue Aug 18 13:10:13.322591 2026] [security2:error] [pid 167459:tid 167621] [client 18.193.252.127:29116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.institutoferiani.com.br"] [uri "/index.php"] [unique_id "aoSD5Gr_JutbFb-8svompAAAAa8"], referer: https://www.institutoferiani.com.br [Tue Aug 18 13:10:13.353796 2026] [security2:error] [pid 167459:tid 167608] [client 20.116.17.175:22724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/privacy.php"] [unique_id "aoSD5Wr_JutbFb-8svom4gAAAaI"] [Tue Aug 18 13:10:13.373011 2026] [security2:error] [pid 167459:tid 167654] [client 158.23.17.4:10960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/qr.php"] [unique_id "aoSD5Wr_JutbFb-8svom4wAAAdA"] [Tue Aug 18 13:10:13.423996 2026] [security2:error] [pid 167459:tid 167646] [client 74.249.206.207:16172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/sf.php"] [unique_id "aoSD5Wr_JutbFb-8svom5wAAAcg"] [Tue Aug 18 13:10:13.435204 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:31937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/ws83.php"] [unique_id "aoSD5Wr_JutbFb-8svom6AAAAgg"] [Tue Aug 18 13:10:13.450085 2026] [security2:error] [pid 167459:tid 167709] [client 74.248.18.37:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/ms-edit.php"] [unique_id "aoSD5Wr_JutbFb-8svom6QAAAgc"] [Tue Aug 18 13:10:13.456954 2026] [security2:error] [pid 167459:tid 167712] [client 138.36.100.162:41632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svom6gAAAgo"] [Tue Aug 18 13:10:13.457042 2026] [security2:error] [pid 167459:tid 167712] [client 138.36.100.162:41632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svom6gAAAgo"] [Tue Aug 18 13:10:13.478583 2026] [security2:error] [pid 167459:tid 167632] [client 158.23.17.4:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "comforthmg.3xsolutions.com"] [uri "/13.php"] [unique_id "aoSD5Wr_JutbFb-8svom7QAAAbo"] [Tue Aug 18 13:10:13.481424 2026] [security2:error] [pid 167459:tid 167637] [client 20.118.172.148:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSD5Wr_JutbFb-8svom7gAAAb8"] [Tue Aug 18 13:10:13.483160 2026] [security2:error] [pid 167459:tid 167698] [client 20.104.49.167:22881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/halo.php"] [unique_id "aoSD5Wr_JutbFb-8svom7wAAAfw"] [Tue Aug 18 13:10:13.504782 2026] [security2:error] [pid 167459:tid 167610] [client 20.215.241.237:55229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/video.php"] [unique_id "aoSD5Wr_JutbFb-8svom8AAAAaQ"] [Tue Aug 18 13:10:13.507525 2026] [security2:error] [pid 167459:tid 167674] [client 20.91.215.254:12836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/goat.php"] [unique_id "aoSD5Wr_JutbFb-8svom8gAAAeQ"] [Tue Aug 18 13:10:13.507699 2026] [security2:error] [pid 167459:tid 167609] [client 52.139.47.57:18516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/php/eval-stdin.php"] [unique_id "aoSD5Wr_JutbFb-8svom8QAAAaM"] [Tue Aug 18 13:10:13.584457 2026] [security2:error] [pid 167459:tid 167672] [client 20.51.153.15:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/evil.php"] [unique_id "aoSD5Wr_JutbFb-8svom9AAAAeI"] [Tue Aug 18 13:10:13.625460 2026] [security2:error] [pid 167459:tid 167649] [client 20.250.13.23:44715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/elp.php"] [unique_id "aoSD5Wr_JutbFb-8svom9gAAAcs"] [Tue Aug 18 13:10:13.692748 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:13.693027 2026] [authz_core:error] [pid 167459:tid 167506] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:13.791226 2026] [security2:error] [pid 167459:tid 167658] [client 20.116.17.175:22726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/css/database.php"] [unique_id "aoSD5Wr_JutbFb-8svonAAAAAdQ"] [Tue Aug 18 13:10:13.864018 2026] [security2:error] [pid 167459:tid 167515] [remote 162.214.205.212:40846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chicodareia.com.br"] [uri "/wp-login.php"] [unique_id "aoSD5Wr_JutbFb-8svonAgABoDc"] [Tue Aug 18 13:10:13.881906 2026] [security2:error] [pid 167459:tid 167596] [client 213.35.127.232:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD5Wr_JutbFb-8svonAwAAAZY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:13.886365 2026] [security2:error] [pid 167459:tid 167625] [client 102.213.179.104:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svonBAAAAbM"] [Tue Aug 18 13:10:13.886509 2026] [security2:error] [pid 167459:tid 167625] [client 102.213.179.104:65007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5Wr_JutbFb-8svonBAAAAbM"] [Tue Aug 18 13:10:13.889875 2026] [security2:error] [pid 167459:tid 167594] [client 20.51.153.15:13367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pw.php"] [unique_id "aoSD5Wr_JutbFb-8svonBQAAAZQ"] [Tue Aug 18 13:10:13.920056 2026] [security2:error] [pid 167459:tid 167633] [client 40.74.65.169:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/yj09.php"] [unique_id "aoSD5Wr_JutbFb-8svonCQAAAbs"] [Tue Aug 18 13:10:13.929821 2026] [security2:error] [pid 167459:tid 167644] [client 40.74.65.169:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/gelay.php"] [unique_id "aoSD5Wr_JutbFb-8svonCwAAAcY"] [Tue Aug 18 13:10:13.939714 2026] [security2:error] [pid 167459:tid 167631] [client 52.139.47.57:13728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/php8.php"] [unique_id "aoSD5Wr_JutbFb-8svonDQAAAbk"] [Tue Aug 18 13:10:13.990382 2026] [security2:error] [pid 167459:tid 167655] [client 20.215.241.237:39326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/hel.php"] [unique_id "aoSD5Wr_JutbFb-8svonDwAAAdE"] [Tue Aug 18 13:10:13.995852 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:13.996108 2026] [authz_core:error] [pid 167459:tid 167495] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:14.004498 2026] [security2:error] [pid 167459:tid 167702] [client 20.118.172.148:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/av.php"] [unique_id "aoSD5mr_JutbFb-8svonEAAAAgA"] [Tue Aug 18 13:10:14.050932 2026] [security2:error] [pid 167459:tid 167544] [remote 129.121.74.194:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "melocorretordeimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSD5mr_JutbFb-8svonEgACCVQ"] [Tue Aug 18 13:10:14.060152 2026] [security2:error] [pid 167459:tid 167682] [client 158.23.17.4:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/dirs.php"] [unique_id "aoSD5mr_JutbFb-8svonEwAAAew"] [Tue Aug 18 13:10:14.224580 2026] [security2:error] [pid 167459:tid 167679] [client 20.51.153.15:13354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fn.php"] [unique_id "aoSD5mr_JutbFb-8svonFwAAAek"] [Tue Aug 18 13:10:14.228874 2026] [security2:error] [pid 167459:tid 167662] [client 74.249.206.207:30273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/k.php"] [unique_id "aoSD5mr_JutbFb-8svonGQAAAdg"] [Tue Aug 18 13:10:14.252738 2026] [security2:error] [pid 167459:tid 167641] [client 20.91.215.254:12823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/Session.php"] [unique_id "aoSD5mr_JutbFb-8svonGgAAAcM"] [Tue Aug 18 13:10:14.281858 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:22774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/privdayz.php"] [unique_id "aoSD5mr_JutbFb-8svonGwAAAeM"] [Tue Aug 18 13:10:14.298595 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:14.298943 2026] [authz_core:error] [pid 167459:tid 167537] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:14.364707 2026] [security2:error] [pid 167459:tid 167651] [client 74.248.133.44:34945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/2.php"] [unique_id "aoSD5mr_JutbFb-8svonIQAAAc0"] [Tue Aug 18 13:10:14.378737 2026] [security2:error] [pid 167459:tid 167642] [client 196.12.128.158:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD5mr_JutbFb-8svonJAAAAcQ"] [Tue Aug 18 13:10:14.378912 2026] [security2:error] [pid 167459:tid 167642] [client 196.12.128.158:60272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD5mr_JutbFb-8svonJAAAAcQ"] [Tue Aug 18 13:10:14.401157 2026] [security2:error] [pid 167459:tid 167618] [client 74.248.18.37:30624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/a7.php"] [unique_id "aoSD5mr_JutbFb-8svonJgAAAaw"] [Tue Aug 18 13:10:14.414054 2026] [security2:error] [pid 167459:tid 167571] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5mr_JutbFb-8svonKAAB_G8"] [Tue Aug 18 13:10:14.414240 2026] [security2:error] [pid 167459:tid 167698] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD5mr_JutbFb-8svonKAAB_G8"] [Tue Aug 18 13:10:14.454353 2026] [security2:error] [pid 167459:tid 167610] [client 20.215.241.237:40554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/grok.php"] [unique_id "aoSD5mr_JutbFb-8svonKwAAAaQ"] [Tue Aug 18 13:10:14.519030 2026] [security2:error] [pid 167459:tid 167694] [client 52.139.47.57:35295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/plugins.php"] [unique_id "aoSD5mr_JutbFb-8svonLgAAAfg"] [Tue Aug 18 13:10:14.530766 2026] [security2:error] [pid 167459:tid 167630] [client 20.118.172.148:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp.php"] [unique_id "aoSD5mr_JutbFb-8svonLwAAAbg"] [Tue Aug 18 13:10:14.559130 2026] [security2:error] [pid 167459:tid 167592] [client 20.51.153.15:13338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kf.php"] [unique_id "aoSD5mr_JutbFb-8svonMAAAAZI"] [Tue Aug 18 13:10:14.573638 2026] [security2:error] [pid 167459:tid 167672] [client 158.23.17.4:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/sn.php"] [unique_id "aoSD5mr_JutbFb-8svonMgAAAeI"] [Tue Aug 18 13:10:14.606603 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:14.607058 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:14.612449 2026] [security2:error] [pid 167459:tid 167681] [client 40.74.65.169:25468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/k.php"] [unique_id "aoSD5mr_JutbFb-8svonNAAAAes"] [Tue Aug 18 13:10:14.670273 2026] [security2:error] [pid 167459:tid 167599] [client 20.104.49.167:8780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/ajq1s.php"] [unique_id "aoSD5mr_JutbFb-8svonNwAAAZk"] [Tue Aug 18 13:10:14.726058 2026] [security2:error] [pid 167459:tid 167597] [client 40.74.65.169:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/atomlib.php"] [unique_id "aoSD5mr_JutbFb-8svonOAAAAZc"] [Tue Aug 18 13:10:14.821511 2026] [security2:error] [pid 167459:tid 167658] [client 20.51.153.15:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/su.php"] [unique_id "aoSD5mr_JutbFb-8svonPAAAAdQ"] [Tue Aug 18 13:10:14.864128 2026] [security2:error] [pid 167459:tid 167716] [client 20.116.17.175:45379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wg459o.php"] [unique_id "aoSD5mr_JutbFb-8svonQQAAAg4"] [Tue Aug 18 13:10:14.897736 2026] [security2:error] [pid 167459:tid 167616] [client 213.35.127.232:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD5mr_JutbFb-8svonRAAAAao"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:14.900847 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:14.901115 2026] [authz_core:error] [pid 167459:tid 167508] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:14.907997 2026] [security2:error] [pid 167459:tid 167625] [client 20.215.241.237:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/indes.php"] [unique_id "aoSD5mr_JutbFb-8svonRQAAAbM"] [Tue Aug 18 13:10:14.934579 2026] [security2:error] [pid 167459:tid 167652] [client 74.249.206.207:47731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/82.php"] [unique_id "aoSD5mr_JutbFb-8svonRgAAAc4"] [Tue Aug 18 13:10:14.941866 2026] [security2:error] [pid 167459:tid 167633] [client 20.171.51.14:36106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pz.php"] [unique_id "aoSD5mr_JutbFb-8svonSQAAAbs"] [Tue Aug 18 13:10:14.941885 2026] [security2:error] [pid 167459:tid 167605] [client 52.139.47.57:35290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/radio.php"] [unique_id "aoSD5mr_JutbFb-8svonSAAAAZ8"] [Tue Aug 18 13:10:14.951423 2026] [security2:error] [pid 167459:tid 167657] [client 20.91.215.254:12829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/acme-challenge.php"] [unique_id "aoSD5mr_JutbFb-8svonSgAAAdM"] [Tue Aug 18 13:10:15.033800 2026] [security2:error] [pid 167459:tid 167707] [client 20.250.13.23:49469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD52r_JutbFb-8svonTgAAAgU"] [Tue Aug 18 13:10:15.051228 2026] [security2:error] [pid 167459:tid 167656] [client 158.23.17.4:33515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/43.php"] [unique_id "aoSD52r_JutbFb-8svonUAAAAdI"] [Tue Aug 18 13:10:15.076743 2026] [security2:error] [pid 167459:tid 167688] [client 20.51.153.15:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wp-key.php"] [unique_id "aoSD52r_JutbFb-8svonUgAAAfI"] [Tue Aug 18 13:10:15.195378 2026] [security2:error] [pid 167459:tid 167608] [client 20.118.172.148:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/file2.php"] [unique_id "aoSD52r_JutbFb-8svonVgAAAaI"] [Tue Aug 18 13:10:15.209310 2026] [security2:error] [pid 167459:tid 167594] [client 74.248.133.44:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "aoSD52r_JutbFb-8svonWAAAAZQ"] [Tue Aug 18 13:10:15.333061 2026] [security2:error] [pid 167459:tid 167618] [client 40.74.65.169:25467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/w.php"] [unique_id "aoSD52r_JutbFb-8svonXQAAAaw"] [Tue Aug 18 13:10:15.356411 2026] [security2:error] [pid 167459:tid 167673] [client 52.139.47.57:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/rem.php"] [unique_id "aoSD52r_JutbFb-8svonXwAAAeM"] [Tue Aug 18 13:10:15.364548 2026] [security2:error] [pid 167459:tid 167674] [client 20.51.153.15:1994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gg.php"] [unique_id "aoSD52r_JutbFb-8svonYQAAAeQ"] [Tue Aug 18 13:10:15.397611 2026] [security2:error] [pid 167459:tid 167598] [client 168.62.48.100:5579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/dlvqo.php"] [unique_id "aoSD52r_JutbFb-8svonZAAAAZg"] [Tue Aug 18 13:10:15.404634 2026] [security2:error] [pid 167459:tid 167592] [client 20.215.241.237:30405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/tTPcH.php"] [unique_id "aoSD52r_JutbFb-8svonZgAAAZI"] [Tue Aug 18 13:10:15.411387 2026] [security2:error] [pid 167459:tid 167589] [client 74.248.18.37:26269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/manager.php"] [unique_id "aoSD52r_JutbFb-8svonZwAAAY8"] [Tue Aug 18 13:10:15.423342 2026] [security2:error] [pid 167459:tid 167672] [client 20.116.17.175:45375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/mifta.php"] [unique_id "aoSD52r_JutbFb-8svonaAAAAeI"] [Tue Aug 18 13:10:15.501788 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:15.502062 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:15.568593 2026] [security2:error] [pid 167459:tid 167661] [client 68.221.73.131:45666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/img.php"] [unique_id "aoSD52r_JutbFb-8svonbgAAAdc"] [Tue Aug 18 13:10:15.597977 2026] [security2:error] [pid 167459:tid 167640] [client 158.23.17.4:29487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/fresh.php"] [unique_id "aoSD52r_JutbFb-8svoncAAAAcI"] [Tue Aug 18 13:10:15.646240 2026] [security2:error] [pid 167459:tid 167694] [client 20.91.215.254:12803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/abcd.php"] [unique_id "aoSD52r_JutbFb-8svoncQAAAfg"] [Tue Aug 18 13:10:15.653678 2026] [security2:error] [pid 167459:tid 167632] [client 20.51.153.15:13391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gi.php"] [unique_id "aoSD52r_JutbFb-8svoncgAAAbo"] [Tue Aug 18 13:10:15.703319 2026] [autoindex:error] [pid 167459:tid 167653] [client 74.248.18.37:29969] AH01276: Cannot serve directory /home4/jeff1000/jx2.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:15.709931 2026] [security2:error] [pid 167459:tid 167671] [client 4.232.151.198:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/atex1.php"] [unique_id "aoSD52r_JutbFb-8svondwAAAeE"] [Tue Aug 18 13:10:15.730163 2026] [security2:error] [pid 167459:tid 167611] [client 20.118.172.148:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/images/class-config.php"] [unique_id "aoSD52r_JutbFb-8svoneAAAAaU"] [Tue Aug 18 13:10:15.804608 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:15.804875 2026] [authz_core:error] [pid 167459:tid 167569] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:15.807200 2026] [security2:error] [pid 167459:tid 167629] [client 52.139.47.57:35300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/server.php"] [unique_id "aoSD52r_JutbFb-8svonewAAAbc"] [Tue Aug 18 13:10:15.807498 2026] [security2:error] [pid 167459:tid 167716] [client 20.104.49.167:10864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/spip.php"] [unique_id "aoSD52r_JutbFb-8svonfAAAAg4"] [Tue Aug 18 13:10:15.847562 2026] [security2:error] [pid 167459:tid 167624] [client 49.145.211.146:10654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD52r_JutbFb-8svondQAAAbI"] [Tue Aug 18 13:10:15.847696 2026] [security2:error] [pid 167459:tid 167624] [client 49.145.211.146:10654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD52r_JutbFb-8svondQAAAbI"] [Tue Aug 18 13:10:15.852967 2026] [security2:error] [pid 167459:tid 167652] [client 20.215.241.237:46391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/bs1.php"] [unique_id "aoSD52r_JutbFb-8svonfgAAAc4"] [Tue Aug 18 13:10:15.862415 2026] [security2:error] [pid 167459:tid 167670] [client 40.74.65.169:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/ee.php"] [unique_id "aoSD52r_JutbFb-8svonfwAAAeA"] [Tue Aug 18 13:10:15.896318 2026] [security2:error] [pid 167459:tid 167631] [client 74.249.206.207:16184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/dex.php"] [unique_id "aoSD52r_JutbFb-8svongAAAAbk"] [Tue Aug 18 13:10:15.910038 2026] [security2:error] [pid 167459:tid 167647] [client 213.35.127.232:54085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD52r_JutbFb-8svongQAAAck"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:15.913278 2026] [security2:error] [pid 167459:tid 167702] [client 74.248.18.37:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/php8.php"] [unique_id "aoSD52r_JutbFb-8svonggAAAgA"] [Tue Aug 18 13:10:15.935347 2026] [security2:error] [pid 167459:tid 167635] [client 20.118.133.132:45206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD52r_JutbFb-8svongwAAAb0"] [Tue Aug 18 13:10:15.943669 2026] [security2:error] [pid 167459:tid 167707] [client 20.51.153.15:1988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pz.php"] [unique_id "aoSD52r_JutbFb-8svonhQAAAgU"] [Tue Aug 18 13:10:15.960796 2026] [security2:error] [pid 167459:tid 167649] [client 121.121.218.203:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.218.121.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "interativaveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD52r_JutbFb-8svonhwAAAcs"] [Tue Aug 18 13:10:15.960981 2026] [security2:error] [pid 167459:tid 167649] [client 121.121.218.203:58023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "interativaveiculos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD52r_JutbFb-8svonhwAAAcs"] [Tue Aug 18 13:10:16.010388 2026] [security2:error] [pid 167459:tid 167593] [client 40.74.65.169:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/fpwch.php"] [unique_id "aoSD6Gr_JutbFb-8svoniAAAAZM"] [Tue Aug 18 13:10:16.041053 2026] [security2:error] [pid 167459:tid 167688] [client 158.23.17.4:33525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/gj.php"] [unique_id "aoSD6Gr_JutbFb-8svonigAAAfI"] [Tue Aug 18 13:10:16.099215 2026] [security2:error] [pid 167459:tid 167614] [client 49.37.150.8:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Gr_JutbFb-8svonjgAAAag"] [Tue Aug 18 13:10:16.101779 2026] [security2:error] [pid 167459:tid 167614] [client 49.37.150.8:62845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Gr_JutbFb-8svonjgAAAag"] [Tue Aug 18 13:10:16.104715 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:16.105002 2026] [authz_core:error] [pid 167459:tid 167555] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:16.131809 2026] [security2:error] [pid 167459:tid 167654] [client 20.116.17.175:45416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/xyn.php"] [unique_id "aoSD6Gr_JutbFb-8svonkAAAAdA"] [Tue Aug 18 13:10:16.148017 2026] [security2:error] [pid 167459:tid 167677] [client 74.248.133.44:12351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSD6Gr_JutbFb-8svonkgAAAec"] [Tue Aug 18 13:10:16.188441 2026] [security2:error] [pid 167459:tid 167695] [client 20.51.153.15:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kk.php"] [unique_id "aoSD6Gr_JutbFb-8svonlAAAAfk"] [Tue Aug 18 13:10:16.239124 2026] [security2:error] [pid 167459:tid 167675] [client 52.139.47.57:9878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/settings.php"] [unique_id "aoSD6Gr_JutbFb-8svonlgAAAeU"] [Tue Aug 18 13:10:16.293093 2026] [security2:error] [pid 167459:tid 167678] [client 20.91.215.254:12696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/kj.php"] [unique_id "aoSD6Gr_JutbFb-8svonlwAAAeg"] [Tue Aug 18 13:10:16.295778 2026] [security2:error] [pid 167459:tid 167712] [client 20.215.241.237:16265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/hp2.php"] [unique_id "aoSD6Gr_JutbFb-8svonmAAAAgo"] [Tue Aug 18 13:10:16.388165 2026] [authz_core:error] [pid 167459:tid 167567] [remote 57.141.22.93:41116] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:16.388619 2026] [authz_core:error] [pid 167459:tid 167567] [remote 57.141.22.93:41116] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:16.407672 2026] [authz_core:error] [pid 167459:tid 167491] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:16.407945 2026] [authz_core:error] [pid 167459:tid 167491] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:16.463531 2026] [security2:error] [pid 167459:tid 167667] [client 20.51.153.15:2044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/phpcheck.php"] [unique_id "aoSD6Gr_JutbFb-8svonnwAAAd0"] [Tue Aug 18 13:10:16.554255 2026] [security2:error] [pid 167459:tid 167715] [client 20.118.172.148:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/alfa.php"] [unique_id "aoSD6Gr_JutbFb-8svonowAAAg0"] [Tue Aug 18 13:10:16.588161 2026] [security2:error] [pid 167459:tid 167661] [client 20.116.17.175:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/index2.php"] [unique_id "aoSD6Gr_JutbFb-8svonpQAAAdc"] [Tue Aug 18 13:10:16.668034 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:13759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/sf.php"] [unique_id "aoSD6Gr_JutbFb-8svonpwAAAfo"] [Tue Aug 18 13:10:16.688857 2026] [security2:error] [pid 167459:tid 167683] [client 20.171.51.14:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kk.php"] [unique_id "aoSD6Gr_JutbFb-8svonqAAAAe0"] [Tue Aug 18 13:10:16.710888 2026] [security2:error] [pid 167459:tid 167700] [client 40.74.65.169:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/FWAZ.php"] [unique_id "aoSD6Gr_JutbFb-8svonqgAAAf4"] [Tue Aug 18 13:10:16.721408 2026] [security2:error] [pid 167459:tid 167632] [client 40.74.65.169:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/tfm.php"] [unique_id "aoSD6Gr_JutbFb-8svonrAAAAbo"] [Tue Aug 18 13:10:16.725885 2026] [security2:error] [pid 167459:tid 167672] [client 20.250.13.23:41548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/666.php"] [unique_id "aoSD6Gr_JutbFb-8svonrQAAAeI"] [Tue Aug 18 13:10:16.742586 2026] [security2:error] [pid 167459:tid 167630] [client 20.215.241.237:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/yb.php"] [unique_id "aoSD6Gr_JutbFb-8svonrgAAAbg"] [Tue Aug 18 13:10:16.784122 2026] [security2:error] [pid 167459:tid 167692] [client 40.74.65.169:49139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD6Gr_JutbFb-8svonsAAAAfY"] [Tue Aug 18 13:10:16.787380 2026] [security2:error] [pid 167459:tid 167650] [client 20.51.153.15:13327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/dg.php"] [unique_id "aoSD6Gr_JutbFb-8svonsQAAAcw"] [Tue Aug 18 13:10:16.841610 2026] [security2:error] [pid 167459:tid 167658] [client 158.23.17.4:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/pd.php"] [unique_id "aoSD6Gr_JutbFb-8svonswAAAdQ"] [Tue Aug 18 13:10:16.894964 2026] [security2:error] [pid 167459:tid 167705] [client 20.104.49.167:8445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/wpup.php"] [unique_id "aoSD6Gr_JutbFb-8svontQAAAgM"] [Tue Aug 18 13:10:16.924345 2026] [security2:error] [pid 167459:tid 167607] [client 213.35.127.232:54305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD6Gr_JutbFb-8svontwAAAaE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:16.924617 2026] [security2:error] [pid 167459:tid 167489] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Gr_JutbFb-8svontgABtB0"] [Tue Aug 18 13:10:16.924764 2026] [security2:error] [pid 167459:tid 167626] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Gr_JutbFb-8svontgABtB0"] [Tue Aug 18 13:10:16.983748 2026] [security2:error] [pid 167459:tid 167648] [client 74.248.18.37:39888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSD6Gr_JutbFb-8svonuQAAAco"] [Tue Aug 18 13:10:16.999528 2026] [security2:error] [pid 167459:tid 167652] [client 20.118.172.148:60459] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mailsg.i-eduqi.com.br"] [uri "/1.php"] [unique_id "aoSD6Gr_JutbFb-8svonugAAAc4"] [Tue Aug 18 13:10:16.999638 2026] [security2:error] [pid 167459:tid 167652] [client 20.118.172.148:60459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/1.php"] [unique_id "aoSD6Gr_JutbFb-8svonugAAAc4"] [Tue Aug 18 13:10:17.008477 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:17.008744 2026] [authz_core:error] [pid 167459:tid 167526] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:17.030271 2026] [security2:error] [pid 167459:tid 167679] [client 103.120.71.157:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Wr_JutbFb-8svonvgAAAek"] [Tue Aug 18 13:10:17.030460 2026] [security2:error] [pid 167459:tid 167679] [client 103.120.71.157:58279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Wr_JutbFb-8svonvgAAAek"] [Tue Aug 18 13:10:17.037181 2026] [security2:error] [pid 167459:tid 167591] [client 74.249.206.207:22972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/puc.php"] [unique_id "aoSD6Wr_JutbFb-8svonvwAAAZE"] [Tue Aug 18 13:10:17.043633 2026] [security2:error] [pid 167459:tid 167653] [client 20.91.215.254:12807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/languages.php"] [unique_id "aoSD6Wr_JutbFb-8svonwAAAAc8"] [Tue Aug 18 13:10:17.062317 2026] [security2:error] [pid 167459:tid 167647] [client 20.116.17.175:22681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/8.php"] [unique_id "aoSD6Wr_JutbFb-8svonwgAAAck"] [Tue Aug 18 13:10:17.073301 2026] [security2:error] [pid 167459:tid 167668] [client 20.51.153.15:13351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/bm.php"] [unique_id "aoSD6Wr_JutbFb-8svonwwAAAd4"] [Tue Aug 18 13:10:17.096548 2026] [security2:error] [pid 167459:tid 167624] [client 52.139.47.57:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/size.php"] [unique_id "aoSD6Wr_JutbFb-8svonxAAAAbI"] [Tue Aug 18 13:10:17.117449 2026] [security2:error] [pid 167459:tid 167581] [remote 50.6.169.131:52044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.169.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nadianobre.com.br"] [uri "/wp-login.php"] [unique_id "aoSD6Wr_JutbFb-8svonxQABpXk"] [Tue Aug 18 13:10:17.119787 2026] [security2:error] [pid 167459:tid 167697] [client 86.120.159.145:62654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Wr_JutbFb-8svonxgAAAfs"] [Tue Aug 18 13:10:17.120288 2026] [security2:error] [pid 167459:tid 167697] [client 86.120.159.145:62654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6Wr_JutbFb-8svonxgAAAfs"] [Tue Aug 18 13:10:17.161059 2026] [security2:error] [pid 167459:tid 167688] [client 20.215.241.237:16271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/vc.php"] [unique_id "aoSD6Wr_JutbFb-8svonygAAAfI"] [Tue Aug 18 13:10:17.258625 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/th.php"] [unique_id "aoSD6Wr_JutbFb-8svonzgAAAZQ"] [Tue Aug 18 13:10:17.321456 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:17.321715 2026] [authz_core:error] [pid 167459:tid 167482] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:17.345150 2026] [security2:error] [pid 167459:tid 167651] [client 20.51.153.15:13370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vu.php"] [unique_id "aoSD6Wr_JutbFb-8svon0gAAAc0"] [Tue Aug 18 13:10:17.389455 2026] [security2:error] [pid 167459:tid 167621] [client 40.74.65.169:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/blurbs.php"] [unique_id "aoSD6Wr_JutbFb-8svon0wAAAa8"] [Tue Aug 18 13:10:17.407097 2026] [security2:error] [pid 167459:tid 167687] [client 168.62.48.100:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/pkmoj.php"] [unique_id "aoSD6Wr_JutbFb-8svon1QAAAfE"] [Tue Aug 18 13:10:17.471130 2026] [security2:error] [pid 167459:tid 167674] [client 4.232.151.198:43485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/class-t.api.php"] [unique_id "aoSD6Wr_JutbFb-8svon1wAAAeQ"] [Tue Aug 18 13:10:17.480821 2026] [security2:error] [pid 167459:tid 167625] [client 40.74.65.169:49113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD6Wr_JutbFb-8svon2QAAAbM"] [Tue Aug 18 13:10:17.495895 2026] [security2:error] [pid 167459:tid 167704] [client 20.118.172.148:60462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/222.php"] [unique_id "aoSD6Wr_JutbFb-8svon2wAAAgI"] [Tue Aug 18 13:10:17.512516 2026] [security2:error] [pid 167459:tid 167642] [client 52.139.47.57:35326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/staging/wp-content/test.php"] [unique_id "aoSD6Wr_JutbFb-8svon3gAAAcQ"] [Tue Aug 18 13:10:17.545423 2026] [security2:error] [pid 167459:tid 167693] [client 40.74.65.169:6243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/tool.php"] [unique_id "aoSD6Wr_JutbFb-8svon3wAAAfc"] [Tue Aug 18 13:10:17.550406 2026] [security2:error] [pid 167459:tid 167711] [client 74.7.175.166:58724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vitalinox.pt.cesarinox.com"] [uri "/index.php"] [unique_id "aoSD52r_JutbFb-8svonVAACCS0"] [Tue Aug 18 13:10:17.579434 2026] [security2:error] [pid 167459:tid 167660] [client 20.116.17.175:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/images.php"] [unique_id "aoSD6Wr_JutbFb-8svon4QAAAdY"] [Tue Aug 18 13:10:17.586425 2026] [security2:error] [pid 167459:tid 167623] [client 20.215.241.237:30458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/pema.php"] [unique_id "aoSD6Wr_JutbFb-8svon4gAAAbE"] [Tue Aug 18 13:10:17.616929 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:17.617187 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:17.636461 2026] [security2:error] [pid 167459:tid 167701] [client 20.51.153.15:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ic.php"] [unique_id "aoSD6Wr_JutbFb-8svon5AAAAf8"] [Tue Aug 18 13:10:17.821348 2026] [security2:error] [pid 167459:tid 167595] [client 20.104.49.167:10862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/myy.php"] [unique_id "aoSD6Wr_JutbFb-8svon6wAAAZU"] [Tue Aug 18 13:10:17.850131 2026] [security2:error] [pid 167459:tid 167650] [client 158.23.17.4:38893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/admin404.php"] [unique_id "aoSD6Wr_JutbFb-8svon7QAAAcw"] [Tue Aug 18 13:10:17.914257 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:17.914708 2026] [authz_core:error] [pid 167459:tid 167487] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:17.915838 2026] [security2:error] [pid 167459:tid 167664] [client 20.91.215.254:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/nw.php"] [unique_id "aoSD6Wr_JutbFb-8svon8QAAAdo"] [Tue Aug 18 13:10:17.939691 2026] [security2:error] [pid 167459:tid 167680] [client 20.118.172.148:57491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/asasx.php"] [unique_id "aoSD6Wr_JutbFb-8svon8wAAAeo"] [Tue Aug 18 13:10:17.940970 2026] [security2:error] [pid 167459:tid 167672] [client 52.139.47.57:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/storage/index.php"] [unique_id "aoSD6Wr_JutbFb-8svon9AAAAeI"] [Tue Aug 18 13:10:17.942937 2026] [security2:error] [pid 167459:tid 167645] [client 213.35.127.232:54515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD6Wr_JutbFb-8svon9QAAAcc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:17.977893 2026] [security2:error] [pid 167459:tid 167607] [client 20.51.153.15:13362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ue.php"] [unique_id "aoSD6Wr_JutbFb-8svon9wAAAaE"] [Tue Aug 18 13:10:18.012699 2026] [authz_core:error] [pid 167459:tid 167501] [remote 57.141.22.10:60760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:18.013011 2026] [authz_core:error] [pid 167459:tid 167501] [remote 57.141.22.10:60760] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:18.037650 2026] [authz_core:error] [pid 167459:tid 167546] [remote 57.141.22.10:60768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:18.037947 2026] [authz_core:error] [pid 167459:tid 167546] [remote 57.141.22.10:60768] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:18.072457 2026] [security2:error] [pid 167459:tid 167652] [client 20.250.13.23:31859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/ws54.php"] [unique_id "aoSD6mr_JutbFb-8svon-wAAAc4"] [Tue Aug 18 13:10:18.076073 2026] [security2:error] [pid 167459:tid 167590] [client 20.215.241.237:39306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/sh.php"] [unique_id "aoSD6mr_JutbFb-8svon_AAAAZA"] [Tue Aug 18 13:10:18.083148 2026] [security2:error] [pid 167459:tid 167633] [client 40.74.65.169:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/100.php"] [unique_id "aoSD6mr_JutbFb-8svon_QAAAbs"] [Tue Aug 18 13:10:18.169400 2026] [security2:error] [pid 167459:tid 167653] [client 40.74.65.169:49077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/media.php"] [unique_id "aoSD6mr_JutbFb-8svooAQAAAc8"] [Tue Aug 18 13:10:18.214445 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:18.214704 2026] [authz_core:error] [pid 167459:tid 167522] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:18.229441 2026] [security2:error] [pid 167459:tid 167647] [client 20.51.153.15:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lr.php"] [unique_id "aoSD6mr_JutbFb-8svooBAAAAck"] [Tue Aug 18 13:10:18.264208 2026] [security2:error] [pid 167459:tid 167629] [client 74.248.18.37:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/222.php"] [unique_id "aoSD6mr_JutbFb-8svooBQAAAbc"] [Tue Aug 18 13:10:18.368745 2026] [security2:error] [pid 167459:tid 167613] [client 158.23.17.4:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/qo.php"] [unique_id "aoSD6mr_JutbFb-8svooCQAAAac"] [Tue Aug 18 13:10:18.388646 2026] [security2:error] [pid 167459:tid 167702] [client 52.139.47.57:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/storage/min.php"] [unique_id "aoSD6mr_JutbFb-8svooCwAAAgA"] [Tue Aug 18 13:10:18.408909 2026] [security2:error] [pid 167459:tid 167708] [client 68.155.154.236:25373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-admin/includes/3p8jj8r.php"] [unique_id "aoSD6mr_JutbFb-8svooDQAAAgY"] [Tue Aug 18 13:10:18.484844 2026] [security2:error] [pid 167459:tid 167641] [client 20.104.49.167:16127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/geido.php"] [unique_id "aoSD6mr_JutbFb-8svooEAAAAcM"] [Tue Aug 18 13:10:18.492137 2026] [security2:error] [pid 167459:tid 167637] [client 40.74.65.169:5681] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.rkveiculos.com"] [uri "/1.php"] [unique_id "aoSD6mr_JutbFb-8svooEwAAAb8"] [Tue Aug 18 13:10:18.492244 2026] [security2:error] [pid 167459:tid 167637] [client 40.74.65.169:5681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/1.php"] [unique_id "aoSD6mr_JutbFb-8svooEwAAAb8"] [Tue Aug 18 13:10:18.495265 2026] [security2:error] [pid 167459:tid 167695] [client 20.215.241.237:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/button.php"] [unique_id "aoSD6mr_JutbFb-8svooFAAAAfk"] [Tue Aug 18 13:10:18.506309 2026] [security2:error] [pid 167459:tid 167675] [client 20.51.153.15:13349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ka.php"] [unique_id "aoSD6mr_JutbFb-8svooFwAAAeU"] [Tue Aug 18 13:10:18.517733 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:18.517998 2026] [authz_core:error] [pid 167459:tid 167582] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:18.575455 2026] [security2:error] [pid 167459:tid 167621] [client 20.118.133.132:45222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD6mr_JutbFb-8svooGwAAAa8"] [Tue Aug 18 13:10:18.590754 2026] [security2:error] [pid 167459:tid 167614] [client 20.91.215.254:14312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/lofmebwd.php"] [unique_id "aoSD6mr_JutbFb-8svooHQAAAag"] [Tue Aug 18 13:10:18.621023 2026] [security2:error] [pid 167459:tid 167670] [client 114.119.138.172:42959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tribunadolitoral.com"] [uri "/em-curitiba-sergio-moro-e-recebido-por-entidades-da-saude/"] [unique_id "aoSD6mr_JutbFb-8svooHgAAAeA"], referer: https://tribunadolitoral.com/parana-inicia-semana-com-oferta-de-11-613-vagas-de-emprego-nas-agencias-do-trabalhador/ [Tue Aug 18 13:10:18.625661 2026] [security2:error] [pid 167459:tid 167598] [client 74.249.206.207:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/inso.php"] [unique_id "aoSD6mr_JutbFb-8svooHwAAAZg"] [Tue Aug 18 13:10:18.704511 2026] [security2:error] [pid 167459:tid 167693] [client 20.118.172.148:60465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/filemanager.php"] [unique_id "aoSD6mr_JutbFb-8svooIQAAAfc"] [Tue Aug 18 13:10:18.728449 2026] [security2:error] [pid 167459:tid 167665] [client 20.116.17.175:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/a.php"] [unique_id "aoSD6mr_JutbFb-8svooIgAAAds"] [Tue Aug 18 13:10:18.764147 2026] [security2:error] [pid 167459:tid 167623] [client 20.51.153.15:13432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ot.php"] [unique_id "aoSD6mr_JutbFb-8svooJAAAAbE"] [Tue Aug 18 13:10:18.779588 2026] [security2:error] [pid 167459:tid 167602] [client 40.74.65.169:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/ccc.php"] [unique_id "aoSD6mr_JutbFb-8svooJgAAAZw"] [Tue Aug 18 13:10:18.817776 2026] [authz_core:error] [pid 167459:tid 167523] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:18.818073 2026] [authz_core:error] [pid 167459:tid 167523] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:18.821998 2026] [security2:error] [pid 167459:tid 167716] [client 223.185.37.47:23750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD6mr_JutbFb-8svooKQAAAg4"] [Tue Aug 18 13:10:18.822132 2026] [security2:error] [pid 167459:tid 167716] [client 223.185.37.47:23750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD6mr_JutbFb-8svooKQAAAg4"] [Tue Aug 18 13:10:18.825504 2026] [security2:error] [pid 167459:tid 167624] [client 114.5.214.109:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6mr_JutbFb-8svooKgAAAbI"] [Tue Aug 18 13:10:18.828362 2026] [security2:error] [pid 167459:tid 167624] [client 114.5.214.109:50427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD6mr_JutbFb-8svooKgAAAbI"] [Tue Aug 18 13:10:18.853285 2026] [security2:error] [pid 167459:tid 167592] [client 40.74.65.169:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/admin.php"] [unique_id "aoSD6mr_JutbFb-8svooLAAAAZI"] [Tue Aug 18 13:10:18.948991 2026] [security2:error] [pid 167459:tid 167666] [client 20.215.241.237:27661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/wlc.php"] [unique_id "aoSD6mr_JutbFb-8svooMAAAAdw"] [Tue Aug 18 13:10:18.958427 2026] [security2:error] [pid 167459:tid 167687] [client 213.35.127.232:54746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD6mr_JutbFb-8svooMQAAAfE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:18.968075 2026] [security2:error] [pid 167459:tid 167617] [client 52.139.47.57:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/test.php"] [unique_id "aoSD6mr_JutbFb-8svooMgAAAas"] [Tue Aug 18 13:10:18.988918 2026] [security2:error] [pid 167459:tid 167664] [client 158.23.17.4:29445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/sd.php"] [unique_id "aoSD6mr_JutbFb-8svooMwAAAdo"] [Tue Aug 18 13:10:19.011159 2026] [security2:error] [pid 167459:tid 167680] [client 20.51.153.15:2011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ih.php"] [unique_id "aoSD62r_JutbFb-8svooNQAAAeo"] [Tue Aug 18 13:10:19.040451 2026] [security2:error] [pid 167459:tid 167681] [client 170.81.43.147:38480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ns1.fbenevides.com.br"] [uri "/"] [unique_id "aoSD62r_JutbFb-8svooNwAAAes"] [Tue Aug 18 13:10:19.052897 2026] [security2:error] [pid 167459:tid 167607] [client 20.104.49.167:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/gelay.php"] [unique_id "aoSD62r_JutbFb-8svooOAAAAaE"] [Tue Aug 18 13:10:19.186785 2026] [security2:error] [pid 167459:tid 167644] [client 20.116.17.175:41495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/11PJcpMFsD8B.php"] [unique_id "aoSD62r_JutbFb-8svooPgAAAcY"] [Tue Aug 18 13:10:19.189362 2026] [security2:error] [pid 167459:tid 167591] [client 20.171.51.14:31060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/phpcheck.php"] [unique_id "aoSD62r_JutbFb-8svooPwAAAZE"] [Tue Aug 18 13:10:19.224226 2026] [security2:error] [pid 167459:tid 167662] [client 213.202.253.4:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/delpaths.php"] [unique_id "aoSD62r_JutbFb-8svooQQAAAdg"], referer: www.google.com [Tue Aug 18 13:10:19.283431 2026] [security2:error] [pid 167459:tid 167688] [client 20.51.153.15:2026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/k.php"] [unique_id "aoSD62r_JutbFb-8svooQwAAAfI"] [Tue Aug 18 13:10:19.379162 2026] [security2:error] [pid 167459:tid 167639] [client 20.215.241.237:59773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/fi.php"] [unique_id "aoSD62r_JutbFb-8svooRgAAAcE"] [Tue Aug 18 13:10:19.384043 2026] [security2:error] [pid 167459:tid 167613] [client 20.118.172.148:56981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/themes.php"] [unique_id "aoSD62r_JutbFb-8svooRwAAAac"] [Tue Aug 18 13:10:19.391244 2026] [security2:error] [pid 167459:tid 167611] [client 52.139.47.57:2714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/test1.php"] [unique_id "aoSD62r_JutbFb-8svooSAAAAaU"] [Tue Aug 18 13:10:19.419511 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:19.419814 2026] [authz_core:error] [pid 167459:tid 167498] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:19.442840 2026] [security2:error] [pid 167459:tid 167616] [client 158.23.17.4:10948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/km.php"] [unique_id "aoSD62r_JutbFb-8svooTAAAAao"] [Tue Aug 18 13:10:19.457608 2026] [security2:error] [pid 167459:tid 167596] [client 20.91.215.254:13035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSD62r_JutbFb-8svooTQAAAZY"] [Tue Aug 18 13:10:19.473765 2026] [security2:error] [pid 167459:tid 167641] [client 40.74.65.169:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/get.php"] [unique_id "aoSD62r_JutbFb-8svooTgAAAcM"] [Tue Aug 18 13:10:19.538714 2026] [security2:error] [pid 167459:tid 167675] [client 40.74.65.169:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/mac.php"] [unique_id "aoSD62r_JutbFb-8svooUQAAAeU"] [Tue Aug 18 13:10:19.549201 2026] [security2:error] [pid 167459:tid 167638] [client 20.51.153.15:13337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/iu.php"] [unique_id "aoSD62r_JutbFb-8svooUgAAAcA"] [Tue Aug 18 13:10:19.552640 2026] [security2:error] [pid 167459:tid 167658] [client 20.104.49.167:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/atomlib.php"] [unique_id "aoSD62r_JutbFb-8svooUwAAAdQ"] [Tue Aug 18 13:10:19.611761 2026] [security2:error] [pid 167459:tid 167678] [client 40.74.65.169:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/dev1s.php"] [unique_id "aoSD62r_JutbFb-8svooVgAAAeg"] [Tue Aug 18 13:10:19.615308 2026] [authz_core:error] [pid 167459:tid 167474] [remote 57.141.22.91:59646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:19.615585 2026] [authz_core:error] [pid 167459:tid 167474] [remote 57.141.22.91:59646] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:19.722617 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:19.723051 2026] [authz_core:error] [pid 167459:tid 167493] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:19.790122 2026] [security2:error] [pid 167459:tid 167660] [client 20.51.153.15:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pk.php"] [unique_id "aoSD62r_JutbFb-8svooYQAAAdY"] [Tue Aug 18 13:10:19.803233 2026] [security2:error] [pid 167459:tid 167623] [client 20.116.17.175:41515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/99.php"] [unique_id "aoSD62r_JutbFb-8svooYgAAAbE"] [Tue Aug 18 13:10:19.829368 2026] [security2:error] [pid 167459:tid 167661] [client 20.215.241.237:40567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/chris.php"] [unique_id "aoSD62r_JutbFb-8svooYwAAAdc"] [Tue Aug 18 13:10:19.861266 2026] [security2:error] [pid 167459:tid 167686] [client 149.34.210.141:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD62r_JutbFb-8svooZQAAAfA"] [Tue Aug 18 13:10:19.936614 2026] [security2:error] [pid 167459:tid 167615] [client 52.139.47.57:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/thoms.php"] [unique_id "aoSD62r_JutbFb-8svooZgAAAak"] [Tue Aug 18 13:10:19.968178 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:33522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/mf.php"] [unique_id "aoSD62r_JutbFb-8svooaAAAAZI"] [Tue Aug 18 13:10:19.973493 2026] [security2:error] [pid 167459:tid 167621] [client 213.35.127.232:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD62r_JutbFb-8svooaQAAAa8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:19.976526 2026] [security2:error] [pid 167459:tid 167689] [client 20.104.49.167:10784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/ee.php"] [unique_id "aoSD62r_JutbFb-8svooagAAAfM"] [Tue Aug 18 13:10:20.031528 2026] [security2:error] [pid 167459:tid 167715] [client 74.248.133.44:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/dav.php"] [unique_id "aoSD7Gr_JutbFb-8svooawAAAg0"] [Tue Aug 18 13:10:20.091607 2026] [security2:error] [pid 167459:tid 167699] [client 20.91.215.254:14288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSD7Gr_JutbFb-8svoobgAAAf0"] [Tue Aug 18 13:10:20.109557 2026] [security2:error] [pid 167459:tid 167666] [client 20.51.153.15:13330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ge.php"] [unique_id "aoSD7Gr_JutbFb-8svoocQAAAdw"] [Tue Aug 18 13:10:20.116676 2026] [security2:error] [pid 167459:tid 167687] [client 68.155.154.236:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/index/function.php"] [unique_id "aoSD7Gr_JutbFb-8svoocgAAAfE"] [Tue Aug 18 13:10:20.128091 2026] [security2:error] [pid 167459:tid 167685] [client 20.118.172.148:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSD7Gr_JutbFb-8svoodAAAAe8"] [Tue Aug 18 13:10:20.139890 2026] [security2:error] [pid 167459:tid 167686] [client 149.34.210.141:61091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD62r_JutbFb-8svooZQAAAfA"] [Tue Aug 18 13:10:20.159202 2026] [security2:error] [pid 167459:tid 167667] [client 40.74.65.169:25417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/images.php"] [unique_id "aoSD7Gr_JutbFb-8svoodQAAAd0"] [Tue Aug 18 13:10:20.223598 2026] [security2:error] [pid 167459:tid 167627] [client 74.249.206.207:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/aa.php"] [unique_id "aoSD7Gr_JutbFb-8svoodwAAAbU"] [Tue Aug 18 13:10:20.234492 2026] [security2:error] [pid 167459:tid 167652] [client 40.74.65.169:49096] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/1.php"] [unique_id "aoSD7Gr_JutbFb-8svooeAAAAc4"] [Tue Aug 18 13:10:20.234599 2026] [security2:error] [pid 167459:tid 167652] [client 40.74.65.169:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/1.php"] [unique_id "aoSD7Gr_JutbFb-8svooeAAAAc4"] [Tue Aug 18 13:10:20.247622 2026] [security2:error] [pid 167459:tid 167647] [client 20.215.241.237:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/doc.php"] [unique_id "aoSD7Gr_JutbFb-8svooeQAAAck"] [Tue Aug 18 13:10:20.348841 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:20.349098 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:20.357013 2026] [security2:error] [pid 167459:tid 167639] [client 20.51.153.15:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kl.php"] [unique_id "aoSD7Gr_JutbFb-8svoofwAAAcE"] [Tue Aug 18 13:10:20.366262 2026] [security2:error] [pid 167459:tid 167630] [client 52.139.47.57:9889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/tiny.php"] [unique_id "aoSD7Gr_JutbFb-8svoogAAAAbg"] [Tue Aug 18 13:10:20.406185 2026] [security2:error] [pid 167459:tid 167616] [client 20.116.17.175:22660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/yup.php"] [unique_id "aoSD7Gr_JutbFb-8svoohAAAAao"] [Tue Aug 18 13:10:20.465848 2026] [authz_core:error] [pid 167459:tid 167470] [remote 57.141.22.38:26592] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:20.466256 2026] [authz_core:error] [pid 167459:tid 167470] [remote 57.141.22.38:26592] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:20.504858 2026] [security2:error] [pid 167459:tid 167705] [client 158.23.17.4:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ie.php"] [unique_id "aoSD7Gr_JutbFb-8svooigAAAgM"] [Tue Aug 18 13:10:20.521954 2026] [security2:error] [pid 167459:tid 167678] [client 20.118.172.148:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/buy.php"] [unique_id "aoSD7Gr_JutbFb-8svooiwAAAeg"] [Tue Aug 18 13:10:20.597640 2026] [security2:error] [pid 167459:tid 167643] [client 74.248.18.37:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/w1.php"] [unique_id "aoSD7Gr_JutbFb-8svoojwAAAcU"] [Tue Aug 18 13:10:20.622169 2026] [security2:error] [pid 167459:tid 167625] [client 20.51.153.15:13386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gs.php"] [unique_id "aoSD7Gr_JutbFb-8svookAAAAbM"] [Tue Aug 18 13:10:20.646958 2026] [security2:error] [pid 167459:tid 167655] [client 20.104.49.167:10852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/tfm.php"] [unique_id "aoSD7Gr_JutbFb-8svookQAAAdE"] [Tue Aug 18 13:10:20.655535 2026] [security2:error] [pid 167459:tid 167598] [client 68.155.154.236:25367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Requests/library/upload.php"] [unique_id "aoSD7Gr_JutbFb-8svookwAAAZg"] [Tue Aug 18 13:10:20.660432 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:20.660876 2026] [authz_core:error] [pid 167459:tid 167479] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:20.665471 2026] [security2:error] [pid 167459:tid 167620] [client 20.215.241.237:2955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/1337.php"] [unique_id "aoSD7Gr_JutbFb-8svoolQAAAa4"] [Tue Aug 18 13:10:20.701461 2026] [security2:error] [pid 167459:tid 167637] [client 40.74.65.169:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/we.php"] [unique_id "aoSD7Gr_JutbFb-8svoolwAAAb8"] [Tue Aug 18 13:10:20.815274 2026] [security2:error] [pid 167459:tid 167711] [client 52.139.47.57:9891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/tool.php"] [unique_id "aoSD7Gr_JutbFb-8svoomwAAAgk"] [Tue Aug 18 13:10:20.822190 2026] [security2:error] [pid 167459:tid 167682] [client 20.91.215.254:12677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/f7.php"] [unique_id "aoSD7Gr_JutbFb-8svoonAAAAew"] [Tue Aug 18 13:10:20.860060 2026] [security2:error] [pid 167459:tid 167716] [client 40.74.65.169:52297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/alls.php"] [unique_id "aoSD7Gr_JutbFb-8svoonQAAAg4"] [Tue Aug 18 13:10:20.861781 2026] [security2:error] [pid 167459:tid 167671] [client 20.51.153.15:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lw.php"] [unique_id "aoSD7Gr_JutbFb-8svoonwAAAeE"] [Tue Aug 18 13:10:20.898561 2026] [security2:error] [pid 167459:tid 167700] [client 20.118.172.148:60471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/dropdown.php"] [unique_id "aoSD7Gr_JutbFb-8svooowAAAf4"] [Tue Aug 18 13:10:20.925808 2026] [security2:error] [pid 167459:tid 167592] [client 158.23.17.4:9355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/nw.php"] [unique_id "aoSD7Gr_JutbFb-8svoopAAAAZI"] [Tue Aug 18 13:10:20.926116 2026] [security2:error] [pid 167459:tid 167621] [client 40.74.65.169:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/coffee.php"] [unique_id "aoSD7Gr_JutbFb-8svoopQAAAa8"] [Tue Aug 18 13:10:20.962014 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:20.962290 2026] [authz_core:error] [pid 167459:tid 167492] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:20.998209 2026] [security2:error] [pid 167459:tid 167635] [client 213.35.127.232:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD7Gr_JutbFb-8svooqAAAAb0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:21.031018 2026] [security2:error] [pid 167459:tid 167676] [client 20.116.17.175:64855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/222.php"] [unique_id "aoSD7Wr_JutbFb-8svooqQAAAeY"] [Tue Aug 18 13:10:21.038264 2026] [security2:error] [pid 167459:tid 167466] [remote 162.214.205.212:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.205.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "becacao.us"] [uri "/wp-login.php"] [unique_id "aoSD7Wr_JutbFb-8svooqwACBwY"] [Tue Aug 18 13:10:21.106071 2026] [security2:error] [pid 167459:tid 167646] [client 20.215.241.237:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/Njima.php"] [unique_id "aoSD7Wr_JutbFb-8svoorgAAAcg"] [Tue Aug 18 13:10:21.144742 2026] [security2:error] [pid 167459:tid 167710] [client 20.51.153.15:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vj.php"] [unique_id "aoSD7Wr_JutbFb-8svoorwAAAgg"] [Tue Aug 18 13:10:21.149275 2026] [security2:error] [pid 167459:tid 167666] [client 68.155.154.236:25360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/Cachex.php"] [unique_id "aoSD7Wr_JutbFb-8svoosQAAAdw"] [Tue Aug 18 13:10:21.239610 2026] [security2:error] [pid 167459:tid 167686] [client 20.118.172.148:60478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/inputs.php"] [unique_id "aoSD7Wr_JutbFb-8svooswAAAfA"] [Tue Aug 18 13:10:21.242053 2026] [security2:error] [pid 167459:tid 167673] [client 52.139.47.57:35283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/top.php"] [unique_id "aoSD7Wr_JutbFb-8svootAAAAeM"] [Tue Aug 18 13:10:21.265766 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:21.266043 2026] [authz_core:error] [pid 167459:tid 167473] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:21.354968 2026] [security2:error] [pid 167459:tid 167672] [client 20.104.49.167:10777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/tool.php"] [unique_id "aoSD7Wr_JutbFb-8svoovAAAAeI"] [Tue Aug 18 13:10:21.377870 2026] [security2:error] [pid 167459:tid 167639] [client 158.23.17.4:29502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/sb.php"] [unique_id "aoSD7Wr_JutbFb-8svoovQAAAcE"] [Tue Aug 18 13:10:21.398983 2026] [security2:error] [pid 167459:tid 167611] [client 20.51.153.15:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mimes.php"] [unique_id "aoSD7Wr_JutbFb-8svoovgAAAaU"] [Tue Aug 18 13:10:21.486582 2026] [security2:error] [pid 167459:tid 167605] [client 20.91.215.254:14274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/photo.php"] [unique_id "aoSD7Wr_JutbFb-8svooxQAAAZ8"] [Tue Aug 18 13:10:21.525149 2026] [security2:error] [pid 167459:tid 167638] [client 20.215.241.237:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/BIBIL.php"] [unique_id "aoSD7Wr_JutbFb-8svooyAAAAcA"] [Tue Aug 18 13:10:21.535132 2026] [security2:error] [pid 167459:tid 167689] [client 178.153.171.161:7124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD7Wr_JutbFb-8svooyQAAAfM"] [Tue Aug 18 13:10:21.535244 2026] [security2:error] [pid 167459:tid 167689] [client 178.153.171.161:7124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD7Wr_JutbFb-8svooyQAAAfM"] [Tue Aug 18 13:10:21.539597 2026] [security2:error] [pid 167459:tid 167651] [client 40.74.65.169:25430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/coffexium.php"] [unique_id "aoSD7Wr_JutbFb-8svooygAAAc0"] [Tue Aug 18 13:10:21.546870 2026] [security2:error] [pid 167459:tid 167623] [client 157.20.138.62:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD7Wr_JutbFb-8svooywAAAbE"] [Tue Aug 18 13:10:21.547027 2026] [security2:error] [pid 167459:tid 167623] [client 157.20.138.62:64178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD7Wr_JutbFb-8svooywAAAbE"] [Tue Aug 18 13:10:21.564823 2026] [security2:error] [pid 167459:tid 167714] [client 68.155.154.236:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/Menu/fonts/%20backup/log/index/js/wpup.php"] [unique_id "aoSD7Wr_JutbFb-8svoozAAAAgw"] [Tue Aug 18 13:10:21.591692 2026] [security2:error] [pid 167459:tid 167628] [client 20.118.172.148:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/100.php"] [unique_id "aoSD7Wr_JutbFb-8svoozQAAAbY"] [Tue Aug 18 13:10:21.619623 2026] [security2:error] [pid 167459:tid 167678] [client 40.74.65.169:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD7Wr_JutbFb-8svoo0gAAAeg"] [Tue Aug 18 13:10:21.659361 2026] [security2:error] [pid 167459:tid 167675] [client 52.139.47.57:9858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/txets.php"] [unique_id "aoSD7Wr_JutbFb-8svoo1AAAAeU"] [Tue Aug 18 13:10:21.676245 2026] [security2:error] [pid 167459:tid 167698] [client 20.116.17.175:45394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-temp.php"] [unique_id "aoSD7Wr_JutbFb-8svoo1QAAAfw"] [Tue Aug 18 13:10:21.734233 2026] [security2:error] [pid 167459:tid 167625] [client 40.74.65.169:5642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/gdn.php"] [unique_id "aoSD7Wr_JutbFb-8svoo1wAAAbM"] [Tue Aug 18 13:10:21.744733 2026] [security2:error] [pid 167459:tid 167614] [client 74.249.206.207:32850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/img.php"] [unique_id "aoSD7Wr_JutbFb-8svoo2AAAAag"] [Tue Aug 18 13:10:21.751368 2026] [security2:error] [pid 167459:tid 167642] [client 20.51.153.15:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ni.php"] [unique_id "aoSD7Wr_JutbFb-8svoo2QAAAcQ"] [Tue Aug 18 13:10:21.766290 2026] [autoindex:error] [pid 167459:tid 167598] [client 205.210.31.166:63786] AH01276: Cannot serve directory /home3/ezycolorcom/dfvcolor.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:21.794005 2026] [security2:error] [pid 167459:tid 167712] [client 20.118.133.132:31266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/admin.php"] [unique_id "aoSD7Wr_JutbFb-8svoo3AAAAgo"] [Tue Aug 18 13:10:21.819561 2026] [security2:error] [pid 167459:tid 167637] [client 158.23.17.4:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/xj.php"] [unique_id "aoSD7Wr_JutbFb-8svoo3gAAAb8"] [Tue Aug 18 13:10:21.878358 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:21.878809 2026] [authz_core:error] [pid 167459:tid 167545] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:21.884039 2026] [security2:error] [pid 167459:tid 167660] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD7Wr_JutbFb-8svoo3wAB1kQ"] [Tue Aug 18 13:10:21.915170 2026] [security2:error] [pid 167459:tid 167711] [client 20.104.49.167:15742] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/1.php"] [unique_id "aoSD7Wr_JutbFb-8svoo4gAAAgk"] [Tue Aug 18 13:10:21.915256 2026] [security2:error] [pid 167459:tid 167711] [client 20.104.49.167:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/1.php"] [unique_id "aoSD7Wr_JutbFb-8svoo4gAAAgk"] [Tue Aug 18 13:10:21.950588 2026] [security2:error] [pid 167459:tid 167606] [client 20.250.13.23:9330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/deepseek_d.php"] [unique_id "aoSD7Wr_JutbFb-8svoo4wAAAaA"] [Tue Aug 18 13:10:21.961327 2026] [security2:error] [pid 167459:tid 167615] [client 20.171.51.14:31094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/dg.php"] [unique_id "aoSD7Wr_JutbFb-8svoo5AAAAak"] [Tue Aug 18 13:10:21.968784 2026] [security2:error] [pid 167459:tid 167636] [client 20.215.241.237:59735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/too.php"] [unique_id "aoSD7Wr_JutbFb-8svoo5gAAAb4"] [Tue Aug 18 13:10:22.007040 2026] [security2:error] [pid 167459:tid 167709] [client 20.118.172.148:57512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/akc.php"] [unique_id "aoSD7mr_JutbFb-8svoo6QAAAgc"] [Tue Aug 18 13:10:22.015389 2026] [security2:error] [pid 167459:tid 167674] [client 213.35.127.232:55403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD7mr_JutbFb-8svoo6gAAAeQ"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:22.037165 2026] [security2:error] [pid 167459:tid 167595] [client 68.155.154.236:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-2019.php"] [unique_id "aoSD7mr_JutbFb-8svoo7AAAAZU"] [Tue Aug 18 13:10:22.078740 2026] [security2:error] [pid 167459:tid 167624] [client 52.139.47.57:13743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/virus.php"] [unique_id "aoSD7mr_JutbFb-8svoo7gAAAbI"] [Tue Aug 18 13:10:22.083116 2026] [security2:error] [pid 167459:tid 167662] [client 4.232.151.198:38866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/w.php"] [unique_id "aoSD7mr_JutbFb-8svoo8AAAAdg"] [Tue Aug 18 13:10:22.102551 2026] [security2:error] [pid 167459:tid 167670] [client 74.248.133.44:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/wp_wol.php"] [unique_id "aoSD7mr_JutbFb-8svoo8QAAAeA"] [Tue Aug 18 13:10:22.156670 2026] [security2:error] [pid 167459:tid 167687] [client 20.51.153.15:13316] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "portopreguicas.com.br"] [uri "/1.php"] [unique_id "aoSD7mr_JutbFb-8svoo9AAAAfE"] [Tue Aug 18 13:10:22.156775 2026] [security2:error] [pid 167459:tid 167687] [client 20.51.153.15:13316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/1.php"] [unique_id "aoSD7mr_JutbFb-8svoo9AAAAfE"] [Tue Aug 18 13:10:22.162640 2026] [security2:error] [pid 167459:tid 167716] [client 20.91.215.254:23107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-aa.php"] [unique_id "aoSD7mr_JutbFb-8svoo9QAAAg4"] [Tue Aug 18 13:10:22.187038 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:22.187296 2026] [authz_core:error] [pid 167459:tid 167535] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:22.218469 2026] [security2:error] [pid 167459:tid 167680] [client 40.74.65.169:25516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/red.php"] [unique_id "aoSD7mr_JutbFb-8svoo-AAAAeo"] [Tue Aug 18 13:10:22.305679 2026] [security2:error] [pid 167459:tid 167607] [client 40.74.65.169:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSD7mr_JutbFb-8svoo-gAAAaE"] [Tue Aug 18 13:10:22.340956 2026] [security2:error] [pid 167459:tid 167644] [client 158.23.17.4:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ns.php"] [unique_id "aoSD7mr_JutbFb-8svoo_QAAAcY"] [Tue Aug 18 13:10:22.350373 2026] [security2:error] [pid 167459:tid 167672] [client 168.62.48.100:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/kopyw.php"] [unique_id "aoSD7mr_JutbFb-8svoo_wAAAeI"] [Tue Aug 18 13:10:22.352567 2026] [security2:error] [pid 167459:tid 167639] [client 20.116.17.175:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/spadex.php"] [unique_id "aoSD7mr_JutbFb-8svopAAAAAcE"] [Tue Aug 18 13:10:22.362884 2026] [security2:error] [pid 167459:tid 167619] [client 20.118.172.148:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "aoSD7mr_JutbFb-8svopAQAAAa0"] [Tue Aug 18 13:10:22.387358 2026] [security2:error] [pid 167459:tid 167656] [client 20.215.241.237:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.241.215.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.classeanovohamburgo.com.br"] [uri "/g3.php"] [unique_id "aoSD7mr_JutbFb-8svopAgAAAdI"] [Tue Aug 18 13:10:22.444779 2026] [security2:error] [pid 167459:tid 167663] [client 20.51.153.15:13403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/88.php"] [unique_id "aoSD7mr_JutbFb-8svopBAAAAdk"] [Tue Aug 18 13:10:22.489204 2026] [authz_core:error] [pid 167459:tid 167510] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:22.489468 2026] [authz_core:error] [pid 167459:tid 167510] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:22.491219 2026] [security2:error] [pid 167459:tid 167613] [client 52.139.47.57:13757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/we.php"] [unique_id "aoSD7mr_JutbFb-8svopBgAAAac"] [Tue Aug 18 13:10:22.556482 2026] [security2:error] [pid 167459:tid 167623] [client 40.74.65.169:6274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/166.php"] [unique_id "aoSD7mr_JutbFb-8svopCAAAAbE"] [Tue Aug 18 13:10:22.701623 2026] [security2:error] [pid 167459:tid 167620] [client 20.51.153.15:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/hj.php"] [unique_id "aoSD7mr_JutbFb-8svopDAAAAa4"] [Tue Aug 18 13:10:22.705704 2026] [security2:error] [pid 167459:tid 167693] [client 20.104.49.167:16090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/dev1s.php"] [unique_id "aoSD7mr_JutbFb-8svopDgAAAfc"] [Tue Aug 18 13:10:22.705730 2026] [security2:error] [pid 167459:tid 167713] [client 74.249.206.207:22938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/222.php"] [unique_id "aoSD7mr_JutbFb-8svopDQAAAgs"] [Tue Aug 18 13:10:22.751189 2026] [security2:error] [pid 167459:tid 167704] [client 68.155.154.236:25378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/social-link/index.php"] [unique_id "aoSD7mr_JutbFb-8svopEQAAAgI"] [Tue Aug 18 13:10:22.787690 2026] [security2:error] [pid 167459:tid 167637] [client 20.118.172.148:60026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/php.php"] [unique_id "aoSD7mr_JutbFb-8svopGAAAAb8"] [Tue Aug 18 13:10:22.804400 2026] [security2:error] [pid 167459:tid 167678] [client 20.91.215.254:14332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/d.php"] [unique_id "aoSD7mr_JutbFb-8svopGQAAAeg"] [Tue Aug 18 13:10:22.808900 2026] [security2:error] [pid 167459:tid 167703] [client 158.23.17.4:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/gk.php"] [unique_id "aoSD7mr_JutbFb-8svopGgAAAgE"] [Tue Aug 18 13:10:22.902335 2026] [security2:error] [pid 167459:tid 167697] [client 40.74.65.169:52263] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "aoSD7mr_JutbFb-8svopHgAAAfs"] [Tue Aug 18 13:10:22.945773 2026] [security2:error] [pid 167459:tid 167606] [client 20.51.153.15:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ij.php"] [unique_id "aoSD7mr_JutbFb-8svopIAAAAaA"] [Tue Aug 18 13:10:22.980672 2026] [security2:error] [pid 167459:tid 167706] [client 20.116.17.175:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSD7mr_JutbFb-8svopJAAAAgQ"] [Tue Aug 18 13:10:22.992502 2026] [security2:error] [pid 167459:tid 167632] [client 40.74.65.169:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/yj09.php"] [unique_id "aoSD7mr_JutbFb-8svopJQAAAbo"] [Tue Aug 18 13:10:23.031646 2026] [security2:error] [pid 167459:tid 167640] [client 213.35.127.232:55615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD72r_JutbFb-8svopKwAAAcI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:23.116888 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:23.117142 2026] [authz_core:error] [pid 167459:tid 167564] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:23.211231 2026] [security2:error] [pid 167459:tid 167680] [client 52.139.47.57:13729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/work.php"] [unique_id "aoSD72r_JutbFb-8svopNgAAAeo"] [Tue Aug 18 13:10:23.231404 2026] [security2:error] [pid 167459:tid 167673] [client 20.51.153.15:2046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ud.php"] [unique_id "aoSD72r_JutbFb-8svopOQAAAeM"] [Tue Aug 18 13:10:23.235612 2026] [authz_core:error] [pid 167459:tid 167568] [remote 57.141.22.119:48866] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:23.235897 2026] [authz_core:error] [pid 167459:tid 167568] [remote 57.141.22.119:48866] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:23.236151 2026] [security2:error] [pid 167459:tid 167628] [client 20.250.13.23:41570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/function/function.php"] [unique_id "aoSD72r_JutbFb-8svopOgAAAbY"] [Tue Aug 18 13:10:23.237161 2026] [security2:error] [pid 167459:tid 167681] [client 68.155.154.236:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/.cache/x.php"] [unique_id "aoSD72r_JutbFb-8svopOwAAAes"] [Tue Aug 18 13:10:23.262294 2026] [security2:error] [pid 167459:tid 167607] [client 20.104.49.167:22077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/we.php"] [unique_id "aoSD72r_JutbFb-8svopPAAAAaE"] [Tue Aug 18 13:10:23.283710 2026] [security2:error] [pid 167459:tid 167627] [client 20.118.133.132:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupobelmais.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD72r_JutbFb-8svopPQAAAbU"] [Tue Aug 18 13:10:23.320601 2026] [security2:error] [pid 167459:tid 167647] [client 40.74.65.169:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/file3.php"] [unique_id "aoSD72r_JutbFb-8svopPwAAAck"] [Tue Aug 18 13:10:23.350145 2026] [security2:error] [pid 167459:tid 167603] [client 20.118.172.148:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/t.php"] [unique_id "aoSD72r_JutbFb-8svopQAAAAZ0"] [Tue Aug 18 13:10:23.352460 2026] [security2:error] [pid 167459:tid 167611] [client 158.23.17.4:10990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/wn.php"] [unique_id "aoSD72r_JutbFb-8svopQQAAAaU"] [Tue Aug 18 13:10:23.414211 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:23.414485 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:23.423124 2026] [security2:error] [pid 167459:tid 167710] [client 4.232.151.198:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/archive.php"] [unique_id "aoSD72r_JutbFb-8svopRAAAAgg"] [Tue Aug 18 13:10:23.488259 2026] [security2:error] [pid 167459:tid 167641] [client 20.51.153.15:13396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ip.php"] [unique_id "aoSD72r_JutbFb-8svopRQAAAcM"] [Tue Aug 18 13:10:23.515535 2026] [security2:error] [pid 167459:tid 167591] [client 20.91.215.254:12713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/widgets.php"] [unique_id "aoSD72r_JutbFb-8svopRwAAAZE"] [Tue Aug 18 13:10:23.518879 2026] [security2:error] [pid 167459:tid 167646] [client 20.116.17.175:22718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/srontol.php"] [unique_id "aoSD72r_JutbFb-8svopSAAAAcg"] [Tue Aug 18 13:10:23.585032 2026] [security2:error] [pid 167459:tid 167679] [client 40.74.65.169:52308] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/Text/"] [unique_id "aoSD72r_JutbFb-8svopSgAAAek"] [Tue Aug 18 13:10:23.626349 2026] [security2:error] [pid 167459:tid 167605] [client 52.139.47.57:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin.php"] [unique_id "aoSD72r_JutbFb-8svopTAAAAZ8"] [Tue Aug 18 13:10:23.636816 2026] [security2:error] [pid 167459:tid 167675] [client 74.249.206.207:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/key.php"] [unique_id "aoSD72r_JutbFb-8svopTgAAAeU"] [Tue Aug 18 13:10:23.666101 2026] [security2:error] [pid 167459:tid 167610] [client 40.74.65.169:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/scxy.php"] [unique_id "aoSD72r_JutbFb-8svopTwAAAaQ"] [Tue Aug 18 13:10:23.691030 2026] [security2:error] [pid 167459:tid 167625] [client 68.155.154.236:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/nextpage/index.php"] [unique_id "aoSD72r_JutbFb-8svopUQAAAbM"] [Tue Aug 18 13:10:23.713879 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:23.714166 2026] [authz_core:error] [pid 167459:tid 167546] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:23.789474 2026] [security2:error] [pid 167459:tid 167704] [client 20.51.153.15:13350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/99.php"] [unique_id "aoSD72r_JutbFb-8svopVQAAAgI"] [Tue Aug 18 13:10:23.802567 2026] [security2:error] [pid 167459:tid 167714] [client 74.248.18.37:30619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-login.php"] [unique_id "aoSD72r_JutbFb-8svopVgAAAgw"] [Tue Aug 18 13:10:23.812762 2026] [security2:error] [pid 167459:tid 167589] [client 216.73.161.216:30033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-login.php"] [unique_id "aoSD72r_JutbFb-8svopVwAAAY8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:10:23.827963 2026] [security2:error] [pid 167459:tid 167678] [client 158.23.17.4:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/app.php"] [unique_id "aoSD72r_JutbFb-8svopWQAAAeg"] [Tue Aug 18 13:10:23.881453 2026] [security2:error] [pid 167459:tid 167667] [client 20.118.172.148:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/index/function.php"] [unique_id "aoSD72r_JutbFb-8svopWwAAAd0"] [Tue Aug 18 13:10:23.952698 2026] [security2:error] [pid 167459:tid 167686] [client 197.184.64.235:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD72r_JutbFb-8svopXQAAAfA"] [Tue Aug 18 13:10:23.952839 2026] [security2:error] [pid 167459:tid 167686] [client 197.184.64.235:42706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD72r_JutbFb-8svopXQAAAfA"] [Tue Aug 18 13:10:23.958407 2026] [security2:error] [pid 167459:tid 167694] [client 20.104.49.167:20875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/gdn.php"] [unique_id "aoSD72r_JutbFb-8svopYAAAAfg"] [Tue Aug 18 13:10:24.021253 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:24.021611 2026] [authz_core:error] [pid 167459:tid 167511] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:24.046272 2026] [security2:error] [pid 167459:tid 167620] [client 213.35.127.232:55851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD8Gr_JutbFb-8svopZAAAAa4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:24.116300 2026] [security2:error] [pid 167459:tid 167709] [client 40.74.65.169:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/y.php"] [unique_id "aoSD8Gr_JutbFb-8svopZwAAAgc"] [Tue Aug 18 13:10:24.179312 2026] [security2:error] [pid 167459:tid 167669] [client 68.155.154.236:25385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSD8Gr_JutbFb-8svopaQAAAd8"] [Tue Aug 18 13:10:24.195587 2026] [security2:error] [pid 167459:tid 167640] [client 52.139.47.57:13739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/about.php"] [unique_id "aoSD8Gr_JutbFb-8svopagAAAcI"] [Tue Aug 18 13:10:24.206548 2026] [security2:error] [pid 167459:tid 167615] [client 20.250.13.23:41575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/nw.php"] [unique_id "aoSD8Gr_JutbFb-8svopawAAAak"] [Tue Aug 18 13:10:24.224818 2026] [security2:error] [pid 167459:tid 167621] [client 20.91.215.254:14297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-includes/js/tinymce/themes/login.php"] [unique_id "aoSD8Gr_JutbFb-8svopbAAAAa8"] [Tue Aug 18 13:10:24.281019 2026] [security2:error] [pid 167459:tid 167715] [client 40.74.65.169:52310] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-content/uploads/"] [unique_id "aoSD8Gr_JutbFb-8svopbwAAAg0"] [Tue Aug 18 13:10:24.351764 2026] [security2:error] [pid 167459:tid 167666] [client 40.74.65.169:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "aoSD8Gr_JutbFb-8svopcwAAAdw"] [Tue Aug 18 13:10:24.354588 2026] [security2:error] [pid 167459:tid 167594] [client 158.23.17.4:63652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/87.php"] [unique_id "aoSD8Gr_JutbFb-8svopdAAAAZQ"] [Tue Aug 18 13:10:24.376416 2026] [security2:error] [pid 167459:tid 167617] [client 20.116.17.175:45387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/file5.php"] [unique_id "aoSD8Gr_JutbFb-8svopdgAAAas"] [Tue Aug 18 13:10:24.420812 2026] [security2:error] [pid 167459:tid 167654] [client 74.249.206.207:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/chosen.php"] [unique_id "aoSD8Gr_JutbFb-8svopegAAAdA"] [Tue Aug 18 13:10:24.471643 2026] [security2:error] [pid 167459:tid 167645] [client 138.36.100.162:42308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopewAAAcc"] [Tue Aug 18 13:10:24.471733 2026] [security2:error] [pid 167459:tid 167645] [client 138.36.100.162:42308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopewAAAcc"] [Tue Aug 18 13:10:24.476153 2026] [security2:error] [pid 167459:tid 167607] [client 20.118.172.148:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wk/index.php"] [unique_id "aoSD8Gr_JutbFb-8svopfAAAAaE"] [Tue Aug 18 13:10:24.537197 2026] [security2:error] [pid 167459:tid 167702] [client 20.51.153.15:2035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/er.php"] [unique_id "aoSD8Gr_JutbFb-8svopgwAAAgA"] [Tue Aug 18 13:10:24.586733 2026] [security2:error] [pid 167459:tid 167591] [client 68.155.154.236:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSD8Gr_JutbFb-8svophgAAAZE"] [Tue Aug 18 13:10:24.594576 2026] [security2:error] [pid 167459:tid 167612] [client 74.248.18.37:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSD8Gr_JutbFb-8svopiQAAAaY"] [Tue Aug 18 13:10:24.597587 2026] [security2:error] [pid 167459:tid 167542] [remote 121.200.216.188:34668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.216.200.121.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/wp-login.php"] [unique_id "aoSD8Gr_JutbFb-8svopiAABvFI"] [Tue Aug 18 13:10:24.614627 2026] [security2:error] [pid 167459:tid 167633] [client 52.139.47.57:18518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/admin.php"] [unique_id "aoSD8Gr_JutbFb-8svopiwAAAbs"] [Tue Aug 18 13:10:24.621246 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:24.621513 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:24.713424 2026] [security2:error] [pid 167459:tid 167593] [client 74.248.133.44:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/fm2.php"] [unique_id "aoSD8Gr_JutbFb-8svopjgAAAZM"] [Tue Aug 18 13:10:24.755282 2026] [security2:error] [pid 167459:tid 167698] [client 178.211.139.240:54153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.139.211.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSD8Gr_JutbFb-8svopjwAAAfw"], referer: www.google.com [Tue Aug 18 13:10:24.827432 2026] [security2:error] [pid 167459:tid 167693] [client 40.74.65.169:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/modric8QWQCC.php"] [unique_id "aoSD8Gr_JutbFb-8svopkgAAAfc"] [Tue Aug 18 13:10:24.850138 2026] [security2:error] [pid 167459:tid 167638] [client 158.23.17.4:9286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/zi.php"] [unique_id "aoSD8Gr_JutbFb-8svoplAAAAcA"] [Tue Aug 18 13:10:24.874956 2026] [security2:error] [pid 167459:tid 167642] [client 20.116.17.175:22699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/yup.php"] [unique_id "aoSD8Gr_JutbFb-8svoplQAAAcQ"] [Tue Aug 18 13:10:24.878004 2026] [security2:error] [pid 167459:tid 167679] [client 20.91.215.254:14334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/abc.php"] [unique_id "aoSD8Gr_JutbFb-8svoplgAAAek"] [Tue Aug 18 13:10:24.878164 2026] [security2:error] [pid 167459:tid 167714] [client 20.51.153.15:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/qk.php"] [unique_id "aoSD8Gr_JutbFb-8svoplwAAAgw"] [Tue Aug 18 13:10:24.900107 2026] [security2:error] [pid 167459:tid 167650] [client 102.213.179.104:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopmQAAAcw"] [Tue Aug 18 13:10:24.900226 2026] [security2:error] [pid 167459:tid 167650] [client 102.213.179.104:49288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopmQAAAcw"] [Tue Aug 18 13:10:24.910962 2026] [security2:error] [pid 167459:tid 167711] [client 196.12.128.158:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopmwAAAgk"] [Tue Aug 18 13:10:24.911157 2026] [security2:error] [pid 167459:tid 167711] [client 196.12.128.158:61126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD8Gr_JutbFb-8svopmwAAAgk"] [Tue Aug 18 13:10:24.964555 2026] [security2:error] [pid 167459:tid 167678] [client 40.74.65.169:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-content/index.php"] [unique_id "aoSD8Gr_JutbFb-8svopngAAAeg"] [Tue Aug 18 13:10:24.991593 2026] [security2:error] [pid 167459:tid 167590] [client 68.155.154.236:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/pullquote/windex.php"] [unique_id "aoSD8Gr_JutbFb-8svopnwAAAZA"] [Tue Aug 18 13:10:24.998696 2026] [security2:error] [pid 167459:tid 167646] [client 74.248.18.37:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/default.php"] [unique_id "aoSD8Gr_JutbFb-8svopoAAAAcg"] [Tue Aug 18 13:10:25.050058 2026] [security2:error] [pid 167459:tid 167667] [client 40.74.65.169:49052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "aoSD8Wr_JutbFb-8svopowAAAd0"] [Tue Aug 18 13:10:25.057880 2026] [security2:error] [pid 167459:tid 167697] [client 20.104.49.167:8389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/166.php"] [unique_id "aoSD8Wr_JutbFb-8svoppAAAAfs"] [Tue Aug 18 13:10:25.068956 2026] [security2:error] [pid 167459:tid 167629] [client 213.35.127.232:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD8Wr_JutbFb-8svoppQAAAbc"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:25.080018 2026] [security2:error] [pid 167459:tid 167671] [client 20.118.172.148:59975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-blink.php"] [unique_id "aoSD8Wr_JutbFb-8svoppgAAAeE"] [Tue Aug 18 13:10:25.128683 2026] [security2:error] [pid 167459:tid 167606] [client 20.51.153.15:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fraie1p4.php"] [unique_id "aoSD8Wr_JutbFb-8svopqAAAAaA"] [Tue Aug 18 13:10:25.144057 2026] [security2:error] [pid 167459:tid 167536] [remote 129.121.123.168:48458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.123.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "m2mit.cloud"] [uri "/wp-login.php"] [unique_id "aoSD8Wr_JutbFb-8svopqQAB-kw"] [Tue Aug 18 13:10:25.170019 2026] [security2:error] [pid 167459:tid 167632] [client 52.139.47.57:9876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "aoSD8Wr_JutbFb-8svopqgAAAbo"] [Tue Aug 18 13:10:25.181477 2026] [autoindex:error] [pid 167459:tid 167620] [client 43.163.112.239:44598] AH01276: Cannot serve directory /home4/cidadedemilao/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:25.182484 2026] [security2:error] [pid 167459:tid 167599] [client 20.118.133.132:45215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/biufile.php"] [unique_id "aoSD8Wr_JutbFb-8svoprAAAAZk"] [Tue Aug 18 13:10:25.225891 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:25.226185 2026] [authz_core:error] [pid 167459:tid 167462] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:25.228166 2026] [security2:error] [pid 167459:tid 167663] [client 74.249.206.207:30327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/wpxml.php"] [unique_id "aoSD8Wr_JutbFb-8svoprgAAAdk"] [Tue Aug 18 13:10:25.366865 2026] [security2:error] [pid 167459:tid 167661] [client 68.155.154.236:25377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/help/crnpwfiu.php"] [unique_id "aoSD8Wr_JutbFb-8svoptgAAAdc"] [Tue Aug 18 13:10:25.397538 2026] [security2:error] [pid 167459:tid 167666] [client 20.51.153.15:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fs.php"] [unique_id "aoSD8Wr_JutbFb-8svopuAAAAdw"] [Tue Aug 18 13:10:25.445044 2026] [security2:error] [pid 167459:tid 167680] [client 158.23.17.4:9344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/92.php"] [unique_id "aoSD8Wr_JutbFb-8svopuwAAAeo"] [Tue Aug 18 13:10:25.527158 2026] [authz_core:error] [pid 167459:tid 167549] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:25.527435 2026] [authz_core:error] [pid 167459:tid 167549] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:25.545512 2026] [security2:error] [pid 167459:tid 167573] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Wr_JutbFb-8svopwAABwXE"] [Tue Aug 18 13:10:25.545764 2026] [security2:error] [pid 167459:tid 167639] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8Wr_JutbFb-8svopwAABwXE"] [Tue Aug 18 13:10:25.557621 2026] [security2:error] [pid 167459:tid 167611] [client 20.118.172.148:60005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/xfun.php"] [unique_id "aoSD8Wr_JutbFb-8svopwQAAAaU"] [Tue Aug 18 13:10:25.566083 2026] [security2:error] [pid 167459:tid 167592] [client 20.91.215.254:14327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/classwithtostring.php"] [unique_id "aoSD8Wr_JutbFb-8svopwgAAAZI"] [Tue Aug 18 13:10:25.568323 2026] [security2:error] [pid 167459:tid 167592] [client 168.62.48.100:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/zznmg.php"] [unique_id "aoSD8Wr_JutbFb-8svopwwAAAZI"] [Tue Aug 18 13:10:25.593164 2026] [security2:error] [pid 167459:tid 167597] [client 40.74.65.169:6222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/modric7Z7J2X.php"] [unique_id "aoSD8Wr_JutbFb-8svopxAAAAZc"] [Tue Aug 18 13:10:25.608686 2026] [security2:error] [pid 167459:tid 167658] [client 178.211.139.240:54195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.139.211.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m2mit.com.br"] [uri "/images/images/cache.php"] [unique_id "aoSD8Wr_JutbFb-8svopxwAAAdQ"], referer: www.google.com [Tue Aug 18 13:10:25.639559 2026] [security2:error] [pid 167459:tid 167648] [client 20.116.17.175:41497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD8Wr_JutbFb-8svopyAAAAco"] [Tue Aug 18 13:10:25.689907 2026] [security2:error] [pid 167459:tid 167690] [client 20.51.153.15:13408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/rb.php"] [unique_id "aoSD8Wr_JutbFb-8svopygAAAfQ"] [Tue Aug 18 13:10:25.692802 2026] [security2:error] [pid 167459:tid 167653] [client 40.74.65.169:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/admin.php"] [unique_id "aoSD8Wr_JutbFb-8svopywAAAc8"] [Tue Aug 18 13:10:25.746867 2026] [security2:error] [pid 167459:tid 167655] [client 40.74.65.169:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/blurbs.php"] [unique_id "aoSD8Wr_JutbFb-8svopzAAAAdE"] [Tue Aug 18 13:10:25.749582 2026] [security2:error] [pid 167459:tid 167651] [client 52.139.47.57:2698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/min.php"] [unique_id "aoSD8Wr_JutbFb-8svopzQAAAc0"] [Tue Aug 18 13:10:25.762733 2026] [security2:error] [pid 167459:tid 167623] [client 68.155.154.236:25390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/plugins/majapahitslot/index.php"] [unique_id "aoSD8Wr_JutbFb-8svopzgAAAbE"] [Tue Aug 18 13:10:25.826417 2026] [security2:error] [pid 167459:tid 167627] [client 213.202.253.4:58061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.253.202.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diogobeltrame.com.br"] [uri "/delpaths.php"] [unique_id "aoSD8Wr_JutbFb-8svop0QAAAbU"], referer: www.google.com [Tue Aug 18 13:10:25.832187 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:25.832647 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:25.971068 2026] [security2:error] [pid 167459:tid 167703] [client 20.51.153.15:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/37.php"] [unique_id "aoSD8Wr_JutbFb-8svop1wAAAgE"] [Tue Aug 18 13:10:25.987815 2026] [security2:error] [pid 167459:tid 167613] [client 74.248.18.37:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/info.php"] [unique_id "aoSD8Wr_JutbFb-8svop2AAAAac"] [Tue Aug 18 13:10:26.072424 2026] [security2:error] [pid 167459:tid 167593] [client 74.248.133.44:51943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/xmlrpc.php0"] [unique_id "aoSD8mr_JutbFb-8svop2wAAAZM"] [Tue Aug 18 13:10:26.081379 2026] [security2:error] [pid 167459:tid 167677] [client 213.35.127.232:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD8mr_JutbFb-8svop3AAAAec"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:26.082872 2026] [security2:error] [pid 167459:tid 167629] [client 52.173.121.69:55565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD8mr_JutbFb-8svop3QAAAbc"] [Tue Aug 18 13:10:26.111181 2026] [security2:error] [pid 167459:tid 167686] [client 68.155.154.236:25348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/post-date/index.php"] [unique_id "aoSD8mr_JutbFb-8svop3wAAAfA"] [Tue Aug 18 13:10:26.134534 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:26.134811 2026] [authz_core:error] [pid 167459:tid 167562] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:26.156167 2026] [security2:error] [pid 167459:tid 167668] [client 20.116.17.175:22751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-the.php"] [unique_id "aoSD8mr_JutbFb-8svop4gAAAd4"] [Tue Aug 18 13:10:26.162394 2026] [security2:error] [pid 167459:tid 167660] [client 52.139.47.57:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/blue/xmrlpc.php"] [unique_id "aoSD8mr_JutbFb-8svop4wAAAdY"] [Tue Aug 18 13:10:26.202600 2026] [security2:error] [pid 167459:tid 167699] [client 47.128.49.54:19202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "armazemdolarrs.com.br"] [uri "/robots.txt"] [unique_id "aoSD8mr_JutbFb-8svop5AAAAf0"] [Tue Aug 18 13:10:26.206873 2026] [security2:error] [pid 167459:tid 167632] [client 20.118.133.132:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/coffexium.php"] [unique_id "aoSD8mr_JutbFb-8svop5QAAAbo"] [Tue Aug 18 13:10:26.213087 2026] [security2:error] [pid 167459:tid 167609] [client 20.91.215.254:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/adminfuns.php"] [unique_id "aoSD8mr_JutbFb-8svop5gAAAaM"] [Tue Aug 18 13:10:26.265877 2026] [security2:error] [pid 167459:tid 167620] [client 20.51.153.15:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/md.php"] [unique_id "aoSD8mr_JutbFb-8svop6QAAAa4"] [Tue Aug 18 13:10:26.365036 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/modricXP4D68.php"] [unique_id "aoSD8mr_JutbFb-8svop6wAAAbI"] [Tue Aug 18 13:10:26.384945 2026] [security2:error] [pid 167459:tid 167661] [client 40.74.65.169:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/file52.php"] [unique_id "aoSD8mr_JutbFb-8svop7AAAAdc"] [Tue Aug 18 13:10:26.398381 2026] [security2:error] [pid 167459:tid 167708] [client 114.119.129.176:31639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.meucrescer.com.br"] [uri "/storage/app/uploads/public/684/18e/701/68418e701e6ee839111822.webp"] [unique_id "aoSD8mr_JutbFb-8svop7QAAAgY"], referer: https://www.meucrescer.com.br/empreendimentos/meu-crescer-meier [Tue Aug 18 13:10:26.418080 2026] [security2:error] [pid 167459:tid 167684] [client 49.145.211.146:11128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8mr_JutbFb-8svop7wAAAe4"] [Tue Aug 18 13:10:26.418194 2026] [security2:error] [pid 167459:tid 167684] [client 49.145.211.146:11128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8mr_JutbFb-8svop7wAAAe4"] [Tue Aug 18 13:10:26.422321 2026] [security2:error] [pid 167459:tid 167618] [client 20.250.13.23:9862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/xleet.php"] [unique_id "aoSD8mr_JutbFb-8svop8AAAAaw"] [Tue Aug 18 13:10:26.435179 2026] [authz_core:error] [pid 167459:tid 167504] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:26.435443 2026] [authz_core:error] [pid 167459:tid 167504] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:26.437281 2026] [security2:error] [pid 167459:tid 167617] [client 40.74.65.169:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/bajah.php"] [unique_id "aoSD8mr_JutbFb-8svop8gAAAas"] [Tue Aug 18 13:10:26.517033 2026] [security2:error] [pid 167459:tid 167695] [client 20.51.153.15:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/iy.php"] [unique_id "aoSD8mr_JutbFb-8svop9gAAAfk"] [Tue Aug 18 13:10:26.582592 2026] [security2:error] [pid 167459:tid 167598] [client 49.37.150.8:63444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8mr_JutbFb-8svop-AAAAZg"] [Tue Aug 18 13:10:26.584838 2026] [security2:error] [pid 167459:tid 167664] [client 52.139.47.57:13709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "aoSD8mr_JutbFb-8svop-QAAAdo"] [Tue Aug 18 13:10:26.585091 2026] [security2:error] [pid 167459:tid 167598] [client 49.37.150.8:63444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD8mr_JutbFb-8svop-AAAAZg"] [Tue Aug 18 13:10:26.600320 2026] [security2:error] [pid 167459:tid 167607] [client 158.23.17.4:9407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/jm.php"] [unique_id "aoSD8mr_JutbFb-8svop-wAAAaE"] [Tue Aug 18 13:10:26.657684 2026] [security2:error] [pid 167459:tid 167644] [client 68.155.154.236:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/navigation-submenu/index.php"] [unique_id "aoSD8mr_JutbFb-8svop_AAAAcY"] [Tue Aug 18 13:10:26.734970 2026] [security2:error] [pid 167459:tid 167701] [client 74.249.206.207:30323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/file1221.php"] [unique_id "aoSD8mr_JutbFb-8svop_wAAAf8"] [Tue Aug 18 13:10:26.736791 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:26.737091 2026] [authz_core:error] [pid 167459:tid 167527] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:26.776677 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/cong.php"] [unique_id "aoSD8mr_JutbFb-8svoqAgAAAdI"] [Tue Aug 18 13:10:26.847483 2026] [security2:error] [pid 167459:tid 167707] [client 20.91.215.254:12806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/abc.php"] [unique_id "aoSD8mr_JutbFb-8svoqBQAAAgU"] [Tue Aug 18 13:10:26.860597 2026] [security2:error] [pid 167459:tid 167651] [client 20.118.172.148:57478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/p.php"] [unique_id "aoSD8mr_JutbFb-8svoqBwAAAc0"] [Tue Aug 18 13:10:27.016457 2026] [security2:error] [pid 167459:tid 167704] [client 20.51.153.15:13368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/og.php"] [unique_id "aoSD82r_JutbFb-8svoqDwAAAgI"] [Tue Aug 18 13:10:27.016700 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:13737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/index.php"] [unique_id "aoSD82r_JutbFb-8svoqEAAAAaQ"] [Tue Aug 18 13:10:27.018884 2026] [security2:error] [pid 167459:tid 167580] [remote 3.109.96.140:45728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.96.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samarapraseres.com.br"] [uri "/wp-login.php"] [unique_id "aoSD82r_JutbFb-8svoqDgABzHg"] [Tue Aug 18 13:10:27.027636 2026] [security2:error] [pid 167459:tid 167645] [client 74.248.18.37:53858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/a.php"] [unique_id "aoSD82r_JutbFb-8svoqEQAAAcc"] [Tue Aug 18 13:10:27.035764 2026] [authz_core:error] [pid 167459:tid 167513] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:27.036039 2026] [authz_core:error] [pid 167459:tid 167513] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:27.098801 2026] [security2:error] [pid 167459:tid 167713] [client 40.74.65.169:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/geck.php"] [unique_id "aoSD82r_JutbFb-8svoqFAAAAgs"] [Tue Aug 18 13:10:27.099835 2026] [security2:error] [pid 167459:tid 167702] [client 213.35.127.232:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD82r_JutbFb-8svoqFQAAAgA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:27.113100 2026] [security2:error] [pid 167459:tid 167613] [client 40.74.65.169:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/domvf.php"] [unique_id "aoSD82r_JutbFb-8svoqFgAAAac"] [Tue Aug 18 13:10:27.148665 2026] [security2:error] [pid 167459:tid 167697] [client 158.23.17.4:10961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/wj.php"] [unique_id "aoSD82r_JutbFb-8svoqGQAAAfs"] [Tue Aug 18 13:10:27.152026 2026] [security2:error] [pid 167459:tid 167657] [client 20.171.51.14:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/bm.php"] [unique_id "aoSD82r_JutbFb-8svoqGgAAAdM"] [Tue Aug 18 13:10:27.160830 2026] [security2:error] [pid 167459:tid 167629] [client 40.74.65.169:5661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.rkveiculos.com"] [uri "/clara.php"] [unique_id "aoSD82r_JutbFb-8svoqGwAAAbc"] [Tue Aug 18 13:10:27.175748 2026] [security2:error] [pid 167459:tid 167627] [client 20.250.13.23:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/wp.php"] [unique_id "aoSD82r_JutbFb-8svoqHAAAAbU"] [Tue Aug 18 13:10:27.227176 2026] [security2:error] [pid 167459:tid 167696] [client 20.116.17.175:22666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/xwpg.php"] [unique_id "aoSD82r_JutbFb-8svoqHwAAAfo"] [Tue Aug 18 13:10:27.310054 2026] [security2:error] [pid 167459:tid 167636] [client 20.51.153.15:13417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lp.php"] [unique_id "aoSD82r_JutbFb-8svoqIQAAAb4"] [Tue Aug 18 13:10:27.336497 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:27.336804 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:27.402204 2026] [security2:error] [pid 167459:tid 167662] [client 68.155.154.236:4056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/css/dist/block-directory/upload.php"] [unique_id "aoSD82r_JutbFb-8svoqKQAAAdg"] [Tue Aug 18 13:10:27.424967 2026] [security2:error] [pid 167459:tid 167694] [client 185.191.171.1:21564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754289153/1756598400/"] [unique_id "aoSD82r_JutbFb-8svoqLAAAAfg"] [Tue Aug 18 13:10:27.425098 2026] [security2:error] [pid 167459:tid 167694] [client 185.191.171.1:21564] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "iicn.edu.mz"] [uri "/events-category/eventos/1754289153/1756598400/"] [unique_id "aoSD82r_JutbFb-8svoqLAAAAfg"] [Tue Aug 18 13:10:27.435757 2026] [security2:error] [pid 167459:tid 167600] [client 52.139.47.57:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/light/flower.php"] [unique_id "aoSD82r_JutbFb-8svoqLQAAAZo"] [Tue Aug 18 13:10:27.502641 2026] [security2:error] [pid 167459:tid 167633] [client 103.120.71.157:59257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqMAAAAbs"] [Tue Aug 18 13:10:27.502973 2026] [security2:error] [pid 167459:tid 167617] [client 52.173.121.69:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD82r_JutbFb-8svoqLwAAAas"] [Tue Aug 18 13:10:27.504499 2026] [security2:error] [pid 167459:tid 167633] [client 103.120.71.157:59257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqMAAAAbs"] [Tue Aug 18 13:10:27.541439 2026] [security2:error] [pid 167459:tid 167699] [client 20.91.215.254:13046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/sf.php"] [unique_id "aoSD82r_JutbFb-8svoqMgAAAf0"] [Tue Aug 18 13:10:27.556598 2026] [security2:error] [pid 167459:tid 167628] [client 20.116.17.175:45437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/dex.php"] [unique_id "aoSD82r_JutbFb-8svoqMwAAAbY"] [Tue Aug 18 13:10:27.563372 2026] [security2:error] [pid 167459:tid 167461] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqNAAB2wE"] [Tue Aug 18 13:10:27.563506 2026] [security2:error] [pid 167459:tid 167665] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqNAAB2wE"] [Tue Aug 18 13:10:27.568979 2026] [security2:error] [pid 167459:tid 167589] [client 20.118.172.148:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSD82r_JutbFb-8svoqNQAAAY8"] [Tue Aug 18 13:10:27.576070 2026] [security2:error] [pid 167459:tid 167688] [client 74.249.206.207:16148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/nox.php"] [unique_id "aoSD82r_JutbFb-8svoqNgAAAfI"] [Tue Aug 18 13:10:27.596964 2026] [security2:error] [pid 167459:tid 167682] [client 86.120.159.145:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqOAAAAew"] [Tue Aug 18 13:10:27.597356 2026] [security2:error] [pid 167459:tid 167682] [client 86.120.159.145:63176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD82r_JutbFb-8svoqOAAAAew"] [Tue Aug 18 13:10:27.600119 2026] [security2:error] [pid 167459:tid 167603] [client 20.104.49.167:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/file3.php"] [unique_id "aoSD82r_JutbFb-8svoqOQAAAZ0"] [Tue Aug 18 13:10:27.604348 2026] [security2:error] [pid 167459:tid 167611] [client 20.51.153.15:13435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ey.php"] [unique_id "aoSD82r_JutbFb-8svoqOgAAAaU"] [Tue Aug 18 13:10:27.638710 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:27.639019 2026] [authz_core:error] [pid 167459:tid 167550] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:27.686758 2026] [security2:error] [pid 167459:tid 167690] [client 158.23.17.4:9373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/74.php"] [unique_id "aoSD82r_JutbFb-8svoqPwAAAfQ"] [Tue Aug 18 13:10:27.786928 2026] [security2:error] [pid 167459:tid 167649] [client 40.74.65.169:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/biufile.php"] [unique_id "aoSD82r_JutbFb-8svoqRAAAAcs"] [Tue Aug 18 13:10:27.815235 2026] [security2:error] [pid 167459:tid 167704] [client 40.74.65.169:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/fpwch.php"] [unique_id "aoSD82r_JutbFb-8svoqRgAAAgI"] [Tue Aug 18 13:10:27.841957 2026] [security2:error] [pid 167459:tid 167637] [client 20.51.153.15:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lv.php"] [unique_id "aoSD82r_JutbFb-8svoqSAAAAb8"] [Tue Aug 18 13:10:27.863933 2026] [security2:error] [pid 167459:tid 167634] [client 52.139.47.57:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/light/min.php"] [unique_id "aoSD82r_JutbFb-8svoqSQAAAbw"] [Tue Aug 18 13:10:27.940426 2026] [authz_core:error] [pid 167459:tid 167543] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:27.940697 2026] [authz_core:error] [pid 167459:tid 167543] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:27.980437 2026] [security2:error] [pid 167459:tid 167667] [client 20.116.17.175:45404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/xyn.php"] [unique_id "aoSD82r_JutbFb-8svoqTwAAAd0"] [Tue Aug 18 13:10:27.982640 2026] [security2:error] [pid 167459:tid 167693] [client 74.248.18.37:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/chosen.php"] [unique_id "aoSD82r_JutbFb-8svoqUAAAAfc"] [Tue Aug 18 13:10:28.009858 2026] [security2:error] [pid 167459:tid 167701] [client 20.250.13.23:53406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/155.php"] [unique_id "aoSD9Gr_JutbFb-8svoqVAAAAf8"] [Tue Aug 18 13:10:28.015400 2026] [security2:error] [pid 167459:tid 167629] [client 20.104.49.167:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/y.php"] [unique_id "aoSD9Gr_JutbFb-8svoqVQAAAbc"] [Tue Aug 18 13:10:28.017095 2026] [security2:error] [pid 167459:tid 167671] [client 20.118.172.148:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/aaa.php"] [unique_id "aoSD9Gr_JutbFb-8svoqWAAAAeE"] [Tue Aug 18 13:10:28.044910 2026] [security2:error] [pid 167459:tid 167696] [client 68.155.154.236:25357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/update/wpupex.php"] [unique_id "aoSD9Gr_JutbFb-8svoqWgAAAfo"] [Tue Aug 18 13:10:28.098277 2026] [security2:error] [pid 167459:tid 167632] [client 20.51.153.15:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/51.php"] [unique_id "aoSD9Gr_JutbFb-8svoqXwAAAbo"] [Tue Aug 18 13:10:28.112174 2026] [security2:error] [pid 167459:tid 167625] [client 213.35.127.232:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD9Gr_JutbFb-8svoqYAAAAbM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:28.190803 2026] [security2:error] [pid 167459:tid 167706] [client 20.91.215.254:12699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/chosen.php"] [unique_id "aoSD9Gr_JutbFb-8svoqYgAAAgQ"] [Tue Aug 18 13:10:28.242911 2026] [security2:error] [pid 167459:tid 167645] [client 74.248.18.37:26804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/i.php"] [unique_id "aoSD9Gr_JutbFb-8svoqaAAAAcc"] [Tue Aug 18 13:10:28.311457 2026] [security2:error] [pid 167459:tid 167670] [client 52.139.47.57:9905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/colors/ocean/min.php"] [unique_id "aoSD9Gr_JutbFb-8svoqawAAAeA"] [Tue Aug 18 13:10:28.323812 2026] [security2:error] [pid 167459:tid 167695] [client 74.249.206.207:30279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/akismet.php"] [unique_id "aoSD9Gr_JutbFb-8svoqbAAAAfk"] [Tue Aug 18 13:10:28.346122 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:28.346395 2026] [authz_core:error] [pid 167459:tid 167502] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:28.390742 2026] [security2:error] [pid 167459:tid 167660] [client 20.118.172.148:59979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/term.php"] [unique_id "aoSD9Gr_JutbFb-8svoqcQAAAdY"] [Tue Aug 18 13:10:28.408044 2026] [security2:error] [pid 167459:tid 167607] [client 20.51.153.15:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ew.php"] [unique_id "aoSD9Gr_JutbFb-8svoqcgAAAaE"] [Tue Aug 18 13:10:28.478549 2026] [security2:error] [pid 167459:tid 167682] [client 68.155.154.236:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-admin/install.php"] [unique_id "aoSD9Gr_JutbFb-8svoqdQAAAew"] [Tue Aug 18 13:10:28.486064 2026] [security2:error] [pid 167459:tid 167603] [client 40.74.65.169:52315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/dejavu.php"] [unique_id "aoSD9Gr_JutbFb-8svoqdgAAAZ0"] [Tue Aug 18 13:10:28.491751 2026] [security2:error] [pid 167459:tid 167592] [client 20.116.17.175:22721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSD9Gr_JutbFb-8svoqdwAAAZI"] [Tue Aug 18 13:10:28.511116 2026] [security2:error] [pid 167459:tid 167658] [client 40.74.65.169:49083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/adminner.php"] [unique_id "aoSD9Gr_JutbFb-8svoqeQAAAdQ"] [Tue Aug 18 13:10:28.638224 2026] [security2:error] [pid 167459:tid 167690] [client 158.23.17.4:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/av.php"] [unique_id "aoSD9Gr_JutbFb-8svoqfAAAAfQ"] [Tue Aug 18 13:10:28.647791 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:28.648077 2026] [authz_core:error] [pid 167459:tid 167576] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:28.734578 2026] [security2:error] [pid 167459:tid 167638] [client 52.139.47.57:9867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/css/min.php"] [unique_id "aoSD9Gr_JutbFb-8svoqgAAAAcA"] [Tue Aug 18 13:10:28.740478 2026] [security2:error] [pid 167459:tid 167707] [client 20.51.153.15:1976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pqr.php"] [unique_id "aoSD9Gr_JutbFb-8svoqggAAAgU"] [Tue Aug 18 13:10:28.743981 2026] [security2:error] [pid 167459:tid 167619] [client 20.116.17.175:44718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/yup.php"] [unique_id "aoSD9Gr_JutbFb-8svoqhAAAAa0"] [Tue Aug 18 13:10:28.773089 2026] [security2:error] [pid 167459:tid 167623] [client 74.249.206.207:40165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/admin.php"] [unique_id "aoSD9Gr_JutbFb-8svoqhQAAAbE"] [Tue Aug 18 13:10:28.818758 2026] [security2:error] [pid 167459:tid 167654] [client 74.248.18.37:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSD9Gr_JutbFb-8svoqhwAAAdA"] [Tue Aug 18 13:10:28.924378 2026] [security2:error] [pid 167459:tid 167653] [client 20.91.215.254:12854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/u.php"] [unique_id "aoSD9Gr_JutbFb-8svoqjAAAAc8"] [Tue Aug 18 13:10:28.927177 2026] [security2:error] [pid 167459:tid 167646] [client 20.118.172.148:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/7.php"] [unique_id "aoSD9Gr_JutbFb-8svoqjQAAAcg"] [Tue Aug 18 13:10:29.001288 2026] [security2:error] [pid 167459:tid 167643] [client 20.116.17.175:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-good.php"] [unique_id "aoSD9Gr_JutbFb-8svoqkAAAAcU"] [Tue Aug 18 13:10:29.116431 2026] [security2:error] [pid 167459:tid 167657] [client 158.23.17.4:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ag.php"] [unique_id "aoSD9Wr_JutbFb-8svoqkgAAAdM"] [Tue Aug 18 13:10:29.124804 2026] [security2:error] [pid 167459:tid 167700] [client 213.35.127.232:57011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD9Wr_JutbFb-8svoqkwAAAf4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:29.151033 2026] [security2:error] [pid 167459:tid 167613] [client 52.139.47.57:2717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/data.php"] [unique_id "aoSD9Wr_JutbFb-8svoqlgAAAac"] [Tue Aug 18 13:10:29.160484 2026] [authz_core:error] [pid 167459:tid 167558] [remote 57.141.22.41:44598] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:29.160972 2026] [authz_core:error] [pid 167459:tid 167558] [remote 57.141.22.41:44598] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:29.165484 2026] [security2:error] [pid 167459:tid 167608] [client 78.47.98.55:54898] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSD9Gr_JutbFb-8svoqgwAAAaI"], referer: https://www.saojudas.com.br/ [Tue Aug 18 13:10:29.185629 2026] [security2:error] [pid 167459:tid 167668] [client 40.74.65.169:25463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/aaf.php"] [unique_id "aoSD9Wr_JutbFb-8svoqmQAAAd4"] [Tue Aug 18 13:10:29.187602 2026] [security2:error] [pid 167459:tid 167655] [client 40.74.65.169:49049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/abcd.php"] [unique_id "aoSD9Wr_JutbFb-8svoqmgAAAdE"] [Tue Aug 18 13:10:29.212525 2026] [security2:error] [pid 167459:tid 167705] [client 20.104.49.167:22067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/modric8QWQCC.php"] [unique_id "aoSD9Wr_JutbFb-8svoqnAAAAgM"] [Tue Aug 18 13:10:29.250997 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:29.251327 2026] [authz_core:error] [pid 167459:tid 167541] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:29.263643 2026] [security2:error] [pid 167459:tid 167609] [client 168.62.48.100:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/bhfnd.php"] [unique_id "aoSD9Wr_JutbFb-8svoqoQAAAaM"] [Tue Aug 18 13:10:29.274099 2026] [security2:error] [pid 167459:tid 167611] [client 52.28.162.93:28714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSD9Gr_JutbFb-8svoqfgAAAaU"], referer: https://www.saojudas.com.br [Tue Aug 18 13:10:29.300002 2026] [autoindex:error] [pid 167459:tid 167599] [client 82.102.18.182:46410] AH01276: Cannot serve directory /home4/ctrrefrigeracao/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:29.352590 2026] [security2:error] [pid 167459:tid 167662] [client 114.119.136.203:33393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.barretoveiculos.com"] [uri "/veiculo/257463/207-sedan-passion-xs-1-6-flex-16v-4p-aut"] [unique_id "aoSD9Wr_JutbFb-8svoqpQAAAdg"], referer: http://www.barretoveiculos.com/ [Tue Aug 18 13:10:29.501800 2026] [security2:error] [pid 167459:tid 167680] [client 82.102.18.188:41130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aoSD9Wr_JutbFb-8svoqqwAAAeo"] [Tue Aug 18 13:10:29.512212 2026] [security2:error] [pid 167459:tid 167642] [client 158.23.17.4:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ig.php"] [unique_id "aoSD9Wr_JutbFb-8svoqrQAAAcQ"] [Tue Aug 18 13:10:29.527796 2026] [security2:error] [pid 167459:tid 167670] [client 20.118.172.148:57535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/file5.php"] [unique_id "aoSD9Wr_JutbFb-8svoqrgAAAeA"] [Tue Aug 18 13:10:29.541481 2026] [security2:error] [pid 167459:tid 167590] [client 20.51.153.15:13355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/an.php"] [unique_id "aoSD9Wr_JutbFb-8svoqsQAAAZA"] [Tue Aug 18 13:10:29.559367 2026] [security2:error] [pid 167459:tid 167706] [client 52.139.47.57:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/home.php"] [unique_id "aoSD9Wr_JutbFb-8svoqtAAAAgQ"] [Tue Aug 18 13:10:29.622135 2026] [security2:error] [pid 167459:tid 167688] [client 68.155.154.236:25356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "aoSD9Wr_JutbFb-8svoqtgAAAfI"] [Tue Aug 18 13:10:29.622932 2026] [security2:error] [pid 167459:tid 167712] [client 223.185.37.47:10883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD9Wr_JutbFb-8svoqtwAAAgo"] [Tue Aug 18 13:10:29.623024 2026] [security2:error] [pid 167459:tid 167712] [client 223.185.37.47:10883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSD9Wr_JutbFb-8svoqtwAAAgo"] [Tue Aug 18 13:10:29.657703 2026] [security2:error] [pid 167459:tid 167644] [client 20.116.17.175:45432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wmore1.php"] [unique_id "aoSD9Wr_JutbFb-8svoquQAAAcY"] [Tue Aug 18 13:10:29.669098 2026] [security2:error] [pid 167459:tid 167597] [client 20.118.133.132:45234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/dex.php"] [unique_id "aoSD9Wr_JutbFb-8svoquwAAAZc"] [Tue Aug 18 13:10:29.720664 2026] [security2:error] [pid 167459:tid 167648] [client 20.127.136.245:12092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/upload.php"] [unique_id "aoSD9Wr_JutbFb-8svoqvgAAAco"] [Tue Aug 18 13:10:29.850359 2026] [security2:error] [pid 167459:tid 167702] [client 20.51.153.15:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sy.php"] [unique_id "aoSD9Wr_JutbFb-8svoqwwAAAgA"] [Tue Aug 18 13:10:29.853542 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:29.853830 2026] [authz_core:error] [pid 167459:tid 167544] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:29.856616 2026] [security2:error] [pid 167459:tid 167709] [client 20.91.215.254:14287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/customize.php"] [unique_id "aoSD9Wr_JutbFb-8svoqxAAAAgc"] [Tue Aug 18 13:10:29.862817 2026] [security2:error] [pid 167459:tid 167596] [client 40.74.65.169:49045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/simple.php"] [unique_id "aoSD9Wr_JutbFb-8svoqxQAAAZY"] [Tue Aug 18 13:10:29.884803 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/h02ugyh.php"] [unique_id "aoSD9Wr_JutbFb-8svoqxwAAAgk"] [Tue Aug 18 13:10:29.919233 2026] [security2:error] [pid 167459:tid 167624] [client 74.248.18.37:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/vx.php"] [unique_id "aoSD9Wr_JutbFb-8svoqyAAAAbI"] [Tue Aug 18 13:10:29.946207 2026] [security2:error] [pid 167459:tid 167631] [client 20.104.49.167:10853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/modric7Z7J2X.php"] [unique_id "aoSD9Wr_JutbFb-8svoqygAAAbk"] [Tue Aug 18 13:10:29.979480 2026] [security2:error] [pid 167459:tid 167634] [client 158.23.17.4:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ta.php"] [unique_id "aoSD9Wr_JutbFb-8svoqzgAAAbw"] [Tue Aug 18 13:10:29.992110 2026] [security2:error] [pid 167459:tid 167713] [client 74.249.206.207:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.206.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.3xsolutions.com"] [uri "/ajax.php"] [unique_id "aoSD9Wr_JutbFb-8svoqzwAAAgs"] [Tue Aug 18 13:10:29.998459 2026] [security2:error] [pid 167459:tid 167664] [client 20.118.172.148:56976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSD9Wr_JutbFb-8svoq0AAAAdo"] [Tue Aug 18 13:10:30.092324 2026] [security2:error] [pid 167459:tid 167613] [client 20.116.17.175:45316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/special.php"] [unique_id "aoSD9mr_JutbFb-8svoq0wAAAac"] [Tue Aug 18 13:10:30.120686 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:35281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/images/min.php"] [unique_id "aoSD9mr_JutbFb-8svoq1QAAAfA"] [Tue Aug 18 13:10:30.125460 2026] [security2:error] [pid 167459:tid 167710] [client 20.51.153.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/57.php"] [unique_id "aoSD9mr_JutbFb-8svoq1gAAAgg"] [Tue Aug 18 13:10:30.136751 2026] [security2:error] [pid 167459:tid 167612] [client 213.35.127.232:57248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD9mr_JutbFb-8svoq1wAAAaY"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:30.153436 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:30.153680 2026] [authz_core:error] [pid 167459:tid 167472] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:30.227881 2026] [security2:error] [pid 167459:tid 167599] [client 82.102.18.188:41144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marthaimenes.com"] [uri "/xmlrpc.php"] [unique_id "aoSD9mr_JutbFb-8svoq2gAAAZk"] [Tue Aug 18 13:10:30.408166 2026] [security2:error] [pid 167459:tid 167633] [client 158.23.17.4:9331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/34.php"] [unique_id "aoSD9mr_JutbFb-8svoq5AAAAbs"] [Tue Aug 18 13:10:30.423688 2026] [security2:error] [pid 167459:tid 167646] [client 149.34.210.141:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD9mr_JutbFb-8svoq5gAAAcg"] [Tue Aug 18 13:10:30.458113 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:30.458550 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:30.465549 2026] [security2:error] [pid 167459:tid 167697] [client 20.118.172.148:57483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/index.php"] [unique_id "aoSD9mr_JutbFb-8svoq6AAAAfs"] [Tue Aug 18 13:10:30.536626 2026] [security2:error] [pid 167459:tid 167706] [client 40.74.65.169:49072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/wp-manager.php"] [unique_id "aoSD9mr_JutbFb-8svoq6wAAAgQ"] [Tue Aug 18 13:10:30.574837 2026] [security2:error] [pid 167459:tid 167688] [client 20.116.17.175:64789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSD9mr_JutbFb-8svoq7wAAAfI"] [Tue Aug 18 13:10:30.578239 2026] [security2:error] [pid 167459:tid 167712] [client 40.74.65.169:25446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/155.php"] [unique_id "aoSD9mr_JutbFb-8svoq8AAAAgo"] [Tue Aug 18 13:10:30.690218 2026] [security2:error] [pid 167459:tid 167646] [client 149.34.210.141:61800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSD9mr_JutbFb-8svoq5gAAAcg"] [Tue Aug 18 13:10:30.700517 2026] [security2:error] [pid 167459:tid 167708] [client 52.139.47.57:9907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/includes/header.php"] [unique_id "aoSD9mr_JutbFb-8svoq-wAAAgY"] [Tue Aug 18 13:10:30.758902 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:30.759198 2026] [authz_core:error] [pid 167459:tid 167570] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:30.771514 2026] [security2:error] [pid 167459:tid 167684] [client 52.173.121.69:57278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/weozh.php"] [unique_id "aoSD9mr_JutbFb-8svorAAAAAe4"] [Tue Aug 18 13:10:30.793752 2026] [security2:error] [pid 167459:tid 167630] [client 74.248.133.44:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/gebase.php69"] [unique_id "aoSD9mr_JutbFb-8svorAgAAAbg"] [Tue Aug 18 13:10:30.810358 2026] [security2:error] [pid 167459:tid 167602] [client 20.91.215.254:12801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/mah/function.php"] [unique_id "aoSD9mr_JutbFb-8svorBAAAAZw"] [Tue Aug 18 13:10:30.812626 2026] [security2:error] [pid 167459:tid 167592] [client 74.7.175.175:35286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.juliocorretordeimoveis.com.br"] [uri "/cgi-sys/404.html"] [unique_id "aoSD9mr_JutbFb-8svorAwABkmA"] [Tue Aug 18 13:10:30.839307 2026] [security2:error] [pid 167459:tid 167709] [client 20.118.172.148:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-includes/class-wp-http-client.php"] [unique_id "aoSD9mr_JutbFb-8svorBgAAAgc"] [Tue Aug 18 13:10:30.861743 2026] [security2:error] [pid 167459:tid 167679] [client 68.155.154.236:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "aoSD9mr_JutbFb-8svorCAAAAek"] [Tue Aug 18 13:10:30.870425 2026] [security2:error] [pid 167459:tid 167638] [client 74.7.241.176:53854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dglmaritimeagency.com.br"] [uri "/robots.txt"] [unique_id "aoSD9mr_JutbFb-8svorCQABwEE"] [Tue Aug 18 13:10:30.901957 2026] [autoindex:error] [pid 167459:tid 167551] [remote 136.110.27.48:34582] AH01276: Cannot serve directory /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:30.904188 2026] [security2:error] [pid 167459:tid 167595] [client 20.118.133.132:45245] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "newinox.com.br"] [uri "/1.php"] [unique_id "aoSD9mr_JutbFb-8svorEAAAAZU"] [Tue Aug 18 13:10:30.904285 2026] [security2:error] [pid 167459:tid 167595] [client 20.118.133.132:45245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/1.php"] [unique_id "aoSD9mr_JutbFb-8svorEAAAAZU"] Not Found: /visualizar-cliente/images/favicon.ico [Tue Aug 18 13:10:30.974060 2026] [security2:error] [pid 167459:tid 167714] [client 158.23.17.4:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/he.php"] [unique_id "aoSD9mr_JutbFb-8svorFQAAAgw"] [Tue Aug 18 13:10:30.998560 2026] [security2:error] [pid 167459:tid 167629] [client 20.127.136.245:4278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wk/index.php"] [unique_id "aoSD9mr_JutbFb-8svorGAAAAbc"] [Tue Aug 18 13:10:31.007031 2026] [security2:error] [pid 167459:tid 167613] [client 20.116.17.175:41510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/thoms.php"] [unique_id "aoSD92r_JutbFb-8svorGQAAAac"] [Tue Aug 18 13:10:31.061404 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:31.061838 2026] [authz_core:error] [pid 167459:tid 167572] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:31.064266 2026] [security2:error] [pid 167459:tid 167609] [client 20.51.153.15:13433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ah.php"] [unique_id "aoSD92r_JutbFb-8svorHAAAAaM"] [Tue Aug 18 13:10:31.119189 2026] [security2:error] [pid 167459:tid 167693] [client 52.139.47.57:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/index.php"] [unique_id "aoSD92r_JutbFb-8svorHwAAAfc"] [Tue Aug 18 13:10:31.155441 2026] [security2:error] [pid 167459:tid 167654] [client 213.35.127.232:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD92r_JutbFb-8svorIAAAAdA"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:31.160028 2026] [security2:error] [pid 167459:tid 167651] [client 4.232.151.198:49113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/bless.php"] [unique_id "aoSD92r_JutbFb-8svorIgAAAc0"] [Tue Aug 18 13:10:31.223540 2026] [security2:error] [pid 167459:tid 167715] [client 40.74.65.169:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/xiugai.php"] [unique_id "aoSD92r_JutbFb-8svorIwAAAg0"] [Tue Aug 18 13:10:31.257406 2026] [security2:error] [pid 167459:tid 167683] [client 40.74.65.169:52255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/ops.php"] [unique_id "aoSD92r_JutbFb-8svorJQAAAe0"] [Tue Aug 18 13:10:31.310617 2026] [security2:error] [pid 167459:tid 167660] [client 20.118.172.148:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/atomlib.php"] [unique_id "aoSD92r_JutbFb-8svorLgAAAdY"] [Tue Aug 18 13:10:31.312619 2026] [security2:error] [pid 167459:tid 167706] [client 74.248.18.37:55091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wap.php"] [unique_id "aoSD92r_JutbFb-8svorLwAAAgQ"] [Tue Aug 18 13:10:31.313952 2026] [security2:error] [pid 167459:tid 167598] [client 20.104.49.167:10788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/modricXP4D68.php"] [unique_id "aoSD92r_JutbFb-8svorMAAAAZg"] [Tue Aug 18 13:10:31.325227 2026] [security2:error] [pid 167459:tid 167696] [client 20.51.153.15:1945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vw.php"] [unique_id "aoSD92r_JutbFb-8svorMQAAAfo"] [Tue Aug 18 13:10:31.358388 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:31.358650 2026] [authz_core:error] [pid 167459:tid 167494] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:31.440498 2026] [security2:error] [pid 167459:tid 167712] [client 158.23.17.4:63676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/gz.php"] [unique_id "aoSD92r_JutbFb-8svorNQAAAgo"] [Tue Aug 18 13:10:31.487293 2026] [security2:error] [pid 167459:tid 167614] [client 20.91.215.254:12709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/filter.php"] [unique_id "aoSD92r_JutbFb-8svorNgAAAag"] [Tue Aug 18 13:10:31.560234 2026] [security2:error] [pid 167459:tid 167644] [client 20.51.153.15:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lj.php"] [unique_id "aoSD92r_JutbFb-8svorOQAAAcY"] [Tue Aug 18 13:10:31.567615 2026] [security2:error] [pid 167459:tid 167615] [client 20.171.51.14:5427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/vu.php"] [unique_id "aoSD92r_JutbFb-8svorPgAAAak"] [Tue Aug 18 13:10:31.661166 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:31.661586 2026] [authz_core:error] [pid 167459:tid 167540] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:31.672088 2026] [security2:error] [pid 167459:tid 167648] [client 20.118.172.148:39172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/min.php"] [unique_id "aoSD92r_JutbFb-8svorQwAAAco"] [Tue Aug 18 13:10:31.689159 2026] [security2:error] [pid 167459:tid 167607] [client 74.248.18.37:35032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-includes/Requests/library/index.php"] [unique_id "aoSD92r_JutbFb-8svorRQAAAaE"] [Tue Aug 18 13:10:31.746984 2026] [security2:error] [pid 167459:tid 167590] [client 74.248.133.44:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/akcc.php"] [unique_id "aoSD92r_JutbFb-8svorSAAAAZA"] [Tue Aug 18 13:10:31.812518 2026] [security2:error] [pid 167459:tid 167711] [client 20.51.153.15:13361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kh.php"] [unique_id "aoSD92r_JutbFb-8svorTAAAAgk"] [Tue Aug 18 13:10:31.839264 2026] [security2:error] [pid 167459:tid 167670] [client 52.139.47.57:35275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/link-add.php"] [unique_id "aoSD92r_JutbFb-8svorUAAAAeA"] [Tue Aug 18 13:10:31.893636 2026] [security2:error] [pid 167459:tid 167593] [client 20.116.17.175:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSD92r_JutbFb-8svorVwAAAZM"] [Tue Aug 18 13:10:31.921359 2026] [security2:error] [pid 167459:tid 167707] [client 158.23.17.4:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/nf.php"] [unique_id "aoSD92r_JutbFb-8svorWQAAAgU"] [Tue Aug 18 13:10:31.933756 2026] [security2:error] [pid 167459:tid 167661] [client 40.74.65.169:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/wp-load.php"] [unique_id "aoSD92r_JutbFb-8svorWgAAAdc"] [Tue Aug 18 13:10:31.953222 2026] [security2:error] [pid 167459:tid 167691] [client 40.74.65.169:25410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/mac.php"] [unique_id "aoSD92r_JutbFb-8svorXQAAAfU"] [Tue Aug 18 13:10:31.961358 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:31.961810 2026] [authz_core:error] [pid 167459:tid 167486] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:32.016874 2026] [security2:error] [pid 167459:tid 167671] [client 82.102.18.188:41146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aoSD-Gr_JutbFb-8svorYAAAAeE"] [Tue Aug 18 13:10:32.032023 2026] [security2:error] [pid 167459:tid 167627] [client 52.173.121.69:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/rymmm.php"] [unique_id "aoSD-Gr_JutbFb-8svorYQAAAbU"] [Tue Aug 18 13:10:32.034392 2026] [security2:error] [pid 167459:tid 167608] [client 20.127.136.245:19173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-act.php"] [unique_id "aoSD-Gr_JutbFb-8svorYgAAAaI"] [Tue Aug 18 13:10:32.073875 2026] [security2:error] [pid 167459:tid 167668] [client 20.104.49.167:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cristalsulvidros.com.br"] [uri "/clara.php"] [unique_id "aoSD-Gr_JutbFb-8svorZAAAAd4"] [Tue Aug 18 13:10:32.075441 2026] [security2:error] [pid 167459:tid 167695] [client 157.20.138.62:64825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorZQAAAfk"] [Tue Aug 18 13:10:32.075756 2026] [security2:error] [pid 167459:tid 167695] [client 157.20.138.62:64825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorZQAAAfk"] [Tue Aug 18 13:10:32.076277 2026] [security2:error] [pid 167459:tid 167688] [client 178.153.171.161:27980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorZgAAAfI"] [Tue Aug 18 13:10:32.076371 2026] [security2:error] [pid 167459:tid 167688] [client 178.153.171.161:27980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorZgAAAfI"] [Tue Aug 18 13:10:32.077290 2026] [security2:error] [pid 167459:tid 167705] [client 20.51.153.15:1971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/jb.php"] [unique_id "aoSD-Gr_JutbFb-8svorZwAAAgM"] [Tue Aug 18 13:10:32.130971 2026] [security2:error] [pid 167459:tid 167634] [client 20.91.215.254:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/input.php"] [unique_id "aoSD-Gr_JutbFb-8svoraQAAAbw"] [Tue Aug 18 13:10:32.168032 2026] [security2:error] [pid 167459:tid 167599] [client 20.118.172.148:56960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/mac.php"] [unique_id "aoSD-Gr_JutbFb-8svorawAAAZk"] [Tue Aug 18 13:10:32.170490 2026] [security2:error] [pid 167459:tid 167703] [client 213.35.127.232:57681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD-Gr_JutbFb-8svorbAAAAgE"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:32.183227 2026] [security2:error] [pid 167459:tid 167677] [client 20.118.133.132:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupobelmais.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD-Gr_JutbFb-8svorbQAAAec"] [Tue Aug 18 13:10:32.244668 2026] [security2:error] [pid 167459:tid 167620] [client 20.116.17.175:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/222.php"] [unique_id "aoSD-Gr_JutbFb-8svordAAAAa4"] [Tue Aug 18 13:10:32.260440 2026] [authz_core:error] [pid 167459:tid 167543] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:32.260704 2026] [authz_core:error] [pid 167459:tid 167543] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:32.263186 2026] [security2:error] [pid 167459:tid 167636] [client 52.139.47.57:18549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/login.php"] [unique_id "aoSD-Gr_JutbFb-8svordwAAAb4"] [Tue Aug 18 13:10:32.291934 2026] [security2:error] [pid 167459:tid 167655] [client 4.232.151.198:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/sagax1.php"] [unique_id "aoSD-Gr_JutbFb-8svorewAAAdE"] [Tue Aug 18 13:10:32.294815 2026] [security2:error] [pid 167459:tid 167698] [client 20.250.13.23:9922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/96i.php"] [unique_id "aoSD-Gr_JutbFb-8svorfAAAAfw"] [Tue Aug 18 13:10:32.334107 2026] [security2:error] [pid 167459:tid 167712] [client 158.23.17.4:33501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/xv.php"] [unique_id "aoSD-Gr_JutbFb-8svorgAAAAgo"] [Tue Aug 18 13:10:32.375146 2026] [security2:error] [pid 167459:tid 167681] [client 20.116.17.175:22706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/root.php"] [unique_id "aoSD-Gr_JutbFb-8svorggAAAes"] [Tue Aug 18 13:10:32.494687 2026] [security2:error] [pid 167459:tid 167642] [client 51.68.107.141:15441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scaclinic.com.br"] [uri "/robots.txt"] [unique_id "aoSD-Gr_JutbFb-8svorhwAAAcQ"] [Tue Aug 18 13:10:32.494810 2026] [security2:error] [pid 167459:tid 167642] [client 51.68.107.141:15441] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scaclinic.com.br"] [uri "/robots.txt"] [unique_id "aoSD-Gr_JutbFb-8svorhwAAAcQ"] [Tue Aug 18 13:10:32.568056 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:32.568324 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:32.610346 2026] [security2:error] [pid 167459:tid 167638] [client 40.74.65.169:49073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/155.php"] [unique_id "aoSD-Gr_JutbFb-8svorjwAAAcA"] [Tue Aug 18 13:10:32.634471 2026] [security2:error] [pid 167459:tid 167704] [client 20.127.136.245:17079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-admin/css/bolt.php"] [unique_id "aoSD-Gr_JutbFb-8svorkQAAAgI"] [Tue Aug 18 13:10:32.636465 2026] [security2:error] [pid 167459:tid 167711] [client 40.74.65.169:25420] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "aoSD-Gr_JutbFb-8svorkgAAAgk"] [Tue Aug 18 13:10:32.667807 2026] [security2:error] [pid 167459:tid 167660] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorjgAB1nQ"] [Tue Aug 18 13:10:32.676916 2026] [security2:error] [pid 167459:tid 167640] [client 52.139.47.57:9888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/min.php"] [unique_id "aoSD-Gr_JutbFb-8svorkwAAAcI"] [Tue Aug 18 13:10:32.694253 2026] [authz_core:error] [pid 167459:tid 167577] [remote 57.141.22.11:45352] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:32.694592 2026] [authz_core:error] [pid 167459:tid 167577] [remote 57.141.22.11:45352] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:32.711900 2026] [security2:error] [pid 167459:tid 167595] [client 82.102.18.188:41158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "aoSD-Gr_JutbFb-8svorlwAAAZU"] [Tue Aug 18 13:10:32.793493 2026] [security2:error] [pid 167459:tid 167674] [client 20.91.215.254:12996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/jquery.php"] [unique_id "aoSD-Gr_JutbFb-8svormAAAAeQ"] [Tue Aug 18 13:10:32.831231 2026] [security2:error] [pid 167459:tid 167691] [client 20.118.172.148:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/nc4.php"] [unique_id "aoSD-Gr_JutbFb-8svormgAAAfU"] [Tue Aug 18 13:10:32.858150 2026] [security2:error] [pid 167459:tid 167700] [client 158.23.17.4:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/mx.php"] [unique_id "aoSD-Gr_JutbFb-8svornAAAAf4"] [Tue Aug 18 13:10:32.882891 2026] [security2:error] [pid 167459:tid 167629] [client 20.116.17.175:45430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/fpwch.php"] [unique_id "aoSD-Gr_JutbFb-8svornQAAAbc"] [Tue Aug 18 13:10:32.940164 2026] [security2:error] [pid 167459:tid 167686] [client 20.51.153.15:13402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/do.php"] [unique_id "aoSD-Gr_JutbFb-8svorogAAAfA"] [Tue Aug 18 13:10:32.952754 2026] [security2:error] [pid 167459:tid 167662] [client 114.5.214.109:50428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorowAAAdg"] [Tue Aug 18 13:10:32.962402 2026] [security2:error] [pid 167459:tid 167662] [client 114.5.214.109:50428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-Gr_JutbFb-8svorowAAAdg"] [Tue Aug 18 13:10:33.047986 2026] [security2:error] [pid 167459:tid 167634] [client 68.155.154.236:25350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/certificates/upload.php"] [unique_id "aoSD-Wr_JutbFb-8svorqwAAAbw"] [Tue Aug 18 13:10:33.093918 2026] [security2:error] [pid 167459:tid 167641] [client 20.104.49.167:44045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD-Wr_JutbFb-8svorrgAAAcM"] [Tue Aug 18 13:10:33.103156 2026] [security2:error] [pid 167459:tid 167626] [client 20.171.51.14:5402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ic.php"] [unique_id "aoSD-Wr_JutbFb-8svorsAAAAbQ"] Not Found: /editar-cliente/images/favicon.ico [Tue Aug 18 13:10:33.113581 2026] [security2:error] [pid 167459:tid 167612] [client 52.139.47.57:13724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "aoSD-Wr_JutbFb-8svorsQAAAaY"] [Tue Aug 18 13:10:33.169114 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:33.169576 2026] [authz_core:error] [pid 167459:tid 167496] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:33.176120 2026] [security2:error] [pid 167459:tid 167639] [client 74.248.18.37:30014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-admin/wp.php"] [unique_id "aoSD-Wr_JutbFb-8svortQAAAcE"] [Tue Aug 18 13:10:33.188623 2026] [security2:error] [pid 167459:tid 167714] [client 213.35.127.232:57899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD-Wr_JutbFb-8svortgAAAgw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:33.243980 2026] [security2:error] [pid 167459:tid 167699] [client 20.118.172.148:39207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/as.php"] [unique_id "aoSD-Wr_JutbFb-8svoruAAAAf0"] [Tue Aug 18 13:10:33.253885 2026] [security2:error] [pid 167459:tid 167680] [client 20.51.153.15:2004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/yw.php"] [unique_id "aoSD-Wr_JutbFb-8svorugAAAeo"] [Tue Aug 18 13:10:33.296575 2026] [security2:error] [pid 167459:tid 167692] [client 40.74.65.169:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/index.php"] [unique_id "aoSD-Wr_JutbFb-8svoruwAAAfY"] [Tue Aug 18 13:10:33.323299 2026] [security2:error] [pid 167459:tid 167618] [client 40.74.65.169:52247] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-admin/js/"] [unique_id "aoSD-Wr_JutbFb-8svorvAAAAaw"] [Tue Aug 18 13:10:33.384261 2026] [security2:error] [pid 167459:tid 167673] [client 20.116.17.175:45411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/mg.php"] [unique_id "aoSD-Wr_JutbFb-8svorwAAAAeM"] [Tue Aug 18 13:10:33.408993 2026] [security2:error] [pid 167459:tid 167600] [client 158.23.17.4:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/45.php"] [unique_id "aoSD-Wr_JutbFb-8svorwQAAAZo"] [Tue Aug 18 13:10:33.460316 2026] [security2:error] [pid 167459:tid 167675] [client 20.91.215.254:14305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/media-new.php"] [unique_id "aoSD-Wr_JutbFb-8svorxAAAAeU"] [Tue Aug 18 13:10:33.467918 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:33.468207 2026] [authz_core:error] [pid 167459:tid 167561] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:33.516917 2026] [security2:error] [pid 167459:tid 167602] [client 168.62.48.100:5624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/qfvqu.php"] [unique_id "aoSD-Wr_JutbFb-8svorxwAAAZw"] [Tue Aug 18 13:10:33.522531 2026] [security2:error] [pid 167459:tid 167637] [client 20.51.153.15:13325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/qh.php"] [unique_id "aoSD-Wr_JutbFb-8svoryAAAAb8"] [Tue Aug 18 13:10:33.550979 2026] [security2:error] [pid 167459:tid 167690] [client 52.139.47.57:9904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/network/post.php"] [unique_id "aoSD-Wr_JutbFb-8svorzAAAAfQ"] [Tue Aug 18 13:10:33.588616 2026] [security2:error] [pid 167459:tid 167681] [client 46.232.235.133:47340] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "mudancasmb.com.br"] [uri "/"] [unique_id "aoSD-Wr_JutbFb-8svorzgAAAes"] [Tue Aug 18 13:10:33.589937 2026] [security2:error] [pid 167459:tid 167644] [client 74.248.18.37:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "aoSD-Wr_JutbFb-8svorzwAAAcY"] [Tue Aug 18 13:10:33.627377 2026] [security2:error] [pid 167459:tid 167670] [client 20.118.172.148:39119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/k.php"] [unique_id "aoSD-Wr_JutbFb-8svor0QAAAeA"] [Tue Aug 18 13:10:33.766420 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:33.766675 2026] [authz_core:error] [pid 167459:tid 167518] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:33.787533 2026] [security2:error] [pid 167459:tid 167630] [client 20.51.153.15:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/r.php"] [unique_id "aoSD-Wr_JutbFb-8svor3AAAAbg"] [Tue Aug 18 13:10:33.795973 2026] [security2:error] [pid 167459:tid 167613] [client 158.23.17.4:8739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/wy.php"] [unique_id "aoSD-Wr_JutbFb-8svor3QAAAac"] [Tue Aug 18 13:10:33.849235 2026] [security2:error] [pid 167459:tid 167598] [client 74.248.133.44:34946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "aoSD-Wr_JutbFb-8svor4wAAAZg"] [Tue Aug 18 13:10:33.931429 2026] [security2:error] [pid 167459:tid 167609] [client 20.116.17.175:45373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/reop3.php"] [unique_id "aoSD-Wr_JutbFb-8svor5gAAAaM"] [Tue Aug 18 13:10:33.961826 2026] [security2:error] [pid 167459:tid 167686] [client 52.139.47.57:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/test.php"] [unique_id "aoSD-Wr_JutbFb-8svor5wAAAfA"] [Tue Aug 18 13:10:33.983646 2026] [security2:error] [pid 167459:tid 167669] [client 40.74.65.169:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/aaa.php"] [unique_id "aoSD-Wr_JutbFb-8svor6QAAAd8"] [Tue Aug 18 13:10:34.013146 2026] [security2:error] [pid 167459:tid 167693] [client 40.74.65.169:25477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/makeasmtp.php"] [unique_id "aoSD-mr_JutbFb-8svor6gAAAfc"] [Tue Aug 18 13:10:34.017785 2026] [security2:error] [pid 167459:tid 167654] [client 20.118.172.148:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/media/com_sppagebuilder/assets/iconfont/km/fonts/index.php"] [unique_id "aoSD-mr_JutbFb-8svor6wAAAdA"] [Tue Aug 18 13:10:34.024255 2026] [security2:error] [pid 167459:tid 167651] [client 20.51.153.15:2029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/17.php"] [unique_id "aoSD-mr_JutbFb-8svor7AAAAc0"] [Tue Aug 18 13:10:34.038981 2026] [security2:error] [pid 167459:tid 167634] [client 20.104.49.167:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD-mr_JutbFb-8svor7QAAAbw"] [Tue Aug 18 13:10:34.049645 2026] [security2:error] [pid 167459:tid 167591] [client 52.173.121.69:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/lddxs.php"] [unique_id "aoSD-mr_JutbFb-8svor7gAAAZE"] [Tue Aug 18 13:10:34.051621 2026] [security2:error] [pid 167459:tid 167599] [client 20.127.136.245:16891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "aoSD-mr_JutbFb-8svor7wAAAZk"] [Tue Aug 18 13:10:34.070523 2026] [security2:error] [pid 167459:tid 167703] [client 68.155.154.236:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/well-known/index.php"] [unique_id "aoSD-mr_JutbFb-8svor8QAAAgE"] [Tue Aug 18 13:10:34.074315 2026] [authz_core:error] [pid 167459:tid 167549] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:34.074585 2026] [authz_core:error] [pid 167459:tid 167549] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:34.134837 2026] [security2:error] [pid 167459:tid 167710] [client 20.91.215.254:12716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/includes/ms.php"] [unique_id "aoSD-mr_JutbFb-8svor9AAAAgg"] [Tue Aug 18 13:10:34.187360 2026] [security2:error] [pid 167459:tid 167697] [client 82.102.18.188:39298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "aoSD-mr_JutbFb-8svor9gAAAfs"] [Tue Aug 18 13:10:34.212450 2026] [security2:error] [pid 167459:tid 167695] [client 213.35.127.232:58118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD-mr_JutbFb-8svor9wAAAfk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:34.317304 2026] [security2:error] [pid 167459:tid 167673] [client 158.23.17.4:10988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/f.php"] [unique_id "aoSD-mr_JutbFb-8svor_gAAAeM"] [Tue Aug 18 13:10:34.340547 2026] [security2:error] [pid 167459:tid 167617] [client 20.116.17.175:41528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/php5.php"] [unique_id "aoSD-mr_JutbFb-8svosAAAAAas"] [Tue Aug 18 13:10:34.352180 2026] [security2:error] [pid 167459:tid 167611] [client 20.51.153.15:1864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ev.php"] [unique_id "aoSD-mr_JutbFb-8svosAQAAAaU"] [Tue Aug 18 13:10:34.370269 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:34.370567 2026] [authz_core:error] [pid 167459:tid 167525] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:34.374742 2026] [security2:error] [pid 167459:tid 167706] [client 52.139.47.57:35282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/themes/themes/wp-cron.php"] [unique_id "aoSD-mr_JutbFb-8svosAwAAAgQ"] [Tue Aug 18 13:10:34.387266 2026] [security2:error] [pid 167459:tid 167616] [client 20.250.13.23:18296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/as.php"] [unique_id "aoSD-mr_JutbFb-8svosBAAAAao"] [Tue Aug 18 13:10:34.422361 2026] [security2:error] [pid 167459:tid 167647] [client 20.171.51.14:17778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ue.php"] [unique_id "aoSD-mr_JutbFb-8svosBQAAAck"] [Tue Aug 18 13:10:34.463372 2026] [security2:error] [pid 167459:tid 167702] [client 20.116.17.175:52919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-temp.php"] [unique_id "aoSD-mr_JutbFb-8svosBwAAAgA"] [Tue Aug 18 13:10:34.486135 2026] [security2:error] [pid 167459:tid 167709] [client 20.118.172.148:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/system_log.php"] [unique_id "aoSD-mr_JutbFb-8svosCQAAAgc"] [Tue Aug 18 13:10:34.515053 2026] [security2:error] [pid 167459:tid 167597] [client 46.232.235.133:47356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://:"] [hostname "mudancasmb.com.br"] [uri "/wp-json/batch/v1"] [unique_id "aoSD-mr_JutbFb-8svosCgAAAZc"] [Tue Aug 18 13:10:34.523994 2026] [security2:error] [pid 167459:tid 167700] [client 197.184.64.235:42707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-mr_JutbFb-8svosDAAAAf4"] [Tue Aug 18 13:10:34.524088 2026] [security2:error] [pid 167459:tid 167700] [client 197.184.64.235:42707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-mr_JutbFb-8svosDAAAAf4"] [Tue Aug 18 13:10:34.605313 2026] [security2:error] [pid 167459:tid 167653] [client 20.51.153.15:1935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xs.php"] [unique_id "aoSD-mr_JutbFb-8svosDwAAAc8"] [Tue Aug 18 13:10:34.662147 2026] [security2:error] [pid 167459:tid 167593] [client 138.36.100.162:42469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-mr_JutbFb-8svosFwAAAZM"] [Tue Aug 18 13:10:34.662250 2026] [security2:error] [pid 167459:tid 167593] [client 138.36.100.162:42469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD-mr_JutbFb-8svosFwAAAZM"] [Tue Aug 18 13:10:34.678796 2026] [security2:error] [pid 167459:tid 167613] [client 40.74.65.169:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/FWAZ.php"] [unique_id "aoSD-mr_JutbFb-8svosGAAAAac"] [Tue Aug 18 13:10:34.714851 2026] [security2:error] [pid 167459:tid 167598] [client 40.74.65.169:25454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "aoSD-mr_JutbFb-8svosGgAAAZg"] [Tue Aug 18 13:10:34.766438 2026] [security2:error] [pid 167459:tid 167660] [client 20.91.215.254:12697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/images/moon.php"] [unique_id "aoSD-mr_JutbFb-8svosHgAAAdY"] [Tue Aug 18 13:10:34.804457 2026] [security2:error] [pid 167459:tid 167610] [client 74.248.18.37:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/bgymj.php"] [unique_id "aoSD-mr_JutbFb-8svosIAAAAaQ"] [Tue Aug 18 13:10:34.814262 2026] [security2:error] [pid 167459:tid 167684] [client 20.118.172.148:60447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/x.php"] [unique_id "aoSD-mr_JutbFb-8svosIQAAAe4"] [Tue Aug 18 13:10:34.842375 2026] [security2:error] [pid 167459:tid 167677] [client 68.155.154.236:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Ipv6.php"] [unique_id "aoSD-mr_JutbFb-8svosJgAAAec"] [Tue Aug 18 13:10:34.887200 2026] [security2:error] [pid 167459:tid 167694] [client 20.116.17.175:22658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/acp.php"] [unique_id "aoSD-mr_JutbFb-8svosKgAAAfg"] [Tue Aug 18 13:10:34.892555 2026] [security2:error] [pid 167459:tid 167713] [client 82.102.18.188:39300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "aoSD-mr_JutbFb-8svosLAAAAgs"] [Tue Aug 18 13:10:34.901685 2026] [security2:error] [pid 167459:tid 167698] [client 20.127.136.245:11522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "aoSD-mr_JutbFb-8svosLQAAAfw"] [Tue Aug 18 13:10:34.927061 2026] [security2:error] [pid 167459:tid 167699] [client 158.23.17.4:8714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/30.php"] [unique_id "aoSD-mr_JutbFb-8svosMAAAAf0"] [Tue Aug 18 13:10:34.932051 2026] [security2:error] [pid 167459:tid 167680] [client 52.139.47.57:2695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/user/min.php"] [unique_id "aoSD-mr_JutbFb-8svosMQAAAeo"] [Tue Aug 18 13:10:34.936062 2026] [security2:error] [pid 167459:tid 167666] [client 20.51.153.15:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/lmfi2.php"] [unique_id "aoSD-mr_JutbFb-8svosMgAAAdw"] [Tue Aug 18 13:10:35.022504 2026] [security2:error] [pid 167459:tid 167646] [client 20.104.49.167:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "aoSD-2r_JutbFb-8svosNwAAAcg"] [Tue Aug 18 13:10:35.034596 2026] [security2:error] [pid 167459:tid 167706] [client 168.62.48.100:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/oivcl.php"] [unique_id "aoSD-2r_JutbFb-8svosOAAAAgQ"] [Tue Aug 18 13:10:35.080259 2026] [security2:error] [pid 167459:tid 167690] [client 74.248.133.44:12614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/updates.php"] [unique_id "aoSD-2r_JutbFb-8svosOQAAAfQ"] [Tue Aug 18 13:10:35.143922 2026] [security2:error] [pid 167459:tid 167597] [client 20.171.51.14:5423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/lr.php"] [unique_id "aoSD-2r_JutbFb-8svosRAAAAZc"] [Tue Aug 18 13:10:35.153570 2026] [security2:error] [pid 167459:tid 167681] [client 20.118.172.148:57489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/autoload_classmap.php"] [unique_id "aoSD-2r_JutbFb-8svosRQAAAes"] [Tue Aug 18 13:10:35.164405 2026] [security2:error] [pid 167459:tid 167619] [client 74.248.18.37:30610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/gecko-new.php"] [unique_id "aoSD-2r_JutbFb-8svosRgAAAa0"] [Tue Aug 18 13:10:35.189733 2026] [security2:error] [pid 167459:tid 167615] [client 178.156.181.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thatianysantana.com.br"] [uri "/index.php"] [unique_id "aoSD-Wr_JutbFb-8svor4gABqQI"], referer: https://thatianysantana.com.br/ [Tue Aug 18 13:10:35.225322 2026] [security2:error] [pid 167459:tid 167710] [client 213.35.127.232:58340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSD-2r_JutbFb-8svosTAAAAgg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:35.281851 2026] [security2:error] [pid 167459:tid 167629] [client 216.73.160.238:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monteelimaadvocacia.com.br"] [uri "/wp-login.php"] [unique_id "aoSD-2r_JutbFb-8svosTgAAAbc"] [Tue Aug 18 13:10:35.282154 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:35.282200 2026] [security2:error] [pid 167459:tid 167594] [client 68.155.154.236:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSD-2r_JutbFb-8svosUAAAAZQ"] [Tue Aug 18 13:10:35.282436 2026] [authz_core:error] [pid 167459:tid 167528] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:35.344774 2026] [security2:error] [pid 167459:tid 167623] [client 20.91.215.254:23104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-content/backup.php"] [unique_id "aoSD-2r_JutbFb-8svosUQAAAbE"] [Tue Aug 18 13:10:35.347767 2026] [security2:error] [pid 167459:tid 167592] [client 20.51.153.15:1949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fd.php"] [unique_id "aoSD-2r_JutbFb-8svosUgAAAZI"] [Tue Aug 18 13:10:35.356552 2026] [security2:error] [pid 167459:tid 167674] [client 52.139.47.57:9868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/users.php"] [unique_id "aoSD-2r_JutbFb-8svosUwAAAeQ"] [Tue Aug 18 13:10:35.358810 2026] [security2:error] [pid 167459:tid 167574] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/lock360.php"] [unique_id "aoSD-2r_JutbFb-8svosVAAB13I"] [Tue Aug 18 13:10:35.376989 2026] [security2:error] [pid 167459:tid 167598] [client 40.74.65.169:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/site.php"] [unique_id "aoSD-2r_JutbFb-8svosVwAAAZg"] [Tue Aug 18 13:10:35.408855 2026] [security2:error] [pid 167459:tid 167616] [client 20.118.133.132:31259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/coffee.php"] [unique_id "aoSD-2r_JutbFb-8svosWAAAAao"] [Tue Aug 18 13:10:35.415978 2026] [security2:error] [pid 167459:tid 167643] [client 40.74.65.169:25466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/system_log.php"] [unique_id "aoSD-2r_JutbFb-8svosWQAAAcU"] [Tue Aug 18 13:10:35.426472 2026] [security2:error] [pid 167459:tid 167621] [client 20.91.215.254:12707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/import.php"] [unique_id "aoSD-2r_JutbFb-8svosWgAAAa8"] [Tue Aug 18 13:10:35.438928 2026] [security2:error] [pid 167459:tid 167634] [client 196.12.128.158:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD-2r_JutbFb-8svosWwAAAbw"] [Tue Aug 18 13:10:35.439063 2026] [security2:error] [pid 167459:tid 167634] [client 196.12.128.158:61941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSD-2r_JutbFb-8svosWwAAAbw"] [Tue Aug 18 13:10:35.445170 2026] [security2:error] [pid 167459:tid 167668] [client 4.232.151.198:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wpc.php"] [unique_id "aoSD-2r_JutbFb-8svosXAAAAd4"] [Tue Aug 18 13:10:35.491058 2026] [security2:error] [pid 167459:tid 167589] [client 20.116.17.175:22730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/yas.php"] [unique_id "aoSD-2r_JutbFb-8svosYAAAAY8"] [Tue Aug 18 13:10:35.500865 2026] [security2:error] [pid 167459:tid 167599] [client 20.118.172.148:57015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/hosty.php"] [unique_id "aoSD-2r_JutbFb-8svosYQAAAZk"] [Tue Aug 18 13:10:35.506465 2026] [security2:error] [pid 167459:tid 167531] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/log.php"] [unique_id "aoSD-2r_JutbFb-8svosYgAB50c"] [Tue Aug 18 13:10:35.574513 2026] [security2:error] [pid 167459:tid 167473] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/pi.php"] [unique_id "aoSD-2r_JutbFb-8svosZQAB0A0"] [Tue Aug 18 13:10:35.579576 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:35.579855 2026] [authz_core:error] [pid 167459:tid 167534] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:35.596878 2026] [security2:error] [pid 167459:tid 167688] [client 20.91.215.254:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "aoSD-2r_JutbFb-8svosZgAAAfI"] [Tue Aug 18 13:10:35.605584 2026] [security2:error] [pid 167459:tid 167595] [client 158.23.17.4:29456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/pu.php"] [unique_id "aoSD-2r_JutbFb-8svosZwAAAZU"] [Tue Aug 18 13:10:35.609953 2026] [security2:error] [pid 167459:tid 167666] [client 20.51.153.15:1967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/info2.php"] [unique_id "aoSD-2r_JutbFb-8svosaAAAAdw"] [Tue Aug 18 13:10:35.613495 2026] [security2:error] [pid 167459:tid 167632] [client 82.102.18.188:39304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "aoSD-2r_JutbFb-8svosaQAAAbo"] [Tue Aug 18 13:10:35.653645 2026] [security2:error] [pid 167459:tid 167586] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/lv.php"] [unique_id "aoSD-2r_JutbFb-8svosbAABpX4"] [Tue Aug 18 13:10:35.799966 2026] [security2:error] [pid 167459:tid 167600] [client 52.139.47.57:35301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "aoSD-2r_JutbFb-8svoscgAAAZo"] [Tue Aug 18 13:10:35.803243 2026] [security2:error] [pid 167459:tid 167505] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/mah/function.php"] [unique_id "aoSD-2r_JutbFb-8svoscwAB6y0"] [Tue Aug 18 13:10:35.809538 2026] [security2:error] [pid 167459:tid 167715] [client 74.248.18.37:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/aa.php"] [unique_id "aoSD-2r_JutbFb-8svosdQAAAg0"] [Tue Aug 18 13:10:35.875343 2026] [security2:error] [pid 167459:tid 167695] [client 20.51.153.15:1997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sx.php"] [unique_id "aoSD-2r_JutbFb-8svosewAAAfk"] [Tue Aug 18 13:10:35.882180 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:35.882613 2026] [authz_core:error] [pid 167459:tid 167524] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:35.888639 2026] [security2:error] [pid 167459:tid 167710] [client 20.118.172.148:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/test1.php"] [unique_id "aoSD-2r_JutbFb-8svosfQAAAgg"] [Tue Aug 18 13:10:35.912727 2026] [security2:error] [pid 167459:tid 167716] [client 20.116.17.175:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ah25.php"] [unique_id "aoSD-2r_JutbFb-8svosfwAAAg4"] [Tue Aug 18 13:10:35.939594 2026] [security2:error] [pid 167459:tid 167465] [remote 129.121.48.235:40704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.48.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-login.php"] [unique_id "aoSD-2r_JutbFb-8svosgQABuwU"] [Tue Aug 18 13:10:35.945956 2026] [security2:error] [pid 167459:tid 167530] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSD-2r_JutbFb-8svosggABkkY"] [Tue Aug 18 13:10:35.974495 2026] [security2:error] [pid 167459:tid 167683] [client 74.7.230.53:37214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.expeditions.atlas-ia.com"] [uri "/index.php"] [unique_id "aoSD-2r_JutbFb-8svosNgAB7Sw"] [Tue Aug 18 13:10:36.019425 2026] [security2:error] [pid 167459:tid 167690] [client 74.248.133.44:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/cnzcsfwm.php"] [unique_id "aoSD_Gr_JutbFb-8svosiQAAAfQ"] [Tue Aug 18 13:10:36.028204 2026] [security2:error] [pid 167459:tid 167555] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/info.php"] [unique_id "aoSD_Gr_JutbFb-8svosiwAB1F8"] [Tue Aug 18 13:10:36.028214 2026] [security2:error] [pid 167459:tid 167482] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/phpinfo.php"] [unique_id "aoSD_Gr_JutbFb-8svosjQAB1BY"] [Tue Aug 18 13:10:36.061709 2026] [security2:error] [pid 167459:tid 167626] [client 40.74.65.169:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/ccc.php"] [unique_id "aoSD_Gr_JutbFb-8svoskQAAAbQ"] [Tue Aug 18 13:10:36.064667 2026] [security2:error] [pid 167459:tid 167636] [client 20.91.215.254:12819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/php/cat.dev.php"] [unique_id "aoSD_Gr_JutbFb-8svoskgAAAb4"] [Tue Aug 18 13:10:36.094069 2026] [security2:error] [pid 167459:tid 167526] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/mass.php"] [unique_id "aoSD_Gr_JutbFb-8svoslAACC0I"] [Tue Aug 18 13:10:36.112673 2026] [security2:error] [pid 167459:tid 167714] [client 40.74.65.169:25457] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-admin/css/"] [unique_id "aoSD_Gr_JutbFb-8svoslQAAAgw"] [Tue Aug 18 13:10:36.133741 2026] [security2:error] [pid 167459:tid 167698] [client 20.51.153.15:13344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nu.php"] [unique_id "aoSD_Gr_JutbFb-8svoslgAAAfw"] [Tue Aug 18 13:10:36.144770 2026] [security2:error] [pid 167459:tid 167676] [client 20.116.17.175:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/spadex.php"] [unique_id "aoSD_Gr_JutbFb-8svoslwAAAeY"] [Tue Aug 18 13:10:36.151073 2026] [security2:error] [pid 167459:tid 167610] [client 102.213.179.104:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svosmAAAAaQ"] [Tue Aug 18 13:10:36.151203 2026] [security2:error] [pid 167459:tid 167610] [client 102.213.179.104:49973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svosmAAAAaQ"] [Tue Aug 18 13:10:36.159671 2026] [security2:error] [pid 167459:tid 167699] [client 68.155.154.236:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/assets/plugins/gmap/dapa.php"] [unique_id "aoSD_Gr_JutbFb-8svosmQAAAf0"] [Tue Aug 18 13:10:36.177725 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:36.177993 2026] [authz_core:error] [pid 167459:tid 167557] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:36.211674 2026] [security2:error] [pid 167459:tid 167694] [client 52.139.47.57:18532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/wp-load.php"] [unique_id "aoSD_Gr_JutbFb-8svosnwAAAfg"] [Tue Aug 18 13:10:36.221881 2026] [security2:error] [pid 167459:tid 167576] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/test.php"] [unique_id "aoSD_Gr_JutbFb-8svosoAABuXQ"] [Tue Aug 18 13:10:36.237383 2026] [security2:error] [pid 167459:tid 167666] [client 158.23.17.4:33534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ry.php"] [unique_id "aoSD_Gr_JutbFb-8svosoQAAAdw"] [Tue Aug 18 13:10:36.237893 2026] [security2:error] [pid 167459:tid 167510] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/memberfuns.php"] [unique_id "aoSD_Gr_JutbFb-8svosogABrDI"] [Tue Aug 18 13:10:36.239099 2026] [security2:error] [pid 167459:tid 167711] [client 213.35.127.232:58581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD_Gr_JutbFb-8svosowAAAgk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:36.253123 2026] [security2:error] [pid 167459:tid 167589] [client 20.91.215.254:12686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-admin/sx.php"] [unique_id "aoSD_Gr_JutbFb-8svospAAAAY8"] [Tue Aug 18 13:10:36.261615 2026] [security2:error] [pid 167459:tid 167603] [client 20.118.172.148:60468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/zwso.php"] [unique_id "aoSD_Gr_JutbFb-8svospQAAAZ0"] [Tue Aug 18 13:10:36.292135 2026] [security2:error] [pid 167459:tid 167625] [client 20.127.136.245:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSD_Gr_JutbFb-8svosqQAAAbM"] [Tue Aug 18 13:10:36.309323 2026] [security2:error] [pid 167459:tid 167617] [client 82.102.18.188:39318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "aoSD_Gr_JutbFb-8svosqgAAAas"] [Tue Aug 18 13:10:36.316528 2026] [security2:error] [pid 167459:tid 167667] [client 94.229.214.255:15952] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD_Gr_JutbFb-8svosqwAAAd0"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:36.385582 2026] [security2:error] [pid 167459:tid 167500] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/meta.php"] [unique_id "aoSD_Gr_JutbFb-8svosrwAB0ig"] [Tue Aug 18 13:10:36.436385 2026] [security2:error] [pid 167459:tid 167627] [client 20.116.17.175:45381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/ano.php"] [unique_id "aoSD_Gr_JutbFb-8svossAAAAbU"] [Tue Aug 18 13:10:36.473962 2026] [security2:error] [pid 167459:tid 167664] [client 20.51.153.15:1947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ko.php"] [unique_id "aoSD_Gr_JutbFb-8svosswAAAdo"] [Tue Aug 18 13:10:36.513921 2026] [security2:error] [pid 167459:tid 167615] [client 74.248.18.37:26284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/NewFile.php"] [unique_id "aoSD_Gr_JutbFb-8svostQAAAak"] [Tue Aug 18 13:10:36.533224 2026] [security2:error] [pid 167459:tid 167485] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/mini.php"] [unique_id "aoSD_Gr_JutbFb-8svostgAB4Rk"] [Tue Aug 18 13:10:36.549500 2026] [security2:error] [pid 167459:tid 167511] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "aoSD_Gr_JutbFb-8svosuAAB1zM"] [Tue Aug 18 13:10:36.550324 2026] [security2:error] [pid 167459:tid 167582] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/app_dev.php"] [unique_id "aoSD_Gr_JutbFb-8svosuwAB13o"] [Tue Aug 18 13:10:36.556400 2026] [security2:error] [pid 167459:tid 167546] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svosvAAB8VY"] [Tue Aug 18 13:10:36.556519 2026] [security2:error] [pid 167459:tid 167687] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svosvAAB8VY"] [Tue Aug 18 13:10:36.560879 2026] [security2:error] [pid 167459:tid 167541] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.27.110.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/i.php"] [unique_id "aoSD_Gr_JutbFb-8svosvQABzFE"] [Tue Aug 18 13:10:36.615572 2026] [security2:error] [pid 167459:tid 167643] [client 20.104.49.167:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/av.php"] [unique_id "aoSD_Gr_JutbFb-8svosvgAAAcU"] [Tue Aug 18 13:10:36.625650 2026] [security2:error] [pid 167459:tid 167696] [client 52.139.47.57:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/wp-login.php"] [unique_id "aoSD_Gr_JutbFb-8svoswAAAAfo"] [Tue Aug 18 13:10:36.677215 2026] [security2:error] [pid 167459:tid 167463] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/mm.php"] [unique_id "aoSD_Gr_JutbFb-8svoswwAB9AM"] [Tue Aug 18 13:10:36.704656 2026] [security2:error] [pid 167459:tid 167634] [client 158.23.17.4:9309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/pm.php"] [unique_id "aoSD_Gr_JutbFb-8svosxAAAAbw"] [Tue Aug 18 13:10:36.706662 2026] [security2:error] [pid 167459:tid 167660] [client 20.118.172.148:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/Geforce.php"] [unique_id "aoSD_Gr_JutbFb-8svosxQAAAdY"] [Tue Aug 18 13:10:36.741006 2026] [security2:error] [pid 167459:tid 167602] [client 74.248.18.37:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-mail.php"] [unique_id "aoSD_Gr_JutbFb-8svosyAAAAZw"] [Tue Aug 18 13:10:36.741752 2026] [security2:error] [pid 167459:tid 167657] [client 40.74.65.169:49067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/admin.php"] [unique_id "aoSD_Gr_JutbFb-8svosyQAAAdM"] [Tue Aug 18 13:10:36.745013 2026] [security2:error] [pid 167459:tid 167592] [client 20.91.215.254:12800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ebs.php7"] [unique_id "aoSD_Gr_JutbFb-8svosygAAAZI"] [Tue Aug 18 13:10:36.753113 2026] [security2:error] [pid 167459:tid 167684] [client 20.51.153.15:2033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/pl.php"] [unique_id "aoSD_Gr_JutbFb-8svosywAAAe4"] [Tue Aug 18 13:10:36.781632 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:36.781982 2026] [authz_core:error] [pid 167459:tid 167568] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:36.816392 2026] [security2:error] [pid 167459:tid 167708] [client 40.74.65.169:52289] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "aoSD_Gr_JutbFb-8svoszQAAAgY"] [Tue Aug 18 13:10:36.828530 2026] [security2:error] [pid 167459:tid 167677] [client 20.116.17.175:22662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/nwflm.php"] [unique_id "aoSD_Gr_JutbFb-8svos0AAAAec"] [Tue Aug 18 13:10:36.829983 2026] [security2:error] [pid 167459:tid 167487] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/modules/mod_footer.php"] [unique_id "aoSD_Gr_JutbFb-8svos0QABwxs"] [Tue Aug 18 13:10:36.841355 2026] [security2:error] [pid 167459:tid 167693] [client 20.250.13.23:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/min.php"] [unique_id "aoSD_Gr_JutbFb-8svos0wAAAfc"] [Tue Aug 18 13:10:36.935216 2026] [security2:error] [pid 167459:tid 167667] [client 94.229.214.255:15952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD_Gr_JutbFb-8svosqwAAAd0"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:36.973319 2026] [security2:error] [pid 167459:tid 167581] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/moon.php"] [unique_id "aoSD_Gr_JutbFb-8svos1gABpHk"] [Tue Aug 18 13:10:36.983249 2026] [security2:error] [pid 167459:tid 167597] [client 20.91.215.254:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/st.php"] [unique_id "aoSD_Gr_JutbFb-8svos1wAAAZc"] [Tue Aug 18 13:10:36.987407 2026] [security2:error] [pid 167459:tid 167669] [client 20.116.17.175:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-includes/block-bindings/index.php"] [unique_id "aoSD_Gr_JutbFb-8svos2AAAAd8"] [Tue Aug 18 13:10:36.996482 2026] [security2:error] [pid 167459:tid 167640] [client 4.232.151.198:47484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/fone1.php"] [unique_id "aoSD_Gr_JutbFb-8svos2QAAAcI"] [Tue Aug 18 13:10:37.003735 2026] [security2:error] [pid 167459:tid 167639] [client 20.104.49.167:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/images.php"] [unique_id "aoSD_Wr_JutbFb-8svos2wAAAcE"] [Tue Aug 18 13:10:37.008277 2026] [security2:error] [pid 167459:tid 167595] [client 20.51.153.15:13411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/env.php"] [unique_id "aoSD_Wr_JutbFb-8svos3AAAAZU"] [Tue Aug 18 13:10:37.021338 2026] [security2:error] [pid 167459:tid 167631] [client 20.127.136.245:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSD_Wr_JutbFb-8svos3gAAAbk"] [Tue Aug 18 13:10:37.048416 2026] [security2:error] [pid 167459:tid 167702] [client 52.139.47.57:9910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/wp-mail.php"] [unique_id "aoSD_Wr_JutbFb-8svos3wAAAgA"] [Tue Aug 18 13:10:37.073131 2026] [security2:error] [pid 167459:tid 167647] [client 49.37.150.8:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Wr_JutbFb-8svos4AAAAck"] [Tue Aug 18 13:10:37.073229 2026] [security2:error] [pid 167459:tid 167647] [client 49.37.150.8:64052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Wr_JutbFb-8svos4AAAAck"] [Tue Aug 18 13:10:37.082979 2026] [security2:error] [pid 167459:tid 167701] [client 49.145.211.146:11567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svos1QAAAf8"] [Tue Aug 18 13:10:37.083095 2026] [security2:error] [pid 167459:tid 167701] [client 49.145.211.146:11567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Gr_JutbFb-8svos1QAAAf8"] [Tue Aug 18 13:10:37.110361 2026] [security2:error] [pid 167459:tid 167589] [client 82.102.18.188:39330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "aoSD_Wr_JutbFb-8svos4gAAAY8"] [Tue Aug 18 13:10:37.118086 2026] [security2:error] [pid 167459:tid 167519] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/n.php"] [unique_id "aoSD_Wr_JutbFb-8svos4wAB7Ds"] [Tue Aug 18 13:10:37.149991 2026] [security2:error] [pid 167459:tid 167629] [client 103.120.71.157:60227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Wr_JutbFb-8svos5AAAAbc"] [Tue Aug 18 13:10:37.150156 2026] [security2:error] [pid 167459:tid 167629] [client 103.120.71.157:60227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_Wr_JutbFb-8svos5AAAAbc"] [Tue Aug 18 13:10:37.172982 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:37.173276 2026] [authz_core:error] [pid 167459:tid 167571] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:37.176743 2026] [security2:error] [pid 167459:tid 167685] [client 45.92.229.109:39077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.229.92.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ozzyfernandesoficial.com.br"] [uri "/wp-admin/plugins.php"] [unique_id "aoSD_Wr_JutbFb-8svos3QAAAe8"], referer: https://ozzyfernandesoficial.com.br/wp-login.php [Tue Aug 18 13:10:37.183238 2026] [security2:error] [pid 167459:tid 167646] [client 158.23.17.4:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/dr.php"] [unique_id "aoSD_Wr_JutbFb-8svos6AAAAcg"] [Tue Aug 18 13:10:37.211058 2026] [security2:error] [pid 167459:tid 167637] [client 20.118.172.148:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/fpwch.php"] [unique_id "aoSD_Wr_JutbFb-8svos6wAAAb8"] [Tue Aug 18 13:10:37.225754 2026] [security2:error] [pid 167459:tid 167699] [client 74.248.133.44:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/MYK4TJEfFvO.php"] [unique_id "aoSD_Wr_JutbFb-8svos8AAAAf0"] [Tue Aug 18 13:10:37.258745 2026] [security2:error] [pid 167459:tid 167697] [client 213.35.127.232:58777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSD_Wr_JutbFb-8svos8wAAAfs"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:37.265494 2026] [security2:error] [pid 167459:tid 167464] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/nc4.php"] [unique_id "aoSD_Wr_JutbFb-8svos9AABxAQ"] [Tue Aug 18 13:10:37.270578 2026] [security2:error] [pid 167459:tid 167678] [client 20.51.153.15:13406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/mz.php"] [unique_id "aoSD_Wr_JutbFb-8svos9QAAAeg"] [Tue Aug 18 13:10:37.370958 2026] [security2:error] [pid 167459:tid 167691] [client 68.155.154.236:25397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/mt/byp.php"] [unique_id "aoSD_Wr_JutbFb-8svos-gAAAfU"] [Tue Aug 18 13:10:37.375229 2026] [security2:error] [pid 167459:tid 167630] [client 20.116.17.175:45389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/wp-load.php"] [unique_id "aoSD_Wr_JutbFb-8svos-wAAAbg"] [Tue Aug 18 13:10:37.379813 2026] [security2:error] [pid 167459:tid 167617] [client 20.91.215.254:13047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/include/Lurd.class.php"] [unique_id "aoSD_Wr_JutbFb-8svos_AAAAas"] [Tue Aug 18 13:10:37.407989 2026] [security2:error] [pid 167459:tid 167561] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/new.php"] [unique_id "aoSD_Wr_JutbFb-8svos_QAB4WU"] [Tue Aug 18 13:10:37.426671 2026] [security2:error] [pid 167459:tid 167609] [client 40.85.222.29:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSD_Wr_JutbFb-8svos_wAAAaM"] [Tue Aug 18 13:10:37.437455 2026] [security2:error] [pid 167459:tid 167624] [client 40.74.65.169:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/reviall.php"] [unique_id "aoSD_Wr_JutbFb-8svotAAAAAbI"] [Tue Aug 18 13:10:37.472980 2026] [security2:error] [pid 167459:tid 167627] [client 52.139.47.57:2731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/wp-settings.php"] [unique_id "aoSD_Wr_JutbFb-8svotAwAAAbU"] [Tue Aug 18 13:10:37.517897 2026] [security2:error] [pid 167459:tid 167634] [client 40.74.65.169:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/pucci.php"] [unique_id "aoSD_Wr_JutbFb-8svotBQAAAbw"] [Tue Aug 18 13:10:37.527425 2026] [security2:error] [pid 167459:tid 167660] [client 20.104.49.167:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/ops.php"] [unique_id "aoSD_Wr_JutbFb-8svotBgAAAdY"] [Tue Aug 18 13:10:37.552056 2026] [access_compat:error] [pid 167459:tid 167523] [remote 136.110.27.48:34582] AH01797: client denied by server configuration: /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/server-status [Tue Aug 18 13:10:37.558167 2026] [security2:error] [pid 167459:tid 167556] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/packed.php"] [unique_id "aoSD_Wr_JutbFb-8svotCAAB02A"] [Tue Aug 18 13:10:37.573553 2026] [security2:error] [pid 167459:tid 167684] [client 20.127.136.245:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/0x.php"] [unique_id "aoSD_Wr_JutbFb-8svotCQAAAe4"] [Tue Aug 18 13:10:37.580537 2026] [security2:error] [pid 167459:tid 167707] [client 20.51.153.15:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ft.php"] [unique_id "aoSD_Wr_JutbFb-8svotCgAAAgU"] [Tue Aug 18 13:10:37.621926 2026] [security2:error] [pid 167459:tid 167661] [client 20.91.215.254:12692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-admin/includes/post.php"] [unique_id "aoSD_Wr_JutbFb-8svotDQAAAdc"] [Tue Aug 18 13:10:37.720371 2026] [security2:error] [pid 167459:tid 167667] [client 40.85.222.29:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSD_Wr_JutbFb-8svotEwAAAd0"] [Tue Aug 18 13:10:37.764315 2026] [security2:error] [pid 167459:tid 167621] [client 158.23.17.4:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ts.php"] [unique_id "aoSD_Wr_JutbFb-8svotFgAAAa8"] [Tue Aug 18 13:10:37.819089 2026] [security2:error] [pid 167459:tid 167640] [client 82.102.18.188:39332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "aoSD_Wr_JutbFb-8svotGQAAAcI"] [Tue Aug 18 13:10:37.835192 2026] [security2:error] [pid 167459:tid 167644] [client 74.248.18.37:26257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-Blogs.php"] [unique_id "aoSD_Wr_JutbFb-8svotGwAAAcY"] [Tue Aug 18 13:10:37.847568 2026] [security2:error] [pid 167459:tid 167702] [client 20.118.172.148:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-blog-header.php"] [unique_id "aoSD_Wr_JutbFb-8svotHAAAAgA"] [Tue Aug 18 13:10:37.850912 2026] [security2:error] [pid 167459:tid 167647] [client 158.23.17.4:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/tq.php"] [unique_id "aoSD_Wr_JutbFb-8svotHQAAAck"] [Tue Aug 18 13:10:37.859173 2026] [security2:error] [pid 167459:tid 167472] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/plugin.php"] [unique_id "aoSD_Wr_JutbFb-8svotHgACCQw"] [Tue Aug 18 13:10:37.871233 2026] [security2:error] [pid 167459:tid 167692] [client 20.51.153.15:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/h.php"] [unique_id "aoSD_Wr_JutbFb-8svotHwAAAfY"] [Tue Aug 18 13:10:37.880493 2026] [security2:error] [pid 167459:tid 167603] [client 20.104.49.167:40376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/coffexium.php"] [unique_id "aoSD_Wr_JutbFb-8svotIAAAAZ0"] [Tue Aug 18 13:10:37.882477 2026] [security2:error] [pid 167459:tid 167549] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/server-info"] [unique_id "aoSD_Wr_JutbFb-8svotIQABqFk"] [Tue Aug 18 13:10:37.885215 2026] [security2:error] [pid 167459:tid 167525] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.env"] [unique_id "aoSD_Wr_JutbFb-8svotJQABqEE"] [Tue Aug 18 13:10:37.895805 2026] [security2:error] [pid 167459:tid 167610] [client 52.139.47.57:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-admin/x.php"] [unique_id "aoSD_Wr_JutbFb-8svotJgAAAaQ"] [Tue Aug 18 13:10:37.898653 2026] [security2:error] [pid 167459:tid 167629] [client 68.155.154.236:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/MTOS/byp.php"] [unique_id "aoSD_Wr_JutbFb-8svotJwAAAbc"] [Tue Aug 18 13:10:37.987427 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:37.987680 2026] [authz_core:error] [pid 167459:tid 167471] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:38.004708 2026] [security2:error] [pid 167459:tid 167635] [client 40.85.222.29:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/weozh.php"] [unique_id "aoSD_mr_JutbFb-8svotLQAAAb0"] [Tue Aug 18 13:10:38.007487 2026] [security2:error] [pid 167459:tid 167676] [client 167.235.143.113:43344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.saojudas.com.br"] [uri "/index.php"] [unique_id "aoSD_Wr_JutbFb-8svotKQAAAeY"], referer: https://www.saojudas.com.br [Tue Aug 18 13:10:38.037630 2026] [security2:error] [pid 167459:tid 167637] [client 20.116.17.175:22779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/jj.php"] [unique_id "aoSD_mr_JutbFb-8svotLwAAAb8"] [Tue Aug 18 13:10:38.050773 2026] [security2:error] [pid 167459:tid 167631] [client 20.91.215.254:12841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/seoo/ulc2.php"] [unique_id "aoSD_mr_JutbFb-8svotMAAAAbk"] [Tue Aug 18 13:10:38.097135 2026] [security2:error] [pid 167459:tid 167703] [client 86.120.159.145:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_mr_JutbFb-8svotMwAAAgE"] [Tue Aug 18 13:10:38.097633 2026] [security2:error] [pid 167459:tid 167703] [client 86.120.159.145:63697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_mr_JutbFb-8svotMwAAAgE"] [Tue Aug 18 13:10:38.105536 2026] [security2:error] [pid 167459:tid 167656] [client 20.116.17.175:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/srontol.php"] [unique_id "aoSD_mr_JutbFb-8svotNAAAAdI"] [Tue Aug 18 13:10:38.112700 2026] [security2:error] [pid 167459:tid 167605] [client 74.248.133.44:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/Casper.php"] [unique_id "aoSD_mr_JutbFb-8svotNQAAAZ8"] [Tue Aug 18 13:10:38.131180 2026] [security2:error] [pid 167459:tid 167619] [client 40.74.65.169:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/nope.php"] [unique_id "aoSD_mr_JutbFb-8svotNwAAAa0"] [Tue Aug 18 13:10:38.163546 2026] [security2:error] [pid 167459:tid 167508] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/public/moon.php"] [unique_id "aoSD_mr_JutbFb-8svotOgACDjA"] [Tue Aug 18 13:10:38.229419 2026] [security2:error] [pid 167459:tid 167671] [client 40.74.65.169:25408] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/blocks/details/"] [unique_id "aoSD_mr_JutbFb-8svotPAAAAeE"] [Tue Aug 18 13:10:38.234527 2026] [security2:error] [pid 167459:tid 167687] [client 20.118.172.148:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/about/function.php"] [unique_id "aoSD_mr_JutbFb-8svotPQAAAfE"] [Tue Aug 18 13:10:38.246487 2026] [security2:error] [pid 167459:tid 167569] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_mr_JutbFb-8svotPgABo20"] [Tue Aug 18 13:10:38.246683 2026] [security2:error] [pid 167459:tid 167609] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSD_mr_JutbFb-8svotPgABo20"] [Tue Aug 18 13:10:38.271546 2026] [security2:error] [pid 167459:tid 167625] [client 213.35.127.232:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSD_mr_JutbFb-8svotQAAAAbM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:38.286708 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:38.286990 2026] [authz_core:error] [pid 167459:tid 167476] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:38.287242 2026] [security2:error] [pid 167459:tid 167696] [client 40.85.222.29:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/rymmm.php"] [unique_id "aoSD_mr_JutbFb-8svotQwAAAfo"] [Tue Aug 18 13:10:38.309590 2026] [security2:error] [pid 167459:tid 167462] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/public/storage.php"] [unique_id "aoSD_mr_JutbFb-8svotRAAB7QI"] [Tue Aug 18 13:10:38.339585 2026] [security2:error] [pid 167459:tid 167660] [client 158.23.17.4:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/53.php"] [unique_id "aoSD_mr_JutbFb-8svotRQAAAdY"] [Tue Aug 18 13:10:38.358991 2026] [security2:error] [pid 167459:tid 167623] [client 52.139.47.57:9870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-blogs.php"] [unique_id "aoSD_mr_JutbFb-8svotRwAAAbE"] [Tue Aug 18 13:10:38.369346 2026] [security2:error] [pid 167459:tid 167691] [client 20.91.215.254:12695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-configs.php"] [unique_id "aoSD_mr_JutbFb-8svotSAAAAfU"] [Tue Aug 18 13:10:38.400057 2026] [security2:error] [pid 167459:tid 167684] [client 52.173.121.69:46221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zjggu.php"] [unique_id "aoSD_mr_JutbFb-8svotSwAAAe4"] [Tue Aug 18 13:10:38.400429 2026] [security2:error] [pid 167459:tid 167591] [client 20.127.136.245:11573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/222.php"] [unique_id "aoSD_mr_JutbFb-8svotTAAAAZE"] [Tue Aug 18 13:10:38.455501 2026] [security2:error] [pid 167459:tid 167527] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/radio.php"] [unique_id "aoSD_mr_JutbFb-8svotTQABw0M"] [Tue Aug 18 13:10:38.463204 2026] [security2:error] [pid 167459:tid 167661] [client 20.51.153.15:13410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/40.php"] [unique_id "aoSD_mr_JutbFb-8svotUAAAAdc"] [Tue Aug 18 13:10:38.478648 2026] [security2:error] [pid 167459:tid 167590] [client 114.119.140.64:34295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.classeamotel.com"] [uri "/fotos/universitaria"] [unique_id "aoSD_mr_JutbFb-8svotUQAAAZA"], referer: https://www.classeamotel.com/fotos/universitaria?C=M%3BO%3DA [Tue Aug 18 13:10:38.496711 2026] [security2:error] [pid 167459:tid 167713] [client 82.102.18.188:39334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "aoSD_mr_JutbFb-8svotUgAAAgs"] [Tue Aug 18 13:10:38.497772 2026] [security2:error] [pid 167459:tid 167633] [client 20.116.17.175:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/img.php"] [unique_id "aoSD_mr_JutbFb-8svotVAAAAbs"] [Tue Aug 18 13:10:38.505074 2026] [security2:error] [pid 167459:tid 167612] [client 20.104.49.167:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/BDKR28WP.php"] [unique_id "aoSD_mr_JutbFb-8svotVQAAAaY"] [Tue Aug 18 13:10:38.513967 2026] [security2:error] [pid 167459:tid 167667] [client 20.118.133.132:45247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/classwithtostring.php"] [unique_id "aoSD_mr_JutbFb-8svotVgAAAd0"] [Tue Aug 18 13:10:38.517850 2026] [security2:error] [pid 167459:tid 167578] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.env.bak"] [unique_id "aoSD_mr_JutbFb-8svotWgABk3Y"] [Tue Aug 18 13:10:38.517858 2026] [security2:error] [pid 167459:tid 167572] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.env.backup"] [unique_id "aoSD_mr_JutbFb-8svotWQABk3A"] [Tue Aug 18 13:10:38.581901 2026] [security2:error] [pid 167459:tid 167639] [client 40.85.222.29:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/lddxs.php"] [unique_id "aoSD_mr_JutbFb-8svotYAAAAcE"] [Tue Aug 18 13:10:38.588136 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:38.588459 2026] [authz_core:error] [pid 167459:tid 167533] [remote 216.73.216.206:15459] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:38.605446 2026] [security2:error] [pid 167459:tid 167586] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/root.php"] [unique_id "aoSD_mr_JutbFb-8svotYQACAH4"] [Tue Aug 18 13:10:38.614187 2026] [security2:error] [pid 167459:tid 167701] [client 20.118.172.148:57532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/function/function.php"] [unique_id "aoSD_mr_JutbFb-8svotYgAAAf8"] [Tue Aug 18 13:10:38.649861 2026] [security2:error] [pid 167459:tid 167704] [client 74.248.18.37:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "aoSD_mr_JutbFb-8svotZAAAAgI"] [Tue Aug 18 13:10:38.703921 2026] [security2:error] [pid 167459:tid 167603] [client 20.51.153.15:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ee.php"] [unique_id "aoSD_mr_JutbFb-8svotZwAAAZ0"] [Tue Aug 18 13:10:38.712038 2026] [security2:error] [pid 167459:tid 167614] [client 158.23.17.4:56751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/cv.php"] [unique_id "aoSD_mr_JutbFb-8svotaAAAAag"] [Tue Aug 18 13:10:38.719753 2026] [security2:error] [pid 167459:tid 167636] [client 20.91.215.254:12735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/lite.php"] [unique_id "aoSD_mr_JutbFb-8svotaQAAAb4"] [Tue Aug 18 13:10:38.747584 2026] [security2:error] [pid 167459:tid 167465] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/server.php"] [unique_id "aoSD_mr_JutbFb-8svotbgAB4gU"] [Tue Aug 18 13:10:38.772917 2026] [security2:error] [pid 167459:tid 167711] [client 52.139.47.57:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content.attacker-decoy/themes/test.php"] [unique_id "aoSD_mr_JutbFb-8svotdAAAAgk"] [Tue Aug 18 13:10:38.806266 2026] [security2:error] [pid 167459:tid 167706] [client 20.116.17.175:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/file5.php"] [unique_id "aoSD_mr_JutbFb-8svotdgAAAgQ"] [Tue Aug 18 13:10:38.806871 2026] [security2:error] [pid 167459:tid 167676] [client 68.155.154.236:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "aoSD_mr_JutbFb-8svotdwAAAeY"] [Tue Aug 18 13:10:38.818247 2026] [security2:error] [pid 167459:tid 167482] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.env.old"] [unique_id "aoSD_mr_JutbFb-8svoteAACAxY"] [Tue Aug 18 13:10:38.829198 2026] [security2:error] [pid 167459:tid 167665] [client 40.74.65.169:49066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/nope.php"] [unique_id "aoSD_mr_JutbFb-8svotegAAAds"] [Tue Aug 18 13:10:38.857090 2026] [security2:error] [pid 167459:tid 167631] [client 40.85.222.29:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/zjggu.php"] [unique_id "aoSD_mr_JutbFb-8svotewAAAbk"] [Tue Aug 18 13:10:38.876694 2026] [security2:error] [pid 167459:tid 167663] [client 20.127.136.245:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/aa.php"] [unique_id "aoSD_mr_JutbFb-8svotfAAAAdk"] [Tue Aug 18 13:10:38.889535 2026] [security2:error] [pid 167459:tid 167697] [client 20.171.51.14:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ka.php"] [unique_id "aoSD_mr_JutbFb-8svotfwAAAfs"] [Tue Aug 18 13:10:38.908783 2026] [security2:error] [pid 167459:tid 167512] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "aoSD_mr_JutbFb-8svotgAAB6zQ"] [Tue Aug 18 13:10:38.936324 2026] [security2:error] [pid 167459:tid 167695] [client 40.74.65.169:52281] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "aoSD_mr_JutbFb-8svotggAAAfk"] [Tue Aug 18 13:10:38.960778 2026] [security2:error] [pid 167459:tid 167671] [client 168.62.48.100:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/zugvi.php"] [unique_id "aoSD_mr_JutbFb-8svotgwAAAeE"] [Tue Aug 18 13:10:38.961522 2026] [security2:error] [pid 167459:tid 167687] [client 20.118.172.148:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-signin.php"] [unique_id "aoSD_mr_JutbFb-8svothQAAAfE"] [Tue Aug 18 13:10:38.969025 2026] [security2:error] [pid 167459:tid 167650] [client 158.23.17.4:9369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/lq.php"] [unique_id "aoSD_mr_JutbFb-8svothgAAAcw"] [Tue Aug 18 13:10:38.992501 2026] [security2:error] [pid 167459:tid 167478] [remote 192.250.229.214:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.229.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jic.org.br"] [uri "/wp-login.php"] [unique_id "aoSD_mr_JutbFb-8svotigABxhI"] [Tue Aug 18 13:10:38.994064 2026] [security2:error] [pid 167459:tid 167688] [client 20.51.153.15:2018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ak.php"] [unique_id "aoSD_mr_JutbFb-8svotiwAAAfI"] [Tue Aug 18 13:10:39.006953 2026] [security2:error] [pid 167459:tid 167635] [client 20.91.215.254:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-post.php"] [unique_id "aoSD_2r_JutbFb-8svotjAAAAb0"] [Tue Aug 18 13:10:39.042110 2026] [security2:error] [pid 167459:tid 167503] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/backend/.env"] [unique_id "aoSD_2r_JutbFb-8svotqQAB7Ss"] [Tue Aug 18 13:10:39.042850 2026] [security2:error] [pid 167459:tid 167501] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/config/.env"] [unique_id "aoSD_2r_JutbFb-8svotqgAB7Sk"] [Tue Aug 18 13:10:39.043034 2026] [security2:error] [pid 167459:tid 167581] [remote 136.110.27.48:34582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/api/.env"] [unique_id "aoSD_2r_JutbFb-8svotqwAB7Xk"] [Tue Aug 18 13:10:39.068534 2026] [security2:error] [pid 167459:tid 167529] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/shell.php"] [unique_id "aoSD_2r_JutbFb-8svottQAB1kU"] [Tue Aug 18 13:10:39.288345 2026] [security2:error] [pid 167459:tid 167615] [client 213.35.127.232:59222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSD_2r_JutbFb-8svottwAAAak"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:39.741671 2026] [security2:error] [pid 167459:tid 167623] [client 74.248.133.44:14968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/beence.php"] [unique_id "aoSD_2r_JutbFb-8svotuAAAAbE"] [Tue Aug 18 13:10:39.775271 2026] [http2:info] [pid 180811:tid 180811] h2_workers: created with min=128 max=192 idle_ms=600000 [Tue Aug 18 13:10:39.797042 2026] [security2:error] [pid 180811:tid 180944] [client 20.118.133.132:31284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/wp-ws68.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdMwAAAAM"] [Tue Aug 18 13:10:39.798010 2026] [security2:error] [pid 180811:tid 180942] [client 20.171.51.14:2699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ot.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdNAAAAAE"] [Tue Aug 18 13:10:39.798233 2026] [security2:error] [pid 180811:tid 180943] [client 20.104.49.167:32467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/sf.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdNQAAAAI"] [Tue Aug 18 13:10:39.798599 2026] [security2:error] [pid 180811:tid 180946] [client 40.85.222.29:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/dlvqo.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdNgAAAAU"] [Tue Aug 18 13:10:39.799108 2026] [security2:error] [pid 180811:tid 180948] [client 20.118.172.148:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/f35.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdNwAAAAc"] [Tue Aug 18 13:10:39.799397 2026] [security2:error] [pid 180811:tid 180950] [client 68.155.154.236:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-content/themes/home/index.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdOAAAAAk"] [Tue Aug 18 13:10:39.799837 2026] [security2:error] [pid 180811:tid 180952] [client 82.102.18.188:39348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "aoSD_0m4-PkKNOC4yxZdOQAAAAs"] [Tue Aug 18 13:10:39.800166 2026] [security2:error] [pid 180811:tid 180954] [client 20.51.153.15:1982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/test_info.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdOgAAAA0"] [Tue Aug 18 13:10:39.800599 2026] [security2:error] [pid 180811:tid 180956] [client 20.116.17.175:41509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.michelepamela.com.br"] [uri "/we.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdOwAAAA8"] [Tue Aug 18 13:10:39.800745 2026] [security2:error] [pid 180811:tid 180958] [client 20.127.136.245:5008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/abcd.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdPAAAABE"] [Tue Aug 18 13:10:39.801473 2026] [security2:error] [pid 180811:tid 180962] [client 158.23.17.4:10979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/you.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdPgAAABU"] [Tue Aug 18 13:10:39.801607 2026] [security2:error] [pid 180811:tid 180964] [client 40.74.65.169:64205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/new.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdPwAAABc"] [Tue Aug 18 13:10:39.804507 2026] [security2:error] [pid 180811:tid 180966] [client 40.74.65.169:25450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-temp.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdQAAAABk"] [Tue Aug 18 13:10:39.894308 2026] [security2:error] [pid 180811:tid 180982] [client 20.116.17.175:44732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/yup.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdRwAAACk"] [Tue Aug 18 13:10:39.941680 2026] [security2:error] [pid 180811:tid 180848] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/sim.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdZwAAECQ"] [Tue Aug 18 13:10:39.942214 2026] [security2:error] [pid 180811:tid 180967] [client 52.139.47.57:13707] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdbgAAABo"] [Tue Aug 18 13:10:39.942304 2026] [security2:error] [pid 180811:tid 180967] [client 52.139.47.57:13707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/1.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdbgAAABo"] [Tue Aug 18 13:10:39.966547 2026] [authz_core:error] [pid 180811:tid 180857] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:39.966642 2026] [authz_core:error] [pid 180811:tid 180856] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:39.966855 2026] [authz_core:error] [pid 180811:tid 180857] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:39.966913 2026] [authz_core:error] [pid 180811:tid 180856] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:40.017010 2026] [security2:error] [pid 180811:tid 180949] [client 20.91.215.254:13045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/uploads/index.php/wp-includes/Text/"] [unique_id "aoSEAEm4-PkKNOC4yxZdcwAAAAg"] [Tue Aug 18 13:10:40.021737 2026] [security2:error] [pid 180811:tid 180969] [client 20.91.215.254:14310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp/images/my.php"] [unique_id "aoSEAEm4-PkKNOC4yxZddAAAABw"] [Tue Aug 18 13:10:40.082359 2026] [security2:error] [pid 180811:tid 181005] [client 40.85.222.29:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/pkmoj.php"] [unique_id "aoSEAEm4-PkKNOC4yxZddgAAAEA"] [Tue Aug 18 13:10:40.087438 2026] [security2:error] [pid 180811:tid 180860] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/simple.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdeAAAQTA"] [Tue Aug 18 13:10:40.092084 2026] [authz_core:error] [pid 180811:tid 180859] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:40.092383 2026] [authz_core:error] [pid 180811:tid 180859] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:40.143337 2026] [security2:error] [pid 180811:tid 180960] [client 142.111.55.53:55146] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdPQAAABM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:40.212590 2026] [security2:error] [pid 180811:tid 181018] [client 20.118.172.148:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/gg.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdgQAAAE0"] [Tue Aug 18 13:10:40.232561 2026] [security2:error] [pid 180811:tid 180873] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/st.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdiAAAUj0"] [Tue Aug 18 13:10:40.252419 2026] [security2:error] [pid 180811:tid 181026] [client 20.51.153.15:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/14.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdiQAAAFU"] [Tue Aug 18 13:10:40.308987 2026] [security2:error] [pid 180811:tid 180991] [client 213.35.127.232:59429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdigAAADI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:40.318482 2026] [security2:error] [pid 180811:tid 181029] [client 158.23.17.4:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ez.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdiwAAAFg"] [Tue Aug 18 13:10:40.362196 2026] [security2:error] [pid 180811:tid 181030] [client 40.85.222.29:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/kopyw.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdjAAAAFk"] [Tue Aug 18 13:10:40.369251 2026] [security2:error] [pid 180811:tid 181021] [client 52.139.47.57:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdjQAAAFA"] [Tue Aug 18 13:10:40.385865 2026] [security2:error] [pid 180811:tid 180874] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/subdom/ant/makeasmtp.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdjgAAXD4"] [Tue Aug 18 13:10:40.392770 2026] [security2:error] [pid 180811:tid 180951] [client 74.248.18.37:32918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/themes.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdjwAAAAo"] [Tue Aug 18 13:10:40.414872 2026] [security2:error] [pid 180811:tid 181036] [client 52.173.121.69:56003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/dlvqo.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdkAAAAF8"] [Tue Aug 18 13:10:40.463902 2026] [security2:error] [pid 180811:tid 181041] [client 20.127.136.245:7359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/admin.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdkQAAAGQ"] [Tue Aug 18 13:10:40.486585 2026] [security2:error] [pid 180811:tid 181045] [client 40.74.65.169:49087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/new.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdkwAAAGg"] [Tue Aug 18 13:10:40.502455 2026] [security2:error] [pid 180811:tid 181049] [client 40.74.65.169:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-admin/js/index.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdlQAAAGw"] [Tue Aug 18 13:10:40.521172 2026] [security2:error] [pid 180811:tid 181053] [client 82.102.18.188:39358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "aoSEAEm4-PkKNOC4yxZdlgAAAHA"] [Tue Aug 18 13:10:40.531190 2026] [security2:error] [pid 180811:tid 180876] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/system.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdlwAAckA"] [Tue Aug 18 13:10:40.552538 2026] [security2:error] [pid 180811:tid 181056] [client 158.23.17.4:15800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/un.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdmQAAAHM"] [Tue Aug 18 13:10:40.569238 2026] [security2:error] [pid 180811:tid 181060] [client 20.51.153.15:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tk.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdmwAAAHc"] [Tue Aug 18 13:10:40.582437 2026] [security2:error] [pid 180811:tid 181061] [client 20.118.172.148:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/class.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdnAAAAHg"] [Tue Aug 18 13:10:40.615071 2026] [security2:error] [pid 180811:tid 181064] [client 68.155.154.236:25407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdngAAAHs"] [Tue Aug 18 13:10:40.635384 2026] [security2:error] [pid 180811:tid 180880] [remote 47.128.40.33:37788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villasgarage.com.br"] [uri "/robots.txt"] [unique_id "aoSEAEm4-PkKNOC4yxZdoAAAA0Q"] [Tue Aug 18 13:10:40.656882 2026] [security2:error] [pid 180811:tid 180942] [client 40.85.222.29:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/zznmg.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdogAAAAE"] [Tue Aug 18 13:10:40.676533 2026] [security2:error] [pid 180811:tid 180883] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/system_log.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdpAAACUc"] [Tue Aug 18 13:10:40.696951 2026] [security2:error] [pid 180811:tid 181046] [client 20.91.215.254:14321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/alfa-rex1.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdpgAAAGk"] [Tue Aug 18 13:10:40.699529 2026] [security2:error] [pid 180811:tid 181047] [client 20.91.215.254:12832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-content/function.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdpwAAAGo"] [Tue Aug 18 13:10:40.713505 2026] [security2:error] [pid 180811:tid 181015] [client 74.248.18.37:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/bolt.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdqAAAAEo"] [Tue Aug 18 13:10:40.741192 2026] [security2:error] [pid 180811:tid 180959] [client 223.185.37.47:15694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdrAAAABI"] [Tue Aug 18 13:10:40.750438 2026] [security2:error] [pid 180811:tid 180959] [client 223.185.37.47:15694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdrAAAABI"] [Tue Aug 18 13:10:40.781049 2026] [authz_core:error] [pid 180811:tid 180889] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:40.781309 2026] [authz_core:error] [pid 180811:tid 180889] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:40.781982 2026] [security2:error] [pid 180811:tid 180960] [client 142.111.55.53:55146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "plenitude.com.br"] [uri "/wp-comments-post.php"] [unique_id "aoSD_0m4-PkKNOC4yxZdPQAAABM"], referer: http://plenitude.com.br/como-a-reprogramacao-mental-equilibra/ [Tue Aug 18 13:10:40.823711 2026] [security2:error] [pid 180811:tid 180952] [client 52.139.47.57:35314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/api.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdrwAAAAs"] [Tue Aug 18 13:10:40.827866 2026] [security2:error] [pid 180811:tid 180892] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/templates/beez3/error.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdsgAAGlA"] [Tue Aug 18 13:10:40.834064 2026] [security2:error] [pid 180811:tid 180968] [client 20.116.17.175:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/classwithtostring.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdswAAABs"] [Tue Aug 18 13:10:40.840378 2026] [security2:error] [pid 180811:tid 180970] [client 158.23.17.4:29491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/asus.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdtAAAAB0"] [Tue Aug 18 13:10:40.883360 2026] [security2:error] [pid 180811:tid 180893] [remote 136.110.27.48:33158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.github/.env"] [unique_id "aoSEAEm4-PkKNOC4yxZdtQAAL1E"] [Tue Aug 18 13:10:40.906029 2026] [security2:error] [pid 180811:tid 180995] [client 20.51.153.15:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/hp.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdugAAADY"] [Tue Aug 18 13:10:40.912312 2026] [security2:error] [pid 180811:tid 180980] [client 4.232.94.69:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/fxcexgle.php"] [unique_id "aoSEAEm4-PkKNOC4yxZduwAAACc"] [Tue Aug 18 13:10:40.918430 2026] [security2:error] [pid 180811:tid 181027] [client 74.248.133.44:12656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/configs.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdvQAAAFY"] [Tue Aug 18 13:10:40.947486 2026] [security2:error] [pid 180811:tid 180983] [client 20.104.49.167:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/k.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdvwAAACo"] [Tue Aug 18 13:10:40.955509 2026] [security2:error] [pid 180811:tid 181002] [client 40.85.222.29:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/bhfnd.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdwAAAAD0"] [Tue Aug 18 13:10:40.975076 2026] [security2:error] [pid 180811:tid 180901] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/test.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdwwAAQlk"] [Tue Aug 18 13:10:40.983628 2026] [security2:error] [pid 180811:tid 180947] [client 176.36.146.80:57099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.146.36.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automoveismn.com.br"] [uri "/envia-contato.php"] [unique_id "aoSEAEm4-PkKNOC4yxZdxQAAAAY"], referer: https://automoveismn.com.br/contato [Tue Aug 18 13:10:41.013813 2026] [security2:error] [pid 180811:tid 181012] [client 20.118.172.148:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/flower.php"] [unique_id "aoSEAUm4-PkKNOC4yxZdyAAAAEc"] [Tue Aug 18 13:10:41.041869 2026] [security2:error] [pid 180811:tid 181058] [client 149.34.210.141:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSEAUm4-PkKNOC4yxZdywAAAHU"] [Tue Aug 18 13:10:41.093231 2026] [security2:error] [pid 180811:tid 181017] [client 20.118.133.132:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/mgrr.php"] [unique_id "aoSEAUm4-PkKNOC4yxZdzQAAAEw"] [Tue Aug 18 13:10:41.122252 2026] [security2:error] [pid 180811:tid 180906] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/test1.php"] [unique_id "aoSEAUm4-PkKNOC4yxZdzwAAWF4"] [Tue Aug 18 13:10:41.157159 2026] [security2:error] [pid 180811:tid 181034] [client 20.51.153.15:1955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wx.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd0AAAAF0"] [Tue Aug 18 13:10:41.161162 2026] [security2:error] [pid 180811:tid 181035] [client 20.127.136.245:19187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/adminfuns.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd0QAAAF4"] [Tue Aug 18 13:10:41.180777 2026] [security2:error] [pid 180811:tid 181040] [client 40.74.65.169:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/puc.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd1QAAAGM"] [Tue Aug 18 13:10:41.184574 2026] [security2:error] [pid 180811:tid 181042] [client 40.74.65.169:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/apreset.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd1gAAAGU"] [Tue Aug 18 13:10:41.195385 2026] [fcgid:warn] [pid 180811:tid 181043] (70014)End of file found: [client 66.132.186.199:4724] mod_fcgid: can't get data from http client [Tue Aug 18 13:10:41.199865 2026] [security2:error] [pid 180811:tid 181044] [client 82.102.18.188:39362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "aoSEAUm4-PkKNOC4yxZd2QAAAGc"] [Tue Aug 18 13:10:41.238143 2026] [security2:error] [pid 180811:tid 181019] [client 52.139.47.57:9872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/ccx/index.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd3AAAAE4"] [Tue Aug 18 13:10:41.249794 2026] [security2:error] [pid 180811:tid 181051] [client 40.85.222.29:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/qfvqu.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd3QAAAG4"] [Tue Aug 18 13:10:41.266774 2026] [security2:error] [pid 180811:tid 180911] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/text.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd3gAAb2M"] [Tue Aug 18 13:10:41.317375 2026] [security2:error] [pid 180811:tid 181058] [client 149.34.210.141:62507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSEAUm4-PkKNOC4yxZdywAAAHU"] [Tue Aug 18 13:10:41.326921 2026] [security2:error] [pid 180811:tid 181010] [client 213.35.127.232:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd4AAAAEU"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:41.339558 2026] [authz_core:error] [pid 180811:tid 180913] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:41.339932 2026] [authz_core:error] [pid 180811:tid 180913] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:41.345252 2026] [security2:error] [pid 180811:tid 181064] [client 158.23.17.4:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/22.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd5AAAAHs"] [Tue Aug 18 13:10:41.349345 2026] [security2:error] [pid 180811:tid 181030] [client 20.91.215.254:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-content/plugins/alfanew.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd5QAAAFk"] [Tue Aug 18 13:10:41.357242 2026] [security2:error] [pid 180811:tid 181033] [client 4.232.94.69:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/locale.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd5wAAAFw"] [Tue Aug 18 13:10:41.362680 2026] [security2:error] [pid 180811:tid 181021] [client 20.91.215.254:14293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-2019.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd6AAAAFA"] [Tue Aug 18 13:10:41.366230 2026] [security2:error] [pid 180811:tid 181067] [client 20.118.172.148:39186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/motu.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd6QAAAH4"] [Tue Aug 18 13:10:41.416085 2026] [security2:error] [pid 180811:tid 180918] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/themes/zmousse/otuz1.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd7AAAAWo"] [Tue Aug 18 13:10:41.426364 2026] [security2:error] [pid 180811:tid 181018] [client 114.119.149.66:40237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "themenstyle.com.br"] [uri "/the-knockout-with-david-grinsfelder/"] [unique_id "aoSEAUm4-PkKNOC4yxZd7QAAAE0"], referer: https://laruicci.com/fr/blogs/news/laruicci-x-the-mens-style [Tue Aug 18 13:10:41.525000 2026] [security2:error] [pid 180811:tid 180998] [client 136.144.35.194:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botheschafer.com.br"] [uri "/wp-login.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd7wAAADk"] [Tue Aug 18 13:10:41.539567 2026] [security2:error] [pid 180811:tid 180941] [client 40.85.222.29:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/oivcl.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd8AAAAAA"] [Tue Aug 18 13:10:41.563088 2026] [security2:error] [pid 180811:tid 180921] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/u.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd8wAAJm0"] [Tue Aug 18 13:10:41.574990 2026] [security2:error] [pid 180811:tid 180952] [client 20.51.153.15:1881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/dj.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd9AAAAAs"] [Tue Aug 18 13:10:41.620320 2026] [authz_core:error] [pid 180811:tid 180922] [remote 136.110.27.48:33158] AH01630: client denied by server configuration: /home4/gueirosadv/_wildcard_.gueirosadvocacia.com.br/.htpasswd [Tue Aug 18 13:10:41.650579 2026] [security2:error] [pid 180811:tid 180968] [client 68.155.154.236:25383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/Text/Diff/Engine/upload.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd-wAAABs"] [Tue Aug 18 13:10:41.654227 2026] [security2:error] [pid 180811:tid 180956] [client 52.139.47.57:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/db-status.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd_QAAAA8"] [Tue Aug 18 13:10:41.686712 2026] [security2:error] [pid 180811:tid 180988] [client 20.118.172.148:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/404.php"] [unique_id "aoSEAUm4-PkKNOC4yxZd_gAAAC8"] [Tue Aug 18 13:10:41.703241 2026] [security2:error] [pid 180811:tid 181054] [client 74.248.18.37:38243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/bthil.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeAAAAAHE"] [Tue Aug 18 13:10:41.708650 2026] [security2:error] [pid 180811:tid 180930] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/updates.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeAQAANXY"] [Tue Aug 18 13:10:41.808390 2026] [security2:error] [pid 180811:tid 181004] [client 20.116.17.175:44701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-the.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeBQAAAD8"] [Tue Aug 18 13:10:41.809463 2026] [security2:error] [pid 180811:tid 181005] [client 20.51.153.15:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fa.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeBgAAAEA"] [Tue Aug 18 13:10:41.844586 2026] [security2:error] [pid 180811:tid 180947] [client 20.127.136.245:16875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/akc.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeCAAAAAY"] [Tue Aug 18 13:10:41.860126 2026] [security2:error] [pid 180811:tid 180978] [client 40.74.65.169:49035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/1mage.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeCQAAACU"] [Tue Aug 18 13:10:41.861902 2026] [security2:error] [pid 180811:tid 180935] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/upload/autoload_classmap.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeCgAAR3s"] [Tue Aug 18 13:10:41.866989 2026] [security2:error] [pid 180811:tid 181011] [client 40.74.65.169:25409] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/Requests/"] [unique_id "aoSEAUm4-PkKNOC4yxZeCwAAAEY"] [Tue Aug 18 13:10:41.898775 2026] [authz_core:error] [pid 180811:tid 180936] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:41.899030 2026] [authz_core:error] [pid 180811:tid 180936] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:41.910869 2026] [security2:error] [pid 180811:tid 180965] [client 82.102.18.188:39368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "aoSEAUm4-PkKNOC4yxZeDgAAABg"] [Tue Aug 18 13:10:41.971605 2026] [security2:error] [pid 180811:tid 181035] [client 20.118.133.132:31232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/55.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeEwAAAF4"] [Tue Aug 18 13:10:41.989390 2026] [security2:error] [pid 180811:tid 181036] [client 40.85.222.29:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/zugvi.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeFAAAAF8"] [Tue Aug 18 13:10:41.990157 2026] [security2:error] [pid 180811:tid 181027] [client 4.232.94.69:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/cache-base.php"] [unique_id "aoSEAUm4-PkKNOC4yxZeFQAAAFY"] [Tue Aug 18 13:10:42.004174 2026] [security2:error] [pid 180811:tid 181002] [client 20.91.215.254:12679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/cjfuns.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeFgAAAD0"] [Tue Aug 18 13:10:42.004545 2026] [security2:error] [pid 180811:tid 181003] [client 20.91.215.254:14303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/xmrlpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeFwAAAD4"] [Tue Aug 18 13:10:42.013747 2026] [security2:error] [pid 180811:tid 180812] [remote 20.250.13.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.3xsolutions.com.br"] [uri "/uploads/admin.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeGQAAZAA"] [Tue Aug 18 13:10:42.018939 2026] [security2:error] [pid 180811:tid 181047] [client 4.232.151.198:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/ncx.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeGwAAAGo"] [Tue Aug 18 13:10:42.082852 2026] [security2:error] [pid 180811:tid 181025] [client 52.139.47.57:16765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/endurance-page-cache/wp-content/module.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeHQAAAFQ"] [Tue Aug 18 13:10:42.106005 2026] [security2:error] [pid 180811:tid 181045] [client 20.171.51.14:31084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ih.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeHwAAAGg"] [Tue Aug 18 13:10:42.129351 2026] [security2:error] [pid 180811:tid 181051] [client 20.51.153.15:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/fb.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeIAAAAG4"] [Tue Aug 18 13:10:42.137305 2026] [security2:error] [pid 180811:tid 180816] [remote 136.110.27.48:33158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_dsa"] [unique_id "aoSEAkm4-PkKNOC4yxZeIQAAIwQ"] [Tue Aug 18 13:10:42.141311 2026] [security2:error] [pid 180811:tid 180819] [remote 136.110.27.48:33158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/.ssh/id_rsa"] [unique_id "aoSEAkm4-PkKNOC4yxZeJAAAIwc"] [Tue Aug 18 13:10:42.172134 2026] [security2:error] [pid 180811:tid 180946] [client 158.23.17.4:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/zs.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeJwAAAAU"] [Tue Aug 18 13:10:42.205056 2026] [authz_core:error] [pid 180811:tid 180838] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:42.205516 2026] [authz_core:error] [pid 180811:tid 180838] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:42.214596 2026] [security2:error] [pid 180811:tid 181010] [client 20.118.172.148:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/lite.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeKwAAAEU"] [Tue Aug 18 13:10:42.243878 2026] [security2:error] [pid 180811:tid 181063] [client 20.104.49.167:19261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/82.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeLAAAAHo"] [Tue Aug 18 13:10:42.289687 2026] [security2:error] [pid 180811:tid 181030] [client 40.85.222.29:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wsrer.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeLwAAAFk"] [Tue Aug 18 13:10:42.301557 2026] [security2:error] [pid 180811:tid 181033] [client 20.116.17.175:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/cong.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeMAAAAFw"] [Tue Aug 18 13:10:42.347016 2026] [security2:error] [pid 180811:tid 181040] [client 213.35.127.232:59889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeMQAAAGM"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:42.388533 2026] [security2:error] [pid 180811:tid 180945] [client 20.51.153.15:1873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gw.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeMwAAAAQ"] [Tue Aug 18 13:10:42.481113 2026] [security2:error] [pid 180811:tid 181013] [client 178.153.171.161:30800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeNQAAAEg"] [Tue Aug 18 13:10:42.481273 2026] [security2:error] [pid 180811:tid 181013] [client 178.153.171.161:30800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeNQAAAEg"] [Tue Aug 18 13:10:42.505105 2026] [security2:error] [pid 180811:tid 180944] [client 52.139.47.57:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.47.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.zelareimoveis.com.br"] [uri "/wp-content/home.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeNwAAAAM"] [Tue Aug 18 13:10:42.508086 2026] [authz_core:error] [pid 180811:tid 180842] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:42.508564 2026] [authz_core:error] [pid 180811:tid 180842] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:42.540627 2026] [security2:error] [pid 180811:tid 181015] [client 40.74.65.169:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/imsc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeOAAAAEo"] [Tue Aug 18 13:10:42.549014 2026] [security2:error] [pid 180811:tid 180958] [client 40.74.65.169:52319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/8.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeOQAAABE"] [Tue Aug 18 13:10:42.578803 2026] [security2:error] [pid 180811:tid 180998] [client 40.85.222.29:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/ucpfr.php"] [unique_id "aoSEAkm4-PkKNOC4yxZePQAAADk"] [Tue Aug 18 13:10:42.593117 2026] [security2:error] [pid 180811:tid 181031] [client 68.155.154.236:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wordpress/wp-content/plugins/cvqvgfk/index.php"] [unique_id "aoSEAkm4-PkKNOC4yxZePgAAAFo"] [Tue Aug 18 13:10:42.623643 2026] [security2:error] [pid 180811:tid 180941] [client 20.118.172.148:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/lock360.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeQAAAAAA"] [Tue Aug 18 13:10:42.623780 2026] [security2:error] [pid 180811:tid 181008] [client 157.20.138.62:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZePwAAAEM"] [Tue Aug 18 13:10:42.623887 2026] [security2:error] [pid 180811:tid 181008] [client 157.20.138.62:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZePwAAAEM"] [Tue Aug 18 13:10:42.624839 2026] [security2:error] [pid 180811:tid 180966] [client 82.102.18.188:39372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "aoSEAkm4-PkKNOC4yxZeQQAAABk"] [Tue Aug 18 13:10:42.630133 2026] [security2:error] [pid 180811:tid 181039] [client 20.51.153.15:13345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/sw.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeQgAAAGI"] [Tue Aug 18 13:10:42.658519 2026] [security2:error] [pid 180811:tid 180954] [client 4.232.94.69:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/lite.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeRQAAAA0"] [Tue Aug 18 13:10:42.659435 2026] [security2:error] [pid 180811:tid 181001] [client 20.91.215.254:12724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/user/12.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeRgAAADw"] [Tue Aug 18 13:10:42.736050 2026] [security2:error] [pid 180811:tid 181049] [client 20.104.49.167:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/dex.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeSAAAAGw"] [Tue Aug 18 13:10:42.736511 2026] [security2:error] [pid 180811:tid 180957] [client 20.127.136.245:16881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/buy.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeSQAAABA"] [Tue Aug 18 13:10:42.789483 2026] [security2:error] [pid 180811:tid 181048] [client 20.91.215.254:23106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-content/plugins/fix/00.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeTAAAAGs"] [Tue Aug 18 13:10:42.808752 2026] [authz_core:error] [pid 180811:tid 180847] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:42.809028 2026] [authz_core:error] [pid 180811:tid 180847] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:42.860160 2026] [security2:error] [pid 180811:tid 180989] [client 158.23.17.4:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/iz.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeUAAAADA"] [Tue Aug 18 13:10:42.860897 2026] [security2:error] [pid 180811:tid 180970] [client 40.85.222.29:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/yxijx.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeUQAAAB0"] [Tue Aug 18 13:10:42.957601 2026] [security2:error] [pid 180811:tid 180978] [client 52.173.121.69:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/pkmoj.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeVQAAACU"] [Tue Aug 18 13:10:42.979632 2026] [security2:error] [pid 180811:tid 180960] [client 46.102.21.132:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.21.102.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeVgAAABM"] [Tue Aug 18 13:10:42.979772 2026] [security2:error] [pid 180811:tid 180960] [client 46.102.21.132:49608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEAkm4-PkKNOC4yxZeVgAAABM"] [Tue Aug 18 13:10:43.003119 2026] [cgid:error] [pid 180811:tid 181046] [client 74.248.18.37:50894] AH01265: stderr from /home4/jeff1000/jx2.com.br/cgi-bin/: attempt to invoke directory as script [Tue Aug 18 13:10:43.023669 2026] [security2:error] [pid 180811:tid 181023] [client 20.116.17.175:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/xwpg.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeWQAAAFI"] [Tue Aug 18 13:10:43.027868 2026] [security2:error] [pid 180811:tid 180968] [client 74.248.133.44:37269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/delpaths.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeWgAAABs"] [Tue Aug 18 13:10:43.057805 2026] [security2:error] [pid 180811:tid 180955] [client 20.51.153.15:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gc.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeXAAAAA4"] [Tue Aug 18 13:10:43.111175 2026] [authz_core:error] [pid 180811:tid 180825] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:43.111480 2026] [authz_core:error] [pid 180811:tid 180825] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:43.138273 2026] [security2:error] [pid 180811:tid 180996] [client 40.85.222.29:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/zwlsv.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeYQAAADc"] [Tue Aug 18 13:10:43.143694 2026] [security2:error] [pid 180811:tid 181027] [client 20.127.136.245:1841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/cong.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeZAAAAFY"] [Tue Aug 18 13:10:43.191222 2026] [security2:error] [pid 180811:tid 180862] [remote 136.110.27.48:33158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/id_rsa"] [unique_id "aoSEA0m4-PkKNOC4yxZeawAAajI"] [Tue Aug 18 13:10:43.191843 2026] [security2:error] [pid 180811:tid 180860] [remote 136.110.27.48:33158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "prod.app.gueirosadvocacia.com.br"] [uri "/id_dsa"] [unique_id "aoSEA0m4-PkKNOC4yxZeagAAajA"] [Tue Aug 18 13:10:43.207311 2026] [security2:error] [pid 180811:tid 181043] [client 82.102.18.188:37212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marthaimenes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "aoSEA0m4-PkKNOC4yxZebgAAAGY"] [Tue Aug 18 13:10:43.213209 2026] [security2:error] [pid 180811:tid 180974] [client 74.248.18.37:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/x.php"] [unique_id "aoSEA0m4-PkKNOC4yxZebwAAACE"] [Tue Aug 18 13:10:43.230646 2026] [security2:error] [pid 180811:tid 181025] [client 40.74.65.169:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/imscjpg.php"] [unique_id "aoSEA0m4-PkKNOC4yxZecAAAAFQ"] [Tue Aug 18 13:10:43.243532 2026] [security2:error] [pid 180811:tid 181045] [client 40.74.65.169:52326] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/1.php"] [unique_id "aoSEA0m4-PkKNOC4yxZecQAAAGg"] [Tue Aug 18 13:10:43.243610 2026] [security2:error] [pid 180811:tid 181045] [client 40.74.65.169:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/1.php"] [unique_id "aoSEA0m4-PkKNOC4yxZecQAAAGg"] [Tue Aug 18 13:10:43.285174 2026] [security2:error] [pid 180811:tid 181034] [client 4.232.94.69:58278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/wp-good.php"] [unique_id "aoSEA0m4-PkKNOC4yxZecwAAAF0"] [Tue Aug 18 13:10:43.292424 2026] [security2:error] [pid 180811:tid 181006] [client 20.51.153.15:1927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/uq.php"] [unique_id "aoSEA0m4-PkKNOC4yxZedAAAAEE"] [Tue Aug 18 13:10:43.328039 2026] [security2:error] [pid 180811:tid 181021] [client 43.130.12.43:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.12.130.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.virtualti.net.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeZQAAAFA"] [Tue Aug 18 13:10:43.357697 2026] [security2:error] [pid 180811:tid 181058] [client 68.155.154.236:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "aoSEA0m4-PkKNOC4yxZedgAAAHU"] [Tue Aug 18 13:10:43.359683 2026] [security2:error] [pid 180811:tid 181020] [client 213.35.127.232:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSEA0m4-PkKNOC4yxZedwAAAE8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:43.364339 2026] [security2:error] [pid 180811:tid 181057] [client 158.23.17.4:8727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/se.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeeAAAAHQ"] [Tue Aug 18 13:10:43.424918 2026] [security2:error] [pid 180811:tid 181064] [client 40.85.222.29:13288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/jrpga.php"] [unique_id "aoSEA0m4-PkKNOC4yxZefAAAAHs"] [Tue Aug 18 13:10:43.426605 2026] [security2:error] [pid 180811:tid 181044] [client 20.91.215.254:12822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/.well-known/acme-challenge//locale.php"] [unique_id "aoSEA0m4-PkKNOC4yxZefQAAAGc"] [Tue Aug 18 13:10:43.518076 2026] [security2:error] [pid 180811:tid 181018] [client 20.91.215.254:12808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/ku.php"] [unique_id "aoSEA0m4-PkKNOC4yxZegQAAAE0"] [Tue Aug 18 13:10:43.529652 2026] [security2:error] [pid 180811:tid 181050] [client 20.51.153.15:1857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/32.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeggAAAG0"] [Tue Aug 18 13:10:43.594794 2026] [security2:error] [pid 180811:tid 181062] [client 74.248.18.37:39000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/cv.php"] [unique_id "aoSEA0m4-PkKNOC4yxZehwAAAHk"] [Tue Aug 18 13:10:43.625422 2026] [security2:error] [pid 180811:tid 181016] [client 4.232.151.198:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeiQAAAEs"] [Tue Aug 18 13:10:43.626240 2026] [security2:error] [pid 180811:tid 180951] [client 114.5.214.109:50429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeigAAAAo"] [Tue Aug 18 13:10:43.626702 2026] [security2:error] [pid 180811:tid 180951] [client 114.5.214.109:50429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeigAAAAo"] [Tue Aug 18 13:10:43.642367 2026] [security2:error] [pid 180811:tid 181037] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEA0m4-PkKNOC4yxZehQAAYCg"] [Tue Aug 18 13:10:43.689178 2026] [security2:error] [pid 180811:tid 180981] [client 20.118.172.148:60416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "aoSEA0m4-PkKNOC4yxZejAAAACg"] [Tue Aug 18 13:10:43.702941 2026] [authz_core:error] [pid 180811:tid 180998] [client 192.178.4.134:63829] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:43.703202 2026] [authz_core:error] [pid 180811:tid 180998] [client 192.178.4.134:63829] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:43.704101 2026] [security2:error] [pid 180811:tid 180957] [client 40.85.222.29:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/museu/yhweq.php"] [unique_id "aoSEA0m4-PkKNOC4yxZejgAAABA"] [Tue Aug 18 13:10:43.800306 2026] [security2:error] [pid 180811:tid 180969] [client 20.104.49.167:40359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/puc.php"] [unique_id "aoSEA0m4-PkKNOC4yxZemQAAABw"] [Tue Aug 18 13:10:43.895074 2026] [security2:error] [pid 180811:tid 180950] [client 158.23.17.4:63666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/vp.php"] [unique_id "aoSEA0m4-PkKNOC4yxZenwAAAAk"] [Tue Aug 18 13:10:43.895576 2026] [security2:error] [pid 180811:tid 180965] [client 20.51.153.15:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/73.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeoAAAABg"] [Tue Aug 18 13:10:43.909335 2026] [security2:error] [pid 180811:tid 181017] [client 20.116.17.175:44692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/dex.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeoQAAAEw"] [Tue Aug 18 13:10:43.916937 2026] [security2:error] [pid 180811:tid 180967] [client 4.232.94.69:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/goods.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeowAAABo"] [Tue Aug 18 13:10:43.925299 2026] [security2:error] [pid 180811:tid 181023] [client 20.127.136.245:11574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSEA0m4-PkKNOC4yxZepQAAAFI"] [Tue Aug 18 13:10:43.925738 2026] [security2:error] [pid 180811:tid 180972] [client 40.74.65.169:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/qlex1.php"] [unique_id "aoSEA0m4-PkKNOC4yxZepgAAAB8"] [Tue Aug 18 13:10:43.928145 2026] [security2:error] [pid 180811:tid 181022] [client 168.62.48.100:5571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/wsrer.php"] [unique_id "aoSEA0m4-PkKNOC4yxZepwAAAFE"] [Tue Aug 18 13:10:43.948642 2026] [security2:error] [pid 180811:tid 181032] [client 20.118.133.132:31290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/ajax.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeqAAAAFs"] [Tue Aug 18 13:10:43.951758 2026] [security2:error] [pid 180811:tid 180952] [client 40.74.65.169:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/about.php"] [unique_id "aoSEA0m4-PkKNOC4yxZeqQAAAAs"] [Tue Aug 18 13:10:43.978192 2026] [security2:error] [pid 180811:tid 181036] [client 158.23.17.4:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/evil.php"] [unique_id "aoSEA0m4-PkKNOC4yxZerAAAAF8"] [Tue Aug 18 13:10:43.987406 2026] [security2:error] [pid 180811:tid 181003] [client 40.85.222.29:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/nwwha.php"] [unique_id "aoSEA0m4-PkKNOC4yxZerQAAAD4"] [Tue Aug 18 13:10:44.018366 2026] [authz_core:error] [pid 180811:tid 180877] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:44.018673 2026] [authz_core:error] [pid 180811:tid 180877] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:44.092867 2026] [security2:error] [pid 180811:tid 181005] [client 20.91.215.254:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/import.php"] [unique_id "aoSEBEm4-PkKNOC4yxZeuAAAAEA"] [Tue Aug 18 13:10:44.123143 2026] [security2:error] [pid 180811:tid 180975] [client 74.248.133.44:12671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/NewFile.php"] [unique_id "aoSEBEm4-PkKNOC4yxZevAAAACI"] [Tue Aug 18 13:10:44.128110 2026] [security2:error] [pid 180811:tid 181034] [client 20.118.172.148:56973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-links-opml.php"] [unique_id "aoSEBEm4-PkKNOC4yxZevQAAAF0"] [Tue Aug 18 13:10:44.131159 2026] [security2:error] [pid 180811:tid 181052] [client 20.51.153.15:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ib.php"] [unique_id "aoSEBEm4-PkKNOC4yxZevgAAAG8"] [Tue Aug 18 13:10:44.267710 2026] [security2:error] [pid 180811:tid 181057] [client 40.85.222.29:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/opsqt.php"] [unique_id "aoSEBEm4-PkKNOC4yxZewwAAAHQ"] [Tue Aug 18 13:10:44.371927 2026] [security2:error] [pid 180811:tid 180987] [client 213.35.127.232:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSEBEm4-PkKNOC4yxZeyQAAAC4"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:44.433883 2026] [security2:error] [pid 180811:tid 180945] [client 20.100.169.31:17222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/ioxi-o.php"] [unique_id "aoSEBEm4-PkKNOC4yxZezQAAAAQ"] [Tue Aug 18 13:10:44.465470 2026] [security2:error] [pid 180811:tid 181050] [client 20.104.49.167:40364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/inso.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe0AAAAG0"] [Tue Aug 18 13:10:44.493582 2026] [security2:error] [pid 180811:tid 180944] [client 20.91.215.254:13026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/chosen.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe1AAAAAM"] [Tue Aug 18 13:10:44.544568 2026] [security2:error] [pid 180811:tid 180941] [client 40.85.222.29:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/jvcpa.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe2AAAAAA"] [Tue Aug 18 13:10:44.549743 2026] [security2:error] [pid 180811:tid 181010] [client 4.232.94.69:59065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe2QAAAEU"] [Tue Aug 18 13:10:44.551294 2026] [security2:error] [pid 180811:tid 180964] [client 20.116.17.175:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/xyn.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe2gAAABc"] [Tue Aug 18 13:10:44.555613 2026] [security2:error] [pid 180811:tid 181039] [client 20.127.136.245:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/db.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe3AAAAGI"] [Tue Aug 18 13:10:44.622883 2026] [security2:error] [pid 180811:tid 181037] [client 40.74.65.169:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/mariju.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe4QAAAGA"] [Tue Aug 18 13:10:44.649891 2026] [security2:error] [pid 180811:tid 180979] [client 40.74.65.169:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/admin.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe5AAAACY"] [Tue Aug 18 13:10:44.658426 2026] [security2:error] [pid 180811:tid 181049] [client 158.23.17.4:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ph.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe5wAAAGw"] [Tue Aug 18 13:10:44.717435 2026] [security2:error] [pid 180811:tid 180948] [client 20.250.13.23:17395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/php8.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe6wAAAAc"] [Tue Aug 18 13:10:44.737302 2026] [security2:error] [pid 180811:tid 180958] [client 20.91.215.254:12703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/cropper.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe7AAAABE"] [Tue Aug 18 13:10:44.762394 2026] [security2:error] [pid 180811:tid 180989] [client 68.155.154.236:25402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/first.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe7gAAADA"] [Tue Aug 18 13:10:44.832174 2026] [security2:error] [pid 180811:tid 180924] [remote 129.121.74.194:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.74.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ezycolor.com.br"] [uri "/wp-login.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe7wAABnA"] [Tue Aug 18 13:10:44.839880 2026] [security2:error] [pid 180811:tid 180969] [client 40.85.222.29:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe8QAAABw"] [Tue Aug 18 13:10:44.843629 2026] [security2:error] [pid 180811:tid 180980] [client 20.118.172.148:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/.alf.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe8gAAACc"] [Tue Aug 18 13:10:44.860760 2026] [security2:error] [pid 180811:tid 181013] [client 51.38.115.13:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.115.38.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe6QAAAEg"] [Tue Aug 18 13:10:44.983791 2026] [security2:error] [pid 180811:tid 181020] [client 197.184.64.235:42708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.64.184.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe9QAAAE8"] [Tue Aug 18 13:10:44.983906 2026] [security2:error] [pid 180811:tid 181020] [client 197.184.64.235:42708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "marcosrsantos.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe9QAAAE8"] [Tue Aug 18 13:10:44.990611 2026] [security2:error] [pid 180811:tid 181022] [client 52.173.121.69:9721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/kopyw.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe9gAAAFE"] [Tue Aug 18 13:10:45.023192 2026] [security2:error] [pid 180811:tid 181028] [client 74.248.133.44:14961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/system.php"] [unique_id "aoSEBUm4-PkKNOC4yxZe-AAAAFc"] [Tue Aug 18 13:10:45.035619 2026] [security2:error] [pid 180811:tid 181007] [client 103.168.147.235:49236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZe-gAAAEI"] [Tue Aug 18 13:10:45.073569 2026] [security2:error] [pid 180811:tid 181038] [client 20.100.169.31:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/0x.php"] [unique_id "aoSEBUm4-PkKNOC4yxZe-wAAAGE"] [Tue Aug 18 13:10:45.123471 2026] [security2:error] [pid 180811:tid 181030] [client 40.85.222.29:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfAAAAAFk"] [Tue Aug 18 13:10:45.136131 2026] [security2:error] [pid 180811:tid 180977] [client 20.91.215.254:12861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/asd.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfAQAAACQ"] [Tue Aug 18 13:10:45.173840 2026] [security2:error] [pid 180811:tid 181046] [client 4.232.94.69:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/cv.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfAwAAAGk"] [Tue Aug 18 13:10:45.204632 2026] [security2:error] [pid 180811:tid 180986] [client 20.104.49.167:24245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/aa.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfBAAAAC0"] [Tue Aug 18 13:10:45.228696 2026] [authz_core:error] [pid 180811:tid 180930] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:45.229170 2026] [authz_core:error] [pid 180811:tid 180930] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:45.301952 2026] [security2:error] [pid 180811:tid 180998] [client 158.23.17.4:38865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/s.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfCQAAADk"] [Tue Aug 18 13:10:45.308238 2026] [security2:error] [pid 180811:tid 181059] [client 40.74.65.169:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/cofbgxlk.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfDQAAAHY"] [Tue Aug 18 13:10:45.357326 2026] [security2:error] [pid 180811:tid 181053] [client 40.74.65.169:25461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/edit.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfDwAAAHA"] [Tue Aug 18 13:10:45.375311 2026] [security2:error] [pid 180811:tid 180987] [client 20.118.133.132:31242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/yj09.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfEAAAAC4"] [Tue Aug 18 13:10:45.378587 2026] [security2:error] [pid 180811:tid 181063] [client 138.36.100.162:42769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.100.36.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfEQAAAHo"] [Tue Aug 18 13:10:45.385778 2026] [security2:error] [pid 180811:tid 181036] [client 213.35.127.232:60585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfEgAAAF8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:45.394903 2026] [security2:error] [pid 180811:tid 181018] [client 40.85.222.29:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfFAAAAE0"] [Tue Aug 18 13:10:45.408646 2026] [security2:error] [pid 180811:tid 180946] [client 4.232.151.198:42593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/wso.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfFQAAAAU"] [Tue Aug 18 13:10:45.437832 2026] [security2:error] [pid 180811:tid 180994] [client 20.127.136.245:4830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/dropdown.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfFwAAADU"] [Tue Aug 18 13:10:45.458267 2026] [security2:error] [pid 180811:tid 181034] [client 20.91.215.254:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/images/xmrlpc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfGAAAAF0"] [Tue Aug 18 13:10:45.475350 2026] [security2:error] [pid 180811:tid 180991] [client 158.23.17.4:25384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/pw.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfGgAAADI"] [Tue Aug 18 13:10:45.526162 2026] [authz_core:error] [pid 180811:tid 180934] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:45.526434 2026] [authz_core:error] [pid 180811:tid 180934] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:45.544000 2026] [security2:error] [pid 180811:tid 181019] [client 20.51.153.15:13376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xm.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfHwAAAE4"] [Tue Aug 18 13:10:45.546135 2026] [security2:error] [pid 180811:tid 181051] [client 74.248.18.37:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfIAAAAG4"] [Tue Aug 18 13:10:45.622482 2026] [security2:error] [pid 180811:tid 181058] [client 20.48.236.86:10774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfGQAAAHU"] [Tue Aug 18 13:10:45.689280 2026] [security2:error] [pid 180811:tid 180954] [client 158.23.17.4:33495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/uo.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfJgAAAA0"] [Tue Aug 18 13:10:45.699661 2026] [security2:error] [pid 180811:tid 180985] [client 40.85.222.29:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfKAAAACw"] [Tue Aug 18 13:10:45.709568 2026] [autoindex:error] [pid 180811:tid 180988] [client 66.132.186.199:4744] AH01276: Cannot serve directory /home3/cp39imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:45.719285 2026] [security2:error] [pid 180811:tid 180948] [client 40.85.222.29:13293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfKgAAAAc"] [Tue Aug 18 13:10:45.735175 2026] [security2:error] [pid 180811:tid 180958] [client 68.155.154.236:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/js/crop/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfKwAAABE"] [Tue Aug 18 13:10:45.742008 2026] [security2:error] [pid 180811:tid 181040] [client 20.100.169.31:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/222.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfLAAAAGM"] [Tue Aug 18 13:10:45.792272 2026] [security2:error] [pid 180811:tid 181063] [client 138.36.100.162:42769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "natupedras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfEQAAAHo"] [Tue Aug 18 13:10:45.793141 2026] [security2:error] [pid 180811:tid 180963] [client 20.51.153.15:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/zy.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfLgAAABY"] [Tue Aug 18 13:10:45.802134 2026] [security2:error] [pid 180811:tid 180999] [client 20.104.49.167:28862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/img.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfMAAAADo"] [Tue Aug 18 13:10:45.818171 2026] [security2:error] [pid 180811:tid 180983] [client 103.168.147.235:49253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfMQAAACo"] [Tue Aug 18 13:10:45.826946 2026] [authz_core:error] [pid 180811:tid 180835] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:45.827214 2026] [authz_core:error] [pid 180811:tid 180835] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:45.831797 2026] [security2:error] [pid 180811:tid 180971] [client 4.232.94.69:58283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/core.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfMwAAAB4"] [Tue Aug 18 13:10:45.843435 2026] [security2:error] [pid 180811:tid 180964] [client 20.91.215.254:12824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/akc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfQAAAABc"] [Tue Aug 18 13:10:45.847684 2026] [security2:error] [pid 180811:tid 180980] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com.br"] [uri "/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfLwAAACc"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:10:45.897819 2026] [security2:error] [pid 180811:tid 180842] [remote 89.185.225.24:39244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.225.185.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paciolli.com.br"] [uri "/wp-login.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfRAAAKB4"] [Tue Aug 18 13:10:45.915509 2026] [authz_core:error] [pid 180811:tid 180846] [remote 57.141.22.53:46242] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:45.915955 2026] [authz_core:error] [pid 180811:tid 180846] [remote 57.141.22.53:46242] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:45.980815 2026] [security2:error] [pid 180811:tid 181064] [client 196.12.128.158:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.128.12.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfSAAAAHs"] [Tue Aug 18 13:10:45.980930 2026] [security2:error] [pid 180811:tid 181064] [client 196.12.128.158:62683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "osuperpoder.com"] [uri "/xmlrpc.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfSAAAAHs"] [Tue Aug 18 13:10:45.986421 2026] [security2:error] [pid 180811:tid 181056] [client 74.248.133.44:25857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/IDhrIlrLb.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfSQAAAHM"] [Tue Aug 18 13:10:45.992844 2026] [security2:error] [pid 180811:tid 181038] [client 40.85.222.29:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/assets/admin/login/info.php"] [unique_id "aoSEBUm4-PkKNOC4yxZfSgAAAGE"] [Tue Aug 18 13:10:46.008621 2026] [security2:error] [pid 180811:tid 181041] [client 40.74.65.169:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/contacto.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfSwAAAGQ"] [Tue Aug 18 13:10:46.033365 2026] [security2:error] [pid 180811:tid 180993] [client 20.171.51.14:23526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/k.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfTwAAADQ"] [Tue Aug 18 13:10:46.034185 2026] [security2:error] [pid 180811:tid 181030] [client 40.74.65.169:25375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-content/admin.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfUAAAAFk"] [Tue Aug 18 13:10:46.109051 2026] [security2:error] [pid 180811:tid 181006] [client 40.85.222.29:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfUgAAAEE"] [Tue Aug 18 13:10:46.129988 2026] [security2:error] [pid 180811:tid 181000] [client 20.51.153.15:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/q.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfVgAAADs"] [Tue Aug 18 13:10:46.156404 2026] [security2:error] [pid 180811:tid 180951] [client 5.161.177.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tecpolorefrigeracaosp.com.br"] [uri "/index.php"] [unique_id "aoSEBEm4-PkKNOC4yxZe6gAACm4"], referer: https://tecpolorefrigeracaosp.com.br/ [Tue Aug 18 13:10:46.175948 2026] [security2:error] [pid 180811:tid 181012] [client 57.129.81.225:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfTQAAAEc"] [Tue Aug 18 13:10:46.185680 2026] [security2:error] [pid 180811:tid 180990] [client 20.127.136.245:11581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/file.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfWQAAADE"] [Tue Aug 18 13:10:46.239450 2026] [security2:error] [pid 180811:tid 181004] [client 74.248.18.37:9352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/index/function.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfYAAAAD8"] [Tue Aug 18 13:10:46.260165 2026] [security2:error] [pid 180811:tid 181067] [client 157.90.155.240:49780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfXwAAAH4"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:10:46.279254 2026] [security2:error] [pid 180811:tid 181034] [client 158.23.17.4:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/fn.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfYgAAAF0"] [Tue Aug 18 13:10:46.283398 2026] [security2:error] [pid 180811:tid 180944] [client 40.85.222.29:12625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfYwAAAAM"] [Tue Aug 18 13:10:46.293664 2026] [security2:error] [pid 180811:tid 180991] [client 158.23.17.4:9379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/kx.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfZAAAADI"] [Tue Aug 18 13:10:46.326077 2026] [security2:error] [pid 180811:tid 181035] [client 20.91.215.254:12715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-content/plugins/css-ready/file.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfaAAAAF4"] [Tue Aug 18 13:10:46.338426 2026] [security2:error] [pid 180811:tid 180962] [client 20.116.17.175:52592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-admin/js/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfaQAAABU"] [Tue Aug 18 13:10:46.364977 2026] [security2:error] [pid 180811:tid 180984] [client 20.100.169.31:17233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/aa.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfbAAAACs"] [Tue Aug 18 13:10:46.400077 2026] [security2:error] [pid 180811:tid 181029] [client 213.35.127.232:60811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfbQAAAFg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:46.408263 2026] [security2:error] [pid 180811:tid 181001] [client 40.85.222.29:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/weozh.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfbwAAADw"] [Tue Aug 18 13:10:46.410206 2026] [security2:error] [pid 180811:tid 181058] [client 20.51.153.15:1870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xf.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfcAAAAHU"] [Tue Aug 18 13:10:46.434842 2026] [authz_core:error] [pid 180811:tid 180825] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:46.435105 2026] [authz_core:error] [pid 180811:tid 180825] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:46.451060 2026] [security2:error] [pid 180811:tid 181002] [client 20.48.236.86:10778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfcgAAAD0"] [Tue Aug 18 13:10:46.459437 2026] [security2:error] [pid 180811:tid 181036] [client 4.232.94.69:59148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/ahax.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfcwAAAF8"] [Tue Aug 18 13:10:46.483826 2026] [security2:error] [pid 180811:tid 181024] [client 20.91.215.254:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/maintenance.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfdAAAAFM"] [Tue Aug 18 13:10:46.515401 2026] [security2:error] [pid 180811:tid 181040] [client 20.118.172.148:57509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/.trash7206/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfdQAAAGM"] [Tue Aug 18 13:10:46.536142 2026] [security2:error] [pid 180811:tid 180989] [client 20.104.49.167:19256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/222.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfdgAAADA"] [Tue Aug 18 13:10:46.572226 2026] [security2:error] [pid 180811:tid 180971] [client 40.85.222.29:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfdwAAAB4"] [Tue Aug 18 13:10:46.583206 2026] [security2:error] [pid 180811:tid 180964] [client 103.168.147.235:49278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfeAAAABc"] [Tue Aug 18 13:10:46.594436 2026] [security2:error] [pid 180811:tid 181066] [client 88.99.80.227:12092] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.parquefazendadasflores.com.br"] [uri "/index.php"] [unique_id "aoSEBUm4-PkKNOC4yxZe_QAAAH0"], referer: https://www.parquefazendadasflores.com.br [Tue Aug 18 13:10:46.656304 2026] [security2:error] [pid 180811:tid 181052] [client 74.248.18.37:30467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/ws83.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfegAAAG8"] [Tue Aug 18 13:10:46.667957 2026] [security2:error] [pid 180811:tid 180885] [remote 162.214.96.231:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.96.214.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocionais.com.br"] [uri "/wp-login.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfjQAAPkk"] [Tue Aug 18 13:10:46.685307 2026] [security2:error] [pid 180811:tid 180955] [client 20.51.153.15:1948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/gb.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfjgAAAA4"] [Tue Aug 18 13:10:46.691486 2026] [security2:error] [pid 180811:tid 180960] [client 40.74.65.169:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/image2.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfkAAAABM"] [Tue Aug 18 13:10:46.699735 2026] [security2:error] [pid 180811:tid 181032] [client 40.85.222.29:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/rymmm.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfkQAAAFs"] [Tue Aug 18 13:10:46.731570 2026] [security2:error] [pid 180811:tid 181064] [client 40.74.65.169:52350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/inputs.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfkwAAAHs"] [Tue Aug 18 13:10:46.738582 2026] [authz_core:error] [pid 180811:tid 180890] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:46.739049 2026] [authz_core:error] [pid 180811:tid 180890] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:46.746646 2026] [security2:error] [pid 180811:tid 180957] [client 68.155.154.236:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/theme-compat/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZflAAAABA"] [Tue Aug 18 13:10:46.818641 2026] [security2:error] [pid 180811:tid 181060] [client 57.129.81.152:38750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZflQAAAHc"] [Tue Aug 18 13:10:46.848623 2026] [security2:error] [pid 180811:tid 180976] [client 40.85.222.29:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfmQAAACM"] [Tue Aug 18 13:10:46.876776 2026] [security2:error] [pid 180811:tid 180948] [client 74.248.133.44:21147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/cJLGqzB.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfnAAAAAc"] [Tue Aug 18 13:10:46.898404 2026] [security2:error] [pid 180811:tid 180974] [client 20.127.136.245:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/goods.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfnQAAACE"] [Tue Aug 18 13:10:46.924421 2026] [security2:error] [pid 180811:tid 180968] [client 20.48.236.86:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/admin.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfoAAAABs"] [Tue Aug 18 13:10:46.934256 2026] [security2:error] [pid 180811:tid 181004] [client 158.23.17.4:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/va.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfogAAAD8"] [Tue Aug 18 13:10:46.953295 2026] [security2:error] [pid 180811:tid 181027] [client 52.173.121.69:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zznmg.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfowAAAFY"] [Tue Aug 18 13:10:46.963418 2026] [security2:error] [pid 180811:tid 181034] [client 20.51.153.15:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/jp.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfpQAAAF0"] [Tue Aug 18 13:10:47.000536 2026] [security2:error] [pid 180811:tid 180987] [client 40.85.222.29:12609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/lddxs.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfpwAAAC4"] [Tue Aug 18 13:10:47.022939 2026] [security2:error] [pid 180811:tid 181017] [client 157.90.155.240:7264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.antoniopericiacontabil.com"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfmAAAAEw"], referer: https://www.antoniopericiacontabil.com.br/ [Tue Aug 18 13:10:47.042339 2026] [security2:error] [pid 180811:tid 181041] [client 20.91.215.254:13054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/goat.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfqgAAAGQ"] [Tue Aug 18 13:10:47.097196 2026] [core:notice] [pid 180811:tid 180894] AH00113: /home3/uniaonutri/public_html/.htaccess:34 cannot use a full URL in a 401 ErrorDocument directive --- ignoring! [Tue Aug 18 13:10:47.117230 2026] [security2:error] [pid 180811:tid 180951] [client 20.100.169.31:17252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/abcd.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfrQAAAAo"] [Tue Aug 18 13:10:47.126136 2026] [security2:error] [pid 180811:tid 181042] [client 20.116.17.175:52903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-good.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfrgAAAGU"] [Tue Aug 18 13:10:47.131757 2026] [security2:error] [pid 180811:tid 180979] [client 40.85.222.29:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/assets/filemanager/dialog.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfrwAAACY"] [Tue Aug 18 13:10:47.136923 2026] [security2:error] [pid 180811:tid 181044] [client 20.91.215.254:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/options-writing.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfsAAAAGc"] [Tue Aug 18 13:10:47.218994 2026] [security2:error] [pid 180811:tid 181033] [client 20.118.133.132:45207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/scxy.php"] [unique_id "aoSEB0m4-PkKNOC4yxZftgAAAFw"] [Tue Aug 18 13:10:47.249343 2026] [security2:error] [pid 180811:tid 180963] [client 172.182.200.96:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfuAAAABY"] [Tue Aug 18 13:10:47.252591 2026] [security2:error] [pid 180811:tid 180999] [client 20.171.51.14:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/iu.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfuQAAADo"] [Tue Aug 18 13:10:47.278419 2026] [security2:error] [pid 180811:tid 180966] [client 20.104.49.167:4939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/key.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfuwAAABk"] [Tue Aug 18 13:10:47.291865 2026] [security2:error] [pid 180811:tid 180965] [client 20.51.153.15:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/eq.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfvQAAABg"] [Tue Aug 18 13:10:47.295400 2026] [security2:error] [pid 180811:tid 181020] [client 40.85.222.29:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/zjggu.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfvwAAAE8"] [Tue Aug 18 13:10:47.299441 2026] [security2:error] [pid 180811:tid 181003] [client 4.232.94.69:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/contact_tpl.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfwAAAAD4"] [Tue Aug 18 13:10:47.309005 2026] [security2:error] [pid 180811:tid 180955] [client 158.23.17.4:25396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kf.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfxgAAAA4"] [Tue Aug 18 13:10:47.385359 2026] [security2:error] [pid 180811:tid 180995] [client 40.74.65.169:49120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/fb.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfyQAAADY"] [Tue Aug 18 13:10:47.401060 2026] [security2:error] [pid 180811:tid 181046] [client 103.168.147.235:49303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfzAAAAGk"] [Tue Aug 18 13:10:47.406067 2026] [security2:error] [pid 180811:tid 181060] [client 40.74.65.169:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/av.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfzQAAAHc"] [Tue Aug 18 13:10:47.412678 2026] [security2:error] [pid 180811:tid 181006] [client 40.85.222.29:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/assets/font/bootstrap-icon/shell.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfzgAAAEE"] [Tue Aug 18 13:10:47.419774 2026] [security2:error] [pid 180811:tid 181015] [client 213.35.127.232:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfzwAAAEo"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:47.436091 2026] [security2:error] [pid 180811:tid 181051] [client 141.95.54.132:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.54.95.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfugAAAG4"] [Tue Aug 18 13:10:47.500157 2026] [security2:error] [pid 180811:tid 181030] [client 102.213.179.104:50647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.179.213.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf1gAAAFk"] [Tue Aug 18 13:10:47.500285 2026] [security2:error] [pid 180811:tid 181030] [client 102.213.179.104:50647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cidadaniasemfronteiras.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf1gAAAFk"] [Tue Aug 18 13:10:47.503285 2026] [security2:error] [pid 180811:tid 180993] [client 49.37.150.8:64650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.150.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf1wAAADQ"] [Tue Aug 18 13:10:47.503377 2026] [security2:error] [pid 180811:tid 180993] [client 49.37.150.8:64650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kuringacomunicacao.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf1wAAADQ"] [Tue Aug 18 13:10:47.523838 2026] [security2:error] [pid 180811:tid 180880] [remote 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf2AAAAkQ"] [Tue Aug 18 13:10:47.523975 2026] [security2:error] [pid 180811:tid 180943] [client 2804:7b50:20:4021:bc0f:c9af:3c65:a551:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "thatianysantana.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf2AAAAkQ"] [Tue Aug 18 13:10:47.544476 2026] [security2:error] [pid 180811:tid 181027] [client 20.51.153.15:1964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ep.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf2QAAAFY"] [Tue Aug 18 13:10:47.555858 2026] [security2:error] [pid 180811:tid 181034] [client 20.118.172.148:39176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/.well-known/logs233/index.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf2gAAAF0"] [Tue Aug 18 13:10:47.562794 2026] [security2:error] [pid 180811:tid 181047] [client 68.155.154.236:3970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/shortcode/index.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf2wAAAGo"] [Tue Aug 18 13:10:47.575970 2026] [security2:error] [pid 180811:tid 181065] [client 40.85.222.29:13237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/dlvqo.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf3QAAAHw"] [Tue Aug 18 13:10:47.653137 2026] [security2:error] [pid 180811:tid 181028] [client 49.145.211.146:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.211.145.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf4AAAAFc"] [Tue Aug 18 13:10:47.653266 2026] [security2:error] [pid 180811:tid 181028] [client 49.145.211.146:11999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf4AAAAFc"] [Tue Aug 18 13:10:47.669788 2026] [security2:error] [pid 180811:tid 181039] [client 172.182.200.96:15724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf4gAAAGI"] [Tue Aug 18 13:10:47.703210 2026] [security2:error] [pid 180811:tid 181055] [client 40.85.222.29:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/.well-known/acme-challenge/local-access.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf5AAAAHI"] [Tue Aug 18 13:10:47.709663 2026] [security2:error] [pid 180811:tid 181009] [client 20.48.236.86:10655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/biufile.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf5gAAAEQ"] [Tue Aug 18 13:10:47.737674 2026] [security2:error] [pid 180811:tid 181038] [client 158.23.17.4:10987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/fo.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf5wAAAGE"] [Tue Aug 18 13:10:47.743745 2026] [security2:error] [pid 180811:tid 181067] [client 20.100.169.31:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/admin.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf6AAAAH4"] [Tue Aug 18 13:10:47.752441 2026] [security2:error] [pid 180811:tid 181014] [client 20.91.215.254:12838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/Session.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf6wAAAEk"] [Tue Aug 18 13:10:47.773577 2026] [security2:error] [pid 180811:tid 180967] [client 20.91.215.254:14328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/aspera/faspex/wp-admin/gecko-litespeed.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf7AAAABo"] [Tue Aug 18 13:10:47.778114 2026] [security2:error] [pid 180811:tid 180990] [client 74.248.133.44:12620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.133.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "automotivapoa.com.br"] [uri "/akc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf7QAAADE"] [Tue Aug 18 13:10:47.824591 2026] [security2:error] [pid 180811:tid 181036] [client 20.51.153.15:1882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/rf.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf8QAAAF8"] [Tue Aug 18 13:10:47.839802 2026] [security2:error] [pid 180811:tid 181002] [client 103.120.71.157:61508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.71.120.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf8wAAAD0"] [Tue Aug 18 13:10:47.839933 2026] [security2:error] [pid 180811:tid 181002] [client 103.120.71.157:61508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf8wAAAD0"] [Tue Aug 18 13:10:47.868301 2026] [security2:error] [pid 180811:tid 180947] [client 40.85.222.29:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/pkmoj.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf9gAAAAY"] [Tue Aug 18 13:10:47.912657 2026] [security2:error] [pid 180811:tid 180963] [client 158.23.17.4:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/su.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf9wAAABY"] [Tue Aug 18 13:10:47.924676 2026] [security2:error] [pid 180811:tid 181042] [client 4.232.94.69:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/alfa-rex.php"] [unique_id "aoSEB0m4-PkKNOC4yxZf-AAAAGU"] [Tue Aug 18 13:10:47.942840 2026] [authz_core:error] [pid 180811:tid 180918] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:47.943313 2026] [authz_core:error] [pid 180811:tid 180918] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:47.981670 2026] [security2:error] [pid 180811:tid 181008] [client 78.46.215.1:52846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSEBkm4-PkKNOC4yxZfYQAAAEM"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:10:48.007210 2026] [security2:error] [pid 180811:tid 180960] [client 40.85.222.29:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/php-compat/Olu2RK.php"] [unique_id "aoSECEm4-PkKNOC4yxZf_QAAABM"] [Tue Aug 18 13:10:48.072245 2026] [security2:error] [pid 180811:tid 181063] [client 40.74.65.169:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/gi.php"] [unique_id "aoSECEm4-PkKNOC4yxZf_wAAAHo"] [Tue Aug 18 13:10:48.072696 2026] [security2:error] [pid 180811:tid 181032] [client 172.182.200.96:15738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/weozh.php"] [unique_id "aoSECEm4-PkKNOC4yxZgAAAAAFs"] [Tue Aug 18 13:10:48.114337 2026] [security2:error] [pid 180811:tid 180961] [client 40.74.65.169:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/classwithtostring.php"] [unique_id "aoSECEm4-PkKNOC4yxZgAQAAABQ"] [Tue Aug 18 13:10:48.129609 2026] [security2:error] [pid 180811:tid 181060] [client 168.62.48.100:5584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/ucpfr.php"] [unique_id "aoSECEm4-PkKNOC4yxZgAwAAAHc"] [Tue Aug 18 13:10:48.136593 2026] [security2:error] [pid 180811:tid 181022] [client 20.127.136.245:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/hplfuns.php"] [unique_id "aoSECEm4-PkKNOC4yxZgBAAAAFE"] [Tue Aug 18 13:10:48.149355 2026] [security2:error] [pid 180811:tid 180982] [client 40.85.222.29:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/kopyw.php"] [unique_id "aoSECEm4-PkKNOC4yxZgBQAAACk"] [Tue Aug 18 13:10:48.175868 2026] [security2:error] [pid 180811:tid 180953] [client 103.168.147.235:49325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZgCAAAAAw"] [Tue Aug 18 13:10:48.224801 2026] [security2:error] [pid 180811:tid 181064] [client 20.51.153.15:1983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xynz1.php"] [unique_id "aoSECEm4-PkKNOC4yxZgDAAAAHs"] [Tue Aug 18 13:10:48.236478 2026] [security2:error] [pid 180811:tid 181023] [client 74.248.18.37:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/aaa.php"] [unique_id "aoSECEm4-PkKNOC4yxZgDgAAAFI"] [Tue Aug 18 13:10:48.237507 2026] [authz_core:error] [pid 180811:tid 180923] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:48.237785 2026] [authz_core:error] [pid 180811:tid 180923] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:48.241885 2026] [security2:error] [pid 180811:tid 181025] [client 20.48.236.86:11069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/coffexium.php"] [unique_id "aoSECEm4-PkKNOC4yxZgDwAAAFQ"] [Tue Aug 18 13:10:48.303756 2026] [security2:error] [pid 180811:tid 181066] [client 40.85.222.29:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/assets/wow.php"] [unique_id "aoSECEm4-PkKNOC4yxZgEgAAAH0"] [Tue Aug 18 13:10:48.377266 2026] [security2:error] [pid 180811:tid 181044] [client 158.23.17.4:29442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/loading.php"] [unique_id "aoSECEm4-PkKNOC4yxZgEwAAAGc"] [Tue Aug 18 13:10:48.417644 2026] [security2:error] [pid 180811:tid 180997] [client 20.91.215.254:12722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/maint.php"] [unique_id "aoSECEm4-PkKNOC4yxZgFwAAADg"] [Tue Aug 18 13:10:48.429975 2026] [security2:error] [pid 180811:tid 180985] [client 40.85.222.29:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/zznmg.php"] [unique_id "aoSECEm4-PkKNOC4yxZgGQAAACw"] [Tue Aug 18 13:10:48.434243 2026] [security2:error] [pid 180811:tid 180949] [client 213.35.127.232:61271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZgGgAAAAg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:48.476616 2026] [security2:error] [pid 180811:tid 180962] [client 168.119.96.239:17694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSEB0m4-PkKNOC4yxZfqAAAABU"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:10:48.487794 2026] [security2:error] [pid 180811:tid 180993] [client 20.51.153.15:1920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vo.php"] [unique_id "aoSECEm4-PkKNOC4yxZgIQAAADQ"] [Tue Aug 18 13:10:48.493029 2026] [security2:error] [pid 180811:tid 180970] [client 20.91.215.254:14335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/acme-challenge.php"] [unique_id "aoSECEm4-PkKNOC4yxZgJwAAAB0"] [Tue Aug 18 13:10:48.538036 2026] [authz_core:error] [pid 180811:tid 180864] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:48.538303 2026] [authz_core:error] [pid 180811:tid 180864] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:48.579519 2026] [security2:error] [pid 180811:tid 180996] [client 78.46.215.1:55200] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orientadoraespiritualbhsp.com.br"] [uri "/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZgbQAAADc"], referer: http://orientadoraespiritualbhsp.com.br/ [Tue Aug 18 13:10:48.595973 2026] [security2:error] [pid 180811:tid 180994] [client 172.182.200.96:15636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/rymmm.php"] [unique_id "aoSECEm4-PkKNOC4yxZgeQAAADU"] [Tue Aug 18 13:10:48.598202 2026] [security2:error] [pid 180811:tid 181059] [client 40.85.222.29:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/wp_y13h6oGI.php"] [unique_id "aoSECEm4-PkKNOC4yxZgegAAAHY"] [Tue Aug 18 13:10:48.630639 2026] [security2:error] [pid 180811:tid 180992] [client 20.100.169.31:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/adminfuns.php"] [unique_id "aoSECEm4-PkKNOC4yxZgewAAADM"] [Tue Aug 18 13:10:48.657891 2026] [security2:error] [pid 180811:tid 180948] [client 86.120.159.145:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.159.120.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSECEm4-PkKNOC4yxZgfAAAAAc"] [Tue Aug 18 13:10:48.658015 2026] [security2:error] [pid 180811:tid 180948] [client 86.120.159.145:64229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "srasaneamento.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSECEm4-PkKNOC4yxZgfAAAAAc"] [Tue Aug 18 13:10:48.717831 2026] [autoindex:error] [pid 180811:tid 181018] [client 158.158.74.177:11525] AH01276: Cannot serve directory /home4/patiojardinsma/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:48.736937 2026] [security2:error] [pid 180811:tid 181060] [client 20.51.153.15:1973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/wu.php"] [unique_id "aoSECEm4-PkKNOC4yxZggAAAAHc"] [Tue Aug 18 13:10:48.745924 2026] [security2:error] [pid 180811:tid 180996] [client 40.74.65.169:49026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/video.php"] [unique_id "aoSECEm4-PkKNOC4yxZggQAAADc"] [Tue Aug 18 13:10:48.752103 2026] [security2:error] [pid 180811:tid 180973] [client 20.118.172.148:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/themes/haha.php"] [unique_id "aoSECEm4-PkKNOC4yxZgggAAACA"] [Tue Aug 18 13:10:48.770279 2026] [security2:error] [pid 180811:tid 181006] [client 40.85.222.29:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/bhfnd.php"] [unique_id "aoSECEm4-PkKNOC4yxZghAAAAEE"] [Tue Aug 18 13:10:48.771381 2026] [security2:error] [pid 180811:tid 181000] [client 4.232.94.69:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/wp-login.php"] [unique_id "aoSECEm4-PkKNOC4yxZgbAAAADs"] [Tue Aug 18 13:10:48.809859 2026] [security2:error] [pid 180811:tid 180993] [client 40.74.65.169:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-content/themes/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZgiAAAADQ"] [Tue Aug 18 13:10:48.830705 2026] [security2:error] [pid 180811:tid 181059] [client 20.171.51.14:5388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/pk.php"] [unique_id "aoSECEm4-PkKNOC4yxZgiQAAAHY"] [Tue Aug 18 13:10:48.840671 2026] [authz_core:error] [pid 180811:tid 180857] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:48.840952 2026] [authz_core:error] [pid 180811:tid 180857] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:48.866305 2026] [security2:error] [pid 180811:tid 180986] [client 4.232.151.198:47471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/zup.php73"] [unique_id "aoSECEm4-PkKNOC4yxZgjQAAAC0"] [Tue Aug 18 13:10:48.876753 2026] [security2:error] [pid 180811:tid 180977] [client 40.85.222.29:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/css/Lgt1ghftfgbaas.php"] [unique_id "aoSECEm4-PkKNOC4yxZgjgAAACQ"] [Tue Aug 18 13:10:48.897727 2026] [security2:error] [pid 180811:tid 181048] [client 20.91.215.254:25643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/g.php"] [unique_id "aoSECEm4-PkKNOC4yxZgkAAAAGs"] [Tue Aug 18 13:10:48.908094 2026] [security2:error] [pid 180811:tid 180970] [client 20.118.133.132:31256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/ws13.php"] [unique_id "aoSECEm4-PkKNOC4yxZgkQAAAB0"] [Tue Aug 18 13:10:48.939925 2026] [security2:error] [pid 180811:tid 181066] [client 145.239.81.31:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.81.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZghQAAAH0"] [Tue Aug 18 13:10:48.966133 2026] [security2:error] [pid 180811:tid 181062] [client 158.23.17.4:29447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ke.php"] [unique_id "aoSECEm4-PkKNOC4yxZgkwAAAHk"] [Tue Aug 18 13:10:48.986989 2026] [security2:error] [pid 180811:tid 180917] [remote 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSECEm4-PkKNOC4yxZglAAARGk"] [Tue Aug 18 13:10:48.987249 2026] [security2:error] [pid 180811:tid 181009] [client 2405:201:e05c:f052:e833:7121:3afe:43c7:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "belmais.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSECEm4-PkKNOC4yxZglAAARGk"] [Tue Aug 18 13:10:49.015840 2026] [security2:error] [pid 180811:tid 181039] [client 20.51.153.15:1907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/de.php"] [unique_id "aoSECUm4-PkKNOC4yxZglQAAAGI"] [Tue Aug 18 13:10:49.060821 2026] [security2:error] [pid 180811:tid 181013] [client 20.91.215.254:12821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/phpMailer.php"] [unique_id "aoSECUm4-PkKNOC4yxZgmAAAAEg"] [Tue Aug 18 13:10:49.085215 2026] [security2:error] [pid 180811:tid 181047] [client 20.48.236.86:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/dex.php"] [unique_id "aoSECUm4-PkKNOC4yxZgmgAAAGo"] [Tue Aug 18 13:10:49.090679 2026] [security2:error] [pid 180811:tid 180987] [client 172.182.200.96:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/lddxs.php"] [unique_id "aoSECUm4-PkKNOC4yxZgmwAAAC4"] [Tue Aug 18 13:10:49.103599 2026] [security2:error] [pid 180811:tid 181017] [client 40.85.222.29:12622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/qfvqu.php"] [unique_id "aoSECUm4-PkKNOC4yxZgnAAAAEw"] [Tue Aug 18 13:10:49.140944 2026] [security2:error] [pid 180811:tid 180942] [client 20.91.215.254:13049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/abcd.php"] [unique_id "aoSECUm4-PkKNOC4yxZgoQAAAAE"] [Tue Aug 18 13:10:49.147830 2026] [authz_core:error] [pid 180811:tid 180911] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:49.148284 2026] [authz_core:error] [pid 180811:tid 180911] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:49.169623 2026] [security2:error] [pid 180811:tid 181016] [client 40.85.222.29:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/rest-api/menu.php"] [unique_id "aoSECUm4-PkKNOC4yxZgogAAAEs"] [Tue Aug 18 13:10:49.207761 2026] [security2:error] [pid 180811:tid 180994] [client 57.129.81.155:40204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.matronfer.com.br"] [uri "/index.php"] [unique_id "aoSECUm4-PkKNOC4yxZglwAAADU"] [Tue Aug 18 13:10:49.207978 2026] [security2:error] [pid 180811:tid 181026] [client 68.155.154.236:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/blog/byp.php"] [unique_id "aoSECUm4-PkKNOC4yxZgowAAAFU"] [Tue Aug 18 13:10:49.208563 2026] [security2:error] [pid 180811:tid 181025] [client 168.119.96.239:15282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ancavisi.com.br"] [uri "/index.php"] [unique_id "aoSECUm4-PkKNOC4yxZgmQAAAFQ"], referer: http://ancavisi.com.br/ [Tue Aug 18 13:10:49.259423 2026] [security2:error] [pid 180811:tid 181065] [client 20.100.169.31:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/akc.php"] [unique_id "aoSECUm4-PkKNOC4yxZgpQAAAHw"] [Tue Aug 18 13:10:49.297119 2026] [security2:error] [pid 180811:tid 181057] [client 20.51.153.15:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/album.php"] [unique_id "aoSECUm4-PkKNOC4yxZgpwAAAHQ"] [Tue Aug 18 13:10:49.308250 2026] [autoindex:error] [pid 180811:tid 180898] [remote 2602:80d:1008::25:0] AH01276: Cannot serve directory /home3/cp36imobibrasil/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:49.323792 2026] [security2:error] [pid 180811:tid 181010] [client 74.248.18.37:58892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/abcd.php"] [unique_id "aoSECUm4-PkKNOC4yxZgqwAAAEU"] [Tue Aug 18 13:10:49.325071 2026] [security2:error] [pid 180811:tid 181049] [client 20.127.136.245:2092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/htaccess.php"] [unique_id "aoSECUm4-PkKNOC4yxZgrAAAAGw"] [Tue Aug 18 13:10:49.397505 2026] [security2:error] [pid 180811:tid 181068] [client 4.232.94.69:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/Auth.php"] [unique_id "aoSECUm4-PkKNOC4yxZgsAAAAH8"] [Tue Aug 18 13:10:49.414122 2026] [security2:error] [pid 180811:tid 180943] [client 40.85.222.29:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/oivcl.php"] [unique_id "aoSECUm4-PkKNOC4yxZgsQAAAAI"] [Tue Aug 18 13:10:49.423751 2026] [security2:error] [pid 180811:tid 180961] [client 158.23.17.4:28632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/wp-key.php"] [unique_id "aoSECUm4-PkKNOC4yxZgsgAAABQ"] [Tue Aug 18 13:10:49.444906 2026] [security2:error] [pid 180811:tid 181005] [client 40.74.65.169:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/hel.php"] [unique_id "aoSECUm4-PkKNOC4yxZgtgAAAEA"] [Tue Aug 18 13:10:49.445549 2026] [authz_core:error] [pid 180811:tid 180877] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:49.445804 2026] [authz_core:error] [pid 180811:tid 180877] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:49.448924 2026] [security2:error] [pid 180811:tid 180956] [client 213.35.127.232:61499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSECUm4-PkKNOC4yxZgtwAAAA8"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:49.454635 2026] [security2:error] [pid 180811:tid 180952] [client 20.118.172.148:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/themes/theme/about.php"] [unique_id "aoSECUm4-PkKNOC4yxZguAAAAAs"] [Tue Aug 18 13:10:49.458708 2026] [security2:error] [pid 180811:tid 181060] [client 40.85.222.29:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/customize/5dCx2y.php"] [unique_id "aoSECUm4-PkKNOC4yxZguQAAAHc"] [Tue Aug 18 13:10:49.511039 2026] [security2:error] [pid 180811:tid 181027] [client 40.74.65.169:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-blog.php"] [unique_id "aoSECUm4-PkKNOC4yxZgvAAAAFY"] [Tue Aug 18 13:10:49.546696 2026] [security2:error] [pid 180811:tid 181020] [client 20.91.215.254:25624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/gecko.php"] [unique_id "aoSECUm4-PkKNOC4yxZgvwAAAE8"] [Tue Aug 18 13:10:49.558378 2026] [security2:error] [pid 180811:tid 180953] [client 172.182.200.96:15712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/zjggu.php"] [unique_id "aoSECUm4-PkKNOC4yxZgwAAAAAw"] [Tue Aug 18 13:10:49.582919 2026] [security2:error] [pid 180811:tid 181067] [client 20.51.153.15:2025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/kv.php"] [unique_id "aoSECUm4-PkKNOC4yxZgxQAAAH4"] [Tue Aug 18 13:10:49.672709 2026] [security2:error] [pid 180811:tid 180988] [client 52.173.121.69:65106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/bhfnd.php"] [unique_id "aoSECUm4-PkKNOC4yxZgyQAAAC8"] [Tue Aug 18 13:10:49.676115 2026] [security2:error] [pid 180811:tid 181053] [client 20.116.17.175:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wmore1.php"] [unique_id "aoSECUm4-PkKNOC4yxZgygAAAHA"] [Tue Aug 18 13:10:49.696816 2026] [security2:error] [pid 180811:tid 181066] [client 40.85.222.29:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/zugvi.php"] [unique_id "aoSECUm4-PkKNOC4yxZgywAAAH0"] [Tue Aug 18 13:10:49.737969 2026] [security2:error] [pid 180811:tid 180974] [client 40.85.222.29:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/bK9rpN.php"] [unique_id "aoSECUm4-PkKNOC4yxZgzgAAACE"] [Tue Aug 18 13:10:49.745038 2026] [authz_core:error] [pid 180811:tid 180912] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:49.745303 2026] [authz_core:error] [pid 180811:tid 180912] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:49.783485 2026] [security2:error] [pid 180811:tid 181013] [client 20.118.133.132:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupobelmais.com.br"] [uri "/aa.php"] [unique_id "aoSECUm4-PkKNOC4yxZg0gAAAEg"] [Tue Aug 18 13:10:49.793758 2026] [security2:error] [pid 180811:tid 180958] [client 149.22.83.209:54967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "www.brasiltocantins.com.br"] [uri "/wp-login.php"] [unique_id "aoSECEm4-PkKNOC4yxZgfgAAABE"] [Tue Aug 18 13:10:49.810513 2026] [security2:error] [pid 180811:tid 180980] [client 168.62.48.100:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/yxijx.php"] [unique_id "aoSECUm4-PkKNOC4yxZg0wAAACc"] [Tue Aug 18 13:10:49.811139 2026] [security2:error] [pid 180811:tid 180973] [client 20.91.215.254:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/css/colors/file.php"] [unique_id "aoSECUm4-PkKNOC4yxZg1AAAACA"] [Tue Aug 18 13:10:49.827159 2026] [security2:error] [pid 180811:tid 180976] [client 4.232.151.198:42592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.151.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucascamargosadv.com.br"] [uri "/k.php"] [unique_id "aoSECUm4-PkKNOC4yxZg1QAAACM"] [Tue Aug 18 13:10:49.836526 2026] [security2:error] [pid 180811:tid 181017] [client 20.104.49.167:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/chosen.php"] [unique_id "aoSECUm4-PkKNOC4yxZg1gAAAEw"] [Tue Aug 18 13:10:49.901267 2026] [security2:error] [pid 180811:tid 181028] [client 20.100.169.31:3999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/buy.php"] [unique_id "aoSECUm4-PkKNOC4yxZg2AAAAFc"] [Tue Aug 18 13:10:49.914465 2026] [security2:error] [pid 180811:tid 180971] [client 172.182.200.96:15683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/dlvqo.php"] [unique_id "aoSECUm4-PkKNOC4yxZg2QAAAB4"] [Tue Aug 18 13:10:49.937341 2026] [security2:error] [pid 180811:tid 180994] [client 20.51.153.15:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/z.php"] [unique_id "aoSECUm4-PkKNOC4yxZg2gAAADU"] [Tue Aug 18 13:10:49.950107 2026] [security2:error] [pid 180811:tid 180981] [client 20.91.215.254:12853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/kj.php"] [unique_id "aoSECUm4-PkKNOC4yxZg3AAAACg"] [Tue Aug 18 13:10:49.974066 2026] [security2:error] [pid 180811:tid 180963] [client 68.155.154.236:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/blocks/file/index.php"] [unique_id "aoSECUm4-PkKNOC4yxZg3gAAABY"] [Tue Aug 18 13:10:49.984062 2026] [security2:error] [pid 180811:tid 180964] [client 40.85.222.29:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wsrer.php"] [unique_id "aoSECUm4-PkKNOC4yxZg3wAAABc"] [Tue Aug 18 13:10:50.010482 2026] [security2:error] [pid 180811:tid 181065] [client 20.118.172.148:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/wp-content/plugins/plugin/index.php"] [unique_id "aoSECkm4-PkKNOC4yxZg4QAAAHw"] [Tue Aug 18 13:10:50.028834 2026] [security2:error] [pid 180811:tid 180987] [client 4.232.94.69:61238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/axx.php"] [unique_id "aoSECkm4-PkKNOC4yxZg4wAAAC4"] [Tue Aug 18 13:10:50.042100 2026] [security2:error] [pid 180811:tid 181001] [client 159.69.158.189:32414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSECEm4-PkKNOC4yxZgHQAAADw"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:10:50.045844 2026] [authz_core:error] [pid 180811:tid 180836] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:50.045913 2026] [security2:error] [pid 180811:tid 181032] [client 20.171.51.14:19896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/ge.php"] [unique_id "aoSECkm4-PkKNOC4yxZg6QAAAFs"] [Tue Aug 18 13:10:50.046118 2026] [authz_core:error] [pid 180811:tid 180836] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:50.056490 2026] [security2:error] [pid 180811:tid 180959] [client 103.168.147.235:49345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSECkm4-PkKNOC4yxZg6gAAABI"] [Tue Aug 18 13:10:50.113256 2026] [security2:error] [pid 180811:tid 181064] [client 40.85.222.29:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/IXR/options.php"] [unique_id "aoSECkm4-PkKNOC4yxZg7gAAAHs"] [Tue Aug 18 13:10:50.139680 2026] [security2:error] [pid 180811:tid 180952] [client 40.74.65.169:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/grok.php"] [unique_id "aoSECkm4-PkKNOC4yxZg8QAAAAs"] [Tue Aug 18 13:10:50.167570 2026] [security2:error] [pid 180811:tid 181027] [client 20.48.236.86:10783] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vigus.net"] [uri "/1.php"] [unique_id "aoSECkm4-PkKNOC4yxZg8wAAAFY"] [Tue Aug 18 13:10:50.167693 2026] [security2:error] [pid 180811:tid 181027] [client 20.48.236.86:10783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/1.php"] [unique_id "aoSECkm4-PkKNOC4yxZg8wAAAFY"] [Tue Aug 18 13:10:50.174649 2026] [security2:error] [pid 180811:tid 180969] [client 158.23.17.4:29488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/nh.php"] [unique_id "aoSECkm4-PkKNOC4yxZg9AAAABw"] [Tue Aug 18 13:10:50.196325 2026] [security2:error] [pid 180811:tid 181021] [client 20.127.136.245:2073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/images/wso.php"] [unique_id "aoSECkm4-PkKNOC4yxZg9gAAAFA"] [Tue Aug 18 13:10:50.211881 2026] [security2:error] [pid 180811:tid 181020] [client 40.74.65.169:25497] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/js/jquery/"] [unique_id "aoSECkm4-PkKNOC4yxZg9wAAAE8"] [Tue Aug 18 13:10:50.229924 2026] [security2:error] [pid 180811:tid 181067] [client 20.51.153.15:1904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/xg.php"] [unique_id "aoSECkm4-PkKNOC4yxZg-wAAAH4"] [Tue Aug 18 13:10:50.263039 2026] [security2:error] [pid 180811:tid 181050] [client 20.91.215.254:16570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/gettest.php"] [unique_id "aoSECkm4-PkKNOC4yxZg_gAAAG0"] [Tue Aug 18 13:10:50.269161 2026] [security2:error] [pid 180811:tid 180967] [client 172.202.39.151:12479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ortopedistapetornozelo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSECkm4-PkKNOC4yxZg_wAAABo"] [Tue Aug 18 13:10:50.282292 2026] [security2:error] [pid 180811:tid 180947] [client 40.85.222.29:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/ucpfr.php"] [unique_id "aoSECkm4-PkKNOC4yxZhAAAAAAY"] [Tue Aug 18 13:10:50.292413 2026] [security2:error] [pid 180811:tid 180939] [remote 47.128.26.99:56768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "caboclotaperoa.com.br"] [uri "/robots.txt"] [unique_id "aoSECkm4-PkKNOC4yxZhAQAAXX8"] [Tue Aug 18 13:10:50.334054 2026] [security2:error] [pid 180811:tid 181025] [client 74.248.18.37:39917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/wp-good.php"] [unique_id "aoSECkm4-PkKNOC4yxZhBAAAAFQ"] [Tue Aug 18 13:10:50.356069 2026] [authz_core:error] [pid 180811:tid 180819] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:50.356523 2026] [authz_core:error] [pid 180811:tid 180819] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:50.368894 2026] [security2:error] [pid 180811:tid 181040] [client 20.118.133.132:30665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/btx25.php"] [unique_id "aoSECkm4-PkKNOC4yxZhBgAAAGM"] [Tue Aug 18 13:10:50.401319 2026] [security2:error] [pid 180811:tid 180974] [client 68.155.154.236:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSECkm4-PkKNOC4yxZhCAAAACE"] [Tue Aug 18 13:10:50.416776 2026] [security2:error] [pid 180811:tid 181011] [client 20.250.13.23:17353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/wp-content/admin.php"] [unique_id "aoSECkm4-PkKNOC4yxZhCQAAAEY"] [Tue Aug 18 13:10:50.450563 2026] [security2:error] [pid 180811:tid 181038] [client 172.182.200.96:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/pkmoj.php"] [unique_id "aoSECkm4-PkKNOC4yxZhCwAAAGE"] [Tue Aug 18 13:10:50.459480 2026] [security2:error] [pid 180811:tid 180986] [client 20.91.215.254:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/al.php"] [unique_id "aoSECkm4-PkKNOC4yxZhDAAAAC0"] [Tue Aug 18 13:10:50.461018 2026] [security2:error] [pid 180811:tid 181018] [client 213.35.127.232:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/edit.php"] [unique_id "aoSECkm4-PkKNOC4yxZhDQAAAE0"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:50.461077 2026] [security2:error] [pid 180811:tid 180958] [client 40.85.222.29:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/images/slide/2025/09/op4.php"] [unique_id "aoSECkm4-PkKNOC4yxZhDgAAABE"] [Tue Aug 18 13:10:50.530197 2026] [security2:error] [pid 180811:tid 181036] [client 20.51.153.15:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/nd.php"] [unique_id "aoSECkm4-PkKNOC4yxZhFgAAAF8"] [Tue Aug 18 13:10:50.573661 2026] [security2:error] [pid 180811:tid 180971] [client 40.85.222.29:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/yxijx.php"] [unique_id "aoSECkm4-PkKNOC4yxZhFwAAAB4"] [Tue Aug 18 13:10:50.581536 2026] [security2:error] [pid 180811:tid 181019] [client 20.118.172.148:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/xmr.php"] [unique_id "aoSECkm4-PkKNOC4yxZhGQAAAE4"] [Tue Aug 18 13:10:50.586046 2026] [security2:error] [pid 180811:tid 180955] [client 20.100.169.31:3476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/cong.php"] [unique_id "aoSECkm4-PkKNOC4yxZhGgAAAA4"] [Tue Aug 18 13:10:50.588115 2026] [security2:error] [pid 180811:tid 180994] [client 158.23.17.4:8756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/oo.php"] [unique_id "aoSECkm4-PkKNOC4yxZhGwAAADU"] [Tue Aug 18 13:10:50.595663 2026] [security2:error] [pid 180811:tid 181048] [client 20.91.215.254:14304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/languages.php"] [unique_id "aoSECkm4-PkKNOC4yxZhHAAAAGs"] [Tue Aug 18 13:10:50.660043 2026] [security2:error] [pid 180811:tid 180948] [client 4.232.94.69:58274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/disagraeed.php"] [unique_id "aoSECkm4-PkKNOC4yxZhIgAAAAc"] [Tue Aug 18 13:10:50.693361 2026] [security2:error] [pid 180811:tid 181001] [client 172.202.39.151:38401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ortopedistapetornozelo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSECkm4-PkKNOC4yxZhJQAAADw"] [Tue Aug 18 13:10:50.693381 2026] [security2:error] [pid 180811:tid 181024] [client 20.48.236.86:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/coffee.php"] [unique_id "aoSECkm4-PkKNOC4yxZhJgAAAFM"] [Tue Aug 18 13:10:50.703713 2026] [security2:error] [pid 180811:tid 181032] [client 20.116.17.175:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/special.php"] [unique_id "aoSECkm4-PkKNOC4yxZhJwAAAFs"] [Tue Aug 18 13:10:50.745323 2026] [security2:error] [pid 180811:tid 181068] [client 40.85.222.29:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/class-wp-theme-json-schema-variable.php"] [unique_id "aoSECkm4-PkKNOC4yxZhKAAAAH8"] [Tue Aug 18 13:10:50.745707 2026] [security2:error] [pid 180811:tid 181007] [client 159.69.158.189:42822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ceussmedicina.com.br"] [uri "/index.php"] [unique_id "aoSECkm4-PkKNOC4yxZhHwAAAEI"], referer: http://ceussmedicina.com.br/ [Tue Aug 18 13:10:50.766749 2026] [security2:error] [pid 180811:tid 180999] [client 52.173.121.69:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/qfvqu.php"] [unique_id "aoSECkm4-PkKNOC4yxZhKgAAADo"] [Tue Aug 18 13:10:50.776906 2026] [security2:error] [pid 180811:tid 180960] [client 20.51.153.15:13360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ri.php"] [unique_id "aoSECkm4-PkKNOC4yxZhKwAAABM"] [Tue Aug 18 13:10:50.782897 2026] [security2:error] [pid 180811:tid 181049] [client 223.185.37.47:30196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.37.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSECkm4-PkKNOC4yxZhLAAAAGw"] [Tue Aug 18 13:10:50.787765 2026] [security2:error] [pid 180811:tid 181049] [client 223.185.37.47:30196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "miruku.co.mz"] [uri "/xmlrpc.php"] [unique_id "aoSECkm4-PkKNOC4yxZhLAAAAGw"] [Tue Aug 18 13:10:50.810605 2026] [security2:error] [pid 180811:tid 180982] [client 158.23.17.4:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/gg.php"] [unique_id "aoSECkm4-PkKNOC4yxZhLgAAACk"] [Tue Aug 18 13:10:50.823681 2026] [security2:error] [pid 180811:tid 181060] [client 172.182.200.96:15625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/kopyw.php"] [unique_id "aoSECkm4-PkKNOC4yxZhLwAAAHc"] [Tue Aug 18 13:10:50.825521 2026] [security2:error] [pid 180811:tid 181027] [client 103.168.147.235:49398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSECkm4-PkKNOC4yxZhMAAAAFY"] [Tue Aug 18 13:10:50.832841 2026] [security2:error] [pid 180811:tid 181020] [client 40.74.65.169:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/indes.php"] [unique_id "aoSECkm4-PkKNOC4yxZhMQAAAE8"] [Tue Aug 18 13:10:50.844956 2026] [security2:error] [pid 180811:tid 180953] [client 68.155.154.236:25384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "aoSECkm4-PkKNOC4yxZhMgAAAAw"] [Tue Aug 18 13:10:50.852061 2026] [security2:error] [pid 180811:tid 180993] [client 40.85.222.29:13227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/zwlsv.php"] [unique_id "aoSECkm4-PkKNOC4yxZhMwAAADQ"] [Tue Aug 18 13:10:50.907476 2026] [security2:error] [pid 180811:tid 180995] [client 40.74.65.169:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/adminfuns.php"] [unique_id "aoSECkm4-PkKNOC4yxZhNQAAADY"] [Tue Aug 18 13:10:50.937244 2026] [security2:error] [pid 180811:tid 181034] [client 20.127.136.245:28724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/index/function.php"] [unique_id "aoSECkm4-PkKNOC4yxZhOAAAAF0"] [Tue Aug 18 13:10:50.950168 2026] [authz_core:error] [pid 180811:tid 180854] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:50.950591 2026] [authz_core:error] [pid 180811:tid 180854] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:51.008715 2026] [security2:error] [pid 180811:tid 181040] [client 20.48.236.86:10405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/classwithtostring.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhOwAAAGM"] [Tue Aug 18 13:10:51.013293 2026] [security2:error] [pid 180811:tid 180974] [client 20.51.153.15:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/tp.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhPAAAACE"] [Tue Aug 18 13:10:51.040210 2026] [security2:error] [pid 180811:tid 180969] [client 20.91.215.254:16531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/goods.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhPwAAABw"] [Tue Aug 18 13:10:51.041794 2026] [security2:error] [pid 180811:tid 180978] [client 40.85.222.29:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/css/nDJvnf.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhQAAAACU"] [Tue Aug 18 13:10:51.062996 2026] [security2:error] [pid 180811:tid 181038] [client 20.104.49.167:21146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/wpxml.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhQQAAAGE"] [Tue Aug 18 13:10:51.112215 2026] [security2:error] [pid 180811:tid 180990] [client 20.91.215.254:12844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhRgAAADE"] [Tue Aug 18 13:10:51.131003 2026] [security2:error] [pid 180811:tid 181045] [client 74.248.18.37:58976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/simple.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhSQAAAGg"] [Tue Aug 18 13:10:51.140268 2026] [security2:error] [pid 180811:tid 180996] [client 40.85.222.29:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/jrpga.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhSgAAADc"] [Tue Aug 18 13:10:51.188020 2026] [security2:error] [pid 180811:tid 181048] [client 158.23.17.4:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ja.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhTgAAAGs"] [Tue Aug 18 13:10:51.208864 2026] [security2:error] [pid 180811:tid 181043] [client 20.100.169.31:17245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/css/classwithtostring.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhTwAAAGY"] [Tue Aug 18 13:10:51.242150 2026] [security2:error] [pid 180811:tid 180987] [client 20.118.172.148:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/about.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhUgAAAC4"] [Tue Aug 18 13:10:51.251481 2026] [authz_core:error] [pid 180811:tid 180867] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:51.251747 2026] [authz_core:error] [pid 180811:tid 180867] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:51.283475 2026] [security2:error] [pid 180811:tid 181018] [client 4.232.94.69:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/e69ovfsr.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhVwAAAE0"] [Tue Aug 18 13:10:51.291792 2026] [security2:error] [pid 180811:tid 180960] [client 20.51.153.15:1793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/zj.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhWAAAABM"] [Tue Aug 18 13:10:51.319477 2026] [security2:error] [pid 180811:tid 180956] [client 40.85.222.29:13221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/pomo/mail.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhXAAAAA8"] [Tue Aug 18 13:10:51.347567 2026] [security2:error] [pid 180811:tid 181006] [client 172.202.39.151:38448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ortopedistapetornozelo.com.br"] [uri "/admin.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhXgAAAEE"] [Tue Aug 18 13:10:51.417747 2026] [security2:error] [pid 180811:tid 181015] [client 40.85.222.29:12629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/museu/yhweq.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhYwAAAEo"] [Tue Aug 18 13:10:51.453114 2026] [security2:error] [pid 180811:tid 180977] [client 20.48.236.86:10808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/wp-ws68.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhZQAAACQ"] [Tue Aug 18 13:10:51.460546 2026] [security2:error] [pid 180811:tid 181050] [client 172.182.200.96:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/zznmg.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhaAAAAG0"] [Tue Aug 18 13:10:51.484072 2026] [security2:error] [pid 180811:tid 181055] [client 213.35.127.232:61939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/plugins.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhagAAAHI"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:51.518972 2026] [security2:error] [pid 180811:tid 180941] [client 158.23.17.4:20436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/gi.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhbAAAAAA"] [Tue Aug 18 13:10:51.527134 2026] [security2:error] [pid 180811:tid 181009] [client 40.74.65.169:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/tTPcH.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhbQAAAEQ"] [Tue Aug 18 13:10:51.536537 2026] [security2:error] [pid 180811:tid 180969] [client 191.237.254.161:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santusdesign.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhbgAAABw"] [Tue Aug 18 13:10:51.551836 2026] [security2:error] [pid 180811:tid 181038] [client 20.51.153.15:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/x.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhcAAAAGE"] [Tue Aug 18 13:10:51.554876 2026] [authz_core:error] [pid 180811:tid 180926] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:51.555176 2026] [authz_core:error] [pid 180811:tid 180926] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:51.596381 2026] [security2:error] [pid 180811:tid 180976] [client 40.85.222.29:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-admin/includes/ms-repository.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhdAAAACM"] [Tue Aug 18 13:10:51.600683 2026] [security2:error] [pid 180811:tid 180990] [client 40.74.65.169:25478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/ms-edit.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhdgAAADE"] [Tue Aug 18 13:10:51.607512 2026] [security2:error] [pid 180811:tid 180979] [client 149.34.210.141:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.210.34.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSEC0m4-PkKNOC4yxZheAAAACY"] [Tue Aug 18 13:10:51.614653 2026] [security2:error] [pid 180811:tid 181008] [client 20.104.49.167:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/file1221.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhegAAAEM"] [Tue Aug 18 13:10:51.639496 2026] [security2:error] [pid 180811:tid 180942] [client 20.91.215.254:12848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/nw.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhfAAAAAE"] [Tue Aug 18 13:10:51.697166 2026] [security2:error] [pid 180811:tid 180983] [client 68.155.154.236:14209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhfgAAACo"] [Tue Aug 18 13:10:51.697185 2026] [security2:error] [pid 180811:tid 181016] [client 40.85.222.29:13205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/nwwha.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhfwAAAEs"] [Tue Aug 18 13:10:51.715635 2026] [security2:error] [pid 180811:tid 181026] [client 20.116.17.175:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-content/themes/index.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhgQAAAFU"] [Tue Aug 18 13:10:51.759893 2026] [security2:error] [pid 180811:tid 180978] [client 20.91.215.254:14330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-activat.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhgwAAACU"] [Tue Aug 18 13:10:51.829764 2026] [security2:error] [pid 180811:tid 180996] [client 20.100.169.31:4006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/db.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhhwAAADc"] [Tue Aug 18 13:10:51.840537 2026] [security2:error] [pid 180811:tid 180950] [client 52.173.121.69:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/oivcl.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhiQAAAAk"] [Tue Aug 18 13:10:51.844653 2026] [security2:error] [pid 180811:tid 180958] [client 20.91.215.254:25659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/gulu.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhigAAABE"] [Tue Aug 18 13:10:51.845839 2026] [security2:error] [pid 180811:tid 181056] [client 172.182.200.96:15736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/bhfnd.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhiwAAAHM"] [Tue Aug 18 13:10:51.870217 2026] [security2:error] [pid 180811:tid 180998] [client 20.51.153.15:1952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/yn.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhjwAAADk"] [Tue Aug 18 13:10:51.883300 2026] [security2:error] [pid 180811:tid 180979] [client 149.34.210.141:63210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "galeriadoengenho.com"] [uri "/xmlrpc.php"] [unique_id "aoSEC0m4-PkKNOC4yxZheAAAACY"] [Tue Aug 18 13:10:51.907227 2026] [security2:error] [pid 180811:tid 181039] [client 4.232.94.69:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/alfa-rex1.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhkgAAAGI"] [Tue Aug 18 13:10:51.916839 2026] [security2:error] [pid 180811:tid 181022] [client 40.85.222.29:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/sodium_compat/rd64D5.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhkwAAAFE"] [Tue Aug 18 13:10:51.924741 2026] [security2:error] [pid 180811:tid 181054] [client 158.23.17.4:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/xx.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhlAAAAHE"] [Tue Aug 18 13:10:51.975323 2026] [security2:error] [pid 180811:tid 181058] [client 20.250.13.23:10094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/222.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhmAAAAHU"] [Tue Aug 18 13:10:51.981244 2026] [security2:error] [pid 180811:tid 181029] [client 40.85.222.29:13229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/opsqt.php"] [unique_id "aoSEC0m4-PkKNOC4yxZhmQAAAFg"] [Tue Aug 18 13:10:51.997842 2026] [security2:error] [pid 180811:tid 181021] [client 66.249.70.133:62703] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "agendapreta.com"] [uri "/robots.txt"] [unique_id "aoSEC0m4-PkKNOC4yxZhmgAAAFA"] [Tue Aug 18 13:10:52.058841 2026] [security2:error] [pid 180811:tid 181027] [client 20.118.133.132:45233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newinox.com.br"] [uri "/SDsadqwrf.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhnQAAAFY"] [Tue Aug 18 13:10:52.064494 2026] [security2:error] [pid 180811:tid 181041] [client 74.248.18.37:26790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/atex1.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhngAAAGQ"] [Tue Aug 18 13:10:52.140012 2026] [security2:error] [pid 180811:tid 181067] [client 20.48.236.86:10787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/mgrr.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhoQAAAH4"] [Tue Aug 18 13:10:52.154425 2026] [authz_core:error] [pid 180811:tid 180890] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:52.154707 2026] [authz_core:error] [pid 180811:tid 180890] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:52.166656 2026] [security2:error] [pid 180811:tid 181012] [client 20.51.153.15:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/11.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhpQAAAEc"] [Tue Aug 18 13:10:52.194787 2026] [security2:error] [pid 180811:tid 180962] [client 20.118.133.132:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.133.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "grupobelmais.com.br"] [uri "/av.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhpgAAABU"] [Tue Aug 18 13:10:52.210387 2026] [security2:error] [pid 180811:tid 180947] [client 40.85.222.29:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/assets/lXppkm.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhpwAAAAY"] [Tue Aug 18 13:10:52.217232 2026] [security2:error] [pid 180811:tid 181034] [client 20.91.215.254:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.showprimeautomoveis.com.br"] [uri "/lock360.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhqAAAAF0"] [Tue Aug 18 13:10:52.226537 2026] [security2:error] [pid 180811:tid 181040] [client 40.74.65.169:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/bs1.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhqgAAAGM"] [Tue Aug 18 13:10:52.272656 2026] [security2:error] [pid 180811:tid 181013] [client 40.85.222.29:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/jvcpa.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhqwAAAEg"] [Tue Aug 18 13:10:52.297384 2026] [security2:error] [pid 180811:tid 180984] [client 40.74.65.169:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/222.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhrQAAACs"] [Tue Aug 18 13:10:52.301560 2026] [security2:error] [pid 180811:tid 180965] [client 20.91.215.254:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/lofmebwd.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhrgAAABg"] [Tue Aug 18 13:10:52.407580 2026] [security2:error] [pid 180811:tid 180970] [client 20.127.136.245:15343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/info.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhtwAAAB0"] [Tue Aug 18 13:10:52.427238 2026] [security2:error] [pid 180811:tid 181019] [client 20.116.17.175:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/thoms.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhuAAAAE4"] [Tue Aug 18 13:10:52.433253 2026] [security2:error] [pid 180811:tid 181026] [client 172.182.200.96:15646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/qfvqu.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhugAAAFU"] [Tue Aug 18 13:10:52.459642 2026] [authz_core:error] [pid 180811:tid 180898] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:52.460115 2026] [authz_core:error] [pid 180811:tid 180898] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:52.463016 2026] [security2:error] [pid 180811:tid 181009] [client 20.100.169.31:17267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/dropdown.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhvAAAAEQ"] [Tue Aug 18 13:10:52.491524 2026] [security2:error] [pid 180811:tid 180963] [client 40.85.222.29:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/Requests/about.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhvwAAABY"] [Tue Aug 18 13:10:52.503759 2026] [security2:error] [pid 180811:tid 181046] [client 213.35.127.232:62193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-login.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhwQAAAGk"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:52.512023 2026] [security2:error] [pid 180811:tid 181061] [client 20.91.215.254:13013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/wp-admin/user/xmrlpc.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhwwAAAHg"] [Tue Aug 18 13:10:52.516980 2026] [security2:error] [pid 180811:tid 180981] [client 68.155.154.236:14311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/weozh.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhxAAAACg"] [Tue Aug 18 13:10:52.535930 2026] [security2:error] [pid 180811:tid 180990] [client 4.232.94.69:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/cd.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhxgAAADE"] [Tue Aug 18 13:10:52.554489 2026] [security2:error] [pid 180811:tid 181023] [client 40.85.222.29:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/block-supports/input.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhxwAAAFI"] [Tue Aug 18 13:10:52.579293 2026] [security2:error] [pid 180811:tid 180942] [client 20.91.215.254:16554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/h.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhyQAAAAE"] [Tue Aug 18 13:10:52.714559 2026] [security2:error] [pid 180811:tid 181029] [client 20.48.236.86:10723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/55.php"] [unique_id "aoSEDEm4-PkKNOC4yxZhzgAAAFg"] [Tue Aug 18 13:10:52.750136 2026] [security2:error] [pid 180811:tid 180891] [remote 216.73.216.206:21677] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "bioarquitetar.com"] [uri "/page/3/"] [unique_id "aoSEDEm4-PkKNOC4yxZhzwAAIk8"] [Tue Aug 18 13:10:52.758543 2026] [security2:error] [pid 180811:tid 180952] [client 20.104.49.167:14707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/nox.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh0AAAAAs"] [Tue Aug 18 13:10:52.778146 2026] [security2:error] [pid 180811:tid 181006] [client 40.85.222.29:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/html-api/wp-load.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh1AAAAEE"] [Tue Aug 18 13:10:52.787397 2026] [security2:error] [pid 180811:tid 181017] [client 103.168.147.235:49418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh1QAAAEw"] [Tue Aug 18 13:10:52.836210 2026] [security2:error] [pid 180811:tid 181028] [client 40.85.222.29:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/wp-conflg.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh1gAAAFc"] [Tue Aug 18 13:10:52.855024 2026] [security2:error] [pid 180811:tid 180946] [client 52.173.121.69:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/zugvi.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh2AAAAAU"] [Tue Aug 18 13:10:52.855898 2026] [security2:error] [pid 180811:tid 180953] [client 158.23.17.4:29479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/conn-test.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh2QAAAAw"] [Tue Aug 18 13:10:52.858449 2026] [security2:error] [pid 180811:tid 181052] [client 172.182.200.96:15629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/oivcl.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh2gAAAG8"] [Tue Aug 18 13:10:52.877621 2026] [security2:error] [pid 180811:tid 180999] [client 20.91.215.254:10213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.showprimeautomoveis.com.br"] [uri "/log.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh3AAAADo"] [Tue Aug 18 13:10:52.878834 2026] [security2:error] [pid 180811:tid 181067] [client 158.23.17.4:25354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/pz.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh3QAAAH4"] [Tue Aug 18 13:10:52.905790 2026] [security2:error] [pid 180811:tid 181059] [client 20.116.17.175:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh3wAAAHY"] [Tue Aug 18 13:10:52.912432 2026] [security2:error] [pid 180811:tid 181033] [client 40.74.65.169:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/hp2.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh4AAAAFw"] [Tue Aug 18 13:10:52.973933 2026] [security2:error] [pid 180811:tid 180948] [client 20.118.172.148:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/admin.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh5AAAAAc"] [Tue Aug 18 13:10:52.979610 2026] [security2:error] [pid 180811:tid 181025] [client 40.74.65.169:25282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/cgi-bin/index.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh5QAAAFQ"] [Tue Aug 18 13:10:52.980378 2026] [security2:error] [pid 180811:tid 180973] [client 20.127.136.245:18674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/profile.php"] [unique_id "aoSEDEm4-PkKNOC4yxZh5gAAACA"] [Tue Aug 18 13:10:53.007684 2026] [autoindex:error] [pid 180811:tid 180968] [client 20.91.215.254:14320] AH01276: Cannot serve directory /home3/vidraca/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive [Tue Aug 18 13:10:53.035564 2026] [security2:error] [pid 180811:tid 180965] [client 172.202.39.151:38415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.39.202.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ortopedistapetornozelo.com.br"] [uri "/public/css.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh6QAAABg"] [Tue Aug 18 13:10:53.057271 2026] [security2:error] [pid 180811:tid 181004] [client 178.153.171.161:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.171.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh7QAAAD8"] [Tue Aug 18 13:10:53.057431 2026] [security2:error] [pid 180811:tid 181004] [client 178.153.171.161:47462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jx2.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh7QAAAD8"] [Tue Aug 18 13:10:53.057794 2026] [authz_core:error] [pid 180811:tid 180924] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:53.058085 2026] [authz_core:error] [pid 180811:tid 180924] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:53.083829 2026] [security2:error] [pid 180811:tid 180945] [client 20.100.169.31:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/file.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh8AAAAAQ"] [Tue Aug 18 13:10:53.093688 2026] [security2:error] [pid 180811:tid 181048] [client 40.85.222.29:12656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/sitemaps/about.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh8wAAAGs"] [Tue Aug 18 13:10:53.099625 2026] [security2:error] [pid 180811:tid 181047] [client 68.155.154.236:14318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/rymmm.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh9AAAAGo"] [Tue Aug 18 13:10:53.130430 2026] [security2:error] [pid 180811:tid 180980] [client 40.85.222.29:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/Requests/library/a1cord.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh9QAAACc"] [Tue Aug 18 13:10:53.149775 2026] [security2:error] [pid 180811:tid 181030] [client 157.20.138.62:49738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh9wAAAFk"] [Tue Aug 18 13:10:53.149965 2026] [security2:error] [pid 180811:tid 181030] [client 157.20.138.62:49738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apostolicoprofetico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh9wAAAFk"] [Tue Aug 18 13:10:53.156709 2026] [security2:error] [pid 180811:tid 181055] [client 4.232.94.69:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/dropdown.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh-AAAAHI"] [Tue Aug 18 13:10:53.172775 2026] [security2:error] [pid 180811:tid 180916] [remote 57.141.22.27:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.22.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/public/index.php/locais/beautiful-beach"] [unique_id "aoSEDUm4-PkKNOC4yxZh-QAAX2g"] [Tue Aug 18 13:10:53.178094 2026] [security2:error] [pid 180811:tid 180941] [client 20.91.215.254:23111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/past1.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh-gAAAAA"] [Tue Aug 18 13:10:53.187613 2026] [security2:error] [pid 180811:tid 180992] [client 20.171.51.14:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.51.171.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns2.domcoworking.com.br"] [uri "/kl.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh-wAAADM"] [Tue Aug 18 13:10:53.217793 2026] [security2:error] [pid 180811:tid 181023] [client 20.91.215.254:14320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aoSEDUm4-PkKNOC4yxZh_gAAAFI"] [Tue Aug 18 13:10:53.241307 2026] [security2:error] [pid 180811:tid 180942] [client 20.48.236.86:10779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/ajax.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiAAAAAAE"] [Tue Aug 18 13:10:53.303483 2026] [security2:error] [pid 180811:tid 181044] [client 20.104.49.167:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/akismet.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiBwAAAGc"] [Tue Aug 18 13:10:53.308343 2026] [security2:error] [pid 180811:tid 180974] [client 20.91.215.254:13989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/hello.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiCAAAACE"] [Tue Aug 18 13:10:53.309497 2026] [security2:error] [pid 180811:tid 181058] [client 172.182.200.96:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/zugvi.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiCQAAAHU"] [Tue Aug 18 13:10:53.310375 2026] [security2:error] [pid 180811:tid 181042] [client 20.51.153.15:1972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/vm.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiCgAAAGU"] [Tue Aug 18 13:10:53.358311 2026] [authz_core:error] [pid 180811:tid 180815] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:53.358596 2026] [authz_core:error] [pid 180811:tid 180815] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:53.379003 2026] [security2:error] [pid 180811:tid 180952] [client 40.85.222.29:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/images/wp-load.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiEAAAAAs"] [Tue Aug 18 13:10:53.421908 2026] [security2:error] [pid 180811:tid 181027] [client 40.85.222.29:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/images/wp/snXZcWW.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiEgAAAFY"] [Tue Aug 18 13:10:53.437292 2026] [security2:error] [pid 180811:tid 181041] [client 20.127.136.245:14785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/sx.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiEwAAAGQ"] [Tue Aug 18 13:10:53.458578 2026] [security2:error] [pid 180811:tid 180989] [client 68.155.154.236:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/lddxs.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiFAAAADA"] [Tue Aug 18 13:10:53.459244 2026] [security2:error] [pid 180811:tid 181000] [client 168.62.48.100:5620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.48.62.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colmeiaconnect.com.br"] [uri "/zwlsv.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiFQAAADs"] [Tue Aug 18 13:10:53.491303 2026] [security2:error] [pid 180811:tid 180997] [client 20.250.13.23:54492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.13.250.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.vidracariaitaipu.com.br"] [uri "/wp-content/themes/pridmag/il.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiHgAAADg"] [Tue Aug 18 13:10:53.510699 2026] [security2:error] [pid 180811:tid 181054] [client 20.91.215.254:10205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.showprimeautomoveis.com.br"] [uri "/lv.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiMwAAAHE"] [Tue Aug 18 13:10:53.520608 2026] [security2:error] [pid 180811:tid 180981] [client 213.35.127.232:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/index.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiNgAAACg"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:53.549105 2026] [security2:error] [pid 180811:tid 181050] [client 20.51.153.15:1981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/eg.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiSgAAAG0"] [Tue Aug 18 13:10:53.565227 2026] [security2:error] [pid 180811:tid 180973] [client 191.237.254.161:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.254.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santusdesign.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiTQAAACA"] [Tue Aug 18 13:10:53.607109 2026] [security2:error] [pid 180811:tid 181062] [client 40.74.65.169:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/yb.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiUgAAAHk"] [Tue Aug 18 13:10:53.617298 2026] [security2:error] [pid 180811:tid 181034] [client 158.23.17.4:10951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/fg.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiUwAAAF0"] [Tue Aug 18 13:10:53.660638 2026] [security2:error] [pid 180811:tid 180980] [client 40.85.222.29:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/theme-compat/82NtBt.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiVQAAACc"] [Tue Aug 18 13:10:53.670451 2026] [security2:error] [pid 180811:tid 180941] [client 20.48.236.86:10710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vigus.net"] [uri "/yj09.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiaQAAAAA"] [Tue Aug 18 13:10:53.671223 2026] [security2:error] [pid 180811:tid 180992] [client 40.74.65.169:52241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/BDKR28WP.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiagAAADM"] [Tue Aug 18 13:10:53.694896 2026] [security2:error] [pid 180811:tid 180958] [client 172.182.200.96:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/wsrer.php"] [unique_id "aoSEDUm4-PkKNOC4yxZicAAAABE"] [Tue Aug 18 13:10:53.702377 2026] [security2:error] [pid 180811:tid 181032] [client 40.85.222.29:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/assets/admin/login/info.php"] [unique_id "aoSEDUm4-PkKNOC4yxZicgAAAFs"] [Tue Aug 18 13:10:53.710973 2026] [security2:error] [pid 180811:tid 181015] [client 20.100.169.31:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/goods.php"] [unique_id "aoSEDUm4-PkKNOC4yxZicwAAAEo"] [Tue Aug 18 13:10:53.717739 2026] [security2:error] [pid 180811:tid 180974] [client 68.155.154.236:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kuringacomunicacao.com.br"] [uri "/images/security.php"] [unique_id "aoSEDUm4-PkKNOC4yxZidAAAACE"] [Tue Aug 18 13:10:53.774062 2026] [security2:error] [pid 180811:tid 181035] [client 4.232.94.69:58277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/22.php"] [unique_id "aoSEDUm4-PkKNOC4yxZieQAAAF4"] [Tue Aug 18 13:10:53.803276 2026] [security2:error] [pid 180811:tid 181036] [client 158.23.17.4:49177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "financeiro.queroficarnanet.com"] [uri "/kk.php"] [unique_id "aoSEDUm4-PkKNOC4yxZifAAAAF8"] [Tue Aug 18 13:10:53.809312 2026] [security2:error] [pid 180811:tid 180987] [client 20.51.153.15:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/uk.php"] [unique_id "aoSEDUm4-PkKNOC4yxZifQAAAC4"] [Tue Aug 18 13:10:53.829463 2026] [security2:error] [pid 180811:tid 181060] [client 20.104.49.167:4208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/admin.php"] [unique_id "aoSEDUm4-PkKNOC4yxZigAAAAHc"] [Tue Aug 18 13:10:53.887979 2026] [security2:error] [pid 180811:tid 181004] [client 20.91.215.254:23118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/file61.php"] [unique_id "aoSEDUm4-PkKNOC4yxZijwAAAD8"] [Tue Aug 18 13:10:53.960165 2026] [authz_core:error] [pid 180811:tid 180918] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:53.960439 2026] [authz_core:error] [pid 180811:tid 180918] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:53.963808 2026] [security2:error] [pid 180811:tid 180992] [client 40.85.222.29:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/block-bindings/UpeDL0.php"] [unique_id "aoSEDUm4-PkKNOC4yxZinwAAADM"] [Tue Aug 18 13:10:53.969438 2026] [security2:error] [pid 180811:tid 180999] [client 20.127.136.245:28359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hoteisecovip.com.br"] [uri "/inputs.php"] [unique_id "aoSEDUm4-PkKNOC4yxZioAAAADo"] [Tue Aug 18 13:10:53.992313 2026] [security2:error] [pid 180811:tid 181061] [client 40.85.222.29:13240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/theme-previews-exception.php"] [unique_id "aoSEDUm4-PkKNOC4yxZiogAAAHg"] [Tue Aug 18 13:10:54.005883 2026] [security2:error] [pid 180811:tid 181023] [client 20.127.136.245:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiowAAAFI"] [Tue Aug 18 13:10:54.017932 2026] [security2:error] [pid 180811:tid 180967] [client 20.91.215.254:25626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/images/index.php"] [unique_id "aoSEDkm4-PkKNOC4yxZipQAAABo"] [Tue Aug 18 13:10:54.042179 2026] [security2:error] [pid 180811:tid 180958] [client 20.116.17.175:52281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.17.116.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teresinahost.site"] [uri "/root.php"] [unique_id "aoSEDkm4-PkKNOC4yxZipwAAABE"] [Tue Aug 18 13:10:54.075310 2026] [security2:error] [pid 180811:tid 180963] [client 74.248.18.37:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.portalosol.com.br"] [uri "/class-t.api.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiqgAAABY"] [Tue Aug 18 13:10:54.076219 2026] [security2:error] [pid 180811:tid 180946] [client 20.91.215.254:14326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/wp-includes/style-engine/about.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiqwAAAAU"] [Tue Aug 18 13:10:54.096315 2026] [security2:error] [pid 180811:tid 181039] [client 20.51.153.15:1942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/creds.php"] [unique_id "aoSEDkm4-PkKNOC4yxZirAAAAGI"] [Tue Aug 18 13:10:54.100631 2026] [security2:error] [pid 180811:tid 180996] [client 74.248.18.37:19833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jx2.com.br"] [uri "/edit-tags.php"] [unique_id "aoSEDkm4-PkKNOC4yxZirQAAADc"] [Tue Aug 18 13:10:54.106505 2026] [security2:error] [pid 180811:tid 181007] [client 68.221.73.131:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.73.221.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.comatmotos.com.br"] [uri "/key.php"] [unique_id "aoSEDkm4-PkKNOC4yxZirwAAAEI"] [Tue Aug 18 13:10:54.143595 2026] [security2:error] [pid 180811:tid 180978] [client 20.91.215.254:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.showprimeautomoveis.com.br"] [uri "/mah/function.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiswAAACU"] [Tue Aug 18 13:10:54.179935 2026] [security2:error] [pid 180811:tid 180976] [client 52.173.121.69:44665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.121.173.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confiancaveiculostj.com.br"] [uri "/wsrer.php"] [unique_id "aoSEDkm4-PkKNOC4yxZitwAAACM"] [Tue Aug 18 13:10:54.237189 2026] [security2:error] [pid 180811:tid 181054] [client 40.85.222.29:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/html-api/QxXX0h.php"] [unique_id "aoSEDkm4-PkKNOC4yxZivAAAAHE"] [Tue Aug 18 13:10:54.261463 2026] [authz_core:error] [pid 180811:tid 180844] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:54.261716 2026] [authz_core:error] [pid 180811:tid 180844] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:54.267396 2026] [security2:error] [pid 180811:tid 181059] [client 158.23.17.4:10992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ve.php"] [unique_id "aoSEDkm4-PkKNOC4yxZivgAAAHY"] [Tue Aug 18 13:10:54.274857 2026] [security2:error] [pid 180811:tid 180982] [client 40.85.222.29:13245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/images/menu/2025/04/aa97abcd1241bfd851db3d662a4f2b62e.php"] [unique_id "aoSEDkm4-PkKNOC4yxZivwAAACk"] [Tue Aug 18 13:10:54.283011 2026] [security2:error] [pid 180811:tid 181050] [client 40.74.65.169:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.65.74.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.classeanovohamburgo.com.br"] [uri "/vc.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiwAAAAG0"] [Tue Aug 18 13:10:54.301036 2026] [security2:error] [pid 180811:tid 180961] [client 20.104.49.167:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns1.wrtech.com.br"] [uri "/ajax.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiwQAAABQ"] [Tue Aug 18 13:10:54.334521 2026] [security2:error] [pid 180811:tid 180973] [client 20.51.153.15:1979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.153.51.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portopreguicas.com.br"] [uri "/ho.php"] [unique_id "aoSEDkm4-PkKNOC4yxZixAAAACA"] [Tue Aug 18 13:10:54.337663 2026] [security2:error] [pid 180811:tid 180959] [client 20.100.169.31:22616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.169.100.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bjagricola.com.br"] [uri "/hplfuns.php"] [unique_id "aoSEDkm4-PkKNOC4yxZixQAAABI"] [Tue Aug 18 13:10:54.357128 2026] [security2:error] [pid 180811:tid 180922] [remote 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDkm4-PkKNOC4yxZixwAAc24"] [Tue Aug 18 13:10:54.357317 2026] [security2:error] [pid 180811:tid 181056] [client 2405:4803:c821:6370:c1f1:c4a7:71ff:c3d1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "condominiopratico.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDkm4-PkKNOC4yxZixwAAc24"] [Tue Aug 18 13:10:54.364901 2026] [security2:error] [pid 180811:tid 180965] [client 172.182.200.96:15706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/ucpfr.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiyAAAABg"] [Tue Aug 18 13:10:54.365965 2026] [security2:error] [pid 180811:tid 181006] [client 40.74.65.169:52238] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.primetecnologiauniformes.filialweb.com"] [uri "/wp-includes/l10n/"] [unique_id "aoSEDkm4-PkKNOC4yxZiyQAAAEE"] [Tue Aug 18 13:10:54.400142 2026] [security2:error] [pid 180811:tid 181016] [client 68.155.154.236:14285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.154.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gruposilva.com.br"] [uri "/zjggu.php"] [unique_id "aoSEDkm4-PkKNOC4yxZiywAAAEs"] [Tue Aug 18 13:10:54.482326 2026] [security2:error] [pid 180811:tid 180981] [client 4.232.94.69:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.94.232.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.zelareimoveis.com.br"] [uri "/hkvkjguw.php"] [unique_id "aoSEDkm4-PkKNOC4yxZizQAAACg"] [Tue Aug 18 13:10:54.517358 2026] [security2:error] [pid 180811:tid 181062] [client 20.127.136.245:28362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.hoteisecovip.com.br"] [uri "/admin.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi0AAAAHk"] [Tue Aug 18 13:10:54.519708 2026] [security2:error] [pid 180811:tid 180966] [client 40.85.222.29:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/Text/r51tv7.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi0QAAABk"] [Tue Aug 18 13:10:54.526899 2026] [security2:error] [pid 180811:tid 181019] [client 20.118.172.148:39188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.172.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailsg.i-eduqi.com.br"] [uri "/adminfuns.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi0wAAAE4"] [Tue Aug 18 13:10:54.535443 2026] [security2:error] [pid 180811:tid 180985] [client 213.35.127.232:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.127.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wondermoving.com"] [uri "/wp-admin/profile.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi1AAAACw"], referer: https://wondermoving.com/wp-login.php [Tue Aug 18 13:10:54.562104 2026] [authz_core:error] [pid 180811:tid 180821] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php4 [Tue Aug 18 13:10:54.562395 2026] [authz_core:error] [pid 180811:tid 180821] [remote 216.73.216.206:21677] AH01630: client denied by server configuration: /home1/bioarquitetar/public_html/index.php3 [Tue Aug 18 13:10:54.573453 2026] [security2:error] [pid 180811:tid 180971] [client 40.85.222.29:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vanessafernanda.site"] [uri "/wp-includes/fazemrx1949_l7oIHvFs.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi1gAAAB4"] [Tue Aug 18 13:10:54.596013 2026] [security2:error] [pid 180811:tid 181061] [client 103.168.147.235:49464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "vapvistorias.com.br"] [uri "/index.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi2QAAAHg"] [Tue Aug 18 13:10:54.612537 2026] [security2:error] [pid 180811:tid 180983] [client 20.127.136.245:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.136.127.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ferreiralucas.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi2gAAACo"] [Tue Aug 18 13:10:54.695395 2026] [security2:error] [pid 180811:tid 181063] [client 158.23.17.4:29499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.17.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.plenitude.com.br"] [uri "/ia.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi3QAAAHo"] [Tue Aug 18 13:10:54.721803 2026] [security2:error] [pid 180811:tid 181048] [client 20.91.215.254:13952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ferreirafreitas.com.br"] [uri "/index.bak.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi4AAAAGs"] [Tue Aug 18 13:10:54.786341 2026] [security2:error] [pid 180811:tid 181033] [client 172.182.200.96:15718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.200.182.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.floripaveiculos.com.br"] [uri "/yxijx.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi4wAAAFw"] [Tue Aug 18 13:10:54.791441 2026] [security2:error] [pid 180811:tid 180964] [client 20.91.215.254:13392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.showprimeautomoveis.com.br"] [uri "/makeasmtp.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi5AAAABc"] [Tue Aug 18 13:10:54.806496 2026] [security2:error] [pid 180811:tid 180976] [client 40.85.222.29:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.222.85.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ceussmedicina.com.br"] [uri "/wp-includes/images/JpIAZA.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi5gAAACM"] [Tue Aug 18 13:10:54.812053 2026] [security2:error] [pid 180811:tid 181021] [client 20.91.215.254:23140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.raben.xyz"] [uri "/license.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi5wAAAFA"] [Tue Aug 18 13:10:54.827713 2026] [security2:error] [pid 180811:tid 180945] [client 114.5.214.109:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.214.5.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi6gAAAAQ"] [Tue Aug 18 13:10:54.827803 2026] [security2:error] [pid 180811:tid 180945] [client 114.5.214.109:50430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "portalosol.com.br"] [uri "/xmlrpc.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi6gAAAAQ"] [Tue Aug 18 13:10:54.837917 2026] [security2:error] [pid 180811:tid 181023] [client 20.91.215.254:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.215.91.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidracariaitaipu.com.br"] [uri "/f7.php"] [unique_id "aoSEDkm4-PkKNOC4yxZi6wAAAFI"]